Inbound default-accept is the other Unix inheritance

Root Lock allowlists per-program outbound. Root Lock Firewall is the host-path stateful filter for a closed appliance.

Root Lock Firewall | Prototype


Overview: A listening service on a Linux host accepts inbound connections unless a packet filter refuses them. Root Lock Firewall is that filter on a closed HeartSuite appliance: observe real traffic, approve a finite allowlist, seal it.

Root Lock controls outbound destinations per program, at the kernel, using literal IP addresses. The two products address different layers and are designed to be used together on the appliance image.

In this section


A listener will accept a stranger by default

Inbound default-accept is a different OS assumption from Root Lock’s outbound allowlist. How Root Lock Firewall addresses that hole.

Observe real traffic, approve a list, seal it

Host-shaped stateful filter on a closed appliance: observe real traffic, approve a finite allowlist for this box, then seal it. Root Lock is the OS under the filter.

Where the packet boundary holds

Root Lock Firewall’s packet boundary, residuals, and which tool to put beside it for those gaps.

Walkthrough: observe, approve, seal

From first boot to Firewall Lockdown: observe, approve, seal. The intended Dashboard path on a Root Lock Firewall appliance.