Compare commits

...
51 Commits
Author SHA1 Message Date
xtaci 03f27ec53d Revert "passive tunnel termination"
This reverts commit bf1d0d6419.
2018-03-16 13:44:44 +08:00
xtaciandGitHub b2390a5dd3 Update README.md 2018-03-16 13:30:53 +08:00
xtaci bf1d0d6419 passive tunnel termination 2018-03-05 16:38:28 +08:00
xtaciandGitHub 834cc5d596 Update README.md 2017-12-03 21:59:22 +08:00
xtaciandGitHub 825ccca6ac Update README.md 2017-10-23 02:59:28 -05:00
xtaci 2845af3911 print quiet option 2017-10-21 19:34:26 +08:00
xtaciandGitHub 31a9d13871 Merge pull request #509 from jiangtiandao/master
reduce docker image size by using multi stage build
2017-10-21 19:16:01 +08:00
xtaci 43761f486c add '-quiet' option to suppress stream open/close messages 2017-10-21 19:11:14 +08:00
xtaci 030e39bf74 add encryption support for sm4 2017-10-09 22:58:44 +08:00
Rheinmetal e6a1d00758 reduce docker image size by using multi stage build 2017-09-23 10:26:17 +08:00
xtaci 9d5a5b9c0d upd travis 2017-09-04 11:06:21 +08:00
xtaci 4aaf974a0b add ethereum qrcode 2017-08-06 17:22:46 +08:00
xtaciandGitHub 1600d4d26f Update README.md 2017-08-02 19:26:33 +08:00
xtaciandGitHub c612e5e153 Update README.md 2017-07-30 18:48:11 +08:00
xtaciandGitHub 2fef48ce71 Update README.md 2017-07-30 18:47:19 +08:00
xtaciandGitHub 1d492accd6 Update README.md 2017-07-30 18:46:48 +08:00
xtaci d1beaf8383 update README.md 2017-07-02 00:14:39 +08:00
xtaciandGitHub ded53a9229 Update README.md 2017-05-20 19:35:17 +08:00
xtaciandGitHub 65751d535b Update README.md 2017-05-20 19:34:42 +08:00
xtaci 4b5f7c1405 add bitcoin donate 2017-05-20 18:48:05 +08:00
xtaciandGitHub 25bad3c03c Update README.md 2017-04-26 11:16:48 +08:00
xtaciandGitHub d2c4d04600 Update README.md 2017-04-26 11:07:24 +08:00
xtaci 0cb075b061 add a log for re-connecting 2017-04-08 10:38:51 +08:00
xtaciandGitHub ab7a8321a6 Update README.md 2017-03-29 21:08:16 +08:00
xtaci 6496672b61 Revert "use io.CopyBuffer instead of io.Copy for memory recycle"
This reverts commit ad8683d46c.
2017-03-28 15:34:23 +08:00
xtaci ae513e9af1 inject version in Dockerfile 2017-03-27 15:56:29 +08:00
xtaci 36763feca4 ignore sigpipe 2017-03-24 22:52:06 +08:00
xtaci acf7a01922 adjust parameters based on improvements in kcp-go 2017-03-21 22:29:05 +08:00
xtaciandGitHub ee01d61266 Update README.md 2017-03-20 12:57:48 +08:00
xtaciandGitHub fd7ed8532e Update README.md 2017-03-20 12:56:23 +08:00
xtaci ff9e3d699b add SetWriteDelay func 2017-03-18 13:07:34 +08:00
xtaci e667b74b35 remove pprof on client side to shrink binary size 2017-03-15 12:42:16 +08:00
xtaciandGitHub 9a162e7008 Update README.md 2017-03-14 12:36:51 +08:00
xtaciandGitHub bf4170ddff Update README.md 2017-03-13 23:31:47 +08:00
xtaciandGitHub 915db867bd Delete README-CN.md 2017-03-13 23:31:31 +08:00
xtaciandGitHub e32fa78db6 Update README-CN.md 2017-03-13 23:30:16 +08:00
xtaciandGitHub 12b8cdb366 Update README-CN.md 2017-03-13 23:29:24 +08:00
xtaciandGitHub 87120a019b Update README-CN.md 2017-03-13 14:09:20 +08:00
xtaciandGitHub 2ab1e3fb26 Update README.md 2017-03-13 14:08:37 +08:00
xtaci b3c4ec9483 update 2017-03-12 21:12:03 +08:00
xtaci 91335c3db6 listen to all 6060 2017-03-12 21:03:44 +08:00
xtaci 7df2c447db add -pprof option for debuging purpose 2017-03-12 20:53:53 +08:00
xtaci ad8683d46c use io.CopyBuffer instead of io.Copy for memory recycle 2017-03-11 13:20:28 +08:00
xtaci ca4800f298 remove hard limit for tcp socket buffer,let kernel autoscale 2017-03-10 12:53:14 +08:00
xtaci a25c9eb3a9 fix possible CLOSE_WAIT in client 2017-03-08 16:33:10 +08:00
xtaci a0e8b2592e use keepalive in smux alone directly 2017-03-07 20:33:52 +08:00
xtaci dc6b61ded3 remove a deprecated func 2017-03-07 10:49:06 +08:00
xtaci 298b4a0795 adjusta default parameters 2017-03-02 11:04:01 +08:00
xtaci 1334ce5a9a Revert "adjust defaults"
This reverts commit 6efb6008e5.
