clash/adapter/outbound/trojan.go

301 lines
8.1 KiB
Go
Raw Normal View History

2020-03-19 12:26:53 +00:00
package outbound
import (
"context"
"crypto/tls"
2020-03-19 12:26:53 +00:00
"fmt"
"net"
2021-10-16 12:19:59 +00:00
"net/http"
2020-03-19 12:26:53 +00:00
"strconv"
N "github.com/Dreamacro/clash/common/net"
2023-09-22 06:45:34 +00:00
"github.com/Dreamacro/clash/component/ca"
2020-03-19 12:26:53 +00:00
"github.com/Dreamacro/clash/component/dialer"
"github.com/Dreamacro/clash/component/proxydialer"
tlsC "github.com/Dreamacro/clash/component/tls"
2020-03-19 12:26:53 +00:00
C "github.com/Dreamacro/clash/constant"
2021-05-13 14:18:49 +00:00
"github.com/Dreamacro/clash/transport/gun"
"github.com/Dreamacro/clash/transport/trojan"
2020-03-19 12:26:53 +00:00
)
type Trojan struct {
*Base
instance *trojan.Trojan
2021-10-16 12:19:59 +00:00
option *TrojanOption
// for gun mux
gunTLSConfig *tls.Config
gunConfig *gun.Config
transport *gun.TransportWrap
2023-03-10 02:01:05 +00:00
realityConfig *tlsC.RealityConfig
2020-03-19 12:26:53 +00:00
}
2020-03-19 12:26:53 +00:00
type TrojanOption struct {
BasicOption
2023-03-08 09:18:46 +00:00
Name string `proxy:"name"`
Server string `proxy:"server"`
Port int `proxy:"port"`
Password string `proxy:"password"`
ALPN []string `proxy:"alpn,omitempty"`
SNI string `proxy:"sni,omitempty"`
SkipCertVerify bool `proxy:"skip-cert-verify,omitempty"`
Fingerprint string `proxy:"fingerprint,omitempty"`
UDP bool `proxy:"udp,omitempty"`
Network string `proxy:"network,omitempty"`
RealityOpts RealityOptions `proxy:"reality-opts,omitempty"`
GrpcOpts GrpcOptions `proxy:"grpc-opts,omitempty"`
WSOpts WSOptions `proxy:"ws-opts,omitempty"`
ClientFingerprint string `proxy:"client-fingerprint,omitempty"`
2021-10-16 12:19:59 +00:00
}
func (t *Trojan) plainStream(ctx context.Context, c net.Conn) (net.Conn, error) {
2021-10-16 12:19:59 +00:00
if t.option.Network == "ws" {
host, port, _ := net.SplitHostPort(t.addr)
wsOpts := &trojan.WebsocketOption{
Host: host,
Port: port,
Path: t.option.WSOpts.Path,
}
if t.option.SNI != "" {
wsOpts.Host = t.option.SNI
}
if len(t.option.WSOpts.Headers) != 0 {
header := http.Header{}
for key, value := range t.option.WSOpts.Headers {
header.Add(key, value)
}
wsOpts.Headers = header
}
return t.instance.StreamWebsocketConn(ctx, c, wsOpts)
2021-10-16 12:19:59 +00:00
}
return t.instance.StreamConn(ctx, c)
2020-03-19 12:26:53 +00:00
}
// StreamConnContext implements C.ProxyAdapter
func (t *Trojan) StreamConnContext(ctx context.Context, c net.Conn, metadata *C.Metadata) (net.Conn, error) {
var err error
if tlsC.HaveGlobalFingerprint() && len(t.option.ClientFingerprint) == 0 {
t.option.ClientFingerprint = tlsC.GetGlobalFingerprint()
}
if t.transport != nil {
2023-03-10 02:01:05 +00:00
c, err = gun.StreamGunWithConn(c, t.gunTLSConfig, t.gunConfig, t.realityConfig)
} else {
c, err = t.plainStream(ctx, c)
}
if err != nil {
return nil, fmt.Errorf("%s connect error: %w", t.addr, err)
}
2022-04-30 14:26:38 +00:00
if metadata.NetWork == C.UDP {
err = t.instance.WriteHeader(c, trojan.CommandUDP, serializesSocksAddr(metadata))
return c, err
}
err = t.instance.WriteHeader(c, trojan.CommandTCP, serializesSocksAddr(metadata))
return c, err
}
2021-04-29 03:23:14 +00:00
// DialContext implements C.ProxyAdapter
func (t *Trojan) DialContext(ctx context.Context, metadata *C.Metadata, opts ...dialer.Option) (_ C.Conn, err error) {
// gun transport
if t.transport != nil && len(opts) == 0 {
c, err := gun.StreamGunWithTransport(t.transport, t.gunConfig)
if err != nil {
return nil, err
}
if err = t.instance.WriteHeader(c, trojan.CommandTCP, serializesSocksAddr(metadata)); err != nil {
c.Close()
return nil, err
}
return NewConn(c, t), nil
}
2022-12-19 16:11:02 +00:00
return t.DialContextWithDialer(ctx, dialer.NewDialer(t.Base.DialOptions(opts...)...), metadata)
2022-12-19 13:34:07 +00:00
}
2022-12-19 13:34:07 +00:00
// DialContextWithDialer implements C.ProxyAdapter
func (t *Trojan) DialContextWithDialer(ctx context.Context, dialer C.Dialer, metadata *C.Metadata) (_ C.Conn, err error) {
if len(t.option.DialerProxy) > 0 {
dialer, err = proxydialer.NewByName(t.option.DialerProxy, dialer)
if err != nil {
return nil, err
}
}
2022-12-19 13:34:07 +00:00
c, err := dialer.DialContext(ctx, "tcp", t.addr)
2020-03-19 12:26:53 +00:00
if err != nil {
return nil, fmt.Errorf("%s connect error: %w", t.addr, err)
2020-03-19 12:26:53 +00:00
}
N.TCPKeepAlive(c)
2022-12-16 14:15:44 +00:00
defer func(c net.Conn) {
2022-12-13 05:20:40 +00:00
safeConnClose(c, err)
2022-12-16 14:15:44 +00:00
}(c)
c, err = t.StreamConnContext(ctx, c, metadata)
2020-03-19 12:26:53 +00:00
if err != nil {
return nil, err
2020-03-19 12:26:53 +00:00
}
return NewConn(c, t), err
2020-03-19 12:26:53 +00:00
}
// ListenPacketContext implements C.ProxyAdapter
func (t *Trojan) ListenPacketContext(ctx context.Context, metadata *C.Metadata, opts ...dialer.Option) (_ C.PacketConn, err error) {
var c net.Conn
// grpc transport
if t.transport != nil && len(opts) == 0 {
c, err = gun.StreamGunWithTransport(t.transport, t.gunConfig)
if err != nil {
return nil, fmt.Errorf("%s connect error: %w", t.addr, err)
}
defer func(c net.Conn) {
2022-12-13 05:20:40 +00:00
safeConnClose(c, err)
}(c)
2022-12-19 13:34:07 +00:00
err = t.instance.WriteHeader(c, trojan.CommandUDP, serializesSocksAddr(metadata))
2021-04-05 15:26:13 +00:00
if err != nil {
2022-12-19 13:34:07 +00:00
return nil, err
2021-04-05 15:26:13 +00:00
}
2022-12-19 13:34:07 +00:00
pc := t.instance.PacketConn(c)
return newPacketConn(pc, t), err
}
2022-12-19 16:11:02 +00:00
return t.ListenPacketWithDialer(ctx, dialer.NewDialer(t.Base.DialOptions(opts...)...), metadata)
2022-12-19 13:34:07 +00:00
}
// ListenPacketWithDialer implements C.ProxyAdapter
func (t *Trojan) ListenPacketWithDialer(ctx context.Context, dialer C.Dialer, metadata *C.Metadata) (_ C.PacketConn, err error) {
if len(t.option.DialerProxy) > 0 {
dialer, err = proxydialer.NewByName(t.option.DialerProxy, dialer)
if err != nil {
return nil, err
}
}
2022-12-19 13:34:07 +00:00
c, err := dialer.DialContext(ctx, "tcp", t.addr)
if err != nil {
return nil, fmt.Errorf("%s connect error: %w", t.addr, err)
}
defer func(c net.Conn) {
2022-12-19 13:34:07 +00:00
safeConnClose(c, err)
}(c)
N.TCPKeepAlive(c)
c, err = t.plainStream(ctx, c)
2022-12-19 13:34:07 +00:00
if err != nil {
return nil, fmt.Errorf("%s connect error: %w", t.addr, err)
}
2022-05-01 22:27:45 +00:00
err = t.instance.WriteHeader(c, trojan.CommandUDP, serializesSocksAddr(metadata))
if err != nil {
return nil, err
}
pc := t.instance.PacketConn(c)
return newPacketConn(pc, t), err
}
2022-12-19 13:34:07 +00:00
// SupportWithDialer implements C.ProxyAdapter
func (t *Trojan) SupportWithDialer() C.NetWork {
return C.ALLNet
2022-12-19 13:34:07 +00:00
}
// ListenPacketOnStreamConn implements C.ProxyAdapter
func (t *Trojan) ListenPacketOnStreamConn(c net.Conn, metadata *C.Metadata) (_ C.PacketConn, err error) {
2020-03-19 12:26:53 +00:00
pc := t.instance.PacketConn(c)
return newPacketConn(pc, t), err
2020-03-19 12:26:53 +00:00
}
// SupportUOT implements C.ProxyAdapter
func (t *Trojan) SupportUOT() bool {
return true
}
2020-03-19 12:26:53 +00:00
func NewTrojan(option TrojanOption) (*Trojan, error) {
addr := net.JoinHostPort(option.Server, strconv.Itoa(option.Port))
2020-03-19 12:26:53 +00:00
tOption := &trojan.Option{
Password: option.Password,
ALPN: option.ALPN,
ServerName: option.Server,
SkipCertVerify: option.SkipCertVerify,
Fingerprint: option.Fingerprint,
ClientFingerprint: option.ClientFingerprint,
2022-03-29 16:15:39 +00:00
}
2020-03-19 12:26:53 +00:00
if option.SNI != "" {
tOption.ServerName = option.SNI
}
t := &Trojan{
2020-03-19 12:26:53 +00:00
Base: &Base{
2022-08-28 05:41:19 +00:00
name: option.Name,
addr: addr,
tp: C.Trojan,
udp: option.UDP,
2023-02-24 05:53:44 +00:00
tfo: option.TFO,
2023-08-09 08:57:39 +00:00
mpTcp: option.MPTCP,
2022-08-28 05:41:19 +00:00
iface: option.Interface,
rmark: option.RoutingMark,
prefer: C.NewDNSPrefer(option.IPVersion),
2020-03-19 12:26:53 +00:00
},
instance: trojan.New(tOption),
2021-10-16 12:19:59 +00:00
option: &option,
}
2023-03-10 02:01:05 +00:00
var err error
t.realityConfig, err = option.RealityOpts.Parse()
if err != nil {
return nil, err
}
tOption.Reality = t.realityConfig
if option.Network == "grpc" {
dialFn := func(network, addr string) (net.Conn, error) {
var err error
var cDialer C.Dialer = dialer.NewDialer(t.Base.DialOptions()...)
if len(t.option.DialerProxy) > 0 {
cDialer, err = proxydialer.NewByName(t.option.DialerProxy, cDialer)
if err != nil {
return nil, err
}
}
c, err := cDialer.DialContext(context.Background(), "tcp", t.addr)
if err != nil {
return nil, fmt.Errorf("%s connect error: %s", t.addr, err.Error())
}
N.TCPKeepAlive(c)
return c, nil
}
2022-07-11 05:42:28 +00:00
tlsConfig := &tls.Config{
NextProtos: option.ALPN,
MinVersion: tls.VersionTLS12,
InsecureSkipVerify: tOption.SkipCertVerify,
ServerName: tOption.ServerName,
2022-07-11 05:42:28 +00:00
}
2023-09-22 06:45:34 +00:00
var err error
tlsConfig, err = ca.GetSpecifiedFingerprintTLSConfig(tlsConfig, option.Fingerprint)
if err != nil {
return nil, err
2022-07-11 05:42:28 +00:00
}
2023-03-10 02:01:05 +00:00
t.transport = gun.NewHTTP2Client(dialFn, tlsConfig, tOption.ClientFingerprint, t.realityConfig)
2022-03-29 16:15:39 +00:00
t.gunTLSConfig = tlsConfig
t.gunConfig = &gun.Config{
ServiceName: option.GrpcOpts.GrpcServiceName,
Host: tOption.ServerName,
}
}
return t, nil
2020-03-19 12:26:53 +00:00
}