router.go 42 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199120012011202120312041205120612071208120912101211121212131214121512161217121812191220122112221223122412251226122712281229123012311232123312341235123612371238123912401241124212431244124512461247124812491250125112521253125412551256125712581259126012611262126312641265126612671268126912701271127212731274127512761277127812791280128112821283128412851286128712881289129012911292129312941295129612971298129913001301130213031304130513061307130813091310131113121313131413151316131713181319132013211322132313241325132613271328132913301331133213331334133513361337133813391340134113421343134413451346134713481349
  1. package route
  2. import (
  3. "context"
  4. "errors"
  5. "net"
  6. "net/netip"
  7. "net/url"
  8. "os"
  9. "os/user"
  10. "runtime"
  11. "strings"
  12. "time"
  13. "github.com/sagernet/sing-box/adapter"
  14. "github.com/sagernet/sing-box/common/conntrack"
  15. "github.com/sagernet/sing-box/common/dialer"
  16. "github.com/sagernet/sing-box/common/geoip"
  17. "github.com/sagernet/sing-box/common/geosite"
  18. "github.com/sagernet/sing-box/common/process"
  19. "github.com/sagernet/sing-box/common/sniff"
  20. "github.com/sagernet/sing-box/common/taskmonitor"
  21. C "github.com/sagernet/sing-box/constant"
  22. "github.com/sagernet/sing-box/experimental/libbox/platform"
  23. "github.com/sagernet/sing-box/log"
  24. "github.com/sagernet/sing-box/option"
  25. "github.com/sagernet/sing-box/outbound"
  26. "github.com/sagernet/sing-box/transport/fakeip"
  27. "github.com/sagernet/sing-dns"
  28. "github.com/sagernet/sing-mux"
  29. "github.com/sagernet/sing-tun"
  30. "github.com/sagernet/sing-vmess"
  31. "github.com/sagernet/sing/common"
  32. "github.com/sagernet/sing/common/buf"
  33. "github.com/sagernet/sing/common/bufio"
  34. "github.com/sagernet/sing/common/bufio/deadline"
  35. "github.com/sagernet/sing/common/control"
  36. E "github.com/sagernet/sing/common/exceptions"
  37. F "github.com/sagernet/sing/common/format"
  38. M "github.com/sagernet/sing/common/metadata"
  39. N "github.com/sagernet/sing/common/network"
  40. "github.com/sagernet/sing/common/ntp"
  41. "github.com/sagernet/sing/common/task"
  42. "github.com/sagernet/sing/common/uot"
  43. "github.com/sagernet/sing/common/winpowrprof"
  44. "github.com/sagernet/sing/service"
  45. "github.com/sagernet/sing/service/pause"
  46. )
  47. var _ adapter.Router = (*Router)(nil)
  48. type Router struct {
  49. ctx context.Context
  50. logger log.ContextLogger
  51. dnsLogger log.ContextLogger
  52. inboundByTag map[string]adapter.Inbound
  53. outbounds []adapter.Outbound
  54. outboundByTag map[string]adapter.Outbound
  55. rules []adapter.Rule
  56. defaultDetour string
  57. defaultOutboundForConnection adapter.Outbound
  58. defaultOutboundForPacketConnection adapter.Outbound
  59. needGeoIPDatabase bool
  60. needGeositeDatabase bool
  61. geoIPOptions option.GeoIPOptions
  62. geositeOptions option.GeositeOptions
  63. geoIPReader *geoip.Reader
  64. geositeReader *geosite.Reader
  65. geositeCache map[string]adapter.Rule
  66. needFindProcess bool
  67. dnsClient *dns.Client
  68. defaultDomainStrategy dns.DomainStrategy
  69. dnsRules []adapter.DNSRule
  70. ruleSets []adapter.RuleSet
  71. ruleSetMap map[string]adapter.RuleSet
  72. defaultTransport dns.Transport
  73. transports []dns.Transport
  74. transportMap map[string]dns.Transport
  75. transportDomainStrategy map[dns.Transport]dns.DomainStrategy
  76. dnsReverseMapping *DNSReverseMapping
  77. fakeIPStore adapter.FakeIPStore
  78. interfaceFinder *control.DefaultInterfaceFinder
  79. autoDetectInterface bool
  80. defaultInterface string
  81. defaultMark uint32
  82. autoRedirectOutputMark uint32
  83. networkMonitor tun.NetworkUpdateMonitor
  84. interfaceMonitor tun.DefaultInterfaceMonitor
  85. packageManager tun.PackageManager
  86. powerListener winpowrprof.EventListener
  87. processSearcher process.Searcher
  88. timeService *ntp.Service
  89. pauseManager pause.Manager
  90. clashServer adapter.ClashServer
  91. v2rayServer adapter.V2RayServer
  92. platformInterface platform.Interface
  93. needWIFIState bool
  94. needPackageManager bool
  95. wifiState adapter.WIFIState
  96. started bool
  97. }
  98. func NewRouter(
  99. ctx context.Context,
  100. logFactory log.Factory,
  101. options option.RouteOptions,
  102. dnsOptions option.DNSOptions,
  103. ntpOptions option.NTPOptions,
  104. inbounds []option.Inbound,
  105. platformInterface platform.Interface,
  106. ) (*Router, error) {
  107. router := &Router{
  108. ctx: ctx,
  109. logger: logFactory.NewLogger("router"),
  110. dnsLogger: logFactory.NewLogger("dns"),
  111. outboundByTag: make(map[string]adapter.Outbound),
  112. rules: make([]adapter.Rule, 0, len(options.Rules)),
  113. dnsRules: make([]adapter.DNSRule, 0, len(dnsOptions.Rules)),
  114. ruleSetMap: make(map[string]adapter.RuleSet),
  115. needGeoIPDatabase: hasRule(options.Rules, isGeoIPRule) || hasDNSRule(dnsOptions.Rules, isGeoIPDNSRule),
  116. needGeositeDatabase: hasRule(options.Rules, isGeositeRule) || hasDNSRule(dnsOptions.Rules, isGeositeDNSRule),
  117. geoIPOptions: common.PtrValueOrDefault(options.GeoIP),
  118. geositeOptions: common.PtrValueOrDefault(options.Geosite),
  119. geositeCache: make(map[string]adapter.Rule),
  120. needFindProcess: hasRule(options.Rules, isProcessRule) || hasDNSRule(dnsOptions.Rules, isProcessDNSRule) || options.FindProcess,
  121. defaultDetour: options.Final,
  122. defaultDomainStrategy: dns.DomainStrategy(dnsOptions.Strategy),
  123. interfaceFinder: control.NewDefaultInterfaceFinder(),
  124. autoDetectInterface: options.AutoDetectInterface,
  125. defaultInterface: options.DefaultInterface,
  126. defaultMark: options.DefaultMark,
  127. pauseManager: service.FromContext[pause.Manager](ctx),
  128. platformInterface: platformInterface,
  129. needWIFIState: hasRule(options.Rules, isWIFIRule) || hasDNSRule(dnsOptions.Rules, isWIFIDNSRule),
  130. needPackageManager: common.Any(inbounds, func(inbound option.Inbound) bool {
