mirror of
https://github.com/rustdesk/rustdesk.git
synced 2026-09-06 08:01:03 +03:00
The single punch leaves before hbbs has told the controller where to dial, so it is never in flight at the same time as the controller's SYN: it opens our NAT, meets nothing, and a gateway that answers it with RST takes the mapping down with it, leaving the listener waiting on a hole that no longer exists. Punch again while the controller may still be dialing, and race those punches against the accept. That is two ways in where there was one: the mapping is rebuilt if a RST took it, and once the controller sits in SYN_SENT one of the punches meets its SYN and completes as a simultaneous open - which a punch sent before the controller had been told anything never could. The crossing reaches the punch rather than the listener because the two sockets share the address but only the punch matches the four-tuple, which the tests now pin down. There is no instant to aim at, and no window either. `Client::connect` sizes the controller's dial only after our PunchHoleSent, from its own rendezvous time and the direct failures it has recorded for us: CONNECT_TIMEOUT between two known-asymmetric NATs that never failed, punch_time_used times three or six otherwise, floored at a second - so a peer that failed once dials for a second or two from then on, and none of that reaches this side. The repeats therefore cover our own ceiling instead, CONNECT_TIMEOUT, which is exactly as long as the accept has always been willing to take a connection through the hole, and back off across it: dense at the start, where every window begins and the short ones end, sparse afterwards, which is `punch_udp`'s shape for the same reason. A window past that ceiling was lost before this change too, and mostly to the controller's own kernel - Windows gives a SYN up at 21s, Linux's next re-send after 15s is at 31s; a window short of it costs a few SYNs to a port already closed. No punch is cut on a per-attempt timeout; one in flight is bounded only by the shared deadline plus PUNCH_GRACE. A punch is cancel-safe only while it is still in SYN_SENT; once the controller's SYN has crossed it the socket is half way through a handshake, and cutting it there cuts the connection the controller is opening - whose `connect` has already returned, so that attempt fails outright, there being no relay fallback after a failed TCP handshake. A timer cannot tell the two states apart, and none is needed: a gateway that answers with RST fails the connect at once and the loop punches again, while one that drops the SYN in silence leaves the socket in SYN_SENT, holding the mapping open while the kernel re-sends, which any SYN of the controller's then crosses - a second punch has nothing to add. The deadline decides whether another punch starts; one in flight runs a grace past it, enough for a crossing begun just before it to complete. The last sleep is cut at the deadline rather than run out past it, so the window ends on a punch given that grace and not on a gap of up to the backoff ceiling: the controller's window opened after ours, on the PunchHoleSent hbbs relayed, so one as long as ours is still open through our tail. Only the accept races the punch, never `accept_connection`: that one does not return until the session it goes on to run has ended, so racing it would tear a live session down. Whichever arrives first is the one connection the request produces. `meta` carries the control permissions hbbs granted for this one controller, so serving the loser as well would hand them to a second peer - and nothing about a connection tells the two apart before `create_tcp_connection` has spoken to it, least of all its address: a carrier NAT shares one between subscribers, and a NAT that pools its external addresses may dial us from a different one than hbbs saw the controller through. So the address is not checked, as `accept_connection` never checked it; the handshake says who arrived, and what holds the invariant is that there is no second serve. Those permissions are a ceiling and not a grant either way: `Connection` gates every message on `authorized`, and latches the login scope of the first request it accepts, so a peer that reached the hole still arrives with nothing. The accept loops rather than taking a single connection, so that a transient accept error does not spend the window the controller still has to arrive in. libp2p's DCUtR reaches the same place by having both peers dial at one instant agreed over the relay. Nothing we send reaches the controller directly, so we cover its dial window rather than name an instant inside it. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019aokqJuhjvB3kijXtAg5Ns
265 lines
9.2 KiB
TOML
265 lines
9.2 KiB
TOML
[package]
|
|
name = "rustdesk"
|
|
version = "1.5.0"
|
|
authors = ["rustdesk <info@rustdesk.com>"]
|
|
edition = "2021"
|
|
build= "build.rs"
|
|
description = "RustDesk Remote Desktop"
|
|
default-run = "rustdesk"
|
|
rust-version = "1.75"
|
|
|
|
[lib]
|
|
name = "librustdesk"
|
|
crate-type = ["cdylib", "staticlib", "rlib"]
|
|
|
|
[[bin]]
|
|
name = "naming"
|
|
path = "src/naming.rs"
|
|
|
|
[[bin]]
|
|
name = "service"
|
|
path = "src/service.rs"
|
|
|
|
[features]
|
|
inline = []
|
|
use_samplerate = ["samplerate"]
|
|
use_rubato = ["rubato"]
|
|
use_dasp = ["dasp"]
|
|
flutter = ["flutter_rust_bridge"]
|
|
default = ["use_dasp"]
|
|
hwcodec = ["scrap/hwcodec"]
|
|
vram = ["scrap/vram"]
|
|
mediacodec = ["scrap/mediacodec"]
|
|
drm = ["scrap/drm"]
