kernel: lockdown at confidentiality and the BPF LSM - #80
Merged
Merged
Conversation
The guest's root is not the kernel's. The kernel runs lockdown, forced to confidentiality, and the BPF LSM, and builds neither /dev/mem nor /proc/kcore: root can neither read nor rewrite the kernel, and a consumer can enforce policy in the guest with BPF LSM programs it loads before the tenant's init. kernel/Dockerfile fails a build whose config lost any of it after olddefconfig. `task boot:lockdown` asks a booted guest for its LSMs and its lockdown level, and checks root cannot lower it. The logind check now shares that test's boot. No boot cost that can be told from noise (kernel/README.md). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
aledbf
force-pushed
the
kernel/bpf-lsm-lockdown
branch
from
October 1, 2026 15:40
268d762 to
477911d
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The guest kernel now runs
lockdown(forced to confidentiality) and the BPF LSM, and no longer builds/dev/memor/proc/kcore. Root in the guest can neither read nor rewrite the kernel, and a consumer can enforce policy with BPF LSM programs it loads before the tenant's init. This is the first step of spin's F2b ("the guest defends itself").Changes
SECURITY,SECURITYFS,SECURITY_NETWORK,SECURITY_PATH,BPF_LSM,SECURITY_LOCKDOWN_LSM(_EARLY),LOCK_DOWN_KERNEL_FORCE_CONFIDENTIALITYandLSM="lockdown,bpf"on;DEVMEMandPROC_KCOREoff.kernel/Dockerfilefails if olddefconfig drops any of these, or turnsDEVMEM,PROC_KCORE,MODULESorKEXECback on.task boot:lockdownboots a disposable guest and assertslsm = lockdown,capability,bpf,[confidentiality], and that root cannot lower it. The logind check now shares its boot helper.task boot:initcalls, 20 interleaved boots each against main's kernel: no cost distinguishable from noise (p50 196.3 vs 208.3 ms on a loaded host). The numbers are inkernel/README.md.use of bpf to read kernel RAM is restrictedat boot and carries on; logins are unaffected (task boot:logindpasses).This is a new machine: the kernel's content changes, so every existing checkpoint stops resuming.
🤖 Generated with Claude Code
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.