Show HN: NSL – WSL for Linux
Thread
Loading the complete thread in the background. This saved snapshot is available now. Refresh
Unofficial Hacker News client; not affiliated with Y Combinator.
Show HN: NSL – WSL for Linux
Loading the complete thread in the background. This saved snapshot is available now. Refresh
Unofficial Hacker News client; not affiliated with Y Combinator.
thayne · · focus · HN ↗
bketelsen · · focus · HN ↗
NekkoDroid · · focus · HN ↗
To be fair, WSL mounts all your drives under /mnt/ by default, which I would argue isn't any better, arguably even worse.
jm4 · · focus · HN ↗
Can you explain the advantages of systemd-nspawn containers versus podman/docker? I’m not familiar with systemd-nspawn, but I’m a regular user of distrobox and podman.
MrDrMcCoy · · focus · HN ↗
the_real_cher · · focus · HN ↗
mhitza · · focus · HN ↗
smw · · focus · HN ↗
bketelsen · · focus · HN ↗
the_real_cher · · focus · HN ↗
varispeed · · focus · HN ↗
The website's Claudisms are unbearable.
graemep · · focus · HN ↗
> It's yet another step in my long journey to keep my host installation free from all the changing and breaking dev dependencies that force a reinstall every few months.
Something that also require a bit of explanation. What do you do that makes this such a common problem.
bketelsen · · focus · HN ↗
As for keeping my host clean - it's the developer's curse that always gets me. Install libWhatever3.2-dev because you need it to compile something, then don't realize until next time you open Chrome that it broke your system in some subtle way. There are dozens of ways to solve this like devcontainers, docker, incus, fully separate or remote vms. I like the WSL2 model so I wanted that same UX.
graemep · · focus · HN ↗
kevin_thibedeau · · focus · HN ↗
okanat · · focus · HN ↗
rpcope1 · · focus · HN ↗
pkulak · · focus · HN ↗
ktm5j · · focus · HN ↗
GlacierFox · · focus · HN ↗
ktm5j · · focus · HN ↗
nurettin · · focus · HN ↗
pkulak · · focus · HN ↗
[deleted] · · focus · HN ↗
[deleted]
failbuffer · · focus · HN ↗
pkulak · · focus · HN ↗
RandomGerm4n · · focus · HN ↗
KyleGospo · · focus · HN ↗
mikae1 · · focus · HN ↗
Which?
lproven · · focus · HN ↗
<a href="https://news.ycombinator.com/item?id=49896422">https://news.ycombinator.com/item?id=49896422
rao-v · · focus · HN ↗
I never thought I’d prefer WSL to even my MacBook for working with remote servers and dev but somehow I do.
I of course know the many ways to roll something like this for myself, yes dev containers are better for many things etc. but it’s wierd how good the ergonomics of a WSL like container are.
bketelsen · · focus · HN ↗
snapplebobapple · · focus · HN ↗
rao-v · · focus · HN ↗
lucideer · · focus · HN ↗
From the OP I see:
> my long journey to keep my host installation free from all the changing and breaking dev dependencies that force a reinstall every few months
mise does this 100% for me (assuming we don't count mise itself as one of those dev dependencies). I'm struggling to think of what falls outside of it?
tonymet · · focus · HN ↗
lucideer · · focus · HN ↗
tonymet · · focus · HN ↗
dingaling911 · · focus · HN ↗
Now all you have to do is run NSL under WSL.
bketelsen · · focus · HN ↗
0x457 · · focus · HN ↗
delusional · · focus · HN ↗
nateb2022 · · focus · HN ↗
edu4rdshl · · focus · HN ↗
The architecture decisions, etc are dictated by me as well :)
If you have any suggestions, etc, they are welcome.
bketelsen · · focus · HN ↗
0x457 · · focus · HN ↗
bityard · · focus · HN ↗
So basically, it's been all Claude'd up extremely recently.
That said, the landing page, docs, and git README are much higher quality than I normally see out of LLM-generated projects, so at least the author knows how to reign in the needless verbosity and write for a technical audience. So I will give him credit for that at least.
edu4rdshl · · focus · HN ↗
Ideas/issues/PRs are welcome.
edu4rdshl · · focus · HN ↗
pkulak · · focus · HN ↗
I used to poo-poo when people said that containers aren't a _real_ security boundary, at least for personal stuff, and not a multi-tenant server. But I bet even mid-tier LLMs can break out of LXC/Docker/nspawn at this point.
fhn · · focus · HN ↗
pkulak · · focus · HN ↗
esseph · · focus · HN ↗
esseph · · focus · HN ↗
Already__Taken · · focus · HN ↗
cookiengineer · · focus · HN ↗
I'm using firecracker now with a very defensive systemd-as-separate-non-admin-user seccomp sandbox on top, which seems to hold them off long enough for me to see an agent going rogue and intervening.
Currently I still have hopes that eBPF sandboxing will help, but just a couple days ago my agent discovered a use after free bug in the ebpf kernel-side verifier... so there's that.
bloppe · · focus · HN ↗
dathinab · · focus · HN ↗
> Your files and your account [..]
