2015-09-19 21:54:36 +00:00
|
|
|
package protocol
|
2015-09-07 15:12:31 +00:00
|
|
|
|
|
|
|
import (
|
2016-11-19 13:38:13 +00:00
|
|
|
"fmt"
|
2015-09-07 15:16:30 +00:00
|
|
|
"io"
|
2016-08-20 18:55:45 +00:00
|
|
|
"v2ray.com/core/common/alloc"
|
2016-12-04 08:10:47 +00:00
|
|
|
"v2ray.com/core/common/errors"
|
2016-08-20 18:55:45 +00:00
|
|
|
"v2ray.com/core/common/log"
|
|
|
|
v2net "v2ray.com/core/common/net"
|
|
|
|
"v2ray.com/core/proxy"
|
2015-09-07 15:12:31 +00:00
|
|
|
)
|
|
|
|
|
|
|
|
const (
|
2015-09-17 15:37:04 +00:00
|
|
|
socksVersion = byte(0x05)
|
|
|
|
socks4Version = byte(0x04)
|
2015-09-09 10:13:52 +00:00
|
|
|
|
2015-09-12 09:51:42 +00:00
|
|
|
AuthNotRequired = byte(0x00)
|
|
|
|
AuthGssApi = byte(0x01)
|
|
|
|
AuthUserPass = byte(0x02)
|
|
|
|
AuthNoMatchingMethod = byte(0xFF)
|
2015-09-17 15:37:04 +00:00
|
|
|
|
|
|
|
Socks4RequestGranted = byte(90)
|
|
|
|
Socks4RequestRejected = byte(91)
|
|
|
|
)
|
|
|
|
|
2015-09-07 15:12:31 +00:00
|
|
|
// Authentication request header of Socks5 protocol
|
|
|
|
type Socks5AuthenticationRequest struct {
|
2015-09-07 15:16:30 +00:00
|
|
|
version byte
|
2015-09-07 20:26:37 +00:00
|
|
|
nMethods byte
|
2015-09-07 15:16:30 +00:00
|
|
|
authMethods [256]byte
|
2015-09-07 15:12:31 +00:00
|
|
|
}
|
|
|
|
|
2015-09-09 10:13:52 +00:00
|
|
|
func (request *Socks5AuthenticationRequest) HasAuthMethod(method byte) bool {
|
2015-09-11 12:12:26 +00:00
|
|
|
for i := 0; i < int(request.nMethods); i++ {
|
2015-09-09 10:13:52 +00:00
|
|
|
if request.authMethods[i] == method {
|
|
|
|
return true
|
|
|
|
}
|
|
|
|
}
|
|
|
|
return false
|
|
|
|
}
|
|
|
|
|
2015-09-17 15:37:04 +00:00
|
|
|
func ReadAuthentication(reader io.Reader) (auth Socks5AuthenticationRequest, auth4 Socks4AuthenticationRequest, err error) {
|
2016-08-01 15:47:20 +00:00
|
|
|
buffer := make([]byte, 256)
|
2015-10-08 21:06:12 +00:00
|
|
|
|
2016-08-01 15:47:20 +00:00
|
|
|
nBytes, err := reader.Read(buffer)
|
2015-09-07 15:16:30 +00:00
|
|
|
if err != nil {
|
|
|
|
return
|
|
|
|
}
|
|
|
|
if nBytes < 2 {
|
2016-11-19 13:38:13 +00:00
|
|
|
err = errors.New("Socks: Insufficient header.")
