Distrobox mounts $HOME in the container at $HOME by default. WSL and NSL do not, and that's my preference. This means you can install tools that change your default path, change your dotfiles, etc, without affecting the host. The other obvious difference is that distrobox is powered by podman or docker, while NSL uses a VM that runs systemd-nspawn containers.
none of the above. a single vm started by systemd-vmspawn which then starts one or more containers for your instances using systemd-nspawn. It ends up being fast and lightweight.
This is most useful to people who run Linux as their daily driver so rather than saying its like WSL can you explain what it offers that existing Linux containers do not?
Its also sounds different from WSL which I thought is a VM rather than a container.
> It's yet another step in my long journey to keep my host installation free from all the changing and breaking dev dependencies that force a reinstall every few months.
Something that also require a bit of explanation. What do you do that makes this such a common problem.
WSL2 uses a shared VM that does host integration (networking, shared files, permanent storage for each instance). NSL uses the same model but with Linux native technical implementations.
As for keeping my host clean - it's the developer's curse that always gets me. Install libWhatever3.2-dev because you need it to compile something, then don't realize until next time you open Chrome that it broke your system in some subtle way. There are dozens of ways to solve this like devcontainers, docker, incus, fully separate or remote vms. I like the WSL2 model so I wanted that same UX.
So a single VM with multiple containers within it? Interesting, but I think you should make it immediately clear on your site. Persistence is not the USP because there are lots of ways that you can get persistent VMs or sandboxes.
Nope. This is a VM, with containers inside. And the containers weren't "re-implemented", it uses existing systemd containers. That's what I was able to learn by skimming the site for 30 seconds. Did you not even do that? And why even be so condescending to someone else's project?
Because it does seem like we already have tools that skin this particular cat, it's valid to wonder what value this project provides over existing solutions.. even if they chose the wrong example to compare it to. Why do you think that's condescending?
LXC is a jail and qemu is an extra layer of emulation. Why pay that extra cost? Just because it serves a wsl image isn't really an answer. How is that worth the extra layer?
I have to say this is nice packaging. It is weirdly not obvious how nice it is to cleanly use a different “machine” inside your desktop.
I never thought I’d prefer WSL to even my MacBook for working with remote servers and dev but somehow I do.
I of course know the many ways to roll something like this for myself, yes dev containers are better for many things etc. but it’s wierd how good the ergonomics of a WSL like container are.
Thanks for saying so! That's exactly why I wrote this. The UX of wsl2 is just right. There are a lot of other ways to accomplish this, but none touch that same experience.
I'm confused why VM + systemd-nspawn? From my understaing WSL 2 runs a single VM + something like systemd-nspawn per "linux installation", but it runs a VM because it needs linux kernel. Why not just do systemd-nspawn if you alread on linux?
I'd trust OP to make good architectural decisions/provide guidance even if AI mostly wrote the docs and UI. Looking into their GitHub, seems they are an engineering manager at Microsoft and contribute semi regularly to uBlue and Project Bluefin. Should be better quality than some random vibeslopper.
I was surprised I hadn't heard of this as a separate tool from systemd-nspawn. Then I realized why... the GitHub repo shows version 0.6 released in 2022, then version 1.0.0 last week, followed by a flurry of releases up to 1.8.0 yesterday.
So basically, it's been all Claude'd up extremely recently.
That said, the landing page, docs, and git README are much higher quality than I normally see out of LLM-generated projects, so at least the author knows how to reign in the needless verbosity and write for a technical audience. So I will give him credit for that at least.
Way better isolation, is my guess. Plus, you can use a different kernel this way.
I used to poo-poo when people said that containers aren't a _real_ security boundary, at least for personal stuff, and not a multi-tenant server. But I bet even mid-tier LLMs can break out of LXC/Docker/nspawn at this point.
"During a test conducted by Trail of Bits researcher Artem Dinaburg, a preview version of GPT 5.6-Cyber was tasked with breaking out of a Debian 12 virtual machine. Initially, the agent exploited a known Linux kernel vulnerability, CVE-2026-53359, by developing its own exploit. After the host was updated, the agent found another pathway through libslirp, chaining a known vulnerability (CVE-2026-9539) with a previously unassigned bug to gain arbitrary host memory access. Even after QEMU and libslirp were updated, the agent analyzed system components and constructed a new escape chain using three zero-day vulnerabilities and one KVM flaw that had not yet reached the distribution kernel.
These findings suggest that general-purpose VMs may not be adequate security boundaries for highly capable AI agents, especially in older systems with delayed security updates. Trail of Bits recommends using specialized isolation systems like Firecracker, restricting VM access, and implementing rapid patching to mitigate these risks."
CVEs for runc are much more frequent than CVEs for KVM. The attack surface area is bigger, and containers were never intended as a security boundary, but rather as a resource management tool.
The name WSL has always struck me as a bit back area (LSW would seem to make more sense, since it is a Linux subsystem for Windows). I guess they mean it as a Windows Subsystem for Linuxing.
Anyway, should this be called LSL or WSLL? Or maybe LSWSL.
The naming is a bit awkward now, but an original design goal of the Windows NT kernel was the ability to host different types of OS "personalities" (userspace, essentially) on top of the Windows kernel, and these are called "subsystems." Win32 is one such subsystem, although there was no need to formally call it "Windows Subsystem for Win32" because everyone understood that it was just Win32 ported to NT.
