2
0
mirror of https://gitlab.com/Nanolx/NanoDroid synced 2024-10-31 09:20:23 +00:00
NanoDroid/patcher/CommonPatcher
2020-08-17 18:40:58 +02:00

660 lines
18 KiB
Bash

#!/sbin/sh
##########################################################################################
#
# NanoDroid Patcher (Haystack Frontend)
# by Nanolx
#
##########################################################################################
VERSION=22.6.90.99999999
##########################################################################################
# Generic Functions
##########################################################################################
show_banner () {
ui_print " "
ui_print "********************************"
ui_print " NanoDroid "
ui_print " Framework Patcher "
ui_print " Powered by DexPatcher "
ui_print " ${VERSION} "
ui_print "********************************"
ui_print " "
}
setup_environment () {
TMPDIR=/dev/tmp/install
APEX_LD=/system
export ANDROID_DATA=${TMPDIR}
export PATCHER_ADDOND_DATA=/data/adb/nanodroid_patcher
}
ui_print() {
${BOOTMODE} && echo "${1}" || \
echo -e "ui_print ${1}\nui_print" >> /proc/self/fd/${OUTFD}
}
is_mounted () {
if [ ! -z "$2" ]; then
cat /proc/mounts | grep $1 | grep $2, >/dev/null
else
cat /proc/mounts | grep $1 >/dev/null
fi
return $?
}
# taken from Magisk, with modifications for NanoDroid
mount_apex_loop () {
local number=0
local minorx=1
local loop
[ -e /dev/block/loop1 ] && minorx=$(stat -Lc '%T' /dev/block/loop1)
apex_mount="${1}"
mkdir -p "${apex_mount}"
echo " *** mount_apex_loop [apex_mount]: ${apex_mount}"
while [ ${number} -lt 64 ]; do
loop=/dev/block/loop${number}
[ -e ${loop} ] || mknod ${loop} b 7 $((number * minorx))
if losetup "${loop}" /apex/apex_payload.img 2>/dev/null; then
echo " *** mount_apex_loop [loop]: ${loop}"
if mount -text4 -oro,noatime "${loop}" "${apex_mount}"; then
rm -f /apex/apex_payload.img
break
fi
fi
number=$((number + 1))
done
}
# taken from Magisk, with modifications for NanoDroid
mount_apex () {
if ${BOOTMODE}; then
APEX_LD=/system/apex/com.android.runtime
else
APEX_LD=/apex/com.android.runtime
mkdir -p /apex
for apex in /system/apex/*; do
apex_mount="/apex/$(basename ${apex} .apex)"
apex_loop="/dev/loop_apex_$(basename ${apex} .apex)"
[ "${apex_mount}" == /apex/com.android.runtime.release ] && apex_mount=/apex/com.android.runtime
[ "${apex_mount}" == /apex/com.android.runtime.debug ] && apex_mount=/apex/com.android.runtime
if [ -f "${apex}" ]; then
unzip -oq "${apex}" apex_payload.img -d /apex
mount_apex_loop "${apex_mount}" || error "APEX loop setup failed!"
elif [ -d "${apex}" ]; then
mount -o bind "${apex}" "${apex_mount}"
fi
done
export ANDROID_RUNTIME_ROOT=/apex/com.android.runtime
export ANDROID_TZDATA_ROOT=/apex/com.android.tzdata
fi
echo " INFO: #10 [APEX_LD] ${APEX_LD}"
echo " INFO: #11 [APEX [ALL]] $(ls /system/apex/*.apex)"
}
# taken from Magisk, with minor modifications for NanoDroid
mount_partitions () {
DEVICE_AB=FALSE
VENDOR_COMPAT=FALSE
SYSTEM_AS_ROOT=FALSE
SLOT=$(grep_cmdline androidboot.slot_suffix)
echo " INFO: #1 [SLOT] ${SLOT}"
if [ -z ${SLOT} ]; then
SLOT=$(grep_cmdline androidboot.slot)
echo " INFO: #2 [SLOT] ${SLOT}"
if [ ! -z ${SLOT} ]; then
SLOT=_${SLOT}
echo " INFO: #3 [SLOT] ${SLOT}"
DEVICE_AB=TRUE
fi
fi
system_tmp=$(find /dev/block -type l -name system${SLOT} | head -n 1)
echo " INFO: #4 [system_tmp] ${system_tmp}"
SYSTEM_BLOCK=$(readlink -f ${system_tmp})
echo " INFO: #5 [SYSTEM_BLOCK] ${SYSTEM_BLOCK}"
is_mounted /data || mount /data || error "failed to mount /data!"
