Linux’s Integrity Policy Enforcement “IPE” module is gaining a useful addition with the in-development Linux 6.19 kernel.

The Linux Integrity Policy Enforcement now honors the “AT_EXECVE_CHECK” flag so user-space interpreters can signal to the kernel to perform IPE security checks on script files before execution. This functionality with AT_EXECVE_CHECK extends IPE enforcement now to indirectly-executed scripts on the system.