Highly-opinionated (ex-bullshit-free) MTPROTO proxy for Telegram. If you use v1.0 or upgrade broke you proxy, please read the chapter Version 2
Você não pode selecionar mais de 25 tópicos Os tópicos devem começar com uma letra ou um número, podem incluir traços ('-') e podem ter até 35 caracteres.

run_proxy.go 10KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389
  1. package cli
  2. import (
  3. "context"
  4. "fmt"
  5. "net"
  6. "os"
  7. "strings"
  8. "github.com/9seconds/mtg/v2/antireplay"
  9. "github.com/9seconds/mtg/v2/events"
  10. "github.com/9seconds/mtg/v2/internal/config"
  11. "github.com/9seconds/mtg/v2/internal/proxyprotocol"
  12. "github.com/9seconds/mtg/v2/internal/utils"
  13. "github.com/9seconds/mtg/v2/ipblocklist"
  14. "github.com/9seconds/mtg/v2/ipblocklist/files"
  15. "github.com/9seconds/mtg/v2/logger"
  16. "github.com/9seconds/mtg/v2/mtglib"
  17. "github.com/9seconds/mtg/v2/network/v2"
  18. "github.com/9seconds/mtg/v2/stats"
  19. "github.com/pires/go-proxyproto"
  20. "github.com/rs/zerolog"
  21. "github.com/yl2chen/cidranger"
  22. )
  23. func makeLogger(conf *config.Config) mtglib.Logger {
  24. // An unset log time format keeps mtg's historical default
  25. // (Unix milliseconds), so the existing output does not change.
  26. logTimeFormat := config.TypeLogTimeFormat{
  27. Value: conf.LogTimeFormat.Get(config.TypeLogTimeFormatUnixMs),
  28. }
  29. zerolog.TimeFieldFormat = logTimeFormat.ZerologFormat()
  30. zerolog.TimestampFieldName = "timestamp"
  31. zerolog.LevelFieldName = "level"
  32. if conf.Debug.Get(false) {
  33. zerolog.SetGlobalLevel(zerolog.DebugLevel)
  34. } else {
  35. zerolog.SetGlobalLevel(zerolog.WarnLevel)
  36. }
  37. baseLogger := zerolog.New(os.Stdout).With().Timestamp().Logger()
  38. return logger.NewZeroLogger(baseLogger)
  39. }
  40. func makeNetwork(conf *config.Config, version string) (mtglib.Network, error) {
  41. resolver, err := network.GetDNS(conf.GetDNS())
  42. if err != nil {
  43. return nil, fmt.Errorf("cannot create DNS resolver: %w", err)
  44. }
  45. base := network.New(
  46. resolver,
  47. "",
  48. conf.Network.Timeout.TCP.Get(0),
  49. conf.Network.Timeout.HTTP.Get(0),
  50. conf.Network.Timeout.Idle.Get(0),
  51. net.KeepAliveConfig{
  52. Enable: !conf.Network.KeepAlive.Disabled.Get(false),
  53. Idle: conf.Network.KeepAlive.Idle.Get(0),
  54. Interval: conf.Network.KeepAlive.Interval.Get(0),
  55. Count: int(conf.Network.KeepAlive.Count.Get(0)),
  56. },
  57. int(conf.Network.TCPNotSentLowat.Get(network.DefaultTCPNotSentLowat)),
  58. )
  59. proxyDialers := make([]mtglib.Network, len(conf.Network.Proxies))
  60. for idx, v := range conf.Network.Proxies {
  61. value, err := network.NewProxyNetwork(base, v.Get(nil))
  62. if err != nil {
  63. return nil, fmt.Errorf("cannot use %v for proxy url: %w", v.Get(nil), err)
  64. }
  65. proxyDialers[idx] = value
  66. }
  67. switch len(proxyDialers) {
  68. case 0:
  69. return base, nil
  70. case 1:
  71. return proxyDialers[0], nil
  72. }
  73. value, err := network.Join(proxyDialers...)
