Compare commits

...
16 Commits
Author SHA1 Message Date
xtaci e26ab6729f spelling 2016-08-22 14:46:57 +08:00
xtaci 583fe3ba24 simple layer 2016-08-21 19:09:08 +08:00
xtaci 7fd6442284 refer to my fork 2016-08-20 21:15:05 +08:00
xtaci 81f4643830 Revert "refer to fork"
This reverts commit 744a6407e7.
2016-08-20 20:49:44 +08:00
xtaci 744a6407e7 refer to fork 2016-08-20 20:23:04 +08:00
xtaci 2cf5292ac1 revert yamux config 2016-08-20 18:37:52 +08:00
xtaci b3a8b631b4 upd README 2016-08-20 16:48:10 +08:00
xtaci 1167419210 add salsa20, xtea crypto 2016-08-20 15:02:25 +08:00
xtaci 56f9f0d01a Merge branch 'master' of https://github.com/xtaci/kcptun 2016-08-20 13:39:01 +08:00
xtaci 96888f1cac pisces 2016-08-20 13:35:27 +08:00
xtaciandGitHub e752d70c79 Update README.en.md 2016-08-20 10:47:59 +08:00
xtaciandGitHub a882b94e5b Update README.md 2016-08-20 10:46:34 +08:00
xtaciandGitHub 790a6d5352 Update README.en.md 2016-08-19 21:21:03 +08:00
xtaciandGitHub 603c2db5ab Update README.md 2016-08-19 21:20:15 +08:00
xtaci 581df3a34d update README.md 2016-08-19 15:00:25 +08:00
xtaci 6113d2b497 update README.md 2016-08-19 14:27:13 +08:00
5 changed files with 75 additions and 48 deletions
+1 -2
View File
@@ -3,7 +3,6 @@ MAINTAINER xtaci <daniel820313@gmail.com>
RUN apk update && \
apk upgrade && \
apk add git
RUN go get github.com/xtaci/kcptun/client
RUN go get github.com/xtaci/kcptun/server
RUN go get github.com/xtaci/kcptun/client && go get github.com/xtaci/kcptun/server
EXPOSE 29900/udp
EXPOSE 12948
+26 -18
View File
@@ -1,7 +1,7 @@
# <img src="logo.png" alt="kcptun" height="60px" />
[![GoDoc][1]][2] [![Release][13]][14] [![Powered][17]][18] [![MIT licensed][11]][12] [![Build Status][3]][4] [![Go Report Card][5]][6] [![Downloads][15]][16] [![Gitter][19]][20]
[1]: https://godoc.org/github.com/xtaci/kcptun?status.svg
[2]: https://godoc.org/github.com/xtaci/kcptun
[![Release][13]][14] [![Powered][17]][18] [![MIT licensed][11]][12] [![Build Status][3]][4] [![Go Report Card][5]][6] [![Downloads][15]][16] [![Gitter][19]][20] [![Docker][1]][2]
[1]: https://images.microbadger.com/badges/image/xtaci/kcptun.svg
[2]: https://microbadger.com/images/xtaci/kcptun
[3]: https://travis-ci.org/xtaci/kcptun.svg?branch=master
[4]: https://travis-ci.org/xtaci/kcptun
[5]: https://goreportcard.com/badge/github.com/xtaci/kcptun
@@ -40,7 +40,9 @@ Client Side: ./client_darwin_amd64 -r "SERVERIP:4000" -l ":1080" -mode fast2 //
* WIFI: 5GHz TL-WDR3320
### *Usage* :lollipop:
Help output under MacOS X:
```
$ ./client_darwin_amd64 -h
NAME:
kcptun - kcptun client
@@ -48,7 +50,7 @@ USAGE:
client_darwin_amd64 [global options] command [command options] [arguments...]
VERSION:
20160816
20160820
COMMANDS:
help, h Shows a list of commands or help for one command
@@ -56,22 +58,22 @@ COMMANDS:
GLOBAL OPTIONS:
--localaddr value, -l value local listen address (default: ":12948")
--remoteaddr value, -r value kcp server address (default: "vps:29900")
--key value key for communcation, must be the same as kcptun server (default: "it's a secrect") [$KCPTUN_KEY]
--crypt value methods for encryption: aes, aes-128, aes-192, tea, xor, none (default: "aes")
--mode value mode for communication: fast3, fast2, fast, normal (default: "fast")
--conn value establish N physical connections as specified by 'conn' to server (default: 1)
--mtu value set MTU of UDP packets, suggest 'tracepath' to discover path mtu (default: 1350)
--key value pre-shared secret for client and server (default: "it's a secrect") [$KCPTUN_KEY]
--crypt value aes, aes-128, aes-192, salsa20, blowfish, twofish, cast5, 3des, tea, xtea, xor, none (default: "aes")
--mode value profiles: fast3, fast2, fast, normal (default: "fast")
--conn value set num of UDP connections to server (default: 1)
--mtu value set maximum transmission unit of UDP packets (default: 1350)
--sndwnd value set send window size(num of packets) (default: 128)
--rcvwnd value set receive window size(num of packets) (default: 1024)
--nocomp disable compression
--datashard value set reed-solomon erasure coding - datashard (default: 10)
--parityshard value set reed-solomon erasure coding - parityshard (default: 3)
--dscp value set DSCP(6bit) (default: 0)
--nocomp disable compression
--help, -h show help
--version, -v print the version
```
```
$ ./server_darwin_amd64 -h
NAME:
kcptun - kcptun server
@@ -79,7 +81,7 @@ USAGE:
server_darwin_amd64 [global options] command [command options] [arguments...]
VERSION:
20160816
20160820
COMMANDS:
help, h Shows a list of commands or help for one command
@@ -87,16 +89,16 @@ COMMANDS:
GLOBAL OPTIONS:
--listen value, -l value kcp server listen address (default: ":29900")
--target value, -t value target server address (default: "127.0.0.1:12948")
--key value key for communcation, must be the same as kcptun client (default: "it's a secrect") [$KCPTUN_KEY]
--crypt value methods for encryption: aes, aes-128, aes-192, tea, xor, none (default: "aes")
--mode value mode for communication: fast3, fast2, fast, normal (default: "fast")
--mtu value set MTU of UDP packets, suggest 'tracepath' to discover path mtu (default: 1350)
--key value pre-shared secret for client and server (default: "it's a secrect") [$KCPTUN_KEY]
--crypt value aes, aes-128, aes-192, salsa20, blowfish, twofish, cast5, 3des, tea, xtea, xor, none (default: "aes")
--mode value profiles: fast3, fast2, fast, normal (default: "fast")
--mtu value set maximum transmission unit of UDP packets (default: 1350)
--sndwnd value set send window size(num of packets) (default: 1024)
--rcvwnd value set receive window size(num of packets) (default: 1024)
--nocomp disable compression
--datashard value set reed-solomon erasure coding - datashard (default: 10)
--parityshard value set reed-solomon erasure coding - parityshard (default: 3)
--dscp value set DSCP(6bit) (default: 0)
--nocomp disable compression
--help, -h show help
--version, -v print the version
```
@@ -122,6 +124,12 @@ other parameters can be set independently.
***NOTICE: if too much retranmission happens, it's quite possible the windows are too large***
### *Security* :lollipop:
No matter what encryption you are using for application layer, if you specify ```-crypt none``` to kcptun,
the header will be ***PLAINTEXT*** to everyone; I suggest ```-crypt aes-128``` for encryption at least .
NOTICE: ```-crypt xor``` is also insecure, do not use this unless you know what you are doing.
### *Memory Control* :lollipop:
Routers, mobile devices are sensitive to memory consumption; by setting GOGC environment(eg: GOGC=20) will lower memory consumption.
Reference: https://blog.golang.org/go15gc
+24 -18
View File
@@ -1,7 +1,7 @@
# <img src="logo.png" alt="kcptun" height="60px" />
[![GoDoc][1]][2] [![Release][13]][14] [![Powered][17]][18] [![MIT licensed][11]][12] [![Build Status][3]][4] [![Go Report Card][5]][6] [![Downloads][15]][16] [![Gitter][19]][20]
[1]: https://godoc.org/github.com/xtaci/kcptun?status.svg
[2]: https://godoc.org/github.com/xtaci/kcptun
[![Release][13]][14] [![Powered][17]][18] [![MIT licensed][11]][12] [![Build Status][3]][4] [![Go Report Card][5]][6] [![Downloads][15]][16] [![Gitter][19]][20] [![Docker][1]][2]
[1]: https://images.microbadger.com/badges/image/xtaci/kcptun.svg
[2]: https://microbadger.com/images/xtaci/kcptun
[3]: https://travis-ci.org/xtaci/kcptun.svg?branch=master
[4]: https://travis-ci.org/xtaci/kcptun
[5]: https://goreportcard.com/badge/github.com/xtaci/kcptun
@@ -39,6 +39,7 @@
### *使用方法* :lollipop:
在Mac OS X El Capitan下的帮助输出:
```
$ ./client_darwin_amd64 -h
NAME:
kcptun - kcptun client
@@ -46,7 +47,7 @@ USAGE:
client_darwin_amd64 [global options] command [command options] [arguments...]
VERSION:
20160816
20160820
COMMANDS:
help, h Shows a list of commands or help for one command
@@ -54,22 +55,22 @@ COMMANDS:
GLOBAL OPTIONS:
--localaddr value, -l value local listen address (default: ":12948")
--remoteaddr value, -r value kcp server address (default: "vps:29900")
--key value key for communcation, must be the same as kcptun server (default: "it's a secrect") [$KCPTUN_KEY]
--crypt value methods for encryption: aes, aes-128, aes-192, tea, xor, none (default: "aes")
--mode value mode for communication: fast3, fast2, fast, normal (default: "fast")
--conn value establish N physical connections as specified by 'conn' to server (default: 1)
--mtu value set MTU of UDP packets, suggest 'tracepath' to discover path mtu (default: 1350)
--key value pre-shared secret for client and server (default: "it's a secrect") [$KCPTUN_KEY]
--crypt value aes, aes-128, aes-192, salsa20, blowfish, twofish, cast5, 3des, tea, xtea, xor, none (default: "aes")
--mode value profiles: fast3, fast2, fast, normal (default: "fast")
--conn value set num of UDP connections to server (default: 1)
--mtu value set maximum transmission unit of UDP packets (default: 1350)
--sndwnd value set send window size(num of packets) (default: 128)
--rcvwnd value set receive window size(num of packets) (default: 1024)
--nocomp disable compression
--datashard value set reed-solomon erasure coding - datashard (default: 10)
--parityshard value set reed-solomon erasure coding - parityshard (default: 3)
--dscp value set DSCP(6bit) (default: 0)
--nocomp disable compression
--help, -h show help
--version, -v print the version
```
```
$ ./server_darwin_amd64 -h
NAME:
kcptun - kcptun server
@@ -77,7 +78,7 @@ USAGE:
server_darwin_amd64 [global options] command [command options] [arguments...]
VERSION:
20160816
20160820
COMMANDS:
help, h Shows a list of commands or help for one command
@@ -85,16 +86,16 @@ COMMANDS:
GLOBAL OPTIONS:
--listen value, -l value kcp server listen address (default: ":29900")
--target value, -t value target server address (default: "127.0.0.1:12948")
--key value key for communcation, must be the same as kcptun client (default: "it's a secrect") [$KCPTUN_KEY]
--crypt value methods for encryption: aes, aes-128, aes-192, tea, xor, none (default: "aes")
--mode value mode for communication: fast3, fast2, fast, normal (default: "fast")
--mtu value set MTU of UDP packets, suggest 'tracepath' to discover path mtu (default: 1350)
--key value pre-shared secret for client and server (default: "it's a secrect") [$KCPTUN_KEY]
--crypt value aes, aes-128, aes-192, salsa20, blowfish, twofish, cast5, 3des, tea, xtea, xor, none (default: "aes")
--mode value profiles: fast3, fast2, fast, normal (default: "fast")
--mtu value set maximum transmission unit of UDP packets (default: 1350)
--sndwnd value set send window size(num of packets) (default: 1024)
--rcvwnd value set receive window size(num of packets) (default: 1024)
--nocomp disable compression
--datashard value set reed-solomon erasure coding - datashard (default: 10)
--parityshard value set reed-solomon erasure coding - parityshard (default: 3)
--dscp value set DSCP(6bit) (default: 0)
--nocomp disable compression
--help, -h show help
--version, -v print the version
```
@@ -140,6 +141,11 @@ GLOBAL OPTIONS:
max_bandwidth_fec = max_bandwidth * (10 + 3) /10 = 1.3*max_bandwidth 1.3 * 25Mbps = 32.5Mbps
```
### *安全* :lollipop:
无论你上层如何加密,如果```-crypt none```,那么协议头部都是***明文***的,建议至少采用```-crypt aes-128```加密。
