Mbox is a lightweight sandboxing mechanism that any user can use without special privileges in commodity operating systems. For more details, see doc/NOTE.web or visit the website.
$ cd src
$ cp {.,}configsbox.h
$ ./configure
$ make
- src/tests-sbox : test codes
/sbox.{c,h} : system call hooks
/mbox.c : main
$ ./mbox -h : help
$ ./mbox ls : give it a shot
$ ./testall.sh : test all unit tests
$ ./mbox -s ls : run ls with seccomp/bpf (if supported)
$ ./mbox -i -- wget google.com : a simple use
$ ./mbox -n -i -- wget google.com : no network
is important to add --security-opt seccomp:unconfined for running mbox inside docker-container.
basic mbox docker:
docker run -it --security-opt seccomp:unconfined --rm cumi/mbox
advance: you could extends cumi/mbox in any project.
Content type
Image
Digest
Size
88.9 MB
Last updated
over 7 years ago
docker pull cumi/mbox