This file pins the launcher's externally observable behavior — the cross-repo compatibility surface between the binaries and every consumer. Consumers interact with it through the entry package (launcherPath/probe/grantArgs) and the launcher protocol; changing anything below requires a version bump for the whole package family and a note in the release notes.
landlock-run [--ro <path>]... [--rw <path>]... -- <argv>...
landlock-run --probe
--ro <path>: grant read + execute beneath <path>.--rw <path>: grant full filesystem access beneath <path> (every access the negotiated kernel ABI can govern).--rw /dev/null grant works).--: mandatory separator; everything after it is the command argv, exec'd via execvp with the launcher's environment unchanged.--probe: mutually exclusive with grants and a command.125 (LAUNCHER_FAILURE_EXIT): every launcher-level failure — usage error, kernel that cannot enforce Landlock, unopenable grant root, failed exec. The wrapped command was NOT run.exec, every child status is passed through unchanged, including 125. Consumers therefore require both status 125 and a landlock-run: fatal line to attribute launcher failure.--probe: 0 when the kernel enforces (fully or partially), 125 otherwise.landlock: fully enforced or landlock: partially enforced (older ABI). The entry package's probe() maps these to full/partial; a non-zero probe exit maps to unusable.landlock-run: partial enforcement (older Landlock ABI) and proceeds — still confined for everything the kernel supports.landlock-run: before exiting 125.The launcher sets no_new_privs, installs the ruleset on itself, and execs the command; the ruleset is inherited across execve, so every descendant process is equally confined. The ruleset governs the filesystem accesses of the kernel's negotiated Landlock ABI (up to ABI 5); accesses newer than the running ABI are not governed and are the difference between full and partial.