2017-03-02 00:08:34 +08:00
xtaci 6efb6008e5 adjust defaults 2017-03-01 16:27:33 +08:00
xtaci 53d4bbfe4c change default parameters 2017-03-01 11:06:20 +08:00
11 changed files with 112 additions and 425 deletions
+1 -1
View File
@@ -1,6 +1,6 @@
language: go
go:
- 1.6
- 1.9
before_install:
- go get github.com/mattn/goveralls
- go get golang.org/x/tools/cmd/cover
Binary file not shown.

After

Width:  |  Height:  |  Size: 636 B

+5 -2
View File
@@ -1,8 +1,11 @@
FROM golang:alpine
FROM golang:alpine as builder
MAINTAINER xtaci <daniel820313@gmail.com>
RUN apk update && \
apk upgrade && \
apk add git
RUN go get github.com/xtaci/kcptun/client && go get github.com/xtaci/kcptun/server
RUN go get -ldflags "-X main.VERSION=$(date -u +%Y%m%d) -s -w" github.com/xtaci/kcptun/client && go get -ldflags "-X main.VERSION=$(date -u +%Y%m%d) -s -w" github.com/xtaci/kcptun/server
FROM alpine:3.6
COPY --from=builder /go/bin /bin
EXPOSE 29900/udp
EXPOSE 12948
-362
View File
@@ -1,362 +0,0 @@
# <img src="logo.png" alt="kcptun" height="54px" />
[![Release][13]][14] [![Powered][17]][18] [![MIT licensed][11]][12] [![Build Status][3]][4] [![Go Report Card][5]][6] [![Downloads][15]][16] [![Docker][1]][2]
[1]: https://images.microbadger.com/badges/image/xtaci/kcptun.svg
[2]: https://microbadger.com/images/xtaci/kcptun
[3]: https://travis-ci.org/xtaci/kcptun.svg?branch=master
[4]: https://travis-ci.org/xtaci/kcptun
[5]: https://goreportcard.com/badge/github.com/xtaci/kcptun
[6]: https://goreportcard.com/report/github.com/xtaci/kcptun
[7]: https://img.shields.io/badge/license-MIT-blue.svg
[8]: https://raw.githubusercontent.com/xtaci/kcptun/master/LICENSE.md
[11]: https://img.shields.io/badge/license-MIT-blue.svg
[12]: LICENSE.md
[13]: https://img.shields.io/github/release/xtaci/kcptun.svg
[14]: https://github.com/xtaci/kcptun/releases/latest
[15]: https://img.shields.io/github/downloads/xtaci/kcptun/total.svg?maxAge=1800
[16]: https://github.com/xtaci/kcptun/releases
[17]: https://img.shields.io/badge/KCP-Powered-blue.svg
[18]: https://github.com/skywind3000/kcp
<img src="kcptun.png" alt="kcptun" height="300px"/>
-
### 快速设定
客户端、服务器分别**下载**对应平台的[预编译版本](https://github.com/xtaci/kcptun/releases),并**解压**,通过下面的命令**启动**端口转发。
```
KCP客户端: ./client_darwin_amd64 -r "KCP服务器IP地址:4000" -l ":8388" -mode fast2
KCP服务器: ./server_linux_amd64 -t "目标服务器IP地址:8388" -l ":4000" -mode fast2
```
以上命令可以实现8388/tcp端口的转发(通过4000/udp端口),即:
Application -> KCP客户端(8388/tcp) -> KCP服务器(4000/udp) -> Server(8388/tcp)
### 从源码安装
```
$go get -u github.com/xtaci/kcptun/client
$go get -u github.com/xtaci/kcptun/server
```
注意: 如果出现错误提示,请确保依赖库能正确访问到。
Release中的所有二进制版本,是通过 `build-release.sh` 脚本生成并优化。
### 速度对比
<img src="fast.png" alt="fast.com" height="256px" />
* 测速网站: https://fast.com
* 接入速度: 100Mbps
* WIFI: 5GHz TL-WDR3320
### 使用方法
在Mac OS X El Capitan下的帮助输出,注意默认值:
```
$ ./client_darwin_amd64 -h
NAME:
kcptun - client(with SMUX)
USAGE:
client_darwin_amd64 [global options] command [command options] [arguments...]
VERSION:
20170120
COMMANDS:
help, h Shows a list of commands or help for one command
GLOBAL OPTIONS:
--localaddr value, -l value local listen address (default: ":12948")
--remoteaddr value, -r value kcp server address (default: "vps:29900")
--key value pre-shared secret between client and server (default: "it's a secrect") [$KCPTUN_KEY]
--crypt value aes, aes-128, aes-192, salsa20, blowfish, twofish, cast5, 3des, tea, xtea, xor, none (default: "aes")
--mode value profiles: fast3, fast2, fast, normal (default: "fast")
--conn value set num of UDP connections to server (default: 1)
--autoexpire value set auto expiration time(in seconds) for a single UDP connection, 0 to disable (default: 0)
--mtu value set maximum transmission unit for UDP packets (default: 1350)
--sndwnd value set send window size(num of packets) (default: 128)
--rcvwnd value set receive window size(num of packets) (default: 512)
--datashard value, --ds value set reed-solomon erasure coding - datashard (default: 10)
--parityshard value, --ps value set reed-solomon erasure coding - parityshard (default: 3)
--dscp value set DSCP(6bit) (default: 0)
--nocomp disable compression
--snmplog value collect snmp to file, aware of timeformat in golang, like: ./snmp-20060102.log
--snmpperiod value snmp collect period, in seconds (default: 60)
--log value specify a log file to output, default goes to stderr
-c value config from json file, which will override the command from shell
--help, -h show help
--version, -v print the version
$ ./server_darwin_amd64 -h
NAME:
kcptun - server(with SMUX)
USAGE:
server_darwin_amd64 [global options] command [command options] [arguments...]
