mseal_all()
mseal_all()
Posted Jan 21, 2024 23:10 UTC (Sun) by NYKevin (subscriber, #129325)In reply to: mseal_all() by NYKevin
Parent article: mseal() gets closer
Correction: mseal does not prevent you from writing to the memory, so actually this is less of a problem than I thought. Still not sure it's workable, however, because nearly any nontrivial malloc implementation will eventually want to call sbrk or mmap, and that would be prevented by sealing the whole address space. With cooperation from libc, some kind of more restricted sealing might be possible, however.