Built-in Tor leaves webhook and Meld requests on direct network path
まだ誰も着手していません。
評価
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 初心者へのやさしさ
- 55/100
- issue の種類
- バグ
- 明瞭さ
- おおむね明確
- 活発さ
- 活発
- 領域
- mobile-dev, networking, security
調査の方向性
Start by reading data/src/commonMain/kotlin/com/blockstream/data/GreenWebhooksHttpClient.kt, data/src/commonMain/kotlin/com/blockstream/data/meld/MeldHttpClient.kt, and network/src/commonMain/kotlin/com/blockstream/network/AppHttpClient.kt, then trace how the active Tor proxy is exposed to HTTP clients. Verify both webhook and Meld requests wait for Tor readiness and never fall back to direct connections; add a production-flavor integration check covering both hosts.
索引モデルが issue の本文から書いたものです。
説明
What happened
With the app's built-in Tor setting enabled and fully bootstrapped, the Android app still made direct DNS and TLS connections to green-webhooks.blockstream.com and ramps.blockstream.com. These connections came from the device network path rather than the app's Tor proxy.
Test setup and observed result
- Source: Blockstream/green_android commit 8062ee10a546fe408987366616cd5c4823b7e03c (5.7.0 tree).
- Runtime: Android API 36 x86_64 emulator; disposable, empty testnet wallet; built-in Tor switch enabled. The app log showed Tor bootstrap at 100% and GDK connections with use_tor=True.
- Build: source-built productionGoogleDebug, not the official signed release. The public checkout required two diagnostic changes to run on this emulator: removal of an early logging branch that crashed the local no-key debug build before Koin initialization, and addition of x86_64 to the productionGoogle ABI filter. Neither change altered the network clients or Tor routing.
- On wallet overview, device registration invoked https://green-webhooks.blockstream.com/register-device. The emulator capture showed direct DNS for that host and a direct TLS ClientHello with its SNI.
- On opening Transactions, the app invoked https://ramps.blockstream.com/payments/transactions. The capture again showed direct DNS and TLS connections for that host. The view schedules another poll every 60 seconds.
In the production-flavor capture, direct DNS was visible at original frames 33206 (green-webhooks) and 33994–33995 (ramps); corresponding direct TLS ClientHello packets appeared at 33248 and 34001. The redacted runtime log records the webhook and Meld requests after Tor reached 100%.
The relevant clients are data/src/commonMain/kotlin/com/blockstream/data/GreenWebhooksHttpClient.kt and data/src/commonMain/kotlin/com/blockstream/data/meld/MeldHttpClient.kt. Both inherit network/src/commonMain/kotlin/com/blockstream/network/AppHttpClient.kt, which does not bind these Ktor requests to the app's Tor proxy. The app's Tor setting reaches GDK but not these clients.
WalletOverviewViewModel.kt:122-143 passes greenWallet.xPubHashId as externalCustomerId with an FCM token to /register-device; only optional nodeId is gated to development/debug. TransactViewModel.kt:136-166 passes the wallet-derived ID as externalCustomerIds to /payments/transactions. The destination can therefore associate a stable wallet-derived ID with a direct IP connection. TLS keeps that ID out of an ordinary on-path packet capture; the capture proves the direct route and host, while the source establishes the request fields.
Expected result
When built-in Tor is enabled, these HTTP clients should use the active Tor proxy, wait for it to be ready, and avoid direct fallback. A production-flavor integration check for both hosts would help prevent regression.
I have not tested Blockstream's official signed APK, and this report does not establish how every release or platform behaves. No real funds or personal wallet data were used.
Evidence
- Capture, part 1 — original frames 1–20,000
- Capture, part 2 — original frames 20,001–34,423; contains the packets cited above
- Request-event log — original app log lines for the two requests
- Tor startup log — redacted bootstrap and GDK lines
The two ZIPs hold the complete 35,895,240-byte emulator capture, split at frame 20,000 to stay below GitHub's per-file limit. Original capture SHA-256: e38d08baa31460a9d23123c4ff249b0f61780310dcc51ed4538a70a974bf1a08. For a frame in part 2, subtract 20,000 to find its position in that file.
The request-event log includes the disposable test wallet's FCM token and wallet-derived ID. The full app logcat is omitted because it also contains mnemonic recovery words.
A short excerpt shows Tor fully bootstrapped before both requests:
1790406524.234 Tor progress=100
1790406546.842 GDK network=testnet use_tor=True
1790406566.884 request host=green-webhooks.blockstream.com path=/register-device
1790406625.737 request host=ramps.blockstream.com path=/payments/transactions
Related: #164 covered older Countly traffic with external Tor configuration. This report concerns built-in Tor and different HTTP clients.
- 主要言語
- Kotlin
- スター
- 271
- フォーク
- 108
- PR マージ指標
- 30日以内にマージされた PR はありません
環境構築
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
Blockstream/green_android のほかの issue
-
難易度 1/5 1時間未満 初心者へのやさしさ 88/100
Blockstream/green_android#313 ·
-
難易度 3/5 1〜2日 初心者へのやさしさ 76/100
Blockstream/green_android#315 ·
-
Support scanning SeedQR recovery phrases再び着手できるかも @ardier16 が 33 日前に担当しましたが、オープン中のプルリクエストはありません。 オープンfeature request
Blockstream/green_android#311 · コメント 2 件 · 担当者 1 名 ·
-
UX: Use "Passphrase BIP39" as a universal untranslated label — don't translate it as "contraseña"再び着手できるかも @ardier16 が 33 日前に担当しましたが、オープン中のプルリクエストはありません。 オープンenhancement
Blockstream/green_android#310 · コメント 4 件 · 担当者 1 名 ·
-
2-of-3 multisig with 2FA: Show service xpub (per-account) for faster recovery再び着手できるかも @domegabri が 39 日前に担当しましたが、オープン中のプルリクエストはありません。 オープンenhancement status: planned
Blockstream/green_android#309 · コメント 2 件 · 担当者 2 名 ·
Blockstream/green_android の issue をすべて見る
似ている issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
-
Source is down
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
keiyoushi/extensions-source#19491 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
-
難易度 1/5 1時間未満 初心者へのやさしさ 92/100