frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Kernel-enforced sandbox App and SDK for AI agents, MCP and LLM workloads

https://github.com/always-further/nono
1•decodebytes•1h ago

Comments

decodebytes•1h ago
Hey HN

Luke here.

I wanted to introduce a project I have building for the past few weeks in response to events such as openclaw and the glaring security issues at hand. Prior to nono, I created Sigstore , a project used for software supply chain security now used by pypi, npm, brew and GitHub for release attestation and provence.

The problem: Protecting the host from the agent is largely solved, microVMs (kata, firecracker), containers , nono is more focused on protecting the environment or workspace itself - having said that, the isolation controls from the host are pretty solid as we use landlock and seatbelt.

nono uses OS-level isolation, atomic snapshots, and command auditing, secret / token protections (using keychain on linux and the secure enclave chip on apple)

Linux: Landlock LSM (kernel 5.13+) macOS: Seatbelt (sandbox_init) After sandbox + exec(), there's no syscall to expand permissions. The kernel says no.

Filesystem: read/write/allow per directory or file Network: block entirely (per-host filtering planned)

Atomic Rollbacks: Content-addressable storage — Files are stored by SHA-256 hash. Identical content is never duplicated, keeping storage efficient even across long sessions with many reverts — Every snapshot is committed to a Merkle tree. Tampering or corruption becomes more easily detectable

Audit trail of commands: nono automatically generates a cryptographically verifiable audit trail of every file change made by a sandboxed AI agent.

SDKs. We have two SDKs releasing soon using FFI bindings, python and typescript to allow uses to easily implement nono features into their own code base.

Technical details:

Written in Rust. Uses the landlock crate on Linux, raw FFI to sandbox_init() on macOS. Secrets via keyring crate. All paths canonicalized at grant time to prevent symlink escapes.

Landlock ABI v4+ gives us TCP port filtering. Older kernels fall back to full network allow/deny. macOS Seatbelt profiles are generated dynamically as Scheme-like DSL strings.

Limitations:

Network is binary, on or off - plans are in place to introduce IP filtering.

GitHub: https://github.com/always-further/nono Docs: https://docs.nono.dev Site: https://noto.sh

Apache 2.0. Would love feedback!

Britain Lost a Quarter of all pubs (14,000 Pubs) in 13 Years

https://laurenleek.substack.com/p/britain-lost-14000-third-places-they
1•m463•51s ago•0 comments

All Look Same?

https://alllooksame.com/
1•mirawelner•2m ago•0 comments

Martial arts robots dazzle at 2026 Spring Festival Gala [video]

https://www.youtube.com/watch?v=mUmlv814aJo
1•lisper•2m ago•0 comments

Show HN: Geneclaw – An AI agent framework that safely evolves its own code

https://github.com/Clawland-AI/Geneclaw
1•geneclawai•3m ago•1 comments

GitSyncMarks – Browser extension that syncs bookmarks to your own GitHub repo

https://github.com/d0dg3r/GitSyncMarks
2•d0dg3r•7m ago•0 comments

Owning Your Data

https://www.coryd.dev/posts/2026/owning-your-data
2•cdrnsf•8m ago•0 comments

Andrew Ranken, Whose Drumming Powered the Pogues, Dies at 72

https://www.nytimes.com/2026/02/11/arts/music/andrew-ranken-dead-the-pogues.html
2•bookofjoe•9m ago•1 comments

Astrolabe

https://en.wikipedia.org/wiki/Astrolabe
2•jhncls•9m ago•0 comments

The A.I. Disruption We've Been Waiting for Has Arrived

https://www.nytimes.com/2026/02/18/opinion/ai-software.html
3•gyomu•10m ago•0 comments

Productivity App to auto categorize your work and improve your workflow

https://dreamdimension.net/deepfocusapp/
2•dreamdimension•10m ago•1 comments

I was banned from the Wikipediocracy forum after unmasking a pro-CCP doxxer

https://xcancel.com/Liltjay08Foo/status/2023735372136464471
2•kurtreed2•11m ago•1 comments

Persona: Controlling LLM Personality with Vector Algebra

https://arxiv.org/abs/2602.15669
2•mldev_exe•11m ago•0 comments

Your Agent Framework Is Just a Bad Clone of Elixir

https://georgeguimaraes.com/your-agent-orchestrator-is-just-a-bad-clone-of-elixir/
3•ellieh•12m ago•0 comments

"Child's Play: Tech's new generation and the end of thinking"

https://harpers.org/archive/2026/03/childs-play-sam-kriss-ai-startup-roy-lee/
2•YPGolyadkin•14m ago•0 comments

am: Sandbox AppImages with Application Manager

https://github.com/ivan-hc/AM
2•my10thhnaccount•16m ago•0 comments

Inside The Birthplace of Your Favorite Technology

https://www.nytimes.com/interactive/2026/02/18/technology/bell-labs-history.html
2•jbegley•17m ago•0 comments

Tailwind CSS v4.2.0 Released

https://twitter.com/adamwathan/status/2024144333511815588
3•hbroadbent•18m ago•1 comments

Bayesian Time-Series Analysis on Retreating Economic Freedom

https://www.mdpi.com/2227-7099/14/1/34
2•PaulHoule•18m ago•0 comments

Scaling Job Execution: From Cron to Distributed Schedulers for Thousands Per

https://animeshgaitonde.medium.com/from-cron-to-distributed-schedulers-scaling-job-execution-to-t...
2•birdculture•19m ago•0 comments

Spotify Privacy Policy Request Metrics

https://www.spotify.com/us/legal/privacy-policy/#10-privacy-request-metrics
2•hentrep•19m ago•1 comments

Meta Begins $65M Election Push to Advance A.I. Agenda

https://www.nytimes.com/2026/02/18/technology/meta-65-million-election-ai.html
3•mykowebhn•20m ago•1 comments

Minimal Writing App

https://miniauthor.app
1•getpostHTTP•21m ago•2 comments

Models.dev – An open-source database of AI models

https://models.dev/
2•JnBrymn•21m ago•0 comments

LeafKit HTML Escaping Vulnerability

https://blog.vapor.codes/posts/leafkit-xss-vulnerability/
2•frizlab•21m ago•0 comments

Unihertz Jelly Max Guide • February 10, 2025 • 4,290 words

https://listed.to/@MilesBHuff/60337/unihertz-jelly-max-guide
3•yeah879846•21m ago•0 comments

US plans online portal to bypass content bans in Europe and elsewhere

https://www.reuters.com/world/us-plans-online-portal-bypass-content-bans-europe-elsewhere-2026-02...
9•c420•24m ago•1 comments

New Site Tracks Oregon Corporate Ties to Federal Immigration Enforcement

https://www.wewillfreeus.org/new-site-tracks-oregon-corporate-ties-to-federal-immigration-enforce...
2•cdrnsf•24m ago•0 comments

As Trump retreats from climate goals, China is becoming a green superpower

https://www.bbc.co.uk/news/resources/idt-8d2b6944-4f7a-45b4-96fd-2d92499ff97d
4•mmarian•25m ago•0 comments

Empiricists vs. Extrapolators

https://www.secondbest.ca/p/empiricists-vs-extrapolators
2•ctoth•25m ago•0 comments

Productively Programming Accelerated Computing Systems – Rohan Yadav (Stanford) [video]

https://www.youtube.com/watch?v=eWZ1HkOZ__Q
2•matt_d•27m ago•0 comments