Releases: Greigh/Blockingmachine
Release list
v1.0.0-rc.6
Blockingmachine v1.0.0-rc.6
Sixth release candidate for Blockingmachine 1.0, focused on rule engine correctness, deduplication precision, and publishing hygiene. This release resolves a long-standing tie-breaking flaw in the rule selection engine, closes a canonical key collision in scriptlet deduplication, and eliminates duplicate package listings on GitHub Packages. All 565 automated tests pass.
Highlights since RC 5
-
Rule Engine:
selectBestRule—$importantPriority Fix (@blockingmachine/core):RuleDeduplicator.selectBestRulepreviously failed to prefer$important-flagged rules over equivalent non-$importantvariants when provenance scores were equal, causing the wrong representative rule to be selected during deduplication.- Added an explicit
$importantpriority check before suffix-pattern and score comparisons, ensuring||domain.com^$importantalways wins over||domain.com^in a merge group.
-
Rule Engine: Scriptlet Whitespace Normalization (
@blockingmachine/core):RuleDeduplicator.stripRulepreviously generated distinct canonical keys for identical scriptlet rules that differed only in internal whitespace (e.g.,##+js(set, admiral, noopfn)vs##+js(set, admiral, noopfn)), causing functionally-duplicate scriptlet rules to survive deduplication.- Scriptlet payloads are now collapsed to a single canonical whitespace form (
payload.replace(/\s+/g, ' ').trim()) before key generation, correctly deduplicating all equivalent scriptlet variants.
-
Duplicate Package Fix — GitHub Packages Publishing:
scripts/publish-gpr.mjspreviously published each package under three separate names (@greigh/blockingmachine-core,@greigh/core,@blockingmachine/core), resulting in four package listings on GitHub Packages instead of the expected two.- Simplified to publish only under the canonical
@blockingmachine/coreand@blockingmachine/clinames, matching the package scope declared in each workspacepackage.json.
-
CI: Release Notes Lookup Fix (
.github/workflows/publish.yml):- Replaced the fragile string-manipulation release notes filename derivation with a robust
grep -oPpattern that correctly maps anyv1.0.0-rc.Ntag toscripts/release-notes-rcN.md. - Updated the workflow fallback tag from the stale
v1.0.0-rc.4tov1.0.0-rc.6.
- Replaced the fragile string-manipulation release notes filename derivation with a robust
-
Test Suite Expansion:
- Added regression coverage for
selectBestRule$importanttie-breaking. - Added regression coverage for scriptlet canonical key whitespace equivalence.
- 565 automated tests passing across 23 test suites (100% pass rate).
- Zero TypeScript diagnostics, zero ESLint errors.
- Added regression coverage for
Downloads & Assets
| Asset | Description |
|---|---|
Blockingmachine-1.0.0-rc.6-arm64.dmg |
macOS Apple Silicon installer |
Blockingmachine-darwin-arm64-1.0.0-rc.6.zip |
macOS Apple Silicon standalone app |
blockingmachine-core-1.0.0-rc.6.tgz |
Core library NPM package |
blockingmachine-cli-1.0.0-rc.6.tgz |
CLI executable NPM package |
blockingmachine-chrome-mv3-v1.0.0.zip |
Chrome Manifest V3 extension |
blockingmachine-firefox-mv3-v1.0.0.zip |
Firefox Manifest V3 extension |
SHA256SUMS.txt |
SHA-256 verification checksums |
v1.0.0-rc.5
Blockingmachine v1.0.0-rc.5
Fifth release candidate for Blockingmachine 1.0 featuring a comprehensive Principal Software Engineer security and production-readiness audit across the monorepo, in-place hardening against OS command injection, SSRF, path traversal, stream DoS, and CSRF attacks, cryptographic SHA-256 filter feed integrity verification, native crash diagnostics, Chromium OS sandboxing, and expanded test coverage (434 automated tests passing).
Highlights since RC 4
- Monorepo Security & Production Audit (
AUDIT.md):- Completed an exhaustive 42-section Principal Software Engineer audit across all 8 workspaces (
@blockingmachine/core,@blockingmachine/cli,@blockingmachine/electron-app,@blockingmachine/system-daemon,@blockingmachine/browser-extension,database,homeassistant-addon, andhomeassistant-integration). - Audited for architectural boundaries, memory safety, concurrency, IPC security, error boundaries, and input sanitization, certifying 100% READY for production release.
- Completed an exhaustive 42-section Principal Software Engineer audit across all 8 workspaces (
- OS Command Injection Defense (
@blockingmachine/electron-app):- Replaced unescaped shell
execinvocations indaemonManager.tswith parameterizedexecFileAsync(child_process.execFile), completely bypassing shell interpreter expansion. - Added strict regex validation (
/^[a-zA-Z0-9_\- ]+$/) on daemon service names to reject control characters and shell metacharacters. - Hardened async execution with structured
try...finally { clearTimeout(timeout); }to prevent open timer leaks.
- Replaced unescaped shell
- SSRF, Path Traversal & Feed Integrity Verification (
@blockingmachine/core):- Enforced
redirect: "manual"in filter fetch pipeline and validated HTTP redirect destinations againstisSafePublicWebUrl(), neutralizing redirect-based SSRF. - Blocked path traversal into sensitive operating system files and directories (
/etc,/proc,/sys,~/.ssh,~/.aws,.env) with 403 Forbidden responses. - Added SHA-256 checksum calculation and
expectedSha256validation for downloaded filter feeds; rejects corrupted or tampered lists with 422 Unprocessable Entity.
- Enforced
- CSRF, DoS & Stream Protection:
- Enforced strict
OriginandHostvalidation across daemon, electron HTTP, and Home Assistant addon endpoints (/v1/control/*,/v1/compile,/v1/telemetry/browser), blocking cross-origin drive-by requests. - Enforced
POSTmethod requirement for state mutations on/v1/compile. - Added 1MB incoming stream caps across all HTTP servers, immediately destroying abusive or runaway request streams (
req.destroy()). - Wrapped URI decoding operations across all route handlers in safe try/catch blocks, returning 400 Bad Request on malformed URI sequences.
- Enforced RFC 1035 domain length checks (max 253 characters) across
/v1/checkand CLI serve endpoints. - Sanitized 500 Internal Server Error handlers to prevent leaking stack traces or internal environment variables to clients.
- Enforced strict
- Desktop Application Hardening & Resilience (
@blockingmachine/electron-app):- Enabled Chromium OS-level sandboxing (
sandbox: true) on BrowserWindow instances alongside existingcontextIsolation: trueandnodeIntegration: false. - Installed a strict permission request handler rejecting unnecessary hardware access requests (camera, microphone, geolocation).
- Implemented a persistent native crash boundary (
setupCrashBoundary) capturing uncaught exceptions and unhandled promise rejections to timestamped log files inuserData/crash-logs. - Enforced a 64-subscriber concurrency cap on Server-Sent Events (SSE) connections to prevent file descriptor exhaustion, with automatic idle cleanup on unref'd heartbeat timers.
- Enabled Chromium OS-level sandboxing (
- Continuous Integration & Quality Assurance:
- Added regression test suites in
core,electron-app, andclipackages. - Test suite expanded to 434 passing automated tests (100% pass rate).
- Zero TypeScript compiler diagnostics and zero ESLint errors across all packages.
- Added regression test suites in
Downloads & Assets
| Asset | Description |
|---|---|
Blockingmachine-1.0.0-rc.5-arm64.dmg |
macOS Apple Silicon installer (Drag to Applications) |
Blockingmachine-darwin-arm64-1.0.0-rc.5.zip |
macOS Apple Silicon standalone zipped app |
blockingmachine-core-1.0.0-rc.5.tgz |
Core library NPM package |
blockingmachine-cli-1.0.0-rc.5.tgz |
CLI executable NPM package |
blockingmachine-chrome-mv3-v1.0.0.zip |
Chrome Web Store Manifest V3 browser extension bundle |
blockingmachine-firefox-mv3-v1.0.0.zip |
Firefox Add-ons Manifest V3 browser extension bundle |
SHA256SUMS.txt |
SHA-256 verification checksums |
Verification Checksums (SHA-256)
e24edeed66a633ef0d76d837686e3ed905ba9cc422c10490532ceb1ad2dd2226 Blockingmachine-1.0.0-rc.5-arm64.dmg
52aed82895e0e277cdb52908609417f8972c5d8cd32530c15fa7b515ff54a1bb Blockingmachine-darwin-arm64-1.0.0-rc.5.zip
8c38142fb6322e967fdb960184a4b8a474c414ecf7cdea46b25cdcba80b4e529 blockingmachine-core-1.0.0-rc.5.tgz
9ed980dd563f62a2e5376a23dedff48c52b588a6d5faf359d5e9a5306a2ef9de blockingmachine-cli-1.0.0-rc.5.tgz
052543d515e70bd490ca9a15020ce75598e2f050d5e586404c11642fd2d3fcb1 blockingmachine-chrome-mv3-v1.0.0.zip
b67db0e90e1002215adf17fc463a7016a0041cf55da8af4443bd318a73b8769f blockingmachine-firefox-mv3-v1.0.0.zip
v1.0.0-rc.4
Blockingmachine v1.0.0-rc.4
Fourth release candidate for Blockingmachine 1.0 featuring full resolution of all 31 GitHub Dependabot alerts, comprehensive dependency upgrades to the latest stable ecosystems, automated CodeQL security analysis, formal security policy disclosure (SECURITY.md), daemon test suite isolation and scoping hardening, and multi-store browser extension packaging.
