Highly-opinionated (ex-bullshit-free) MTPROTO proxy for Telegram. If you use v1.0 or upgrade broke you proxy, please read the chapter Version 2
選択できるのは25トピックまでです。 トピックは、先頭が英数字で、英数字とダッシュ('-')を使用した35文字以内のものにしてください。

run_proxy.go 10KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380
  1. package cli
  2. import (
  3. "context"
  4. "fmt"
  5. "net"
  6. "os"
  7. "slices"
  8. "strings"
  9. "github.com/9seconds/mtg/v2/antireplay"
  10. "github.com/9seconds/mtg/v2/events"
  11. "github.com/9seconds/mtg/v2/internal/config"
  12. "github.com/9seconds/mtg/v2/internal/desync"
  13. "github.com/9seconds/mtg/v2/internal/proxyprotocol"
  14. "github.com/9seconds/mtg/v2/internal/utils"
  15. "github.com/9seconds/mtg/v2/ipblocklist"
  16. "github.com/9seconds/mtg/v2/ipblocklist/files"
  17. "github.com/9seconds/mtg/v2/logger"
  18. "github.com/9seconds/mtg/v2/mtglib"
  19. "github.com/9seconds/mtg/v2/network/v2"
  20. "github.com/9seconds/mtg/v2/stats"
  21. "github.com/pires/go-proxyproto"
  22. "github.com/rs/zerolog"
  23. "github.com/yl2chen/cidranger"
  24. )
  25. func makeLogger(conf *config.Config) mtglib.Logger {
  26. zerolog.TimeFieldFormat = zerolog.TimeFormatUnixMs
  27. zerolog.TimestampFieldName = "timestamp"
  28. zerolog.LevelFieldName = "level"
  29. if conf.Debug.Get(false) {
  30. zerolog.SetGlobalLevel(zerolog.DebugLevel)
  31. } else {
  32. zerolog.SetGlobalLevel(zerolog.WarnLevel)
  33. }
  34. baseLogger := zerolog.New(os.Stdout).With().Timestamp().Logger()
  35. return logger.NewZeroLogger(baseLogger)
  36. }
  37. func makeNetwork(conf *config.Config, version string) (mtglib.Network, error) {
  38. resolver, err := network.GetDNS(conf.GetDNS())
  39. if err != nil {
  40. return nil, fmt.Errorf("cannot create DNS resolver: %w", err)
  41. }
  42. base := network.New(
  43. resolver,
  44. "",
  45. conf.Network.Timeout.TCP.Get(0),
  46. conf.Network.Timeout.HTTP.Get(0),
  47. conf.Network.Timeout.Idle.Get(0),
  48. net.KeepAliveConfig{
  49. Enable: !conf.Network.KeepAlive.Disabled.Get(false),
  50. Idle: conf.Network.KeepAlive.Idle.Get(0),
  51. Interval: conf.Network.KeepAlive.Interval.Get(0),
  52. Count: int(conf.Network.KeepAlive.Count.Get(0)),
  53. },
  54. int(conf.Network.TCPNotSentLowat.Get(network.DefaultTCPNotSentLowat)),
  55. )
  56. proxyDialers := make([]mtglib.Network, len(conf.Network.Proxies))
  57. for idx, v := range conf.Network.Proxies {
  58. value, err := network.NewProxyNetwork(base, v.Get(nil))
  59. if err != nil {
  60. return nil, fmt.Errorf("cannot use %v for proxy url: %w", v.Get(nil), err)
  61. }
  62. proxyDialers[idx] = value
  63. }
  64. switch len(proxyDialers) {
  65. case 0:
  66. return base, nil
  67. case 1:
  68. return proxyDialers[0], nil
  69. }
  70. value, err := network.Join(proxyDialers...)
