Compare commits

..

54 Commits

Author SHA1 Message Date
rustdesk
7dc127c00f bump webrtc fork: T3-rtx restart on fast retransmission while shutting down too
rustdesk-org/webrtc 48100bf1. The restart for the earliest chunk's fast
retransmission reached only the Established branch of the write loop; the
shutdown states still carry data in flight and recover it the same way, so a
closing association could still resend everything on a loss its fast
retransmit had already recovered. Both branches share one helper now.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019aokqJuhjvB3kijXtAg5Ns
2026-09-06 00:12:57 +08:00
rustdesk
ad2efb8f2e bump webrtc fork: T3-rtx restarts only for the earliest chunk's fast retransmission
rustdesk-org/webrtc 2b8e55bc. Sending without a congestion window, a fast
retransmission of any chunk restarted T3-rtx, so a chunk past the fast
retransmission cap - left to that timer - never reached it while later
chunks kept being resent, which a lossy stream does every couple of frames.
The timer is the earliest in-flight chunk's, and only its resend restarts
it now. Nothing else changes; the benchmark is unchanged.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019aokqJuhjvB3kijXtAg5Ns
2026-09-05 23:50:49 +08:00
rustdesk
7bab2c3297 bump webrtc fork: MTU-safe bundles, a reordering window, tail loss within the RTT
rustdesk-org/webrtc cc6633bc, three commits on 825a0a48, all on the path
that sends without a congestion window:

Both bundlers counted a DATA chunk by its payload alone; with the header and
padding counted, bundles of small chunks stay within the MTU, and the fragment
payload rounds down to 1160 so a full chunk does too. A chunk is fast
retransmitted at most five times, KCP's IKCP_FASTACK_LIMIT.

A frame's chunks go out within microseconds of each other, so on a path that
jitters the send-order rule resent every chunk that landed behind three of
its siblings: 2.7x the payload on the wire at 10ms of jitter, and on a link
without the room for that, a queue that fed on itself. A reordering window,
RACK's, makes evidence count only from what was sent a quarter of an srtt
after the chunk once the path is seen to reorder, widening on the duplicate
TSNs the receiver reports. 5 Mbps, 1% loss, 20ms jitter: 600 of 600 frames
at a 98ms mean where 290 arrived at 6.2s.

A chunk lost at the tail of a burst has only T3-rtx, which ran from floors
sized for a 200ms delayed ack and restarted only on the tail's predecessor's
ack: 600ms and more. Every DATA chunk now carries the I bit, the floors are
KCP's shape, and a fast retransmission restarts the timer. One 200-byte
message per frame at 5% loss: 9 of 600 later than 200ms, from 42.

Random loss without jitter is unchanged at every rate and frame size.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019aokqJuhjvB3kijXtAg5Ns
2026-09-05 22:55:44 +08:00
rustdesk
dd5f4cd866 udp: make the punch deadline absolute, so a talking peer cannot defer it
`select!` rebuilds every arm each iteration, so the relative retry sleep was
restarted by each datagram that arrived before it fired. The peer sets that
rate, and an old-build peer's empty datagrams match no arm and loop without
even the recv-error pause, so MAX_TIME went unchecked and the retransmit was
starved with it. `udp_nat_connect` awaits the punch ahead of the KCP timeout
and nothing above it bounds the phase, so the punch held the direct race open
and the relay fallback out of reach for as long as the peer kept sending.

Absolute instants for both clocks. The new test floods empty datagrams for
four times the deadline: the punch now ends at 3s where it ran the full 12s.

Also note at the symmetric-NAT branch that WebRTC not following the legacy
relay decision there is deliberate, so it is not later "fixed" into agreement.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019aokqJuhjvB3kijXtAg5Ns
2026-09-05 15:49:48 +08:00
rustdesk
72fe4878d4 l10n: the two WebRTC keys were missing from Urdu
Every other lang file on the branch carries them; ur.rs was skipped when
they were added.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019aokqJuhjvB3kijXtAg5Ns
2026-09-05 15:06:53 +08:00
rustdesk
f94c861182 port_forward: restore the ? the close removal left as a match
Dropping the explicit close_webrtc() from the parse-error arm left a match
that only re-spells `?`; master just reworked this function, so the branch
now leaves port_forward.rs untouched.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019aokqJuhjvB3kijXtAg5Ns
2026-09-05 15:04:43 +08:00
rustdesk
fe2946617e bump hbb_common: quiet the webrtc-rs warnings that describe the race's normal outcome
Cancelling the transport that lost the race, and trickle checking before it
holds a pair, are what the design does on every session that connects - and
webrtc-rs reports both at warn, 90 lines of a 386-line controlled-side log,
beside connections that succeeded. agent_internal and peer_connection drop to
error; agent_gather keeps warn, since an unreachable STUN server is the one
upstream signal that explains a session which never connected.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01M54JAqUK4RynudFou89hod
2026-09-05 15:04:43 +08:00
rustdesk
aef7d9758b bump hbb_common: end the ICE forwarder at gathering complete, drop the closes Drop covers
hbb_common now closes the local-candidate channel when gathering
completes, so the controlled side's forwarder in spawn_webrtc_answerer
ends there, and its signaling connection to hbbs with it, instead of
sitting on a socket hbbs closed at 90s idle for the rest of the session.
It also keeps the reassembly buffer across fragmented frames.

Stream closes the WebRTC peer connection on drop (hbb_common b0b624d),
so the close_webrtc() calls in port_forward and io_loop that sat
immediately before a return or the end of scope did nothing Drop was
not about to do, while the comments beside them still said a bare drop
leaked the pc. Remove both.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019aokqJuhjvB3kijXtAg5Ns
2026-09-05 15:04:43 +08:00
rustdesk
231ccae10d web: show the WebRTC toggle and transport in the web UI
The web client now speaks WebRTC, but the desktop settings page hides
the punch options on web and the remote page opens without the session
tab that carries the transport name. Let the existing "Enable WebRTC P2P
connection" checkbox through on web (the other punch options stay
native-only), and add a Transport row to the quality monitor for WebRTC
sessions only (with "(TURN)" when ICE relayed), on every platform.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JXJJGEGdgu26wgCppvUXdZ
2026-09-05 15:04:43 +08:00
rustdesk
62b2b67bfd bump hbb_common: decode TURN userinfo, add the webrtc_echo example
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JXJJGEGdgu26wgCppvUXdZ
2026-09-05 15:04:43 +08:00
rustdesk
ab89f2338c webrtc: take the fork's loss recovery for sending without a congestion window
rustdesk-org/webrtc 825a0a48: without a congestion window a chunk is lost
once three chunks sent after its latest transmission are acked, counted in
send order so retransmitted chunks are covered too, and the fast retransmit
sends every lost chunk at once, as KCP nc=1 does; before, a lost
retransmission waited for T3-rtx. Also fixes the delayed SACK timer never
re-arming, the switch applying to established associations, T3-rtx
resending one chunk when the peer's window is full, and bounds new data to
1 MiB / 1024 chunks in flight like KCP's snd_wnd.

Simulated 35ms one-way, random loss both ways, 30 fps, frames later than
200ms out of 1200: 12 KB at 5% loss 996 -> 55 (KCP 61); 40 KB at 2% loss
1183 -> 20 (KCP 39).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019aokqJuhjvB3kijXtAg5Ns
2026-09-05 15:04:43 +08:00
rustdesk
810b7aef76 webrtc: send over SCTP without a congestion window, as KCP does
The same link that streams over KCP crawls over WebRTC. webrtc-sctp runs
RFC 4960's AIMD: a fast retransmit halves cwnd, a T3 drops it to one MTU, and
slow start only rebuilds it while data is queued behind it. Where the loss is
random rather than congestion - a lossy long-haul link - the rate settles at
the Mathis ceiling MSS/(RTT*sqrt(p)) however idle the link is: about 1.3 Mbps
at 70ms RTT and 1% loss, 0.6 Mbps at 5%, while 1080p wants 2-5 Mbps. KCP's
turbo profile (nc=1) has no congestion window at all.

The fork now carries a switch that bypasses the two places gating sends on
cwnd, and hbb_common turns it on for every peer connection unless
`allow-webrtc-congestion-control` is set - the same opt-in KCP has in
`allow-kcp-congestion-control`, for the reason at `get_kcp_cc_enabled`.
Sender-side only; a browser or an older build on the other end interoperates.

Measured over a simulated link (35ms one-way, random loss both ways, 12 KB
frames at 30fps, 300 frames): at 1% loss the window stretches 9.9s of video to
20.7s with a mean latency of 5.5s; without it the stream stays realtime at a
mean of 113ms. At 3%: 47s and 15s against 10.2s and 290ms.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019aokqJuhjvB3kijXtAg5Ns
2026-09-05 15:04:43 +08:00
rustdesk
88d5172611 hbb_common: bump to the webrtc branch rebased on main
Picks up upstream's session-cache eviction by pc identity (#589, adopted without its
unused insert-path helper), the 90-day log retention, and the wlroots output fixes.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019aokqJuhjvB3kijXtAg5Ns
2026-09-05 15:04:43 +08:00
rustdesk
3a62d81573 tcp: repeat the punch across the controller's dial window
The single punch leaves before hbbs has told the controller where to dial, so
it is never in flight at the same time as the controller's SYN: it opens our
NAT, meets nothing, and a gateway that answers it with RST takes the mapping
down with it, leaving the listener waiting on a hole that no longer exists.

Punch again while the controller may still be dialing, and race those punches
against the accept. That is two ways in where there was one: the mapping is
rebuilt if a RST took it, and once the controller sits in SYN_SENT one of the
punches meets its SYN and completes as a simultaneous open - which a punch sent
before the controller had been told anything never could. The crossing reaches
the punch rather than the listener because the two sockets share the address
but only the punch matches the four-tuple, which the tests now pin down.

There is no instant to aim at, and no window either. `Client::connect` sizes
the controller's dial only after our PunchHoleSent, from its own rendezvous
time and the direct failures it has recorded for us: CONNECT_TIMEOUT between
two known-asymmetric NATs that never failed, punch_time_used times three or
six otherwise, floored at a second - so a peer that failed once dials for a
second or two from then on, and none of that reaches this side. The repeats
therefore cover our own ceiling instead, CONNECT_TIMEOUT, which is exactly as
long as the accept has always been willing to take a connection through the
hole, and back off across it: dense at the start, where every window begins
and the short ones end, sparse afterwards, which is `punch_udp`'s shape for
the same reason. A window past that ceiling was lost before this change too,
and mostly to the controller's own kernel - Windows gives a SYN up at 21s,
Linux's next re-send after 15s is at 31s; a window short of it costs a few
SYNs to a port already closed.

No punch is cut on a per-attempt timeout; one in flight is bounded only by
the shared deadline plus PUNCH_GRACE. A punch is cancel-safe only while it is
still in SYN_SENT; once the controller's SYN has crossed it the socket is half
way through a handshake, and cutting it there cuts the connection the
controller is opening - whose `connect` has already returned, so that attempt
fails outright, there being no relay fallback after a failed TCP handshake. A
timer cannot tell the two states apart, and none is needed: a gateway that
answers with RST fails the connect at once and the loop punches again, while
one that drops the SYN in silence leaves the socket in SYN_SENT, holding the
mapping open while the kernel re-sends, which any SYN of the controller's then
crosses - a second punch has nothing to add. The deadline decides whether
another punch starts; one in flight runs a grace past it, enough for a
crossing begun just before it to complete. The last sleep is cut at the
deadline rather than run out past it, so the window ends on a punch given
that grace and not on a gap of up to the backoff ceiling: the controller's
window opened after ours, on the PunchHoleSent hbbs relayed, so one as long
as ours is still open through our tail.

Only the accept races the punch, never `accept_connection`: that one does not
return until the session it goes on to run has ended, so racing it would tear a
live session down.

Whichever arrives first is the one connection the request produces. `meta`
carries the control permissions hbbs granted for this one controller, so
serving the loser as well would hand them to a second peer - and nothing about
a connection tells the two apart before `create_tcp_connection` has spoken to
it, least of all its address: a carrier NAT shares one between subscribers,
and a NAT that pools its external addresses may dial us from a different one
than hbbs saw the controller through. So the address is not checked, as
`accept_connection` never checked it; the handshake says who arrived, and what
holds the invariant is that there is no second serve. Those
permissions are a ceiling and not a grant either way: `Connection` gates every
message on `authorized`, and latches the login scope of the first request it
accepts, so a peer that reached the hole still arrives with nothing.

The accept loops rather than taking a single connection, so that a transient
accept error does not spend the window the controller still has to arrive in.

libp2p's DCUtR reaches the same place by having both peers dial at one instant
agreed over the relay. Nothing we send reaches the controller directly, so we
cover its dial window rather than name an instant inside it.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019aokqJuhjvB3kijXtAg5Ns
2026-09-05 15:04:43 +08:00
rustdesk
b6b4d4f036 webrtc: skip the controller's ICE re-send instead of queueing it twice
The controller sends every candidate twice, because the server's hop to a
peer registered over UDP can lose one. The ICE agent that dedups repeats
sits downstream of the answerer's queue, so the answerer paid for both
copies: a slot, a JSON parse, and the ICE agent's lock, once per repeat.

Remember a digest of what was queued and skip the repeat. Recorded only
once queued, so a candidate a full queue refused stays repairable by the
re-send.

The queue's depth is unchanged. A real peer gathers well under it - four
STUN servers, link-local IPv6 filtered, one component - and the drain
empties it as candidates trickle in, so what this removes is the redundant
work, not an overflow.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019aokqJuhjvB3kijXtAg5Ns
2026-09-05 15:04:43 +08:00
rustdesk
5f3a046188 webrtc: correct the RTT variance floor to dcsctp's scaling
The earlier commit took dcsctp's min_rtt_variance = 220 as a raw floor under
rttvar. dcsctp divides the option by kHeuristicVarianceAdjustment = 8.0 first,
a historical accident it kept because downstream users had measured good
values with it, so the intended floor is 27.5ms of variance contributing 110ms
to RTO. Flooring at 220 contributed 880ms instead, which on a 50ms path left
RTO within 7% of the 1000ms default this change exists to escape.

The fork also now records why T1/T2 share T3's RTO manager here, unlike
dcsctp's separate control timers: RTO_INITIAL is the T3 value for the first
DATA chunk, since no RTT sample exists before the first SACK.
2026-09-05 15:04:43 +08:00
rustdesk
188b02ed2f udp: make the punch prove itself, and keep the listener answering
punch_udp sent a zero-length datagram and called the hole open on whatever
arrived next. The rendezvous NAT test's own leftover replies satisfy that
immediately - connect() does not flush the receive queue - so the retry loop
never ran and success meant nothing. The dead socket then cost KCP its full
timeout to rediscover, which is how a failed punch came to take 18 seconds.

Probes now carry a magic and a 64-bit transaction id, and both ends answer
each other's probes, so returning is a fact: a reply echoing our own id is the
one thing that proves the pair carries traffic both ways. With failure now
distinguishable from 'not yet', the window drops from 20s to 3s.

Two asymmetries fall out of that:

Only the connector stops on its own acknowledgement, because only it has
something to send next. An acknowledgement proves our probe came back, not
that the peer's probe was answered - and after punch_udp returns nothing
answers probes any more, since KCP's io loop drops anything shorter than its
header. A listener that stopped there would go mute while a peer whose own
probe or answer was lost - the normal state of a hole still opening - kept
probing an endpoint that works, until it timed out.

So the listener stops on the peer's first real packet instead, and hands that
packet to KcpStream::accept as its init_packet: its arrival proves the pair as
well as an acknowledgement would, and KCP never retransmits its SYN.
2026-09-05 15:04:43 +08:00
rustdesk
90833ec315 webrtc: take dcsctp's retransmission timings and IPv6-safe MTU
webrtc-sctp ships RFC 4960's RTO.Initial/RTO.Min (3000/1000), TCP's values for
arbitrary public paths. On this workload they set the recovery time outright:
a request/response exchange keeps one chunk in flight, so no later SACK ever
raises miss_indicator to the 3 that arms fast retransmit, and the T3 floor is
the only way back. A single loss during a handshake or a first keyframe
therefore costs whole seconds.

The fork now carries dcsctp's numbers instead - the SCTP implementation Google
wrote to replace usrsctp for Chrome's WebRTC data channels, the same realtime
workload: rto_initial 500, rto_min 400, a 220ms floor under the RTT variance,
and mtu 1191. INITIAL_MTU 1228 plus DTLS/UDP/IPv6 overhead is 1313, past the
1280 minimum, so every full-size chunk fragmented on an IPv6 path.

Both patch entries move to the new branch, which also carries the Windows IPv6
byte-swap fix, so one rev matches the whole webrtc 0.13 stack.
2026-09-05 15:04:43 +08:00
rustdesk
a4f48e3631 bump hbb_common: one STUN list, and drop the dead IPv4 half
`test_ipv6` kept its own hand-written copy of the STUN servers. It now reads
`WebRTCStream::stun_servers()`, so an operator who points OPTION_ICE_SERVERS at their own
server gets it on both paths instead of one.

`test_bind_ipv6` sends nothing - `connect` only makes the kernel pick a route and a source
address - so the whole cost is DNS. It races the lookups rather than betting this host's
IPv6 support on whether the first entry happens to publish a AAAA where the user resolves
from; google's does not, from a Chinese resolver, and it was the entry being bet on.

`stun_ipv4_test`, `STUNS_V4` and `test_nat_ipv4` have had no callers since the punch stopped
taking its port from a second socket, and go.

`get_kcp_cc_enabled` reads the renamed option through `option2bool`, like every other one.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019UzcMTdYTEv2QbMHcTSUy3
2026-09-05 15:04:42 +08:00
rustdesk
18a8f9ac85 bump hbb_common: name the family a WebRTC session runs over
`stream_type` reaches the UI as the transport that won the race, and every other transport
already carries the family in that label - the v6 punch reports `IPv6`. WebRTC does not: one
label covers both families, and it is the one path whose real remote address can differ from
the rendezvous-observed one the session is identified by.

Refine it at the hand-off to the UI rather than at the source: five sites in client.rs
compare `typ == "WebRTC"`, so widening the label there would silently move control flow.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019UzcMTdYTEv2QbMHcTSUy3
2026-09-05 15:04:42 +08:00
rustdesk
5ff93aafb4 bump hbb_common: drop link-local IPv6 from ICE gathering
Also pin webrtc-util to a fork of 0.11.0 carrying a Windows IPv6 enumeration fix.
`ifaces` reads the adapter list's on-wire IPv6 bytes as host-order `[u16; 8]`, so on a
little-endian host every group comes out byte-swapped and unbindable: a peer's real
240e:369:9606:4600:f52a:7a8d:2530:4de0 is enumerated as e24:6903:696:46:2af5:8d7a:3025:e04d,
::1 as ::100 and fe80:: as 80fe::. Each fails to bind with WSAEADDRNOTAVAIL, so ICE gathers
no IPv6 host candidate at all on Windows - where a globally routable address is the one
NAT-free path a CGNAT'd peer has.

Never reported upstream; the unix twin of the same bug was fixed in webrtc-rs#475 (2023).
Fork: rustdesk-org/webrtc, branch rustdesk-patches, tag webrtc-util-0.11.0-win-ipv6.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019UzcMTdYTEv2QbMHcTSUy3
2026-09-05 15:04:42 +08:00
rustdesk
7712e66540 bump hbb_common: name the punch by every transport it carries
`get_local_endpoint_trickle` became `local_endpoint() -> &str`, which
cannot fail, so both call sites lose an unreachable error arm — the
mediator's closed a pc against a failure that no longer exists.

`punch_type` named one transport, and picked it off `allow_tcp_punch`.
A round carries several at once — a NAT port and a v6 address and an
offer — and since the TCP punch became a switch it can carry none, so
one name had to misreport both: the logs of the round that broke WebRTC
read "#1 UDP punch attempt" while the request also carried the v6
address and the offer that was actually failing, and a round with
nothing to punch with was labelled "WebRTC". List them instead —
"UDP+IPv6+WebRTC" — and call the empty round "Relay", which is what it
can still end as and what `typ` prints for it.

The offer is moved into the request rather than cloned into it; that
was its last use.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019UzcMTdYTEv2QbMHcTSUy3
2026-09-05 15:04:42 +08:00
rustdesk
44d4fb59b2 feat: make the TCP punch a user option, with TCP as the backstop
TCP punching was the one direct transport without a switch, while UDP,
IPv6 and WebRTC each had one. Add "Enable TCP hole punching" above the
UDP toggle on both desktop and mobile, default on — including on
self-hosted servers, since unlike the other three (whose default-off
there guards against an hbbs that cannot forward their fields) TCP
punching has always been supported by every server.

Turning all four off would leave no way to punch at all, so TCP runs
regardless in that case. That backstop keys off the switches alone: a
transport that is enabled but fails to materialize — no public v6
address, no NAT port, a failed offerer — is already covered by the
relay fallback for a round that ends up with no usable direct
transport. With the TCP punch off, the fallback request is skipped
too: it exists only to carry that punch, and would otherwise reach
connect() with nothing to try and merely open a second relay.

Known cost, unchanged behavior for the peer: the request carries no
field for this choice, so a peer that receives one with no udp_port and
no offer still punches a TCP hole and listens for a connection the
controller will not make. Representing the transport choice on the
wire needs a proto field and the server forwarding it.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016HV43uh1ztv6Wm5qi3Y1ne
2026-09-05 15:04:41 +08:00
rustdesk
14dc121d23 fix: give the UDP NAT test a real window when the TCP clock is faked
The punch request carries udp_port only if the rendezvous server's
TestNatResponse has arrived, and the wait for it was bounded by
rtt / 2 — half the TCP connect time, on the assumption that TCP and
UDP round trips are comparable and the test, started earlier, has
already answered.

A transparent TCP proxy breaks that assumption: a TUN-mode VPN on the
host, or a redirect-mode proxy on the LAN gateway serving every device
behind it, completes the handshake locally in ~3ms while the real UDP
round trip is hundreds of ms. Log-confirmed against 5.161.65.208: ping
341ms, TCP connect 3.7ms, connect to a dead port there "succeeds" just
as fast. The window collapsed to ~1.5ms, udp_port stayed 0 on every
attempt, and UDP punch was never even requested — although UDP itself
passes such gateways untouched.

So use the TCP clock only when it is believable: below a plausible WAN
round trip it says nothing about the UDP path, and a flat ceiling
applies instead. The loop still exits the moment the port arrives, so
a genuinely nearby server pays nothing and only a UDP-dead network
waits out the ceiling — on the udp-carrying round alone, while the
parallel pure-TCP round is unaffected.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016HV43uh1ztv6Wm5qi3Y1ne
2026-09-05 15:04:41 +08:00
rustdesk
8148795f19 bump hbb_common: WebRTC peer connections own their I/O runtime
Closing the controlling window left the controlled side waiting out
ICE decay — ~25-30s in the peer's log, its disconnected/failed ladder
running to completion — where TCP delivers a FIN at once. The session
end closed the pc by spawning onto io_loop's own
`#[tokio::main(flavor = "current_thread")]` runtime, which is dropped
the moment io_loop returns, and nothing after that call yields: the
task was never polled even once, so no DTLS close_notify ever left.

Every attempt to fix that on the caller's side failed the same way,
because the mismatch was never about where the close ran: a pc's UDP
sockets register with the reactor, and its ICE/DTLS/SCTP pumps spawn
on the runtime, that is current while it is built — so a pc created
by a session outlives the only runtime that can drive its I/O, and a
close driven anywhere else completes without reaching the wire.

The bump homes them where they can outlive any caller: WebRTCStream
builds on a process-lifetime runtime and every detached close runs
there as its own never-cancelled task. io_loop keeps its plain
close_webrtc() calls and only documents why nothing here may spawn or
await the teardown on the dying session runtime.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016HV43uh1ztv6Wm5qi3Y1ne
2026-09-05 15:04:41 +08:00
rustdesk
a35630b499 webrtc: fix race edge cases that discard or mislabel a direct connection
Three correctness fixes in the transport race, plus three convention
cleanups.

- race_transports_prefer_webrtc committed a relayed result while a direct
  attempt was still in flight: the others arm returned on
  webrtc_fut.is_none() even with an unfinished direct future, and the
  WebRTC-error arm returned a held relay without checking others_fut. A
  relay is now committed only when nothing direct can still arrive (or
  the window expires); a parked relay is also preferred over composing
  an error when both sides fail. Three regression tests, mutation-checked.

- connect()'s plain select_ok let a TURN-relayed WebRTC win as "first
  success", dropping still-racing UDP/IPv6 direct attempts and reporting
  the relayed pair as direct. It now runs through the same prefer-P2P
  race with each attempt carrying whether its path is direct, and the
  WebRTC future resolves is_relayed() so a TURN win is held behind
  direct attempts, not committed as one.

- The RelayResponse path kept direct == true when a WebRTC win's DTLS
  handshake failed and it fell back to relay, so the relay was reported
  P2P. Clear the flag with the transport switch.

- Trim the OffererGuard doc to the three-line max; move the new
  enable-webrtc localization key to the end of every lang list; the KCP
  option constant moved to hbb_common config::keys (0f663aa).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ExUfAkYbq8UC9pQCiLy8TQ
2026-09-05 15:04:41 +08:00
rustdesk
cbec70cd6a webrtc: trim the comments to AGENTS.md length; drop is_direct_transport
386 added comment lines down to 287 across client, mediator, kcp_stream
and common. Same rule as hbb_common 3d64e43: out go past-bug narration,
rejected alternatives, measurements and restatements of the code; the
non-derivable why stays.

is_direct_transport goes with them. Judging the race by a transport
label was replaced by the resolved direct flag, leaving it used only by
its own test — and, having been inserted between the doc comment and
race_transports_prefer_webrtc, it had also taken that function's
contract with it. Removing it reattaches the doc where it belongs.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ExUfAkYbq8UC9pQCiLy8TQ
2026-09-05 15:04:13 +08:00
rustdesk
ccf9afd069 webrtc: judge the race by the resolved path, not the label; bound the ICE queue
Third review round. Two of these are regressions from the previous one.

- The RelayResponse race predicate was `is_direct_transport(result.2)`,
  which answers true for the label "WebRTC" - but WebRTC is only a
  direct path when ICE nominated a non-TURN pair. A TURN-relayed WebRTC
  result therefore committed instantly and cancelled the IPv6 attempt
  racing beside it, which is the same inversion the previous fix removed
  in the other direction. (That fix was also argued from a wrong premise:
  the site does carry an IPv6 future, pushed ~50 lines earlier than the
  relay one.) Each future now resolves whether its path is direct and
  the predicate reads that bool, matching the outer race, and the
  downstream recomputation goes away.

- policy_relay still folded in Config::is_proxy(), and that is what gets
  persisted into the peer's config as force-always-relay - so one
  session through a proxy pinned the peer to relay forever and disabled
  WebRTC for it, exactly the latch the previous round fixed for
  WebSocket. Split out peer_relay: the saved option or an explicit
  request for THIS peer, and the only part written back.

- The controlled side buffered remote ICE candidates in an unbounded
  channel while the controller caps the same buffer at 64, and draining
  one costs a JSON parse plus the ICE agent's lock. Whoever can reach a
  session's route could grow it without limit inside the long-lived
  service process. Bounded, with the overflow logged through the
  existing throttle.

- That route was also removed by key alone when an answerer finished, so
  a punch retry that built a fresh answerer under the same fingerprint
  had its live sender deleted by the previous one's cleanup - after
  which it received no candidates at all. Evict only our own sender, the
  way the session cache already guards the analogous case.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ExUfAkYbq8UC9pQCiLy8TQ
2026-09-05 15:04:13 +08:00
rustdesk
ea7407b73b scrap/benchmark: give the Duration divisor an explicit u32
The webrtc feature pulls time 0.3 into scrap's graph (hbb_common ->
webrtc -> webrtc-dtls -> der-parser -> asn1-rs), and that crate carries
an `impl Div<time::Duration> for std::time::Duration`. Orphan rules
allow it because the RHS is its own type, and trait impls are visible
across the whole dependency graph without a use, so std::time::Duration
now has two Div candidates. `yuv_count as _` casts to a plain inference
variable, which both candidates fit, so it stops resolving:

  error[E0282]: type annotations needed
    --> libs/scrap/examples/benchmark.rs:146:33

Only two of the four sites are reported - rustc emits one E0282 per
function body - so all four are annotated. The already-explicit
`as u32` at the hwcodec site and `start.elapsed() / cnt` are unaffected,
the latter because an integer literal's variable can only unify with an
integral type and rules the time impl out on its own.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-05 15:04:13 +08:00
rustdesk
7fe4d186e5 webrtc: close without an await point; do not report an unknown path as direct
- close_webrtc is no longer async (hbb_common 88f965f), so the ten call
  sites in port_forward and io_loop - all inside select! arms or futures
  the UI can abandon - can no longer be cancelled mid-teardown, which
  left the pc unclosable and its session entry stranded. Client's own
  spawn_close_webrtc went with it: the runtime-teardown guard it existed
  for now lives in close_detached, so both Drop paths share one
  implementation.

- webrtc_relayed() returns None when no candidate pair is selected or
  the pc closed under a concurrent teardown, and both call sites read
  that as "not relayed", i.e. direct. A TURN-relayed session could
  therefore be shown to the user as peer-to-peer. Claiming a direct path
  needs evidence of one, so an unknown answer now counts as relayed.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ExUfAkYbq8UC9pQCiLy8TQ
2026-09-05 15:04:13 +08:00
rustdesk
d60577e80d fix three ways ws + WebRTC could not work in practice
Review of #15684 and hbb_common#579. Each of these left the code reading
correct while the feature did not function.

- The RelayResponse race classified P2P with `result.2 == "IPv6"`, but
  that site's futures are only ever the relay ("Relay"/"WebSocket") and
  the WebRTC branch's own "WebRTC" — so the predicate was constantly
  false. When the relay landed first the result was still right (the
  webrtc arm's `others_fut.is_none()` fallback), but when WebRTC
  connected FIRST it was parked as if it were a relay and the relay was
  committed on arrival, discarding a live direct connection. That is the
  LAN case: the better the network, the worse the outcome. Classify by
  what the label means, via is_direct_transport, and test both orderings
  — only the relay-first one was covered.

- handle_peer_info wrote "force-always-relay=Y" into the peer's saved
  config whenever force_relay was set, which now includes the WebSocket
  transport. One ws session therefore turned the peer into a permanent
  relay-by-policy peer, and relay-by-policy means Relay-only ICE, so
  WebRTC could never go direct to it again — the flagship path worked
  exactly once. Persist policy_relay, which is the user's choice; the
  transport is a property of this client, not of the peer.

- The answerer gated on this machine's enable-webrtc option, but that is
  LocalConfig: the UI process writes it and never syncs it over IPC,
  while handle_punch_hole runs in the server process, which on Windows
  resolves LocalConfig under a different profile and reads the
  private-server default of "N". The gate refused to answer in exactly
  the self-hosted deployments the transport exists for. Drop it: the
  answerer follows the request, like the udp/ipv6 legs, and the option
  still gates the feature where it can — an offer only exists because
  some controller had it enabled.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ExUfAkYbq8UC9pQCiLy8TQ
2026-09-05 15:04:13 +08:00
rustdesk
704f7495b9 android: define getifaddrs/freeifaddrs for the api-21 sysroot
Turning on hbb_common's "webrtc" feature pulls webrtc-util into the android
link, and its ifaces() -- reached from vnet::Net::new() on every ICE gather --
calls getifaddrs(). bionic exports getifaddrs/freeifaddrs only from API 24,
while flutter/ndk_*.sh builds against --platform 21, so every abi failed to
link on the undefined symbols.

Raising the platform to 24 would have to drag minSdkVersion 22 with it and
turn the link error into a load-time one on Android 5.1/6.0, so define the
two symbols instead, using the RTM_GETLINK + RTM_GETADDR netlink dump bionic
itself uses. The definition also shadows bionic's on API >= 24 rather than
delegating to it, so the path that ships is the path every test device runs.

Checked against synthesised netlink dumps on the host -- link/address parsing,
prefix masks, point-to-point, ipv6 scope ids, malformed and truncated messages
-- under UBSan and byte-exact guard malloc, with a deliberately unsigned
remainder as the negative control.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-05 15:04:13 +08:00
rustdesk
3f5ce9acae kcp: make the congestion-control profile opt-in, not the default
The branch had flipped KCP to nc=0 (built-in congestion window) for
every session. That is a transport-behavior change for all users made on
reasoning alone, and the reasoning does not decide it: which profile wins
depends on why packets are being lost.

nc=1 - what RustDesk has always shipped - never shrinks the send window,
so on a genuinely congested uplink it deepens the loss it is reacting to.
But nc=0's backoff is blunt: a fast retransmit halves the window while an
RTO sets cwnd = 1 outright (ikcp.c) and recovery slow-starts from one
packet, so on a link with random loss and no congestion - Wi-Fi
interference, a long-haul path - it reads loss as congestion and can
stall an interactive stream for seconds. That failure mode is also the
more visible one to a remote-desktop user.

No benchmark settles this either: a loopback A/B has no bottleneck queue,
hence no congestion to control, and would flatter nc=1 by construction.
Deciding it needs a shaped link or field data.

So keep the profile users already run and let the other one be asked for
("enable-kcp-congestion-control" = "Y"). Flipping the default later is a
one-line change once there is evidence. kcp-sys keeps its own test
covering the nc=0 path.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ExUfAkYbq8UC9pQCiLy8TQ
2026-09-05 15:04:13 +08:00
rustdesk
b962063f03 ipc/auth: replace the local throttle with the shared throttled_log!
auth.rs predated hbb_common's LogThrottle and grew its own equivalent:
same shape (last_log_at + suppressed), same 5s interval, plus a helper
and three OnceLock<Mutex<..>> statics. It also counted the other way -
excluding the event being reported - so each of the three sites carried
two near-identical log::warn! arms to avoid printing "suppressed 0".

The shared macro covers all of it: one static per call site declared by
the expansion, and the multiplicity suffix appears only when there is
one, which is what those duplicated arms were for. 102 lines out, 27 in.

Behavior difference, deliberate: a burst now reads "(x47)" - the total
including this line - instead of "(suppressed 46 similar events)". One
number, no arithmetic, and one convention across the codebase.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ExUfAkYbq8UC9pQCiLy8TQ
2026-09-05 15:04:13 +08:00
rustdesk
06a7cc9239 kcp: client-side integration tests over real loopback sockets
kcp-sys has been through two review rounds of behavioral fixes; the
client wrapper (kcp_io pumps, connect/accept deadlines, framed-stream
adaptation, guard lifetimes) had no tests pinning what rustdesk actually
relies on. Four now do, each through real 127.0.0.1 UDP sockets and the
BytesCodec framing sessions use:

- handshake + bidirectional framed roundtrip + graceful close: the peer
  observes end-of-stream instead of hanging (guard outlives the framed
  stream so the FIN goes out);
- a writer that queues 50 frames and closes immediately loses none of
  them - the client-side pin for the close-tail-drain semantics;
- socket errors after the peer vanishes are treated as loss: writes keep
  succeeding, nothing tears down (ICMP is advisory on connected UDP);
- the connect deadline holds when nothing answers.

Mutation-checked: dropping inbound forwarding in kcp_io reddens exactly
the three tests that need the pump, and the timeout test alone stays
green.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ExUfAkYbq8UC9pQCiLy8TQ
2026-09-05 15:04:13 +08:00
rustdesk
5618e984b6 add enable-webrtc option; gate test_ipv6 under forced relay
OPTION_ENABLE_WEBRTC (hbb_common 48c2d4d) follows the udp/ipv6 punch
options end to end: default on against the public server, off against
private ones, same settings UI placement on desktop and mobile, and the
same bool2option local-option handling. Gates:

- controller: should_create_webrtc_offerer checks it first — no pc, no
  STUN/TURN gathering, no offer in the request;
- controlled: unlike the udp/ipv6 legs, which deliberately follow the
  request, answering builds a pc that gathers ICE from this host, so
  the answerer honors this machine's own switch too.

Translations for "Enable WebRTC P2P connection" added to all 50 lang
files next to the IPv6 entry (IPv6 and WebRTC are invariant terms in
the same grammatical slot in every one of them).

Also stop probing v6 reachability (test_ipv6) under any forced relay:
the v6 punch socket is never bound there, so the probe was wasted work
on every ws/proxy/relay connection.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ExUfAkYbq8UC9pQCiLy8TQ
2026-09-05 15:04:12 +08:00
rustdesk
578a95289f ws: read the all-ICE declaration from the offer envelope, drop the proto field
Companion to hbb_common 68d2729: the full-ICE declaration now lives as
an `ice_policy: "all"` key inside the webrtc:// envelope, so the request
assembly no longer sets webrtc_all_ice and the controlled side asks the
envelope (endpoint_declares_all_ice) instead of a PunchHole field. The
rendezvous server carries the offer opaquely — no forwarding to keep in
sync. Skew behavior is unchanged: an unmarked or unparseable envelope
reads as the old Relay-only semantics.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ExUfAkYbq8UC9pQCiLy8TQ
2026-09-05 15:04:12 +08:00
rustdesk
22c4e080bb bump kcp-sys: 7 review fixes on rustdesk-patches (fa51c15 -> 023a006)
Reverts the connect/accept/add_conn changes that regressed concurrent
connects (the state_map guard held across add_conn is load-bearing), states
the single-conn contract on KcpEndpoint so shared-endpoint behaviour stops
consuming review effort, pins the two invariants that keep truncated input
from aborting under panic='abort', and fixes three findings from external
review: sendwnd() echoing raw config instead of KCP's effective window (a
non-positive factory value stalled sending forever), the passive closer's
lost final FIN delaying EOF by up to ~20s, and the doubled window
overflowing for extreme factory values.

Lock-only change: cargo update -p kcp-sys also re-picked libloading's
windows-targets between two versions already present in the lock; that was
reverted to keep this commit to the one line it is about. cargo metadata
--locked passes on the result.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-05 15:04:12 +08:00
rustdesk
585d1fb3ca ws: decouple ICE policy from force_relay — full-ICE WebRTC over WebSocket
WebSocket support folds into force_relay because a ws tunnel kills
classic TCP/UDP punching — but that conflated transport necessity with
relay policy, and the WebRTC decisions keyed off the merged flag: a ws
client built no offerer at all without TURN, and only a Relay-only-ICE
one with it. ws deployments could never reach a direct WebRTC
connection, which is exactly the path they are supposed to live on.

Split the flag. LoginConfigHandler now tracks policy_relay (the
force-always-relay option, an explicit relay request — /r ids and
retry-via-relay included — and proxy) separately; force_relay stays
policy_relay || use_ws() and keeps governing the classic paths, so
non-ws behavior is unchanged everywhere:

- the offerer's existence and ICE policy follow policy_relay: under
  pure ws the offer gathers every candidate type and may go direct;
  under relay-by-policy it stays Relay-only ICE, TURN-gated, exactly
  as before;
- the RelayResponse race applies the prefer-P2P window under ws (a
  direct ICE path is worth delaying an already-ready relay for) while
  policy relay keeps first-success semantics;
- the request carries webrtc_all_ice (hbb_common 64b54ab) so the
  controlled side knows the offer is full-ICE: it answers with full ICE
  and no TURN requirement, while offers without the bit keep today's
  relay-only answer path on every version-skew combination.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ExUfAkYbq8UC9pQCiLy8TQ
2026-09-05 15:04:12 +08:00
rustdesk
c313d6dc1c bump kcp-sys: 14 review fixes on rustdesk-patches (6e44b93 -> fa51c15)
Picks up the handshake-recovery work plus the review round on top of it:
ABBA deadlock between the endpoint's two DashMaps, graceful-close tail
truncation, mid-stream hole on ikcp_send failure, FIN retransmission for
lost-FIN half-open hangs, SYN-ACK budget burned on dropped packets,
spurious ConnectTimeout after a completed handshake, accept-backlog
overflow stranding conns, aliasing UB in the output callback, and the
log-facade/throttling cleanup (per-packet sites no longer reach the
debug-level file logger, peer-rate warns throttled).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ExUfAkYbq8UC9pQCiLy8TQ
2026-09-05 15:04:12 +08:00
rustdesk
fa399e01ad fix: the KCP io throttle reset itself every cycle, so it never throttled
The send and recv arms shared one counter, and an ICMP error on a connected
socket is reported once and then cleared — so the steady state is an
alternation: the send succeeds and clears the counter, the next recv reports
the error and finds the counter at 1, and logs. Every error still wrote a
line, at the ~100/s the previous commit set out to stop, while the
persistent-failure and recovery branches were unreachable.

Use one LogThrottle per direction instead of a hand-rolled counter. That
removes the shared state the bug lived in, drops a third throttling mechanism
in favour of the one already added, and leaves the surrounding `if let Err`
untouched rather than reshaping it into a match.

Also fix test_udp_uat's socket-error arm, the untreated twin of the punch_udp
site: it had no backoff at all, so a persistent error re-armed recv
immediately and spun the loop at CPU speed, one warn line per iteration.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ExUfAkYbq8UC9pQCiLy8TQ
2026-09-05 15:04:12 +08:00
rustdesk
324b58e04e fix: bound log volume on sites whose rate a peer or retry loop controls
Debug output goes to the log file, so a site that fires per received message
or per retry lets someone else decide how much a machine writes to disk. The
WebRTC work added the first such sites.

- KCP io loop: absorbing ICMP errors as packet loss made a broken socket write
  ~100 lines a second for the 60s until the pong timeout reaps it. Log by run
  instead: one line when a run starts, one per ~5s while it persists so a stuck
  socket stays visible, and one on recovery with the total.
- punch_udp: the recv error retries every 10ms for up to MAX_TIME, so one line
  per occurrence wrote thousands per punch. Log the first, report the count in
  the timeout message.
- ICE candidate paths (client, mediator): the peer sets the candidate rate and
  the rendezvous route carrying them needs no prior punch, so throttle to one
  line a minute each with the suppressed count.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ExUfAkYbq8UC9pQCiLy8TQ
2026-09-05 15:04:12 +08:00
rustdesk
8ad7c257cf fix: evict the oldest pending ICE candidate, not the newest
Candidates arrive in gathering order — host, then srflx, then relay — so a
full buffer was discarding exactly the ones that traverse NAT while keeping
host ones that only work on a shared LAN. Evict from the front instead.

Also document why the controller's ICE bridge must not reconnect on error, in
contrast to the controlled side's per-candidate retry: its socket address is
the return route itself (mangled into PunchHole.socket_addr, echoed back in
IceCandidate.socket_addr, resolved through tcp_punch), so a reconnect would
arrive from an address no route points at, and the server drops the old entry
when the connection closes. Once it dies both directions are dead, and
abandoning WebRTC is the correct response rather than retrying.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ExUfAkYbq8UC9pQCiLy8TQ
2026-09-05 15:04:11 +08:00
rustdesk
d5cf646db3 fix: don't let the preferred branch's own relay preempt a direct fallback
race_transports_prefer_webrtc committed any success from its first argument
outright, on the assumption that it is the WebRTC connect. It is not: the call
site passes a whole punch attempt, which internally falls back to request_relay
when its direct transports fail. That relay was therefore committed instantly
while the offer-less fallback's TCP punch was still in flight — inverting the
preference this function exists to enforce, since the is_p2p predicate the
caller already supplies was applied only to the `others` branch.

Apply it to both branches: a direct result from either side still commits
immediately, and a relayed result from either side is held for the window so
the other side can land something direct. Also commit a held connection when
the surviving branch errors, which the previous code only did on the first
branch's failure path.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ExUfAkYbq8UC9pQCiLy8TQ
2026-09-05 15:04:11 +08:00
rustdesk
3ca5465689 fix: carry switch_code through WebRTC relay fallbacks after rebase
The rebase onto master (switch-code feature) added an 8th request_relay
parameter; pass the interface's switch code from both WebRTC->relay
fallback paths so a role-swap session survives the fallback. Also drop
a duplicate bindgen 0.72.1 entry the Cargo.lock merge produced.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ExUfAkYbq8UC9pQCiLy8TQ
2026-09-05 15:04:11 +08:00
rustdesk
872ec56602 fix: KCP/UDP resilience to ICMP resets; optional KCP congestion control
- treat ICMP-driven UDP socket errors (WSAECONNRESET 10054 on Windows,
  ECONNREFUSED on Linux) as packet loss in punch_udp and the KCP pump
  instead of tearing the session down; KCP retransmits through them and a
  truly dead link is still reaped by the pong/app-level timeouts
- resolve STUN hostnames via tokio::net::lookup_host so DNS never blocks a
  runtime worker; fix the inverted non-IPv4 error message
- add enable-kcp-congestion-control option (default on): switch the turbo
  profile to nc=0 so brief loss on constrained links no longer spirals into
  stalls; sender-side only, no wire negotiation
- pin kcp-sys to the rustdesk-patches branch: upstream main lost the
  RustDesk patches on the EasyTier sync, and this branch also wires
  set_kcp_config_factory into connection setup, making the option effective

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-09-05 15:04:11 +08:00
rustdesk
9b986be5a0 feat: decouple WebRTC from UDP punch, route controlled signaling over TCP
- the WebRTC offer now rides any punch request; only an offer-less request
  may close and reuse the rendezvous socket for TCP punching
  (request_allows_tcp_punch replaces the udp_port-based invariant), with a
  separate offer-less request racing as the TCP fallback
- WebSocket mode no longer disables WebRTC — ws only tunnels the
  signaling/relay legs while ICE stays the only P2P path there; SOCKS proxy
  still disables it (ICE would bypass the proxy and leak the real IP)
- controlled side: WebRTC-only punch replies and trickled ICE candidates go
  over dedicated TCP connections to the rendezvous server instead of the UDP
  mediator channel, for ws/TCP-only hbbs deployments; drop the now-redundant
  rz_sender plumbing and the 400ms candidate re-send on that leg
- guard is_udp handling against responses to requests that advertised no
  udp_port; skip the IPv6 socket bind under force-relay
- test_udp_uat: drop the STUN port race — the punch port must come from the
  rendezvous server's TestNatResponse observing this socket's mapping, a
  STUN probe from another socket can advertise an unreachable port
- bump hbb_common (webrtc 0.13 MSRV pin rationale + upgrade checklist docs)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-09-05 15:04:11 +08:00
rustdesk
4dfef0e632 fix: preserve WebRTC transport preference 2026-09-05 15:04:11 +08:00
rustdesk
20d5fd8c58 feat: WebRTC transport racing, DTLS identity binding, and pc-leak fixes
- prefer-P2P racing (race_transports_prefer_webrtc) across punch and RelayResponse; ICE bridge with 400ms candidate resend
- controlled-side answerer and ICE routing; sign local DTLS fingerprint into SignedId, controller verifies the binding fail-closed
- fix pc leaks: close_webrtc() on insecure-decline paths (io_loop, port_forward); compute direct before disarming the offerer guard
- point hbb_common to the WebRTC data-plane commit 9f5a296

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-09-05 15:04:11 +08:00
rustdesk
f9ecc48b2e fix: route WebRTC ICE through rendezvous paths 2026-09-05 15:04:11 +08:00
rustdesk
b7f6789a8c feat: race WebRTC as a direct transport enhancement 2026-09-05 15:04:11 +08:00
rustdesk
64c2ad4d5a feat: route WebRTC ICE on controlled side 2026-09-05 15:04:11 +08:00
rustdesk
a4491c7ad1 feat: add rendezvous WebRTC signaling fields 2026-09-05 15:04:11 +08:00
RustDesk
3fc11c0f81 port forward shared conn (#16062)
* hbb_common: bump to the port-forward-mux proto

Also latches PortForward.multiplex into login_scope_digest, which
destructures PortForward's fields exhaustively by design (a new field
must be latched or deliberately ignored to compile).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EZ49AbZJYfm8NTp5yDPMab

* port_forward_mux: window accounting and channel frame builders

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EZ49AbZJYfm8NTp5yDPMab

* port_forward_mux: fix RecvWindow counter overflow on long transfers

Replace cumulative accounting (granted/received) with remaining credit
tracking to prevent u32 overflow after 4 GiB of data on a single channel.
Wire behavior is identical, but the fix allows large file transfers
without mid-stream channel closure.

Add regression test for 8 GiB transfer to verify fix.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EZ49AbZJYfm8NTp5yDPMab

* port_forward_mux: credit-windowed relay halves and channel coordinator

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EZ49AbZJYfm8NTp5yDPMab

* server: PortForwardMux channel table and per-channel tasks

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EZ49AbZJYfm8NTp5yDPMab

* server: multiplexed port-forward connections stay in the protobuf loop

Wire PortForwardMux into Connection: take the multiplexed path at login
when the controller sets PortForward.multiplex, route
PortForwardChannel frames to it from on_message, sweep the channel
table's targets after open/close, and clean it up on connection close.

Introduce is_port_forward() (socket-based or multiplexed) and use it
at the four sites that classify the connection, so a multiplexed
connection stays in the message loop, gets TestDelay keepalives, and
reports features.port_forward_mux in PeerInfo. The three sites that
break into the raw pipe loop or gate the keepalive still check
port_forward_socket specifically, since a multiplexed connection must
not take that path.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EZ49AbZJYfm8NTp5yDPMab

* cm: update a port-forward row's targets as tunnel channels come and go

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EZ49AbZJYfm8NTp5yDPMab

* port_forward_mux: controller tunnel with a single-writer stream loop

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EZ49AbZJYfm8NTp5yDPMab

* port_forward_mux: publish Muxed before spawning the tunnel loop

Publishing after spawn let a loop that dies immediately reset the state
first, so the later publish pinned it at Muxed with a dead handle
forever. Also adds a test pinning open-before-data ordering across many
concurrently opened channels, and drops an unused Clone derive.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EZ49AbZJYfm8NTp5yDPMab

* port forward: share one multiplexed tunnel across a window's listeners

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EZ49AbZJYfm8NTp5yDPMab

* port forward: fix round 1 review findings

Drop the mux default-false assignment now that definite-assignment proves
every path that reads it has set it; the enable-port-forward-mux config
commit picks up the missing attribution trailers; the default-on test
pins the enable- prefix itself rather than option2bool's weaker fallback.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EZ49AbZJYfm8NTp5yDPMab

* port_forward_mux: end-to-end tests over a loopback tunnel

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EZ49AbZJYfm8NTp5yDPMab

* port_forward_mux: fix bulk test's premature half-close, pin the half-close limitation

many_channels_echo_concurrently_and_a_bulk_one_does_not_starve_them dropped
its bulk write half as soon as writing finished, which shuts down the write
side of the socket and, by design (see the design doc's TCP half-close
non-goal; today's run_forward does the same), ends the whole channel. Keep
the write half alive until the reader is done so the test measures
starvation, not half-close. Add a_local_half_close_ends_the_whole_channel to
pin that limitation in code.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EZ49AbZJYfm8NTp5yDPMab

* port_forward_mux: cap send credit and other final review fixes

Fix 1 (critical): clamp SendCredit to MAX_SEND_CREDIT (= CHANNEL_WINDOW)
in both new() and add(), so a peer with tunnel permission can no longer
advertise an unbounded window and force the controlled side's unbounded
FrameSink::Direct sink to buffer unlimited target data per channel.

Fix 2: rename the "starve" test to many_channels_echo_concurrently and
drop its (untrue) starvation claim, since it opens every channel before
the bulk transfer starts. Add a_channel_opened_during_a_bulk_transfer_
is_served_promptly, which opens the small channel while the bulk one is
demonstrably mid-flight.

Fix 3: only look up the tunnel permission for `open` frames in the
PortForwardChannel arm of on_message, instead of once per data frame.

Fix 4: two rustfmt deviations in connection.rs (matches! wrapping and a
tuple literal), fixed by hand without a blanket cargo fmt run.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EZ49AbZJYfm8NTp5yDPMab

* port_forward_mux: report a refused channel's reason as an error dialog

The controlled side already answers a refused port-forward channel with
opened { success: false, message }; on the multiplexed path TunnelHandle::
on_frame only logged that message at debug and closed the channel, so the
user saw a closed connection with no explanation, worst on the RDP path
where only the RDP client's own error remained. on_frame now returns the
message the window should show, deduplicated per distinct reason (capped
at MAX_REPORTED_OPEN_ERRORS) so one page load's dozen refused connections
surface one dialog per reason instead of a dozen.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EZ49AbZJYfm8NTp5yDPMab

* Use on_error for refused-channel dialog in tunnel_loop

Redirect the refused-channel error through the standard on_error path
instead of calling msgbox directly, for consistency with other errors
in the port-forward flow.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EZ49AbZJYfm8NTp5yDPMab

* port forward: apply the whole-branch review

Correctness:
- listen(): the Legacy arm is merged with the Claimed arm. On its own it
  ignored outcome.local_eof, so a client that hung up during login still
  got a target connect, an audit record and a CM row on the controlled
  side, and ignored outcome.mux, so a peer upgraded while a legacy window
  stayed open answered as a tunnel while the controller went raw.
- Refusal dialogs are deduplicated per quiet spell (10 s) rather than per
  tunnel lifetime; the lifetime set went silent for the rest of a
  long-lived window after the first burst.
- Android's CM listener handles UpdatePortForward; it fell into `_ => {}`.
- relay_socket_to_tunnel reads into one scratch buffer per channel and
  sends an exact-size copy. A frame owning its 64 KiB read allocation
  pinned it until sent, once per byte on interactive traffic.

Consistency and cleanups:
- The controlled side's refusal text is the raw pipe's wording, RDP
  substitution included.
- connection.rs: the PortForwardChannel arm is a one-line hook, the CM
  label is pushed from the 1 s tick alone, and the unreachable inner.tx
  fall-through is gone.
- The Ready enum is removed; wait_ready() returns Option<Claim>.
- SendCredit::add wakes with notify_one alone.
- on_ui_command() replaces the two ui_receiver handlers in listen().
- TunnelHandle is no longer re-exported (unused-import warning).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EZ49AbZJYfm8NTp5yDPMab

* port forward: a legacy window stays legacy until it is reopened

Review: the merged `Claimed | Legacy` arm gave a legacy window a hot
transition to a tunnel — every accept re-negotiated, and a peer upgraded
while the window stayed open was promoted underneath live connections.
The product does not need a mode switch inside a window's lifetime, and
the transition was extra state-machine surface for nothing: reopening
the window picks up an upgraded peer.

The two arms are separate again. `Claimed` negotiates once and the
peer's answer fixes the window's mode. `Legacy` logs in for every accept
as before, asks for no tunnel — `LoginConfigHandler::port_forward_mux`
carries the request per login, so the raw pipe never has to talk to a
peer that thinks it agreed to multiplex — and ignores what the peer
reports. Both arms keep skipping a local socket that hung up during
login.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EZ49AbZJYfm8NTp5yDPMab

* hbb_common: bump to main with rustdesk/hbb_common#594 merged

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EZ49AbZJYfm8NTp5yDPMab

* server: admit only INITIAL_WINDOW on a channel before opened

The demultiplexer accepted CHANNEL_WINDOW into a pending channel's
unbounded queue, four times the bound the channel task enforces once
it polls. The window now starts at INITIAL_WINDOW and is widened right
before `opened` advertises the rest.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EZ49AbZJYfm8NTp5yDPMab

* port_forward_mux: a tunnel ends when its window drops the Tunnel

The loop held its own handle and state sender, so once the window
closed nothing was left to stop it: it kept answering TestDelay and the
peer connection, CM row included, lived on until the peer went away.
`Tunnel` now owns a watch sender nobody sends on; the loop's receiver
errors when the last `Tunnel` drops, and the loop ends.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EZ49AbZJYfm8NTp5yDPMab

* port forward: one tunnel per mapping, bound to the authenticated target

The login latches `PortForward.host`/`port` into the session scope and
approval is shown that target, but a window-wide tunnel let any later
`open` name another target with only `enable-tunnel` rechecked. A
tunnel now belongs to one listener and serves the one target its login
authenticated: the controlled side refuses an `open` for any other
target, and a window with several targets uses one connection each,
approved on its own.

With one owner per tunnel the claim needs no waiters: `Establishing`,
`Claim::Wait` and `wait_ready` go, and `try_claim` becomes a plain
read. The CM label that followed a tunnel's targets goes with them; a
row shows its mapping's target, as before.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EZ49AbZJYfm8NTp5yDPMab

* port forward: the legacy comment names the mapping, not the window

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EZ49AbZJYfm8NTp5yDPMab

* port_forward_mux: a window violation drops the channel on the spot

Both demultiplexers only queued a `Violation` and left the entry until
the channel task woke and exited, so a peer that kept sending past the
window queued one more entry per frame in the meantime, bounded by
nothing. The entry now goes the moment `accept` fails; later frames for
that id are unknown-channel noise.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EZ49AbZJYfm8NTp5yDPMab

* port forward: the login's target travels with the accept, not the handler

`listen()` wrote `lc.port_forward` (and, on this branch, `port_forward_mux`)
into the window's shared `LoginConfigHandler` before connecting, and
`create_login_msg` read them back only when the peer's `Hash` arrived.
Two mappings logging in at the same time could therefore swap targets:
on master that bridged a local socket to the wrong target, and with a
tunnel bound to its login's target it also left the mapping refusing
every later accept until it was recreated.

The target is now a `PortForward` carried by the interface clone that
handles one accept, passed explicitly down to `create_login_msg`; the
handler no longer has a field to race on. No lock spans the login.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EZ49AbZJYfm8NTp5yDPMab

* port_forward_mux: pin permission revocation and whole-tunnel failure in tests

Both already hold; the review asked for them to be stated. `enable-tunnel`
turned off mid-session refuses the next `open` while the live channel
keeps relaying, and a dead tunnel ends every channel on it together,
after which the next accept establishes again on the same `Tunnel`.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EZ49AbZJYfm8NTp5yDPMab

* port forward: the legacy comment names re-adding the mapping only

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EZ49AbZJYfm8NTp5yDPMab

* port forward: the raw pipe runs the code it always ran

The multiplexed login had replaced `connect_and_login`, so a mapping
with the setting off, a peer without the feature, or a listener latched
`Legacy` still went through the tunnel's state machine, the capped
pre-read and the changed local-EOF rule. Feature off now means the old
code: `listen()` keeps its accept arm and `connect_and_login` as they
were, and the tunnel is a branch taken only when the setting is on, in
`establish_tunnel` with its own `connect_and_login_mux`. The one line
the raw path does differently is the target riding with the accept's
interface clone instead of the shared handler.

`get_port_forward_mux_enabled` had one caller and moves in here, so
`common.rs` is untouched.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EZ49AbZJYfm8NTp5yDPMab

* port forward: a UI login answers the challenge its own connection was given

`handle_login_from_ui` hashed the typed password against `lc.hash`, the
window's shared handler field, and the window's password prompt is
broadcast to every listener. With two mappings both waiting on that
prompt, the `Hash` that arrived last had overwritten the other's, so
one of the two answered the wrong challenge and failed to log in.
Master shares the same state and broadcasts the same way.

The `Hash` is now a parameter of the login; `Session` keeps it beside
the connection it belongs to, and the per-accept clone that
`with_port_forward` makes gets a slot of its own. `lc.hash` stays for
`handle_peer_info`, which only needs the salt, and that is per peer.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EZ49AbZJYfm8NTp5yDPMab

* port forward: a mapping without its hash waits for it before answering the prompt

The window's password prompt is broadcast to every mapping, and can
reach one whose own connection has not received its `Hash` yet. That
mapping used to answer anyway, with a digest over an empty challenge:
the peer refused it and counted a failed attempt, and the empty-salt
result was written into the shared `lc.password`, where the mapping that
prompted had just stored the right one and the next `handle_peer_info`
would persist whatever was there.

The connection's challenge is now `Option<Hash>`, `None` until
`handle_hash` runs, and `handle_login_from_ui` sends nothing without it.
The mapping that prompted stores the salted password in the shared
handler, and the waiting one logs in with that against its own challenge
when its `Hash` arrives, without prompting again.

Test: A answers its prompt, the same broadcast reaches B before its
hash, B sends nothing, B's hash arrives and its login carries B's
challenge and B's target with no dialog. It runs the real `handle_hash`
for B.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EZ49AbZJYfm8NTp5yDPMab

* port forward: the tunnel's login is the raw pipe's, asked for by a window flag

Master's fix for the shared login slots (#16069) keeps the target and
the challenge in the window's `LoginConfigHandler` and serializes the
mappings' logins with a turn lock, all inside `port_forward.rs`. This
branch had carried a broader shape of the same fix, a `with_port_forward`
on `Interface` and the target and `Hash` as parameters through the login
functions, which every caller had to follow. That is gone: `Interface`,
`Session`, `create_login_msg`, `send_login`, `handle_hash` and
`handle_login_from_ui` are as on master.

What the tunnel needs on top is one bit in the login, `multiplex`. It is
a window flag beside `port_forward` in the handler, set once in `io_loop`
before the window's mappings start, so an accept's claim and its login
read the same value; the setting takes effect for windows opened after
it changes. `connect_and_login_mux` is now master's `connect_and_login`
with the tunnel's three differences and the same `hash_arrived` and
`login_from_ui` calls. The raw pipe is master's, line for line.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EZ49AbZJYfm8NTp5yDPMab

* hbb_common: bump to main with rustdesk/hbb_common#595 merged

840c8ec..f94e3fe is that one merge: the five local settings custom
clients could not preset.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EZ49AbZJYfm8NTp5yDPMab

* port forward: the off switch gets a checkbox in Settings → General

`enable-port-forward-mux` was readable only by editing the config file.
It is a local setting of the controlling side, so it sits with the other
outgoing ones, after "Open connection in new tab", with a tooltip saying
what it does.

The two new keys are translated in every language. The three that the
mobile file manager added, "Export", "Export Logs" and "Import Folder",
were empty everywhere but five languages; they are filled in too, and
Korean's "xdp-portal-unavailable" with them.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EZ49AbZJYfm8NTp5yDPMab

* Urdu: fill the backlog of empty and missing translations

ur.rs had fallen behind: 104 keys carried an empty value and 35 keys the
other languages have were absent altogether. Both are filled in, the
missing ones in the order template.rs lists them.

Eight entries stay empty on purpose. They are keys that only ur.rs still
carries, absent from template.rs and from every other language, so their
English source cannot be recovered and nothing reads them:
remember_account_tip, os_account_desk_tip, another_user_login_*_tip,
xorg_not_found_*_tip and no_desktop_*_tip. Twelve more dead keys keep
the values they have; removing either group is a separate decision.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EZ49AbZJYfm8NTp5yDPMab

* Urdu: drop the keys template.rs no longer lists

The twenty keys removed here are absent from template.rs and from every
other language file; ur.rs was the only one still carrying them, eight
of them with no value at all. They are leftovers of features that are
gone: the plugin menu, the OS-account login prompts, the Xorg and
no-desktop errors.

ur.rs now holds exactly the template's key set, all of it translated.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EZ49AbZJYfm8NTp5yDPMab

* port forward: closing the tunnel reaches channels parked on their socket

A channel whose far end neither reads nor writes has both relays parked
on the socket, not on the inbound queue, so `close_all` dropping the
queue's sender woke neither: the socket and both tasks lived on until
the far end hung up. Both sides now hold a per-tunnel teardown signal
that `run_channel` selects on beside its own cancel, and `close_all`
sends it after clearing the map.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EZ49AbZJYfm8NTp5yDPMab

* port forward: a mapping latched to the raw pipe logs in without asking for the tunnel

The login copied the window's `port_forward_mux` into `multiplex`, so a
mapping that had latched to the raw pipe on an old peer kept asking for
the tunnel. Once that peer was upgraded it answered with a tunnel while
the controller switched to raw framing, and every later connection on
the mapping was dead until it was re-added. The login now carries its
own `port_forward_multiplex`, filled with the target under the turn
lock: the probe asks, the raw pipe does not.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EZ49AbZJYfm8NTp5yDPMab

* port forward: a channel opened as its tunnel closes still gets the teardown

`open` can straddle `close_all`: the claim passed, the frame receiver was
still alive, and the channel subscribed after the signal had gone out.
`watch::subscribe` marks earlier sends as seen, and the entry sits in a
map that was already cleared, so nothing would ever end it. The signal is
now a level: `close_all` raises it with `send_replace`, which stores even
with no channel live, and `run_channel` waits for the value rather than
for a change.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EZ49AbZJYfm8NTp5yDPMab

* port forward: the connect guard counts a live tunnel as connected

`connect_port_forward_if_needed` returned early only for a raw-pipe
socket; called again with a tunnel up it would have built a second
`PortForwardMux` and dropped every channel of the first. Not reachable
today, since the logon response is sent once, but the other checks in
this change already read `is_port_forward()`.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EZ49AbZJYfm8NTp5yDPMab

* Urdu: the two terminal clipboard keys master added

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EZ49AbZJYfm8NTp5yDPMab

* port forward: a tunnel's TCP stream refuses packets over twice MAX_FRAME

The codec takes a header declaring up to 1 GiB and hands the packet up
only once it has all arrived, so the channel window bounded what the
peer may send, not what this side buffers. Both sides now cap the codec
at 2 * MAX_FRAME as soon as multiplexing is agreed: a data frame with
its envelope and MAC fits with room to spare, and a header over the cap
ends the tunnel before a byte of payload is read. TCP only; the
WebSocket and WebRTC codecs carry caps of their own.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EZ49AbZJYfm8NTp5yDPMab

* port forward: a channel id still live when the counter comes round is skipped

The controller handed out `next_id` unchecked. 2^32 opens later it lands
on a channel still up: the entry here was replaced, while the peer,
which ignores an `open` for a live id, kept routing that id to the old
socket, so the new local connection's bytes went into the old target
connection. The id is now taken under the map's lock and advanced past
any id in use.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EZ49AbZJYfm8NTp5yDPMab

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-09-05 14:59:51 +08:00
77 changed files with 6266 additions and 822 deletions

302
Cargo.lock generated
View File

@@ -753,24 +753,6 @@ dependencies = [
"syn 2.0.98",
]
[[package]]
name = "bindgen"
version = "0.71.1"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "5f58bf3d7db68cfbac37cfc485a8d711e87e064c3d0fe0435b92f7a407f9d6b3"
dependencies = [
"bitflags 2.9.1",
"cexpr",
"clang-sys",
"itertools 0.12.1",
"proc-macro2 1.0.93",
"quote 1.0.36",
"regex",
"rustc-hash 2.1.1",
"shlex",
"syn 2.0.98",
]
[[package]]
name = "bindgen"
version = "0.72.1"
@@ -1161,30 +1143,6 @@ version = "0.2.1"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "613afe47fcd5fac7ccf1db93babcb082c5994d996f20b8b159f2ad1658eb5724"
[[package]]
name = "chacha20"
version = "0.9.1"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "c3613f74bd2eac03dad61bd53dbe620703d4371614fe0bc3b9f04dd36fe4e818"
dependencies = [
"cfg-if 1.0.0",
"cipher",
"cpufeatures",
]
[[package]]
name = "chacha20poly1305"
version = "0.10.1"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "10cd79432192d1c0f4e1a0fef9527696cc039165d729fb41b3f4f4f354c2dc35"
dependencies = [
"aead",
"chacha20",
"cipher",
"poly1305",
"zeroize",
]
[[package]]
name = "chrono"
version = "0.4.41"
@@ -1234,7 +1192,6 @@ checksum = "773f3b9af64447d2ce9850330c473515014aa235e6a783b02db81ff39e4a3dad"
dependencies = [
"crypto-common",
"inout",
"zeroize",
]
[[package]]
@@ -2324,7 +2281,7 @@ version = "0.5.2"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "330c60081dcc4c72131f8eb70510f1ac07223e5d4163db481a04a0befcffa412"
dependencies = [
"libloading 0.8.4",
"libloading 0.7.4",
]
[[package]]
@@ -2442,42 +2399,6 @@ dependencies = [
"linux-raw-sys 0.6.5",
]
[[package]]
name = "dtls"
version = "0.13.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "f531dd7c181beaf3cebab3716afa4d0d41ab888be85232583f56bbaf07ca208a"
dependencies = [
"aes",
"aes-gcm",
"async-trait",
"bincode",
"byteorder",
"cbc",
"ccm",
"chacha20poly1305",
"der-parser",
"hmac",
"log",
"p256",
"p384",
"portable-atomic",
"rand 0.9.2",
"rand_core 0.6.4",
"rcgen",
"ring",
"rustls",
"sec1",
"serde 1.0.228",
"sha1",
"sha2",
"thiserror 1.0.61",
"tokio",
"webrtc-util",
"x25519-dalek",
"x509-parser",
]
[[package]]
name = "dtoa"
version = "0.4.8"
@@ -2863,7 +2784,7 @@ dependencies = [
"is-terminal",
"lazy_static",
"log",
"nu-ansi-term 0.49.0",
"nu-ansi-term",
"regex",
"thiserror 1.0.61",
]
@@ -3766,6 +3687,7 @@ dependencies = [
"mac_address",
"machine-uid",
"osascript",
"percent-encoding",
"protobuf",
"protobuf-codegen",
"rand 0.8.5",
@@ -4177,16 +4099,15 @@ dependencies = [
[[package]]
name = "interceptor"
version = "0.15.0"
version = "0.14.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "ea51375727680dc15f06e8ad90fa31df75d79dd030100e8ad60eef1c27fe2c98"
checksum = "1ac0781c825d602095113772e389ef0607afcb869ae0e68a590d8e0799cdcef8"
dependencies = [
"async-trait",
"bytes",
"futures",
"log",
"portable-atomic",
"rand 0.9.2",
"rand 0.8.5",
"rtcp",
"rtp",
"thiserror 1.0.61",
@@ -4338,11 +4259,11 @@ dependencies = [
[[package]]
name = "kcp-sys"
version = "0.1.0"
source = "git+https://github.com/rustdesk-org/kcp-sys#32a6c09fc6223f54aea83981a6aa8995931d29be"
source = "git+https://github.com/rustdesk-org/kcp-sys?branch=rustdesk-patches#023a0065398968989f2ddfcf5cc72bb886d02675"
dependencies = [
"anyhow",
"auto_impl",
"bindgen 0.71.1",
"bindgen 0.72.1",
"bitflags 2.9.1",
"bytes",
"cc",
@@ -4353,8 +4274,6 @@ dependencies = [
"thiserror 2.0.17",
"tokio",
"tokio-util",
"tracing",
"tracing-subscriber",
"zerocopy 0.7.34",
]
@@ -4488,7 +4407,7 @@ source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "e310b3a6b5907f99202fcdb4960ff45b93735d7c7d96b760fcff8db2dc0e103d"
dependencies = [
"cfg-if 1.0.0",
"windows-targets 0.52.6",
"windows-targets 0.48.5",
]
[[package]]
@@ -5210,16 +5129,6 @@ dependencies = [
"winapi 0.3.9",
]
[[package]]
name = "nu-ansi-term"
version = "0.46.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "77a8165726e8236064dbb45459242600304b42a5ea24ee2948e18e023bf7ba84"
dependencies = [
"overload",
"winapi 0.3.9",
]
[[package]]
name = "nu-ansi-term"
version = "0.49.0"
@@ -5883,12 +5792,6 @@ dependencies = [
"serde_json 1.0.118",
]
[[package]]
name = "overload"
version = "0.1.1"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "b15813163c1d831bf4a13c3610c05c0d03b39feb07f7e09fa234dac9b15aaf39"
[[package]]
name = "owned_ttf_parser"
version = "0.25.1"
@@ -6277,17 +6180,6 @@ dependencies = [
"windows-sys 0.52.0",
]
[[package]]
name = "poly1305"
version = "0.8.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "8159bd90725d2df49889a078b54f4f79e87f1f8a8444194cdca81d38f5393abf"
dependencies = [
"cpufeatures",
"opaque-debug",
"universal-hash",
]
[[package]]
name = "polyval"
version = "0.6.2"
@@ -7094,9 +6986,9 @@ dependencies = [
[[package]]
name = "rtcp"
version = "0.14.0"
version = "0.13.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "81d30d1c4091644431c22acf9f8be6191b56805e0e977f15ca7104b4a6d6eaec"
checksum = "e9689528bf3a9eb311fd938d05516dd546412f9ce4fffc8acfc1db27cc3dbf72"
dependencies = [
"bytes",
"thiserror 1.0.61",
@@ -7105,14 +6997,14 @@ dependencies = [
[[package]]
name = "rtp"
version = "0.14.0"
version = "0.13.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "2f126f38ea84c02480e32e547c1459a939052f74fb92117ac3eef23fdac6b023"
checksum = "c54733451a67d76caf9caa07a7a2cec6871ea9dda92a7847f98063d459200f4b"
dependencies = [
"bytes",
"memchr",
"portable-atomic",
"rand 0.9.2",
"rand 0.8.5",
"serde 1.0.228",
"thiserror 1.0.61",
"webrtc-util",
@@ -7267,6 +7159,7 @@ dependencies = [
"terminfo",
"termios 0.3.3",
"tiny-skia",
"tokio",
"totp-rs",
"tray-icon",
"ttf-parser",
@@ -7547,11 +7440,11 @@ dependencies = [
[[package]]
name = "sdp"
version = "0.10.0"
version = "0.8.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "32c374dceda16965d541c8800ce9cc4e1c14acfd661ddf7952feeedc3411e5c6"
checksum = "4cd277015eada44a0bb810a4b84d3bf6e810573fa62fb442f457edf6a1087a69"
dependencies = [
"rand 0.9.2",
"rand 0.8.5",
"substring",
"thiserror 1.0.61",
"url",
@@ -7781,15 +7674,6 @@ dependencies = [
"tzdb 0.5.10",
]
[[package]]
name = "sharded-slab"
version = "0.1.7"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "f40ca3c46823713e0d4209592e8d6e826aa57e928f09752619fc696c499637f6"
dependencies = [
"lazy_static",
]
[[package]]
name = "shared_library"
version = "0.1.9"
@@ -8129,15 +8013,15 @@ dependencies = [
[[package]]
name = "stun"
version = "0.9.0"
version = "0.8.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "1a512c5d501e3e3b5a4bb3e8e31462d56d54a66b95a28b8596e14422bf21c32b"
checksum = "7dbc2bab375524093c143dc362a03fb6a1fb79e938391cdb21665688f88a088a"
dependencies = [
"base64 0.22.1",
"crc",
"lazy_static",
"md-5",
"rand 0.9.2",
"rand 0.8.5",
"ring",
"subtle",
"thiserror 1.0.61",
@@ -8519,16 +8403,6 @@ dependencies = [
"syn 2.0.98",
]
[[package]]
name = "thread_local"
version = "1.1.8"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "8b9ef9bad013ada3808854ceac7b46812a6465ba368859a37e2100283d2d719c"
dependencies = [
"cfg-if 1.0.0",
"once_cell",
]
[[package]]
name = "threadpool"
version = "1.8.1"
@@ -8908,32 +8782,6 @@ source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "b9d12581f227e93f094d3af2ae690a574abb8a2b9b7a96e7cfe9647b2b617678"
dependencies = [
"once_cell",
"valuable",
]
[[package]]
name = "tracing-log"
version = "0.2.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "ee855f1f400bd0e5c02d150ae5de3840039a3f54b025156404e34c23c03f47c3"
dependencies = [
"log",
"once_cell",
"tracing-core",
]
[[package]]
name = "tracing-subscriber"
version = "0.3.19"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "e8189decb5ac0fa7bc8b96b7cb9b2701d60d48805aca84a238004d665fcc4008"
dependencies = [
"nu-ansi-term 0.46.0",
"sharded-slab",
"smallvec",
"thread_local",
"tracing-core",
"tracing-log",
]
[[package]]
@@ -9048,9 +8896,9 @@ dependencies = [
[[package]]
name = "turn"
version = "0.11.0"
version = "0.10.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "5ed995882f66ab94238de77c62e5e778389698ab700afa4696f4754da8f457cb"
checksum = "3f5aea1116456e1da71c45586b87c72e3b43164fbf435eb93ff6aa475416a9a4"
dependencies = [
"async-trait",
"base64 0.22.1",
@@ -9058,7 +8906,7 @@ dependencies = [
"log",
"md-5",
"portable-atomic",
"rand 0.9.2",
"rand 0.8.5",
"ring",
"stun",
"thiserror 1.0.61",
@@ -9184,12 +9032,6 @@ dependencies = [
"unic-common",
]
[[package]]
name = "unicase"
version = "2.8.1"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "75b844d17643ee918803943289730bec8aac480150456169e647ed0b576ba539"
[[package]]
name = "unicode-bidi"
version = "0.3.15"
@@ -9335,12 +9177,6 @@ dependencies = [
"bindgen 0.65.1",
]
[[package]]
name = "valuable"
version = "0.1.1"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "ba73ea9cf16a25df0c8caa16c51acb937d5712a8429db78a3ee29d5dcacd3a65"
[[package]]
name = "vcpkg"
version = "0.2.15"
@@ -9724,25 +9560,26 @@ dependencies = [
[[package]]
name = "webrtc"
version = "0.14.0"
version = "0.13.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "08fd686c0920ac08f3a57eacc48e31f0e4ca1ffefba4478784606f78c14e83ad"
checksum = "24bab7195998d605c862772f90a452ba655b90a2f463c850ac032038890e367a"
dependencies = [
"arc-swap",
"async-trait",
"bytes",
"dtls",
"cfg-if 1.0.0",
"hex",
"interceptor",
"lazy_static",
"log",
"portable-atomic",
"rand 0.9.2",
"rand 0.8.5",
"rcgen",
"regex",
"ring",
"rtcp",
"rtp",
"rustls",
"sdp",
"serde 1.0.228",
"serde_json 1.0.118",
@@ -9750,12 +9587,13 @@ dependencies = [
"smol_str",
"stun",
"thiserror 1.0.61",
"time 0.3.36",
"tokio",
"turn",
"unicase",
"url",
"waitgroup",
"webrtc-data",
"webrtc-dtls",
"webrtc-ice",
"webrtc-mdns",
"webrtc-media",
@@ -9766,9 +9604,9 @@ dependencies = [
[[package]]
name = "webrtc-data"
version = "0.12.0"
version = "0.11.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "062a5438d63bb0756a221693d76cc0dd6119affee1dfdfe57abe3a2a8c8b3eea"
checksum = "4e97b932854da633a767eff0cc805425a2222fc6481e96f463e57b015d949d1d"
dependencies = [
"bytes",
"log",
@@ -9780,17 +9618,54 @@ dependencies = [
]
[[package]]
name = "webrtc-ice"
version = "0.14.0"
name = "webrtc-dtls"
version = "0.12.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "69cb13fd1a373e68addc4bba0c8ca058627518e54342583d024bdcbb8ae5d97d"
checksum = "5ccbe4d9049390ab52695c3646c1395c877e16c15fb05d3bda8eee0c7351711c"
dependencies = [
"aes",
"aes-gcm",
"async-trait",
"bincode",
"byteorder",
"cbc",
"ccm",
"der-parser",
"hkdf",
"hmac",
"log",
"p256",
"p384",
"portable-atomic",
"rand 0.8.5",
"rand_core 0.6.4",
"rcgen",
"ring",
"rustls",
"sec1",
"serde 1.0.228",
"sha1",
"sha2",
"subtle",
"thiserror 1.0.61",
"tokio",
"webrtc-util",
"x25519-dalek",
"x509-parser",
]
[[package]]
name = "webrtc-ice"
version = "0.13.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "eb51bde0d790f109a15bfe4d04f1b56fb51d567da231643cb3f21bb74d678997"
dependencies = [
"arc-swap",
"async-trait",
"crc",
"log",
"portable-atomic",
"rand 0.9.2",
"rand 0.8.5",
"serde 1.0.228",
"serde_json 1.0.118",
"stun",
@@ -9806,9 +9681,9 @@ dependencies = [
[[package]]
name = "webrtc-mdns"
version = "0.10.0"
version = "0.9.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "a17279a067e75df72ce923fdeb7f04cd808f6f5aa4910dc6bcb4fbe66b396ace"
checksum = "979cc85259c53b7b620803509d10d35e2546fa505d228850cbe3f08765ea6ea8"
dependencies = [
"log",
"socket2 0.5.10",
@@ -9819,22 +9694,21 @@ dependencies = [
[[package]]
name = "webrtc-media"
version = "0.11.0"
version = "0.10.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "94a84c910fec0848fd5a0d8a5651e0ddbdedaf25a7d3ae3f0b15f71ac73a1773"
checksum = "80041211deccda758a3e19aa93d6b10bc1d37c9183b519054b40a83691d13810"
dependencies = [
"byteorder",
"bytes",
"rand 0.9.2",
"rand 0.8.5",
"rtp",
"thiserror 1.0.61",
]
[[package]]
name = "webrtc-sctp"
version = "0.13.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "f985465467d8910c1f8ac4382cd64f83b1f6a1a75021a82b221546f6fb3b856f"
version = "0.12.0"
source = "git+https://github.com/rustdesk-org/webrtc?rev=48100bf13e694d7e5bbb49b9a753dbad1c359d0c#48100bf13e694d7e5bbb49b9a753dbad1c359d0c"
dependencies = [
"arc-swap",
"async-trait",
@@ -9842,7 +9716,7 @@ dependencies = [
"crc",
"log",
"portable-atomic",
"rand 0.9.2",
"rand 0.8.5",
"thiserror 1.0.61",
"tokio",
"webrtc-util",
@@ -9850,9 +9724,9 @@ dependencies = [
[[package]]
name = "webrtc-srtp"
version = "0.16.0"
version = "0.15.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "66d8cdc33413f1d0192670a80ce93d17cb78d57fe3a2414be30d6f6dff121123"
checksum = "01e773f79b09b057ffbda6b03fe7b43403b012a240cf8d05d630674c3723b5bb"
dependencies = [
"aead",
"aes",
@@ -9873,19 +9747,19 @@ dependencies = [
[[package]]
name = "webrtc-util"
version = "0.12.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "d1c0c7e0c8f280f2bbfae442701465777ac07adaf46ce0c5863cd58e13fe472a"
version = "0.11.0"
source = "git+https://github.com/rustdesk-org/webrtc?rev=48100bf13e694d7e5bbb49b9a753dbad1c359d0c#48100bf13e694d7e5bbb49b9a753dbad1c359d0c"
dependencies = [
"async-trait",
"bitflags 1.3.2",
"bytes",
"ipnet",
"lazy_static",
"libc",
"log",
"nix 0.26.4",
"portable-atomic",
"rand 0.9.2",
"rand 0.8.5",
"thiserror 1.0.61",
"tokio",
"winapi 0.3.9",

View File

@@ -52,7 +52,7 @@ screencapturekit = ["cpal/screencapturekit"]
[dependencies]
async-trait = "0.1"
scrap = { path = "libs/scrap", features = ["wayland"] }
hbb_common = { path = "libs/hbb_common" }
hbb_common = { path = "libs/hbb_common", features = ["webrtc"] }
serde_derive = "1.0"
serde = "1.0"
serde_json = "1.0"
@@ -83,7 +83,7 @@ fon = "0.6"
shutdown_hooks = "0.1"
totp-rs = { version = "5.4", default-features = false, features = ["gen_secret", "otpauth"] }
stunclient = "0.4"
kcp-sys= { git = "https://github.com/rustdesk-org/kcp-sys"}
kcp-sys= { git = "https://github.com/rustdesk-org/kcp-sys", branch = "rustdesk-patches" }
reqwest = { version = "0.12", features = ["blocking", "socks", "json", "native-tls", "rustls-tls", "rustls-tls-native-roots", "gzip", "zstd"], default-features=false }
[target.'cfg(not(target_os = "linux"))'.dependencies]
@@ -215,6 +215,19 @@ exclude = ["vdi/host"]
# This allows building and running on systems without libxdo installed (e.g., Wayland-only)
[patch.crates-io]
libxdo-sys = { path = "libs/libxdo-sys-stub" }
# One branch off upstream v0.13.0, the tag whose crate versions match this stack.
# webrtc-util: reads the Windows adapter list's IPv6 addresses as host-order u16 groups, so every
# one comes out byte-swapped, fails to bind, and ICE gathers no IPv6 host candidate on Windows.
# webrtc-sctp: RFC 4960's 1s RTO floor makes a single loss cost 1-3s on a link whose RTT is 24-64ms,
# and fast retransmit cannot cover a request/response exchange; INITIAL_MTU 1228 also fragments on
# IPv6; and its AIMD pins a lossy long-haul link to MSS/(RTT*sqrt(p)), so a switch sends without
# a congestion window, as KCP does - on by default, `allow-webrtc-congestion-control` opts back in.
# Sending that way, a reordering window keeps a chunk that is merely late from being resent on a
# path that jitters, every DATA chunk asks for its SACK at once so a lost tail is back within an
# RTT at KCP's RTO floors, and bundles of small chunks stay within the MTU.
# Pinned by rev, not branch: a fork branch can be rewritten out from under the lockfile.
webrtc-util = { git = "https://github.com/rustdesk-org/webrtc", rev = "48100bf13e694d7e5bbb49b9a753dbad1c359d0c" }
webrtc-sctp = { git = "https://github.com/rustdesk-org/webrtc", rev = "48100bf13e694d7e5bbb49b9a753dbad1c359d0c" }
[package.metadata.winres]
LegalCopyright = "Copyright © 2026 Purslane Tech Pte. Ltd. All rights reserved."
@@ -234,6 +247,7 @@ os-version = "0.2"
[dev-dependencies]
hound = "3.5"
docopt = "1.1"
tokio = { version = "1.44", features = ["test-util"] }
[package.metadata.bundle]
name = "RustDesk"

View File

@@ -43,6 +43,15 @@ fn build_manifest() {
}
}
// bionic only exports getifaddrs()/freeifaddrs() from API 24, while the jniLibs
// are built against the API 21 sysroot (flutter/ndk_*.sh). webrtc-util calls
// them, so without this the android link fails on undefined symbols.
fn build_android_ifaddrs() {
let file = "src/platform/android_ifaddrs.c";
cc::Build::new().file(file).compile("android_ifaddrs");
println!("cargo:rerun-if-changed={}", file);
}
fn install_android_deps() {
let target_os = std::env::var("CARGO_CFG_TARGET_OS").unwrap();
if target_os != "android" {
@@ -89,5 +98,8 @@ fn main() {
build_mac();
println!("cargo:rustc-link-lib=framework=ApplicationServices");
}
if target_os == "android" {
build_android_ifaddrs();
}
println!("cargo:rerun-if-changed=build.rs");
}

View File

@@ -1633,7 +1633,8 @@ String bool2option(String option, bool b) {
String res;
if (option.startsWith('enable-') &&
option != kOptionEnableUdpPunch &&
option != kOptionEnableIpv6Punch) {
option != kOptionEnableIpv6Punch &&
option != kOptionEnableWebrtc) {
res = b ? defaultOptionYes : 'N';
} else if (option.startsWith('allow-') ||
option == kOptionStopService ||

View File

@@ -606,6 +606,9 @@ class QualityMonitor extends StatelessWidget {
_row(
"Codec", qualityMonitorModel.data.codecFormat ?? '-'),
_row("Chroma", qualityMonitorModel.data.chroma ?? '-'),
if (qualityMonitorModel.webrtcTransport != null)
_row("Transport",
qualityMonitorModel.webrtcTransport!),
],
),
)

View File

@@ -164,6 +164,7 @@ const String kOptionPeerTabVisible = "peer-tab-visible";
const String kOptionPeerCardUiType = "peer-card-ui-type";
const String kOptionCurrentAbName = "current-ab-name";
const String kOptionEnableConfirmClosingTabs = "enable-confirm-closing-tabs";
const String kOptionEnablePortForwardMux = "enable-port-forward-mux";
const String kOptionAllowAlwaysSoftwareRender = "allow-always-software-render";
const String kOptionEnableCheckUpdate = "enable-check-update";
const String kOptionAllowAutoUpdate = "allow-auto-update";
@@ -171,10 +172,12 @@ const String kOptionAllowRemoveWallpaper = "allow-remove-wallpaper";
const String kOptionStopService = "stop-service";
const String kOptionDirectxCapture = "enable-directx-capture";
const String kOptionAllowRemoteCmModification = "allow-remote-cm-modification";
const String kOptionEnableTcpPunch = "enable-tcp-punch";
const String kOptionEnableUdpPunch = "enable-udp-punch";
const String kOptionEnableIpv6Punch = "enable-ipv6-punch";
const String kOptionAllowSyncClipboardBetweenSessions =
"allow-sync-clipboard-between-sessions";
const String kOptionEnableWebrtc = "enable-webrtc";
const String kOptionEnableTrustedDevices = "enable-trusted-devices";
const String kOptionShowVirtualMouse = "show-virtual-mouse";
const String kOptionVirtualMouseScale = "virtual-mouse-scale";

View File

@@ -509,6 +509,15 @@ class _GeneralState extends State<_General> {
kOptionOpenNewConnInTabs,
isServer: false,
),
Tooltip(
message: translate('port-forward-mux-tip'),
child: _OptionCheckBox(
context,
'Reuse one connection for port forwarding',
kOptionEnablePortForwardMux,
isServer: false,
),
),
// though this is related to GUI, but opengl problem affects all users, so put in config rather than local
if (isLinux)
Tooltip(
@@ -563,6 +572,12 @@ class _GeneralState extends State<_General> {
kOptionDirectxCapture,
),
if (!isWeb && !incomingOnly) ...[
_OptionCheckBox(
context,
'Enable TCP hole punching',
kOptionEnableTcpPunch,
isServer: false,
),
_OptionCheckBox(
context,
'Enable UDP hole punching',
@@ -575,6 +590,15 @@ class _GeneralState extends State<_General> {
kOptionEnableIpv6Punch,
isServer: false,
),
],
if (!incomingOnly)
_OptionCheckBox(
context,
'Enable WebRTC P2P connection',
kOptionEnableWebrtc,
isServer: false,
),
if (!isWeb && !incomingOnly)
Tooltip(
message: translate('sync-clipboard-between-sessions-tip'),
child: _OptionCheckBox(
@@ -584,7 +608,6 @@ class _GeneralState extends State<_General> {
isServer: false,
),
),
],
];
// Add client-side wakelock option for desktop platforms

View File

@@ -97,10 +97,12 @@ class _SettingsState extends State<SettingsPage> with WidgetsBindingObserver {
var _hideNetwork = false;
var _hideWebSocket = false;
var _enableTrustedDevices = false;
var _enableTcpPunch = false;
var _enableUdpPunch = false;
var _allowInsecureTlsFallback = false;
var _disableUdp = false;
var _enableIpv6Punch = false;
var _enableWebrtc = false;
var _isUsingPublicServer = false;
var _allowAskForNoteAtEndOfConnection = false;
var _preventSleepWhileConnected = true;
@@ -141,8 +143,10 @@ class _SettingsState extends State<SettingsPage> with WidgetsBindingObserver {
bind.mainGetBuildinOption(key: kOptionHideWebSocketSetting) == 'Y' ||
isWeb;
_enableTrustedDevices = mainGetBoolOptionSync(kOptionEnableTrustedDevices);
_enableTcpPunch = mainGetLocalBoolOptionSync(kOptionEnableTcpPunch);
_enableUdpPunch = mainGetLocalBoolOptionSync(kOptionEnableUdpPunch);
_enableIpv6Punch = mainGetLocalBoolOptionSync(kOptionEnableIpv6Punch);
_enableWebrtc = mainGetLocalBoolOptionSync(kOptionEnableWebrtc);
_allowAskForNoteAtEndOfConnection =
mainGetLocalBoolOptionSync(kOptionAllowAskForNoteAtEndOfConnection);
_preventSleepWhileConnected =
@@ -815,31 +819,65 @@ class _SettingsState extends State<SettingsPage> with WidgetsBindingObserver {
});
},
),
if (!incomingOnly)
SettingsTile.switchTile(
title: Text(translate('Enable TCP hole punching')),
initialValue: _enableTcpPunch,
onToggle: isOptionFixed(kOptionEnableTcpPunch)
? null
: (v) async {
await mainSetLocalBoolOption(kOptionEnableTcpPunch, v);
final newValue =
mainGetLocalBoolOptionSync(kOptionEnableTcpPunch);
setState(() {
_enableTcpPunch = newValue;
});
},
),
if (!incomingOnly)
SettingsTile.switchTile(
title: Text(translate('Enable UDP hole punching')),
initialValue: _enableUdpPunch,
onToggle: (v) async {
await mainSetLocalBoolOption(kOptionEnableUdpPunch, v);
final newValue =
mainGetLocalBoolOptionSync(kOptionEnableUdpPunch);
setState(() {
_enableUdpPunch = newValue;
});
},
onToggle: isOptionFixed(kOptionEnableUdpPunch)
? null
: (v) async {
await mainSetLocalBoolOption(kOptionEnableUdpPunch, v);
final newValue =
mainGetLocalBoolOptionSync(kOptionEnableUdpPunch);
setState(() {
_enableUdpPunch = newValue;
});
},
),
if (!incomingOnly)
SettingsTile.switchTile(
title: Text(translate('Enable IPv6 P2P connection')),
initialValue: _enableIpv6Punch,
onToggle: (v) async {
await mainSetLocalBoolOption(kOptionEnableIpv6Punch, v);
final newValue =
mainGetLocalBoolOptionSync(kOptionEnableIpv6Punch);
setState(() {
_enableIpv6Punch = newValue;
});
},
onToggle: isOptionFixed(kOptionEnableIpv6Punch)
? null
: (v) async {
await mainSetLocalBoolOption(kOptionEnableIpv6Punch, v);
final newValue =
mainGetLocalBoolOptionSync(kOptionEnableIpv6Punch);
setState(() {
_enableIpv6Punch = newValue;
});
},
),
if (!incomingOnly)
SettingsTile.switchTile(
title: Text(translate('Enable WebRTC P2P connection')),
initialValue: _enableWebrtc,
onToggle: isOptionFixed(kOptionEnableWebrtc)
? null
: (v) async {
await mainSetLocalBoolOption(kOptionEnableWebrtc, v);
final newValue =
mainGetLocalBoolOptionSync(kOptionEnableWebrtc);
setState(() {
_enableWebrtc = newValue;
});
},
),
SettingsTile(
title: Text(translate('Language')),

View File

@@ -3597,6 +3597,16 @@ class QualityMonitorModel with ChangeNotifier {
bool get show => _show;
QualityMonitorData get data => _data;
// Only a WebRTC session names its transport here: web has no session tab
// to show it on, and WebRTC is the one path that can be direct or TURN.
String? get webrtcTransport {
final ffiModel = parent.target?.ffiModel;
if (ffiModel == null) return null;
final streamType = ffiModel.cachedPeerData.streamType;
if (!streamType.startsWith('WebRTC')) return null;
return ffiModel.direct == false ? '$streamType (TURN)' : streamType;
}
checkShowQualityMonitor(SessionID sessionId) async {
final show = await bind.sessionGetToggleOption(
sessionId: sessionId, arg: 'show-quality-monitor') ==

View File

@@ -143,7 +143,7 @@ fn test_vpx(
println!(
"{:?} encode: {:?}, {} byte",
codec_id,
time_sum / yuv_count as _,
time_sum / yuv_count as u32,
size / yuv_count
);
@@ -156,7 +156,7 @@ fn test_vpx(
println!(
"{:?} decode: {:?}",
codec_id,
start.elapsed() / yuv_count as _
start.elapsed() / yuv_count as u32
);
}
@@ -212,7 +212,7 @@ fn test_av1(
assert_eq!(av1s.len(), yuv_count);
println!(
"AV1 encode: {:?}, {} byte",
time_sum / yuv_count as _,
time_sum / yuv_count as u32,
size / yuv_count
);
let mut decoder = AomDecoder::new().unwrap();
@@ -221,7 +221,7 @@ fn test_av1(
let _ = decoder.decode(&av1);
let _ = decoder.flush();
}
println!("AV1 decode: {:?}", start.elapsed() / yuv_count as _);
println!("AV1 decode: {:?}", start.elapsed() / yuv_count as u32);
}
#[cfg(feature = "hwcodec")]

File diff suppressed because it is too large Load Diff

View File

@@ -185,6 +185,14 @@ impl<T: InvokeUiSession> Remote<T> {
.unwrap()
.set_connected();
let is_secured = peer.is_secured();
// Only WebRTC needs refining: its label names the transport that won the race,
// not the family ICE ended up nominating, and it is the one path where the two
// can disagree with the address the rendezvous observed.
let stream_type = if peer.webrtc_remote_ipv6().await.unwrap_or(false) {
"WebRTC/IPv6"
} else {
stream_type
};
self.handler
.set_connection_type(is_secured, direct, stream_type); // flutter -> connection_ready
if !is_secured

View File

@@ -1,7 +1,7 @@
use std::{
collections::HashMap,
future::Future,
net::{SocketAddr, ToSocketAddrs},
net::SocketAddr,
sync::{Arc, Mutex, RwLock},
task::Poll,
};
@@ -1153,6 +1153,13 @@ pub fn is_public(url: &str) -> bool {
host == "rustdesk.com" || host.ends_with(".rustdesk.com")
}
pub fn get_tcp_punch_enabled() -> bool {
config::option2bool(
keys::OPTION_ENABLE_TCP_PUNCH,
&get_local_option(keys::OPTION_ENABLE_TCP_PUNCH),
)
}
pub fn get_udp_punch_enabled() -> bool {
config::option2bool(
keys::OPTION_ENABLE_UDP_PUNCH,
@@ -1167,9 +1174,19 @@ pub fn get_ipv6_punch_enabled() -> bool {
)
}
pub fn get_webrtc_enabled() -> bool {
config::option2bool(
keys::OPTION_ENABLE_WEBRTC,
&get_local_option(keys::OPTION_ENABLE_WEBRTC),
)
}
pub fn get_local_option(key: &str) -> String {
let v = LocalConfig::get_option(key);
if key == keys::OPTION_ENABLE_UDP_PUNCH || key == keys::OPTION_ENABLE_IPV6_PUNCH {
if key == keys::OPTION_ENABLE_UDP_PUNCH
|| key == keys::OPTION_ENABLE_IPV6_PUNCH
|| key == keys::OPTION_ENABLE_WEBRTC
{
if v.is_empty() {
if !is_public(&Config::get_rendezvous_server()) {
return "N".to_owned();
@@ -2126,11 +2143,21 @@ pub fn get_rs_pk(str_base64: &str) -> Option<sign::PublicKey> {
}
pub fn decode_id_pk(signed: &[u8], key: &sign::PublicKey) -> ResultType<(String, [u8; 32])> {
let (id, pk, _) = decode_id_pk_dtls(signed, key)?;
Ok((id, pk))
}
/// Like [`decode_id_pk`] but also returns the signed DTLS certificate fingerprint (empty string
/// for non-WebRTC peers), used to bind a WebRTC DTLS channel to the verified peer identity.
pub fn decode_id_pk_dtls(
signed: &[u8],
key: &sign::PublicKey,
) -> ResultType<(String, [u8; 32], String)> {
let res = IdPk::parse_from_bytes(
&sign::verify(signed, key).map_err(|_| anyhow!("Signature mismatch"))?,
)?;
if let Some(pk) = get_pk(&res.pk) {
Ok((res.id, pk))
Ok((res.id, pk, res.dtls_fingerprint))
} else {
bail!("Wrong their public length");
}
@@ -2432,16 +2459,26 @@ pub fn is_udp_disabled() -> bool {
Config::get_option(keys::OPTION_DISABLE_UDP) == "Y"
}
/// Run KCP with its congestion window (nc=0) instead of the turbo profile it has always shipped.
///
/// Opt-in: which profile wins depends on why packets are lost — nc=1 deepens real congestion,
/// while nc=0 reads random loss as congestion and its RTO backoff drops cwnd to 1. Undecidable
/// without a shaped link, so keep what users run today.
#[inline]
pub fn get_kcp_cc_enabled() -> bool {
let k = keys::OPTION_ALLOW_KCP_CC;
config::option2bool(k, &Config::get_option(k))
}
// this crate https://github.com/yoshd/stun-client supports nat type
async fn stun_ipv6_test(stun_server: &str) -> ResultType<(SocketAddr, String)> {
use std::net::ToSocketAddrs;
async fn stun_ipv6_test(stun_server: String) -> ResultType<(SocketAddr, String)> {
use stunclient::StunClient;
let local_addr = SocketAddr::from(([0u16; 8], 0)); // [::]:0
let socket = UdpSocket::bind(&local_addr).await?;
let Some(stun_addr) = stun_server
.to_socket_addrs()?
.filter(|x| x.is_ipv6())
.next()
// Resolve via tokio so DNS never blocks the async runtime worker.
let Some(stun_addr) = tokio::net::lookup_host(&stun_server)
.await?
.find(|x| x.is_ipv6())
else {
bail!(
"Failed to resolve STUN ipv6 server address: {}",
@@ -2451,81 +2488,36 @@ async fn stun_ipv6_test(stun_server: &str) -> ResultType<(SocketAddr, String)> {
let client = StunClient::new(stun_addr);
let addr = client.query_external_address_async(&socket).await?;
Ok(if addr.ip().is_ipv6() {
(addr, stun_server.to_owned())
(addr, stun_server)
} else {
bail!("STUN server returned non-IPv6 address: {}", addr)
})
}
async fn stun_ipv4_test(stun_server: &str) -> ResultType<(SocketAddr, String)> {
use std::net::ToSocketAddrs;
use stunclient::StunClient;
let local_addr = SocketAddr::from(([0u8; 4], 0));
let socket = UdpSocket::bind(&local_addr).await?;
let Some(stun_addr) = stun_server
.to_socket_addrs()?
.filter(|x| x.is_ipv4())
.next()
else {
bail!(
"Failed to resolve STUN ipv4 server address: {}",
stun_server
);
};
let client = StunClient::new(stun_addr);
let addr = client.query_external_address_async(&socket).await?;
Ok(if addr.ip().is_ipv4() {
(addr, stun_server.to_owned())
} else {
bail!("STUN server returned non-IPv6 address: {}", addr)
})
}
static STUNS_V4: [&str; 3] = [
"stun.l.google.com:19302",
"stun.cloudflare.com:3478",
"stun.nextcloud.com:3478",
];
static STUNS_V6: [&str; 3] = [
"stun.l.google.com:19302",
"stun.cloudflare.com:3478",
"stun.nextcloud.com:3478",
];
pub async fn test_nat_ipv4() -> ResultType<(SocketAddr, String)> {
use hbb_common::futures::future::{select_ok, FutureExt};
let tests = STUNS_V4
.iter()
.map(|&stun| stun_ipv4_test(stun).boxed())
.collect::<Vec<_>>();
match select_ok(tests).await {
Ok(res) => {
return Ok(res.0);
}
Err(e) => {
bail!(
"Failed to get public IPv4 address via public STUN servers: {}",
e
);
}
};
}
async fn test_bind_ipv6() -> ResultType<SocketAddr> {
use hbb_common::futures::future::FutureExt;
let local_addr = SocketAddr::from(([0u16; 8], 0)); // [::]:0
let socket = UdpSocket::bind(local_addr).await?;
let addr = STUNS_V6[0]
.to_socket_addrs()?
.filter(|x| x.is_ipv6())
.next()
.ok_or_else(|| {
anyhow!(
"Failed to resolve STUN ipv6 server address: {}",
STUNS_V6[0]
)
})?;
// Nothing is sent - `connect` only makes the kernel pick a route and a source address - so any
// resolvable target answers equally and the whole cost is DNS. Race the lookups rather than
// walk them: this is awaited inline on the connection path, not every STUN host publishes a
// AAAA, and one resolver that hangs must not decide whether this host has v6.
let lookups = hbb_common::webrtc::WebRTCStream::default_stun_servers()
.into_iter()
.map(|stun| {
(async move {
let addr = tokio::net::lookup_host(&stun)
.await?
.find(|x| x.is_ipv6())
.ok_or_else(|| {
anyhow!("Failed to resolve STUN ipv6 server address: {}", stun)
})?;
Ok::<SocketAddr, hbb_common::anyhow::Error>(addr)
})
.boxed()
})
.collect::<Vec<_>>();
let (addr, _) = hbb_common::futures::future::select_ok(lookups).await?;
socket.connect(addr).await?;
Ok(socket.local_addr()?)
}
@@ -2592,9 +2584,9 @@ pub async fn test_ipv6() -> Option<tokio::task::JoinHandle<()>> {
Some(tokio::spawn(async {
use hbb_common::futures::future::{select_ok, FutureExt};
let tests = STUNS_V6
.iter()
.map(|&stun| stun_ipv6_test(stun).boxed())
let tests = hbb_common::webrtc::WebRTCStream::default_stun_servers()
.into_iter()
.map(|stun| stun_ipv6_test(stun).boxed())
.collect::<Vec<_>>();
match select_ok(tests).await {
@@ -2615,51 +2607,117 @@ pub async fn test_ipv6() -> Option<tokio::task::JoinHandle<()>> {
}))
}
// A punch packet carries a magic and a transaction id so a reply can be *proven* to answer this
// probe. The punch it replaces sent a zero-length datagram and called the hole open on whatever
// arrived next - which the rendezvous NAT test's own leftover replies satisfied instantly, so the
// retry loop below never actually ran and its success meant nothing.
const PUNCH_PROBE: [u8; 4] = *b"RDP?";
const PUNCH_ACK: [u8; 4] = *b"RDP!";
const PUNCH_PACKET_LEN: usize = 12;
fn punch_packet(tag: &[u8; 4], tid: u64) -> [u8; PUNCH_PACKET_LEN] {
let mut packet = [0u8; PUNCH_PACKET_LEN];
packet[..4].copy_from_slice(tag);
packet[4..].copy_from_slice(&tid.to_le_bytes());
packet
}
fn punch_tid(packet: &[u8], tag: &[u8; 4]) -> Option<u64> {
if packet.len() != PUNCH_PACKET_LEN || packet[..4] != tag[..] {
return None;
}
packet[4..].try_into().ok().map(u64::from_le_bytes)
}
/// Punch until one of our own probes is acknowledged. Both ends run this identically - each
/// probes, each answers the other's probes - and each returns only once a reply carrying its own
/// transaction id comes back, the one thing that proves the pair carries traffic both ways.
///
/// Returning is therefore a fact rather than a guess, which is what lets the caller stop instead
/// of handing a dead socket to a transport whose only way to discover the truth is to time out.
///
/// A datagram that is neither probe nor acknowledgement is returned rather than dropped: it means
/// the peer finished first and is already speaking KCP, whose SYN is never retransmitted.
///
/// Only the connector stops on its own acknowledgement, because only it has something to send
/// next. An acknowledgement proves our probe came back, not that the peer's probe was answered -
/// and after this returns nothing answers probes any more, since KCP's io loop drops anything
/// shorter than its header. A listener that stopped here would go mute while a peer whose own
/// probe or answer was lost - the normal state of a hole that is still opening - kept probing an
/// endpoint that works, until it timed out. So the listener stops on the peer's first real packet.
pub async fn punch_udp(
socket: Arc<UdpSocket>,
listen: bool,
) -> ResultType<Option<bytes::BytesMut>> {
let tid = ((hbb_common::time_based_rand() as u64) << 32) | hbb_common::time_based_rand() as u64;
let probe = punch_packet(&PUNCH_PROBE, tid);
let mut data = [0u8; 1500];
// `connect` does not flush the receive queue, so the NAT test's extra replies are still in it.
while socket.try_recv(&mut data).is_ok() {}
let mut retry_interval = Duration::from_millis(20);
const MAX_INTERVAL: Duration = Duration::from_millis(200);
const MAX_TIME: Duration = Duration::from_secs(20);
let mut packets_sent = 0;
socket.send(&[]).await.ok();
packets_sent += 1;
let mut last_send_time = Instant::now();
// Both ends start within one rendezvous round trip of each other and the acknowledgement is
// one peer round trip, so a pair that has not answered in this long is not going to. The old
// 20s came from having no way to tell "not yet" from "never".
const MAX_TIME: Duration = Duration::from_secs(3);
let mut probes_sent = 0u32;
let mut probes_seen = 0u32;
let mut acked = false;
let mut recv_errors = 0u32;
socket.send(&probe).await.ok();
probes_sent += 1;
let tm = Instant::now();
let mut data = [0u8; 1500];
// Absolute instants, not relative sleeps: `select!` rebuilds every arm each iteration, so a
// peer that keeps the receive side ready restarts a relative timer before it can fire. That
// both defeats MAX_TIME and starves the retransmit, and the peer decides the rate - an
// old-build peer's empty datagrams match no arm below and loop without even a pause.
let deadline = tm + MAX_TIME;
let mut next_probe = tm + retry_interval;
loop {
tokio::select! {
_ = hbb_common::sleep(retry_interval.as_secs_f32()) => {
if tm.elapsed() > MAX_TIME {
bail!("UDP punch is timed out, stop sending packets after {:?} packets", packets_sent);
}
let elapsed = last_send_time.elapsed();
if elapsed >= retry_interval {
socket.send(&[]).await.ok();
packets_sent += 1;
// Exponentially increase interval to reduce network pressure
retry_interval = std::cmp::min(
Duration::from_millis((retry_interval.as_millis() as f64 * 1.5) as u64),
MAX_INTERVAL
);
last_send_time = Instant::now();
}
_ = tokio::time::sleep_until(deadline) => {
bail!("UDP punch is timed out, {probes_sent} probes sent, {probes_seen} probes received, acked: {acked}, {recv_errors} recv errors absorbed");
}
_ = tokio::time::sleep_until(next_probe) => {
socket.send(&probe).await.ok();
probes_sent += 1;
retry_interval = std::cmp::min(retry_interval.mul_f64(1.5), MAX_INTERVAL);
next_probe = Instant::now() + retry_interval;
}
res = socket.recv(&mut data) => match res {
Err(e) => bail!("UDP punch failed, {packets_sent} packets sent: {e}"),
Err(e) => {
// ICMP unreachable from the peer's NAT is expected while the hole forms and
// surfaces here as ConnectionReset/Refused; treat it as loss, MAX_TIME bounds
// the attempt. Log only the first - this retries every 10ms.
recv_errors += 1;
if recv_errors == 1 {
log::debug!("UDP punch recv error (treated as loss): {e}");
}
hbb_common::sleep(0.01).await;
}
Ok(n) => {
// log::debug!("UDP punch succeeded after sending {} packets after {:?}", packets_sent, tm.elapsed());
if listen {
if n == 0 {
continue;
let ack = punch_tid(&data[..n], &PUNCH_ACK);
if ack == Some(tid) {
if !listen {
log::debug!(
"UDP punch confirmed in {:?}, {probes_sent} probes sent, {probes_seen} received",
tm.elapsed()
);
return Ok(None);
}
acked = true;
} else if let Some(peer_tid) = punch_tid(&data[..n], &PUNCH_PROBE) {
probes_seen += 1;
socket.send(&punch_packet(&PUNCH_ACK, peer_tid)).await.ok();
} else if ack.is_none() && n > 0 {
log::debug!(
"UDP punch confirmed by {n} bytes of peer data in {:?}, {probes_sent} probes sent",
tm.elapsed()
);
return Ok(Some(bytes::BytesMut::from(&data[..n])));
}
return Ok(None);
}
}
}
@@ -2783,6 +2841,38 @@ mod tests {
)
}
// The deadline must hold against a peer that keeps the receive side ready. `select!` rebuilds
// its arms every iteration, so a relative sleep would be restarted by every datagram and the
// punch would run for as long as the peer keeps talking, with no outer timeout to stop it.
#[tokio::test]
async fn test_udp_punch_deadline_survives_a_talkative_peer() {
let a = UdpSocket::bind("127.0.0.1:0").await.unwrap();
let b = UdpSocket::bind("127.0.0.1:0").await.unwrap();
let (a_addr, b_addr) = (a.local_addr().unwrap(), b.local_addr().unwrap());
a.connect(b_addr).await.unwrap();
b.connect(a_addr).await.unwrap();
// Empty datagrams answer no probe and match no return branch, so they only feed the loop.
// Sent well past the punch deadline so a restarted timer would show up as a long run.
let flooder = tokio::spawn(async move {
let end = Instant::now() + Duration::from_secs(12);
while Instant::now() < end {
if b.send(&[]).await.is_err() {
break;
}
sleep(Duration::from_millis(5)).await;
}
});
let start = Instant::now();
let res = punch_udp(Arc::new(a), false).await;
let elapsed = start.elapsed();
flooder.abort();
assert!(res.is_err(), "the punch should have timed out");
assert!(
elapsed < Duration::from_secs(6),
"the punch ran for {elapsed:?}; its deadline did not hold"
);
}
#[test]
fn untrusted_peer_id_validation() {
let cases = [

View File

@@ -24,7 +24,6 @@ use std::os::windows::io::AsRawHandle;
use std::{
fs,
path::{Path, PathBuf},
sync::{Mutex, OnceLock},
};
#[cfg(windows)]
use windows::Win32::{Foundation::HANDLE, System::Pipes::GetNamedPipeClientProcessId};
@@ -520,66 +519,17 @@ pub(crate) fn ensure_peer_executable_matches_current_by_fd(
#[cfg(any(target_os = "windows", target_os = "linux", target_os = "macos"))]
const UNAUTHORIZED_IPC_LOG_INTERVAL: std::time::Duration = std::time::Duration::from_secs(5);
#[cfg(any(target_os = "windows", target_os = "linux", target_os = "macos"))]
#[derive(Default)]
struct UnauthorizedIpcLogThrottle {
last_log_at: Option<std::time::Instant>,
suppressed: u64,
}
#[cfg(any(target_os = "windows", target_os = "linux", target_os = "macos"))]
impl UnauthorizedIpcLogThrottle {
#[inline]
fn on_reject(&mut self, now: std::time::Instant) -> Option<u64> {
if let Some(last) = self.last_log_at {
if now.saturating_duration_since(last) < UNAUTHORIZED_IPC_LOG_INTERVAL {
self.suppressed += 1;
return None;
}
}
self.last_log_at = Some(now);
Some(std::mem::take(&mut self.suppressed))
}
}
#[cfg(any(target_os = "windows", target_os = "linux", target_os = "macos"))]
#[inline]
fn throttled_unauthorized_ipc_log(
throttle_cell: &OnceLock<Mutex<UnauthorizedIpcLogThrottle>>,
emit: impl FnOnce(u64),
) {
let throttle = throttle_cell.get_or_init(|| Mutex::new(UnauthorizedIpcLogThrottle::default()));
let should_log = match throttle.lock() {
Ok(mut throttle) => throttle.on_reject(std::time::Instant::now()),
Err(_) => Some(0),
};
if let Some(suppressed) = should_log {
emit(suppressed);
}
}
#[cfg(any(target_os = "linux", target_os = "macos"))]
#[inline]
fn log_rejected_service_connection(postfix: &str, peer_uid: Option<u32>, active_uid: Option<u32>) {
static LOG_THROTTLE: OnceLock<Mutex<UnauthorizedIpcLogThrottle>> = OnceLock::new();
throttled_unauthorized_ipc_log(&LOG_THROTTLE, |suppressed| {
if suppressed > 0 {
log::warn!(
"Rejected unauthorized connection on protected service-scoped IPC channel: postfix={}, peer_uid={:?}, active_uid={:?} (suppressed {} similar events)",
postfix,
peer_uid,
active_uid,
suppressed
);
} else {
log::warn!(
"Rejected unauthorized connection on protected service-scoped IPC channel: postfix={}, peer_uid={:?}, active_uid={:?}",
postfix,
peer_uid,
active_uid
);
}
});
hbb_common::throttled_log!(
UNAUTHORIZED_IPC_LOG_INTERVAL,
warn,
"Rejected unauthorized connection on protected service-scoped IPC channel: postfix={}, peer_uid={:?}, active_uid={:?}",
postfix,
peer_uid,
active_uid
);
}
#[cfg(target_os = "linux")]
@@ -589,25 +539,14 @@ pub(crate) fn log_rejected_uinput_connection(
peer_uid: Option<u32>,
active_uid: Option<u32>,
) {
static LOG_THROTTLE: OnceLock<Mutex<UnauthorizedIpcLogThrottle>> = OnceLock::new();
throttled_unauthorized_ipc_log(&LOG_THROTTLE, |suppressed| {
if suppressed > 0 {
log::warn!(
"Rejected unauthorized connection on uinput ipc channel: postfix={}, peer_uid={:?}, active_uid={:?} (suppressed {} similar events)",
postfix,
peer_uid,
active_uid,
suppressed
);
} else {
log::warn!(
"Rejected unauthorized connection on uinput ipc channel: postfix={}, peer_uid={:?}, active_uid={:?}",
postfix,
peer_uid,
active_uid
);
}
});
hbb_common::throttled_log!(
UNAUTHORIZED_IPC_LOG_INTERVAL,
warn,
"Rejected unauthorized connection on uinput ipc channel: postfix={}, peer_uid={:?}, active_uid={:?}",
postfix,
peer_uid,
active_uid
);
}
#[cfg(windows)]
@@ -620,31 +559,17 @@ pub(crate) fn log_rejected_windows_ipc_connection(
peer_is_system: Option<bool>,
peer_is_elevated: Option<bool>,
) {
static LOG_THROTTLE: OnceLock<Mutex<UnauthorizedIpcLogThrottle>> = OnceLock::new();
throttled_unauthorized_ipc_log(&LOG_THROTTLE, |suppressed| {
if suppressed > 0 {
log::warn!(
"Rejected unauthorized connection on ipc channel: postfix={}, peer_pid={:?}, peer_session_id={:?}, expected_session_id={:?}, peer_is_system={:?}, peer_is_elevated={:?} (suppressed {} similar events)",
postfix,
peer_pid,
peer_session_id,
expected_session_id,
peer_is_system,
peer_is_elevated,
suppressed
);
} else {
log::warn!(
"Rejected unauthorized connection on ipc channel: postfix={}, peer_pid={:?}, peer_session_id={:?}, expected_session_id={:?}, peer_is_system={:?}, peer_is_elevated={:?}",
postfix,
peer_pid,
peer_session_id,
expected_session_id,
peer_is_system,
peer_is_elevated
);
}
});
hbb_common::throttled_log!(
UNAUTHORIZED_IPC_LOG_INTERVAL,
warn,
"Rejected unauthorized connection on ipc channel: postfix={}, peer_pid={:?}, peer_session_id={:?}, expected_session_id={:?}, peer_is_system={:?}, peer_is_elevated={:?}",
postfix,
peer_pid,
peer_session_id,
expected_session_id,
peer_is_system,
peer_is_elevated
);
}
#[cfg(any(target_os = "linux", target_os = "macos"))]

View File

@@ -19,7 +19,28 @@ pub struct KcpStream {
stop_sender: Option<oneshot::Sender<()>>,
}
const KCP_IO_ERR_LOG_INTERVAL: std::time::Duration = std::time::Duration::from_secs(5);
static KCP_SEND_ERR_LOG: hbb_common::log_throttle::LogThrottle =
hbb_common::log_throttle::LogThrottle::new(KCP_IO_ERR_LOG_INTERVAL);
static KCP_RECV_ERR_LOG: hbb_common::log_throttle::LogThrottle =
hbb_common::log_throttle::LogThrottle::new(KCP_IO_ERR_LOG_INTERVAL);
impl KcpStream {
// Opt in to KCP's built-in congestion window (nc=0) instead of the pure turbo profile
// (nc=1) that has always shipped; see `get_kcp_cc_enabled` for why this is not the default.
// Sender-side only, so no wire negotiation is needed and either peer may run either profile.
// Requires kcp-sys from the `rustdesk-patches` branch, which wires the config factory into
// connection setup (on older revs the factory was stored but never consulted).
fn apply_kcp_config(endpoint: &mut KcpEndpoint) {
if crate::get_kcp_cc_enabled() {
endpoint.set_kcp_config_factory(Box::new(|conv| {
let mut config = kcp_sys::ffi_safe::KcpConfig::new_turbo(conv);
config.nc = Some(0);
config
}));
}
}
fn create_framed(stream: stream::KcpStream, local_addr: Option<SocketAddr>) -> Stream {
Stream::Tcp(FramedStream(
tokio_util::codec::Framed::new(DynTcpStream(Box::new(stream)), BytesCodec::new()),
@@ -35,6 +56,7 @@ impl KcpStream {
init_packet: Option<BytesMut>,
) -> ResultType<(Self, Stream)> {
let mut endpoint = KcpEndpoint::new();
Self::apply_kcp_config(&mut endpoint);
endpoint.run().await;
let (input, output) = (
@@ -70,6 +92,7 @@ impl KcpStream {
timeout: std::time::Duration,
) -> ResultType<(Self, Stream)> {
let mut endpoint = KcpEndpoint::new();
Self::apply_kcp_config(&mut endpoint);
endpoint.run().await;
let (input, output) = (
@@ -104,6 +127,10 @@ impl KcpStream {
let udp = udp_socket.clone();
tokio::spawn(async move {
let mut buf = vec![0; 1500];
// Socket errors are ICMP unreachable on a connected UDP socket — advisory, and
// routine while a hole forms — so treat them as loss and let KCP's pong timeout reap
// a link that is really dead. One throttle PER DIRECTION: the error is reported once
// and cleared, so send-ok/recv-err alternates and a shared counter never fires.
loop {
tokio::select! {
_ = &mut stop_receiver => {
@@ -112,8 +139,10 @@ impl KcpStream {
}
Some(data) = output.recv() => {
if let Err(e) = udp.send(&data.inner()).await {
log::debug!("KCP send error: {:?}", e);
break;
if let Some(n) = KCP_SEND_ERR_LOG.due() {
log::debug!("KCP send error x{n} (treated as loss), last: {e}");
}
tokio::time::sleep(std::time::Duration::from_millis(10)).await;
}
}
result = udp.recv_from(&mut buf) => {
@@ -127,8 +156,10 @@ impl KcpStream {
.await.ok();
}
Err(e) => {
log::debug!("KCP recv_from error: {:?}", e);
break;
if let Some(n) = KCP_RECV_ERR_LOG.due() {
log::debug!("KCP recv error x{n} (treated as loss), last: {e}");
}
tokio::time::sleep(std::time::Duration::from_millis(10)).await;
}
}
}
@@ -149,3 +180,124 @@ impl Drop for KcpStream {
}
}
}
#[cfg(test)]
mod tests {
use super::*;
use std::time::Duration;
async fn connected_pair() -> (Arc<UdpSocket>, Arc<UdpSocket>) {
let a = UdpSocket::bind("127.0.0.1:0").await.unwrap();
let b = UdpSocket::bind("127.0.0.1:0").await.unwrap();
a.connect(b.local_addr().unwrap()).await.unwrap();
b.connect(a.local_addr().unwrap()).await.unwrap();
(Arc::new(a), Arc::new(b))
}
async fn establish() -> ((KcpStream, Stream), (KcpStream, Stream)) {
let (a, b) = connected_pair().await;
let (accept_res, connect_res) = tokio::join!(
KcpStream::accept(b, Duration::from_secs(5), None),
KcpStream::connect(a, Duration::from_secs(5))
);
(
connect_res.expect("connect over loopback"),
accept_res.expect("accept over loopback"),
)
}
// The full client path over real loopback sockets: handshake through the kcp_io
// pumps, framed data both ways, then a graceful close. The endpoint guard stays
// alive across the stream drop so the FIN can go out, and the peer's framed
// stream must end (BrokenPipe from the kcp reader) instead of hanging.
#[tokio::test]
async fn test_kcp_stream_loopback_roundtrip_and_close() {
let ((_guard_a, mut stream_a), (_guard_b, mut stream_b)) = establish().await;
stream_a
.send_bytes(Bytes::from_static(b"ping"))
.await
.unwrap();
let got = stream_b.next_timeout(5000).await.unwrap().unwrap();
assert_eq!(&got[..], b"ping");
stream_b
.send_bytes(Bytes::from_static(b"pong"))
.await
.unwrap();
let got = stream_a.next_timeout(5000).await.unwrap().unwrap();
assert_eq!(&got[..], b"pong");
drop(stream_a);
match stream_b.next_timeout(10_000).await {
None | Some(Err(_)) => {}
Some(Ok(data)) => panic!("unexpected data after close: {:?}", data),
}
}
// A writer that queues many frames and closes immediately must not cost the
// reader any of them: every frame arrives intact, in order, before end-of-stream.
// This is the client-side pin for the kcp-sys close-tail-drain semantics, through
// the real BytesCodec framing rustdesk sessions use.
#[tokio::test]
async fn test_kcp_stream_close_delivers_all_frames() {
let ((_guard_a, mut tx), (_guard_b, mut rx)) = establish().await;
const N: usize = 50;
let payload = vec![7u8; 32 * 1024];
for _ in 0..N {
tx.send_bytes(Bytes::from(payload.clone())).await.unwrap();
}
drop(tx);
let mut got = 0usize;
loop {
match rx.next_timeout(10_000).await {
Some(Ok(data)) => {
assert_eq!(data.len(), payload.len(), "frame boundary broken");
assert!(data.iter().all(|&b| b == 7), "frame content corrupted");
got += 1;
}
// BrokenPipe (kcp reader end) or timeout-None both end the stream.
None | Some(Err(_)) => break,
}
}
assert_eq!(got, N, "graceful close lost frames");
}
// Socket errors on the connected UDP socket (ICMP unreachable after the peer
// vanishes) are advisory: the io loop must treat them as loss - keep accepting
// writes, keep running - rather than tearing the session down. Whether the OS
// actually surfaces ECONNREFUSED here is platform-dependent; either way the
// session must stay alive for this window.
#[tokio::test]
async fn test_kcp_io_treats_socket_errors_as_loss() {
let ((_guard_a, mut stream_a), (guard_b, stream_b)) = establish().await;
// Kill the peer entirely: endpoint stops, socket closes.
drop(stream_b);
drop(guard_b);
tokio::time::sleep(Duration::from_millis(50)).await;
for _ in 0..10 {
stream_a
.send_bytes(Bytes::from_static(b"into the void"))
.await
.expect("socket errors must be treated as loss, not stream failure");
tokio::time::sleep(Duration::from_millis(20)).await;
}
}
// The connect deadline must hold when nothing answers: no hang, prompt error.
#[tokio::test]
async fn test_kcp_connect_timeout_without_peer() {
let (a, _b) = connected_pair().await;
let start = tokio::time::Instant::now();
let res = KcpStream::connect(a, Duration::from_millis(600)).await;
assert!(res.is_err(), "connect must fail with no peer endpoint");
assert!(
start.elapsed() < Duration::from_secs(5),
"connect did not honor its deadline"
);
}
}

