‹ BackHN Continuity

Thread

Show HN: Drop – A rootless Linux sandbox with gVisor support

193 points · 63 comments · mixedbit

  1. saghm · · focus · HN ↗
    This is super interesting to me. I&#x27;ve slowly been working on something similar (<a href="https:&#x2F;&#x2F;gitlab.com&#x2F;saghm&#x2F;tartarus" rel="nofollow">https:&#x2F;&#x2F;gitlab.com&#x2F;saghm&#x2F;tartarus) because my ideal sandboxing is &quot;prevent writing to anything outside this dir but still allow reading to most things so that I don&#x27;t have to manually copy things into a container&#x2F;VM&quot;. I approached it by trying to figure out how to build up a bubblewrap based on a config that gave the properties I wanted, with the hope that I could eventually expand it to support other platforms via stuff like `sandbox-exec` on MacOS, but I haven&#x27;t had time to work on it more for a while.

    At a glance, this seems to be providing most of what I was originally looking for when I ended up deciding I&#x27;d have to write it myself, but focusing specifically on Linux and providing a more full-fledged sandbox rather than only caring about a small set of permissions that I personally had a need for. Probably the biggest (and least hardened) feature that I spent time on in mine was trying to figure out how to allow arbitrary GUI apps so that I could run agents in it via Zed.

    I&#x27;m definitely going to try this out and see how well it works for me. It&#x27;s insane to me that this is something none of the big AI companies have bothered solving this yet other than via opaque rules built into their harnesses or absolutely awful manual rules that expect me to hard-code shapes of shell commands that I want to allow or not allow.

    1. killerstorm · · focus · HN ↗
      &gt; my ideal sandboxing is &quot;prevent writing to anything outside this dir but still allow reading to most things so that I don&#x27;t have to manually copy things into a container&#x2F;VM&quot;

      That&#x27;s what Codex does out of the box, and it&#x27;s not good against malware - i.e. a rogue npm packet (or even just codex after prompt injection) can read your ssh key and send it to the attacker.

      1. saghm · · focus · HN ↗
        &gt; That&#x27;s what Codex does out of the box

        As I said, opaque rules built into the harness rub me the the wrong way. They could change in an update without anything making it clear. Plus, I don&#x27;t use Codex outside of work (I don&#x27;t have any active paid subscriptions LLM offerings).

        &gt; it&#x27;s not good against malware - i.e. a rogue npm packet (or even just codex after prompt injection) can read your ssh key and send it to the attacker

        Ignoring the repeated references to software I don&#x27;t personally use, I never said I was trying to hedge against malware. The use case for me is when I&#x27;m running agents directly based off of prompts that I give them and asking them to modify some files. If I wanted a solution for running code I didn&#x27;t trust, I wouldn&#x27;t rely on what I wrote, because that&#x27;s not the intended use case at all.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.