On Thu, 2022-10-13 at 14:28 -0700, Rick Edgecombe wrote: > In the meantime we could have a new bit shstk_strict, > that requests behavior like these patches implement, and kills the > process on violation. Glibc/tools could add support for this strict > bit > and anyone that wants to more carefully compile with it could finally > get shadow stack today. Then the implementation of the warn and > continue mode could follow that, and glibc could map the original > shstk > bit to that kernel mode. So the old binaries would get there > eventually, which is better than the continuing nothing they have > today. Hi, Any thoughts on this proposal? Thanks, Rick