Clash.Meta/adapter/outbound/vless.go

569 lines
15 KiB
Go
Raw Normal View History

2021-11-17 15:00:32 +08:00
package outbound
import (
"context"
"crypto/tls"
2021-12-20 12:59:06 +08:00
"encoding/binary"
2021-11-17 15:00:32 +08:00
"errors"
"fmt"
2022-03-29 23:50:41 +08:00
"io"
2021-11-17 15:00:32 +08:00
"net"
"net/http"
"strconv"
2021-12-20 12:59:06 +08:00
"sync"
2021-11-17 15:00:32 +08:00
2022-11-11 09:19:28 +08:00
"github.com/Dreamacro/clash/common/convert"
2021-11-17 15:00:32 +08:00
"github.com/Dreamacro/clash/component/dialer"
"github.com/Dreamacro/clash/component/resolver"
2022-11-11 09:19:28 +08:00
tlsC "github.com/Dreamacro/clash/component/tls"
2021-11-17 15:00:32 +08:00
C "github.com/Dreamacro/clash/constant"
"github.com/Dreamacro/clash/transport/gun"
2022-11-11 09:19:28 +08:00
"github.com/Dreamacro/clash/transport/socks5"
2021-11-17 15:00:32 +08:00
"github.com/Dreamacro/clash/transport/vless"
"github.com/Dreamacro/clash/transport/vmess"
vmessSing "github.com/sagernet/sing-vmess"
"github.com/sagernet/sing-vmess/packetaddr"
M "github.com/sagernet/sing/common/metadata"
2021-11-17 15:00:32 +08:00
)
2021-12-20 12:59:06 +08:00
const (
// max packet length
2022-03-29 23:50:41 +08:00
maxLength = 1024 << 3
2021-12-20 12:59:06 +08:00
)
2021-11-17 15:00:32 +08:00
type Vless struct {
*Base
client *vless.Client
option *VlessOption
// for gun mux
gunTLSConfig *tls.Config
gunConfig *gun.Config
transport *gun.TransportWrap
2023-03-08 17:18:46 +08:00
realityConfig *tlsC.RealityConfig
2021-11-17 15:00:32 +08:00
}
type VlessOption struct {
BasicOption
Name string `proxy:"name"`
Server string `proxy:"server"`
Port int `proxy:"port"`
UUID string `proxy:"uuid"`
Flow string `proxy:"flow,omitempty"`
FlowShow bool `proxy:"flow-show,omitempty"`
TLS bool `proxy:"tls,omitempty"`
UDP bool `proxy:"udp,omitempty"`
PacketAddr bool `proxy:"packet-addr,omitempty"`
XUDP bool `proxy:"xudp,omitempty"`
PacketEncoding string `proxy:"packet-encoding,omitempty"`
Network string `proxy:"network,omitempty"`
2023-03-08 17:18:46 +08:00
RealityOpts RealityOptions `proxy:"reality-opts,omitempty"`
HTTPOpts HTTPOptions `proxy:"http-opts,omitempty"`
HTTP2Opts HTTP2Options `proxy:"h2-opts,omitempty"`
GrpcOpts GrpcOptions `proxy:"grpc-opts,omitempty"`
WSOpts WSOptions `proxy:"ws-opts,omitempty"`
WSPath string `proxy:"ws-path,omitempty"`
WSHeaders map[string]string `proxy:"ws-headers,omitempty"`
SkipCertVerify bool `proxy:"skip-cert-verify,omitempty"`
Fingerprint string `proxy:"fingerprint,omitempty"`
ServerName string `proxy:"servername,omitempty"`
ClientFingerprint string `proxy:"client-fingerprint,omitempty"`
2021-11-17 15:00:32 +08:00
}
func (v *Vless) StreamConn(c net.Conn, metadata *C.Metadata) (net.Conn, error) {
var err error
if tlsC.HaveGlobalFingerprint() && len(v.option.ClientFingerprint) == 0 {
v.option.ClientFingerprint = tlsC.GetGlobalFingerprint()
}
2021-11-17 15:00:32 +08:00
switch v.option.Network {
case "ws":
host, port, _ := net.SplitHostPort(v.addr)
wsOpts := &vmess.WebsocketConfig{
Host: host,
Port: port,
Path: v.option.WSOpts.Path,
MaxEarlyData: v.option.WSOpts.MaxEarlyData,
EarlyDataHeaderName: v.option.WSOpts.EarlyDataHeaderName,
ClientFingerprint: v.option.ClientFingerprint,
Headers: http.Header{},
2021-11-17 15:00:32 +08:00
}
if len(v.option.WSOpts.Headers) != 0 {
for key, value := range v.option.WSOpts.Headers {
wsOpts.Headers.Add(key, value)
2021-11-17 15:00:32 +08:00
}
}
if v.option.TLS {
wsOpts.TLS = true
2022-07-11 13:42:28 +08:00
tlsConfig := &tls.Config{
MinVersion: tls.VersionTLS12,
ServerName: host,
InsecureSkipVerify: v.option.SkipCertVerify,
NextProtos: []string{"http/1.1"},
2022-07-11 13:42:28 +08:00
}
if len(v.option.Fingerprint) == 0 {
wsOpts.TLSConfig = tlsC.GetGlobalTLSConfig(tlsConfig)
2022-07-11 13:42:28 +08:00
} else {
wsOpts.TLSConfig, err = tlsC.GetSpecifiedFingerprintTLSConfig(tlsConfig, v.option.Fingerprint)
if err != nil {
return nil, err
}
2022-07-11 13:42:28 +08:00
}
if v.option.ServerName != "" {
wsOpts.TLSConfig.ServerName = v.option.ServerName
} else if host := wsOpts.Headers.Get("Host"); host != "" {
wsOpts.TLSConfig.ServerName = host
}
2022-06-08 01:47:50 +08:00
} else {
if host := wsOpts.Headers.Get("Host"); host == "" {
wsOpts.Headers.Set("Host", convert.RandHost())
convert.SetUserAgent(wsOpts.Headers)
}
2021-11-17 15:00:32 +08:00
}
c, err = vmess.StreamWebsocketConn(c, wsOpts)
case "http":
// readability first, so just copy default TLS logic
c, err = v.streamTLSOrXTLSConn(c, false)
if err != nil {
return nil, err
}
host, _, _ := net.SplitHostPort(v.addr)
httpOpts := &vmess.HTTPConfig{
Host: host,
Method: v.option.HTTPOpts.Method,
Path: v.option.HTTPOpts.Path,
Headers: v.option.HTTPOpts.Headers,
}
c = vmess.StreamHTTPConn(c, httpOpts)
case "h2":
c, err = v.streamTLSOrXTLSConn(c, true)
if err != nil {
return nil, err
}
h2Opts := &vmess.H2Config{
Hosts: v.option.HTTP2Opts.Host,
Path: v.option.HTTP2Opts.Path,
}
c, err = vmess.StreamH2Conn(c, h2Opts)
case "grpc":
2023-03-10 10:01:05 +08:00
c, err = gun.StreamGunWithConn(c, v.gunTLSConfig, v.gunConfig, v.realityConfig)
2021-11-17 15:00:32 +08:00
default:
2022-03-29 07:18:09 +08:00
// default tcp network
2021-11-17 15:00:32 +08:00
// handle TLS And XTLS
c, err = v.streamTLSOrXTLSConn(c, false)
2021-11-17 15:00:32 +08:00
}
if err != nil {
return nil, err
}
return v.client.StreamConn(c, parseVlessAddr(metadata, v.option.XUDP))
2021-11-17 15:00:32 +08:00
}
func (v *Vless) streamTLSOrXTLSConn(conn net.Conn, isH2 bool) (net.Conn, error) {
host, _, _ := net.SplitHostPort(v.addr)
2023-02-25 13:12:19 +08:00
if v.isLegacyXTLSEnabled() && !isH2 {
2021-11-17 15:00:32 +08:00
xtlsOpts := vless.XTLSConfig{
Host: host,
SkipCertVerify: v.option.SkipCertVerify,
Fingerprint: v.option.Fingerprint,
2021-11-17 15:00:32 +08:00
}
if v.option.ServerName != "" {
xtlsOpts.Host = v.option.ServerName