注意: ```-crypt xor``` 也是不安全的,除非你知道你在做什么。
### *内存控制* :lollipop:
路由器,手机等嵌入式设备通常对内存用量敏感,通过调节环境变量GOGC(例如GOGC=20)后启动client,可以降低内存使用。
参考:https://blog.golang.org/go15gc
+12 -5
View File
@@ -12,9 +12,9 @@ import (
"golang.org/x/crypto/pbkdf2"
"github.com/golang/snappy"
"github.com/hashicorp/yamux"
"github.com/urfave/cli"
kcp "github.com/xtaci/kcp-go"
"github.com/xtaci/yamux"
)
var (
@@ -109,13 +109,13 @@ func main() {
cli.StringFlag{
Name: "key",
Value: "it's a secrect",
Usage: "pre-shared secret for client and server",
Usage: "pre-shared secret between client and server",
EnvVar: "KCPTUN_KEY",
},
cli.StringFlag{
Name: "crypt",
Value: "aes",
Usage: "aes, aes-128, aes-192, blowfish, cast5, 3des, tea, xor, none",
Usage: "aes, aes-128, aes-192, salsa20, blowfish, twofish, cast5, 3des, tea, xtea, xor, none",
},
cli.StringFlag{
Name: "mode",
@@ -130,7 +130,7 @@ func main() {
cli.IntFlag{
Name: "mtu",
Value: 1350,
Usage: "set maximum transmission unit of UDP packets",
Usage: "set maximum transmission unit for UDP packets",
},
cli.IntFlag{
Name: "sndwnd",
@@ -234,11 +234,18 @@ func main() {
block, _ = kcp.NewAESBlockCrypt(pass[:24])
case "blowfish":
block, _ = kcp.NewBlowfishBlockCrypt(pass)
case "twofish":
block, _ = kcp.NewTwofishBlockCrypt(pass)
case "cast5":
block, _ = kcp.NewCast5BlockCrypt(pass[:16])
case "3des":
block, _ = kcp.NewTripleDESBlockCrypt(pass[:24])
case "xtea":
block, _ = kcp.NewXTEABlockCrypt(pass[:16])
case "salsa20":
block, _ = kcp.NewSalsa20BlockCrypt(pass)
default:
crypt = "aes"
block, _ = kcp.NewAESBlockCrypt(pass)
}
@@ -266,7 +273,7 @@ func main() {
AcceptBacklog: 256,
EnableKeepAlive: true,
KeepAliveInterval: 30 * time.Second,
ConnectionWriteTimeout: 10 * time.Second,
ConnectionWriteTimeout: 30 * time.Second,
MaxStreamWindowSize: uint32(sockbuf),
LogOutput: os.Stderr,
}
+12 -5
View File
@@ -12,9 +12,9 @@ import (
"golang.org/x/crypto/pbkdf2"
"github.com/golang/snappy"
"github.com/hashicorp/yamux"
"github.com/urfave/cli"
kcp "github.com/xtaci/kcp-go"
"github.com/xtaci/yamux"
)
var (
@@ -127,13 +127,13 @@ func main() {
cli.StringFlag{
Name: "key",
Value: "it's a secrect",
Usage: "pre-shared secret for client and server",
Usage: "pre-shared secret between client and server",
EnvVar: "KCPTUN_KEY",
},
cli.StringFlag{
Name: "crypt",
Value: "aes",
Usage: "aes, aes-128, aes-192, blowfish, cast5, 3des, tea, xor, none",
Usage: "aes, aes-128, aes-192, salsa20, blowfish, twofish, cast5, 3des, tea, xtea, xor, none",
},
cli.StringFlag{
Name: "mode",
@@ -143,7 +143,7 @@ func main() {
cli.IntFlag{
Name: "mtu",
Value: 1350,
Usage: "set maximum transmission unit of UDP packets",
Usage: "set maximum transmission unit for UDP packets",
},
cli.IntFlag{
Name: "sndwnd",
@@ -240,11 +240,18 @@ func main() {
block, _ = kcp.NewAESBlockCrypt(pass[:24])
case "blowfish":
block, _ = kcp.NewBlowfishBlockCrypt(pass)
case "twofish":
block, _ = kcp.NewTwofishBlockCrypt(pass)
case "cast5":
block, _ = kcp.NewCast5BlockCrypt(pass[:16])
case "3des":
block, _ = kcp.NewTripleDESBlockCrypt(pass[:24])
case "xtea":
block, _ = kcp.NewXTEABlockCrypt(pass[:16])
case "salsa20":
block, _ = kcp.NewSalsa20BlockCrypt(pass)
default:
crypt = "aes"
block, _ = kcp.NewAESBlockCrypt(pass)
}
@@ -284,7 +291,7 @@ func main() {
AcceptBacklog: 256,
EnableKeepAlive: true,
KeepAliveInterval: 30 * time.Second,
ConnectionWriteTimeout: 10 * time.Second,
ConnectionWriteTimeout: 30 * time.Second,
MaxStreamWindowSize: uint32(sockbuf),
LogOutput: os.Stderr,
}