CellGuard: LTE/5G-NR lock + IMSI-catcher detection KSU module
- cgcap.ko: cpif CP-frame capture via kprobe/kallsyms, stock-GKI build - ratlock.sh: hold modem to LTE+NR(5G), block 2G/3G downgrade - cgdetect.sh: always-on behavioral cell-site-simulator detection - cgctl.sh + WebUI: block/detect toggles, status + alerts - build-stock-gki.sh: reproducible stock-GKI module build pipeline
This commit is contained in:
57
service.sh
Executable file
57
service.sh
Executable file
@@ -0,0 +1,57 @@
|
||||
#!/system/bin/sh
|
||||
# CellGuard — late service script
|
||||
#
|
||||
# Primary goal: (1) prevent cellular downgrade — hold the modem to LTE + 5G(NR)
|
||||
# only; (2) detect IMSI-catchers / cell-site simulators from the modem's own
|
||||
# CP<->AP diagnostic stream.
|
||||
#
|
||||
# On rango (Shannon S5400 / cpif, PCIe) there is NO raw-AT tty and no exposed
|
||||
# SIT command to inject, so:
|
||||
# * enforcement uses the platform telephony API (ratlock.sh)
|
||||
# * diagnostics use a kernel capture module (cgcap.ko) that taps every cpif
|
||||
# channel and exposes the raw frames at /proc/cgcap/frames
|
||||
# * decode + CSS heuristics run in userspace (tools/cg_decode.py)
|
||||
|
||||
MODDIR=${0%/*}
|
||||
CONFIG_DIR="/data/adb/cellguard"
|
||||
LOG="$CONFIG_DIR/cellguard.log"
|
||||
KMOD="$MODDIR/common/kmod/cgcap.ko"
|
||||
|
||||
mkdir -p "$CONFIG_DIR"
|
||||
log() { echo "[$(date '+%Y-%m-%d %H:%M:%S')] $1" >> "$LOG"; }
|
||||
|
||||
log "CellGuard service start"
|
||||
|
||||
# --- 1. diagnostics: load the CP-frame capture module ---
|
||||
if lsmod 2>/dev/null | grep -q '^cgcap '; then
|
||||
log "cgcap already loaded"
|
||||
elif [ -f "$KMOD" ]; then
|
||||
insmod "$KMOD" 2>>"$LOG" && log "cgcap.ko loaded (diag at /proc/cgcap/frames)" \
|
||||
|| log "cgcap.ko insmod FAILED — check dmesg (is cpif up?)"
|
||||
else
|
||||
log "cgcap.ko missing at $KMOD — build it first"
|
||||
fi
|
||||
|
||||
# --- 2. enforcement: hold every active SIM to LTE + 5G(NR) only ---
|
||||
# ratlock runs its own watchdog loop; launch once, in background.
|
||||
if ! pgrep -f "$MODDIR/ratlock.sh" >/dev/null 2>&1; then
|
||||
# wait briefly for RIL/subscriptions to come up after boot
|
||||
for i in $(seq 1 30); do
|
||||
[ -n "$(cmd phone get-allowed-network-types-for-users -s 0 2>/dev/null)$(cmd phone get-allowed-network-types-for-users -s 1 2>/dev/null)" ] && break
|
||||
sleep 1
|
||||
done
|
||||
nohup sh "$MODDIR/ratlock.sh" 5 >/dev/null 2>&1 &
|
||||
log "ratlock started (LTE+NR/5G enforcement watchdog)"
|
||||
else
|
||||
log "ratlock already running"
|
||||
fi
|
||||
|
||||
# --- 3. detection: always-on IMSI-catcher detector (independent of WebUI) ---
|
||||
if ! pgrep -f "$MODDIR/cgdetect.sh" >/dev/null 2>&1; then
|
||||
nohup sh "$MODDIR/cgdetect.sh" 4 >/dev/null 2>&1 &
|
||||
log "cgdetect started (always-on IMSI-catcher detector)"
|
||||
else
|
||||
log "cgdetect already running"
|
||||
fi
|
||||
|
||||
log "CellGuard service done"
|
||||
Reference in New Issue
Block a user