Linux Kernel Lockdown LSM Interactive Simulator
CONFIG_SECURITY_LOCKDOWN_LSM=y
Safe Process
Integrity Tamper (/dev/mem)
Confidentiality Leak (/proc/kcore)
Mode: Confidentiality (2)
Next Step ⏭
Auto Play ▶
Reset ↺
Theme 🌓
Userspace / EUID=0
Standard User App
read() / write() / mmap()
Normal unprivileged task
Integrity Attack (Root)
open("/dev/mem", O_RDWR)
init_module(unsigned_ko)
Kernel text modification
Confidentiality Leak (Root)
open("/proc/kcore", O_RDONLY)
bpf(BPF_PROG_LOAD, kprobe)
Secret data extraction
Kernel Lockdown LSM
/sys/kernel/security/lockdown = [none] integrity [confidentiality]
security_locked_down()
Hook intercepts raw I/O & BPF
Checks reason & severity level:
LOCKDOWN_INTEGRITY_MAX
LOCKDOWN_CONFIDENTIALITY_MAX
Policy Decision Matrix
Level 0: None -> All permitted
Level 1: Integrity -> Block tampered writes
Level 2: Confidentiality -> Block reads & writes
Active Level: 2 (Confidentiality)
Enforcement Outcome
OPERATION GRANTED
Return: 0 (Success)
Normal syscall path
Execution completes safely
BLOCKED: -EPERM
Return: -1 (errno: EPERM)
dmesg notice logged:
"Lockdown: ... is restricted;"
"see man kernel_lockdown.7"
Ready. Choose a scenario: Safe Process, Integrity Tamper, or Confidentiality Leak.
Step: 0/4