memfd Seals Turn Shared Memory into a Kernel-Enforced Immutable Payload
Shared memory is efficient partly because two processes can observe the same storage without copying it. That property becomes a security problem when one side validates bytes and later consumes them while another side still holds authority to mutate the same object. Linux memfd sealing can narrow that race by making selected mutations fail in the kernel before the file descriptor crosses a trust boundary. memfd_create() creates an anonymous file and returns an ordinary file descriptor. The object can be sized, written, mapped, and transferred over a UNIX domain socket. With MFD_ALLOW_SEALING, the inode starts with an empty seal set, allowing the producer to add irreversible restrictions after population.