mirror of
https://github.com/xtaci/kcptun.git
synced 2024-04-21 12:32:32 +00:00
Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
e26ab6729f | ||
|
|
583fe3ba24 | ||
|
|
7fd6442284 | ||
|
|
81f4643830 | ||
|
|
744a6407e7 | ||
|
|
2cf5292ac1 | ||
|
|
b3a8b631b4 | ||
|
|
1167419210 | ||
|
|
56f9f0d01a | ||
|
|
96888f1cac | ||
|
|
e752d70c79 | ||
|
|
a882b94e5b | ||
|
|
790a6d5352 | ||
|
|
603c2db5ab | ||
|
|
581df3a34d | ||
|
|
6113d2b497 |
+1
-2
@@ -3,7 +3,6 @@ MAINTAINER xtaci <daniel820313@gmail.com>
|
||||
RUN apk update && \
|
||||
apk upgrade && \
|
||||
apk add git
|
||||
RUN go get github.com/xtaci/kcptun/client
|
||||
RUN go get github.com/xtaci/kcptun/server
|
||||
RUN go get github.com/xtaci/kcptun/client && go get github.com/xtaci/kcptun/server
|
||||
EXPOSE 29900/udp
|
||||
EXPOSE 12948
|
||||
|
||||
+26
-18
@@ -1,7 +1,7 @@
|
||||
# <img src="logo.png" alt="kcptun" height="60px" />
|
||||
[![GoDoc][1]][2] [![Release][13]][14] [![Powered][17]][18] [![MIT licensed][11]][12] [![Build Status][3]][4] [![Go Report Card][5]][6] [![Downloads][15]][16] [![Gitter][19]][20]
|
||||
[1]: https://godoc.org/github.com/xtaci/kcptun?status.svg
|
||||
[2]: https://godoc.org/github.com/xtaci/kcptun
|
||||
[![Release][13]][14] [![Powered][17]][18] [![MIT licensed][11]][12] [![Build Status][3]][4] [![Go Report Card][5]][6] [![Downloads][15]][16] [![Gitter][19]][20] [![Docker][1]][2]
|
||||
[1]: https://images.microbadger.com/badges/image/xtaci/kcptun.svg
|
||||
[2]: https://microbadger.com/images/xtaci/kcptun
|
||||
[3]: https://travis-ci.org/xtaci/kcptun.svg?branch=master
|
||||
[4]: https://travis-ci.org/xtaci/kcptun
|
||||
[5]: https://goreportcard.com/badge/github.com/xtaci/kcptun
|
||||
@@ -40,7 +40,9 @@ Client Side: ./client_darwin_amd64 -r "SERVERIP:4000" -l ":1080" -mode fast2 //
|
||||
* WIFI: 5GHz TL-WDR3320
|
||||
|
||||
### *Usage* :lollipop:
|
||||
Help output under MacOS X:
|
||||
```
|
||||
$ ./client_darwin_amd64 -h
|
||||
NAME:
|
||||
kcptun - kcptun client
|
||||
|
||||
@@ -48,7 +50,7 @@ USAGE:
|
||||
client_darwin_amd64 [global options] command [command options] [arguments...]
