smolmachines / smolvm as a sandbox for untrusted Python & JavaScript
- ID: a76a88cb
- 原文链接: https://simonwillison.net/2026/Aug/19/smolmachines-untrusted-sandbox/
- 作者: Simon Willison
- 日期: 2026-08-19
- 来源类型: blog
- 标签: sandbox, microvm, agent-safety, testing, benchmark
- 质量评分: 3/5
- 抓取时间: 2026-08-20T15:44:49Z
中文导读
Simon Willison 让 Claude Fable 5 在 Claude Code for web 里实测 smolvm 1.8.3 作为不可信 Python 与 JS 代码沙箱。容器本身是 Firecracker guest、无 /dev/kvm,smolvm machine run 报 kvm not available,Fable 的 Plan B 是把完整测试集放到有 /dev/kvm 的 GitHub Actions ubuntu runner 上跑再删除 workflow。结果确认硬件隔离 microVM 属性全部到位:冷启动 0.6-1.5 秒、热执行约 50ms、CPU 与 RAM 限制、guest 超时、存储配额、只读输入挂载与可写输出挂载、非特权模式均按预期工作。
为什么值得关注
硬件隔离 microVM 沙箱实测:50ms 热执行与完整资源限制,agent 执行环境的对比基线
原文摘录 (English Excerpt)
s://simonwillison.net/elsewhere/research/) smolmachines / smolvm as a sandbox for untrusted Python & JavaScript — Testing smolvm 1.8.3 shows it is well suited for sandboxing untrusted Python and JavaScript data transformations using hardware-isolated VMs rather than shared-kernel containers. Offline local images, no-network execution, CPU/RAM limits, guest-enforced timeouts, storage quotas, read-only input mounts, writable output mounts, and \--unprivileged\ all worked as intended, with cold starts around 0.6–1.5 seconds and warm executions around 50 ms.
I tasked Claude Fable 5 running in Claude Code for web with the following research task:
Put https://smolmachines.com through its paces as a fast secure sandbox. Explore what it would take to use this to run untrusted Python and JavaScript code in a way that is limited in what RAM and CPU time it can take up (protection against "while true") with no network access and filesystem access only to designated files
Goal is to be able to use this to execute user-provided tasks for things like data transformations
It quickly ran into a problem: the Claude Code for web environment can't run smol machines. Quoting the notes it wrote:
- This Claude Code container: Linux 6.18.5-fc-v20 (itself a Firecracker guest), 4 vCPU, 15GB RAM. No /dev/kvm, no vmx/svm CPU flags → no nested virt.
- smolvm machine run fails as expected: "kvm not available".
- Plan B: GitHub Actions ubuntu runners DO expose /dev
Obsidian 证据
- 来源 digest: AK RSS Digest 2026-08-20(2026-08-20,评分 8.0)
- 原文经 opencli web read / opencli arxiv paper 抓取核对,关键数字与摘要均锚定抓取内容。