VERSION:
20170120
COMMANDS:
help, h Shows a list of commands or help for one command
GLOBAL OPTIONS:
--listen value, -l value kcp server listen address (default: ":29900")
--target value, -t value target server address (default: "127.0.0.1:12948")
--key value pre-shared secret between client and server (default: "it's a secrect") [$KCPTUN_KEY]
--crypt value aes, aes-128, aes-192, salsa20, blowfish, twofish, cast5, 3des, tea, xtea, xor, none (default: "aes")
--mode value profiles: fast3, fast2, fast, normal (default: "fast")
--mtu value set maximum transmission unit for UDP packets (default: 1350)
--sndwnd value set send window size(num of packets) (default: 1024)
--rcvwnd value set receive window size(num of packets) (default: 1024)
--datashard value, --ds value set reed-solomon erasure coding - datashard (default: 10)
--parityshard value, --ps value set reed-solomon erasure coding - parityshard (default: 3)
--dscp value set DSCP(6bit) (default: 0)
--nocomp disable compression
--snmplog value collect snmp to file, aware of timeformat in golang, like: ./snmp-20060102.log
--snmpperiod value snmp collect period, in seconds (default: 60)
--log value specify a log file to output, default goes to stderr
-c value config from json file, which will override the command from shell
--help, -h show help
--version, -v print the version
```
#### 分层参数图
<p align="left"><img src="layeredparams.png" alt="params" height="450px"/></p>
**两端参数必须一致的有**:
* datashard --前向纠错
* parityshard --前向纠错
* nocomp --压缩
* key --密钥
* crypt --加密算法
其余为两边可独立设定的参数
### 内置模式
响应速度:
*fast3 > fast2 >* **[fast]** *> normal > default*
有效载荷比:
*default > normal >* **[fast]** *> fast2 > fast3*
中间-mode参数比较均衡,总之就是越快,包重传越激进。
更高级的 **手动档** 需要理解KCP协议,并通过 **隐藏参数** 调整,例如:
```
-mode manual -nodelay 1 -resend 2 -nc 1 -interval 20
```
* 搭配1. fast + FEC(5,5)
* 搭配2. fast2 + FEC(10,3)
* 搭配3. fast2 + FEC(0,0)
默认profile参考: https://github.com/xtaci/kcptun/blob/master/client/main.go#L248
### 前向纠错
前向纠错采用Reed Solomon纠删码, 它的基本原理如下: 给定n个数据块d1, d2,…, dn,n和一个正整数m, RS根据n个数据块生成m个校验块, c1, c2,…, cm。 对于任意的n和m, 从n个原始数据块和m 个校验块中任取n块就能解码出原始数据, 即RS最多**容忍m个数据块或者校验块同时丢失**。
![reed-solomon](rs.png)
通过参数```-datashard n -parityshard m``` 在两端同时设定。
数据包发送顺序严格遵循: n个datashard紧接m个parityshard,重复。
注意:为了发挥FEC最佳效果,设置 parityshard/(parity+datashard) > packet loss,比如5/(5+5) > 30%
### 窗口调整
**简易窗口自我调优方法**
> 第一步:同时在两端逐步增大client rcvwnd和server sndwnd;
> 第二步:尝试下载,观察如果带宽利用率(服务器+客户端两端都要观察)到达预期则停止,否则跳转到第一步。
**注意:产生大量重传时,一定是窗口偏大了**
### 安全
无论你上层如何加密,如果```-crypt none```,那么**协议头部**都是**明文**的,建议至少采用```-crypt aes-128```加密,并修改密码。
密码可以通过`-key`指定,也可以通过环境变量`KCPTUN_KEY`指定。
注意: ```-crypt xor``` 也是不安全的,除非你知道你在做什么。
附加密速度Benchmark
```
BenchmarkAES128-4 200000 11182 ns/op
BenchmarkAES192-4 200000 12699 ns/op
BenchmarkAES256-4 100000 13757 ns/op
BenchmarkTEA-4 50000 26441 ns/op
BenchmarkSimpleXOR-4 3000000 441 ns/op
BenchmarkBlowfish-4 30000 48036 ns/op
BenchmarkNone-4 20000000 106 ns/op
BenchmarkCast5-4 20000 60222 ns/op
BenchmarkTripleDES-4 2000 878759 ns/op
BenchmarkTwofish-4 20000 68501 ns/op
BenchmarkXTEA-4 20000 77417 ns/op
BenchmarkSalsa20-4 300000 4998 ns/op
```
### 内存控制
路由器,手机等嵌入式设备通常对**内存用量敏感**,通过调节环境变量GOGC(例如GOGC=20)后启动client,可以降低内存使用。
参考:https://blog.golang.org/go15gc
### DSCP
DSCP差分服务代码点(Differentiated Services Code Point),IETF于1998年12月发布了Diff-ServDifferentiated Service)的QoS分类标准。它在每个数据包IP头部的服务类别TOS标识字节中,利用已使用的**6比特**和未使用的2比特,通过编码值来区分优先级。
常用DSCP值可以参考[Wikipedia DSCP](https://en.wikipedia.org/wiki/Differentiated_services#Commonly_used_DSCP_values),至于有没有用,完全取决于数据包经过的设备。
通过 ```-dscp ``` 参数指定dscp值,两端可分别设定。
注意:设置dscp不一定会更好,需要尝试。
### Snappy数据流压缩
> Snappy is a compression/decompression library. It does not aim for maximum
> compression, or compatibility with any other compression library; instead,
> it aims for very high speeds and reasonable compression. For instance,
> compared to the fastest mode of zlib, Snappy is an order of magnitude faster
> for most inputs, but the resulting compressed files are anywhere from 20% to
> 100% bigger.
