# CI for the landlock-run packages under native/landlock-run. A separate # workflow from ci.yml keeps the native OS/architecture matrix independent of # the harness Node matrix. Release assembly and publication use the companion # Landlock Run Release workflow. name: Landlock Run on: pull_request: paths: - '.github/workflows/landlock-run.yml' - '.github/workflows/landlock-run-release.yml' - 'native/landlock-run/**' - 'package.json' - 'pnpm-lock.yaml' - 'pnpm-workspace.yaml' push: branches: [master] paths: - '.github/workflows/landlock-run.yml' - '.github/workflows/landlock-run-release.yml' - 'native/landlock-run/**' - 'package.json' - 'pnpm-lock.yaml' - 'pnpm-workspace.yaml' workflow_dispatch: concurrency: group: ${{ github.workflow }}-${{ github.ref }} cancel-in-progress: true permissions: contents: read env: # CI runs must never report to the production telemetry endpoint baked # into apps/cli/cordis.yml (AppCLIEntry disables the row when set). DSH_TELEMETRY_DISABLED: '1' defaults: run: working-directory: native/landlock-run jobs: matrix: name: Matrix runs-on: ubuntu-24.04 outputs: ci: ${{ steps.matrix.outputs.ci }} steps: - uses: actions/checkout@v4 - id: matrix run: echo "ci=$(node ./scripts/github-matrix.mjs ci)" >> "$GITHUB_OUTPUT" native: name: ${{ matrix.platform }} needs: matrix runs-on: ${{ matrix.runner }} strategy: fail-fast: false matrix: ${{ fromJson(needs.matrix.outputs.ci) }} steps: - uses: actions/checkout@v4 - uses: pnpm/action-setup@v4 with: package_json_file: package.json - uses: actions/setup-node@v4 with: node-version: 24 cache: pnpm cache-dependency-path: pnpm-lock.yaml - name: Install dependencies run: pnpm install --filter @deepseek-ai/node-addon-landlock-run-workspace... --frozen-lockfile - name: Install musl toolchain run: | sudo apt-get update -q sudo apt-get install -yq musl-tools - name: Build TypeScript run: pnpm build:ts - name: Typecheck run: pnpm typecheck - name: Build native binaries (this architecture is the builder of record) run: pnpm build:native - name: Entry tests (keyless) run: node ./test/entry.test.js # NALR_REQUIRE_LANDLOCK: a self-skip on the very platform that exists to # prove enforcement would be a false green, so an unenforcing kernel # fails the leg instead of skipping. - name: Launcher tests (real kernel enforcement) run: node ./test/launcher.test.js env: NALR_REQUIRE_LANDLOCK: 1 - name: Pack rehearsal (pack → install → confine, this platform only) run: | node ./scripts/pack-release.mjs .release/npm --current-platform-only node ./scripts/verify-packed-install.mjs .release/npm --current-platform-only env: NALR_REQUIRE_LANDLOCK: 1 darwin: name: darwin (no platform package — degradation proof) runs-on: macos-latest steps: - uses: actions/checkout@v4 - uses: pnpm/action-setup@v4 with: package_json_file: package.json - uses: actions/setup-node@v4 with: node-version: 24 cache: pnpm cache-dependency-path: pnpm-lock.yaml - name: Install dependencies run: pnpm install --filter @deepseek-ai/node-addon-landlock-run-workspace... --frozen-lockfile - name: Build TypeScript run: pnpm build:ts - name: Typecheck run: pnpm typecheck - name: Entry tests (keyless) run: node ./test/entry.test.js - name: Launcher tests (must self-skip cleanly) run: node ./test/launcher.test.js - name: Pack rehearsal (entry only — fallback resolution + unusable probe) run: | node ./scripts/pack-release.mjs .release/npm --current-platform-only node ./scripts/verify-packed-install.mjs .release/npm --current-platform-only