This directory builds landlock-run, a Landlock self-restrict-then-exec launcher: a small, auditable confinement binary distributed as prebuilt per-platform npm packages, plus the thin JS entry package that resolves it and implements its CLI contract. It belongs to the repository's root pnpm workspace and lockfile. The main repository owns native CI, tarball assembly, verification, and npm publication; keep package-family changes coordinated with harness consumers in the same repository.
The project is pre-1.0. Prefer the correct public API over compatibility shims: if a package name, exported field, layout, or contract detail is wrong, rename it and update all references in the same change. Do not add deprecated aliases unless a stable release already needs them.
NALR_* prefix is for build/test orchestration only.packages/entry/ Published entry package: JavaScript API (resolve/probe/grants) + the C source.
packages/linux-*/ Published per-platform packages: one prebuilt static binary, no JavaScript.
scripts/ Build, matrix derivation, prepack gates, and release orchestration.
test/ Plain-node behavioral tests (entry API + real-kernel launcher proofs).
docs/ Architecture, packaging, CLI contract, release, support matrix, naming.
pnpm install
pnpm build:ts # entry packages → lib/
pnpm build:native # this Linux architecture's binaries (needs musl-tools); fails fast elsewhere
pnpm typecheck
pnpm test # entry tests everywhere; launcher tests need linux + built binary
packages/<name>/package.json (os, cpu), packages/<name>/prebuilds.json (the binaries that may exist there), and docs/support-matrix.md stay synchronized when the matrix changes. scripts/github-matrix.mjs derives CI and release matrices from it; nothing else enumerates platforms.-linux-x64), never tool variants — those stay inside prebuilds.json. Static musl linking is why there is no libc suffix: one binary serves glibc and musl distros.verify-launcher-binary.mjs), entry packages without built lib/ (verify-entry-lib.mjs), and the release pipeline byte-pins installed binaries against the workspace builds (verify-packed-install.mjs).npm pack, never pnpm pack: pnpm's pack path strips the executable bit (observed on 11.7.0), shipping a launcher no consumer can spawn. pack-release.mjs encodes the split; the rehearsal asserts executability of the installed copy so a regression fails loudly instead of masquerading as a non-enforcing kernel.packages/*/bin/, packages/*/lib/, dist/, .release/, *.tsbuildinfo. Ignore rules live in the ROOT .gitignore only — a package-nested ignore file can silently drop payload from tarballs.User-facing docs are English. Keep the README focused on install, usage, and support status; durable design decisions belong in docs/ alongside the code, and the current implementation belongs in docs/architecture.md.