Highly-opinionated (ex-bullshit-free) MTPROTO proxy for Telegram. If you use v1.0 or upgrade broke you proxy, please read the chapter Version 2
選択できるのは25トピックまでです。 トピックは、先頭が英数字で、英数字とダッシュ('-')を使用した35文字以内のものにしてください。

run_proxy.go 11KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422
  1. package cli
  2. import (
  3. "context"
  4. "fmt"
  5. "net"
  6. "os"
  7. "strings"
  8. "time"
  9. "github.com/9seconds/mtg/v2/antireplay"
  10. "github.com/9seconds/mtg/v2/events"
  11. "github.com/9seconds/mtg/v2/internal/config"
  12. "github.com/9seconds/mtg/v2/internal/proxyprotocol"
  13. "github.com/9seconds/mtg/v2/internal/utils"
  14. "github.com/9seconds/mtg/v2/ipblocklist"
  15. "github.com/9seconds/mtg/v2/ipblocklist/files"
  16. "github.com/9seconds/mtg/v2/logger"
  17. "github.com/9seconds/mtg/v2/mtglib"
  18. "github.com/9seconds/mtg/v2/network/v2"
  19. "github.com/9seconds/mtg/v2/stats"
  20. "github.com/pires/go-proxyproto"
  21. "github.com/rs/zerolog"
  22. "github.com/yl2chen/cidranger"
  23. )
  24. func makeLogger(conf *config.Config) mtglib.Logger {
  25. zerolog.TimeFieldFormat = logTimeFormat(conf.LogTimeFormat)
  26. zerolog.TimestampFieldName = "timestamp"
  27. zerolog.LevelFieldName = "level"
  28. if conf.Debug.Get(false) {
  29. zerolog.SetGlobalLevel(zerolog.DebugLevel)
  30. } else {
  31. zerolog.SetGlobalLevel(zerolog.WarnLevel)
  32. }
  33. baseLogger := zerolog.New(os.Stdout).With().Timestamp().Logger()
  34. return logger.NewZeroLogger(baseLogger)
  35. }
  36. func logTimeFormat(value string) string {
  37. switch strings.ToLower(strings.TrimSpace(value)) {
  38. case "", "unix-ms":
  39. return zerolog.TimeFormatUnixMs
  40. case "unix":
  41. return zerolog.TimeFormatUnix
  42. case "unix-micro":
  43. return zerolog.TimeFormatUnixMicro
  44. case "unix-nano":
  45. return zerolog.TimeFormatUnixNano
  46. case "rfc3339":
  47. return time.RFC3339
  48. case "rfc3339-nano":
  49. return time.RFC3339Nano
  50. default:
  51. return value
  52. }
  53. }
  54. func makeNetwork(conf *config.Config, version string) (mtglib.Network, error) {
  55. resolver, err := network.GetDNS(conf.GetDNS())
  56. if err != nil {
  57. return nil, fmt.Errorf("cannot create DNS resolver: %w", err)
  58. }
  59. base := network.New(
  60. resolver,
  61. "",
  62. conf.Network.Timeout.TCP.Get(0),
  63. conf.Network.Timeout.HTTP.Get(0),
  64. conf.Network.Timeout.Idle.Get(0),
  65. net.KeepAliveConfig{
  66. Enable: !conf.Network.KeepAlive.Disabled.Get(false),
  67. Idle: conf.Network.KeepAlive.Idle.Get(0),
  68. Interval: conf.Network.KeepAlive.Interval.Get(0),
  69. Count: int(conf.Network.KeepAlive.Count.Get(0)),
  70. },
  71. int(conf.Network.TCPNotSentLowat.Get(network.DefaultTCPNotSentLowat)),
  72. )
  73. proxyDialers := make([]mtglib.Network, len(conf.Network.Proxies))
  74. for idx, v := range conf.Network.Proxies {
  75. value, err := network.NewProxyNetwork(base, v.Get(nil))
  76. if err != nil {
  77. return nil, fmt.Errorf("cannot use %v for proxy url: %w", v.Get(nil), err)
  78. }
  79. proxyDialers[idx] = value
  80. }
  81. switch len(proxyDialers) {
  82. case 0:
  83. return base, nil
  84. case 1:
  85. return proxyDialers[0], nil
  86. }
  87. value, err := network.Join(proxyDialers...)
