expeditioneer@gentoo.org Dennis Lamm Firejail is a SUID program that reduces the risk of security breaches by restricting the running environment of untrusted applications using Linux namespaces and seccomp-bpf. It allows a process and all its descendants to have their own private view of the globally shared kernel resources, such as the network stack, process table, mount table. This is the regular version. For a long term support version see sys-apps/firejail-lts. cpe:/a:firejail_project:firejail netblue30/firejail Enable support for custom AppArmor profiles Enable chrooting to custom directory Install contrib scripts Enable file transfers between sandboxes and the host system Enable global config file Enable networking features Enable overlayfs Enable private home feature Enable system call filtering Enable attaching a new user namespace to a sandbox (--noroot option) Enable whitelist Enable X11 sandboxing