Răsfoiți Sursa

refactor(native): rename package family to node-addon-system

imccyu 2 săptămâni în urmă
părinte
comite
7264906f99
83 a modificat fișierele cu 236 adăugiri și 236 ștergeri
  1. 2 2
      .agents/notes/implemented/feature/2026-07-06-sandbox.i18n.yaml
  2. 1 1
      .agents/notes/implemented/feature/2026-07-06-sandbox.md
  3. 1 1
      .agents/notes/implemented/feature/2026-07-06-sandbox.zh.md
  4. 2 2
      .agents/notes/implemented/process/2026-08-10-npm-release-sequences.i18n.yaml
  5. 2 2
      .agents/notes/implemented/process/2026-08-10-npm-release-sequences.md
  6. 2 2
      .agents/notes/implemented/process/2026-08-10-npm-release-sequences.zh.md
  7. 10 10
      .github/workflows/node-addon-system-release.yml
  8. 12 12
      .github/workflows/node-addon-system.yml
  9. 2 2
      .github/workflows/release-publish.yml
  10. 2 2
      .github/workflows/release.yml
  11. 3 3
      .github/workflows/sandbox.yml
  12. 1 1
      AGENTS.md
  13. 1 1
      THIRD_PARTY_NOTICES.md
  14. 2 2
      apps/desktop/scripts/package-target.ts
  15. 1 1
      apps/web/tests/preview-boot.e2e.ts
  16. 2 2
      native/README.i18n.yaml
  17. 3 3
      native/README.md
  18. 3 3
      native/README.zh.md
  19. 3 3
      native/system/README.i18n.yaml
  20. 6 6
      native/system/README.md
  21. 6 6
      native/system/README.zh.md
  22. 3 3
      native/system/docs/architecture.md
  23. 3 3
      native/system/docs/naming.md
  24. 3 3
      native/system/docs/packaging.md
  25. 18 18
      native/system/docs/release.md
  26. 2 2
      native/system/docs/support-matrix.md
  27. 2 2
      native/system/package.json
  28. 3 3
      native/system/packages/entry/README.i18n.yaml
  29. 3 3
      native/system/packages/entry/README.md
  30. 3 3
      native/system/packages/entry/README.zh.md
  31. 4 4
      native/system/packages/entry/package.json
  32. 2 2
      native/system/packages/entry/src/index.ts
  33. 1 1
      native/system/packages/entry/src/main.c
  34. 3 3
      native/system/packages/linux-arm64/README.i18n.yaml
  35. 3 3
      native/system/packages/linux-arm64/README.md
  36. 3 3
      native/system/packages/linux-arm64/README.zh.md
  37. 3 3
      native/system/packages/linux-arm64/package.json
  38. 3 3
      native/system/packages/linux-x64/README.i18n.yaml
  39. 3 3
      native/system/packages/linux-x64/README.md
  40. 3 3
      native/system/packages/linux-x64/README.zh.md
  41. 3 3
      native/system/packages/linux-x64/package.json
  42. 2 2
      native/system/scripts/commit-release.mjs
  43. 3 3
      native/system/scripts/verify-packed-install.mjs
  44. 4 4
      native/system/scripts/verify-release.mjs
  45. 2 2
      native/system/test/entry.test.js
  46. 1 1
      native/system/test/launcher.test.js
  47. 2 2
      package.json
  48. 2 2
      packages/experimental/webworker-packer/README.i18n.yaml
  49. 1 1
      packages/experimental/webworker-packer/README.md
  50. 1 1
      packages/experimental/webworker-packer/README.zh.md
  51. 1 1
      packages/experimental/webworker-packer/src/repository.ts
  52. 2 2
      packages/experimental/webworker-packer/tests/image-loadable.spec.ts
  53. 2 2
      packages/experimental/webworker-runtime/README.i18n.yaml
  54. 1 1
      packages/experimental/webworker-runtime/README.md
  55. 1 1
      packages/experimental/webworker-runtime/README.zh.md
  56. 1 1
      packages/experimental/webworker-runtime/package.json
  57. 1 1
      packages/experimental/webworker-runtime/tests/node/child-process.spec.ts
  58. 1 1
      packages/experimental/webworker-runtime/tests/node/node-stubs.spec.ts
  59. 2 2
      packages/sandbox/sandbox-local/README.i18n.yaml
  60. 1 1
      packages/sandbox/sandbox-local/README.md
  61. 1 1
      packages/sandbox/sandbox-local/README.zh.md
  62. 1 1
      packages/sandbox/sandbox-local/package.json
  63. 1 1
      packages/sandbox/sandbox-local/src/index.ts
  64. 1 1
      packages/sandbox/sandbox-local/src/profiles.ts
  65. 1 1
      packages/sandbox/sandbox-local/tests/landlock.e2e.ts
  66. 1 1
      packages/sandbox/sandbox-local/tests/local.spec.ts
  67. 4 4
      packages/sandbox/sandbox-local/tests/packed-install.e2e.ts
  68. 1 1
      packages/sandbox/sandbox-local/tsconfig.json
  69. 1 1
      packages/shell/bash-sandbox/package.json
  70. 2 2
      packages/shell/bash-sandbox/tests/landlock.e2e.ts
  71. 1 1
      packages/shell/bash-sandbox/tests/partial-landlock.spec.ts
  72. 1 1
      packages/shell/bash-sandbox/tsconfig.json
  73. 13 13
      pnpm-lock.yaml
  74. 3 3
      pnpm-workspace.yaml
  75. 3 3
      scripts/benchmark-npm-resolution.ts
  76. 1 1
      scripts/check-workspace-constraints.spec.ts
  77. 16 16
      scripts/check-workspace-constraints.ts
  78. 3 3
      scripts/clean.spec.ts
  79. 2 2
      scripts/clean.ts
  80. 3 3
      scripts/gen-third-party-notices.spec.ts
  81. 5 5
      scripts/gen-third-party-notices.ts
  82. 1 1
      tsconfig.base.json
  83. 1 1
      tsconfig.host.json

+ 2 - 2
.agents/notes/implemented/feature/2026-07-06-sandbox.i18n.yaml

@@ -2,5 +2,5 @@
 # side as of the last confirmed-consistent state. Both languages carry equal authority;
 # after editing either side, bring the other along and re-record with:
 #   pnpm run verify-translation-pairing --write .agents/notes/implemented/feature/2026-07-06-sandbox.md
-2026-07-06-sandbox.md: a6e5639e21ca7140cb0314c9918319e99b1495f6
-2026-07-06-sandbox.zh.md: 5144b3fa719465707d7fb2870d45094b8c07661a
+2026-07-06-sandbox.md: 31d96836ad2f932f2abf7d1d76242a711f0de2f6
+2026-07-06-sandbox.zh.md: fdf5f4b1691b4a55fffbd206847c99307e12c9da

+ 1 - 1
.agents/notes/implemented/feature/2026-07-06-sandbox.md

@@ -64,7 +64,7 @@ Left open, for the phase that needs them: whether network restriction arrives as
 
 The launcher is a ~300-line C program (plain C11 over the raw Landlock UAPI — no libraries beyond a statically linked musl, so the audit surface is that one file plus the kernel's stable syscall contract): `--ro <path>` / `--rw <path>` grants, `--`, the wrapped argv; it installs the ruleset on itself and `exec`s (rulesets are inherited across `execve`, and it sets `no_new_privs` before restricting); `--probe` enforces a maximal ruleset in a short-lived child and exits 0 only when the kernel actually enforces; every launcher failure exits 125 without running the child and prints a fatal `landlock-run:` line. A successfully exec'd child may also return 125, so status alone is not launcher evidence. An older ABI prints the exact `landlock-run: partial enforcement (older Landlock ABI)` notice before it executes the child, so that line is not fatal evidence.
 
-The Landlock launcher source and package family live at `native/landlock-run`, next to the harness consumers and inside the root pnpm workspace. The [`native/` README](../../../../native/README.md) owns the shared lockfile, native build, pack rehearsal, and npm publication boundary. Platform binaries are selected by npm, and the entry package owns path resolution, probing, CLI flags, the fatal prefix, and the partial-enforcement notice while the harness maps sandbox modes to grants. Versioning the entry point with its binaries keeps probe parsing and launch syntax aligned.
+The Landlock launcher source and package family live at `native/system`, next to the harness consumers and inside the root pnpm workspace. The [`native/` README](../../../../native/README.md) owns the shared lockfile, native build, pack rehearsal, and npm publication boundary. Platform binaries are selected by npm, and the entry package owns path resolution, probing, CLI flags, the fatal prefix, and the partial-enforcement notice while the harness maps sandbox modes to grants. Versioning the entry point with its binaries keeps probe parsing and launch syntax aligned.
 
 Backend profiles share the mode contract but differ in necessary host grants. Landlock and Seatbelt allow only `/dev/null` in read-only mode; workspace-write also permits their required host temp roots. Each wrap carries backend-specific denial signatures. Landlock reports partial enforcement on older ABIs that cannot govern every operation, while successful bwrap and Seatbelt profiles report full enforcement.
 

+ 1 - 1
.agents/notes/implemented/feature/2026-07-06-sandbox.zh.md

@@ -64,7 +64,7 @@ OS 子进程约束适用于 bash 执行器(包括钩子命令),后续还
 
 launcher 是一个约 300 行的 C 程序(纯 C11,直接使用 Landlock UAPI——除静态链接的 musl 外无其他库,因此审计面仅为该文件加内核的稳定 syscall 约定):`--ro <path>` / `--rw <path>` 授权,`--`,被包装的 argv;它为自身安装规则集并执行 `exec`(规则集跨 `execve` 继承,且它在限制前设置 `no_new_privs`);`--probe` 在一个短生命周期子进程中强制最大规则集,仅当内核确实强制时才以 0 退出;所有 launcher 失败都会以 125 退出且不运行子进程,并打印一行致命的 `landlock-run:` 诊断。成功完成 exec 的子进程也可能返回 125,因此仅凭退出状态不能作为 launcher 失败的证据。较旧的 ABI 会在执行子进程之前打印精确的 `landlock-run: partial enforcement (older Landlock ABI)` 通知,因此该行不是致命证据。
 
-Landlock launcher 源码和包家族位于 `native/landlock-run`,与 harness 消费方同仓,并属于根 pnpm workspace。[`native/` README](../../../../native/README.zh.md)负责共享锁文件、原生构建、打包演练和 npm 发布边界。平台二进制由 npm 选择,入口包拥有路径解析、探测、CLI(命令行界面)参数、致命前缀和部分强制执行通知,而 harness 将沙箱模式映射为授权。将入口点与其二进制一起版本化,使探测解析和启动语法保持对齐。
+Landlock launcher 源码和包家族位于 `native/system`,与 harness 消费方同仓,并属于根 pnpm workspace。[`native/` README](../../../../native/README.zh.md)负责共享锁文件、原生构建、打包演练和 npm 发布边界。平台二进制由 npm 选择,入口包拥有路径解析、探测、CLI(命令行界面)参数、致命前缀和部分强制执行通知,而 harness 将沙箱模式映射为授权。将入口点与其二进制一起版本化,使探测解析和启动语法保持对齐。
 
 后端 profile 共享模式约定但在必要的主机授权上有所不同。Landlock 和 Seatbelt 在 read-only 模式下仅允许 `/dev/null`;workspace-write 还允许各自所需的主机临时目录根。每次包装携带后端特定的拒绝签名。Landlock 在较旧的 ABI 无法管控所有操作时报告 partial enforcement,而成功的 bwrap 和 Seatbelt profile 报告 full enforcement。
 

+ 2 - 2
.agents/notes/implemented/process/2026-08-10-npm-release-sequences.i18n.yaml

@@ -2,5 +2,5 @@
 # side as of the last confirmed-consistent state. Both languages carry equal authority;
 # after editing either side, bring the other along and re-record with:
 #   pnpm run verify-translation-pairing --write .agents/notes/implemented/process/2026-08-10-npm-release-sequences.md
-2026-08-10-npm-release-sequences.md: 6729b506a9cfe7f6d4410dbf0750621901e07293
-2026-08-10-npm-release-sequences.zh.md: 18a30d6dd57c17b8e13cc3a1f71bc91242a391ff
+2026-08-10-npm-release-sequences.md: c403964d8de1c158e5949b5e112a038832709874
+2026-08-10-npm-release-sequences.zh.md: d03da4c4485c4807497dfb28b61ab342bb4c8d12

+ 2 - 2
.agents/notes/implemented/process/2026-08-10-npm-release-sequences.md

@@ -8,7 +8,7 @@ English | [中文](2026-08-10-npm-release-sequences.zh.md)
 
 This repository held three unrelated groups of publishable packages and no channel that sent any of them to a registry.
 
-`packages/*/*` and `apps/*` form the runtime surface of `@deepseek-ai/dsh`; `vendor/*` holds nine rescoped Cordis framework packages, each carrying its upstream version; `native/landlock-run/packages/*` holds Linux platform packages with their own workflow. The three differ in version baseline, change rate, and build requirements: dsh moves with the product, vendor moves only when upstream is re-synced or a local modification changes, and native needs a musl toolchain and one build per architecture. Forcing them through one pipeline means every product release republishes the framework and the native binaries.
+`packages/*/*` and `apps/*` form the runtime surface of `@deepseek-ai/dsh`; `vendor/*` holds nine rescoped Cordis framework packages, each carrying its upstream version; `native/system/packages/*` holds Linux platform packages with their own workflow. The three differ in version baseline, change rate, and build requirements: dsh moves with the product, vendor moves only when upstream is re-synced or a local modification changes, and native needs a musl toolchain and one build per architecture. Forcing them through one pipeline means every product release republishes the framework and the native binaries.
 
 Two hard blockers sat in the way. All 217 workspace manifests set `private: true`, which npm refuses to publish. The subtler one was 933 hand-written `peerDependencies: "^0.0.1"` entries between sibling dsh packages: `pnpm pack` substitutes the `workspace:` protocol but leaves semver ranges alone, and `^0.0.1` means `>=0.0.1 <0.0.2` — it excludes `0.0.2`, and semver excludes prereleases from a range without a prerelease of its own, so it excluded `0.0.1-rc.1` too. Those entries never failed only because the version never left `0.0.1`.
 
@@ -24,7 +24,7 @@ Two hard blockers sat in the way. All 217 workspace manifests set `private: true
 |---|---|---|---|---|
 | dsh | Publish set: non-experimental `packages/*/*` + `apps/*`; private experimental packages join only the shared version bump | one version for the publish set, private dsh packages, and workspace root, `0.0.x` | `dsh-v<version>` | `release.yml` (pack) / `release-publish.yml` (publish) |
 | vendored framework | the nine `vendor/*` packages | each package on its own version line | `vendor-<package>-v<version>` (one per package) | `release-vendor.yml` (pack) / `release-vendor-publish.yml` (publish) |
-| native | `native/landlock-run/packages/*` | its own `0.0.x` | `landlock-run-v<version>` | `landlock-run-release.yml` |
+| native | `native/system/packages/*` | its own `0.0.x` | `node-addon-system-v<version>` | `node-addon-system-release.yml` |
 
 All three publish to the `@deepseek-ai` scope on npmjs.com, and access is per sequence rather than per scope: the vendored framework and the native packages are `public`, and the dsh family has been `public` since its own sequence went public on 2026-08-13 ([rationale](../../archived/process/2026-08-13-public-vendor-and-native-sequences.md)). No publish path passes `--access`, because one flag cannot serve sequences that disagree and would override the manifest that owns the level.
 

+ 2 - 2
.agents/notes/implemented/process/2026-08-10-npm-release-sequences.zh.md

@@ -8,7 +8,7 @@ Status: implemented
 
 这个仓库有三组互不相干的可发布包,却没有任何发布通道把它们送上 registry。
 
-`packages/*/*` 与 `apps/*` 组成 `@deepseek-ai/dsh` 的运行面;`vendor/*` 是九个 rescope 过的 Cordis 框架包,各自带着上游的版本号;`native/landlock-run/packages/*` 是 Linux 平台包,有自己的 workflow。三组的版本基线、变更节奏和构建要求都不同:dsh 随产品迭代,vendor 只在同步上游或改动本地修改时才动,native 需要 musl 工具链和逐架构构建。把它们塞进一条发布流水线,等于每次产品发版都要重发框架和原生二进制。
+`packages/*/*` 与 `apps/*` 组成 `@deepseek-ai/dsh` 的运行面;`vendor/*` 是九个 rescope 过的 Cordis 框架包,各自带着上游的版本号;`native/system/packages/*` 是 Linux 平台包,有自己的 workflow。三组的版本基线、变更节奏和构建要求都不同:dsh 随产品迭代,vendor 只在同步上游或改动本地修改时才动,native 需要 musl 工具链和逐架构构建。把它们塞进一条发布流水线,等于每次产品发版都要重发框架和原生二进制。
 
 挡路的还有两处硬门。全部 217 个 workspace manifest 都是 `private: true`,`npm publish` 直接拒绝。更隐蔽的是 933 条 dsh 兄弟包之间硬写的 `peerDependencies: "^0.0.1"`:`pnpm pack` 只替换 `workspace:` 协议,不动语义范围,而 `^0.0.1` 等于 `>=0.0.1 <0.0.2`——发 `0.0.2` 落不进去,发 `0.0.1-rc.1` 也落不进去(semver 规定不带预发布段的范围排除预发布版本)。这些条目至今没出事,只因为版本一直停在 `0.0.1`。
 
@@ -24,7 +24,7 @@ Status: implemented
 |---|---|---|---|---|
 | dsh | 发布集:非 experimental 的 `packages/*/*` + `apps/*`;私有实验性包仅加入共享版本 bump | 发布集、私有 dsh 包与 workspace 根共用一个 `0.0.x` | `dsh-v<版本>` | `release.yml`(pack)/ `release-publish.yml`(发布) |
 | vendored framework | `vendor/*` 九个包 | 每包各自一条版本线 | `vendor-<包名>-v<版本>`(每包一个) | `release-vendor.yml`(pack)/ `release-vendor-publish.yml`(发布) |
-| native | `native/landlock-run/packages/*` | 自己的 `0.0.x` | `landlock-run-v<版本>` | `landlock-run-release.yml` |
+| native | `native/system/packages/*` | 自己的 `0.0.x` | `node-addon-system-v<版本>` | `node-addon-system-release.yml` |
 
 三组一律发到 npmjs.com 的 `@deepseek-ai` scope,且 access 按序列而非按 scope 区分:vendored 框架与 native 包是 `public`,dsh 族自 2026-08-13 其自身序列公开发布起即为 `public`([理由](../../archived/process/2026-08-13-public-vendor-and-native-sequences.md))。没有任何发布路径传 `--access`——一个选项无法服务级别互不相同的序列,且会覆盖真正拥有该级别的 manifest。
 

+ 10 - 10
.github/workflows/landlock-run-release.yml → .github/workflows/node-addon-system-release.yml

@@ -1,13 +1,13 @@
-# Build and publish the @deepseek-ai/node-addon-landlock-run package family from the
+# Build and publish the @deepseek-ai/node-addon-system package family from the
 # harness source of record. Rehearsal and publication consume the same packed
 # tarballs; each native binary is built on its matching architecture.
-name: Landlock Run Release
+name: Node Addon System Release
 
 on:
   workflow_dispatch:
     inputs:
       publish:
-        description: Publish packed tarballs to npm. Must run from a landlock-run-v* tag.
+        description: Publish packed tarballs to npm. Must run from a node-addon-system-v* tag.
         required: true
         type: boolean
         default: false
@@ -23,7 +23,7 @@ concurrency:
 
 defaults:
   run:
-    working-directory: native/landlock-run
+    working-directory: native/system
 
 jobs:
   matrix:
@@ -58,7 +58,7 @@ jobs:
           cache-dependency-path: pnpm-lock.yaml
 
       - name: Install dependencies
-        run: pnpm install --filter @deepseek-ai/node-addon-landlock-run-workspace... --frozen-lockfile
+        run: pnpm install --filter @deepseek-ai/node-addon-system-workspace... --frozen-lockfile
 
       - name: Install musl toolchain
         run: |
@@ -75,7 +75,7 @@ jobs:
         uses: actions/upload-artifact@v4
         with:
           name: ${{ matrix.artifact }}
-          path: native/landlock-run/${{ matrix.dir }}/bin/*
+          path: native/system/${{ matrix.dir }}/bin/*
           if-no-files-found: error
           retention-days: 7
 
@@ -97,7 +97,7 @@ jobs:
           cache-dependency-path: pnpm-lock.yaml
 
       - name: Install dependencies
-        run: pnpm install --filter @deepseek-ai/node-addon-landlock-run-workspace... --frozen-lockfile
+        run: pnpm install --filter @deepseek-ai/node-addon-system-workspace... --frozen-lockfile
 
       - name: Build TypeScript
         run: pnpm build:ts
@@ -111,7 +111,7 @@ jobs:
         uses: actions/download-artifact@v4
         with:
           pattern: prebuild-*
-          path: native/landlock-run/.release/prebuild-artifacts
+          path: native/system/.release/prebuild-artifacts
 
       - name: Assemble and verify prebuilds
         run: node ./scripts/assemble-prebuilds.mjs .release/prebuild-artifacts
@@ -133,7 +133,7 @@ jobs:
         uses: actions/upload-artifact@v4
         with:
           name: npm-tarballs
-          path: native/landlock-run/dist/npm/*
+          path: native/system/dist/npm/*
           if-no-files-found: error
           retention-days: 7
 
@@ -162,7 +162,7 @@ jobs:
         uses: actions/download-artifact@v4
         with:
           name: npm-tarballs
-          path: native/landlock-run/dist/npm
+          path: native/system/dist/npm
 
       - name: Configure npm token fallback
         env:

+ 12 - 12
.github/workflows/landlock-run.yml → .github/workflows/node-addon-system.yml

@@ -1,24 +1,24 @@
-# CI for the landlock-run packages under native/landlock-run. A separate
+# CI for the node-addon-system packages under native/system. A separate
 # workflow from ci.yml keeps the native OS/architecture matrix independent of
 # the harness Node matrix. Release assembly and publication use the companion
-# Landlock Run Release workflow.
-name: Landlock Run
+# Node Addon System Release workflow.
+name: Node Addon System
 
 on:
   pull_request:
     paths:
-      - '.github/workflows/landlock-run.yml'
-      - '.github/workflows/landlock-run-release.yml'
-      - 'native/landlock-run/**'
+      - '.github/workflows/node-addon-system.yml'
+      - '.github/workflows/node-addon-system-release.yml'
+      - 'native/system/**'
       - 'package.json'
       - 'pnpm-lock.yaml'
       - 'pnpm-workspace.yaml'
   push:
     branches: [master]
     paths:
-      - '.github/workflows/landlock-run.yml'
-      - '.github/workflows/landlock-run-release.yml'
-      - 'native/landlock-run/**'
+      - '.github/workflows/node-addon-system.yml'
+      - '.github/workflows/node-addon-system-release.yml'
+      - 'native/system/**'
       - 'package.json'
       - 'pnpm-lock.yaml'
       - 'pnpm-workspace.yaml'
@@ -38,7 +38,7 @@ env:
 
 defaults:
   run:
-    working-directory: native/landlock-run
+    working-directory: native/system
 
 jobs:
   matrix:
@@ -73,7 +73,7 @@ jobs:
           cache-dependency-path: pnpm-lock.yaml
 
       - name: Install dependencies
-        run: pnpm install --filter @deepseek-ai/node-addon-landlock-run-workspace... --frozen-lockfile
+        run: pnpm install --filter @deepseek-ai/node-addon-system-workspace... --frozen-lockfile
 
       - name: Install musl toolchain
         run: |
@@ -124,7 +124,7 @@ jobs:
           cache-dependency-path: pnpm-lock.yaml
 
       - name: Install dependencies
-        run: pnpm install --filter @deepseek-ai/node-addon-landlock-run-workspace... --frozen-lockfile
+        run: pnpm install --filter @deepseek-ai/node-addon-system-workspace... --frozen-lockfile
 
       - name: Build TypeScript
         run: pnpm build:ts

+ 2 - 2
.github/workflows/release-publish.yml

@@ -76,8 +76,8 @@ jobs:
       # are optional, and building them needs a musl toolchain per architecture.
       - name: Pack the Landlock entry for verification
         run: |
-          pnpm --dir native/landlock-run run build:ts
-          pnpm --dir native/landlock-run/packages/entry pack --pack-destination "$PWD/dist/npm-landlock"
+          pnpm --dir native/system run build:ts
+          pnpm --dir native/system/packages/entry pack --pack-destination "$PWD/dist/npm-landlock"
 
       - name: Verify packed install
         run: pnpm run release:verify-packed-install --family dsh --from dist/npm --from dist/npm-vendor --from dist/npm-landlock

+ 2 - 2
.github/workflows/release.yml

@@ -166,8 +166,8 @@ jobs:
       # are optional, and building them needs a musl toolchain per architecture.
       - name: Pack the Landlock entry for verification
         run: |
-          pnpm --dir native/landlock-run run build:ts
-          pnpm --dir native/landlock-run/packages/entry pack --pack-destination "$PWD/dist/npm-landlock"
+          pnpm --dir native/system run build:ts
+          pnpm --dir native/system/packages/entry pack --pack-destination "$PWD/dist/npm-landlock"
 
       - name: Verify packed install
         run: pnpm run release:verify-packed-install --family dsh --from dist/npm --from dist/npm-vendor --from dist/npm-landlock

+ 3 - 3
.github/workflows/sandbox.yml

@@ -3,7 +3,7 @@
 # .agents/notes/implemented/process/2026-07-21-serial-cross-platform-ci-reference.md.
 # A separate workflow from ci.yml because the axis is different — these jobs
 # fan out over OS×runner (kernel capabilities), not node versions. The Landlock
-# launcher is built from native/landlock-run on each Landlock leg and installed
+# launcher is built from native/system on each Landlock leg and installed
 # from the same tarballs the main-repository release workflow publishes.
 name: Sandbox
 
@@ -84,8 +84,8 @@ jobs:
         run: |
           sudo apt-get update -q
           sudo apt-get install -yq musl-tools
-          pnpm --dir native/landlock-run run build:ts
-          pnpm --dir native/landlock-run run build:native
+          pnpm --dir native/system run build:ts
+          pnpm --dir native/system run build:native
 
       # The unit suite runs on ubuntu in `checks`; this is the one darwin leg
       # in the workflow, so run it here too — the platform-dependent unit

+ 1 - 1
AGENTS.md

@@ -49,7 +49,7 @@ packages/    @deepseek-ai/dsh-<pkg> workspaces at packages/<group>/<pkg>/
   support/     dev/test infrastructure
   util/        zero-dependency utilities
 python/      Python SDK/runtime (see python/README.md)
-native/      @deepseek-ai/node-addon-landlock-run source of record (see native/README.md)
+native/      @deepseek-ai/node-addon-system source of record (see native/README.md)
 benchmarks/  performance gates
 .agents/     Agent workflows and Agent Notes (`notes/`)
 docs/        architecture, generated catalogs, postmortems, cookbook (see docs/AGENTS.md)

+ 1 - 1
THIRD_PARTY_NOTICES.md

@@ -224,4 +224,4 @@ Direct dependencies of the `pyproject.toml` manifests, plus `uv` as the developm
 
 ## First-party native packages
 
-`@deepseek-ai/node-addon-landlock-run` (and its platform packages) is built and released from this repository under BSD 3-Clause. It is listed here for completeness; it is first-party, not third-party.
+`@deepseek-ai/node-addon-system` (and its platform packages) is built and released from this repository under BSD 3-Clause. It is listed here for completeness; it is first-party, not third-party.

+ 2 - 2
apps/desktop/scripts/package-target.ts

@@ -266,10 +266,10 @@ async function main(): Promise<void> {
   await runPnpm(['run', 'release:pack', '--family', 'vendor', '--out', buildPaths.packedVendor], buildEnv, REPOSITORY_ROOT)
   rmSync(buildPaths.packedLandlock, { recursive: true, force: true })
   mkdirSync(buildPaths.packedLandlock, { recursive: true })
-  await runPnpm(['--dir', 'native/landlock-run', 'run', 'build:ts'], buildEnv, REPOSITORY_ROOT)
+  await runPnpm(['--dir', 'native/system', 'run', 'build:ts'], buildEnv, REPOSITORY_ROOT)
   await runPnpm([
     '--dir',
-    'native/landlock-run/packages/entry',
+    'native/system/packages/entry',
     'pack',
     '--pack-destination',
     buildPaths.packedLandlock,

+ 1 - 1
apps/web/tests/preview-boot.e2e.ts

@@ -415,7 +415,7 @@ async function bootPreview(origin: string, browser: Browser): Promise<void> {
     await page.getByText(SHOWCASE_OLDEST, { exact: true }).waitFor({ timeout: 15_000 })
     expect(pageErrors.map(error => error.message)).toEqual([])
     expect(consoleErrors.filter(line =>
-      /watchFile|failed to watch|node-addon-landlock-run\.probe|sandbox backend is usable|SANDBOX_UNAVAILABLE/i.test(line))).toEqual([])
+      /watchFile|failed to watch|node-addon-system\.probe|sandbox backend is usable|SANDBOX_UNAVAILABLE/i.test(line))).toEqual([])
   } catch (error) {
     await saveFailureShot(page, 'preview-boot')
     throw pageErrors.length === 0

+ 2 - 2
native/README.i18n.yaml

@@ -2,5 +2,5 @@
 # side as of the last confirmed-consistent state. Both languages carry equal authority;
 # after editing either side, bring the other along and re-record with:
 #   pnpm run verify-translation-pairing --write native/README.md
-README.md: 51c8da7b57df15e65b8e431ee18ce6cebb89d54b
-README.zh.md: 6d07c6afb43e2763795a71639707454b9cfbe280
+README.md: e962d1f5492379fe25c0546da58306ec671bd0aa
+README.zh.md: d383ff02ddec29e095a7da5c52175c96fca514f9

+ 3 - 3
native/README.md

@@ -2,10 +2,10 @@
 
 English | [中文](README.zh.md)
 
-Native source and public packages maintained with DeepSeek Harness. The [`landlock-run/` workspace](landlock-run/README.md) owns the Landlock self-restrict-then-exec launcher consumed by the harness, including its architecture, three-package npm family, platform support, development workflow, and [release procedure](landlock-run/docs/release.md).
+Native source and public packages maintained with DeepSeek Harness. The [`system/` workspace](system/README.md) owns the Landlock self-restrict-then-exec launcher consumed by the harness, including its architecture, three-package npm family, platform support, development workflow, and [release procedure](system/docs/release.md).
 
 ## Workspace and release boundary
 
-`landlock-run/` and its packages belong to the repository's root pnpm workspace and lockfile. Harness consumers use the current workspace entry package during development and CI, so a launcher contract change and its consumer update can land and be tested together.
+`system/` and its packages belong to the repository's root pnpm workspace and lockfile. Harness consumers use the current workspace entry package during development and CI, so a launcher contract change and its consumer update can land and be tested together.
 
-The main repository's `Landlock Run` workflow builds and tests each supported architecture. `Landlock Run Release` assembles those native artifacts, packs and verifies the three npm tarballs, then optionally publishes them under one launcher version. The entry package retains platform packages as npm optional dependencies, so npm still installs only the package matching the user's operating system and CPU.
+The main repository's `Node Addon System` workflow builds and tests each supported architecture. `Node Addon System Release` assembles those native artifacts, packs and verifies the three npm tarballs, then optionally publishes them under one launcher version. The entry package retains platform packages as npm optional dependencies, so npm still installs only the package matching the user's operating system and CPU.

+ 3 - 3
native/README.zh.md

@@ -2,10 +2,10 @@
 
 [English](README.md) | 中文
 
-与 DeepSeek Harness 一同维护的原生源码和公开包。[`landlock-run/` workspace](landlock-run/README.zh.md) 负责 harness 使用的 Landlock 自限后执行启动器,包括其架构、由三个包组成的 npm 包家族、平台支持、开发工作流和[发布流程](landlock-run/docs/release.md)。
+与 DeepSeek Harness 一同维护的原生源码和公开包。[`system/` workspace](system/README.zh.md) 负责 harness 使用的 Landlock 自限后执行启动器,包括其架构、由三个包组成的 npm 包家族、平台支持、开发工作流和[发布流程](system/docs/release.md)。
 
 ## Workspace 与发布边界
 
-`landlock-run/` 及其包属于仓库根 pnpm workspace,并共用根锁文件。开发和 CI 中的 harness 消费方直接使用当前 workspace 的入口包,因此启动器约定变更与消费方更新可以在同一个改动中落地并一起测试。
+`system/` 及其包属于仓库根 pnpm workspace,并共用根锁文件。开发和 CI 中的 harness 消费方直接使用当前 workspace 的入口包,因此启动器约定变更与消费方更新可以在同一个改动中落地并一起测试。
 
-主仓库的 `Landlock Run` 工作流为每个受支持架构构建并测试。`Landlock Run Release` 汇集这些原生产物,打包并验证三个 npm tarball,随后可选择以同一个启动器版本发布。入口包继续将平台包声明为 npm 可选依赖,因此 npm 仍然只会安装与用户操作系统和 CPU 匹配的包。
+主仓库的 `Node Addon System` 工作流为每个受支持架构构建并测试。`Node Addon System Release` 汇集这些原生产物,打包并验证三个 npm tarball,随后可选择以同一个启动器版本发布。入口包继续将平台包声明为 npm 可选依赖,因此 npm 仍然只会安装与用户操作系统和 CPU 匹配的包。

+ 3 - 3
native/system/README.i18n.yaml

@@ -1,6 +1,6 @@
 # Bilingual-pair consistency record (docs/i18n/README.md): the git blob hash of each
 # side as of the last confirmed-consistent state. Both languages carry equal authority;
 # after editing either side, bring the other along and re-record with:
-#   pnpm run verify-translation-pairing --write native/landlock-run/README.md
-README.md: bf9b163d42a9b7402dbf4c045d47e7b8d36e15ab
-README.zh.md: 7bd4765a73f0d5df2a4710ce06ff319f6c902db6
+#   pnpm run verify-translation-pairing --write native/system/README.md
+README.md: c3eeb84ea3b8853fc3da12dbd929e919191175ce
+README.zh.md: 30fa0ebd3e8c0127c63cde8e2ddb21b36fef5756

+ 6 - 6
native/system/README.md

@@ -1,4 +1,4 @@
-# @deepseek-ai/node-addon-landlock-run
+# @deepseek-ai/node-addon-system
 
 English | [中文](README.zh.md)
 
@@ -9,15 +9,15 @@ The tool is **`landlock-run`** — a self-restrict-then-exec [Landlock](https://
 ## Install
 
 ```sh
-npm install @deepseek-ai/node-addon-landlock-run
+npm install @deepseek-ai/node-addon-system
 ```
 
 Published packages use an entry package plus platform optional packages:
 
 ```text
-@deepseek-ai/node-addon-landlock-run
-@deepseek-ai/node-addon-landlock-run-linux-x64
-@deepseek-ai/node-addon-landlock-run-linux-arm64
+@deepseek-ai/node-addon-system
+@deepseek-ai/node-addon-system-linux-x64
+@deepseek-ai/node-addon-system-linux-arm64
 ```
 
 npm's `os`/`cpu` fields make installers fetch only the matching platform package. There is no install-time build fallback on purpose: on a host without a platform package the resolved path never exists, the probe reports `unusable`, and the consumer falls closed.
@@ -25,7 +25,7 @@ npm's `os`/`cpu` fields make installers fetch only the matching platform package
 ## Usage
 
 ```js
-import { grantArgs, launcherPath, probe } from '@deepseek-ai/node-addon-landlock-run';
+import { grantArgs, launcherPath, probe } from '@deepseek-ai/node-addon-system';
 
 const launcher = launcherPath();
 if (probe(launcher) !== 'unusable') {

+ 6 - 6
native/system/README.zh.md

@@ -1,4 +1,4 @@
-# @deepseek-ai/node-addon-landlock-run
+# @deepseek-ai/node-addon-system
 
 [English](README.md) | 中文
 
@@ -9,15 +9,15 @@
 ## 安装
 
 ```sh
-npm install @deepseek-ai/node-addon-landlock-run
+npm install @deepseek-ai/node-addon-system
 ```
 
 已发布包由一个入口包和可选平台包组成:
 
 ```text
-@deepseek-ai/node-addon-landlock-run
-@deepseek-ai/node-addon-landlock-run-linux-x64
-@deepseek-ai/node-addon-landlock-run-linux-arm64
+@deepseek-ai/node-addon-system
+@deepseek-ai/node-addon-system-linux-x64
+@deepseek-ai/node-addon-system-linux-arm64
 ```
 
 npm 的 `os`/`cpu` 字段使安装器只拉取匹配的平台包。系统有意不提供安装时构建回退:在没有对应平台包的宿主上,解析后的路径绝不存在,探测会报告 `unusable`,消费方以失败闭合方式处理。
@@ -25,7 +25,7 @@ npm 的 `os`/`cpu` 字段使安装器只拉取匹配的平台包。系统有意
 ## 用法
 
 ```js
-import { grantArgs, launcherPath, probe } from '@deepseek-ai/node-addon-landlock-run';
+import { grantArgs, launcherPath, probe } from '@deepseek-ai/node-addon-system';
 
 const launcher = launcherPath();
 if (probe(launcher) !== 'unusable') {

+ 3 - 3
native/system/docs/architecture.md

@@ -6,8 +6,8 @@ This repository owns confinement *mechanism*, not policy: consumers (agent harne
 
 The family is one entry package plus per-platform binary packages:
 
-- **Entry package** (`@deepseek-ai/node-addon-landlock-run`): ESM JavaScript. Owns the tool's CLI contract — path resolution (`launcherPath`), the functional probe (`probe`), grant-argv construction (`grantArgs`), and the contract constants. Ships the C source in its tarball for auditability. Lists every platform package as an `optionalDependency`.
-- **Platform packages** (`@deepseek-ai/node-addon-landlock-run-linux-{x64,arm64}`): one prebuilt static binary under `bin/`, a `prebuilds.json` declaring it, and no JavaScript at all. npm's `os`/`cpu` fields select the matching one at install time; the entry package resolves it to a file path — there is nothing to import.
+- **Entry package** (`@deepseek-ai/node-addon-system`): ESM JavaScript. Owns the tool's CLI contract — path resolution (`launcherPath`), the functional probe (`probe`), grant-argv construction (`grantArgs`), and the contract constants. Ships the C source in its tarball for auditability. Lists every platform package as an `optionalDependency`.
+- **Platform packages** (`@deepseek-ai/node-addon-system-linux-{x64,arm64}`): one prebuilt static binary under `bin/`, a `prebuilds.json` declaring it, and no JavaScript at all. npm's `os`/`cpu` fields select the matching one at install time; the entry package resolves it to a file path — there is nothing to import.
 
 Because the CLI parser and binary are versioned together in one package family, the parser cannot fall behind that binary version. Preventing that mismatch is why the package split exists.
 
@@ -15,7 +15,7 @@ There is no shared loader package: platform packages have nothing to load. If a
 
 ## Resolution and availability
 
-`launcherPath()` resolves `@deepseek-ai/node-addon-landlock-run-<platform>-<arch>` and returns `<package>/bin/landlock-run`. When the package is not resolvable it returns a deterministic fallback path inside the entry package's own `node_modules` that simply never exists. Existence is deliberately unchecked either way: `probe()` is the single availability signal, and a missing binary probes `unusable` exactly like an unenforcing kernel. Consumers get one degradation path, not two.
+`launcherPath()` resolves `@deepseek-ai/node-addon-system-<platform>-<arch>` and returns `<package>/bin/landlock-run`. When the package is not resolvable it returns a deterministic fallback path inside the entry package's own `node_modules` that simply never exists. Existence is deliberately unchecked either way: `probe()` is the single availability signal, and a missing binary probes `unusable` exactly like an unenforcing kernel. Consumers get one degradation path, not two.
 
 The probe is functional — the launcher builds and enforces a real maximal ruleset in a short-lived child — because version checks would miss a kernel that has the syscalls but refuses enforcement.
 

+ 3 - 3
native/system/docs/naming.md

@@ -2,11 +2,11 @@
 
 ## npm packages
 
-The public package family belongs to the `@deepseek-ai` scope and uses the `node-addon-landlock-run` package prefix; platform packages append platform information only:
+The public package family belongs to the `@deepseek-ai` scope and uses the `node-addon-system` package prefix; platform packages append platform information only:
 
 ```text
-@deepseek-ai/node-addon-landlock-run
-@deepseek-ai/node-addon-landlock-run-<platform>
+@deepseek-ai/node-addon-system
+@deepseek-ai/node-addon-system-<platform>
 ```
 
 Platform suffixes carry no libc component (binaries are static musl) and no variant component — variants stay inside `prebuilds.json` and binary filenames.

+ 3 - 3
native/system/docs/packaging.md

@@ -5,9 +5,9 @@ The package family uses the same layout as native packages such as esbuild: one
 ## Published packages
 
 ```text
-@deepseek-ai/node-addon-landlock-run
-@deepseek-ai/node-addon-landlock-run-linux-x64
-@deepseek-ai/node-addon-landlock-run-linux-arm64
+@deepseek-ai/node-addon-system
+@deepseek-ai/node-addon-system-linux-x64
+@deepseek-ai/node-addon-system-linux-arm64
 ```
 
 Unsupported platforms are intentionally absent from `optionalDependencies` — see [support-matrix.md](support-matrix.md).

+ 18 - 18
native/system/docs/release.md

@@ -7,54 +7,54 @@ Pre-1.0: treat this as a release checklist, not a stability policy.
 The launcher workspace root and its three public packages share one version. Run the bump helper from the repository root:
 
 ```sh
-pnpm --dir native/landlock-run release:bump patch          # or minor / major / x.y.z
+pnpm --dir native/system release:bump patch          # or minor / major / x.y.z
 ```
 
-It updates `native/landlock-run/package.json` and every `native/landlock-run/packages/*` manifest, refreshes the repository root lockfile (`--ignore-scripts --lockfile-only`), and runs `release:verify`. Explicit versions accept full semver including prereleases (`pnpm --dir native/landlock-run release:bump 0.0.0-test.0`); the publish workflow puts prerelease versions under the `next` dist-tag, so `latest` never points at a test build. Keep `workspace:*` dependencies in source; pnpm converts them to concrete versions during pack.
+It updates `native/system/package.json` and every `native/system/packages/*` manifest, refreshes the repository root lockfile (`--ignore-scripts --lockfile-only`), and runs `release:verify`. Explicit versions accept full semver including prereleases (`pnpm --dir native/system release:bump 0.0.0-test.0`); the publish workflow puts prerelease versions under the `next` dist-tag, so `latest` never points at a test build. Keep `workspace:*` dependencies in source; pnpm converts them to concrete versions during pack.
 
-Version bumps are normal source changes: open a release PR (or commit) with the launcher manifests and root lockfile, merge it, then create the matching `landlock-run-vX.Y.Z` tag from that commit. The namespace avoids colliding with release tags for other package families in the repository. The publish workflow validates that the tag matches every launcher package version.
+Version bumps are normal source changes: open a release PR (or commit) with the launcher manifests and root lockfile, merge it, then create the matching `node-addon-system-vX.Y.Z` tag from that commit. The namespace avoids colliding with release tags for other package families in the repository. The publish workflow validates that the tag matches every launcher package version.
 
 ```sh
-pnpm --dir native/landlock-run release:commit patch        # bump + stage + commit in one command
-git tag landlock-run-v0.0.2
+pnpm --dir native/system release:commit patch        # bump + stage + commit in one command
+git tag node-addon-system-v0.0.2
 ```
 
 ## Preflight
 
 ```sh
 pnpm install --frozen-lockfile
-pnpm --dir native/landlock-run build:ts
-pnpm --dir native/landlock-run typecheck
-pnpm --dir native/landlock-run test:entry
+pnpm --dir native/system build:ts
+pnpm --dir native/system typecheck
+pnpm --dir native/system test:entry
 ```
 
 On a Linux host, also rehearse the pack path locally:
 
 ```sh
-pnpm --dir native/landlock-run build:native
-pnpm --dir native/landlock-run test:launcher
-node native/landlock-run/scripts/pack-release.mjs native/landlock-run/.release/npm --current-platform-only
-node native/landlock-run/scripts/verify-packed-install.mjs native/landlock-run/.release/npm --current-platform-only
+pnpm --dir native/system build:native
+pnpm --dir native/system test:launcher
+node native/system/scripts/pack-release.mjs native/system/.release/npm --current-platform-only
+node native/system/scripts/verify-packed-install.mjs native/system/.release/npm --current-platform-only
 ```
 
 ## Publish
 
-Use the main repository's `Landlock Run Release` workflow so every binary is built on its matching native runner:
+Use the main repository's `Node Addon System Release` workflow so every binary is built on its matching native runner:
 
 1. Run it with `publish=false` (from the release commit) to build all platform binaries, assemble and verify the payloads, pack the tarballs in publish order, rehearse the packed install, and upload the `npm-tarballs` artifact for inspection.
-2. Create and push the `landlock-run-vX.Y.Z` tag matching the package versions.
+2. Create and push the `node-addon-system-vX.Y.Z` tag matching the package versions.
 3. Run the same workflow from that tag with `publish=true`.
 
 The workflow publishes only from the final packed tarballs, in `publish-order.txt` order (platform packages before the entry that optionally depends on them). A current-platform rehearsal can still query npm for metadata about an incompatible optional platform package; that package cannot supply the host launcher, which comes from the matching local tarball. Publishing every platform package before the entry ensures a public entry version never points ahead of its platform packages. The workflow supports npm trusted publishing through GitHub OIDC; without it, provide an `NPM_TOKEN` secret in the `npm-publish` environment. Packages publish with `--access public`.
 
-The three scoped package names must be bootstrapped with an `@deepseek-ai` organization token through the `NPM_TOKEN` fallback: npm [requires a package to exist before a trusted publisher can be configured](https://docs.npmjs.com/cli/v11/commands/npm-trust/). After the first release creates all three packages, configure each package to trust `landlock-run-release.yml` in this repository with the `npm-publish` environment, then remove the fallback token when organization policy permits it.
+The three scoped package names must be bootstrapped with an `@deepseek-ai` organization token through the `NPM_TOKEN` fallback: npm [requires a package to exist before a trusted publisher can be configured](https://docs.npmjs.com/cli/v11/commands/npm-trust/). After the first release creates all three packages, configure each package to trust `node-addon-system-release.yml` in this repository with the `npm-publish` environment, then remove the fallback token when organization policy permits it.
 
 Manual local fallback (current platform's packages only) — always through `pack-release.mjs`, never `pnpm publish` directly (pnpm's pack path strips the launcher's executable bit; see [packaging.md](packaging.md)):
 
 ```sh
-node native/landlock-run/scripts/pack-release.mjs native/landlock-run/dist/npm --current-platform-only
-node native/landlock-run/scripts/verify-packed-install.mjs native/landlock-run/dist/npm --current-platform-only
-while IFS= read -r tarball; do npm publish "native/landlock-run/dist/npm/${tarball}" --access public; done < native/landlock-run/dist/npm/publish-order.txt
+node native/system/scripts/pack-release.mjs native/system/dist/npm --current-platform-only
+node native/system/scripts/verify-packed-install.mjs native/system/dist/npm --current-platform-only
+while IFS= read -r tarball; do npm publish "native/system/dist/npm/${tarball}" --access public; done < native/system/dist/npm/publish-order.txt
 ```
 
 Do not commit `.npmrc` files with tokens or registry overrides.

+ 2 - 2
native/system/docs/support-matrix.md

@@ -4,8 +4,8 @@
 
 | Platform package | GitHub runner (builder of record) | Notes |
 |---|---|---|
-| `@deepseek-ai/node-addon-landlock-run-linux-x64` | `ubuntu-24.04` | static musl — glibc and musl distros alike |
-| `@deepseek-ai/node-addon-landlock-run-linux-arm64` | `ubuntu-24.04-arm` | static musl — glibc and musl distros alike |
+| `@deepseek-ai/node-addon-system-linux-x64` | `ubuntu-24.04` | static musl — glibc and musl distros alike |
+| `@deepseek-ai/node-addon-system-linux-arm64` | `ubuntu-24.04-arm` | static musl — glibc and musl distros alike |
 
 Enforcement additionally requires a kernel with Landlock enabled (5.13+). The negotiated ABI level decides the probe verdict: every access this build knows governed → `full`; an older ABI governing a subset → `partial` (still confined for everything it supports); Landlock absent or disabled → `unusable`, and the launcher refuses to run commands at all. The probe — not the kernel version — is the authority: a kernel built without Landlock, or with the LSM disabled, probes `unusable` regardless of its version.
 

+ 2 - 2
native/system/package.json

@@ -1,5 +1,5 @@
 {
-  "name": "@deepseek-ai/node-addon-landlock-run-workspace",
+  "name": "@deepseek-ai/node-addon-system-workspace",
   "version": "0.1.1",
   "private": true,
   "type": "module",
@@ -23,7 +23,7 @@
     "release:verify-packed-install": "node ./scripts/verify-packed-install.mjs"
   },
   "devDependencies": {
-    "@deepseek-ai/node-addon-landlock-run": "workspace:*",
+    "@deepseek-ai/node-addon-system": "workspace:*",
     "@types/node": "^26.0.1",
     "tsx": "^4.20.6",
     "typescript": "^6.0.3"

+ 3 - 3
native/system/packages/entry/README.i18n.yaml

@@ -1,6 +1,6 @@
 # Bilingual-pair consistency record (docs/i18n/README.md): the git blob hash of each
 # side as of the last confirmed-consistent state. Both languages carry equal authority;
 # after editing either side, bring the other along and re-record with:
-#   pnpm run verify-translation-pairing --write native/landlock-run/packages/entry/README.md
-README.md: fff722428c5d213d9fcce0ee87a1d48cdc189884
-README.zh.md: cbf867d9dd3551a12b74b19a6ceaf2be3e1c53a6
+#   pnpm run verify-translation-pairing --write native/system/packages/entry/README.md
+README.md: 4bf08c3845f9a627b8d6f7fffdf928c386cfa57f
+README.zh.md: c6b7d8ffa40f909f63ad02c4eb26576418932d7e

+ 3 - 3
native/system/packages/entry/README.md

@@ -1,11 +1,11 @@
-# @deepseek-ai/node-addon-landlock-run
+# @deepseek-ai/node-addon-system
 
 English | [中文](README.zh.md)
 
 Landlock self-restrict-then-exec launcher for confining subprocesses on Linux: this entry package resolves the per-platform prebuilt binary, runs its functional enforcement probe, and builds its grant argv — consumers never spell launcher flags or parse launcher output themselves.
 
 ```js
-import { grantArgs, launcherPath, probe } from '@deepseek-ai/node-addon-landlock-run';
+import { grantArgs, launcherPath, probe } from '@deepseek-ai/node-addon-system';
 
 const launcher = launcherPath();
 if (probe(launcher) !== 'unusable') {
@@ -15,4 +15,4 @@ if (probe(launcher) !== 'unusable') {
 
 The launcher installs a Landlock ruleset on itself and `exec`s the wrapped command; the ruleset is inherited across `execve`, so the whole process tree runs confined. Everything not granted is denied, and launcher failures exit `125` without running the command — fail-closed, never fail-open. The binary contract is pinned in the repo's `docs/cli-contract.md`; the C source rides this tarball (`src/main.c`) for audit.
 
-Platform packages (`os`/`cpu`-selected optional dependencies, no JavaScript inside): `@deepseek-ai/node-addon-landlock-run-linux-x64`, `@deepseek-ai/node-addon-landlock-run-linux-arm64`. On hosts without one, `launcherPath()` returns a deterministic nonexistent path and `probe()` reports `'unusable'` — there is deliberately no install-time compile fallback.
+Platform packages (`os`/`cpu`-selected optional dependencies, no JavaScript inside): `@deepseek-ai/node-addon-system-linux-x64`, `@deepseek-ai/node-addon-system-linux-arm64`. On hosts without one, `launcherPath()` returns a deterministic nonexistent path and `probe()` reports `'unusable'` — there is deliberately no install-time compile fallback.

+ 3 - 3
native/system/packages/entry/README.zh.md

@@ -1,11 +1,11 @@
-# @deepseek-ai/node-addon-landlock-run
+# @deepseek-ai/node-addon-system
 
 [English](README.md) | 中文
 
 用于在 Linux 上限制子进程的 Landlock「先限制自身、再执行」启动器:此入口包定位对应平台的预构建二进制文件,运行功能性强制执行探测,并构建其授权 argv。消费方无需自行拼写启动器标志或解析启动器输出。
 
 ```js
-import { grantArgs, launcherPath, probe } from '@deepseek-ai/node-addon-landlock-run';
+import { grantArgs, launcherPath, probe } from '@deepseek-ai/node-addon-system';
 
 const launcher = launcherPath();
 if (probe(launcher) !== 'unusable') {
@@ -15,4 +15,4 @@ if (probe(launcher) !== 'unusable') {
 
 启动器在自身上安装 Landlock 规则集,再 `exec` 被包装的命令;该规则集会跨 `execve` 继承,因此整个进程树都在限制下运行。未授予的一切都被拒绝;启动器失败时以 `125` 退出且不运行命令:采用失败闭合策略,绝不在失败时放行。二进制约定锁定在仓库的 `docs/cli-contract.md` 中;C 源码作为 `src/main.c` 随该 tarball 分发,便于审计。
 
-平台包(由 `os`/`cpu` 选择的可选依赖,内部不含 JavaScript):`@deepseek-ai/node-addon-landlock-run-linux-x64`、`@deepseek-ai/node-addon-landlock-run-linux-arm64`。在缺少对应包的宿主上,`launcherPath()` 返回一个固定但不存在的路径,`probe()` 报告 `'unusable'`;系统有意不提供安装时编译回退。
+平台包(由 `os`/`cpu` 选择的可选依赖,内部不含 JavaScript):`@deepseek-ai/node-addon-system-linux-x64`、`@deepseek-ai/node-addon-system-linux-arm64`。在缺少对应包的宿主上,`launcherPath()` 返回一个固定但不存在的路径,`probe()` 报告 `'unusable'`;系统有意不提供安装时编译回退。

+ 4 - 4
native/system/packages/entry/package.json

@@ -1,12 +1,12 @@
 {
-  "name": "@deepseek-ai/node-addon-landlock-run",
+  "name": "@deepseek-ai/node-addon-system",
   "version": "0.1.1",
   "type": "module",
   "description": "Landlock self-restrict-then-exec launcher for sandboxing subprocesses on Linux: per-platform prebuilt static binaries plus the JS seam that resolves, probes, and speaks their CLI contract",
   "repository": {
     "type": "git",
     "url": "git+https://github.com/deepseek-harness/deepseek-harness.git",
-    "directory": "native/landlock-run/packages/entry"
+    "directory": "native/system/packages/entry"
   },
   "main": "lib/index.js",
   "types": "lib/index.d.ts",
@@ -35,7 +35,7 @@
     "access": "public"
   },
   "optionalDependencies": {
-    "@deepseek-ai/node-addon-landlock-run-linux-arm64": "workspace:*",
-    "@deepseek-ai/node-addon-landlock-run-linux-x64": "workspace:*"
+    "@deepseek-ai/node-addon-system-linux-arm64": "workspace:*",
+    "@deepseek-ai/node-addon-system-linux-x64": "workspace:*"
   }
 }

+ 2 - 2
native/system/packages/entry/src/index.ts

@@ -53,7 +53,7 @@ export interface LauncherGrants {
 
 /**
  * Path of the launcher binary for this host: resolved from the per-platform
- * npm package `@deepseek-ai/node-addon-landlock-run-<platform>-<arch>` (npm's
+ * npm package `@deepseek-ai/node-addon-system-<platform>-<arch>` (npm's
  * `os`/`cpu` fields make installers fetch only the matching one). When the
  * package is not resolvable — a platform without one, or an install that
  * skipped the optional dependency — the returned fallback path points inside
@@ -69,7 +69,7 @@ export interface LauncherGrants {
 export function launcherPath(
   resolvePackageJson: (specifier: string) => string = createRequire(import.meta.url).resolve,
 ): string {
-  const platformPackage = `@deepseek-ai/node-addon-landlock-run-${process.platform}-${process.arch}`
+  const platformPackage = `@deepseek-ai/node-addon-system-${process.platform}-${process.arch}`
   try {
     return join(dirname(resolvePackageJson(`${platformPackage}/package.json`)), 'bin', LAUNCHER_BIN)
   } catch {

+ 1 - 1
native/system/packages/entry/src/main.c

@@ -31,7 +31,7 @@
  * linked statically), so the whole audit surface is this file plus the
  * kernel's stable syscall contract. Built natively per architecture by
  * `scripts/build.ts` into the per-platform npm packages
- * (`@deepseek-ai/node-addon-landlock-run-linux-{x64,arm64}`); the argv grammar,
+ * (`@deepseek-ai/node-addon-system-linux-{x64,arm64}`); the argv grammar,
  * exit codes, and report lines are pinned in `docs/cli-contract.md`.
  */
 

+ 3 - 3
native/system/packages/linux-arm64/README.i18n.yaml

@@ -1,6 +1,6 @@
 # Bilingual-pair consistency record (docs/i18n/README.md): the git blob hash of each
 # side as of the last confirmed-consistent state. Both languages carry equal authority;
 # after editing either side, bring the other along and re-record with:
-#   pnpm run verify-translation-pairing --write native/landlock-run/packages/linux-arm64/README.md
-README.md: dfcc9e97dc1393a42ff4b89ac009cdfd31e1497b
-README.zh.md: 350044e92f1d0247222cc16c82f03588ed0154c9
+#   pnpm run verify-translation-pairing --write native/system/packages/linux-arm64/README.md
+README.md: 11449d1043ea9913424d732af4f3c81599252a0b
+README.zh.md: d74a65aa94a840e1432ef23c43b1ad1cfe356385

+ 3 - 3
native/system/packages/linux-arm64/README.md

@@ -1,9 +1,9 @@
-# @deepseek-ai/node-addon-landlock-run-linux-arm64
+# @deepseek-ai/node-addon-system-linux-arm64
 
 English | [中文](README.zh.md)
 
-Prebuilt `bin/landlock-run` Landlock launcher for linux-arm64 — a static musl binary compiled natively (no cross toolchain) from the C source shipped in [`@deepseek-ai/node-addon-landlock-run`](https://www.npmjs.com/package/@deepseek-ai/node-addon-landlock-run). npm's `os`/`cpu` fields select this package at install time; the entry package resolves it to a file path — it ships no JavaScript and is never imported.
+Prebuilt `bin/landlock-run` Landlock launcher for linux-arm64 — a static musl binary compiled natively (no cross toolchain) from the C source shipped in [`@deepseek-ai/node-addon-system`](https://www.npmjs.com/package/@deepseek-ai/node-addon-system). npm's `os`/`cpu` fields select this package at install time; the entry package resolves it to a file path — it ships no JavaScript and is never imported.
 
 The binary is git-ignored and rides the npm tarball via the `files` list; the `prepack` gate refuses to pack when it is missing or has the wrong ELF architecture, and the release pipeline byte-pins the packed binary against the CI build it came from. Static musl linking means one binary for glibc and musl distros alike — hence no libc suffix in the name.
 
-Sibling: `@deepseek-ai/node-addon-landlock-run-linux-x64`.
+Sibling: `@deepseek-ai/node-addon-system-linux-x64`.

+ 3 - 3
native/system/packages/linux-arm64/README.zh.md

@@ -1,9 +1,9 @@
-# @deepseek-ai/node-addon-landlock-run-linux-arm64
+# @deepseek-ai/node-addon-system-linux-arm64
 
 [English](README.md) | 中文
 
-面向 linux-arm64 的预构建 `bin/landlock-run` Landlock 启动器:一个由 [`@deepseek-ai/node-addon-landlock-run`](https://www.npmjs.com/package/@deepseek-ai/node-addon-landlock-run) 包所附的 C 源码原生编译而成的静态 musl 二进制文件(不使用交叉工具链)。npm 的 `os`/`cpu` 字段在安装时选择此包;入口包将其定位到文件路径。该包不包含 JavaScript,也绝不会被导入。
+面向 linux-arm64 的预构建 `bin/landlock-run` Landlock 启动器:一个由 [`@deepseek-ai/node-addon-system`](https://www.npmjs.com/package/@deepseek-ai/node-addon-system) 包所附的 C 源码原生编译而成的静态 musl 二进制文件(不使用交叉工具链)。npm 的 `os`/`cpu` 字段在安装时选择此包;入口包将其定位到文件路径。该包不包含 JavaScript,也绝不会被导入。
 
 该二进制文件被 git 忽略,并通过 `files` 列表进入 npm tarball;如果文件缺失或 ELF 架构错误,`prepack` 门禁会拒绝打包,发布流水线则会按字节核验打包的二进制文件与其来源 CI 构建产物一致。静态 musl 链接使同一个二进制文件同时适用于 glibc 和 musl 发行版,因此名称中没有 libc 后缀。
 
-同级包:`@deepseek-ai/node-addon-landlock-run-linux-x64`。
+同级包:`@deepseek-ai/node-addon-system-linux-x64`。

+ 3 - 3
native/system/packages/linux-arm64/package.json

@@ -1,11 +1,11 @@
 {
-  "name": "@deepseek-ai/node-addon-landlock-run-linux-arm64",
+  "name": "@deepseek-ai/node-addon-system-linux-arm64",
   "version": "0.1.1",
-  "description": "Prebuilt landlock-run Landlock launcher binary for linux-arm64 (static musl) — resolved as a file path by @deepseek-ai/node-addon-landlock-run, never imported",
+  "description": "Prebuilt landlock-run Landlock launcher binary for linux-arm64 (static musl) — resolved as a file path by @deepseek-ai/node-addon-system, never imported",
   "repository": {
     "type": "git",
     "url": "git+https://github.com/deepseek-harness/deepseek-harness.git",
-    "directory": "native/landlock-run/packages/linux-arm64"
+    "directory": "native/system/packages/linux-arm64"
   },
   "os": [
     "linux"

+ 3 - 3
native/system/packages/linux-x64/README.i18n.yaml

@@ -1,6 +1,6 @@
 # Bilingual-pair consistency record (docs/i18n/README.md): the git blob hash of each
 # side as of the last confirmed-consistent state. Both languages carry equal authority;
 # after editing either side, bring the other along and re-record with:
-#   pnpm run verify-translation-pairing --write native/landlock-run/packages/linux-x64/README.md
-README.md: d08cc0c4abbc74f64c5d1075dea796427211bd8f
-README.zh.md: ed6839aa6230b16b82c67a716fc0a4128e5a977c
+#   pnpm run verify-translation-pairing --write native/system/packages/linux-x64/README.md
+README.md: c0b85ccbecd88df943d645fdd3c5880f7d5f3000
+README.zh.md: b0e04e1be41b21089801b6d8c9156e3d73558fff

+ 3 - 3
native/system/packages/linux-x64/README.md

@@ -1,9 +1,9 @@
-# @deepseek-ai/node-addon-landlock-run-linux-x64
+# @deepseek-ai/node-addon-system-linux-x64
 
 English | [中文](README.zh.md)
 
-Prebuilt `bin/landlock-run` Landlock launcher for linux-x64 — a static musl binary compiled natively (no cross toolchain) from the C source shipped in [`@deepseek-ai/node-addon-landlock-run`](https://www.npmjs.com/package/@deepseek-ai/node-addon-landlock-run). npm's `os`/`cpu` fields select this package at install time; the entry package resolves it to a file path — it ships no JavaScript and is never imported.
+Prebuilt `bin/landlock-run` Landlock launcher for linux-x64 — a static musl binary compiled natively (no cross toolchain) from the C source shipped in [`@deepseek-ai/node-addon-system`](https://www.npmjs.com/package/@deepseek-ai/node-addon-system). npm's `os`/`cpu` fields select this package at install time; the entry package resolves it to a file path — it ships no JavaScript and is never imported.
 
 The binary is git-ignored and rides the npm tarball via the `files` list; the `prepack` gate refuses to pack when it is missing or has the wrong ELF architecture, and the release pipeline byte-pins the packed binary against the CI build it came from. Static musl linking means one binary for glibc and musl distros alike — hence no libc suffix in the name.
 
-Sibling: `@deepseek-ai/node-addon-landlock-run-linux-arm64`.
+Sibling: `@deepseek-ai/node-addon-system-linux-arm64`.

+ 3 - 3
native/system/packages/linux-x64/README.zh.md

@@ -1,9 +1,9 @@
-# @deepseek-ai/node-addon-landlock-run-linux-x64
+# @deepseek-ai/node-addon-system-linux-x64
 
 [English](README.md) | 中文
 
-面向 linux-x64 的预构建 `bin/landlock-run` Landlock 启动器:一个由 [`@deepseek-ai/node-addon-landlock-run`](https://www.npmjs.com/package/@deepseek-ai/node-addon-landlock-run) 包所附的 C 源码原生编译而成的静态 musl 二进制文件(不使用交叉工具链)。npm 的 `os`/`cpu` 字段在安装时选择此包;入口包将其定位到文件路径。该包不包含 JavaScript,也绝不会被导入。
+面向 linux-x64 的预构建 `bin/landlock-run` Landlock 启动器:一个由 [`@deepseek-ai/node-addon-system`](https://www.npmjs.com/package/@deepseek-ai/node-addon-system) 包所附的 C 源码原生编译而成的静态 musl 二进制文件(不使用交叉工具链)。npm 的 `os`/`cpu` 字段在安装时选择此包;入口包将其定位到文件路径。该包不包含 JavaScript,也绝不会被导入。
 
 该二进制文件被 git 忽略,并通过 `files` 列表进入 npm tarball;如果文件缺失或 ELF 架构错误,`prepack` 门禁会拒绝打包,发布流水线则会按字节核验打包的二进制文件与其来源 CI 构建产物一致。静态 musl 链接使同一个二进制文件同时适用于 glibc 和 musl 发行版,因此名称中没有 libc 后缀。
 
-同级包:`@deepseek-ai/node-addon-landlock-run-linux-arm64`。
+同级包:`@deepseek-ai/node-addon-system-linux-arm64`。

+ 3 - 3
native/system/packages/linux-x64/package.json

@@ -1,11 +1,11 @@
 {
-  "name": "@deepseek-ai/node-addon-landlock-run-linux-x64",
+  "name": "@deepseek-ai/node-addon-system-linux-x64",
   "version": "0.1.1",
-  "description": "Prebuilt landlock-run Landlock launcher binary for linux-x64 (static musl) — resolved as a file path by @deepseek-ai/node-addon-landlock-run, never imported",
+  "description": "Prebuilt landlock-run Landlock launcher binary for linux-x64 (static musl) — resolved as a file path by @deepseek-ai/node-addon-system, never imported",
   "repository": {
     "type": "git",
     "url": "git+https://github.com/deepseek-harness/deepseek-harness.git",
-    "directory": "native/landlock-run/packages/linux-x64"
+    "directory": "native/system/packages/linux-x64"
   },
   "os": [
     "linux"

+ 2 - 2
native/system/scripts/commit-release.mjs

@@ -37,6 +37,6 @@ run('git', [
   'packages/*/package.json',
   '../../pnpm-lock.yaml',
 ]);
-run('git', ['commit', '-m', `release(landlock-run): ${version}`]);
+run('git', ['commit', '-m', `release(node-addon-system): ${version}`]);
 
-console.log(`Committed release ${version}. Create the tag manually: git tag landlock-run-v${version}`);
+console.log(`Committed release ${version}. Create the tag manually: git tag node-addon-system-v${version}`);

+ 3 - 3
native/system/scripts/verify-packed-install.mjs

@@ -31,7 +31,7 @@ import { entryDirs, packageDirs, platformDirs, readJson, root } from './repo.mjs
 const args = process.argv.slice(2);
 const currentPlatformOnly = args.includes('--current-platform-only');
 const tarballDir = path.resolve(args.find((arg) => !arg.startsWith('--')) || path.join(root, 'dist', 'npm'));
-const entryPackageName = '@deepseek-ai/node-addon-landlock-run';
+const entryPackageName = '@deepseek-ai/node-addon-system';
 
 function tarballName(manifest) {
   if (manifest.name.startsWith('@')) {
@@ -180,10 +180,10 @@ import { spawnSync } from 'node:child_process';
 import fs from 'node:fs';
 import os from 'node:os';
 import path from 'node:path';
-import { grantArgs, launcherPath, probe } from '@deepseek-ai/node-addon-landlock-run';
+import { grantArgs, launcherPath, probe } from '@deepseek-ai/node-addon-system';
 
 const requireLandlock = process.env.NALR_REQUIRE_LANDLOCK === '1';
-const platformPackage = '@deepseek-ai/node-addon-landlock-run-' + process.platform + '-' + process.arch;
+const platformPackage = '@deepseek-ai/node-addon-system-' + process.platform + '-' + process.arch;
 const resolved = launcherPath();
 assert.ok(path.isAbsolute(resolved), 'launcherPath must be absolute');
 assert.ok(resolved.includes(path.join(...platformPackage.split('/'))), 'launcherPath must point into the platform package: ' + resolved);

+ 4 - 4
native/system/scripts/verify-release.mjs

@@ -2,7 +2,7 @@
 /**
  * Release verification. Always: every published package carries one shared
  * version, and — when running from a tag or publishing — the
- * `landlock-run-vX.Y.Z` tag matches it. With `--prebuilds`: every platform package's declared
+ * `node-addon-system-vX.Y.Z` tag matches it. With `--prebuilds`: every platform package's declared
  * binaries exist with the right ELF architecture (run after
  * `assemble-prebuilds.mjs` or a local `build:native`).
  */
@@ -10,7 +10,7 @@
 import path from 'node:path';
 import { packageDirs, platformDirs, readJson, root, verifyPlatformBinaries } from './repo.mjs';
 
-const TAG_PREFIX = 'refs/tags/landlock-run-v';
+const TAG_PREFIX = 'refs/tags/node-addon-system-v';
 
 function verifyVersions() {
   const packages = packageDirs().map((dir) => ({
@@ -29,12 +29,12 @@ function verifyVersions() {
   const ref = process.env.GITHUB_REF || '';
   const publish = process.env.RELEASE_PUBLISH === 'true';
   if (publish && !ref.startsWith(TAG_PREFIX)) {
-    throw new Error('publishing requires running the workflow from a landlock-run-v* tag');
+    throw new Error('publishing requires running the workflow from a node-addon-system-v* tag');
   }
   if (ref.startsWith(TAG_PREFIX)) {
     const tagVersion = ref.slice(TAG_PREFIX.length);
     if (tagVersion !== version) {
-      throw new Error(`tag/version mismatch: tag landlock-run-v${tagVersion}, packages ${version}`);
+      throw new Error(`tag/version mismatch: tag node-addon-system-v${tagVersion}, packages ${version}`);
     }
   }
 

+ 2 - 2
native/system/test/entry.test.js

@@ -15,7 +15,7 @@ import {
   grantArgs,
   launcherPath,
   probe,
-} from '@deepseek-ai/node-addon-landlock-run';
+} from '@deepseek-ai/node-addon-system';
 
 // --- constants are part of the CLI contract ---
 assert.equal(LAUNCHER_BIN, 'landlock-run');
@@ -31,7 +31,7 @@ assert.deepEqual(
 assert.deepEqual(grantArgs({ readWrite: ['/a'], readOnly: ['/b'] }), ['--ro', '/b', '--rw', '/a']);
 
 // --- launcherPath: resolves the platform package next to its package.json ---
-const platformPackage = `@deepseek-ai/node-addon-landlock-run-${process.platform}-${process.arch}`;
+const platformPackage = `@deepseek-ai/node-addon-system-${process.platform}-${process.arch}`;
 const resolvedViaSeam = launcherPath((specifier) => {
   assert.equal(specifier, `${platformPackage}/package.json`);
   return path.join('/fake-install', specifier);

+ 1 - 1
native/system/test/launcher.test.js

@@ -22,7 +22,7 @@ import {
   grantArgs,
   launcherPath,
   probe,
-} from '@deepseek-ai/node-addon-landlock-run';
+} from '@deepseek-ai/node-addon-system';
 
 const FATAL_PREFIX = 'landlock-run: ';
 const PARTIAL_NOTICE = 'landlock-run: partial enforcement (older Landlock ABI)';

+ 2 - 2
package.json

@@ -11,8 +11,8 @@
   "workspaces": [
     "vendor/*",
     "packages/*/*",
-    "native/landlock-run",
-    "native/landlock-run/packages/*",
+    "native/system",
+    "native/system/packages/*",
     "apps/*",
     "website"
   ],

+ 2 - 2
packages/experimental/webworker-packer/README.i18n.yaml

@@ -2,5 +2,5 @@
 # side as of the last confirmed-consistent state. Both languages carry equal authority;
 # after editing either side, bring the other along and re-record with:
 #   pnpm run verify-translation-pairing --write packages/experimental/webworker-packer/README.md
-README.md: 598a175637a6111001b07b0186c0f1a465d54a9c
-README.zh.md: 8f05e39d34bd33613065cf86fd9c6e51ff90d88e
+README.md: 4cf8b569ef288905ea555e4206553b5aeada1708
+README.zh.md: 712118f24bb686a3fb61b6a272471a45817928ae

+ 1 - 1
packages/experimental/webworker-packer/README.md

@@ -31,7 +31,7 @@ The pack is a three-layer standard stack:
 2. **Publish view** — each workspace or vendored package contributes its built npm slice (`files` through picomatch) without source or workspace `dist/`. External packages retain published JavaScript under both `src/` and `dist/` because their `main` or `exports` may point there; only generic test, map, declaration, and archive exclusions apply.
 3. **Reachability sweep** — the runtime loader's own resolution walks from every workspace export face plus the worker assembly's seeds (`IMAGE_ENTRY_SEEDS`), lowering each reached module to the wrapper contract at pack time. The transform reports statically named imports, re-exports, and dynamic imports; calls through `require`; and module-scope direct calls of the form `createRequire(import.meta.url)('pkg')` through a named import from `node:module` or `module`, including an import alias. Page assets (`lib/client.js` behind `./client` exports) ship verbatim; an unresolvable request from our own code fails the pack, third-party ones are tolerated to fail loud at require time.
 
-`repository.ts` owns the repo-shaped inputs (workspace scan of `vendor/`, `packages/`, `native/landlock-run/packages/`, and `apps/`; profile composition through the real CLI dump path); `pack.ts` owns none of them, so the same library packs a different tree by being called differently. The native scan makes the Landlock entry package an ordinary published-view dependency while its executable remains a Worker platform implementation. The CLI is `dsh-pack-vfs-image --out <file> [--profile web]`; `apps/web`'s `build:preview` runs it after the preview shell build.
+`repository.ts` owns the repo-shaped inputs (workspace scan of `vendor/`, `packages/`, `native/system/packages/`, and `apps/`; profile composition through the real CLI dump path); `pack.ts` owns none of them, so the same library packs a different tree by being called differently. The native scan makes the Landlock entry package an ordinary published-view dependency while its executable remains a Worker platform implementation. The CLI is `dsh-pack-vfs-image --out <file> [--profile web]`; `apps/web`'s `build:preview` runs it after the preview shell build.
 
 The repository adapter also declares the preview-only fixture trees under `webworker-runtime/tests/fixtures/`. The CLI packs each named fixture into a separate deterministic overlay archive plus a browser-readable manifest. Overlay files bypass npm publish-view and module-reachability exclusions, so dot directories and example source files remain intact; their mounts are limited to `home/` and `workspace/`. `pack.ts` treats them as opaque bytes, and Session and Workspace interpretation stays in the runtime packages that own those formats.
 

+ 1 - 1
packages/experimental/webworker-packer/README.zh.md

@@ -31,7 +31,7 @@ VFS 镜像打包器:把一份合成 profile 变成浏览器 worker 挂载为
 2. **发布视图**——每个 workspace 或 vendored 包贡献其构建后的 npm 切片(`files` 走 picomatch),不带源码和 workspace `dist/`。外部包的 `main` 或 `exports` 可能指向 `src/` 或 `dist/`,因此两处发布 JavaScript 都会保留,只应用通用的测试、map、声明与归档排除规则。
 3. **可达性 sweep**——用运行时加载器自己的解析,从全部 workspace 导出面加 worker 装配种子(`IMAGE_ENTRY_SEEDS`)出发,pack 时把每个可达模块降低到包装契约。Transform 会报告具名静态 import、re-export 与动态 import、经 `require` 发起的调用,以及通过 `node:module` 或 `module` 具名导入(含导入别名)在模块作用域直接发起的 `createRequire(import.meta.url)('pkg')` 调用。页面资产(`./client` 导出背后的 `lib/client.js`)原样直发;自家代码的不可解析请求打包即失败,第三方的容忍到 require 时 fail loud。
 
-`repository.ts` 拥有仓库形态输入(`vendor/`、`packages/`、`native/landlock-run/packages/` 与 `apps/` 的 workspace 扫描;经真 CLI dump 路径合成 profile);`pack.ts` 一概不拥有,同一库换参即可打另一棵树。Native 扫描使 Landlock 入口包成为普通发布视图依赖,其可执行文件仍由 Worker 平台实现。CLI 为 `dsh-pack-vfs-image --out <file> [--profile web]`;`apps/web` 的 `build:preview` 在预览壳构建后运行它。
+`repository.ts` 拥有仓库形态输入(`vendor/`、`packages/`、`native/system/packages/` 与 `apps/` 的 workspace 扫描;经真 CLI dump 路径合成 profile);`pack.ts` 一概不拥有,同一库换参即可打另一棵树。Native 扫描使 Landlock 入口包成为普通发布视图依赖,其可执行文件仍由 Worker 平台实现。CLI 为 `dsh-pack-vfs-image --out <file> [--profile web]`;`apps/web` 的 `build:preview` 在预览壳构建后运行它。
 
 仓库适配层还声明 `webworker-runtime/tests/fixtures/` 下仅用于 preview 的 fixture tree。CLI 会把每套具名 fixture 打成一份独立的确定性 overlay 归档,并写出浏览器可读的 manifest。Overlay 文件绕过 NPM 发布视图和模块可达性排除规则,因此点目录与示例源码会完整保留;其挂载位置仅限 `home/` 与 `workspace/`。`pack.ts` 把它们视为不透明字节;Session 与 Workspace 的解释仍归拥有这些格式的 runtime 包。
 

+ 1 - 1
packages/experimental/webworker-packer/src/repository.ts

@@ -21,7 +21,7 @@ import type { ConfigTree, ImageTree, PackResult } from './pack.ts'
  * package family contributes its unchanged JavaScript entry from `native/`;
  * examples and python never occur on a roster's dependency chain.
  */
-const WORKSPACE_SCAN_ROOTS = ['vendor', 'packages', 'native/landlock-run/packages', 'apps']
+const WORKSPACE_SCAN_ROOTS = ['vendor', 'packages', 'native/system/packages', 'apps']
 
 /** Composition entry point package: the `dsh` CLI, run from source. */
 const CLI_PACKAGE = 'apps/cli'

+ 2 - 2
packages/experimental/webworker-packer/tests/image-loadable.spec.ts

@@ -35,7 +35,7 @@ const repoRoot = fileURLToPath(new URL('../../../../', import.meta.url))
 
 /** A leaf workspace package: real build output, no dependencies to drag in. */
 const SUBJECT = '@deepseek-ai/dsh-timeout'
-const LANDLOCK = '@deepseek-ai/node-addon-landlock-run'
+const LANDLOCK = '@deepseek-ai/node-addon-system'
 const PLUGIN_INVENTORY = '@deepseek-ai/dsh-plugin-package-inventory-deepseek'
 const WEB_SERVER = '@deepseek-ai/dsh-host-webserver'
 
@@ -86,7 +86,7 @@ const subjectBuilt = [
   'vendor/loader/lib/index.js',
   'packages/host/webserver/lib/index.js',
   'packages/llm/plugin-package-inventory-deepseek/lib/index.js',
-  'native/landlock-run/packages/entry/lib/index.js',
+  'native/system/packages/entry/lib/index.js',
   'packages/preset/agent-presets/lib/typert.host.js',
   'packages/preset/agent-presets/lib/typert.remote-client.js',
 ].every(path => existsSync(join(repoRoot, path)))

+ 2 - 2
packages/experimental/webworker-runtime/README.i18n.yaml

@@ -2,5 +2,5 @@
 # side as of the last confirmed-consistent state. Both languages carry equal authority;
 # after editing either side, bring the other along and re-record with:
 #   pnpm run verify-translation-pairing --write packages/experimental/webworker-runtime/README.md
-README.md: 3f9f3d1d75324d23ef74fd570a645a260c0e34a3
-README.zh.md: b566a0ebf0f7ccdb9bf09f4063376a529fbb0290
+README.md: 0bfac2891e14d7c6f9947c62acf968bef8220565
+README.zh.md: b31fd325c79c82d3992a62cbe4c9fb8c5506211b

+ 1 - 1
packages/experimental/webworker-runtime/README.md

@@ -50,7 +50,7 @@ None; this package neither assembles nor sends a provider request.
 - **The worker composition writes plaintext session logs** (`compression: 'none'` boot patch): it carries no Zstandard codec, so exported logs are `.jsonl`, never `.jsonl.zstd`.
 - **`node:dns/promises`, `node:vm`, `node:net`, `node:sqlite`, `node:worker_threads` are structural stubs**: every call reports its refusal on the console and throws. Rows needing native DNS, a real process, or realm isolation cannot run here.
 - **Filesystem watchers observe only the mounted VFS**: image seeding is silent and the VFS has no symlinks or external writers. `persistent`, `ref()`, and `unref()` preserve the Node API but cannot control a dedicated Worker's lifetime because browsers expose no ref-counted event loop.
-- **Worker confinement is a VFS boundary, not kernel Landlock**: `read-only` and `workspace-write` run the unchanged `@deepseek-ai/node-addon-landlock-run` JavaScript and launcher argv, but the process layer implements the logical `landlock-run` executable and enforces its grants on every shell filesystem request. `full` therefore covers the Worker command table and mounted VFS only; it does not claim arbitrary native-process execution or Linux kernel isolation.
+- **Worker confinement is a VFS boundary, not kernel Landlock**: `read-only` and `workspace-write` run the unchanged `@deepseek-ai/node-addon-system` JavaScript and launcher argv, but the process layer implements the logical `landlock-run` executable and enforces its grants on every shell filesystem request. `full` therefore covers the Worker command table and mounted VFS only; it does not claim arbitrary native-process execution or Linux kernel isolation.
 - **The worker bundle pins a path inside `@yarnpkg/parsers`** — the build resolves the package's own `lib/shell.js` instead of its root, whose barrel also re-exports the Syml parser and so drags js-yaml into a bundle that never parses that format (around 175 kB, plus its module body at worker start). The path is derived from the package manifest, so a layout change fails the build rather than reinstating the barrel; upgrading the dependency means re-checking that the shell parser still lives there.
 - **The shell is not bash**: no loops, functions, `case`, job control, or process substitution — the grammar stops at pipelines, `&&`/`||`, subshells, groups, redirections, and expansion. `&` runs its command to completion in place, `sed` accepts only substitution scripts, patterns are JavaScript regular expressions, and the command table holds coreutils only (no `git`, no network tools).
 - **A shell process has no synchronous filesystem**: it reads and writes the host's VFS by message, because blocking on a reply would need `SharedArrayBuffer`, which requires a cross-origin isolation GitHub Pages cannot grant. Directory-walking commands therefore cost one round trip per entry, and two concurrent commands can interleave their writes.

+ 1 - 1
packages/experimental/webworker-runtime/README.zh.md

@@ -50,7 +50,7 @@ kind: "package-library"
 - **worker 组合写明文会话日志**(`compression: 'none'` boot patch):不带 Zstandard 编解码器,导出日志是 `.jsonl`,不会是 `.jsonl.zstd`。
 - **`node:dns/promises`、`node:vm`、`node:net`、`node:sqlite`、`node:worker_threads` 是结构化 stub**:每次调用在 console 报告拒绝并抛出。需要原生 DNS、真进程或真 realm 隔离的行在此无法运行。
 - **文件 watcher 只能观察已挂载的 VFS**:镜像 seed 不产生事件,VFS 也没有符号链接或外部写入方。`persistent`、`ref()` 和 `unref()` 保留 Node API,但浏览器没有引用计数事件循环,因此这些接口不能控制 dedicated Worker 的生存期。
-- **Worker confinement 是 VFS 边界,不是内核 Landlock**:`read-only` 和 `workspace-write` 运行未经修改的 `@deepseek-ai/node-addon-landlock-run` JavaScript 与 launcher argv,进程层则实现逻辑 `landlock-run` 可执行文件,并在 shell 的每次文件系统请求上执行其授权。`full` 仅覆盖 Worker 命令表和已挂载 VFS,不表示能够执行任意 native 进程,也不表示 Linux 内核隔离。
+- **Worker confinement 是 VFS 边界,不是内核 Landlock**:`read-only` 和 `workspace-write` 运行未经修改的 `@deepseek-ai/node-addon-system` JavaScript 与 launcher argv,进程层则实现逻辑 `landlock-run` 可执行文件,并在 shell 的每次文件系统请求上执行其授权。`full` 仅覆盖 Worker 命令表和已挂载 VFS,不表示能够执行任意 native 进程,也不表示 Linux 内核隔离。
 - **worker 束钉住了 `@yarnpkg/parsers` 的包内路径**——构建解析到该包自己的 `lib/shell.js` 而非包根,因为包根 barrel 还 re-export 了 Syml 解析器,会把 js-yaml 拖进一个从不解析该格式的束(约 175 kB,外加 worker 启动时的模块体求值)。该路径由包 manifest 派生,包内布局一变即构建期失败、不会静默退回 barrel;升级这个依赖时须复核 shell 解析器是否仍在那里。
 - **这个 shell 不是 bash**:没有循环、函数、`case`、作业控制或进程替换——语法止步于管道、`&&`/`||`、子 shell、group、重定向与展开。`&` 会就地把命令跑完,`sed` 只接受替换脚本,模式是 JavaScript 正则,命令表只有 coreutils(没有 `git`,没有网络工具)。
 - **shell 进程没有同步文件面**:它靠消息读写宿主的 VFS,因为阻塞等待回帧需要 `SharedArrayBuffer`,而那要求 GitHub Pages 给不了的跨源隔离。因此目录遍历类命令每个条目一次往返,并发的两条命令写入可以交错。

+ 1 - 1
packages/experimental/webworker-runtime/package.json

@@ -57,7 +57,7 @@
     "@deepseek-ai/dsh-session-persistence-jsonl": "workspace:^",
     "@deepseek-ai/dsh-subagent": "workspace:^",
     "@deepseek-ai/dsh-subprocess-local": "workspace:^",
-    "@deepseek-ai/node-addon-landlock-run": "workspace:^",
+    "@deepseek-ai/node-addon-system": "workspace:^",
     "@types/picomatch": "^3.0.2",
     "@types/readable-stream": "^4.0.24",
     "chokidar": "^5.0.0"

+ 1 - 1
packages/experimental/webworker-runtime/tests/node/child-process.spec.ts

@@ -18,7 +18,7 @@ import { setActiveVfs } from '@deepseek-ai/dsh-experimental-webworker-runtime/sr
 import { spawn, spawnSync } from '@deepseek-ai/dsh-experimental-webworker-runtime/src/node/builtin_modules/implemented/child_process.ts'
 import {
   LAUNCHER_FAILURE_EXIT, grantArgs, launcherPath, probe,
-} from '@deepseek-ai/node-addon-landlock-run'
+} from '@deepseek-ai/node-addon-system'
 import { processAlive, signalProcess } from '@deepseek-ai/dsh-experimental-webworker-runtime/src/node/process-table.ts'
 import { hostFileSystem } from '@deepseek-ai/dsh-experimental-webworker-runtime/src/shell/fs-access.ts'
 import {

+ 1 - 1
packages/experimental/webworker-runtime/tests/node/node-stubs.spec.ts

@@ -118,7 +118,7 @@ describe('constructible-but-inert fakes', () => {
 describe('replaced external packages', () => {
   it('lists the packages the loader serves from the bundle', () => {
     expect(REPLACED_EXTERNAL_PACKAGES).not.toContain('chokidar')
-    expect(REPLACED_EXTERNAL_PACKAGES).not.toContain('@deepseek-ai/node-addon-landlock-run')
+    expect(REPLACED_EXTERNAL_PACKAGES).not.toContain('@deepseek-ai/node-addon-system')
     expect(REPLACED_EXTERNAL_PACKAGES).toContain('ws')
   })
 

+ 2 - 2
packages/sandbox/sandbox-local/README.i18n.yaml

@@ -2,5 +2,5 @@
 # side as of the last confirmed-consistent state. Both languages carry equal authority;
 # after editing either side, bring the other along and re-record with:
 #   pnpm run verify-translation-pairing --write packages/sandbox/sandbox-local/README.md
-README.md: 75bfb1124ece23a3a9cea0f733fb1cca42a19c16
-README.zh.md: 0edfce8c6c53a663bfe2d2e80758da83e75172f6
+README.md: 16deeef790f28b232dc517784ca45ecb38749c6f
+README.zh.md: 4d163766ff6c8097c60cfb8376a21d2a9a441100

+ 1 - 1
packages/sandbox/sandbox-local/README.md

@@ -74,7 +74,7 @@ Selection is by platform first, probes second: each platform has a runner chain
 
 The bwrap profile combines a read-only host root, a fresh `/dev`, and `/proc` from a private PID namespace — commands manage their descendants but cannot see host processes, so procfs magic links cannot bypass the mounts; `workspace-write` adds an ephemeral `/tmp` and a writable workspace bind. The [private-PID note](../../../.agents/notes/implemented/bug-fix/2026-08-06-bwrap-private-pid-namespace.md) records the boundary.
 
-The Landlock launcher ships as an npm-distributed native addon (`@deepseek-ai/node-addon-landlock-run`) that supplies the platform launcher, functional probe, and grant vocabulary; this provider maps mode to grants only, keeping path resolution and probe parsing with the versioned binary.
+The Landlock launcher ships as an npm-distributed native addon (`@deepseek-ai/node-addon-system`) that supplies the platform launcher, functional probe, and grant vocabulary; this provider maps mode to grants only, keeping path resolution and probe parsing with the versioned binary.
 
 The Seatbelt profile is allow-default with `(deny file-write*)` plus write allow-lists derived from the shared `writableRoots` helper, so exactly the mode's promised file effects are governed; every root is canonicalized because Seatbelt matches resolved paths (`/tmp` IS `/private/tmp`).
 

+ 1 - 1
packages/sandbox/sandbox-local/README.zh.md

@@ -74,7 +74,7 @@ kind: "package-reference"
 
 bwrap profile 组合只读宿主根目录、全新 `/dev` 与私有 PID 命名空间中的 `/proc`——命令可管理其后代,但看不到宿主进程,因此 procfs 魔法链接无法绕过挂载;`workspace-write` 另加临时的 `/tmp` 与可写工作区绑定挂载。[私有 PID 笔记](../../../.agents/notes/implemented/bug-fix/2026-08-06-bwrap-private-pid-namespace.zh.md)记录该边界。
 
-Landlock launcher 以 npm 分发的原生插件(`@deepseek-ai/node-addon-landlock-run`)提供平台 launcher、功能探测与授权词汇;此提供方只做模式到授权的映射,把路径解析与探测解析保留在带版本的 binary 中。
+Landlock launcher 以 npm 分发的原生插件(`@deepseek-ai/node-addon-system`)提供平台 launcher、功能探测与授权词汇;此提供方只做模式到授权的映射,把路径解析与探测解析保留在带版本的 binary 中。
 
 Seatbelt profile 默认允许,带 `(deny file-write*)` 与来自共享 `writableRoots` 辅助函数的写入 allow-list,因此恰好管辖模式承诺的文件操作;每个根目录都经过规范化,因为 Seatbelt 匹配解析后的路径(`/tmp` 就是 `/private/tmp`)。
 

+ 1 - 1
packages/sandbox/sandbox-local/package.json

@@ -35,7 +35,7 @@
   "dependencies": {
     "@deepseek-ai/dsh-sandbox-windows-acl": "workspace:^",
     "@deepseek-ai/dsh-util-values": "workspace:^",
-    "@deepseek-ai/node-addon-landlock-run": "workspace:^",
+    "@deepseek-ai/node-addon-system": "workspace:^",
     "@deepseek-ai/schemastery": "workspace:^"
   },
   "devDependencies": {

+ 1 - 1
packages/sandbox/sandbox-local/src/index.ts

@@ -30,7 +30,7 @@ import {
   LAUNCHER_FAILURE_EXIT,
   launcherPath as landlockLauncherPath,
   probe as defaultProbeLandlock,
-} from '@deepseek-ai/node-addon-landlock-run'
+} from '@deepseek-ai/node-addon-system'
 import { Context } from '@deepseek-ai/cordis'
 import z from '@deepseek-ai/schemastery'
 import { SandboxProvider, SandboxUnavailableError } from '@deepseek-ai/dsh-sandbox'

+ 1 - 1
packages/sandbox/sandbox-local/src/profiles.ts

@@ -4,7 +4,7 @@
  * @module @deepseek-ai/dsh-sandbox-local/profiles
  */
 
-import { grantArgs as landlockGrantArgs } from '@deepseek-ai/node-addon-landlock-run'
+import { grantArgs as landlockGrantArgs } from '@deepseek-ai/node-addon-system'
 import { writableRoots } from '@deepseek-ai/dsh-sandbox'
 import type { SandboxPolicy } from '@deepseek-ai/dsh-sandbox'
 

+ 1 - 1
packages/sandbox/sandbox-local/tests/landlock.e2e.ts

@@ -6,7 +6,7 @@ import { join } from 'node:path'
 import { afterEach, describe, expect, it } from 'vitest'
 import { Context } from '@deepseek-ai/cordis'
 import type { SandboxPolicy } from '@deepseek-ai/dsh-sandbox'
-import { launcherPath } from '@deepseek-ai/node-addon-landlock-run'
+import { launcherPath } from '@deepseek-ai/node-addon-system'
 import { LocalSandboxProvider } from '@deepseek-ai/dsh-sandbox-local'
 
 /**

+ 1 - 1
packages/sandbox/sandbox-local/tests/local.spec.ts

@@ -12,7 +12,7 @@ import { tmpdir } from 'node:os'
 import { join } from 'node:path'
 import { afterEach, describe, expect, it, vi } from 'vitest'
 import { Context } from '@deepseek-ai/cordis'
-import { LAUNCHER_FAILURE_EXIT } from '@deepseek-ai/node-addon-landlock-run'
+import { LAUNCHER_FAILURE_EXIT } from '@deepseek-ai/node-addon-system'
 import { SANDBOX_UNAVAILABLE, SandboxUnavailableError } from '@deepseek-ai/dsh-sandbox'
 import type { SandboxPolicy } from '@deepseek-ai/dsh-sandbox'
 import {

+ 4 - 4
packages/sandbox/sandbox-local/tests/packed-install.e2e.ts

@@ -22,11 +22,11 @@ import { packedWorkspaceClosure, readWorkspacePackages } from './packed-workspac
 
 const packageDir = fileURLToPath(new URL('..', import.meta.url))
 const repoRoot = fileURLToPath(new URL('../../../..', import.meta.url))
-const nativeDir = join(repoRoot, 'native/landlock-run')
+const nativeDir = join(repoRoot, 'native/system')
 const sourceLauncher = join(nativeDir, 'packages', `linux-${process.arch}`, 'bin', 'landlock-run')
-const platformPackageName = `@deepseek-ai/node-addon-landlock-run-linux-${process.arch}`
+const platformPackageName = `@deepseek-ai/node-addon-system-linux-${process.arch}`
 
-const NATIVE_PACKAGE_PREFIX = '@deepseek-ai/node-addon-landlock-run'
+const NATIVE_PACKAGE_PREFIX = '@deepseek-ai/node-addon-system'
 
 /** ELF `e_machine` (offset 18, LE) for this host: x86-64 = 62, AArch64 = 183. */
 const E_MACHINE = { x64: 62, arm64: 183 }[process.arch as 'x64' | 'arm64']
@@ -109,7 +109,7 @@ describe.skipIf(!packable)('sandbox-local: packed-tarball distribution (publish-
       import { spawnSync } from 'node:child_process'
       import { existsSync } from 'node:fs'
       import { Context } from '@deepseek-ai/cordis'
-      import { launcherPath } from '@deepseek-ai/node-addon-landlock-run'
+      import { launcherPath } from '@deepseek-ai/node-addon-system'
       import { LocalSandboxProvider } from '@deepseek-ai/dsh-sandbox-local'
       const ctx = new Context()
       await ctx.plugin(LocalSandboxProvider, {})

+ 1 - 1
packages/sandbox/sandbox-local/tsconfig.json

@@ -18,7 +18,7 @@
       "path": "../../../vendor/schemastery"
     },
     {
-      "path": "../../../native/landlock-run/packages/entry"
+      "path": "../../../native/system/packages/entry"
     },
     {
       "path": "../../llm/llm"

+ 1 - 1
packages/shell/bash-sandbox/package.json

@@ -41,7 +41,7 @@
     "@deepseek-ai/dsh-sandbox-local": "workspace:^",
     "@deepseek-ai/dsh-sandbox-policy": "workspace:^",
     "@deepseek-ai/cordis": "workspace:^",
-    "@deepseek-ai/node-addon-landlock-run": "workspace:^",
+    "@deepseek-ai/node-addon-system": "workspace:^",
     "@deepseek-ai/dsh-session-projection": "workspace:^"
   }
 }

+ 2 - 2
packages/shell/bash-sandbox/tests/landlock.e2e.ts

@@ -5,7 +5,7 @@ import { homedir, tmpdir } from 'node:os'
 import { join } from 'node:path'
 import { afterEach, describe, expect, it } from 'vitest'
 import { Context } from '@deepseek-ai/cordis'
-import { launcherPath } from '@deepseek-ai/node-addon-landlock-run'
+import { launcherPath } from '@deepseek-ai/node-addon-system'
 import { LocalSandboxProvider } from '@deepseek-ai/dsh-sandbox-local'
 import { SandboxPolicyService } from '@deepseek-ai/dsh-sandbox-policy'
 import SessionProjectionRegistry from '@deepseek-ai/dsh-session-projection'
@@ -21,7 +21,7 @@ import LocalSubprocessRuntime from '@deepseek-ai/dsh-subprocess-local'
  * `@deepseek-ai/dsh-sandbox-local`.
  *
  * Self-skips when the running kernel does not enforce Landlock. CI builds the launcher from
- * `native/landlock-run` before running this file.
+ * `native/system` before running this file.
  */
 
 const probe = spawnSync(launcherPath(), ['--probe'], { timeout: 5_000, encoding: 'utf8' })

+ 1 - 1
packages/shell/bash-sandbox/tests/partial-landlock.spec.ts

@@ -10,7 +10,7 @@ import { join } from 'node:path'
 import { afterEach, describe, expect, it } from 'vitest'
 import { Context } from '@deepseek-ai/cordis'
 import SessionProjectionRegistry from '@deepseek-ai/dsh-session-projection'
-import { LAUNCHER_FAILURE_EXIT } from '@deepseek-ai/node-addon-landlock-run'
+import { LAUNCHER_FAILURE_EXIT } from '@deepseek-ai/node-addon-system'
 import { SANDBOX_UNAVAILABLE, SandboxUnavailableError } from '@deepseek-ai/dsh-sandbox'
 import { LocalSandboxProvider } from '@deepseek-ai/dsh-sandbox-local'
 import { SandboxPolicyService } from '@deepseek-ai/dsh-sandbox-policy'

+ 1 - 1
packages/shell/bash-sandbox/tsconfig.json

@@ -15,7 +15,7 @@
       "path": "../../../vendor/cordis"
     },
     {
-      "path": "../../../native/landlock-run/packages/entry"
+      "path": "../../../native/system/packages/entry"
     },
     {
       "path": "../../util/brand"

+ 13 - 13
pnpm-lock.yaml

@@ -739,9 +739,9 @@ importers:
         specifier: ^1.49.0
         version: 1.61.1
 
-  native/landlock-run:
+  native/system:
     devDependencies:
-      '@deepseek-ai/node-addon-landlock-run':
+      '@deepseek-ai/node-addon-system':
         specifier: workspace:*
         version: link:packages/entry
       '@types/node':
@@ -754,18 +754,18 @@ importers:
         specifier: ^6.0.3
         version: 6.0.3
 
-  native/landlock-run/packages/entry:
+  native/system/packages/entry:
     optionalDependencies:
-      '@deepseek-ai/node-addon-landlock-run-linux-arm64':
+      '@deepseek-ai/node-addon-system-linux-arm64':
         specifier: workspace:*
         version: link:../linux-arm64
-      '@deepseek-ai/node-addon-landlock-run-linux-x64':
+      '@deepseek-ai/node-addon-system-linux-x64':
         specifier: workspace:*
         version: link:../linux-x64
 
-  native/landlock-run/packages/linux-arm64: {}
+  native/system/packages/linux-arm64: {}
 
-  native/landlock-run/packages/linux-x64: {}
+  native/system/packages/linux-x64: {}
 
   packages/acp/acp:
     dependencies:
@@ -5658,9 +5658,9 @@ importers:
       '@deepseek-ai/dsh-subprocess-local':
         specifier: workspace:^
         version: link:../../subprocess/subprocess-local
-      '@deepseek-ai/node-addon-landlock-run':
+      '@deepseek-ai/node-addon-system':
         specifier: workspace:^
-        version: link:../../../native/landlock-run/packages/entry
+        version: link:../../../native/system/packages/entry
       '@types/picomatch':
         specifier: ^3.0.2
         version: 3.0.2
@@ -7432,9 +7432,9 @@ importers:
       '@deepseek-ai/dsh-util-values':
         specifier: workspace:^
         version: link:../../util/values
-      '@deepseek-ai/node-addon-landlock-run':
+      '@deepseek-ai/node-addon-system':
         specifier: workspace:^
-        version: link:../../../native/landlock-run/packages/entry
+        version: link:../../../native/system/packages/entry
       '@deepseek-ai/schemastery':
         specifier: link:../../../vendor/schemastery
         version: link:../../../vendor/schemastery
@@ -8447,9 +8447,9 @@ importers:
       '@deepseek-ai/dsh-subprocess-local':
         specifier: workspace:^
         version: link:../../subprocess/subprocess-local
-      '@deepseek-ai/node-addon-landlock-run':
+      '@deepseek-ai/node-addon-system':
         specifier: workspace:^
-        version: link:../../../native/landlock-run/packages/entry
+        version: link:../../../native/system/packages/entry
 
   packages/shell/pwsh-local:
     dependencies:

+ 3 - 3
pnpm-workspace.yaml

@@ -2,9 +2,9 @@ packages:
   - vendor/*
   - packages/*/*
   # The Landlock launcher is developed with its harness consumers but keeps
-  # its native build and publication scripts under native/landlock-run.
-  - native/landlock-run
-  - native/landlock-run/packages/*
+  # its native build and publication scripts under native/system.
+  - native/system
+  - native/system/packages/*
   # Product assemblies over the package tier; apps/cli owns the `dsh` bin.
   - apps/*
   # Private package owning repository-level benchmark dependencies.

+ 3 - 3
scripts/benchmark-npm-resolution.ts

@@ -16,8 +16,8 @@ const WORKSPACE_MANIFEST_GLOBS = [
   'apps/*/package.json',
   'packages/*/*/package.json',
   'vendor/*/package.json',
-  'native/landlock-run/package.json',
-  'native/landlock-run/packages/*/package.json',
+  'native/system/package.json',
+  'native/system/packages/*/package.json',
 ]
 const INSTALLED_MANIFEST_GLOBS = [
   'node_modules/.pnpm/*/node_modules/*/package.json',
@@ -131,7 +131,7 @@ export function parseBenchmarkOptions(args: readonly string[]): BenchmarkOptions
 }
 
 function workspaceManifestPath(path: string): boolean {
-  return /^(?:apps\/[^/]+|packages\/[^/]+\/[^/]+|vendor\/[^/]+|native\/landlock-run(?:\/packages\/[^/]+)?)\/package\.json$/.test(path)
+  return /^(?:apps\/[^/]+|packages\/[^/]+\/[^/]+|vendor\/[^/]+|native\/system(?:\/packages\/[^/]+)?)\/package\.json$/.test(path)
 }
 
 function workspaceManifestPaths(root: string, ref: string | undefined): string[] {

+ 1 - 1
scripts/check-workspace-constraints.spec.ts

@@ -102,7 +102,7 @@ describe('dsh family version coherence', () => {
   it('leaves other sequences to their own version lines', () => {
     expect(checkDshFamilyVersion({ name: '@deepseek-ai/cordis', version: '4.0.1' }, '0.1.2-rc.1')).toBeUndefined()
     expect(checkDshFamilyVersion(
-      { name: '@deepseek-ai/node-addon-landlock-run', version: '0.1.1' },
+      { name: '@deepseek-ai/node-addon-system', version: '0.1.1' },
       '0.1.2-rc.1',
     )).toBeUndefined()
     expect(checkDshFamilyVersion({ version: '0.1.2-alpha.5' }, '0.1.2-rc.1')).toBeUndefined()

+ 16 - 16
scripts/check-workspace-constraints.ts

@@ -18,7 +18,7 @@ const workspaceGlobs = [
   { dir: 'vendor', depth: 1 },
   { dir: 'packages', depth: 2 },
   { dir: 'native', depth: 1 },
-  { dir: 'native/landlock-run/packages', depth: 1 },
+  { dir: 'native/system/packages', depth: 1 },
   { dir: 'apps', depth: 1 },
 ] as const
 const vendoredPackages = new Set([
@@ -32,14 +32,14 @@ const vendoredPackages = new Set([
   '@deepseek-ai/cordis-plugin-hmr',
   '@deepseek-ai/cordis-plugin-logger-console',
 ])
-const publicLandlockPackages = new Set([
-  '@deepseek-ai/node-addon-landlock-run',
-  '@deepseek-ai/node-addon-landlock-run-linux-arm64',
-  '@deepseek-ai/node-addon-landlock-run-linux-x64',
+const publicNativePackages = new Set([
+  '@deepseek-ai/node-addon-system',
+  '@deepseek-ai/node-addon-system-linux-arm64',
+  '@deepseek-ai/node-addon-system-linux-x64',
 ])
 /** Deliberate source payloads whose exact bytes are part of the package's audit surface. */
 const publicationSourceAllowlist: Readonly<Record<string, readonly string[]>> = {
-  '@deepseek-ai/node-addon-landlock-run': ['src/main.c'],
+  '@deepseek-ai/node-addon-system': ['src/main.c'],
 }
 const repositoryUrl = 'git+https://github.com/deepseek-harness/deepseek-harness.git'
 /**
@@ -114,8 +114,8 @@ function readJson(path: string): PackageManifest {
 
 const rootManifest = readJson(join(root, 'package.json'))
 const repositoryVersion = rootManifest.version
-const landlockWorkspaceManifest = readJson(join(root, 'native/landlock-run/package.json'))
-const landlockVersion = landlockWorkspaceManifest.version
+const nativeWorkspaceManifest = readJson(join(root, 'native/system/package.json'))
+const nativeVersion = nativeWorkspaceManifest.version
 
 /** Repo-relative dirs holding a package.json, walked to the configured depth. */
 function packageDirs(base: string, depth: number): string[] {
@@ -310,12 +310,12 @@ export function checkWorkspaceManifest({ dir, manifest }: WorkspaceManifest): st
   const label = manifest.name ?? dir
   const familyVersionError = checkDshFamilyVersion(manifest, repositoryVersion)
   if (familyVersionError !== undefined) errors.push(familyVersionError)
-  const isLandlockPackageDir = dir.startsWith('native/landlock-run/packages/')
-  const isPublicLandlockPackage = isLandlockPackageDir
+  const isNativePackageDir = dir.startsWith('native/system/packages/')
+  const isPublicNativePackage = isNativePackageDir
     && manifest.name !== undefined
-    && publicLandlockPackages.has(manifest.name)
+    && publicNativePackages.has(manifest.name)
 
-  if (isPublicLandlockPackage) {
+  if (isPublicNativePackage) {
     if (manifest.private === true) {
       errors.push(`${label}: published Landlock package must not set "private": true`)
     }
@@ -375,12 +375,12 @@ export function checkWorkspaceManifest({ dir, manifest }: WorkspaceManifest): st
     }
   }
 
-  if (isLandlockPackageDir) {
-    if (!isPublicLandlockPackage) {
+  if (isNativePackageDir) {
+    if (!isPublicNativePackage) {
       errors.push(`${label}: unexpected package in the public Landlock package family`)
     }
-    if (manifest.version !== landlockVersion) {
-      errors.push(`${label}: package.json version must match Landlock workspace version ${landlockVersion ?? '(missing)'}`)
+    if (manifest.version !== nativeVersion) {
+      errors.push(`${label}: package.json version must match native workspace version ${nativeVersion ?? '(missing)'}`)
     }
   }
 

+ 3 - 3
scripts/clean.spec.ts

@@ -64,16 +64,16 @@ describe('RepositoryCleaner', () => {
 
   it('removes the native Landlock entry output and solution build info', async () => {
     const root = fixture()
-    const entry = 'native/landlock-run/packages/entry'
+    const entry = 'native/system/packages/entry'
     addProject(root, entry, 'lib')
     write(join(root, entry, 'lib/index.js'))
-    write(join(root, 'native/landlock-run/tsconfig.tsbuildinfo'))
+    write(join(root, 'native/system/tsconfig.tsbuildinfo'))
 
     await new RepositoryCleaner(root).clean()
 
     expect(existsSync(join(root, entry, 'lib'))).toBe(false)
     expect(existsSync(join(root, entry, 'src/index.ts'))).toBe(true)
-    expect(existsSync(join(root, 'native/landlock-run/tsconfig.tsbuildinfo'))).toBe(false)
+    expect(existsSync(join(root, 'native/system/tsconfig.tsbuildinfo'))).toBe(false)
   })
 
   it('refuses project outputs reached through a symlink outside the repository', async () => {

+ 2 - 2
scripts/clean.ts

@@ -77,7 +77,7 @@ export class RepositoryCleaner {
     }
     await this.addIfPresent(
       targets,
-      join(this.root, 'native/landlock-run/tsconfig.tsbuildinfo'),
+      join(this.root, 'native/system/tsconfig.tsbuildinfo'),
       canonicalRoot,
     )
 
@@ -122,7 +122,7 @@ export class RepositoryCleaner {
     const outputs = new Set<string>()
     const pending = [join(this.root, 'tsconfig.json')]
     const visited = new Set<string>()
-    const nativeEntryOutput = join(this.root, 'native/landlock-run/packages/entry/lib')
+    const nativeEntryOutput = join(this.root, 'native/system/packages/entry/lib')
 
     while (pending.length > 0) {
       const nextConfigPath = pending.pop()

+ 3 - 3
scripts/gen-third-party-notices.spec.ts

@@ -351,12 +351,12 @@ describe('official Claude distribution authorization', () => {
 
 describe('manifestPatterns', () => {
   it('derives globs from the declared members, so a new member area is read', () => {
-    expect(manifestPatterns(['packages/*/*', 'tools/*', 'native/landlock-run', 'native/landlock-run/packages/*'])).toEqual([
+    expect(manifestPatterns(['packages/*/*', 'tools/*', 'native/system', 'native/system/packages/*'])).toEqual([
       'package.json',
       'packages/*/*/package.json',
       'tools/*/package.json',
-      'native/landlock-run/package.json',
-      'native/landlock-run/packages/*/package.json',
+      'native/system/package.json',
+      'native/system/packages/*/package.json',
     ])
   })
 })

+ 5 - 5
scripts/gen-third-party-notices.ts

@@ -40,9 +40,9 @@ const DEV_ONLY_AREAS = [
 
 /** First-party public native packages: reachable at runtime but not third-party. */
 const FIRST_PARTY = new Set([
-  '@deepseek-ai/node-addon-landlock-run',
-  '@deepseek-ai/node-addon-landlock-run-linux-arm64',
-  '@deepseek-ai/node-addon-landlock-run-linux-x64',
+  '@deepseek-ai/node-addon-system',
+  '@deepseek-ai/node-addon-system-linux-arm64',
+  '@deepseek-ai/node-addon-system-linux-x64',
 ])
 
 /** Official SDK identity covered by the project's narrow owner authorization. */
@@ -295,7 +295,7 @@ function installedManifest(name: string, manifests: Map<string, Manifest>, expec
   let manifest: (Manifest & { license?: string; repository?: string | { url?: string }; homepage?: string }) | undefined
   // Workspace-local link farms can expose a dependency that is not linked at
   // the repository root; both are backed by the root workspace's lockfile.
-  for (const store of ['node_modules', 'native/landlock-run/node_modules']) {
+  for (const store of ['node_modules', 'native/system/node_modules']) {
     const direct = resolve(root, store, name, 'package.json')
     if (existsSync(direct)) {
       const candidate = JSON.parse(readFileSync(direct, 'utf8')) as typeof manifest
@@ -747,7 +747,7 @@ ${python.map(dep => `| [\`${dep.name}\`](${dep.repo}) | ${dep.license} | ${dep.r
 
 ## First-party native packages
 
-\`@deepseek-ai/node-addon-landlock-run\` (and its platform packages) is built and released from this repository under BSD 3-Clause. It is listed here for completeness; it is first-party, not third-party.
+\`@deepseek-ai/node-addon-system\` (and its platform packages) is built and released from this repository under BSD 3-Clause. It is listed here for completeness; it is first-party, not third-party.
 `
 }
 

+ 1 - 1
tsconfig.base.json

@@ -37,7 +37,7 @@
       "@deepseek-ai/cordis-plugin-timer": ["./vendor/timer/src"],
       "@deepseek-ai/cordis-plugin-hmr": ["./vendor/hmr/src"],
       "@deepseek-ai/cordis-plugin-logger-console": ["./vendor/logger-console/src"],
-      "@deepseek-ai/node-addon-landlock-run": ["./native/landlock-run/packages/entry/src/index.ts"],
+      "@deepseek-ai/node-addon-system": ["./native/system/packages/entry/src/index.ts"],
       "@deepseek-ai/dsh-invariants": ["./packages/runtime-diagnostics/invariants/src/index.ts"],
       "@deepseek-ai/dsh-tool-call-timeout-policy": ["./packages/guard/timeout-policy/src"],
       "@deepseek-ai/dsh-spill-policy/notice": ["./packages/spill/spill-policy/src/notice.ts"],

+ 1 - 1
tsconfig.host.json

@@ -251,7 +251,7 @@
     { "path": "./packages/shell/pwsh-local" },
     { "path": "./packages/shell/pwsh-sandbox" },
     { "path": "./packages/shell/tool-pwsh" },
-    { "path": "./native/landlock-run/packages/entry" },
+    { "path": "./native/system/packages/entry" },
     { "path": "./packages/sandbox/sandbox" },
     { "path": "./packages/sandbox/sandbox-local" },
     { "path": "./packages/sandbox/sandbox-policy" },