sdwdate not blocking internet when initializing


I was reading things related to sdwdate and came across this part of the documentation which says that networking is blocked until sdwdate initialize and randomize time:

So I tested it and in all cases I was able to reach internet even if sdwdate was still trying to reach all the onion endpoints. I do see the following line in the live logs after it successfully reach the 3 onion addresses:

/usr/bin/whonix-workstation-firewall - OK: Loading Whonix firewall...
/usr/bin/whonix-workstation-firewall - OK: Skipping firewall mode detection since already set to 'full'.
/usr/bin/whonix-workstation-firewall - OK: (Full torified network access allowed.)
/usr/bin/whonix-workstation-firewall - OK: Qubes DNS firewall rules ok.
/usr/bin/whonix-workstation-firewall - OK: Whonix firewall loaded.

But I’m able to do anything like using curl to both normal and onion domains or use the Tor Browser before it even finishes in the workstation.

I’m running Qubes 4.2 with Whonix 17 (fresh install from ISO).

Is this a bug or is this supposed to happens on Qubes-Whonix? I can’t find any mention of this not being enabled specifically on Qubes-Whonix.

Wondering where the documentation on how to enable this feature has gone or why it vanished.

That wiki page failed to point out:

  • The feature is for testers-only.
  • Omits documentation how to enable this feature by default.

I briefly pointed that out in the wiki.

Unspecific to Qubes-Whonix vs Non-Qubes-Whonix.

Future TODO: document to enable this