Initial commit: Null DRM Official
Capture, decrypt, and restream toolkit with compiled-in app modules (RTE, TG4, BBC), on-device MITM proxy, streamd control plane, and www. BBC module.yaml is published (clear streams); other module values stay local.
This commit is contained in:
commit
2fa8f2435f
121 changed files with 17802 additions and 0 deletions
81
apps/proxy/device/tproxy_iptables.sh
Normal file
81
apps/proxy/device/tproxy_iptables.sh
Normal file
|
|
@ -0,0 +1,81 @@
|
|||
#!/system/bin/sh
|
||||
# Transparent redirect: package UID TCP/443 → local appproxy (no Wi‑Fi http_proxy).
|
||||
# Usage:
|
||||
# tproxy_iptables.sh start <package> [port]
|
||||
# tproxy_iptables.sh stop
|
||||
# tproxy_iptables.sh status
|
||||
|
||||
set -eu
|
||||
CHAIN=APPROXY_TPROXY
|
||||
ACTION="${1:-}"
|
||||
|
||||
uid_for_package() {
|
||||
pkg="$1"
|
||||
# dumpsys package <pkg> | grep userId= OR stat on data dir
|
||||
uid=$(dumpsys package "$pkg" 2>/dev/null | grep -m1 -oE 'userId=[0-9]+' | head -1 | cut -d= -f2 || true)
|
||||
if [ -z "$uid" ]; then
|
||||
uid=$(stat -c %u "/data/user/0/$pkg" 2>/dev/null || true)
|
||||
fi
|
||||
echo "$uid"
|
||||
}
|
||||
|
||||
stop_rules() {
|
||||
iptables -t nat -D OUTPUT -j "$CHAIN" 2>/dev/null || true
|
||||
iptables -t nat -F "$CHAIN" 2>/dev/null || true
|
||||
iptables -t nat -X "$CHAIN" 2>/dev/null || true
|
||||
echo "STOPPED"
|
||||
}
|
||||
|
||||
start_rules() {
|
||||
pkg="$1"
|
||||
port="$2"
|
||||
uid=$(uid_for_package "$pkg")
|
||||
if [ -z "$uid" ] || [ "$uid" = "0" ]; then
|
||||
echo "ERR: cannot resolve uid for package $pkg" >&2
|
||||
exit 1
|
||||
fi
|
||||
proxy_uid=$(stat -c %u /data/local/tmp/appproxy 2>/dev/null || echo "")
|
||||
# Prefer the running process uid if available
|
||||
if pidof appproxy >/dev/null 2>&1; then
|
||||
proxy_uid=$(stat -c %u /proc/$(pidof appproxy | awk '{print $1}') 2>/dev/null || echo "$proxy_uid")
|
||||
fi
|
||||
|
||||
stop_rules >/dev/null
|
||||
iptables -t nat -N "$CHAIN"
|
||||
# Never redirect the mitm itself (loop).
|
||||
if [ -n "$proxy_uid" ]; then
|
||||
iptables -t nat -A "$CHAIN" -m owner --uid-owner "$proxy_uid" -j RETURN
|
||||
fi
|
||||
# Skip localhost / link-local.
|
||||
iptables -t nat -A "$CHAIN" -d 127.0.0.0/8 -j RETURN
|
||||
iptables -t nat -A "$CHAIN" -d 10.0.0.0/8 -j RETURN 2>/dev/null || true
|
||||
# Redirect only the target app's HTTPS.
|
||||
iptables -t nat -A "$CHAIN" -p tcp -m owner --uid-owner "$uid" --dport 443 -j REDIRECT --to-ports "$port"
|
||||
iptables -t nat -A OUTPUT -j "$CHAIN"
|
||||
echo "STARTED pkg=$pkg uid=$uid port=$port proxy_uid=${proxy_uid:-unknown}"
|
||||
}
|
||||
|
||||
status_rules() {
|
||||
echo "=== $CHAIN ==="
|
||||
iptables -t nat -L "$CHAIN" -n -v 2>/dev/null || echo "(no chain)"
|
||||
echo "=== OUTPUT head ==="
|
||||
iptables -t nat -L OUTPUT -n -v 2>/dev/null | head -20
|
||||
}
|
||||
|
||||
case "$ACTION" in
|
||||
start)
|
||||
pkg="${2:?package required}"
|
||||
port="${3:-8080}"
|
||||
start_rules "$pkg" "$port"
|
||||
;;
|
||||
stop)
|
||||
stop_rules
|
||||
;;
|
||||
status)
|
||||
status_rules
|
||||
;;
|
||||
*)
|
||||
echo "usage: $0 start <package> [port] | stop | status" >&2
|
||||
exit 2
|
||||
;;
|
||||
esac
|
||||
Loading…
Add table
Add a link
Reference in a new issue