Syn: human approval for privileged actions on remote development machines
Rust
0
70 commits
updated Sep 30, 2026

Approve each remote sudo request from your Mac.
If an agent working on your Ubuntu machine needs sudo to install a package, Syn pauses that request and shows it on your Mac. You can review the machine, account, executable, and arguments, then choose Approve once with Touch ID or your Mac login password, or choose Deny. Syn also works for commands you start yourself: it gates eligible invocations by one configured account after normal sudo policy, without trying to tell a human from an agent.
Play the 20-second video · Download the 1080p MP4
The video uses fictional machine and command details to illustrate an approval.
sudo.ws 1.9.x. A Raspberry Pi 5 is the tested example, not a requirement.sudo. The Mac must also reach the remote machine directly on TCP port 41781 for approvals; an SSH proxy alone is insufficient. SSH must permit forced root public-key commands for Syn's restricted maintenance key./usr/bin/sudo -n /usr/bin/true. It makes no administrative change. Review the request on your Mac and choose Approve once; the command should exit successfully. A nested agent sandbox may block sudo before Syn runs, so use a host terminal for this check.The Mac ZIP already contains the matching remote source and helper; there is no separate Ubuntu installer to download. If setup fails, keep recovery access and see recovery.
Syn shows the remote machine, source account, executable, arguments, and time remaining. Arguments that may contain a secret are hidden until you choose Reveal. Each approval needs fresh Touch ID or Mac login-password authentication and applies to one invocation.
| Your choice or situation | What happens on the remote machine |
|---|---|
| Approve once | The signed approval lets that invocation proceed once. |
| Deny | A signed denial received by the remote machine stops the invocation without password fallback. If the Mac cannot confirm delivery, check the original remote terminal; it may still offer password fallback after timeout. |
| Press Enter while an interactive request is pending | Syn cancels the request and opens the machine's normal password prompt immediately. |
| No Mac decision within 90 seconds | An interactive terminal may offer the normal password prompt. Unanswered non-interactive sudo fails without a prompt; it can still succeed if approved on the Mac. |
The remote sudo plug-in signs the executable, separate arguments, working directory, identities, and environment digest for the invocation already accepted by sudo policy. Invalid data, replay, and local policy rejection fail closed. During everyday sudo use, the remote account password stays in the remote PAM conversation: Syn does not send it to the Mac, save it, or place it in command arguments.
Syn's setup flow is:
Only the remote machine's public profile returns to the Mac. The target authorization private key stays remote; Mac authorization keys and the client identity stay in Keychain or the Secure Enclave.
The separate maintenance SSH key stays in a private directory under the Mac's ~/Library/Application Support/Syn/Maintenance. The remote entry forces Syn's fixed dispatcher and disables forwarding, user startup hooks and terminal allocation. SSH must permit forced root public-key commands; Syn will not enable unrestricted root login or change your SSH policy. This key authorizes privileged Syn installation, so protect it like an administrator credential.
Setup uses SSH to inspect, transfer, build, install, pair, update, recover, or uninstall Syn. Everyday approvals use a direct mutually authenticated TLS connection, with no SSH tunnel, VPN-provider integration, or Syn cloud relay. The remote agent listens on the server-side address selected during SSH setup, on TCP port 41781, while the Mac reconnects through the hostname you supplied. Reachability can come from a LAN, an existing private network, or another route you control; Syn neither configures a network provider nor opens public ingress.
Approval messages bind both endpoints to the exact compiled release ID and commit. A valid signature from another release is still rejected, and the Mac reports a mismatch as update required rather than attempting approval.
Update is Mac-led and uses SSH again. It preserves the target identity and settings, restores ordinary password sudo before package replacement, installs the Mac's exact remote release, and keeps the previous recovery helper until the updated release passes its fresh final approval.
If setup disconnects or stops after privileged state may exist, retry resumes from the protected operation journal or runs local recovery; it never treats a lost SSH reply as success. Recovery removes Syn's NOPASSWD rule first, restores ordinary password sudo and provider state, and retains protected keys and backups.
To stop using Syn, run sudo /usr/bin/synctl uninstall --restore-local-sudo --apply in a trusted terminal on the remote machine, then verify ordinary password sudo works. Uninstall follows the same safety ordering, revokes Syn's restricted maintenance SSH entry, disables its runtime service, and removes the package. Pairing keys, the recovery helper, and sudo backups remain available for conservative recovery rather than being silently deleted. The Mac app's Remove button only forgets the saved machine and stops its connection; it does not change remote sudo or pairing, so use it after remote uninstall.
To revoke only the Mac's maintenance access while keeping Syn installed, run sudo /var/lib/syn/maintenance/synctl --json maintenance revoke --apply in a trusted administrator session on the remote machine. Revocation removes only Syn's recorded SSH entry; unrelated keys and recovery access remain. A replacement Mac needs a new bootstrap after revocation.
See the hybrid acceptance results, September 9 implementation checkpoint, protocol, threat model, recovery, and the SSH maintenance contract before live use.
crates/syn-protocol: signed wire types, deterministic encoding, and validation.crates/syn-agent: rootless Unix-socket to direct mTLS WebSocket relay.crates/syn-sudo-plugin: classic sudo approval ABI and PAM fallback.crates/synctl: diagnostics and guarded lifecycle operations.macos: native SwiftUI approver and Mac-led setup source.packaging: remote service, PAM, policy, and Debian package assets.docs: security, protocol, recovery, implementation, and validation records.Rust 1.85+, Swift 6/Xcode, clang, and pkg-config are required.
make check
make test
make lint
make macos-app
Human-readable CLI output is the default. --json emits one stable JSON value; diagnostics go to stderr, and security-sensitive changes require root plus explicit --apply. There is no network command-submission API.
Licensed under either Apache-2.0 or MIT, at your option.
Rust
45.2%
Swift
43.7%
Python
8.1%
Shell
3.0%
Syn: human approval for privileged actions on remote development machines
Rust
0
70 commits
updated Sep 30, 2026

Approve each remote sudo request from your Mac.
If an agent working on your Ubuntu machine needs sudo to install a package, Syn pauses that request and shows it on your Mac. You can review the machine, account, executable, and arguments, then choose Approve once with Touch ID or your Mac login password, or choose Deny. Syn also works for commands you start yourself: it gates eligible invocations by one configured account after normal sudo policy, without trying to tell a human from an agent.
Play the 20-second video · Download the 1080p MP4
The video uses fictional machine and command details to illustrate an approval.
sudo.ws 1.9.x. A Raspberry Pi 5 is the tested example, not a requirement.sudo. The Mac must also reach the remote machine directly on TCP port 41781 for approvals; an SSH proxy alone is insufficient. SSH must permit forced root public-key commands for Syn's restricted maintenance key./usr/bin/sudo -n /usr/bin/true. It makes no administrative change. Review the request on your Mac and choose Approve once; the command should exit successfully. A nested agent sandbox may block sudo before Syn runs, so use a host terminal for this check.The Mac ZIP already contains the matching remote source and helper; there is no separate Ubuntu installer to download. If setup fails, keep recovery access and see recovery.
Syn shows the remote machine, source account, executable, arguments, and time remaining. Arguments that may contain a secret are hidden until you choose Reveal. Each approval needs fresh Touch ID or Mac login-password authentication and applies to one invocation.
| Your choice or situation | What happens on the remote machine |
|---|---|
| Approve once | The signed approval lets that invocation proceed once. |
| Deny | A signed denial received by the remote machine stops the invocation without password fallback. If the Mac cannot confirm delivery, check the original remote terminal; it may still offer password fallback after timeout. |
| Press Enter while an interactive request is pending | Syn cancels the request and opens the machine's normal password prompt immediately. |
| No Mac decision within 90 seconds | An interactive terminal may offer the normal password prompt. Unanswered non-interactive sudo fails without a prompt; it can still succeed if approved on the Mac. |
The remote sudo plug-in signs the executable, separate arguments, working directory, identities, and environment digest for the invocation already accepted by sudo policy. Invalid data, replay, and local policy rejection fail closed. During everyday sudo use, the remote account password stays in the remote PAM conversation: Syn does not send it to the Mac, save it, or place it in command arguments.
Syn's setup flow is:
Only the remote machine's public profile returns to the Mac. The target authorization private key stays remote; Mac authorization keys and the client identity stay in Keychain or the Secure Enclave.
The separate maintenance SSH key stays in a private directory under the Mac's ~/Library/Application Support/Syn/Maintenance. The remote entry forces Syn's fixed dispatcher and disables forwarding, user startup hooks and terminal allocation. SSH must permit forced root public-key commands; Syn will not enable unrestricted root login or change your SSH policy. This key authorizes privileged Syn installation, so protect it like an administrator credential.
Setup uses SSH to inspect, transfer, build, install, pair, update, recover, or uninstall Syn. Everyday approvals use a direct mutually authenticated TLS connection, with no SSH tunnel, VPN-provider integration, or Syn cloud relay. The remote agent listens on the server-side address selected during SSH setup, on TCP port 41781, while the Mac reconnects through the hostname you supplied. Reachability can come from a LAN, an existing private network, or another route you control; Syn neither configures a network provider nor opens public ingress.
Approval messages bind both endpoints to the exact compiled release ID and commit. A valid signature from another release is still rejected, and the Mac reports a mismatch as update required rather than attempting approval.
Update is Mac-led and uses SSH again. It preserves the target identity and settings, restores ordinary password sudo before package replacement, installs the Mac's exact remote release, and keeps the previous recovery helper until the updated release passes its fresh final approval.
If setup disconnects or stops after privileged state may exist, retry resumes from the protected operation journal or runs local recovery; it never treats a lost SSH reply as success. Recovery removes Syn's NOPASSWD rule first, restores ordinary password sudo and provider state, and retains protected keys and backups.
To stop using Syn, run sudo /usr/bin/synctl uninstall --restore-local-sudo --apply in a trusted terminal on the remote machine, then verify ordinary password sudo works. Uninstall follows the same safety ordering, revokes Syn's restricted maintenance SSH entry, disables its runtime service, and removes the package. Pairing keys, the recovery helper, and sudo backups remain available for conservative recovery rather than being silently deleted. The Mac app's Remove button only forgets the saved machine and stops its connection; it does not change remote sudo or pairing, so use it after remote uninstall.
To revoke only the Mac's maintenance access while keeping Syn installed, run sudo /var/lib/syn/maintenance/synctl --json maintenance revoke --apply in a trusted administrator session on the remote machine. Revocation removes only Syn's recorded SSH entry; unrelated keys and recovery access remain. A replacement Mac needs a new bootstrap after revocation.
See the hybrid acceptance results, September 9 implementation checkpoint, protocol, threat model, recovery, and the SSH maintenance contract before live use.
crates/syn-protocol: signed wire types, deterministic encoding, and validation.crates/syn-agent: rootless Unix-socket to direct mTLS WebSocket relay.crates/syn-sudo-plugin: classic sudo approval ABI and PAM fallback.crates/synctl: diagnostics and guarded lifecycle operations.macos: native SwiftUI approver and Mac-led setup source.packaging: remote service, PAM, policy, and Debian package assets.docs: security, protocol, recovery, implementation, and validation records.Rust 1.85+, Swift 6/Xcode, clang, and pkg-config are required.
make check
make test
make lint
make macos-app
Human-readable CLI output is the default. --json emits one stable JSON value; diagnostics go to stderr, and security-sensitive changes require root plus explicit --apply. There is no network command-submission API.
Licensed under either Apache-2.0 or MIT, at your option.
Rust
45.2%
Swift
43.7%
Python
8.1%
Shell
3.0%