sandboxkit
Sandboxed code execution on Linux. Run a Python callable in a forked child or an argv command in a subprocess, isolated by namespaces, rlimits and Landlock. Rootless by default: an unprivileged user namespace gives the payload uid 0 inside its own mount, pid, network (no connectivity), ipc and uts namespaces.
Requires Python 3.10+ and Linux, with unprivileged user namespaces for the default configuration. Landlock support comes from landlockpy and is used when the running kernel has it.
Install
pip install sandboxkit
Usage
from sandboxkit import RLimits, Sandbox
sandbox = Sandbox(
rlimits=RLimits(cpu_seconds=5, memory_bytes=64 << 20),
timeout=10,
)
result = sandbox.run_argv(["/usr/bin/python3", "-c", "print(2 + 2)"])
assert result.ok and result.stdout == b"4\n"
# or run a callable. An OSError inside surfaces as result.errno
result = sandbox.run(lambda: print("running as uid", __import__("os").getuid()))
namespacespicks the unshare(2) set.Namespace.CGROUPis opt-in.- The real uid/gid is mapped to 0 inside, written by the parent through /proc// so it works on kernels that reject self-mapping.
strict=TrueraisesSandboxErroron any namespace failure.strict=False(default) skips refused namespaces with a stderr note.landlock=takes a configured but unenforcedlandlockpy.Ruleset, restricted in the payload only, so the object stays usable.hostname=sets the UTS hostname,mount_proc=Truemounts a fresh /proc,timeout=kills the whole sandbox tree.namespaces_supported()probes which namespaces this kernel actually lets the caller create;userns_available()checks the USER path.
Documentation
- API: docstrings in
src/sandboxkit/, mostlysandbox.py - namespaces(7): https://man7.org/linux/man-pages/man7/namespaces.7.html
- user_namespaces(7): https://man7.org/linux/man-pages/man7/user_namespaces.7.html
- unshare(2): https://man7.org/linux/man-pages/man2/unshare.2.html
- setrlimit(2): https://man7.org/linux/man-pages/man2/setrlimit.2.html
- Landlock: https://docs.kernel.org/userspace-api/landlock.html
License: 0BSD.
Metadata
Release files for sandboxkit 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| sandboxkit-0.1.0.tar.gz | 74.0 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| sandboxkit-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 88.9 kB
Release files / sandboxkit-0.1.0.tar.gz
| Download URL | sandboxkit-0.1.0.tar.gz |
|---|---|
| Size | 74.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
d8933b772d503b7bb96a94edb1d7d12957d7bc3e47ceaf9e04491fc53ec024f4
|
|
BLAKE2b-256 checksum How to use checksums |
5a4d8a8b1ac72f5ce63672cf027e9a2d24a01cf3d05ecd1014e51b70133103d8
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 22, 2026.
Transparency logRelease files / sandboxkit-0.1.0-py3-none-any.whl
| Download URL | sandboxkit-0.1.0-py3-none-any.whl |
|---|---|
| Size | 14.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
febac0ceafe9bef846ab9bf0dc39157d052bc0e5a3d572cf289e0cb77cd6aa24
|
|
BLAKE2b-256 checksum How to use checksums |
be0dee48d3a25a94a56f75087cb9b0172e7629e2bce28ffd403401bd50c53420
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 22, 2026.
Transparency log