Re: [PATCH] exec: Set file unwritable before LSM check

From: Linus Torvalds
Date: Fri Mar 09 2018 - 14:13:57 EST


On Fri, Mar 9, 2018 at 11:07 AM, Kees Cook <keescook@xxxxxxxxxxxx> wrote:
> The LSM check should happen after the file has been confirmed to be
> unchanging. Without this, we could have a ToCToU issue between the
> LSM verification and the actual contents of the file later.

Can we please not add random crazy six-letter acronyms that nobody
uses outside of a very small community?

The point of a commit message is to *explain*, not confuse.

Linus