> Reference: http://google.github.io/snappy/
压缩对于非加密,非压缩的数据能降低传输数据量,比如点对点的HTTP数据转发。
通过参数 ```-nocomp``` 在两端同时设定以关闭压缩。
> 提示: 关闭压缩可能会降低延迟。
### 流量控制
**必要性: 针对流量敏感的服务器,做双保险。**
> 基本原则: SERVER的发送速率不能超过ADSL下行带宽,否则只会浪费您的服务器带宽。
在server通过linux tc,可以限制服务器发送带宽。
举例: 用linux tc限制server发送带宽为32mbit/s:
```
root@kcptun:~# cat tc.sh
tc qdisc del dev eth0 root
tc qdisc add dev eth0 root handle 1: htb
tc class add dev eth0 parent 1: classid 1:1 htb rate 32mbit
tc filter add dev eth0 protocol ip parent 1:0 prio 1 handle 10 fw flowid 1:1
iptables -t mangle -A POSTROUTING -o eth0 -j MARK --set-mark 10
root@kcptun:~#
```
其中eth0为网卡,有些服务器为ens3,有些为p2p1,通过ifconfig查询修改。
### SNMP
```go
// Snmp defines network statistics indicator
type Snmp struct {
BytesSent uint64 // raw bytes sent
BytesReceived uint64
MaxConn uint64
ActiveOpens uint64
PassiveOpens uint64
CurrEstab uint64 // count of connections for now
InErrs uint64 // udp read errors
InCsumErrors uint64 // checksum errors from CRC32
KCPInErrors uint64 // packet iput errors from kcp
InSegs uint64
OutSegs uint64
InBytes uint64 // udp bytes received
OutBytes uint64 // udp bytes sent
RetransSegs uint64
FastRetransSegs uint64
EarlyRetransSegs uint64
LostSegs uint64 // number of segs infered as lost
RepeatSegs uint64 // number of segs duplicated
FECRecovered uint64 // correct packets recovered from FEC
FECErrs uint64 // incorrect packets recovered from FEC
FECSegs uint64 // FEC segments received
FECShortShards uint64 // number of data shards that's not enough for recovery
}
```
使用```kill -SIGUSR1 pid``` 可以在控制台打印出SNMP信息,通常用于精细调整**当前链路的有效载荷比**。
观察```RetransSegs,FastRetransSegs,LostSegs,OutSegs```这几者的数值比例,用于参考调整```-mode manual,fec```的参数。
#### 带宽计算公式
```
在不丢包的情况下,有最大-rcvwnd 个数据包在网络上正在向你传输,以平均数据包大小avgsize计算,在任意时刻,有:
network_cap = rcvwnd*avgsize
数据流向你,这个值再除以ping值(rtt),等于最大带宽使用量。
max_bandwidth = network_cap/rtt = rcvwnd*avgsize/rtt
举例,设rcvwnd = 1024, avgsize = 1KB, rtt = 400ms,则:
max_bandwidth = 1024 * 1KB / 400ms = 2.5MB/s ~= 25Mbps
(注:以上计算不包括前向纠错的数据量)
前向纠错是最大带宽量的一个固定比例增加:
max_bandwidth_fec = max_bandwidth*(datashard+parityshard)/datashard
举例,设datashard = 10 , partiyshard = 3,则:
max_bandwidth_fec = max_bandwidth * (10 + 3) /10 = 1.3*max_bandwidth 1.3 * 25Mbps = 32.5Mbps
```
### 故障排除
> Q: 客户端和服务器端**皆无** ```stream opened```信息。
> A: 连接客户端程序的端口设置错误。
> Q: 客户端有 ```stream opened```信息,服务器端没有。
> A: 连接服务器的端口设置错误,或者被防火墙拦截。
> Q: 客户端服务器**皆有** ```stream opened```信息,但无法通信。
> A: 上层软件的设定错误。
### 免责申明
**用户以各种方式使用本软件(包括但不限于修改使用、直接使用、通过第三方使用)的过程中,不得以任何方式利用本软件直接或间接从事违反中国法律、以及社会公德的行为。软件的使用者需对自身行为负责,因使用软件引发的一切纠纷,由使用者承担全部法律及连带责任。作者不承担任何法律及连带责任。**
**对免责声明的解释、修改及更新权均属于作者本人所有。**
### 特别鸣谢
> 郑H立, 南东风, Li, 七七, 凌君, 昶,LesMiserables, KyOn, 噼里啪啦, 继斌, 小苍辛苦, **Ken**,
> 乔槁, 佳晨, 猪肉佬, lcx, 昊文, 冰峰, 凡, alex, **海豹叔叔**, 奥姐, 张冰, 司成,
> 武子, **慎**Alex43211**Coxxs**,荣,NeroNg,吴骁,定一,我不是林JPatrick, 超, 陈,windfarer, 宇,
> 今晶,斌,晓东,最后一缕阳光,亮,Ethan,一心不乱,allenm,冬卯,GELATO,用户1Butterfly,光子曲面,
> 丞佳,捉鱼,TalonBiny,李勇,***阿彪******rinex20***Fabre,路过发光体,池子,kk,杰,维维
好人一生平安!
