Files
rustdesk/src/lang/be.rs
RustDesk ae6af2de43 Webrtc (#15684)
* feat: add rendezvous WebRTC signaling fields

* feat: route WebRTC ICE on controlled side

* feat: race WebRTC as a direct transport enhancement

* fix: route WebRTC ICE through rendezvous paths

* feat: WebRTC transport racing, DTLS identity binding, and pc-leak fixes

- prefer-P2P racing (race_transports_prefer_webrtc) across punch and RelayResponse; ICE bridge with 400ms candidate resend
- controlled-side answerer and ICE routing; sign local DTLS fingerprint into SignedId, controller verifies the binding fail-closed
- fix pc leaks: close_webrtc() on insecure-decline paths (io_loop, port_forward); compute direct before disarming the offerer guard
- point hbb_common to the WebRTC data-plane commit 9f5a296

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix: preserve WebRTC transport preference

* feat: decouple WebRTC from UDP punch, route controlled signaling over TCP

- the WebRTC offer now rides any punch request; only an offer-less request
  may close and reuse the rendezvous socket for TCP punching
  (request_allows_tcp_punch replaces the udp_port-based invariant), with a
  separate offer-less request racing as the TCP fallback
- WebSocket mode no longer disables WebRTC — ws only tunnels the
  signaling/relay legs while ICE stays the only P2P path there; SOCKS proxy
  still disables it (ICE would bypass the proxy and leak the real IP)
- controlled side: WebRTC-only punch replies and trickled ICE candidates go
  over dedicated TCP connections to the rendezvous server instead of the UDP
  mediator channel, for ws/TCP-only hbbs deployments; drop the now-redundant
  rz_sender plumbing and the 400ms candidate re-send on that leg
- guard is_udp handling against responses to requests that advertised no
  udp_port; skip the IPv6 socket bind under force-relay
- test_udp_uat: drop the STUN port race — the punch port must come from the
  rendezvous server's TestNatResponse observing this socket's mapping, a
  STUN probe from another socket can advertise an unreachable port
- bump hbb_common (webrtc 0.13 MSRV pin rationale + upgrade checklist docs)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix: KCP/UDP resilience to ICMP resets; optional KCP congestion control

- treat ICMP-driven UDP socket errors (WSAECONNRESET 10054 on Windows,
  ECONNREFUSED on Linux) as packet loss in punch_udp and the KCP pump
  instead of tearing the session down; KCP retransmits through them and a
  truly dead link is still reaped by the pong/app-level timeouts
- resolve STUN hostnames via tokio::net::lookup_host so DNS never blocks a
  runtime worker; fix the inverted non-IPv4 error message
- add enable-kcp-congestion-control option (default on): switch the turbo
  profile to nc=0 so brief loss on constrained links no longer spirals into
  stalls; sender-side only, no wire negotiation
- pin kcp-sys to the rustdesk-patches branch: upstream main lost the
  RustDesk patches on the EasyTier sync, and this branch also wires
  set_kcp_config_factory into connection setup, making the option effective

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix: carry switch_code through WebRTC relay fallbacks after rebase

The rebase onto master (switch-code feature) added an 8th request_relay
parameter; pass the interface's switch code from both WebRTC->relay
fallback paths so a role-swap session survives the fallback. Also drop
a duplicate bindgen 0.72.1 entry the Cargo.lock merge produced.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ExUfAkYbq8UC9pQCiLy8TQ

* fix: don't let the preferred branch's own relay preempt a direct fallback

race_transports_prefer_webrtc committed any success from its first argument
outright, on the assumption that it is the WebRTC connect. It is not: the call
site passes a whole punch attempt, which internally falls back to request_relay
when its direct transports fail. That relay was therefore committed instantly
while the offer-less fallback's TCP punch was still in flight — inverting the
preference this function exists to enforce, since the is_p2p predicate the
caller already supplies was applied only to the `others` branch.

Apply it to both branches: a direct result from either side still commits
immediately, and a relayed result from either side is held for the window so
the other side can land something direct. Also commit a held connection when
the surviving branch errors, which the previous code only did on the first
branch's failure path.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ExUfAkYbq8UC9pQCiLy8TQ

* fix: evict the oldest pending ICE candidate, not the newest

Candidates arrive in gathering order — host, then srflx, then relay — so a
full buffer was discarding exactly the ones that traverse NAT while keeping
host ones that only work on a shared LAN. Evict from the front instead.

Also document why the controller's ICE bridge must not reconnect on error, in
contrast to the controlled side's per-candidate retry: its socket address is
the return route itself (mangled into PunchHole.socket_addr, echoed back in
IceCandidate.socket_addr, resolved through tcp_punch), so a reconnect would
arrive from an address no route points at, and the server drops the old entry
when the connection closes. Once it dies both directions are dead, and
abandoning WebRTC is the correct response rather than retrying.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ExUfAkYbq8UC9pQCiLy8TQ

* fix: bound log volume on sites whose rate a peer or retry loop controls

Debug output goes to the log file, so a site that fires per received message
or per retry lets someone else decide how much a machine writes to disk. The
WebRTC work added the first such sites.

- KCP io loop: absorbing ICMP errors as packet loss made a broken socket write
  ~100 lines a second for the 60s until the pong timeout reaps it. Log by run
  instead: one line when a run starts, one per ~5s while it persists so a stuck
  socket stays visible, and one on recovery with the total.
- punch_udp: the recv error retries every 10ms for up to MAX_TIME, so one line
  per occurrence wrote thousands per punch. Log the first, report the count in
  the timeout message.
- ICE candidate paths (client, mediator): the peer sets the candidate rate and
  the rendezvous route carrying them needs no prior punch, so throttle to one
  line a minute each with the suppressed count.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ExUfAkYbq8UC9pQCiLy8TQ

* fix: the KCP io throttle reset itself every cycle, so it never throttled

The send and recv arms shared one counter, and an ICMP error on a connected
socket is reported once and then cleared — so the steady state is an
alternation: the send succeeds and clears the counter, the next recv reports
the error and finds the counter at 1, and logs. Every error still wrote a
line, at the ~100/s the previous commit set out to stop, while the
persistent-failure and recovery branches were unreachable.

Use one LogThrottle per direction instead of a hand-rolled counter. That
removes the shared state the bug lived in, drops a third throttling mechanism
in favour of the one already added, and leaves the surrounding `if let Err`
untouched rather than reshaping it into a match.

Also fix test_udp_uat's socket-error arm, the untreated twin of the punch_udp
site: it had no backoff at all, so a persistent error re-armed recv
immediately and spun the loop at CPU speed, one warn line per iteration.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ExUfAkYbq8UC9pQCiLy8TQ

* bump kcp-sys: 14 review fixes on rustdesk-patches (6e44b93 -> fa51c15)

Picks up the handshake-recovery work plus the review round on top of it:
ABBA deadlock between the endpoint's two DashMaps, graceful-close tail
truncation, mid-stream hole on ikcp_send failure, FIN retransmission for
lost-FIN half-open hangs, SYN-ACK budget burned on dropped packets,
spurious ConnectTimeout after a completed handshake, accept-backlog
overflow stranding conns, aliasing UB in the output callback, and the
log-facade/throttling cleanup (per-packet sites no longer reach the
debug-level file logger, peer-rate warns throttled).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ExUfAkYbq8UC9pQCiLy8TQ

* ws: decouple ICE policy from force_relay — full-ICE WebRTC over WebSocket

WebSocket support folds into force_relay because a ws tunnel kills
classic TCP/UDP punching — but that conflated transport necessity with
relay policy, and the WebRTC decisions keyed off the merged flag: a ws
client built no offerer at all without TURN, and only a Relay-only-ICE
one with it. ws deployments could never reach a direct WebRTC
connection, which is exactly the path they are supposed to live on.

Split the flag. LoginConfigHandler now tracks policy_relay (the
force-always-relay option, an explicit relay request — /r ids and
retry-via-relay included — and proxy) separately; force_relay stays
policy_relay || use_ws() and keeps governing the classic paths, so
non-ws behavior is unchanged everywhere:

- the offerer's existence and ICE policy follow policy_relay: under
  pure ws the offer gathers every candidate type and may go direct;
  under relay-by-policy it stays Relay-only ICE, TURN-gated, exactly
  as before;
- the RelayResponse race applies the prefer-P2P window under ws (a
  direct ICE path is worth delaying an already-ready relay for) while
  policy relay keeps first-success semantics;
- the request carries webrtc_all_ice (hbb_common 64b54ab) so the
  controlled side knows the offer is full-ICE: it answers with full ICE
  and no TURN requirement, while offers without the bit keep today's
  relay-only answer path on every version-skew combination.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ExUfAkYbq8UC9pQCiLy8TQ

* bump kcp-sys: 7 review fixes on rustdesk-patches (fa51c15 -> 023a006)

Reverts the connect/accept/add_conn changes that regressed concurrent
connects (the state_map guard held across add_conn is load-bearing), states
the single-conn contract on KcpEndpoint so shared-endpoint behaviour stops
consuming review effort, pins the two invariants that keep truncated input
from aborting under panic='abort', and fixes three findings from external
review: sendwnd() echoing raw config instead of KCP's effective window (a
non-positive factory value stalled sending forever), the passive closer's
lost final FIN delaying EOF by up to ~20s, and the doubled window
overflowing for extreme factory values.

Lock-only change: cargo update -p kcp-sys also re-picked libloading's
windows-targets between two versions already present in the lock; that was
reverted to keep this commit to the one line it is about. cargo metadata
--locked passes on the result.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* ws: read the all-ICE declaration from the offer envelope, drop the proto field

Companion to hbb_common 68d2729: the full-ICE declaration now lives as
an `ice_policy: "all"` key inside the webrtc:// envelope, so the request
assembly no longer sets webrtc_all_ice and the controlled side asks the
envelope (endpoint_declares_all_ice) instead of a PunchHole field. The
rendezvous server carries the offer opaquely — no forwarding to keep in
sync. Skew behavior is unchanged: an unmarked or unparseable envelope
reads as the old Relay-only semantics.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ExUfAkYbq8UC9pQCiLy8TQ

* add enable-webrtc option; gate test_ipv6 under forced relay

OPTION_ENABLE_WEBRTC (hbb_common 48c2d4d) follows the udp/ipv6 punch
options end to end: default on against the public server, off against
private ones, same settings UI placement on desktop and mobile, and the
same bool2option local-option handling. Gates:

- controller: should_create_webrtc_offerer checks it first — no pc, no
  STUN/TURN gathering, no offer in the request;
- controlled: unlike the udp/ipv6 legs, which deliberately follow the
  request, answering builds a pc that gathers ICE from this host, so
  the answerer honors this machine's own switch too.

Translations for "Enable WebRTC P2P connection" added to all 50 lang
files next to the IPv6 entry (IPv6 and WebRTC are invariant terms in
the same grammatical slot in every one of them).

Also stop probing v6 reachability (test_ipv6) under any forced relay:
the v6 punch socket is never bound there, so the probe was wasted work
on every ws/proxy/relay connection.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ExUfAkYbq8UC9pQCiLy8TQ

* kcp: client-side integration tests over real loopback sockets

kcp-sys has been through two review rounds of behavioral fixes; the
client wrapper (kcp_io pumps, connect/accept deadlines, framed-stream
adaptation, guard lifetimes) had no tests pinning what rustdesk actually
relies on. Four now do, each through real 127.0.0.1 UDP sockets and the
BytesCodec framing sessions use:

- handshake + bidirectional framed roundtrip + graceful close: the peer
  observes end-of-stream instead of hanging (guard outlives the framed
  stream so the FIN goes out);
- a writer that queues 50 frames and closes immediately loses none of
  them - the client-side pin for the close-tail-drain semantics;
- socket errors after the peer vanishes are treated as loss: writes keep
  succeeding, nothing tears down (ICMP is advisory on connected UDP);
- the connect deadline holds when nothing answers.

Mutation-checked: dropping inbound forwarding in kcp_io reddens exactly
the three tests that need the pump, and the timeout test alone stays
green.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ExUfAkYbq8UC9pQCiLy8TQ

* ipc/auth: replace the local throttle with the shared throttled_log!

auth.rs predated hbb_common's LogThrottle and grew its own equivalent:
same shape (last_log_at + suppressed), same 5s interval, plus a helper
and three OnceLock<Mutex<..>> statics. It also counted the other way -
excluding the event being reported - so each of the three sites carried
two near-identical log::warn! arms to avoid printing "suppressed 0".

The shared macro covers all of it: one static per call site declared by
the expansion, and the multiplicity suffix appears only when there is
one, which is what those duplicated arms were for. 102 lines out, 27 in.

Behavior difference, deliberate: a burst now reads "(x47)" - the total
including this line - instead of "(suppressed 46 similar events)". One
number, no arithmetic, and one convention across the codebase.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ExUfAkYbq8UC9pQCiLy8TQ

* kcp: make the congestion-control profile opt-in, not the default

The branch had flipped KCP to nc=0 (built-in congestion window) for
every session. That is a transport-behavior change for all users made on
reasoning alone, and the reasoning does not decide it: which profile wins
depends on why packets are being lost.

nc=1 - what RustDesk has always shipped - never shrinks the send window,
so on a genuinely congested uplink it deepens the loss it is reacting to.
But nc=0's backoff is blunt: a fast retransmit halves the window while an
RTO sets cwnd = 1 outright (ikcp.c) and recovery slow-starts from one
packet, so on a link with random loss and no congestion - Wi-Fi
interference, a long-haul path - it reads loss as congestion and can
stall an interactive stream for seconds. That failure mode is also the
more visible one to a remote-desktop user.

No benchmark settles this either: a loopback A/B has no bottleneck queue,
hence no congestion to control, and would flatter nc=1 by construction.
Deciding it needs a shaped link or field data.

So keep the profile users already run and let the other one be asked for
("enable-kcp-congestion-control" = "Y"). Flipping the default later is a
one-line change once there is evidence. kcp-sys keeps its own test
covering the nc=0 path.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ExUfAkYbq8UC9pQCiLy8TQ

* android: define getifaddrs/freeifaddrs for the api-21 sysroot

Turning on hbb_common's "webrtc" feature pulls webrtc-util into the android
link, and its ifaces() -- reached from vnet::Net::new() on every ICE gather --
calls getifaddrs(). bionic exports getifaddrs/freeifaddrs only from API 24,
while flutter/ndk_*.sh builds against --platform 21, so every abi failed to
link on the undefined symbols.

Raising the platform to 24 would have to drag minSdkVersion 22 with it and
turn the link error into a load-time one on Android 5.1/6.0, so define the
two symbols instead, using the RTM_GETLINK + RTM_GETADDR netlink dump bionic
itself uses. The definition also shadows bionic's on API >= 24 rather than
delegating to it, so the path that ships is the path every test device runs.

Checked against synthesised netlink dumps on the host -- link/address parsing,
prefix masks, point-to-point, ipv6 scope ids, malformed and truncated messages
-- under UBSan and byte-exact guard malloc, with a deliberately unsigned
remainder as the negative control.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* fix three ways ws + WebRTC could not work in practice

Review of #15684 and hbb_common#579. Each of these left the code reading
correct while the feature did not function.

- The RelayResponse race classified P2P with `result.2 == "IPv6"`, but
  that site's futures are only ever the relay ("Relay"/"WebSocket") and
  the WebRTC branch's own "WebRTC" — so the predicate was constantly
  false. When the relay landed first the result was still right (the
  webrtc arm's `others_fut.is_none()` fallback), but when WebRTC
  connected FIRST it was parked as if it were a relay and the relay was
  committed on arrival, discarding a live direct connection. That is the
  LAN case: the better the network, the worse the outcome. Classify by
  what the label means, via is_direct_transport, and test both orderings
  — only the relay-first one was covered.

- handle_peer_info wrote "force-always-relay=Y" into the peer's saved
  config whenever force_relay was set, which now includes the WebSocket
  transport. One ws session therefore turned the peer into a permanent
  relay-by-policy peer, and relay-by-policy means Relay-only ICE, so
  WebRTC could never go direct to it again — the flagship path worked
  exactly once. Persist policy_relay, which is the user's choice; the
  transport is a property of this client, not of the peer.

- The answerer gated on this machine's enable-webrtc option, but that is
  LocalConfig: the UI process writes it and never syncs it over IPC,
  while handle_punch_hole runs in the server process, which on Windows
  resolves LocalConfig under a different profile and reads the
  private-server default of "N". The gate refused to answer in exactly
  the self-hosted deployments the transport exists for. Drop it: the
  answerer follows the request, like the udp/ipv6 legs, and the option
  still gates the feature where it can — an offer only exists because
  some controller had it enabled.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ExUfAkYbq8UC9pQCiLy8TQ

* webrtc: close without an await point; do not report an unknown path as direct

- close_webrtc is no longer async (hbb_common 88f965f), so the ten call
  sites in port_forward and io_loop - all inside select! arms or futures
  the UI can abandon - can no longer be cancelled mid-teardown, which
  left the pc unclosable and its session entry stranded. Client's own
  spawn_close_webrtc went with it: the runtime-teardown guard it existed
  for now lives in close_detached, so both Drop paths share one
  implementation.

- webrtc_relayed() returns None when no candidate pair is selected or
  the pc closed under a concurrent teardown, and both call sites read
  that as "not relayed", i.e. direct. A TURN-relayed session could
  therefore be shown to the user as peer-to-peer. Claiming a direct path
  needs evidence of one, so an unknown answer now counts as relayed.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ExUfAkYbq8UC9pQCiLy8TQ

* scrap/benchmark: give the Duration divisor an explicit u32

The webrtc feature pulls time 0.3 into scrap's graph (hbb_common ->
webrtc -> webrtc-dtls -> der-parser -> asn1-rs), and that crate carries
an `impl Div<time::Duration> for std::time::Duration`. Orphan rules
allow it because the RHS is its own type, and trait impls are visible
across the whole dependency graph without a use, so std::time::Duration
now has two Div candidates. `yuv_count as _` casts to a plain inference
variable, which both candidates fit, so it stops resolving:

  error[E0282]: type annotations needed
    --> libs/scrap/examples/benchmark.rs:146:33

Only two of the four sites are reported - rustc emits one E0282 per
function body - so all four are annotated. The already-explicit
`as u32` at the hwcodec site and `start.elapsed() / cnt` are unaffected,
the latter because an integer literal's variable can only unify with an
integral type and rules the time impl out on its own.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* webrtc: judge the race by the resolved path, not the label; bound the ICE queue

Third review round. Two of these are regressions from the previous one.

- The RelayResponse race predicate was `is_direct_transport(result.2)`,
  which answers true for the label "WebRTC" - but WebRTC is only a
  direct path when ICE nominated a non-TURN pair. A TURN-relayed WebRTC
  result therefore committed instantly and cancelled the IPv6 attempt
  racing beside it, which is the same inversion the previous fix removed
  in the other direction. (That fix was also argued from a wrong premise:
  the site does carry an IPv6 future, pushed ~50 lines earlier than the
  relay one.) Each future now resolves whether its path is direct and
  the predicate reads that bool, matching the outer race, and the
  downstream recomputation goes away.

- policy_relay still folded in Config::is_proxy(), and that is what gets
  persisted into the peer's config as force-always-relay - so one
  session through a proxy pinned the peer to relay forever and disabled
  WebRTC for it, exactly the latch the previous round fixed for
  WebSocket. Split out peer_relay: the saved option or an explicit
  request for THIS peer, and the only part written back.

- The controlled side buffered remote ICE candidates in an unbounded
  channel while the controller caps the same buffer at 64, and draining
  one costs a JSON parse plus the ICE agent's lock. Whoever can reach a
  session's route could grow it without limit inside the long-lived
  service process. Bounded, with the overflow logged through the
  existing throttle.

- That route was also removed by key alone when an answerer finished, so
  a punch retry that built a fresh answerer under the same fingerprint
  had its live sender deleted by the previous one's cleanup - after
  which it received no candidates at all. Evict only our own sender, the
  way the session cache already guards the analogous case.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ExUfAkYbq8UC9pQCiLy8TQ

* webrtc: trim the comments to AGENTS.md length; drop is_direct_transport

386 added comment lines down to 287 across client, mediator, kcp_stream
and common. Same rule as hbb_common 3d64e43: out go past-bug narration,
rejected alternatives, measurements and restatements of the code; the
non-derivable why stays.

is_direct_transport goes with them. Judging the race by a transport
label was replaced by the resolved direct flag, leaving it used only by
its own test — and, having been inserted between the doc comment and
race_transports_prefer_webrtc, it had also taken that function's
contract with it. Removing it reattaches the doc where it belongs.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ExUfAkYbq8UC9pQCiLy8TQ

* webrtc: fix race edge cases that discard or mislabel a direct connection

Three correctness fixes in the transport race, plus three convention
cleanups.

- race_transports_prefer_webrtc committed a relayed result while a direct
  attempt was still in flight: the others arm returned on
  webrtc_fut.is_none() even with an unfinished direct future, and the
  WebRTC-error arm returned a held relay without checking others_fut. A
  relay is now committed only when nothing direct can still arrive (or
  the window expires); a parked relay is also preferred over composing
  an error when both sides fail. Three regression tests, mutation-checked.

- connect()'s plain select_ok let a TURN-relayed WebRTC win as "first
  success", dropping still-racing UDP/IPv6 direct attempts and reporting
  the relayed pair as direct. It now runs through the same prefer-P2P
  race with each attempt carrying whether its path is direct, and the
  WebRTC future resolves is_relayed() so a TURN win is held behind
  direct attempts, not committed as one.

- The RelayResponse path kept direct == true when a WebRTC win's DTLS
  handshake failed and it fell back to relay, so the relay was reported
  P2P. Clear the flag with the transport switch.

- Trim the OffererGuard doc to the three-line max; move the new
  enable-webrtc localization key to the end of every lang list; the KCP
  option constant moved to hbb_common config::keys (0f663aa).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ExUfAkYbq8UC9pQCiLy8TQ

* bump hbb_common: WebRTC peer connections own their I/O runtime

Closing the controlling window left the controlled side waiting out
ICE decay — ~25-30s in the peer's log, its disconnected/failed ladder
running to completion — where TCP delivers a FIN at once. The session
end closed the pc by spawning onto io_loop's own
`#[tokio::main(flavor = "current_thread")]` runtime, which is dropped
the moment io_loop returns, and nothing after that call yields: the
task was never polled even once, so no DTLS close_notify ever left.

Every attempt to fix that on the caller's side failed the same way,
because the mismatch was never about where the close ran: a pc's UDP
sockets register with the reactor, and its ICE/DTLS/SCTP pumps spawn
on the runtime, that is current while it is built — so a pc created
by a session outlives the only runtime that can drive its I/O, and a
close driven anywhere else completes without reaching the wire.

The bump homes them where they can outlive any caller: WebRTCStream
builds on a process-lifetime runtime and every detached close runs
there as its own never-cancelled task. io_loop keeps its plain
close_webrtc() calls and only documents why nothing here may spawn or
await the teardown on the dying session runtime.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016HV43uh1ztv6Wm5qi3Y1ne

* fix: give the UDP NAT test a real window when the TCP clock is faked

The punch request carries udp_port only if the rendezvous server's
TestNatResponse has arrived, and the wait for it was bounded by
rtt / 2 — half the TCP connect time, on the assumption that TCP and
UDP round trips are comparable and the test, started earlier, has
already answered.

A transparent TCP proxy breaks that assumption: a TUN-mode VPN on the
host, or a redirect-mode proxy on the LAN gateway serving every device
behind it, completes the handshake locally in ~3ms while the real UDP
round trip is hundreds of ms. Log-confirmed against 5.161.65.208: ping
341ms, TCP connect 3.7ms, connect to a dead port there "succeeds" just
as fast. The window collapsed to ~1.5ms, udp_port stayed 0 on every
attempt, and UDP punch was never even requested — although UDP itself
passes such gateways untouched.

So use the TCP clock only when it is believable: below a plausible WAN
round trip it says nothing about the UDP path, and a flat ceiling
applies instead. The loop still exits the moment the port arrives, so
a genuinely nearby server pays nothing and only a UDP-dead network
waits out the ceiling — on the udp-carrying round alone, while the
parallel pure-TCP round is unaffected.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016HV43uh1ztv6Wm5qi3Y1ne

* feat: make the TCP punch a user option, with TCP as the backstop

TCP punching was the one direct transport without a switch, while UDP,
IPv6 and WebRTC each had one. Add "Enable TCP hole punching" above the
UDP toggle on both desktop and mobile, default on — including on
self-hosted servers, since unlike the other three (whose default-off
there guards against an hbbs that cannot forward their fields) TCP
punching has always been supported by every server.

Turning all four off would leave no way to punch at all, so TCP runs
regardless in that case. That backstop keys off the switches alone: a
transport that is enabled but fails to materialize — no public v6
address, no NAT port, a failed offerer — is already covered by the
relay fallback for a round that ends up with no usable direct
transport. With the TCP punch off, the fallback request is skipped
too: it exists only to carry that punch, and would otherwise reach
connect() with nothing to try and merely open a second relay.

Known cost, unchanged behavior for the peer: the request carries no
field for this choice, so a peer that receives one with no udp_port and
no offer still punches a TCP hole and listens for a connection the
controller will not make. Representing the transport choice on the
wire needs a proto field and the server forwarding it.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016HV43uh1ztv6Wm5qi3Y1ne

* bump hbb_common: name the punch by every transport it carries

`get_local_endpoint_trickle` became `local_endpoint() -> &str`, which
cannot fail, so both call sites lose an unreachable error arm — the
mediator's closed a pc against a failure that no longer exists.

`punch_type` named one transport, and picked it off `allow_tcp_punch`.
A round carries several at once — a NAT port and a v6 address and an
offer — and since the TCP punch became a switch it can carry none, so
one name had to misreport both: the logs of the round that broke WebRTC
read "#1 UDP punch attempt" while the request also carried the v6
address and the offer that was actually failing, and a round with
nothing to punch with was labelled "WebRTC". List them instead —
"UDP+IPv6+WebRTC" — and call the empty round "Relay", which is what it
can still end as and what `typ` prints for it.

The offer is moved into the request rather than cloned into it; that
was its last use.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019UzcMTdYTEv2QbMHcTSUy3

* bump hbb_common: drop link-local IPv6 from ICE gathering

Also pin webrtc-util to a fork of 0.11.0 carrying a Windows IPv6 enumeration fix.
`ifaces` reads the adapter list's on-wire IPv6 bytes as host-order `[u16; 8]`, so on a
little-endian host every group comes out byte-swapped and unbindable: a peer's real
240e:369:9606:4600:f52a:7a8d:2530:4de0 is enumerated as e24:6903:696:46:2af5:8d7a:3025:e04d,
::1 as ::100 and fe80:: as 80fe::. Each fails to bind with WSAEADDRNOTAVAIL, so ICE gathers
no IPv6 host candidate at all on Windows - where a globally routable address is the one
NAT-free path a CGNAT'd peer has.

Never reported upstream; the unix twin of the same bug was fixed in webrtc-rs#475 (2023).
Fork: rustdesk-org/webrtc, branch rustdesk-patches, tag webrtc-util-0.11.0-win-ipv6.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019UzcMTdYTEv2QbMHcTSUy3

* bump hbb_common: name the family a WebRTC session runs over

`stream_type` reaches the UI as the transport that won the race, and every other transport
already carries the family in that label - the v6 punch reports `IPv6`. WebRTC does not: one
label covers both families, and it is the one path whose real remote address can differ from
the rendezvous-observed one the session is identified by.

Refine it at the hand-off to the UI rather than at the source: five sites in client.rs
compare `typ == "WebRTC"`, so widening the label there would silently move control flow.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019UzcMTdYTEv2QbMHcTSUy3

* bump hbb_common: one STUN list, and drop the dead IPv4 half

`test_ipv6` kept its own hand-written copy of the STUN servers. It now reads
`WebRTCStream::stun_servers()`, so an operator who points OPTION_ICE_SERVERS at their own
server gets it on both paths instead of one.

`test_bind_ipv6` sends nothing - `connect` only makes the kernel pick a route and a source
address - so the whole cost is DNS. It races the lookups rather than betting this host's
IPv6 support on whether the first entry happens to publish a AAAA where the user resolves
from; google's does not, from a Chinese resolver, and it was the entry being bet on.

`stun_ipv4_test`, `STUNS_V4` and `test_nat_ipv4` have had no callers since the punch stopped
taking its port from a second socket, and go.

`get_kcp_cc_enabled` reads the renamed option through `option2bool`, like every other one.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019UzcMTdYTEv2QbMHcTSUy3

* webrtc: take dcsctp's retransmission timings and IPv6-safe MTU

webrtc-sctp ships RFC 4960's RTO.Initial/RTO.Min (3000/1000), TCP's values for
arbitrary public paths. On this workload they set the recovery time outright:
a request/response exchange keeps one chunk in flight, so no later SACK ever
raises miss_indicator to the 3 that arms fast retransmit, and the T3 floor is
the only way back. A single loss during a handshake or a first keyframe
therefore costs whole seconds.

The fork now carries dcsctp's numbers instead - the SCTP implementation Google
wrote to replace usrsctp for Chrome's WebRTC data channels, the same realtime
workload: rto_initial 500, rto_min 400, a 220ms floor under the RTT variance,
and mtu 1191. INITIAL_MTU 1228 plus DTLS/UDP/IPv6 overhead is 1313, past the
1280 minimum, so every full-size chunk fragmented on an IPv6 path.

Both patch entries move to the new branch, which also carries the Windows IPv6
byte-swap fix, so one rev matches the whole webrtc 0.13 stack.

* udp: make the punch prove itself, and keep the listener answering

punch_udp sent a zero-length datagram and called the hole open on whatever
arrived next. The rendezvous NAT test's own leftover replies satisfy that
immediately - connect() does not flush the receive queue - so the retry loop
never ran and success meant nothing. The dead socket then cost KCP its full
timeout to rediscover, which is how a failed punch came to take 18 seconds.

Probes now carry a magic and a 64-bit transaction id, and both ends answer
each other's probes, so returning is a fact: a reply echoing our own id is the
one thing that proves the pair carries traffic both ways. With failure now
distinguishable from 'not yet', the window drops from 20s to 3s.

Two asymmetries fall out of that:

Only the connector stops on its own acknowledgement, because only it has
something to send next. An acknowledgement proves our probe came back, not
that the peer's probe was answered - and after punch_udp returns nothing
answers probes any more, since KCP's io loop drops anything shorter than its
header. A listener that stopped there would go mute while a peer whose own
probe or answer was lost - the normal state of a hole still opening - kept
probing an endpoint that works, until it timed out.

So the listener stops on the peer's first real packet instead, and hands that
packet to KcpStream::accept as its init_packet: its arrival proves the pair as
well as an acknowledgement would, and KCP never retransmits its SYN.

* webrtc: correct the RTT variance floor to dcsctp's scaling

The earlier commit took dcsctp's min_rtt_variance = 220 as a raw floor under
rttvar. dcsctp divides the option by kHeuristicVarianceAdjustment = 8.0 first,
a historical accident it kept because downstream users had measured good
values with it, so the intended floor is 27.5ms of variance contributing 110ms
to RTO. Flooring at 220 contributed 880ms instead, which on a 50ms path left
RTO within 7% of the 1000ms default this change exists to escape.

The fork also now records why T1/T2 share T3's RTO manager here, unlike
dcsctp's separate control timers: RTO_INITIAL is the T3 value for the first
DATA chunk, since no RTT sample exists before the first SACK.

* webrtc: skip the controller's ICE re-send instead of queueing it twice

The controller sends every candidate twice, because the server's hop to a
peer registered over UDP can lose one. The ICE agent that dedups repeats
sits downstream of the answerer's queue, so the answerer paid for both
copies: a slot, a JSON parse, and the ICE agent's lock, once per repeat.

Remember a digest of what was queued and skip the repeat. Recorded only
once queued, so a candidate a full queue refused stays repairable by the
re-send.

The queue's depth is unchanged. A real peer gathers well under it - four
STUN servers, link-local IPv6 filtered, one component - and the drain
empties it as candidates trickle in, so what this removes is the redundant
work, not an overflow.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019aokqJuhjvB3kijXtAg5Ns

* tcp: repeat the punch across the controller's dial window

The single punch leaves before hbbs has told the controller where to dial, so
it is never in flight at the same time as the controller's SYN: it opens our
NAT, meets nothing, and a gateway that answers it with RST takes the mapping
down with it, leaving the listener waiting on a hole that no longer exists.

Punch again while the controller may still be dialing, and race those punches
against the accept. That is two ways in where there was one: the mapping is
rebuilt if a RST took it, and once the controller sits in SYN_SENT one of the
punches meets its SYN and completes as a simultaneous open - which a punch sent
before the controller had been told anything never could. The crossing reaches
the punch rather than the listener because the two sockets share the address
but only the punch matches the four-tuple, which the tests now pin down.

There is no instant to aim at, and no window either. `Client::connect` sizes
the controller's dial only after our PunchHoleSent, from its own rendezvous
time and the direct failures it has recorded for us: CONNECT_TIMEOUT between
two known-asymmetric NATs that never failed, punch_time_used times three or
six otherwise, floored at a second - so a peer that failed once dials for a
second or two from then on, and none of that reaches this side. The repeats
therefore cover our own ceiling instead, CONNECT_TIMEOUT, which is exactly as
long as the accept has always been willing to take a connection through the
hole, and back off across it: dense at the start, where every window begins
and the short ones end, sparse afterwards, which is `punch_udp`'s shape for
the same reason. A window past that ceiling was lost before this change too,
and mostly to the controller's own kernel - Windows gives a SYN up at 21s,
Linux's next re-send after 15s is at 31s; a window short of it costs a few
SYNs to a port already closed.

No punch is cut on a per-attempt timeout; one in flight is bounded only by
the shared deadline plus PUNCH_GRACE. A punch is cancel-safe only while it is
still in SYN_SENT; once the controller's SYN has crossed it the socket is half
way through a handshake, and cutting it there cuts the connection the
controller is opening - whose `connect` has already returned, so that attempt
fails outright, there being no relay fallback after a failed TCP handshake. A
timer cannot tell the two states apart, and none is needed: a gateway that
answers with RST fails the connect at once and the loop punches again, while
one that drops the SYN in silence leaves the socket in SYN_SENT, holding the
mapping open while the kernel re-sends, which any SYN of the controller's then
crosses - a second punch has nothing to add. The deadline decides whether
another punch starts; one in flight runs a grace past it, enough for a
crossing begun just before it to complete. The last sleep is cut at the
deadline rather than run out past it, so the window ends on a punch given
that grace and not on a gap of up to the backoff ceiling: the controller's
window opened after ours, on the PunchHoleSent hbbs relayed, so one as long
as ours is still open through our tail.

Only the accept races the punch, never `accept_connection`: that one does not
return until the session it goes on to run has ended, so racing it would tear a
live session down.

Whichever arrives first is the one connection the request produces. `meta`
carries the control permissions hbbs granted for this one controller, so
serving the loser as well would hand them to a second peer - and nothing about
a connection tells the two apart before `create_tcp_connection` has spoken to
it, least of all its address: a carrier NAT shares one between subscribers,
and a NAT that pools its external addresses may dial us from a different one
than hbbs saw the controller through. So the address is not checked, as
`accept_connection` never checked it; the handshake says who arrived, and what
holds the invariant is that there is no second serve. Those
permissions are a ceiling and not a grant either way: `Connection` gates every
message on `authorized`, and latches the login scope of the first request it
accepts, so a peer that reached the hole still arrives with nothing.

The accept loops rather than taking a single connection, so that a transient
accept error does not spend the window the controller still has to arrive in.

libp2p's DCUtR reaches the same place by having both peers dial at one instant
agreed over the relay. Nothing we send reaches the controller directly, so we
cover its dial window rather than name an instant inside it.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019aokqJuhjvB3kijXtAg5Ns

* hbb_common: bump to the webrtc branch rebased on main

Picks up upstream's session-cache eviction by pc identity (#589, adopted without its
unused insert-path helper), the 90-day log retention, and the wlroots output fixes.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019aokqJuhjvB3kijXtAg5Ns

* webrtc: send over SCTP without a congestion window, as KCP does

The same link that streams over KCP crawls over WebRTC. webrtc-sctp runs
RFC 4960's AIMD: a fast retransmit halves cwnd, a T3 drops it to one MTU, and
slow start only rebuilds it while data is queued behind it. Where the loss is
random rather than congestion - a lossy long-haul link - the rate settles at
the Mathis ceiling MSS/(RTT*sqrt(p)) however idle the link is: about 1.3 Mbps
at 70ms RTT and 1% loss, 0.6 Mbps at 5%, while 1080p wants 2-5 Mbps. KCP's
turbo profile (nc=1) has no congestion window at all.

The fork now carries a switch that bypasses the two places gating sends on
cwnd, and hbb_common turns it on for every peer connection unless
`allow-webrtc-congestion-control` is set - the same opt-in KCP has in
`allow-kcp-congestion-control`, for the reason at `get_kcp_cc_enabled`.
Sender-side only; a browser or an older build on the other end interoperates.

Measured over a simulated link (35ms one-way, random loss both ways, 12 KB
frames at 30fps, 300 frames): at 1% loss the window stretches 9.9s of video to
20.7s with a mean latency of 5.5s; without it the stream stays realtime at a
mean of 113ms. At 3%: 47s and 15s against 10.2s and 290ms.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019aokqJuhjvB3kijXtAg5Ns

* webrtc: take the fork's loss recovery for sending without a congestion window

rustdesk-org/webrtc 825a0a48: without a congestion window a chunk is lost
once three chunks sent after its latest transmission are acked, counted in
send order so retransmitted chunks are covered too, and the fast retransmit
sends every lost chunk at once, as KCP nc=1 does; before, a lost
retransmission waited for T3-rtx. Also fixes the delayed SACK timer never
re-arming, the switch applying to established associations, T3-rtx
resending one chunk when the peer's window is full, and bounds new data to
1 MiB / 1024 chunks in flight like KCP's snd_wnd.

