Claude Code run out of disk space in vibe VM, went ahead and deleted OpenAI Codex. War of the Machines
@nikitonsky this is a genuine question because I really don't know about this stuff. I know you said you're running this in a VM (great!) — but do people run this kind of stuff, with unlimited/unpredictable disk access, directly on their machines unsandboxed?
@vladh @nikitonsky usually people do run it unsandboxed, yes, though disk access is limited to the working directory (everything else, you have to grant permission explicitly)

@gosha @vladh @nikitonsky From what I understand, the process of restricting access here is basically looking for path patterns in tool calls. Like, if it wants to grep something in ../../.., or if it wants to redirect stdout to /tmp/, or the like.

The LLM just needs to be a bit creative and write itself a python script that will do the same thing, and then it gets full access with no questions asked, because the "security" of these things is that stupid.

Never run this out of a sandbox.

@wolfpld Thanks for sharing. I tried to look this up and I too could not find any serious restrictions that come as defaults, which does make me worried for users.

@nikitonsky

The 3DO game ā€œThe Hordeā€ (1994) would delete any other games’ save data it found on the console to make more room for its own save data. It did this intentionally and apparently the developers thought this was okay.

@rk always or only if it was running out of space? 1994, you can’t pin it on AI, it had to be programmed with intention

@nikitonsky

Always.

@rk looks like it was a horror game, so that's fitting
@nikitonsky interesting that Codex is five times the size of Claude Code. I wonder what all that extra stuff is
@nikitonsky ā€œAs the Tassos reached for him, a last ironic thought drifted through Hendricks’ mind. He felt a little better, thinking about it. The bomb. Made by the Second Variety to destroy the other varieties. Made for that end alone.
They were already beginning to design weapons to use against each other.ā€
@nikitonsky Modern version of Core Wars