On Mon, Sep 21, 2020 at 03:49:56PM +0300, Jarkko Sakkinen wrote: > The 2nd part of the answer is the answer to the question: why we want to > feed LSM hooks enclaves exactly in this state. The question can be further refined as why: why this is the best possible set of substates to filter in? "no holes" part is obvious as the consequence of not surpassing permissions of any of the pages in range, as you could otherwise break the state with ioctl(SGX_ENCLAVE_ADD_PAGES) with permssions that are below the mmap permissions. /Jarkko