Drop: Rootless Linux Sandboxing with gVisor Support

Drop provides rootless isolation for Linux applications

Drop is a Linux sandboxing tool designed to isolate programs and AI coding agents without requiring the user to leave their existing work environment. Unlike traditional containers, Drop leverages the host's existing distribution, meaning all previously installed programs are available within the sandbox without the need for container image setup.

Core Architecture and Security Model

Drop utilizes Linux user namespaces to create disposable, isolated environments. It implements a security model based on the following primitives:

  • Namespace Isolation: Drop creates separate process, mount, network, IPC, and cgroup namespaces. This ensures that sandboxed processes have their own process tree and network stack, isolated from the host.
  • Rootless Execution: The tool does not require root privileges to run. It drops all user namespace capabilities before executing the sandboxed program, preventing the program from performing privileged operations like bind mounts within the namespace.
  • Filesystem Virtualization: Each environment is assigned its own writable and persistent home directory. The original host home directory is hidden by default, preventing sandboxed processes from accessing sensitive files like SSH keys.
  • gVisor Integration: For higher security requirements, Drop supports the gVisor user-space kernel. This adds a layer of insulation between the sandboxed application and the host kernel, reducing the attack surface for kernel exploits.

Primary Use Cases

Drop is specifically optimized for two high-risk scenarios:

  1. Isolating Coding Agents: AI agents can be run with the --dangerously-skip-permissions flag, allowing Drop to enforce permissions at the OS level. This prevents hallucinated commands (e.g., rm -rf ~) or prompt injections from affecting the actual host home directory or accessing local services.
  2. Third-Party Program Isolation: Programs installed via package managers like PyPI or npm can be run within Drop to contain the damage of supply chain attacks or malicious packages.

Configuration and Workflow

Drop uses a high-level TOML configuration language to define which files, directories, and local network services are exposed to the sandbox. To streamline the workflow, Drop implements a base configuration that is shared across environments, allowing users to create new isolated spaces without repetitive configuration work.

Community Perspectives and Comparisons

Users and developers in the Hacker News community have compared Drop to other isolation tools, highlighting several trade-offs:

  • Comparison to Bubblewrap (bwrap): While both use namespaces, Drop provides a more structured environment management system (similar to Python's virtualenv) and optional gVisor support, whereas bwrap is often used for ad-hoc, manual configuration.
  • Comparison to Containers (Docker/Podman): Users noted that Drop's primary advantage over standard containers is the lack of image management overhead; it uses the host's existing binaries and libraries.
  • Current Limitations: Early adopters have identified challenges in developing GUI applications with hardware acceleration (e.g., games) and managing containerized applications that require docker-compose within the sandbox.

"I've been very happy with it so far... it nails the convenience vs isolation aspect quite well, and I would like to get to a point where I can use it for all my development by default."

"I'm definitely going to try this out and see how well it works for me. It's insane to me that this is something none of the big AI companies have bothered solving this yet other than via opaque rules built into their harnesses."

Sources

Related

  • Dispatch
  • Dispatch
  • Project
  • Dispatch
  • Project