https.go 6.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243
  1. package transport
  2. import (
  3. "bytes"
  4. "context"
  5. "errors"
  6. "io"
  7. "net"
  8. "net/http"
  9. "net/url"
  10. "os"
  11. "strconv"
  12. "sync"
  13. "time"
  14. "github.com/sagernet/sing-box/adapter"
  15. "github.com/sagernet/sing-box/common/dialer"
  16. "github.com/sagernet/sing-box/common/tls"
  17. C "github.com/sagernet/sing-box/constant"
  18. "github.com/sagernet/sing-box/dns"
  19. "github.com/sagernet/sing-box/log"
  20. "github.com/sagernet/sing-box/option"
  21. "github.com/sagernet/sing/common"
  22. "github.com/sagernet/sing/common/buf"
  23. E "github.com/sagernet/sing/common/exceptions"
  24. "github.com/sagernet/sing/common/logger"
  25. M "github.com/sagernet/sing/common/metadata"
  26. N "github.com/sagernet/sing/common/network"
  27. aTLS "github.com/sagernet/sing/common/tls"
  28. sHTTP "github.com/sagernet/sing/protocol/http"
  29. mDNS "github.com/miekg/dns"
  30. "golang.org/x/net/http2"
  31. )
  32. const MimeType = "application/dns-message"
  33. var _ adapter.DNSTransport = (*HTTPSTransport)(nil)
  34. func RegisterHTTPS(registry *dns.TransportRegistry) {
  35. dns.RegisterTransport[option.RemoteHTTPSDNSServerOptions](registry, C.DNSTypeHTTPS, NewHTTPS)
  36. }
  37. type HTTPSTransport struct {
  38. dns.TransportAdapter
  39. logger logger.ContextLogger
  40. dialer N.Dialer
  41. destination *url.URL
  42. headers http.Header
  43. transportAccess sync.Mutex
  44. transport *http.Transport
  45. transportResetAt time.Time
  46. }
  47. func NewHTTPS(ctx context.Context, logger log.ContextLogger, tag string, options option.RemoteHTTPSDNSServerOptions) (adapter.DNSTransport, error) {
  48. transportDialer, err := dns.NewRemoteDialer(ctx, options.RemoteDNSServerOptions)
  49. if err != nil {
  50. return nil, err
  51. }
  52. tlsOptions := common.PtrValueOrDefault(options.TLS)
  53. tlsOptions.Enabled = true
  54. tlsConfig, err := tls.NewClient(ctx, options.Server, tlsOptions)
  55. if err != nil {
  56. return nil, err
  57. }
  58. if common.Error(tlsConfig.Config()) == nil && !common.Contains(tlsConfig.NextProtos(), http2.NextProtoTLS) {
  59. tlsConfig.SetNextProtos(append(tlsConfig.NextProtos(), http2.NextProtoTLS))
  60. }
  61. if !common.Contains(tlsConfig.NextProtos(), "http/1.1") {
  62. tlsConfig.SetNextProtos(append(tlsConfig.NextProtos(), "http/1.1"))
  63. }
  64. headers := options.Headers.Build()
  65. host := headers.Get("Host")
  66. if host != "" {
  67. headers.Del("Host")
  68. } else {
  69. if tlsConfig.ServerName() != "" {
  70. host = tlsConfig.ServerName()
  71. } else {
  72. host = options.Server
  73. }
  74. }
  75. destinationURL := url.URL{
  76. Scheme: "https",
  77. Host: host,
  78. }
  79. if destinationURL.Host == "" {
  80. destinationURL.Host = options.Server
  81. }
  82. if options.ServerPort != 0 && options.ServerPort != 443 {
  83. destinationURL.Host = net.JoinHostPort(destinationURL.Host, strconv.Itoa(int(options.ServerPort)))
  84. }
  85. path := options.Path
  86. if path == "" {
  87. path = "/dns-query"
  88. }
  89. err = sHTTP.URLSetPath(&destinationURL, path)
  90. if err != nil {
  91. return nil, err
  92. }
  93. serverAddr := options.DNSServerAddressOptions.Build()
  94. if serverAddr.Port == 0 {
  95. serverAddr.Port = 443
  96. }
  97. if !serverAddr.IsValid() {
  98. return nil, E.New("invalid server address: ", serverAddr)
  99. }
  100. return NewHTTPSRaw(
  101. dns.NewTransportAdapterWithRemoteOptions(C.DNSTypeHTTPS, tag, options.RemoteDNSServerOptions),
  102. logger,
  103. transportDialer,
  104. &destinationURL,
  105. headers,
  106. serverAddr,
  107. tlsConfig,
  108. ), nil
  109. }
  110. func NewHTTPSRaw(
  111. adapter dns.TransportAdapter,
  112. logger log.ContextLogger,
  113. dialer N.Dialer,
