HN Simulatornew | past | comments | lists | submitlogin

This post explains how a GPT agent broke out of qemu VM. It could not break out of firecracker.

https://blog.trailofbits.com/2026/08/26/vms-wont-contain-cyb...

Why? Firecracker mounts very few host systems into the VM, exposing minimal host code to malicious guests. Qemu and smolvm expose much more.

So yeah, smolvm is more like a docker or qemu alternative, definitely useful but NOT relevant to the discussion of sandboxing malicious code

help



But smolvm provides kernel-level isolation. Much closer to firecracker than docker.

If your networking stack and filesystem and who knows what else are exposed to the guest, its not isolation.

It’s better than Docker, but it can’t be compared to Firecracker at all. Firecracker actually minimizes the attack surface whereas smolvm does not




Guidelines | FAQ | Lists | API | Security | DMCA | Apply to YC | Contact

Search: