#!/system/bin/sh # Transparent redirect: package UID TCP/443 → local appproxy (no Wi‑Fi http_proxy). # Usage: # tproxy_iptables.sh start [port] # tproxy_iptables.sh stop # tproxy_iptables.sh status set -eu CHAIN=APPROXY_TPROXY ACTION="${1:-}" uid_for_package() { pkg="$1" # dumpsys package | grep userId= OR stat on data dir uid=$(dumpsys package "$pkg" 2>/dev/null | grep -m1 -oE 'userId=[0-9]+' | head -1 | cut -d= -f2 || true) if [ -z "$uid" ]; then uid=$(stat -c %u "/data/user/0/$pkg" 2>/dev/null || true) fi echo "$uid" } stop_rules() { iptables -t nat -D OUTPUT -j "$CHAIN" 2>/dev/null || true iptables -t nat -F "$CHAIN" 2>/dev/null || true iptables -t nat -X "$CHAIN" 2>/dev/null || true echo "STOPPED" } start_rules() { pkg="$1" port="$2" uid=$(uid_for_package "$pkg") if [ -z "$uid" ] || [ "$uid" = "0" ]; then echo "ERR: cannot resolve uid for package $pkg" >&2 exit 1 fi proxy_uid=$(stat -c %u /data/local/tmp/appproxy 2>/dev/null || echo "") # Prefer the running process uid if available if pidof appproxy >/dev/null 2>&1; then proxy_uid=$(stat -c %u /proc/$(pidof appproxy | awk '{print $1}') 2>/dev/null || echo "$proxy_uid") fi stop_rules >/dev/null iptables -t nat -N "$CHAIN" # Never redirect the mitm itself (loop). if [ -n "$proxy_uid" ]; then iptables -t nat -A "$CHAIN" -m owner --uid-owner "$proxy_uid" -j RETURN fi # Skip localhost / link-local. iptables -t nat -A "$CHAIN" -d 127.0.0.0/8 -j RETURN iptables -t nat -A "$CHAIN" -d 10.0.0.0/8 -j RETURN 2>/dev/null || true # Redirect only the target app's HTTPS. iptables -t nat -A "$CHAIN" -p tcp -m owner --uid-owner "$uid" --dport 443 -j REDIRECT --to-ports "$port" iptables -t nat -A OUTPUT -j "$CHAIN" echo "STARTED pkg=$pkg uid=$uid port=$port proxy_uid=${proxy_uid:-unknown}" } status_rules() { echo "=== $CHAIN ===" iptables -t nat -L "$CHAIN" -n -v 2>/dev/null || echo "(no chain)" echo "=== OUTPUT head ===" iptables -t nat -L OUTPUT -n -v 2>/dev/null | head -20 } case "$ACTION" in start) pkg="${2:?package required}" port="${3:-8080}" start_rules "$pkg" "$port" ;; stop) stop_rules ;; status) status_rules ;; *) echo "usage: $0 start [port] | stop | status" >&2 exit 2 ;; esac