freedom.go 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526
  1. package freedom
  2. import (
  3. "context"
  4. "crypto/rand"
  5. "io"
  6. "math/big"
  7. "time"
  8. "github.com/pires/go-proxyproto"
  9. "github.com/xtls/xray-core/common"
  10. "github.com/xtls/xray-core/common/buf"
  11. "github.com/xtls/xray-core/common/dice"
  12. "github.com/xtls/xray-core/common/errors"
  13. "github.com/xtls/xray-core/common/net"
  14. "github.com/xtls/xray-core/common/platform"
  15. "github.com/xtls/xray-core/common/retry"
  16. "github.com/xtls/xray-core/common/session"
  17. "github.com/xtls/xray-core/common/signal"
  18. "github.com/xtls/xray-core/common/task"
  19. "github.com/xtls/xray-core/core"
  20. "github.com/xtls/xray-core/features/dns"
  21. "github.com/xtls/xray-core/features/policy"
  22. "github.com/xtls/xray-core/features/stats"
  23. "github.com/xtls/xray-core/proxy"
  24. "github.com/xtls/xray-core/transport"
  25. "github.com/xtls/xray-core/transport/internet"
  26. "github.com/xtls/xray-core/transport/internet/stat"
  27. "github.com/xtls/xray-core/transport/internet/tls"
  28. )
  29. var useSplice bool
  30. func init() {
  31. common.Must(common.RegisterConfig((*Config)(nil), func(ctx context.Context, config interface{}) (interface{}, error) {
  32. h := new(Handler)
  33. if err := core.RequireFeatures(ctx, func(pm policy.Manager, d dns.Client) error {
  34. return h.Init(config.(*Config), pm, d)
  35. }); err != nil {
  36. return nil, err
  37. }
  38. return h, nil
  39. }))
  40. const defaultFlagValue = "NOT_DEFINED_AT_ALL"
  41. value := platform.NewEnvFlag(platform.UseFreedomSplice).GetValue(func() string { return defaultFlagValue })
  42. switch value {
  43. case defaultFlagValue, "auto", "enable":
  44. useSplice = true
  45. }
  46. }
  47. // Handler handles Freedom connections.
  48. type Handler struct {
  49. policyManager policy.Manager
  50. dns dns.Client
  51. config *Config
  52. }
  53. // Init initializes the Handler with necessary parameters.
  54. func (h *Handler) Init(config *Config, pm policy.Manager, d dns.Client) error {
  55. h.config = config
  56. h.policyManager = pm
  57. h.dns = d
  58. return nil
  59. }
  60. func (h *Handler) policy() policy.Session {
  61. p := h.policyManager.ForLevel(h.config.UserLevel)
  62. return p
  63. }
  64. func (h *Handler) resolveIP(ctx context.Context, domain string, localAddr net.Address) net.Address {
  65. ips, err := h.dns.LookupIP(domain, dns.IPOption{
  66. IPv4Enable: (localAddr == nil || localAddr.Family().IsIPv4()) && h.config.preferIP4(),
  67. IPv6Enable: (localAddr == nil || localAddr.Family().IsIPv6()) && h.config.preferIP6(),
  68. })
  69. { // Resolve fallback
  70. if (len(ips) == 0 || err != nil) && h.config.hasFallback() && localAddr == nil {
  71. ips, err = h.dns.LookupIP(domain, dns.IPOption{
  72. IPv4Enable: h.config.fallbackIP4(),
  73. IPv6Enable: h.config.fallbackIP6(),
  74. })
  75. }
  76. }
  77. if err != nil {
  78. errors.LogInfoInner(ctx, err, "failed to get IP address for domain ", domain)
  79. }
  80. if len(ips) == 0 {
  81. return nil
  82. }
  83. return net.IPAddress(ips[dice.Roll(len(ips))])
  84. }
  85. func isValidAddress(addr *net.IPOrDomain) bool {
  86. if addr == nil {
  87. return false
  88. }
  89. a := addr.AsAddress()
  90. return a != net.AnyIP
  91. }
  92. // Process implements proxy.Outbound.
  93. func (h *Handler) Process(ctx context.Context, link *transport.Link, dialer internet.Dialer) error {
  94. outbounds := session.OutboundsFromContext(ctx)
  95. ob := outbounds[len(outbounds)-1]
  96. if !ob.Target.IsValid() {
  97. return errors.New("target not specified.")
  98. }
  99. ob.Name = "freedom"
  100. ob.CanSpliceCopy = 1
  101. inbound := session.InboundFromContext(ctx)
  102. destination := ob.Target
  103. UDPOverride := net.UDPDestination(nil, 0)
  104. if h.config.DestinationOverride != nil {
  105. server := h.config.DestinationOverride.Server
  106. if isValidAddress(server.Address) {
  107. destination.Address = server.Address.AsAddress()
  108. UDPOverride.Address = destination.Address
  109. }
  110. if server.Port != 0 {
  111. destination.Port = net.Port(server.Port)
  112. UDPOverride.Port = destination.Port
  113. }
  114. }
  115. input := link.Reader
  116. output := link.Writer
  117. var conn stat.Connection
  118. err := retry.ExponentialBackoff(5, 100).On(func() error {
  119. dialDest := destination
  120. if h.config.hasStrategy() && dialDest.Address.Family().IsDomain() {
  121. ip := h.resolveIP(ctx, dialDest.Address.Domain(), dialer.Address())
  122. if ip != nil {
  123. dialDest = net.Destination{
  124. Network: dialDest.Network,
  125. Address: ip,
  126. Port: dialDest.Port,
  127. }
  128. errors.LogInfo(ctx, "dialing to ", dialDest)
  129. } else if h.config.forceIP() {
  130. return dns.ErrEmptyResponse
  131. }
  132. }
  133. rawConn, err := dialer.Dial(ctx, dialDest)
  134. if err != nil {
  135. return err
  136. }
  137. if h.config.ProxyProtocol > 0 && h.config.ProxyProtocol <= 2 {
  138. version := byte(h.config.ProxyProtocol)
  139. srcAddr := inbound.Source.RawNetAddr()
  140. dstAddr := rawConn.RemoteAddr()
  141. header := proxyproto.HeaderProxyFromAddrs(version, srcAddr, dstAddr)
  142. if _, err = header.WriteTo(rawConn); err != nil {
  143. rawConn.Close()
  144. return err
  145. }
  146. }
  147. conn = rawConn
  148. return nil
  149. })
  150. if err != nil {
  151. return errors.New("failed to open connection to ", destination).Base(err)
  152. }
  153. defer conn.Close()
  154. errors.LogInfo(ctx, "connection opened to ", destination, ", local endpoint ", conn.LocalAddr(), ", remote endpoint ", conn.RemoteAddr())
  155. var newCtx context.Context
  156. var newCancel context.CancelFunc
  157. if session.TimeoutOnlyFromContext(ctx) {
  158. newCtx, newCancel = context.WithCancel(context.Background())
  159. }
  160. plcy := h.policy()
  161. ctx, cancel := context.WithCancel(ctx)
  162. timer := signal.CancelAfterInactivity(ctx, func() {
  163. cancel()
  164. if newCancel != nil {
  165. newCancel()
  166. }
  167. }, plcy.Timeouts.ConnectionIdle)
  168. requestDone := func() error {
  169. defer timer.SetTimeout(plcy.Timeouts.DownlinkOnly)
  170. var writer buf.Writer
  171. if destination.Network == net.Network_TCP {
  172. if h.config.Fragment != nil {
  173. errors.LogDebug(ctx, "FRAGMENT", h.config.Fragment.PacketsFrom, h.config.Fragment.PacketsTo, h.config.Fragment.LengthMin, h.config.Fragment.LengthMax,
  174. h.config.Fragment.IntervalMin, h.config.Fragment.IntervalMax)
  175. writer = buf.NewWriter(&FragmentWriter{
  176. fragment: h.config.Fragment,
  177. writer: conn,
  178. })
  179. } else {
  180. writer = buf.NewWriter(conn)
  181. }
  182. } else {
  183. writer = NewPacketWriter(conn, h, ctx, UDPOverride)
  184. if h.config.Noises != nil {
  185. errors.LogDebug(ctx, "NOISE", h.config.Noises)
  186. writer = &NoisePacketWriter{
  187. Writer: writer,
  188. noises: h.config.Noises,
  189. firstWrite: true,
  190. UDPOverride: UDPOverride,
  191. }
  192. }
  193. }
  194. if err := buf.Copy(input, writer, buf.UpdateActivity(timer)); err != nil {
  195. return errors.New("failed to process request").Base(err)
  196. }
  197. return nil
  198. }
  199. responseDone := func() error {
  200. defer timer.SetTimeout(plcy.Timeouts.UplinkOnly)
  201. if destination.Network == net.Network_TCP {
  202. var writeConn net.Conn
  203. var inTimer *signal.ActivityTimer
  204. if inbound := session.InboundFromContext(ctx); inbound != nil && inbound.Conn != nil && useSplice {
  205. writeConn = inbound.Conn
  206. inTimer = inbound.Timer
  207. }
  208. if !isTLSConn(conn) { // it would be tls conn in special use case of MITM, we need to let link handle traffic
  209. return proxy.CopyRawConnIfExist(ctx, conn, writeConn, link.Writer, timer, inTimer)
  210. }
  211. }
  212. var reader buf.Reader
  213. if destination.Network == net.Network_TCP {
  214. reader = buf.NewReader(conn)
  215. } else {
  216. reader = NewPacketReader(conn, UDPOverride)
  217. }
  218. if err := buf.Copy(reader, output, buf.UpdateActivity(timer)); err != nil {
  219. return errors.New("failed to process response").Base(err)
  220. }
  221. return nil
  222. }
  223. if newCtx != nil {
  224. ctx = newCtx
  225. }
  226. if err := task.Run(ctx, requestDone, task.OnSuccess(responseDone, task.Close(output))); err != nil {
  227. return errors.New("connection ends").Base(err)
  228. }
  229. return nil
  230. }
  231. func isTLSConn(conn stat.Connection) bool {
  232. if conn != nil {
  233. statConn, ok := conn.(*stat.CounterConnection)
  234. if ok {
  235. conn = statConn.Connection
  236. }
  237. if _, ok := conn.(*tls.Conn); ok {
  238. return true
  239. }
  240. }
  241. return false
  242. }
  243. func NewPacketReader(conn net.Conn, UDPOverride net.Destination) buf.Reader {
  244. iConn := conn
  245. statConn, ok := iConn.(*stat.CounterConnection)
  246. if ok {
  247. iConn = statConn.Connection
  248. }
  249. var counter stats.Counter
  250. if statConn != nil {
  251. counter = statConn.ReadCounter
  252. }
  253. if c, ok := iConn.(*internet.PacketConnWrapper); ok && UDPOverride.Address == nil && UDPOverride.Port == 0 {
  254. return &PacketReader{
  255. PacketConnWrapper: c,
  256. Counter: counter,
  257. }
  258. }
  259. return &buf.PacketReader{Reader: conn}
  260. }
  261. type PacketReader struct {
  262. *internet.PacketConnWrapper
  263. stats.Counter
  264. }
  265. func (r *PacketReader) ReadMultiBuffer() (buf.MultiBuffer, error) {
  266. b := buf.New()
  267. b.Resize(0, buf.Size)
  268. n, d, err := r.PacketConnWrapper.ReadFrom(b.Bytes())
  269. if err != nil {
