Linux 6.12 IPE (Integrity Policy Enforcement) LSM
1. Origin & Storage Layer Trusted Provenance Source: initramfs / dm-verity Path: /bin/lab_tool Property: boot_verified=TRUE Hash: Immutable signed Mutable Storage (Untrusted) Source: ext4 /tmp /home Path: /tmp/untrusted_payload Property: boot_verified=FALSE Threat: Local Priv-Esc / RCE 2. IPE LSM Policy Engine LSM Hook Interception security_bprm_check(bprm, op=EXECUTE) Active Policy (Lab_Hardened) DEFAULT action=DENY Rule 1: op=EXEC boot_verified=TRUE -> action=ALLOW Fallback: Untrusted -> DEFAULT DENY Kernel Enforcement Switch Mode: /sys/kernel/security/ipe/enforce = 1 3. Audit & Outcome ✓ EXECUTION GRANTED LSM Hook: ret = 0 Binary executed in userspace Integrity: VERIFIED Process alive ✕ BLOCKED (-EACCES) LSM Hook: ret = -EACCES type=1420 audit(ipe) action=DENY res=0 Unauthorized exec prevented
Ready. Choose a scenario: Boot Verified Binary or /tmp Untrusted Script.
Step: 0/4