|
||||
|
||||
VERSION:
|
||||
20160816
|
||||
20160820
|
||||
|
||||
COMMANDS:
|
||||
help, h Shows a list of commands or help for one command
|
||||
@@ -56,22 +58,22 @@ COMMANDS:
|
||||
GLOBAL OPTIONS:
|
||||
--localaddr value, -l value local listen address (default: ":12948")
|
||||
--remoteaddr value, -r value kcp server address (default: "vps:29900")
|
||||
--key value key for communcation, must be the same as kcptun server (default: "it's a secrect") [$KCPTUN_KEY]
|
||||
--crypt value methods for encryption: aes, aes-128, aes-192, tea, xor, none (default: "aes")
|
||||
--mode value mode for communication: fast3, fast2, fast, normal (default: "fast")
|
||||
--conn value establish N physical connections as specified by 'conn' to server (default: 1)
|
||||
--mtu value set MTU of UDP packets, suggest 'tracepath' to discover path mtu (default: 1350)
|
||||
--key value pre-shared secret for client and server (default: "it's a secrect") [$KCPTUN_KEY]
|
||||
--crypt value aes, aes-128, aes-192, salsa20, blowfish, twofish, cast5, 3des, tea, xtea, xor, none (default: "aes")
|
||||
--mode value profiles: fast3, fast2, fast, normal (default: "fast")
|
||||
--conn value set num of UDP connections to server (default: 1)
|
||||
--mtu value set maximum transmission unit of UDP packets (default: 1350)
|
||||
--sndwnd value set send window size(num of packets) (default: 128)
|
||||
--rcvwnd value set receive window size(num of packets) (default: 1024)
|
||||
--nocomp disable compression
|
||||
--datashard value set reed-solomon erasure coding - datashard (default: 10)
|
||||
--parityshard value set reed-solomon erasure coding - parityshard (default: 3)
|
||||
--dscp value set DSCP(6bit) (default: 0)
|
||||
--nocomp disable compression
|
||||
--help, -h show help
|
||||
--version, -v print the version
|
||||
```
|
||||
|
||||
```
|
||||
|
||||
$ ./server_darwin_amd64 -h
|
||||
NAME:
|
||||
kcptun - kcptun server
|
||||
|
||||
@@ -79,7 +81,7 @@ USAGE:
|
||||
server_darwin_amd64 [global options] command [command options] [arguments...]
|
||||
|
||||
VERSION:
|
||||
20160816
|
||||
20160820
|
||||
|
||||
COMMANDS:
|
||||
help, h Shows a list of commands or help for one command
|
||||
@@ -87,16 +89,16 @@ COMMANDS:
|
||||
GLOBAL OPTIONS:
|
||||
--listen value, -l value kcp server listen address (default: ":29900")
|
||||
--target value, -t value target server address (default: "127.0.0.1:12948")
|
||||
--key value key for communcation, must be the same as kcptun client (default: "it's a secrect") [$KCPTUN_KEY]
|
||||
--crypt value methods for encryption: aes, aes-128, aes-192, tea, xor, none (default: "aes")
|
||||
--mode value mode for communication: fast3, fast2, fast, normal (default: "fast")
|
||||
--mtu value set MTU of UDP packets, suggest 'tracepath' to discover path mtu (default: 1350)
|
||||
--key value pre-shared secret for client and server (default: "it's a secrect") [$KCPTUN_KEY]
|
||||
--crypt value aes, aes-128, aes-192, salsa20, blowfish, twofish, cast5, 3des, tea, xtea, xor, none (default: "aes")
|
||||
--mode value profiles: fast3, fast2, fast, normal (default: "fast")
|
||||
--mtu value set maximum transmission unit of UDP packets (default: 1350)
|
||||
--sndwnd value set send window size(num of packets) (default: 1024)
|
||||
--rcvwnd value set receive window size(num of packets) (default: 1024)
|
||||
--nocomp disable compression
|
||||
--datashard value set reed-solomon erasure coding - datashard (default: 10)
|
||||
--parityshard value set reed-solomon erasure coding - parityshard (default: 3)
|
||||
--dscp value set DSCP(6bit) (default: 0)
|
||||
--nocomp disable compression
|
||||
--help, -h show help
|
||||
--version, -v print the version
|
||||
```
|
||||
@@ -122,6 +124,12 @@ other parameters can be set independently.
|
||||
|
||||
***NOTICE: if too much retranmission happens, it's quite possible the windows are too large***
|
||||
|
||||
### *Security* :lollipop:
|
||||
No matter what encryption you are using for application layer, if you specify ```-crypt none``` to kcptun,
|
||||
the header will be ***PLAINTEXT*** to everyone; I suggest ```-crypt aes-128``` for encryption at least .
|
||||
|
||||
NOTICE: ```-crypt xor``` is also insecure, do not use this unless you know what you are doing.
|
||||
|
||||
### *Memory Control* :lollipop:
|
||||
Routers, mobile devices are sensitive to memory consumption; by setting GOGC environment(eg: GOGC=20) will lower memory consumption.
