▲ | jononor 6 days ago | ||||||||||||||||
What is the best way? Or at least, a better way? | |||||||||||||||||
▲ | babush 6 days ago | parent | next [-] | ||||||||||||||||
I recall Shopify having a seccomp-based jail to run untrusted ruby code. But their use-case was very limited so they can get away with blocking almost every syscall. Other than that... VMs? The fact that people consider JS/WASM engines good security sandboxes is a bit scary tbf. | |||||||||||||||||
| |||||||||||||||||
▲ | kissgyorgy 6 days ago | parent | prev | next [-] | ||||||||||||||||
Landlock, cgroups on Linux | |||||||||||||||||
▲ | ehsanu1 5 days ago | parent | prev [-] | ||||||||||||||||
gVisor |