It prevents any user from overwriting an existing executable, and it
prevents any user from adding an executable file to a common directory
(/usr/bin).
It also prevents any user from overwriting a different user's data file.
What specific threat model are you feeling is still present on Linux
today that this proposal is supposed to address?
thanks,
greg k-h
--