mirror of
https://github.com/rustdesk/rustdesk-server.git
synced 2026-03-09 21:43:14 +08:00
Compare commits
48 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
753c774380 | ||
|
|
f626f82a94 | ||
|
|
011b316183 | ||
|
|
24620c0a07 | ||
|
|
fa2b42db76 | ||
|
|
099aaa6b55 | ||
|
|
85af668a4f | ||
|
|
74cb82c8a2 | ||
|
|
1b440b61e7 | ||
|
|
6aa0019f8d | ||
|
|
506b0b5364 | ||
|
|
bf3e9471a6 | ||
|
|
4bdc205fca | ||
|
|
cbadfcdfb1 | ||
|
|
d878222fc1 | ||
|
|
848b5aedb7 | ||
|
|
9036b7b9fa | ||
|
|
1c5d4c3cb2 | ||
|
|
b1ad5c2e0c | ||
|
|
6991b6eca0 | ||
|
|
f6c5088aad | ||
|
|
baecd45f27 | ||
|
|
f7fc45a3d2 | ||
|
|
a4940f4634 | ||
|
|
545ae2fd93 | ||
|
|
8c477c8cd0 | ||
|
|
ccc870de77 | ||
|
|
70e6cf13ec | ||
|
|
dbab22cbbc | ||
|
|
fab70ce8e7 | ||
|
|
d11607fb6c | ||
|
|
51d8cd80c1 | ||
|
|
269f2fe0eb | ||
|
|
2d385d88d3 | ||
|
|
595aeb6d50 | ||
|
|
06bd1117f6 | ||
|
|
ee04df9779 | ||
|
|
a98d322685 | ||
|
|
670fb87ee1 | ||
|
|
50d7975ad8 | ||
|
|
003d9f1324 | ||
|
|
26549d7e7e | ||
|
|
913de8515e | ||
|
|
3340322355 | ||
|
|
06409279f4 | ||
|
|
0862bc8c04 | ||
|
|
acaee5b7a4 | ||
|
|
bfcfa68eae |
14
.github/ISSUE_TEMPLATE/ask-a-question.md
vendored
Normal file
14
.github/ISSUE_TEMPLATE/ask-a-question.md
vendored
Normal file
@@ -0,0 +1,14 @@
|
|||||||
|
---
|
||||||
|
name: Ask a question
|
||||||
|
about: Ask the community for help
|
||||||
|
title: ''
|
||||||
|
labels: 'question'
|
||||||
|
assignees: ''
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
This is the place for generic questions. Please stay on topic and be polite.
|
||||||
|
|
||||||
|
**Notes**
|
||||||
|
- Please write in english only. If you provide some images in different languages, you're required to write a translation in english.
|
||||||
|
- In any case, **NEVER** put here the content if your `id_ed25519` file
|
||||||
35
.github/ISSUE_TEMPLATE/bug_report.md
vendored
Normal file
35
.github/ISSUE_TEMPLATE/bug_report.md
vendored
Normal file
@@ -0,0 +1,35 @@
|
|||||||
|
---
|
||||||
|
name: Bug report
|
||||||
|
about: Create a report to help us improve
|
||||||
|
title: ''
|
||||||
|
labels: 'bug'
|
||||||
|
assignees: ''
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
**Describe the bug**
|
||||||
|
A clear and concise description of what the bug is.
|
||||||
|
|
||||||
|
**Describe the environment**
|
||||||
|
- Install environment: docker, docker swarm, podman, kubernetes, or package
|
||||||
|
- If available, the `docker-compose.yaml` file
|
||||||
|
- If package, we need the distribution and release: Ubuntu 22.04, Debian 11, ...
|
||||||
|
- Or if you're running the plain binary, how you're running it
|
||||||
|
- In any case, you have to specify the version in use
|
||||||
|
|
||||||
|
**How to Reproduce the bug**
|
||||||
|
Steps to reproduce the behavior:
|
||||||
|
1. Given the previously described environment
|
||||||
|
2. Do this and that
|
||||||
|
3. I get this error
|
||||||
|
|
||||||
|
**Expected behavior**
|
||||||
|
This should happen instead.
|
||||||
|
|
||||||
|
**Additional context**
|
||||||
|
Add any other context about the problem here.
|
||||||
|
|
||||||
|
**Notes**
|
||||||
|
- Please write in english only. If you provide some images in different languages, you're required to write a translation in english.
|
||||||
|
- In any case, **NEVER** put here the content if your `id_ed25519` file
|
||||||
|
|
||||||
1
.github/ISSUE_TEMPLATE/config.yml
vendored
Normal file
1
.github/ISSUE_TEMPLATE/config.yml
vendored
Normal file
@@ -0,0 +1 @@
|
|||||||
|
blank_issues_enabled: false
|
||||||
25
.github/ISSUE_TEMPLATE/feature_request.md
vendored
Normal file
25
.github/ISSUE_TEMPLATE/feature_request.md
vendored
Normal file
@@ -0,0 +1,25 @@
|
|||||||
|
---
|
||||||
|
name: Feature request
|
||||||
|
about: Suggest an idea for this project
|
||||||
|
title: ''
|
||||||
|
labels: 'enhancement'
|
||||||
|
assignees: ''
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
**Is your feature request related to a problem? Please describe.**
|
||||||
|
A clear and concise description of what the problem is.
|
||||||
|
|
||||||
|
**Describe the solution you'd like**
|
||||||
|
A clear and concise description of what you want to happen.
|
||||||
|
|
||||||
|
**Describe alternatives you've considered**
|
||||||
|
A clear and concise description of any alternative solutions or features you've considered.
|
||||||
|
|
||||||
|
**Additional context**
|
||||||
|
Add any other context about the feature request here.
|
||||||
|
|
||||||
|
**Notes**
|
||||||
|
- Please write in english only. If you provide some images in different languages, you're required to write a translation in english.
|
||||||
|
- In any case, **NEVER** put here the content if your `id_ed25519` file
|
||||||
|
|
||||||
158
.github/workflows/build.yaml
vendored
158
.github/workflows/build.yaml
vendored
@@ -44,9 +44,11 @@ jobs:
|
|||||||
- name: Install toolchain
|
- name: Install toolchain
|
||||||
uses: actions-rs/toolchain@v1
|
uses: actions-rs/toolchain@v1
|
||||||
with:
|
with:
|
||||||
toolchain: nightly
|
toolchain: "1.62"
|
||||||
override: true
|
override: true
|
||||||
default: true
|
default: true
|
||||||
|
components: rustfmt
|
||||||
|
profile: minimal
|
||||||
target: ${{ matrix.job.target }}
|
target: ${{ matrix.job.target }}
|
||||||
|
|
||||||
- name: Build
|
- name: Build
|
||||||
@@ -56,63 +58,95 @@ jobs:
|
|||||||
args: --release --all-features --target=${{ matrix.job.target }}
|
args: --release --all-features --target=${{ matrix.job.target }}
|
||||||
use-cross: true
|
use-cross: true
|
||||||
|
|
||||||
# - name: Run tests
|
- name: Exec chmod
|
||||||
# run: cargo test --verbose
|
run: chmod -v a+x target/${{ matrix.job.target }}/release/*
|
||||||
|
|
||||||
- name: Publish Artifacts
|
- name: Publish Artifacts
|
||||||
uses: actions/upload-artifact@v3
|
uses: actions/upload-artifact@v3
|
||||||
with:
|
with:
|
||||||
name: binaries-${{ matrix.job.name }}
|
name: binaries-linux-${{ matrix.job.name }}
|
||||||
path: |
|
path: |
|
||||||
target/${{ matrix.job.target }}/release/hbbr
|
target/${{ matrix.job.target }}/release/hbbr
|
||||||
target/${{ matrix.job.target }}/release/hbbs
|
target/${{ matrix.job.target }}/release/hbbs
|
||||||
|
target/${{ matrix.job.target }}/release/rustdesk-utils
|
||||||
|
if-no-files-found: error
|
||||||
|
|
||||||
|
build-win:
|
||||||
|
name: Build - windows
|
||||||
|
runs-on: windows-2019
|
||||||
|
|
||||||
|
steps:
|
||||||
|
|
||||||
|
- name: Checkout
|
||||||
|
uses: actions/checkout@v3
|
||||||
|
|
||||||
|
- name: Install toolchain
|
||||||
|
uses: actions-rs/toolchain@v1
|
||||||
|
with:
|
||||||
|
toolchain: "1.62"
|
||||||
|
override: true
|
||||||
|
default: true
|
||||||
|
components: rustfmt
|
||||||
|
profile: minimal
|
||||||
|
target: x86_64-pc-windows-msvc
|
||||||
|
|
||||||
|
- name: Build
|
||||||
|
uses: actions-rs/cargo@v1
|
||||||
|
with:
|
||||||
|
command: build
|
||||||
|
args: --release --all-features --target=x86_64-pc-windows-msvc
|
||||||
|
use-cross: true
|
||||||
|
|
||||||
|
- name: Publish Artifacts
|
||||||
|
uses: actions/upload-artifact@v3
|
||||||
|
with:
|
||||||
|
name: binaries-windows-x86_64
|
||||||
|
path: |
|
||||||
|
target\x86_64-pc-windows-msvc\release\hbbr.exe
|
||||||
|
target\x86_64-pc-windows-msvc\release\hbbs.exe
|
||||||
|
target\x86_64-pc-windows-msvc\release\rustdesk-utils.exe
|
||||||
if-no-files-found: error
|
if-no-files-found: error
|
||||||
|
|
||||||
# github (draft) release with all binaries
|
# github (draft) release with all binaries
|
||||||
release:
|
release:
|
||||||
|
|
||||||
name: Github release
|
name: Github release
|
||||||
needs: build
|
needs:
|
||||||
|
- build
|
||||||
|
- build-win
|
||||||
runs-on: ubuntu-22.04
|
runs-on: ubuntu-22.04
|
||||||
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
|
matrix:
|
||||||
|
job:
|
||||||
|
- { os: "linux", name: "amd64" }
|
||||||
|
- { os: "linux", name: "arm64v8" }
|
||||||
|
- { os: "linux", name: "armv7" }
|
||||||
|
- { os: "linux", name: "i386" }
|
||||||
|
- { os: "windows", name: "x86_64" }
|
||||||
|
|
||||||
steps:
|
steps:
|
||||||
|
|
||||||
- name: Download binaries (amd64)
|
- name: Download binaries (${{ matrix.job.os }} - ${{ matrix.job.name }})
|
||||||
uses: actions/download-artifact@v3
|
uses: actions/download-artifact@v3
|
||||||
with:
|
with:
|
||||||
name: binaries-amd64
|
name: binaries-${{ matrix.job.os }}-${{ matrix.job.name }}
|
||||||
path: amd64
|
path: ${{ matrix.job.name }}
|
||||||
|
|
||||||
- name: Download binaries (arm64v8)
|
- name: Exec chmod
|
||||||
uses: actions/download-artifact@v3
|
run: chmod -v a+x ${{ matrix.job.name }}/*
|
||||||
with:
|
|
||||||
name: binaries-arm64v8
|
|
||||||
path: arm64v8
|
|
||||||
|
|
||||||
- name: Download binaries (armv7)
|
- name: Pack files (${{ matrix.job.os }} - ${{ matrix.job.name }})
|
||||||
uses: actions/download-artifact@v3
|
run: |
|
||||||
with:
|
sudo apt update
|
||||||
name: binaries-armv7
|
DEBIAN_FRONTEND=noninteractive sudo apt install -y zip
|
||||||
path: armv7
|
zip ${{ matrix.job.name }}/rustdesk-server-${{ matrix.job.os }}-${{ matrix.job.name }}.zip ${{ matrix.job.name }}/*
|
||||||
|
|
||||||
- name: Download binaries (i386)
|
- name: Create Release (${{ matrix.job.os }} - (${{ matrix.job.name }})
|
||||||
uses: actions/download-artifact@v3
|
|
||||||
with:
|
|
||||||
name: binaries-i386
|
|
||||||
path: i386
|
|
||||||
|
|
||||||
- name: Rename files
|
|
||||||
run: for arch in amd64 arm64v8 armv7 i386 ; do for b in hbbr hbbs ; do mv -v ${arch}/${b} ${arch}/${b}-${arch} ; done ; done
|
|
||||||
|
|
||||||
- name: Create Release
|
|
||||||
uses: softprops/action-gh-release@v1
|
uses: softprops/action-gh-release@v1
|
||||||
with:
|
with:
|
||||||
draft: true
|
draft: true
|
||||||
files: |
|
files: ${{ matrix.job.name }}/rustdesk-server-${{ matrix.job.os }}-${{ matrix.job.name }}.zip
|
||||||
amd64/*
|
|
||||||
arm64v8/*
|
|
||||||
armv7/*
|
|
||||||
i386/*
|
|
||||||
|
|
||||||
# docker build and push of single-arch images
|
# docker build and push of single-arch images
|
||||||
docker:
|
docker:
|
||||||
@@ -137,7 +171,7 @@ jobs:
|
|||||||
- name: Download binaries
|
- name: Download binaries
|
||||||
uses: actions/download-artifact@v3
|
uses: actions/download-artifact@v3
|
||||||
with:
|
with:
|
||||||
name: binaries-${{ matrix.job.name }}
|
name: binaries-linux-${{ matrix.job.name }}
|
||||||
path: docker/rootfs/usr/bin
|
path: docker/rootfs/usr/bin
|
||||||
|
|
||||||
- name: Make binaries executable
|
- name: Make binaries executable
|
||||||
@@ -209,8 +243,10 @@ jobs:
|
|||||||
echo "MAJOR_TAG=$M" >> $GITHUB_ENV
|
echo "MAJOR_TAG=$M" >> $GITHUB_ENV
|
||||||
|
|
||||||
# manifest for :1.2.3 tag
|
# manifest for :1.2.3 tag
|
||||||
|
# this has to run only if invoked by a new tag
|
||||||
- name: Create and push manifest (:ve.rs.ion)
|
- name: Create and push manifest (:ve.rs.ion)
|
||||||
uses: Noelware/docker-manifest-action@master
|
uses: Noelware/docker-manifest-action@master
|
||||||
|
if: github.event_name != 'workflow_dispatch'
|
||||||
with:
|
with:
|
||||||
base-image: ${{ secrets.DOCKER_IMAGE }}:${{ env.GIT_TAG }}
|
base-image: ${{ secrets.DOCKER_IMAGE }}:${{ env.GIT_TAG }}
|
||||||
extra-images: ${{ secrets.DOCKER_IMAGE }}:${{ env.GIT_TAG }}-amd64,${{ secrets.DOCKER_IMAGE }}:${{ env.GIT_TAG }}-arm64v8,${{ secrets.DOCKER_IMAGE }}:${{ env.GIT_TAG }}-armv7,${{ secrets.DOCKER_IMAGE }}:${{ env.GIT_TAG }}-i386
|
extra-images: ${{ secrets.DOCKER_IMAGE }}:${{ env.GIT_TAG }}-amd64,${{ secrets.DOCKER_IMAGE }}:${{ env.GIT_TAG }}-arm64v8,${{ secrets.DOCKER_IMAGE }}:${{ env.GIT_TAG }}-armv7,${{ secrets.DOCKER_IMAGE }}:${{ env.GIT_TAG }}-i386
|
||||||
@@ -255,7 +291,7 @@ jobs:
|
|||||||
- name: Download binaries
|
- name: Download binaries
|
||||||
uses: actions/download-artifact@v3
|
uses: actions/download-artifact@v3
|
||||||
with:
|
with:
|
||||||
name: binaries-${{ matrix.job.name }}
|
name: binaries-linux-${{ matrix.job.name }}
|
||||||
path: docker-classic/
|
path: docker-classic/
|
||||||
|
|
||||||
- name: Make binaries executable
|
- name: Make binaries executable
|
||||||
@@ -289,3 +325,55 @@ jobs:
|
|||||||
tags: |
|
tags: |
|
||||||
${{ secrets.DOCKER_IMAGE_CLASSIC }}:${{ matrix.job.tag }}
|
${{ secrets.DOCKER_IMAGE_CLASSIC }}:${{ matrix.job.tag }}
|
||||||
labels: ${{ steps.meta.outputs.labels }}
|
labels: ${{ steps.meta.outputs.labels }}
|
||||||
|
|
||||||
|
|
||||||
|
deb-package:
|
||||||
|
|
||||||
|
name: debian package - ${{ matrix.job.name }}
|
||||||
|
needs: build
|
||||||
|
runs-on: ubuntu-22.04
|
||||||
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
|
matrix:
|
||||||
|
job:
|
||||||
|
- { name: "amd64", debian_platform: "amd64", crossbuild_package: "" }
|
||||||
|
- { name: "arm64v8", debian_platform: "arm64", crossbuild_package: "crossbuild-essential-arm64" }
|
||||||
|
- { name: "armv7", debian_platform: "armhf", crossbuild_package: "crossbuild-essential-armhf" }
|
||||||
|
- { name: "i386", debian_platform: "i386", crossbuild_package: "crossbuild-essential-i386" }
|
||||||
|
|
||||||
|
steps:
|
||||||
|
|
||||||
|
- name: Checkout
|
||||||
|
uses: actions/checkout@v3
|
||||||
|
|
||||||
|
- name: Set up QEMU
|
||||||
|
uses: docker/setup-qemu-action@v2
|
||||||
|
|
||||||
|
- name: Create packaging env
|
||||||
|
run: |
|
||||||
|
sudo apt update
|
||||||
|
DEBIAN_FRONTEND=noninteractive sudo apt install -y devscripts build-essential debhelper pkg-config ${{ matrix.job.crossbuild_package }}
|
||||||
|
mkdir -p debian-build/${{ matrix.job.name }}/bin
|
||||||
|
|
||||||
|
- name: Download binaries
|
||||||
|
uses: actions/download-artifact@v3
|
||||||
|
with:
|
||||||
|
name: binaries-linux-${{ matrix.job.name }}
|
||||||
|
path: debian-build/${{ matrix.job.name }}/bin
|
||||||
|
|
||||||
|
- name: Build package for ${{ matrix.job.name }} arch
|
||||||
|
run: |
|
||||||
|
chmod -v a+x debian-build/${{ matrix.job.name }}/bin/*
|
||||||
|
cp -vr debian systemd debian-build/${{ matrix.job.name }}/
|
||||||
|
cat debian/control.tpl | sed 's/{{ ARCH }}/${{ matrix.job.debian_platform }}/' > debian-build/${{ matrix.job.name }}/debian/control
|
||||||
|
cd debian-build/${{ matrix.job.name }}/
|
||||||
|
debuild -i -us -uc -b -a${{ matrix.job.debian_platform }}
|
||||||
|
|
||||||
|
- name: Create Release
|
||||||
|
uses: softprops/action-gh-release@v1
|
||||||
|
with:
|
||||||
|
draft: true
|
||||||
|
files: |
|
||||||
|
debian-build/rustdesk-server-hbbr_*_${{ matrix.job.debian_platform }}.deb
|
||||||
|
debian-build/rustdesk-server-hbbs_*_${{ matrix.job.debian_platform }}.deb
|
||||||
|
debian-build/rustdesk-server-utils_*_${{ matrix.job.debian_platform }}.deb
|
||||||
|
|||||||
5
.gitignore
vendored
5
.gitignore
vendored
@@ -1,3 +1,8 @@
|
|||||||
