Skip to content

v2.0.0

Choose a tag to compare

@yosebyte yosebyte released this 11 Sep 11:03
· 54 commits to main since this release

Nowhere 2.0.0

Important

Nowhere 2 introduces a new, wire-incompatible data-plane protocol. Nowhere 1.x Portal, Vector, native next hops, and alternate clients cannot connect to this release. Upgrade every peer on a traffic path together.

Nowhere 2 establishes one fixed nw2 protocol for TLS/TCP and QUIC/UDP, adds optional Morph wire masking, introduces carrier-specific endpoint configuration, and strengthens Mux, SOCKS, pairing, and datagram resource admission.

Highlights

  • Replaced the V1 data plane with the fixed nw2 ALPN and V2 authentication, flow, Mux, and QUIC UDP framing.
  • Added carrier-specific endpoint paths with independent TCP/UDP ports and address-family selection: tcp, tcp4, tcp6, udp, udp4, and udp6.
  • Added morph=0|1, an optional ChaCha20-based transform below TLS/TCP and QUIC/UDP.
  • Redesigned TLS Mux around adaptive, full-duplex carrier pools shared across directions.
  • Added explicit resource admission for Mux streams, terminal delivery, SOCKS clients and UDP targets, Portal claims, and QUIC stream credit.
  • Reworked URL parsing, canonical effective configuration, protocol documentation, operational guidance, and interoperability specifications.

Nowhere 2 Wire Boundary

Nowhere 2 accepts only TLS 1.3 connections that negotiate ALPN nw2.

  • now/1, custom ALPN values, and missing ALPN are rejected.
  • The alpn URL query is ignored and cannot alter the protocol.
  • Authentication derivation, Mux framing, QUIC UDP framing, and flow-ID layout are incompatible with Nowhere 1.x.
  • Every native Portal next hop and alternate implementation must speak the V2 contract.

Endpoint Configuration

Endpoints now declare their available carriers directly:

  • HOST:PORT enables TLS/TCP and QUIC/UDP on one port.
  • HOST/tcp:PORT or HOST/udp:PORT enables one carrier.
  • HOST/tcp4:PORT/udp6:PORT selects independent ports and address families.

The V1 Portal wildcard shorthand remains supported: portal://key@:2000 is normalized to portal://key@*:2000.

net is now an ignored query parameter. Use the endpoint path to control which carriers exist.

Morph Wire Masking

morph=1 applies a shared-key-derived ChaCha20 transform beneath TLS/TCP and QUIC/UDP.

  • Both ends of every hop must use the same morph value; there is no negotiation or fallback.
  • TCP adds one client-generated 12-byte nonce per connection.
  • UDP adds a 12-byte nonce to every datagram; Morph-enabled QUIC requires a path that carries at least 1212-byte UDP payloads.
  • Morph changes the socket wire image only. It does not add authentication, integrity, replay protection, traffic-analysis resistance, or protocol camouflage.

Mux and Resource Model

mux=0 remains the default and opens dedicated TLS lanes. With mux=1, one session adapts across up to eight full-duplex TLS carriers, reuses idle carriers, chooses the least-occupied carrier at capacity, and retires fully idle carriers after 30 seconds.

V2 replaces legacy logical-flow quotas with bounded implementation resources:

  • 4,096 active streams per Mux carrier.
  • 1,024 accepted SOCKS clients and 1,024 active SOCKS UDP targets per Vector.
  • 4,096 active or pending Portal claims per authenticated session and 65,536 across the registry.
  • Bounded Mux incoming, terminal, and outbound queues; saturation closes the affected carrier rather than accumulating peer-controlled state.

Upgrade Notes

  1. Upgrade Portal, Vector, native Portal chains, and alternate clients together. V1 and V2 cannot share a carrier.
  2. Remove reliance on custom alpn values; V2 requires nw2.
  3. Replace net=tcp|udp|mix with compact or explicit carrier endpoints.
  4. When both carriers are declared, omitted up and down now default to tcp; set directions explicitly when preserving a prior UDP-oriented deployment.
  5. Replace NOW_QUIC_MEMORY_PROFILE with NOW_TRANSPORT_MEMORY_PROFILE, which now governs the shared QUIC and TLS Mux memory profile.
  6. Configure morph=1 on both ends of each hop only after confirming UDP path MTU and peer support.
  7. Review the new Configuration, Protocol, and Interoperability documents before deployment.

Full Changelog: v1.8.3...v2.0.0