Linux Kernel Lockdown LSM Interactive Simulator
CONFIG_SECURITY_LOCKDOWN_LSM=y
Userspace / EUID=0 Standard User App read() / write() / mmap() Normal unprivileged task Integrity Attack (Root) open("/dev/mem", O_RDWR) init_module(unsigned_ko) Kernel text modification Confidentiality Leak (Root) open("/proc/kcore", O_RDONLY) bpf(BPF_PROG_LOAD, kprobe) Secret data extraction Kernel Lockdown LSM /sys/kernel/security/lockdown = [none] integrity [confidentiality] security_locked_down() Hook intercepts raw I/O & BPF Checks reason & severity level: LOCKDOWN_INTEGRITY_MAX LOCKDOWN_CONFIDENTIALITY_MAX Policy Decision Matrix Level 0: None -> All permitted Level 1: Integrity -> Block tampered writes Level 2: Confidentiality -> Block reads & writes Active Level: 2 (Confidentiality) Enforcement Outcome OPERATION GRANTED Return: 0 (Success) Normal syscall path Execution completes safely BLOCKED: -EPERM Return: -1 (errno: EPERM) dmesg notice logged: "Lockdown: ... is restricted;" "see man kernel_lockdown.7"
Ready. Choose a scenario: Safe Process, Integrity Tamper, or Confidentiality Leak.
Step: 0/4