default.go 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451
  1. package inbound
  2. import (
  3. "context"
  4. "net"
  5. "net/netip"
  6. "os"
  7. "sync"
  8. "time"
  9. "github.com/sagernet/sing-box/adapter"
  10. "github.com/sagernet/sing-box/common/proxyproto"
  11. "github.com/sagernet/sing-box/common/settings"
  12. C "github.com/sagernet/sing-box/constant"
  13. "github.com/sagernet/sing-box/log"
  14. "github.com/sagernet/sing-box/option"
  15. "github.com/sagernet/sing-dns"
  16. "github.com/sagernet/sing/common"
  17. "github.com/sagernet/sing/common/buf"
  18. E "github.com/sagernet/sing/common/exceptions"
  19. M "github.com/sagernet/sing/common/metadata"
  20. N "github.com/sagernet/sing/common/network"
  21. "github.com/database64128/tfo-go"
  22. )
  23. var _ adapter.Inbound = (*myInboundAdapter)(nil)
  24. type myInboundAdapter struct {
  25. protocol string
  26. network []string
  27. ctx context.Context
  28. router adapter.Router
  29. logger log.ContextLogger
  30. tag string
  31. listenOptions option.ListenOptions
  32. connHandler adapter.ConnectionHandler
  33. packetHandler adapter.PacketHandler
  34. oobPacketHandler adapter.OOBPacketHandler
  35. packetUpstream any
  36. // http mixed
  37. setSystemProxy bool
  38. clearSystemProxy func() error
  39. // internal
  40. tcpListener net.Listener
  41. udpConn *net.UDPConn
  42. udpAddr M.Socksaddr
  43. packetAccess sync.RWMutex
  44. packetOutboundClosed chan struct{}
  45. packetOutbound chan *myInboundPacket
  46. }
  47. func (a *myInboundAdapter) Type() string {
  48. return a.protocol
  49. }
  50. func (a *myInboundAdapter) Tag() string {
  51. return a.tag
  52. }
  53. func (a *myInboundAdapter) Start() error {
  54. var err error
  55. if common.Contains(a.network, N.NetworkTCP) {
  56. _, err = a.ListenTCP()
  57. if err != nil {
  58. return err
  59. }
  60. go a.loopTCPIn()
  61. }
  62. if common.Contains(a.network, N.NetworkUDP) {
  63. _, err = a.ListenUDP()
  64. if err != nil {
  65. return err
  66. }
  67. a.packetOutboundClosed = make(chan struct{})
  68. a.packetOutbound = make(chan *myInboundPacket)
  69. if a.oobPacketHandler != nil {
  70. if _, threadUnsafeHandler := common.Cast[N.ThreadUnsafeWriter](a.packetUpstream); !threadUnsafeHandler {
  71. go a.loopUDPOOBIn()
  72. } else {
  73. go a.loopUDPOOBInThreadSafe()
  74. }
  75. } else {
  76. if _, threadUnsafeHandler := common.Cast[N.ThreadUnsafeWriter](a.packetUpstream); !threadUnsafeHandler {
  77. go a.loopUDPIn()
  78. } else {
  79. go a.loopUDPInThreadSafe()
  80. }
  81. go a.loopUDPOut()
  82. }
  83. }
  84. if a.setSystemProxy {
  85. a.clearSystemProxy, err = settings.SetSystemProxy(a.router, M.SocksaddrFromNet(a.tcpListener.Addr()).Port, a.protocol == C.TypeMixed)
  86. if err != nil {
  87. return E.Cause(err, "set system proxy")
  88. }
  89. }
  90. return nil
  91. }
  92. func (a *myInboundAdapter) ListenTCP() (net.Listener, error) {
  93. var err error
  94. bindAddr := M.SocksaddrFrom(netip.Addr(a.listenOptions.Listen), a.listenOptions.ListenPort)
  95. var tcpListener net.Listener
  96. if !a.listenOptions.TCPFastOpen {
  97. tcpListener, err = net.ListenTCP(M.NetworkFromNetAddr(N.NetworkTCP, bindAddr.Addr), bindAddr.TCPAddr())
  98. } else {
  99. tcpListener, err = tfo.ListenTCP(M.NetworkFromNetAddr(N.NetworkTCP, bindAddr.Addr), bindAddr.TCPAddr())
  100. }
  101. if err == nil {
  102. a.logger.Info("tcp server started at ", tcpListener.Addr())
  103. }
  104. if a.listenOptions.ProxyProtocol {
  105. a.logger.Debug("proxy protocol enabled")
  106. tcpListener = &proxyproto.Listener{Listener: tcpListener}
  107. }
  108. a.tcpListener = tcpListener
  109. return tcpListener, err
  110. }
  111. func (a *myInboundAdapter) ListenUDP() (net.PacketConn, error) {
  112. bindAddr := M.SocksaddrFrom(netip.Addr(a.listenOptions.Listen), a.listenOptions.ListenPort)
  113. udpConn, err := net.ListenUDP(M.NetworkFromNetAddr(N.NetworkUDP, bindAddr.Addr), bindAddr.UDPAddr())
  114. if err != nil {
  115. return nil, err
  116. }
  117. a.udpConn = udpConn
  118. a.udpAddr = bindAddr
  119. a.logger.Info("udp server started at ", udpConn.LocalAddr())
  120. return udpConn, err
  121. }
  122. func (a *myInboundAdapter) Close() error {
  123. var err error
  124. if a.clearSystemProxy != nil {
  125. err = a.clearSystemProxy()
  126. }
  127. return E.Errors(err, common.Close(
  128. a.tcpListener,
  129. common.PtrOrNil(a.udpConn),
  130. ))
  131. }
  132. func (a *myInboundAdapter) upstreamHandler(metadata adapter.InboundContext) adapter.UpstreamHandlerAdapter {
  133. return adapter.NewUpstreamHandler(metadata, a.newConnection, a.streamPacketConnection, a)
  134. }
  135. func (a *myInboundAdapter) upstreamContextHandler() adapter.UpstreamHandlerAdapter {
  136. return adapter.NewUpstreamContextHandler(a.newConnection, a.newPacketConnection, a)
  137. }
  138. func (a *myInboundAdapter) newConnection(ctx context.Context, conn net.Conn, metadata adapter.InboundContext) error {
  139. a.logger.InfoContext(ctx, "inbound connection to ", metadata.Destination)
  140. return a.router.RouteConnection(ctx, conn, metadata)
  141. }
  142. func (a *myInboundAdapter) streamPacketConnection(ctx context.Context, conn N.PacketConn, metadata adapter.InboundContext) error {
  143. a.logger.InfoContext(ctx, "inbound packet connection to ", metadata.Destination)
  144. return a.router.RoutePacketConnection(ctx, conn, metadata)
  145. }
  146. func (a *myInboundAdapter) newPacketConnection(ctx context.Context, conn N.PacketConn, metadata adapter.InboundContext) error {
  147. ctx = log.ContextWithNewID(ctx)
  148. a.logger.InfoContext(ctx, "inbound packet connection from ", metadata.Source)
  149. a.logger.InfoContext(ctx, "inbound packet connection to ", metadata.Destination)
  150. return a.router.RoutePacketConnection(ctx, conn, metadata)
  151. }
  152. func (a *myInboundAdapter) loopTCPIn() {
  153. tcpListener := a.tcpListener
  154. for {
  155. conn, err := tcpListener.Accept()
  156. if err != nil {
  157. return
  158. }
  159. go a.injectTCP(conn)
  160. }
  161. }
  162. func (a *myInboundAdapter) createMetadata(conn net.Conn, metadata adapter.InboundContext) adapter.InboundContext {
  163. metadata.Inbound = a.tag
  164. metadata.InboundType = a.protocol
  165. metadata.SniffEnabled = a.listenOptions.SniffEnabled
  166. metadata.SniffOverrideDestination = a.listenOptions.SniffOverrideDestination
  167. metadata.DomainStrategy = dns.DomainStrategy(a.listenOptions.DomainStrategy)
  168. metadata.Network = N.NetworkTCP
  169. if !metadata.Source.IsValid() {
  170. metadata.Source = M.SocksaddrFromNet(conn.RemoteAddr())
  171. }
  172. if !metadata.Destination.IsValid() {
  173. metadata.Destination = M.SocksaddrFromNet(conn.LocalAddr())
  174. }
  175. if tcpConn, isTCP := common.Cast[*net.TCPConn](conn); isTCP {
  176. metadata.OriginDestination = M.SocksaddrFromNet(tcpConn.LocalAddr())
  177. }
  178. return metadata
  179. }
  180. func (a *myInboundAdapter) injectTCP(conn net.Conn) {
  181. ctx := log.ContextWithNewID(a.ctx)
  182. metadata := a.createMetadata(conn, adapter.InboundContext{})
  183. a.logger.InfoContext(ctx, "inbound connection from ", metadata.Source)
  184. hErr := a.connHandler.NewConnection(ctx, conn, metadata)
  185. if hErr != nil {
  186. conn.Close()
  187. a.NewError(ctx, E.Cause(hErr, "process connection from ", metadata.Source))
  188. }
  189. }
  190. func (a *myInboundAdapter) routeTCP(ctx context.Context, conn net.Conn, metadata adapter.InboundContext) {
  191. a.logger.InfoContext(ctx, "inbound connection from ", metadata.Source)
  192. hErr := a.newConnection(ctx, conn, metadata)
  193. if hErr != nil {
  194. conn.Close()
  195. a.NewError(ctx, E.Cause(hErr, "process connection from ", metadata.Source))
  196. }
  197. }
  198. func (a *myInboundAdapter) loopUDPIn() {
  199. defer close(a.packetOutboundClosed)
  200. _buffer := buf.StackNewPacket()
  201. defer common.KeepAlive(_buffer)
  202. buffer := common.Dup(_buffer)
  203. defer buffer.Release()
  204. buffer.IncRef()
  205. defer buffer.DecRef()
  206. packetService := (*myInboundPacketAdapter)(a)
  207. for {
  208. buffer.Reset()
  209. n, addr, err := a.udpConn.ReadFromUDPAddrPort(buffer.FreeBytes())
  210. if err != nil {
  211. return
  212. }
  213. buffer.Truncate(n)
  214. var metadata adapter.InboundContext
  215. metadata.Inbound = a.tag
  216. metadata.InboundType = a.protocol
  217. metadata.SniffEnabled = a.listenOptions.SniffEnabled
  218. metadata.SniffOverrideDestination = a.listenOptions.SniffOverrideDestination
  219. metadata.DomainStrategy = dns.DomainStrategy(a.listenOptions.DomainStrategy)
  220. metadata.Network = N.NetworkUDP
  221. metadata.Source = M.SocksaddrFromNetIP(addr)
  222. metadata.OriginDestination = a.udpAddr
  223. err = a.packetHandler.NewPacket(a.ctx, packetService, buffer, metadata)
  224. if err != nil {
  225. a.newError(E.Cause(err, "process packet from ", metadata.Source))
  226. }
  227. }
  228. }
  229. func (a *myInboundAdapter) loopUDPOOBIn() {
  230. defer close(a.packetOutboundClosed)
  231. _buffer := buf.StackNewPacket()
  232. defer common.KeepAlive(_buffer)
  233. buffer := common.Dup(_buffer)
  234. defer buffer.Release()
  235. buffer.IncRef()
  236. defer buffer.DecRef()
