bun test v1.4.2 (744846f84) sandbox.test.ts: ✓ the landlockconfig policy is deny-by-default with fs/net/scope grants [0.57ms] ✓ the policy excludes the home and sibling integrations (leaf-scoped) [0.13ms] ✓ multiple connect ports collapse into one connect_tcp rule [0.03ms] ✓ no connect ports means no egress rule [0.02ms] ✓ bind ports emit a bind_tcp rule alongside connect egress [0.03ms] ✓ multiple bind ports collapse into one bind_tcp rule [0.02ms] ✓ no bind ports still handles bind_tcp so every bind is denied [0.14ms] landlock-policy-cli.test.ts: ✓ lowerIntegrationPolicy: writable surface is StateDirectory + private tmpfs [0.10ms] ✓ lowerIntegrationPolicy: credentials mount is read-only, ports pass through [0.03ms] ✓ lowerIntegrationPolicy: a shared exchange dir joins the writable surface [0.03ms] ✓ resolveFromEnv: colon-lists split, absent vars yield empty [0.09ms] ✓ resolveFromEnv -> lowerIntegrationPolicy: the shared dir env reaches rw [0.04ms] ✓ end-to-end: deny-by-default doc grants exactly StateDir(rw) + cred(ro) + 443 [0.18ms] ✓ lowerIntegrationPolicy: bindPorts fold through into a bind_tcp rule [0.06ms] ✓ lowerIntegrationPolicy: absent bindPorts grants no bind but keeps it handled [0.03ms] ✓ lowerIntegrationPolicy: extraPaths route ro→roDirs, rw→rwDirs [0.19ms] ✓ lowerIntegrationPolicy: extraPaths ro-file routes to roFiles, not roDirs [0.17ms] ✓ lowerIntegrationPolicy: %t/%h in extraPaths expand from the unit env [0.05ms] ✓ lowerIntegrationPolicy: an unresolvable specifier fails closed [0.09ms] ✓ resolveFromEnv: %t/%h sources come from XDG_RUNTIME_DIR/HOME [0.02ms] 20 pass 0 fail 58 expect() calls Ran 20 tests across 2 files. [18.00ms]