Skip to content

The status page says stage 06 fails the build on a setuid bit or file capability its allowlists do not justify - #249

Merged
DevomB merged 1 commit into
mainfrom
status-setuid-fails
Oct 7, 2026
Merged

DevomB merged 1 commit into
mainfrom
status-setuid-fails

Conversation

@DevomB

@DevomB DevomB commented Oct 7, 2026

Copy link
Copy Markdown
Owner

What was wrong. docs/status.md's stage 06 row said the stage strips every setuid bit the allowlist does not justify. Since c431bf4, stage 06 runs tools/audit-setuid.sh without --strip (build/stages/06-iso.sh:146), so an unlisted setuid or setgid bit, or an unlisted file capability, fails the build. --strip is only for a root staged by hand, as docs/hardening.md ("setuid elimination") already says.

What changed. That one sentence of the row now says the stage fails the build on any setuid bit or file capability its allowlists do not justify.

How the run proves it. This is docs only, and no script reads the row. #245 also edits docs/status.md, but sixty lines further down, so the two merge cleanly in either order.

… capability its allowlists do not justify: it has since c431bf4, and the page still said the stage strips them

Stage 06 runs tools/audit-setuid.sh without --strip, which fails on an
unlisted bit or capability (docs/hardening.md, "setuid elimination"); --strip
is only for a root staged by hand.
@DevomB
DevomB merged commit 68bf207 into main Oct 7, 2026
10 of 11 checks passed
@DevomB
DevomB deleted the status-setuid-fails branch October 7, 2026 20:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant