Also, a sysctl for rejecting the call would seem reasonable.
Also, a sysctl for rejecting the call would seem reasonable.
And why not just fix the exec call in userland? I'm not sure who supplies it - the C standard library or the kernel headers. You would fix all the cases of accidentally calling something with argc==0 and it would not run afoul of the kernel breaking userspace.
Ironically the reason pkexec exists on Ubuntu server installs seems to be that they want to have a package management service (PackageKit) hanging off dbus even in headless setups, for reasons that aren't obvious. There have been earlier local root bugs caused by PackageKit as well[1].
(The irony being, the LWN documented discussion where a dev defends ipc-accessible privileged daemons as more secure and justifies pkexec as facilitating access to these).
But with having a resident daemon approach you lose the process ownership, which sometimes is damn handy to have. Accidentally granting root to do a wrong thing and then not even being able to kill the thing with Ctrl-C or xkill is quite disempowering.
Naturally I'd personally prefer rc.subr or s6 or nosh (though I've seen people footgun themselves with all of those too, albeit less often than SysV) but it is what it is, and most days I can bring myself to believe that the systemd transition was the sort of imperfect net win that's usually as good as you get in an ecosystem as complex as this one.
At the same time, you can still not elevate inside an application. I would love to run a command to open a single file as root in vim, or VS code, or copy one file as root in Nautilus. I think you can click a little lock in Gnome settings somewhere and unlock certain pages, but it is far from widespread.