udp_aes.go 5.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192
  1. package shadowsocks2022
  2. import (
  3. "bytes"
  4. "crypto/cipher"
  5. "io"
  6. "github.com/v2fly/struc"
  7. "github.com/v2fly/v2ray-core/v5/common/buf"
  8. "github.com/v2fly/v2ray-core/v5/common/net"
  9. )
  10. type AESUDPClientPacketProcessor struct {
  11. requestSeparateHeaderBlockCipher cipher.Block
  12. responseSeparateHeaderBlockCipher cipher.Block
  13. mainPacketAEAD func([]byte) cipher.AEAD
  14. EIHGenerator func([]byte) ExtensibleIdentityHeaders
  15. }
  16. func NewAESUDPClientPacketProcessor(requestSeparateHeaderBlockCipher, responseSeparateHeaderBlockCipher cipher.Block, mainPacketAEAD func([]byte) cipher.AEAD, eih func([]byte) ExtensibleIdentityHeaders) *AESUDPClientPacketProcessor {
  17. return &AESUDPClientPacketProcessor{
  18. requestSeparateHeaderBlockCipher: requestSeparateHeaderBlockCipher,
  19. responseSeparateHeaderBlockCipher: responseSeparateHeaderBlockCipher,
  20. mainPacketAEAD: mainPacketAEAD,
  21. EIHGenerator: eih,
  22. }
  23. }
  24. type separateHeader struct {
  25. SessionID [8]byte
  26. PacketID uint64
  27. }
  28. type header struct {
  29. Type byte
  30. TimeStamp uint64
  31. PaddingLength uint16 `struc:"sizeof=Padding"`
  32. Padding []byte
  33. }
  34. type respHeader struct {
  35. Type byte
  36. TimeStamp uint64
  37. ClientSessionID [8]byte
  38. PaddingLength uint16 `struc:"sizeof=Padding"`
  39. Padding []byte
  40. }
  41. type cachedUDPState struct {
  42. sessionAEAD cipher.AEAD
  43. sessionRecvAEAD cipher.AEAD
  44. }
  45. func (p *AESUDPClientPacketProcessor) EncodeUDPRequest(request *UDPRequest, out *buf.Buffer,
  46. cache UDPClientPacketProcessorCachedStateContainer,
  47. ) error {
  48. separateHeaderStruct := separateHeader{PacketID: request.PacketID, SessionID: request.SessionID}
  49. separateHeaderBuffer := buf.New()
  50. defer separateHeaderBuffer.Release()
  51. {
  52. err := struc.Pack(separateHeaderBuffer, &separateHeaderStruct)
  53. if err != nil {
  54. return newError("failed to pack separateHeader").Base(err)
  55. }
  56. }
  57. separateHeaderBufferBytes := separateHeaderBuffer.Bytes()
  58. {
  59. encryptedDest := out.Extend(16)
  60. p.requestSeparateHeaderBlockCipher.Encrypt(encryptedDest, separateHeaderBufferBytes)
  61. }
  62. if p.EIHGenerator != nil {
  63. eih := p.EIHGenerator(separateHeaderBufferBytes[0:16])
  64. eihHeader := struct {
  65. EIH ExtensibleIdentityHeaders
  66. }{
  67. EIH: eih,
  68. }
  69. err := struc.Pack(out, &eihHeader)
  70. if err != nil {
  71. return newError("failed to pack eih").Base(err)
  72. }
  73. }
  74. headerStruct := header{
  75. Type: UDPHeaderTypeClientToServerStream,
  76. TimeStamp: request.TimeStamp,
  77. PaddingLength: 0,
  78. Padding: nil,
  79. }
  80. requestBodyBuffer := buf.New()
  81. {
  82. err := struc.Pack(requestBodyBuffer, &headerStruct)
  83. if err != nil {
  84. return newError("failed to header").Base(err)
  85. }
  86. }
  87. {
  88. err := addrParser.WriteAddressPort(requestBodyBuffer, request.Address, net.Port(request.Port))
  89. if err != nil {
  90. return newError("failed to write address port").Base(err)
  91. }
  92. }
  93. {
  94. _, err := io.Copy(requestBodyBuffer, bytes.NewReader(request.Payload.Bytes()))
  95. if err != nil {
  96. return newError("failed to copy payload").Base(err)
  97. }
