endpoint.go 27 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873
  1. //go:build with_gvisor
  2. package tailscale
  3. import (
  4. "context"
  5. "fmt"
  6. "net"
  7. "net/http"
  8. "net/netip"
  9. "net/url"
  10. "os"
  11. "path/filepath"
  12. "reflect"
  13. "runtime"
  14. "strings"
  15. "sync/atomic"
  16. "syscall"
  17. "time"
  18. "github.com/sagernet/gvisor/pkg/tcpip"
  19. "github.com/sagernet/gvisor/pkg/tcpip/adapters/gonet"
  20. "github.com/sagernet/gvisor/pkg/tcpip/header"
  21. "github.com/sagernet/gvisor/pkg/tcpip/stack"
  22. "github.com/sagernet/gvisor/pkg/tcpip/transport/icmp"
  23. "github.com/sagernet/sing-box/adapter"
  24. "github.com/sagernet/sing-box/adapter/endpoint"
  25. "github.com/sagernet/sing-box/common/dialer"
  26. C "github.com/sagernet/sing-box/constant"
  27. "github.com/sagernet/sing-box/experimental/deprecated"
  28. "github.com/sagernet/sing-box/log"
  29. "github.com/sagernet/sing-box/option"
  30. "github.com/sagernet/sing-box/route/rule"
  31. "github.com/sagernet/sing-tun"
  32. "github.com/sagernet/sing-tun/ping"
  33. "github.com/sagernet/sing/common"
  34. "github.com/sagernet/sing/common/bufio"
  35. "github.com/sagernet/sing/common/control"
  36. E "github.com/sagernet/sing/common/exceptions"
  37. F "github.com/sagernet/sing/common/format"
  38. "github.com/sagernet/sing/common/logger"
  39. M "github.com/sagernet/sing/common/metadata"
  40. N "github.com/sagernet/sing/common/network"
  41. "github.com/sagernet/sing/service"
  42. "github.com/sagernet/sing/service/filemanager"
  43. _ "github.com/sagernet/tailscale/feature/relayserver"
  44. "github.com/sagernet/tailscale/ipn"
  45. tsDNS "github.com/sagernet/tailscale/net/dns"
  46. "github.com/sagernet/tailscale/net/netmon"
  47. "github.com/sagernet/tailscale/net/netns"
  48. "github.com/sagernet/tailscale/net/tsaddr"
  49. tsTUN "github.com/sagernet/tailscale/net/tstun"
  50. "github.com/sagernet/tailscale/tsnet"
  51. "github.com/sagernet/tailscale/types/ipproto"
  52. "github.com/sagernet/tailscale/types/nettype"
  53. "github.com/sagernet/tailscale/version"
  54. "github.com/sagernet/tailscale/wgengine"
  55. "github.com/sagernet/tailscale/wgengine/filter"
  56. "github.com/sagernet/tailscale/wgengine/router"
  57. "github.com/sagernet/tailscale/wgengine/wgcfg"
  58. "go4.org/netipx"
  59. )
  60. var (
  61. _ adapter.OutboundWithPreferredRoutes = (*Endpoint)(nil)
  62. _ adapter.DirectRouteOutbound = (*Endpoint)(nil)
  63. _ dialer.PacketDialerWithDestination = (*Endpoint)(nil)
  64. )
  65. func init() {
  66. version.SetVersion("sing-box " + C.Version)
  67. }
  68. func RegisterEndpoint(registry *endpoint.Registry) {
  69. endpoint.Register[option.TailscaleEndpointOptions](registry, C.TypeTailscale, NewEndpoint)
  70. }
  71. type Endpoint struct {
  72. endpoint.Adapter
  73. ctx context.Context
  74. router adapter.Router
  75. logger logger.ContextLogger
  76. dnsRouter adapter.DNSRouter
  77. network adapter.NetworkManager
  78. platformInterface adapter.PlatformInterface
  79. server *tsnet.Server
  80. stack *stack.Stack
  81. icmpForwarder *tun.ICMPForwarder
  82. filter *atomic.Pointer[filter.Filter]
  83. onReconfigHook wgengine.ReconfigListener
  84. cfg *wgcfg.Config
  85. dnsCfg *tsDNS.Config
  86. routeDomains common.TypedValue[map[string]bool]
  87. routePrefixes atomic.Pointer[netipx.IPSet]
  88. acceptRoutes bool
  89. exitNode string
  90. exitNodeAllowLANAccess bool
  91. advertiseRoutes []netip.Prefix
  92. advertiseExitNode bool
  93. advertiseTags []string
  94. relayServerPort *uint16
  95. relayServerStaticEndpoints []netip.AddrPort
  96. udpTimeout time.Duration
  97. systemInterface bool
  98. systemInterfaceName string
  99. systemInterfaceMTU uint32
  100. serverStarted bool
  101. systemTun tun.Tun
  102. systemDialer *dialer.DefaultDialer
  103. fallbackTCPCloser func()
  104. }
  105. func (t *Endpoint) registerNetstackHandlers() {
  106. netstack := t.server.ExportNetstack()
  107. if netstack == nil {
  108. return
  109. }
  110. previousTCP := netstack.GetTCPHandlerForFlow
  111. netstack.GetTCPHandlerForFlow = func(src, dst netip.AddrPort) (handler func(net.Conn), intercept bool) {
  112. if previousTCP != nil {
  113. handler, intercept = previousTCP(src, dst)
  114. if handler != nil || !intercept {
  115. return handler, intercept
  116. }
  117. }
  118. return func(conn net.Conn) {
  119. ctx := log.ContextWithNewID(t.ctx)
  120. source := M.SocksaddrFrom(src.Addr(), src.Port())
  121. destination := M.SocksaddrFrom(dst.Addr(), dst.Port())
  122. t.NewConnectionEx(ctx, conn, source, destination, nil)
  123. }, true
  124. }
  125. previousUDP := netstack.GetUDPHandlerForFlow
  126. netstack.GetUDPHandlerForFlow = func(src, dst netip.AddrPort) (handler func(nettype.ConnPacketConn), intercept bool) {
  127. if previousUDP != nil {
  128. handler, intercept = previousUDP(src, dst)
  129. if handler != nil || !intercept {
  130. return handler, intercept
  131. }
  132. }
  133. return func(conn nettype.ConnPacketConn) {
  134. ctx := log.ContextWithNewID(t.ctx)
  135. source := M.SocksaddrFrom(src.Addr(), src.Port())
  136. destination := M.SocksaddrFrom(dst.Addr(), dst.Port())
  137. packetConn := bufio.NewUnbindPacketConnWithAddr(conn, destination)
  138. t.NewPacketConnectionEx(ctx, packetConn, source, destination, nil)
  139. }, true
  140. }
  141. }
  142. func NewEndpoint(ctx context.Context, router adapter.Router, logger log.ContextLogger, tag string, options option.TailscaleEndpointOptions) (adapter.Endpoint, error) {
  143. stateDirectory := options.StateDirectory
  144. if stateDirectory == "" {
  145. stateDirectory = "tailscale"
  146. }
  147. hostname := options.Hostname
  148. if hostname == "" {
  149. osHostname, _ := os.Hostname()
  150. osHostname = strings.TrimSpace(osHostname)
  151. hostname = osHostname
  152. }
  153. if hostname == "" {
  154. hostname = "sing-box"
  155. }
  156. stateDirectory = filemanager.BasePath(ctx, os.ExpandEnv(stateDirectory))
  157. stateDirectory, _ = filepath.Abs(stateDirectory)
  158. for _, advertiseRoute := range options.AdvertiseRoutes {
  159. if advertiseRoute.Addr().IsUnspecified() && advertiseRoute.Bits() == 0 {
  160. return nil, E.New("`advertise_routes` cannot be default, use `advertise_exit_node` instead.")
  161. }
  162. }
  163. if options.AdvertiseExitNode && options.ExitNode != "" {
  164. return nil, E.New("cannot advertise an exit node and use an exit node at the same time.")
  165. }
  166. var udpTimeout time.Duration
  167. if options.UDPTimeout != 0 {
  168. udpTimeout = time.Duration(options.UDPTimeout)
  169. } else {
  170. udpTimeout = C.UDPTimeout
  171. }
  172. var remoteIsDomain bool
  173. if options.ControlURL != "" {
  174. controlURL, err := url.Parse(options.ControlURL)
  175. if err != nil {
  176. return nil, E.Cause(err, "parse control URL")
  177. }
  178. remoteIsDomain = M.ParseSocksaddr(controlURL.Hostname()).IsDomain()
  179. } else {
  180. // controlplane.tailscale.com
  181. remoteIsDomain = true
  182. }
  183. hasLegacyDialer := !reflect.DeepEqual(options.DialerOptions, option.DialerOptions{})
  184. hasControlHTTPClient := options.ControlHTTPClient != nil && !options.ControlHTTPClient.IsEmpty()
  185. if hasLegacyDialer && hasControlHTTPClient {
  186. return nil, E.New("control_http_client is conflict with deprecated dialer options")
  187. }
  188. controlHTTPClientOptions := common.PtrValueOrDefault(options.ControlHTTPClient)
  189. if hasLegacyDialer {
  190. deprecated.Report(ctx, deprecated.OptionLegacyTailscaleEndpointDialer)
  191. controlHTTPClientOptions.DialerOptions = options.DialerOptions
  192. }
  193. if remoteIsDomain {
  194. controlHTTPClientOptions.ResolveOnDetour = true
  195. }
  196. outboundDialer, err := dialer.NewWithOptions(dialer.Options{
  197. Context: ctx,
  198. Options: options.DialerOptions,
  199. RemoteIsDomain: remoteIsDomain,
  200. ResolverOnDetour: true,
  201. NewDialer: true,
  202. })
  203. if err != nil {
  204. return nil, err
  205. }
  206. dnsRouter := service.FromContext[adapter.DNSRouter](ctx)
  207. httpClientManager := service.FromContext[adapter.HTTPClientManager](ctx)
  208. controlTransport, err := httpClientManager.ResolveTransport(ctx, logger, controlHTTPClientOptions)
  209. if err != nil {
  210. return nil, E.Cause(err, "create control HTTP client")
  211. }
  212. controlHTTPClient := &http.Client{Transport: controlTransport}
  213. server := &tsnet.Server{
  214. Dir: stateDirectory,
  215. Hostname: hostname,
  216. Logf: func(format string, args ...any) {
  217. logger.Trace(fmt.Sprintf(format, args...))
  218. },
  219. UserLogf: func(format string, args ...any) {
  220. logger.Debug(fmt.Sprintf(format, args...))
  221. },
  222. Ephemeral: options.Ephemeral,
  223. AuthKey: options.AuthKey,
  224. ControlURL: options.ControlURL,
  225. AdvertiseTags: options.AdvertiseTags,
  226. Dialer: &endpointDialer{Dialer: outboundDialer, logger: logger},
  227. LookupHook: func(ctx context.Context, host string) ([]netip.Addr, error) {
  228. return dnsRouter.Lookup(ctx, host, outboundDialer.(dialer.ResolveDialer).QueryOptions())
  229. },
  230. DNS: &dnsConfigurtor{},
  231. HTTPClient: controlHTTPClient,
  232. }
  233. return &Endpoint{
  234. Adapter: endpoint.NewAdapter(C.TypeTailscale, tag, []string{N.NetworkTCP, N.NetworkUDP, N.NetworkICMP}, nil),
  235. ctx: ctx,
  236. router: router,
  237. logger: logger,
  238. dnsRouter: dnsRouter,
  239. network: service.FromContext[adapter.NetworkManager](ctx),
  240. platformInterface: service.FromContext[adapter.PlatformInterface](ctx),
  241. server: server,
  242. acceptRoutes: options.AcceptRoutes,
  243. exitNode: options.ExitNode,
  244. exitNodeAllowLANAccess: options.ExitNodeAllowLANAccess,
  245. advertiseRoutes: options.AdvertiseRoutes,
  246. advertiseExitNode: options.AdvertiseExitNode,
  247. advertiseTags: options.AdvertiseTags,
  248. relayServerPort: options.RelayServerPort,
  249. relayServerStaticEndpoints: options.RelayServerStaticEndpoints,
  250. udpTimeout: udpTimeout,
  251. systemInterface: options.SystemInterface,
  252. systemInterfaceName: options.SystemInterfaceName,
  253. systemInterfaceMTU: options.SystemInterfaceMTU,
  254. }, nil
  255. }
  256. func (t *Endpoint) Start(stage adapter.StartStage) error {
  257. switch stage {
  258. case adapter.StartStateStart:
  259. return t.start()
  260. case adapter.StartStatePostStart:
  261. return t.postStart()
  262. }
  263. return nil
  264. }
  265. func (t *Endpoint) start() error {
  266. if t.platformInterface != nil {
  267. err := t.network.UpdateInterfaces()
  268. if err != nil {
  269. return err
  270. }
  271. netmon.RegisterInterfaceGetter(func() ([]netmon.Interface, error) {
  272. return common.Map(t.network.InterfaceFinder().Interfaces(), func(it control.Interface) netmon.Interface {
  273. return netmon.Interface{
  274. Interface: &net.Interface{
  275. Index: it.Index,
  276. MTU: it.MTU,
  277. Name: it.Name,
  278. HardwareAddr: it.HardwareAddr,
  279. Flags: it.Flags,
  280. },
  281. AltAddrs: common.Map(it.Addresses, func(it netip.Prefix) net.Addr {
  282. return &net.IPNet{
  283. IP: it.Addr().AsSlice(),
  284. Mask: net.CIDRMask(it.Bits(), it.Addr().BitLen()),
  285. }
  286. }),
  287. }
  288. }), nil
  289. })
  290. }
  291. if t.systemInterface {
  292. mtu := t.systemInterfaceMTU
  293. if mtu == 0 {
  294. mtu = uint32(tsTUN.DefaultTUNMTU())
  295. }
  296. tunName := t.systemInterfaceName
  297. if tunName == "" {
  298. tunName = tun.CalculateInterfaceName("tailscale")
  299. }
  300. tunOptions := tun.Options{
  301. Name: tunName,
  302. MTU: mtu,
  303. GSO: true,
  304. InterfaceScope: true,
  305. InterfaceMonitor: t.network.InterfaceMonitor(),
  306. InterfaceFinder: t.network.InterfaceFinder(),
  307. Logger: t.logger,
  308. EXP_ExternalConfiguration: true,
  309. }
  310. systemTun, err := tun.New(tunOptions)
