turns out ldid can already do this...

This commit is contained in:
zx
2024-09-18 22:02:51 -04:00
parent edd34f6713
commit 91494bc3a3
3 changed files with 7 additions and 25 deletions

View File

@@ -61,8 +61,8 @@ def main(parser: ArgumentParser) -> None:
app.plist.change_minimum_version(args.m) app.plist.change_minimum_version(args.m)
if args.k is not None: if args.k is not None:
app.change_icon(args.k, tmpdir) app.change_icon(args.k, tmpdir)
if args.x is not None: # `validate_inputs()` made it a dict if args.x is not None:
app.executable.merge_entitlements(args.x, tmpdir) app.executable.merge_entitlements(args.x)
if args.remove_supported_devices: if args.remove_supported_devices:
app.plist.remove_uisd() app.plist.remove_uisd()

View File

@@ -1,9 +1,6 @@
import os import os
import shutil import shutil
import plistlib
import subprocess import subprocess
from typing import Any
from plistlib import dump as pdump
from cyan import tbhutils from cyan import tbhutils
from .executable import Executable from .executable import Executable
@@ -98,27 +95,12 @@ class MainExecutable(Executable):
self.sign_with_entitlements(ENT_PATH) self.sign_with_entitlements(ENT_PATH)
print("[*] restored entitlements") print("[*] restored entitlements")
def merge_entitlements( def merge_entitlements(self, entitlements: str) -> None:
self, entitlements: dict[str, Any], tmpdir: str self.sign_with_entitlements(entitlements)
) -> None: print("[*] merged new entitlements")
ENT_PATH = f"{tmpdir}/new.entitlements"
existing: dict[str, Any]
if self.write_entitlements(ENT_PATH): # has entitlements
with open(ENT_PATH, "rb") as f:
existing = plistlib.load(f)
else:
existing = {}
new = existing | entitlements
with open(ENT_PATH, "wb") as f2:
pdump(new, f2)
self.sign_with_entitlements(ENT_PATH)
print("[*] modified entitlement keys:", ", ".join(entitlements))
def sign_with_entitlements(self, entitlements: str) -> bool: def sign_with_entitlements(self, entitlements: str) -> bool:
return subprocess.run( return subprocess.run(
[self.ldid, f"-S{entitlements}", self.path] [self.ldid, f"-S{entitlements}", "-M", self.path]
).returncode == 0 ).returncode == 0

View File

@@ -75,7 +75,7 @@ def validate_inputs(args: Namespace) -> Optional[str]:
try: try:
with open(args.x, "rb") as f: with open(args.x, "rb") as f:
args.x = pload(f) pload(f)
except Exception: except Exception:
sys.exit("[!] couldn't parse given entitlements file") sys.exit("[!] couldn't parse given entitlements file")