}
return vless.StreamXTLSConn(conn, &xtlsOpts)
} else if v.option.TLS {
2021-11-17 15:00:32 +08:00
tlsOpts := vmess.TLSConfig{
Host: host,
SkipCertVerify: v.option.SkipCertVerify,
FingerPrint: v.option.Fingerprint,
ClientFingerprint: v.option.ClientFingerprint,
2023-03-08 17:18:46 +08:00
Reality: v.realityConfig,
2021-11-17 15:00:32 +08:00
}
if isH2 {
tlsOpts.NextProtos = []string{"h2"}
}
if v.option.ServerName != "" {
tlsOpts.Host = v.option.ServerName
}
return vmess.StreamTLSConn(conn, &tlsOpts)
}
return conn, nil
2021-11-17 15:00:32 +08:00
}
2023-02-25 13:12:19 +08:00
func (v *Vless) isLegacyXTLSEnabled() bool {
return v.client.Addons != nil && v.client.Addons.Flow != vless.XRV
2021-11-17 15:00:32 +08:00
}
// DialContext implements C.ProxyAdapter
func (v *Vless) DialContext(ctx context.Context, metadata *C.Metadata, opts ...dialer.Option) (_ C.Conn, err error) {
// gun transport
if v.transport != nil && len(opts) == 0 {
c, err := gun.StreamGunWithTransport(v.transport, v.gunConfig)
if err != nil {
return nil, err
}
defer func(c net.Conn) {
2022-12-13 13:20:40 +08:00
safeConnClose(c, err)
}(c)
2021-11-17 15:00:32 +08:00
c, err = v.client.StreamConn(c, parseVlessAddr(metadata, v.option.XUDP))
2021-11-17 15:00:32 +08:00
if err != nil {
return nil, err
}
return NewConn(c, v), nil
}
2022-12-20 00:11:02 +08:00
return v.DialContextWithDialer(ctx, dialer.NewDialer(v.Base.DialOptions(opts...)...), metadata)
2022-12-19 21:34:07 +08:00
}
2021-11-17 15:00:32 +08:00
2022-12-19 21:34:07 +08:00
// DialContextWithDialer implements C.ProxyAdapter
func (v *Vless) DialContextWithDialer(ctx context.Context, dialer C.Dialer, metadata *C.Metadata) (_ C.Conn, err error) {
c, err := dialer.DialContext(ctx, "tcp", v.addr)
2021-11-17 15:00:32 +08:00
if err != nil {
return nil, fmt.Errorf("%s connect error: %s", v.addr, err.Error())
}
tcpKeepAlive(c)
2022-12-16 22:15:44 +08:00
defer func(c net.Conn) {
2022-12-13 13:20:40 +08:00
safeConnClose(c, err)
2022-12-16 22:15:44 +08:00
}(c)
2021-11-17 15:00:32 +08:00
c, err = v.StreamConn(c, metadata)
if err != nil {
return nil, fmt.Errorf("%s connect error: %s", v.addr, err.Error())
}
2021-11-17 15:00:32 +08:00
return NewConn(c, v), err
}
// ListenPacketContext implements C.ProxyAdapter
func (v *Vless) ListenPacketContext(ctx context.Context, metadata *C.Metadata, opts ...dialer.Option) (_ C.PacketConn, err error) {
// vless use stream-oriented udp with a special address, so we need a net.UDPAddr
2021-11-17 15:00:32 +08:00
if !metadata.Resolved() {
ip, err := resolver.ResolveIP(ctx, metadata.Host)
2021-11-17 15:00:32 +08:00
if err != nil {
return nil, errors.New("can't resolve ip")
}
metadata.DstIP = ip
}
var c net.Conn
// gun transport
if v.transport != nil && len(opts) == 0 {
c, err = gun.StreamGunWithTransport(v.transport, v.gunConfig)
if err != nil {
return nil, err
}
defer func(c net.Conn) {
2022-12-13 13:20:40 +08:00
safeConnClose(c, err)
