+++ This bug was initially created as a clone of Bug #646443 +++ Description of problem: Please remove setuid setup of files in your package with file capabilities. This is to satisfy the F15 feature. https://fedoraproject.org/wiki/Features/RemoveSETUID An example of how this was done for X is. %if 0%{?fedora} < 15 %define Xorgperms %attr(4711, root, root) %else %define Xorgperms %attr(0711,root,root) %caps(cap_sys_admin,cap_sys_rawio,cap_dac_override=pe) %endif
Any movement on this?
We need *all* capabilities in general; the launch helper is used to run arbitrary programs. It's pretty much an alternative init. In practice cap_sys_admin and cap_dac_override would probably be enough, but I don't really want to guess. How do we request "all"? Note that in the future hopefully this setuid helper will be going away in favor of asking systemd to do the activation. See https://bugs.freedesktop.org/show_bug.cgi?id=34526
Bug 646485 comment 2 is related to this.
Thats fine, Closing WONTFIX, Or could CLOSE NOTABUG.