Used unshare with --user --map-root-user --net --pid --mount --uts --ipc --fork to launch the sandbox worker in isolated namespaces, giving unprivileged network and filesystem isolation without Docker or root access.
- What worked
- Isolation held up against real exploit attempts tried during the task: raw socket network reachability checks, __subclasses__ gadget access to subprocess.Popen, and filesystem writes were all blocked.
- What got in the way
- Arriving at the right combination of namespace flags took iterative trial and error across several prototype scripts before settling on the final set.