Omahub
← All plugins
O

Albus DPI

by Oğulcan Yetim

Kernel-level deep packet inspection (DPI) evasion engine and DNS-over-HTTPS suite with verified ML-KEM post-quantum key exchange and Omarchy integration.

Security review

Potentially dangerous behavior detected · 58 findings

Deterministic scan — not a security guarantee

High
Risk level
High
Analyzed commit
d4933ba
Scanned
5 minutes ago
  • high persistence …/app/service.rs:742

    Registers scheduled or boot-time system tasks.

    systemctl enable --now albus.service failed".into());
  • high persistence …/app/service.rs:848

    Registers scheduled or boot-time system tasks.

    systemctl disable exited {}", s);
  • high persistence …/app/service.rs:852

    Registers scheduled or boot-time system tasks.

    systemctl disable failed to spawn ({})", e);
  • System package manager operation.

    apt-get install -y clang llvm linux-headers-generic linux-libc-dev
  • System package manager operation.

    apt-get install -y clang llvm linux-headers-generic linux-libc-dev
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo apt-get install -y clang llvm linux-headers-generic linux-libc-dev
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo apt-get install -y clang llvm linux-headers-generic linux-libc-dev
  • medium sudo Panel.qml:796

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo systemctl restart albus")
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo user on a non-system path.
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo user + user path) but the guard is inactive (setgroups
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo invocations per validated uid so one user's
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo user environment with strict format and passwd validation
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo user invocations must not silently promote user settings
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo invocations (not their file).
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo invocations
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo invocation on a user path expects a drop
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo albus service start')\x1b[0m");
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo for accurate capability detection)");
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo albus service start'",
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo albus service install` upgrade path, because
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo albus service status");
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo albus service logs");
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo albus cleanup`.",
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo albus cleanup` and verify /etc/resolv.conf.",
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo iptables -S OUTPUT | grep albus` and /etc/resolv.conf.",
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo iptables -S OUTPUT | grep albus`",
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo albus cleanup` afterwards); say so instead of implying full removal.
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo albus cleanup` if needed, then remove it manually)",
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo albus cleanup) before this listener is stopped.",
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo albus cleanup`).",
  • low obfuscation …/app/config.rs:1311

    Augments a command with octal/hex escape sequences.

    \0name"));
  • low obfuscation …/app/monitor.rs:273

    Augments a command with octal/hex escape sequences.

    \x1bafter-tail-text");
  • low obfuscation …/app/monitor.rs:286

    Augments a command with octal/hex escape sequences.

    \x07text"), "text");
  • low obfuscation …/ebpf/loader.rs:816

    Augments a command with octal/hex escape sequences.

    \x7FELF" {
  • low obfuscation …/dns/server.rs:1095

    Augments a command with octal/hex escape sequences.

    \x1bb")); // ESC
  • low obfuscation …/dns/server.rs:1096

    Augments a command with octal/hex escape sequences.

    \x7fb")); // DEL
  • low obfuscation …/dns/doh.rs:1387

    Augments a command with octal/hex escape sequences.

    \x00junkjunk";
  • low obfuscation …/dns/doh.rs:1439

    Augments a command with octal/hex escape sequences.

    \x00junkjunk"),
  • low obfuscation …/dns/doh.rs:1440

    Augments a command with octal/hex escape sequences.

    \x00junkjunk"),
  • low obfuscation …/dns/doh.rs:1441

    Augments a command with octal/hex escape sequences.

    \x00junkjunk"),
  • low obfuscation …/dns/doh.rs:1442

    Augments a command with octal/hex escape sequences.

    \x00junkjunk"),
  • low obfuscation …/dns/doh.rs:1445

    Augments a command with octal/hex escape sequences.

    \x00junkjunk",
  • Docs external_hosts README.md:19

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/oqullcan/albus.git && cd albus
  • Docs sudo README.md:26

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo albus run --doh-upstream mullvad-base       # foreground with options
  • Docs sudo README.md:27

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo albus config set --doh-upstream cloudflare  # persist + live-reload daemon
  • Docs sudo README.md:28

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo albus cleanup                               # restore DNS + firewall
  • Docs sudo README.md:36

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo albus service install` — install binary, systemd unit, polkit rule; creates the `albus` user and starts the daemon
  • Docs sudo README.md:37

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo albus service uninstall` — stop, remove unit and rule, revert firewall and DNS (binary is kept by design, with a printed notice)
  • Docs sudo README.md:38

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo albus service start` — start the background daemon
  • Docs sudo README.md:39

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo albus service stop` — stop the background daemon
  • Docs sudo README.md:40

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo albus service restart` — restart (crash-safe: rules re-applied on start)
  • Docs sudo README.md:41

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo albus service reload` — SIGHUP, zero-downtime eBPF map reload
  • Docs sudo README.md:42

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo albus service status` — systemd unit state
  • Docs sudo README.md:43

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo albus service logs` — stream the daemon journal
  • Docs sudo README.md:44

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo albus run [--flags]` — run the engine in the foreground with options
  • Docs sudo README.md:45

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo albus config set KEY VALUE` — persist a setting and live-reload the daemon
  • Docs sudo README.md:46

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo albus cleanup` — restore `/etc/resolv.conf` and purge firewall rules

Automated analysis only — not a security guarantee.

AI review did not complete

The automated AI review at commit 726bc90 could not be finished. Treat it as unavailable — the deterministic scan above is still the primary automated check.

