File Locations
Anything that runs as root — or that root is pointed at — is installed to a root-owned location, never under your home directory: a location you can write to is a location a compromised agent running as you can write to.
| Path | Contents | Owner |
|---|---|---|
~/.local/bin/sevorix | The daemon and CLI | you |
/usr/local/lib/sevorix/ | Privileged binaries (sevsh, the eBPF daemon), sevsh's recorded SHA-256, and the verification script | root:root |
/usr/local/bin/sevsh | PATH-visible symlink to the root-owned sevsh | root:root |
/usr/local/bin/sevorix-cgroup-helper | Per-session process containment | root:root |
/usr/local/bin/sevorix-agent-launcher | Privileged agent sandbox launcher | root:root |
/usr/local/bin/sevorix-agent-wrap | Puts a launched agent's process tree in a Sevorix cgroup | root:root |
/etc/sudoers.d/sevorix-* | Passwordless invocation of the helpers above, if you accepted them | root:root |
/usr/local/share/ca-certificates/sevorix-mitm.crt | The TLS interception CA, if you enabled TLS inspection and chose to trust it | root:root |
/etc/sysctl.d/60-sevorix-userns.conf | The user-namespace setting, if you accepted it | root:root |
~/.sevorix/policies/ | Policy files (one .json per policy, or an array per file) | you |
~/.sevorix/roles/ | Role files | you |
~/.sevorix/settings.json | Daemon settings — intervention, TLS, inbound scanning, experimental flags | you |
~/.sevorix/logs/ | Session traffic logs | you |
~/.sevorix/models/ | Downloaded classifier models | you |
~/.sevorix/integrations/ | Integration manifests and backups | you |
~/.local/state/sevorix/ | PID files and per-session metadata (including session tokens) | you |
~/.config/sevorix/hub_token | Sevorix Hub authentication token | you |
~/.config/sevorix/policies.json | Legacy single-file policy fallback, still loaded if no directory policies are found | you |
A known inconsistency
sevorix config check still reports on the older ~/.config/sevorix/ paths. The actual load order prioritises ~/.sevorix/; the migration is incomplete and the check's output has not caught up. Trust ~/.sevorix/ as the primary store.