bun test v1.3.13 (bf2e2cec) sandbox.test.ts: ✓ the landlockconfig policy is deny-by-default with fs/net/scope grants [3.00ms] ✓ the policy excludes the home and sibling integrations (leaf-scoped) ✓ multiple connect ports collapse into one connect_tcp rule ✓ no connect ports means no egress rule ✓ bind ports emit a bind_tcp rule alongside connect egress ✓ multiple bind ports collapse into one bind_tcp rule ✓ no bind ports still handles bind_tcp so every bind is denied [1.00ms] landlock-policy-cli.test.ts: ✓ lowerIntegrationPolicy: writable surface is StateDirectory + private tmpfs ✓ lowerIntegrationPolicy: credentials mount is read-only, ports pass through ✓ lowerIntegrationPolicy: a shared exchange dir joins the writable surface ✓ resolveFromEnv: colon-lists split, absent vars yield empty [1.00ms] ✓ resolveFromEnv -> lowerIntegrationPolicy: the shared dir env reaches rw ✓ end-to-end: deny-by-default doc grants exactly StateDir(rw) + cred(ro) + 443 ✓ lowerIntegrationPolicy: bindPorts fold through into a bind_tcp rule ✓ lowerIntegrationPolicy: absent bindPorts grants no bind but keeps it handled ✓ lowerIntegrationPolicy: extraPaths route ro→roDirs, rw→rwDirs ✓ lowerIntegrationPolicy: extraPaths ro-file routes to roFiles, not roDirs ✓ lowerIntegrationPolicy: %t/%h in extraPaths expand from the unit env ✓ lowerIntegrationPolicy: an unresolvable specifier fails closed ✓ resolveFromEnv: %t/%h sources come from XDG_RUNTIME_DIR/HOME 20 pass 0 fail 58 expect() calls Ran 20 tests across 2 files. [22.00ms]