  131. return len(inbound.TunOptions.IncludePackage) > 0 || len(inbound.TunOptions.ExcludePackage) > 0
  132. }),
  133. }
  134. router.dnsClient = dns.NewClient(dns.ClientOptions{
  135. DisableCache: dnsOptions.DNSClientOptions.DisableCache,
  136. DisableExpire: dnsOptions.DNSClientOptions.DisableExpire,
  137. IndependentCache: dnsOptions.DNSClientOptions.IndependentCache,
  138. RDRC: func() dns.RDRCStore {
  139. cacheFile := service.FromContext[adapter.CacheFile](ctx)
  140. if cacheFile == nil {
  141. return nil
  142. }
  143. if !cacheFile.StoreRDRC() {
  144. return nil
  145. }
  146. return cacheFile
  147. },
  148. Logger: router.dnsLogger,
  149. })
  150. for i, ruleOptions := range options.Rules {
  151. routeRule, err := NewRule(router, router.logger, ruleOptions, true)
  152. if err != nil {
  153. return nil, E.Cause(err, "parse rule[", i, "]")
  154. }
  155. router.rules = append(router.rules, routeRule)
  156. }
  157. for i, dnsRuleOptions := range dnsOptions.Rules {
  158. dnsRule, err := NewDNSRule(router, router.logger, dnsRuleOptions, true)
  159. if err != nil {
  160. return nil, E.Cause(err, "parse dns rule[", i, "]")
  161. }
  162. router.dnsRules = append(router.dnsRules, dnsRule)
  163. }
  164. for i, ruleSetOptions := range options.RuleSet {
  165. if _, exists := router.ruleSetMap[ruleSetOptions.Tag]; exists {
  166. return nil, E.New("duplicate rule-set tag: ", ruleSetOptions.Tag)
  167. }
  168. ruleSet, err := NewRuleSet(ctx, router, router.logger, ruleSetOptions)
  169. if err != nil {
  170. return nil, E.Cause(err, "parse rule-set[", i, "]")
  171. }
  172. router.ruleSets = append(router.ruleSets, ruleSet)
  173. router.ruleSetMap[ruleSetOptions.Tag] = ruleSet
  174. }
  175. transports := make([]dns.Transport, len(dnsOptions.Servers))
  176. dummyTransportMap := make(map[string]dns.Transport)
  177. transportMap := make(map[string]dns.Transport)
  178. transportTags := make([]string, len(dnsOptions.Servers))
  179. transportTagMap := make(map[string]bool)
  180. transportDomainStrategy := make(map[dns.Transport]dns.DomainStrategy)
  181. for i, server := range dnsOptions.Servers {
  182. var tag string
  183. if server.Tag != "" {
  184. tag = server.Tag
  185. } else {
  186. tag = F.ToString(i)
  187. }
  188. if transportTagMap[tag] {
  189. return nil, E.New("duplicate dns server tag: ", tag)
  190. }
  191. transportTags[i] = tag
  192. transportTagMap[tag] = true
  193. }
  194. ctx = adapter.ContextWithRouter(ctx, router)
  195. for {
  196. lastLen := len(dummyTransportMap)
  197. for i, server := range dnsOptions.Servers {
  198. tag := transportTags[i]
  199. if _, exists := dummyTransportMap[tag]; exists {
  200. continue
  201. }
  202. var detour N.Dialer
  203. if server.Detour == "" {
  204. detour = dialer.NewRouter(router)
  205. } else {
  206. detour = dialer.NewDetour(router, server.Detour)
  207. }
  208. switch server.Address {
  209. case "local":
  210. default:
  211. serverURL, _ := url.Parse(server.Address)
  212. var serverAddress string
  213. if serverURL != nil {
  214. serverAddress = serverURL.Hostname()
  215. }
  216. if serverAddress == "" {
  217. serverAddress = server.Address
  218. }
  219. notIpAddress := !M.ParseSocksaddr(serverAddress).Addr.IsValid()
  220. if server.AddressResolver != "" {
  221. if !transportTagMap[server.AddressResolver] {
  222. return nil, E.New("parse dns server[", tag, "]: address resolver not found: ", server.AddressResolver)
  223. }
  224. if upstream, exists := dummyTransportMap[server.AddressResolver]; exists {
  225. detour = dns.NewDialerWrapper(detour, router.dnsClient, upstream, dns.DomainStrategy(server.AddressStrategy), time.Duration(server.AddressFallbackDelay))
  226. } else {
  227. continue
  228. }
  229. } else if notIpAddress && strings.Contains(server.Address, ".") {
  230. return nil, E.New("parse dns server[", tag, "]: missing address_resolver")
  231. }
  232. }
  233. var clientSubnet netip.Prefix
  234. if server.ClientSubnet != nil {
  235. clientSubnet = server.ClientSubnet.Build()
  236. } else if dnsOptions.ClientSubnet != nil {
  237. clientSubnet = dnsOptions.ClientSubnet.Build()
  238. }
  239. transport, err := dns.CreateTransport(dns.TransportOptions{
  240. Context: ctx,
  241. Logger: logFactory.NewLogger(F.ToString("dns/transport[", tag, "]")),
  242. Name: tag,
  243. Dialer: detour,
  244. Address: server.Address,
  245. ClientSubnet: clientSubnet,
  246. })
  247. if err != nil {
  248. return nil, E.Cause(err, "parse dns server[", tag, "]")
  249. }
  250. transports[i] = transport
  251. dummyTransportMap[tag] = transport
  252. if server.Tag != "" {
  253. transportMap[server.Tag] = transport
  254. }
  255. strategy := dns.DomainStrategy(server.Strategy)
  256. if strategy != dns.DomainStrategyAsIS {
  257. transportDomainStrategy[transport] = strategy
  258. }
  259. }
  260. if len(transports) == len(dummyTransportMap) {
  261. break
  262. }
  263. if lastLen != len(dummyTransportMap) {
  264. continue
  265. }
  266. unresolvedTags := common.MapIndexed(common.FilterIndexed(dnsOptions.Servers, func(index int, server option.DNSServerOptions) bool {
  267. _, exists := dummyTransportMap[transportTags[index]]
  268. return !exists
  269. }), func(index int, server option.DNSServerOptions) string {
  270. return transportTags[index]
  271. })
  272. if len(unresolvedTags) == 0 {
  273. panic(F.ToString("unexpected unresolved dns servers: ", len(transports), " ", len(dummyTransportMap), " ", len(transportMap)))
  274. }
  275. return nil, E.New("found circular reference in dns servers: ", strings.Join(unresolvedTags, " "))
  276. }
  277. var defaultTransport dns.Transport
  278. if dnsOptions.Final != "" {
  279. defaultTransport = dummyTransportMap[dnsOptions.Final]
  280. if defaultTransport == nil {
  281. return nil, E.New("default dns server not found: ", dnsOptions.Final)
  282. }
  283. }
  284. if defaultTransport == nil {
  285. if len(transports) == 0 {
  286. transports = append(transports, common.Must1(dns.CreateTransport(dns.TransportOptions{
