https.go 6.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242
  1. package transport
  2. import (
  3. "bytes"
  4. "context"
  5. "errors"
  6. "io"
  7. "net"
  8. "net/http"
  9. "net/url"
  10. "strconv"
  11. "sync"
  12. "time"
  13. "github.com/sagernet/sing-box/adapter"
  14. "github.com/sagernet/sing-box/common/dialer"
  15. "github.com/sagernet/sing-box/common/tls"
  16. C "github.com/sagernet/sing-box/constant"
  17. "github.com/sagernet/sing-box/dns"
  18. "github.com/sagernet/sing-box/log"
  19. "github.com/sagernet/sing-box/option"
  20. "github.com/sagernet/sing/common"
  21. "github.com/sagernet/sing/common/buf"
  22. E "github.com/sagernet/sing/common/exceptions"
  23. "github.com/sagernet/sing/common/logger"
  24. M "github.com/sagernet/sing/common/metadata"
  25. N "github.com/sagernet/sing/common/network"
  26. aTLS "github.com/sagernet/sing/common/tls"
  27. sHTTP "github.com/sagernet/sing/protocol/http"
  28. mDNS "github.com/miekg/dns"
  29. "golang.org/x/net/http2"
  30. )
  31. const MimeType = "application/dns-message"
  32. var _ adapter.DNSTransport = (*HTTPSTransport)(nil)
  33. func RegisterHTTPS(registry *dns.TransportRegistry) {
  34. dns.RegisterTransport[option.RemoteHTTPSDNSServerOptions](registry, C.DNSTypeHTTPS, NewHTTPS)
  35. }
  36. type HTTPSTransport struct {
  37. dns.TransportAdapter
  38. logger logger.ContextLogger
  39. dialer N.Dialer
  40. destination *url.URL
  41. headers http.Header
  42. transportAccess sync.Mutex
  43. transport *http.Transport
  44. transportResetAt time.Time
  45. }
  46. func NewHTTPS(ctx context.Context, logger log.ContextLogger, tag string, options option.RemoteHTTPSDNSServerOptions) (adapter.DNSTransport, error) {
  47. transportDialer, err := dns.NewRemoteDialer(ctx, options.RemoteDNSServerOptions)
  48. if err != nil {
  49. return nil, err
  50. }
  51. tlsOptions := common.PtrValueOrDefault(options.TLS)
  52. tlsOptions.Enabled = true
  53. tlsConfig, err := tls.NewClient(ctx, logger, options.Server, tlsOptions)
  54. if err != nil {
  55. return nil, err
  56. }
  57. if common.Error(tlsConfig.STDConfig()) == nil && !common.Contains(tlsConfig.NextProtos(), http2.NextProtoTLS) {
  58. tlsConfig.SetNextProtos(append(tlsConfig.NextProtos(), http2.NextProtoTLS))
  59. }
  60. if !common.Contains(tlsConfig.NextProtos(), "http/1.1") {
  61. tlsConfig.SetNextProtos(append(tlsConfig.NextProtos(), "http/1.1"))
  62. }
  63. headers := options.Headers.Build()
  64. host := headers.Get("Host")
  65. if host != "" {
  66. headers.Del("Host")
  67. } else {
  68. if tlsConfig.ServerName() != "" {
  69. host = tlsConfig.ServerName()
  70. } else {
  71. host = options.Server
  72. }
  73. }
  74. destinationURL := url.URL{
  75. Scheme: "https",
  76. Host: host,
  77. }
  78. if destinationURL.Host == "" {
  79. destinationURL.Host = options.Server
  80. }
  81. if options.ServerPort != 0 && options.ServerPort != 443 {
  82. destinationURL.Host = net.JoinHostPort(destinationURL.Host, strconv.Itoa(int(options.ServerPort)))
  83. }
  84. path := options.Path
  85. if path == "" {
  86. path = "/dns-query"
  87. }
  88. err = sHTTP.URLSetPath(&destinationURL, path)
  89. if err != nil {
  90. return nil, err
  91. }
  92. serverAddr := options.DNSServerAddressOptions.Build()
  93. if serverAddr.Port == 0 {
  94. serverAddr.Port = 443
  95. }
  96. if !serverAddr.IsValid() {
  97. return nil, E.New("invalid server address: ", serverAddr)
  98. }
  99. return NewHTTPSRaw(
  100. dns.NewTransportAdapterWithRemoteOptions(C.DNSTypeHTTPS, tag, options.RemoteDNSServerOptions),
  101. logger,
  102. transportDialer,
  103. &destinationURL,
  104. headers,
  105. serverAddr,
  106. tlsConfig,
  107. ), nil
  108. }
  109. func NewHTTPSRaw(
  110. adapter dns.TransportAdapter,
  111. logger log.ContextLogger,
  112. dialer N.Dialer,
  113. destination *url.URL,
  114. headers http.Header,
  115. serverAddr M.Socksaddr,
  116. tlsConfig tls.Config,
  117. ) *HTTPSTransport {
  118. var transport *http.Transport
  119. if tlsConfig != nil {
  120. transport = &http.Transport{
  121. ForceAttemptHTTP2: true,
  122. DialTLSContext: func(ctx context.Context, network, addr string) (net.Conn, error) {
  123. tcpConn, hErr := dialer.DialContext(ctx, network, serverAddr)
  124. if hErr != nil {
  125. return nil, hErr
  126. }
  127. tlsConn, hErr := aTLS.ClientHandshake(ctx, tcpConn, tlsConfig)
  128. if hErr != nil {
  129. tcpConn.Close()
  130. return nil, hErr
  131. }
  132. return tlsConn, nil
  133. },
  134. }
  135. } else {
  136. transport = &http.Transport{
  137. DialContext: func(ctx context.Context, network, addr string) (net.Conn, error) {
  138. return dialer.DialContext(ctx, network, serverAddr)
  139. },
  140. }
  141. }
  142. return &HTTPSTransport{
  143. TransportAdapter: adapter,
  144. logger: logger,
  145. dialer: dialer,
  146. destination: destination,
  147. headers: headers,
  148. transport: transport,
  149. }
  150. }
  151. func (t *HTTPSTransport) Start(stage adapter.StartStage) error {
  152. if stage != adapter.StartStateStart {
  153. return nil
  154. }
  155. return dialer.InitializeDetour(t.dialer)
  156. }
  157. func (t *HTTPSTransport) Close() error {
  158. t.transportAccess.Lock()
  159. defer t.transportAccess.Unlock()
  160. t.transport.CloseIdleConnections()
  161. t.transport = t.transport.Clone()
  162. return nil
  163. }
  164. func (t *HTTPSTransport) Exchange(ctx context.Context, message *mDNS.Msg) (*mDNS.Msg, error) {
  165. startAt := time.Now()
  166. response, err := t.exchange(ctx, message)
  167. if err != nil {
  168. if errors.Is(err, context.DeadlineExceeded) {
  169. t.transportAccess.Lock()
  170. defer t.transportAccess.Unlock()
  171. if t.transportResetAt.After(startAt) {
  172. return nil, err
  173. }
  174. t.transport.CloseIdleConnections()
  175. t.transport = t.transport.Clone()
  176. t.transportResetAt = time.Now()
  177. }
  178. return nil, err
  179. }
  180. return response, nil
  181. }
  182. func (t *HTTPSTransport) exchange(ctx context.Context, message *mDNS.Msg) (*mDNS.Msg, error) {
  183. exMessage := *message
  184. exMessage.Id = 0
  185. exMessage.Compress = true
  186. requestBuffer := buf.NewSize(1 + message.Len())
  187. rawMessage, err := exMessage.PackBuffer(requestBuffer.FreeBytes())
  188. if err != nil {
  189. requestBuffer.Release()
  190. return nil, err
  191. }
  192. request, err := http.NewRequestWithContext(ctx, http.MethodPost, t.destination.String(), bytes.NewReader(rawMessage))
  193. if err != nil {
  194. requestBuffer.Release()
  195. return nil, err
  196. }
  197. request.Header = t.headers.Clone()
  198. request.Header.Set("Content-Type", MimeType)
  199. request.Header.Set("Accept", MimeType)
  200. response, err := t.transport.RoundTrip(request)
  201. requestBuffer.Release()
  202. if err != nil {
  203. return nil, err
  204. }
  205. defer response.Body.Close()
  206. if response.StatusCode != http.StatusOK {
  207. return nil, E.New("unexpected status: ", response.Status)
  208. }
  209. var responseMessage mDNS.Msg
  210. if response.ContentLength > 0 {
  211. responseBuffer := buf.NewSize(int(response.ContentLength))
  212. _, err = responseBuffer.ReadFullFrom(response.Body, int(response.ContentLength))
  213. if err != nil {
  214. return nil, err
  215. }
  216. err = responseMessage.Unpack(responseBuffer.Bytes())
  217. responseBuffer.Release()
  218. } else {
  219. rawMessage, err = io.ReadAll(response.Body)
  220. if err != nil {
  221. return nil, err
  222. }
  223. err = responseMessage.Unpack(rawMessage)
  224. }
  225. if err != nil {
  226. return nil, err
  227. }
  228. return &responseMessage, nil
  229. }