v0.7.0
v0.7.0 - Process Network ACL (PNACL)
This release introduces Process Network ACL (PNACL), a comprehensive per-process network access control system. Define policies to allow, deny, or require approval for network connections based on process identity, hostname patterns, IP addresses, CIDR blocks, ports, and protocols.
Features
Process Network ACL (PNACL)
Control network access at the process level with flexible policy rules:
network_acl:
default: deny
processes:
- name: "claude-code"
match:
process_name: "claude-code"
default: approve
rules:
- target: "*.anthropic.com"
port: 443
decision: allow
- target: "10.0.0.0/8"
decision: deny
children:
- name: "curl"
match:
process_name: "curl"
inherit: true
rules:
- target: "pypi.org"
decision: allowKey Capabilities
| Feature | Description |
|---|---|
| Process Matching | Match by process name, path, or bundle ID |
| Target Matching | Hostname globs (*.example.com), IP addresses, CIDR blocks |
| Port & Protocol | Filter by port ranges and protocol (TCP/UDP) |
| Decision Types | allow, deny, approve, allow_once_then_approve, audit |
| Child Inheritance | Children inherit parent policies with optional overrides |
| Learning Mode | Observe traffic and generate policies automatically |
| Rule Persistence | Permanent decisions auto-saved to config |
Platform Support
| Platform | Blocking | Approval Dialog | Backend |
|---|---|---|---|
| Linux | ✅ eBPF | ✅ zenity/kdialog | TC hooks + cgroup socket |
| macOS | ✅ Network Extension | ✅ Native SwiftUI | NEFilterDataProvider |
| Windows | ⏳ Future | ✅ Native WPF | WFP Driver (planned) |
Native Approval Dialogs
When a network connection requires approval, a native dialog appears:
- Linux: Uses zenity or kdialog (auto-detected), PowerShell fallback in WSL
- macOS: Native SwiftUI app with 15-second notification escalation
- Windows: Native WPF dialog with system shield icon
network_acl:
approval_ui:
mode: auto # auto | enabled | disabled
timeout: 30sNew CLI Commands
# Network ACL management
agentsh network-acl list [--process <name>] [--json]
agentsh network-acl add <process> <target> [--decision allow|deny|approve]
agentsh network-acl remove <index> --process <name>
agentsh network-acl test <process> <target>
agentsh network-acl watch [--process <name>]
agentsh network-acl learn --process <name> --duration <duration>
# Daemon management (Linux)
agentsh daemon install # Install systemd user service
agentsh daemon uninstall
agentsh daemon status
agentsh daemon restartSeccomp Wrapper Default Enabled
The seccomp-bpf wrapper (agentsh-unixwrap) is now enabled by default for shell shim mode, providing syscall-level enforcement without configuration changes.
Package contents by architecture:
- linux_amd64: Includes
agentsh-unixwrapfor full seccomp enforcement - linux_arm64: Graceful degradation (warning logged, no seccomp enforcement)
Architecture
Linux eBPF Backend
Process → connect() → TC ingress hook → BPF map lookup → cgroup socket hook
↓
Policy Engine ← Connection Holder ← Approval Manager
↓
allow/deny/prompt → verdict
macOS Network Extension
Process → Network Flow → NEFilterDataProvider → PolicyBridge
↓
ApprovalManager ← XPC Server ← Go Policy Engine
↓
[15s timeout] → ApprovalDialog.app escalation
Pull Requests
PR #66: Process Network ACL - Linux Implementation
- Implement core policy engine with flexible matching (hostname, IP, CIDR, port, protocol)
- Add Linux eBPF backend with TC hooks and cgroup socket integration
- Implement approval flow with interactive prompts
- Add CLI commands for network ACL and daemon management
- Support UDP connections and connection hold for approval workflow
PR #67: Process Network ACL - macOS Implementation
- Implement Network Extension integration with NEFilterDataProvider
- Add Swift components for process identification via code signing
- Implement PolicyBridge for Swift-Go communication
- Add XPC server handlers for PNACL requests
- Support real-time flow interception and verdict blocking
PR #68: Cross-Platform Native Approval Dialogs
- Add native dialog system for Linux (zenity/kdialog), macOS (osascript), Windows (PowerShell)
