by [OK Ryoko], revision 2024-11-24.1
Assumed audience: Linux system administrators, Linux utility authors and [Fedora Linux] package maintainers. Familiarity with [credentials], [capabilities], [syscalls], [strace], [Linux PAM] and [SELinux] is assumed.
In this report, I build on the work described in [SUID-root Binaries in Fedora Workstation 39]. Once again, my goal is to characterize the SUID-root binaries present on the system and establish minimal file capability sets for those binaries.
I provide a high-level summary of outcomes in the “The findings at a glance” section.