hardened_malloc
hardened_malloc copied to clipboard
linux: make use of mseal(2)
Instead of protecting the global read-only data structure after startup via the read-only flag, which can be reverted, use the in Linux 6.10 introduced irreversible syscall mseal(2).
I've been running this for about a week now without issue.
Will get to this eventually, it's just very low priority due to low impact.
Kindly ping