HNHacker News
TopNewBestAskShowJobs

binsquare

1,064 karma · joined October 1, 2019

working on smolmachines.com
submissionscomments
binsquare··on Opus 5.5 agents discover two room-temperature magnetic semiconductor candidates
I think ai certainly raises the bar for those with taste
binsquare··on Linux containers in 500 lines of code (2016)
I'm going to toss in smolvm as well because firecracker needs some expertise to make the box usable and secure.

https://github.com/smol-machines/smolvm

binsquare··on Show HN: Pi pod – Run your pi coding agent in sandboxes on your own server
thanks! author of smolvm here.

I focus on being the batteries-included approach for microVMs. So network is off by default, and you can allow specific hosts (DNS is filtered too), so an agent can reach its model API and nothing else.

And then I also put a lot of work in the jailer-style hardening around the VMM process itself: seccomp allowlist, Landlock, separate unprivileged uid per VM, and cgroup limits.

So that users have security & knobs right out of the box.

fwiw i used to operate an AWS service using firecracker.

binsquare··on Docker has always used microVMs (well since 2016)
The shared kernel/lack of isolation between the cotnainer workloads is the model that this article isn't really touching but is really important.

Because the current needs are extremely lightweight and isolated environments i.e. vm per workload rather than shared.

And there's been a lot of wonderful innovations happen there

binsquare··on Newgrounds.com – A community of games, music, and art
I'm glad that Newgrounds is one of those sites that has kept it's soul all these years.

Even the same old games are still there

binsquare··on OpenDLSS: A Vulkan Reimplementation of Nvidia's DLSS 5 Neural Rendering Network
it used to just be a upscaling, but now it completely changes the artstyle.
binsquare··on 5x faster Edge Functions: V8 isolates to Firecracker MicroVMs
I'll keep it going just for you
binsquare··on 5x faster Edge Functions: V8 isolates to Firecracker MicroVMs
Libkrun and firecracker had similar foundations (Rust, KVM, rust-vmm).

Firecracker has a long track record but has a lot of knobs and tunings to get the security right.

smolvm's serve mode confines each VMM by default with a seccomp allowlist, Landlock, a per-VM uid and no_new_privs, much like Firecracker's jailer.

For dangerous workloads, people can do the same things such as skip host mounts and use virtio-net.

It's not a different security class just because it's libkrun vs firecracker

binsquare··on 5x faster Edge Functions: V8 isolates to Firecracker MicroVMs
yes, separate kernels + virtualized hardware via hypervisor.

containers are built on linux primitives & so shares the kernel.

binsquare··on OpenDLSS: A Vulkan Reimplementation of Nvidia's DLSS 5 Neural Rendering Network
At what point does this neural rendering take away the human touch on the art styles?
binsquare··on 5x faster Edge Functions: V8 isolates to Firecracker MicroVMs
I focus on building the best VM tech.

Good sandboxing is a feature of a good VM.

Outside of that I support GPU and enables something called branchable computing.

binsquare··on 5x faster Edge Functions: V8 isolates to Firecracker MicroVMs
Kernel level isolation.

Functionality of criu built in so you can get rewind, pause, in an accessible manner.

Embeddable (you can write JavaScript to programmatically use an isolated environment)

Native performance on multiplatform + consistent experience across platforms.

binsquare··on Fuck Android Developer Verification Program
Almost sounds like one of the intentional product decisions
binsquare··on 5x faster Edge Functions: V8 isolates to Firecracker MicroVMs
Appreciate your support!
binsquare··on 5x faster Edge Functions: V8 isolates to Firecracker MicroVMs
can confirm that this is true for the fargate product used by consumers.

as someone who worked on it

binsquare··on 5x faster Edge Functions: V8 isolates to Firecracker MicroVMs
That seems off to me as well.

Fwiw, you can run this instead free and open source: https://github.com/smol-machines/smolvm

Disclaimer: Am author.

binsquare··on 5x faster Edge Functions: V8 isolates to Firecracker MicroVMs
v8 isolates are still shared kernel

while microvm's are separate kernel + hardware virtualization through hypervisor guarantees

I wouldn't call it bad either, just different tools for different things

binsquare··on Nvidia wants to put a watchdog chip next to every AI agent
Why is it effectively irrelevant?

Agentic workloads are trained and largely based on human workloads. Albeit properties and scale can be different.

A concrete example might be helpful to me because I don't understand the binary conclusion

binsquare··on World Labs Is Joining AMD
it was also likely difficult to do what WL was looking to do without significant amount of compute.

Think it's a good match

binsquare··on Nvidia wants to put a watchdog chip next to every AI agent
Running untrusted workloads have been done at scale for a long time.

Every cloud provider dealt with it and concluded that virtual machine technology is an important part of that stack.

Couple it with the right observability, tooling I do think we can curb risks posed by agents.

binsquare··on Tell HN: Codex Is Down [fixed]
Good thing they don't promise SLA's.
binsquare··on CVE-2025-13032: Entering and Breaking the Avast Antivirus Sandbox Part 2
I work on making this a reality with an embeddable VM.

Performance doesn't have to be supbar, infact with the right properties and focus on being lightweight - I see 90% of native performance.

I work on this as context: https://github.com/smol-machines/smolvm

binsquare··on Show HN: Drop – A rootless Linux sandbox with gVisor support
hey there, smolvm might be the right tool for your needs of containerization + GUI with gpu acceleration through vulkan.
binsquare··on Show HN: Drop – A rootless Linux sandbox with gVisor support
I think at the surface level it's a wide problem but the solutions so far are shallow attempts
binsquare··on Show HN: Drop – A rootless Linux sandbox with gVisor support
Every comment is talking about their own sandbox implementation.
binsquare··on AX – Google’s Open Agentic Orchestrator
It's a different level of isolation, worktrees help agent work on different code repository in parallel but things get wonky once you consider processes and environments variables
binsquare··on Inside ZCode: Silently uploading your Git history to the cloud
It's not naive it makes running these ai agents inside the sandbox even more important
binsquare··on How GLM built its own inference infrastructure
Given the rate of improvement, why is this deranged?
binsquare··on Cloudflare AKE cuts origin HelloRetryRequests from 52% to 3.7%
I like to think that the coding agents has basically raised the bar.

Those who are above the bar can steer and add their expertise to hit a new level.

binsquare··on Ask HN: What are you working on? (September 2026)
I'm building smol machines, a new sandboxing primitive that works locally/remotely to introduce "branchable compute".

It's an idea I had to basically makes it possible to checkpoint, branch, rollback the entire vm kind of like git but on the entire computer.

https://github.com/smol-machines/smolvm

Page 1 of 10Next →