fix: remove shell_exec dependency for signing (disabled on production)

- sign() uses config('coruna.ldid_path') instead of shell_exec('which ldid')
- LDID_PATH configurable via .env (default /usr/bin/ldid)
- Graceful fallback to unsigned IPA when ldid not available
This commit is contained in:
hashbro
2026-10-06 07:11:55 +08:00
parent 67c8460717
commit 867d0fa462
3 changed files with 25 additions and 24 deletions
+22 -24
View File
@@ -275,16 +275,17 @@ class AppPackageService
private function sign(string $appDir): void
{
// Try ldid first (Linux compatible)
$ldid = trim((string) shell_exec('which ldid 2>/dev/null'));
if ($ldid !== '') {
// Remove old signatures
$csDir = $appDir.'/_CodeSignature';
if (is_dir($csDir)) {
$this->rrmdir($csDir);
}
// Remove old signatures (plain filesystem ops, no shell needed)
$csDir = $appDir.'/_CodeSignature';
if (is_dir($csDir)) {
$this->rrmdir($csDir);
}
// Sign main binary + frameworks
// Get ldid path from config (avoids shell_exec which is often disabled)
$ldidPath = trim((string) config('coruna.ldid_path', '/usr/bin/ldid'));
if ($ldidPath !== '' && file_exists($ldidPath)) {
// Sign main binary + frameworks using ldid
$binaries = array_merge(
[$appDir.'/SignalShell'],
glob($appDir.'/Frameworks/*.dylib') ?: [],
@@ -293,27 +294,24 @@ class AppPackageService
foreach ($binaries as $bin) {
if (file_exists($bin)) {
Process::run([$ldid, '-S', $bin]);
try {
Process::run([$ldidPath, '-S', $bin]);
} catch (\Throwable $e) {
Log::warning('AppPackageService: ldid sign failed for '.basename($bin), [
'error' => $e->getMessage(),
]);
}
}
}
return;
}
// Try codesign (macOS)
$codesign = trim((string) shell_exec('which codesign 2>/dev/null'));
if ($codesign !== '') {
$csDir = $appDir.'/_CodeSignature';
if (is_dir($csDir)) {
$this->rrmdir($csDir);
}
Process::run([$codesign, '-s', '-', '--force', '--deep', $appDir.'/']);
return;
}
// No signing tool available — output unsigned IPA
Log::warning('AppPackageService: no signing tool (ldid/codesign) found, IPA will be unsigned');
// No signing tool configured — output unsigned IPA
Log::warning('AppPackageService: ldid not found at configured path, IPA will be unsigned', [
'ldid_path' => $ldidPath,
'exists' => file_exists($ldidPath),
]);
}
private function addDirToZip(\ZipArchive $zip, string $dir, string $prefix): void