
623 lines
19 KiB
Raw Normal View History

2018-01-29 23:47:04 +01:00
package main
import (
crypto_rand "crypto/rand"
2019-10-14 01:45:38 +02:00
2018-01-29 23:47:04 +01:00
2018-07-05 18:05:24 +02:00
2018-01-29 23:47:04 +01:00
clocksmith "github.com/jedisct1/go-clocksmith"
stamps "github.com/jedisct1/go-dnsstamps"
2018-01-29 23:47:04 +01:00
type Proxy struct {
userName string
child bool
proxyPublicKey [32]byte
proxySecretKey [32]byte
ephemeralKeys bool
questionSizeEstimator QuestionSizeEstimator
serversInfo ServersInfo
timeout time.Duration
certRefreshDelay time.Duration
certRefreshDelayAfterFailure time.Duration
certIgnoreTimestamp bool
mainProto string
listenAddresses []string
localDoHListenAddresses []string
localDoHPath string
localDoHCertFile string
localDoHCertKeyFile string
daemonize bool
registeredServers []RegisteredServer
registeredRelays []RegisteredServer
pluginBlockIPv6 bool
pluginBlockUnqualified bool
pluginBlockUndelegated bool
cache bool
cacheSize int
cacheNegMinTTL uint32
cacheNegMaxTTL uint32
cacheMinTTL uint32
cacheMaxTTL uint32
rejectTTL uint32
cloakTTL uint32
queryLogFile string
queryLogFormat string
queryLogIgnoredQtypes []string
nxLogFile string
nxLogFormat string
blockNameFile string
whitelistNameFile string
blockNameLogFile string
whitelistNameLogFile string
blockNameFormat string
whitelistNameFormat string
blockIPFile string
blockIPLogFile string
blockIPFormat string
forwardFile string
cloakFile string
pluginsGlobals PluginsGlobals
sources []*Source
clientsCount uint32
maxClients uint32
xTransport *XTransport
allWeeklyRanges *map[string]WeeklyRanges
logMaxSize int
logMaxAge int
logMaxBackups int
blockedQueryResponse string
queryMeta []string
routes *map[string][]string
serversBlockingFragments []string
showCerts bool
dohCreds *map[string]DOHClientCreds
skipAnonIncompatbibleResolvers bool
2018-01-29 23:47:04 +01:00
func (proxy *Proxy) addDNSListener(listenAddrStr string) {
listenUDPAddr, err := net.ResolveUDPAddr("udp", listenAddrStr)
if err != nil {
2018-01-29 23:47:04 +01:00
listenTCPAddr, err := net.ResolveTCPAddr("tcp", listenAddrStr)
if err != nil {
2018-01-29 23:47:04 +01:00
// if 'userName' is not set, continue as before
if len(proxy.userName) <= 0 {
if err := proxy.udpListenerFromAddr(listenUDPAddr); err != nil {
if err := proxy.tcpListenerFromAddr(listenTCPAddr); err != nil {
// if 'userName' is set and we are the parent process
if !proxy.child {
// parent
listenerUDP, err := net.ListenUDP("udp", listenUDPAddr)
2018-01-29 23:47:04 +01:00
if err != nil {
listenerTCP, err := net.ListenTCP("tcp", listenTCPAddr)
2018-01-29 23:47:04 +01:00
if err != nil {
fdUDP, err := listenerUDP.File() // On Windows, the File method of UDPConn is not implemented.
if err != nil {
dlog.Fatalf("Unable to switch to a different user: %v", err)
fdTCP, err := listenerTCP.File() // On Windows, the File method of TCPListener is not implemented.