  287. Context: ctx,
  288. Name: "local",
  289. Address: "local",
  290. Dialer: common.Must1(dialer.NewDefault(router, option.DialerOptions{})),
  291. })))
  292. }
  293. defaultTransport = transports[0]
  294. }
  295. if _, isFakeIP := defaultTransport.(adapter.FakeIPTransport); isFakeIP {
  296. return nil, E.New("default DNS server cannot be fakeip")
  297. }
  298. router.defaultTransport = defaultTransport
  299. router.transports = transports
  300. router.transportMap = transportMap
  301. router.transportDomainStrategy = transportDomainStrategy
  302. if dnsOptions.ReverseMapping {
  303. router.dnsReverseMapping = NewDNSReverseMapping()
  304. }
  305. if fakeIPOptions := dnsOptions.FakeIP; fakeIPOptions != nil && dnsOptions.FakeIP.Enabled {
  306. var inet4Range netip.Prefix
  307. var inet6Range netip.Prefix
  308. if fakeIPOptions.Inet4Range != nil {
  309. inet4Range = *fakeIPOptions.Inet4Range
  310. }
  311. if fakeIPOptions.Inet6Range != nil {
  312. inet6Range = *fakeIPOptions.Inet6Range
  313. }
  314. router.fakeIPStore = fakeip.NewStore(ctx, router.logger, inet4Range, inet6Range)
  315. }
  316. usePlatformDefaultInterfaceMonitor := platformInterface != nil && platformInterface.UsePlatformDefaultInterfaceMonitor()
  317. needInterfaceMonitor := options.AutoDetectInterface || common.Any(inbounds, func(inbound option.Inbound) bool {
  318. return inbound.HTTPOptions.SetSystemProxy || inbound.MixedOptions.SetSystemProxy || inbound.TunOptions.AutoRoute
  319. })
  320. if !usePlatformDefaultInterfaceMonitor {
  321. networkMonitor, err := tun.NewNetworkUpdateMonitor(router.logger)
  322. if !((err != nil && !needInterfaceMonitor) || errors.Is(err, os.ErrInvalid)) {
  323. if err != nil {
  324. return nil, err
  325. }
  326. router.networkMonitor = networkMonitor
  327. networkMonitor.RegisterCallback(func() {
  328. _ = router.interfaceFinder.Update()
  329. })
  330. interfaceMonitor, err := tun.NewDefaultInterfaceMonitor(router.networkMonitor, router.logger, tun.DefaultInterfaceMonitorOptions{
  331. OverrideAndroidVPN: options.OverrideAndroidVPN,
  332. UnderNetworkExtension: platformInterface != nil && platformInterface.UnderNetworkExtension(),
  333. })
  334. if err != nil {
  335. return nil, E.New("auto_detect_interface unsupported on current platform")
  336. }
  337. interfaceMonitor.RegisterCallback(router.notifyNetworkUpdate)
  338. router.interfaceMonitor = interfaceMonitor
  339. }
  340. } else {
  341. interfaceMonitor := platformInterface.CreateDefaultInterfaceMonitor(router.logger)
  342. interfaceMonitor.RegisterCallback(router.notifyNetworkUpdate)
  343. router.interfaceMonitor = interfaceMonitor
  344. }
  345. if ntpOptions.Enabled {
  346. ntpDialer, err := dialer.New(router, ntpOptions.DialerOptions)
  347. if err != nil {
  348. return nil, E.Cause(err, "create NTP service")
  349. }
  350. timeService := ntp.NewService(ntp.Options{
  351. Context: ctx,
  352. Dialer: ntpDialer,
  353. Logger: logFactory.NewLogger("ntp"),
  354. Server: ntpOptions.ServerOptions.Build(),
  355. Interval: time.Duration(ntpOptions.Interval),
  356. WriteToSystem: ntpOptions.WriteToSystem,
  357. })
  358. service.MustRegister[ntp.TimeService](ctx, timeService)
  359. router.timeService = timeService
  360. }
  361. return router, nil
  362. }
  363. func (r *Router) Initialize(inbounds []adapter.Inbound, outbounds []adapter.Outbound, defaultOutbound func() adapter.Outbound) error {
  364. inboundByTag := make(map[string]adapter.Inbound)
  365. for _, inbound := range inbounds {
  366. inboundByTag[inbound.Tag()] = inbound
  367. }
  368. outboundByTag := make(map[string]adapter.Outbound)
  369. for _, detour := range outbounds {
  370. outboundByTag[detour.Tag()] = detour
  371. }
  372. var defaultOutboundForConnection adapter.Outbound
  373. var defaultOutboundForPacketConnection adapter.Outbound
  374. if r.defaultDetour != "" {
  375. detour, loaded := outboundByTag[r.defaultDetour]
  376. if !loaded {
  377. return E.New("default detour not found: ", r.defaultDetour)
  378. }
  379. if common.Contains(detour.Network(), N.NetworkTCP) {
  380. defaultOutboundForConnection = detour
  381. }
  382. if common.Contains(detour.Network(), N.NetworkUDP) {
  383. defaultOutboundForPacketConnection = detour
  384. }
  385. }
  386. if defaultOutboundForConnection == nil {
  387. for _, detour := range outbounds {
  388. if common.Contains(detour.Network(), N.NetworkTCP) {
  389. defaultOutboundForConnection = detour
  390. break
  391. }
  392. }
  393. }
  394. if defaultOutboundForPacketConnection == nil {
  395. for _, detour := range outbounds {
  396. if common.Contains(detour.Network(), N.NetworkUDP) {
  397. defaultOutboundForPacketConnection = detour
  398. break
  399. }
  400. }
  401. }
  402. if defaultOutboundForConnection == nil || defaultOutboundForPacketConnection == nil {
  403. detour := defaultOutbound()
  404. if defaultOutboundForConnection == nil {
  405. defaultOutboundForConnection = detour
  406. }
  407. if defaultOutboundForPacketConnection == nil {
  408. defaultOutboundForPacketConnection = detour
  409. }
  410. outbounds = append(outbounds, detour)
  411. outboundByTag[detour.Tag()] = detour
  412. }
  413. r.inboundByTag = inboundByTag
  414. r.outbounds = outbounds
  415. r.defaultOutboundForConnection = defaultOutboundForConnection
  416. r.defaultOutboundForPacketConnection = defaultOutboundForPacketConnection
  417. r.outboundByTag = outboundByTag
  418. for i, rule := range r.rules {
  419. if _, loaded := outboundByTag[rule.Outbound()]; !loaded {
  420. return E.New("outbound not found for rule[", i, "]: ", rule.Outbound())
  421. }
  422. }
  423. return nil
  424. }
  425. func (r *Router) Outbounds() []adapter.Outbound {
  426. if !r.started {
  427. return nil
  428. }
  429. return r.outbounds
  430. }
  431. func (r *Router) PreStart() error {
  432. monitor := taskmonitor.New(r.logger, C.StartTimeout)
  433. if r.interfaceMonitor != nil {
  434. monitor.Start("initialize interface monitor")
  435. err := r.interfaceMonitor.Start()
  436. monitor.Finish()
  437. if err != nil {
  438. return err
  439. }
  440. }
  441. if r.networkMonitor != nil {
  442. monitor.Start("initialize network monitor")
  443. err := r.networkMonitor.Start()
  444. monitor.Finish()
  445. if err != nil {
  446. return err
  447. }
  448. }
  449. if r.fakeIPStore != nil {
  450. monitor.Start("initialize fakeip store")
  451. err := r.fakeIPStore.Start()
  452. monitor.Finish()
  453. if err != nil {
  454. return err
  455. }
  456. }
  457. return nil
  458. }
  459. func (r *Router) Start() error {
  460. monitor := taskmonitor.New(r.logger, C.StartTimeout)
  461. if r.needGeoIPDatabase {
  462. monitor.Start("initialize geoip database")
  463. err := r.prepareGeoIPDatabase()
  464. monitor.Finish()
  465. if err != nil {
  466. return err
  467. }
  468. }
  469. if r.needGeositeDatabase {
  470. monitor.Start("initialize geosite database")
  471. err := r.prepareGeositeDatabase()
  472. monitor.Finish()
  473. if err != nil {
  474. return err
  475. }
  476. }
  477. if r.needGeositeDatabase {
  478. for _, rule := range r.rules {
  479. err := rule.UpdateGeosite()
  480. if err != nil {
  481. r.logger.Error("failed to initialize geosite: ", err)
  482. }
  483. }
  484. for _, rule := range r.dnsRules {
  485. err := rule.UpdateGeosite()
  486. if err != nil {
  487. r.logger.Error("failed to initialize geosite: ", err)
  488. }
  489. }
  490. err := common.Close(r.geositeReader)
  491. if err != nil {
  492. return err
  493. }
  494. r.geositeCache = nil
  495. r.geositeReader = nil
  496. }
  497. if runtime.GOOS == "windows" {
  498. powerListener, err := winpowrprof.NewEventListener(r.notifyWindowsPowerEvent)
  499. if err == nil {
  500. r.powerListener = powerListener
  501. } else {
  502. r.logger.Warn("initialize power listener: ", err)
  503. }
  504. }
  505. if r.powerListener != nil {
  506. monitor.Start("start power listener")
  507. err := r.powerListener.Start()
  508. monitor.Finish()
  509. if err != nil {
  510. return E.Cause(err, "start power listener")
  511. }
  512. }
  513. monitor.Start("initialize DNS client")
  514. r.dnsClient.Start()
  515. monitor.Finish()
  516. if C.IsAndroid && r.platformInterface == nil {
  517. monitor.Start("initialize package manager")
  518. packageManager, err := tun.NewPackageManager(tun.PackageManagerOptions{
  519. Callback: r,
  520. Logger: r.logger,
  521. })
  522. monitor.Finish()
  523. if err != nil {
  524. return E.Cause(err, "create package manager")
  525. }
  526. if r.needPackageManager {
  527. monitor.Start("start package manager")
  528. err = packageManager.Start()
  529. monitor.Finish()
  530. if err != nil {
  531. return E.Cause(err, "start package manager")
  532. }
  533. }
  534. r.packageManager = packageManager
  535. }
  536. for i, rule := range r.dnsRules {
  537. monitor.Start("initialize DNS rule[", i, "]")
  538. err := rule.Start()
  539. monitor.Finish()
  540. if err != nil {
  541. return E.Cause(err, "initialize DNS rule[", i, "]")
  542. }
  543. }
  544. for i, transport := range r.transports {
  545. monitor.Start("initialize DNS transport[", i, "]")
  546. err := transport.Start()
  547. monitor.Finish()
  548. if err != nil {
  549. return E.Cause(err, "initialize DNS server[", i, "]")
  550. }
  551. }
  552. if r.timeService != nil {
  553. monitor.Start("initialize time service")
  554. err := r.timeService.Start()
  555. monitor.Finish()
  556. if err != nil {
  557. return E.Cause(err, "initialize time service")
  558. }
  559. }
  560. return nil
  561. }
  562. func (r *Router) Close() error {
  563. monitor := taskmonitor.New(r.logger, C.StopTimeout)
  564. var err error
  565. for i, rule := range r.rules {
  566. monitor.Start("close rule[", i, "]")
  567. err = E.Append(err, rule.Close(), func(err error) error {
  568. return E.Cause(err, "close rule[", i, "]")
  569. })
  570. monitor.Finish()
  571. }
  572. for i, rule := range r.dnsRules {
  573. monitor.Start("close dns rule[", i, "]")
  574. err = E.Append(err, rule.Close(), func(err error) error {
  575. return E.Cause(err, "close dns rule[", i, "]")
  576. })
  577. monitor.Finish()
  578. }
  579. for i, transport := range r.transports {
  580. monitor.Start("close dns transport[", i, "]")
  581. err = E.Append(err, transport.Close(), func(err error) error {
  582. return E.Cause(err, "close dns transport[", i, "]")
  583. })
  584. monitor.Finish()
  585. }
  586. if r.geoIPReader != nil {
  587. monitor.Start("close geoip reader")
  588. err = E.Append(err, r.geoIPReader.Close(), func(err error) error {
  589. return E.Cause(err, "close geoip reader")
  590. })
  591. monitor.Finish()
  592. }
  593. if r.interfaceMonitor != nil {
  594. monitor.Start("close interface monitor")
  595. err = E.Append(err, r.interfaceMonitor.Close(), func(err error) error {
  596. return E.Cause(err, "close interface monitor")
  597. })
  598. monitor.Finish()
  599. }
  600. if r.networkMonitor != nil {
  601. monitor.Start("close network monitor")
  602. err = E.Append(err, r.networkMonitor.Close(), func(err error) error {
  603. return E.Cause(err, "close network monitor")
  604. })
  605. monitor.Finish()
  606. }
  607. if r.packageManager != nil {
  608. monitor.Start("close package manager")
  609. err = E.Append(err, r.packageManager.Close(), func(err error) error {
  610. return E.Cause(err, "close package manager")
  611. })
  612. monitor.Finish()
  613. }
  614. if r.powerListener != nil {
  615. monitor.Start("close power listener")
  616. err = E.Append(err, r.powerListener.Close(), func(err error) error {
  617. return E.Cause(err, "close power listener")
  618. })
  619. monitor.Finish()
  620. }
  621. if r.timeService != nil {
  622. monitor.Start("close time service")
  623. err = E.Append(err, r.timeService.Close(), func(err error) error {
  624. return E.Cause(err, "close time service")
  625. })
  626. monitor.Finish()
  627. }
  628. if r.fakeIPStore != nil {
  629. monitor.Start("close fakeip store")
  630. err = E.Append(err, r.fakeIPStore.Close(), func(err error) error {
