Compare commits

..
27 Commits
Author SHA1 Message Date
xtaci 8705bd7670 upd 2016-08-27 09:17:16 +08:00
xtaci b4e5181a2f optimize retry strategy 2016-08-27 09:00:35 +08:00
xtaci 94f61b5945 upd param 2016-08-26 13:04:38 +08:00
xtaci efc0b99d21 Revert "replace yamux with muxado"
This reverts commit 3803993529.
2016-08-26 11:35:13 +08:00
xtaci 3803993529 replace yamux with muxado 2016-08-26 10:58:43 +08:00
xtaci d23ff7c351 upd 2016-08-25 20:34:33 +08:00
xtaci f383ee31a5 add autoexpire option 2016-08-25 20:33:04 +08:00
xtaci d399f220f0 remove a line 2016-08-25 20:04:34 +08:00
xtaci 59a1bbc7b8 SetFinalizer to session 2016-08-25 18:22:20 +08:00
xtaci 3b656e101f better api 2016-08-25 11:46:17 +08:00
xtaci aec364eb72 set tcp socket buffer 2016-08-24 12:27:33 +08:00
xtaci e26ab6729f spelling 2016-08-22 14:46:57 +08:00
xtaci 583fe3ba24 simple layer 2016-08-21 19:09:08 +08:00
xtaci 7fd6442284 refer to my fork 2016-08-20 21:15:05 +08:00
xtaci 81f4643830 Revert "refer to fork"
This reverts commit 744a6407e7.
2016-08-20 20:49:44 +08:00
xtaci 744a6407e7 refer to fork 2016-08-20 20:23:04 +08:00
xtaci 2cf5292ac1 revert yamux config 2016-08-20 18:37:52 +08:00
xtaci b3a8b631b4 upd README 2016-08-20 16:48:10 +08:00
xtaci 1167419210 add salsa20, xtea crypto 2016-08-20 15:02:25 +08:00
xtaci 56f9f0d01a Merge branch 'master' of https://github.com/xtaci/kcptun 2016-08-20 13:39:01 +08:00
xtaci 96888f1cac pisces 2016-08-20 13:35:27 +08:00
xtaciandGitHub e752d70c79 Update README.en.md 2016-08-20 10:47:59 +08:00
xtaciandGitHub a882b94e5b Update README.md 2016-08-20 10:46:34 +08:00
xtaciandGitHub 790a6d5352 Update README.en.md 2016-08-19 21:21:03 +08:00
xtaciandGitHub 603c2db5ab Update README.md 2016-08-19 21:20:15 +08:00
xtaci 581df3a34d update README.md 2016-08-19 15:00:25 +08:00
xtaci 6113d2b497 update README.md 2016-08-19 14:27:13 +08:00
5 changed files with 123 additions and 58 deletions
+1 -2
View File
@@ -3,7 +3,6 @@ MAINTAINER xtaci <daniel820313@gmail.com>
RUN apk update && \
apk upgrade && \
apk add git
RUN go get github.com/xtaci/kcptun/client
RUN go get github.com/xtaci/kcptun/server
RUN go get github.com/xtaci/kcptun/client && go get github.com/xtaci/kcptun/server
EXPOSE 29900/udp
EXPOSE 12948
+26 -18
View File
@@ -1,7 +1,7 @@
# <img src="logo.png" alt="kcptun" height="60px" />
[![GoDoc][1]][2] [![Release][13]][14] [![Powered][17]][18] [![MIT licensed][11]][12] [![Build Status][3]][4] [![Go Report Card][5]][6] [![Downloads][15]][16] [![Gitter][19]][20]
[1]: https://godoc.org/github.com/xtaci/kcptun?status.svg
[2]: https://godoc.org/github.com/xtaci/kcptun
[![Release][13]][14] [![Powered][17]][18] [![MIT licensed][11]][12] [![Build Status][3]][4] [![Go Report Card][5]][6] [![Downloads][15]][16] [![Gitter][19]][20] [![Docker][1]][2]
[1]: https://images.microbadger.com/badges/image/xtaci/kcptun.svg
[2]: https://microbadger.com/images/xtaci/kcptun
[3]: https://travis-ci.org/xtaci/kcptun.svg?branch=master
[4]: https://travis-ci.org/xtaci/kcptun
[5]: https://goreportcard.com/badge/github.com/xtaci/kcptun
@@ -40,7 +40,9 @@ Client Side: ./client_darwin_amd64 -r "SERVERIP:4000" -l ":1080" -mode fast2 //
* WIFI: 5GHz TL-WDR3320
### *Usage* :lollipop:
Help output under MacOS X:
```
$ ./client_darwin_amd64 -h
NAME:
kcptun - kcptun client
@@ -48,7 +50,7 @@ USAGE:
client_darwin_amd64 [global options] command [command options] [arguments...]
VERSION:
20160816
20160820
COMMANDS:
help, h Shows a list of commands or help for one command
@@ -56,22 +58,22 @@ COMMANDS:
GLOBAL OPTIONS:
--localaddr value, -l value local listen address (default: ":12948")
--remoteaddr value, -r value kcp server address (default: "vps:29900")
--key value key for communcation, must be the same as kcptun server (default: "it's a secrect") [$KCPTUN_KEY]
--crypt value methods for encryption: aes, aes-128, aes-192, tea, xor, none (default: "aes")
--mode value mode for communication: fast3, fast2, fast, normal (default: "fast")
--conn value establish N physical connections as specified by 'conn' to server (default: 1)
--mtu value set MTU of UDP packets, suggest 'tracepath' to discover path mtu (default: 1350)
--key value pre-shared secret for client and server (default: "it's a secrect") [$KCPTUN_KEY]
--crypt value aes, aes-128, aes-192, salsa20, blowfish, twofish, cast5, 3des, tea, xtea, xor, none (default: "aes")
--mode value profiles: fast3, fast2, fast, normal (default: "fast")
--conn value set num of UDP connections to server (default: 1)
--mtu value set maximum transmission unit of UDP packets (default: 1350)
--sndwnd value set send window size(num of packets) (default: 128)
--rcvwnd value set receive window size(num of packets) (default: 1024)
--nocomp disable compression
--datashard value set reed-solomon erasure coding - datashard (default: 10)
--parityshard value set reed-solomon erasure coding - parityshard (default: 3)
--dscp value set DSCP(6bit) (default: 0)
--nocomp disable compression
--help, -h show help
--version, -v print the version
```
```
$ ./server_darwin_amd64 -h
NAME:
kcptun - kcptun server
@@ -79,7 +81,7 @@ USAGE:
server_darwin_amd64 [global options] command [command options] [arguments...]
VERSION:
20160816
20160820
COMMANDS:
help, h Shows a list of commands or help for one command
@@ -87,16 +89,16 @@ COMMANDS:
GLOBAL OPTIONS:
--listen value, -l value kcp server listen address (default: ":29900")
--target value, -t value target server address (default: "127.0.0.1:12948")
--key value key for communcation, must be the same as kcptun client (default: "it's a secrect") [$KCPTUN_KEY]
--crypt value methods for encryption: aes, aes-128, aes-192, tea, xor, none (default: "aes")
--mode value mode for communication: fast3, fast2, fast, normal (default: "fast")
--mtu value set MTU of UDP packets, suggest 'tracepath' to discover path mtu (default: 1350)
--key value pre-shared secret for client and server (default: "it's a secrect") [$KCPTUN_KEY]
--crypt value aes, aes-128, aes-192, salsa20, blowfish, twofish, cast5, 3des, tea, xtea, xor, none (default: "aes")
--mode value profiles: fast3, fast2, fast, normal (default: "fast")
--mtu value set maximum transmission unit of UDP packets (default: 1350)
--sndwnd value set send window size(num of packets) (default: 1024)
--rcvwnd value set receive window size(num of packets) (default: 1024)
--nocomp disable compression
--datashard value set reed-solomon erasure coding - datashard (default: 10)
--parityshard value set reed-solomon erasure coding - parityshard (default: 3)
--dscp value set DSCP(6bit) (default: 0)
--nocomp disable compression
--help, -h show help
--version, -v print the version
```
@@ -122,6 +124,12 @@ other parameters can be set independently.
***NOTICE: if too much retranmission happens, it's quite possible the windows are too large***
### *Security* :lollipop:
No matter what encryption you are using for application layer, if you specify ```-crypt none``` to kcptun,
the header will be ***PLAINTEXT*** to everyone; I suggest ```-crypt aes-128``` for encryption at least .
NOTICE: ```-crypt xor``` is also insecure, do not use this unless you know what you are doing.
### *Memory Control* :lollipop:
Routers, mobile devices are sensitive to memory consumption; by setting GOGC environment(eg: GOGC=20) will lower memory consumption.