  311. if err != nil {
  312. return err
  313. }
  314. err = systemTun.Start()
  315. if err != nil {
  316. _ = systemTun.Close()
  317. return err
  318. }
  319. wgTunDevice, err := newTunDeviceAdapter(systemTun, int(mtu), t.logger)
  320. if err != nil {
  321. _ = systemTun.Close()
  322. return err
  323. }
  324. systemDialer, err := dialer.NewDefault(t.ctx, option.DialerOptions{
  325. BindInterface: tunName,
  326. })
  327. if err != nil {
  328. _ = systemTun.Close()
  329. return err
  330. }
  331. t.systemTun = systemTun
  332. t.systemDialer = systemDialer
  333. t.server.TunDevice = wgTunDevice
  334. }
  335. if mark := t.network.AutoRedirectOutputMark(); mark > 0 {
  336. controlFunc := t.network.AutoRedirectOutputMarkFunc()
  337. if bindFunc := t.network.AutoDetectInterfaceFunc(); bindFunc != nil {
  338. controlFunc = control.Append(controlFunc, bindFunc)
  339. }
  340. netns.SetControlFunc(controlFunc)
  341. } else if runtime.GOOS == "android" && t.platformInterface != nil {
  342. netns.SetControlFunc(func(network, address string, c syscall.RawConn) error {
  343. return control.Raw(c, func(fd uintptr) error {
  344. return t.platformInterface.AutoDetectInterfaceControl(int(fd))
  345. })
  346. })
  347. }
  348. return nil
  349. }
  350. func (t *Endpoint) postStart() error {
  351. err := t.server.Start()
  352. if err != nil {
  353. if t.systemTun != nil {
  354. _ = t.systemTun.Close()
  355. }
  356. return err
  357. }
  358. t.serverStarted = true
  359. if t.fallbackTCPCloser == nil {
  360. t.fallbackTCPCloser = t.server.RegisterFallbackTCPHandler(func(src, dst netip.AddrPort) (handler func(net.Conn), intercept bool) {
  361. return func(conn net.Conn) {
  362. ctx := log.ContextWithNewID(t.ctx)
  363. source := M.SocksaddrFrom(src.Addr(), src.Port())
  364. destination := M.SocksaddrFrom(dst.Addr(), dst.Port())
  365. t.NewConnectionEx(ctx, conn, source, destination, nil)
  366. }, true
  367. })
  368. }
  369. t.server.ExportLocalBackend().ExportEngine().(wgengine.ExportedUserspaceEngine).SetOnReconfigListener(t.onReconfig)
  370. ipStack := t.server.ExportNetstack().ExportIPStack()
  371. gErr := ipStack.SetSpoofing(tun.DefaultNIC, true)
  372. if gErr != nil {
  373. return gonet.TranslateNetstackError(gErr)
  374. }
  375. gErr = ipStack.SetPromiscuousMode(tun.DefaultNIC, true)
  376. if gErr != nil {
  377. return gonet.TranslateNetstackError(gErr)
  378. }
  379. icmpForwarder := tun.NewICMPForwarder(t.ctx, ipStack, t, t.udpTimeout)
  380. ipStack.SetTransportProtocolHandler(icmp.ProtocolNumber4, icmpForwarder.HandlePacket)
  381. ipStack.SetTransportProtocolHandler(icmp.ProtocolNumber6, icmpForwarder.HandlePacket)
  382. t.stack = ipStack
  383. t.icmpForwarder = icmpForwarder
  384. t.registerNetstackHandlers()
  385. localBackend := t.server.ExportLocalBackend()
  386. perfs := &ipn.MaskedPrefs{
  387. Prefs: ipn.Prefs{
  388. RouteAll: t.acceptRoutes,
  389. AdvertiseRoutes: t.advertiseRoutes,
  390. },
  391. RouteAllSet: true,
  392. ExitNodeIPSet: true,
  393. AdvertiseRoutesSet: true,
  394. RelayServerPortSet: true,
  395. RelayServerStaticEndpointsSet: true,
  396. }
  397. if t.advertiseExitNode {
  398. perfs.AdvertiseRoutes = append(perfs.AdvertiseRoutes, tsaddr.ExitRoutes()...)