|
|
# The display wake, as its OWN compile gate on top of `drm`. Everything else in the drm backend
|
|
# READS (it captures a scanout); the wake WRITES, injecting one synthetic pointer event from the
|
|
# root service so a compositor that idle-disabled its outputs re-enables them. That is a different
|
|
# kind of operation and deserves a switch that can remove it from the binary entirely, without
|
|
# giving up DRM capture: `--features drm` builds the capture path with no wake code compiled in.
|
|
drm-wake = ["drm"]
|
|
linux-pkg-config = ["magnum-opus/linux-pkg-config", "scrap/linux-pkg-config"]
|
|
unix-file-copy-paste = [
|
|
"dep:x11-clipboard",
|
|
"dep:x11rb",
|
|
"dep:percent-encoding",
|
|
"dep:once_cell",
|
|
"clipboard/unix-file-copy-paste",
|
|
]
|
|
screencapturekit = ["cpal/screencapturekit"]
|
|
|
|
# See more keys and their definitions at https://doc.rust-lang.org/cargo/reference/manifest.html
|
|
|
|
[dependencies]
|
|
async-trait = "0.1"
|
|
scrap = { path = "libs/scrap", features = ["wayland"] }
|
|
hbb_common = { path = "libs/hbb_common", features = ["webrtc"] }
|
|
serde_derive = "1.0"
|
|
serde = "1.0"
|
|
serde_json = "1.0"
|
|
serde_repr = "0.1"
|
|
cfg-if = "1.0"
|
|
lazy_static = "1.4"
|
|
sha2 = "0.10"
|
|
repng = "0.2"
|
|
parity-tokio-ipc = { git = "https://github.com/rustdesk-org/parity-tokio-ipc" }
|
|
magnum-opus = { git = "https://github.com/rustdesk-org/magnum-opus" }
|
|
dasp = { version = "0.11", features = ["signal", "interpolate-linear", "interpolate"], optional = true }
|
|
rubato = { version = "0.12", optional = true }
|
|
samplerate = { version = "0.2", optional = true }
|
|
uuid = { version = "1.3", features = ["v4"] }
|
|
num_cpus = "1.15"
|
|
bytes = { version = "1.4", features = ["serde"] }
|
|
default-net = "0.14"
|
|
wol-rs = "1.0"
|
|
flutter_rust_bridge = { version = "=1.80", features = ["uuid"], optional = true}
|
|
errno = "0.3"
|
|
rdev = { git = "https://github.com/rustdesk-org/rdev" }
|
|
url = { version = "2.3", features = ["serde"] }
|
|
crossbeam-queue = "0.3"
|
|
hex = "0.4"
|
|
chrono = "0.4"
|
|
cidr-utils = "0.5"
|
|
fon = "0.6"
|
|
shutdown_hooks = "0.1"
|
|
totp-rs = { version = "5.4", default-features = false, features = ["gen_secret", "otpauth"] }
|
|
stunclient = "0.4"
|
|
kcp-sys= { git = "https://github.com/rustdesk-org/kcp-sys", branch = "rustdesk-patches" }
|
|
reqwest = { version = "0.12", features = ["blocking", "socks", "json", "native-tls", "rustls-tls", "rustls-tls-native-roots", "gzip", "zstd"], default-features=false }
|
|
|
|
[target.'cfg(not(target_os = "linux"))'.dependencies]
|
|
# https://github.com/rustdesk/rustdesk/discussions/10197, not use cpal on linux
|
|
cpal = { git = "https://github.com/rustdesk-org/cpal", branch = "osx-screencapturekit" }
|
|
ringbuf = "0.3"
|
|
|
|
[target.'cfg(not(any(target_os = "android", target_os = "ios")))'.dependencies]
|
|
mac_address = "1.1"
|
|
sciter-rs = { git = "https://github.com/rustdesk-org/rust-sciter", branch = "dyn" }
|
|
sys-locale = "0.3"
|
|
enigo = { path = "libs/enigo", features = [ "with_serde" ] }
|
|
clipboard = { path = "libs/clipboard" }
|
|
ctrlc = "3.2"
|
|