### 相关软件
1. https://github.com/bettermanbao/openwrt-kcptun
2. https://github.com/EasyPi/openwrt-kcptun
3. https://github.com/kuoruan/luci-app-kcptun
4. https://github.com/dfdragon/kcptun_gclient
5. https://github.com/dfdragon/kcptun_xclient
### 参考资料
1. https://github.com/skywind3000/kcp -- KCP - A Fast and Reliable ARQ Protocol.
2. https://github.com/klauspost/reedsolomon -- Reed-Solomon Erasure Coding in Go.
3. https://en.wikipedia.org/wiki/Differentiated_services -- DSCP.
4. http://google.github.io/snappy/ -- A fast compressor/decompressor.
5. https://www.backblaze.com/blog/reed-solomon/ -- Reed-Solomon Explained.
6. http://www.qualcomm.cn/products/raptorq -- RaptorQ Forward Error Correction Scheme for Object Delivery.
7. https://en.wikipedia.org/wiki/PBKDF2 -- Key stretching.
8. http://blog.appcanary.com/2016/encrypt-or-compress.html -- Should you encrypt or compress first?
9. https://github.com/hashicorp/yamux -- Connection multiplexing library.
10. https://tools.ietf.org/html/rfc6937 -- Proportional Rate Reduction for TCP.
11. https://tools.ietf.org/html/rfc5827 -- Early Retransmit for TCP and Stream Control Transmission Protocol (SCTP).
12. http://http2.github.io/ -- What is HTTP/2?
13. http://www.lartc.org/LARTC-zh_CN.GB2312.pdf -- Linux Advanced Routing & Traffic Control
14. https://en.wikipedia.org/wiki/Noisy-channel_coding_theorem -- Noisy channel coding theorem
+45 -28
View File
@@ -1,5 +1,7 @@
# <img src="logo.png" alt="kcptun" height="54px" />
[![Release][13]][14] [![Powered][17]][18] [![MIT licensed][11]][12] [![Build Status][3]][4] [![Go Report Card][5]][6] [![Downloads][15]][16] [![Docker][1]][2]
[1]: https://images.microbadger.com/badges/image/xtaci/kcptun.svg
[2]: https://microbadger.com/images/xtaci/kcptun
[3]: https://travis-ci.org/xtaci/kcptun.svg?branch=master
@@ -17,15 +19,18 @@
[17]: https://img.shields.io/badge/KCP-Powered-blue.svg
[18]: https://github.com/skywind3000/kcp
<img src="kcptun.png" alt="kcptun" height="300px"/>
[简体中文](README-CN.md)
> *kcptun maintains a single website — [github.com/xtaci/kcptun](https://github.com/xtaci/kcptun). Any websites other than [github.com/xtaci/kcptun](https://github.com/xtaci/kcptun) are not endorsed by xtaci. kcptun won't publish anything on any social media.*
-
> *KCP communication group: 364933586 (QQ group number), KCP integration, tuning, network transmission and related technical discussions.*
### QuickStart
Increase number of open files on your server, as:
`ulimit -n 65535`, or write it in `~/.bashrc`.
Download precompiled [Releases](https://github.com/xtaci/kcptun/releases).
```
@@ -34,7 +39,11 @@ KCP Server: ./server_linux_amd64 -t "TARGET_IP:8388" -l ":4000" -mode fast2
```
The above commands will establish port forwarding for 8388/tcp as:
Application -> KCP Client(8388/tcp) -> KCP Server(4000/udp) -> Server(8388/tcp)
> Application -> **KCP Client(8388/tcp) -> KCP Server(4000/udp)** -> Target Server(8388/tcp)
Tunnels the original connection:
> Application -> Target Server(8388/tcp)
### Install from source
@@ -55,7 +64,8 @@ All precompiled releases are genereated from `build-release.sh` script.
> **Q: I have a high speed network link, how to reach the maximum bandwidth?**
> **A:** Increase `-rcvwnd` on KCP Client and `-sndwnd` on KCP Server **simultaneously & gradually**, the mininum one decides the maximum transfer rate of the link, as `wnd * mtu / rtt`; Then try downloading something and to see if it meets your requirements.
> **A:** Increase `-rcvwnd` on KCP Client and `-sndwnd` on KCP Server **simultaneously & gradually**, the mininum one decides the maximum transfer rate of the link, as `wnd * mtu / rtt`; Then try downloading something and to see if it meets your requirements.
(mtu is adjustable by `-mtu`)
#### Improving Latency
@@ -157,7 +167,7 @@ It is able to detect and correct multiple symbol errors. By adding t check symbo
![reed-solomon](rs.png)
Setting parameters of RS-Code with ```-datashard m -parityshard n``` on both KCP Client & KCP Server.