  74. if err != nil {
  75. panic(err)
  76. }
  77. return value, nil
  78. }
  79. func makeAntiReplayCache(conf *config.Config) mtglib.AntiReplayCache {
  80. if !conf.Defense.AntiReplay.Enabled.Get(false) {
  81. return antireplay.NewNoop()
  82. }
  83. return antireplay.NewStableBloomFilter(
  84. conf.Defense.AntiReplay.MaxSize.Get(antireplay.DefaultStableBloomFilterMaxSize),
  85. conf.Defense.AntiReplay.ErrorRate.Get(antireplay.DefaultStableBloomFilterErrorRate),
  86. )
  87. }
  88. func makeIPBlocklist(conf config.ListConfig,
  89. logger mtglib.Logger,
  90. ntw mtglib.Network,
  91. updateCallback ipblocklist.FireholUpdateCallback,
  92. ) (mtglib.IPBlocklist, error) {
  93. if !conf.Enabled.Get(false) {
  94. return ipblocklist.NewNoop(), nil
  95. }
  96. remoteURLs := []string{}
  97. localFiles := []string{}
  98. for _, v := range conf.URLs {
  99. if v.IsRemote() {
  100. remoteURLs = append(remoteURLs, v.String())
  101. } else {
  102. localFiles = append(localFiles, v.String())
  103. }
  104. }
  105. blocklist, err := ipblocklist.NewFirehol(logger.Named("ipblockist"),
  106. ntw,
  107. conf.DownloadConcurrency.Get(1),
  108. remoteURLs,
  109. localFiles,
  110. updateCallback)
  111. if err != nil {
  112. return nil, fmt.Errorf("incorrect parameters for firehol: %w", err)
  113. }
  114. go blocklist.Run(conf.UpdateEach.Get(ipblocklist.DefaultFireholUpdateEach))
  115. return blocklist, nil
  116. }
  117. func makeIPAllowlist(conf config.ListConfig,
  118. logger mtglib.Logger,
  119. ntw mtglib.Network,
  120. updateCallback ipblocklist.FireholUpdateCallback,
  121. ) (mtglib.IPBlocklist, error) {
  122. var (
  123. allowlist mtglib.IPBlocklist
  124. err error
  125. )
  126. if !conf.Enabled.Get(false) {
  127. allowlist, err = ipblocklist.NewFireholFromFiles(
  128. logger.Named("ipblocklist"),
  129. 1,
  130. []files.File{
  131. files.NewMem([]*net.IPNet{
  132. cidranger.AllIPv4,
  133. cidranger.AllIPv6,
  134. }),
  135. },
  136. updateCallback,
  137. )
  138. go allowlist.Run(conf.UpdateEach.Get(ipblocklist.DefaultFireholUpdateEach))
  139. } else {
  140. allowlist, err = makeIPBlocklist(
  141. conf,
  142. logger,
  143. ntw,
  144. updateCallback,
  145. )
  146. }
  147. if err != nil {
  148. return nil, fmt.Errorf("cannot build allowlist: %w", err)
  149. }
  150. return allowlist, nil
  151. }
  152. func makeEventStream(conf *config.Config, logger mtglib.Logger) (mtglib.EventStream, error) {
  153. factories := make([]events.ObserverFactory, 0, 2)
  154. if conf.Stats.StatsD.Enabled.Get(false) {
  155. statsdFactory, err := stats.NewStatsd(
  156. conf.Stats.StatsD.Address.Get(""),
  157. logger.Named("statsd"),
  158. conf.Stats.StatsD.MetricPrefix.Get(stats.DefaultStatsdMetricPrefix),
  159. conf.Stats.StatsD.TagFormat.Get(stats.DefaultStatsdTagFormat))
  160. if err != nil {
  161. return nil, fmt.Errorf("cannot build statsd observer: %w", err)
  162. }
  163. factories = append(factories, statsdFactory.Make)
  164. }
  165. if conf.Stats.Prometheus.Enabled.Get(false) {
