@struktoai/mirage-node. Install the Sandlock CLI on PATH; its full ruleset
requires Linux 6.12+ (Landlock ABI v6).
captures: ["@external"], delegating unresolved program
names while Mirage keeps its commands, pipes and redirects. Use
captures: ["python3", "node", "@external"] to select native interpreters too. Direct runtime.execute(ProcessExecution(...)) calls take
an argv array without shell interpretation. Choose the interpreter in argv;
there is no Python-specific home setting.
The adapter grants read access to common system paths (/usr, /lib,
/lib64, /bin, /etc, /proc, /dev, where present) plus your configured paths.
Interpreters installed elsewhere need an explicit fs_readable grant.
Config env and execution env are passed to the confined child; execution
values override config values. Host credentials are not inherited.
Workspace access
Sandlock hasprocess reach. Its native filesystem calls require a real
mount to access Mirage’s virtual files. Grant an existing
FUSE mount through fs_readable or fs_writable.
The runtime does not create that mount or automatically bind it to the
execution’s Mirage session. Paths outside Mirage mounts use the host
filesystem and do not pass through Mirage’s policy or observation pipeline.