sandboxed 0 ▲ hlfshell 7 hours ago · Tech · hide · 0 comments The most common theme in most of my golang libraries is - “I needed it for another larger project”. Queue a side quest and boom, new library. sandboxed is no different. sandboxed is a Go virtual filesystem for storing untrusted data as encrypted chunks. The original project driving the need for this is still too early; I’ll talk more about it when I have something substantial to share. I wanted the ability to download arbitrary binary data and protect the system from it. This might make a few of you go “why the hell would you want to do that?”; well, wait for the other project. Others might point out that a virtual machine would be a great way to isolate the payload. No argument here. I have my reasons for wanting to avoid virtualization here. So what does sandboxed do? It presents an fs interface for use in golang where a manifest file tracks individual files within the “file system”. Every file is streamed through a per file encryption buffer when writing data to disk. The… No comments yet. Log in to reply on the Fediverse. Comments will appear here.