On Tue, 24 Jun 1997, Michael Meskes wrote:

>It seems I misunderstood what suidmanager does.
>But I still don't see the reason for non-setuid  programs listed there
>by default. Does that mean 'You can make this program suid, but we
>prefer it to be not-suid.'?

It means that a program has registered a binary and will respect changed
permissions for that file when upgraded. If you generate an entry in
/etc/suid.conf manually it usually means that the package who contains
that binary does not make any provisions made to preserve permissions. On
the next upgrade those permissions will be lost and you need to run


to restore the permissions to the configuration in /etc/suid.conf.

What it means for debmake is: I really would like those binaries to be
setuid (restricted to execution only by a group) and it is necessary to
use the full capabilities that debmake provides. But there was a
significant disagreement about having such binaries installed by default.
Fantastic rumours and imaginative stories about setuid binaries in debmake
began to be spread on debian-devel and so I finally decided to not install
those permissions by default. 

That was the initial motivation to develop suidmanager by the way....

