giuseppe / easyseccomp
DSL language to write seccomp filters
☆36Updated 11 months ago
Alternatives and similar repositories for easyseccomp:
Users that are interested in easyseccomp are comparing it to the libraries listed below
- C-friendly API to make path resolution safer on Linux.☆88Updated this week
- A dynamic library bundling the guest payload consumed by libkrun☆86Updated this week
- A fair-share ratelimiter implemented as a BPF socket filter☆13Updated 2 years ago
- ☆38Updated 2 years ago
- Container Registry Synchronization made easy and fast☆12Updated 3 years ago
- OCI runtime for frankenlibc unikernel☆62Updated 7 months ago
- Library to work with linux namespaces in go☆35Updated last year
- a C library for accessing OCI runtime and image spec files☆55Updated last month
- calltop is a tracing tool. It provides a dynamic real-time view of system calls on Linux. It traces also python, java, php and ruby funct…☆27Updated 3 years ago
- RegisterMachine Go☆20Updated 7 years ago
- Sandboxing File System☆46Updated 5 years ago
- A tool to list and diagnose bpf programs. (Who watches the watchers..? :)☆95Updated 4 years ago
- agent for handling seccomp descriptors for container runtimes☆45Updated last year
- Detect compiler names and versions from ELF files☆25Updated 6 months ago
- Easier tracing of packets through iptables☆34Updated 2 weeks ago
- Source-code based coverage for eBPF programs actually running in the Linux kernel☆131Updated last month
- Kit for building Falco drivers: kernel modules or eBPF probes☆65Updated this week
- Container image converter aiming to minimize image size and speed up boot time dramatically with block-level de-dupliction and lazy-pull …☆20Updated 6 years ago
- Proof-of-Concept Linux kernel module to export kernel APIs over kernel device nodes☆25Updated 6 years ago
- Example BPF program with LSM hooks☆33Updated 4 years ago
- Discover Linux kernel namespaces in Go. Almost everywhere. Aware of various OCI container engines, even engines in containers.☆43Updated 3 weeks ago
- A user-mode network ("slirp") CNI plugin - container networking for unprivileged users☆18Updated 6 years ago
- [POC] Rootless Containers without `/etc/subuid` and `/etc/subgid`☆17Updated 4 years ago
- A daemon that manages SELinux policies on a filesystem☆37Updated last year
- Helps run tests in virtual machines☆122Updated last month
- LSM BPF module to block pwnkit (CVE-2021-4034) like exploits☆21Updated 3 years ago
- Simple project to demonstrate the loading of eBPF programs via florianl/go-tc.☆33Updated last week
- kdevops history tree - use new git tree☆46Updated 11 months ago
- A collection of ideas for new kernel features☆52Updated 5 months ago
- A Rust library for managing eBPF programs.☆117Updated last year