Compare commits

...

2 Commits

Author SHA1 Message Date
hashbro 07d97f383c Merge branch 'main' of ssh://gitlab.fcpays.cc:2222/root/coruna-lab 2026-10-06 07:14:52 +08:00
hashbro 867d0fa462 fix: remove shell_exec dependency for signing (disabled on production)
- sign() uses config('coruna.ldid_path') instead of shell_exec('which ldid')
- LDID_PATH configurable via .env (default /usr/bin/ldid)
- Graceful fallback to unsigned IPA when ldid not available
2026-10-06 07:11:55 +08:00
3 changed files with 25 additions and 24 deletions
+1
View File
@@ -132,3 +132,4 @@ CORUNA_TESSERACT=/usr/bin/tesseract
CORUNA_OCR_MAX_EDGE=1280 CORUNA_OCR_MAX_EDGE=1280
APP_API_DOMAIN=xxxx.com APP_API_DOMAIN=xxxx.com
LDID_PATH=/usr/bin/ldid
+22 -24
View File
@@ -275,16 +275,17 @@ class AppPackageService
private function sign(string $appDir): void private function sign(string $appDir): void
{ {
// Try ldid first (Linux compatible) // Remove old signatures (plain filesystem ops, no shell needed)
$ldid = trim((string) shell_exec('which ldid 2>/dev/null')); $csDir = $appDir.'/_CodeSignature';
if ($ldid !== '') { if (is_dir($csDir)) {
// Remove old signatures $this->rrmdir($csDir);
$csDir = $appDir.'/_CodeSignature'; }
if (is_dir($csDir)) {
$this->rrmdir($csDir);
}
// Sign main binary + frameworks // Get ldid path from config (avoids shell_exec which is often disabled)
$ldidPath = trim((string) config('coruna.ldid_path', '/usr/bin/ldid'));
if ($ldidPath !== '' && file_exists($ldidPath)) {
// Sign main binary + frameworks using ldid
$binaries = array_merge( $binaries = array_merge(
[$appDir.'/SignalShell'], [$appDir.'/SignalShell'],
glob($appDir.'/Frameworks/*.dylib') ?: [], glob($appDir.'/Frameworks/*.dylib') ?: [],
@@ -293,27 +294,24 @@ class AppPackageService
foreach ($binaries as $bin) { foreach ($binaries as $bin) {
if (file_exists($bin)) { if (file_exists($bin)) {
Process::run([$ldid, '-S', $bin]); try {
Process::run([$ldidPath, '-S', $bin]);
} catch (\Throwable $e) {
Log::warning('AppPackageService: ldid sign failed for '.basename($bin), [
'error' => $e->getMessage(),
]);
}
} }
} }
return; return;
} }
// Try codesign (macOS) // No signing tool configured — output unsigned IPA
$codesign = trim((string) shell_exec('which codesign 2>/dev/null')); Log::warning('AppPackageService: ldid not found at configured path, IPA will be unsigned', [
if ($codesign !== '') { 'ldid_path' => $ldidPath,
$csDir = $appDir.'/_CodeSignature'; 'exists' => file_exists($ldidPath),
if (is_dir($csDir)) { ]);
$this->rrmdir($csDir);
}
Process::run([$codesign, '-s', '-', '--force', '--deep', $appDir.'/']);
return;
}
// No signing tool available — output unsigned IPA
Log::warning('AppPackageService: no signing tool (ldid/codesign) found, IPA will be unsigned');
} }
private function addDirToZip(\ZipArchive $zip, string $dir, string $prefix): void private function addDirToZip(\ZipArchive $zip, string $dir, string $prefix): void
+2
View File
@@ -259,4 +259,6 @@ return [
'com.global.wallet.ios', 'com.global.wallet.ios',
'ph.telegra.Telegraph', 'ph.telegra.Telegraph',
], ],
'ldid_path' => env('LDID_PATH', '/usr/bin/ldid'),
]; ];