On Wed, 24 Jan 2024 at 09:21, Kees Cook <keescook@xxxxxxxxxxxx> wrote: > > I opted to tie "current->in_execve" lifetime to bprm lifetime just to > have a clean boundary (i.e. strictly in alloc/free_bprm()). Honestly, the less uinnecessary churn that horrible flag causes, the better. IOW, I think the goal here should be "minimal fix" followed by "remove that horrendous thing". Linus