  631. return E.Cause(err, "close fakeip store")
  632. })
  633. monitor.Finish()
  634. }
  635. return err
  636. }
  637. func (r *Router) PostStart() error {
  638. monitor := taskmonitor.New(r.logger, C.StopTimeout)
  639. if len(r.ruleSets) > 0 {
  640. monitor.Start("initialize rule-set")
  641. ruleSetStartContext := NewRuleSetStartContext()
  642. var ruleSetStartGroup task.Group
  643. for i, ruleSet := range r.ruleSets {
  644. ruleSetInPlace := ruleSet
  645. ruleSetStartGroup.Append0(func(ctx context.Context) error {
  646. err := ruleSetInPlace.StartContext(ctx, ruleSetStartContext)
  647. if err != nil {
  648. return E.Cause(err, "initialize rule-set[", i, "]")
  649. }
  650. return nil
  651. })
  652. }
  653. ruleSetStartGroup.Concurrency(5)
  654. ruleSetStartGroup.FastFail()
  655. err := ruleSetStartGroup.Run(r.ctx)
  656. monitor.Finish()
  657. if err != nil {
  658. return err
  659. }
  660. ruleSetStartContext.Close()
  661. }
  662. needFindProcess := r.needFindProcess
  663. needWIFIState := r.needWIFIState
  664. for _, ruleSet := range r.ruleSets {
  665. metadata := ruleSet.Metadata()
  666. if metadata.ContainsProcessRule {
  667. needFindProcess = true
  668. }
  669. if metadata.ContainsWIFIRule {
  670. needWIFIState = true
  671. }
  672. }
  673. if C.IsAndroid && r.platformInterface == nil && !r.needPackageManager {
  674. if needFindProcess {
  675. monitor.Start("start package manager")
  676. err := r.packageManager.Start()
  677. monitor.Finish()
  678. if err != nil {
  679. return E.Cause(err, "start package manager")
  680. }
  681. } else {
  682. r.packageManager = nil
  683. }
  684. }
  685. if needFindProcess {
  686. if r.platformInterface != nil {
  687. r.processSearcher = r.platformInterface
  688. } else {
  689. monitor.Start("initialize process searcher")
  690. searcher, err := process.NewSearcher(process.Config{
  691. Logger: r.logger,
  692. PackageManager: r.packageManager,
  693. })
  694. monitor.Finish()
  695. if err != nil {
  696. if err != os.ErrInvalid {
  697. r.logger.Warn(E.Cause(err, "create process searcher"))
  698. }
  699. } else {
  700. r.processSearcher = searcher
  701. }
  702. }
  703. }
  704. if needWIFIState && r.platformInterface != nil {
  705. monitor.Start("initialize WIFI state")
  706. r.needWIFIState = true
  707. r.interfaceMonitor.RegisterCallback(func(_ int) {
  708. r.updateWIFIState()
  709. })
  710. r.updateWIFIState()
  711. monitor.Finish()
  712. }
  713. for i, rule := range r.rules {
  714. monitor.Start("initialize rule[", i, "]")
  715. err := rule.Start()
  716. monitor.Finish()
  717. if err != nil {
  718. return E.Cause(err, "initialize rule[", i, "]")
  719. }
  720. }
  721. for _, ruleSet := range r.ruleSets {
  722. monitor.Start("post start rule_set[", ruleSet.Name(), "]")
  723. err := ruleSet.PostStart()
  724. monitor.Finish()
  725. if err != nil {
  726. return E.Cause(err, "post start rule_set[", ruleSet.Name(), "]")
  727. }
  728. }
  729. r.started = true
  730. return nil
  731. }
  732. func (r *Router) Cleanup() error {
  733. for _, ruleSet := range r.ruleSetMap {
  734. ruleSet.Cleanup()
  735. }
  736. runtime.GC()
  737. return nil
  738. }
  739. func (r *Router) Outbound(tag string) (adapter.Outbound, bool) {
  740. outbound, loaded := r.outboundByTag[tag]
  741. return outbound, loaded
  742. }
  743. func (r *Router) DefaultOutbound(network string) (adapter.Outbound, error) {
  744. if network == N.NetworkTCP {
  745. if r.defaultOutboundForConnection == nil {
  746. return nil, E.New("missing default outbound for TCP connections")
  747. }
  748. return r.defaultOutboundForConnection, nil
  749. } else {
  750. if r.defaultOutboundForPacketConnection == nil {
  751. return nil, E.New("missing default outbound for UDP connections")
  752. }
  753. return r.defaultOutboundForPacketConnection, nil
  754. }
  755. }
  756. func (r *Router) FakeIPStore() adapter.FakeIPStore {
  757. return r.fakeIPStore
  758. }
  759. func (r *Router) RuleSet(tag string) (adapter.RuleSet, bool) {
  760. ruleSet, loaded := r.ruleSetMap[tag]
  761. return ruleSet, loaded
  762. }
  763. func (r *Router) NeedWIFIState() bool {
  764. return r.needWIFIState
  765. }
  766. func (r *Router) RouteConnection(ctx context.Context, conn net.Conn, metadata adapter.InboundContext) error {
  767. if r.pauseManager.IsDevicePaused() {
  768. return E.New("reject connection to ", metadata.Destination, " while device paused")
  769. }
  770. if metadata.InboundDetour != "" {
  771. if metadata.LastInbound == metadata.InboundDetour {
  772. return E.New("routing loop on detour: ", metadata.InboundDetour)
  773. }
  774. detour := r.inboundByTag[metadata.InboundDetour]
  775. if detour == nil {
  776. return E.New("inbound detour not found: ", metadata.InboundDetour)
  777. }
  778. injectable, isInjectable := detour.(adapter.InjectableInbound)
  779. if !isInjectable {
  780. return E.New("inbound detour is not injectable: ", metadata.InboundDetour)
  781. }
  782. if !common.Contains(injectable.Network(), N.NetworkTCP) {
  783. return E.New("inject: TCP unsupported")
  784. }
  785. metadata.LastInbound = metadata.Inbound
  786. metadata.Inbound = metadata.InboundDetour
  787. metadata.InboundDetour = ""
  788. err := injectable.NewConnection(ctx, conn, metadata)
  789. if err != nil {
  790. return E.Cause(err, "inject ", detour.Tag())
  791. }
  792. return nil
  793. }
  794. conntrack.KillerCheck()
  795. metadata.Network = N.NetworkTCP
  796. switch metadata.Destination.Fqdn {
  797. case mux.Destination.Fqdn:
  798. return E.New("global multiplex is deprecated since sing-box v1.7.0, enable multiplex in inbound options instead.")
  799. case vmess.MuxDestination.Fqdn:
  800. return E.New("global multiplex (v2ray legacy) not supported since sing-box v1.7.0.")
  801. case uot.MagicAddress:
  802. return E.New("global UoT not supported since sing-box v1.7.0.")
  803. case uot.LegacyMagicAddress:
  804. return E.New("global UoT (legacy) not supported since sing-box v1.7.0.")
  805. }
  806. if r.fakeIPStore != nil && r.fakeIPStore.Contains(metadata.Destination.Addr) {
  807. domain, loaded := r.fakeIPStore.Lookup(metadata.Destination.Addr)
  808. if !loaded {
  809. return E.New("missing fakeip context")
  810. }
  811. metadata.OriginDestination = metadata.Destination
  812. metadata.Destination = M.Socksaddr{
  813. Fqdn: domain,
  814. Port: metadata.Destination.Port,
  815. }
  816. metadata.FakeIP = true
  817. r.logger.DebugContext(ctx, "found fakeip domain: ", domain)
  818. }
  819. if deadline.NeedAdditionalReadDeadline(conn) {
  820. conn = deadline.NewConn(conn)
  821. }
  822. if metadata.InboundOptions.SniffEnabled && !sniff.Skip(metadata) {
  823. buffer := buf.NewPacket()
  824. err := sniff.PeekStream(
  825. ctx,
  826. &metadata,
  827. conn,
  828. buffer,
  829. time.Duration(metadata.InboundOptions.SniffTimeout),
  830. sniff.StreamDomainNameQuery,
  831. sniff.TLSClientHello,
  832. sniff.HTTPHost,
  833. sniff.BitTorrent,
  834. )
  835. if err == nil {
  836. if metadata.InboundOptions.SniffOverrideDestination && M.IsDomainName(metadata.Domain) {
  837. metadata.Destination = M.Socksaddr{
  838. Fqdn: metadata.Domain,
  839. Port: metadata.Destination.Port,
  840. }
  841. }
  842. if metadata.Domain != "" {
  843. r.logger.DebugContext(ctx, "sniffed protocol: ", metadata.Protocol, ", domain: ", metadata.Domain)
  844. } else {
  845. r.logger.DebugContext(ctx, "sniffed protocol: ", metadata.Protocol)
  846. }
  847. }
  848. if !buffer.IsEmpty() {
  849. conn = bufio.NewCachedConn(conn, buffer)
  850. } else {
  851. buffer.Release()
  852. }
  853. }
  854. if r.dnsReverseMapping != nil && metadata.Domain == "" {
  855. domain, loaded := r.dnsReverseMapping.Query(metadata.Destination.Addr)
  856. if loaded {
  857. metadata.Domain = domain
  858. r.logger.DebugContext(ctx, "found reserve mapped domain: ", metadata.Domain)
  859. }
  860. }
  861. if metadata.Destination.IsFqdn() && dns.DomainStrategy(metadata.InboundOptions.DomainStrategy) != dns.DomainStrategyAsIS {
  862. addresses, err := r.Lookup(adapter.WithContext(ctx, &metadata), metadata.Destination.Fqdn, dns.DomainStrategy(metadata.InboundOptions.DomainStrategy))
  863. if err != nil {
  864. return err
  865. }
  866. metadata.DestinationAddresses = addresses
  867. r.dnsLogger.DebugContext(ctx, "resolved [", strings.Join(F.MapToString(metadata.DestinationAddresses), " "), "]")
  868. }
  869. if metadata.Destination.IsIPv4() {
  870. metadata.IPVersion = 4
  871. } else if metadata.Destination.IsIPv6() {
  872. metadata.IPVersion = 6
  873. }
  874. ctx, matchedRule, detour, err := r.match(ctx, &metadata, r.defaultOutboundForConnection)
  875. if err != nil {
  876. return err
  877. }
  878. if !common.Contains(detour.Network(), N.NetworkTCP) {
  879. return E.New("missing supported outbound, closing connection")
  880. }
  881. if r.clashServer != nil {
  882. trackerConn, tracker := r.clashServer.RoutedConnection(ctx, conn, metadata, matchedRule)
  883. defer tracker.Leave()
  884. conn = trackerConn
  885. }
  886. if r.v2rayServer != nil {
  887. if statsService := r.v2rayServer.StatsService(); statsService != nil {
  888. conn = statsService.RoutedConnection(metadata.Inbound, detour.Tag(), metadata.User, conn)
  889. }
  890. }
  891. return detour.NewConnection(ctx, conn, metadata)
  892. }
  893. func (r *Router) RoutePacketConnection(ctx context.Context, conn N.PacketConn, metadata adapter.InboundContext) error {
  894. if r.pauseManager.IsDevicePaused() {
  895. return E.New("reject packet connection to ", metadata.Destination, " while device paused")
  896. }
  897. if metadata.InboundDetour != "" {
  898. if metadata.LastInbound == metadata.InboundDetour {
  899. return E.New("routing loop on detour: ", metadata.InboundDetour)
  900. }
  901. detour := r.inboundByTag[metadata.InboundDetour]
  902. if detour == nil {
  903. return E.New("inbound detour not found: ", metadata.InboundDetour)
  904. }
  905. injectable, isInjectable := detour.(adapter.InjectableInbound)
  906. if !isInjectable {
  907. return E.New("inbound detour is not injectable: ", metadata.InboundDetour)
  908. }
  909. if !common.Contains(injectable.Network(), N.NetworkUDP) {
  910. return E.New("inject: UDP unsupported")
  911. }
  912. metadata.LastInbound = metadata.Inbound
  913. metadata.Inbound = metadata.InboundDetour
  914. metadata.InboundDetour = ""
  915. err := injectable.NewPacketConnection(ctx, conn, metadata)
  916. if err != nil {
  917. return E.Cause(err, "inject ", detour.Tag())
  918. }
  919. return nil
  920. }
  921. conntrack.KillerCheck()
  922. metadata.Network = N.NetworkUDP
  923. if r.fakeIPStore != nil && r.fakeIPStore.Contains(metadata.Destination.Addr) {
  924. domain, loaded := r.fakeIPStore.Lookup(metadata.Destination.Addr)
  925. if !loaded {
  926. return E.New("missing fakeip context")
  927. }
  928. metadata.OriginDestination = metadata.Destination
  929. metadata.Destination = M.Socksaddr{
  930. Fqdn: domain,
  931. Port: metadata.Destination.Port,
  932. }
  933. metadata.FakeIP = true
  934. r.logger.DebugContext(ctx, "found fakeip domain: ", domain)
  935. }
  936. // Currently we don't have deadline usages for UDP connections
  937. /*if deadline.NeedAdditionalReadDeadline(conn) {
  938. conn = deadline.NewPacketConn(bufio.NewNetPacketConn(conn))
  939. }*/
  940. if metadata.InboundOptions.SniffEnabled || metadata.Destination.Addr.IsUnspecified() {
  941. var bufferList []*buf.Buffer
  942. for {
  943. var (
  944. buffer = buf.NewPacket()
  945. destination M.Socksaddr
  946. done = make(chan struct{})
  947. err error
  948. )
  949. go func() {
  950. sniffTimeout := C.ReadPayloadTimeout
  951. if metadata.InboundOptions.SniffTimeout > 0 {
  952. sniffTimeout = time.Duration(metadata.InboundOptions.SniffTimeout)
  953. }
  954. conn.SetReadDeadline(time.Now().Add(sniffTimeout))
  955. destination, err = conn.ReadPacket(buffer)
  956. conn.SetReadDeadline(time.Time{})
  957. close(done)
  958. }()
  959. select {
  960. case <-done:
  961. case <-ctx.Done():
  962. conn.Close()
  963. return ctx.Err()
  964. }
  965. if err != nil {
  966. buffer.Release()