target
|
target
|
||||||
id*
|
id*
|
||||||
db*
|
db*
|
||||||
|
debian-build
|
||||||
|
debian/.debhelper
|
||||||
|
debian/debhelper-build-stamp
|
||||||
|
.DS_Store
|
||||||
|
.vscode
|
||||||
|
|||||||
79
Cargo.lock
generated
79
Cargo.lock
generated
@@ -194,9 +194,9 @@ checksum = "14c189c53d098945499cdfa7ecc63567cf3886b3332b312a5b4585d8d3a6a610"
|
|||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "bytes"
|
name = "bytes"
|
||||||
version = "1.1.0"
|
version = "1.2.0"
|
||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
checksum = "c4872d67bab6358e59559027aa3b9157c53d9358c51423c17554809a8858e0f8"
|
checksum = "f0b3de4a0c5e67e16066a0715723abd91edc2f9001d09c46e1dca929351e130e"
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "cc"
|
name = "cc"
|
||||||
@@ -749,7 +749,7 @@ dependencies = [
|
|||||||
"log",
|
"log",
|
||||||
"mac_address",
|
"mac_address",
|
||||||
"protobuf",
|
"protobuf",
|
||||||
"protobuf-codegen-pure",
|
"protobuf-codegen",
|
||||||
"quinn",
|
"quinn",
|
||||||
"rand",
|
"rand",
|
||||||
"regex",
|
"regex",
|
||||||
@@ -760,7 +760,7 @@ dependencies = [
|
|||||||
"sodiumoxide",
|
"sodiumoxide",
|
||||||
"tokio",
|
"tokio",
|
||||||
"tokio-socks",
|
"tokio-socks",
|
||||||
"tokio-util 0.6.9",
|
"tokio-util 0.7.1",
|
||||||
"toml",
|
"toml",
|
||||||
"winapi",
|
"winapi",
|
||||||
"zstd",
|
"zstd",
|
||||||
@@ -1463,60 +1463,56 @@ dependencies = [
|
|||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "protobuf"
|
name = "protobuf"
|
||||||
version = "3.0.0-alpha.2"
|
version = "3.1.0"
|
||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
checksum = "9d5ef59c35c7472ce5e1b6c5924b87585143d1fc2cf39eae0009bba6c4df62f1"
|
checksum = "4ee4a7d8b91800c8f167a6268d1a1026607368e1adc84e98fe044aeb905302f7"
|
||||||
|
dependencies = [
|
||||||
|
"bytes",
|
||||||
|
"once_cell",
|
||||||
|
"protobuf-support",
|
||||||
|
"thiserror",
|
||||||
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "protobuf-codegen"
|
name = "protobuf-codegen"
|
||||||
version = "3.0.0-alpha.2"
|
version = "3.1.0"
|
||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
checksum = "89100ee819f69b77a4cab389fec9dd155a305af4c615e6413ec1ef9341f333ef"
|
checksum = "07b893e5e7d3395545d5244f8c0d33674025bd566b26c03bfda49b82c6dec45e"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"anyhow",
|
"anyhow",
|
||||||
|
"once_cell",
|
||||||
"protobuf",
|
"protobuf",
|
||||||
"protobuf-parse",
|
"protobuf-parse",
|
||||||
"thiserror",
|
"regex",
|
||||||
]
|
|
||||||
|
|
||||||
[[package]]
|
|
||||||
name = "protobuf-codegen-pure"
|
|
||||||
version = "3.0.0-alpha.2"
|
|
||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
|
||||||
checksum = "79453e74d08190551e821533ee42c447f9e21ca26f83520e120e6e8af27f6879"
|
|
||||||
dependencies = [
|
|
||||||
"anyhow",
|
|
||||||
"protobuf",
|
|
||||||
"protobuf-codegen",
|
|
||||||
"protobuf-parse",
|
|
||||||
"thiserror",
|
|
||||||
]
|
|
||||||
|
|
||||||
[[package]]
|
|
||||||
name = "protobuf-parse"
|
|
||||||
version = "3.0.0-alpha.2"
|
|
||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
|
||||||
checksum = "c265ffc69976efc3056955b881641add3186ad0be893ef10622482d80d1d2b68"
|
|
||||||
dependencies = [
|
|
||||||
"anyhow",
|
|
||||||
"protobuf",
|
|
||||||
"protoc",
|
|
||||||
"tempfile",
|
"tempfile",
|
||||||
"thiserror",
|
"thiserror",
|
||||||
]
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "protoc"
|
name = "protobuf-parse"
|
||||||
version = "3.0.0-alpha.2"
|
version = "3.1.0"
|
||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
checksum = "1f1f8b318a54d18fbe542513331e058f4f8ce6502e542e057c50c7e5e803fdab"
|
checksum = "9b1447dd751c434cc1b415579837ebd0411ed7d67d465f38010da5d7cd33af4d"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"anyhow",
|
"anyhow",
|
||||||
|
"indexmap",
|
||||||
"log",
|
"log",
|
||||||
|
"protobuf",
|
||||||
|
"protobuf-support",
|
||||||
|
"tempfile",
|
||||||
"thiserror",
|
"thiserror",
|
||||||
"which",
|
"which",
|
||||||
]
|
]
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "protobuf-support"
|
||||||
|
version = "3.1.0"
|
||||||
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
|
checksum = "8ca157fe12fc7ee2e315f2f735e27df41b3d97cdd70ea112824dac1ffb08ee1c"
|
||||||
|
dependencies = [
|
||||||
|
"thiserror",
|
||||||
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "punycode"
|
name = "punycode"
|
||||||
version = "0.4.1"
|
version = "0.4.1"
|
||||||
@@ -2197,10 +2193,11 @@ checksum = "cda74da7e1a664f795bb1f8a87ec406fb89a02522cf6e50620d016add6dbbf5c"
|
|||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "tokio"
|
name = "tokio"
|
||||||
version = "1.18.2"
|
version = "1.20.0"
|
||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
checksum = "4903bf0427cf68dddd5aa6a93220756f8be0c34fcfa9f5e6191e103e15a31395"
|
checksum = "57aec3cfa4c296db7255446efb4928a6be304b431a806216105542a67b6ca82e"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
|
"autocfg",
|
||||||
"bytes",
|
"bytes",
|
||||||
"libc",
|
"libc",
|
||||||
"memchr",
|
"memchr",
|
||||||
@@ -2284,11 +2281,9 @@ checksum = "9e99e1983e5d376cd8eb4b66604d2e99e79f5bd988c3055891dcd8c9e2604cc0"
|
|||||||
dependencies = [
|
dependencies = [
|
||||||
"bytes",
|
"bytes",
|
||||||
"futures-core",
|
"futures-core",
|
||||||
"futures-io",
|
|
||||||
"futures-sink",
|
"futures-sink",
|
||||||
"log",
|
"log",
|
||||||
"pin-project-lite",
|
"pin-project-lite",
|
||||||
"slab",
|
|
||||||
"tokio",
|
"tokio",
|
||||||
]
|
]
|
||||||
|
|
||||||
@@ -2300,9 +2295,13 @@ checksum = "0edfdeb067411dba2044da6d1cb2df793dd35add7888d73c16e3381ded401764"
|
|||||||
dependencies = [
|
dependencies = [
|
||||||
"bytes",
|
"bytes",
|
||||||
"futures-core",
|
"futures-core",
|
||||||
|
"futures-io",
|
||||||
"futures-sink",
|
"futures-sink",
|
||||||
|
"futures-util",
|
||||||
"pin-project-lite",
|
"pin-project-lite",
|
||||||
|
"slab",
|
||||||
"tokio",
|
"tokio",
|
||||||
|
"tracing",
|
||||||
]
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
|
|||||||
@@ -10,6 +10,10 @@ default-run = "hbbs"
|
|||||||
name = "hbbr"
|
name = "hbbr"
|
||||||
path = "src/hbbr.rs"
|
path = "src/hbbr.rs"
|
||||||
|
|
||||||
|
[[bin]]
|
||||||
|
name = "rustdesk-utils"
|
||||||
|
path = "src/utils.rs"
|
||||||
|
|
||||||
# See more keys and their definitions at https://doc.rust-lang.org/cargo/reference/manifest.html
|
# See more keys and their definitions at https://doc.rust-lang.org/cargo/reference/manifest.html
|
||||||
|
|
||||||
[dependencies]
|
[dependencies]
|
||||||
@@ -45,6 +49,8 @@ http = "0.2"
|
|||||||
flexi_logger = { version = "0.22", features = ["async", "use_chrono_for_offset"] }
|
flexi_logger = { version = "0.22", features = ["async", "use_chrono_for_offset"] }
|
||||||
ipnetwork = "0.20"
|
ipnetwork = "0.20"
|
||||||
local-ip-address = "0.4"
|
local-ip-address = "0.4"
|
||||||
|
dns-lookup = "1.0.8"
|
||||||
|
ping = "0.4.0"
|
||||||
|
|
||||||
[build-dependencies]
|
[build-dependencies]
|
||||||
hbb_common = { path = "libs/hbb_common" }
|
hbb_common = { path = "libs/hbb_common" }
|
||||||
|
|||||||
158
README.md
158
README.md
@@ -16,10 +16,11 @@ Self-host your own RustDesk server, it is free and open source.
|
|||||||
cargo build --release
|
cargo build --release
|
||||||
```
|
```
|
||||||
|
|
||||||
Two executables will be generated in target/release.
|
Three executables will be generated in target/release.
|
||||||
|
|
||||||
- hbbs - RustDesk ID/Rendezvous server
|
- hbbs - RustDesk ID/Rendezvous server
|
||||||
- hbbr - RustDesk relay server
|
- hbbr - RustDesk relay server
|
||||||
|
- rustdesk-utils - RustDesk CLI utilities
|
||||||
|
|
||||||
You can find updated binaries on the [releases](https://github.com/rustdesk/rustdesk-server/releases) page.
|
You can find updated binaries on the [releases](https://github.com/rustdesk/rustdesk-server/releases) page.
|
||||||
|
|
||||||
@@ -31,7 +32,7 @@ Docker images are automatically generated and published on every github release.
|
|||||||
|
|
||||||
### Classic image
|
### Classic image
|
||||||
|
|
||||||
These images are build against `ubuntu-20.04` with the only addition of the binaries (both hbbr and hbbs). They're available on [Docker hub](https://hub.docker.com/r/rustdesk/rustdesk-server/) with these tags:
|
These images are build against `ubuntu-20.04` with the only addition of the main binaries (`hbbr` and `hbbs`). They're available on [Docker hub](https://hub.docker.com/r/rustdesk/rustdesk-server/) with these tags:
|
||||||
|
|
||||||
| architecture | image:tag |
|
| architecture | image:tag |
|
||||||
| --- | --- |
|
| --- | --- |
|
||||||
@@ -40,16 +41,18 @@ These images are build against `ubuntu-20.04` with the only addition of the bina
|
|||||||
|
|
||||||
You can start these images directly with `docker run` with these commands:
|
You can start these images directly with `docker run` with these commands:
|
||||||
|
|
||||||
```
|
```bash
|
||||||
docker run --name hbbs --net=host -v "$PWD:/root" -d rustdesk/rustdesk-server:latest hbbs -r <relay-server-ip[:port]>
|
docker run --name hbbs --net=host -v "$PWD/data:/root" -d rustdesk/rustdesk-server:latest hbbs -r <relay-server-ip[:port]>
|
||||||
docker run --name hbbr --net=host -v "$PWD:/root" -d rustdesk/rustdesk-server:latest hbbr
|
docker run --name hbbr --net=host -v "$PWD/data:/root" -d rustdesk/rustdesk-server:latest hbbr
|
||||||
```
|
```
|
||||||
|
|
||||||
or without --net=host, but P2P direct connection can not work.
|
or without --net=host, but P2P direct connection can not work.
|
||||||
|
|
||||||
|
For systems using SELinux, replacing `/root` by `/root:z` is required for the containers to run correctly. Alternatively, SELinux container separation can be disabled completely adding the option `--security-opt label=disable`.
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
docker run --name hbbs -p 21115:21115 -p 21116:21116 -p 21116:21116/udp -p 21118:21118 -v "$PWD:/root" -d rustdesk/rustdesk-server:latest hbbs -r <relay-server-ip[:port]>
|
docker run --name hbbs -p 21115:21115 -p 21116:21116 -p 21116:21116/udp -p 21118:21118 -v "$PWD/data:/root" -d rustdesk/rustdesk-server:latest hbbs -r <relay-server-ip[:port]>
|
||||||
docker run --name hbbr -p 21117:21117 -p 21119:21119 -v "$PWD:/root" -d rustdesk/rustdesk-server:latest hbbr
|
docker run --name hbbr -p 21117:21117 -p 21119:21119 -v "$PWD/data:/root" -d rustdesk/rustdesk-server:latest hbbr
|
||||||
```
|
```
|
||||||
|
|
||||||
The `relay-server-ip` parameter is the IP address (or dns name) of the server running these containers. The **optional** `port` parameter has to be used if you use a port different than **21117** for `hbbr`.
|
The `relay-server-ip` parameter is the IP address (or dns name) of the server running these containers. The **optional** `port` parameter has to be used if you use a port different than **21117** for `hbbr`.
|
||||||
@@ -74,7 +77,7 @@ services:
|
|||||||
image: rustdesk/rustdesk-server:latest
|
image: rustdesk/rustdesk-server:latest
|
||||||
command: hbbs -r rustdesk.example.com:21117
|
command: hbbs -r rustdesk.example.com:21117
|
||||||
volumes:
|
volumes:
|
||||||
- ./hbbs:/root
|
- ./data:/root
|
||||||
networks:
|
networks:
|
||||||
- rustdesk-net
|
- rustdesk-net
|
||||||
depends_on:
|
depends_on:
|
||||||
@@ -89,7 +92,7 @@ services:
|
|||||||
image: rustdesk/rustdesk-server:latest
|
image: rustdesk/rustdesk-server:latest
|
||||||
command: hbbr
|
command: hbbr
|
||||||
volumes:
|
volumes:
|
||||||
- ./hbbr:/root
|
- ./data:/root
|
||||||
networks:
|
networks:
|
||||||
- rustdesk-net
|
- rustdesk-net
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
@@ -176,3 +179,140 @@ We use these environment variables:
|
|||||||
| --- | --- | --- |
|
| --- | --- | --- |
|
||||||
| RELAY | no | the IP address/DNS name of the machine running this container |
|
| RELAY | no | the IP address/DNS name of the machine running this container |
|
||||||
| ENCRYPTED_ONLY | yes | if set to **"1"** unencrypted connection will not be accepted |
|
| ENCRYPTED_ONLY | yes | if set to **"1"** unencrypted connection will not be accepted |
|
||||||
|
| DB_URL | yes | path for database file |
|
||||||
|
| KEY_PUB | yes | public part of the key pair |
|
||||||
|
| KEY_PRIV | yes | private part of the key pair |
|
||||||
|
| RUST_LOG | yes | set debug level (error|warn|info|debug|trace) |
|
||||||
|
|
||||||
|
### Secret management in S6-overlay based images
|
||||||
|
|
||||||
|
You can obviously keep the key pair in a docker volume, but the best practices tells you to not write the keys on the filesystem; so we provide a couple of options.
|
||||||
|
|
||||||
|
On container startup, the presence of the keypair is checked (`/data/id_ed25519.pub` and `/data/id_ed25519`) and if one of these keys doesn't exist, it's recreated from ENV variables or docker secrets.
|
||||||
|
Then the validity of the keypair is checked: if public and private keys doesn't match, the container will stop.
|
||||||
|
If you provide no keys, `hbbs` will generate one for you, and it'll place it in the default location.
|
||||||
|
|
||||||
|
#### Use ENV to store the key pair
|
||||||
|
|
||||||
|
You can use docker environment variables to store the keys. Just follow this examples:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
docker run --name rustdesk-server \
|
||||||
|
--net=host \
|
||||||
|
-e "RELAY=rustdeskrelay.example.com" \
|
||||||
|
-e "ENCRYPTED_ONLY=1" \
|
||||||
|
-e "DB_URL=/db/db_v2.sqlite3" \
|
||||||
|
-e "KEY_PRIV=FR2j78IxfwJNR+HjLluQ2Nh7eEryEeIZCwiQDPVe+PaITKyShphHAsPLn7So0OqRs92nGvSRdFJnE2MSyrKTIQ==" \
|
||||||
|
-e "KEY_PUB=iEyskoaYRwLDy5+0qNDqkbPdpxr0kXRSZxNjEsqykyE=" \
|
||||||
|
-v "$PWD/db:/db" -d rustdesk/rustdesk-server-s6:latest
|
||||||
|
```
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
version: '3'
|
||||||
|
|
||||||
|
services:
|
||||||
|
rustdesk-server:
|
||||||
|
container_name: rustdesk-server
|
||||||
|
ports:
|
||||||
|
- 21115:21115
|
||||||
|
- 21116:21116
|
||||||
|
- 21116:21116/udp
|
||||||
|
- 21117:21117
|
||||||
|
- 21118:21118
|
||||||
|
- 21119:21119
|
||||||
|
image: rustdesk/rustdesk-server-s6:latest
|
||||||
|
environment:
|
||||||
|
- "RELAY=rustdesk.example.com:21117"
|
||||||
|
- "ENCRYPTED_ONLY=1"
|
||||||
|
- "DB_URL=/db/db_v2.sqlite3"
|
||||||
|
- "KEY_PRIV=FR2j78IxfwJNR+HjLluQ2Nh7eEryEeIZCwiQDPVe+PaITKyShphHAsPLn7So0OqRs92nGvSRdFJnE2MSyrKTIQ=="
|
||||||
|
- "KEY_PUB=iEyskoaYRwLDy5+0qNDqkbPdpxr0kXRSZxNjEsqykyE="
|
||||||
|
volumes:
|
||||||
|
- ./db:/db
|
||||||
|
restart: unless-stopped
|
||||||
|
```
|
||||||
|
|
||||||
|
#### Use Docker secrets to store the key pair
|
||||||
|
|
||||||
|
You can alternatively use docker secrets to store the keys.
|
||||||
|
This is useful if you're using **docker-compose** or **docker swarm**.
