Skip to main content
Pre-release

This release is a pre-release and may not be stable for production use.

gl-sandbox

Provider-agnostic sandbox SDK: run untrusted code, ship files in and out, and build reusable sandbox images — across E2B, OpenSandbox and AWS Bedrock AgentCore behind one interface.

Installation

The core install is provider-free — it pulls in no backend SDK. Pick the backends you need:

pip install gl-sandbox                    # ABCs, models, errors, tracing — no backend
pip install 'gl-sandbox[e2b]'             # + E2B
pip install 'gl-sandbox[opensandbox]'     # + OpenSandbox
pip install 'gl-sandbox[bedrock]'         # + AWS Bedrock AgentCore
pip install 'gl-sandbox[all]'             # + everything

Importing a backend module without its extra raises an ImportError naming the extra to install.

Layout

The package is organized capability-first: a provider-agnostic root, then one package per capability, then one module per provider inside it.

gl_sandbox/
├── base.py              BaseSandbox — provider- and capability-agnostic lifecycle
├── models.py            ExecutionResult, ExecutionStatus, SandboxFile
├── errors.py            Stage-attributed error taxonomy
├── observability.py     Optional OpenTelemetry spans (no-op when OTel is absent)
├── constants.py         Shared defaults
├── utils.py             Install-code generation, timeout resolution, retry wrappers
├── providers/           Provider-scoped helpers shared across capabilities
│   └── opensandbox/
│       └── snapshot.py    Snapshot name → id resolution      [opensandbox]
├── code_interpreter/    Capability: run code
│   ├── base.py            CodeInterpreterSandbox
│   ├── e2b.py             E2BSandbox                  [e2b]
│   ├── opensandbox.py     OpenSandbox                 [opensandbox]
│   └── bedrock.py         BedrockAgentCoreSandbox     [bedrock]
├── computer_use/        Capability: reserved for the desktop-automation axis
└── template/            Build sandbox images / templates / snapshots
    ├── base.py            BaseTemplateBuilder
    ├── e2b.py             E2BTemplateBuilder          [e2b]
    ├── opensandbox.py     OpenSandboxTemplateBuilder  [opensandbox]
    └── bedrock.py         BedrockTemplateBuilder      (no extra needed — no build step)

Backends live in their own modules, by design. gl_sandbox, gl_sandbox.code_interpreter and gl_sandbox.template export only ABCs, models and errors, so importing them pulls in no provider SDK. Import a concrete backend from its own module:

from gl_sandbox.code_interpreter.e2b import E2BSandbox  # not from gl_sandbox

Usage

Run code in a sandbox

import asyncio

from gl_sandbox import ExecutionStatus
from gl_sandbox.code_interpreter.e2b import E2BSandbox


async def main() -> None:
    sandbox = await E2BSandbox.create(api_key="e2b_...", additional_packages=["numpy"])
    try:
        result = await sandbox.execute_code("import numpy; print(numpy.__version__)")
        if result.status is ExecutionStatus.SUCCESS:
            print(result.stdout)
        else:
            print(result.error)
    finally:
        await sandbox.terminate()


asyncio.run(main())

Upload files, then run against them

SandboxFile is gl-sandbox's own two-field DTO, so nothing here depends on an inference library. Any structurally compatible object (.filename + .data) is accepted, including gllm_inference.schema.Attachment.

from gl_sandbox import SandboxFile

files = [SandboxFile.from_bytes(b"a,b\n1,2\n", "data.csv")]
result = await sandbox.execute_code(
    "import pandas as pd; print(pd.read_csv('/files/data.csv'))",
    files=files,
)

