Good news. Debian seems to use capabilities over setuid bits for most default binaries. Things like
ping don’t have setuid by default.
All binaries with setuid on a fresh Whonix installation are
There are no setgid binaries by default.
firejail probably just needs CAP_SETUID and CAP_SETGID for user namespaces. Maybe CAP_SYS_ADMIN too but I’m not sure.
Some firejail commands will need others. For example,
firejail --chroot will need CAP_SYS_CHROOT.
mount and umount will likely just need CAP_SYS_ADMIN.
su and sudo probably just need CAP_SETUID and CAP_SETGID.
These will need a lot of testing.