On 8/4/25 8:22 PM, Ionen Wolkens wrote:

> +1 from me
> 
> Albeit perhaps one thing that may be worth mentioning (at a glance)
> is util-linux[caps].
> 
> 1. it depends on libcap-ng rather than libcap
> 
> 2. libcap-ng is pretty small, but when it's going to be pulled
> for almost *every* users when I think(?) "most" likely did not
> have it before may be worth thinking about (for me it's pulled
> by qemu either way but that has a more limited userbase)
> 
> 3. util-linux[caps] only controls installing setpriv(1), it's IMO
> a nice/useful tool but afaik most users do not really know/use it
> and will more typically use `su -c` as root -- assuming that they
> need to do this at all
> 
> Providing that by default still doesn't sound so bad (it's not
> suid-root unlike su, meant to be used by a privileged user), but
> moving it to IUSE=setpriv could be an option. Renaming USE does
> disrupt users like usual though and some users may rely on this tool
> for important scripts.
> 
> I don't really mind either way myself, just thought it'd be worth
> mentioning.


IMHO it's no bad thing for setpriv to be widely available. But I never
do use "su -c" at all -- I strictly avoid it in favor of "runuser",
largely because it isn't USE-conditional. I wouldn't mind using setpriv
-- it does offer a bit more control at least...


-- 
Eli Schwartz

Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature

Reply via email to