Chapters & navigation

START HERE

Project overview

Release status, supported boundaries and the complete documentation map for SysWarden.

v4.10.0Updated October 1, 20267 min read
On this page

SysWarden is a Linux host firewall orchestrator and out-of-band security-log analysis toolkit. It combines authoritative nftables policy with bounded firewalld or UFW compatibility, local threat-intelligence lists, WAAP log analysis, host telemetry, authenticated HA exchange and a native local terminal dashboard.

v4.10.0 is the latest IVV-validated, stable public release. Its signed tag and twelve public assets were published and independently verified on 1 October 2026. The protected IVV run accepted all twelve required checks. The historical v4.03.3 report and v4.04.3 operational runbooks retain their exact original scope.

The historical public v4.03.2 release closed LOT 2, including the LOT 2A Linux-only surface reduction, LOT 2B three-package reproducibility and LOT 2S bounded security remediation. The historical v4.03.3 release carried that qualified boundary forward and addressed defects observed after publication. The historical v4.04.0 change set and the corrections required during protected release qualification were first published in the historical v4.04.2 release. The historical v4.04.3 release published the qualified firewall convergence, WireGuard recovery, telemetry classification, uninstall safety and package provenance corrections.

Documentation map#

  • Release assurance: IVV and IVVQ explains intermediate Patch, Minor and Major validation, full Upgrade qualification, evidence continuity and the implementation status.

  • Build and install from source covers the version-specific candidate builder, pinned tools, exact source revision, local package verification, installation and snapshot recovery. Source builds remain separate from qualified public releases.

  • Deployment tutorial covers the supported package matrix, exact release inventory, verified installation, optional image staging, configuration, upgrade safety and command inventory.

  • Historical v4.02.8 to v4.03.2 migration provides the Debian 13 first-hop runbook, rollback and interrupted-package recovery boundary.

  • Version-specific runbook: v4.03.2 to v4.03.3 migration covers the four dynamic nftables sets, legacy interval handling, the recorded Ubuntu 26.04 installation gate and the restricted rollback boundary.

  • RHEL 9+ image extensions distinguishes the available offline staging extension from the planned runtime-only package integration profile.

  • BunkerWeb integration defines the authenticated HA dialect, ownership model and cluster migration fence.

  • Bounded use cases provides laboratory procedures with explicit prerequisites, limits, verification and rollback.

  • Source repository is the authoritative implementation.

  • Public Releases are the only supported source for release packages.

The two migration runbooks are retained for their exact historical versions. They are not a general upgrade path to current source. In particular, the historical updater step targeting v4.03.3 now refuses the newer latest release by design. Preserve that version guard.

v4.10.0 follows IVV (Integration, Verification and Validation). Upgrade generations such as the version-specific v5.00.0 require full IVVQ, including Qualification. The tested product is 8c3405758a9b369924f466d12652e99d3a84dc56; the signed publication commit is 3cc06b62d42b5adadc46fc9a252fece5adf670c1. The assurance record explains the protected acceptance, bounded owner publication recovery, signatures and evidence limits.

Supported release boundary#

The v4.10.0 public release contains four Linux package variants:

Package familyArchitecturesPackage count
DEBamd641
RPM standardx86_641
RPM package-owned RHELPOx86_641
APKx86_641

The complete public Release contains exactly twelve assets: the four packages, a detached DEB signature, two checksum inventories, one release archive, one SPDX SBOM, one Plumber report, one signed update manifest and its detached Ed25519 signature. No package, updater or qualification route exists outside this AMD64/x86_64 Linux matrix.

Historical v4.04.3 product boundary#

The following details retain the historical v4.04.3 baseline. They do not describe the complete v4.10.0 feature set or expand its validation scope.

