google / nsjailLinks
A lightweight process isolation tool that utilizes Linux namespaces, cgroups, rlimits and seccomp-bpf syscall filters, leveraging the Kafel BPF language for enhanced security.
☆3,642Updated last week
Alternatives and similar repositories for nsjail
Users that are interested in nsjail are comparing it to the libraries listed below
Sorting:
- Low-level unprivileged sandboxing tool used by Flatpak and similar projects☆5,354Updated 5 months ago
- syzkaller is an unsupervised coverage-guided kernel fuzzer☆5,989Updated this week
- A foreign function interface for bash.☆2,153Updated 3 weeks ago
- Wrangling Untrusted File Formats Safely☆4,689Updated last month
- Linux system exploration and troubleshooting tool with first class support for containers☆8,171Updated last month
- A userspace out-of-memory killer☆2,009Updated this week
- Ignite a Firecracker microVM☆3,525Updated 2 years ago
- A fast and lightweight fully featured OCI runtime and C library for running containers☆3,722Updated last week
- Embeddable, replicated and fault-tolerant SQL engine.☆4,257Updated last month
- Fully static, unprivileged, self-contained, containers as executable binaries.☆2,520Updated 6 years ago
- Painless relocation of Linux binaries–and all of their dependencies–without containers.☆3,006Updated 2 years ago
- Content-Addressable Data Synchronization Tool☆1,559Updated 3 months ago
- A Virtual Machine Monitor for modern Cloud workloads. Features include CPU, memory and device hotplug, support for running Windows and Li…☆5,142Updated this week
- OSv, a new operating system for the cloud.☆4,215Updated 3 weeks ago
- Generate sandboxes for C/C++ libraries automatically☆1,722Updated 2 months ago
- unfork(2) is the inverse of fork(2). sort of.☆1,483Updated last year
- A kernel designed to run one and only one application in a virtualized environment☆3,037Updated last week
- The main libseccomp repository☆891Updated this week
- Record and Replay Framework☆10,320Updated last week
- Linux namespaces and seccomp-bpf sandbox☆6,917Updated this week
- Checkpoint/Restore tool☆3,586Updated this week
- like ~~grep~~ UBER, but for binaries☆1,758Updated last week
- The Unikernel & MicroVM Compilation and Deployment Platform☆2,791Updated 2 years ago
- firecracker-containerd enables containerd to manage containers as Firecracker microVMs☆2,617Updated last week
- Programmable debugger☆1,954Updated this week
- Checked C is an extension to C that lets programmers write C code with bounds checking and improved type-safety. The goal is to let peopl…☆3,258Updated last year
- Porting Windows Dynamic Link Libraries to Linux☆4,469Updated 9 months ago
- A dynamic library providing Virtualization-based process isolation capabilities☆1,485Updated this week
- Create microVMs from OCI images☆1,577Updated 3 months ago
- Security oriented software fuzzer. Supports evolutionary, feedback-driven fuzzing based on code coverage (SW and HW based)☆3,294Updated last week