3 ms·
I don't understand why no one has tried to make a harness without full shell access yet. It would be so much safer.
by andunie 1mo ago
I don't understand why no one has tried to make a harness without full shell access yet.
It would be so much safer.
- skohan 1mo agoIs that the harness' job? It seems to me the best place for sandboxing is at the OS level (i.e. running the harness inside a container with correct access configured).
- adverbly 1mo agoI would argue that it is the harness's job... Certainly for any harness which is targeting an end user. They don't sell cars without seat belts, and it is the car manufacturer who has to do it. Also, small nitpick but technically a container doesn't give full isolation compared to something like a VM.
- skohan 1mo agoOk that's fair if it's targeting a non-technical audience. But I think this will eventually be a problem solved at the OS level in a more streamlined way. I.e. there will be fine-grained permissions you need to approve to give an agent access to the system.
- jbstack 1mo agoYou want both. The harness and the sandbox do different things. The harness says "You have access to tool X, Y, and Z, but not A, B, C". The sandbox says "If you try to use X to access a forbidden resource, I'll prevent you from reaching it".
- adverbly 1mo agosandboxing?
- _0ffh 1mo agoThat's what I though. I've got a harness that uses landlock. Might not be perfect, but should be good enough for almost all cases.
- henry_291488 1mo ago[dead]
- tokai 1mo agoThat exist? "permission": { "bash": "deny" } Or something equivalent in any agentic editor of your choice.
- adamtulinius 1mo agoWhat does that achieve if the agent can still run processes on the host system?
- SuperCuber 1mo agowhat do you mean? the agent can't do it anymore if there's no bash permission
- abecedarius 1mo agoI haven't tried this but sounds like https://github.com/cloudflare/cloudflare-os https://github.com/cloudflare/cloudflare-os ?