# arboard = { version = "3.4", features = ["wayland-data-control"] }
|
|
arboard = { git = "https://github.com/rustdesk-org/arboard", features = ["wayland-data-control"] }
|
|
clipboard-master = { git = "https://github.com/rustdesk-org/clipboard-master" }
|
|
portable-pty = { git = "https://github.com/rustdesk-org/wezterm", branch = "rustdesk/pty_based_0.8.1", package = "portable-pty" }
|
|
|
|
system_shutdown = "4.0"
|
|
qrcode-generator = "4.1"
|
|
|
|
[target.'cfg(target_os = "windows")'.dependencies]
|
|
winapi = { version = "0.3", features = [
|
|
"winuser",
|
|
"wincrypt",
|
|
"shellscalingapi",
|
|
"pdh",
|
|
"synchapi",
|
|
"memoryapi",
|
|
"shellapi",
|
|
"devguid",
|
|
"setupapi",
|
|
"cguid",
|
|
"cfgmgr32",
|
|
"ioapiset",
|
|
"winspool",
|
|
] }
|
|
windows = { version = "0.61", features = [
|
|
"Win32",
|
|
"Win32_Foundation",
|
|
"Win32_Security",
|
|
"Win32_Security_Authorization",
|
|
"Win32_Storage_FileSystem",
|
|
"Win32_System",
|
|
"Win32_System_Com",
|
|
"Win32_System_Diagnostics",
|
|
"Win32_System_Diagnostics_ToolHelp",
|
|
"Win32_System_Environment",
|
|
"Win32_System_IO",
|
|
"Win32_System_Memory",
|
|
"Win32_System_Pipes",
|
|
"Win32_System_Registry",
|
|
"Win32_System_SystemInformation",
|
|
"Win32_System_Threading",
|
|
"Win32_UI_Shell",
|
|
"Win32_UI_WindowsAndMessaging",
|
|
] }
|
|
winreg = "0.11"
|
|
windows-service = "0.6"
|
|
virtual_display = { path = "libs/virtual_display" }
|
|
remote_printer = { path = "libs/remote_printer" }
|
|
impersonate_system = { git = "https://github.com/rustdesk-org/impersonate-system" }
|
|
shared_memory = "0.12"
|
|
tauri-winrt-notification = "0.1"
|
|
|
|
[target.'cfg(target_os = "macos")'.dependencies]
|
|
objc = "0.2"
|
|
cocoa = "0.24"
|
|
dispatch = "0.2"
|
|
core-foundation = "0.9"
|
|
core-graphics = "0.22"
|
|
include_dir = "0.7"
|
|
fruitbasket = "0.10"
|
|
objc_id = "0.1"
|
|
# If we use piet "0.7" here, we must also update core-graphics to "0.24".
|
|
piet = "0.6"
|
|
piet-coregraphics = "0.6"
|
|
foreign-types = "0.3"
|
|
|
|
[target.'cfg(any(target_os = "macos", target_os = "linux", target_os = "windows"))'.dependencies]
|
|
tray-icon = { git = "https://github.com/tauri-apps/tray-icon", version = "0.21.3" }
|
|
tao = { git = "https://github.com/rustdesk-org/tao", branch = "dev" }
|
|
image = "0.24"
|
|
|
|
[target.'cfg(any(target_os = "macos", target_os = "linux"))'.dependencies]
|
|
keepawake = { git = "https://github.com/rustdesk-org/keepawake-rs" }
|
|
|
|
[target.'cfg(any(target_os = "windows", target_os = "linux"))'.dependencies]
|
|
wallpaper = { git = "https://github.com/rustdesk-org/wallpaper.rs" }
|
|
tiny-skia = "0.11"
|
|
softbuffer = "0.4"
|
|
fontdb = "0.23"
|
|
bytemuck = "1.23"
|
|
ttf-parser = "0.25"
|
|
|
|
[target.'cfg(target_os = "linux")'.dependencies]
|
|
libxdo-sys = "0.11"
|
|
psimple = { package = "libpulse-simple-binding", version = "2.27" }
|
|
pulse = { package = "libpulse-binding", version = "2.27" }
|
|
rust-pulsectl = { git = "https://github.com/rustdesk-org/pulsectl" }
|
|
async-process = "1.7"
|
|
evdev = { git="https://github.com/rustdesk-org/evdev" }
|
|
dbus = "0.9"
|
|
dbus-crossroads = "0.5"
|
|
