#!/bin/bash
set -e
ISO_OUT="/home/workspace/nullframe-os/nullframe-os-1.0.0.iso"
WORK="/tmp/nullframe-build"
ISOPATH="/home/workspace/nullframe-os"

rm -rf "$WORK"
mkdir -p "$WORK"/{boot,rootfs}

echo "[+] Creating minimal rootfs..."
mkdir -p "$WORK/rootfs"/{bin,sbin,etc,proc,sys,dev,run,tmp,var,usr/{bin,sbin,lib},opt/nullframe/{wifi,ble,rf,network},boot,tmp,root}

# Use busybox for everything
ln -sf /bin/busybox "$WORK/rootfs/bin/sh"
ln -sf /bin/busybox "$WORK/rootfs/bin/ls"
ln -sf /bin/busybox "$WORK/rootfs/bin/cat"
ln -sf /bin/busybox "$WORK/rootfs/bin/echo"
ln -sf /bin/busybox "$WORK/rootfs/bin/mkdir"
ln -sf /bin/busybox "$WORK/rootfs/bin/mount"
ln -sf /bin/busybox "$WORK/rootfs/bin/umount"
ln -sf /bin/busybox "$WORK/rootfs/bin/ps"
ln -sf /bin/busybox "$WORK/rootfs/bin/kill"
ln -sf /bin/busybox "$WORK/rootfs/bin/sleep"
ln -sf /bin/busybox "$WORK/rootfs/bin/python3"

# Copy executables we need
cp /bin/busybox "$WORK/rootfs/bin/"
cp /bin/sh "$WORK/rootfs/bin/"

# Python for attack scripts
if [ -f /usr/bin/python3 ]; then
    cp /usr/bin/python3 "$WORK/rootfs/bin/"
fi

# Copy attack scripts
echo "[+] Installing attack tools..."
cp "$ISOPATH/tools/menu.sh" "$WORK/rootfs/opt/nullframe/"
mkdir -p "$WORK/rootfs/opt/nullframe/"{wifi,ble,rf,network}

cat > "$WORK/rootfs/opt/nullframe/wifi/monitor.sh" << 'WIFI'
#!/bin/sh
echo "╔══════════════════════════════════╗"
echo "║   WiFi Monitor Mode Enabler      ║"
echo "╚══════════════════════════════════╝"
echo "[*] Detecting wireless interfaces..."
ip link show 2>/dev/null | grep -E 'wlan|wl' || echo "[!] No wireless interface found"
echo "[*] Usage: airmon-ng start wlan0"
echo "[*] Then: airodump-ng wlan0mon"
WIFI

cat > "$WORK/rootfs/opt/nullframe/wifi/scan.sh" << 'SCAN'
#!/bin/sh
echo "╔══════════════════════════════════╗"
echo "║   WiFi Network Scanner           ║"
echo "╚══════════════════════════════════╝"
echo "[*] Place adapter in monitor mode first"
echo "[*] Run: airodump-ng wlan0mon"
SCAN

cat > "$WORK/rootfs/opt/nullframe/wifi/deauth.sh" << 'DEAUTH'
#!/bin/sh
echo "╔══════════════════════════════════╗"
echo "║   WiFi Deauth Attack              ║"
echo "╚══════════════════════════════════╝"
echo "[*] Usage: aireplay-ng --deauth 10 -a <BSSID> wlan0mon"
DEAUTH

cat > "$WORK/rootfs/opt/nullframe/ble/scan.sh" << 'BLE'
#!/bin/sh
echo "╔══════════════════════════════════╗"
echo "║   BLE Device Scanner              ║"
echo "╚══════════════════════════════════╝"
echo "[*] Scanning for BLE devices..."
hciconfig 2>/dev/null || echo "[!] No HCI interface"
hcitool lescan 2>/dev/null || echo "[*] Run: hciconfig hci0 up"
BLE

