Skip to content

v0.7.0

Choose a tag to compare

@github-actions github-actions released this 15 Jan 22:08
· 761 commits to main since this release

v0.7.0 - Process Network ACL (PNACL)

This release introduces Process Network ACL (PNACL), a comprehensive per-process network access control system. Define policies to allow, deny, or require approval for network connections based on process identity, hostname patterns, IP addresses, CIDR blocks, ports, and protocols.

Features

Process Network ACL (PNACL)

Control network access at the process level with flexible policy rules:

network_acl:
  default: deny
  processes:
    - name: "claude-code"
      match:
        process_name: "claude-code"
      default: approve
      rules:
        - target: "*.anthropic.com"
          port: 443
          decision: allow
        - target: "10.0.0.0/8"
          decision: deny
      children:
        - name: "curl"
          match:
            process_name: "curl"
          inherit: true
          rules:
            - target: "pypi.org"
              decision: allow

Key Capabilities

Feature Description
Process Matching Match by process name, path, or bundle ID
Target Matching Hostname globs (*.example.com), IP addresses, CIDR blocks
Port & Protocol Filter by port ranges and protocol (TCP/UDP)
Decision Types allow, deny, approve, allow_once_then_approve, audit
Child Inheritance Children inherit parent policies with optional overrides
Learning Mode Observe traffic and generate policies automatically
Rule Persistence Permanent decisions auto-saved to config

Platform Support

Platform Blocking Approval Dialog Backend
Linux ✅ eBPF ✅ zenity/kdialog TC hooks + cgroup socket
macOS ✅ Network Extension ✅ Native SwiftUI NEFilterDataProvider
Windows ⏳ Future ✅ Native WPF WFP Driver (planned)

Native Approval Dialogs

When a network connection requires approval, a native dialog appears:

  • Linux: Uses zenity or kdialog (auto-detected), PowerShell fallback in WSL
  • macOS: Native SwiftUI app with 15-second notification escalation
  • Windows: Native WPF dialog with system shield icon
network_acl:
  approval_ui:
    mode: auto  # auto | enabled | disabled
    timeout: 30s

New CLI Commands

# Network ACL management
agentsh network-acl list [--process <name>] [--json]
agentsh network-acl add <process> <target> [--decision allow|deny|approve]
agentsh network-acl remove <index> --process <name>
agentsh network-acl test <process> <target>
agentsh network-acl watch [--process <name>]
agentsh network-acl learn --process <name> --duration <duration>

# Daemon management (Linux)
agentsh daemon install    # Install systemd user service
agentsh daemon uninstall
agentsh daemon status
agentsh daemon restart

Seccomp Wrapper Default Enabled

The seccomp-bpf wrapper (agentsh-unixwrap) is now enabled by default for shell shim mode, providing syscall-level enforcement without configuration changes.

Package contents by architecture:

  • linux_amd64: Includes agentsh-unixwrap for full seccomp enforcement
  • linux_arm64: Graceful degradation (warning logged, no seccomp enforcement)

Architecture

Linux eBPF Backend

Process → connect() → TC ingress hook → BPF map lookup → cgroup socket hook
                                              ↓
                      Policy Engine ← Connection Holder ← Approval Manager
                                              ↓
                                    allow/deny/prompt → verdict

macOS Network Extension

Process → Network Flow → NEFilterDataProvider → PolicyBridge
                                                     ↓
                          ApprovalManager ← XPC Server ← Go Policy Engine
                                                     ↓
                          [15s timeout] → ApprovalDialog.app escalation

Pull Requests

PR #66: Process Network ACL - Linux Implementation

  • Implement core policy engine with flexible matching (hostname, IP, CIDR, port, protocol)
  • Add Linux eBPF backend with TC hooks and cgroup socket integration
  • Implement approval flow with interactive prompts
  • Add CLI commands for network ACL and daemon management
  • Support UDP connections and connection hold for approval workflow

PR #67: Process Network ACL - macOS Implementation

  • Implement Network Extension integration with NEFilterDataProvider
  • Add Swift components for process identification via code signing
  • Implement PolicyBridge for Swift-Go communication
  • Add XPC server handlers for PNACL requests
  • Support real-time flow interception and verdict blocking

PR #68: Cross-Platform Native Approval Dialogs

  • Add native dialog system for Linux (zenity/kdialog), macOS (osascript), Windows (PowerShell)
  • Auto-detect environment with CI detection and display availability checks
  • WSL hybrid support with PowerShell fallback
  • Configurable approval UI mode and timeout