if err != nil {
dlog.Fatalf("Unable to switch to a different user: %v", err)
defer listenerUDP.Close()
defer listenerTCP.Close()
FileDescriptors = append(FileDescriptors, fdUDP)
FileDescriptors = append(FileDescriptors, fdTCP)
// child
listenerUDP, err := net.FilePacketConn(os.NewFile(uintptr(3+FileDescriptorNum), "listenerUDP"))
if err != nil {
dlog.Fatalf("Unable to switch to a different user: %v", err)
listenerTCP, err := net.FileListener(os.NewFile(uintptr(3+FileDescriptorNum), "listenerTCP"))
if err != nil {
dlog.Fatalf("Unable to switch to a different user: %v", err)
dlog.Noticef("Now listening to %v [UDP]", listenUDPAddr)
go proxy.udpListener(listenerUDP.(*net.UDPConn))
dlog.Noticef("Now listening to %v [TCP]", listenAddrStr)
go proxy.tcpListener(listenerTCP.(*net.TCPListener))
func (proxy *Proxy) addLocalDoHListener(listenAddrStr string) {
listenTCPAddr, err := net.ResolveTCPAddr("tcp", listenAddrStr)
if err != nil {
// if 'userName' is not set, continue as before
if len(proxy.userName) <= 0 {
if err := proxy.localDoHListenerFromAddr(listenTCPAddr); err != nil {
// if 'userName' is set and we are the parent process
if !proxy.child {
// parent
listenerTCP, err := net.ListenTCP("tcp", listenTCPAddr)
if err != nil {
fdTCP, err := listenerTCP.File() // On Windows, the File method of TCPListener is not implemented.
if err != nil {
dlog.Fatalf("Unable to switch to a different user: %v", err)
defer listenerTCP.Close()
FileDescriptors = append(FileDescriptors, fdTCP)
// child
listenerTCP, err := net.FileListener(os.NewFile(uintptr(3+FileDescriptorNum), "listenerTCP"))
if err != nil {
dlog.Fatalf("Unable to switch to a different user: %v", err)
dlog.Noticef("Now listening to https://%v%v [DoH]", listenAddrStr, proxy.localDoHPath)
go proxy.localDoHListener(listenerTCP.(*net.TCPListener))
func (proxy *Proxy) StartProxy() {
proxy.questionSizeEstimator = NewQuestionSizeEstimator()
if _, err := crypto_rand.Read(proxy.proxySecretKey[:]); err != nil {
curve25519.ScalarBaseMult(&proxy.proxyPublicKey, &proxy.proxySecretKey)
for _, registeredServer := range proxy.registeredServers {
proxy.serversInfo.registerServer(registeredServer.name, registeredServer.stamp)
2018-01-29 23:47:04 +01:00
liveServers, err := proxy.serversInfo.refresh(proxy)
if liveServers > 0 {
proxy.certIgnoreTimestamp = false
if proxy.showCerts {
2018-01-29 23:47:04 +01:00
if liveServers > 0 {
dlog.Noticef("dnscrypt-proxy is ready - live servers: %d", liveServers)
if !proxy.child {
if err := ServiceManagerReadyNotify(); err != nil {
2018-01-29 23:47:04 +01:00
} else if err != nil {
dlog.Notice("dnscrypt-proxy is waiting for at least one server to be reachable")
go func() {
for {
clocksmith.Sleep(PrefetchSources(proxy.xTransport, proxy.sources))
2018-07-05 18:05:24 +02:00
if len(proxy.serversInfo.registeredServers) > 0 {
go func() {
for {
delay := proxy.certRefreshDelay
if liveServers == 0 {
delay = proxy.certRefreshDelayAfterFailure