  98. }
  99. {
  100. cacheKey := string(separateHeaderBufferBytes[0:8])
  101. receivedCacheInterface := cache.GetCachedState(cacheKey)
  102. cachedState := &cachedUDPState{}
  103. if receivedCacheInterface != nil {
  104. cachedState = receivedCacheInterface.(*cachedUDPState)
  105. }
  106. if cachedState.sessionAEAD == nil {
  107. cachedState.sessionAEAD = p.mainPacketAEAD(separateHeaderBufferBytes[0:8])
  108. cache.PutCachedState(cacheKey, cachedState)
  109. }
  110. mainPacketAEADMaterialized := cachedState.sessionAEAD
  111. encryptedDest := out.Extend(int32(mainPacketAEADMaterialized.Overhead()) + requestBodyBuffer.Len())
  112. mainPacketAEADMaterialized.Seal(encryptedDest[:0], separateHeaderBuffer.Bytes()[4:16], requestBodyBuffer.Bytes(), nil)
  113. }
  114. return nil
  115. }
  116. func (p *AESUDPClientPacketProcessor) DecodeUDPResp(input []byte, resp *UDPResponse,
  117. cache UDPClientPacketProcessorCachedStateContainer,
  118. ) error {
  119. separateHeaderBuffer := buf.New()
  120. defer separateHeaderBuffer.Release()
  121. {
  122. encryptedDest := separateHeaderBuffer.Extend(16)
  123. p.responseSeparateHeaderBlockCipher.Decrypt(encryptedDest, input)
  124. }
  125. separateHeaderStruct := separateHeader{}
  126. {
  127. err := struc.Unpack(separateHeaderBuffer, &separateHeaderStruct)
  128. if err != nil {
  129. return newError("failed to unpack separateHeader").Base(err)
  130. }
  131. }
  132. resp.PacketID = separateHeaderStruct.PacketID
  133. resp.SessionID = separateHeaderStruct.SessionID
  134. {
  135. cacheKey := string(separateHeaderBuffer.Bytes()[0:8])
  136. receivedCacheInterface := cache.GetCachedServerState(cacheKey)
  137. cachedState := &cachedUDPState{}
  138. if receivedCacheInterface != nil {
  139. cachedState = receivedCacheInterface.(*cachedUDPState)
  140. }
  141. if cachedState.sessionRecvAEAD == nil {
  142. cachedState.sessionRecvAEAD = p.mainPacketAEAD(separateHeaderBuffer.Bytes()[0:8])
  143. cache.PutCachedServerState(cacheKey, cachedState)
  144. }
  145. mainPacketAEADMaterialized := cachedState.sessionRecvAEAD
  146. decryptedDestBuffer := buf.New()
  147. decryptedDest := decryptedDestBuffer.Extend(int32(len(input)) - 16 - int32(mainPacketAEADMaterialized.Overhead()))
  148. _, err := mainPacketAEADMaterialized.Open(decryptedDest[:0], separateHeaderBuffer.Bytes()[4:16], input[16:], nil)
  149. if err != nil {
  150. return newError("failed to open main packet").Base(err)
  151. }
  152. decryptedDestReader := bytes.NewReader(decryptedDest)
  153. headerStruct := respHeader{}
  154. {
  155. err := struc.Unpack(decryptedDestReader, &headerStruct)
  156. if err != nil {
  157. return newError("failed to unpack header").Base(err)
  158. }
  159. }
  160. resp.TimeStamp = headerStruct.TimeStamp
  161. addressReaderBuf := buf.New()
  162. defer addressReaderBuf.Release()
  163. var port net.Port
  164. resp.Address, port, err = addrParser.ReadAddressPort(addressReaderBuf, decryptedDestReader)
  165. if err != nil {
  166. return newError("failed to read address port").Base(err)
  167. }
  168. resp.Port = int(port)
  169. readedLength := decryptedDestReader.Size() - int64(decryptedDestReader.Len())
  170. decryptedDestBuffer.Advance(int32(readedLength))
  171. resp.Payload = decryptedDestBuffer
  172. resp.ClientSessionID = headerStruct.ClientSessionID
  173. return nil
  174. }
  175. }