Write workspace files and run commands safely

Workspace primitives provide one bounded contract across E2B, OpenSandbox, and Bedrock AgentCore for durable files and exact-argv execution:

from gl_sandbox import WorkspaceFileWriteRequest
from gl_sandbox.code_interpreter import run_workspace_command, write_workspace_file

await write_workspace_file(
    sandbox,
    WorkspaceFileWriteRequest(
        relative_path="reports/result.json",
        data=b'{"ok": true}',
        max_bytes=16 * 1024 * 1024,
        overwrite=True,
    ),
)
result = await run_workspace_command(
    sandbox,
    ["python", "tools/report.py", "--output", "reports/result.json"],
    cwd_components=("reports",),
    env={"PYTHONUNBUFFERED": "1"},
    env_allowlist=("HOME",),
    timeout=30,
    max_output_bytes=1024 * 1024,
)

Writes reject absolute paths, traversal, symlinks, oversized payloads, and unauthorized replacement. Commands receive an exact argv vector without shell interpolation, run in a confined directory with an allowlisted environment, and return bounded output with observed byte counts, completeness, and truncation flags. Counts are exact when the corresponding *_byte_count_complete flag is true; a provider that leaves a pipe open after bounded timeout cleanup reports false rather than claiming completeness. The default empty env_allowlist deliberately omits PATH; non-absolute executables are still resolved with Python's os.defpath fallback. Allowlist PATH explicitly when a command needs a custom search path. None means the 30-second package default for command timeouts, while <= 0 disables the inner deadline. The write primitive disables the provider code-channel timeout because the bounded write itself has no separate timeout parameter. Cancellation terminates the sandbox; callers must discard it and create a new session before issuing more work. Confinement fails closed when the runner lacks the required descriptor/procfs features or the Linux openat2/Landlock kernel enforcement used by the command helper. Each file write runs in a fresh exec-launched helper, where Landlock is installed immediately before mutation; persistent provider code kernels are never restricted. Linux file writes require Landlock ABI 3 (the REFER and TRUNCATE rights) and fail closed on older or unsupported kernels. Process setup is performed without preexec_fn, so threaded providers do not inherit fork-time Python callbacks.

Build a template once, create sandboxes from it

from gl_sandbox.template import TemplateSpec
from gl_sandbox.template.e2b import E2BTemplateBuilder

builder = E2BTemplateBuilder(api_key="e2b_...")
result = await builder.ensure(TemplateSpec(name="my-base", packages=["pandas", "numpy"]))
sandbox = await E2BSandbox.create(api_key="e2b_...", template=result.ref.template_id)

Errors carry the stage that failed

Every exception records the Stage at its raise site and exposes transient, so retry logic and user-facing messages never drift apart.

from gl_sandbox import SandboxStartError, Stage

try:
    sandbox = await E2BSandbox.create(api_key="e2b_...")
except SandboxStartError as exc:
    if exc.stage is Stage.CREATE and exc.transient:
        ...  # worth retrying

Tracing

observability.py emits OpenTelemetry spans under the gl_sandbox.* namespace against whatever tracer provider the host application configured. It is fully optional: with OpenTelemetry absent, every helper degrades to a no-op, and gl-sandbox takes no dependency on it.

Development

make setup             # uv + pre-commit + dependencies
make test              # unit tests with coverage (needs --all-extras; see below)
make test-core         # import smoke test: core install must work with no extras
make test-integration  # live, credential-gated tests that provision real sandboxes
make ruff              # lint + format check

Unit tests require --all-extras: only the OpenSandbox SDK is stubbed in conftest.py, while the E2B and Bedrock tests import their SDKs for real. Integration tests are excluded by default via addopts = "-m 'not integration'" and each self-skips without its credentials.

Relationship to gllm-tools

This library was extracted from gllm-tools (gllm_tools/code_interpreter/) as a 1:1 copy. gllm-tools retains its own copy and is unaffected; the two have not yet been deduplicated.

Deliberate differences from the origin:

gllm-inference dependency removed — Attachment replaced by SandboxFile
Provider SDKs extras-only — core install pulls in no backend
PydanticExecutorSandbox dropped (was deprecated)
E2B / Bedrock imports guarded, so a missing extra names itself
Layout capability-first, so computer_use/ can land beside code_interpreter/

Everything the port deliberately did not clean up is catalogued in docs/TECHNICAL-DEBT.md — 29 open items ranked by severity, plus the invariants that look like bugs and must be preserved.

