bjfish
I would like to create a server that allows other users to run white-listed functions. It would be nice if the untrusted code were packaged as hex packages.
The use case is to allow users to run plugins to a framework in a shared server environment.
I’ve seen some existing implementations/experiments of this in Elixir.
What would be the most thorough approach be to run untrusted Elixir code?
Some previous threads/code I’ve found:
Trending in Questions
I having some trouble figuring out if I have set myself too strict of standards for my production server. Currently I can handle 75% of r...
New
Documentation
While reading the Scoped Routes section, I noticed that the documentation currently refers to a problem without explainin...
New
Hello,
I’m trying to build a basic Phoenix web-app, and I’d like to use Tailwind.
However, when I launch mix phx.server, I get an error...
New
Hi everyone,
I am toying with the idea of building a “match maker” for giving personal help to people that wants to start coding.
I sta...
New
I recently noticed that Elixir’s Logger defaults its primary log level to :debug when no :logger, :level application configuration is pre...
New
I’m working on a small exercise involving update_in/3, and I came up with this solution:
data = %{
name: "Periodic Table",
category:...
New
I’ve got trouble wrapping my head around the order in which functions are called in this snippet (from Phoenix’s authentication):
toke...
New
Other Trending Topics
Edit: 2026 May 15 - This post is archived.
Mob is alive!!
Main docs: mob v0.7.11 — Documentation
A bit of explanation for the slightly c...
New
Hey, I’m Jesse and I’m the main contributor behind Dexter, a full-featured, lightning-fast Elixir LSP optimized for large codebases. It s...
New
I am happy to introduce the very α version of the new programming language compiled to BEAM.
Welcome Cure.
It has literally three kille...
New
Hobbes is a low-level distributed database for the Elixir programming language.
Hobbes provides a simple, safe, and scalable storage lay...
New
Hi everyone!
The first release candidate for the Expert language server project is now available!
We’ve published a press release detai...
New
A little off-topic, but I feel like people here have a good head on their shoulders.
I used to be quite good at making software. Was luc...
New
Categories:
Sub Categories:
Forums
Popular Tags
- #ecto
- #liveview
- #troubleshooting
- #learning-elixir
- #library
- #deployment
- #erlang
- #testing
- #genserver
- #mix
- #absinthe
- #remote-other
- #otp
- #plug
- #how-to-question
- #macros
- #postgres
- #elixirconf
- #channels
- #exunit
- #discussion
- #code-sync
- #podcasts
- #javascript
- #onsite
- #dialyzer
- #docker
- #authentication
- #umbrella
- #full-time-contract
- #podcasts-by-brainlid
- #ai
- #ecto-query
- #elixirconf-us
- #blog-post
- #elixir-ls
- #phoenix_html
- #iex
- #graphql
- #genstage
- #websockets
- #supervisor
- #advent-of-code
- #distillery
- #processes
- #elixirconf-eu
- #api
- #forms
- #metaprogramming
- #hex











Showing Posts 1 to 10- Show Best Posts
- Show All (oldest first)
- Show All (newest first)
OvermindDL1
Why not let them run an embedded language, like LUA?
christhekeele
FWIW I stopped researching exbox because the people interested it gave up on in-language sandboxes for their project and switched to Docker to run untrusted code.
bjfish
I’m currently the impression this could/should be done by limiting the available functions at compile time and would require modifying the elixir compiler to restrict specific modules.
minhajuddin
The only sure of way running untrusted code seems to be using docker.
talentdeficit
you can construct function calls dynamically at runtime. i don’t think it’s possible to sandbox elixir/erlang code without modifying the vm
michalmuskala
There are extremely many ways to call a function - in a lot of places you can pass
{module, function, arguments}tuples, you can create atoms at runtime in many ways as well. I don’t see a viable way of filtering this.OS-process-level sandboxing is definitely a much better idea.
DianaOlympos
I know i am a Cassandra at that point and that i mess a bit with the whole fun thing.
But Docker is not a sandbox. Is it better than the BEAM isolation ? Yes probably. But if you need a secure sandbox with Docker, the advise right now and for the year to come probably is to have one VM per Docker container. If you want a more secure sandbox/container, have a look at FreeBSD Jails or SmartOS Zones. You can run a Docker container on SmartOS Zones.
OvermindDL1
Exactly this! Docker is NOT a sandbox, it is pretty trivial to ‘break out of it’, and it is designed for process segmentation, not sandboxing, and the developers are upfront about that. Anyone using docker to sandbox has a ticking time-bomb…
SmartOS Zones would be a good sandbox though. FreeBSD Jails, they ‘mostly’ work, but they can be broken out of with relative ease now too. I’d still say just support lua or something, not elixir.
bjfish
I’ve found another thread discussing sandboxing here:
Also, found one elixir lua impementation (not sure if this is sandboxed though):
https://github.com/bendiken/exlua
OvermindDL1
There are a lot of LUA implementations for the BEAM:
GitHub - rvirding/luerl: Lua in Erlang · GitHub by the very own RVirding, this is implemented in erlang, not super fast, but very safe, it implements ‘most’ of lua, good enough for simple scripting. However you can implement lua things in erlang/elixir that can be called from lua very fast, so it makes a great simple scripting layer.
GitHub - dryex/exlua: Lua for Elixir. · GitHub is just an Elixir wrapper of luerl to change the API a bit, does not add anything though.
GitHub - Eonblast/Erlualib: An Erlang linked-in driver that allows embedding Lua into the Erlang VM · GitHub Embedded driver to add lua to the BEAM, full power and normal lua speed, but you can crash the VM if lua crashes (rare, but possible). ^.^
Do it yourself via a port: This is probably what you should do, make your own C LUA Port system (and release it as a hex.pm library!) that connects to the BEAM via a Port, full safety, full sandbox (as long as you leave out the lua standard library like filesystem and network I/O), etc…
EDIT: It would be fun to build a new simple safe scripting language on Elixir though, not hard to do. ^.^