Summary
Sometimes, parts of computer code need to be hidden from helpers that write or modify code, but still accessible to tools that prepare the program for running. The authors looked at different ways to control who can read these hidden parts and found that common methods like containers, permissions, and sandboxes cannot tell who is reading the code. This means it's hard to protect some intellectual property in code from being seen by automated coding assistants, even though it's needed by compilers.
What this means in practice
- •For software developers: Prevent automated coding tools from accessing sensitive code parts while allowing compilers to function properly.
- •For devops teams: Design deployment environments that protect intellectual property in code from unauthorized reading by certain programs.
Abstract
The compiler must read modules a physics-based solver cannot build without; the coding agent must not read that intellectual property. The harness does not ship that rule. We classified fifteen read routes against a container, permission rules and a sandbox. None of the three can tell which program is reading.