|
||||||
|
Just follow this examples:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
cat secrets/id_ed25519.pub | docker secret create key_pub -
|
||||||
|
cat secrets/id_ed25519 | docker secret create key_priv -
|
||||||
|
docker service create --name rustdesk-server \
|
||||||
|
--secret key_priv --secret key_pub \
|
||||||
|
--net=host \
|
||||||
|
-e "RELAY=rustdeskrelay.example.com" \
|
||||||
|
-e "ENCRYPTED_ONLY=1" \
|
||||||
|
-e "DB_URL=/db/db_v2.sqlite3" \
|
||||||
|
--mount "type=bind,source=$PWD/db,destination=/db" \
|
||||||
|
rustdesk/rustdesk-server-s6:latest
|
||||||
|
```
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
version: '3'
|
||||||
|
|
||||||
|
services:
|
||||||
|
rustdesk-server:
|
||||||
|
container_name: rustdesk-server
|
||||||
|
ports:
|
||||||
|
- 21115:21115
|
||||||
|
- 21116:21116
|
||||||
|
- 21116:21116/udp
|
||||||
|
- 21117:21117
|
||||||
|
- 21118:21118
|
||||||
|
- 21119:21119
|
||||||
|
image: rustdesk/rustdesk-server-s6:latest
|
||||||
|
environment:
|
||||||
|
- "RELAY=rustdesk.example.com:21117"
|
||||||
|
- "ENCRYPTED_ONLY=1"
|
||||||
|
- "DB_URL=/db/db_v2.sqlite3"
|
||||||
|
volumes:
|
||||||
|
- ./db:/db
|
||||||
|
restart: unless-stopped
|
||||||
|
secrets:
|
||||||
|
- key_pub
|
||||||
|
- key_priv
|
||||||
|
|
||||||
|
secrets:
|
||||||
|
key_pub:
|
||||||
|
file: secrets/id_ed25519.pub
|
||||||
|
key_priv:
|
||||||
|
file: secrets/id_ed25519
|
||||||
|
```
|
||||||
|
|
||||||
|
## How to create a keypair
|
||||||
|
|
||||||
|
A keypair is needed for encryption; you can provide it, as explained before, but you need a way to create one.
|
||||||
|
|
||||||
|
You can use this command to generate a keypair:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
/usr/bin/rustdesk-utils genkeypair
|
||||||
|
```
|
||||||
|
|
||||||
|
If you don't have (or don't want) the `rustdesk-utils` package installed on your system, you can invoke the same command with docker:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
docker run --rm --entrypoint /usr/bin/rustdesk-utils rustdesk/rustdesk-server-s6:latest genkeypair
|
||||||
|
```
|
||||||
|
|
||||||
|
The output will be something like this:
|
||||||
|
|
||||||
|
```text
|
||||||
|
Public Key: 8BLLhtzUBU/XKAH4mep3p+IX4DSApe7qbAwNH9nv4yA=
|
||||||
|
Secret Key: egAVd44u33ZEUIDTtksGcHeVeAwywarEdHmf99KM5ajwEsuG3NQFT9coAfiZ6nen4hfgNICl7upsDA0f2e/jIA==
|
||||||
|
```
|
||||||
|
|
||||||
|
## .deb packages
|
||||||
|
|
||||||
|
Separate .deb packages are available for each binary, you can find them in the [releases](https://github.com/rustdesk/rustdesk-server/releases).
|
||||||
|
These packages are meant for the following distributions:
|
||||||
|
|
||||||
|
- Ubuntu 22.04 LTS
|
||||||
|
- Ubuntu 20.04 LTS
|
||||||
|
- Ubuntu 18.04 LTS
|
||||||
|
- Debian 11 bullseye
|
||||||
|
- Debian 10 buster
|
||||||
|
|||||||
BIN
db_v2.sqlite3
BIN
db_v2.sqlite3
Binary file not shown.
5
debian/changelog
vendored
Normal file
5
debian/changelog
vendored
Normal file
@@ -0,0 +1,5 @@
|
|||||||
|
rustdesk-server (1.1.6) UNRELEASED; urgency=medium
|
||||||
|
|
||||||
|
* Initial release
|
||||||
|
|
||||||
|
-- open-trade <info@rustdesk.com> Fri, 15 Jul 2022 12:27:27 +0200
|
||||||
1
debian/compat
vendored
Normal file
1
debian/compat
vendored
Normal file
@@ -0,0 +1 @@
|
|||||||
|
10
|
||||||
27
debian/control.tpl
vendored
Normal file
27
debian/control.tpl
vendored
Normal file
@@ -0,0 +1,27 @@
|
|||||||
|
Source: rustdesk-server
|
||||||
|
Section: net
|
||||||
|
Priority: optional
|
||||||
|
Maintainer: open-trade <info@rustdesk.com>
|
||||||
|
Build-Depends: debhelper (>= 10), pkg-config
|
||||||
|
Standards-Version: 4.5.0
|
||||||
|
Homepage: https://rustdesk.com/
|
||||||
|
|
||||||
|
Package: rustdesk-server-hbbs
|
||||||
|
Architecture: {{ ARCH }}
|
||||||
|
Depends: systemd ${misc:Depends}
|
||||||
|
Description: RustDesk server
|
||||||
|
Self-host your own RustDesk server, it is free and open source.
|
||||||
|
|
||||||
|
Package: rustdesk-server-hbbr
|
||||||
|
Architecture: {{ ARCH }}
|
||||||
|
Depends: systemd ${misc:Depends}
|
||||||
|
Description: RustDesk server
|
||||||
|
Self-host your own RustDesk server, it is free and open source.
|
||||||
|
This package contains the RustDesk relay server.
|
||||||
|
|
||||||
|
Package: rustdesk-server-utils
|
||||||
|
Architecture: {{ ARCH }}
|
||||||
|
Depends: ${misc:Depends}
|
||||||
|
Description: RustDesk server
|
||||||
|
Self-host your own RustDesk server, it is free and open source.
|
||||||
|
This package contains the rustdesk-utils binary.
|
||||||
679
debian/copyright
vendored
Normal file
679
debian/copyright
vendored
Normal file
@@ -0,0 +1,679 @@
|
|||||||
|
Format: https://www.debian.org/doc/packaging-manuals/copyright-format/1.0/
|
||||||
|
Upstream-Name: rustdesk-server
|
||||||
|
Files: *
|
||||||
|
Copyright: Copyright 2022 open-trade <info@rustdesk.com>
|
||||||
|
License: AGPL-3.0
|
||||||
|
This program is free software: you can redistribute it and/or modify
|
||||||
|
it under the terms of the GNU Affero General Public License as published by
|
||||||
|
the Free Software Foundation, either version 3 of the License, or
|
||||||
|
(at your option) any later version.
|
||||||
|
.
|
||||||
|
This program is distributed in the hope that it will be useful,
|
||||||
|
but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||||
|
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||||
|
GNU Affero General Public License for more details.
|
||||||
|
.
|
||||||
|
You should have received a copy of the GNU Affero General Public License
|
||||||
|
along with this program. If not, see <http://www.gnu.org/licenses/>.
|
||||||
|
.
|
||||||
|
GNU AFFERO GENERAL PUBLIC LICENSE
|
||||||
|
Version 3, 19 November 2007
|
||||||
|
.
|
||||||
|
Copyright (C) 2007 Free Software Foundation, Inc. <http://fsf.org/>
|
||||||
|
Everyone is permitted to copy and distribute verbatim copies
|
||||||
|
of this license document, but changing it is not allowed.
|
||||||
|
.
|
||||||
|
Preamble
|
||||||
|
.
|
||||||
|
The GNU Affero General Public License is a free, copyleft license for
|
||||||
|
software and other kinds of works, specifically designed to ensure
|
||||||
|
cooperation with the community in the case of network server software.
|
||||||
|
.
|
||||||
|
The licenses for most software and other practical works are designed
|
||||||
|
to take away your freedom to share and change the works. By contrast,
|
||||||
|
our General Public Licenses are intended to guarantee your freedom to
|
||||||
|
share and change all versions of a program--to make sure it remains free
|
||||||
|
software for all its users.
|
||||||
|
.
|
||||||
|
When we speak of free software, we are referring to freedom, not
|
||||||
|
price. Our General Public Licenses are designed to make sure that you
|
||||||
|
have the freedom to distribute copies of free software (and charge for
|
||||||
|
them if you wish), that you receive source code or can get it if you
|
||||||
|
want it, that you can change the software or use pieces of it in new
|
||||||
|
free programs, and that you know you can do these things.
|
||||||
|
.
|
||||||
|
Developers that use our General Public Licenses protect your rights
|
||||||
|
with two steps: (1) assert copyright on the software, and (2) offer
|
||||||
|
you this License which gives you legal permission to copy, distribute
|
||||||
|
and/or modify the software.
|
||||||
|
.
|
||||||
|
A secondary benefit of defending all users' freedom is that
|
||||||
|
improvements made in alternate versions of the program, if they
|
||||||
|
receive widespread use, become available for other developers to
|
||||||
|
incorporate. Many developers of free software are heartened and
|
||||||
|
encouraged by the resulting cooperation. However, in the case of
|
||||||
|
software used on network servers, this result may fail to come about.
|
||||||
|
The GNU General Public License permits making a modified version and
|
||||||
|
letting the public access it on a server without ever releasing its
|
||||||
|
source code to the public.
|
||||||
|
.
|
||||||
|
The GNU Affero General Public License is designed specifically to
|
||||||
|
ensure that, in such cases, the modified source code becomes available
|
||||||
|
to the community. It requires the operator of a network server to
|
||||||
|
provide the source code of the modified version running there to the
|
||||||
|
users of that server. Therefore, public use of a modified version, on
|
||||||
|
a publicly accessible server, gives the public access to the source
|
||||||
|
code of the modified version.
|
||||||
|
.
|
||||||
|
An older license, called the Affero General Public License and
|
||||||
|
published by Affero, was designed to accomplish similar goals. This is
|
||||||
|
a different license, not a version of the Affero GPL, but Affero has
|
||||||
|
released a new version of the Affero GPL which permits relicensing under
|
||||||
|
this license.
|
||||||
|
.
|
||||||
|
The precise terms and conditions for copying, distribution and
|
||||||
|
modification follow.
|
||||||
|
.
|
||||||
|
TERMS AND CONDITIONS
|
||||||
|
.
|
||||||
|
0. Definitions.
|
||||||
|
.
|
||||||
|
"This License" refers to version 3 of the GNU Affero General Public License.
|
||||||
|
.
|
||||||
|
"Copyright" also means copyright-like laws that apply to other kinds of
|
||||||
|
works, such as semiconductor masks.
|
||||||
|
.
|
||||||
|
"The Program" refers to any copyrightable work licensed under this
|
||||||
|
License. Each licensee is addressed as "you". "Licensees" and
|
||||||
|
"recipients" may be individuals or organizations.
|
||||||
|
.
|
||||||
|
To "modify" a work means to copy from or adapt all or part of the work
|
||||||
|
in a fashion requiring copyright permission, other than the making of an
|
||||||
|
exact copy. The resulting work is called a "modified version" of the
|
||||||
|
earlier work or a work "based on" the earlier work.
|
||||||
|
.
|
||||||
|
A "covered work" means either the unmodified Program or a work based
|
||||||
|
on the Program.
|
||||||
|
.
|
||||||
|
To "propagate" a work means to do anything with it that, without
|
||||||
|
permission, would make you directly or secondarily liable for
|
||||||
|
infringement under applicable copyright law, except executing it on a
|
||||||
|
computer or modifying a private copy. Propagation includes copying,
|
||||||
|
distribution (with or without modification), making available to the
|
||||||
|
public, and in some countries other activities as well.
|
||||||
|
.
|
||||||
|
To "convey" a work means any kind of propagation that enables other
|
||||||
|
parties to make or receive copies. Mere interaction with a user through
|
||||||
|
a computer network, with no transfer of a copy, is not conveying.
|
||||||
|
.
|
||||||
|
An interactive user interface displays "Appropriate Legal Notices"
|
||||||
|
to the extent that it includes a convenient and prominently visible
|
||||||
|
feature that (1) displays an appropriate copyright notice, and (2)
|
||||||
|
tells the user that there is no warranty for the work (except to the
|
||||||
|
extent that warranties are provided), that licensees may convey the
|
||||||
|
work under this License, and how to view a copy of this License. If
|
||||||
|
the interface presents a list of user commands or options, such as a
|
||||||
|
menu, a prominent item in the list meets this criterion.
|
||||||
|
.
|
||||||
|
1. Source Code.
|
||||||
|
.
|
||||||
|
The "source code" for a work means the preferred form of the work
|
||||||
|
for making modifications to it. "Object code" means any non-source
|
||||||
|
form of a work.
|
||||||
|
.
|
||||||
|
A "Standard Interface" means an interface that either is an official
|
||||||
|
standard defined by a recognized standards body, or, in the case of
|
||||||
|
interfaces specified for a particular programming language, one that
|
||||||
|
is widely used among developers working in that language.
|
||||||
|
.
|
||||||
|
The "System Libraries" of an executable work include anything, other
|
||||||
|
than the work as a whole, that (a) is included in the normal form of
|
||||||
|
packaging a Major Component, but which is not part of that Major
|
||||||
|
Component, and (b) serves only to enable use of the work with that
|
||||||
|
Major Component, or to implement a Standard Interface for which an
|
||||||
|
implementation is available to the public in source code form. A
|
||||||
|
"Major Component", in this context, means a major essential component
|
||||||
|
(kernel, window system, and so on) of the specific operating system
|
||||||
|
(if any) on which the executable work runs, or a compiler used to
|
||||||
|
produce the work, or an object code interpreter used to run it.
|
||||||
|
.
|
||||||
|
The "Corresponding Source" for a work in object code form means all
|
||||||
|
the source code needed to generate, install, and (for an executable
|
||||||
|
work) run the object code and to modify the work, including scripts to
|
||||||
|
control those activities. However, it does not include the work's
|
||||||
|
System Libraries, or general-purpose tools or generally available free
|
||||||
|
programs which are used unmodified in performing those activities but
|
||||||
|
which are not part of the work. For example, Corresponding Source
|
||||||
|
includes interface definition files associated with source files for
|
||||||
|
the work, and the source code for shared libraries and dynamically
|
||||||
|
linked subprograms that the work is specifically designed to require,
|
||||||
|
such as by intimate data communication or control flow between those
|
||||||
|
subprograms and other parts of the work.
|
||||||
|
.
|
||||||
|
The Corresponding Source need not include anything that users
|
||||||
|
can regenerate automatically from other parts of the Corresponding
|
||||||
|
Source.
|
||||||
|
.
|
||||||
|
The Corresponding Source for a work in source code form is that
|
||||||
|
same work.
|
||||||
|
.
|
||||||
|
2. Basic Permissions.
|
||||||
|
.
|
||||||
|
All rights granted under this License are granted for the term of
|
||||||
|
copyright on the Program, and are irrevocable provided the stated
|
||||||
|
conditions are met. This License explicitly affirms your unlimited
|
||||||
|
permission to run the unmodified Program. The output from running a
|
||||||
|
covered work is covered by this License only if the output, given its
|
||||||
|
content, constitutes a covered work. This License acknowledges your
|
||||||
|
rights of fair use or other equivalent, as provided by copyright law.
|
||||||
|
.
|
||||||
|
You may make, run and propagate covered works that you do not
|
||||||
|
convey, without conditions so long as your license otherwise remains
|
||||||
|
in force. You may convey covered works to others for the sole purpose
|
||||||
|
of having them make modifications exclusively for you, or provide you
|
||||||
|
with facilities for running those works, provided that you comply with
|
||||||
|
the terms of this License in conveying all material for which you do
|
||||||
|
not control copyright. Those thus making or running the covered works
|
||||||
|
for you must do so exclusively on your behalf, under your direction
|
||||||
|
and control, on terms that prohibit them from making any copies of
|
||||||
|
your copyrighted material outside their relationship with you.
|
||||||
|
.
|
||||||
|
Conveying under any other circumstances is permitted solely under
|
||||||
|
the conditions stated below. Sublicensing is not allowed; section 10
|
||||||
|
makes it unnecessary.
|
||||||
|
.
|
||||||
|
3. Protecting Users' Legal Rights From Anti-Circumvention Law.
|
||||||
|
.
|
||||||
|
No covered work shall be deemed part of an effective technological
|
||||||
|
measure under any applicable law fulfilling obligations under article
|
||||||
|
11 of the WIPO copyright treaty adopted on 20 December 1996, or
|
||||||
|
similar laws prohibiting or restricting circumvention of such
|
||||||
|
measures.
|
||||||
|
.
|
||||||
|
When you convey a covered work, you waive any legal power to forbid
|
||||||
|
circumvention of technological measures to the extent such circumvention
|
||||||
|
is effected by exercising rights under this License with respect to
|
||||||
|
the covered work, and you disclaim any intention to limit operation or
|
||||||
|
modification of the work as a means of enforcing, against the work's
|
||||||
|
users, your or third parties' legal rights to forbid circumvention of
|
||||||
|
technological measures.
|
||||||
|
.
|
||||||
|
4. Conveying Verbatim Copies.
|
||||||
|
.
|
||||||
|
You may convey verbatim copies of the Program's source code as you
|
||||||
|
receive it, in any medium, provided that you conspicuously and
|
||||||
|
appropriately publish on each copy an appropriate copyright notice;
|
||||||
|
keep intact all notices stating that this License and any
|
||||||
|
non-permissive terms added in accord with section 7 apply to the code;
|
||||||
|
keep intact all notices of the absence of any warranty; and give all
|
||||||
|
recipients a copy of this License along with the Program.
|
||||||
|
.
|
||||||
|
You may charge any price or no price for each copy that you convey,
|
||||||
|
and you may offer support or warranty protection for a fee.
|
||||||
|
.
|
||||||
|
5. Conveying Modified Source Versions.
|
||||||
|
.
|
||||||
|
You may convey a work based on the Program, or the modifications to
|
||||||
|
produce it from the Program, in the form of source code under the
|
||||||
|
terms of section 4, provided that you also meet all of these conditions:
|
||||||
|
.
|
||||||
|
a) The work must carry prominent notices stating that you modified
|
||||||
|
it, and giving a relevant date.
|
||||||
|
.
|
||||||
|
b) The work must carry prominent notices stating that it is
|
||||||
|
released under this License and any conditions added under section
|
||||||
|
7. This requirement modifies the requirement in section 4 to
|
||||||
|
"keep intact all notices".
|
||||||
|
.
|
||||||
|
c) You must license the entire work, as a whole, under this
|
||||||
|
License to anyone who comes into possession of a copy. This
|
||||||
|
License will therefore apply, along with any applicable section 7
|
||||||
|
additional terms, to the whole of the work, and all its parts,
|
||||||
|
regardless of how they are packaged. This License gives no
|
||||||
|
permission to license the work in any other way, but it does not
|
||||||
|
invalidate such permission if you have separately received it.
|
||||||
|
.
|
||||||
|
d) If the work has interactive user interfaces, each must display
|
||||||
|
Appropriate Legal Notices; however, if the Program has interactive
|
||||||
|
interfaces that do not display Appropriate Legal Notices, your
|
||||||
|
work need not make them do so.
|
||||||
|
.
|
||||||
|
A compilation of a covered work with other separate and independent
|
||||||
|
works, which are not by their nature extensions of the covered work,
|
||||||
|
and which are not combined with it such as to form a larger program,
|
||||||
|
in or on a volume of a storage or distribution medium, is called an
|
||||||
|
"aggregate" if the compilation and its resulting copyright are not
|
||||||
|
used to limit the access or legal rights of the compilation's users
|
||||||
|
beyond what the individual works permit. Inclusion of a covered work
|
||||||
|
in an aggregate does not cause this License to apply to the other
|
||||||
|
parts of the aggregate.
|
||||||
|
.
|
||||||
|
6. Conveying Non-Source Forms.
|
||||||
|
.
|
||||||
|
You may convey a covered work in object code form under the terms
|
||||||
|
of sections 4 and 5, provided that you also convey the
|
||||||
|
machine-readable Corresponding Source under the terms of this License,
|
||||||
|
in one of these ways:
|
||||||
|
.
|
||||||
|
a) Convey the object code in, or embodied in, a physical product
|
||||||
|
(including a physical distribution medium), accompanied by the
|
||||||
|
Corresponding Source fixed on a durable physical medium
|
||||||
|
customarily used for software interchange.
|
||||||
|
.
|
||||||
|
b) Convey the object code in, or embodied in, a physical product
|
||||||
|
(including a physical distribution medium), accompanied by a
|
||||||
|
written offer, valid for at least three years and valid for as
|
||||||
|
long as you offer spare parts or customer support for that product
|
||||||
|
model, to give anyone who possesses the object code either (1) a
|
||||||
|
copy of the Corresponding Source for all the software in the
|
||||||
|
product that is covered by this License, on a durable physical
|
||||||
|
medium customarily used for software interchange, for a price no
|
||||||
|
more than your reasonable cost of physically performing this
|
||||||
|
conveying of source, or (2) access to copy the
|
||||||
|
Corresponding Source from a network server at no charge.
|
||||||
|
.
|
||||||
|
c) Convey individual copies of the object code with a copy of the
|
||||||
|
written offer to provide the Corresponding Source. This
|
||||||
|
alternative is allowed only occasionally and noncommercially, and
|
||||||
|
only if you received the object code with such an offer, in accord
|
||||||
|
with subsection 6b.
|
||||||
|
.
|
||||||
|
d) Convey the object code by offering access from a designated
|
||||||
|
place (gratis or for a charge), and offer equivalent access to the
|
||||||
|
Corresponding Source in the same way through the same place at no
|
||||||
|
further charge. You need not require recipients to copy the
|
||||||
|
Corresponding Source along with the object code. If the place to
|
||||||
|
copy the object code is a network server, the Corresponding Source
|
||||||
|
may be on a different server (operated by you or a third party)
|
||||||
|
that supports equivalent copying facilities, provided you maintain
|
||||||
|
clear directions next to the object code saying where to find the
|
||||||
|
Corresponding Source. Regardless of what server hosts the
|
||||||
|
Corresponding Source, you remain obligated to ensure that it is
|
||||||
|
available for as long as needed to satisfy these requirements.
|
||||||
|
.
|
||||||
|
e) Convey the object code using peer-to-peer transmission, provided
|
||||||
|
you inform other peers where the object code and Corresponding
|
||||||
|
Source of the work are being offered to the general public at no
|
||||||
|
charge under subsection 6d.
|
||||||
|
.
|
||||||
|
A separable portion of the object code, whose source code is excluded
|
||||||
|
from the Corresponding Source as a System Library, need not be
|
||||||
|
included in conveying the object code work.
|
||||||
|
.
|
||||||
|
A "User Product" is either (1) a "consumer product", which means any
|
||||||
|
tangible personal property which is normally used for personal, family,
|
||||||
|
or household purposes, or (2) anything designed or sold for incorporation
|
||||||
|
into a dwelling. In determining whether a product is a consumer product,
|
||||||
|
doubtful cases shall be resolved in favor of coverage. For a particular
|
||||||
|
product received by a particular user, "normally used" refers to a
|
||||||
|
typical or common use of that class of product, regardless of the status
|
||||||
|
of the particular user or of the way in which the particular user
|
||||||
|
actually uses, or expects or is expected to use, the product. A product
|
||||||
|
is a consumer product regardless of whether the product has substantial
|
||||||
|
commercial, industrial or non-consumer uses, unless such uses represent
|
||||||
|
the only significant mode of use of the product.
|
||||||
|
.
|
||||||
|
"Installation Information" for a User Product means any methods,
|
||||||
|
procedures, authorization keys, or other information required to install
|
||||||
|
and execute modified versions of a covered work in that User Product from
|
||||||
|
a modified version of its Corresponding Source. The information must
|
||||||
|
suffice to ensure that the continued functioning of the modified object
|
||||||
|
code is in no case prevented or interfered with solely because
|
||||||
|
modification has been made.
|
||||||
|
.
|
||||||
|
If you convey an object code work under this section in, or with, or
|
||||||
|
specifically for use in, a User Product, and the conveying occurs as
|
||||||
|
part of a transaction in which the right of possession and use of the
|
||||||
|
User Product is transferred to the recipient in perpetuity or for a
|
||||||
|
fixed term (regardless of how the transaction is characterized), the
|
||||||
|
Corresponding Source conveyed under this section must be accompanied
|
||||||
|
by the Installation Information. But this requirement does not apply
|
||||||
|
if neither you nor any third party retains the ability to install
|
||||||
|
modified object code on the User Product (for example, the work has
|
||||||
|
been installed in ROM).
|
||||||
|
.
|
||||||
|
The requirement to provide Installation Information does not include a
|
||||||
|
requirement to continue to provide support service, warranty, or updates
|
||||||
|
for a work that has been modified or installed by the recipient, or for
|
||||||
|
the User Product in which it has been modified or installed. Access to a
|
||||||
|
network may be denied when the modification itself materially and
|
||||||
|
adversely affects the operation of the network or violates the rules and
|
||||||
|
protocols for communication across the network.
|
||||||
|
.
|
||||||
|
Corresponding Source conveyed, and Installation Information provided,
|
||||||
|
in accord with this section must be in a format that is publicly
|
||||||
|
documented (and with an implementation available to the public in
|
||||||
|
source code form), and must require no special password or key for
|
||||||
|
unpacking, reading or copying.
|
||||||
|
.
|
||||||
|
7. Additional Terms.
|
||||||
|
.
|
||||||
|
"Additional permissions" are terms that supplement the terms of this
|
||||||
|
License by making exceptions from one or more of its conditions.
|
||||||
|
Additional permissions that are applicable to the entire Program shall
|
||||||
|
be treated as though they were included in this License, to the extent
|
||||||
|
that they are valid under applicable law. If additional permissions
|
||||||
|
apply only to part of the Program, that part may be used separately
|
||||||
|
under those permissions, but the entire Program remains governed by
|
||||||
|
this License without regard to the additional permissions.
|
||||||
|
.
|
||||||
|
When you convey a copy of a covered work, you may at your option
|
||||||
|
remove any additional permissions from that copy, or from any part of
|
||||||
|
it. (Additional permissions may be written to require their own
|
||||||
|
removal in certain cases when you modify the work.) You may place
|
||||||
|
additional permissions on material, added by you to a covered work,
|
||||||
|
for which you have or can give appropriate copyright permission.
|
||||||
|
.
|
||||||
|
Notwithstanding any other provision of this License, for material you
|
||||||
|
add to a covered work, you may (if authorized by the copyright holders of
|
||||||
|
that material) supplement the terms of this License with terms:
|
||||||
|
.
|
||||||
|
a) Disclaiming warranty or limiting liability differently from the
|
||||||
|
terms of sections 15 and 16 of this License; or
|
||||||
|
.
|
||||||
|
b) Requiring preservation of specified reasonable legal notices or
|
||||||
|
author attributions in that material or in the Appropriate Legal
|
||||||
|
Notices displayed by works containing it; or
|
||||||
|
.
|
||||||
|
c) Prohibiting misrepresentation of the origin of that material, or
|
||||||
|
requiring that modified versions of such material be marked in
|
||||||
|
reasonable ways as different from the original version; or
|
||||||
|
.
|
||||||
|
d) Limiting the use for publicity purposes of names of licensors or
|
||||||
|
authors of the material; or
|
||||||
|
.
|
||||||
|
e) Declining to grant rights under trademark law for use of some
|
||||||
|
trade names, trademarks, or service marks; or
|
||||||
|
.
|
||||||
|
f) Requiring indemnification of licensors and authors of that
|
||||||
|
material by anyone who conveys the material (or modified versions of
|
||||||
|
it) with contractual assumptions of liability to the recipient, for
|
||||||
|
any liability that these contractual assumptions directly impose on
|
||||||
|
those licensors and authors.
|
||||||
|
.
|
||||||
|
All other non-permissive additional terms are considered "further
|
||||||
|
restrictions" within the meaning of section 10. If the Program as you
|
||||||
|
received it, or any part of it, contains a notice stating that it is
|
||||||
|
governed by this License along with a term that is a further
|
||||||
|
restriction, you may remove that term. If a license document contains
|
||||||
|
a further restriction but permits relicensing or conveying under this
|
||||||
|
License, you may add to a covered work material governed by the terms
|
||||||
|
of that license document, provided that the further restriction does
|
||||||
|
not survive such relicensing or conveying.
|
||||||
|
.
|
||||||
|
If you add terms to a covered work in accord with this section, you
|
||||||
|
must place, in the relevant source files, a statement of the
|
||||||
|
additional terms that apply to those files, or a notice indicating
|
||||||
|
where to find the applicable terms.
|
||||||
|
.
|
||||||
|
Additional terms, permissive or non-permissive, may be stated in the
|
||||||
|
form of a separately written license, or stated as exceptions;
|
||||||
|
the above requirements apply either way.
|
||||||
|
.
|
||||||
|
8. Termination.
|
||||||
|
.
|
||||||
|
You may not propagate or modify a covered work except as expressly
|
||||||
|
provided under this License. Any attempt otherwise to propagate or
|
||||||
|
modify it is void, and will automatically terminate your rights under
|
||||||
|
this License (including any patent licenses granted under the third
|
||||||
|
paragraph of section 11).
|
||||||
|
.
|
||||||
|
However, if you cease all violation of this License, then your
|
||||||
|
license from a particular copyright holder is reinstated (a)
|
||||||
|
provisionally, unless and until the copyright holder explicitly and
|
||||||
|
finally terminates your license, and (b) permanently, if the copyright
|
||||||
|
holder fails to notify you of the violation by some reasonable means
|
||||||
|
prior to 60 days after the cessation.
|
||||||
|
.
|
||||||
|
Moreover, your license from a particular copyright holder is
|
||||||
|
reinstated permanently if the copyright holder notifies you of the
|
||||||
|
violation by some reasonable means, this is the first time you have
|
||||||
|
received notice of violation of this License (for any work) from that
|
||||||
|
copyright holder, and you cure the violation prior to 30 days after
|
||||||
|
your receipt of the notice.
|
||||||
|
.
|
||||||
|
Termination of your rights under this section does not terminate the
|
||||||
|
licenses of parties who have received copies or rights from you under
|
||||||
|
this License. If your rights have been terminated and not permanently
|
||||||
|
reinstated, you do not qualify to receive new licenses for the same
|
||||||
|
material under section 10.
|
||||||
|
.
|
||||||
|
9. Acceptance Not Required for Having Copies.
|
||||||
|
.
|
||||||
|
You are not required to accept this License in order to receive or
|
||||||
|
run a copy of the Program. Ancillary propagation of a covered work
|
||||||
|
occurring solely as a consequence of using peer-to-peer transmission
|
||||||
|
to receive a copy likewise does not require acceptance. However,
|
||||||
|
nothing other than this License grants you permission to propagate or
|
||||||
|
modify any covered work. These actions infringe copyright if you do
|
||||||
|
not accept this License. Therefore, by modifying or propagating a
|
||||||
|
covered work, you indicate your acceptance of this License to do so.
|
||||||
|
.
|
||||||
|
10. Automatic Licensing of Downstream Recipients.
|
||||||
|
.
|
||||||
|
Each time you convey a covered work, the recipient automatically
|
||||||
|
receives a license from the original licensors, to run, modify and
|
||||||
|
propagate that work, subject to this License. You are not responsible
|
||||||
|
for enforcing compliance by third parties with this License.
|
||||||
|
.
|
||||||
|
An "entity transaction" is a transaction transferring control of an
|
||||||
|
organization, or substantially all assets of one, or subdividing an
|
||||||
|
organization, or merging organizations. If propagation of a covered
|
||||||
|
work results from an entity transaction, each party to that
|
||||||
|
transaction who receives a copy of the work also receives whatever
|
||||||
|
licenses to the work the party's predecessor in interest had or could
|
||||||
|
give under the previous paragraph, plus a right to possession of the
|
||||||
|
Corresponding Source of the work from the predecessor in interest, if
|
||||||
|
the predecessor has it or can get it with reasonable efforts.
|
||||||
|
.
|
||||||
|
You may not impose any further restrictions on the exercise of the
|
||||||
|
rights granted or affirmed under this License. For example, you may
|
||||||
|
not impose a license fee, royalty, or other charge for exercise of
|
||||||
|
rights granted under this License, and you may not initiate litigation
|
||||||
|
(including a cross-claim or counterclaim in a lawsuit) alleging that
|
||||||
|
any patent claim is infringed by making, using, selling, offering for
|
||||||
|
sale, or importing the Program or any portion of it.
|
||||||
|
.
|
||||||
|
11. Patents.
|
||||||
|
.
|
||||||
|
A "contributor" is a copyright holder who authorizes use under this
|
||||||
|
License of the Program or a work on which the Program is based. The
|
||||||
|
work thus licensed is called the contributor's "contributor version".
|
||||||
|
.
|
||||||
|
A contributor's "essential patent claims" are all patent claims
|
||||||
|
owned or controlled by the contributor, whether already acquired or
|
||||||
|
hereafter acquired, that would be infringed by some manner, permitted
|
||||||
|
by this License, of making, using, or selling its contributor version,
|
||||||
|
but do not include claims that would be infringed only as a
|
||||||
|
consequence of further modification of the contributor version. For
|
||||||
|
purposes of this definition, "control" includes the right to grant
|
||||||
|
patent sublicenses in a manner consistent with the requirements of
|
||||||
|
this License.
|
||||||
|
.
|
||||||
|
Each contributor grants you a non-exclusive, worldwide, royalty-free
|
||||||
|
patent license under the contributor's essential patent claims, to
|
||||||
|
make, use, sell, offer for sale, import and otherwise run, modify and
|
||||||
|
propagate the contents of its contributor version.
|
||||||
|
.
|
||||||
|
In the following three paragraphs, a "patent license" is any express
|
||||||
|
agreement or commitment, however denominated, not to enforce a patent
|
||||||
|
(such as an express permission to practice a patent or covenant not to
|
||||||
|
sue for patent infringement). To "grant" such a patent license to a
|
||||||
|
party means to make such an agreement or commitment not to enforce a
|
||||||
|
patent against the party.
|
||||||
|
.
|
||||||
|
If you convey a covered work, knowingly relying on a patent license,
|
||||||
|
and the Corresponding Source of the work is not available for anyone
|
||||||
|
to copy, free of charge and under the terms of this License, through a
|
||||||
|
publicly available network server or other readily accessible means,
|
||||||
|
then you must either (1) cause the Corresponding Source to be so
|
||||||
|
available, or (2) arrange to deprive yourself of the benefit of the
|
||||||
|
patent license for this particular work, or (3) arrange, in a manner
|
||||||
|
consistent with the requirements of this License, to extend the patent
|
||||||
|
license to downstream recipients. "Knowingly relying" means you have
|
||||||
|
actual knowledge that, but for the patent license, your conveying the
|
||||||
|
covered work in a country, or your recipient's use of the covered work
|
||||||
|
in a country, would infringe one or more identifiable patents in that
|
||||||
|
country that you have reason to believe are valid.
|
||||||
|
.
|
||||||
|
If, pursuant to or in connection with a single transaction or
|
||||||
|
arrangement, you convey, or propagate by procuring conveyance of, a
|
||||||
|
covered work, and grant a patent license to some of the parties
|
||||||
|
receiving the covered work authorizing them to use, propagate, modify
|
||||||
|
or convey a specific copy of the covered work, then the patent license
|
||||||
|
you grant is automatically extended to all recipients of the covered
|
||||||
|
work and works based on it.
|
||||||
|
.
|
||||||
|
A patent license is "discriminatory" if it does not include within
|
||||||
|
the scope of its coverage, prohibits the exercise of, or is
|
||||||
|
conditioned on the non-exercise of one or more of the rights that are
|
||||||
|
specifically granted under this License. You may not convey a covered
|
||||||
|
work if you are a party to an arrangement with a third party that is
|
||||||
|
in the business of distributing software, under which you make payment
|
||||||
|
to the third party based on the extent of your activity of conveying
|
||||||
|
the work, and under which the third party grants, to any of the
|
||||||
|
parties who would receive the covered work from you, a discriminatory
|
||||||
|
patent license (a) in connection with copies of the covered work
|
||||||
|
conveyed by you (or copies made from those copies), or (b) primarily
|
||||||
|
for and in connection with specific products or compilations that
|
||||||
|
contain the covered work, unless you entered into that arrangement,
|
||||||
|
or that patent license was granted, prior to 28 March 2007.
|
||||||
|
.
|
||||||
|
Nothing in this License shall be construed as excluding or limiting
|
||||||
|
any implied license or other defenses to infringement that may
|
||||||
|
otherwise be available to you under applicable patent law.
|
||||||
|
.
|
||||||
|
12. No Surrender of Others' Freedom.
|
||||||
|
.
|
||||||
|
If conditions are imposed on you (whether by court order, agreement or
|
||||||
|
otherwise) that contradict the conditions of this License, they do not
|
||||||
|
excuse you from the conditions of this License. If you cannot convey a
|
||||||
|
covered work so as to satisfy simultaneously your obligations under this
|
||||||
|
License and any other pertinent obligations, then as a consequence you may
|
||||||
|
not convey it at all. For example, if you agree to terms that obligate you
|
||||||
|
to collect a royalty for further conveying from those to whom you convey
|
||||||
|
the Program, the only way you could satisfy both those terms and this
|
||||||
|
License would be to refrain entirely from conveying the Program.
|
||||||
|
.
