@@ -130,6 +130,13 @@ Use cases
- Chrome browser: protect some security sensitive data structures.
+- System mappings:
+ If supported by an architecture (via CONFIG_ARCH_HAS_MSEAL_SYSTEM_MAPPINGS),
+ the CONFIG_MSEAL_SYSTEM_MAPPINGS seals system mappings, e.g. vdso, vvar,
+ uprobes, sigpage, vectors, etc. CHECKPOINT_RESTORE, UML, gVisor, rr are
+ known to relocate or unmap system mapping, therefore this config can't be
+ enabled universally.
+
When not to use mseal
=====================
Applications can apply sealing to any virtual memory region from userspace,