|
@@ -2,14 +2,11 @@ package route
|
|
|
|
|
|
import (
|
|
|
"context"
|
|
|
- "io"
|
|
|
"net"
|
|
|
- "net/http"
|
|
|
"net/netip"
|
|
|
"net/url"
|
|
|
"os"
|
|
|
"os/user"
|
|
|
- "path/filepath"
|
|
|
"strings"
|
|
|
"time"
|
|
|
|
|
@@ -37,7 +34,6 @@ import (
|
|
|
F "github.com/sagernet/sing/common/format"
|
|
|
M "github.com/sagernet/sing/common/metadata"
|
|
|
N "github.com/sagernet/sing/common/network"
|
|
|
- "github.com/sagernet/sing/common/rw"
|
|
|
"github.com/sagernet/sing/common/uot"
|
|
|
)
|
|
|
|
|
@@ -72,6 +68,7 @@ type Router struct {
|
|
|
outbounds []adapter.Outbound
|
|
|
outboundByTag map[string]adapter.Outbound
|
|
|
rules []adapter.Rule
|
|
|
+ ipRules []adapter.IPRule
|
|
|
defaultDetour string
|
|
|
defaultOutboundForConnection adapter.Outbound
|
|
|
defaultOutboundForPacketConnection adapter.Outbound
|
|
@@ -128,6 +125,7 @@ func NewRouter(
|
|
|
dnsLogger: logFactory.NewLogger("dns"),
|
|
|
outboundByTag: make(map[string]adapter.Outbound),
|
|
|
rules: make([]adapter.Rule, 0, len(options.Rules)),
|
|
|
+ ipRules: make([]adapter.IPRule, 0, len(options.IPRules)),
|
|
|
dnsRules: make([]adapter.DNSRule, 0, len(dnsOptions.Rules)),
|
|
|
needGeoIPDatabase: hasRule(options.Rules, isGeoIPRule) || hasDNSRule(dnsOptions.Rules, isGeoIPDNSRule),
|
|
|
needGeositeDatabase: hasRule(options.Rules, isGeositeRule) || hasDNSRule(dnsOptions.Rules, isGeositeDNSRule),
|
|
@@ -149,6 +147,13 @@ func NewRouter(
|
|
|
}
|
|
|
router.rules = append(router.rules, routeRule)
|
|
|
}
|
|
|
+ for i, ipRuleOptions := range options.IPRules {
|
|
|
+ ipRule, err := NewIPRule(router, router.logger, ipRuleOptions)
|
|
|
+ if err != nil {
|
|
|
+ return nil, E.Cause(err, "parse ip rule[", i, "]")
|
|
|
+ }
|
|
|
+ router.ipRules = append(router.ipRules, ipRule)
|
|
|
+ }
|
|
|
for i, dnsRuleOptions := range dnsOptions.Rules {
|
|
|
dnsRule, err := NewDNSRule(router, router.logger, dnsRuleOptions)
|
|
|
if err != nil {
|
|
@@ -156,6 +161,7 @@ func NewRouter(
|
|
|
}
|
|
|
router.dnsRules = append(router.dnsRules, dnsRule)
|
|
|
}
|
|
|
+
|
|
|
transports := make([]dns.Transport, len(dnsOptions.Servers))
|
|
|
dummyTransportMap := make(map[string]dns.Transport)
|
|
|
transportMap := make(map[string]dns.Transport)
|
|
@@ -516,27 +522,6 @@ func (r *Router) Close() error {
|
|
|
)
|
|
|
}
|
|
|
|
|
|
-func (r *Router) GeoIPReader() *geoip.Reader {
|
|
|
- return r.geoIPReader
|
|
|
-}
|
|
|
-
|
|
|
-func (r *Router) LoadGeosite(code string) (adapter.Rule, error) {
|
|
|
- rule, cached := r.geositeCache[code]
|
|
|
- if cached {
|
|
|
- return rule, nil
|
|
|
- }
|
|
|
- items, err := r.geositeReader.Read(code)
|
|
|
- if err != nil {
|
|
|
- return nil, err
|
|
|
- }
|
|
|
- rule, err = NewDefaultRule(r, nil, geosite.Compile(items))
|
|
|
- if err != nil {
|
|
|
- return nil, err
|
|
|
- }
|
|
|
- r.geositeCache[code] = rule
