awesome-repositories.com
المدونة
awesome-repositories.com

اكتشف أفضل مستودعات المصادر المفتوحة باستخدام بحث مدعوم بالذكاء الاصطناعي.

استكشفعمليات بحث منسقةبدائل مفتوحة المصدربرمجيات ذاتية الاستضافةالمدونةخريطة الموقع
المشروعحولكيفية ترتيب النتائجالصحافةخادم MCP
قانونيالخصوصيةالشروط
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
projectatomic avatar

projectatomic/bubblewrap

0
View on GitHub↗
7,731 نجوم·356 تفرعات·C·2 مشاهدات

Bubblewrap

Bubblewrap هو أداة تنفيذ في بيئة معزولة (sandbox) غير مميزة لنظام Linux تعزل العمليات عن النظام المضيف. ينشئ بيئات آمنة من خلال الاستفادة من مساحات أسماء Linux لفصل موارد النظام، بما في ذلك الشبكة، وPID، ومكدسات IPC.

يتميز المشروع بتمكين تنفيذ البرمجيات غير الموثوقة دون الحاجة إلى امتيازات الجذر (root) على الجهاز المضيف. يمنع تصعيد الامتيازات عن طريق تعطيل تنفيذ ثنائيات setuid ويستخدم تعيين هوية المستخدم لعزل أذونات العملية عن نظام التشغيل المضيف.

تدير الأداة سطح أمان شاملاً يتضمن التحكم في الوصول إلى نظام الملفات لتقييد رؤية الدليل وأذونات القراءة فقط. كما يقلل من سطح هجوم النواة من خلال تصفية استدعاءات النظام seccomp.

Features

  • Linux Sandboxes - Creates isolated execution environments using Linux kernel primitives to restrict resource access and system visibility.
  • Mount-Namespace Virtualization - Provides a restricted filesystem view by isolating mount points and enforcing read-only permissions.
  • Container User Identity Mapping - Translates internal sandbox user identities to host identities to isolate process permissions from the host system.
  • Unprivileged Container Execution - Enables the execution of applications in isolated environments without requiring root privileges on the host machine.
  • Process Isolation - Restricts process access to system resources by creating private network, PID, and IPC instances.
  • Namespace-Based Isolation - Implements isolated environments using Linux kernel namespaces to separate network, PID, and IPC stacks from the host.
  • Process User Isolation - Redefines user and group identities to isolate process permissions from the host operating system.
  • Isolated Execution Sandboxes - Executes processes in a secure, unprivileged environment using Linux namespaces for isolation.
  • System Call Surface Minimizers - Reduces the kernel attack surface by restricting the available host system call interface using seccomp.
  • Privilege Escalation Prevention - Prevents privilege escalation by blocking the execution of setuid binaries within the sandboxed environment.
  • Read-Only Filesystem Enforcement - Enforces read-only access and restricts visibility of host directories within the secure execution environment.
  • System Call Filter Analysis - Limits the specific kernel syscalls a process can execute by applying seccomp filters.
  • Seccomp Profiles - Applies seccomp filter profiles to restrict the set of kernel system calls a process can execute.
  • Sandboxing and Isolation - Sandboxing tool using namespaces without requiring root.

سجل النجوم

مخطط تاريخ النجوم لـ projectatomic/bubblewrapمخطط تاريخ النجوم لـ projectatomic/bubblewrap

بحث بالذكاء الاصطناعي

استكشف المزيد من المستودعات الرائعة

صف ما تحتاجه بلغة بسيطة — وسيقوم الذكاء الاصطناعي بترتيب آلاف المشاريع مفتوحة المصدر المنسقة حسب الصلة.

