service.go 11.5 KB
Newer Older
1 2 3 4 5 6 7 8 9 10 11 12 13 14
// Copyright 2017 fatedier, fatedier@gmail.com
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
//     http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.

F
fatedier 已提交
15 16 17
package server

import (
F
fatedier 已提交
18
	"bytes"
F
fatedier 已提交
19 20 21 22 23
	"crypto/rand"
	"crypto/rsa"
	"crypto/tls"
	"crypto/x509"
	"encoding/pem"
F
fatedier 已提交
24
	"fmt"
F
fatedier 已提交
25
	"io/ioutil"
F
fatedier 已提交
26
	"math/big"
F
fatedier 已提交
27 28
	"net"
	"net/http"
F
fatedier 已提交
29 30 31
	"time"

	"github.com/fatedier/frp/assets"
F
fatedier 已提交
32
	"github.com/fatedier/frp/g"
F
fatedier 已提交
33
	"github.com/fatedier/frp/models/msg"
F
fatedier 已提交
34 35
	"github.com/fatedier/frp/models/nathole"
	"github.com/fatedier/frp/server/controller"
F
fatedier 已提交
36 37
	"github.com/fatedier/frp/server/group"
	"github.com/fatedier/frp/server/ports"
F
fatedier 已提交
38 39
	"github.com/fatedier/frp/server/proxy"
	"github.com/fatedier/frp/server/stats"
F
fatedier 已提交
40
	"github.com/fatedier/frp/utils/log"
41
	frpNet "github.com/fatedier/frp/utils/net"
F
fatedier 已提交
42 43 44
	"github.com/fatedier/frp/utils/util"
	"github.com/fatedier/frp/utils/version"
	"github.com/fatedier/frp/utils/vhost"
45

F
fatedier 已提交
46
	"github.com/fatedier/golib/net/mux"
F
fatedier 已提交
47
	fmux "github.com/hashicorp/yamux"
F
fatedier 已提交
48 49
)

F
fatedier 已提交
50 51 52 53
const (
	connReadTimeout time.Duration = 10 * time.Second
)

54 55
var ServerService *Service

56
// Server service
F
fatedier 已提交
57
type Service struct {
58
	// Dispatch connections to different handlers listen on same port
59 60
	muxer *mux.Mux

61
	// Accept connections from client
62
	listener frpNet.Listener
F
fatedier 已提交
63

64
	// Accept connections using kcp
F
fatedier 已提交
65 66
	kcpListener frpNet.Listener

F
FishFish 已提交
67 68 69
	// Accept connections using websocket
	websocketListener frpNet.Listener

F
fatedier 已提交
70 71 72
	// Accept frp tls connections
	tlsListener frpNet.Listener

F
fatedier 已提交
73 74 75 76 77 78
	// Manage all controllers
	ctlManager *ControlManager

	// Manage all proxies
	pxyManager *proxy.ProxyManager

F
fatedier 已提交
79
	// All resource managers and controllers
F
fatedier 已提交
80 81 82 83
	rc *controller.ResourceController

	// stats collector to store server and proxies stats info
	statsCollector stats.Collector
F
fatedier 已提交
84 85

	tlsConfig *tls.Config
F
fatedier 已提交
86 87 88
}

func NewService() (svr *Service, err error) {
F
fatedier 已提交
89
	cfg := &g.GlbServerCfg.ServerCommonConf
F
fatedier 已提交
90
	svr = &Service{
F
fatedier 已提交
91 92 93 94
		ctlManager: NewControlManager(),
		pxyManager: proxy.NewProxyManager(),
		rc: &controller.ResourceController{
			VisitorManager: controller.NewVisitorManager(),
F
fatedier 已提交
95 96 97
			TcpPortManager: ports.NewPortManager("tcp", cfg.ProxyBindAddr, cfg.AllowPorts),
			UdpPortManager: ports.NewPortManager("udp", cfg.ProxyBindAddr, cfg.AllowPorts),
		},
F
fatedier 已提交
98
		tlsConfig: generateTLSConfig(),
F
fatedier 已提交
99
	}
F
fatedier 已提交
100 101