  71. if err != nil {
  72. panic(err)
  73. }
  74. return value, nil
  75. }
  76. func makeAntiReplayCache(conf *config.Config) mtglib.AntiReplayCache {
  77. if !conf.Defense.AntiReplay.Enabled.Get(false) {
  78. return antireplay.NewNoop()
  79. }
  80. return antireplay.NewStableBloomFilter(
  81. conf.Defense.AntiReplay.MaxSize.Get(antireplay.DefaultStableBloomFilterMaxSize),
  82. conf.Defense.AntiReplay.ErrorRate.Get(antireplay.DefaultStableBloomFilterErrorRate),
  83. )
  84. }
  85. func makeIPBlocklist(conf config.ListConfig,
  86. logger mtglib.Logger,
  87. ntw mtglib.Network,
  88. updateCallback ipblocklist.FireholUpdateCallback,
  89. ) (mtglib.IPBlocklist, error) {
  90. if !conf.Enabled.Get(false) {
  91. return ipblocklist.NewNoop(), nil
  92. }
  93. remoteURLs := []string{}
  94. localFiles := []string{}
  95. for _, v := range conf.URLs {
  96. if v.IsRemote() {
  97. remoteURLs = append(remoteURLs, v.String())
  98. } else {
  99. localFiles = append(localFiles, v.String())
  100. }
  101. }
  102. blocklist, err := ipblocklist.NewFirehol(logger.Named("ipblockist"),
  103. ntw,
  104. conf.DownloadConcurrency.Get(1),
  105. remoteURLs,
  106. localFiles,
  107. updateCallback)
  108. if err != nil {
  109. return nil, fmt.Errorf("incorrect parameters for firehol: %w", err)
  110. }
  111. go blocklist.Run(conf.UpdateEach.Get(ipblocklist.DefaultFireholUpdateEach))
  112. return blocklist, nil
  113. }
  114. func makeIPAllowlist(conf config.ListConfig,
  115. logger mtglib.Logger,
  116. ntw mtglib.Network,
  117. updateCallback ipblocklist.FireholUpdateCallback,
  118. ) (mtglib.IPBlocklist, error) {
  119. var (
  120. allowlist mtglib.IPBlocklist
  121. err error
  122. )
  123. if !conf.Enabled.Get(false) {
  124. allowlist, err = ipblocklist.NewFireholFromFiles(
  125. logger.Named("ipblocklist"),
  126. 1,
  127. []files.File{
  128. files.NewMem([]*net.IPNet{
  129. cidranger.AllIPv4,
  130. cidranger.AllIPv6,
  131. }),
  132. },
  133. updateCallback,
  134. )
  135. go allowlist.Run(conf.UpdateEach.Get(ipblocklist.DefaultFireholUpdateEach))
  136. } else {
  137. allowlist, err = makeIPBlocklist(
  138. conf,
  139. logger,
  140. ntw,
  141. updateCallback,
  142. )
  143. }
  144. if err != nil {
  145. return nil, fmt.Errorf("cannot build allowlist: %w", err)
  146. }
  147. return allowlist, nil
  148. }
  149. func makeEventStream(conf *config.Config, logger mtglib.Logger) (mtglib.EventStream, error) {
  150. factories := make([]events.ObserverFactory, 0, 2)
  151. if conf.Stats.StatsD.Enabled.Get(false) {
  152. statsdFactory, err := stats.NewStatsd(
  153. conf.Stats.StatsD.Address.Get(""),
  154. logger.Named("statsd"),
  155. conf.Stats.StatsD.MetricPrefix.Get(stats.DefaultStatsdMetricPrefix),
  156. conf.Stats.StatsD.TagFormat.Get(stats.DefaultStatsdTagFormat),
  157. )
  158. if err != nil {
  159. return nil, fmt.Errorf("cannot build statsd observer: %w", err)
  160. }
  161. factories = append(factories, statsdFactory.Make)
  162. }
  163. if conf.Stats.Prometheus.Enabled.Get(false) {
  164. prometheus := stats.NewPrometheus(
  165. conf.Stats.Prometheus.MetricPrefix.Get(stats.DefaultMetricPrefix),
  166. conf.Stats.Prometheus.HTTPPath.Get("/"),
  167. )
  168. listener, err := net.Listen("tcp", conf.Stats.Prometheus.BindTo.Get(""))
  169. if err != nil {
  170. return nil, fmt.Errorf("cannot start a listener for prometheus: %w", err)
