Highly-opinionated (ex-bullshit-free) MTPROTO proxy for Telegram. If you use v1.0 or upgrade broke you proxy, please read the chapter Version 2
Du kannst nicht mehr als 25 Themen auswählen Themen müssen mit entweder einem Buchstaben oder einer Ziffer beginnen. Sie können Bindestriche („-“) enthalten und bis zu 35 Zeichen lang sein.

proxy.go 6.4KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269
  1. package mtglib
  2. import (
  3. "context"
  4. "errors"
  5. "fmt"
  6. "io"
  7. "net"
  8. "sync"
  9. "time"
  10. "github.com/9seconds/mtg/v2/mtglib/internal/faketls"
  11. "github.com/9seconds/mtg/v2/mtglib/internal/faketls/record"
  12. "github.com/9seconds/mtg/v2/mtglib/internal/obfuscated2"
  13. "github.com/9seconds/mtg/v2/mtglib/internal/relay"
  14. "github.com/9seconds/mtg/v2/mtglib/internal/telegram"
  15. "github.com/panjf2000/ants/v2"
  16. )
  17. type Proxy struct {
  18. ctx context.Context
  19. ctxCancel context.CancelFunc
  20. streamWaitGroup sync.WaitGroup
  21. idleTimeout time.Duration
  22. bufferSize int
  23. workerPool *ants.PoolWithFunc
  24. telegram *telegram.Telegram
  25. secret Secret
  26. antiReplayCache AntiReplayCache
  27. timeAttackDetector TimeAttackDetector
  28. ipBlocklist IPBlocklist
  29. eventStream EventStream
  30. logger Logger
  31. }
  32. func (p *Proxy) ServeConn(conn net.Conn) {
  33. ctx := newStreamContext(p.ctx, p.logger, conn)
  34. defer ctx.Close()
  35. go func() {
  36. <-ctx.Done()
  37. ctx.Close()
  38. }()
  39. p.eventStream.Send(ctx, EventStart{
  40. CreatedAt: time.Now(),
  41. ConnID: ctx.connID,
  42. RemoteIP: ctx.ClientIP(),
  43. })
  44. ctx.logger.Info("Stream has been started")
  45. defer func() {
  46. p.eventStream.Send(ctx, EventFinish{
  47. CreatedAt: time.Now(),
  48. ConnID: ctx.connID,
  49. })
  50. ctx.logger.Info("Stream has been finished")
  51. }()
  52. if err := p.doFakeTLSHandshake(ctx, ctx.clientConn); err != nil {
  53. p.logger.InfoError("faketls handshake is failed", err)
  54. return
  55. }
  56. if err := p.doObfuscated2Handshake(ctx); err != nil {
  57. p.logger.InfoError("obfuscated2 handshake is failed", err)
  58. return
  59. }
  60. if err := p.doTelegramCall(ctx); err != nil {
  61. p.logger.WarningError("cannot dial to telegram", err)
  62. return
  63. }
  64. rel := relay.AcquireRelay(ctx, p.logger.Named("relay"), p.bufferSize, p.idleTimeout)
  65. defer relay.ReleaseRelay(rel)
  66. if err := rel.Process(ctx.clientConn, ctx.telegramConn); err != nil {
  67. p.logger.DebugError("relay has been finished", err)
  68. }
  69. }
  70. func (p *Proxy) Serve(listener net.Listener) error {
  71. for {
  72. conn, err := listener.Accept()
  73. if err != nil {
  74. return fmt.Errorf("cannot accept a new connection: %w", err)
  75. }
  76. if addr := conn.RemoteAddr().(*net.TCPAddr).IP; p.ipBlocklist.Contains(addr) {
  77. conn.Close()
  78. p.eventStream.Send(p.ctx, EventIPBlocklisted{
  79. CreatedAt: time.Now(),
  80. RemoteIP: addr,
  81. })
  82. continue
  83. }
  84. err = p.workerPool.Invoke(conn)
  85. switch {
  86. case err == nil:
  87. case errors.Is(err, ants.ErrPoolClosed):
  88. return nil
  89. case errors.Is(err, ants.ErrPoolOverload):
  90. p.eventStream.Send(p.ctx, EventConcurrencyLimited{
  91. CreatedAt: time.Now(),
  92. })
  93. }
  94. }
  95. }
  96. func (p *Proxy) Shutdown() {
  97. p.ctxCancel()
  98. p.streamWaitGroup.Wait()
  99. p.workerPool.Release()
  100. }
  101. func (p *Proxy) doFakeTLSHandshake(ctx *streamContext, conn io.ReadWriter) error {
  102. rec := record.AcquireRecord()
  103. defer record.ReleaseRecord(rec)
  104. if err := rec.Read(conn); err != nil {
  105. return fmt.Errorf("cannot read client hello: %w", err)
  106. }
  107. hello, err := faketls.ParseClientHello(p.secret.Key[:], rec.Payload.Bytes())
  108. if err != nil {
  109. return fmt.Errorf("cannot parse client hello: %w", err)
