mirror of
https://github.com/xtaci/kcptun.git
synced 2024-04-21 12:32:32 +00:00
Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
8705bd7670 | ||
|
|
b4e5181a2f | ||
|
|
94f61b5945 | ||
|
|
efc0b99d21 | ||
|
|
3803993529 | ||
|
|
d23ff7c351 | ||
|
|
f383ee31a5 | ||
|
|
d399f220f0 | ||
|
|
59a1bbc7b8 | ||
|
|
3b656e101f | ||
|
|
aec364eb72 | ||
|
|
e26ab6729f | ||
|
|
583fe3ba24 | ||
|
|
7fd6442284 | ||
|
|
81f4643830 | ||
|
|
744a6407e7 | ||
|
|
2cf5292ac1 | ||
|
|
b3a8b631b4 | ||
|
|
1167419210 | ||
|
|
56f9f0d01a | ||
|
|
96888f1cac | ||
|
|
e752d70c79 | ||
|
|
a882b94e5b | ||
|
|
790a6d5352 | ||
|
|
603c2db5ab | ||
|
|
581df3a34d | ||
|
|
6113d2b497 | ||
|
|
d3b8a4d71d | ||
|
|
1f0a4a2c2f | ||
|
|
75923fb08f | ||
|
|
0243422885 | ||
|
|
6374cb0d36 | ||
|
|
0aedc21c50 | ||
|
|
727887517f | ||
|
|
7b81b24e8d | ||
|
|
ba22434379 | ||
|
|
003617186b | ||
|
|
b9ce27cb3e | ||
|
|
c93a199823 | ||
|
|
bb34894947 | ||
|
|
f743a075c5 | ||
|
|
a04c959c9c | ||
|
|
4a79d26d35 | ||
|
|
8104d18959 | ||
|
|
ae699f498c | ||
|
|
dbdd79f1d6 | ||
|
|
51bdedb1b3 | ||
|
|
8ea071fa03 | ||
|
|
f74201a410 | ||
|
|
96622bcfc0 | ||
|
|
29328b375a | ||
|
|
db7f1def1b | ||
|
|
628e723167 | ||
|
|
ff393ccacb | ||
|
|
1bb61dbcfc | ||
|
|
0b1598d09f | ||
|
|
0552bebe46 | ||
|
|
d158e6df3f | ||
|
|
cf7bca5cb7 | ||
|
|
99a2b60c7d | ||
|
|
4a5024b361 | ||
|
|
12bd3853d5 | ||
|
|
7992b87889 | ||
|
|
cfcc2e0676 | ||
|
|
1e870f02af | ||
|
|
bf2abf14e7 | ||
|
|
2df3e6c438 | ||
|
|
ba4c93c3f5 | ||
|
|
bc22f46065 | ||
|
|
3fc15de95d | ||
|
|
6f9449bb10 | ||
|
|
c6cbfd307e | ||
|
|
d68792cb1a | ||
|
|
117edce137 | ||
|
|
990a5f7f87 | ||
|
|
19d7d74d59 | ||
|
|
31afe325ad | ||
|
|
ab7519c2d6 | ||
|
|
d6da2e1ead | ||
|
|
4d5a3dd791 | ||
|
|
4a46d696b6 | ||
|
|
33d50dcd45 | ||
|
|
2b3f6dbabe | ||
|
|
448717fa1c | ||
|
|
887fba3381 | ||
|
|
fb62d45df8 | ||
|
|
cd1e2b4ff7 | ||
|
|
5ee659dd41 | ||
|
|
1a596f55f4 | ||
|
|
889a904dca | ||
|
|
172dcf6481 | ||
|
|
ff92c70b40 | ||
|
|
af1d28ae5a | ||
|
|
4a7d143c69 | ||
|
|
7ff69f16d5 | ||
|
|
7eb037c4dd | ||
|
|
a87f6af812 | ||
|
|
7574f9bfd3 | ||
|
|
d5b5cf683b | ||
|
|
fded353b68 | ||
|
|
832dbed064 | ||
|
|
4b660fa02c | ||
|
|
59e6ebee05 | ||
|
|
c1a895426d | ||
|
|
ebdcc9ae8a | ||
|
|
2c076f7a34 | ||
|
|
a1a0fbd060 | ||
|
|
bc4214e4a8 | ||
|
|
61e6dfe87b | ||
|
|
4448a2658d | ||
|
|
c9a312f12b | ||
|
|
2bb48495d3 | ||
|
|
06f0a6f80b | ||
|
|
ea895ad824 | ||
|
|
a72bf0c9b5 | ||
|
|
2b83dbda07 | ||
|
|
c35ef339af | ||
|
|
c96d4b534e | ||
|
|
6216049c14 | ||
|
|
0d98020e59 | ||
|
|
14ea6f8a71 | ||
|
|
214669eaf9 | ||
|
|
48d2cad6ac | ||
|
|
67cd5a4e22 | ||
|
|
f49392c95e | ||
|
|
4c9370a252 | ||
|
|
ef3cf3d982 | ||
|
|
8e5f405336 | ||
|
|
2aa6887860 | ||
|
|
9d13ec9350 | ||
|
|
ef9d08567f | ||
|
|
66ebcf2773 | ||
|
|
67a08b43ed | ||
|
|
46ce8a2e51 | ||
|
|
fd6a6e4a64 | ||
|
|
1de3c1fa8a | ||
|
|
cc821b6eaf | ||
|
|
6f8ce90c23 | ||
|
|
32be3e836b | ||
|
|
664a79e488 | ||
|
|
74d874b0db | ||
|
|
58874784f3 | ||
|
|
f92bae1d03 | ||
|
|
a1aa89ea1c | ||
|
|
52c75f68ba | ||
|
|
57fce73ca6 | ||
|
|
13e980cdff |
@@ -0,0 +1,13 @@
|
||||
Before firing issue, make sure you figured out the following common questions.
|
||||
|
||||
PLEASE DO SEARCH FIRST.
|
||||
|
||||
1. Check your ```-key xxx``` for at least 3 times, ***MAKE SURE*** both sides share the same secret.
|
||||
2. ```-nocomp, -datashard, -parityshard, -key, -crypt``` ***must be the same*** on both side.
|
||||
3. Did you correctly set the ***-target*** on the server side?
|
||||
4. ***MAKE SURE*** ```telnet target port``` on your server successful(don't ask me why couldn't).
|
||||
5. Does your ***firewall allows UDP*** communications? (including your ISP Cable-Modem)
|
||||
6. Are you using the **same version** for both client & server
|
||||
7. Are you using the **latest release**?
|
||||
8. Which **OS** do you use?
|
||||
9. Which end for this issue related to, **client or server**?
|
||||
+5
-3
@@ -1,6 +1,8 @@
|
||||
FROM golang:latest
|
||||
FROM golang:alpine
|
||||
MAINTAINER xtaci <daniel820313@gmail.com>
|
||||
RUN go get github.com/xtaci/kcptun/client
|
||||
RUN go get github.com/xtaci/kcptun/server
|
||||
RUN apk update && \
|
||||
apk upgrade && \
|
||||
apk add git
|
||||
RUN go get github.com/xtaci/kcptun/client && go get github.com/xtaci/kcptun/server
|
||||
EXPOSE 29900/udp
|
||||
EXPOSE 12948
|
||||
|
||||
+240
@@ -0,0 +1,240 @@
|
||||
# <img src="logo.png" alt="kcptun" height="60px" />
|
||||
[![Release][13]][14] [![Powered][17]][18] [![MIT licensed][11]][12] [![Build Status][3]][4] [![Go Report Card][5]][6] [![Downloads][15]][16] [![Gitter][19]][20] [![Docker][1]][2]
|
||||
[1]: https://images.microbadger.com/badges/image/xtaci/kcptun.svg
|
||||
[2]: https://microbadger.com/images/xtaci/kcptun
|
||||
[3]: https://travis-ci.org/xtaci/kcptun.svg?branch=master
|
||||
[4]: https://travis-ci.org/xtaci/kcptun
|
||||
[5]: https://goreportcard.com/badge/github.com/xtaci/kcptun
|
||||
[6]: https://goreportcard.com/report/github.com/xtaci/kcptun
|
||||
[7]: https://img.shields.io/badge/license-MIT-blue.svg
|
||||
[8]: https://raw.githubusercontent.com/xtaci/kcptun/master/LICENSE.md
|
||||
[9]: https://img.shields.io/github/stars/xtaci/kcptun.svg
|
||||
[10]: https://github.com/xtaci/kcptun/stargazers
|
||||
[11]: https://img.shields.io/badge/license-MIT-blue.svg
|
||||
[12]: LICENSE.md
|
||||
[13]: https://img.shields.io/github/release/xtaci/kcptun.svg
|
||||
[14]: https://github.com/xtaci/kcptun/releases/latest
|
||||
[15]: https://img.shields.io/github/downloads/xtaci/kcptun/total.svg?maxAge=1800
|
||||
[16]: https://github.com/xtaci/kcptun/releases
|
||||
[17]: https://img.shields.io/badge/KCP-Powered-blue.svg
|
||||
[18]: https://github.com/skywind3000/kcp
|
||||
[19]: https://badges.gitter.im/xtaci/kcptun.svg
|
||||
[20]: https://gitter.im/xtaci/kcptun?utm_source=badge&utm_medium=badge&utm_campaign=pr-badge
|
||||
|
||||
A tool for converting tcp stream into kcp+udp stream, :zap: ***[download address](https://github.com/xtaci/kcptun/releases/latest)***:zap:
|
||||
|
||||

|
||||
|
||||
***kcptun is based on [kcp-go](https://github.com/xtaci/kcp-go)***
|
||||
|
||||
### *QuickStart* :lollipop:
|
||||
```
|
||||
Server Side: ./server_linux_amd64 -t "127.0.0.1:1080" -l ":4000" -mode fast2 // forwarding to local port 1080
|
||||
Client Side: ./client_darwin_amd64 -r "SERVERIP:4000" -l ":1080" -mode fast2 // listening on port 1080
|
||||
```
|
||||
|
||||
### *Performance* :lollipop:
|
||||
<img src="fast.png" alt="fast.com" height="256px" />
|
||||
* Speed tested with: https://fast.com
|
||||
* WAN Link Speed: 100M ADSL
|
||||
* WIFI: 5GHz TL-WDR3320
|
||||
|
||||
### *Usage* :lollipop:
|
||||
Help output under MacOS X:
|
||||
```
|
||||
$ ./client_darwin_amd64 -h
|
||||
NAME:
|
||||
kcptun - kcptun client
|
||||
|
||||
USAGE:
|
||||
client_darwin_amd64 [global options] command [command options] [arguments...]
