Capture, decrypt, and restream toolkit with compiled-in app modules (RTE, TG4, BBC), on-device MITM proxy, streamd control plane, and www. BBC module.yaml is published (clear streams); other module values stay local.
81 lines
2.3 KiB
Bash
81 lines
2.3 KiB
Bash
#!/system/bin/sh
|
||
# Transparent redirect: package UID TCP/443 → local appproxy (no Wi‑Fi http_proxy).
|
||
# Usage:
|
||
# tproxy_iptables.sh start <package> [port]
|
||
# tproxy_iptables.sh stop
|
||
# tproxy_iptables.sh status
|
||
|
||
set -eu
|
||
CHAIN=APPROXY_TPROXY
|
||
ACTION="${1:-}"
|
||
|
||
uid_for_package() {
|
||
pkg="$1"
|
||
# dumpsys package <pkg> | grep userId= OR stat on data dir
|
||
uid=$(dumpsys package "$pkg" 2>/dev/null | grep -m1 -oE 'userId=[0-9]+' | head -1 | cut -d= -f2 || true)
|
||
if [ -z "$uid" ]; then
|
||
uid=$(stat -c %u "/data/user/0/$pkg" 2>/dev/null || true)
|
||
fi
|
||
echo "$uid"
|
||
}
|
||
|
||
stop_rules() {
|
||
iptables -t nat -D OUTPUT -j "$CHAIN" 2>/dev/null || true
|
||
iptables -t nat -F "$CHAIN" 2>/dev/null || true
|
||
iptables -t nat -X "$CHAIN" 2>/dev/null || true
|
||
echo "STOPPED"
|
||
}
|
||
|
||
start_rules() {
|
||
pkg="$1"
|
||
port="$2"
|
||
uid=$(uid_for_package "$pkg")
|
||
if [ -z "$uid" ] || [ "$uid" = "0" ]; then
|
||
echo "ERR: cannot resolve uid for package $pkg" >&2
|
||
exit 1
|
||
fi
|
||
proxy_uid=$(stat -c %u /data/local/tmp/appproxy 2>/dev/null || echo "")
|
||
# Prefer the running process uid if available
|
||
if pidof appproxy >/dev/null 2>&1; then
|
||
proxy_uid=$(stat -c %u /proc/$(pidof appproxy | awk '{print $1}') 2>/dev/null || echo "$proxy_uid")
|
||
fi
|
||
|
||
stop_rules >/dev/null
|
||
iptables -t nat -N "$CHAIN"
|
||
# Never redirect the mitm itself (loop).
|
||
if [ -n "$proxy_uid" ]; then
|
||
iptables -t nat -A "$CHAIN" -m owner --uid-owner "$proxy_uid" -j RETURN
|
||
fi
|
||
# Skip localhost / link-local.
|
||
iptables -t nat -A "$CHAIN" -d 127.0.0.0/8 -j RETURN
|
||
iptables -t nat -A "$CHAIN" -d 10.0.0.0/8 -j RETURN 2>/dev/null || true
|
||
# Redirect only the target app's HTTPS.
|
||
iptables -t nat -A "$CHAIN" -p tcp -m owner --uid-owner "$uid" --dport 443 -j REDIRECT --to-ports "$port"
|
||
iptables -t nat -A OUTPUT -j "$CHAIN"
|
||
echo "STARTED pkg=$pkg uid=$uid port=$port proxy_uid=${proxy_uid:-unknown}"
|
||
}
|
||
|
||
status_rules() {
|
||
echo "=== $CHAIN ==="
|
||
iptables -t nat -L "$CHAIN" -n -v 2>/dev/null || echo "(no chain)"
|
||
echo "=== OUTPUT head ==="
|
||
iptables -t nat -L OUTPUT -n -v 2>/dev/null | head -20
|
||
}
|
||
|
||
case "$ACTION" in
|
||
start)
|
||
pkg="${2:?package required}"
|
||
port="${3:-8080}"
|
||
start_rules "$pkg" "$port"
|
||
;;
|
||
stop)
|
||
stop_rules
|
||
;;
|
||
status)
|
||
status_rules
|
||
;;
|
||
*)
|
||
echo "usage: $0 start <package> [port] | stop | status" >&2
|
||
exit 2
|
||
;;
|
||
esac
|