#1098773 uidmap: use CAP_SETGID instead of setuid on platforms that support it

Package:
uidmap
Source:
uidmap
Description:
programs to help use subuids
Submitter:
Daniel Kahn Gillmor
Date:
2025-02-23 22:12:02 UTC
Severity:
normal
#1098773#5
Date:
2016-06-16 19:02:02 UTC
From:
To:
newgrp is currently setuid root.  Since the only superuser activity it
is supposed to execute is changing group status, it would be safer to
use setcap CAP_SETGID instead.

the iputils-ping package made this transition for ping.  That package
Recommends: libcap2-bin, and has a postinst containing:

if [ "$1" = configure ]; then
    # If we have setcap is installed, try setting cap_net_raw+ep,
    # which allows us to install our binaries without the setuid
    # bit.
    if command -v setcap > /dev/null; then
        if setcap cap_net_raw+ep /bin/ping; then
            chmod u-s /bin/ping
        else
            echo "Setcap failed on /bin/ping, falling back to setuid" >&2
            chmod u+s /bin/ping
        fi
    else
        echo "Setcap is not installed, falling back to setuid" >&2
        chmod u+s /bin/ping
    fi
fi


It would be great to do a similar thing for newgrp.

#1098773#10
Date:
2021-03-09 18:31:01 UTC
From:
To:
Hello,

The executables installed by newgrp and uidmap are still today setuid
instead of using capabilities

When looking at the build system, it seems tha the newuidmap and
newgidmap are actually meant use the file capabilities instead of being
setuid:


src/Makefile.am:	setcap cap_setuid+ep $(DESTDIR)$(ubindir)/newuidmap
src/Makefile.am:	setcap cap_setgid+ep $(DESTDIR)$(ubindir)/newgidmap

#1098773#15
Date:
2025-02-23 22:04:28 UTC
From:
To:
login has moved to src:util-linux.
uidmap is a binary package of src:shadow.

Lets keep track of this for both source packages.