mirror of
https://github.com/ScuroNeko/mtg.git
synced 2026-08-31 14:14:02 +03:00
REPOSITORY / ScuroNeko/mtg
Compare commits
Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
c07e3d573d | ||
|
|
f192a718f4 | ||
|
|
0c4523d2c8 | ||
|
|
b0063a4a25 | ||
|
|
6dc494e7d0 | ||
|
|
534d5b755e | ||
|
|
aa7e488a3a | ||
|
|
eba3673e27 | ||
|
|
a27facaa16 | ||
|
|
78a9ff18a5 | ||
|
|
c0899d0743 | ||
|
|
12563219e6 | ||
|
|
59b5ff4080 | ||
|
|
d7e554540d | ||
|
|
1575b82688 | ||
|
|
5df1f594cc | ||
|
|
02ad052c49 | ||
|
|
2b8c7825ca | ||
|
|
75357b3e3c | ||
|
|
d8b14dc765 | ||
|
|
e0850869ba | ||
|
|
9375552180 | ||
|
|
cbe5b8c94e | ||
|
|
63b425f245 | ||
|
|
b53ead4372 | ||
|
|
2cdd66c722 | ||
|
|
2ae0101d18 | ||
|
|
6da9c2e58d | ||
|
|
6d89f14c9b | ||
|
|
442e2da330 | ||
|
|
a9b3560b25 | ||
|
|
880dd04728 | ||
|
|
8ea1aa3f5e | ||
|
|
4e5a83cfe9 | ||
|
|
5282ca26f3 | ||
|
|
2077db1f1e | ||
|
|
1a9bc80091 | ||
|
|
30170b9413 | ||
|
|
4687a7c899 | ||
|
|
d467fba674 | ||
|
|
6e447b1d59 | ||
|
|
b15a8ec4a5 | ||
|
|
6bef4df091 | ||
|
|
0ce0c668b9 | ||
|
|
01e201365b | ||
|
|
0b52367a82 | ||
|
|
25c842daf1 | ||
|
|
4c543aaea2 | ||
|
|
fee133a62f | ||
|
|
7d38fec74e | ||
|
|
15bb5be6c4 | ||
|
|
ad8c09a2a3 | ||
|
|
2f626e2138 | ||
|
|
93bed24a0b | ||
|
|
219235e181 | ||
|
|
79f54a4e67 | ||
|
|
4b78e83be7 | ||
|
|
ad30eca406 | ||
|
|
ecf947b86c | ||
|
|
5be581154e | ||
|
|
bc3b517e8b | ||
|
|
3f8f96b91f | ||
|
|
ef55fbba15 | ||
|
|
e7416bc04d | ||
|
|
9a6264a89f | ||
|
|
33e0509c5a | ||
|
|
ffad717829 | ||
|
|
7b1f86b75d | ||
|
|
a5e59d9ef7 | ||
|
|
16c06f247c | ||
|
|
0ddaabb136 | ||
|
|
558fec60de | ||
|
|
cc101c9a47 | ||
|
|
e6fa69d288 | ||
|
|
c14a2329c5 | ||
|
|
4c75066ef8 | ||
|
|
ce8163d1b7 | ||
|
|
ca77157fd5 | ||
|
|
66f4d967e7 | ||
|
|
d19cfb1df4 | ||
|
|
3540408adf | ||
|
|
7917434a37 | ||
|
|
853395106b | ||
|
|
d1b0d1f133 | ||
|
|
73bd7287f0 | ||
|
|
31b8ab4482 | ||
|
|
bae5407372 | ||
|
|
4814b0fcc1 | ||
|
|
3ce549bb16 | ||
|
|
5c636a68dc | ||
|
|
9f6f906786 | ||
|
|
eb32766c1f | ||
|
|
787d72cf52 | ||
|
|
ce8f1ebb6c | ||
|
|
cd29f3e20b | ||
|
|
3e105f2beb | ||
|
|
6bbdd99e7f | ||
|
|
894c68019e | ||
|
|
98f18fc22b | ||
|
|
01b739aa7c | ||
|
|
dbaa743e03 | ||
|
|
d1e5f9d145 | ||
|
|
686f177ab9 | ||
|
|
706aef8ca1 | ||
|
|
14dfb9506a | ||
|
|
f742066c54 | ||
|
|
fbe4d32590 | ||
|
|
d0f18be91d | ||
|
|
929b73e2eb | ||
|
|
6b7364238a | ||
|
|
866906e770 | ||
|
|
b3c8c4a47d | ||
|
|
fbc7499cda | ||
|
|
ca5800cf60 | ||
|
|
00bb7be900 | ||
|
|
e8c70603f7 | ||
|
|
9d72904508 | ||
|
|
456ed5b051 | ||
|
|
4b7be8c565 |
@@ -2,6 +2,18 @@
|
||||
|
||||
name: CI
|
||||
|
||||
permissions:
|
||||
actions: read
|
||||
checks: read
|
||||
contents: read
|
||||
deployments: read
|
||||
issues: read
|
||||
discussions: read
|
||||
pull-requests: read
|
||||
repository-projects: read
|
||||
security-events: read
|
||||
statuses: read
|
||||
|
||||
on:
|
||||
push:
|
||||
tags:
|
||||
@@ -26,11 +38,11 @@ jobs:
|
||||
test:
|
||||
name: Test
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 5
|
||||
timeout-minutes: 10
|
||||
strategy:
|
||||
matrix:
|
||||
go_version:
|
||||
- ^1.16
|
||||
- ^1.18
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v2
|
||||
@@ -57,6 +69,38 @@ jobs:
|
||||
with:
|
||||
file: ./coverage.txt
|
||||
|
||||
fuzz:
|
||||
name: Fuzzing
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 20
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v2
|
||||
with:
|
||||
submodules: recursive
|
||||
|
||||
- name: Setup Go
|
||||
uses: actions/setup-go@v2
|
||||
with:
|
||||
go-version: ^1.18
|
||||
|
||||
- name: Cache fuzz results
|
||||
uses: actions/cache@v2
|
||||
with:
|
||||
path: ~/.cache/go-build/fuzz
|
||||
key: ${{ runner.os }}-go-${{ hashFiles('**/*_fuzz_test.go', '**/*_fuzz_internal_test.go') }}
|
||||
restore-keys: ${{ runner.os }}-go-
|
||||
|
||||
- name: Cache dependencies
|
||||
uses: actions/cache@v2
|
||||
with:
|
||||
path: ~/go/pkg/mod
|
||||
key: ${{ runner.os }}-go-${{ hashFiles('**/go.sum') }}
|
||||
restore-keys: ${{ runner.os }}-go-
|
||||
|
||||
- name: Run fuzzing
|
||||
run: make -j4 fuzz
|
||||
|
||||
lint:
|
||||
name: Lint
|
||||
runs-on: ubuntu-latest
|
||||
@@ -67,15 +111,20 @@ jobs:
|
||||
with:
|
||||
submodules: recursive
|
||||
|
||||
- name: Run linter
|
||||
uses: golangci/golangci-lint-action@v2
|
||||
- name: Setup Go
|
||||
uses: actions/setup-go@v2
|
||||
with:
|
||||
version: v1.41.1
|
||||
go-version: ^1.18
|
||||
|
||||
- name: Run linter
|
||||
uses: golangci/golangci-lint-action@v3
|
||||
with:
|
||||
version: v1.45.0
|
||||
|
||||
docker:
|
||||
name: Docker
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 15
|
||||
timeout-minutes: 20
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v2
|
||||
|
||||
@@ -11,6 +11,14 @@
|
||||
#
|
||||
name: "CodeQL"
|
||||
|
||||
# https://docs.github.com/en/actions/reference/workflow-syntax-for-github-actions#permissions
|
||||
# https://github.com/github/codeql-action/issues/572
|
||||
permissions:
|
||||
actions: read
|
||||
contents: read
|
||||
pull-requests: read
|
||||
security-events: write
|
||||
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
|
||||
+1
-1
@@ -9,4 +9,4 @@ format = "colored-line-number"
|
||||
|
||||
[linters]
|
||||
enable-all = true
|
||||
disable = ["gochecknoglobals", "gas", "goerr113", "exhaustivestruct"]
|
||||
disable = ["thelper", "ireturn", "varnamelen", "gochecknoglobals", "gas", "goerr113", "exhaustivestruct", "containedctx"]
|
||||
|
||||
+1
-1
@@ -1,7 +1,7 @@
|
||||
###############################################################################
|
||||
# BUILD STAGE
|
||||
|
||||
FROM golang:1.16-alpine AS build
|
||||
FROM golang:1.18-alpine AS build
|
||||
|
||||
RUN set -x \
|
||||
&& apk --no-cache --update add \
|
||||
|
||||
@@ -2,12 +2,12 @@ ROOT_DIR := $(shell dirname $(realpath $(lastword $(MAKEFILE_LIST))))
|
||||
IMAGE_NAME := mtg
|
||||
APP_NAME := $(IMAGE_NAME)
|
||||
|
||||
GOLANGCI_LINT_VERSION := v1.41.1
|
||||
GOLANGCI_LINT_VERSION := v1.45.0
|
||||
|
||||
VERSION_GO := $(shell go version)
|
||||
VERSION_DATE := $(shell date -Ru)
|
||||
VERSION_TAG := $(shell git describe --tags --always)
|
||||
COMMON_BUILD_FLAGS := -trimpath -mod=readonly -ldflags="-extldflags '-static' -s -w -X 'main.version=$(VERSION_TAG) ($(VERSION_GO)) [$(VERSION_DATE)]'"
|
||||
VERSION := $(shell git describe --exact-match HEAD 2>/dev/null || git describe --tags --always)
|
||||
COMMON_BUILD_FLAGS := -trimpath -mod=readonly -ldflags="-extldflags '-static' -s -w -X 'main.version=$(VERSION)'"
|
||||
|
||||
FUZZ_FLAGS := -fuzztime=120s
|
||||
|
||||
GOBIN := $(ROOT_DIR)/.bin
|
||||
GOTOOL := env "GOBIN=$(GOBIN)" "PATH=$(ROOT_DIR)/.bin:$(PATH)"
|
||||
@@ -39,7 +39,7 @@ vendor: go.mod go.sum
|
||||
|
||||
.PHONY: fmt
|
||||
fmt:
|
||||
@$(GOTOOL) gofumpt -w -s -extra "$(ROOT_DIR)"
|
||||
@$(GOTOOL) gofumpt -w -extra "$(ROOT_DIR)"
|
||||
|
||||
.PHONY: test
|
||||
test:
|
||||
@@ -78,21 +78,44 @@ install-tools: install-tools-lint install-tools-godoc install-tools-gofumpt inst
|
||||
|
||||
.PHONY: install-tools-lint
|
||||
install-tools-lint: .bin
|
||||
@curl -sfL https://install.goreleaser.com/github.com/golangci/golangci-lint.sh \
|
||||
@curl -sfL https://raw.githubusercontent.com/golangci/golangci-lint/master/install.sh \
|
||||
| bash -s -- -b "$(GOBIN)" "$(GOLANGCI_LINT_VERSION)"
|
||||
|
||||
.PHONY: install-tools-godoc
|
||||
install-tools-godoc: .bin
|
||||
@$(GOTOOL) go get -u golang.org/x/tools/cmd/godoc
|
||||
@$(GOTOOL) go install golang.org/x/tools/cmd/godoc@latest
|
||||
|
||||
.PHONY: install-tools-gofumpt
|
||||
install-tools-gofumpt: .bin
|
||||
@$(GOTOOL) go get -u mvdan.cc/gofumpt
|
||||
@$(GOTOOL) go install mvdan.cc/gofumpt@latest
|
||||
|
||||
.PHONY: goreleaser
|
||||
install-tools-goreleaser: .bin
|
||||
@$(GOTOOL) go get -u github.com/goreleaser/goreleaser
|
||||
@$(GOTOOL) go install github.com/goreleaser/goreleaser@latest
|
||||
|
||||
.PHONY: update-deps
|
||||
update-deps:
|
||||
@go get -u && go mod tidy
|
||||
@go get -u && go mod tidy -go=1.18
|
||||
|
||||
.PHONY: fuzz
|
||||
fuzz: fuzz-ClientHello fuzz-ServerGenerateHandshakeFrame fuzz-ClientHandshake fuzz-ServerReceive fuzz-ServerSend
|
||||
|
||||
.PHONY: fuzz-ClientHello
|
||||
fuzz-ClientHello:
|
||||
@go test -fuzz=FuzzClientHello $(FUZZ_FLAGS) "$(ROOT_DIR)/mtglib/internal/faketls"
|
||||
|
||||
.PHONY: fuzz-ServerGenerateHandshakeFrame
|
||||
fuzz-ServerGenerateHandshakeFrame:
|
||||
@go test -fuzz=FuzzServerGenerateHandshakeFrame $(FUZZ_FLAGS) "$(ROOT_DIR)/mtglib/internal/obfuscated2"
|
||||
|
||||
.PHONY: fuzz-ClientHandshake
|
||||
fuzz-ClientHandshake:
|
||||
@go test -fuzz=FuzzClientHandshake $(FUZZ_FLAGS) "$(ROOT_DIR)/mtglib/internal/obfuscated2"
|
||||
|
||||
.PHONY: fuzz-ServerReceive
|
||||
fuzz-ServerReceive:
|
||||
@go test -fuzz=FuzzServerReceive $(FUZZ_FLAGS) "$(ROOT_DIR)/mtglib/internal/obfuscated2"
|
||||
|
||||
.PHONY: fuzz-ServerSend
|
||||
fuzz-ServerSend:
|
||||
@go test -fuzz=FuzzServerSend $(FUZZ_FLAGS) "$(ROOT_DIR)/mtglib/internal/obfuscated2"
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
# mtg
|
||||
|
||||
Highly-opionated (ex-bullshit-free) MTPROTO proxy for
|
||||
Highly-opinionated (ex-bullshit-free) MTPROTO proxy for
|
||||
[Telegram](https://telegram.org/).
|
||||
|
||||
[](https://github.com/9seconds/mtg/actions/workflows/ci.yaml)
|
||||
@@ -196,7 +196,7 @@ go get github.com/9seconds/mtg/v2
|
||||
#### Build from sources
|
||||
|
||||
```console
|
||||
git clone https://github.com:9seconds/mtg.git
|
||||
git clone https://github.com/9seconds/mtg.git
|
||||
cd mtg
|
||||
make static
|
||||
```
|
||||
@@ -224,6 +224,16 @@ $ mtg generate-secret --hex google.com
|
||||
ee473ce5d4958eb5f968c87680a23854a0676f6f676c652e636f6d
|
||||
```
|
||||
|
||||
equivalent commands with docker:
|
||||
|
||||
```console
|
||||
$ docker run --rm nineseconds/mtg:2 generate-secret google.com
|
||||
7ibaERuTSGPH1RdztfYnN4tnb29nbGUuY29t
|
||||
|
||||
$ docker run --rm nineseconds/mtg:2 generate-secret --hex google.com
|
||||
ee473ce5d4958eb5f968c87680a23854a0676f6f676c652e636f6d
|
||||
```
|
||||
|
||||
This secret is a keystone for a proxy and your password for a client.
|
||||
You need to keep it secured.
|
||||
|
||||
@@ -307,12 +317,16 @@ Now you can create a systemd unit:
|
||||
```console
|
||||
$ cat /etc/systemd/system/mtg.service
|
||||
[Unit]
|
||||
Description=mtg
|
||||
Description=mtg - MTProto proxy server
|
||||
Documentation=https://github.com/9seconds/mtg
|
||||
After=network.target
|
||||
|
||||
[Service]
|
||||
ExecStart=/usr/local/bin/mtg run /etc/mtg.toml
|
||||
Restart=always
|
||||
RestartSec=3
|
||||
DynamicUser=true
|
||||
AmbientCapabilities=CAP_NET_BIND_SERVICE
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
@@ -324,7 +338,7 @@ $ sudo systemctl start mtg
|
||||
or you can run a docker image
|
||||
|
||||
```console
|
||||
docker run -d -v /etc/mtg.toml:/config.toml -p 443:3128 --restart=unless-stopped nineseconds/mtg:2
|
||||
docker run -d -v /etc/mtg.toml:/config.toml -p 443:3128 --name mtg-proxy --restart=unless-stopped nineseconds/mtg:2
|
||||
```
|
||||
|
||||
where _443_ is a host port (a port you want to connect to from a
|
||||
@@ -353,6 +367,12 @@ $ mtg access /etc/mtg.toml
|
||||
}
|
||||
```
|
||||
|
||||
or if you are using docker:
|
||||
|
||||
```console
|
||||
$ docker exec mtg-proxy /mtg access /config.toml
|
||||
```
|
||||
|
||||
## Metrics
|
||||
|
||||
Out of the box, mtg works with
|
||||
@@ -367,11 +387,12 @@ Here goes a list of metrics with their types but without a prefix.
|
||||
| client_connections | gauge | `ip_family` | Count of processing client connections. |
|
||||
| telegram_connections | gauge | `telegram_ip`, `dc` | Count of connections to Telegram servers. |
|
||||
| domain_fronting_connections | gauge | `ip_family` | Count of connections to fronting domain. |
|
||||
| iplist_size | gauge | `ip_list` | A size of either allowlist or blocklist in use. |
|
||||
| telegram_traffic | counter | `telegram_ip`, `dc`, `direction` | Count of bytes, transmitted to/from Telegram. |
|
||||
| domain_fronting_traffic | counter | `direction` | Count of bytes, transmitted to/from fronting domain. |
|
||||
| domain_fronting | counter | – | Count of domain fronting events. |
|
||||
| concurrency_limited | counter | – | Count of events, when client connection was rejected due to concurrency limit. |
|
||||
| ip_blocklisted | counter | – | Count of events when client connection was rejected because IP was found in the blacklist. |
|
||||
| ip_blocklisted | counter | `ip_list` | Count of events when client connection was rejected because IP was found in the blocklist. |
|
||||
| replay_attacks | counter | – | Count of detected replay attacks. |
|
||||
|
||||
Tag meaning:
|
||||
@@ -382,3 +403,4 @@ Tag meaning:
|
||||
| dc | | A number of the Telegram DC for a connection. |
|
||||
| telegram_ip | | IP address of the Telegram server. |
|
||||
| direction | `to_client`, `from_client` | A direction of the traffic flow. |
|
||||
| ip_list | `allowlist`, `blocklist` | A type of the IP list. |
|
||||
|
||||
@@ -0,0 +1,26 @@
|
||||
package essentials
|
||||
|
||||
import (
|
||||
"io"
|
||||
"net"
|
||||
)
|
||||
|
||||
// CloseableReader is a reader interface that can close its reading end.
|
||||
type CloseableReader interface {
|
||||
io.Reader
|
||||
CloseRead() error
|
||||
}
|
||||
|
||||
// CloseableWriter is a writer that can close its writing end.
|
||||
type CloseableWriter interface {
|
||||
io.Writer
|
||||
CloseWrite() error
|
||||
}
|
||||
|
||||
// Conn is an extension of net.Conn that can close its ends. This mostly
|
||||
// implies TCP connections.
|
||||
type Conn interface {
|
||||
net.Conn
|
||||
CloseableReader
|
||||
CloseableWriter
|
||||
}
|
||||
@@ -0,0 +1,6 @@
|
||||
// This is a minimal package that contains _essentials_ of mtglib and its
|
||||
// complimentary packages. This is mostly required to comply some interfaces
|
||||
// between mtglib and its internals to avoid circular dependencies.
|
||||
//
|
||||
// This package should contain only bare minimum and mostly technical.
|
||||
package essentials
|
||||
@@ -102,6 +102,8 @@ func eventStreamProcessor(ctx context.Context, eventChan <-chan mtglib.Event, ob
|
||||
observer.EventConcurrencyLimited(typedEvt)
|
||||
case mtglib.EventReplayAttack:
|
||||
observer.EventReplayAttack(typedEvt)
|
||||
case mtglib.EventIPListSize:
|
||||
observer.EventIPListSize(typedEvt)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -204,6 +204,27 @@ func (suite *EventStreamTestSuite) TestEventReplayAttack() {
|
||||
time.Sleep(100 * time.Millisecond)
|
||||
}
|
||||
|
||||
func (suite *EventStreamTestSuite) TestEventIPListSize() {
|
||||
evt := mtglib.NewEventIPListSize(10, true)
|
||||
|
||||
for _, v := range []*ObserverMock{suite.observerMock1, suite.observerMock2} {
|
||||
v.
|
||||
On("EventIPListSize", mock.Anything).
|
||||
Once().
|
||||
Run(func(args mock.Arguments) {
|
||||
caught, ok := args.Get(0).(mtglib.EventIPListSize)
|
||||
|
||||
suite.True(ok)
|
||||
suite.Equal(evt.Timestamp(), caught.Timestamp())
|
||||
suite.Equal(evt.Size, caught.Size)
|
||||
suite.Equal(evt.IsBlockList, caught.IsBlockList)
|
||||
})
|
||||
}
|
||||
|
||||
suite.stream.Send(suite.ctx, evt)
|
||||
time.Sleep(100 * time.Millisecond)
|
||||
}
|
||||
|
||||
func (suite *EventStreamTestSuite) TearDownTest() {
|
||||
suite.stream.Shutdown()
|
||||
suite.ctxCancel()
|
||||
|
||||
@@ -53,6 +53,9 @@ type Observer interface {
|
||||
// EventReplayAttack reacts on incoming mtglib.EventReplayAttack event.
|
||||
EventReplayAttack(mtglib.EventReplayAttack)
|
||||
|
||||
// EventIPListSize reacts on incoming mtglib.EventIPListSize
|
||||
EventIPListSize(mtglib.EventIPListSize)
|
||||
|
||||
// Shutdown stop observer. Default event stream guarantees:
|
||||
// 1. If shutdown is executed, it is executed only once
|
||||
// 2. Observer won't receieve any new message after this
|
||||
|
||||
@@ -41,6 +41,10 @@ func (o *ObserverMock) EventReplayAttack(evt mtglib.EventReplayAttack) {
|
||||
o.Called(evt)
|
||||
}
|
||||
|
||||
func (o *ObserverMock) EventIPListSize(evt mtglib.EventIPListSize) {
|
||||
o.Called(evt)
|
||||
}
|
||||
|
||||
func (o *ObserverMock) Shutdown() {
|
||||
o.Called()
|
||||
}
|
||||
|
||||
@@ -130,6 +130,21 @@ func (m multiObserver) EventReplayAttack(evt mtglib.EventReplayAttack) {
|
||||
wg.Wait()
|
||||
}
|
||||
|
||||
func (m multiObserver) EventIPListSize(evt mtglib.EventIPListSize) {
|
||||
wg := &sync.WaitGroup{}
|
||||
wg.Add(len(m.observers))
|
||||
|
||||
for _, v := range m.observers {
|
||||
go func(obs Observer) {
|
||||
defer wg.Done()
|
||||
|
||||
obs.EventIPListSize(evt)
|
||||
}(v)
|
||||
}
|
||||
|
||||
wg.Wait()
|
||||
}
|
||||
|
||||
func (m multiObserver) Shutdown() {
|
||||
for _, v := range m.observers {
|
||||
v.Shutdown()
|
||||
|
||||
@@ -25,6 +25,7 @@ func (n noopObserver) EventFinish(_ mtglib.EventFinish)
|
||||
func (n noopObserver) EventConcurrencyLimited(_ mtglib.EventConcurrencyLimited) {}
|
||||
func (n noopObserver) EventIPBlocklisted(_ mtglib.EventIPBlocklisted) {}
|
||||
func (n noopObserver) EventReplayAttack(_ mtglib.EventReplayAttack) {}
|
||||
func (n noopObserver) EventIPListSize(_ mtglib.EventIPListSize) {}
|
||||
func (n noopObserver) Shutdown() {}
|
||||
|
||||
// NewNoopObserver creates an observer which discards each message.
|
||||
|
||||
@@ -27,6 +27,7 @@ func (suite *NoopTestSuite) SetupSuite() {
|
||||
"concurrency-limited": mtglib.NewEventConcurrencyLimited(),
|
||||
"ip-blacklisted": mtglib.NewEventIPBlocklisted(net.ParseIP("10.0.0.10")),
|
||||
"replay-attack": mtglib.NewEventReplayAttack("connID"),
|
||||
"ip-list-size": mtglib.NewEventIPListSize(10, true),
|
||||
}
|
||||
suite.ctx = context.Background()
|
||||
}
|
||||
@@ -65,6 +66,8 @@ func (suite *NoopTestSuite) TestObserver() {
|
||||
observer.EventIPBlocklisted(typedEvt)
|
||||
case mtglib.EventReplayAttack:
|
||||
observer.EventReplayAttack(typedEvt)
|
||||
case mtglib.EventIPListSize:
|
||||
observer.EventIPListSize(typedEvt)
|
||||
}
|
||||
})
|
||||
}
|
||||
|
||||
+38
-2
@@ -30,7 +30,9 @@ concurrency = 8192
|
||||
# A size of user-space buffer for TCP to use. Since we do 2 connections,
|
||||
# then we have tcp-buffer * (4 + 2) per each connection: read/write for
|
||||
# each connection + 2 copy buffers to pump the data between sockets.
|
||||
tcp-buffer = "4kb"
|
||||
#
|
||||
# Deprecated: this setting is no longer makes any effect.
|
||||
# tcp-buffer = "4kb"
|
||||
|
||||
# Sometimes you want to enforce mtg to use some types of
|
||||
# IP connectivity to Telegram. We have 4 modes:
|
||||
@@ -56,6 +58,19 @@ domain-fronting-port = 443
|
||||
# time range of this parameter.
|
||||
tolerate-time-skewness = "5s"
|
||||
|
||||
# Telegram has a concept of DC. You can think about DC as a number of a cluster
|
||||
# with a certain purpose. Some clusters serve media, some - messages, some rule
|
||||
# channels and so on. But sometimes unknown DC number is requested by client.
|
||||
# It could be a bug or some global reconfiguration of the Telegram.
|
||||
#
|
||||
# By default, proxy rejects such requests. But it is also possible to fallback
|
||||
# this request to any DC. Telegram works in a way that any DC is able to serve
|
||||
# any request but sacrificing a latency.
|
||||
#
|
||||
# If this setting is disabled (default), mtg will reject a connection.
|
||||
# Otherwise, chose a new DC.
|
||||
allow-fallback-on-unknown-dc = false
|
||||
|
||||
# network defines different network-related settings
|
||||
[network]
|
||||
# please be aware that mtg needs to do some external requests. For
|
||||
@@ -155,12 +170,33 @@ download-concurrency = 2
|
||||
# You can provider links here (starts with https:// or http://) or
|
||||
# path to a local file, but in this case it should be absolute.
|
||||
urls = [
|
||||
# "https://iplists.firehol.org/files/firehol_level1.netset",
|
||||
"https://iplists.firehol.org/files/firehol_level1.netset",
|
||||
# "/local.file"
|
||||
]
|
||||
# How often do we need to update a blocklist set.
|
||||
update-each = "24h"
|
||||
|
||||
# Allowlist is an opposite to a blocklist. Only those IPs that are coming from
|
||||
# subnets defined in these lists are allowed. All others will be rejected.
|
||||
#
|
||||
# If this feature is disabled, then there won't be any check performed by this
|
||||
# validator. It is possible to combine both blocklist and whitelist.
|
||||
[defense.allowlist]
|
||||
# You can enable/disable this feature.
|
||||
enabled = false
|
||||
# This is a limiter for concurrency. In order to protect website
|
||||
# from overloading, we download files in this number of threads.
|
||||
download-concurrency = 2
|
||||
# A list of URLs in FireHOL format (https://iplists.firehol.org/)
|
||||
# You can provider links here (starts with https:// or http://) or
|
||||
# path to a local file, but in this case it should be absolute.
|
||||
urls = [
|
||||
# "https://iplists.firehol.org/files/firehol_level1.netset",
|
||||
# "/local.file"
|
||||
|
||||
]
|
||||
update-each = "24h"