Simulated 35ms one-way, random loss both ways, 30 fps, frames later than
200ms out of 1200: 12 KB at 5% loss 996 -> 55 (KCP 61); 40 KB at 2% loss
1183 -> 20 (KCP 39).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019aokqJuhjvB3kijXtAg5Ns

* bump hbb_common: decode TURN userinfo, add the webrtc_echo example

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JXJJGEGdgu26wgCppvUXdZ

* web: show the WebRTC toggle and transport in the web UI

The web client now speaks WebRTC, but the desktop settings page hides
the punch options on web and the remote page opens without the session
tab that carries the transport name. Let the existing "Enable WebRTC P2P
connection" checkbox through on web (the other punch options stay
native-only), and add a Transport row to the quality monitor for WebRTC
sessions only (with "(TURN)" when ICE relayed), on every platform.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JXJJGEGdgu26wgCppvUXdZ

* bump hbb_common: end the ICE forwarder at gathering complete, drop the closes Drop covers

hbb_common now closes the local-candidate channel when gathering
completes, so the controlled side's forwarder in spawn_webrtc_answerer
ends there, and its signaling connection to hbbs with it, instead of
sitting on a socket hbbs closed at 90s idle for the rest of the session.
It also keeps the reassembly buffer across fragmented frames.

Stream closes the WebRTC peer connection on drop (hbb_common b0b624d),
so the close_webrtc() calls in port_forward and io_loop that sat
immediately before a return or the end of scope did nothing Drop was
not about to do, while the comments beside them still said a bare drop
leaked the pc. Remove both.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019aokqJuhjvB3kijXtAg5Ns

* bump hbb_common: quiet the webrtc-rs warnings that describe the race's normal outcome

Cancelling the transport that lost the race, and trickle checking before it
holds a pair, are what the design does on every session that connects - and
webrtc-rs reports both at warn, 90 lines of a 386-line controlled-side log,
beside connections that succeeded. agent_internal and peer_connection drop to
error; agent_gather keeps warn, since an unreachable STUN server is the one
upstream signal that explains a session which never connected.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01M54JAqUK4RynudFou89hod

* port_forward: restore the `?` the close removal left as a match

Dropping the explicit close_webrtc() from the parse-error arm left a match
that only re-spells `?`; master just reworked this function, so the branch
now leaves port_forward.rs untouched.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019aokqJuhjvB3kijXtAg5Ns

* l10n: the two WebRTC keys were missing from Urdu

Every other lang file on the branch carries them; ur.rs was skipped when
they were added.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019aokqJuhjvB3kijXtAg5Ns

* udp: make the punch deadline absolute, so a talking peer cannot defer it

`select!` rebuilds every arm each iteration, so the relative retry sleep was
restarted by each datagram that arrived before it fired. The peer sets that
rate, and an old-build peer's empty datagrams match no arm and loop without
even the recv-error pause, so MAX_TIME went unchecked and the retransmit was
starved with it. `udp_nat_connect` awaits the punch ahead of the KCP timeout
and nothing above it bounds the phase, so the punch held the direct race open
and the relay fallback out of reach for as long as the peer kept sending.

Absolute instants for both clocks. The new test floods empty datagrams for
four times the deadline: the punch now ends at 3s where it ran the full 12s.

Also note at the symmetric-NAT branch that WebRTC not following the legacy
relay decision there is deliberate, so it is not later "fixed" into agreement.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019aokqJuhjvB3kijXtAg5Ns

* bump webrtc fork: MTU-safe bundles, a reordering window, tail loss within the RTT

rustdesk-org/webrtc cc6633bc, three commits on 825a0a48, all on the path
that sends without a congestion window:

Both bundlers counted a DATA chunk by its payload alone; with the header and
padding counted, bundles of small chunks stay within the MTU, and the fragment
payload rounds down to 1160 so a full chunk does too. A chunk is fast
retransmitted at most five times, KCP's IKCP_FASTACK_LIMIT.

A frame's chunks go out within microseconds of each other, so on a path that
jitters the send-order rule resent every chunk that landed behind three of
its siblings: 2.7x the payload on the wire at 10ms of jitter, and on a link
without the room for that, a queue that fed on itself. A reordering window,
RACK's, makes evidence count only from what was sent a quarter of an srtt
after the chunk once the path is seen to reorder, widening on the duplicate
TSNs the receiver reports. 5 Mbps, 1% loss, 20ms jitter: 600 of 600 frames
at a 98ms mean where 290 arrived at 6.2s.

A chunk lost at the tail of a burst has only T3-rtx, which ran from floors
sized for a 200ms delayed ack and restarted only on the tail's predecessor's
ack: 600ms and more. Every DATA chunk now carries the I bit, the floors are
KCP's shape, and a fast retransmission restarts the timer. One 200-byte
message per frame at 5% loss: 9 of 600 later than 200ms, from 42.

Random loss without jitter is unchanged at every rate and frame size.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019aokqJuhjvB3kijXtAg5Ns

* bump webrtc fork: T3-rtx restarts only for the earliest chunk's fast retransmission

rustdesk-org/webrtc 2b8e55bc. Sending without a congestion window, a fast
retransmission of any chunk restarted T3-rtx, so a chunk past the fast
retransmission cap - left to that timer - never reached it while later
chunks kept being resent, which a lossy stream does every couple of frames.
The timer is the earliest in-flight chunk's, and only its resend restarts
it now. Nothing else changes; the benchmark is unchanged.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019aokqJuhjvB3kijXtAg5Ns

* bump webrtc fork: T3-rtx restart on fast retransmission while shutting down too

rustdesk-org/webrtc 48100bf1. The restart for the earliest chunk's fast
retransmission reached only the Established branch of the write loop; the
shutdown states still carry data in flight and recover it the same way, so a
closing association could still resend everything on a loss its fast
retransmit had already recovered. Both branches share one helper now.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019aokqJuhjvB3kijXtAg5Ns

---------

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-09-06 00:21:28 +08:00

775 lines
71 KiB
Rust
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
lazy_static::lazy_static! {
pub static ref T: std::collections::HashMap<&'static str, &'static str> =
[
("Status", "Стан"),
("Your Desktop", "Ваш працоўны стол"),
("desk_tip", "Ваш працоўны стол даступны з гэтым ID і паролем."),
("Password", "Пароль"),
("Ready", "Гатова"),
("Established", "Усталявана"),
("connecting_status", "Ідзе падключэнне да сеткі RustDesk..."),
("Enable service", "Уключыць службу"),
("Start service", "Запусціць службу"),
("Service is running", "Служба запушчана"),
("Service is not running", "Служба не запушчана"),
("not_ready_status", "Не падключана. Праверце падключэнне."),
("Control Remote Desktop", "Новае падключэнне"),
("Transfer file", "Перадаць файлы"),
("Connect", "Падключыцца"),
("Recent sessions", "Апошнія сеансы"),
("Address book", "Адрасная кніга"),
("Confirmation", "Пацвярджэнне"),
("TCP tunneling", "TCP-тунэляванне"),
("Remove", "Выдаліць"),
("Refresh random password", "Абнавіць выпадковы пароль"),
("Set your own password", "Задаць свой пароль"),
("Enable keyboard/mouse", "Выкарыстоўваць клавіятуру/мыш"),
("Enable clipboard", "Выкарыстоўваць буфер абмену"),
("Enable file transfer", "Выкарыстоўваць перадачу файлаў"),
("Enable TCP tunneling", "Выкарыстоўваць тунэляванне TCP"),
("IP Whitelisting", "Спіс дазволеных IP-адрасоў"),
("ID/Relay Server", "ID/Рэтранслятар"),
("Import server config", "Імпартаваць канфігурацыю сервера"),
("Export Server Config", "Экспартаваць канфігурацыю сервера"),
("Import server configuration successfully", "Канфігурацыя сервера паспяхова імпартавана"),
("Export server configuration successfully", "Канфігурацыя сервера паспяхова экспартавана"),
("Invalid server configuration", "Няправільная канфігурацыя сервера"),
("Clipboard is empty", "Буфер абмену пусты"),
("Stop service", "Спыніць службу"),
("Change ID", "Змяніць ID"),
("Your new ID", "Новы ID"),
("length %min% to %max%", "даўжыня %min%...%max%"),
("starts with a letter", "пачынаецца з літары"),
("allowed characters", "дазволеныя сімвалы"),
("id_change_tip", "Дазволена выкарыстоўваць толькі сімвалы a-z, A-Z, 0-9, - (dash) і _ (падкрэсліванне). Першай павінна быць літара a-z, A-Z. Даўжыня ад 6 да 16."),
("Website", "Сайт"),
("About", "Пра праграму"),
("Slogan_tip", "Зроблена з душой у гэтым вар'яцкім свеце!"),
("Privacy Statement", "Заява аб канфідэнцыйнасці"),
("Mute", "Адключыць гук"),
("Build Date", "Дата зборкі"),
("Version", "Версія"),
("Home", "Галоўная"),
("Audio Input", "Аўдыяўваход"),
("Enhancements", "Паляпшэнні"),
("Hardware Codec", "Апаратны кодэк"),
("Adaptive bitrate", "Адаптыўны бітрэйт"),
("ID Server", "Сервер ID"),
("Relay Server", "Рэтранслятар"),
("API Server", "Сервер API"),
("invalid_http", "Адрас павінен пачынацца з http:// або https://"),
("Invalid IP", "Няправільны IP-адрас"),
("Invalid format", "Няправільны фармат"),
("server_not_support", "Пакуль не падтрымліваецца серверам"),
("Not available", "Недаступна"),
("Too frequent", "Занадта часта"),
("Cancel", "Скасаваць"),
("Skip", "Прапусціць"),
("Close", "Закрыць"),
("Retry", "Паўтарыць спробу"),
("OK", "ОК"),
("Password Required", "Патрабуецца пароль"),
("Please enter your password", "Увядзіце пароль"),
("Remember password", "Запомніць пароль"),
("Wrong Password", "Няправільны пароль"),
("Do you want to enter again?", "Паўтарыць уваход?"),
("Connection Error", "Памылка падключэння"),
("Error", "Памылка"),
("Reset by the peer", "Скінута абанентам"),
("Connecting...", "Падключэнне..."),
("Connection in progress. Please wait.", "Ідзе падключэнне. Пачакайце."),
("Please try 1 minute later", "Паспрабуйце праз хвіліну"),
("Login Error", "Памылка ўваходу"),
("Successful", "Паспяхова"),
("Connected, waiting for image...", "Падключана, чаканне відарыса..."),
("Name", "Назва"),
("Type", "Тып"),
("Modified", "Зменена"),
("Size", "Памер"),
("Show Hidden Files", "Паказаць схаваныя файлы"),
("Receive", "Атрымаць"),
("Send", "Адправіць"),
("Refresh File", "Абнавіць файл"),
("Local", "Лакальны"),
("Remote", "Аддалены"),
("Remote Computer", "Аддалены камп'ютар"),
("Local Computer", "Лакальны камп'ютар"),
("Confirm Delete", "Пацвердзіць выдаленне"),
("Delete", "Выдаліць"),
("Properties", "Уласцівасці"),
("Multi Select", "Шматлікі выбар"),
("Select All", "Выбраць усе"),
("Unselect All", "Скасаваць выбар усіх"),
("Empty Directory", "Пусты каталог"),
("Not an empty directory", "Каталог не пусты"),
("Are you sure you want to delete this file?", "Выдаліць гэты файл?"),
("Are you sure you want to delete this empty directory?", "Выдаліць пусты каталог?"),
("Are you sure you want to delete the file of this directory?", "Выдаліць файл з гэтага каталога?"),
("Do this for all conflicts", "Прымяніць да ўсіх канфліктаў"),
("This is irreversible!", "Гэтага нельга адрабіць!"),
("Deleting", "Ідзе выдаленне"),
("files", "файлы"),
("Waiting", "Чаканне"),
("Finished", "Завершана"),
("Speed", "Хуткасць"),
("Custom Image Quality", "Карыстальніцкая якасць відарыса"),
("Privacy mode", "Рэжым канфідэнцыйнасці"),
("Block user input", "Заблакіраваць увод на аддаленай прыладзе"),
("Unblock user input", "Разблакіраваць увод на аддаленай прыладзе"),
("Adjust Window", "Наладзіць акно"),
("Original", "Арыгінал"),
("Shrink", "Сціснуць"),
("Stretch", "Расцягнуць"),
("Scrollbar", "Паласа прагортвання"),
("ScrollAuto", "Аўта-прагортванне"),
("Good image quality", "Добрая якасць відарыса"),
("Balanced", "Баланс паміж якасцю і хуткасцю"),
("Optimize reaction time", "Аптымізацыя хуткасці рэакцыі"),
("Custom", "Карыстальніцкая"),
("Show remote cursor", "Паказваць аддалены курсор"),
("Show quality monitor", "Паказваць манітор якасці"),
("Disable clipboard", "Адключыць буфер абмену"),
("Lock after session end", "Заблакіраваць уліковы запіс пасля сеанса"),
("Insert Ctrl + Alt + Del", "Уставіць Ctrl + Alt + Del"),
("Insert Lock", "Заблакіраваць уліковы запіс"),
("Refresh", "Абнавіць"),
("ID does not exist", "ID не існуе"),
("Failed to connect to rendezvous server", "Немагчыма падключыцца да прамежкавага сервера"),
("Please try later", "Паспрабуйце пазней"),
("Remote desktop is offline", "Аддаленая прылада не ў сетцы"),
("Key mismatch", "Неадпаведнасць ключоў"),
("Timeout", "Час чакання скончыўся"),
("Failed to connect to relay server", "Немагчыма падключыцца да рэтранслятара"),
("Failed to connect via rendezvous server", "Немагчыма падключыцца праз прамежкавы сервер"),
("Failed to connect via relay server", "Немагчыма падключыцца праз рэтранслятар"),
("Failed to make direct connection to remote desktop", "Не ўдалося ўсталяваць прамога падключэння да аддаленай прылады"),
("Set Password", "Задаць пароль"),
("OS Password", "Пароль уваходу ў аперацыйную сістэму"),
("install_tip", "У некаторых выпадках з-за UAC, RustDesk можа працаваць на баку абанента неадпаведным чынам. Каб пазбегнуць магчымых праблем з UAC, націсніце кнопку ніжэй для ўсталявання RustDesk у сістэме."),
("Click to upgrade", "Абнавіць"),
("Configure", "Наладзіць"),
("config_acc", "Каб аддаленна кіраваць сваім працоўным сталом, вам трэба дазволіць RustDesk правы \"доступу\""),
("config_screen", "Для аддаленага доступу да працоўнага стала вам трэба даць RustDesk правы \"здымку экрана\"."),
("Installing ...", "Ідзе ўсталёўванне..."),
("Install", "Усталяваць"),
("Installation", "Усталёўванне"),
("Installation Path", "Шлях усталёўвання"),
("Create start menu shortcuts", "Стварыць ярлыкі ў меню \"Пуск\""),
("Create desktop icon", "Стварыць значок на працоўным стале"),
("agreement_tip", "Пачынаючы ўсталёўванне, вы прымаеце ўмовы ліцэнзійнага пагаднення."),
("Accept and Install", "Прыняць і ўсталяваць"),
("End-user license agreement", "Ліцэнзійнае пагадненне з канчатковым карыстальнікам"),
("Generating ...", "Ідзе генерыраванне..."),
("Your installation is lower version.", "Усталявана ранейшая версія"),
("not_close_tcp_tip", "Не закрываць гэтага акна пры выкарыстанні тунэлю."),
("Listening ...", "Чаканне..."),
("Remote Host", "Аддалены хост"),
("Remote Port", "Аддалены порт"),
("Action", "Дзеянне"),
("Add", "Дадаць"),
("Local Port", "Лакальны порт"),
("Local Address", "Лакальны адрас"),
("Change Local Port", "Змяніць лакальны порт"),
("setup_server_tip", "Для хутчэйшага падключэння наладзьце ўласны сервер."),
("Too short, at least 6 characters.", "Занадта кароткі, мінімум 6 сімвалаў."),
("The confirmation is not identical.", "Пацвярджэнне не супадае."),
("Permissions", "Дазволы"),
("Accept", "Прыняць"),
("Dismiss", "Адхіліць"),
("Disconnect", "Адключыць"),
("Enable file copy and paste", "Дазволіць капіяванне і ўстаўку файлаў"),
("Connected", "Падключана"),
("Direct and encrypted connection", "Прамое і зашыфраванае падключэнне"),
("Relayed and encrypted connection", "Рэтрансляванае і зашыфраванае падключэнне"),
("Direct and unencrypted connection", "Прамое і незашыфраванае падключэнне"),
("Relayed and unencrypted connection", "Рэтрансляванае і незашыфраванае падключэнне"),
("Enter Remote ID", "Увядзіце ID абанента"),
("Enter your password", "Увядзіце пароль"),
("Logging in...", "Уваходжанне..."),
("Enable RDP session sharing", "Уключыць абагульванне сеанса RDP"),
("Auto Login", "Аўтаматычны ўваход ва ўліковы запіс"),
("Enable direct IP access", "Дазволіць прамы доступ па IP-адрасе"),
("Rename", "Перайменаваць"),
("Space", "Месца"),
("Create desktop shortcut", "Стварыць ярлык на працоўным стале"),
("Change Path", "Змяніць шлях"),
("Create Folder", "Стварыць папку"),
("Please enter the folder name", "Увядзіце імя папкі"),
("Fix it", "Выправіць"),
("Warning", "Папярэджанне"),
("Login screen using Wayland is not supported", "Уваход у сістэму з выкарыстаннем Wayland не падтрымліваецца"),
("Reboot required", "Патрабуецца перазагрузка"),
("Unsupported display server", "Сервер адлюстравання не падтрымліваецца"),
("x11 expected", "Чакаецца X11"),
("Port", "Порт"),
("Settings", "Налады"),
("Username", "Імя карыстальніка"),
("Invalid port", "Памылковы порт"),
("Closed manually by the peer", "Закрыта абанентам уручную"),
("Enable remote configuration modification", "Дазволіць аддаленае змяненне канфігурацыі"),
("Run without install", "Запусціць без усталявання"),
("Connect via relay", "Падключыцца праз рэтранслятар"),
("Always connect via relay", "Заўсёды падключацца праз рэтранслятар"),
("whitelist_tip", "Атрымліваць доступ да маёй прылады могуць толькі IP-адрасы з белага спісу."),
("Login", "Увайсці"),
("Verify", "Праверыць"),
("Remember me", "Запомніць"),
("Trust this device", "Давяраць гэтай прыладзе"),
("Verification code", "Праверачны код"),
("verification_tip", "Выяўлена новая прылада, на зарэгістраваны адрас электроннай пошты адпраўлены праверачны код. Увядзіце яго, каб працягнуць уваходжанне ў сістэму."),
("Logout", "Выйсці"),
("Tags", "Цэтлікі"),
("Search ID", "Пошук по ID"),
("whitelist_sep", "Падзяленне коскай, кропкай з коскай, прабелам або новым радком."),
("Add ID", "Дадаць ID"),
("Add Tag", "Дадаць цэтлік"),
("Unselect all tags", "Скасаваць выбар усіх цэтлікаў"),
("Network error", "Памылка сеткі"),
("Username missed", "Прапушчана імя карыстальніка"),
("Password missed", "Прапушчаны пароль"),
("Wrong credentials", "Памылковае імя або пароль"),
("The verification code is incorrect or has expired", "Памылковы або пратэрмінаваны праверачны код"),
("Edit Tag", "Рэдагаваць цэтлік"),
("Forget Password", "Не захоўваць пароль"),
("Favorites", "Абранае"),
("Add to Favorites", "Дадаць у абранае"),
("Remove from Favorites", "Выдаліць з абранага"),
("Empty", "Пуста"),
("Invalid folder name", "Недапушчальная назва папкі"),
("Socks5 Proxy", "Socks5-проксі"),
("Socks5/Http(s) Proxy", "Socks5/Http(s)-проксі"),
("Discovered", "Знойдзена"),
("install_daemon_tip", "Для запуску пры загрузцы трэба ўсталяваць сістэмную службу"),
("Remote ID", "ID абанента"),
("Paste", "Уставіць"),
("Paste here?", "Уставіць сюды?"),
("Are you sure to close the connection?", "Закрыць падключэнне?"),
("Download new version", "Спампаваць новую версію"),
("Touch mode", "Рэжым сэнсарнага экрана"),
("Mouse mode", "Рэжым мышы/сэнсарнай панэлі"),
("One-Finger Tap", "Націсканне адным пальцам"),
("Left Mouse", "Левая кнопка мышы"),
("One-Long Tap", "Доўгае націсканне адным пальцам"),
("Two-Finger Tap", "Націсканне двума пальцамі"),
("Right Mouse", "Правая кнопка мышы"),
("One-Finger Move", "Перамяшчэнне адным пальцам"),
("Double Tap & Move", "Двайное націсканне і перамяшчэнне"),
("Mouse Drag", "Перацягванне мышшу"),
("Three-Finger vertically", "Трыма пальцамі па вертыкалі"),
("Mouse Wheel", "Колца мышы"),
("Two-Finger Move", "Перамяшчэнне двума пальцамі"),
("Canvas Move", "Перамяшчэнне палатна"),
("Pinch to Zoom", "Маштабаванне шчыпком"),
("Canvas Zoom", "Маштабаванне палатна"),
("Reset canvas", "Скінуць маштабаванне палатна"),
("No permission of file transfer", "Няма дазволу на перадачу файлаў"),
("Note", "Нататка"),
("Connection", "Падключэнне"),
("Share screen", "Дэманстрацыя экрана"),
("Chat", "Чат"),
("Total", "Усяго"),
("items", "элементы"),
("Selected", "Выбрана"),
("Screen Capture", "Захоп экрана"),
("Input Control", "Кіраванне ўводам"),
("Audio Capture", "Захоп аўдыя"),
("Do you accept?", "Вы згодныя?"),
("Open System Setting", "Адкрыць налады сістэмы"),
("How to get Android input permission?", "Як атрымаць дазвол на ўвод Android?"),
("android_input_permission_tip1", "Каб аддаленая прылада магла кіраваць вашай Android-прыладай з дапамогай мышы або націсканняў, трэба дазволіць RustDesk выкарыстоўваць службу \"Спецыяльныя магчымасці\"."),
("android_input_permission_tip2", "Зайдзіце на адпаведную старонку сістэмных налад, знайдзіце і перайдзіце ва \"Усталяваныя службы\", уключыце службу \"RustDesk Input\"."),
("android_new_connection_tip", "Новы запыт на кіраванне вашай бягучай прыладай."),
("android_service_will_start_tip", "Уключэнне захопу экрана аўтаматычна запускае службу, дазваляючы іншым прыладам запытаць падключэнне да гэтай прылады."),
("android_stop_service_tip", "Закрыццё службы аўтаматычна закрые ўсе ўстаноўленыя падключэнні."),
("android_version_audio_tip", "Бягучая версія Android не падтрымлівае захопу гуку, абнавіце яе да Android 10 ці вышэй."),
("android_start_service_tip", "Націсніце [Запусціць службу] або дазвольце [Захоп экрана], каб запусціць службу дэманстрацыі экрана."),
("android_permission_may_not_change_tip", "Дазволы для ўстаноўленых падключэнняў не могуць быць зменены, патрабуецца перападключэнне."),
("Account", "Уліковы запіс"),
("Overwrite", "Перазапісаць"),
("This file exists, skip or overwrite this file?", "Файл існуе, прапусціць ці перазапісаць яго?"),
("Quit", "Выйсці"),
("Help", "Дапамога"),
("Failed", "Не ўдалося"),
("Succeeded", "Выканана"),
("Someone turns on privacy mode, exit", "Хтосьці ўключыў рэжым канфідэнцыйнасці, выхад"),
("Unsupported", "Не падтрымліваецца"),
("Peer denied", "Забаронена абанентам"),
("Peer exit", "Абанент выйшаў"),
("Failed to turn off", "Немагчыма выключыць"),
("Turned off", "Выключаны"),
("Language", "Мова"),
("Keep RustDesk background service", "Захаваць фонавую службу RustDesk"),
("Ignore Battery Optimizations", "Ігнараваць аптымізацыю ўжывання батарэі"),
("android_open_battery_optimizations_tip", "Перайдзіце на наступную старонку налад"),
("Start on boot", "Запускаць пры загрузцы"),
("Start the screen sharing service on boot, requires special permissions", "Запускаць службу дэманстрацыі экрана пры загрузцы (патрабуюцца спецыяльныя дазволы)"),
("Connection not allowed", "Падключэнне не дазволена"),
("Legacy mode", "Састарэлы рэжым"),
("Map mode", "Рэжым супастаўлення"),
("Translate mode", "Рэжым перакладу"),
("Use permanent password", "Выкарыстоўваць пастаянны пароль"),
("Use both passwords", "Выкарыстоўваць абодва паролі"),
("Set permanent password", "Задаць пастаянны пароль"),
("Enable remote restart", "Дазволіць аддалены перазапуск"),
("Restart remote device", "Перазапусціць аддаленую прыладу"),
("Are you sure you want to restart", "Вы ўпэўненыя, што хочаце зрабіць перазапуск?"),
("Restarting remote device", "Ідзе перазапуск аддаленай прылады"),
("remote_restarting_tip", "Аддаленая прылада перазапускаецца. Закрыйце гэта паведамленне і праз некаторы час перападключыцеся, выкарыстоўваючы пастаянны пароль."),
("Copied", "Скапіявана"),
("Exit Fullscreen", "Выйсці з поўнаэкраннага рэжыму"),
("Fullscreen", "Поўнаэкранны рэжым"),
("Mobile Actions", "Мабільныя дзеянні"),
("Select Monitor", "Выберыце манітор"),
("Control Actions", "Дзеянні па кіраванні"),
("Display Settings", "Налады адлюстравання"),
("Ratio", "Суадносіны"),
("Image Quality", "Якасць відарыса"),
("Scroll Style", "Стыль прагортвання"),
("Show Toolbar", "Паказаць панэль інструментаў"),
("Hide Toolbar", "Схаваць панэль інструментаў"),
("Direct Connection", "Прамое падключэнне"),
("Relay Connection", "Рэтрансляванае падключэнне"),
("Secure Connection", "Бяспечнае падключэнне"),
("Insecure Connection", "Нябяспечнае падключэнне"),
("Scale original", "Арыгінальны маштаб"),
("Scale adaptive", "Адаптыўны маштаб"),
("General", "Агульныя"),
("Security", "Бяспека"),
("Theme", "Тэма"),
("Dark Theme", "Цёмная тэма"),
("Light Theme", "Светлая тэма"),
("Dark", "Цёмная"),
("Light", "Светлая"),
("Follow System", "Сістэмная"),
("Enable hardware codec", "Уключыць апаратны кодэк"),
("Unlock Security Settings", "Разблакіраваць налады бяспекі"),
("Enable audio", "Уключыць перадачу гуку"),
("Unlock Network Settings", "Разблакіраваць сеткавыя налады"),
("Server", "Сервер"),
("Direct IP Access", "Прамы IP-доступ"),
("Proxy", "Проксі"),
("Apply", "Прымяніць"),
("Disconnect all devices?", "Адключыць усе прылады?"),
("Clear", "Ачысціць"),
("Audio Input Device", "Прылада ўводу гуку"),
("Use IP Whitelisting", "Выкарыстоўваць белы спіс IP"),
("Network", "Сетка"),
("Pin Toolbar", "Закрэпіць панэль інструментаў"),
("Unpin Toolbar", "Адкрэпіць панэль інструментаў"),
("Recording", "Запіс"),
("Directory", "Каталог"),
("Automatically record incoming sessions", "Аўтаматычна запісваць уваходныя сесіі"),
("Automatically record outgoing sessions", "Аўтаматычна запісваць выходныя сесіі"),
("Change", "Змяніць"),
("Start session recording", "Пачаць запіс сесіі"),
("Stop session recording", "Спыніць запіс сесіі"),
("Enable recording session", "Уключыць запіс сесіі"),
("Enable LAN discovery", "Уключыць выяўленне ў лакальнай сетцы"),
("Deny LAN discovery", "Забараніць выяўленне ў лакальнай сетцы"),
("Write a message", "Напісаць паведамленне"),
("Prompt", "Падказка"),
("Please wait for confirmation of UAC...", "Дачакайцеся пацверджання UAC..."),
("elevated_foreground_window_tip", "Бягучае акно аддаленага працоўнага стала патрабуе вышэйшых прывілегій для працы, таму часова немагчыма выкарыстоўваць мыш і клавіятуру. Можна папрасіць абанента згарнуць бягучае акно або націснуць кнопку павышэння правоў у акне кіравання падключэннем. Каб прадухіліць гэту праблему ў будучыні, рэкамендуецца ўсталяваць праграмнае забеспячэнне на аддаленай прыладзе."),
("Disconnected", "Адключана"),
("Other", "Іншае"),
("Confirm before closing multiple tabs", "Пацвердзіць закрыццё некалькіх укладак"),
("Keyboard Settings", "Налады клавіятуры"),
("Full Access", "Поўны доступ"),
("Screen Share", "Дэманстрацыя экрана"),
("ubuntu-21-04-required", "Wayland патрабуе Ubuntu версіі 21.04 або навейшай."),
("wayland-requires-higher-linux-version", "Для Wayland патрабуецца вышэйшая версія дыстрыбутыва Linux. Карыстайцеся працоўным сталом X11 або зменіце сваю АС."),
("xdp-portal-unavailable", "Не ўдалося захапіць экран Wayland. Магчыма, XDG Desktop Portal завяршыўся аварыйна або недаступны. Паспрабуйце перазапусціць яго камандай `systemctl --user restart xdg-desktop-portal`."),
("JumpLink", "Прагляд"),
("Please Select the screen to be shared(Operate on the peer side).", "Выберыце экран для дэманстрацыі (кіруецца на баку абанента)."),
("Show RustDesk", "Паказаць RustDesk"),
("This PC", "Гэты камп’ютар"),
("or", "або"),
("Elevate", "Павысіць"),
("Zoom cursor", "Маштабаванне курсора"),
("Accept sessions via password", "Прымаць сеансы па паролю"),
("Accept sessions via click", "Прымаць сеансы націскам кнопкі"),
("Accept sessions via both", "Прымаць сеансы па паролю і націскам кнопкі"),
("Please wait for the remote side to accept your session request...", "Дачакайцеся, пакуль абанент прымае ваш запыт на сеанс..."),
("One-time Password", "Аднаразовы пароль"),
("Use one-time password", "Выкарыстоўваць аднаразовы пароль"),
("One-time password length", "Даўжыня аднагаразовага пароля"),
("Request access to your device", "Запыт на доступ да вашай прылады"),
("Hide connection management window", "Схаваць акно кіравання падключэннямі"),
("hide_cm_tip", "Дазваляць схаванне акна ў выпадку, калі прымаюцца сесіі па паролю або выкарыстоўваецца пастаянны пароль"),
("wayland_experiment_tip", "Падтрымка Wayland знаходзіцца на эксперыментальнай стадыі, калі вам трэба аўтаматычны доступ, выкарыстоўвайце X11."),
("Right click to select tabs", "Выбар укладак націсканнем правай кнопкі мышы"),
("Skipped", "Прапушчана"),
("Add to address book", "Дадаць у адрасную кнігу"),
("Group", "Група"),
("Search", "Пошук"),
("Closed manually by web console", "Закрыта ўручную праз вэб-кансоль"),
("Local keyboard type", "Тып лакальнай клавіятуры"),
("Select local keyboard type", "Выберыце тып лакальнай клавіятуры"),
("software_render_tip", "Калі ў вас ёсць відэакарта Nvidia і аддаленае акно закрываецца адразу пасля падключэння, магчыма, дапаможа ўсталяванне драйвера Nouveau і выбар выкарыстання праграмнай візуалізацыі. Патрабуецца перазагрузка."),
("Always use software rendering", "Заўсёды выкарыстоўваць праграмную візуалізацыю"),
("config_input", "Каб кіраваць аддаленым працоўным сталом праз клавіятуру, трэба дазволіць RustDesk \"Маніторынг уводу\"."),
("config_microphone", "Каб размаўляць з абанентам, трэба дазволіць RustDesk запіс аўдыя."),
("request_elevation_tip", "Таксама можна запытаць павышэння правоў, калі хто-небудзь знаходзіцца на баку абанента."),
("Wait", "Чакайце"),
("Elevation Error", "Памылка павышэння правоў"),
("Ask the remote user for authentication", "Запытаць праверку сапраўднасці ў абанента"),
("Choose this if the remote account is administrator", "Выберыце гэта, калі абанент з'яўляецца адміністратарам"),
("Transmit the username and password of administrator", "Перадаць імя карыстальніка і пароль адміністратара"),
("still_click_uac_tip", "Дагэтуль патрэбна, каб абанент націснуў \"OK\" ў акне UAC пры запуску RustDesk."),
("Request Elevation", "Запытаць павышэння"),
("wait_accept_uac_tip", "Пачакайце, пакуль абанент пацвердзіць запыт UAC."),
("Elevate successfully", "Правы павышаны"),
("uppercase", "верхні рэгістр"),
("lowercase", "ніжні рэгістр"),
("digit", "лічбы"),
("special character", "спецыяльныя сімвалы"),
("length>=8", "8+ сімвалаў"),
("Weak", "Слабы"),
("Medium", "Сярэдні"),
("Strong", "Моцны"),
("Switch Sides", "Пераключыць бакі"),
("Please confirm if you want to share your desktop?", "Вы сапраўды дазваляеце дэманстрацыю працоўнага стала?"),
("Display", "Адлюстраванне"),
("Default View Style", "Стандартны стыль адлюстравання"),
("Default Scroll Style", "Стандартны стыль прагортвання"),
("Default Image Quality", "Стандартная якасць відарыса"),
("Default Codec", "Стандартны кодэк"),
("Bitrate", "Бітрэйт"),
("FPS", "Колькасць кадраў у секунду"),
("Auto", "Аўта"),
("Other Default Options", "Іншыя стандартныя параметры"),
("Voice call", "Галасавы выклік"),
("Text chat", "Тэкставы чат"),
("Stop voice call", "Спыніць галасавы выклік"),
("relay_hint_tip", "Непасрэднае падключэнне можа быць немагчымым. У гэтым выпадку можна спрабаваць падключыцца праз рэтранслятар.\nАкрамя таго, калі вы хочаце адразу выкарыстоўваць рэтранслятар, можна дадаць да ідэнтыфікатара суфікс \"/r\" або ўключыць \"Заўсёды падключацца праз рэтранслятар\" у наладах абанента."),
("Reconnect", "Перападключыць"),
("Codec", "Кодэк"),
("Resolution", "Раздзяляльнасць"),
("No transfers in progress", "Перадача не ажыццяўляецца"),
("Set one-time password length", "Усталяваць даўжыню аднаразовага пароля"),
("RDP Settings", "Налады RDP"),
("Sort by", "Сартаваць па"),
("New Connection", "Новае падключэнне"),
("Restore", "Аднавіць"),
("Minimize", "Згарнуць"),
("Maximize", "Разгарнуць"),
("Your Device", "Ваша прылада"),
("empty_recent_tip", "Няма апошніх сеансаў!\nЧас запланаваць новы."),
("empty_favorite_tip", "Яшчэ няма абраных абанентаў?\nДавайце знойдзем, каго можна дадаць у абранае."),
("empty_lan_tip", "Абанентаў не знойдзена."),
("empty_address_book_tip", "У адраснай кнізе няма абанентаў."),
("Empty Username", "Пустае імя карыстальніка"),
("Empty Password", "Пусты пароль"),
("Me", "Я"),
("identical_file_tip", "Файл ідэнтычны файлу абанента"),
("show_monitors_tip", "Паказваць маніторы на панэлі інструментаў"),
("View Mode", "Рэжым прагляду"),
("verify_rustdesk_password_tip", "Пацвердзіць пароль RustDesk"),
("No need to elevate", "Павышэнне правоў не патрабуецца"),
("System Sound", "Сістэмны гук"),
("Default", "Стандартна"),
("New RDP", "Новы RDP"),
("Fingerprint", "Адбітак"),
("Copy Fingerprint", "Капіяваць адбітак"),
("no fingerprints", "адбіткі адсутнічаюць"),
("Update", "Абнавіць"),
("resolution_original_tip", "Арыгінальная раздзяляльнасць"),
("resolution_fit_local_tip", "Супадзенне з лакальнай раздзяляльнасцю"),
("resolution_custom_tip", "Карыстацкая раздзяляльнасць"),
("Collapse toolbar", "Згарнуць панэль інструментаў"),
("Accept and Elevate", "Прыняць і павысіць"),
("accept_and_elevate_btn_tooltip", "Дазволіць падключэнне і павысіць правы UAC."),
("clipboard_wait_response_timeout_tip", "Час чакання адказу капіявання буфера абмену скончыўся"),
("Incoming connection", "Уваходнае падключэнне"),
("Outgoing connection", "Выходнае падключэнне"),
("Exit", "Выйсці"),
("Open", "Адкрыць"),
("logout_tip", "Вы сапраўды хочаце выйсці?"),
("Service", "Служба"),
("Start", "Запусціць"),
("Stop", "Спыніць"),
("exceed_max_devices", "Дасягнута максімальная колькасць кантраляваных прылад."),
("Sync with recent sessions", "Сінхранізацыя з апошнімі сеансамі"),
("Sort tags", "Сартаваць цэтлікі"),
("Open connection in new tab", "Адкрыць падключэнне ў новай укладцы"),
("Move tab to new window", "Перамясціць укладку ў новае акно"),
("Can not be empty", "Ня можа быць пустым"),
("Already exists", "Ужо існуе"),
("Change Password", "Змяніць пароль"),
("Refresh Password", "Абнавіць пароль"),
("ID", "ID"),
("Grid View", "Сетка"),
("List View", "Спіс"),
("Select", "Выбар"),
("Toggle Tags", "Пераключыць цэтлікі"),
("pull_ab_failed_tip", "Немагчыма абнавіць адрасную кнігу"),
("push_ab_failed_tip", "Немагчыма сінхранізаваць адрасную кнігу з серверам"),
("synced_peer_readded_tip", "Прылады, якія былі на апошніх сеансах, будуць сінхранізаваны з адраснай кнігай."),
("Change Color", "Змяніць колер"),
("Primary Color", "Асноўны колер"),
("HSV Color", "Колер HSV"),
("Installation Successful!", "Усталяванне выканана!"),
("Installation failed!", "Усталяванне не ўдалося."),
("Reverse mouse wheel", "Адваротнае прагортванне мышшу"),
("{} sessions", "Колькасць сеансаў: {}"),
("scam_title", "Вас могуць ПАДМАНУЦЬ!"),
("scam_text1", "Калі вы размаўляеце па тэлефоне з кімсьці НЕЗНАЁМЫМ і каму вы НЕ ДАВЕРАЕЦЕ, і гэта асоба просіць вас выкарыстаць RustDesk і запусціць яго службу, не працягвайце і неадкладна скончыце размову."),
("scam_text2", "Магчыма, гэта аферыст, які спрабуе скрасці вашы грошы або іншую асабістую інфармацыю."),
("Don't show again", "Не паказваць больш"),
("I Agree", "Згаджаюся"),
("Decline", "Адхіліць"),
("Timeout in minutes", "Час чакання (у хвілінах)"),
("auto_disconnect_option_tip", "Аўтаматычна закрываць уваходныя сеансы пры неактыўнасці карыстальніка"),
("Connection failed due to inactivity", "Збой падключэння з-за неактыўнасці"),
("Check for software update on startup", "Праверка абнаўленняў праграмы пры запуску"),
("upgrade_rustdesk_server_pro_to_{}_tip", "Абнавіце RustDesk Server Pro да версіі {} або навейшай!"),
("pull_group_failed_tip", "Немагчыма абнавіць групу"),
("Filter by intersection", "Фільтраваць па перасячэнні"),
("Remove wallpaper during incoming sessions", "Схаваць шпалеры працоўнага стала ў часе ўваходнага сеанса"),
("Test", "Тэст"),
("display_is_plugged_out_msg", "Дысплэй адключаны, пераключыцеся на першы дысплэй."),
("No displays", "Няма дысплэяў"),
("Open in new window", "Адкрыць у новым акне"),
("Show displays as individual windows", "Паказваць дысплэі ў асобных вокнах"),
("Use all my displays for the remote session", "Выкарыстоўваць усе мае дысплэі для аддаленага сеанса"),
("selinux_tip", "На вашай прыладзе ўключаны SELinux, што можа ствараць перашкоды ў працы RustDesk на баку абанента."),
("Change view", "Рэжым"),
("Big tiles", "Вялікія пліткі"),
("Small tiles", "Маленькія пліткі"),
("List", "Спіс"),
("Virtual display", "Віртуальны дысплэй"),
("Plug out all", "Адключыць усё"),
("True color (4:4:4)", "True color (4:4:4)"),
("Enable blocking user input", "Дазволіць блакіраванне ўводу на прыладзе"),
("id_input_tip", "Можна ўвесці ідэнтыфікатар, прамы IP-адрас або дамен з портам (<дамен>:<порт>).\nКаб атрымаць доступ да прылады на іншым серверы, дадайце адрас сервера (<id>@<адрас_сервера>?key=<ключ_значэнне>), напрыклад:\n9123456234@192.168.16.1:21117?key=5Qbwsde3unUcJBtrx9ZkvUmwFNoExHzpryHuPUdqlWM=.\nКалі трэба атрымаць доступ да прылады на агульнадаступным серверы, увядзіце \"<id>@public\", ключ для публічнага сервера не патрабуецца."),
("privacy_mode_impl_mag_tip", "Рэжым 1"),
("privacy_mode_impl_virtual_display_tip", "Рэжым 2"),
("Enter privacy mode", "Уключыць рэжым канфідэнцыйнасці"),
("Exit privacy mode", "Адключыць рэжым канфідэнцыйнасці"),
("idd_not_support_under_win10_2004_tip", "Драйвер непрамога адлюстравання не падтрымліваецца. Патрабуецца Windows 10 версіі 2004 або навейшая."),
("input_source_1_tip", "Крыніца ўводу 1"),
("input_source_2_tip", "Крыніца ўводу 2"),
("Swap control-command key", "Памяняць месцамі значэнні кнопак Ctrl і Command"),
("swap-left-right-mouse", "Памяняць месцамі значэнні левай і правай кнопак мышы"),
("2FA code", "Код двухфактарнай праверкі сапраўднасці"),
("More", "Яшчэ"),
("enable-2fa-title", "Выкарыстоўваць двухфактарную праверку сапраўднасці"),
("enable-2fa-desc", "Наладзьце праграму праверкі сапраўднасці. Выкарыстоўвайце, напрыклад, Authy, Microsoft або Google Authenticator на тэлефоне ці камп’ютары.\n\nАдскануйце QR-код з дапамогай праграмы праверкі сапраўднасці і ўвядзіце код, які пакажа гэта праграма, каб уключыць двухфактарную праверку сапраўднасці."),
("wrong-2fa-code", "Немагчыма пацвердзіць код. Праверце код і налады мясцовага часу."),
("enter-2fa-title", "Двухфактарная праверка сапраўднасці"),
("Email verification code must be 6 characters.", "Код пацвярджэння па электроннай пошце павінен складацца з 6 сімвалаў."),
("2FA code must be 6 digits.", "Код двухфактарнай праверкі сапраўднасці павінен складацца з 6 лічбаў."),
("Multiple Windows sessions found", "Знойдзена некалькі сеансаў Windows"),
("Please select the session you want to connect to", "Выберыце сеанс, да якога вы хочаце падключыцца"),
("powered_by_me", "Заснавана на RustDesk"),
("outgoing_only_desk_tip", "Гэта спецыялізаваная версія.\nВы можаце падключацца да іншых прылад, але іншыя прылады не могуць падключацца да вашай."),
("preset_password_warning", "Гэта спецыялізаваная версія з прадвызначаным паролем. Любы, хто ведае гэты пароль, можа атрымаць поўны кантроль над вашай прыладай. Калі гэта для вас нечакана, адразу выдаліце гэта праграмнае забеспячэнне."),
("Security Alert", "Папярэджанне аб бяспецы"),
("My address book", "Мая адрасная кніга"),
("Personal", "Асабістая"),
("Owner", "Уладальнік"),
("Set shared password", "Задаць агульны пароль"),
("Exist in", "Існуе ў"),
("Read-only", "Толькі для чытання"),
("Read/Write", "Чытанне і запіс"),
("Full Control", "Поўны доступ"),
("share_warning_tip", "Палі вышэй з'яўляюцца агульнымі і бачнымі іншым."),
("Everyone", "Усе"),
("ab_web_console_tip", "Больш у вэб-кансолі"),
("allow-only-conn-window-open-tip", "Дазволіць падключэнне толькі пры адкрытым акне RustDesk"),
("no_need_privacy_mode_no_physical_displays_tip", "Фізічныя дысплэі адсутнічаюць, няма патрэбы выкарыстоўваць рэжым канфідэнцыйнасці."),
("Follow remote cursor", "Прытрымлівацца аддаленага курсора"),
("Follow remote window focus", "Прытрымлівацца фокуса аддаленага акна"),
("default_proxy_tip", "Стандартныя пратакол і порт: Socks5 і 1080"),
("no_audio_input_device_tip", "Прылада ўваходнага аудыё не знойдзена."),
("Incoming", "Уваходныя"),
("Outgoing", "Выходныя"),
("Clear Wayland screen selection", "Скасаваць выбар экрана Wayland"),
("clear_Wayland_screen_selection_tip", "Пасля скасавання можна зноў выбраць экран для дэманстрацыі."),
("confirm_clear_Wayland_screen_selection_tip", "Скасаваць выбар экрана Wayland?"),
("android_new_voice_call_tip", "Прыйшоў новы запыт на галасавы выклік. Калі вы прымеце яго, гук пераключыцца на галасавае падключэнне."),
("texture_render_tip", "Выкарыстоўваць візуалізацыю тэкстур, каб зрабіць відарысы больш плаўнымі."),
("Use texture rendering", "Візуалізацыя тэкстур"),
("Floating window", "Нефіксаванае акно"),
("floating_window_tip", "Дапамагае падтрымліваць фонавую службу RustDesk"),
("Keep screen on", "Трымаць экран уключаным"),
("Never", "Ніколі"),
("During controlled", "Пры кіраванні"),
("During service is on", "Пры запушчанай службе"),
("Capture screen using DirectX", "Захоп экрана з выкарыстаннем DirectX"),
("Back", "Назад"),
("Apps", "Праграмы"),
("Volume up", "Гучнасць+"),
("Volume down", "Гучнасць-"),
("Power", "Сілкаванне"),
("Telegram bot", "Telegram-бот"),
("enable-bot-tip", "Калі ўключана, можна атрымліваць код двухфактарнай праверкі сапраўднасці ад бота. Таксама ён можа выконваць функцыю апавяшчэння пра падключэнне."),
("enable-bot-desc", "1) Адкрыйце чат з @BotFather.\n2) Адпраўце каманду \"/newbot\". Пасля выканання гэтага кроку вы атрымаеце токен.\n3) Пачніце чат з вашым толькі што створаным ботам. Адпраўце паведамленне, якое пачынаецца з касой рысы (\"/\"), напрыклад, \"/hello\", каб яго актываваць.\n"),
("cancel-2fa-confirm-tip", "Адключыць двухфактарную праверку сапраўднасці?"),
("cancel-bot-confirm-tip", "Адключыць Telegram-бота"),
("About RustDesk", "Пра RustDesk"),
("Send clipboard keystrokes", "Адпраўляць націсканні клавіш у буфер абмену"),
("network_error_tip", "Праверце падключэнне да сеткі, пасля чаго націсніце \"Паўтарыць спробу\"."),
("Unlock with PIN", "Разблакіраваць PIN-кодам"),
("Requires at least {} characters", "Патрабуецца больш сімвалаў (ад {})"),
