Files
EdgeNode/internal/iplibrary/manager_ip_list.go

350 lines
7.5 KiB
Go
Raw Normal View History

package iplibrary
import (
2024-04-06 15:37:14 +08:00
"github.com/TeaOSLab/EdgeCommon/pkg/iputils"
"github.com/TeaOSLab/EdgeCommon/pkg/nodeconfigs"
"github.com/TeaOSLab/EdgeCommon/pkg/rpc/pb"
2022-09-21 16:49:48 +08:00
teaconst "github.com/TeaOSLab/EdgeNode/internal/const"
"github.com/TeaOSLab/EdgeNode/internal/events"
"github.com/TeaOSLab/EdgeNode/internal/goman"
"github.com/TeaOSLab/EdgeNode/internal/remotelogs"
"github.com/TeaOSLab/EdgeNode/internal/rpc"
2024-03-31 10:08:53 +08:00
"github.com/TeaOSLab/EdgeNode/internal/trackers"
"github.com/TeaOSLab/EdgeNode/internal/utils/idles"
"github.com/TeaOSLab/EdgeNode/internal/waf"
"github.com/TeaOSLab/EdgeNode/internal/zero"
"github.com/iwind/TeaGo/Tea"
2024-03-31 10:08:53 +08:00
"github.com/iwind/TeaGo/types"
"os"
"sync"
"time"
)
var SharedIPListManager = NewIPListManager()
var IPListUpdateNotify = make(chan bool, 1)
func init() {
if !teaconst.IsMain {
2022-09-21 16:49:48 +08:00
return
}
events.On(events.EventLoaded, func() {
goman.New(func() {
SharedIPListManager.Start()
})
})
events.OnClose(func() {
2022-01-12 20:31:04 +08:00
SharedIPListManager.Stop()
})
2022-09-21 16:49:48 +08:00
var ticker = time.NewTicker(24 * time.Hour)
goman.New(func() {
idles.RunTicker(ticker, func() {
2022-09-21 16:49:48 +08:00
SharedIPListManager.DeleteExpiredItems()
})
2022-09-21 16:49:48 +08:00
})
}
// IPListManager IP名单管理
type IPListManager struct {
2022-01-12 20:31:04 +08:00
ticker *time.Ticker
2024-03-31 10:08:53 +08:00
db IPListDB
2023-04-19 12:01:02 +08:00
lastVersion int64
fetchPageSize int64
listMap map[int64]*IPList
mu sync.RWMutex
2023-04-19 12:01:02 +08:00
isFirstTime bool
}
func NewIPListManager() *IPListManager {
return &IPListManager{
2023-04-19 12:01:02 +08:00
fetchPageSize: 5_000,
listMap: map[int64]*IPList{},
isFirstTime: true,
}
}
func (this *IPListManager) Start() {
this.Init()
// 第一次读取
err := this.Loop()
if err != nil {
2021-11-10 21:51:56 +08:00
remotelogs.ErrorObject("IP_LIST_MANAGER", err)
}
2022-01-12 20:31:04 +08:00
this.ticker = time.NewTicker(60 * time.Second)
if Tea.IsTesting() {
2022-01-12 20:31:04 +08:00
this.ticker = time.NewTicker(10 * time.Second)
}
var countErrors = 0
for {
select {
2022-01-12 20:31:04 +08:00
case <-this.ticker.C:
case <-IPListUpdateNotify:
}
err = this.Loop()
if err != nil {
2020-11-15 11:58:08 +08:00
countErrors++
2021-11-10 21:51:56 +08:00
remotelogs.ErrorObject("IP_LIST_MANAGER", err)
2020-11-15 11:58:08 +08:00
// 连续错误小于3次的我们立即重试
if countErrors <= 3 {
select {
case IPListUpdateNotify <- true:
default:
}
}
2020-11-15 11:58:08 +08:00
} else {
countErrors = 0
}
}
}
2022-01-12 20:31:04 +08:00
func (this *IPListManager) Stop() {
if this.ticker != nil {
this.ticker.Stop()
}
}
func (this *IPListManager) Init() {
// 从数据库中当中读取数据
2024-03-31 10:08:53 +08:00
// 检查sqlite文件是否存在以便决定使用sqlite还是kv
var sqlitePath = Tea.Root + "/data/ip_list.db"
_, sqliteErr := os.Stat(sqlitePath)
var db IPListDB
var err error
2024-04-02 19:54:04 +08:00
if sqliteErr == nil || !teaconst.EnableKVCacheStore {
2024-03-31 12:54:30 +08:00
db, err = NewSQLiteIPList()
2024-03-31 10:08:53 +08:00
} else {
2024-03-31 12:54:30 +08:00
db, err = NewKVIPList()
2024-03-31 10:08:53 +08:00
}
if err != nil {
remotelogs.Error("IP_LIST_MANAGER", "create ip list local database failed: "+err.Error())
} else {
this.db = db
// 删除本地数据库中过期的条目
_ = db.DeleteExpiredItems()
// 本地数据库中最大版本号
2024-03-31 10:08:53 +08:00
this.lastVersion, err = db.ReadMaxVersion()
if err != nil {
remotelogs.Error("IP_LIST_MANAGER", "find max version failed: "+err.Error())
this.lastVersion = 0
}
remotelogs.Println("IP_LIST_MANAGER", "starting from '"+db.Name()+"' version '"+types.String(this.lastVersion)+"' ...")
