mihomo/adapter/outbound/shadowsocks.go

361 lines
11 KiB
Go
Raw Normal View History

2019-12-08 12:17:24 +08:00
package outbound
2018-06-10 22:50:03 +08:00
import (
"context"
"errors"
2018-06-10 22:50:03 +08:00
"fmt"
"net"
"strconv"
"time"
2018-06-10 22:50:03 +08:00
N "github.com/Dreamacro/clash/common/net"
2019-02-11 15:25:10 +08:00
"github.com/Dreamacro/clash/common/structure"
2020-02-09 17:02:48 +08:00
"github.com/Dreamacro/clash/component/dialer"
2018-06-10 22:50:03 +08:00
C "github.com/Dreamacro/clash/constant"
"github.com/Dreamacro/clash/transport/restls"
2021-05-13 22:18:49 +08:00
obfs "github.com/Dreamacro/clash/transport/simple-obfs"
shadowtls "github.com/Dreamacro/clash/transport/sing-shadowtls"
2021-05-13 22:18:49 +08:00
"github.com/Dreamacro/clash/transport/socks5"
v2rayObfs "github.com/Dreamacro/clash/transport/v2ray-plugin"
restlsC "github.com/3andne/restls-client-go"
shadowsocks "github.com/metacubex/sing-shadowsocks"
2022-12-05 11:03:28 +08:00
"github.com/metacubex/sing-shadowsocks/shadowimpl"
"github.com/sagernet/sing/common/bufio"
M "github.com/sagernet/sing/common/metadata"
2022-06-18 10:50:18 +08:00
"github.com/sagernet/sing/common/uot"
2018-06-10 22:50:03 +08:00
)
type ShadowSocks struct {
2018-12-22 23:56:42 +08:00
*Base
method shadowsocks.Method
2019-02-11 15:25:10 +08:00
2022-06-18 10:50:18 +08:00
option *ShadowSocksOption
2019-02-11 15:25:10 +08:00
// obfs
obfsMode string
obfsOption *simpleObfsOption
v2rayOption *v2rayObfs.Option
shadowTLSOption *shadowtls.ShadowTLSOption
restlsConfig *restlsC.Config
2018-06-10 22:50:03 +08:00
}
type ShadowSocksOption struct {
BasicOption
Name string `proxy:"name"`
Server string `proxy:"server"`
Port int `proxy:"port"`
Password string `proxy:"password"`
Cipher string `proxy:"cipher"`
UDP bool `proxy:"udp,omitempty"`
Plugin string `proxy:"plugin,omitempty"`
PluginOpts map[string]any `proxy:"plugin-opts,omitempty"`
UDPOverTCP bool `proxy:"udp-over-tcp,omitempty"`
2023-03-15 14:08:52 +08:00
UDPOverTCPVersion int `proxy:"udp-over-tcp-version,omitempty"`
ClientFingerprint string `proxy:"client-fingerprint,omitempty"`
}
2019-02-11 15:25:10 +08:00
type simpleObfsOption struct {
Mode string `obfs:"mode,omitempty"`
2019-02-11 15:25:10 +08:00
Host string `obfs:"host,omitempty"`
}
type v2rayObfsOption struct {
Mode string `obfs:"mode"`
Host string `obfs:"host,omitempty"`
Path string `obfs:"path,omitempty"`
TLS bool `obfs:"tls,omitempty"`
2022-07-11 13:42:28 +08:00
Fingerprint string `obfs:"fingerprint,omitempty"`
Headers map[string]string `obfs:"headers,omitempty"`
SkipCertVerify bool `obfs:"skip-cert-verify,omitempty"`
Mux bool `obfs:"mux,omitempty"`
2019-02-11 15:25:10 +08:00
}
type shadowTLSOption struct {
Password string `obfs:"password"`
Host string `obfs:"host"`
Fingerprint string `obfs:"fingerprint,omitempty"`
SkipCertVerify bool `obfs:"skip-cert-verify,omitempty"`
Version int `obfs:"version,omitempty"`
}
type restlsOption struct {
Password string `obfs:"password"`
Host string `obfs:"host"`
VersionHint string `obfs:"version-hint"`
RestlsScript string `obfs:"restls-script,omitempty"`
}
2021-04-29 11:23:14 +08:00
// StreamConn implements C.ProxyAdapter
func (ss *ShadowSocks) StreamConn(c net.Conn, metadata *C.Metadata) (net.Conn, error) {
2023-03-14 16:50:27 +08:00
// fix tls handshake not timeout
ctx, cancel := context.WithTimeout(context.Background(), C.DefaultTLSTimeout)
