Troubleshooting
Common problems with a Sevorix install, and what to check for each.
sevorix start refuses to start — most often there is no logged-in account with an active subscription. Run sevorix hub login and check your subscription status.
command not found: sevorix or sevsh — ~/.local/bin is not on your PATH. Add export PATH="$HOME/.local/bin:$PATH" to your shell config.
A policy has no effect. Work through these in order — the first is by far the most common:
- Is the policy in a role? A policy file on disk does nothing until its
idis listed in a role under~/.sevorix/roles/, and that role is the session's active role. See roles. - Is the context right? A
Shellpolicy never fires on network traffic, andNetworkis outbound-only — response bodies needInbound. - Is the command going through
sevsh? Nothing outside asevshsession is observed. - Did the daemon reload? Policy changes on disk need
sevorix session reload(or a restart). - Is a broad
Allowsuperseding it? AnAllowmatch beats everyBlockin the same role.sevorix config checkwarns about match-everything patterns.
Port 3000 already in use — another process, often a local dev server, is holding the default port. Stop it, or start with --port <N>.
Permission denied during the Claude Code integration — the launcher uses a mount namespace to bind sevsh over /bin/bash, which needs sudo. Confirm the installer wrote the agent-launcher sudoers rule, or that your user has sudo rights.
A Yellow Lane action is blocked instead of reviewed — session containment is unavailable, most often because the cgroup helper prompt was declined. Re-run ./install-binary.sh from the release bundle and accept it, or see when the agent cannot be suspended for the intervention.containment setting.
The Advanced enforcement tier never activates — on a release-bundle install it cannot today: Advanced needs the eBPF kernel bytecode, which current bundles do not ship. Beyond that, check /sys/kernel/security/lsm for bpf, and confirm experimental.lsm_blocking: true in ~/.sevorix/settings.json. Both are required. Setting the flag on a kernel without bpf active logs an Enforcement tier downgraded warning and marks the session DEGRADED — the expected outcome on WSL2 and stock cloud kernels, where Advanced is unavailable regardless of settings.
sevorix stop says the daemon is not running, and removes files — that is correct behaviour, not a bug. A PID file outlives a daemon that crashed or was killed, and the OS recycles PIDs, so Sevorix verifies that the process at a recorded PID really is its own binary before signalling it. A stale PID file is reported, cleaned up, and never signalled.