|
||||
Reference: https://blog.golang.org/go15gc
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
# <img src="logo.png" alt="kcptun" height="60px" />
|
||||
[![GoDoc][1]][2] [![Release][13]][14] [![Powered][17]][18] [![MIT licensed][11]][12] [![Build Status][3]][4] [![Go Report Card][5]][6] [![Downloads][15]][16] [![Gitter][19]][20]
|
||||
[1]: https://godoc.org/github.com/xtaci/kcptun?status.svg
|
||||
[2]: https://godoc.org/github.com/xtaci/kcptun
|
||||
[![Release][13]][14] [![Powered][17]][18] [![MIT licensed][11]][12] [![Build Status][3]][4] [![Go Report Card][5]][6] [![Downloads][15]][16] [![Gitter][19]][20] [![Docker][1]][2]
|
||||
[1]: https://images.microbadger.com/badges/image/xtaci/kcptun.svg
|
||||
[2]: https://microbadger.com/images/xtaci/kcptun
|
||||
[3]: https://travis-ci.org/xtaci/kcptun.svg?branch=master
|
||||
[4]: https://travis-ci.org/xtaci/kcptun
|
||||
[5]: https://goreportcard.com/badge/github.com/xtaci/kcptun
|
||||
@@ -39,6 +39,7 @@
|
||||
### *使用方法* :lollipop:
|
||||
在Mac OS X El Capitan下的帮助输出:
|
||||
```
|
||||
$ ./client_darwin_amd64 -h
|
||||
NAME:
|
||||
kcptun - kcptun client
|
||||
|
||||
@@ -46,7 +47,7 @@ USAGE:
|
||||
client_darwin_amd64 [global options] command [command options] [arguments...]
|
||||
|
||||
VERSION:
|
||||
20160816
|
||||
20160820
|
||||
|
||||
COMMANDS:
|
||||
help, h Shows a list of commands or help for one command
|
||||
@@ -54,22 +55,22 @@ COMMANDS:
|
||||
GLOBAL OPTIONS:
|
||||
--localaddr value, -l value local listen address (default: ":12948")
|
||||
--remoteaddr value, -r value kcp server address (default: "vps:29900")
|
||||
--key value key for communcation, must be the same as kcptun server (default: "it's a secrect") [$KCPTUN_KEY]
|
||||
--crypt value methods for encryption: aes, aes-128, aes-192, tea, xor, none (default: "aes")
|
||||
--mode value mode for communication: fast3, fast2, fast, normal (default: "fast")
|
||||
--conn value establish N physical connections as specified by 'conn' to server (default: 1)
|
||||
--mtu value set MTU of UDP packets, suggest 'tracepath' to discover path mtu (default: 1350)
|
||||
--key value pre-shared secret for client and server (default: "it's a secrect") [$KCPTUN_KEY]
|
||||
--crypt value aes, aes-128, aes-192, salsa20, blowfish, twofish, cast5, 3des, tea, xtea, xor, none (default: "aes")
|
||||
--mode value profiles: fast3, fast2, fast, normal (default: "fast")
|
||||
--conn value set num of UDP connections to server (default: 1)
|
||||
--mtu value set maximum transmission unit of UDP packets (default: 1350)
|
||||
--sndwnd value set send window size(num of packets) (default: 128)
|
||||
--rcvwnd value set receive window size(num of packets) (default: 1024)
|
||||
--nocomp disable compression
|
||||
--datashard value set reed-solomon erasure coding - datashard (default: 10)
|
||||
--parityshard value set reed-solomon erasure coding - parityshard (default: 3)
|
||||
--dscp value set DSCP(6bit) (default: 0)
|
||||
--nocomp disable compression
|
||||
--help, -h show help
|
||||
--version, -v print the version
|
||||
```
|
||||
|
||||
```
|
||||
|
||||
$ ./server_darwin_amd64 -h
|
||||
NAME:
|
||||
kcptun - kcptun server
|
||||
|
||||
@@ -77,7 +78,7 @@ USAGE:
|
||||
server_darwin_amd64 [global options] command [command options] [arguments...]
