5 ms·
Can you give me a .NET assembly (DLL), that I then load, run in a completely safe sandbox with practically zero risk, and then unload? Is .NET sandboxing effec
by VikingCoder 6y ago
Can you give me a .NET assembly (DLL), that I then load, run in a completely safe sandbox with practically zero risk, and then unload?
Is .NET sandboxing effective yet? It's my belief that if I want to do something like this, that I'm way better off using V8 or some other sandbox to host your code. Or use Deno or something.
Or is it still not possible to run someone else's .NET code really safely?
Asking for a friend who wants to make an online game in the style of C-ROBOTS, but is afraid of running other people's code.
- whb07 6y agoIn theory, they could create a wasm binary I know they are starting to incorporate more of it via blazor among others
- arethuza 6y agoWasmtime includes support for .Net: https://github.com/bytecodealliance/wasmtime/ https://github.com/bytecodealliance/wasmtime/
- Limb 6y agoHave you ever looked into Terrarium? It was created by the .NET team a long time ago to demonstrate the capabilities of .NET. You program a creature and simulate an ecosystem which consist of other peoples "creatures" which if I recall correctly were essentially just DLL's of their code. http://terrariumapp.github.io/ http://terrariumapp.github.io/
- Const-me 6y agoMicrosoft says the answer is “no”. https://devblogs.microsoft.com/dotnet/porting-to-net-core/ https://devblogs.microsoft.com/dotnet/porting-to-net-core/ scroll to “App Domains” and “Sandboxing” sections. Personally, I would still consider it. For a game, the risks are not that large, it’s not a bank nor a nuclear silo. You can use Mono.Cecil library to reflect assemblies without loading them as code or executing any parts of them. You gonna need to whitelist allowed imports (allow stuff like String/List/Dictionary but not much else), blacklist pointer types everywhere (function arguments, return values, and locals variables, CIL+metadata do have types of things), blacklist DllImportAttribute, and probably a few other things I forgot. The performance should be awesome that way, however security-wise that’s not 100% failsafe. Also easy to DoS your server by consuming too much CPU or using all the memory. You might need workarounds to address these issues. Mono.Cecil can patch code making new assemblies, not just inspect/reflect. Probably for these reasons MS discontinued app domains / code security, and recommends processes, containers or virtual machines instead. You can run another instance of .NET runtime inside these things, the startup/warmup time is not that bad, it's not a Java. P.S. If you only allow to edit code in your editor i.e. don’t need support for visual studio + Microsoft’s compiler, you can make your own language where only safe things are expressible, and compile that one into CIL. Simplifies many things, you only need to worry about CPU time and RAM usage. You don’t need to emit DLLs nor mess with CIL directly, can compile scripts into delegates using System.Linq.Expressions or probably some third-party libraries.
- voxic11 6y agoYes! You can do this using a webassemnbly runtime. For example if you look at your browsers network activity on this page you can see a bunch of standard dotnet assemblies being downloaded https://try.dot.net/ https://try.dot.net/ also see https://dotnet.microsoft.com/apps/aspnet/web-apps/blazor https://dotnet.microsoft.com/apps/aspnet/web-apps/blazor
- MarkSweep 6y agoMicrosoft documents that code-access security should not be used as a security boundary: https://docs.microsoft.com/en-us/dotnet/framework/misc/code-access-security https://docs.microsoft.com/en-us/dotnet/framework/misc/code-... As others in this thread have mentioned, CAS does not even exist in .NET Core and .NET 5.