Skip to content

Commit 8d46d2b

Browse files
committed
Harden release readiness checks
1 parent a8196a7 commit 8d46d2b

24 files changed

Lines changed: 707 additions & 81 deletions

‎.github/workflows/build-gui.yml‎

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -48,6 +48,14 @@ jobs:
4848
"$($hash.Hash) $(Split-Path $zip -Leaf)" | Set-Content -Encoding ascii "$zip.sha256"
4949
Get-ChildItem dist -Filter "MITM-DomainFronting-Control-Center-*.zip*" | Format-Table -AutoSize
5050
51+
- name: Verify release artifact contents
52+
shell: pwsh
53+
run: |
54+
$tag = "${{ github.ref_name }}"
55+
if (-not $tag) { $tag = "dev" }
56+
$zip = "dist/MITM-DomainFronting-Control-Center-$tag-windows-x64.zip"
57+
python main.py release-check --zip $zip --checksum "$zip.sha256"
58+
5159
- name: Upload GUI build artifact
5260
if: always()
5361
uses: actions/upload-artifact@v4

‎.github/workflows/validate.yml‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -109,6 +109,7 @@ jobs:
109109
run: |
110110
python tests/python/health_policy_tests.py
111111
python tests/python/readiness_tests.py
112+
python tests/python/release_artifact_tests.py
112113
python tests/python/gui_readiness_tests.py
113114
114115
- name: Validate transport experiment manifest

‎CHANGELOG.md‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -15,6 +15,9 @@
1515
- Shared readiness model for CLI/GUI orchestration with `ProjectState`, `CheckResult`, and `RepairAction` contracts.
1616
- `main.py probe` now emits the shared readiness state instead of running a separate health-probe path.
1717
- Python regression tests now live under `tests/python/`; `scripts/` is kept for operator commands, diagnostics, builders, and app entrypoints.
18+
- `main.py release-check` gates release readiness and ZIP artifact verification, including checksum and forbidden local certificate/key checks.
19+
- Release readiness checks and ZIP artifact verification.
20+
- Farsi quick start, maintainer map, generated-files policy, roadmap, and architecture decision records.
1821

1922
### Changed
2023

@@ -26,6 +29,7 @@
2629
- JA3 runtime self-audit comparison extracted to testable `ja3::self_audit` (env: `MITM_STREAM_EXPECTED_JA3`).
2730
- JA3 MD5 hex encoding writes directly into a pre-sized buffer instead of allocating per byte.
2831
- No change to default runtime behavior unless maintainers apply optional patches.
32+
- Removed obsolete historical patch files now superseded by committed loopback and ignore rules.
2933

3034
### Notes
3135

‎README.md‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -177,7 +177,9 @@ Firefox -> Settings -> About Firefox -> پنج بار روی لوگو بزنید
177177
- `Xray-config/mycert.crt` و `Xray-config/mycert.key`: گواهی و کلید شخصی شما؛ این فایل‌ها local هستند و نباید commit شوند.
178178
- `scripts/gui.py`: مرکز کنترل گرافیکی برای راه‌اندازی، تست، تعمیر و گزارش محلی.
179179
- `scripts/`: ابزارهای validate، preflight، health، DNS، route، browser و release.
180+
- `tests/python/`: تست‌های رگرسیون و ساختار پروژه.
180181
- `docs/`: راهنماهای جزئی‌تر درباره گواهی، مرورگر، DNS، پروفایل‌ها، سازگاری پلتفرم، release و عیب‌یابی.
182+
- `ROADMAP.md`: وضعیت کارهای انجام‌شده و شکاف‌های باقی‌مانده.
181183
- `.local-state/`: گزارش‌ها و تاریخچه محلی برنامه؛ خروجی پشتیبانی است و نباید بدون بازبینی ارسال شود.
182184

183185
## بررسی و عیب‌یابی محلی
@@ -218,8 +220,11 @@ py -3 scripts\lab_evidence_validate.py lab-evidence.bundle.json
218220

219221
## راهنماهای تکمیلی
220222

223+
- شروع سریع فارسی: `docs/fa/quick-start.md`
221224
- راهنمای GUI: `docs/gui.md`
222225
- یکپارچه‌سازی Chromium: `docs/chromium-integration.md`
226+
- نقشه نگه‌داری: `docs/reference/maintainer-map.md`
227+
- مرز فایل‌های منبع و تولیدی: `docs/reference/generated-files.md`
223228
- چرخه عمر گواهی: `docs/certificate-lifecycle.md`
224229
- عیب‌یابی و preflight: `docs/preflight-and-diagnostics.md`
225230
- پروفایل‌های عملیاتی: `docs/operating-profiles.md`