liveServers, _ = proxy.serversInfo.refresh(proxy)
if liveServers > 0 {
proxy.certIgnoreTimestamp = false
2018-07-05 18:05:24 +02:00
2018-01-29 23:47:04 +01:00
func (proxy *Proxy) udpListener(clientPc *net.UDPConn) {
defer clientPc.Close()
2018-01-29 23:47:04 +01:00
for {
buffer := make([]byte, MaxDNSPacketSize-1)
length, clientAddr, err := clientPc.ReadFrom(buffer)
if err != nil {
packet := buffer[:length]
go func() {
start := time.Now()
2018-01-29 23:47:04 +01:00
if !proxy.clientsCountInc() {
dlog.Warnf("Too many incoming connections (max=%d)", proxy.maxClients)
2018-01-29 23:47:04 +01:00
defer proxy.clientsCountDec()
proxy.processIncomingQuery("udp", proxy.mainProto, packet, &clientAddr, clientPc, start)
2018-01-29 23:47:04 +01:00
func (proxy *Proxy) udpListenerFromAddr(listenAddr *net.UDPAddr) error {
2018-01-29 23:47:04 +01:00
clientPc, err := net.ListenUDP("udp", listenAddr)
if err != nil {
return err
2018-01-29 23:47:04 +01:00
dlog.Noticef("Now listening to %v [UDP]", listenAddr)
go proxy.udpListener(clientPc)
return nil
2018-01-29 23:47:04 +01:00
func (proxy *Proxy) tcpListener(acceptPc *net.TCPListener) {
defer acceptPc.Close()
2018-01-29 23:47:04 +01:00
for {
clientPc, err := acceptPc.Accept()
if err != nil {
go func() {
start := time.Now()
2018-01-29 23:47:04 +01:00
defer clientPc.Close()
if !proxy.clientsCountInc() {
dlog.Warnf("Too many incoming connections (max=%d)", proxy.maxClients)
2018-01-29 23:47:04 +01:00
defer proxy.clientsCountDec()
2020-03-13 18:44:30 +01:00
if err := clientPc.SetDeadline(time.Now().Add(proxy.timeout)); err != nil {
2019-12-09 12:11:24 +01:00
2018-06-06 15:54:51 +02:00
packet, err := ReadPrefixed(&clientPc)
if err != nil {
2018-01-29 23:47:04 +01:00
clientAddr := clientPc.RemoteAddr()
proxy.processIncomingQuery("tcp", "tcp", packet, &clientAddr, clientPc, start)
2018-01-29 23:47:04 +01:00
func (proxy *Proxy) tcpListenerFromAddr(listenAddr *net.TCPAddr) error {
2018-01-29 23:47:04 +01:00
acceptPc, err := net.ListenTCP("tcp", listenAddr)
if err != nil {
return err
2018-01-29 23:47:04 +01:00
dlog.Noticef("Now listening to %v [TCP]", listenAddr)
go proxy.tcpListener(acceptPc)
return nil
2018-01-29 23:47:04 +01:00
func (proxy *Proxy) localDoHListenerFromAddr(listenAddr *net.TCPAddr) error {
acceptPc, err := net.ListenTCP("tcp", listenAddr)
if err != nil {
return err
dlog.Noticef("Now listening to https://%v%v [DoH]", listenAddr, proxy.localDoHPath)
go proxy.localDoHListener(acceptPc)
return nil
2019-10-14 01:45:38 +02:00
func (proxy *Proxy) prepareForRelay(ip net.IP, port int, encryptedQuery *[]byte) {
anonymizedDNSHeader := []byte{0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0x00, 0x00}
relayedQuery := append(anonymizedDNSHeader, ip.To16()...)
var tmp [2]byte
binary.BigEndian.PutUint16(tmp[0:2], uint16(port))
relayedQuery = append(relayedQuery, tmp[:]...)
relayedQuery = append(relayedQuery, *encryptedQuery...)
