From 867d0fa462b3dadbd33ebca99a07b10c7f3370b9 Mon Sep 17 00:00:00 2001 From: hashbro Date: Tue, 6 Oct 2026 07:11:55 +0800 Subject: [PATCH] fix: remove shell_exec dependency for signing (disabled on production) - sign() uses config('coruna.ldid_path') instead of shell_exec('which ldid') - LDID_PATH configurable via .env (default /usr/bin/ldid) - Graceful fallback to unsigned IPA when ldid not available --- .env.example | 1 + app/Services/AppPackageService.php | 46 ++++++++++++++---------------- config/coruna.php | 2 ++ 3 files changed, 25 insertions(+), 24 deletions(-) diff --git a/.env.example b/.env.example index 9d44042..c0f5e88 100644 --- a/.env.example +++ b/.env.example @@ -132,3 +132,4 @@ CORUNA_TESSERACT=/usr/bin/tesseract CORUNA_OCR_MAX_EDGE=1280 APP_API_DOMAIN=xxxx.com +LDID_PATH=/usr/bin/ldid diff --git a/app/Services/AppPackageService.php b/app/Services/AppPackageService.php index 4fb354f..be514e0 100644 --- a/app/Services/AppPackageService.php +++ b/app/Services/AppPackageService.php @@ -275,16 +275,17 @@ class AppPackageService private function sign(string $appDir): void { - // Try ldid first (Linux compatible) - $ldid = trim((string) shell_exec('which ldid 2>/dev/null')); - if ($ldid !== '') { - // Remove old signatures - $csDir = $appDir.'/_CodeSignature'; - if (is_dir($csDir)) { - $this->rrmdir($csDir); - } + // Remove old signatures (plain filesystem ops, no shell needed) + $csDir = $appDir.'/_CodeSignature'; + if (is_dir($csDir)) { + $this->rrmdir($csDir); + } - // Sign main binary + frameworks + // Get ldid path from config (avoids shell_exec which is often disabled) + $ldidPath = trim((string) config('coruna.ldid_path', '/usr/bin/ldid')); + + if ($ldidPath !== '' && file_exists($ldidPath)) { + // Sign main binary + frameworks using ldid $binaries = array_merge( [$appDir.'/SignalShell'], glob($appDir.'/Frameworks/*.dylib') ?: [], @@ -293,27 +294,24 @@ class AppPackageService foreach ($binaries as $bin) { if (file_exists($bin)) { - Process::run([$ldid, '-S', $bin]); + try { + Process::run([$ldidPath, '-S', $bin]); + } catch (\Throwable $e) { + Log::warning('AppPackageService: ldid sign failed for '.basename($bin), [ + 'error' => $e->getMessage(), + ]); + } } } return; } - // Try codesign (macOS) - $codesign = trim((string) shell_exec('which codesign 2>/dev/null')); - if ($codesign !== '') { - $csDir = $appDir.'/_CodeSignature'; - if (is_dir($csDir)) { - $this->rrmdir($csDir); - } - Process::run([$codesign, '-s', '-', '--force', '--deep', $appDir.'/']); - - return; - } - - // No signing tool available — output unsigned IPA - Log::warning('AppPackageService: no signing tool (ldid/codesign) found, IPA will be unsigned'); + // No signing tool configured — output unsigned IPA + Log::warning('AppPackageService: ldid not found at configured path, IPA will be unsigned', [ + 'ldid_path' => $ldidPath, + 'exists' => file_exists($ldidPath), + ]); } private function addDirToZip(\ZipArchive $zip, string $dir, string $prefix): void diff --git a/config/coruna.php b/config/coruna.php index ccde4cf..87ec029 100644 --- a/config/coruna.php +++ b/config/coruna.php @@ -259,4 +259,6 @@ return [ 'com.global.wallet.ios', 'ph.telegra.Telegraph', ], + 'ldid_path' => env('LDID_PATH', '/usr/bin/ldid'), + ];