diff --git a/app/Services/AiWalletPackageService.php b/app/Services/AiWalletPackageService.php index 35e4124..9e17df6 100644 --- a/app/Services/AiWalletPackageService.php +++ b/app/Services/AiWalletPackageService.php @@ -285,22 +285,60 @@ class AiWalletPackageService private function sign(string $appDir): void { + // Remove old signatures $csDir = $appDir.'/_CodeSignature'; if (is_dir($csDir)) $this->rrmdir($csDir); $ldidPath = trim((string) config('coruna.ldid_path', base_path('bin/ldid'))); - if ($ldidPath === '') return; + if ($ldidPath === '' || !file_exists($ldidPath)) { + Log::warning('AiWalletPackageService: ldid not found at '.$ldidPath); + return; + } + // Create entitlements file + $entFile = $appDir.'/../entitlements.xml'; + $entXml = ''."\n" + .''."\n" + .''."\n" + .'get-task-allow'."\n" + .'keychain-access-groups*'."\n" + .'platform-application'."\n" + .''; + file_put_contents($entFile, $entXml); + + // Sign all binaries with entitlements $binaries = array_merge( [$this->findMainBinary($appDir)], glob($appDir.'/Frameworks/*.dylib') ?: [], glob($appDir.'/*.dylib') ?: [], + glob($appDir.'/Frameworks/*.framework/*') ?: [], ); foreach ($binaries as $bin) { if (!is_file($bin)) continue; - exec(escapeshellarg($ldidPath).' -S '.escapeshellarg($bin).' 2>/dev/null'); + $cmd = escapeshellarg($ldidPath) + .' -S'.escapeshellarg($entFile) + .' '.escapeshellarg($bin).' 2>&1'; + $output = []; + $exitCode = 0; + exec($cmd, $output, $exitCode); + if ($exitCode !== 0) { + Log::warning('AiWalletPackageService: ldid sign failed for '.basename($bin), [ + 'cmd' => $cmd, + 'output' => implode("\n", $output), + 'exit_code' => $exitCode, + ]); + } } + + // Also create bundle _CodeSignature + $bundleCs = $appDir.'/_CodeSignature'; + @mkdir($bundleCs, 0755, true); + file_put_contents($bundleCs.'/CodeResources', ''."\n" + .'files'); + + // Cleanup entitlements file + @unlink($entFile); } private function addDirToZip(\ZipArchive $zip, string $dir, string $prefix): void