







A dynamic library providing Virtualization-based process isolation capabilities
Vercel Sandbox
Vercel Sandbox allows you to run arbitrary code in isolated, ephemeral Linux VMs.
anthropic-experimental/sandbox-runtime
A lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrary processes at the OS level, without requiring a container.
smol machines — ship and run software with isolation by default
Run any workload in a fast, hardware-isolated Linux VM. The same SDK and the same .smolmachine artifact run identically:
Why AVF?
AVF and pKVM: next-generation Trustworthy Execution Environment for connected products

TEE.fail: Breaking Trusted Execution Environments via DDR5 Memory Bus Interposition
Breaking Trusted Execution Environments via DDR5 Memory Bus Interposition

Intent to Prototype: Isolated Web Apps
https://github.com/reillyeon/isolated-web-apps/blob/main/README.md
Cross-Platform File System Operations Based on libuv
A cross-platform interface to file system operations, built on top of the libuv C library.

Sprites - Stateful sandboxes
Persistent, hardware-isolated execution environments for arbitrary code. Run AI agents, untrusted code, and more in secure sandbox environments with checkpoint & restore.
Genode - Genode Operating System Framework
We understand the complexity of code and policy as the most fundamental security problem shared by modern general-purpose operating systems. Because of high functional demands and dynamic workloads, however, this complexity cannot be avoided. But it can be organized. Genode is a novel OS architecture that is able to master complexity by applying a strict organizational structure to all software components including device drivers, system services, and applications. The Genode OS framework is an open-source tool kit for building highly secure component-based operating systems. It scales from embedded devices to dynamic general-purpose computing.
Tock OS A Rust Based Open Platform for Transparent and Secure Root of Trust Devices
Windmill | Build, deploy and monitor internal software at scale
Open-source workflow engine to build workflows, data pipelines and internal tools at scale. Self-hostable, for developers and AI, with enterprise security.

oss-security - Dirty Frag: Universal Linux LPE
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
How programs get run: ELF binaries
The previous article in this series described the general mechanisms that th [...]
Apptainer - Portable, Reproducible Containers
Apptainer is an open source container platform designed to run complex applications on high-performance computing (HPC) clusters in a simple, portable, and reproducible way.
Kernel Probes (Kprobes) — The Linux Kernel documentation
Kprobes enables you to dynamically break into any kernel routine and collect debugging and performance information non-disruptively. You can trap at almost any kernel code address [1], specifying a handler routine to be invoked when the breakpoint is hit.
Exploring the idea of self-hosting a Bluesky PDS alongside my Indiekit instance — turning it into a dual-protocol server that federates over both ActivityPub and AT Protocol simultaneously. Inspired by Wafrn’s approach, adapted to Indiekit’s plugin architecture and Cloudron deployment. The goal: ow…
Ricardo Mendes
rmendes.net