rule_action.go 8.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324
  1. package rule
  2. import (
  3. "context"
  4. "net/netip"
  5. "strings"
  6. "sync"
  7. "syscall"
  8. "time"
  9. "github.com/sagernet/sing-box/adapter"
  10. "github.com/sagernet/sing-box/common/dialer"
  11. "github.com/sagernet/sing-box/common/sniff"
  12. C "github.com/sagernet/sing-box/constant"
  13. "github.com/sagernet/sing-box/option"
  14. "github.com/sagernet/sing-dns"
  15. "github.com/sagernet/sing-tun"
  16. "github.com/sagernet/sing/common"
  17. E "github.com/sagernet/sing/common/exceptions"
  18. F "github.com/sagernet/sing/common/format"
  19. "github.com/sagernet/sing/common/logger"
  20. N "github.com/sagernet/sing/common/network"
  21. )
  22. func NewRuleAction(router adapter.Router, logger logger.ContextLogger, action option.RuleAction) (adapter.RuleAction, error) {
  23. switch action.Action {
  24. case "":
  25. return nil, nil
  26. case C.RuleActionTypeRoute:
  27. return &RuleActionRoute{
  28. Outbound: action.RouteOptions.Outbound,
  29. }, nil
  30. case C.RuleActionTypeRouteOptions:
  31. return &RuleActionRouteOptions{
  32. UDPDisableDomainUnmapping: action.RouteOptionsOptions.UDPDisableDomainUnmapping,
  33. UDPConnect: action.RouteOptionsOptions.UDPConnect,
  34. }, nil
  35. case C.RuleActionTypeDirect:
  36. directDialer, err := dialer.New(router, option.DialerOptions(action.DirectOptions))
  37. if err != nil {
  38. return nil, err
  39. }
  40. var description string
  41. descriptions := action.DirectOptions.Descriptions()
  42. switch len(descriptions) {
  43. case 0:
  44. case 1:
  45. description = F.ToString("(", descriptions[0], ")")
  46. case 2:
  47. description = F.ToString("(", descriptions[0], ",", descriptions[1], ")")
  48. default:
  49. description = F.ToString("(", descriptions[0], ",", descriptions[1], ",...)")
  50. }
  51. return &RuleActionDirect{
  52. Dialer: directDialer,
  53. description: description,
  54. }, nil
  55. case C.RuleActionTypeReject:
  56. return &RuleActionReject{
  57. Method: action.RejectOptions.Method,
  58. NoDrop: action.RejectOptions.NoDrop,
  59. logger: logger,
  60. }, nil
  61. case C.RuleActionTypeHijackDNS:
  62. return &RuleActionHijackDNS{}, nil
  63. case C.RuleActionTypeSniff:
  64. sniffAction := &RuleActionSniff{
  65. snifferNames: action.SniffOptions.Sniffer,
  66. Timeout: time.Duration(action.SniffOptions.Timeout),
  67. }
  68. return sniffAction, sniffAction.build()
  69. case C.RuleActionTypeResolve:
  70. return &RuleActionResolve{
  71. Strategy: dns.DomainStrategy(action.ResolveOptions.Strategy),
  72. Server: action.ResolveOptions.Server,
  73. }, nil
  74. default:
  75. panic(F.ToString("unknown rule action: ", action.Action))
  76. }
  77. }
  78. func NewDNSRuleAction(logger logger.ContextLogger, action option.DNSRuleAction) adapter.RuleAction {
  79. switch action.Action {
  80. case "":
  81. return nil
  82. case C.RuleActionTypeRoute:
  83. return &RuleActionDNSRoute{
  84. Server: action.RouteOptions.Server,
  85. DisableCache: action.RouteOptions.DisableCache,
  86. RewriteTTL: action.RouteOptions.RewriteTTL,
  87. ClientSubnet: action.RouteOptions.ClientSubnet.Build(),
  88. }
  89. case C.RuleActionTypeRouteOptions:
  90. return &RuleActionDNSRouteOptions{
  91. DisableCache: action.RouteOptionsOptions.DisableCache,
  92. RewriteTTL: action.RouteOptionsOptions.RewriteTTL,
  93. ClientSubnet: action.RouteOptionsOptions.ClientSubnet.Build(),
  94. }
  95. case C.RuleActionTypeReject:
