Repository navigation
developer guide
github-actions[bot] edited this page Oct 3, 2026
·
4 revisions
Status: the browser shell is in a PR. Parts marked "(coming in v0.1)" are not on main yet.
Read AGENTS.md first. It holds the rules.
| Path | Holds |
|---|---|
src-tauri/ |
The Rust core: Tauri app, router logic, proxy, window shell. |
src/ui/ |
The bundled pages: toolbar, internal pages, styles, mock data. |
tests/leak/ |
The leak test harness (coming in v0.1). |
scripts/ |
CI and lint helper scripts, wiki publishing. |
docs/wiki/ |
All docs. CI publishes them to the GitHub wiki. |
One OS window holds three kinds of web view. (Coming in v0.1.)
+---------------- window ------------------+
| toolbar (bundled, IPC) |
+------------------------------------------+
| internal (bundled, IPC) eepview://... | shown for internal pages
| tab-<n> (remote, NO IPC) | one per web tab
+------------------------------------------+
tab-<n> --> gatekeeper (127.0.0.1) --> I2P router --> I2P network
Rust core --I2PControl--> router (verify, status, stats)
-
toolbarandinternalload bundled pages and may call Rust commands. -
tab-<n>loads a remote.i2ppage and has no IPC. A hostile site cannot reach a command. - The gatekeeper is a loopback proxy in Rust. It forwards
.i2phosts only. - No
tab-<n>exists before the router passes verification.
Read No-leak architecture and the Browser shell page before you touch networking or web views. The command and event list is in the IPC contract (coming in v0.1).
Requirements: Rust 1.96 (pinned in rust-toolchain.toml), Node.js 22 or later, and the OS libraries for Tauri.
npm ci
npm run tauri dev| Task | Command |
|---|---|
| Rust tests | cargo test --manifest-path src-tauri/Cargo.toml |
| UI tests | npm test |
| UI coverage gate | npm run test:coverage |
| Leak harness | see Leak test (coming in v0.1) |
| Type check | npm run typecheck |
See Coverage for the ratchet.
npm run lint
cargo fmt --manifest-path src-tauri/Cargo.toml --check
cargo clippy --manifest-path src-tauri/Cargo.toml --all-targets --locked -- -D warnings
./scripts/complexity.shInstall the hooks once with lefthook install. They run the fast checks before each commit. CI runs the full set. See CI and quality gates.
- No lint exclusions of any kind.
- Functions have 40 lines or less, 5 parameters or less, nesting 3 or less. Complexity is 10 or less.
- No new HTTP client crates.
- Pin actions by full SHA.
- No clearnet code path without explicit user consent.
- Never use
--no-verifyor--admin.
The full list is in AGENTS.md.
- Start a branch from main.
- Contract: add the command, event or type to the IPC contract and to
src/ui/contract.ts. - Rust: build the command in
src-tauri/src/. Keep pure logic in small modules. Touch no networking or web view code outside the places the architecture test allows. - UI: call the command from
src/ui/. Add the page or control. Check light and dark. - Tests: unit tests for every pure module. Coverage only goes up. Run the architecture and leak tests if you touched networking.
- Wiki: add or update the feature page in
docs/wiki/, link it fromdocs/wiki/README.md, and add a History line with the PR link. - Open the PR with a clear Conventional Commit title, and turn on auto-merge with
gh pr merge <n> --squash --auto. Own the PR until it is merged: fix a red check at once, and resolve review threads while CI runs. Merge main in only when the PR has a conflict (DIRTY). If a check is red on main too, report it and do not change the gate in your PR. See the Workflow section of AGENTS.md. Do not editCHANGELOG.md. The release job generates it from the PR titles.
Generated from docs/wiki in the repository. Edit there, not here.