*encryptedQuery = relayedQuery
func (proxy *Proxy) exchangeWithUDPServer(serverInfo *ServerInfo, sharedKey *[32]byte, encryptedQuery []byte, clientNonce []byte) ([]byte, error) {
2019-10-14 01:45:38 +02:00
upstreamAddr := serverInfo.UDPAddr
if serverInfo.RelayUDPAddr != nil {
upstreamAddr = serverInfo.RelayUDPAddr
var err error
var pc net.Conn
proxyDialer := proxy.xTransport.proxyDialer
if proxyDialer == nil {
pc, err = net.DialUDP("udp", nil, upstreamAddr)
} else {
pc, err = (*proxyDialer).Dial("udp", upstreamAddr.String())
2018-01-29 23:47:04 +01:00
if err != nil {
return nil, err
defer pc.Close()
2020-03-13 18:44:30 +01:00
if err := pc.SetDeadline(time.Now().Add(serverInfo.Timeout)); err != nil {
2019-12-09 12:11:24 +01:00
return nil, err
2019-10-14 01:45:38 +02:00
if serverInfo.RelayUDPAddr != nil {
proxy.prepareForRelay(serverInfo.UDPAddr.IP, serverInfo.UDPAddr.Port, &encryptedQuery)
2018-01-29 23:47:04 +01:00
encryptedResponse := make([]byte, MaxDNSPacketSize)
2020-01-29 18:14:03 +01:00
for tries := 2; tries > 0; tries-- {
2020-03-13 18:44:30 +01:00
if _, err := pc.Write(encryptedQuery); err != nil {
2020-01-29 18:14:03 +01:00
return nil, err
length, err := pc.Read(encryptedResponse)
if err == nil {
encryptedResponse = encryptedResponse[:length]
2020-03-26 13:30:39 +01:00
dlog.Debugf("[%v] Retry on timeout", serverInfo.Name)
2018-01-29 23:47:04 +01:00
return proxy.Decrypt(serverInfo, sharedKey, encryptedResponse, clientNonce)
2018-01-29 23:47:04 +01:00
func (proxy *Proxy) exchangeWithTCPServer(serverInfo *ServerInfo, sharedKey *[32]byte, encryptedQuery []byte, clientNonce []byte) ([]byte, error) {
2019-10-14 01:45:38 +02:00
upstreamAddr := serverInfo.TCPAddr
if serverInfo.RelayUDPAddr != nil {
upstreamAddr = serverInfo.RelayTCPAddr
var err error
var pc net.Conn
2018-06-06 15:54:51 +02:00
proxyDialer := proxy.xTransport.proxyDialer
if proxyDialer == nil {
2019-10-14 01:45:38 +02:00
pc, err = net.DialTCP("tcp", nil, upstreamAddr)
2018-06-06 15:54:51 +02:00
} else {
pc, err = (*proxyDialer).Dial("tcp", upstreamAddr.String())
2018-01-29 23:47:04 +01:00
if err != nil {
return nil, err
defer pc.Close()
2020-03-13 18:44:30 +01:00
if err := pc.SetDeadline(time.Now().Add(serverInfo.Timeout)); err != nil {
2019-12-09 12:11:24 +01:00
return nil, err
2019-10-14 01:45:38 +02:00
if serverInfo.RelayTCPAddr != nil {
proxy.prepareForRelay(serverInfo.TCPAddr.IP, serverInfo.TCPAddr.Port, &encryptedQuery)
encryptedQuery, err = PrefixWithSize(encryptedQuery)
2018-01-29 23:47:04 +01:00
if err != nil {
return nil, err
2020-03-13 18:44:30 +01:00
if _, err := pc.Write(encryptedQuery); err != nil {
2019-12-09 12:11:24 +01:00
return nil, err
encryptedResponse, err := ReadPrefixed(&pc)
2018-07-09 15:49:36 +02:00
if err != nil {
return nil, err
return proxy.Decrypt(serverInfo, sharedKey, encryptedResponse, clientNonce)
2018-01-29 23:47:04 +01:00
func (proxy *Proxy) clientsCountInc() bool {
for {
count := atomic.LoadUint32(&proxy.clientsCount)
2018-01-29 23:47:04 +01:00
if count >= proxy.maxClients {
return false
if atomic.CompareAndSwapUint32(&proxy.clientsCount, count, count+1) {
dlog.Debugf("clients count: %d", count+1)
2018-01-29 23:47:04 +01:00
return true
func (proxy *Proxy) clientsCountDec() {
for {