  967. if !errors.Is(err, os.ErrDeadlineExceeded) {
  968. return err
  969. }
  970. } else {
  971. if metadata.Destination.Addr.IsUnspecified() {
  972. metadata.Destination = destination
  973. }
  974. if metadata.InboundOptions.SniffEnabled {
  975. if len(bufferList) > 0 {
  976. err = sniff.PeekPacket(
  977. ctx,
  978. &metadata,
  979. buffer.Bytes(),
  980. sniff.QUICClientHello,
  981. )
  982. } else {
  983. err = sniff.PeekPacket(
  984. ctx, &metadata,
  985. buffer.Bytes(),
  986. sniff.DomainNameQuery,
  987. sniff.QUICClientHello,
  988. sniff.STUNMessage,
  989. sniff.UTP,
  990. sniff.UDPTracker,
  991. sniff.DTLSRecord)
  992. }
  993. if E.IsMulti(err, sniff.ErrClientHelloFragmented) && len(bufferList) == 0 {
  994. bufferList = append(bufferList, buffer)
  995. r.logger.DebugContext(ctx, "attempt to sniff fragmented QUIC client hello")
  996. continue
  997. }
  998. if metadata.Protocol != "" {
  999. if metadata.InboundOptions.SniffOverrideDestination && M.IsDomainName(metadata.Domain) {
  1000. metadata.Destination = M.Socksaddr{
  1001. Fqdn: metadata.Domain,
  1002. Port: metadata.Destination.Port,
  1003. }
  1004. }
  1005. if metadata.Domain != "" && metadata.Client != "" {
  1006. r.logger.DebugContext(ctx, "sniffed packet protocol: ", metadata.Protocol, ", domain: ", metadata.Domain, ", client: ", metadata.Client)
  1007. } else if metadata.Domain != "" {
  1008. r.logger.DebugContext(ctx, "sniffed packet protocol: ", metadata.Protocol, ", domain: ", metadata.Domain)
  1009. } else if metadata.Client != "" {
  1010. r.logger.DebugContext(ctx, "sniffed packet protocol: ", metadata.Protocol, ", client: ", metadata.Client)
  1011. } else {
  1012. r.logger.DebugContext(ctx, "sniffed packet protocol: ", metadata.Protocol)
  1013. }
  1014. }
  1015. }
  1016. conn = bufio.NewCachedPacketConn(conn, buffer, destination)
  1017. }
  1018. for _, cachedBuffer := range common.Reverse(bufferList) {
  1019. conn = bufio.NewCachedPacketConn(conn, cachedBuffer, destination)
  1020. }
  1021. break
  1022. }
  1023. }
  1024. if r.dnsReverseMapping != nil && metadata.Domain == "" {
  1025. domain, loaded := r.dnsReverseMapping.Query(metadata.Destination.Addr)
  1026. if loaded {
  1027. metadata.Domain = domain
  1028. r.logger.DebugContext(ctx, "found reserve mapped domain: ", metadata.Domain)
  1029. }
  1030. }
  1031. if metadata.Destination.IsFqdn() && dns.DomainStrategy(metadata.InboundOptions.DomainStrategy) != dns.DomainStrategyAsIS {
  1032. addresses, err := r.Lookup(adapter.WithContext(ctx, &metadata), metadata.Destination.Fqdn, dns.DomainStrategy(metadata.InboundOptions.DomainStrategy))
  1033. if err != nil {
  1034. return err
  1035. }
  1036. metadata.DestinationAddresses = addresses
  1037. r.dnsLogger.DebugContext(ctx, "resolved [", strings.Join(F.MapToString(metadata.DestinationAddresses), " "), "]")
  1038. }
  1039. if metadata.Destination.IsIPv4() {
  1040. metadata.IPVersion = 4
  1041. } else if metadata.Destination.IsIPv6() {
  1042. metadata.IPVersion = 6
  1043. }
  1044. ctx, matchedRule, detour, err := r.match(ctx, &metadata, r.defaultOutboundForPacketConnection)
  1045. if err != nil {
  1046. return err
  1047. }
  1048. if !common.Contains(detour.Network(), N.NetworkUDP) {
  1049. return E.New("missing supported outbound, closing packet connection")
  1050. }
  1051. if r.clashServer != nil {
  1052. trackerConn, tracker := r.clashServer.RoutedPacketConnection(ctx, conn, metadata, matchedRule)
  1053. defer tracker.Leave()
  1054. conn = trackerConn
  1055. }
  1056. if r.v2rayServer != nil {
  1057. if statsService := r.v2rayServer.StatsService(); statsService != nil {
  1058. conn = statsService.RoutedPacketConnection(metadata.Inbound, detour.Tag(), metadata.User, conn)
  1059. }
  1060. }
  1061. if metadata.FakeIP {
  1062. conn = bufio.NewNATPacketConn(bufio.NewNetPacketConn(conn), metadata.OriginDestination, metadata.Destination)
  1063. }
  1064. return detour.NewPacketConnection(ctx, conn, metadata)
  1065. }
  1066. func (r *Router) match(ctx context.Context, metadata *adapter.InboundContext, defaultOutbound adapter.Outbound) (context.Context, adapter.Rule, adapter.Outbound, error) {
  1067. matchRule, matchOutbound := r.match0(ctx, metadata, defaultOutbound)
  1068. if contextOutbound, loaded := outbound.TagFromContext(ctx); loaded {
  1069. if contextOutbound == matchOutbound.Tag() {
  1070. return nil, nil, nil, E.New("connection loopback in outbound/", matchOutbound.Type(), "[", matchOutbound.Tag(), "]")
  1071. }
  1072. }
  1073. ctx = outbound.ContextWithTag(ctx, matchOutbound.Tag())
  1074. return ctx, matchRule, matchOutbound, nil
  1075. }
  1076. func (r *Router) match0(ctx context.Context, metadata *adapter.InboundContext, defaultOutbound adapter.Outbound) (adapter.Rule, adapter.Outbound) {
  1077. if r.processSearcher != nil {
  1078. var originDestination netip.AddrPort
  1079. if metadata.OriginDestination.IsValid() {
  1080. originDestination = metadata.OriginDestination.AddrPort()
  1081. } else if metadata.Destination.IsIP() {
  1082. originDestination = metadata.Destination.AddrPort()
  1083. }
  1084. processInfo, err := process.FindProcessInfo(r.processSearcher, ctx, metadata.Network, metadata.Source.AddrPort(), originDestination)
  1085. if err != nil {
  1086. r.logger.InfoContext(ctx, "failed to search process: ", err)
  1087. } else {
  1088. if processInfo.ProcessPath != "" {
  1089. r.logger.InfoContext(ctx, "found process path: ", processInfo.ProcessPath)
  1090. } else if processInfo.PackageName != "" {
  1091. r.logger.InfoContext(ctx, "found package name: ", processInfo.PackageName)
  1092. } else if processInfo.UserId != -1 {
  1093. if /*needUserName &&*/ true {
  1094. osUser, _ := user.LookupId(F.ToString(processInfo.UserId))
  1095. if osUser != nil {
  1096. processInfo.User = osUser.Username
  1097. }
  1098. }
  1099. if processInfo.User != "" {
  1100. r.logger.InfoContext(ctx, "found user: ", processInfo.User)
  1101. } else {
  1102. r.logger.InfoContext(ctx, "found user id: ", processInfo.UserId)
  1103. }
  1104. }
  1105. metadata.ProcessInfo = processInfo
  1106. }
  1107. }
  1108. for i, rule := range r.rules {