mount -o bind /dev/urandom /dev/random
! is_mounted /system && mount -o rw /system
! is_mounted /system && mount -o rw ${SYSTEM_BLOCK} /system
! is_mounted /system && error "failed to mount /system!"
if [ -f /system/init.rc ]; then
SYSTEM_AS_ROOT=true
[ -L /system_root ] && rm -f /system_root
mkdir /system_root 2>/dev/null
mount --move /system /system_root
mount -o bind /system_root/system /system
fi
vendor_tmp=$(find /dev/block -type l -name vendor${SLOT} | head -n 1)
echo " INFO: #6 [vendor_tmp] ${vendor_tmp}"
VENDOR_BLOCK=$(readlink -f ${vendor_tmp})
echo " INFO: #7 [VENDOR_BLOCK] ${VENDOR_BLOCK}"
! is_mounted /vendor && mount -o ro /vendor || mount -o ro ${VENDOR_BLOCK} /vendor
if [ -d /system/vendor ]; then
### XXX work-around required for some ROMs
VENDOR_COMPAT=TRUE
ln -sf /system/vendor /vendor >/dev/null
fi
echo " "
mount | awk '{print $1 " on " $3 " params: " $6}'
echo " "
echo " INFO: #8 [prop]"
ls -l /system/*.prop
export build_props=$(find /system /system_root /vendor -type f -name build.prop)
echo " INFO: #9 [build_props] ${build_props}"
[ -z "${build_props}" ] && error "failed to mount /system (unsupported A/B device?)"
[ -d /system/apex ] && mount_apex
}
umount_partitions () {
umount -l /system_root 2>/dev/null
umount -l /system 2>/dev/null
umount -l /vendor 2>/dev/null
umount -l /dev/random 2>/dev/null
mount | awk '/ \/apex/{print $3}' | while read apex_mount; do
umount -l "${apex_mount}" 2>/dev/null
done
mount | awk '/ \/apex/{print $1}' | while read apex_loop; do
losetup -d "${apex_loop}" 2>/dev/null
done
unset ANDROID_RUNTIME_ROOT
unset ANDROID_TZDATA_ROOT
unset BOOTCLASSPATH
rm -rf ${APEX_TMP}/apex
rm -rf /apex
}
error () {
ui_print " "
ui_print " !! ${@}"
ui_print " "
exit 1
}
set_perm () {
chown ${2}:${3} ${1} || error "failed change owner for ${1}"
chmod ${4} ${1} || error "failed to change mode for ${1}"
if [ ! -z "${5}" ]; then
chcon ${5} ${1} 2>/dev/null
else chcon 'u:object_r:system_file:s0' ${1} 2>/dev/null
fi
}
set_perm_recursive() {
find ${1} -type d 2>/dev/null | while read dir; do
set_perm ${dir} ${2} ${3} ${4} ${6}
done
find ${1} -type f 2>/dev/null | while read file; do
set_perm ${file} ${2} ${3} ${5} ${6}
done
}
set_perm_data () {
if [ "${1}" = "-r" ]; then
echo " perm: data [recursive] {${2}}"
set_perm_recursive ${2} 0 0 0755 0644
else
echo " perm: data [single] {${1}}"
set_perm ${1} 0 0 0644
fi
}
##########################################################################################
# Device Functions
##########################################################################################
detect_outfd () {
if [ -z $OUTFD ] || readlink /proc/$$/fd/$OUTFD | grep -q /tmp; then
# We will have to manually find out OUTFD
for FD in `ls /proc/$$/fd`; do
if readlink /proc/$$/fd/$FD | grep -q pipe; then
if ps | grep -v grep | grep -q " 3 $FD "; then
OUTFD=$FD
break
fi
fi
done
fi
}
detect_bootmode () {
[ -z $BOOTMODE ] && ps | grep zygote | grep -qv grep && BOOTMODE=true
[ -z $BOOTMODE ] && ps -A 2>/dev/null | grep zygote | grep -qv grep && BOOTMODE=true
[ -z $BOOTMODE ] && BOOTMODE=false
}
grep_prop() {
[ -f /vendor/build.prop ] && \
FILES="/system/build.prop /vendor/build.prop" || \
FILES="/system/build.prop"
sed -n "s/^${1}=//p" ${FILES} | head -n 1
}
grep_cmdline() {
local REGEX="s/^${1}=//p"
sed -E 's/ +/\n/g' /proc/cmdline | \
sed -n "${REGEX}" 2>/dev/null
}
detect_odex () {
SERVICES_JAR_DEX=$(unzip -lq /system/framework/services.jar | grep classes.dex)
if [ -n "$(find '/system/framework/' -name 'services.vdex')" ]; then
ROM_DEX_STATUS=VDEX
elif [ -n "$(find '/system/framework/' -name 'services.odex')" ]; then
ROM_DEX_STATUS=ODEX
else ROM_DEX_STATUS=UNKOWN
fi
[ "${SERVICES_JAR_DEX}" ] && ROM_DEX_STATUS=DEODEX
ui_print " "
ui_print " ++"
ui_print " ++ services.jar status: ${ROM_DEX_STATUS}"
ui_print " ++"
[ "${SDK_VERSION}" -gt 27 -a "${ROM_DEX_STATUS}" != "DEODEX" ] && \
error "Android 9 or newer is only supported on de-odexed ROMs currently"
}
detect_arch () {
ABI=$(grep_prop ro.product.cpu.abi | cut -c-3)
ABI2=$(grep_prop ro.product.cpu.abi2 | cut -c-3)
ABILONG=$(grep_prop ro.product.cpu.abi)
ARCH=arm
[ "$ABI" = "x86" ] && ARCH=x86
[ "$ABI2" = "x86" ] && ARCH=x86
[ "$ABILONG" = "arm64-v8a" ] && ARCH=arm64
[ "$ABILONG" = "x86_64" ] && ARCH=x86_64
case ${ARCH} in
arm | arm64 )
ZIPB=${BASEDIR}/zip.arm
FILE=${BASEDIR}/file.arm
if [ -f ${TMPDIR}/busybox.arm ]; then
BUSY=${TMPDIR}/busybox.arm
else BUSY=${BASEDIR}/busybox.arm
fi
;;
x86 | x86_64 )
ZIPB=${BASEDIR}/zip.x86
FILE=${BASEDIR}/file.x86
if [ -f ${TMPDIR}/busybox.x86 ]; then
BUSY=${TMPDIR}/busybox.x86
else BUSY=${BASEDIR}/busybox.x86
fi
;;
esac
V_EX=${BASEDIR}/vdexExtractor.${ARCH}
chmod 0755 ${BUSY}
rm -rf ${BASEDIR}/busybox
mkdir -p ${BASEDIR}/busybox
ln -sf ${BUSY} ${BASEDIR}/busybox/busybox
${BUSY} --install -s ${BASEDIR}/busybox/
export PATH="${BASEDIR}/busybox:/system/bin:/system/xbin"
DALVIKVM_BIN=$(ls -l ${APEX_LD}/bin/dalvikvm | awk '{print $NF}')
DALVIKVM_ARCH=$("${FILE}" -m "${BASEDIR}/magic.mgc" -L ${APEX_LD}/bin/dalvikvm)
case ${DALVIKVM_BIN} in
*dalvikvm32* )
export LD_LIBRARY_PATH="${APEX_LD}/lib:/system/lib:/vendor/lib:/system/vendor/lib:/product/lib:/system/product/lib"
;;
*dalvikvm64* )
export LD_LIBRARY_PATH="${APEX_LD}/lib64:/system/lib64:/vendor/lib64:/system/vendor/lib64:/product/lib64:/system/product/lib64"
;;
*dalvikvm* )
case ${DALVIKVM_ARCH} in
*32-bit* )
export LD_LIBRARY_PATH="${APEX_LD}/lib:/system/lib:/vendor/lib:/system/vendor/lib:/product/lib:/system/product/lib"
;;
*64-bit* )
export LD_LIBRARY_PATH="${APEX_LD}/lib64:/system/lib64:/vendor/lib64:/system/vendor/lib64:/product/lib64:/system/product/lib64"
;;
esac
;;
esac
if [ -f ${APEX_LD}/etc/ld.config.txt ]; then
export LD_CONFIG_FILE="${APEX_LD}/etc/ld.config.txt"
elif [ -f ${APEX_LD}/etc/ld.config.${SDK_VERSION}.txt ]; then
export LD_CONFIG_FILE="${APEX_LD}/etc/ld.config.${SDK_VERSION}.txt"
fi
echo " *** LD_CONFIG_FILE=${LD_CONFIG_FILE}"
ui_print " > device architecture: ${ARCH}"
}
detect_sdk () {
SDK_VERSION=$(grep_prop ro.build.version.sdk)
[ "${SDK_VERSION}" -gt 29 ] && \
error "Android versions beyond Android 10 are not yet supported"
[ "${SDK_VERSION}" -lt 16 ] && \
error "Android versions before Jelly Bean are not supported"
if [ "${SDK_VERSION}" -gt 25 ]; then
BAKSMALI="${BASEDIR}/baksmali_26.dex"
SMALI="${BASEDIR}/smali_26.dex"
elif [ "${SDK_VERSION}" -gt 23 ]; then
BAKSMALI="${BASEDIR}/baksmali_24.dex"
SMALI="${BASEDIR}/smali_24.dex"
else
BAKSMALI="${BASEDIR}/baksmali_19.dex"
SMALI="${BASEDIR}/smali_19.dex"
fi
if [ "${SDK_VERSION}" -gt 25 ]; then
DEXPATCHER="${BASEDIR}/dexpatcher_26.dex"
else DEXPATCHER="${BASEDIR}/dexpatcher_19.dex"
fi
PATCH_CORE="${BASEDIR}/core_services.jar.dex"
if [ "${SDK_VERSION}" -lt 24 ]; then
ui_print " > Android 4.1 - 6.0 (SDK ${SDK_VERSION}) detected"
PATCH_HOOK="${BASEDIR}/hook_4.1-6.0_services.jar.dex"
else
ui_print " > Android 7.0 - 10.0 (SDK ${SDK_VERSION}) detected"
PATCH_HOOK="${BASEDIR}/hook_7.0-10.0_services.jar.dex"
fi
[ "${SDK_VERSION}" -gt 21 ] && DEX_OPTS="--multi-dex-threaded"
}
##########################################################################################
# by @ale5000
##########################################################################################
check_fake_package_signature () {
PERMISSION=android.permission.FAKE_PACKAGE_SIGNATURE
PERMISSION_OD=$(echo -n "${PERMISSION}" | od -A n -t x1 | tr -d '\n' | sed -e 's/^ //g;s/ /00/g')
HAS_FAKESIGN=false
FW_RES_DIR="${TMPDIR}/framework-res"
if [ ! -f ${FW_RES_DIR}/AndroidManifest.xml ]; then
mkdir -p "${FW_RES_DIR}"
unzip -oq /system/framework/framework-res.apk -d "${FW_RES_DIR}"
fi
grep -qF "${PERMISSION}" "${FW_RES_DIR}/AndroidManifest.xml" && HAS_FAKESIGN=true
od -A n -t x1 "${FW_RES_DIR}/AndroidManifest.xml" | tr -d ' \n' | grep -qF "${PERMISSION_OD}" && HAS_FAKESIGN=true
${HAS_FAKESIGN} && return 0 || return 1
}
##########################################################################################
# Patcher Functions
##########################################################################################
setup_patcher () {
ui_print " > preparing environment"
rm -rf ${TMPDIR}
mkdir -p ${TMPDIR}
unzip -oq "${ZIP}" -d ${TMPDIR} || \
error "failed to prepare environment"
for bin in zip.arm zip.x86 \
vdexExtractor.arm vdexExtractor.x86 \
vdexExtractor.arm64 vdexExtractor.x86_64 \
file.arm file.x86; do
chmod 0755 "${BASEDIR}/${bin}" || \
