Build patched iloader for ExtensionKit IDs, profiles and Keychain [skip ci]
This commit is contained in:
@@ -0,0 +1,62 @@
|
|||||||
|
name: Build MusicBridge compatible iloader
|
||||||
|
on:
|
||||||
|
workflow_dispatch:
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
jobs:
|
||||||
|
windows:
|
||||||
|
runs-on: windows-latest
|
||||||
|
timeout-minutes: 60
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
with:
|
||||||
|
persist-credentials: false
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
with:
|
||||||
|
repository: nab138/iloader
|
||||||
|
ref: 348eefd7de78e9bc612c9d619b8b1e7a80ba3ba0
|
||||||
|
path: build/compat/iloader
|
||||||
|
persist-credentials: false
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
with:
|
||||||
|
repository: nab138/isideload
|
||||||
|
ref: f6a4d5dba717d72fc2af63eaba26b27ba44116be
|
||||||
|
path: build/compat/isideload
|
||||||
|
persist-credentials: false
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
with:
|
||||||
|
repository: nab138/apple-crates
|
||||||
|
ref: 5da0b8df9b202434b1eff2700059b1ee142592ac
|
||||||
|
path: build/compat/apple-crates
|
||||||
|
persist-credentials: false
|
||||||
|
- uses: dtolnay/rust-toolchain@stable
|
||||||
|
- uses: ilammy/msvc-dev-cmd@v1
|
||||||
|
- uses: oven-sh/setup-bun@v2
|
||||||
|
- name: Patch pinned sources
|
||||||
|
run: python tools/iloader/prepare.py build/compat
|
||||||
|
- name: Install frontend dependencies
|
||||||
|
working-directory: build/compat/iloader
|
||||||
|
run: bun install --frozen-lockfile
|
||||||
|
- name: Test extension discovery, bundle IDs and signing permissions
|
||||||
|
working-directory: build/compat/iloader/src-tauri
|
||||||
|
run: |
|
||||||
|
cargo test -p isideload --lib musicbridge
|
||||||
|
if ($LASTEXITCODE -ne 0) { exit $LASTEXITCODE }
|
||||||
|
cargo test -p apple-codesign --lib musicbridge
|
||||||
|
if ($LASTEXITCODE -ne 0) { exit $LASTEXITCODE }
|
||||||
|
- name: Build portable GUI
|
||||||
|
working-directory: build/compat/iloader
|
||||||
|
run: bunx tauri build --no-bundle --config src-tauri/ci.conf.json
|
||||||
|
- name: Package helper with provenance
|
||||||
|
run: |
|
||||||
|
New-Item -ItemType Directory -Force build/iloader-musicbridge
|
||||||
|
Copy-Item build/compat/iloader/src-tauri/target/release/iloader.exe build/iloader-musicbridge/iloader-musicbridge.exe
|
||||||
|
Copy-Item tools/iloader/README.md build/iloader-musicbridge/README.md
|
||||||
|
Get-ChildItem build/compat/iloader -Filter 'LICENSE*' | Copy-Item -Destination build/iloader-musicbridge
|
||||||
|
Get-FileHash build/iloader-musicbridge/iloader-musicbridge.exe | Format-List | Out-File build/iloader-musicbridge/SHA256.txt
|
||||||
|
- uses: actions/upload-artifact@v4
|
||||||
|
with:
|
||||||
|
name: iloader-musicbridge-windows
|
||||||
|
path: build/iloader-musicbridge
|
||||||
|
if-no-files-found: error
|
||||||
|
retention-days: 7
|
||||||
@@ -0,0 +1,28 @@
|
|||||||
|
# iloader: совместимость с MusicBridge 0.7.0
|
||||||
|
|
||||||
|
Это отдельная неофициальная portable-сборка iloader для Windows. Исходники:
|
||||||
|
- https://github.com/nab138/iloader/tree/348eefd7de78e9bc612c9d619b8b1e7a80ba3ba0
|
||||||
|
- https://github.com/nab138/isideload/tree/f6a4d5dba717d72fc2af63eaba26b27ba44116be
|
||||||
|
- https://github.com/nab138/apple-crates/tree/5da0b8df9b202434b1eff2700059b1ee142592ac
|
||||||
|
|
||||||
|
Патчи хранятся в репозитории MusicBridge в tools/iloader. Workflow
|
||||||
|
iloader-compat.yml запускается вручную, не использует Apple Account/сертификаты.
|
||||||
|
Apple-авторизация и подпись происходят только локально на компьютере пользователя.
