mirror of
https://github.com/XTLS/Xray-core.git
synced 2026-10-02 05:46:39 +00:00
Windows sends name queries to the DNS servers of all interfaces, and a resolver on the local network (e.g. 192.168.1.1 from DHCP) is reached through its more specific LAN route instead of the TUN, so DNS leaks past it. IPv6 bypasses a TUN that cannot carry it. With autoSystemRoutingTable set, the Windows TUN now adds Windows Filtering Platform filters, all in one transaction and in a dynamic session, so that they are removed when Xray exits, even if it crashes: - DNS (port 53) only goes through the TUN, in both directions: its local address, and the interface it leaves or arrives by, must be the TUN's. - IPv6 is blocked in both directions when the TUN has no IPv6 address or no IPv6 route, except loopback, neighbor and multicast listener discovery, and DHCPv6. - Xray's own traffic is exempt: its connections out with a hard permit, which Windows Firewall rules do not override (like sing-box's strict_route), connections to its inbounds with an ordinary one. If the filters cannot be added, the TUN does not start on Windows 10 and later (only a warning on 7/8). The new `strictRoute` option (true by default) turns them off. Also on Windows: - A warning for `dns` servers outside gateway and autoSystemRoutingTable, as queries to them cannot go through the TUN and are blocked. - While DNS is restricted and autoOutboundsInterface is in use, Xray resolves the names it would ask Windows for itself (Go's resolver on its own sockets). Those lookups and the `localhost` DNS server skip the TUN's DNS servers, unless another interface uses them too, instead of looping back into the TUN. - The DNS cache is flushed when the TUN starts and stops, and DNS registration is turned off on the TUN (through netsh before Windows 10 1809). - Close no longer panics when registering the route or interface change callbacks failed. The README's Windows section describes all of it. Tested on Windows 11, elevated, amd64 and 386: the filters, DNS arriving through a real Wintun adapter and blocked outside it, the IPv6 block, Windows Firewall rules, and a real Xray run. Windows 7/8 and Windows 10 before 1809 are untested. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
112 lines
2.5 KiB
Go
112 lines
2.5 KiB
Go
package localdns
|
|
|
|
import (
|
|
"context"
|
|
"syscall"
|
|
"time"
|
|
|
|
"github.com/xtls/xray-core/common/errors"
|
|
"github.com/xtls/xray-core/common/net"
|
|
"github.com/xtls/xray-core/features/dns"
|
|
"github.com/xtls/xray-core/transport/internet"
|
|
)
|
|
|
|
// Client is an implementation of dns.Client, which queries localhost for DNS.
|
|
type Client struct {
|
|
d *net.Dialer
|
|
r *net.Resolver
|
|
}
|
|
|
|
// Type implements common.HasType.
|
|
func (*Client) Type() interface{} {
|
|
return dns.ClientType()
|
|
}
|
|
|
|
// Start implements common.Runnable.
|
|
func (*Client) Start() error { return nil }
|
|
|
|
// Close implements common.Closable.
|
|
func (*Client) Close() error { return nil }
|
|
|
|
// LookupIP implements Client.
|
|
func (c *Client) LookupIP(host string, option dns.IPOption) ([]net.IP, uint32, error) {
|
|
var ips []net.IP
|
|
var err error
|
|
if len(internet.Controllers) > 0 {
|
|
ips, err = c.r.LookupIP(context.Background(), "ip", host)
|
|
} else {
|
|
ips, err = net.LookupIP(host)
|
|
}
|
|
if err != nil {
|
|
return nil, 0, err
|
|
}
|
|
parsedIPs := make([]net.IP, 0, len(ips))
|
|
ipv4 := make([]net.IP, 0, len(ips))
|
|
ipv6 := make([]net.IP, 0, len(ips))
|
|
for _, ip := range ips {
|
|
parsed := net.IPAddress(ip)
|
|
if parsed == nil {
|
|
continue
|
|
}
|
|
parsedIP := parsed.IP()
|
|
parsedIPs = append(parsedIPs, parsedIP)
|
|
|
|
if len(parsedIP) == net.IPv4len {
|
|
ipv4 = append(ipv4, parsedIP)
|
|
} else {
|
|
ipv6 = append(ipv6, parsedIP)
|
|
}
|
|
}
|
|
|
|
switch {
|
|
case option.IPv4Enable && option.IPv6Enable:
|
|
if len(parsedIPs) > 0 {
|
|
return parsedIPs, dns.DefaultTTL, nil
|
|
}
|
|
case option.IPv4Enable:
|
|
if len(ipv4) > 0 {
|
|
return ipv4, dns.DefaultTTL, nil
|
|
}
|
|
case option.IPv6Enable:
|
|
if len(ipv6) > 0 {
|
|
return ipv6, dns.DefaultTTL, nil
|
|
}
|
|
}
|
|
return nil, 0, dns.ErrEmptyResponse
|
|
}
|
|
|
|
// New create a new dns.Client that queries localhost for DNS.
|
|
func New() *Client {
|
|
d := &net.Dialer{
|
|
Timeout: time.Second * 16,
|
|
Control: func(network, address string, c syscall.RawConn) error {
|
|
var errs []error
|
|
for _, ctl := range internet.Controllers {
|
|
if err := ctl(network, address, c); err != nil {
|
|
errs = append(errs, err)
|
|
}
|
|
}
|
|
err := errors.Combine(errs...)
|
|
if err != nil {
|
|
errors.LogInfoInner(context.Background(), err, "failed to apply external controller")
|
|
}
|
|
return err
|
|
},
|
|
}
|
|
|
|
r := &net.Resolver{
|
|
PreferGo: true,
|
|
Dial: func(ctx context.Context, network, address string) (net.Conn, error) {
|
|
if internet.IsSkippedDNSServer(address) {
|
|
return nil, errors.New("skipped DNS server ", address)
|
|
}
|
|
return d.DialContext(ctx, network, address)
|
|
},
|
|
}
|
|
|
|
return &Client{
|
|
d: d,
|
|
r: r,
|
|
}
|
|
}
|