Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesiTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
NsJail is a Linux command-line utility that runs a program inside a restricted environment. It combines kernel isolation features (namespaces, cgroups, and seccomp-bpf syscall filters) with filesystem and resource limits that you configure. It is a useful layer of defense, but it is not a security guarantee on its own. How safe a given setup is depends on the policy you write, the kernel and distribution you run it on, and whether the restrictions you think are active actually are.
What NsJail is
NsJail is a process-isolation tool for Linux. You point it at a program, describe what that program may see and do, and it launches the program inside a sandbox that matches the description. The project is published on GitHub under the google/nsjail repository. Its README states plainly that “This is not an official Google product.” Treat it as a community-maintained utility that Google happens to host, not as a supported Google product.
NsJail is small enough to read and audit, which is one reason it appears in security-oriented projects. A 2020 assessment by Trail of Bits, prepared for the Freedom of the Press Foundation, recommended it partly for that simplicity and for its configuration examples. That assessment is discussed in detail below.
The isolation mechanisms it can apply
NsJail does not invent its own sandbox kernel. It drives features that Linux already provides and gives you a single configuration surface for them. The controls it documents are:
#1 Best Overall
- Linux namespaces, which give the process its own view of selected resources such as process IDs, mounts, network, users, and hostnames. Which namespaces are available depends on the host.
- Filesystem restrictions, including
chrootorpivot_root, read-only bind mounts, and tmpfs mounts. These control which files the process can read or write. - Resource limits on CPU time, memory, and process counts.
- cgroups for grouping and constraining resource use.
- seccomp-bpf filters, written in the Kafel policy language, which decide which system calls the process may make.
- Network options, including isolated network interfaces and userland networking through pasta.
These are controls that are available, not controls that switch on automatically. A minimal invocation may apply only a subset of them. Check your configuration to see exactly what is enforced.
Operating modes
NsJail’s README documents four modes. The mode decides how the sandbox is started and how long it lives.
| Mode | What it does | Typical use shown in project examples |
|---|---|---|
| LISTEN | Opens a TCP listener and forks a sandboxed process for each incoming connection | Network services |
| ONCE | Runs the target one time and exits | A one-time shell or single job |
| EXECVE | Executes the target directly, without a supervising process | Running a program under a fixed policy |
| RERUN | Executes the target repeatedly | Fuzzing, where the same target is run many times with different inputs |
Uses the project documents
The README and the Google-hosted examples describe several use cases. These are the project’s own examples. They show what the tool can be configured to do; they do not show that any particular configuration is safe for your workload.
Free tools Windows power users keep installed
One-click scans. No signup required.
- Hosting network services that should accept connections but run with limited privileges
- Hosting capture-the-flag (CTF) challenges, where each participant’s session must be contained
- Fuzzing targets in repeated runs
- Sandboxing desktop applications. The README includes example configurations for a Firefox setup and a document viewer.
- Running a program with a minimal filesystem that contains only what it needs
Whether a desktop application or service works under your restrictions depends on the files, devices, and system calls it uses. A configuration that works for one program may break another.
Building NsJail
The README describes building from source. The steps are:
- Install the build dependencies listed in the README for your distribution.
- Clone the
google/nsjailrepository from GitHub. - Change into the cloned directory and run
make. - Confirm the binary runs and review its options with
nsjail --help(or the path to the built binary, if you have not installed it into yourPATH). The flags shown by your build are the authoritative reference for your version.
Building is the easy part. The next step is deciding how you will supply configuration.
Configuration: command-line flags or protobuf files
NsJail accepts configuration in two ways, and the README documents both:
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →- Command-line flags are convenient for quick experiments and for one-off runs.
- Protobuf-based configuration files are better for policies you want to version, review, and reuse. Use these for anything you intend to run repeatedly.
The README’s examples cover selecting namespaces, setting user and group IDs and their mappings, arranging bind mounts and tmpfs, and writing seccomp policy. Copy these examples only as starting points. Each mount, user mapping, and syscall allowance has to match the program you are running and the machine you are running it on.
Host requirements and common failures
NsJail depends on what the host kernel and distribution provide. The README and the project’s troubleshooting guidance point to these areas:
- User namespaces. If unprivileged user namespaces are disabled on the host, setups that rely on them will fail. The fix is either to enable them (a host-level decision with its own security trade-offs) or to adjust the configuration.
- Mount setup. Errors in bind mounts, tmpfs, or
pivot_rootusually mean a path does not exist inside the new root, or a mount is not permitted in the current namespace. - Namespace availability. Some namespaces are not supported on every host. The README notes that you may need to disable a namespace when the host does not support it.
- Kernel-version dependencies. Some features depend on a minimum kernel version. Check the README’s notes against your kernel before you debug a policy.
Because these requirements vary by distribution and kernel, there is no single deployment recipe that works everywhere. Test on the same kernel and distribution you plan to use.
Is NsJail a secure sandbox?
NsJail is a configurable isolation tool. Its security outcome depends on what you configure and where you run it. Three points matter most.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minute- Mechanisms are not outcomes. Namespaces, filesystem restrictions, resource limits, and syscall filters only protect you as far as the policy blocks what matters. The documentation does not establish that any default or example configuration is sufficient for untrusted workloads.
- Sandboxing is defense in depth. The 2020 Trail of Bits assessment, SecureDrop Workstation Assessment (Appendix H), treats process isolation this way: as one layer alongside other controls, not as a replacement for them.
- Privilege setup matters. The same 2020 assessment, which examined the SecureDrop Workstation environment, identified a dependency on user namespaces and warned that NsJail was not designed to be launched safely as a setuid binary in the circumstances it reviewed. It discussed running as root or through a constrained wrapper in that environment. That was a single system, at a specific date. Do not read it as a current verdict on every distribution or deployment.
Adapting a policy before you rely on it
Before you trust a policy, work through these questions for the program you are sandboxing:
Best Value
- Which files, directories, and devices does it need to read, and which should it be unable to see?
- Which system calls does it need? Start from a deny-by-default seccomp policy and add only what is required.
- Does it need network access? If so, to which addresses and ports, and does it need an isolated interface or userland networking?
- Which privileges does it run with, and which user and group IDs should it map to?
- What is its normal resource profile for memory, CPU time, and process count? Set limits that are generous enough for normal use and tight enough to contain runaway behaviour.
- Does the policy behave the same way on the target kernel and distribution? Verify each restriction by checking that the forbidden action actually fails.
How NsJail compares with other isolation tools
The 2020 Trail of Bits assessment names Bubblewrap, Firejail, Docker, LXC, and gVisor as alternatives and discusses how their approaches differ. Its comparison was made for the SecureDrop Workstation environment at that time, so use it as a starting point rather than a current benchmark. When you compare tools yourself, use these axes:
- Process-level isolation versus a VM or application-kernel boundary
- Kernel attack surface and the privileges the tool requires
- Availability of namespaces and cgroups on your host
- How expressive the policy language is, and how much of it you must write yourself
- Filesystem and network needs of the program
- Configuration and maintenance effort over time
- Compatibility with the program and any performance cost
No performance or adoption figures are established for NsJail in the sources available for this article, so judge those axes by testing your own workload.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →

