1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
//! WireGuard tunnel: Noise IKpsk2 handshake + ChaCha20-Poly1305 transport.
//!
//! This module is a Rust port of the Go `wg` package. Use [`Adapter`] for the
//! one-line setup that bridges WireGuard peers into a pktkit
//! [`L3Connector`](crate::L3Connector). For lower-level control, use
//! [`Handler`] directly (one identity) or [`MultiHandler`] (multiple
//! identities sharing a single UDP socket).
//!
//! # Wire format
//!
//! The packet types are exactly those in the WireGuard whitepaper:
//!
//! | Type | Size | Direction |
//! |------|------|-------------------------|
//! | 1 | 148 | initiator → responder |
//! | 2 | 92 | responder → initiator |
//! | 3 | 64 | responder → initiator |
//! | 4 | var | both |
//!
//! Cookie replies (type 3) implement the DoS-mitigation path: under load the
//! responder validates MAC2 and answers a missing/invalid one with an
//! address-bound cookie reply; the initiator decrypts it and retries with a
//! valid MAC2.
//!
//! # Crypto
//!
//! All primitives come from RustCrypto:
//!
//! - X25519 via `curve25519-dalek` (`MontgomeryPoint::mul_clamped`).
//! - ChaCha20-Poly1305 and XChaCha20-Poly1305 via `chacha20poly1305`.
//! - Blake2s-128 / Blake2s-256 via `blake2`; HKDF is hand-rolled on top of
//! `hmac::Hmac<Blake2s256>`.
//!
//! The `crypto` submodule wraps these into the KDF/AEAD helpers the handshake
//! and transport layers use.
pub use ;
pub use ;
pub use ;
pub use ;
pub use ;
pub use SlidingWindow;
pub use ;
pub use ;