Bring the node-addon-landlock-run tree (tag v0.0.1, commit 614f7fd) into native/landlock-run as its source of record: launcher development happens here, next to the harness consumers, and the standalone repository becomes the release mirror the tree is exported to for packing and publishing (procedure in native/README.md). The subtree keeps its own pnpm workspace and lockfile and is NOT added to the harness workspace: harness installs, gates, and CI never touch it. The mirror's .github/ stays out of the subtree; a separate manually-dispatched workflow (.github/workflows/landlock-run.yml) runs the subtree's CI legs — the per-architecture native builds, real-kernel launcher proofs, and pack rehearsal — adapted with working-directory/cache paths. eslint ignores the subtree like vendor/; AGENTS.md gains the native/ layout line (+5 words on its budget ceiling).
native/
Source of record for node-addon-landlock-run, the Landlock self-restrict-then-exec launcher the harness consumes from npm (packages/sandbox/sandbox-local, packages/bash/bash-sandbox). Launcher development happens HERE, next to the consumers; the standalone repository is the release mirror that packs and publishes the npm package family.
Release mirror
| Directory | Mirror repo | Last exported release | Commit |
|---|---|---|---|
landlock-run/ |
https://github.com/deepseek-harness/node-addon-landlock-run | v0.0.1 |
614f7fd7dc11e6eaceefba9e7ff1fbe28b51ba22 |
The subtree is a self-contained pnpm workspace with its own AGENTS.md, docs, gates, and lockfile; it is NOT part of the harness workspace (pnpm-workspace.yaml does not include it), so harness installs, builds, and CI gates never touch it. The mirror's .github/ stays out of the subtree — .github/workflows/landlock-run.yml (manual dispatch) runs the subtree's CI legs here, and a change to those legs is mirrored into the mirror's ci.yml at the next export.
Export procedure (cutting a release)
- Land the launcher change here through a normal harness PR; dispatch the
Landlock Runworkflow and get its legs green. - In the mirror checkout, replace everything except
.github/:git -C <mirror> rm -rq -- . ':!.github', thengit -C <harness> archive HEAD:native/landlock-run | tar -x -C <mirror>, thengit -C <mirror> add -Aand commit. - In the mirror, follow its release checklist (
docs/release.md):pnpm release:commit <version>→ merge → tagvX.Y.Z→ two-phaseReleaseworkflow (publish=falserehearsal, thenpublish=truefrom the tag). - Update the manifest table above with the released tag/commit, and bump the harness consumers' dependency range in the same change.
The mirror must not diverge: a change committed there directly (hotfix during a release) is ported back here before the next export.