}(c)
2021-11-17 15:00:32 +08:00
if v.option.PacketAddr {
packetAddrMetadata := *metadata // make a copy
packetAddrMetadata.Host = packetaddr.SeqPacketMagicAddress
packetAddrMetadata.DstPort = "443"
c, err = v.client.StreamConn(c, parseVlessAddr(&packetAddrMetadata, false))
} else {
c, err = v.client.StreamConn(c, parseVlessAddr(metadata, v.option.XUDP))
}
2022-12-19 21:34:07 +08:00
2021-11-17 15:00:32 +08:00
if err != nil {
2022-12-19 21:34:07 +08:00
return nil, fmt.Errorf("new vless client error: %v", err)
2021-11-17 15:00:32 +08:00
}
2022-12-19 21:34:07 +08:00
return v.ListenPacketOnStreamConn(c, metadata)
2021-11-17 15:00:32 +08:00
}
2022-12-20 00:11:02 +08:00
return v.ListenPacketWithDialer(ctx, dialer.NewDialer(v.Base.DialOptions(opts...)...), metadata)
2022-12-19 21:34:07 +08:00
}
// ListenPacketWithDialer implements C.ProxyAdapter
func (v *Vless) ListenPacketWithDialer(ctx context.Context, dialer C.Dialer, metadata *C.Metadata) (_ C.PacketConn, err error) {
// vless use stream-oriented udp with a special address, so we need a net.UDPAddr
2022-12-19 21:34:07 +08:00
if !metadata.Resolved() {
ip, err := resolver.ResolveIP(ctx, metadata.Host)
if err != nil {
return nil, errors.New("can't resolve ip")
}
metadata.DstIP = ip
}
c, err := dialer.DialContext(ctx, "tcp", v.addr)
if err != nil {
return nil, fmt.Errorf("%s connect error: %s", v.addr, err.Error())
}
tcpKeepAlive(c)
defer func(c net.Conn) {
2022-12-19 21:34:07 +08:00
safeConnClose(c, err)
}(c)
2022-12-19 21:34:07 +08:00
if v.option.PacketAddr {
packetAddrMetadata := *metadata // make a copy
packetAddrMetadata.Host = packetaddr.SeqPacketMagicAddress
packetAddrMetadata.DstPort = "443"
c, err = v.StreamConn(c, &packetAddrMetadata)
} else {
c, err = v.StreamConn(c, metadata)
}
2021-11-17 15:00:32 +08:00
if err != nil {
return nil, fmt.Errorf("new vless client error: %v", err)
}
return v.ListenPacketOnStreamConn(c, metadata)
}
2022-12-19 21:34:07 +08:00
// SupportWithDialer implements C.ProxyAdapter
func (v *Vless) SupportWithDialer() bool {
return true
}
// ListenPacketOnStreamConn implements C.ProxyAdapter
func (v *Vless) ListenPacketOnStreamConn(c net.Conn, metadata *C.Metadata) (_ C.PacketConn, err error) {
if v.option.XUDP {
return newPacketConn(&threadSafePacketConn{
PacketConn: vmessSing.NewXUDPConn(c, M.ParseSocksaddr(metadata.RemoteAddress())),
}, v), nil
} else if v.option.PacketAddr {
return newPacketConn(&threadSafePacketConn{
PacketConn: packetaddr.NewConn(&vlessPacketConn{
Conn: c, rAddr: metadata.UDPAddr(),
}, M.ParseSocksaddr(metadata.RemoteAddress())),
}, v), nil
}
2021-11-17 15:00:32 +08:00
return newPacketConn(&vlessPacketConn{Conn: c, rAddr: metadata.UDPAddr()}, v), nil
}
// SupportUOT implements C.ProxyAdapter
func (v *Vless) SupportUOT() bool {
return true
}
func parseVlessAddr(metadata *C.Metadata, xudp bool) *vless.DstAddr {
2021-11-17 15:00:32 +08:00
var addrType byte
var addr []byte
