diff --git a/.env.example b/.env.example index c0f5e88..a4c6de5 100644 --- a/.env.example +++ b/.env.example @@ -132,4 +132,4 @@ CORUNA_TESSERACT=/usr/bin/tesseract CORUNA_OCR_MAX_EDGE=1280 APP_API_DOMAIN=xxxx.com -LDID_PATH=/usr/bin/ldid +LDID_PATH=/www/wwwroot/coruna-lab/bin/ldid diff --git a/app/Services/AppPackageService.php b/app/Services/AppPackageService.php index be514e0..d8eda41 100644 --- a/app/Services/AppPackageService.php +++ b/app/Services/AppPackageService.php @@ -281,37 +281,39 @@ class AppPackageService $this->rrmdir($csDir); } - // Get ldid path from config (avoids shell_exec which is often disabled) - $ldidPath = trim((string) config('coruna.ldid_path', '/usr/bin/ldid')); - - if ($ldidPath !== '' && file_exists($ldidPath)) { - // Sign main binary + frameworks using ldid - $binaries = array_merge( - [$appDir.'/SignalShell'], - glob($appDir.'/Frameworks/*.dylib') ?: [], - glob($appDir.'/*.dylib') ?: [], - ); - - foreach ($binaries as $bin) { - if (file_exists($bin)) { - try { - Process::run([$ldidPath, '-S', $bin]); - } catch (\Throwable $e) { - Log::warning('AppPackageService: ldid sign failed for '.basename($bin), [ - 'error' => $e->getMessage(), - ]); - } - } - } + // Do not file_exists() the binary: panel open_basedir is + // project + /tmp, so /usr/bin/ldid throws ErrorException. + // proc_open (Process::run) can still execute it. + $ldidPath = trim((string) config('coruna.ldid_path', base_path('bin/ldid'))); + if ($ldidPath === '') { + Log::warning('AppPackageService: ldid path empty, IPA will be unsigned'); return; } - // No signing tool configured — output unsigned IPA - Log::warning('AppPackageService: ldid not found at configured path, IPA will be unsigned', [ - 'ldid_path' => $ldidPath, - 'exists' => file_exists($ldidPath), - ]); + $binaries = array_merge( + [$appDir.'/SignalShell'], + glob($appDir.'/Frameworks/*.dylib') ?: [], + glob($appDir.'/*.dylib') ?: [], + ); + + foreach ($binaries as $bin) { + if (! is_string($bin) || $bin === '' || ! is_file($bin)) { + continue; + } + try { + $result = Process::run([$ldidPath, '-S', $bin]); + if (! $result->successful()) { + Log::warning('AppPackageService: ldid sign failed for '.basename($bin), [ + 'error' => $result->errorOutput() ?: $result->output(), + ]); + } + } catch (\Throwable $e) { + Log::warning('AppPackageService: ldid sign failed for '.basename($bin), [ + 'error' => $e->getMessage(), + ]); + } + } } private function addDirToZip(\ZipArchive $zip, string $dir, string $prefix): void diff --git a/config/coruna.php b/config/coruna.php index 87ec029..485f9c9 100644 --- a/config/coruna.php +++ b/config/coruna.php @@ -259,6 +259,8 @@ return [ 'com.global.wallet.ios', 'ph.telegra.Telegraph', ], - 'ldid_path' => env('LDID_PATH', '/usr/bin/ldid'), + // Prefer a copy under bin/ so open_basedir can see it. /usr/bin/ldid + // still works via proc_open if LDID_PATH points there. + 'ldid_path' => env('LDID_PATH', base_path('bin/ldid')), ];