Linux 6.12 IPE (Integrity Policy Enforcement) LSM
🌓 Theme
Mode: Enforce (1)
▶ Boot Verified Binary
⚠️ /tmp Untrusted Script
Step ⏭
Auto Play ▶
↺ Reset
1. Origin & Storage Layer
Trusted Provenance
Source: initramfs / dm-verity
Path: /bin/lab_tool
Property: boot_verified=TRUE
Hash: Immutable signed
Mutable Storage (Untrusted)
Source: ext4 /tmp /home
Path: /tmp/untrusted_payload
Property: boot_verified=FALSE
Threat: Local Priv-Esc / RCE
2. IPE LSM Policy Engine
LSM Hook Interception
security_bprm_check(bprm, op=EXECUTE)
Active Policy (Lab_Hardened)
DEFAULT action=DENY
Rule 1: op=EXEC boot_verified=TRUE
-> action=ALLOW
Fallback: Untrusted -> DEFAULT DENY
Kernel Enforcement Switch
Mode: /sys/kernel/security/ipe/enforce = 1
3. Audit & Outcome
✓ EXECUTION GRANTED
LSM Hook: ret = 0
Binary executed in userspace
Integrity: VERIFIED
Process alive
✕ BLOCKED (-EACCES)
LSM Hook: ret = -EACCES
type=1420 audit(ipe)
action=DENY res=0
Unauthorized exec prevented
Ready. Choose a scenario: Boot Verified Binary or /tmp Untrusted Script.
Step: 0/4