|
||||||
|
13. Remote Network Interaction; Use with the GNU General Public License.
|
||||||
|
.
|
||||||
|
Notwithstanding any other provision of this License, if you modify the
|
||||||
|
Program, your modified version must prominently offer all users
|
||||||
|
interacting with it remotely through a computer network (if your version
|
||||||
|
supports such interaction) an opportunity to receive the Corresponding
|
||||||
|
Source of your version by providing access to the Corresponding Source
|
||||||
|
from a network server at no charge, through some standard or customary
|
||||||
|
means of facilitating copying of software. This Corresponding Source
|
||||||
|
shall include the Corresponding Source for any work covered by version 3
|
||||||
|
of the GNU General Public License that is incorporated pursuant to the
|
||||||
|
following paragraph.
|
||||||
|
.
|
||||||
|
Notwithstanding any other provision of this License, you have
|
||||||
|
permission to link or combine any covered work with a work licensed
|
||||||
|
under version 3 of the GNU General Public License into a single
|
||||||
|
combined work, and to convey the resulting work. The terms of this
|
||||||
|
License will continue to apply to the part which is the covered work,
|
||||||
|
but the work with which it is combined will remain governed by version
|
||||||
|
3 of the GNU General Public License.
|
||||||
|
.
|
||||||
|
14. Revised Versions of this License.
|
||||||
|
.
|
||||||
|
The Free Software Foundation may publish revised and/or new versions of
|
||||||
|
the GNU Affero General Public License from time to time. Such new versions
|
||||||
|
will be similar in spirit to the present version, but may differ in detail to
|
||||||
|
address new problems or concerns.
|
||||||
|
.
|
||||||
|
Each version is given a distinguishing version number. If the
|
||||||
|
Program specifies that a certain numbered version of the GNU Affero General
|
||||||
|
Public License "or any later version" applies to it, you have the
|
||||||
|
option of following the terms and conditions either of that numbered
|
||||||
|
version or of any later version published by the Free Software
|
||||||
|
Foundation. If the Program does not specify a version number of the
|
||||||
|
GNU Affero General Public License, you may choose any version ever published
|
||||||
|
by the Free Software Foundation.
|
||||||
|
.
|
||||||
|
If the Program specifies that a proxy can decide which future
|
||||||
|
versions of the GNU Affero General Public License can be used, that proxy's
|
||||||
|
public statement of acceptance of a version permanently authorizes you
|
||||||
|
to choose that version for the Program.
|
||||||
|
.
|
||||||
|
Later license versions may give you additional or different
|
||||||
|
permissions. However, no additional obligations are imposed on any
|
||||||
|
author or copyright holder as a result of your choosing to follow a
|
||||||
|
later version.
|
||||||
|
.
|
||||||
|
15. Disclaimer of Warranty.
|
||||||
|
.
|
||||||
|
THERE IS NO WARRANTY FOR THE PROGRAM, TO THE EXTENT PERMITTED BY
|
||||||
|
APPLICABLE LAW. EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT
|
||||||
|
HOLDERS AND/OR OTHER PARTIES PROVIDE THE PROGRAM "AS IS" WITHOUT WARRANTY
|
||||||
|
OF ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO,
|
||||||
|
THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
|
||||||
|
PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE OF THE PROGRAM
|
||||||
|
IS WITH YOU. SHOULD THE PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF
|
||||||
|
ALL NECESSARY SERVICING, REPAIR OR CORRECTION.
|
||||||
|
.
|
||||||
|
16. Limitation of Liability.
|
||||||
|
.
|
||||||
|
IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING
|
||||||
|
WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MODIFIES AND/OR CONVEYS
|
||||||
|
THE PROGRAM AS PERMITTED ABOVE, BE LIABLE TO YOU FOR DAMAGES, INCLUDING ANY
|
||||||
|
GENERAL, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES ARISING OUT OF THE
|
||||||
|
USE OR INABILITY TO USE THE PROGRAM (INCLUDING BUT NOT LIMITED TO LOSS OF
|
||||||
|
DATA OR DATA BEING RENDERED INACCURATE OR LOSSES SUSTAINED BY YOU OR THIRD
|
||||||
|
PARTIES OR A FAILURE OF THE PROGRAM TO OPERATE WITH ANY OTHER PROGRAMS),
|
||||||
|
EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF
|
||||||
|
SUCH DAMAGES.
|
||||||
|
.
|
||||||
|
17. Interpretation of Sections 15 and 16.
|
||||||
|
.
|
||||||
|
If the disclaimer of warranty and limitation of liability provided
|
||||||
|
above cannot be given local legal effect according to their terms,
|
||||||
|
reviewing courts shall apply local law that most closely approximates
|
||||||
|
an absolute waiver of all civil liability in connection with the
|
||||||
|
Program, unless a warranty or assumption of liability accompanies a
|
||||||
|
copy of the Program in return for a fee.
|
||||||
|
.
|
||||||
|
END OF TERMS AND CONDITIONS
|
||||||
|
.
|
||||||
|
How to Apply These Terms to Your New Programs
|
||||||
|
.
|
||||||
|
If you develop a new program, and you want it to be of the greatest
|
||||||
|
possible use to the public, the best way to achieve this is to make it
|
||||||
|
free software which everyone can redistribute and change under these terms.
|
||||||
|
.
|
||||||
|
To do so, attach the following notices to the program. It is safest
|
||||||
|
to attach them to the start of each source file to most effectively
|
||||||
|
state the exclusion of warranty; and each file should have at least
|
||||||
|
the "copyright" line and a pointer to where the full notice is found.
|
||||||
|
.
|
||||||
|
<one line to give the program's name and a brief idea of what it does.>
|
||||||
|
Copyright (C) <year> <name of author>
|
||||||
|
.
|
||||||
|
This program is free software: you can redistribute it and/or modify
|
||||||
|
it under the terms of the GNU Affero General Public License as published by
|
||||||
|
the Free Software Foundation, either version 3 of the License, or
|
||||||
|
(at your option) any later version.
|
||||||
|
.
|
||||||
|
This program is distributed in the hope that it will be useful,
|
||||||
|
but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||||
|
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||||
|
GNU Affero General Public License for more details.
|
||||||
|
.
|
||||||
|
You should have received a copy of the GNU Affero General Public License
|
||||||
|
along with this program. If not, see <http://www.gnu.org/licenses/>.
|
||||||
|
.
|
||||||
|
Also add information on how to contact you by electronic and paper mail.
|
||||||
|
.
|
||||||
|
If your software can interact with users remotely through a computer
|
||||||
|
network, you should also make sure that it provides a way for users to
|
||||||
|
get its source. For example, if your program is a web application, its
|
||||||
|
interface could display a "Source" link that leads users to an archive
|
||||||
|
of the code. There are many ways you could offer source, and different
|
||||||
|
solutions will be better for different programs; see section 13 for the
|
||||||
|
specific requirements.
|
||||||
|
.
|
||||||
|
You should also get your employer (if you work as a programmer) or school,
|
||||||
|
if any, to sign a "copyright disclaimer" for the program, if necessary.
|
||||||
|
For more information on this, and how to apply and follow the GNU AGPL, see
|
||||||
|
<http://www.gnu.org/licenses/>.
|
||||||
6
debian/rules
vendored
Executable file
6
debian/rules
vendored
Executable file
@@ -0,0 +1,6 @@
|
|||||||
|
#!/usr/bin/make -f
|
||||||
|
%:
|
||||||
|
dh $@
|
||||||
|
|
||||||
|
override_dh_builddeb:
|
||||||
|
dh_builddeb -- -Zgzip
|
||||||
2
debian/rustdesk-server-hbbr.install
vendored
Normal file
2
debian/rustdesk-server-hbbr.install
vendored
Normal file
@@ -0,0 +1,2 @@
|
|||||||
|
bin/hbbr usr/bin
|
||||||
|
systemd/rustdesk-hbbr.service lib/systemd/system
|
||||||
24
debian/rustdesk-server-hbbr.postinst
vendored
Normal file
24
debian/rustdesk-server-hbbr.postinst
vendored
Normal file
@@ -0,0 +1,24 @@
|
|||||||
|
#!/bin/sh
|
||||||
|
set -e
|
||||||
|
|
||||||
|
SERVICE=rustdesk-hbbr.service
|
||||||
|
|
||||||
|
case "$1" in
|
||||||
|
configure|abort-upgrade|abort-deconfigure|abort-remove)
|
||||||
|
mkdir -p /var/lib/rustdesk-server/
|
||||||
|
deb-systemd-helper unmask "${SERVICE}" >/dev/null || true
|
||||||
|
if deb-systemd-helper --quiet was-enabled "${SERVICE}"; then
|
||||||
|
deb-systemd-invoke enable "${SERVICE}" >/dev/null || true
|
||||||
|
else
|
||||||
|
deb-systemd-invoke update-state "${SERVICE}" >/dev/null || true
|
||||||
|
fi
|
||||||
|
systemctl --system daemon-reload >/dev/null || true
|
||||||
|
if [ -n "$2" ]; then
|
||||||
|
deb-systemd-invoke restart "${SERVICE}" >/dev/null || true
|
||||||
|
else
|
||||||
|
deb-systemd-invoke start "${SERVICE}" >/dev/null || true
|
||||||
|
fi
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
|
||||||
|
exit 0
|
||||||
18
debian/rustdesk-server-hbbr.postrm
vendored
Normal file
18
debian/rustdesk-server-hbbr.postrm
vendored
Normal file
@@ -0,0 +1,18 @@
|
|||||||
|
#!/bin/sh
|
||||||
|
set -e
|
||||||
|
|
||||||
|
SERVICE=rustdesk-hbbr.service
|
||||||
|
|
||||||
|
systemctl --system daemon-reload >/dev/null || true
|
||||||
|
|
||||||
|
if [ "$1" = "purge" ]; then
|
||||||
|
rm -rf /var/lib/rustdesk-server/
|
||||||
|
deb-systemd-helper purge "${SERVICE}" >/dev/null || true
|
||||||
|
deb-systemd-helper unmask "${SERVICE}" >/dev/null || true
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [ "$1" = "remove" ]; then
|
||||||
|
deb-systemd-helper mask "${SERVICE}" >/dev/null || true
|
||||||
|
fi
|
||||||
|
|
||||||
|
exit 0
|
||||||
13
debian/rustdesk-server-hbbr.prerm
vendored
Normal file
13
debian/rustdesk-server-hbbr.prerm
vendored
Normal file
@@ -0,0 +1,13 @@
|
|||||||
|
#!/bin/sh
|
||||||
|
set -e
|
||||||
|
|
||||||
|
SERVICE=rustdesk-hbbr.service
|
||||||
|
|
||||||
|
case "$1" in
|
||||||
|
remove|deconfigure)
|
||||||
|
deb-systemd-invoke stop "${SERVICE}" >/dev/null || true
|
||||||
|
deb-systemd-invoke disable "${SERVICE}" >/dev/null || true
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
|
||||||
|
exit 0
|
||||||
2
debian/rustdesk-server-hbbs.install
vendored
Normal file
2
debian/rustdesk-server-hbbs.install
vendored
Normal file
@@ -0,0 +1,2 @@
|
|||||||
|
bin/hbbs usr/bin
|
||||||
|
systemd/rustdesk-hbbs.service lib/systemd/system
|
||||||
24
debian/rustdesk-server-hbbs.postinst
vendored
Normal file
24
debian/rustdesk-server-hbbs.postinst
vendored
Normal file
@@ -0,0 +1,24 @@
|
|||||||
|
#!/bin/sh
|
||||||
|
set -e
|
||||||
|
|
||||||
|
SERVICE=rustdesk-hbbs.service
|
||||||
|
|
||||||
|
case "$1" in
|
||||||
|
configure|abort-upgrade|abort-deconfigure|abort-remove)
|
||||||
|
mkdir -p /var/lib/rustdesk-server/
|
||||||
|
deb-systemd-helper unmask "${SERVICE}" >/dev/null || true
|
||||||
|
if deb-systemd-helper --quiet was-enabled "${SERVICE}"; then
|
||||||
|
deb-systemd-invoke enable "${SERVICE}" >/dev/null || true
|
||||||
|
else
|
||||||
|
deb-systemd-invoke update-state "${SERVICE}" >/dev/null || true
|
||||||
|
fi
|
||||||
|
systemctl --system daemon-reload >/dev/null || true
|
||||||
|
if [ -n "$2" ]; then
|
||||||
|
deb-systemd-invoke restart "${SERVICE}" >/dev/null || true
|
||||||
|
else
|
||||||
|
deb-systemd-invoke start "${SERVICE}" >/dev/null || true
|
||||||
|
fi
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
|
||||||
|
exit 0
|
||||||
18
debian/rustdesk-server-hbbs.postrm
vendored
Normal file
18
debian/rustdesk-server-hbbs.postrm
vendored
Normal file
@@ -0,0 +1,18 @@
|
|||||||
|
#!/bin/sh
|
||||||
|
set -e
|
||||||
|
|
||||||
|
SERVICE=rustdesk-hbbs.service
|
||||||
|
|
||||||
|
systemctl --system daemon-reload >/dev/null || true
|
||||||
|
|
||||||
|
if [ "$1" = "purge" ]; then
|
||||||
|
rm -rf /var/lib/rustdesk-server/
|
||||||
|
deb-systemd-helper purge "${SERVICE}" >/dev/null || true
|
||||||
|
deb-systemd-helper unmask "${SERVICE}" >/dev/null || true
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [ "$1" = "remove" ]; then
|
||||||
|
deb-systemd-helper mask "${SERVICE}" >/dev/null || true
|
||||||
|
fi
|
||||||
|
|
||||||
|
exit 0
|
||||||
13
debian/rustdesk-server-hbbs.prerm
vendored
Normal file
13
debian/rustdesk-server-hbbs.prerm
vendored
Normal file
@@ -0,0 +1,13 @@
|
|||||||
|
#!/bin/sh
|
||||||
|
set -e
|
||||||
|
|
||||||
|
SERVICE=rustdesk-hbbs.service
|
||||||
|
|
||||||
|
case "$1" in
|
||||||
|
remove|deconfigure)
|
||||||
|
deb-systemd-invoke stop "${SERVICE}" >/dev/null || true
|
||||||
|
deb-systemd-invoke disable "${SERVICE}" >/dev/null || true
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
|
||||||
|
exit 0
|
||||||
1
debian/rustdesk-server-utils.install
vendored
Normal file
1
debian/rustdesk-server-utils.install
vendored
Normal file
@@ -0,0 +1 @@
|
|||||||
|
bin/rustdesk-utils usr/bin
|
||||||
1
debian/source/format
vendored
Normal file
1
debian/source/format
vendored
Normal file
@@ -0,0 +1 @@
|
|||||||
|
3.0 (native)
|
||||||
@@ -15,7 +15,7 @@ services:
|
|||||||
image: rustdesk/rustdesk-server:latest
|
image: rustdesk/rustdesk-server:latest
|
||||||
command: hbbs -r rustdesk.example.com:21117
|
command: hbbs -r rustdesk.example.com:21117
|
||||||
volumes:
|
volumes:
|
||||||
- ./hbbs:/root
|
- ./data:/root
|
||||||
networks:
|
networks:
|
||||||
- rustdesk-net
|
- rustdesk-net
|
||||||
depends_on:
|
depends_on:
|
||||||
@@ -30,7 +30,7 @@ services:
|
|||||||
image: rustdesk/rustdesk-server:latest
|
image: rustdesk/rustdesk-server:latest
|
||||||
command: hbbr
|
command: hbbr
|
||||||
volumes:
|
volumes:
|
||||||
- ./hbbr:/root
|
- ./data:/root
|
||||||
networks:
|
networks:
|
||||||
- rustdesk-net
|
- rustdesk-net
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
|
|||||||
@@ -7,7 +7,8 @@ ADD https://github.com/just-containers/s6-overlay/releases/download/v${S6_OVERLA
|
|||||||
RUN \
|
RUN \
|
||||||
tar -C / -Jxpf /tmp/s6-overlay-noarch.tar.xz && \
|
tar -C / -Jxpf /tmp/s6-overlay-noarch.tar.xz && \
|
||||||
tar -C / -Jxpf /tmp/s6-overlay-${S6_ARCH}.tar.xz && \
|
tar -C / -Jxpf /tmp/s6-overlay-${S6_ARCH}.tar.xz && \
|
||||||
rm /tmp/s6-overlay*.tar.xz
|
rm /tmp/s6-overlay*.tar.xz && \
|
||||||
|
ln -s /run /var/run
|
||||||
|
|
||||||
COPY rootfs /
|
COPY rootfs /
|
||||||
|
|
||||||
|
|||||||
1
docker/rootfs/etc/s6-overlay/s6-rc.d/hbbr/dependencies
Normal file
1
docker/rootfs/etc/s6-overlay/s6-rc.d/hbbr/dependencies
Normal file
@@ -0,0 +1 @@
|
|||||||
|
key-secret
|
||||||
@@ -1 +1,2 @@
|
|||||||
|
key-secret
|
||||||
hbbr
|
hbbr
|
||||||
|
|||||||
1
docker/rootfs/etc/s6-overlay/s6-rc.d/key-secret/type
Executable file
1
docker/rootfs/etc/s6-overlay/s6-rc.d/key-secret/type
Executable file
@@ -0,0 +1 @@
|
|||||||
|
oneshot
|
||||||
1
docker/rootfs/etc/s6-overlay/s6-rc.d/key-secret/up
Executable file
1
docker/rootfs/etc/s6-overlay/s6-rc.d/key-secret/up
Executable file
@@ -0,0 +1 @@
|
|||||||
|
/etc/s6-overlay/s6-rc.d/key-secret/up.real
|
||||||
58
docker/rootfs/etc/s6-overlay/s6-rc.d/key-secret/up.real
Executable file
58
docker/rootfs/etc/s6-overlay/s6-rc.d/key-secret/up.real
Executable file
@@ -0,0 +1,58 @@
|
|||||||
|
#!/command/with-contenv sh
|
||||||
|
|
||||||
|
if [ ! -d /data ] ; then
|
||||||
|
mkdir /data
|
||||||
|
fi
|
||||||
|
|
||||||
|
# normal docker secrets
|
||||||
|
if [ ! -f /data/id_ed25519.pub ] && [ -r /run/secrets/key_pub ] ; then
|
||||||
|
cp /run/secrets/key_pub /data/id_ed25519.pub
|
||||||
|
echo "Public key created from secret"
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [ ! -f /data/id_ed25519 ] && [ -r /run/secrets/key_priv ] ; then
|
||||||
|
cp /run/secrets/key_priv /data/id_ed25519
|
||||||
|
echo "Private key created from secret"
|
||||||
|
fi
|
||||||
|
|
||||||
|
# ENV variables
|
||||||
|
if [ ! -f /data/id_ed25519.pub ] && [ ! "$KEY_PUB" = "" ] ; then
|
||||||
|
echo -n "$KEY_PUB" > /data/id_ed25519.pub
|
||||||
|
echo "Public key created from ENV variable"
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [ ! -f /data/id_ed25519 ] && [ ! "$KEY_PRIV" = "" ] ; then
|
||||||
|
echo -n "$KEY_PRIV" > /data/id_ed25519
|
||||||
|
echo "Private key created from ENV variable"
|
||||||
|
fi
|
||||||
|
|
||||||
|
# check if both keys provided
|
||||||
|
if [ -f /data/id_ed25519.pub ] && [ ! -f /data/id_ed25519 ] ; then
|
||||||
|
echo "Private key missing."