Start searching with AI

بدائل مفتوحة المصدر لـ Bubblewrap

مشاريع مفتوحة المصدر مشابهة، مرتبة حسب عدد الميزات المشتركة مع Bubblewrap.
  • netblue30/firejailالصورة الرمزية لـ netblue30

    netblue30/firejail

    7,069عرض على GitHub↗

    Firejail is a Linux application sandbox and kernel security wrapper that isolates untrusted applications from the host system. It uses kernel namespaces and seccomp filters to restrict filesystem access, drop kernel capabilities, and limit the system attack surface. The project is distinguished by its use of predefined security profiles to automatically apply filesystem restrictions and syscall limits based on the executable being launched. It provides specialized isolation for portable packages such as AppImages and implements X11 display isolation via proxy servers to prevent keyboard loggi

    C
    عرض على GitHub↗7,069
  • containers/bubblewrapالصورة الرمزية لـ containers

    containers/bubblewrap

    5,839عرض على GitHub↗

    Bubblewrap is a Linux sandbox runner that creates lightweight, isolated execution environments for running untrusted applications. It combines Linux user, mount, network, PID, and UTS namespaces with seccomp-BPF system call filtering to restrict filesystem, network, process, and inter-process communication access. The project provides comprehensive process isolation by giving each sandbox its own private tmpfs root with selective bind-mounts, a separate network stack containing only a loopback interface, an independent process ID space, and remapped user and group identifiers. It applies secc

    Clinux-containersuser-namespaces
    عرض على GitHub↗5,839
  • ioi/isolateالصورة الرمزية لـ ioi

    ioi/isolate

    1,441عرض على GitHub↗

    Isolate is a low-level sandbox designed to execute untrusted programs within a strictly controlled environment. It functions as a process isolation engine that prevents potentially harmful code from interacting with or damaging the host operating system. The tool leverages Linux kernel primitives, including namespaces and control groups, to partition system resources and enforce hardware usage boundaries. By applying filesystem virtualization and system call filtering, it restricts the visibility and interaction of a process with the host, ensuring that untrusted applications operate only wit

    C
    عرض على GitHub↗1,441
  • youki-dev/youkiالصورة الرمزية لـ youki-dev

    youki-dev/youki

    7,452عرض على GitHub↗

    Youki is a low-level container runtime written in Rust that creates and manages isolated containers according to Open Container Initiative specifications. It serves as an execution engine that can function as a rootless container manager or a pluggable Kubernetes CRI runtime to manage pods and containers within a cluster. The project distinguishes itself by providing a Wasm container runtime capable of executing WebAssembly modules as isolated workloads compatible with standard orchestration tools. It further supports a rootless execution model, allowing isolated environments to start as non-

    Rustcontainersdockerkubernetes
    عرض على GitHub↗7,452
عرض جميع البدائل الـ 30 لـ Bubblewrap→

الأسئلة الشائعة

ما هي وظيفة projectatomic/bubblewrap؟

Bubblewrap هو أداة تنفيذ في بيئة معزولة (sandbox) غير مميزة لنظام Linux تعزل العمليات عن النظام المضيف. ينشئ بيئات آمنة من خلال الاستفادة من مساحات أسماء Linux لفصل موارد النظام، بما في ذلك الشبكة، وPID، ومكدسات IPC.

ما هي الميزات الرئيسية لـ projectatomic/bubblewrap؟

الميزات الرئيسية لـ projectatomic/bubblewrap هي: Linux Sandboxes, Mount-Namespace Virtualization, Container User Identity Mapping, Unprivileged Container Execution, Process Isolation, Namespace-Based Isolation, Process User Isolation, Isolated Execution Sandboxes.

ما هي البدائل مفتوحة المصدر لـ projectatomic/bubblewrap؟

تشمل البدائل مفتوحة المصدر لـ projectatomic/bubblewrap: netblue30/firejail — Firejail is a Linux application sandbox and kernel security wrapper that isolates untrusted applications from the host… containers/bubblewrap — Bubblewrap is a Linux sandbox runner that creates lightweight, isolated execution environments for running untrusted… ioi/isolate — Isolate is a low-level sandbox designed to execute untrusted programs within a strictly controlled environment. It… youki-dev/youki — Youki is a low-level container runtime written in Rust that creates and manages isolated containers according to Open… flatpak/flatpak — Flatpak is a sandboxed application framework and standardized packaging format for Linux desktop applications. It… mviereck/x11docker — x11docker is an OCI container GUI orchestrator and hardware bridge designed to execute graphical applications and full…