cat > "$WORK/rootfs/opt/nullframe/ble/glitch.sh" << 'GLITCH'
#!/bin/sh
echo "╔══════════════════════════════════╗"
echo "║   Cursed BLE Glitcher             ║"
echo "╚══════════════════════════════════╝"
echo "[!] For authorized security testing only"
python3 << 'PY'
import struct, time, random
print("[*] Initializing cursed spectral waveform...")
# Generate "cursed" RF patterns
patterns = [
    bytes([random.randint(0, 255) for _ in range(16)]),
    bytes([0x00, 0xFF, 0x00, 0xFF] * 4),
    bytes([0xAA, 0x55, 0xAA, 0x55] * 4)
]
for i, p in enumerate(patterns):
    print(f"[*] Pattern {i+1}: {p.hex()}")
    time.sleep(0.5)
print("[+] Cursed BLE glitch complete")
PY
GLITCH

cat > "$WORK/rootfs/opt/nullframe/ble/fuzz.sh" << 'FUZZ'
#!/bin/sh
echo "╔══════════════════════════════════╗"
echo "║   BLE Fuzzer                      ║"
echo "╚══════════════════════════════════╝"
echo "[*] Fuzzing BLE GATT services..."
python3 -c "print('[+] BLE fuzz ready')"
FUZZ

cat > "$WORK/rootfs/opt/nullframe/rf/sniff.sh" << 'RF'
#!/bin/sh
echo "╔══════════════════════════════════╗"
echo "║   RF Signal Sniffer               ║"
echo "╚══════════════════════════════════╝"
echo "[*] Requires RTL-SDR hardware"
echo "[*] Install: apt-get install rtl-sdr"
echo "[*] Use:rtl_sdr -f 433M -s 256k output.bin"
RF

cat > "$WORK/rootfs/opt/nullframe/rf/glitch.sh" << 'RFGLITCH'
#!/bin/sh
echo "╔══════════════════════════════════╗"
echo "║   Cursed RF Glitcher              ║"
echo "╚══════════════════════════════════╝"
echo "[*] Generating glitch waveforms..."
python3 << 'PY'
import random, time
print("[*] Creating cursed RF patterns...")
for i in range(5):
    freq = random.randint(300, 900)
    print(f"[*] Glitch {i+1}: {freq}MHz spectral burst")
    time.sleep(0.3)
print("[+] RF glitch complete")
PY
RFGLITCH

cat > "$WORK/rootfs/opt/nullframe/network/arpSpoof.sh" << 'NET'
#!/bin/sh
echo "╔══════════════════════════════════╗"
echo "║   ARP Spoofing Tool               ║"
echo "╚══════════════════════════════════╝"
if [ -z "$1" ] || [ -z "$2" ]; then
    echo "[*] Usage: arpSpoof.sh <target_ip> <gateway_ip>"
    exit 1
fi
TARGET=$1
GATEWAY=$2
echo "[*] Spoofing $TARGET via $GATEWAY"
echo "[*] Enable IP forwarding: echo 1 > /proc/sys/net/ipv4/ip_forward"
NET

cat > "$WORK/rootfs/opt/nullframe/network/mitm.sh" << 'MITM'
#!/bin/sh
echo "╔══════════════════════════════════╗"
echo "║   MITM Attack Suite              ║"
echo "╚══════════════════════════════════╝"
echo "[*] Use: ettercap -i eth0 -M arp:remote /target/ /gateway/"
MITM

chmod +x "$WORK/rootfs/opt/nullframe/wifi/monitor.sh"
chmod +x "$WORK/rootfs/opt/nullframe/wifi/scan.sh"
chmod +x "$WORK/rootfs/opt/nullframe/wifi/deauth.sh"
chmod +x "$WORK/rootfs/opt/nullframe/ble/scan.sh"
chmod +x "$WORK/rootfs/opt/nullframe/ble/glitch.sh"
chmod +x "$WORK/rootfs/opt/nullframe/ble/fuzz.sh"
chmod +x "$WORK/rootfs/opt/nullframe/rf/sniff.sh"
chmod +x "$WORK/rootfs/opt/nullframe/rf/glitch.sh"
chmod +x "$WORK/rootfs/opt/nullframe/network/arpSpoof.sh"
chmod +x "$WORK/rootfs/opt/nullframe/network/mitm.sh"

