Using a library that reflects
Simple Story
A piece of equipment the exercise depends on inspects its own internals, and the checklist refuses it.
This page is a stub
The outline below is the intended structure and is not yet written. Until it is, use the Policy Reference for the individual fields.
The situation
A legitimate dependency trips the reflection rules, and the exercise must keep working without the student gaining reflective access.
The policy fragment
The smallest security-policy.yaml addition that solves it, shown in full so it can be pasted
into an existing policy.
What this still forbids
The operations the recipe deliberately does not enable, so the boundary stays visible.
The tempting wrong version
Adding the reflecting package to the allow-list at a level that exempts the student's own code as well.
Notes
- Check the recipe against both controls: the permitted operation must succeed, and the nearest forbidden neighbour must still be rejected.