Posts for the month of October 2026

Sllim release 0.19

wordmark-black-on-white.svg

Sllim version 0.19 is available at https://retracile.net/git/sllim.git, and the project page is Sllim.

The small stuff

Sllim now targets Python 3.11 or newer; on Rocky Linux 9, use python3.12. I've added more looping inference detection to catch more ways models (especially heavily quantized variants) wind up spiraling unproductively burning tokens. And there are many bugfixes for bugs found while using the tool and from asking a model to review the code for bugs to fix.

New functionality

And one significant feature: DNF mirror proxying

For profiles configured with a VM-based sandbox, you could configure a whitelist of HTTP operations and sites the agent could access. But crafting a regex that would allow access to all the Fedora RPM repo mirrors was not viable. You could create a regex to cover them all, but it would be quite leaky. In practice, I would have to configure the whitelist with a wildcard entry, run sllim profile sandbox -c "dnf install -y git", and then remove the wildcard. The obvious problems there include a) forgetting to revert the wildcard, thus allowing the agent unrestricted internet access, and b) having to install tools the agent needs instead of letting the agent figure out what it needed and handle it.

So I added DNF-specific logic to allow requests to the various mirrors while retaining the network filtering. If you have a profile configured with a (Fedora) VM and filtered networking, you can run sllim profile update my-profile --dnf-mirror https://mirrors.fedoraproject.org And then the agent is able to run sudo dnf install -y git (or tesseract, or whatever) as it discovers a need for it.

Details

One feature of DNF that I wanted to preserve was its mirror speed tracking. In particular, I did not want to have to implement logic to figure out what mirrors work well and which are slow. After all, dnf already does that. But that means I couldn't collapse all requests to one hostname: dnf would no longer have visibility into the different mirrors. Nor did I want to have to try to match every request against all the different potential prefixes. So instead, I took each mirror in the mirror list, and replaced its base URL with a name like <hash>.dnfmirror.local/. Then, when a request comes in, dnfmirror.local addresses are handled by the DNF proxy logic, the hash is looked up to find the original base URL, the real URL is constructed, and the connection is made.

Conclusion

I've found that when agents know they can install software via dnf, they'll grab the tools they need that you didn't anticipate, and get the job done. The tesseract example above was from a real scenario where I was running a text-only model and it needed to extract text from images. It installed tesseract, extracted the data from the images, and completed the assignment.

Enabling sudo dnf install has been a significant upgrade in Sllim's capabilities.