@artemist @mildsunrise Yeah, at least here only things setuid I have on my Gentoo machines (thanks to suidctl + mount nosuid) are ones I've personally reviewed (which lead me to rewrite su(1)…). And sudo wouldn't make it, way too big, meanwhile I've done so for doas.
And eventually aim to do the same for ones stuck to running as root (syslog, mdevd, …), at least tinyssh I've already done as I package it.