  399. }
  400. if t.relayServerPort != nil {
  401. perfs.RelayServerPort = t.relayServerPort
  402. }
  403. if len(t.relayServerStaticEndpoints) > 0 {
  404. perfs.RelayServerStaticEndpoints = t.relayServerStaticEndpoints
  405. }
  406. _, err = localBackend.EditPrefs(perfs)
  407. if err != nil {
  408. return E.Cause(err, "update prefs")
  409. }
  410. t.filter = localBackend.ExportFilter()
  411. go t.watchState()
  412. return nil
  413. }
  414. func (t *Endpoint) watchState() {
  415. localBackend := t.server.ExportLocalBackend()
  416. localBackend.WatchNotifications(t.ctx, ipn.NotifyInitialState, nil, func(roNotify *ipn.Notify) (keepGoing bool) {
  417. if roNotify.State != nil && *roNotify.State != ipn.NeedsLogin && *roNotify.State != ipn.NoState {
  418. return false
  419. }
  420. authURL := localBackend.StatusWithoutPeers().AuthURL
  421. if authURL != "" {
  422. t.logger.Info("Waiting for authentication: ", authURL)
  423. if t.platformInterface != nil {
  424. err := t.platformInterface.SendNotification(&adapter.Notification{
  425. Identifier: "tailscale-authentication",
  426. TypeName: "Tailscale Authentication Notifications",
  427. TypeID: 10,
  428. Title: "Tailscale Authentication",
  429. Body: F.ToString("Tailscale outbound[", t.Tag(), "] is waiting for authentication."),
  430. OpenURL: authURL,
  431. })
  432. if err != nil {
  433. t.logger.Error("send authentication notification: ", err)
  434. }
  435. }
  436. return false
  437. }
  438. return true
  439. })
  440. if t.exitNode != "" {
  441. localBackend.WatchNotifications(t.ctx, ipn.NotifyInitialState, nil, func(roNotify *ipn.Notify) (keepGoing bool) {
  442. if roNotify.State == nil || *roNotify.State != ipn.Running {
  443. return true
  444. }
  445. status, err := common.Must1(t.server.LocalClient()).Status(t.ctx)
  446. if err != nil {
  447. t.logger.Error("set exit node: ", err)
  448. return
  449. }
  450. perfs := &ipn.MaskedPrefs{
  451. Prefs: ipn.Prefs{
  452. ExitNodeAllowLANAccess: t.exitNodeAllowLANAccess,
  453. },
  454. ExitNodeIPSet: true,
  455. ExitNodeAllowLANAccessSet: true,
  456. }
  457. err = perfs.SetExitNodeIP(t.exitNode, status)
  458. if err != nil {
  459. t.logger.Error("set exit node: ", err)
  460. return true
  461. }
  462. _, err = localBackend.EditPrefs(perfs)
  463. if err != nil {
  464. t.logger.Error("set exit node: ", err)
  465. return true
  466. }
  467. return false
  468. })
  469. }
  470. }
  471. func (t *Endpoint) Close() error {
  472. var err error
  473. if t.serverStarted {
  474. err = common.Close(common.PtrOrNil(t.server))
  475. t.serverStarted = false
  476. }
  477. netmon.RegisterInterfaceGetter(nil)
  478. netns.SetControlFunc(nil)
  479. if t.fallbackTCPCloser != nil {
  480. t.fallbackTCPCloser()
  481. t.fallbackTCPCloser = nil
  482. }
  483. if t.systemTun != nil {
  484. t.systemTun.Close()
  485. t.systemTun = nil
  486. }
  487. return err
  488. }
  489. func (t *Endpoint) DialContext(ctx context.Context, network string, destination M.Socksaddr) (net.Conn, error) {
  490. switch network {
  491. case N.NetworkTCP:
  492. t.logger.InfoContext(ctx, "outbound connection to ", destination)
  493. case N.NetworkUDP:
  494. t.logger.InfoContext(ctx, "outbound packet connection to ", destination)
  495. }
  496. if destination.IsDomain() {
  497. destinationAddresses, err := t.dnsRouter.Lookup(ctx, destination.Fqdn, adapter.DNSQueryOptions{})
  498. if err != nil {
  499. return nil, err
  500. }
  501. return N.DialSerial(ctx, t, network, destination, destinationAddresses)
  502. }
  503. if t.systemDialer != nil {
  504. return t.systemDialer.DialContext(ctx, network, destination)
  505. }
  506. addr4, addr6 := t.server.TailscaleIPs()
  507. remoteAddr := tcpip.FullAddress{
  508. NIC: 1,
  509. Port: destination.Port,
  510. Addr: addressFromAddr(destination.Addr),
  511. }
  512. var localAddr tcpip.FullAddress
  513. var networkProtocol tcpip.NetworkProtocolNumber
  514. if destination.IsIPv4() {
  515. if !addr4.IsValid() {
  516. return nil, E.New("missing Tailscale IPv4 address")
  517. }
  518. networkProtocol = header.IPv4ProtocolNumber
  519. localAddr = tcpip.FullAddress{
  520. NIC: 1,
  521. Addr: addressFromAddr(addr4),
  522. }
  523. } else {
  524. if !addr6.IsValid() {
  525. return nil, E.New("missing Tailscale IPv6 address")
  526. }
  527. networkProtocol = header.IPv6ProtocolNumber
  528. localAddr = tcpip.FullAddress{
  529. NIC: 1,
  530. Addr: addressFromAddr(addr6),
  531. }
  532. }
  533. switch N.NetworkName(network) {
  534. case N.NetworkTCP:
  535. tcpConn, err := gonet.DialTCPWithBind(ctx, t.stack, localAddr, remoteAddr, networkProtocol)
  536. if err != nil {
  537. return nil, err
  538. }
  539. return tcpConn, nil
  540. case N.NetworkUDP:
  541. udpConn, err := gonet.DialUDP(t.stack, &localAddr, &remoteAddr, networkProtocol)
  542. if err != nil {
  543. return nil, err
  544. }
  545. return udpConn, nil
  546. default:
  547. return nil, E.Extend(N.ErrUnknownNetwork, network)
  548. }
  549. }
  550. func (t *Endpoint) listenPacketWithAddress(ctx context.Context, destination M.Socksaddr) (net.PacketConn, error) {
  551. if t.systemDialer != nil {
  552. return t.systemDialer.ListenPacket(ctx, destination)
  553. }
  554. addr4, addr6 := t.server.TailscaleIPs()
  555. bind := tcpip.FullAddress{
  556. NIC: 1,
  557. }
  558. var networkProtocol tcpip.NetworkProtocolNumber
  559. if destination.IsIPv4() {
  560. if !addr4.IsValid() {
  561. return nil, E.New("missing Tailscale IPv4 address")
  562. }
  563. networkProtocol = header.IPv4ProtocolNumber
  564. bind.Addr = addressFromAddr(addr4)
  565. } else {
  566. if !addr6.IsValid() {
  567. return nil, E.New("missing Tailscale IPv6 address")
  568. }
  569. networkProtocol = header.IPv6ProtocolNumber
  570. bind.Addr = addressFromAddr(addr6)
  571. }
  572. udpConn, err := gonet.DialUDP(t.stack, &bind, nil, networkProtocol)
  573. if err != nil {
  574. return nil, err
  575. }
  576. return udpConn, nil
  577. }
  578. func (t *Endpoint) ListenPacketWithDestination(ctx context.Context, destination M.Socksaddr) (net.PacketConn, netip.Addr, error) {
  579. t.logger.InfoContext(ctx, "outbound packet connection to ", destination)
  580. if destination.IsDomain() {
  581. destinationAddresses, err := t.dnsRouter.Lookup(ctx, destination.Fqdn, adapter.DNSQueryOptions{})
  582. if err != nil {
  583. return nil, netip.Addr{}, err
  584. }
  585. var errors []error
  586. for _, address := range destinationAddresses {
  587. packetConn, packetErr := t.listenPacketWithAddress(ctx, M.SocksaddrFrom(address, destination.Port))
  588. if packetErr == nil {
  589. return packetConn, address, nil
  590. }
  591. errors = append(errors, packetErr)
  592. }
  593. return nil, netip.Addr{}, E.Errors(errors...)
  594. }
  595. packetConn, err := t.listenPacketWithAddress(ctx, destination)
  596. if err != nil {
  597. return nil, netip.Addr{}, err
  598. }
  599. if destination.IsIP() {
  600. return packetConn, destination.Addr, nil
  601. }
  602. return packetConn, netip.Addr{}, nil
  603. }
  604. func (t *Endpoint) ListenPacket(ctx context.Context, destination M.Socksaddr) (net.PacketConn, error) {
  605. packetConn, destinationAddress, err := t.ListenPacketWithDestination(ctx, destination)
  606. if err != nil {
  607. return nil, err
  608. }
  609. if destinationAddress.IsValid() && destination != M.SocksaddrFrom(destinationAddress, destination.Port) {
  610. return bufio.NewNATPacketConn(bufio.NewPacketConn(packetConn), M.SocksaddrFrom(destinationAddress, destination.Port), destination), nil
  611. }
  612. return packetConn, nil
  613. }
  614. func (t *Endpoint) PrepareConnection(network string, source M.Socksaddr, destination M.Socksaddr, routeContext tun.DirectRouteContext, timeout time.Duration) (tun.DirectRouteDestination, error) {
  615. tsFilter := t.filter.Load()
  616. if tsFilter != nil {
  617. var ipProto ipproto.Proto
  618. switch N.NetworkName(network) {
