PageSourceSearch

https://sonomos.ai/assets/Uninstall-7_ndklIp.js

js sonomos.ai collected 2026-09-24 13:33:05 UTC 13,450 bytes, 1 lines download raw bytes

1import{j as e}from"./app-C5yrFt3l.js";import{C as r,U as n,T as t,a as s,X as o}from"./prose-BHwwadCR.js";function l(){return e.jsxs(e.Fragment,{children:[e.jsx(r,{eyebrow:"Reference",title:"Uninstall Locke",lead:e.jsx(e.Fragment,{children:"Removing Locke is not only deleting a program. Locke arms things on your machine — a trusted certificate authority, a proxy setting, browser registrations — and an uninstall that left those behind would leave a live interception capability on a computer with nothing on it to explain why. This is what each platform reverses, in what order, and what it deliberately does not touch."})}),e.jsx("h2",{id:"windows",children:"Windows"}),e.jsxs("p",{children:[e.jsx(n,{children:"Settings › Apps › Locke › Uninstall"}),", or"," ",e.jsx(n,{children:"Start menu › Locke › Uninstall"}),". One “are you sure”, then one question about the data Locke kept on this computer, then it runs."]}),e.jsx("p",{children:"Before any program file is deleted, Locke runs its own cleanup script. The order is chosen so that no intermediate state strands you:"}),e.jsx(t,{caption:"What the Windows uninstall reverses, in order",head:["#","Step","Why here"],rows:[["1","Stops every Locke process","A running Locke re-arms what has just been disarmed — and it holds open the very files the uninstaller is about to delete. Processes are matched by their image path under the install directory, never by name."],["2","Removes the capture-lock firewall rules, if any were installed","Those rules are machine state and they outlive the app. Left behind with no proxy to funnel into, your browser simply stops reaching the internet, permanently, with nothing left on the machine naming a cause. They come down before the proxy does."],["3","Turns the system proxy off, and clears HTTP_PROXY / HTTPS_PROXY","Before the certificate, not after. Untrusting first leaves your traffic bent at a proxy you can no longer trust: every HTTPS request fails validation, with no working browser to look up why."],["4","Untrusts the certificate authority, and clears NODE_EXTRA_CA_CERTS","Safe now — nothing is being intercepted any more."],["5","Removes the browser native-messaging registrations","All eight per-user registry roots, so no browser is left resolving a manifest that names a path inside a directory that no longer exists."],["6","Removes the scheduled logon task, if one was ever registered","Nothing in the desktop app registers one, but the command-line tool can."],["7","Deletes the certificate authority's private key — always, no prompt","A key that can mint a trusted certificate for any hostname must not outlive the trust. It is a capability, not data, so this is never a question."],["8","Deletes your detection history, audit log and profile — only if you said yes","Last, because the steps above read files out of there: the proxy backup, the installed registration script, the certificate itself."],["9","Verifies, and reports what it found","See below."]]}),e.jsx(s,{kind:"note",title:"Every step is conditional on the thing being ours",children:e.jsxs("p",{children:["An uninstall on a machine that never armed capture changes nothing, and says so. The system proxy is only touched while it still points at Locke’s own address, and is then ",e.jsx("em",{children:"restored"})," from the backup taken before Locke first changed it — including “there was no setting at all” — rather than zeroed."," ",e.jsx("code",{children:"HTTP_PROXY"})," and ",e.jsx("code",{children:"HTTPS_PROXY"})," are cleared only while they still name Locke’s proxy, so your own or your employer’s value is never eaten."]})}),e.jsxs("p",{children:["If everything armed is gone, the uninstall just completes. If something is left, you get a dialog and an offer to open a report that carries the exact command for each item. If a Sonomos root certificate is"," ",e.jsx("em",{children:"still trusted"}),", that gets its own dialog saying so first and in those words — because that leftover is a live interception capability rather than one item on a list."]}),e.jsx(s,{kind:"tip",title:"An update is not a removal",children:e.jsxs("p",{children:["Installing a new version does not run any of this, so an update does not untrust the certificate and disarm capture on every release. A silent uninstall (",e.jsx("code",{children:"/S"}),", and any IT deployment) also"," ",e.jsx("strong",{children:"keeps"})," your data: an unattended run must only ever do less than an attended one."]})}),e.jsx("h2",{id:"linux",children:"Linux"}),e.jsxs("p",{children:["Removal is a script installed ",e.jsx("em",{children:"into"})," the app’s own directory, not left behind in your downloads folder — deleting the download must never orphan a trusted root certificate."]}
