--unshareRye can run scripts inside Linux namespaces (aka “unshare”) with a single flag. This isolates your script from the host:
/app (read-mostly), the rest is a tiny tmpfs jailThis is Linux-only and requires no root privileges.
# Full isolation (fs+net+pid+uts)
rye --unshare myscript.rye
# Allow network but keep other isolation
rye --unshare --unshare-net=false myscript.rye
# Keep your full filesystem view (cwd not remounted), but isolate net/pid/uts
rye --unshare --unshare-fs=false myscript.rye
You can also enable it per-project in .ryesec:
unshare:
enabled: true
fs: true
net: true
pid: true
uts: true
Rye exposes simple helpers to check isolation at runtime (Rye-itself context):
cc Rye-itself
cfg: Unshare-config? ; => {active: true, fs: true, net: true, pid: true, uts: true}
if (cfg -> "active") { print "Sandboxed." }
Common checks:
Is-unshare — true if running inside unshareIs-unshare-fs / Is-unshare-net / Is-unshare-pid / Is-unshare-utsRequire-unshared — exit with error if not sandboxed (great for CI)Example: skip network work when isolated
cc Rye-itself
if Is-unshare-net {
print "Network disabled; skipping fetch."
} else {
; do network work here
}
--unshare--unshare gives you predictability, safety, and reproducibility without heavy tools like Docker/Podman. Its usefulness depends on what your script does and where it runs.
When it shines
When it may be unnecessary (or inconvenient)
--unshare-fs=false.--unshare-net=false.Summary: For tests, CI, builds, batch jobs, and untrusted code, --unshare provides container‑like safety with near‑zero setup. For day‑to‑day interactive tools that must edit your project, run without it or relax specific namespaces.
--unshareRye constructs a minimal, in‑memory filesystem (tmpfs) “jail” and selectively mounts a few locations:
Default access policy
What happens if a script writes to /home?
Verify the behavior
Bash
# Attempt to create a file in host home dir (will fail)
rye --unshare -e 'file "/home/test.txt" | .write "hello"'
ls /home/test.txt shows no such file.Read vs. write in /app
; 1) Reading works
_ = file "/app/README.md" | .read
print "Read successfully!"
; 2) Writing is blocked
file "/app/test.txt" | .write "data"
Running with rye --unshare prints “Read successfully!” then errors on the write.
/tmp for outputs when using --unshare (project dir /app is remounted read-only where possible)Require-unshared at the start of critical scripts to enforce policy--unshare-net=false or adjust .ryesec--unshare is not available; scripts should branch on Is-unshare and continue gracefully/app is best-effort; on some kernels it may remain writable (a warning is printed)