bun test v1.4.2 (744846f84) sandbox.test.ts: ✓ the landlockconfig policy is deny-by-default with fs/net/scope grants [0.52ms] ✓ the policy excludes the home and sibling integrations (leaf-scoped) [0.15ms] ✓ multiple connect ports collapse into one connect_tcp rule [0.02ms] ✓ no connect ports means no egress rule [0.02ms] ✓ bind ports emit a bind_tcp rule alongside connect egress [0.02ms] ✓ multiple bind ports collapse into one bind_tcp rule [0.01ms] ✓ no bind ports still handles bind_tcp so every bind is denied [0.09ms] landlock-policy-cli.test.ts: ✓ lowerIntegrationPolicy: writable surface is StateDirectory + private tmpfs [0.07ms] ✓ lowerIntegrationPolicy: credentials mount is read-only, ports pass through [0.02ms] ✓ lowerIntegrationPolicy: a shared exchange dir joins the writable surface [0.02ms] ✓ resolveFromEnv: colon-lists split, absent vars yield empty [0.06ms] ✓ end-to-end: deny-by-default doc grants exactly StateDir(rw) + cred(ro) + 443 [0.14ms] ✓ lowerIntegrationPolicy: bindPorts fold through into a bind_tcp rule [0.03ms] ✓ lowerIntegrationPolicy: absent bindPorts grants no bind but keeps it handled [0.02ms] ✓ lowerIntegrationPolicy: extraPaths route ro→roDirs, rw→rwDirs [0.13ms] ✓ lowerIntegrationPolicy: extraPaths ro-file routes to roFiles, not roDirs [0.08ms] ✓ lowerIntegrationPolicy: %t/%h in extraPaths expand from the unit env [0.04ms] ✓ lowerIntegrationPolicy: an unresolvable specifier fails closed [0.10ms] ✓ resolveFromEnv: %t/%h sources come from XDG_RUNTIME_DIR/HOME [0.01ms] 19 pass 0 fail 55 expect() calls Ran 19 tests across 2 files. [6.00ms]