Linux Yama LSM Ptrace Scope Restrictions Simulator
CONFIG_SECURITY_YAMA=y
Parent -> Child Trace
Sibling -> Sibling Attack
Admin (CAP_SYS_PTRACE)
Scope: 1 (Restricted Parent-Child)
Next Step ⏭
Auto Play ▶
Reset ↺
Theme 🌓
Tracer Process (UID 1000)
Target: Direct Child
GDB debug session
Parent spawned child process
Target: Sibling Process
SSH Agent / Browser
Same UID, separate parent
Credential extraction attack
Target: System Task
Admin / Strace tool
Holds CAP_SYS_PTRACE
Privileged system tracing
Kernel Yama LSM Engine
kernel.yama.ptrace_scope = 1 (Restricted)
security_ptrace_access_check()
Traps ptrace(PTRACE_ATTACH)
Evaluates lineage: parent_or_child?
Checks prctl(PR_SET_PTRACER)
Yama Ptrace Scopes
Scope 0: Classic DAC (Same-UID allowed)
Scope 1: Restricted (Parent-child only)
Scope 2: Admin only (CAP_SYS_PTRACE)
Status: Sibling ptrace blocked
Tracing Outcome
PTRACE GRANTED
Return: 0 (Success)
Target paused for debug
Normal GDB/tracing active
BLOCKED: -EPERM
ptrace() -> -1 (EPERM)
Lineage check failed
Sibling attack thwarted
Process memory protected
Ready. Choose a scenario: Parent -> Child Trace, Sibling Attack, or Admin.
Step: 0/4