Re: [6.8-rc1 Regression] Unable to exec apparmor_parser from virt-aa-helper
From: Linus Torvalds
Date: Wed Jan 24 2024 - 12:31:07 EST
On Wed, 24 Jan 2024 at 09:21, Kees Cook <keescook@xxxxxxxxxxxx> wrote:
>
> I opted to tie "current->in_execve" lifetime to bprm lifetime just to
> have a clean boundary (i.e. strictly in alloc/free_bprm()).
Honestly, the less uinnecessary churn that horrible flag causes, the better.
IOW, I think the goal here should be "minimal fix" followed by "remove
that horrendous thing".
Linus