View File

@@ -659,9 +659,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("screenshot-merged-screen-not-supported-tip", "لقطة الشاشة للشاشات المدمجة غير مدعومة"),
("screenshot-action-tip", "إجراء لقطة الشاشة"),
("Save as", "حفظ باسم"),
("Export", ""),
("Export Logs", ""),
("Import Folder", ""),
("Export", "تصدير"),
("Export Logs", "تصدير السجلات"),
("Import Folder", "استيراد مجلد"),
("Copy to clipboard", "نسخ إلى الحافظة"),
("Enable remote printer", "تمكين الطابعة عن بُعد"),
("Downloading {}", "جارٍ تنزيل {}"),
@@ -766,5 +766,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", ""),
("Enable", "تفعيل"),
("Reuse one connection for port forwarding", "إعادة استخدام اتصال واحد لإعادة توجيه المنافذ"),
("port-forward-mux-tip", "تمرير جميع اتصالات إعادة توجيه المنافذ عبر اتصال واحد بالجهاز الآخر، بدلاً من الاتصال وتسجيل الدخول من جديد لكل اتصال."),
("Enable WebRTC P2P connection", "تمكين اتصال نظير إلى نظير عبر WebRTC"),
("Enable TCP hole punching", "تمكين تقنية حفر الثغرات عبر TCP"),
].iter().cloned().collect();
}

View File

@@ -659,9 +659,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("screenshot-merged-screen-not-supported-tip", "Аб’яднанне здымкаў экранаў з некалькіх дысплэяў у дадзены момант не падтрымліваецца. Пераключыцеся на адзін з дысплэяў і паўтарыце дзеянне."),
("screenshot-action-tip", "Выберыце, што рабіць з атрыманым здымкам экрана."),
("Save as", "Захаваць у файл"),
("Export", ""),
("Export Logs", ""),
("Import Folder", ""),
("Export", "Экспартаваць"),
("Export Logs", "Экспартаваць журналы"),
("Import Folder", "Імпартаваць папку"),
("Copy to clipboard", "Скапіяваць у буфер абмену"),
("Enable remote printer", "Выкарыстоўваць аддалены прынтар"),
("Downloading {}", "Ідзе спампоўванне {}"),
@@ -766,5 +766,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", ""),
("Enable", "Уключыць"),
("Reuse one connection for port forwarding", "Выкарыстоўваць адно злучэнне для перанакіравання партоў"),
("port-forward-mux-tip", "Перадаваць усе злучэнні аднаго перанакіравання партоў праз адно злучэнне з аддаленай прыладай замест паўторнага падлучэння і ўваходу для кожнага з іх."),
("Enable WebRTC P2P connection", "Выкарыстоўваць падключэнне WebRTC P2P"),
("Enable TCP hole punching", "Выкарыстоўваць TCP hole punching"),
].iter().cloned().collect();
}

View File

@@ -659,9 +659,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("screenshot-merged-screen-not-supported-tip", "Обединяването на снимки от няколко екрана в момента не се поддържа. Моля, превключете към един екран и опитайте отново."),
("screenshot-action-tip", "Моля, изберете как да продължите със снимката на екрана."),
("Save as", "Запазване като"),
("Export", ""),
("Export Logs", ""),
("Import Folder", ""),
("Export", "Изнасяне"),
("Export Logs", "Изнасяне на дневниците"),
("Import Folder", "Внасяне на папка"),
("Copy to clipboard", "Копиране в клипборда"),
("Enable remote printer", "Позволяване на отдалечен принтер"),
("Downloading {}", "Изтегляне на {}"),
@@ -766,5 +766,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", ""),
("Enable", "Активирай"),
("Reuse one connection for port forwarding", "Използване на една връзка за пренасочване на портове"),
("port-forward-mux-tip", "Всички връзки на едно пренасочване на портове минават през една връзка към отсрещния компютър, вместо да се свързвате и влизате отново за всяка от тях."),
("Enable WebRTC P2P connection", "Позволяване на WebRTC P2P връзка"),
("Enable TCP hole punching", "Позволяване на TCP hole punching"),
].iter().cloned().collect();
}

View File

@@ -659,9 +659,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("screenshot-merged-screen-not-supported-tip", "Actualment no és possible combinar captures de pantalla de diverses pantalles. Canvieu a una sola pantalla i torneu a provar."),
("screenshot-action-tip", "Seleccioneu com voleu continuar amb la captura de pantalla."),
("Save as", "Anomena i desa"),
("Export", ""),
("Export Logs", ""),
("Import Folder", ""),
("Export", "Exporta"),
("Export Logs", "Exporta els registres"),
("Import Folder", "Importa una carpeta"),
("Copy to clipboard", "Copia al porta-retalls"),
("Enable remote printer", "Habilita l'impressora remota"),
("Downloading {}", "Descarregant {}"),
@@ -766,5 +766,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", ""),
("Enable", "Habilita"),
("Reuse one connection for port forwarding", "Reutilitza una connexió per a la redirecció de ports"),
("port-forward-mux-tip", "Fa passar totes les connexions d'una redirecció de ports per una única connexió amb l'altre equip, en lloc de connectar i iniciar la sessió de nou per a cadascuna."),
("Enable WebRTC P2P connection", "Habilita la connexió WebRTC P2P"),
("Enable TCP hole punching", "Activa la perforació TCP"),
].iter().cloned().collect();
}

View File

@@ -766,5 +766,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", "允许终端应用复制到剪贴板"),
("Enable", "启用"),
("Reuse one connection for port forwarding", "端口转发复用同一条连接"),
("port-forward-mux-tip", "同一条端口转发规则上的所有连接共用一条到对方的连接,而不是每条连接都重新连接并登录一次。"),
("Enable WebRTC P2P connection", "启用 WebRTC P2P 连接"),
("Enable TCP hole punching", "启用 TCP 打洞"),
].iter().cloned().collect();
}

View File

@@ -659,9 +659,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("screenshot-merged-screen-not-supported-tip", "Sloučení snímků obrazovky z více displejů aktuálně není podporováno. Přepněte na jeden displej a zkuste to znovu."),
("screenshot-action-tip", "Vyberte, jak pokračovat se snímkem obrazovky."),
("Save as", "Uložit jako"),
("Export", ""),
("Export Logs", ""),
("Import Folder", ""),
("Export", "Exportovat"),
("Export Logs", "Exportovat protokoly"),
("Import Folder", "Importovat složku"),
("Copy to clipboard", "Kopírovat do schránky"),
("Enable remote printer", "Povolit vzdálenou tiskárnu"),
("Downloading {}", "Stahuje se {}"),
@@ -766,5 +766,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", ""),
("Enable", "Povolit"),
("Reuse one connection for port forwarding", "Znovu použít jedno připojení pro přesměrování portů"),
("port-forward-mux-tip", "Vede všechna připojení jednoho přesměrování portů přes jediné připojení k protějšku místo opakovaného připojování a přihlašování pro každé z nich."),
("Enable WebRTC P2P connection", "Povolit připojení WebRTC P2P"),
("Enable TCP hole punching", "Povolit TCP hole punching"),
].iter().cloned().collect();
}

View File

@@ -659,9 +659,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("screenshot-merged-screen-not-supported-tip", "Sammenfletning af skærmbilleder fra flere skærme understøttes ikke i øjeblikket. Skift venligst til en enkelt skærm og prøv igen."),
("screenshot-action-tip", "Vælg venligst, hvordan du vil fortsætte med skærmbilledet."),
("Save as", "Gem som"),
("Export", ""),
("Export Logs", ""),
("Import Folder", ""),
("Export", "Eksportér"),
("Export Logs", "Eksportér logfiler"),
("Import Folder", "Importér mappe"),
("Copy to clipboard", "Kopiér til udklipsholder"),
("Enable remote printer", "Aktivér fjernprinter"),
("Downloading {}", "Downloader {}"),
@@ -766,5 +766,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", ""),
("Enable", "Aktivér"),
("Reuse one connection for port forwarding", "Genbrug én forbindelse til portvideresendelse"),
("port-forward-mux-tip", "Fører alle forbindelser i en portvideresendelse gennem én enkelt forbindelse til modparten i stedet for at forbinde og logge ind igen for hver enkelt."),
("Enable WebRTC P2P connection", "Aktivér WebRTC P2P-forbindelse"),
("Enable TCP hole punching", "Aktivér TCP hole punching"),
].iter().cloned().collect();
}

View File

@@ -659,9 +659,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("screenshot-merged-screen-not-supported-tip", "Das Zusammenführen von Screenshots von mehreren Bildschirmen wird derzeit nicht unterstützt. Bitte wechseln Sie zu einem einzelnen Bildschirm und versuchen Sie es erneut."),
("screenshot-action-tip", "Bitte wählen Sie aus, wie Sie mit dem Screenshot fortfahren möchten."),
("Save as", "Speichern unter"),
("Export", ""),
("Export Logs", ""),
("Import Folder", ""),
("Export", "Exportieren"),
("Export Logs", "Protokolle exportieren"),
("Import Folder", "Ordner importieren"),
("Copy to clipboard", "In Zwischenablage kopieren"),
("Enable remote printer", "Entfernten Drucker aktivieren"),
("Downloading {}", "{} herunterladen"),
@@ -766,5 +766,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", ""),
("Enable", "Aktivieren"),
("Reuse one connection for port forwarding", "Eine Verbindung für die Portweiterleitung wiederverwenden"),
("port-forward-mux-tip", "Alle Verbindungen einer Portweiterleitung über eine einzige Verbindung zur Gegenstelle führen, statt sich für jede einzelne neu zu verbinden und anzumelden."),
("Enable WebRTC P2P connection", "WebRTC-P2P-Verbindung aktivieren"),
("Enable TCP hole punching", "TCP-Hole-Punching aktivieren"),
].iter().cloned().collect();
}

View File

@@ -659,9 +659,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("screenshot-merged-screen-not-supported-tip", "Η συγχώνευση στιγμιότυπων οθόνης από πολλές οθόνες δεν υποστηρίζεται προς το παρόν. Αλλάξτε σε μία μόνο οθόνη και δοκιμάστε ξανά."),
("screenshot-action-tip", "Επιλέξτε πώς θα συνεχίσετε με το στιγμιότυπο οθόνης."),
("Save as", "Αποθήκευση ως"),
("Export", ""),
("Export Logs", ""),
("Import Folder", ""),
("Export", "Εξαγωγή"),
("Export Logs", "Εξαγωγή αρχείων καταγραφής"),
("Import Folder", "Εισαγωγή φακέλου"),
("Copy to clipboard", "Αντιγραφή στο πρόχειρο"),
("Enable remote printer", "Ενεργοποίηση απομακρυσμένου εκτυπωτή"),
("Downloading {}", "Γίνεται Λήψη {}"),
@@ -766,5 +766,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", ""),
("Enable", "Ενεργοποίηση"),
("Reuse one connection for port forwarding", "Επαναχρησιμοποίηση μίας σύνδεσης για την προώθηση θυρών"),
("port-forward-mux-tip", "Όλες οι συνδέσεις μιας προώθησης θυρών περνούν από μία μόνο σύνδεση προς τον απομακρυσμένο υπολογιστή, αντί να πραγματοποιείται νέα σύνδεση και ταυτοποίηση για κάθε μία."),
("Enable WebRTC P2P connection", "Ενεργοποίηση σύνδεσης WebRTC P2P"),
("Enable TCP hole punching", "Ενεργοποίηση διάτρησης οπών TCP"),
].iter().cloned().collect();
}

View File

@@ -277,5 +277,6 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("Your ip is blocked by the peer", "Your IP is blocked by the peer"),
("sync-clipboard-between-sessions-tip", "Text or images copied in one remote session are also sent to the clipboard of your other connected sessions."),
("terminal-clipboard-write-tip", "An app in the terminal wants to copy text to this device's clipboard. If granted, this permission applies to terminal apps in all connections until you turn it off in Settings. Manual copy and paste are unaffected."),
("port-forward-mux-tip", "Carry every connection of a port-forward mapping over a single connection to the peer, instead of connecting and logging in again for each one."),
].iter().cloned().collect();
}

View File

@@ -659,9 +659,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("screenshot-merged-screen-not-supported-tip", "Kunfandi ekrankopiojn de pluraj ekranoj aktuale ne estas subtenata. Bonvolu ŝanĝi al unu ekrano kaj reprovi."),
("screenshot-action-tip", "Bonvolu elekti kiel daŭrigi kun la ekrankopio."),
("Save as", "Konservi kiel"),
("Export", ""),
("Export Logs", ""),
("Import Folder", ""),
("Export", "Eksporti"),
("Export Logs", "Eksporti protokolojn"),
("Import Folder", "Importi dosierujon"),
("Copy to clipboard", "Kopii al la poŝo"),
("Enable remote printer", "Ebligi foran presilon"),
("Downloading {}", "Elŝutas {}"),
@@ -766,5 +766,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", ""),
("Enable", "Ebligi"),
("Reuse one connection for port forwarding", "Reuzi unu konekton por pordo-plusendado"),
("port-forward-mux-tip", "Ĉiuj konektoj de unu pordo-plusendado iras tra unu sola konekto al la alia komputilo, anstataŭ konekti kaj ensaluti denove por ĉiu el ili."),
("Enable WebRTC P2P connection", "Ebligi WebRTC P2P-konekton"),
("Enable TCP hole punching", "Ebligi TCP-trapikadon"),
].iter().cloned().collect();
}

View File

@@ -659,9 +659,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("screenshot-merged-screen-not-supported-tip", "La fusión de capturas de pantalla de múltiples monitores no está soportada. Por favor, cambie a un monitor e inténtelo de nuevo."),
("screenshot-action-tip", "Por favor, seleccione cómo continuar con la captura de pantalla."),
("Save as", "Guardar como"),
("Export", ""),
("Export Logs", ""),
("Import Folder", ""),
("Export", "Exportar"),
("Export Logs", "Exportar registros"),
("Import Folder", "Importar carpeta"),
("Copy to clipboard", "Copiar al portapapeles"),
("Enable remote printer", "Habilitar impresora remota"),
("Downloading {}", "Descargando {}"),
@@ -766,5 +766,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", ""),
("Enable", "Habilitar"),
("Reuse one connection for port forwarding", "Reutilizar una conexión para la redirección de puertos"),
("port-forward-mux-tip", "Llevar todas las conexiones de una redirección de puertos por una única conexión con el otro equipo, en lugar de conectar e iniciar sesión de nuevo para cada una."),
("Enable WebRTC P2P connection", "Habilitar conexión WebRTC P2P"),
("Enable TCP hole punching", "Habilitar perforación de agujero TCP"),
].iter().cloned().collect();
}

View File

@@ -659,9 +659,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("screenshot-merged-screen-not-supported-tip", "Mitme kuva kuvatõmmiste ühendamine pole praegu toetatud. Palun lülitu ühele kuvale ja proovi uuesti."),
("screenshot-action-tip", "Palun vali, kuidas kuvatõmmisega jätkata."),
("Save as", "Salvesta kui"),
("Export", ""),
("Export Logs", ""),
("Import Folder", ""),
("Export", "Ekspordi"),
("Export Logs", "Ekspordi logid"),
("Import Folder", "Impordi kaust"),
("Copy to clipboard", "Kopeeri lõikelauale"),
("Enable remote printer", "Luba kaugprinter"),
("Downloading {}", "Allalaadimine: {}"),
@@ -766,5 +766,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", ""),
("Enable", "Luba"),
("Reuse one connection for port forwarding", "Kasuta pordi suunamiseks üht ühendust"),
("port-forward-mux-tip", "Juhib ühe pordisuunamise kõik ühendused ühe teise arvutiga loodud ühenduse kaudu, selle asemel et iga ühenduse jaoks uuesti ühenduda ja sisse logida."),
("Enable WebRTC P2P connection", "Luba WebRTC P2P-ühendus"),
("Enable TCP hole punching", "Luba TCP-augustamine"),
].iter().cloned().collect();
}

View File

@@ -659,9 +659,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("screenshot-merged-screen-not-supported-tip", "Pantaila anitzen pantaila-argazkiak bateratzea ez da onartzen une honetan. Aldatu pantaila bakarrera eta saiatu berriro."),
("screenshot-action-tip", "Hautatu pantaila-argazkiarekin nola jarraitu."),
("Save as", "Gorde honela"),
("Export", ""),
("Export Logs", ""),
("Import Folder", ""),
("Export", "Esportatu"),
("Export Logs", "Esportatu erregistroak"),
("Import Folder", "Inportatu karpeta"),
("Copy to clipboard", "Kopiatu arbelera"),
("Enable remote printer", "Gaitu urruneko inprimagailua"),
("Downloading {}", "{} deskargatzen"),
@@ -766,5 +766,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", ""),
("Enable", "Gaitu"),
("Reuse one connection for port forwarding", "Berrerabili konexio bakarra portuen birbideratzerako"),
("port-forward-mux-tip", "Portu-birbideratze baten konexio guztiak beste ordenagailurako konexio bakar batetik eramaten ditu, bakoitzerako berriro konektatu eta saioa hasi beharrean."),
("Enable WebRTC P2P connection", "Gaitu WebRTC P2P konexioa"),
("Enable TCP hole punching", "Gaitu TCP zulo-egitea"),
].iter().cloned().collect();
}

View File

@@ -659,9 +659,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("screenshot-merged-screen-not-supported-tip", "ادغام تصاویر از نمایشگرهای متعدد در حال حاضر پشتیبانی نمی شود. لطفاً به یک صفحه نمایش واحد تغییر دهید و دوباره امتحان کنید."),
("screenshot-action-tip", "لطفاً نحوه ادامه با تصویر را انتخاب کنید."),
("Save as", "ذخیره به عنوان"),
("Export", ""),
("Export Logs", ""),
("Import Folder", ""),
("Export", "خروجی گرفتن"),
("Export Logs", "خروجی گرفتن از گزارش‌ها"),
("Import Folder", "درون‌ریزی پوشه"),
("Copy to clipboard", "در کلیپ بورد کپی کنید"),
("Enable remote printer", "چاپگر از راه دور را فعال کنید"),
("Downloading {}", "بارگیری {}"),
@@ -766,5 +766,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", ""),
("Enable", "فعال‌سازی"),
("Reuse one connection for port forwarding", "استفاده مجدد از یک اتصال برای هدایت پورت"),
("port-forward-mux-tip", "همه اتصال‌های یک هدایت پورت از یک اتصال واحد به دستگاه مقابل عبور می‌کنند، به‌جای اتصال و ورود دوباره برای هر کدام."),
("Enable WebRTC P2P connection", "فعال‌سازی اتصال همتا‌به‌همتای WebRTC"),
("Enable TCP hole punching", "فعال‌سازی تکنیک TCP hole punching"),
].iter().cloned().collect();
}

View File

@@ -659,9 +659,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("screenshot-merged-screen-not-supported-tip", "Yhdistetyn näytön kuvakaappaus ei ole tuettu"),
("screenshot-action-tip", "Valitse, mitä haluat tehdä kuvakaappaukselle"),
("Save as", "Tallenna nimellä"),
("Export", ""),
("Export Logs", ""),
("Import Folder", ""),
("Export", "Vie"),
("Export Logs", "Vie lokit"),
("Import Folder", "Tuo kansio"),
("Copy to clipboard", "Kopioi leikepöydälle"),
("Enable remote printer", "Ota etätulostin käyttöön"),
("Downloading {}", "Ladataan {}"),
@@ -766,5 +766,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", ""),
("Enable", "Ota käyttöön"),
("Reuse one connection for port forwarding", "Käytä yhtä yhteyttä portin edelleenohjaukseen"),
("port-forward-mux-tip", "Välittää kaikki yhden portin edelleenohjauksen yhteydet yhden vastapuoleen avatun yhteyden kautta sen sijaan, että jokaista varten muodostettaisiin yhteys ja kirjauduttaisiin uudelleen."),
("Enable WebRTC P2P connection", "Ota WebRTC P2P yhteys käyttöön"),
("Enable TCP hole punching", "Ota käyttöön TCP hole punching tekniikka"),
].iter().cloned().collect();
}

View File

@@ -659,9 +659,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("screenshot-merged-screen-not-supported-tip", "Actuellement, la prise de capture décran ne prend pas en charge les affichages multiples. Veuillez réessayer après avoir sélectionné un seul affichage."),
("screenshot-action-tip", "Veuillez choisir laction à effectuer avec la capture décran."),
("Save as", "Enregistrer sous"),
("Export", ""),
("Export Logs", ""),
("Import Folder", ""),
("Export", "Exporter"),
("Export Logs", "Exporter les journaux"),
("Import Folder", "Importer un dossier"),
("Copy to clipboard", "Copier dans le presse-papier"),
("Enable remote printer", "Activer limpression à distance"),
("Downloading {}", "Téléchargement de {}"),
@@ -766,5 +766,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", ""),
("Enable", "Activer"),
("Reuse one connection for port forwarding", "Réutiliser une seule connexion pour la redirection de ports"),
("port-forward-mux-tip", "Faire passer toutes les connexions d'une redirection de ports par une seule connexion vers le pair, au lieu de se connecter et de s'authentifier à nouveau pour chacune."),
("Enable WebRTC P2P connection", "Activer la connexion P2P WebRTC"),
("Enable TCP hole punching", "Activer le « hole punching » TCP"),
].iter().cloned().collect();
}

View File

@@ -659,9 +659,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("screenshot-merged-screen-not-supported-tip", "რამდენიმე ეკრანის სურათის გაერთიანება ამჟამად მხარდაჭერილი არ არის. გადართეთ ერთ ეკრანზე და სცადეთ ხელახლა."),
("screenshot-action-tip", "აირჩიეთ, როგორ გავაგრძელოთ ეკრანის სურათთან მუშაობა."),
("Save as", "შენახვა როგორც"),
("Export", ""),
("Export Logs", ""),
("Import Folder", ""),
("Export", "ექსპორტი"),
("Export Logs", "ჟურნალების ექსპორტი"),
("Import Folder", "საქაღალდის იმპორტი"),
("Copy to clipboard", "ბუფერში კოპირება"),
("Enable remote printer", "დისტანციური პრინტერის ჩართვა"),
("Downloading {}", "მიმდინარეობს {}-ის ჩამოტვირთვა"),
@@ -766,5 +766,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", ""),
("Enable", "ჩართვა"),
("Reuse one connection for port forwarding", "პორტის გადამისამართებისთვის ერთი კავშირის ხელახლა გამოყენება"),
("port-forward-mux-tip", "ერთი პორტის გადამისამართების ყველა კავშირი გადის მეორე კომპიუტერთან დამყარებული ერთი კავშირით, ნაცვლად იმისა, რომ თითოეულისთვის თავიდან დაუკავშირდეს და შევიდეს სისტემაში."),
("Enable WebRTC P2P connection", "WebRTC P2P კავშირის ჩართვა"),
("Enable TCP hole punching", "TCP hole punching-ის ჩართვა"),
].iter().cloned().collect();
}

View File

@@ -659,9 +659,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("screenshot-merged-screen-not-supported-tip", "મર્જ કરેલ સ્ક્રીનશોટ સપોર્ટેડ નથી."),
("screenshot-action-tip", "સ્ક્રીનશોટ પછીની ક્રિયા"),
("Save as", "તરીકે સાચવો"),
("Export", ""),
("Export Logs", ""),
("Import Folder", ""),
("Export", "એક્સપોર્ટ કરો"),
("Export Logs", "લોગ એક્સપોર્ટ કરો"),
("Import Folder", "ફોલ્ડર ઇમ્પોર્ટ કરો"),
("Copy to clipboard", "ક્લિપબોર્ડમાં કોપી કરો"),
("Enable remote printer", "રિમોટ પ્રિન્ટર સક્ષમ કરો"),
("Downloading {}", "{} ડાઉનલોડ થઈ રહ્યું છે"),
@@ -766,5 +766,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", ""),
("Enable", "સક્ષમ કરો"),
("Reuse one connection for port forwarding", "પોર્ટ ફોરવર્ડિંગ માટે એક જ કનેક્શન ફરી વાપરો"),
("port-forward-mux-tip", "એક પોર્ટ ફોરવર્ડિંગનાં બધાં કનેક્શન સામેના કમ્પ્યુટર સાથેના એક જ કનેક્શન મારફતે જાય છે, દરેક માટે ફરીથી કનેક્ટ અને લોગિન કરવાને બદલે."),
("Enable WebRTC P2P connection", "WebRTC P2P કનેક્શન સક્ષમ કરો"),
("Enable TCP hole punching", "TCP હોલ પંચિંગ સક્ષમ કરો"),
].iter().cloned().collect();
}

View File

@@ -659,9 +659,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("screenshot-merged-screen-not-supported-tip", "צילום מסך משולב מכל המסכים אינו נתמך"),
("screenshot-action-tip", "בחר פעולה לאחר צילום המסך"),
("Save as", "שמור בשם"),
("Export", ""),
("Export Logs", ""),
("Import Folder", ""),
("Export", "ייצוא"),
("Export Logs", "ייצוא יומנים"),
("Import Folder", "ייבוא תיקייה"),
("Copy to clipboard", "העתק ללוח"),
("Enable remote printer", "אפשר מדפסת מרוחקת"),
("Downloading {}", "מוריד את {}"),
@@ -766,5 +766,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", ""),
("Enable", "הפעל"),
("Reuse one connection for port forwarding", "שימוש חוזר בחיבור אחד להעברת פורטים"),
("port-forward-mux-tip", "כל החיבורים של העברת פורטים אחת עוברים דרך חיבור יחיד למחשב המרוחק, במקום ליצור חיבור חדש ולהיכנס מחדש עבור כל אחד מהם."),
("Enable WebRTC P2P connection", "אפשר חיבור WebRTC P2P"),
("Enable TCP hole punching", "אפשר TCP hole punching"),
].iter().cloned().collect();
}

View File

@@ -659,9 +659,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("screenshot-merged-screen-not-supported-tip", "मर्ज की गई स्क्रीन के स्क्रीनशॉट समर्थित नहीं हैं।"),
("screenshot-action-tip", "स्क्रीनशॉट लेने के बाद की कार्रवाई"),
("Save as", "इस रूप में सहेजें"),
("Export", ""),
("Export Logs", ""),
("Import Folder", ""),
("Export", "एक्सपोर्ट करें"),
("Export Logs", "लॉग एक्सपोर्ट करें"),
("Import Folder", "फ़ोल्डर इंपोर्ट करें"),
("Copy to clipboard", "क्लिपबोर्ड पर कॉपी करें"),
("Enable remote printer", "रिमोट प्रिंटर सक्षम करें"),
("Downloading {}", "{} डाउनलोड हो रहा है"),
@@ -766,5 +766,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", ""),
("Enable", "सक्षम करें"),
("Reuse one connection for port forwarding", "पोर्ट फ़ॉरवर्डिंग के लिए एक ही कनेक्शन दोबारा उपयोग करें"),
("port-forward-mux-tip", "एक पोर्ट फ़ॉरवर्डिंग के सभी कनेक्शन दूसरे कंप्यूटर से बने एक ही कनेक्शन से होकर जाते हैं, हर एक के लिए दोबारा कनेक्ट और लॉगिन करने के बजाय।"),
("Enable WebRTC P2P connection", "WebRTC P2P कनेक्शन सक्षम करें"),
("Enable TCP hole punching", "TCP होल पंचिंग सक्षम करें"),
].iter().cloned().collect();
}

View File

@@ -659,9 +659,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("screenshot-merged-screen-not-supported-tip", "Spajanje snimaka zaslona s više zaslona trenutačno nije podržano. Prebacite se na jedan zaslon i pokušajte ponovno."),
("screenshot-action-tip", "Odaberite kako nastaviti sa snimkom zaslona."),
("Save as", "Spremi kao"),
("Export", ""),
("Export Logs", ""),
("Import Folder", ""),
("Export", "Izvoz"),
("Export Logs", "Izvoz zapisnika"),
("Import Folder", "Uvoz mape"),
("Copy to clipboard", "Kopiraj u međuspremnik"),
("Enable remote printer", "Omogući udaljeni pisač"),
("Downloading {}", "Preuzimanje {}"),
@@ -766,5 +766,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", ""),
("Enable", "Omogući"),
("Reuse one connection for port forwarding", "Ponovno koristi jednu vezu za prosljeđivanje portova"),
("port-forward-mux-tip", "Sve veze jednog prosljeđivanja portova idu kroz jednu vezu prema drugoj strani, umjesto ponovnog povezivanja i prijave za svaku od njih."),
("Enable WebRTC P2P connection", "Omogući WebRTC P2P vezu"),
("Enable TCP hole punching", "Omogući TCP hole punching"),
].iter().cloned().collect();
}

View File

@@ -659,9 +659,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("screenshot-merged-screen-not-supported-tip", "Egyesített képernyőről nem támogatott a képernyőkép készítése"),
("screenshot-action-tip", "Képernyőkép-művelet"),
("Save as", "Mentés másként"),
("Export", ""),
("Export Logs", ""),
("Import Folder", ""),
("Export", "Exportálás"),
("Export Logs", "Naplók exportálása"),
("Import Folder", "Mappa importálása"),
("Copy to clipboard", "Másolás a vágólapra"),
("Enable remote printer", "Távoli nyomtatók engedélyezése"),
("Downloading {}", "{} letöltése"),
@@ -766,5 +766,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", ""),
("Enable", "Engedélyezés"),
("Reuse one connection for port forwarding", "Egyetlen kapcsolat újrafelhasználása a portátirányításhoz"),
("port-forward-mux-tip", "Egy portátirányítás összes kapcsolatát egyetlen, a másik géppel létesített kapcsolaton vezeti át, ahelyett hogy mindegyikhez újra csatlakozna és bejelentkezne."),
("Enable WebRTC P2P connection", "WebRTC P2P kapcsolat engedélyezése"),
("Enable TCP hole punching", "TCP résszűrés engedélyezése"),
].iter().cloned().collect();
}

View File

@@ -659,9 +659,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("screenshot-merged-screen-not-supported-tip", "Menggabungkan tangkapan layar dari beberapa tampilan saat ini tidak didukung. Silakan beralih ke satu tampilan dan coba lagi."),
("screenshot-action-tip", "Silakan pilih cara melanjutkan dengan tangkapan layar."),
("Save as", "Simpan sebagai"),
("Export", ""),
("Export Logs", ""),
("Import Folder", ""),
("Export", "Ekspor"),
("Export Logs", "Ekspor Log"),
("Import Folder", "Impor Folder"),
("Copy to clipboard", "Salin ke papan klip"),
("Enable remote printer", "Aktifkan printer jarak jauh"),
("Downloading {}", "Mendownload {}"),
@@ -766,5 +766,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", ""),
("Enable", "Aktifkan"),
("Reuse one connection for port forwarding", "Gunakan ulang satu koneksi untuk penerusan port"),
("port-forward-mux-tip", "Menyalurkan semua koneksi dari satu penerusan port melalui satu koneksi ke perangkat lain, alih-alih menyambung dan masuk lagi untuk setiap koneksi."),
("Enable WebRTC P2P connection", "Aktifkan koneksi P2P WebRTC"),
("Enable TCP hole punching", "Aktifkan TCP hole punching"),
].iter().cloned().collect();
}

View File

@@ -659,9 +659,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("screenshot-merged-screen-not-supported-tip", "L'unione della cattura di schermate di più display non è attualmente supportata.\nPassa ad un singolo display e riprova."),
("screenshot-action-tip", "Seleziona come continuare con la schermata."),
("Save as", "Salva come"),
("Export", ""),
("Export Logs", ""),
("Import Folder", ""),
("Export", "Esporta"),
("Export Logs", "Esporta i log"),
("Import Folder", "Importa cartella"),
("Copy to clipboard", "Copia negli appunti"),
("Enable remote printer", "Abilita stampante remota"),
("Downloading {}", "Download {}"),
@@ -766,5 +766,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", ""),
("Enable", "Abilita"),
("Reuse one connection for port forwarding", "Riutilizza una sola connessione per l'inoltro delle porte"),
("port-forward-mux-tip", "Fa passare tutte le connessioni di un inoltro di porte su un'unica connessione verso il dispositivo remoto, invece di connettersi e autenticarsi di nuovo per ognuna."),
("Enable WebRTC P2P connection", "Abilita connessione P2P WebRTC"),
("Enable TCP hole punching", "Abilita hole punching TCP"),
].iter().cloned().collect();
}

View File

@@ -659,9 +659,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("screenshot-merged-screen-not-supported-tip", "複数のディスプレイのスクリーンショットの結合は、現在非対応です。単一のディスプレイに切り替えてもう一度お試しください。"),
("screenshot-action-tip", "スクリーンショットを続行する方法を選択してください。"),
("Save as", "保存先"),
("Export", ""),
("Export Logs", ""),
("Import Folder", ""),
("Export", "エクスポート"),
("Export Logs", "ログをエクスポート"),
("Import Folder", "フォルダをインポート"),
("Copy to clipboard", "クリップボードにコピー"),
("Enable remote printer", "リモートプリンターを有効化する"),
("Downloading {}", "{} をダウンロード中"),
@@ -766,5 +766,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", ""),
("Enable", "有効にする"),
("Reuse one connection for port forwarding", "ポート転送で 1 つの接続を再利用する"),
("port-forward-mux-tip", "1 つのポート転送のすべての接続を、相手への 1 本の接続にまとめます。接続ごとに接続とログインをやり直しません。"),
("Enable WebRTC P2P connection", "WebRTC P2P 接続を有効化する"),
("Enable TCP hole punching", "TCP ホールパンチを有効化する"),
].iter().cloned().collect();
}

View File

@@ -378,7 +378,7 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("Screen Share", "화면 공유"),
("ubuntu-21-04-required", "Wayland는 Ubuntu 21.04 이상 버전이 필요합니다."),
("wayland-requires-higher-linux-version", "Wayland는 상위 버전의 Linux 배포판이 필요합니다. X11 데스크탑을 사용하거나 OS를 변경하세요."),
("xdp-portal-unavailable", ""),
("xdp-portal-unavailable", "Wayland 화면 캡처에 실패했습니다. XDG Desktop Portal이 중단되었거나 사용할 수 없습니다. `systemctl --user restart xdg-desktop-portal` 명령으로 다시 시작해 보세요."),
("JumpLink", "점프 링크"),
("Please Select the screen to be shared(Operate on the peer side).", "공유할 화면을 선택하세요 (피어 측에서 작동)"),
("Show RustDesk", "RustDesk 표시"),
@@ -659,9 +659,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("screenshot-merged-screen-not-supported-tip", "현재 다중 디스플레이의 스크린샷 병합이 지원되지 않습니다. 단일 디스플레이로 전환한 후 다시 시도해 주세요."),
("screenshot-action-tip", "스크린샷을 계속 진행할 방법을 선택해 주세요."),
("Save as", "다른 이름으로 저장"),
("Export", ""),
("Export Logs", ""),
("Import Folder", ""),
("Export", "내보내기"),
("Export Logs", "로그 내보내기"),
("Import Folder", "폴더 가져오기"),
("Copy to clipboard", "클립보드에 복사"),
("Enable remote printer", "원격 프린터 허용"),
("Downloading {}", "{} 다운로드 중"),
@@ -766,5 +766,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", ""),
("Enable", "활성화"),
("Reuse one connection for port forwarding", "포트 포워딩에 연결 하나를 재사용"),
("port-forward-mux-tip", "포트 포워딩 하나의 모든 연결을 상대방과의 단일 연결로 전달합니다. 연결마다 다시 접속하고 로그인하지 않습니다."),
("Enable WebRTC P2P connection", "WebRTC P2P 연결 사용"),
("Enable TCP hole punching", "TCP 홀 펀칭 사용"),
].iter().cloned().collect();
}

View File

@@ -659,9 +659,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("screenshot-merged-screen-not-supported-tip", "Бірнеше дисплейдің скриншоттарын біріктіруге қазір қолдау көрсетілмейді. Жеке дисплейге ауысып, қайталап көруді өтінеміз."),
("screenshot-action-tip", "Скриншотпен қалай жалғастыру керектігін таңдауды өтінеміз."),
("Save as", "Басқаша сақтау"),
("Export", ""),
("Export Logs", ""),
("Import Folder", ""),
("Export", "Экспорттау"),
("Export Logs", "Журналдарды экспорттау"),
("Import Folder", "Қалтаны импорттау"),
("Copy to clipboard", "Көшіру-тақтаға көшіру"),
("Enable remote printer", "Қашықтағы принтерді іске қосу"),
("Downloading {}", "{} жүктелуде"),
@@ -766,5 +766,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", ""),
("Enable", "Қосу"),
("Reuse one connection for port forwarding", "Порт бағыттау үшін бір қосылымды қайта пайдалану"),
("port-forward-mux-tip", "Бір порт бағыттаудың барлық қосылымдары әрқайсысы үшін қайта қосылып кірудің орнына қарсы құрылғымен орнатылған бір қосылым арқылы өтеді."),
("Enable WebRTC P2P connection", "WebRTC P2P қосылымын іске қосу"),
("Enable TCP hole punching", "TCP hole punching'ті іске қосу"),
].iter().cloned().collect();
}

View File

@@ -659,9 +659,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("screenshot-merged-screen-not-supported-tip", "Kelių ekranų nuotraukų sujungimas šiuo metu nepalaikomas. Perjunkite į vieną ekraną ir bandykite dar kartą."),
("screenshot-action-tip", "Pasirinkite, ką daryti su ekrano nuotrauka."),
("Save as", "Įrašyti kaip"),
("Export", ""),
("Export Logs", ""),
("Import Folder", ""),
("Export", "Eksportuoti"),
("Export Logs", "Eksportuoti žurnalus"),
("Import Folder", "Importuoti aplanką"),
("Copy to clipboard", "Kopijuoti į iškarpinę"),
("Enable remote printer", "Įgalinti nuotolinį spausdintuvą"),
("Downloading {}", "Atsisiunčiama {}"),
@@ -766,5 +766,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", ""),
("Enable", "Įgalinti"),
("Reuse one connection for port forwarding", "Prievadų peradresavimui naudoti vieną ryšį"),
("port-forward-mux-tip", "Visi vieno prievadų peradresavimo ryšiai eina per vieną ryšį su kitu kompiuteriu, užuot kiekvienam iš jų jungiantis ir prisijungiant iš naujo."),
("Enable WebRTC P2P connection", "Įgalinti WebRTC P2P ryšį"),
("Enable TCP hole punching", "Įgalinti TCP gręžimą (hole punching)"),
].iter().cloned().collect();
}

View File

@@ -659,9 +659,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("screenshot-merged-screen-not-supported-tip", "Vairāku displeju ekrānuzņēmumu apvienošana pašlaik netiek atbalstīta. Lūdzu, pārslēdzieties uz vienu displeju un mēģiniet vēlreiz."),
("screenshot-action-tip", "Lūdzu, atlasiet, kā turpināt darbu ar ekrānuzņēmumu."),
("Save as", "Saglabāt kā"),
("Export", ""),
("Export Logs", ""),
("Import Folder", ""),
("Export", "Eksportēt"),
("Export Logs", "Eksportēt žurnālus"),
("Import Folder", "Importēt mapi"),
("Copy to clipboard", "Kopēt starpliktuvē"),
("Enable remote printer", "Iespējot attālo printeri"),
("Downloading {}", "Notiek {} lejupielāde"),
@@ -766,5 +766,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", ""),
("Enable", "Iespējot"),
("Reuse one connection for port forwarding", "Atkārtoti izmantot vienu savienojumu portu pārsūtīšanai"),
("port-forward-mux-tip", "Visi viena portu pārsūtījuma savienojumi tiek novadīti pa vienu savienojumu ar otru datoru, nevis katram no tiem izveidojot jaunu savienojumu un pieteikšanos."),
("Enable WebRTC P2P connection", "Iespējot WebRTC P2P savienojumu"),
("Enable TCP hole punching", "Iespējot TCP caurumu veidošanu"),
].iter().cloned().collect();
}

