mirror of
https://github.com/onyx-and-iris/q3rcon-proxy.git
synced 2026-04-07 15:53:29 +00:00
Compare commits
20 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| c42df03858 | |||
| 64c1df645d | |||
| 51f22f480b | |||
| 3d1c8f90f3 | |||
| 2fc0f7a74f | |||
| 6cd90ae1dd | |||
| 826756eb6e | |||
| 05fb7bdd0f | |||
| e8f213fded | |||
| 3a8758a4d7 | |||
| 2c8ae43303 | |||
| 0935fc1190 | |||
| 3e039824de | |||
| 0c054377ba | |||
| 5ac3f805e2 | |||
| ab548d669a | |||
| 107f914d3b | |||
| 0fdf9d10c3 | |||
| 690fabddaf | |||
| f6f0044a84 |
4
.gitignore
vendored
4
.gitignore
vendored
@@ -19,3 +19,7 @@
|
||||
|
||||
# Go workspace file
|
||||
go.work
|
||||
|
||||
# testing
|
||||
run.sh
|
||||
server.yaml
|
||||
35
CHANGELOG.md
35
CHANGELOG.md
@@ -11,8 +11,41 @@ Before any major/minor/patch bump all unit tests will be run to verify they pass
|
||||
|
||||
- [x]
|
||||
|
||||
## [0.6.0] - 2024-03-21
|
||||
|
||||
### Added
|
||||
|
||||
- new environment variable `Q3RCON_DEBUG` for enabling debug logging. Defaults to 0.
|
||||
- rcon responses are now logged at debug level
|
||||
- invalid responses (rcon and query) now logged
|
||||
|
||||
### Changed
|
||||
|
||||
- All packet header checking methods moved into Session struct.
|
||||
|
||||
### Fixed
|
||||
|
||||
- a bug causing the proxy not to send back query responses
|
||||
|
||||
## [0.3.0] - 2024-03-08
|
||||
|
||||
### Added
|
||||
|
||||
- outgoing rcon requests now logged at info level
|
||||
- new environment variable `Q3RCON_HOST` for specifying which ip to bind the proxy to. Defaults to `0.0.0.0`.
|
||||
|
||||
### Changed
|
||||
|
||||
- now using [logrus][logrus] package for logging.
|
||||
|
||||
### Fixed
|
||||
|
||||
- a `slice bounds out of range` error due to query packets being logged.
|
||||
|
||||
## [0.1.0] - 2024-01-27
|
||||
|
||||
### Added
|
||||
|
||||
- only forward packets if the header matches q3 rcon/query.
|
||||
|
||||
## [0.0.1] - 2024-01-27
|
||||
@@ -20,3 +53,5 @@ Before any major/minor/patch bump all unit tests will be run to verify they pass
|
||||
### Added
|
||||
|
||||
- All source files for lilproxy including full commit history.
|
||||
|
||||
[logrus]: https://github.com/sirupsen/logrus
|
||||
|
||||
12
README.md
12
README.md
@@ -2,6 +2,10 @@
|
||||
|
||||
A modification of [lilproxy][lilproxy_url] that forwards only Q3 rcon/query packets. Useful for separating the rcon port from the game server port.
|
||||
|
||||
### Why
|
||||
|
||||
Unfortunately the Q3Rcon engine ties the rcon port to the game servers public port used for client connections. This proxy will allow you to run rcon through a separate whitelisted port.
|
||||
|
||||
### Use
|
||||
|
||||
Run one or multiple rcon proxies by setting an environment variable `Q3RCON_PROXY`
|
||||
@@ -16,13 +20,15 @@ This would configure q3rcon-proxy to run 3 proxy servers listening on ports `200
|
||||
|
||||
Then just run the binary which you can compile yourself, download from `Releases` or use the included Dockerfile.
|
||||
|
||||
### Why
|
||||
### Logging
|
||||
|
||||
Avoid sending plaintext rcon commands to the public game server port. In general I would advise anyone using rcon remotely to use a secured connection but perhaps you've passed rcon to a clan friend who doesn't know about secured connections. Now you can instruct them to use rcon only through a whitelisted port.
|
||||
Set the log level with environment variable `Q3RCON_LOGLEVEL`:
|
||||
|
||||
`0 = Panic, 1 = Fatal, 2 = Error, 3 = Warning, 4 = Info, 5 = Debug, 6 = Trace`
|
||||
|
||||
### Special Thanks
|
||||
|
||||
[Dylan][user_link] For writing this proxy.
|
||||
[Dylan][user_link] For writing [lilproxy][lilproxy_url].
|
||||
|
||||
[lilproxy_url]: https://github.com/dgparker/lilproxy
|
||||
[user_link]: https://github.com/dgparker
|
||||
|
||||
@@ -3,21 +3,56 @@ package main
|
||||
import (
|
||||
"fmt"
|
||||
"os"
|
||||
"strconv"
|
||||
"slices"
|
||||
"strings"
|
||||
"time"
|
||||
|
||||
log "github.com/sirupsen/logrus"
|
||||
|
||||
"github.com/onyx-and-iris/q3rcon-proxy/pkg/udpproxy"
|
||||
)
|
||||
|
||||
func start(proxy string) {
|
||||
func main() {
|
||||
logLevel, err := getEnvInt("Q3RCON_LOGLEVEL")
|
||||
if err != nil {
|
||||
log.Fatalf("unable to parse Q3RCON_LEVEL: %s", err.Error())
|
||||
}
|
||||
if slices.Contains(log.AllLevels, log.Level(logLevel)) {
|
||||
log.SetLevel(log.Level(logLevel))
|
||||
}
|
||||
|
||||
proxies := os.Getenv("Q3RCON_PROXY")
|
||||
if proxies == "" {
|
||||
log.Fatal("env Q3RCON_PROXY required")
|
||||
}
|
||||
|
||||
host := os.Getenv("Q3RCON_HOST")
|
||||
if host == "" {
|
||||
host = "0.0.0.0"
|
||||
}
|
||||
|
||||
staleTimeout, err := getEnvInt("Q3RCON_STALE_SESSION_TIMEOUT")
|
||||
if err != nil {
|
||||
log.Fatalf("unable to parse Q3RCON_STALE_SESSION_TIMEOUT: %s", err.Error())
|
||||
}
|
||||
|
||||
for _, proxy := range strings.Split(proxies, ";") {
|
||||
go start(host, proxy, staleTimeout)
|
||||
}
|
||||
|
||||
<-make(chan int)
|
||||
}
|
||||
|
||||
func start(host, proxy string, staleTimeout int) {
|
||||
port, target := func() (string, string) {
|
||||
x := strings.Split(proxy, ":")
|
||||
return x[0], x[1]
|
||||
}()
|
||||
|
||||
c, err := udpproxy.New(fmt.Sprintf("%s:%s", host, port), fmt.Sprintf("127.0.0.1:%s", target))
|
||||
c, err := udpproxy.New(
|
||||
fmt.Sprintf("%s:%s", host, port),
|
||||
fmt.Sprintf("127.0.0.1:%s", target),
|
||||
udpproxy.WithStaleTimeout(time.Duration(staleTimeout)*time.Minute))
|
||||
if err != nil {
|
||||
log.Fatal(err)
|
||||
}
|
||||
@@ -26,51 +61,3 @@ func start(proxy string) {
|
||||
|
||||
log.Fatal(c.ListenAndServe())
|
||||
}
|
||||
|
||||
var (
|
||||
proxies, host string
|
||||
)
|
||||
|
||||
func getenvInt(key string) (int, error) {
|
||||
s := os.Getenv(key)
|
||||
if s == "" {
|
||||
return 0, nil
|
||||
}
|
||||
v, err := strconv.Atoi(s)
|
||||
if err != nil {
|
||||
return 0, err
|
||||
}
|
||||
return v, nil
|
||||
}
|
||||
|
||||
func init() {
|
||||
proxies = os.Getenv("Q3RCON_PROXY")
|
||||
if proxies == "" {
|
||||
log.Fatal("env Q3RCON_PROXY required")
|
||||
}
|
||||
|
||||
host = os.Getenv("Q3RCON_HOST")
|
||||
if host == "" {
|
||||
host = "0.0.0.0"
|
||||
}
|
||||
|
||||
debug, err := getenvInt("Q3RCON_DEBUG")
|
||||
if err != nil {
|
||||
log.Fatal(err)
|
||||
}
|
||||
|
||||
if debug == 1 {
|
||||
log.SetLevel(log.DebugLevel)
|
||||
} else {
|
||||
log.SetLevel(log.InfoLevel)
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
func main() {
|
||||
for _, proxy := range strings.Split(proxies, ";") {
|
||||
go start(proxy)
|
||||
}
|
||||
|
||||
<-make(chan int)
|
||||
}
|
||||
|
||||
18
cmd/q3rcon-proxy/util.go
Normal file
18
cmd/q3rcon-proxy/util.go
Normal file
@@ -0,0 +1,18 @@
|
||||
package main
|
||||
|
||||
import (
|
||||
"os"
|
||||
"strconv"
|
||||
)
|
||||
|
||||
func getEnvInt(key string) (int, error) {
|
||||
s := os.Getenv(key)
|
||||
if s == "" {
|
||||
return 0, nil
|
||||
}
|
||||
v, err := strconv.Atoi(s)
|
||||
if err != nil {
|
||||
return 0, err
|
||||
}
|
||||
