English · Nearby Transfer is an encrypted local-network file transfer and NAS WebDAV library-sync app for nearby devices. It runs as an Electron desktop app on Linux and Windows, with a separate Android client that reuses the same v2 protocol. Files move directly between devices over the LAN — no relay server, no cloud — encrypted end-to-end with Ed25519 identities, X25519 key agreement, and AES-256-GCM chunk encryption.
中文 · Nearby Transfer 是一款面向局域网近场设备的加密文件传输与 NAS WebDAV 共享库同步应用。桌面端基于 Electron,支持 Linux 与 Windows;Android 端为独立应用,复用同一套 v2 协议。文件在设备间经局域网直传,无需中继服务器、不经过云端,全程采用 Ed25519 身份签名、X25519 密钥协商与 AES-256-GCM 分块加密。
- Encrypted direct transfer · 加密直传 — device-to-device over TCP/UDP on the LAN, no relay or cloud. Ed25519-signed identities, X25519 ECDH session keys, AES-256-GCM per-chunk encryption.
- 6-digit SAS pairing · 6 位配对码 — mutual verification with a short authentication string before trust is saved; replay-protected signed confirmations.
- Resumable chunked transfer · 断点续传 — 4 MiB chunks with committed-offset checkpoints; transfers resume after interruption.
- 7-protocol engine · 七协议引擎 — hot-switchable drivers (
v2-stream,turbo-parallel,quic-udp,smb-share,webdav-sync,v1-classic,ftps-secure) with category-based selection. - Shared library (WebDAV) · 共享库 — turn a device into an HTTPS WebDAV NAS; browse, upload, download, and delete with Bearer-token auth over self-signed TLS.
- Concurrent multi-device · 多设备并发 — send to and receive from several peers simultaneously.
- Cross-platform · 跨平台 — desktop (Electron, Linux/Windows) and Android share one protocol; interoperable across all three.
- Directory sync · 目录同步 — CLI
synccommand recursively transfers directories with incremental detection (quick 1 MiB hash + full SHA-256), conflict resolution (rename-new/overwrite/skip), and resume support. - Security hardened · 安全加固 — timing-safe comparisons prevent side-channel attacks; DoS protection via frame size limits (16 MB wire / 1 MB chunk / 4 MB message); 96-bit random nonces per chunk (no IV reuse); path traversal prevention in receive planner.
Desktop · 桌面端
# install dependencies (Node.js >= 24)
npm install
# run the app
npm start
# run the smoke test suite
npm test
# build installers
npm run dist:windows # Windows NSIS installer
npm run dist:linux # Linux tar.gz + zipPre-built installers for the latest release are on the Releases page.
Android · 安卓端
Open android-app/ in Android Studio (or run ./gradlew.bat :android-app:assembleDebug) and install the resulting APK. Requires Android 8.0 (API 26) or later.
Released at v1.3.0. The v2 protocol — Ed25519 identities, SAS pairing, AES-256-GCM chunk encryption, resumable transfers, WebDAV shared library, and the 7-protocol engine — is stable and cross-platform tested across Windows, Ubuntu, and CentOS. Work is underway to extract the protocol core into a reusable TypeScript package (@nearby-transfer/core) and to grow the ecosystem (CLI, Docker, LocalSend interop) per the roadmap.
- Finds other running app instances on the same LAN with UDP multicast.
- Sends files directly between devices without a relay server.
- Encrypts file content with X25519 key agreement and AES-256-GCM chunk encryption.
- Signs transfer requests with an Ed25519 device identity key.
- Shows a receive confirmation dialog for every incoming transfer.
- Saves accepted files to the system Downloads folder by default, with a user-selectable receive location.
- Provides packaging targets for Linux, Windows, and Android.
| Platform | Supported range | Architectures | Packages |
|---|---|---|---|
| Linux RPM family | RHEL/Rocky/Alma/CentOS Stream 8-10 | x64, arm64 | rpm |
| Linux DEB family | Ubuntu 22.04-26.04 or newer compatible releases | x64, arm64 | deb |
| Windows | Windows 10-11 | x64, arm64 | exe installer, zip test package |
| Android | Android 8-16, API 26+ | arm64-v8a first, x86_64 for emulator later | apk/aab planned |
Unsigned Windows builds are intended for testing. Public Windows releases should use platform code signing.
npm install
npm startnpm run check
npm testSee docs/build.md for complete Linux, Windows, and Android build steps, signing notes, and release artifact guidance.
For the v1.0 rewrite plan, current implementation boundary, and moving the
working directory to another computer, see
docs/next-version-handoff.md.
For a one-page path index covering the handoff, UI, Android, desktop, protocol,
and test entry points, see HANDOFF.md.
The complete v2 protocol specification — covering device identity (Ed25519),
UDP multicast discovery, 6-digit SAS pairing, resumable encrypted transfer
(X25519 ECDH + AES-256-GCM), signed stream control, and stream multiplexing —
is in docs/protocol/v2-spec.md. The source of truth
lives in packages/protocol-spec/v2-spec.md.
Deterministic test vectors (identity, session key, chunk encryption, SAS pairing
code, canonical JSON, wire frame, chunk frame, discovery/pairing signatures,
manifest serialization) are in
packages/core/test/vectors/ and verified by
npm run test:core. Regenerate them with
npx tsx packages/core/scripts/generate-all-vectors.ts.
npm run dist:linuxThe Linux build uses electron-builder and creates deb and rpm artifacts under ../nearby-transfer-dist/.
Linux packages install under /opt/nearby-transfer while keeping the desktop display name Nearby Transfer.
npm run dist:linux
npm run dist:windowsCross-platform packages are best built on matching CI runners. The repository includes GitHub Actions workflows for Linux, Windows, and Android artifacts.
On Linux, Windows zip test packages can be generated without Wine by running:
electron-builder --config packaging/electron-builder.yml --win zip --x64 --arm64The Windows NSIS installer requires Wine when cross-building from Linux, or a native Windows runner.
On Windows:
.\gradlew.bat :android-app:assembleDebugOn Linux and macOS:
./gradlew :android-app:assembleDebugThe Android project is a native client under android-app/ that reuses the same discovery and encrypted transfer protocol. See docs/android.md for Android compatibility notes.
- This MVP uses UDP multicast for discovery instead of mDNS to keep the first implementation dependency-light.
- Firewalls may block discovery or transfer ports until the app is allowed on the local network.
- Received files are saved to the system Downloads folder by default. Use the in-app save-location control to choose a different folder.
- Android is implemented as a separate native client and reuses the desktop discovery and encrypted transfer protocol.
- Public Windows releases should be code-signed, and Android debug APKs should not be used for public distribution.