Linux Seccomp-BPF Syscall Sandbox Architecture Simulator
CONFIG_SECCOMP_FILTER=y
Safe Syscall (read/write)
Restricted Syscall (ptrace)
Hostile Syscall (reboot/unshare)
Mode: BPF Filter (2)
Next Step ⏭
Auto Play ▶
Reset ↺
Theme 🌓
Userspace Application
Safe Syscall
write(1, buf, len)
Standard I/O & computation
Restricted Call (Privilege)
ptrace(PTRACE_ATTACH, ...)
Dangerous introspection
High exploit abuse risk
Hostile Syscall
reboot(LINUX_REBOOT_MAGIC)
Kernel state mutation
Container breakout attempt
Kernel Seccomp Engine
SECCOMP_MODE_FILTER (seccomp.mode = 2)
__secure_computing()
Traps CPU syscall instruction
struct seccomp_data { nr, arch, args }
Executes attached cBPF filter
BPF Filter Policy Matrix
Rule 1: read/write/exit -> ALLOW
Rule 2: ptrace/reboot -> ERRNO(EPERM)
Rule 3: unshare/bpf -> KILL_PROCESS
Status: Sandbox filter active
Execution Outcome
SECCOMP_RET_ALLOW
sys_call_table[nr]() executed
Normal syscall path
Returns syscall result
SECCOMP_RET_ERRNO
Syscall handler bypassed
Return: -1 (errno: EPERM)
Attack surface neutralized
Process safely contained
Ready. Choose a scenario: Safe Syscall, Restricted Syscall, or Hostile Syscall.
Step: 0/4