1),e.jsx(t,{caption:"The Linux uninstall commands",head:["Command","What it removes"],rows:[[e.jsx("code",{children:"~/.local/share/sonomos/app/locke/uninstall.sh"},"a"),"This install."],[e.jsx("code",{children:"~/.local/share/sonomos/app/locke/uninstall.sh --remove-shared"},"b"),"This install, plus this computer's shared state."],[e.jsx("code",{children:"~/.local/share/sonomos/app/locke/uninstall.sh --remove-shared --force-shared"},"c"),"The same, even while a Sonomos process is running."]]}),e.jsxs("p",{children:["That is the default location; if you set ",e.jsx("code",{children:"SONOMOS_PREFIX"}),", the script lives under that instead. A removal is"," ",e.jsx("strong",{children:"two decisions"}),", and they are asked separately:"]}),e.jsx(t,{caption:"The two halves of a Linux removal, and how each is consented to",head:["Half","What it covers","How you agree to it"],rows:[["This install","The install directory, the models, the locke symlink, systemd user units, runtime and cache state, and the certificate authority's private keys.",e.jsxs(e.Fragment,{children:["The ordinary ",e.jsx("code",{children:"Proceed with removal? [y/N]"}),"."]})],["This computer's shared state",e.jsxs(e.Fragment,{children:["The ",e.jsx("code",{children:":443"})," redirect, the root-owned helper at"," ",e.jsx("code",{children:"/usr/local/libexec/sonomos-redirect"}),", the"," ",e.jsx("code",{children:"/etc/sudoers.d/sonomos-redirect"})," rule, the"," ",e.jsx("code",{children:"sonomos-proxy"})," and ",e.jsx("code",{children:"sonomos-bypass"})," groups, certificate trust in the system store and in every browser profile, and the ",e.jsx("code",{children:"NODE_EXTRA_CA_CERTS"})," block in your shell startup file."]}),e.jsxs(e.Fragment,{children:["A ",e.jsx("strong",{children:"second"}),", separate question that defaults to"," ",e.jsx("strong",{children:"No"})," and lists every item by path — or"," ",e.jsx("code",{children:"--remove-shared"})," given up front."]})]]}),e.jsxs("p",{children:["The split is not caution for its own sake. There is one redirect helper, one sudo rule, one pair of groups and one system trust store per machine, and every Locke on that machine uses the same ones — a second install, a developer checkout, a throwaway copy under"," ",e.jsx("code",{children:"/tmp"}),". Removing one install must not silently stop another from screening anything. What follows from that:"]}),e.jsxs("ul",{children:[e.jsxs("li",{children:[e.jsx("strong",{children:"Declining the machine-wide half never blocks the uninstall."})," The install is removed either way."]}),e.jsxs("li",{children:[e.jsx("strong",{children:"Declining means no password prompt at all."})," Only that half needs root, so a run that touches nothing outside the install never asks for one."]}),e.jsxs("li",{children:[e.jsx("strong",{children:"A running Locke refuses the machine-wide half"})," rather than warning about it. The failure it would otherwise cause is silent: the other install keeps running with its redirect disarmed, which does not crash anything, it just stops screening. Stop it and re-run, or override the refusal with ",e.jsx("code",{children:"--force-shared"})," — which grants no consent of its own; you still answer the question."]}),e.jsxs("li",{children:[e.jsx("strong",{children:"The redirect comes down before the helper and the sudo rule that undo it."})," The reverse order points every outbound"," ",e.jsx("code",{children:":443"})," connection at a dead port with nothing left authorised to undo it."]}),e.jsxs("li",{children:[e.jsx("strong",{children:"The certificate authority’s private key is removed unconditionally"}),", in both halves, with no prompt — the same rule as Windows, for the same reason."]}),e.jsxs("li",{children:[e.jsx("strong",{children:"Anything left behind on purpose is printed with the exact command for it."})," The last step deletes the install directory, and ",e.jsx("code",{children:"uninstall.sh"})," along with it, so “re-run the uninstaller” would be advice with nothing left to run."]