Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
OpenFlux
English | Русский
Network stack research tool. TCP tunnel with pluggable transports.
Overview
Client (SOCKS5) --> Transport --> Exit Node --> Internet
Requirements
- Golang v. 1.26.3+ - is required for building desktop client / exit node binary (universal-bypass-tool);
- Android Native Development Kit (NDK) v.27.0.12077973+ - is required for building Android client binary;
- XCode v. 26.6+ - is required for building iOS client binary;
- Linux VPS / VDS exit node.
Overview
TCP packets are sent via Transport. Currently, there are two transports available:
- Yandex - sends packets via Yandex Docs cursor messages;
- Max - sends packets via WebRTC DataChannel.
Client side runs a SOCKS5 proxy, exit node decapsulates and forwards packets to destination point.
Structure
OpenFlux/
├── main.go # CLI entry (client / exit-node)
├── export_ios.go # cgo bridge for the iOS static library (build tag: ios)
├── transport/
│ ├── transport.go # Transport interface
│ ├── compressor.go # Compression wrapper
│ ├── yandex/ # Yandex Docs backend
│ └── oneme/ # MAX Messenger backend
├── tunnel/
│ ├── tunnel.go # TCP tunnel core
│ ├── endpoint.go # Virtual NIC
│ └── rawsocket_{linux,darwin,windows}.go # Raw socket (exit node), per-OS
├── socks5/ # SOCKS5 server
├── network/ # Checksums, packet parsing
├── utils/ # Logging
├── ios-app/ # SwiftUI iOS client (XcodeGen), links liboflux.a
├── core/ # OpenFlux core (submodule): liboflux.a is built from its mobile/ios
├── build_ios.sh # Build the iOS static library (liboflux.a) from core/
├── build_ios_app.sh # Build + archive + export the iOS app IPA
└── build_android.sh # Build the Android client binary
Build (desktop client / exit-node binary)
go mod tidy
go build -o universal-bypass-tool .
Build for Android (client binary)
export ANDROID_NDK_HOME=<your Android NDK path>
./build_android.sh
Build for iOS (client library)
The iOS library comes from the OpenFlux core in the core/ submodule
(core/mobile/ios): the same code the Android and desktop clients run, so the
app speaks the Session, falls back to classic nodes, and reads links exactly as
they do.
git submodule update --init core
export XCODE_PATH="<your Xcode.app path>" # optional, defaults to /Applications/Xcode.app
./build_ios.sh
Usage
1. Setting up exit node
- You must have root access on exit node machine;
- Only legacy Yandex document editor is supported (you can toggle this setting from the interface).
The exit node's TCP connections live in a userspace stack (gvisor), so the
kernel has no socket for them and would send an RST on every reply, tearing
the tunnel down. That RST must be suppressed — but do it scoped, not
host-wide. A blanket -j DROP on all outbound RSTs makes every closed port
answer with silence (scanners see filtered instead of closed) and stops
the host from resetting unrelated connections.
Recommended (scoped to a dedicated egress IP):
# give the box a second/alias IP for the tunnel, e.g. 203.0.113.10
sudo iptables -A OUTPUT -p tcp --tcp-flags RST RST -s 203.0.113.10 -j DROP
sudo ./universal-bypass-tool --exit-node --local-ip 203.0.113.10 \
--url "YOUR_YANDEX_DOC_URL" --debug
Even cleaner: run the exit node in its own network namespace / container so the
rule never touches the host's main services. Note that -m owner --uid-owner
does not work here — the tunnel-breaking RSTs are generated by the kernel
with no owning socket, so the owner match never fires.
Host-wide fallback (only on a single-purpose box, understanding the trade-off):
sudo iptables -A OUTPUT -p tcp --tcp-flags RST RST -j DROP
sudo ./universal-bypass-tool --exit-node --url "YOUR_YANDEX_DOC_URL" --debug
1. Setting up desktop client:
Setup commands for desktop client:
./universal-bypass-tool --client --url "YOUR_YANDEX_DOC_URL" --socks5 :1080 --debug
Then set up SOCKS5 proxy in your browser at localhost:1080.
Flags
| Flag | Default | Description |
|---|---|---|
--client |
Run as client | |
--exit-node |
Run as exit node | |
--socks5 |
:1080 |
SOCKS5 listen address |
--url |
https://localhost |
Document URL (Yandex Docs) |
--maxToken |
`` | Auth token (Max) |
--maxUid |
`` | User ID (Max) |
--debug |
false |
Enable verbose logging |
--transport |
yandex |
Select transport backend |
Implementing custom transports
You are free to implement the Transport interface from transport/transport.go and register your custom transport in main.go switch block.
License
This project is licensed under the GNU General Public License v3.0 or later. See LICENSE for the full text.
Third-party licenses are listed in NOTICE.
Disclaimer
Educational use only. Test on your own machines and networks.