Skip to content
  • MangoFly

    A self-hosted WireGuard mesh. Devices connect straight to each other; the coordination server is one binary and a SQLite file, and never sees their traffic.

    encrypted WireGuard · peer to peerLaptopbehind home NATServerin a datacentrePhoneon mobile datacoordination serverone binary · one SQLite filecontrol plane only (TLS)keys · tunnel addresses · peer lists · sealed ICE candidatesholds no private keys · carries no traffic · cannot decryptdatacontrol
  • MangoDock

    Docker management with nothing on the hosts. Reaches each daemon over an ordinary SSH session — no agent to install, no port to open.

    The MangoDock dashboard showing three host cards with container state counts, CPU and memory gauges, a usage history and recent events
  • MangoWiFi

    A Wi-Fi 6/7/8 test bench. One binary runs as Console or Agent either side of the access point under test, measuring latency under real load.

    AP under testWi-Fi 6 / 6E / 7Agentstation side · real radioLAN receiveriperf3 -sConsoleUI · orchestrates · probes
  • Blog
  • Nothing phones home

    No telemetry, no analytics, no crash reporter, no account login. Check it with a packet capture on your own network.

    Download MangoSSH
  • Project
  • Download
  • Hardware setup

    The bench: MediaTek cards, the two PCs, the AP and the optional RF gear.

    over the air — the path under testprobe crosses here in both directionsAgent PCLinux · kernel 6.7+MT7925 · M.2 / PCIeeth0AP under testWi-Fi 6 / 6E / 7LANwired-RF alternativeSMA cables + programmable attenuatorreplaces the arc above · repeatable · what roaming needsLAN switchConsole PCthe UI · runs the probeeth0LAN receiveriperf3 -s · port 5201eth0EthernetRFoptionalws 7745 · udp 7746 (ws+1) · iperf3 5201

    Three machines and the access point. Only the Agent has real requirements, because it is the station whose radio every measurement depends on.

    Agent box — the station

    • Linux, kernel 6.7 or newer — The mt7925e driver landed in 6.7. An older kernel will not bind the card.
    • MediaTek MT7925 — PCIe or M.2, as the client-simulator radio. It is the card the project targets; the virtual-station work is sized around driving 20–50 simulated clients from this one radio.
    • A second radio, optionally — For passive capture alongside the run. Configured separately as the monitor radio.
    • iw, wpa_supplicant, iperf3 — On PATH. Baseline probes each binary's version rather than assuming it exists.
    • Two networks — Associated to the AP over the air, and reachable from the Console.

    Console box — the UI

    • Any desktop OS — The Tauri UI is OS-agnostic; only the radio code is pinned to Linux.
    • Wired to the AP's LAN side — This is what makes the probe cross the air exactly once in each direction.
    • Agent address, port and pair token — Entered in Settings. Without the token the Agent will not accept the connection.

    LAN receiver

    • Any Linux or Windows box — On the AP's wired side.
    • iperf3 -s on 5201 — Left listening. If it is absent the load step skips and the run says so.

    Optional RF gear

    • Programmable attenuator — A Mini-Circuits USB RCDAT or similar, for roaming work — it is what moves the station toward a cell edge repeatably.
    • SMA cabling — For wired-RF mode, where the repeatable baseline lives.
    • A second AP — Required by every MAPC row. Wi-Fi 8 station silicon is required by the Enhanced MLO rows.
    Setup: the target AP, the band and channel, and whether this is an over-the-air or wired-RF rig.

    Ports to leave open

    • TCP 7745 — Console to Agent, WebSocket control.
    • UDP 7746 — The probe echo. Always the WebSocket port plus one — change the port and this follows.
    • TCP 5201 — iperf3 on the LAN receiver.