{"id":35050522,"url":"https://github.com/ind4skylivey/winewarden","last_synced_at":"2025-12-27T09:14:21.213Z","repository":{"id":329856314,"uuid":"1120804362","full_name":"ind4skylivey/winewarden","owner":"ind4skylivey","description":"Play Windows games on Linux without trusting random executables with your system.","archived":false,"fork":false,"pushed_at":"2025-12-22T01:40:45.000Z","size":1393,"stargazers_count":0,"open_issues_count":0,"forks_count":0,"subscribers_count":0,"default_branch":"main","last_synced_at":"2025-12-23T12:57:00.462Z","etag":null,"topics":["gaming","heroic","linux","lutris","proton","rust","sandbox","security","wine","wine-proton"],"latest_commit_sha":null,"homepage":"","language":"Rust","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/ind4skylivey.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2025-12-22T01:05:42.000Z","updated_at":"2025-12-22T01:46:31.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/ind4skylivey/winewarden","commit_stats":null,"previous_names":["ind4skylivey/winewarden"],"tags_count":null,"template":false,"template_full_name":null,"purl":"pkg:github/ind4skylivey/winewarden","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ind4skylivey%2Fwinewarden","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ind4skylivey%2Fwinewarden/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ind4skylivey%2Fwinewarden/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ind4skylivey%2Fwinewarden/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/ind4skylivey","download_url":"https://codeload.github.com/ind4skylivey/winewarden/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ind4skylivey%2Fwinewarden/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":28076736,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","status":"online","status_checked_at":"2025-12-27T02:00:05.897Z","response_time":58,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["gaming","heroic","linux","lutris","proton","rust","sandbox","security","wine","wine-proton"],"created_at":"2025-12-27T09:14:19.507Z","updated_at":"2025-12-27T09:14:21.206Z","avatar_url":"https://github.com/ind4skylivey.png","language":"Rust","funding_links":[],"categories":[],"sub_categories":[],"readme":"# WineWarden\n\n\u003cp align=\"center\"\u003e\n  \u003cimg src=\"assets/ui/banner.png\" alt=\"WineWarden banner\" width=\"100%\" /\u003e\n\u003c/p\u003e\n\n\u003cp align=\"center\"\u003e\n  \u003cimg src=\"https://readme-typing-svg.demolab.com?font=Fira+Code\u0026size=18\u0026pause=1000\u0026color=7CFC00\u0026center=true\u0026vCenter=true\u0026width=900\u0026lines=Play+Windows+games+on+Linux;without+trusting+random+executables+with+your+system.\" alt=\"WineWarden tagline\" /\u003e\n\u003c/p\u003e\n\n\u003cp align=\"center\"\u003e\n  \u003cimg alt=\"CI\" src=\"https://github.com/ind4skylivey/winewarden/actions/workflows/ci.yml/badge.svg\" /\u003e\n  \u003cimg alt=\"Security Audit\" src=\"https://github.com/ind4skylivey/winewarden/actions/workflows/security-audit.yml/badge.svg\" /\u003e\n  \u003cimg alt=\"Release\" src=\"https://github.com/ind4skylivey/winewarden/actions/workflows/release.yml/badge.svg\" /\u003e\n  \u003cimg alt=\"License\" src=\"https://img.shields.io/github/license/ind4skylivey/winewarden\" /\u003e\n  \u003cimg alt=\"Rust\" src=\"https://img.shields.io/badge/rust-1.75%2B-ff7a18\" /\u003e\n  \u003cimg alt=\"Platform\" src=\"https://img.shields.io/badge/platform-linux-4caf50\" /\u003e\n  \u003cimg alt=\"Status\" src=\"https://img.shields.io/badge/status-pre--alpha-ff5252\" /\u003e\n\u003c/p\u003e\n\n\"Play Windows games on Linux without trusting random executables with your system.\"\n\nWineWarden is a calm, always-on protection layer for Wine, Proton, Lutris, and Steam. It is not an antivirus. It does not moralize. It exists so you can play without anxiety.