Reference: https://blog.golang.org/go15gc
+24 -18
View File
@@ -1,7 +1,7 @@
# <img src="logo.png" alt="kcptun" height="60px" />
[![GoDoc][1]][2] [![Release][13]][14] [![Powered][17]][18] [![MIT licensed][11]][12] [![Build Status][3]][4] [![Go Report Card][5]][6] [![Downloads][15]][16] [![Gitter][19]][20]
[1]: https://godoc.org/github.com/xtaci/kcptun?status.svg
[2]: https://godoc.org/github.com/xtaci/kcptun
[![Release][13]][14] [![Powered][17]][18] [![MIT licensed][11]][12] [![Build Status][3]][4] [![Go Report Card][5]][6] [![Downloads][15]][16] [![Gitter][19]][20] [![Docker][1]][2]
[1]: https://images.microbadger.com/badges/image/xtaci/kcptun.svg
[2]: https://microbadger.com/images/xtaci/kcptun
[3]: https://travis-ci.org/xtaci/kcptun.svg?branch=master
[4]: https://travis-ci.org/xtaci/kcptun
[5]: https://goreportcard.com/badge/github.com/xtaci/kcptun
@@ -39,6 +39,7 @@
### *使用方法* :lollipop:
在Mac OS X El Capitan下的帮助输出:
```
$ ./client_darwin_amd64 -h
NAME:
kcptun - kcptun client
@@ -46,7 +47,7 @@ USAGE:
client_darwin_amd64 [global options] command [command options] [arguments...]
VERSION:
20160816
20160820
COMMANDS:
help, h Shows a list of commands or help for one command
@@ -54,22 +55,22 @@ COMMANDS:
GLOBAL OPTIONS:
--localaddr value, -l value local listen address (default: ":12948")
--remoteaddr value, -r value kcp server address (default: "vps:29900")
--key value key for communcation, must be the same as kcptun server (default: "it's a secrect") [$KCPTUN_KEY]
--crypt value methods for encryption: aes, aes-128, aes-192, tea, xor, none (default: "aes")
--mode value mode for communication: fast3, fast2, fast, normal (default: "fast")
--conn value establish N physical connections as specified by 'conn' to server (default: 1)
--mtu value set MTU of UDP packets, suggest 'tracepath' to discover path mtu (default: 1350)
--key value pre-shared secret for client and server (default: "it's a secrect") [$KCPTUN_KEY]
--crypt value aes, aes-128, aes-192, salsa20, blowfish, twofish, cast5, 3des, tea, xtea, xor, none (default: "aes")
--mode value profiles: fast3, fast2, fast, normal (default: "fast")
--conn value set num of UDP connections to server (default: 1)
--mtu value set maximum transmission unit of UDP packets (default: 1350)
--sndwnd value set send window size(num of packets) (default: 128)
--rcvwnd value set receive window size(num of packets) (default: 1024)
--nocomp disable compression
--datashard value set reed-solomon erasure coding - datashard (default: 10)
--parityshard value set reed-solomon erasure coding - parityshard (default: 3)
--dscp value set DSCP(6bit) (default: 0)
--nocomp disable compression
--help, -h show help
--version, -v print the version
```
```
$ ./server_darwin_amd64 -h
NAME:
kcptun - kcptun server
@@ -77,7 +78,7 @@ USAGE:
server_darwin_amd64 [global options] command [command options] [arguments...]
