Firejail is a SUID program that reduces the risk of security breaches by restricting the running environment of untrusted applications using Linux namespaces and seccomp-bpf. It allows a process and all its descendants to have their own private view of the globally shared kernel resources, such as the network stack, process table, mount table.

Written in C with virtually no dependencies, the software runs on any Linux computer with a 3.x kernel version or newer. The sandbox is lightweight, the overhead is low. There are no complicated configuration files to edit, no socket connections open, no daemons running in the background. All security features are implemented directly in Linux kernel and available on any Linux computer.

Firejail can sandbox any type of processes: servers, graphical applications, and even user login sessions. The software includes security profiles for a large number of Linux programs: Mozilla Firefox, Chromium, VLC, Transmission etc.

Features

  • Linux namespaces
  • Filesystem container: local filesystem, chroot filesystem, overlay filesystem
  • Four security filters: seccomp, protocol, noroot user namespace, Linux capabilities
  • Custom security profiles
  • Resource allocation: Linux control groups and rlimits
  • Networking support
  • Statistics and monitoring
  • Graphical user interface

Project Samples

Project Activity

See All Activity >

Follow firejail

firejail Web Site

You Might Also Like
Employee monitoring software with screenshots Icon
Employee monitoring software with screenshots

Clear visibility and insights into how employees work. Even remotely.

Stay productive working at any distance from anywhere with Monitask.
Rate This Project
Login To Rate This Project

User Ratings

★★★★★
★★★★
★★★
★★
2
0
0
0
0
ease 1 of 5 2 of 5 3 of 5 4 of 5 5 of 5 5 / 5
features 1 of 5 2 of 5 3 of 5 4 of 5 5 of 5 5 / 5
design 1 of 5 2 of 5 3 of 5 4 of 5 5 of 5 5 / 5
support 1 of 5 2 of 5 3 of 5 4 of 5 5 of 5 5 / 5

User Reviews

  • Excellent! Many thanks.
  • Many thanks to the developer for this great utility!! Since I've been using Sandboxie for windows long ago, I've been eagerly waiting for a similar online protection tool for linux, and finally firejail made that break. It's been sometime using this great lightweight tool and it works great. Appreciated are the regular updates and features as well. I use Linux Mint, so I'm hoping that it'll be integrated in the future releases of mainstream linux soon. Either way firejail rocks, feature rich and solid !!
Read more reviews >

Additional Project Details

Registered

2014-02-28