Highlights since RC 3
- 100% Dependabot & Security Alert Remediation:
- Eliminated all 31 GitHub Dependabot alerts across all repository dependencies and workspaces.
- Fully mitigated upstream vulnerabilities across
fast-uri,qs,uuid,@xmldom/xmldom,js-yaml, andextract-zip(via drop-in@electron-internal/extract-zip). - GitHub security dashboard and repository status currently verify 0 open Dependabot alerts.
- Ecosystem & Dependency Modernization:
- Upgraded core runtime compatibility targeting Node.js
>=24.0.0. - Upgraded
@types/nodeto^26.6.2. - Upgraded ESLint to
^10.11.0and@typescript-eslintto^8.70.1. - Upgraded Jest testing framework to
^30.5.2. - Modernized CLI and telemetry utilities: Chalk
^6.0.0, Cosmiconfig^10.0.0, Dotenv^18.0.0, and Mongoose^9.10.2.
- Upgraded core runtime compatibility targeting Node.js
- CodeQL Security Analysis & Formal Security Policy:
- Integrated automated CodeQL analysis workflow (
.github/workflows/codeql.yml) scanning JavaScript and TypeScript codebases on push and pull request tomain. - Established formal
SECURITY.mddefining supported versions, vulnerability disclosure procedures, and response commitments.
- Integrated automated CodeQL analysis workflow (
- Daemon Reliability & IPC Scoping Fixes:
- Isolated background test suites for
BlockingmachineDaemonto prevent port contention and ensure reliable CI execution. - Hardened IPC event framing and local variable scoping (
timestampStr) across telemetry streams to eliminate cross-session state bleed.
- Isolated background test suites for
- Browser Extension Multi-Store Packaging:
- Packaged production-ready Manifest V3 bundles for Chrome Web Store (
blockingmachine-chrome-mv3-v1.0.0.zip) and Mozilla Firefox Add-ons (blockingmachine-firefox-mv3-v1.0.0.zip). - Added automated compliance validation script (
scripts/verify-mv3-compliance.mjs) ensuring zero declarativeNetRequest rule conflicts and strict permissions scoping.
- Packaged production-ready Manifest V3 bundles for Chrome Web Store (
- Continuous Integration & Quality Assurance:
- All CI workflows (CI, HACS Validation, CodeQL Analysis) passing cleanly with 100% test pass rate across 352 test cases.
- Zero TypeScript compiler diagnostics and zero ESLint errors across all packages.
Downloads & Assets
| Asset | Description |
|---|---|
Blockingmachine-1.0.0-rc.4-arm64.dmg |
macOS Apple Silicon installer (Drag to Applications) |
Blockingmachine-darwin-arm64-1.0.0-rc.4.zip |
macOS Apple Silicon standalone zipped app |
blockingmachine-core-1.0.0-rc.4.tgz |
Core library NPM package |
blockingmachine-cli-1.0.0-rc.4.tgz |
CLI executable NPM package |
blockingmachine-chrome-mv3-v1.0.0.zip |
Chrome Web Store Manifest V3 browser extension bundle |
blockingmachine-firefox-mv3-v1.0.0.zip |
Firefox Add-ons Manifest V3 browser extension bundle |
SHA256SUMS.txt |
SHA-256 verification checksums |
Verification Checksums (SHA-256)
5f19fdbe9eb4886b4dbc1000328807cfe29c25df9d275afcc0ea6c6314f2ce75 Blockingmachine-1.0.0-rc.4-arm64.dmg
52816238cbde1308a159bd3a8436e492f63b322fa84bd65c73af566c4f578159 Blockingmachine-darwin-arm64-1.0.0-rc.4.zip
e444a98974961584d38ff9231489c57663bb6cd81e710ea26d753523c5a64d82 blockingmachine-core-1.0.0-rc.4.tgz
4c7d1e7299413d59ae9c34d9d630c08fcc56453f352661b73566d8bf63039702 blockingmachine-cli-1.0.0-rc.4.tgz
c9593dc5d5ed34309b79d4398e0632bade09e43d9b513ab25bdd7626e48c102d blockingmachine-chrome-mv3-v1.0.0.zip
0c2ec94a6674b556ab5d72e94125f35cd14ae4764009cd83fe98f027d6a24db5 blockingmachine-firefox-mv3-v1.0.0.zip
v1.0.0-rc.3
Blockingmachine v1.0.0-rc.3
Third release candidate for Blockingmachine 1.0 featuring hardened AI classification, entropy recalibration, badfilter neutralization, desktop UI polish, and macOS application installers.
