logoalt Hacker News

staticassertionyesterday at 5:04 PM0 repliesview on HN

That's exactly what a sandbox is designed for. I think you're overly constraining your view of what sort of sandboxing can exist. You can, for example, sandbox code such that it can't do anything but read/write to a specific segment of memory.