defer cancel()
return ss.StreamConnContext(ctx, c, metadata)
}
2023-03-14 16:50:27 +08:00
func (ss *ShadowSocks) StreamConnContext(ctx context.Context, c net.Conn, metadata *C.Metadata) (net.Conn, error) {
useEarly := false
2019-02-11 15:25:10 +08:00
switch ss.obfsMode {
case "tls":
2019-02-11 15:25:10 +08:00
c = obfs.NewTLSObfs(c, ss.obfsOption.Host)
case "http":
_, port, _ := net.SplitHostPort(ss.addr)
2019-02-11 15:25:10 +08:00
c = obfs.NewHTTPObfs(c, ss.obfsOption.Host, port)
case "websocket":
var err error
c, err = v2rayObfs.NewV2rayObfs(c, ss.v2rayOption)
2019-02-11 15:25:10 +08:00
if err != nil {
return nil, fmt.Errorf("%s connect error: %w", ss.addr, err)
2019-02-11 15:25:10 +08:00
}
2023-03-14 16:50:27 +08:00
case shadowtls.Mode:
var err error
c, err = shadowtls.NewShadowTLS(ctx, c, ss.shadowTLSOption)
if err != nil {
return nil, err
}
useEarly = true
case restls.Mode:
var err error
2023-03-14 16:50:27 +08:00
c, err = restls.NewRestls(ctx, c, ss.restlsConfig)
if err != nil {
return nil, fmt.Errorf("%s (restls) connect error: %w", ss.addr, err)
}
2023-03-14 16:50:27 +08:00
useEarly = true
}
2023-03-14 16:50:27 +08:00
useEarly = useEarly || N.NeedHandshake(c)
2022-06-18 16:38:44 +08:00
if metadata.NetWork == C.UDP && ss.option.UDPOverTCP {
2023-03-15 14:08:52 +08:00
var uotDestination M.Socksaddr
if ss.option.UDPOverTCPVersion == 1 {
uotDestination.Fqdn = uot.LegacyMagicAddress
} else {
uotDestination.Fqdn = uot.MagicAddress
}
2023-03-14 16:50:27 +08:00
if useEarly {
2023-03-15 14:08:52 +08:00
return ss.method.DialEarlyConn(c, uotDestination), nil
} else {
2023-03-15 14:08:52 +08:00
return ss.method.DialConn(c, uotDestination)
}
}
2023-03-14 16:50:27 +08:00
if useEarly {
return ss.method.DialEarlyConn(c, M.ParseSocksaddr(metadata.RemoteAddress())), nil
} else {
return ss.method.DialConn(c, M.ParseSocksaddr(metadata.RemoteAddress()))
2022-06-18 16:38:44 +08:00
}
}
2021-04-29 11:23:14 +08:00
// DialContext implements C.ProxyAdapter
func (ss *ShadowSocks) DialContext(ctx context.Context, metadata *C.Metadata, opts ...dialer.Option) (_ C.Conn, err error) {
2022-12-20 00:11:02 +08:00
return ss.DialContextWithDialer(ctx, dialer.NewDialer(ss.Base.DialOptions(opts...)...), metadata)
2022-12-19 21:34:07 +08:00
}
// DialContextWithDialer implements C.ProxyAdapter
func (ss *ShadowSocks) DialContextWithDialer(ctx context.Context, dialer C.Dialer, metadata *C.Metadata) (_ C.Conn, err error) {
c, err := dialer.DialContext(ctx, "tcp", ss.addr)
if err != nil {
return nil, fmt.Errorf("%s connect error: %w", ss.addr, err)
}
tcpKeepAlive(c)
2022-12-16 22:15:44 +08:00
defer func(c net.Conn) {
2022-12-13 13:20:40 +08:00
safeConnClose(c, err)
2022-12-16 22:15:44 +08:00
}(c)
2023-03-14 16:50:27 +08:00
c, err = ss.StreamConnContext(ctx, c, metadata)
return NewConn(c, ss), err
2018-06-10 22:50:03 +08:00
}
// ListenPacketContext implements C.ProxyAdapter
func (ss *ShadowSocks) ListenPacketContext(ctx context.Context, metadata *C.Metadata, opts ...dialer.Option) (C.PacketConn, error) {
2022-12-20 00:11:02 +08:00
return ss.ListenPacketWithDialer(ctx, dialer.NewDialer(ss.Base.DialOptions(opts...)...), metadata)
2022-12-19 21:34:07 +08:00
}
// ListenPacketWithDialer implements C.ProxyAdapter
func (ss *ShadowSocks) ListenPacketWithDialer(ctx context.Context, dialer C.Dialer, metadata *C.Metadata) (_ C.PacketConn, err error) {
2022-06-18 10:50:18 +08:00
if ss.option.UDPOverTCP {
2022-12-19 21:34:07 +08:00
tcpConn, err := ss.DialContextWithDialer(ctx, dialer, metadata)
2022-06-18 10:50:18 +08:00
if err != nil {
return nil, err
}
2023-03-15 14:08:52 +08:00
destination := M.ParseSocksaddr(metadata.RemoteAddress())
if ss.option.UDPOverTCPVersion == 1 {
return newPacketConn(uot.NewConn(tcpConn, false, destination), ss), nil
} else {
return newPacketConn(uot.NewLazyConn(tcpConn, uot.Request{Destination: destination}), ss), nil
}
2022-06-18 10:50:18 +08:00
}
addr, err := resolveUDPAddrWithPrefer(ctx, "udp", ss.addr, ss.prefer)
2019-04-23 23:29:36 +08:00
if err != nil {
2020-01-31 14:43:54 +08:00
return nil, err
2019-04-23 23:29:36 +08:00
}
2022-12-19 21:34:07 +08:00
pc, err := dialer.ListenPacket(ctx, "udp", "", addr.AddrPort())
2019-04-24 10:29:29 +08:00
if err != nil {
2020-01-31 14:43:54 +08:00
return nil, err
2019-04-24 10:29:29 +08:00
}
pc = ss.method.DialPacketConn(&bufio.BindPacketConn{PacketConn: pc, Addr: addr})
return newPacketConn(pc, ss), nil
2019-04-23 23:29:36 +08:00
}
2022-12-19 21:34:07 +08:00
// SupportWithDialer implements C.ProxyAdapter
func (ss *ShadowSocks) SupportWithDialer() bool {
return true
}
2022-06-18 16:38:44 +08:00
// ListenPacketOnStreamConn implements C.ProxyAdapter
func (ss *ShadowSocks) ListenPacketOnStreamConn(c net.Conn, metadata *C.Metadata) (_ C.PacketConn, err error) {
if ss.option.UDPOverTCP {
2023-03-15 14:08:52 +08:00
destination := M.ParseSocksaddr(metadata.RemoteAddress())
if ss.option.UDPOverTCPVersion == 1 {
return newPacketConn(uot.NewConn(c, false, destination), ss), nil
} else {
return newPacketConn(uot.NewLazyConn(c, uot.Request{Destination: destination}), ss), nil
}
2022-06-18 16:38:44 +08:00
}
return nil, errors.New("no support")
}
// SupportUOT implements C.ProxyAdapter
func (ss *ShadowSocks) SupportUOT() bool {
return ss.option.UDPOverTCP
}
func NewShadowSocks(option ShadowSocksOption) (*ShadowSocks, error) {
addr := net.JoinHostPort(option.Server, strconv.Itoa(option.Port))
method, err := shadowimpl.FetchMethod(option.Cipher, option.Password, time.Now)
if err != nil {
return nil, fmt.Errorf("ss %s initialize error: %w", addr, err)
2018-06-10 22:50:03 +08:00
}
var v2rayOption *v2rayObfs.Option
2019-02-11 15:25:10 +08:00
var obfsOption *simpleObfsOption
var shadowTLSOpt *shadowtls.ShadowTLSOption
var restlsConfig *restlsC.Config
2019-02-11 15:25:10 +08:00
obfsMode := ""
decoder := structure.NewDecoder(structure.Option{TagName: "obfs", WeaklyTypedInput: true})
if option.Plugin == "obfs" {
opts := simpleObfsOption{Host: "bing.com"}
if err := decoder.Decode(option.PluginOpts, &opts); err != nil {
return nil, fmt.Errorf("ss %s initialize obfs error: %w", addr, err)
2019-02-11 15:25:10 +08:00
}
2019-06-18 20:37:53 +08:00
if opts.Mode != "tls" && opts.Mode != "http" {
return nil, fmt.Errorf("ss %s obfs mode error: %s", addr, opts.Mode)
2019-06-18 20:37:53 +08:00
}
2019-02-11 15:25:10 +08:00
obfsMode = opts.Mode
obfsOption = &opts
} else if option.Plugin == "v2ray-plugin" {
opts := v2rayObfsOption{Host: "bing.com", Mux: true}
2019-02-11 15:25:10 +08:00
if err := decoder.Decode(option.PluginOpts, &opts); err != nil {
return nil, fmt.Errorf("ss %s initialize v2ray-plugin error: %w", addr, err)
2019-02-11 15:25:10 +08:00
}
2019-06-18 20:37:53 +08:00
if opts.Mode != "websocket" {
return nil, fmt.Errorf("ss %s obfs mode error: %s", addr, opts.Mode)
2019-06-18 20:37:53 +08:00
}
2019-02-11 15:25:10 +08:00
obfsMode = opts.Mode
v2rayOption = &v2rayObfs.Option{
Host: opts.Host,
Path: opts.Path,
Headers: opts.Headers,
Mux: opts.Mux,
}
2019-06-18 20:37:53 +08:00
2019-02-11 15:25:10 +08:00
if opts.TLS {
v2rayOption.TLS = true
v2rayOption.SkipCertVerify = opts.SkipCertVerify
2019-02-11 15:25:10 +08:00
}
} else if option.Plugin == shadowtls.Mode {
obfsMode = shadowtls.Mode
opt := &shadowTLSOption{
Version: 2,
}
if err := decoder.Decode(option.PluginOpts, opt); err != nil {
return nil, fmt.Errorf("ss %s initialize shadow-tls-plugin error: %w", addr, err)
}
shadowTLSOpt = &shadowtls.ShadowTLSOption{
Password: opt.Password,
Host: opt.Host,
Fingerprint: opt.Fingerprint,
ClientFingerprint: option.ClientFingerprint,
SkipCertVerify: opt.SkipCertVerify,
Version: opt.Version,
}
} else if option.Plugin == restls.Mode {
obfsMode = restls.Mode
restlsOpt := &restlsOption{}
if err := decoder.Decode(option.PluginOpts, restlsOpt); err != nil {
return nil, fmt.Errorf("ss %s initialize restls-plugin error: %w", addr, err)
}
restlsConfig, err = restlsC.NewRestlsConfig(restlsOpt.Host, restlsOpt.Password, restlsOpt.VersionHint, restlsOpt.RestlsScript, option.ClientFingerprint)
restlsConfig.SessionTicketsDisabled = true
if err != nil {
return nil, fmt.Errorf("ss %s initialize restls-plugin error: %w", addr, err)
}
}
2023-03-15 14:08:52 +08:00
switch option.UDPOverTCPVersion {
case uot.Version, uot.LegacyVersion:
case 0:
option.UDPOverTCPVersion = uot.Version
default:
return nil, fmt.Errorf("ss %s unknown udp over tcp protocol version: %d", addr, option.UDPOverTCPVersion)
}
return &ShadowSocks{
2018-12-22 23:56:42 +08:00
Base: &Base{
2022-08-28 13:41:19 +08:00
name: option.Name,
addr: addr,
tp: C.Shadowsocks,
udp: option.UDP,
2023-02-24 13:53:44 +08:00
tfo: option.TFO,
2022-08-28 13:41:19 +08:00
iface: option.Interface,
rmark: option.RoutingMark,
prefer: C.NewDNSPrefer(option.IPVersion),
2018-12-22 23:56:42 +08:00
},
method: method,
2019-02-11 15:25:10 +08:00
option: &option,
obfsMode: obfsMode,
v2rayOption: v2rayOption,
obfsOption: obfsOption,
shadowTLSOption: shadowTLSOpt,
restlsConfig: restlsConfig,
}, nil
2018-06-10 22:50:03 +08:00
}
2020-02-17 17:34:19 +08:00
type ssPacketConn struct {
2019-04-23 23:29:36 +08:00
net.PacketConn
2020-01-31 14:43:54 +08:00
rAddr net.Addr
2019-04-23 23:29:36 +08:00
}
2020-02-17 17:34:19 +08:00
func (spc *ssPacketConn) WriteTo(b []byte, addr net.Addr) (n int, err error) {
2020-01-31 14:43:54 +08:00
packet, err := socks5.EncodeUDPPacket(socks5.ParseAddrToSocksAddr(addr), b)
2019-10-11 20:11:18 +08:00
if err != nil {
return
}
2020-02-17 17:34:19 +08:00
return spc.PacketConn.WriteTo(packet[3:], spc.rAddr)
2019-04-23 23:29:36 +08:00
}
2020-02-17 17:34:19 +08:00
func (spc *ssPacketConn) ReadFrom(b []byte) (int, net.Addr, error) {
n, _, e := spc.PacketConn.ReadFrom(b)
2020-02-18 16:05:12 +08:00
if e != nil {
return 0, nil, e
}
2020-02-18 16:05:12 +08:00
addr := socks5.SplitAddr(b[:n])
if addr == nil {
return 0, nil, errors.New("parse addr error")
}
2020-03-02 23:47:23 +08:00
udpAddr := addr.UDPAddr()
if udpAddr == nil {
return 0, nil, errors.New("parse addr error")
}
2019-04-23 23:29:36 +08:00
copy(b, b[len(addr):])
2020-03-02 23:47:23 +08:00
return n - len(addr), udpAddr, e
2019-04-23 23:29:36 +08:00
}