|
| 1 | +//go:build linux |
| 2 | + |
| 3 | +package tun |
| 4 | + |
| 5 | +import ( |
| 6 | + "net/netip" |
| 7 | + "os/exec" |
| 8 | + "strings" |
| 9 | + |
| 10 | + E "github.com/sagernet/sing/common/exceptions" |
| 11 | + F "github.com/sagernet/sing/common/format" |
| 12 | + |
| 13 | + "golang.org/x/sys/unix" |
| 14 | +) |
| 15 | + |
| 16 | +func (r *autoRedirect) iptablesPathForFamily(family int) string { |
| 17 | + if family == unix.AF_INET { |
| 18 | + return r.iptablesPath |
| 19 | + } else { |
| 20 | + return r.ip6tablesPath |
| 21 | + } |
| 22 | +} |
| 23 | + |
| 24 | +func (r *autoRedirect) setupIPTables(family int) error { |
| 25 | + tableNameOutput := r.tableName + "-output" |
| 26 | + tableNameForward := r.tableName + "-forward" |
| 27 | + tableNamePreRouteing := r.tableName + "-prerouting" |
| 28 | + iptablesPath := r.iptablesPathForFamily(family) |
| 29 | + redirectPort := r.redirectPort() |
| 30 | + // OUTPUT |
| 31 | + err := r.runShell(iptablesPath, "-t nat -N", tableNameOutput) |
| 32 | + if err != nil { |
| 33 | + return err |
| 34 | + } |
| 35 | + err = r.runShell(iptablesPath, "-t nat -A", tableNameOutput, |
| 36 | + "-p tcp -o", r.tunOptions.Name, |
| 37 | + "-j REDIRECT --to-ports", redirectPort) |
| 38 | + if err != nil { |
| 39 | + return err |
| 40 | + } |
| 41 | + err = r.runShell(iptablesPath, "-t nat -I OUTPUT -j", tableNameOutput) |
| 42 | + if err != nil { |
| 43 | + return err |
| 44 | + } |
| 45 | + if r.androidSu { |
| 46 | + return nil |
| 47 | + } |
| 48 | + // FORWARD |
| 49 | + err = r.runShell(iptablesPath, "-N", tableNameForward) |
| 50 | + if err != nil { |
| 51 | + return err |
| 52 | + } |
| 53 | + err = r.runShell(iptablesPath, "-A", tableNameForward, |
| 54 | + "-i", r.tunOptions.Name, "-j", "ACCEPT") |
| 55 | + if err != nil { |
| 56 | + return err |
| 57 | + } |
| 58 | + err = r.runShell(iptablesPath, "-A", tableNameForward, |
| 59 | + "-o", r.tunOptions.Name, "-j", "ACCEPT") |
| 60 | + if err != nil { |
| 61 | + return err |
| 62 | + } |
| 63 | + err = r.runShell(iptablesPath, "-I FORWARD -j", tableNameForward) |
| 64 | + if err != nil { |
| 65 | + return err |
| 66 | + } |
| 67 | + // PREROUTING |
| 68 | + err = r.runShell(iptablesPath, "-t nat -N", tableNamePreRouteing) |
| 69 | + if err != nil { |
| 70 | + return err |
| 71 | + } |
| 72 | + var ( |
| 73 | + routeAddress []netip.Prefix |
| 74 | + routeExcludeAddress []netip.Prefix |
| 75 | + ) |
| 76 | + if family == unix.AF_INET { |
| 77 | + routeAddress = r.tunOptions.Inet4RouteAddress |
| 78 | + routeExcludeAddress = r.tunOptions.Inet4RouteExcludeAddress |
| 79 | + } else { |
| 80 | + routeAddress = r.tunOptions.Inet6RouteAddress |
| 81 | + routeExcludeAddress = r.tunOptions.Inet6RouteExcludeAddress |
| 82 | + } |
| 83 | + if len(routeAddress) > 0 && (len(r.tunOptions.IncludeInterface) > 0 || len(r.tunOptions.IncludeUID) > 0) { |
| 84 | + return E.New("`*_route_address` is conflict with `include_interface` or `include_uid`") |
| 85 | + } |