  96. return &RuleActionReject{
  97. Method: action.RejectOptions.Method,
  98. NoDrop: action.RejectOptions.NoDrop,
  99. logger: logger,
  100. }
  101. default:
  102. panic(F.ToString("unknown rule action: ", action.Action))
  103. }
  104. }
  105. type RuleActionRoute struct {
  106. Outbound string
  107. }
  108. func (r *RuleActionRoute) Type() string {
  109. return C.RuleActionTypeRoute
  110. }
  111. func (r *RuleActionRoute) String() string {
  112. return F.ToString("route(", r.Outbound, ")")
  113. }
  114. type RuleActionRouteOptions struct {
  115. UDPDisableDomainUnmapping bool
  116. UDPConnect bool
  117. }
  118. func (r *RuleActionRouteOptions) Type() string {
  119. return C.RuleActionTypeRouteOptions
  120. }
  121. func (r *RuleActionRouteOptions) String() string {
  122. var descriptions []string
  123. if r.UDPDisableDomainUnmapping {
  124. descriptions = append(descriptions, "udp-disable-domain-unmapping")
  125. }
  126. if r.UDPConnect {
  127. descriptions = append(descriptions, "udp-connect")
  128. }
  129. return F.ToString("route-options(", strings.Join(descriptions, ","), ")")
  130. }
  131. type RuleActionDNSRoute struct {
  132. Server string
  133. DisableCache bool
  134. RewriteTTL *uint32
  135. ClientSubnet netip.Prefix
  136. }
  137. func (r *RuleActionDNSRoute) Type() string {
  138. return C.RuleActionTypeRoute
  139. }
  140. func (r *RuleActionDNSRoute) String() string {
  141. return F.ToString("route(", r.Server, ")")
  142. }
  143. type RuleActionDNSRouteOptions struct {
  144. DisableCache bool
  145. RewriteTTL *uint32
  146. ClientSubnet netip.Prefix
  147. }
  148. func (r *RuleActionDNSRouteOptions) Type() string {
  149. return C.RuleActionTypeRouteOptions
  150. }
  151. func (r *RuleActionDNSRouteOptions) String() string {
  152. var descriptions []string
  153. if r.DisableCache {
  154. descriptions = append(descriptions, "disable-cache")
  155. }
  156. if r.RewriteTTL != nil {
  157. descriptions = append(descriptions, F.ToString("rewrite-ttl(", *r.RewriteTTL, ")"))
  158. }
  159. if r.ClientSubnet.IsValid() {
  160. descriptions = append(descriptions, F.ToString("client-subnet(", r.ClientSubnet, ")"))
  161. }
  162. return F.ToString("route-options(", strings.Join(descriptions, ","), ")")
  163. }
  164. type RuleActionDirect struct {
  165. Dialer N.Dialer
  166. description string
  167. }
  168. func (r *RuleActionDirect) Type() string {
  169. return C.RuleActionTypeDirect
  170. }
  171. func (r *RuleActionDirect) String() string {
  172. return "direct" + r.description
  173. }
  174. type RuleActionReject struct {
  175. Method string
  176. NoDrop bool
  177. logger logger.ContextLogger
  178. dropAccess sync.Mutex
  179. dropCounter []time.Time
  180. }
  181. func (r *RuleActionReject) Type() string {
  182. return C.RuleActionTypeReject
  183. }
  184. func (r *RuleActionReject) String() string {
  185. if r.Method == C.RuleActionRejectMethodDefault {
  186. return "reject"
  187. }
  188. return F.ToString("reject(", r.Method, ")")
  189. }
  190. func (r *RuleActionReject) Error(ctx context.Context) error {
  191. var returnErr error
  192. switch r.Method {
  193. case C.RuleActionRejectMethodDefault:
  194. returnErr = syscall.ECONNREFUSED
  195. case C.RuleActionRejectMethodDrop:
  196. return tun.ErrDrop
  197. default:
  198. panic(F.ToString("unknown reject method: ", r.Method))
  199. }
  200. r.dropAccess.Lock()
  201. defer r.dropAccess.Unlock()
  202. timeNow := time.Now()