> Ports and windows on the host
it is quite likely that you can break out even with no linux containers related CVEs. --isolate does seem to fix that somehow but is explicit opt. in and "more painful to use" .. (which creates a UX challenge unlikely to end well from a security POV).
akdev1l · · focus · HN ↗
zenoprax · · focus · HN ↗
avadodin · · focus · HN ↗
Any kernel could be the last to support old nVidia drivers for your $10k card.
okanat · · focus · HN ↗
Windows (10 LTSC or 11 with dTPM) actually works better for old Nvidia systems with WSL. You even get CUDA libraries within WSL.
gslepak · · focus · HN ↗
<a href="https://github.com/89luca89/distrobox" rel="nofollow">https://github.com/89luca89/distrobox
bee_rider · · focus · HN ↗
Anyway, should this be called LSL or WSLL? Or maybe LSWSL.
dspillett · · focus · HN ↗
bityard · · focus · HN ↗
The NT kernel designers came from VMS, and during development MS made various half-hearted promises that NT would be able to run VMS software as well but never actually followed through. If they had, there would likely have been a Windows Subsystem for VMS.
zokier · · focus · HN ↗
zamadatix · · focus · HN ↗
<a href="https://helparchive.huntertur.net/document/52712" rel="nofollow">https://helparchive.huntertur.net/document/52712
lukeh · · focus · HN ↗
bitwize · · focus · HN ↗
<a href="https://en.wikipedia.org/wiki/Windows_Services_for_UNIX" rel="nofollow">https://en.wikipedia.org/wiki/Windows_Services_for_UNIX
It's a subsystem instead of "services" because WSL1 really was an NT subsystem: a "kernel personality" that knows how to interpret Linux system calls just like the DOS and OS/2 subsystems of early NT.
michaelastreiko · · focus · HN ↗
bezko · · focus · HN ↗
bita_nidir · · focus · HN ↗
FWIW, I'm currently using systemd-nspawn via mkosi: <a href="https://github.com/systemd/mkosi" rel="nofollow">https://github.com/systemd/mkosi
It makes an image and runs it in separate namespace. It can start at bash or init. It's very fast but there seem to be a problem creating an Ubuntu image on Debian and vice versa.
codr1 · · focus · HN ↗
28304283409234 · · focus · HN ↗
teeskay · · focus · HN ↗
naman_307 · · focus · HN ↗
dathinab · · focus · HN ↗
And what prevented adopting/supporting existing projects, instead of further tool ecosystem fragmentation?
philips · · focus · HN ↗
And then I read your comment and my first reaction was, oh, they typoed toolbox. But, nope, Red Hat created toolbx which confusingly has the CLI binary of `toolbox`: <a href="https://containertoolbx.org" rel="nofollow">https://containertoolbx.org
bketelsen · · focus · HN ↗
philips · · focus · HN ↗
bketelsen · · focus · HN ↗
philips · · focus · HN ↗
bketelsen · · focus · HN ↗
senectus1 · · focus · HN ↗
Fnoord · · focus · HN ↗
aj2048 · · focus · HN ↗
frunklooper · · focus · HN ↗
ilvez · · focus · HN ↗
bketelsen · · focus · HN ↗
ilvez · · focus · HN ↗
Will try to give it a spin later.
ilvez · · focus · HN ↗
isityettime · · focus · HN ↗
tonymet · · focus · HN ↗
It's neat seeing this experience come to linux.
Sure you "could" do this with a bunch of tools, but it's the UX that matters.
Creative idea to fix something that nobody thought was broken, but actually was.
ocean2 · · focus · HN ↗
seabrookmx · · focus · HN ↗
The benefit is that its super low overhead (no VM).
bketelsen · · focus · HN ↗
zahlman · · focus · HN ↗
bketelsen · · focus · HN ↗
andai · · focus · HN ↗
I'm a bit of an outsider here (I don't understand computer) but a few weeks ago I was wrestling with the question of deploying an application on many boxen. After looking into Docker (and unikernels, lol) I arrived at the conclusion that "the operating system is part of my application."
A very bloated "part", which I did not write, don't understand very well, and which spontaneously self-modifies. An OS is a big bag of global mutable state! Ew!
This made me very sad. (At which point I was informed that I had basically reinvented NixOS from first principles?)
Also something about "we don't break userspace -- that's libc's job!"
<a href="https://blog.hiler.eu/win32-the-only-stable-abi/" rel="nofollow">https://blog.hiler.eu/win32-the-only-stable-abi/
TonyStr · · focus · HN ↗
lproven · · focus · HN ↗
<a href="https://snowlinux.org/" rel="nofollow">https://snowlinux.org/
I submitted the Github page as a new story:
<a href="https://github.com/frostyard/snowdesktop" rel="nofollow">https://github.com/frostyard/snowdesktop
<a href="https://news.ycombinator.com/item?id=49907568">https://news.ycombinator.com/item?id=49907568
bketelsen · · focus · HN ↗
lproven · · focus · HN ↗
Is that massive amount of bumf machine-generated?
bketelsen · · focus · HN ↗
lproven · · focus · HN ↗
Gosh. OK then.
martijnvds · · focus · HN ↗
The company behind rebranded to SUE.
just60sec · · focus · HN ↗
Got a quick demo? Just opening an editor, running a dev server, and showing how you access the files would help me get a feel for it.
vaporup · · focus · HN ↗
- <a href="https://sdme.io" rel="nofollow">https://sdme.io
- <a href="https://www.youtube.com/watch?v=1eVfgzd_xyQ" rel="nofollow">https://www.youtube.com/watch?v=1eVfgzd_xyQ
bketelsen · · focus · HN ↗
vaporup · · focus · HN ↗
humanfromearth9 · · focus · HN ↗
aniceperson · · focus · HN ↗
aniceperson · · focus · HN ↗