Skip to content

Troubleshooting ​

Common problems with a Sevorix install, and what to check for each.

sevorix start refuses to start — most often there is no logged-in account with an active subscription. Run sevorix hub login and check your subscription status.

command not found: sevorix or sevsh — ~/.local/bin is not on your PATH. Add export PATH="$HOME/.local/bin:$PATH" to your shell config.

A policy has no effect. Work through these in order — the first is by far the most common:

  1. Is the policy in a role? A policy file on disk does nothing until its id is listed in a role under ~/.sevorix/roles/, and that role is the session's active role. See roles.
  2. Is the context right? A Shell policy never fires on network traffic, and Network is outbound-only — response bodies need Inbound.
  3. Is the command going through sevsh? Nothing outside a sevsh session is observed.
  4. Did the daemon reload? Policy changes on disk need sevorix session reload (or a restart).
  5. Is a broad Allow superseding it? An Allow match beats every Block in the same role. sevorix config check warns about match-everything patterns.

Port 3000 already in use — another process, often a local dev server, is holding the default port. Stop it, or start with --port <N>.

Permission denied during the Claude Code integration — the launcher uses a mount namespace to bind sevsh over /bin/bash, which needs sudo. Confirm the installer wrote the agent-launcher sudoers rule, or that your user has sudo rights.

A Yellow Lane action is blocked instead of reviewed — session containment is unavailable, most often because the cgroup helper prompt was declined. Re-run ./install-binary.sh from the release bundle and accept it, or see when the agent cannot be suspended for the intervention.containment setting.

The Advanced enforcement tier never activates — on a release-bundle install it cannot today: Advanced needs the eBPF kernel bytecode, which current bundles do not ship. Beyond that, check /sys/kernel/security/lsm for bpf, and confirm experimental.lsm_blocking: true in ~/.sevorix/settings.json. Both are required. Setting the flag on a kernel without bpf active logs an Enforcement tier downgraded warning and marks the session DEGRADED — the expected outcome on WSL2 and stock cloud kernels, where Advanced is unavailable regardless of settings.

sevorix stop says the daemon is not running, and removes files — that is correct behaviour, not a bug. A PID file outlives a daemon that crashed or was killed, and the OS recycles PIDs, so Sevorix verifies that the process at a recorded PID really is its own binary before signalling it. A stale PID file is reported, cleaned up, and never signalled.

Runtime containment for autonomous AI agents.