PR #69: macOS ApprovalDialog App

  • Add standalone SwiftUI app for escalated approval prompts
  • Implement Unix socket client for Go policy server communication
  • Add 15-second escalation logic when notifications are ignored
  • Support URL scheme launching (agentsh-approval://)

PR #70: Windows Native Approval Dialog

  • Add native WPF approval dialog using .NET Framework 4.8.1
  • Custom UI matching macOS functionality
  • Countdown timeout with auto-deny behavior
  • System shield icon extracted from imageres.dll

PR #71: Enable Seccomp Wrapper by Default

  • Enable sandbox.unix_sockets.enabled by default for shell shim mode
  • Add platform guards for non-Linux and CGO-disabled builds
  • Fix RecvFD blocking by adding 10-second timeout
  • Add testcontainers integration tests for seccomp wrapper
  • Include agentsh-unixwrap binary in Linux release packages

Bug Fixes

  • fix(pnacl): Add UDP support and document connection hold limitation
  • fix(pnacl): Parse host:port format in network-acl test command
  • fix(ebpf): Update BPF programs for kernel 6.x compatibility
  • fix(ebpf): Address critical enforcement issues from code review
  • fix(macos): Fix polling startup and error view visibility bugs
  • fix(macos): Respect PNACL fail-closed and clear stale retry state
  • fix(macos): Synchronize fail-closed config and guard stale submissions
  • fix(macos): Fix escalation retry and notification permission race
  • fix(macos): Fix server error handling and approval dialog issues
  • fix(seccomp): Add timeout to RecvFD to prevent blocking exec
  • fix(darwin): Improve macOS compatibility and add darwin-specific tests
  • fix(release): Include agentsh-unixwrap in Linux packages (amd64)

Documentation

  • Added docs/plans/2026-01-13-process-network-acl-design.md - PNACL design document
  • Added docs/plans/2026-01-14-approval-dialog-implementation.md - Approval dialog design
  • Added docs/plans/2026-01-14-windows-minifilter-driver.md - Windows WFP driver design
  • Added docs/macos-fskit-evaluation.md - macOS FSKit evaluation and decision
  • Updated README with PNACL configuration examples
  • Updated platform comparison documentation

Commits

PNACL Core (PR #66)

  • a9f0ff0 feat(pnacl): implement Phase 1 core policy engine
  • 4f858f2 feat(pnacl): implement Phase 2 Linux eBPF backend
  • 8118065 feat(pnacl): implement Phase 3 approval flow integration
  • 25910d3 feat(pnacl): implement CLI commands for network ACL and daemon management
  • b286e42 fix(pnacl): add UDP support and document connection hold limitation
  • 2b1641c fix(pnacl): add use_default timeout fallback and fix spec compliance

PNACL macOS (PR #67)

  • e0984b8 feat(pnacl): implement core policy engine for Process Network ACL
  • b3a1b4f feat(pnacl): add macOS Swift components for process identification
  • 3760b07 feat(pnacl): add macOS approval flow infrastructure (Phase 3)
  • 5353d4c feat(pnacl): implement Network Extension verdict blocking (Phase 4)
  • 959dbfb feat(pnacl): add PNACL handlers to XPC server (Phase 5)

Approval Dialogs (PR #68, #69, #70)

  • 2c4fca8 feat(approval): add cross-platform native dialog for approval prompts
  • 32abbb0 feat(macos): add ApprovalDialog app structure
  • 6d7f83c feat(macos): add ApprovalView SwiftUI component for approval dialog
  • 031c63c feat(macos): add escalation logic to ApprovalManager
  • 8eeb702 feat(windows): add native WPF approval dialog

Seccomp Wrapper (PR #71)

  • 74d29fa feat(seccomp): enable unix socket wrapper by default for shim mode
  • 210a7f4 test(seccomp): add unit tests for setupSeccompWrapper
  • 8ce90ac fix(seccomp): add timeout to RecvFD to prevent blocking exec

eBPF Fixes

  • a6d3fda fix(ebpf): update BPF programs for kernel 6.x compatibility
  • 1697301 fix(ebpf): address critical enforcement issues from code review
  • f776124 fix(ebpf): address additional code review findings

Release Packaging

  • 357380f fix(release): include agentsh-unixwrap in Linux packages
  • caa02a6 fix(release): build unixwrap only for amd64 (arm64 gets graceful degradation)
  • d743adb fix(release): consolidate Linux archives to avoid duplicate naming

Full Changelog: v0.6.0...v0.7.0

🤖 Generated with Claude Code