|
||||||
|
echo "You must provide BOTH the private and the public key."
|
||||||
|
/run/s6/basedir/bin/halt
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [ ! -f /data/id_ed25519.pub ] && [ -f /data/id_ed25519 ] ; then
|
||||||
|
echo "Public key missing."
|
||||||
|
echo "You must provide BOTH the private and the public key."
|
||||||
|
/run/s6/basedir/bin/halt
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
# here we have either no keys or both
|
||||||
|
|
||||||
|
# if we have both keys, we fix permissions and ownership
|
||||||
|
# and check for keypair validation
|
||||||
|
if [ -f /data/id_ed25519.pub ] && [ -f /data/id_ed25519 ] ; then
|
||||||
|
chmod 0600 /data/id_ed25519.pub /data/id_ed25519
|
||||||
|
chown root:root /data/id_ed25519.pub /data/id_ed25519
|
||||||
|
/usr/bin/rustdesk-utils validatekeypair "$(cat /data/id_ed25519.pub)" "$(cat /data/id_ed25519)" || {
|
||||||
|
echo "Key pair not valid"
|
||||||
|
/run/s6/basedir/bin/halt
|
||||||
|
exit 1
|
||||||
|
}
|
||||||
|
fi
|
||||||
|
|
||||||
|
# if we have no keypair, hbbs will generate one
|
||||||
0
docker/rootfs/etc/s6-overlay/s6-rc.d/user/contents.d/key-secret
Executable file
0
docker/rootfs/etc/s6-overlay/s6-rc.d/user/contents.d/key-secret
Executable file
@@ -7,11 +7,11 @@ edition = "2018"
|
|||||||
# See more keys and their definitions at https://doc.rust-lang.org/cargo/reference/manifest.html
|
# See more keys and their definitions at https://doc.rust-lang.org/cargo/reference/manifest.html
|
||||||
|
|
||||||
[dependencies]
|
[dependencies]
|
||||||
protobuf = "3.0.0-alpha.2"
|
protobuf = { version = "3.1", features = ["with-bytes"] }
|
||||||
tokio = { version = "1.15", features = ["full"] }
|
tokio = { version = "1.20", features = ["full"] }
|
||||||
tokio-util = { version = "0.6", features = ["full"] }
|
tokio-util = { version = "0.7", features = ["full"] }
|
||||||
futures = "0.3"
|
futures = "0.3"
|
||||||
bytes = "1.1"
|
bytes = "1.2"
|
||||||
log = "0.4"
|
log = "0.4"
|
||||||
env_logger = "0.9"
|
env_logger = "0.9"
|
||||||
socket2 = { version = "0.3", features = ["reuseport"] }
|
socket2 = { version = "0.3", features = ["reuseport"] }
|
||||||
@@ -38,7 +38,7 @@ mac_address = "1.1"
|
|||||||
quic = []
|
quic = []
|
||||||
|
|
||||||
[build-dependencies]
|
[build-dependencies]
|
||||||
protobuf-codegen-pure = "3.0.0-alpha.2"
|
protobuf-codegen = "3.1"
|
||||||
|
|
||||||
[target.'cfg(target_os = "windows")'.dependencies]
|
[target.'cfg(target_os = "windows")'.dependencies]
|
||||||
winapi = { version = "0.3", features = ["winuser"] }
|
winapi = { version = "0.3", features = ["winuser"] }
|
||||||
|
|||||||
@@ -1,9 +1,14 @@
|
|||||||
fn main() {
|
fn main() {
|
||||||
std::fs::create_dir_all("src/protos").unwrap();
|
std::fs::create_dir_all("src/protos").unwrap();
|
||||||
protobuf_codegen_pure::Codegen::new()
|
protobuf_codegen::Codegen::new()
|
||||||
|
.pure()
|
||||||
.out_dir("src/protos")
|
.out_dir("src/protos")
|
||||||
.inputs(&["protos/rendezvous.proto", "protos/message.proto"])
|
.inputs(&["protos/rendezvous.proto", "protos/message.proto"])
|
||||||
.include("protos")
|
.include("protos")
|
||||||
|
.customize(
|
||||||
|
protobuf_codegen::Customize::default()
|
||||||
|
.tokio_bytes(true)
|
||||||
|
)
|
||||||
.run()
|
.run()
|
||||||
.expect("Codegen failed.");
|
.expect("Codegen failed.");
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -148,6 +148,15 @@ message PeerDiscovery {
|
|||||||
string misc = 7;
|
string misc = 7;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
message OnlineRequest {
|
||||||
|
string id = 1;
|
||||||
|
repeated string peers = 2;
|
||||||
|
}
|
||||||
|
|
||||||
|
message OnlineResponse {
|
||||||
|
bytes states = 1;
|
||||||
|
}
|
||||||
|
|
||||||
message RendezvousMessage {
|
message RendezvousMessage {
|
||||||
oneof union {
|
oneof union {
|
||||||
RegisterPeer register_peer = 6;
|
RegisterPeer register_peer = 6;
|
||||||
@@ -167,5 +176,7 @@ message RendezvousMessage {
|
|||||||
TestNatRequest test_nat_request = 20;
|
TestNatRequest test_nat_request = 20;
|
||||||
TestNatResponse test_nat_response = 21;
|
TestNatResponse test_nat_response = 21;
|
||||||
PeerDiscovery peer_discovery = 22;
|
PeerDiscovery peer_discovery = 22;
|
||||||
|
OnlineRequest online_request = 23;
|
||||||
|
OnlineResponse online_response = 24;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -693,7 +693,7 @@ const PEERS: &str = "peers";
|
|||||||
|
|
||||||
impl PeerConfig {
|
impl PeerConfig {
|
||||||
pub fn load(id: &str) -> PeerConfig {
|
pub fn load(id: &str) -> PeerConfig {
|
||||||
let _ = CONFIG.read().unwrap(); // for lock
|
let _unused = CONFIG.read().unwrap(); // for lock
|
||||||
match confy::load_path(&Self::path(id)) {
|
match confy::load_path(&Self::path(id)) {
|
||||||
Ok(config) => config,
|
Ok(config) => config,
|
||||||
Err(err) => {
|
Err(err) => {
|
||||||
@@ -704,7 +704,7 @@ impl PeerConfig {
|
|||||||
}
|
}
|
||||||
|
|
||||||
pub fn store(&self, id: &str) {
|
pub fn store(&self, id: &str) {
|
||||||
let _ = CONFIG.read().unwrap(); // for lock
|
let _unused = CONFIG.read().unwrap(); // for lock
|
||||||
if let Err(err) = confy::store_path(Self::path(id), self) {
|
if let Err(err) = confy::store_path(Self::path(id), self) {
|
||||||
log::error!("Failed to store config: {}", err);
|
log::error!("Failed to store config: {}", err);
|
||||||
}
|
}
|
||||||
@@ -845,7 +845,7 @@ pub struct LanPeers {
|
|||||||
|
|
||||||
impl LanPeers {
|
impl LanPeers {
|
||||||
pub fn load() -> LanPeers {
|
pub fn load() -> LanPeers {
|
||||||
let _ = CONFIG.read().unwrap(); // for lock
|
let _unused = CONFIG.read().unwrap(); // for lock
|
||||||
match confy::load_path(&Config::file_("_lan_peers")) {
|
match confy::load_path(&Config::file_("_lan_peers")) {
|
||||||
Ok(peers) => peers,
|
Ok(peers) => peers,
|
||||||
Err(err) => {
|
Err(err) => {
|
||||||
|
|||||||
@@ -3,10 +3,9 @@ use hbb_common::{anyhow::Context, log, ResultType};
|
|||||||
use ini::Ini;
|
use ini::Ini;
|
||||||
use sodiumoxide::crypto::sign;
|
use sodiumoxide::crypto::sign;
|
||||||
use std::{
|
use std::{
|
||||||
collections::HashMap,
|
|
||||||
io::prelude::*,
|
io::prelude::*,
|
||||||
io::Read,
|
io::Read,
|
||||||
net::{IpAddr, SocketAddr},
|
net::SocketAddr,
|
||||||
time::{Instant, SystemTime},
|
time::{Instant, SystemTime},
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -119,7 +118,7 @@ pub fn gen_sk(wait: u64) -> (String, Option<sign::SecretKey>) {
|
|||||||
};
|
};
|
||||||
let (mut pk, mut sk) = gen_func();
|
let (mut pk, mut sk) = gen_func();
|
||||||
for _ in 0..300 {
|
for _ in 0..300 {
|
||||||
if !pk.contains("/") {
|
if !pk.contains("/") && !pk.contains(":") {
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
(pk, sk) = gen_func();
|
(pk, sk) = gen_func();
|
||||||
|
|||||||
@@ -8,9 +8,7 @@ use std::{ops::DerefMut, str::FromStr};
|
|||||||
//use sqlx::postgres::PgPoolOptions;
|
//use sqlx::postgres::PgPoolOptions;
|
||||||
//use sqlx::mysql::MySqlPoolOptions;
|
//use sqlx::mysql::MySqlPoolOptions;
|
||||||
|
|
||||||
pub(crate) type DB = sqlx::Sqlite;
|
|
||||||
pub(crate) type MapValue = serde_json::map::Map<String, Value>;
|
pub(crate) type MapValue = serde_json::map::Map<String, Value>;
|
||||||
pub(crate) type MapStr = std::collections::HashMap<String, String>;
|
|
||||||
type Pool = deadpool::managed::Pool<DbPool>;
|
type Pool = deadpool::managed::Pool<DbPool>;
|
||||||
|
|
||||||
pub struct DbPool {
|
pub struct DbPool {
|
||||||
@@ -107,13 +105,6 @@ impl Database {
|
|||||||
.await?)
|
.await?)
|
||||||
}
|
}
|
||||||
|
|
||||||
pub async fn get_peer_id(&self, guid: &[u8]) -> ResultType<Option<String>> {
|
|
||||||
Ok(sqlx::query!("select id from peer where guid = ?", guid)
|
|
||||||
.fetch_optional(self.pool.get().await?.deref_mut())
|
|
||||||
.await?
|
|
||||||
.map(|x| x.id))
|
|
||||||
}
|
|
||||||
|
|
||||||
#[inline]
|
#[inline]
|
||||||
pub async fn get_conn(&self) -> ResultType<deadpool::managed::Object<DbPool>> {
|
pub async fn get_conn(&self) -> ResultType<deadpool::managed::Object<DbPool>> {
|
||||||
Ok(self.pool.get().await?)
|
Ok(self.pool.get().await?)
|
||||||
@@ -135,8 +126,8 @@ impl Database {
|
|||||||
pub async fn insert_peer(
|
pub async fn insert_peer(
|
||||||
&self,
|
&self,
|
||||||
id: &str,
|
id: &str,
|
||||||
uuid: &Vec<u8>,
|
uuid: &[u8],
|
||||||
pk: &Vec<u8>,
|
pk: &[u8],
|
||||||
info: &str,
|
info: &str,
|
||||||
) -> ResultType<Vec<u8>> {
|
) -> ResultType<Vec<u8>> {
|
||||||
let guid = uuid::Uuid::new_v4().as_bytes().to_vec();
|
let guid = uuid::Uuid::new_v4().as_bytes().to_vec();
|
||||||
@@ -157,7 +148,7 @@ impl Database {
|
|||||||
&self,
|
&self,
|
||||||
guid: &Vec<u8>,
|
guid: &Vec<u8>,
|
||||||
id: &str,
|
id: &str,
|
||||||
pk: &Vec<u8>,
|
pk: &[u8],
|
||||||
info: &str,
|
info: &str,
|
||||||
) -> ResultType<()> {
|
) -> ResultType<()> {
|
||||||
sqlx::query!(
|
sqlx::query!(
|
||||||
@@ -209,13 +200,6 @@ mod tests {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
#[inline]
|
|
||||||
pub fn guid2str(guid: &Vec<u8>) -> String {
|
|
||||||
let mut bytes = [0u8; 16];
|
|
||||||
bytes[..].copy_from_slice(&guid);
|
|
||||||
uuid::Uuid::from_bytes(bytes).to_string()
|
|
||||||
}
|
|
||||||
|
|
||||||
pub(crate) fn get_str(v: &Value) -> Option<&str> {
|
pub(crate) fn get_str(v: &Value) -> Option<&str> {
|
||||||
match v {
|
match v {
|
||||||
Value::String(v) => {
|
Value::String(v) => {
|
||||||
|
|||||||
23
src/peer.rs
23
src/peer.rs
@@ -4,6 +4,7 @@ use hbb_common::{
|
|||||||
log,
|
log,
|
||||||
rendezvous_proto::*,
|
rendezvous_proto::*,
|
||||||
tokio::sync::{Mutex, RwLock},
|
tokio::sync::{Mutex, RwLock},
|
||||||
|
bytes::Bytes,
|
||||||
ResultType,
|
ResultType,
|
||||||
};
|
};
|
||||||
use serde_derive::{Deserialize, Serialize};
|
use serde_derive::{Deserialize, Serialize};
|
||||||
@@ -25,13 +26,12 @@ pub(crate) struct PeerInfo {
|
|||||||
pub(crate) ip: String,
|
pub(crate) ip: String,
|
||||||
}
|
}
|
||||||
|
|
||||||
#[derive(Clone, Debug)]
|
|
||||||
pub(crate) struct Peer {
|
pub(crate) struct Peer {
|
||||||
pub(crate) socket_addr: SocketAddr,
|
pub(crate) socket_addr: SocketAddr,
|
||||||
pub(crate) last_reg_time: Instant,
|
pub(crate) last_reg_time: Instant,
|
||||||
pub(crate) guid: Vec<u8>,
|
pub(crate) guid: Vec<u8>,
|
||||||
pub(crate) uuid: Vec<u8>,
|
pub(crate) uuid: Bytes,
|
||||||
pub(crate) pk: Vec<u8>,
|
pub(crate) pk: Bytes,
|
||||||
pub(crate) user: Option<Vec<u8>>,
|
pub(crate) user: Option<Vec<u8>>,
|
||||||
pub(crate) info: PeerInfo,
|
pub(crate) info: PeerInfo,
|
||||||
pub(crate) disabled: bool,
|
pub(crate) disabled: bool,
|
||||||
@@ -44,8 +44,8 @@ impl Default for Peer {
|
|||||||
socket_addr: "0.0.0.0:0".parse().unwrap(),
|
socket_addr: "0.0.0.0:0".parse().unwrap(),
|
||||||
last_reg_time: get_expired_time(),
|
last_reg_time: get_expired_time(),
|
||||||
guid: Vec::new(),
|
guid: Vec::new(),
|
||||||
uuid: Vec::new(),
|
uuid: Bytes::new(),
|
||||||
pk: Vec::new(),
|
pk: Bytes::new(),
|
||||||
info: Default::default(),
|
info: Default::default(),
|
||||||
user: None,
|
user: None,
|
||||||
disabled: false,
|
disabled: false,
|
||||||
@@ -93,8 +93,8 @@ impl PeerMap {
|
|||||||
id: String,
|
id: String,
|
||||||
peer: LockPeer,
|
peer: LockPeer,
|
||||||
addr: SocketAddr,
|
addr: SocketAddr,
|
||||||
uuid: Vec<u8>,
|
uuid: Bytes,
|
||||||
pk: Vec<u8>,
|
pk: Bytes,
|
||||||
ip: String,
|
ip: String,
|
||||||
) -> register_pk_response::Result {
|
) -> register_pk_response::Result {
|
||||||
log::info!("update_pk {} {:?} {:?} {:?}", id, addr, uuid, pk);
|
log::info!("update_pk {} {:?} {:?} {:?}", id, addr, uuid, pk);
|
||||||
@@ -139,8 +139,8 @@ impl PeerMap {
|
|||||||
if let Ok(Some(v)) = self.db.get_peer(id).await {
|
if let Ok(Some(v)) = self.db.get_peer(id).await {
|
||||||
let peer = Peer {
|
let peer = Peer {
|
||||||
guid: v.guid,
|
guid: v.guid,
|
||||||
uuid: v.uuid,
|
uuid: v.uuid.into(),
|
||||||
pk: v.pk,
|
pk: v.pk.into(),
|
||||||
user: v.user,
|
user: v.user,
|
||||||
info: serde_json::from_str::<PeerInfo>(&v.info).unwrap_or_default(),
|
info: serde_json::from_str::<PeerInfo>(&v.info).unwrap_or_default(),
|
||||||
disabled: v.status == Some(0),
|
disabled: v.status == Some(0),
|
||||||
@@ -177,9 +177,4 @@ impl PeerMap {
|
|||||||
pub(crate) async fn is_in_memory(&self, id: &str) -> bool {
|
pub(crate) async fn is_in_memory(&self, id: &str) -> bool {
|
||||||
self.map.read().await.contains_key(id)
|
self.map.read().await.contains_key(id)
|
||||||
}
|
}
|
||||||
|
|
||||||
#[inline]
|
|
||||||
pub(crate) async fn remove(&self, id: &str) {
|
|
||||||
self.map.write().await.remove(id);
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -420,7 +420,7 @@ async fn make_pair_(stream: impl StreamTrait, addr: SocketAddr, key: &str, limit
|
|||||||
let mut stream = stream;
|
let mut stream = stream;
|
||||||
if let Ok(Some(Ok(bytes))) = timeout(30_000, stream.recv()).await {
|
if let Ok(Some(Ok(bytes))) = timeout(30_000, stream.recv()).await {
|
||||||
if let Ok(msg_in) = RendezvousMessage::parse_from_bytes(&bytes) {
|
if let Ok(msg_in) = RendezvousMessage::parse_from_bytes(&bytes) {
|
||||||
if let Some(rendezvous_message::Union::request_relay(rf)) = msg_in.union {
|
if let Some(rendezvous_message::Union::RequestRelay(rf)) = msg_in.union {
|
||||||
if !key.is_empty() && rf.licence_key != key {
|
if !key.is_empty() && rf.licence_key != key {
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -89,12 +89,7 @@ enum LoopFailure {
|
|||||||
|
|
||||||
impl RendezvousServer {
|
impl RendezvousServer {
|
||||||
#[tokio::main(flavor = "multi_thread")]
|
#[tokio::main(flavor = "multi_thread")]
|
||||||
pub async fn start(
|
pub async fn start(port: i32, serial: i32, key: &str, rmem: usize) -> ResultType<()> {
|
||||||
port: i32,
|
|
||||||
serial: i32,
|
|
||||||
key: &str,
|
|
||||||
rmem: usize,
|
|
||||||
) -> ResultType<()> {
|
|
||||||
let (key, sk) = Self::get_server_sk(key);
|
let (key, sk) = Self::get_server_sk(key);
|
||||||
let addr = format!("0.0.0.0:{}", port);
|
let addr = format!("0.0.0.0:{}", port);
|
||||||
let addr2 = format!("0.0.0.0:{}", port - 1);
|
let addr2 = format!("0.0.0.0:{}", port - 1);
|
||||||
@@ -112,6 +107,17 @@ impl RendezvousServer {
|
|||||||
if !version.is_empty() {
|
if !version.is_empty() {
|
||||||
log::info!("software_url: {}, version: {}", software_url, version);
|
log::info!("software_url: {}, version: {}", software_url, version);
|
||||||
}
|
}
|
||||||
|
let mask = get_arg("mask").parse().ok();
|
||||||
|
let local_ip = if mask.is_none() {
|
||||||
|
"".to_owned()
|
||||||
|
} else {
|
||||||
|
get_arg_or(
|
||||||
|
"local-ip",
|
||||||
|
local_ip_address::local_ip()
|
||||||
|
.map(|x| x.to_string())
|
||||||
|
.unwrap_or_default(),
|
||||||
|
)
|
||||||
|
};
|
||||||
let mut rs = Self {
|
let mut rs = Self {
|
||||||
tcp_punch: Arc::new(Mutex::new(HashMap::new())),
|
tcp_punch: Arc::new(Mutex::new(HashMap::new())),
|
||||||
pm,
|
pm,
|
||||||
@@ -124,20 +130,14 @@ impl RendezvousServer {
|
|||||||
version,
|
version,
|
||||||
software_url,
|
software_url,
|
||||||
sk,
|
sk,
|
||||||
mask: get_arg("mask").parse().ok(),
|
mask,
|
||||||
local_ip: get_arg_or(
|
local_ip,
|
||||||
"local-ip",
|
|
||||||
local_ip_address::local_ip()
|
|
||||||
.map(|x| x.to_string())
|
|
||||||
.unwrap_or_default(),
|
|
||||||
),
|
|
||||||
}),
|
}),
|
||||||
};
|
};
|
||||||
log::info!("mask: {:?}", rs.inner.mask);
|
log::info!("mask: {:?}", rs.inner.mask);
|
||||||
log::info!("local-ip: {:?}", rs.inner.local_ip);
|
log::info!("local-ip: {:?}", rs.inner.local_ip);
|
||||||
std::env::set_var("PORT_FOR_API", port.to_string());
|
std::env::set_var("PORT_FOR_API", port.to_string());
|
||||||
rs.parse_relay_servers(&get_arg("relay-servers"));
|
rs.parse_relay_servers(&get_arg("relay-servers"));
|
||||||
let pm = rs.pm.clone();
|
|
||||||
let mut listener = new_listener(&addr, false).await?;
|
let mut listener = new_listener(&addr, false).await?;
|
||||||
let mut listener2 = new_listener(&addr2, false).await?;
|
let mut listener2 = new_listener(&addr2, false).await?;
|
||||||
let mut listener3 = new_listener(&addr3, false).await?;
|
let mut listener3 = new_listener(&addr3, false).await?;
|
||||||
@@ -298,7 +298,7 @@ impl RendezvousServer {
|
|||||||
) -> ResultType<()> {
|
) -> ResultType<()> {
|
||||||
if let Ok(msg_in) = RendezvousMessage::parse_from_bytes(&bytes) {
|
if let Ok(msg_in) = RendezvousMessage::parse_from_bytes(&bytes) {
|
||||||
match msg_in.union {
|
match msg_in.union {
|
||||||
Some(rendezvous_message::Union::register_peer(rp)) => {
|
Some(rendezvous_message::Union::RegisterPeer(rp)) => {
|
||||||
// B registered
|
// B registered
|
||||||
if rp.id.len() > 0 {
|
if rp.id.len() > 0 {
|
||||||
log::trace!("New peer registered: {:?} {:?}", &rp.id, &addr);
|
log::trace!("New peer registered: {:?} {:?}", &rp.id, &addr);
|
||||||
@@ -314,7 +314,7 @@ impl RendezvousServer {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
Some(rendezvous_message::Union::register_pk(rk)) => {
|
Some(rendezvous_message::Union::RegisterPk(rk)) => {
|
||||||
if rk.uuid.is_empty() || rk.pk.is_empty() {
|
if rk.uuid.is_empty() || rk.pk.is_empty() {
|
||||||
return Ok(());
|
return Ok(());
|
||||||
}
|
}
|
||||||
@@ -401,7 +401,7 @@ impl RendezvousServer {
|
|||||||
});
|
});
|
||||||
socket.send(&msg_out, addr).await?
