← Back to context

Comment by simonw

10 hours ago

This is promising, but there's one feature that's missing that I really care about: fine-grained networking.

They have this for Windows and Linux, but it's sadly missing for macOS - see the support table here: https://github.com/microsoft/mxc/blob/main/docs/backends/sea...

Things macOS is missing include "Allow/deny by hostname" and "Allow/deny by IP, CIDR, port, or protocol".

The rest all looks great, and if you are on Linux or Windows those restrictions don't apply.

I guess this is the universal challenge of building an abstraction layer over multiple different technologies.

hey simon,

smol machines actually support exactly those things across macs,linux, windows btw: https://github.com/smol-machines/smolvm/blob/main/AGENTS.md#...

here's a snippet of how it looks like to configure that:

  [network]
  allow_hosts         = ["api.github.com"]          # hostname, also allows its subdomains
  allow_host_patterns = ["example.com", "*.npmjs.org"]  # exact names, or *. for subdomains only
  allow_cidrs         = ["10.0.0.0/8", "1.1.1.1"]  # IP ranges  or single IPs

  [[network.credentials]]
  name                 = "github"
  environment_variable = "GITHUB_TOKEN"

  • how does it do it?

    proxy in the middle (but cert pinning problems)

    or DNS filtering? (but agent could have "memorized" stable IP)

    • Cert pinning: not a problem. we don't decrypt traffic, we just pass it through. The only exception is hosts you give a credential to, since we have to insert the key.

      Memorized IP: doesn't work, the vm can only connect to an IP if it came from a DNS lookup of an allowed name. Any other IP is blocked.

      A bit of "shared responsibility" philosophy kicking through but I try to have good defaults

Fine grained network policies is supported by microsandbox- a project that has already been working hard at building an abstraction layer over multiple different technologies. Microsandbox (on unix) builds on top of libkrun (a VM abstraction layer for unix). I am building a convenient runner on top of microsandbox: https://github.com/runcontain/runcontain (undergoing a rename right now). The best thing Microsoft could contribute right now would be great technology for light-weight containment on Windows.

They could bundle in a HTTP proxy (enforcing similar rules) perhaps. It takes a bit of reading to dig-through the Claude speak, but "Egress confinement is enforced; using the proxy is cooperative" simply means that there's no network egress, except through the proxy.

Of course, that only limits HTTP; and not other forms of network requests.

... interestingly, Anthropic's SRT is built on the same macOS primitives and DOES support the network configuration I'm looking for:

https://github.com/anthropics/sandbox-runtime/tree/main#as-a...

  const config: SandboxRuntimeConfig = {
    network: {
      allowedDomains: ['example.com', 'api.github.com'],
      deniedDomains: [],
    },
    filesystem: {
      denyRead: ['~/.ssh'],
      allowWrite: ['.', '/tmp'],
      denyWrite: ['.env'],
    },
  }