finds.dev← search

// the find

gen0sec/jailer

★ 59 · C · Apache-2.0 · updated Sep 2026

Jailer is an eBPF-based process jailing system that provides mandatory access control (MAC) for Linux. It tracks processes using BPF task_storage maps and enforces role-based policies on file access, network operations, and process execution.

An eBPF/BPF-LSM sandboxing daemon for Linux that enforces per-process file, network, and exec policies using task_storage maps, explicitly modeled on Meta's internal jailing system. Aimed at people who want container-adjacent process confinement without namespaces or seccomp, e.g. locking down AI agent processes or web workers to specific ports and paths.

It hooks the right LSM points (task_alloc, file_open, socket_bind/connect, bprm_check_security) and propagates jail state through task_storage on fork/exec, which is the correct way to do inheritance rather than re-checking a PID table on every syscall. It ships four enrollment mechanisms (socket, exec-by-inode, cgroup, xattr), which matters in practice since you often can't modify the target binary to opt it in. The daemonless bootstrap mode pinning programs to bpffs and exiting is a legitimate attack-surface reduction over a persistent daemon holding CAP_BPF. It also ships actual attacker-side test scripts (reverse shell, SSRF, priv-esc) that demonstrate enforcement rather than just asserting it works.

The README states outright it's not production-ready and the policy format can change without notice, so anyone building on it now is signing up for churn. Signed-binary validation is listed as a feature but is a stub, which is a real gap for anything claiming MAC guarantees. Path matching relies on dentry-walking with 'cache invalidation' and no discussion of the race window between check and use, and TOCTOU is historically where LSM path-based controls fall apart. It's also a very young project (59 stars, 3 forks, single maintainer group) with no mention of fuzzing the BPF verifier-facing code paths, so kernel version compatibility and crash resilience are unproven outside their own test matrix.

View on GitHub → Homepage ↗

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →