inbound.go 7.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292
  1. package inbound
  2. import (
  3. "io"
  4. "sync"
  5. "v2ray.com/core/app"
  6. "v2ray.com/core/app/dispatcher"
  7. "v2ray.com/core/app/proxyman"
  8. "v2ray.com/core/common"
  9. "v2ray.com/core/common/alloc"
  10. "v2ray.com/core/common/crypto"
  11. "v2ray.com/core/common/errors"
  12. v2io "v2ray.com/core/common/io"
  13. "v2ray.com/core/common/loader"
  14. "v2ray.com/core/common/log"
  15. v2net "v2ray.com/core/common/net"
  16. "v2ray.com/core/common/protocol"
  17. "v2ray.com/core/common/uuid"
  18. "v2ray.com/core/proxy"
  19. "v2ray.com/core/proxy/registry"
  20. "v2ray.com/core/proxy/vmess"
  21. "v2ray.com/core/proxy/vmess/encoding"
  22. vmessio "v2ray.com/core/proxy/vmess/io"
  23. "v2ray.com/core/transport/internet"
  24. )
  25. type userByEmail struct {
  26. sync.RWMutex
  27. cache map[string]*protocol.User
  28. defaultLevel uint32
  29. defaultAlterIDs uint16
  30. }
  31. func NewUserByEmail(users []*protocol.User, config *DefaultConfig) *userByEmail {
  32. cache := make(map[string]*protocol.User)
  33. for _, user := range users {
  34. cache[user.Email] = user
  35. }
  36. return &userByEmail{
  37. cache: cache,
  38. defaultLevel: config.Level,
  39. defaultAlterIDs: uint16(config.AlterId),
  40. }
  41. }
  42. func (v *userByEmail) Get(email string) (*protocol.User, bool) {
  43. var user *protocol.User
  44. var found bool
  45. v.RLock()
  46. user, found = v.cache[email]
  47. v.RUnlock()
  48. if !found {
  49. v.Lock()
  50. user, found = v.cache[email]
  51. if !found {
  52. account := &vmess.Account{
  53. Id: uuid.New().String(),
  54. AlterId: uint32(v.defaultAlterIDs),
  55. }
  56. user = &protocol.User{
  57. Level: v.defaultLevel,
  58. Email: email,
  59. Account: loader.NewTypedSettings(account),
  60. }
  61. v.cache[email] = user
  62. }
  63. v.Unlock()
  64. }
  65. return user, found
  66. }
  67. // Inbound connection handler that handles messages in VMess format.
  68. type VMessInboundHandler struct {
  69. sync.RWMutex
  70. packetDispatcher dispatcher.PacketDispatcher
  71. inboundHandlerManager proxyman.InboundHandlerManager
  72. clients protocol.UserValidator
  73. usersByEmail *userByEmail
  74. accepting bool
  75. listener *internet.TCPHub
  76. detours *DetourConfig
  77. meta *proxy.InboundHandlerMeta
  78. }
  79. func (v *VMessInboundHandler) Port() v2net.Port {
  80. return v.meta.Port
  81. }
  82. func (v *VMessInboundHandler) Close() {
  83. v.accepting = false
  84. if v.listener != nil {
  85. v.Lock()
  86. v.listener.Close()
  87. v.listener = nil
  88. v.clients.Release()
  89. v.clients = nil
  90. v.Unlock()
  91. }
  92. }
  93. func (v *VMessInboundHandler) GetUser(email string) *protocol.User {
  94. v.RLock()
  95. defer v.RUnlock()
  96. if !v.accepting {
  97. return nil
  98. }
  99. user, existing := v.usersByEmail.Get(email)
  100. if !existing {
  101. v.clients.Add(user)
  102. }
  103. return user
  104. }
  105. func (v *VMessInboundHandler) Start() error {
  106. if v.accepting {
  107. return nil
  108. }
  109. tcpListener, err := internet.ListenTCP(v.meta.Address, v.meta.Port, v.HandleConnection, v.meta.StreamSettings)
  110. if err != nil {
  111. log.Error("VMess|Inbound: Unable to listen tcp ", v.meta.Address, ":", v.meta.Port, ": ", err)
  112. return err
  113. }
  114. v.accepting = true
  115. v.Lock()
  116. v.listener = tcpListener
  117. v.Unlock()
  118. return nil
  119. }
  120. func (v *VMessInboundHandler) HandleConnection(connection internet.Connection) {
  121. defer connection.Close()
  122. if !v.accepting {
  123. return
  124. }
  125. connReader := v2net.NewTimeOutReader(8, connection)
  126. defer connReader.Release()
  127. reader := v2io.NewBufferedReader(connReader)
  128. defer reader.Release()
  129. v.RLock()
  130. if !v.accepting {
  131. v.RUnlock()
  132. return
  133. }
  134. session := encoding.NewServerSession(v.clients)
  135. defer session.Release()
  136. request, err := session.DecodeRequestHeader(reader)
  137. v.RUnlock()
  138. if err != nil {
  139. if errors.Cause(err) != io.EOF {
  140. log.Access(connection.RemoteAddr(), "", log.AccessRejected, err)
  141. log.Info("VMessIn: Invalid request from ", connection.RemoteAddr(), ": ", err)
  142. }
  143. connection.SetReusable(false)
  144. return
  145. }
  146. log.Access(connection.RemoteAddr(), request.Destination(), log.AccessAccepted, "")
  147. log.Info("VMessIn: Received request for ", request.Destination())
  148. connection.SetReusable(request.Option.Has(protocol.RequestOptionConnectionReuse))
  149. ray := v.packetDispatcher.DispatchToOutbound(&proxy.SessionInfo{
  150. Source: v2net.DestinationFromAddr(connection.RemoteAddr()),
  151. Destination: request.Destination(),
  152. User: request.User,
  153. Inbound: v.meta,
  154. })
  155. input := ray.InboundInput()
  156. output := ray.InboundOutput()
  157. defer input.Close()
  158. defer output.Release()
  159. var readFinish sync.Mutex
  160. readFinish.Lock()
  161. userSettings := request.User.GetSettings()
  162. connReader.SetTimeOut(userSettings.PayloadReadTimeout)
  163. reader.SetCached(false)
  164. go func() {
  165. bodyReader := session.DecodeRequestBody(reader)
  166. var requestReader v2io.Reader
  167. if request.Option.Has(protocol.RequestOptionChunkStream) {
  168. auth := &crypto.AEADAuthenticator{
  169. AEAD: new(encoding.FnvAuthenticator),
  170. NonceGenerator: crypto.NoOpBytesGenerator{},
  171. AdditionalDataGenerator: crypto.NoOpBytesGenerator{},
  172. }
  173. authReader := crypto.NewAuthenticationReader(auth, bodyReader, request.Command == protocol.RequestCommandTCP)
  174. requestReader = v2io.NewAdaptiveReader(authReader)
  175. } else {
  176. requestReader = v2io.NewAdaptiveReader(bodyReader)
  177. }
  178. if err := v2io.PipeUntilEOF(requestReader, input); err != nil {
  179. connection.SetReusable(false)
  180. }
  181. requestReader.Release()
  182. input.Close()
  183. readFinish.Unlock()
  184. }()
  185. writer := v2io.NewBufferedWriter(connection)
  186. defer writer.Release()
  187. response := &protocol.ResponseHeader{
  188. Command: v.generateCommand(request),
  189. }
  190. if connection.Reusable() {
  191. response.Option.Set(protocol.ResponseOptionConnectionReuse)
  192. }
  193. session.EncodeResponseHeader(response, writer)
  194. bodyWriter := session.EncodeResponseBody(writer)
  195. var v2writer v2io.Writer = v2io.NewAdaptiveWriter(bodyWriter)
  196. if request.Option.Has(protocol.RequestOptionChunkStream) {
  197. v2writer = vmessio.NewAuthChunkWriter(v2writer)
  198. }
  199. // Optimize for small response packet
  200. if data, err := output.Read(); err == nil {
  201. if err := v2writer.Write(data); err != nil {
  202. connection.SetReusable(false)
  203. }
  204. writer.SetCached(false)
  205. if err := v2io.PipeUntilEOF(output, v2writer); err != nil {
  206. connection.SetReusable(false)
  207. }
  208. }
  209. output.Release()
  210. if request.Option.Has(protocol.RequestOptionChunkStream) {
  211. if err := v2writer.Write(alloc.NewLocalBuffer(32)); err != nil {
  212. connection.SetReusable(false)
  213. }
  214. }
  215. writer.Flush()
  216. v2writer.Release()
  217. readFinish.Lock()
  218. }
  219. type Factory struct{}
  220. func (v *Factory) StreamCapability() v2net.NetworkList {
  221. return v2net.NetworkList{
  222. Network: []v2net.Network{v2net.Network_TCP, v2net.Network_KCP, v2net.Network_WebSocket},
  223. }
  224. }
  225. func (v *Factory) Create(space app.Space, rawConfig interface{}, meta *proxy.InboundHandlerMeta) (proxy.InboundHandler, error) {
  226. if !space.HasApp(dispatcher.APP_ID) {
  227. return nil, common.ErrBadConfiguration
  228. }
  229. config := rawConfig.(*Config)
  230. allowedClients := vmess.NewTimedUserValidator(protocol.DefaultIDHash)
  231. for _, user := range config.User {
  232. allowedClients.Add(user)
  233. }
  234. handler := &VMessInboundHandler{
  235. packetDispatcher: space.GetApp(dispatcher.APP_ID).(dispatcher.PacketDispatcher),
  236. clients: allowedClients,
  237. detours: config.Detour,
  238. usersByEmail: NewUserByEmail(config.User, config.GetDefaultValue()),
  239. meta: meta,
  240. }
  241. if space.HasApp(proxyman.APP_ID_INBOUND_MANAGER) {
  242. handler.inboundHandlerManager = space.GetApp(proxyman.APP_ID_INBOUND_MANAGER).(proxyman.InboundHandlerManager)
  243. }
  244. return handler, nil
  245. }
  246. func init() {
  247. registry.MustRegisterInboundHandlerCreator(loader.GetType(new(Config)), new(Factory))
  248. }