Skip to main content
Requirements for Python code generation validation.

Classes

CLASS PythonExecutionReq

Verifies that Python code runs without raising exceptions. Optionally validates that captured stdout does not exceed a size limit, eliminating the double-execution cost of separate OutputSizeLimit checks. Extracts the highest-scoring Python code block from the modelโ€™s last output and validates or executes it according to the configured execution tier. Use execution_tier to select behavior by intent:
  • "static" (default) โ€” parse and import-check only, no execution.
  • "local_unsafe" โ€” subprocess execution, no policy restrictions.
  • "local" โ€” subprocess execution with a declared capability policy.
  • "docker_unsafe" โ€” Docker-isolated execution, no policy restrictions.
  • "docker" โ€” Docker-isolated execution with a declared capability policy.
Args:
  • execution_tier: One of "static", "local_unsafe", "local", "docker_unsafe", or "docker". Defaults to "static".
  • policy: Override the tierโ€™s default policy. Ignored for "static" and unsafe tiers unless explicitly provided.
  • allowed_imports: Allowlist of importable top-level modules. None allows any import.
  • max_output_chars: Maximum allowed stdout size in characters. None = no size check (default). When set, adds output size validation in the same execution pass, avoiding the double-execution cost of using OutputSizeLimit. Only enforced for tiers that execute code (local_unsafe, local, docker_unsafe, docker); static tier skips output check.
  • timeout: Deprecated. Pass policy=CapabilityPolicy(timeout=N) instead. When provided, overrides the policy timeout.
  • allow_unsafe_execution: Deprecated. Use execution_tier="local_unsafe" instead.
  • use_sandbox: Deprecated. Use execution_tier="docker" instead.
Attributes:
  • validation_fn: The validation function attached to this requirement; always non-None.