netsectool
v0.1.3
Published
Submit solutions for the ETH Network Security course project.
Readme
netsectool
Submit your solutions for the ETH Network Security course project.
npx netsectool@latest login
npx netsectool@latest submit tid01 project/main.goNo installation needed — npx fetches it each time. Node 20 or newer.
Logging in
Your instructor emails you an API token that starts with nst_. You need it
once:
$ npx netsectool@latest login
API token: ****************************************
Verifying token against https://netsec-submit.inf.ethz.ch...
Login successful!
Authentication token stored at /home/you/.netsec-auth-token
Course: netsec-2026
Student: Anna Meier (ameier)The token is stored in ~/.netsec-auth-token with permissions 0600 — readable
only by you. Treat it like a password: it is how the server knows a submission
is yours. If you ever think someone else has seen it, ask your instructor to
issue a new one.
If your course uses a different server:
npx netsectool@latest login --server https://your-server.exampleIt is remembered, so you only pass --server once.
Submitting
$ npx netsectool@latest submit tid01 project/main.go
Submitting main.go to tid01...
✓ Submitted (id: sub_01HQ8ZK3, sha256: 3f9a1c…, 4.2 KB)
Received at 2026-09-22 14:03:11 CESTYou can submit as often as you like. Every submission is kept, and the newest one is what counts. Resubmitting does not delete anything.
Before uploading, the tool checks locally — so you find out instantly, not after
a round trip — that the file exists, is a regular .go file, is within the
task's size limit, is valid UTF-8, and is not empty.
Two things produce a warning but do not block you:
- the filename is not what the task expects (you submitted
solution.gowhen the task wantsmain.go) - the deadline appears to have passed — the tool still sends it and lets the server decide, because your computer's clock is not the authority
The tool sends a SHA-256 of your file, and the server recomputes it and refuses the submission if the two disagree. A corrupted upload is rejected rather than stored.
Checking what you have submitted
$ npx netsectool@latest tasks
Tasks for netsec-2026
TASK TITLE SENT DEADLINE
tid01 Basic Connectivity Test (1P) 2 2026-10-30 23:59:59 CET
tid02 Basic Multipath Test (1P) 1 2026-10-30 23:59:59 CET
tid10 Minimize Carbon Intensity (4P) 0 2026-10-30 23:59:59 CET
...status is where you stand on every test at a glance:
$ npx netsectool@latest status
Your results for netsec-2026
TEST TITLE RESULT RUNS POINTS
tid01 Basic Connectivity Test (1P) v passed 5/5 runs 1/1 P
tid02 Basic Multipath Test (1P) v passed 5/5 runs 1/1 P
tid10 Minimize Carbon Intensity (4P) ~ partial 3/5 runs 2.4/4 P
tid11 Maximize Bandwidth with Bounded Latency (5P) x failed 0/5 runs 0/5 P
tid20 EPIC Hidden-Paths (2P) - queued (#3)
tid30 FABRID Basic Connectivity (3P) - judging
tid31 FABRID: manufacturer A or B (1P) - not submitted
...
14.4 of 27 points
One test in detail: netsectool status <task-id>What each result means:
| Shown | Meaning |
|---|---|
| - not submitted | You have not sent anything for this test yet |
| - queued (#3) | Received and waiting for the judge; the number is your place in line |
| - judging | The judge is running your client right now |
| v passed | Every verifier run passed this test |
| ~ partial | Some verifier runs passed; you get that fraction of the points |
| x failed | Your client ran, but no verifier run passed this test |
| x build failed | Your file did not compile |
| x import check failed | Your file imports a package that is not allowed |
| ! judge error | Something broke on our side, not yours — tell your instructor |
Give it a task id to see the history for one test, with the time of each attempt:
$ npx netsectool@latest status tid01
2 submission(s) for tid01
latest 2026-09-22 14:03:11 CEST main.go
sub_01HQ8ZK3 sha256 3f9a1c… 4.2 KB
ACCEPTED 5/5 runs passed 1/1 P
#2 2026-09-21 09:12:44 CEST main.go
sub_01HQ2FB7 sha256 8c40de… 3.9 KB
WRONG_ANSWER 0/5 runs passed 0/1 POnly your newest submission for a test counts — that is the one shown in the overview and the one a grader takes.