|
||||
|
||||
# statsd statistics integration.
|
||||
[stats.statsd]
|
||||
# enabled/disabled
|
||||
|
||||
@@ -1,32 +1,57 @@
|
||||
module github.com/9seconds/mtg/v2
|
||||
|
||||
go 1.16
|
||||
go 1.18
|
||||
|
||||
require (
|
||||
github.com/OneOfOne/xxhash v1.2.8
|
||||
github.com/alecthomas/kong v0.2.17
|
||||
github.com/alecthomas/units v0.0.0-20210208195552-ff826a37aa15
|
||||
github.com/alecthomas/kong v0.5.0
|
||||
github.com/alecthomas/units v0.0.0-20211218093645-b94a6e3cc137
|
||||
github.com/armon/go-socks5 v0.0.0-20160902184237-e75332964ef5
|
||||
github.com/babolivier/go-doh-client v0.0.0-20201028162107-a76cff4cb8b6
|
||||
github.com/d4l3k/messagediff v1.2.1 // indirect
|
||||
github.com/golang/protobuf v1.5.2 // indirect
|
||||
github.com/gotd/td v0.34.0
|
||||
github.com/jarcoal/httpmock v1.0.8
|
||||
github.com/kentik/patricia v0.0.0-20201202224819-f9447a6e25f1
|
||||
github.com/libp2p/go-reuseport v0.0.2
|
||||
github.com/mccutchen/go-httpbin v1.1.1
|
||||
github.com/panjf2000/ants/v2 v2.4.6
|
||||
github.com/pelletier/go-toml v1.9.3
|
||||
github.com/prometheus/client_golang v1.11.0
|
||||
github.com/prometheus/common v0.30.0 // indirect
|
||||
github.com/prometheus/procfs v0.7.1 // indirect
|
||||
github.com/rs/zerolog v1.23.0
|
||||
github.com/panjf2000/ants/v2 v2.4.8
|
||||
github.com/pelletier/go-toml v1.9.4
|
||||
github.com/prometheus/client_golang v1.12.1
|
||||
github.com/prometheus/common v0.32.1 // indirect
|
||||
github.com/prometheus/procfs v0.7.3 // indirect
|
||||
github.com/rs/zerolog v1.26.1
|
||||
github.com/smira/go-statsd v1.3.2
|
||||
github.com/stretchr/objx v0.3.0 // indirect
|
||||
github.com/stretchr/testify v1.7.0
|
||||
github.com/tylertreat/BoomFilters v0.0.0-20210315201527-1a82519a3e43
|
||||
golang.org/x/crypto v0.0.0-20210711020723-a769d52b0f97
|
||||
golang.org/x/net v0.0.0-20210726213435-c6fcb2dbf985
|
||||
golang.org/x/sys v0.0.0-20210630005230-0f9fa26af87c
|
||||
golang.org/x/crypto v0.0.0-20220315160706-3147a52a75dd
|
||||
golang.org/x/net v0.0.0-20211112202133-69e39bad7dc2 // indirect
|
||||
golang.org/x/sys v0.0.0-20220319134239-a9b59b0215f8
|
||||
google.golang.org/protobuf v1.27.1 // indirect
|
||||
)
|
||||
|
||||
require (
|
||||
github.com/txthinking/socks5 v0.0.0-20220212043548-414499347d4a
|
||||
github.com/yl2chen/cidranger v1.0.2
|
||||
)
|
||||
|
||||
require (
|
||||
github.com/beorn7/perks v1.0.1 // indirect
|
||||
github.com/cenkalti/backoff/v4 v4.1.0 // indirect
|
||||
github.com/cespare/xxhash/v2 v2.1.2 // indirect
|
||||
github.com/davecgh/go-spew v1.1.1 // indirect
|
||||
github.com/gotd/ige v0.1.5 // indirect
|
||||
github.com/gotd/xor v0.1.1 // indirect
|
||||
github.com/matttproud/golang_protobuf_extensions v1.0.1 // indirect
|
||||
github.com/patrickmn/go-cache v2.1.0+incompatible // indirect
|
||||
github.com/pkg/errors v0.9.1 // indirect
|
||||
github.com/pmezard/go-difflib v1.0.0 // indirect
|
||||
github.com/prometheus/client_model v0.2.0 // indirect
|
||||
github.com/txthinking/runnergroup v0.0.0-20220212043759-8da8edb7dae8 // indirect
|
||||
github.com/txthinking/x v0.0.0-20210326105829-476fab902fbe // indirect
|
||||
go.uber.org/atomic v1.7.0 // indirect
|
||||
go.uber.org/multierr v1.6.0 // indirect
|
||||
go.uber.org/zap v1.16.0 // indirect
|
||||
golang.org/x/sync v0.0.0-20210220032951-036812b2e83c // indirect
|
||||
golang.org/x/xerrors v0.0.0-20200804184101-5ec99f83aff1 // indirect
|
||||
gopkg.in/yaml.v3 v3.0.0-20210107192922-496545a6307b // indirect
|
||||
)
|
||||
|
||||
@@ -37,15 +37,17 @@ github.com/BurntSushi/xgb v0.0.0-20160522181843-27f122750802/go.mod h1:IVnqGOEym
|
||||
github.com/OneOfOne/xxhash v1.2.8 h1:31czK/TI9sNkxIKfaUfGlU47BAxQ0ztGgd9vPyqimf8=
|
||||
github.com/OneOfOne/xxhash v1.2.8/go.mod h1:eZbhyaAYD41SGSSsnmcpxVoRiQ/MPUTjUdIIOT9Um7Q=
|
||||
github.com/PuerkitoBio/goquery v1.6.1/go.mod h1:GsLWisAFVj4WgDibEWF4pvYnkVQBpKBKeU+7zCJoLcc=
|
||||
github.com/alecthomas/kong v0.2.17 h1:URDISCI96MIgcIlQyoCAlhOmrSw6pZScBNkctg8r0W0=
|
||||
github.com/alecthomas/kong v0.2.17/go.mod h1:ka3VZ8GZNPXv9Ov+j4YNLkI8mTuhXyr/0ktSlqIydQQ=
|
||||
github.com/alecthomas/kong v0.5.0 h1:u8Kdw+eeml93qtMZ04iei0CFYve/WPcA5IFh+9wSskE=
|
||||
github.com/alecthomas/kong v0.5.0/go.mod h1:uzxf/HUh0tj43x1AyJROl3JT7SgsZ5m+icOv1csRhc0=
|
||||
github.com/alecthomas/repr v0.0.0-20210801044451-80ca428c5142 h1:8Uy0oSf5co/NZXje7U1z8Mpep++QJOldL2hs/sBQf48=
|
||||
github.com/alecthomas/repr v0.0.0-20210801044451-80ca428c5142/go.mod h1:2kn6fqh/zIyPLmm3ugklbEi5hg5wS435eygvNfaDQL8=
|
||||
github.com/alecthomas/template v0.0.0-20160405071501-a0175ee3bccc/go.mod h1:LOuyumcjzFXgccqObfd/Ljyb9UuFJ6TxHnclSeseNhc=
|
||||
github.com/alecthomas/template v0.0.0-20190718012654-fb15b899a751/go.mod h1:LOuyumcjzFXgccqObfd/Ljyb9UuFJ6TxHnclSeseNhc=
|
||||
github.com/alecthomas/units v0.0.0-20151022065526-2efee857e7cf/go.mod h1:ybxpYRFXyAe+OPACYpWeL0wqObRcbAqCMya13uyzqw0=
|
||||
github.com/alecthomas/units v0.0.0-20190717042225-c3de453c63f4/go.mod h1:ybxpYRFXyAe+OPACYpWeL0wqObRcbAqCMya13uyzqw0=
|
||||
github.com/alecthomas/units v0.0.0-20190924025748-f65c72e2690d/go.mod h1:rBZYJk541a8SKzHPHnH3zbiI+7dagKZ0cgpgrD7Fyho=
|
||||
github.com/alecthomas/units v0.0.0-20210208195552-ff826a37aa15 h1:AUNCr9CiJuwrRYS3XieqF+Z9B9gNxo/eANAJCF2eiN4=
|
||||
github.com/alecthomas/units v0.0.0-20210208195552-ff826a37aa15/go.mod h1:OMCwj8VM1Kc9e19TLln2VL61YJF0x1XFtfdL4JdbSyE=
|
||||
github.com/alecthomas/units v0.0.0-20211218093645-b94a6e3cc137 h1:s6gZFSlWYmbqAuRjVTiNNhvNRfY2Wxp9nhfyel4rklc=
|
||||
github.com/alecthomas/units v0.0.0-20211218093645-b94a6e3cc137/go.mod h1:OMCwj8VM1Kc9e19TLln2VL61YJF0x1XFtfdL4JdbSyE=
|
||||
github.com/andres-erbsen/clock v0.0.0-20160526145045-9e14626cd129/go.mod h1:rFgpPQZYZ8vdbc+48xibu8ALc3yeyd64IhHS+PU6Yyg=
|
||||
github.com/andybalholm/cascadia v1.1.0/go.mod h1:GsXiBklL0woXo1j/WYWtSYYC4ouU9PqHO0sqidkEA4Y=
|
||||
github.com/armon/go-socks5 v0.0.0-20160902184237-e75332964ef5 h1:0CwZNZbxp69SHPdPJAN/hZIm0C4OItdklCFmMRWYpio=
|
||||
@@ -59,8 +61,9 @@ github.com/beorn7/perks v1.0.1/go.mod h1:G2ZrVWU2WbWT9wwq4/hrbKbnv/1ERSJQ0ibhJ6r
|
||||
github.com/cenkalti/backoff/v4 v4.1.0 h1:c8LkOFQTzuO0WBM/ae5HdGQuZPfPxp7lqBRwQRm4fSc=
|
||||
github.com/cenkalti/backoff/v4 v4.1.0/go.mod h1:scbssz8iZGpm3xbr14ovlUdkxfGXNInqkPWOWmG2CLw=
|
||||
github.com/census-instrumentation/opencensus-proto v0.2.1/go.mod h1:f6KPmirojxKA12rnyqOA5BBL4O983OfeGPqjHWSTneU=
|
||||
github.com/cespare/xxhash/v2 v2.1.1 h1:6MnRN8NT7+YBpUIWxHtefFZOKTAPgGjpQSxqLNn0+qY=
|
||||
github.com/cespare/xxhash/v2 v2.1.1/go.mod h1:VGX0DQ3Q6kWi7AoAeZDth3/j3BFtOZR5XLFGgcrjCOs=
|
||||
github.com/cespare/xxhash/v2 v2.1.2 h1:YRXhKfTDauu4ajMg1TPgFO5jnlC2HCbmLXMcTG5cbYE=
|
||||
github.com/cespare/xxhash/v2 v2.1.2/go.mod h1:VGX0DQ3Q6kWi7AoAeZDth3/j3BFtOZR5XLFGgcrjCOs=
|
||||
github.com/chzyer/logex v1.1.10/go.mod h1:+Ywpsq7O8HXn0nuIou7OrIPyXbp3wmkHB+jjWRnGsAI=
|
||||
github.com/chzyer/readline v0.0.0-20180603132655-2972be24d48e/go.mod h1:nSuG5e5PlCu98SY8svDHJxuZscDgtXS6KTTbou5AhLI=
|
||||
github.com/chzyer/test v0.0.0-20180213035817-a1ea475d72b1/go.mod h1:Q3SI9o4m/ZMnBNeIyt5eFwwo7qiLfzFZmjNmxjkiQlU=
|
||||
@@ -162,14 +165,13 @@ github.com/jpillora/backoff v1.0.0/go.mod h1:J/6gKK9jxlEcS3zixgDgUAsiuZ7yrSoa/FX
|
||||
github.com/json-iterator/go v1.1.6/go.mod h1:+SdeFBvtyEkXs7REEP0seUULqWtbJapLOCVDaaPEHmU=
|
||||
github.com/json-iterator/go v1.1.10/go.mod h1:KdQUCv79m/52Kvf8AW2vK1V8akMuk1QjK/uOdHXbAo4=
|
||||
github.com/json-iterator/go v1.1.11/go.mod h1:KdQUCv79m/52Kvf8AW2vK1V8akMuk1QjK/uOdHXbAo4=
|
||||
github.com/json-iterator/go v1.1.12/go.mod h1:e30LSqwooZae/UwlEbR2852Gd8hjQvJoHmT4TnhNGBo=
|
||||
github.com/jstemmer/go-junit-report v0.0.0-20190106144839-af01ea7f8024/go.mod h1:6v2b51hI/fHJwM22ozAgKL4VKDeJcHhJFhtBdhmNjmU=
|
||||
github.com/jstemmer/go-junit-report v0.9.1/go.mod h1:Brl9GWCQeLvo8nXZwPNNblvFj/XSXhF0NWZEnDohbsk=
|
||||
github.com/julienschmidt/httprouter v1.2.0/go.mod h1:SYymIcj16QtmaHHD7aYtjjsJG7VTCxuUUipMqKk8s4w=
|
||||
github.com/julienschmidt/httprouter v1.3.0/go.mod h1:JR6WtHb+2LUe8TCKY3cZOxFyyO8IZAc4RVcycCCAKdM=
|
||||
github.com/k0kubun/colorstring v0.0.0-20150214042306-9440f1994b88/go.mod h1:3w7q1U84EfirKl04SVQ/s7nPm1ZPhiXd34z40TNz36k=
|
||||
github.com/k0kubun/pp v2.4.0+incompatible/go.mod h1:GWse8YhT0p8pT4ir3ZgBbfZild3tgzSScAn6HmfYukg=
|
||||
github.com/kentik/patricia v0.0.0-20201202224819-f9447a6e25f1 h1:D7qhJP3R49ZjUzpzKQ6B2H3lgejPs6DTO5gRomhhOpE=
|
||||
github.com/kentik/patricia v0.0.0-20201202224819-f9447a6e25f1/go.mod h1:2OfLA+0esiUJpwMjrH39pEk79cb8MvGTBS9YlZpejJ4=
|
||||
github.com/kisielk/gotool v1.0.0/go.mod h1:XhKaO+MFFWcvkIS/tQcRk01m1F5IRFswLeQ+oQHNcck=
|
||||
github.com/konsorten/go-windows-terminal-sequences v1.0.1/go.mod h1:T0+1ngSBFLxvqU3pZ+m/2kptfBszLMUkC4ZK/EgS/cQ=
|
||||
github.com/konsorten/go-windows-terminal-sequences v1.0.3/go.mod h1:T0+1ngSBFLxvqU3pZ+m/2kptfBszLMUkC4ZK/EgS/cQ=
|
||||
@@ -179,8 +181,6 @@ github.com/kr/pretty v0.1.0/go.mod h1:dAy3ld7l9f0ibDNOQOHHMYYIIbhfbHSm3C4ZsoJORN
|
||||
github.com/kr/pty v1.1.1/go.mod h1:pFQYn66WHrOpPYNljwOMqo10TkYh1fy3cYio2l3bCsQ=
|
||||
github.com/kr/text v0.1.0 h1:45sCR5RtlFHMR4UwH9sdQ5TC8v0qDQCHnXt+kaKSTVE=
|
||||
github.com/kr/text v0.1.0/go.mod h1:4Jbv+DJW3UT/LiOwJeYQe1efqtUx/iVham/4vfdArNI=
|
||||
github.com/libp2p/go-reuseport v0.0.2 h1:XSG94b1FJfGA01BUrT82imejHQyTxO4jEWqheyCXYvU=
|
||||
github.com/libp2p/go-reuseport v0.0.2/go.mod h1:SPD+5RwGC7rcnzngoYC86GjPzjSywuQyMVAheVBD9nQ=
|
||||
github.com/mattn/go-colorable v0.1.2/go.mod h1:U0ppj6V5qS13XJ6of8GYAs25YV2eR4EVcfRqFIhoBtE=
|
||||
github.com/mattn/go-isatty v0.0.8/go.mod h1:Iq45c/XA43vh69/j3iqttzPXn0bhXyGjM0Hdxcsrc5s=
|
||||
github.com/mattn/go-isatty v0.0.9/go.mod h1:YNRxwqDuOph6SZLI9vUUz6OYw3QyUt7WiY2yME+cCiQ=
|
||||
@@ -192,12 +192,15 @@ github.com/modern-go/concurrent v0.0.0-20180228061459-e0a39a4cb421/go.mod h1:6dJ
|
||||
github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd/go.mod h1:6dJC0mAP4ikYIbvyc7fijjWJddQyLn8Ig3JB5CqoB9Q=
|
||||
github.com/modern-go/reflect2 v0.0.0-20180701023420-4b7aa43c6742/go.mod h1:bx2lNnkwVCuqBIxFjflWJWanXIb3RllmbCylyMrvgv0=
|
||||
github.com/modern-go/reflect2 v1.0.1/go.mod h1:bx2lNnkwVCuqBIxFjflWJWanXIb3RllmbCylyMrvgv0=
|
||||
github.com/modern-go/reflect2 v1.0.2/go.mod h1:yWuevngMOJpCy52FWWMvUC8ws7m/LJsjYzDa0/r8luk=
|
||||
github.com/mwitkow/go-conntrack v0.0.0-20161129095857-cc309e4a2223/go.mod h1:qRWi+5nqEBWmkhHvq77mSJWrCKwh8bxhgT7d/eI7P4U=
|
||||
github.com/mwitkow/go-conntrack v0.0.0-20190716064945-2f068394615f/go.mod h1:qRWi+5nqEBWmkhHvq77mSJWrCKwh8bxhgT7d/eI7P4U=
|
||||
github.com/panjf2000/ants/v2 v2.4.6 h1:drmj9mcygn2gawZ155dRbo+NfXEfAssjZNU1qoIb4gQ=
|
||||
github.com/panjf2000/ants/v2 v2.4.6/go.mod h1:f6F0NZVFsGCp5A7QW/Zj/m92atWwOkY0OIhFxRNFr4A=
|
||||
github.com/pelletier/go-toml v1.9.3 h1:zeC5b1GviRUyKYd6OJPvBU/mcVDVoL1OhT17FCt5dSQ=
|
||||
github.com/pelletier/go-toml v1.9.3/go.mod h1:u1nR/EPcESfeI/szUZKdtJ0xRNbUoANCkoOuaOx1Y+c=
|
||||
github.com/panjf2000/ants/v2 v2.4.8 h1:JgTbolX6K6RreZ4+bfctI0Ifs+3mrE5BIHudQxUDQ9k=
|
||||
github.com/panjf2000/ants/v2 v2.4.8/go.mod h1:f6F0NZVFsGCp5A7QW/Zj/m92atWwOkY0OIhFxRNFr4A=
|
||||
github.com/patrickmn/go-cache v2.1.0+incompatible h1:HRMgzkcYKYpi3C8ajMPV8OFXaaRUnok+kx1WdO15EQc=
|
||||
github.com/patrickmn/go-cache v2.1.0+incompatible/go.mod h1:3Qf8kWWT7OJRJbdiICTKqZju1ZixQ/KpMGzzAfe6+WQ=
|
||||
github.com/pelletier/go-toml v1.9.4 h1:tjENF6MfZAg8e4ZmZTeWaWiT2vXtsoO6+iuOjFhECwM=
|
||||
github.com/pelletier/go-toml v1.9.4/go.mod h1:u1nR/EPcESfeI/szUZKdtJ0xRNbUoANCkoOuaOx1Y+c=
|
||||
github.com/pkg/diff v0.0.0-20210226163009-20ebb0f2a09e/go.mod h1:pJLUxLENpZxwdsKMEsNbx1VGcRFpLqf3715MtcvvzbA=
|
||||
github.com/pkg/errors v0.8.0/go.mod h1:bwawxfHBFNV+L2hUp1rHADufV3IMtnDRdf1r5NINEl0=
|
||||
github.com/pkg/errors v0.8.1/go.mod h1:bwawxfHBFNV+L2hUp1rHADufV3IMtnDRdf1r5NINEl0=
|
||||
@@ -208,8 +211,9 @@ github.com/pmezard/go-difflib v1.0.0/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZN
|
||||
github.com/prometheus/client_golang v0.9.1/go.mod h1:7SWBe2y4D6OKWSNQJUaRYU/AaXPKyh/dDVn+NZz0KFw=
|
||||
github.com/prometheus/client_golang v1.0.0/go.mod h1:db9x61etRT2tGnBNRi70OPL5FsnadC4Ky3P0J6CfImo=
|
||||
github.com/prometheus/client_golang v1.7.1/go.mod h1:PY5Wy2awLA44sXw4AOSfFBetzPP4j5+D6mVACh+pe2M=
|
||||
github.com/prometheus/client_golang v1.11.0 h1:HNkLOAEQMIDv/K+04rukrLx6ch7msSRwf3/SASFAGtQ=
|
||||
github.com/prometheus/client_golang v1.11.0/go.mod h1:Z6t4BnS23TR94PD6BsDNk8yVqroYurpAkEiz0P2BEV0=
|
||||
github.com/prometheus/client_golang v1.12.1 h1:ZiaPsmm9uiBeaSMRznKsCDNtPCS0T3JVDGF+06gjBzk=
|
||||
github.com/prometheus/client_golang v1.12.1/go.mod h1:3Z9XVyYiZYEO+YQWt3RD2R3jrbd179Rt297l4aS6nDY=
|
||||
github.com/prometheus/client_model v0.0.0-20180712105110-5c3871d89910/go.mod h1:MbSGuTsp3dbXC40dX6PRTWyKYBIrTGTE9sqQNg2J8bo=
|
||||
github.com/prometheus/client_model v0.0.0-20190129233127-fd36f4220a90/go.mod h1:xMI15A0UPsDsEKsMN9yxemIoYk6Tm2C1GtYGdfGttqA=
|
||||
github.com/prometheus/client_model v0.0.0-20190812154241-14fe0d1b01d4/go.mod h1:xMI15A0UPsDsEKsMN9yxemIoYk6Tm2C1GtYGdfGttqA=
|
||||
@@ -218,20 +222,20 @@ github.com/prometheus/client_model v0.2.0/go.mod h1:xMI15A0UPsDsEKsMN9yxemIoYk6T
|
||||
github.com/prometheus/common v0.4.1/go.mod h1:TNfzLD0ON7rHzMJeJkieUDPYmFC7Snx/y86RQel1bk4=
|
||||
github.com/prometheus/common v0.10.0/go.mod h1:Tlit/dnDKsSWFlCLTWaA1cyBgKHSMdTB80sz/V91rCo=
|
||||
github.com/prometheus/common v0.26.0/go.mod h1:M7rCNAaPfAosfx8veZJCuw84e35h3Cfd9VFqTh1DIvc=
|
||||
github.com/prometheus/common v0.30.0 h1:JEkYlQnpzrzQFxi6gnukFPdQ+ac82oRhzMcIduJu/Ug=
|
||||
github.com/prometheus/common v0.30.0/go.mod h1:vu+V0TpY+O6vW9J44gczi3Ap/oXXR10b+M/gUGO4Hls=
|
||||
github.com/prometheus/common v0.32.1 h1:hWIdL3N2HoUx3B8j3YN9mWor0qhY/NlEKZEaXxuIRh4=
|
||||
github.com/prometheus/common v0.32.1/go.mod h1:vu+V0TpY+O6vW9J44gczi3Ap/oXXR10b+M/gUGO4Hls=
|
||||
github.com/prometheus/procfs v0.0.0-20181005140218-185b4288413d/go.mod h1:c3At6R/oaqEKCNdg8wHV1ftS6bRYblBhIjjI8uT2IGk=
|
||||
github.com/prometheus/procfs v0.0.2/go.mod h1:TjEm7ze935MbeOT/UhFTIMYKhuLP4wbCsTZCD3I8kEA=
|
||||
github.com/prometheus/procfs v0.1.3/go.mod h1:lV6e/gmhEcM9IjHGsFOCxxuZ+z1YqCvr4OA4YeYWdaU=
|
||||
github.com/prometheus/procfs v0.6.0/go.mod h1:cz+aTbrPOrUb4q7XlbU9ygM+/jj0fzG6c1xBZuNvfVA=
|
||||
github.com/prometheus/procfs v0.7.1 h1:TlEtJq5GvGqMykEwWzbZWjjztF86swFhsPix1i0bkgA=
|
||||
github.com/prometheus/procfs v0.7.1/go.mod h1:cz+aTbrPOrUb4q7XlbU9ygM+/jj0fzG6c1xBZuNvfVA=
|
||||
github.com/prometheus/procfs v0.7.3 h1:4jVXhlkAyzOScmCkXBTOLRLTz8EeU+eyjrwB/EPq0VU=
|
||||
github.com/prometheus/procfs v0.7.3/go.mod h1:cz+aTbrPOrUb4q7XlbU9ygM+/jj0fzG6c1xBZuNvfVA=
|
||||
github.com/quasilyte/go-ruleguard/dsl v0.3.2/go.mod h1:KeCP03KrjuSO0H1kTuZQCWlQPulDV6YMIXmpQss17rU=
|
||||
github.com/rogpeppe/go-internal v1.3.0/go.mod h1:M8bDsm7K2OlrFYOpmOWEs/qY81heoFRclV5y23lUDJ4=
|
||||
github.com/rogpeppe/go-internal v1.8.0/go.mod h1:WmiCO8CzOY8rg0OYDC4/i/2WRWAB6poM+XZ2dLUbcbE=
|
||||
github.com/rs/xid v1.2.1/go.mod h1:+uKXf+4Djp6Md1KODXJxgGQPKngRmWyn10oCKFzNHOQ=
|
||||
github.com/rs/zerolog v1.23.0 h1:UskrK+saS9P9Y789yNNulYKdARjPZuS35B8gJF2x60g=
|
||||
github.com/rs/zerolog v1.23.0/go.mod h1:6c7hFfxPOy7TacJc4Fcdi24/J0NKYGzjG8FWRI916Qo=
|
||||
github.com/rs/xid v1.3.0/go.mod h1:trrq9SKmegXys3aeAKXMUTdJsYXVwGY3RLcfgqegfbg=
|
||||
github.com/rs/zerolog v1.26.1 h1:/ihwxqH+4z8UxyI70wM1z9yCvkWcfz/a3mj48k/Zngc=
|
||||
github.com/rs/zerolog v1.26.1/go.mod h1:/wSSJWX7lVrsOwlbyTRSOJvqRlc+WjWlfes+CiJ+tmc=
|
||||
github.com/sebdah/goldie/v2 v2.5.3/go.mod h1:oZ9fp0+se1eapSRjfYbsV/0Hqhbuu3bJVvKI/NNtssI=
|
||||
github.com/sergi/go-diff v1.0.0/go.mod h1:0CfEIISq7TuYL3j771MWULgwwjU+GofnZX9QAmXWZgo=
|
||||
github.com/sergi/go-diff v1.1.0/go.mod h1:STckp+ISIX8hZLjrqAeVduY0gWCT9IjLuqbuNXdaHfM=
|
||||
@@ -244,20 +248,27 @@ github.com/stretchr/objx v0.1.0/go.mod h1:HFkY916IF+rwdDfMAkV7OtwuqBVzrE8GR6GFx+
|
||||
github.com/stretchr/objx v0.1.1/go.mod h1:HFkY916IF+rwdDfMAkV7OtwuqBVzrE8GR6GFx+wExME=
|
||||
github.com/stretchr/objx v0.3.0 h1:NGXK3lHquSN08v5vWalVI/L8XU9hdzE/G6xsrze47As=
|
||||
github.com/stretchr/objx v0.3.0/go.mod h1:qt09Ya8vawLte6SNmTgCsAVtYtaKzEcn8ATUoHMkEqE=
|
||||
github.com/stretchr/testify v1.1.5-0.20170809224252-890a5c3458b4/go.mod h1:a8OnRcib4nhh0OaRAV+Yts87kKdq0PP7pXfy6kDkUVs=
|
||||
github.com/stretchr/testify v1.2.2/go.mod h1:a8OnRcib4nhh0OaRAV+Yts87kKdq0PP7pXfy6kDkUVs=
|
||||
github.com/stretchr/testify v1.3.0/go.mod h1:M5WIy9Dh21IEIfnGCwXGc5bZfKNJtfHm1UVUgZn+9EI=
|
||||
github.com/stretchr/testify v1.4.0/go.mod h1:j7eGeouHqKxXV5pUuKE4zz7dFj8WfuZ+81PSLYec5m4=
|
||||
github.com/stretchr/testify v1.5.1/go.mod h1:5W2xD1RspED5o8YsWQXVCued0rvSQ+mT+I5cxcmMvtA=
|
||||
github.com/stretchr/testify v1.6.1/go.mod h1:6Fq8oRcR53rry900zMqJjRRixrwX3KX962/h/Wwjteg=
|
||||
github.com/stretchr/testify v1.7.0 h1:nwc3DEeHmmLAfoZucVR881uASk0Mfjw8xYJ99tb5CcY=
|
||||
github.com/stretchr/testify v1.7.0/go.mod h1:6Fq8oRcR53rry900zMqJjRRixrwX3KX962/h/Wwjteg=
|
||||
github.com/txthinking/runnergroup v0.0.0-20210608031112-152c7c4432bf/go.mod h1:CLUSJbazqETbaR+i0YAhXBICV9TrKH93pziccMhmhpM=
|
||||
github.com/txthinking/runnergroup v0.0.0-20220212043759-8da8edb7dae8 h1:iYc+JnXtzv6sdMx9Q7OTKkDAn7FhDPDogcjeSfEQcLY=
|
||||
github.com/txthinking/runnergroup v0.0.0-20220212043759-8da8edb7dae8/go.mod h1:CLUSJbazqETbaR+i0YAhXBICV9TrKH93pziccMhmhpM=
|
||||
github.com/txthinking/socks5 v0.0.0-20220212043548-414499347d4a h1:BOqgJ4jku0LHPDoR51RD8Mxmo0LHxCzJT/M9MemYdHo=
|
||||
github.com/txthinking/socks5 v0.0.0-20220212043548-414499347d4a/go.mod h1:7NloQcrxaZYKURWph5HLxVDlIwMHJXCPkeWPtpftsIg=
|
||||
github.com/txthinking/x v0.0.0-20210326105829-476fab902fbe h1:gMWxZxBFRAXqoGkwkYlPX2zvyyKNWJpxOxCrjqJkm5A=
|
||||
github.com/txthinking/x v0.0.0-20210326105829-476fab902fbe/go.mod h1:WgqbSEmUYSjEV3B1qmee/PpP2NYEz4bL9/+mF1ma+s4=
|
||||
github.com/tylertreat/BoomFilters v0.0.0-20210315201527-1a82519a3e43 h1:QEePdg0ty2r0t1+qwfZmQ4OOl/MB2UXIeJSpIZv56lg=
|
||||
github.com/tylertreat/BoomFilters v0.0.0-20210315201527-1a82519a3e43/go.mod h1:OYRfF6eb5wY9VRFkXJH8FFBi3plw2v+giaIu7P054pM=
|
||||
github.com/yl2chen/cidranger v1.0.2 h1:lbOWZVCG1tCRX4u24kuM1Tb4nHqWkDxwLdoS+SevawU=
|
||||
github.com/yl2chen/cidranger v1.0.2/go.mod h1:9U1yz7WPYDwf0vpNWFaeRh0bjwz5RVgRy/9UEQfHl0g=
|
||||
github.com/yuin/goldmark v1.1.25/go.mod h1:3hX8gzYuyVAZsxl0MRgGTJEmQBFcNTphYh9decYSb74=
|
||||
github.com/yuin/goldmark v1.1.27/go.mod h1:3hX8gzYuyVAZsxl0MRgGTJEmQBFcNTphYh9decYSb74=
|
||||
github.com/yuin/goldmark v1.1.32/go.mod h1:3hX8gzYuyVAZsxl0MRgGTJEmQBFcNTphYh9decYSb74=
|
||||
github.com/yuin/goldmark v1.2.1/go.mod h1:3hX8gzYuyVAZsxl0MRgGTJEmQBFcNTphYh9decYSb74=
|
||||
github.com/yuin/goldmark v1.4.0/go.mod h1:mwnBkeHKe2W/ZEtQ+71ViKU8L12m81fl3OWwC1Zlc8k=
|
||||
go.opencensus.io v0.21.0/go.mod h1:mSImk1erAIZhrmZN+AvHh14ztQfjbGwt4TtuofqLduU=
|
||||
go.opencensus.io v0.22.0/go.mod h1:+kGneAE2xo2IficOXnaByMWTGM9T73dGwxeWcUqIpI8=
|
||||
go.opencensus.io v0.22.2/go.mod h1:yxeiOL68Rb0Xd1ddK5vPZ/oVn4vY4Ynel7k9FzqtOIw=
|
||||
@@ -279,8 +290,9 @@ golang.org/x/crypto v0.0.0-20190510104115-cbcb75029529/go.mod h1:yigFU9vqHzYiE8U
|
||||
golang.org/x/crypto v0.0.0-20190605123033-f99c8df09eb5/go.mod h1:yigFU9vqHzYiE8UmvKecakEJjdnWj3jj499lnFckfCI=
|
||||
golang.org/x/crypto v0.0.0-20191011191535-87dc89f01550/go.mod h1:yigFU9vqHzYiE8UmvKecakEJjdnWj3jj499lnFckfCI=
|
||||
golang.org/x/crypto v0.0.0-20200622213623-75b288015ac9/go.mod h1:LzIPMQfyMNhhGPhUkYOs5KpL4U8rLKemX1yGLhDgUto=
|
||||
golang.org/x/crypto v0.0.0-20210711020723-a769d52b0f97 h1:/UOmuWzQfxxo9UtlXMwuQU8CMgg1eZXqTRwkSQJWKOI=
|
||||
golang.org/x/crypto v0.0.0-20210711020723-a769d52b0f97/go.mod h1:GvvjBRRGRdwPK5ydBHafDWAxML/pGHZbMvKqRZ5+Abc=
|
||||
golang.org/x/crypto v0.0.0-20211215165025-cf75a172585e/go.mod h1:P+XmwS30IXTQdn5tA2iutPOUgjI07+tq3H3K9MVA1s8=
|
||||
golang.org/x/crypto v0.0.0-20220315160706-3147a52a75dd h1:XcWmESyNjXJMLahc3mqVQJcgSTDxFxhETVlfk9uGc38=
|
||||
golang.org/x/crypto v0.0.0-20220315160706-3147a52a75dd/go.mod h1:IxCIyHEi3zRg3s0A5j5BB6A9Jmi73HwBIUl50j+osU4=
|
||||
golang.org/x/exp v0.0.0-20190121172915-509febef88a4/go.mod h1:CJ0aWSM057203Lf6IL+f9T1iT9GByDxfZKAQTCR3kQA=
|
||||
golang.org/x/exp v0.0.0-20190306152737-a1d7652674e8/go.mod h1:CJ0aWSM057203Lf6IL+f9T1iT9GByDxfZKAQTCR3kQA=
|
||||
golang.org/x/exp v0.0.0-20190510132918-efd6b22b2522/go.mod h1:ZjyILWgesfNpC6sMxTJOJm9Kp84zZh5NQWvqDGG3Qr8=
|
||||
@@ -311,8 +323,9 @@ golang.org/x/mod v0.1.0/go.mod h1:0QHyrYULN0/3qlju5TqG8bIK38QM8yzMo5ekMj3DlcY=
|
||||
golang.org/x/mod v0.1.1-0.20191105210325-c90efee705ee/go.mod h1:QqPTAvyqsEbceGzBzNggFXnrqF1CaUcvgkdR5Ot7KZg=
|
||||
golang.org/x/mod v0.1.1-0.20191107180719-034126e5016b/go.mod h1:QqPTAvyqsEbceGzBzNggFXnrqF1CaUcvgkdR5Ot7KZg=
|
||||
golang.org/x/mod v0.2.0/go.mod h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA=
|
||||
golang.org/x/mod v0.3.0 h1:RM4zey1++hCTbCVQfnWeKs9/IEsaBLA8vTkd0WVtmH4=
|
||||
golang.org/x/mod v0.3.0/go.mod h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA=
|
||||
golang.org/x/mod v0.4.2 h1:Gz96sIWK3OalVv/I/qNygP42zyoKp3xptRVCWRFEBvo=
|
||||
golang.org/x/mod v0.4.2/go.mod h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA=
|
||||
golang.org/x/net v0.0.0-20180218175443-cbe0f9307d01/go.mod h1:mL1N/T3taQHkDXs73rZJwtUhF3w3ftmwwsq0BUmARs4=
|
||||
golang.org/x/net v0.0.0-20180724234803-3673e40ba225/go.mod h1:mL1N/T3taQHkDXs73rZJwtUhF3w3ftmwwsq0BUmARs4=
|
||||
golang.org/x/net v0.0.0-20180826012351-8a410e7b638d/go.mod h1:mL1N/T3taQHkDXs73rZJwtUhF3w3ftmwwsq0BUmARs4=
|
||||
@@ -345,8 +358,9 @@ golang.org/x/net v0.0.0-20200822124328-c89045814202/go.mod h1:/O7V0waA8r7cgGh81R
|
||||
golang.org/x/net v0.0.0-20201021035429-f5854403a974/go.mod h1:sp8m0HH+o8qH0wwXwYZr8TS3Oi6o0r6Gce1SSxlDquU=
|
||||
golang.org/x/net v0.0.0-20210226172049-e18ecbb05110/go.mod h1:m0MpNAwzfU5UDzcl9v0D8zg8gWTRqZa9RBIspLL5mdg=
|
||||
golang.org/x/net v0.0.0-20210525063256-abc453219eb5/go.mod h1:9nx3DQGgdP8bBQD5qxJ1jj9UTztislL4KSBs9R2vV5Y=
|
||||
golang.org/x/net v0.0.0-20210726213435-c6fcb2dbf985 h1:4CSI6oo7cOjJKajidEljs9h+uP0rRZBPPPhcCbj5mw8=
|
||||
golang.org/x/net v0.0.0-20210726213435-c6fcb2dbf985/go.mod h1:9nx3DQGgdP8bBQD5qxJ1jj9UTztislL4KSBs9R2vV5Y=
|
||||
golang.org/x/net v0.0.0-20210805182204-aaa1db679c0d/go.mod h1:9nx3DQGgdP8bBQD5qxJ1jj9UTztislL4KSBs9R2vV5Y=
