Remix.run Logo
▲ Normal_gaussian 15 hours ago

Smolvm with it's libkrun vmm provides significantly worse security positioning than slicervms use of firecracker, which leads to slicervm for any dangerous or secure workload.

https://github.com/libkrun/libkrun

▲binsquare 15 hours ago | parent [-]

Libkrun and firecracker had similar foundations (Rust, KVM, rust-vmm).

Firecracker has a long track record but has a lot of knobs and tunings to get the security right.

smolvm's serve mode confines each VMM by default with a seccomp allowlist, Landlock, a per-VM uid and no_new_privs, much like Firecracker's jailer.

For dangerous workloads, people can do the same things such as skip host mounts and use virtio-net.

It's not a different security class just because it's libkrun vs firecracker