|
||||
|
||||
VERSION:
|
||||
20160820
|
||||
|
||||
COMMANDS:
|
||||
help, h Shows a list of commands or help for one command
|
||||
|
||||
GLOBAL OPTIONS:
|
||||
--localaddr value, -l value local listen address (default: ":12948")
|
||||
--remoteaddr value, -r value kcp server address (default: "vps:29900")
|
||||
--key value pre-shared secret for client and server (default: "it's a secrect") [$KCPTUN_KEY]
|
||||
--crypt value aes, aes-128, aes-192, salsa20, blowfish, twofish, cast5, 3des, tea, xtea, xor, none (default: "aes")
|
||||
--mode value profiles: fast3, fast2, fast, normal (default: "fast")
|
||||
--conn value set num of UDP connections to server (default: 1)
|
||||
--mtu value set maximum transmission unit of UDP packets (default: 1350)
|
||||
--sndwnd value set send window size(num of packets) (default: 128)
|
||||
--rcvwnd value set receive window size(num of packets) (default: 1024)
|
||||
--datashard value set reed-solomon erasure coding - datashard (default: 10)
|
||||
--parityshard value set reed-solomon erasure coding - parityshard (default: 3)
|
||||
--dscp value set DSCP(6bit) (default: 0)
|
||||
--nocomp disable compression
|
||||
--help, -h show help
|
||||
--version, -v print the version
|
||||
|
||||
|
||||
$ ./server_darwin_amd64 -h
|
||||
NAME:
|
||||
kcptun - kcptun server
|
||||
|
||||
USAGE:
|
||||
server_darwin_amd64 [global options] command [command options] [arguments...]
|
||||
|
||||
VERSION:
|
||||
20160820
|
||||
|
||||
COMMANDS:
|
||||
help, h Shows a list of commands or help for one command
|
||||
|
||||
GLOBAL OPTIONS:
|
||||
--listen value, -l value kcp server listen address (default: ":29900")
|
||||
--target value, -t value target server address (default: "127.0.0.1:12948")
|
||||
--key value pre-shared secret for client and server (default: "it's a secrect") [$KCPTUN_KEY]
|
||||
--crypt value aes, aes-128, aes-192, salsa20, blowfish, twofish, cast5, 3des, tea, xtea, xor, none (default: "aes")
|
||||
--mode value profiles: fast3, fast2, fast, normal (default: "fast")
|
||||
--mtu value set maximum transmission unit of UDP packets (default: 1350)
|
||||
--sndwnd value set send window size(num of packets) (default: 1024)
|
||||
--rcvwnd value set receive window size(num of packets) (default: 1024)
|
||||
--datashard value set reed-solomon erasure coding - datashard (default: 10)
|
||||
--parityshard value set reed-solomon erasure coding - parityshard (default: 3)
|
||||
--dscp value set DSCP(6bit) (default: 0)
|
||||
--nocomp disable compression
|
||||
--help, -h show help
|
||||
--version, -v print the version
|
||||
```
|
||||
|
||||
### *Applications* :lollipop:
|
||||
1. Real-time gaming.
|
||||
2. Cross-ISP data exchange in PRC.
|
||||
3. Other lossy network.
|
||||
|
||||
### *Parameters* :lollipop:
|
||||
***Both sides must agree on the following parameters:***
|
||||
* datashard
|
||||
* parityshard
|
||||
* nocomp
|
||||
* key
|
||||
* crypt
|
||||
|
||||
other parameters can be set independently.
|
||||
|
||||
*How to optimize*:
|
||||
> Step 1:Increase client rcvwnd & server sndwnd simultaneously & gradually。
|
||||
> Step 2:Try download something and observer, if the bandwidth usage is close the limit then stop, otherwise goto step 1.
|
||||
|
||||
***NOTICE: if too much retranmission happens, it's quite possible the windows are too large***
|
||||
|
||||
### *Security* :lollipop:
|
||||
No matter what encryption you are using for application layer, if you specify ```-crypt none``` to kcptun,
|
||||
the header will be ***PLAINTEXT*** to everyone; I suggest ```-crypt aes-128``` for encryption at least .
|
||||
|
||||
NOTICE: ```-crypt xor``` is also insecure, do not use this unless you know what you are doing.
|
||||
|
||||
### *Memory Control* :lollipop:
|
||||
Routers, mobile devices are sensitive to memory consumption; by setting GOGC environment(eg: GOGC=20) will lower memory consumption.
|
||||
Reference: https://blog.golang.org/go15gc
|
||||
|
||||
### *Traffic Control* :lollipop:
|
||||
***Intended audience : for those server's bandwidth is quite limited.***
|
||||
|
||||
Example: To limit outgoing bandwidth to 32mbit/s on server.
|
||||
```
|
||||
root@kcptun:~# cat tc.sh
|
||||
tc qdisc del dev eth0 root
|
||||
tc qdisc add dev eth0 root handle 1: htb
|
||||
tc class add dev eth0 parent 1: classid 1:1 htb rate 32mbit
|
||||
tc filter add dev eth0 protocol ip parent 1:0 prio 1 handle 10 fw flowid 1:1
|
||||
iptables -t mangle -A POSTROUTING -o eth0 -j MARK --set-mark 10
|
||||
root@kcptun:~#
|
||||
```
|
||||
|
||||
### *DSCP* :lollipop:
|
||||
Differentiated services or DiffServ is a computer networking architecture that specifies a simple, scalable and coarse-grained mechanism for classifying and managing network traffic and providing quality of service (QoS) on modern IP networks. DiffServ can, for example, be used to provide low-latency to critical network traffic such as voice or streaming media while providing simple best-effort service to non-critical services such as web traffic or file transfers.
|
||||
|
||||
DiffServ uses a 6-bit differentiated services code point (DSCP) in the 8-bit differentiated services field (DS field) in the IP header for packet classification purposes. The DS field and ECN field replace the outdated IPv4 TOS field.[1]
|
||||
|
||||
setting each side with ```-dscp value```.
|
||||
|
||||
### *Embeded Mode* :lollipop:
|
||||
Latency:
|
||||
*fast3 >* ***[fast2]*** *> fast > normal > default*
|
||||
Payload Ratio:
|
||||
*default > normal > fast >* ***[fast2]*** *> fast3*
|
||||
Parameters in middle is balanced for latency & payload ratio, the faster you get the more wasteful you are.
|
||||
Manual control is supported with hidden parameters, you must understand KCP protocol before doing this.
|
||||
```
|
||||
-mode manual -nodelay 1 -resend 2 -nc 1 -interval 20
|
||||
```
|
||||
I suggest fast2 for high-loss network, normal for low-loss network.
|
||||
|
||||
### *Forward Error Correction* :lollipop:
|
||||
In coding theory, the Reed–Solomon code belongs to the class of non-binary cyclic error-correcting codes. The Reed–Solomon code is based on univariate polynomials over finite fields.
|
||||
|
||||
It is able to detect and correct multiple symbol errors. By adding t check symbols to the data, a Reed–Solomon code can detect any combination of up to t erroneous symbols, or correct up to ⌊t/2⌋ symbols. As an erasure code, it can correct up to t known erasures, or it can detect and correct combinations of errors and erasures. Furthermore, Reed–Solomon codes are suitable as multiple-burst bit-error correcting codes, since a sequence of b + 1 consecutive bit errors can affect at most two symbols of size b. The choice of t is up to the designer of the code, and may be selected within wide limits.
|
||||
|
||||

|
||||
|
||||
Setting parameters of RS-Code with ```-datashard 10 -parityshard 3```
|
||||
|
||||
### *Snappy Stream Compression* :lollipop:
|
||||
> Snappy is a compression/decompression library. It does not aim for maximum
|
||||
> compression, or compatibility with any other compression library; instead,
|
||||
> it aims for very high speeds and reasonable compression. For instance,
|
||||
> compared to the fastest mode of zlib, Snappy is an order of magnitude faster
|
||||
> for most inputs, but the resulting compressed files are anywhere from 20% to
|
||||
> 100% bigger.
