rule_default.go 9.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302
  1. package rule
  2. import (
  3. "context"
  4. "github.com/sagernet/sing-box/adapter"
  5. C "github.com/sagernet/sing-box/constant"
  6. "github.com/sagernet/sing-box/experimental/deprecated"
  7. "github.com/sagernet/sing-box/log"
  8. "github.com/sagernet/sing-box/option"
  9. E "github.com/sagernet/sing/common/exceptions"
  10. "github.com/sagernet/sing/service"
  11. )
  12. func NewRule(ctx context.Context, logger log.ContextLogger, options option.Rule, checkOutbound bool) (adapter.Rule, error) {
  13. switch options.Type {
  14. case "", C.RuleTypeDefault:
  15. if !options.DefaultOptions.IsValid() {
  16. return nil, E.New("missing conditions")
  17. }
  18. switch options.DefaultOptions.Action {
  19. case "", C.RuleActionTypeRoute:
  20. if options.DefaultOptions.RouteOptions.Outbound == "" && checkOutbound {
  21. return nil, E.New("missing outbound field")
  22. }
  23. }
  24. return NewDefaultRule(ctx, logger, options.DefaultOptions)
  25. case C.RuleTypeLogical:
  26. if !options.LogicalOptions.IsValid() {
  27. return nil, E.New("missing conditions")
  28. }
  29. switch options.LogicalOptions.Action {
  30. case "", C.RuleActionTypeRoute:
  31. if options.LogicalOptions.RouteOptions.Outbound == "" && checkOutbound {
  32. return nil, E.New("missing outbound field")
  33. }
  34. }
  35. return NewLogicalRule(ctx, logger, options.LogicalOptions)
  36. default:
  37. return nil, E.New("unknown rule type: ", options.Type)
  38. }
  39. }
  40. var _ adapter.Rule = (*DefaultRule)(nil)
  41. type DefaultRule struct {
  42. abstractDefaultRule
  43. }
  44. type RuleItem interface {
  45. Match(metadata *adapter.InboundContext) bool
  46. String() string
  47. }
  48. func NewDefaultRule(ctx context.Context, logger log.ContextLogger, options option.DefaultRule) (*DefaultRule, error) {
  49. action, err := NewRuleAction(ctx, logger, options.RuleAction)
  50. if err != nil {
  51. return nil, E.Cause(err, "action")
  52. }
  53. rule := &DefaultRule{
  54. abstractDefaultRule{
  55. invert: options.Invert,
  56. action: action,
  57. },
  58. }
  59. router := service.FromContext[adapter.Router](ctx)
  60. networkManager := service.FromContext[adapter.NetworkManager](ctx)
  61. if len(options.Inbound) > 0 {
  62. item := NewInboundRule(options.Inbound)
  63. rule.items = append(rule.items, item)
  64. rule.allItems = append(rule.allItems, item)
  65. }
  66. if options.IPVersion > 0 {
  67. switch options.IPVersion {
  68. case 4, 6:
  69. item := NewIPVersionItem(options.IPVersion == 6)
  70. rule.items = append(rule.items, item)
  71. rule.allItems = append(rule.allItems, item)
  72. default:
  73. return nil, E.New("invalid ip version: ", options.IPVersion)
  74. }
  75. }
  76. if len(options.Network) > 0 {
  77. item := NewNetworkItem(options.Network)
  78. rule.items = append(rule.items, item)
  79. rule.allItems = append(rule.allItems, item)
  80. }
  81. if len(options.AuthUser) > 0 {
  82. item := NewAuthUserItem(options.AuthUser)
  83. rule.items = append(rule.items, item)
  84. rule.allItems = append(rule.allItems, item)
  85. }
  86. if len(options.Protocol) > 0 {
  87. item := NewProtocolItem(options.Protocol)
  88. rule.items = append(rule.items, item)
  89. rule.allItems = append(rule.allItems, item)
  90. }
  91. if len(options.Client) > 0 {
  92. item := NewClientItem(options.Client)
  93. rule.items = append(rule.items, item)
  94. rule.allItems = append(rule.allItems, item)
  95. }
  96. if len(options.Domain) > 0 || len(options.DomainSuffix) > 0 {
  97. item := NewDomainItem(options.Domain, options.DomainSuffix)
  98. rule.destinationAddressItems = append(rule.destinationAddressItems, item)
  99. rule.allItems = append(rule.allItems, item)
  100. }
  101. if len(options.DomainKeyword) > 0 {
  102. item := NewDomainKeywordItem(options.DomainKeyword)
  103. rule.destinationAddressItems = append(rule.destinationAddressItems, item)
  104. rule.allItems = append(rule.allItems, item)
  105. }
  106. if len(options.DomainRegex) > 0 {
  107. item, err := NewDomainRegexItem(options.DomainRegex)
  108. if err != nil {
  109. return nil, E.Cause(err, "domain_regex")
  110. }
  111. rule.destinationAddressItems = append(rule.destinationAddressItems, item)
  112. rule.allItems = append(rule.allItems, item)
  113. }
  114. if len(options.Geosite) > 0 {
  115. item := NewGeositeItem(router, logger, options.Geosite)
  116. rule.destinationAddressItems = append(rule.destinationAddressItems, item)
  117. rule.allItems = append(rule.allItems, item)
  118. }
  119. if len(options.SourceGeoIP) > 0 {
  120. item := NewGeoIPItem(router, logger, true, options.SourceGeoIP)
  121. rule.sourceAddressItems = append(rule.sourceAddressItems, item)
  122. rule.allItems = append(rule.allItems, item)
  123. }
  124. if len(options.GeoIP) > 0 {
  125. item := NewGeoIPItem(router, logger, false, options.GeoIP)
  126. rule.destinationIPCIDRItems = append(rule.destinationIPCIDRItems, item)
  127. rule.allItems = append(rule.allItems, item)
  128. }
  129. if len(options.SourceIPCIDR) > 0 {
  130. item, err := NewIPCIDRItem(true, options.SourceIPCIDR)
  131. if err != nil {
  132. return nil, E.Cause(err, "source_ip_cidr")
  133. }
  134. rule.sourceAddressItems = append(rule.sourceAddressItems, item)
  135. rule.allItems = append(rule.allItems, item)
  136. }
  137. if options.SourceIPIsPrivate {
  138. item := NewIPIsPrivateItem(true)
  139. rule.sourceAddressItems = append(rule.sourceAddressItems, item)
  140. rule.allItems = append(rule.allItems, item)
  141. }
  142. if len(options.IPCIDR) > 0 {
  143. item, err := NewIPCIDRItem(false, options.IPCIDR)
  144. if err != nil {
  145. return nil, E.Cause(err, "ipcidr")
  146. }
  147. rule.destinationIPCIDRItems = append(rule.destinationIPCIDRItems, item)
  148. rule.allItems = append(rule.allItems, item)
  149. }
  150. if options.IPIsPrivate {
  151. item := NewIPIsPrivateItem(false)
  152. rule.destinationIPCIDRItems = append(rule.destinationIPCIDRItems, item)
  153. rule.allItems = append(rule.allItems, item)
  154. }
  155. if len(options.SourcePort) > 0 {
  156. item := NewPortItem(true, options.SourcePort)
  157. rule.sourcePortItems = append(rule.sourcePortItems, item)
  158. rule.allItems = append(rule.allItems, item)
  159. }
  160. if len(options.SourcePortRange) > 0 {
  161. item, err := NewPortRangeItem(true, options.SourcePortRange)
  162. if err != nil {
  163. return nil, E.Cause(err, "source_port_range")
  164. }
  165. rule.sourcePortItems = append(rule.sourcePortItems, item)
  166. rule.allItems = append(rule.allItems, item)
  167. }
  168. if len(options.Port) > 0 {
  169. item := NewPortItem(false, options.Port)
  170. rule.destinationPortItems = append(rule.destinationPortItems, item)
  171. rule.allItems = append(rule.allItems, item)
  172. }
  173. if len(options.PortRange) > 0 {
  174. item, err := NewPortRangeItem(false, options.PortRange)
  175. if err != nil {
  176. return nil, E.Cause(err, "port_range")
  177. }
  178. rule.destinationPortItems = append(rule.destinationPortItems, item)
  179. rule.allItems = append(rule.allItems, item)
  180. }
  181. if len(options.ProcessName) > 0 {
  182. item := NewProcessItem(options.ProcessName)
  183. rule.items = append(rule.items, item)
  184. rule.allItems = append(rule.allItems, item)
  185. }
  186. if len(options.ProcessPath) > 0 {
  187. item := NewProcessPathItem(options.ProcessPath)
  188. rule.items = append(rule.items, item)