|
2015-09-07 15:16:30 +00:00
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2016-08-01 15:47:20 +00:00
|
|
|
if buffer[0] == socks4Version {
|
|
|
|
auth4.Version = buffer[0]
|
|
|
|
auth4.Command = buffer[1]
|
|
|
|
auth4.Port = v2net.PortFromBytes(buffer[2:4])
|
|
|
|
copy(auth4.IP[:], buffer[4:8])
|
2015-10-13 11:55:06 +00:00
|
|
|
err = Socks4Downgrade
|
2015-09-17 15:37:04 +00:00
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2016-08-01 15:47:20 +00:00
|
|
|
auth.version = buffer[0]
|
2015-09-07 15:16:30 +00:00
|
|
|
if auth.version != socksVersion {
|
2016-01-18 11:24:33 +00:00
|
|
|
log.Warning("Socks: Unknown protocol version ", auth.version)
|
2016-06-27 06:53:35 +00:00
|
|
|
err = proxy.ErrInvalidProtocolVersion
|
2015-09-07 15:16:30 +00:00
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2016-08-01 15:47:20 +00:00
|
|
|
auth.nMethods = buffer[1]
|
2015-09-07 20:26:37 +00:00
|
|
|
if auth.nMethods <= 0 {
|
2016-01-18 11:24:33 +00:00
|
|
|
log.Warning("Socks: Zero length of authentication methods")
|
2016-06-27 06:53:35 +00:00
|
|
|
err = proxy.ErrInvalidAuthentication
|
2015-09-07 15:16:30 +00:00
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2015-09-15 22:06:22 +00:00
|
|
|
if nBytes-2 != int(auth.nMethods) {
|
2016-01-18 11:24:33 +00:00
|
|
|
log.Warning("Socks: Unmatching number of auth methods, expecting ", auth.nMethods, ", but got ", nBytes)
|
2016-06-27 06:53:35 +00:00
|
|
|
err = proxy.ErrInvalidAuthentication
|
2015-09-07 20:26:37 +00:00
|
|
|
return
|
|
|
|
}
|
2016-08-01 15:47:20 +00:00
|
|
|
copy(auth.authMethods[:], buffer[2:nBytes])
|
2015-09-07 15:16:30 +00:00
|
|
|
return
|
2015-09-07 15:12:31 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
type Socks5AuthenticationResponse struct {
|
2015-09-07 15:16:30 +00:00
|
|
|
version byte
|
|
|
|
authMethod byte
|
2015-09-07 15:12:31 +00:00
|
|
|
}
|
|
|
|
|
2015-09-09 10:13:52 +00:00
|
|
|
func NewAuthenticationResponse(authMethod byte) *Socks5AuthenticationResponse {
|
2015-09-16 14:27:36 +00:00
|
|
|
return &Socks5AuthenticationResponse{
|
|
|
|
version: socksVersion,
|
|
|
|
authMethod: authMethod,
|
|
|
|
}
|
2015-09-09 10:13:52 +00:00
|
|
|
}
|
|
|
|
|
2015-09-16 14:06:16 +00:00
|
|
|
func WriteAuthentication(writer io.Writer, r *Socks5AuthenticationResponse) error {
|
|
|
|
_, err := writer.Write([]byte{r.version, r.authMethod})
|
2015-09-08 11:18:55 +00:00
|
|
|
return err
|
2015-09-17 15:37:04 +00:00
|
|
|
}
|
|
|
|
|
2015-09-15 22:05:59 +00:00
|
|
|
type Socks5UserPassRequest struct {
|
2015-09-15 22:06:22 +00:00
|
|
|
version byte
|
|
|
|
username string
|
|
|
|
password string
|
2015-09-15 22:05:59 +00:00
|
|
|
}
|
|
|
|
|
2015-10-10 13:51:35 +00:00
|
|
|
func (request Socks5UserPassRequest) Username() string {
|
|
|
|
return request.username
|
|
|
|
}
|
|
|
|
|
|
|
|
func (request Socks5UserPassRequest) Password() string {
|
|
|
|
return request.password
|
2015-09-15 22:05:59 +00:00
|
|
|
}
|
|
|
|
|
2015-09-25 15:59:45 +00:00
|
|
|
func (request Socks5UserPassRequest) AuthDetail() string {
|
|
|
|
return request.username + ":" + request.password
|
|
|
|
}
|
|
|
|
|
2015-09-15 22:05:59 +00:00
|
|
|
func ReadUserPassRequest(reader io.Reader) (request Socks5UserPassRequest, err error) {
|
2016-11-01 11:37:35 +00:00
|
|
|
buffer := alloc.NewLocalBuffer(512)
|
2015-10-08 21:06:12 +00:00
|
|
|
defer buffer.Release()
|
|
|
|
|
2016-12-06 10:03:42 +00:00
|
|
|
_, err = buffer.FillFullFrom(reader, 2)
|
2015-09-15 22:06:22 +00:00
|
|
|
if err != nil {
|
|
|
|
return
|
|
|
|
}
|
2016-12-06 10:03:42 +00:00
|
|
|
request.version = buffer.Byte(0)
|
|
|
|
nUsername := int(buffer.Byte(1))
|
|
|
|
|
|
|
|
buffer.Clear()
|
|
|
|
_, err = buffer.FillFullFrom(reader, nUsername)
|
2015-09-15 22:06:22 +00:00
|
|
|
if err != nil {
|
|
|
|
return
|
|
|
|
}
|
2016-12-06 10:03:42 +00:00
|
|
|
request.username = string(buffer.Bytes())
|
2015-09-15 22:06:22 +00:00
|
|
|
|
2016-12-06 10:03:42 +00:00
|
|
|
_, err = buffer.FillFullFrom(reader, 1)
|
2015-09-15 22:06:22 +00:00
|
|
|
if err != nil {
|
|
|
|
return
|
|
|
|
}
|
2016-12-06 10:03:42 +00:00
|
|
|
nPassword := int(buffer.Byte(0))
|
|
|
|
_, err = buffer.FillFullFrom(reader, nPassword)
|
2015-09-15 22:06:22 +00:00
|
|
|
if err != nil {
|
|
|
|
return
|
|
|
|
}
|
2016-12-06 10:03:42 +00:00
|
|
|
request.password = string(buffer.Bytes())
|
2015-09-15 22:06:22 +00:00
|
|
|
return
|
2015-09-15 22:05:59 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
type Socks5UserPassResponse struct {
|
2015-09-15 22:06:22 +00:00
|
|
|
version byte
|
|
|
|
status byte
|
2015-09-15 22:05:59 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
func NewSocks5UserPassResponse(status byte) Socks5UserPassResponse {
|
2015-09-16 15:07:05 +00:00
|
|
|
return Socks5UserPassResponse{
|
|
|
|
version: socksVersion,
|
|
|
|
status: status,
|
|
|
|
}
|
2015-09-15 22:05:59 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
func WriteUserPassResponse(writer io.Writer, response Socks5UserPassResponse) error {
|
2015-09-15 22:06:22 +00:00
|
|
|
_, err := writer.Write([]byte{response.version, response.status})
|
|
|
|
return err
|
2015-09-15 22:05:59 +00:00
|
|
|
}
|
|
|
|
|
2015-09-08 11:18:55 +00:00
|
|
|
const (
|
|
|
|
AddrTypeIPv4 = byte(0x01)
|
|
|
|
AddrTypeIPv6 = byte(0x04)
|
|
|
|
AddrTypeDomain = byte(0x03)
|
2015-09-09 10:13:52 +00:00
|
|
|
|
|
|
|
CmdConnect = byte(0x01)
|
|
|
|
CmdBind = byte(0x02)
|
|
|
|
CmdUdpAssociate = byte(0x03)
|
2015-09-08 11:18:55 +00:00
|
|
|
)
|
|
|
|
|
