From: Ehsanul Hoque Date: 2010-07-24T11:15:06+09:00 Subject: Re: Ruby sandbox secure enough for evaluating any code? --_9a0e83a3-7d57-4593-add3-f89e646e40d0_ Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable > I'd like a sandbox that simply disallows system calls=2C like creating fi= les etc=2C so that anybody can supply some code that can be eval-ed within = the sandbox=2C with no known potential for harm. > I know about safe levels=2C but I googled it and there was some discussio= n about how there were ways to thwart that. I also found this=2C which seem= s quite nice: http://github.com/tario/shikashi > But I have yet to get that working. Are there any other ways to go about = this? Perhaps there are other ways in JRuby? I'd just like to allow the sor= t of operations you'd need for most algorithms=2C so all the usual methods = of arrays=2C numbers=2C hashes and strings basically=2C and perhaps some se= lected custom classes. It would also probably be nice if you could somehow = limit the memory/cpu taken up by the code in the sandbox=2C if that's at al= l possible.=20 Update: I found a replacement for why's old freaky sandbox that works with = jruby: http://flouri.sh/2009/4/4/how-to-set-up-the-jruby-sandboxStill not s= ure how to account for memory consumption/cpu=2C but I'm guessing there may= be some JVM configuration setting that can do something about that. And a = simple timeout for infinite or lengthy loops is good enough for my case. = =20 _________________________________________________________________ The New Busy is not the old busy. Search=2C chat and e-mail from your inbox= . http://www.windowslive.com/campaign/thenewbusy?ocid=3DPID28326::T:WLMTAGL:O= N:WL:en-US:WM_HMP:042010_3= --_9a0e83a3-7d57-4593-add3-f89e646e40d0_--