// HACKER NEWS — CYBERSECURITY
Show HN: Corral – Kill every command your agent starts
corral runs a command with a time limit. When corral returns, no process that
the command started is still alive. corral verifies this before it returns. If
it cannot prove it, corral exits with code 120.
AI coding agents and CI jobs run shell commands that they did not write. A
typical runner signals its child process or the child's process group, and then
waits until the output pipes close. This model fails in three common cases:
Leftover processes keep ports, file locks, and CPU, and the next run can fail
because of them.
corral controls the full process tree, not only its direct child. In enforced
mode, the command runs in its own cgroup v2 group, and one write to
cgroup.kill stops every process in the group. Without a cgroup, corral is a
child subreaper, so orphaned processes become its children. It finds the
remaining processes through /proc and signals them through pidfds. In both
modes, the run ends when the command exits, not when the pipes close.
corral is not a security sandbox. It does not limit file access, network
access, or privileges.
corral needs Linux 5.11 or later, and 5.14 or later for enforced mode.
The prebuilt binary is for x86-64 with glibc 2.36 or later (for example Ubuntu
22.10, Debian 12, or Fedora 37, or a later release):
To build from source, you need glibc 2.36, CMake 3.22, Ninja, and GCC 11 or
Clang 14. The tests need Python 3.10.
The default, --cgroup-mode=auto, uses enforced mode when it can.
A DURATION is a number with ms, s, m, or h. A SIZE is a number of bytes
with an optional K, M, or G.