if count := atomic.LoadUint32(&proxy.clientsCount); count == 0 || atomic.CompareAndSwapUint32(&proxy.clientsCount, count, count-1) {
2018-01-29 23:47:04 +01:00
func (proxy *Proxy) processIncomingQuery(clientProto string, serverProto string, query []byte, clientAddr *net.Addr, clientPc net.Conn, start time.Time) (response []byte) {
2018-07-05 18:05:24 +02:00
if len(query) < MinDNSPacketSize {
2018-01-29 23:47:04 +01:00
pluginsState := NewPluginsState(proxy, clientProto, clientAddr, serverProto, start)
serverName := "-"
2019-12-23 11:37:45 +01:00
needsEDNS0Padding := false
serverInfo := proxy.serversInfo.getOne()
if serverInfo != nil {
serverName = serverInfo.Name
2019-12-23 11:37:45 +01:00
needsEDNS0Padding = (serverInfo.Proto == stamps.StampProtoTypeDoH || serverInfo.Proto == stamps.StampProtoTypeTLS)
query, _ = pluginsState.ApplyQueryPlugins(&proxy.pluginsGlobals, query, needsEDNS0Padding)
if len(query) < MinDNSPacketSize || len(query) > MaxDNSPacketSize {
if pluginsState.action == PluginsActionDrop {
pluginsState.returnCode = PluginsReturnCodeDrop
2018-01-29 23:47:04 +01:00
var err error
if pluginsState.synthResponse != nil {
response, err = pluginsState.synthResponse.PackBuffer(response)
if err != nil {
pluginsState.returnCode = PluginsReturnCodeParseError
2018-01-29 23:47:04 +01:00
2018-07-05 18:05:24 +02:00
if len(response) == 0 && serverInfo != nil {
var ttl *uint32
pluginsState.serverName = serverName
2018-04-14 15:03:21 +02:00
if serverInfo.Proto == stamps.StampProtoTypeDNSCrypt {
sharedKey, encryptedQuery, clientNonce, err := proxy.Encrypt(serverInfo, query, serverProto)
if err != nil && serverProto == "udp" {
dlog.Debug("Unable to pad for UDP, re-encrypting query for TCP")
serverProto = "tcp"
sharedKey, encryptedQuery, clientNonce, err = proxy.Encrypt(serverInfo, query, serverProto)
if err != nil {
2018-06-04 23:18:28 +02:00
pluginsState.returnCode = PluginsReturnCodeParseError
if serverProto == "udp" {
response, err = proxy.exchangeWithUDPServer(serverInfo, sharedKey, encryptedQuery, clientNonce)
2020-03-25 17:45:59 +01:00
retryOverTCP := false
if err == nil && len(response) >= MinDNSPacketSize && response[2]&0x02 == 0x02 {
2020-03-25 17:45:59 +01:00
retryOverTCP = true
} else if neterr, ok := err.(net.Error); ok && neterr.Timeout() {
2020-03-26 13:30:39 +01:00
dlog.Debugf("[%v] Retry over TCP after UDP timeouts", serverName)
2020-03-25 17:45:59 +01:00
retryOverTCP = true
if retryOverTCP {
2019-10-20 02:04:32 +02:00
serverProto = "tcp"
sharedKey, encryptedQuery, clientNonce, err = proxy.Encrypt(serverInfo, query, serverProto)
2019-10-20 02:04:32 +02:00
if err != nil {
pluginsState.returnCode = PluginsReturnCodeParseError
2019-10-20 23:07:36 +02:00
2019-10-20 02:04:32 +02:00
response, err = proxy.exchangeWithTCPServer(serverInfo, sharedKey, encryptedQuery, clientNonce)
} else {
response, err = proxy.exchangeWithTCPServer(serverInfo, sharedKey, encryptedQuery, clientNonce)
2020-01-30 13:15:29 +01:00
if err != nil {
if stale, ok := pluginsState.sessionData["stale"]; ok {
dlog.Debug("Serving stale response")
response, err = (stale.(*dns.Msg)).Pack()
if err != nil {
if neterr, ok := err.(net.Error); ok && neterr.Timeout() {
pluginsState.returnCode = PluginsReturnCodeServerTimeout
} else {
