Initial commit: Null DRM Official

Capture, decrypt, and restream toolkit with compiled-in app modules
(RTE, TG4, BBC), on-device MITM proxy, streamd control plane, and www.
BBC module.yaml is published (clear streams); other module values stay local.
This commit is contained in:
404errordeveloper 2026-10-06 00:25:35 +02:00
commit 2fa8f2435f
121 changed files with 17802 additions and 0 deletions

102
apps/proxy/README.md Normal file
View file

@ -0,0 +1,102 @@
# proxy — on-device HTTPS MITM (appproxy)
Host CLI plus the Android binary that MITMs phone HTTPS, so a capture can see
license URLs, manifests and auth headers.
```text
apps/proxy/
proxyctlcmd/ host CLI, hosted by bin/drm as `drm proxy`
device/ linux/arm64 MITM source (module: appproxy)
rteproxy-ca.crt MITM CA (subject hash 6c3578b4)
```
The process name on the phone is **`appproxy`**. Some on-disk names still say
`rteproxy-*`, and those paths are still read, so an already-provisioned phone keeps
working.
## Build
```bash
go -C apps/cli build -o ../../bin/drm . # host CLI
./bin/drm proxy build # cross-compile the device binary
```
`proxy build` compiles `device/` for linux/arm64 into
`apps/proxy/proxy-android-arm64` and copies it to `bin/proxy-android-arm64`.
## Use
```bash
# trust the MITM CA (needs Magisk; mounts into the system store)
./bin/drm proxy install-ca --reinject
./bin/drm proxy reinject-ca # mount only, CA already pushed
# structured capture proxy
./bin/drm proxy start --install-ca --reinject
./bin/drm proxy stop
# record everything while you explore an unknown app
./bin/drm proxy discover --install-ca --reinject
./bin/drm proxy discover --force-stop <package> # so it inherits the CA mount
# pull artifacts without re-running, and release the phone
./bin/drm proxy pull
./bin/drm proxy clear-proxy
```
Always clear the proxy when done, or the phone keeps pointing at a dead listener.
### Transparent mode (UK VPN OK — no Wi‑Fi HTTP proxy)
Root `iptables` redirects only one app’s TCP/443 into on-device `appproxy`. The
phone can stay on NordVPN UK; nothing sets `http_proxy`.
```bash
# leave UK VPN connected on the phone, then:
./bin/drm proxy transparent --package bbc.iplayer.android --reinject
# open the app / play — Ctrl+C stops iptables and pulls files
```
Writes on device (adb-readable):
```text
/data/local/tmp/capture/<package>/cap.json
/data/local/tmp/capture/<package>/traffic.jsonl
/data/local/tmp/capture/<package>/appproxy.log
```
Pull anytime:
```bash
adb pull /data/local/tmp/capture/bbc.iplayer.android ./bbc-cap
```
Force-stop the target app once after CA reinject so it inherits the Magisk CA mount.
The device binary cannot read an app module's values file, so a module's
manifest-scoring hosts are passed to it as flags (`--match`, `--score-host`,
`--score-deny`). `drm capture` does this automatically.
## Artifacts
| File | What |
|---|---|
| `appproxy_traffic.jsonl` / `traffic.jsonl` | every HTTP(S) request/response (discover / transparent) |
| `appproxy_cap.json` / `cap.json` | structured mpd / license / auth / pssh when detected |
| `appproxy.log` | tagged lines: `[MPD]` `[LIC]` `[PSSH]` `[MAN]` `[TPROXY]` |
Pulled into `outputs/discover/<stamp>/` or `outputs/transparent/<stamp>/`.
## Device paths
| Remote | Role |
|---|---|
| `/data/local/tmp/appproxy` | binary |
| `/data/local/tmp/appproxy_cap.json` | structured capture (proxy mode) |
| `/data/local/tmp/capture/<pkg>/` | transparent out-dir (cap + traffic + log) |
| `/data/local/tmp/tproxy_iptables.sh` | UID REDIRECT helper |
| `/data/local/tmp/6c3578b4.0` | system CA hash file |
| Wi‑Fi `http_proxy` | used only in classic proxy mode — **not** in transparent mode |
**Full guide: [docs/capture.md](../../docs/capture.md)** — CA troubleshooting and how
to mine a discover dump.