	// Init group controller
F
fatedier 已提交
102
	svr.rc.TcpGroupCtl = group.NewTcpGroupCtl(svr.rc.TcpPortManager)
F
fatedier 已提交
103

F
fatedier 已提交
104
	// Init assets
F
fatedier 已提交
105
	err = assets.Load(cfg.AssetsDir)
F
fatedier 已提交
106 107 108 109 110
	if err != nil {
		err = fmt.Errorf("Load assets error: %v", err)
		return
	}

111 112 113 114 115 116 117 118 119 120 121 122 123
	var (
		httpMuxOn  bool
		httpsMuxOn bool
	)
	if cfg.BindAddr == cfg.ProxyBindAddr {
		if cfg.BindPort == cfg.VhostHttpPort {
			httpMuxOn = true
		}
		if cfg.BindPort == cfg.VhostHttpsPort {
			httpsMuxOn = true
		}
	}

F
fatedier 已提交
124
	// Listen for accepting connections from client.
125
	ln, err := net.Listen("tcp", fmt.Sprintf("%s:%d", cfg.BindAddr, cfg.BindPort))
F
fatedier 已提交
126 127 128 129
	if err != nil {
		err = fmt.Errorf("Create server listener error, %v", err)
		return
	}
F
FishFish 已提交
130

F
fix ci  
fatedier 已提交
131 132
	svr.muxer = mux.NewMux(ln)
	go svr.muxer.Serve()
F
FishFish 已提交
133 134
	ln = svr.muxer.DefaultListener()

135
	svr.listener = frpNet.WrapLogListener(ln)
F
fatedier 已提交
136
	log.Info("frps tcp listen on %s:%d", cfg.BindAddr, cfg.BindPort)
F
fatedier 已提交
137 138

	// Listen for accepting connections from client using kcp protocol.
F
fatedier 已提交
139 140
	if cfg.KcpBindPort > 0 {
		svr.kcpListener, err = frpNet.ListenKcp(cfg.BindAddr, cfg.KcpBindPort)
F
fatedier 已提交
141
		if err != nil {
F
fatedier 已提交
142
			err = fmt.Errorf("Listen on kcp address udp [%s:%d] error: %v", cfg.BindAddr, cfg.KcpBindPort, err)
F
fatedier 已提交
143 144
			return
		}
F
fatedier 已提交
145
		log.Info("frps kcp listen on udp %s:%d", cfg.BindAddr, cfg.KcpBindPort)
F
fatedier 已提交
146
	}
F
fatedier 已提交
147

F
fatedier 已提交
148
	// Listen for accepting connections from client using websocket protocol.
F
fatedier 已提交
149
	websocketPrefix := []byte("GET " + frpNet.FrpWebsocketPath)
F
fatedier 已提交
150 151 152 153 154
	websocketLn := svr.muxer.Listen(0, uint32(len(websocketPrefix)), func(data []byte) bool {
		return bytes.Equal(data, websocketPrefix)
	})
	svr.websocketListener = frpNet.NewWebsocketListener(websocketLn)

F
fatedier 已提交
155
	// Create http vhost muxer.
F
fatedier 已提交
156
	if cfg.VhostHttpPort > 0 {
F
fatedier 已提交
157 158 159
		rp := vhost.NewHttpReverseProxy(vhost.HttpReverseProxyOptions{
			ResponseHeaderTimeoutS: cfg.VhostHttpTimeout,
		})
F
fatedier 已提交
160
		svr.rc.HttpReverseProxy = rp
F
fatedier 已提交
161 162 163 164 165

		address := fmt.Sprintf("%s:%d", cfg.ProxyBindAddr, cfg.VhostHttpPort)
		server := &http.Server{
			Addr:    address,
			Handler: rp,
F
fatedier 已提交
166
		}
F
fatedier 已提交
167
		var l net.Listener
168
		if httpMuxOn {
F
fatedier 已提交
169
			l = svr.muxer.ListenHttp(1)
170 171 172 173 174 175
		} else {
			l, err = net.Listen("tcp", address)
			if err != nil {
				err = fmt.Errorf("Create vhost http listener error, %v", err)
				return
			}
F
fatedier 已提交
176
		}
F
fatedier 已提交
177
		go server.Serve(l)
F
fatedier 已提交
178
		log.Info("http service listen on %s:%d", cfg.ProxyBindAddr, cfg.VhostHttpPort)
F
fatedier 已提交
179 180 181
	}

	// Create https vhost muxer.
F
fatedier 已提交
182
	if cfg.VhostHttpsPort > 0 {
183 184
		var l net.Listener
		if httpsMuxOn {
F
fatedier 已提交
185
			l = svr.muxer.ListenHttps(1)
186 187 188 189 190 191
		} else {
			l, err = net.Listen("tcp", fmt.Sprintf("%s:%d", cfg.ProxyBindAddr, cfg.VhostHttpsPort))
			if err != nil {
				err = fmt.Errorf("Create server listener error, %v", err)
				return
			}
F
fatedier 已提交
192
		}
193

F
fatedier 已提交
194
		svr.rc.VhostHttpsMuxer, err = vhost.NewHttpsMuxer(frpNet.WrapLogListener(l), 30*time.Second)
F
fatedier 已提交
195 196 197 198
		if err != nil {
			err = fmt.Errorf("Create vhost httpsMuxer error, %v", err)
			return
		}
F
fatedier 已提交
199 200 201
		log.Info("https service listen on %s:%d", cfg.ProxyBindAddr, cfg.VhostHttpsPort)
	}

F
fatedier 已提交
202 203 204 205 206 207
	// frp tls listener
	tlsListener := svr.muxer.Listen(1, 1, func(data []byte) bool {
		return int(data[0]) == frpNet.FRP_TLS_HEAD_BYTE
	})
	svr.tlsListener = frpNet.WrapLogListener(tlsListener)

F
fatedier 已提交
208 209
	// Create nat hole controller.
	if cfg.BindUdpPort > 0 {
F
fatedier 已提交
210
		var nc *nathole.NatHoleController
F
fatedier 已提交
211
		addr := fmt.Sprintf("%s:%d", cfg.BindAddr, cfg.BindUdpPort)
F
fatedier 已提交
212
		nc, err = nathole.NewNatHoleController(addr)
F
fatedier 已提交
213 214 215 216
		if err != nil {
			err = fmt.Errorf("Create nat hole controller error, %v", err)
			return
		}
F
fatedier 已提交
217
		svr.rc.NatHoleController = nc
F
fatedier 已提交
218
		log.Info("nat hole udp service listen on %s:%d", cfg.BindAddr, cfg.BindUdpPort)
F
fatedier 已提交
219 220
	}

F
fatedier 已提交
221
	var statsEnable bool
F
fatedier 已提交
222
	// Create dashboard web server.
F
fatedier 已提交
223
	if cfg.DashboardPort > 0 {
F
fatedier 已提交
224
		err = svr.RunDashboardServer(cfg.DashboardAddr, cfg.DashboardPort)
F
fatedier 已提交
225 226 227 228
		if err != nil {
			err = fmt.Errorf("Create dashboard web server error, %v", err)
			return
		}
T
timerever 已提交
229
		log.Info("Dashboard listen on %s:%d", cfg.DashboardAddr, cfg.DashboardPort)
F
fatedier 已提交
230
		statsEnable = true
F
fatedier 已提交
231
	}
F
FishFish 已提交
232

F
fatedier 已提交
233
	svr.statsCollector = stats.NewInternalCollector(statsEnable)
F
fatedier 已提交
234 235 236 237
	return
}

func (svr *Service) Run() {
F
fatedier 已提交
238 239
	if svr.rc.NatHoleController != nil {
		go svr.rc.NatHoleController.Run()
F
fatedier 已提交
240
	}
F
fatedier 已提交
241
	if g.GlbServerCfg.KcpBindPort > 0 {
F
fatedier 已提交
242 243 244
		go svr.HandleListener(svr.kcpListener)
	}

F
fatedier 已提交
245
	go svr.HandleListener(svr.websocketListener)
F
fatedier 已提交
246
	go svr.HandleListener(svr.tlsListener)
F
fatedier 已提交
247

F
fatedier 已提交
248 249 250 251
	svr.HandleListener(svr.listener)
}

func (svr *Service) HandleListener(l frpNet.Listener) {
F
fatedier 已提交
252 253
	// Listen for incoming connections from client.
	for {
F
fatedier 已提交
254
		c, err := l.Accept()
F
fatedier 已提交
255 256 257 258
		if err != nil {
			log.Warn("Listener for incoming connections from client closed")
			return
		}
F
fatedier 已提交
259
		c = frpNet.CheckAndEnableTLSServerConn(c, svr.tlsConfig)
F
fatedier 已提交
260 261

		// Start a new goroutine for dealing connections.
262 263 264 265 266
		go func(frpConn frpNet.Conn) {
			dealFn := func(conn frpNet.Conn) {
				var rawMsg msg.Message
				conn.SetReadDeadline(time.Now().Add(connReadTimeout))
				if rawMsg, err = msg.ReadMsg(conn); err != nil {
F
fatedier 已提交
267
					log.Trace("Failed to read message: %v", err)
268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287
					conn.Close()
					return
				}
				conn.SetReadDeadline(time.Time{})

				switch m := rawMsg.(type) {
				case *msg.Login:
					err = svr.RegisterControl(conn, m)
					// If login failed, send error message there.
					// Otherwise send success message in control's work goroutine.
					if err != nil {
						conn.Warn("%v", err)
						msg.WriteMsg(conn, &msg.LoginResp{
							Version: version.Full(),
							Error:   err.Error(),
						})
						conn.Close()
					}
				case *msg.NewWorkConn:
					svr.RegisterWorkConn(conn, m)
F
fatedier 已提交
288 289
				case *msg.NewVisitorConn:
					if err = svr.RegisterVisitorConn(conn, m); err != nil {
F
fatedier 已提交
290
						conn.Warn("%v", err)
F
fatedier 已提交
291
						msg.WriteMsg(conn, &msg.NewVisitorConnResp{
F
fatedier 已提交
292 293 294 295 296
							ProxyName: m.ProxyName,
							Error:     err.Error(),
						})
						conn.Close()
					} else {
F
fatedier 已提交
297
						msg.WriteMsg(conn, &msg.NewVisitorConnResp{
F
fatedier 已提交
298 299 300 301
							ProxyName: m.ProxyName,
							Error:     "",
						})
					}
302 303 304 305
				default:
					log.Warn("Error message type for the new connection [%s]", conn.RemoteAddr().String())
					conn.Close()
				}
F
fatedier 已提交
306 307
			}

F
fatedier 已提交
308
			if g.GlbServerCfg.TcpMux {
F
fatedier 已提交
309
				fmuxCfg := fmux.DefaultConfig()
F
fatedier 已提交
310
				fmuxCfg.KeepAliveInterval = 20 * time.Second
F
fatedier 已提交
311 312
				fmuxCfg.LogOutput = ioutil.Discard
				session, err := fmux.Server(frpConn, fmuxCfg)
F
fatedier 已提交
313
				if err != nil {
314
					log.Warn("Failed to create mux connection: %v", err)
F
fatedier 已提交
315
					frpConn.Close()
316 317 318 319 320 321
					return
				}

				for {
					stream, err := session.AcceptStream()
					if err != nil {
322
						log.Debug("Accept new mux stream error: %v", err)
F
fatedier 已提交
323
						session.Close()
324 325 326 327
						return
					}
					wrapConn := frpNet.WrapConn(stream)
					go dealFn(wrapConn)
F
fatedier 已提交
328
				}
329 330
			} else {
				dealFn(frpConn)
F
fatedier 已提交
331 332 333 334 335
			}
		}(c)
	}
}

336
func (svr *Service) RegisterControl(ctlConn frpNet.Conn, loginMsg *msg.Login) (err error) {
F
fatedier 已提交
337 338 339 340 341 342 343 344 345 346
	ctlConn.Info("client login info: ip [%s] version [%s] hostname [%s] os [%s] arch [%s]",
		ctlConn.RemoteAddr().String(), loginMsg.Version, loginMsg.Hostname, loginMsg.Os, loginMsg.Arch)

	// Check client version.
	if ok, msg := version.Compat(loginMsg.Version); !ok {
		err = fmt.Errorf("%s", msg)
		return
	}

	// Check auth.
F
fatedier 已提交
347
	if util.GetAuthKey(g.GlbServerCfg.Token, loginMsg.Timestamp) != loginMsg.PrivilegeKey {
F
fatedier 已提交
348 349 350 351 352 353 354 355 356 357 358 359 360
		err = fmt.Errorf("authorization failed")
		return
	}

	// If client's RunId is empty, it's a new client, we just create a new controller.
	// Otherwise, we check if there is one controller has the same run id. If so, we release previous controller and start new one.
	if loginMsg.RunId == "" {
		loginMsg.RunId, err = util.RandId()
		if err != nil {
			return
		}
	}

F
fatedier 已提交
361
	ctl := NewControl(svr.rc, svr.pxyManager, svr.statsCollector, ctlConn, loginMsg)
F
fatedier 已提交
362

F
fatedier 已提交
363
	if oldCtl := svr.ctlManager.Add(loginMsg.RunId, ctl); oldCtl != nil {
F
fatedier 已提交
364
		oldCtl.allShutdown.WaitDone()
F
fatedier 已提交
365 366 367 368
	}

	ctlConn.AddLogPrefix(loginMsg.RunId)
	ctl.Start()
369 370

	// for statistics
F
fatedier 已提交
371 372 373 374 375
	svr.statsCollector.Mark(stats.TypeNewClient, &stats.NewClientPayload{})

	go func() {
		// block until control closed
		ctl.WaitClosed()
F
fatedier 已提交
376
		svr.ctlManager.Del(loginMsg.RunId, ctl)
F
fatedier 已提交
377
	}()
F
fatedier 已提交
378 379 380 381
	return
}

// RegisterWorkConn register a new work connection to control and proxies need it.
382
func (svr *Service) RegisterWorkConn(workConn frpNet.Conn, newMsg *msg.NewWorkConn) {
F
fatedier 已提交
383
	ctl, exist := svr.ctlManager.GetById(newMsg.RunId)
F
fatedier 已提交
384 385 386 387 388 389 390 391
	if !exist {
		workConn.Warn("No client control found for run id [%s]", newMsg.RunId)
		return
	}
	ctl.RegisterWorkConn(workConn)
	return
}

F
fatedier 已提交
392
func (svr *Service) RegisterVisitorConn(visitorConn frpNet.Conn, newMsg *msg.NewVisitorConn) error {
F
fatedier 已提交
393
	return svr.rc.VisitorManager.NewConn(newMsg.ProxyName, visitorConn, newMsg.Timestamp, newMsg.SignKey,
F
fatedier 已提交
394 395
		newMsg.UseEncryption, newMsg.UseCompression)
}
F
fatedier 已提交
396 397 398 399 400 401 402 403 404 405 406 407 408 409 410 411 412 413 414 415 416

// Setup a bare-bones TLS config for the server
func generateTLSConfig() *tls.Config {
	key, err := rsa.GenerateKey(rand.Reader, 1024)
	if err != nil {
		panic(err)
	}
	template := x509.Certificate{SerialNumber: big.NewInt(1)}
	certDER, err := x509.CreateCertificate(rand.Reader, &template, &template, &key.PublicKey, key)
	if err != nil {
		panic(err)
	}
	keyPEM := pem.EncodeToMemory(&pem.Block{Type: "RSA PRIVATE KEY", Bytes: x509.MarshalPKCS1PrivateKey(key)})
	certPEM := pem.EncodeToMemory(&pem.Block{Type: "CERTIFICATE", Bytes: certDER})

	tlsCert, err := tls.X509KeyPair(certPEM, keyPEM)
	if err != nil {
		panic(err)
	}
	return &tls.Config{Certificates: []tls.Certificate{tlsCert}}
}