  88. if err != nil {
  89. panic(err)
  90. }
  91. return value, nil
  92. }
  93. func makeAntiReplayCache(conf *config.Config) mtglib.AntiReplayCache {
  94. if !conf.Defense.AntiReplay.Enabled.Get(false) {
  95. return antireplay.NewNoop()
  96. }
  97. return antireplay.NewStableBloomFilter(
  98. conf.Defense.AntiReplay.MaxSize.Get(antireplay.DefaultStableBloomFilterMaxSize),
  99. conf.Defense.AntiReplay.ErrorRate.Get(antireplay.DefaultStableBloomFilterErrorRate),
  100. )
  101. }
  102. func makeIPBlocklist(conf config.ListConfig,
  103. logger mtglib.Logger,
  104. ntw mtglib.Network,
  105. updateCallback ipblocklist.FireholUpdateCallback,
  106. ) (mtglib.IPBlocklist, error) {
  107. if !conf.Enabled.Get(false) {
  108. return ipblocklist.NewNoop(), nil
  109. }
  110. remoteURLs := []string{}
  111. localFiles := []string{}
  112. for _, v := range conf.URLs {
  113. if v.IsRemote() {
  114. remoteURLs = append(remoteURLs, v.String())
  115. } else {
  116. localFiles = append(localFiles, v.String())
  117. }
  118. }
  119. blocklist, err := ipblocklist.NewFirehol(logger.Named("ipblockist"),
  120. ntw,
  121. conf.DownloadConcurrency.Get(1),
  122. remoteURLs,
  123. localFiles,
  124. updateCallback)
  125. if err != nil {
  126. return nil, fmt.Errorf("incorrect parameters for firehol: %w", err)
  127. }
  128. go blocklist.Run(conf.UpdateEach.Get(ipblocklist.DefaultFireholUpdateEach))
  129. return blocklist, nil
  130. }
  131. func makeIPAllowlist(conf config.ListConfig,
  132. logger mtglib.Logger,
  133. ntw mtglib.Network,
  134. updateCallback ipblocklist.FireholUpdateCallback,
  135. ) (mtglib.IPBlocklist, error) {
  136. var (
  137. allowlist mtglib.IPBlocklist
  138. err error
  139. )
  140. if !conf.Enabled.Get(false) {
  141. allowlist, err = ipblocklist.NewFireholFromFiles(
  142. logger.Named("ipblocklist"),
  143. 1,
  144. []files.File{
  145. files.NewMem([]*net.IPNet{
  146. cidranger.AllIPv4,
  147. cidranger.AllIPv6,
  148. }),
  149. },
  150. updateCallback,
  151. )
  152. go allowlist.Run(conf.UpdateEach.Get(ipblocklist.DefaultFireholUpdateEach))
  153. } else {
  154. allowlist, err = makeIPBlocklist(
  155. conf,
  156. logger,
  157. ntw,
  158. updateCallback,
  159. )
  160. }
  161. if err != nil {
  162. return nil, fmt.Errorf("cannot build allowlist: %w", err)
  163. }
  164. return allowlist, nil
  165. }
  166. func makeEventStream(conf *config.Config, logger mtglib.Logger) (mtglib.EventStream, error) {
  167. factories := make([]events.ObserverFactory, 0, 2)
  168. if conf.Stats.StatsD.Enabled.Get(false) {
  169. statsdFactory, err := stats.NewStatsd(
  170. conf.Stats.StatsD.Address.Get(""),
  171. logger.Named("statsd"),
  172. conf.Stats.StatsD.MetricPrefix.Get(stats.DefaultStatsdMetricPrefix),
  173. conf.Stats.StatsD.TagFormat.Get(stats.DefaultStatsdTagFormat))
  174. if err != nil {
  175. return nil, fmt.Errorf("cannot build statsd observer: %w", err)
  176. }
  177. factories = append(factories, statsdFactory.Make)
  178. }
  179. if conf.Stats.Prometheus.Enabled.Get(false) {
  180. prometheus := stats.NewPrometheus(
  181. conf.Stats.Prometheus.MetricPrefix.Get(stats.DefaultMetricPrefix),
  182. conf.Stats.Prometheus.HTTPPath.Get("/"),
  183. )
  184. listener, err := net.Listen("tcp", conf.Stats.Prometheus.BindTo.Get(""))
  185. if err != nil {
  186. return nil, fmt.Errorf("cannot start a listener for prometheus: %w", err)
  187. }
  188. go prometheus.Serve(listener) //nolint: errcheck
  189. factories = append(factories, prometheus.Make)
  190. }
  191. if len(factories) > 0 {
  192. return events.NewEventStream(factories), nil
  193. }
  194. return events.NewNoopStream(), nil
  195. }
  196. func warnSNIMismatch(conf *config.Config, ntw mtglib.Network, log mtglib.Logger) {
  197. host := conf.Secret.Host
  198. if host == "" {
  199. return
  200. }
  201. addresses, err := net.DefaultResolver.LookupIPAddr(context.Background(), host)
  202. if err != nil {
  203. log.BindStr("hostname", host).
