-
-
Notifications
You must be signed in to change notification settings - Fork 3
no leak architecture
github-actions[bot] edited this page Oct 3, 2026
·
6 revisions
Status: shipped in #29.
Five independent layers keep the web engine away from the clearnet and from local services. A leak needs all five to fail. The full decision is ADR 0001.
| Layer | What it does |
|---|---|
| L1 gatekeeper | eepview's own proxy on loopback. It forwards only .i2p requests, and only to the verified router proxy. |
| L2 engine proxy | Every web tab uses the gatekeeper as its proxy. |
| L3 request filter | A page policy on every response (L3a), and an engine rule list attached before the first load (L3b, macOS and Windows). |
| L4 navigation guard | Only http(s)://*.i2p may load in a tab or open a new one. |
| L5 WebRTC off | WebRTC sends UDP outside the proxy, so it is removed in every frame. |
The router console view is not a leak path for eepsites:
| View | Why it is not a leak path |
|---|---|
console (router console) |
It loads only the detected console origin, http://127.0.0.1:<port>, after an engine rule list that allows only that origin (macOS, Windows). An eepsite can never load in it: an .i2p link opens in a normal tab through L4, and anything else is cancelled. No tab-* webview can reach it, because the tabs keep L1–L5 and loopback stays blocked for them. It has no IPC, WebRTC is off, and no probe runs at start. See Router console and ADR 0001. |
| Path | Why it is not a leak |
|---|---|
"Open a GitHub issue" on eepview://report
|
It runs only after the user's click. eepview opens no socket: the system browser opens the page, outside eepview and outside I2P. The URL always starts with the fixed prefix https://github.com/tcivie/eepview/issues/new, and its text is the scrubbed preview the user just read. Only the internal webview may call it, and JavaScript gets no opener permission. See Diagnostics and bug reports. |
JavaScript is on. The layers sit below JavaScript, so they hold with it on. You can turn it off per site.
-
cargo test --workspaceinsrc-tauriruns the architecture test (tests/architecture.rs), which fails if a layer is removed. - The leak test runs the real binary against canaries.
- No OS-level layer yet (L6, see the roadmap).
- Linux has no engine rule list yet (L3b); the page policy covers it. The console view has no page policy, so on Linux it relies on its navigation guard and the router's own pages.
- The L3b rule list allows exactly the hosts of the one host predicate: after the
.i2pallow rule it blocksxn--labels,b32.i2p, short*.b32.i2pnames and port 0 again, and allows ab32name of 52 base32 characters or more. The WebKit regex subset has no|, so each form is a rule of its own, in order.
- 2026-10-03 — The report path, the only clearnet action, after a click — #56
- 2026-10-03 — Five layers, the platform bridge and the architecture test — #29
- 2026-10-03 — Router console view: not a leak path for eepsites — #54
- 2026-10-03 — The L3b rule list accepts exactly what the host predicate accepts — #69
Generated from docs/wiki in the repository. Edit there, not here.