On Thu, Sep 10, 2020 at 08:38:21PM +0200, Mickaël Salaün wrote: > There is also the use case of noexec mounts and file permissions. From > user space point of view, it doesn't matter which kernel component is in > charge of defining the policy. The syscall should then not be tied with > a verification/integrity/signature/appraisal vocabulary, but simply an > access control one. permission()?