error "failed to prepare environment"
done
mkdir -p /data/adb/
}
call_dalvikvm () {
if [[ -z "${ND_BOOTCLASSPATH}" ]]; then
DALVIKVM_OPTS=""
for jar in /system/framework/*.jar; do
ND_BOOTCLASSPATH="${jar}:${ND_BOOTCLASSPATH}"
done
for jar in /apex/*/javalib/*.jar; do
ND_BOOTCLASSPATH="${jar}:${ND_BOOTCLASSPATH}"
done
export BOOTCLASSPATH=${ND_BOOTCLASSPATH}
supported_opts=$(${APEX_LD}/bin/dalvikvm --help 2>&1)
[[ "${supported_opts}" == *\[no\]image-dex2oat* ]] && DALVIKVM_OPTS="${DALVIKVM_OPTS} -Xnoimage-dex2oat"
[[ "${supported_opts}" == *verbose:*gc* ]] && DALVIKVM_OPTS="${DALVIKVM_OPTS} -verbose:gc"
[[ "${supported_opts}" == *verbose:*jit* ]] && DALVIKVM_OPTS="${DALVIKVM_OPTS} -verbose:jit"
[[ "${supported_opts}" == *verbose:*jni* ]] && DALVIKVM_OPTS="${DALVIKVM_OPTS} -verbose:jni"
[[ "${supported_opts}" == *verbose:*class* ]] && DALVIKVM_OPTS="${DALVIKVM_OPTS} -verbose:class"
echo " *** BOOTCLASSPATH=${BOOTCLASSPATH}"
echo " *** DALVIKVM_OPTS=${DALVIKVM_OPTS}"
fi
${APEX_LD}/bin/dalvikvm -Xnoimage-dex2oat ${DALVIKVM_OPTS} "${@}"
}
deodex_vdex () {
ui_print " >> deodexing services.jar [VDEX]"
cp /system/framework/oat/${ARCH}/services.vdex \
${BASEDIR}/services.vdex || \
error "failed to copy services.vdex"
${V_EX} -i ${BASEDIR}/services.vdex \
--ignore-crc-error --debug=4 || \
error "failed to deodex services.vdex"
mv ${BASEDIR}/services.apk_classes.dex ${BASEDIR}/classes.dex || \
error "failed to deodex services.vdex"
${ZIPB} -j "${BASEDIR}/services.jar" \
"${BASEDIR}/classes.dex" || \
error "zip failed"
}
deodex_odex () {
ui_print " >> deodexing services.jar [ODEX]"
cp "/system/framework/oat/${ARCH}/services.odex" "${BASEDIR}"
# baksmali/smali options switches (version dependent)
if [ "${SDK_VERSION}" -lt 24 ]; then
MAIN=main
DEODEX="-x"
ASSEMBLE=
BOOTCLASSPATH="-c"
else
MAIN=Main
DEODEX="x"
ASSEMBLE="a"
BOOTCLASSPATH="-b"
CLASSPATHDIR="-d"
fi
ui_print " [1] baksmali services.odex"
call_dalvikvm \
-classpath "${BAKSMALI}" \
org.jf.baksmali.${MAIN} \
${DEODEX} \
${BOOTCLASSPATH} "/system/framework/${ARCH}/boot.oat" \
${CLASSPATHDIR} "/system/framework/${ARCH}" \
${CLASSPATHDIR} "/system/framework" \
-o "${BASEDIR}/services.jar-deodex" \
"${BASEDIR}/services.odex" || \
error "failed to deodex services.jar"
ui_print " [2] smali services.odex"
call_dalvikvm \
-classpath "${SMALI}" \
org.jf.smali.${MAIN} \
${ASSEMBLE} \
-o "${BASEDIR}/services.jar-deodex/classes.dex" \
"${BASEDIR}/services.jar-deodex" || \
error "failed to rebuild classes.dex"
${ZIPB} -j "${BASEDIR}/services.jar" \
"${BASEDIR}/services.jar-deodex"/classes*.dex || \
error "zip failed"
rm -rf "${BASEDIR}/services.jar-deodex"
}
patch_services () {
ui_print " "
ui_print " > patching signature spoofing support"
ui_print " "
cp /system/framework/services.jar \
${BASEDIR}/services.jar || \
