Automic VaultAutomic Vault

brew

Installer jailkit avec Homebrew, apt, MacPorts

Consultez les chemins d'installation, exécutables, métadonnées et notes de sécurité de jailkit pour les workflows d'agents IA.

installation

Commandes d'installation supplémentaires

macOS

Homebrewvérifié · 100%
brew install jailkit

local Homebrew formula metadata

MacPortsvérifié · 94%
sudo port install jailkit

MacPorts ports tree · security/jailkit/Portfile · Source: api.github.com

Linux

Debian aptvérifié · 92%
sudo apt install jailkit

Debian stable package indexes · jailkit · Source: deb.debian.org

aperçu

Résumé du paquet

Utilities to create limited user accounts in a chroot jail

Commandes et alias

  • jk_check
  • jk_chrootlaunch
  • jk_chrootsh
  • jk_cp
  • jk_init
  • jk_jailuser
  • jk_list
  • jk_lsh
  • jk_socketd
  • jk_uchroot
  • jk_update

historique

Historique du projet et usages

Jailkit is a Unix security toolkit for creating and maintaining chroot jails for users, shells, and daemons. It is an older, conservative package whose value is automation around a risky primitive: `chroot`.

Historique du projet

The project page and man page credit Olivier Sessink and carry copyright years beginning in 2003. Jailkit was built to automate repeated chroot setup tasks, including copying binaries and libraries into a jail, limiting commands through a restricted shell, checking jail integrity, and forwarding logs from inside a jail.

The project has stayed intentionally narrow. The homepage emphasizes stable, security-focused behavior: utilities abort when configuration or environment checks are not secure, and syslog messages explain what failed. Maintenance releases in 2019 and 2021 focused on Python 3 compatibility, `jk_update`, `jk_init`, and man-page cleanup rather than broad feature expansion.

Historique d'adoption

The homepage states that Jailkit is used in network security appliances, large enterprise and ISP internet servers, smaller companies, and private deployments for securing CVS, SFTP, shell, and daemon processes. Homebrew API data available during this enrichment recorded 142 installs over 365 days, which matches a specialized system-administration tool with long tail usage.

Modes d'utilisation

Administrators use Jailkit to initialize a jail, copy only the commands and libraries needed for a task, move users into the jail, restrict allowed commands through `jk_lsh`, and check common jail security mistakes with `jk_check`. The man page stresses that writable system directories, setuid programs, and root privileges inside a jail can defeat the intended isolation.

Pourquoi les passionnés de paquets s'y intéressent

Jailkit matters to package nerds because it packages institutional Unix hardening lore into named commands: `jk_init`, `jk_cp`, `jk_chrootsh`, `jk_lsh`, `jk_jailuser`, `jk_check`, and friends. It is not glamorous, but it turns chroot from a hand-built directory-tree ritual into repeatable system administration.

Chronologie

  • 2003: Project copyright and man-page history begin under Olivier Sessink.
  • 2019: Jailkit 2.21 added full Python 3 compatibility and removed the long-deprecated `jk_addjailuser` utility.
  • 2021: Jailkit 2.22 fixed Python 3 compatibility in `jk_update` and improved `jk_init.ini` defaults.
  • 2021: Jailkit 2.23 fixed `jk_init` edge cases and cleaned up man-page locations.
  • 2026: The project page documented non-exposure to CVE-2026-23268/CVE-2026-23269 because Jailkit exits when required system calls fail or are not permitted.

Related projects

  • Jailkit is related to the Unix `chroot(2)` facility, OpenSSH restricted SFTP setups, limited shells, rsync/scp/CVS jail deployments, and OS-level isolation mechanisms. Unlike containers, its focus is small, explicit filesystem jails for accounts and daemons.

posture de sécurité

Niveau de risque : vert

narrow executable package without higher-risk signals.

Classificateur de risque

risque vert · confiance faible · appliance

Pourquoi

  • narrow executable package without higher-risk signals

Signaux

  • metadata:no-higher-risk-signals

Comportement d'installation

  • Aucun hook post-install Homebrew n’est enregistré dans les métadonnées de formule.
  • Les métadonnées de bottle Homebrew sont disponibles pour 6 plateformes.
  • S’installe avec 1 dépendances d’exécution.

