server.go 3.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159
  1. package server
  2. import (
  3. "context"
  4. "fmt"
  5. "log"
  6. "net"
  7. "net/netip"
  8. "sync"
  9. "time"
  10. "github.com/SenseUnit/dtlspipe/util"
  11. "github.com/pion/dtls/v2"
  12. "github.com/pion/dtls/v2/pkg/protocol"
  13. "github.com/pion/dtls/v2/pkg/protocol/recordlayer"
  14. "github.com/pion/transport/v2/udp"
  15. )
  16. const (
  17. Backlog = 1024
  18. )
  19. type Server struct {
  20. listener net.Listener
  21. dtlsConfig *dtls.Config
  22. rAddr string
  23. psk func([]byte) ([]byte, error)
  24. timeout time.Duration
  25. idleTimeout time.Duration
  26. baseCtx context.Context
  27. cancelCtx func()
  28. staleMode util.StaleMode
  29. workerWG sync.WaitGroup
  30. timeLimitFunc func() time.Duration
  31. allowFunc func(net.Addr, net.Addr) bool
  32. }
  33. func New(cfg *Config) (*Server, error) {
  34. cfg = cfg.populateDefaults()
  35. baseCtx, cancelCtx := context.WithCancel(cfg.BaseContext)
  36. srv := &Server{
  37. rAddr: cfg.RemoteAddress,
  38. timeout: cfg.Timeout,
  39. psk: cfg.PSKCallback,
  40. idleTimeout: cfg.IdleTimeout,
  41. baseCtx: baseCtx,
  42. cancelCtx: cancelCtx,
  43. staleMode: cfg.StaleMode,
  44. timeLimitFunc: cfg.TimeLimitFunc,
  45. allowFunc: cfg.AllowFunc,
  46. }
  47. lAddrPort, err := netip.ParseAddrPort(cfg.BindAddress)
  48. if err != nil {
  49. cancelCtx()
  50. return nil, fmt.Errorf("can't parse bind address: %w", err)
  51. }
  52. srv.dtlsConfig = &dtls.Config{
  53. ExtendedMasterSecret: dtls.RequireExtendedMasterSecret,
  54. ConnectContextMaker: srv.contextMaker,
  55. PSK: srv.psk,
  56. MTU: cfg.MTU,
  57. InsecureSkipVerifyHello: cfg.SkipHelloVerify,
  58. CipherSuites: cfg.CipherSuites,
  59. EllipticCurves: cfg.EllipticCurves,
  60. }
  61. lc := udp.ListenConfig{
  62. AcceptFilter: func(packet []byte) bool {
  63. pkts, err := recordlayer.UnpackDatagram(packet)
  64. if err != nil || len(pkts) < 1 {
  65. return false
  66. }
  67. h := &recordlayer.Header{}
  68. if err := h.Unmarshal(pkts[0]); err != nil {
  69. return false
  70. }
  71. return h.ContentType == protocol.ContentTypeHandshake
  72. },
  73. Backlog: Backlog,
  74. }
  75. listener, err := lc.Listen("udp", net.UDPAddrFromAddrPort(lAddrPort))
  76. if err != nil {
  77. cancelCtx()
  78. return nil, fmt.Errorf("server listen failed: %w", err)
  79. }
  80. srv.listener = listener
  81. go srv.listen()
  82. return srv, nil
  83. }
  84. func (srv *Server) listen() {
  85. defer srv.Close()
  86. for srv.baseCtx.Err() == nil {
  87. conn, err := srv.listener.Accept()
  88. if err != nil {
  89. log.Printf("conn accept failed: %v", err)
  90. continue
  91. }
  92. if !srv.allowFunc(conn.LocalAddr(), conn.RemoteAddr()) {
  93. continue
  94. }
  95. srv.workerWG.Add(1)
  96. go func(conn net.Conn) {
  97. defer srv.workerWG.Done()
  98. defer conn.Close()
  99. conn, err := dtls.Server(conn, srv.dtlsConfig)
  100. if err != nil {
  101. log.Printf("DTLS accept error: %v", err)
  102. return
  103. }
  104. defer conn.Close()
  105. srv.serve(conn)
  106. }(conn)
  107. }
  108. }
  109. func (srv *Server) serve(conn net.Conn) {
  110. log.Printf("[+] conn %s <=> %s", conn.LocalAddr(), conn.RemoteAddr())
  111. defer log.Printf("[-] conn %s <=> %s", conn.LocalAddr(), conn.RemoteAddr())
  112. defer conn.Close()
  113. ctx := srv.baseCtx
  114. tl := srv.timeLimitFunc()
  115. if tl != 0 {
  116. newCtx, cancel := context.WithTimeout(ctx, tl)
  117. defer cancel()
  118. ctx = newCtx
  119. }
  120. dialCtx, cancel := context.WithTimeout(ctx, srv.timeout)
  121. defer cancel()
  122. remoteConn, err := (&net.Dialer{}).DialContext(dialCtx, "udp", srv.rAddr)
  123. if err != nil {
  124. log.Printf("remote dial failed: %v", err)
  125. return
  126. }
  127. defer remoteConn.Close()
  128. util.PairConn(ctx, conn, remoteConn, srv.idleTimeout, srv.staleMode)
  129. }
  130. func (srv *Server) contextMaker() (context.Context, func()) {
  131. return context.WithTimeout(srv.baseCtx, srv.timeout)
  132. }
  133. func (srv *Server) Close() error {
  134. srv.cancelCtx()
  135. err := srv.listener.Close()
  136. srv.workerWG.Wait()
  137. return err
  138. }