|Albert S. dbdb35db37||2 months ago|
|README.md||7 months ago|
|qssb.h||2 months ago|
qssb.h is a simple header only library that provides an interface to sandbox applications. Using Seccomp and Linux Namespaces for that purpose requires some knowledge of annoying details which this library aims to abstract away as much as possible.
No release yet, API is unstable.
Systemcall filtering, restricting file system access, dropping privileges, isolating the application from the network, etc.
Kernel >=3.17 sys/capabilities.h header. Depending on your system, libcap might be needed for this.
You can thank a Debian-specific patch for that. In the future, the library may check against that. Execute echo 1 > /proc/sys/kernel/unprivileged_userns_clone to disable that patch for now.
To be written
Real world project: cgit sandboxed: https://git.quitesimple.org/cgitsb
Contributions are very welcome. Options: