https.go 5.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221
  1. package transport
  2. import (
  3. "bytes"
  4. "context"
  5. "errors"
  6. "io"
  7. "net"
  8. "net/http"
  9. "net/url"
  10. "strconv"
  11. "sync"
  12. "time"
  13. "github.com/sagernet/sing-box/adapter"
  14. "github.com/sagernet/sing-box/common/dialer"
  15. "github.com/sagernet/sing-box/common/tls"
  16. C "github.com/sagernet/sing-box/constant"
  17. "github.com/sagernet/sing-box/dns"
  18. "github.com/sagernet/sing-box/log"
  19. "github.com/sagernet/sing-box/option"
  20. "github.com/sagernet/sing/common"
  21. "github.com/sagernet/sing/common/buf"
  22. E "github.com/sagernet/sing/common/exceptions"
  23. "github.com/sagernet/sing/common/logger"
  24. M "github.com/sagernet/sing/common/metadata"
  25. N "github.com/sagernet/sing/common/network"
  26. sHTTP "github.com/sagernet/sing/protocol/http"
  27. mDNS "github.com/miekg/dns"
  28. "golang.org/x/net/http2"
  29. )
  30. const MimeType = "application/dns-message"
  31. var _ adapter.DNSTransport = (*HTTPSTransport)(nil)
  32. func RegisterHTTPS(registry *dns.TransportRegistry) {
  33. dns.RegisterTransport[option.RemoteHTTPSDNSServerOptions](registry, C.DNSTypeHTTPS, NewHTTPS)
  34. }
  35. type HTTPSTransport struct {
  36. dns.TransportAdapter
  37. logger logger.ContextLogger
  38. dialer N.Dialer
  39. destination *url.URL
  40. headers http.Header
  41. transportAccess sync.Mutex
  42. transport *HTTPSTransportWrapper
  43. transportResetAt time.Time
  44. }
  45. func NewHTTPS(ctx context.Context, logger log.ContextLogger, tag string, options option.RemoteHTTPSDNSServerOptions) (adapter.DNSTransport, error) {
  46. transportDialer, err := dns.NewRemoteDialer(ctx, options.RemoteDNSServerOptions)
  47. if err != nil {
  48. return nil, err
  49. }
  50. tlsOptions := common.PtrValueOrDefault(options.TLS)
  51. tlsOptions.Enabled = true
  52. tlsConfig, err := tls.NewClient(ctx, logger, options.Server, tlsOptions)
  53. if err != nil {
  54. return nil, err
  55. }
  56. if len(tlsConfig.NextProtos()) == 0 {
  57. tlsConfig.SetNextProtos([]string{http2.NextProtoTLS, "http/1.1"})
  58. }
  59. headers := options.Headers.Build()
  60. host := headers.Get("Host")
  61. if host != "" {
  62. headers.Del("Host")
  63. } else {
  64. if tlsConfig.ServerName() != "" {
  65. host = tlsConfig.ServerName()
  66. } else {
  67. host = options.Server
  68. }
  69. }
  70. destinationURL := url.URL{
  71. Scheme: "https",
  72. Host: host,
  73. }
  74. if destinationURL.Host == "" {
  75. destinationURL.Host = options.Server
  76. }
  77. if options.ServerPort != 0 && options.ServerPort != 443 {
  78. destinationURL.Host = net.JoinHostPort(destinationURL.Host, strconv.Itoa(int(options.ServerPort)))
  79. }
  80. path := options.Path
  81. if path == "" {
  82. path = "/dns-query"
  83. }
  84. err = sHTTP.URLSetPath(&destinationURL, path)
  85. if err != nil {
  86. return nil, err
  87. }
  88. serverAddr := options.DNSServerAddressOptions.Build()
  89. if serverAddr.Port == 0 {
  90. serverAddr.Port = 443
  91. }
  92. if !serverAddr.IsValid() {
  93. return nil, E.New("invalid server address: ", serverAddr)
  94. }
  95. return NewHTTPSRaw(
  96. dns.NewTransportAdapterWithRemoteOptions(C.DNSTypeHTTPS, tag, options.RemoteDNSServerOptions),
  97. logger,
  98. transportDialer,
  99. &destinationURL,
  100. headers,
  101. serverAddr,
  102. tlsConfig,
  103. ), nil
  104. }
