go-judge-py
A Pythonic wrapper around go-judge that provides self-managing, lightweight, rootless containers for secure code execution on Linux.
Unlike standard API clients, go-judge-py handles the entire lifecycle: it automatically downloads the sandbox binary, builds a root filesystem (rootfs) from official Linux distribution images (Debian, Alpine, Arch, Fedora), and manages the sandbox server for you.
Ideal for:
- 🛡️ Verifying AI-generated code (LLM code interpreters)
- ⚖️ Online Judge systems
- 🏫 Computer Science Education (grading scripts)
✨ Features
- Zero-Dependency Setup: Automatically fetches the
go-judgebinary and builds the execution environment. - Multi-Distro Support: Create environments based on Debian, Alpine, Arch Linux, or Fedora.
- Rootless & Secure: Runs entirely in user namespaces (no
sudorequired) usingunshare. - Parallel Execution: Native support for batch processing with concurrent requests.
- Resource Control: Fine-grained limits on CPU, Memory, and Process count.
📦 Installation
pip install go-judge
# or with uv
uv add go-judge
Requirements: Linux system with unshare enabled (modern Kernels default).
1. Basic Usage (Python & C++)
The library comes with default configurations for common languages.
from go_judge import Sandbox
# Automatically builds a Debian environment with GCC and Python installed
# This might take a minute the first time to download the rootfs
with Sandbox("standard-env", distribution="debian", packages=["g++", "python3"]) as sb:
# Run Python
res = sb.run("python", "print('Hello from the Sandbox!')")
print(res["stdout"]) # Output: Hello from the Sandbox!
# Run C++ (Compiles and Executes)
cpp_code = """
#include <iostream>
int main() { std::cout << "Fast C++" << std::endl; }
"""
res = sb.run("cpp", cpp_code)
print(res["stdout"]) # Output: Fast C++
2. Custom Languages & Resource Limits
You can register custom languages (like C) and set strict resource limits.
from go_judge import Sandbox
with Sandbox("custom-env", distribution="debian", packages=["gcc"]) as sb:
# Register C configuration
sb.register_language("c", {
"src_name": "main.c",
"bin_name": "main",
"compile": {
"args": ["/usr/bin/gcc", "main.c", "-o", "main"],
"env": ["PATH=/usr/bin:/bin"]
},
"run": {
"args": ["./main"],
"env": ["PATH=/usr/bin:/bin"]
}
})
# Run with constraints: 100ms CPU time, 32MB Memory
result = sb.run(
"c",
"int main() { return 0; }",
exec_cpu_limit_ns=100_000_000,
exec_memory_limit_b=33_554_432
)
3. High-Performance Batch Processing
Execute code against multiple inputs in parallel using the built-in thread pool.
inputs = ["1 1", "2 2", "10 20"] # stdin for each test case
code = """
a, b = map(int, input().split())
print(a + b)
"""
with Sandbox("py-worker") as sb:
# Returns a list of results, preserving order
results = sb.run_multiple("python", code, inputs)
for res in results:
print(f"Status: {res['status']}, Output: {res['stdout'].strip()}")
🛠️ Supported Distributions
go-judge-py pulls metadata from the Linux Containers (LXC) project to build environments.
| Distro | Keyword | Best For |
|---|---|---|
| Alpine | alpine |
Ultra-lightweight, fast startup. |
| Debian | debian |
Compatibility, standard glibc. |
| Fedora | fedora |
Bleeding edge packages. |
| Arch | arch |
Rolling release updates. |
Example:
# Use a specific version of Debian
sb = Sandbox("old-stable", distribution="debian", release="bullseye")
💻 Development
Clone the repository and set up the environment using uv.
# Run integration tests (requires Linux)
uv run pytest -s tests/test_integration.py
Metadata
Release files for go-judge 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| go_judge-0.1.0.tar.gz | 11.1 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| go_judge-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 24.7 kB
Release files / go_judge-0.1.0.tar.gz
| Download URL | go_judge-0.1.0.tar.gz |
|---|---|
| Size | 11.1 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
d9dbf274bb515fa6ec5e516a5bc13ec6440e5cf2d3db692fb8f33361f76be26a
|
|
BLAKE2b-256 checksum How to use checksums |
4f1651ff532b01c51a5ac58ade6861d7ae7e8097ea01286f0407f29549a704fa
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jan 25, 2026.
Transparency logRelease files / go_judge-0.1.0-py3-none-any.whl
| Download URL | go_judge-0.1.0-py3-none-any.whl |
|---|---|
| Size | 13.6 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
4ac9ffa049ccfe9001d44e3b50d7b16974782419f29535aa552c85f4977c4fd6
|
|
BLAKE2b-256 checksum How to use checksums |
61950f0af8a15ad06406a1277a6813bf1339d31106dd18e538292a7e7e9e7d4c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jan 25, 2026.
Transparency log