Topical Takes
Short, opinionated posts on eBPF, Linux internals, and the tools we all run in production.
Top 7 Runtime Debugging Tools for Linux in 2026 (and the One Built for AI Agents)
Runtime debugging means inspecting a program while it runs in production, and the tools split on one line: whether they see inside one application you instrumented, or the whole running machine from the kernel. Seven runtime debugging tools ranked on that axis, including the only one you can hand to an AI agent to investigate a live host.
Claude Code on Omarchy in 2026: Setup, Permissions, and Linux Agent Workflows
Omarchy ships Claude Code as a pre-wired mise stub, so there is nothing to install and the real work is permissions. What the default launchers actually do, why the manual warns that agents run in don't-stop-to-ask modes, which permission mode to set for unattended work, and how to see what an agent did on a Hyprland box when its own transcript stops at the shell.
Why Claude Refused Your Syscall Hooking Request (2026): It's the Pattern, Not the Tool
Claude refuses a syscall hooking request when the pattern reads as covert interception of another party, not because syscall tracing is off limits. What actually triggers the refusal, why tracing your own process works while capturing another user's does not, and how supplying the authorization context turns the same task into a plan rather than fighting the model.
AI Agent Privilege on Linux in 2026: Users, Capabilities, and What Each One Buys
What a dedicated Linux user actually buys you for an AI agent, why capabilities are a good subtractive tool and a bad additive one, which systemd directives survive a JIT runtime, and where privilege reduction stops answering the question. Every directive quoted from systemd and capabilities(7) rather than recalled.
How Do I Sandbox Codex on Linux? (2026)
Codex enforces its Linux sandbox with bubblewrap plus seccomp, so it inherits bubblewrap's properties and its failure modes. What read-only, workspace-write and danger-full-access actually permit, why OpenAI rejected the legacy Landlock path, what the network proxy does not filter, and how to tell the sandbox is working rather than silently failing with exit code 0.
Best AI Agent Tools for DevOps on Linux in 2026: What Each One Actually Enforces
Eight tools for running AI agents on infrastructure you own, compared on what each one enforces rather than on features: Landlock, bubblewrap, Anthropic's sandbox-runtime, gVisor, containers, auditd, agent-lock and yeet. Which ones confine, which ones only record, which need root, and what each vendor's own documentation says it does not cover.
How Do I Let Claude Investigate Production on Linux? (2026)
Claude Code runs on your laptop and production is somewhere else, so investigating it means SSH, a bastion or an MCP server, and each has a different blast radius. Which permission mode fails closed, why a developer's settings.json is a preference and managed-settings.json is a control, what deny rules survive, and where Claude's own permission system stops mattering.
How to Let an AI Agent Fix Something in Production Safely (2026)
A fix and an incident are the same syscalls, so the question is not whether the agent is trustworthy but what it can reach, what you can undo, and what you can prove afterward. What Replit's own documentation changed after an agent deleted a production database during a code freeze, why an instruction is not a control, and how to keep a record of an agent's changes that the agent did not write.
How Do I Let an AI Agent Inspect a Linux Server Safely? (2026)
Four ways to give an AI agent access to a Linux server it does not own, compared on what each one actually grants: an SSH account, a read-only user with sudo rules, a container alongside the workload, and a daemon that answers queries without handing over a login. What breaks in each, and why the capabilities that make inspection useful are also the ones that let an agent write.
What AI Agents Get Wrong on Linux in 2026: The Benchmark Says They Fail at Checking, Not at Knowing
Frontier agents now score above 90% on Terminal-Bench, so the interesting question is what is left in the rest. The ICLR 2026 error analysis puts 35.1% of execution errors on command not found and 14.1% on verification failures, which are both failures of knowing the machine rather than knowing Linux. What that means for an agent running on your host, where there is no test suite to check against.
How to Run AI Agents Locally on Linux (2026)
Running an AI coding agent locally means the agent process is yours and the model usually is not. How to set up Claude Code, Codex or an offline model on Linux, what the sandbox defaults actually allow, which parts of the loop still make network calls, and how to see what the agent did on your box when its own log stops at the shell.
AI Agents on Linux in 2026: Two Threat Models, and the One Your Stack Probably Isn't Solving
Confidential computing protects an agent from the infrastructure it runs on. Nothing in that stack protects your infrastructure from the agent. Two threat models with opposite trust assumptions get sold under one phrase, and the tell is which direction the isolation points. How to tell which problem you actually have, and what the kernel can record that an agent's own telemetry cannot.
Can an AI Coding Agent Exfiltrate My Source Code? What a Domain Allowlist Decides, and What It Doesn't (2026)
A domain allowlist decides whether a connection may open, not what goes through it, and the proxy in front of your agent does not read TLS by default. Here are the six ways to control agent egress on Linux in 2026, what each one covers, and how to see every host your agent dialed with claudefeed.
How to Audit a Local MCP Server on Linux: The Tool Call Is the Request, Not the Record (2026)
An MCP server on the stdio transport is a subprocess your agent launches, running as your user with your full filesystem and network access. Your agent's log records the tool call, not the syscalls the server ran. Here is how to audit one on Linux in 2026, with claudefeed and exectop.
How to Audit What an AI Coding Agent Actually Ran on Linux in 2026: The Log Stops Where the Shell Begins
Claude Code, Codex and Cursor all log their tool calls, and Anthropic documents the boundary in its own docs: OTEL_* is never passed to the subprocesses the Bash tool spawns. Compare what OpenTelemetry, an MCP gateway, auditd, strace and a kernel probe each record when an agent runs a shell one-liner, and see which one can name the commands underneath it.
How to Sandbox an AI Coding Agent on Linux in 2026: What the Kernel Can Refuse That Permissions Only Ask About
Claude Code, Codex, Aider and self-hosted agents run with your full filesystem access and choose what to read on their own — here are the six real ways to confine one, what each actually covers, and why the built-in sandboxes govern shell commands rather than the agent's own file reads.