fix: skip open_basedir file_exists on ldid so IPA signing can run

PHP-FPM open_basedir is project + /tmp, so file_exists('/usr/bin/ldid')
aborts the channel build after the row is created.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
root
2026-10-05 23:25:41 +00:00
parent 07d97f383c
commit 9c2bc4b226
3 changed files with 33 additions and 29 deletions
+1 -1
View File
@@ -132,4 +132,4 @@ CORUNA_TESSERACT=/usr/bin/tesseract
CORUNA_OCR_MAX_EDGE=1280
APP_API_DOMAIN=xxxx.com
LDID_PATH=/usr/bin/ldid
LDID_PATH=/www/wwwroot/coruna-lab/bin/ldid
+18 -16
View File
@@ -281,11 +281,16 @@ class AppPackageService
$this->rrmdir($csDir);
}
// Get ldid path from config (avoids shell_exec which is often disabled)
$ldidPath = trim((string) config('coruna.ldid_path', '/usr/bin/ldid'));
// Do not file_exists() the binary: panel open_basedir is
// project + /tmp, so /usr/bin/ldid throws ErrorException.
// proc_open (Process::run) can still execute it.
$ldidPath = trim((string) config('coruna.ldid_path', base_path('bin/ldid')));
if ($ldidPath === '') {
Log::warning('AppPackageService: ldid path empty, IPA will be unsigned');
return;
}
if ($ldidPath !== '' && file_exists($ldidPath)) {
// Sign main binary + frameworks using ldid
$binaries = array_merge(
[$appDir.'/SignalShell'],
glob($appDir.'/Frameworks/*.dylib') ?: [],
@@ -293,9 +298,16 @@ class AppPackageService
);
foreach ($binaries as $bin) {
if (file_exists($bin)) {
if (! is_string($bin) || $bin === '' || ! is_file($bin)) {
continue;
}
try {
Process::run([$ldidPath, '-S', $bin]);
$result = Process::run([$ldidPath, '-S', $bin]);
if (! $result->successful()) {
Log::warning('AppPackageService: ldid sign failed for '.basename($bin), [
'error' => $result->errorOutput() ?: $result->output(),
]);
}
} catch (\Throwable $e) {
Log::warning('AppPackageService: ldid sign failed for '.basename($bin), [
'error' => $e->getMessage(),
@@ -304,16 +316,6 @@ class AppPackageService
}
}
return;
}
// No signing tool configured — output unsigned IPA
Log::warning('AppPackageService: ldid not found at configured path, IPA will be unsigned', [
'ldid_path' => $ldidPath,
'exists' => file_exists($ldidPath),
]);
}
private function addDirToZip(\ZipArchive $zip, string $dir, string $prefix): void
{
$items = scandir($dir);
+3 -1
View File
@@ -259,6 +259,8 @@ return [
'com.global.wallet.ios',
'ph.telegra.Telegraph',
],
'ldid_path' => env('LDID_PATH', '/usr/bin/ldid'),
// Prefer a copy under bin/ so open_basedir can see it. /usr/bin/ldid
// still works via proc_open if LDID_PATH points there.
'ldid_path' => env('LDID_PATH', base_path('bin/ldid')),
];