The browser, the sandbox and VMs
How Homeling uses websites and runs code, and how to watch it do so.
How Homeling uses websites
In Homeling: Settings → Browser → Which browser Homeling drives
- In-app browser: a private web view inside Homeling.
- Chrome: a Chrome window you can watch, with its own Homeling profile, never yours.
- In a sandbox you can watch: Chromium inside a small Linux computer on your Mac (below).
- Automatic: Chrome when it's installed, otherwise the in-app one.
Whichever you pick, the same checks apply: before Homeling submits a form, signs in or buys something on a page, it asks you (approvals). The Mac App Store version always uses the in-app browser. “Overnight jobs may use Chrome without a window” lets background work run Chrome hidden; while you're using Homeling, Chrome always shows its window.
Watch it in the sandbox
Choose “In a sandbox you can watch” and Homeling browses in Chromium inside a separate Linux computer that runs on your Mac. Open Sandbox in the sidebar (⌘7) to see its screen as it works. It's view-only until you click Let me take over; Stop ends Homeling's session.
The first time, it downloads about 700 MB, and it uses about 2 GB of memory while it runs. It's in the download from homeling.ai, on Macs that can run it.
VMs for running code
When a request needs code to run, Homeling runs it in a small Linux computer of its own, a VM, one per chat or job, so what it runs stays inside the VM and the one folder it shares with it. Each gets 2 processor cores and 1 GB of memory, and stops after 10 idle minutes. To reach a website from inside, Homeling asks you first, one site at a time.
VM terminal in the sidebar (⌘6) shows every command and its output as it runs. Stop stops a VM now (the next command starts it again); Destroy removes it and its disk, and the task's shared folder stays. A chat shows “Running in a VM” while it works. VMs are in the download from homeling.ai only.
Saved logins
In Homeling: Settings → Logins
Save a login or an API key so Homeling can sign in to a site for you. Homeling uses a saved login by its name only: it fills a login only on that login's own site, adds an API key only to requests to its own host, and never sees, logs or exports the value. An export with a passphrase carries them sealed.