Null-DRM-Official/apps/proxy/device/tproxy_iptables.sh
404errordeveloper 2fa8f2435f Initial commit: Null DRM Official
Capture, decrypt, and restream toolkit with compiled-in app modules
(RTE, TG4, BBC), on-device MITM proxy, streamd control plane, and www.
BBC module.yaml is published (clear streams); other module values stay local.
2026-10-06 00:25:35 +02:00

81 lines
2.3 KiB
Bash
Raw Permalink Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

#!/system/bin/sh
# Transparent redirect: package UID TCP/443 → local appproxy (no Wi‑Fi http_proxy).
# Usage:
# tproxy_iptables.sh start <package> [port]
# tproxy_iptables.sh stop
# tproxy_iptables.sh status
set -eu
CHAIN=APPROXY_TPROXY
ACTION="${1:-}"
uid_for_package() {
pkg="$1"
# dumpsys package <pkg> | grep userId= OR stat on data dir
uid=$(dumpsys package "$pkg" 2>/dev/null | grep -m1 -oE 'userId=[0-9]+' | head -1 | cut -d= -f2 || true)
if [ -z "$uid" ]; then
uid=$(stat -c %u "/data/user/0/$pkg" 2>/dev/null || true)
fi
echo "$uid"
}
stop_rules() {
iptables -t nat -D OUTPUT -j "$CHAIN" 2>/dev/null || true
iptables -t nat -F "$CHAIN" 2>/dev/null || true
iptables -t nat -X "$CHAIN" 2>/dev/null || true
echo "STOPPED"
}
start_rules() {
pkg="$1"
port="$2"
uid=$(uid_for_package "$pkg")
if [ -z "$uid" ] || [ "$uid" = "0" ]; then
echo "ERR: cannot resolve uid for package $pkg" >&2
exit 1
fi
proxy_uid=$(stat -c %u /data/local/tmp/appproxy 2>/dev/null || echo "")
# Prefer the running process uid if available
if pidof appproxy >/dev/null 2>&1; then
proxy_uid=$(stat -c %u /proc/$(pidof appproxy | awk '{print $1}') 2>/dev/null || echo "$proxy_uid")
fi
stop_rules >/dev/null
iptables -t nat -N "$CHAIN"
# Never redirect the mitm itself (loop).
if [ -n "$proxy_uid" ]; then
iptables -t nat -A "$CHAIN" -m owner --uid-owner "$proxy_uid" -j RETURN
fi
# Skip localhost / link-local.
iptables -t nat -A "$CHAIN" -d 127.0.0.0/8 -j RETURN
iptables -t nat -A "$CHAIN" -d 10.0.0.0/8 -j RETURN 2>/dev/null || true
# Redirect only the target app's HTTPS.
iptables -t nat -A "$CHAIN" -p tcp -m owner --uid-owner "$uid" --dport 443 -j REDIRECT --to-ports "$port"
iptables -t nat -A OUTPUT -j "$CHAIN"
echo "STARTED pkg=$pkg uid=$uid port=$port proxy_uid=${proxy_uid:-unknown}"
}
status_rules() {
echo "=== $CHAIN ==="
iptables -t nat -L "$CHAIN" -n -v 2>/dev/null || echo "(no chain)"
echo "=== OUTPUT head ==="
iptables -t nat -L OUTPUT -n -v 2>/dev/null | head -20
}
case "$ACTION" in
start)
pkg="${2:?package required}"
port="${3:-8080}"
start_rules "$pkg" "$port"
;;
stop)
stop_rules
;;
status)
status_rules
;;
*)
echo "usage: $0 start <package> [port] | stop | status" >&2
exit 2
;;
esac