  • The release validates and commits one authoritative nftables ruleset. If exactly one supported firewalld or UFW frontend is already active, it may reconcile only bounded SysWarden-owned trusted-source and HA-port rules.
  • Native nftables host and CIDR mutations use complete interval-set start and exclusive end markers. Unterminated starts are repaired before replacement; ambiguous states and intervals containing internal boundaries fail closed. An exclusive end marker left alone after timed-start expiry is treated as functionally absent, and a later re-ban must install and verify a complete pair. Release evidence still requires the isolated real-kernel nftables gate.
  • core.firewall_backend = "keep" is the default and changes no firewall service state. It refuses policy mutation while an iptables-services or netfilter-persistent service is active or enabled. nftables validates an operator-prepared active and enabled nftables service without performing a transition and refuses any active or enabled firewalld, UFW, iptables-services or netfilter-persistent frontend.
  • Operational policy mutation requires an active, unambiguous supported service manager. Package hooks running with no service-manager runtime defer install and reload instead of invoking host firewall or kernel tools.
  • iptables remains parseable for configuration compatibility but is not an operational policy mode in the historical v4.04.3. Operational firewall policy mutation paths reject this choice before changing persistent policy inputs or kernel firewall state. Automatic service migration is outside the qualified release contract.
  • WireGuard requires the explicit nftables backend. The bounded firewalld and UFW compatibility path does not open the WireGuard UDP port or forwarding rules. Active firewalld and UFW target-host execution remains outside the qualified evidence.
  • The optional RHEL-compatible image staging extension is additive and is not called by normal package, update or reload workflows. It installs one local, checksum-bound RPM into a fresh unmounted image root without package scripts or triggers, then defers runtime convergence to a marker-guarded first boot. Offline staging is not runtime-readiness evidence.
  • A separate runtime-only Go and package-owned host-integration extension is a planned design boundary only. It has no shipped source or operator procedure in the historical v4.04.3.
  • WAAP analyzes configured logs after the application writes them. SysWarden is not an inline HTTP proxy and does not sanitize request traffic.
  • The supported multi-origin OSINT path discards syntactically valid private, 6to4 and other non-public or special-use entries before consensus and logs only a bounded origin-and-count warning. Malformed entries, insufficient post-filter sources and custom feed validation failures remain fatal.
  • In the historical v4.04.3, Geo deny and strict-allow selections come from one deterministic IPverse country-ip-blocks CC0-1.0 RIR allocation snapshot embedded in the CLI. Only the official signed SysWarden release chain authenticates the reviewed snapshot bytes. Runtime operation performs no country-data download and requires no per-country files. Allocation country is not physical or current operational geolocation. See the version-specific GeoIP boundary for exact provenance, valid empty families and strict-allow behavior.
  • syswarden tui runs inside the invoking local console or SSH terminal. It opens no listening socket.
  • The current product contains no browser terminal, HTTPS or WebSocket terminal bridge, remote PTY route, token-management command or network terminal service. SysWarden owns no listener or generated firewall permission on TCP
  • The HA API uses TLS 1.3, a bearer token and configurable TCP port 62026 by default. All partner and node-to-node operations remain authenticated.
  • The optional BunkerWeb extension is disabled by default. It must never edit SysWarden files or invoke the local CLI remotely.

HA migration boundary#

Historical static ownership and provenance-aware temporary ownership are separate stores. The authenticated integrator selects a dialect with one fresh GET /ha/status per peer and serialized cycle. Enriched requests are allowed only when both sync_ttl and sync_provenance are present.

Migration is a cluster campaign. The operator supplies one complete member and external-writer inventory, then distributes one verified activation manifest to every node and to the integrator. The capability native_sync_fence_v1 announces schema support only. Live proof comes from the dynamic, challenge-bound native_sync_fence object.

The integrator compares the manifest epoch, membership_sha256 and legacy_writer_inventory_sha256 with live values as opaque, case-sensitive strings. It does not recalculate either digest. Historical cleanup uses the exact observed X-SysWarden-HA-Fence-Condition; HTTP 428, 400 and 412 reject without mutation. A one-hour all-peer absence window is evidence only, never proof of drain.

The historical v4.03.2 freeze required written partner confirmation against this frozen contract and no unexplained partner-attributable static residue.

Release status#

The v4.10.0 release is public, stable, non-draft and non-prerelease. Use its verified tag, twelve-asset inventory and version-specific verification evidence.

No statement in this wiki is a regulatory certification, performance guarantee or support claim for an unlisted distribution or incomplete HA topology.

Wiki publication model#

Wiki changes are reviewed against the same source revision as the release. A page is not evidence by itself. After publication, local links, external HTTPS links and current-surface terminology must be revalidated against the exact published content.

Search pages and sections. Nothing leaves your browser.

Tab to a result, Enter to open. Escape to close.