  204. WarningError("SNI-DNS check: cannot resolve secret hostname", err)
  205. return
  206. }
  207. ourIP4 := conf.PublicIPv4.Get(nil)
  208. if ourIP4 == nil {
  209. ourIP4 = getIP(ntw, "tcp4")
  210. }
  211. ourIP6 := conf.PublicIPv6.Get(nil)
  212. if ourIP6 == nil {
  213. ourIP6 = getIP(ntw, "tcp6")
  214. }
  215. if ourIP4 == nil && ourIP6 == nil {
  216. log.Warning("SNI-DNS check: cannot detect public IP address; set public-ipv4/public-ipv6 in config or run 'mtg doctor'")
  217. return
  218. }
  219. v4Match := ourIP4 == nil
  220. v6Match := ourIP6 == nil
  221. for _, addr := range addresses {
  222. if ourIP4 != nil && addr.IP.String() == ourIP4.String() {
  223. v4Match = true
  224. }
  225. if ourIP6 != nil && addr.IP.String() == ourIP6.String() {
  226. v6Match = true
  227. }
  228. }
  229. if v4Match && v6Match {
  230. return
  231. }
  232. resolved := make([]string, 0, len(addresses))
  233. for _, addr := range addresses {
  234. resolved = append(resolved, addr.IP.String())
  235. }
  236. our := ""
  237. if ourIP4 != nil {
  238. our = ourIP4.String()
  239. }
  240. if ourIP6 != nil {
  241. if our != "" {
  242. our += "/"
  243. }
  244. our += ourIP6.String()
  245. }
  246. entry := log.BindStr("hostname", host).
  247. BindStr("resolved", strings.Join(resolved, ", ")).
  248. BindStr("public_ip", our)
  249. if ourIP4 != nil {
  250. entry = entry.BindStr("ipv4_match", fmt.Sprintf("%t", v4Match))
  251. }
  252. if ourIP6 != nil {
  253. entry = entry.BindStr("ipv6_match", fmt.Sprintf("%t", v6Match))
  254. }
  255. entry.Warning("SNI-DNS mismatch: secret hostname does not resolve to this server's public IP. " +
  256. "DPI may detect and block the proxy. See 'mtg doctor' for details")
  257. }
  258. func warnDeprecatedDomainFronting(conf *config.Config, log mtglib.Logger) {
  259. if conf.DomainFrontingIP.Value != nil {
  260. log.Warning(`config option "domain-fronting-ip" is deprecated and ignored; use "host" in [domain-fronting] instead`)
  261. }
  262. if conf.DomainFronting.IP.Value != nil {
  263. log.Warning(`config option "ip" in [domain-fronting] is deprecated and ignored; use "host" instead`)
  264. }
  265. }
  266. func runProxy(conf *config.Config, version string) error { //nolint: funlen, cyclop
  267. logger := makeLogger(conf)
  268. logger.BindJSON("configuration", conf.String()).Debug("configuration")
  269. warnDeprecatedDomainFronting(conf, logger)
  270. eventStream, err := makeEventStream(conf, logger)
  271. if err != nil {
  272. return fmt.Errorf("cannot build event stream: %w", err)
  273. }
  274. ntw, err := makeNetwork(conf, version)
  275. if err != nil {
  276. return fmt.Errorf("cannot build network: %w", err)
  277. }
  278. warnSNIMismatch(conf, ntw, logger)
