← All courses
IVYXSTUDIO · COURSE

SEC 201

sec-201 · v1.0.0

ivyx✓

Permission, Sandboxing, Secret Management: watch a deny list wave through an attribute walk, build the allow list that stops it and measure its cost, budget a process, confine a path against a symlink, scrub a secret and find the shapes it misses, and close one leak with a test that stays red.

intermediate485 min9 lessonsen
#security#sandboxing#permissions#secrets#platform#ai-series#intermediate

What this course is for

By the end of this course you can give a piece of code the least permission that works, isolate it in a process with a budget it cannot exceed, keep a secret out of the output including the traceback, and prove a specific leak is closed with a test that fails when you reopen it.

What you will be able to do

  • Hand a careful deny list one payload that names no forbidden word and watch it reach every class in the program
  • Build an allow list from an ast walk, stop all thirty escapes, and measure the seven ordinary payloads it refuses
  • Give a run its own process with a CPU cap and a deadline and read the exit code of a process a signal killed
  • Confine a path to a directory and defeat the confinement with a symlink and a check that ran in the wrong order
  • Measure a scrubber perfect on bare secrets and blind to a secret that was base64 encoded or split across a newline
  • Compare env, file and manager on who can read a secret and find the one that prints it in a traceback
  • Name the reach a sandbox keeps and tell a restriction that holds from one that only looks like it does
  • Close a real leak and write the regression test that goes red when the fix is reverted

Who it is for

Learners who finished CONT 201 and can write a Python function, and who now have to run code, resolve a path, or log a message they did not fully write.

Before you start

  • PYTHON 101, for functions, the ast module and the standard library the course is built on
  • CONT 201, for the service this course sandboxes and the habit of measuring a boundary

Lesson path

Least permission3 lessons

A deny list cannot be finished; an allow list can, at a cost

  1. 1The agent that read your keys40 min

    Hand a helpful sandbox one payload that uses no import and watch it succeed

  2. 2The deny list and the ways around it55 min

    Score a careful deny list against all thirty escapes and find where the curve stops improving

  3. 3The allow list and what it costs55 min

    Score an ast allow list on the same set, then on the twenty payloads that should run, and read all four numbers

Isolation2 lessons

A process with a budget, and a filesystem it can only partly see

  1. 4A process with a budget55 min

    Give the work its own process with a memory cap, a CPU cap and a deadline, and see what a killed process leaves behind

  2. 5The filesystem it can see55 min

    Confine a path, then defeat your own confinement with a symlink and a normalisation that ran in the wrong order

Secrets2 lessons

Keeping a key out of the output and out of the traceback

  1. 6Keeping the key out of the output55 min

    Measure a scrubber against bare secrets, then against the six shapes, and explain the gap between the two scores

  2. 7Where a secret actually lives55 min

    Compare env, file and manager on the question of who can read it, and find the one that prints it in a traceback

Judgment2 lessons

What a sandbox still reaches, and a fix that stays fixed

  1. 8What it can still reach55 min

    Name the reach a sandboxed process keeps, and tell a restriction that holds from one that only looks like it does

  2. 9Close one leak and prove it60 min

    Pick a real leak from the earlier lessons, close it, and write the test that goes red when the fix is reverted

About this course

SEC 201 · Permission, Sandboxing, Secret Management

CONT 201 put wave one's retriever in a container and asked what was inside the image. This course asks a narrower question about the same service: when it runs code it did not write, resolves a path a user sent, or logs a message built from a request, what is that code allowed to reach, and what does it leak? The answer for most systems is more than anyone intended, and the course is about closing the gap between what you meant to allow and what you actually did, one measured leak at a time.

The course teaches no attacks. Every payload in it reaches an attribute or a builtin inside your own Python kernel, on your own machine, and none is a technique whose value is that it works against somebody else's system. The payloads are boring on purpose. The point each one makes is not that it is clever but that a filter written in good faith cannot see what a short Python expression can reach, a path can point at, or a secret can be encoded into.

Every number here is measured live in the kernel and is the same on every machine, because the course is the standard library and nothing else. There is no model, no network, and nothing to install; the setup cell confirms it. The cells that isolate a process run short child processes with a CPU cap and a deadline, and every cell returns in a second or two.

How this course teaches

Lesson 1 is a tour: it builds a careful deny list, watches it stop ten obvious payloads, and hands it an eleventh that reaches every class in the program without naming a forbidden word. The eight lessons after it are graded work, each built the same way, and nine of their cells are yours.

  • A prediction you commit to before the cell runs, graded on the reasoning and not the guess, where being wrong is the point.
  • Warmups: a one line blank or a short exercise under the theory it practices, each with a four rung hint ladder whose last rung explains and still does not hand over the code.
  • An exercise that is broken when you open it.
  • A diagnose cell that runs, prints a confident and plausible conclusion, and is wrong, with the evidence that refuses it already on the screen.
  • A challenge that ends in a sentence you write, which the tutor grades, so a green tick earned for the wrong reason can be taken back.

