tailcat: add application-layer UDP support - #25
Open
sksingh2005 wants to merge 1 commit into
Open
Conversation
Add client and server UDP APIs, filtering, NAT64 forwarding, tests, and documentation. Signed-off-by: Shashank Singh <shashanksgh3@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Related Issue: #23
Summary
Adds generic application-layer UDP support to Tailcat using connected packet connections.
Applications can now exchange UDP datagrams with a server or forward them through a Tailcat exit node while reusing the existing WireGuard, direct-path discovery, and DERP fallback data plane.
Fix
Introduces client-side
DialUDPPortandDialUDPAPIs and server-sideOnUDPandOnUDPForwardhandlers. UDP flows preserve datagram boundaries and expose their source and destination endpoints throughConnPacketConn.The server packet filter now supports UDP served-port restrictions and UDP exit-node traffic. IPv4 forwarding uses the existing NAT64 mapping, and
ProxyPacketConnsprovides datagram-safe bidirectional forwarding. The API documentation also defines the 1232-byte safe UDP payload limit for Tailcat’s IPv6 tunnel MTU.Test
Added integration tests using the existing local DERP and STUN environment.
Coverage includes datagram echoing, endpoint preservation, two simultaneous clients with independent source ports, served-port filtering, maximum safe payload delivery, and IPv4 UDP forwarding through the server.
The full Go test suite, race-enabled UDP tests,
go vet, native and WASM builds, and headless-browser tests pass.