Re: [GIT PULL] execve updates for v6.13-rc1 (take 2)

From: Kees Cook
Date: Thu Nov 28 2024 - 21:08:33 EST




On November 28, 2024 12:24:27 PM GMT+10:00, Linus Torvalds <torvalds@xxxxxxxxxxxxxxxxxxxx> wrote:
>But no, I do not accept changing well-documented behaviour of
>AT_EMPTY_PATH, much less the insanity of making "execveat()" have
>completely different semantics for AT_EMPTY_PATH than a plain openat.

Yeah, that was going to be the next question. ;) Okay, so, that last thing I can see here as an option is to add an exec-specific AT flag, and if that isn't workable I don't see a way to make this happen with execveat.

-Kees

--
Kees Cook