| 86 | + err = r.runShell(iptablesPath, "-t nat -A", tableNamePreRouteing, |
| 87 | + "-i", r.tunOptions.Name, "-j RETURN") |
| 88 | + if err != nil { |
| 89 | + return err |
| 90 | + } |
| 91 | + for _, address := range routeExcludeAddress { |
| 92 | + err = r.runShell(iptablesPath, "-t nat -A", tableNamePreRouteing, |
| 93 | + "-d", address.String(), "-j RETURN") |
| 94 | + if err != nil { |
| 95 | + return err |
| 96 | + } |
| 97 | + } |
| 98 | + for _, name := range r.tunOptions.ExcludeInterface { |
| 99 | + err = r.runShell(iptablesPath, "-t nat -A", tableNamePreRouteing, |
| 100 | + "-i", name, "-j RETURN") |
| 101 | + if err != nil { |
| 102 | + return err |
| 103 | + } |
| 104 | + } |
| 105 | + for _, uid := range r.tunOptions.ExcludeUID { |
| 106 | + err = r.runShell(iptablesPath, "-t nat -A", tableNamePreRouteing, |
| 107 | + "-m owner --uid-owner", uid, "-j RETURN") |
| 108 | + if err != nil { |
| 109 | + return err |
| 110 | + } |
| 111 | + } |
| 112 | + var dnsServerAddress netip.Addr |
| 113 | + if family == unix.AF_INET { |
| 114 | + dnsServerAddress = r.tunOptions.Inet4Address[0].Addr().Next() |
| 115 | + } else { |
| 116 | + dnsServerAddress = r.tunOptions.Inet6Address[0].Addr().Next() |
| 117 | + } |
| 118 | + if len(routeAddress) > 0 { |
| 119 | + for _, address := range routeAddress { |
| 120 | + err = r.runShell(iptablesPath, "-t nat -A", tableNamePreRouteing, |
| 121 | + "-d", address.String(), "-p udp --dport 53 -j DNAT --to", dnsServerAddress) |
| 122 | + if err != nil { |
| 123 | + return err |
| 124 | + } |
| 125 | + } |
| 126 | + } else if len(r.tunOptions.IncludeInterface) > 0 || len(r.tunOptions.IncludeUID) > 0 { |
| 127 | + for _, name := range r.tunOptions.IncludeInterface { |
| 128 | + err = r.runShell(iptablesPath, "-t nat -A", tableNamePreRouteing, |
| 129 | + "-i", name, "-p udp --dport 53 -j DNAT --to", dnsServerAddress) |
| 130 | + if err != nil { |
| 131 | + return err |
| 132 | + } |
| 133 | + } |
| 134 | + for _, uidRange := range r.tunOptions.IncludeUID { |
| 135 | + for uid := uidRange.Start; uid <= uidRange.End; uid++ { |
| 136 | + err = r.runShell(iptablesPath, "-t nat -A", tableNamePreRouteing, |
| 137 | + "-m owner --uid-owner", uid, "-p udp --dport 53 -j DNAT --to", dnsServerAddress) |
| 138 | + if err != nil { |
| 139 | + return err |
| 140 | + } |
| 141 | + } |
| 142 | + } |
| 143 | + } else { |
| 144 | + err = r.runShell(iptablesPath, "-t nat -A", tableNamePreRouteing, |
| 145 | + "-p udp --dport 53 -j DNAT --to", dnsServerAddress) |
| 146 | + if err != nil { |
| 147 | + return err |
| 148 | + } |
| 149 | + } |
| 150 | + |
| 151 | + err = r.runShell(iptablesPath, "-t nat -A", tableNamePreRouteing, "-m addrtype --dst-type LOCAL -j RETURN") |
| 152 | + if err != nil { |
| 153 | + return err |
| 154 | + } |
| 155 | + |
| 156 | + if len(routeAddress) > 0 { |
| 157 | + for _, address := range routeAddress { |
| 158 | + err = r.runShell(iptablesPath, "-t nat -A", tableNamePreRouteing, |
| 159 | + "-d", address.String(), "-p tcp -j REDIRECT --to-ports", redirectPort) |
