BVisor
An Embedded Bash Sandbox, 2ms Boot, Written in Zig
Details
- External ID
- 47125966
- Source
- HN
- Company
- —
- Product
- BVisor
- Website domain
- github.com
- Launched
- Feb. 23, 2026
- Cohort
- —
- Upvotes
- 24
- Upvotes percentile
- 0.7183288409703504
- Tags
- —
- Fetched at
- Sept. 7, 2026, 9:25 p.m.
- Updated at
- Sept. 7, 2026, 9:25 p.m.
Description
bVisor is an SDK and runtime for safely executing bash commands directly on your host machine. We built it on the belief that "sandbox" doesn't need to mean shipping off to remote sandbox products, or spinning up local VMs / containers. Sometimes, you just want to run that bash command locally.bVisor boots a sandbox from user-space without special permissions, powered by seccomp user notifier. This allows us to intercept syscalls from guest processes and selectively virtualize them to block privilege escalation, isolate process visibility, and keep filesystem changes isolated per sandbox (copy-on-write). Sandboxes boot in 2ms, and can run arbitrary binaries at native speed (with minor overhead per syscall). This approach is heavily inspired by Google's gVisor.As of today, bVisor supports most filesystem operations, basic file I/O, and can run complex binaries such as python interpreters. It is packaged as a Typescript SDK and installable via npm. There's much to still implement (such as outbound network access to support 'curl', shipping a python SDK, etc), but we wanted to share it here for feedback and anyone who'd be able to make use of the current featureset!
Enrichment
- Theme
- lightweight and on-device AI runtimes
- Vertical
- Security
- Function
- Dev tools
- Audience
- Developer
- AI stance
- Not AI
- Project type
- Hobby / open-source project
- Normalized one-liner
- embedded bash sandbox in zig
- Manually corrected
- False
Could you build this?
No Creating a secure, sub-2ms embedded sandbox runtime in Zig that safely intercepts and sandboxes arbitrary Bash processes requires specialized systems programming and OS isolation primitives.
What it would actually take: This requires implementing low-level OS virtualization primitives such as Linux namespaces, cgroups, seccomp-bpf system call filtering, or ptrace-based syscall interception in Zig/C. The developer needs deep systems security and OS kernel expertise to guarantee isolation against escapes, fork bombs, and side-channel leaks without relying on traditional VM overhead.
Discussion
9 comments analyzed.
Competitors mentioned: E2B (dedicated VM alternative), napigen (NAPI bindings generator), zigpyUltimate (Python bridging for Zig)
Concerns raised: Whether it can fully replace dedicated VM providers like E2B, Syscall filtering/virtualization security model vs. full VM isolation
Competitors
Other products that read as similar to this one — 183 launches clear the similarity bar, closest 8 shown.
Attention rank: #66 of 184 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 104 days after the earliest competitor.
- Drop · hn · 2026-09-22 · 189 upvotes · similarity 0.49
- Tarit · hn · 2026-07-08 · 6 upvotes · similarity 0.46
- sandbin · ph · 2026-09-12 · 2 upvotes · similarity 0.45
- Bx · hn · 2026-04-07 · 8 upvotes · similarity 0.45
- Forkrun · hn · 2026-03-27 · 151 upvotes · similarity 0.45
- Sub-millisecond VM sandboxes using CoW memory forking · hn · 2026-03-17 · 311 upvotes · similarity 0.44
- Bsub.io · hn · 2025-11-17 · 23 upvotes · similarity 0.44
- Tiny VM sandbox in C with apps in Rust, C and Zig · hn · 2025-12-12 · 196 upvotes · similarity 0.44
Other launches for this product
- No other launches for this product.
Same idea, different domain
Nobody's really built a dev tools tool for Sales yet.