Nuk4sd Sandbox Vault System
Nuk4sd Sandbox Vault System HPPeterSteve / nuk4sd Public Notifications You must be signed in to change notification settings Fork 1 Star 2 Branches Tags Open more actions menu Latest commit History 54 Commits 54 Commits Folders and files Name Name Last commit message Last commit date assets assets c_src c_src debian debian runtime runtime rust rust .clang-format .clang-format .editorconfig .editorconfig .gitignore .gitignore Cargo.toml Cargo.toml FLAGS_CHEATSHEET.md FLAGS_CHEATSHEET.md LICENSE LICENSE PKGBUILD PKGBUILD README.md README.md RELEASE_NOTES.md RELEASE_NOTES.md build.rs build.rs build_deb.ps1 build_deb.ps1 build_deb.sh build_deb.sh nuk4sd.install nuk4sd.install rustfmt.toml rustfmt.toml Repository files navigation Nuk4sd Nuk4sd is a Linux process isolation and encrypted vault management tool written in C and Rust. It relies on Linux kernel primitives—including user namespaces, mount namespaces, Seccomp-BPF filters, Landlock LSM rules, and FUSE filesystems—to run target processes in restricted environments and handle password-protected file storage.
This ProductLaunch is relevant to the technology intelligence record because it involves Meta. The source article should remain the factual reference for follow-up coverage.
- HPPeterSteve / nuk4sd Public Notifications You must be signed in to change notification settings Fork 1 Star 2 Branches Tags Open more actions menu Latest commit History 54 Commits 54 Commits Folders and files Name Name Last commit message Last commit date assets assets c_src c_src debian debian runtime runtime rust rust .clang-format .clang-format .editorconfig .editorconfig .gitignore .gitignore Cargo.toml Cargo.toml FLAGS_CHEATSHEET.md FLAGS_CHEATSHEET.md LICENSE LICENSE PKGBUILD PKGBUILD README.md README.md RELEASE_NOTES.md RELEASE_NOTES.md build.rs build.rs build_deb.ps1 build_deb.ps1 build_deb.sh build_deb.sh nuk4sd.install nuk4sd.install rustfmt.toml rustfmt.toml Repository files navigation Nuk4sd Nuk4sd is a Linux process isolation and encrypted vault management tool written in C and Rust.
- It relies on Linux kernel primitives—including user namespaces, mount namespaces, Seccomp-BPF filters, Landlock LSM rules, and FUSE filesystems—to run target processes in restricted environments and handle password-protected file storage.
- Architecture The project is structured into two main operational components: process sandboxing and encrypted vault management.
- Sandbox Component (C Core) Namespaces : Isolates user ( CLONE_NEWUSER ), mount ( CLONE_NEWNS ), PID ( CLONE_NEWPID ), network ( CLONE_NEWNET ), IPC ( CLONE_NEWIPC ), and UTS ( CLONE_NEWUTS ) namespaces.
- Syscall Filtering : Implements Seccomp-BPF filters with standard and strict allowlist profiles to restrict available system calls.
- Access Control : Enforces Landlock LSM rules for path-level filesystem access restriction.