Rebuild Arti from audited source with enforced provenance

Vendored arti.xcframework rebuilt from source (Rust 1.96.0, normalized
archive metadata for reproducible hashes). New ARTI-BINARY-PROVENANCE.md
records toolchain, rebuild steps, and a SHA256 manifest for every file
in the xcframework. A new CI workflow turns that policy into a gate:
PRs must keep the binary matching the manifest, and binary changes must
ship with source/lockfile/build-script evidence.

Also raises TorManager.awaitReady's default timeout from 25s to 75s to
match the bootstrap monitor deadline - a shorter wait reported "not
ready" while Arti was still legitimately bootstrapping, silently
stranding queued relay work.

Privacy policy, Tor integration doc, and privacy assessment updated to
match the current implementation.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
jack
2026-06-10 16:22:15 +01:00
co-authored by Claude Fable 5
parent 3eb4f2bd72
commit 4093ee6733
14 changed files with 333 additions and 65 deletions
+7 -26
View File
@@ -2,7 +2,7 @@ Tor-by-default integration (scaffold)
Overview
- All network traffic is routed via a local Tor SOCKS5 proxy by default, with fail-closed behavior when Tor isnt ready. There are no user-visible settings.
- This repo now includes a minimal TorManager and TorURLSession to make dropping in an embedded Tor framework straightforward.
- This repo vendors an Arti-backed Swift package under `localPackages/Arti`, including a Rust static-library xcframework linked by SwiftPM.
Key pieces
- TorManager
@@ -12,36 +12,17 @@ Key pieces
- Provides a shared URLSession configured with a SOCKS5 proxy when Tor is enforced/ready.
- NostrRelayManager and GeoRelayDirectory now use this session and await Tor readiness before starting network activity.
Dropin steps
1) Build or obtain a small Tor framework
- Recommended: Tor C (client-only) with static linking and dead-strip.
- Configure Tor with a minimal feature set:
./configure \
--enable-static \
--disable-asciidoc --disable-unittests --disable-manpage \
--disable-zstd --disable-lzma --enable-zlib \
--disable-systemd --disable-ptrace --disable-seccomp
CFLAGS="-Os -fdata-sections -ffunction-sections" \
LDFLAGS="-Wl,-dead_strip"
- Build a tiny OpenSSL/LibreSSL (no engines, strip symbols) or reuse system crypto where permitted on macOS.
Artifact maintenance
- Binary provenance, rebuild steps, and current hashes are documented in `docs/ARTI-BINARY-PROVENANCE.md`.
- The xcframework must include iOS device, iOS simulator, and macOS arm64 slices.
- Any refresh should review the Rust source, `Cargo.lock`, generated header, build script, and new hashes together.
2) Add the framework to Xcode targets
- Drop your xcframework into `Frameworks/`. The project is prewired in `project.yml` to link/embed `Frameworks/tor-nolzma.xcframework` (rename yours to match, or update the path).
- Ensure the binary includes the slices you need (iOS device/simulator and/or macOS). If your xcframework lacks simulator slices, you can still build/run on device or macOS arm64; simulator will fail to link.
- On iOS, it will be embedded and signed automatically.
3) Wire Tor bootstrap in TorManager.startTor()
- Two paths are already implemented:
- If a module named `Tor` is present (iCepa API), it starts `TORThread` directly.
- Otherwise, it attempts a dynamic load (`dlopen`) of a bundled framework binary named `tor-nolzma.framework/tor-nolzma` (or `Tor.framework/Tor`), resolves `tor_run_main`, and launches Tor on a background thread.
- `TorManager` writes a torrc and then probes `127.0.0.1:39050` until ready.
4) Verify networking
Verification
- On app launch, TorManager.startIfNeeded() is called implicitly by awaitReady().
- NostrRelayManager.connect() awaits readiness, then creates WebSocket tasks via TorURLSession.shared.
- GeoRelayDirectory.fetchRemote() awaits readiness, then fetches via TorURLSession.shared.
5) Optional macOS optimization
Optional macOS optimization
- Detect a system Tor binary (e.g., /opt/homebrew/bin/tor) and run it as a subprocess to avoid bundling. Keep the embedded fallback for portability.
torrc template