// 从本地数据库中加载
var offset int64 = 0
2023-04-19 12:01:02 +08:00
var size int64 = 2_000
2024-03-31 10:08:53 +08:00
var tr = trackers.Begin("IP_LIST_MANAGER:load")
defer tr.End()
for {
2024-03-31 10:08:53 +08:00
items, goNext, readErr := db.ReadItems(offset, size)
2022-08-30 18:49:21 +08:00
var l = len(items)
2024-03-31 10:08:53 +08:00
if readErr != nil {
remotelogs.Error("IP_LIST_MANAGER", "read ip list from local database failed: "+readErr.Error())
} else {
this.processItems(items, false)
2024-03-31 10:08:53 +08:00
if !goNext {
break
}
}
2022-08-30 18:49:21 +08:00
offset += int64(l)
}
}
}
func (this *IPListManager) Loop() error {
// 是否同步IP名单
nodeConfig, _ := nodeconfigs.SharedNodeConfig()
if nodeConfig != nil && !nodeConfig.EnableIPLists {
return nil
}
2023-04-19 12:01:02 +08:00
// 第一次同步则打印信息
if this.isFirstTime {
remotelogs.Println("IP_LIST_MANAGER", "initializing ip items ...")
}
for {
hasNext, err := this.fetch()
if err != nil {
return err
}
if !hasNext {
break
}
time.Sleep(1 * time.Second)
}
2023-04-19 12:01:02 +08:00
// 第一次同步则打印信息
if this.isFirstTime {
this.isFirstTime = false
remotelogs.Println("IP_LIST_MANAGER", "finished initializing ip items")
}
return nil
}
func (this *IPListManager) fetch() (hasNext bool, err error) {
rpcClient, err := rpc.SharedRPC()
if err != nil {
return false, err
}
2022-08-24 20:04:46 +08:00
itemsResp, err := rpcClient.IPItemRPC.ListIPItemsAfterVersion(rpcClient.Context(), &pb.ListIPItemsAfterVersionRequest{
2023-04-19 12:01:02 +08:00
Version: this.lastVersion,
Size: this.fetchPageSize,
})
if err != nil {
2022-04-08 15:25:53 +08:00
if rpc.IsConnError(err) {
2023-08-13 14:25:59 +08:00
remotelogs.Debug("IP_LIST_MANAGER", "rpc connection error: "+err.Error())
2022-04-08 15:25:53 +08:00
return false, nil
}
return false, err
}
2022-08-30 18:49:21 +08:00
var items = itemsResp.IpItems
if len(items) == 0 {
return false, nil
}
// 保存到本地数据库
if this.db != nil {
for _, item := range items {
err = this.db.AddItem(item)
if err != nil {
remotelogs.Error("IP_LIST_MANAGER", "insert item to local database failed: "+err.Error())
}
}
}
this.processItems(items, true)
return true, nil
}
func (this *IPListManager) FindList(listId int64) *IPList {
2024-04-06 15:37:14 +08:00
this.mu.RLock()
2023-08-08 15:39:00 +08:00
var list = this.listMap[listId]
2024-04-06 15:37:14 +08:00
this.mu.RUnlock()
return list
}
2022-09-21 16:49:48 +08:00
func (this *IPListManager) DeleteExpiredItems() {
if this.db != nil {
_ = this.db.DeleteExpiredItems()
}
}
func (this *IPListManager) ListMap() map[int64]*IPList {
return this.listMap
}
2023-04-19 12:01:02 +08:00
// 处理IP条目
func (this *IPListManager) processItems(items []*pb.IPItem, fromRemote bool) {
var changedLists = map[*IPList]zero.Zero{}
for _, item := range items {
2023-09-12 16:05:18 +08:00
// 调试
if Tea.IsTesting() {
this.debugItem(item)
}
var list *IPList
// TODO 实现节点专有List
if item.ServerId > 0 { // 服务专有List
switch item.ListType {
case "black":
list = SharedServerListManager.FindBlackList(item.ServerId, true)
case "white":
list = SharedServerListManager.FindWhiteList(item.ServerId, true)
}
} else if item.IsGlobal { // 全局List
switch item.ListType {
case "black":
list = GlobalBlackIPList
case "white":
list = GlobalWhiteIPList
}
} else { // 其他List
2024-04-06 15:37:14 +08:00
this.mu.Lock()
list = this.listMap[item.ListId]
2024-04-06 15:37:14 +08:00
this.mu.Unlock()
}
if list == nil {
list = NewIPList()
2024-04-06 15:37:14 +08:00
this.mu.Lock()
this.listMap[item.ListId] = list
2024-04-06 15:37:14 +08:00
this.mu.Unlock()
}
2021-10-04 17:42:38 +08:00
changedLists[list] = zero.New()
2021-10-04 17:42:38 +08:00
if item.IsDeleted {
2022-04-09 18:28:22 +08:00
list.Delete(uint64(item.Id))
2021-02-06 17:34:33 +08:00
// 从WAF名单中删除
waf.SharedIPBlackList.RemoveIP(item.IpFrom, item.ServerId, fromRemote)
2021-02-06 17:34:33 +08:00
// 操作事件
if fromRemote {
SharedActionManager.DeleteItem(item.ListType, item)
}
2021-02-06 17:34:33 +08:00
continue
}
2021-02-06 17:34:33 +08:00
2021-10-04 17:42:38 +08:00
list.AddDelay(&IPItem{
2022-04-09 18:28:22 +08:00
Id: uint64(item.Id),
2021-02-06 17:34:33 +08:00
Type: item.Type,
2024-04-06 15:37:14 +08:00
IPFrom: iputils.ToBytes(item.IpFrom),
IPTo: iputils.ToBytes(item.IpTo),
2021-02-06 17:34:33 +08:00
ExpiredAt: item.ExpiredAt,
EventLevel: item.EventLevel,
})
2021-02-06 17:34:33 +08:00
// 事件操作
if fromRemote {
SharedActionManager.DeleteItem(item.ListType, item)
SharedActionManager.AddItem(item.ListType, item)
}
}
2021-10-04 17:42:38 +08:00
2024-03-30 14:42:56 +08:00
if len(changedLists) > 0 {
for changedList := range changedLists {
changedList.Sort()
}
2021-10-04 17:42:38 +08:00
}
if fromRemote {
var latestVersion = items[len(items)-1].Version
2023-04-19 12:01:02 +08:00
if latestVersion > this.lastVersion {
this.lastVersion = latestVersion
}
}
}
2023-09-12 16:05:18 +08:00
// 调试IP信息
func (this *IPListManager) debugItem(item *pb.IPItem) {
2024-03-31 10:08:53 +08:00
var ipRange = item.IpFrom
if len(item.IpTo) > 0 {
ipRange += " - " + item.IpTo
}
2023-09-12 16:05:18 +08:00
if item.IsDeleted {
2024-03-31 10:08:53 +08:00
remotelogs.Debug("IP_ITEM_DEBUG", "delete '"+ipRange+"'")
2023-09-12 16:05:18 +08:00
} else {
2024-03-31 10:08:53 +08:00
remotelogs.Debug("IP_ITEM_DEBUG", "add '"+ipRange+"'")
2023-09-12 16:05:18 +08:00
}
}