View File

@@ -659,9 +659,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("screenshot-merged-screen-not-supported-tip", "മെർജ് ചെയ്ത സ്ക്രീൻഷോട്ട് പിന്തുണയ്ക്കുന്നില്ല."),
("screenshot-action-tip", "സ്ക്രീൻഷോട്ടിന് ശേഷമുള്ള നടപടി"),
("Save as", "പേരിൽ സേവ് ചെയ്യുക"),
("Export", ""),
("Export Logs", ""),
("Import Folder", ""),
("Export", "എക്‌സ്‌പോർട്ട് ചെയ്യുക"),
("Export Logs", "ലോഗുകൾ എക്‌സ്‌പോർട്ട് ചെയ്യുക"),
("Import Folder", "ഫോൾഡർ ഇംപോർട്ട് ചെയ്യുക"),
("Copy to clipboard", "ക്ലിപ്പ്ബോർഡിലേക്ക് കോപ്പി ചെയ്യുക"),
("Enable remote printer", "റിമോട്ട് പ്രിന്റർ അനുവദിക്കുക"),
("Downloading {}", "{} ഡൗൺലോഡ് ചെയ്യുന്നു"),
@@ -766,5 +766,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", ""),
("Enable", "അനുവദിക്കുക"),
("Reuse one connection for port forwarding", "പോർട്ട് ഫോർവേഡിംഗിന് ഒരേ കണക്ഷൻ വീണ്ടും ഉപയോഗിക്കുക"),
("port-forward-mux-tip", "ഒരു പോർട്ട് ഫോർവേഡിംഗിന്റെ എല്ലാ കണക്ഷനുകളും മറ്റേ കമ്പ്യൂട്ടറിലേക്കുള്ള ഒരൊറ്റ കണക്ഷനിലൂടെ കടന്നുപോകുന്നു, ഓരോന്നിനും വീണ്ടും കണക്റ്റ് ചെയ്ത് ലോഗിൻ ചെയ്യുന്നതിനു പകരം."),
("Enable WebRTC P2P connection", "WebRTC P2P കണക്ഷൻ അനുവദിക്കുക"),
("Enable TCP hole punching", "TCP ഹോൾ പഞ്ചിംഗ് അനുവദിക്കുക"),
].iter().cloned().collect();
}

View File

@@ -659,9 +659,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("screenshot-merged-screen-not-supported-tip", "Sammenslåing av skjermbilder fra flere skjermer støttes for øyeblikket ikke. Bytt til én enkelt skjerm og prøv igjen."),
("screenshot-action-tip", "Velg hvordan du vil fortsette med skjermbildet."),
("Save as", "Lagre som"),
("Export", ""),
("Export Logs", ""),
("Import Folder", ""),
("Export", "Eksporter"),
("Export Logs", "Eksporter logger"),
("Import Folder", "Importer mappe"),
("Copy to clipboard", "Kopier til utklipstavlen"),
("Enable remote printer", "Aktiver fjernskriver"),
("Downloading {}", "Laster ned {}"),
@@ -766,5 +766,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", ""),
("Enable", "Aktiver"),
("Reuse one connection for port forwarding", "Gjenbruk én tilkobling for portvideresending"),
("port-forward-mux-tip", "Fører alle tilkoblinger i en portvideresending gjennom én enkelt tilkobling til motparten i stedet for å koble til og logge inn på nytt for hver enkelt."),
("Enable WebRTC P2P connection", "Aktiver WebRTC P2P-tilkobling"),
("Enable TCP hole punching", "Aktiver TCP hole punching"),
].iter().cloned().collect();
}

View File

@@ -766,5 +766,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", ""),
("Enable", "Inschakelen"),
("Reuse one connection for port forwarding", "Eén verbinding hergebruiken voor poortdoorschakeling"),
("port-forward-mux-tip", "Alle verbindingen van een poortdoorschakeling via één enkele verbinding met de andere computer laten lopen, in plaats van voor elke verbinding opnieuw verbinding te maken en in te loggen."),
("Enable WebRTC P2P connection", "WebRTC P2P-verbinding inschakelen"),
("Enable TCP hole punching", "TCP-hole punching inschakelen"),
].iter().cloned().collect();
}

View File

@@ -659,9 +659,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("screenshot-merged-screen-not-supported-tip", "Łączenie zrzutów ekranu z wielu wyświetlaczy nie jest obecnie obsługiwane. Przełącz się na pojedynczy wyświetlacz i spróbuj ponownie."),
("screenshot-action-tip", "Wybierz sposób kontynuacji zrzutu ekranu."),
("Save as", "Zapisz jako"),
("Export", ""),
("Export Logs", ""),
("Import Folder", ""),
("Export", "Eksportuj"),
("Export Logs", "Eksportuj dzienniki"),
("Import Folder", "Importuj folder"),
("Copy to clipboard", "Kopiuj do schowka"),
("Enable remote printer", "Włącz zdalne drukowanie"),
("Downloading {}", "Pobieranie {}"),
@@ -766,5 +766,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", ""),
("Enable", "Włącz"),
("Reuse one connection for port forwarding", "Użyj ponownie jednego połączenia do przekierowania portów"),
("port-forward-mux-tip", "Przekazuj wszystkie połączenia jednego przekierowania portów przez jedno połączenie ze zdalnym komputerem, zamiast łączyć się i logować od nowa dla każdego z nich."),
("Enable WebRTC P2P connection", "Włącz połączenie P2P WebRTC"),
("Enable TCP hole punching", "Włącz tworzenie tunelu TCP"),
].iter().cloned().collect();
}

View File

@@ -659,9 +659,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("screenshot-merged-screen-not-supported-tip", "A junção de capturas de ecrã de vários ecrãs não é atualmente suportada. Mude para um único ecrã e tente novamente."),
("screenshot-action-tip", "Selecione como pretende continuar com a captura de ecrã."),
("Save as", "Guardar como"),
("Export", ""),
("Export Logs", ""),
("Import Folder", ""),
("Export", "Exportar"),
("Export Logs", "Exportar Registos"),
("Import Folder", "Importar Pasta"),
("Copy to clipboard", "Copiar para a área de transferência"),
("Enable remote printer", "Ativar impressora remota"),
("Downloading {}", "A transferir {}"),
@@ -766,5 +766,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", ""),
("Enable", "Ativar"),
("Reuse one connection for port forwarding", "Reutilizar uma ligação para o reencaminhamento de portas"),
("port-forward-mux-tip", "Encaminhar todas as ligações de um reencaminhamento de portas por uma única ligação ao outro computador, em vez de ligar e iniciar sessão novamente para cada uma."),
("Enable WebRTC P2P connection", "Ativar ligação P2P por WebRTC"),
("Enable TCP hole punching", "Ativar TCP hole punching"),
].iter().cloned().collect();
}

View File

@@ -766,5 +766,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", ""),
("Enable", "Habilitar"),
("Reuse one connection for port forwarding", "Reutilizar uma conexão para encaminhamento de portas"),
("port-forward-mux-tip", "Levar todas as conexões de um encaminhamento de portas por uma única conexão com o outro computador, em vez de conectar e fazer login novamente para cada uma."),
("Enable WebRTC P2P connection", "Habilitar conexão WebRTC P2P"),
("Enable TCP hole punching", "Habilitar TCP hole punching"),
].iter().cloned().collect();
}

View File

@@ -659,9 +659,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("screenshot-merged-screen-not-supported-tip", "Captura de ecran a ecranului combinat nu este suportată în prezent."),
("screenshot-action-tip", "Selectează acțiunea pentru captura de ecran: salvează ca fișier sau copiază în clipboard."),
("Save as", "Salvează ca"),
("Export", ""),
("Export Logs", ""),
("Import Folder", ""),
("Export", "Exportă"),
("Export Logs", "Exportă jurnalele"),
("Import Folder", "Importă folder"),
("Copy to clipboard", "Copiază în clipboard"),
("Enable remote printer", "Activează imprimanta la distanță"),
("Downloading {}", "Se descarcă {}"),
@@ -766,5 +766,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", ""),
("Enable", "Activează"),
("Reuse one connection for port forwarding", "Reutilizează o singură conexiune pentru redirecționarea porturilor"),
("port-forward-mux-tip", "Trece toate conexiunile unei redirecționări de porturi printr-o singură conexiune către celălalt calculator, în loc să se conecteze și să se autentifice din nou pentru fiecare."),
("Enable WebRTC P2P connection", "Activează conexiunea P2P prin WebRTC"),
("Enable TCP hole punching", "Activează traversarea TCP (hole punching)"),
].iter().cloned().collect();
}

View File

@@ -659,9 +659,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("screenshot-merged-screen-not-supported-tip", "Объединение снимков экранов с нескольких дисплеев в настоящее время не поддерживается. Переключитесь на один дисплей и повторите действие."),
("screenshot-action-tip", "Выберите, что делать с полученным снимком экрана."),
("Save as", "Сохранить в файл"),
("Export", ""),
("Export Logs", ""),
("Import Folder", ""),
("Export", "Экспортировать"),
("Export Logs", "Экспортировать журналы"),
("Import Folder", "Импортировать папку"),
("Copy to clipboard", "Копировать в буфер обмена"),
("Enable remote printer", "Использовать удалённый принтер"),
("Downloading {}", "Скачивание"),
@@ -766,5 +766,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", ""),
("Enable", "Включить"),
("Reuse one connection for port forwarding", "Использовать одно подключение для перенаправления портов"),
("port-forward-mux-tip", "Передавать все соединения одного перенаправления портов через одно подключение к удалённому устройству вместо повторного подключения и входа для каждого из них."),
("Enable WebRTC P2P connection", "Использовать подключение WebRTC P2P"),
("Enable TCP hole punching", "Использовать TCP hole punching"),
].iter().cloned().collect();
}

View File

@@ -659,9 +659,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("screenshot-merged-screen-not-supported-tip", "S'unione de sa catura de ischermadas de prus ischermos como no est suportada.\nCola a un'ischermu ebbia e torra a proare."),
("screenshot-action-tip", "Seletziona comente sighire cun s'ischermada."),
("Save as", "Sarva comente"),
("Export", ""),
("Export Logs", ""),
("Import Folder", ""),
("Export", "Esporta"),
("Export Logs", "Esporta is registros"),
("Import Folder", "Importa cartella"),
("Copy to clipboard", "Còpia in punta de billete"),
("Enable remote printer", "Abìlita imprentadora remota"),
("Downloading {}", "Iscarrighende {}"),
@@ -766,5 +766,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", ""),
("Enable", "Abìlita"),
("Reuse one connection for port forwarding", "Torra a impreare una connessione pro s'imbiu de is portas"),
("port-forward-mux-tip", "Totu is connessiones de un'imbiu de portas passant in una connessione ebbia a s'àteru computadore, in logu de si connètere e intrare torra pro dontzi una."),
("Enable WebRTC P2P connection", "Abìlita connessione P2P WebRTC"),
("Enable TCP hole punching", "Abìlita s'istampadura TCP"),
].iter().cloned().collect();
}

View File

@@ -659,9 +659,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("screenshot-merged-screen-not-supported-tip", "Zlučovanie snímok obrazovky z viacerých displejov nie je momentálne podporované. Prepnite na jeden displej a skúste to znova."),
("screenshot-action-tip", "Vyberte, ako pokračovať so snímkou obrazovky."),
("Save as", "Uložiť ako"),
("Export", ""),
("Export Logs", ""),
("Import Folder", ""),
("Export", "Exportovať"),
("Export Logs", "Exportovať protokoly"),
("Import Folder", "Importovať priečinok"),
("Copy to clipboard", "Kopírovať do schránky"),
("Enable remote printer", "Povoliť vzdialenú tlačiareň"),
("Downloading {}", "Sťahuje sa {}"),
@@ -766,5 +766,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", ""),
("Enable", "Povoliť"),
("Reuse one connection for port forwarding", "Znovu použiť jedno pripojenie na presmerovanie portov"),
("port-forward-mux-tip", "Vedie všetky pripojenia jedného presmerovania portov cez jediné pripojenie k druhej strane namiesto opakovaného pripájania a prihlasovania pre každé z nich."),
("Enable WebRTC P2P connection", "Povoliť pripojenie WebRTC P2P"),
("Enable TCP hole punching", "Povoliť TCP hole punching"),
].iter().cloned().collect();
}

View File

@@ -659,9 +659,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("screenshot-merged-screen-not-supported-tip", "Združevanje posnetkov zaslona z več zaslonov trenutno ni podprto. Preklopite na en zaslon in poskusite znova."),
("screenshot-action-tip", "Izberite, kako nadaljevati s posnetkom zaslona."),
("Save as", "Shrani kot"),
("Export", ""),
("Export Logs", ""),
("Import Folder", ""),
("Export", "Izvozi"),
("Export Logs", "Izvozi dnevnike"),
("Import Folder", "Uvozi mapo"),
("Copy to clipboard", "Kopiraj v odložišče"),
("Enable remote printer", "Omogoči oddaljeni tiskalnik"),
("Downloading {}", "Prenašanje {}"),
@@ -766,5 +766,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", ""),
("Enable", "Omogoči"),
("Reuse one connection for port forwarding", "Ponovno uporabi eno povezavo za posredovanje vrat"),
("port-forward-mux-tip", "Vse povezave enega posredovanja vrat potekajo prek ene same povezave do druge strani, namesto ponovnega povezovanja in prijave za vsako od njih."),
("Enable WebRTC P2P connection", "Omogoči povezavo WebRTC P2P"),
("Enable TCP hole punching", "Omogoči preboj lukenj TCP"),
].iter().cloned().collect();
}

View File

@@ -659,9 +659,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("screenshot-merged-screen-not-supported-tip", "Bashkimi i pamjeve të ekranit nga disa ekrane aktualisht nuk mbështetet. Ju lutemi kaloni te një ekran i vetëm dhe provoni përsëri."),
("screenshot-action-tip", "Ju lutemi zgjidhni si të vazhdoni me pamjen e ekranit."),
("Save as", "Ruaj si"),
("Export", ""),
("Export Logs", ""),
("Import Folder", ""),
("Export", "Eksporto"),
("Export Logs", "Eksporto regjistrat"),
("Import Folder", "Importo dosjen"),
("Copy to clipboard", "Kopjo te clipboard"),
("Enable remote printer", "Aktivizo printerin në distancë"),
("Downloading {}", "Duke shkarkuar {}"),
@@ -766,5 +766,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", ""),
("Enable", "Aktivizo"),
("Reuse one connection for port forwarding", "Ripërdor një lidhje për përcjelljen e porteve"),
("port-forward-mux-tip", "Të gjitha lidhjet e një përcjelljeje portesh kalojnë përmes një lidhjeje të vetme me kompjuterin tjetër, në vend që të lidhet dhe të hyjë sërish për secilën prej tyre."),
("Enable WebRTC P2P connection", "Aktivizo lidhjen WebRTC P2P"),
("Enable TCP hole punching", "Aktivizo TCP hole punching"),
].iter().cloned().collect();
}

View File

@@ -659,9 +659,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("screenshot-merged-screen-not-supported-tip", "Spajanje snimaka ekrana sa više prikaza trenutno nije podržano. Molimo prebacite na jedan prikaz i pokušajte ponovo."),
("screenshot-action-tip", "Molimo izaberite kako da nastavite sa snimkom ekrana."),
("Save as", "Sačuvaj kao"),
("Export", ""),
("Export Logs", ""),
("Import Folder", ""),
("Export", "Izvoz"),
("Export Logs", "Izvoz dnevnika"),
("Import Folder", "Uvoz fascikle"),
("Copy to clipboard", "Kopiraj u clipboard"),
("Enable remote printer", "Omogući udaljeni štampač"),
("Downloading {}", "Preuzimanje {}"),
@@ -766,5 +766,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", ""),
("Enable", "Omogući"),
("Reuse one connection for port forwarding", "Ponovo koristi jednu vezu za prosleđivanje portova"),
("port-forward-mux-tip", "Sve veze jednog prosleđivanja portova idu kroz jednu vezu ka drugoj strani, umesto povezivanja i prijavljivanja iznova za svaku od njih."),
("Enable WebRTC P2P connection", "Omogući WebRTC P2P konekciju"),
("Enable TCP hole punching", "Omogući TCP hole punching"),
].iter().cloned().collect();
}

View File

@@ -766,5 +766,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", ""),
("Enable", "Aktivera"),
("Reuse one connection for port forwarding", "Återanvänd en anslutning för portvidarebefordran"),
("port-forward-mux-tip", "Låt alla anslutningar i en portvidarebefordran gå via en enda anslutning till motparten, i stället för att ansluta och logga in på nytt för varje anslutning."),
("Enable WebRTC P2P connection", "Aktivera WebRTC P2P anslutning"),
("Enable TCP hole punching", "Aktivera TCP hålslagning"),
].iter().cloned().collect();
}

View File

@@ -659,9 +659,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("screenshot-merged-screen-not-supported-tip", "ஸ்கிரீன்ஷாட்_இணைக்கப்பட்ட_திரை_ஆதரவற்ற_குறிப்பு"),
("screenshot-action-tip", "ஸ்கிரீன்ஷாட்_செயல்_குறிப்பு"),
("Save as", "இப்படி சேமி"),
("Export", ""),
("Export Logs", ""),
("Import Folder", ""),
("Export", "ஏற்றுமதி"),
("Export Logs", "பதிவுகளை ஏற்றுமதி செய்"),
("Import Folder", "கோப்புறையை இறக்குமதி செய்"),
("Copy to clipboard", "கிளிப்போர்டில் நகல்"),
("Enable remote printer", "தொலை அச்சுப்பொறி இயக்கு"),
("Downloading {}", "{} பதிவிறக்குகிறது"),
@@ -766,5 +766,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", ""),
("Enable", "இயக்கு"),
("Reuse one connection for port forwarding", "போர்ட் ஃபார்வேர்டிங்கிற்கு ஒரே இணைப்பை மீண்டும் பயன்படுத்து"),
("port-forward-mux-tip", "ஒரு போர்ட் ஃபார்வேர்டிங்கின் அனைத்து இணைப்புகளும் மறுமுனைக்கான ஒரே இணைப்பின் வழியாகச் செல்லும், ஒவ்வொன்றுக்கும் மீண்டும் இணைந்து உள்நுழைவதற்குப் பதிலாக."),
("Enable WebRTC P2P connection", "WebRTC P2P இணைப்பு இயக்கு"),
("Enable TCP hole punching", "TCP hole punching இயக்கு"),
].iter().cloned().collect();
}

View File

@@ -766,5 +766,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", ""),
("Enable", ""),
("Reuse one connection for port forwarding", ""),
("port-forward-mux-tip", ""),
("Enable WebRTC P2P connection", ""),
("Enable TCP hole punching", ""),
].iter().cloned().collect();
}

View File

@@ -659,9 +659,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("screenshot-merged-screen-not-supported-tip", "ขณะนี้ยังไม่รองรับการรวมภาพหน้าจอจากหลายจอแสดงผล กรุณาสลับไปใช้จอแสดงผลเดียวแล้วลองใหม่"),
("screenshot-action-tip", "กรุณาเลือกวิธีดำเนินการต่อกับภาพหน้าจอ"),
("Save as", "บันทึกเป็น"),
("Export", ""),
("Export Logs", ""),
("Import Folder", ""),
("Export", "ส่งออก"),
("Export Logs", "ส่งออกบันทึกการทำงาน"),
("Import Folder", "นำเข้าโฟลเดอร์"),
("Copy to clipboard", "คัดลอกไปยังคลิปบอร์ด"),
("Enable remote printer", "เปิดใช้งานเครื่องพิมพ์ระยะไกล"),
("Downloading {}", "กำลังดาวน์โหลด {}"),
@@ -766,5 +766,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", ""),
("Enable", "เปิดใช้งาน"),
("Reuse one connection for port forwarding", "ใช้การเชื่อมต่อเดียวร่วมกันสำหรับการส่งต่อพอร์ต"),
("port-forward-mux-tip", "ส่งการเชื่อมต่อทั้งหมดของการส่งต่อพอร์ตหนึ่งรายการผ่านการเชื่อมต่อเดียวไปยังอีกฝ่าย แทนการเชื่อมต่อและเข้าสู่ระบบใหม่ทุกครั้ง"),
("Enable WebRTC P2P connection", "เปิดใช้งานการเชื่อมต่อ P2P แบบ WebRTC"),
("Enable TCP hole punching", "เปิดใช้งาน TCP hole punching"),
].iter().cloned().collect();
}

View File

@@ -659,9 +659,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("screenshot-merged-screen-not-supported-tip", "Birden fazla ekranın ekran görüntülerinin birleştirilmesi şu anda desteklenmiyor. Lütfen tek bir ekrana geçin ve tekrar deneyin."),
("screenshot-action-tip", "Lütfen ekran görüntüsüyle nasıl devam edeceğinizi seçin."),
("Save as", "Farklı kaydet"),
("Export", ""),
("Export Logs", ""),
("Import Folder", ""),
("Export", "Dışa aktar"),
("Export Logs", "Günlükleri dışa aktar"),
("Import Folder", "Klasör içe aktar"),
("Copy to clipboard", "Panoya kopyala"),
("Enable remote printer", "Uzak yazıcıyı etkinleştir"),
("Downloading {}", "{} indiriliyor"),
@@ -766,5 +766,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", ""),
("Enable", "Etkinleştir"),
("Reuse one connection for port forwarding", "Port yönlendirme için tek bağlantıyı yeniden kullan"),
("port-forward-mux-tip", "Bir port yönlendirmesindeki tüm bağlantıları, her biri için yeniden bağlanıp oturum açmak yerine karşı tarafa açılan tek bir bağlantı üzerinden taşır."),
("Enable WebRTC P2P connection", "WebRTC P2P bağlantısını etkinleştir"),
("Enable TCP hole punching", "TCP delik açmayı etkinleştir"),
].iter().cloned().collect();
}

View File

@@ -766,5 +766,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", ""),
("Enable", "啟用"),
("Reuse one connection for port forwarding", "連接埠轉送重複使用同一條連線"),
("port-forward-mux-tip", "同一條連接埠轉送規則上的所有連線共用一條到對方的連線,而不是每條連線都重新連線並登入一次。"),
("Enable WebRTC P2P connection", "啟用 WebRTC P2P 連線"),
("Enable TCP hole punching", "啟用 TCP 打洞"),
].iter().cloned().collect();
}

View File

@@ -659,9 +659,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("screenshot-merged-screen-not-supported-tip", "Об'єднання знімків кількох дисплеїв наразі не підтримується. Перейдіть на один дисплей і спробуйте знову."),
("screenshot-action-tip", "Виберіть, що робити зі знімком екрана."),
("Save as", "Зберегти як"),
("Export", ""),
("Export Logs", ""),
("Import Folder", ""),
("Export", "Експортувати"),
("Export Logs", "Експортувати журнали"),
("Import Folder", "Імпортувати теку"),
("Copy to clipboard", "Скопіювати до буфера обміну"),
("Enable remote printer", "Увімкнути віддалений принтер"),
("Downloading {}", "Завантаження {}"),
@@ -766,5 +766,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", ""),
("Enable", "Увімкнути"),
("Reuse one connection for port forwarding", "Використовувати одне з'єднання для перенаправлення портів"),
("port-forward-mux-tip", "Передавати всі з'єднання одного перенаправлення портів через одне з'єднання з віддаленим пристроєм замість повторного під'єднання та входу для кожного з них."),
("Enable WebRTC P2P connection", "Увімкнути P2P-підключення через WebRTC"),
("Enable TCP hole punching", "Увімкнути TCP hole punching"),
].iter().cloned().collect();
}

