{"author":"decodebytes","children":[{"author":"sukinai","children":[],"created_at":"2026-02-01T21:58:22.000Z","created_at_i":1769983102,"id":46849790,"options":[],"parent_id":46849615,"points":null,"story_id":46849615,"text":"This hits the real problem: once agents execute code, \u201cplease don\u2019t read ~&#x2F;.ssh\u201d is not a security control. Kernel-enforced isolation + tight allowlists is.\nThe secrets workflow (keychain&#x2F;secret service \u2192 env \u2192 zeroize) is especially practical. Biggest thing I\u2019d want as a user is very explicit docs on the remaining gaps (macOS read-permissive mode, procfs&#x2F;env&#x2F;subprocess behavior, and what Landlock can\u2019t cover yet vs seccomp). If that\u2019s clear, this could be a default wrapper for local agent runs.","title":null,"type":"comment","url":null},{"author":"grigio","children":[],"created_at":"2026-02-01T23:10:03.000Z","created_at_i":1769987403,"id":46850335,"options":[],"parent_id":46849615,"points":null,"story_id":46849615,"text":"nice project, it seems the only non-broken websites are Github and nono.sh","title":null,"type":"comment","url":null},{"author":"gossterrible","children":[{"author":"decodebytes","children":[],"created_at":"2026-02-02T07:20:18.000Z","created_at_i":1770016818,"id":46853344,"options":[],"parent_id":46850844,"points":null,"story_id":46849615,"text":"Good question - and the answer is no, they cannot escape.\nnono uses Landlock (Linux) and Seatbelt (macOS) - these are kernel-level security mechanisms. When a sandbox is created:<p>All child processes inherit the restrictions - if the agent spawns Python, Bash, or compiles and runs a binary, that process is equally sandboxed There is no API to remove or expand the sandbox - once restrict_self() (Landlock) or sandbox_init() (Seatbelt) is called, the restrictions are permanent for that process tree.","title":null,"type":"comment","url":null}],"created_at":"2026-02-02T00:16:35.000Z","created_at_i":1769991395,"id":46850844,"options":[],"parent_id":46849615,"points":null,"story_id":46849615,"text":"I think with access to bash any AI agent can write a basic python&#x2F;bash script and run it to evade you sandbox , Right ?","title":null,"type":"comment","url":null},{"author":"veunes","children":[],"created_at":"2026-02-02T09:27:50.000Z","created_at_i":1770024470,"id":46854039,"options":[],"parent_id":46849615,"points":null,"story_id":46849615,"text":"The zeroize after exec feature sounds good, but what is the threat model in an agent context? If the agent can run printenv in the first millisecond and exfiltrate it (if net is allowed), zeroizing won&#x27;t help<p>It seems egress filtering (allowlists) is more critical for agents than memory protection. If I allow an agent to run npm install, I&#x27;m opening a network Pandora&#x27;s box, and Landlock (until ABI v4) offers pretty limited control there","title":null,"type":"comment","url":null}],"created_at":"2026-02-01T21:35:04.000Z","created_at_i":1769981704,"id":46849615,"options":[],"parent_id":null,"points":4,"story_id":46849615,"text":"Hey HN<p>Luke here.<p>I built nono and got it out quick then I expected, in response to the openclaw carnage, but its use is beyond openclaw.<p>The problem: AI agents execute code on your machine. Prompt injections, hallucinations, or compromised tools can read ~&#x2F;.ssh, exfiltrate credentials, or worse. Application-level sandboxes can be bypassed by the code they&#x27;re sandboxing.<p>I have been around security for a long old time now (i started something called sigstore a few years back) and have seen this pattern so many times before.<p>The solution pitch: nono uses OS-level isolation that userspace can&#x27;t escape:<p>Linux: Landlock LSM (kernel 5.13+)\nmacOS: Seatbelt (sandbox_init)\nAfter sandbox + exec(), there&#x27;s no syscall to expand permissions. The kernel says no.<p>What it does:<p>nono run --read .&#x2F;src --allow .&#x2F;output -- cargo build\nnono run --profile claude-code -- claude\nnono run --allow . --net-block -- npm install\nnono run --secrets api_key -- .&#x2F;my-agent<p>Filesystem: read&#x2F;write&#x2F;allow per directory or file\nNetwork: block entirely (per-host filtering planned)\nSecrets: loads from macOS Keychain &#x2F; Linux Secret Service, injects as env vars, zeroizes after exec<p>Technical details:<p>Written in Rust. ~2k LOC. Uses the landlock crate on Linux, raw FFI to sandbox_init() on macOS. Secrets via keyring crate. All paths canonicalized at grant time to prevent symlink escapes.<p>Landlock ABI v4+ gives us TCP port filtering. Older kernels fall back to full network allow&#x2F;deny. macOS Seatbelt profiles are generated dynamically as Scheme-like DSL strings.<p>Limitations:<p>macOS: Currently allows all reads to make executables work. Tightening in next release.\nLinux: Landlock doesn&#x27;t cover everything (no UDP filtering until recent kernels, no syscall filtering - that&#x27;s seccomp territory)\nNo Windows support (yet?)<p>Origin:<p>Built this for OpenClaw (AI agent platform handling Telegram&#x2F;WhatsApp messages). Needed real isolation, not &quot;please don&#x27;t read this file&quot; isolation. Generalized it because every agent runner has this problem.<p>GitHub: <a href=\"https:&#x2F;&#x2F;github.com&#x2F;lukehinds&#x2F;nono\" rel=\"nofollow\">https:&#x2F;&#x2F;github.com&#x2F;lukehinds&#x2F;nono</a>\nDocs: <a href=\"https:&#x2F;&#x2F;docs.nono.dev\" rel=\"nofollow\">https:&#x2F;&#x2F;docs.nono.dev</a>\nSite: <a href=\"https:&#x2F;&#x2F;noto.sh\" rel=\"nofollow\">https:&#x2F;&#x2F;noto.sh</a><p>Apache 2.0. Would love feedback on the security model, especially from folks who&#x27;ve worked with Landlock or Seatbelt. Having said that, the code needs a good tidy and I am not exactly proud of it, so go easy on me!","title":"Show HN: Nono \u2013 Kernel-enforced sandboxing for AI agents","type":"story","url":"https://nono.sh"}
