Skip to content

no leak architecture

github-actions[bot] edited this page Oct 3, 2026 · 6 revisions

No-leak architecture

Status: shipped in #29.

Five independent layers keep the web engine away from the clearnet and from local services. A leak needs all five to fail. The full decision is ADR 0001.

How it works

Layer What it does
L1 gatekeeper eepview's own proxy on loopback. It forwards only .i2p requests, and only to the verified router proxy.
L2 engine proxy Every web tab uses the gatekeeper as its proxy.
L3 request filter A page policy on every response (L3a), and an engine rule list attached before the first load (L3b, macOS and Windows).
L4 navigation guard Only http(s)://*.i2p may load in a tab or open a new one.
L5 WebRTC off WebRTC sends UDP outside the proxy, so it is removed in every frame.

The router console view is not a leak path for eepsites:

View Why it is not a leak path
console (router console) It loads only the detected console origin, http://127.0.0.1:<port>, after an engine rule list that allows only that origin (macOS, Windows). An eepsite can never load in it: an .i2p link opens in a normal tab through L4, and anything else is cancelled. No tab-* webview can reach it, because the tabs keep L1–L5 and loopback stays blocked for them. It has no IPC, WebRTC is off, and no probe runs at start. See Router console and ADR 0001.

The one clearnet action: Report a problem

Path Why it is not a leak
"Open a GitHub issue" on eepview://report It runs only after the user's click. eepview opens no socket: the system browser opens the page, outside eepview and outside I2P. The URL always starts with the fixed prefix https://github.com/tcivie/eepview/issues/new, and its text is the scrubbed preview the user just read. Only the internal webview may call it, and JavaScript gets no opener permission. See Diagnostics and bug reports.

JavaScript is on. The layers sit below JavaScript, so they hold with it on. You can turn it off per site.

How to use / run locally

  • cargo test --workspace in src-tauri runs the architecture test (tests/architecture.rs), which fails if a layer is removed.
  • The leak test runs the real binary against canaries.

Limits

  • No OS-level layer yet (L6, see the roadmap).
  • Linux has no engine rule list yet (L3b); the page policy covers it. The console view has no page policy, so on Linux it relies on its navigation guard and the router's own pages.
  • The L3b rule list allows exactly the hosts of the one host predicate: after the .i2p allow rule it blocks xn-- labels, b32.i2p, short *.b32.i2p names and port 0 again, and allows a b32 name of 52 base32 characters or more. The WebKit regex subset has no |, so each form is a rule of its own, in order.

History

  • 2026-10-03 — The report path, the only clearnet action, after a click — #56
  • 2026-10-03 — Five layers, the platform bridge and the architecture test — #29
  • 2026-10-03 — Router console view: not a leak path for eepsites — #54
  • 2026-10-03 — The L3b rule list accepts exactly what the host predicate accepts — #69

Clone this wiki locally