Skip to content

Executability check (Linux >= 6.13) #1431

Open
@rusty-snake

Description

@rusty-snake

https://docs.kernel.org/next/userspace-api/check_exec.html

  • AT_EXECVE_CHECK
    • for execveat which is rustix_1_0_5::not_implemented::quite_yet ATM. However we do not need to wait for it, we can just add it to AtFlags.
  • SECBIT_EXEC_RESTRICT_FILE and SECBIT_EXEC_DENY_INTERACTIVE (+ _LOCKED variants)
    • add to CapabilitiesSecureBits

Oblivious it depends on linux_raw_sys and libc support for those flags.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions