On Sun, Jan 13, 2019 at 03:31:58PM +0100, Yves-Alexis Perez wrote:
> the range 64040-64044 is assigned to various grsec-related groups. The
> groups are created by the linux-grsec-base package postinst, which was
> used when src:linux-grsec was a thing. Unfortunately, there is no more
> package since grsecurity is now private, so linux-grsec-base doesn't
> really make sense anymore (although it can still be used for grsecurity
> customers).
> 
> The grsec-proc group (64044) can still be used with the hidepid feature
> of mainline Linux kernel, and I'm pondering providing a package doing
> some hardening and maybe creating that group.
> 
> It could also be a different gid, but I guess reusing it doesn't hurt
> that much?

Hmm.  I mean, it's possible that it wouldn't hurt, and I'm not sure
whether I have a strong opinion on it, but for the record could you
explain the positive benefits of reusing it?

Are you considering simply reusing the username and UID but creating it
in another package?

Thanks,

-- 
Colin Watson                                       [[email protected]]

Reply via email to