Files
deepseek-harness/native/landlock-run/packages/entry
imccyu a213befd0f build(release): publish the vendored framework and the native packages publicly
The three release sequences shipped with publishConfig.access: restricted, so
nothing in the @deepseek-ai scope was installable from outside the organization.

A restricted dependency is what actually blocks a public consumer: every harness
package declares the vendored framework as a peerDependency, and
dsh-sandbox-local declares the Landlock entry as a dependency. Those two
sequences therefore go public first — the nine vendor/* packages and the three
native/landlock-run packages — while the dsh family stays restricted until its
own sequence is opened deliberately. No public package requires a restricted one
in this arrangement.

Access is now per sequence, so no publish path can pass --access: one flag
cannot express two levels and would override the manifest that owns the fact.
publish.ts stops passing it, matching the native workflow, and
check-workspace-constraints holds each manifest to its own sequence's level,
which is what stops the scope from drifting one package at a time.

Harness consumers reference the Landlock entry as workspace:^ instead of
workspace:*, so a published harness package accepts the entry's patch and minor
releases. The entry keeps workspace:* for its platform packages, where the
binary must match the entry version exactly.

Two rationales that named a private registry no longer describe the vendored
sequence; they now state the durable reason, which is that the verification must
not depend on the registry already carrying matching versions.
2026-08-13 14:05:48 +08:00
..

@deepseek-ai/node-addon-landlock-run

English | 中文

Landlock self-restrict-then-exec launcher for confining subprocesses on Linux: this entry package resolves the per-platform prebuilt binary, runs its functional enforcement probe, and builds its grant argv — consumers never spell launcher flags or parse launcher output themselves.

import { grantArgs, launcherPath, probe } from '@deepseek-ai/node-addon-landlock-run';

const launcher = launcherPath();
if (probe(launcher) !== 'unusable') {
  const argv = [launcher, ...grantArgs({ readOnly: ['/'], readWrite: ['/tmp/work'] }), '--', 'bash', '-c', command];
}

The launcher installs a Landlock ruleset on itself and execs the wrapped command; the ruleset is inherited across execve, so the whole process tree runs confined. Everything not granted is denied, and launcher failures exit 125 without running the command — fail-closed, never fail-open. The binary contract is pinned in the repo's docs/cli-contract.md; the C source rides this tarball (src/main.c) for audit.

Platform packages (os/cpu-selected optional dependencies, no JavaScript inside): @deepseek-ai/node-addon-landlock-run-linux-x64, @deepseek-ai/node-addon-landlock-run-linux-arm64. On hosts without one, launcherPath() returns a deterministic nonexistent path and probe() reports 'unusable' — there is deliberately no install-time compile fallback.