Tier 3 of a protest-hardening review. The BLE mesh is already properly fenced off from network reachability and needs nothing here; every gap is on the internet side, or in how someone gets a build they can trust. Say when Tor is blocked. The bootstrap poll loop simply ended at its 75-second deadline, leaving isStarting true with no further state, so a network that blocks Tor was indistinguishable from a slow one and the UI said "starting tor…" indefinitely. TorManager now exposes bootstrapDidStall and posts .TorBootstrapDidStall, and the app reports that mesh messaging still works while internet delivery is paused. It is cleared on each new start or restart, so a later attempt can report again. Let relays be added by hand. The four built-in relays are well-known clearnet hostnames, which is four names for a censor to block and no recourse short of a new build. NostrRelaySettings persists up to eight additional relays, normalized, .onion accepted, with a settings editor. They join the same target set as the built-ins and are subject to the same activation policy. Removal reconciles against the previous set: the teardown path iterates the current targets, so without that a removed relay's socket and queued sends would linger — covered by a test that fails without it. The merged list is cached rather than recomputed, because allowedRelayList consults it once per candidate URL and would otherwise read UserDefaults inside that loop. Stop stranding people who denied location. The activation gate required location permission or a mutual favorite, but teleporting into a geohash requires neither, so someone with no permission and no favorites could sit in a channel that never connected while Tor and the relays stayed suppressed and nothing said why. Being in a location channel is now a third arm of the gate, in both the activation service and the relay manager's copy of the policy, and leaving the channel closes it again. Stop burning the Tor timeout when Tor is off. GeoRelayDirectory awaited Tor readiness unconditionally, but with the preference off TorManager has been shut down, so every refresh spent the full bootstrap deadline and the directory froze on its cached copy. It now keys on the preference, not on live readiness: Tor wanted but unavailable must still skip the fetch rather than fall back to clearnet. Say what turning Tor off costs. The toggle's copy described it as hiding your IP "for location channels", understating both scope and consequence. It now names private messages too, and while the toggle is off the settings screen states that every relay can see the device IP. Make builds verifiable. There was no release verification of any kind: no signatures, no checksums, no documented procedure. Post-takedown that is the acute gap, because mirrors appear and people install whatever they can find during a shutdown. source-manifest.yml publishes a per-tag SHA-256 manifest with a provenance attestation, self-checking before it publishes, and docs/VERIFYING-A-BUILD.md explains how to verify source and states plainly that compiled builds from anywhere but the App Store cannot be verified. It also records the gaps honestly: no published signing key, no reproducible build, no non-GitHub mirror. docs/TOR-INTEGRATION.md was substantially stale — it documented a torrc, SOCKSPort and ControlPort that the in-process Arti client does not use, and claimed there are no user-visible settings — so it is rewritten, including the deferred gap below. Deferred: no Tor bridges or pluggable transports. arti-client is built without pt-client or bridge-client and bootstraps from stock config, so in a country that blocks Tor outright there is still no circumvention path — only a clear report that there isn't. Closing it needs the Rust features, bridge config through the FFI, and an xcframework rebuild under the pinned toolchain with a provenance update, which is its own change. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
4.7 KiB
Tor integration
Overview
Internet traffic — Nostr relay sockets and the geo-relay directory fetch — is routed through Tor by default, fail-closed: when Tor is wanted but not ready, requests queue rather than falling back to clearnet.
Tor is provided by Arti, in-process, vendored as a Swift package under localPackages/Arti wrapping a Rust static-library xcframework. There is no tor binary, no torrc, and no control port. A SOCKS5 listener on 127.0.0.1:39050 is the only interface.
Key pieces
TorManager— owns the Arti client and its data directory under Application Support, exposes the SOCKS port, and providesawaitReady().torEnforcedis compile-time: true unlessBITCHAT_DEV_ALLOW_CLEARNETis defined. It is not set anywhere inConfigs/or the project file, so release builds enforce.isStarting,bootstrapProgress, andbootstrapSummarydescribe an attempt in flight.bootstrapDidStallbecomes true when an attempt spends its whole 75-second deadline without completing, and posts.TorBootstrapDidStall. This is the state a network that blocks Tor produces, and it is deliberately distinct fromisStarting: without it the UI says "starting tor…" indefinitely. It is cleared on each new start or restart.
TorURLSession— a sharedURLSessionwith the SOCKS proxy configured when proxying is on, and an unproxied session when it is off.setProxyMode(useTor:)is the switch, driven byNetworkActivationService.NetworkActivationService— decides whether Tor may run at all. Tor starts when the activation policy permits it and the Tor preference is on.persistedTorPreference(in:)is anonisolatedread of that preference for callers off the main actor.
Both network call sites go through TorURLSession: NostrRelayManager (relay websockets) and GeoRelayDirectory (directory CSV refresh). There is no other outbound network in the app or the share extension.
The Tor preference is user-visible
The earlier version of this document said there are no user-visible settings. There is one: a tor routing toggle in settings, persisted under networkActivationService.userTorEnabled, defaulting to on.
Turning it off is a real change in exposure, not a performance tweak. Every fail-closed guard is conditioned on the preference, so with it off:
- relay websockets connect directly, and every relay operator sees the device IP — including relays carrying private messages;
- the geo-relay directory fetch also goes direct.
The settings UI states this while the toggle is off.
GeoRelayDirectory keys its Tor wait on the preference, not on live readiness, and this distinction is load-bearing. With Tor off, waiting for a client that has been shut down would spend the full bootstrap timeout on every refresh and freeze the directory on its cached copy. With Tor on but not ready, the wait must still fail so the fetch is skipped rather than silently leaking the IP.
Relays
Private messages target the built-in relay set plus any relays added by hand (NostrRelaySettings, capped at 8, .onion addresses accepted). The built-in set is four well-known clearnet hostnames, so a filter blocking four names would otherwise end internet-delivered private messages until a new build shipped.
Artifact maintenance
- Binary provenance, rebuild steps, and current hashes:
docs/ARTI-BINARY-PROVENANCE.md, enforced by.github/workflows/arti-provenance.yml. - The xcframework must include iOS device, iOS simulator, and macOS arm64 slices.
- Any refresh reviews the Rust source,
Cargo.lock, generated header, build script, and new hashes together. A binary-only update is not acceptable.
Known gap: no bridges or pluggable transports
arti-client is built with default-features = false and features ["tokio", "rustls"] only — no pt-client, no bridge-client — and arti-bitchat/src/lib.rs bootstraps from stock configuration with no bridge lines and no configurable directory authorities.
So in a country that blocks Tor by blocking the public relays and directory authorities, bootstrap never completes. The app reports that clearly now instead of appearing to start forever, and the BLE mesh is unaffected, but there is no circumvention path: obfs4, snowflake, and meek are all unavailable.
Closing this means enabling the pluggable-transport features, plumbing bridge configuration through the FFI and a settings surface, and rebuilding the xcframework under the pinned toolchain with a provenance-manifest update. That is the single largest remaining gap in censorship resilience for the internet transport.
Dev bypass (local only)
Define the Swift compiler flag BITCHAT_DEV_ALLOW_CLEARNET to allow direct network access without Tor while developing. Never enable it in release builds.