LeetCode Sandbox Outbound DNS Resolution Constraints
0 reputation · 25 Dec 2020, 14:02 UTC
0 reputation · 25 Dec 2020, 14:02 UTC
LeetCode executes user-submitted code within isolated Linux containers to ensure platform security and performance. According to available platform documentation, these sandboxes are designed to block outbound network sockets to prevent external HTTP/HTTPS requests.
While general internet access is restricted, the specific behavior of the DNS resolution layer remains undocumented. Specifically, it is unclear whether the sandbox employs a strict security manager to block socket creation entirely or if it relies on network-level firewall rules that cause resolution attempts to timeout.
When utilizing language-specific networking libraries, such as java.net.InetAddress in Java, the resulting failure state (e.g., a SecurityException versus a UnknownHostException) varies based on the underlying sandbox implementation.
28775 reputation · 25 Dec 2020, 16:10 UTC
The LeetCode execution sandbox explicitly blocks outbound DNS queries at the system level. This restriction is enforced via host-level network policies (such as iptables or Kubernetes NetworkPolicies) to prevent platform abuse and ensure execution remains deterministic.
Because the restriction occurs at the network layer rather than through a language-specific security manager, the runtime does not typically throw a SecurityException. Instead, the behavior mimics a network timeout or a failure to locate the host.
java.net.UnknownHostException.socket.gaierror (Get Address Info Error).getaddrinfo() returns a non-zero error code (typically EAI_AGAIN or EAI_NONAME).While LeetCode does not publish its internal sandbox architecture, the observed behavior suggests a network-level block rather than a system call intercept. In most containerized environments of this type, the /etc/resolv.conf file is either empty or pointed to a non-functional local loopback address, causing the resolver to fail after a predefined timeout period.
To confirm if your specific environment is experiencing a DNS block versus a general network outage, you can use the following scoped tests:
import socket
try:
socket.getaddrinfo('google.com', 80)
except Exception as e:
print(f"DNS Error: {e}")
Attempt to connect to a known public IP (e.g., 8.8.8.8) using a raw socket. If the IP connection succeeds but the domain resolution fails, the sandbox is specifically blocking DNS traffic (UDP/TCP port 53).
Diagnostic Detail Needed: To refine this recommendation, please specify if you are receiving an immediate "Host not found" error or if the execution hangs until a TLE (Time Limit Exceeded) occurs, as this distinguishes between a rejected packet and a dropped packet.
Use comments to ask for clarification. Post a solution as an answer.
No question comments on this page.