The NT kernel designers came from VMS, and during development MS made various half-hearted promises that NT would be able to run VMS software as well but never actually followed through. If they had, there would likely have been a Windows Subsystem for VMS.
It makes an image and runs it in separate namespace. It can start at bash or init. It's very fast but there seem to be a problem creating an Ubuntu image on Debian and vice versa.
Is the VM layer mostly for host hygiene, or are you also treating the instances as a real security boundary when something untrusted (deps or agent-written code) runs inside?
thayne | 5 hours ago
[OP] bketelsen | 5 hours ago
NekkoDroid | 24 minutes ago
To be fair, WSL mounts all your drives under /mnt/ by default, which I would argue isn't any better, arguably even worse.
the_real_cher | 5 hours ago
mhitza | 5 hours ago
smw | 5 hours ago
[OP] bketelsen | 5 hours ago
the_real_cher | 2 hours ago
It's an interesting project.
Are these systemd containers comparable to lxc containers or better maybe?
This could be a really interesting alternative to fully featured LXC containers.
Ubuntu has a similar cli tool you probably know about called multi-pass but it just spins up Ubuntu distros.
The issue I had with multipass was how difficult it was to access and backup files, I guess it was meant for more of a disposable container.
varispeed | 5 hours ago
The website's Claudisms are unbearable.
graemep | 5 hours ago
Its also sounds different from WSL which I thought is a VM rather than a container.
> It's yet another step in my long journey to keep my host installation free from all the changing and breaking dev dependencies that force a reinstall every few months.
Something that also require a bit of explanation. What do you do that makes this such a common problem.
[OP] bketelsen | 5 hours ago
As for keeping my host clean - it's the developer's curse that always gets me. Install libWhatever3.2-dev because you need it to compile something, then don't realize until next time you open Chrome that it broke your system in some subtle way. There are dozens of ways to solve this like devcontainers, docker, incus, fully separate or remote vms. I like the WSL2 model so I wanted that same UX.
graemep | 3 hours ago
kevin_thibedeau | 2 hours ago
rpcope1 | 5 hours ago
pkulak | 5 hours ago
ktm5j | 5 hours ago
nurettin | 4 hours ago
pkulak | 4 hours ago
failbuffer | 4 hours ago
pkulak | 4 hours ago
RandomGerm4n | 5 hours ago
KyleGospo | 4 hours ago
rao-v | 5 hours ago
I never thought I’d prefer WSL to even my MacBook for working with remote servers and dev but somehow I do.
I of course know the many ways to roll something like this for myself, yes dev containers are better for many things etc. but it’s wierd how good the ergonomics of a WSL like container are.
[OP] bketelsen | 4 hours ago
snapplebobapple | an hour ago
dingaling911 | 5 hours ago
Now all you have to do is run NSL under WSL.
[OP] bketelsen | 5 hours ago
0x457 | 5 hours ago
delusional | 5 hours ago
nateb2022 | 4 hours ago
[OP] bketelsen | 4 hours ago
0x457 | 4 hours ago
bityard | 2 hours ago
So basically, it's been all Claude'd up extremely recently.
That said, the landing page, docs, and git README are much higher quality than I normally see out of LLM-generated projects, so at least the author knows how to reign in the needless verbosity and write for a technical audience. So I will give him credit for that at least.
pkulak | 4 hours ago
I used to poo-poo when people said that containers aren't a _real_ security boundary, at least for personal stuff, and not a multi-tenant server. But I bet even mid-tier LLMs can break out of LXC/Docker/nspawn at this point.
fhn | 4 hours ago
pkulak | 4 hours ago
esseph | 3 hours ago
esseph | 3 hours ago
---
"During a test conducted by Trail of Bits researcher Artem Dinaburg, a preview version of GPT 5.6-Cyber was tasked with breaking out of a Debian 12 virtual machine. Initially, the agent exploited a known Linux kernel vulnerability, CVE-2026-53359, by developing its own exploit. After the host was updated, the agent found another pathway through libslirp, chaining a known vulnerability (CVE-2026-9539) with a previously unassigned bug to gain arbitrary host memory access. Even after QEMU and libslirp were updated, the agent analyzed system components and constructed a new escape chain using three zero-day vulnerabilities and one KVM flaw that had not yet reached the distribution kernel.
These findings suggest that general-purpose VMs may not be adequate security boundaries for highly capable AI agents, especially in older systems with delayed security updates. Trail of Bits recommends using specialized isolation systems like Firecracker, restricting VM access, and implementing rapid patching to mitigate these risks."
---
https://www.scworld.com/brief/ai-agent-repeatedly-escapes-vi...
bloppe | 3 hours ago
bee_rider | 4 hours ago
Anyway, should this be called LSL or WSLL? Or maybe LSWSL.
dspillett | 3 hours ago
bityard | 3 hours ago
The NT kernel designers came from VMS, and during development MS made various half-hearted promises that NT would be able to run VMS software as well but never actually followed through. If they had, there would likely have been a Windows Subsystem for VMS.
michaelastreiko | 4 hours ago
bezko | 4 hours ago
bita_nidir | 3 hours ago
FWIW, I'm currently using systemd-nspawn via mkosi: https://github.com/systemd/mkosi
It makes an image and runs it in separate namespace. It can start at bash or init. It's very fast but there seem to be a problem creating an Ubuntu image on Debian and vice versa.
codr1 | 3 hours ago
28304283409234 | 3 hours ago
teeskay | 3 hours ago
naman_307 | 44 minutes ago