  1109. metadata.ResetRuleCache()
  1110. if rule.Match(metadata) {
  1111. detour := rule.Outbound()
  1112. r.logger.DebugContext(ctx, "match[", i, "] ", rule.String(), " => ", detour)
  1113. if outbound, loaded := r.Outbound(detour); loaded {
  1114. return rule, outbound
  1115. }
  1116. r.logger.ErrorContext(ctx, "outbound not found: ", detour)
  1117. }
  1118. }
  1119. return nil, defaultOutbound
  1120. }
  1121. func (r *Router) InterfaceFinder() control.InterfaceFinder {
  1122. return r.interfaceFinder
  1123. }
  1124. func (r *Router) UpdateInterfaces() error {
  1125. if r.platformInterface == nil || !r.platformInterface.UsePlatformInterfaceGetter() {
  1126. return r.interfaceFinder.Update()
  1127. } else {
  1128. interfaces, err := r.platformInterface.Interfaces()
  1129. if err != nil {
  1130. return err
  1131. }
  1132. r.interfaceFinder.UpdateInterfaces(interfaces)
  1133. return nil
  1134. }
  1135. }
  1136. func (r *Router) AutoDetectInterface() bool {
  1137. return r.autoDetectInterface
  1138. }
  1139. func (r *Router) AutoDetectInterfaceFunc() control.Func {
  1140. if r.platformInterface != nil && r.platformInterface.UsePlatformAutoDetectInterfaceControl() {
  1141. return r.platformInterface.AutoDetectInterfaceControl()
  1142. } else {
  1143. if r.interfaceMonitor == nil {
  1144. return nil
  1145. }
  1146. return control.BindToInterfaceFunc(r.InterfaceFinder(), func(network string, address string) (interfaceName string, interfaceIndex int, err error) {
  1147. remoteAddr := M.ParseSocksaddr(address).Addr
  1148. if C.IsLinux {
  1149. interfaceName, interfaceIndex = r.InterfaceMonitor().DefaultInterface(remoteAddr)
  1150. if interfaceIndex == -1 {
  1151. err = tun.ErrNoRoute
  1152. }
  1153. } else {
  1154. interfaceIndex = r.InterfaceMonitor().DefaultInterfaceIndex(remoteAddr)
  1155. if interfaceIndex == -1 {
  1156. err = tun.ErrNoRoute
  1157. }
  1158. }
  1159. return
  1160. })
  1161. }
  1162. }
  1163. func (r *Router) RegisterAutoRedirectOutputMark(mark uint32) error {
  1164. if r.autoRedirectOutputMark > 0 {
  1165. return E.New("only one auto-redirect can be configured")
  1166. }
  1167. r.autoRedirectOutputMark = mark
  1168. return nil
  1169. }
  1170. func (r *Router) AutoRedirectOutputMark() uint32 {
  1171. return r.autoRedirectOutputMark
  1172. }
  1173. func (r *Router) DefaultInterface() string {
  1174. return r.defaultInterface
  1175. }
  1176. func (r *Router) DefaultMark() uint32 {
  1177. return r.defaultMark
  1178. }
  1179. func (r *Router) Rules() []adapter.Rule {
  1180. return r.rules
  1181. }
  1182. func (r *Router) WIFIState() adapter.WIFIState {
  1183. return r.wifiState
  1184. }
  1185. func (r *Router) NetworkMonitor() tun.NetworkUpdateMonitor {
  1186. return r.networkMonitor
  1187. }
  1188. func (r *Router) InterfaceMonitor() tun.DefaultInterfaceMonitor {
  1189. return r.interfaceMonitor
  1190. }
  1191. func (r *Router) PackageManager() tun.PackageManager {
  1192. return r.packageManager
  1193. }
  1194. func (r *Router) ClashServer() adapter.ClashServer {
  1195. return r.clashServer
  1196. }
  1197. func (r *Router) SetClashServer(server adapter.ClashServer) {
  1198. r.clashServer = server
  1199. }
  1200. func (r *Router) V2RayServer() adapter.V2RayServer {
  1201. return r.v2rayServer
  1202. }
  1203. func (r *Router) SetV2RayServer(server adapter.V2RayServer) {
  1204. r.v2rayServer = server
  1205. }
  1206. func (r *Router) OnPackagesUpdated(packages int, sharedUsers int) {
  1207. r.logger.Info("updated packages list: ", packages, " packages, ", sharedUsers, " shared users")
  1208. }
  1209. func (r *Router) NewError(ctx context.Context, err error) {
  1210. common.Close(err)
  1211. if E.IsClosedOrCanceled(err) {
  1212. r.logger.DebugContext(ctx, "connection closed: ", err)
  1213. return
  1214. }
  1215. r.logger.ErrorContext(ctx, err)
  1216. }
  1217. func (r *Router) notifyNetworkUpdate(event int) {
  1218. if event == tun.EventNoRoute {
  1219. r.pauseManager.NetworkPause()
  1220. r.logger.Error("missing default interface")
  1221. } else {
  1222. r.pauseManager.NetworkWake()
  1223. if C.IsAndroid && r.platformInterface == nil {
  1224. var vpnStatus string
  1225. if r.interfaceMonitor.AndroidVPNEnabled() {
  1226. vpnStatus = "enabled"
  1227. } else {
  1228. vpnStatus = "disabled"
  1229. }
  1230. r.logger.Info("updated default interface ", r.interfaceMonitor.DefaultInterfaceName(netip.IPv4Unspecified()), ", index ", r.interfaceMonitor.DefaultInterfaceIndex(netip.IPv4Unspecified()), ", vpn ", vpnStatus)
  1231. } else {
  1232. r.logger.Info("updated default interface ", r.interfaceMonitor.DefaultInterfaceName(netip.IPv4Unspecified()), ", index ", r.interfaceMonitor.DefaultInterfaceIndex(netip.IPv4Unspecified()))
  1233. }
  1234. }
  1235. if !r.started {
  1236. return
  1237. }
  1238. _ = r.ResetNetwork()
  1239. }
  1240. func (r *Router) ResetNetwork() error {
  1241. conntrack.Close()
  1242. for _, outbound := range r.outbounds {
  1243. listener, isListener := outbound.(adapter.InterfaceUpdateListener)
  1244. if isListener {
  1245. listener.InterfaceUpdated()
  1246. }
  1247. }
  1248. for _, transport := range r.transports {
  1249. transport.Reset()
  1250. }
  1251. return nil
  1252. }
  1253. func (r *Router) updateWIFIState() {
  1254. if r.platformInterface == nil {
  1255. return
  1256. }
  1257. state := r.platformInterface.ReadWIFIState()
  1258. if state != r.wifiState {
  1259. r.wifiState = state
  1260. if state.SSID == "" && state.BSSID == "" {
  1261. r.logger.Info("updated WIFI state: disconnected")
  1262. } else {
  1263. r.logger.Info("updated WIFI state: SSID=", state.SSID, ", BSSID=", state.BSSID)
  1264. }
  1265. }
  1266. }
  1267. func (r *Router) notifyWindowsPowerEvent(event int) {
  1268. switch event {
  1269. case winpowrprof.EVENT_SUSPEND:
  1270. r.pauseManager.DevicePause()
  1271. _ = r.ResetNetwork()
  1272. case winpowrprof.EVENT_RESUME:
  1273. if !r.pauseManager.IsDevicePaused() {
  1274. return
  1275. }
  1276. fallthrough
  1277. case winpowrprof.EVENT_RESUME_AUTOMATIC:
  1278. r.pauseManager.DeviceWake()
  1279. _ = r.ResetNetwork()
  1280. }
  1281. }