VERSION:
20160816
20160820
COMMANDS:
help, h Shows a list of commands or help for one command
@@ -85,16 +86,16 @@ COMMANDS:
GLOBAL OPTIONS:
--listen value, -l value kcp server listen address (default: ":29900")
--target value, -t value target server address (default: "127.0.0.1:12948")
--key value key for communcation, must be the same as kcptun client (default: "it's a secrect") [$KCPTUN_KEY]
--crypt value methods for encryption: aes, aes-128, aes-192, tea, xor, none (default: "aes")
--mode value mode for communication: fast3, fast2, fast, normal (default: "fast")
--mtu value set MTU of UDP packets, suggest 'tracepath' to discover path mtu (default: 1350)
--key value pre-shared secret for client and server (default: "it's a secrect") [$KCPTUN_KEY]
--crypt value aes, aes-128, aes-192, salsa20, blowfish, twofish, cast5, 3des, tea, xtea, xor, none (default: "aes")
--mode value profiles: fast3, fast2, fast, normal (default: "fast")
--mtu value set maximum transmission unit of UDP packets (default: 1350)
--sndwnd value set send window size(num of packets) (default: 1024)
--rcvwnd value set receive window size(num of packets) (default: 1024)
--nocomp disable compression
--datashard value set reed-solomon erasure coding - datashard (default: 10)
--parityshard value set reed-solomon erasure coding - parityshard (default: 3)
--dscp value set DSCP(6bit) (default: 0)
--nocomp disable compression
--help, -h show help
--version, -v print the version
```
@@ -140,6 +141,11 @@ GLOBAL OPTIONS:
max_bandwidth_fec = max_bandwidth * (10 + 3) /10 = 1.3*max_bandwidth 1.3 * 25Mbps = 32.5Mbps
```
### *安全* :lollipop:
无论你上层如何加密,如果```-crypt none```,那么协议头部都是***明文***的,建议至少采用```-crypt aes-128```加密。
注意: ```-crypt xor``` 也是不安全的,除非你知道你在做什么。
### *内存控制* :lollipop:
路由器,手机等嵌入式设备通常对内存用量敏感,通过调节环境变量GOGC(例如GOGC=20)后启动client,可以降低内存使用。
参考:https://blog.golang.org/go15gc
+51 -14
View File
@@ -7,14 +7,15 @@ import (
"math/rand"
"net"
"os"
"runtime"
"time"
"golang.org/x/crypto/pbkdf2"
"github.com/golang/snappy"
"github.com/hashicorp/yamux"
"github.com/urfave/cli"
kcp "github.com/xtaci/kcp-go"
"github.com/xtaci/yamux"
)
var (
@@ -109,13 +110,13 @@ func main() {
cli.StringFlag{
Name: "key",
Value: "it's a secrect",
Usage: "pre-shared secret for client and server",
Usage: "pre-shared secret between client and server",
EnvVar: "KCPTUN_KEY",
},
cli.StringFlag{
Name: "crypt",
Value: "aes",
Usage: "aes, aes-128, aes-192, blowfish, cast5, 3des, tea, xor, none",
Usage: "aes, aes-128, aes-192, salsa20, blowfish, twofish, cast5, 3des, tea, xtea, xor, none",
},
cli.StringFlag{
Name: "mode",
@@ -127,10 +128,15 @@ func main() {
Value: 1,
Usage: "set num of UDP connections to server",
},
cli.IntFlag{
Name: "autoexpire",
Value: 0,
Usage: "set auto expiration time(in seconds) for a single UDP connection, 0 to disable",
},
cli.IntFlag{
Name: "mtu",
Value: 1350,
Usage: "set maximum transmission unit of UDP packets",
Usage: "set maximum transmission unit for UDP packets",
},
cli.IntFlag{
Name: "sndwnd",
@@ -234,11 +240,18 @@ func main() {
block, _ = kcp.NewAESBlockCrypt(pass[:24])
case "blowfish":
block, _ = kcp.NewBlowfishBlockCrypt(pass)
case "twofish":
block, _ = kcp.NewTwofishBlockCrypt(pass)
case "cast5":
block, _ = kcp.NewCast5BlockCrypt(pass[:16])
case "3des":
block, _ = kcp.NewTripleDESBlockCrypt(pass[:24])
case "xtea":
block, _ = kcp.NewXTEABlockCrypt(pass[:16])
case "salsa20":
block, _ = kcp.NewSalsa20BlockCrypt(pass)
default:
crypt = "aes"
block, _ = kcp.NewAESBlockCrypt(pass)
}
@@ -247,6 +260,7 @@ func main() {
mtu, sndwnd, rcvwnd := c.Int("mtu"), c.Int("sndwnd"), c.Int("rcvwnd")
nocomp, acknodelay := c.Bool("nocomp"), c.Bool("acknodelay")
dscp, sockbuf, keepalive, conn := c.Int("dscp"), c.Int("sockbuf"), c.Int("keepalive"), c.Int("conn")
autoexpire := c.Int("autoexpire")
log.Println("listening on:", listener.Addr())
log.Println("encryption:", crypt)