Metadata

Release files for gl-sandbox-binary 0.0.1b2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Built distributions (wheels)

Table of built distributions (wheels) for gl-sandbox-binary 0.0.1b2
File
gl_sandbox_binary-0.0.1b2-cp313-cp313-win_amd64.whl CPython 3.13 CPython 3.13 Windows x86-64 Details
gl_sandbox_binary-0.0.1b2-cp313-cp313-manylinux_2_31_x86_64.whl CPython 3.13 CPython 3.13 Linux glibc 2.31+ x86-64 Details
gl_sandbox_binary-0.0.1b2-cp313-cp313-macosx_13_0_arm64.whl CPython 3.13 CPython 3.13 macOS 13.0+ ARM64 Details
gl_sandbox_binary-0.0.1b2-cp312-cp312-win_amd64.whl CPython 3.12 CPython 3.12 Windows x86-64 Details
gl_sandbox_binary-0.0.1b2-cp312-cp312-manylinux_2_31_x86_64.whl CPython 3.12 CPython 3.12 Linux glibc 2.31+ x86-64 Details
gl_sandbox_binary-0.0.1b2-cp312-cp312-macosx_13_0_arm64.whl CPython 3.12 CPython 3.12 macOS 13.0+ ARM64 Details
gl_sandbox_binary-0.0.1b2-cp311-cp311-win_amd64.whl CPython 3.11 CPython 3.11 Windows x86-64 Details
gl_sandbox_binary-0.0.1b2-cp311-cp311-manylinux_2_31_x86_64.whl CPython 3.11 CPython 3.11 Linux glibc 2.31+ x86-64 Details
gl_sandbox_binary-0.0.1b2-cp311-cp311-macosx_13_0_arm64.whl CPython 3.11 CPython 3.11 macOS 13.0+ ARM64 Details

Total release size: 7.4 MB

Release files / gl_sandbox_binary-0.0.1b2-cp313-cp313-win_amd64.whl

Download URL gl_sandbox_binary-0.0.1b2-cp313-cp313-win_amd64.whl
Size 686.4 kB
Tags CPython 3.13 Windows x86-64
SHA-256 checksum
How to use checksums
99bbc4ae1973dd1adb499bf5806a55106d0886d5ca25cfea3ca8dc27bdf1ef09
BLAKE2b-256 checksum
How to use checksums
f920a0b21ea6f756914a33c9f6a1b381b93b6df4169b84662529ecf7ad6a5956
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.

Transparency log

Release files / gl_sandbox_binary-0.0.1b2-cp313-cp313-manylinux_2_31_x86_64.whl

Download URL gl_sandbox_binary-0.0.1b2-cp313-cp313-manylinux_2_31_x86_64.whl
Size 1.1 MB
Tags CPython 3.13 Linux glibc 2.31+ x86-64
SHA-256 checksum
How to use checksums
27703eae75a6be443ef247736dbf60ebe7c571feefcdb19a31ff82fb476a3896
BLAKE2b-256 checksum
How to use checksums
af6e163fa0ae617b3a19d9cc94b54be5565f6b27b967f91af6535c94e2b15de7
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.8.24

Release files / gl_sandbox_binary-0.0.1b2-cp313-cp313-macosx_13_0_arm64.whl

Download URL gl_sandbox_binary-0.0.1b2-cp313-cp313-macosx_13_0_arm64.whl
Size 758.3 kB
Tags CPython 3.13 macOS 13.0+ ARM64
SHA-256 checksum
How to use checksums
8c565991cb69111a71d44a33b09a41ace1e772ca6dfa1111fc8c78ed701f0008
BLAKE2b-256 checksum
How to use checksums
d0ea74a7850fbd11818ff717427cdfd25c0511a8895d7933dbe79494220a0091
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.

