E
Analyzed about 3 years ago
encapsulate provides its client process the same environment it's started in, except for some limitations:
encapsulate remounts the whole filesystem read-only, except for user-selectable regions which are mounted read-write. It also isolates the process from the system's process table, network interface, IPC, and shared memory tables.
127
lines of code
0
current contributors
over 7 years
since last commit
1
users on Open Hub