rule_default.go 9.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303
  1. package rule
  2. import (
  3. "context"
  4. "github.com/sagernet/sing-box/adapter"
  5. C "github.com/sagernet/sing-box/constant"
  6. "github.com/sagernet/sing-box/experimental/deprecated"
  7. "github.com/sagernet/sing-box/log"
  8. "github.com/sagernet/sing-box/option"
  9. "github.com/sagernet/sing/common"
  10. E "github.com/sagernet/sing/common/exceptions"
  11. "github.com/sagernet/sing/service"
  12. )
  13. func NewRule(ctx context.Context, logger log.ContextLogger, options option.Rule, checkOutbound bool) (adapter.Rule, error) {
  14. switch options.Type {
  15. case "", C.RuleTypeDefault:
  16. if !options.DefaultOptions.IsValid() {
  17. return nil, E.New("missing conditions")
  18. }
  19. switch options.DefaultOptions.Action {
  20. case "", C.RuleActionTypeRoute:
  21. if options.DefaultOptions.RouteOptions.Outbound == "" && checkOutbound {
  22. return nil, E.New("missing outbound field")
  23. }
  24. }
  25. return NewDefaultRule(ctx, logger, options.DefaultOptions)
  26. case C.RuleTypeLogical:
  27. if !options.LogicalOptions.IsValid() {
  28. return nil, E.New("missing conditions")
  29. }
  30. switch options.LogicalOptions.Action {
  31. case "", C.RuleActionTypeRoute:
  32. if options.LogicalOptions.RouteOptions.Outbound == "" && checkOutbound {
  33. return nil, E.New("missing outbound field")
  34. }
  35. }
  36. return NewLogicalRule(ctx, logger, options.LogicalOptions)
  37. default:
  38. return nil, E.New("unknown rule type: ", options.Type)
  39. }
  40. }
  41. var _ adapter.Rule = (*DefaultRule)(nil)
  42. type DefaultRule struct {
  43. abstractDefaultRule
  44. }
  45. type RuleItem interface {
  46. Match(metadata *adapter.InboundContext) bool
  47. String() string
  48. }
  49. func NewDefaultRule(ctx context.Context, logger log.ContextLogger, options option.DefaultRule) (*DefaultRule, error) {
  50. action, err := NewRuleAction(ctx, logger, options.RuleAction)
  51. if err != nil {
  52. return nil, E.Cause(err, "action")
  53. }
  54. rule := &DefaultRule{
  55. abstractDefaultRule{
  56. invert: options.Invert,
  57. action: action,
  58. },
  59. }
  60. router := service.FromContext[adapter.Router](ctx)
  61. networkManager := service.FromContext[adapter.NetworkManager](ctx)
  62. if len(options.Inbound) > 0 {
  63. item := NewInboundRule(options.Inbound)
  64. rule.items = append(rule.items, item)
  65. rule.allItems = append(rule.allItems, item)
  66. }
  67. if options.IPVersion > 0 {
  68. switch options.IPVersion {
  69. case 4, 6:
  70. item := NewIPVersionItem(options.IPVersion == 6)
  71. rule.items = append(rule.items, item)
  72. rule.allItems = append(rule.allItems, item)
  73. default:
  74. return nil, E.New("invalid ip version: ", options.IPVersion)
  75. }
  76. }
  77. if len(options.Network) > 0 {
  78. item := NewNetworkItem(options.Network)
  79. rule.items = append(rule.items, item)
  80. rule.allItems = append(rule.allItems, item)
  81. }
  82. if len(options.AuthUser) > 0 {
  83. item := NewAuthUserItem(options.AuthUser)
  84. rule.items = append(rule.items, item)
  85. rule.allItems = append(rule.allItems, item)
  86. }
  87. if len(options.Protocol) > 0 {
  88. item := NewProtocolItem(options.Protocol)
  89. rule.items = append(rule.items, item)
  90. rule.allItems = append(rule.allItems, item)
  91. }
  92. if len(options.Client) > 0 {
  93. item := NewClientItem(options.Client)
  94. rule.items = append(rule.items, item)
  95. rule.allItems = append(rule.allItems, item)
  96. }
  97. if len(options.Domain) > 0 || len(options.DomainSuffix) > 0 {
  98. item := NewDomainItem(options.Domain, options.DomainSuffix)
  99. rule.destinationAddressItems = append(rule.destinationAddressItems, item)
