» Tag
linux
134 postsJailbox: Hardened, Network-Isolated KVM VMs for AI Coding Agents
Jailbox creates hardened, network-isolated KVM VMs to contain AI coding agents and untrusted code, with no route back to your host or LAN.
QuantmLayer Locks Down AI Coding Agents with Kernel-Level Sandboxing
QuantmLayer sandboxes AI coding agents with kernel-level containment (BPF-LSM, seccomp, cgroups), blocking attacks default Docker can't stop.
Tailvisor gives macOS/Linux VMs their own Tailscale identity
Tailvisor is an open-source VM sandbox giving macOS/Linux guests their own Tailscale identity via a gVisor-based networking layer.
CommitBrief — AI code reviews, right in your terminal
A provider-agnostic, local-first CLI that reviews your staged changes, a historic range, or a whole GitHub pull request. Zero telemetry, no server. Free and open source.
commitbrief.comLinux 7.2 Released with Cache-Aware Scheduler and USB4STREAM
Linux 7.2 ships cache-aware task scheduling, a fairer GPU scheduler, USB4STREAM support, and Btrfs performance gains.
Rsync 3.5.0 Patches 33 Security Flaws in Path and Daemon Handling
Rsync 3.5.0 closes 33 security vulnerabilities, mostly symlink-race path handling bugs in the daemon and client, with CVE IDs and regression tests.
Lerd: An Open-Source, Rootless Herd Alternative for Linux and macOS
Lerd is an open-source, rootless Podman-based PHP dev environment for Linux and macOS, offering Herd-like .test domains, TLS and AI-agent integration.
PostgreSQL and the Linux OOM Killer: A Safer Default
How strict Linux memory overcommit (vm.overcommit_memory=2) prevents OOM-killer-driven crashes in PostgreSQL, backed by a direct benchmark comparison.
Furtex: Linux Post-Exploitation and Evasion Research Toolkit
Furtex is a Linux post-exploitation and evasion research toolkit based on io_uring and eBPF, designed for authorized research.
Booting Linux on Apple's M4: SPTM, Locked Registers and WFI Bugs
Deep dive into booting Linux on Apple's M4 chip: SPTM hardening, register debugging, and a WFI erratum that breaks ARM64 spec compliance.
Kakehashi: run macOS ARM64 binaries on Linux aarch64, no JIT
Kakehashi is an experimental userspace layer that runs macOS ARM64 binaries natively on Linux aarch64 without JIT, aimed at cutting CI costs.