Hraness
Theme
Appearance

saved

unikernels were hard. key word: were.

by Geoffrey Huntleyghuntley.compublished

Hraness wrote this summary from a saved copy of the source. Quotations are taken word for word from the source.

gist

In a pub conversation with former MirageOS developer Justin Cormack, Geoffrey Huntley argues unikernels are back because AI removed their friction: missing libraries, drivers, and storage can now be ported in a loop. He calls the multi-user operating system design debt whose shell aids attackers, and says anyone serious about security should pick seL4 or seriously consider unikernels.

ideas

  • Hard was past tense. Concepts once dismissed as hard, like Nix, Bazel, and unikernels, are now in the model weights; the obstacle is dogma.
  • No shell, no next hop. Without a userland shell or interpreter, an exploited app gives attackers and models nothing to pivot with; Cormack counters that attack-surface reduction is fuzzy.
  • Port the gaps. Agents can port a Go Stripe library to OCaml, or rewrite mkfs.xfs in Rust against the original as a golden oracle; S3 plus a local NVMe cache covers storage.
  • Spaceleans. Huntley built NTP, networking, logging, and Microsoft Orleans in OCaml as a distributed unikernel in a week.
  • Back pressure picks languages. OCaml’s fast compiles and .mli files suit agents, slow Rust builds tax hallucination retries, and new languages like Cursed can be built for roughly US$6,000 per attempt.

quotes

“Unikernels were hard. Key word: were. Now we have AI.”

Geoffrey Huntley, the post’s thesis.

“Someone pops the userland application and gets a shell. That shell is a VIP butler service for exfiltration.”

Geoffrey Huntley, on why the operating system is design debt.

“if there's no shell and no interpreter, there's nothing in the model weights that knows what to do next.”

Geoffrey Huntley, on turning drive-by attacks into targeted ones.

“I did all of it in a week. I'll probably never release it, but it falsified the idea that unikernels are hard.”

Geoffrey Huntley, on Spaceleans, Microsoft Orleans ported to an OCaml unikernel.