I've put some effort to integrate it to my agentic workflow. The problem, however, with docker in smolvm: it work-ish (there is example), but quite hacky.
Another problem which I wasnt able to solve - persistent image without Dockerfile. CloudInit will be ideal.
Documention at this moment in an early stage.
Overall, its a great project but for me was simpler just use Virtual Machine Manager (libvirt GUI).
I wish all luck to the maintainers, but probably DX-wise I will prefer to have more granular or predictable controls (eg micro cloud from Canonical).
Yep - similar in some ways but headed towards different directions.
I am building a virtual machine to simplify/replace container infra. Ex. we run containers inside of linux VM's even in the `cloud`, resulting in managing both the vm, and the containers.
But smol machines is a lightweight, portable VM that you can package into a single portable .smolmachine file to be rehydrated on any platform, kind of like how containers are used for today.
Sandboxing happens to be a feature of virtual machines, so we are alike in being used for sandboxing.
I have a solution based on Nix that can be used to generate reproducible container images: https://github.com/nothingnesses/agent-images . It lets you customise which agents, harnesses, or any other packages you want included in the VM and it uses `agent-box` for sandboxing.
It's a batteries included alternative to firecracker with a couple of new ideas tossed into the mix i.e. portable like a container (bake into a single file and rehydrate the vm anywhere), dynamic resource allocation, etc.
I'm using a container. The risk isn't exactly "agent leverages 0-day against you to steal all your data" but more "agent mistakenly though $HOME was theirs and deleted it" so as long as you "copy data in > copy data out" without bind-mounting or automatically sync files, container works just fine for "isolating" them.
I've tried both incus and firecracker. Both seem to work well after initial script setup. I've got the impression that firecracker should be a fairly safe option for such use cases.
Well for starters, all the single binaries I made of various distros a month ago, simply don't work anymore for no obvious reason. Trying to execute the process silently exits after about 10 seconds with a 0 exit code and no output, shell or anything at all, and no errors. I have absolutely no idea what to do now.
it's incredibly repairable. I still use the t480 for modern workloads because I've been able to switch out the battery, the fan, the keyboard with fairly abundant aftermarket parts.
sadly my t480's usb c port is no longer able to charge the device, do you know of a way to fix it without replacing the mobo / getting god tier soldering skills? i'm kinda attached since i did a bunch of upgrades like two heatpipes and glass touchpad, sad to see my laptop from college die for a reason like the port dying
This happens often on old ones. Its kind of a consumable part unless you get a magnetic usb-c adaptor.
the sub-board is replaceable but does need soldering....not god tier skills at all though, I think most people with some soldering experience could do it as it's just a few pins, but I guess it's not plug and play. It's really the one weakness in this model.
On virtually all t480's I've seen having a broken USB-C port it was only the left one (some people don't even realize there are two!) so you can charge using the second one and since it has thunderbolt you could connect a dock and both charge and have e.g. a monitor on one port(obviously?).
On my current t480 I also succeeded in slightly bending the port shell tighter and using a USB-C cable with tighter tolerances to get the port to be usable for charging again, but it's a not guaranteed trial and error solution.
what a small world! i did the port bend thing after the issues first popped up, but eventually that stopped working as well.
interestingly, when i try to charge from right / thunderbolt port, it doesn't seem to work / the led doesn't turn on, and I saw another post with a thunderbolt flash guide that i might look into. thanks to you and everyone else who commented, i think i have a new sidequest to end the weekend with : )
There was an old version of firmware that would brick the thunderbolt port. Something about every connect/disconnect cycle would write tons to the port's eeprom eventually bricking it.
I don't think there is a fix, it's more a case of if your T480 still works, get a newer firmware installed asap.
I have the same issue. For all the talk of USB-C's supposed design for redirecting damage from the ports to the connector, it failed pretty badly here for probably thousands of people. Never had these issues with a barrel connector.
The problem I always had with barrel connectors is that they get loose, sometimes very quickly, and this experience has been near-universal. Even the more fancy barrel-with-center-pin connector found on some PowerPC PowerBooks and iBooks wasn’t immune.
USB-C is definitely no panacea when it comes to durability, though. I’ve had better luck with Lightening and wish the USB-C connector took more inspiration from it.
yeah, same thing happened to my daily driver T480s, so I took precautions and now I use magnetic adapter on TB port since if that's gone whole computer is gone
I despise these new USB-C ports, never had such thing happen on proprietary Thinkpad ports over decades
Opus 5 also downgrades. it's now Fable -> Opus 5 ; Opus 5 -> Opus 4.8.
Unclear why they want to nerf their own products with sometimes right classifiers. I guess the government ban might've been real and not coordinated marketing?
I don't understand why people believe this conspiracy theory of "oh the government ban was just marketing". That claim feels so incredibly ridiculous to me. It cost Anthropic a ton of money and reputation, and worst of all: it absolutely killed their competitive advantage. They were 1-2 months ahead of OpenAI, but trump conveniently gave OpenAI the time they needed to catch up and push 5.6 out the door without having to lose their subscriber base to the competitor.
It has network filtering + placeholders for secrets.
OSS, no logins needed