v2.0.0
Nowhere 2.0.0
Important
Nowhere 2 introduces a new, wire-incompatible data-plane protocol. Nowhere 1.x Portal, Vector, native next hops, and alternate clients cannot connect to this release. Upgrade every peer on a traffic path together.
Nowhere 2 establishes one fixed nw2 protocol for TLS/TCP and QUIC/UDP, adds optional Morph wire masking, introduces carrier-specific endpoint configuration, and strengthens Mux, SOCKS, pairing, and datagram resource admission.
Highlights
- Replaced the V1 data plane with the fixed
nw2ALPN and V2 authentication, flow, Mux, and QUIC UDP framing. - Added carrier-specific endpoint paths with independent TCP/UDP ports and address-family selection:
tcp,tcp4,tcp6,udp,udp4, andudp6. - Added
morph=0|1, an optional ChaCha20-based transform below TLS/TCP and QUIC/UDP. - Redesigned TLS Mux around adaptive, full-duplex carrier pools shared across directions.
- Added explicit resource admission for Mux streams, terminal delivery, SOCKS clients and UDP targets, Portal claims, and QUIC stream credit.
- Reworked URL parsing, canonical effective configuration, protocol documentation, operational guidance, and interoperability specifications.
Nowhere 2 Wire Boundary
Nowhere 2 accepts only TLS 1.3 connections that negotiate ALPN nw2.
now/1, custom ALPN values, and missing ALPN are rejected.- The
alpnURL query is ignored and cannot alter the protocol. - Authentication derivation, Mux framing, QUIC UDP framing, and flow-ID layout are incompatible with Nowhere 1.x.
- Every native Portal
nexthop and alternate implementation must speak the V2 contract.
Endpoint Configuration
Endpoints now declare their available carriers directly:
HOST:PORTenables TLS/TCP and QUIC/UDP on one port.HOST/tcp:PORTorHOST/udp:PORTenables one carrier.HOST/tcp4:PORT/udp6:PORTselects independent ports and address families.
The V1 Portal wildcard shorthand remains supported: portal://key@:2000 is normalized to portal://key@*:2000.
net is now an ignored query parameter. Use the endpoint path to control which carriers exist.
Morph Wire Masking
morph=1 applies a shared-key-derived ChaCha20 transform beneath TLS/TCP and QUIC/UDP.
- Both ends of every hop must use the same
morphvalue; there is no negotiation or fallback. - TCP adds one client-generated 12-byte nonce per connection.
- UDP adds a 12-byte nonce to every datagram; Morph-enabled QUIC requires a path that carries at least 1212-byte UDP payloads.
- Morph changes the socket wire image only. It does not add authentication, integrity, replay protection, traffic-analysis resistance, or protocol camouflage.
Mux and Resource Model
mux=0 remains the default and opens dedicated TLS lanes. With mux=1, one session adapts across up to eight full-duplex TLS carriers, reuses idle carriers, chooses the least-occupied carrier at capacity, and retires fully idle carriers after 30 seconds.
V2 replaces legacy logical-flow quotas with bounded implementation resources:
- 4,096 active streams per Mux carrier.
- 1,024 accepted SOCKS clients and 1,024 active SOCKS UDP targets per Vector.
- 4,096 active or pending Portal claims per authenticated session and 65,536 across the registry.
- Bounded Mux incoming, terminal, and outbound queues; saturation closes the affected carrier rather than accumulating peer-controlled state.
Upgrade Notes
- Upgrade Portal, Vector, native Portal chains, and alternate clients together. V1 and V2 cannot share a carrier.
- Remove reliance on custom
alpnvalues; V2 requiresnw2. - Replace
net=tcp|udp|mixwith compact or explicit carrier endpoints. - When both carriers are declared, omitted
upanddownnow default totcp; set directions explicitly when preserving a prior UDP-oriented deployment. - Replace
NOW_QUIC_MEMORY_PROFILEwithNOW_TRANSPORT_MEMORY_PROFILE, which now governs the shared QUIC and TLS Mux memory profile. - Configure
morph=1on both ends of each hop only after confirming UDP path MTU and peer support. - Review the new Configuration, Protocol, and Interoperability documents before deployment.
Full Changelog: v1.8.3...v2.0.0