  189. rule.allItems = append(rule.allItems, item)
  190. }
  191. if len(options.ProcessPathRegex) > 0 {
  192. item, err := NewProcessPathRegexItem(options.ProcessPathRegex)
  193. if err != nil {
  194. return nil, E.Cause(err, "process_path_regex")
  195. }
  196. rule.items = append(rule.items, item)
  197. rule.allItems = append(rule.allItems, item)
  198. }
  199. if len(options.PackageName) > 0 {
  200. item := NewPackageNameItem(options.PackageName)
  201. rule.items = append(rule.items, item)
  202. rule.allItems = append(rule.allItems, item)
  203. }
  204. if len(options.User) > 0 {
  205. item := NewUserItem(options.User)
  206. rule.items = append(rule.items, item)
  207. rule.allItems = append(rule.allItems, item)
  208. }
  209. if len(options.UserID) > 0 {
  210. item := NewUserIDItem(options.UserID)
  211. rule.items = append(rule.items, item)
  212. rule.allItems = append(rule.allItems, item)
  213. }
  214. if options.ClashMode != "" {
  215. item := NewClashModeItem(ctx, options.ClashMode)
  216. rule.items = append(rule.items, item)
  217. rule.allItems = append(rule.allItems, item)
  218. }
  219. if len(options.NetworkType) > 0 {
  220. item := NewNetworkTypeItem(networkManager, options.NetworkType)
  221. rule.items = append(rule.items, item)
  222. rule.allItems = append(rule.allItems, item)
  223. }
  224. if options.NetworkIsExpensive {
  225. item := NewNetworkIsExpensiveItem(networkManager)
  226. rule.items = append(rule.items, item)
  227. rule.allItems = append(rule.allItems, item)
  228. }
  229. if options.NetworkIsConstrained {
  230. item := NewNetworkIsConstrainedItem(networkManager)
  231. rule.items = append(rule.items, item)
  232. rule.allItems = append(rule.allItems, item)
  233. }
  234. if len(options.WIFISSID) > 0 {
  235. item := NewWIFISSIDItem(networkManager, options.WIFISSID)
  236. rule.items = append(rule.items, item)
  237. rule.allItems = append(rule.allItems, item)
  238. }
  239. if len(options.WIFIBSSID) > 0 {
  240. item := NewWIFIBSSIDItem(networkManager, options.WIFIBSSID)
  241. rule.items = append(rule.items, item)
  242. rule.allItems = append(rule.allItems, item)
  243. }
  244. if len(options.RuleSet) > 0 {
  245. var matchSource bool
  246. if options.RuleSetIPCIDRMatchSource {
  247. matchSource = true
  248. } else
  249. //nolint:staticcheck
  250. if options.Deprecated_RulesetIPCIDRMatchSource {
  251. matchSource = true
  252. deprecated.Report(ctx, deprecated.OptionBadMatchSource)
  253. }
  254. item := NewRuleSetItem(router, options.RuleSet, matchSource, false)
  255. rule.items = append(rule.items, item)
  256. rule.allItems = append(rule.allItems, item)
  257. }
  258. return rule, nil
  259. }
  260. var _ adapter.Rule = (*LogicalRule)(nil)
  261. type LogicalRule struct {
  262. abstractLogicalRule
  263. }
  264. func NewLogicalRule(ctx context.Context, logger log.ContextLogger, options option.LogicalRule) (*LogicalRule, error) {
  265. action, err := NewRuleAction(ctx, logger, options.RuleAction)
  266. if err != nil {
  267. return nil, E.Cause(err, "action")
  268. }
  269. rule := &LogicalRule{
  270. abstractLogicalRule{
  271. rules: make([]adapter.HeadlessRule, len(options.Rules)),
  272. invert: options.Invert,
  273. action: action,
  274. },
  275. }
  276. switch options.Mode {
  277. case C.LogicalTypeAnd:
  278. rule.mode = C.LogicalTypeAnd
  279. case C.LogicalTypeOr:
  280. rule.mode = C.LogicalTypeOr
  281. default:
  282. return nil, E.New("unknown logical mode: ", options.Mode)
  283. }
  284. for i, subOptions := range options.Rules {
  285. subRule, err := NewRule(ctx, logger, subOptions, false)
  286. if err != nil {
  287. return nil, E.Cause(err, "sub rule[", i, "]")
  288. }
  289. rule.rules[i] = subRule
  290. }
  291. return rule, nil
  292. }