return v, nil
|
||||
}
|
||||
18
debian/q3rcon-proxy.service
vendored
Normal file
18
debian/q3rcon-proxy.service
vendored
Normal file
@@ -0,0 +1,18 @@
|
||||
[Unit]
|
||||
Description=Q3Rcon Proxy Service
|
||||
Wants=network.target
|
||||
After=network.target
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
User=gameservers
|
||||
Environment="Q3RCON_PROXY=20000:28960;20001:28961;20002:28962"
|
||||
Environment="Q3RCON_HOST=0.0.0.0"
|
||||
Environment="Q3RCON_DEBUG=0"
|
||||
|
||||
ExecStart=/usr/local/bin/q3rcon-proxy
|
||||
Restart=always
|
||||
RestartSec=3
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
@@ -2,6 +2,7 @@ package udpproxy
|
||||
|
||||
import (
|
||||
"errors"
|
||||
"fmt"
|
||||
"net"
|
||||
"strings"
|
||||
"time"
|
||||
@@ -9,24 +10,27 @@ import (
|
||||
log "github.com/sirupsen/logrus"
|
||||
)
|
||||
|
||||
type Session struct {
|
||||
type session struct {
|
||||
serverConn *net.UDPConn
|
||||
proxyConn *net.UDPConn
|
||||
caddr *net.UDPAddr
|
||||
updateTime time.Time
|
||||
|
||||
validator
|
||||
}
|
||||
|
||||
func newSession(caddr *net.UDPAddr, raddr *net.UDPAddr, proxyConn *net.UDPConn) (*Session, error) {
|
||||
func newSession(caddr *net.UDPAddr, raddr *net.UDPAddr, proxyConn *net.UDPConn) (*session, error) {
|
||||
serverConn, err := net.DialUDP("udp", nil, raddr)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
|
||||
session := &Session{
|
||||
session := &session{
|
||||
serverConn: serverConn,
|
||||
proxyConn: proxyConn,
|
||||
caddr: caddr,
|
||||
updateTime: time.Now(),
|
||||
validator: newValidator(),
|
||||
}
|
||||
|
||||
go session.listen()
|
||||
@@ -34,33 +38,9 @@ func newSession(caddr *net.UDPAddr, raddr *net.UDPAddr, proxyConn *net.UDPConn)
|
||||
return session, nil
|
||||
}
|
||||
|
||||
func (s *Session) isRconRequestPacket(buf []byte) bool {
|
||||
return string(buf[:8]) == "\xff\xff\xff\xffrcon"
|
||||
}
|
||||
|
||||
func (s *Session) isQueryRequestPacket(buf []byte) bool {
|
||||
return string(buf[:13]) == "\xff\xff\xff\xffgetstatus" || string(buf[:11]) == "\xff\xff\xff\xffgetinfo"
|
||||
}
|
||||
|
||||
func (s *Session) isValidRequestPacket(buf []byte) bool {
|
||||
return s.isRconRequestPacket(buf) || s.isQueryRequestPacket(buf)
|
||||
}
|
||||
|
||||
func (s *Session) isRconResponsePacket(buf []byte) bool {
|
||||
return string(buf[:9]) == "\xff\xff\xff\xffprint"
|
||||
}
|
||||
|
||||
func (s *Session) isQueryResponsePacket(buf []byte) bool {
|
||||
return string(buf[:18]) == "\xff\xff\xff\xffstatusResponse" || string(buf[:16]) == "\xff\xff\xff\xffinfoResponse"
|
||||
}
|
||||
|
||||
func (s *Session) isValidResponsePacket(buf []byte) bool {
|
||||
return s.isRconResponsePacket(buf) || s.isQueryResponsePacket(buf)
|
||||
}
|
||||
|
||||
func (s *Session) listen() error {
|
||||
func (s *session) listen() error {
|
||||
buf := make([]byte, 2048)
|
||||
for {
|
||||
buf := make([]byte, 2048)
|
||||
n, err := s.serverConn.Read(buf)
|
||||
if err != nil {
|
||||
log.Error(err)
|
||||
@@ -71,7 +51,7 @@ func (s *Session) listen() error {
|
||||
}
|
||||
}
|
||||
|
||||
func (s *Session) proxyFrom(buf []byte) error {
|
||||
func (s *session) proxyFrom(buf []byte) error {
|
||||
if !s.isValidResponsePacket(buf) {
|
||||
err := errors.New("not a rcon or query response packet")
|
||||
log.Error(err.Error())
|
||||