  279. blocklist, err := makeIPBlocklist(
  280. conf.Defense.Blocklist,
  281. logger.Named("blocklist"),
  282. ntw,
  283. func(ctx context.Context, size int) {
  284. eventStream.Send(ctx, mtglib.NewEventIPListSize(size, true))
  285. })
  286. if err != nil {
  287. return fmt.Errorf("cannot build ip blocklist: %w", err)
  288. }
  289. allowlist, err := makeIPAllowlist(
  290. conf.Defense.Allowlist,
  291. logger.Named("allowlist"),
  292. ntw,
  293. func(ctx context.Context, size int) {
  294. eventStream.Send(ctx, mtglib.NewEventIPListSize(size, false))
  295. },
  296. )
  297. if err != nil {
  298. return fmt.Errorf("cannot build ip allowlist: %w", err)
  299. }
  300. doppelGangerURLs := make([]string, len(conf.Defense.Doppelganger.URLs))
  301. for i, v := range conf.Defense.Doppelganger.URLs {
  302. doppelGangerURLs[i] = v.String()
  303. }
  304. opts := mtglib.ProxyOpts{
  305. Logger: logger,
  306. Network: ntw,
  307. AntiReplayCache: makeAntiReplayCache(conf),
  308. IPBlocklist: blocklist,
  309. IPAllowlist: allowlist,
  310. EventStream: eventStream,
  311. Secret: conf.Secret,
  312. Concurrency: conf.GetConcurrency(mtglib.DefaultConcurrency),
  313. DomainFrontingPort: conf.GetDomainFrontingPort(mtglib.DefaultDomainFrontingPort),
  314. DomainFrontingHost: conf.GetDomainFrontingHost(),
  315. DomainFrontingProxyProtocol: conf.GetDomainFrontingProxyProtocol(false),
  316. PreferIP: conf.PreferIP.Get(mtglib.DefaultPreferIP),
  317. AutoUpdate: conf.AutoUpdate.Get(false),
  318. AllowFallbackOnUnknownDC: conf.AllowFallbackOnUnknownDC.Get(false),
  319. TolerateTimeSkewness: conf.TolerateTimeSkewness.Value,
  320. IdleTimeout: conf.Network.Timeout.Idle.Get(mtglib.DefaultIdleTimeout),
  321. HandshakeTimeout: conf.Network.Timeout.Handshake.Get(mtglib.DefaultHandshakeTimeout),
  322. DoppelGangerURLs: doppelGangerURLs,
  323. DoppelGangerPerRaid: conf.Defense.Doppelganger.Repeats.Get(mtglib.DoppelGangerPerRaid),
  324. DoppelGangerEach: conf.Defense.Doppelganger.UpdateEach.Get(mtglib.DoppelGangerEach),
  325. DoppelGangerDRS: conf.Defense.Doppelganger.DRS.Get(false),
  326. }
  327. proxy, err := mtglib.NewProxy(opts)
  328. if err != nil {
  329. return fmt.Errorf("cannot create a proxy: %w", err)
  330. }
  331. listener, err := utils.NewListener(conf.BindTo.Get(""), 0)
  332. if err != nil {
  333. return fmt.Errorf("cannot start proxy: %w", err)
  334. }
  335. if conf.ProxyProtocolListener.Get(false) {
  336. listener = &proxyprotocol.ListenerAdapter{
  337. Listener: proxyproto.Listener{
  338. Listener: listener,
  339. },
  340. }
  341. }
  342. ctx := utils.RootContext()
  343. go proxy.Serve(listener) //nolint: errcheck
  344. <-ctx.Done()
  345. listener.Close() //nolint: errcheck
  346. proxy.Shutdown()
  347. return nil
  348. }