<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>kernel on tomrochette.com</title>
    <link>https://tomrochette.com/tags/kernel/</link>
    <description>Recent content in kernel on tomrochette.com</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en</language>
    <managingEditor>tom@tomrochette.com (Tom Rochette)</managingEditor>
    <webMaster>tom@tomrochette.com (Tom Rochette)</webMaster>
    <copyright>© 2026 Tom Rochette</copyright>
    <lastBuildDate>Wed, 07 Oct 2026 06:38:49 -0400</lastBuildDate><atom:link href="https://tomrochette.com/tags/kernel/index.xml" rel="self" type="application/rss+xml" />
    
    <item>
      <title>nono</title>
      <link>https://tomrochette.com/agents/sandboxing/nono/</link>
      <pubDate>Wed, 07 Oct 2026 00:00:00 +0000</pubDate>
      <author>tom@tomrochette.com (Tom Rochette)</author>
      <guid>https://tomrochette.com/agents/sandboxing/nono/</guid>
      <category>research-note</category><category>agent-curated</category><category>fully-ai-generated</category><category>llm=glm-5.3-flash</category><category>sandboxing</category><category>isolation</category><category>security</category><category>kernel</category><category>open-source</category>
      <description>&lt;p&gt;nono is a capability-based sandbox CLI and SDK family from nolabs-ai, the team behind Sigstore, that sandboxes an AI agent session at the kernel level and, distinctively, launches each delegated tool the agent calls under its own command sandbox with separate filesystem, network, and credential policy.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;nono&amp;rsquo;s design point is that the agent&amp;rsquo;s session sandbox is not enough: each delegated tool gets its own sandbox, so git sees only the repo and git config, gh receives a token through a credential proxy scoped to selected API methods and paths, and the agent can widen none of it from inside its session.&lt;/strong&gt;&lt;/p&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;What it is&#xA;    &lt;div id=&#34;what-it-is&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#what-it-is&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;p&gt;A Rust core with an installable CLI (curl script, Homebrew, Nix flake) plus Go, TypeScript, and Python SDKs over FFI, so the same policies can gate an agent harness or an application&amp;rsquo;s own LLM calls.&#xA;The session sandbox uses kernel primitives, and the broker wraps each controlled tool in a command policy of its own: the tool does not inherit the session&amp;rsquo;s broad grants, working-directory access, raw credential paths, or network access unless its profile says so.&#xA;Profiles can chain policies (git may call ssh under a chained policy while direct ssh from the agent stays denied) and route credentials through an L7-filtering proxy that enforces which API methods and paths a token may touch.&#xA;The project also advertises an immutable cryptographic audit chain and atomic rollback, and the registry namespace moved from &lt;code&gt;always-further&lt;/code&gt; to &lt;code&gt;nolabs-ai&lt;/code&gt; in the run-up to 1.0.&#xA;Apache-2.0, built by the Sigstore team, with an OpenSSF Best Practices badge and testimonials from staff and principal security engineers at Datadog and Okta on the README.&lt;/p&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;Status&#xA;    &lt;div id=&#34;status&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#status&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;p&gt;Fast-growing with no Hacker News help: 4,377 stars, 226 open issues and PRs, pushed 2026-10-05 as of 2026-10-07, created 2026-01-31.&lt;/p&gt;&#xA;&lt;picture&gt;&#xA;  &lt;source media=&#34;(prefers-color-scheme: dark)&#34; srcset=&#34;https://api.star-history.com/chart?repos=nolabs-ai/nono&amp;type=date&amp;theme=dark&amp;legend=top-left&#34; /&gt;&#xA;  &lt;source media=&#34;(prefers-color-scheme: light)&#34; srcset=&#34;https://api.star-history.com/chart?repos=nolabs-ai/nono&amp;type=date&amp;theme=dark&amp;legend=top-left&#34; /&gt;&#xA;  &lt;img alt=&#34;Star History Chart&#34; src=&#34;https://api.star-history.com/chart?repos=nolabs-ai/nono&amp;type=date&amp;theme=dark&amp;legend=top-left&#34; /&gt;&#xA;&lt;/picture&gt;&#xA;&lt;p&gt;The release train is active and pre-1.0: v0.77.0 on 2026-09-11, v0.78.0 on 2026-09-16, and v0.79.0 on 2026-09-30, with the README carrying an APIs-are-stabilizing note ahead of a 1.0.&#xA;&lt;strong&gt;Hacker News never embraced it: four submissions between 2026-02-01 and 2026-02-04 drew 4, 1, and 2 points, an August resubmission drew 3, and the stars grew without a front-page thread, so the evidence base is the repo, the docs, and named enterprise testimonials rather than public debate.&lt;/strong&gt;&lt;/p&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;Strengths&#xA;    &lt;div id=&#34;strengths&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#strengths&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;The finest-grained policy model in this category: per-tool command sandboxes with chained policies, rather than one blanket agent sandbox.&lt;/li&gt;&#xA;&lt;li&gt;The credential proxy answers key exfiltration per endpoint, which is stricter than vaults that inject a whole key.&lt;/li&gt;&#xA;&lt;li&gt;Credible security pedigree (the Sigstore team) plus an OpenSSF badge and a stated audit chain.&lt;/li&gt;&#xA;&lt;li&gt;SDK surface (Go, TypeScript, Python, Rust core) means the policies are callable from product code, not just a terminal.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;Cautions&#xA;    &lt;div id=&#34;cautions&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#cautions&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Pre-1.0 with an explicit API-change warning, and the namespace migration (&lt;code&gt;always-further&lt;/code&gt; to &lt;code&gt;nolabs-ai&lt;/code&gt;) is churn early adopters must handle.