mirror of
https://git.churchofmalware.org/leviathan/OVERWATCH
synced 2026-09-24 08:35:03 +00:00
Adds a sixth source: police and surveillance aircraft overhead, via the free
community ADS-B networks (opendata.adsb.fi, api.adsb.lol fallback, no API
key). Contacts are matched by ICAO 24-bit address against a bundled registry
of 1,971 US law-enforcement airframes generated by scripts/gen-le-aircraft.py
from ADSBexchange's basic-ac-db and committed as res/raw/le_aircraft.csv.
Community feeds are used deliberately: FlightAware and Flightradar24 filter
law-enforcement flights at government request, which is the traffic this
source exists to see. Two parse traps handled — the envelope is {"ac":[..]}
on radius queries but {"aircraft":[..]} on wider ones, and alt_baro is the
string "ground" when parked.
Registry coverage is imperfect, so the scanner also detects loiter/orbit
behaviour (3+ samples over 4+ min within 5 km of their centroid, below
12,000 ft and under 200 kt). Surveillance aircraft circle; airliners and
medevac flights going somewhere do not. Behaviour-only hits are capped at 69
and must be within 8 km, so ordinary traffic never alerts.
Rejected with measurements: plane-alert-db matched 0 of 394 live aircraft
over a 250 nm sweep of DC while 15 helicopters were aloft (only 255 of its
entries are US-registered); registry.faa.gov is Akamai-403 and N-number
keyed; OpenSky's CSV is 94 MB for the same data; EFF's Atlas of Surveillance
has no aircraft identities at all, only a 2022 FAA drone lookup.
Overpass query widened from ALPR-only to man_made=surveillance plus
highway=speed_camera, classified into ALPR / speed camera / generic camera
with separate falloff curves so a shop's CCTV cannot alarm like a Flock
install. Cache key bumped to deflock2_ so v1 ALPR-only entries are not served
for another 24 h.
DeFlock, Waze and aircraft are now scored by continuous distance falloff
rather than flat values. The anchors are absolute metres and deliberately
independent of the detection-radius setting: moving a slider must not move
the threat level.
New SOURCES.md documents every endpoint, identifier and scoring table,
including the sources that were tried and rejected and the measurements that
killed them.
Verified against live traffic: detected San Diego PD's AS50 at 1580 m /
1000 ft scoring 83 (ORANGE) and a San Diego County Sheriff B407 at 11742 m
scoring 44, with the score tracking the helicopter from 81 to 83 as it
closed. Both match the falloff formula exactly.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RsfSpnwuxCkcXKkD9XH8SR
50 lines
2.5 KiB
Bash
Executable File
50 lines
2.5 KiB
Bash
Executable File
#!/bin/bash
|
|
# Feed a location to an Android emulator, for testing OVERWATCH's
|
|
# location-driven sources (DeFlock, Waze).
|
|
#
|
|
# scripts/emu-gps.sh <lat> <lon> [serial] [seconds]
|
|
# scripts/emu-gps.sh 38.8324 -77.1062 # Springfield VA, 120s
|
|
# scripts/emu-gps.sh 40.7128 -74.0060 emulator-5558 300
|
|
#
|
|
# Why not `adb emu geo fix`: it returns OK and frequently changes nothing.
|
|
# Verified 2026-09-16 on emulator 37.1.11.0 — a fresh AVD and a 2-day-old one
|
|
# both stayed pinned at a stale Northern California fix through dozens of
|
|
# `geo fix` calls and raw `geo nmea` sentences, every one answered OK. The
|
|
# same trap is recorded in the DUCAT project's notes. Android's own test
|
|
# provider bypasses the emulator console entirely and lands immediately.
|
|
#
|
|
# Two things have to be true or the app still sees nothing:
|
|
# 1. `appops set --uid 0` (NOT `--uid shell`, which fails with
|
|
# "uid 2000 not allowed to perform MOCK_LOCATION").
|
|
# 2. Something must actually engage the GPS provider. OVERWATCH requests
|
|
# PRIORITY_HIGH_ACCURACY, so starting a scan is enough; with a BALANCED
|
|
# request Play services parks the fused provider at ProviderRequest[OFF]
|
|
# and no fix is ever delivered.
|
|
#
|
|
# Note the argument orders differ between tools and it is easy to transpose:
|
|
# this script and `set-test-provider-location` take LAT,LON; `geo fix` takes
|
|
# LON first. Verify with:
|
|
# adb -s <serial> shell dumpsys location | grep -m1 "last location"
|
|
set -e
|
|
LAT=${1:?usage: emu-gps.sh <lat> <lon> [serial] [seconds]}
|
|
LON=${2:?usage: emu-gps.sh <lat> <lon> [serial] [seconds]}
|
|
SERIAL=${3:-emulator-5558}
|
|
SECONDS_TOTAL=${4:-120}
|
|
export PATH=$PATH:${ANDROID_HOME:-$HOME/Android/Sdk}/platform-tools
|
|
|
|
adb -s "$SERIAL" shell settings put secure location_mode 3 >/dev/null 2>&1 || true
|
|
adb -s "$SERIAL" shell appops set --uid 0 android:mock_location allow >/dev/null 2>&1 || true
|
|
adb -s "$SERIAL" shell cmd location providers add-test-provider gps >/dev/null 2>&1 || true
|
|
adb -s "$SERIAL" shell cmd location providers set-test-provider-enabled gps true >/dev/null 2>&1 || true
|
|
|
|
echo "feeding $LAT,$LON to $SERIAL for ${SECONDS_TOTAL}s (every 3s)…"
|
|
END=$((SECONDS + SECONDS_TOTAL))
|
|
while [ $SECONDS -lt $END ]; do
|
|
# A test-provider location is one-shot; re-send so it never ages out from
|
|
# under a scanner that only polls every few minutes.
|
|
adb -s "$SERIAL" shell cmd location providers set-test-provider-location gps \
|
|
--location "$LAT,$LON" >/dev/null 2>&1 || true
|
|
sleep 3
|
|
done
|
|
echo "done. verify: adb -s $SERIAL shell dumpsys location | grep -m1 'last location'"
|