@@ -261,6 +275,7 @@ func main() {
log.Println("sockbuf:", sockbuf)
log.Println("keepalive:", keepalive)
log.Println("conn:", conn)
log.Println("autoexpire:", autoexpire)
config := &yamux.Config{
AcceptBacklog: 256,
@@ -298,27 +313,49 @@ func main() {
session, err = yamux.Client(newCompStream(kcpconn), config)
}
checkError(err)
runtime.SetFinalizer(session, func(s *yamux.Session) {
s.Close()
})
return session
}
numconn := uint16(conn)
var muxes []*yamux.Session
for i := uint16(0); i < numconn; i++ {
muxes = append(muxes, createConn())
muxes := make([]struct {
session *yamux.Session
ttl time.Time
}, numconn)
for k := range muxes {
muxes[k].session = createConn()
muxes[k].ttl = time.Now().Add(time.Duration(autoexpire) * time.Second)
}
rr := uint16(0)
for {
p1, err := listener.AcceptTCP()
if err := p1.SetReadBuffer(sockbuf); err != nil {
log.Println("TCP SetReadBuffer:", err)
}
if err := p1.SetWriteBuffer(sockbuf); err != nil {
log.Println("TCP SetWriteBuffer:", err)
}
checkError(err)
mux := muxes[rr%numconn]
p2, err := mux.Open()
idx := rr % numconn
OPEN_P2:
// do auto expiration
if autoexpire > 0 && time.Now().After(muxes[idx].ttl) {
log.Println("autoexpired")
muxes[idx].session = createConn()
muxes[idx].ttl = time.Now().Add(time.Duration(autoexpire) * time.Second)
}
// do session open
p2, err := muxes[idx].session.Open()
if err != nil { // yamux failure
log.Println(err)
p1.Close()
muxes[rr%numconn] = createConn()
mux.Close()
continue
muxes[idx].session = createConn()
muxes[idx].ttl = time.Now().Add(time.Duration(autoexpire) * time.Second)
goto OPEN_P2
}
go handleClient(p1, p2)
rr++
+21 -6
View File
@@ -12,9 +12,9 @@ import (
"golang.org/x/crypto/pbkdf2"
"github.com/golang/snappy"
"github.com/hashicorp/yamux"
"github.com/urfave/cli"
kcp "github.com/xtaci/kcp-go"
"github.com/xtaci/yamux"
)
var (
@@ -61,18 +61,26 @@ func handleMux(conn io.ReadWriteCloser, target string, config *yamux.Config) {
return
}
defer mux.Close()
for {
p1, err := mux.Accept()
if err != nil {
log.Println(err)
return
}
sockbuf := int(config.MaxStreamWindowSize)
p2, err := net.DialTimeout("tcp", target, 5*time.Second)
if err != nil {
log.Println(err)
return
}
if err := p2.(*net.TCPConn).SetReadBuffer(sockbuf); err != nil {
log.Println("TCP SetReadBuffer:", err)
}
if err := p2.(*net.TCPConn).SetWriteBuffer(sockbuf); err != nil {
log.Println("TCP SetWriteBuffer:", err)
}
go handleClient(p1, p2)
}
}
@@ -127,13 +135,13 @@ func main() {
cli.StringFlag{
Name: "key",
Value: "it's a secrect",
Usage: "pre-shared secret for client and server",
Usage: "pre-shared secret between client and server",
EnvVar: "KCPTUN_KEY",
},
cli.StringFlag{
Name: "crypt",
Value: "aes",
Usage: "aes, aes-128, aes-192, blowfish, cast5, 3des, tea, xor, none",
Usage: "aes, aes-128, aes-192, salsa20, blowfish, twofish, cast5, 3des, tea, xtea, xor, none",
},
cli.StringFlag{
Name: "mode",
@@ -143,7 +151,7 @@ func main() {
cli.IntFlag{
Name: "mtu",
Value: 1350,
Usage: "set maximum transmission unit of UDP packets",
Usage: "set maximum transmission unit for UDP packets",
},
cli.IntFlag{
Name: "sndwnd",
@@ -240,11 +248,18 @@ func main() {
block, _ = kcp.NewAESBlockCrypt(pass[:24])
case "blowfish":
block, _ = kcp.NewBlowfishBlockCrypt(pass)
case "twofish":
block, _ = kcp.NewTwofishBlockCrypt(pass)
case "cast5":
block, _ = kcp.NewCast5BlockCrypt(pass[:16])
case "3des":
block, _ = kcp.NewTripleDESBlockCrypt(pass[:24])
case "xtea":
block, _ = kcp.NewXTEABlockCrypt(pass[:16])
case "salsa20":
block, _ = kcp.NewSalsa20BlockCrypt(pass)
default:
crypt = "aes"
block, _ = kcp.NewAESBlockCrypt(pass)
}
@@ -289,7 +304,7 @@ func main() {
LogOutput: os.Stderr,
}
for {
if conn, err := lis.Accept(); err == nil {
if conn, err := lis.AcceptKCP(); err == nil {
log.Println("remote address:", conn.RemoteAddr())
conn.SetStreamMode(true)
conn.SetNoDelay(nodelay, interval, resend, nc)