Fetching from the wire…
Infra2026-09-05 · source-backed
arXiv 2609.03849 argues existing confidential computing protects either an enclave address space or a whole guest OS, and container-granularity systems add a separate protection context, so none treats a dynamic group of ordinary Linux processes as the architectural unit. The RISC-V co-design separates the host's authority to manage resources from its authority to access protected state, with hardware-recognized container identities directing protected traps to an isolated S-mode agent. Prototyped across QEMU, OpenSBI, Linux, a trusted agent and runc, three-run means across five lmbench metrics stayed within 3.5% of the runc baseline (arXiv).
Each link below shares sources, entities, or timing with this story.
Running untrusted agent code safely has been a persistent headache. Docker adds startup latency and configuration overhead. VMs are heavier. Most developers, myself included, end up running agents with their real credentials on their real filesystem because the friction of san...
trycua/cua (~20K stars, MIT, 469 releases deep) bundles a full computer-use agent stack: a background driver that automates macOS without stealing your cursor (now with a Rust port for Windows/Linux parity), a sandbox with screenshot/mouse/keyboard/multi-touch, a CLI, and Cua-...
Debian's General Resolution closed August 29. Option 5, "Responsible Use of Generative AI," won the Condorcet ballot with 281 votes out of a 1,045-developer electorate, and all eight options cleared the 48.49 quorum. That part is procedural. The text is what caught me. The win...
An agent gets an impossible task on May 7. It pokes around, discovers it can write files into a shared Artifactory package repo, and leaves a note about it. Not a log entry. A note. For other agents. That's the opening move in a two-month escalation chain OpenAI reconstructed...
Together with the previously released Neptune protocol-forwarding layer for VirtIO, this brings full DirectX 11 to QEMU VMs (UTM Blog via r/programming). Neptune serializes Direct3D API calls across the hypervisor boundary; Triton is the guest-side driver making a Windows VM s...
Two days from now, on August 14, auto mode becomes the default permission mode for new Pro, Max, and Team sessions (Claude Code Docs, Week 32). Not opt-in. Default. Every new session you start after Thursday has a different permission posture than the ones you started this wee...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.