3 ms·
The build isolation approach sounds interesting, but I'm not sure I understand. Do you mean isolating build scripts by using a VFS mapped to the real FS and ma
by brandonpayton 1mo ago
The build isolation approach sounds interesting, but I'm not sure I understand.
Do you mean isolating build scripts by using a VFS mapped to the real FS and masking away everything the build script should not have access to?
> The some points of trouble I ran into were dead symlinks left behind on the FS pointing to real files
Symlinks make this space trickier for sure.
> escape codes interacting with the terminal (e.g. escape codes reading from the clipboard).
Woah. TIL this was possible.
- grayrest 1mo ago> Do you mean isolating build scripts by using a VFS mapped to the real FS and masking away everything the build script should not have access to? Yes. Essentially the idea was to find the source control root (or something configurable) and mount the real subtree into a VFS where everything interacts with the filesystem through the VFS. I can run wasm compiled versions of apps I don't really trust or run native patched versions that I do. For background, I'm writing a UI platform in Roc [1] and using just [2] in order to script things. I had extra tokens so I decided to do an LLM port of just over to Roc to exercise the compiler (it's pre-0.1, pushing the compiler leads to crashes) and people won't have to install Rust to write apps. Like wasm, Roc code can't access the outside world without the host providing the access to the outside world so in the process of the port I thought "I don't have to make posix calls, I can put it in sandbox and lie about it" so that's how I got here. I'm fairly close to being able to do hermetic builds so that's a possibility but this is mostly an exploration of whether the idea works or not. [1] https://roc-lang.org/ https://roc-lang.org/ [2] https://github.com/casey/just https://github.com/casey/just
- brandonpayton 1mo agoThanks for sharing details. It does seem like a natural place for a Wasm sandbox + VFS. Hopefully we can make running these kinds of commands easier as the project progresses. If you have any interest, please feel to suggest what you want or submit a PR at https://github.com/Automattic/kandelo/ https://github.com/Automattic/kandelo/. It's easy to get stuck in our own heads working on these tools, and hearing from any real/potential user would be good oxygen for the project.