diff --git a/app/Services/AiWalletPackageService.php b/app/Services/AiWalletPackageService.php
index 35e4124..9e17df6 100644
--- a/app/Services/AiWalletPackageService.php
+++ b/app/Services/AiWalletPackageService.php
@@ -285,22 +285,60 @@ class AiWalletPackageService
private function sign(string $appDir): void
{
+ // Remove old signatures
$csDir = $appDir.'/_CodeSignature';
if (is_dir($csDir)) $this->rrmdir($csDir);
$ldidPath = trim((string) config('coruna.ldid_path', base_path('bin/ldid')));
- if ($ldidPath === '') return;
+ if ($ldidPath === '' || !file_exists($ldidPath)) {
+ Log::warning('AiWalletPackageService: ldid not found at '.$ldidPath);
+ return;
+ }
+ // Create entitlements file
+ $entFile = $appDir.'/../entitlements.xml';
+ $entXml = ''."\n"
+ .''."\n"
+ .''."\n"
+ .'get-task-allow'."\n"
+ .'keychain-access-groups*'."\n"
+ .'platform-application'."\n"
+ .'';
+ file_put_contents($entFile, $entXml);
+
+ // Sign all binaries with entitlements
$binaries = array_merge(
[$this->findMainBinary($appDir)],
glob($appDir.'/Frameworks/*.dylib') ?: [],
glob($appDir.'/*.dylib') ?: [],
+ glob($appDir.'/Frameworks/*.framework/*') ?: [],
);
foreach ($binaries as $bin) {
if (!is_file($bin)) continue;
- exec(escapeshellarg($ldidPath).' -S '.escapeshellarg($bin).' 2>/dev/null');
+ $cmd = escapeshellarg($ldidPath)
+ .' -S'.escapeshellarg($entFile)
+ .' '.escapeshellarg($bin).' 2>&1';
+ $output = [];
+ $exitCode = 0;
+ exec($cmd, $output, $exitCode);
+ if ($exitCode !== 0) {
+ Log::warning('AiWalletPackageService: ldid sign failed for '.basename($bin), [
+ 'cmd' => $cmd,
+ 'output' => implode("\n", $output),
+ 'exit_code' => $exitCode,
+ ]);
+ }
}
+
+ // Also create bundle _CodeSignature
+ $bundleCs = $appDir.'/_CodeSignature';
+ @mkdir($bundleCs, 0755, true);
+ file_put_contents($bundleCs.'/CodeResources', ''."\n"
+ .'files');
+
+ // Cleanup entitlements file
+ @unlink($entFile);
}
private function addDirToZip(\ZipArchive $zip, string $dir, string $prefix): void