|
|
|
- return rule, nil
|
|
|
-}
|
|
|
-
|
|
|
func (r *Router) Outbound(tag string) (adapter.Outbound, bool) {
|
|
|
outbound, loaded := r.outboundByTag[tag]
|
|
|
return outbound, loaded
|
|
@@ -811,6 +796,10 @@ func (r *Router) Rules() []adapter.Rule {
|
|
|
return r.rules
|
|
|
}
|
|
|
|
|
|
+func (r *Router) IPRules() []adapter.IPRule {
|
|
|
+ return r.ipRules
|
|
|
+}
|
|
|
+
|
|
|
func (r *Router) NetworkMonitor() tun.NetworkUpdateMonitor {
|
|
|
return r.networkMonitor
|
|
|
}
|
|
@@ -846,239 +835,6 @@ func (r *Router) SetV2RayServer(server adapter.V2RayServer) {
|
|
|
r.v2rayServer = server
|
|
|
}
|
|
|
|
|
|
-func hasRule(rules []option.Rule, cond func(rule option.DefaultRule) bool) bool {
|
|
|
- for _, rule := range rules {
|
|
|
- switch rule.Type {
|
|
|
- case C.RuleTypeDefault:
|
|
|
- if cond(rule.DefaultOptions) {
|
|
|
- return true
|
|
|
- }
|
|
|
- case C.RuleTypeLogical:
|
|
|
- for _, subRule := range rule.LogicalOptions.Rules {
|
|
|
- if cond(subRule) {
|
|
|
- return true
|
|
|
- }
|
|
|
- }
|
|
|
- }
|
|
|
- }
|
|
|
- return false
|
|
|
-}
|
|
|
-
|
|
|
-func hasDNSRule(rules []option.DNSRule, cond func(rule option.DefaultDNSRule) bool) bool {
|
|
|
- for _, rule := range rules {
|
|
|
- switch rule.Type {
|
|
|
- case C.RuleTypeDefault:
|
|
|
- if cond(rule.DefaultOptions) {
|
|
|
- return true
|
|
|
- }
|
|
|
- case C.RuleTypeLogical:
|
|
|
- for _, subRule := range rule.LogicalOptions.Rules {
|
|
|
- if cond(subRule) {
|
|
|
- return true
|
|
|
- }
|
|
|
- }
|
|
|
- }
|
|
|
- }
|
|
|
- return false
|
|
|
-}
|
|
|
-
|
|
|
-func isGeoIPRule(rule option.DefaultRule) bool {
|
|
|
- return len(rule.SourceGeoIP) > 0 && common.Any(rule.SourceGeoIP, notPrivateNode) || len(rule.GeoIP) > 0 && common.Any(rule.GeoIP, notPrivateNode)
|
|
|
-}
|
|
|
-
|
|
|
-func isGeoIPDNSRule(rule option.DefaultDNSRule) bool {
|
|
|
- return len(rule.SourceGeoIP) > 0 && common.Any(rule.SourceGeoIP, notPrivateNode)
|
|
|
-}
|
|
|
-
|
|
|
-func isGeositeRule(rule option.DefaultRule) bool {
|
|
|
- return len(rule.Geosite) > 0
|
|
|
-}
|
|
|
-
|
|
|
-func isGeositeDNSRule(rule option.DefaultDNSRule) bool {
|
|
|
- return len(rule.Geosite) > 0
|
|
|
-}
|
|
|
-
|
|
|
-func isProcessRule(rule option.DefaultRule) bool {
|
|
|
- return len(rule.ProcessName) > 0 || len(rule.ProcessPath) > 0 || len(rule.PackageName) > 0 || len(rule.User) > 0 || len(rule.UserID) > 0
|
|
|
-}
|
|
|
-
|
|
|
-func isProcessDNSRule(rule option.DefaultDNSRule) bool {
|
|
|
- return len(rule.ProcessName) > 0 || len(rule.ProcessPath) > 0 || len(rule.PackageName) > 0 || len(rule.User) > 0 || len(rule.UserID) > 0
|
|
|
-}
|
|
|
-
|
|
|
-func notPrivateNode(code string) bool {
|
|
|
- return code != "private"
|
|
|
-}
|
|
|
-
|
|
|
-func (r *Router) prepareGeoIPDatabase() error {
|
|
|
- var geoPath string
|
|
|
- if r.geoIPOptions.Path != "" {
|
|
|
- geoPath = r.geoIPOptions.Path
|
|
|
- } else {
|
|
|
- geoPath = "geoip.db"
|
|
|
- if foundPath, loaded := C.FindPath(geoPath); loaded {
|
|
|
- geoPath = foundPath
|
|
|
- }
|
|
|
- }
|
|
|
- geoPath = C.BasePath(geoPath)
|
|
|
- if !rw.FileExists(geoPath) {
|
|
|
- r.logger.Warn("geoip database not exists: ", geoPath)
|
|
|
- var err error
|
|
|
- for attempts := 0; attempts < 3; attempts++ {
|
|
|
- err = r.downloadGeoIPDatabase(geoPath)
|
|
|
- if err == nil {
|
|
|
- break
|
|
|
- }
|
|
|
- r.logger.Error("download geoip database: ", err)
|
|
|
- os.Remove(geoPath)
|
|
|
- // time.Sleep(10 * time.Second)
|
|
|
- }
|
|
|
- if err != nil {
|
|
|
- return err
|
|
|
- }
|
|
|
- }
|
|
|
- geoReader, codes, err := geoip.Open(geoPath)
|
|
|
- if err != nil {
|
|
|
- return E.Cause(err, "open geoip database")
|
|
|
- }
|
|
|
- r.logger.Info("loaded geoip database: ", len(codes), " codes")
|
|
|
- r.geoIPReader = geoReader
|
|
|
- return nil
|
|
|
-}
|
|
|
-
|
|
|
-func (r *Router) prepareGeositeDatabase() error {
|
|
|
- var geoPath string
|
|
|
- if r.geositeOptions.Path != "" {
|
|
|
- geoPath = r.geositeOptions.Path
|
|
|
- } else {
|
|
|
- geoPath = "geosite.db"
|
|
|
- if foundPath, loaded := C.FindPath(geoPath); loaded {
|
|
|
- geoPath = foundPath
|
|
|
- }
|
|
|
- }
|
|
|
- geoPath = C.BasePath(geoPath)
|
|
|
- if !rw.FileExists(geoPath) {
|
|
|
- r.logger.Warn("geosite database not exists: ", geoPath)
|
|
|
- var err error
|
|
|
- for attempts := 0; attempts < 3; attempts++ {
|
|
|
- err = r.downloadGeositeDatabase(geoPath)
|
|
|
- if err == nil {
|
|
|
- break
|
|
|
- }
|
|
|
- r.logger.Error("download geosite database: ", err)
|
|
|
- os.Remove(geoPath)
|
|
|
- // time.Sleep(10 * time.Second)
|
|
|
- }
|
|
|
- if err != nil {
|
|
|
- return err
|
|
|
- }
|
|
|
- }
|
|
|
- geoReader, codes, err := geosite.Open(geoPath)
|
|
|
- if err == nil {
|
|
|
- r.logger.Info("loaded geosite database: ", len(codes), " codes")
|
|
|
- r.geositeReader = geoReader
|
|
|
- } else {
|
|
|
- return E.Cause(err, "open geosite database")
|
|
|
- }
|
|
|
- return nil
|
|
|
-}
|
|
|
-
|
|
|
-func (r *Router) downloadGeoIPDatabase(savePath string) error {
|
|
|
- var downloadURL string
|
|
|
- if r.geoIPOptions.DownloadURL != "" {
|
|
|
- downloadURL = r.geoIPOptions.DownloadURL
|
|
|
- } else {
|
|
|
- downloadURL = "https://github.com/SagerNet/sing-geoip/releases/latest/download/geoip.db"
|
|
|
- }
|
|
|
- r.logger.Info("downloading geoip database")
|
|
|
- var detour adapter.Outbound
|
|
|
- if r.geoIPOptions.DownloadDetour != "" {
|
|
|
- outbound, loaded := r.Outbound(r.geoIPOptions.DownloadDetour)
|
|
|
- if !loaded {
|
|
|
- return E.New("detour outbound not found: ", r.geoIPOptions.DownloadDetour)
|
|
|
- }
|
|
|
- detour = outbound
|
|
|
- } else {
|
|
|
- detour = r.defaultOutboundForConnection
|
|
|
- }
|
|
|
-
|
