2026年8月22日土曜日

WSL2上のOpen Code実行環境のセキュリティを...

OpenCodeのインストール
$ curl -fsSL https://opencode.ai/install | bash
Installing opencode version: 1.18.11
■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■ 100%
Successfully added opencode to $PATH in /home/alfaalfa/.bashrc

▄
█▀▀█ █▀▀█ █▀▀█ █▀▀▄ █▀▀▀ █▀▀█ █▀▀█ █▀▀█
█░░█ █░░█ █▀▀▀ █░░█ █░░░ █░░█ █░░█ █▀▀▀
▀▀▀▀ █▀▀▀ ▀▀▀▀ ▀ ▀ ▀▀▀▀ ▀▀▀▀ ▀▀▀▀ ▀▀▀▀

OpenCode includes free models, to start:

cd # Open directory
opencode # Run command

For more information visit https://opencode.ai/docs

OpenTUIエージェントはBun(高速なJavaScriptランタイム・ツールキット)を使用してるようなので、
Bunをインストールします。
$ sudo apt update

$ curl -fsSL https://bun.sh/install | bash
######################################################################## 100.0%
bun was installed successfully to ~/.bun/bin/bun

Added "~/.bun/bin" to $PATH in "~/.bashrc"

To get started, run:

source /home/alfaalfa/.bashrc
bun --help

$ cat .bashrc
# ~/.bashrc: executed by bash(1) for non-login shells.
# see /usr/share/doc/bash/examples/startup-files (in the package bash-doc)
# for examples
~省略~
# bun
export BUN_INSTALL="$HOME/.bun"
export PATH="$BUN_INSTALL/bin:$PATH"

$ source ~/.bashrc

$ bun --version
1.4.0

WSL2上でOpen Codeを実行する時のセキュリティについて調べてみると、
WSL2からWindowsのアプリを実行したり、ドライブの内容が参照出来たりするのは良くないそうです。
そりゃ、そうか。
少しでも心配を減らすために、上記の2点を止めたいと思います。
「/etc/wsl.conf」を編集してWSLを再起動します。
$ cat /etc/wsl.conf
[boot]
systemd=true

[user]
default=alfaalfa

[interop]
enabled = false
appendWindowsPath = false

[automount]
enabled = false

変更後の確認
$ notepad.exe
notepad.exe: command not found

$ df を実行して「/mnt/c」とかのWindows上のドライブをマウントしてないこと

以上です。

0 件のコメント: