I’m confused. Why is this remapping option exposed to userspace?

It's not. In the demo video the exploit code is a Linux kernel module, not a userspace application.