---
title: "Running a Linux AI Agent on FreeBSD, Then Letting It Lock Its Own Doors"
description: "Claude Code ships no FreeBSD build, so one user reached for the Linuxulator — and, eventually, a dead-man’s switch"
author: "Nate Ledger"
published: 2026-10-06T22:00:00Z
modified: 2026-10-07T20:37:51Z
url: https://rews.cc/a/running-a-linux-ai-agent-on-freebsd-then-letting-it-lock-its-c536a3
language: en
tags: ["freebsd", "linuxulator", "kde", "xrdp", "ai", "tech"]
publisher: "Rews (https://rews.cc)"
---

# Running a Linux AI Agent on FreeBSD, Then Letting It Lock Its Own Doors

*Claude Code ships no FreeBSD build, so one user reached for the Linuxulator — and, eventually, a dead-man’s switch*

By Nate Ledger · October 6, 2026 · https://rews.cc/a/running-a-linux-ai-agent-on-freebsd-then-letting-it-lock-its-c536a3

## In brief

- Christian Hofstede-Kuhn ran Claude Code’s Linux binary on a FreeBSD 15.1 desktop VM via the Linuxulator
- FreeBSD translates the binary’s system calls; a Rocky Linux 9 userland under /compat/linux fakes a Linux 5.15.0 kernel
- Getting Plasma usable over xrdp needed the scfb driver and a VirtIO-GPU framebuffer, still without GPU acceleration
- The author then had the agent firewall the machine it ran on, using a dead-man’s switch verified from a fresh SSH session

The plan, Christian Hofstede-Kuhn writes, was boring on purpose: a FreeBSD desktop VM on his Proxmox cluster running KDE Plasma, reachable from any machine — “something to live in, not something to admire.” Then he wanted Anthropic’s Claude Code on it. [Writing on his blog](https://blog.hofstede.it/claude-code-on-a-freebsd-desktop-plasma-xrdp-the-linuxulator-and-one-very-confusing-path/), he notes the small problem: Claude Code ships no FreeBSD binary. It does ship a Linux one, and FreeBSD has been running Linux binaries through its Linuxulator for decades. He had already done it for a Factorio server. How hard could an AI coding agent be?

It is worth being precise about what was actually running, because the trick is older and cleaner than it sounds. Claude Code was not running “natively” and was not being emulated. It is an unmodified Linux ELF binary; the FreeBSD kernel recognizes the Linux brand and translates its system calls through the Linuxulator. There is no Linux kernel anywhere — no VM, no container. But the binary expects glibc and a Linux-shaped filesystem, which lives under /compat/linux, courtesy of a Rocky Linux 9 userland package called linux\_base-rl9.

That arrangement gives the machine two faces. Native FreeBSD processes see the real system; Linux processes see the compat tree as their root. Ask /compat/linux/bin/uname what it thinks it is and it answers “Linux bsdesktop 5.15.0” — a kernel version read from a sysctl, compat.linux.osrelease, basically the number the Linuxulator claims to be so glibc stays contented. Ask the native uname and you get FreeBSD 15.1-RELEASE-p4. As a bonus, the userland package is version 9.8 while the release file inside it still says 9.7. He did not chase that one.

Getting to that point took four detours. The X server died at boot with “no screens found” because Proxmox’s default display offers no DRM device and neither fallback driver was installed — fixed with the scfb driver, since the VM boots UEFI and exposes the GOP framebuffer. Plasma 6’s native RDP server, KRDP, simply is not packaged for FreeBSD, so remote access went through xrdp, which runs its own Xorg per session on display :10. Switching the VM to VirtIO-GPU did deliver a proper framebuffer — the driver politely evicted efifb from the console — but no DRM, no virgl, no accelerated OpenGL: Plasma still reported llvmpipe, every pixel rendered in software on the CPU, and the desktop stayed laggy. He turned off most desktop effects and stopped thinking about it.

There is also a cloud on the horizon he cannot fix: Plasma 6.8 drops the X11 session this entire setup rests on. It works today, on 6.7, and he is plain that it “isn’t a future-proof recommendation.” He suspects he will be pinning packages for a while.

The ending was better than the plan. Once the agent ran stably, Hofstede-Kuhn asked it to lock down the network of the very machine it was running on — over the SSH session a bad firewall rule would have severed. The agent handled this with a dead-man’s switch and asked him to verify from a fresh connection before anything became permanent. Much of the industry’s safety effort goes into [building fences around AI agents that the agents themselves cannot tear down](https://rews.cc/a/nvidia-builds-a-leash-for-ai-agents-and-buys-back-150-billio-d75af9). This was the opposite posture: hand the agent the keys, but make it prove the door still opens before it changes the locks.

One detail deserves the last word. The agent, remember, sees the Linux view first. As far as it can tell, it lives on Rocky Linux 9.7 with kernel 5.15.0, on a machine that is in fact FreeBSD 15.1. It changed the landlord’s locks without ever meeting the landlord — and, from where it sits, everything it did was correct.
