[6.8-rc1 Regression] Unable to exec apparmor_parser from virt-aa-helper

Linus Torvalds torvalds at linux-foundation.org
Wed Jan 24 17:27:34 UTC 2024


On Wed, 24 Jan 2024 at 09:21, Kees Cook <keescook at chromium.org> wrote:
>
> I opted to tie "current->in_execve" lifetime to bprm lifetime just to
> have a clean boundary (i.e. strictly in alloc/free_bprm()).

Honestly, the less uinnecessary churn that horrible flag causes, the better.

IOW, I think the goal here should be "minimal fix" followed by "remove
that horrendous thing".

              Linus



More information about the Linux-security-module-archive mailing list