Harsh Kashyap 97c8097d51 fix(seccomp): extend default whitelist and merge ALLOWED_SYSCALLS (#275)
* fix(seccomp): extend default python syscall whitelist

* fix(seccomp): merge ALLOWED_SYSCALLS with defaults

* test(seccomp): add syscall merge regression tests

* docs(seccomp): document ALLOWED_SYSCALLS append semantics in FAQ

* test(seccomp): keep default syscalls when extending whitelist

---------

Co-authored-by: Harsh Kashyap <harshkashyap@Harshs-MacBook-Pro.local>
2026-07-01 09:54:14 +08:00
2024-05-10 02:22:01 +08:00
2025-07-21 17:14:39 +08:00
2024-07-02 23:02:22 +08:00
2024-08-10 16:33:25 +08:00
2024-08-10 16:33:25 +08:00

Dify-Sandbox

Introduction

Dify-Sandbox offers a simple way to run untrusted code in a secure environment. It is designed to be used in a multi-tenant environment, where multiple users can submit code to be executed. The code is executed in a sandboxed environment, which restricts the resources and system calls that the code can access.

Use

Requirements

DifySandbox currently only supports Linux, as it's designed for docker containers. It requires the following dependencies:

  • libseccomp
  • pkg-config
  • gcc
  • golang 1.20.6

Steps

  1. Clone the repository using git clone https://github.com/langgenius/dify-sandbox and navigate to the project directory.
  2. Run ./install.sh to install the necessary dependencies.
  3. Run ./build/build_[amd64|arm64].sh to build the sandbox binary.
  4. Run ./main to start the server.

If you want to debug the server, firstly use build script to build the sandbox library binaries, then debug as you want with your IDE.

FAQ

Refer to the FAQ document

Workflow

workflow

S
Description
A lightweight, fast, and secure code execution environment that supports multiple programming languages
Readme Apache-2.0 14 MiB
Latest
2025-05-07 05:52:38 -04:00
Languages
Go 86.7%
Shell 4.5%
Dockerfile 3.9%
C++ 2.4%
Python 2.2%
Other 0.3%