Complete SQLite-only Arti integration seams #3

Closed
ober wants to merge 220 commits from feat/tor-everywhere-complete into master
Owner

This PR implements the Jerboa-sqlite-only Tor foundation described in Tor-everywhere.md and records the remaining qualification gates.

Implemented:

  • Maintained Arti fork changes are stored under patches/arti/ and applied reproducibly into target/arti-patched; vendor/arti remains a pinned read-only source mirror.
  • Jerboa SQLite directory, ordinary state, encrypted key, replay, and PoW storage seams use authenticated transactions and generation fencing.
  • Arti external typed state-directory primitives now support restart round trips and competing-writer rejection. Full tor-hsservice injection remains disabled until its concrete filesystem handles are refactored.
  • Rust supervisor launch provisions independent storage, application, and wrapping-key credentials over inherited descriptors 3, 4, and 5, with executable/socket validation and child cleanup.
  • Jerboa transport contexts are bound to their client; close, stream-close, and onion-key operations fail closed when backend callbacks are absent or fail.
  • Typed WASM directory preconditions and consensus/authcert/microdescriptor differential fixtures are covered.
  • RustCrypto TLS fixtures, dependency/artifact checks, SBOM generation, IPC, storage, sandbox, leak, and Jerboa module behavior tests are included.

Verification:

  • make test
  • make binary
  • ./tools/apply-arti-patches --check
  • make check-deps
  • make check-artifacts
  • cargo check --locked --features arti-onion-service
  • ./jtor --version (0.3.0)

Production capabilities remain disabled pending controlled Tor/HTTPS interoperability, full tor-hsservice SQLite state injection, broader typed parser construction, bridge/PT qualification, separately authorized sibling application integrations, platform confinement evidence, and independent security review. The ignored canary requires operator-provided JTOR_CANARY_BINARY and JTOR_CANARY_TARGET.

This PR implements the Jerboa-sqlite-only Tor foundation described in `Tor-everywhere.md` and records the remaining qualification gates. Implemented: - Maintained Arti fork changes are stored under `patches/arti/` and applied reproducibly into `target/arti-patched`; `vendor/arti` remains a pinned read-only source mirror. - Jerboa SQLite directory, ordinary state, encrypted key, replay, and PoW storage seams use authenticated transactions and generation fencing. - Arti external typed state-directory primitives now support restart round trips and competing-writer rejection. Full `tor-hsservice` injection remains disabled until its concrete filesystem handles are refactored. - Rust supervisor launch provisions independent storage, application, and wrapping-key credentials over inherited descriptors 3, 4, and 5, with executable/socket validation and child cleanup. - Jerboa transport contexts are bound to their client; close, stream-close, and onion-key operations fail closed when backend callbacks are absent or fail. - Typed WASM directory preconditions and consensus/authcert/microdescriptor differential fixtures are covered. - RustCrypto TLS fixtures, dependency/artifact checks, SBOM generation, IPC, storage, sandbox, leak, and Jerboa module behavior tests are included. Verification: - `make test` - `make binary` - `./tools/apply-arti-patches --check` - `make check-deps` - `make check-artifacts` - `cargo check --locked --features arti-onion-service` - `./jtor --version` (`0.3.0`) Production capabilities remain disabled pending controlled Tor/HTTPS interoperability, full `tor-hsservice` SQLite state injection, broader typed parser construction, bridge/PT qualification, separately authorized sibling application integrations, platform confinement evidence, and independent security review. The ignored canary requires operator-provided `JTOR_CANARY_BINARY` and `JTOR_CANARY_TARGET`.
ober closed this pull request 2026-09-24 12:08:16 -04:00

Pull request closed

Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
ober/jerboa-tor!3
No description provided.