spaces-landlock-policy-test
checks.x86_64-linux.spaces-landlock-policy
· build #173
· raw
1bun test v1.4.2 (744846f84)23sandbox.test.ts:4✓ the landlockconfig policy is deny-by-default with fs/net/scope grants [0.52ms]5✓ the policy excludes the home and sibling integrations (leaf-scoped) [0.15ms]6✓ multiple connect ports collapse into one connect_tcp rule [0.02ms]7✓ no connect ports means no egress rule [0.02ms]8✓ bind ports emit a bind_tcp rule alongside connect egress [0.02ms]9✓ multiple bind ports collapse into one bind_tcp rule [0.01ms]10✓ no bind ports still handles bind_tcp so every bind is denied [0.09ms]1112landlock-policy-cli.test.ts:13✓ lowerIntegrationPolicy: writable surface is StateDirectory + private tmpfs [0.07ms]14✓ lowerIntegrationPolicy: credentials mount is read-only, ports pass through [0.02ms]15✓ lowerIntegrationPolicy: a shared exchange dir joins the writable surface [0.02ms]16✓ resolveFromEnv: colon-lists split, absent vars yield empty [0.06ms]17✓ end-to-end: deny-by-default doc grants exactly StateDir(rw) + cred(ro) + 443 [0.14ms]18✓ lowerIntegrationPolicy: bindPorts fold through into a bind_tcp rule [0.03ms]19✓ lowerIntegrationPolicy: absent bindPorts grants no bind but keeps it handled [0.02ms]20✓ lowerIntegrationPolicy: extraPaths route ro→roDirs, rw→rwDirs [0.13ms]21✓ lowerIntegrationPolicy: extraPaths ro-file routes to roFiles, not roDirs [0.08ms]22✓ lowerIntegrationPolicy: %t/%h in extraPaths expand from the unit env [0.04ms]23✓ lowerIntegrationPolicy: an unresolvable specifier fails closed [0.10ms]24✓ resolveFromEnv: %t/%h sources come from XDG_RUNTIME_DIR/HOME [0.01ms]2526 19 pass27 0 fail28 55 expect() calls29Ran 19 tests across 2 files. [6.00ms]