feat: integrate Arti with Jerboa SQLite storage #1

Merged
ober merged 72 commits from feat/tor-everywhere into master 2026-09-23 16:51:28 -04:00
Owner

Implements the Arti fork integration with Jerboa SQLite as the only persistent storage backend.

Highlights:

  • Adds the vendored Arti storage seam and fail-closed Jerboa SQLite store adapter.
  • Adds authenticated, private Unix IPC for the Jerboa SQLite service and supervised storage proxy.
  • Adds authenticated Arti stream IPC with bounded requests, stream quotas, and capability checks.
  • Routes Jerboa transport/client adapters through explicit fail-closed capability callbacks.
  • Adds persistent consensus/authcert/microdesc storage tests, tombstone deletion coverage, and restart checks.
  • Adds dependency/artifact policy audits and capability evidence documentation.
  • Bumps the synchronized project version to 0.2.0.

Verification:

  • make test
  • make check-deps
  • make check-artifacts
  • make binary
  • python3 tests/storage-service.py ./jtor
  • python3 tests/storage-proxy.py
  • python3 tests/engine-ipc.py

Known blocked capability gates remain explicitly disabled in config/capabilities.json: production-reviewed Rust-only TLS, complete Arti Store expiry/recommendation coverage, controlled Tor network canary, onion service/key manager integration, and directory/descriptor parser wiring.

Implements the Arti fork integration with Jerboa SQLite as the only persistent storage backend. Highlights: - Adds the vendored Arti storage seam and fail-closed Jerboa SQLite store adapter. - Adds authenticated, private Unix IPC for the Jerboa SQLite service and supervised storage proxy. - Adds authenticated Arti stream IPC with bounded requests, stream quotas, and capability checks. - Routes Jerboa transport/client adapters through explicit fail-closed capability callbacks. - Adds persistent consensus/authcert/microdesc storage tests, tombstone deletion coverage, and restart checks. - Adds dependency/artifact policy audits and capability evidence documentation. - Bumps the synchronized project version to 0.2.0. Verification: - `make test` - `make check-deps` - `make check-artifacts` - `make binary` - `python3 tests/storage-service.py ./jtor` - `python3 tests/storage-proxy.py` - `python3 tests/engine-ipc.py` Known blocked capability gates remain explicitly disabled in `config/capabilities.json`: production-reviewed Rust-only TLS, complete Arti Store expiry/recommendation coverage, controlled Tor network canary, onion service/key manager integration, and directory/descriptor parser wiring.
ober added 20 commits 2026-09-23 14:23:47 -04:00
ober merged commit dcd7e41668 into master 2026-09-23 16:51:28 -04:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
ober/jerboa-tor!1
No description provided.