A lightweight process isolation tool that utilizes Linux namespaces, cgroups, rlimits and seccomp-bpf syscall filters, leveraging the Kafel BPF language for enhanced security.
翻译 - 轻量级进程隔离工具,利用Linux名称空间和seccomp-bpf syscall过滤器(借助kafel bpf语言)
Go library for installing a seccomp BPF system call filter.
🔒 download, verify & run torbrowser in a sandbox
Merged to firejail; Find syscalls of executables for seccomp-bpf sandbox policies.