nixbot

builds

succeeded spaces-landlock-policy-test checks.x86_64-linux.spaces-landlock-policy · build #110 · raw

1bun test v1.3.13 (bf2e2cec)23sandbox.test.ts:4✓ the landlockconfig policy is deny-by-default with fs/net/scope grants [3.00ms]5✓ the policy excludes the home and sibling integrations (leaf-scoped) [1.00ms]6✓ multiple connect ports collapse into one connect_tcp rule7✓ no connect ports means no egress rule8✓ bind ports emit a bind_tcp rule alongside connect egress9✓ multiple bind ports collapse into one bind_tcp rule10✓ no bind ports still handles bind_tcp so every bind is denied [3.00ms]1112landlock-policy-cli.test.ts:13✓ lowerIntegrationPolicy: writable surface is StateDirectory + private tmpfs [1.00ms]14✓ lowerIntegrationPolicy: credentials mount is read-only, ports pass through15✓ lowerIntegrationPolicy: a shared exchange dir joins the writable surface16✓ resolveFromEnv: colon-lists split, absent vars yield empty17✓ end-to-end: deny-by-default doc grants exactly StateDir(rw) + cred(ro) + 443 [1.00ms]18✓ lowerIntegrationPolicy: bindPorts fold through into a bind_tcp rule19✓ lowerIntegrationPolicy: absent bindPorts grants no bind but keeps it handled20✓ lowerIntegrationPolicy: extraPaths route ro→roDirs, rw→rwDirs [2.00ms]21✓ lowerIntegrationPolicy: extraPaths ro-file routes to roFiles, not roDirs22✓ lowerIntegrationPolicy: %t/%h in extraPaths expand from the unit env23✓ lowerIntegrationPolicy: an unresolvable specifier fails closed [1.00ms]24✓ resolveFromEnv: %t/%h sources come from XDG_RUNTIME_DIR/HOME2526 19 pass27 0 fail28 55 expect() calls29Ran 19 tests across 2 files. [225.00ms]