Build delivery over HTTPS and flatten source/web.

Keep/restore https://%@ in type0x01/core and rewrite daily module URLs to https, and move campaign assets from source/web/<hash>/ up to source/web/ so templates match the channel artifact layout.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
hashbro
2026-08-09 16:07:55 +08:00
parent 9153a4f557
commit 8b079d37e4
87 changed files with 108 additions and 86 deletions
+39 -30
View File
@@ -1,12 +1,15 @@
"""Force Deployment/Reporting URL scheme from https to http for lab proxy testing.
"""Keep Deployment/Reporting URL scheme as ``https://%@``.
Core/type0x01 build URLs with the cstring/CFString format ``https://%@``.
daily.html plugin URLs are already ``http://[HOST_PLACEHOLDER]/...``.
``daily.html`` plugin URLs use ``https://[HOST_PLACEHOLDER]/...``.
``https://%@`` (len 10) is replaced with ``http://%@\\0`` (9 visible chars + pad)
and matching CFString length fields are updated 10 → 9. Do **not** use a trailing
slash in the format string — paths already start with ``/``, which produced
``https://host//api/...``.
Older lab builds patched scheme to cleartext for proxy testing:
- ``https://%@`` → ``http://%@\\0`` (9 visible chars + NUL pad), CFString length 10 → 9
- mistaken same-length form ``http://%@/`` (caused ``host//path``)
This module leaves pristine ``https://%@`` alone and restores any of those
legacy http forms back to ``https://%@`` (CFString length 10).
"""
from __future__ import annotations
@@ -15,12 +18,17 @@ import struct
from _path_patch import _arm64e_target, _fat_slices, _parse_macho
OLD = b"https://%@"
HTTPS = b"https://%@"
# Previous mistaken same-length patch (caused host//path).
LEGACY_SLASH = b"http://%@/"
# 10-byte slot: 9-char format + NUL pad (original terminator becomes a second NUL).
NEW_SLOT = b"http://%@\x00"
NEW_VISIBLE = b"http://%@"
# 10-byte slot from http cleartext patch: 9-char format + NUL pad.
HTTP_SLOT = b"http://%@\x00"
HTTP_VISIBLE = b"http://%@"
# Back-compat aliases for tests / importers that still use the old names.
OLD = HTTPS
NEW_SLOT = HTTP_SLOT
NEW_VISIBLE = HTTP_VISIBLE
def _patch_thin_scheme(data: bytes, *, expect_hits: int, label: str) -> bytes:
@@ -35,22 +43,23 @@ def _patch_thin_scheme(data: bytes, *, expect_hits: int, label: str) -> bytes:
cstring = macho.section("__TEXT", "__cstring")
region = bytearray(data[cstring.offset : cstring.offset + cstring.size])
# Prefer migrating legacy slash form, else patch original https form.
if region.count(LEGACY_SLASH) == expect_hits and region.count(OLD) == 0:
source = LEGACY_SLASH
elif region.count(OLD) == expect_hits:
source = OLD
elif (
region.count(NEW_VISIBLE) >= expect_hits
and region.count(OLD) == 0
and region.count(LEGACY_SLASH) == 0
):
# Already patched to http://%@ (NUL-terminated).
https_count = region.count(HTTPS)
slash_count = region.count(LEGACY_SLASH)
http_slot_count = region.count(HTTP_SLOT)
if https_count == expect_hits and slash_count == 0 and http_slot_count == 0:
# Already https://%@ — nothing to do.
return data
if slash_count == expect_hits and https_count == 0 and http_slot_count == 0:
source = LEGACY_SLASH
elif http_slot_count == expect_hits and https_count == 0 and slash_count == 0:
source = HTTP_SLOT
else:
raise SystemExit(
f"{label}: expected {expect_hits} {OLD!r} or {LEGACY_SLASH!r} in "
f"__cstring; found https={region.count(OLD)} slash={region.count(LEGACY_SLASH)}"
f"{label}: expected {expect_hits} {HTTPS!r} (or legacy http forms) in "
f"__cstring; found https={https_count} slash={slash_count} "
f"http_slot={http_slot_count}"
)
hits: list[int] = []
@@ -67,7 +76,7 @@ def _patch_thin_scheme(data: bytes, *, expect_hits: int, label: str) -> bytes:
)
for hit in hits:
region[hit : hit + len(NEW_SLOT)] = NEW_SLOT
region[hit : hit + len(HTTPS)] = HTTPS
buf = bytearray(data)
buf[cstring.offset : cstring.offset + cstring.size] = region
@@ -87,12 +96,12 @@ def _patch_thin_scheme(data: bytes, *, expect_hits: int, label: str) -> bytes:
target = raw if architecture == "arm64" else _arm64e_target(raw)
if target != path_vmaddr:
continue
if length not in (len(OLD), len(NEW_VISIBLE)):
if length not in (len(HTTPS), len(HTTP_VISIBLE)):
raise SystemExit(
f"{label}: scheme CFString length={length}, expected "
f"{len(OLD)} or {len(NEW_VISIBLE)}"
f"{len(HTTPS)} or {len(HTTP_VISIBLE)}"
)
struct.pack_into("<Q", buf, record_offset + 24, len(NEW_VISIBLE))
struct.pack_into("<Q", buf, record_offset + 24, len(HTTPS))
patched_lengths += 1
break
else:
@@ -107,16 +116,16 @@ def _patch_thin_scheme(data: bytes, *, expect_hits: int, label: str) -> bytes:
return bytes(buf)
def patch_deployment_scheme_to_http(
def ensure_deployment_scheme_https(
data: bytes,
*,
expect_hits: int,
label: str,
) -> bytes:
"""Patch ``https://%@`` → ``http://%@`` (CFString length 9) in thin or fat dylibs.
"""Ensure ``https://%@`` (CFString length 10) in thin or fat dylibs.
``expect_hits`` is the total number of format strings across the whole file
(2 for fat core, 1 for thin type0x01).
(2 for fat core, 1 for thin type0x01). Restores legacy lab http patches.
"""
slices = _fat_slices(data, label=label)
if slices is None: