2022-04-09 22:30:36 +08:00
|
|
|
package sniffer
|
|
|
|
|
|
|
|
import (
|
|
|
|
"errors"
|
2022-10-11 21:35:26 +08:00
|
|
|
"fmt"
|
2022-04-09 22:30:36 +08:00
|
|
|
"net"
|
2022-05-02 22:24:14 +08:00
|
|
|
"net/netip"
|
2022-10-11 21:35:26 +08:00
|
|
|
"sync"
|
2022-04-21 23:08:37 +08:00
|
|
|
"time"
|
2022-04-21 22:06:08 +08:00
|
|
|
|
2023-11-03 21:01:45 +08:00
|
|
|
"github.com/metacubex/mihomo/common/cache"
|
|
|
|
N "github.com/metacubex/mihomo/common/net"
|
|
|
|
"github.com/metacubex/mihomo/component/trie"
|
|
|
|
C "github.com/metacubex/mihomo/constant"
|
|
|
|
"github.com/metacubex/mihomo/constant/sniffer"
|
|
|
|
"github.com/metacubex/mihomo/log"
|
2022-04-09 22:30:36 +08:00
|
|
|
)
|
|
|
|
|
|
|
|
var (
|
|
|
|
ErrorUnsupportedSniffer = errors.New("unsupported sniffer")
|
2022-04-16 08:21:31 +08:00
|
|
|
ErrorSniffFailed = errors.New("all sniffer failed")
|
2022-05-02 05:17:13 +08:00
|
|
|
ErrNoClue = errors.New("not enough information for making a decision")
|
2022-04-09 22:30:36 +08:00
|
|
|
)
|
|
|
|
|
2022-10-14 07:46:33 +08:00
|
|
|
var Dispatcher *SnifferDispatcher
|
2022-04-09 22:30:36 +08:00
|
|
|
|
2022-10-14 07:46:33 +08:00
|
|
|
type SnifferDispatcher struct {
|
2023-08-09 13:51:02 +08:00
|
|
|
enable bool
|
|
|
|
sniffers map[sniffer.Sniffer]SnifferConfig
|
|
|
|
forceDomain *trie.DomainSet
|
|
|
|
skipSNI *trie.DomainSet
|
|
|
|
skipList *cache.LruCache[string, uint8]
|
|
|
|
rwMux sync.RWMutex
|
|
|
|
forceDnsMapping bool
|
|
|
|
parsePureIp bool
|
2022-10-14 07:46:33 +08:00
|
|
|
}
|
2022-04-16 08:21:31 +08:00
|
|
|
|
2023-10-19 18:30:20 +08:00
|
|
|
func (sd *SnifferDispatcher) shouldOverride(metadata *C.Metadata) bool {
|
|
|
|
return (metadata.Host == "" && sd.parsePureIp) ||
|
|
|
|
sd.forceDomain.Has(metadata.Host) ||
|
|
|
|
(metadata.DNSMode == C.DNSMapping && sd.forceDnsMapping)
|
|
|
|
}
|
|
|
|
|
|
|
|
func (sd *SnifferDispatcher) UDPSniff(packet C.PacketAdapter) bool {
|
|
|
|
metadata := packet.Metadata()
|
|
|
|
|
|
|
|
if sd.shouldOverride(packet.Metadata()) {
|
|
|
|
for sniffer, config := range sd.sniffers {
|
|
|
|
if sniffer.SupportNetwork() == C.UDP || sniffer.SupportNetwork() == C.ALLNet {
|
|
|
|
inWhitelist := sniffer.SupportPort(metadata.DstPort)
|
|
|
|
overrideDest := config.OverrideDest
|
|
|
|
|
|
|
|
if inWhitelist {
|
2023-10-19 23:51:37 +08:00
|
|
|
host, err := sniffer.SniffData(packet.Data())
|
2023-10-19 18:30:20 +08:00
|
|
|
if err != nil {
|
|
|
|
continue
|
|
|
|
}
|
|
|
|
|
|
|
|
sd.replaceDomain(metadata, host, overrideDest)
|
|
|
|
return true
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
return false
|
|
|
|
}
|
|
|
|
|
2023-09-24 19:27:55 +08:00
|
|
|
// TCPSniff returns true if the connection is sniffed to have a domain
|
|
|
|
func (sd *SnifferDispatcher) TCPSniff(conn *N.BufferedConn, metadata *C.Metadata) bool {
|
2023-10-19 18:30:20 +08:00
|
|
|
if sd.shouldOverride(metadata) {
|
2022-04-23 09:52:23 +08:00
|
|
|
inWhitelist := false
|
2023-01-23 14:08:11 +08:00
|
|
|
overrideDest := false
|
|
|
|
for sniffer, config := range sd.sniffers {
|
2023-01-23 13:16:25 +08:00
|
|
|
if sniffer.SupportNetwork() == C.TCP || sniffer.SupportNetwork() == C.ALLNet {
|
2023-08-09 13:51:02 +08:00
|
|
|
inWhitelist = sniffer.SupportPort(metadata.DstPort)
|
2023-01-23 13:16:25 +08:00
|
|
|
if inWhitelist {
|
2023-01-23 14:08:11 +08:00
|
|
|
overrideDest = config.OverrideDest
|
2023-01-23 13:16:25 +08:00
|
|
|
break
|
|
|
|
}
|
2022-04-21 22:06:08 +08:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2022-04-23 09:52:23 +08:00
|
|
|
if !inWhitelist {
|
2023-09-24 19:27:55 +08:00
|
|
|
return false
|
2022-04-23 09:52:23 +08:00
|
|
|
}
|
|
|
|
|
2022-10-11 21:35:26 +08:00
|
|
|
sd.rwMux.RLock()
|
2023-08-09 13:51:02 +08:00
|
|
|
dst := fmt.Sprintf("%s:%d", metadata.DstIP, metadata.DstPort)
|
2022-10-11 21:35:26 +08:00
|
|
|
if count, ok := sd.skipList.Get(dst); ok && count > 5 {
|
|
|
|
log.Debugln("[Sniffer] Skip sniffing[%s] due to multiple failures", dst)
|
|
|
|
defer sd.rwMux.RUnlock()
|
2023-09-24 19:27:55 +08:00
|
|
|
return false
|
2022-10-11 21:35:26 +08:00
|
|
|
}
|
|
|
|
sd.rwMux.RUnlock()
|
|
|
|
|
2023-02-24 09:54:54 +08:00
|
|
|
if host, err := sd.sniffDomain(conn, metadata); err != nil {
|
2022-10-11 21:35:26 +08:00
|
|
|
sd.cacheSniffFailed(metadata)
|
2023-08-09 13:51:02 +08:00
|
|
|
log.Debugln("[Sniffer] All sniffing sniff failed with from [%s:%d] to [%s:%d]", metadata.SrcIP, metadata.SrcPort, metadata.String(), metadata.DstPort)
|
2023-09-24 19:27:55 +08:00
|
|
|
return false
|
2022-04-17 20:02:13 +08:00
|
|
|
} else {
|
2023-04-01 11:53:39 +08:00
|
|
|
if sd.skipSNI.Has(host) {
|
2022-04-17 20:02:13 +08:00
|
|
|
log.Debugln("[Sniffer] Skip sni[%s]", host)
|
2023-09-24 19:27:55 +08:00
|
|
|
return false
|
2022-04-17 20:02:13 +08:00
|
|
|
}
|
2022-04-16 08:21:31 +08:00
|
|
|
|
2022-10-11 21:35:26 +08:00
|
|
|
sd.rwMux.RLock()
|
|
|
|
sd.skipList.Delete(dst)
|
|
|
|
sd.rwMux.RUnlock()
|
|
|
|
|
2023-01-23 14:08:11 +08:00
|
|
|
sd.replaceDomain(metadata, host, overrideDest)
|
2023-09-24 19:27:55 +08:00
|
|
|
return true
|
2022-04-17 20:02:13 +08:00
|
|
|
}
|
|
|
|
}
|
2023-09-24 19:27:55 +08:00
|
|
|
return false
|
2022-04-16 08:21:31 +08:00
|
|
|
}
|
|
|
|
|
2023-01-23 14:08:11 +08:00
|
|
|
func (sd *SnifferDispatcher) replaceDomain(metadata *C.Metadata, host string, overrideDest bool) {
|
2023-09-24 19:27:55 +08:00
|
|
|
// show log early, since the following code may mutate `metadata.Host`
|
2023-10-20 22:36:29 +08:00
|
|
|
log.Debugln("[Sniffer] Sniff %s [%s]-->[%s] success, replace domain [%s]-->[%s]",
|
|
|
|
metadata.NetWork,
|
2023-09-24 19:27:55 +08:00
|
|
|
metadata.SourceDetail(),
|
|
|
|
metadata.RemoteAddress(),
|
|
|
|
metadata.Host, host)
|
2023-02-10 13:01:53 +08:00
|
|
|
metadata.SniffHost = host
|
|
|
|
if overrideDest {
|
|
|
|
metadata.Host = host
|
2023-01-23 14:08:11 +08:00
|
|
|
}
|
2023-02-10 13:01:53 +08:00
|
|
|
metadata.DNSMode = C.DNSNormal
|
2022-04-09 22:30:36 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
func (sd *SnifferDispatcher) Enable() bool {
|
|
|
|
return sd.enable
|
|
|
|
}
|
|
|
|
|
2022-10-14 07:46:33 +08:00
|
|
|
func (sd *SnifferDispatcher) sniffDomain(conn *N.BufferedConn, metadata *C.Metadata) (string, error) {
|
2023-01-23 14:08:11 +08:00
|
|
|
for s := range sd.sniffers {
|
2022-10-11 21:35:26 +08:00
|
|
|
if s.SupportNetwork() == C.TCP {
|
|
|
|
_ = conn.SetReadDeadline(time.Now().Add(1 * time.Second))
|
2022-04-10 20:01:35 +08:00
|
|
|
_, err := conn.Peek(1)
|
2022-05-02 22:24:14 +08:00
|
|
|
_ = conn.SetReadDeadline(time.Time{})
|
2022-04-10 20:01:35 +08:00
|
|
|
if err != nil {
|
2022-04-21 23:08:37 +08:00
|
|
|
_, ok := err.(*net.OpError)
|
2022-05-08 09:09:39 +08:00
|
|
|
if ok {
|
2022-10-11 21:35:26 +08:00
|
|
|
sd.cacheSniffFailed(metadata)
|
2022-05-07 12:44:28 +08:00
|
|
|
log.Errorln("[Sniffer] [%s] may not have any sent data, Consider adding skip", metadata.DstIP.String())
|
2022-05-02 22:24:14 +08:00
|
|
|
_ = conn.Close()
|
2022-04-21 23:08:37 +08:00
|
|
|
}
|
2022-05-07 12:44:28 +08:00
|
|
|
|
2022-05-08 09:09:39 +08:00
|
|
|
return "", err
|
2022-04-10 20:01:35 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
bufferedLen := conn.Buffered()
|
|
|
|
bytes, err := conn.Peek(bufferedLen)
|
2022-04-09 22:30:36 +08:00
|
|
|
if err != nil {
|
2022-04-27 18:04:02 +08:00
|
|
|
log.Debugln("[Sniffer] the data length not enough")
|
2022-04-09 22:30:36 +08:00
|
|
|
continue
|
|
|
|
}
|
|
|
|
|
2023-10-19 18:30:20 +08:00
|
|
|
host, err := s.SniffData(bytes)
|
2022-04-09 22:30:36 +08:00
|
|
|
if err != nil {
|
2022-10-11 21:35:26 +08:00
|
|
|
//log.Debugln("[Sniffer] [%s] Sniff data failed %s", s.Protocol(), metadata.DstIP)
|
2022-04-09 22:30:36 +08:00
|
|
|
continue
|
|
|
|
}
|
2022-04-10 20:01:35 +08:00
|
|
|
|
2022-05-02 22:24:14 +08:00
|
|
|
_, err = netip.ParseAddr(host)
|
|
|
|
if err == nil {
|
2022-10-11 21:35:26 +08:00
|
|
|
//log.Debugln("[Sniffer] [%s] Sniff data failed %s", s.Protocol(), metadata.DstIP)
|
2022-05-02 22:24:14 +08:00
|
|
|
continue
|
|
|
|
}
|
|
|
|
|
2022-04-16 08:21:31 +08:00
|
|
|
return host, nil
|
2022-04-09 22:30:36 +08:00
|
|
|
}
|
|
|
|
}
|
2022-04-16 08:21:31 +08:00
|
|
|
|
|
|
|
return "", ErrorSniffFailed
|
2022-04-09 22:30:36 +08:00
|
|
|
}
|
|
|
|
|
2022-10-11 21:35:26 +08:00
|
|
|
func (sd *SnifferDispatcher) cacheSniffFailed(metadata *C.Metadata) {
|
|
|
|
sd.rwMux.Lock()
|
2023-08-09 13:51:02 +08:00
|
|
|
dst := fmt.Sprintf("%s:%d", metadata.DstIP, metadata.DstPort)
|
2022-10-11 21:35:26 +08:00
|
|
|
count, _ := sd.skipList.Get(dst)
|
|
|
|
if count <= 5 {
|
|
|
|
count++
|
|
|
|
}
|
|
|
|
sd.skipList.Set(dst, count)
|
|
|
|
sd.rwMux.Unlock()
|
|
|
|
}
|
|
|
|
|
2022-04-16 08:21:31 +08:00
|
|
|
func NewCloseSnifferDispatcher() (*SnifferDispatcher, error) {
|
2022-04-09 22:30:36 +08:00
|
|
|
dispatcher := SnifferDispatcher{
|
2022-04-16 08:21:31 +08:00
|
|
|
enable: false,
|
|
|
|
}
|
|
|
|
|
|
|
|
return &dispatcher, nil
|
|
|
|
}
|
|
|
|
|
2023-04-01 11:53:39 +08:00
|
|
|
func NewSnifferDispatcher(snifferConfig map[sniffer.Type]SnifferConfig,
|
|
|
|
forceDomain *trie.DomainSet, skipSNI *trie.DomainSet,
|
2022-10-14 08:42:28 +08:00
|
|
|
forceDnsMapping bool, parsePureIp bool) (*SnifferDispatcher, error) {
|
2022-04-16 08:21:31 +08:00
|
|
|
dispatcher := SnifferDispatcher{
|
2022-10-14 07:46:33 +08:00
|
|
|
enable: true,
|
|
|
|
forceDomain: forceDomain,
|
|
|
|
skipSNI: skipSNI,
|
2023-01-23 14:08:11 +08:00
|
|
|
skipList: cache.New(cache.WithSize[string, uint8](128), cache.WithAge[string, uint8](600)),
|
2022-10-14 07:46:33 +08:00
|
|
|
forceDnsMapping: forceDnsMapping,
|
2022-10-14 08:42:28 +08:00
|
|
|
parsePureIp: parsePureIp,
|
2023-01-23 14:08:11 +08:00
|
|
|
sniffers: make(map[sniffer.Sniffer]SnifferConfig, 0),
|
2022-04-09 22:30:36 +08:00
|
|
|
}
|
|
|
|
|
2023-01-23 13:16:25 +08:00
|
|
|
for snifferName, config := range snifferConfig {
|
|
|
|
s, err := NewSniffer(snifferName, config)
|
2022-04-09 22:30:36 +08:00
|
|
|
if err != nil {
|
2022-04-27 18:04:02 +08:00
|
|
|
log.Errorln("Sniffer name[%s] is error", snifferName)
|
2022-04-16 08:21:31 +08:00
|
|
|
return &SnifferDispatcher{enable: false}, err
|
2022-04-09 22:30:36 +08:00
|
|
|
}
|
2023-01-23 14:08:11 +08:00
|
|
|
dispatcher.sniffers[s] = config
|
2022-04-09 22:30:36 +08:00
|
|
|
}
|
|
|
|
|
2022-04-16 08:21:31 +08:00
|
|
|
return &dispatcher, nil
|
2022-04-09 22:30:36 +08:00
|
|
|
}
|
|
|
|
|
2023-01-23 13:16:25 +08:00
|
|
|
func NewSniffer(name sniffer.Type, snifferConfig SnifferConfig) (sniffer.Sniffer, error) {
|
2022-04-09 22:30:36 +08:00
|
|
|
switch name {
|
2022-05-02 08:46:24 +08:00
|
|
|
case sniffer.TLS:
|
2023-01-23 13:16:25 +08:00
|
|
|
return NewTLSSniffer(snifferConfig)
|
2022-05-02 08:46:24 +08:00
|
|
|
case sniffer.HTTP:
|
2023-01-23 13:16:25 +08:00
|
|
|
return NewHTTPSniffer(snifferConfig)
|
2023-10-19 18:30:20 +08:00
|
|
|
case sniffer.QUIC:
|
|
|
|
return NewQuicSniffer(snifferConfig)
|
2022-04-09 22:30:36 +08:00
|
|
|
default:
|
|
|
|
return nil, ErrorUnsupportedSniffer
|
|
|
|
}
|
|
|
|
}
|