Re: [RFC 37/37] fs/binfmt_elf: Block old shstk elf bit

From: Florian Weimer
Date: Sun Nov 06 2022 - 04:34:32 EST


* H. J. Lu:

> This change doesn't make a binary CET compatible. It just requires
> that the toolchain must be updated and all binaries have to be
> recompiled with the new toolchain to enable CET. It doesn't solve any
> issue which can't be solved by not updating glibc.

Right, and it doesn't even address the library case (the kernel would
have to hook into mmap for that). The kernel shouldn't do this.

Thanks,
Florian