\n\n```\n==[ W I N E W A R D E N ]===================================================\ncalm by design · silent by default · strict by choice\n===========================================================================\n```\n\n## What It Is\n\n- Active Enforcement: Landlock sandboxing and Seccomp syscall interception\n- WineWarden Mode: silent protection with no prompts during gameplay\n- Trust Tiers: clear reassurance signals (Green, Yellow, Red)\n- Sacred Zones: protect the places games should never need\n- Prefix Hygiene: keep prefixes clean and stable over time\n- Network Safety: observe without breaking multiplayer\n- Pirate-Safe Mode: stronger isolation with zero judgment\n- Human Reports: short, calm summaries after each run\n\n## Why It Feels Different\n\n- Secure by default\n- Easy to relax\n- Hard to break accidentally\n- No popups mid-game\n- No shame, no fear\n\n## Active Protection \u0026 Requirements\n\nWineWarden now enforces security actively using kernel-level features:\n- **Landlock LSM:** Creates a strict filesystem sandbox, blocking access to your personal files (`$HOME`, `.ssh`, etc.) unless explicitly allowed.\n- **Seccomp User Notification:** Intercepts network calls (`connect`, `bind`) in real-time, allowing the Policy Engine to decide based on destination IP/Port.\n\n### System Requirements\n- **Linux Kernel 5.11+** (Required for Landlock and Seccomp Notify)\n- **libseccomp** development headers:\n  - Debian/Ubuntu: `sudo apt install libseccomp-dev`\n  - Fedora: `sudo dnf install libseccomp-devel`\n  - Arch: `sudo pacman -S libseccomp`\n\n## Installation\n\n```bash\n# 1. Build from source\ncargo build --release\n\n# 2. Install binaries\ncargo install --path crates/winewarden-cli\ncargo install --path crates/winewarden-daemon\n```\n\n## Quick Start\n\n```bash\n# Initialize config\nwinewarden init\n\n# Run a game quietly (no prompts during gameplay)\nwinewarden run /path/to/game.exe -- -arg1 -arg2\n\n# Run with a provided event log (JSONL of AccessAttempt)\nwinewarden run /path/to/game.exe --event-log tests/fixtures/events.jsonl --no-run\n\n# View a report\nwinewarden report --input ~/.local/share/winewarden/reports/\u003cid\u003e.json\n```\n\n## Interactive Guide (Full Tour)\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cstrong\u003e[+] 1) Install from source\u003c/strong\u003e\u003c/summary\u003e\n\n```bash\ncargo build --release\ncargo install --path crates/winewarden-cli\ncargo install --path crates/winewarden-daemon\n```\n```\nTip: use a dedicated Rust toolchain for reproducible builds.\n```\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cstrong\u003e[+] 2) Initialize config\u003c/strong\u003e\u003c/summary\u003e\n\n```bash\nwinewarden init\n```\n\nConfig file lives at: `~/.config/winewarden/config.toml`\n```\nConfig path: ~/.config/winewarden/config.toml\nReports:     ~/.local/share/winewarden/reports/\n```\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cstrong\u003e[+] 3) Run a game (direct)\u003c/strong\u003e\u003c/summary\u003e\n\n```bash\nwinewarden run /path/to/game.exe -- -arg1 -arg2\n```\n```\nNo prompts during gameplay. Summary after exit.\n```\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cstrong\u003e[+] 4) Run via daemon (background mode)\u003c/strong\u003e\u003c/summary\u003e\n\n```bash\nwinewarden daemon start\nwinewarden run --daemon /path/to/game.exe -- -arg1 -arg2\nwinewarden daemon status\n```\n```\nDaemon uses a local Unix socket with user-only access.\n```\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cstrong\u003e[+] 5) Live monitoring (optional)\u003c/strong\u003e\u003c/summary\u003e\n\n```bash\n# All live monitors\nwinewarden run --live /path/to/game.exe -- -arg1 -arg2\n\n# Or pick specific channels\nwinewarden run --live-fs --live-proc --live-net --poll-ms 250 /path/to/game.exe -- -arg1\n```\n```\nLive monitoring observes only; it does not interrupt gameplay.\n```\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cstrong\u003e[+] 6) Trust tiers (pin or relax)\u003c/strong\u003e\u003c/summary\u003e\n\n```bash\n# Inspect trust tier for an executable\nwinewarden trust get /path/to/game.exe\n\n# Pin a tier\nwinewarden trust set /path/to/game.exe green\n```\n```\nGreen = known safe behavior\nYellow = unknown but non-hostile\nRed = strict isolation\n```\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cstrong\u003e[+] 7) Prefix hygiene\u003c/strong\u003e\u003c/summary\u003e\n\n```bash\nwinewarden prefix scan /path/to/prefix\nwinewarden prefix snapshot /path/to/prefix\n```\n```\nPrefix hygiene keeps the ecosystem stable over time.