Linux BPF Hardening & Constant Blinding Architecture Simulator
CONFIG_BPF_JIT_ALWAYS_ON=y
Userspace / bpf() Syscall Benign eBPF Program BPF_PROG_TYPE_SOCKET_FILTER Privileged CAP_BPF / Root Unprivileged User Task UID=1000 without CAP_BPF bpf(BPF_PROG_LOAD, ...) Exploit probing kernel BPF JIT Spray Payload MOV64_IMM 0x4831c04831db Hidden shellcode inside IMM Seeking native gadget jump Kernel BPF Hardening Engine unprivileged_bpf_disabled=2 & bpf_jit_harden=2 Access Control & Verifier 1. unprivileged_bpf_disabled test 2. DAG static safety analyzer 3. CONFIG_BPF_JIT_ALWAYS_ON=y JIT Constant Blinding bpf_jit_blind_constants() Mask M = prandom_u32() Emits: (IMM ^ M) followed by XOR M Status: Shellcode constants destroyed JIT Compilation Outcome JIT COMPILED (SAFE) Executable page allocated All constants blinded Zero exploitable gadgets BLOCKED: -EPERM Syscall returned -1 unprivileged_bpf_disabled No BPF program loaded Attack surface eliminated
Ready. Choose a scenario: Benign BPF Program, Unprivileged BPF Exploit, or JIT Spray.
Step: 0/4