feat: add Tor SOCKS5 proxy support for outbound .onion connections#89
Closed
sat-engineer wants to merge 1 commit intogetAlby:mainfrom
Closed
feat: add Tor SOCKS5 proxy support for outbound .onion connections#89sat-engineer wants to merge 1 commit intogetAlby:mainfrom
sat-engineer wants to merge 1 commit intogetAlby:mainfrom
Conversation
3 tasks
Implement SOCKS5 protocol in connection.rs to route outbound peer connections through a Tor proxy. This enables LDK nodes to connect to peers at .onion addresses. Changes: - Add tor_socks5_connect() with full SOCKS5 handshake (RFC 1928/1929) - Support Tor stream isolation via random password auth per connection - Add set_tor_proxy_address() on NodeBuilder (FFI-compatible via UDL) - Route OnionV3 addresses through SOCKS5, clearnet through direct TCP - Include base32 encoder for OnionV3 address derivation Based on the approach in upstream ldk-node PR lightningdevkit#778, but with a self-contained SOCKS5 implementation that doesn't depend on unreleased lightning_net_tokio::tor_connect_outbound(). Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
c7a84c9 to
e799323
Compare
Author
|
Reopening with clean history |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
connection.rsto route outbound peer connections through a Tor proxy, enabling LDK nodes to connect to peers at.onionaddressesset_tor_proxy_address()onNodeBuilderwith FFI-compatible UDL bindingsOnionV3addresses through SOCKS5 proxy while keeping clearnet addresses on direct TCPDetails
This is a self-contained SOCKS5 implementation (~100 lines) that doesn't depend on unreleased upstream code. It follows the approach of ldk-node #778 but avoids the dependency on
lightning_net_tokio::tor_connect_outbound()which isn't in any released crate version yet.SOCKS5 features:
EntropySource::get_secure_random_bytes())Architecture:
tor_proxy_addresslives onNodeBuilder(notConfig) for UniFFI compatibilityConnectionManagerdetects.onionaddresses and routes them through the proxyTest plan
cargo checkpasses with zero warnings.onionsucceeded🤖 Generated with Claude Code