Setting parameters of RS-Code with ```-datashard m -parityshard n``` on **BOTH** KCP Client & KCP Server **MUST** be **IDENTICAL**.
#### DSCP
@@ -215,7 +225,7 @@ kcptun has builtin snappy algorithms for compressing streams:
Compression may save bandwidth for **PLAINTEXT** data, such as HTTP data.
Compression is enabled by default, you can disable it by setting ```-nocomp``` on both KCP Client & KCP Server.
Compression is enabled by default, you can disable it by setting ```-nocomp``` on **BOTH** KCP Client & KCP Server **MUST** be **IDENTICAL**.
#### SNMP
@@ -257,31 +267,38 @@ https://github.com/skywind3000/kcp/blob/master/README.en.md#protocol-configurati
Low-level KCP configuration can be altered by using manual mode like above, make sure you really **UNDERSTAND** what these means before doing **ANY** manual settings.
### Support
You can support this project by the following methods:
### Identical Parmeters
1. Vultr promotion code:
http://www.vultr.com/?ref=6897065
The parameters below **MUST** be **IDENTICAL** on **BOTH** side:
2. Paypal
https://www.paypal.me/xtaci
Your name or github name will be listed on this page by default.
1. -key
1. -crypt
1. -nocomp
1. -datashard
1. -parityshard
### References
1. https://github.com/skywind3000/kcp -- KCP - A Fast and Reliable ARQ Protocol.
2. https://github.com/klauspost/reedsolomon -- Reed-Solomon Erasure Coding in Go.
3. https://en.wikipedia.org/wiki/Differentiated_services -- DSCP.
4. http://google.github.io/snappy/ -- A fast compressor/decompressor.
5. https://www.backblaze.com/blog/reed-solomon/ -- Reed-Solomon Explained.
6. http://www.qualcomm.cn/products/raptorq -- RaptorQ Forward Error Correction Scheme for Object Delivery.
7. https://en.wikipedia.org/wiki/PBKDF2 -- Key stretching.
8. http://blog.appcanary.com/2016/encrypt-or-compress.html -- Should you encrypt or compress first?
9. https://github.com/hashicorp/yamux -- Connection multiplexing library.
10. https://tools.ietf.org/html/rfc6937 -- Proportional Rate Reduction for TCP.
11. https://tools.ietf.org/html/rfc5827 -- Early Retransmit for TCP and Stream Control Transmission Protocol (SCTP).
12. http://http2.github.io/ -- What is HTTP/2?
13. http://www.lartc.org/ -- Linux Advanced Routing & Traffic Control
14. https://en.wikipedia.org/wiki/Noisy-channel_coding_theorem -- Noisy channel coding theorem
1. https://github.com/xtaci/kcp-go/ -- A Production-Grade Reliable-UDP Library for golang
1. https://github.com/klauspost/reedsolomon -- Reed-Solomon Erasure Coding in Go.
1. https://en.wikipedia.org/wiki/Differentiated_services -- DSCP.
1. http://google.github.io/snappy/ -- A fast compressor/decompressor.
1. https://www.backblaze.com/blog/reed-solomon/ -- Reed-Solomon Explained.
1. http://www.qualcomm.cn/products/raptorq -- RaptorQ Forward Error Correction Scheme for Object Delivery.
1. https://en.wikipedia.org/wiki/PBKDF2 -- Key stretching.
1. http://blog.appcanary.com/2016/encrypt-or-compress.html -- Should you encrypt or compress first?
1. https://github.com/hashicorp/yamux -- Connection multiplexing library.
1. https://tools.ietf.org/html/rfc6937 -- Proportional Rate Reduction for TCP.
1. https://tools.ietf.org/html/rfc5827 -- Early Retransmit for TCP and Stream Control Transmission Protocol (SCTP).
1. http://http2.github.io/ -- What is HTTP/2?
1. http://www.lartc.org/ -- Linux Advanced Routing & Traffic Control
1. https://en.wikipedia.org/wiki/Noisy-channel_coding_theorem -- Noisy channel coding theorem
1. https://play.google.com/store/apps/details?id=com.k17game.k3 -- Battle Zone - Earth 2048, an online strategy game using kcp.