  270. b.Release()
  271. return nil, err
  272. }
  273. b.Resize(0, int32(n))
  274. b.UDP = &net.Destination{
  275. Address: net.IPAddress(d.(*net.UDPAddr).IP),
  276. Port: net.Port(d.(*net.UDPAddr).Port),
  277. Network: net.Network_UDP,
  278. }
  279. if r.Counter != nil {
  280. r.Counter.Add(int64(n))
  281. }
  282. return buf.MultiBuffer{b}, nil
  283. }
  284. func NewPacketWriter(conn net.Conn, h *Handler, ctx context.Context, UDPOverride net.Destination) buf.Writer {
  285. iConn := conn
  286. statConn, ok := iConn.(*stat.CounterConnection)
  287. if ok {
  288. iConn = statConn.Connection
  289. }
  290. var counter stats.Counter
  291. if statConn != nil {
  292. counter = statConn.WriteCounter
  293. }
  294. if c, ok := iConn.(*internet.PacketConnWrapper); ok {
  295. return &PacketWriter{
  296. PacketConnWrapper: c,
  297. Counter: counter,
  298. Handler: h,
  299. Context: ctx,
  300. UDPOverride: UDPOverride,
  301. }
  302. }
  303. return &buf.SequentialWriter{Writer: conn}
  304. }
  305. type PacketWriter struct {
  306. *internet.PacketConnWrapper
  307. stats.Counter
  308. *Handler
  309. context.Context
  310. UDPOverride net.Destination
  311. }
  312. func (w *PacketWriter) WriteMultiBuffer(mb buf.MultiBuffer) error {
  313. for {
  314. mb2, b := buf.SplitFirst(mb)
  315. mb = mb2
  316. if b == nil {
  317. break
  318. }
  319. var n int
  320. var err error
  321. if b.UDP != nil {
  322. if w.UDPOverride.Address != nil {
  323. b.UDP.Address = w.UDPOverride.Address
  324. }
  325. if w.UDPOverride.Port != 0 {
  326. b.UDP.Port = w.UDPOverride.Port
  327. }
  328. if w.Handler.config.hasStrategy() && b.UDP.Address.Family().IsDomain() {
  329. ip := w.Handler.resolveIP(w.Context, b.UDP.Address.Domain(), nil)
  330. if ip != nil {
  331. b.UDP.Address = ip
  332. }
  333. }
  334. destAddr, _ := net.ResolveUDPAddr("udp", b.UDP.NetAddr())
  335. if destAddr == nil {
  336. b.Release()
  337. continue
  338. }
  339. n, err = w.PacketConnWrapper.WriteTo(b.Bytes(), destAddr)
  340. } else {
  341. n, err = w.PacketConnWrapper.Write(b.Bytes())
  342. }
  343. b.Release()
  344. if err != nil {
  345. buf.ReleaseMulti(mb)
  346. return err
  347. }
  348. if w.Counter != nil {
  349. w.Counter.Add(int64(n))
  350. }
  351. }
  352. return nil
  353. }
  354. type NoisePacketWriter struct {
  355. buf.Writer
  356. noises []*Noise
  357. firstWrite bool
  358. UDPOverride net.Destination
  359. }
  360. // MultiBuffer writer with Noise before first packet
  361. func (w *NoisePacketWriter) WriteMultiBuffer(mb buf.MultiBuffer) error {
  362. if w.firstWrite {
  363. w.firstWrite = false
  364. //Do not send Noise for dns requests(just to be safe)
  365. if w.UDPOverride.Port == 53 {
  366. return w.Writer.WriteMultiBuffer(mb)
  367. }
  368. var noise []byte
  369. var err error
  370. for _, n := range w.noises {
  371. //User input string or base64 encoded string
  372. if n.StrNoise != nil {
  373. noise = n.StrNoise
  374. } else {
  375. //Random noise
  376. noise, err = GenerateRandomBytes(randBetween(int64(n.LengthMin),
  377. int64(n.LengthMax)))
  378. }
  379. if err != nil {
  380. return err
