404PrivacyDocs

Windows runtime

On Windows, 404 imports a Linux root filesystem into WSL2. The distribution is a deployment environment for STATIC and the Linux packet path. Browser configuration and certificate trust still happen on the Windows host.

Boot sequence

The packaged /etc/wsl.conf sets the default user and automount behavior; it does not start the service. The desktop app normally starts STATIC explicitly after writing the runtime config and preparing packet state. For a manual/fallback start, /opt/404/404-init.sh reads the Windows username from /opt/404/win-user, looks for the config under AppData/Roaming/com.404.app/static/ (then the legacy AppData/Roaming/404/static/ path), mounts the BPF filesystem where needed, attempts traffic-control attachment on live eth* egress interfaces, and starts /opt/404/static.

The binary’s proxy listener is reachable to the configured Windows browser at the local address and port specified by the runtime config. The Windows CLI guide uses 4040 for proxy traffic and 4042 for control status.

Which component owns what

ComponentResponsibility
Windows hostWSL import, browser proxy configuration, trusting the public CA certificate.
Rose distributionLinux filesystem, startup contract, BPF mount, and packet program attachment.
STATICProxy sessions, profile store, outbound fetch, CA key custody, page injection, local control API, and packet profile sync attempt.

An attached eBPF program does not prove that the current profile synced to its map. Inspect Packet boundary for conditions and limitations. The distro source is the authoritative packaging contract.