TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Nsjail – A light-weight process isolation tool for Linux

87 点作者 LaFolle超过 7 年前

7 条评论

jeblair超过 7 年前
This seems very similar to Bubblewrap: <a href="https:&#x2F;&#x2F;github.com&#x2F;projectatomic&#x2F;bubblewrap" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;projectatomic&#x2F;bubblewrap</a>
评论 #15480857 未加载
woahhvicky超过 7 年前
How does this compare to firejail?
评论 #15478977 未加载
Bromskloss超过 7 年前
Is this what I should use if I want to intercept filesystem calls (and rewrite them, or generate on the fly the file that is about to be accessed)? Something else I should look into for this purpose?
评论 #15479561 未加载
评论 #15479554 未加载
therein超过 7 年前
Is there a minimum required kernel version? How does it compare to proot?<p>We use proot in our build pipeline and it would be interesting to look into alternatives.
评论 #15479772 未加载
评论 #15479997 未加载
TheDong超过 7 年前
This seems to be almost exactly like systemd-nspawn other than the ability to write seccomp policies in kafel.<p>Are there any other notable differences?
评论 #15482752 未加载
_Marak_超过 7 年前
I&#x27;ve been using nsjail in production with good success lately. It&#x27;s a solid tool.<p>Thank you authors! Really appreciate your work on this project.
andystanton超过 7 年前
I have become conditioned by seeing so many Javascript frameworks reach the front page over the years that I parsed this as &#x27;JsNail&#x27; on first glance.