feat: add Mihomo-native domain intelligence backend - #32
Open
gentslava wants to merge 62 commits into
Open
Conversation
Document the Mihomo-native observation and validation boundary, guarded rule ownership and apply semantics, and approved Indigo Console mockups for exact and site-scoped custom rules. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Split the approved report and review scope into risk-first, testable slices while keeping Git publication and automatic apply explicitly deferred. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Add fail-closed routing-log and connection-snapshot adapters with IDNA normalization, privacy-safe timestamps, source-independent fingerprints, and adjacent-bucket reconciliation. The module remains disconnected and disabled. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Persist privacy-bounded Mihomo observations and UTC daily aggregates with source-independent deduplication, deterministic cross-source reconciliation, migration-safe schema changes, and transactional rollback guarantees. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Derive registrable sites with the PSL private section, keep never-add and non-widenable policies independent, and serialize validated exact or site rules without crossing protected boundaries. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Fan the existing Mihomo log stream into a disabled-by-default domain observer with a bounded fingerprint-deduplicated queue, single-flight persistence drain, failure-streak reporting, and shutdown-safe cancellation. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Add an abortable single-flight /connections pulse, conservatively reconcile snapshot observations, and expose bounded parser-drift health with delayed same-ID correlation and clean restart semantics. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Parse active inline and provider rules conservatively, preserve managed provider identity, and block recommendations when coverage cannot be proven complete. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Reject non-global DNS answers and require distinct external resolver authorities before DIRECT probing. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Validate and pin every HTTPS hop while preserving SNI and Host, bounding redirects, and sanitizing transport evidence. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Generate an authenticated private Mihomo listener for the selected non-empty channel while keeping credentials out of APIs and URLs. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Authenticate dedicated proxy probes, pin every HTTPS hop, and verify the generated Mihomo route identity without mutating live selectors. Add an opt-in real-Mihomo integration test for listener auth and connection metadata.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Evaluate canonical, deduplicated A/B evidence against non-weakenable safety thresholds and current scope policy. Persist safe address-alternative facts and fail closed on unstable proxy, stale scope, malformed evidence, or incomplete coverage.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Add durable candidate, validation, attempt, and decision state with strict persistence boundaries, lease fencing, lifecycle chronology, and fourteen-day operational retention. Reconcile current filter policy before validation and preserve inert excluded audit rows for safe re-entry.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Add protected bounded overview and candidate-list read models with strict shared contracts. Harden settings and persisted decision reads against malformed storage while preserving fail-closed report semantics. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Add reversible candidate review state, scope changes, rechecks, strict report contracts, lifecycle-aware counts, and the additive SQLite migration. Keep the slice report-only and document the future locked apply veto for rejected candidates. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Wire report-only settings, production coverage and A/B execution through the serialized Mihomo runtime gate. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Move UI, CLI, and guarded publication into the active implementation plan while keeping production capability server-derived and disabled by default.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Add the protected Auto Rules workspace, candidate and exclusion review flows, separate safety filters, responsive behavior, and browser evidence. Keep automatic publishing fail-closed until the server capability lands.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Keep the strict list contract while accepting the forward-only transport hint emitted by TanStack Query. Parse the shared contract inside browser fixtures so the live failure remains covered.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Add read-only collect, validation, and report commands with protected atomic artifacts. Read every report component from one SQLite snapshot and keep live observer uncertainty fail-closed.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Align candidate and exclusion states, responsive mode and filter editors, and shared controls with the approved design. Keep apply-only actions fail-closed until publisher mutations are implemented.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Add a native skip-to-content control, codify the interaction contract, and synchronize the approved Pencil exceptions state.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Keep pending actions and detail affordances explicit while preventing long candidate rules and recheck controls from breaking responsive layouts.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Preserve the allowlisted validation stage in scheduler logs while redacting source errors, and align typed Mihomo connection fixtures with normalized inbound metadata. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Align candidate actions across review states, preserve long domain readability at the desktop boundary, and expose unavailable apply feedback to pointer and keyboard users. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Keep candidate actions on stable desktop columns and bound long rule identities so observed and generated domains cannot overlap.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Keep desktop action columns fixed, constrain long domain identities to their copy area, and give pending mobile status controls the same geometry as actions. Add regression coverage across compact and wide layouts.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Keep candidate actions aligned across desktop breakpoints and isolate long observed domains from full proposed rules. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Add a fail-closed local-only Git publisher with deterministic managed-block updates, crash recovery, repository attestation, and container runtime support. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Parse a report-first deployment capability, expose strict apply readiness, and keep apply unavailable until local provisioning is attested. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Recognize only the exact legacy settings capability, fail closed to report-only, and surface malformed current responses as errors. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Materialize the attested local Git blob atomically into Mihomo’s code-owned provider path while preserving conflicting or interrupted state for explicit reconciliation. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Parse bounded Mihomo provider and rule state, then fail closed unless the generated local domain provider and route prefix are active on the intended VPN group. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Coordinate managed rule deployment across boot and reconnect, and make Mihomo secret rotation crash-safe with a durable dual-credential journal.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Persist prepared rule operations, automatic consent and UTC budget reservations so local Git publication can recover without duplicate ownership or budget effects. Isolate router tests from the developer database and cover migration invariants and crash boundaries.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Give the Git and fsync integration scenario a scoped timeout that reflects its measured runtime under the full test suite.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Persist fenced activation attempts and terminal outcomes so interrupted apply operations can resume safely without stale completions.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Add a journal-callable, attested and crash-safe publisher for replacing the active local Mihomo provider from an exact managed Git commit.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Distinguish an untouched expected parent from the exact journaled child commit without mutating or provisioning the local rule repository.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Apply a journaled delta to the attested managed block and verify the exact intended digest before creating a local Git commit. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Validate deployment capability before reading apply readiness so a stale runtime contract schedules recovery instead of crashing the lifecycle.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Recover prepared local Git commits, materialize exact journaled content, and persist fenced activation outcomes under a caller-held apply lock.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Route activation through the shared config coordinator and keep report-mode recovery free of side effects.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Recover journaled operations before admission and preserve ordered, deferred wakes across partial activation and shutdown.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Revalidate mutable evidence under the shared mutation tail, recover durable operations before validation, and fail closed without stranding ordinary vetoes.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Add durable, fail-closed candidate application with idempotent operation recovery and activation reporting. Wire the review UI to per-domain apply states and align responsive controls with the approved Pencil design. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Remove Git publishing from Submerge and make the dedicated domain-rules volume the canonical rule store. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
gentslava
marked this pull request as ready for review
August 5, 2026 07:45
Update the light Traffic chart expectation and design-system reference to the approved Pencil accent token. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
gentslava
force-pushed
the
feature/domain-intelligence
branch
from
August 5, 2026 08:03
c8e7c09 to
f03a0d6
Compare
Align derived accent surfaces and borders with the approved Pencil accent while preserving the separate brand logo color.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- Introduced geosite handling in the domain intelligence module, including decoding and materializing geosite categories from local databases. - Added tests for geosite functionality, ensuring proper decoding of geosite entries and validation of attributes. - Updated coverage model to incorporate geosite categories, enhancing domain coverage evaluation. - Refactored existing code to improve whitespace handling and semantic normalization for domain rules. - Improved error handling for malformed geosite data and ensured compatibility with existing domain coverage logic.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Safety
Test plan
Deferred