Hacker Newsnew | past | comments | ask | show | jobs | submit | corv's commentslogin

When AI and robots take care of everything there is more time to make babbies


Interesting! The sandboxing space definitely deserves more attention.

On the other side of the spectrum, we're working on a lightweight approach that augments user namespaces with libseccomp to filter syscalls via BPF.

https://github.com/corv89/shannot


Leash does it via eBPF today. Are you open to a collab?


Absolutely. I’ll send you an email


We've been exploring libseccomp/BPF filters on top of bubblewrap namespaces for LLM sandboxing - the BPF layer lets you go beyond read-only mounts to syscall restrictions. Open to collaboration on pushing this further: https://github.com/corv89/shannot


I've replaced my OrbStack usage entirely with Podman Desktop and have zero issues with it, unlike with OrbStack.

In particular the 1TB VM disk image OrbStack uses wreaks havok with deduplicating backups. Their disk cache also caused me hours of debugging why my assets weren't up-to-date.

Admittedly the OrbStack GUI is super snappy tho.


Seeing Treeform here immediately made me think of Nim, and lo-and behold that's what the Javascript is generated from, cool!


Thanks! It's all Nim, all the time.


Happy to see it get more attention here - it really is versatile


Awesome and in Nim!


> There’s also a Russian torpedo that uses a similar concept to “fly” at supersonic speeds underwater.

Supercavitation


Is it supercavitation or is it riding in a bubble of steam that it creates ahead of itself?

Either way, it’s effectively flying through the air bubble underwater, which was the concept I was thinking of.


The missing magic incantation to create your Brewfile:

brew bundle dump


In the case of an existing Brewfile, make sure to execute "brew bundle dump --force" to overwrite the Brewfile with updated list of formulae, kegs etc.


Ah ha! I had searched the article to see if there was a way to do that. Because while it would be awesome to have a file like this, creating it sounded like a pain.


Thank you!


sweeeet


It's really good but the fs caching has bit me a couple times before I realized what was going on.


Can you tell more about this?


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: