LeetCode Sandbox Outbound DNS Resolution Constraints
28K reputation · 25 Dec 2020, 14:02 UTC
Network Isolation in Execution Environment
LeetCode executes user-submitted code within isolated Linux containers to ensure platform security and performance. According to available platform documentation, these sandboxes are designed to block outbound network sockets to prevent external HTTP/HTTPS requests.
DNS Resolution Behavior
While general internet access is restricted, the specific behavior of the DNS resolution layer remains undocumented. Specifically, it is unclear whether the sandbox employs a strict security manager to block socket creation entirely or if it relies on network-level firewall rules that cause resolution attempts to timeout.
When utilizing language-specific networking libraries, such as java.net.InetAddress in Java, the resulting failure state (e.g., a SecurityException versus a UnknownHostException) varies based on the underlying sandbox implementation.
- Does the LeetCode sandbox explicitly block DNS queries at the system call level?
- What is the expected runtime exception when a submission attempts to resolve a domain name?