I use modulejail. I like it. I think it fills a void in system security, especially in the current climate.
However, I would never, ever, recommend it be included in any distroâs repos. Remember, inclusion in a repo implies that the distro both trusts the application, and is willing to support it. Itâs the support area where the problem lies.
Remember that modulejail blacklists all modules that are not currently in use when it is run.
I have a laptop old enough to have a built-in DVD-RW. I use it mostly for testing, but also occasionally to rip CDs. Recently when I tried to rip a new purchase, the drive wouldnât work. I have no traditional CD player, so I was anxious to hear this one.
Rather than think and troubleshoot, I got out a portable USB one and plugged it into my main system. Same result, now on two machines. After some cursing and headscratching, it hit me. Neither drive had been in use when I ran modulejail. I cleared its blacklist, rebooted, accessed the drives, then re-ran it. Both drives worked just fine afterwards. I added their modules to the whitelist.
I had to do the same with my VPN. UDP, and by extension Wireguard, is blocked on the Wi-Fi at work. I usually switch manually to OpenVPN over TCP when I use my personal laptop there. Of course, after having run modulejail while using Wireguard at home, OpenVPN and tun were blacklisted.
Extrapolate from two examples by an 30-year experienced Linuxhead to a forum full of people who canât even do a search first, or provide an inxi -zv8 when reporting issues and youâll see what a support headache this could become.
No, modulejail is a tool for advanced users who can and will troubleshoot their own issues, and therefore it should not be in any distroâs repos. I would include the Chaotic-AUR repo in that.
Finally, thus far (2026-05-31), the security issues AI has found in modules (where modulejail could prevent an exploit) all require physical keyboard access to the system in question and have not been remote-access security issues.
This makes modulejail a more limited and esoteric security function which could be handled much more easily with proper login/password and physical security. That also makes it of little benefit to the ordinary user of CachyOS, unless of course, their family and friends are running exploits on their home PC⌠Thus, it is not âcriticalâ as you assert.
The author of modulejail describes it as a tool to buy time between exploit discovery and patching. The Linux ecosystem is really, really good at quickly patching security issues. Rolling-releases are really good at getting those patches out quickly. Adding to a releaseâs support load could slow that process down.
So, yes I use it (even though I have no actual use case), but I donât recommend it to either ordinary users, or to distros to include their repos.
Sorry. Go to the AUR.