\n```\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cstrong\u003e[+] 8) Reports (human + JSON)\u003c/strong\u003e\u003c/summary\u003e\n\n```bash\nwinewarden report --input ~/.local/share/winewarden/reports/\u003cid\u003e.json\nwinewarden report --input ~/.local/share/winewarden/reports/\u003cid\u003e.json --json\n```\n```\nHuman summaries by default. Structured JSON on demand.\n```\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cstrong\u003e[+] 9) Integration snippets (real paths)\u003c/strong\u003e\u003c/summary\u003e\n\n```bash\n# Steam (Launch Options):\nwinewarden run -- %command%\n\n# Steam (example Windows game path):\n~/.steam/steam/steamapps/common/SomeGame/SomeGame.exe\n\n# Proton prefix (example, for reference only):\n~/.steam/steam/steamapps/compatdata/123456/pfx/drive_c/\n\n# Lutris (example prefix and game path):\n~/.local/share/lutris/runners/wine/wine-ge-8-26-x86_64\n~/Games/SomeGame/drive_c/Program Files/SomeGame/SomeGame.exe\n\n# Heroic (example default install path):\n~/Games/Heroic/SomeGame/SomeGame.exe\n```\n\nSee:\n- `integrations/steam/README.md`\n- `integrations/lutris/README.md`\n- `integrations/heroic/README.md`\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cstrong\u003e[+] 10) Profiles (default / relaxed / pirate-safe)\u003c/strong\u003e\u003c/summary\u003e\n\nCopy one of the presets into your config location:\n\n```bash\ncp config/default.toml ~/.config/winewarden/config.toml\n# or\ncp config/relaxed.toml ~/.config/winewarden/config.toml\n# or\ncp config/pirate-safe.toml ~/.config/winewarden/config.toml\n```\n\u003c/details\u003e\n\n## Flow Maps (Mini Diagrams)\n\n```\nExecution Flow\n-------------\nwinewarden run\n   |\n   v\n[Runner] --\u003e [Monitor] --\u003e [Policy Engine] --\u003e [Reporting]\n   |             |                |\n   v             v                v\nPrefix Manager  Live Watch      Trust Tiers\n```\n\n```\nDecision Flow\n-------------\nAccess Attempt\n   |\n   v\nSacred Zone? ---\u003e yes ---\u003e Deny / Redirect / Virtualize\n   |\n   no\n   |\n   v\nInside Prefix? ---\u003e no ---\u003e Deny\n   |\n   yes\n   |\n   v\nAllow + Log\n```\n\n## Daemon Mode\n\n```bash\n# Start the background daemon\nwinewarden daemon start\n\n# Run a game through the daemon\nwinewarden run --daemon /path/to/game.exe -- -arg1 -arg2\n\n# Check daemon health\nwinewarden daemon ping\n```\n\n## Architecture (Separation of Concerns)\n\n- Policy Engine: decisions only\n- Monitor: observation without interruption\n- Runner: safe command construction\n- Prefix Manager: hygiene, snapshots, quarantine\n- Reporting: human summaries and JSON\n- WineWarden Daemon: background scheduling\n\n```\n   [Runner] → [Monitor] → [Policy Engine] → [Reporting]\n        ↘        ↘              ↘              ↘\n     [Prefix Manager]        [Trust Tiers]   [Human Reports]\n```\n\n## Configuration\n\nConfiguration is TOML and readable by design. See:\n\n- `config/default.toml`\n- `config/relaxed.toml`\n- `config/pirate-safe.toml`\n\nVariables supported:\n\n- `${HOME}`\n- `${DATA_DIR}`\n- `${CONFIG_DIR}`\n\n## Reports (Human First)\n\nExamples of the tone you should expect:\n\n- \"This game tried to access files outside its sandbox.\"\n- \"That access was denied.\"\n- \"Your system remains intact.\"\n\n## Documentation\n\n- [docs/vision.md](docs/vision.md)\n- [docs/threat-model.md](docs/threat-model.md)\n- [docs/winewarden-mode.md](docs/winewarden-mode.md)\n- [docs/trust-tiers.md](docs/trust-tiers.md)\n- [docs/sacred-zones.md](docs/sacred-zones.md)\n- [docs/prefix-hygiene.md](docs/prefix-hygiene.md)\n- [docs/networking.md](docs/networking.md)\n- [docs/pirate-safe-mode.md](docs/pirate-safe-mode.md)\n- [docs/reports.md](docs/reports.md)\n- [docs/configuration.md](docs/configuration.md)\n- [docs/architecture.md](docs/architecture.md)\n- [docs/glossary.md](docs/glossary.md)\n\n## Status\n\nThe foundation is solid. Active enforcement hooks (Landlock and Seccomp) are implemented and integrated into the monitor layer, providing real protection without changing the calm user experience.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Find4skylivey%2Fwinewarden","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Find4skylivey%2Fwinewarden","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Find4skylivey%2Fwinewarden/lists"}