View File

@@ -3,7 +3,7 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
[
("Status", "حالت"),
("Your Desktop", "آپ کا ڈیسک ٹاپ"),
("desk_tip", ""),
("desk_tip", "آپ کے ڈیسک ٹاپ تک اس ID اور پاس ورڈ کے ذریعے رسائی حاصل کی جا سکتی ہے۔"),
("Password", "پاس ورڈ"),
("Ready", "تیار"),
("Established", "قائم کیا گیا"),
@@ -12,7 +12,7 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("Start service", "سروس شروع کریں"),
("Service is running", "سروس چل رہی ہے"),
("Service is not running", "سروس نہیں چل رہی ہے"),
("not_ready_status", ""),
("not_ready_status", "تیار نہیں۔ براہِ کرم اپنا کنکشن جانچیں"),
("Control Remote Desktop", "ریموٹ ڈیسک ٹاپ کو کنٹرول کریں"),
("Transfer file", "فائل منتقل کریں"),
("Connect", "کنیکٹ کریں"),
@@ -41,12 +41,11 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("length %min% to %max%", "لمبائی %min% سے %max%"),
("starts with a letter", "حرف سے شروع ہوتا ہے"),
("allowed characters", "اجازت یافتہ حروف"),
("id_change_tip", ""),
("id_change_tip", "صرف a-z، A-Z، 0-9، - (ڈیش) اور _ (انڈر اسکور) حروف کی اجازت ہے۔ پہلا حرف a-z یا A-Z ہونا چاہیے۔ لمبائی 6 سے 16 کے درمیان ہو۔"),
("Website", "ویب سائٹ"),
("About", "کے بارے میں"),
("Slogan_tip", "سلوگن_ٹپ"),
("Privacy Statement", "رازداری کا بیان"),
("License", "لائسنس"),
("Mute", "خاموش"),
("Build Date", "بنیاد کی تاریخ"),
("Version", "ورژن"),
@@ -149,21 +148,20 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("install_tip", "انسٹال کرنے کا مشورہ"),
("Click to upgrade", "اپگریڈ کرنے کے لئے کلک کریں"),
("Configure", "ترتیب دینا"),
("config_acc", ""),
("config_screen", ""),
("config_acc", "اپنے ڈیسک ٹاپ کو دور سے کنٹرول کرنے کے لیے آپ کو RustDesk کو \"Accessibility\" کی اجازتیں دینا ہوں گی۔"),
("config_screen", "اپنے ڈیسک ٹاپ تک دور سے رسائی کے لیے آپ کو RustDesk کو \"Screen Recording\" کی اجازتیں دینا ہوں گی۔"),
("Installing ...", "انسٹال ہو رہا ہے..."),
("Install", "انسٹال کریں"),
("Installation", "انسٹالیشن"),
("Installation Path", "انسٹالیشن کا راستہ"),
("Create start menu shortcuts", "اسٹارٹ مینو شارٹ کٹس بنائیں"),
("Create desktop icon", "ڈیسکٹاپ آئیکن بنائیں"),
("agreement_tip", ""),
("agreement_tip", "انسٹالیشن شروع کرنے سے آپ لائسنس معاہدہ قبول کرتے ہیں۔"),
("Accept and Install", "قبول کریں اور انسٹال کریں"),
("End-user license agreement", "اختتامی صارف کے لائسنس کا معاہدہ"),
("Generating ...", "بنا رہے ہیں..."),
("Your installation is lower version.", "آپ کی تنصیب کم ورژن ہے۔"),
("Please install the latest version.", "براہِ مہربانی تازہ ترین ورژن انسٹال کریں۔"),
("not_close_tcp_tip", ""),
("not_close_tcp_tip", "جب تک آپ ٹنل استعمال کر رہے ہیں، یہ ونڈو بند نہ کریں"),
("Listening ...", "سن رہا ہے..."),
("Remote Host", "ریموٹ میزبان"),
("Remote Port", "ریموٹ پورٹ"),
@@ -212,7 +210,7 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("Run without install", "انسٹال کے بغیر چلائیں"),
("Connect via relay", "ریلے کے ذریعے کنیکٹ کریں"),
("Always connect via relay", "ہمیشہ ریلے کے ذریعے کنیکٹ کریں"),
("whitelist_tip", ""),
("whitelist_tip", "صرف وائٹ لسٹ میں شامل IP مجھ تک رسائی حاصل کر سکتے ہیں"),
("Login", "لاگ ان کریں"),
("Verify", "تصدیق کریں"),
("Remember me", "یاد رکھیں"),
@@ -222,7 +220,7 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("Logout", "لاگ آؤٹ"),
("Tags", "ٹیگز"),
("Search ID", "ID تلاش کریں"),
("whitelist_sep", ""),
("whitelist_sep", "کوما، سیمی کولن، خالی جگہ یا نئی سطر سے الگ کریں"),
("Add ID", "ID شامل کریں"),
("Add Tag", "ٹیگ شامل کریں"),
("Unselect all tags", "تمام ٹیگز کو غیر منتخب کریں"),
@@ -241,7 +239,7 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("Socks5 Proxy", "پروکسی ساکس5"),
("Socks5/Http(s) Proxy", "ساکس5/Http(s) پروکسی"),
("Discovered", "دریافت شدہ"),
("install_daemon_tip", ""),
("install_daemon_tip", "بوٹ پر شروع ہونے کے لیے آپ کو سسٹم سروس انسٹال کرنا ہوگی۔"),
("Remote ID", "ریموٹ ID"),
("Paste", "چسپاں کریں"),
("Paste here?", "یہاں چسپاں کریں؟"),
@@ -278,14 +276,14 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("Do you accept?", "کیا آپ قبول کرتے ہیں؟"),
("Open System Setting", "سسٹم کی ترتیبات کھولیں"),
("How to get Android input permission?", "Android کی درآمد کی اجازت کیسے حاصل کریں؟"),
("android_input_permission_tip1", ""),
("android_input_permission_tip2", ""),
("android_new_connection_tip", ""),
("android_service_will_start_tip", ""),
("android_stop_service_tip", ""),
("android_version_audio_tip", ""),
("android_start_service_tip", ""),
("android_permission_may_not_change_tip", ""),
("android_input_permission_tip1", "کسی دور دراز آلے کو ماؤس یا ٹچ کے ذریعے آپ کے Android آلے کو کنٹرول کرنے کے لیے آپ کو RustDesk کو \"Accessibility\" سروس استعمال کرنے کی اجازت دینا ہوگی۔"),
("android_input_permission_tip2", "براہِ کرم اگلے سسٹم سیٹنگز صفحے پر جائیں، [Installed Services] تلاش کر کے کھولیں اور [RustDesk Input] سروس آن کریں۔"),
("android_new_connection_tip", "ایک نئی کنٹرول درخواست موصول ہوئی ہے، جو آپ کے موجودہ آلے کو کنٹرول کرنا چاہتی ہے۔"),
("android_service_will_start_tip", "\"Screen Capture\" آن کرنے سے سروس خودکار طور پر شروع ہو جائے گی، جس سے دوسرے آلات آپ کے آلے سے کنکشن کی درخواست کر سکیں گے۔"),
("android_stop_service_tip", "سروس بند کرنے سے تمام قائم شدہ کنکشن خودکار طور پر بند ہو جائیں گے۔"),
("android_version_audio_tip", "موجودہ Android ورژن آڈیو کیپچر کی حمایت نہیں کرتا، براہِ کرم Android 10 یا اس سے نئے ورژن پر اپ گریڈ کریں۔"),
("android_start_service_tip", "اسکرین شیئرنگ سروس شروع کرنے کے لیے [Start service] پر ٹیپ کریں یا [Screen Capture] کی اجازت فعال کریں۔"),
("android_permission_may_not_change_tip", "قائم شدہ کنکشنز کی اجازتیں دوبارہ منسلک ہونے تک فوراً تبدیل نہیں ہو سکتیں۔"),
("Account", "کھاتا"),
("Overwrite", "اوور رائٹ کریں"),
("This file exists, skip or overwrite this file?", "یہ فائل موجود ہے، اس فائل کو چھوڑیں یا اوور رائٹ کریں؟"),
@@ -296,14 +294,13 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("Someone turns on privacy mode, exit", "کوئی پرائیویسی موڈ آن کرتا ہے، باہر نکلیں"),
("Unsupported", "غیر معاون"),
("Peer denied", "ہم منسب نے انکار کر دیا"),
("Please install plugins", "براہِ مہربانی پلگ ان انسٹال کریں"),
("Peer exit", "ہم منسب باہر نکل گیا"),
("Failed to turn off", "بند کرنے میں ناکام"),
("Turned off", "بند کر دیا"),
("Language", "زبان"),
("Keep RustDesk background service", "RustDesk پس منظر کی خدمت کو برقرار رکھیں"),
("Ignore Battery Optimizations", "بیٹری کی اصلاحات کو نظر انداز کریں"),
("android_open_battery_optimizations_tip", ""),
("android_open_battery_optimizations_tip", "اگر آپ یہ خصوصیت بند کرنا چاہتے ہیں تو براہِ کرم اگلے RustDesk ایپلیکیشن سیٹنگز صفحے پر جائیں، [Battery] تلاش کر کے کھولیں اور [Unrestricted] کا نشان ہٹا دیں"),
("Start on boot", "شروع کرنے پر شروع کریں"),
("Start the screen sharing service on boot, requires special permissions", "بوٹ پر سکرین شیئرنگ سروس شروع کریں، خاص اجازتوں کی ضرورت ہے"),
("Connection not allowed", "جڑنے کی اجازت نہیں ہے"),
@@ -317,7 +314,7 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("Restart remote device", "ریموٹ ڈیوائس کو ری اسٹارٹ کریں"),
("Are you sure you want to restart", "کیا آپ واقعی ری اسٹارٹ کرنا چاہتے ہیں؟"),
("Restarting remote device", "ریموٹ ڈیوائس ری اسٹارٹ ہو رہی ہے"),
("remote_restarting_tip", ""),
("remote_restarting_tip", "دور دراز آلہ دوبارہ شروع ہو رہا ہے، براہِ کرم یہ پیغام بند کریں اور کچھ دیر بعد مستقل پاس ورڈ کے ساتھ دوبارہ منسلک ہوں"),
("Copied", "نقل ہو گیا"),
("Exit Fullscreen", "مکمل سکرین سے باہر نکلیں"),
("Fullscreen", "مکمل سکرین"),
@@ -408,19 +405,19 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("Closed manually by web console", "ویب کنسول کے ذریعے دستی طور پر بند کیا گیا"),
("Local keyboard type", "مقامی کیبورڈ کا قسم"),
("Select local keyboard type", "مقامی کیبورڈ کا قسم منتخب کریں"),
("software_render_tip", ""),
("software_render_tip", "اگر آپ Linux پر Nvidia گرافکس کارڈ استعمال کر رہے ہیں اور منسلک ہونے کے فوراً بعد ریموٹ ونڈو بند ہو جاتی ہے، تو اوپن سورس Nouveau ڈرائیور پر منتقل ہونا اور سافٹ ویئر رینڈرنگ کا انتخاب مددگار ہو سکتا ہے۔ سافٹ ویئر کو دوبارہ شروع کرنا ضروری ہے۔"),
("Always use software rendering", "ہم sempre سافٹ ویر رینڈرنگ استعمال کریں"),
("config_input", "config_input"),
("config_microphone", ""),
("request_elevation_tip", ""),
("config_microphone", "دور سے بات کرنے کے لیے آپ کو RustDesk کو \"Record Audio\" کی اجازتیں دینا ہوں گی۔"),
("request_elevation_tip", "اگر دوسری طرف کوئی موجود ہے تو آپ اختیارات میں اضافے کی درخواست بھی کر سکتے ہیں۔"),
("Wait", "انتظار کریں"),
("Elevation Error", "علیٰ کرنے کی خرابی"),
("Ask the remote user for authentication", "ریموٹ صارف سے تصدیق کے لیے پوچھیں"),
("Choose this if the remote account is administrator", "ریموٹ اکاؤنٹ ایڈمنسٹریٹر ہو تو یہ منتخب کریں"),
("Transmit the username and password of administrator", "ایڈمنسٹریٹر کا صارف نام اور پاس ورڈ پروگرام کے ذریعے بھیجیں"),
("still_click_uac_tip", ""),
("still_click_uac_tip", "پھر بھی ضروری ہے کہ دور دراز صارف چل رہے RustDesk کی UAC ونڈو پر OK پر کلک کرے۔"),
("Request Elevation", "علیٰ کرنے کا درخواست دیں"),
("wait_accept_uac_tip", ""),
("wait_accept_uac_tip", "براہِ کرم انتظار کریں کہ دور دراز صارف UAC ڈائیلاگ قبول کرے۔"),
("Elevate successfully", "علیٰ کامیابی سے ہو گئے"),
("uppercase", "بڑے حروف"),
("lowercase", "چھوٹے حروف"),
@@ -438,7 +435,7 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("Default Image Quality", "ڈیفالٹ تصویر کی معیار"),
("Default Codec", "ڈیفالٹ کوڈک"),
("Bitrate", "بٹ ریٹ"),
("FPS", ""),
("FPS", "FPS"),
("Auto", "خودکار"),
("Other Default Options", "دوسروں ڈیفالٹ اختیارات"),
("Voice call", "صوتی کال"),
@@ -464,20 +461,10 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("Empty Username", "خالی صارف نام"),
("Empty Password", "خالی پاس ورڈ"),
("Me", "میں"),
("identical_file_tip", ""),
("show_monitors_tip", ""),
("identical_file_tip", "یہ فائل دوسری طرف موجود فائل کے بالکل یکساں ہے۔"),
("show_monitors_tip", "ٹول بار میں مانیٹر دکھائیں"),
("View Mode", "دیکھنے کا طریقہ"),
("login_linux_tip", "login_linux_tip"),
("verify_rustdesk_password_tip", ""),
("remember_account_tip", ""),
("os_account_desk_tip", ""),
("OS Account", "OS اکاؤنٹ"),
("another_user_login_title_tip", ""),
("another_user_login_text_tip", ""),
("xorg_not_found_title_tip", ""),
("xorg_not_found_text_tip", ""),
("no_desktop_title_tip", ""),
("no_desktop_text_tip", ""),
("verify_rustdesk_password_tip", "RustDesk پاس ورڈ کی تصدیق کریں"),
("No need to elevate", "اپنے کو ہیں نہیں"),
("System Sound", "سسٹم سائونڈ"),
("Default", "ڈیفالٹ"),
@@ -485,30 +472,24 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("Fingerprint", "فنگر پرنٹ"),
("Copy Fingerprint", "فنگر پرنٹ کاپی کریں"),
("no fingerprints", "کوئی فنگر پرنٹ نہیں"),
("Select a peer", "ایک پیر منتخب کریں"),
("Select peers", "پیرز منتخب کریں"),
("Plugins", "پلگ انز"),
("Uninstall", "ان انسٹال کریں"),
("Update", "اپڈیٹ کریں"),
("Enable", "فعال کریں"),
("Disable", "غیر فعال کریں"),
("Options", "اختیارات"),
("resolution_original_tip", ""),
("resolution_fit_local_tip", ""),
("resolution_custom_tip", ""),
("resolution_original_tip", "اصل ریزولوشن"),
("resolution_fit_local_tip", "مقامی ریزولوشن کے مطابق"),
("resolution_custom_tip", "حسبِ ضرورت ریزولوشن"),
("Collapse toolbar", "ٹول بار کو سکڑیں"),
("Accept and Elevate", "قبول کریں اور علیٰ کریں"),
("accept_and_elevate_btn_tooltip", ""),
("clipboard_wait_response_timeout_tip", ""),
("accept_and_elevate_btn_tooltip", "کنکشن قبول کریں اور UAC اجازتیں بڑھائیں۔"),
("clipboard_wait_response_timeout_tip", "کاپی کے جواب کا انتظار ختم ہو گیا۔"),
("Incoming connection", "آنے والا کنکشن"),
("Outgoing connection", "جانے والا کنکشن"),
("Exit", "خارج ہوں"),
("Open", "کھولیں"),
("logout_tip", ""),
("logout_tip", "کیا آپ واقعی لاگ آؤٹ کرنا چاہتے ہیں؟"),
("Service", "سروس"),
("Start", "شروع کریں"),
("Stop", "روک دیں"),
("exceed_max_devices", ""),
("exceed_max_devices", "آپ زیرِ انتظام آلات کی زیادہ سے زیادہ تعداد تک پہنچ چکے ہیں۔"),
("Sync with recent sessions", "پچھلے سیشنز کے ساتھ ہم آہنگ کریں"),
("Sort tags", "ٹیگز کو ترتیب دیں"),
("Open connection in new tab", "کنکشن کو نئے ٹیب میں کھولیں"),
@@ -517,14 +498,14 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("Already exists", "پہلے سے موجود ہے"),
("Change Password", "پاسورڈ تبدیل کریں"),
("Refresh Password", "پاسورڈ ریفریش کریں"),
("ID", ""),
("ID", "ID"),
("Grid View", "گوڈ ویو"),
("List View", "لسٹ ویو"),
("Select", "منتخب کریں"),
("Toggle Tags", "ٹیگز ٹوگل کریں"),
("pull_ab_failed_tip", ""),
("push_ab_failed_tip", ""),
("synced_peer_readded_tip", ""),
("pull_ab_failed_tip", "ایڈریس بک تازہ کرنے میں ناکامی"),
("push_ab_failed_tip", "ایڈریس بک کو سرور سے ہم آہنگ کرنے میں ناکامی"),
("synced_peer_readded_tip", "حالیہ سیشنز میں موجود آلات دوبارہ ایڈریس بک سے ہم آہنگ کر دیے جائیں گے۔"),
("Change Color", "رنگ تبدیل کریں"),
("Primary Color", "پرائمری رنگ"),
("HSV Color", "HSV رنگ"),
@@ -539,11 +520,11 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("I Agree", "میں قبول کرتا ہوں"),
("Decline", "ناکام کریں"),
("Timeout in minutes", "منٹوں میں ٹائیم آؤٹ"),
("auto_disconnect_option_tip", ""),
("auto_disconnect_option_tip", "صارف کی غیر فعالی پر آنے والے سیشنز خودکار طور پر بند کریں"),
("Connection failed due to inactivity", "انفعال کی وजہ سے کنکشن ناکام ہو گیا"),
("Check for software update on startup", "سٹارٹ اپ پر سافٹ ویر اپڈیٹ کے لیے چیک کریں"),
("upgrade_rustdesk_server_pro_to_{}_tip", ""),
("pull_group_failed_tip", ""),
("upgrade_rustdesk_server_pro_to_{}_tip", "براہِ کرم RustDesk Server Pro کو ورژن {} یا اس سے نئے پر اپ گریڈ کریں!"),
("pull_group_failed_tip", "گروپ تازہ کرنے میں ناکامی"),
("Filter by intersection", "فلٹر بائی انسٹریکشن"),
("Remove wallpaper during incoming sessions", "ان کلینگ سیشنز کے دوران والپیپر کو ہٹائیں"),
("Test", "ٹیسٹ"),
@@ -552,7 +533,7 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("Open in new window", "نئی ونڈو میں کھولیں"),
("Show displays as individual windows", "ڈسپلے کو افراد کے طور پر دکھائیں"),
("Use all my displays for the remote session", "ریموٹ سیشن کے لیے میرے تمام ڈسپلے استعمال کریں"),
("selinux_tip", ""),
("selinux_tip", "آپ کے آلے پر SELinux فعال ہے، جو RustDesk کو بطور کنٹرول شدہ فریق درست طور پر چلنے سے روک سکتا ہے۔"),
("Change view", "ویو تبدیل کریں"),
("Big tiles", "بڑے ٹائل"),
("Small tiles", "چھوٹے ٹائل"),
@@ -561,14 +542,14 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("Plug out all", "تمام پلگ آؤٹ کریں"),
("True color (4:4:4)", "اصل رنگ (4:4:4)"),
("Enable blocking user input", "صارف ان پٹ کو روکنے کی اجازت دیں"),
("id_input_tip", ""),
("privacy_mode_impl_mag_tip", ""),
("privacy_mode_impl_virtual_display_tip", ""),
("id_input_tip", "آپ ایک ID، براہِ راست IP، یا پورٹ کے ساتھ ڈومین (<domain>:<port>) درج کر سکتے ہیں۔\nاگر آپ کسی دوسرے سرور پر موجود آلے تک رسائی چاہتے ہیں تو سرور کا پتہ ساتھ لگائیں (<id>@<server_address>?key=<key_value>)، مثلاً،\n9123456234@192.168.16.1:21117?key=5Qbwsde3unUcJBtrx9ZkvUmwFNoExHzpryHuPUdqlWM=۔\nاگر آپ کسی عوامی سرور پر موجود آلے تک رسائی چاہتے ہیں تو \"<id>@public\" درج کریں، عوامی سرور کے لیے کلید درکار نہیں۔\n\nاگر آپ پہلے کنکشن پر ریلے کنکشن کا استعمال لازمی کرنا چاہتے ہیں تو ID کے آخر میں \"/r\" شامل کریں، مثلاً، \"9123456234/r\"۔"),
("privacy_mode_impl_mag_tip", "موڈ 1"),
("privacy_mode_impl_virtual_display_tip", "موڈ 2"),
("Enter privacy mode", "خفیہ موڈ میں داخل ہوں"),
("Exit privacy mode", "خفیہ موڈ سے باہر نکلیں"),
("idd_not_support_under_win10_2004_tip", ""),
("input_source_1_tip", ""),
("input_source_2_tip", ""),
("idd_not_support_under_win10_2004_tip", "بالواسطہ ڈسپلے ڈرائیور معاون نہیں ہے۔ Windows 10 ورژن 2004 یا اس سے نیا درکار ہے۔"),
("input_source_1_tip", "ان پٹ ماخذ 1"),
("input_source_2_tip", "ان پٹ ماخذ 2"),
("Swap control-command key", "control-command کلید کو سوپ کریں"),
("swap-left-right-mouse", "بائی-دائی ماؤس کو سوپ کریں"),
("2FA code", "2FA کوڈ"),
@@ -582,8 +563,8 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("Multiple Windows sessions found", "متعدد ونڈوز سیشن ملے"),
("Please select the session you want to connect to", "براہ کرم وہ سیشن منتخب کریں جس سے آپ منسلک ہونا چاہتے ہیں"),
("powered_by_me", "میں کی طرف سے طاقتور"),
("outgoing_only_desk_tip", ""),
("preset_password_warning", ""),
("outgoing_only_desk_tip", "یہ ایک حسبِ ضرورت ایڈیشن ہے۔\nآپ دوسرے آلات سے منسلک ہو سکتے ہیں، لیکن دوسرے آلات آپ کے آلے سے منسلک نہیں ہو سکتے۔"),
("preset_password_warning", "یہ حسبِ ضرورت ایڈیشن پہلے سے مقرر پاس ورڈ کے ساتھ آتا ہے۔ جو بھی یہ پاس ورڈ جانتا ہو وہ آپ کے آلے کا مکمل کنٹرول حاصل کر سکتا ہے۔ اگر آپ کو اس کی توقع نہیں تھی تو سافٹ ویئر فوراً ان انسٹال کر دیں۔"),
("Security Alert", "سیکورٹی الرٹ"),
("My address book", "میری ایڈریس بک"),
("Personal", "شخصی"),
@@ -593,25 +574,25 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("Read-only", "صرف پڑھنے کے لیے"),
("Read/Write", "پڑھنے/لکھنے"),
("Full Control", "پورا کنٹرول"),
("share_warning_tip", ""),
("share_warning_tip", "اوپر دیے گئے خانے مشترکہ ہیں اور دوسروں کو نظر آتے ہیں۔"),
("Everyone", "ہر کوئی"),
("ab_web_console_tip", ""),
("allow-only-conn-window-open-tip", ""),
("no_need_privacy_mode_no_physical_displays_tip", ""),
("ab_web_console_tip", "ویب کنسول پر مزید"),
("allow-only-conn-window-open-tip", "کنکشن کی اجازت صرف اس صورت میں دیں جب RustDesk ونڈو کھلی ہو"),
("no_need_privacy_mode_no_physical_displays_tip", "کوئی طبعی ڈسپلے نہیں، پرائیویسی موڈ استعمال کرنے کی ضرورت نہیں۔"),
("Follow remote cursor", "ریموٹ کرسر کی پیروی کریں"),
("Follow remote window focus", "ریموٹ ونڈو فوکس کی پیروی کریں"),
("default_proxy_tip", ""),
("no_audio_input_device_tip", ""),
("default_proxy_tip", "پہلے سے طے شدہ پروٹوکول اور پورٹ Socks5 اور 1080 ہیں"),
("no_audio_input_device_tip", "کوئی آڈیو ان پٹ آلہ نہیں ملا۔"),
("Incoming", "آنے والے"),
("Outgoing", "بھیجے جا رہے"),
("Clear Wayland screen selection", "Wayland سکرین کی انتخاب صاف کریں"),
("clear_Wayland_screen_selection_tip", ""),
("confirm_clear_Wayland_screen_selection_tip", ""),
("android_new_voice_call_tip", ""),
("texture_render_tip", ""),
("clear_Wayland_screen_selection_tip", "اسکرین کا انتخاب صاف کرنے کے بعد آپ شیئر کرنے کے لیے اسکرین دوبارہ منتخب کر سکتے ہیں۔"),
("confirm_clear_Wayland_screen_selection_tip", "کیا آپ واقعی Wayland اسکرین کا انتخاب صاف کرنا چاہتے ہیں؟"),
("android_new_voice_call_tip", "ایک نئی صوتی کال کی درخواست موصول ہوئی۔ اگر آپ قبول کرتے ہیں تو آڈیو صوتی رابطے پر منتقل ہو جائے گا۔"),
("texture_render_tip", "تصاویر کو ہموار بنانے کے لیے ٹیکسچر رینڈرنگ استعمال کریں۔ اگر آپ کو رینڈرنگ کے مسائل درپیش ہوں تو یہ اختیار بند کر کے دیکھ سکتے ہیں۔"),
("Use texture rendering", "ٹیکسچر رینڈرنگ کا استعمال کریں"),
("Floating window", "فلوٹنگ ونڈو"),
("floating_window_tip", ""),
("floating_window_tip", "یہ RustDesk کی پس منظر سروس کو برقرار رکھنے میں مدد دیتا ہے"),
("Keep screen on", "سکرین کو آن رکھیں"),
("Never", "کبھی نہیں"),
("During controlled", "کنٹرول کے دوران"),
@@ -623,13 +604,13 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("Volume down", "آواز کم کریں"),
("Power", "پاور"),
("Telegram bot", "ٹیلیگرام بات"),
("enable-bot-tip", ""),
("enable-bot-desc", ""),
("cancel-2fa-confirm-tip", ""),
("cancel-bot-confirm-tip", ""),
("enable-bot-tip", "اگر آپ یہ خصوصیت فعال کریں تو آپ اپنے بوٹ سے 2FA کوڈ وصول کر سکتے ہیں۔ یہ کنکشن کی اطلاع کے طور پر بھی کام کر سکتا ہے۔"),
("enable-bot-desc", "1. @BotFather کے ساتھ چیٹ کھولیں۔\n2. کمانڈ \"/newbot\" بھیجیں۔ یہ مرحلہ مکمل کرنے کے بعد آپ کو ایک ٹوکن ملے گا۔\n3. اپنے نئے بنائے گئے بوٹ کے ساتھ چیٹ شروع کریں۔ اسے فعال کرنے کے لیے فارورڈ سلیش (\"/\") سے شروع ہونے والا پیغام، جیسے \"/hello\"، بھیجیں۔\n"),
("cancel-2fa-confirm-tip", "کیا آپ واقعی 2FA منسوخ کرنا چاہتے ہیں؟"),
("cancel-bot-confirm-tip", "کیا آپ واقعی Telegram بوٹ منسوخ کرنا چاہتے ہیں؟"),
("About RustDesk", "رستڈیسک کے بارے میں"),
("Send clipboard keystrokes", "کلپ بورڈ کی چابیاں بھیجیں"),
("network_error_tip", ""),
("network_error_tip", "براہِ کرم اپنا نیٹ ورک کنکشن جانچیں، پھر دوبارہ کوشش پر کلک کریں۔"),
("Unlock with PIN", "PIN کے ساتھ انلاک کریں"),
("Requires at least {} characters", "کم از کم {} حروف کی ضرورت ہے"),
("Wrong PIN", "غلط PIN"),
@@ -638,56 +619,56 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("Manage trusted devices", "معتبر آلے مینیج کریں"),
("Platform", "پلیٹ فارم"),
("Days remaining", "دن باقی"),
("enable-trusted-devices-tip", ""),
("enable-trusted-devices-tip", "قابلِ اعتماد آلات پر 2FA تصدیق چھوڑ دیں"),
("Parent directory", "والد ڈائرکٹری"),
("Resume", "جاری رکھیں"),
("Invalid file name", "غلط فائل کا نام"),
("one-way-file-transfer-tip", ""),
("one-way-file-transfer-tip", "کنٹرول شدہ فریق پر یک طرفہ فائل منتقلی فعال ہے۔"),
("Authentication Required", "توثیق کی ضرورت ہے"),
("Authenticate", "توثیق کریں"),
("web_id_input_tip", ""),
("web_id_input_tip", "آپ اسی سرور میں ایک ID درج کر سکتے ہیں، ویب کلائنٹ میں براہِ راست IP رسائی معاون نہیں ہے۔\nاگر آپ کسی دوسرے سرور پر موجود آلے تک رسائی چاہتے ہیں تو سرور کا پتہ ساتھ لگائیں (<id>@<server_address>?key=<key_value>)، مثلاً،\n9123456234@192.168.16.1:21117?key=5Qbwsde3unUcJBtrx9ZkvUmwFNoExHzpryHuPUdqlWM=۔\nاگر آپ کسی عوامی سرور پر موجود آلے تک رسائی چاہتے ہیں تو \"<id>@public\" درج کریں، عوامی سرور کے لیے کلید درکار نہیں۔"),
("Download", "ڈاؤن لوڈ کریں"),
("Upload folder", "اپ لوڈ فولڈر"),
("Upload files", "فائلیں اپ لوڈ کریں"),
("Clipboard is synchronized", "کلپ بورڈ مطابق ہے"),
("Update client clipboard", "کلپ بورڈ کو اپ ڈیٹ کریں"),
("Untagged", "غیر تعلق یافتہ"),
("new-version-of-{}-tip", ""),
("new-version-of-{}-tip", "{} کا ایک نیا ورژن دستیاب ہے"),
("Accessible devices", "قابلِ رسائی والے آلے"),
("upgrade_remote_rustdesk_client_to_{}_tip", ""),
("d3d_render_tip", ""),
("upgrade_remote_rustdesk_client_to_{}_tip", "براہِ کرم دور دراز فریق پر RustDesk کلائنٹ کو ورژن {} یا اس سے نئے پر اپ گریڈ کریں!"),
("d3d_render_tip", "جب D3D رینڈرنگ فعال ہو تو کچھ مشینوں پر ریموٹ کنٹرول اسکرین سیاہ ہو سکتی ہے۔"),
("Use D3D rendering", "D3D رینڈرنگ کا استعمال کریں"),
("Printer", "پرنٹر"),
("printer-os-requirement-tip", ""),
("printer-requires-installed-{}-client-tip", ""),
("printer-{}-not-installed-tip", ""),
("printer-{}-ready-tip", ""),
("printer-os-requirement-tip", "پرنٹر کی بیرونی خصوصیت کے لیے Windows 10 یا اس سے نیا درکار ہے۔"),
("printer-requires-installed-{}-client-tip", "دور دراز پرنٹنگ استعمال کرنے کے لیے اس آلے پر {} انسٹال ہونا ضروری ہے۔"),
("printer-{}-not-installed-tip", "{} پرنٹر انسٹال نہیں ہے۔"),
("printer-{}-ready-tip", "{} پرنٹر انسٹال ہے اور استعمال کے لیے تیار ہے۔"),
("Install {} Printer", " {} پرنٹر انسٹال کریں"),
("Outgoing Print Jobs", "بیرونی پرنٹ کام"),
("Incoming Print Jobs", "اندر کے پرنٹ کام"),
("Incoming Print Job", "اندر کا پرنٹ کام"),
("use-the-default-printer-tip", ""),
("use-the-selected-printer-tip", ""),
("auto-print-tip", ""),
("print-incoming-job-confirm-tip", ""),
("remote-printing-disallowed-tile-tip", ""),
("remote-printing-disallowed-text-tip", ""),
("save-settings-tip", ""),
("use-the-default-printer-tip", "پہلے سے طے شدہ پرنٹر استعمال کریں"),
("use-the-selected-printer-tip", "منتخب کردہ پرنٹر استعمال کریں"),
("auto-print-tip", "منتخب کردہ پرنٹر سے خودکار طور پر پرنٹ کریں۔"),
("print-incoming-job-confirm-tip", "آپ کو دور دراز سے ایک پرنٹ جاب موصول ہوئی۔ کیا آپ اسے اپنی طرف چلانا چاہتے ہیں؟"),
("remote-printing-disallowed-tile-tip", "دور دراز پرنٹنگ کی اجازت نہیں"),
("remote-printing-disallowed-text-tip", "کنٹرول شدہ فریق کی اجازت کی ترتیبات دور دراز پرنٹنگ سے انکار کرتی ہیں۔"),
("save-settings-tip", "ترتیبات محفوظ کریں"),
("dont-show-again-tip", " ٹپ دوبارہ نہ دکھائیں "),
("Take screenshot", "اسکرین شاٹ لیں"),
("Taking screenshot", "اسکرین شاٹ لے رہے ہیں"),
("screenshot-merged-screen-not-supported-tip", ""),
("screenshot-merged-screen-not-supported-tip", "متعدد ڈسپلے کے اسکرین شاٹس کو ملانا فی الحال معاون نہیں ہے۔ براہِ کرم ایک ڈسپلے پر منتقل ہو کر دوبارہ کوشش کریں۔"),
("screenshot-action-tip", "اسکرین شاٹ ایکشن ٹپ"),
("Save as", "حفظ کے طور پر"),
("Copy to clipboard", "کلپ بورڈ پر کاپی کریں"),
("Enable remote printer", "ریموٹ پرنٹر کو فعال کریں"),
("Downloading {}", "ڈاؤن لوڈ ہو رہا ہے {}"),
("{} Update", "{} اپ ڈیٹ"),
("{}-to-update-tip", ""),
("download-new-version-failed-tip", ""),
("{}-to-update-tip", "{} اب بند ہو کر نیا ورژن انسٹال کرے گا۔"),
("download-new-version-failed-tip", "ڈاؤن لوڈ ناکام۔ آپ دوبارہ کوشش کر سکتے ہیں یا \"Download\" بٹن پر کلک کر کے ریلیز صفحے سے ڈاؤن لوڈ کر کے دستی طور پر اپ گریڈ کر سکتے ہیں۔"),
("Auto update", "خودکار اپ ڈیٹ"),
("update-failed-check-msi-tip", ""),
("websocket_tip", ""),
("update-failed-check-msi-tip", "انسٹالیشن کے طریقے کی جانچ ناکام۔ براہِ کرم \"Download\" بٹن پر کلک کر کے ریلیز صفحے سے ڈاؤن لوڈ کریں اور دستی طور پر اپ گریڈ کریں۔"),
("websocket_tip", "WebSocket استعمال کرتے وقت صرف ریلے کنکشنز معاون ہیں۔"),
("Use WebSocket", "WebSocket استعمال کریں"),
("Trackpad speed", "ٹریک پیڈ کی رفتار"),
("Default trackpad speed", "ڈیفالٹ ٹریک پیڈ کی رفتار"),
@@ -709,7 +690,7 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("The user is not an administrator.", "صارف ایڈمنسٹریٹر نہیں ہے"),
("Failed to check if the user is an administrator.", "صارف ایڈمنسٹریٹر ہے یا نہیں چیک کرنے میں ناکام"),
("Supported only in the installed version.", "صرف انسٹال شدہ ورژن میں معاونت کی جاتی ہے۔"),
("elevation_username_tip", ""),
("elevation_username_tip", "صارف نام یا ڈومین صارف نام درج کریں"),
("Preparing for installation ...", "انسٹالیشن کی تیاری ..."),
("Show my cursor", "میرا کرسر دکھائیں"),
("Scale custom", "اپنی مرضی کے مطابق پیمانہ"),
@@ -725,28 +706,70 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("Alias", "عرف نام"),
("ScrollEdge", "اسکرول ایج"),
("Allow insecure TLS fallback", "غیر محفوظ TLS فالبیک کی اجازت دیں"),
("allow-insecure-tls-fallback-tip", ""),
("allow-insecure-tls-fallback-tip", "پہلے سے طے شدہ طور پر RustDesk TLS استعمال کرنے والے پروٹوکولز کے لیے سرور کے سرٹیفکیٹ کی تصدیق کرتا ہے۔\nیہ اختیار فعال ہونے پر، تصدیق ناکام ہونے کی صورت میں RustDesk تصدیق کا مرحلہ چھوڑ کر آگے بڑھ جائے گا۔"),
("Disable UDP", "UDP کو غیر فعال کریں"),
("disable-udp-tip", ""),
("server-oss-not-support-tip", ""),
("disable-udp-tip", "طے کرتا ہے کہ صرف TCP استعمال کیا جائے یا نہیں۔\nیہ اختیار فعال ہونے پر RustDesk UDP 21116 مزید استعمال نہیں کرے گا، اس کی جگہ TCP 21116 استعمال ہوگا۔"),
("server-oss-not-support-tip", "نوٹ: RustDesk سرور OSS میں یہ خصوصیت شامل نہیں ہے۔"),
("input note here", "نوٹ یہاں درج کریں"),
("note-at-conn-end-tip", ""),
("note-at-conn-end-tip", "کنکشن کے اختتام پر نوٹ کے لیے پوچھیں"),
("Show terminal extra keys", "ٹرمنل اضافی کیز دکھائیں"),
("Relative mouse mode", "رشتہ دار ماؤس موڈ"),
("rel-mouse-not-supported-peer-tip", ""),
("rel-mouse-not-ready-tip", ""),
("rel-mouse-lock-failed-tip", ""),
("rel-mouse-exit-{}-tip", ""),
("rel-mouse-permission-lost-tip", ""),
("rel-mouse-not-supported-peer-tip", "منسلک فریق نسبتی ماؤس موڈ کی حمایت نہیں کرتا۔"),
("rel-mouse-not-ready-tip", "نسبتی ماؤس موڈ ابھی تیار نہیں۔ براہِ کرم دوبارہ کوشش کریں۔"),
("rel-mouse-lock-failed-tip", "کرسر مقفل کرنے میں ناکامی۔ نسبتی ماؤس موڈ بند کر دیا گیا ہے۔"),
("rel-mouse-exit-{}-tip", "باہر نکلنے کے لیے {} دبائیں۔"),
("rel-mouse-permission-lost-tip", "کی بورڈ کی اجازت واپس لے لی گئی۔ نسبتی ماؤس موڈ بند کر دیا گیا ہے۔"),
("Changelog", "تبدیلی کا لاگ"),
("keep-awake-during-outgoing-sessions-label", ""),
("keep-awake-during-incoming-sessions-label", ""),
("keep-awake-during-outgoing-sessions-label", "بیرونی سیشنز کے دوران اسکرین بیدار رکھیں"),
("keep-awake-during-incoming-sessions-label", "آنے والے سیشنز کے دوران اسکرین بیدار رکھیں"),
("Continue with {}", "continue-with-{}"),
("Display Name", "display-name"),
("password-hidden-tip", ""),
("preset-password-in-use-tip", ""),
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", ""),
("password-hidden-tip", "مستقل پاس ورڈ مقرر ہے (پوشیدہ)۔"),
("preset-password-in-use-tip", "پہلے سے مقرر پاس ورڈ اس وقت استعمال میں ہے۔"),
("terminal-clipboard-write-tip", "ٹرمنل میں ایک ایپ اس ڈیوائس کے کلپ بورڈ پر متن کاپی کرنا چاہتی ہے۔ اجازت دینے پر یہ اجازت تمام کنکشن کی ٹرمنل ایپس پر لاگو رہے گی جب تک آپ اسے ترتیبات میں بند نہ کر دیں۔ دستی کاپی اور پیسٹ متاثر نہیں ہوں گے۔"),
("Allow terminal apps to copy to clipboard", "ٹرمنل ایپس کو کلپ بورڈ پر کاپی کرنے کی اجازت دیں"),
("Export", "برآمد کریں"),
("Export Logs", "لاگز برآمد کریں"),
("Import Folder", "فولڈر درآمد کریں"),
("Enable privacy mode", "پرائیویسی موڈ فعال کریں"),
("allow-remote-toolbar-docking-any-edge", "ریموٹ ٹول بار کو ونڈو کے کسی بھی کنارے پر لگانے کی اجازت دیں"),
("API Token", "API ٹوکن"),
("Deploy", "تعینات کریں"),
("Custom ID (optional)", "حسبِ ضرورت ID (اختیاری)"),
("server_requires_deployment_tip", "سرور کا تقاضا ہے کہ یہ آلہ واضح طور پر تعینات کیا جائے۔ ابھی تعینات کریں؟"),
("The server does not require explicit deployment.", "سرور کو واضح تعیناتی کی ضرورت نہیں۔"),
("Unknown response.", "نامعلوم جواب۔"),
("wayland-keyboard-input-disabled-tip", "کی بورڈ ان پٹ کی اجازت دیں؟"),
("wayland-keyboard-input-consent-tip", "اس دور دراز کمپیوٹر پر آپ جو کچھ ٹائپ کریں گے (بشمول پاس ورڈ) اسے اس پر موجود دوسری ایپس پڑھ سکتی ہیں۔"),
("wayland-keyboard-input-applies-to-tip", "یہ انتخاب اس پر لاگو ہوتا ہے:"),
("wayland-soft-keyboard-input-label", "سافٹ کی بورڈ ان پٹ"),
("wayland-keyboard-input-reset-choice-tip", "کی بورڈ ان پٹ کا انتخاب دوبارہ ترتیب دیں"),
("remember-wayland-keyboard-choice-tip", "اس دور دراز کمپیوٹر کے لیے دوبارہ نہ پوچھیں"),
("Why this happens", "ایسا کیوں ہوتا ہے"),
("Switch display", "ڈسپلے تبدیل کریں"),
("Show monitor switch button on the main toolbar", "مرکزی ٹول بار پر مانیٹر تبدیل کرنے کا بٹن دکھائیں"),
("Show on the minimized toolbar", "چھوٹے کیے گئے ٹول بار پر دکھائیں"),
("All monitors", "تمام مانیٹر"),
("#{} monitor", "#{} مانیٹر"),
("conn-e2ee-unavailable-tip", "اینڈ ٹو اینڈ خفیہ کاری کی تصدیق نہیں ہو سکی۔\nدور دراز آلہ ابھی ترتیب دیا جا رہا ہو سکتا ہے۔ بعد میں دوبارہ کوشش کریں۔\nاگر ایسا بار بار ہو تو ممکن ہے سرور قابلِ اعتماد نہ ہو۔\nپھر بھی جاری رکھیں؟"),
("ID whitelisting", "ID وائٹ لسٹنگ"),
("Use ID whitelisting", "ID وائٹ لسٹنگ استعمال کریں"),
("id_whitelist_tip", "صرف وائٹ لسٹ میں شامل IDs مجھ تک رسائی حاصل کر سکتی ہیں"),
("id_whitelist_wildcard_tip", "وائلڈ کارڈ معاون ہیں: '*' کسی بھی تعداد میں حروف سے مطابقت رکھتا ہے، '?' بالکل ایک حرف سے"),
("Invalid ID", "غلط ID"),
("Your ID is blocked by the peer", "آپ کی ID دوسرے فریق نے مسدود کر دی ہے"),
("Your ip is blocked by the peer", "آپ کا IP دوسرے فریق نے مسدود کر دیا ہے"),
("id_whitelist_caveat_tip", "ID کی اطلاع منسلک ہونے والا کلائنٹ خود دیتا ہے۔ یہ وائٹ لسٹ خطرے کو کم کرتی ہے، پاس ورڈ یا 2FA کا متبادل نہیں۔"),
("whitelist_cidr_tip", "CIDR اشاریہ معاون ہے، مثلاً 192.168.1.0/24"),
("Continue", "جاری رکھیں"),
("Browser didn't open? Use the url below to sign in.", "براؤزر نہیں کھلا؟ سائن اِن کرنے کے لیے نیچے دیا گیا URL استعمال کریں۔"),
("Lock canvas", "کینوس مقفل کریں"),
("Sync clipboard between sessions", "سیشنز کے درمیان کلپ بورڈ ہم آہنگ کریں"),
("sync-clipboard-between-sessions-tip", "ایک ریموٹ سیشن میں کاپی کیا گیا متن یا تصاویر آپ کے دیگر منسلک سیشنز کے کلپ بورڈ پر بھی بھیجی جاتی ہیں۔"),
("Reuse one connection for port forwarding", "پورٹ فارورڈنگ کے لیے ایک ہی کنکشن دوبارہ استعمال کریں"),
("port-forward-mux-tip", "ایک پورٹ فارورڈنگ کے تمام کنکشن دوسرے کمپیوٹر کے ساتھ بنے ایک ہی کنکشن سے گزرتے ہیں، ہر ایک کے لیے دوبارہ منسلک ہو کر لاگ اِن کرنے کے بجائے۔"),
("Enable WebRTC P2P connection", "WebRTC P2P کنکشن کو فعال کریں"),
("Enable TCP hole punching", "TCP ہول پنچنگ کو فعال کریں"),
].iter().cloned().collect();
}

View File

@@ -659,9 +659,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("screenshot-merged-screen-not-supported-tip", "Không hỗ trợ chụp gộp nhiều màn hình."),
("screenshot-action-tip", "Hành động chụp màn hình"),
("Save as", "Lưu thành"),
("Export", ""),
("Export Logs", ""),
("Import Folder", ""),
("Export", "Xuất"),
("Export Logs", "Xuất nhật ký"),
("Import Folder", "Nhập thư mục"),
("Copy to clipboard", "Sao chép vào Clipboard"),
("Enable remote printer", "Bật máy in từ xa"),
("Downloading {}", "Đang tải xuống {}"),
@@ -766,5 +766,9 @@ pub static ref T: std::collections::HashMap<&'static str, &'static str> =
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", ""),
("Enable", "Bật"),
("Reuse one connection for port forwarding", "Dùng chung một kết nối cho chuyển tiếp cổng"),
("port-forward-mux-tip", "Chuyển toàn bộ kết nối của một quy tắc chuyển tiếp cổng qua một kết nối duy nhất tới máy đối phương, thay vì kết nối và đăng nhập lại cho từng kết nối."),
("Enable WebRTC P2P connection", "Cho phép kết nối WebRTC P2P"),
("Enable TCP hole punching", "Bật TCP Hole Punching"),
].iter().cloned().collect();
}

View File

@@ -45,6 +45,7 @@ mod custom_server;
mod lang;
#[cfg(not(any(target_os = "android", target_os = "ios")))]
mod port_forward;
mod port_forward_mux;
#[cfg(not(any(target_os = "android", target_os = "ios")))]
mod tray;

View File

@@ -0,0 +1,404 @@
/*
* getifaddrs()/freeifaddrs() for Android: bionic only exports them from API 24,
* while the jniLibs are built against the API 21 sysroot (flutter/ndk_*.sh) and
* webrtc-util calls them whenever WebRTC gathers ICE candidates.
*
* Only AF_INET and AF_INET6 entries are reported; the AF_PACKET ones the real
* getifaddrs() also returns have no reader in this build.
*/
#include <errno.h>
#include <stdlib.h>
#include <string.h>
#include <unistd.h>
#include <ifaddrs.h>
#include <net/if.h>
#include <netinet/in.h>
#include <sys/socket.h>
#include <linux/netlink.h>
#include <linux/rtnetlink.h>
/* Refuse a single netlink datagram larger than this rather than grow forever. */
#define RD_NL_MAX_BUF (1024 * 1024)
/* A dump that never terminates must not hang the caller. */
#define RD_NL_MAX_DATAGRAMS 4096
typedef int (*rd_nl_cb)(struct nlmsghdr *nlh, void *ctx);
struct rd_link_info {
unsigned int index;
unsigned int flags;
char name[IFNAMSIZ + 1];
};
struct rd_link_table {
struct rd_link_info *items;
size_t len;
size_t cap;
};
/* One allocation per reported address; `ifa` first so freeifaddrs() can free
* the node it is handed. */
struct rd_ifaddrs_storage {
struct ifaddrs ifa;
struct sockaddr_storage addr;
struct sockaddr_storage netmask;
struct sockaddr_storage ifu;
char name[IFNAMSIZ + 1];
};
struct rd_addr_ctx {
const struct rd_link_table *links;
struct ifaddrs *head;
struct ifaddrs *tail;
};
static void rd_parse_rtattr(struct rtattr *rta, int len, struct rtattr **tb, int max)
{
memset(tb, 0, sizeof(*tb) * ((size_t)max + 1));
for (; RTA_OK(rta, len); rta = RTA_NEXT(rta, len)) {
if (rta->rta_type <= (unsigned short)max && tb[rta->rta_type] == NULL)
tb[rta->rta_type] = rta;
}
}
/* `len` must stay signed: NLMSG_NEXT subtracts the *aligned* length, which
* overshoots on an unaligned trailing message, and only a negative remainder
* stops NLMSG_OK from reading past the buffer. */
static int rd_nl_parse(char *buf, int len, unsigned short reply_type, unsigned int seq,
rd_nl_cb cb, void *ctx, int *done)
{
struct nlmsghdr *nlh = (struct nlmsghdr *)buf;
for (; NLMSG_OK(nlh, len); nlh = NLMSG_NEXT(nlh, len)) {
if (nlh->nlmsg_seq != seq)
continue;
if (nlh->nlmsg_type == NLMSG_DONE) {
*done = 1;
return 0;
}
if (nlh->nlmsg_type == NLMSG_ERROR) {
struct nlmsgerr *err = (struct nlmsgerr *)NLMSG_DATA(nlh);
if (nlh->nlmsg_len >= NLMSG_LENGTH(sizeof(*err)) && err->error != 0)
errno = -err->error;
else
errno = EIO;
return -1;
}
if (nlh->nlmsg_type != reply_type)
continue;
if (cb(nlh, ctx) != 0)
return -1;
/* A non-multipart reply is the whole answer; nothing follows it. */
if ((nlh->nlmsg_flags & NLM_F_MULTI) == 0) {
*done = 1;
return 0;
}
}
return 0;
}
static int rd_nl_dump(int fd, unsigned short request_type, unsigned short reply_type,
unsigned int seq, rd_nl_cb cb, void *ctx)
{
struct {
struct nlmsghdr nlh;
struct rtgenmsg gen;
} req;
struct sockaddr_nl kernel;
char *buf;
size_t cap = 8192;
int datagrams = 0;
int done = 0;
int rc = -1;
int saved;
memset(&req, 0, sizeof(req));
req.nlh.nlmsg_len = NLMSG_LENGTH(sizeof(req.gen));
req.nlh.nlmsg_type = request_type;
req.nlh.nlmsg_flags = NLM_F_REQUEST | NLM_F_DUMP;
req.nlh.nlmsg_seq = seq;
req.gen.rtgen_family = AF_UNSPEC;
memset(&kernel, 0, sizeof(kernel));
kernel.nl_family = AF_NETLINK;
for (;;) {
if (sendto(fd, &req, req.nlh.nlmsg_len, 0, (struct sockaddr *)&kernel,
sizeof(kernel)) >= 0)
break;
if (errno != EINTR)
return -1;
}
buf = (char *)malloc(cap);
if (buf == NULL) {
errno = ENOMEM;
return -1;
}
while (!done) {
/* MSG_PEEK|MSG_TRUNC reports the datagram's real size, so an
* undersized buffer costs a resize instead of a silent truncation. */
ssize_t n = recv(fd, buf, cap, MSG_PEEK | MSG_TRUNC);
if (n < 0) {
if (errno == EINTR)
continue;
goto out;
}
if ((size_t)n > cap) {
char *grown;
if ((size_t)n > RD_NL_MAX_BUF) {
errno = EMSGSIZE;
goto out;
}
grown = (char *)realloc(buf, (size_t)n);
if (grown == NULL) {
errno = ENOMEM;
goto out;
}
buf = grown;
cap = (size_t)n;
continue;
}
n = recv(fd, buf, cap, 0);
if (n < 0) {
if (errno == EINTR)
continue;
goto out;
}
if (n == 0 || ++datagrams > RD_NL_MAX_DATAGRAMS) {
errno = EIO;
goto out;
}
if (rd_nl_parse(buf, (int)n, reply_type, seq, cb, ctx, &done) != 0)
goto out;
}
rc = 0;
out:
saved = errno;
free(buf);
errno = saved;
return rc;
}
static int rd_link_cb(struct nlmsghdr *nlh, void *ctx)
{
struct rd_link_table *t = (struct rd_link_table *)ctx;
struct ifinfomsg *ifi;
struct rtattr *tb[IFLA_IFNAME + 1];
struct rd_link_info *slot;
int payload;
int namelen;
if (nlh->nlmsg_len < NLMSG_LENGTH(sizeof(*ifi)))
return 0;
ifi = (struct ifinfomsg *)NLMSG_DATA(nlh);
payload = (int)nlh->nlmsg_len - (int)NLMSG_SPACE(sizeof(*ifi));
if (payload < 0)
payload = 0;
rd_parse_rtattr(IFLA_RTA(ifi), payload, tb, IFLA_IFNAME);
/* An interface we cannot name is of no use: callers dereference ifa_name. */
if (tb[IFLA_IFNAME] == NULL || (int)RTA_PAYLOAD(tb[IFLA_IFNAME]) <= 0)
return 0;
if (t->len == t->cap) {
size_t ncap = t->cap ? t->cap * 2 : 16;
struct rd_link_info *items =
(struct rd_link_info *)realloc(t->items, ncap * sizeof(*items));
if (items == NULL) {
errno = ENOMEM;
return -1;
}
t->items = items;
t->cap = ncap;
}
slot = &t->items[t->len];
memset(slot, 0, sizeof(*slot));
slot->index = (unsigned int)ifi->ifi_index;
slot->flags = ifi->ifi_flags;
namelen = (int)RTA_PAYLOAD(tb[IFLA_IFNAME]);
if (namelen > IFNAMSIZ)
namelen = IFNAMSIZ;
memcpy(slot->name, RTA_DATA(tb[IFLA_IFNAME]), (size_t)namelen);
slot->name[namelen] = '\0';
t->len++;
return 0;
}
static const struct rd_link_info *rd_link_find(const struct rd_link_table *t,
unsigned int index)
{
size_t i;
for (i = 0; i < t->len; i++) {
if (t->items[i].index == index)
return &t->items[i];
}
return NULL;
}
static void rd_fill_mask(unsigned char *out, int len, unsigned int prefix)
{
int i;
if (prefix > (unsigned int)len * 8)
prefix = (unsigned int)len * 8;
for (i = 0; i < len; i++) {
if (prefix >= 8) {
out[i] = 0xff;
prefix -= 8;
} else if (prefix > 0) {
out[i] = (unsigned char)(0xff << (8 - prefix));
prefix = 0;
} else {
out[i] = 0;
}
}
}
static void rd_set_in(struct sockaddr_storage *ss, const void *addr)
{
struct sockaddr_in *sin = (struct sockaddr_in *)ss;
sin->sin_family = AF_INET;
memcpy(&sin->sin_addr, addr, 4);
}
static int rd_addr_cb(struct nlmsghdr *nlh, void *ctx)
{
struct rd_addr_ctx *c = (struct rd_addr_ctx *)ctx;
struct ifaddrmsg *ifa;
struct rtattr *tb[IFA_BROADCAST + 1];
struct rtattr *ra;
const struct rd_link_info *link;
struct rd_ifaddrs_storage *st;
int payload;
if (nlh->nlmsg_len < NLMSG_LENGTH(sizeof(*ifa)))
return 0;
ifa = (struct ifaddrmsg *)NLMSG_DATA(nlh);
if (ifa->ifa_family != AF_INET && ifa->ifa_family != AF_INET6)
return 0;
/* Without the link entry there is no name, and callers deref ifa_name. */
link = rd_link_find(c->links, ifa->ifa_index);
if (link == NULL)
return 0;
payload = (int)nlh->nlmsg_len - (int)NLMSG_SPACE(sizeof(*ifa));
if (payload < 0)
payload = 0;
rd_parse_rtattr(IFA_RTA(ifa), payload, tb, IFA_BROADCAST);
/* On a point-to-point link IFA_ADDRESS holds the peer and IFA_LOCAL the
* local address; ipv6 only ever sets IFA_ADDRESS. */
if (ifa->ifa_family == AF_INET)
ra = tb[IFA_LOCAL] ? tb[IFA_LOCAL] : tb[IFA_ADDRESS];
else
ra = tb[IFA_ADDRESS] ? tb[IFA_ADDRESS] : tb[IFA_LOCAL];
if (ra == NULL)
return 0;
if ((int)RTA_PAYLOAD(ra) < (ifa->ifa_family == AF_INET ? 4 : 16))
return 0;
st = (struct rd_ifaddrs_storage *)calloc(1, sizeof(*st));
if (st == NULL) {
errno = ENOMEM;
return -1;
}
memcpy(st->name, link->name, sizeof(st->name));
st->ifa.ifa_name = st->name;
st->ifa.ifa_flags = link->flags;
st->ifa.ifa_addr = (struct sockaddr *)&st->addr;
st->ifa.ifa_netmask = (struct sockaddr *)&st->netmask;
if (ifa->ifa_family == AF_INET) {
struct sockaddr_in *mask = (struct sockaddr_in *)&st->netmask;
rd_set_in(&st->addr, RTA_DATA(ra));
mask->sin_family = AF_INET;
rd_fill_mask((unsigned char *)&mask->sin_addr, 4, ifa->ifa_prefixlen);
if ((link->flags & IFF_POINTOPOINT) && tb[IFA_ADDRESS] && tb[IFA_LOCAL] &&
(int)RTA_PAYLOAD(tb[IFA_ADDRESS]) >= 4 &&
memcmp(RTA_DATA(tb[IFA_ADDRESS]), RTA_DATA(tb[IFA_LOCAL]), 4) != 0) {
rd_set_in(&st->ifu, RTA_DATA(tb[IFA_ADDRESS]));
st->ifa.ifa_dstaddr = (struct sockaddr *)&st->ifu;
} else if (tb[IFA_BROADCAST] && (int)RTA_PAYLOAD(tb[IFA_BROADCAST]) >= 4) {
rd_set_in(&st->ifu, RTA_DATA(tb[IFA_BROADCAST]));
st->ifa.ifa_broadaddr = (struct sockaddr *)&st->ifu;
}
} else {
struct sockaddr_in6 *sin6 = (struct sockaddr_in6 *)&st->addr;
struct sockaddr_in6 *mask = (struct sockaddr_in6 *)&st->netmask;
sin6->sin6_family = AF_INET6;
memcpy(&sin6->sin6_addr, RTA_DATA(ra), 16);
/* A link-local address is not routable without its scope id. */
if (IN6_IS_ADDR_LINKLOCAL(&sin6->sin6_addr) ||
IN6_IS_ADDR_MC_LINKLOCAL(&sin6->sin6_addr))
sin6->sin6_scope_id = ifa->ifa_index;
mask->sin6_family = AF_INET6;
rd_fill_mask((unsigned char *)&mask->sin6_addr, 16, ifa->ifa_prefixlen);
}
if (c->tail != NULL)
c->tail->ifa_next = &st->ifa;
else
c->head = &st->ifa;
c->tail = &st->ifa;
return 0;
}
void freeifaddrs(struct ifaddrs *ifa)
{
while (ifa != NULL) {
struct ifaddrs *next = ifa->ifa_next;
free(ifa);
ifa = next;
}
}
int getifaddrs(struct ifaddrs **ifap)
{
struct rd_link_table links;
struct rd_addr_ctx ctx;
int fd;
int saved;
if (ifap == NULL) {
errno = EINVAL;
return -1;
}
*ifap = NULL;
memset(&links, 0, sizeof(links));
memset(&ctx, 0, sizeof(ctx));
ctx.links = &links;
fd = socket(AF_NETLINK, SOCK_RAW | SOCK_CLOEXEC, NETLINK_ROUTE);
if (fd < 0)
return -1;
if (rd_nl_dump(fd, RTM_GETLINK, RTM_NEWLINK, 1, rd_link_cb, &links) != 0)
goto fail;
if (rd_nl_dump(fd, RTM_GETADDR, RTM_NEWADDR, 2, rd_addr_cb, &ctx) != 0)
goto fail;
close(fd);
free(links.items);
*ifap = ctx.head;
return 0;
fail:
saved = errno;
close(fd);
free(links.items);
freeifaddrs(ctx.head);
errno = saved;
return -1;
}

