Remix.run Logo
▲ 0x457 10 hours ago

I'm confused why VM + systemd-nspawn? From my understaing WSL 2 runs a single VM + something like systemd-nspawn per "linux installation", but it runs a VM because it needs linux kernel. Why not just do systemd-nspawn if you alread on linux?

▲pkulak 10 hours ago | parent | next [-]

Way better isolation, is my guess. Plus, you can use a different kernel this way.

I used to poo-poo when people said that containers aren't a _real_ security boundary, at least for personal stuff, and not a multi-tenant server. But I bet even mid-tier LLMs can break out of LXC/Docker/nspawn at this point.

▲fhn 9 hours ago | parent [-]

can they not break out of a VM?

▲pkulak 9 hours ago | parent | next [-]

It's at least harder! Better chance it'll hit your 5-hour limit before it does. haha

▲esseph 9 hours ago | parent [-]

See my response to the above comment

▲bloppe 8 hours ago | parent | prev | next [-]

CVEs for runc are much more frequent than CVEs for KVM. The attack surface area is bigger, and containers were never intended as a security boundary, but rather as a resource management tool.

▲dathinab 4 hours ago | parent | next [-]

through just from scanning the feature side

> Your files and your account [..]

> Ports and windows on the host

it is quite likely that you can break out even with no linux containers related CVEs. --isolate does seem to fix that somehow but is explicit opt. in and "more painful to use" ... (which creates a UX challenge unlikely to end well from a security POV).

▲akdev1l 3 hours ago | parent | prev [-]

libkrun exists so we can just run containers inside a virtualized environment without special tooling

▲zenoprax an hour ago | parent [-]

I was just testing this and it's not clear that it works out of the box. `krun` shows a different kernel than with `crun` but it doesn't reflect the dropped capabilities in the same way. I'm probably holding it wrong but I'm not sure what to look for at the moment.

▲esseph 9 hours ago | parent | prev [-]

Yes, and have.

---

"During a test conducted by Trail of Bits researcher Artem Dinaburg, a preview version of GPT 5.6-Cyber was tasked with breaking out of a Debian 12 virtual machine. Initially, the agent exploited a known Linux kernel vulnerability, CVE-2026-53359, by developing its own exploit. After the host was updated, the agent found another pathway through libslirp, chaining a known vulnerability (CVE-2026-9539) with a previously unassigned bug to gain arbitrary host memory access. Even after QEMU and libslirp were updated, the agent analyzed system components and constructed a new escape chain using three zero-day vulnerabilities and one KVM flaw that had not yet reached the distribution kernel.

These findings suggest that general-purpose VMs may not be adequate security boundaries for highly capable AI agents, especially in older systems with delayed security updates. Trail of Bits recommends using specialized isolation systems like Firecracker, restricting VM access, and implementing rapid patching to mitigate these risks."

---

https://www.scworld.com/brief/ai-agent-repeatedly-escapes-vi...

▲bketelsen 10 hours ago | parent | prev | next [-]

you could, and if that's your preference https://nspawn.org is just right.

▲bityard 7 hours ago | parent | next [-]

I was surprised I hadn't heard of this as a separate tool from systemd-nspawn. Then I realized why... the GitHub repo shows version 0.6 released in 2022, then version 1.0.0 last week, followed by a flurry of releases up to 1.8.0 yesterday.

So basically, it's been all Claude'd up extremely recently.

That said, the landing page, docs, and git README are much higher quality than I normally see out of LLM-generated projects, so at least the author knows how to reign in the needless verbosity and write for a technical audience. So I will give him credit for that at least.

▲0x457 10 hours ago | parent | prev [-]

Neat, I wasn't aware of this tool. I just either run nixosContainer in systemd-nspawn or OCI image in systemd-nspawn.

▲delusional 10 hours ago | parent | prev [-]

Claude told him to do it this way.

▲nateb2022 10 hours ago | parent [-]

I'd trust OP to make good architectural decisions/provide guidance even if AI mostly wrote the docs and UI. Looking into their GitHub, seems they are an engineering manager at Microsoft and contribute semi regularly to uBlue and Project Bluefin. Should be better quality than some random vibeslopper.