Package: base-passwd
Version: 3.5.45
Severity: normal

Hi,

the range 64040-64044 is assigned to various grsec-related groups. The
groups are created by the linux-grsec-base package postinst, which was
used when src:linux-grsec was a thing. Unfortunately, there is no more
package since grsecurity is now private, so linux-grsec-base doesn't
really make sense anymore (although it can still be used for grsecurity
customers).

The grsec-proc group (64044) can still be used with the hidepid feature
of mainline Linux kernel, and I'm pondering providing a package doing
some hardening and maybe creating that group.

It could also be a different gid, but I guess reusing it doesn't hurt
that much?

Thanks in advance for your input on this.

Regards,
-- 
Yves-Alexis

-- System Information:
Debian Release: buster/sid
  APT prefers unstable-debug
  APT policy: (500, 'unstable-debug'), (500, 'unstable'), (450, 'experimental')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 4.19.0-1-amd64 (SMP w/2 CPU cores)
Locale: LANG=fr_FR.utf8, LC_CTYPE=fr_FR.utf8 (charmap=UTF-8), 
LANGUAGE=fr_FR.utf8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages base-passwd depends on:
ii  libc6              2.28-4
ii  libdebconfclient0  0.246

Versions of packages base-passwd recommends:
ii  debconf [debconf-2.0]  1.5.69

base-passwd suggests no packages.

-- debconf information excluded

Reply via email to