|
socket.send(&msg_out, addr).await?
|
||||||
}
|
}
|
||||||
Some(rendezvous_message::Union::punch_hole_request(ph)) => {
|
Some(rendezvous_message::Union::PunchHoleRequest(ph)) => {
|
||||||
if self.pm.is_in_memory(&ph.id).await {
|
if self.pm.is_in_memory(&ph.id).await {
|
||||||
self.handle_udp_punch_hole_request(addr, ph, key).await?;
|
self.handle_udp_punch_hole_request(addr, ph, key).await?;
|
||||||
} else {
|
} else {
|
||||||
@@ -413,13 +413,13 @@ impl RendezvousServer {
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
Some(rendezvous_message::Union::punch_hole_sent(phs)) => {
|
Some(rendezvous_message::Union::PunchHoleSent(phs)) => {
|
||||||
self.handle_hole_sent(phs, addr, Some(socket)).await?;
|
self.handle_hole_sent(phs, addr, Some(socket)).await?;
|
||||||
}
|
}
|
||||||
Some(rendezvous_message::Union::local_addr(la)) => {
|
Some(rendezvous_message::Union::LocalAddr(la)) => {
|
||||||
self.handle_local_addr(la, addr, Some(socket)).await?;
|
self.handle_local_addr(la, addr, Some(socket)).await?;
|
||||||
}
|
}
|
||||||
Some(rendezvous_message::Union::configure_update(mut cu)) => {
|
Some(rendezvous_message::Union::ConfigureUpdate(mut cu)) => {
|
||||||
if addr.ip() == ADDR_127 && cu.serial > self.inner.serial {
|
if addr.ip() == ADDR_127 && cu.serial > self.inner.serial {
|
||||||
let mut inner: Inner = (*self.inner).clone();
|
let mut inner: Inner = (*self.inner).clone();
|
||||||
inner.serial = cu.serial;
|
inner.serial = cu.serial;
|
||||||
@@ -440,7 +440,7 @@ impl RendezvousServer {
|
|||||||
);
|
);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
Some(rendezvous_message::Union::software_update(su)) => {
|
Some(rendezvous_message::Union::SoftwareUpdate(su)) => {
|
||||||
if !self.inner.version.is_empty() && su.url != self.inner.version {
|
if !self.inner.version.is_empty() && su.url != self.inner.version {
|
||||||
let mut msg_out = RendezvousMessage::new();
|
let mut msg_out = RendezvousMessage::new();
|
||||||
msg_out.set_software_update(SoftwareUpdate {
|
msg_out.set_software_update(SoftwareUpdate {
|
||||||
@@ -467,7 +467,7 @@ impl RendezvousServer {
|
|||||||
) -> bool {
|
) -> bool {
|
||||||
if let Ok(msg_in) = RendezvousMessage::parse_from_bytes(&bytes) {
|
if let Ok(msg_in) = RendezvousMessage::parse_from_bytes(&bytes) {
|
||||||
match msg_in.union {
|
match msg_in.union {
|
||||||
Some(rendezvous_message::Union::punch_hole_request(ph)) => {
|
Some(rendezvous_message::Union::PunchHoleRequest(ph)) => {
|
||||||
// there maybe several attempt, so sink can be none
|
// there maybe several attempt, so sink can be none
|
||||||
if let Some(sink) = sink.take() {
|
if let Some(sink) = sink.take() {
|
||||||
self.tcp_punch.lock().await.insert(addr, sink);
|
self.tcp_punch.lock().await.insert(addr, sink);
|
||||||
@@ -475,43 +475,47 @@ impl RendezvousServer {
|
|||||||
allow_err!(self.handle_tcp_punch_hole_request(addr, ph, &key, ws).await);
|
allow_err!(self.handle_tcp_punch_hole_request(addr, ph, &key, ws).await);
|
||||||
return true;
|
return true;
|
||||||
}
|
}
|
||||||
Some(rendezvous_message::Union::request_relay(mut rf)) => {
|
Some(rendezvous_message::Union::RequestRelay(mut rf)) => {
|
||||||
// there maybe several attempt, so sink can be none
|
// there maybe several attempt, so sink can be none
|
||||||
if let Some(sink) = sink.take() {
|
if let Some(sink) = sink.take() {
|
||||||
self.tcp_punch.lock().await.insert(addr, sink);
|
self.tcp_punch.lock().await.insert(addr, sink);
|
||||||
}
|
}
|
||||||
if let Some(peer) = self.pm.get_in_memory(&rf.id).await {
|
if let Some(peer) = self.pm.get_in_memory(&rf.id).await {
|
||||||
let mut msg_out = RendezvousMessage::new();
|
let mut msg_out = RendezvousMessage::new();
|
||||||
rf.socket_addr = AddrMangle::encode(addr);
|
rf.socket_addr = AddrMangle::encode(addr).into();
|
||||||
msg_out.set_request_relay(rf);
|
msg_out.set_request_relay(rf);
|
||||||
let peer_addr = peer.read().await.socket_addr;
|
let peer_addr = peer.read().await.socket_addr;
|
||||||
self.tx.send(Data::Msg(msg_out, peer_addr)).ok();
|
self.tx.send(Data::Msg(msg_out, peer_addr)).ok();
|
||||||
}
|
}
|
||||||
return true;
|
return true;
|
||||||
}
|
}
|
||||||
Some(rendezvous_message::Union::relay_response(mut rr)) => {
|
Some(rendezvous_message::Union::RelayResponse(mut rr)) => {
|
||||||
let addr_b = AddrMangle::decode(&rr.socket_addr);
|
let addr_b = AddrMangle::decode(&rr.socket_addr);
|
||||||
rr.socket_addr = Default::default();
|
rr.socket_addr = Default::default();
|
||||||
let id = rr.get_id();
|
let id = rr.id();
|
||||||
if !id.is_empty() {
|
if !id.is_empty() {
|
||||||
let pk = self.get_pk(&rr.version, id.to_owned()).await;
|
let pk = self.get_pk(&rr.version, id.to_owned()).await;
|
||||||
rr.set_pk(pk);
|
rr.set_pk(pk);
|
||||||
}
|
}
|
||||||
let mut msg_out = RendezvousMessage::new();
|
let mut msg_out = RendezvousMessage::new();
|
||||||
if self.is_lan(addr_b) {
|
if !rr.relay_server.is_empty() {
|
||||||
// https://github.com/rustdesk/rustdesk-server/issues/24
|
if self.is_lan(addr_b) {
|
||||||
rr.relay_server = self.inner.local_ip.clone();
|
// https://github.com/rustdesk/rustdesk-server/issues/24
|
||||||
|
rr.relay_server = self.inner.local_ip.clone();
|
||||||
|
} else if rr.relay_server == self.inner.local_ip {
|
||||||
|
rr.relay_server = self.get_relay_server(addr.ip(), addr_b.ip());
|
||||||
|
}
|
||||||
}
|
}
|
||||||
msg_out.set_relay_response(rr);
|
msg_out.set_relay_response(rr);
|
||||||
allow_err!(self.send_to_tcp_sync(msg_out, addr_b).await);
|
allow_err!(self.send_to_tcp_sync(msg_out, addr_b).await);
|
||||||
}
|
}
|
||||||
Some(rendezvous_message::Union::punch_hole_sent(phs)) => {
|
Some(rendezvous_message::Union::PunchHoleSent(phs)) => {
|
||||||
allow_err!(self.handle_hole_sent(phs, addr, None).await);
|
allow_err!(self.handle_hole_sent(phs, addr, None).await);
|
||||||
}
|
}
|
||||||
Some(rendezvous_message::Union::local_addr(la)) => {
|
Some(rendezvous_message::Union::LocalAddr(la)) => {
|
||||||
allow_err!(self.handle_local_addr(la, addr, None).await);
|
allow_err!(self.handle_local_addr(la, addr, None).await);
|
||||||
}
|
}
|
||||||
Some(rendezvous_message::Union::test_nat_request(tar)) => {
|
Some(rendezvous_message::Union::TestNatRequest(tar)) => {
|
||||||
let mut msg_out = RendezvousMessage::new();
|
let mut msg_out = RendezvousMessage::new();
|
||||||
let mut res = TestNatResponse {
|
let mut res = TestNatResponse {
|
||||||
port: addr.port() as _,
|
port: addr.port() as _,
|
||||||
@@ -526,7 +530,7 @@ impl RendezvousServer {
|
|||||||
msg_out.set_test_nat_response(res);
|
msg_out.set_test_nat_response(res);
|
||||||
Self::send_to_sink(sink, msg_out).await;
|
Self::send_to_sink(sink, msg_out).await;
|
||||||
}
|
}
|
||||||
Some(rendezvous_message::Union::register_pk(_rk)) => {
|
Some(rendezvous_message::Union::RegisterPk(_)) => {
|
||||||
let res = register_pk_response::Result::NOT_SUPPORT;
|
let res = register_pk_response::Result::NOT_SUPPORT;
|
||||||
let mut msg_out = RendezvousMessage::new();
|
let mut msg_out = RendezvousMessage::new();
|
||||||
msg_out.set_register_pk_response(RegisterPkResponse {
|
msg_out.set_register_pk_response(RegisterPkResponse {
|
||||||
@@ -602,7 +606,7 @@ impl RendezvousServer {
|
|||||||
);
|
);
|
||||||
let mut msg_out = RendezvousMessage::new();
|
let mut msg_out = RendezvousMessage::new();
|
||||||
let mut p = PunchHoleResponse {
|
let mut p = PunchHoleResponse {
|
||||||
socket_addr: AddrMangle::encode(addr),
|
socket_addr: AddrMangle::encode(addr).into(),
|
||||||
pk: self.get_pk(&phs.version, phs.id).await,
|
pk: self.get_pk(&phs.version, phs.id).await,
|
||||||
relay_server: phs.relay_server.clone(),
|
relay_server: phs.relay_server.clone(),
|
||||||
..Default::default()
|
..Default::default()
|
||||||
@@ -659,6 +663,7 @@ impl RendezvousServer {
|
|||||||
key: &str,
|
key: &str,
|
||||||
ws: bool,
|
ws: bool,
|
||||||
) -> ResultType<(RendezvousMessage, Option<SocketAddr>)> {
|
) -> ResultType<(RendezvousMessage, Option<SocketAddr>)> {
|
||||||
|
let mut ph = ph;
|
||||||
if !key.is_empty() && ph.licence_key != key {
|
if !key.is_empty() && ph.licence_key != key {
|
||||||
let mut msg_out = RendezvousMessage::new();
|
let mut msg_out = RendezvousMessage::new();
|
||||||
msg_out.set_punch_hole_response(PunchHoleResponse {
|
msg_out.set_punch_hole_response(PunchHoleResponse {
|
||||||
@@ -689,20 +694,13 @@ impl RendezvousServer {
|
|||||||
let mut msg_out = RendezvousMessage::new();
|
let mut msg_out = RendezvousMessage::new();
|
||||||
let peer_is_lan = self.is_lan(peer_addr);
|
let peer_is_lan = self.is_lan(peer_addr);
|
||||||
let is_lan = self.is_lan(addr);
|
let is_lan = self.is_lan(addr);
|
||||||
|
let mut relay_server = self.get_relay_server(addr.ip(), peer_addr.ip());
|
||||||
if unsafe { ALWAYS_USE_RELAY } || (peer_is_lan ^ is_lan) {
|
if unsafe { ALWAYS_USE_RELAY } || (peer_is_lan ^ is_lan) {
|
||||||
let relay_server = if peer_is_lan {
|
if peer_is_lan {
|
||||||
// https://github.com/rustdesk/rustdesk-server/issues/24
|
// https://github.com/rustdesk/rustdesk-server/issues/24
|
||||||
self.inner.local_ip.clone()
|
relay_server = self.inner.local_ip.clone()
|
||||||
} else {
|
|
||||||
self.get_relay_server(addr.ip(), peer_addr.ip())
|
|
||||||
};
|
|
||||||
if !relay_server.is_empty() {
|
|
||||||
msg_out.set_request_relay(RequestRelay {
|
|
||||||
relay_server,
|
|
||||||
..Default::default()
|
|
||||||
});
|
|
||||||
return Ok((msg_out, Some(peer_addr)));
|
|
||||||
}
|
}
|
||||||
|
ph.nat_type = NatType::SYMMETRIC.into(); // will force relay
|
||||||
}
|
}
|
||||||
let same_intranet = !ws
|
let same_intranet = !ws
|
||||||
&& match peer_addr {
|
&& match peer_addr {
|
||||||
@@ -715,8 +713,7 @@ impl RendezvousServer {
|
|||||||
_ => false,
|
_ => false,
|
||||||
},
|
},
|
||||||
};
|
};
|
||||||
let socket_addr = AddrMangle::encode(addr);
|
let socket_addr = AddrMangle::encode(addr).into();
|
||||||
let relay_server = self.get_relay_server(addr.ip(), peer_addr.ip());
|
|
||||||
if same_intranet {
|
if same_intranet {
|
||||||
log::debug!(
|
log::debug!(
|
||||||
"Fetch local addr {:?} {:?} request from {:?}",
|
"Fetch local addr {:?} {:?} request from {:?}",
|
||||||
@@ -754,6 +751,35 @@ impl RendezvousServer {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
#[inline]
|
||||||
|
async fn handle_online_request(
|
||||||
|
&mut self,
|
||||||
|
stream: &mut FramedStream,
|
||||||
|
peers: Vec<String>,
|
||||||
|
) -> ResultType<()> {
|
||||||
|
let mut states = BytesMut::zeroed((peers.len() + 7) / 8);
|
||||||
|
for i in 0..peers.len() {
|
||||||
|
if let Some(peer) = self.pm.get_in_memory(&peers[i]).await {
|
||||||
|
let elapsed = peer.read().await.last_reg_time.elapsed().as_millis() as i32;
|
||||||
|
// bytes index from left to right
|
||||||
|
let states_idx = i / 8;
|
||||||
|
let bit_idx = 7 - i % 8;
|
||||||
|
if elapsed < REG_TIMEOUT {
|
||||||
|
states[states_idx] |= 0x01 << bit_idx;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
let mut msg_out = RendezvousMessage::new();
|
||||||
|
msg_out.set_online_response(OnlineResponse {
|
||||||
|
states: states.into(),
|
||||||
|
..Default::default()
|
||||||
|
});
|
||||||
|
stream.send(&msg_out).await?;
|
||||||
|
|
||||||
|
Ok(())
|
||||||
|
}
|
||||||
|
|
||||||
#[inline]
|
#[inline]
|
||||||
async fn send_to_tcp(&mut self, msg: RendezvousMessage, addr: SocketAddr) {
|
async fn send_to_tcp(&mut self, msg: RendezvousMessage, addr: SocketAddr) {
|
||||||
let mut tcp = self.tcp_punch.lock().await.remove(&addr);
|
let mut tcp = self.tcp_punch.lock().await.remove(&addr);
|
||||||
@@ -860,7 +886,7 @@ impl RendezvousServer {
|
|||||||
self.relay_servers = self.relay_servers0.clone();
|
self.relay_servers = self.relay_servers0.clone();
|
||||||
}
|
}
|
||||||
|
|
||||||
fn get_relay_server(&self, pa: IpAddr, pb: IpAddr) -> String {
|
fn get_relay_server(&self, _pa: IpAddr, _pb: IpAddr) -> String {
|
||||||
if self.relay_servers.is_empty() {
|
if self.relay_servers.is_empty() {
|
||||||
return "".to_owned();
|
return "".to_owned();
|
||||||
} else if self.relay_servers.len() == 1 {
|
} else if self.relay_servers.len() == 1 {
|
||||||
@@ -1012,8 +1038,8 @@ impl RendezvousServer {
|
|||||||
}
|
}
|
||||||
|
|
||||||
async fn handle_listener2(&self, stream: TcpStream, addr: SocketAddr) {
|
async fn handle_listener2(&self, stream: TcpStream, addr: SocketAddr) {
|
||||||
|
let mut rs = self.clone();
|
||||||
if addr.ip().to_string() == "127.0.0.1" {
|
if addr.ip().to_string() == "127.0.0.1" {
|
||||||
let rs = self.clone();
|
|
||||||
tokio::spawn(async move {
|
tokio::spawn(async move {
