Theseus Navigator — Silent Mode's Electron browser with the Ariadne resolver built in.
Three bugs, all found by driving the add-on in a real Theseus and watching the egress IP rather than reasoning about it. 1. The generated config used pre-1.11 schema. `sniff` on an inbound and the `block` outbound type were deprecated in sing-box 1.11 and REMOVED in 1.13, so 1.14.1 refused the whole file and exited 1. Routing is now a bare `final`; rule `action` semantics changed in 1.12 and the explicit inbound→outbound rule was never needed. 2. xray-core 26.3.27's REALITY would not complete a handshake with a sing-box client — and, after ruling out keys (three derivations, a fresh pair used verbatim), shortIds (explicit and empty), clock skew, dest reachability, TLS 1.3/X25519 on the dest, and xtls-rprx-vision, not with a correctly configured xray client either. sing-box against sing-box works first try. The exits now run sing-box, which is what the add-on already ships to every client, so there is no longer a cross-implementation surface at all. Migration script included; it keeps the port, the SNI and the existing uuid pool and only changes the Reality keypair. Worth recording separately: xray's REALITY inbound field is `dest`, not sing-box's `target`. That was wrong too, independently. 3. leaseEndpoint cached the full vless URL. The Reality key and short id live inside that URL, so re-keying an exit left every client failing against a stale copy for the whole 24h lease. It now caches only the uuid and rebuilds the URL from the current catalogue entry, so a re-key takes effect as soon as the catalogue refreshes. Verified in Theseus over CDP: baseline 80.187.100.105, tunnel up 81.31.210.65 (the sm-1 exit), off restores the baseline, and sm-3 is correctly refused to a free-tier caller. |
||
|---|---|---|
| addon-build/docx-editor | ||
| bundled-addons | ||
| dev | ||
| docs | ||
| lib | ||
| nsis | ||
| scripts | ||
| snapshots | ||
| addon-inject-preload.js | ||
| addon-tab-preload.js | ||
| addon-update-pubkeys.js | ||
| addon-updater.js | ||
| addons-host.js | ||
| address-picker-preload.js | ||
| address-picker.html | ||
| approval-preload.js | ||
| approval.html | ||
| auth-prompt-preload.js | ||
| auth-prompt.html | ||
| bcnr-origin.js | ||
| bcnr-preload.js | ||
| BROWSER-PROMPT.md | ||
| chrome.html | ||
| collision-preload.js | ||
| collision.html | ||
| DESIGN-integrated-wallet.md | ||
| DESIGN-password-manager.md | ||
| DESIGN-wallet-multi-account-amendment.md | ||
| downloads-preload.js | ||
| downloads.html | ||
| engine-picker-preload.js | ||
| engine-picker.html | ||
| error-preload.js | ||
| error.html | ||
| GOTCHAS.md | ||
| home-preload.js | ||
| home.html | ||
| js-dialog-preload.js | ||
| js-dialog.html | ||
| link-status-preload.js | ||
| link-status.html | ||
| main.js | ||
| messages-preload.js | ||
| messages.html | ||
| package-lock.json | ||
| package.json | ||
| PACKAGING-PROMPT.md | ||
| PENDING.md | ||
| popover-preload.js | ||
| popover.html | ||
| preload.js | ||
| pw-fill-preload.js | ||
| pw-fill.html | ||
| README.md | ||
| RELEASE-HANDOFF.md | ||
| ROADMAP-identity-wallet.md | ||
| SESSION-PROMPT-identity-wallet.md | ||
| settings-preload.js | ||
| settings.html | ||
| sidebar-preload.js | ||
| test-installer.wsb | ||
| webapps.js | ||
Theseus Navigator
The browser — the consumer face of the stack. Native .bch support with the
resolver built in, so a user installs one app instead of modifying their
operating system. Named for the thread through the labyrinth: the chain is the
thread.
Scope
- Electron shell (Chromium engine, no forking): tabs, address bar, history.
- In-process
.bchresolution — no system daemon, no NRPT, no OS trust-store changes; reusesbns.jsfrom the BNS repo as a library. - Record handling:
hrender,ipconnect,p/s3via in-app gateway,uredirect. - TLS via cert-verify hook (Electron
setCertificateVerifyProc) against the BNS root / on-chaintlsfingerprints — no OS store touched. - Provenance indicator: shows whether a page came from the chain / Sia / a direct server, with NFT category and record type — the decentralized padlock.
Status: not started
Build it in its own session/repo. The ready-to-paste brief is
BROWSER-PROMPT.md (a reference copy in this folder; canonical source is
D:\Dev\NameCoin\BROWSER-PROMPT.md — if they diverge, NameCoin wins). It points
here and reuses the resolver core. theseus.bch is registered and should
eventually serve the browser's own homepage over the protocol it implements.
Roadmap
BUILD-ROADMAP.md Stage 5.