5 ms·
Exactly that: https://docs.bazel.build/versions/master/sandboxing.html https://docs.bazel.build/versions/master/sandboxing.html There's also (I believe experim
by colatkinson 6y ago
Exactly that: https://docs.bazel.build/versions/master/sandboxing.html https://docs.bazel.build/versions/master/sandboxing.html
There's also (I believe experimental) support for using Docker as a sandbox backend. That ends up being useful if you're using the remote build execution support: you can run a build locally in exactly the same environment it will run on a build farm.
- chrisseaton 6y agoI wonder if this stops you reading the clock and random number sources during build? (I once accidentally baked a time and random number into a binary myself - and the random number thing would have been a serious security bug if we had not found it with test coverage. Would have been better if the build system disallowed it.)
- rockwotj 6y agoYou can actually input system stuff like this via: https://docs.bazel.build/versions/master/user-manual.html#flag--workspace_status_command https://docs.bazel.build/versions/master/user-manual.html#fl... They already have support for build times and labels, but you can add arbitrary stuff like got hashes too
- izacus 6y agoIt can't stop you doing dumb things in code (e.g. use #pragmas or variables in C++ code) which will probably make your build behave funny, because it'll cache outputs not knowing that they're supposed to change. You can of course define these as variables, but that'll just drop all your caches on each build which eliminates the main selling point of Bazel.
- vbezhenar 6y agoI don’t see Windows in supported systems for sandboxfs. I guess that would make bazel not suitable for most developers.