github jpillora/chisel v1.13.0

pre-release3 hours ago

Chisel 1.13.0 is a prerelease adding SOCKS5 UDP ASSOCIATE through the new
opt-in udpsocks remote type, addressing #189.

SOCKS5 UDP support

  • 1080:udpsocks serves TCP CONNECT and UDP ASSOCIATE on the client.
  • R:1080:udpsocks serves the same commands on the server, with traffic
    exiting through the client.
  • TCP and UDP bind the same configured interface and port. The exposed UDP
    relay does not allocate a random port for each association. Bare udpsocks
    defaults to 127.0.0.1:1080.
  • UDP traffic travels through the encrypted tunnel, with destination DNS
    resolved at the exit. Replies retain their actual source IP and port;
    outgoing source ports remain stable across destination changes, supporting
    protocols such as TFTP.
  • Existing SOCKS permissions apply. Forward mode needs server --socks5;
    reverse mode needs server --reverse.

Upgrade both peers to use UDP ASSOCIATE. Existing socks remotes remain
TCP-only. UDP-capable applications must support SOCKS5 UDP ASSOCIATE and keep
its TCP control connection open. SOCKS BIND and UDP fragmentation are unsupported.

Defaults are 100 associations per listener, 100 destinations per association,
a 15-second destination idle timeout, and 9,012-byte packets including the
SOCKS UDP header. Operating-system UDP limits also apply; macOS's default
9,216-byte send limit accommodates Chisel's default packet size.

See the user guide
for setup, authentication, firewall rules, application examples, and limits.

Other fixes

  • Restrict reverse UDP replies to registered return peers, bound peer state,
    and expire idle peers rather than forwarding packets to arbitrary endpoints.

Validation and performance

Builds and tests pass on Ubuntu, macOS, and Windows. Linux validation also
includes the full race-enabled suite, third-party client interoperability,
resource-limit boundaries, two-block TFTP exchanges, and overload recovery.

In three loopback benchmark runs with 1,200-byte payloads and sixteen clients,
forward UDP delivered 17.17 MB/s (137.4 Mbps) and reverse UDP delivered
16.88 MB/s (135.0 Mbps), with zero loss in all runs. These are local workload
measurements, not WAN throughput guarantees. See the
performance report
for methodology, larger-packet results, overload behavior, and reproduction.

This release is marked prerelease. GitHub's latest stable release and the
Docker latest, 1, and 1.12 tags remain on the existing stable version.
Use the versioned jpillora/chisel:1.13.0 or ghcr.io/jpillora/chisel:1.13.0
image to try it.

Don't miss a new chisel release

NewReleases is sending notifications on new releases.