&lt;/li&gt;&#xA;&lt;li&gt;Kernel-primitive isolation shares the host kernel; there is no VM or gVisor tier, so a kernel exploit is out of scope for this boundary.&lt;/li&gt;&#xA;&lt;li&gt;No independent audit or adversarial write-up exists that I could find, and the HN footprint is four near-zero threads.&lt;/li&gt;&#xA;&lt;li&gt;The marketing register on the README (&amp;ldquo;pioneered the zero-latency, zero-setup agent sandbox&amp;rdquo;, &amp;ldquo;copied by many&amp;rdquo;) is self-assessment, not evidence.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;Pricing&#xA;    &lt;div id=&#34;pricing&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#pricing&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;p&gt;Free and open source under Apache-2.0, no paid tiers or hosted offering found as of 2026-10-07.&lt;/p&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;Compared to&#xA;    &lt;div id=&#34;compared-to&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#compared-to&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://tomrochette.com/agents/sandboxing/openshell/&#34; &gt;OpenShell&lt;/a&gt;: NVIDIA&amp;rsquo;s runtime adds container and MicroVM boundaries and holds model keys at an inference proxy; nono stays at kernel primitives but scopes every tool&amp;rsquo;s credentials per endpoint, so choose OpenShell for VM strength, nono for delegation control.&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://tomrochette.com/agents/sandboxing/drop/&#34; &gt;Drop&lt;/a&gt;: the namespace wrapper that keeps your host distribution with no per-tool brokering; simpler, and its threat model stops at the session boundary.&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://tomrochette.com/agents/sandboxing/fence/&#34; &gt;Fence&lt;/a&gt;: the other OS-primitives CLI; Fence applies one policy per invocation, while nono brokers each delegated tool separately and proxies its credentials.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;Bottom line&#xA;    &lt;div id=&#34;bottom-line&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#bottom-line&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;p&gt;&lt;strong&gt;Recommended for engineers whose main fear is the agent misusing the tools it delegates to, and who want per-tool, per-endpoint credential policy from a team with a security track record.&lt;/strong&gt;&#xA;Not for anyone who needs VM-grade boundaries today or an externally audited 1.0.&lt;/p&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;Changes&#xA;    &lt;div id=&#34;changes&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#changes&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;2026-10-07 - Created from the entrant-resolution run, profiling the Sigstore team&amp;rsquo;s per-command sandbox broker with its credential proxy and the no-HN-growth finding.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;See also&#xA;    &lt;div id=&#34;see-also&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#see-also&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://tomrochette.com/agents/sandboxing/sandboxing-feature-matrix/&#34; &gt;Sandboxing Feature Matrix&lt;/a&gt; - the category comparison this note joins&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://tomrochette.com/agents/sandboxing/openshell/&#34; &gt;OpenShell&lt;/a&gt; - the VM-backed policy runtime with the model-key proxy&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://tomrochette.com/agents/sandboxing/fence/&#34; &gt;Fence&lt;/a&gt; - the invocation-level sibling using the same OS primitives&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://tomrochette.com/agents/sandboxing/drop/&#34; &gt;Drop&lt;/a&gt; - the session-scoped namespace alternative&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;References&#xA;    &lt;div id=&#34;references&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#references&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/nolabs-ai/nono&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=github.com&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;https://github.com/nolabs-ai/nono&lt;/a&gt; - repository, mechanism, testimonials, OpenSSF badge, namespace-migration notice&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://docs.nono.sh/&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=docs.nono.sh&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;https://docs.nono.sh/&lt;/a&gt; - the CLI, Rust core, and Go/TypeScript/Python SDK surface&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://api.github.com/repos/nolabs-ai/nono&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=api.github.com&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;https://api.github.com/repos/nolabs-ai/nono&lt;/a&gt; - stars, open issues, creation and push dates as of 2026-10-07&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://api.github.com/repos/nolabs-ai/nono/releases&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=api.github.com&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;https://api.github.com/repos/nolabs-ai/nono/releases&lt;/a&gt; - the v0.77.0 through v0.79.0 release record&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://hn.algolia.com/api/v1/items/46849615&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=hn.algolia.com&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;https://hn.algolia.com/api/v1/items/46849615&lt;/a&gt; - the 4-point Show HN of 2026-02-01, the largest of four near-zero threads&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;</description>
      
    </item>
    
  </channel>
</rss>
