nixbot

builds

succeeded spaces-landlock-policy-test checks.x86_64-linux.spaces-landlock-policy · build #175 · raw

1bun test v1.3.13 (bf2e2cec)23sandbox.test.ts:4✓ the landlockconfig policy is deny-by-default with fs/net/scope grants [3.00ms]5✓ the policy excludes the home and sibling integrations (leaf-scoped)6✓ multiple connect ports collapse into one connect_tcp rule7✓ no connect ports means no egress rule8✓ bind ports emit a bind_tcp rule alongside connect egress9✓ multiple bind ports collapse into one bind_tcp rule10✓ no bind ports still handles bind_tcp so every bind is denied [1.00ms]1112landlock-policy-cli.test.ts:13✓ lowerIntegrationPolicy: writable surface is StateDirectory + private tmpfs14✓ lowerIntegrationPolicy: credentials mount is read-only, ports pass through15✓ lowerIntegrationPolicy: a shared exchange dir joins the writable surface16✓ resolveFromEnv: colon-lists split, absent vars yield empty [1.00ms]17✓ resolveFromEnv -> lowerIntegrationPolicy: the shared dir env reaches rw18✓ end-to-end: deny-by-default doc grants exactly StateDir(rw) + cred(ro) + 44319✓ lowerIntegrationPolicy: bindPorts fold through into a bind_tcp rule20✓ lowerIntegrationPolicy: absent bindPorts grants no bind but keeps it handled21✓ lowerIntegrationPolicy: extraPaths route ro→roDirs, rw→rwDirs22✓ lowerIntegrationPolicy: extraPaths ro-file routes to roFiles, not roDirs23✓ lowerIntegrationPolicy: %t/%h in extraPaths expand from the unit env24✓ lowerIntegrationPolicy: an unresolvable specifier fails closed25✓ resolveFromEnv: %t/%h sources come from XDG_RUNTIME_DIR/HOME2627 20 pass28 0 fail29 58 expect() calls30Ran 20 tests across 2 files. [22.00ms]