I naively assumed the extensions were 'sandboxed' to some degree.
I naively assumed the extensions were 'sandboxed' to some degree.
Well, it’s absolutely not and you can access the full filesystem. Which is handy if you are legit, but very permissive & much more a security threat than I imagined.
Be careful what extensions you install people :)
I agree, this seems bad! Sandboxing is still a very weakly implemented craft for most applications, especially those that run extensions or plugins.
(I build a lot of software that runs plugins and has no sandboxing at all, and it really frustrates me. I'm constantly looking out for cross-platform Python-friendly sandboxing tech that might help with this in the future.)
voice of decades past -- sandboxing is very well known and deeply implemented in many aspects of ordinary daily computing; sandboxing is endlessly difficult and can be mis-applied; people who want to break into things and steal and wreak havoc ruin software environments for everyone else.
I actually tried running clickhouse in container2wasm and it crashed because it only had one CPU core, so YMMV—although that shouldn’t be a problem for Python (or any code custom built for your plugin framework).
For me, I want to avoid separate processes. I definitely want to avoid separate VMs.
[1] https://github.com/extism/python-sdk
I’ve become very paranoid with extensions as of late. It’s great that llms have gotten so good and banging out personal tools. I am using a few home grown extensions in my own setup.
Any extension has full access to execute programs as the user.
Your operating system might have some security measures in place.
I honestly thought that was how the Javacsript and Python ecosystems worked? And surely many others.
Yes.
> I naively assumed the extensions were 'sandboxed' to some degree.
No. This is fairly obvious if you have used more than a few extensions - often they'll ask you to download and install binaries.