|
|
- if parentDir := filepath.Dir(savePath); parentDir != "" {
|
|
|
- os.MkdirAll(parentDir, 0o755)
|
|
|
- }
|
|
|
-
|
|
|
- saveFile, err := os.OpenFile(savePath, os.O_CREATE|os.O_WRONLY, 0o644)
|
|
|
- if err != nil {
|
|
|
- return E.Cause(err, "open output file: ", downloadURL)
|
|
|
- }
|
|
|
- defer saveFile.Close()
|
|
|
-
|
|
|
- httpClient := &http.Client{
|
|
|
- Transport: &http.Transport{
|
|
|
- ForceAttemptHTTP2: true,
|
|
|
- TLSHandshakeTimeout: 5 * time.Second,
|
|
|
- DialContext: func(ctx context.Context, network, addr string) (net.Conn, error) {
|
|
|
- return detour.DialContext(ctx, network, M.ParseSocksaddr(addr))
|
|
|
- },
|
|
|
- },
|
|
|
- }
|
|
|
- defer httpClient.CloseIdleConnections()
|
|
|
- response, err := httpClient.Get(downloadURL)
|
|
|
- if err != nil {
|
|
|
- return err
|
|
|
- }
|
|
|
- defer response.Body.Close()
|
|
|
- _, err = io.Copy(saveFile, response.Body)
|
|
|
- return err
|
|
|
-}
|
|
|
-
|
|
|
-func (r *Router) downloadGeositeDatabase(savePath string) error {
|
|
|
- var downloadURL string
|
|
|
- if r.geositeOptions.DownloadURL != "" {
|
|
|
- downloadURL = r.geositeOptions.DownloadURL
|
|
|
- } else {
|
|
|
- downloadURL = "https://github.com/SagerNet/sing-geosite/releases/latest/download/geosite.db"
|
|
|
- }
|
|
|
- r.logger.Info("downloading geosite database")
|
|
|
- var detour adapter.Outbound
|
|
|
- if r.geositeOptions.DownloadDetour != "" {
|
|
|
- outbound, loaded := r.Outbound(r.geositeOptions.DownloadDetour)
|
|
|
- if !loaded {
|
|
|
- return E.New("detour outbound not found: ", r.geositeOptions.DownloadDetour)
|
|
|
- }
|
|
|
- detour = outbound
|
|
|
- } else {
|
|
|
- detour = r.defaultOutboundForConnection
|
|
|
- }
|
|
|
-
|
|
|
- if parentDir := filepath.Dir(savePath); parentDir != "" {
|
|
|
- os.MkdirAll(parentDir, 0o755)
|
|
|
- }
|
|
|
-
|
|
|
- saveFile, err := os.OpenFile(savePath, os.O_CREATE|os.O_WRONLY, 0o644)
|
|
|
- if err != nil {
|
|
|
- return E.Cause(err, "open output file: ", downloadURL)
|
|
|
- }
|
|
|
- defer saveFile.Close()
|
|
|
-
|
|
|
- httpClient := &http.Client{
|
|
|
- Transport: &http.Transport{
|
|
|
- ForceAttemptHTTP2: true,
|
|
|
- TLSHandshakeTimeout: 5 * time.Second,
|
|
|
- DialContext: func(ctx context.Context, network, addr string) (net.Conn, error) {
|
|
|
- return detour.DialContext(ctx, network, M.ParseSocksaddr(addr))
|
|
|
- },
|
|
|
- },
|
|
|
- }
|
|
|
- defer httpClient.CloseIdleConnections()
|
|
|
- response, err := httpClient.Get(downloadURL)
|
|
|
- if err != nil {
|
|
|
- return err
|
|
|
- }
|
|
|
- defer response.Body.Close()
|
|
|
- _, err = io.Copy(saveFile, response.Body)
|
|
|
- return err
|
|
|
-}
|
|
|
-
|
|
|
func (r *Router) OnPackagesUpdated(packages int, sharedUsers int) {
|
|
|
r.logger.Info("updated packages list: ", packages, " packages, ", sharedUsers, " shared users")
|
|
|
}
|