Low-level unprivileged sandboxing tool used by Flatpak and similar projects
-
Updated
Sep 25, 2026 - C
Low-level unprivileged sandboxing tool used by Flatpak and similar projects
StemJail: Dynamic Role Compartmentalization
A pure-Go implementation of fakeroot using Linux user namespaces.
Simple desktop application sandboxing tool for GNU\Linux
Very experimental docker authorization plugin, disabling some trivial ways of gaining root via docker
Experiments with unshare
Limit SFTP access to a remote (Linux) system
Kernel patches for non-init user namespace on FUSE filesystem
Runs commands in Linux containers with configurable levels of isolation.
Nesting containers with podman
A nix shell running in a (thin) container
Real apt + dpkg that install Debian packages into ~/.local without root, built only on what Debian ships: user and mount namespaces, unprivileged overlayfs and systemd's user manager. Services run as sandboxed user units. Plain bash, no containers or helpers.
Droidspaces container kernel patches and flashable boot images for Xiaomi 17 (pudding, SM8850) on Android 17 / HyperOS 4.0.0.9-4.0.0.26 with the Android Common Kernel 6.12 GKI baseline
Low-level lightweight toolkit to build process-level isolation sandbox environment(s) in linux
Restricts unprivileged user namespaces to declared executables. A BPF LSM program on the kernel’s userns_create hook refuses a namespace to anything that has not been declared, so Flatpak and Bubblejail keep working on a system where namespaces are otherwise closed.
To associate your repository with the user-namespaces topic, visit your repo's landing page and select "manage topics."