spoofer

package
v0.9.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 28, 2026 License: MIT Imports: 23 Imported by: 0

Documentation

Overview

Package spoofer provides a network stack spoofer built on top of gVisor's netstack. It can intercept and forward TCP and UDP traffic from a TUN device or an io.ReadWriteCloser.

OnTCPConn is an eager compatibility API: the intercepted client handshake is complete before the callback runs. PrepareTCP is the connection-gated API: it lets a forward proxy connect its upstream before Spoofer accepts the client connection.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func NewIOEndpoint

func NewIOEndpoint(rwc io.ReadWriteCloser, mtu uint32, qlen int) *ioEndpoint

NewIOEndpoint creates a new link-layer endpoint that wraps an io.ReadWriteCloser. Packets are read from the RWC and injected into the netstack, and outbound packets are written to the RWC. If mtu is 0, it defaults to 1500. If qlen is less than 1, it defaults to 1024.

func NewTunEndpoint

func NewTunEndpoint(tun tun.Tun, qlen int) *tunEndpoint

NewTunEndpoint creates a new link-layer endpoint that wraps a TUN device directly. It uses the TUN's native batch operations and MTU for better performance compared to the io.ReadWriteCloser wrapper. If qlen is less than 1, it defaults to 1024.

Types

type Opts

type Opts struct {
	// OnTCPConn is the eager, compatibility TCP callback. Spoofer completes the
	// intercepted client handshake before it calls this function. A failure to
	// connect the real upstream can therefore not make the original Dial fail.
	// Forward proxies that need correct connection results must use PrepareTCP.
	OnTCPConn func(net.Conn, stack.TransportEndpointID)
	// PrepareTCP prepares the real upstream before Spoofer accepts an
	// intercepted TCP connection. If preparation fails, Spoofer resets the
	// client flow and calls OnTCPError. If it succeeds, Spoofer completes the
	// client handshake and passes the connection to the prepared handler.
	// PrepareTCP takes priority when both TCP callbacks are set.
	PrepareTCP func(context.Context, stack.TransportEndpointID) (PreparedTCPHandler, error)
	// OnTCPError reports preparation and client-endpoint errors from the
	// connection-gated PrepareTCP path. Spoofer calls it from a forwarding
	// goroutine. The callback must be safe for concurrent use.
	OnTCPError func(stack.TransportEndpointID, error)
	// TCPPrepareTimeout limits each PrepareTCP call. The default is 30 seconds.
	// Values less than or equal to zero use the default. PrepareTCP must stop
	// work and release partial resources when its context is done.
	TCPPrepareTimeout time.Duration
	// OnUDPConn is called when a new UDP stream is forwarded.
	// The callback receives a packet connection and the transport endpoint ID.
	OnUDPConn func(gonnect.PacketConn, stack.TransportEndpointID)

	// Endpoint is the link-layer endpoint used by the netstack.
	// Set it via WithRWCEndpoint or WithTunEndpoint before calling Launch.
	Endpoint stack.LinkEndpoint

	// TCPSendBufferSize sets the default TCP send buffer size.
	TCPSendBufferSize int
	// TCPReceiveBufferSize sets the default TCP receive buffer size.
	TCPReceiveBufferSize int
	// TTL sets the default TTL for outgoing packets.
	TTL int
	// ICMPBurst sets the ICMP rate limiter burst size.
	ICMPBurst int
	// ICMPLimit sets the ICMP rate limit (packets per second).
	ICMPLimit float64
	// CongestionControlAlg sets the TCP congestion control algorithm name
	// (e.g., "cubic", "reno").
	CongestionControlAlg string
	// DisableNagle disables Nagle's algorithm (TCP_NODELAY).
	DisableNagle bool
	// DisableTCPModRecBuff disables TCP moderate receive buffer auto-tuning.
	DisableTCPModRecBuff bool
	// TCPRec sets the TCP recovery option for tail loss probe.
	TCPRec *tcpip.TCPRecovery

	// TCPKeepAlive enables TCP keep-alive on forwarded connections.
	TCPKeepAlive bool
	// TCPKeepAliveIdle sets the time before sending keep-alive probes.
	TCPKeepAliveIdle time.Duration
	// TCPKeepaliveInterval sets the interval between keep-alive probes.
	TCPKeepaliveInterval time.Duration
	// TCPKeepaliveCount sets the maximum number of unacknowledged keep-alive probes.
	TCPKeepaliveCount int

	// TCPForwardWnd sets the TCP receive window size for forwarded connections.
	TCPForwardWnd int
	// TCPForwardAttempts sets the maximum concurrent TCP connection forwarding attempts.
	TCPForwardAttempts int

	// NetStackOpts provides additional netstack configuration options.
	NetStackOpts *helpers.Opts
}

Opts holds configuration options for the spoofer. It controls network stack behavior, TCP/UDP forwarding, and endpoint setup.

func (*Opts) Launch

func (o *Opts) Launch() (*stack.Stack, error)

Launch initializes and starts the network stack with the configured options. It creates a NIC, sets up TCP and UDP forwarders, enables promiscuous mode and spoofing, and configures routing for IPv4 and IPv6.

PrepareTCP calls always have their individual timeout. Use LaunchContext when shutdown must also cancel pending preparation calls. Returns the initialized stack or an error if setup fails.

func (*Opts) LaunchContext added in v0.7.0

func (o *Opts) LaunchContext(ctx context.Context) (*stack.Stack, error)

LaunchContext is like Launch, and it also uses ctx as the Spoofer lifetime. Cancel ctx before stack shutdown to stop all pending PrepareTCP calls. Removing the Spoofer NIC also cancels these calls.

func (*Opts) WithRWCEndpoint

func (o *Opts) WithRWCEndpoint(rwc io.ReadWriteCloser, qlen int) *Opts

WithRWCEndpoint configures the spoofer to use an io.ReadWriteCloser as the link-layer endpoint. It wraps the RWC in an IOEndpoint with the given MTU and queue length. If mtu is 0, it defaults to 1500. If qlen is less than 1, it defaults to 1024. Returns the Opts for method chaining.

func (*Opts) WithTunEndpoint

func (o *Opts) WithTunEndpoint(tun tun.Tun, qlen int) *Opts

WithTunEndpoint configures the spoofer to use a TUN device as the link-layer endpoint. It creates a TunEndpoint with the given queue length. If qlen is less than 1, it defaults to 1024. Returns the Opts for method chaining.

type PreparedTCPHandler added in v0.7.0

type PreparedTCPHandler interface {
	HandleTCP(net.Conn)
	Close() error
}

PreparedTCPHandler owns an upstream resource that is ready for use. Spoofer calls HandleTCP only after it completes the intercepted client handshake. Ownership passes to HandleTCP at that point. Spoofer calls Close instead if it cannot create the client endpoint.

type PreparedTCPHandlerFuncs added in v0.7.0

type PreparedTCPHandlerFuncs struct {
	HandleFunc func(net.Conn)
	CloseFunc  func() error
}

PreparedTCPHandlerFuncs adapts functions to PreparedTCPHandler.

func (PreparedTCPHandlerFuncs) Close added in v0.7.0

func (h PreparedTCPHandlerFuncs) Close() error

Close calls CloseFunc when it is not nil.

func (PreparedTCPHandlerFuncs) HandleTCP added in v0.7.0

func (h PreparedTCPHandlerFuncs) HandleTCP(conn net.Conn)

HandleTCP calls HandleFunc when it is not nil.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL