WSL-style Linux machines for Linux hosts
nsl (NSpawn Subsystem for Linux) gives Linux hosts WSL-style persistent Linux machines: each machine is a whole distro with its own packages and services, running as a systemd-nspawn container inside one small VM. It starts on demand, keeps the host atomic, and integrates with your files, account, ports and desktop.
nsl opens a login shell in your default machine in the directory you were in, and nsl run executes a single command and returns its exit status. Machines are created with nsl create, e.g. nsl create debian --distro debian:13.
Your $HOME, /run/media/USER and /mnt appear at /mnt/host inside the machine. You keep your username, UID and GID, and get passwordless sudo inside the machine.
A server listening inside a machine is reachable at the same port on host 127.0.0.1, and Wayland applications running in the machine open windows on your desktop.
Debian, Ubuntu, Fedora, CentOS Stream, Arch, openSUSE Tumbleweed and openSUSE Leap machine images, rebuilt weekly and verified against the signed Frostyard publishing workflow before use.
--isolated gives a machine its own VM with no access to host files, desktop or host actions, for running software you do not trust.
nsl runs as your user, installs no host packages, and changes no device permissions, groups or sudoers.
Machines run as systemd-nspawn containers inside a single small VM that starts when you use it; the trust model and what a machine may touch on the host are documented in the architecture section.
Machine images are published for seven distros, rebuilt weekly, and verified against the signed Frostyard publishing workflow before use.
Free and open source under the MIT license.
It gives a Linux host persistent Linux machines, as WSL does for Windows. Each machine is a whole distro with its own packages and services, running as a systemd-nspawn container in one small VM that starts when you use it.
Create one with nsl create debian --distro debian:13 (images are verified against the signed Frostyard publishing workflow). Then nsl opens a login shell in your default machine in your current directory, and nsl run runs a single command and returns its exit status.
Yes. Your $HOME, /run/media/USER and /mnt appear at /mnt/host, and you keep your username, UID and GID with passwordless sudo inside the machine.
Seven signed distros: Debian, Ubuntu, Fedora, CentOS Stream, Arch, openSUSE Tumbleweed and openSUSE Leap. Images are rebuilt weekly.
Yes. --isolated gives a machine a VM of its own with no access to host files, desktop or host actions, for software you do not trust.
No. nsl runs as your user, installs no host packages, and changes no device permissions, groups or sudoers.
Yes, nsl is MIT licensed and part of Frostyard.
No. It has no stable release yet; v0.4.0 is the first release of this design, and v0.3.0 and earlier are a retired prototype. The tested host is Snow Linux 13 on x86-64 with systemd 261.2, QEMU 10.0.13, virtiofsd 1.13.2 and GNOME Wayland.