  166. prometheus := stats.NewPrometheus(
  167. conf.Stats.Prometheus.MetricPrefix.Get(stats.DefaultMetricPrefix),
  168. conf.Stats.Prometheus.HTTPPath.Get("/"),
  169. )
  170. listener, err := net.Listen("tcp", conf.Stats.Prometheus.BindTo.Get(""))
  171. if err != nil {
  172. return nil, fmt.Errorf("cannot start a listener for prometheus: %w", err)
  173. }
  174. go prometheus.Serve(listener) //nolint: errcheck
  175. factories = append(factories, prometheus.Make)
  176. }
  177. if len(factories) > 0 {
  178. return events.NewEventStream(factories), nil
  179. }
  180. return events.NewNoopStream(), nil
  181. }
  182. func warnSNIMismatch(conf *config.Config, ntw mtglib.Network, log mtglib.Logger) {
  183. host := conf.Secret.Host
  184. if host == "" {
  185. return
  186. }
  187. res := runSNICheck(context.Background(), net.DefaultResolver, conf, ntw)
  188. if res.ResolveErr != nil {
  189. log.BindStr("hostname", host).
  190. WarningError("SNI-DNS check: cannot resolve secret hostname", res.ResolveErr)
  191. return
  192. }
  193. if !res.PublicIPKnown() {
  194. log.Warning("SNI-DNS check: cannot detect public IP address; set public-ipv4/public-ipv6 in config or run 'mtg doctor'")
  195. return
  196. }
  197. v4Match := res.OurIPv4 == nil || res.IPv4Match
  198. v6Match := res.OurIPv6 == nil || res.IPv6Match
  199. if v4Match && v6Match {
  200. return
  201. }
  202. resolved := make([]string, 0, len(res.Resolved))
  203. for _, ip := range res.Resolved {
  204. resolved = append(resolved, ip.String())
  205. }
  206. our := ""
  207. if res.OurIPv4 != nil {
  208. our = res.OurIPv4.String()
  209. }
  210. if res.OurIPv6 != nil {
  211. if our != "" {
  212. our += "/"
  213. }
  214. our += res.OurIPv6.String()
  215. }
  216. entry := log.BindStr("hostname", host).
  217. BindStr("resolved", strings.Join(resolved, ", ")).
  218. BindStr("public_ip", our)
  219. if res.OurIPv4 != nil {
  220. entry = entry.BindStr("ipv4_match", fmt.Sprintf("%t", v4Match))
  221. }
  222. if res.OurIPv6 != nil {
  223. entry = entry.BindStr("ipv6_match", fmt.Sprintf("%t", v6Match))
  224. }
  225. entry.Warning("SNI-DNS mismatch: secret hostname does not resolve to this server's public IP. " +
  226. "DPI may detect and block the proxy. See 'mtg doctor' for details")
  227. }
  228. func warnDeprecatedDomainFronting(conf *config.Config, log mtglib.Logger) {
  229. if conf.DomainFrontingIP.Value != nil {
  230. log.Warning(`config option "domain-fronting-ip" is deprecated and ignored; use "host" in [domain-fronting] instead`)
  231. }
  232. if conf.DomainFronting.IP.Value != nil {
  233. log.Warning(`config option "ip" in [domain-fronting] is deprecated and ignored; use "host" instead`)
  234. }
  235. }
  236. func runProxy(conf *config.Config, version string) error { //nolint: funlen, cyclop
  237. logger := makeLogger(conf)
  238. logger.BindJSON("configuration", conf.String()).Debug("configuration")
  239. warnDeprecatedDomainFronting(conf, logger)
  240. eventStream, err := makeEventStream(conf, logger)
  241. if err != nil {
  242. return fmt.Errorf("cannot build event stream: %w", err)
  243. }
  244. ntw, err := makeNetwork(conf, version)
  245. if err != nil {
  246. return fmt.Errorf("cannot build network: %w", err)
  247. }
  248. warnSNIMismatch(conf, ntw, logger)
  249. blocklist, err := makeIPBlocklist(
  250. conf.Defense.Blocklist,
  251. logger.Named("blocklist"),
  252. ntw,
  253. func(ctx context.Context, size int) {
  254. eventStream.Send(ctx, mtglib.NewEventIPListSize(size, true))
  255. })
  256. if err != nil {
  257. return fmt.Errorf("cannot build ip blocklist: %w", err)
  258. }
  259. allowlist, err := makeIPAllowlist(
  260. conf.Defense.Allowlist,
  261. logger.Named("allowlist"),
  262. ntw,
  263. func(ctx context.Context, size int) {
  264. eventStream.Send(ctx, mtglib.NewEventIPListSize(size, false))
  265. },
  266. )
  267. if err != nil {
  268. return fmt.Errorf("cannot build ip allowlist: %w", err)
  269. }
  270. doppelGangerURLs := make([]string, len(conf.Defense.Doppelganger.URLs))
  271. for i, v := range conf.Defense.Doppelganger.URLs {
  272. doppelGangerURLs[i] = v.String()
  273. }
  274. opts := mtglib.ProxyOpts{
  275. Logger: logger,
  276. Network: ntw,
  277. AntiReplayCache: makeAntiReplayCache(conf),
  278. IPBlocklist: blocklist,
  279. IPAllowlist: allowlist,
  280. EventStream: eventStream,
  281. Secret: conf.Secret,
  282. Concurrency: conf.GetConcurrency(mtglib.DefaultConcurrency),
  283. DomainFrontingPort: conf.GetDomainFrontingPort(mtglib.DefaultDomainFrontingPort),
  284. DomainFrontingHost: conf.GetDomainFrontingHost(),
  285. DomainFrontingProxyProtocol: conf.GetDomainFrontingProxyProtocol(false),
  286. PreferIP: conf.PreferIP.Get(mtglib.DefaultPreferIP),
  287. AutoUpdate: conf.AutoUpdate.Get(false),
  288. AllowFallbackOnUnknownDC: conf.AllowFallbackOnUnknownDC.Get(false),
  289. TolerateTimeSkewness: conf.TolerateTimeSkewness.Value,
  290. IdleTimeout: conf.Network.Timeout.Idle.Get(mtglib.DefaultIdleTimeout),
  291. HandshakeTimeout: conf.Network.Timeout.Handshake.Get(mtglib.DefaultHandshakeTimeout),
  292. DoppelGangerURLs: doppelGangerURLs,
  293. DoppelGangerPerRaid: conf.Defense.Doppelganger.Repeats.Get(mtglib.DoppelGangerPerRaid),
  294. DoppelGangerEach: conf.Defense.Doppelganger.UpdateEach.Get(mtglib.DoppelGangerEach),
  295. DoppelGangerDRS: conf.Defense.Doppelganger.DRS.Get(false),
  296. }
  297. proxy, err := mtglib.NewProxy(opts)
  298. if err != nil {
  299. return fmt.Errorf("cannot create a proxy: %w", err)
  300. }
  301. listener, err := utils.NewListener(conf.BindTo.Get(""), 0)
  302. if err != nil {
  303. return fmt.Errorf("cannot start proxy: %w", err)
  304. }
  305. if conf.ProxyProtocolListener.Get(false) {
  306. listener = &proxyprotocol.ListenerAdapter{
  307. Listener: proxyproto.Listener{
  308. Listener: listener,
  309. },
  310. }
  311. }
  312. ctx := utils.RootContext()
  313. go proxy.Serve(listener) //nolint: errcheck
  314. <-ctx.Done()
  315. listener.Close() //nolint: errcheck
  316. proxy.Shutdown()
  317. return nil
  318. }