google / nsjailLinks
A lightweight process isolation tool that utilizes Linux namespaces, cgroups, rlimits and seccomp-bpf syscall filters, leveraging the Kafel BPF language for enhanced security.
☆3,551Updated 3 weeks ago
Alternatives and similar repositories for nsjail
Users that are interested in nsjail are comparing it to the libraries listed below
Sorting:
- Low-level unprivileged sandboxing tool used by Flatpak and similar projects☆4,972Updated 3 months ago
- Checkpoint/Restore tool☆3,469Updated this week
- Linux namespaces and seccomp-bpf sandbox☆6,745Updated last week
- Programmable debugger☆1,937Updated this week
- syzkaller is an unsupervised coverage-guided kernel fuzzer☆5,896Updated last week
- A userspace out-of-memory killer☆1,993Updated 2 weeks ago
- A Virtual Machine Monitor for modern Cloud workloads. Features include CPU, memory and device hotplug, support for running Windows and Li…☆4,942Updated this week
- Linux system exploration and troubleshooting tool with first class support for containers☆8,124Updated 8 months ago
- Painless relocation of Linux binaries–and all of their dependencies–without containers.☆3,001Updated 2 years ago
- Content-Addressable Data Synchronization Tool☆1,546Updated last month
- A foreign function interface for bash.☆2,148Updated last year
- Simple Linux seccomp rules without writing any code☆508Updated 4 months ago
- The main libseccomp repository☆880Updated last month
- Fully static, unprivileged, self-contained, containers as executable binaries.☆2,518Updated 6 years ago
- Application Kernel for Containers☆17,189Updated this week
- The Unikernel & MicroVM Compilation and Deployment Platform☆2,780Updated 2 years ago
- Ignite a Firecracker microVM☆3,522Updated last year
- Generate sandboxes for C/C++ libraries automatically☆1,715Updated 3 weeks ago
- Embeddable, replicated and fault-tolerant SQL engine.☆4,210Updated last week
- firecracker-containerd enables containerd to manage containers as Firecracker microVMs☆2,552Updated last week
- strace is a diagnostic, debugging and instructional userspace utility for Linux☆2,501Updated last week
- A kernel designed to run one and only one application in a virtualized environment☆3,001Updated 2 weeks ago
- High-level tracing language for Linux☆9,726Updated this week
- Fast trigram based code search☆1,736Updated last year
- Dynamic Tracing in Linux☆1,019Updated 2 months ago
- Record and Replay Framework☆10,205Updated last month
- Wrangling Untrusted File Formats Safely☆4,650Updated 3 months ago
- go-audit is an alternative to the auditd daemon that ships with many distros☆1,648Updated last week
- Checksec☆2,234Updated 2 months ago
- Interactively grep source code. Source for http://livegrep.com/☆2,149Updated 2 months ago