|
||||
|
||||
VERSION:
|
||||
20160816
|
||||
20160820
|
||||
|
||||
COMMANDS:
|
||||
help, h Shows a list of commands or help for one command
|
||||
@@ -85,16 +86,16 @@ COMMANDS:
|
||||
GLOBAL OPTIONS:
|
||||
--listen value, -l value kcp server listen address (default: ":29900")
|
||||
--target value, -t value target server address (default: "127.0.0.1:12948")
|
||||
--key value key for communcation, must be the same as kcptun client (default: "it's a secrect") [$KCPTUN_KEY]
|
||||
--crypt value methods for encryption: aes, aes-128, aes-192, tea, xor, none (default: "aes")
|
||||
--mode value mode for communication: fast3, fast2, fast, normal (default: "fast")
|
||||
--mtu value set MTU of UDP packets, suggest 'tracepath' to discover path mtu (default: 1350)
|
||||
--key value pre-shared secret for client and server (default: "it's a secrect") [$KCPTUN_KEY]
|
||||
--crypt value aes, aes-128, aes-192, salsa20, blowfish, twofish, cast5, 3des, tea, xtea, xor, none (default: "aes")
|
||||
--mode value profiles: fast3, fast2, fast, normal (default: "fast")
|
||||
--mtu value set maximum transmission unit of UDP packets (default: 1350)
|
||||
--sndwnd value set send window size(num of packets) (default: 1024)
|
||||
--rcvwnd value set receive window size(num of packets) (default: 1024)
|
||||
--nocomp disable compression
|
||||
--datashard value set reed-solomon erasure coding - datashard (default: 10)
|
||||
--parityshard value set reed-solomon erasure coding - parityshard (default: 3)
|
||||
--dscp value set DSCP(6bit) (default: 0)
|
||||
--nocomp disable compression
|
||||
--help, -h show help
|
||||
--version, -v print the version
|
||||
```
|
||||
@@ -140,6 +141,11 @@ GLOBAL OPTIONS:
|
||||
max_bandwidth_fec = max_bandwidth * (10 + 3) /10 = 1.3*max_bandwidth = 1.3 * 25Mbps = 32.5Mbps
|
||||
```
|
||||
|
||||
### *安全* :lollipop:
|
||||
无论你上层如何加密,如果```-crypt none```,那么协议头部都是***明文***的,建议至少采用```-crypt aes-128```加密。
|
||||
|
||||
注意: ```-crypt xor``` 也是不安全的,除非你知道你在做什么。
|
||||
|
||||
### *内存控制* :lollipop:
|
||||
路由器,手机等嵌入式设备通常对内存用量敏感,通过调节环境变量GOGC(例如GOGC=20)后启动client,可以降低内存使用。
|
||||
参考:https://blog.golang.org/go15gc
|
||||
|
||||
+12
-5
@@ -12,9 +12,9 @@ import (
|
||||
"golang.org/x/crypto/pbkdf2"
|
||||
|
||||
"github.com/golang/snappy"
|
||||
"github.com/hashicorp/yamux"
|
||||
"github.com/urfave/cli"
|
||||
kcp "github.com/xtaci/kcp-go"
|
||||
"github.com/xtaci/yamux"
|
||||
)
|
||||
|
||||
var (
|
||||
@@ -109,13 +109,13 @@ func main() {
|
||||
cli.StringFlag{
|
||||
Name: "key",
|
||||
Value: "it's a secrect",
|
||||
Usage: "pre-shared secret for client and server",
|
||||
Usage: "pre-shared secret between client and server",
|
||||
EnvVar: "KCPTUN_KEY",
|
||||
},
|
||||
cli.StringFlag{
|
||||
Name: "crypt",
|
||||
Value: "aes",
|
||||
Usage: "aes, aes-128, aes-192, blowfish, cast5, 3des, tea, xor, none",
|
||||
Usage: "aes, aes-128, aes-192, salsa20, blowfish, twofish, cast5, 3des, tea, xtea, xor, none",
|
||||
},
|
||||
cli.StringFlag{
|
||||
Name: "mode",
|
||||
@@ -130,7 +130,7 @@ func main() {
|
||||
cli.IntFlag{
|
||||
Name: "mtu",
|
||||
Value: 1350,
|
||||
Usage: "set maximum transmission unit of UDP packets",
|
||||
