Highly-opinionated (ex-bullshit-free) MTPROTO proxy for Telegram. If you use v1.0 or upgrade broke you proxy, please read the chapter Version 2
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

run_proxy.go 10KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402
  1. package cli
  2. import (
  3. "context"
  4. "fmt"
  5. "net"
  6. "os"
  7. "strings"
  8. "github.com/9seconds/mtg/v2/antireplay"
  9. "github.com/9seconds/mtg/v2/events"
  10. "github.com/9seconds/mtg/v2/internal/config"
  11. "github.com/9seconds/mtg/v2/internal/proxyprotocol"
  12. "github.com/9seconds/mtg/v2/internal/utils"
  13. "github.com/9seconds/mtg/v2/ipblocklist"
  14. "github.com/9seconds/mtg/v2/ipblocklist/files"
  15. "github.com/9seconds/mtg/v2/logger"
  16. "github.com/9seconds/mtg/v2/mtglib"
  17. "github.com/9seconds/mtg/v2/network/v2"
  18. "github.com/9seconds/mtg/v2/stats"
  19. "github.com/pires/go-proxyproto"
  20. "github.com/rs/zerolog"
  21. "github.com/yl2chen/cidranger"
  22. )
  23. func makeLogger(conf *config.Config) mtglib.Logger {
  24. zerolog.TimeFieldFormat = zerolog.TimeFormatUnixMs
  25. zerolog.TimestampFieldName = "timestamp"
  26. zerolog.LevelFieldName = "level"
  27. if conf.Debug.Get(false) {
  28. zerolog.SetGlobalLevel(zerolog.DebugLevel)
  29. } else {
  30. zerolog.SetGlobalLevel(zerolog.WarnLevel)
  31. }
  32. baseLogger := zerolog.New(os.Stdout).With().Timestamp().Logger()
  33. return logger.NewZeroLogger(baseLogger)
  34. }
  35. func makeNetwork(conf *config.Config, version string) (mtglib.Network, error) {
  36. resolver, err := network.GetDNS(conf.GetDNS())
  37. if err != nil {
  38. return nil, fmt.Errorf("cannot create DNS resolver: %w", err)
  39. }
  40. base := network.New(
  41. resolver,
  42. "",
  43. conf.Network.Timeout.TCP.Get(0),
  44. conf.Network.Timeout.HTTP.Get(0),
  45. conf.Network.Timeout.Idle.Get(0),
  46. net.KeepAliveConfig{
  47. Enable: !conf.Network.KeepAlive.Disabled.Get(false),
  48. Idle: conf.Network.KeepAlive.Idle.Get(0),
  49. Interval: conf.Network.KeepAlive.Interval.Get(0),
  50. Count: int(conf.Network.KeepAlive.Count.Get(0)),
  51. },
  52. int(conf.Network.TCPNotSentLowat.Get(network.DefaultTCPNotSentLowat)),
  53. )
  54. proxyDialers := make([]mtglib.Network, len(conf.Network.Proxies))
  55. for idx, v := range conf.Network.Proxies {
  56. value, err := network.NewProxyNetwork(base, v.Get(nil))
  57. if err != nil {
  58. return nil, fmt.Errorf("cannot use %v for proxy url: %w", v.Get(nil), err)
  59. }
  60. proxyDialers[idx] = value
  61. }
  62. switch len(proxyDialers) {
  63. case 0:
  64. return base, nil
  65. case 1:
  66. return proxyDialers[0], nil
  67. }
  68. value, err := network.Join(proxyDialers...)
  69. if err != nil {
  70. panic(err)
  71. }
  72. return value, nil
  73. }
  74. func makeAntiReplayCache(conf *config.Config) mtglib.AntiReplayCache {
  75. if !conf.Defense.AntiReplay.Enabled.Get(false) {
  76. return antireplay.NewNoop()
  77. }
  78. return antireplay.NewStableBloomFilter(
  79. conf.Defense.AntiReplay.MaxSize.Get(antireplay.DefaultStableBloomFilterMaxSize),
  80. conf.Defense.AntiReplay.ErrorRate.Get(antireplay.DefaultStableBloomFilterErrorRate),
  81. )
  82. }
  83. func makeIPBlocklist(conf config.ListConfig,
  84. logger mtglib.Logger,
  85. ntw mtglib.Network,
  86. updateCallback ipblocklist.FireholUpdateCallback,
  87. ) (mtglib.IPBlocklist, error) {
  88. if !conf.Enabled.Get(false) {
  89. return ipblocklist.NewNoop(), nil
  90. }
  91. remoteURLs := []string{}
  92. localFiles := []string{}
  93. for _, v := range conf.URLs {
  94. if v.IsRemote() {
  95. remoteURLs = append(remoteURLs, v.String())
  96. } else {
  97. localFiles = append(localFiles, v.String())
  98. }
  99. }
  100. blocklist, err := ipblocklist.NewFirehol(logger.Named("ipblockist"),
  101. ntw,
  102. conf.DownloadConcurrency.Get(1),
  103. remoteURLs,
  104. localFiles,
  105. updateCallback)
  106. if err != nil {
  107. return nil, fmt.Errorf("incorrect parameters for firehol: %w", err)
  108. }
  109. go blocklist.Run(conf.UpdateEach.Get(ipblocklist.DefaultFireholUpdateEach))
  110. return blocklist, nil
  111. }
  112. func makeIPAllowlist(conf config.ListConfig,
  113. logger mtglib.Logger,
  114. ntw mtglib.Network,
  115. updateCallback ipblocklist.FireholUpdateCallback,
  116. ) (mtglib.IPBlocklist, error) {
  117. var (
  118. allowlist mtglib.IPBlocklist
  119. err error
  120. )
  121. if !conf.Enabled.Get(false) {
  122. allowlist, err = ipblocklist.NewFireholFromFiles(
  123. logger.Named("ipblocklist"),
  124. 1,
  125. []files.File{
  126. files.NewMem([]*net.IPNet{
  127. cidranger.AllIPv4,
  128. cidranger.AllIPv6,
  129. }),
  130. },
  131. updateCallback,
  132. )
  133. go allowlist.Run(conf.UpdateEach.Get(ipblocklist.DefaultFireholUpdateEach))
  134. } else {
  135. allowlist, err = makeIPBlocklist(
  136. conf,
  137. logger,
  138. ntw,
  139. updateCallback,
  140. )
  141. }
  142. if err != nil {
  143. return nil, fmt.Errorf("cannot build allowlist: %w", err)
  144. }
  145. return allowlist, nil
  146. }
  147. func makeEventStream(conf *config.Config, logger mtglib.Logger) (mtglib.EventStream, error) {
  148. factories := make([]events.ObserverFactory, 0, 2)
  149. if conf.Stats.StatsD.Enabled.Get(false) {
  150. statsdFactory, err := stats.NewStatsd(
  151. conf.Stats.StatsD.Address.Get(""),
  152. logger.Named("statsd"),
  153. conf.Stats.StatsD.MetricPrefix.Get(stats.DefaultStatsdMetricPrefix),
  154. conf.Stats.StatsD.TagFormat.Get(stats.DefaultStatsdTagFormat))
  155. if err != nil {
  156. return nil, fmt.Errorf("cannot build statsd observer: %w", err)
  157. }
  158. factories = append(factories, statsdFactory.Make)
  159. }
  160. if conf.Stats.Prometheus.Enabled.Get(false) {
  161. prometheus := stats.NewPrometheus(
  162. conf.Stats.Prometheus.MetricPrefix.Get(stats.DefaultMetricPrefix),
  163. conf.Stats.Prometheus.HTTPPath.Get("/"),
  164. )
  165. listener, err := net.Listen("tcp", conf.Stats.Prometheus.BindTo.Get(""))
  166. if err != nil {
  167. return nil, fmt.Errorf("cannot start a listener for prometheus: %w", err)
  168. }
  169. go prometheus.Serve(listener) //nolint: errcheck
  170. factories = append(factories, prometheus.Make)
  171. }
  172. if len(factories) > 0 {
  173. return events.NewEventStream(factories), nil
  174. }
  175. return events.NewNoopStream(), nil
  176. }
  177. func warnSNIMismatch(conf *config.Config, ntw mtglib.Network, log mtglib.Logger) {
  178. host := conf.Secret.Host
  179. if host == "" {
  180. return
  181. }
  182. addresses, err := net.DefaultResolver.LookupIPAddr(context.Background(), host)
  183. if err != nil {
  184. log.BindStr("hostname", host).