})]}),e.jsx(s,{kind:"note",title:"Non-interactive runs do strictly less",children:e.jsxs("p",{children:["There is no ",e.jsx("code",{children:"--yes"}),". Every prompt reads end-of-input as its default, and every default is No — so"," ",e.jsx("code",{children:"--remove-shared"})," on a run with nobody to answer removes nothing at all, because the ordinary ",e.jsx("em",{children:"Proceed?"})," question is still unanswered."]})}),e.jsx("h2",{id:"data",children:"Your detection history"}),e.jsxs("p",{children:["On both platforms the default is ",e.jsx("strong",{children:"keep"}),", and the paths are printed either way — as removed, or as kept with the exact command to remove each one later."]}),e.jsx("p",{children:"A privacy product that silently keeps your detection history after you uninstall it is a bad look. One that silently deletes it may destroy evidence you wanted. So it is asked, plainly, once. And it defaults to keeping because there is no export path today: offering to delete would be offering an irreversible action with no alternative."}),e.jsxs("p",{children:["On Linux that covers the metrics database under"," ",e.jsx("code",{children:"~/.local/share/Sonomos/"}),", its backups, and the token seed beside it. The seed follows the ",e.jsx("em",{children:"same"})," answer as the database and never a separate one: deleting it re-randomises every future stand-in value, so past and future reports stop lining up with each other."]}
1),e.jsx("h2",{id:"manual",children:"Running the cleanup by hand"}),e.jsx("p",{children:"On Windows the same cleanup is runnable directly, which is what to do if the uninstaller could not run it — a blocked script policy, say:"}),e.jsx("p",{children:e.jsx("code",{children:'& "$env:LOCALAPPDATA\\Programs\\locke\\resources\\windows\\uninstall-cleanup.ps1" -InstallDir "$env:LOCALAPPDATA\\Programs\\locke"'})}),e.jsxs("p",{children:["That reverses everything armed and ",e.jsx("strong",{children:"keeps"})," your data, matching the default the uninstaller itself offers. Add"," ",e.jsx("code",{children:"-DeleteData"})," only if you also want the detection history, audit log and profile gone — there is no dialog on this path, so the flag is the whole of the decision."]}),e.jsxs("p",{children:["On Linux the uninstaller runs the same way with or without its install record, and never refuses for the lack of one. Without a record it"," ",e.jsx("em",{children:"discovers"})," what is actually on the machine instead — the helper and the sudo rule at their one fixed path each, the two groups, trust anchors in all three distribution directories, every browser certificate store, and the default install location — and prints which mode found what. Refusing to run for want of a record is exactly how an orphaned certificate authority goes unremoved."]}),e.jsx("h2",{id:"leftovers",children:"What it cannot remove for you"}),e.jsx("p",{children:"Neither uninstaller elevates, because neither installer did. Anything machine-wide is therefore detected, named, and left alone with the elevated command printed beside it rather than silently skipped:"}),e.jsxs("ul",{children:[e.jsxs("li",{children:[e.jsx("strong",{children:"Windows:"})," Sonomos anchors in the machine-wide certificate store (nothing Locke ships writes there, but a developer with an elevated shell can have), the WinHTTP machine proxy, and machine-scope ",e.jsx("code",{children:"HTTP_PROXY"})," / ",e.jsx("code",{children:"HTTPS_PROXY"})," /"," ",e.jsx("code",{children:"NODE_EXTRA_CA_CERTS"}),". If a capture-lock firewall rule survives, the report names the exact"," ",e.jsx("code",{children:"Remove-NetFirewallRule"})," command — a machine that cannot reach the internet is never reported as a clean uninstall."]}),e.jsxs("li",{children:[e.jsx("strong",{children:"Both platforms: the browser extension."})," It came from a browser store, so it is yours to remove, from your browser’s own extensions page."]}),e.jsxs("li",{children:[e.jsx("strong",{children:"Linux:"})," another install, or a developer checkout, is reported plainly and left alone. Deleting a second install’s certificate authority out from under it is the same class of mistake this script exists to prevent, so it is told to you rather than counted as a failure."]})]}),e.jsxs("p",{children:["If something is still bothering you after a removal,"," ",e.jsx(o,{to:"/support/locke/support/",children:"Support & feedback"})," has the fastest route to a human, and"," ",e.jsx(o,{to:"/support/locke/troubleshooting/",children:"Troubleshooting"})," covers the usual suspects."]})]})}export{l as Uninstall};

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.