Linux Seccomp-BPF Syscall Sandbox Architecture Simulator
CONFIG_SECCOMP_FILTER=y
Userspace Application Safe Syscall write(1, buf, len) Standard I/O & computation Restricted Call (Privilege) ptrace(PTRACE_ATTACH, ...) Dangerous introspection High exploit abuse risk Hostile Syscall reboot(LINUX_REBOOT_MAGIC) Kernel state mutation Container breakout attempt Kernel Seccomp Engine SECCOMP_MODE_FILTER (seccomp.mode = 2) __secure_computing() Traps CPU syscall instruction struct seccomp_data { nr, arch, args } Executes attached cBPF filter BPF Filter Policy Matrix Rule 1: read/write/exit -> ALLOW Rule 2: ptrace/reboot -> ERRNO(EPERM) Rule 3: unshare/bpf -> KILL_PROCESS Status: Sandbox filter active Execution Outcome SECCOMP_RET_ALLOW sys_call_table[nr]() executed Normal syscall path Returns syscall result SECCOMP_RET_ERRNO Syscall handler bypassed Return: -1 (errno: EPERM) Attack surface neutralized Process safely contained
Ready. Choose a scenario: Safe Syscall, Restricted Syscall, or Hostile Syscall.
Step: 0/4