No cell in this course passes in the state it ships, and that is checked mechanically before the course is published.

The particular danger of this subject is a check that answers a different question from the one you asked. A deny list answers does this name a forbidden word when the question is does this reach a forbidden capability. A path check answers does the text start with the base when the question is does the file start with the base. A scrubber answers are these exact characters present when the question is is the secret recoverable. docker ps said Up in the last course; here a green test says safe when the question was would this go red if the fix were reverted. Every diagnose cell is one of those, and every refusal is the measurement that answers the right question.

What you will be able to do

  • Hand a careful deny list one payload that names no forbidden word and watch it reach every class in the program.
  • Build an allow list from an ast walk, stop all thirty escapes, and measure the seven ordinary payloads it refuses.
  • Give a run its own process with a CPU cap and a deadline and read the exit code of a process a signal killed.
  • Confine a path to a directory and defeat the confinement with a symlink and a check that ran in the wrong order.
  • Measure a scrubber perfect on bare secrets and blind to a secret that was base64 encoded or split across a newline.
  • Compare env, file and manager on who can read a secret and find the one that prints it in a traceback.
  • Name the reach a sandbox keeps and tell a restriction that holds from one that only looks like it does.
  • Close a real leak and write the regression test that goes red when the fix is reverted.

The lessons

1. The agent that read your keys. A deny list built from ten obvious payloads stops all ten and waves through ().__class__.__mro__[-1].__subclasses__(), which names no forbidden word and reaches 285 classes. The capability was never behind the word.

2. The deny list and the ways around it. Scored against all thirty escapes, the deny list stops 10 and misses 20, and building it one payload at a time its curve reaches 10 by the ninth payload and never rises again. The twenty subtle payloads add zero new words, and banning the dunders still leaves type(()) through.

3. The allow list and what it costs. An ast walk permitting arithmetic, comprehensions and safe builtins stops all 30 escapes and refuses 7 of 20 ordinary payloads, every one a method call, because a method is an attribute access and the allow list refuses all of them. Four numbers: deny (10, 0), allow (30, 7).

4. A process with a budget. A deadline stops a sleep with no return code, a one second CPU cap kills a busy loop with SIGXCPU and return code -24 on every machine, and a memory cap does whatever the operating system does, which is why the course grades on the first two. A killed process leaves its half-written file behind.

5. The filesystem it can see. A confinement that checks the normalised text refuses a ../ climb and approves a symlink that reads a file outside the base; resolving with realpath first refuses it. The order is the fix, and the base must be resolved too, because the temporary directory is itself a symlink.

6. Keeping the key out of the output. A scrubber built from bare secrets leaks 0 of 3 on bare and 6 of 20 over six shapes, catching URL, JSON and traceback where the secret is contiguous and missing base64 and split where its bytes changed. It redacts none of the twenty clean lines.

7. Where a secret actually lives. An environment variable is inherited by every child process, a file can be owner-only and does not travel, and a manager hands you a self-redacting object. On the traceback axis the plain-string key appears in the error message and the object's [REDACTED] does not, decided by string versus object, not by any scrubber.

8. What it can still reach. The sandbox keeps a large correct reach: it runs 13 of 20 ordinary payloads, computes anything the allow list permits, reads every confined file, and leaves four of seven axes unrestricted. Each axis has a restriction that holds and one that looks like it, told apart only by running the attack.

9. Close one leak and prove it. The path confinement's leak becomes one test, test_symlink_refused, which passes on the fix and fails on the broken code. Of three reasonable tests only that one protects the fix, because only it goes red when someone reverts realpath to normpath.

Requirements

Python 3.10 or later. This course installs nothing and imports only the standard library: ast, os, re, base64, resource, subprocess, signal, tempfile. requires.packages is empty, and the setup cell confirms the imports. The lessons that isolate a process use resource.setrlimit, which is a POSIX feature present on macOS and Linux; the memory-cap cell prints what your operating system does and no graded cell depends on it, so the course runs the same on the Linux runner it is verified on and on a Mac.

What to read outside this course

The Python data model reference defines the dunders lesson 1 walks, __class__, __mro__, __subclasses__, and reading it is how you learn none of it is a trick. The ast module documentation is lesson 3's tool. For the larger argument, the write-ups on why blocklisting eval of untrusted input cannot be made safe reach the same conclusion this course measures. The resource module and the os.path documentation cover the budget and the path resolution of lessons 4 and 5, and os.path.realpath versus normpath is exactly lesson 5's fix. For secrets, any secret-manager's own guidance on not logging credentials is lesson 6 and 7 in prose.