<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>linux on tomrochette.com</title>
    <link>https://tomrochette.com/tags/linux/</link>
    <description>Recent content in linux on tomrochette.com</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en</language>
    <managingEditor>tom@tomrochette.com (Tom Rochette)</managingEditor>
    <webMaster>tom@tomrochette.com (Tom Rochette)</webMaster>
    <copyright>© 2026 Tom Rochette</copyright>
    <lastBuildDate>Tue, 29 Sep 2026 04:38:43 -0400</lastBuildDate><atom:link href="https://tomrochette.com/tags/linux/index.xml" rel="self" type="application/rss+xml" />
    
    <item>
      <title>Drop</title>
      <link>https://tomrochette.com/agents/sandboxing/drop/</link>
      <pubDate>Tue, 29 Sep 2026 00:00:00 +0000</pubDate>
      <author>tom@tomrochette.com (Tom Rochette)</author>
      <guid>https://tomrochette.com/agents/sandboxing/drop/</guid>
      <category>research-note</category><category>agent-curated</category><category>fully-ai-generated</category><category>llm=glm-5.3-flash</category><category>sandboxing</category><category>isolation</category><category>linux</category><category>open-source</category>
      <description>&lt;p&gt;Drop is Jan Wrobel&amp;rsquo;s Apache-2.0, Go-based Linux sandbox that wraps any program or coding agent in a rootless environment built from your existing distribution: user, mount, PID, IPC, cgroup, and network namespaces plus dropped capabilities, with optional gVisor underneath and pasta networking that denies localhost services by default.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Drop&amp;rsquo;s bet is that isolation should not cost you your environment: it sandboxes inside the distribution you already run, no images and no VM required, and a 193-point launch says the gap between the thin wrappers and the VM tools was real.&lt;/strong&gt;&lt;/p&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;What it is&#xA;    &lt;div id=&#34;what-it-is&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#what-it-is&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;p&gt;A single prebuilt binary with a virtualenv-style workflow: &lt;code&gt;drop init&lt;/code&gt; creates an environment with a TOML config, &lt;code&gt;drop run&lt;/code&gt; starts a sandboxed shell in it, and environments are disposable while a shared &lt;code&gt;base.toml&lt;/code&gt; means you configure once and spawn freely.&#xA;The sandbox gets its own writable home directory while the original home is hidden, selected files and directories mount read-only, the current working directory is read-write with &lt;code&gt;.git&lt;/code&gt; read-only, and your username is preserved, so every program you already installed just works.&#xA;Underneath it uses your existing distribution rather than an image: namespaces isolate the process tree, all capabilities drop before exec so the sandboxed program cannot do privileged operations even within its own user namespace, and a mount namespace rearranges the root filesystem to hide the host.&#xA;Networking runs through pasta with access to localhost services denied by default, and an optional gVisor mode stops sandboxed programs from issuing syscalls to the host kernel directly.&#xA;The docs pitch two use cases: coding agents run with &lt;code&gt;--dangerously-skip-permissions&lt;/code&gt; so a hallucinated &lt;code&gt;rm -rf ~&lt;/code&gt; or a prompt injection hunting &lt;code&gt;~/.ssh&lt;/code&gt; finds nothing, and third-party installs from PyPI or npm contained the way a supply-chain compromise deserves.&#xA;Install is a curl of a release binary for amd64 or arm64 plus the passt/pasta package, with documented AppArmor configuration for Ubuntu 24+ and SELinux configuration for Fedora.&lt;/p&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;Status&#xA;    &lt;div id=&#34;status&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#status&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;p&gt;Young tool, older project, one strong launch: 331 stars, 10 forks, 6 open issues as of 2026-09-29, created 2025-07-25, pushed 2026-09-28, latest release v0.2.1 on 2026-08-24.&#xA;The Show HN thread on 2026-09-22 drew 193 points with substantive comparisons to bubblewrap and proot in the top replies.&#xA;&lt;strong&gt;The repository sat for fourteen months before the launch found it its audience, so the traction is one good Hacker News day, not a community, and the maintainer list is one person.&lt;/strong&gt;&lt;/p&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;Strengths&#xA;    &lt;div id=&#34;strengths&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#strengths&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Keeps the working environment intact: host distro, installed tools, and username all survive the boundary, which neither a container nor a VM manages.&lt;/li&gt;&#xA;&lt;li&gt;A real kernel boundary by default: six namespace types plus a full capability drop, with gVisor one flag away when the threat model warrants a user-space kernel.&lt;/li&gt;&#xA;&lt;li&gt;Sensible defaults aimed at exactly this category&amp;rsquo;s threats: localhost denied, &lt;code&gt;.git&lt;/code&gt; read-only, home hidden, &lt;code&gt;~/.ssh&lt;/code&gt; nonexistent.&lt;/li&gt;&#xA;&lt;li&gt;The TOML base-plus-override config makes per-project policy cheap instead of per-invocation flags.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;Cautions&#xA;    &lt;div id=&#34;cautions&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#cautions&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Pre-1.0 (v0.2.1), solo-maintained, and fourteen months old with a community measured in one launch thread.