Files
rustunnel/droid-wiki/overview/getting-started.md
T
bzuccaro 2bf8da739b
CI / cargo fmt (push) Canceled after 0s
CI / cargo clippy (macos-latest) (push) Canceled after 0s
CI / cargo clippy (ubuntu-latest) (push) Canceled after 0s
CI / cargo clippy (windows-latest) (push) Canceled after 0s
CI / cargo test (macos-latest) (push) Canceled after 0s
CI / cargo test (ubuntu-latest) (push) Canceled after 0s
CI / cargo test (windows-latest) (push) Canceled after 0s
CI / cargo build (macos-latest) (push) Canceled after 0s
CI / cargo build (ubuntu-latest) (push) Canceled after 0s
CI / cargo build (windows-latest) (push) Canceled after 0s
CI / cargo build --release (macos-latest) (push) Canceled after 0s
CI / cargo build --release (ubuntu-latest) (push) Canceled after 0s
CI / cargo build --release (windows-latest) (push) Canceled after 0s
CI / CLI smoke (macos-latest) (push) Canceled after 0s
CI / CLI smoke (ubuntu-latest) (push) Canceled after 0s
CI / CLI smoke (windows-latest) (push) Canceled after 0s
CI / Minimal E2E (macos-latest) (push) Canceled after 0s
CI / Minimal E2E (ubuntu-latest) (push) Canceled after 0s
CI / Minimal E2E (windows-latest) (push) Canceled after 0s
feat: replace connection keys with short seed-derived rtun3 keys
Connection keys are now a ~49-char seed (rtun3.) instead of a bundled
~1740-char certificate blob. Both endpoints deterministically derive an
identical Ed25519 CA from the seed and mint ephemeral server/client leaves
at startup (keyderive.rs); the app-layer auth token is derived from the seed.
Target is passed separately on connect (resocks-style).

- connkey.rs: rtun3 seed parse/format
- keyderive.rs: CA/server/client/token derivation
- keygen takes no args; connect requires --target
- remove miniz_oxide; TLS layer unchanged
- add determinism + key-based e2e + wrong-seed-rejected tests
- update wiki, README, design spec, CI smoke
2026-08-02 12:31:53 -06:00

2.2 KiB

Getting started

Prerequisites

  • Rust 1.85+ (the project uses Edition 2024)
  • A POSIX shell or PowerShell for running commands
  • curl (for E2E testing)

Build

cd rustunnel
cargo build --release

The release binary is produced at target/release/rustunnel.

Run tests

cargo fmt --check
cargo clippy --all-targets -- -D warnings
cargo check
cargo test --all-targets

The test suite includes unit tests for framing, SOCKS5 parsing, TLS config building, credential generation, connection key roundtrips, and full end-to-end tunnel flows.

Generate credentials

./target/release/rustunnel generate --out ./creds

This creates:

  • creds/ca.pem — CA certificate
  • creds/ca.key — CA private key
  • creds/server.crt — server certificate
  • creds/server.key — server private key
  • creds/client.crt — client certificate
  • creds/client.key — client private key
  • creds/token.txt — auth token
  • creds/config.json — configuration file with paths and defaults

Run a tunnel

Start the listener

./target/release/rustunnel listen \
  --listen 127.0.0.1:4180 \
  --cert ./creds/server.crt \
  --key ./creds/server.key \
  --ca-cert ./creds/ca.pem \
  --auth-token-file ./creds/token.txt

Start the connector

./target/release/rustunnel connect \
  --target 127.0.0.1:4180 \
  --socks 127.0.0.1:1180 \
  --cert ./creds/client.crt \
  --key ./creds/client.key \
  --ca-cert ./creds/ca.pem \
  --auth-token-file ./creds/token.txt

Use the SOCKS5 proxy

curl --proxy socks5h://127.0.0.1:1180 http://127.0.0.1:4181/

Using a connection key

Instead of passing individual certificate paths, you can use a short connection key from which both ends derive identical credentials:

./target/release/rustunnel keygen

Start the listener with the key:

./target/release/rustunnel listen --listen 0.0.0.0:4180 --connection-key <key>

Connect with the same key, passing the listener address explicitly:

./target/release/rustunnel connect --target 127.0.0.1:4180 <key>

Defaults

  • Listener bind address: 0.0.0.0:4180
  • Connector target: required (not stored in the key)
  • Connector SOCKS5 proxy: 127.0.0.1:1180