[PATCH v6 0/9] Add support for memory sealing
Stephen Röttger
sroettger@google.com
Tue Dec 2 17:41:59 GMT 2025
On Mon, Dec 1, 2025 at 2:46 PM Florian Weimer <fweimer@redhat.com> wrote:
>
> * Stephen Röttger:
>
> > Florian, do you see any other option to make this work?
>
> I don't think we can make this work due to the obvious conflict in
> goals.
>
> I'm not sure how many installations critically depend on glibc patching.
> It could be anti-cheats, tracing and debugging tools, userspace GPU
> drivers. Anyone who has to rely on binary patching will have a very
> hard time upgrading to a newer glibc from their distribution because
> there is currently no reliable system-wide way to disable this
> functionality.
>
> Maybe it's not a problem because the number of impacted users is low?
> Hard to tell.
Would it be an option to ship the feature disabled by default and enabling it
using a tunable instead?
That way, distros or applications could start using it and we would get some
confidence in the amount of incompatible code. And at that point, we could
switch the default to enabled.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 5283 bytes
Desc: S/MIME Cryptographic Signature
URL: <https://sourceware.org/pipermail/libc-alpha/attachments/20251202/7b155ef4/attachment-0001.p7s>
More information about the Libc-alpha
mailing list