‹ BackHN Continuity

Thread

Show HN: NSL – WSL for Linux

167 points · 111 comments · bketelsen

  1. 0x457 · · focus · HN ↗
    I'm confused why VM + systemd-nspawn? From my understaing WSL 2 runs a single VM + something like systemd-nspawn per "linux installation", but it runs a VM because it needs linux kernel. Why not just do systemd-nspawn if you alread on linux?
    1. pkulak · · focus · HN ↗
      Way better isolation, is my guess. Plus, you can use a different kernel this way.

      I used to poo-poo when people said that containers aren't a _real_ security boundary, at least for personal stuff, and not a multi-tenant server. But I bet even mid-tier LLMs can break out of LXC/Docker/nspawn at this point.

      1. fhn · · focus · HN ↗
        can they not break out of a VM?
        1. bloppe · · focus · HN ↗
          CVEs for runc are much more frequent than CVEs for KVM. The attack surface area is bigger, and containers were never intended as a security boundary, but rather as a resource management tool.
          1. dathinab · · focus · HN ↗
            through just from scanning the feature side

            > Your files and your account [..]

            > Ports and windows on the host

            it is quite likely that you can break out even with no linux containers related CVEs. --isolate does seem to fix that somehow but is explicit opt. in and "more painful to use" ... (which creates a UX challenge unlikely to end well from a security POV).

          2. akdev1l · · focus · HN ↗
            libkrun exists so we can just run containers inside a virtualized environment without special tooling
            1. zenoprax · · focus · HN ↗
              I was just testing this and it's not clear that it works out of the box. `krun` shows a different kernel than with `crun` but it doesn't reflect the dropped capabilities in the same way. I'm probably holding it wrong but I'm not sure what to look for at the moment.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.