Skip to main content
Sandlock runs native commands, including Python and Node.js. Mirage supports it in the Python SDK and @struktoai/mirage-node. Install the Sandlock CLI on PATH; its full ruleset requires Linux 6.12+ (Landlock ABI v6).
Sandlock defaults to captures: ["@external"], delegating unresolved program names while Mirage keeps its commands, pipes and redirects. Use captures: ["python3", "node", "@external"] to select native interpreters too. Direct runtime.execute(ProcessExecution(...)) calls take an argv array without shell interpretation. Choose the interpreter in argv; there is no Python-specific home setting. The adapter grants read access to common system paths (/usr, /lib, /lib64, /bin, /etc, /proc, /dev, where present) plus your configured paths. Interpreters installed elsewhere need an explicit fs_readable grant. Config env and execution env are passed to the confined child; execution values override config values. Host credentials are not inherited.

Workspace access

Sandlock has process reach. Its native filesystem calls require a real mount to access Mirage’s virtual files. Grant an existing FUSE mount through fs_readable or fs_writable. The runtime does not create that mount or automatically bind it to the execution’s Mirage session. Paths outside Mirage mounts use the host filesystem and do not pass through Mirage’s policy or observation pipeline.