|
||||
golang.org/x/net v0.0.0-20211112202133-69e39bad7dc2 h1:CIJ76btIcR3eFI5EgSo6k1qKw9KJexJuRLI9G7Hp5wE=
|
||||
golang.org/x/net v0.0.0-20211112202133-69e39bad7dc2/go.mod h1:9nx3DQGgdP8bBQD5qxJ1jj9UTztislL4KSBs9R2vV5Y=
|
||||
golang.org/x/oauth2 v0.0.0-20180821212333-d2e6202438be/go.mod h1:N/0e6XlmueqKjAGxoOufVs8QHGRruUQn6yWY3a++T0U=
|
||||
golang.org/x/oauth2 v0.0.0-20190226205417-e64efc72b421/go.mod h1:gOpvHmFTYa4IltrdGE7lF6nIHvwfUNPOp7c8zoXwtLw=
|
||||
golang.org/x/oauth2 v0.0.0-20190604053449-0f29369cfe45/go.mod h1:gOpvHmFTYa4IltrdGE7lF6nIHvwfUNPOp7c8zoXwtLw=
|
||||
@@ -361,15 +375,14 @@ golang.org/x/sync v0.0.0-20190423024810-112230192c58/go.mod h1:RxMgew5VJxzue5/jJ
|
||||
golang.org/x/sync v0.0.0-20190911185100-cd5d95a43a6e/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
|
||||
golang.org/x/sync v0.0.0-20200317015054-43a5402ce75a/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
|
||||
golang.org/x/sync v0.0.0-20200625203802-6e8e738ad208/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
|
||||
golang.org/x/sync v0.0.0-20201020160332-67f06af15bc9/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
|
||||
golang.org/x/sync v0.0.0-20201207232520-09787c993a3a h1:DcqTD9SDLc+1P/r1EmRBwnVsrOwW+kk2vWf9n+1sGhs=
|
||||
golang.org/x/sync v0.0.0-20201207232520-09787c993a3a/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
|
||||
golang.org/x/sync v0.0.0-20210220032951-036812b2e83c h1:5KslGYwFpkhGh+Q16bwMP3cOontH8FOep7tGV86Y7SQ=
|
||||
golang.org/x/sync v0.0.0-20210220032951-036812b2e83c/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
|
||||
golang.org/x/sys v0.0.0-20180830151530-49385e6e1522/go.mod h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY=
|
||||
golang.org/x/sys v0.0.0-20180905080454-ebe1bf3edb33/go.mod h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY=
|
||||
golang.org/x/sys v0.0.0-20181116152217-5ac8a444bdc5/go.mod h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY=
|
||||
golang.org/x/sys v0.0.0-20190215142949-d0b11bdaac8a/go.mod h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY=
|
||||
golang.org/x/sys v0.0.0-20190222072716-a9d3bda3a223/go.mod h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY=
|
||||
golang.org/x/sys v0.0.0-20190228124157-a34e9553db1e/go.mod h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY=
|
||||
golang.org/x/sys v0.0.0-20190312061237-fead79001313/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
|
||||
golang.org/x/sys v0.0.0-20190412213103-97732733099d/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
|
||||
golang.org/x/sys v0.0.0-20190422165155-953cdadca894/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
|
||||
@@ -400,13 +413,13 @@ golang.org/x/sys v0.0.0-20200625212154-ddb9806d33ae/go.mod h1:h1NjWce9XRLGQEsW7w
|
||||
golang.org/x/sys v0.0.0-20200803210538-64077c9b5642/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
|
||||
golang.org/x/sys v0.0.0-20200930185726-fdedc70b468f/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
|
||||
golang.org/x/sys v0.0.0-20201119102817-f84b799fce68/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
|
||||
golang.org/x/sys v0.0.0-20210119212857-b64e53b001e4/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
|
||||
golang.org/x/sys v0.0.0-20210124154548-22da62e12c0c/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
|
||||
golang.org/x/sys v0.0.0-20210423082822-04245dca01da/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
|
||||
golang.org/x/sys v0.0.0-20210603081109-ebe580a85c40/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
|
||||
golang.org/x/sys v0.0.0-20210615035016-665e8c7367d1/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
|
||||
golang.org/x/sys v0.0.0-20210630005230-0f9fa26af87c h1:F1jZWGFhYfh0Ci55sIpILtKKK8p3i2/krTr0H1rg74I=
|
||||
golang.org/x/sys v0.0.0-20210630005230-0f9fa26af87c/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
|
||||
golang.org/x/sys v0.0.0-20210809222454-d867a43fc93e/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
|
||||
golang.org/x/sys v0.0.0-20220114195835-da31bd327af9/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
|
||||
golang.org/x/sys v0.0.0-20220319134239-a9b59b0215f8 h1:OH54vjqzRWmbJ62fjuhxy7AxFFgoHN0/DPc/UrL8cAs=
|
||||
golang.org/x/sys v0.0.0-20220319134239-a9b59b0215f8/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
|
||||
golang.org/x/term v0.0.0-20201126162022-7de9c90e9dd1/go.mod h1:bj7SfCRtBDWHUb9snDiAeCFNEtKQo2Wmx5Cou7ajbmo=
|
||||
golang.org/x/text v0.0.0-20170915032832-14c0d48ead0c/go.mod h1:NqM8EUOU14njkJ3fqMW+pc6Ldnwhi/IjpwHt7yyuwOQ=
|
||||
golang.org/x/text v0.3.0/go.mod h1:NqM8EUOU14njkJ3fqMW+pc6Ldnwhi/IjpwHt7yyuwOQ=
|
||||
@@ -460,8 +473,8 @@ golang.org/x/tools v0.0.0-20200729194436-6467de6f59a7/go.mod h1:njjCfa9FT2d7l9Bc
|
||||
golang.org/x/tools v0.0.0-20200804011535-6c149bb5ef0d/go.mod h1:njjCfa9FT2d7l9Bc6FUM5FLjQPp3cFF28FI3qnDFljA=
|
||||
golang.org/x/tools v0.0.0-20200820010801-b793a1359eac/go.mod h1:njjCfa9FT2d7l9Bc6FUM5FLjQPp3cFF28FI3qnDFljA=
|
||||
golang.org/x/tools v0.0.0-20200825202427-b303f430e36d/go.mod h1:njjCfa9FT2d7l9Bc6FUM5FLjQPp3cFF28FI3qnDFljA=
|
||||
golang.org/x/tools v0.1.0 h1:po9/4sTYwZU9lPhi1tOrb4hCv3qrhiQ77LZfGa2OjwY=
|
||||
golang.org/x/tools v0.1.0/go.mod h1:xkSsbof2nBLbhDlRMhhhyNLN/zl3eTqcnHD5viDpcZ0=
|
||||
golang.org/x/tools v0.1.7 h1:6j8CgantCy3yc8JGBqkDLMKWqZ0RDU2g1HVgacojGWQ=
|
||||
golang.org/x/tools v0.1.7/go.mod h1:LGqMHiF4EqQNHR1JncWGqT5BVaXmza+X+BDGol+dOxo=
|
||||
golang.org/x/xerrors v0.0.0-20190717185122-a985d3407aa7/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0=
|
||||
golang.org/x/xerrors v0.0.0-20191011141410-1b5146add898/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0=
|
||||
golang.org/x/xerrors v0.0.0-20191204190536-9bdfabe68543/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0=
|
||||
|
||||
@@ -13,6 +13,7 @@ import (
|
||||
"strings"
|
||||
"sync"
|
||||
|
||||
"github.com/9seconds/mtg/v2/essentials"
|
||||
"github.com/9seconds/mtg/v2/internal/config"
|
||||
"github.com/9seconds/mtg/v2/internal/utils"
|
||||
"github.com/9seconds/mtg/v2/mtglib"
|
||||
@@ -106,7 +107,7 @@ func (a *Access) Run(cli *CLI, version string) error {
|
||||
}
|
||||
|
||||
func (a *Access) getIP(ntw mtglib.Network, protocol string) net.IP {
|
||||
client := ntw.MakeHTTPClient(func(ctx context.Context, network, address string) (net.Conn, error) {
|
||||
client := ntw.MakeHTTPClient(func(ctx context.Context, network, address string) (essentials.Conn, error) {
|
||||
return ntw.DialContext(ctx, protocol, address) // nolint: wrapcheck
|
||||
})
|
||||
|
||||
|
||||
+81
-17
@@ -1,6 +1,7 @@
|
||||
package cli
|
||||
|
||||
import (
|
||||
"context"
|
||||
"fmt"
|
||||
"net"
|
||||
"net/url"
|
||||
@@ -11,11 +12,13 @@ import (
|
||||
"github.com/9seconds/mtg/v2/internal/config"
|
||||
"github.com/9seconds/mtg/v2/internal/utils"
|
||||
"github.com/9seconds/mtg/v2/ipblocklist"
|
||||
"github.com/9seconds/mtg/v2/ipblocklist/files"
|
||||
"github.com/9seconds/mtg/v2/logger"
|
||||
"github.com/9seconds/mtg/v2/mtglib"
|
||||
"github.com/9seconds/mtg/v2/network"
|
||||
"github.com/9seconds/mtg/v2/stats"
|
||||
"github.com/rs/zerolog"
|
||||
"github.com/yl2chen/cidranger"
|
||||
)
|
||||
|
||||
func makeLogger(conf *config.Config) mtglib.Logger {
|
||||
@@ -38,10 +41,9 @@ func makeNetwork(conf *config.Config, version string) (mtglib.Network, error) {
|
||||
tcpTimeout := conf.Network.Timeout.TCP.Get(network.DefaultTimeout)
|
||||
httpTimeout := conf.Network.Timeout.HTTP.Get(network.DefaultHTTPTimeout)
|
||||
dohIP := conf.Network.DOHIP.Get(net.ParseIP(network.DefaultDOHHostname)).String()
|
||||
bufferSize := conf.TCPBuffer.Get(network.DefaultBufferSize)
|
||||
userAgent := "mtg/" + version
|
||||
|
||||
baseDialer, err := network.NewDefaultDialer(tcpTimeout, int(bufferSize))
|
||||
baseDialer, err := network.NewDefaultDialer(tcpTimeout, 0)
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("cannot build a default dialer: %w", err)
|
||||
}
|
||||
@@ -86,15 +88,19 @@ func makeAntiReplayCache(conf *config.Config) mtglib.AntiReplayCache {
|
||||
)
|
||||
}
|
||||
|
||||
func makeIPBlocklist(conf *config.Config, logger mtglib.Logger, ntw mtglib.Network) (mtglib.IPBlocklist, error) {
|
||||
if !conf.Defense.Blocklist.Enabled.Get(false) {
|
||||
func makeIPBlocklist(conf config.ListConfig,
|
||||
logger mtglib.Logger,
|
||||
ntw mtglib.Network,
|
||||
updateCallback ipblocklist.FireholUpdateCallback,
|
||||
) (mtglib.IPBlocklist, error) {
|
||||
if !conf.Enabled.Get(false) {
|
||||
return ipblocklist.NewNoop(), nil
|
||||
}
|
||||
|
||||
remoteURLs := []string{}
|
||||
localFiles := []string{}
|
||||
|
||||
for _, v := range conf.Defense.Blocklist.URLs {
|
||||
for _, v := range conf.URLs {
|
||||
if v.IsRemote() {
|
||||
remoteURLs = append(remoteURLs, v.String())
|
||||
} else {
|
||||
@@ -102,16 +108,54 @@ func makeIPBlocklist(conf *config.Config, logger mtglib.Logger, ntw mtglib.Netwo
|
||||
}
|
||||
}
|
||||
|
||||
firehol, err := ipblocklist.NewFirehol(logger.Named("ipblockist"),
|
||||
blocklist, err := ipblocklist.NewFirehol(logger.Named("ipblockist"),
|
||||
ntw,
|
||||
conf.Defense.Blocklist.DownloadConcurrency.Get(1),
|
||||
conf.DownloadConcurrency.Get(1),
|
||||
remoteURLs,
|
||||
localFiles)
|
||||
localFiles,
|
||||
updateCallback)
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("incorrect parameters for firehol: %w", err)
|
||||
}
|
||||
|
||||
return firehol, nil
|
||||
go blocklist.Run(conf.UpdateEach.Get(ipblocklist.DefaultFireholUpdateEach))
|
||||
|
||||
return blocklist, nil
|
||||
}
|
||||
|
||||
func makeIPAllowlist(conf config.ListConfig,
|
||||
logger mtglib.Logger,
|
||||
ntw mtglib.Network,
|
||||
updateCallback ipblocklist.FireholUpdateCallback,
|
||||
) (allowlist mtglib.IPBlocklist, err error) {
|
||||
if !conf.Enabled.Get(false) {
|
||||
allowlist, err = ipblocklist.NewFireholFromFiles(
|
||||
logger.Named("ipblocklist"),
|
||||
1,
|
||||
[]files.File{
|
||||
files.NewMem([]*net.IPNet{
|
||||
cidranger.AllIPv4,
|
||||
cidranger.AllIPv6,
|
||||
}),
|
||||
},
|
||||
updateCallback,
|
||||
)
|
||||
|
||||
go allowlist.Run(conf.UpdateEach.Get(ipblocklist.DefaultFireholUpdateEach))
|
||||
} else {
|
||||
allowlist, err = makeIPBlocklist(
|
||||
conf,
|
||||
logger,
|
||||
ntw,
|
||||
updateCallback,
|
||||
)
|
||||
}
|
||||
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("cannot build allowlist: %w", err)
|
||||
}
|
||||
|
||||
return allowlist, nil
|
||||
}
|
||||
|
||||
func makeEventStream(conf *config.Config, logger mtglib.Logger) (mtglib.EventStream, error) {
|
||||
@@ -153,24 +197,42 @@ func makeEventStream(conf *config.Config, logger mtglib.Logger) (mtglib.EventStr
|
||||
return events.NewNoopStream(), nil
|
||||
}
|
||||
|
||||
func runProxy(conf *config.Config, version string) error {
|
||||
func runProxy(conf *config.Config, version string) error { // nolint: funlen
|
||||
logger := makeLogger(conf)
|
||||
|
||||
logger.BindStr("configuration", conf.String()).Debug("configuration")
|
||||
logger.BindJSON("configuration", conf.String()).Debug("configuration")
|
||||
|
||||
eventStream, err := makeEventStream(conf, logger)
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot build event stream: %w", err)
|
||||
}
|
||||
|
||||
ntw, err := makeNetwork(conf, version)
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot build network: %w", err)
|
||||
}
|
||||
|
||||
blocklist, err := makeIPBlocklist(conf, logger, ntw)
|
||||
blocklist, err := makeIPBlocklist(
|
||||
conf.Defense.Blocklist,
|
||||
logger.Named("blocklist"),
|
||||
ntw,
|
||||
func(ctx context.Context, size int) {
|
||||
eventStream.Send(ctx, mtglib.NewEventIPListSize(size, true))
|
||||
})
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot build ip blocklist: %w", err)
|
||||
}
|
||||
|
||||
eventStream, err := makeEventStream(conf, logger)
|
||||
allowlist, err := makeIPAllowlist(
|
||||
conf.Defense.Allowlist,
|
||||
logger.Named("allowlist"),
|
||||
ntw,
|
||||
func(ctx context.Context, size int) {
|
||||
eventStream.Send(ctx, mtglib.NewEventIPListSize(size, false))
|
||||
},
|
||||
)
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot build event stream: %w", err)
|
||||
return fmt.Errorf("cannot build ip allowlist: %w", err)
|
||||
}
|
||||
|
||||
opts := mtglib.ProxyOpts{
|
||||
@@ -178,13 +240,15 @@ func runProxy(conf *config.Config, version string) error {
|
||||
Network: ntw,
|
||||
AntiReplayCache: makeAntiReplayCache(conf),
|
||||
IPBlocklist: blocklist,
|
||||
IPAllowlist: allowlist,
|
||||
EventStream: eventStream,
|
||||
|
||||
Secret: conf.Secret,
|
||||
BufferSize: conf.TCPBuffer.Get(mtglib.DefaultBufferSize),
|
||||
DomainFrontingPort: conf.DomainFrontingPort.Get(mtglib.DefaultDomainFrontingPort),
|
||||
IdleTimeout: conf.Network.Timeout.Idle.Get(mtglib.DefaultIdleTimeout),
|
||||
PreferIP: conf.PreferIP.Get(mtglib.DefaultPreferIP),
|
||||
|
||||
AllowFallbackOnUnknownDC: conf.AllowFallbackOnUnknownDC.Get(false),
|
||||
TolerateTimeSkewness: conf.TolerateTimeSkewness.Value,
|
||||
}
|
||||
|
||||
proxy, err := mtglib.NewProxy(opts)
|
||||
@@ -192,7 +256,7 @@ func runProxy(conf *config.Config, version string) error {
|
||||
return fmt.Errorf("cannot create a proxy: %w", err)
|
||||
}
|
||||
|
||||
listener, err := net.Listen("tcp", conf.BindTo.Get(""))
|
||||
listener, err := utils.NewListener(conf.BindTo.Get(""), 0)
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot start proxy: %w", err)
|
||||
}
|
||||
|
||||
@@ -15,7 +15,7 @@ type SimpleRun struct {
|
||||
|
||||
Debug bool `kong:"name='debug',short='d',help='Run in debug mode.'"` // nolint: lll
|
||||
Concurrency uint64 `kong:"name='concurrency',short='c',default='8192',help='Max number of concurrent connection to proxy.'"` // nolint: lll
|
||||
TCPBuffer string `kong:"name='tcp-buffer',short='b',default='4KB',help='Size of TCP buffer to use.'"` // nolint: lll
|
||||
TCPBuffer string `kong:"name='tcp-buffer',short='b',default='4KB',help='Deprecated and ignored'"` // nolint: lll
|
||||
PreferIP string `kong:"name='prefer-ip',short='i',default='prefer-ipv6',help='IP preference. By default we prefer IPv6 with fallback to IPv4.'"` // nolint: lll
|
||||
DomainFrontingPort uint64 `kong:"name='domain-fronting-port',short='p',default='443',help='A port to access for domain fronting.'"` // nolint: lll
|
||||
DOHIP net.IP `kong:"name='doh-ip',short='n',default='9.9.9.9',help='IP address of DNS-over-HTTP to use.'"` // nolint: lll
|
||||
@@ -38,10 +38,6 @@ func (s *SimpleRun) Run(cli *CLI, version string) error { // nolint: cyclop
|
||||
return fmt.Errorf("incorrect concurrency: %w", err)
|
||||
}
|
||||
|
||||
if err := conf.TCPBuffer.Set(s.TCPBuffer); err != nil {
|
||||
return fmt.Errorf("incorrect tcp-buffer: %w", err)
|
||||
}
|
||||
|
||||
if err := conf.PreferIP.Set(s.PreferIP); err != nil {
|
||||
return fmt.Errorf("incorrect prefer-ip: %w", err)
|
||||
}
|
||||
@@ -71,6 +67,7 @@ func (s *SimpleRun) Run(cli *CLI, version string) error { // nolint: cyclop
|
||||
}
|
||||
|
||||
conf.Debug.Value = s.Debug
|
||||
conf.AllowFallbackOnUnknownDC.Value = true
|
||||
conf.Defense.AntiReplay.Enabled.Value = true
|
||||
|
||||
if err := conf.Validate(); err != nil {
|
||||
|
||||
+29
-18
@@ -8,27 +8,36 @@ import (
|
||||
"github.com/9seconds/mtg/v2/mtglib"
|
||||
)
|
||||
|
||||
type Optional struct {
|
||||
Enabled TypeBool `json:"enabled"`
|
||||
}
|
||||
|
||||
type ListConfig struct {
|
||||
Optional
|
||||
|
||||
DownloadConcurrency TypeConcurrency `json:"downloadConcurrency"`
|
||||
URLs []TypeBlocklistURI `json:"urls"`
|
||||
UpdateEach TypeDuration `json:"updateEach"`
|
||||
}
|
||||
|
||||
type Config struct {
|
||||
Debug TypeBool `json:"debug"`
|
||||
Secret mtglib.Secret `json:"secret"`
|
||||
BindTo TypeHostPort `json:"bindTo"`
|
||||
TCPBuffer TypeBytes `json:"tcpBuffer"`
|
||||
PreferIP TypePreferIP `json:"preferIp"`
|
||||
DomainFrontingPort TypePort `json:"domainFrontingPort"`
|
||||
TolerateTimeSkewness TypeDuration `json:"tolerateTimeSkewness"`
|
||||
Concurrency TypeConcurrency `json:"concurrency"`
|
||||
Defense struct {
|
||||
Debug TypeBool `json:"debug"`
|
||||
AllowFallbackOnUnknownDC TypeBool `json:"allowFallbackOnUnknownDc"`
|
||||
Secret mtglib.Secret `json:"secret"`
|
||||
BindTo TypeHostPort `json:"bindTo"`
|
||||
PreferIP TypePreferIP `json:"preferIp"`
|
||||
DomainFrontingPort TypePort `json:"domainFrontingPort"`
|
||||
TolerateTimeSkewness TypeDuration `json:"tolerateTimeSkewness"`
|
||||
Concurrency TypeConcurrency `json:"concurrency"`
|
||||
Defense struct {
|
||||
AntiReplay struct {
|
||||
Enabled TypeBool `json:"enabled"`
|
||||
Optional
|
||||
|
||||
MaxSize TypeBytes `json:"maxSize"`
|
||||
ErrorRate TypeErrorRate `json:"errorRate"`
|
||||
} `json:"antiReplay"`
|
||||
Blocklist struct {
|
||||
Enabled TypeBool `json:"enabled"`
|
||||
DownloadConcurrency TypeConcurrency `json:"downloadConcurrency"`
|
||||
URLs []TypeBlocklistURI `json:"urls"`
|
||||
UpdateEach TypeDuration `json:"updateEach"`
|
||||
} `json:"blocklist"`
|
||||
Blocklist ListConfig `json:"blocklist"`
|
||||
Allowlist ListConfig `json:"allowlist"`
|
||||
} `json:"defense"`
|
||||
Network struct {
|
||||
Timeout struct {
|
||||
@@ -41,13 +50,15 @@ type Config struct {
|
||||
} `json:"network"`
|
||||
Stats struct {
|
||||
StatsD struct {
|
||||
Enabled TypeBool `json:"enabled"`
|
||||
Optional
|
||||
|
||||
Address TypeHostPort `json:"address"`
|
||||
MetricPrefix TypeMetricPrefix `json:"metricPrefix"`
|
||||
TagFormat TypeStatsdTagFormat `json:"tagFormat"`
|
||||
} `json:"statsd"`
|
||||
Prometheus struct {
|
||||
Enabled TypeBool `json:"enabled"`
|
||||
Optional
|
||||
|
||||
BindTo TypeHostPort `json:"bindTo"`
|
||||
HTTPPath TypeHTTPPath `json:"httpPath"`
|
||||
MetricPrefix TypeMetricPrefix `json:"metricPrefix"`
|
||||
|
||||
@@ -9,15 +9,15 @@ import (
|
||||
)
|
||||
|
||||
type tomlConfig struct {
|
||||
Debug bool `toml:"debug" json:"debug,omitempty"`
|
||||
Secret string `toml:"secret" json:"secret"`
|
||||
BindTo string `toml:"bind-to" json:"bindTo"`
|
||||
TCPBuffer string `toml:"tcp-buffer" json:"tcpBuffer,omitempty"`
|
||||
PreferIP string `toml:"prefer-ip" json:"preferIp,omitempty"`
|
||||
DomainFrontingPort uint `toml:"domain-fronting-port" json:"domainFrontingPort,omitempty"`
|
||||
TolerateTimeSkewness string `toml:"tolerate-time-skewness" json:"tolerateTimeSkewness,omitempty"`
|
||||
Concurrency uint `toml:"concurrency" json:"concurrency,omitempty"`
|
||||
Defense struct {
|
||||
Debug bool `toml:"debug" json:"debug,omitempty"`
|
||||
AllowFallbackOnUnknownDC bool `toml:"allow-fallback-on-unknown-dc" json:"allowFallbackOnUnknownDc,omitempty"`
|
||||
Secret string `toml:"secret" json:"secret"`
|
||||
BindTo string `toml:"bind-to" json:"bindTo"`
|
||||
PreferIP string `toml:"prefer-ip" json:"preferIp,omitempty"`
|
||||
DomainFrontingPort uint `toml:"domain-fronting-port" json:"domainFrontingPort,omitempty"`
|
||||
TolerateTimeSkewness string `toml:"tolerate-time-skewness" json:"tolerateTimeSkewness,omitempty"`
|
||||
Concurrency uint `toml:"concurrency" json:"concurrency,omitempty"`
|
||||
Defense struct {
|
||||
AntiReplay struct {
|
||||
Enabled bool `toml:"enabled" json:"enabled,omitempty"`
|
||||
MaxSize string `toml:"max-size" json:"maxSize,omitempty"`
|
||||
@@ -29,6 +29,12 @@ type tomlConfig struct {
|
||||
URLs []string `toml:"urls" json:"urls,omitempty"`
|
||||
UpdateEach string `toml:"update-each" json:"updateEach,omitempty"`
|
||||
} `toml:"blocklist" json:"blocklist,omitempty"`
|
||||
Allowlist struct {
|
||||
Enabled bool `toml:"enabled" json:"enabled,omitempty"`
|
||||
DownloadConcurrency uint `toml:"download-concurrency" json:"downloadConcurrency,omitempty"`
|
||||
URLs []string `toml:"urls" json:"urls,omitempty"`
|
||||
UpdateEach string `toml:"update-each" json:"updateEach,omitempty"`
|
||||
} `toml:"allowlist" json:"allowlist,omitempty"`
|
||||
} `toml:"defense" json:"defense,omitempty"`
|
||||
Network struct {
|
||||
Timeout struct {
|
||||
|
||||
@@ -2,9 +2,9 @@ package testlib
|
||||
|
||||
import (
|
||||
"context"
|
||||
"net"
|
||||
"net/http"
|
||||
|
||||
"github.com/9seconds/mtg/v2/essentials"
|
||||
"github.com/stretchr/testify/mock"
|
||||
)
|
||||
|
||||
@@ -12,19 +12,20 @@ type MtglibNetworkMock struct {
|
||||
mock.Mock
|
||||
}
|
||||
|
||||
func (m *MtglibNetworkMock) Dial(network, address string) (net.Conn, error) {
|
||||
func (m *MtglibNetworkMock) Dial(network, address string) (essentials.Conn, error) {
|
||||
args := m.Called(network, address)
|
||||
|
||||
return args.Get(0).(net.Conn), args.Error(1) // nolint: wrapcheck
|
||||
return args.Get(0).(essentials.Conn), args.Error(1) // nolint: wrapcheck, forcetypeassert
|
||||
}
|
||||
|
||||
func (m *MtglibNetworkMock) DialContext(ctx context.Context, network, address string) (net.Conn, error) {
|
||||
func (m *MtglibNetworkMock) DialContext(ctx context.Context, network, address string) (essentials.Conn, error) {
|
||||
args := m.Called(ctx, network, address)
|
||||
|
||||
return args.Get(0).(net.Conn), args.Error(1) // nolint: wrapcheck
|
||||
return args.Get(0).(essentials.Conn), args.Error(1) // nolint: wrapcheck, forcetypeassert
|
||||
}
|
||||
|
||||
func (m *MtglibNetworkMock) MakeHTTPClient(dialFunc func(ctx context.Context,
|
||||
network, address string) (net.Conn, error)) *http.Client {
|
||||
return m.Called(dialFunc).Get(0).(*http.Client)
|
||||
network, address string) (essentials.Conn, error),
|
||||
) *http.Client {
|
||||
return m.Called(dialFunc).Get(0).(*http.Client) // nolint: forcetypeassert
|
||||
}
|
||||
|
||||
@@ -7,42 +7,50 @@ import (
|
||||
"github.com/stretchr/testify/mock"
|
||||
)
|
||||
|
||||
type NetConnMock struct {
|
||||
type EssentialsConnMock struct {
|
||||
mock.Mock
|
||||
}
|
||||
|
||||
func (n *NetConnMock) Read(b []byte) (int, error) {
|
||||
func (n *EssentialsConnMock) Read(b []byte) (int, error) {
|
||||
args := n.Called(b)
|
||||
|
||||
return args.Int(0), args.Error(1)
|
||||
}
|
||||
|
||||
func (n *NetConnMock) Write(b []byte) (int, error) {
|
||||
func (n *EssentialsConnMock) Write(b []byte) (int, error) {
|
||||
args := n.Called(b)
|
||||
|
||||
