https.go 5.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213
  1. package transport
  2. import (
  3. "bytes"
  4. "context"
  5. "io"
  6. "net"
  7. "net/http"
  8. "net/url"
  9. "strconv"
  10. "github.com/sagernet/sing-box/adapter"
  11. "github.com/sagernet/sing-box/common/dialer"
  12. "github.com/sagernet/sing-box/common/tls"
  13. C "github.com/sagernet/sing-box/constant"
  14. "github.com/sagernet/sing-box/dns"
  15. "github.com/sagernet/sing-box/log"
  16. "github.com/sagernet/sing-box/option"
  17. "github.com/sagernet/sing/common"
  18. "github.com/sagernet/sing/common/buf"
  19. E "github.com/sagernet/sing/common/exceptions"
  20. "github.com/sagernet/sing/common/logger"
  21. M "github.com/sagernet/sing/common/metadata"
  22. N "github.com/sagernet/sing/common/network"
  23. aTLS "github.com/sagernet/sing/common/tls"
  24. sHTTP "github.com/sagernet/sing/protocol/http"
  25. mDNS "github.com/miekg/dns"
  26. "golang.org/x/net/http2"
  27. )
  28. const MimeType = "application/dns-message"
  29. var _ adapter.DNSTransport = (*HTTPSTransport)(nil)
  30. func RegisterHTTPS(registry *dns.TransportRegistry) {
  31. dns.RegisterTransport[option.RemoteHTTPSDNSServerOptions](registry, C.DNSTypeHTTPS, NewHTTPS)
  32. }
  33. type HTTPSTransport struct {
  34. dns.TransportAdapter
  35. logger logger.ContextLogger
  36. dialer N.Dialer
  37. destination *url.URL
  38. headers http.Header
  39. transport *http.Transport
  40. }
  41. func NewHTTPS(ctx context.Context, logger log.ContextLogger, tag string, options option.RemoteHTTPSDNSServerOptions) (adapter.DNSTransport, error) {
  42. transportDialer, err := dns.NewRemoteDialer(ctx, options.RemoteDNSServerOptions)
  43. if err != nil {
  44. return nil, err
  45. }
  46. tlsOptions := common.PtrValueOrDefault(options.TLS)
  47. tlsOptions.Enabled = true
  48. tlsConfig, err := tls.NewClient(ctx, options.Server, tlsOptions)
  49. if err != nil {
  50. return nil, err
  51. }
  52. if common.Error(tlsConfig.Config()) == nil && !common.Contains(tlsConfig.NextProtos(), http2.NextProtoTLS) {
  53. tlsConfig.SetNextProtos(append(tlsConfig.NextProtos(), http2.NextProtoTLS))
  54. }
  55. if !common.Contains(tlsConfig.NextProtos(), "http/1.1") {
  56. tlsConfig.SetNextProtos(append(tlsConfig.NextProtos(), "http/1.1"))
  57. }
  58. headers := options.Headers.Build()
  59. host := headers.Get("Host")
  60. if host != "" {
  61. headers.Del("Host")
  62. } else {
  63. if tlsConfig.ServerName() != "" {
  64. host = tlsConfig.ServerName()
  65. } else {
  66. host = options.Server
  67. }
  68. }
  69. destinationURL := url.URL{
  70. Scheme: "https",
  71. Host: host,
  72. }
  73. if destinationURL.Host == "" {
  74. destinationURL.Host = options.Server
  75. }
  76. if options.ServerPort != 0 && options.ServerPort != 443 {
  77. destinationURL.Host = net.JoinHostPort(destinationURL.Host, strconv.Itoa(int(options.ServerPort)))
  78. }
  79. path := options.Path
  80. if path == "" {
  81. path = "/dns-query"
  82. }
  83. err = sHTTP.URLSetPath(&destinationURL, path)
  84. if err != nil {
  85. return nil, err
  86. }
  87. serverAddr := options.DNSServerAddressOptions.Build()
  88. if serverAddr.Port == 0 {
  89. serverAddr.Port = 443
  90. }
  91. return NewHTTPSRaw(
  92. dns.NewTransportAdapterWithRemoteOptions(C.DNSTypeHTTPS, tag, options.RemoteDNSServerOptions),
  93. logger,
  94. transportDialer,
