device_system_stack.go 6.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243
  1. //go:build with_gvisor
  2. package wireguard
  3. import (
  4. "context"
  5. "net/netip"
  6. "time"
  7. "github.com/sagernet/gvisor/pkg/buffer"
  8. "github.com/sagernet/gvisor/pkg/tcpip"
  9. "github.com/sagernet/gvisor/pkg/tcpip/header"
  10. "github.com/sagernet/gvisor/pkg/tcpip/network/ipv4"
  11. "github.com/sagernet/gvisor/pkg/tcpip/network/ipv6"
  12. "github.com/sagernet/gvisor/pkg/tcpip/stack"
  13. "github.com/sagernet/gvisor/pkg/tcpip/transport/icmp"
  14. "github.com/sagernet/gvisor/pkg/tcpip/transport/tcp"
  15. "github.com/sagernet/gvisor/pkg/tcpip/transport/udp"
  16. "github.com/sagernet/sing-box/adapter"
  17. "github.com/sagernet/sing-box/log"
  18. "github.com/sagernet/sing-tun"
  19. "github.com/sagernet/sing-tun/ping"
  20. "github.com/sagernet/sing/common"
  21. E "github.com/sagernet/sing/common/exceptions"
  22. "github.com/sagernet/sing/common/logger"
  23. "github.com/sagernet/wireguard-go/device"
  24. )
  25. var _ Device = (*systemStackDevice)(nil)
  26. type systemStackDevice struct {
  27. *systemDevice
  28. ctx context.Context
  29. logger logger.ContextLogger
  30. stack *stack.Stack
  31. endpoint *deviceEndpoint
  32. writeBufs [][]byte
  33. }
  34. func newSystemStackDevice(options DeviceOptions) (*systemStackDevice, error) {
  35. system, err := newSystemDevice(options)
  36. if err != nil {
  37. return nil, err
  38. }
  39. endpoint := &deviceEndpoint{
  40. mtu: options.MTU,
  41. done: make(chan struct{}),
  42. }
  43. ipStack, err := tun.NewGVisorStackWithOptions(endpoint, stack.NICOptions{}, true)
  44. if err != nil {
  45. return nil, err
  46. }
  47. var (
  48. inet4Address netip.Addr
  49. inet6Address netip.Addr
  50. )
  51. for _, prefix := range options.Address {
  52. addr := tun.AddressFromAddr(prefix.Addr())
  53. protoAddr := tcpip.ProtocolAddress{
  54. AddressWithPrefix: tcpip.AddressWithPrefix{
  55. Address: addr,
  56. PrefixLen: prefix.Bits(),
  57. },
  58. }
  59. if prefix.Addr().Is4() {
  60. inet4Address = prefix.Addr()
  61. protoAddr.Protocol = ipv4.ProtocolNumber
  62. } else {
  63. inet6Address = prefix.Addr()
  64. protoAddr.Protocol = ipv6.ProtocolNumber
  65. }
  66. gErr := ipStack.AddProtocolAddress(tun.DefaultNIC, protoAddr, stack.AddressProperties{})
  67. if gErr != nil {
  68. return nil, E.New("parse local address ", protoAddr.AddressWithPrefix, ": ", gErr.String())
  69. }
  70. }
  71. if options.Handler != nil {
  72. ipStack.SetTransportProtocolHandler(tcp.ProtocolNumber, tun.NewTCPForwarder(options.Context, ipStack, options.Handler).HandlePacket)
  73. ipStack.SetTransportProtocolHandler(udp.ProtocolNumber, tun.NewUDPForwarder(options.Context, ipStack, options.Handler, options.UDPTimeout).HandlePacket)
  74. icmpForwarder := tun.NewICMPForwarder(options.Context, ipStack, options.Handler, options.UDPTimeout)
  75. icmpForwarder.SetLocalAddresses(inet4Address, inet6Address)
  76. ipStack.SetTransportProtocolHandler(icmp.ProtocolNumber4, icmpForwarder.HandlePacket)
  77. ipStack.SetTransportProtocolHandler(icmp.ProtocolNumber6, icmpForwarder.HandlePacket)
  78. }
  79. return &systemStackDevice{
  80. ctx: options.Context,
  81. logger: options.Logger,
  82. systemDevice: system,
  83. stack: ipStack,
  84. endpoint: endpoint,
  85. }, nil
  86. }
  87. func (w *systemStackDevice) SetDevice(device *device.Device) {
  88. w.endpoint.device = device
  89. }
  90. func (w *systemStackDevice) Write(bufs [][]byte, offset int) (count int, err error) {
  91. if w.batchDevice != nil {
  92. w.writeBufs = w.writeBufs[:0]
  93. for _, packet := range bufs {
  94. if !w.writeStack(packet[offset:]) {
  95. w.writeBufs = append(w.writeBufs, packet)
  96. }
  97. }
  98. if len(w.writeBufs) > 0 {
  99. return w.batchDevice.BatchWrite(bufs, offset)
  100. }
  101. } else {
  102. for _, packet := range bufs {
  103. if !w.writeStack(packet[offset:]) {
  104. if tun.PacketOffset > 0 {
