[$] Much ado about SBAT

Post Syndicated from original https://lwn.net/Articles/938422/

Sometimes, the shortest patches lead to the longest threads; for a case in
point, see this
three-line change
posted by Emanuele Giuseppe Esposito. The purpose of
this change is to improve the security of locked-down systems by adding a
“revocation number” to the kernel image. But, as the discussion revealed,
both the cost and the value of this feature are seen differently across the
kernel-development community.