  171. }
  172. go prometheus.Serve(listener) //nolint: errcheck
  173. factories = append(factories, prometheus.Make)
  174. }
  175. if len(factories) > 0 {
  176. return events.NewEventStream(factories), nil
  177. }
  178. return events.NewNoopStream(), nil
  179. }
  180. func warnSNIMismatch(conf *config.Config, ntw mtglib.Network, log mtglib.Logger) {
  181. host := conf.Secret.Host
  182. if host == "" {
  183. return
  184. }
  185. log = log.BindStr("hostname", host)
  186. res, err := runSNICheck(context.Background(), conf, net.DefaultResolver, ntw)
  187. if err != nil {
  188. log.WarningError("SNI-DNS check: cannot resolve secret hostname", err)
  189. return
  190. }
  191. if res.OurIP4 == "" && res.OurIP6 == "" {
  192. log.Warning("SNI-DNS check: cannot detect public IP address; set public-ipv4/public-ipv6 in config or run 'mtg doctor'")
  193. return
  194. }
  195. if len(res.ResolvedIP4) > 0 && !slices.Contains(res.ResolvedIP4, res.OurIP4) {
  196. log.
  197. BindStr("public_ip", res.OurIP4).
  198. BindStr("resolved", strings.Join(res.ResolvedIP4, ",")).
  199. Warning("SNI-DNS check: address mismatch")
  200. }
  201. if len(res.ResolvedIP6) > 0 && !slices.Contains(res.ResolvedIP6, res.OurIP6) {
  202. log.
  203. BindStr("public_ip", res.OurIP6).
  204. BindStr("resolved", strings.Join(res.ResolvedIP6, ",")).
  205. Warning("SNI-DNS check: address mismatch")
  206. }
  207. }
  208. func warnDeprecatedDomainFronting(conf *config.Config, log mtglib.Logger) {
  209. if conf.DomainFrontingIP.Value != nil {
  210. log.Warning(`config option "domain-fronting-ip" is deprecated and ignored; use "host" in [domain-fronting] instead`)
  211. }
  212. if conf.DomainFronting.IP.Value != nil {
  213. log.Warning(`config option "ip" in [domain-fronting] is deprecated and ignored; use "host" instead`)
  214. }
  215. }
  216. const dpiDesyncHandshakeWindowClamp = 256
  217. func runProxy(conf *config.Config, version string) error { //nolint: funlen, cyclop
  218. logger := makeLogger(conf)
  219. logger.BindJSON("configuration", conf.String()).Debug("configuration")
  220. warnDeprecatedDomainFronting(conf, logger)
  221. eventStream, err := makeEventStream(conf, logger)
  222. if err != nil {
  223. return fmt.Errorf("cannot build event stream: %w", err)
  224. }
  225. ntw, err := makeNetwork(conf, version)
  226. if err != nil {
  227. return fmt.Errorf("cannot build network: %w", err)
  228. }
  229. warnSNIMismatch(conf, ntw, logger)
  230. blocklist, err := makeIPBlocklist(
  231. conf.Defense.Blocklist,
  232. logger.Named("blocklist"),
  233. ntw,
  234. func(ctx context.Context, size int) {
  235. eventStream.Send(ctx, mtglib.NewEventIPListSize(size, true))
  236. },
  237. )
  238. if err != nil {
  239. return fmt.Errorf("cannot build ip blocklist: %w", err)
  240. }
  241. allowlist, err := makeIPAllowlist(
  242. conf.Defense.Allowlist,
  243. logger.Named("allowlist"),
  244. ntw,
  245. func(ctx context.Context, size int) {
  246. eventStream.Send(ctx, mtglib.NewEventIPListSize(size, false))
  247. },
  248. )
  249. if err != nil {
  250. return fmt.Errorf("cannot build ip allowlist: %w", err)
  251. }
  252. windowClamp := 0
  253. if conf.DPIDesync.Get(false) {
  254. // Empirically chosen: small enough for Linux IPv4 DPI desync, but still
  255. // large enough for Telegram media after the post-handshake clamp restore.
  256. windowClamp = dpiDesyncHandshakeWindowClamp
  257. }
  258. doppelGangerURLs := make([]string, len(conf.Defense.Doppelganger.URLs))
  259. for i, v := range conf.Defense.Doppelganger.URLs {
  260. doppelGangerURLs[i] = v.String()
  261. }
  262. opts := mtglib.ProxyOpts{
  263. Logger: logger,
  264. Network: ntw,
  265. AntiReplayCache: makeAntiReplayCache(conf),
  266. IPBlocklist: blocklist,
  267. IPAllowlist: allowlist,
  268. EventStream: eventStream,
  269. Secret: conf.Secret,
  270. Concurrency: conf.GetConcurrency(mtglib.DefaultConcurrency),
  271. DomainFrontingPort: conf.GetDomainFrontingPort(mtglib.DefaultDomainFrontingPort),
  272. DomainFrontingHost: conf.GetDomainFrontingHost(),
  273. DomainFrontingProxyProtocol: conf.GetDomainFrontingProxyProtocol(false),
  274. PreferIP: conf.PreferIP.Get(mtglib.DefaultPreferIP),
  275. AutoUpdate: conf.AutoUpdate.Get(false),
  276. AllowFallbackOnUnknownDC: conf.AllowFallbackOnUnknownDC.Get(false),
  277. TolerateTimeSkewness: conf.TolerateTimeSkewness.Value,
  278. IdleTimeout: conf.Network.Timeout.Idle.Get(mtglib.DefaultIdleTimeout),
  279. HandshakeTimeout: conf.Network.Timeout.Handshake.Get(mtglib.DefaultHandshakeTimeout),
  280. DoppelGangerURLs: doppelGangerURLs,
  281. DoppelGangerPerRaid: conf.Defense.Doppelganger.Repeats.Get(mtglib.DoppelGangerPerRaid),
  282. DoppelGangerEach: conf.Defense.Doppelganger.UpdateEach.Get(mtglib.DoppelGangerEach),
  283. DoppelGangerDRS: conf.Defense.Doppelganger.DRS.Get(false),
  284. DPIDesync: windowClamp > 0,
  285. }
  286. proxy, err := mtglib.NewProxy(opts)
  287. if err != nil {
  288. return fmt.Errorf("cannot create a proxy: %w", err)
  289. }
  290. listener, err := utils.NewListener(conf.BindTo.Get(""), windowClamp)
  291. if err != nil {
  292. return fmt.Errorf("cannot start proxy: %w", err)
  293. }
  294. if conf.ProxyProtocolListener.Get(false) {
  295. listener = &proxyprotocol.ListenerAdapter{
  296. Listener: proxyproto.Listener{
  297. Listener: listener,
  298. },
  299. }
  300. }
  301. ctx := utils.RootContext()
  302. if windowClamp > 0 {
  303. desyncSvc, err := desync.Start(int(conf.BindTo.Port))
  304. if err != nil {
  305. return fmt.Errorf("cannot start raw desync: %w", err)
  306. }
  307. defer desyncSvc.Close() //nolint: errcheck
  308. }
  309. go proxy.Serve(listener) //nolint: errcheck
  310. <-ctx.Done()
  311. listener.Close() //nolint: errcheck
  312. proxy.Shutdown()
  313. return nil
  314. }