  105. func NewHTTPSRaw(
  106. adapter dns.TransportAdapter,
  107. logger log.ContextLogger,
  108. dialer N.Dialer,
  109. destination *url.URL,
  110. headers http.Header,
  111. serverAddr M.Socksaddr,
  112. tlsConfig tls.Config,
  113. ) *HTTPSTransport {
  114. return &HTTPSTransport{
  115. TransportAdapter: adapter,
  116. logger: logger,
  117. dialer: dialer,
  118. destination: destination,
  119. headers: headers,
  120. transport: NewHTTPSTransportWrapper(tls.NewDialer(dialer, tlsConfig), serverAddr),
  121. }
  122. }
  123. func (t *HTTPSTransport) Start(stage adapter.StartStage) error {
  124. if stage != adapter.StartStateStart {
  125. return nil
  126. }
  127. return dialer.InitializeDetour(t.dialer)
  128. }
  129. func (t *HTTPSTransport) Close() error {
  130. t.Reset()
  131. return nil
  132. }
  133. func (t *HTTPSTransport) Reset() {
  134. t.transportAccess.Lock()
  135. defer t.transportAccess.Unlock()
  136. t.transport.CloseIdleConnections()
  137. t.transport = t.transport.Clone()
  138. }
  139. func (t *HTTPSTransport) Exchange(ctx context.Context, message *mDNS.Msg) (*mDNS.Msg, error) {
  140. startAt := time.Now()
  141. response, err := t.exchange(ctx, message)
  142. if err != nil {
  143. if errors.Is(err, context.DeadlineExceeded) {
  144. t.transportAccess.Lock()
  145. defer t.transportAccess.Unlock()
  146. if t.transportResetAt.After(startAt) {
  147. return nil, err
  148. }
  149. t.transport.CloseIdleConnections()
  150. t.transport = t.transport.Clone()
  151. t.transportResetAt = time.Now()
  152. }
  153. return nil, err
  154. }
  155. return response, nil
  156. }
  157. func (t *HTTPSTransport) exchange(ctx context.Context, message *mDNS.Msg) (*mDNS.Msg, error) {
  158. exMessage := *message
  159. exMessage.Id = 0
  160. exMessage.Compress = true
  161. requestBuffer := buf.NewSize(1 + message.Len())
  162. rawMessage, err := exMessage.PackBuffer(requestBuffer.FreeBytes())
  163. if err != nil {
  164. requestBuffer.Release()
  165. return nil, err
  166. }
  167. request, err := http.NewRequestWithContext(ctx, http.MethodPost, t.destination.String(), bytes.NewReader(rawMessage))
  168. if err != nil {
  169. requestBuffer.Release()
  170. return nil, err
  171. }
  172. request.Header = t.headers.Clone()
  173. request.Header.Set("Content-Type", MimeType)
  174. request.Header.Set("Accept", MimeType)
  175. t.transportAccess.Lock()
  176. currentTransport := t.transport
  177. t.transportAccess.Unlock()
  178. response, err := currentTransport.RoundTrip(request)
  179. requestBuffer.Release()
  180. if err != nil {
  181. return nil, err
  182. }
  183. defer response.Body.Close()
  184. if response.StatusCode != http.StatusOK {
  185. return nil, E.New("unexpected status: ", response.Status)
  186. }
  187. var responseMessage mDNS.Msg
  188. if response.ContentLength > 0 {
  189. responseBuffer := buf.NewSize(int(response.ContentLength))
  190. defer responseBuffer.Release()
  191. _, err = responseBuffer.ReadFullFrom(response.Body, int(response.ContentLength))
  192. if err != nil {
  193. return nil, err
  194. }
  195. err = responseMessage.Unpack(responseBuffer.Bytes())
  196. } else {
  197. rawMessage, err = io.ReadAll(response.Body)
  198. if err != nil {
  199. return nil, err
  200. }
  201. err = responseMessage.Unpack(rawMessage)
  202. }
  203. if err != nil {
  204. return nil, err
  205. }
  206. return &responseMessage, nil
  207. }