4 ms·
uv run is using virtual envs, that's the de facto standard, and those are sandboxes for python deps. So it already is. Plus inline deps mean you can pin python
by BiteCode_dev 1y ago
uv run is using virtual envs, that's the de facto standard, and those are sandboxes for python deps. So it already is.
Plus inline deps mean you can pin python versions and 3rd party modules using pyproject.toml syntax in a comment of your script. This is not perfect locking, as it doesn't pin sub dependencies, but it's already more that any other tool out there.
If you want perfect locking, create a project, and use uv lock. You are already in a different category of code.
- simonw 1y agoOP isn't talking about virtual environment style sandboxing, they're talking about sandboxes that prevent arbitrary code from deleting or stealing any information your user account has access to on your computer.
- throwaway290 1y agoRun it in a Docker container?
- cedws 1y agoDocker isn’t a sandbox and shouldn’t be treated like one. Admittedly if I’m going to run untrusted code I’ll run it in Docker, but I’m aware that whatever I’m running could break out. I wouldn’t blindly run some bullshit even in Docker unless I’m 90% sure it’s safe already.
- throwaway290 1y agoHow do you get to 90% sure for code that has any dependencies?
- OutOfHere 1y agoWhy is Docker (or extensions thereof) not a sandbox? Granted, it could access the internet, but that's necessary.
- cedws 1y agoDocker's primary purpose is to give applications their own namespaces in which they can run without conflict. It does confine applications to their own root filesystem, own process namespace and so on, but this isn't intended as a security boundary. cgroup escapes happen. Firecracker and gVisor provide much stronger isolation. Both are battle tested; clouds run millions of multi-tenant workloads on these every day. Docker would simply never even be a candidate for this purpose.
- integralid 1y ago>but I’m aware that whatever I’m running could break out If you have a working docker escape exploit at hand, that works on unprivileged containers, you can earn some good money. Just saying. Docker was not created as a sandbox, but people rely on it for security and it is a sandbox at this point. Hell, containerd is one of kuberbetes backends and it absolutely relies on it being a secure sandbox.
- BiteCode_dev 1y agoThis has been attempted many times with python, and always been a failure because of the dynamism of the language, even by big actors. The solution, therefor, as always been to use the OS tooling for that. Even the .Net ecosystem eventually went into that direction. The JS ecosystem is making that mistake right now, and will of course, deprecate this API in 10 years after they realize they can't make it secure either unless they basically reimplement BSD jails entirely.
- deleted 1y ago[deleted]
- simonw 1y agoDeno has had this feature for five years already, since May 2020: https://deno.com/blog/v1 https://deno.com/blog/v1