DragonTCP Lite VPN
This version deliberately returns to the lightweight DragonTCP architecture.
DragonTCP itself is an HTTP/HTTPS CONNECT proxy tunnel; Android's VpnService
is only the local adapter that feeds normal app TCP traffic into that proxy.
Architecture
Android apps
|
| IPv4 TCP / DNS packets
v
Android VpnService TUN
|
| lightweight userspace TCP adapter
v
127.0.0.1:8080 HTTP CONNECT
|
v
DragonTCP Go client
|
| adaptive records + mandatory XOR 0xAD
| TCP/53
v
DragonTCP Lite server
|
v
Internet destination
There is no Linux TUN, no server NAT, no raw-IP DragonTCP protocol, and no packet batching on the DragonTCP server. The remote side is the same style of lightweight stream proxy that worked in the earlier Termux tests.
Defaults
Android:
Server port: 53/TCP
Token: optional / empty allowed
Local proxy: 127.0.0.1:8080
Pollers: 1 (fixed)
Reconnect Every: 1
Chunk Start: Max Chunk
Chunk Min: 32
Chunk Max: 1,048,576 bytes
Chunk Grow After: 16 successes
Chunk timeout: 2 seconds
XOR: 0xAD, mandatory
DNS: 1.1.1.1 through DNS-over-TCP through DragonTCP
The Android log is intentionally quiet. It shows service state, actual errors, and DragonTCP adaptive changes such as:
adaptive upload chunk: 65536 -> 32768 after transport failure
adaptive download chunk: 32 -> 64 after stable success
It does not redraw the screen or print periodic traffic statistics.
Android traffic behavior
- IPv4 TCP: forwarded through DragonTCP.
- DNS UDP/53: converted to DNS-over-TCP and sent to
1.1.1.1through the local DragonTCP HTTP CONNECT proxy. - IPv6: captured by the VPN and dropped so it cannot bypass DragonTCP.
- Other UDP: not forwarded in this HTTP CONNECT build.
- ICMP/ping: not forwarded.
This trade-off keeps DragonTCP itself lightweight and stream-oriented.
Start the server
Port 53 is privileged on Linux, so run as root:
sudo ./dragontcp-lite-server-linux-amd64 --chunk-max 1048576
No token is required by default. To require one:
sudo ./dragontcp-lite-server-linux-amd64 --token 'SECRET' --chunk-max 1048576
The Android Token field must contain the same value.
If you do not want to run the binary as root:
sudo setcap cap_net_bind_service=+ep ./dragontcp-lite-server-linux-amd64
./dragontcp-lite-server-linux-amd64
If TCP/53 is already occupied by a DNS resolver, free that port first.
Android usage
- Install
DragonTCP-LiteVPN-arm64.apk. - Enter the server address.
- Leave Port at
53. - Leave Token empty if the server was started without
--token. - Keep
Reconnect every = 1for restrictive networks. - Press CONNECT and approve Android's VPN dialog.
- Press STOP to terminate both the TUN adapter and DragonTCP core.
The app excludes its own UID from the VPN, so the DragonTCP TCP/53 transport uses the physical/mobile network and does not loop into its own TUN interface.
Build everything from source
Requirements:
- Go 1.22+
- JDK 17+
- Android SDK platform + build-tools (35 works)
- Android 10 / API 29 or newer on the phone
- Kotlin compiler 1.9.x distribution containing
kotlinx-coroutines-core-jvm.jar zip
Example environment:
export ANDROID_SDK_ROOT="$HOME/Android/Sdk"
export KOTLIN_HOME="$HOME/.sdkman/candidates/kotlin/current"
Then:
./build_all.sh
Outputs:
bin/dragontcp-lite-server-linux-amd64
bin/dragontcp-lite-server-linux-arm64
android/lib/arm64-v8a/libdragontcp_client.so
android/build/DragonTCP-LiteVPN-arm64.apk
libdragontcp_client.so is intentionally the Android ARM64 Go executable stored
in the APK native-library directory. DragonService launches it with
ProcessBuilder; it is not JNI.
Build only the Go core/server
./build_core.sh
Build only the APK
After the core has been built:
cd android
./build_apk.sh
The script creates a local debug signing key if one does not already exist. For production distribution, supply your own keystore/signing process.
Source layout
core/ DragonTCP Go client/server
android/src/com/dragontcp/client/ Android UI + VpnService
android/src/tech/xvanturing/... Lightweight TUN-to-proxy stack
android/lib/arm64-v8a/ Embedded DragonTCP Android core
licenses/ Third-party licenses
Third-party stack
The userspace Android TUN/TCP adapter is adapted from the Apache-2.0-licensed
FreeProxy project. See THIRD_PARTY_NOTICES.md and
licenses/FreeProxy-APACHE-2.0.txt.
Validation performed for this package
- Go unit/build checks: PASS.
- Empty-token client/server protocol: PASS.
- Fixed 1 poller + reconnect every 1: PASS.
- 8 MiB HTTP transfer through local DragonTCP proxy: SHA-256 exact.
- Kotlin TUN adapter compilation: PASS.
- Android Java service/UI compilation: PASS.
- ARM64 Android DragonTCP core build: PASS.
- APK resource/DEX/native packaging: PASS.
- APK signature verification (v3): PASS.
- Supplied APK uses the same signing certificate as the previous v7 APK (versionCode 8), so it can be installed as an in-place update over v7.
A physical Android device is still required to validate the final VpnService path against a real mobile network.