x11-clipboard = {git="https://github.com/clslaid/x11-clipboard", branch = "feat/store-batch", optional = true}
|
|
x11rb = {version = "0.12", features = ["all-extensions"], optional = true}
|
|
percent-encoding = {version = "2.3", optional = true}
|
|
once_cell = {version = "1.18", optional = true}
|
|
nix = { version = "0.29", features = ["term", "process"]}
|
|
gtk = "0.18"
|
|
termios = "0.3"
|
|
terminfo = "0.8"
|
|
winit = "0.30"
|
|
|
|
[target.'cfg(any(target_os = "linux", target_os = "android"))'.dependencies]
|
|
openssl = { version = "0.10", features = ["vendored"] }
|
|
|
|
[target.'cfg(target_os = "android")'.dependencies]
|
|
android_logger = "0.13"
|
|
jni = "0.21"
|
|
android-wakelock = { git = "https://github.com/rustdesk-org/android-wakelock" }
|
|
|
|
[workspace]
|
|
members = ["libs/scrap", "libs/hbb_common", "libs/enigo", "libs/clipboard", "libs/virtual_display", "libs/virtual_display/dylib", "libs/portable", "libs/remote_printer"]
|
|
exclude = ["vdi/host"]
|
|
|
|
# Patch libxdo-sys to use a stub implementation that doesn't require libxdo
|
|
# This allows building and running on systems without libxdo installed (e.g., Wayland-only)
|
|
[patch.crates-io]
|
|
libxdo-sys = { path = "libs/libxdo-sys-stub" }
|
|
# One branch off upstream v0.13.0, the tag whose crate versions match this stack.
|
|
# webrtc-util: reads the Windows adapter list's IPv6 addresses as host-order u16 groups, so every
|
|
# one comes out byte-swapped, fails to bind, and ICE gathers no IPv6 host candidate on Windows.
|
|
# webrtc-sctp: RFC 4960's 1s RTO floor makes a single loss cost 1-3s on a link whose RTT is 24-64ms,
|
|
# and fast retransmit cannot cover a request/response exchange; INITIAL_MTU 1228 also fragments on
|
|
# IPv6. The fork commit carries the arithmetic.
|
|
# Pinned by rev, not branch: a fork branch can be rewritten out from under the lockfile.
|
|
webrtc-util = { git = "https://github.com/rustdesk-org/webrtc", rev = "0a84ba37fbca940b82f230fb469d1b3a3172abf6" }
|
|
webrtc-sctp = { git = "https://github.com/rustdesk-org/webrtc", rev = "0a84ba37fbca940b82f230fb469d1b3a3172abf6" }
|
|
|
|
[package.metadata.winres]
|
|
LegalCopyright = "Copyright © 2026 Purslane Tech Pte. Ltd. All rights reserved."
|
|
ProductName = "RustDesk"
|
|
FileDescription = "RustDesk Remote Desktop"
|
|
OriginalFilename = "rustdesk.exe"
|
|
|
|
[target.'cfg(target_os="windows")'.build-dependencies]
|
|
winres = "0.1"
|
|
winapi = { version = "0.3", features = [ "winnt", "pdh", "synchapi" ] }
|
|
|
|
[build-dependencies]
|
|
cc = "1.0"
|
|
hbb_common = { path = "libs/hbb_common" }
|
|
os-version = "0.2"
|
|
|
|
[dev-dependencies]
|
|
hound = "3.5"
|
|
docopt = "1.1"
|
|
tokio = { version = "1.44", features = ["test-util"] }
|
|
|
|
[package.metadata.bundle]
|
|
name = "RustDesk"
|
|
identifier = "com.carriez.rustdesk"
|
|
icon = ["res/32x32.png", "res/128x128.png", "res/128x128@2x.png"]
|
|
osx_minimum_system_version = "10.14"
|
|
|
|
#https://github.com/johnthagen/min-sized-rust
|
|
[profile.release]
|
|
lto = true
|
|
codegen-units = 1
|
|
panic = 'abort'
|
|
strip = true
|
|
#opt-level = 'z' # only have smaller size after strip
|
|
rpath = true
|
|
|
|
[profile.dev]
|
|
debug = 1
|