- nsjail
- firejail
- bubblewrap
- runc
etc.
- nsjail
- firejail
- bubblewrap
- runc
etc.
A cursory look at NSjail tells me its filesystem stuff is less granular than bwrap's bind mounting.
Firejail can't handle : in some paths (at all, no escaping provided) which made me dump it.
This doesn't match my experience. For example, the following works just fine in a profile file:
blacklist /sys/devices/pci0000:00/*
Can you give an example of what you had problems with?cf https://github.com/netblue30/firejail/issues/4614, https://github.com/netblue30/firejail/blob/master/src/fireja... and https://github.com/netblue30/firejail/blob/master/src/lib/co...
A parent comment mentions ebpf syscall interception, many end up combining gvisor and nsjail and seccomp.
Edit: funnily, chatgpt 03-mini tells me nsjail is the second hardest to use (first = systemd) of these...