This disables various destructive functions and prevents the generated code from interfering with the test (e.g. fork bomb, killing other processes, removing filesystem files, etc.) WARNING This function is NOT a security sandbox. Untrusted code, including, model- generated
(maximum_memory_bytes=None)
| 676 | |
| 677 | |
| 678 | def reliability_guard(maximum_memory_bytes=None): |
| 679 | """ |
| 680 | This disables various destructive functions and prevents the generated code |
| 681 | from interfering with the test (e.g. fork bomb, killing other processes, |
| 682 | removing filesystem files, etc.) |
| 683 | WARNING |
| 684 | This function is NOT a security sandbox. Untrusted code, including, model- |
| 685 | generated code, should not be blindly executed outside of one. See the |
| 686 | Codex paper for more information about OpenAI's code sandbox, and proceed |
| 687 | with caution. |
| 688 | """ |
| 689 | |
| 690 | if maximum_memory_bytes is not None: |
| 691 | import resource |
| 692 | |
| 693 | resource.setrlimit( |
| 694 | resource.RLIMIT_AS, (maximum_memory_bytes, maximum_memory_bytes) |
| 695 | ) |
| 696 | resource.setrlimit( |
| 697 | resource.RLIMIT_DATA, (maximum_memory_bytes, maximum_memory_bytes) |
| 698 | ) |
| 699 | if not platform.uname().system == "Darwin": |
| 700 | resource.setrlimit( |
| 701 | resource.RLIMIT_STACK, (maximum_memory_bytes, maximum_memory_bytes) |
| 702 | ) |
| 703 | |
| 704 | faulthandler.disable() |
| 705 | |
| 706 | import builtins |
| 707 | |
| 708 | builtins.exit = None |
| 709 | builtins.quit = None |
| 710 | |
| 711 | import os |
| 712 | |
| 713 | os.environ["OMP_NUM_THREADS"] = "1" |
| 714 | |
| 715 | os.kill = None |
| 716 | os.system = None |
| 717 | os.putenv = None |
| 718 | os.remove = None |
| 719 | os.removedirs = None |
| 720 | os.rmdir = None |
| 721 | os.fchdir = None |
| 722 | os.setuid = None |
| 723 | os.fork = None |
| 724 | os.forkpty = None |
| 725 | os.killpg = None |
| 726 | os.rename = None |
| 727 | os.renames = None |
| 728 | os.truncate = None |
| 729 | os.replace = None |
| 730 | os.unlink = None |
| 731 | os.fchmod = None |
| 732 | os.fchown = None |
| 733 | os.chmod = None |
| 734 | os.chown = None |
| 735 | os.chroot = None |