404PrivacyDocs

Linux installation

The published standalone STATIC binary is for Linux x86_64. It runs as a local proxy without Rose. Linux packet handling requires an additional, privileged eBPF setup; you can get the proxy working first.

1. Stage the binary and profiles

Download static_proxy-linux-x86_64 from the latest release into Downloads. Then run:

mkdir -p "$HOME/404-runtime"
mv "$HOME/Downloads/static_proxy-linux-x86_64" "$HOME/404-runtime/static_proxy"
chmod +x "$HOME/404-runtime/static_proxy"
RELEASE_TAG=v2.6.93
git clone --depth 1 --branch "$RELEASE_TAG" https://github.com/un-nf/404.git "$HOME/404-source"
cp -R "$HOME/404-source/src/STATIC_proxy/profiles" "$HOME/404-runtime/profiles"

The standalone binary release does not include the profiles/ directory. Set RELEASE_TAG to the tag shown on the release you downloaded (the example is the current tagged release) so the profile catalog matches the binary. If $HOME/404-source already exists, use a matching checkout instead of cloning over it.

2. Select a profile and start STATIC

cd "$HOME/404-runtime"
./static_proxy --profiles-path ./profiles --list-profiles
./static_proxy --profiles-path ./profiles --profile firefox-windows

Use chrome-windows for Chromium-family browsers or edge-windows for Edge. Leave STATIC running in this terminal. With these standalone CLI defaults, the listener is 127.0.0.1:8443 and the control endpoint is 127.0.0.1:8445.

3. Trust the local CA

In another terminal:

curl -s http://127.0.0.1:8445/ca/status

Find the generated static-ca.crt path in the response. On Debian or Ubuntu, install that public certificate into the system trust store:

sudo cp /path/to/static-ca.crt /usr/local/share/ca-certificates/static-ca.crt
sudo update-ca-certificates

Other distributions use different trust-store tools. Firefox may also need a separate import into its Authorities store. Keep the private key private and remove the certificate from trust when you retire this installation.

4. Route the browser and verify

Open a normal HTTPS page in that browser. If it does not load, confirm STATIC is still running and the browser uses port 8443. Certificate errors usually mean the browser does not trust the CA generated by this instance. Turn off the browser proxy when STATIC stops.

Optional Linux packet layer

The proxy works without eBPF. For packet-layer changes, build src/ebpf/ttl_editor.o from the source tree and attach it to the interface that actually carries egress traffic. This requires Linux tc, eBPF support, elevated privileges, and a profile map that STATIC can update. A successful tc attach alone does not prove the selected browser profile is active in the packet layer.

Use the current eBPF reference for build, attach, map, and verification details before enabling it. The source Makefile lists its build dependencies.