I was asked to put this to the discussion again before submitting the proposal. I think the current emphasis of the discussion is best discussed in the devel mailing list, but I made it a habit to always allow the whole community to add their thoughts.
Massively simplified: enabling ptrace_scope brings us to the kernel default and it mitigates some types of attacks in some contexts, which can be realistic for some audiences of Fedora, but it breaks some (mostly debugger) functions used by some software developers.
Developers can easily mitigate the issue (one command to disable it temporarily or permanently), but this can still be demotivating for those who just started working with such tools (decreasing the chance that they become active development contributors on Fedora) and all types of developers who are not yet active in the devel mailing list or reading through change proposals need to find out about how to mitigate before they can use the simple commands obviously (the proposal contains means to mitigate this issue though).
It is unlikely that “average users” will experience an impact, which is suggested by openSuSE, Arch and Ubuntu that all use the kernel default for about 10 years.
More details in my post in the devel mailing discussion:
(I’m saving space by not copying/pasting it here.)
… or in the change proposal in its current state:
However, in Discourse it might be useful to discuss if I shall change the name of the proposal: I somehow felt it useful to contain a hint in the title that tells average users what this is about (incl. the goal, which might be easier for users to link to their own case than technical implementations, and therefore allow them to give feedback about if that is important for them or not). But I am not sure if the title as it is at the moment is a bit “suggestive” and triggers average users already to vote in a certain direction. … open to thoughts ![]()
@mjw FYI ![]()