|
||||||
|
|
||||||
|
Исправления: обнаружение Extensions вместе с PlugIns, переименование и получение
|
||||||
|
профиля каждого расширения, вложенная подпись ExtensionKit и общий Keychain для
|
||||||
|
MusicBridge только в пределах разрешений настоящего provisioning profile Apple.
|
||||||
|
Регрессионные Rust-тесты проверяют обе папки расширений, сохранение новых Bundle ID,
|
||||||
|
обработку вложенной подписи и отказ при недопустимой Keychain group.
|
||||||
|
|
||||||
|
Использование после успешной сборки:
|
||||||
|
1. Закрыть обычный iloader. Удалять его и установленный MusicBridge не требуется.
|
||||||
|
2. Запустить iloader-musicbridge.exe. Заголовок окна содержит compatibility build.
|
||||||
|
3. Использовать прежний Apple Account; выбрать исходную MusicBridge 0.7.0 IPA.
|
||||||
|
4. Подписать и установить заново. Все расширения нужно сохранить.
|
||||||
|
5. Проверить обычное подключение, затем кнопку системного пульта и Пункт управления.
|
||||||
|
|
||||||
|
Вариант сохраняет идентификатор/хранилище обычного iloader для локального входа,
|
||||||
|
поэтому одновременно запускать обе версии не нужно. Обновления из upstream в
|
||||||
|
этой сборке отключены. Совместимость нового extension point с бесплатным профилем
|
||||||
|
Apple окончательно подтверждается только установкой на устройстве.
|
||||||
@@ -0,0 +1,46 @@
|
|||||||
|
diff --git a/apple-codesign-quick/src/bundle.rs b/apple-codesign-quick/src/bundle.rs
|
||||||
|
index 040fd07..2bfa359 100644
|
||||||
|
--- a/apple-codesign-quick/src/bundle.rs
|
||||||
|
+++ b/apple-codesign-quick/src/bundle.rs
|
||||||
|
@@ -16,6 +16,23 @@ const FAIRPLAY_DIR: &str = "SC_Info";
|
||||||
|
const CODE_SIGNATURE_DIR: &str = "_CodeSignature";
|
||||||
|
const CODE_RESOURCES_FILE: &str = "CodeResources";
|
||||||
|
|
||||||
|
+#[cfg(test)]
|
||||||
|
+mod musicbridge_extensionkit_tests {
|
||||||
|
+ use super::*;
|
||||||
|
+ #[test]
|
||||||
|
+ fn musicbridge_extensionkit_is_signed_as_nested_bundle() {
|
||||||
|
+ let unique = std::time::SystemTime::now().duration_since(std::time::UNIX_EPOCH).unwrap().as_nanos();
|
||||||
|
+ let root = std::env::temp_dir().join(format!("musicbridge-codesign-test-{unique}"));
|
||||||
|
+ let extension = root.join("Extensions/Remote.appex");
|
||||||
|
+ std::fs::create_dir_all(&extension).unwrap();
|
||||||
|
+ std::fs::write(extension.join("Info.plist"), b"fixture").unwrap();
|
||||||
|
+ let bundle = Bundle { path: root, app_info: Dictionary::new() };
|
||||||
|
+ assert_eq!(bundle.sub_bundles().unwrap(), vec![extension]);
|
||||||
|
+ assert!(!should_hash_resource("Extensions/Remote.appex/Remote", "Main"));
|
||||||
|
+ assert!(should_hash_resource("Assets.car", "Main"));
|
||||||
|
+ }
|
||||||
|
+}
|
||||||
|
+
|
||||||
|
pub struct BundleSigningSettings<'a> {
|
||||||
|
pub team_id: String,
|
||||||
|
pub main_entitlements: Dictionary,
|
||||||
|
@@ -202,7 +219,7 @@ impl Bundle {
|
||||||
|
|
||||||
|
fn sub_bundles(&self) -> Result<Vec<PathBuf>> {
|
||||||
|
let mut bundles = Vec::new();
|
||||||
|
- for folder in ["Frameworks", "PlugIns"] {
|
||||||
|
+ for folder in ["Frameworks", "PlugIns", "Extensions"] {
|
||||||
|
let dir = self.path.join(folder);
|
||||||
|
#[cfg(feature = "wasm")]
|
||||||
|
if !isideload_vfs::fs::metadata(&dir)
|
||||||
|
@@ -463,7 +480,7 @@ fn should_hash_resource(relative: &str, executable: &str) -> bool {
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
- for nested_root in ["Frameworks/", "PlugIns/"] {
|
||||||
|
+ for nested_root in ["Frameworks/", "PlugIns/", "Extensions/"] {
|
||||||
|
if let Some(rest) = relative.strip_prefix(nested_root)
|
||||||
|
&& rest.contains('/')
|
||||||
|
{
|
||||||
@@ -0,0 +1,151 @@
|
|||||||
|
diff --git a/isideload/src/sideload/application.rs b/isideload/src/sideload/application.rs
|
||||||
|
index 4e0ccd0..be80af4 100644
|
||||||
|
--- a/isideload/src/sideload/application.rs
|
||||||
|
+++ b/isideload/src/sideload/application.rs
|
||||||
|
@@ -20,6 +20,33 @@ pub struct Application {
|
||||||
|
//pub temp_path: PathBuf,
|
||||||
|
}
|
||||||
|
|
||||||
|
+#[cfg(test)]
|
||||||
|
+mod musicbridge_tests {
|
||||||
|
+ use super::*;
|
||||||
|
+ #[test]
|
||||||
|
+ fn musicbridge_extensionkit_is_renamed_and_persisted() {
|
||||||
|
+ let root = std::env::temp_dir().join(format!("musicbridge-sign-test-{}", uuid::Uuid::new_v4()));
|
||||||
|
+ for (directory, id) in [("", "ru.yukinoki.musicbridge"),
|
||||||
|
+ ("PlugIns/Widget.appex", "ru.yukinoki.musicbridge.widgets"),
|
||||||
|
+ ("Extensions/Remote.appex", "ru.yukinoki.musicbridge.remote")] {
|
||||||
|
+ let path = root.join(directory);
|
||||||
|
+ std::fs::create_dir_all(&path).unwrap();
|
||||||
|
+ let mut info = plist::Dictionary::new();
|
||||||
|
+ info.insert("CFBundleIdentifier".into(), id.into());
|
||||||
|
+ plist::to_file_xml(path.join("Info.plist"), &info).unwrap();
|
||||||
|
+ }
|
||||||
|
+ let mut app = Application::new(root.clone()).unwrap();
|
||||||
|
+ assert_eq!(app.bundle.app_extensions().len(), 2);
|
||||||
|
+ app.update_bundle_id("ru.yukinoki.musicbridge", "ru.yukinoki.musicbridge.TEAM").unwrap();
|
||||||
|
+ app.bundle.write_info().unwrap();
|
||||||
|
+ for extension in app.bundle.app_extensions_mut() { extension.write_info().unwrap(); }
|
||||||
|
+ let saved = Application::new(root).unwrap();
|
||||||
|
+ for extension in saved.bundle.app_extensions() {
|
||||||
|
+ assert!(extension.bundle_identifier().unwrap().starts_with("ru.yukinoki.musicbridge.TEAM."));
|
||||||
|
+ }
|
||||||
|
+ }
|
||||||
|
+}
|
||||||
|
+
|
||||||
|
impl Application {
|
||||||
|
pub fn new(path: PathBuf) -> Result<Self, Report> {
|
||||||
|
if !isideload_vfs::fs::metadata(&path).is_ok() {
|
||||||
|
diff --git a/isideload/src/sideload/bundle.rs b/isideload/src/sideload/bundle.rs
|
||||||
|
index 67a947d..2cc2282 100644
|
||||||
|
--- a/isideload/src/sideload/bundle.rs
|
||||||
|
+++ b/isideload/src/sideload/bundle.rs
|
||||||
|
@@ -45,23 +45,19 @@ impl Bundle {
|
||||||
|
"Failed to parse Info.plist".to_string(),
|
||||||
|
))?;
|
||||||
|
|
||||||
|
- // Load app extensions from PlugIns directory
|
||||||
|
- let plug_ins_dir = bundle_path.join("PlugIns");
|
||||||
|
- let app_extensions = if isideload_vfs::fs::metadata(&plug_ins_dir).is_ok() {
|
||||||
|
- isideload_vfs::fs::read_dir(&plug_ins_dir)
|
||||||
|
- .context(SideloadError::InvalidBundle(
|
||||||
|
- "Failed to read PlugIns directory".to_string(),
|
||||||
|
- ))?
|
||||||
|
- .filter_map(|entry| entry.ok())
|
||||||
|
- .filter(|entry| {
|
||||||
|
- entry.file_type().map(|ft| ft.is_dir()).unwrap_or(false)
|
||||||
|
- && isideload_vfs::fs::metadata(&entry.path().join("Info.plist")).is_ok()
|
||||||
|
- })
|
||||||
|
- .filter_map(|entry| Bundle::new(entry.path()).ok())
|
||||||
|
- .collect()
|
||||||
|
- } else {
|
||||||
|
- Vec::new()
|
||||||
|
- };
|
||||||
|
+ // ExtensionKit uses Extensions; WidgetKit and older extensions use PlugIns.
|
||||||
|
+ // Invalid nested bundles must fail signing, never be silently skipped.
|
||||||
|
+ let mut app_extensions = Vec::new();
|
||||||
|
+ for folder in ["PlugIns", "Extensions"] {
|
||||||
|
+ let directory = bundle_path.join(folder);
|
||||||
|
+ if !isideload_vfs::fs::metadata(&directory).is_ok() { continue; }
|
||||||
|
+ for entry in isideload_vfs::fs::read_dir(&directory)? {
|
||||||
|
+ let entry = entry?;
|
||||||
|
+ if entry.file_type()?.is_dir() {
|
||||||
|
+ app_extensions.push(Bundle::new(entry.path())?);
|
||||||
|
+ }
|
||||||
|
+ }
|
||||||
|
+ }
|
||||||
|
|
||||||
|
// Load frameworks from Frameworks directory
|
||||||
|
let frameworks_dir = bundle_path.join("Frameworks");
|
||||||
|
diff --git a/isideload/src/sideload/sign.rs b/isideload/src/sideload/sign.rs
|
||||||
|
index a3d9799..cf3904d 100644
|
||||||
|
--- a/isideload/src/sideload/sign.rs
|
||||||
|
+++ b/isideload/src/sideload/sign.rs
|
||||||
|
@@ -63,6 +63,10 @@ where
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
+ let musicbridge = app.main_bundle_id()? == format!("ru.yukinoki.musicbridge.{}", team.team_id)
|
||||||
|
+ && app.bundle.app_info.get("MusicBridgeSharedKeychainGroup").and_then(plist::Value::as_string)
|
||||||
|
+ == Some("ru.yukinoki.musicbridge.remote-control");
|
||||||
|
+ if musicbridge { entitlements = musicbridge_keychain(&entitlements)?; }
|
||||||
|
let mut settings = BundleSigningSettings::new(&team.team_id, entitlements, Some(&signer));
|
||||||
|
settings.embedded_mobileprovision = Some(main_provisioning_profile.encoded_profile.as_ref());
|
||||||
|
|
||||||
|
@@ -75,9 +79,56 @@ where
|
||||||
|
.map(|(bundle_id, _, entitlements)| (bundle_id.clone(), entitlements.clone()))
|
||||||
|
.collect();
|
||||||
|
|
||||||
|
+ if musicbridge {
|
||||||
|
+ let remote_id = format!("{}.remote", app.main_bundle_id()?);
|
||||||
|
+ let remote = settings.entitlements_by_bundle_id.get(&remote_id)
|
||||||
|
+ .ok_or_report().context("MusicBridge remote extension has no provisioning profile")?;
|
||||||
|
+ let remote = musicbridge_keychain(remote)?;
|
||||||
|
+ settings.entitlements_by_bundle_id.insert(remote_id, remote);
|
||||||
|
+ }
|
||||||
|
+
|
||||||
|
if let Some(callback) = &progress_callback {
|
||||||
|
callback(0.5).await;
|
||||||
|
}
|
||||||
|
|
||||||
|
Ok(sign_bundle(&app.bundle.bundle_dir, &settings)?)
|
||||||
|
}
|
||||||
|
+
|
||||||
|
+// Request only a group explicitly permitted by Apple's actual profile.
|
||||||
|
+fn musicbridge_keychain(profile: &Dictionary) -> Result<Dictionary, Report> {
|
||||||
|
+ let application = profile.get("application-identifier").and_then(plist::Value::as_string)
|
||||||
|
+ .ok_or_report().context("Profile has no application-identifier")?;
|
||||||
|
+ let prefix = application.split_once('.').ok_or_report().context("Invalid app identifier")?.0;
|
||||||
|
+ let shared = format!("{}.ru.yukinoki.musicbridge.remote-control", prefix);
|
||||||
|
+ let allowed = profile.get("keychain-access-groups").and_then(plist::Value::as_array)
|
||||||
|
+ .ok_or_report().context("Profile has no Keychain groups")?;
|
||||||
|
+ if !allowed.iter().filter_map(plist::Value::as_string).any(|group|
|
||||||
|
+ group == shared || group == format!("{}.*", prefix)) {
|
||||||
|
+ bail!("Apple's provisioning profile does not permit the MusicBridge shared Keychain group");
|
||||||
|
+ }
|
||||||
|
+ let mut result = profile.clone();
|
||||||
|
+ // A concrete per-app default group comes first, shared group second.
|
||||||
|
+ result.insert("keychain-access-groups".into(), plist::Value::Array(vec![
|
||||||
|
+ plist::Value::String(application.into()), plist::Value::String(shared)]));
|
||||||
|
+ Ok(result)
|
||||||
|
+}
|
||||||
|
+
|
||||||
|
+#[cfg(test)]
|
||||||
|
+mod musicbridge_tests {
|
||||||
|
+ use super::*;
|
||||||
|
+ fn profile(group: &str) -> Dictionary {
|
||||||
|
+ let mut p = Dictionary::new();
|
||||||
|
+ p.insert("application-identifier".into(), "TEAM.ru.yukinoki.musicbridge.TEAM".into());
|
||||||
|
+ p.insert("keychain-access-groups".into(), plist::Value::Array(vec![group.into()]));
|
||||||
|
+ p
|
||||||
|
+ }
|
||||||
|
+ #[test]
|
||||||
|
+ fn musicbridge_sharing_respects_profile() {
|
||||||
|
+ let value = musicbridge_keychain(&profile("TEAM.*")).unwrap();
|
||||||
|
+ let groups = value["keychain-access-groups"].as_array().unwrap();
|
||||||
|
+ assert_eq!(groups[0].as_string(), Some("TEAM.ru.yukinoki.musicbridge.TEAM"));
|
||||||
|
+ assert_eq!(groups[1].as_string(), Some("TEAM.ru.yukinoki.musicbridge.remote-control"));
|
||||||
|
+ assert!(musicbridge_keychain(&profile("OTHER.*")).is_err());
|
||||||
|
+ assert!(musicbridge_keychain(&profile("TEAM.unrelated")).is_err());
|
||||||
|
+ }
|
||||||
|
+}
|
||||||
@@ -0,0 +1,33 @@
|
|||||||
|
"""Apply reviewed patches to pinned upstream checkouts. No Apple credentials involved."""
|
||||||
|
import json
|
||||||
|
from pathlib import Path
|
||||||
|
import subprocess
|
||||||
|
import sys
|
||||||
|
|
||||||
|
root = Path(sys.argv[1]).resolve()
|
||||||
|
patches = Path(__file__).resolve().parent
|
||||||
|
versions = {
|
||||||
|
"iloader": "348eefd7de78e9bc612c9d619b8b1e7a80ba3ba0",
|
||||||
|
"isideload": "f6a4d5dba717d72fc2af63eaba26b27ba44116be",
|
||||||
|
"apple-crates": "5da0b8df9b202434b1eff2700059b1ee142592ac",
|
||||||
|
}
|
||||||
|
for name, commit in versions.items():
|
||||||
|
path = root / name
|
||||||
|
actual = subprocess.check_output(["git", "-C", str(path), "rev-parse", "HEAD"], text=True).strip()
|
||||||
|
if actual != commit:
|
||||||
|
raise RuntimeError(f"Unexpected {name} revision: {actual}")
|
||||||
|
for name, patch in [("isideload", "isideload.patch"), ("apple-crates", "apple-codesign.patch")]:
|
||||||
|
subprocess.run(["git", "-C", str(root/name), "apply", "--check", str(patches/patch)], check=True)
|
||||||
|
subprocess.run(["git", "-C", str(root/name), "apply", str(patches/patch)], check=True)
|
||||||
|
|
||||||
|
manifest = root / "iloader/src-tauri/Cargo.toml"
|
||||||
|
with manifest.open("a", encoding="utf-8") as file:
|
||||||
|
file.write('\n[patch."https://github.com/nab138/isideload"]\nisideload = { path = "../../isideload/isideload" }\n')
|
||||||
|
file.write('\n[patch."https://github.com/nab138/apple-crates"]\napple-codesign = { path = "../../apple-crates/apple-codesign-quick" }\n')
|
||||||
|
# Portable helper: preserve upstream identifier/storage so existing Apple login can
|
||||||
|
# be reused locally. Use a distinct title and disable upstream update replacement.
|
||||||
|
config = root / "iloader/src-tauri/ci.conf.json"
|
||||||
|
value = json.loads(config.read_text(encoding="utf-8"))
|
||||||
|
value["app"] = {"windows": [{"title": "iloader — MusicBridge compatibility build", "width": 800, "height": 600}]}
|
||||||
|
config.write_text(json.dumps(value, indent=2), encoding="utf-8")
|
||||||
|
print("Patched pinned iloader, extension discovery, nested signing and profile-checked Keychain sharing.")
|
||||||
Reference in New Issue
Block a user