Unprivileged sandboxing tool for isolating Linux processes
Unprivileged sandboxing tool for Linux
bwrap$ bwrap --ro-bind / / --tmpfs /tmp /bin/bash$ bwrap --bind /home/user /home/user --tmpfs /tmp /bin/sh$ bwrap --unshare-net --ro-bind / / /usr/bin/wget https://example.com