Highlights since RC 2
- AI Architecture & Type Centralization:
- Centralized all AI verdicts, targets, threat categories, heuristic models, and metadata schemas into
packages/core/src/ai/types.ts. - Guaranteed complete cross-package type contracts across
@blockingmachine/core,@blockingmachine/cli, and@blockingmachine/electron-app.
- Centralized all AI verdicts, targets, threat categories, heuristic models, and metadata schemas into
- Entropy Engine Recalibration:
- Fine-tuned Shannon entropy scoring thresholds to prevent false positives on legitimate hashes, UUIDs, and CDN identifiers while effectively detecting DGA domains.
- Added base64 chunk pattern detection, subdomain segment analysis, and bigram transition anomaly scoring.
- Rule Synthesizer & Badfilter Neutralization:
- Added automatic
$badfilterrule generation to neutralize conflicting or erroneous upstream filter rules without modifying external feeds. - Added procedural scriptlet defuser synthesis (
##+js(...),#%#//scriptlet(...)) and domain-anchored network blocking with strict separator enforcement.
- Added automatic
- Reputation & Threat Intelligence:
- Dynamic threat categorization across Adware, Trackers, Cryptominers, Telemetry, Phishing, and Evasive Adblock Walls.
- Enriched CNAME cloaking analysis with recursive depth limits and strict loop detection.
- Desktop Application & UI Polish:
- AI Radar and Domain Inspector: added live risk level indicators, confidence gauges, and direct one-click rule synthesis.
- Deploy Hub & Dashboard: enhanced status indicators for connected sinkholes (Pi-hole, AdGuard Home, Local Feed Server).
- Resolved all TypeScript and ESLint type warnings across Electron views and IPC bridges.
- Guarded macOS login item registration in unpackaged development to prevent OS platform errors.
- Testing & Continuous Integration:
- All 352 unit and integration tests passing with 100% pass rate.
- Calibrated benchmark inference headroom to ensure stable CI test execution across virtualized runners.
- Clean build output across all monorepo workspaces with 0 lint warnings.
Downloads & Assets
| Asset | Description |
|---|---|
Blockingmachine-1.0.0-rc.3-arm64.dmg |
macOS Apple Silicon installer (Drag to Applications) |
Blockingmachine-darwin-arm64-1.0.0-rc.3.zip |
macOS Apple Silicon standalone zipped app |
blockingmachine-core-1.0.0-rc.3.tgz |
Core library NPM package |
blockingmachine-cli-1.0.0-rc.3.tgz |
CLI executable NPM package |
SHA256SUMS.txt |
SHA-256 verification checksums |
Verification Checksums (SHA-256)
899d5ec8411ebcfee6854d60babf462a5d922af534339fc23b85f91def64797e Blockingmachine-1.0.0-rc.3-arm64.dmg
2f1053568d4eca3bfb507dcb7a41acc1d3c27157276549ab2f999d2a39a32d28 Blockingmachine-darwin-arm64-1.0.0-rc.3.zip
add08a6ca9f51075fa8076b1f695ec17affc3748dd66ad686d946f7feab8cd8c blockingmachine-core-1.0.0-rc.3.tgz
9756637dfd362a7a1b69e3bc6af8dec38102a5b8f8f4a892078a3725c096a047 blockingmachine-cli-1.0.0-rc.3.tgz
v1.0.0-rc.2
Blockingmachine v1.0.0-rc.2
Second release candidate for Blockingmachine 1.0.
Highlights since RC 1
• Full Rule Precedence & DNS Exception Suppression:
- Eliminated the DNS exception leakage bug across
/etc/hosts,dnsmasq, andunboundwhere allowlisted domains were still sinkholed by active blocks. - Implemented
resolveDnsPrecedenceto automatically prune blocked domains when covered by allowlists (@@||domain^). - Added child subdomain exception unblocking directives (
server=/sub.domain/#in dnsmasq,local-zone: ... transparentin unbound). - Standardized
$importantoverride mechanics:$importantexceptions override$importantblocks, and$importantblocks override normal exceptions.
