Bring the node-addon-landlock-run tree (tag v0.0.1, commit 614f7fd) into native/landlock-run as its source of record: launcher development happens here, next to the harness consumers, and the standalone repository becomes the release mirror the tree is exported to for packing and publishing (procedure in native/README.md). The subtree keeps its own pnpm workspace and lockfile and is NOT added to the harness workspace: harness installs, gates, and CI never touch it. The mirror's .github/ stays out of the subtree; a separate manually-dispatched workflow (.github/workflows/landlock-run.yml) runs the subtree's CI legs — the per-architecture native builds, real-kernel launcher proofs, and pack rehearsal — adapted with working-directory/cache paths. eslint ignores the subtree like vendor/; AGENTS.md gains the native/ layout line (+5 words on its budget ceiling).
1.3 KiB
node-addon-landlock-run
Landlock self-restrict-then-exec launcher for confining subprocesses on Linux: this entry package resolves the per-platform prebuilt binary, runs its functional enforcement probe, and builds its grant argv — consumers never spell launcher flags or parse launcher output themselves.
import { grantArgs, launcherPath, probe } from 'node-addon-landlock-run';
const launcher = launcherPath();
if (probe(launcher) !== 'unusable') {
const argv = [launcher, ...grantArgs({ readOnly: ['/'], readWrite: ['/tmp/work'] }), '--', 'bash', '-c', command];
}
The launcher installs a Landlock ruleset on itself and execs the wrapped command; the ruleset is inherited across execve, so the whole process tree runs confined. Everything not granted is denied, and launcher failures exit 125 without running the command — fail-closed, never fail-open. The binary contract is pinned in the repo's docs/cli-contract.md; the C source rides this tarball (src/main.c) for audit.
Platform packages (os/cpu-selected optional dependencies, no JavaScript inside): node-addon-landlock-run-linux-x64, node-addon-landlock-run-linux-arm64. On hosts without one, launcherPath() returns a deterministic nonexistent path and probe() reports 'unusable' — there is deliberately no install-time compile fallback.