Judgement and contest platform with processes isolation
-
Updated
Dec 8, 2021 - Java
Judgement and contest platform with processes isolation
A v1 command execution sandbox in Zig with timeout control, output capture, and process handling.
EFFICIENT DOMAIN-LEVEL PROCESS ISOLATION ON AARCH64, Customized Linux Kernel
Execução isolada de tarefas Node.js em processos filhos descartáveis, com IPC estruturado, timeout, cancelamento, concorrência limitada e encerramento confirmado.
Hardened subprocess sandbox for AI agent tools. Enforces process-tree timeouts, 64KB middle-truncation, and path jailing.
Long-running worker runtime for Coretsia: supervised pools, process isolation, task sources, lifecycle control, and deterministic safety.
OS-level process confinement (Landlock + seccomp-bpf) for spawned command execution
Stop unapproved local AI workloads outside the sandbox with a Linux cgroup-v2 guard. No install: fork the repo and run the hosted containment probe.
Lightweight Linux container runtime in C with a supervisor, namespace isolation, kernel-level memory monitoring, and scheduling experiments.
Production-grade Electron multi-runtime RPC framework (utilityProcess + MessageChannelMain) with a built-in Debug Panel | 生产级 Electron 多进程 RPC 框架 + 调试面板
Low-level lightweight toolkit to build process-level isolation sandbox environment(s) in linux
Runtime security layer that observes, restricts, and analyzes command behavior using Landlock, Seccomp-BPF, and execution tracing.
Process sandbox for untrusted code - Linux namespaces, firejail, bubblewrap, watchdog timeout
Implementation of a secure, low-level application designed on CertiKOS formally verified operating system kernel. Simulation of an autonomous satellite critical susystems - environmental monitoring, task scheduling and watchdog diagnostics - within a trusted computing environment. Developed as part of my diploma thesis at the University of Patras.
🛡️ Windows filesystem sandbox for AI agents — intercepts ntdll syscalls and redirects writes into a copy-on-write overlay. Agents run git/node/python freely while the real disk stays untouched. Child-process injection, whiteout deletes, glob policy, nested-sandbox blocking.
A sub-millisecond C-based Serverless engine utilizing Linux kernel namespaces and synchronous IPC for zero-overhead, high-throughput function execution.
Per-capability process isolation: applies the limits carried in a capability token to a child process before it execs. Standalone crate extracted from NOESAR EVOLUTION.
能力越大,责任越大。请负责任地使用 BeeHive。 "像蜂群一样协作,像守卫一样警惕,像蜂后一样智慧。"
To associate your repository with the process-isolation topic, visit your repo's landing page and select "manage topics."