|
||||||
let mut stream = stream;
|
let mut stream = stream;
|
||||||
let mut buffer = [0; 64];
|
let mut buffer = [0; 64];
|
||||||
@@ -1031,34 +1057,31 @@ impl RendezvousServer {
|
|||||||
let mut stream = stream;
|
let mut stream = stream;
|
||||||
if let Some(Ok(bytes)) = stream.next_timeout(30_000).await {
|
if let Some(Ok(bytes)) = stream.next_timeout(30_000).await {
|
||||||
if let Ok(msg_in) = RendezvousMessage::parse_from_bytes(&bytes) {
|
if let Ok(msg_in) = RendezvousMessage::parse_from_bytes(&bytes) {
|
||||||
if let Some(rendezvous_message::Union::test_nat_request(_)) = msg_in.union {
|
match msg_in.union {
|
||||||
let mut msg_out = RendezvousMessage::new();
|
Some(rendezvous_message::Union::TestNatRequest(_)) => {
|
||||||
msg_out.set_test_nat_response(TestNatResponse {
|
let mut msg_out = RendezvousMessage::new();
|
||||||
port: addr.port() as _,
|
msg_out.set_test_nat_response(TestNatResponse {
|
||||||
..Default::default()
|
port: addr.port() as _,
|
||||||
});
|
..Default::default()
|
||||||
stream.send(&msg_out).await.ok();
|
});
|
||||||
|
stream.send(&msg_out).await.ok();
|
||||||
|
}
|
||||||
|
Some(rendezvous_message::Union::OnlineRequest(or)) => {
|
||||||
|
allow_err!(rs.handle_online_request(&mut stream, or.peers).await);
|
||||||
|
}
|
||||||
|
_ => {}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
async fn handle_listener(
|
async fn handle_listener(&self, stream: TcpStream, addr: SocketAddr, key: &str, ws: bool) {
|
||||||
&self,
|
|
||||||
stream: TcpStream,
|
|
||||||
addr: SocketAddr,
|
|
||||||
key: &str,
|
|
||||||
ws: bool,
|
|
||||||
) {
|
|
||||||
log::debug!("Tcp connection from {:?}, ws: {}", addr, ws);
|
log::debug!("Tcp connection from {:?}, ws: {}", addr, ws);
|
||||||
let mut rs = self.clone();
|
let mut rs = self.clone();
|
||||||
let key = key.to_owned();
|
let key = key.to_owned();
|
||||||
tokio::spawn(async move {
|
tokio::spawn(async move {
|
||||||
allow_err!(
|
allow_err!(rs.handle_listener_inner(stream, addr, &key, ws).await);
|
||||||
rs.handle_listener_inner(stream, addr, &key, ws)
|
|
||||||
.await
|
|
||||||
);
|
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -1078,10 +1101,7 @@ impl RendezvousServer {
|
|||||||
while let Ok(Some(Ok(msg))) = timeout(30_000, b.next()).await {
|
while let Ok(Some(Ok(msg))) = timeout(30_000, b.next()).await {
|
||||||
match msg {
|
match msg {
|
||||||
tungstenite::Message::Binary(bytes) => {
|
tungstenite::Message::Binary(bytes) => {
|
||||||
if !self
|
if !self.handle_tcp(&bytes, &mut sink, addr, key, ws).await {
|
||||||
.handle_tcp(&bytes, &mut sink, addr, key, ws)
|
|
||||||
.await
|
|
||||||
{
|
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -1092,10 +1112,7 @@ impl RendezvousServer {
|
|||||||
let (a, mut b) = Framed::new(stream, BytesCodec::new()).split();
|
let (a, mut b) = Framed::new(stream, BytesCodec::new()).split();
|
||||||
sink = Some(Sink::TcpStream(a));
|
sink = Some(Sink::TcpStream(a));
|
||||||
while let Ok(Some(Ok(bytes))) = timeout(30_000, b.next()).await {
|
while let Ok(Some(Ok(bytes))) = timeout(30_000, b.next()).await {
|
||||||
if !self
|
if !self.handle_tcp(&bytes, &mut sink, addr, key, ws).await {
|
||||||
.handle_tcp(&bytes, &mut sink, addr, key, ws)
|
|
||||||
.await
|
|
||||||
{
|
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -1108,13 +1125,13 @@ impl RendezvousServer {
|
|||||||
}
|
}
|
||||||
|
|
||||||
#[inline]
|
#[inline]
|
||||||
async fn get_pk(&mut self, version: &str, id: String) -> Vec<u8> {
|
async fn get_pk(&mut self, version: &str, id: String) -> Bytes {
|
||||||
if version.is_empty() || self.inner.sk.is_none() {
|
if version.is_empty() || self.inner.sk.is_none() {
|
||||||
Vec::new()
|
Bytes::new()
|
||||||
} else {
|
} else {
|
||||||
match self.pm.get(&id).await {
|
match self.pm.get(&id).await {
|
||||||
Some(peer) => {
|
Some(peer) => {
|
||||||
let pk = peer.read().await.pk.clone();
|
let pk = peer.read().await.pk.clone().into();
|
||||||
sign::sign(
|
sign::sign(
|
||||||
&hbb_common::message_proto::IdPk {
|
&hbb_common::message_proto::IdPk {
|
||||||
id,
|
id,
|
||||||
@@ -1125,8 +1142,9 @@ impl RendezvousServer {
|
|||||||
.unwrap_or_default(),
|
.unwrap_or_default(),
|
||||||
&self.inner.sk.as_ref().unwrap(),
|
&self.inner.sk.as_ref().unwrap(),
|
||||||
)
|
)
|
||||||
|
.into()
|
||||||
}
|
}
|
||||||
_ => Vec::new(),
|
_ => Bytes::new(),
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -1230,13 +1248,6 @@ async fn test_hbbs(addr: SocketAddr) -> ResultType<()> {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
#[inline]
|
|
||||||
fn distance(a: &(i32, i32), b: &(i32, i32)) -> i32 {
|
|
||||||
let dx = a.0 - b.0;
|
|
||||||
let dy = a.1 - b.1;
|
|
||||||
dx * dx + dy * dy
|
|
||||||
}
|
|
||||||
|
|
||||||
#[inline]
|
#[inline]
|
||||||
async fn send_rk_res(
|
async fn send_rk_res(
|
||||||
socket: &mut FramedSocket,
|
socket: &mut FramedSocket,
|
||||||
|
|||||||
173
src/utils.rs
Normal file
173
src/utils.rs
Normal file
@@ -0,0 +1,173 @@
|
|||||||
|
use dns_lookup::{lookup_addr, lookup_host};
|
||||||
|
use hbb_common::{bail, ResultType};
|
||||||
|
use sodiumoxide::crypto::sign;
|
||||||
|
use std::{
|
||||||
|
env,
|
||||||
|
net::{IpAddr, TcpStream},
|
||||||
|
process, str,
|
||||||
|
};
|
||||||
|
|
||||||
|
fn print_help() {
|
||||||
|
println!(
|
||||||
|
"Usage:
|
||||||
|
rustdesk-util [command]\n
|
||||||
|
Available Commands:
|
||||||
|
genkeypair Generate a new keypair
|
||||||
|
validatekeypair [public key] [secret key] Validate an existing keypair
|
||||||
|
doctor [rustdesk-server] Check for server connection problems"
|
||||||
|
);
|
||||||
|
process::exit(0x0001);
|
||||||
|
}
|
||||||
|
|
||||||
|
fn error_then_help(msg: &str) {
|
||||||
|
println!("ERROR: {}\n", msg);
|
||||||
|
print_help();
|
||||||
|
}
|
||||||
|
|
||||||
|
fn gen_keypair() {
|
||||||
|
let (pk, sk) = sign::gen_keypair();
|
||||||
|
let public_key = base64::encode(pk);
|
||||||
|
let secret_key = base64::encode(sk);
|
||||||
|
println!("Public Key: {public_key}");
|
||||||
|
println!("Secret Key: {secret_key}");
|
||||||
|
}
|
||||||
|
|
||||||
|
fn validate_keypair(pk: &str, sk: &str) -> ResultType<()> {
|
||||||
|
let sk1 = base64::decode(&sk);
|
||||||
|
if sk1.is_err() {
|
||||||
|
bail!("Invalid secret key");
|
||||||
|
}
|
||||||
|
let sk1 = sk1.unwrap();
|
||||||
|
|
||||||
|
let secret_key = sign::SecretKey::from_slice(sk1.as_slice());
|
||||||
|
if secret_key.is_none() {
|
||||||
|
bail!("Invalid Secret key");
|
||||||
|
}
|
||||||
|
let secret_key = secret_key.unwrap();
|
||||||
|
|
||||||
|
let pk1 = base64::decode(&pk);
|
||||||
|
if pk1.is_err() {
|
||||||
|
bail!("Invalid public key");
|
||||||
|
}
|
||||||
|
let pk1 = pk1.unwrap();
|
||||||
|
|
||||||
|
let public_key = sign::PublicKey::from_slice(pk1.as_slice());
|
||||||
|
if public_key.is_none() {
|
||||||
|
bail!("Invalid Public key");
|
||||||
|
}
|
||||||
|
let public_key = public_key.unwrap();
|
||||||
|
|
||||||
|
let random_data_to_test = b"This is meh.";
|
||||||
|
let signed_data = sign::sign(random_data_to_test, &secret_key);
|
||||||
|
let verified_data = sign::verify(&signed_data, &public_key);
|
||||||
|
if verified_data.is_err() {
|
||||||
|
bail!("Key pair is INVALID");
|
||||||
|
}
|
||||||
|
let verified_data = verified_data.unwrap();
|
||||||
|
|
||||||
|
if random_data_to_test != &verified_data[..] {
|
||||||
|
bail!("Key pair is INVALID");
|
||||||
|
}
|
||||||
|
|
||||||
|
Ok(())
|
||||||
|
}
|
||||||
|
|
||||||
|
fn doctor_tcp(address: std::net::IpAddr, port: &str, desc: &str) {
|
||||||
|
let start = std::time::Instant::now();
|
||||||
|
let conn = format!("{}:{}", address, port);
|
||||||
|
if let Ok(_stream) = TcpStream::connect(conn.as_str()) {
|
||||||
|
let elapsed = std::time::Instant::now().duration_since(start);
|
||||||
|
println!(
|
||||||
|
"TCP Port {} ({}): OK in {} ms",
|
||||||
|
port,
|
||||||
|
desc,
|
||||||
|
elapsed.as_millis()
|
||||||
|
);
|
||||||
|
} else {
|
||||||
|
println!("TCP Port {} ({}): ERROR", port, desc);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
fn doctor_ip(server_ip_address: std::net::IpAddr, server_address: Option<&str>) {
|
||||||
|
println!("\nChecking IP address: {}", server_ip_address);
|
||||||
|
println!("Is IPV4: {}", server_ip_address.is_ipv4());
|
||||||
|
println!("Is IPV6: {}", server_ip_address.is_ipv6());
|
||||||
|
|
||||||
|
// reverse dns lookup
|
||||||
|
// TODO: (check) doesn't seem to do reverse lookup on OSX...
|
||||||
|
let reverse = lookup_addr(&server_ip_address).unwrap();
|
||||||
|
if server_address.is_some() {
|
||||||
|
if reverse == server_address.unwrap() {
|
||||||
|
println!("Reverse DNS lookup: '{}' MATCHES server address", reverse);
|
||||||
|
} else {
|
||||||
|
println!(
|
||||||
|
"Reverse DNS lookup: '{}' DOESN'T MATCH server address '{}'",
|
||||||
|
reverse,
|
||||||
|
server_address.unwrap()
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// TODO: ICMP ping?
|
||||||
|
|
||||||
|
// port check TCP (UDP is hard to check)
|
||||||
|
doctor_tcp(server_ip_address, "21114", "API");
|
||||||
|
doctor_tcp(server_ip_address, "21115", "hbbs extra port for nat test");
|
||||||
|
doctor_tcp(server_ip_address, "21116", "hbbs");
|
||||||
|
doctor_tcp(server_ip_address, "21117", "hbbr tcp");
|
||||||
|
doctor_tcp(server_ip_address, "21118", "hbbs websocket");
|
||||||
|
doctor_tcp(server_ip_address, "21119", "hbbr websocket");
|
||||||
|
|
||||||
|
// TODO: key check
|
||||||
|
}
|
||||||
|
|
||||||
|
fn doctor(server_address_unclean: &str) {
|
||||||
|
let server_address3 = server_address_unclean.trim();
|
||||||
|
let server_address2 = server_address3.to_lowercase();
|
||||||
|
let server_address = server_address2.as_str();
|
||||||
|
println!("Checking server: {}\n", server_address);
|
||||||
|
let server_ipaddr = server_address.parse::<IpAddr>();
|
||||||
|
if server_ipaddr.is_err() {
|
||||||
|
// the passed string is not an ip address
|
||||||
|
let ips: Vec<std::net::IpAddr> = lookup_host(server_address).unwrap();
|
||||||
|
println!("Found {} IP addresses: ", ips.iter().count());
|
||||||
|
|
||||||
|
ips.iter().for_each(|ip| println!(" - {ip}"));
|
||||||
|
|
||||||
|
ips.iter().for_each(|ip| doctor_ip(*ip, Some(server_address)));
|
||||||
|
|
||||||
|
} else {
|
||||||
|
// user requested an ip address
|
||||||
|
doctor_ip(server_ipaddr.unwrap(), None);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
fn main() {
|
||||||
|
let args: Vec<_> = env::args().collect();
|
||||||
|
if args.len() <= 1 {
|
||||||
|
print_help();
|
||||||
|
}
|
||||||
|
|
||||||
|
let command = args[1].to_lowercase();
|
||||||
|
match command.as_str() {
|
||||||
|
"genkeypair" => gen_keypair(),
|
||||||
|
"validatekeypair" => {
|
||||||
|
if args.len() <= 3 {
|
||||||
|
error_then_help("You must supply both the public and the secret key");
|
||||||
|
}
|
||||||
|
let res = validate_keypair(args[2].as_str(), args[3].as_str());
|
||||||
|
if let Err(e) = res {
|
||||||
|
println!("{}", e);
|
||||||
|
process::exit(0x0001);
|
||||||
|
}
|
||||||
|
println!("Key pair is VALID");
|
||||||
|
}
|
||||||
|
"doctor" => {
|
||||||
|
if args.len() <= 2 {
|
||||||
|
error_then_help("You must supply the rustdesk-server address");
|
||||||
|
}
|
||||||
|
doctor(args[2].as_str());
|
||||||
|
}
|
||||||
|
_ => print_help(),
|
||||||
|
}
|
||||||
|
}
|
||||||
18
systemd/rustdesk-hbbr.service
Normal file
18
systemd/rustdesk-hbbr.service
Normal file
@@ -0,0 +1,18 @@
|
|||||||
|
|
||||||
|
[Unit]
|
||||||
|
Description=Rustdesk Relay Server
|
||||||
|
|
||||||
|
[Service]
|
||||||
|
Type=simple
|
||||||
|
LimitNOFILE=1000000
|
||||||
|
ExecStart=/usr/bin/hbbr
|
||||||
|
WorkingDirectory=/var/lib/rustdesk-server/
|
||||||
|
User=
|
||||||
|
Group=
|
||||||
|
Restart=always
|
||||||
|
# Restart service after 10 seconds if node service crashes
|
||||||
|
RestartSec=10
|
||||||
|
|
||||||
|
[Install]
|
||||||
|
WantedBy=multi-user.target
|
||||||
|
|
||||||
18
systemd/rustdesk-hbbs.service
Normal file
18
systemd/rustdesk-hbbs.service
Normal file
@@ -0,0 +1,18 @@
|
|||||||
|
|
||||||
|
[Unit]
|
||||||
|
Description=Rustdesk Signal Server
|
||||||
|
|
||||||
|
[Service]
|
||||||
|
Type=simple
|
||||||
|
LimitNOFILE=1000000
|
||||||
|
ExecStart=/usr/bin/hbbs
|
||||||
|
WorkingDirectory=/var/lib/rustdesk-server/
|
||||||
|
User=
|
||||||
|
Group=
|
||||||
|
Restart=always
|
||||||
|
# Restart service after 10 seconds if node service crashes
|
||||||
|
RestartSec=10
|
||||||
|
|
||||||
|
[Install]
|
||||||
|
WantedBy=multi-user.target
|
||||||
|
|
||||||
Reference in New Issue
Block a user