Skip to content
re4Public

About

Harbor - Torrent Client

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Repository files navigation

Harbor

A Windows torrent client with built-in WireGuard, OpenVPN and SOCKS5 support. Transfers wait until the connection is verified and block if protection fails.

Written in C# with WPF and .NET 10.

Harbor's Workbench layout in dark mode, showing the transfer table and file selection.

Workbench, the default layout. Screenshots are rendered by the app with sample transfers; speeds and connection status are illustrative.

Features · Layouts · Run · Build · Tests

Features

  • Torrents and magnets. Open torrent files, fetch magnet metadata, find peers through HTTP(S) trackers, and download from peers or web seeds.
  • Queue controls. Pause, resume, remove, move transfers up the queue, and choose which files to download. Removing a transfer keeps its downloaded files.
  • Transfer details. Progress, download and upload rates, peer counts, remaining time, file lists and tracker results. Add HTTP(S) trackers to public torrents.
  • Limits. Set bandwidth caps, the number of active transfers, a download folder and a seeding ratio.
  • Connection profiles. Import WireGuard and OpenVPN configurations, or enter a SOCKS5 gateway and optional credentials. Native VPN components are bundled.
  • Windows traffic rules. A separate guard restricts Harbor's traffic before transfers start. Lost protection blocks transfers instead of falling back to a direct connection.
  • Saved preferences. Layout, theme, queue, profiles and credentials are stored for your Windows account. Settings are encrypted with Windows DPAPI.

This is a development build. Local transfer and VPN tests pass, and a live OpenVPN download has been observed progressing. Broader provider testing and full VPN download verification are still pending. See the verification record for the exact coverage.

Layouts

Choose Settings → Appearance. Changes apply immediately and save automatically. All three layouts have light and dark themes and use the same queue.

Layout View
Workbench Compact table with transfer details underneath. The default.
Precision Sidebar filters and a roomier transfer list.
Focus A short queue on the left and the selected transfer on the right.

Precision

Harbor's Precision layout in light mode, with sidebar filters and transfer details.

Focus

Harbor's Focus layout in light mode, showing one transfer's progress, speed and files.

Layout and theme settings

Harbor's appearance settings, with Workbench, Precision and Focus choices.

Run

You need Windows x64 and the .NET 10 Desktop Runtime for Windows x64. The SDK includes the runtime if you already build .NET apps.

Open Harbor.App.exe from the extracted package, or from artifacts/Harbor after publishing a build. Keep the whole folder together, including native.

  1. Open Connections and save a profile.
  2. Select Connect. Approve the Windows prompt for Harbor.Guard.exe.
  3. Wait for Protected.
  4. Add a torrent file or magnet link.
  5. Select the transfer and choose Resume. New transfers start paused.

Harbor starts offline every time. Only the guard needs administrator approval; the main app runs as a normal user. You do not need Docker, WSL or a separate VPN desktop client.

Connection profiles

Type What to provide
SOCKS5 Numeric IPv4 gateway, port, and username/password if required.
WireGuard A .conf file with one interface, one peer, an IPv4 tunnel address, a numeric IPv4 endpoint and AllowedIPs including 0.0.0.0/0.
OpenVPN An .ovpn file using dev tun, one numeric IPv4 remote, UDP or TCP, and a CA certificate. Inline certificates and keys are supported.

OpenVPN profiles from Nyr's openvpn-install are supported with a numeric IPv4 endpoint. Enter credentials in the profile editor when the server uses auth-user-pass.

Harbor rejects scripts, plugins, nested configurations and custom management settings. Interactive MFA, encrypted-key password prompts, TAP profiles and multiple OpenVPN remotes are not supported.

Build from source

Use Windows x64, PowerShell and the .NET 10 SDK for Windows x64. global.json accepts the .NET 10 SDK from 10.0.100 onward through feature-band roll-forward.

Run these commands from the folder containing Harbor.slnx.

Build and run

.\scripts\Build.ps1
.\src\Harbor.App\bin\Release\net10.0-windows\Harbor.App.exe

The build script checks the native VPN files, restores locked NuGet packages, builds Release and runs the regular test suite. Internet access is needed to fetch missing dependencies. Native downloads are checked against pinned hashes and signatures.

Create a runnable package

Close the copy of Harbor in artifacts/Harbor and wait for its guard to exit first. Publishing replaces the files in that folder.

.\scripts\Build.ps1 -Publish
.\artifacts\Harbor\Harbor.App.exe

The output includes the app, guard, native VPN components, drivers, documentation and notices. Copy or zip the entire artifacts/Harbor folder when moving the package. The destination computer still needs the .NET 10 Desktop Runtime.

Run the build steps yourself

.\scripts\Setup-Vpn.ps1
dotnet restore Harbor.slnx --locked-mode
dotnet build Harbor.slnx -c Release --no-restore
.\tests\Harbor.Tests\bin\Release\net10.0-windows\Harbor.Tests.exe

Setup-Vpn.ps1 returns without downloading anything when the bundled files match their hashes. Driver setup happens when you connect.

For Visual Studio, open Harbor.slnx with a version that supports .NET 10 and the .NET desktop development workload. Run the setup script once before the first build, then use Harbor.App as the startup project.

Tests

The regular suite currently has 23 passing tests, covering protected proxy traffic, profile validation, encrypted settings, saved layouts and real torrent/magnet transfers through a local test proxy.

After a build, run it again with:

.\tests\Harbor.Tests\bin\Release\net10.0-windows\Harbor.Tests.exe

For Windows filtering and native VPN checks, open an administrator PowerShell in the project folder:

.\scripts\Test-Guard.ps1
.\scripts\Test-NativeVpn.ps1

These use local endpoints and generated keys. They create temporary adapters and traffic rules, then clean them up. Signed driver packages remain available in Windows.

To render the layouts without making a connection:

.\src\Harbor.App\bin\Release\net10.0-windows\Harbor.App.exe --layout-smoke-test

Close any app running from that same build folder first. The check uses separate settings and sample transfers, writes PNGs and result.json to layout-verification beside the executable, and exits. It checks all three layouts, both themes, compact windows and selection preservation.

Test results and remaining checks are listed in docs/VERIFICATION.md.

Limits worth knowing

  • Torrent traffic uses TCP. DHT, UDP trackers, uTP, peer exchange, local discovery, inbound peers and automatic port forwarding are disabled. Native VPN traffic can still use UDP.
  • A magnet needs a reachable peer to supply its file list. Without HTTP(S) trackers, Harbor cannot discover that peer.
  • Native IPv6 is disabled. VPN and proxy endpoints must be numeric IPv4 addresses.
  • Downloads must use local folders. UNC paths, mapped drives and paths through junctions or symbolic links are rejected.
  • Windows DPAPI protects saved settings and profiles. It does not encrypt downloaded files, torrent metadata or resume files.

For native VPNs, Harbor binds its traffic to the selected adapter and leaves the normal route for other apps alone. Windows filtering rules persist if Harbor crashes. The Protected label means the traffic rules and a TLS connection were checked; it does not promise anonymity. Your provider still sees your source IP, and SOCKS5 does not encrypt traffic by itself.

The architecture notes cover routing, DNS, the guard and failure handling.

Troubleshooting

A magnet stays on “Finding peers” or “Getting details”.
Check the Trackers tab. At least one supplied HTTP(S) tracker needs to return a reachable peer. An empty or dead swarm cannot provide metadata. For public torrents, you can add a tracker you trust.

A VPN connection stays blocked.
Read the message beneath the top bar. Harbor keeps transfers blocked when it cannot verify protection. Check the selected profile, server availability and credentials.

The tunnel address is already in use.
Another VPN may be using the same address. Use a separate provider profile with a different assigned address, or disconnect the conflicting tunnel yourself. Harbor does not stop other VPN apps.

The build cannot find an SDK.
Run dotnet --list-sdks and check that a .NET 10 SDK is installed. The Desktop Runtime alone cannot build the project.

Moving or removing an installed copy

Close Harbor and wait for its guard to exit. Before moving or deleting a copy that has been used to connect, run:

.\scripts\Remove-Guard.ps1

From the source tree, the script targets artifacts/Harbor. From an extracted package, it targets that package. It requests administrator approval to remove the installation's traffic rules and any orphaned private adapter. Downloads, saved profiles and shared driver packages are kept.

Source layout

Path Contents
src/Harbor.App WPF interface, layouts and transfer controls.
src/Harbor.Core Models, torrent sessions and protected transports.
src/Harbor.Windows VPN control, Windows filtering and encrypted settings.
src/Harbor.Guard Administrator helper for traffic rules and adapters.
tests/Harbor.Tests Proxy, torrent, profile and native VPN checks.
scripts Build, native setup, tests and guard removal.
docs Screenshots, architecture and verification notes.

Dependency versions and license terms are in THIRD-PARTY-NOTICES.md. Keep the bundled notices with any package you distribute.

About

Harbor - Torrent Client

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages