Highly-opinionated (ex-bullshit-free) MTPROTO proxy for Telegram. If you use v1.0 or upgrade broke you proxy, please read the chapter Version 2
選択できるのは25トピックまでです。 トピックは、先頭が英数字で、英数字とダッシュ('-')を使用した35文字以内のものにしてください。

run_proxy.go 7.8KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301
  1. package cli
  2. import (
  3. "context"
  4. "fmt"
  5. "net"
  6. "os"
  7. "time"
  8. "github.com/9seconds/mtg/v2/antireplay"
  9. "github.com/9seconds/mtg/v2/events"
  10. "github.com/9seconds/mtg/v2/internal/config"
  11. "github.com/9seconds/mtg/v2/internal/proxyprotocol"
  12. "github.com/9seconds/mtg/v2/internal/utils"
  13. "github.com/9seconds/mtg/v2/ipblocklist"
  14. "github.com/9seconds/mtg/v2/ipblocklist/files"
  15. "github.com/9seconds/mtg/v2/logger"
  16. "github.com/9seconds/mtg/v2/mtglib"
  17. "github.com/9seconds/mtg/v2/network/v2"
  18. "github.com/9seconds/mtg/v2/stats"
  19. "github.com/pires/go-proxyproto"
  20. "github.com/rs/zerolog"
  21. "github.com/yl2chen/cidranger"
  22. )
  23. func makeLogger(conf *config.Config) mtglib.Logger {
  24. zerolog.TimeFieldFormat = zerolog.TimeFormatUnixMs
  25. zerolog.TimestampFieldName = "timestamp"
  26. zerolog.LevelFieldName = "level"
  27. if conf.Debug.Get(false) {
  28. zerolog.SetGlobalLevel(zerolog.DebugLevel)
  29. } else {
  30. zerolog.SetGlobalLevel(zerolog.WarnLevel)
  31. }
  32. baseLogger := zerolog.New(os.Stdout).With().Timestamp().Logger()
  33. return logger.NewZeroLogger(baseLogger)
  34. }
  35. func makeNetwork(conf *config.Config, version string) (mtglib.Network, error) {
  36. resolver, err := network.GetDNS(conf.GetDNS())
  37. if err != nil {
  38. return nil, fmt.Errorf("cannot create DNS resolver: %w", err)
  39. }
  40. base := network.New(
  41. resolver,
  42. "",
  43. conf.Network.Timeout.TCP.Get(0),
  44. conf.Network.Timeout.HTTP.Get(0),
  45. conf.Network.Timeout.Idle.Get(0),
  46. )
  47. proxyDialers := make([]mtglib.Network, len(conf.Network.Proxies))
  48. for idx, v := range conf.Network.Proxies {
  49. value, err := network.NewProxyNetwork(base, v.Get(nil))
  50. if err != nil {
  51. return nil, fmt.Errorf("cannot use %v for proxy url: %w", v.Get(nil), err)
  52. }
  53. proxyDialers[idx] = value
  54. }
  55. switch len(proxyDialers) {
  56. case 0:
  57. return base, nil
  58. case 1:
  59. return proxyDialers[0], nil
  60. }
  61. value, err := network.Join(proxyDialers...)
  62. if err != nil {
  63. panic(err)
  64. }
  65. return value, nil
  66. }
  67. func makeAntiReplayCache(conf *config.Config) mtglib.AntiReplayCache {
  68. if !conf.Defense.AntiReplay.Enabled.Get(false) {
  69. return antireplay.NewNoop()
  70. }
  71. return antireplay.NewStableBloomFilter(
  72. conf.Defense.AntiReplay.MaxSize.Get(antireplay.DefaultStableBloomFilterMaxSize),
  73. conf.Defense.AntiReplay.ErrorRate.Get(antireplay.DefaultStableBloomFilterErrorRate),
  74. )
  75. }
  76. func makeIPBlocklist(conf config.ListConfig,
  77. logger mtglib.Logger,
  78. ntw mtglib.Network,
  79. updateCallback ipblocklist.FireholUpdateCallback,
  80. ) (mtglib.IPBlocklist, error) {
  81. if !conf.Enabled.Get(false) {
  82. return ipblocklist.NewNoop(), nil
  83. }
  84. remoteURLs := []string{}
  85. localFiles := []string{}
  86. for _, v := range conf.URLs {
  87. if v.IsRemote() {
  88. remoteURLs = append(remoteURLs, v.String())
  89. } else {
  90. localFiles = append(localFiles, v.String())
  91. }
  92. }
  93. blocklist, err := ipblocklist.NewFirehol(logger.Named("ipblockist"),
  94. ntw,
  95. conf.DownloadConcurrency.Get(1),
  96. remoteURLs,
  97. localFiles,
  98. updateCallback)
  99. if err != nil {
  100. return nil, fmt.Errorf("incorrect parameters for firehol: %w", err)
  101. }
  102. go blocklist.Run(conf.UpdateEach.Get(ipblocklist.DefaultFireholUpdateEach))
  103. return blocklist, nil
  104. }
  105. func makeIPAllowlist(conf config.ListConfig,
  106. logger mtglib.Logger,
  107. ntw mtglib.Network,
  108. updateCallback ipblocklist.FireholUpdateCallback,
  109. ) (mtglib.IPBlocklist, error) {
  110. var (
  111. allowlist mtglib.IPBlocklist
  112. err error
  113. )
  114. if !conf.Enabled.Get(false) {
  115. allowlist, err = ipblocklist.NewFireholFromFiles(
  116. logger.Named("ipblocklist"),
  117. 1,
  118. []files.File{
  119. files.NewMem([]*net.IPNet{
  120. cidranger.AllIPv4,
  121. cidranger.AllIPv6,
  122. }),
  123. },
  124. updateCallback,
  125. )
  126. go allowlist.Run(conf.UpdateEach.Get(ipblocklist.DefaultFireholUpdateEach))
  127. } else {
  128. allowlist, err = makeIPBlocklist(
  129. conf,
  130. logger,
  131. ntw,
  132. updateCallback,
  133. )
  134. }
  135. if err != nil {
  136. return nil, fmt.Errorf("cannot build allowlist: %w", err)
  137. }
  138. return allowlist, nil
  139. }
  140. func makeEventStream(conf *config.Config, logger mtglib.Logger) (mtglib.EventStream, error) {
  141. factories := make([]events.ObserverFactory, 0, 2)
  142. if conf.Stats.StatsD.Enabled.Get(false) {
  143. statsdFactory, err := stats.NewStatsd(
  144. conf.Stats.StatsD.Address.Get(""),
  145. logger.Named("statsd"),
  146. conf.Stats.StatsD.MetricPrefix.Get(stats.DefaultStatsdMetricPrefix),
  147. conf.Stats.StatsD.TagFormat.Get(stats.DefaultStatsdTagFormat))
  148. if err != nil {
  149. return nil, fmt.Errorf("cannot build statsd observer: %w", err)
  150. }
  151. factories = append(factories, statsdFactory.Make)
  152. }
  153. if conf.Stats.Prometheus.Enabled.Get(false) {
  154. prometheus := stats.NewPrometheus(
  155. conf.Stats.Prometheus.MetricPrefix.Get(stats.DefaultMetricPrefix),
  156. conf.Stats.Prometheus.HTTPPath.Get("/"),
  157. )
  158. listener, err := net.Listen("tcp", conf.Stats.Prometheus.BindTo.Get(""))
  159. if err != nil {
  160. return nil, fmt.Errorf("cannot start a listener for prometheus: %w", err)
  161. }
  162. go prometheus.Serve(listener) //nolint: errcheck
  163. factories = append(factories, prometheus.Make)
  164. }
  165. if len(factories) > 0 {
  166. return events.NewEventStream(factories), nil
  167. }
  168. return events.NewNoopStream(), nil
  169. }
  170. func runProxy(conf *config.Config, version string) error { //nolint: funlen
  171. logger := makeLogger(conf)
  172. logger.BindJSON("configuration", conf.String()).Debug("configuration")
  173. eventStream, err := makeEventStream(conf, logger)
  174. if err != nil {
  175. return fmt.Errorf("cannot build event stream: %w", err)
  176. }
  177. ntw, err := makeNetwork(conf, version)
  178. if err != nil {
  179. return fmt.Errorf("cannot build network: %w", err)
  180. }
  181. blocklist, err := makeIPBlocklist(
  182. conf.Defense.Blocklist,
  183. logger.Named("blocklist"),
  184. ntw,
  185. func(ctx context.Context, size int) {
  186. eventStream.Send(ctx, mtglib.NewEventIPListSize(size, true))
  187. })
  188. if err != nil {
  189. return fmt.Errorf("cannot build ip blocklist: %w", err)
  190. }
  191. allowlist, err := makeIPAllowlist(
  192. conf.Defense.Allowlist,
  193. logger.Named("allowlist"),
  194. ntw,
  195. func(ctx context.Context, size int) {
  196. eventStream.Send(ctx, mtglib.NewEventIPListSize(size, false))
  197. },
  198. )
  199. if err != nil {
  200. return fmt.Errorf("cannot build ip allowlist: %w", err)
  201. }
  202. doppelGangerURLs := make([]string, len(conf.Defense.Doppelganger.URLs))
  203. for i, v := range conf.Defense.Doppelganger.URLs {
  204. doppelGangerURLs[i] = v.String()
  205. }
  206. opts := mtglib.ProxyOpts{
  207. Logger: logger,
  208. Network: ntw,
  209. AntiReplayCache: makeAntiReplayCache(conf),
  210. IPBlocklist: blocklist,
  211. IPAllowlist: allowlist,
  212. EventStream: eventStream,
  213. Secret: conf.Secret,
  214. Concurrency: conf.GetConcurrency(mtglib.DefaultConcurrency),
  215. DomainFrontingPort: conf.GetDomainFrontingPort(mtglib.DefaultDomainFrontingPort),
  216. DomainFrontingIP: conf.GetDomainFrontingIP(nil),
  217. DomainFrontingProxyProtocol: conf.GetDomainFrontingProxyProtocol(false),
  218. PreferIP: conf.PreferIP.Get(mtglib.DefaultPreferIP),
  219. AutoUpdate: conf.AutoUpdate.Get(false),
  220. AllowFallbackOnUnknownDC: conf.AllowFallbackOnUnknownDC.Get(false),
  221. TolerateTimeSkewness: conf.TolerateTimeSkewness.Value,
  222. IdleTimeout: conf.Network.Timeout.Idle.Get(time.Minute),
  223. DoppelGangerURLs: doppelGangerURLs,
  224. DoppelGangerPerRaid: conf.Defense.Doppelganger.Repeats.Get(mtglib.DoppelGangerPerRaid),
  225. DoppelGangerEach: conf.Defense.Doppelganger.UpdateEach.Get(mtglib.DoppelGangerEach),
  226. DoppelGangerDRS: conf.Defense.Doppelganger.DRS.Get(false),
  227. }
  228. proxy, err := mtglib.NewProxy(opts)
  229. if err != nil {
  230. return fmt.Errorf("cannot create a proxy: %w", err)
  231. }
  232. listener, err := utils.NewListener(conf.BindTo.Get(""), 0)
  233. if err != nil {
  234. return fmt.Errorf("cannot start proxy: %w", err)
  235. }
  236. if conf.ProxyProtocolListener.Get(false) {
  237. listener = &proxyprotocol.ListenerAdapter{
  238. Listener: proxyproto.Listener{
  239. Listener: listener,
  240. },
  241. }
  242. }
  243. ctx := utils.RootContext()
  244. go proxy.Serve(listener) //nolint: errcheck
  245. <-ctx.Done()
  246. listener.Close() //nolint: errcheck
  247. proxy.Shutdown()
  248. return nil
  249. }