Privilege-separated secure DHCPv4 client for Linux.
-
Updated
Jul 6, 2026 - C
Privilege-separated secure DHCPv4 client for Linux.
Dynamic loading with privilege separation
Avant-garde Network Application Server for illumos.
Adds restrictive patterns to Crystal
Kernel-enforced sandboxing for untrusted processes. Two zero-dependency core tools, one shared profile format, plus an optional BPF-LSM module.
Fast, kernel-enforced application sandbox for macOS and Linux. Default-deny TOML profiles, Seatbelt + Landlock + seccomp + namespaces under the hood. Pasta/slirp4netns auto-plumbed network with per-IP nftables.
Reliability control plane for scoped VPN, proxy and access-continuity paths — crash-consistent policy generations, privilege-separated stores, replay-proof action leases.
Splits privileges between an unprivileged user account and a separate sysmaint account
Two-stage security architecture to mitigate indirect prompt injection attacks in rich content via privilege separation
The Project work done at IITK
MIT 6.858 Computer Systems Security (2022) labs on the zoobar app: buffer-overflow exploits, privilege separation, a Z3 symbolic-execution bug-finder, browser-security attacks, and the SecFS secure file system. Educational self-study.
Keeps your Mac awake only while AI agents are working. Session-aware sleep management for Claude Code, OpenCode & long jobs; clamshell support, MIT.
Self-hosted deployment platform whose control panel never runs as root — privilege-separated Go daemon + typed schema-whitelisted executor, hash-chained audit log, no open ports.
Splits privileges between an unprivileged user account and a separate sysmaint account
Privilege-separated LLM agent — ring-fence the blast radius
Add a description, image, and links to the privilege-separation topic page so that developers can more easily learn about it.
To associate your repository with the privilege-separation topic, visit your repo's landing page and select "manage topics."