| ▲ | jononor 6 months ago | ||||||||||||||||
What is the best way? Or at least, a better way? | |||||||||||||||||
| ▲ | babush 6 months ago | parent | next [-] | ||||||||||||||||
I recall Shopify having a seccomp-based jail to run untrusted ruby code. But their use-case was very limited so they can get away with blocking almost every syscall. Other than that... VMs? The fact that people consider JS/WASM engines good security sandboxes is a bit scary tbf. | |||||||||||||||||
| |||||||||||||||||
| ▲ | kissgyorgy 6 months ago | parent | prev | next [-] | ||||||||||||||||
Landlock, cgroups on Linux | |||||||||||||||||
| ▲ | ehsanu1 6 months ago | parent | prev [-] | ||||||||||||||||
gVisor | |||||||||||||||||