Hi Tomoyo maintainers,
On 6/27/2026 7:28 AM, Tetsuo Handa wrote:
I updated your patch like below in order to exclude kernel threads from this check.
If we are OK to go with modifying individual LSM, I'll apply this change.
Archiving this patch, I see you have had no answer from other
maintainers to your question about the approach taken (per-LSM instead
of aiming for a hook-wide fix). Patches have indeed been merged for
other affected LSMs:
4d587cd8a721 ("apparmor: mediate the implicit connect of TCP fast open
sendmsg")
44c74d27d1b9 ("selinux: check connect-related permissions on TCP Fast Open")
33cb713db016 ("landlock: Fix TCP Fast Open connection bypass")
Have a nice day!
Matthieu