@@ -86,16 +66,25 @@ func (s *Session) proxyFrom(buf []byte) error {
|
||||
}
|
||||
|
||||
if s.isRconResponsePacket(buf) {
|
||||
parts := strings.Split(string(buf[10:]), " ")
|
||||
log.Debugf("Response: %s", strings.Join(parts, " "))
|
||||
if s.isBadRconResponse(buf) {
|
||||
log.Infof("Response: Bad rcon from %s", s.caddr.IP)
|
||||
} else {
|
||||
log.Debugf("Response: %s", string(buf[len(s.rconResponseHeader):]))
|
||||
}
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
func (s *Session) proxyTo(buf []byte) error {
|
||||
func (s *session) proxyTo(buf []byte) error {
|
||||
if !s.isValidRequestPacket(buf) {
|
||||
err := errors.New("not a rcon or query request packet")
|
||||
var err error
|
||||
if s.isChallengeRequestPacket(buf) {
|
||||
parts := strings.SplitN(string(buf), " ", 3)
|
||||
err = fmt.Errorf("invalid challenge from %s with GUID: %s", s.caddr.IP, parts[len(parts)-1])
|
||||
} else {
|
||||
err = errors.New("not a rcon or query request packet")
|
||||
}
|
||||
log.Error(err.Error())
|
||||
return err
|
||||
}
|
||||
@@ -108,8 +97,8 @@ func (s *Session) proxyTo(buf []byte) error {
|
||||
}
|
||||
|
||||
if s.isRconRequestPacket(buf) {
|
||||
parts := strings.Split(string(buf), " ")
|
||||
log.Infof("From [%s] To [%s] Command: %s", s.caddr.IP.String(), s.serverConn.RemoteAddr().String(), strings.Join(parts[2:], " "))
|
||||
parts := strings.SplitN(string(buf), " ", 3)
|
||||
log.Infof("From [%s] To [%s] Command: %s", s.caddr.IP, s.serverConn.RemoteAddr(), parts[len(parts)-1])
|
||||
}
|
||||
|
||||
return nil
|
||||
|
||||
@@ -8,6 +8,21 @@ import (
|
||||
log "github.com/sirupsen/logrus"
|
||||
)
|
||||
|
||||
// Option is a functional option type that allows us to configure the Client.
|
||||
type Option func(*Client)
|
||||
|
||||
// WithStaleTimeout is a functional option to set the stale session timeout
|
||||
func WithStaleTimeout(timeout time.Duration) Option {
|
||||
return func(c *Client) {
|
||||
if timeout < time.Minute {
|
||||
log.Warnf("cannot set stale session timeout to less than 1 minute.. defaulting to 5 minutes")
|
||||
return
|
||||
}
|
||||
|
||||
c.timeout = timeout
|
||||
}
|
||||
}
|
||||
|
||||
type Client struct {
|
||||
laddr *net.UDPAddr
|
||||
raddr *net.UDPAddr
|
||||
@@ -15,10 +30,12 @@ type Client struct {
|
||||
proxyConn *net.UDPConn
|
||||
|
||||
mutex sync.RWMutex
|
||||
sessions map[string]*Session
|
||||
sessions map[string]*session
|
||||
|
||||
timeout time.Duration
|
||||
}
|
||||
|
||||
func New(port, target string) (*Client, error) {
|
||||
func New(port, target string, options ...Option) (*Client, error) {
|
||||
laddr, err := net.ResolveUDPAddr("udp", port)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
@@ -29,12 +46,19 @@ func New(port, target string) (*Client, error) {
|
||||
return nil, err
|
||||
}
|
||||
|
||||
return &Client{
|
||||
c := &Client{
|
||||
laddr: laddr,
|
||||
raddr: raddr,
|
||||
mutex: sync.RWMutex{},
|
||||
sessions: map[string]*Session{},
|
||||
}, nil
|
||||
sessions: map[string]*session{},
|
||||
timeout: 5 * time.Minute,
|
||||
}
|
||||
|
||||
for _, o := range options {
|
||||
o(c)
|
||||
}
|
||||
|
||||
return c, nil
|
||||
}
|
||||
|
||||
func (c *Client) ListenAndServe() error {
|
||||
@@ -46,15 +70,15 @@ func (c *Client) ListenAndServe() error {
|
||||
|
||||
go c.pruneSessions()
|
||||
|
||||
