init
This commit is contained in:
@@ -28,6 +28,7 @@ from _common import (
|
||||
)
|
||||
from _domain_patch import parse_domain_list, patch_fixed_domains_in_dylib
|
||||
from _path_patch import patch_initial_daily_path
|
||||
from _scheme_patch import patch_deployment_scheme_to_http
|
||||
import _common
|
||||
|
||||
from coruna_netconfig_pipeline import (
|
||||
@@ -59,10 +60,11 @@ def obfuscate_coruna_7z_header(standard_7z: bytes) -> bytes:
|
||||
return bytes(out)
|
||||
|
||||
|
||||
# Match sample wires (source/sync/*.html): Method = LZMA2:13 7zAES:19.
|
||||
# py7zr defaults to LZMA2:24, which the client 7z extractor rejects (-1).
|
||||
# Sample wires use 7-Zip EncodedHeader shape (next_sz≈47, Headers Size=191).
|
||||
# py7zr writes a different EncodedHeader the client rejects as NO_ARCHIVE (17).
|
||||
# macOS `7z a <file>` embeds Unix mode bits (extract -1). `7z a -siNAME` does not.
|
||||
_7Z_PACK_FILTER = "LZMA2:a=0:d=8k"
|
||||
_7Z_CACHE_TAG = b"lzma2:13\0"
|
||||
_7Z_CACHE_TAG = b"lzma2:13-si\0"
|
||||
|
||||
|
||||
def _find_7z() -> str:
|
||||
@@ -71,15 +73,16 @@ def _find_7z() -> str:
|
||||
if path:
|
||||
return path
|
||||
raise SystemExit(
|
||||
"7z required to pack Coruna archives (LZMA2:13). Install p7zip."
|
||||
"7z required to pack Coruna archives (LZMA2:13 via -si). Install p7zip."
|
||||
)
|
||||
|
||||
|
||||
def make_passworded_7z(member_name: str, payload: bytes, password: str) -> bytes:
|
||||
"""Build passworded 7z with sample-compatible LZMA2:13; cache by content."""
|
||||
"""Build passworded 7z matching sample EncodedHeader/attrs; cache by content."""
|
||||
arc_name = Path(member_name).name
|
||||
cache_key = sha256_hex(
|
||||
_7Z_CACHE_TAG
|
||||
+ member_name.encode("utf-8")
|
||||
+ arc_name.encode("utf-8")
|
||||
+ b"\0"
|
||||
+ password.encode("utf-8")
|
||||
+ b"\0"
|
||||
@@ -92,12 +95,7 @@ def make_passworded_7z(member_name: str, payload: bytes, password: str) -> bytes
|
||||
|
||||
seven = _find_7z()
|
||||
with tempfile.TemporaryDirectory() as tmp:
|
||||
root = Path(tmp)
|
||||
# Keep archive member name flat (basename only) like original wires.
|
||||
arc_name = Path(member_name).name
|
||||
member = root / arc_name
|
||||
member.write_bytes(payload)
|
||||
archive = root / "out.7z"
|
||||
archive = Path(tmp) / "out.7z"
|
||||
cmd = [
|
||||
seven,
|
||||
"a",
|
||||
@@ -105,17 +103,17 @@ def make_passworded_7z(member_name: str, payload: bytes, password: str) -> bytes
|
||||
f"-m0={_7Z_PACK_FILTER}",
|
||||
"-mhe=on",
|
||||
f"-p{password}",
|
||||
f"-si{arc_name}",
|
||||
"-y",
|
||||
"-bso0",
|
||||
"-bsp0",
|
||||
str(archive),
|
||||
str(member),
|
||||
]
|
||||
proc = subprocess.run(cmd, capture_output=True, text=True)
|
||||
proc = subprocess.run(cmd, input=payload, capture_output=True)
|
||||
if proc.returncode != 0 or not archive.is_file():
|
||||
detail = (proc.stderr or proc.stdout or "").strip()
|
||||
detail = (proc.stderr or proc.stdout or b"").decode("utf-8", "replace").strip()
|
||||
raise RuntimeError(
|
||||
f"7z pack failed (code {proc.returncode}): {detail or 'no output'}"
|
||||
f"7z -si pack failed (code {proc.returncode}): {detail or 'no output'}"
|
||||
)
|
||||
data = archive.read_bytes()
|
||||
|
||||
@@ -317,6 +315,10 @@ def main() -> int:
|
||||
reporting_seed=rep,
|
||||
label=label,
|
||||
)
|
||||
# Fat arm64+arm64e: 2× https://%@ → http://%@/ for lab cleartext proxy.
|
||||
data = patch_deployment_scheme_to_http(
|
||||
data, expect_hits=2, label=label
|
||||
)
|
||||
|
||||
if expect > 0:
|
||||
data = patch_module_channel(
|
||||
|
||||
Reference in New Issue
Block a user