This is a public archive. The code now lives in the mono-repo: https://github.com/rust-vmm/rust-vmm/
-
Updated
Aug 18, 2026 - Rust
This is a public archive. The code now lives in the mono-repo: https://github.com/rust-vmm/rust-vmm/
Composable agent runtime with enforced isolation boundaries
DSL language to write seccomp filters
Generate VM's with kernel tracing, code sandboxing and security profiles for long running agents.
A lightweight process isolation tool, requiring absolutely no privileges to run
force-bind with seccomp-bpf notifications
A survey and analysis of source code sandboxing
Arbor — The Agentic RL Sandbox. Checkpoint-native. Branch-safe. Self-hosted.
Seccomp-based proxy leak detector and proxifier.
Go library to reduce privileges on Linux by syscall groups through seccomp-bpf.
Lightweight, secure, single-file HTTP/HTTPS proxy in C with zero dependencies
Automated Approach for Generation of Seccomp System Call Filters
A Golang-based syscall interception tool using Seccomp Notify as an alternative to ptrace
BSc thesis on Linux kernel sandboxing with Landlock & seccomp
Paranoid level sandboxing
Simple demonstration of tracing processes in Go using ptrace and seccomp
To associate your repository with the seccomp-bpf topic, visit your repo's landing page and select "manage topics."