Revue recommandée

Avant une utilisation sans surveillance par un agent, vérifiez si l'outil lit des identifiants en clair, écrit un état distant, publie des artefacts ou lance des plugins.

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
/etc/jailkit/JAIL/etc/jailkit/

exécutables

Exécutables installés

CommandeTypeExpositionNote
jk_checkcliexécutable global
jk_chrootlaunchcliexécutable global
jk_chrootshcliexécutable global
jk_cpcliexécutable global
jk_initcliexécutable global
jk_jailusercliexécutable global
jk_listcliexécutable global
jk_lshcliexécutable global
jk_socketdcliexécutable global
jk_uchrootcliexécutable global
jk_updatecliexécutable global

fraîcheur

Version et fraîcheur

Ces signaux séparent l'âge de génération de la page, l'activité du gestionnaire de paquets et la comparaison avec les versions amont. Un retard de version n'est signalé que lorsqu'une URL de preuve et des versions comparables sont présentes.

page générée2026-07-26
version du gestionnaire2.23
gestionnaire mis à jour
données localesOK
amontnot checked
dernière version détectéenon détecté

https://olivier.sessink.nl/jailkit/

  • infoNo package-manager update timestamp was available.confiance faible
  • infoRelease/tag comparison is only available for GitHub repositories.https://olivier.sessink.nl/jailkit/confiance none

métadonnées d'installation

Métadonnées du paquet

Clé du paquetbrew:jailkit
Version2.23
Gestionnaire de paquetsHomebrew
Page du gestionnaire de paquetshttps://formulae.brew.sh/formula/jailkit
Page d'accueilhttps://olivier.sessink.nl/jailkit/
Dépôthttps://cvs.savannah.nongnu.org/viewvc/jailkit
Docs amonthttps://olivier.sessink.nl/jailkit
LicenceBSD-3-Clause AND LGPL-2.0-or-later
Archive sourcehttps://olivier.sessink.nl/jailkit/jailkit-2.23.tar.bz2
Dépendancespython@3.14
Bouteilledisponible (sur arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
post-install Homebrewnon défini
Serviceaucun déclaré

faits du registre

Détails de la base source

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namejailkit
Version Scheme0
Revision1
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • stable

correspondances dans les bases sources

Autres enregistrements de gestionnaires de paquets

Les correspondances proviennent d’index externes de gestionnaires de paquets et restent séparées des liens de paquets Automic Vault locaux.

Debian apt95%

jailkit 2.23-2+b1

tools to generate chroot jails easily

https://olivier.sessink.nl/jailkit/

sudo apt install jailkit
  • Section: utils
  • Architecture: amd64
  • Source Package: jailkit
  • 2 Dépendances
  • normalized package name match
  • Correspondance par : Jailkit
Debian stable package indexes · deb.debian.org · Debian stable package indexes: jailkit from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz
Ubuntu apt95%

jailkit 2.23-2

tools to generate chroot jails easily

https://olivier.sessink.nl/jailkit/

sudo apt install jailkit
  • Section: universe/utils
  • Architecture: amd64
  • 2 Dépendances
  • normalized package name match
  • Correspondance par : Jailkit
Ubuntu 24.04 LTS package indexes · archive.ubuntu.com · Ubuntu 24.04 LTS package indexes: jailkit from https://archive.ubuntu.com/ubuntu/dists/noble/universe/binary-amd64/Packages.gz
MacPorts95%

jailkit

sudo port install jailkit
  • normalized package name match
  • Correspondance par : Jailkit
MacPorts ports tree · api.github.com · MacPorts ports tree: security/jailkit/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1

piste source

Généré depuis les données du dépôt

Cette page est servie par av-web depuis l'artéfact SQLite privé des paquets généré par scripts/generate-pkg-sqlite.py.

Sources utilisées

  • Geiger risk classifier
  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated configuration and credential file locations
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment