This workspace builds landlock-run, a Landlock self-restrict-then-exec launcher: a small, auditable confinement binary distributed as prebuilt per-platform npm packages, plus the thin JS entry package that resolves it and speaks its CLI contract. The source of record is the deepseek-harness repository's native/landlock-run/; the node-addon-landlock-run repository is the release mirror this tree is exported to for packing and publishing (procedure: native/README.md in the harness repo). Make changes in the source of record, never only in the mirror.
The project is pre-1.0. Prefer the correct public shape over compatibility shims: if a package name, exported field, layout, or contract detail is wrong, rename it and update all references in the same change. Do not add deprecated aliases unless a stable release already needs them.
NALR_* prefix is for build/test orchestration only.packages/entry/ Published entry package: JS seam (resolve/probe/grants) + the C source.
packages/linux-*/ Published per-platform packages: one prebuilt static binary, no JavaScript.
scripts/ Build, matrix derivation, prepack gates, and release orchestration.
test/ Plain-node behavioral tests (entry seam + real-kernel launcher proofs).
docs/ Architecture, packaging, CLI contract, release, support matrix, naming.
pnpm install
pnpm build:ts # entry packages → lib/
pnpm build:native # this Linux architecture's binaries (needs musl-tools); fails fast elsewhere
pnpm typecheck
pnpm test # entry tests everywhere; launcher tests need linux + built binary
packages/<name>/package.json (os, cpu), packages/<name>/prebuilds.json (the binaries that may exist there), and docs/support-matrix.md stay synchronized when the matrix changes. scripts/github-matrix.mjs derives CI and release matrices from it; nothing else enumerates platforms.-linux-x64), never tool variants — those stay inside prebuilds.json. Static musl linking is why there is no libc suffix: one binary serves glibc and musl distros.verify-launcher-binary.mjs), entry packages without built lib/ (verify-entry-lib.mjs), and the release pipeline byte-pins installed binaries against the workspace builds (verify-packed-install.mjs).npm pack, never pnpm pack: pnpm's pack path strips the executable bit (observed on 11.7.0), shipping a launcher no consumer can spawn. pack-release.mjs encodes the split; the rehearsal asserts executability of the installed copy so a regression fails loudly instead of masquerading as a non-enforcing kernel.packages/*/bin/, packages/*/lib/, dist/, .release/, *.tsbuildinfo. Ignore rules live in the ROOT .gitignore only — a package-nested ignore file can silently drop payload from tarballs.User-facing docs are English. Keep the README focused on install, usage, and support status; durable design decisions belong in docs/ alongside the code, and the current implemented shape belongs in docs/architecture.md.