  203. r.dropCounter = common.Filter(r.dropCounter, func(t time.Time) bool {
  204. return timeNow.Sub(t) <= 30*time.Second
  205. })
  206. r.dropCounter = append(r.dropCounter, timeNow)
  207. if len(r.dropCounter) > 50 {
  208. if ctx != nil {
  209. r.logger.DebugContext(ctx, "dropped due to flooding")
  210. }
  211. return tun.ErrDrop
  212. }
  213. return returnErr
  214. }
  215. type RuleActionHijackDNS struct{}
  216. func (r *RuleActionHijackDNS) Type() string {
  217. return C.RuleActionTypeHijackDNS
  218. }
  219. func (r *RuleActionHijackDNS) String() string {
  220. return "hijack-dns"
  221. }
  222. type RuleActionSniff struct {
  223. snifferNames []string
  224. StreamSniffers []sniff.StreamSniffer
  225. PacketSniffers []sniff.PacketSniffer
  226. Timeout time.Duration
  227. // Deprecated
  228. OverrideDestination bool
  229. }
  230. func (r *RuleActionSniff) Type() string {
  231. return C.RuleActionTypeSniff
  232. }
  233. func (r *RuleActionSniff) build() error {
  234. for _, name := range r.snifferNames {
  235. switch name {
  236. case C.ProtocolTLS:
  237. r.StreamSniffers = append(r.StreamSniffers, sniff.TLSClientHello)
  238. case C.ProtocolHTTP:
  239. r.StreamSniffers = append(r.StreamSniffers, sniff.HTTPHost)
  240. case C.ProtocolQUIC:
  241. r.PacketSniffers = append(r.PacketSniffers, sniff.QUICClientHello)
  242. case C.ProtocolDNS:
  243. r.StreamSniffers = append(r.StreamSniffers, sniff.StreamDomainNameQuery)
  244. r.PacketSniffers = append(r.PacketSniffers, sniff.DomainNameQuery)
  245. case C.ProtocolSTUN:
  246. r.PacketSniffers = append(r.PacketSniffers, sniff.STUNMessage)
  247. case C.ProtocolBitTorrent:
  248. r.StreamSniffers = append(r.StreamSniffers, sniff.BitTorrent)
  249. r.PacketSniffers = append(r.PacketSniffers, sniff.UTP)
  250. r.PacketSniffers = append(r.PacketSniffers, sniff.UDPTracker)
  251. case C.ProtocolDTLS:
  252. r.PacketSniffers = append(r.PacketSniffers, sniff.DTLSRecord)
  253. case C.ProtocolSSH:
  254. r.StreamSniffers = append(r.StreamSniffers, sniff.SSH)
  255. case C.ProtocolRDP:
  256. r.StreamSniffers = append(r.StreamSniffers, sniff.RDP)
  257. default:
  258. return E.New("unknown sniffer: ", name)
  259. }
  260. }
  261. return nil
  262. }
  263. func (r *RuleActionSniff) String() string {
  264. if len(r.snifferNames) == 0 && r.Timeout == 0 {
  265. return "sniff"
  266. } else if len(r.snifferNames) > 0 && r.Timeout == 0 {
  267. return F.ToString("sniff(", strings.Join(r.snifferNames, ","), ")")
  268. } else if len(r.snifferNames) == 0 && r.Timeout > 0 {
  269. return F.ToString("sniff(", r.Timeout.String(), ")")
  270. } else {
  271. return F.ToString("sniff(", strings.Join(r.snifferNames, ","), ",", r.Timeout.String(), ")")
  272. }
  273. }
  274. type RuleActionResolve struct {
  275. Strategy dns.DomainStrategy
  276. Server string
  277. }
  278. func (r *RuleActionResolve) Type() string {
  279. return C.RuleActionTypeResolve
  280. }
  281. func (r *RuleActionResolve) String() string {
  282. if r.Strategy == dns.DomainStrategyAsIS && r.Server == "" {
  283. return F.ToString("resolve")
  284. } else if r.Strategy != dns.DomainStrategyAsIS && r.Server == "" {
  285. return F.ToString("resolve(", option.DomainStrategy(r.Strategy).String(), ")")
  286. } else if r.Strategy == dns.DomainStrategyAsIS && r.Server != "" {
  287. return F.ToString("resolve(", r.Server, ")")
  288. } else {
  289. return F.ToString("resolve(", option.DomainStrategy(r.Strategy).String(), ",", r.Server, ")")
  290. }
  291. }