‎ROADMAP.md‎

Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
# Roadmap And Gap Tracker
2+
3+
This file tracks product coherence work that should remain visible between releases.
4+
5+
## Completed
6+
7+
- Shared `ProjectState`, `CheckResult`, and `RepairAction` readiness layer.
8+
- `main.py probe` emits shared readiness state.
9+
- GUI dashboard consumes readiness state for next action, safety banner, and status cards.
10+
- Unsafe external listener detection is visible in CLI and GUI.
11+
- Python regression tests moved to `tests/python/`.
12+
- Release ZIP verifier added and wired into the GUI release workflow.
13+
- Maintainer map and ADRs added.
14+
15+
## Next
16+
17+
- Extract more of `scripts/gui.py` into focused GUI modules.
18+
- Add a guided trust checklist panel backed by shared readiness fields.
19+
- Add explicit JA3 oracle fields and measured-vs-configured UI.
20+
- Add `verified-session` evidence bundle command.
21+
- Add release artifact verifier output to release notes.
22+
- Consolidate CA docs into a single certificate reference.
23+
- Consolidate DNS/profile/protocol docs into a single network-model reference.
24+
- Add JSON schemas for `configs/`, `providers/`, and `config-src/`.
25+
26+
## Open Gaps
27+
28+
| Gap | Desired Outcome | Current Status |
29+
|---|---|---|
30+
| Per-process telemetry | Show app-owned Xray counters separately from system counters | System counters are labeled; per-process telemetry not implemented |
31+
| JA3 oracle workflow | User enters oracle URL and expected hash; app records measured result | Readiness model supports fields; GUI flow not complete |
32+
| Verified runtime session | One command saves redacted runtime evidence | Planned |
33+
| Docs consolidation | Fewer first-contact docs, stronger reference docs | Started with Farsi quick start, ADRs, maintainer map |
34+
| GUI modularization | `scripts/gui.py` becomes a small entrypoint | Started with `scripts/core/gui_readiness.py` |

‎docs/adr/0001-xray-as-runtime.md‎

Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,19 @@
1+
# ADR 0001: Xray Is The Runtime Source Of Truth
2+
3+
## Status
4+
5+
Accepted.
6+
7+
## Context
8+
9+
The project contains Python diagnostics, GUI orchestration, generated profiles, and Rust validation experiments. Without a clear boundary, these pieces can look like competing runtimes.
10+
11+
## Decision
12+
13+
Xray remains the actual runtime for proxying, routing, MITM, domain-fronting, and uTLS fingerprint behavior. Python, GUI, config-src, tests, and Rust validate, generate, observe, or assist around Xray.
14+
15+
## Consequences
16+
17+
- Runtime behavior must be proven against generated Xray configs.
18+
- Rust code is validation/experimental unless explicitly promoted later.
19+
- Native Xray-core integration is deferred until a feature is stable enough to justify a Go/Xray-core implementation.
Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,19 @@
1+
# ADR 0002: No Silent Trust-Store Installation
2+
3+
## Status
4+
5+
Accepted.
6+
7+
## Context
8+
9+
The project creates local CA material for browser MITM diagnostics. Installing trust silently would be risky and surprising.
10+
11+
## Decision
12+
13+
The app may generate local certificate files and show instructions, but it must not silently install a CA into Windows, browser, or machine trust stores.
14+
15+
## Consequences
16+
17+
- Trust setup remains explicit and user-controlled.
18+
- GUI and CLI should report trust state and recommended next action.
19+
- Any future trust-changing action must require clear confirmation and must explain system impact.
Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,19 @@
1+
# ADR 0003: Browser Proxy First
2+
3+
## Status
4+
5+
Accepted.
6+
7+
## Context
8+
9+
The project supports browser diagnostics and optional fingerprint checks. OS-wide proxy or TUN changes are higher-risk and harder to reason about for newcomers.
10+
11+
## Decision
12+
13+
The default diagnostic path is an explicit browser proxy against the local Xray listener. TUN and OS proxy state are detected or documented, not silently changed.
14+
15+
## Consequences
16+
17+
- Page Check should run before advanced fingerprint checks.
18+
- CloakBrowser is an app-layer fingerprint path, not a routing engine.
19+
- System proxy and TUN states are warnings/context unless the user intentionally configures them.
Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,19 @@
1+
# ADR 0004: JA3 Oracle Required For Measured Fingerprint Claims
2+
3+
## Status
4+
5+
Accepted.
6+
7+
## Context
8+
9+
Xray can be configured with `tlsSettings.fingerprint: "chrome"`, but that is not the same as externally measured JA3 proof.
10+
11+
## Decision
12+
13+
The app may say a TLS fingerprint is configured when the Xray config sets it. It may only claim a measured JA3 match when an external JA3 oracle returns matching evidence.
14+
15+
## Consequences
16+
17+
- Without an oracle URL and expected value, JA3 status remains `not measured`.
18+
- GUI/docs must distinguish configured uTLS behavior from measured TLS fingerprint evidence.
19+
- Browser fingerprint checks and TLS fingerprint checks remain separate concepts.
Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,19 @@
1+
# ADR 0005: Local Source-Labeled Telemetry
2+
3+
## Status
4+
5+
Accepted.
6+
7+
## Context
8+
9+
The GUI shows network and activity telemetry. Some telemetry is system-wide while future telemetry may be app- or process-specific.
10+
11+
## Decision
12+
13+
Telemetry must stay local and must label its source, scope, and confidence. System counter telemetry must not be presented as per-Xray telemetry.
14+
15+
## Consequences
16+
17+
- The right rail can show rates, totals, and running time, but labels must clarify measurement scope.
18+
- Future per-process or Xray-log telemetry should be shown as a distinct source.
19+
- No automatic upload of telemetry is allowed.

0 commit comments

Comments
 (0)