3 ms·
> They both use docker for isolation Docker isn't really meant as a security mechanism. Among other things, you still expose the full kernel API as an attack s
by Merovius 10y ago
> They both use docker for isolation
Docker isn't really meant as a security mechanism. Among other things, you still expose the full kernel API as an attack surface. I can't imagine that they only use Docker, at the very least they'll probably have some dedicated machines for the playgrounds. Even then, this is probably not a great idea.
The playground uses NaCl (and AFAIK that includes seccomp), restricting both the instructions that you can use and the set of system calls that you can make (basically just read/write on fds 0-3 and exit). It's what chromes sandbox is based upon.
There are a couple of implications from this (most are described in the blog post linked elsewhere), e.g. that time is faked and that playground-code runs single-threaded. A great consequence, though, is that playground code is 100% deterministic, meaning it can be cached (and it is cached pretty aggressively), reducing the load for popular snippets.
- Manishearth 10y agoHm, seems like they both just use docker's sandboxing parameters (https://github.com/rust-lang/rust-playpen/blob/master/src/docker.rs#L20 https://github.com/rust-lang/rust-playpen/blob/master/src/do... , https://github.com/integer32llc/rust-playground/blob/master/ui/src/sandbox.rs#L211 https://github.com/integer32llc/rust-playground/blob/master/... ). The official one used to use libseccomp, but it doesn't anymore. They probably should use https://github.com/servo/gaol https://github.com/servo/gaol (should be drop-in) or seccomp , I'll file issues. IIRC they're on their own dedicated instances.