buf := make([]byte, 2048)
|
||||
for {
|
||||
buf := make([]byte, 2048)
|
||||
n, caddr, err := c.proxyConn.ReadFromUDP(buf)
|
||||
if err != nil {
|
||||
log.Error(err)
|
||||
}
|
||||
|
||||
session, found := c.sessions[caddr.String()]
|
||||
if !found {
|
||||
session, ok := c.sessions[caddr.String()]
|
||||
if !ok {
|
||||
session, err = newSession(caddr, c.raddr, c.proxyConn)
|
||||
if err != nil {
|
||||
log.Error(err)
|
||||
@@ -76,8 +100,9 @@ func (c *Client) pruneSessions() {
|
||||
for range ticker.C {
|
||||
for _, session := range c.sessions {
|
||||
c.mutex.RLock()
|
||||
if time.Since(session.updateTime) > time.Minute*5 {
|
||||
if time.Since(session.updateTime) > c.timeout {
|
||||
delete(c.sessions, session.caddr.String())
|
||||
log.Tracef("session for %s deleted", session.caddr)
|
||||
}
|
||||
c.mutex.RUnlock()
|
||||
}
|
||||
|
||||
65
pkg/udpproxy/validator.go
Normal file
65
pkg/udpproxy/validator.go
Normal file
@@ -0,0 +1,65 @@
|
||||
package udpproxy
|
||||
|
||||
import "bytes"
|
||||
|
||||
type validator struct {
|
||||
rconRequestHeader []byte
|
||||
getstatusRequestHeader []byte
|
||||
getinfoRequestHeader []byte
|
||||
getchallengeRequestHeader []byte
|
||||
rconResponseHeader []byte
|
||||
getstatusResponseHeader []byte
|
||||
getinfoResponseHeader []byte
|
||||
badRconIdentifier []byte
|
||||
}
|
||||
|
||||
func newValidator() validator {
|
||||
return validator{
|
||||
rconRequestHeader: []byte("\xff\xff\xff\xffrcon"),
|
||||
getstatusRequestHeader: []byte("\xff\xff\xff\xffgetstatus"),
|
||||
getinfoRequestHeader: []byte("\xff\xff\xff\xffgetinfo"),
|
||||
getchallengeRequestHeader: []byte("\xff\xff\xff\xffgetchallenge"),
|
||||
rconResponseHeader: []byte("\xff\xff\xff\xffprint\n"),
|
||||
getstatusResponseHeader: []byte("\xff\xff\xff\xffstatusResponse\n"),
|
||||
getinfoResponseHeader: []byte("\xff\xff\xff\xffinfoResponse\n"),
|
||||
badRconIdentifier: []byte("Bad rcon"),
|
||||
}
|
||||
}
|
||||
|
||||
func (v validator) compare(buf, c []byte) bool {
|
||||
return bytes.Equal(buf[:len(c)], c)
|
||||
}
|
||||
|
||||
func (v validator) isRconRequestPacket(buf []byte) bool {
|
||||
return v.compare(buf, v.rconRequestHeader)
|
||||
}
|
||||
|
||||
func (v validator) isQueryRequestPacket(buf []byte) bool {
|
||||
return v.compare(buf, v.getstatusRequestHeader) ||
|
||||
v.compare(buf, v.getinfoRequestHeader)
|
||||
}
|
||||
|
||||
func (v validator) isValidRequestPacket(buf []byte) bool {
|
||||
return v.isRconRequestPacket(buf) || v.isQueryRequestPacket(buf)
|
||||
}
|
||||
|
||||
func (v validator) isChallengeRequestPacket(buf []byte) bool {
|
||||
return v.compare(buf, v.getchallengeRequestHeader)
|
||||
}
|
||||
|
||||
func (v validator) isRconResponsePacket(buf []byte) bool {
|
||||
return v.compare(buf, v.rconResponseHeader)
|
||||
}
|
||||
|
||||
func (v validator) isQueryResponsePacket(buf []byte) bool {
|
||||
return v.compare(buf, v.getstatusResponseHeader) ||
|
||||
v.compare(buf, v.getinfoResponseHeader)
|
||||
}
|
||||
|
||||
func (v validator) isValidResponsePacket(buf []byte) bool {
|
||||
return v.isRconResponsePacket(buf) || v.isQueryResponsePacket(buf)
|
||||
}
|
||||
|
||||
func (v validator) isBadRconResponse(buf []byte) bool {
|
||||
return v.compare(buf[len(v.rconResponseHeader):], v.badRconIdentifier)
|
||||
}
|
||||
Reference in New Issue
Block a user