{"_id":"@dangzhuotong/node-addon-landlock-run","name":"@dangzhuotong/node-addon-landlock-run","dist-tags":{"next":"0.1.1","latest":"0.1.1"},"versions":{"0.1.1":{"name":"@dangzhuotong/node-addon-landlock-run","version":"0.1.1","type":"module","description":"Landlock self-restrict-then-exec launcher for sandboxing subprocesses on Linux: per-platform prebuilt static binaries plus the JS seam that resolves, probes, and speaks their CLI contract","repository":{"type":"git","url":"git+https://github.com/deepseek-harness/deepseek-harness.git","directory":"native/landlock-run/packages/entry"},"main":"lib/index.js","types":"lib/index.d.ts","exports":{".":{"types":"./lib/index.d.ts","default":"./lib/index.js"},"./package.json":"./package.json"},"engines":{"node":">=20"},"license":"BSD-3-Clause","publishConfig":{"access":"public"},"optionalDependencies":{"@dangzhuotong/node-addon-landlock-run-linux-arm64":"0.1.1","@dangzhuotong/node-addon-landlock-run-linux-x64":"0.1.1"},"scripts":{"build:js":"tsc -b"},"_id":"@dangzhuotong/node-addon-landlock-run@0.1.1","gitHead":"53baf21dfae3d134fa248f36dafb4ab1fe28e55c","bugs":{"url":"https://github.com/deepseek-harness/deepseek-harness/issues"},"homepage":"https://github.com/deepseek-harness/deepseek-harness#readme","_integrity":"sha512-eh94mKxFaG7lEAmeEtmQIHbqz9io8xKIk0FIJq3nFXOcn1XqkfPcWkwNiTaC8Z7/VNnNsrXB2tOCbnm89EDXdQ==","_resolved":"D:\\Coding\\deepseek-harness-master\\dist\\npm\\native\\dangzhuotong-node-addon-landlock-run-0.1.1.tgz","_from":"file:dist/npm/native/dangzhuotong-node-addon-landlock-run-0.1.1.tgz","_nodeVersion":"22.21.1","_npmVersion":"10.9.4","dist":{"integrity":"sha512-eh94mKxFaG7lEAmeEtmQIHbqz9io8xKIk0FIJq3nFXOcn1XqkfPcWkwNiTaC8Z7/VNnNsrXB2tOCbnm89EDXdQ==","shasum":"fb263bd58bf4dd5d92bb831867f83fdf08cd36dc","tarball":"https://registry.npmjs.org/@dangzhuotong/node-addon-landlock-run/-/node-addon-landlock-run-0.1.1.tgz","fileCount":8,"unpackedSize":26338,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIE22wyePv8YKdnFzDjPtAx/jU/9xXpwphVCQ6qd7wbvSAiBRGngKO8g8dgEcUIAK1ZdXlEz4MkjRsGPoV9ufGBL91Q=="}]},"_npmUser":{"name":"dangzhuotong","email":"353199054@qq.com"},"directories":{},"maintainers":[{"name":"dangzhuotong","email":"353199054@qq.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/node-addon-landlock-run_0.1.1_1787281317116_0.2443298100986342"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-21T03:01:56.964Z","0.1.1":"2026-08-21T03:01:57.379Z","modified":"2026-08-21T03:01:57.651Z"},"maintainers":[{"name":"dangzhuotong","email":"353199054@qq.com"}],"description":"Landlock self-restrict-then-exec launcher for sandboxing subprocesses on Linux: per-platform prebuilt static binaries plus the JS seam that resolves, probes, and speaks their CLI contract","homepage":"https://github.com/deepseek-harness/deepseek-harness#readme","repository":{"type":"git","url":"git+https://github.com/deepseek-harness/deepseek-harness.git","directory":"native/landlock-run/packages/entry"},"bugs":{"url":"https://github.com/deepseek-harness/deepseek-harness/issues"},"license":"BSD-3-Clause","readme":"# @dangzhuotong/node-addon-landlock-run\n\n[English](README.md) | 中文\n\n用于在 Linux 上限制子进程的 Landlock「先限制自身、再执行」启动器：此入口包定位对应平台的预构建二进制文件，运行功能性强制执行探测，并构建其授权 argv。消费方无需自行拼写启动器标志或解析启动器输出。\n\n```js\nimport { grantArgs, launcherPath, probe } from '@dangzhuotong/node-addon-landlock-run';\n\nconst launcher = launcherPath();\nif (probe(launcher) !== 'unusable') {\n  const argv = [launcher, ...grantArgs({ readOnly: ['/'], readWrite: ['/tmp/work'] }), '--', 'bash', '-c', command];\n}\n```\n\n启动器在自身上安装 Landlock 规则集，再 `exec` 被包装的命令；该规则集会跨 `execve` 继承，因此整个进程树都在限制下运行。未授予的一切都被拒绝；启动器失败时以 `125` 退出且不运行命令：采用失败闭合策略，绝不在失败时放行。二进制约定锁定在仓库的 `docs/cli-contract.md` 中；C 源码作为 `src/main.c` 随该 tarball 分发，便于审计。\n\n平台包（由 `os`/`cpu` 选择的可选依赖，内部不含 JavaScript）：`@dangzhuotong/node-addon-landlock-run-linux-x64`、`@dangzhuotong/node-addon-landlock-run-linux-arm64`。在缺少对应包的宿主上，`launcherPath()` 返回一个固定但不存在的路径，`probe()` 报告 `'unusable'`；系统有意不提供安装时编译回退。\n","readmeFilename":"README.zh.md","_rev":"1-ef0583bde615a3ed1eb27a0972163ac8"}