# Create disclaimer
cp "$ISOPATH/boot/disclaimer.txt" "$WORK/boot/disclaimer.txt"

# Create MOTD with RGB
cat > "$WORK/rootfs/etc/motd" << 'MOTD'
╔═══════════════════════════════════════════════════════════╗
║                                                           ║
║   ██╗  ██╗██████╗  ██████╗ ██████╗ ███████╗              ║
║   ██║ ██╔╝██╔══██╗██╔═══██╗██╔══██╗██╔════╝              ║
║   █████╔╝ ██████╔╝██║   ██║██████╔╝███████╗              ║
║   ██╔═██╗ ██╔══██╗██║   ██║██╔══██╗╚════██║              ║
║   ██║  ██╗██████╔╝╚██████╔╝██████╔╝███████║              ║
║   ╚═╝  ╚═╝╚═════╝  ╚═════╝ ╚═════╝ ╚══════╝              ║
║                                                           ║
║            SECURITY TESTING LABORATORY                    ║
║                                                           ║
║   ⚠️  AUTHORIZED USE ONLY - ALL ACTIVITY LOGGED  ⚠️      ║
║                                                           ║
╚═══════════════════════════════════════════════════════════╝

/opt/nullframe/menu.sh - Launch attack menu
/tools - List available tools
WARNING: Unauthorized access is illegal
MOTD

# Create init script
cat > "$WORK/rootfs/init" << 'INIT'
#!/bin/sh
/bin/sh
INIT

# Download Alpine kernel and initramfs
echo "[+] Downloading Alpine kernel..."
KERNEL_URL="https://dl-cdn.alpinelinux.org/alpine/v3.19/releases/x86_64/vmlinuz-lts"
INITRAMFS_URL="https://dl-cdn.alpinelinux.org/alpine/v3.19/releases/x86_64/initramfs-lts"

curl -sL "$KERNEL_URL" -o "$WORK/boot/vmlinuz" && echo "[+] Kernel downloaded" || echo "[!] Kernel failed"
curl -sL "$INITRAMFS_URL" -o "$WORK/boot/initramfs" && echo "[+] Initramfs downloaded" || echo "[!] Initramfs failed"

# Setup boot
echo "[+] Setting up boot loader..."
mkdir -p "$WORK/boot/syslinux"

cat > "$WORK/boot/syslinux/syslinux.cfg << 'SYSLINUX'
DEFAULT menu
TIMEOUT 30
PROMPT 1

MENU TITLE NullFrame OS - Security Testing Lab
MENU COLOR border 30;44
MENU COLOR title 1;36;44
MENU COLOR sel 30;47
MENU COLOR unsel 37;44

LABEL menu
MENU LABEL NullFrame OS (Live)
KERNEL /boot/vmlinuz
APPEND initrd=/boot/initramfs vga=791 quiet splash
TEXT HELP
Boot NullFrame Security Testing OS
ENDTEXT

LABEL safe  
MENU LABEL NullFrame OS (Safe Mode)
KERNEL /boot/vmlinuz
APPEND initrd=/boot/initramfs vga=791
TEXT HELP
Boot without attack tools
ENDTEXT

LABEL disclaimer
MENU LABEL View Disclaimer
KERNEL /boot/menu.c32
APPEND /boot/disclaimer.txt
TEXT HELP
Show legal disclaimer
ENDTEXT
SYSLINUX

# Copy isolinux
if [ -f /usr/share/syslinux/isolinux.bin ]; then
    cp /usr/share/syslinux/isolinux.bin "$WORK/boot/syslinux/"
fi

cat > "$WORK/boot/syslinux/boot.cat << 'BOOTCAT'
NullFrame OS
BOOTCAT

# Build ISO
echo "[+] Building ISO..."
xorriso -as mkisofs \
    -R \
    -b boot/syslinux/isolinux.bin \
    -c boot/syslinux/boot.cat \
    -no-emul-boot \
    -boot-load-size 4 \
    -boot-info-table \
    -isohybrid-mbr /usr/share/syslinux/mbr/mbr.bin \
    -o "$ISO_OUT" \
    "$WORK/" 2>&1

if [ -f "$ISO_OUT" ]; then
    echo ""
    echo "═══════════════════════════════════════════"
    echo "[+] ISO CREATED: $ISO_OUT"
    echo "═══════════════════════════════════════════"
    ls -lh "$ISO_OUT"
else
    echo "[!] Build failed"
fi
