Skip to content

Latest commit

 

History

276 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Nowhere

One relay. Two carriers. Independent directions.

A cross-platform relay that composes TLS/TCP and QUIC/UDP
independently for every flow.

Quick start · Ecosystem · Architecture · Live operations · Documentation · Wire protocol

Nowhere joins TLS/TCP and QUIC/UDP behind one service edge. Vector accepts local SOCKS5 traffic; Portal authenticates carriers and reaches the target. Each flow selects its uplink and downlink independently.

Core property What it means
Unified edge TLS/TCP and QUIC/UDP share one service identity and lifecycle
Split routing Uplink and downlink choose their carrier independently
Optional Morph A keyed transform masks the TLS/QUIC wire image
TCP and UDP SOCKS5 CONNECT and UDP ASSOCIATE are both supported
Native chaining Portal forwards directly to Portal with no local proxy loop
Built-in telemetry The same binary discovers and inspects live instances

Quick start

Use a stable Rust toolchain on a supported target, or download a prebuilt binary.

1. Build

cargo build --release --locked

2. Start Portal

Listen on TLS/TCP and QUIC/UDP at all interfaces on port 2000:

./target/release/nowhere "portal://change-me@*:2000"

3. Start Vector

Connect to Portal and expose SOCKS5 on 127.0.0.1:1080:

./target/release/nowhere \
  "vector://change-me@portal.example:2000?up=tcp&down=tcp&socks=127.0.0.1:1080"

4. Inspect

Open the local TUI from another terminal:

./target/release/nowhere tui

Ecosystem

CLIENT

Anywhere
Native Swift client with independent TCP/UDP carriers, TLS multiplexing, and Morph.

App Store
DEPLOY

nowhere-sh
Interactive Linux VPS deployment script for installation, upgrades, links, QR codes.

Quick start
CONTROL

OpenCtrl
Supervises Nowhere processes and exposes their telemetry through REST and SSE.

API reference
OPERATE

NowhereDash
Web dashboard managed through OpenCtrl, with live telemetry and protected subscriptions.

Quick start

How it works

 Application
  TCP / UDP
      |
    SOCKS5
      |
      v
+------------+  Uplink carrier   +--------------+  Native `next` uplink   +-------------+
|   Vector   |==================>| Entry Portal |========================>| Next Portal |
|            |<==================|              |<========================| (optional)  |
+------------+  Downlink carrier +--------------+  Native `next` downlink +-------------+
                                         |                                       |
                                 direct or SOCKS5                        direct or SOCKS5
                                         |                                       |
                                         v                                       v
                                  +------------+                          +------------+
                                  |   Target   |                          |   Target   |
                                  +------------+                          +------------+

Endpoint format

Each service URL uses either a compact endpoint for both carriers on one port, or an explicit endpoint that assigns carriers, ports, and address families.

Endpoint Meaning
@*:2000 TLS/TCP and QUIC/UDP on wildcard addresses, port 2000
@*/tcp:2006 TLS/TCP only, IPv4 and IPv6
@*/udp:2017 QUIC/UDP only, IPv4 and IPv6
@*/tcp4:2006/udp6:2017 TLS/TCP on IPv4 and QUIC/UDP on IPv6

Independent directions

up and down accept tcp, udp, or mix. With both carriers available, the default is TCP; mux=1 enables TLS multiplexing.

up ↓ / down → tcp udp mix
tcp TT TQ TT ↔ TQ
udp QT QQ QT ↔ QQ
mix TT ↔ QT TQ ↔ QQ TT ↔ QQ

T means TLS/TCP and Q means QUIC/UDP, with the uplink listed first. mix randomly selects either carrier with equal probability for each flow and may try the alternate route once before commitment. Portal next= applies the same policy independently on each hop.

Data path

Carrier bootstrap                 Logical flow

+----------------+                +----------------+----------+-------------+
| AuthFrame      |                | FlowHeader     | Target?  | Payload ... |
| 32 bytes       |                | 5 bytes        | variable | after READY |
+----------------+                +----------------+----------+-------------+
        |                                  |
        +-- TLS: dedicated lane or Mux     +-- TCP: reliable byte stream
        +-- QUIC: first stream only        +-- UDP: UoT or QUIC DATAGRAM

Morph

morph=1 masks the bare TLS/QUIC wire image with a transform derived from the shared key:

TCP  client -> server   [ prelude 64B ][ nonce 12B ][ ChaCha20-XOR(TLS stream) ]
     server -> client                               [ ChaCha20-XOR(TLS stream) ]

UDP  each datagram      [ nonce 12B ][ ChaCha20-XOR(QUIC datagram) ]

Native chaining

A Portal can open the next Nowhere hop directly:

nowhere \
  "portal://relay-key@:2000?next=origin-key@origin.example:2000&up=udp&down=udp"

next is lazy, mutually exclusive with outbound socks, and bounded to seven hops.

Live operations

Nowhere TUI showing live traffic histories, connection and carrier metrics, anonymous access logs, runtime events, filtering, pause, and help

The read-only TUI discovers local Portal and Vector instances. It presents traffic, carrier, process, and anonymized event data without controlling their lifecycle. Third-party clients use the same telemetry contract.

Public deployment

The local examples disable certificate verification by omitting sni. Public deployments should use a trusted certificate and verified server name:

nowhere "portal://change-me@:2000?tls=2&crt=/etc/nowhere/cert.pem&key=/etc/nowhere/key.pem"
nowhere "vector://change-me@portal.example:2000?sni=portal.example&socks=127.0.0.1:1080"

Documentation

Guide Covers
Quick start Build, run, and connect
Ecosystem Clients, deployment and control tools, and share links
Configuration Service URLs, options, chaining, and environment variables
Wire protocol Authentication, flows, Mux, and Morph
Security Certificate verification and trust boundaries
Operations Deployment and runtime behavior
Platforms Supported targets and platform differences
Telemetry Local discovery and monitoring integrations

See the documentation index for the complete reference.

Development

Run the standard checks on a supported host:

cargo fmt --all -- --check
cargo test --all-targets --locked
cargo clippy --all-targets --locked -- -D warnings
cargo build --release --locked

On macOS, Apple Container provides the reusable Linux check environment:

./scripts/check-linux.sh

CI covers Linux, macOS, and Windows. Release packaging covers Linux GNU/musl on x86-64 and AArch64, macOS on Apple Silicon, and Windows x86-64 MSVC. Protocol changes must update the wire document and protocol vectors together.

License

Nowhere is licensed under the GNU General Public License v3.0.


© 2026 NodePassProject. All rights reserved.

About

A cross-platform relay that composes TLS/TCP and QUIC/UDP independently for every flow.

Topics

Resources

Security policy

Stars

453 stars

Watchers

27 watching

Forks

Releases

Packages

Contributors

Languages