  105. common.ClearArray(packet[offset-tun.PacketOffset : offset])
  106. tun.PacketFillHeader(packet[offset-tun.PacketOffset:], tun.PacketIPVersion(packet[offset:]))
  107. }
  108. _, err = w.device.Write(packet[offset-tun.PacketOffset:])
  109. }
  110. if err != nil {
  111. return
  112. }
  113. }
  114. }
  115. // WireGuard will not read count
  116. return
  117. }
  118. func (w *systemStackDevice) Close() error {
  119. close(w.endpoint.done)
  120. w.stack.Close()
  121. for _, endpoint := range w.stack.CleanupEndpoints() {
  122. endpoint.Abort()
  123. }
  124. w.stack.Wait()
  125. return w.systemDevice.Close()
  126. }
  127. func (w *systemStackDevice) writeStack(packet []byte) bool {
  128. var (
  129. networkProtocol tcpip.NetworkProtocolNumber
  130. destination netip.Addr
  131. )
  132. switch header.IPVersion(packet) {
  133. case header.IPv4Version:
  134. networkProtocol = header.IPv4ProtocolNumber
  135. destination = netip.AddrFrom4(header.IPv4(packet).DestinationAddress().As4())
  136. case header.IPv6Version:
  137. networkProtocol = header.IPv6ProtocolNumber
  138. destination = netip.AddrFrom16(header.IPv6(packet).DestinationAddress().As16())
  139. }
  140. for _, prefix := range w.options.Address {
  141. if prefix.Contains(destination) {
  142. return false
  143. }
  144. }
  145. packetBuffer := stack.NewPacketBuffer(stack.PacketBufferOptions{
  146. Payload: buffer.MakeWithData(packet),
  147. })
  148. w.endpoint.dispatcher.DeliverNetworkPacket(networkProtocol, packetBuffer)
  149. packetBuffer.DecRef()
  150. return true
  151. }
  152. func (w *systemStackDevice) CreateDestination(metadata adapter.InboundContext, routeContext tun.DirectRouteContext, timeout time.Duration) (tun.DirectRouteDestination, error) {
  153. ctx := log.ContextWithNewID(w.ctx)
  154. destination, err := ping.ConnectGVisor(
  155. ctx, w.logger,
  156. metadata.Source.Addr, metadata.Destination.Addr,
  157. routeContext,
  158. w.stack,
  159. w.inet4Address, w.inet6Address,
  160. timeout,
  161. )
  162. if err != nil {
  163. return nil, err
  164. }
  165. w.logger.InfoContext(ctx, "linked ", metadata.Network, " connection from ", metadata.Source.AddrString(), " to ", metadata.Destination.AddrString())
  166. return destination, nil
  167. }
  168. type deviceEndpoint struct {
  169. mtu uint32
  170. done chan struct{}
  171. device *device.Device
  172. dispatcher stack.NetworkDispatcher
  173. }
  174. func (ep *deviceEndpoint) MTU() uint32 {
  175. return ep.mtu
  176. }
  177. func (ep *deviceEndpoint) SetMTU(mtu uint32) {
  178. }
  179. func (ep *deviceEndpoint) MaxHeaderLength() uint16 {
  180. return 0
  181. }
  182. func (ep *deviceEndpoint) LinkAddress() tcpip.LinkAddress {
  183. return ""
  184. }
  185. func (ep *deviceEndpoint) SetLinkAddress(addr tcpip.LinkAddress) {
  186. }
  187. func (ep *deviceEndpoint) Capabilities() stack.LinkEndpointCapabilities {
  188. return stack.CapabilityRXChecksumOffload
  189. }
  190. func (ep *deviceEndpoint) Attach(dispatcher stack.NetworkDispatcher) {
  191. ep.dispatcher = dispatcher
  192. }
  193. func (ep *deviceEndpoint) IsAttached() bool {
  194. return ep.dispatcher != nil
  195. }
  196. func (ep *deviceEndpoint) Wait() {
  197. }
  198. func (ep *deviceEndpoint) ARPHardwareType() header.ARPHardwareType {
  199. return header.ARPHardwareNone
  200. }
  201. func (ep *deviceEndpoint) AddHeader(buffer *stack.PacketBuffer) {
  202. }
  203. func (ep *deviceEndpoint) ParseHeader(ptr *stack.PacketBuffer) bool {
  204. return true
  205. }
  206. func (ep *deviceEndpoint) WritePackets(list stack.PacketBufferList) (int, tcpip.Error) {
  207. for _, packetBuffer := range list.AsSlice() {
  208. destination := packetBuffer.Network().DestinationAddress()
  209. ep.device.InputPacket(destination.AsSlice(), packetBuffer.AsSlices())
  210. }
  211. return list.Len(), nil
  212. }
  213. func (ep *deviceEndpoint) Close() {
  214. }
  215. func (ep *deviceEndpoint) SetOnCloseAction(f func()) {
  216. }