Add integration tests for pixi in a sandbox to this repo #5529
Copy link
Copy link
Open
Description
Activity
Good idea! Do you think you could contribute this?
Hi @baszalmstra! I was investigating this issue.
From my understanding, the ask is that pixi should not panic when run in a sandboxed environment (like Claude Code). Failures are expected and fine - but the process shouldn't crash unexpectedly.To test this, I used bwrap on Linux to implement filesystem and network restrictions similar to what Claude Code uses:
- Read-only root filesystem
- Only current directory writable
- No access to home directory
- Network blocked
But, pixi handles sandbox restrictions gracefully with error messages - no panics occur.
So, is this the right approach? What's the specific scenario that caused the original panic?
Metadata
Metadata
Assignees
Labels
No labels
We want to use pixi in a sandbox (claude code) and sometimes run into panics because of that. The most recent thing @borchero found was https://github.com/servo/core-foundation-rs/blob/6f844cf1a1a18e25b70fcdf1bcdc458555bd2eff/core-foundation/src/lib.rs#L102
I think it would be cool if we had an integration test that lets the compiled binary run in a sandbox so we can catch potential issues.