Security
Stronger workspace isolation: a VM option and sealed previews
Workspaces get an extra system call filter, a new VM isolation class for untrusted code, and previews that can no longer reach your ZeroLog account.
Every workspace already ran on gVisor, a kernel in user space. Three things changed today.
- A tighter filter. gVisor now also blocks system calls a development environment does not need, such as kernel keyrings, module loading and the kernel log. We measured that common tools, builds and browsers still work.
- A VM class. When you create a container you can choose VM (its own small virtual machine with its own kernel) or VM + gVisor (the same, with gVisor inside). Use them for code you do not trust. They start a few seconds slower.
- Sealed previews. Websites and apps you preview from a container used to run under the zerolog.ch address. They now run in an isolated origin with their own access link, so code in a preview cannot use your session.
If gVisor is ever missing on a machine, workspaces there no longer start at all; before, they fell back to a weaker filter. See Isolation.