("Wrong PIN", "Памылковы PIN-код"),
("Set PIN", "Задаць PIN-код"),
("Enable trusted devices", "Уключэнне давераных прылад"),
("Manage trusted devices", "Кіраванне даверанымі прыладамі"),
("Platform", "Платформа"),
("Days remaining", "Засталося дзён"),
("enable-trusted-devices-tip", "Дазволіць давераным прыладам прапускаць праверку сапраўднасці 2FA"),
("Parent directory", "Бацькоўскі каталог"),
("Resume", "Працягнуць"),
("Invalid file name", "Памылковая назва файла"),
("one-way-file-transfer-tip", "На баку абанента ўключана аднабаковая перадача файлаў."),
("Authentication Required", "Патрабуецца праверка сапраўднасці"),
("Authenticate", "Прайсці праверку"),
("web_id_input_tip", "Можна ўвесці ID на тым самым серверы, прамы доступ па IP у вэб-кліенце не падтрымліваецца.\nКалі вы хочаце атрымаць доступ да прылады на іншым серверы, дадайце адрас сервера (<id>@<адрас_сервера>?key=<ключ>), напрыклад,\n9123456234@192.168.16.1:21117?key=5Qbwsde3unUcJBtrx9ZkvUmwFNoExHzpryHuPUdqlWM=.\nКалі вы хочаце атрымаць доступ да прылады на публічным серверы, увядзіце \"<id>@public\", для публічнага сервера ключ не патрэбны."),
("Download", "Спампаваць"),
("Upload folder", "Запампаваць папку"),
("Upload files", "Запампаваць файлы"),
("Clipboard is synchronized", "Буфер абмену сінхранізаваны"),
("Update client clipboard", "Абнавіць буфер абмену кліента"),
("Untagged", "Без цэтліка"),
("new-version-of-{}-tip", "Даступна новая версія {}"),
("Accessible devices", "Даступныя прылады"),
("upgrade_remote_rustdesk_client_to_{}_tip", "Абнавіце кліент RustDesk да версіі {} або навейшай на баку абанента!"),
("d3d_render_tip", "Пры ўключэнні візуалізацыі D3D на некаторых прыладах аддалены экран можа быць чорным."),
("Use D3D rendering", "Выкарыстоўваць візуалізацыю D3D"),
("Printer", "Прынтар"),
("printer-os-requirement-tip", "Для работы функцыі выходнай сувязі з прынтарам патрабуецца Windows 10 або навейшай версіі."),
("printer-requires-installed-{}-client-tip", "Каб выкарыстоўваць аддалены друк, {} павінен быць усталяваны на гэтай прыладзе."),
("printer-{}-not-installed-tip", "Прынтар {} не ўсталяваны."),
("printer-{}-ready-tip", "Прынтар {} усталяваны і гатовы да выкарыстання."),
("Install {} Printer", "Усталюйце прынтар {}"),
("Outgoing Print Jobs", "Выходныя заданні друку"),
("Incoming Print Jobs", "Уваходныя заданні друку"),
("Incoming Print Job", "Уваходнае заданне друку"),
("use-the-default-printer-tip", "Выкарыстоўваць прынтар стандартна"),
("use-the-selected-printer-tip", "Выкарыстоўваць выбраны прынтар"),
("auto-print-tip", "Аўтаматычна выконваць друк на выбраным прынтары"),
("print-incoming-job-confirm-tip", "З аддаленай прылады атрымана заданне на друк. Выканаць яго лакальна?"),
("remote-printing-disallowed-tile-tip", "Аддалены друк забаронены"),
("remote-printing-disallowed-text-tip", "Налады дазволаў на баку абанента забараняюць аддалены друк."),
("save-settings-tip", "Захаваць налады"),
("dont-show-again-tip", "Больш не паказваць"),
("Take screenshot", "Зрабіць здымак экрана"),
("Taking screenshot", "Робіцца здымак экрана"),
("screenshot-merged-screen-not-supported-tip", "Аб’яднанне здымкаў экранаў з некалькіх дысплэяў у дадзены момант не падтрымліваецца. Пераключыцеся на адзін з дысплэяў і паўтарыце дзеянне."),
("screenshot-action-tip", "Выберыце, што рабіць з атрыманым здымкам экрана."),
("Save as", "Захаваць у файл"),
("Export", "Экспартаваць"),
("Export Logs", "Экспартаваць журналы"),
("Import Folder", "Імпартаваць папку"),
("Copy to clipboard", "Скапіяваць у буфер абмену"),
("Enable remote printer", "Выкарыстоўваць аддалены прынтар"),
("Downloading {}", "Ідзе спампоўванне {}"),
("{} Update", "Абнавіць {}"),
("{}-to-update-tip", "{} закрыецца і ўсталюе новую версію."),
("download-new-version-failed-tip", "Памылка спампоўвання. Можна паўтарыць спробу або націснуць кнопку \"Спампаваць\", каб спампаваць праграму з афіцыйнага сайта і абнавіць уручную."),
("Auto update", "Аўтаматычнае абнаўленне"),
("update-failed-check-msi-tip", "Немагчыма вызначыць метад усталявання. Націсніце кнопку \"Спампаваць\", каб спампаваць праграму з афіцыйнага сайта і абнавіце яго ўручную."),
("websocket_tip", "WebSocket падтрымлівае толькі падключэнні да рэтранслятара."),
("Use WebSocket", "Выкарыстоўваць WebSocket"),
("Trackpad speed", "Хуткасць трэкпада"),
("Default trackpad speed", "Стандартная хуткасць трэкпада"),
("Numeric one-time password", "Лічбавы аднаразовы пароль"),
("Enable IPv6 P2P connection", "Выкарыстоўваць падключэнне IPv6 P2P"),
("Enable UDP hole punching", "Выкарыстоўваць UDP hole punching"),
("View camera", "Рэжым камеры"),
("Enable camera", "Уключыць камеру"),
("No cameras", "Камера адсутнічае"),
("view_camera_unsupported_tip", "Аддаленая прылада не падтрымлівае рэжыму камеры."),
("Terminal", "Тэрмінал"),
("Enable terminal", "Уключыць тэрмінал"),
("New tab", "Новая ўкладка"),
("Keep terminal sessions on disconnect", "Захоўваць сеансы тэрмінала пры адключэнні"),
("Terminal (Run as administrator)", "Тэрмінал (адміністратар)"),
("terminal-admin-login-tip", "Увядзіце імя карыстальніка і пароль адміністратара абанента."),
("Failed to get user token.", "Не ўдалося атрымаць токен карыстальніка."),
("Incorrect username or password.", "Памылковае імя карыстальніка або пароль."),
("The user is not an administrator.", "Карыстальнік не з’яўляецца адміністратарам."),
("Failed to check if the user is an administrator.", "Немагчыма праверыць, ці з’яўляецца карыстальнік адміністратарам."),
("Supported only in the installed version.", "Падтрымліваецца толькі ва ўсталёвачнай версіі."),
("elevation_username_tip", "Увядзіце карыстальніка або дамен\\карыстальніка"),
("Preparing for installation ...", "Ідзе падрыхтоўка да ўсталявання..."),
("Show my cursor", "Паказваць мой курсор"),
("Scale custom", "Карыстальніцкае маштабаванне"),
("Custom scale slider", "Карыстальніцкі паўзунок маштабавання"),
("Decrease", "Паменшыць"),
("Increase", "Павялічыць"),
("Show virtual mouse", "Паказаць віртуальную мыш"),
("Virtual mouse size", "Памер віртуальнай мышы"),
("Small", "Маленькі"),
("Large", "Вялікі"),
("Show virtual joystick", "Паказваць віртуальны джойстык"),
("Edit note", "Змяніць нататку"),
("Alias", "Псеўданім"),
("ScrollEdge", "Прагортваць з краю"),
("Allow insecure TLS fallback", "Дазволіць небяспечныя TLS"),
("allow-insecure-tls-fallback-tip", "Стандартна RustDesk правярае сертыфікат сервера на наяўнасць пратаколаў, якія выкарыстоўваюць TLS.\nКалі гэта функцыя ўключана, RustDesk прапусціць дадзены этап і працягне працу ў выпадку няўдалай праверкі."),
("Disable UDP", "Выключыць UDP"),
("disable-udp-tip", "Вызначае, ці варта выкарыстоўваць толькі TCP.\nКалі ўключана, RustDesk не будзе выкарыстоўваць UDP 21116, замест чаго будзе выкарыстоўвацца TCP 21116."),
("server-oss-not-support-tip", "ЗАЎВАГА! у OSS-серверы RustDesk гэта функцыя адсутнічае."),
("input note here", "увядзіце нататку"),
("note-at-conn-end-tip", "Запытваць нататку ў канцы сеанса"),
("Show terminal extra keys", "Паказваць дадатковыя кнопкі тэрмінала"),
("Relative mouse mode", "Рэжым адноснага перамяшчэння мышы"),
("rel-mouse-not-supported-peer-tip", "Рэжым адноснага перамяшчэння мышы не падтрымліваецца падключаным абанентам."),
("rel-mouse-not-ready-tip", "Рэжым адноснага перамяшчэння мышы яшчэ не гатовы. Паспрабуйце зноў."),
("rel-mouse-lock-failed-tip", "Немагчыма заблакіраваць курсор. Рэжым адноснага перамяшчэння мышы адключаны."),
("rel-mouse-exit-{}-tip", "Націсніце {}, каб выйсці."),
("rel-mouse-permission-lost-tip", "Дазвол на выкарыстанне клавіятуры скасаваны. Рэжым адноснага перамяшчэння мышы адключаны."),
("Changelog", "Журнал змяненняў"),
("keep-awake-during-outgoing-sessions-label", "Не адключаць экрана ў часе выходных сеансаў"),
("keep-awake-during-incoming-sessions-label", "Не адключаць экрана ў часе ўваходных сеансаў"),
("Continue with {}", "Працягнуць з {}"),
("Display Name", "Імя для адлюстравання"),
("password-hidden-tip", "Зададзены пастаянны пароль (скрыты)."),
("preset-password-in-use-tip", "Пададзены пароль цяпер выкарыстоўваецца"),
("Enable privacy mode", "Уключыць рэжым канфідэнцыйнасці"),
("allow-remote-toolbar-docking-any-edge", "Дазволіць замацоўванне аддаленай панэлі інструментаў да любога краю акна"),
("API Token", "Токен API"),
("Deploy", "Разгарнуць"),
("Custom ID (optional)", "Карыстальніцкі ID (неабавязкова)"),
("server_requires_deployment_tip", "Сервер патрабуе яўнага разгортвання гэтай прылады. Разгарнуць зараз?"),
("The server does not require explicit deployment.", "Сервер не патрабуе яўнага разгортвання."),
("Unknown response.", "Невядомы адказ."),
("wayland-keyboard-input-disabled-tip", "Дазволіць увод з клавіятуры?"),
("wayland-keyboard-input-consent-tip", "Тое, што вы набіраеце на гэтым аддаленым кампутары (у тым ліку паролі), могуць прачытаць іншыя праграмы на ім."),
("wayland-keyboard-input-applies-to-tip", "Гэты выбар прымяняецца да:"),
("wayland-soft-keyboard-input-label", "Увод з экраннай клавіятуры"),
("wayland-keyboard-input-reset-choice-tip", "Скінуць выбар уводу з клавіятуры"),
("remember-wayland-keyboard-choice-tip", "Не пытацца зноў для гэтага аддаленага кампутара"),
("Why this happens", "Чаму гэта адбываецца"),
("Switch display", "Пераключыць дысплэй"),
("Show monitor switch button on the main toolbar", "Паказваць кнопку пераключэння манітора на галоўнай панэлі інструментаў"),
("Show on the minimized toolbar", "Паказваць на згорнутай панэлі інструментаў"),
("All monitors", "Усе манітори"),
("#{} monitor", "Манітор {}"),
("conn-e2ee-unavailable-tip", "Не ўдалося праверыць скразное шыфраванне.\nАддаленая прылада, магчыма, яшчэ наладжваецца. Паспрабуйце пазней.\nКалі гэта будзе паўтарацца, сервер можа быць ненадзейным.\nУсё роўна працягнуць?"),
("ID whitelisting", "Спіс дазволеных ID"),
("Use ID whitelisting", "Выкарыстоўваць белы спіс ID"),
("id_whitelist_tip", "Атрымліваць доступ да маёй прылады могуць толькі ID з белага спісу."),
("id_whitelist_wildcard_tip", "Падтрымліваюцца падстаноўныя знакі: '*' адпавядае любой колькасці сімвалаў, '?' — роўна аднаму сімвалу"),
("Invalid ID", "Няправільны ID"),
("Your ID is blocked by the peer", "Ваш ID заблакаваны аддаленай прыладай"),
("Your ip is blocked by the peer", "Ваш IP-адрас заблакаваны аддаленай прыладай"),
("id_whitelist_caveat_tip", "ID паведамляецца кліентам, які падключаецца. Белы спіс памяншае паверхню атакі і не замяняе пароль або 2FA"),
("whitelist_cidr_tip", "Падтрымліваецца натацыя CIDR, напрыклад: 192.168.1.0/24"),
("Continue", "Працягнуць"),
("Browser didn't open? Use the url below to sign in.", "Браўзер не адкрыўся? Скарыстайцеся спасылкай ніжэй, каб увайсці."),
("Lock canvas", "Заблакіраваць палатно"),
("Sync clipboard between sessions", "Сінхранізаваць буфер абмену паміж сеансамі"),
("sync-clipboard-between-sessions-tip", "Тэкст або відарысы, скапіяваныя ў адным аддаленым сеансе, таксама адпраўляюцца ў буфер абмену іншых вашых падключаных сеансаў."),
("terminal-clipboard-write-tip", ""),
("Allow terminal apps to copy to clipboard", ""),
("Enable", "Уключыць"),
("Reuse one connection for port forwarding", "Выкарыстоўваць адно злучэнне для перанакіравання партоў"),
("port-forward-mux-tip", "Перадаваць усе злучэнні аднаго перанакіравання партоў праз адно злучэнне з аддаленай прыладай замест паўторнага падлучэння і ўваходу для кожнага з іх."),
("Enable WebRTC P2P connection", "Выкарыстоўваць падключэнне WebRTC P2P"),
("Enable TCP hole punching", "Выкарыстоўваць TCP hole punching"),
].iter().cloned().collect();
}