2024-08-19 to 2024-08-25
News
More capable privileged-programs replace setuid-programs
More capable privileged-programs replace setuid-programs
Where the kernel supports it, Guix System can now assign POSIX capabilities to trusted executables. Capabilities offer a more granular alternative to the traditional setuid and setgid permissions, which remain available.
To reflect this, (gnu system setuid) has been renamed to (gnu system privilege). privileged-programs replaces setuid-programs as operating-system field and defaults to %default-privileged-programs. The executables themselves have moved from /run/setuid-programs to /run/privileged/bin.
Guix Weekly News