Sentinel v1.0.2 — freeroot/proot coverage + defaults fix
- Defaults layering fix: the panel's 5-item abuse.known_processes default was masking the comprehensive node list on every node (v2ray, xray, cloudflared, ngrok, tunnels, spam tools were effectively unwatched). The full list now ships, plus
proot. - freeroot coverage (the foxy touxxx proot Ubuntu-userland installer): jar blocklisting via intel,
prootprocess signature, console-log indicators ("Do you want to install Ubuntu?", "Executing proot"), volumescan content patterns (foxytouxxx,freeroot,ubuntu-base-), and aFreeroot_Proot_InstallerYARA rule. - Wider abusive listen ports: 1080, 8388, 9001, 9030, 3128, 8118.
Verified live: jar drop → critical onaccess blocklist event; proot process → high abuse event; config sync + intel persistence intact.