Highly-opinionated (ex-bullshit-free) MTPROTO proxy for Telegram. If you use v1.0 or upgrade broke you proxy, please read the chapter Version 2
Вы не можете выбрать более 25 тем Темы должны начинаться с буквы или цифры, могут содержать дефисы(-) и должны содержать не более 35 символов.

run_proxy.go 7.1KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283
  1. package cli
  2. import (
  3. "context"
  4. "fmt"
  5. "net"
  6. "os"
  7. "github.com/9seconds/mtg/v2/antireplay"
  8. "github.com/9seconds/mtg/v2/events"
  9. "github.com/9seconds/mtg/v2/internal/config"
  10. "github.com/9seconds/mtg/v2/internal/proxyprotocol"
  11. "github.com/9seconds/mtg/v2/internal/utils"
  12. "github.com/9seconds/mtg/v2/ipblocklist"
  13. "github.com/9seconds/mtg/v2/ipblocklist/files"
  14. "github.com/9seconds/mtg/v2/logger"
  15. "github.com/9seconds/mtg/v2/mtglib"
  16. "github.com/9seconds/mtg/v2/network/v2"
  17. "github.com/9seconds/mtg/v2/stats"
  18. "github.com/pires/go-proxyproto"
  19. "github.com/rs/zerolog"
  20. "github.com/yl2chen/cidranger"
  21. )
  22. func makeLogger(conf *config.Config) mtglib.Logger {
  23. zerolog.TimeFieldFormat = zerolog.TimeFormatUnixMs
  24. zerolog.TimestampFieldName = "timestamp"
  25. zerolog.LevelFieldName = "level"
  26. if conf.Debug.Get(false) {
  27. zerolog.SetGlobalLevel(zerolog.DebugLevel)
  28. } else {
  29. zerolog.SetGlobalLevel(zerolog.WarnLevel)
  30. }
  31. baseLogger := zerolog.New(os.Stdout).With().Timestamp().Logger()
  32. return logger.NewZeroLogger(baseLogger)
  33. }
  34. func makeNetwork(conf *config.Config, version string) (mtglib.Network, error) {
  35. base := network.New(
  36. nil,
  37. "mtg/"+version,
  38. conf.Network.Timeout.TCP.Get(0),
  39. conf.Network.Timeout.HTTP.Get(0),
  40. conf.Network.Timeout.Idle.Get(0),
  41. )
  42. proxyDialers := make([]network.Network, len(conf.Network.Proxies))
  43. for idx, v := range conf.Network.Proxies {
  44. value, err := network.NewProxyNetwork(base, v.Get(nil))
  45. if err != nil {
  46. return nil, fmt.Errorf("cannot use %v for proxy url: %w", v.Get(nil), err)
  47. }
  48. proxyDialers[idx] = value
  49. }
  50. switch len(proxyDialers) {
  51. case 0:
  52. return base, nil
  53. case 1:
  54. return proxyDialers[0], nil
  55. }
  56. value, err := network.Join(proxyDialers...)
  57. if err != nil {
  58. panic(err)
  59. }
  60. return value, nil
  61. }
  62. func makeAntiReplayCache(conf *config.Config) mtglib.AntiReplayCache {
  63. if !conf.Defense.AntiReplay.Enabled.Get(false) {
  64. return antireplay.NewNoop()
  65. }
  66. return antireplay.NewStableBloomFilter(
  67. conf.Defense.AntiReplay.MaxSize.Get(antireplay.DefaultStableBloomFilterMaxSize),
  68. conf.Defense.AntiReplay.ErrorRate.Get(antireplay.DefaultStableBloomFilterErrorRate),
  69. )
  70. }
  71. func makeIPBlocklist(conf config.ListConfig,
  72. logger mtglib.Logger,
  73. ntw mtglib.Network,
  74. updateCallback ipblocklist.FireholUpdateCallback,
  75. ) (mtglib.IPBlocklist, error) {
  76. if !conf.Enabled.Get(false) {
  77. return ipblocklist.NewNoop(), nil
  78. }
  79. remoteURLs := []string{}
  80. localFiles := []string{}
  81. for _, v := range conf.URLs {
  82. if v.IsRemote() {
  83. remoteURLs = append(remoteURLs, v.String())
  84. } else {
  85. localFiles = append(localFiles, v.String())
  86. }
  87. }
  88. blocklist, err := ipblocklist.NewFirehol(logger.Named("ipblockist"),
  89. ntw,
  90. conf.DownloadConcurrency.Get(1),
  91. remoteURLs,
  92. localFiles,
  93. updateCallback)
  94. if err != nil {
  95. return nil, fmt.Errorf("incorrect parameters for firehol: %w", err)
  96. }
  97. go blocklist.Run(conf.UpdateEach.Get(ipblocklist.DefaultFireholUpdateEach))
  98. return blocklist, nil
  99. }
  100. func makeIPAllowlist(conf config.ListConfig,
  101. logger mtglib.Logger,
  102. ntw mtglib.Network,
  103. updateCallback ipblocklist.FireholUpdateCallback,
  104. ) (mtglib.IPBlocklist, error) {
  105. var (
  106. allowlist mtglib.IPBlocklist
  107. err error
  108. )
  109. if !conf.Enabled.Get(false) {
  110. allowlist, err = ipblocklist.NewFireholFromFiles(
  111. logger.Named("ipblocklist"),
  112. 1,
  113. []files.File{
  114. files.NewMem([]*net.IPNet{
  115. cidranger.AllIPv4,
  116. cidranger.AllIPv6,
  117. }),
