{"repo":"google/nsjail","free":true,"listed":false,"github":"https://github.com/google/nsjail","clone":"git clone https://github.com/google/nsjail.git","description":"A lightweight process isolation tool that utilizes Linux namespaces, cgroups, rlimits and seccomp-bpf syscall filters, leveraging the Kafel BPF language for enhanced security.","language":"C++","stars":4061,"topics":["security","linux-namespaces","linux","process-isolation","seccomp-bpf-policies","chroot"],"license":"Apache-2.0","category":"security-tools","readme_excerpt":"NsJail Linux process isolation tool using namespaces, resource limits, and seccomp-bpf syscall filters. Features - Multiple isolation modes : TCP listener (inetd-style), standalone single-run, continuous re-execution - Namespace isolation : UTS, MOUNT, PID, IPC, NET, USER, CGROUPS, TIME - Filesystem constraints : chroot() , pivot root() , read-only mounts, custom /proc and tmpfs - Resource limits : CPU time, memory, file descriptors, process count - Syscall filtering : Kafel seccomp-bpf policies - Network isolation : Cloned/isolated Ethernet interfaces, MACVLAN support, userland networking (pasta) - Cgroup integration : Memory, PID, CPU, net cls control (v1 and v2) - Configuration : Protobuf-based config files or command-line arguments Installation Build from source Docker Quick Start Basic isolated shell Network service (inetd-style) Re-running process (useful for fuzzing) Usage Execution Modes Flag Mode Description ------ ------ ------------- -Ml LISTEN TCP server, fork process per connection -Mo ONCE Execute once, exit -Me EXECVE Direct execution without supervisor -Mr RERUN Execute repeatedly (useful for fuzzing) Common Options Configuration Files NsJail uses Protocol Buffers for configuration. Schema: config.proto Example configuration Load with: Override command: Example Configs - bash-with-fake-geteuid.cfg : Bash with fake root UID - firefox-with-net-wayland.cfg : Sandboxed Firefox with networking - home-documents-with-xorg-no-net.cfg : Document viewer with X11, no net","default_branch":null,"files":null,"tree":[],"storefront":"/r/google","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/google/nsjail/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}