View File

@@ -1,6 +1,7 @@
use std::sync::{Arc, RwLock};
use crate::client::*;
use crate::port_forward_mux::{Claim, Tunnel, CHANNEL_WINDOW};
use hbb_common::{
allow_err, bail,
config::READ_TIMEOUT,
@@ -88,10 +89,33 @@ pub async fn listen(
run_rdp(addr.port(), &rdp_display_name(&lc, &id));
}
let mut ui_receiver = ui_receiver;
// One tunnel per mapping; the listener drops it on its way out, and that
// ends the tunnel.
let tunnel = Tunnel::new();
loop {
tokio::select! {
Ok((forward, addr)) = listener.accept() => {
log::info!("new connection from {:?}", addr);
// A multiplexed window takes the connection on the mapping's
// tunnel, or probes for one on its first accept. Everything
// else, the setting off or a peer without the feature, is the
// raw pipe below, as it always was.
let claim = if lc.read().unwrap().port_forward_mux { tunnel.claim() } else { Claim::Legacy };
match claim {
Claim::Muxed(handle) => {
if let Err(e) = handle.open(&remote_host, remote_port, forward, Vec::new()) {
log::debug!("cannot open channel for {:?}: {}", addr, e);
}
continue;
}
Claim::Claimed => {
if establish_tunnel(&tunnel, &id, &password, &mut ui_receiver, &interface, forward, addr, key, token, is_rdp, &remote_host, remote_port).await {
break;
}
continue;
}
Claim::Legacy => {}
}
let id = id.clone();
let password = password.clone();
let mut forward = Framed::new(forward, BytesCodec::new());
@@ -181,7 +205,7 @@ async fn connect_and_login(
match msg_in.union {
Some(message::Union::Hash(hash)) => {
challenge = Some(hash.clone());
if !hash_arrived(&interface, password, hash, pending_login.take(), remote_host, remote_port, &mut stream).await {
if !hash_arrived(&interface, password, hash, pending_login.take(), remote_host, remote_port, false, &mut stream).await {
return Ok(None);
}
}
@@ -213,7 +237,7 @@ async fn connect_and_login(
d = ui_receiver.recv() => {
match d {
Some(Data::Login(login)) => match &challenge {
Some(hash) => login_from_ui(&interface, hash, login, remote_host, remote_port, &mut stream).await,
Some(hash) => login_from_ui(&interface, hash, login, remote_host, remote_port, false, &mut stream).await,
None => pending_login = Some(login),
},
Some(Data::Message(msg)) => {
@@ -240,22 +264,24 @@ async fn connect_and_login(
/// A mapping's login is built from the window's shared handler:
/// `create_login_msg` reads `port_forward` and `handle_login_from_ui` reads
/// `hash`. Mappings log in concurrently, so each fills them and sends under
/// the window's turn lock, or one login carried another mapping's target or
/// answered another's challenge.
/// `create_login_msg` reads `port_forward` and `port_forward_multiplex`,
/// `handle_login_from_ui` reads `hash`. Mappings log in concurrently, so each
/// fills them and sends under the window's turn lock, or one login carried
/// another mapping's target or answered another's challenge.
async fn login_with_hash(
interface: &impl Interface,
password: &str,
hash: Hash,
remote_host: &str,
remote_port: i32,
mux: bool,
stream: &mut Stream,
) -> bool {
let lc = interface.get_lch();
let turn = lc.read().unwrap().port_forward_login_turn.clone();
let _turn = turn.lock().await;
lc.write().unwrap().port_forward = (remote_host.to_owned(), remote_port);
lc.write().unwrap().port_forward_multiplex = mux;
interface.handle_hash(password, hash, stream).await
}
@@ -273,14 +299,15 @@ async fn hash_arrived(
pending_login: Option<UiLogin>,
remote_host: &str,
remote_port: i32,
mux: bool,
stream: &mut Stream,
) -> bool {
match pending_login {
Some(login) => {
login_from_ui(interface, &hash, login, remote_host, remote_port, stream).await;
login_from_ui(interface, &hash, login, remote_host, remote_port, mux, stream).await;
true
}
None => login_with_hash(interface, password, hash, remote_host, remote_port, stream).await,
None => login_with_hash(interface, password, hash, remote_host, remote_port, mux, stream).await,
}
}
@@ -292,6 +319,7 @@ async fn login_from_ui(
login: UiLogin,
remote_host: &str,
remote_port: i32,
mux: bool,
stream: &mut Stream,
) {
let lc = interface.get_lch();
@@ -300,6 +328,7 @@ async fn login_from_ui(
{
let mut lc = lc.write().unwrap();
lc.port_forward = (remote_host.to_owned(), remote_port);
lc.port_forward_multiplex = mux;
lc.set_hash(hash.clone());
}
let (os_username, os_password, password, remember) = login;
@@ -308,6 +337,227 @@ async fn login_from_ui(
.await;
}
/// The first accept of a multiplexed mapping. It logs in asking for the
/// tunnel, and the peer's answer fixes this listener's mode until it closes:
/// a peer with the feature gets a tunnel every later accept joins, one
/// without gets today's raw pipe for this connection and `Legacy` for the
/// rest. Re-adding the mapping is how a user picks up an upgraded peer;
/// nothing switches modes underneath live connections. Returns `true` when
/// the listener should stop.
async fn establish_tunnel(
tunnel: &Tunnel,
id: &str,
password: &str,
ui_receiver: &mut mpsc::UnboundedReceiver<Data>,
interface: &impl Interface,
forward: TcpStream,
addr: std::net::SocketAddr,
key: &str,
token: &str,
is_rdp: bool,
remote_host: &str,
remote_port: i32,
) -> bool {
let mut forward = Framed::new(forward, BytesCodec::new());
let mut close_port_forward = false;
match connect_and_login_mux(id, password, ui_receiver, interface.clone(), &mut forward, key, token, is_rdp, &mut close_port_forward, remote_host, remote_port).await {
Ok(Some(outcome)) if outcome.mux => {
let handle = tunnel.set_muxed(outcome.stream, interface.clone());
if !outcome.local_eof {
let (socket, prebuf) = take_socket(forward, outcome.prebuf);
if let Err(e) = handle.open(remote_host, remote_port, socket, prebuf) {
log::debug!("cannot open channel for {:?}: {}", addr, e);
}
}
}
Ok(Some(outcome)) => {
tunnel.set_legacy();
if outcome.local_eof {
log::debug!("legacy peer and local {:?} already gone", addr);
} else {
run_legacy(outcome, forward, addr, interface.clone());
}
}
_ if close_port_forward => {
tunnel.set_failed();
return true;
}
Err(err) => {
tunnel.set_failed();
interface.on_establish_connection_error(err.to_string());
}
_ => tunnel.set_failed(),
}
false
}
/// `connect_and_login` for a mapping that wants the tunnel: the pre-read
/// stops at one window rather than growing without bound, and a local EOF
/// no longer ends the login, since the tunnel may still be wanted. It
/// reports what the peer answered rather than a raw stream, because the
/// caller's next step depends on it. The login itself is the raw pipe's,
/// told to ask for the tunnel.
async fn connect_and_login_mux(
id: &str,
password: &str,
ui_receiver: &mut mpsc::UnboundedReceiver<Data>,
interface: impl Interface,
forward: &mut Framed<TcpStream, BytesCodec>,
key: &str,
token: &str,
is_rdp: bool,
close_port_forward: &mut bool,
remote_host: &str,
remote_port: i32,
) -> ResultType<Option<LoginOutcome>> {
let conn_type = if is_rdp {
ConnType::RDP
} else {
ConnType::PORT_FORWARD
};
let ((mut stream, direct, _pk, _kcp, _stream_type), (feedback, rendezvous_server)) =
Client::start(id, key, token, conn_type, interface.clone()).await?;
interface.update_direct(Some(direct));
if !stream.is_secured() && !crate::common::is_direct_ip_access(id) {
if !confirm_insecure_connection(&interface, ui_receiver).await {
*close_port_forward = true;
return Ok(None);
}
}
let mut buffer = Vec::new();
let mut local_eof = false;
let mux;
let mut received = false;
let mut challenge = None;
let mut pending_login = None;
let _keep_it = hc_connection(feedback, rendezvous_server, token).await;
loop {
tokio::select! {
res = timeout(READ_TIMEOUT, stream.next()) => match res {
Err(_) => {
bail!("Timeout");
}
Ok(Some(Ok(bytes))) => {
if !received {
received = true;
interface.update_received(true);
}
let msg_in = Message::parse_from_bytes(&bytes)?;
match msg_in.union {
Some(message::Union::Hash(hash)) => {
challenge = Some(hash.clone());
if !hash_arrived(&interface, password, hash, pending_login.take(), remote_host, remote_port, true, &mut stream).await {
return Ok(None);
}
}
Some(message::Union::LoginResponse(lr)) => match lr.union {
Some(login_response::Union::Error(err)) => {
if !interface.handle_login_error(&err) {
return Ok(None);
}
}
Some(login_response::Union::PeerInfo(pi)) => {
mux = peer_supports_mux(&pi);
interface.handle_peer_info(pi);
break;
}
_ => {}
}
Some(message::Union::TestDelay(t)) => {
interface.handle_test_delay(t, &mut stream).await;
}
_ => {}
}
}
Ok(Some(Err(err))) => {
bail!("Connection closed: {}", err);
}
_ => {
bail!("Reset by the peer");
}
},
d = ui_receiver.recv() => {
match d {
Some(Data::Login(login)) => match &challenge {
Some(hash) => login_from_ui(&interface, hash, login, remote_host, remote_port, true, &mut stream).await,
None => pending_login = Some(login),
},
Some(Data::Message(msg)) => {
allow_err!(stream.send(&msg).await);
}
_ => {}
}
},
// Stop pulling once the pre-read buffer is a window deep; the
// rest waits in the kernel until the channel opens. A local EOF
// no longer aborts the login: the tunnel may still be wanted.
res = forward.next(), if !local_eof && buffer.len() < CHANNEL_WINDOW as usize => {
if let Some(Ok(bytes)) = res {
buffer.extend(bytes);
} else {
local_eof = true;
}
},
}
}
Ok(Some(LoginOutcome {
stream,
mux,
prebuf: buffer,
local_eof,
}))
}
/// Today's raw pipe, for peers without multiplexing.
fn run_legacy(
outcome: LoginOutcome,
forward: Framed<TcpStream, BytesCodec>,
addr: std::net::SocketAddr,
interface: impl Interface,
) {
let mut stream = outcome.stream;
let prebuf = outcome.prebuf;
tokio::spawn(async move {
stream.set_raw();
if !prebuf.is_empty() {
allow_err!(stream.send_bytes(prebuf.into()).await);
}
if let Err(err) = run_forward(forward, stream).await {
interface.msgbox("error", "Error", &err.to_string(), "");
}
log::info!("connection from {:?} closed", addr);
});
}
struct LoginOutcome {
stream: Stream,
mux: bool,
prebuf: Vec<u8>,
local_eof: bool,
}
fn peer_supports_mux(pi: &PeerInfo) -> bool {
pi.features.as_ref().map(|f| f.port_forward_mux).unwrap_or(false)
}
/// `into_inner()` would drop bytes the codec pulled but never yielded.
fn take_socket(forward: Framed<TcpStream, BytesCodec>, mut prebuf: Vec<u8>) -> (TcpStream, Vec<u8>) {
let parts = forward.into_parts();
prebuf.extend_from_slice(&parts.read_buf);
(parts.io, prebuf)
}
/// The controlling side's `enable-port-forward-mux`: on unless set to `N`.
pub fn mux_enabled() -> bool {
use hbb_common::config::{keys, option2bool, LocalConfig};
option2bool(
keys::OPTION_ENABLE_PORT_FORWARD_MUX,
&LocalConfig::get_option(keys::OPTION_ENABLE_PORT_FORWARD_MUX),
)
}
async fn run_forward(forward: Framed<TcpStream, BytesCodec>, stream: Stream) -> ResultType<()> {
log::info!("new port forwarding connection started");
let mut forward = forward;
@@ -453,8 +703,8 @@ mod login_tests {
let (mut a, mut a_peer) = loopback().await;
let (mut b, mut b_peer) = loopback().await;
tokio::join!(
login_with_hash(&ui, "pw", hash("a"), "a", 1, &mut a),
login_with_hash(&ui, "pw", hash("b"), "b", 2, &mut b),
login_with_hash(&ui, "pw", hash("a"), "a", 1, false, &mut a),
login_with_hash(&ui, "pw", hash("b"), "b", 2, false, &mut b),
);
assert_eq!(target(&login_at(&mut a_peer).await), ("a".to_owned(), 1));
assert_eq!(target(&login_at(&mut b_peer).await), ("b".to_owned(), 2));
@@ -472,10 +722,10 @@ mod login_tests {
let (mut a, mut a_peer) = loopback().await;
let (mut b, mut b_peer) = loopback().await;
// A's hash arrived last, so it is the one the handler holds.
assert!(login_with_hash(&ui, "pw", hash("a"), "a", 1, &mut a).await);
assert!(login_with_hash(&ui, "pw", hash("a"), "a", 1, false, &mut a).await);
login_at(&mut a_peer).await;
let typed = (String::new(), String::new(), "pw".to_owned(), false);
login_from_ui(&ui, &hash("b"), typed, "b", 2, &mut b).await;
login_from_ui(&ui, &hash("b"), typed, "b", 2, false, &mut b).await;
let lr = login_at(&mut b_peer).await;
assert_eq!(lr.password, digest("b"));
assert_eq!(target(&lr), ("b".to_owned(), 2));
@@ -494,10 +744,110 @@ mod login_tests {
// The prompt's password reached B before its hash, and no other
// mapping has stored it in the handler yet.
let typed = (String::new(), String::new(), "pw".to_owned(), false);
assert!(hash_arrived(&ui, "", hash("b"), Some(typed), "b", 2, &mut b).await);
assert!(hash_arrived(&ui, "", hash("b"), Some(typed), "b", 2, false, &mut b).await);
let lr = login_at(&mut b_peer).await;
assert_eq!(lr.password, digest("b"));
assert_eq!(target(&lr), ("b".to_owned(), 2));
});
}
#[test]
fn a_raw_pipe_login_on_a_multiplexed_window_does_not_ask_for_the_tunnel() {
let rt = tokio::runtime::Builder::new_current_thread()
.enable_all()
.build()
.unwrap();
rt.block_on(async {
let ui = window();
// The window probes for the tunnel, but this mapping latched to
// the raw pipe: its login must read as the raw pipe's, or an
// upgraded peer answers with a tunnel it then never gets.
ui.lc.write().unwrap().port_forward_mux = true;
let (mut a, mut a_peer) = loopback().await;
assert!(login_with_hash(&ui, "pw", hash("a"), "a", 1, false, &mut a).await);
assert!(!login_at(&mut a_peer).await.port_forward().multiplex);
});
}
#[test]
fn a_password_typed_at_the_prompt_keeps_a_raw_pipe_login_raw() {
let rt = tokio::runtime::Builder::new_current_thread()
.enable_all()
.build()
.unwrap();
rt.block_on(async {
let ui = window();
ui.lc.write().unwrap().port_forward_mux = true;
let (mut b, mut b_peer) = loopback().await;
let typed = (String::new(), String::new(), "pw".to_owned(), false);
login_from_ui(&ui, &hash("b"), typed, "b", 2, false, &mut b).await;
assert!(!login_at(&mut b_peer).await.port_forward().multiplex);
});
}
#[test]
fn a_probing_login_asks_for_the_tunnel() {
let rt = tokio::runtime::Builder::new_current_thread()
.enable_all()
.build()
.unwrap();
rt.block_on(async {
let ui = window();
let (mut a, mut a_peer) = loopback().await;
assert!(login_with_hash(&ui, "pw", hash("a"), "a", 1, true, &mut a).await);
assert!(login_at(&mut a_peer).await.port_forward().multiplex);
});
}
}
#[cfg(test)]
mod tests {
use super::*;
#[test]
fn peer_supports_mux_reads_the_features_bit() {
let mut pi = PeerInfo::new();
assert!(!peer_supports_mux(&pi));
pi.features = Some(Features { port_forward_mux: false, ..Default::default() }).into();
assert!(!peer_supports_mux(&pi));
pi.features = Some(Features { port_forward_mux: true, ..Default::default() }).into();
assert!(peer_supports_mux(&pi));
}
#[test]
fn port_forward_mux_defaults_to_on() {
use hbb_common::config::{keys, option2bool};
// option2bool's fallback branch is also "on unless N", so the value
// assertions below would pass for a prefixless key too. The `enable-`
// prefix is what actually guarantees the default, and renaming the key
// to an `allow-` one would silently flip it — pin the prefix itself.
assert!(keys::OPTION_ENABLE_PORT_FORWARD_MUX.starts_with("enable-"));
assert!(option2bool(keys::OPTION_ENABLE_PORT_FORWARD_MUX, ""));
assert!(option2bool(keys::OPTION_ENABLE_PORT_FORWARD_MUX, "Y"));
assert!(!option2bool(keys::OPTION_ENABLE_PORT_FORWARD_MUX, "N"));
}
#[test]
fn take_socket_hands_back_a_working_socket_and_the_prebuf() {
use hbb_common::tokio::io::{AsyncReadExt, AsyncWriteExt};
let rt = tokio::runtime::Builder::new_current_thread().enable_all().build().unwrap();
rt.block_on(async {
let l = tokio::net::TcpListener::bind("127.0.0.1:0").await.unwrap();
let addr = l.local_addr().unwrap();
let mut client = TcpStream::connect(addr).await.unwrap();
let (server, _) = l.accept().await.unwrap();
let mut framed = Framed::new(server, BytesCodec::new());
client.write_all(b"abc").await.unwrap();
// Read through the codec, as connect_and_login does during login.
let pulled = framed.next().await.unwrap().unwrap();
assert_eq!(&pulled[..], b"abc");
let (mut sock, prebuf) = take_socket(framed, pulled.to_vec());
assert_eq!(prebuf, b"abc".to_vec());
// Bytes written after the handoff arrive on the bare socket.
client.write_all(b"def").await.unwrap();
let mut buf = [0u8; 3];
sock.read_exact(&mut buf).await.unwrap();
assert_eq!(&buf, b"def");
});
}
}

1739
src/port_forward_mux.rs Normal file

File diff suppressed because it is too large Load Diff

View File

@@ -1,4 +1,6 @@
use std::{
collections::{hash_map::RandomState, HashMap, VecDeque},
hash::BuildHasher,
net::SocketAddr,
sync::{
atomic::{AtomicBool, Ordering},
@@ -21,8 +23,13 @@ use hbb_common::{
rendezvous_proto::*,
sleep,
socket_client::{self, connect_tcp, is_ipv4, new_direct_udp_for, new_udp_for},
tokio::{self, select, sync::Mutex, time::interval},
tokio::{
self, select,
sync::{mpsc, Mutex},
time::interval,
},
udp::FramedSocket,
webrtc::WebRTCStream,
AddrMangle, IntoTargetAddr, ResultType, Stream, TargetAddr,
};
@@ -47,7 +54,66 @@ lazy_static::lazy_static! {
static ref SOLVING_PK_MISMATCH: Mutex<String> = Default::default();
static ref LAST_MSG: Mutex<(SocketAddr, Instant)> = Mutex::new((SocketAddr::new([0; 4].into(), 0), Instant::now()));
static ref LAST_RELAY_MSG: Mutex<(SocketAddr, Instant)> = Mutex::new((SocketAddr::new([0; 4].into(), 0), Instant::now()));
static ref WEBRTC_ICE_TXS: Mutex<HashMap<String, IceRoute>> = Default::default();
static ref ICE_DIGEST_STATE: RandomState = Default::default();
}
/// Remote ICE candidates buffered per session while the answerer applies them. Same depth as the
/// controller's own buffer (`Client::MAX_PENDING_WEBRTC_ICE`), though that one evicts its oldest
/// where a full channel here refuses the newest.
const MAX_PENDING_REMOTE_ICE: usize = 64;
/// Queued candidates remembered so the controller's re-send is skipped instead of taking a slot
/// of its own. Far more than an honest peer gathers, at eight bytes each.
const ICE_DEDUP_WINDOW: usize = 256;
// The rendezvous ICE route is reachable without a prior punch and the peer decides how many
// candidates it sends, so these sites would let someone else set how much this machine writes to
// its log file. One line a minute each, carrying the suppressed count.
const ICE_LOG_INTERVAL: std::time::Duration = std::time::Duration::from_secs(60);
static UNKNOWN_ICE_SESSION_LOG: hbb_common::log_throttle::LogThrottle =
hbb_common::log_throttle::LogThrottle::new(ICE_LOG_INTERVAL);
static REJECTED_REMOTE_ICE_LOG: hbb_common::log_throttle::LogThrottle =
hbb_common::log_throttle::LogThrottle::new(ICE_LOG_INTERVAL);
static FULL_ICE_QUEUE_LOG: hbb_common::log_throttle::LogThrottle =
hbb_common::log_throttle::LogThrottle::new(ICE_LOG_INTERVAL);
struct IceRoute {
tx: mpsc::Sender<String>,
recent: VecDeque<u64>,
}
impl IceRoute {
fn new(tx: mpsc::Sender<String>) -> Self {
Self {
tx,
recent: VecDeque::new(),
}
}
/// Keeps `queue` the only way onto the channel, so nothing reaches it unrecorded.
fn is_same_channel(&self, other: &mpsc::Sender<String>) -> bool {
self.tx.same_channel(other)
}
/// Skip the controller's re-send of a candidate already queued: the ICE agent that dedups
/// repeats is downstream of this queue, so the copy would spend a slot of its own.
/// False means the candidate was dropped.
fn queue(&mut self, candidate: String) -> bool {
let digest = ICE_DIGEST_STATE.hash_one(candidate.as_str());
if self.recent.contains(&digest) {
// Only honest about the drop if the route is still alive to have taken it.
return !self.tx.is_closed();
}
// Recorded once queued, never before: a refused candidate stays repairable by the re-send.
if self.tx.try_send(candidate).is_err() {
return false;
}
if self.recent.len() >= ICE_DEDUP_WINDOW {
self.recent.pop_front();
}
self.recent.push_back(digest);
true
}
}
static SHOULD_EXIT: AtomicBool = AtomicBool::new(false);
static MANUAL_RESTARTED: AtomicBool = AtomicBool::new(false);
static SENT_REGISTER_PK: AtomicBool = AtomicBool::new(false);
@@ -399,6 +465,30 @@ impl RendezvousMediator {
allow_err!(rz.handle_intranet(fla, server).await);
});
}
Some(rendezvous_message::Union::IceCandidate(ice)) => {
let queued = {
let mut txs = WEBRTC_ICE_TXS.lock().await;
txs.get_mut(&ice.session_key)
.map(|route| route.queue(ice.candidate))
};
match queued {
Some(false) => {
if let Some(n) = FULL_ICE_QUEUE_LOG.due() {
log::debug!("dropped {} ICE candidate(s): queue full or closed", n);
}
}
None => {
if let Some(n) = UNKNOWN_ICE_SESSION_LOG.due() {
log::debug!(
"dropped {} ICE candidate(s) for unknown WebRTC session key, last: {}",
n,
ice.session_key
);
}
}
_ => {}
}
}
Some(rendezvous_message::Union::ConfigureUpdate(cu)) => {
let v0 = Config::get_rendezvous_servers();
Config::set_option(
@@ -508,6 +598,7 @@ impl RendezvousMediator {
rr.secure,
false,
Default::default(),
String::new(),
meta,
)
.await
@@ -522,6 +613,7 @@ impl RendezvousMediator {
secure: bool,
initiate: bool,
socket_addr_v6: bytes::Bytes,
webrtc_sdp_answer: String,
meta: ConnectionMeta,
) -> ResultType<()> {
let peer_addr = AddrMangle::decode(&socket_addr);
@@ -540,6 +632,7 @@ impl RendezvousMediator {
socket_addr: socket_addr.into(),
version: crate::VERSION.to_owned(),
socket_addr_v6,
webrtc_sdp_answer,
..Default::default()
};
if initiate {
@@ -606,6 +699,7 @@ impl RendezvousMediator {
true,
true,
socket_addr_v6,
String::new(),
meta,
)
.await
@@ -642,6 +736,163 @@ impl RendezvousMediator {
Ok(())
}
/// Build the WebRTC answerer for a punch-hole offer and return the SDP answer that rides in
/// the punch reply (PunchHoleSent / RelayResponse).
///
/// Awaited inline on the punch-reply path, which only holds because everything here is local
/// (pc + keygen + SDP; trickle means the answer carries no candidates). Keep network I/O out
/// — connection setup belongs in the detached task below.
async fn spawn_webrtc_answerer(
&self,
ph: &PunchHole,
relay_only_ice: bool,
server: ServerPtr,
peer_addr: SocketAddr,
meta: ConnectionMeta,
) -> ResultType<String> {
let mut stream =
WebRTCStream::new(&ph.webrtc_sdp_offer, relay_only_ice, CONNECT_TIMEOUT).await?;
let answer = stream.local_endpoint().to_owned();
let session_key = stream.session_key().to_owned();
let return_route = ph.socket_addr.clone();
// A duplicate PunchHole (the offerer re-sends the same request across punch attempts)
// resolves to the SESSIONS-cached stream. `take_local_ice_rx` yields the receiver
// exactly once per stream instance, so `None` here means an answerer was already
// spawned for this offer: return the (identical) cached answer without spawning a
// second connect task. Otherwise two `create_tcp_connection` tasks would detach and
// read the same data channel, interleaving the handshake and corrupting the session.
let Some(mut local_ice_rx) = stream.take_local_ice_rx() else {
return Ok(answer);
};
// Bounded: how many candidates arrive is the sender's choice, while draining one costs a
// JSON parse and the ICE agent's lock, so an unbounded queue lets whoever can reach this
// session's route grow it without limit inside a long-lived service process. A full queue
// drops the newest candidate, and the controller re-sends it once — the digests beside the
// sender are what keep that re-send from spending a slot of its own.
let (remote_ice_tx, mut remote_ice_rx) = mpsc::channel::<String>(MAX_PENDING_REMOTE_ICE);
let own_ice_tx = remote_ice_tx.clone();
WEBRTC_ICE_TXS
.lock()
.await
.insert(session_key.clone(), IceRoute::new(remote_ice_tx));
let stream_for_remote_ice = stream.clone();
tokio::spawn(async move {
while let Some(candidate) = remote_ice_rx.recv().await {
if let Err(err) = stream_for_remote_ice.add_remote_ice_candidate(&candidate).await
{
if let Some(n) = REJECTED_REMOTE_ICE_LOG.due() {
log::warn!(
"failed to add {} remote WebRTC ICE candidate(s), last: {}",
n,
err
);
}
}
}
});
{
let host = self.host.clone();
let socket_addr = return_route.clone();
let session_key_for_ice = session_key.clone();
tokio::spawn(async move {
// Candidates ride a dedicated TCP connection to the rendezvous server, like
// the answer, NOT the mediator channel: that channel is UDP in the default
// setup, and target deployments front hbbs with websocket/TCP only, where
// its UDP port is unreachable. The server keeps candidate-carrying TCP
// connections open, so one lazily-opened connection serves the whole
// trickle, and TCP reliability replaces the old 400ms duplicate re-send
// (the controller keeps its own re-send for the server->peer UDP downlink).
let mut conn = None;
while let Some(candidate) = local_ice_rx.recv().await {
let mut msg = Message::new();
msg.set_ice_candidate(IceCandidate {
socket_addr: socket_addr.clone(),
session_key: session_key_for_ice.clone(),
candidate,
..Default::default()
});
// One reconnect attempt per candidate: the first send after an hbbs
// restart or an idle-killed connection fails on the stale stream.
for _ in 0..2 {
if conn.is_none() {
match connect_tcp(&*host, CONNECT_TIMEOUT).await {
Ok(s) => conn = Some(s),
Err(err) => {
log::warn!(
"failed to connect for WebRTC ICE candidate: {}",
err
);
break;
}
}
}
if let Some(s) = conn.as_mut() {
match s.send(&msg).await {
Ok(()) => break,
Err(err) => {
log::debug!(
"WebRTC ICE candidate send failed, reconnecting: {}",
err
);
conn = None;
}
}
}
}
}
});
}
let session_key_for_cleanup = session_key.clone();
tokio::spawn(async move {
let result = stream.wait_connected(CONNECT_TIMEOUT).await;
// Only evict our own route. The key is the offer's DTLS fingerprint, identical across
// the controller's punch retries, so a retry that built a fresh answerer has already
// replaced this entry — removing it blindly would delete the live session's sender and
// leave it receiving no candidates at all.
{
let mut txs = WEBRTC_ICE_TXS.lock().await;
if txs
.get(&session_key_for_cleanup)
.is_some_and(|route| route.is_same_channel(&own_ice_tx))
{
txs.remove(&session_key_for_cleanup);
}
}
if let Err(err) = result {
log::warn!("webrtc wait_connected failed: {}", err);
// Release the pc now rather than waiting for the ICE agent to time out into a
// terminal state (~30s); this also drops the SESSIONS entry promptly.
stream.close().await;
return;
}
// create_tcp_connection takes ownership of the stream; keep a handle to close the pc
// once the session returns. It runs the whole session and returns Ok on normal end,
// Err on setup failure — either way the pc must be closed, else it lingers forever in
// SESSIONS (its state handler only fires on a terminal ICE state, which a cleanly
// closed session may never reach) leaking the pc, channels, and socket fds.
let stream_for_cleanup = stream.clone();
if let Err(err) = crate::server::create_tcp_connection(
server,
Stream::WebRTC(stream),
peer_addr,
true,
meta,
)
.await
{
log::warn!("failed to create WebRTC server connection: {}", err);
}
stream_for_cleanup.close().await;
});
Ok(answer)
}
async fn handle_punch_hole(&self, ph: PunchHole, server: ServerPtr) -> ResultType<()> {
let mut peer_addr = AddrMangle::decode(&ph.socket_addr);
let last = *LAST_MSG.lock().await;
@@ -651,18 +902,52 @@ impl RendezvousMediator {
return Ok(());
}
let peer_addr_v6 = hbb_common::AddrMangle::decode(&ph.socket_addr_v6);
let relay = use_ws() || Config::is_proxy() || ph.force_relay;
let local_proxy = use_ws() || Config::is_proxy();
let relay = local_proxy || ph.force_relay;
let mut socket_addr_v6 = Default::default();
let meta = connection_meta(
ph.control_permissions.into_option(),
ph.controlled_context.into_option(),
ph.control_permissions.clone().into_option(),
ph.controlled_context.clone().into_option(),
);
// The controller's force_relay alone does not say whether ICE must be Relay-only; its
// offer envelope does. `ice_policy: "all"` means the relay was forced by the transport
// (ws), so answer with full ICE and let a direct pair form.
let webrtc_relay_only =
ph.force_relay && !WebRTCStream::endpoint_declares_all_ice(&ph.webrtc_sdp_offer);
// No enable-webrtc check here: it is LocalConfig, which the UI process writes and never
// syncs over IPC, so this (server) process would read the private-server default of "N"
// and refuse to answer in exactly the self-hosted deployments the transport is for.
// A proxy still rules it out — ICE would bypass it and leak the real IP.
let webrtc_viable = !ph.webrtc_sdp_offer.is_empty()
&& !Config::is_proxy()
&& (!webrtc_relay_only || WebRTCStream::has_turn_server());
let webrtc_sdp_answer = if webrtc_viable {
self.spawn_webrtc_answerer(
&ph,
webrtc_relay_only,
server.clone(),
peer_addr,
meta.clone(),
)
.await
.unwrap_or_else(|err| {
log::warn!("failed to create WebRTC answer: {}", err);
String::new()
})
} else {
String::new()
};
if peer_addr_v6.port() > 0 && !relay {
socket_addr_v6 =
start_ipv6(peer_addr_v6, peer_addr, server.clone(), meta.clone()).await;
}
let relay_server = self.get_relay_server(ph.relay_server);
// for ensure, websocket go relay directly
// A symmetric NAT relays the legacy transports but deliberately not WebRTC: the answer
// built above rides along on the relay request, and ICE probes the candidate pairs rather
// than trusting this classification, so a direct WebRTC pair can still form on a
// connection this branch has already called relay-only. Do not gate the answerer on
// nat_type to make the two agree.
if ph.nat_type.enum_value() == Ok(NatType::SYMMETRIC)
|| Config::get_nat_type() == NatType::SYMMETRIC as i32
|| relay
@@ -678,6 +963,7 @@ impl RendezvousMediator {
true,
true,
socket_addr_v6.clone(),
webrtc_sdp_answer.clone(),
meta,
)
.await;
@@ -691,6 +977,7 @@ impl RendezvousMediator {
nat_type: nat_type.into(),
version: crate::VERSION.to_owned(),
socket_addr_v6,
webrtc_sdp_answer,
..Default::default()
};
if ph.udp_port > 0 {
@@ -699,12 +986,25 @@ impl RendezvousMediator {
.await?;
return Ok(());
}
if !ph.webrtc_sdp_offer.is_empty() {
// Return the answer over its own short-lived TCP connection rather than the mediator
// channel: that channel is UDP by default, and hbbs applies UDP-punch semantics
// (source-address observation) to a PunchHoleSent that arrives on it. No TCP punch
// is made — the controller keeps its request socket for trickled ICE.
let mut msg_out = Message::new();
msg_out.set_punch_hole_sent(msg_punch);
let mut socket = connect_tcp(&*self.host, CONNECT_TIMEOUT).await?;
socket.send(&msg_out).await?;
return Ok(());
}
log::debug!("Punch tcp hole to {:?}", peer_addr);
let mut socket = {
let socket = connect_tcp(&*self.host, CONNECT_TIMEOUT).await?;
let local_addr = socket.local_addr();
// key important here for punch hole to tell my gateway incoming peer is safe.
// it can not be async here, because local_addr can not be reused, we must close the connection before use it again.
// Awaited rather than spawned so the mapping exists before `PunchHoleSent` goes out;
// `local_addr` itself is shared, not exclusive - every socket here binds it with the
// reuse flags `new_socket` sets.
allow_err!(socket_client::connect_tcp_local(peer_addr, Some(local_addr), 30).await);
socket
};
@@ -712,7 +1012,10 @@ impl RendezvousMediator {
msg_out.set_punch_hole_sent(msg_punch);
let bytes = msg_out.write_to_bytes()?;
socket.send_raw(bytes).await?;
crate::accept_connection(server.clone(), socket, peer_addr, true, meta).await;
let local_addr = socket.local_addr();
// The listener inside takes this address over, so the mediator's socket goes first.
drop(socket);
punch_tcp_until_connected(server, peer_addr, local_addr, meta).await;
Ok(())
}
@@ -951,11 +1254,11 @@ async fn udp_nat_listen(
let socket_cloned = socket.clone();
let func = async {
socket.connect(peer_addr).await?;
let res = crate::punch_udp(socket.clone(), true).await?;
let init_packet = crate::punch_udp(socket.clone(), true).await?;
let stream = crate::kcp_stream::KcpStream::accept(
socket,
Duration::from_millis(CONNECT_TIMEOUT as _),
res,
init_packet,
)
.await?;
crate::server::create_tcp_connection(server, stream.1, peer_addr_v4, true, meta).await?;
@@ -971,6 +1274,194 @@ async fn udp_nat_listen(
Ok(())
}
/// Where the repeats start, and the factor they slow by. The controller's SYN arrives once, at an
/// instant we are never told, inside a window we are not told either: `Client::connect` sizes its
/// dial only after our PunchHoleSent, from its own rendezvous time and the direct failures it has
/// recorded for us - `CONNECT_TIMEOUT` between two known-asymmetric NATs that never failed, as
/// little as a second once one has. So the repeats cover our own ceiling instead, `CONNECT_TIMEOUT`,
/// which is as long as the accept below has always been willing to take a connection, and back
/// off across it: dense at the start, where every window begins and the short ones end, sparse
/// afterwards, which is `punch_udp`'s shape for the same reason.
const PUNCH_INTERVAL: f32 = 0.15;
const PUNCH_BACKOFF: f32 = 1.5;
const PUNCH_MAX_INTERVAL: f32 = 2.0;
/// How long a punch in flight may run past the deadline, and the only timer it runs on. A punch
/// is cancel-safe while it is still in SYN_SENT and not once the controller's SYN has crossed it:
/// the socket is then half way through a handshake, and dropping it there cuts the connection the
/// controller is opening - which its `connect` has already returned, so that attempt fails
/// outright rather than falling back to relay. A timer cannot tell the two states apart, so no
/// punch is cut on a schedule of its own, and none needs to be. A gateway that answers with RST
/// fails the connect at once, and the loop punches again. One that drops the SYN in silence
/// leaves the socket in SYN_SENT, where it holds the mapping open and the kernel re-sends the
/// SYN, and any SYN of the controller's that arrives crosses it - a second punch has nothing to
/// add. That leaves the deadline, and this much past it lets a crossing begun just before it
/// complete; Windows gives a SYN up at about 21s anyway.
const PUNCH_GRACE: u64 = 3000;
/// The punch above leaves before hbbs has told the controller where to dial, so it is never in
/// flight at the same time as the controller's SYN: it opens our NAT, meets nothing, and a gateway
/// that answers it with RST takes the mapping down with it - leaving the listener below waiting on
/// a hole that no longer exists. Punching again across the window in which the controller dials
/// rebuilds it, and once the controller sits in SYN_SENT one of those punches meets its SYN and
/// completes as a simultaneous open: a second way in, which a single punch never had.
async fn punch_tcp_until_connected(
server: ServerPtr,
peer_addr: SocketAddr,
local_addr: SocketAddr,
meta: ConnectionMeta,
) {
use hbb_common::tcp::new_listener;
// Shadows the module's `std::time::Instant`: the deadline is held against tokio's sleeps and
// timeouts, so it runs on their clock.
use hbb_common::tokio::time::Instant;
// Not fatal on its own - the punch below can still meet the controller's SYN without it, and
// that half is the one a listener the OS refused to bind could not have covered anyway.
let listener = match new_listener(local_addr, true).await {
Ok(listener) => {
log::info!("Server listening on: {local_addr}");
Some(listener)
}
Err(err) => {
log::warn!("Failed to listen on {local_addr} after punching: {err}");
None
}
};
// Bounds both halves: the punch keeps the mapping open only while the accept is still
// willing to take a connection through it.
let until = Instant::now() + Duration::from_millis(CONNECT_TIMEOUT);
let punch = punch_until(until, peer_addr, |ms| {
socket_client::connect_tcp_local(peer_addr, Some(local_addr), ms)
});
let Some(listener) = listener else {
if let Some(stream) = punch.await {
serve_punched(server, stream, peer_addr, meta).await;
}
return;
};
// Accepting in a loop, not once: a transient `accept` error must not spend the whole window
// the controller still has to arrive in.
let accept = async {
loop {
let left = until.saturating_duration_since(Instant::now()).as_millis() as u64;
if left == 0 {
break;
}
match hbb_common::timeout(left, listener.accept()).await {
// Not filtered by address, as `accept_connection` never did: hbbs saw the
// controller through one mapping and a NAT that pools its external addresses may
// dial us from another, and what keeps `meta`'s control permissions from a second
// peer is the handshake, plus that exactly one connection is ever served.
Ok(Ok(accepted)) => return Some(accepted),
Ok(Err(err)) => {
log::warn!("Failed to accept from {peer_addr}: {err}");
// One that persists - EMFILE, say - would otherwise spin here for the window.
sleep(1.).await;
}
Err(_) => break,
}
}
log::info!("Nothing connected to the hole punched to {peer_addr}");
None
};
// Only the accept races the punch. Racing `accept_connection` instead would race the whole
// session it goes on to run, so a punch landing mid-session would tear that session down.
//
// Whichever arrives first is the one connection this request produces. Serving the loser too
// would give a second peer the control permissions hbbs granted for this one controller, and
// no test on the connection itself can tell the two apart before `create_tcp_connection` has
// spoken to it - so the invariant is kept here, by there being no second serve.
let punched = select! {
// Both ready at once is two connections, not one seen twice - a crossing carries the
// punch's four-tuple, which the listener never matches - and the punch is the one kept:
// it is known to have met something at the address hbbs gave, where the accept takes
// any address, and dropping it would reset the connection the controller is opening.
biased;
Some(stream) = punch => stream,
Some((stream, addr)) = accept => {
return accept_punched_connection(server, stream, addr, meta).await;
}
else => return,
};
serve_punched(server, punched, peer_addr, meta).await;
}
/// The repeats of `punch_tcp_until_connected`, over any punch rather than `connect_tcp_local`
/// alone, so that a test can run the schedule against a paused clock - which no socket can be.
async fn punch_until<T, F, Fut>(
until: tokio::time::Instant,
peer_addr: SocketAddr,
mut punch: F,
) -> Option<T>
where
F: FnMut(u64) -> Fut,
Fut: std::future::Future<Output = ResultType<T>>,
{
use hbb_common::tokio::time::Instant;
let mut interval = PUNCH_INTERVAL;
let mut round = 0;
loop {
// The deadline decides whether another punch starts, never how long one already in
// flight may take: that one runs to PUNCH_GRACE past it.
let left = until.saturating_duration_since(Instant::now());
if left.is_zero() {
log::debug!("None of {round} punches to {peer_addr} was met");
return None;
}
// Cut at the deadline rather than slept out past it, so the window ends on a punch and
// not on a gap of up to PUNCH_MAX_INTERVAL: the controller's window opened after ours,
// on the PunchHoleSent hbbs relayed, so one as long as ours is still open through our tail.
tokio::time::sleep(Duration::from_secs_f32(interval).min(left)).await;
interval = (interval * PUNCH_BACKOFF).min(PUNCH_MAX_INTERVAL);
let ms = until.saturating_duration_since(Instant::now()).as_millis() as u64 + PUNCH_GRACE;
match punch(ms).await {
// The controller's SYN crossed this punch, so the stream is the connection it
// dialed, not a spare one: dropping it would reset that connection.
Ok(stream) => return Some(stream),
// Not logged one by one, but the count says which gateway it was: RST fails a
// punch at once and fits a dozen into the window, a silent drop holds the one
// punch for the whole of it. `connect_tcp_local` keeps no errno anyway.
Err(_) => round += 1,
}
}
}
async fn serve_punched(
server: ServerPtr,
stream: Stream,
peer_addr: SocketAddr,
meta: ConnectionMeta,
) {
log::info!("Punched tcp hole to {peer_addr}, connected on the punch itself");
if let Err(err) =
crate::server::create_tcp_connection(server, stream, peer_addr, true, meta).await
{
log::warn!("Failed to serve the connection punched to {peer_addr}: {err}");
}
}
/// The accept half of `accept_connection`, kept here because only the accept may race the punch.
async fn accept_punched_connection(
server: ServerPtr,
stream: tokio::net::TcpStream,
addr: SocketAddr,
meta: ConnectionMeta,
) {
use crate::server::create_tcp_connection;
stream.set_nodelay(true).ok();
match stream.local_addr() {
Ok(stream_addr) => {
let stream = Stream::from(stream, stream_addr);
if let Err(err) = create_tcp_connection(server, stream, addr, true, meta).await {
log::warn!("Failed to serve the connection from {addr}: {err}");
}
}
Err(err) => log::warn!("Failed to read the address accepted from {addr}: {err}"),
}
}
// When config is not yet synced from root, register_pk may have already been sent with a new generated pk.
// After config sync completes, the pk may change. This struct detects pk changes and triggers
// a re-registration by setting key_confirmed to false.
@@ -995,3 +1486,255 @@ impl Drop for CheckIfResendPk {
}
}
}
#[cfg(test)]
mod tests {
use super::{mpsc, socket_client, tokio, IceRoute, ICE_DEDUP_WINDOW, MAX_PENDING_REMOTE_ICE};
use hbb_common::tcp::new_listener;
use std::net::SocketAddr;
// A SOCKS proxy makes `connect_tcp_local` dial the proxy and ignore the local address, so
// nothing these two assert can hold. Read once, from the same global config production reads.
fn proxied() -> bool {
hbb_common::config::Config::get_socks().is_some()
}
/// Both held while their addresses are read, so the pair cannot be the same port - which
/// `SO_REUSEPORT` would let bind twice rather than refuse, leaving the tests degenerate.
async fn free_loopback_pair() -> (SocketAddr, SocketAddr) {
let (a, b) = (
tokio::net::TcpListener::bind("127.0.0.1:0").await.unwrap(),
tokio::net::TcpListener::bind("127.0.0.1:0").await.unwrap(),
);
(a.local_addr().unwrap(), b.local_addr().unwrap())
}
fn queue(route: &mut IceRoute, candidate: &str) -> bool {
route.queue(candidate.to_owned())
}
#[test]
fn the_re_sent_copy_does_not_spend_a_queue_slot() {
// Two slots, three sends: without the dedup the re-send takes the second and "relay",
// the one that traverses NAT, is the one refused.
let (tx, mut rx) = mpsc::channel::<String>(2);
let mut route = IceRoute::new(tx);
for _ in 0..2 {
assert!(queue(&mut route, "host"));
}
assert!(queue(&mut route, "relay"));
let mut queued = Vec::new();
while let Ok(candidate) = rx.try_recv() {
queued.push(candidate);
}
assert_eq!(queued, vec!["host".to_owned(), "relay".to_owned()]);
}
#[test]
fn a_candidate_the_full_queue_refused_is_not_remembered() {
let (tx, mut rx) = mpsc::channel::<String>(1);
let mut route = IceRoute::new(tx);
assert!(queue(&mut route, "host"));
assert!(!queue(&mut route, "relay"));
// The re-send is the only repair for a refused candidate; remembering it would swallow it.
assert_eq!(rx.try_recv().ok(), Some("host".to_owned()));
assert!(queue(&mut route, "relay"));
assert_eq!(rx.try_recv().ok(), Some("relay".to_owned()));
}
#[test]
fn a_re_send_is_skipped_while_the_original_is_still_queued() {
let (tx, mut rx) = mpsc::channel::<String>(MAX_PENDING_REMOTE_ICE);
let mut route = IceRoute::new(tx);
for i in 0..MAX_PENDING_REMOTE_ICE {
assert!(queue(&mut route, &format!("candidate-{}", i)));
}
assert!(queue(&mut route, "candidate-0"));
let mut queued = 0;
while rx.try_recv().is_ok() {
queued += 1;
}
assert_eq!(queued, MAX_PENDING_REMOTE_ICE);
}
#[test]
fn the_window_forgets_in_arrival_order() {
let (tx, mut rx) = mpsc::channel::<String>(MAX_PENDING_REMOTE_ICE);
let mut route = IceRoute::new(tx);
for i in 0..=ICE_DEDUP_WINDOW {
assert!(queue(&mut route, &format!("candidate-{}", i)));
assert!(rx.try_recv().is_ok());
}
// The oldest digest made room for the newest, so its re-send is admitted again.
assert!(queue(&mut route, "candidate-0"));
assert!(rx.try_recv().is_ok());
// A recent one is still skipped.
let recent = format!("candidate-{}", ICE_DEDUP_WINDOW);
assert!(queue(&mut route, &recent));
assert!(rx.try_recv().is_err());
}
// The second way in that the repeat punch opens: a punch reaching a peer already in SYN_SENT
// is answered by that socket rather than reset, and the two ends come up on one connection.
// A punch that misses the crossing is reset outright here, loopback having no NAT to absorb
// it and no round trip to hide behind - so a single punch lands only by luck, and repeating
// is what makes it land at all. That is the premise of the repeat, asserted directly. A round
// that misses costs one loopback RST, so rounds are cheap and there are many.
#[tokio::test(flavor = "multi_thread", worker_threads = 2)]
async fn a_punch_that_meets_the_peers_syn_connects_both_ends() {
// The crossing needs both connects genuinely in flight at once. Loopback answers a SYN to
// a port nobody is listening on with an instant RST, so on one CPU the first connect runs
// to completion before the second is scheduled and no round can ever cross - a property of
// the box, which this test cannot tell apart from a broken punch.
if proxied() || std::thread::available_parallelism().map_or(true, |cpus| cpus.get() < 2) {
return;
}
for _ in 0..256 {
let (a, b) = free_loopback_pair().await;
// Held for the whole crossing, because production always has one here and the design
// rests on which of the two the kernel hands the connection to: the punch and the
// peer's SYN share a four-tuple exactly, the listener only matches the address, and
// the punch has to win that or every crossing would be swallowed as a plain accept.
let listener = new_listener(a, true).await.unwrap();
let to_b = tokio::spawn(socket_client::connect_tcp_local(b, Some(a), 3000));
let to_a = tokio::spawn(socket_client::connect_tcp_local(a, Some(b), 3000));
let (at_a, at_b) = tokio::join!(to_b, to_a);
let (Ok(Ok(mut at_a)), Ok(Ok(mut at_b))) = (at_a, at_b) else {
continue;
};
at_a.send_bytes(bytes::Bytes::from_static(b"punch"))
.await
.unwrap();
let got = at_b.next_timeout(3000).await.unwrap().unwrap();
assert_eq!(&got[..], b"punch", "both ends must share one connection");
assert!(
hbb_common::timeout(200, listener.accept()).await.is_err(),
"the crossing must reach the punch, not be accepted as an inbound connection"
);
return;
}
panic!("no punch met the peer's SYN in 256 rounds on a machine that can cross them");
}
// The punch binds the address the listener already holds, so it has to go through the same
// `connect_tcp_local` production uses - a punch built by hand here would still pass if
// `new_socket` ever stopped setting the reuse flags, while every real punch failed to bind.
// The peer's view of the source port is what proves the bind took: a fallback to an ephemeral
// one would connect just as happily.
#[tokio::test(flavor = "multi_thread", worker_threads = 2)]
async fn a_punch_binds_the_address_the_listener_holds() {
if proxied() {
return;
}
// `free_loopback_pair` hands back ports it no longer holds, so another process can take
// one in between; retry rather than fail for something the punch had no part in.
for _ in 0..8 {
let (local, peer_addr) = free_loopback_pair().await;
let (Ok(listener), Ok(peer)) = (
new_listener(local, true).await,
new_listener(peer_addr, true).await,
) else {
continue;
};
let punch = tokio::spawn(socket_client::connect_tcp_local(
peer_addr,
Some(local),
1500,
));
let (_peer_side, seen_as) = hbb_common::timeout(3000, peer.accept())
.await
.expect("the punch must reach the peer")
.unwrap();
assert_eq!(
seen_as.port(),
local.port(),
"the punch must leave from the address the listener holds, not an ephemeral one"
);
// Held, not asserted and dropped: the coexistence below is only exercised while this
// socket is still on the address, which is the state production spends its window in.
let _punched = punch.await.unwrap().expect("the punch must connect");
let dialed = tokio::spawn(tokio::net::TcpStream::connect(local));
let accepted = hbb_common::timeout(3000, listener.accept()).await;
assert!(
matches!(accepted, Ok(Ok(_))),
"the listener must still take connections while a punch shares its address: {accepted:?}"
);
assert!(dialed.await.unwrap().is_ok());
return;
}
panic!("could not hold two free loopback addresses in 8 tries");
}
// The schedule on its own, against a paused clock: the window is CONNECT_TIMEOUT long, and
// what these pin is where inside it the punches fall, which no socket could show.
#[tokio::test(start_paused = true)]
async fn the_punches_end_on_one_at_the_deadline() {
use super::{punch_until, PUNCH_GRACE, PUNCH_INTERVAL, PUNCH_MAX_INTERVAL};
use hbb_common::{anyhow::anyhow, config::CONNECT_TIMEOUT};
use std::time::Duration;
use tokio::time::Instant;
let peer: SocketAddr = "127.0.0.1:1".parse().unwrap();
let start = Instant::now();
let until = start + Duration::from_millis(CONNECT_TIMEOUT);
let mut punches = Vec::new();
// A gateway that answers with RST: every punch fails the moment it is made.
let met = punch_until::<(), _, _>(until, peer, |ms| {
punches.push((Instant::now(), ms));
async { Err(anyhow!("RST")) }
})
.await;
assert!(met.is_none());
assert_eq!(
Instant::now(),
until,
"must return the moment the window closes, not a backoff later"
);
// Tokio rounds every sleep up to the next millisecond.
let slack = Duration::from_millis(1);
assert!(punches[0].0 - start <= Duration::from_secs_f32(PUNCH_INTERVAL) + slack);
for pair in punches.windows(2) {
assert!(
pair[1].0 - pair[0].0 <= Duration::from_secs_f32(PUNCH_MAX_INTERVAL) + slack,
"no gap in the window may exceed the backoff ceiling: {pair:?}"
);
}
assert_eq!(
*punches.last().unwrap(),
(until, PUNCH_GRACE),
"the window must end on a punch, given the whole grace"
);
}
#[tokio::test(start_paused = true)]
async fn a_punch_in_flight_runs_the_grace_past_the_deadline_and_no_further() {
use super::{punch_until, PUNCH_GRACE};
use hbb_common::{anyhow::anyhow, config::CONNECT_TIMEOUT};
use std::time::Duration;
use tokio::time::Instant;
let peer: SocketAddr = "127.0.0.1:1".parse().unwrap();
let until = Instant::now() + Duration::from_millis(CONNECT_TIMEOUT);
let mut punches = 0;
// A gateway that drops the SYN in silence: the punch sits in SYN_SENT for all it is given.
let met = punch_until::<(), _, _>(until, peer, |ms| {
punches += 1;
async move {
tokio::time::sleep(Duration::from_millis(ms)).await;
Err(anyhow!("timed out"))
}
})
.await;
assert!(met.is_none());
assert_eq!(
punches, 1,
"a punch held in SYN_SENT is the only one the window needs"
);
assert_eq!(
Instant::now(),
until + Duration::from_millis(PUNCH_GRACE),
"must return when the grace runs out, not a backoff later"
);
}
}