| 160 | + if err != nil { |
| 161 | + return err |
| 162 | + } |
| 163 | + } |
| 164 | + } else if len(r.tunOptions.IncludeInterface) > 0 || len(r.tunOptions.IncludeUID) > 0 { |
| 165 | + for _, name := range r.tunOptions.IncludeInterface { |
| 166 | + err = r.runShell(iptablesPath, "-t nat -A", tableNamePreRouteing, |
| 167 | + "-i", name, "-p tcp -j REDIRECT --to-ports", redirectPort) |
| 168 | + if err != nil { |
| 169 | + return err |
| 170 | + } |
| 171 | + } |
| 172 | + for _, uidRange := range r.tunOptions.IncludeUID { |
| 173 | + for uid := uidRange.Start; uid <= uidRange.End; uid++ { |
| 174 | + err = r.runShell(iptablesPath, "-t nat -A", tableNamePreRouteing, |
| 175 | + "-m owner --uid-owner", uid, "-p tcp -j REDIRECT --to-ports", redirectPort) |
| 176 | + if err != nil { |
| 177 | + return err |
| 178 | + } |
| 179 | + } |
| 180 | + } |
| 181 | + } else { |
| 182 | + err = r.runShell(iptablesPath, "-t nat -A", tableNamePreRouteing, |
| 183 | + "-p tcp -j REDIRECT --to-ports", redirectPort) |
| 184 | + if err != nil { |
| 185 | + return err |
| 186 | + } |
| 187 | + } |
| 188 | + err = r.runShell(iptablesPath, "-t nat -I PREROUTING -j", tableNamePreRouteing) |
| 189 | + if err != nil { |
| 190 | + return err |
| 191 | + } |
| 192 | + return nil |
| 193 | +} |
| 194 | + |
| 195 | +func (r *autoRedirect) cleanupIPTables(family int) { |
| 196 | + tableNameOutput := r.tableName + "-output" |
| 197 | + tableNameForward := r.tableName + "-forward" |
| 198 | + tableNamePreRouteing := r.tableName + "-prerouting" |
| 199 | + iptablesPath := r.iptablesPathForFamily(family) |
| 200 | + _ = r.runShell(iptablesPath, "-t nat -D OUTPUT -j", tableNameOutput) |
| 201 | + _ = r.runShell(iptablesPath, "-t nat -F", tableNameOutput) |
| 202 | + _ = r.runShell(iptablesPath, "-t nat -X", tableNameOutput) |
| 203 | + if !r.androidSu { |
| 204 | + _ = r.runShell(iptablesPath, "-D FORWARD -j", tableNameForward) |
| 205 | + _ = r.runShell(iptablesPath, "-F", tableNameForward) |
| 206 | + _ = r.runShell(iptablesPath, "-X", tableNameForward) |
| 207 | + _ = r.runShell(iptablesPath, "-t nat -D PREROUTING -j", tableNamePreRouteing) |
| 208 | + _ = r.runShell(iptablesPath, "-t nat -F", tableNamePreRouteing) |
| 209 | + _ = r.runShell(iptablesPath, "-t nat -X", tableNamePreRouteing) |
| 210 | + } |
| 211 | +} |
| 212 | + |
| 213 | +func (r *autoRedirect) runShell(commands ...any) error { |
| 214 | + commandStr := strings.Join(F.MapToString(commands), " ") |
| 215 | + var command *exec.Cmd |
| 216 | + if r.androidSu { |
| 217 | + command = exec.Command(r.suPath, "-c", commandStr) |
| 218 | + } else { |
| 219 | + commandArray := strings.Split(commandStr, " ") |
| 220 | + command = exec.Command(commandArray[0], commandArray[1:]...) |
| 221 | + } |
| 222 | + combinedOutput, err := command.CombinedOutput() |
| 223 | + if err != nil { |
| 224 | + return E.Extend(err, F.ToString(commandStr, ": ", string(combinedOutput))) |
| 225 | + } |
| 226 | + return nil |
| 227 | +} |
0 commit comments