  237. packetService := (*myInboundPacketAdapter)(a)
  238. oob := make([]byte, 1024)
  239. for {
  240. buffer.Reset()
  241. n, oobN, _, addr, err := a.udpConn.ReadMsgUDPAddrPort(buffer.FreeBytes(), oob)
  242. if err != nil {
  243. return
  244. }
  245. buffer.Truncate(n)
  246. var metadata adapter.InboundContext
  247. metadata.Inbound = a.tag
  248. metadata.InboundType = a.protocol
  249. metadata.SniffEnabled = a.listenOptions.SniffEnabled
  250. metadata.SniffOverrideDestination = a.listenOptions.SniffOverrideDestination
  251. metadata.DomainStrategy = dns.DomainStrategy(a.listenOptions.DomainStrategy)
  252. metadata.Network = N.NetworkUDP
  253. metadata.Source = M.SocksaddrFromNetIP(addr)
  254. metadata.OriginDestination = a.udpAddr
  255. err = a.oobPacketHandler.NewPacket(a.ctx, packetService, buffer, oob[:oobN], metadata)
  256. if err != nil {
  257. a.newError(E.Cause(err, "process packet from ", metadata.Source))
  258. }
  259. }
  260. }
  261. func (a *myInboundAdapter) loopUDPInThreadSafe() {
  262. defer close(a.packetOutboundClosed)
  263. packetService := (*myInboundPacketAdapter)(a)
  264. for {
  265. buffer := buf.NewPacket()
  266. n, addr, err := a.udpConn.ReadFromUDPAddrPort(buffer.FreeBytes())
  267. if err != nil {
  268. buffer.Release()
  269. return
  270. }
  271. buffer.Truncate(n)
  272. var metadata adapter.InboundContext
  273. metadata.Inbound = a.tag
  274. metadata.InboundType = a.protocol
  275. metadata.SniffEnabled = a.listenOptions.SniffEnabled
  276. metadata.SniffOverrideDestination = a.listenOptions.SniffOverrideDestination
  277. metadata.DomainStrategy = dns.DomainStrategy(a.listenOptions.DomainStrategy)
  278. metadata.Network = N.NetworkUDP
  279. metadata.Source = M.SocksaddrFromNetIP(addr)
  280. metadata.OriginDestination = a.udpAddr
  281. err = a.packetHandler.NewPacket(a.ctx, packetService, buffer, metadata)
  282. if err != nil {
  283. buffer.Release()
  284. a.newError(E.Cause(err, "process packet from ", metadata.Source))
  285. }
  286. }
  287. }
  288. func (a *myInboundAdapter) loopUDPOOBInThreadSafe() {
  289. defer close(a.packetOutboundClosed)
  290. packetService := (*myInboundPacketAdapter)(a)
  291. oob := make([]byte, 1024)
  292. for {
  293. buffer := buf.NewPacket()
  294. n, oobN, _, addr, err := a.udpConn.ReadMsgUDPAddrPort(buffer.FreeBytes(), oob)
  295. if err != nil {
  296. buffer.Release()
  297. return
  298. }
  299. buffer.Truncate(n)
  300. var metadata adapter.InboundContext
  301. metadata.Inbound = a.tag
  302. metadata.InboundType = a.protocol
  303. metadata.SniffEnabled = a.listenOptions.SniffEnabled
  304. metadata.SniffOverrideDestination = a.listenOptions.SniffOverrideDestination
  305. metadata.DomainStrategy = dns.DomainStrategy(a.listenOptions.DomainStrategy)
  306. metadata.Network = N.NetworkUDP
  307. metadata.Source = M.SocksaddrFromNetIP(addr)
  308. metadata.OriginDestination = a.udpAddr
  309. err = a.oobPacketHandler.NewPacket(a.ctx, packetService, buffer, oob[:oobN], metadata)
  310. if err != nil {
  311. buffer.Release()
  312. a.newError(E.Cause(err, "process packet from ", metadata.Source))