AI advisory only — not a security guarantee.

Install
$ omarchy plugin add https://github.com/oqullcan/albus --enable
System #security

albus

DPI bypass and encrypted DNS for Linux: eBPF packet desynchronization plus a local validating DoH resolver.

Evade — fragment TLS ClientHello across packets (eBPF MSS clamp + jitter, raw-socket decoys) so middleboxes can't read SNI. Encrypt — resolve DNS locally over DoH with DNSSEC validation, kill-switch, and leak canary. Enforce — fail-closed firewall rules and a rootless daemon that refuses to run unprivileged.

Requirements

Linux 5.10+, cgroup v2, Rust 1.75+. Source builds need clang + kernel headers (CI installs them); the release binary runs standalone.

Quickstart

git clone https://github.com/oqullcan/albus.git && cd albus
cargo build --release
sudo ./target/release/albus service install    # binary + unit + polkit, starts daemon
albus status --json                            # active check for bars and panels
sudo albus run --doh-upstream mullvad-base       # foreground with options
sudo albus config set --doh-upstream cloudflare  # persist + live-reload daemon
sudo albus cleanup                               # restore DNS + firewall
albus monitor                                    # traffic TUI

Daemon

Privileged commands (root — install, control, configure, clean up):

  • sudo albus service install — install binary, systemd unit, polkit rule; creates the albus user and starts the daemon
  • sudo albus service uninstall — stop, remove unit and rule, revert firewall and DNS (binary is kept by design, with a printed notice)
  • sudo albus service start — start the background daemon
  • sudo albus service stop — stop the background daemon
  • sudo albus service restart — restart (crash-safe: rules re-applied on start)
  • sudo albus service reload — SIGHUP, zero-downtime eBPF map reload
  • sudo albus service status — systemd unit state
  • sudo albus service logs — stream the daemon journal
  • sudo albus run [--flags] — run the engine in the foreground with options
  • sudo albus config set KEY VALUE — persist a setting and live-reload the daemon
  • sudo albus cleanup — restore /etc/resolv.conf and purge firewall rules

Unprivileged commands (inspect only):

  • albus status — kernel capability and privilege summary
  • albus status --json — machine-readable status for bars and panels
  • albus config get — print the active configuration as JSON
  • albus monitor — interactive traffic telemetry TUI

Root runs management; the daemon runs as the dedicated albus user with six ambient capabilities (NET_ADMIN, NET_RAW, BPF, PERFMON, NET_BIND_SERVICE, DAC_OVERRIDE). Uninstall keeps /usr/local/bin/albus by design (it says so — remove it manually if wanted).

Options

Evasion:

  • --mss 88 — initial TCP MSS size that fragments the ClientHello
  • --min-mss 64 — per-connection jitter floor (must stay ≤ mss)
  • --restore-after-bytes 600 — byte threshold before restoring line-rate MSS (≥ 64)
  • --restore-mss 0 — MSS restored afterwards (0 = 1460 auto, else 64–1460)
  • --ports 443 — target ports for sock_ops interception (up to 64, comma-separated)
  • --fake-ttl 8 — TTL stamped on injected fake packets
  • --auto-ttl — heuristic hop-distance TTL instead of the fallback (conservative constant, not measured probing)
  • --min-ttl 3, --max-ttl 12 — clamps for the auto-TTL heuristic
  • --fake-sni — override the rotating high-reputation decoy SNI pool
  • --fake-bad-checksum — corrupt TCP checksums with 0xDEAD to confuse stateful middleboxes

DNS:

  • --doh — spawn the local DoH proxy listener on 127.0.0.1:53 (on by default)
  • --doh-upstream quad9 — presets (quad9, cloudflare, mullvad-*) or an https:// URL (https-only, enforced)
  • --doh-bootstrap-ips — static IPv4 endpoints to resolve custom DoH hosts
  • --dnssec — validate RRSIG chains locally: Bogus → SERVFAIL (never cached), unsigned → served insecure, unsigned delegations without DS → insecure (never Bogus)
  • --pqc — offer hybrid ML-KEM-768 where the upstream negotiates it (transport KEX only, logged per upstream)
  • --block-ipv6 — filter AAAA queries so IPv6 can't bypass inspection unfragmented

Containment:

  • --block-quic — drop outbound UDP 443 to force TLS/TCP fallback
  • --block-stun — drop outbound STUN (UDP 3478, 5349) against WebRTC IP leaks
  • --kill-switch — drop all non-loopback plaintext DNS (UDP/TCP 53, TCP 853)
  • --network-lockdown — fail-closed: drop outbound TCP 80/443 if eBPF fails (off by default)
  • --ram-only — keep runtime state in /run tmpfs only
  • -c, --config PATH — load an explicit config file (must be root-owned, non-symlink when privileged)
  • --cgroup /sys/fs/cgroup — cgroup v2 mount point for BPF attachment
  • --verbose — debug logging

Omarchy panel

Quattro widget (BarWidget.qml, Panel.qml): status, resolver profiles, toggles, live logs (1/2 tabs, Space start/stop, C flush caches, P pause). R (Apply & Restart) writes the root-owned /etc/albus/config.json behind a pkexec prompt and then restarts albus.service; it does not merely reload.

mkdir -p ~/.config/omarchy/plugins/io.github.oqullcan.albus.dev
cp manifest.json BarWidget.qml Panel.qml ~/.config/omarchy/plugins/io.github.oqullcan.albus.dev/

License

GPL-3.0