astral-sh / astral-sh/python-build-standalone

Use macOS sandbox to isolate system dependencies

Open
#738 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
4.4k
Forks
314
Avg merge
1d 9h
Merged PRs (30d)
27

Description

#545 was because we were setting CC but not CXX, meaning we were using our own cc command but /usr/bin/c++.

I think we can use the macOS built-in sandboxing system (see `man sandbox-exec` and `man sandbox_init`, see also /System/Library/Sandbox/Profiles/ for examples of the syntax) to restrict access to /usr/bin/c++ and friends, so the build fails if you attempt to use it.

... honestly this kind of sounds like https://github.com/twosigma/ts_isolate, I wonder if we should use that on Linux and whether I should add a macOS implementation with the same API, backed by `sandbox_init`.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.