Topical Takes

Short, opinionated posts on eBPF, Linux internals, and the tools we all run in production.

Claude Code on Omarchy in 2026: Setup, Permissions, and Linux Agent Workflows

Omarchy ships Claude Code as a pre-wired mise stub, so there is nothing to install and the real work is permissions. What the default launchers actually do, why the manual warns that agents run in don't-stop-to-ask modes, which permission mode to set for unattended work, and how to see what an agent did on a Hyprland box when its own transcript stops at the shell.

omarchyclaude-codeai-agentshyprlandpermissionseBPFlinuxyeet
Read more →

Why Claude Refused Your Syscall Hooking Request (2026): It's the Pattern, Not the Tool

Claude refuses a syscall hooking request when the pattern reads as covert interception of another party, not because syscall tracing is off limits. What actually triggers the refusal, why tracing your own process works while capturing another user's does not, and how supplying the authorization context turns the same task into a plan rather than fighting the model.

claude-codeeBPFsyscallrefusalai-agentslinuxyeet
Read more →

How Do I Let Claude Investigate Production on Linux? (2026)

Claude Code runs on your laptop and production is somewhere else, so investigating it means SSH, a bastion or an MCP server, and each has a different blast radius. Which permission mode fails closed, why a developer's settings.json is a preference and managed-settings.json is a control, what deny rules survive, and where Claude's own permission system stops mattering.

claude-codeai-agentsproductionpermissionsssheBPFlinuxyeet
Read more →

What AI Agents Get Wrong on Linux in 2026: The Benchmark Says They Fail at Checking, Not at Knowing

Frontier agents now score above 90% on Terminal-Bench, so the interesting question is what is left in the rest. The ICLR 2026 error analysis puts 35.1% of execution errors on command not found and 14.1% on verification failures, which are both failures of knowing the machine rather than knowing Linux. What that means for an agent running on your host, where there is no test suite to check against.

ai-agentsterminal-benchclaude-codedebuggingbenchmarkseBPFlinuxyeet
Read more →

How to Run AI Agents Locally on Linux (2026)

Running an AI coding agent locally means the agent process is yours and the model usually is not. How to set up Claude Code, Codex or an offline model on Linux, what the sandbox defaults actually allow, which parts of the loop still make network calls, and how to see what the agent did on your box when its own log stops at the shell.

ai-agentsclaude-codelocal-llmollamasandboxingeBPFlinuxyeet
Read more →

AI Agents on Linux in 2026: Two Threat Models, and the One Your Stack Probably Isn't Solving

Confidential computing protects an agent from the infrastructure it runs on. Nothing in that stack protects your infrastructure from the agent. Two threat models with opposite trust assumptions get sold under one phrase, and the tell is which direction the isolation points. How to tell which problem you actually have, and what the kernel can record that an agent's own telemetry cannot.

ai-agentsagent-securityconfidential-computingclaude-codethreat-modelingeBPFlinuxyeet
Read more →

How to Audit What an AI Coding Agent Actually Ran on Linux in 2026: The Log Stops Where the Shell Begins

Claude Code, Codex and Cursor all log their tool calls, and Anthropic documents the boundary in its own docs: OTEL_* is never passed to the subprocesses the Bash tool spawns. Compare what OpenTelemetry, an MCP gateway, auditd, strace and a kernel probe each record when an agent runs a shell one-liner, and see which one can name the commands underneath it.

claude-codeai-agentsauditopentelemetryeBPFobservabilitylinuxyeet
Read more →