From 4ef6d3aa7680b606af1bf6eb9f33b7ebe6c51536 Mon Sep 17 00:00:00 2001 From: CyberMind-FR Date: Thu, 18 Jun 2026 19:20:21 +0200 Subject: [PATCH] docs: record #662 R3 cutover to Go engine + banner port (PR #670) --- .claude/HISTORY.md | 23 +++++++++++++++++++++++ 1 file changed, 23 insertions(+) diff --git a/.claude/HISTORY.md b/.claude/HISTORY.md index 8b4374eb..348a9fd6 100644 --- a/.claude/HISTORY.md +++ b/.claude/HISTORY.md @@ -3,6 +3,29 @@ --- +## 2026-06-18 — #662 R3 CUTOVER to the Go MITM engine (PR #670) — LIVE + banner ported + +- **Cutover executed and live.** The Go engine now serves **100% of R3 traffic**, + replacing the Python mitmproxy workers. Found + fixed 4 blockers that made the dark + package unable to serve the live path: (1) it forged with the wrong CA (ca-wg "WG CA" + vs the "R3 CA" clients trust) → now uses the mitmproxy confdir bundle; (2) root-only + key vs non-root user → R3 CA bundle is group-readable; (3) bound 127.0.0.1 vs the + 10.99.1.1 DNAT target → now binds 10.99.1.1; (4) ran CONNECT vs transparent → now + `--transparent`. `loadCA` scans PEM blocks by type (combined cert+key bundle). +- **Validated on real arm64 hardware** then rolled out gated: localhost forge against + the real R3 CA → scoped-DNAT transparent capture → **canary slot 3 (~25%, dead-man + armed)** → **widen to 100%**. At 100%: 0 restarts, 0 errors, ~64MB total + (vs Python ~280-470MB), even round-robin, 142 distinct SNIs/75s. +- **Banner ported** (the one regression the user caught — "no more banner but fast"). + Go now injects the real loader `