Transparency log

Release files / gl_sandbox_binary-0.0.1b2-cp312-cp312-win_amd64.whl

Download URL gl_sandbox_binary-0.0.1b2-cp312-cp312-win_amd64.whl
Size 686.4 kB
Tags CPython 3.12 Windows x86-64
SHA-256 checksum
How to use checksums
593bb940c8b7292ea8576dbd20c884de97556264e30c03e2397df15dc7f6dd5f
BLAKE2b-256 checksum
How to use checksums
f4d89499bc8158e3f57b7b5cba578702b74184eadbdc6dc14f19e16af03b71ce
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.

Transparency log

Release files / gl_sandbox_binary-0.0.1b2-cp312-cp312-manylinux_2_31_x86_64.whl

Download URL gl_sandbox_binary-0.0.1b2-cp312-cp312-manylinux_2_31_x86_64.whl
Size 1.0 MB
Tags CPython 3.12 Linux glibc 2.31+ x86-64
SHA-256 checksum
How to use checksums
f8e33e8756ba8389594686869276dec2780a6da3da4cc5fe55b9c2b9bc12a0cf
BLAKE2b-256 checksum
How to use checksums
2b5daeae08f0f70b0f82fe0d800eb4b08e6ea23137072c713771ad0191b8d636
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.8.24

Release files / gl_sandbox_binary-0.0.1b2-cp312-cp312-macosx_13_0_arm64.whl

Download URL gl_sandbox_binary-0.0.1b2-cp312-cp312-macosx_13_0_arm64.whl
Size 733.2 kB
Tags CPython 3.12 macOS 13.0+ ARM64
SHA-256 checksum
How to use checksums
65b1643397f6bf0017e3295f73ec79858df21814f0b96bfceb67ecbad0fc91f7
BLAKE2b-256 checksum
How to use checksums
ab0c1f2dc418787d3e09d18c4b960f9d6cf119db3fff034eab6107b7999ed37a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.

Transparency log

Release files / gl_sandbox_binary-0.0.1b2-cp311-cp311-win_amd64.whl

Download URL gl_sandbox_binary-0.0.1b2-cp311-cp311-win_amd64.whl
Size 709.5 kB
Tags CPython 3.11 Windows x86-64
SHA-256 checksum
How to use checksums
1543b9e91561890ccd5c3ebaad8c8b74e3622a7d8f9128642bfc65a6d440f9f5
BLAKE2b-256 checksum
How to use checksums
2da29be82d9db13c2508317b7079ff4439b6f3f5bc25410d75a557c7de16e0ef
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.

Transparency log

Release files / gl_sandbox_binary-0.0.1b2-cp311-cp311-manylinux_2_31_x86_64.whl

Download URL gl_sandbox_binary-0.0.1b2-cp311-cp311-manylinux_2_31_x86_64.whl
Size 966.7 kB
Tags CPython 3.11 Linux glibc 2.31+ x86-64
SHA-256 checksum
How to use checksums
6f743a7fc20d4fad46ead52e8b5f86ed4d8b1c5080e277f9033395e2a2f9f9fe
BLAKE2b-256 checksum
How to use checksums
9d82780070acd7b6a16307c2fcf7348d8a5a9e34ca54c86612d3781c87510785
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.8.24

Release files / gl_sandbox_binary-0.0.1b2-cp311-cp311-macosx_13_0_arm64.whl

Download URL gl_sandbox_binary-0.0.1b2-cp311-cp311-macosx_13_0_arm64.whl
Size 725.2 kB
Tags CPython 3.11 macOS 13.0+ ARM64
SHA-256 checksum
How to use checksums
da99b6256de9e29c362cdc2364b465e40add370707b8cf99920ad3cb5c6ab292
BLAKE2b-256 checksum
How to use checksums
f41efe1c00a8c6ae415487c501541ca3de0851a23b93426305030ba187b40680
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.0.1b2 This release

9 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page