  381. }
  382. w.Writer.WriteMultiBuffer(buf.MultiBuffer{buf.FromBytes(noise)})
  383. if n.DelayMin != 0 {
  384. time.Sleep(time.Duration(randBetween(int64(n.DelayMin), int64(n.DelayMax))) * time.Millisecond)
  385. }
  386. }
  387. }
  388. return w.Writer.WriteMultiBuffer(mb)
  389. }
  390. type FragmentWriter struct {
  391. fragment *Fragment
  392. writer io.Writer
  393. count uint64
  394. }
  395. func (f *FragmentWriter) Write(b []byte) (int, error) {
  396. f.count++
  397. if f.fragment.PacketsFrom == 0 && f.fragment.PacketsTo == 1 {
  398. if f.count != 1 || len(b) <= 5 || b[0] != 22 {
  399. return f.writer.Write(b)
  400. }
  401. recordLen := 5 + ((int(b[3]) << 8) | int(b[4]))
  402. if len(b) < recordLen { // maybe already fragmented somehow
  403. return f.writer.Write(b)
  404. }
  405. data := b[5:recordLen]
  406. buf := make([]byte, 1024)
  407. var hello []byte
  408. for from := 0; ; {
  409. to := from + int(randBetween(int64(f.fragment.LengthMin), int64(f.fragment.LengthMax)))
  410. if to > len(data) {
  411. to = len(data)
  412. }
  413. copy(buf[:3], b)
  414. copy(buf[5:], data[from:to])
  415. l := to - from
  416. from = to
  417. buf[3] = byte(l >> 8)
  418. buf[4] = byte(l)
  419. if f.fragment.IntervalMax == 0 { // combine fragmented tlshello if interval is 0
  420. hello = append(hello, buf[:5+l]...)
  421. } else {
  422. _, err := f.writer.Write(buf[:5+l])
  423. time.Sleep(time.Duration(randBetween(int64(f.fragment.IntervalMin), int64(f.fragment.IntervalMax))) * time.Millisecond)
  424. if err != nil {
  425. return 0, err
  426. }
  427. }
  428. if from == len(data) {
  429. if len(hello) > 0 {
  430. _, err := f.writer.Write(hello)
  431. if err != nil {
  432. return 0, err
  433. }
  434. }
  435. if len(b) > recordLen {
  436. n, err := f.writer.Write(b[recordLen:])
  437. if err != nil {
  438. return recordLen + n, err
  439. }
  440. }
  441. return len(b), nil
  442. }
  443. }
  444. }
  445. if f.fragment.PacketsFrom != 0 && (f.count < f.fragment.PacketsFrom || f.count > f.fragment.PacketsTo) {
  446. return f.writer.Write(b)
  447. }
  448. for from := 0; ; {
  449. to := from + int(randBetween(int64(f.fragment.LengthMin), int64(f.fragment.LengthMax)))
  450. if to > len(b) {
  451. to = len(b)
  452. }
  453. n, err := f.writer.Write(b[from:to])
  454. from += n
  455. time.Sleep(time.Duration(randBetween(int64(f.fragment.IntervalMin), int64(f.fragment.IntervalMax))) * time.Millisecond)
  456. if err != nil {
  457. return from, err
  458. }
  459. if from >= len(b) {
  460. return from, nil
  461. }
  462. }
  463. }
  464. // stolen from github.com/xtls/xray-core/transport/internet/reality
  465. func randBetween(left int64, right int64) int64 {
  466. if left == right {
  467. return left
  468. }
  469. bigInt, _ := rand.Int(rand.Reader, big.NewInt(right-left))
  470. return left + bigInt.Int64()
  471. }
  472. func GenerateRandomBytes(n int64) ([]byte, error) {
  473. b := make([]byte, n)
  474. _, err := rand.Read(b)
  475. // Note that err == nil only if we read len(b) bytes.
  476. if err != nil {
  477. return nil, err
  478. }
  479. return b, nil
  480. }