2019-11-17 19:48:15 +01:00
pluginsState.returnCode = PluginsReturnCodeNetworkError
2018-04-14 15:03:21 +02:00
} else if serverInfo.Proto == stamps.StampProtoTypeDoH {
tid := TransactionID(query)
SetTransactionID(query, 0)
serverResponse, tls, _, err := proxy.xTransport.DoHQuery(serverInfo.useGet, serverInfo.URL, query, proxy.timeout)
SetTransactionID(query, tid)
if err == nil || tls == nil || !tls.HandshakeComplete {
2020-01-30 13:15:29 +01:00
response = nil
} else if stale, ok := pluginsState.sessionData["stale"]; ok {
dlog.Debug("Serving stale response")
response, err = (stale.(*dns.Msg)).Pack()
if err != nil {
2019-11-17 19:48:15 +01:00
pluginsState.returnCode = PluginsReturnCodeNetworkError
2018-01-29 23:47:04 +01:00
2020-01-30 13:15:29 +01:00
if response == nil {
response = serverResponse
2020-01-30 13:15:29 +01:00
if len(response) >= MinDNSPacketSize {
SetTransactionID(response, tid)
2018-01-29 23:47:04 +01:00
} else {
dlog.Fatal("Unsupported protocol")
if len(response) < MinDNSPacketSize || len(response) > MaxDNSPacketSize {
2018-06-04 23:18:28 +02:00
pluginsState.returnCode = PluginsReturnCodeParseError
response, err = pluginsState.ApplyResponsePlugins(&proxy.pluginsGlobals, response, ttl)
2018-01-29 23:47:04 +01:00
if err != nil {
2018-06-04 23:18:28 +02:00
pluginsState.returnCode = PluginsReturnCodeParseError
2018-01-29 23:47:04 +01:00
if pluginsState.action == PluginsActionDrop {
pluginsState.returnCode = PluginsReturnCodeDrop
if pluginsState.synthResponse != nil {
response, err = pluginsState.synthResponse.PackBuffer(response)
if err != nil {
pluginsState.returnCode = PluginsReturnCodeParseError
if rcode := Rcode(response); rcode == dns.RcodeServerFailure { // SERVFAIL
if pluginsState.dnssec {
dlog.Debug("A response had an invalid DNSSEC signature")
} else {
dlog.Infof("Server [%v] returned temporary error code SERVFAIL -- Invalid DNSSEC signature received or server may be experiencing connectivity issues", serverInfo.Name)
} else {
2018-01-29 23:47:04 +01:00
2018-07-05 18:05:24 +02:00
if len(response) < MinDNSPacketSize || len(response) > MaxDNSPacketSize {
pluginsState.returnCode = PluginsReturnCodeParseError
2018-07-05 18:05:24 +02:00
if serverInfo != nil {
2018-01-29 23:47:04 +01:00
if clientProto == "udp" {
if len(response) > pluginsState.maxUnencryptedUDPSafePayloadSize {
2018-01-29 23:47:04 +01:00
response, err = TruncatedResponse(response)
if err != nil {
2018-06-04 23:18:28 +02:00
pluginsState.returnCode = PluginsReturnCodeParseError
2018-01-29 23:47:04 +01:00
clientPc.(net.PacketConn).WriteTo(response, *clientAddr)
if HasTCFlag(response) {
} else {
proxy.questionSizeEstimator.adjust(ResponseOverhead + len(response))
2019-11-26 01:36:35 +01:00
} else if clientProto == "tcp" {
2018-01-29 23:47:04 +01:00
response, err = PrefixWithSize(response)
if err != nil {
2018-06-04 23:18:28 +02:00
pluginsState.returnCode = PluginsReturnCodeParseError
2018-07-05 18:05:24 +02:00
if serverInfo != nil {
2018-01-29 23:47:04 +01:00
2019-11-28 16:46:25 +01:00
if clientPc != nil {
2018-01-29 23:47:04 +01:00
2019-11-28 16:46:25 +01:00
2019-11-26 01:36:35 +01:00
return response
2018-01-29 23:47:04 +01:00
2019-10-09 17:59:46 +02:00
func NewProxy() *Proxy {
return &Proxy{
serversInfo: NewServersInfo(),