Systems Foundations · core
Security & Isolation Boundaries
Threat models, least privilege, capabilities, process and VM isolation, side channels, and secure defaults.
Mental model
Security is control over authority and information flow. Define the adversary, minimize ambient privilege, isolate tenants, validate boundaries, and fail closed. Scope: this card owns the principles — threat modelling, least privilege, capabilities, and failing closed. Which mechanism implements them, and at what cost, is `sandbox-execution-environments`; applying them to an agent is `agent-permissions-sandboxing`.
How to study Security & Isolation Boundaries
Begin by restating the mental model in your own words, then connect it to a concrete system you have built or operated. Name the mechanism, the constraint it addresses, and the trade-off it introduces. Use The True Cost of Containing: A gVisor Case Study (HotCloud '19), USENIX NSDI '20 — Firecracker: Lightweight Virtualization for Serverless Applications, Firecracker: Lightweight Virtualization for Serverless Applications (NSDI '20) to check details, but close the source before writing your explanation. Retrieval is the learning step; rereading is only preparation.
Next, compare Security & Isolation Boundaries with Runtime & Performance Engineering. Ask what changes in correctness, latency, resource use, operability, and failure recovery. Complete Design exercise: Security & Isolation Boundaries and preserve the command, input, output, and one failed attempt as evidence. Finish by explaining the idea without jargon to someone who has not studied the track.
Proof of understanding
- Explain the mechanism from first principles and identify the state it reads or changes.
- Give one situation where the concept is the right choice and one where it is not.
- Predict a realistic failure mode before running the drill, then compare the prediction with evidence.
- Connect the result to a roadmap or build artifact instead of treating the concept as isolated trivia.
Learn from primary sources
Practice and explain it back
Design exercise: Security & Isolation Boundaries
Threat models, least privilege, capabilities, process and VM isolation, side channels, and secure defaults. Implement designOutline() returning non-empty values for: threatModel, trustBoundary, leastPrivilege. Each value must name a concrete mechanism or decision.
Expected evidence: A design outline with threatModel, trustBoundary, leastPrivilege plus an explicit failure mode or trade-off.
Open the interactive drill →Review prompts
- What does "fail closed" mean at a trust boundary, and why is it a design decision rather than an implementation detail?
Build evidence
Synthesize: Systems Foundations
Build a tiny HTTP/1.1 static-file server on raw TCP sockets without a framework or high-level HTTP server library. Parse requests, serve bounded files, handle partial I/O, inject failures, measure the result, and explain how the operating system, network, memory, concurrency, and storage paths interact.
- Accepts TCP connections, parses a bounded HTTP GET request, serves fixture files, and returns explicit errors for malformed requests, missing files, and path traversal attempts
- Names and implements a concurrency model with connection, request-size, timeout, and resource limits, including correct handling of partial reads and writes
- Injects at least a slow client, malformed request, or interrupted transfer and demonstrates bounded failure and recovery
- Reports a reproducible workload with throughput, p50/p95 latency, peak memory, and open-connection observations
- Explains the loader, process, syscall, buffer, filesystem, TCP, and scheduling path in a concise architecture note