error "failed to copy services.jar"
if [ "${ROM_DEX_STATUS}" = "VDEX" ]; then
deodex_vdex
elif [ "${ROM_DEX_STATUS}" = "ODEX" ]; then
deodex_odex
fi
mkdir -p "${BASEDIR}/services.jar-mod"
PATCHES="${PATCH_HOOK} ${PATCH_CORE}"
ui_print " >> patching services.jar"
call_dalvikvm \
-classpath "${DEXPATCHER}" \
lanchon.dexpatcher.Main \
${DEX_OPTS} --api-level "${SDK_VERSION}" \
--verbose --debug \
--output ${BASEDIR}/services.jar-mod \
${BASEDIR}/services.jar ${PATCHES} || \
error "failed to apply patches"
${ZIPB} -d "${BASEDIR}/services.jar" \
'classes*.dex' || \
error "zip failed"
${ZIPB} -j "${BASEDIR}/services.jar" \
"${BASEDIR}/services.jar-mod"/classes*.dex || \
error "zip failed"
}
backup_services_jar () {
ui_print " << backing up services.jar to: /data/media/0/nanodroid_backups"
services_name="services.jar_$(grep_prop ro.build.flavor)_$(grep_prop ro.build.id)"
mkdir -p /data/media/0/nanodroid_backups
cp /system/framework/services.jar "/data/media/0/nanodroid_backups/${services_name}" || \
error "failed to backup services.jar"
}
install_services () {
ui_print " "
for destination in /data/adb/modules/NanoDroid /data/adb/modules/NanoDroid_microG /; do
if [ -d ${destination} ]; then
install_path="${destination}"
break
fi
done
if [ "${install_path}" = "/" ]; then
mount -orw,remount /system || \
error "failed to mount /system read-write"
backup_services_jar
fi
ui_print " << installing patched files to: ${install_path}"
mkdir -p "${install_path}/system/framework"
cp ${BASEDIR}/services.jar "${install_path}/system/framework/" \
|| error "failed to install services.jar"
set_perm_data "${install_path}/system/framework/services.jar"
cp "${BASEDIR}/org.spoofing.apk" "${install_path}/system/framework/"
set_perm_data "${install_path}/system/framework/org.spoofing.apk"
touch /data/adb/NanoDroid_Patched
}
##########################################################################################
# addon.d
##########################################################################################
install_addond () {
ui_print " "
ui_print " Installing addon.d restoration setup"
rm -rf ${PATCHER_ADDOND_DATA}
mkdir -p ${PATCHER_ADDOND_DATA}
for file in core_services.jar.dex dexpatcher_19.dex dexpatcher_26.dex \
hook_4.1-6.0_services.jar.dex hook_7.0-10.0_services.jar.dex \
baksmali_19.dex baksmali_24.dex baksmali_26.dex \
smali_19.dex smali_24.dex smali_26.dex \
magic.mgc org.spoofing.apk; do
cp "${BASEDIR}/${file}" ${PATCHER_ADDOND_DATA}/
done
cp /dev/tmp/CommonPatcher ${PATCHER_ADDOND_DATA}/
for file in ${ZIPB} ${V_EX} ${BUSY} ${FILE}; do
cp ${file} ${PATCHER_ADDOND_DATA}/
chmod 0755 ${PATCHER_ADDOND_DATA}/$(basename "${file}")
done
mkdir -p /system/addon.d/
cp "${BASEDIR}/70-nanodroidpatcher.sh" /system/addon.d/
chmod 0755 /system/addon.d/70-nanodroidpatcher.sh
}