  619. case N.NetworkTCP:
  620. ipProto = ipproto.TCP
  621. case N.NetworkUDP:
  622. ipProto = ipproto.UDP
  623. case N.NetworkICMP:
  624. if !destination.IsIPv6() {
  625. ipProto = ipproto.ICMPv4
  626. } else {
  627. ipProto = ipproto.ICMPv6
  628. }
  629. }
  630. response := tsFilter.Check(source.Addr, destination.Addr, destination.Port, ipProto)
  631. switch response {
  632. case filter.Drop:
  633. return nil, syscall.ECONNREFUSED
  634. case filter.DropSilently:
  635. return nil, tun.ErrDrop
  636. }
  637. }
  638. var ipVersion uint8
  639. if !destination.IsIPv6() {
  640. ipVersion = 4
  641. } else {
  642. ipVersion = 6
  643. }
  644. routeDestination, err := t.router.PreMatch(adapter.InboundContext{
  645. Inbound: t.Tag(),
  646. InboundType: t.Type(),
  647. IPVersion: ipVersion,
  648. Network: network,
  649. Source: source,
  650. Destination: destination,
  651. }, routeContext, timeout, false)
  652. if err != nil {
  653. switch {
  654. case rule.IsBypassed(err):
  655. err = nil
  656. case rule.IsRejected(err):
  657. t.logger.Trace("reject ", network, " connection from ", source.AddrString(), " to ", destination.AddrString())
  658. default:
  659. if network == N.NetworkICMP {
  660. t.logger.Warn(E.Cause(err, "link ", network, " connection from ", source.AddrString(), " to ", destination.AddrString()))
  661. }
  662. }
  663. }
  664. return routeDestination, err
  665. }
  666. func (t *Endpoint) NewConnectionEx(ctx context.Context, conn net.Conn, source M.Socksaddr, destination M.Socksaddr, onClose N.CloseHandlerFunc) {
  667. var metadata adapter.InboundContext
  668. metadata.Inbound = t.Tag()
  669. metadata.InboundType = t.Type()
  670. metadata.Source = source
  671. addr4, addr6 := t.server.TailscaleIPs()
  672. switch destination.Addr {
  673. case addr4:
  674. destination.Addr = netip.AddrFrom4([4]uint8{127, 0, 0, 1})
  675. case addr6:
  676. destination.Addr = netip.IPv6Loopback()
  677. }
  678. metadata.Destination = destination
  679. t.logger.InfoContext(ctx, "inbound connection from ", source)
  680. t.logger.InfoContext(ctx, "inbound connection to ", metadata.Destination)
  681. t.router.RouteConnectionEx(ctx, conn, metadata, onClose)
  682. }
  683. func (t *Endpoint) NewPacketConnectionEx(ctx context.Context, conn N.PacketConn, source M.Socksaddr, destination M.Socksaddr, onClose N.CloseHandlerFunc) {
  684. var metadata adapter.InboundContext
  685. metadata.Inbound = t.Tag()
  686. metadata.InboundType = t.Type()
  687. metadata.Source = source
  688. addr4, addr6 := t.server.TailscaleIPs()
  689. switch destination.Addr {
  690. case addr4:
  691. metadata.OriginDestination = destination
  692. destination.Addr = netip.AddrFrom4([4]uint8{127, 0, 0, 1})
  693. conn = bufio.NewNATPacketConn(bufio.NewNetPacketConn(conn), metadata.OriginDestination, destination)
  694. case addr6:
  695. metadata.OriginDestination = destination
  696. destination.Addr = netip.IPv6Loopback()
  697. conn = bufio.NewNATPacketConn(bufio.NewNetPacketConn(conn), metadata.OriginDestination, destination)
  698. }
  699. metadata.Destination = destination
  700. t.logger.InfoContext(ctx, "inbound packet connection from ", source)
  701. t.logger.InfoContext(ctx, "inbound packet connection to ", metadata.Destination)
  702. t.router.RoutePacketConnectionEx(ctx, conn, metadata, onClose)
  703. }
  704. func (t *Endpoint) NewDirectRouteConnection(metadata adapter.InboundContext, routeContext tun.DirectRouteContext, timeout time.Duration) (tun.DirectRouteDestination, error) {
  705. ctx := log.ContextWithNewID(t.ctx)
  706. var destination tun.DirectRouteDestination
  707. var err error
  708. if t.systemDialer != nil {
  709. destination, err = ping.ConnectDestination(
  710. ctx, t.logger,
  711. t.systemDialer.DialerForICMPDestination(metadata.Destination.Addr).Control,
  712. metadata.Destination.Addr, routeContext, timeout,
  713. )
  714. } else {
  715. inet4Address, inet6Address := t.server.TailscaleIPs()
