Privilege-separated secure DHCPv4 client for Linux.
-
Updated
Jul 6, 2026 - C
Privilege-separated secure DHCPv4 client for Linux.
Dynamic loading with privilege separation
Avant-garde Network Application Server for illumos.
Kernel-enforced sandboxing for untrusted processes. Two zero-dependency core tools, one shared profile format, plus an optional BPF-LSM module.
Adds restrictive patterns to Crystal
Fast, kernel-enforced application sandbox for macOS and Linux. Default-deny TOML profiles, Seatbelt + Landlock + seccomp + namespaces under the hood. Pasta/slirp4netns auto-plumbed network with per-IP nftables.
Splits privileges between an unprivileged user account and a separate sysmaint account
Reliability control plane for scoped VPN, proxy and access-continuity paths — crash-consistent policy generations, privilege-separated stores, replay-proof action leases.
Human-approved sudo/root command broker for local AI agents
Splits privileges between an unprivileged user account and a separate sysmaint account
Two-stage security architecture to mitigate indirect prompt injection attacks in rich content via privilege separation
The Project work done at IITK
Keeps your Mac awake only while AI agents are working. Session-aware sleep management for Claude Code, OpenCode & long jobs; clamshell support, MIT.
MIT 6.858 Computer Systems Security (2022) labs on the zoobar app: buffer-overflow exploits, privilege separation, a Z3 symbolic-execution bug-finder, browser-security attacks, and the SecFS secure file system. Educational self-study.
Privilege-separated LLM agent — ring-fence the blast radius
Binário setuid root, escrito em Rust, que executa as operações privilegiadas do Selynt Panel em servidores DirectAdmin. Faz a mediação entre o painel e o sistema — ciclo de vida dos processos, isolamento, limites de recursos e integração com o servidor web — abandonando privilégio antes de qualquer lógica e respondendo em JSON.
Self-hosted deployment platform whose control panel never runs as root — privilege-separated Go daemon + typed schema-whitelisted executor, hash-chained audit log, no open ports.
Add a description, image, and links to the privilege-separation topic page so that developers can more easily learn about it.
To associate your repository with the privilege-separation topic, visit your repo's landing page and select "manage topics."