Hi, > > > which system supports memfd without sealing? > > > > RHEL 7.2. kernel version 3.10.0-327.el7.x86_64 > > Correct, it was backported without sealing for some reason. > > I would rather have an explicit seal=off argument on such system > (because sealing is expected to be available with memfd in general)
Or just drop support for memfd without sealing. cheers, Gerd