  118. },
  119. updateCallback,
  120. )
  121. go allowlist.Run(conf.UpdateEach.Get(ipblocklist.DefaultFireholUpdateEach))
  122. } else {
  123. allowlist, err = makeIPBlocklist(
  124. conf,
  125. logger,
  126. ntw,
  127. updateCallback,
  128. )
  129. }
  130. if err != nil {
  131. return nil, fmt.Errorf("cannot build allowlist: %w", err)
  132. }
  133. return allowlist, nil
  134. }
  135. func makeEventStream(conf *config.Config, logger mtglib.Logger) (mtglib.EventStream, error) {
  136. factories := make([]events.ObserverFactory, 0, 2)
  137. if conf.Stats.StatsD.Enabled.Get(false) {
  138. statsdFactory, err := stats.NewStatsd(
  139. conf.Stats.StatsD.Address.Get(""),
  140. logger.Named("statsd"),
  141. conf.Stats.StatsD.MetricPrefix.Get(stats.DefaultStatsdMetricPrefix),
  142. conf.Stats.StatsD.TagFormat.Get(stats.DefaultStatsdTagFormat))
  143. if err != nil {
  144. return nil, fmt.Errorf("cannot build statsd observer: %w", err)
  145. }
  146. factories = append(factories, statsdFactory.Make)
  147. }
  148. if conf.Stats.Prometheus.Enabled.Get(false) {
  149. prometheus := stats.NewPrometheus(
  150. conf.Stats.Prometheus.MetricPrefix.Get(stats.DefaultMetricPrefix),
  151. conf.Stats.Prometheus.HTTPPath.Get("/"),
  152. )
  153. listener, err := net.Listen("tcp", conf.Stats.Prometheus.BindTo.Get(""))
  154. if err != nil {
  155. return nil, fmt.Errorf("cannot start a listener for prometheus: %w", err)
  156. }
  157. go prometheus.Serve(listener) //nolint: errcheck
  158. factories = append(factories, prometheus.Make)
  159. }
  160. if len(factories) > 0 {
  161. return events.NewEventStream(factories), nil
  162. }
  163. return events.NewNoopStream(), nil
  164. }
  165. func runProxy(conf *config.Config, version string) error { //nolint: funlen
  166. logger := makeLogger(conf)
  167. logger.BindJSON("configuration", conf.String()).Debug("configuration")
  168. eventStream, err := makeEventStream(conf, logger)
  169. if err != nil {
  170. return fmt.Errorf("cannot build event stream: %w", err)
  171. }
  172. ntw, err := makeNetwork(conf, version)
  173. if err != nil {
  174. return fmt.Errorf("cannot build network: %w", err)
  175. }
  176. blocklist, err := makeIPBlocklist(
  177. conf.Defense.Blocklist,
  178. logger.Named("blocklist"),
  179. ntw,
  180. func(ctx context.Context, size int) {
  181. eventStream.Send(ctx, mtglib.NewEventIPListSize(size, true))
  182. })
  183. if err != nil {
  184. return fmt.Errorf("cannot build ip blocklist: %w", err)
  185. }
  186. allowlist, err := makeIPAllowlist(
  187. conf.Defense.Allowlist,
  188. logger.Named("allowlist"),
  189. ntw,
  190. func(ctx context.Context, size int) {
  191. eventStream.Send(ctx, mtglib.NewEventIPListSize(size, false))
  192. },
  193. )
  194. if err != nil {
  195. return fmt.Errorf("cannot build ip allowlist: %w", err)
  196. }
  197. opts := mtglib.ProxyOpts{
  198. Logger: logger,
  199. Network: ntw,
  200. AntiReplayCache: makeAntiReplayCache(conf),
  201. IPBlocklist: blocklist,
  202. IPAllowlist: allowlist,
  203. EventStream: eventStream,
  204. Secret: conf.Secret,
  205. DomainFrontingPort: conf.GetDomainFrontingPort(mtglib.DefaultDomainFrontingPort),
  206. DomainFrontingIP: conf.GetDomainFrontingIP(nil),
  207. DomainFrontingProxyProtocol: conf.GetDomainFrontingProxyProtocol(false),
  208. PreferIP: conf.PreferIP.Get(mtglib.DefaultPreferIP),
  209. AutoUpdate: conf.AutoUpdate.Get(false),
  210. AllowFallbackOnUnknownDC: conf.AllowFallbackOnUnknownDC.Get(false),
  211. TolerateTimeSkewness: conf.TolerateTimeSkewness.Value,
  212. }
  213. proxy, err := mtglib.NewProxy(opts)
  214. if err != nil {
  215. return fmt.Errorf("cannot create a proxy: %w", err)
  216. }
  217. listener, err := utils.NewListener(conf.BindTo.Get(""), 0)
  218. if err != nil {
  219. return fmt.Errorf("cannot start proxy: %w", err)
  220. }
  221. if conf.ProxyProtocolListener.Get(false) {
  222. listener = &proxyprotocol.ListenerAdapter{
  223. Listener: proxyproto.Listener{
  224. Listener: listener,
  225. },
  226. }
  227. }
  228. ctx := utils.RootContext()
  229. go proxy.Serve(listener) //nolint: errcheck
  230. <-ctx.Done()
  231. listener.Close() //nolint: errcheck
  232. proxy.Shutdown()
  233. return nil
  234. }