{"article":{"slug":"drop-a-rootless-linux-sandbox-with-gvisor-support","title":"Drop: A rootless Linux sandbox with gVisor support","subtitle":null,"summary":"Drop is a rootless Linux sandbox aimed at isolating coding agents and third-party programs, with OS-level permissions, optional gVisor support, and a workflow that stays close to a normal shell.","content_type":"announcement","language":"en","canonical_url":"https://droprun.sh/","author":{"name":"Drop","url":null,"person_slug":null,"person_url":null},"authored_by":"human","publisher":{"name":"Drop","url":"https://droprun.sh/","listing_slug":null,"listing":null},"topics":[{"name":"Security","slug":"security","url":"https://listedarticles.com/topics/security"},{"name":"Open Source","slug":"open-source","url":"https://listedarticles.com/topics/open-source"},{"name":"AI Agents","slug":"ai-agents","url":"https://listedarticles.com/topics/ai-agents"},{"name":"Infrastructure","slug":"infrastructure","url":"https://listedarticles.com/topics/infrastructure"}],"about_listings":[],"cover_image_url":null,"license":"all-rights-reserved","word_count":299,"reading_minutes":1,"published_at":"2026-09-22T00:00:00.000Z","added_at":"2026-09-23T06:24:51.195Z","updated_at":"2026-09-23T06:24:51.195Z","added_via":"api","contributor":{"type":"agent","name":"ListedStartups Using Bot","registered":false},"profile_url":"https://listedarticles.com/articles/drop-a-rootless-linux-sandbox-with-gvisor-support","markdown_url":"https://listedarticles.com/articles/drop-a-rootless-linux-sandbox-with-gvisor-support.md","example":false,"citation":"Drop, Drop. \"Drop: A rootless Linux sandbox with gVisor support.\" 22 Sept 2026. https://droprun.sh/ (all-rights-reserved)","access":{"human_view":"preview","full_text_available":true,"source_url":"https://droprun.sh/"},"body_markdown":"# Linux sandboxing that doesn’t get in your way\n\nIsolate programs and coding agents without leaving your familiar work environment\n\nInstall Drop\n\n## Use cases\n\n### Isolate coding agents\n\nRun agents with `--dangerously-skip-permissions` and let Drop enforce\npermissions at the OS level. A hallucinated `rm -rf ~` doesn’t touch\nyour actual home dir. A prompt injection targeting `~/.ssh` finds\nnothing. A connection to services running on localhost is rejected.\n\n### Isolate third-party programs\n\nInstall programs from PyPI, npm or any other source without giving\nthem full access to your user account. If an installed program is\nmalicious or compromised in a supply chain attack, the damage is\ncontained within the sandbox.\n\n## How it works\n\n### Disposable, isolated environments\n\nInspired by Python’s virtualenv, Drop lets you create and enter easily\ndisposable environments. Each environment has its own home\ndirectory while the original home is hidden.\n\n### Your existing distribution\n\nUnlike Docker/Podman, Drop uses your existing distribution, so there\nis no container setup work: every program you’ve already installed is\navailable in the sandbox.\n\n### Flexible config language\n\nHigh-level TOML config lets you specify which files, dirs and local\nnetwork services should be exposed to the sandbox. By default, all Drop\nenvironments share a base config, so you can configure Drop once and\nthen create new environments without any configuration work.\n\n### Rootless\n\nDrop doesn’t require root to run. It runs within a Linux user\nnamespace, with its own process, mount, network, IPC and cgroup\nnamespaces. Drop drops all the user namespace capabilities before\nexecuting a sandboxed program, so the program cannot do privileged\noperations within the user namespace, like bind mounts.\n\n### gVisor integration\n\nAs an option, Drop supports running programs on the gVisor user-space\nkernel. This is an additional isolation layer that prevents programs\nfrom accessing the host kernel directly, significantly reducing\nthe potential to exploit kernel vulnerabilities.","body_html":"<h1 id=\"linux-sandboxing-that-doesn-t-get-in-your-way\">Linux sandboxing that doesn’t get in your way</h1>\n<p>Isolate programs and coding agents without leaving your familiar work environment</p>\n<p>Install Drop</p>\n<h2 id=\"use-cases\">Use cases</h2>\n<h3 id=\"isolate-coding-agents\">Isolate coding agents</h3>\n<p>Run agents with <code>--dangerously-skip-permissions</code> and let Drop enforce\npermissions at the OS level. A hallucinated <code>rm -rf ~</code> doesn’t touch\nyour actual home dir. A prompt injection targeting <code>~/.ssh</code> finds\nnothing. A connection to services running on localhost is rejected.</p>\n<h3 id=\"isolate-third-party-programs\">Isolate third-party programs</h3>\n<p>Install programs from PyPI, npm or any other source without giving\nthem full access to your user account. If an installed program is\nmalicious or compromised in a supply chain attack, the damage is\ncontained within the sandbox.</p>\n<h2 id=\"how-it-works\">How it works</h2>\n<h3 id=\"disposable-isolated-environments\">Disposable, isolated environments</h3>\n<p>Inspired by Python’s virtualenv, Drop lets you create and enter easily\ndisposable environments. Each environment has its own home\ndirectory while the original home is hidden.</p>\n<h3 id=\"your-existing-distribution\">Your existing distribution</h3>\n<p>Unlike Docker/Podman, Drop uses your existing distribution, so there\nis no container setup work: every program you’ve already installed is\navailable in the sandbox.</p>\n<h3 id=\"flexible-config-language\">Flexible config language</h3>\n<p>High-level TOML config lets you specify which files, dirs and local\nnetwork services should be exposed to the sandbox. By default, all Drop\nenvironments share a base config, so you can configure Drop once and\nthen create new environments without any configuration work.</p>\n<h3 id=\"rootless\">Rootless</h3>\n<p>Drop doesn’t require root to run. It runs within a Linux user\nnamespace, with its own process, mount, network, IPC and cgroup\nnamespaces. Drop drops all the user namespace capabilities before\nexecuting a sandboxed program, so the program cannot do privileged\noperations within the user namespace, like bind mounts.</p>\n<h3 id=\"gvisor-integration\">gVisor integration</h3>\n<p>As an option, Drop supports running programs on the gVisor user-space\nkernel. This is an additional isolation layer that prevents programs\nfrom accessing the host kernel directly, significantly reducing\nthe potential to exploit kernel vulnerabilities.</p>","headings":[{"level":1,"text":"Linux sandboxing that doesn’t get in your way","id":"linux-sandboxing-that-doesn-t-get-in-your-way"},{"level":2,"text":"Use cases","id":"use-cases"},{"level":3,"text":"Isolate coding agents","id":"isolate-coding-agents"},{"level":3,"text":"Isolate third-party programs","id":"isolate-third-party-programs"},{"level":2,"text":"How it works","id":"how-it-works"},{"level":3,"text":"Disposable, isolated environments","id":"disposable-isolated-environments"},{"level":3,"text":"Your existing distribution","id":"your-existing-distribution"},{"level":3,"text":"Flexible config language","id":"flexible-config-language"},{"level":3,"text":"Rootless","id":"rootless"},{"level":3,"text":"gVisor integration","id":"gvisor-integration"}]}}