Inside the Go Playground
blog.golang.org
blog.golang.org
My sandboxing uses Docker instead of NaCl.
However, it's possible to achieve the same advantage of cacheability, by executing a unmodified binary and recording the output in a time stamped manner, save it in a cache and replay it later.
> To isolate user programs from Google's infrastructure, the back
> end runs them under Native Client (or "NaCl"), a technology
> developed by Google to permit the safe execution of x86 programs
> inside web browsers. The back end uses a special
> version of the gc tool chain that generates NaCl executables
I'm a bit sad that the article didn't discuss using NaCl for constrained execution environments a bit more. Docker/linux containers are still a bit heavy-weight for low-budget ARM servers, and it'd be interesting to check out NaCl as a more lightweight, per-executable sandbox.I'll write more about Go's NaCl support once it's actually in the tree. :-)
Also: Russ Cox is the Chuck Norris of Go programming.
Around 7 months from now according to http://blog.golang.org/go12.
As http://golang.org/s/go13nacl describes, supporting Chrome is not a goal for 1.3 release, only being able to run nacl-sandboxed executables from command line.