|
||||
|
||||
> Reference: http://google.github.io/snappy/
|
||||
|
||||
disable compression by setting ```-nocomp``` on both side.
|
||||
|
||||
> Tips: Turning off compression may reduce latency.
|
||||
|
||||
### *SNMP* :lollipop:
|
||||
```go
|
||||
// Snmp defines network statistics indicator
|
||||
type Snmp struct {
|
||||
BytesSent uint64 // payload bytes sent
|
||||
BytesReceived uint64
|
||||
MaxConn uint64
|
||||
ActiveOpens uint64
|
||||
PassiveOpens uint64
|
||||
CurrEstab uint64
|
||||
InErrs uint64
|
||||
InCsumErrors uint64 // checksum errors
|
||||
InSegs uint64
|
||||
OutSegs uint64
|
||||
OutBytes uint64 // udp bytes sent
|
||||
RetransSegs uint64
|
||||
FastRetransSegs uint64
|
||||
EarlyRetransSegs uint64
|
||||
LostSegs uint64
|
||||
RepeatSegs uint64
|
||||
FECRecovered uint64
|
||||
FECErrs uint64
|
||||
FECSegs uint64 // fec segments received
|
||||
}
|
||||
```
|
||||
|
||||
Sending a signal by ```kill -SIGUSR1 pid``` will give SNMP information for KCP,useful for fine-grained adjustment.
|
||||
Of which ```RetransSegs,FastRetransSegs,LostSegs,OutSegs``` is the most useful.
|
||||
|
||||
### *Donations* :dollar:
|
||||

|
||||
|
||||
All donations to this project will be used on the R&D of [gonet/2](http://gonet2.github.io/).
|
||||
|
||||
### *References* :paperclip:
|
||||
1. https://github.com/skywind3000/kcp -- KCP - A Fast and Reliable ARQ Protocol.
|
||||
2. https://github.com/klauspost/reedsolomon -- Reed-Solomon Erasure Coding in Go.
|
||||
3. https://en.wikipedia.org/wiki/Differentiated_services -- DSCP.
|
||||
4. http://google.github.io/snappy/ -- A fast compressor/decompressor.
|
||||
5. https://www.backblaze.com/blog/reed-solomon/ -- Reed-Solomon Explained.
|
||||
6. http://www.qualcomm.cn/products/raptorq -- RaptorQ Forward Error Correction Scheme for Object Delivery.
|
||||
7. https://en.wikipedia.org/wiki/PBKDF2 -- Key stretching.
|
||||
8. http://blog.appcanary.com/2016/encrypt-or-compress.html -- Should you encrypt or compress first?
|
||||
9. https://github.com/hashicorp/yamux -- Connection multiplexing library.
|
||||
10. https://tools.ietf.org/html/rfc6937 -- Proportional Rate Reduction for TCP.
|
||||
11. https://tools.ietf.org/html/rfc5827 -- Early Retransmit for TCP and Stream Control Transmission Protocol (SCTP).
|
||||
12. http://http2.github.io/ -- What is HTTP/2?
|
||||
13. http://www.lartc.org/ -- Linux Advanced Routing & Traffic Control
|
||||
@@ -1,48 +1,199 @@
|
||||
# <img src="logo.png" alt="kcptun" height="60px" />
|
||||
[![GoDoc][1]][2] [![Build Status][3]][4] [![Go Report Card][5]][6] [![Coverage Statusd][7]][8]
|
||||
[1]: https://godoc.org/github.com/xtaci/kcptun?status.svg
|
||||
[2]: https://godoc.org/github.com/xtaci/kcptun
|
||||
[![Release][13]][14] [![Powered][17]][18] [![MIT licensed][11]][12] [![Build Status][3]][4] [![Go Report Card][5]][6] [![Downloads][15]][16] [![Gitter][19]][20] [![Docker][1]][2]
|
||||
[1]: https://images.microbadger.com/badges/image/xtaci/kcptun.svg
|
||||
[2]: https://microbadger.com/images/xtaci/kcptun
|
||||
[3]: https://travis-ci.org/xtaci/kcptun.svg?branch=master
|
||||
[4]: https://travis-ci.org/xtaci/kcptun
|
||||
[5]: https://goreportcard.com/badge/xtaci/kcptun
|
||||
[6]: https://goreportcard.com/report/xtaci/kcptun
|
||||
[7]: https://coveralls.io/repos/github/xtaci/kcptun/badge.svg?branch=master
|
||||
[8]: https://coveralls.io/github/xtaci/kcptun?branch=master
|
||||
[5]: https://goreportcard.com/badge/github.com/xtaci/kcptun
|
||||
[6]: https://goreportcard.com/report/github.com/xtaci/kcptun
|
||||
[7]: https://img.shields.io/badge/license-MIT-blue.svg
|
||||
[8]: https://raw.githubusercontent.com/xtaci/kcptun/master/LICENSE.md
|
||||
[11]: https://img.shields.io/badge/license-MIT-blue.svg
|
||||
[12]: LICENSE.md
|
||||
[13]: https://img.shields.io/github/release/xtaci/kcptun.svg
|
||||
[14]: https://github.com/xtaci/kcptun/releases/latest
|
||||
[15]: https://img.shields.io/github/downloads/xtaci/kcptun/total.svg?maxAge=1800
|
||||
[16]: https://github.com/xtaci/kcptun/releases
|
||||
[17]: https://img.shields.io/badge/KCP-Powered-blue.svg
|
||||
[18]: https://github.com/skywind3000/kcp
|
||||
[19]: https://badges.gitter.im/xtaci/kcptun.svg
|
||||
[20]: https://gitter.im/xtaci/kcptun?utm_source=badge&utm_medium=badge&utm_campaign=pr-badge
|
||||
|
||||
TCP流转换为KCP+UDP流,:zap:***[下载地址](https://github.com/xtaci/kcptun/releases/latest)***:zap:工作示意图:
|
||||
***[kcp-go](https://github.com/xtaci/kcp-go)协议测试小工具 :zap: [官方下载地址](https://github.com/xtaci/kcptun/releases/latest):zap:***
|
||||
|
||||

|
||||
|
||||
***kcptun是[kcp](https://github.com/xtaci/kcp-go)协议的一个简单应用,可以用于任意tcp网络程序的传输承载,以提高在丢包环境下的网络流畅度。***
|
||||
_采用极简设计,客户端+服务器源码总共400行,方便用户自己扩展_ 。
|
||||
|
||||
[English Readme](README.en.md)
|
||||
### *快速设定* :lollipop:
|
||||
```
|
||||
服务器: ./server_linux_amd64 -t "127.0.0.1:1080" -l ":554" -mode fast2 // 转发到本地1080端口
|
||||
客户端: ./client_darwin_amd64 -r "IP地址:554" -l ":1080" -mode fast2 // 监听本地1080端口
|
||||
服务器: ./server_linux_amd64 -t "127.0.0.1:8388" -l ":4000" -mode fast2 // 转发到服务器的本地8388端口
|
||||
客户端: ./client_darwin_amd64 -r "服务器IP地址:4000" -l ":8388" -mode fast2 // 监听客户端的本地8388端口
|
||||
注: 服务器端需要有服务监听8388端口
|
||||
```
|
||||
|
||||
### *使用の方法* :lollipop:
|
||||

|
||||

|
||||
### *速度对比* :lollipop:
|
||||
<img src="fast.png" alt="fast.com" height="256px" />
|
||||
* 测速网站: https://fast.com
|
||||
* 接入: 100M ADSL
|
||||
* WIFI: 5GHz TL-WDR3320
|
||||
|
||||
### *适用范围限定* :lollipop:
|
||||
1. 实时网络游戏的数据传输
|
||||
2. 跨运营商的流量传输
|
||||
3. 其他高丢包通信链路的TCP承载
|
||||
### *使用方法* :lollipop:
|
||||
在Mac OS X El Capitan下的帮助输出:
|
||||
```
|
||||
$ ./client_darwin_amd64 -h
|
||||
NAME:
|
||||
kcptun - kcptun client
|
||||
|
||||
### *推荐参数* :lollipop:
|
||||
USAGE:
|
||||
client_darwin_amd64 [global options] command [command options] [arguments...]
|
||||
|
||||
VERSION:
|
||||
20160820
|
||||
|
||||
COMMANDS:
|
||||
help, h Shows a list of commands or help for one command
|
||||
|
||||
GLOBAL OPTIONS:
|
||||
--localaddr value, -l value local listen address (default: ":12948")
|
||||
--remoteaddr value, -r value kcp server address (default: "vps:29900")
|
||||
--key value pre-shared secret for client and server (default: "it's a secrect") [$KCPTUN_KEY]
|
||||
--crypt value aes, aes-128, aes-192, salsa20, blowfish, twofish, cast5, 3des, tea, xtea, xor, none (default: "aes")
|
||||
--mode value profiles: fast3, fast2, fast, normal (default: "fast")
|
||||
--conn value set num of UDP connections to server (default: 1)
|
||||
--mtu value set maximum transmission unit of UDP packets (default: 1350)
|
||||
--sndwnd value set send window size(num of packets) (default: 128)
|
||||
--rcvwnd value set receive window size(num of packets) (default: 1024)
|
||||
--datashard value set reed-solomon erasure coding - datashard (default: 10)
|
||||
--parityshard value set reed-solomon erasure coding - parityshard (default: 3)
|
||||
--dscp value set DSCP(6bit) (default: 0)
|
||||
--nocomp disable compression
|
||||
--help, -h show help
|
||||
--version, -v print the version
|
||||
|
||||
|
||||
$ ./server_darwin_amd64 -h
|
||||
NAME:
|
||||
kcptun - kcptun server
|
||||
|
||||
USAGE:
|
||||
server_darwin_amd64 [global options] command [command options] [arguments...]
|
||||
|
||||
VERSION:
|
||||
20160820
|
||||
|
||||
COMMANDS:
|
||||
help, h Shows a list of commands or help for one command
|
||||
|
||||
GLOBAL OPTIONS:
|
||||
--listen value, -l value kcp server listen address (default: ":29900")
|
||||
--target value, -t value target server address (default: "127.0.0.1:12948")
|
||||
--key value pre-shared secret for client and server (default: "it's a secrect") [$KCPTUN_KEY]
|
||||
--crypt value aes, aes-128, aes-192, salsa20, blowfish, twofish, cast5, 3des, tea, xtea, xor, none (default: "aes")
|
||||
--mode value profiles: fast3, fast2, fast, normal (default: "fast")
|
||||
--mtu value set maximum transmission unit of UDP packets (default: 1350)
|
||||
--sndwnd value set send window size(num of packets) (default: 1024)
|
||||
--rcvwnd value set receive window size(num of packets) (default: 1024)
|
||||
--datashard value set reed-solomon erasure coding - datashard (default: 10)
|
||||
--parityshard value set reed-solomon erasure coding - parityshard (default: 3)
|
||||
--dscp value set DSCP(6bit) (default: 0)
|
||||
--nocomp disable compression
|
||||
--help, -h show help
|
||||
--version, -v print the version
|
||||
```
|
||||
适用大部分ADSL接入(非对称上下行)的参数(实验环境电信100M ADSL)
|
||||
SERVER: -mtu 1400 -sndwnd 2048 -rcvwnd 2048 -mode fast2
|
||||
CLIENT: -mtu 1400 -sndwnd 256 -rcvwnd 2048 -mode fast2 -dscp 46
|
||||
其它带宽请按比例降低窗口,比如50M ADSL,把CLIENT的 -sndwnd -rcvwnd减掉一半,SERVER不变
|
||||
|
||||
### *参数调整* :lollipop:
|
||||
***两端参数必须一致的有:***
|
||||
* datashard
|
||||
* parityshard
|
||||
* nocomp
|
||||
* key
|
||||
* crypt
|
||||
|
||||
其余为两边可独立设定的参数
|
||||
|
||||
*简易自我调优方法*:
|
||||
> 第一步:同时在两端逐步增大client rcvwnd和server sndwnd;
|
||||
> 第二步:尝试下载,观察如果带宽利用率(服务器+客户端两端都要观察)接近物理带宽则停止,否则跳转到第一步。
|
||||
|
||||
***注意:产生大量重传时,一定是窗口偏大了***
|
||||
|
||||
*带宽计算公式*:
|
||||
```
|
||||
*巭孬嫑乱动*
|
||||
在不丢包的情况下,有最大-rcvwnd 个数据包在网络上正在向你传输,以平均数据包大小avgsize计算,在任意时刻,有:
|
||||
|
||||
network_cap = rcvwnd*avgsize
|
||||
|
||||
数据流向你,这个值再除以ping值(rtt),等于最大带宽使用量。
|
||||
|
||||
max_bandwidth = network_cap/rtt = rcvwnd*avgsize/rtt
|
||||
|
||||
举例,设rcvwnd = 1024, avgsize = 1KB, rtt = 400ms,则:
|
||||
|
||||
max_bandwidth = 1024 * 1KB / 400ms = 2.5MB/s ~= 25Mbps
|
||||
|
||||
(注:以上计算不包括前向纠错的数据量)
|
||||
|
||||
前向纠错是最大带宽量的一个固定比例增加:
|
||||
|
||||
max_bandwidth_fec = max_bandwidth*(datashard+parityshard)/datashard
|
||||
|
||||
举例,设datashard = 10 , partiyshard = 3,则:
|
||||
|
||||
max_bandwidth_fec = max_bandwidth * (10 + 3) /10 = 1.3*max_bandwidth = 1.3 * 25Mbps = 32.5Mbps
|
||||
```
|
||||
|
||||
### *安全* :lollipop:
|
||||
无论你上层如何加密,如果```-crypt none```,那么协议头部都是***明文***的,建议至少采用```-crypt aes-128```加密。
|
||||
|
||||
注意: ```-crypt xor``` 也是不安全的,除非你知道你在做什么。
|
||||
|
||||
### *内存控制* :lollipop:
|
||||
路由器,手机等嵌入式设备通常对内存用量敏感,通过调节环境变量GOGC(例如GOGC=20)后启动client,可以降低内存使用。
|
||||
参考:https://blog.golang.org/go15gc
|
||||
|
||||
### *流量控制* :lollipop:
|
||||
***必要性: 针对流量敏感的服务器,做双保险。***
|
||||
|
||||
> 基本原则: SERVER的发送速率不能超过ADSL下行带宽,否则只会浪费您的服务器带宽。
|
||||
|
||||
在server通过linux tc,可以限制服务器发送带宽。
|
||||
举例: 用linux tc限制server发送带宽为32mbit/s:
|
||||
```
|
||||
root@kcptun:~# cat tc.sh
|
||||
tc qdisc del dev eth0 root
|
||||
tc qdisc add dev eth0 root handle 1: htb
|
||||
tc class add dev eth0 parent 1: classid 1:1 htb rate 32mbit
|
||||
tc filter add dev eth0 protocol ip parent 1:0 prio 1 handle 10 fw flowid 1:1
|
||||
iptables -t mangle -A POSTROUTING -o eth0 -j MARK --set-mark 10
|
||||
root@kcptun:~#
|
||||
```
|
||||
其中eth0为网卡,有些服务器为ens3,有些为p2p1,通过ifconfig查询修改。
|
||||
|
||||
|
||||
### *DSCP* :lollipop:
|
||||
DSCP差分服务代码点(Differentiated Services Code Point),IETF于1998年12月发布了Diff-Serv(Differentiated Service)的QoS分类标准。它在每个数据包IP头部的服务类别TOS标识字节中,利用已使用的6比特和未使用的2比特,通过编码值来区分优先级。
|
||||
常用DSCP值可以参考[Wikipedia DSCP](https://en.wikipedia.org/wiki/Differentiated_services#Commonly_used_DSCP_values),至于有没有用,完全取决于数据包经过的设备。
|
||||
常用DSCP值可以参考[Wikipedia DSCP](https://en.wikipedia.org/wiki/Differentiated_services#Commonly_used_DSCP_values),至于有没有用,完全取决于数据包经过的设备。
|
||||
|
||||
通过 ```-dscp ``` 参数指定dscp值,两端可分别设定。
|
||||
|
||||
### *前向纠错* :lollipop:
|
||||
前向纠错采用Reed Solomon纠删码, 它的基本原理如下: 给定n个数据块d1, d2,…, dn,n和一个正整数m, RS根据n个数据块生成m个校验块, c1, c2,…, cm。 对于任意的n和m, 从n个原始数据块和m 个校验块中任取n块就能解码出原始数据, 即RS最多容忍m个数据块或者校验块同时丢失。
|
||||
|
||||

|
||||
|
||||
通过参数```-datashard 10 -parityshard 3``` 在两端同时设定。
|
||||
|
||||
### *Snappy数据流压缩* :lollipop:
|
||||
> Snappy is a compression/decompression library. It does not aim for maximum
|
||||
> compression, or compatibility with any other compression library; instead,
|
||||
> it aims for very high speeds and reasonable compression. For instance,
|
||||
> compared to the fastest mode of zlib, Snappy is an order of magnitude faster
|
||||
> for most inputs, but the resulting compressed files are anywhere from 20% to
|
||||
> 100% bigger.
|
||||
|
||||
> Reference: http://google.github.io/snappy/
|
||||
|
||||
通过参数 ```-nocomp``` 在两端同时设定以关闭压缩。
|
||||
> 提示: 关闭压缩可能会降低延迟。
|
||||
|
||||
### *内置模式* :lollipop:
|
||||
响应速度:
|
||||
@@ -54,13 +205,7 @@ DSCP差分服务代码点(Differentiated Services Code Point),IETF于1998
|
||||
```
|
||||
-mode manual -nodelay 1 -resend 2 -nc 1 -interval 20
|
||||
```
|
||||
|
||||
### *前向纠错* :lollipop:
|
||||
前向纠错采用Reed Solomon纠删码, 它的基本原理如下: 给定n个数据块d1, d2,…, dn,n和一个正整数m, RS根据n个数据块生成m个校验块, c1, c2,…, cm。 对于任意的n和m, 从n个原始数据块和m 个校验块中任取n块就能解码出原始数据, 即RS最多容忍m个数据块或者校验块同时丢失。
|
||||
|
||||

|
||||
|
||||
通过```-datashard 10 -parityshard 3``` 可以调整Reed Solomon参数。
|
||||
高丢包率的网络建议采用fast2, 低丢包率的网络,建议采用normal。
|
||||
|
||||
### *SNMP* :lollipop:
|
||||
```go
|
||||
@@ -91,21 +236,39 @@ type Snmp struct {
|
||||
使用```kill -SIGUSR1 pid``` 可以在控制台打印出SNMP信息,通常用于精细调整***当前链路的有效载荷比***。
|
||||
观察```RetransSegs,FastRetransSegs,LostSegs,OutSegs```这几者的数值比例,用于参考调整```-mode manual,fec```的参数。
|
||||
|
||||
### *性能对比* :lollipop:
|
||||
```
|
||||
root@vultr:~# iperf -s
|
||||
------------------------------------------------------------
|
||||
Server listening on TCP port 5001
|
||||
TCP window size: 4.00 MByte (default)
|
||||
------------------------------------------------------------
|
||||
[ 4] local 172.7.7.1 port 5001 connected with 172.7.7.2 port 55453
|
||||
[ ID] Interval Transfer Bandwidth
|
||||
[ 4] 0.0-18.0 sec 5.50 MBytes 2.56 Mbits/sec <-- connection via kcptun
|
||||
[ 5] local 45.32.xxx.xxx port 5001 connected with 218.88.xxx.xxx port 17220
|
||||
[ 5] 0.0-17.9 sec 2.12 MBytes 997 Kbits/sec <-- direct connnection via tcp
|
||||
```
|
||||
### *故障排除* :lollipop:
|
||||
> Q: 客户端和服务器端***皆无*** ```stream opened```信息。
|
||||
> A: 连接客户端程序的端口设置错误。
|
||||
|
||||
> Q: 客户端有 ```stream opened```信息,服务器端没有。
|
||||
> A: 连接服务器的端口设置错误,或者被防火墙拦截。
|
||||
|
||||
> Q: 客户端服务器***皆有*** ```stream opened```信息,但无法通信。
|
||||
> A: 上层软件的设定错误。
|
||||
|
||||
### *免责申明* :warning:
|
||||
用户以各种方式使用本软件(包括但不限于修改使用、直接使用、通过第三方使用)的过程中,不得以任何方式利用本软件直接或间接从事违反中国法律、以及社会公德的行为。软件的使用者需对自身行为负责,因使用软件引发的一切纠纷,由使用者承担全部法律及连带责任。作者不承担任何法律及连带责任。
|
||||
|
||||
对免责声明的解释、修改及更新权均属于作者本人所有。
|
||||
|
||||
### *捐赠* :dollar:
|
||||

|
||||
|
||||
对该项目的捐款将用于[gonet/2](http://gonet2.github.io/)游戏服务器框架的研发。
|
||||
|
||||
```特别感谢: 郑H立, 南D风, Li, 七q, 凌J,昶,Les*ables, Ky*n, 噼**啦, 等,名字已做特殊处理。```
|
||||
|
||||
### *参考资料* :paperclip:
|
||||
1. https://github.com/skywind3000/kcp -- KCP - A Fast and Reliable ARQ Protocol.
|
||||
2. https://github.com/klauspost/reedsolomon -- Reed-Solomon Erasure Coding in Go.
|
||||
3. https://en.wikipedia.org/wiki/Differentiated_services -- DSCP.
|
||||
4. http://google.github.io/snappy/ -- A fast compressor/decompressor.
|
||||
5. https://www.backblaze.com/blog/reed-solomon/ -- Reed-Solomon Explained.
|
||||
6. http://www.qualcomm.cn/products/raptorq -- RaptorQ Forward Error Correction Scheme for Object Delivery.
|
||||
7. https://en.wikipedia.org/wiki/PBKDF2 -- Key stretching.
|
||||
8. http://blog.appcanary.com/2016/encrypt-or-compress.html -- Should you encrypt or compress first?
|
||||
9. https://github.com/hashicorp/yamux -- Connection multiplexing library.
|
||||
10. https://tools.ietf.org/html/rfc6937 -- Proportional Rate Reduction for TCP.
|
||||
11. https://tools.ietf.org/html/rfc5827 -- Early Retransmit for TCP and Stream Control Transmission Protocol (SCTP).
|
||||
12. http://http2.github.io/ -- What is HTTP/2?
|
||||
13. http://www.lartc.org/LARTC-zh_CN.GB2312.pdf -- Linux Advanced Routing & Traffic Control
|
||||
|
||||
+5
-4
@@ -12,6 +12,7 @@ fi
|
||||
|
||||
VERSION=`date -u +%Y%m%d`
|
||||
LDFLAGS="-X main.VERSION=$VERSION -s -w"
|
||||
GCFLAGS="-B"
|
||||
|
||||
OSES=(linux darwin windows freebsd)
|
||||
ARCHS=(amd64 386)
|
||||
@@ -22,8 +23,8 @@ for os in ${OSES[@]}; do
|
||||
then
|
||||
suffix=".exe"
|
||||
fi
|
||||
env GOOS=$os GOARCH=$arch go build -ldflags "$LDFLAGS" -o client_${os}_${arch}${suffix} github.com/xtaci/kcptun/client
|
||||
env GOOS=$os GOARCH=$arch go build -ldflags "$LDFLAGS" -o server_${os}_${arch}${suffix} github.com/xtaci/kcptun/server
|
||||
env CGO_ENABLED=0 GOOS=$os GOARCH=$arch go build -ldflags "$LDFLAGS" -gcflags "$GCFLAGS" -o client_${os}_${arch}${suffix} github.com/xtaci/kcptun/client
|
||||
env CGO_ENABLED=0 GOOS=$os GOARCH=$arch go build -ldflags "$LDFLAGS" -gcflags "$GCFLAGS" -o server_${os}_${arch}${suffix} github.com/xtaci/kcptun/server
|
||||
if $UPX; then upx -9 client_${os}_${arch}${suffix} server_${os}_${arch}${suffix};fi
|
||||
tar -zcf kcptun-${os}-${arch}-$VERSION.tar.gz client_${os}_${arch}${suffix} server_${os}_${arch}${suffix}
|
||||
$MD5 kcptun-${os}-${arch}-$VERSION.tar.gz
|
||||
@@ -33,8 +34,8 @@ done
|
||||
# ARM
|
||||
ARMS=(5 6 7)
|
||||
for v in ${ARMS[@]}; do
|
||||
env GOOS=linux GOARCH=arm GOARM=$v go build -ldflags "$LDFLAGS" -o client_linux_arm$v github.com/xtaci/kcptun/client
|
||||
env GOOS=linux GOARCH=arm GOARM=$v go build -ldflags "$LDFLAGS" -o server_linux_arm$v github.com/xtaci/kcptun/server
|
||||
env CGO_ENABLED=0 GOOS=linux GOARCH=arm GOARM=$v go build -ldflags "$LDFLAGS" -gcflags "$GCFLAGS" -o client_linux_arm$v github.com/xtaci/kcptun/client
|
||||
env CGO_ENABLED=0 GOOS=linux GOARCH=arm GOARM=$v go build -ldflags "$LDFLAGS" -gcflags "$GCFLAGS" -o server_linux_arm$v github.com/xtaci/kcptun/server
|
||||
done
|
||||
if $UPX; then upx -9 client_linux_arm* server_linux_arm*;fi
|
||||
tar -zcf kcptun-linux-arm-$VERSION.tar.gz client_linux_arm* server_linux_arm*
|
||||
|
||||
BIN
Binary file not shown.
|
Before Width: | Height: | Size: 66 KiB |
+148
-63
@@ -7,19 +7,22 @@ import (
|
||||
"math/rand"
|
||||
"net"
|
||||
"os"
|
||||
"runtime"
|
||||
"time"
|
||||
|
||||
"golang.org/x/crypto/pbkdf2"
|
||||
|
||||
"github.com/golang/snappy"
|
||||
"github.com/hashicorp/yamux"
|
||||
"github.com/urfave/cli"
|
||||
"github.com/xtaci/kcp-go"
|
||||
kcp "github.com/xtaci/kcp-go"
|
||||
"github.com/xtaci/yamux"
|
||||
)
|
||||
|
||||
var (
|
||||
// VERSION is injected by buildflags
|
||||
VERSION = "SELFBUILD"
|
||||
SALT = "kcp-go"
|
||||
// SALT is use for pbkdf2 key expansion
|
||||
SALT = "kcp-go"
|
||||
)
|
||||
|
||||
type compStream struct {
|
||||
@@ -85,6 +88,10 @@ func checkError(err error) {
|
||||
|
||||
func main() {
|
||||
rand.Seed(int64(time.Now().Nanosecond()))
|
||||
if VERSION == "SELFBUILD" {
|
||||
// add more log flags for debugging
|
||||
log.SetFlags(log.LstdFlags | log.Lshortfile)
|
||||
}
|
||||
myApp := cli.NewApp()
|
||||
myApp.Name = "kcptun"
|
||||
myApp.Usage = "kcptun client"
|
||||
@@ -103,28 +110,33 @@ func main() {
|
||||
cli.StringFlag{
|
||||
Name: "key",
|
||||
Value: "it's a secrect",
|
||||
Usage: "key for communcation, must be the same as kcptun server",
|
||||
Usage: "pre-shared secret between client and server",
|
||||
EnvVar: "KCPTUN_KEY",
|
||||
},
|
||||
cli.StringFlag{
|
||||
Name: "crypt",
|
||||
Value: "aes",
|
||||
Usage: "methods for encryption: aes, tea, xor, none",
|
||||
Usage: "aes, aes-128, aes-192, salsa20, blowfish, twofish, cast5, 3des, tea, xtea, xor, none",
|
||||
},
|
||||
cli.StringFlag{
|
||||
Name: "mode",
|
||||
Value: "fast",
|
||||
Usage: "mode for communication: fast3, fast2, fast, normal",
|
||||
Usage: "profiles: fast3, fast2, fast, normal",
|
||||
},
|
||||
cli.IntFlag{
|
||||
Name: "conn",
|
||||
Value: 1,
|
||||
Usage: "establish N physical connections as specified by 'conn' to server",
|
||||
Usage: "set num of UDP connections to server",
|
||||
},
|
||||
cli.IntFlag{
|
||||
Name: "autoexpire",
|
||||
Value: 0,
|
||||
Usage: "set auto expiration time(in seconds) for a single UDP connection, 0 to disable",
|
||||
},
|
||||
cli.IntFlag{
|
||||
Name: "mtu",
|
||||
Value: 1350,
|
||||
Usage: "set MTU of UDP packets, suggest 'tracepath' to discover path mtu",
|
||||
Usage: "set maximum transmission unit for UDP packets",
|
||||
},
|
||||
cli.IntFlag{
|
||||
Name: "sndwnd",
|
||||
@@ -136,10 +148,6 @@ func main() {
|
||||
Value: 1024,
|
||||
Usage: "set receive window size(num of packets)",
|
||||
},
|
||||
cli.BoolFlag{
|
||||
Name: "nocomp",
|
||||
Usage: "disable compression",
|
||||
},
|
||||
cli.IntFlag{
|
||||
Name: "datashard",
|
||||
Value: 10,
|
||||
@@ -151,14 +159,19 @@ func main() {
|
||||
Usage: "set reed-solomon erasure coding - parityshard",
|
||||
},
|
||||
cli.BoolFlag{
|
||||
Name: "acknodelay",
|
||||
Usage: "flush ack immediately when a packet is received",
|
||||
Name: "acknodelay",
|
||||
Usage: "flush ack immediately when a packet is received",
|
||||
Hidden: true,
|
||||
},
|
||||
cli.IntFlag{
|
||||
Name: "dscp",
|
||||
Value: 0,
|
||||
Usage: "set DSCP(6bit)",
|
||||
},
|
||||
cli.BoolFlag{
|
||||
Name: "nocomp",
|
||||
Usage: "disable compression",
|
||||
},
|
||||
cli.IntFlag{
|
||||
Name: "nodelay",
|
||||
Value: 0,
|
||||
@@ -179,14 +192,23 @@ func main() {
|
||||
Value: 0,
|
||||
Hidden: true,
|
||||
},
|
||||
cli.IntFlag{
|
||||
Name: "sockbuf",
|
||||
Value: 4194304, // socket buffer size in bytes
|
||||
Hidden: true,
|
||||
},
|
||||
cli.IntFlag{
|
||||
Name: "keepalive",
|
||||
Value: 10, // nat keepalive interval in seconds
|
||||
Hidden: true,
|
||||
},
|
||||
}
|
||||
myApp.Action = func(c *cli.Context) {
|
||||
myApp.Action = func(c *cli.Context) error {
|
||||
log.Println("version:", VERSION)
|
||||
addr, err := net.ResolveTCPAddr("tcp", c.String("localaddr"))
|
||||
checkError(err)
|
||||
listener, err := net.ListenTCP("tcp", addr)
|
||||
checkError(err)
|
||||
pass := pbkdf2.Key([]byte(c.String("key")), []byte(SALT), 4096, 32, sha1.New)
|
||||
|
||||
// kcp server
|
||||
nodelay, interval, resend, nc := c.Int("nodelay"), c.Int("interval"), c.Int("resend"), c.Int("nc")
|
||||
@@ -202,75 +224,138 @@ func main() {
|
||||
nodelay, interval, resend, nc = 1, 10, 2, 1
|
||||
}
|
||||
|
||||
log.Println("listening on:", listener.Addr())
|
||||
log.Println("encryption:", c.String("crypt"))
|
||||
log.Println("nodelay parameters:", nodelay, interval, resend, nc)
|
||||
log.Println("remote address:", c.String("remoteaddr"))
|
||||
log.Println("sndwnd:", c.Int("sndwnd"), "rcvwnd:", c.Int("rcvwnd"))
|
||||
log.Println("compression:", !c.Bool("nocomp"))
|
||||
log.Println("mtu:", c.Int("mtu"))
|
||||
log.Println("datashard:", c.Int("datashard"), "parityshard:", c.Int("parityshard"))
|
||||
log.Println("acknodelay:", c.Bool("acknodelay"))
|
||||
log.Println("dscp:", c.Int("dscp"))
|
||||
log.Println("conn:", c.Int("conn"))
|
||||
crypt := c.String("crypt")
|
||||
pass := pbkdf2.Key([]byte(c.String("key")), []byte(SALT), 4096, 32, sha1.New)
|
||||
var block kcp.BlockCrypt
|
||||
switch c.String("crypt") {
|
||||
case "tea":
|
||||
block, _ = kcp.NewTEABlockCrypt(pass[:16])
|
||||
case "xor":
|
||||
block, _ = kcp.NewSimpleXORBlockCrypt(pass)
|
||||
case "none":
|
||||
block, _ = kcp.NewNoneBlockCrypt(pass)
|
||||
case "aes-128":
|
||||
block, _ = kcp.NewAESBlockCrypt(pass[:16])
|
||||
case "aes-192":
|
||||
block, _ = kcp.NewAESBlockCrypt(pass[:24])
|
||||
case "blowfish":
|
||||
block, _ = kcp.NewBlowfishBlockCrypt(pass)
|
||||
case "twofish":
|
||||
block, _ = kcp.NewTwofishBlockCrypt(pass)
|
||||
case "cast5":
|
||||
block, _ = kcp.NewCast5BlockCrypt(pass[:16])
|
||||
case "3des":
|
||||
block, _ = kcp.NewTripleDESBlockCrypt(pass[:24])
|
||||
case "xtea":
|
||||
block, _ = kcp.NewXTEABlockCrypt(pass[:16])
|
||||
case "salsa20":
|
||||
block, _ = kcp.NewSalsa20BlockCrypt(pass)
|
||||
default:
|
||||
crypt = "aes"
|
||||
block, _ = kcp.NewAESBlockCrypt(pass)
|
||||
}
|
||||
|
||||
remoteaddr := c.String("remoteaddr")
|
||||
datashard, parityshard := c.Int("datashard"), c.Int("parityshard")
|
||||
mtu, sndwnd, rcvwnd := c.Int("mtu"), c.Int("sndwnd"), c.Int("rcvwnd")
|
||||
nocomp, acknodelay := c.Bool("nocomp"), c.Bool("acknodelay")
|
||||
dscp, sockbuf, keepalive, conn := c.Int("dscp"), c.Int("sockbuf"), c.Int("keepalive"), c.Int("conn")
|
||||
autoexpire := c.Int("autoexpire")
|
||||
|
||||
log.Println("listening on:", listener.Addr())
|
||||
log.Println("encryption:", crypt)
|
||||
log.Println("nodelay parameters:", nodelay, interval, resend, nc)
|
||||
log.Println("remote address:", remoteaddr)
|
||||
log.Println("sndwnd:", sndwnd, "rcvwnd:", rcvwnd)
|
||||
log.Println("compression:", !nocomp)
|
||||
log.Println("mtu:", mtu)
|
||||
log.Println("datashard:", datashard, "parityshard:", parityshard)
|
||||
log.Println("acknodelay:", acknodelay)
|
||||
log.Println("dscp:", dscp)
|
||||
log.Println("sockbuf:", sockbuf)
|
||||
log.Println("keepalive:", keepalive)
|
||||
log.Println("conn:", conn)
|
||||
log.Println("autoexpire:", autoexpire)
|
||||
|
||||
config := &yamux.Config{
|
||||
AcceptBacklog: 256,
|
||||
EnableKeepAlive: true,
|
||||
KeepAliveInterval: 30 * time.Second,
|
||||
ConnectionWriteTimeout: 10 * time.Second,
|
||||
MaxStreamWindowSize: uint32(sockbuf),
|
||||
LogOutput: os.Stderr,
|
||||
}
|
||||
createConn := func() *yamux.Session {
|
||||
var block kcp.BlockCrypt
|
||||
switch c.String("crypt") {
|
||||
case "tea":
|
||||
block, _ = kcp.NewTEABlockCrypt(pass[:16])
|
||||
case "xor":
|
||||
block, _ = kcp.NewSimpleXORBlockCrypt(pass)
|
||||
case "none":
|
||||
block, _ = kcp.NewNoneBlockCrypt(pass)
|
||||
default:
|
||||
block, _ = kcp.NewAESBlockCrypt(pass)
|
||||
}
|
||||
kcpconn, err := kcp.DialWithOptions(c.String("remoteaddr"), block, c.Int("datashard"), c.Int("parityshard"))
|
||||
kcpconn, err := kcp.DialWithOptions(remoteaddr, block, datashard, parityshard)
|
||||
checkError(err)
|
||||
kcpconn.SetStreamMode(true)
|
||||
kcpconn.SetNoDelay(nodelay, interval, resend, nc)
|
||||
kcpconn.SetWindowSize(c.Int("sndwnd"), c.Int("rcvwnd"))
|
||||
kcpconn.SetMtu(c.Int("mtu"))
|
||||
kcpconn.SetACKNoDelay(c.Bool("acknodelay"))
|
||||
kcpconn.SetDSCP(c.Int("dscp"))
|
||||
kcpconn.SetWindowSize(sndwnd, rcvwnd)
|
||||
kcpconn.SetMtu(mtu)
|
||||
kcpconn.SetACKNoDelay(acknodelay)
|
||||
kcpconn.SetKeepAlive(keepalive)
|
||||
|
||||
if err := kcpconn.SetDSCP(dscp); err != nil {
|
||||
log.Println("SetDSCP:", err)
|
||||
}
|
||||
if err := kcpconn.SetReadBuffer(sockbuf); err != nil {
|
||||
log.Println("SetReadBuffer:", err)
|
||||
}
|
||||
if err := kcpconn.SetWriteBuffer(sockbuf); err != nil {
|
||||
log.Println("SetWriteBuffer:", err)
|
||||
}
|
||||
|
||||
// stream multiplex
|
||||
config := &yamux.Config{
|
||||
AcceptBacklog: 256,
|
||||
EnableKeepAlive: true,
|
||||
KeepAliveInterval: 30 * time.Second,
|
||||
ConnectionWriteTimeout: 30 * time.Second,
|
||||
MaxStreamWindowSize: 16777216,
|
||||
LogOutput: os.Stderr,
|
||||
}
|
||||
var session *yamux.Session
|
||||
if c.Bool("nocomp") {
|
||||
if nocomp {
|
||||
session, err = yamux.Client(kcpconn, config)
|
||||
} else {
|
||||
session, err = yamux.Client(newCompStream(kcpconn), config)
|
||||
}
|
||||
checkError(err)
|
||||
runtime.SetFinalizer(session, func(s *yamux.Session) {
|
||||
s.Close()
|
||||
})
|
||||
return session
|
||||
}
|
||||
|
||||
numconn := uint16(c.Int("conn"))
|
||||
var muxes []*yamux.Session
|
||||
for i := uint16(0); i < numconn; i++ {
|
||||
muxes = append(muxes, createConn())
|
||||
numconn := uint16(conn)
|
||||
muxes := make([]struct {
|
||||
session *yamux.Session
|
||||
ttl time.Time
|
||||
}, numconn)
|
||||
|
||||
for k := range muxes {
|
||||
muxes[k].session = createConn()
|
||||
muxes[k].ttl = time.Now().Add(time.Duration(autoexpire) * time.Second)
|
||||
}
|
||||
|
||||
rr := uint16(0)
|
||||
for {
|
||||
p1, err := listener.AcceptTCP()
|
||||
if err := p1.SetReadBuffer(sockbuf); err != nil {
|
||||
log.Println("TCP SetReadBuffer:", err)
|
||||
}
|
||||
if err := p1.SetWriteBuffer(sockbuf); err != nil {
|
||||
log.Println("TCP SetWriteBuffer:", err)
|
||||
}
|
||||
checkError(err)
|
||||
mux := muxes[rr%numconn]
|
||||
p2, err := mux.Open()
|
||||
idx := rr % numconn
|
||||
|
||||
OPEN_P2:
|
||||
// do auto expiration
|
||||
if autoexpire > 0 && time.Now().After(muxes[idx].ttl) {
|
||||
log.Println("autoexpired")
|
||||
muxes[idx].session = createConn()
|
||||
muxes[idx].ttl = time.Now().Add(time.Duration(autoexpire) * time.Second)
|
||||
}
|
||||
|
||||
// do session open
|
||||
p2, err := muxes[idx].session.Open()
|
||||
if err != nil { // yamux failure
|
||||
log.Println(err)
|
||||
p1.Close()
|
||||
mux.Close()
|
||||
muxes[rr%numconn] = createConn()
|
||||
continue
|
||||
muxes[idx].session = createConn()
|
||||
muxes[idx].ttl = time.Now().Add(time.Duration(autoexpire) * time.Second)
|
||||
goto OPEN_P2
|
||||
}
|
||||
go handleClient(p1, p2)
|
||||
rr++
|
||||
|
||||
+1
-1
@@ -8,7 +8,7 @@ import (
|
||||
"os/signal"
|
||||
"syscall"
|
||||
|
||||
"github.com/xtaci/kcp-go"
|
||||
kcp "github.com/xtaci/kcp-go"
|
||||
)
|
||||
|
||||
func init() {
|
||||
|
||||
BIN
Binary file not shown.
|
After Width: | Height: | Size: 4.3 KiB |
Binary file not shown.
|
After Width: | Height: | Size: 6.8 KiB |
BIN
Binary file not shown.
|
Before Width: | Height: | Size: 63 KiB |
+110
-49
@@ -12,14 +12,16 @@ import (
|
||||
"golang.org/x/crypto/pbkdf2"
|
||||
|
||||
"github.com/golang/snappy"
|
||||
"github.com/hashicorp/yamux"
|
||||
"github.com/urfave/cli"
|
||||
"github.com/xtaci/kcp-go"
|
||||
kcp "github.com/xtaci/kcp-go"
|
||||
"github.com/xtaci/yamux"
|
||||
)
|
||||
|
||||
var (
|
||||
// VERSION is injected by buildflags
|
||||
VERSION = "SELFBUILD"
|
||||
SALT = "kcp-go"
|
||||
// SALT is use for pbkdf2 key expansion
|
||||
SALT = "kcp-go"
|
||||
)
|
||||
|
||||
type compStream struct {
|
||||
@@ -51,36 +53,34 @@ func newCompStream(conn net.Conn) *compStream {
|
||||
}
|
||||
|
||||
// handle multiplex-ed connection
|
||||
func handleMux(conn io.ReadWriteCloser, target string) {
|
||||
func handleMux(conn io.ReadWriteCloser, target string, config *yamux.Config) {
|
||||
// stream multiplex
|
||||
var mux *yamux.Session
|
||||
config := &yamux.Config{
|
||||
AcceptBacklog: 256,
|
||||
EnableKeepAlive: true,
|
||||
KeepAliveInterval: 30 * time.Second,
|
||||
ConnectionWriteTimeout: 30 * time.Second,
|
||||
MaxStreamWindowSize: 16777216,
|
||||
LogOutput: os.Stderr,
|
||||
}
|
||||
m, err := yamux.Server(conn, config)
|
||||
mux, err := yamux.Server(conn, config)
|
||||
if err != nil {
|
||||
log.Println(err)
|
||||
return
|
||||
}
|
||||
mux = m
|
||||
defer mux.Close()
|
||||
|
||||
for {
|
||||
p1, err := mux.Accept()
|
||||
if err != nil {
|
||||
log.Println(err)
|
||||
return
|
||||
}
|
||||
sockbuf := int(config.MaxStreamWindowSize)
|
||||
p2, err := net.DialTimeout("tcp", target, 5*time.Second)
|
||||
if err != nil {
|
||||
log.Println(err)
|
||||
return
|
||||
}
|
||||
|
||||
if err := p2.(*net.TCPConn).SetReadBuffer(sockbuf); err != nil {
|
||||
log.Println("TCP SetReadBuffer:", err)
|
||||
}
|
||||
if err := p2.(*net.TCPConn).SetWriteBuffer(sockbuf); err != nil {
|
||||
log.Println("TCP SetWriteBuffer:", err)
|
||||
}
|
||||
|
||||
go handleClient(p1, p2)
|
||||
}
|
||||
}
|
||||
@@ -113,6 +113,10 @@ func handleClient(p1, p2 io.ReadWriteCloser) {
|
||||
|
||||
func main() {
|
||||
rand.Seed(int64(time.Now().Nanosecond()))
|
||||
if VERSION == "SELFBUILD" {
|
||||
// add more log flags for debugging
|
||||
log.SetFlags(log.LstdFlags | log.Lshortfile)
|
||||
}
|
||||
myApp := cli.NewApp()
|
||||
myApp.Name = "kcptun"
|
||||
myApp.Usage = "kcptun server"
|
||||
@@ -131,23 +135,23 @@ func main() {
|
||||
cli.StringFlag{
|
||||
Name: "key",
|
||||
Value: "it's a secrect",
|
||||
Usage: "key for communcation, must be the same as kcptun client",
|
||||
Usage: "pre-shared secret between client and server",
|
||||
EnvVar: "KCPTUN_KEY",
|
||||
},
|
||||
cli.StringFlag{
|
||||
Name: "crypt",
|
||||
Value: "aes",
|
||||
Usage: "methods for encryption: aes, tea, xor, none",
|
||||
Usage: "aes, aes-128, aes-192, salsa20, blowfish, twofish, cast5, 3des, tea, xtea, xor, none",
|
||||
},
|
||||
cli.StringFlag{
|
||||
Name: "mode",
|
||||
Value: "fast",
|
||||
Usage: "mode for communication: fast3, fast2, fast, normal",
|
||||
Usage: "profiles: fast3, fast2, fast, normal",
|
||||
},
|
||||
cli.IntFlag{
|
||||
Name: "mtu",
|
||||
Value: 1350,
|
||||
Usage: "set MTU of UDP packets, suggest 'tracepath' to discover path mtu",
|
||||
Usage: "set maximum transmission unit for UDP packets",
|
||||
},
|
||||
cli.IntFlag{
|
||||
Name: "sndwnd",
|
||||
@@ -159,10 +163,6 @@ func main() {
|
||||
Value: 1024,
|
||||
Usage: "set receive window size(num of packets)",
|
||||
},
|
||||
cli.BoolFlag{
|
||||
Name: "nocomp",
|
||||
Usage: "disable compression",
|
||||
},
|
||||
cli.IntFlag{
|
||||
Name: "datashard",
|
||||
Value: 10,
|
||||
@@ -174,14 +174,19 @@ func main() {
|
||||
Usage: "set reed-solomon erasure coding - parityshard",
|
||||
},
|
||||
cli.BoolFlag{
|
||||
Name: "acknodelay",
|
||||
Usage: "flush ack immediately when a packet is received",
|
||||
Name: "acknodelay",
|
||||
Usage: "flush ack immediately when a packet is received",
|
||||
Hidden: true,
|
||||
},
|
||||
cli.IntFlag{
|
||||
Name: "dscp",
|
||||
Value: 0,
|
||||
Usage: "set DSCP(6bit)",
|
||||
},
|
||||
cli.BoolFlag{
|
||||
Name: "nocomp",
|
||||
Usage: "disable compression",
|
||||
},
|
||||
cli.IntFlag{
|
||||
Name: "nodelay",
|
||||
Value: 0,
|
||||
@@ -202,8 +207,18 @@ func main() {
|
||||
Value: 0,
|
||||
Hidden: true,
|
||||
},
|
||||
cli.IntFlag{
|
||||
Name: "sockbuf",
|
||||
Value: 4194304, // socket buffer size in bytes
|
||||
Hidden: true,
|
||||
},
|
||||
cli.IntFlag{
|
||||
Name: "keepalive",
|
||||
Value: 10, // nat keepalive interval in seconds
|
||||
Hidden: true,
|
||||
},
|
||||
}
|
||||
myApp.Action = func(c *cli.Context) {
|
||||
myApp.Action = func(c *cli.Context) error {
|
||||
log.Println("version:", VERSION)
|
||||
nodelay, interval, resend, nc := c.Int("nodelay"), c.Int("interval"), c.Int("resend"), c.Int("nc")
|
||||
switch c.String("mode") {
|
||||
@@ -217,45 +232,91 @@ func main() {
|
||||
nodelay, interval, resend, nc = 1, 10, 2, 1
|
||||
}
|
||||
|
||||
crypt := c.String("crypt")
|
||||
pass := pbkdf2.Key([]byte(c.String("key")), []byte(SALT), 4096, 32, sha1.New)
|
||||
var block kcp.BlockCrypt
|
||||
switch c.String("crypt") {
|
||||
switch crypt {
|
||||
case "tea":
|
||||
block, _ = kcp.NewTEABlockCrypt(pass[:16])
|
||||
case "xor":
|
||||
block, _ = kcp.NewSimpleXORBlockCrypt(pass)
|
||||
case "none":
|
||||
block, _ = kcp.NewNoneBlockCrypt(pass)
|
||||
case "aes-128":
|
||||
block, _ = kcp.NewAESBlockCrypt(pass[:16])
|
||||
case "aes-192":
|
||||
block, _ = kcp.NewAESBlockCrypt(pass[:24])
|
||||
case "blowfish":
|
||||
block, _ = kcp.NewBlowfishBlockCrypt(pass)
|
||||
case "twofish":
|
||||
block, _ = kcp.NewTwofishBlockCrypt(pass)
|
||||
case "cast5":
|
||||
block, _ = kcp.NewCast5BlockCrypt(pass[:16])
|
||||
case "3des":
|
||||
block, _ = kcp.NewTripleDESBlockCrypt(pass[:24])
|
||||
case "xtea":
|
||||
block, _ = kcp.NewXTEABlockCrypt(pass[:16])
|
||||
case "salsa20":
|
||||
block, _ = kcp.NewSalsa20BlockCrypt(pass)
|
||||
default:
|
||||
crypt = "aes"
|
||||
block, _ = kcp.NewAESBlockCrypt(pass)
|
||||
}
|
||||
|
||||
lis, err := kcp.ListenWithOptions(c.String("listen"), block, c.Int("datashard"), c.Int("parityshard"))
|
||||
datashard, parityshard := c.Int("datashard"), c.Int("parityshard")
|
||||
lis, err := kcp.ListenWithOptions(c.String("listen"), block, datashard, parityshard)
|
||||
if err != nil {
|
||||
log.Fatal(err)
|
||||
}
|
||||
log.Println("listening on ", lis.Addr())
|
||||
log.Println("encryption:", c.String("crypt"))
|
||||
log.Println("nodelay parameters:", nodelay, interval, resend, nc)
|
||||
log.Println("sndwnd:", c.Int("sndwnd"), "rcvwnd:", c.Int("rcvwnd"))
|
||||
log.Println("compression:", !c.Bool("nocomp"))
|
||||
log.Println("mtu:", c.Int("mtu"))
|
||||
log.Println("datashard:", c.Int("datashard"), "parityshard:", c.Int("parityshard"))
|
||||
log.Println("acknodelay:", c.Bool("acknodelay"))
|
||||
log.Println("dscp:", c.Int("dscp"))
|
||||
for {
|
||||
if conn, err := lis.Accept(); err == nil {
|
||||
log.Println("remote address:", conn.RemoteAddr())
|
||||
conn.SetNoDelay(nodelay, interval, resend, nc)
|
||||
conn.SetMtu(c.Int("mtu"))
|
||||
conn.SetWindowSize(c.Int("sndwnd"), c.Int("rcvwnd"))
|
||||
conn.SetACKNoDelay(c.Bool("acknodelay"))
|
||||
conn.SetDSCP(c.Int("dscp"))
|
||||
|
||||
if c.Bool("nocomp") {
|
||||
go handleMux(conn, c.String("target"))
|
||||
mtu, sndwnd, rcvwnd := c.Int("mtu"), c.Int("sndwnd"), c.Int("rcvwnd")
|
||||
nocomp, acknodelay := c.Bool("nocomp"), c.Bool("acknodelay")
|
||||
dscp, sockbuf, keepalive := c.Int("dscp"), c.Int("sockbuf"), c.Int("keepalive")
|
||||
target := c.String("target")
|
||||
|
||||
log.Println("listening on ", lis.Addr())
|
||||
log.Println("encryption:", crypt)
|
||||
log.Println("nodelay parameters:", nodelay, interval, resend, nc)
|
||||
log.Println("sndwnd:", sndwnd, "rcvwnd:", rcvwnd)
|
||||
log.Println("compression:", !nocomp)
|
||||
log.Println("mtu:", mtu)
|
||||
log.Println("datashard:", datashard, "parityshard:", parityshard)
|
||||
log.Println("acknodelay:", acknodelay)
|
||||
log.Println("dscp:", dscp)
|
||||
log.Println("sockbuf:", sockbuf)
|
||||
log.Println("keepalive:", keepalive)
|
||||
|
||||
if err := lis.SetDSCP(dscp); err != nil {
|
||||
log.Println("SetDSCP:", err)
|
||||
}
|
||||
if err := lis.SetReadBuffer(sockbuf); err != nil {
|
||||
log.Println("SetReadBuffer:", err)
|
||||
}
|
||||
if err := lis.SetWriteBuffer(sockbuf); err != nil {
|
||||
log.Println("SetWriteBuffer:", err)
|
||||
}
|
||||
config := &yamux.Config{
|
||||
AcceptBacklog: 256,
|
||||
EnableKeepAlive: true,
|
||||
KeepAliveInterval: 30 * time.Second,
|
||||
ConnectionWriteTimeout: 10 * time.Second,
|
||||
MaxStreamWindowSize: uint32(sockbuf),
|
||||
LogOutput: os.Stderr,
|
||||
}
|
||||
for {
|
||||
if conn, err := lis.AcceptKCP(); err == nil {
|
||||
log.Println("remote address:", conn.RemoteAddr())
|
||||
conn.SetStreamMode(true)
|
||||
conn.SetNoDelay(nodelay, interval, resend, nc)
|
||||
conn.SetMtu(mtu)
|
||||
conn.SetWindowSize(sndwnd, rcvwnd)
|
||||
conn.SetACKNoDelay(acknodelay)
|
||||
conn.SetKeepAlive(keepalive)
|
||||
|
||||
if nocomp {
|
||||
go handleMux(conn, target, config)
|
||||
} else {
|
||||
go handleMux(newCompStream(conn), c.String("target"))
|
||||
go handleMux(newCompStream(conn), target, config)
|
||||
}
|
||||
} else {
|
||||
log.Println(err)
|
||||
|
||||
+1
-1
@@ -8,7 +8,7 @@ import (
|
||||
"os/signal"
|
||||
"syscall"
|
||||
|
||||
"github.com/xtaci/kcp-go"
|
||||
kcp "github.com/xtaci/kcp-go"
|
||||
)
|
||||
|
||||
func init() {
|
||||
|
||||
Reference in New Issue
Block a user