  185. WarningError("SNI-DNS check: cannot resolve secret hostname", err)
  186. return
  187. }
  188. ourIP4 := conf.PublicIPv4.Get(nil)
  189. if ourIP4 == nil {
  190. ourIP4 = getIP(ntw, "tcp4")
  191. }
  192. ourIP6 := conf.PublicIPv6.Get(nil)
  193. if ourIP6 == nil {
  194. ourIP6 = getIP(ntw, "tcp6")
  195. }
  196. if ourIP4 == nil && ourIP6 == nil {
  197. log.Warning("SNI-DNS check: cannot detect public IP address; set public-ipv4/public-ipv6 in config or run 'mtg doctor'")
  198. return
  199. }
  200. v4Match := ourIP4 == nil
  201. v6Match := ourIP6 == nil
  202. for _, addr := range addresses {
  203. if ourIP4 != nil && addr.IP.String() == ourIP4.String() {
  204. v4Match = true
  205. }
  206. if ourIP6 != nil && addr.IP.String() == ourIP6.String() {
  207. v6Match = true
  208. }
  209. }
  210. if v4Match && v6Match {
  211. return
  212. }
  213. resolved := make([]string, 0, len(addresses))
  214. for _, addr := range addresses {
  215. resolved = append(resolved, addr.IP.String())
  216. }
  217. our := ""
  218. if ourIP4 != nil {
  219. our = ourIP4.String()
  220. }
  221. if ourIP6 != nil {
  222. if our != "" {
  223. our += "/"
  224. }
  225. our += ourIP6.String()
  226. }
  227. entry := log.BindStr("hostname", host).
  228. BindStr("resolved", strings.Join(resolved, ", ")).
  229. BindStr("public_ip", our)
  230. if ourIP4 != nil {
  231. entry = entry.BindStr("ipv4_match", fmt.Sprintf("%t", v4Match))
  232. }
  233. if ourIP6 != nil {
  234. entry = entry.BindStr("ipv6_match", fmt.Sprintf("%t", v6Match))
  235. }
  236. entry.Warning("SNI-DNS mismatch: secret hostname does not resolve to this server's public IP. " +
  237. "DPI may detect and block the proxy. See 'mtg doctor' for details")
  238. }
  239. func warnDeprecatedDomainFronting(conf *config.Config, log mtglib.Logger) {
  240. if conf.DomainFrontingIP.Value != nil {
  241. log.Warning(`config option "domain-fronting-ip" is deprecated and ignored; use "host" in [domain-fronting] instead`)
  242. }
  243. if conf.DomainFronting.IP.Value != nil {
  244. log.Warning(`config option "ip" in [domain-fronting] is deprecated and ignored; use "host" instead`)
  245. }
  246. }
  247. func runProxy(conf *config.Config, version string) error { //nolint: funlen, cyclop
  248. logger := makeLogger(conf)
  249. logger.BindJSON("configuration", conf.String()).Debug("configuration")
  250. warnDeprecatedDomainFronting(conf, logger)
  251. eventStream, err := makeEventStream(conf, logger)
  252. if err != nil {
  253. return fmt.Errorf("cannot build event stream: %w", err)
  254. }
  255. ntw, err := makeNetwork(conf, version)
  256. if err != nil {
  257. return fmt.Errorf("cannot build network: %w", err)
  258. }
  259. warnSNIMismatch(conf, ntw, logger)
  260. blocklist, err := makeIPBlocklist(
  261. conf.Defense.Blocklist,
  262. logger.Named("blocklist"),
  263. ntw,
  264. func(ctx context.Context, size int) {
  265. eventStream.Send(ctx, mtglib.NewEventIPListSize(size, true))
  266. })
  267. if err != nil {
  268. return fmt.Errorf("cannot build ip blocklist: %w", err)
  269. }
  270. allowlist, err := makeIPAllowlist(
  271. conf.Defense.Allowlist,
  272. logger.Named("allowlist"),
  273. ntw,
  274. func(ctx context.Context, size int) {
  275. eventStream.Send(ctx, mtglib.NewEventIPListSize(size, false))
  276. },
  277. )
  278. if err != nil {
  279. return fmt.Errorf("cannot build ip allowlist: %w", err)
  280. }
  281. doppelGangerURLs := make([]string, len(conf.Defense.Doppelganger.URLs))
  282. for i, v := range conf.Defense.Doppelganger.URLs {
  283. doppelGangerURLs[i] = v.String()
  284. }
  285. opts := mtglib.ProxyOpts{
  286. Logger: logger,
  287. Network: ntw,
  288. AntiReplayCache: makeAntiReplayCache(conf),
  289. IPBlocklist: blocklist,
  290. IPAllowlist: allowlist,
  291. EventStream: eventStream,
  292. Secret: conf.Secret,
  293. Concurrency: conf.GetConcurrency(mtglib.DefaultConcurrency),
  294. DomainFrontingPort: conf.GetDomainFrontingPort(mtglib.DefaultDomainFrontingPort),
  295. DomainFrontingHost: conf.GetDomainFrontingHost(),
  296. DomainFrontingProxyProtocol: conf.GetDomainFrontingProxyProtocol(false),
  297. PreferIP: conf.PreferIP.Get(mtglib.DefaultPreferIP),
  298. AutoUpdate: conf.AutoUpdate.Get(false),
  299. AllowFallbackOnUnknownDC: conf.AllowFallbackOnUnknownDC.Get(false),
  300. TolerateTimeSkewness: conf.TolerateTimeSkewness.Value,
  301. IdleTimeout: conf.Network.Timeout.Idle.Get(mtglib.DefaultIdleTimeout),
  302. HandshakeTimeout: conf.Network.Timeout.Handshake.Get(mtglib.DefaultHandshakeTimeout),
  303. DoppelGangerURLs: doppelGangerURLs,
  304. DoppelGangerPerRaid: conf.Defense.Doppelganger.Repeats.Get(mtglib.DoppelGangerPerRaid),
  305. DoppelGangerEach: conf.Defense.Doppelganger.UpdateEach.Get(mtglib.DoppelGangerEach),
  306. DoppelGangerDRS: conf.Defense.Doppelganger.DRS.Get(false),
  307. }
  308. proxy, err := mtglib.NewProxy(opts)
  309. if err != nil {
  310. return fmt.Errorf("cannot create a proxy: %w", err)
  311. }
  312. listener, err := utils.NewListener(conf.BindTo.Get(""), 0)
  313. if err != nil {
  314. return fmt.Errorf("cannot start proxy: %w", err)
  315. }
  316. if conf.ProxyProtocolListener.Get(false) {
  317. listener = &proxyprotocol.ListenerAdapter{
  318. Listener: proxyproto.Listener{
  319. Listener: listener,
  320. },
  321. }
  322. }
  323. ctx := utils.RootContext()
  324. go proxy.Serve(listener) //nolint: errcheck
  325. <-ctx.Done()
  326. listener.Close() //nolint: errcheck
  327. proxy.Shutdown()
  328. return nil
  329. }