# Data models ## ConnectionKey ```rust pub struct ConnectionKey { pub version: u8, // must be 1 pub target: String, // listener address pub ca_cert_pem: String, pub server_cert_pem: String, pub server_key_pem: String, pub client_cert_pem: String, pub client_key_pem: String, pub auth_token: String, } ``` Encoded as: `rtun1.` + base64url(JSON) — no padding. ## Config ```rust pub struct Config { pub listen_address: String, pub listen_port: u16, pub socks_address: String, pub socks_port: u16, pub ca_cert_path: String, pub server_cert_path: String, pub server_key_path: String, pub client_cert_path: String, pub client_key_path: String, pub auth_token_path: String, } ``` ## Frame ```rust pub struct Frame { pub frame_type: u8, // 0x01 CONNECT, 0x02 CONNECT_REPLY, 0x03 DATA, 0x04 CLOSE, 0x05 ERROR pub stream_id: u64, // odd for client-initiated pub flags: u8, // reserved (0x00) pub payload: Bytes, } ``` Wire format: 1 byte type + 8 bytes stream_id (big-endian) + 4 bytes len (big-endian) + 1 byte flags + len bytes payload. Max payload: 4 MiB. ## Socks5Target ```rust pub enum Socks5Target { Ipv4(std::net::Ipv4Addr, u16), Domain { domain: String, port: u16 }, } ``` ## GeneratedMaterial ```rust pub struct GeneratedMaterial { pub ca_cert_pem: String, pub ca_key_pem: String, pub server_cert_pem: String, pub server_key_pem: String, pub client_cert_pem: String, pub client_key_pem: String, pub auth_token: String, } ``` ## Error enums - `TlsError` — missing/invalid certificates, identity mismatch, expiration, verification failure - `AuthError` — missing or invalid token - `TunnelError` — TLS error, auth error, bind error, connection refused, port in use, protocol error - `HostError` — DNS resolution failure, invalid hostname, no addresses - `Socks5Error` — invalid version, unsupported auth/command/addr type, parse errors - `FrameError` — frame too short, payload overflow, I/O error, protocol error ## Key source files | File | Purpose | | ---- | ------- | | `src/connkey.rs` | `ConnectionKey` | | `src/config.rs` | `Config` | | `src/framing.rs` | `Frame`, `FrameReader`, `FrameWriter` | | `src/socks5.rs` | `Socks5Target`, `Socks5State`, `Socks5Error` | | `src/generate.rs` | `GeneratedMaterial` | | `src/errors.rs` | `TlsError`, `AuthError`, `TunnelError`, `HostError` |