  114. destination *url.URL,
  115. headers http.Header,
  116. serverAddr M.Socksaddr,
  117. tlsConfig tls.Config,
  118. ) *HTTPSTransport {
  119. var transport *http.Transport
  120. if tlsConfig != nil {
  121. transport = &http.Transport{
  122. ForceAttemptHTTP2: true,
  123. DialTLSContext: func(ctx context.Context, network, addr string) (net.Conn, error) {
  124. tcpConn, hErr := dialer.DialContext(ctx, network, serverAddr)
  125. if hErr != nil {
  126. return nil, hErr
  127. }
  128. tlsConn, hErr := aTLS.ClientHandshake(ctx, tcpConn, tlsConfig)
  129. if hErr != nil {
  130. tcpConn.Close()
  131. return nil, hErr
  132. }
  133. return tlsConn, nil
  134. },
  135. }
  136. } else {
  137. transport = &http.Transport{
  138. DialContext: func(ctx context.Context, network, addr string) (net.Conn, error) {
  139. return dialer.DialContext(ctx, network, serverAddr)
  140. },
  141. }
  142. }
  143. return &HTTPSTransport{
  144. TransportAdapter: adapter,
  145. logger: logger,
  146. dialer: dialer,
  147. destination: destination,
  148. headers: headers,
  149. transport: transport,
  150. }
  151. }
  152. func (t *HTTPSTransport) Start(stage adapter.StartStage) error {
  153. if stage != adapter.StartStateStart {
  154. return nil
  155. }
  156. return dialer.InitializeDetour(t.dialer)
  157. }
  158. func (t *HTTPSTransport) Close() error {
  159. t.transportAccess.Lock()
  160. defer t.transportAccess.Unlock()
  161. t.transport.CloseIdleConnections()
  162. t.transport = t.transport.Clone()
  163. return nil
  164. }
  165. func (t *HTTPSTransport) Exchange(ctx context.Context, message *mDNS.Msg) (*mDNS.Msg, error) {
  166. startAt := time.Now()
  167. response, err := t.exchange(ctx, message)
  168. if err != nil {
  169. if errors.Is(err, os.ErrDeadlineExceeded) {
  170. t.transportAccess.Lock()
  171. defer t.transportAccess.Unlock()
  172. if t.transportResetAt.After(startAt) {
  173. return nil, err
  174. }
  175. t.transport.CloseIdleConnections()
  176. t.transport = t.transport.Clone()
  177. t.transportResetAt = time.Now()
  178. }
  179. return nil, err
  180. }
  181. return response, nil
  182. }
  183. func (t *HTTPSTransport) exchange(ctx context.Context, message *mDNS.Msg) (*mDNS.Msg, error) {
  184. exMessage := *message
  185. exMessage.Id = 0
  186. exMessage.Compress = true
  187. requestBuffer := buf.NewSize(1 + message.Len())
  188. rawMessage, err := exMessage.PackBuffer(requestBuffer.FreeBytes())
  189. if err != nil {
  190. requestBuffer.Release()
  191. return nil, err
  192. }
  193. request, err := http.NewRequestWithContext(ctx, http.MethodPost, t.destination.String(), bytes.NewReader(rawMessage))
  194. if err != nil {
  195. requestBuffer.Release()
  196. return nil, err
  197. }
  198. request.Header = t.headers.Clone()
  199. request.Header.Set("Content-Type", MimeType)
  200. request.Header.Set("Accept", MimeType)
  201. response, err := t.transport.RoundTrip(request)
  202. requestBuffer.Release()
  203. if err != nil {
  204. return nil, err
  205. }
  206. defer response.Body.Close()
  207. if response.StatusCode != http.StatusOK {
  208. return nil, E.New("unexpected status: ", response.Status)
  209. }
  210. var responseMessage mDNS.Msg
  211. if response.ContentLength > 0 {
  212. responseBuffer := buf.NewSize(int(response.ContentLength))
  213. _, err = responseBuffer.ReadFullFrom(response.Body, int(response.ContentLength))
  214. if err != nil {
  215. return nil, err
  216. }
  217. err = responseMessage.Unpack(responseBuffer.Bytes())
  218. responseBuffer.Release()
  219. } else {
  220. rawMessage, err = io.ReadAll(response.Body)
  221. if err != nil {
  222. return nil, err
  223. }
  224. err = responseMessage.Unpack(rawMessage)
  225. }
  226. if err != nil {
  227. return nil, err
  228. }
  229. return &responseMessage, nil
  230. }