return args.Int(0), args.Error(1)
|
||||
}
|
||||
|
||||
func (n *NetConnMock) Close() error {
|
||||
func (n *EssentialsConnMock) Close() error {
|
||||
return n.Called().Error(0) // nolint: wrapcheck
|
||||
}
|
||||
|
||||
func (n *NetConnMock) LocalAddr() net.Addr {
|
||||
return n.Called().Get(0).(net.Addr)
|
||||
func (n *EssentialsConnMock) CloseRead() error {
|
||||
return n.Called().Error(0) // nolint: wrapcheck
|
||||
}
|
||||
|
||||
func (n *NetConnMock) RemoteAddr() net.Addr {
|
||||
return n.Called().Get(0).(net.Addr)
|
||||
func (n *EssentialsConnMock) CloseWrite() error {
|
||||
return n.Called().Error(0) // nolint: wrapcheck
|
||||
}
|
||||
|
||||
func (n *NetConnMock) SetDeadline(t time.Time) error {
|
||||
func (n *EssentialsConnMock) LocalAddr() net.Addr {
|
||||
return n.Called().Get(0).(net.Addr) // nolint: forcetypeassert
|
||||
}
|
||||
|
||||
func (n *EssentialsConnMock) RemoteAddr() net.Addr {
|
||||
return n.Called().Get(0).(net.Addr) // nolint: forcetypeassert
|
||||
}
|
||||
|
||||
func (n *EssentialsConnMock) SetDeadline(t time.Time) error {
|
||||
return n.Called(t).Error(0) // nolint: wrapcheck
|
||||
}
|
||||
|
||||
func (n *NetConnMock) SetReadDeadline(t time.Time) error {
|
||||
func (n *EssentialsConnMock) SetReadDeadline(t time.Time) error {
|
||||
return n.Called(t).Error(0) // nolint: wrapcheck
|
||||
}
|
||||
|
||||
func (n *NetConnMock) SetWriteDeadline(t time.Time) error {
|
||||
func (n *EssentialsConnMock) SetWriteDeadline(t time.Time) error {
|
||||
return n.Called(t).Error(0) // nolint: wrapcheck
|
||||
}
|
||||
|
||||
@@ -0,0 +1,38 @@
|
||||
package utils
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
"net"
|
||||
|
||||
"github.com/9seconds/mtg/v2/network"
|
||||
)
|
||||
|
||||
type Listener struct {
|
||||
net.Listener
|
||||
}
|
||||
|
||||
func (l Listener) Accept() (net.Conn, error) {
|
||||
conn, err := l.Listener.Accept()
|
||||
if err != nil {
|
||||
return nil, err // nolint: wrapcheck
|
||||
}
|
||||
|
||||
if err := network.SetClientSocketOptions(conn, 0); err != nil {
|
||||
conn.Close()
|
||||
|
||||
return nil, fmt.Errorf("cannot set TCP options: %w", err)
|
||||
}
|
||||
|
||||
return conn, nil
|
||||
}
|
||||
|
||||
func NewListener(bindTo string, bufferSize int) (net.Listener, error) {
|
||||
base, err := net.Listen("tcp", bindTo)
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("cannot build a base listener: %w", err)
|
||||
}
|
||||
|
||||
return Listener{
|
||||
Listener: base,
|
||||
}, nil
|
||||
}
|
||||
@@ -1,3 +1,4 @@
|
||||
//go:build !windows
|
||||
// +build !windows
|
||||
|
||||
package utils
|
||||
|
||||
@@ -1,3 +1,4 @@
|
||||
//go:build windows
|
||||
// +build windows
|
||||
|
||||
package utils
|
||||
|
||||
@@ -1,3 +1,4 @@
|
||||
//go:build !windows
|
||||
// +build !windows
|
||||
|
||||
package utils
|
||||
|
||||
@@ -1,3 +1,4 @@
|
||||
//go:build windows
|
||||
// +build windows
|
||||
|
||||
package utils
|
||||
|
||||
@@ -0,0 +1,63 @@
|
||||
package files
|
||||
|
||||
import (
|
||||
"context"
|
||||
"fmt"
|
||||
"io"
|
||||
"net/http"
|
||||
"net/url"
|
||||
)
|
||||
|
||||
type httpFile struct {
|
||||
http *http.Client
|
||||
url string
|
||||
}
|
||||
|
||||
func (h httpFile) Open(ctx context.Context) (io.ReadCloser, error) {
|
||||
request, err := http.NewRequestWithContext(ctx, http.MethodGet, h.url, nil)
|
||||
if err != nil {
|
||||
panic(err)
|
||||
}
|
||||
|
||||
response, err := h.http.Do(request)
|
||||
if err != nil {
|
||||
if response != nil {
|
||||
io.Copy(io.Discard, response.Body) // nolint: errcheck
|
||||
response.Body.Close()
|
||||
}
|
||||
|
||||
return nil, fmt.Errorf("cannot get url %s: %w", h.url, err)
|
||||
}
|
||||
|
||||
if response.StatusCode >= http.StatusBadRequest {
|
||||
return nil, fmt.Errorf("unexpected status code %d", response.StatusCode)
|
||||
}
|
||||
|
||||
return response.Body, nil
|
||||
}
|
||||
|
||||
func (h httpFile) String() string {
|
||||
return h.url
|
||||
}
|
||||
|
||||
func NewHTTP(client *http.Client, endpoint string) (File, error) {
|
||||
if client == nil {
|
||||
return nil, ErrBadHTTPClient
|
||||
}
|
||||
|
||||
parsed, err := url.Parse(endpoint)
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("incorrect url %s: %w", endpoint, err)
|
||||
}
|
||||
|
||||
switch parsed.Scheme {
|
||||
case "http", "https":
|
||||
default:
|
||||
return nil, fmt.Errorf("unsupported url %s", endpoint)
|
||||
}
|
||||
|
||||
return httpFile{
|
||||
http: client,
|
||||
url: endpoint,
|
||||
}, nil
|
||||
}
|
||||
@@ -0,0 +1,90 @@
|
||||
package files_test
|
||||
|
||||
import (
|
||||
"context"
|
||||
"io"
|
||||
"net/http"
|
||||
"net/http/httptest"
|
||||
"strings"
|
||||
"testing"
|
||||
|
||||
"github.com/9seconds/mtg/v2/ipblocklist/files"
|
||||
"github.com/stretchr/testify/suite"
|
||||
)
|
||||
|
||||
type HTTPTestSuite struct {
|
||||
suite.Suite
|
||||
|
||||
httpClient *http.Client
|
||||
httpServer *httptest.Server
|
||||
ctx context.Context
|
||||
ctxCancel context.CancelFunc
|
||||
}
|
||||
|
||||
func (suite *HTTPTestSuite) makeFile(path string) (files.File, error) {
|
||||
return files.NewHTTP(suite.httpClient, suite.httpServer.URL+"/"+path) // nolint: wrapcheck
|
||||
}
|
||||
|
||||
func (suite *HTTPTestSuite) SetupSuite() {
|
||||
mux := http.NewServeMux()
|
||||
|
||||
mux.Handle("/", http.FileServer(http.Dir("testdata")))
|
||||
|
||||
suite.httpServer = httptest.NewServer(mux)
|
||||
suite.httpClient = suite.httpServer.Client()
|
||||
}
|
||||
|
||||
func (suite *HTTPTestSuite) SetupTest() {
|
||||
suite.ctx, suite.ctxCancel = context.WithCancel(context.Background())
|
||||
}
|
||||
|
||||
func (suite *HTTPTestSuite) TearDownTest() {
|
||||
suite.ctxCancel()
|
||||
suite.httpServer.CloseClientConnections()
|
||||
}
|
||||
|
||||
func (suite *HTTPTestSuite) TearDownSuite() {
|
||||
suite.httpServer.Close()
|
||||
}
|
||||
|
||||
func (suite *HTTPTestSuite) TestBadURL() {
|
||||
_, err := files.NewHTTP(suite.httpClient, "sdfsdf")
|
||||
suite.Error(err)
|
||||
}
|
||||
|
||||
func (suite *HTTPTestSuite) TestBadSchema() {
|
||||
_, err := files.NewHTTP(suite.httpClient, "gopher://lala")
|
||||
suite.Error(err)
|
||||
}
|
||||
|
||||
func (suite *HTTPTestSuite) TestNilHTTPClient() {
|
||||
_, err := files.NewHTTP(nil, "")
|
||||
suite.Error(err)
|
||||
}
|
||||
|
||||
func (suite *HTTPTestSuite) TestAbsentFile() {
|
||||
file, err := suite.makeFile("absent")
|
||||
suite.NoError(err)
|
||||
|
||||
_, err = file.Open(suite.ctx)
|
||||
suite.Error(err)
|
||||
}
|
||||
|
||||
func (suite *HTTPTestSuite) TestOk() {
|
||||
file, err := suite.makeFile("readable")
|
||||
suite.NoError(err)
|
||||
|
||||
readCloser, err := file.Open(suite.ctx)
|
||||
suite.NoError(err)
|
||||
|
||||
defer readCloser.Close()
|
||||
|
||||
data, err := io.ReadAll(readCloser)
|
||||
suite.NoError(err)
|
||||
suite.Equal("Hooray!", strings.TrimSpace(string(data)))
|
||||
}
|
||||
|
||||
func TestHTTP(t *testing.T) {
|
||||
t.Parallel()
|
||||
suite.Run(t, &HTTPTestSuite{})
|
||||
}
|
||||
@@ -0,0 +1,14 @@
|
||||
package files
|
||||
|
||||
import (
|
||||
"context"
|
||||
"errors"
|
||||
"io"
|
||||
)
|
||||
|
||||
var ErrBadHTTPClient = errors.New("incorrect http client")
|
||||
|
||||
type File interface {
|
||||
Open(context.Context) (io.ReadCloser, error)
|
||||
String() string
|
||||
}
|
||||
@@ -0,0 +1,30 @@
|
||||
package files
|
||||
|
||||
import (
|
||||
"context"
|
||||
"fmt"
|
||||
"io"
|
||||
"os"
|
||||
)
|
||||
|
||||
type localFile struct {
|
||||
path string
|
||||
}
|
||||
|
||||
func (l localFile) Open(ctx context.Context) (io.ReadCloser, error) {
|
||||
return os.Open(l.path) // nolint: wrapcheck
|
||||
}
|
||||
|
||||
func (l localFile) String() string {
|
||||
return l.path
|
||||
}
|
||||
|
||||
func NewLocal(path string) (File, error) {
|
||||
if stat, err := os.Stat(path); os.IsNotExist(err) || stat.IsDir() || stat.Mode().Perm()&0o400 == 0 {
|
||||
return nil, fmt.Errorf("%s is not a readable file", path)
|
||||
}
|
||||
|
||||
return localFile{
|
||||
path: path,
|
||||
}, nil
|
||||
}
|
||||
@@ -0,0 +1,55 @@
|
||||
package files_test
|
||||
|
||||
import (
|
||||
"context"
|
||||
"io"
|
||||
"path/filepath"
|
||||
"strings"
|
||||
"testing"
|
||||
|
||||
"github.com/9seconds/mtg/v2/ipblocklist/files"
|
||||
"github.com/stretchr/testify/assert"
|
||||
"github.com/stretchr/testify/suite"
|
||||
)
|
||||
|
||||
type LocalTestSuite struct {
|
||||
suite.Suite
|
||||
}
|
||||
|
||||
func (suite *LocalTestSuite) getLocalFile(name string) string {
|
||||
return filepath.Join("testdata", name)
|
||||
}
|
||||
|
||||
func (suite *LocalTestSuite) TestIncorrect() {
|
||||
names := []string{
|
||||
"absent",
|
||||
"directory",
|
||||
}
|
||||
|
||||
for _, v := range names {
|
||||
value := v
|
||||
|
||||
suite.T().Run(v, func(t *testing.T) {
|
||||
_, err := files.NewLocal(suite.getLocalFile(value))
|
||||
assert.Error(t, err)
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
func (suite *LocalTestSuite) TestOk() {
|
||||
file, err := files.NewLocal(suite.getLocalFile("readable"))
|
||||
suite.NoError(err)
|
||||
|
||||
reader, err := file.Open(context.Background())
|
||||
suite.NoError(err)
|
||||
|
||||
data, err := io.ReadAll(reader)
|
||||
suite.NoError(err)
|
||||
|
||||
suite.Equal("Hooray!", strings.TrimSpace(string(data)))
|
||||
}
|
||||
|
||||
func TestLocal(t *testing.T) {
|
||||
t.Parallel()
|
||||
suite.Run(t, &LocalTestSuite{})
|
||||
}
|
||||
@@ -0,0 +1,37 @@
|
||||
package files
|
||||
|
||||
import (
|
||||
"context"
|
||||
"io"
|
||||
"net"
|
||||
"strings"
|
||||
)
|
||||
|
||||
type memFile struct {
|
||||
data string
|
||||
}
|
||||
|
||||
func (m memFile) Open(ctx context.Context) (io.ReadCloser, error) {
|
||||
return io.NopCloser(strings.NewReader(m.data)), nil
|
||||
}
|
||||
|
||||
func (m memFile) String() string {
|
||||
return "mem"
|
||||
}
|
||||
|
||||
func NewMem(networks []*net.IPNet) File {
|
||||
builder := strings.Builder{}
|
||||
|
||||
if len(networks) > 0 {
|
||||
builder.WriteString(networks[0].String())
|
||||
}
|
||||
|
||||
for i := 1; i < len(networks); i++ {
|
||||
builder.WriteString("\n")
|
||||
builder.WriteString(networks[i].String())
|
||||
}
|
||||
|
||||
return memFile{
|
||||
data: builder.String(),
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,42 @@
|
||||
package files_test
|
||||
|
||||
import (
|
||||
"context"
|
||||
"io"
|
||||
"net"
|
||||
"strings"
|
||||
"testing"
|
||||
|
||||
"github.com/9seconds/mtg/v2/ipblocklist/files"
|
||||
"github.com/stretchr/testify/suite"
|
||||
)
|
||||
|
||||
type MemTestSuite struct {
|
||||
suite.Suite
|
||||
}
|
||||
|
||||
func (suite *MemTestSuite) TestOk() {
|
||||
_, network1, _ := net.ParseCIDR("192.168.0.1/24")
|
||||
_, network2, _ := net.ParseCIDR("2001:0db8:85a3:0000:0000:8a2e:0370:7334/36")
|
||||
|
||||
file := files.NewMem([]*net.IPNet{
|
||||
network1,
|
||||
network2,
|
||||
})
|
||||
|
||||
reader, err := file.Open(context.Background())
|
||||
suite.NoError(err)
|
||||
|
||||
data, err := io.ReadAll(reader)
|
||||
suite.NoError(err)
|
||||
|
||||
strData := strings.TrimSpace(string(data))
|
||||
|
||||
suite.Contains(strData, "192.168.0.0/24")
|
||||
suite.Contains(strData, "2001:db8:8000::/36")
|
||||
}
|
||||
|
||||
func TestMem(t *testing.T) {
|
||||
t.Parallel()
|
||||
suite.Run(t, &MemTestSuite{})
|
||||
}
|
||||
Vendored
+1
@@ -0,0 +1 @@
|
||||
Hooray!
|
||||
+115
-218
@@ -4,28 +4,28 @@ import (
|
||||
"bufio"
|
||||
"context"
|
||||
"fmt"
|
||||
"io"
|
||||
"net"
|
||||
"net/http"
|
||||
"net/url"
|
||||
"os"
|
||||
"regexp"
|
||||
"strings"
|
||||
"sync"
|
||||
"time"
|
||||
|
||||
"github.com/9seconds/mtg/v2/ipblocklist/files"
|
||||
"github.com/9seconds/mtg/v2/mtglib"
|
||||
"github.com/kentik/patricia"
|
||||
"github.com/kentik/patricia/bool_tree"
|
||||
"github.com/panjf2000/ants/v2"
|
||||
"github.com/yl2chen/cidranger"
|
||||
)
|
||||
|
||||
const (
|
||||
fireholIPv4DefaultCIDR = 32
|
||||
fireholIPv6DefaultCIDR = 128
|
||||
var (
|
||||
fireholRegexpComment = regexp.MustCompile(`\s*#.*?$`)
|
||||
|
||||
fireholIPv4DefaultCIDR = net.CIDRMask(32, 32) // nolint: gomnd
|
||||
fireholIPv6DefaultCIDR = net.CIDRMask(128, 128) // nolint: gomnd
|
||||
)
|
||||
|
||||
var fireholRegexpComment = regexp.MustCompile(`\s*#.*?$`)
|
||||
// FireholUpdateCallback defines a signature of the callback that has to be
|
||||
// execute when ip list is updated.
|
||||
type FireholUpdateCallback func(context.Context, int)
|
||||
|
||||
// Firehol is IPBlocklist which uses lists from FireHOL:
|
||||
// https://iplists.firehol.org/
|
||||
@@ -41,20 +41,17 @@ var fireholRegexpComment = regexp.MustCompile(`\s*#.*?$`)
|
||||
// 127.0.0.1 # you can specify an IP
|
||||
// 10.0.0.0/8 # or cidr
|
||||
type Firehol struct {
|
||||
ctx context.Context
|
||||
ctxCancel context.CancelFunc
|
||||
logger mtglib.Logger
|
||||
ctx context.Context
|
||||
ctxCancel context.CancelFunc
|
||||
logger mtglib.Logger
|
||||
updateMutex sync.RWMutex
|
||||
|
||||
rwMutex sync.RWMutex
|
||||
updateCallback FireholUpdateCallback
|
||||
ranger cidranger.Ranger
|
||||
|
||||
remoteURLs []string
|
||||
localFiles []string
|
||||
blocklists []files.File
|
||||
|
||||
httpClient *http.Client
|
||||
workerPool *ants.Pool
|
||||
|
||||
treeV4 *bool_tree.TreeV4
|
||||
treeV6 *bool_tree.TreeV6
|
||||
}
|
||||
|
||||
// Shutdown stop a background update process.
|
||||
@@ -68,14 +65,15 @@ func (f *Firehol) Contains(ip net.IP) bool {
|
||||
return true
|
||||
}
|
||||
|
||||
f.rwMutex.RLock()
|
||||
defer f.rwMutex.RUnlock()
|
||||
f.updateMutex.RLock()
|
||||
defer f.updateMutex.RUnlock()
|
||||
|
||||
if ip4 := ip.To4(); ip4 != nil {
|
||||
return f.containsIPv4(ip4)
|
||||
ok, err := f.ranger.Contains(ip)
|
||||
if err != nil {
|
||||
f.logger.BindStr("ip", ip.String()).DebugError("Cannot check if ip is present", err)
|
||||
}
|
||||
|
||||
return f.containsIPv6(ip.To16())
|
||||
return ok && err == nil
|
||||
}
|
||||
|
||||
// Run starts a background update process.
|
||||
@@ -98,161 +96,67 @@ func (f *Firehol) Run(updateEach time.Duration) {
|
||||
}
|
||||
}()
|
||||
|
||||
if err := f.update(); err != nil {
|
||||
f.logger.WarningError("cannot update blocklist", err)
|
||||
} else {
|
||||
f.logger.Info("blocklist was updated")
|
||||
}
|
||||
f.update()
|
||||
|
||||
for {
|
||||
select {
|
||||
case <-f.ctx.Done():
|
||||
return
|
||||
case <-ticker.C:
|
||||
if err := f.update(); err != nil {
|
||||
f.logger.WarningError("cannot update blocklist", err)
|
||||
} else {
|
||||
f.logger.Info("blocklist was updated")
|
||||
}
|
||||
f.update()
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func (f *Firehol) containsIPv4(addr net.IP) bool {
|
||||
ip := patricia.NewIPv4AddressFromBytes(addr, 32) // nolint: gomnd
|
||||
|
||||
if ok, _, err := f.treeV4.FindDeepestTag(ip); ok && err == nil {
|
||||
return true
|
||||
}
|
||||
|
||||
return false
|
||||
}
|
||||
|
||||
func (f *Firehol) containsIPv6(addr net.IP) bool {
|
||||
ip := patricia.NewIPv6Address(addr, 128) // nolint: gomnd
|
||||
|
||||
if ok, _, err := f.treeV6.FindDeepestTag(ip); ok && err == nil {
|
||||
return true
|
||||
}
|
||||
|
||||
return false
|
||||
}
|
||||
|
||||
func (f *Firehol) update() error { // nolint: funlen, cyclop
|
||||
func (f *Firehol) update() {
|
||||
ctx, cancel := context.WithCancel(f.ctx)
|
||||
defer cancel()
|
||||
|
||||
wg := &sync.WaitGroup{}
|
||||
wg.Add(len(f.remoteURLs) + len(f.localFiles))
|
||||
wg.Add(len(f.blocklists))
|
||||
|
||||
treeMutex := &sync.Mutex{}
|
||||
v4tree := bool_tree.NewTreeV4()
|
||||
v6tree := bool_tree.NewTreeV6()
|
||||
mutex := &sync.Mutex{}
|
||||
ranger := cidranger.NewPCTrieRanger()
|
||||
|
||||
errorChan := make(chan error, 1)
|
||||
defer close(errorChan)
|
||||
|
||||
for _, v := range f.localFiles {
|
||||
go func(filename string) {
|
||||
for _, v := range f.blocklists {
|
||||
go func(file files.File) {
|
||||
defer wg.Done()
|
||||
|
||||
if err := f.updateLocalFile(ctx, filename, treeMutex, v4tree, v6tree); err != nil {
|
||||
cancel()
|
||||
f.logger.BindStr("filename", filename).WarningError("cannot update", err)
|
||||
logger := f.logger.BindStr("filename", file.String())
|
||||
|
||||
select {
|
||||
case errorChan <- err:
|
||||
default:
|
||||
}
|
||||
fileContent, err := file.Open(ctx)
|
||||
if err != nil {
|
||||
logger.WarningError("update has failed", err)
|
||||
|
||||
return
|
||||
}
|
||||
|
||||
defer fileContent.Close()
|
||||
|
||||
if err := f.updateFromFile(mutex, ranger, bufio.NewScanner(fileContent)); err != nil {
|
||||
logger.WarningError("update has failed", err)
|
||||
}
|
||||
}(v)
|
||||
}
|
||||
|
||||
for _, v := range f.remoteURLs {
|
||||
value := v
|
||||
|
||||
f.workerPool.Submit(func() { // nolint: errcheck
|
||||
defer wg.Done()
|
||||
|
||||
if err := f.updateRemoteURL(ctx, value, treeMutex, v4tree, v6tree); err != nil {
|
||||
cancel()
|
||||
f.logger.BindStr("url", value).WarningError("cannot update", err)
|
||||
|
||||
select {
|
||||
case errorChan <- err:
|
||||
default:
|
||||
}
|
||||
}
|
||||
})
|
||||
}
|
||||
|
||||
wg.Wait()
|
||||
|
||||
select {
|
||||
case err := <-errorChan:
|
||||
return fmt.Errorf("cannot update trees: %w", err)
|
||||
default:
|
||||
f.updateMutex.Lock()
|
||||
defer f.updateMutex.Unlock()
|
||||
|
||||
f.ranger = ranger
|
||||
|
||||
if f.updateCallback != nil {
|
||||
f.updateCallback(ctx, ranger.Len())
|
||||
}
|
||||
|
||||
f.rwMutex.Lock()
|
||||
defer f.rwMutex.Unlock()
|
||||
|
||||
f.treeV4 = v4tree
|
||||
f.treeV6 = v6tree
|
||||
|
||||
return nil
|
||||
f.logger.Info("ip list was updated")
|
||||
}
|
||||
|
||||
func (f *Firehol) updateLocalFile(ctx context.Context, filename string,
|
||||
mutex sync.Locker,
|
||||
v4tree *bool_tree.TreeV4, v6tree *bool_tree.TreeV6) error {
|
||||
filefp, err := os.Open(filename)
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot open file: %w", err)
|
||||
}
|
||||
|
||||
go func(ctx context.Context, closer io.Closer) {
|
||||
<-ctx.Done()
|
||||
closer.Close()
|
||||
}(ctx, filefp)
|
||||
|
||||
defer filefp.Close()
|
||||
|
||||
return f.updateTrees(mutex, filefp, v4tree, v6tree)
|
||||
}
|
||||
|
||||
func (f *Firehol) updateRemoteURL(ctx context.Context, url string,
|
||||
mutex sync.Locker,
|
||||
v4tree *bool_tree.TreeV4, v6tree *bool_tree.TreeV6) error {
|
||||
req, err := http.NewRequestWithContext(ctx, http.MethodGet, url, nil)
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot build a request: %w", err)
|
||||
}
|
||||
|
||||
resp, err := f.httpClient.Do(req) // nolint: bodyclose
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot request a remote URL %s: %w", url, err)
|
||||
}
|
||||
|
||||
go func(ctx context.Context, closer io.Closer) {
|
||||
<-ctx.Done()
|
||||
closer.Close()
|
||||
}(ctx, resp.Body)
|
||||
|
||||
defer func(rc io.ReadCloser) {
|
||||
io.Copy(io.Discard, rc) // nolint: errcheck
|
||||
rc.Close()
|
||||
}(resp.Body)
|
||||
|
||||
return f.updateTrees(mutex, resp.Body, v4tree, v6tree)
|
||||
}
|
||||
|
||||
func (f *Firehol) updateTrees(mutex sync.Locker,
|
||||
reader io.Reader,
|
||||
v4tree *bool_tree.TreeV4,
|
||||
v6tree *bool_tree.TreeV6) error {
|
||||
scanner := bufio.NewScanner(reader)
|
||||
|
||||
func (f *Firehol) updateFromFile(mutex sync.Locker,
|
||||
ranger cidranger.Ranger,
|
||||
scanner *bufio.Scanner,
|
||||
) error {
|
||||
for scanner.Scan() {
|
||||
text := scanner.Text()
|
||||
text = fireholRegexpComment.ReplaceAllLiteralString(text, "")
|
||||
@@ -262,65 +166,47 @@ func (f *Firehol) updateTrees(mutex sync.Locker,
|
||||
continue
|
||||
}
|
||||
|
||||
ip, cidr, err := f.updateParseLine(text)
|
||||
ipnet, err := f.updateParseLine(text)
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot parse a line: %w", err)
|
||||
}
|
||||
|
||||
if err := f.updateAddToTrees(ip, cidr, mutex, v4tree, v6tree); err != nil {
|
||||
return fmt.Errorf("cannot add a node to the tree: %w", err)
|
||||
mutex.Lock()
|
||||
err = ranger.Insert(cidranger.NewBasicRangerEntry(*ipnet))
|
||||
mutex.Unlock()
|
||||
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot insert %v into ranger: %w", ipnet, err)
|
||||
}
|
||||
}
|
||||
|
||||
if scanner.Err() != nil {
|
||||
return fmt.Errorf("cannot parse a response: %w", scanner.Err())
|
||||
return fmt.Errorf("cannot parse a file: %w", scanner.Err())
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
func (f *Firehol) updateParseLine(text string) (net.IP, uint, error) {
|
||||
_, ipnet, err := net.ParseCIDR(text)
|
||||
if err != nil {
|
||||
ipaddr := net.ParseIP(text)
|
||||
if ipaddr == nil {
|
||||
return nil, 0, fmt.Errorf("incorrect ip address %s", text)
|
||||
}
|
||||
|
||||
ip4 := ipaddr.To4()
|
||||
if ip4 != nil {
|
||||
return ip4, fireholIPv4DefaultCIDR, nil
|
||||
}
|
||||
|
||||
return ipaddr.To16(), fireholIPv6DefaultCIDR, nil
|
||||
func (f *Firehol) updateParseLine(text string) (*net.IPNet, error) {
|
||||
if _, ipnet, err := net.ParseCIDR(text); err == nil {
|
||||
return ipnet, nil
|
||||
}
|
||||
|
||||
ones, _ := ipnet.Mask.Size()
|
||||
|
||||
return ipnet.IP, uint(ones), nil
|
||||
}
|
||||
|
||||
func (f *Firehol) updateAddToTrees(ip net.IP, cidr uint,
|
||||
mutex sync.Locker,
|
||||
v4tree *bool_tree.TreeV4, v6tree *bool_tree.TreeV6) error {
|
||||
mutex.Lock()
|
||||
defer mutex.Unlock()
|
||||
|
||||
if ip.To4() != nil {
|
||||
addr := patricia.NewIPv4AddressFromBytes(ip, cidr)
|
||||
|
||||
if _, _, err := v4tree.Set(addr, true); err != nil {
|
||||
return err // nolint: wrapcheck
|
||||
}
|
||||
} else {
|
||||
addr := patricia.NewIPv6Address(ip, cidr)
|
||||
|
||||
if _, _, err := v6tree.Set(addr, true); err != nil {
|
||||
return err // nolint: wrapcheck
|
||||
}
|
||||
ipaddr := net.ParseIP(text)
|
||||
if ipaddr == nil {
|
||||
return nil, fmt.Errorf("incorrect ip address %s", text)
|
||||
}
|
||||
|
||||
return nil
|
||||
mask := fireholIPv4DefaultCIDR
|
||||
|
||||
if ipaddr.To4() == nil {
|
||||
mask = fireholIPv6DefaultCIDR
|
||||
}
|
||||
|
||||
return &net.IPNet{
|
||||
IP: ipaddr,
|
||||
Mask: mask,
|
||||
}, nil
|
||||
}
|
||||
|
||||
// NewFirehol creates a new instance of FireHOL IP blocklist.
|
||||
@@ -329,27 +215,40 @@ func (f *Firehol) updateAddToTrees(ip net.IP, cidr uint,
|
||||
// when it is necessary.
|
||||
func NewFirehol(logger mtglib.Logger, network mtglib.Network,
|
||||
downloadConcurrency uint,
|
||||
remoteURLs []string,
|
||||
localFiles []string) (*Firehol, error) {
|
||||
for _, v := range remoteURLs {
|
||||
parsed, err := url.Parse(v)
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("incorrect url %s: %w", v, err)
|
||||
}
|
||||
|
||||
switch parsed.Scheme {
|
||||
case "http", "https":
|
||||
default:
|
||||
return nil, fmt.Errorf("unsupported url %s", v)
|
||||
}
|
||||
}
|
||||
urls []string,
|
||||
localFiles []string,
|
||||
updateCallback FireholUpdateCallback,
|
||||
) (*Firehol, error) {
|
||||
blocklists := []files.File{}
|
||||
|
||||
for _, v := range localFiles {
|
||||
if stat, err := os.Stat(v); os.IsNotExist(err) || stat.IsDir() || stat.Mode().Perm()&0o400 == 0 {
|
||||
return nil, fmt.Errorf("%s is not a readable file", v)
|
||||
file, err := files.NewLocal(v)
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("cannot create a local file %s: %w", v, err)
|
||||
}
|
||||
|
||||
blocklists = append(blocklists, file)
|
||||
}
|
||||
|
||||
httpClient := network.MakeHTTPClient(nil)
|
||||
|
||||
for _, v := range urls {
|
||||
file, err := files.NewHTTP(httpClient, v)
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("cannot create a HTTP file %s: %w", v, err)
|
||||
}
|
||||
|
||||
blocklists = append(blocklists, file)
|
||||
}
|
||||
|
||||
return NewFireholFromFiles(logger, downloadConcurrency, blocklists, updateCallback)
|
||||
}
|
||||
|
||||
func NewFireholFromFiles(logger mtglib.Logger,
|
||||
downloadConcurrency uint,
|
||||
blocklists []files.File,
|
||||
updateCallback FireholUpdateCallback,
|
||||
) (*Firehol, error) {
|
||||
if downloadConcurrency == 0 {
|
||||
downloadConcurrency = DefaultFireholDownloadConcurrency
|
||||
}
|
||||
@@ -358,14 +257,12 @@ func NewFirehol(logger mtglib.Logger, network mtglib.Network,
|
||||
ctx, cancel := context.WithCancel(context.Background())
|
||||
|
||||
return &Firehol{
|
||||
ctx: ctx,
|
||||
ctxCancel: cancel,
|
||||
logger: logger.Named("firehol"),
|
||||
httpClient: network.MakeHTTPClient(nil),
|
||||
treeV4: bool_tree.NewTreeV4(),
|
||||
treeV6: bool_tree.NewTreeV6(),
|
||||
workerPool: workerPool,
|
||||
remoteURLs: remoteURLs,
|
||||
localFiles: localFiles,
|
||||
ctx: ctx,
|
||||
ctxCancel: cancel,
|
||||
logger: logger.Named("firehol"),
|
||||
ranger: cidranger.NewPCTrieRanger(),
|
||||
workerPool: workerPool,
|
||||
blocklists: blocklists,
|
||||
updateCallback: updateCallback,
|
||||
}, nil
|
||||
}
|
||||
|
||||
@@ -67,7 +67,8 @@ func (suite *FireholTestSuite) TearDownSuite() {
|
||||
func (suite *FireholTestSuite) TestLocalFail() {
|
||||
blocklist, err := ipblocklist.NewFirehol(logger.NewNoopLogger(),
|
||||
suite.networkMock, 2,
|
||||
nil, []string{filepath.Join("testdata", "broken_ipset.ipset")})
|
||||
nil, []string{filepath.Join("testdata", "broken_ipset.ipset")},
|
||||
nil)
|
||||
|
||||
suite.NoError(err)
|
||||
|
||||
@@ -85,7 +86,8 @@ func (suite *FireholTestSuite) TestLocalFail() {
|
||||
func (suite *FireholTestSuite) TestLocalOk() {
|
||||
blocklist, err := ipblocklist.NewFirehol(logger.NewNoopLogger(),
|
||||
suite.networkMock, 2,
|
||||
nil, []string{filepath.Join("testdata", "good_ipset.ipset")})
|
||||
nil, []string{filepath.Join("testdata", "good_ipset.ipset")},
|
||||
nil)
|
||||
|
||||
suite.NoError(err)
|
||||
|
||||
@@ -103,7 +105,7 @@ func (suite *FireholTestSuite) TestLocalOk() {
|
||||
func (suite *FireholTestSuite) TestRemoteFail() {
|
||||
blocklist, err := ipblocklist.NewFirehol(logger.NewNoopLogger(),
|
||||
suite.networkMock, 2,
|
||||
[]string{"https://google.com"}, nil)
|
||||
[]string{"https://google.com"}, nil, nil)
|
||||
|
||||
suite.NoError(err)
|
||||
|
||||
@@ -127,7 +129,7 @@ func (suite *FireholTestSuite) TestMixed() {
|
||||
suite.httpServer.URL,
|
||||
}, []string{
|
||||
filepath.Join("testdata", "good_ipset.ipset"),
|
||||
})
|
||||
}, nil)
|
||||
|
||||
suite.NoError(err)
|
||||
|
||||
|
||||
+4
-1
@@ -2,13 +2,16 @@ package ipblocklist
|
||||
|
||||
import (
|
||||
"net"
|
||||
"time"
|
||||
|
||||
"github.com/9seconds/mtg/v2/mtglib"
|
||||
)
|
||||
|
||||
type noop struct{}
|
||||
|
||||
func (n noop) Contains(ip net.IP) bool { return false }
|
||||
func (n noop) Contains(ip net.IP) bool { return false }
|
||||
func (n noop) Run(updateEach time.Duration) {}
|
||||
func (n noop) Shutdown() {}
|
||||
|
||||
// NewNoop returns a dummy ipblocklist which allows all incoming
|
||||
// connections.
|
||||
|
||||
@@ -17,6 +17,13 @@ func (suite *NoopTestSuite) TestOp() {
|
||||
suite.False(ipblocklist.NewNoop().Contains(net.ParseIP("10.0.0.10")))
|
||||
}
|
||||
|
||||
func (suite *NoopTestSuite) TestRun() {
|
||||
blocklist := ipblocklist.NewNoop()
|
||||
|
||||
blocklist.Run(0)
|
||||
blocklist.Shutdown()
|
||||
}
|
||||
|
||||
func TestNoop(t *testing.T) {
|
||||
t.Parallel()
|
||||
suite.Run(t, &NoopTestSuite{})
|
||||
|
||||
@@ -7,6 +7,7 @@ type noopLogger struct{}
|
||||
func (n noopLogger) Named(_ string) mtglib.Logger { return n }
|
||||
func (n noopLogger) BindInt(_ string, _ int) mtglib.Logger { return n }
|
||||
func (n noopLogger) BindStr(_, _ string) mtglib.Logger { return n }
|
||||
func (n noopLogger) BindJSON(_, _ string) mtglib.Logger { return n }
|
||||
func (n noopLogger) Printf(_ string, _ ...interface{}) {}
|
||||
func (n noopLogger) Info(_ string) {}
|
||||
func (n noopLogger) Warning(_ string) {}
|
||||
|
||||
@@ -15,6 +15,7 @@ const (
|
||||
zeroLogContextVarTypeUnknown zeroLogContextVarType = iota
|
||||
zeroLogContextVarTypeStr
|
||||
zeroLogContextVarTypeInt
|
||||
zeroLogContextVarTypeJSON
|
||||
)
|
||||
|
||||
type zeroLogContext struct {
|
||||
@@ -66,6 +67,17 @@ func (z *zeroLogContext) BindStr(name, value string) mtglib.Logger {
|
||||
}
|
||||
}
|
||||
|
||||
func (z *zeroLogContext) BindJSON(name, value string) mtglib.Logger {
|
||||
return &zeroLogContext{
|
||||
name: z.name,
|
||||
log: z.log,
|
||||
ctxVarType: zeroLogContextVarTypeJSON,
|
||||
ctxVarName: name,
|
||||
ctxVarStr: value,
|
||||
parent: z,
|
||||
}
|
||||
}
|
||||
|
||||
func (z *zeroLogContext) Printf(format string, args ...interface{}) {
|
||||
z.Debug(fmt.Sprintf(format, args...))
|
||||
}
|
||||
@@ -110,6 +122,8 @@ func (z *zeroLogContext) attachCtx(evt *zerolog.Event) {
|
||||
evt.Str(z.ctxVarName, z.ctxVarStr)
|
||||
case zeroLogContextVarTypeInt:
|
||||
evt.Int(z.ctxVarName, z.ctxVarInt)
|
||||
case zeroLogContextVarTypeJSON:
|
||||
evt.RawJSON(z.ctxVarName, []byte(z.ctxVarStr))
|
||||
case zeroLogContextVarTypeUnknown:
|
||||
}
|
||||
}
|
||||
|
||||
@@ -9,7 +9,10 @@
|
||||
package main
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
"math/rand"
|
||||
"runtime/debug"
|
||||
"strconv"
|
||||
"time"
|
||||
|
||||
"github.com/9seconds/mtg/v2/internal/cli"
|
||||
@@ -26,6 +29,32 @@ func main() {
|
||||
panic(err)
|
||||
}
|
||||
|
||||
if buildInfo, ok := debug.ReadBuildInfo(); ok {
|
||||
vcsCommit := "<no-commit>"
|
||||
vcsDate := time.Now()
|
||||
vcsDirty := ""
|
||||
|
||||
for _, setting := range buildInfo.Settings {
|
||||
switch setting.Key {
|
||||
case "vcs.time":
|
||||
vcsDate, _ = time.Parse(time.RFC3339, setting.Value)
|
||||
case "vcs.revision":
|
||||
vcsCommit = setting.Value
|
||||
case "vcs.modified":
|
||||
if isDirty, _ := strconv.ParseBool(setting.Value); isDirty {
|
||||
vcsDirty = " [dirty]"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
version = fmt.Sprintf("%s (%s: %s on %s%s)",
|
||||
version,
|
||||
buildInfo.GoVersion,
|
||||
vcsDate.Format(time.RFC3339),
|
||||
vcsCommit,
|
||||
vcsDirty)
|
||||
}
|
||||
|
||||
cli := &cli.CLI{}
|
||||
ctx := kong.Parse(cli, kong.Vars{
|
||||
"version": version,
|
||||
|
||||
+5
-4
@@ -4,12 +4,13 @@ import (
|
||||
"bytes"
|
||||
"context"
|
||||
"io"
|
||||
"net"
|
||||
"sync"
|
||||
|
||||
"github.com/9seconds/mtg/v2/essentials"
|
||||
)
|
||||
|
||||
type connTraffic struct {
|
||||
net.Conn
|
||||
essentials.Conn
|
||||
|
||||
streamID string
|
||||
stream EventStream
|
||||
@@ -37,7 +38,7 @@ func (c connTraffic) Write(b []byte) (int, error) {
|
||||
}
|
||||
|
||||
type connRewind struct {
|
||||
net.Conn
|
||||
essentials.Conn
|
||||
|
||||
active io.Reader
|
||||
buf bytes.Buffer
|
||||
@@ -58,7 +59,7 @@ func (c *connRewind) Rewind() {
|
||||
c.active = io.MultiReader(&c.buf, c.Conn)
|
||||
}
|
||||
|
||||
func newConnRewind(conn net.Conn) *connRewind {
|
||||
func newConnRewind(conn essentials.Conn) *connRewind {
|
||||
rv := &connRewind{
|
||||
Conn: conn,
|
||||
}
|
||||
|
||||
@@ -14,7 +14,7 @@ import (
|
||||
)
|
||||
|
||||
type ConnRewindBaseConn struct {
|
||||
testlib.NetConnMock
|
||||
testlib.EssentialsConnMock
|
||||
|
||||
readBuffer bytes.Buffer
|
||||
}
|
||||
@@ -29,13 +29,13 @@ type ConnTrafficTestSuite struct {
|
||||
suite.Suite
|
||||
|
||||
eventStreamMock *EventStreamMock
|
||||
connMock *testlib.NetConnMock
|
||||
connMock *testlib.EssentialsConnMock
|
||||
conn io.ReadWriter
|
||||
}
|
||||
|
||||
func (suite *ConnTrafficTestSuite) SetupTest() {
|
||||
suite.eventStreamMock = &EventStreamMock{}
|
||||
suite.connMock = &testlib.NetConnMock{}
|
||||
suite.connMock = &testlib.EssentialsConnMock{}
|
||||
suite.conn = connTraffic{
|
||||
Conn: suite.connMock,
|
||||
streamID: "CONNID",
|
||||
|
||||
+36
-2
@@ -83,7 +83,8 @@ type EventConcurrencyLimited struct {
|
||||
type EventIPBlocklisted struct {
|
||||
eventBase
|
||||
|
||||
RemoteIP net.IP
|
||||
RemoteIP net.IP
|
||||
IsBlockList bool
|
||||
}
|
||||
|
||||
// EventReplayAttack is emitted when mtg detects a replay attack on a
|
||||
@@ -92,6 +93,15 @@ type EventReplayAttack struct {
|
||||
eventBase
|
||||
}
|
||||
|
||||
// EventIPListSize is emitted when mtg updates a contents of the ip lists:
|
||||
// allowlist or blocklist.
|
||||
type EventIPListSize struct {
|
||||
eventBase
|
||||
|
||||
Size int
|
||||
IsBlockList bool
|
||||
}
|
||||
|
||||
// NewEventStart creates a new EventStart event.
|
||||
func NewEventStart(streamID string, remoteIP net.IP) EventStart {
|
||||
return EventStart{
|
||||
@@ -163,7 +173,20 @@ func NewEventIPBlocklisted(remoteIP net.IP) EventIPBlocklisted {
|
||||
eventBase: eventBase{
|
||||
timestamp: time.Now(),
|
||||
},
|
||||
RemoteIP: remoteIP,
|
||||
RemoteIP: remoteIP,
|
||||
IsBlockList: true,
|
||||
}
|
||||
}
|
||||
|
||||
// NewEventIPAllowlisted creates a NewEventIPBlocklisted event with a mark that
|
||||
// it is supposed to be for allow list.
|
||||
func NewEventIPAllowlisted(remoteIP net.IP) EventIPBlocklisted {
|
||||
return EventIPBlocklisted{
|
||||
eventBase: eventBase{
|
||||
timestamp: time.Now(),
|
||||
},
|
||||
RemoteIP: remoteIP,
|
||||
IsBlockList: false,
|
||||
}
|
||||
}
|
||||
|
||||
@@ -176,3 +199,14 @@ func NewEventReplayAttack(streamID string) EventReplayAttack {
|
||||
},
|
||||
}
|
||||
}
|
||||
|
||||
// NewEventIPListSize creates a new EventIPListSize event.
|
||||
func NewEventIPListSize(size int, isBlockList bool) EventIPListSize {
|
||||
return EventIPListSize{
|
||||
eventBase: eventBase{
|
||||
timestamp: time.Now(),
|
||||
},
|
||||
Size: size,
|
||||
IsBlockList: isBlockList,
|
||||
}
|
||||
}
|
||||
|
||||
@@ -60,6 +60,15 @@ func (suite *EventsTestSuite) TestEventIPBlocklisted() {
|
||||
|
||||
suite.Empty(evt.StreamID())
|
||||
suite.WithinDuration(time.Now(), evt.Timestamp(), 10*time.Millisecond)
|
||||
suite.True(evt.IsBlockList)
|
||||
}
|
||||
|
||||
func (suite *EventsTestSuite) TestEventIPAllowlisted() {
|
||||
evt := mtglib.NewEventIPAllowlisted(net.ParseIP("10.0.0.10"))
|
||||
|
||||
suite.Empty(evt.StreamID())
|
||||
suite.WithinDuration(time.Now(), evt.Timestamp(), 10*time.Millisecond)
|
||||
suite.False(evt.IsBlockList)
|
||||
}
|
||||
|
||||
func (suite *EventsTestSuite) TestEventReplayAttack() {
|
||||
@@ -69,6 +78,15 @@ func (suite *EventsTestSuite) TestEventReplayAttack() {
|
||||
suite.WithinDuration(time.Now(), evt.Timestamp(), 10*time.Millisecond)
|
||||
}
|
||||
|
||||
func (suite *EventsTestSuite) TestEventIPListSize() {
|
||||
evt := mtglib.NewEventIPListSize(10, false)
|
||||
|
||||
suite.Empty(evt.StreamID())
|
||||
suite.WithinDuration(time.Now(), evt.Timestamp(), 10*time.Millisecond)
|
||||
suite.Equal(10, evt.Size)
|
||||
suite.False(evt.IsBlockList)
|
||||
}
|
||||
|
||||
func TestEvents(t *testing.T) {
|
||||
t.Parallel()
|
||||
suite.Run(t, &EventsTestSuite{})
|
||||
|
||||
+30
-5
@@ -23,6 +23,8 @@ import (
|
||||
"net"
|
||||
"net/http"
|
||||
"time"
|
||||
|
||||
"github.com/9seconds/mtg/v2/essentials"
|
||||
)
|
||||
|
||||
var (
|
||||
@@ -46,6 +48,10 @@ var (
|
||||
// create a proxy but ip blocklist instance is not defined.
|
||||
ErrIPBlocklistIsNotDefined = errors.New("ip blocklist is not defined")
|
||||
|
||||
// ErrIPAllowlistIsNotDefined is returned if you are trying to
|
||||
// create a proxy but ip allowlist instance is not defined.
|
||||
ErrIPAllowlistIsNotDefined = errors.New("ip allowlist is not defined")
|
||||
|
||||
// ErrEventStreamIsNotDefined is returned if you are trying to create a
|
||||
// proxy but event stream instance is not defined.
|
||||
ErrEventStreamIsNotDefined = errors.New("event stream is not defined")
|
||||
@@ -61,6 +67,8 @@ const (
|
||||
DefaultConcurrency = 4096
|
||||
|
||||
// DefaultBufferSize is a default size of a copy buffer.
|
||||
//
|
||||
// Deprecated: this setting no longer makes any effect.
|
||||
DefaultBufferSize = 16 * 1024 // 16 kib
|
||||
|
||||
// DefaultDomainFrontingPort is a default port (HTTPS) to connect to in
|
||||
@@ -69,6 +77,9 @@ const (
|
||||
|
||||
// DefaultIdleTimeout is a default timeout for closing a connection
|
||||
// in case of idling.
|
||||
//
|
||||
// Deprecated: no longer in use because of changed TCP relay
|
||||
// algorithm.
|
||||
DefaultIdleTimeout = time.Minute
|
||||
|
||||
// DefaultTolerateTimeSkewness is a default timeout for time
|
||||
@@ -83,9 +94,14 @@ const (
|
||||
// by Telegram and a proxy.
|
||||
SecretKeyLength = 16
|
||||
|
||||
// ConnectionIDBytesLength defines a count of random bytes
|
||||
// used to generate a stream/connection ids.
|
||||
// ConnectionIDBytesLength defines a count of random bytes used to generate
|
||||
// a stream/connection ids.
|
||||
ConnectionIDBytesLength = 16
|
||||
|
||||
// TCPRelayReadTimeout defines a max time period between two consecuitive
|
||||
// reads from Telegram after which connection will be terminated. This is
|
||||
// required to abort stale connections.
|
||||
TCPRelayReadTimeout = 20 * time.Second
|
||||
)
|
||||
|
||||
// Network defines a knowledge how to work with a network. It may sound
|
||||
@@ -106,16 +122,16 @@ const (
|
||||
// 3. Doing HTTP requests (for example, for FireHOL ipblocklist).
|
||||
type Network interface {
|
||||
// Dial establishes context-free TCP connections.
|
||||
Dial(network, address string) (net.Conn, error)
|
||||
Dial(network, address string) (essentials.Conn, error)
|
||||
|
||||
// DialContext dials using a context. This is a preferrable
|
||||
// way of establishing TCP connections.
|
||||
DialContext(ctx context.Context, network, address string) (net.Conn, error)
|
||||
DialContext(ctx context.Context, network, address string) (essentials.Conn, error)
|
||||
|
||||
// MakeHTTPClient build an HTTP client with given dial function. If
|
||||
// nothing is provided, then DialContext of this interface is going
|
||||
// to be used.
|
||||
MakeHTTPClient(func(ctx context.Context, network, address string) (net.Conn, error)) *http.Client
|
||||
MakeHTTPClient(func(ctx context.Context, network, address string) (essentials.Conn, error)) *http.Client
|
||||
}
|
||||
|
||||
// AntiReplayCache is an interface that is used to detect replay attacks
|
||||
@@ -164,6 +180,12 @@ type IPBlocklist interface {
|
||||
// Contains checks if given IP address belongs to this blocklist If.
|
||||
// it is, a connection is terminated .
|
||||
Contains(net.IP) bool
|
||||
|
||||
// Run starts a background update procedure for a blocklist
|
||||
Run(time.Duration)
|
||||
|
||||
// Shutdown stops a blocklist. It is assumed that none will access it after.
|
||||
Shutdown()
|
||||
}
|
||||
|
||||
// Event is a data structure which is populated during mtg request
|
||||
@@ -237,6 +259,9 @@ type Logger interface {
|
||||
// BindStr binds new string parameter to a new logger instance.
|
||||
BindStr(name, value string) Logger
|
||||
|
||||
// BindJSON binds a new JSON-encoded string to a new logger instance.
|
||||
BindJSON(name, value string) Logger
|
||||
|
||||
// Printf is to support log.Logger behavior.
|
||||
Printf(format string, args ...interface{})
|
||||
|
||||
|
||||
@@ -11,6 +11,7 @@ type NoopLogger struct{}
|
||||
func (n NoopLogger) Named(_ string) Logger { return n }
|
||||
func (n NoopLogger) BindInt(_ string, _ int) Logger { return n }
|
||||
func (n NoopLogger) BindStr(_, _ string) Logger { return n }
|
||||
func (n NoopLogger) BindJSON(_, _ string) Logger { return n }
|
||||
func (n NoopLogger) Printf(_ string, _ ...interface{}) {}
|
||||
func (n NoopLogger) Info(_ string) {}
|
||||
func (n NoopLogger) Warning(_ string) {}
|
||||
|
||||
@@ -0,0 +1,21 @@
|
||||
package faketls_test
|
||||
|
||||
import (
|
||||
"testing"
|
||||
|
||||
"github.com/9seconds/mtg/v2/mtglib/internal/faketls"
|
||||
"github.com/stretchr/testify/require"
|
||||
)
|
||||
|
||||
var FuzzClientHelloSecret = []byte{1, 2, 3, 4, 5, 6, 7, 8, 9, 10}
|
||||
|
||||
func FuzzClientHello(f *testing.F) {
|
||||
f.Add([]byte{1, 2, 3})
|
||||
|
||||
f.Fuzz(func(t *testing.T, frame []byte) {
|
||||
_, err := faketls.ParseClientHello(FuzzClientHelloSecret, frame)
|
||||
|
||||
// a probability of having != err is almost negligible
|
||||
require.Error(t, err)
|
||||
})
|
||||
}
|
||||
@@ -4,13 +4,13 @@ import (
|
||||
"bytes"
|
||||
"fmt"
|
||||
"math/rand"
|
||||
"net"
|
||||
|
||||
"github.com/9seconds/mtg/v2/essentials"
|
||||
"github.com/9seconds/mtg/v2/mtglib/internal/faketls/record"
|
||||
)
|
||||
|
||||
type Conn struct {
|
||||
net.Conn
|
||||
essentials.Conn
|
||||
|
||||
readBuffer bytes.Buffer
|
||||
}
|
||||
@@ -46,7 +46,11 @@ func (c *Conn) Write(p []byte) (int, error) {
|
||||
|
||||
rec.Type = record.TypeApplicationData
|
||||
rec.Version = record.Version12
|
||||
written := 0
|
||||
|
||||
sendBuffer := acquireBytesBuffer()
|
||||
defer releaseBytesBuffer(sendBuffer)
|
||||
|
||||
lenP := len(p)
|
||||
|
||||
for len(p) > 0 {
|
||||
chunkSize := rand.Intn(record.TLSMaxRecordSize)
|
||||
@@ -56,14 +60,14 @@ func (c *Conn) Write(p []byte) (int, error) {
|
||||
|
||||
rec.Payload.Reset()
|
||||
rec.Payload.Write(p[:chunkSize])
|
||||
rec.Dump(sendBuffer) // nolint: errcheck
|
||||
|
||||
if err := rec.Dump(c.Conn); err != nil {
|
||||
return written, err // nolint: wrapcheck
|
||||
}
|
||||
|
||||
written += chunkSize
|
||||
p = p[chunkSize:]
|
||||
}
|
||||
|
||||
return written, nil
|
||||
if _, err := c.Conn.Write(sendBuffer.Bytes()); err != nil {
|
||||
return 0, err // nolint: wrapcheck
|
||||
}
|
||||
|
||||
return lenP, nil
|
||||
}
|
||||
|
||||
@@ -15,7 +15,7 @@ import (
|
||||
)
|
||||
|
||||
type ConnMock struct {
|
||||
testlib.NetConnMock
|
||||
testlib.EssentialsConnMock
|
||||
|
||||
readBuffer bytes.Buffer
|
||||
writeBuffer bytes.Buffer
|
||||
|
||||
@@ -19,7 +19,7 @@ const (
|
||||
|
||||
// ClientHelloMinLen is a minimal possible length of
|
||||
// ClientHello record.
|
||||
ClientHelloMinLen = 4
|
||||
ClientHelloMinLen = 6
|
||||
|
||||
// WelcomePacketRandomOffset is an offset of random in ServerHello
|
||||
// packet (including record envelope).
|
||||
|
||||
@@ -12,7 +12,7 @@ var bytesBufferPool = sync.Pool{
|
||||
}
|
||||
|
||||
func acquireBytesBuffer() *bytes.Buffer {
|
||||
return bytesBufferPool.Get().(*bytes.Buffer)
|
||||
return bytesBufferPool.Get().(*bytes.Buffer) // nolint: forcetypeassert
|
||||
}
|
||||
|
||||
func releaseBytesBuffer(b *bytes.Buffer) {
|
||||
|
||||
@@ -11,7 +11,7 @@ var recordPool = sync.Pool{
|
||||
}
|
||||
|
||||
func AcquireRecord() *Record {
|
||||
return recordPool.Get().(*Record)
|
||||
return recordPool.Get().(*Record) // nolint: forcetypeassert
|
||||
}
|
||||
|
||||
func ReleaseRecord(r *Record) {
|
||||
|
||||
@@ -0,0 +1,32 @@
|
||||
package obfuscated2
|
||||
|
||||
import (
|
||||
"bytes"
|
||||
"testing"
|
||||
|
||||
"github.com/stretchr/testify/require"
|
||||
)
|
||||
|
||||
var FuzzClientHandshakeSecret = []byte{1, 2, 3}
|
||||
|
||||
func FuzzClientHandshake(f *testing.F) {
|
||||
f.Add([]byte{1, 2, 3})
|
||||
|
||||
f.Fuzz(func(t *testing.T, frame []byte) {
|
||||
data := bytes.NewReader(frame)
|
||||
|
||||
if _, _, _, err := ClientHandshake(FuzzClientHandshakeSecret, data); err != nil {
|
||||
return
|
||||
}
|
||||
|
||||
handshake := clientHandhakeFrame{}
|
||||
require.Len(t, frame, handshakeFrameLen)
|
||||
|
||||
copy(handshake.data[:], frame)
|
||||
|
||||
decryptor := handshake.decryptor(FuzzClientHandshakeSecret)
|
||||
decryptor.XORKeyStream(handshake.data[:], handshake.data[:])
|
||||
|
||||
require.Equal(t, handshakeConnectionType, handshake.connectionType())
|
||||
})
|
||||
}
|
||||
@@ -42,7 +42,7 @@ func (suite *ClientHandshakeTestSuite) TestOk() {
|
||||
writeData := make([]byte, len(snapshot.Encrypted.Text.data))
|
||||
readData := make([]byte, len(snapshot.Decrypted.Text.data))
|
||||
|
||||
connMock := &testlib.NetConnMock{}
|
||||
connMock := &testlib.EssentialsConnMock{}
|
||||
connMock.On("Read", mock.Anything).
|
||||
Once().
|
||||
Return(len(snapshot.Decrypted.Text.data), nil).
|
||||
|
||||
@@ -2,11 +2,12 @@ package obfuscated2
|
||||
|
||||
import (
|
||||
"crypto/cipher"
|
||||
"net"
|
||||
|
||||
"github.com/9seconds/mtg/v2/essentials"
|
||||
)
|
||||
|
||||
type Conn struct {
|
||||
net.Conn
|
||||
essentials.Conn
|
||||
|
||||
Encryptor cipher.Stream
|
||||
Decryptor cipher.Stream
|
||||
|
||||
@@ -1,12 +1,20 @@
|
||||
package obfuscated2_test
|
||||
|
||||
import (
|
||||
"bytes"
|
||||
"crypto/aes"
|
||||
"crypto/cipher"
|
||||
"encoding/base64"
|
||||
"encoding/json"
|
||||
"fmt"
|
||||
"os"
|
||||
"path/filepath"
|
||||
"strings"
|
||||
"testing"
|
||||
|
||||
"github.com/9seconds/mtg/v2/internal/testlib"
|
||||
"github.com/9seconds/mtg/v2/mtglib/internal/obfuscated2"
|
||||
"github.com/stretchr/testify/require"
|
||||
)
|
||||
|
||||
type snapshotBytes struct {
|
||||
@@ -50,6 +58,14 @@ type SnapshotTestSuite struct {
|
||||
snapshots map[string]*Obfuscated2Snapshot
|
||||
}
|
||||
|
||||
type ServerHandshakeTestData struct {
|
||||
connMock *testlib.EssentialsConnMock
|
||||
|
||||
proxyConn obfuscated2.Conn
|
||||
encryptor cipher.Stream
|
||||
decryptor cipher.Stream
|
||||
}
|
||||
|
||||
func (suite *SnapshotTestSuite) IngestSnapshots(dirname, namePrefix string) error {
|
||||
suite.snapshots = map[string]*Obfuscated2Snapshot{}
|
||||
|
||||
@@ -81,3 +97,41 @@ func (suite *SnapshotTestSuite) IngestSnapshots(dirname, namePrefix string) erro
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
func NewServerHandshakeTestData(t *testing.T) ServerHandshakeTestData {
|
||||
buf := &bytes.Buffer{}
|
||||
connMock := &testlib.EssentialsConnMock{}
|
||||
|
||||
handshakeEnc, handshakeDec, err := obfuscated2.ServerHandshake(buf)
|
||||
require.NoError(t, err)
|
||||
|
||||
serverEncrypted := buf.Bytes()
|
||||
decBlock, _ := aes.NewCipher(serverEncrypted[8 : 8+32])
|
||||
decryptor := cipher.NewCTR(decBlock, serverEncrypted[8+32:8+32+16])
|
||||
|
||||
serverDecrypted := make([]byte, len(serverEncrypted))
|
||||
decryptor.XORKeyStream(serverDecrypted, serverEncrypted)
|
||||
|
||||
require.Equal(t, "3d3d3Q",
|
||||
base64.RawStdEncoding.EncodeToString(serverDecrypted[8+32+16:8+32+16+4]))
|
||||
|
||||
serverEncryptedReverted := make([]byte, len(serverEncrypted))
|
||||
|
||||
for i := 0; i < 32+16; i++ {
|
||||
serverEncryptedReverted[8+i] = serverEncrypted[8+32+16-1-i]
|
||||
}
|
||||
|
||||
encBlock, _ := aes.NewCipher(serverEncryptedReverted[8 : 8+32])
|
||||
encryptor := cipher.NewCTR(encBlock, serverEncryptedReverted[8+32:8+32+16])
|
||||
|
||||
return ServerHandshakeTestData{
|
||||
connMock: connMock,
|
||||
proxyConn: obfuscated2.Conn{
|
||||
Conn: connMock,
|
||||
Encryptor: handshakeEnc,
|
||||
Decryptor: handshakeDec,
|
||||
},
|
||||
encryptor: encryptor,
|
||||
decryptor: decryptor,
|
||||
}
|
||||
}
|
||||
|
||||
@@ -21,7 +21,7 @@ var (
|
||||
)
|
||||
|
||||
func acquireSha256Hasher() hash.Hash {
|
||||
return sha256HasherPool.Get().(hash.Hash)
|
||||
return sha256HasherPool.Get().(hash.Hash) // nolint: forcetypeassert
|
||||
}
|
||||
|
||||
func releaseSha256Hasher(h hash.Hash) {
|
||||
@@ -30,7 +30,7 @@ func releaseSha256Hasher(h hash.Hash) {
|
||||
}
|
||||
|
||||
func acquireBytesBuffer() *bytes.Buffer {
|
||||
return bytesBufferPool.Get().(*bytes.Buffer)
|
||||
return bytesBufferPool.Get().(*bytes.Buffer) // nolint: forcetypeassert
|
||||
}
|
||||
|
||||
func releaseBytesBuffer(buf *bytes.Buffer) {
|
||||
|
||||
@@ -0,0 +1,30 @@
|
||||
package obfuscated2
|
||||
|
||||
import (
|
||||
"encoding/binary"
|
||||
"testing"
|
||||
|
||||
"github.com/stretchr/testify/assert"
|
||||
)
|
||||
|
||||
func FuzzServerGenerateHandshakeFrame(f *testing.F) {
|
||||
f.Fuzz(func(t *testing.T, arg int) {
|
||||
frame := generateServerHanshakeFrame()
|
||||
|
||||
assert.NotEqualValues(t, 0xef, frame.data[0])
|
||||
|
||||
firstBytes := binary.LittleEndian.Uint32(frame.data[:4])
|
||||
assert.NotEqualValues(t, 0x44414548, firstBytes)
|
||||
assert.NotEqualValues(t, 0x54534f50, firstBytes)
|
||||
assert.NotEqualValues(t, 0x20544547, firstBytes)
|
||||
assert.NotEqualValues(t, 0x4954504f, firstBytes)
|
||||
assert.NotEqualValues(t, 0xeeeeeeee, firstBytes)
|
||||
|
||||
assert.NotEqualValues(
|
||||
t,
|
||||
0,
|
||||
frame.data[4]|frame.data[5]|frame.data[6]|frame.data[7])
|
||||
|
||||
assert.Equal(t, handshakeConnectionType, frame.connectionType())
|
||||
})
|
||||
}
|
||||
@@ -0,0 +1,58 @@
|
||||
package obfuscated2_test
|
||||
|
||||
import (
|
||||
"testing"
|
||||
|
||||
"github.com/stretchr/testify/assert"
|
||||
"github.com/stretchr/testify/mock"
|
||||
)
|
||||
|
||||
func FuzzServerSend(f *testing.F) {
|
||||
f.Add([]byte{1, 2, 3, 4, 5})
|
||||
|
||||
f.Fuzz(func(t *testing.T, data []byte) {
|
||||
handshakeData := NewServerHandshakeTestData(t)
|
||||
|
||||
handshakeData.connMock.
|
||||
On("Write", mock.Anything).
|
||||
Return(len(data), nil).
|
||||
Once().
|
||||
Run(func(args mock.Arguments) {
|
||||
message := make([]byte, len(data))
|
||||
handshakeData.decryptor.XORKeyStream(message, args.Get(0).([]byte)) // nolint: forcetypeassert
|
||||
assert.Equal(t, message, data)
|
||||
})
|
||||
|
||||
n, err := handshakeData.proxyConn.Write(data)
|
||||
|
||||
assert.EqualValues(t, len(data), n)
|
||||
assert.NoError(t, err)
|
||||
handshakeData.connMock.AssertExpectations(t)
|
||||
})
|
||||
}
|
||||
|
||||
func FuzzServerReceive(f *testing.F) {
|
||||
f.Add([]byte{1, 2, 3, 4, 5})
|
||||
|
||||
f.Fuzz(func(t *testing.T, data []byte) {
|
||||
handshakeData := NewServerHandshakeTestData(t)
|
||||
buffer := make([]byte, len(data))
|
||||
|
||||
handshakeData.connMock.
|
||||
On("Read", mock.Anything).
|
||||
Return(len(data), nil).
|
||||
Once().
|
||||
Run(func(args mock.Arguments) {
|
||||
message := make([]byte, len(data))
|
||||
handshakeData.encryptor.XORKeyStream(message, data)
|
||||
copy(args.Get(0).([]byte), message) // nolint: forcetypeassert
|
||||
})
|
||||
|
||||
n, err := handshakeData.proxyConn.Read(buffer)
|
||||
|
||||
assert.EqualValues(t, len(data), n)
|
||||
assert.NoError(t, err)
|
||||
assert.Equal(t, data, buffer)
|
||||
handshakeData.connMock.AssertExpectations(t)
|
||||
})
|
||||
}
|
||||
@@ -1,14 +1,8 @@
|
||||
package obfuscated2_test
|
||||
|
||||
import (
|
||||
"bytes"
|
||||
"crypto/aes"
|
||||
"crypto/cipher"
|
||||
"encoding/base64"
|
||||
"testing"
|
||||
|
||||
"github.com/9seconds/mtg/v2/internal/testlib"
|
||||
"github.com/9seconds/mtg/v2/mtglib/internal/obfuscated2"
|
||||
"github.com/stretchr/testify/mock"
|
||||
"github.com/stretchr/testify/suite"
|
||||
)
|
||||
@@ -16,64 +10,31 @@ import (
|
||||
type ServerHandshakeTestSuite struct {
|
||||
suite.Suite
|
||||
|
||||
connMock *testlib.NetConnMock
|
||||
proxyConn obfuscated2.Conn
|
||||
encryptor cipher.Stream
|
||||
decryptor cipher.Stream
|
||||
data ServerHandshakeTestData
|
||||
}
|
||||
|
||||
func (suite *ServerHandshakeTestSuite) SetupTest() {
|
||||
buf := &bytes.Buffer{}
|
||||
suite.connMock = &testlib.NetConnMock{}
|
||||
|
||||
encryptor, decryptor, err := obfuscated2.ServerHandshake(buf)
|
||||
suite.NoError(err)
|
||||
|
||||
suite.proxyConn = obfuscated2.Conn{
|
||||
Conn: suite.connMock,
|
||||
Encryptor: encryptor,
|
||||
Decryptor: decryptor,
|
||||
}
|
||||
|
||||
serverEncrypted := buf.Bytes()
|
||||
|
||||
decBlock, _ := aes.NewCipher(serverEncrypted[8 : 8+32])
|
||||
suite.decryptor = cipher.NewCTR(decBlock, serverEncrypted[8+32:8+32+16])
|
||||
|
||||
serverDecrypted := make([]byte, len(serverEncrypted))
|
||||
suite.decryptor.XORKeyStream(serverDecrypted, serverEncrypted)
|
||||
|
||||
suite.Equal("3d3d3Q",
|
||||
base64.RawStdEncoding.EncodeToString(serverDecrypted[8+32+16:8+32+16+4]))
|
||||
|
||||
serverEncryptedReverted := make([]byte, len(serverEncrypted))
|
||||
|
||||
for i := 0; i < 32+16; i++ {
|
||||
serverEncryptedReverted[8+i] = serverEncrypted[8+32+16-1-i]
|
||||
}
|
||||
|
||||
encBlock, _ := aes.NewCipher(serverEncryptedReverted[8 : 8+32])
|
||||
suite.encryptor = cipher.NewCTR(encBlock, serverEncryptedReverted[8+32:8+32+16])
|
||||
suite.data = NewServerHandshakeTestData(suite.T())
|
||||
}
|
||||
|
||||
func (suite *ServerHandshakeTestSuite) TearDownTest() {
|
||||
suite.connMock.AssertExpectations(suite.T())
|
||||
suite.data.connMock.AssertExpectations(suite.T())
|
||||
}
|
||||
|
||||
func (suite *ServerHandshakeTestSuite) TestSendToTelegram() {
|
||||
messageToTelegram := []byte{10, 11, 12, 13, 14, 'a'}
|
||||
|
||||
suite.connMock.
|
||||
suite.data.connMock.
|
||||
On("Write", mock.Anything).
|
||||
Return(len(messageToTelegram), nil).
|
||||
Once().
|
||||
Run(func(args mock.Arguments) {
|
||||
message := make([]byte, len(messageToTelegram))
|
||||
suite.decryptor.XORKeyStream(message, args.Get(0).([]byte))
|
||||
suite.data.decryptor.XORKeyStream(message, args.Get(0).([]byte)) // nolint: forcetypeassert
|
||||
suite.Equal(messageToTelegram, message)
|
||||
})
|
||||
|
||||
n, err := suite.proxyConn.Write(messageToTelegram)
|
||||
n, err := suite.data.proxyConn.Write(messageToTelegram)
|
||||
suite.EqualValues(len(messageToTelegram), n)
|
||||
suite.NoError(err)
|
||||
}
|
||||
@@ -82,17 +43,17 @@ func (suite *ServerHandshakeTestSuite) TestRecieveFromTelegram() {
|
||||
messageFromTelegram := []byte{10, 11, 12, 13, 14, 'a'}
|
||||
buffer := make([]byte, len(messageFromTelegram))
|
||||
|
||||
suite.connMock.
|
||||
suite.data.connMock.
|
||||
On("Read", mock.Anything).
|
||||
Return(len(messageFromTelegram), nil).
|
||||
Once().
|
||||
Run(func(args mock.Arguments) {
|
||||
message := make([]byte, len(messageFromTelegram))
|
||||
suite.encryptor.XORKeyStream(message, messageFromTelegram)
|
||||
copy(args.Get(0).([]byte), message)
|
||||
suite.data.encryptor.XORKeyStream(message, messageFromTelegram)
|
||||
copy(args.Get(0).([]byte), message) // nolint: forcetypeassert
|
||||
})
|
||||
|
||||
n, err := suite.proxyConn.Read(buffer)
|
||||
n, err := suite.data.proxyConn.Read(buffer)
|
||||
suite.EqualValues(len(messageFromTelegram), n)
|
||||
suite.NoError(err)
|
||||
suite.Equal(messageFromTelegram, buffer)
|
||||
|
||||
@@ -1,35 +0,0 @@
|
||||
package relay
|
||||
|
||||
import (
|
||||
"context"
|
||||
"io"
|
||||
)
|
||||
|
||||
type conn struct {
|
||||
io.ReadWriteCloser
|
||||
|
||||
ctx context.Context
|
||||
tickChannel chan struct{}
|
||||
}
|
||||
|
||||
func (c conn) Read(p []byte) (int, error) {
|
||||
n, err := c.ReadWriteCloser.Read(p)
|
||||
|
||||
select {
|
||||
case <-c.ctx.Done():
|
||||
case c.tickChannel <- struct{}{}:
|
||||
}
|
||||
|
||||
return n, err // nolint: wrapcheck
|
||||
}
|
||||
|
||||
func (c conn) Write(p []byte) (int, error) {
|
||||
n, err := c.ReadWriteCloser.Write(p)
|
||||
|
||||
select {
|
||||
case <-c.ctx.Done():
|
||||
case c.tickChannel <- struct{}{}:
|
||||
}
|
||||
|
||||
return n, err // nolint: wrapcheck
|
||||
}
|
||||
@@ -1,125 +0,0 @@
|
||||
package relay
|
||||
|
||||
import (
|
||||
"context"
|
||||
"errors"
|
||||
"io"
|
||||
"testing"
|
||||
|
||||
"github.com/9seconds/mtg/v2/internal/testlib"
|
||||
"github.com/stretchr/testify/mock"
|
||||
"github.com/stretchr/testify/suite"
|
||||
)
|
||||
|
||||
type ConnTestSuite struct {
|
||||
suite.Suite
|
||||
|
||||
ctxCancel context.CancelFunc
|
||||
connMock *testlib.NetConnMock
|
||||
tickChannel chan struct{}
|
||||
buf []byte
|
||||
c conn
|
||||
}
|
||||
|
||||
func (suite *ConnTestSuite) SetupTest() {
|
||||
ctx, cancel := context.WithCancel(context.Background())
|
||||
|
||||
suite.tickChannel = make(chan struct{}, 1)
|
||||
suite.connMock = &testlib.NetConnMock{}
|
||||
suite.ctxCancel = cancel
|
||||
suite.buf = make([]byte, 5)
|
||||
|
||||
suite.c = conn{
|
||||
ReadWriteCloser: suite.connMock,
|
||||
ctx: ctx,
|
||||
tickChannel: suite.tickChannel,
|
||||
}
|
||||
}
|
||||
|
||||
func (suite *ConnTestSuite) TestReadOk() {
|
||||
suite.connMock.On("Read", mock.Anything).Once().Return(len(suite.buf), nil)
|
||||
|
||||
n, err := suite.c.Read(suite.buf)
|
||||
suite.NoError(err)
|
||||
suite.Equal(len(suite.buf), n)
|
||||
|
||||
select {
|
||||
case <-suite.tickChannel:
|
||||
default:
|
||||
suite.FailNow("cannot find a tick event")
|
||||
}
|
||||
}
|
||||
|
||||
func (suite *ConnTestSuite) TestReadErr() {
|
||||
suite.connMock.On("Read", mock.Anything).Once().Return(0, io.EOF)
|
||||
|
||||
_, err := suite.c.Read(suite.buf)
|
||||
suite.True(errors.Is(err, io.EOF))
|
||||
|
||||
select {
|
||||
case <-suite.tickChannel:
|
||||
default:
|
||||
suite.FailNow("cannot find a tick event")
|
||||
}
|
||||
}
|
||||
|
||||
func (suite *ConnTestSuite) TestReadContextDone() {
|
||||
suite.connMock.On("Read", mock.Anything).Once().Return(len(suite.buf), nil)
|
||||
suite.ctxCancel()
|
||||
|
||||
suite.tickChannel <- struct{}{}
|
||||
|
||||
suite.c.Read(suite.buf) // nolint: errcheck
|
||||
}
|
||||
|
||||
func (suite *ConnTestSuite) TestWriteOk() {
|
||||
suite.connMock.On("Write", mock.Anything).Once().Return(len(suite.buf), nil)
|
||||
|
||||
n, err := suite.c.Write(suite.buf)
|
||||
suite.NoError(err)
|
||||
suite.Equal(len(suite.buf), n)
|
||||
|
||||
select {
|
||||
case <-suite.tickChannel:
|
||||
default:
|
||||
suite.FailNow("cannot find a tick event")
|
||||
}
|
||||
}
|
||||
|
||||
func (suite *ConnTestSuite) TestWriteErr() {
|
||||
suite.connMock.On("Write", mock.Anything).Once().Return(0, io.EOF)
|
||||
|
||||
_, err := suite.c.Write(suite.buf)
|
||||
suite.True(errors.Is(err, io.EOF))
|
||||
|
||||
select {
|
||||
case <-suite.tickChannel:
|
||||
default:
|
||||
suite.FailNow("cannot find a tick event")
|
||||
}
|
||||
}
|
||||
|
||||
func (suite *ConnTestSuite) TestWriteContextDone() {
|
||||
suite.connMock.On("Write", mock.Anything).Once().Return(len(suite.buf), nil)
|
||||
suite.ctxCancel()
|
||||
|
||||
suite.tickChannel <- struct{}{}
|
||||
|
||||
suite.c.Write(suite.buf) // nolint: errcheck
|
||||
}
|
||||
|
||||
func (suite *ConnTestSuite) TearDownTest() {
|
||||
select {
|
||||
case <-suite.tickChannel:
|
||||
default:
|
||||
}
|
||||
|
||||
close(suite.tickChannel)
|
||||
|
||||
suite.connMock.AssertExpectations(suite.T())
|
||||
}
|
||||
|
||||
func TestConn(t *testing.T) {
|
||||
t.Parallel()
|
||||
suite.Run(t, &ConnTestSuite{})
|
||||
}
|
||||
@@ -1,5 +1,9 @@
|
||||
package relay
|
||||
|
||||
const (
|
||||
copyBufferSize = 64 * 1024
|
||||
)
|
||||
|
||||
type Logger interface {
|
||||
Printf(msg string, args ...interface{})
|
||||
}
|
||||
|
||||
@@ -1,49 +1,5 @@
|
||||
package relay_test
|
||||
|
||||
import (
|
||||
"bytes"
|
||||
"io"
|
||||
"sync"
|
||||
)
|
||||
|
||||
type loggerMock struct{}
|
||||
|
||||
func (l loggerMock) Printf(format string, args ...interface{}) {}
|
||||
|
||||
type rwcMock struct {
|
||||
bytes.Buffer
|
||||
|
||||
closed bool
|
||||
mutex sync.Mutex
|
||||
}
|
||||
|
||||
func (r *rwcMock) Read(p []byte) (int, error) {
|
||||
r.mutex.Lock()
|
||||
defer r.mutex.Unlock()
|
||||
|
||||
if r.closed {
|
||||
return 0, io.EOF
|
||||
}
|
||||
|
||||
return r.Buffer.Read(p) // nolint: wrapcheck
|
||||
}
|
||||
|
||||
func (r *rwcMock) Write(p []byte) (int, error) {
|
||||
r.mutex.Lock()
|
||||
defer r.mutex.Unlock()
|
||||
|
||||
if r.closed {
|
||||
return 0, io.EOF
|
||||
}
|
||||
|
||||
return r.Buffer.Write(p) // nolint: wrapcheck
|
||||
}
|
||||
|
||||
func (r *rwcMock) Close() error {
|
||||
r.mutex.Lock()
|
||||
defer r.mutex.Unlock()
|
||||
|
||||
r.closed = true
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
@@ -1,45 +1,19 @@
|
||||
package relay
|
||||
|
||||
import (
|
||||
"context"
|
||||
"sync"
|
||||
"time"
|
||||
)
|
||||
import "sync"
|
||||
|
||||
var relayPool = sync.Pool{
|
||||
var copyBufferPool = sync.Pool{
|
||||
New: func() interface{} {
|
||||
return &Relay{
|
||||
tickChannel: make(chan struct{}),
|
||||
errorChannel: make(chan error, 1),
|
||||
}
|
||||
rv := make([]byte, copyBufferSize)
|
||||
|
||||
return &rv
|
||||
},
|
||||
}
|
||||
|
||||
func AcquireRelay(ctx context.Context, logger Logger, bufferSize int, idleTimeout time.Duration) *Relay {
|
||||
ctx, cancel := context.WithCancel(ctx)
|
||||
|
||||
r, ok := relayPool.Get().(*Relay)
|
||||
if !ok {
|
||||
panic("Relay pool has no relay!")
|
||||
}
|
||||
|
||||
r.ctx = ctx
|
||||
r.ctxCancel = cancel
|
||||
r.logger = logger
|
||||
r.tickTimeout = idleTimeout
|
||||
|
||||
if len(r.eastBuffer) != bufferSize {
|
||||
r.eastBuffer = make([]byte, bufferSize)
|
||||
}
|
||||
|
||||
if len(r.westBuffer) != bufferSize {
|
||||
r.westBuffer = make([]byte, bufferSize)
|
||||
}
|
||||
|
||||
return r
|
||||
func acquireCopyBuffer() *[]byte {
|
||||
return copyBufferPool.Get().(*[]byte) // nolint: forcetypeassert
|
||||
}
|
||||
|
||||
func ReleaseRelay(r *Relay) {
|
||||
r.Reset()
|
||||
relayPool.Put(r)
|
||||
func releaseCopyBuffer(buf *[]byte) {
|
||||
copyBufferPool.Put(buf)
|
||||
}
|
||||
|
||||
+39
-114
@@ -2,128 +2,53 @@ package relay
|
||||
|
||||
import (
|
||||
"context"
|
||||
"errors"
|
||||
"io"
|
||||
"sync"
|
||||
"time"
|
||||
|
||||
"github.com/9seconds/mtg/v2/essentials"
|
||||
)
|
||||
|
||||
type Relay struct {
|
||||
ctx context.Context
|
||||
ctxCancel context.CancelFunc
|
||||
logger Logger
|
||||
processMutex sync.Mutex
|
||||
eastBuffer []byte
|
||||
westBuffer []byte
|
||||
tickChannel chan struct{}
|
||||
errorChannel chan error
|
||||
tickTimeout time.Duration
|
||||
func Relay(ctx context.Context, log Logger, telegramConn, clientConn essentials.Conn) {
|
||||
defer telegramConn.Close()
|
||||
defer clientConn.Close()
|
||||
|
||||
ctx, cancel := context.WithCancel(ctx)
|
||||
defer cancel()
|
||||
|
||||
go func() {
|
||||
<-ctx.Done()
|
||||
telegramConn.Close()
|
||||
clientConn.Close()
|
||||
}()
|
||||
|
||||
closeChan := make(chan struct{})
|
||||
|
||||
go func() {
|
||||
defer close(closeChan)
|
||||
|
||||
pump(log, telegramConn, clientConn, "client -> telegram")
|
||||
}()
|
||||
|
||||
pump(log, clientConn, telegramConn, "telegram -> client")
|
||||
|
||||
<-closeChan
|
||||
}
|
||||
|
||||
func (r *Relay) Reset() {
|
||||
r.processMutex.Lock()
|
||||
defer r.processMutex.Unlock()
|
||||
func pump(log Logger, src, dst essentials.Conn, direction string) {
|
||||
defer src.CloseRead() // nolint: errcheck
|
||||
defer dst.CloseWrite() // nolint: errcheck
|
||||
|
||||
if r.ctxCancel != nil {
|
||||
r.ctxCancel()
|
||||
}
|
||||
copyBuffer := acquireCopyBuffer()
|
||||
defer releaseCopyBuffer(copyBuffer)
|
||||
|
||||
r.ctx = nil
|
||||
r.ctxCancel = nil
|
||||
r.logger = nil
|
||||
}
|
||||
n, err := io.CopyBuffer(src, dst, *copyBuffer)
|
||||
|
||||
func (r *Relay) Process(eastConn, westConn io.ReadWriteCloser) error {
|
||||
r.processMutex.Lock()
|
||||
defer r.processMutex.Unlock()
|
||||
|
||||
eastConn = conn{
|
||||
ReadWriteCloser: eastConn,
|
||||
ctx: r.ctx,
|
||||
tickChannel: r.tickChannel,
|
||||
}
|
||||
westConn = conn{
|
||||
ReadWriteCloser: westConn,
|
||||
ctx: r.ctx,
|
||||
tickChannel: r.tickChannel,
|
||||
}
|
||||
|
||||
wg := &sync.WaitGroup{}
|
||||
wg.Add(3) // nolint: gomnd
|
||||
|
||||
go r.runObserver(eastConn, westConn, wg)
|
||||
|
||||
go r.transmit(eastConn, westConn, r.westBuffer, "west", wg)
|
||||
|
||||
r.transmit(westConn, eastConn, r.eastBuffer, "east", wg)
|
||||
|
||||
wg.Wait()
|
||||
|
||||
select {
|
||||
case err := <-r.errorChannel:
|
||||
return err
|
||||
switch {
|
||||
case err == nil:
|
||||
log.Printf("%s has been finished", direction)
|
||||
case errors.Is(err, io.EOF):
|
||||
log.Printf("%s has been finished because of EOF. Written %d bytes", direction, n)
|
||||
default:
|
||||
return nil
|
||||
}
|
||||
}
|
||||
|
||||
func (r *Relay) transmit(src io.ReadCloser, dst io.WriteCloser,
|
||||
buffer []byte, direction string, wg *sync.WaitGroup) {
|
||||
defer wg.Done()
|
||||
|
||||
defer func() {
|
||||
r.ctxCancel()
|
||||
src.Close()
|
||||
dst.Close()
|
||||
}()
|
||||
|
||||
if _, err := io.CopyBuffer(dst, src, buffer); err != nil {
|
||||
r.logger.Printf("error '%v' happened on direction %s", err, direction)
|
||||
|
||||
select {
|
||||
case <-r.ctx.Done():
|
||||
err = r.ctx.Err()
|
||||
default:
|
||||
}
|
||||
|
||||
select {
|
||||
case r.errorChannel <- err:
|
||||
default:
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func (r *Relay) runObserver(one, another io.Closer, wg *sync.WaitGroup) {
|
||||
defer wg.Done()
|
||||
|
||||
ticker := time.NewTicker(time.Second)
|
||||
|
||||
defer func() {
|
||||
one.Close()
|
||||
another.Close()
|
||||
|
||||
ticker.Stop()
|
||||
|
||||
select {
|
||||
case <-ticker.C:
|
||||
default:
|
||||
}
|
||||
}()
|
||||
|
||||
lastTickAt := time.Now()
|
||||
|
||||
for {
|
||||
select {
|
||||
case <-r.ctx.Done():
|
||||
return
|
||||
case <-r.tickChannel:
|
||||
lastTickAt = time.Now()
|
||||
case <-ticker.C:
|
||||
if time.Since(lastTickAt) > r.tickTimeout {
|
||||
r.logger.Printf("exit due to a timeout")
|
||||
r.ctxCancel()
|
||||
|
||||
return
|
||||
}
|
||||
}
|
||||
log.Printf("%s has been finished (written %d bytes): %v", direction, n, err)
|
||||
}
|
||||
}
|
||||
|
||||
@@ -4,7 +4,6 @@ import (
|
||||
"context"
|
||||
"io"
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"github.com/9seconds/mtg/v2/internal/testlib"
|
||||
"github.com/9seconds/mtg/v2/mtglib/internal/relay"
|
||||
@@ -15,60 +14,42 @@ import (
|
||||
type RelayTestSuite struct {
|
||||
suite.Suite
|
||||
|
||||
ctx context.Context
|
||||
ctxCancel context.CancelFunc
|
||||
r *relay.Relay
|
||||
loggerMock relay.Logger
|
||||
ctx context.Context
|
||||
ctxCancel context.CancelFunc
|
||||
telegramConnMock *testlib.EssentialsConnMock
|
||||
clientConnMock *testlib.EssentialsConnMock
|
||||
}
|
||||
|
||||
func (suite *RelayTestSuite) SetupTest() {
|
||||
suite.ctx, suite.ctxCancel = context.WithCancel(context.Background())
|
||||
suite.r = relay.AcquireRelay(suite.ctx, loggerMock{}, 4096, time.Second)
|
||||
ctx, cancel := context.WithCancel(context.Background())
|
||||
suite.ctx = ctx
|
||||
suite.ctxCancel = cancel
|
||||
suite.loggerMock = &loggerMock{}
|
||||
suite.telegramConnMock = &testlib.EssentialsConnMock{}
|
||||
suite.clientConnMock = &testlib.EssentialsConnMock{}
|
||||
}
|
||||
|
||||
func (suite *RelayTestSuite) TearDownTest() {
|
||||
suite.ctxCancel()
|
||||
relay.ReleaseRelay(suite.r)
|
||||
suite.r = nil
|
||||
suite.telegramConnMock.AssertExpectations(suite.T())
|
||||
suite.clientConnMock.AssertExpectations(suite.T())
|
||||
}
|
||||
|
||||
func (suite *RelayTestSuite) TestCancelled() {
|
||||
suite.ctxCancel()
|
||||
func (suite *RelayTestSuite) TestExit() {
|
||||
suite.telegramConnMock.On("Close").Return(nil)
|
||||
suite.telegramConnMock.On("CloseRead").Return(nil).Once()
|
||||
suite.telegramConnMock.On("CloseWrite").Return(nil).Once()
|
||||
suite.telegramConnMock.On("Read", mock.Anything).Return(10, io.EOF).Once()
|
||||
suite.telegramConnMock.On("Write", mock.Anything).Return(10, io.EOF).Maybe()
|
||||
|
||||
eastConn := &rwcMock{}
|
||||
eastConn.Write([]byte{1, 2, 3, 4, 5}) // nolint: errcheck
|
||||
suite.clientConnMock.On("Read", mock.Anything).Return(0, io.EOF).Once()
|
||||
suite.clientConnMock.On("Write", mock.Anything).Return(10, io.EOF).Maybe()
|
||||
suite.clientConnMock.On("Close").Return(nil)
|
||||
suite.clientConnMock.On("CloseRead").Return(nil).Once()
|
||||
suite.clientConnMock.On("CloseWrite").Return(nil).Once()
|
||||
|
||||
westConn := &rwcMock{}
|
||||
westConn.Write([]byte{100, 101, 102}) // nolint: errcheck
|
||||
|
||||
suite.Nil(suite.r.Process(eastConn, westConn))
|
||||
}
|
||||
|
||||
func (suite *RelayTestSuite) TestCopyFine() {
|
||||
eastConn := &rwcMock{}
|
||||
eastConn.Write([]byte{1, 2, 3, 4, 5}) // nolint: errcheck
|
||||
|
||||
westConn := &rwcMock{}
|
||||
westConn.Write([]byte{100, 101, 102}) // nolint: errcheck
|
||||
|
||||
// yes, this test is not good enough. but apparently, if it hangs,
|
||||
// we can debug most of possible issues.
|
||||
_ = suite.r.Process(eastConn, westConn)
|
||||
}
|
||||
|
||||
func (suite *RelayTestSuite) TestTimeout() {
|
||||
eastConn := &rwcMock{}
|
||||
eastConn.Write([]byte{1, 2, 3, 4, 5}) // nolint: errcheck
|
||||
|
||||
westConn := &testlib.NetConnMock{}
|
||||
westConn.On("Close").Return(nil)
|
||||
westConn.On("Read", mock.Anything).Return(0, io.EOF).Run(func(_ mock.Arguments) {
|
||||
time.Sleep(2 * time.Second)
|
||||
})
|
||||
westConn.On("Write", mock.Anything).Return(0, io.EOF).Run(func(_ mock.Arguments) {
|
||||
time.Sleep(2 * time.Second)
|
||||
})
|
||||
|
||||
suite.Error(suite.r.Process(eastConn, westConn))
|
||||
relay.Relay(suite.ctx, suite.loggerMock, suite.telegramConnMock, suite.clientConnMock)
|
||||
}
|
||||
|
||||
func TestRelay(t *testing.T) {
|
||||
|
||||
@@ -7,6 +7,14 @@ type addressPool struct {
|
||||
v6 [][]tgAddr
|
||||
}
|
||||
|
||||
func (a addressPool) isValidDC(dc int) bool {
|
||||
return dc > 0 && dc <= len(a.v4) && dc <= len(a.v6)
|
||||
}
|
||||
|
||||
func (a addressPool) getRandomDC() int {
|
||||
return 1 + rand.Intn(len(a.v4))
|
||||
}
|
||||
|
||||
func (a addressPool) getV4(dc int) []tgAddr {
|
||||
return a.get(a.v4, dc-1)
|
||||
}
|
||||
|
||||
@@ -2,9 +2,13 @@ package telegram
|
||||
|
||||
import (
|
||||
"context"
|
||||
"net"
|
||||
"errors"
|
||||
|
||||
"github.com/9seconds/mtg/v2/essentials"
|
||||
)
|
||||
|
||||
var errNoAddresses = errors.New("no addresses")
|
||||
|
||||
type preferIP uint8
|
||||
|
||||
const (
|
||||
@@ -82,5 +86,5 @@ var (
|
||||
)
|
||||
|
||||
type Dialer interface {
|
||||
DialContext(ctx context.Context, network, address string) (net.Conn, error)
|
||||
DialContext(ctx context.Context, network, address string) (essentials.Conn, error)
|
||||
}
|
||||
|
||||
@@ -3,8 +3,9 @@ package telegram
|
||||
import (
|
||||
"context"
|
||||
"fmt"
|
||||
"net"
|
||||
"strings"
|
||||
|
||||
"github.com/9seconds/mtg/v2/essentials"
|
||||
)
|
||||
|
||||
type Telegram struct {
|
||||
@@ -13,7 +14,7 @@ type Telegram struct {
|
||||
pool addressPool
|
||||
}
|
||||
|
||||
func (t Telegram) Dial(ctx context.Context, dc int) (net.Conn, error) {
|
||||
func (t Telegram) Dial(ctx context.Context, dc int) (essentials.Conn, error) {
|
||||
var addresses []tgAddr
|
||||
|
||||
switch t.preferIP {
|
||||
@@ -27,10 +28,9 @@ func (t Telegram) Dial(ctx context.Context, dc int) (net.Conn, error) {
|
||||
addresses = append(t.pool.getV6(dc), t.pool.getV4(dc)...)
|
||||
}
|
||||
|
||||
var (
|
||||
conn net.Conn
|
||||
err error
|
||||
)
|
||||
var conn essentials.Conn
|
||||
|
||||
err := errNoAddresses
|
||||
|
||||
for _, v := range addresses {
|
||||
conn, err = t.dialer.DialContext(ctx, v.network, v.address)
|
||||
@@ -42,6 +42,14 @@ func (t Telegram) Dial(ctx context.Context, dc int) (net.Conn, error) {
|
||||
return nil, fmt.Errorf("cannot dial to %d dc: %w", dc, err)
|
||||
}
|
||||
|
||||
func (t Telegram) IsKnownDC(dc int) bool {
|
||||
return t.pool.isValidDC(dc)
|
||||
}
|
||||
|
||||
func (t Telegram) GetFallbackDC() int {
|
||||
return t.pool.getRandomDC()
|
||||
}
|
||||
|
||||
func New(dialer Dialer, ipPreference string, useTestDCs bool) (*Telegram, error) {
|
||||
var pref preferIP
|
||||
|
||||
|
||||
@@ -44,6 +44,7 @@ func (suite *TelegramTestSuite) TestUnknownDC() {
|
||||
suite.T().Run(strconv.Itoa(value), func(t *testing.T) {
|
||||
_, err := suite.t.Dial(context.Background(), value)
|
||||
assert.Error(t, err)
|
||||
assert.False(t, suite.t.IsKnownDC(value))
|
||||
})
|
||||
}
|
||||
}
|
||||
@@ -71,6 +72,7 @@ func (suite *TelegramTestSuite) TestDialToCorrectIPs() {
|
||||
|
||||
_, err := suite.t.Dial(context.Background(), idx)
|
||||
assert.True(t, errors.Is(err, io.EOF))
|
||||
assert.True(t, suite.t.IsKnownDC(idx))
|
||||
})
|
||||
}
|
||||
}
|
||||
@@ -135,6 +137,22 @@ func (suite *TelegramTestSuite) TestUnknownPreferIP() {
|
||||
suite.Error(err)
|
||||
}
|
||||
|
||||
func (suite *TelegramTestSuite) TestFallbackDC() {
|
||||
dcs := make([]int, 10)
|
||||
|
||||
for i := 0; i < len(dcs); i++ {
|
||||
dcs[i] = suite.t.GetFallbackDC()
|
||||
}
|
||||
|
||||
for _, v := range dcs {
|
||||
value := v
|
||||
|
||||
suite.T().Run(strconv.Itoa(value), func(t *testing.T) {
|
||||
assert.True(t, suite.t.IsKnownDC(value))
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
func TestTelegram(t *testing.T) {
|
||||
t.Parallel()
|
||||
suite.Run(t, &TelegramTestSuite{})
|
||||
|
||||
+62
-40
@@ -9,6 +9,7 @@ import (
|
||||
"sync"
|
||||
"time"
|
||||
|
||||
"github.com/9seconds/mtg/v2/essentials"
|
||||
"github.com/9seconds/mtg/v2/mtglib/internal/faketls"
|
||||
"github.com/9seconds/mtg/v2/mtglib/internal/faketls/record"
|
||||
"github.com/9seconds/mtg/v2/mtglib/internal/obfuscated2"
|
||||
@@ -23,17 +24,17 @@ type Proxy struct {
|
||||
ctxCancel context.CancelFunc
|
||||
streamWaitGroup sync.WaitGroup
|
||||
|
||||
idleTimeout time.Duration
|
||||
tolerateTimeSkewness time.Duration
|
||||
bufferSize int
|
||||
domainFrontingPort int
|
||||
workerPool *ants.PoolWithFunc
|
||||
telegram *telegram.Telegram
|
||||
allowFallbackOnUnknownDC bool
|
||||
tolerateTimeSkewness time.Duration
|
||||
domainFrontingPort int
|
||||
workerPool *ants.PoolWithFunc
|
||||
telegram *telegram.Telegram
|
||||
|
||||
secret Secret
|
||||
network Network
|
||||
antiReplayCache AntiReplayCache
|
||||
ipBlocklist IPBlocklist
|
||||
blocklist IPBlocklist
|
||||
allowlist IPBlocklist
|
||||
eventStream EventStream
|
||||
logger Logger
|
||||
}
|
||||
@@ -45,7 +46,7 @@ func (p *Proxy) DomainFrontingAddress() string {
|
||||
|
||||
// ServeConn serves a connection. We do not check IP blocklist and
|
||||
// concurrency limit here.
|
||||
func (p *Proxy) ServeConn(conn net.Conn) {
|
||||
func (p *Proxy) ServeConn(conn essentials.Conn) {
|
||||
p.streamWaitGroup.Add(1)
|
||||
defer p.streamWaitGroup.Done()
|
||||
|
||||
@@ -81,13 +82,12 @@ func (p *Proxy) ServeConn(conn net.Conn) {
|
||||
return
|
||||
}
|
||||
|
||||
rel := relay.AcquireRelay(ctx,
|
||||
p.logger.Named("relay"), p.bufferSize, p.idleTimeout)
|
||||
defer relay.ReleaseRelay(rel)
|
||||
|
||||
if err := rel.Process(ctx.clientConn, ctx.telegramConn); err != nil {
|
||||
p.logger.DebugError("relay has been finished", err)
|
||||
}
|
||||
relay.Relay(
|
||||
ctx,
|
||||
ctx.logger.Named("relay"),
|
||||
ctx.telegramConn,
|
||||
ctx.clientConn,
|
||||
)
|
||||
}
|
||||
|
||||
// Serve starts a proxy on a given listener.
|
||||
@@ -106,10 +106,18 @@ func (p *Proxy) Serve(listener net.Listener) error {
|
||||
}
|
||||
}
|
||||
|
||||
ipAddr := conn.RemoteAddr().(*net.TCPAddr).IP
|
||||
ipAddr := conn.RemoteAddr().(*net.TCPAddr).IP // nolint: forcetypeassert
|
||||
logger := p.logger.BindStr("ip", ipAddr.String())
|
||||
|
||||
if p.ipBlocklist.Contains(ipAddr) {
|
||||
if !p.allowlist.Contains(ipAddr) {
|
||||
conn.Close()
|
||||
logger.Info("ip was rejected by allowlist")
|
||||
p.eventStream.Send(p.ctx, NewEventIPAllowlisted(ipAddr))
|
||||
|
||||
continue
|
||||
}
|
||||
|
||||
if p.blocklist.Contains(ipAddr) {
|
||||
conn.Close()
|
||||
logger.Info("ip was blacklisted")
|
||||
p.eventStream.Send(p.ctx, NewEventIPBlocklisted(ipAddr))
|
||||
@@ -136,6 +144,9 @@ func (p *Proxy) Shutdown() {
|
||||
p.ctxCancel()
|
||||
p.streamWaitGroup.Wait()
|
||||
p.workerPool.Release()
|
||||
|
||||
p.allowlist.Shutdown()
|
||||
p.blocklist.Shutdown()
|
||||
}
|
||||
|
||||
func (p *Proxy) doFakeTLSHandshake(ctx *streamContext) bool {
|
||||
@@ -208,7 +219,16 @@ func (p *Proxy) doObfuscated2Handshake(ctx *streamContext) error {
|
||||
}
|
||||
|
||||
func (p *Proxy) doTelegramCall(ctx *streamContext) error {
|
||||
conn, err := p.telegram.Dial(ctx, ctx.dc)
|
||||
dc := ctx.dc
|
||||
|
||||
if p.allowFallbackOnUnknownDC && !p.telegram.IsKnownDC(dc) {
|
||||
dc = p.telegram.GetFallbackDC()
|
||||
ctx.logger = ctx.logger.BindInt("fallback_dc", dc)
|
||||
|
||||
ctx.logger.Warning("unknown DC, fallbacks")
|
||||
}
|
||||
|
||||
conn, err := p.telegram.Dial(ctx, dc)
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot dial to Telegram: %w", err)
|
||||
}
|
||||
@@ -232,7 +252,10 @@ func (p *Proxy) doTelegramCall(ctx *streamContext) error {
|
||||
}
|
||||
|
||||
p.eventStream.Send(ctx,
|
||||
NewEventConnectedToDC(ctx.streamID, conn.RemoteAddr().(*net.TCPAddr).IP, ctx.dc))
|
||||
NewEventConnectedToDC(ctx.streamID,
|
||||
conn.RemoteAddr().(*net.TCPAddr).IP, // nolint: forcetypeassert
|
||||
ctx.dc),
|
||||
)
|
||||
|
||||
return nil
|
||||
}
|
||||
@@ -255,13 +278,12 @@ func (p *Proxy) doDomainFronting(ctx *streamContext, conn *connRewind) {
|
||||
stream: p.eventStream,
|
||||
}
|
||||
|
||||
rel := relay.AcquireRelay(ctx,
|
||||
p.logger.Named("domain-fronting"), p.bufferSize, p.idleTimeout)
|
||||
defer relay.ReleaseRelay(rel)
|
||||
|
||||
if err := rel.Process(conn, frontConn); err != nil {
|
||||
p.logger.DebugError("domain fronting relay has been finished", err)
|
||||
}
|
||||
relay.Relay(
|
||||
ctx,
|
||||
ctx.logger.Named("domain-fronting"),
|
||||
frontConn,
|
||||
conn,
|
||||
)
|
||||
}
|
||||
|
||||
// NewProxy makes a new proxy instance.
|
||||
@@ -277,24 +299,24 @@ func NewProxy(opts ProxyOpts) (*Proxy, error) {
|
||||
|
||||
ctx, cancel := context.WithCancel(context.Background())
|
||||
proxy := &Proxy{
|
||||
ctx: ctx,
|
||||
ctxCancel: cancel,
|
||||
secret: opts.Secret,
|
||||
network: opts.Network,
|
||||
antiReplayCache: opts.AntiReplayCache,
|
||||
ipBlocklist: opts.IPBlocklist,
|
||||
eventStream: opts.EventStream,
|
||||
logger: opts.getLogger("proxy"),
|
||||
domainFrontingPort: opts.getDomainFrontingPort(),
|
||||
tolerateTimeSkewness: opts.getTolerateTimeSkewness(),
|
||||
idleTimeout: opts.getIdleTimeout(),
|
||||
bufferSize: opts.getBufferSize(),
|
||||
telegram: tg,
|
||||
ctx: ctx,
|
||||
ctxCancel: cancel,
|
||||
secret: opts.Secret,
|
||||
network: opts.Network,
|
||||
antiReplayCache: opts.AntiReplayCache,
|
||||
blocklist: opts.IPBlocklist,
|
||||
allowlist: opts.IPAllowlist,
|
||||
eventStream: opts.EventStream,
|
||||
logger: opts.getLogger("proxy"),
|
||||
domainFrontingPort: opts.getDomainFrontingPort(),
|
||||
tolerateTimeSkewness: opts.getTolerateTimeSkewness(),
|
||||
allowFallbackOnUnknownDC: opts.AllowFallbackOnUnknownDC,
|
||||
telegram: tg,
|
||||
}
|
||||
|
||||
pool, err := ants.NewPoolWithFunc(opts.getConcurrency(),
|
||||
func(arg interface{}) {
|
||||
proxy.ServeConn(arg.(net.Conn))
|
||||
proxy.ServeConn(arg.(essentials.Conn)) // nolint: forcetypeassert
|
||||
},
|
||||
ants.WithLogger(opts.getLogger("ants")),
|
||||
ants.WithNonblocking(true))
|
||||
|
||||
+19
-16
@@ -28,6 +28,11 @@ type ProxyOpts struct {
|
||||
// This is a mandatory setting.
|
||||
IPBlocklist IPBlocklist
|
||||
|
||||
// IPAllowlist defines a whitelist of IPs to allow to use proxy.
|
||||
//
|
||||
// This is an optional setting, ignored by default (no restrictions).
|
||||
IPAllowlist IPBlocklist
|
||||
|
||||
// EventStream defines an instance of event stream.
|
||||
//
|
||||
// This ia a mandatory setting.
|
||||
@@ -45,6 +50,8 @@ type ProxyOpts struct {
|
||||
// buffers: to and from.
|
||||
//
|
||||
// This is an optional setting.
|
||||
//
|
||||
// Deprecated: this setting is no longer makes any effect.
|
||||
BufferSize uint
|
||||
|
||||
// Concurrency is a size of the worker pool for connection management.
|
||||
@@ -90,6 +97,16 @@ type ProxyOpts struct {
|
||||
// This is an optional setting.
|
||||
DomainFrontingPort uint
|
||||
|
||||
// AllowFallbackOnUnknownDC defines how proxy behaves if unknown DC was
|
||||
// requested. If this setting is set to false, then such connection
|
||||
// will be rejected. Otherwise, proxy will chose any DC.
|
||||
//
|
||||
// Telegram is designed in a way that any DC can serve any request,
|
||||
// the problem is a latency.
|
||||
//
|
||||
// This is an optional setting.
|
||||
AllowFallbackOnUnknownDC bool
|
||||
|
||||
// UseTestDCs defines if we have to connect to production or to staging
|
||||
// DCs of Telegram.
|
||||
//
|
||||
@@ -108,6 +125,8 @@ func (p ProxyOpts) valid() error {
|
||||
return ErrAntiReplayCacheIsNotDefined
|
||||
case p.IPBlocklist == nil:
|
||||
return ErrIPBlocklistIsNotDefined
|
||||
case p.IPAllowlist == nil:
|
||||
return ErrIPAllowlistIsNotDefined
|
||||
case p.EventStream == nil:
|
||||
return ErrEventStreamIsNotDefined
|
||||
case p.Logger == nil:
|
||||
@@ -119,14 +138,6 @@ func (p ProxyOpts) valid() error {
|
||||
return nil
|
||||
}
|
||||
|
||||
func (p ProxyOpts) getBufferSize() int {
|
||||
if p.BufferSize < 1 {
|
||||
return DefaultBufferSize
|
||||
}
|
||||
|
||||
return int(p.BufferSize)
|
||||
}
|
||||
|
||||
func (p ProxyOpts) getConcurrency() int {
|
||||
if p.Concurrency == 0 {
|
||||
return DefaultConcurrency
|
||||
@@ -143,14 +154,6 @@ func (p ProxyOpts) getDomainFrontingPort() int {
|
||||
return int(p.DomainFrontingPort)
|
||||
}
|
||||
|
||||
func (p ProxyOpts) getIdleTimeout() time.Duration {
|
||||
if p.IdleTimeout == 0 {
|
||||
return DefaultIdleTimeout
|
||||
}
|
||||
|
||||
return p.IdleTimeout
|
||||
}
|
||||
|
||||
func (p ProxyOpts) getTolerateTimeSkewness() time.Duration {
|
||||
if p.TolerateTimeSkewness == 0 {
|
||||
return DefaultTolerateTimeSkewness
|
||||
|
||||
@@ -15,6 +15,7 @@ import (
|
||||
"github.com/9seconds/mtg/v2/antireplay"
|
||||
"github.com/9seconds/mtg/v2/events"
|
||||
"github.com/9seconds/mtg/v2/ipblocklist"
|
||||
"github.com/9seconds/mtg/v2/ipblocklist/files"
|
||||
"github.com/9seconds/mtg/v2/logger"
|
||||
"github.com/9seconds/mtg/v2/mtglib"
|
||||
"github.com/9seconds/mtg/v2/network"
|
||||
@@ -22,6 +23,7 @@ import (
|
||||
"github.com/gotd/td/telegram/dcs"
|
||||
"github.com/gotd/td/tg"
|
||||
"github.com/stretchr/testify/suite"
|
||||
"github.com/yl2chen/cidranger"
|
||||
)
|
||||
|
||||
type ProxyTestSuite struct {
|
||||
@@ -49,11 +51,26 @@ func (suite *ProxyTestSuite) SetupSuite() {
|
||||
ntw, err := network.NewNetwork(dialer, "mtgtest", "1.1.1.1", 0)
|
||||
suite.NoError(err)
|
||||
|
||||
allowlist, _ := ipblocklist.NewFireholFromFiles(
|
||||
logger.NewNoopLogger(),
|
||||
1,
|
||||
[]files.File{
|
||||
files.NewMem([]*net.IPNet{
|
||||
cidranger.AllIPv4,
|
||||
cidranger.AllIPv6,
|
||||
}),
|
||||
},
|
||||
nil,
|
||||
)
|
||||
|
||||
go allowlist.Run(time.Second)
|
||||
|
||||
suite.opts = &mtglib.ProxyOpts{
|
||||
Secret: mtglib.GenerateSecret("httpbin.org"),
|
||||
Network: ntw,
|
||||
AntiReplayCache: antireplay.NewNoop(),
|
||||
IPBlocklist: ipblocklist.NewNoop(),
|
||||
IPAllowlist: allowlist,
|
||||
EventStream: events.NewNoopStream(),
|
||||
Logger: logger.NewNoopLogger(),
|
||||
UseTestDCs: true,
|
||||
@@ -114,6 +131,14 @@ func (suite *ProxyTestSuite) TestCannotInitNoIPBlocklist() {
|
||||
suite.Error(err)
|
||||
}
|
||||
|
||||
func (suite *ProxyTestSuite) TestCannotInitNoIPAllowlist() {
|
||||
opts := *suite.opts
|
||||
opts.IPAllowlist = nil
|
||||
|
||||
_, err := mtglib.NewProxy(opts)
|
||||
suite.Error(err)
|
||||
}
|
||||
|
||||
func (suite *ProxyTestSuite) TestCannotInitNoEventStream() {
|
||||
opts := *suite.opts
|
||||
opts.EventStream = nil
|
||||
|
||||
@@ -6,13 +6,15 @@ import (
|
||||
"encoding/base64"
|
||||
"net"
|
||||
"time"
|
||||
|
||||
"github.com/9seconds/mtg/v2/essentials"
|
||||
)
|
||||
|
||||
type streamContext struct {
|
||||
ctx context.Context
|
||||
ctxCancel context.CancelFunc
|
||||
clientConn net.Conn
|
||||
telegramConn net.Conn
|
||||
clientConn essentials.Conn
|
||||
telegramConn essentials.Conn
|
||||
streamID string
|
||||
dc int
|
||||
logger Logger
|
||||
@@ -47,10 +49,10 @@ func (s *streamContext) Close() {
|
||||
}
|
||||
|
||||
func (s *streamContext) ClientIP() net.IP {
|
||||
return s.clientConn.RemoteAddr().(*net.TCPAddr).IP
|
||||
return s.clientConn.RemoteAddr().(*net.TCPAddr).IP // nolint: forcetypeassert
|
||||
}
|
||||
|
||||
func newStreamContext(ctx context.Context, logger Logger, clientConn net.Conn) *streamContext {
|
||||
func newStreamContext(ctx context.Context, logger Logger, clientConn essentials.Conn) *streamContext {
|
||||
connIDBytes := make([]byte, ConnectionIDBytesLength)
|
||||
|
||||
if _, err := rand.Read(connIDBytes); err != nil {
|
||||
|
||||
@@ -12,7 +12,7 @@ import (
|
||||
type StreamContextTestSuite struct {
|
||||
suite.Suite
|
||||
|
||||
connMock *testlib.NetConnMock
|
||||
connMock *testlib.EssentialsConnMock
|
||||
logger NoopLogger
|
||||
ctx *streamContext
|
||||
ctxCancel context.CancelFunc
|
||||
@@ -27,7 +27,7 @@ func (suite *StreamContextTestSuite) SetupTest() {
|
||||
ctx = context.WithValue(ctx, "key", "value") // nolint: golint, revive, staticcheck
|
||||
|
||||
suite.ctxCancel = cancel
|
||||
suite.connMock = &testlib.NetConnMock{}
|
||||
suite.connMock = &testlib.EssentialsConnMock{}
|
||||
|
||||
addr := &net.TCPAddr{
|
||||
IP: net.ParseIP("10.0.0.10"),
|
||||
@@ -73,7 +73,7 @@ func (suite *StreamContextTestSuite) TestClientIP() {
|
||||
func (suite *StreamContextTestSuite) TestClose() {
|
||||
suite.connMock.On("Close").Once().Return(nil)
|
||||
|
||||
tgConnMock := &testlib.NetConnMock{}
|
||||
tgConnMock := &testlib.EssentialsConnMock{}
|
||||
tgConnMock.On("Close").Once().Return(nil)
|
||||
|
||||
suite.ctx.telegramConn = tgConnMock
|
||||
|
||||
@@ -2,9 +2,10 @@ package network
|
||||
|
||||
import (
|
||||
"context"
|
||||
"net"
|
||||
"sync/atomic"
|
||||
"time"
|
||||
|
||||
"github.com/9seconds/mtg/v2/essentials"
|
||||
)
|
||||
|
||||
const (
|
||||
@@ -30,12 +31,13 @@ type circuitBreakerDialer struct {
|
||||
resetFailuresTimeout time.Duration
|
||||
}
|
||||
|
||||
func (c *circuitBreakerDialer) Dial(network, address string) (net.Conn, error) {
|
||||
func (c *circuitBreakerDialer) Dial(network, address string) (essentials.Conn, error) {
|
||||
return c.DialContext(context.Background(), network, address)
|
||||
}
|
||||
|
||||
func (c *circuitBreakerDialer) DialContext(ctx context.Context,
|
||||
network, address string) (net.Conn, error) {
|
||||
network, address string,
|
||||
) (essentials.Conn, error) {
|
||||
switch atomic.LoadUint32(&c.state) {
|
||||
case circuitBreakerStateClosed:
|
||||
return c.doClosed(ctx, network, address)
|
||||
@@ -47,7 +49,8 @@ func (c *circuitBreakerDialer) DialContext(ctx context.Context,
|
||||
}
|
||||
|
||||
func (c *circuitBreakerDialer) doClosed(ctx context.Context,
|
||||
network, address string) (net.Conn, error) {
|
||||
network, address string,
|
||||
) (essentials.Conn, error) {
|
||||
conn, err := c.Dialer.DialContext(ctx, network, address)
|
||||
|
||||
select {
|
||||
@@ -78,7 +81,9 @@ func (c *circuitBreakerDialer) doClosed(ctx context.Context,
|
||||
return conn, err // nolint: wrapcheck
|
||||
}
|
||||
|
||||
func (c *circuitBreakerDialer) doHalfOpened(ctx context.Context, network, address string) (net.Conn, error) {
|
||||
func (c *circuitBreakerDialer) doHalfOpened(ctx context.Context,
|
||||
network, address string,
|
||||
) (essentials.Conn, error) {
|
||||
if !atomic.CompareAndSwapUint32(&c.halfOpenAttempts, 0, 1) {
|
||||
return nil, ErrCircuitBreakerOpened
|
||||
}
|
||||
@@ -172,14 +177,16 @@ func (c *circuitBreakerDialer) stopTimer(timerRef **time.Timer) {
|
||||
}
|
||||
|
||||
func (c *circuitBreakerDialer) ensureTimer(timerRef **time.Timer,
|
||||
timeout time.Duration, callback func()) {
|
||||
timeout time.Duration, callback func(),
|
||||
) {
|
||||
if *timerRef == nil {
|
||||
*timerRef = time.AfterFunc(timeout, callback)
|
||||
}
|
||||
}
|
||||
|
||||
func newCircuitBreakerDialer(baseDialer Dialer,
|
||||
openThreshold uint32, halfOpenTimeout, resetFailuresTimeout time.Duration) Dialer {
|
||||
openThreshold uint32, halfOpenTimeout, resetFailuresTimeout time.Duration,
|
||||
) Dialer {
|
||||
cb := &circuitBreakerDialer{
|
||||
Dialer: baseDialer,
|
||||
stateMutexChan: make(chan bool, 1),
|
||||
|
||||
@@ -21,7 +21,7 @@ type CircuitBreakerTestSuite struct {
|
||||
mutex sync.Mutex
|
||||
ctx context.Context
|
||||
ctxCancel context.CancelFunc
|
||||
connMock *testlib.NetConnMock
|
||||
connMock *testlib.EssentialsConnMock
|
||||
baseDialerMock *DialerMock
|
||||
}
|
||||
|
||||
@@ -29,7 +29,7 @@ func (suite *CircuitBreakerTestSuite) SetupTest() {
|
||||
suite.mutex = sync.Mutex{}
|
||||
suite.ctx, suite.ctxCancel = context.WithCancel(context.Background())
|
||||
suite.baseDialerMock = &DialerMock{}
|
||||
suite.connMock = &testlib.NetConnMock{}
|
||||
suite.connMock = &testlib.EssentialsConnMock{}
|
||||
suite.d = newCircuitBreakerDialer(suite.baseDialerMock,
|
||||
3, 100*time.Millisecond, 50*time.Millisecond)
|
||||
}
|
||||
|
||||
+11
-42
@@ -6,20 +6,18 @@ import (
|
||||
"net"
|
||||
"time"
|
||||
|
||||
"github.com/libp2p/go-reuseport"
|
||||
"github.com/9seconds/mtg/v2/essentials"
|
||||
)
|
||||
|
||||
type defaultDialer struct {
|
||||
net.Dialer
|
||||
|
||||
bufferSize int
|
||||
}
|
||||
|
||||
func (d *defaultDialer) Dial(network, address string) (net.Conn, error) {
|
||||
func (d *defaultDialer) Dial(network, address string) (essentials.Conn, error) {
|
||||
return d.DialContext(context.Background(), network, address)
|
||||
}
|
||||
|
||||
func (d *defaultDialer) DialContext(ctx context.Context, network, address string) (net.Conn, error) {
|
||||
func (d *defaultDialer) DialContext(ctx context.Context, network, address string) (essentials.Conn, error) {
|
||||
switch network {
|
||||
case "tcp", "tcp4", "tcp6": // nolint: goconst
|
||||
default:
|
||||
@@ -31,36 +29,14 @@ func (d *defaultDialer) DialContext(ctx context.Context, network, address string
|
||||
return nil, fmt.Errorf("cannot dial to %s: %w", address, err)
|
||||
}
|
||||
|
||||
tcpConn, ok := conn.(*net.TCPConn)
|
||||
if !ok {
|
||||
panic("conn type is not tcp")
|
||||
}
|
||||
|
||||
if err := tcpConn.SetNoDelay(true); err != nil {
|
||||
// we do not need to call to end user. End users call us.
