I'm confused why VM + systemd-nspawn? From my understaing WSL 2 runs a single VM + something like systemd-nspawn per "linux installation", but it runs a VM because it needs linux kernel. Why not just do systemd-nspawn if you alread on linux?
Way better isolation, is my guess. Plus, you can use a different kernel this way.
I used to poo-poo when people said that containers aren't a _real_ security boundary, at least for personal stuff, and not a multi-tenant server. But I bet even mid-tier LLMs can break out of LXC/Docker/nspawn at this point.
That has to be the host kernel not the guest kernel. Old Nvidia systems without supported kernel drivers often lack IOMMU to forward PCIe memory, too. I wouldn't recommend using an outdated host kernel with 2026 AI-powered vulnerability scanners.
Windows (10 LTSC or 11 with dTPM) actually works better for old Nvidia systems with WSL. You even get CUDA libraries within WSL and security updates for the next 5 years.
0x457 · · focus · HN ↗
pkulak · · focus · HN ↗
I used to poo-poo when people said that containers aren't a _real_ security boundary, at least for personal stuff, and not a multi-tenant server. But I bet even mid-tier LLMs can break out of LXC/Docker/nspawn at this point.
avadodin · · focus · HN ↗
Any kernel could be the last to support old nVidia drivers for your $10k card.
okanat · · focus · HN ↗
Windows (10 LTSC or 11 with dTPM) actually works better for old Nvidia systems with WSL. You even get CUDA libraries within WSL and security updates for the next 5 years.