Highly-opinionated (ex-bullshit-free) MTPROTO proxy for Telegram. If you use v1.0 or upgrade broke you proxy, please read the chapter Version 2
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

proxy.go 6.4KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272
  1. package mtglib
  2. import (
  3. "context"
  4. "errors"
  5. "fmt"
  6. "net"
  7. "sync"
  8. "time"
  9. "github.com/9seconds/mtg/v2/mtglib/internal/faketls"
  10. "github.com/9seconds/mtg/v2/mtglib/internal/faketls/record"
  11. "github.com/9seconds/mtg/v2/mtglib/internal/obfuscated2"
  12. "github.com/9seconds/mtg/v2/mtglib/internal/relay"
  13. "github.com/9seconds/mtg/v2/mtglib/internal/telegram"
  14. "github.com/panjf2000/ants/v2"
  15. )
  16. type Proxy struct {
  17. ctx context.Context
  18. ctxCancel context.CancelFunc
  19. streamWaitGroup sync.WaitGroup
  20. idleTimeout time.Duration
  21. bufferSize int
  22. workerPool *ants.PoolWithFunc
  23. telegram *telegram.Telegram
  24. secret Secret
  25. antiReplayCache AntiReplayCache
  26. timeAttackDetector TimeAttackDetector
  27. ipBlocklist IPBlocklist
  28. eventStream EventStream
  29. logger Logger
  30. }
  31. func (p *Proxy) ServeConn(conn net.Conn) {
  32. ctx := newStreamContext(p.ctx, p.logger, conn)
  33. defer ctx.Close()
  34. go func() {
  35. <-ctx.Done()
  36. ctx.Close()
  37. }()
  38. p.eventStream.Send(ctx, EventStart{
  39. CreatedAt: time.Now(),
  40. ConnID: ctx.connID,
  41. RemoteIP: ctx.ClientIP(),
  42. })
  43. ctx.logger.Info("Stream has been started")
  44. defer func() {
  45. p.eventStream.Send(ctx, EventFinish{
  46. CreatedAt: time.Now(),
  47. ConnID: ctx.connID,
  48. })
  49. ctx.logger.Info("Stream has been finished")
  50. }()
  51. if err := p.doFakeTLSHandshake(ctx); err != nil {
  52. p.logger.InfoError("faketls handshake is failed", err)
  53. return
  54. }
  55. if err := p.doObfuscated2Handshake(ctx); err != nil {
  56. p.logger.InfoError("obfuscated2 handshake is failed", err)
  57. return
  58. }
  59. if err := p.doTelegramCall(ctx); err != nil {
  60. p.logger.WarningError("cannot dial to telegram", err)
  61. return
  62. }
  63. rel := relay.AcquireRelay(ctx, p.logger.Named("relay"), p.bufferSize, p.idleTimeout)
  64. defer relay.ReleaseRelay(rel)
  65. if err := rel.Process(ctx.clientConn, ctx.telegramConn); err != nil {
  66. p.logger.DebugError("relay has been finished", err)
  67. }
  68. }
  69. func (p *Proxy) Serve(listener net.Listener) error {
  70. for {
  71. conn, err := listener.Accept()
  72. if err != nil {
  73. return fmt.Errorf("cannot accept a new connection: %w", err)
  74. }
  75. if addr := conn.RemoteAddr().(*net.TCPAddr).IP; p.ipBlocklist.Contains(addr) {
  76. conn.Close()
  77. p.eventStream.Send(p.ctx, EventIPBlocklisted{
  78. CreatedAt: time.Now(),
  79. RemoteIP: addr,
  80. })
  81. continue
  82. }
  83. err = p.workerPool.Invoke(conn)
  84. switch {
  85. case err == nil:
  86. case errors.Is(err, ants.ErrPoolClosed):
  87. return nil
  88. case errors.Is(err, ants.ErrPoolOverload):
  89. p.eventStream.Send(p.ctx, EventConcurrencyLimited{
  90. CreatedAt: time.Now(),
  91. })
  92. }
  93. }
  94. }
  95. func (p *Proxy) Shutdown() {
  96. p.ctxCancel()
  97. p.streamWaitGroup.Wait()
  98. p.workerPool.Release()
  99. }
  100. func (p *Proxy) doFakeTLSHandshake(ctx *streamContext) error {
  101. rec := record.AcquireRecord()
  102. defer record.ReleaseRecord(rec)
  103. if err := rec.Read(ctx.clientConn); err != nil {
  104. return fmt.Errorf("cannot read client hello: %w", err)
  105. }
  106. hello, err := faketls.ParseClientHello(p.secret.Key[:], rec.Payload.Bytes())
  107. if err != nil {
  108. return fmt.Errorf("cannot parse client hello: %w", err)
  109. }
  110. if err := p.timeAttackDetector.Valid(hello.Time); err != nil {
  111. return fmt.Errorf("invalid time: %w", err)
  112. }
  113. if p.antiReplayCache.SeenBefore(hello.SessionID) {
  114. p.logger.Warning("anti replay attack was detected")
  115. return fmt.Errorf("anti replay attack from %s", ctx.ClientIP().String())
  116. }
  117. if err := faketls.SendWelcomePacket(ctx.clientConn, p.secret.Key[:], hello); err != nil {
  118. return fmt.Errorf("cannot send a welcome packet: %w", err)
  119. }
  120. ctx.clientConn = &faketls.Conn{
  121. Conn: ctx.clientConn,
  122. }
  123. return nil
  124. }
  125. func (p *Proxy) doObfuscated2Handshake(ctx *streamContext) error {
  126. dc, encryptor, decryptor, err := obfuscated2.ClientHandshake(p.secret.Key[:], ctx.clientConn)
  127. if err != nil {
  128. return fmt.Errorf("cannot process client handshake: %w", err)
  129. }
  130. ctx.dc = dc
  131. ctx.logger = ctx.logger.BindInt("dc", dc)
  132. ctx.clientConn = &obfuscated2.Conn{
  133. Conn: ctx.clientConn,
  134. Encryptor: encryptor,
  135. Decryptor: decryptor,
  136. }
  137. return nil
  138. }
  139. func (p *Proxy) doTelegramCall(ctx *streamContext) error {
  140. conn, err := p.telegram.Dial(ctx, ctx.dc)
  141. if err != nil {
  142. return fmt.Errorf("cannot dial to Telegram: %w", err)
  143. }
  144. encryptor, decryptor, err := obfuscated2.ServerHandshake(conn)
  145. if err != nil {
  146. conn.Close()
  147. return fmt.Errorf("cannot perform obfuscated2 handshake: %w", err)
  148. }
  149. ctx.telegramConn = &obfuscated2.Conn{
  150. Conn: connTelegramTraffic{
  151. Conn: conn,
  152. connID: ctx.connID,
  153. stream: p.eventStream,
  154. ctx: ctx,
  155. },
  156. Encryptor: encryptor,
  157. Decryptor: decryptor,
  158. }
  159. p.eventStream.Send(ctx, EventConnectedToDC{
  160. CreatedAt: time.Now(),
  161. ConnID: ctx.connID,
  162. RemoteIP: conn.RemoteAddr().(*net.TCPAddr).IP,
  163. DC: ctx.dc,
  164. })
  165. return nil
  166. }
  167. func NewProxy(opts ProxyOpts) (*Proxy, error) { // nolint: cyclop, funlen
  168. switch {
  169. case opts.Network == nil:
  170. return nil, ErrNetworkIsNotDefined
  171. case opts.AntiReplayCache == nil:
  172. return nil, ErrAntiReplayCacheIsNotDefined
  173. case opts.IPBlocklist == nil:
  174. return nil, ErrIPBlocklistIsNotDefined
  175. case opts.EventStream == nil:
  176. return nil, ErrEventStreamIsNotDefined
  177. case opts.TimeAttackDetector == nil:
  178. return nil, ErrTimeAttackDetectorIsNotDefined
  179. case opts.Logger == nil:
  180. return nil, ErrLoggerIsNotDefined
  181. case !opts.Secret.Valid():
  182. return nil, ErrSecretInvalid
  183. }
  184. tg, err := telegram.New(opts.Network, opts.PreferIP)
  185. if err != nil {
  186. return nil, fmt.Errorf("cannot build telegram dialer: %w", err)
  187. }
  188. concurrency := opts.Concurrency
  189. if concurrency == 0 {
  190. concurrency = DefaultConcurrency
  191. }
  192. idleTimeout := opts.IdleTimeout
  193. if idleTimeout < 1 {
  194. idleTimeout = DefaultIdleTimeout
  195. }
  196. bufferSize := opts.BufferSize
  197. if bufferSize < 1 {
  198. bufferSize = DefaultBufferSize
  199. }
  200. ctx, cancel := context.WithCancel(context.Background())
  201. proxy := &Proxy{
  202. ctx: ctx,
  203. ctxCancel: cancel,
  204. secret: opts.Secret,
  205. antiReplayCache: opts.AntiReplayCache,
  206. timeAttackDetector: opts.TimeAttackDetector,
  207. ipBlocklist: opts.IPBlocklist,
  208. eventStream: opts.EventStream,
  209. logger: opts.Logger.Named("proxy"),
  210. idleTimeout: idleTimeout,
  211. bufferSize: int(bufferSize),
  212. telegram: tg,
  213. }
  214. pool, err := ants.NewPoolWithFunc(int(concurrency), func(arg interface{}) {
  215. proxy.ServeConn(arg.(net.Conn))
  216. }, ants.WithLogger(opts.Logger.Named("ants")))
  217. if err != nil {
  218. return nil, fmt.Errorf("cannot initialize a pool: %w", err)
  219. }
  220. proxy.workerPool = pool
  221. return proxy, nil
  222. }