One process per sandbox will get you far, if all you want is to execute something. I would go as far as say it is pretty easy.
I want to execute untrusted code. This makes it very difficult indeed.
I want to execute untrusted code. This makes it very difficult indeed.