feat(cli): select transport in config; server MultiServer + client dial handover
- aura-cli config gains [transport] (order + per-transport ports + obfuscate/ masquerade); server binds all enabled transports via MultiServer, client uses dial() with UDP->TCP->QUIC handover. Config examples updated; backward-compatible (defaults to udp,tcp,quic). 21 cli tests incl. a real-UDP-transport loopback. - docs/sing-box.md: integration approach note (process-bridge now; native Go outbound for phones, with crypto-library mapping + KAT requirement). - Normalize rustfmt across the v2 transport files (tcp/dial/udp contract). Whole workspace: 97 tests pass, clippy -D warnings clean, fmt clean. Deploy flow (pki init/issue-server/issue-client) validated with the release binary. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
This commit is contained in:
@@ -30,3 +30,18 @@ dns = "10.7.0.1"
|
||||
sni = "cdn.example.com"
|
||||
# Enable traffic padding to blend packet sizes into HTTPS buckets.
|
||||
padding = true
|
||||
|
||||
[transport]
|
||||
# Aura's own post-quantum transport runs over plain UDP (primary), with TCP/443 and QUIC (HTTP/3
|
||||
# mimicry) as fallbacks. On the server, `order` selects exactly which transports are bound and
|
||||
# accepted simultaneously. Omitting this whole section enables udp/tcp/quic on 443/443/444.
|
||||
order = ["udp", "tcp", "quic"]
|
||||
# The UDP transport and QUIC both ride UDP, so udp_port and quic_port MUST differ. TCP may reuse the
|
||||
# UDP port number (different protocol). Ports bind on the IP from [server] listen above.
|
||||
udp_port = 443
|
||||
tcp_port = 443
|
||||
quic_port = 444
|
||||
# UDP: pad datagrams up to HTTPS size buckets to blur the on-wire size distribution.
|
||||
obfuscate = true
|
||||
# TCP: prepend a minimal HTTP/1.1 preamble (Host = [mimicry] sni) so the open resembles plain HTTP.
|
||||
masquerade = true
|
||||
|
||||
Reference in New Issue
Block a user