Files
harbor-net/docs/goals/windows-local-singbox/EVIDENCE.md

4.2 KiB

Windows Local Sing-Box Evidence

Acceptance Evidence

Record the real artifact that proves the outcome from the Windows-client user's perspective.

  • Windows client now has two independent component blocks:
    • ProxiFyre block remains the existing required app-routing layer.
    • Local sing-box block is optional, visually matches the ProxiFyre finder card, has setup details, install/start/stop/uninstall actions, subscription input, route switch, server list, ping, and config generation actions.
  • Route choice is explicit:
    • Внешний прокси keeps the existing external SOCKS5 flow.
    • Local sing-box generates sing-box-config.json, ensures target local-singbox at 127.0.0.1:1080, and applies ProxiFyre to that local target.
  • Generated config proof is covered by singbox_command_tests::generate_writes_config_and_local_singbox_target:
    • generated config contains a local mixed inbound;
    • selected outbound is retagged to stable vpn;
    • persisted target is local-singbox, kind=local, protocol=socks5, host=127.0.0.1, port=1080, requiresComponent=singbox.
  • Browser visual proof:
    • Vite dev server: http://127.0.0.1:5173/
    • Playwright/system Chrome desktop screenshot showed ProxiFyre and Local sing-box blocks, route switch, subscription input, ping/config actions, and apply/open controls.
    • Mobile screenshot at 390px width showed the same controls stacked without overlap.
    • Final mobile layout metric: docScrollWidth=390, viewportWidth=390, overflow=[].
  • Privileged Windows service lane:
    • Implemented install/start/stop/uninstall paths and PowerShell parser checks.
    • Real elevated UAC install/start was not executed in this session, so this lane is implemented but unproven until manual Windows validation runs.

Verification

Record focused checks that passed, including command and relevant output.

  • cd apps/windows-client && npm run build
    • Passed: tsc && vite build.
  • cd apps/windows-client/src-tauri && cargo test --test storage_tests --test subscription_tests --test singbox_adapter_tests --test component_detection_tests --test singbox_service_tests --test command_tests --test singbox_command_tests
    • Passed:
      • command_tests: 8 passed
      • component_detection_tests: 7 passed
      • singbox_adapter_tests: 6 passed
      • singbox_command_tests: 7 passed
      • singbox_service_tests: 6 passed
      • storage_tests: 8 passed
      • subscription_tests: 7 passed
    • Total focused Local sing-box backend path: 49 passed.
  • cd apps/windows-client/src-tauri && cargo test --test proxifyre_adapter_tests
    • Passed: 6 passed.
    • Proves existing external SOCKS5 route still generates and local-singbox route is blocked when the required component is missing but works when it is running.
  • cargo fmt
    • Passed.
  • apps/windows-client/scripts/install-singbox.ps1 parser check:
    • Covered by singbox_service_tests::install_singbox_script_parses_as_powershell on Windows.
  • Playwright/system Chrome visual check:
    • Desktop viewport 1280x1200: main controls rendered.
    • Mobile viewport 390x900: no horizontal overflow after CSS fix.

Review Notes

Record PRE reviewer, maintainer, or verifier findings that changed the result.

  • PRE self-review: aligned after tightening the service-wrapper contract to WinSW and requiring start_singbox_service to regenerate/check config before service start.
  • POST plan review: implementation stayed inside apps/windows-client and did not reuse root Node subscription parsing. External proxy remains default and does not require Local sing-box.
  • Correctness review: covered storage defaults, redacted subscription URL, HTTP/HTTPS validation, JSON/base64/VLESS subscription parsing, selected-outbound config generation, missing selected server errors, component detection, service command output parsing, Tauri command orchestration, route target generation, TypeScript build, and responsive UI.
  • Maintainability review: Rust owns subscription/cache/config/service state; React owns transient UI only. Tauri commands are typed and do not expose raw PowerShell/stdout to the UI.
  • Residual risk: real UAC install/start/stop/uninstall for VpnProxySingBox must be validated manually on a Windows machine with admin confirmation and network access to GitHub releases.