&lt;/li&gt;&#xA;&lt;li&gt;Namespace isolation shares the host kernel unless gVisor is enabled, which is the difference between containing a confused agent and containing a kernel exploit.&lt;/li&gt;&#xA;&lt;li&gt;Distro hardening is on you: Ubuntu 24+ needs an AppArmor profile change and Fedora an SELinux one, and skipping either weakens the setup.&lt;/li&gt;&#xA;&lt;li&gt;Linux-only (amd64 and arm64), with no macOS story at all, the opposite bet from Clawk.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;Pricing&#xA;    &lt;div id=&#34;pricing&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#pricing&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;p&gt;Free and open source under Apache-2.0; the only costs are the pasta dependency and the machine you run it on.&lt;/p&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;Compared to&#xA;    &lt;div id=&#34;compared-to&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#compared-to&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://tomrochette.com/agents/sandboxing/aigate/&#34; &gt;aigate&lt;/a&gt;: the other wrapper-style column, but maintained, documented, and launched; choose aigate only as a reading exercise, Drop for actual use.&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://tomrochette.com/agents/sandboxing/clawk/&#34; &gt;Clawk&lt;/a&gt;: trades the VM for namespaces, so Drop is lighter and keeps your Linux distro while Clawk is macOS-first and fully isolated.&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://tomrochette.com/agents/sandboxing/openshell/&#34; &gt;OpenShell&lt;/a&gt;: NVIDIA&amp;rsquo;s runtime adds declarative egress policy and credential interception at an inference proxy; Drop hides the filesystem and blocks localhost but has no L7 policy layer, so pick OpenShell for organizational policy, Drop for a personal workstation.&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://tomrochette.com/agents/sandboxing/agent-sandbox/&#34; &gt;Agent Sandbox&lt;/a&gt;: the Kubernetes answer when these workstation sandboxes need to become governed fleet infrastructure.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;Bottom line&#xA;    &lt;div id=&#34;bottom-line&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#bottom-line&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;p&gt;&lt;strong&gt;Recommended for Linux developers who want their coding agent fenced in by the kernel without giving up their installed environment, with gVisor enabled when the work is untrusted.&lt;/strong&gt;&#xA;Not for macOS, and not as a hardened boundary for hostile code until the solo-maintainer risk and the missing audit are priced in.&lt;/p&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;Changes&#xA;    &lt;div id=&#34;changes&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#changes&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;2026-09-29 - Created from the entrant-resolution run, profiling the rootless namespace sandbox that uses the host distribution.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;See also&#xA;    &lt;div id=&#34;see-also&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#see-also&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://tomrochette.com/agents/sandboxing/sandboxing-feature-matrix/&#34; &gt;Sandboxing Feature Matrix&lt;/a&gt; - the category comparison this note joins&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://tomrochette.com/agents/sandboxing/openshell/&#34; &gt;OpenShell&lt;/a&gt; - the vendor-backed policy runtime comparison&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://tomrochette.com/agents/sandboxing/clawk/&#34; &gt;Clawk&lt;/a&gt; - the disposable-VM alternative on macOS&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://tomrochette.com/agents/sandboxing/aigate/&#34; &gt;aigate&lt;/a&gt; - the tiny kernel-wrapper prior art&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;References&#xA;    &lt;div id=&#34;references&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#references&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://droprun.sh&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=droprun.sh&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;https://droprun.sh&lt;/a&gt; - the project site, its two use cases, and the mechanism summary&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/wrr/drop&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=github.com&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;https://github.com/wrr/drop&lt;/a&gt; - repository, README, license, adoption numbers&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://raw.githubusercontent.com/wrr/drop/HEAD/README.md&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=raw.githubusercontent.com&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;https://raw.githubusercontent.com/wrr/drop/HEAD/README.md&lt;/a&gt; - the quick start, sandbox overview, and per-distro hardening requirements&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://droprun.sh/docs/sandbox-overview&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=droprun.sh&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;https://droprun.sh/docs/sandbox-overview&lt;/a&gt; - the filesystem layout and isolation documentation&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://hn.algolia.com/api/v1/items/49801329&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=hn.algolia.com&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;https://hn.algolia.com/api/v1/items/49801329&lt;/a&gt; - the 193-point Show HN launch thread&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;</description>
      
    </item>
    
  </channel>
</rss>
