logoalt Hacker News

simonw • today at 1:08 PM • 4 replies • view on HN

This is promising, but there's one feature that's missing that I really care about: fine-grained networking.

They have this for Windows and Linux, but it's sadly missing for macOS - see the support table here: https://github.com/microsoft/mxc/blob/main/docs/backends/sea...

Things macOS is missing include "Allow/deny by hostname" and "Allow/deny by IP, CIDR, port, or protocol".

The rest all looks great, and if you are on Linux or Windows those restrictions don't apply.

I guess this is the universal challenge of building an abstraction layer over multiple different technologies.


Replies

binsquare • today at 3:35 PM

hey simon,

smol machines actually support exactly those things across macs,linux, windows btw: https://github.com/smol-machines/smolvm/blob/main/AGENTS.md#...

here's a snippet of how it looks like to configure that:

  [network]
  allow_hosts         = ["api.github.com"]          # hostname, also allows its subdomains
  allow_host_patterns = ["example.com", "*.npmjs.org"]  # exact names, or *. for subdomains only
  allow_cidrs         = ["10.0.0.0/8", "1.1.1.1"]  # IP ranges  or single IPs

  [[network.credentials]]
  name                 = "github"
  environment_variable = "GITHUB_TOKEN"
➕ show 2 replies
gregwebs • today at 1:57 PM

Fine grained network policies is supported by microsandbox- a project that has already been working hard at building an abstraction layer over multiple different technologies. Microsandbox (on unix) builds on top of libkrun (a VM abstraction layer for unix). I am building a convenient runner on top of microsandbox: https://github.com/runcontain/runcontain (undergoing a rename right now). The best thing Microsoft could contribute right now would be great technology for light-weight containment on Windows.

dannyw • today at 1:13 PM

They could bundle in a HTTP proxy (enforcing similar rules) perhaps. It takes a bit of reading to dig-through the Claude speak, but "Egress confinement is enforced; using the proxy is cooperative" simply means that there's no network egress, except through the proxy.

Of course, that only limits HTTP; and not other forms of network requests.

simonw • today at 1:27 PM

... interestingly, Anthropic's SRT is built on the same macOS primitives and DOES support the network configuration I'm looking for:

https://github.com/anthropics/sandbox-runtime/tree/main#as-a...

  const config: SandboxRuntimeConfig = {
    network: {
      allowedDomains: ['example.com', 'api.github.com'],
      deniedDomains: [],
    },
    filesystem: {
      denyRead: ['~/.ssh'],
      allowWrite: ['.', '/tmp'],
      denyWrite: ['.env'],
    },
  }