### Donate via Ethereum(ETH)
Address: 0x2e4b43ab3d0983da282592571eef61ae5e60f726 , Or scan here:
<img src="0x2e4b43ab3d0983da282592571eef61ae5e60f726.png" alt="kcptun" height="100px" />
+1
View File
@@ -32,6 +32,7 @@ type Config struct {
Log string `json:"log"`
SnmpLog string `json:"snmplog"`
SnmpPeriod int `json:"snmpperiod"`
Quiet bool `json:"quiet"`
}
func parseJSONConfig(config *Config, path string) error {
+23 -17
View File
@@ -55,15 +55,17 @@ func newCompStream(conn net.Conn) *compStream {
return c
}
func handleClient(sess *smux.Session, p1 io.ReadWriteCloser) {
func handleClient(sess *smux.Session, p1 io.ReadWriteCloser, quiet bool) {
if !quiet {
log.Println("stream opened")
defer log.Println("stream closed")
}
defer p1.Close()
p2, err := sess.OpenStream()
if err != nil {
return
}
log.Println("stream opened")
defer log.Println("stream closed")
defer p1.Close()
defer p2.Close()
// start tunnel
@@ -117,7 +119,7 @@ func main() {
cli.StringFlag{
Name: "crypt",
Value: "aes",
Usage: "aes, aes-128, aes-192, salsa20, blowfish, twofish, cast5, 3des, tea, xtea, xor, none",
Usage: "aes, aes-128, aes-192, salsa20, blowfish, twofish, cast5, 3des, tea, xtea, xor, sm4, none",
},
cli.StringFlag{
Name: "mode",
@@ -185,7 +187,7 @@ func main() {
},
cli.IntFlag{
Name: "interval",
Value: 40,
Value: 50,
Hidden: true,
},
cli.IntFlag{
@@ -223,6 +225,10 @@ func main() {
Value: "",
Usage: "specify a log file to output, default goes to stderr",
},
cli.BoolFlag{
Name: "quiet",
Usage: "to suppress the 'stream open/close' messages",
},
cli.StringFlag{
Name: "c",
Value: "", // when the value is not empty, the config path must exists
@@ -256,6 +262,7 @@ func main() {
config.Log = c.String("log")
config.SnmpLog = c.String("snmplog")
config.SnmpPeriod = c.Int("snmpperiod")
config.Quiet = c.Bool("quiet")
if c.String("c") != "" {
err := parseJSONConfig(&config, c.String("c"))
@@ -272,9 +279,9 @@ func main() {
switch config.Mode {
case "normal":
config.NoDelay, config.Interval, config.Resend, config.NoCongestion = 0, 30, 2, 1
config.NoDelay, config.Interval, config.Resend, config.NoCongestion = 0, 40, 2, 1
case "fast":
config.NoDelay, config.Interval, config.Resend, config.NoCongestion = 0, 20, 2, 1
config.NoDelay, config.Interval, config.Resend, config.NoCongestion = 0, 30, 2, 1
case "fast2":
config.NoDelay, config.Interval, config.Resend, config.NoCongestion = 1, 20, 2, 1
case "fast3":
@@ -290,6 +297,8 @@ func main() {
pass := pbkdf2.Key([]byte(config.Key), []byte(SALT), 4096, 32, sha1.New)
var block kcp.BlockCrypt
switch config.Crypt {
case "sm4":
block, _ = kcp.NewSM4BlockCrypt(pass[:16])
case "tea":
block, _ = kcp.NewTEABlockCrypt(pass[:16])
case "xor":
@@ -334,9 +343,11 @@ func main() {
log.Println("scavengettl:", config.ScavengeTTL)
log.Println("snmplog:", config.SnmpLog)
log.Println("snmpperiod:", config.SnmpPeriod)
log.Println("quiet:", config.Quiet)
smuxConfig := smux.DefaultConfig()
smuxConfig.MaxReceiveBuffer = config.SockBuf
smuxConfig.KeepAliveInterval = time.Duration(config.KeepAlive) * time.Second
createConn := func() (*smux.Session, error) {
kcpconn, err := kcp.DialWithOptions(config.RemoteAddr, block, config.DataShard, config.ParityShard)
@@ -344,11 +355,11 @@ func main() {
return nil, errors.Wrap(err, "createConn()")
}
kcpconn.SetStreamMode(true)
kcpconn.SetWriteDelay(true)
kcpconn.SetNoDelay(config.NoDelay, config.Interval, config.Resend, config.NoCongestion)
kcpconn.SetWindowSize(config.SndWnd, config.RcvWnd)
kcpconn.SetMtu(config.MTU)
kcpconn.SetACKNoDelay(config.AckNodelay)
kcpconn.SetKeepAlive(config.KeepAlive)
if err := kcpconn.SetDSCP(config.DSCP); err != nil {
log.Println("SetDSCP:", err)
@@ -380,6 +391,7 @@ func main() {
if session, err := createConn(); err == nil {
return session
} else {
log.Println("re-connecting:", err)
time.Sleep(time.Second)
}
}
@@ -405,12 +417,6 @@ func main() {
if err != nil {
log.Fatalln(err)
}
if err := p1.SetReadBuffer(config.SockBuf); err != nil {
log.Println("TCP SetReadBuffer:", err)
}
if err := p1.SetWriteBuffer(config.SockBuf); err != nil {
log.Println("TCP SetWriteBuffer:", err)
}
checkError(err)
idx := rr % numconn
@@ -421,7 +427,7 @@ func main() {
muxes[idx].ttl = time.Now().Add(time.Duration(config.AutoExpire) * time.Second)
}
go handleClient(muxes[idx].session, p1)
go handleClient(muxes[idx].session, p1, config.Quiet)
rr++
}
}
+1
View File
@@ -18,6 +18,7 @@ func init() {
func sigHandler() {
ch := make(chan os.Signal, 1)
