deepseek-harness/native/landlock-run/packages/entry
2026-08-13 15:32:17 +08:00
..
src refactor: replace overloaded surface terminology 2026-08-11 15:23:05 +08:00
package.json release(landlock-run): 0.1.1 2026-08-13 15:32:17 +08:00
README.i18n.yaml docs(i18n): standardize contract terminology 2026-08-09 11:33:14 +08:00
README.md fix(landlock-run): publish under deepseek scope 2026-08-06 14:41:17 +08:00
README.zh.md docs(i18n): standardize contract terminology 2026-08-09 11:33:14 +08:00
tsconfig.json chore: adopt node-addon-landlock-run source as native/ subtree 2026-07-14 23:39:58 +08:00

@deepseek-ai/node-addon-landlock-run

English | 中文

Landlock self-restrict-then-exec launcher for confining subprocesses on Linux: this entry package resolves the per-platform prebuilt binary, runs its functional enforcement probe, and builds its grant argv — consumers never spell launcher flags or parse launcher output themselves.

import { grantArgs, launcherPath, probe } from '@deepseek-ai/node-addon-landlock-run';

const launcher = launcherPath();
if (probe(launcher) !== 'unusable') {
  const argv = [launcher, ...grantArgs({ readOnly: ['/'], readWrite: ['/tmp/work'] }), '--', 'bash', '-c', command];
}

The launcher installs a Landlock ruleset on itself and execs the wrapped command; the ruleset is inherited across execve, so the whole process tree runs confined. Everything not granted is denied, and launcher failures exit 125 without running the command — fail-closed, never fail-open. The binary contract is pinned in the repo's docs/cli-contract.md; the C source rides this tarball (src/main.c) for audit.

Platform packages (os/cpu-selected optional dependencies, no JavaScript inside): @deepseek-ai/node-addon-landlock-run-linux-x64, @deepseek-ai/node-addon-landlock-run-linux-arm64. On hosts without one, launcherPath() returns a deterministic nonexistent path and probe() reports 'unusable' — there is deliberately no install-time compile fallback.