Skip to content

kernel: lockdown at confidentiality and the BPF LSM - #80

Merged
aledbf merged 1 commit into
mainfrom
kernel/bpf-lsm-lockdown
Oct 1, 2026
Merged

aledbf merged 1 commit into
mainfrom
kernel/bpf-lsm-lockdown

Conversation

@aledbf

@aledbf aledbf commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

The guest kernel now runs lockdown (forced to confidentiality) and the BPF LSM, and no longer builds /dev/mem or /proc/kcore. Root in the guest can neither read nor rewrite the kernel, and a consumer can enforce policy with BPF LSM programs it loads before the tenant's init. This is the first step of spin's F2b ("the guest defends itself").

Changes

  • Config: SECURITY, SECURITYFS, SECURITY_NETWORK, SECURITY_PATH, BPF_LSM, SECURITY_LOCKDOWN_LSM(_EARLY), LOCK_DOWN_KERNEL_FORCE_CONFIDENTIALITY and LSM="lockdown,bpf" on; DEVMEM and PROC_KCORE off.
  • Build check: kernel/Dockerfile fails if olddefconfig drops any of these, or turns DEVMEM, PROC_KCORE, MODULES or KEXEC back on.
  • Guest test: task boot:lockdown boots a disposable guest and asserts lsm = lockdown,capability,bpf, [confidentiality], and that root cannot lower it. The logind check now shares its boot helper.
  • Measured with task boot:initcalls, 20 interleaved boots each against main's kernel: no cost distinguishable from noise (p50 196.3 vs 208.3 ms on a loaded host). The numbers are in kernel/README.md.
  • Visible change: systemd logs use of bpf to read kernel RAM is restricted at boot and carries on; logins are unaffected (task boot:logind passes).

This is a new machine: the kernel's content changes, so every existing checkpoint stops resuming.

🤖 Generated with Claude Code


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

The guest's root is not the kernel's. The kernel runs lockdown, forced to
confidentiality, and the BPF LSM, and builds neither /dev/mem nor
/proc/kcore: root can neither read nor rewrite the kernel, and a consumer
can enforce policy in the guest with BPF LSM programs it loads before the
tenant's init.

kernel/Dockerfile fails a build whose config lost any of it after
olddefconfig. `task boot:lockdown` asks a booted guest for its LSMs and
its lockdown level, and checks root cannot lower it. The logind check now
shares that test's boot.

No boot cost that can be told from noise (kernel/README.md).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@aledbf
aledbf force-pushed the kernel/bpf-lsm-lockdown branch from 268d762 to 477911d Compare October 1, 2026 15:40
@aledbf
aledbf merged commit 1400f6a into main Oct 1, 2026
3 checks passed
@aledbf
aledbf deleted the kernel/bpf-lsm-lockdown branch October 1, 2026 15:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant