mirror of
https://github.com/xtaci/kcptun.git
synced 2024-04-21 12:32:32 +00:00
Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
61e69d9d5b | ||
|
|
11cdc2038c | ||
|
|
1908dc391e | ||
|
|
51e6b381bf | ||
|
|
3531726339 | ||
|
|
53f814ec9f | ||
|
|
375640d183 | ||
|
|
ae2ba18b08 | ||
|
|
717df77668 | ||
|
|
b61a2c240c | ||
|
|
bfe3524d74 | ||
|
|
8b3b38eeef | ||
|
|
754b4a7186 | ||
|
|
229a4a8783 | ||
|
|
052f0a5397 | ||
|
|
8e74cf410c | ||
|
|
206df4b69f | ||
|
|
4ccc922059 | ||
|
|
1e88951c54 | ||
|
|
6540e3e90a | ||
|
|
9ac03a973b | ||
|
|
f911127426 | ||
|
|
c601a18b3c | ||
|
|
7eb8d3ce41 | ||
|
|
d425d472eb | ||
|
|
bb9574e700 | ||
|
|
4670fa3a92 | ||
|
|
b84a293eda | ||
|
|
7e1acb4a0f | ||
|
|
829694fb75 | ||
|
|
c0c7d56f47 | ||
|
|
79d69e76bc | ||
|
|
2378dc7dfe | ||
|
|
4e4882741a | ||
|
|
af39e7edf0 | ||
|
|
e12977a031 | ||
|
|
5ba941f654 | ||
|
|
5dbc2d25c8 | ||
|
|
0bcf57c444 | ||
|
|
a8b5c0677e | ||
|
|
27b67c1a5a | ||
|
|
45a802a137 | ||
|
|
c8cc2fe95e | ||
|
|
2addfa670d | ||
|
|
4001e1b23d | ||
|
|
40590417a9 | ||
|
|
67db1f276b | ||
|
|
16b4b6a9a0 | ||
|
|
c4d07f13f1 | ||
|
|
5945a2490c | ||
|
|
532b2c89d5 | ||
|
|
b2b4f8cdf6 | ||
|
|
f7655b79e0 | ||
|
|
91980543ee | ||
|
|
02cda02f9a | ||
|
|
6016302e8a | ||
|
|
dfdd4c8c24 | ||
|
|
2195981b01 | ||
|
|
485572857e | ||
|
|
4b2d0e567d | ||
|
|
68b36fbf74 | ||
|
|
9b08423b3e | ||
|
|
35522d30cb | ||
|
|
e8e3e5a894 | ||
|
|
9c95df026b | ||
|
|
09aea3056a | ||
|
|
0788aa8260 | ||
|
|
2f479b788c | ||
|
|
f3f78460a4 | ||
|
|
3127b2d19f | ||
|
|
3db63cdff6 | ||
|
|
5154cf81de | ||
|
|
cc80029b1e | ||
|
|
23d6624745 | ||
|
|
f38f7a8ac5 | ||
|
|
e913f96f7e | ||
|
|
5d0d8bd74d | ||
|
|
4010c83e8f | ||
|
|
76351dff2b | ||
|
|
7a5807cbf5 | ||
|
|
6b26c75ea5 | ||
|
|
0873f349c3 | ||
|
|
281f8675a3 | ||
|
|
65512e9296 | ||
|
|
3ea858ed90 | ||
|
|
5f23781fc0 | ||
|
|
2b3573f4ea | ||
|
|
cb0f299263 | ||
|
|
f64bc908ee | ||
|
|
43c6a674ef | ||
|
|
1a48680a55 | ||
|
|
dbdb5293b4 | ||
|
|
94070bfcbe | ||
|
|
398a0bf9fc | ||
|
|
ff54a2dc92 | ||
|
|
747eba0ee1 | ||
|
|
f057cbc7f4 | ||
|
|
a83ae4bf15 | ||
|
|
4d062090a7 | ||
|
|
27f76582e1 | ||
|
|
b023b542e8 | ||
|
|
9a3be067bf | ||
|
|
8705bd7670 | ||
|
|
b4e5181a2f | ||
|
|
94f61b5945 | ||
|
|
efc0b99d21 | ||
|
|
3803993529 | ||
|
|
d23ff7c351 | ||
|
|
f383ee31a5 | ||
|
|
d399f220f0 | ||
|
|
59a1bbc7b8 | ||
|
|
3b656e101f | ||
|
|
aec364eb72 | ||
|
|
e26ab6729f | ||
|
|
583fe3ba24 | ||
|
|
7fd6442284 | ||
|
|
81f4643830 | ||
|
|
744a6407e7 | ||
|
|
2cf5292ac1 | ||
|
|
b3a8b631b4 | ||
|
|
1167419210 | ||
|
|
56f9f0d01a | ||
|
|
96888f1cac | ||
|
|
e752d70c79 | ||
|
|
a882b94e5b | ||
|
|
790a6d5352 | ||
|
|
603c2db5ab | ||
|
|
581df3a34d | ||
|
|
6113d2b497 | ||
|
|
d3b8a4d71d | ||
|
|
1f0a4a2c2f | ||
|
|
75923fb08f | ||
|
|
0243422885 | ||
|
|
6374cb0d36 | ||
|
|
0aedc21c50 | ||
|
|
727887517f | ||
|
|
7b81b24e8d | ||
|
|
ba22434379 | ||
|
|
003617186b | ||
|
|
b9ce27cb3e | ||
|
|
c93a199823 | ||
|
|
bb34894947 | ||
|
|
f743a075c5 |
@@ -2,11 +2,12 @@ Before firing issue, make sure you figured out the following common questions.
|
||||
|
||||
PLEASE DO SEARCH FIRST.
|
||||
|
||||
1. Are you using the **latest release**?
|
||||
2. Which **OS** do you use?
|
||||
3. Which end for this issue related to, **client or server**?
|
||||
4. Are you using the **same version** for both client & server
|
||||
5. Did you correctly set the ***-target value, -t value target server address (default: "127.0.0.1:12948")*** on the server side?
|
||||
6. Can ```telnet target port``` successful?
|
||||
7. ```-nocomp, -datashard, -parityshard, -key, -crypt``` ***must be the same*** on both side.
|
||||
8. Does your ***firewall allows UDP*** communications? (including your ISP Cable-Modem)
|
||||
1. Check your ```-key xxx``` for at least 3 times, ***MAKE SURE*** both sides share the same secret.
|
||||
2. ```-nocomp, -datashard, -parityshard, -key, -crypt``` ***must be the same*** on both side.
|
||||
3. Did you correctly set the ***-target*** on the server side?
|
||||
4. ***MAKE SURE*** ```telnet target port``` on your server successful(don't ask me why couldn't).
|
||||
5. Does your ***firewall allows UDP*** communications? (including your ISP Cable-Modem)
|
||||
6. Are you using the **same version** for both client & server
|
||||
7. Are you using the **latest release**?
|
||||
8. Which **OS** do you use?
|
||||
9. Which end for this issue related to, **client or server**?
|
||||
|
||||
+1
-2
@@ -3,7 +3,6 @@ MAINTAINER xtaci <daniel820313@gmail.com>
|
||||
RUN apk update && \
|
||||
apk upgrade && \
|
||||
apk add git
|
||||
RUN go get github.com/xtaci/kcptun/client
|
||||
RUN go get github.com/xtaci/kcptun/server
|
||||
RUN go get github.com/xtaci/kcptun/client && go get github.com/xtaci/kcptun/server
|
||||
EXPOSE 29900/udp
|
||||
EXPOSE 12948
|
||||
|
||||
+41
-24
@@ -1,7 +1,7 @@
|
||||
# <img src="logo.png" alt="kcptun" height="60px" />
|
||||
[![GoDoc][1]][2] [![Release][13]][14] [![Powered][17]][18] [![MIT licensed][11]][12] [![Build Status][3]][4] [![Go Report Card][5]][6] [![Downloads][15]][16] [![Gitter][19]][20]
|
||||
[1]: https://godoc.org/github.com/xtaci/kcptun?status.svg
|
||||
[2]: https://godoc.org/github.com/xtaci/kcptun
|
||||
[![Release][13]][14] [![Powered][17]][18] [![MIT licensed][11]][12] [![Build Status][3]][4] [![Go Report Card][5]][6] [![Downloads][15]][16] [![Gitter][19]][20] [![Docker][1]][2]
|
||||
[1]: https://images.microbadger.com/badges/image/xtaci/kcptun.svg
|
||||
[2]: https://microbadger.com/images/xtaci/kcptun
|
||||
[3]: https://travis-ci.org/xtaci/kcptun.svg?branch=master
|
||||
[4]: https://travis-ci.org/xtaci/kcptun
|
||||
[5]: https://goreportcard.com/badge/github.com/xtaci/kcptun
|
||||
@@ -28,10 +28,13 @@ A tool for converting tcp stream into kcp+udp stream, :zap: ***[download address
|
||||
***kcptun is based on [kcp-go](https://github.com/xtaci/kcp-go)***
|
||||
|
||||
### *QuickStart* :lollipop:
|
||||
Client, server, respectively, download the corresponding platform binary compression package, and extract, through the following command to start port forwarding.
|
||||
```
|
||||
Server Side: ./server_linux_amd64 -t "127.0.0.1:1080" -l ":4000" -mode fast2 // forwarding to local port 1080
|
||||
Client Side: ./client_darwin_amd64 -r "SERVERIP:4000" -l ":1080" -mode fast2 // listening on port 1080
|
||||
Server: ./server_linux_amd64 -t "SERVER_IP:8388" -l ":4000" -mode fast2
|
||||
Client: ./client_darwin_amd64 -r "SERVER_IP:4000" -l ":8388" -mode fast2
|
||||
```
|
||||
The above command can establish 8388/tcp port forwarding (through 4000/udp port).
|
||||
|
||||
|
||||
### *Performance* :lollipop:
|
||||
<img src="fast.png" alt="fast.com" height="256px" />
|
||||
@@ -40,16 +43,17 @@ Client Side: ./client_darwin_amd64 -r "SERVERIP:4000" -l ":1080" -mode fast2 //
|
||||
* WIFI: 5GHz TL-WDR3320
|
||||
|
||||
### *Usage* :lollipop:
|
||||
Help output under MacOS X:
|
||||
```
|
||||
$ ./client_darwin_amd64 -h
|
||||
NAME:
|
||||
kcptun - kcptun client
|
||||
kcptun - client(with SMUX)
|
||||
|
||||
USAGE:
|
||||
client_darwin_amd64 [global options] command [command options] [arguments...]
|
||||
|
||||
VERSION:
|
||||
20160811
|
||||
20160922
|
||||
|
||||
COMMANDS:
|
||||
help, h Shows a list of commands or help for one command
|
||||
@@ -57,31 +61,32 @@ COMMANDS:
|
||||
GLOBAL OPTIONS:
|
||||
--localaddr value, -l value local listen address (default: ":12948")
|
||||
--remoteaddr value, -r value kcp server address (default: "vps:29900")
|
||||
--key value key for communcation, must be the same as kcptun server (default: "it's a secrect") [$KCPTUN_KEY]
|
||||
--crypt value methods for encryption: aes, tea, xor, none (default: "aes")
|
||||
--mode value mode for communication: fast3, fast2, fast, normal (default: "fast")
|
||||
--conn value establish N physical connections as specified by 'conn' to server (default: 1)
|
||||
--mtu value set MTU of UDP packets, suggest 'tracepath' to discover path mtu (default: 1350)
|
||||
--key value pre-shared secret between client and server (default: "it's a secrect") [$KCPTUN_KEY]
|
||||
--crypt value aes, aes-128, aes-192, salsa20, blowfish, twofish, cast5, 3des, tea, xtea, xor, none (default: "aes")
|
||||
--mode value profiles: fast3, fast2, fast, normal (default: "fast")
|
||||
--conn value set num of UDP connections to server (default: 1)
|
||||
--autoexpire value set auto expiration time(in seconds) for a single UDP connection, 0 to disable (default: 0)
|
||||
--mtu value set maximum transmission unit for UDP packets (default: 1350)
|
||||
--sndwnd value set send window size(num of packets) (default: 128)
|
||||
--rcvwnd value set receive window size(num of packets) (default: 1024)
|
||||
--nocomp disable compression
|
||||
--datashard value set reed-solomon erasure coding - datashard (default: 10)
|
||||
--parityshard value set reed-solomon erasure coding - parityshard (default: 3)
|
||||
--dscp value set DSCP(6bit) (default: 0)
|
||||
--nocomp disable compression
|
||||
--log value specify a log file to output, default goes to stderr
|
||||
-c value config from json file, which will override the command from shell
|
||||
--help, -h show help
|
||||
--version, -v print the version
|
||||
```
|
||||
|
||||
```
|
||||
$ ./server_darwin_amd64 -h
|
||||
NAME:
|
||||
kcptun - kcptun server
|
||||
kcptun - server(with SMUX)
|
||||
|
||||
USAGE:
|
||||
server_darwin_amd64 [global options] command [command options] [arguments...]
|
||||
|
||||
VERSION:
|
||||
20160811
|
||||
20160922
|
||||
|
||||
COMMANDS:
|
||||
help, h Shows a list of commands or help for one command
|
||||
@@ -89,19 +94,24 @@ COMMANDS:
|
||||
GLOBAL OPTIONS:
|
||||
--listen value, -l value kcp server listen address (default: ":29900")
|
||||
--target value, -t value target server address (default: "127.0.0.1:12948")
|
||||
--key value key for communcation, must be the same as kcptun client (default: "it's a secrect") [$KCPTUN_KEY]
|
||||
--crypt value methods for encryption: aes, tea, xor, none (default: "aes")
|
||||
--mode value mode for communication: fast3, fast2, fast, normal (default: "fast")
|
||||
--mtu value set MTU of UDP packets, suggest 'tracepath' to discover path mtu (default: 1350)
|
||||
--key value pre-shared secret between client and server (default: "it's a secrect") [$KCPTUN_KEY]
|
||||
--crypt value aes, aes-128, aes-192, salsa20, blowfish, twofish, cast5, 3des, tea, xtea, xor, none (default: "aes")
|
||||
--mode value profiles: fast3, fast2, fast, normal (default: "fast")
|
||||
--mtu value set maximum transmission unit for UDP packets (default: 1350)
|
||||
--sndwnd value set send window size(num of packets) (default: 1024)
|
||||
--rcvwnd value set receive window size(num of packets) (default: 1024)
|
||||
--nocomp disable compression
|
||||
--datashard value set reed-solomon erasure coding - datashard (default: 10)
|
||||
--parityshard value set reed-solomon erasure coding - parityshard (default: 3)
|
||||
--dscp value set DSCP(6bit) (default: 0)
|
||||
--nocomp disable compression
|
||||
--log value specify a log file to output, default goes to stderr
|
||||
-c value config from json file, which will override the command from shell
|
||||
--help, -h show help
|
||||
--version, -v print the version
|
||||
```
|
||||
#### *Parameters by Layers* :lollipop:
|
||||
|
||||
<p align="left"><img src="layeredparams.png" alt="params" height="450px"/></p>
|
||||
|
||||
### *Applications* :lollipop:
|
||||
1. Real-time gaming.
|
||||
@@ -124,6 +134,12 @@ other parameters can be set independently.
|
||||
|
||||
***NOTICE: if too much retranmission happens, it's quite possible the windows are too large***
|
||||
|
||||
### *Security* :lollipop:
|
||||
No matter what encryption you are using for application layer, if you specify ```-crypt none``` to kcptun,
|
||||
the header will be ***PLAINTEXT*** to everyone; I suggest ```-crypt aes-128``` for encryption at least .
|
||||
|
||||
NOTICE: ```-crypt xor``` is also insecure, do not use this unless you know what you are doing.
|
||||
|
||||
### *Memory Control* :lollipop:
|
||||
Routers, mobile devices are sensitive to memory consumption; by setting GOGC environment(eg: GOGC=20) will lower memory consumption.
|
||||
Reference: https://blog.golang.org/go15gc
|
||||
@@ -159,6 +175,7 @@ Manual control is supported with hidden parameters, you must understand KCP prot
|
||||
```
|
||||
-mode manual -nodelay 1 -resend 2 -nc 1 -interval 20
|
||||
```
|
||||
I suggest fast2 for high-loss network, normal for low-loss network.
|
||||
|
||||
### *Forward Error Correction* :lollipop:
|
||||
In coding theory, the Reed–Solomon code belongs to the class of non-binary cyclic error-correcting codes. The Reed–Solomon code is based on univariate polynomials over finite fields.
|
||||
@@ -167,7 +184,7 @@ It is able to detect and correct multiple symbol errors. By adding t check symbo
|
||||
|
||||

|
||||
|
||||
Setting parameters of RS-Code with ```-datashard 10 -parityshard 3```
|
||||
Setting parameters of RS-Code with ```-datashard m -parityshard n```
|
||||
|
||||
### *Snappy Stream Compression* :lollipop:
|
||||
> Snappy is a compression/decompression library. It does not aim for maximum
|
||||
@@ -215,7 +232,7 @@ Of which ```RetransSegs,FastRetransSegs,LostSegs,OutSegs``` is the most useful.
|
||||
### *Donations* :dollar:
|
||||

|
||||
|
||||
All donations to this project will be used on the R&D of [gonet/2](http://gonet2.github.io/).
|
||||
Best wishes to you all.
|
||||
|
||||
### *References* :paperclip:
|
||||
1. https://github.com/skywind3000/kcp -- KCP - A Fast and Reliable ARQ Protocol.
|
||||
|
||||
@@ -1,7 +1,11 @@
|
||||
# <img src="logo.png" alt="kcptun" height="60px" />
|
||||
[![GoDoc][1]][2] [![Release][13]][14] [![Powered][17]][18] [![MIT licensed][11]][12] [![Build Status][3]][4] [![Go Report Card][5]][6] [![Downloads][15]][16] [![Gitter][19]][20]
|
||||
[1]: https://godoc.org/github.com/xtaci/kcptun?status.svg
|
||||
[2]: https://godoc.org/github.com/xtaci/kcptun
|
||||
<p align="center"><img src="logo.png" alt="kcptun" height="60px" /></p>
|
||||
<p align="center"><em>A Simple UDP Tunnel Based On KCP</em></p>
|
||||
|
||||
-
|
||||
|
||||
[![Release][13]][14] [![Powered][17]][18] [![MIT licensed][11]][12] [![Build Status][3]][4] [![Go Report Card][5]][6] [![Downloads][15]][16] [![Gitter][19]][20] [![Docker][1]][2]
|
||||
[1]: https://images.microbadger.com/badges/image/xtaci/kcptun.svg
|
||||
[2]: https://microbadger.com/images/xtaci/kcptun
|
||||
[3]: https://travis-ci.org/xtaci/kcptun.svg?branch=master
|
||||
[4]: https://travis-ci.org/xtaci/kcptun
|
||||
[5]: https://goreportcard.com/badge/github.com/xtaci/kcptun
|
||||
@@ -19,35 +23,42 @@
|
||||
[19]: https://badges.gitter.im/xtaci/kcptun.svg
|
||||
[20]: https://gitter.im/xtaci/kcptun?utm_source=badge&utm_medium=badge&utm_campaign=pr-badge
|
||||
|
||||
***[kcp-go](https://github.com/xtaci/kcp-go)协议测试小工具 :zap: [官方下载地址](https://github.com/xtaci/kcptun/releases/latest):zap:***
|
||||
<p align="center"><img src="kcptun.png" alt="kcptun" height="200px"/></p>
|
||||
<p align="center"><a href="https://github.com/xtaci/kcptun/releases/latest">立即安装</a></p>
|
||||
<p align="center"><em>支持macOS/Linux/Windows/FreeBSD/ARM/Raspberry Pi/OpenWrt</em></p>
|
||||
<p align="right"><a href="https://github.com/xtaci/kcptun/blob/master/README.en.md">ENG</a></p>
|
||||
|
||||

|
||||
[English Readme](README.en.md)
|
||||
### *快速设定* :lollipop:
|
||||
-
|
||||
|
||||
### 快速设定
|
||||
|
||||
客户端、服务器分别**下载**对应平台的二进制压缩包,并**解压**,通过下面的命令**启动**端口转发。
|
||||
```
|
||||
服务器: ./server_linux_amd64 -t "127.0.0.1:8388" -l ":4000" -mode fast2 // 转发到服务器的本地8388端口
|
||||
客户端: ./client_darwin_amd64 -r "服务器IP地址:4000" -l ":8388" -mode fast2 // 监听客户端的本地8388端口
|
||||
注: 服务器端需要有服务监听8388端口
|
||||
服务器: ./server_linux_amd64 -t "服务器IP地址:8388" -l ":4000" -mode fast2
|
||||
客户端: ./client_darwin_amd64 -r "服务器IP地址:4000" -l ":8388" -mode fast2
|
||||
```
|
||||
以上命令可以实现8388/tcp端口的转发(通过4000/udp端口)。
|
||||
|
||||
### 速度对比
|
||||
|
||||
### *速度对比* :lollipop:
|
||||
<img src="fast.png" alt="fast.com" height="256px" />
|
||||
* 测速网站: https://fast.com
|
||||
* 接入: 100M ADSL
|
||||
* 接入速度: 100Mbps
|
||||
* WIFI: 5GHz TL-WDR3320
|
||||
|
||||
### *使用方法* :lollipop:
|
||||
在Mac OS X El Capitan下的帮助输出:
|
||||
### 使用方法
|
||||
|
||||
在Mac OS X El Capitan下的帮助输出,注意默认值:
|
||||
```
|
||||
$ ./client_darwin_amd64 -h
|
||||
NAME:
|
||||
kcptun - kcptun client
|
||||
kcptun - client(with SMUX)
|
||||
|
||||
USAGE:
|
||||
client_darwin_amd64 [global options] command [command options] [arguments...]
|
||||
|
||||
VERSION:
|
||||
20160811
|
||||
20161025
|
||||
|
||||
COMMANDS:
|
||||
help, h Shows a list of commands or help for one command
|
||||
@@ -55,31 +66,32 @@ COMMANDS:
|
||||
GLOBAL OPTIONS:
|
||||
--localaddr value, -l value local listen address (default: ":12948")
|
||||
--remoteaddr value, -r value kcp server address (default: "vps:29900")
|
||||
--key value key for communcation, must be the same as kcptun server (default: "it's a secrect") [$KCPTUN_KEY]
|
||||
--crypt value methods for encryption: aes, tea, xor, none (default: "aes")
|
||||
--mode value mode for communication: fast3, fast2, fast, normal (default: "fast")
|
||||
--conn value establish N physical connections as specified by 'conn' to server (default: 1)
|
||||
--mtu value set MTU of UDP packets, suggest 'tracepath' to discover path mtu (default: 1350)
|
||||
--key value pre-shared secret between client and server (default: "it's a secrect") [$KCPTUN_KEY]
|
||||
--crypt value aes, aes-128, aes-192, salsa20, blowfish, twofish, cast5, 3des, tea, xtea, xor, none (default: "aes")
|
||||
--mode value profiles: fast3, fast2, fast, normal (default: "fast")
|
||||
--conn value set num of UDP connections to server (default: 1)
|
||||
--autoexpire value set auto expiration time(in seconds) for a single UDP connection, 0 to disable (default: 0)
|
||||
--mtu value set maximum transmission unit for UDP packets (default: 1350)
|
||||
--sndwnd value set send window size(num of packets) (default: 128)
|
||||
--rcvwnd value set receive window size(num of packets) (default: 1024)
|
||||
--nocomp disable compression
|
||||
--datashard value set reed-solomon erasure coding - datashard (default: 10)
|
||||
--parityshard value set reed-solomon erasure coding - parityshard (default: 3)
|
||||
--dscp value set DSCP(6bit) (default: 0)
|
||||
--nocomp disable compression
|
||||
--log value specify a log file to output, default goes to stderr
|
||||
-c value config from json file, which will override the command from shell
|
||||
--help, -h show help
|
||||
--version, -v print the version
|
||||
```
|
||||
|
||||
```
|
||||
$ ./server_darwin_amd64 -h
|
||||
NAME:
|
||||
kcptun - kcptun server
|
||||
kcptun - server(with SMUX)
|
||||
|
||||
USAGE:
|
||||
server_darwin_amd64 [global options] command [command options] [arguments...]
|
||||
|
||||
VERSION:
|
||||
20160811
|
||||
20161025
|
||||
|
||||
COMMANDS:
|
||||
help, h Shows a list of commands or help for one command
|
||||
@@ -87,67 +99,131 @@ COMMANDS:
|
||||
GLOBAL OPTIONS:
|
||||
--listen value, -l value kcp server listen address (default: ":29900")
|
||||
--target value, -t value target server address (default: "127.0.0.1:12948")
|
||||
--key value key for communcation, must be the same as kcptun client (default: "it's a secrect") [$KCPTUN_KEY]
|
||||
--crypt value methods for encryption: aes, tea, xor, none (default: "aes")
|
||||
--mode value mode for communication: fast3, fast2, fast, normal (default: "fast")
|
||||
--mtu value set MTU of UDP packets, suggest 'tracepath' to discover path mtu (default: 1350)
|
||||
--key value pre-shared secret between client and server (default: "it's a secrect") [$KCPTUN_KEY]
|
||||
--crypt value aes, aes-128, aes-192, salsa20, blowfish, twofish, cast5, 3des, tea, xtea, xor, none (default: "aes")
|
||||
--mode value profiles: fast3, fast2, fast, normal (default: "fast")
|
||||
--mtu value set maximum transmission unit for UDP packets (default: 1350)
|
||||
--sndwnd value set send window size(num of packets) (default: 1024)
|
||||
--rcvwnd value set receive window size(num of packets) (default: 1024)
|
||||
--nocomp disable compression
|
||||
--datashard value set reed-solomon erasure coding - datashard (default: 10)
|
||||
--parityshard value set reed-solomon erasure coding - parityshard (default: 3)
|
||||
--dscp value set DSCP(6bit) (default: 0)
|
||||
--nocomp disable compression
|
||||
--log value specify a log file to output, default goes to stderr
|
||||
-c value config from json file, which will override the command from shell
|
||||
--help, -h show help
|
||||
--version, -v print the version
|
||||
```
|
||||
#### 分层参数图
|
||||
|
||||
### *参数调整* :lollipop:
|
||||
***两端参数必须一致的有:***
|
||||
* datashard
|
||||
* parityshard
|
||||
* nocomp
|
||||
* key
|
||||
* crypt
|
||||
<p align="left"><img src="layeredparams.png" alt="params" height="450px"/></p>
|
||||
|
||||
### 内置模式
|
||||
|
||||
响应速度:
|
||||
*fast3 > fast2 >* **[fast]** *> normal > default*
|
||||
有效载荷比:
|
||||
*default > normal >* **[fast]** *> fast2 > fast3*
|
||||
中间mode参数比较均衡,总之就是越快,包重传越激进。
|
||||
更高级的 **手动档** 需要理解KCP协议,并通过 **隐藏参数** 调整,例如:
|
||||
```
|
||||
-mode manual -nodelay 1 -resend 2 -nc 1 -interval 20
|
||||
```
|
||||
|
||||
* 搭配1. fast + FEC(5,5)
|
||||
* 搭配2. fast2 + FEC(10,3)
|
||||
* 搭配3. fast2 + FEC(0,0)
|
||||
|
||||
默认profile参考: https://github.com/xtaci/kcptun/blob/master/client/main.go#L248
|
||||
|
||||
### 前向纠错
|
||||
|
||||
前向纠错采用Reed Solomon纠删码, 它的基本原理如下: 给定n个数据块d1, d2,…, dn,n和一个正整数m, RS根据n个数据块生成m个校验块, c1, c2,…, cm。 对于任意的n和m, 从n个原始数据块和m 个校验块中任取n块就能解码出原始数据, 即RS最多**容忍m个数据块或者校验块同时丢失**。
|
||||
|
||||

|
||||
|
||||
通过参数```-datashard n -parityshard m``` 在两端同时设定。
|
||||
|
||||
数据包发送顺序严格遵循: n个datashard紧接m个parityshard,重复。
|
||||
|
||||
注意:为了发挥FEC最佳效果,设置 parityshard/(parity+datashard) > packet loss,比如5/(5+5) > 30%
|
||||
|
||||
### 窗口调整
|
||||
|
||||
**两端参数必须一致的有**:
|
||||
|
||||
* datashard --前向纠错
|
||||
* parityshard --前向纠错
|
||||
* nocomp --压缩
|
||||
* key --密钥
|
||||
* crypt --加密算法
|
||||
|
||||
其余为两边可独立设定的参数
|
||||
|
||||
*简易自我调优方法*:
|
||||
**简易窗口自我调优方法**:
|
||||
|
||||
> 第一步:同时在两端逐步增大client rcvwnd和server sndwnd;
|
||||
> 第二步:尝试下载,观察如果带宽利用率(服务器+客户端两端都要观察)接近物理带宽则停止,否则跳转到第一步。
|
||||
|
||||
***注意:产生大量重传时,一定是窗口偏大了***
|
||||
**注意:产生大量重传时,一定是窗口偏大了**
|
||||
|
||||
### 安全
|
||||
|
||||
无论你上层如何加密,如果```-crypt none```,那么**协议头部**都是**明文**的,建议至少采用```-crypt aes-128```加密,并修改密码。
|
||||
|
||||
密码可以通过`-key`指定,也可以通过环境变量`KCPTUN_KEY`指定。
|
||||
|
||||
注意: ```-crypt xor``` 也是不安全的,除非你知道你在做什么。
|
||||
|
||||
附加密速度Benchmark:
|
||||
|
||||
*带宽计算公式*:
|
||||
```
|
||||
在不丢包的情况下,有最大-rcvwnd 个数据包在网络上正在向你传输,以平均数据包大小avgsize计算,在任意时刻,有:
|
||||
|
||||
network_cap = rcvwnd*avgsize
|
||||
|
||||
数据流向你,这个值再除以ping值(rtt),等于最大带宽使用量。
|
||||
|
||||
max_bandwidth = network_cap/rtt = rcvwnd*avgsize/rtt
|
||||
|
||||
举例,设rcvwnd = 1024, avgsize = 1KB, rtt = 400ms,则:
|
||||
|
||||
max_bandwidth = 1024 * 1KB / 400ms = 2.5MB/s ~= 25Mbps
|
||||
|
||||
(注:以上计算不包括前向纠错的数据量)
|
||||
|
||||
前向纠错是最大带宽量的一个固定比例增加:
|
||||
|
||||
max_bandwidth_fec = max_bandwidth*(datashard+parityshard)/datashard
|
||||
|
||||
举例,设datashard = 10 , partiyshard = 3,则:
|
||||
|
||||
max_bandwidth_fec = max_bandwidth * (10 + 3) /10 = 1.3*max_bandwidth = 1.3 * 25Mbps = 32.5Mbps
|
||||
BenchmarkAES128-4 200000 11182 ns/op
|
||||
BenchmarkAES192-4 200000 12699 ns/op
|
||||
BenchmarkAES256-4 100000 13757 ns/op
|
||||
BenchmarkTEA-4 50000 26441 ns/op
|
||||
BenchmarkSimpleXOR-4 3000000 441 ns/op
|
||||
BenchmarkBlowfish-4 30000 48036 ns/op
|
||||
BenchmarkNone-4 20000000 106 ns/op
|
||||
BenchmarkCast5-4 20000 60222 ns/op
|
||||
BenchmarkTripleDES-4 2000 878759 ns/op
|
||||
BenchmarkTwofish-4 20000 68501 ns/op
|
||||
BenchmarkXTEA-4 20000 77417 ns/op
|
||||
BenchmarkSalsa20-4 300000 4998 ns/op
|
||||
```
|
||||
|
||||
### *内存控制* :lollipop:
|
||||
路由器,手机等嵌入式设备通常对内存用量敏感,通过调节环境变量GOGC(例如GOGC=20)后启动client,可以降低内存使用。
|
||||
### 内存控制
|
||||
|
||||
路由器,手机等嵌入式设备通常对**内存用量敏感**,通过调节环境变量GOGC(例如GOGC=20)后启动client,可以降低内存使用。
|
||||
参考:https://blog.golang.org/go15gc
|
||||
|
||||
### *流量控制* :lollipop:
|
||||
***必要性: 针对流量敏感的服务器,做双保险。***
|
||||
|
||||
### DSCP
|
||||
|
||||
DSCP差分服务代码点(Differentiated Services Code Point),IETF于1998年12月发布了Diff-Serv(Differentiated Service)的QoS分类标准。它在每个数据包IP头部的服务类别TOS标识字节中,利用已使用的**6比特**和未使用的2比特,通过编码值来区分优先级。
|
||||
常用DSCP值可以参考[Wikipedia DSCP](https://en.wikipedia.org/wiki/Differentiated_services#Commonly_used_DSCP_values),至于有没有用,完全取决于数据包经过的设备。
|
||||
|
||||
通过 ```-dscp ``` 参数指定dscp值,两端可分别设定。
|
||||
|
||||
注意:设置dscp不一定会更好,需要尝试。
|
||||
|
||||
### Snappy数据流压缩
|
||||
|
||||
> Snappy is a compression/decompression library. It does not aim for maximum
|
||||
> compression, or compatibility with any other compression library; instead,
|
||||
> it aims for very high speeds and reasonable compression. For instance,
|
||||
> compared to the fastest mode of zlib, Snappy is an order of magnitude faster
|
||||
> for most inputs, but the resulting compressed files are anywhere from 20% to
|
||||
> 100% bigger.
|
||||
|
||||
> Reference: http://google.github.io/snappy/
|
||||
|
||||
通过参数 ```-nocomp``` 在两端同时设定以关闭压缩。
|
||||
> 提示: 关闭压缩可能会降低延迟。
|
||||
|
||||
### 流量控制
|
||||
|
||||
**必要性: 针对流量敏感的服务器,做双保险。**
|
||||
|
||||
> 基本原则: SERVER的发送速率不能超过ADSL下行带宽,否则只会浪费您的服务器带宽。
|
||||
|
||||
@@ -164,45 +240,8 @@ root@kcptun:~#
|
||||
```
|
||||
其中eth0为网卡,有些服务器为ens3,有些为p2p1,通过ifconfig查询修改。
|
||||
|
||||
### SNMP
|
||||
|
||||
### *DSCP* :lollipop:
|
||||
DSCP差分服务代码点(Differentiated Services Code Point),IETF于1998年12月发布了Diff-Serv(Differentiated Service)的QoS分类标准。它在每个数据包IP头部的服务类别TOS标识字节中,利用已使用的6比特和未使用的2比特,通过编码值来区分优先级。
|
||||
常用DSCP值可以参考[Wikipedia DSCP](https://en.wikipedia.org/wiki/Differentiated_services#Commonly_used_DSCP_values),至于有没有用,完全取决于数据包经过的设备。
|
||||
|
||||
通过 ```-dscp ``` 参数指定dscp值,两端可分别设定。
|
||||
|
||||
### *前向纠错* :lollipop:
|
||||
前向纠错采用Reed Solomon纠删码, 它的基本原理如下: 给定n个数据块d1, d2,…, dn,n和一个正整数m, RS根据n个数据块生成m个校验块, c1, c2,…, cm。 对于任意的n和m, 从n个原始数据块和m 个校验块中任取n块就能解码出原始数据, 即RS最多容忍m个数据块或者校验块同时丢失。
|
||||
|
||||

|
||||
|
||||
通过参数```-datashard 10 -parityshard 3``` 在两端同时设定。
|
||||
|
||||
### *Snappy数据流压缩* :lollipop:
|
||||
> Snappy is a compression/decompression library. It does not aim for maximum
|
||||
> compression, or compatibility with any other compression library; instead,
|
||||
> it aims for very high speeds and reasonable compression. For instance,
|
||||
> compared to the fastest mode of zlib, Snappy is an order of magnitude faster
|
||||
> for most inputs, but the resulting compressed files are anywhere from 20% to
|
||||
> 100% bigger.
|
||||
|
||||
> Reference: http://google.github.io/snappy/
|
||||
|
||||
通过参数 ```-nocomp``` 在两端同时设定以关闭压缩。
|
||||
> 提示: 关闭压缩可能会降低延迟。
|
||||
|
||||
### *内置模式* :lollipop:
|
||||
响应速度:
|
||||
*fast3 >* ***[fast2]*** *> fast > normal > default*
|
||||
有效载荷比:
|
||||
*default > normal > fast >* ***[fast2]*** *> fast3*
|
||||
中间mode参数比较均衡,总之就是越快越浪费带宽,推荐模式 ***fast2***
|
||||
更高级的 ***手动档*** 需要理解KCP协议,并通过 ***隐藏参数*** 调整,例如:
|
||||
```
|
||||
-mode manual -nodelay 1 -resend 2 -nc 1 -interval 20
|
||||
```
|
||||
|
||||
### *SNMP* :lollipop:
|
||||
```go
|
||||
// Snmp defines network statistics indicator
|
||||
type Snmp struct {
|
||||
@@ -228,32 +267,75 @@ type Snmp struct {
|
||||
}
|
||||
```
|
||||
|
||||
使用```kill -SIGUSR1 pid``` 可以在控制台打印出SNMP信息,通常用于精细调整***当前链路的有效载荷比***。
|
||||
观察```RetransSegs,FastRetransSegs,LostSegs,OutSegs```这几者的数值比例,用于参考调整```-mode manual,fec```的参数。
|
||||
使用```kill -SIGUSR1 pid``` 可以在控制台打印出SNMP信息,通常用于精细调整**当前链路的有效载荷比**。
|
||||
观察```RetransSegs,FastRetransSegs,LostSegs,OutSegs```这几者的数值比例,用于参考调整```-mode manual,fec```的参数。
|
||||
|
||||
### *故障排除* :lollipop:
|
||||
> Q: 客户端和服务器端***皆无*** ```stream opened```信息。
|
||||
#### 带宽计算公式
|
||||
|
||||
```
|
||||
在不丢包的情况下,有最大-rcvwnd 个数据包在网络上正在向你传输,以平均数据包大小avgsize计算,在任意时刻,有:
|
||||
|
||||
network_cap = rcvwnd*avgsize
|
||||
|
||||
数据流向你,这个值再除以ping值(rtt),等于最大带宽使用量。
|
||||
|
||||
max_bandwidth = network_cap/rtt = rcvwnd*avgsize/rtt
|
||||
|
||||
举例,设rcvwnd = 1024, avgsize = 1KB, rtt = 400ms,则:
|
||||
|
||||
max_bandwidth = 1024 * 1KB / 400ms = 2.5MB/s ~= 25Mbps
|
||||
|
||||
(注:以上计算不包括前向纠错的数据量)
|
||||
|
||||
前向纠错是最大带宽量的一个固定比例增加:
|
||||
|
||||
max_bandwidth_fec = max_bandwidth*(datashard+parityshard)/datashard
|
||||
|
||||
举例,设datashard = 10 , partiyshard = 3,则:
|
||||
|
||||
max_bandwidth_fec = max_bandwidth * (10 + 3) /10 = 1.3*max_bandwidth = 1.3 * 25Mbps = 32.5Mbps
|
||||
```
|
||||
|
||||
### 故障排除
|
||||
|
||||
> Q: 客户端和服务器端**皆无** ```stream opened```信息。
|
||||
> A: 连接客户端程序的端口设置错误。
|
||||
|
||||
> Q: 客户端有 ```stream opened```信息,服务器端没有。
|
||||
> A: 连接服务器的端口设置错误,或者被防火墙拦截。
|
||||
|
||||
> Q: 客户端服务器***皆有*** ```stream opened```信息,但无法通信。
|
||||
> Q: 客户端服务器**皆有** ```stream opened```信息,但无法通信。
|
||||
> A: 上层软件的设定错误。
|
||||
|
||||
### *免责申明* :warning:
|
||||
用户以各种方式使用本软件(包括但不限于修改使用、直接使用、通过第三方使用)的过程中,不得以任何方式利用本软件直接或间接从事违反中国法律、以及社会公德的行为。软件的使用者需对自身行为负责,因使用软件引发的一切纠纷,由使用者承担全部法律及连带责任。作者不承担任何法律及连带责任。
|
||||
### 免责申明
|
||||
|
||||
对免责声明的解释、修改及更新权均属于作者本人所有。
|
||||
**用户以各种方式使用本软件(包括但不限于修改使用、直接使用、通过第三方使用)的过程中,不得以任何方式利用本软件直接或间接从事违反中国法律、以及社会公德的行为。软件的使用者需对自身行为负责,因使用软件引发的一切纠纷,由使用者承担全部法律及连带责任。作者不承担任何法律及连带责任。**
|
||||
|
||||
**对免责声明的解释、修改及更新权均属于作者本人所有。**
|
||||
|
||||
### 捐赠
|
||||
|
||||
### *捐赠* :dollar:
|
||||

|
||||
|
||||
对该项目的捐款将用于[gonet/2](http://gonet2.github.io/)游戏服务器框架的研发。
|
||||
### 特别鸣谢
|
||||
|
||||
```特别感谢: 郑H立, 南D风, Li, 七q, 凌J,昶,Les*ables, Ky*n, 噼**啦, 等,名字已做特殊处理。```
|
||||
> 郑H立, 南东风, Li, 七七, 凌君, 昶,LesMiserables, KyOn, 噼里啪啦, 继斌, 小苍辛苦, **Ken**,
|
||||
> 乔槁, 佳晨, 猪肉佬, lcx, 昊文, 冰峰, 凡, alex, **海豹叔叔**, 奥姐, 张冰, 司成,
|
||||
> 武子, **慎**,Alex43211,**Coxxs**,荣,NeroNg,吴骁,定一,我不是林J,Patrick, 超, 陈,windfarer, 宇,
|
||||
> 今晶,斌,晓东,最后一缕阳光。
|
||||
|
||||
好人一生平安!
|
||||
|
||||
### 相关软件
|
||||
|
||||
1. https://github.com/bettermanbao/openwrt-kcptun
|
||||
2. https://github.com/EasyPi/openwrt-kcptun
|
||||
3. https://github.com/kuoruan/luci-app-kcptun
|
||||
4. https://github.com/dfdragon/kcptun_gclient
|
||||
5. https://github.com/dfdragon/kcptun_xclient
|
||||
|
||||
### 参考资料
|
||||
|
||||
### *参考资料* :paperclip:
|
||||
1. https://github.com/skywind3000/kcp -- KCP - A Fast and Reliable ARQ Protocol.
|
||||
2. https://github.com/klauspost/reedsolomon -- Reed-Solomon Erasure Coding in Go.
|
||||
3. https://en.wikipedia.org/wiki/Differentiated_services -- DSCP.
|
||||
@@ -267,3 +349,4 @@ type Snmp struct {
|
||||
11. https://tools.ietf.org/html/rfc5827 -- Early Retransmit for TCP and Stream Control Transmission Protocol (SCTP).
|
||||
12. http://http2.github.io/ -- What is HTTP/2?
|
||||
13. http://www.lartc.org/LARTC-zh_CN.GB2312.pdf -- Linux Advanced Routing & Traffic Control
|
||||
14. https://en.wikipedia.org/wiki/Noisy-channel_coding_theorem -- Noisy channel coding theorem
|
||||
|
||||
+17
-4
@@ -12,6 +12,7 @@ fi
|
||||
|
||||
VERSION=`date -u +%Y%m%d`
|
||||
LDFLAGS="-X main.VERSION=$VERSION -s -w"
|
||||
GCFLAGS=""
|
||||
|
||||
OSES=(linux darwin windows freebsd)
|
||||
ARCHS=(amd64 386)
|
||||
@@ -22,8 +23,8 @@ for os in ${OSES[@]}; do
|
||||
then
|
||||
suffix=".exe"
|
||||
fi
|
||||
env CGO_ENABLED=0 GOOS=$os GOARCH=$arch go build -ldflags "$LDFLAGS" -o client_${os}_${arch}${suffix} github.com/xtaci/kcptun/client
|
||||
env CGO_ENABLED=0 GOOS=$os GOARCH=$arch go build -ldflags "$LDFLAGS" -o server_${os}_${arch}${suffix} github.com/xtaci/kcptun/server
|
||||
env CGO_ENABLED=0 GOOS=$os GOARCH=$arch go build -ldflags "$LDFLAGS" -gcflags "$GCFLAGS" -o client_${os}_${arch}${suffix} github.com/xtaci/kcptun/client
|
||||
env CGO_ENABLED=0 GOOS=$os GOARCH=$arch go build -ldflags "$LDFLAGS" -gcflags "$GCFLAGS" -o server_${os}_${arch}${suffix} github.com/xtaci/kcptun/server
|
||||
if $UPX; then upx -9 client_${os}_${arch}${suffix} server_${os}_${arch}${suffix};fi
|
||||
tar -zcf kcptun-${os}-${arch}-$VERSION.tar.gz client_${os}_${arch}${suffix} server_${os}_${arch}${suffix}
|
||||
$MD5 kcptun-${os}-${arch}-$VERSION.tar.gz
|
||||
@@ -33,9 +34,21 @@ done
|
||||
# ARM
|
||||
ARMS=(5 6 7)
|
||||
for v in ${ARMS[@]}; do
|
||||
env CGO_ENABLED=0 GOOS=linux GOARCH=arm GOARM=$v go build -ldflags "$LDFLAGS" -o client_linux_arm$v github.com/xtaci/kcptun/client
|
||||
env CGO_ENABLED=0 GOOS=linux GOARCH=arm GOARM=$v go build -ldflags "$LDFLAGS" -o server_linux_arm$v github.com/xtaci/kcptun/server
|
||||
env CGO_ENABLED=0 GOOS=linux GOARCH=arm GOARM=$v go build -ldflags "$LDFLAGS" -gcflags "$GCFLAGS" -o client_linux_arm$v github.com/xtaci/kcptun/client
|
||||
env CGO_ENABLED=0 GOOS=linux GOARCH=arm GOARM=$v go build -ldflags "$LDFLAGS" -gcflags "$GCFLAGS" -o server_linux_arm$v github.com/xtaci/kcptun/server
|
||||
done
|
||||
if $UPX; then upx -9 client_linux_arm* server_linux_arm*;fi
|
||||
tar -zcf kcptun-linux-arm-$VERSION.tar.gz client_linux_arm* server_linux_arm*
|
||||
$MD5 kcptun-linux-arm-$VERSION.tar.gz
|
||||
|
||||
#MIPS32LE
|
||||
env CGO_ENABLED=0 GOOS=linux GOARCH=mipsle go build -ldflags "$LDFLAGS" -gcflags "$GCFLAGS" -o client_linux_mipsle github.com/xtaci/kcptun/client
|
||||
env CGO_ENABLED=0 GOOS=linux GOARCH=mipsle go build -ldflags "$LDFLAGS" -gcflags "$GCFLAGS" -o server_linux_mipsle github.com/xtaci/kcptun/server
|
||||
env CGO_ENABLED=0 GOOS=linux GOARCH=mips go build -ldflags "$LDFLAGS" -gcflags "$GCFLAGS" -o client_linux_mips github.com/xtaci/kcptun/client
|
||||
env CGO_ENABLED=0 GOOS=linux GOARCH=mips go build -ldflags "$LDFLAGS" -gcflags "$GCFLAGS" -o server_linux_mips github.com/xtaci/kcptun/server
|
||||
|
||||
if $UPX; then upx -9 client_linux_mips* server_linux_mips*;fi
|
||||
tar -zcf kcptun-linux-mipsle-$VERSION.tar.gz client_linux_mipsle server_linux_mipsle
|
||||
tar -zcf kcptun-linux-mips-$VERSION.tar.gz client_linux_mips server_linux_mips
|
||||
$MD5 kcptun-linux-mipsle-$VERSION.tar.gz
|
||||
$MD5 kcptun-linux-mips-$VERSION.tar.gz
|
||||
|
||||
@@ -0,0 +1,44 @@
|
||||
package main
|
||||
|
||||
import (
|
||||
"encoding/json"
|
||||
"os"
|
||||
)
|
||||
|
||||
// Config for client
|
||||
type Config struct {
|
||||
LocalAddr string `json:"localaddr"`
|
||||
RemoteAddr string `json:"remoteaddr"`
|
||||
Key string `json:"key"`
|
||||
Crypt string `json:"crypt"`
|
||||
Mode string `json:"mode"`
|
||||
Conn int `json:"conn"`
|
||||
AutoExpire int `json:"autoexpire"`
|
||||
MTU int `json:"mtu"`
|
||||
SndWnd int `json:"sndwnd"`
|
||||
RcvWnd int `json:"rcvwnd"`
|
||||
DataShard int `json:"datashard"`
|
||||
ParityShard int `json:"parityshard"`
|
||||
DSCP int `json:"dscp"`
|
||||
NoComp bool `json:"nocomp"`
|
||||
AckNodelay bool `json:"acknodelay"`
|
||||
NoDelay int `json:"nodelay"`
|
||||
Interval int `json:"interval"`
|
||||
Resend int `json:"resend"`
|
||||
NoCongestion int `json:"nc"`
|
||||
SockBuf int `json:"sockbuf"`
|
||||
KeepAlive int `json:"keepalive"`
|
||||
Log string `json:"log"`
|
||||
SnmpLog string `json:"snmplog"`
|
||||
SnmpPeriod int `json:"snmpperiod"`
|
||||
}
|
||||
|
||||
func parseJSONConfig(config *Config, path string) error {
|
||||
file, err := os.Open(path) // For read access.
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
defer file.Close()
|
||||
|
||||
return json.NewDecoder(file).Decode(config)
|
||||
}
|
||||
+268
-103
@@ -2,6 +2,8 @@ package main
|
||||
|
||||
import (
|
||||
"crypto/sha1"
|
||||
"encoding/csv"
|
||||
"fmt"
|
||||
"io"
|
||||
"log"
|
||||
"math/rand"
|
||||
@@ -11,10 +13,11 @@ import (
|
||||
|
||||
"golang.org/x/crypto/pbkdf2"
|
||||
|
||||
"github.com/golang/snappy"
|
||||
"github.com/hashicorp/yamux"
|
||||
"github.com/klauspost/compress/snappy"
|
||||
"github.com/pkg/errors"
|
||||
"github.com/urfave/cli"
|
||||
kcp "github.com/xtaci/kcp-go"
|
||||
"github.com/xtaci/smux"
|
||||
)
|
||||
|
||||
var (
|
||||
@@ -52,7 +55,12 @@ func newCompStream(conn net.Conn) *compStream {
|
||||
return c
|
||||
}
|
||||
|
||||
func handleClient(p1, p2 io.ReadWriteCloser) {
|
||||
func handleClient(sess *smux.Session, p1 io.ReadWriteCloser) {
|
||||
p2, err := sess.OpenStream()
|
||||
if err != nil {
|
||||
return
|
||||
}
|
||||
|
||||
log.Println("stream opened")
|
||||
defer log.Println("stream closed")
|
||||
defer p1.Close()
|
||||
@@ -60,16 +68,10 @@ func handleClient(p1, p2 io.ReadWriteCloser) {
|
||||
|
||||
// start tunnel
|
||||
p1die := make(chan struct{})
|
||||
go func() {
|
||||
io.Copy(p1, p2)
|
||||
close(p1die)
|
||||
}()
|
||||
go func() { io.Copy(p1, p2); close(p1die) }()
|
||||
|
||||
p2die := make(chan struct{})
|
||||
go func() {
|
||||
io.Copy(p2, p1)
|
||||
close(p2die)
|
||||
}()
|
||||
go func() { io.Copy(p2, p1); close(p2die) }()
|
||||
|
||||
// wait for tunnel termination
|
||||
select {
|
||||
@@ -80,7 +82,7 @@ func handleClient(p1, p2 io.ReadWriteCloser) {
|
||||
|
||||
func checkError(err error) {
|
||||
if err != nil {
|
||||
log.Println(err)
|
||||
log.Printf("%+v\n", err)
|
||||
os.Exit(-1)
|
||||
}
|
||||
}
|
||||
@@ -93,7 +95,7 @@ func main() {
|
||||
}
|
||||
myApp := cli.NewApp()
|
||||
myApp.Name = "kcptun"
|
||||
myApp.Usage = "kcptun client"
|
||||
myApp.Usage = "client(with SMUX)"
|
||||
myApp.Version = VERSION
|
||||
myApp.Flags = []cli.Flag{
|
||||
cli.StringFlag{
|
||||
@@ -109,28 +111,33 @@ func main() {
|
||||
cli.StringFlag{
|
||||
Name: "key",
|
||||
Value: "it's a secrect",
|
||||
Usage: "key for communcation, must be the same as kcptun server",
|
||||
Usage: "pre-shared secret between client and server",
|
||||
EnvVar: "KCPTUN_KEY",
|
||||
},
|
||||
cli.StringFlag{
|
||||
Name: "crypt",
|
||||
Value: "aes",
|
||||
Usage: "methods for encryption: aes, aes-128, aes-192, tea, xor, none",
|
||||
Usage: "aes, aes-128, aes-192, salsa20, blowfish, twofish, cast5, 3des, tea, xtea, xor, none",
|
||||
},
|
||||
cli.StringFlag{
|
||||
Name: "mode",
|
||||
Value: "fast",
|
||||
Usage: "mode for communication: fast3, fast2, fast, normal",
|
||||
Usage: "profiles: fast3, fast2, fast, normal",
|
||||
},
|
||||
cli.IntFlag{
|
||||
Name: "conn",
|
||||
Value: 1,
|
||||
Usage: "establish N physical connections as specified by 'conn' to server",
|
||||
Usage: "set num of UDP connections to server",
|
||||
},
|
||||
cli.IntFlag{
|
||||
Name: "autoexpire",
|
||||
Value: 0,
|
||||
Usage: "set auto expiration time(in seconds) for a single UDP connection, 0 to disable",
|
||||
},
|
||||
cli.IntFlag{
|
||||
Name: "mtu",
|
||||
Value: 1350,
|
||||
Usage: "set MTU of UDP packets, suggest 'tracepath' to discover path mtu",
|
||||
Usage: "set maximum transmission unit for UDP packets",
|
||||
},
|
||||
cli.IntFlag{
|
||||
Name: "sndwnd",
|
||||
@@ -142,10 +149,6 @@ func main() {
|
||||
Value: 1024,
|
||||
Usage: "set receive window size(num of packets)",
|
||||
},
|
||||
cli.BoolFlag{
|
||||
Name: "nocomp",
|
||||
Usage: "disable compression",
|
||||
},
|
||||
cli.IntFlag{
|
||||
Name: "datashard",
|
||||
Value: 10,
|
||||
@@ -156,16 +159,20 @@ func main() {
|
||||
Value: 3,
|
||||
Usage: "set reed-solomon erasure coding - parityshard",
|
||||
},
|
||||
cli.BoolFlag{
|
||||
Name: "acknodelay",
|
||||
Usage: "flush ack immediately when a packet is received",
|
||||
Hidden: true,
|
||||
},
|
||||
cli.IntFlag{
|
||||
Name: "dscp",
|
||||
Value: 0,
|
||||
Usage: "set DSCP(6bit)",
|
||||
},
|
||||
cli.BoolFlag{
|
||||
Name: "nocomp",
|
||||
Usage: "disable compression",
|
||||
},
|
||||
cli.BoolFlag{
|
||||
Name: "acknodelay",
|
||||
Usage: "flush ack immediately when a packet is received",
|
||||
Hidden: true,
|
||||
},
|
||||
cli.IntFlag{
|
||||
Name: "nodelay",
|
||||
Value: 0,
|
||||
@@ -196,32 +203,87 @@ func main() {
|
||||
Value: 10, // nat keepalive interval in seconds
|
||||
Hidden: true,
|
||||
},
|
||||
cli.StringFlag{
|
||||
Name: "snmplog",
|
||||
Value: "",
|
||||
Usage: "collect snmp to file, aware of timeformat in golang, like: ./snmp-20060102.log",
|
||||
},
|
||||
cli.IntFlag{
|
||||
Name: "snmpperiod",
|
||||
Value: 60,
|
||||
Usage: "snmp collect period, in seconds",
|
||||
},
|
||||
cli.StringFlag{
|
||||
Name: "log",
|
||||
Value: "",
|
||||
Usage: "specify a log file to output, default goes to stderr",
|
||||
},
|
||||
cli.StringFlag{
|
||||
Name: "c",
|
||||
Value: "", // when the value is not empty, the config path must exists
|
||||
Usage: "config from json file, which will override the command from shell",
|
||||
},
|
||||
}
|
||||
myApp.Action = func(c *cli.Context) error {
|
||||
config := Config{}
|
||||
config.LocalAddr = c.String("localaddr")
|
||||
config.RemoteAddr = c.String("remoteaddr")
|
||||
config.Key = c.String("key")
|
||||
config.Crypt = c.String("crypt")
|
||||
config.Mode = c.String("mode")
|
||||
config.Conn = c.Int("conn")
|
||||
config.AutoExpire = c.Int("autoexpire")
|
||||
config.MTU = c.Int("mtu")
|
||||
config.SndWnd = c.Int("sndwnd")
|
||||
config.RcvWnd = c.Int("rcvwnd")
|
||||
config.DataShard = c.Int("datashard")
|
||||
config.ParityShard = c.Int("parityshard")
|
||||
config.DSCP = c.Int("dscp")
|
||||
config.NoComp = c.Bool("nocomp")
|
||||
config.AckNodelay = c.Bool("acknodelay")
|
||||
config.NoDelay = c.Int("nodelay")
|
||||
config.Interval = c.Int("interval")
|
||||
config.Resend = c.Int("resend")
|
||||
config.NoCongestion = c.Int("nc")
|
||||
config.SockBuf = c.Int("sockbuf")
|
||||
config.KeepAlive = c.Int("keepalive")
|
||||
config.Log = c.String("log")
|
||||
config.SnmpLog = c.String("snmplog")
|
||||
config.SnmpPeriod = c.Int("snmpperiod")
|
||||
|
||||
if c.String("c") != "" {
|
||||
err := parseJSONConfig(&config, c.String("c"))
|
||||
checkError(err)
|
||||
}
|
||||
|
||||
// log redirect
|
||||
if config.Log != "" {
|
||||
f, err := os.OpenFile(config.Log, os.O_RDWR|os.O_CREATE|os.O_APPEND, 0666)
|
||||
checkError(err)
|
||||
defer f.Close()
|
||||
log.SetOutput(f)
|
||||
}
|
||||
|
||||
switch config.Mode {
|
||||
case "normal":
|
||||
config.NoDelay, config.Interval, config.Resend, config.NoCongestion = 0, 30, 2, 1
|
||||
case "fast":
|
||||
config.NoDelay, config.Interval, config.Resend, config.NoCongestion = 0, 20, 2, 1
|
||||
case "fast2":
|
||||
config.NoDelay, config.Interval, config.Resend, config.NoCongestion = 1, 20, 2, 1
|
||||
case "fast3":
|
||||
config.NoDelay, config.Interval, config.Resend, config.NoCongestion = 1, 10, 2, 1
|
||||
}
|
||||
|
||||
log.Println("version:", VERSION)
|
||||
addr, err := net.ResolveTCPAddr("tcp", c.String("localaddr"))
|
||||
addr, err := net.ResolveTCPAddr("tcp", config.LocalAddr)
|
||||
checkError(err)
|
||||
listener, err := net.ListenTCP("tcp", addr)
|
||||
checkError(err)
|
||||
|
||||
// kcp server
|
||||
nodelay, interval, resend, nc := c.Int("nodelay"), c.Int("interval"), c.Int("resend"), c.Int("nc")
|
||||
|
||||
switch c.String("mode") {
|
||||
case "normal":
|
||||
nodelay, interval, resend, nc = 0, 30, 2, 1
|
||||
case "fast":
|
||||
nodelay, interval, resend, nc = 0, 20, 2, 1
|
||||
case "fast2":
|
||||
nodelay, interval, resend, nc = 1, 20, 2, 1
|
||||
case "fast3":
|
||||
nodelay, interval, resend, nc = 1, 10, 2, 1
|
||||
}
|
||||
|
||||
crypt := c.String("crypt")
|
||||
pass := pbkdf2.Key([]byte(c.String("key")), []byte(SALT), 4096, 32, sha1.New)
|
||||
pass := pbkdf2.Key([]byte(config.Key), []byte(SALT), 4096, 32, sha1.New)
|
||||
var block kcp.BlockCrypt
|
||||
switch c.String("crypt") {
|
||||
switch config.Crypt {
|
||||
case "tea":
|
||||
block, _ = kcp.NewTEABlockCrypt(pass[:16])
|
||||
case "xor":
|
||||
@@ -232,91 +294,194 @@ func main() {
|
||||
block, _ = kcp.NewAESBlockCrypt(pass[:16])
|
||||
case "aes-192":
|
||||
block, _ = kcp.NewAESBlockCrypt(pass[:24])
|
||||
case "blowfish":
|
||||
block, _ = kcp.NewBlowfishBlockCrypt(pass)
|
||||
case "twofish":
|
||||
block, _ = kcp.NewTwofishBlockCrypt(pass)
|
||||
case "cast5":
|
||||
block, _ = kcp.NewCast5BlockCrypt(pass[:16])
|
||||
case "3des":
|
||||
block, _ = kcp.NewTripleDESBlockCrypt(pass[:24])
|
||||
case "xtea":
|
||||
block, _ = kcp.NewXTEABlockCrypt(pass[:16])
|
||||
case "salsa20":
|
||||
block, _ = kcp.NewSalsa20BlockCrypt(pass)
|
||||
default:
|
||||
config.Crypt = "aes"
|
||||
block, _ = kcp.NewAESBlockCrypt(pass)
|
||||
}
|
||||
|
||||
remoteaddr := c.String("remoteaddr")
|
||||
datashard, parityshard := c.Int("datashard"), c.Int("parityshard")
|
||||
mtu, sndwnd, rcvwnd := c.Int("mtu"), c.Int("sndwnd"), c.Int("rcvwnd")
|
||||
nocomp, acknodelay := c.Bool("nocomp"), c.Bool("acknodelay")
|
||||
dscp, sockbuf, keepalive, conn := c.Int("dscp"), c.Int("sockbuf"), c.Int("keepalive"), c.Int("conn")
|
||||
|
||||
log.Println("listening on:", listener.Addr())
|
||||
log.Println("encryption:", crypt)
|
||||
log.Println("nodelay parameters:", nodelay, interval, resend, nc)
|
||||
log.Println("remote address:", remoteaddr)
|
||||
log.Println("sndwnd:", sndwnd, "rcvwnd:", rcvwnd)
|
||||
log.Println("compression:", !nocomp)
|
||||
log.Println("mtu:", mtu)
|
||||
log.Println("datashard:", datashard, "parityshard:", parityshard)
|
||||
log.Println("acknodelay:", acknodelay)
|
||||
log.Println("dscp:", dscp)
|
||||
log.Println("sockbuf:", sockbuf)
|
||||
log.Println("keepalive:", keepalive)
|
||||
log.Println("conn:", conn)
|
||||
log.Println("encryption:", config.Crypt)
|
||||
log.Println("nodelay parameters:", config.NoDelay, config.Interval, config.Resend, config.NoCongestion)
|
||||
log.Println("remote address:", config.RemoteAddr)
|
||||
log.Println("sndwnd:", config.SndWnd, "rcvwnd:", config.RcvWnd)
|
||||
log.Println("compression:", !config.NoComp)
|
||||
log.Println("mtu:", config.MTU)
|
||||
log.Println("datashard:", config.DataShard, "parityshard:", config.ParityShard)
|
||||
log.Println("acknodelay:", config.AckNodelay)
|
||||
log.Println("dscp:", config.DSCP)
|
||||
log.Println("sockbuf:", config.SockBuf)
|
||||
log.Println("keepalive:", config.KeepAlive)
|
||||
log.Println("conn:", config.Conn)
|
||||
log.Println("autoexpire:", config.AutoExpire)
|
||||
log.Println("snmplog:", config.SnmpLog)
|
||||
log.Println("snmpperiod:", config.SnmpPeriod)
|
||||
|
||||
config := &yamux.Config{
|
||||
AcceptBacklog: 256,
|
||||
EnableKeepAlive: true,
|
||||
KeepAliveInterval: 30 * time.Second,
|
||||
ConnectionWriteTimeout: 30 * time.Second,
|
||||
MaxStreamWindowSize: uint32(sockbuf),
|
||||
LogOutput: os.Stderr,
|
||||
}
|
||||
createConn := func() *yamux.Session {
|
||||
kcpconn, err := kcp.DialWithOptions(remoteaddr, block, datashard, parityshard)
|
||||
checkError(err)
|
||||
smuxConfig := smux.DefaultConfig()
|
||||
smuxConfig.MaxReceiveBuffer = config.SockBuf
|
||||
|
||||
createConn := func() (*smux.Session, error) {
|
||||
kcpconn, err := kcp.DialWithOptions(config.RemoteAddr, block, config.DataShard, config.ParityShard)
|
||||
if err != nil {
|
||||
return nil, errors.Wrap(err, "createConn()")
|
||||
}
|
||||
kcpconn.SetStreamMode(true)
|
||||
kcpconn.SetNoDelay(nodelay, interval, resend, nc)
|
||||
kcpconn.SetWindowSize(sndwnd, rcvwnd)
|
||||
kcpconn.SetMtu(mtu)
|
||||
kcpconn.SetACKNoDelay(acknodelay)
|
||||
kcpconn.SetKeepAlive(keepalive)
|
||||
kcpconn.SetNoDelay(config.NoDelay, config.Interval, config.Resend, config.NoCongestion)
|
||||
kcpconn.SetWindowSize(config.SndWnd, config.RcvWnd)
|
||||
kcpconn.SetMtu(config.MTU)
|
||||
kcpconn.SetACKNoDelay(config.AckNodelay)
|
||||
kcpconn.SetKeepAlive(config.KeepAlive)
|
||||
|
||||
if err := kcpconn.SetDSCP(dscp); err != nil {
|
||||
if err := kcpconn.SetDSCP(config.DSCP); err != nil {
|
||||
log.Println("SetDSCP:", err)
|
||||
}
|
||||
if err := kcpconn.SetReadBuffer(sockbuf); err != nil {
|
||||
if err := kcpconn.SetReadBuffer(config.SockBuf); err != nil {
|
||||
log.Println("SetReadBuffer:", err)
|
||||
}
|
||||
if err := kcpconn.SetWriteBuffer(sockbuf); err != nil {
|
||||
if err := kcpconn.SetWriteBuffer(config.SockBuf); err != nil {
|
||||
log.Println("SetWriteBuffer:", err)
|
||||
}
|
||||
|
||||
// stream multiplex
|
||||
var session *yamux.Session
|
||||
if nocomp {
|
||||
session, err = yamux.Client(kcpconn, config)
|
||||
var session *smux.Session
|
||||
if config.NoComp {
|
||||
session, err = smux.Client(kcpconn, smuxConfig)
|
||||
} else {
|
||||
session, err = yamux.Client(newCompStream(kcpconn), config)
|
||||
session, err = smux.Client(newCompStream(kcpconn), smuxConfig)
|
||||
}
|
||||
if err != nil {
|
||||
return nil, errors.Wrap(err, "createConn()")
|
||||
}
|
||||
return session, nil
|
||||
}
|
||||
|
||||
// wait until a connection is ready
|
||||
waitConn := func() *smux.Session {
|
||||
for {
|
||||
if session, err := createConn(); err == nil {
|
||||
return session
|
||||
} else {
|
||||
time.Sleep(time.Second)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
numconn := uint16(config.Conn)
|
||||
muxes := make([]struct {
|
||||
session *smux.Session
|
||||
ttl time.Time
|
||||
}, numconn)
|
||||
|
||||
for k := range muxes {
|
||||
sess, err := createConn()
|
||||
checkError(err)
|
||||
return session
|
||||
}
|
||||
|
||||
numconn := uint16(conn)
|
||||
var muxes []*yamux.Session
|
||||
for i := uint16(0); i < numconn; i++ {
|
||||
muxes = append(muxes, createConn())
|
||||
muxes[k].session = sess
|
||||
muxes[k].ttl = time.Now().Add(time.Duration(config.AutoExpire) * time.Second)
|
||||
}
|
||||
|
||||
chScavenger := make(chan *smux.Session, 128)
|
||||
go scavenger(chScavenger)
|
||||
go snmpLogger(config.SnmpLog, config.SnmpPeriod)
|
||||
rr := uint16(0)
|
||||
for {
|
||||
p1, err := listener.AcceptTCP()
|
||||
checkError(err)
|
||||
mux := muxes[rr%numconn]
|
||||
p2, err := mux.Open()
|
||||
if err != nil { // yamux failure
|
||||
log.Println(err)
|
||||
p1.Close()
|
||||
muxes[rr%numconn] = createConn()
|
||||
mux.Close()
|
||||
continue
|
||||
if err != nil {
|
||||
log.Fatalln(err)
|
||||
}
|
||||
go handleClient(p1, p2)
|
||||
if err := p1.SetReadBuffer(config.SockBuf); err != nil {
|
||||
log.Println("TCP SetReadBuffer:", err)
|
||||
}
|
||||
if err := p1.SetWriteBuffer(config.SockBuf); err != nil {
|
||||
log.Println("TCP SetWriteBuffer:", err)
|
||||
}
|
||||
checkError(err)
|
||||
idx := rr % numconn
|
||||
|
||||
// do auto expiration && reconnection
|
||||
if muxes[idx].session.IsClosed() || (config.AutoExpire > 0 && time.Now().After(muxes[idx].ttl)) {
|
||||
chScavenger <- muxes[idx].session
|
||||
muxes[idx].session = waitConn()
|
||||
muxes[idx].ttl = time.Now().Add(time.Duration(config.AutoExpire) * time.Second)
|
||||
}
|
||||
|
||||
go handleClient(muxes[idx].session, p1)
|
||||
rr++
|
||||
}
|
||||
}
|
||||
myApp.Run(os.Args)
|
||||
}
|
||||
|
||||
type scavengeSession struct {
|
||||
session *smux.Session
|
||||
ttl time.Time
|
||||
}
|
||||
|
||||
const (
|
||||
maxScavengeTTL = 10 * time.Minute
|
||||
)
|
||||
|
||||
func scavenger(ch chan *smux.Session) {
|
||||
ticker := time.NewTicker(30 * time.Second)
|
||||
defer ticker.Stop()
|
||||
var sessionList []scavengeSession
|
||||
for {
|
||||
select {
|
||||
case sess := <-ch:
|
||||
sessionList = append(sessionList, scavengeSession{sess, time.Now()})
|
||||
case <-ticker.C:
|
||||
var newList []scavengeSession
|
||||
for k := range sessionList {
|
||||
s := sessionList[k]
|
||||
if s.session.NumStreams() == 0 || s.session.IsClosed() || time.Since(s.ttl) > maxScavengeTTL {
|
||||
log.Println("session scavenged")
|
||||
s.session.Close()
|
||||
} else {
|
||||
newList = append(newList, sessionList[k])
|
||||
}
|
||||
}
|
||||
sessionList = newList
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func snmpLogger(path string, interval int) {
|
||||
if path == "" || interval == 0 {
|
||||
return
|
||||
}
|
||||
ticker := time.NewTicker(time.Duration(interval) * time.Second)
|
||||
defer ticker.Stop()
|
||||
for {
|
||||
select {
|
||||
case <-ticker.C:
|
||||
f, err := os.OpenFile(time.Now().Format(path), os.O_RDWR|os.O_CREATE|os.O_APPEND, 0666)
|
||||
if err != nil {
|
||||
log.Println(err)
|
||||
return
|
||||
}
|
||||
w := csv.NewWriter(f)
|
||||
// write header in empty file
|
||||
if stat, err := f.Stat(); err == nil && stat.Size() == 0 {
|
||||
if err := w.Write(append([]string{"Unix"}, kcp.DefaultSnmp.Header()...)); err != nil {
|
||||
log.Println(err)
|
||||
}
|
||||
}
|
||||
if err := w.Write(append([]string{fmt.Sprint(time.Now().Unix())}, kcp.DefaultSnmp.ToSlice()...)); err != nil {
|
||||
log.Println(err)
|
||||
}
|
||||
kcp.DefaultSnmp.Reset()
|
||||
w.Flush()
|
||||
f.Close()
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
Binary file not shown.
|
After Width: | Height: | Size: 59 KiB |
@@ -0,0 +1,42 @@
|
||||
package main
|
||||
|
||||
import (
|
||||
"encoding/json"
|
||||
"os"
|
||||
)
|
||||
|
||||
// Config for server
|
||||
type Config struct {
|
||||
Listen string `json:"listen"`
|
||||
Target string `json:"target"`
|
||||
Key string `json:"key"`
|
||||
Crypt string `json:"crypt"`
|
||||
Mode string `json:"mode"`
|
||||
MTU int `json:"mtu"`
|
||||
SndWnd int `json:"sndwnd"`
|
||||
RcvWnd int `json:"rcvwnd"`
|
||||
DataShard int `json:"datashard"`
|
||||
ParityShard int `json:"parityshard"`
|
||||
DSCP int `json:"dscp"`
|
||||
NoComp bool `json:"nocomp"`
|
||||
AckNodelay bool `json:"acknodelay"`
|
||||
NoDelay int `json:"nodelay"`
|
||||
Interval int `json:"interval"`
|
||||
Resend int `json:"resend"`
|
||||
NoCongestion int `json:"nc"`
|
||||
SockBuf int `json:"sockbuf"`
|
||||
KeepAlive int `json:"keepalive"`
|
||||
Log string `json:"log"`
|
||||
SnmpLog string `json:"snmplog"`
|
||||
SnmpPeriod int `json:"snmpperiod"`
|
||||
}
|
||||
|
||||
func parseJSONConfig(config *Config, path string) error {
|
||||
file, err := os.Open(path) // For read access.
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
defer file.Close()
|
||||
|
||||
return json.NewDecoder(file).Decode(config)
|
||||
}
|
||||
+186
-87
@@ -2,6 +2,8 @@ package main
|
||||
|
||||
import (
|
||||
"crypto/sha1"
|
||||
"encoding/csv"
|
||||
"fmt"
|
||||
"io"
|
||||
"log"
|
||||
"math/rand"
|
||||
@@ -11,10 +13,10 @@ import (
|
||||
|
||||
"golang.org/x/crypto/pbkdf2"
|
||||
|
||||
"github.com/golang/snappy"
|
||||
"github.com/hashicorp/yamux"
|
||||
"github.com/klauspost/compress/snappy"
|
||||
"github.com/urfave/cli"
|
||||
kcp "github.com/xtaci/kcp-go"
|
||||
"github.com/xtaci/smux"
|
||||
)
|
||||
|
||||
var (
|
||||
@@ -53,25 +55,33 @@ func newCompStream(conn net.Conn) *compStream {
|
||||
}
|
||||
|
||||
// handle multiplex-ed connection
|
||||
func handleMux(conn io.ReadWriteCloser, target string, config *yamux.Config) {
|
||||
func handleMux(conn io.ReadWriteCloser, config *Config) {
|
||||
// stream multiplex
|
||||
mux, err := yamux.Server(conn, config)
|
||||
smuxConfig := smux.DefaultConfig()
|
||||
smuxConfig.MaxReceiveBuffer = config.SockBuf
|
||||
mux, err := smux.Server(conn, smuxConfig)
|
||||
if err != nil {
|
||||
log.Println(err)
|
||||
return
|
||||
}
|
||||
defer mux.Close()
|
||||
|
||||
for {
|
||||
p1, err := mux.Accept()
|
||||
p1, err := mux.AcceptStream()
|
||||
if err != nil {
|
||||
log.Println(err)
|
||||
return
|
||||
}
|
||||
p2, err := net.DialTimeout("tcp", target, 5*time.Second)
|
||||
p2, err := net.DialTimeout("tcp", config.Target, 5*time.Second)
|
||||
if err != nil {
|
||||
p1.Close()
|
||||
log.Println(err)
|
||||
return
|
||||
continue
|
||||
}
|
||||
if err := p2.(*net.TCPConn).SetReadBuffer(config.SockBuf); err != nil {
|
||||
log.Println("TCP SetReadBuffer:", err)
|
||||
}
|
||||
if err := p2.(*net.TCPConn).SetWriteBuffer(config.SockBuf); err != nil {
|
||||
log.Println("TCP SetWriteBuffer:", err)
|
||||
}
|
||||
go handleClient(p1, p2)
|
||||
}
|
||||
@@ -85,16 +95,10 @@ func handleClient(p1, p2 io.ReadWriteCloser) {
|
||||
|
||||
// start tunnel
|
||||
p1die := make(chan struct{})
|
||||
go func() {
|
||||
io.Copy(p1, p2)
|
||||
close(p1die)
|
||||
}()
|
||||
go func() { io.Copy(p1, p2); close(p1die) }()
|
||||
|
||||
p2die := make(chan struct{})
|
||||
go func() {
|
||||
io.Copy(p2, p1)
|
||||
close(p2die)
|
||||
}()
|
||||
go func() { io.Copy(p2, p1); close(p2die) }()
|
||||
|
||||
// wait for tunnel termination
|
||||
select {
|
||||
@@ -103,6 +107,13 @@ func handleClient(p1, p2 io.ReadWriteCloser) {
|
||||
}
|
||||
}
|
||||
|
||||
func checkError(err error) {
|
||||
if err != nil {
|
||||
log.Printf("%+v\n", err)
|
||||
os.Exit(-1)
|
||||
}
|
||||
}
|
||||
|
||||
func main() {
|
||||
rand.Seed(int64(time.Now().Nanosecond()))
|
||||
if VERSION == "SELFBUILD" {
|
||||
@@ -111,7 +122,7 @@ func main() {
|
||||
}
|
||||
myApp := cli.NewApp()
|
||||
myApp.Name = "kcptun"
|
||||
myApp.Usage = "kcptun server"
|
||||
myApp.Usage = "server(with SMUX)"
|
||||
myApp.Version = VERSION
|
||||
myApp.Flags = []cli.Flag{
|
||||
cli.StringFlag{
|
||||
@@ -127,23 +138,23 @@ func main() {
|
||||
cli.StringFlag{
|
||||
Name: "key",
|
||||
Value: "it's a secrect",
|
||||
Usage: "key for communcation, must be the same as kcptun client",
|
||||
Usage: "pre-shared secret between client and server",
|
||||
EnvVar: "KCPTUN_KEY",
|
||||
},
|
||||
cli.StringFlag{
|
||||
Name: "crypt",
|
||||
Value: "aes",
|
||||
Usage: "methods for encryption: aes, aes-128, aes-192, tea, xor, none",
|
||||
Usage: "aes, aes-128, aes-192, salsa20, blowfish, twofish, cast5, 3des, tea, xtea, xor, none",
|
||||
},
|
||||
cli.StringFlag{
|
||||
Name: "mode",
|
||||
Value: "fast",
|
||||
Usage: "mode for communication: fast3, fast2, fast, normal",
|
||||
Usage: "profiles: fast3, fast2, fast, normal",
|
||||
},
|
||||
cli.IntFlag{
|
||||
Name: "mtu",
|
||||
Value: 1350,
|
||||
Usage: "set MTU of UDP packets, suggest 'tracepath' to discover path mtu",
|
||||
Usage: "set maximum transmission unit for UDP packets",
|
||||
},
|
||||
cli.IntFlag{
|
||||
Name: "sndwnd",
|
||||
@@ -155,10 +166,6 @@ func main() {
|
||||
Value: 1024,
|
||||
Usage: "set receive window size(num of packets)",
|
||||
},
|
||||
cli.BoolFlag{
|
||||
Name: "nocomp",
|
||||
Usage: "disable compression",
|
||||
},
|
||||
cli.IntFlag{
|
||||
Name: "datashard",
|
||||
Value: 10,
|
||||
@@ -169,16 +176,20 @@ func main() {
|
||||
Value: 3,
|
||||
Usage: "set reed-solomon erasure coding - parityshard",
|
||||
},
|
||||
cli.BoolFlag{
|
||||
Name: "acknodelay",
|
||||
Usage: "flush ack immediately when a packet is received",
|
||||
Hidden: true,
|
||||
},
|
||||
cli.IntFlag{
|
||||
Name: "dscp",
|
||||
Value: 0,
|
||||
Usage: "set DSCP(6bit)",
|
||||
},
|
||||
cli.BoolFlag{
|
||||
Name: "nocomp",
|
||||
Usage: "disable compression",
|
||||
},
|
||||
cli.BoolFlag{
|
||||
Name: "acknodelay",
|
||||
Usage: "flush ack immediately when a packet is received",
|
||||
Hidden: true,
|
||||
},
|
||||
cli.IntFlag{
|
||||
Name: "nodelay",
|
||||
Value: 0,
|
||||
@@ -209,25 +220,81 @@ func main() {
|
||||
Value: 10, // nat keepalive interval in seconds
|
||||
Hidden: true,
|
||||
},
|
||||
cli.StringFlag{
|
||||
Name: "snmplog",
|
||||
Value: "",
|
||||
Usage: "collect snmp to file, aware of timeformat in golang, like: ./snmp-20060102.log",
|
||||
},
|
||||
cli.IntFlag{
|
||||
Name: "snmpperiod",
|
||||
Value: 60,
|
||||
Usage: "snmp collect period, in seconds",
|
||||
},
|
||||
cli.StringFlag{
|
||||
Name: "log",
|
||||
Value: "",
|
||||
Usage: "specify a log file to output, default goes to stderr",
|
||||
},
|
||||
cli.StringFlag{
|
||||
Name: "c",
|
||||
Value: "", // when the value is not empty, the config path must exists
|
||||
Usage: "config from json file, which will override the command from shell",
|
||||
},
|
||||
}
|
||||
myApp.Action = func(c *cli.Context) error {
|
||||
log.Println("version:", VERSION)
|
||||
nodelay, interval, resend, nc := c.Int("nodelay"), c.Int("interval"), c.Int("resend"), c.Int("nc")
|
||||
switch c.String("mode") {
|
||||
case "normal":
|
||||
nodelay, interval, resend, nc = 0, 30, 2, 1
|
||||
case "fast":
|
||||
nodelay, interval, resend, nc = 0, 20, 2, 1
|
||||
case "fast2":
|
||||
nodelay, interval, resend, nc = 1, 20, 2, 1
|
||||
case "fast3":
|
||||
nodelay, interval, resend, nc = 1, 10, 2, 1
|
||||
config := Config{}
|
||||
config.Listen = c.String("listen")
|
||||
config.Target = c.String("target")
|
||||
config.Key = c.String("key")
|
||||
config.Crypt = c.String("crypt")
|
||||
config.Mode = c.String("mode")
|
||||
config.MTU = c.Int("mtu")
|
||||
config.SndWnd = c.Int("sndwnd")
|
||||
config.RcvWnd = c.Int("rcvwnd")
|
||||
config.DataShard = c.Int("datashard")
|
||||
config.ParityShard = c.Int("parityshard")
|
||||
config.DSCP = c.Int("dscp")
|
||||
config.NoComp = c.Bool("nocomp")
|
||||
config.AckNodelay = c.Bool("acknodelay")
|
||||
config.NoDelay = c.Int("nodelay")
|
||||
config.Interval = c.Int("interval")
|
||||
config.Resend = c.Int("resend")
|
||||
config.NoCongestion = c.Int("nc")
|
||||
config.SockBuf = c.Int("sockbuf")
|
||||
config.KeepAlive = c.Int("keepalive")
|
||||
config.Log = c.String("log")
|
||||
config.SnmpLog = c.String("snmplog")
|
||||
config.SnmpPeriod = c.Int("snmpperiod")
|
||||
|
||||
if c.String("c") != "" {
|
||||
//Now only support json config file
|
||||
err := parseJSONConfig(&config, c.String("c"))
|
||||
checkError(err)
|
||||
}
|
||||
|
||||
crypt := c.String("crypt")
|
||||
pass := pbkdf2.Key([]byte(c.String("key")), []byte(SALT), 4096, 32, sha1.New)
|
||||
// log redirect
|
||||
if config.Log != "" {
|
||||
f, err := os.OpenFile(config.Log, os.O_RDWR|os.O_CREATE|os.O_APPEND, 0666)
|
||||
checkError(err)
|
||||
defer f.Close()
|
||||
log.SetOutput(f)
|
||||
}
|
||||
|
||||
switch config.Mode {
|
||||
case "normal":
|
||||
config.NoDelay, config.Interval, config.Resend, config.NoCongestion = 0, 30, 2, 1
|
||||
case "fast":
|
||||
config.NoDelay, config.Interval, config.Resend, config.NoCongestion = 0, 20, 2, 1
|
||||
case "fast2":
|
||||
config.NoDelay, config.Interval, config.Resend, config.NoCongestion = 1, 20, 2, 1
|
||||
case "fast3":
|
||||
config.NoDelay, config.Interval, config.Resend, config.NoCongestion = 1, 10, 2, 1
|
||||
}
|
||||
|
||||
log.Println("version:", VERSION)
|
||||
pass := pbkdf2.Key([]byte(config.Key), []byte(SALT), 4096, 32, sha1.New)
|
||||
var block kcp.BlockCrypt
|
||||
switch crypt {
|
||||
switch config.Crypt {
|
||||
case "tea":
|
||||
block, _ = kcp.NewTEABlockCrypt(pass[:16])
|
||||
case "xor":
|
||||
@@ -238,69 +305,101 @@ func main() {
|
||||
block, _ = kcp.NewAESBlockCrypt(pass[:16])
|
||||
case "aes-192":
|
||||
block, _ = kcp.NewAESBlockCrypt(pass[:24])
|
||||
case "blowfish":
|
||||
block, _ = kcp.NewBlowfishBlockCrypt(pass)
|
||||
case "twofish":
|
||||
block, _ = kcp.NewTwofishBlockCrypt(pass)
|
||||
case "cast5":
|
||||
block, _ = kcp.NewCast5BlockCrypt(pass[:16])
|
||||
case "3des":
|
||||
block, _ = kcp.NewTripleDESBlockCrypt(pass[:24])
|
||||
case "xtea":
|
||||
block, _ = kcp.NewXTEABlockCrypt(pass[:16])
|
||||
case "salsa20":
|
||||
block, _ = kcp.NewSalsa20BlockCrypt(pass)
|
||||
default:
|
||||
config.Crypt = "aes"
|
||||
block, _ = kcp.NewAESBlockCrypt(pass)
|
||||
}
|
||||
|
||||
datashard, parityshard := c.Int("datashard"), c.Int("parityshard")
|
||||
lis, err := kcp.ListenWithOptions(c.String("listen"), block, datashard, parityshard)
|
||||
if err != nil {
|
||||
log.Fatal(err)
|
||||
}
|
||||
lis, err := kcp.ListenWithOptions(config.Listen, block, config.DataShard, config.ParityShard)
|
||||
checkError(err)
|
||||
log.Println("listening on:", lis.Addr())
|
||||
log.Println("target:", config.Target)
|
||||
log.Println("encryption:", config.Crypt)
|
||||
log.Println("nodelay parameters:", config.NoDelay, config.Interval, config.Resend, config.NoCongestion)
|
||||
log.Println("sndwnd:", config.SndWnd, "rcvwnd:", config.RcvWnd)
|
||||
log.Println("compression:", !config.NoComp)
|
||||
log.Println("mtu:", config.MTU)
|
||||
log.Println("datashard:", config.DataShard, "parityshard:", config.ParityShard)
|
||||
log.Println("acknodelay:", config.AckNodelay)
|
||||
log.Println("dscp:", config.DSCP)
|
||||
log.Println("sockbuf:", config.SockBuf)
|
||||
log.Println("keepalive:", config.KeepAlive)
|
||||
log.Println("snmplog:", config.SnmpLog)
|
||||
log.Println("snmpperiod:", config.SnmpPeriod)
|
||||
|
||||
mtu, sndwnd, rcvwnd := c.Int("mtu"), c.Int("sndwnd"), c.Int("rcvwnd")
|
||||
nocomp, acknodelay := c.Bool("nocomp"), c.Bool("acknodelay")
|
||||
dscp, sockbuf, keepalive := c.Int("dscp"), c.Int("sockbuf"), c.Int("keepalive")
|
||||
target := c.String("target")
|
||||
|
||||
log.Println("listening on ", lis.Addr())
|
||||
log.Println("encryption:", crypt)
|
||||
log.Println("nodelay parameters:", nodelay, interval, resend, nc)
|
||||
log.Println("sndwnd:", sndwnd, "rcvwnd:", rcvwnd)
|
||||
log.Println("compression:", !nocomp)
|
||||
log.Println("mtu:", mtu)
|
||||
log.Println("datashard:", datashard, "parityshard:", parityshard)
|
||||
log.Println("acknodelay:", acknodelay)
|
||||
log.Println("dscp:", dscp)
|
||||
log.Println("sockbuf:", sockbuf)
|
||||
log.Println("keepalive:", keepalive)
|
||||
|
||||
if err := lis.SetDSCP(dscp); err != nil {
|
||||
if err := lis.SetDSCP(config.DSCP); err != nil {
|
||||
log.Println("SetDSCP:", err)
|
||||
}
|
||||
if err := lis.SetReadBuffer(sockbuf); err != nil {
|
||||
if err := lis.SetReadBuffer(config.SockBuf); err != nil {
|
||||
log.Println("SetReadBuffer:", err)
|
||||
}
|
||||
if err := lis.SetWriteBuffer(sockbuf); err != nil {
|
||||
if err := lis.SetWriteBuffer(config.SockBuf); err != nil {
|
||||
log.Println("SetWriteBuffer:", err)
|
||||
}
|
||||
config := &yamux.Config{
|
||||
AcceptBacklog: 256,
|
||||
EnableKeepAlive: true,
|
||||
KeepAliveInterval: 30 * time.Second,
|
||||
ConnectionWriteTimeout: 30 * time.Second,
|
||||
MaxStreamWindowSize: uint32(sockbuf),
|
||||
LogOutput: os.Stderr,
|
||||
}
|
||||
|
||||
go snmpLogger(config.SnmpLog, config.SnmpPeriod)
|
||||
for {
|
||||
if conn, err := lis.Accept(); err == nil {
|
||||
if conn, err := lis.AcceptKCP(); err == nil {
|
||||
log.Println("remote address:", conn.RemoteAddr())
|
||||
conn.SetStreamMode(true)
|
||||
conn.SetNoDelay(nodelay, interval, resend, nc)
|
||||
conn.SetMtu(mtu)
|
||||
conn.SetWindowSize(sndwnd, rcvwnd)
|
||||
conn.SetACKNoDelay(acknodelay)
|
||||
conn.SetKeepAlive(keepalive)
|
||||
conn.SetNoDelay(config.NoDelay, config.Interval, config.Resend, config.NoCongestion)
|
||||
conn.SetMtu(config.MTU)
|
||||
conn.SetWindowSize(config.SndWnd, config.RcvWnd)
|
||||
conn.SetACKNoDelay(config.AckNodelay)
|
||||
conn.SetKeepAlive(config.KeepAlive)
|
||||
|
||||
if nocomp {
|
||||
go handleMux(conn, target, config)
|
||||
if config.NoComp {
|
||||
go handleMux(conn, &config)
|
||||
} else {
|
||||
go handleMux(newCompStream(conn), target, config)
|
||||
go handleMux(newCompStream(conn), &config)
|
||||
}
|
||||
} else {
|
||||
log.Println(err)
|
||||
log.Printf("%+v", err)
|
||||
}
|
||||
}
|
||||
}
|
||||
myApp.Run(os.Args)
|
||||
}
|
||||
|
||||
func snmpLogger(path string, interval int) {
|
||||
if path == "" || interval == 0 {
|
||||
return
|
||||
}
|
||||
ticker := time.NewTicker(time.Duration(interval) * time.Second)
|
||||
defer ticker.Stop()
|
||||
for {
|
||||
select {
|
||||
case <-ticker.C:
|
||||
f, err := os.OpenFile(time.Now().Format(path), os.O_RDWR|os.O_CREATE|os.O_APPEND, 0666)
|
||||
if err != nil {
|
||||
log.Println(err)
|
||||
return
|
||||
}
|
||||
w := csv.NewWriter(f)
|
||||
// write header in empty file
|
||||
if stat, err := f.Stat(); err == nil && stat.Size() == 0 {
|
||||
if err := w.Write(append([]string{"Unix"}, kcp.DefaultSnmp.Header()...)); err != nil {
|
||||
log.Println(err)
|
||||
}
|
||||
}
|
||||
if err := w.Write(append([]string{fmt.Sprint(time.Now().Unix())}, kcp.DefaultSnmp.ToSlice()...)); err != nil {
|
||||
log.Println(err)
|
||||
}
|
||||
kcp.DefaultSnmp.Reset()
|
||||
w.Flush()
|
||||
f.Close()
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user