Open
Description
https://docs.kernel.org/next/userspace-api/check_exec.html
-
AT_EXECVE_CHECK
- for
execveat
which isrustix_1_0_5::not_implemented::quite_yet
ATM. However we do not need to wait for it, we can just add it toAtFlags
.
- for
-
SECBIT_EXEC_RESTRICT_FILE
andSECBIT_EXEC_DENY_INTERACTIVE
(+_LOCKED
variants)- add to
CapabilitiesSecureBits
- add to
Oblivious it depends on linux_raw_sys
and libc
support for those flags.