* https://jdebp.uk/FGA/dont-abuse-su-for-dropping-privileges.h...
One wonders if perhaps these systems weren't on to something.
Their then asserted correct solution to TIOCSTI was that su, sudo, doas, and the like should open a pseudo-terminal and get involved in pumping pseudo-terminal I/O. They were to do this as well as, presumably, managing all of setsid(), child process stopping/suspending with a signal, and setlogname() for the new session; to keep what the old books all say about keeping the same logname even though one has switched user, and being able to use the suspend command in the second shell.
* https://www.openwall.com/lists/oss-security/2017/06/03/9
* https://www.openwall.com/lists/kernel-hardening/2017/05/10/3...
Six months ago, TIOCSTI became optional in Linux.
Oof, weird inference. File inheritance is pretty well known. TIOCSTI is really esoteric.
If you have BusyBox installed, you have runit's chpst and setuidgid built in to it. And most Linux distributions not only package that but also package one or more of these toolsets; most often daemontools and runit, but nosh has an Arch package for example.