Usage: "set maximum transmission unit for UDP packets",
|
||||
},
|
||||
cli.IntFlag{
|
||||
Name: "sndwnd",
|
||||
@@ -234,11 +234,18 @@ func main() {
|
||||
block, _ = kcp.NewAESBlockCrypt(pass[:24])
|
||||
case "blowfish":
|
||||
block, _ = kcp.NewBlowfishBlockCrypt(pass)
|
||||
case "twofish":
|
||||
block, _ = kcp.NewTwofishBlockCrypt(pass)
|
||||
case "cast5":
|
||||
block, _ = kcp.NewCast5BlockCrypt(pass[:16])
|
||||
case "3des":
|
||||
block, _ = kcp.NewTripleDESBlockCrypt(pass[:24])
|
||||
case "xtea":
|
||||
block, _ = kcp.NewXTEABlockCrypt(pass[:16])
|
||||
case "salsa20":
|
||||
block, _ = kcp.NewSalsa20BlockCrypt(pass)
|
||||
default:
|
||||
crypt = "aes"
|
||||
block, _ = kcp.NewAESBlockCrypt(pass)
|
||||
}
|
||||
|
||||
@@ -266,7 +273,7 @@ func main() {
|
||||
AcceptBacklog: 256,
|
||||
EnableKeepAlive: true,
|
||||
KeepAliveInterval: 30 * time.Second,
|
||||
ConnectionWriteTimeout: 10 * time.Second,
|
||||
ConnectionWriteTimeout: 30 * time.Second,
|
||||
MaxStreamWindowSize: uint32(sockbuf),
|
||||
LogOutput: os.Stderr,
|
||||
}
|
||||
|
||||
+12
-5
@@ -12,9 +12,9 @@ import (
|
||||
"golang.org/x/crypto/pbkdf2"
|
||||
|
||||
"github.com/golang/snappy"
|
||||
"github.com/hashicorp/yamux"
|
||||
"github.com/urfave/cli"
|
||||
kcp "github.com/xtaci/kcp-go"
|
||||
"github.com/xtaci/yamux"
|
||||
)
|
||||
|
||||
var (
|
||||
@@ -127,13 +127,13 @@ func main() {
|
||||
cli.StringFlag{
|
||||
Name: "key",
|
||||
Value: "it's a secrect",
|
||||
Usage: "pre-shared secret for client and server",
|
||||
Usage: "pre-shared secret between client and server",
|
||||
EnvVar: "KCPTUN_KEY",
|
||||
},
|
||||
cli.StringFlag{
|
||||
Name: "crypt",
|
||||
Value: "aes",
|
||||
Usage: "aes, aes-128, aes-192, blowfish, cast5, 3des, tea, xor, none",
|
||||
Usage: "aes, aes-128, aes-192, salsa20, blowfish, twofish, cast5, 3des, tea, xtea, xor, none",
|
||||
},
|
||||
cli.StringFlag{
|
||||
Name: "mode",
|
||||
@@ -143,7 +143,7 @@ func main() {
|
||||
cli.IntFlag{
|
||||
Name: "mtu",
|
||||
Value: 1350,
|
||||
Usage: "set maximum transmission unit of UDP packets",
|
||||
Usage: "set maximum transmission unit for UDP packets",
|
||||
},
|
||||
cli.IntFlag{
|
||||
Name: "sndwnd",
|
||||
@@ -240,11 +240,18 @@ func main() {
|
||||
block, _ = kcp.NewAESBlockCrypt(pass[:24])
|
||||
case "blowfish":
|
||||
block, _ = kcp.NewBlowfishBlockCrypt(pass)
|
||||
case "twofish":
|
||||
block, _ = kcp.NewTwofishBlockCrypt(pass)
|
||||
case "cast5":
|
||||
block, _ = kcp.NewCast5BlockCrypt(pass[:16])
|
||||
case "3des":
|
||||
block, _ = kcp.NewTripleDESBlockCrypt(pass[:24])
|
||||
case "xtea":
|
||||
block, _ = kcp.NewXTEABlockCrypt(pass[:16])
|
||||
case "salsa20":
|
||||
block, _ = kcp.NewSalsa20BlockCrypt(pass)
|
||||
default:
|
||||
crypt = "aes"
|
||||
block, _ = kcp.NewAESBlockCrypt(pass)
|
||||
}
|
||||
|
||||
@@ -284,7 +291,7 @@ func main() {
|
||||
AcceptBacklog: 256,
|
||||
EnableKeepAlive: true,
|
||||
KeepAliveInterval: 30 * time.Second,
|
||||
ConnectionWriteTimeout: 10 * time.Second,
|
||||
ConnectionWriteTimeout: 30 * time.Second,
|
||||
MaxStreamWindowSize: uint32(sockbuf),
|
||||
LogOutput: os.Stderr,
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user