View File

@@ -70,6 +70,7 @@ pub mod input_service {
mod connection;
mod login_failure_check;
pub(crate) mod port_forward_mux;
pub mod display_service;
#[cfg(windows)]
pub mod portable_service;
@@ -211,11 +212,21 @@ pub async fn create_tcp_connection(
let sk = sign::SecretKey(sk_);
let mut msg_out = Message::new();
let (our_pk_b, our_sk_b) = box_::gen_keypair();
// On a WebRTC transport, bind our DTLS certificate fingerprint to our signed identity so
// the controller can verify the DTLS channel it negotiated actually terminates at us
// (not a rendezvous/relay that swapped the SDP fingerprint). Empty on other transports.
// Fail immediately on WebRTC if the local fingerprint is unavailable: signing "" would
// only make the client fail-closed after a wasted round-trip.
let dtls_fingerprint = stream.dtls_fingerprint(true).await.unwrap_or_default();
if stream.is_webrtc() && dtls_fingerprint.is_empty() {
bail!("WebRTC local DTLS fingerprint unavailable");
}
msg_out.set_signed_id(SignedId {
id: sign::sign(
&IdPk {
id: Config::get_id(),
pk: Bytes::from(our_pk_b.0.to_vec()),
dtls_fingerprint,
..Default::default()
}
.write_to_bytes()

View File

@@ -257,6 +257,7 @@ pub struct Connection {
view_camera: bool,
terminal: bool,
port_forward_socket: Option<Framed<TcpStream, BytesCodec>>,
port_forward_mux: Option<super::port_forward_mux::PortForwardMux>,
port_forward_address: String,
tx_to_cm: mpsc::UnboundedSender<ipc::Data>,
authorized: bool,
@@ -469,6 +470,7 @@ impl Connection {
view_camera: false,
terminal: false,
port_forward_socket: None,
port_forward_mux: None,
port_forward_address: "".to_owned(),
tx_to_cm,
authorized: false,
@@ -1087,6 +1089,9 @@ impl Connection {
}
}
video_service::notify_video_frame_fetched_by_conn_id(id, None);
if conn.authorized {
password::update_temporary_password();
}
if let Err(err) = conn.try_port_forward_loop(&mut rx_from_cm).await {
conn.on_close(&err.to_string(), false).await;
raii::AuthedConnID::check_remove_session(conn.inner.id(), conn.session_key());
@@ -1642,7 +1647,7 @@ impl Connection {
}
}
fn normalize_port_forward_target(pf: &mut PortForward) -> (String, bool) {
pub(super) fn normalize_port_forward_target(pf: &mut PortForward) -> (String, bool) {
let mut is_rdp = false;
if pf.host == "RDP" && pf.port == 0 {
pf.host = "localhost".to_owned();
@@ -1656,12 +1661,21 @@ impl Connection {
}
async fn connect_port_forward_if_needed(&mut self) -> bool {
if self.port_forward_socket.is_some() {
if self.is_port_forward() {
return true;
}
let Some(login_request::Union::PortForward(pf)) = self.lr.union.as_ref() else {
return true;
};
if pf.multiplex {
crate::port_forward_mux::cap_packet_size(&mut self.stream);
// `inner.tx` is set for the connection's whole life; `None` here is
// unreachable, and refusing the login is the only honest answer.
self.port_forward_mux = self.inner.tx.clone().map(|tx| {
super::port_forward_mux::PortForwardMux::new(tx, self.port_forward_address.clone())
});
return self.port_forward_mux.is_some();
}
let mut pf = pf.clone();
let (mut addr, is_rdp) = Self::normalize_port_forward_target(&mut pf);
self.port_forward_address = addr.clone();
@@ -1744,16 +1758,12 @@ impl Connection {
return false;
}
self.authorized = true;
// One-time means gone once it has let a peer in, not once that peer
// leaves. This session's later logins come in on the password the
// session remembers, so they are not affected.
password::update_temporary_password();
// Releases the budget `check_id_whitelist` charges against this address: only a peer
// that got this far proved more than a self-reported id.
self.clear_id_whitelist_failures();
let (conn_type, auth_conn_type) = if self.file_transfer.is_some() {
(1, AuthConnType::FileTransfer)
} else if self.port_forward_socket.is_some() {
} else if self.is_port_forward() {
(2, AuthConnType::PortForward)
} else if self.view_camera {
(3, AuthConnType::ViewCamera)
@@ -1866,7 +1876,12 @@ impl Connection {
pi.platform_additions = serde_json::to_string(&platform_additions).unwrap_or("".into());
}
if self.port_forward_socket.is_some() {
if self.is_port_forward() {
pi.features = Some(Features {
port_forward_mux: self.port_forward_mux.is_some(),
..Default::default()
})
.into();
let mut msg_out = Message::new();
res.set_peer_info(pi);
msg_out.set_login_response(res);
@@ -2064,11 +2079,16 @@ impl Connection {
#[inline]
fn is_remote(&self) -> bool {
self.file_transfer.is_none()
&& self.port_forward_socket.is_none()
&& !self.is_port_forward()
&& !self.view_camera
&& !self.terminal
}
#[inline]
fn is_port_forward(&self) -> bool {
self.port_forward_socket.is_some() || self.port_forward_mux.is_some()
}
fn try_sub_monitor_services(&mut self) {
let is_remote = self.is_remote();
if is_remote && !self.services_subed {
@@ -2212,6 +2232,16 @@ impl Connection {
self.tx_to_cm.send(data).ok();
}
fn handle_port_forward_channel(&mut self, ch: PortForwardChannel) {
let Some(mux) = self.port_forward_mux.as_mut() else {
log::debug!("port forward channel frame on a non-multiplexed connection");
return;
};
mux.handle(ch, || {
Self::permission(keys::OPTION_ENABLE_TUNNEL, &self.control_permissions)
});
}
#[inline]
fn send_fs(&mut self, data: ipc::FS) {
self.send_to_cm(ipc::Data::FS(data));
@@ -2577,11 +2607,13 @@ impl Connection {
let PortForward {
host,
port,
multiplex,
special_fields: _,
} = pf;
push(b"port_forward");
push(host.as_bytes());
push(&port.to_le_bytes());
push(&[*multiplex as u8]);
}
// Variants this build does not know execute as remote, so they latch as remote.
None | Some(_) => push(b"remote"),
@@ -3866,6 +3898,7 @@ impl Connection {
self.refresh_video_display(Some(request.display as usize));
}
}
Some(message::Union::PortForwardChannel(ch)) => self.handle_port_forward_channel(ch),
Some(message::Union::TerminalAction(action)) => {
#[cfg(not(any(target_os = "android", target_os = "ios")))]
allow_err!(self.handle_terminal_action(action).await);
@@ -5075,6 +5108,9 @@ impl Connection {
let data = ipc::Data::Close;
self.tx_to_cm.send(data).ok();
self.port_forward_socket.take();
if let Some(mut mux) = self.port_forward_mux.take() {
mux.close_all();
}
}
// The `reason` should be consistent with `check_if_retry` if not empty
@@ -5676,7 +5712,7 @@ impl Connection {
let allowed = match conn_type {
AuthConnType::Remote => true,
AuthConnType::FileTransfer => Self::is_file_transfer_scoped_message(msg),
AuthConnType::PortForward => false,
AuthConnType::PortForward => Self::is_port_forward_scoped_message(msg),
AuthConnType::ViewCamera => Self::is_view_camera_scoped_message(msg),
AuthConnType::Terminal => Self::is_terminal_scoped_message(msg),
};
@@ -5750,6 +5786,13 @@ impl Connection {
false
}
fn is_port_forward_scoped_message(msg: &Message) -> bool {
matches!(
msg.union.as_ref(),
Some(message::Union::PortForwardChannel(_))
)
}
fn is_terminal_scoped_message(msg: &Message) -> bool {
match msg.union.as_ref() {
Some(message::Union::TerminalAction(_)) => true,
@@ -5900,6 +5943,7 @@ impl Connection {
Some(message::Union::ScreenshotResponse(_)) => "screenshot_response",
Some(message::Union::TerminalAction(_)) => "terminal_action",
Some(message::Union::TerminalResponse(_)) => "terminal_response",
Some(message::Union::PortForwardChannel(_)) => "port_forward_channel",
Some(message::Union::Misc(misc)) => Self::misc_message_family(misc),
Some(_) => "message.other",
None => "empty",
@@ -7229,6 +7273,10 @@ mod test {
}),
Some("misc.option"),
),
(
msg(|m| m.set_port_forward_channel(PortForwardChannel::new())),
Some("port_forward_channel"),
),
],
),
(
@@ -7290,6 +7338,10 @@ mod test {
}),
Some("misc.option"),
),
(
msg(|m| m.set_port_forward_channel(PortForwardChannel::new())),
Some("port_forward_channel"),
),
],
),
(
@@ -7390,6 +7442,10 @@ mod test {
}),
None,
),
(
msg(|m| m.set_port_forward_channel(PortForwardChannel::new())),
None,
),
],
),
];

View File

@@ -0,0 +1,565 @@
use super::connection::{Connection, Sender};
use crate::port_forward_mux::{
charge, close_msg, effective_window, opened_msg, run_channel, FrameSink, Inbound, RecvWindow,
SendCredit, CHANNEL_WINDOW, INITIAL_WINDOW, MAX_CHANNELS,
};
use hbb_common::{
bytes::Bytes,
log,
message_proto::*,
timeout,
tokio::{self, net::TcpStream, sync::{mpsc, watch}},
};
use std::{
collections::HashMap,
sync::{Arc, Mutex},
};
const CONNECT_TIMEOUT_MS: u64 = 3000;
/// Before `opened` the controller may only have used `INITIAL_WINDOW`.
/// `charged` is the running total of `charge(len)`, not of raw lengths.
fn pending_fits(charged: usize, add_len: usize) -> bool {
charged.saturating_add(charge(add_len) as usize) <= INITIAL_WINDOW as usize
}
struct Entry {
inbound: mpsc::UnboundedSender<Inbound>,
credit: Arc<SendCredit>,
window: Arc<Mutex<RecvWindow>>,
}
/// The controlled side of one multiplexed tunnel. The main loop owns it and
/// forwards every `PortForwardChannel` frame here; each channel is a task.
pub struct PortForwardMux {
channels: HashMap<i32, Entry>,
tx: Sender,
login_target: String,
/// Raised once, by `close_all`, for the channels its `clear` cannot reach:
/// one parked on its target socket is not on the inbound queue.
teardown: watch::Sender<bool>,
}
impl PortForwardMux {
pub fn new(tx: Sender, login_target: String) -> Self {
Self {
channels: HashMap::new(),
tx,
login_target,
teardown: watch::channel(false).0,
}
}
/// `tunnel_permitted` is consulted for `open` alone, so the lookup is not
/// made per 64 KiB of data.
pub fn handle(&mut self, frame: PortForwardChannel, tunnel_permitted: impl FnOnce() -> bool) {
match frame.union {
Some(port_forward_channel::Union::Open(open)) => {
let permitted = tunnel_permitted();
self.on_open(open, permitted)
}
Some(port_forward_channel::Union::Data(d)) => {
let len = d.data.len();
let Some(entry) = self.channels.get(&d.channel_id) else {
log::debug!("port forward data for unknown channel {}", d.channel_id);
return;
};
let accepted = entry.window.lock().unwrap().accept(len);
let delivered = accepted && entry.inbound.send(Inbound::Data(d.data)).is_ok();
if delivered {
return;
}
// Dropped here and now, so the peer cannot queue anything more
// for this id while the task is still on its way out.
let Some(entry) = self.channels.remove(&d.channel_id) else {
return;
};
if !accepted {
log::warn!("port forward channel {} overran its window", d.channel_id);
entry.inbound.send(Inbound::Violation).ok();
}
}
Some(port_forward_channel::Union::Close(c)) => {
if let Some(entry) = self.channels.remove(&c.channel_id) {
entry.inbound.send(Inbound::Close).ok();
} else {
log::debug!("port forward close for unknown channel {}", c.channel_id);
}
}
Some(port_forward_channel::Union::WindowUpdate(u)) => {
match self.channels.get(&u.channel_id) {
Some(entry) => entry.credit.add(u.add),
None => log::debug!(
"port forward window update for unknown channel {}",
u.channel_id
),
}
}
Some(port_forward_channel::Union::Opened(o)) => {
log::debug!("ignoring opened for channel {} on the controlled side", o.channel_id);
}
_ => {}
}
}
fn on_open(&mut self, open: PortForwardOpen, permitted: bool) {
let id = open.channel_id;
self.channels.retain(|_, e| !e.inbound.is_closed());
if !permitted {
self.reply(opened_msg(id, false, "No permission of IP tunneling", 0));
return;
}
if self.channels.len() >= MAX_CHANNELS {
self.reply(opened_msg(id, false, "Too many port forward channels", 0));
return;
}
if self.channels.contains_key(&id) {
log::debug!("ignoring open for live channel {}", id);
return;
}
let mut pf = PortForward {
host: open.host,
port: open.port,
..Default::default()
};
let (addr, is_rdp) = Connection::normalize_port_forward_target(&mut pf);
// Approval and permission checks saw the login's target; a tunnel
// serves that one target and nothing else.
if addr != self.login_target {
log::warn!(
"port forward channel {} asked for {} on a tunnel logged in for {}",
id,
addr,
self.login_target
);
self.reply(opened_msg(id, false, "Port forward target not authorized", 0));
return;
}
let (inbound_tx, inbound_rx) = mpsc::unbounded_channel();
let credit = Arc::new(SendCredit::new(effective_window(open.window)));
let window = Arc::new(Mutex::new(RecvWindow::new(INITIAL_WINDOW)));
self.channels.insert(
id,
Entry {
inbound: inbound_tx,
credit: credit.clone(),
window: window.clone(),
},
);
tokio::spawn(run_controlled_channel(
id,
addr,
is_rdp,
credit,
window,
inbound_rx,
FrameSink::Direct(self.tx.clone()),
self.teardown.subscribe(),
));
}
fn reply(&self, msg: Message) {
self.tx
.send((tokio::time::Instant::now(), Arc::new(msg)))
.ok();
}
#[cfg(test)]
pub fn live_channels(&self) -> usize {
self.channels.len()
}
#[cfg(test)]
pub fn recv_window_remaining(&self, id: i32) -> Option<u32> {
self.channels.get(&id).map(|e| e.window.lock().unwrap().remaining())
}
/// Every task ends and drops its target socket: the queue's senders go for
/// a task on the queue, `teardown` reaches one parked on the socket.
pub fn close_all(&mut self) {
self.channels.clear();
// Not `send`: with no channel live it stores nothing, and one opened
// as the tunnel closes would never see it.
self.teardown.send_replace(true);
}
}
/// Owns the whole channel lifecycle: connect under a `select!` in which a
/// queued command always wins over the connect, buffer what arrives
/// meanwhile, then relay.
async fn run_controlled_channel(
id: i32,
addr: String,
is_rdp: bool,
credit: Arc<SendCredit>,
window: Arc<Mutex<RecvWindow>>,
mut inbound: mpsc::UnboundedReceiver<Inbound>,
sink: FrameSink,
teardown: watch::Receiver<bool>,
) {
let mut pending: Vec<Bytes> = Vec::new();
let mut pending_len = 0usize;
let connect = timeout(CONNECT_TIMEOUT_MS, TcpStream::connect(&addr));
tokio::pin!(connect);
let socket = loop {
tokio::select! {
// Biased with the command arm first: a `close` that is already
// queued must win over a connect that completed on the same poll,
// or `opened` would go out for a channel the controller has dropped.
biased;
cmd = inbound.recv() => match cmd {
Some(Inbound::Data(b)) => {
if !pending_fits(pending_len, b.len()) {
log::warn!("port forward channel {} sent more than INITIAL_WINDOW before opened", id);
sink.send_ordered(close_msg(id)).await.ok();
return;
}
pending_len += charge(b.len()) as usize;
pending.push(b);
}
Some(Inbound::Close) | None => return,
Some(Inbound::Violation) => {
sink.send_ordered(close_msg(id)).await.ok();
return;
}
},
res = &mut connect => {
let err = match res {
Ok(Ok(s)) => break s,
Ok(Err(e)) => e.to_string(),
Err(e) => e.to_string(),
};
log::debug!("port forward channel {} connect {} failed: {}", id, addr, err);
sink.send_ordered(opened_msg(id, false, &unreachable_message(&addr, is_rdp), 0)).await.ok();
return;
}
}
};
// Granted before `opened` leaves, so the peer can never be ahead of it.
window.lock().unwrap().grant(CHANNEL_WINDOW - INITIAL_WINDOW);
if sink
.send_ordered(opened_msg(id, true, "", CHANNEL_WINDOW))
.await
.is_err()
{
return;
}
let (reader, writer) = socket.into_split();
run_channel(id, reader, writer, Vec::new(), pending, credit, window, inbound, sink, teardown).await;
}
/// The same words the raw pipe puts in its login error, so one problem reads
/// the same whichever path the peer takes.
fn unreachable_message(addr: &str, is_rdp: bool) -> String {
format!(
"Failed to access remote {}. Please make sure it is reachable/open.",
if is_rdp { "RDP" } else { addr }
)
}
#[cfg(test)]
mod tests {
use super::*;
use crate::port_forward_mux::{CHANNEL_WINDOW, INITIAL_WINDOW, MAX_CHANNELS, MIN_FRAME_CHARGE};
use hbb_common::{
message_proto::{message, port_forward_channel},
tokio::{
self,
io::{AsyncReadExt, AsyncWriteExt},
net::TcpListener,
sync::mpsc,
time::Instant,
},
};
fn rt() -> tokio::runtime::Runtime {
tokio::runtime::Builder::new_current_thread()
.enable_all()
.build()
.unwrap()
}
/// An echo server standing in for the forward target.
async fn echo_target() -> u16 {
let l = TcpListener::bind("127.0.0.1:0").await.unwrap();
let port = l.local_addr().unwrap().port();
tokio::spawn(async move {
loop {
let (mut s, _) = l.accept().await.unwrap();
tokio::spawn(async move {
let mut buf = [0u8; 4096];
loop {
let n = s.read(&mut buf).await.unwrap_or(0);
if n == 0 || s.write_all(&buf[..n]).await.is_err() {
return;
}
}
});
}
});
port
}
fn open(id: i32, port: u16) -> PortForwardChannel {
let mut ch = PortForwardChannel::new();
ch.set_open(PortForwardOpen {
channel_id: id,
host: "127.0.0.1".to_owned(),
port: port as i32,
window: CHANNEL_WINDOW,
..Default::default()
});
ch
}
fn data(id: i32, bytes: &[u8]) -> PortForwardChannel {
let mut ch = PortForwardChannel::new();
ch.set_data(PortForwardData {
channel_id: id,
data: Bytes::copy_from_slice(bytes),
..Default::default()
});
ch
}
fn close(id: i32) -> PortForwardChannel {
let mut ch = PortForwardChannel::new();
ch.set_close(PortForwardClose { channel_id: id, ..Default::default() });
ch
}
async fn next_frame(rx: &mut mpsc::UnboundedReceiver<(Instant, Arc<Message>)>) -> PortForwardChannel {
let (_, m) = rx.recv().await.unwrap();
match &m.union {
Some(message::Union::PortForwardChannel(ch)) => ch.clone(),
other => panic!("unexpected {:?}", other),
}
}
fn opened(ch: &PortForwardChannel) -> (i32, bool) {
match &ch.union {
Some(port_forward_channel::Union::Opened(o)) => (o.channel_id, o.success),
other => panic!("expected opened, got {:?}", other),
}
}
fn data_of(ch: &PortForwardChannel) -> (i32, Vec<u8>) {
match &ch.union {
Some(port_forward_channel::Union::Data(d)) => (d.channel_id, d.data.to_vec()),
other => panic!("expected data, got {:?}", other),
}
}
#[test]
fn open_connects_and_echoes_pipelined_data() {
rt().block_on(async {
let port = echo_target().await;
let (tx, mut rx) = mpsc::unbounded_channel();
let mut mux = PortForwardMux::new(tx, format!("127.0.0.1:{}", port));
mux.handle(open(1, port), || true);
mux.handle(data(1, b"ping"), || true);
assert_eq!(opened(&next_frame(&mut rx).await), (1, true));
assert_eq!(data_of(&next_frame(&mut rx).await), (1, b"ping".to_vec()));
mux.handle(close(1), || true);
});
}
#[test]
fn unreachable_target_fails_open_and_discards_pipelined_data() {
rt().block_on(async {
let l = TcpListener::bind("127.0.0.1:0").await.unwrap();
let port = l.local_addr().unwrap().port();
drop(l);
let (tx, mut rx) = mpsc::unbounded_channel();
let mut mux = PortForwardMux::new(tx, format!("127.0.0.1:{}", port));
mux.handle(open(1, port), || true);
mux.handle(data(1, b"lost"), || true);
assert_eq!(opened(&next_frame(&mut rx).await), (1, false));
assert!(tokio::time::timeout(std::time::Duration::from_millis(50), rx.recv()).await.is_err());
});
}
#[test]
fn permission_denied_refuses_without_spawning() {
rt().block_on(async {
let port = echo_target().await;
let (tx, mut rx) = mpsc::unbounded_channel();
let mut mux = PortForwardMux::new(tx, format!("127.0.0.1:{}", port));
mux.handle(open(1, port), || false);
assert_eq!(opened(&next_frame(&mut rx).await), (1, false));
assert_eq!(mux.live_channels(), 0);
});
}
#[test]
fn a_revoked_permission_refuses_new_channels_and_keeps_live_ones() {
rt().block_on(async {
let port = echo_target().await;
let (tx, mut rx) = mpsc::unbounded_channel();
let mut mux = PortForwardMux::new(tx, format!("127.0.0.1:{}", port));
mux.handle(open(1, port), || true);
assert_eq!(opened(&next_frame(&mut rx).await), (1, true));
// `enable-tunnel` is consulted per `open`, so turning it off
// mid-session stops new channels; the live one keeps relaying.
mux.handle(open(2, port), || false);
assert_eq!(opened(&next_frame(&mut rx).await), (2, false));
mux.handle(data(1, b"still relayed"), || false);
assert_eq!(data_of(&next_frame(&mut rx).await), (1, b"still relayed".to_vec()));
assert_eq!(mux.live_channels(), 1);
});
}
#[test]
fn close_while_connecting_sends_no_opened() {
rt().block_on(async {
// `close` is queued before the task is first polled. Its `select!` is
// biased towards the command arm, so even a connect that completes on
// that same poll loses: no `opened` may ever be sent.
let port = echo_target().await;
let (tx, mut rx) = mpsc::unbounded_channel();
let mut mux = PortForwardMux::new(tx, format!("127.0.0.1:{}", port));
mux.handle(open(1, port), || true);
mux.handle(close(1), || true);
assert!(tokio::time::timeout(std::time::Duration::from_millis(200), rx.recv()).await.is_err());
assert_eq!(mux.live_channels(), 0);
});
}
#[test]
fn over_window_data_closes_only_that_channel() {
rt().block_on(async {
let port = echo_target().await;
let (tx, mut rx) = mpsc::unbounded_channel();
let mut mux = PortForwardMux::new(tx, format!("127.0.0.1:{}", port));
mux.handle(open(1, port), || true);
mux.handle(open(2, port), || true);
let mut seen = 0;
while seen < 2 {
opened(&next_frame(&mut rx).await);
seen += 1;
}
let too_much = vec![0u8; CHANNEL_WINDOW as usize + 1];
mux.handle(data(1, &too_much), || true);
let ch = next_frame(&mut rx).await;
match &ch.union {
Some(port_forward_channel::Union::Close(c)) => assert_eq!(c.channel_id, 1),
other => panic!("expected close, got {:?}", other),
}
mux.handle(data(2, b"still fine"), || true);
assert_eq!(data_of(&next_frame(&mut rx).await), (2, b"still fine".to_vec()));
});
}
#[test]
fn an_over_window_frame_drops_the_channel_at_once() {
rt().block_on(async {
let port = echo_target().await;
let (tx, mut rx) = mpsc::unbounded_channel();
let mut mux = PortForwardMux::new(tx, format!("127.0.0.1:{}", port));
mux.handle(open(1, port), || true);
opened(&next_frame(&mut rx).await);
let too_much = vec![0u8; CHANNEL_WINDOW as usize + 1];
mux.handle(data(1, &too_much), || true);
// Gone before the channel task has run: whatever the peer keeps
// sending for this id can no longer queue anything.
assert_eq!(mux.live_channels(), 0);
mux.handle(data(1, &too_much), || true);
assert_eq!(mux.live_channels(), 0);
let ch = next_frame(&mut rx).await;
match &ch.union {
Some(port_forward_channel::Union::Close(c)) => assert_eq!(c.channel_id, 1),
other => panic!("expected close, got {:?}", other),
}
});
}
#[test]
fn open_to_a_target_other_than_the_login_target_is_refused() {
rt().block_on(async {
let a = echo_target().await;
let b = echo_target().await;
let (tx, mut rx) = mpsc::unbounded_channel();
let mut mux = PortForwardMux::new(tx, format!("127.0.0.1:{}", a));
mux.handle(open(1, a), || true);
assert_eq!(opened(&next_frame(&mut rx).await), (1, true));
// Approval was for target a; b needs a login of its own.
mux.handle(open(2, b), || true);
let ch = next_frame(&mut rx).await;
match &ch.union {
Some(port_forward_channel::Union::Opened(o)) => {
assert_eq!((o.channel_id, o.success), (2, false));
assert!(!o.message.is_empty());
}
other => panic!("expected opened, got {:?}", other),
}
assert_eq!(mux.live_channels(), 1);
});
}
#[test]
fn demux_admits_only_the_initial_window_before_opened() {
rt().block_on(async {
let port = echo_target().await;
let (tx, mut rx) = mpsc::unbounded_channel();
let mut mux = PortForwardMux::new(tx, format!("127.0.0.1:{}", port));
mux.handle(open(1, port), || true);
// The channel task has not run yet: the demultiplexer alone
// decides what may sit in the queue before `opened`.
assert_eq!(mux.recv_window_remaining(1), Some(INITIAL_WINDOW));
assert_eq!(opened(&next_frame(&mut rx).await), (1, true));
assert_eq!(mux.recv_window_remaining(1), Some(CHANNEL_WINDOW));
});
}
#[test]
fn pending_bytes_are_bounded_by_initial_window_before_opened() {
// A loopback connect completes before a task can observe "connecting",
// so the bound is pinned on the pure predicate the task uses.
assert!(pending_fits(0, INITIAL_WINDOW as usize));
assert!(pending_fits(
INITIAL_WINDOW as usize - MIN_FRAME_CHARGE as usize,
1
));
// A 1-byte frame costs a whole minimum charge here too.
assert!(!pending_fits(
INITIAL_WINDOW as usize - MIN_FRAME_CHARGE as usize + 1,
1
));
assert!(!pending_fits(usize::MAX, 1));
}
/// A target that accepts and hangs up at once, so every channel ends on
/// the target's EOF — the case where only the next `open` frees the entry.
async fn drop_target() -> u16 {
let l = TcpListener::bind("127.0.0.1:0").await.unwrap();
let port = l.local_addr().unwrap().port();
tokio::spawn(async move {
loop {
let (s, _) = l.accept().await.unwrap();
drop(s);
}
});
port
}
#[test]
fn open_frees_dead_entries_so_the_cap_counts_live_channels() {
rt().block_on(async {
let port = drop_target().await;
let (tx, mut rx) = mpsc::unbounded_channel();
let mut mux = PortForwardMux::new(tx, format!("127.0.0.1:{}", port));
for id in 1..=(MAX_CHANNELS as i32 * 2) {
mux.handle(open(id, port), || true);
assert_eq!(opened(&next_frame(&mut rx).await), (id, true));
// The task sends `close` on the target's EOF and exits; the
// entry is dead until the next `open` drops it.
let ch = next_frame(&mut rx).await;
match &ch.union {
Some(port_forward_channel::Union::Close(c)) => assert_eq!(c.channel_id, id),
other => panic!("expected close, got {:?}", other),
}
tokio::task::yield_now().await;
}
});
}
}

View File

@@ -1294,7 +1294,13 @@ impl<T: InvokeUiSession> Session<T> {
// override only if true
if true == force_relay {
self.lc.write().unwrap().force_relay = true;
let mut lc = self.lc.write().unwrap();
lc.force_relay = true;
// An explicit retry-via-relay is a decision about this peer, not transport
// necessity: Relay-only ICE for this round like any force-always-relay session,
// and it is the one kind of relay that belongs in the peer's saved config.
lc.policy_relay = true;
lc.peer_relay = true;
}
self.lc.write().unwrap().peer_info = None;
self.reconnect_count.fetch_add(1, Ordering::SeqCst);
@@ -1944,6 +1950,7 @@ pub async fn io_loop<T: InvokeUiSession>(handler: Session<T>, round: u32) {
let key = crate::get_key(false).await;
#[cfg(not(any(target_os = "android", target_os = "ios")))]
if handler.is_port_forward() {
handler.lc.write().unwrap().port_forward_mux = crate::port_forward::mux_enabled();
if handler.is_rdp() {
let port = handler
.get_option("rdp_port".to_owned())