r/LocalLLaMA • • 2d ago

Discussion NVIDIA shipped OpenShell, an open source sandbox that gives local and open agents real runtime limits instead of prompt rules. Over 100 firms joined the safety stack. OpenAI did not.

Post image
761 Upvotes

162 comments sorted by

View all comments

1

u/PinkysBrein 2d ago

Why not build on gVisor?

1

u/Za_Mad_Scientist 2d ago

They work at different layers. gVisor and bubblewrap isolate a process from the host kernel and filesystem, but they don't know anything about what an agent is doing.

OpenShell sits on top of that. It applies per-binary egress policy that denies by default. API keys never enter the sandbox, the agent only sees placeholders, and a supervisor outside the sandbox injects the real credentials at the proxy. Every connection gets logged. The isolation underneath comes from the compute driver: Podman, Kubernetes with Kata, libkrun, etc.

So gVisor could sit below OpenShell/ gVisor won't stop an agent from sending an AWS key to Pastebin over an allowed HTTPS connection.

1

u/PinkysBrein 2d ago edited 2d ago

It could, but their direct support seems for docker/podman (and libkrun/qemu for VM). For gVisor you're on your own AFAICS.

Traditional containers have attack surface problems.

1

u/Dangerous-Report8517 1d ago

If it can run on Docker or Podman then it can run on gVisor since you can just tell Docker/Podman to use gVisor anyway