# The intake standard

> The intake standard v0 is the list of nine rules, IS-1 to IS-9, that a Harbor task must meet before it can be audited.

Source: https://docs.horizon-audit.online/docs/guide/intake-standard

The intake standard is the published list of nine rules a task must meet before it can be audited, IS-1 to IS-9. A task that misses a rule is not judged. It comes back as "Needs from you", with one line for each rule it misses.

This page is version v0 of the standard. The ids are never renumbered. Each intake result records the version of the standard it was checked against.

## The rules

Every line you see for a miss starts with "Needs from you:". A line names what is needed and where. It never says how to write it.

### IS-1 An instruction

- Requires: `instruction.md` exists and has text.
- Why: with no instruction there is nothing to hold the grader against.
- You see: "Needs from you: an instruction at `instruction.md`."
- You see, when the file has no text: "Needs from you: an `instruction.md` that has text."

### IS-2 A verifier

- Requires: `tests/test.sh` exists. A Windows task has `tests/test.bat` instead.
- Why: the verifier is the grader. A task with none cannot be scored.
- You see: "Needs from you: a verifier at `tests/test.sh`." For a Windows task the line names `tests/test.bat`.

### IS-3 A configuration that parses

- Requires: `task.toml` parses.
- Why: the configuration says how the task runs. A file that does not parse says nothing.
- You see: "Needs from you: a `task.toml` that parses. It fails at:" followed by the line and the parser's message.

### IS-4 An environment

- Requires: one of `environment/Dockerfile`, `environment/docker-compose.yaml`, or `docker_image` under `[environment]` in `task.toml`.
- Why: every run of the audit happens inside the environment the task declares.
- You see: "Needs from you: an environment: `environment/Dockerfile`, `environment/docker-compose.yaml`, or `docker_image` in `task.toml`."
- You see, when the miss is in a separate verifier environment: "Needs from you: an environment for the verifier. `task.toml` declares a separate one under `[verifier.environment]`."

### IS-5 A reference solution

- Requires: `solution/solve.sh` exists, and runs something. A Windows task has `solution/solve.bat` instead.
- Why: the reference solution shows that the task can be solved as written.
- You see: "Needs from you: a reference solution at `solution/solve.sh`." For a Windows task the line names `solution/solve.bat`.
- You see, when the script is a placeholder: "Needs from you: a reference solution that runs something, not a placeholder."

Whether the solution works is a question for the audit, not for this rule.

### IS-6 An environment that builds

- Requires: the environment builds today, from what the task declares.
- Why: a task that no longer builds cannot be run by anyone, model or auditor.
- You see: "Needs from you: an environment that builds. The build stopped at:" followed by the step and the last lines of its output.

The build is attempted only when IS-3, IS-4, IS-8 and IS-9 are met. A build failure on our side is never a miss of this rule.

### IS-7 Every secret declared and supplied

- Requires: every key or outside account the task needs is declared in `task.toml` as `${NAME}`, and a value is supplied for each name.
- Why: an undeclared secret makes a run fail for a reason that is not in the task.

### IS-8 No access to the host

- Requires: `environment/docker-compose.yaml`, when the task has one, uses only settings that keep the task inside its sandbox.
- Why: a task is run as it is written, so it must be safe to run as it is written.
- You see: "Needs from you: a compose file that does not ask for access to the host." followed by the file, the line and the setting.

### IS-9 Resources within the limits

- Requires: `cpus`, `memory_mb` and `storage_mb` under `[environment]` are within the limits of the audit sandbox.
- Why: a task that asks for more than the sandbox has cannot be run as written.
- You see: "Needs from you: resources within the limits of the audit sandbox." followed by what the task asks for and the limit.

[Fix and resubmit](/docs/guide/fix-and-resubmit) says how a request is met.