  110. }
  111. if err := p.timeAttackDetector.Valid(hello.Time); err != nil {
  112. return fmt.Errorf("invalid time: %w", err)
  113. }
  114. if p.antiReplayCache.SeenBefore(hello.SessionID) {
  115. p.logger.Warning("anti replay attack was detected")
  116. return fmt.Errorf("anti replay attack from %s", ctx.ClientIP().String())
  117. }
  118. if err := faketls.SendWelcomePacket(conn, p.secret.Key[:], hello); err != nil {
  119. return fmt.Errorf("cannot send a welcome packet: %w", err)
  120. }
  121. return nil
  122. }
  123. func (p *Proxy) doObfuscated2Handshake(ctx *streamContext) error {
  124. dc, encryptor, decryptor, err := obfuscated2.ClientHandshake(p.secret.Key[:], ctx.clientConn)
  125. if err != nil {
  126. return fmt.Errorf("cannot process client handshake: %w", err)
  127. }
  128. ctx.dc = dc
  129. ctx.logger = ctx.logger.BindInt("dc", dc)
  130. ctx.clientConn = &obfuscated2.Conn{
  131. Conn: ctx.clientConn,
  132. Encryptor: encryptor,
  133. Decryptor: decryptor,
  134. }
  135. return nil
  136. }
  137. func (p *Proxy) doTelegramCall(ctx *streamContext) error {
  138. conn, err := p.telegram.Dial(ctx, ctx.dc)
  139. if err != nil {
  140. return fmt.Errorf("cannot dial to Telegram: %w", err)
  141. }
  142. encryptor, decryptor, err := obfuscated2.ServerHandshake(conn)
  143. if err != nil {
  144. conn.Close()
  145. return fmt.Errorf("cannot perform obfuscated2 handshake: %w", err)
  146. }
  147. ctx.telegramConn = &obfuscated2.Conn{
  148. Conn: connTelegramTraffic{
  149. Conn: conn,
  150. connID: ctx.connID,
  151. stream: p.eventStream,
  152. ctx: ctx,
  153. },
  154. Encryptor: encryptor,
  155. Decryptor: decryptor,
  156. }
  157. p.eventStream.Send(ctx, EventConnectedToDC{
  158. CreatedAt: time.Now(),
  159. ConnID: ctx.connID,
  160. RemoteIP: conn.RemoteAddr().(*net.TCPAddr).IP,
  161. DC: ctx.dc,
  162. })
  163. return nil
  164. }
  165. func NewProxy(opts ProxyOpts) (*Proxy, error) { // nolint: cyclop, funlen
  166. switch {
  167. case opts.Network == nil:
  168. return nil, ErrNetworkIsNotDefined
  169. case opts.AntiReplayCache == nil:
  170. return nil, ErrAntiReplayCacheIsNotDefined
  171. case opts.IPBlocklist == nil:
  172. return nil, ErrIPBlocklistIsNotDefined
  173. case opts.EventStream == nil:
  174. return nil, ErrEventStreamIsNotDefined
  175. case opts.TimeAttackDetector == nil:
  176. return nil, ErrTimeAttackDetectorIsNotDefined
  177. case opts.Logger == nil:
  178. return nil, ErrLoggerIsNotDefined
  179. case !opts.Secret.Valid():
  180. return nil, ErrSecretInvalid
  181. }
  182. tg, err := telegram.New(opts.Network, opts.PreferIP)
  183. if err != nil {
  184. return nil, fmt.Errorf("cannot build telegram dialer: %w", err)
  185. }
  186. concurrency := opts.Concurrency
  187. if concurrency == 0 {
  188. concurrency = DefaultConcurrency
  189. }
  190. idleTimeout := opts.IdleTimeout
  191. if idleTimeout < 1 {
  192. idleTimeout = DefaultIdleTimeout
  193. }
  194. bufferSize := opts.BufferSize
  195. if bufferSize < 1 {
  196. bufferSize = DefaultBufferSize
  197. }
  198. ctx, cancel := context.WithCancel(context.Background())
  199. proxy := &Proxy{
  200. ctx: ctx,
  201. ctxCancel: cancel,
  202. secret: opts.Secret,
  203. antiReplayCache: opts.AntiReplayCache,
  204. timeAttackDetector: opts.TimeAttackDetector,
  205. ipBlocklist: opts.IPBlocklist,
  206. eventStream: opts.EventStream,
  207. logger: opts.Logger.Named("proxy"),
  208. idleTimeout: idleTimeout,
  209. bufferSize: int(bufferSize),
  210. telegram: tg,
  211. }
  212. pool, err := ants.NewPoolWithFunc(int(concurrency), func(arg interface{}) {
  213. proxy.ServeConn(arg.(net.Conn))
  214. }, ants.WithLogger(opts.Logger.Named("ants")))
  215. if err != nil {
  216. return nil, fmt.Errorf("cannot initialize a pool: %w", err)
  217. }
  218. proxy.workerPool = pool
  219. return proxy, nil
  220. }