  95. &destinationURL,
  96. headers,
  97. serverAddr,
  98. tlsConfig,
  99. ), nil
  100. }
  101. func NewHTTPSRaw(
  102. adapter dns.TransportAdapter,
  103. logger log.ContextLogger,
  104. dialer N.Dialer,
  105. destination *url.URL,
  106. headers http.Header,
  107. serverAddr M.Socksaddr,
  108. tlsConfig tls.Config,
  109. ) *HTTPSTransport {
  110. var transport *http.Transport
  111. if tlsConfig != nil {
  112. transport = &http.Transport{
  113. ForceAttemptHTTP2: true,
  114. DialTLSContext: func(ctx context.Context, network, addr string) (net.Conn, error) {
  115. tcpConn, hErr := dialer.DialContext(ctx, network, serverAddr)
  116. if hErr != nil {
  117. return nil, hErr
  118. }
  119. tlsConn, hErr := aTLS.ClientHandshake(ctx, tcpConn, tlsConfig)
  120. if hErr != nil {
  121. tcpConn.Close()
  122. return nil, hErr
  123. }
  124. return tlsConn, nil
  125. },
  126. }
  127. } else {
  128. transport = &http.Transport{
  129. DialContext: func(ctx context.Context, network, addr string) (net.Conn, error) {
  130. return dialer.DialContext(ctx, network, serverAddr)
  131. },
  132. }
  133. }
  134. return &HTTPSTransport{
  135. TransportAdapter: adapter,
  136. logger: logger,
  137. dialer: dialer,
  138. destination: destination,
  139. headers: headers,
  140. transport: transport,
  141. }
  142. }
  143. func (t *HTTPSTransport) Start(stage adapter.StartStage) error {
  144. if stage != adapter.StartStateStart {
  145. return nil
  146. }
  147. return dialer.InitializeDetour(t.dialer)
  148. }
  149. func (t *HTTPSTransport) Close() error {
  150. t.transport.CloseIdleConnections()
  151. t.transport = t.transport.Clone()
  152. return nil
  153. }
  154. func (t *HTTPSTransport) Exchange(ctx context.Context, message *mDNS.Msg) (*mDNS.Msg, error) {
  155. exMessage := *message
  156. exMessage.Id = 0
  157. exMessage.Compress = true
  158. requestBuffer := buf.NewSize(1 + message.Len())
  159. rawMessage, err := exMessage.PackBuffer(requestBuffer.FreeBytes())
  160. if err != nil {
  161. requestBuffer.Release()
  162. return nil, err
  163. }
  164. request, err := http.NewRequestWithContext(ctx, http.MethodPost, t.destination.String(), bytes.NewReader(rawMessage))
  165. if err != nil {
  166. requestBuffer.Release()
  167. return nil, err
  168. }
  169. request.Header = t.headers.Clone()
  170. request.Header.Set("Content-Type", MimeType)
  171. request.Header.Set("Accept", MimeType)
  172. response, err := t.transport.RoundTrip(request)
  173. requestBuffer.Release()
  174. if err != nil {
  175. return nil, err
  176. }
  177. defer response.Body.Close()
  178. if response.StatusCode != http.StatusOK {
  179. return nil, E.New("unexpected status: ", response.Status)
  180. }
  181. var responseMessage mDNS.Msg
  182. if response.ContentLength > 0 {
  183. responseBuffer := buf.NewSize(int(response.ContentLength))
  184. _, err = responseBuffer.ReadFullFrom(response.Body, int(response.ContentLength))
  185. if err != nil {
  186. return nil, err
  187. }
  188. err = responseMessage.Unpack(responseBuffer.Bytes())
  189. responseBuffer.Release()
  190. } else {
  191. rawMessage, err = io.ReadAll(response.Body)
  192. if err != nil {
  193. return nil, err
  194. }
  195. err = responseMessage.Unpack(rawMessage)
  196. }
  197. if err != nil {
  198. return nil, err
  199. }
  200. return &responseMessage, nil
  201. }