  716. if metadata.Destination.Addr.Is4() && !inet4Address.IsValid() || metadata.Destination.Addr.Is6() && !inet6Address.IsValid() {
  717. return nil, E.New("Tailscale is not ready yet")
  718. }
  719. destination, err = ping.ConnectGVisor(
  720. ctx, t.logger,
  721. metadata.Source.Addr, metadata.Destination.Addr,
  722. routeContext,
  723. t.stack,
  724. inet4Address, inet6Address,
  725. timeout,
  726. )
  727. }
  728. if err != nil {
  729. return nil, err
  730. }
  731. t.logger.InfoContext(ctx, "linked ", metadata.Network, " connection from ", metadata.Source.AddrString(), " to ", metadata.Destination.AddrString())
  732. return destination, nil
  733. }
  734. func (t *Endpoint) PreferredDomain(domain string) bool {
  735. routeDomains := t.routeDomains.Load()
  736. if routeDomains == nil {
  737. return false
  738. }
  739. return routeDomains[strings.ToLower(domain)]
  740. }
  741. func (t *Endpoint) PreferredAddress(address netip.Addr) bool {
  742. routePrefixes := t.routePrefixes.Load()
  743. if routePrefixes == nil {
  744. return false
  745. }
  746. return routePrefixes.Contains(address)
  747. }
  748. func (t *Endpoint) Server() *tsnet.Server {
  749. return t.server
  750. }
  751. func (t *Endpoint) onReconfig(cfg *wgcfg.Config, routerCfg *router.Config, dnsCfg *tsDNS.Config) {
  752. if cfg == nil || dnsCfg == nil {
  753. return
  754. }
  755. if (t.cfg != nil && reflect.DeepEqual(t.cfg, cfg)) && (t.dnsCfg != nil && reflect.DeepEqual(t.dnsCfg, dnsCfg)) {
  756. return
  757. }
  758. var inet4Address, inet6Address netip.Addr
  759. for _, address := range cfg.Addresses {
  760. if address.Addr().Is4() {
  761. inet4Address = address.Addr()
  762. } else if address.Addr().Is6() {
  763. inet6Address = address.Addr()
  764. }
  765. }
  766. t.icmpForwarder.SetLocalAddresses(inet4Address, inet6Address)
  767. t.cfg = cfg
  768. t.dnsCfg = dnsCfg
  769. routeDomains := make(map[string]bool)
  770. for fqdn := range dnsCfg.Routes {
  771. routeDomains[fqdn.WithoutTrailingDot()] = true
  772. }
  773. for _, fqdn := range dnsCfg.SearchDomains {
  774. routeDomains[fqdn.WithoutTrailingDot()] = true
  775. }
  776. t.routeDomains.Store(routeDomains)
  777. var builder netipx.IPSetBuilder
  778. for _, peer := range cfg.Peers {
  779. for _, allowedIP := range peer.AllowedIPs {
  780. builder.AddPrefix(allowedIP)
  781. }
  782. }
  783. t.routePrefixes.Store(common.Must1(builder.IPSet()))
  784. if t.onReconfigHook != nil {
  785. t.onReconfigHook(cfg, routerCfg, dnsCfg)
  786. }
  787. }
  788. func addressFromAddr(destination netip.Addr) tcpip.Address {
  789. if destination.Is6() {
  790. return tcpip.AddrFrom16(destination.As16())
  791. } else {
  792. return tcpip.AddrFrom4(destination.As4())
  793. }
  794. }
  795. type endpointDialer struct {
  796. N.Dialer
  797. logger logger.ContextLogger
  798. }
  799. func (d *endpointDialer) DialContext(ctx context.Context, network string, destination M.Socksaddr) (net.Conn, error) {
  800. switch N.NetworkName(network) {
  801. case N.NetworkTCP:
  802. d.logger.InfoContext(ctx, "output connection to ", destination)
  803. case N.NetworkUDP:
  804. d.logger.InfoContext(ctx, "output packet connection to ", destination)
  805. }
  806. return d.Dialer.DialContext(ctx, network, destination)
  807. }
  808. func (d *endpointDialer) ListenPacket(ctx context.Context, destination M.Socksaddr) (net.PacketConn, error) {
  809. d.logger.InfoContext(ctx, "output packet connection")
  810. return d.Dialer.ListenPacket(ctx, destination)
  811. }
  812. type dnsConfigurtor struct {
  813. baseConfig tsDNS.OSConfig
  814. }
  815. func (c *dnsConfigurtor) SetDNS(cfg tsDNS.OSConfig) error {
  816. c.baseConfig = cfg
  817. return nil
  818. }
  819. func (c *dnsConfigurtor) SupportsSplitDNS() bool {
  820. return true
  821. }
  822. func (c *dnsConfigurtor) GetBaseConfig() (tsDNS.OSConfig, error) {
  823. return c.baseConfig, nil
  824. }
  825. func (c *dnsConfigurtor) Close() error {
  826. return nil
  827. }