  100. rule.allItems = append(rule.allItems, item)
  101. }
  102. if len(options.DomainKeyword) > 0 {
  103. item := NewDomainKeywordItem(options.DomainKeyword)
  104. rule.destinationAddressItems = append(rule.destinationAddressItems, item)
  105. rule.allItems = append(rule.allItems, item)
  106. }
  107. if len(options.DomainRegex) > 0 {
  108. item, err := NewDomainRegexItem(options.DomainRegex)
  109. if err != nil {
  110. return nil, E.Cause(err, "domain_regex")
  111. }
  112. rule.destinationAddressItems = append(rule.destinationAddressItems, item)
  113. rule.allItems = append(rule.allItems, item)
  114. }
  115. if len(options.Geosite) > 0 {
  116. item := NewGeositeItem(router, logger, options.Geosite)
  117. rule.destinationAddressItems = append(rule.destinationAddressItems, item)
  118. rule.allItems = append(rule.allItems, item)
  119. }
  120. if len(options.SourceGeoIP) > 0 {
  121. item := NewGeoIPItem(router, logger, true, options.SourceGeoIP)
  122. rule.sourceAddressItems = append(rule.sourceAddressItems, item)
  123. rule.allItems = append(rule.allItems, item)
  124. }
  125. if len(options.GeoIP) > 0 {
  126. item := NewGeoIPItem(router, logger, false, options.GeoIP)
  127. rule.destinationIPCIDRItems = append(rule.destinationIPCIDRItems, item)
  128. rule.allItems = append(rule.allItems, item)
  129. }
  130. if len(options.SourceIPCIDR) > 0 {
  131. item, err := NewIPCIDRItem(true, options.SourceIPCIDR)
  132. if err != nil {
  133. return nil, E.Cause(err, "source_ip_cidr")
  134. }
  135. rule.sourceAddressItems = append(rule.sourceAddressItems, item)
  136. rule.allItems = append(rule.allItems, item)
  137. }
  138. if options.SourceIPIsPrivate {
  139. item := NewIPIsPrivateItem(true)
  140. rule.sourceAddressItems = append(rule.sourceAddressItems, item)
  141. rule.allItems = append(rule.allItems, item)
  142. }
  143. if len(options.IPCIDR) > 0 {
  144. item, err := NewIPCIDRItem(false, options.IPCIDR)
  145. if err != nil {
  146. return nil, E.Cause(err, "ipcidr")
  147. }
  148. rule.destinationIPCIDRItems = append(rule.destinationIPCIDRItems, item)
  149. rule.allItems = append(rule.allItems, item)
  150. }
  151. if options.IPIsPrivate {
  152. item := NewIPIsPrivateItem(false)
  153. rule.destinationIPCIDRItems = append(rule.destinationIPCIDRItems, item)
  154. rule.allItems = append(rule.allItems, item)
  155. }
  156. if len(options.SourcePort) > 0 {
  157. item := NewPortItem(true, options.SourcePort)
  158. rule.sourcePortItems = append(rule.sourcePortItems, item)
  159. rule.allItems = append(rule.allItems, item)
  160. }
  161. if len(options.SourcePortRange) > 0 {
  162. item, err := NewPortRangeItem(true, options.SourcePortRange)
  163. if err != nil {
  164. return nil, E.Cause(err, "source_port_range")
  165. }
  166. rule.sourcePortItems = append(rule.sourcePortItems, item)
  167. rule.allItems = append(rule.allItems, item)
  168. }
  169. if len(options.Port) > 0 {
  170. item := NewPortItem(false, options.Port)
  171. rule.destinationPortItems = append(rule.destinationPortItems, item)
  172. rule.allItems = append(rule.allItems, item)
  173. }
  174. if len(options.PortRange) > 0 {
  175. item, err := NewPortRangeItem(false, options.PortRange)
  176. if err != nil {
  177. return nil, E.Cause(err, "port_range")
  178. }
  179. rule.destinationPortItems = append(rule.destinationPortItems, item)
  180. rule.allItems = append(rule.allItems, item)
  181. }
  182. if len(options.ProcessName) > 0 {
  183. item := NewProcessItem(options.ProcessName)
  184. rule.items = append(rule.items, item)
  185. rule.allItems = append(rule.allItems, item)
  186. }
  187. if len(options.ProcessPath) > 0 {
  188. item := NewProcessPathItem(options.ProcessPath)
  189. rule.items = append(rule.items, item)
  190. rule.allItems = append(rule.allItems, item)
  191. }
  192. if len(options.ProcessPathRegex) > 0 {
  193. item, err := NewProcessPathRegexItem(options.ProcessPathRegex)
  194. if err != nil {
  195. return nil, E.Cause(err, "process_path_regex")
  196. }
  197. rule.items = append(rule.items, item)
  198. rule.allItems = append(rule.allItems, item)
  199. }
  200. if len(options.PackageName) > 0 {
  201. item := NewPackageNameItem(options.PackageName)
  202. rule.items = append(rule.items, item)
  203. rule.allItems = append(rule.allItems, item)
  204. }
  205. if len(options.User) > 0 {
  206. item := NewUserItem(options.User)
  207. rule.items = append(rule.items, item)
  208. rule.allItems = append(rule.allItems, item)
  209. }
  210. if len(options.UserID) > 0 {
  211. item := NewUserIDItem(options.UserID)
  212. rule.items = append(rule.items, item)
  213. rule.allItems = append(rule.allItems, item)
  214. }
  215. if options.ClashMode != "" {
  216. item := NewClashModeItem(ctx, options.ClashMode)
  217. rule.items = append(rule.items, item)
  218. rule.allItems = append(rule.allItems, item)
  219. }
  220. if len(options.NetworkType) > 0 {
  221. item := NewNetworkTypeItem(networkManager, common.Map(options.NetworkType, option.InterfaceType.Build))
  222. rule.items = append(rule.items, item)
  223. rule.allItems = append(rule.allItems, item)
  224. }
  225. if options.NetworkIsExpensive {
  226. item := NewNetworkIsExpensiveItem(networkManager)
  227. rule.items = append(rule.items, item)
  228. rule.allItems = append(rule.allItems, item)
  229. }
  230. if options.NetworkIsConstrained {
  231. item := NewNetworkIsConstrainedItem(networkManager)
  232. rule.items = append(rule.items, item)
  233. rule.allItems = append(rule.allItems, item)
  234. }
  235. if len(options.WIFISSID) > 0 {
  236. item := NewWIFISSIDItem(networkManager, options.WIFISSID)
  237. rule.items = append(rule.items, item)
  238. rule.allItems = append(rule.allItems, item)
  239. }
  240. if len(options.WIFIBSSID) > 0 {
  241. item := NewWIFIBSSIDItem(networkManager, options.WIFIBSSID)
  242. rule.items = append(rule.items, item)
  243. rule.allItems = append(rule.allItems, item)
  244. }
  245. if len(options.RuleSet) > 0 {
  246. var matchSource bool
  247. if options.RuleSetIPCIDRMatchSource {
  248. matchSource = true
  249. } else
  250. //nolint:staticcheck
  251. if options.Deprecated_RulesetIPCIDRMatchSource {
  252. matchSource = true
  253. deprecated.Report(ctx, deprecated.OptionBadMatchSource)
  254. }
  255. item := NewRuleSetItem(router, options.RuleSet, matchSource, false)
  256. rule.items = append(rule.items, item)
  257. rule.allItems = append(rule.allItems, item)
  258. }
  259. return rule, nil
  260. }
  261. var _ adapter.Rule = (*LogicalRule)(nil)
  262. type LogicalRule struct {
  263. abstractLogicalRule
  264. }
  265. func NewLogicalRule(ctx context.Context, logger log.ContextLogger, options option.LogicalRule) (*LogicalRule, error) {
  266. action, err := NewRuleAction(ctx, logger, options.RuleAction)
  267. if err != nil {
  268. return nil, E.Cause(err, "action")
  269. }
  270. rule := &LogicalRule{
  271. abstractLogicalRule{
  272. rules: make([]adapter.HeadlessRule, len(options.Rules)),
  273. invert: options.Invert,
  274. action: action,
  275. },
  276. }
  277. switch options.Mode {
  278. case C.LogicalTypeAnd:
  279. rule.mode = C.LogicalTypeAnd
  280. case C.LogicalTypeOr:
  281. rule.mode = C.LogicalTypeOr
  282. default:
  283. return nil, E.New("unknown logical mode: ", options.Mode)
  284. }
  285. for i, subOptions := range options.Rules {
  286. subRule, err := NewRule(ctx, logger, subOptions, false)
  287. if err != nil {
  288. return nil, E.Cause(err, "sub rule[", i, "]")
  289. }
  290. rule.rules[i] = subRule
  291. }
  292. return rule, nil
  293. }