signal.Notify(ch, syscall.SIGUSR1)
signal.Ignore(syscall.SIGPIPE)
for {
switch <-ch {
+2
View File
@@ -29,6 +29,8 @@ type Config struct {
Log string `json:"log"`
SnmpLog string `json:"snmplog"`
SnmpPeriod int `json:"snmpperiod"`
Pprof bool `json:"pprof"`
Quiet bool `json:"quiet"`
}
func parseJSONConfig(config *Config, path string) error {
+33 -15
View File
@@ -8,6 +8,8 @@ import (
"log"
"math/rand"
"net"
"net/http"
_ "net/http/pprof"
"os"
"time"
@@ -59,6 +61,8 @@ func handleMux(conn io.ReadWriteCloser, config *Config) {
// stream multiplex
smuxConfig := smux.DefaultConfig()
smuxConfig.MaxReceiveBuffer = config.SockBuf
smuxConfig.KeepAliveInterval = time.Duration(config.KeepAlive) * time.Second
mux, err := smux.Server(conn, smuxConfig)
if err != nil {
log.Println(err)
@@ -77,19 +81,15 @@ func handleMux(conn io.ReadWriteCloser, config *Config) {
log.Println(err)
continue
}
if err := p2.(*net.TCPConn).SetReadBuffer(config.SockBuf); err != nil {
log.Println("TCP SetReadBuffer:", err)
}
if err := p2.(*net.TCPConn).SetWriteBuffer(config.SockBuf); err != nil {
log.Println("TCP SetWriteBuffer:", err)
}
go handleClient(p1, p2)
go handleClient(p1, p2, config.Quiet)
}
}
func handleClient(p1, p2 io.ReadWriteCloser) {
log.Println("stream opened")
defer log.Println("stream closed")
func handleClient(p1, p2 io.ReadWriteCloser, quiet bool) {
if !quiet {
log.Println("stream opened")
defer log.Println("stream closed")
}
defer p1.Close()
defer p2.Close()
@@ -144,7 +144,7 @@ func main() {
cli.StringFlag{
Name: "crypt",
Value: "aes",
Usage: "aes, aes-128, aes-192, salsa20, blowfish, twofish, cast5, 3des, tea, xtea, xor, none",
Usage: "aes, aes-128, aes-192, salsa20, blowfish, twofish, cast5, 3des, tea, xtea, xor, sm4, none",
},
cli.StringFlag{
Name: "mode",
@@ -197,7 +197,7 @@ func main() {
},
cli.IntFlag{
Name: "interval",
Value: 40,
Value: 50,
Hidden: true,
},
cli.IntFlag{
@@ -230,11 +230,19 @@ func main() {
Value: 60,
Usage: "snmp collect period, in seconds",
},
cli.BoolFlag{
Name: "pprof",
Usage: "start profiling server on :6060",
},
cli.StringFlag{
Name: "log",
Value: "",
Usage: "specify a log file to output, default goes to stderr",
},
cli.BoolFlag{
Name: "quiet",
Usage: "to suppress the 'stream open/close' messages",
},
cli.StringFlag{
Name: "c",
Value: "", // when the value is not empty, the config path must exists
@@ -265,6 +273,8 @@ func main() {
config.Log = c.String("log")
config.SnmpLog = c.String("snmplog")
config.SnmpPeriod = c.Int("snmpperiod")
config.Pprof = c.Bool("pprof")
config.Quiet = c.Bool("quiet")
if c.String("c") != "" {
//Now only support json config file
@@ -282,9 +292,9 @@ func main() {
switch config.Mode {
case "normal":
config.NoDelay, config.Interval, config.Resend, config.NoCongestion = 0, 30, 2, 1
config.NoDelay, config.Interval, config.Resend, config.NoCongestion = 0, 40, 2, 1
case "fast":
config.NoDelay, config.Interval, config.Resend, config.NoCongestion = 0, 20, 2, 1
config.NoDelay, config.Interval, config.Resend, config.NoCongestion = 0, 30, 2, 1
case "fast2":
config.NoDelay, config.Interval, config.Resend, config.NoCongestion = 1, 20, 2, 1
case "fast3":
@@ -295,6 +305,8 @@ func main() {
pass := pbkdf2.Key([]byte(config.Key), []byte(SALT), 4096, 32, sha1.New)
var block kcp.BlockCrypt
switch config.Crypt {
case "sm4":
block, _ = kcp.NewSM4BlockCrypt(pass[:16])
case "tea":
block, _ = kcp.NewTEABlockCrypt(pass[:16])
case "xor":
@@ -338,6 +350,8 @@ func main() {
log.Println("keepalive:", config.KeepAlive)
log.Println("snmplog:", config.SnmpLog)
log.Println("snmpperiod:", config.SnmpPeriod)
log.Println("pprof:", config.Pprof)
log.Println("quiet:", config.Quiet)
if err := lis.SetDSCP(config.DSCP); err != nil {
log.Println("SetDSCP:", err)
@@ -350,15 +364,19 @@ func main() {
}
go snmpLogger(config.SnmpLog, config.SnmpPeriod)
if config.Pprof {
go http.ListenAndServe(":6060", nil)
}
for {
if conn, err := lis.AcceptKCP(); err == nil {
log.Println("remote address:", conn.RemoteAddr())
conn.SetStreamMode(true)
conn.SetWriteDelay(true)
conn.SetNoDelay(config.NoDelay, config.Interval, config.Resend, config.NoCongestion)
conn.SetMtu(config.MTU)
conn.SetWindowSize(config.SndWnd, config.RcvWnd)
conn.SetACKNoDelay(config.AckNodelay)
conn.SetKeepAlive(config.KeepAlive)
if config.NoComp {
go handleMux(conn, &config)
+1
View File
@@ -18,6 +18,7 @@ func init() {
func sigHandler() {
ch := make(chan os.Signal, 1)
signal.Notify(ch, syscall.SIGUSR1)
signal.Ignore(syscall.SIGPIPE)
for {
switch <-ch {