Low-level unprivileged sandboxing tool used by Flatpak and similar projects
翻译 - 非特权沙箱工具
StemJail: Dynamic Role Compartmentalization
Simple desktop application sandboxing tool for GNU\Linux
Very experimental docker authorization plugin, disabling some trivial ways of gaining root via docker
A pure-Go implementation of fakeroot using Linux user namespaces.
Experiments with unshare
Kernel patches for non-init user namespace on FUSE filesystem
Runs commands in Linux containers with configurable levels of isolation.
Nesting containers with podman
A nix shell running in a (thin) container