Skip to content
gc1dkPublic

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Latest commit

 

History

1 Commit

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 

Repository files navigation

ShellBox

!COMING SOON!

Run anything. Nothing leaks. Never lags your machine.

ShellBox is a from-scratch sandbox system for executing untrusted binaries—APKs, game mods, scripts, cracked tools—inside a closed, isolated container with a hard memory ceiling. Powered by the 1X8H engine and a fully handwritten native desktop interface.

Status: IN DEVELOPMENT — README published early. Code, engine, and UI land here as they are verified.


What makes ShellBox different

VirtualBox / full VMs Containers ShellBox
RAM floor ~512 MB–2 GB per VM low hard-capped, default 256 MB
Can freeze your host? yes yes (OOM) no — watchdog kills on breach
Setup heavy, drivers root/daemon single .exe
Isolation strong medium strong (job objects / cgroups / seccomp)

Non-negotiable memory rules

The sandbox never takes over the host. Enforced at four layers:

  1. Hard cap — Windows Job Object PROCESS_MEMORY limit / Linux cgroup v2 memory.max. The OS itself refuses over-allocation; no userspace polling can miss it.
  2. System reserve floor — engine reads total system RAM at startup; the host always keeps ≥ 1 GB or 15% (whichever is larger) outside sandbox reach.
  3. Watchdog — polls working set every 500 ms; breach or stall → immediate kill + telemetry event.
  4. Supervisor — if the watchdog dies, the parent process restarts it. There is no state where a sandbox runs unbounded.

Defaults: 256 MB RAM cap, 64 process limit, 1024 handle limit, 5% CPU rate, 30 s timeout, 100 MB workspace disk quota. All configurable per-run.

Failure modes handled

Failure Response
Memory breach (OOM attempt) Job/cgroup limit refuses allocation; watchdog kills; event logged
Hang / infinite loop Timeout kill; CPU rate limit keeps host responsive meanwhile
Fork bomb / process storm Process count limit (64 default); excess spawns denied
Handle / FD exhaustion Handle limit; sandbox terminated before host impact
Network escape attempts Kill-switch: WFP (Windows) / nftables (Linux); all egress denied by default
Disk fill Workspace quota; writes fail inside sandbox only
Sandbox binary crash Exit captured, workspace reset to clean snapshot, host unaffected
Watchdog crash Supervisor restarts it; no unbounded window
Privilege escalation attempt Deny; sandbox runs at lowest integrity / nobody
Partial launch failure Full rollback: handles, jobs, temp files released
Host under load already Engine detects free RAM; refuses launch below reserve floor

1X8H engine

The isolation engine, named 1X8H, written entirely from scratch:

  • No borrowed code. No QEMU, no VirtualBox SDK, no gVisor, no vendored libraries. Every line is original, MIT-licensed.
  • Platform backends: Windows Job Objects + WFP, Linux cgroups v2 + seccomp + namespaces, macOS sandbox-exec profile (roadmap).
  • Single purpose: keep untrusted code inside its box, at all times, on any machine.

Custom interface

A handwritten Win32 + DirectX 11 desktop application. Not Electron. Not Qt. Not ImGui. Not Python. Not a webview. Native window, native renderer, own widget code — from scratch.

Build

git clone https://github.com/gc1dk/ShellBox.git
cd ShellBox
cmake -B build -S .
cmake --build build --config Release

Requirements: MSVC 2022 / Clang 16 / GCC 11, CMake 3.16+, C++17.

Roadmap

Milestone State
README + LICENSE published done
1X8H engine core (Windows job objects, memory caps) in progress
Watchdog + supervisor loop planned
Network kill-switch (WFP / nftables) planned
Handwritten Win32 + DX11 interface planned
Linux backend (cgroups v2 + seccomp) planned
Telemetry / event log UI planned
macOS backend planned

License

MIT — Copyright (c) 2026 Gc.idk (gc1dk). See LICENSE.

From scratch. Hard-capped. Host always wins.

— Gc.idk (aka Gc1dk)

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors