Seccomp-bpf policy compiler — Kafel DSL to BPF bytecode
Unprivileged Linux sandbox using namespaces, seccomp, and Landlock
Minimal no_std child-runtime helpers for pnut sandbox setup
CLI for pnut, an unprivileged Linux sandbox