- Auto-detect environment with CI detection and display availability checks
- WSL hybrid support with PowerShell fallback
- Configurable approval UI mode and timeout
PR #69: macOS ApprovalDialog App
- Add standalone SwiftUI app for escalated approval prompts
- Implement Unix socket client for Go policy server communication
- Add 15-second escalation logic when notifications are ignored
- Support URL scheme launching (
agentsh-approval://)
PR #70: Windows Native Approval Dialog
- Add native WPF approval dialog using .NET Framework 4.8.1
- Custom UI matching macOS functionality
- Countdown timeout with auto-deny behavior
- System shield icon extracted from imageres.dll
PR #71: Enable Seccomp Wrapper by Default
- Enable
sandbox.unix_sockets.enabledby default for shell shim mode - Add platform guards for non-Linux and CGO-disabled builds
- Fix RecvFD blocking by adding 10-second timeout
- Add testcontainers integration tests for seccomp wrapper
- Include
agentsh-unixwrapbinary in Linux release packages
Bug Fixes
- fix(pnacl): Add UDP support and document connection hold limitation
- fix(pnacl): Parse host:port format in network-acl test command
- fix(ebpf): Update BPF programs for kernel 6.x compatibility
- fix(ebpf): Address critical enforcement issues from code review
- fix(macos): Fix polling startup and error view visibility bugs
- fix(macos): Respect PNACL fail-closed and clear stale retry state
- fix(macos): Synchronize fail-closed config and guard stale submissions
- fix(macos): Fix escalation retry and notification permission race
- fix(macos): Fix server error handling and approval dialog issues
- fix(seccomp): Add timeout to RecvFD to prevent blocking exec
- fix(darwin): Improve macOS compatibility and add darwin-specific tests
- fix(release): Include agentsh-unixwrap in Linux packages (amd64)
Documentation
- Added
docs/plans/2026-01-13-process-network-acl-design.md- PNACL design document - Added
docs/plans/2026-01-14-approval-dialog-implementation.md- Approval dialog design - Added
docs/plans/2026-01-14-windows-minifilter-driver.md- Windows WFP driver design - Added
docs/macos-fskit-evaluation.md- macOS FSKit evaluation and decision - Updated README with PNACL configuration examples
- Updated platform comparison documentation
Commits
PNACL Core (PR #66)
a9f0ff0feat(pnacl): implement Phase 1 core policy engine4f858f2feat(pnacl): implement Phase 2 Linux eBPF backend8118065feat(pnacl): implement Phase 3 approval flow integration25910d3feat(pnacl): implement CLI commands for network ACL and daemon managementb286e42fix(pnacl): add UDP support and document connection hold limitation2b1641cfix(pnacl): add use_default timeout fallback and fix spec compliance
PNACL macOS (PR #67)
e0984b8feat(pnacl): implement core policy engine for Process Network ACLb3a1b4ffeat(pnacl): add macOS Swift components for process identification3760b07feat(pnacl): add macOS approval flow infrastructure (Phase 3)5353d4cfeat(pnacl): implement Network Extension verdict blocking (Phase 4)959dbfbfeat(pnacl): add PNACL handlers to XPC server (Phase 5)
Approval Dialogs (PR #68, #69, #70)
2c4fca8feat(approval): add cross-platform native dialog for approval prompts32abbb0feat(macos): add ApprovalDialog app structure6d7f83cfeat(macos): add ApprovalView SwiftUI component for approval dialog031c63cfeat(macos): add escalation logic to ApprovalManager8eeb702feat(windows): add native WPF approval dialog
Seccomp Wrapper (PR #71)
74d29fafeat(seccomp): enable unix socket wrapper by default for shim mode210a7f4test(seccomp): add unit tests for setupSeccompWrapper8ce90acfix(seccomp): add timeout to RecvFD to prevent blocking exec
eBPF Fixes
a6d3fdafix(ebpf): update BPF programs for kernel 6.x compatibility1697301fix(ebpf): address critical enforcement issues from code reviewf776124fix(ebpf): address additional code review findings
Release Packaging
357380ffix(release): include agentsh-unixwrap in Linux packagescaa02a6fix(release): build unixwrap only for amd64 (arm64 gets graceful degradation)d743adbfix(release): consolidate Linux archives to avoid duplicate naming
Full Changelog: v0.6.0...v0.7.0
🤖 Generated with Claude Code