newgrp is currently setuid root. Since the only superuser activity it
is supposed to execute is changing group status, it would be safer to
use setcap CAP_SETGID instead.
the iputils-ping package made this transition for ping. That package
Recommends: libcap2-bin, and has a postinst containing:
if [ "$1" = configure ]; then
# If we have setcap is installed, try setting cap_net_raw+ep,
# which allows us to install our binaries without the setuid
# bit.
if command -v setcap > /dev/null; then
if setcap cap_net_raw+ep /bin/ping; then
chmod u-s /bin/ping
else
echo "Setcap failed on /bin/ping, falling back to setuid" >&2
chmod u+s /bin/ping
fi
else
echo "Setcap is not installed, falling back to setuid" >&2
chmod u+s /bin/ping
fi
fi
It would be great to do a similar thing for newgrp.