  313. }
  314. }
  315. }
  316. func (a *myInboundAdapter) loopUDPOut() {
  317. for {
  318. select {
  319. case packet := <-a.packetOutbound:
  320. err := a.writePacket(packet.buffer, packet.destination)
  321. if err != nil && !E.IsClosed(err) {
  322. a.newError(E.New("write back udp: ", err))
  323. }
  324. continue
  325. case <-a.packetOutboundClosed:
  326. }
  327. for {
  328. select {
  329. case packet := <-a.packetOutbound:
  330. packet.buffer.Release()
  331. default:
  332. return
  333. }
  334. }
  335. }
  336. }
  337. func (a *myInboundAdapter) newError(err error) {
  338. a.logger.Error(err)
  339. }
  340. func (a *myInboundAdapter) NewError(ctx context.Context, err error) {
  341. NewError(a.logger, ctx, err)
  342. }
  343. func NewError(logger log.ContextLogger, ctx context.Context, err error) {
  344. common.Close(err)
  345. if E.IsClosedOrCanceled(err) {
  346. logger.DebugContext(ctx, "connection closed: ", err)
  347. return
  348. }
  349. logger.ErrorContext(ctx, err)
  350. }
  351. func (a *myInboundAdapter) writePacket(buffer *buf.Buffer, destination M.Socksaddr) error {
  352. defer buffer.Release()
  353. if destination.IsFqdn() {
  354. udpAddr, err := net.ResolveUDPAddr(N.NetworkUDP, destination.String())
  355. if err != nil {
  356. return err
  357. }
  358. return common.Error(a.udpConn.WriteTo(buffer.Bytes(), udpAddr))
  359. }
  360. return common.Error(a.udpConn.WriteToUDPAddrPort(buffer.Bytes(), destination.AddrPort()))
  361. }
  362. type myInboundPacketAdapter myInboundAdapter
  363. func (s *myInboundPacketAdapter) ReadPacket(buffer *buf.Buffer) (M.Socksaddr, error) {
  364. n, addr, err := s.udpConn.ReadFromUDPAddrPort(buffer.FreeBytes())
  365. if err != nil {
  366. return M.Socksaddr{}, err
  367. }
  368. buffer.Truncate(n)
  369. return M.SocksaddrFromNetIP(addr), nil
  370. }
  371. func (s *myInboundPacketAdapter) WriteIsThreadUnsafe() {
  372. }
  373. type myInboundPacket struct {
  374. buffer *buf.Buffer
  375. destination M.Socksaddr
  376. }
  377. func (s *myInboundPacketAdapter) Upstream() any {
  378. return s.udpConn
  379. }
  380. func (s *myInboundPacketAdapter) WritePacket(buffer *buf.Buffer, destination M.Socksaddr) error {
  381. s.packetAccess.RLock()
  382. defer s.packetAccess.RUnlock()
  383. select {
  384. case <-s.packetOutboundClosed:
  385. return os.ErrClosed
  386. default:
  387. }
  388. s.packetOutbound <- &myInboundPacket{buffer, destination}
  389. return nil
  390. }
  391. func (s *myInboundPacketAdapter) Close() error {
  392. return s.udpConn.Close()
  393. }
  394. func (s *myInboundPacketAdapter) LocalAddr() net.Addr {
  395. return s.udpConn.LocalAddr()
  396. }
  397. func (s *myInboundPacketAdapter) SetDeadline(t time.Time) error {
  398. return s.udpConn.SetDeadline(t)
  399. }
  400. func (s *myInboundPacketAdapter) SetReadDeadline(t time.Time) error {
  401. return s.udpConn.SetReadDeadline(t)
  402. }
  403. func (s *myInboundPacketAdapter) SetWriteDeadline(t time.Time) error {
  404. return s.udpConn.SetWriteDeadline(t)
  405. }