2015-09-07 20:26:37 +00:00
|
|
|
type Socks5Request struct {
|
2015-09-09 10:13:52 +00:00
|
|
|
Version byte
|
|
|
|
Command byte
|
|
|
|
AddrType byte
|
|
|
|
IPv4 [4]byte
|
|
|
|
Domain string
|
|
|
|
IPv6 [16]byte
|
2015-12-02 20:44:01 +00:00
|
|
|
Port v2net.Port
|
2015-09-07 20:26:37 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
func ReadRequest(reader io.Reader) (request *Socks5Request, err error) {
|
2016-12-06 10:03:42 +00:00
|
|
|
buffer := alloc.NewLocalBuffer(512)
|
2015-10-08 21:06:12 +00:00
|
|
|
defer buffer.Release()
|
|
|
|
|
2016-12-05 16:05:47 +00:00
|
|
|
_, err = buffer.FillFullFrom(reader, 4)
|
2015-09-07 20:26:37 +00:00
|
|
|
if err != nil {
|
|
|
|
return
|
|
|
|
}
|
2016-02-05 10:21:13 +00:00
|
|
|
|
2015-09-16 14:27:36 +00:00
|
|
|
request = &Socks5Request{
|
2016-12-06 10:03:42 +00:00
|
|
|
Version: buffer.Byte(0),
|
|
|
|
Command: buffer.Byte(1),
|
2015-09-16 14:27:36 +00:00
|
|
|
// buffer[2] is a reserved field
|
2016-12-06 10:03:42 +00:00
|
|
|
AddrType: buffer.Byte(3),
|
2015-09-16 14:27:36 +00:00
|
|
|
}
|
2015-09-09 10:13:52 +00:00
|
|
|
switch request.AddrType {
|
2015-09-10 22:24:18 +00:00
|
|
|
case AddrTypeIPv4:
|
2016-02-05 10:21:13 +00:00
|
|
|
_, err = io.ReadFull(reader, request.IPv4[:])
|
2015-09-07 20:26:37 +00:00
|
|
|
if err != nil {
|
|
|
|
return
|
|
|
|
}
|
2015-09-10 22:24:18 +00:00
|
|
|
case AddrTypeDomain:
|
2016-12-05 16:05:47 +00:00
|
|
|
buffer.Clear()
|
|
|
|
_, err = buffer.FillFullFrom(reader, 1)
|
2015-09-11 12:12:26 +00:00
|
|
|
if err != nil {
|
|
|
|
return
|
|
|
|
}
|
2016-12-05 16:05:47 +00:00
|
|
|
domainLength := int(buffer.Byte(0))
|
|
|
|
_, err = buffer.FillFullFrom(reader, domainLength)
|
2015-09-07 20:26:37 +00:00
|
|
|
if err != nil {
|
|
|
|
return
|
|
|
|
}
|
2015-09-11 12:12:26 +00:00
|
|
|
|
2016-12-05 16:05:47 +00:00
|
|
|
request.Domain = string(buffer.BytesFrom(-domainLength))
|
2015-09-10 22:24:18 +00:00
|
|
|
case AddrTypeIPv6:
|
2016-02-05 10:21:13 +00:00
|
|
|
_, err = io.ReadFull(reader, request.IPv6[:])
|
2015-09-07 20:26:37 +00:00
|
|
|
if err != nil {
|
|
|
|
return
|
|
|
|
}
|
|
|
|
default:
|
2016-11-19 13:38:13 +00:00
|
|
|
err = fmt.Errorf("Socks: Unexpected address type %d", request.AddrType)
|
2015-09-07 20:26:37 +00:00
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2016-12-05 16:05:47 +00:00
|
|
|
_, err = buffer.FillFullFrom(reader, 2)
|
2015-09-07 20:26:37 +00:00
|
|
|
if err != nil {
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2016-12-05 16:05:47 +00:00
|
|
|
request.Port = v2net.PortFromBytes(buffer.BytesFrom(-2))
|
2015-09-07 20:26:37 +00:00
|
|
|
return
|
|
|
|
}
|
2015-09-08 11:18:55 +00:00
|
|
|
|
2015-09-20 16:22:29 +00:00
|
|
|
func (request *Socks5Request) Destination() v2net.Destination {
|
2015-09-10 22:24:18 +00:00
|
|
|
switch request.AddrType {
|
|
|
|
case AddrTypeIPv4:
|
2015-12-16 22:53:38 +00:00
|
|
|
return v2net.TCPDestination(v2net.IPAddress(request.IPv4[:]), request.Port)
|
2015-09-10 22:24:18 +00:00
|
|
|
case AddrTypeIPv6:
|
2015-12-16 22:53:38 +00:00
|
|
|
return v2net.TCPDestination(v2net.IPAddress(request.IPv6[:]), request.Port)
|
2015-09-10 22:24:18 +00:00
|
|
|
case AddrTypeDomain:
|
2016-02-05 10:21:13 +00:00
|
|
|
return v2net.TCPDestination(v2net.ParseAddress(request.Domain), request.Port)
|
2015-09-10 22:24:18 +00:00
|
|
|
default:
|
|
|
|
panic("Unknown address type")
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2015-09-08 11:18:55 +00:00
|
|
|
const (
|
|
|
|
ErrorSuccess = byte(0x00)
|
|
|
|
ErrorGeneralFailure = byte(0x01)
|
|
|
|
ErrorConnectionNotAllowed = byte(0x02)
|
|
|
|
ErrorNetworkUnreachable = byte(0x03)
|
|
|
|
ErrorHostUnUnreachable = byte(0x04)
|
|
|
|
ErrorConnectionRefused = byte(0x05)
|
|
|
|
ErrorTTLExpired = byte(0x06)
|
|
|
|
ErrorCommandNotSupported = byte(0x07)
|
|
|
|
ErrorAddressTypeNotSupported = byte(0x08)
|
|
|
|
)
|
|
|
|
|
|
|
|
type Socks5Response struct {
|
|
|
|
Version byte
|
|
|
|
Error byte
|
|
|
|
AddrType byte
|
|
|
|
IPv4 [4]byte
|
|
|
|
Domain string
|
|
|
|
IPv6 [16]byte
|
2015-12-02 20:44:01 +00:00
|
|
|
Port v2net.Port
|
2015-09-08 11:18:55 +00:00
|
|
|
}
|
|
|
|
|
2015-09-09 10:13:52 +00:00
|
|
|
func NewSocks5Response() *Socks5Response {
|
2015-09-16 14:27:36 +00:00
|
|
|
return &Socks5Response{
|
|
|
|
Version: socksVersion,
|
|
|
|
}
|
2015-09-09 10:13:52 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
func (r *Socks5Response) SetIPv4(ipv4 []byte) {
|
|
|
|
r.AddrType = AddrTypeIPv4
|
|
|
|
copy(r.IPv4[:], ipv4)
|
|
|
|
}
|
|
|
|
|
|
|
|
func (r *Socks5Response) SetIPv6(ipv6 []byte) {
|
|
|
|
r.AddrType = AddrTypeIPv6
|
|
|
|
copy(r.IPv6[:], ipv6)
|
|
|
|
}
|
|
|
|
|
|
|
|
func (r *Socks5Response) SetDomain(domain string) {
|
|
|
|
r.AddrType = AddrTypeDomain
|
|
|
|
r.Domain = domain
|
|
|
|
}
|
|
|
|
|
2016-02-27 10:02:42 +00:00
|
|
|
func (r *Socks5Response) Write(writer io.Writer) {
|
|
|
|
writer.Write([]byte{r.Version, r.Error, 0x00 /* reserved */, r.AddrType})
|
2015-09-08 11:18:55 +00:00
|
|
|
switch r.AddrType {
|
|
|
|
case 0x01:
|
2016-02-27 10:02:42 +00:00
|
|
|
writer.Write(r.IPv4[:])
|
2015-09-08 11:18:55 +00:00
|
|
|
case 0x03:
|
2016-02-27 10:02:42 +00:00
|
|
|
writer.Write([]byte{byte(len(r.Domain))})
|
|
|
|
writer.Write([]byte(r.Domain))
|
2015-09-08 11:18:55 +00:00
|
|
|
case 0x04:
|
2016-02-27 10:02:42 +00:00
|
|
|
writer.Write(r.IPv6[:])
|
2015-09-08 11:18:55 +00:00
|
|
|
}
|
2016-06-26 20:34:48 +00:00
|
|
|
writer.Write(r.Port.Bytes(nil))
|
2015-09-08 11:18:55 +00:00
|
|
|
}
|