|
||||
if err := SetServerSocketOptions(conn, 0); err != nil {
|
||||
conn.Close()
|
||||
|
||||
return nil, fmt.Errorf("cannot set TCP_NO_DELAY: %w", err)
|
||||
return nil, fmt.Errorf("cannot set socket options: %w", err)
|
||||
}
|
||||
|
||||
if err := tcpConn.SetReadBuffer(d.bufferSize); err != nil {
|
||||
tcpConn.Close()
|
||||
|
||||
return nil, fmt.Errorf("cannot set read buffer size: %w", err)
|
||||
}
|
||||
|
||||
if err := tcpConn.SetWriteBuffer(d.bufferSize); err != nil {
|
||||
tcpConn.Close()
|
||||
|
||||
return nil, fmt.Errorf("cannot set write buffer size: %w", err)
|
||||
}
|
||||
|
||||
if err := tcpConn.SetKeepAlive(true); err != nil {
|
||||
tcpConn.Close()
|
||||
|
||||
return nil, fmt.Errorf("cannot enable keep-alive: %w", err)
|
||||
}
|
||||
|
||||
return tcpConn, nil
|
||||
return conn.(essentials.Conn), nil // nolint: forcetypeassert
|
||||
}
|
||||
|
||||
// NewDefaultDialer build a new dialer which dials bypassing proxies
|
||||
@@ -68,27 +44,20 @@ func (d *defaultDialer) DialContext(ctx context.Context, network, address string
|
||||
//
|
||||
// The most default one you can imagine. But it has tunes TCP
|
||||
// connections and setups SO_REUSEPORT.
|
||||
//
|
||||
// bufferSize is deprecated and ignored. It is kept here for backward
|
||||
// compatibility.
|
||||
func NewDefaultDialer(timeout time.Duration, bufferSize int) (Dialer, error) {
|
||||
switch {
|
||||
case timeout < 0:
|
||||
return nil, fmt.Errorf("timeout %v should be positive number", timeout)
|
||||
case bufferSize < 0:
|
||||
return nil, fmt.Errorf("buffer size %d should be positive number", bufferSize)
|
||||
}
|
||||
|
||||
if timeout == 0 {
|
||||
case timeout == 0:
|
||||
timeout = DefaultTimeout
|
||||
}
|
||||
|
||||
if bufferSize == 0 {
|
||||
bufferSize = DefaultBufferSize
|
||||
}
|
||||
|
||||
return &defaultDialer{
|
||||
Dialer: net.Dialer{
|
||||
Timeout: timeout,
|
||||
Control: reuseport.Control,
|
||||
},
|
||||
bufferSize: bufferSize,
|
||||
}, nil
|
||||
}
|
||||
|
||||
@@ -30,11 +30,6 @@ func (suite *DefaultDialerTestSuite) TestNegativeTimeout() {
|
||||
suite.Error(err)
|
||||
}
|
||||
|
||||
func (suite *DefaultDialerTestSuite) TestNegativeBufferSize() {
|
||||
_, err := network.NewDefaultDialer(0, -1)
|
||||
suite.Error(err)
|
||||
}
|
||||
|
||||
func (suite *DefaultDialerTestSuite) TestUnsupportedProtocol() {
|
||||
_, err := suite.d.DialContext(context.Background(),
|
||||
"udp",
|
||||
|
||||
+11
-2
@@ -1,6 +1,8 @@
|
||||
package network
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
"net"
|
||||
"net/http"
|
||||
"sync"
|
||||
"time"
|
||||
@@ -83,8 +85,13 @@ func (d *dnsResolver) LookupAAAA(hostname string) []string {
|
||||
return ips
|
||||
}
|
||||
|
||||
func newDNSResolver(hostname string, httpClient *http.Client) *dnsResolver {
|
||||
return &dnsResolver{
|
||||
func newDNSResolver(hostname string, httpClient *http.Client) (ret *dnsResolver) {
|
||||
if net.ParseIP(hostname).To4() == nil {
|
||||
// the hostname is an IPv6 address
|
||||
hostname = fmt.Sprintf("[%s]", hostname)
|
||||
}
|
||||
|
||||
ret = &dnsResolver{
|
||||
resolver: doh.Resolver{
|
||||
Host: hostname,
|
||||
Class: doh.IN,
|
||||
@@ -92,4 +99,6 @@ func newDNSResolver(hostname string, httpClient *http.Client) *dnsResolver {
|
||||
},
|
||||
cache: map[string]dnsResolverCacheEntry{},
|
||||
}
|
||||
|
||||
return
|
||||
}
|
||||
|
||||
+14
-3
@@ -20,8 +20,9 @@ package network
|
||||
import (
|
||||
"context"
|
||||
"errors"
|
||||
"net"
|
||||
"time"
|
||||
|
||||
"github.com/9seconds/mtg/v2/essentials"
|
||||
)
|
||||
|
||||
const (
|
||||
@@ -33,10 +34,16 @@ const (
|
||||
// request.
|
||||
DefaultHTTPTimeout = 10 * time.Second
|
||||
|
||||
// Deprecated:
|
||||
//
|
||||
// DefaultBufferSize defines a TCP buffer size. Both read and write, so
|
||||
// for real size, please multiply this number by 2.
|
||||
DefaultBufferSize = 16 * 1024 // 16 kib
|
||||
|
||||
// DefaultTCPKeepAlivePeriod defines a time period between 2
|
||||
// consequitive probes.
|
||||
DefaultTCPKeepAlivePeriod = 10 * time.Second
|
||||
|
||||
// ProxyDialerOpenThreshold is used for load balancing SOCKS5 dialer
|
||||
// only.
|
||||
//
|
||||
@@ -70,6 +77,10 @@ const (
|
||||
|
||||
// DNSTimeout defines a timeout for DNS queries.
|
||||
DNSTimeout = 5 * time.Second
|
||||
|
||||
// tcpLingerTimeout defines a number of seconds to wait for sending
|
||||
// unacknowledged data.
|
||||
tcpLingerTimeout = 1
|
||||
)
|
||||
|
||||
var (
|
||||
@@ -85,6 +96,6 @@ var (
|
||||
// Dialer defines an interface which is required to bootstrap a network
|
||||
// instance from.
|
||||
type Dialer interface {
|
||||
Dial(network, address string) (net.Conn, error)
|
||||
DialContext(ctx context.Context, network, address string) (net.Conn, error)
|
||||
Dial(network, address string) (essentials.Conn, error)
|
||||
DialContext(ctx context.Context, network, address string) (essentials.Conn, error)
|
||||
}
|
||||
|
||||
@@ -2,8 +2,8 @@ package network
|
||||
|
||||
import (
|
||||
"context"
|
||||
"net"
|
||||
|
||||
"github.com/9seconds/mtg/v2/essentials"
|
||||
"github.com/stretchr/testify/mock"
|
||||
)
|
||||
|
||||
@@ -11,14 +11,14 @@ type DialerMock struct {
|
||||
mock.Mock
|
||||
}
|
||||
|
||||
func (d *DialerMock) Dial(network, address string) (net.Conn, error) {
|
||||
func (d *DialerMock) Dial(network, address string) (essentials.Conn, error) {
|
||||
args := d.Called(network, address)
|
||||
|
||||
return args.Get(0).(net.Conn), args.Error(1) // nolint: wrapcheck
|
||||
return args.Get(0).(essentials.Conn), args.Error(1) // nolint: wrapcheck, forcetypeassert
|
||||
}
|
||||
|
||||
func (d *DialerMock) DialContext(ctx context.Context, network, address string) (net.Conn, error) {
|
||||
func (d *DialerMock) DialContext(ctx context.Context, network, address string) (essentials.Conn, error) {
|
||||
args := d.Called(ctx, network, address)
|
||||
|
||||
return args.Get(0).(net.Conn), args.Error(1) // nolint: wrapcheck
|
||||
return args.Get(0).(essentials.Conn), args.Error(1) // nolint: wrapcheck, forcetypeassert
|
||||
}
|
||||
|
||||
@@ -8,6 +8,7 @@ import (
|
||||
"net/url"
|
||||
"strings"
|
||||
|
||||
"github.com/9seconds/mtg/v2/essentials"
|
||||
"github.com/9seconds/mtg/v2/network"
|
||||
socks5 "github.com/armon/go-socks5"
|
||||
"github.com/mccutchen/go-httpbin/httpbin"
|
||||
@@ -18,16 +19,16 @@ type DialerMock struct {
|
||||
mock.Mock
|
||||
}
|
||||
|
||||
func (d *DialerMock) Dial(network, address string) (net.Conn, error) {
|
||||
func (d *DialerMock) Dial(network, address string) (essentials.Conn, error) {
|
||||
args := d.Called(network, address)
|
||||
|
||||
return args.Get(0).(net.Conn), args.Error(1) // nolint: wrapcheck
|
||||
return args.Get(0).(essentials.Conn), args.Error(1) // nolint: wrapcheck, forcetypeassert
|
||||
}
|
||||
|
||||
func (d *DialerMock) DialContext(ctx context.Context, network, address string) (net.Conn, error) {
|
||||
func (d *DialerMock) DialContext(ctx context.Context, network, address string) (essentials.Conn, error) {
|
||||
args := d.Called(ctx, network, address)
|
||||
|
||||
return args.Get(0).(net.Conn), args.Error(1) // nolint: wrapcheck
|
||||
return args.Get(0).(essentials.Conn), args.Error(1) // nolint: wrapcheck, forcetypeassert
|
||||
}
|
||||
|
||||
type HTTPServerTestSuite struct {
|
||||
@@ -53,7 +54,9 @@ func (suite *HTTPServerTestSuite) MakeURL(path string) string {
|
||||
func (suite *HTTPServerTestSuite) MakeHTTPClient(dialer network.Dialer) *http.Client {
|
||||
return &http.Client{
|
||||
Transport: &http.Transport{
|
||||
DialContext: dialer.DialContext,
|
||||
DialContext: func(ctx context.Context, network, address string) (net.Conn, error) {
|
||||
return dialer.DialContext(ctx, network, address) // nolint: wrapcheck
|
||||
},
|
||||
},
|
||||
}
|
||||
}
|
||||
|
||||
@@ -4,19 +4,20 @@ import (
|
||||
"context"
|
||||
"fmt"
|
||||
"math/rand"
|
||||
"net"
|
||||
"net/url"
|
||||
|
||||
"github.com/9seconds/mtg/v2/essentials"
|
||||
)
|
||||
|
||||
type loadBalancedSocks5Dialer struct {
|
||||
dialers []Dialer
|
||||
}
|
||||
|
||||
func (l loadBalancedSocks5Dialer) Dial(network, address string) (net.Conn, error) {
|
||||
func (l loadBalancedSocks5Dialer) Dial(network, address string) (essentials.Conn, error) {
|
||||
return l.DialContext(context.Background(), network, address)
|
||||
}
|
||||
|
||||
func (l loadBalancedSocks5Dialer) DialContext(ctx context.Context, network, address string) (net.Conn, error) {
|
||||
func (l loadBalancedSocks5Dialer) DialContext(ctx context.Context, network, address string) (essentials.Conn, error) {
|
||||
length := len(l.dialers)
|
||||
start := rand.Intn(length)
|
||||
moved := false
|
||||
|
||||
+14
-7
@@ -9,6 +9,7 @@ import (
|
||||
"sync"
|
||||
"time"
|
||||
|
||||
"github.com/9seconds/mtg/v2/essentials"
|
||||
"github.com/9seconds/mtg/v2/mtglib"
|
||||
)
|
||||
|
||||
@@ -30,11 +31,11 @@ type network struct {
|
||||
dns *dnsResolver
|
||||
}
|
||||
|
||||
func (n *network) Dial(protocol, address string) (net.Conn, error) {
|
||||
func (n *network) Dial(protocol, address string) (essentials.Conn, error) {
|
||||
return n.DialContext(context.Background(), protocol, address)
|
||||
}
|
||||
|
||||
func (n *network) DialContext(ctx context.Context, protocol, address string) (net.Conn, error) {
|
||||
func (n *network) DialContext(ctx context.Context, protocol, address string) (essentials.Conn, error) {
|
||||
host, port, _ := net.SplitHostPort(address)
|
||||
|
||||
ips, err := n.dnsResolve(protocol, host)
|
||||
@@ -46,7 +47,8 @@ func (n *network) DialContext(ctx context.Context, protocol, address string) (ne
|
||||
ips[i], ips[j] = ips[j], ips[i]
|
||||
})
|
||||
|
||||
var conn net.Conn
|
||||
var conn essentials.Conn
|
||||
|
||||
for _, v := range ips {
|
||||
conn, err = n.dialer.DialContext(ctx, protocol, net.JoinHostPort(v, port))
|
||||
|
||||
@@ -59,7 +61,8 @@ func (n *network) DialContext(ctx context.Context, protocol, address string) (ne
|
||||
}
|
||||
|
||||
func (n *network) MakeHTTPClient(dialFunc func(ctx context.Context,
|
||||
network, address string) (net.Conn, error)) *http.Client {
|
||||
network, address string) (essentials.Conn, error),
|
||||
) *http.Client {
|
||||
if dialFunc == nil {
|
||||
dialFunc = n.DialContext
|
||||
}
|
||||
@@ -121,7 +124,8 @@ func (n *network) dnsResolve(protocol, address string) ([]string, error) {
|
||||
// It brings simple DNS cache and DNS-Over-HTTPS when necessary.
|
||||
func NewNetwork(dialer Dialer,
|
||||
userAgent, dohHostname string,
|
||||
httpTimeout time.Duration) (mtglib.Network, error) {
|
||||
httpTimeout time.Duration,
|
||||
) (mtglib.Network, error) {
|
||||
switch {
|
||||
case httpTimeout < 0:
|
||||
return nil, fmt.Errorf("timeout should be positive number %s", httpTimeout)
|
||||
@@ -144,13 +148,16 @@ func NewNetwork(dialer Dialer,
|
||||
|
||||
func makeHTTPClient(userAgent string,
|
||||
timeout time.Duration,
|
||||
dialFunc func(ctx context.Context, network, address string) (net.Conn, error)) *http.Client {
|
||||
dialFunc func(ctx context.Context, network, address string) (essentials.Conn, error),
|
||||
) *http.Client {
|
||||
return &http.Client{
|
||||
Timeout: timeout,
|
||||
Transport: networkHTTPTransport{
|
||||
userAgent: userAgent,
|
||||
next: &http.Transport{
|
||||
DialContext: dialFunc,
|
||||
DialContext: func(ctx context.Context, network, address string) (net.Conn, error) {
|
||||
return dialFunc(ctx, network, address)
|
||||
},
|
||||
},
|
||||
},
|
||||
}
|
||||
|
||||
@@ -0,0 +1,41 @@
|
||||
package network
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
"net"
|
||||
)
|
||||
|
||||
// SetClientSocketOptions tunes a TCP socket that represents a connection to
|
||||
// end user (not Telegram service or fronting domain).
|
||||
//
|
||||
// bufferSize setting is deprecated and ignored.
|
||||
func SetClientSocketOptions(conn net.Conn, bufferSize int) error {
|
||||
return setCommonSocketOptions(conn.(*net.TCPConn)) // nolint: forcetypeassert
|
||||
}
|
||||
|
||||
// SetServerSocketOptions tunes a TCP socket that represents a connection to
|
||||
// remote server like Telegram or fronting domain (but not end user).
|
||||
func SetServerSocketOptions(conn net.Conn, bufferSize int) error {
|
||||
return setCommonSocketOptions(conn.(*net.TCPConn)) // nolint: forcetypeassert
|
||||
}
|
||||
|
||||
func setCommonSocketOptions(conn *net.TCPConn) error {
|
||||
if err := conn.SetKeepAlivePeriod(DefaultTCPKeepAlivePeriod); err != nil {
|
||||
return fmt.Errorf("cannot set time period of TCP keepalive probes: %w", err)
|
||||
}
|
||||
|
||||
if err := conn.SetLinger(tcpLingerTimeout); err != nil {
|
||||
return fmt.Errorf("cannot set TCP linger timeout: %w", err)
|
||||
}
|
||||
|
||||
rawConn, err := conn.SyscallConn()
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot get underlying raw connection: %w", err)
|
||||
}
|
||||
|
||||
if err := setSocketReuseAddrPort(rawConn); err != nil {
|
||||
return fmt.Errorf("cannot setup SO_REUSEADDR/PORT: %w", err)
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
@@ -0,0 +1,31 @@
|
||||
//go:build !windows
|
||||
// +build !windows
|
||||
|
||||
package network
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
"syscall"
|
||||
|
||||
"golang.org/x/sys/unix"
|
||||
)
|
||||
|
||||
func setSocketReuseAddrPort(conn syscall.RawConn) error {
|
||||
var err error
|
||||
|
||||
conn.Control(func(fd uintptr) { // nolint: errcheck
|
||||
err = unix.SetsockoptInt(int(fd), unix.SOL_SOCKET, unix.SO_REUSEADDR, 1)
|
||||
if err != nil {
|
||||
err = fmt.Errorf("cannot set SO_REUSEADDR: %w", err)
|
||||
|
||||
return
|
||||
}
|
||||
|
||||
err = unix.SetsockoptInt(int(fd), unix.SOL_SOCKET, unix.SO_REUSEPORT, 1)
|
||||
if err != nil {
|
||||
err = fmt.Errorf("cannot set SO_REUSEPORT: %w", err)
|
||||
}
|
||||
})
|
||||
|
||||
return err
|
||||
}
|
||||
@@ -0,0 +1,10 @@
|
||||
//go:build windows
|
||||
// +build windows
|
||||
|
||||
package network
|
||||
|
||||
import "syscall"
|
||||
|
||||
func setSocketReuseAddrPort(conn syscall.RawConn) error {
|
||||
return nil
|
||||
}
|
||||
+146
-5
@@ -1,21 +1,162 @@
|
||||
package network
|
||||
|
||||
import (
|
||||
"context"
|
||||
"fmt"
|
||||
"io"
|
||||
"net"
|
||||
"net/url"
|
||||
|
||||
"golang.org/x/net/proxy"
|
||||
"github.com/9seconds/mtg/v2/essentials"
|
||||
"github.com/txthinking/socks5"
|
||||
)
|
||||
|
||||
type socks5Dialer struct {
|
||||
Dialer
|
||||
|
||||
username []byte
|
||||
password []byte
|
||||
proxyAddress string
|
||||
}
|
||||
|
||||
func (s socks5Dialer) Dial(network, address string) (essentials.Conn, error) {
|
||||
return s.DialContext(context.Background(), network, address)
|
||||
}
|
||||
|
||||
func (s socks5Dialer) DialContext(ctx context.Context, network, address string) (essentials.Conn, error) {
|
||||
switch network {
|
||||
case "tcp", "tcp4", "tcp6":
|
||||
default:
|
||||
return nil, fmt.Errorf("%s network type is not supported", network)
|
||||
}
|
||||
|
||||
conn, err := s.Dialer.DialContext(ctx, network, s.proxyAddress)
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("cannot dial to the proxy: %w", err)
|
||||
}
|
||||
|
||||
if err := s.handshake(conn); err != nil {
|
||||
conn.Close()
|
||||
|
||||
return nil, fmt.Errorf("cannot perform a handshake: %w", err)
|
||||
}
|
||||
|
||||
if err := s.connect(conn, address); err != nil {
|
||||
conn.Close()
|
||||
|
||||
return nil, fmt.Errorf("cannot connect to a destination host %s: %w", address, err)
|
||||
}
|
||||
|
||||
return conn, nil
|
||||
}
|
||||
|
||||
func (s socks5Dialer) handshake(conn io.ReadWriter) error {
|
||||
authMethod := socks5.MethodUsernamePassword
|
||||
if len(s.username)+len(s.password) == 0 {
|
||||
authMethod = socks5.MethodNone
|
||||
}
|
||||
|
||||
if err := s.handshakeNegotiation(conn, authMethod); err != nil {
|
||||
return fmt.Errorf("cannot perform negotiation: %w", err)
|
||||
}
|
||||
|
||||
if authMethod == socks5.MethodNone {
|
||||
return nil
|
||||
}
|
||||
|
||||
if err := s.handshakeAuth(conn); err != nil {
|
||||
return fmt.Errorf("cannot authenticate: %w", err)
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
func (s socks5Dialer) handshakeNegotiation(conn io.ReadWriter, authMethod byte) error {
|
||||
request := socks5.NewNegotiationRequest([]byte{authMethod})
|
||||
if _, err := request.WriteTo(conn); err != nil {
|
||||
return fmt.Errorf("cannot send request: %w", err)
|
||||
}
|
||||
|
||||
response, err := socks5.NewNegotiationReplyFrom(conn)
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot read response: %w", err)
|
||||
}
|
||||
|
||||
if response.Method != authMethod {
|
||||
return fmt.Errorf("%v is unsupported auth method", authMethod)
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
func (s socks5Dialer) handshakeAuth(conn io.ReadWriter) error {
|
||||
request := socks5.NewUserPassNegotiationRequest(s.username, s.password)
|
||||
|
||||
if _, err := request.WriteTo(conn); err != nil {
|
||||
return fmt.Errorf("cannot send a request: %w", err)
|
||||
}
|
||||
|
||||
response, err := socks5.NewUserPassNegotiationReplyFrom(conn)
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot read a response: %w", err)
|
||||
}
|
||||
|
||||
if response.Status != socks5.UserPassStatusSuccess {
|
||||
return fmt.Errorf("authenticate has failed: %v", response.Status)
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
func (s socks5Dialer) connect(conn io.ReadWriter, address string) error {
|
||||
addrType, host, port, err := socks5.ParseAddress(address)
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot parse address: %w", err)
|
||||
}
|
||||
|
||||
if addrType == socks5.ATYPDomain {
|
||||
host = host[1:]
|
||||
}
|
||||
|
||||
request := socks5.NewRequest(socks5.CmdConnect, addrType, host, port)
|
||||
|
||||
if _, err := request.WriteTo(conn); err != nil {
|
||||
return fmt.Errorf("cannot send a request: %w", err)
|
||||
}
|
||||
|
||||
response, err := socks5.NewReplyFrom(conn)
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot read a response: %w", err)
|
||||
}
|
||||
|
||||
if response.Rep != socks5.RepSuccess {
|
||||
return fmt.Errorf("unsuccessful request: %v", response.Rep)
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
// NewSocks5Dialer build a new dialer from a given one (so, in theory
|
||||
// you can chain here). Proxy parameters are passed with URI in a form of:
|
||||
//
|
||||
// socks5://[user:[password]]@host:port
|
||||
func NewSocks5Dialer(baseDialer Dialer, proxyURL *url.URL) (Dialer, error) {
|
||||
rv, err := proxy.FromURL(proxyURL, baseDialer)
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("cannot initialize socks5 proxy dialer: %w", err)
|
||||
if _, _, err := net.SplitHostPort(proxyURL.Host); err != nil {
|
||||
return nil, fmt.Errorf("incorrect url %s", proxyURL.Redacted())
|
||||
}
|
||||
|
||||
return rv.(Dialer), nil
|
||||
dialer := socks5Dialer{
|
||||
Dialer: baseDialer,
|
||||
proxyAddress: proxyURL.Host,
|
||||
}
|
||||
|
||||
if proxyURL.User != nil {
|
||||
password, isSet := proxyURL.User.Password()
|
||||
if isSet {
|
||||
dialer.username = []byte(proxyURL.User.Username())
|
||||
dialer.password = []byte(password)
|
||||
}
|
||||
}
|
||||
|
||||
return dialer, nil
|
||||
}
|
||||
|
||||
@@ -55,7 +55,7 @@ func (suite *Socks5TestSuite) TestRequestOk() {
|
||||
suite.Equal(http.StatusOK, resp.StatusCode)
|
||||
}
|
||||
|
||||
func TestSocks5TestSuite(t *testing.T) {
|
||||
func TestSocks5(t *testing.T) {
|
||||
t.Parallel()
|
||||
suite.Run(t, &Socks5TestSuite{})
|
||||
}
|
||||
|
||||
@@ -89,6 +89,13 @@ const (
|
||||
// Type: counter
|
||||
MetricReplayAttacks = "replay_attacks"
|
||||
|
||||
// MetricIPListSize defines a metric for the size of the the ip list.
|
||||
//
|
||||
// Type: gauge
|
||||
// Tags:
|
||||
// ip_list | 'allowlist' or 'blocklist'
|
||||
MetricIPListSize = "iplist_size"
|
||||
|
||||
// TagIPFamily defines a name of the 'ip_family' tag and all values.
|
||||
TagIPFamily = "ip_family"
|
||||
|
||||
@@ -114,4 +121,13 @@ const (
|
||||
// TagDirectionFromClient defines that traffic is sent from a client to
|
||||
// Telegram.
|
||||
TagDirectionFromClient = "from_client"
|
||||
|
||||
// TagIPList defines a name of the 'ip_list' and all values.
|
||||
TagIPList = "ip_list"
|
||||
|
||||
// TagIPListAllow defines a value of 'ip_list' of allowlist.
|
||||
TagIPListAllow = "allowlist"
|
||||
|
||||
// TagIPListBlock defines a value of 'ip_list' of blocklist.
|
||||
TagIPListBlock = "blocklist"
|
||||
)
|
||||
|
||||
+1
-1
@@ -11,7 +11,7 @@ var streamInfoPool = sync.Pool{
|
||||
}
|
||||
|
||||
func acquireStreamInfo() *streamInfo {
|
||||
return streamInfoPool.Get().(*streamInfo)
|
||||
return streamInfoPool.Get().(*streamInfo) // nolint: forcetypeassert
|
||||
}
|
||||
|
||||
func releaseStreamInfo(info *streamInfo) {
|
||||
|
||||
+30
-9
@@ -110,14 +110,28 @@ func (p prometheusProcessor) EventConcurrencyLimited(_ mtglib.EventConcurrencyLi
|
||||
p.factory.metricConcurrencyLimited.Inc()
|
||||
}
|
||||
|
||||
func (p prometheusProcessor) EventIPBlocklisted(_ mtglib.EventIPBlocklisted) {
|
||||
p.factory.metricIPBlocklisted.Inc()
|
||||
func (p prometheusProcessor) EventIPBlocklisted(evt mtglib.EventIPBlocklisted) {
|
||||
tag := TagIPListBlock
|
||||
if !evt.IsBlockList {
|
||||
tag = TagIPListAllow
|
||||
}
|
||||
|
||||
p.factory.metricIPBlocklisted.WithLabelValues(tag).Inc()
|
||||
}
|
||||
|
||||
func (p prometheusProcessor) EventReplayAttack(_ mtglib.EventReplayAttack) {
|
||||
p.factory.metricReplayAttacks.Inc()
|
||||
}
|
||||
|
||||
func (p prometheusProcessor) EventIPListSize(evt mtglib.EventIPListSize) {
|
||||
tag := TagIPListBlock
|
||||
if !evt.IsBlockList {
|
||||
tag = TagIPListAllow
|
||||
}
|
||||
|
||||
p.factory.metricIPListSize.WithLabelValues(tag).Set(float64(evt.Size))
|
||||
}
|
||||
|
||||
func (p prometheusProcessor) Shutdown() {
|
||||
for k, v := range p.streams {
|
||||
releaseStreamInfo(v)
|
||||
@@ -137,13 +151,14 @@ type PrometheusFactory struct {
|
||||
metricClientConnections *prometheus.GaugeVec
|
||||
metricTelegramConnections *prometheus.GaugeVec
|
||||
metricDomainFrontingConnections *prometheus.GaugeVec
|
||||
metricIPListSize *prometheus.GaugeVec
|
||||
|
||||
metricTelegramTraffic *prometheus.CounterVec
|
||||
metricDomainFrontingTraffic *prometheus.CounterVec
|
||||
metricIPBlocklisted *prometheus.CounterVec
|
||||
|
||||
metricDomainFronting prometheus.Counter
|
||||
metricConcurrencyLimited prometheus.Counter
|
||||
metricIPBlocklisted prometheus.Counter
|
||||
metricReplayAttacks prometheus.Counter
|
||||
}
|
||||
|
||||
@@ -197,6 +212,11 @@ func NewPrometheus(metricPrefix, httpPath string) *PrometheusFactory { // nolint
|
||||
Name: MetricDomainFrontingConnections,
|
||||
Help: "A number of connections which talk to front domain.",
|
||||
}, []string{TagIPFamily}),
|
||||
metricIPListSize: prometheus.NewGaugeVec(prometheus.GaugeOpts{
|
||||
Namespace: metricPrefix,
|
||||
Name: MetricIPListSize,
|
||||
Help: "A size of the ip list (blocklist or allowlist)",
|
||||
}, []string{TagIPList}),
|
||||
|
||||
metricTelegramTraffic: prometheus.NewCounterVec(prometheus.CounterOpts{
|
||||
Namespace: metricPrefix,
|
||||
@@ -208,6 +228,11 @@ func NewPrometheus(metricPrefix, httpPath string) *PrometheusFactory { // nolint
|
||||
Name: MetricDomainFrontingTraffic,
|
||||
Help: "Traffic which is generated talking with front domain.",
|
||||
}, []string{TagDirection}),
|
||||
metricIPBlocklisted: prometheus.NewCounterVec(prometheus.CounterOpts{
|
||||
Namespace: metricPrefix,
|
||||
Name: MetricIPBlocklisted,
|
||||
Help: "A number of rejected sessions due to ip blocklisting.",
|
||||
}, []string{TagIPList}),
|
||||
|
||||
metricDomainFronting: prometheus.NewCounter(prometheus.CounterOpts{
|
||||
Namespace: metricPrefix,
|
||||
@@ -219,11 +244,6 @@ func NewPrometheus(metricPrefix, httpPath string) *PrometheusFactory { // nolint
|
||||
Name: MetricConcurrencyLimited,
|
||||
Help: "A number of sessions that were rejected by concurrency limiter.",
|
||||
}),
|
||||
metricIPBlocklisted: prometheus.NewCounter(prometheus.CounterOpts{
|
||||
Namespace: metricPrefix,
|
||||
Name: MetricIPBlocklisted,
|
||||
Help: "A number of rejected sessions due to ip blocklisting.",
|
||||
}),
|
||||
metricReplayAttacks: prometheus.NewCounter(prometheus.CounterOpts{
|
||||
Namespace: metricPrefix,
|
||||
Name: MetricReplayAttacks,
|
||||
@@ -234,13 +254,14 @@ func NewPrometheus(metricPrefix, httpPath string) *PrometheusFactory { // nolint
|
||||
registry.MustRegister(factory.metricClientConnections)
|
||||
registry.MustRegister(factory.metricTelegramConnections)
|
||||
registry.MustRegister(factory.metricDomainFrontingConnections)
|
||||
registry.MustRegister(factory.metricIPListSize)
|
||||
|
||||
registry.MustRegister(factory.metricTelegramTraffic)
|
||||
registry.MustRegister(factory.metricDomainFrontingTraffic)
|
||||
registry.MustRegister(factory.metricIPBlocklisted)
|
||||
|
||||
registry.MustRegister(factory.metricDomainFronting)
|
||||
registry.MustRegister(factory.metricConcurrencyLimited)
|
||||
registry.MustRegister(factory.metricIPBlocklisted)
|
||||
registry.MustRegister(factory.metricReplayAttacks)
|
||||
|
||||
return factory
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user