Skip to content

feat(*): add macOS support - #254

Open
kmod-midori wants to merge 4 commits into
dndx:mainfrom
kmod-midori:macos-fastpath
Open

kmod-midori wants to merge 4 commits into
dndx:mainfrom
kmod-midori:macos-fastpath

Conversation

@kmod-midori

Copy link
Copy Markdown

Fix #62 and #171 by adding utun support missing in tokio-tun.

Tested with WireGuard via macOS client (26.6) and latest Linux server.

kmod-midori and others added 4 commits September 28, 2026 11:40
A fastpath socket is bound one syscall before it is connected to its peer, and macOS
hands an unconnected SO_REUSEPORT socket that shares the listening address every
datagram that arrives, whoever sent it. The macOS support worked around that by not
creating a fastpath socket at all, which left the main loop forwarding the upstream
traffic of every connection.

Keep the fastpath and look at where each datagram came from instead: one from anybody
other than the peer was picked up while the socket was still being set up and belongs
to another client, so it is dropped rather than passed to the wrong connection. That
leaves no macOS conditional in the client.

Measured through a local tunnel with 50 clients sending one datagram each: arrivals
spread over 0.4s lose nothing, a simultaneous burst loses the first datagram of around
12% of them, which is what dropping what a socket grabs while it is being set up costs.

Co-Authored-By: Claude Code <noreply@anthropic.com>
Diffing against upstream 6256f63 shows a few hunks that only reformatted or
reordered Linux-only code, plus a drive-by TTL fix in the client's connection
table that macOS does not need. Revert those so the port is the only change.

Co-Authored-By: Claude Code <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Build for mac m1 chip?

1 participant