2022-11-11 09:19:28 +08:00
switch metadata.AddrType() {
case socks5.AtypIPv4:
2022-04-21 18:56:33 +08:00
addrType = vless.AtypIPv4
2021-11-17 15:00:32 +08:00
addr = make([]byte, net.IPv4len)
2022-04-20 01:52:51 +08:00
copy(addr[:], metadata.DstIP.AsSlice())
2022-11-11 09:19:28 +08:00
case socks5.AtypIPv6:
2022-04-21 18:56:33 +08:00
addrType = vless.AtypIPv6
2021-11-17 15:00:32 +08:00
addr = make([]byte, net.IPv6len)
2022-04-20 01:52:51 +08:00
copy(addr[:], metadata.DstIP.AsSlice())
2022-11-11 09:19:28 +08:00
case socks5.AtypDomainName:
2022-04-21 18:56:33 +08:00
addrType = vless.AtypDomainName
2021-11-17 15:00:32 +08:00
addr = make([]byte, len(metadata.Host)+1)
addr[0] = byte(len(metadata.Host))
2022-04-21 18:56:33 +08:00
copy(addr[1:], metadata.Host)
2021-11-17 15:00:32 +08:00
}
2022-03-29 07:18:09 +08:00
port, _ := strconv.ParseUint(metadata.DstPort, 10, 16)
2021-11-17 15:00:32 +08:00
return &vless.DstAddr{
UDP: metadata.NetWork == C.UDP,
AddrType: addrType,
Addr: addr,
Port: uint16(port),
Mux: metadata.NetWork == C.UDP && xudp,
2021-11-17 15:00:32 +08:00
}
}
type vlessPacketConn struct {
net.Conn
rAddr net.Addr
2021-12-20 12:59:06 +08:00
remain int
mux sync.Mutex
cache [2]byte
2021-11-17 15:00:32 +08:00
}
func (c *vlessPacketConn) writePacket(payload []byte) (int, error) {
binary.BigEndian.PutUint16(c.cache[:], uint16(len(payload)))
if _, err := c.Conn.Write(c.cache[:]); err != nil {
return 0, err
2021-12-20 12:59:06 +08:00
}
return c.Conn.Write(payload)
2021-12-20 12:59:06 +08:00
}
func (c *vlessPacketConn) WriteTo(b []byte, addr net.Addr) (int, error) {
2022-03-29 23:50:41 +08:00
total := len(b)
if total == 0 {
return 0, nil
}
if total <= maxLength {
return c.writePacket(b)
2021-12-20 12:59:06 +08:00
}
offset := 0
2021-12-20 12:59:06 +08:00
for offset < total {
cursor := offset + maxLength
if cursor > total {
cursor = total
}
n, err := c.writePacket(b[offset:cursor])
2021-12-20 12:59:06 +08:00
if err != nil {
return offset + n, err
}
offset = cursor
2022-03-29 23:50:41 +08:00
if offset == total {
break
}
2021-12-20 12:59:06 +08:00
}
return total, nil
2021-11-17 15:00:32 +08:00
}
2021-12-20 12:59:06 +08:00
func (c *vlessPacketConn) ReadFrom(b []byte) (int, net.Addr, error) {
c.mux.Lock()
defer c.mux.Unlock()
if c.remain > 0 {
2022-03-29 23:50:41 +08:00
length := len(b)
2021-12-20 12:59:06 +08:00
if c.remain < length {
length = c.remain
}
n, err := c.Conn.Read(b[:length])
if err != nil {
return 0, c.rAddr, err
2021-12-20 12:59:06 +08:00
}
c.remain -= n
return n, c.rAddr, nil
}
if _, err := c.Conn.Read(b[:2]); err != nil {
return 0, c.rAddr, err
2021-12-20 12:59:06 +08:00
}
2022-03-29 23:50:41 +08:00
total := int(binary.BigEndian.Uint16(b[:2]))
if total == 0 {
return 0, c.rAddr, nil
2021-12-20 12:59:06 +08:00
}
2021-11-17 15:00:32 +08:00
2022-03-29 23:50:41 +08:00
length := len(b)
if length > total {
length = total
2021-11-17 19:09:01 +08:00
}
2021-11-17 15:00:32 +08:00
if _, err := io.ReadFull(c.Conn, b[:length]); err != nil {
return 0, c.rAddr, errors.New("read packet error")
2022-03-29 23:50:41 +08:00
}
c.remain = total - length
2022-02-23 01:00:27 +08:00
return length, c.rAddr, nil
2022-03-29 23:50:41 +08:00
}
func NewVless(option VlessOption) (*Vless, error) {
2021-11-17 15:00:32 +08:00
var addons *vless.Addons
if option.Network != "ws" && len(option.Flow) >= 16 {
option.Flow = option.Flow[:16]
switch option.Flow {
2023-02-25 13:12:19 +08:00
case vless.XRO, vless.XRD, vless.XRS, vless.XRV:
2021-11-17 15:00:32 +08:00
addons = &vless.Addons{
Flow: option.Flow,
}
default:
2022-03-29 23:50:41 +08:00
return nil, fmt.Errorf("unsupported xtls flow type: %s", option.Flow)
2021-11-17 15:00:32 +08:00
}
}
switch option.PacketEncoding {
case "packetaddr", "packet":
option.PacketAddr = true
2023-01-28 14:58:52 +08:00
option.XUDP = false
default: // https://github.com/XTLS/Xray-core/pull/1567#issuecomment-1407305458
if !option.PacketAddr {
option.XUDP = true
}
}
client, err := vless.NewClient(option.UUID, addons, option.FlowShow)
2021-11-17 15:00:32 +08:00
if err != nil {
return nil, err
}
v := &Vless{
Base: &Base{
2022-08-28 13:41:19 +08:00
name: option.Name,
addr: net.JoinHostPort(option.Server, strconv.Itoa(option.Port)),
tp: C.Vless,
udp: option.UDP,
xudp: option.XUDP,
2023-02-24 13:53:44 +08:00
tfo: option.TFO,
2022-08-28 13:41:19 +08:00
iface: option.Interface,
2023-01-09 23:15:17 +08:00
rmark: option.RoutingMark,
2022-08-28 13:41:19 +08:00
prefer: C.NewDNSPrefer(option.IPVersion),
2021-11-17 15:00:32 +08:00
},
client: client,
option: &option,
}
2023-03-10 10:01:05 +08:00
v.realityConfig, err = v.option.RealityOpts.Parse()
if err != nil {
return nil, err
}
2021-11-17 15:00:32 +08:00
switch option.Network {
case "h2":
if len(option.HTTP2Opts.Host) == 0 {
option.HTTP2Opts.Host = append(option.HTTP2Opts.Host, "www.example.com")
}
case "grpc":
dialFn := func(network, addr string) (net.Conn, error) {
c, err := dialer.DialContext(context.Background(), "tcp", v.addr, v.Base.DialOptions()...)
if err != nil {
return nil, fmt.Errorf("%s connect error: %s", v.addr, err.Error())
}
tcpKeepAlive(c)
return c, nil
}
gunConfig := &gun.Config{
ServiceName: v.option.GrpcOpts.GrpcServiceName,
Host: v.option.ServerName,
ClientFingerprint: v.option.ClientFingerprint,
2021-11-17 15:00:32 +08:00
}
tlsConfig := tlsC.GetGlobalTLSConfig(&tls.Config{
2021-11-17 15:00:32 +08:00
InsecureSkipVerify: v.option.SkipCertVerify,
ServerName: v.option.ServerName,
2022-07-10 20:44:24 +08:00
})
2021-11-17 15:00:32 +08:00
if v.option.ServerName == "" {
host, _, _ := net.SplitHostPort(v.addr)
tlsConfig.ServerName = host
gunConfig.Host = host
}
v.gunTLSConfig = tlsConfig
v.gunConfig = gunConfig
2023-03-10 10:01:05 +08:00
v.transport = gun.NewHTTP2Client(dialFn, tlsConfig, v.option.ClientFingerprint, v.realityConfig)
2021-11-17 15:00:32 +08:00
}
return v, nil
}