• Canonical Section Ordering & Deterministic Output: - Adblock filter exports (
adguard,abp) now enforce canonical section ordering:- Header / Metadata
- Whitelist & Exception Rules (
@@,#@#,#@%#,#@$#) - Procedural Scriptlet Defusers (
##+js,#%#,#$#) - Cosmetic & Element Hiding Rules (
##,#?#,$$) - Network Blocking Rules (
||,|,/regex/,0.0.0.0)
- Deterministic alphabetical sorting within sections ensures reproducible builds and zero arbitrary diff churn.
• Scriptlet Classification & Deduplication Engine: - Procedural scriptlets (
##+js(...),#%#//scriptlet(...),#$#...) now classify as"scriptlet"instead of generic"cosmetic". - In
RuleDeduplicator, scriptlet arguments are stored separately inparts.scriptlet, preserving multiple distinct scriptlets on the same domain.
• Unified Domain Evaluation Engine: - Shared
evaluateDomainRulesacross Core, CLI (test,serve/v1/check), and Electron IPC (inspect-domain).
• Multi-Vendor Anti-Adblock & Scriptlet Defusers: - Expanded radar and procedural scriptlets against Admiral, Google Funding Choices / Privacy Messaging, BlockThrough / PageFair, AdInPlay, Ezoic, NitroPay, and Snigel Ad Recovery.
• Security & Memory Hardening: - SSRF Protection: Added IPv4-mapped IPv6 hex decoding (
::ffff:x:y) to close loopback/metadata SSRF bypass vectors; verified IPv6 documentation and private subnets. - Memory Bounds: Added 25MB response streaming cap to Electron sinkhole HTTP client (
sinkholeFetch.ts) to prevent remote OOM crashes. - Database Parity: Fixed DNS exception suppression across hosts, dnsmasq, unbound, named, privoxy, and shadowrocket in
packages/database/scripts/update.js.
• Complete Test Coverage: - Expanded test suite to 357 passing tests (100% pass rate) with 0 lint warnings and clean monorepo builds.
Feedback
Please report issues against this RC before 1.0.0 final.
v1.0.0-rc.1
Blockingmachine v1.0.0-rc.1
First release candidate for Blockingmachine 1.0.
Downloads
- macOS Apple Silicon:
Blockingmachine-1.0.0-rc.1-mac-arm64.dmg
Highlights since the last beta
- Defense Suite module naming and first-run setup refresh
- Deploy Hub: clearer AdGuard Home vs Home Assistant handling, custom Direct API port, optional allow-untrusted local TLS
- Separate AdGuard Direct URL for AI Radar / query-log scout (no more silent zero-query results when HA mode is selected)
- Mini-AI quality pass: confidence display fixed (0–100%), fewer infrastructure false positives, stronger bar for Malware/Phishing while keeping real ad/tracker detection
- Local network feed server for sinkhole subscription URLs
Install notes (macOS)
This RC build is signed with Developer ID but not notarized yet. On first open, macOS Gatekeeper may block it. Use Right-click → Open (or allow it in System Settings → Privacy & Security), then launch again.
Keep Blockingmachine running when using the LAN feed URL so AdGuard Home / Pi-hole can fetch updates.
Checksums
SHA-256 (Blockingmachine-1.0.0-rc.1-mac-arm64.dmg)
f2057d26a7babd643eebe74178374957070d29c231d194ca2d94ad1277125ccf
Feedback
Please report issues against this RC before 1.0.0 final.
v1.0.0-beta.7
v1.0.0-beta.3
BlockingMachine v1.0.0-beta.3
🚀 Features
- Initial beta release of BlockingMachine
- Support for multiple filter list formats:
- AdGuard
- ABP (AdBlock Plus)
- Hosts
- Dnsmasq
- Unbound
- Domains
- Plain text
- Built-in collection of 18 curated filter lists including:
- AdGuard DNS Filter
- uBlock Origin Filters
- EasyList
- OISD Blocklist Small
- Peter Lowe's List
and more
💡 Core Features
- Rule deduplication and optimization
- Custom rules support
- Multiple export formats
- Dark/Light/System theme support
- Progress tracking for rule processing
- Configurable save locations
🔧 Technical Details
- Built with Electron and React (Typescript)
- Native arm64 support for Apple Silicon (Windows and Linux coming soon)
- Efficient rule processing engine
- Automated updates support (not sure the stability)
- Secure IPC communication
🐛 Known Issues
- First-time startup may take longer due to initial filter list downloads
- Some filter lists may occasionally be unavailable
📝 Notes
- This is a beta release intended for testing
- Feedback and bug reports are welcome
🔍 System Requirements
- macOS 11.0 or later
- 300mb free drive space