Seeing your result
Every submission is run by the course's judge: it builds your main.go and
runs it against the verifiers, just as the final grading does. This takes a
minute or two. Pass --wait to watch it finish:
$ npx netsectool@latest submit tid10 project/main.go --wait
Submitting main.go to tid10...
✓ Submitted (id: sub_01M36RH8, sha256: 6e0a85…, 12.3 KB)
Received at 2026-09-23 11:11:18 CEST
queued (position 3)...
judging...
sub_01M36RH8 tid10 main.go 2026-09-23 11:11:18 CEST
Verdict PARTIAL 3/5 runs passed
Test ID 10
Points 2.4 of 4
Judged 2026-09-23 11:13:02 CESTWithout --wait, the verdict appears in status and result once it is ready:
npx netsectool@latest result # your newest submission
npx netsectool@latest result tid10 # your newest submission to tid10
npx netsectool@latest result sub_01M36RH8 --wait| Verdict | Meaning |
|---|---|
| ACCEPTED | Every verifier run passed this task's test |
| PARTIAL | Some runs passed; you get that fraction of the points |
| WRONG_ANSWER | Your client ran, but no run passed this test |
| IMPORT_CHECK_FAILED | Your file imports a package that is not allowed. result shows which |
| BUILD_FAILED | Your client did not compile. result shows the compiler output |
| SYSTEM_ERROR | The judge itself failed. Not your fault; tell your instructor |
You see the result for the task you submitted to only. Submitting the same file to another task gives that task's result, and it is instant: identical files are judged once.
Commands
| Command | What it does |
|---|---|
| login | Verify a token and store it |
| logout | Remove the stored token from this machine |
| whoami | Show who the stored token belongs to |
| tasks | List tasks, deadlines and your submission counts |
| submit <task-id> <file> | Submit a file; it is queued for the judge |
| status [task-id] | Your submission history and verdicts, newest first |
| result [id] | The judge's verdict and compiler output (submission id, task id, or your newest) |
Options
| Flag | Meaning |
|---|---|
| --server URL | Talk to a different server |
| --token TOKEN | Use this token instead of the stored one |
| --wait | submit / result: wait until the judge has a verdict |
| --json | Machine-readable output, no colour |
| --no-color | Disable colour |
| -h, --help | Help |
| -v, --version | Version |
Environment variables
| Variable | Meaning |
|---|---|
| NETSECTOOL_SERVER | Default server (--server wins) |
| NETSECTOOL_TOKEN | Default token (--token wins) |
| DEBUG=netsectool* | Print stack traces on failure |
Exit codes
Useful if you submit from a script or a Makefile:
| Code | Meaning |
|---|---|
| 0 | Success |
| 1 | Something went wrong (including a file that cannot be submitted) |
| 2 | You invoked the command incorrectly |
| 3 | Authentication problem — log in again, or ask for a new token |
| 4 | The server considered your submission and rejected it |
| 5 | The server could not be reached |
With --json, successful output is a single JSON document on stdout; errors
are JSON on stderr, so a pipeline reading stdout either gets clean data or
nothing at all.
When something goes wrong
Errors are one line plus a hint:
error The deadline for "tid01" has passed.
hint: The deadline was 2026-10-30T23:59:59+01:00."That does not look like a valid API token." — tokens start with nst_ and
are one long line. Copy the whole value, with no surrounding spaces or quotes.
"… is readable by other users." — the credential file's permissions were
loosened. Run chmod 600 ~/.netsec-auth-token, and ask your instructor for a
new token, since it may have been exposed.
"Could not reach the submission server." — check your network. If you are off campus your course may require the VPN.
"This API token has been revoked." — ask your instructor for a new one.
Your submission stays queued for a long time. Near a deadline many
students submit at once and each run takes a minute or two. result shows your
position in the queue. Your submission counts from when it was received, not
from when it is judged.
For anything else, re-run with DEBUG=netsectool* and include the output when
you ask for help:
DEBUG=netsectool* npx netsectool@latest submit tid01 project/main.goPrivacy
The tool sends your token, the file you name, its filename, and its SHA-256. It does not read anything else from your machine and does not send telemetry. Your submissions are visible to you and to the course staff — never to other students.
