29 Commits
v1.1 ... v1.2.2

Author SHA1 Message Date
zx
4e05892e1d chore: bump version to v1.2.2 2024-10-12 14:56:32 -04:00
zx
54359e0935 fix: don't zip hidden files (lol @whoeevee) 2024-10-12 14:53:42 -04:00
zx
46752d0a26 chore: update orion to v1.0.2 2024-09-30 20:16:19 -04:00
zx
ce20baae4a chore: bump version to v1.2.1
fuck my life
2024-09-18 22:03:48 -04:00
zx
91494bc3a3 turns out ldid can already do this... 2024-09-18 22:02:51 -04:00
zx
edd34f6713 chore: bump version to v1.2 2024-09-18 21:45:21 -04:00
zx
c1c0b2294e feat, refactor: entitlement merging, MainExecutable 2024-09-18 21:39:02 -04:00
zx
2d16015c78 chore: bump version to v1.1.6 2024-09-16 20:26:37 -04:00
zx
4c979a91e7 template: grammar?
idrk
2024-09-16 20:25:55 -04:00
zx
b4aa6c9b69 chore: use enhancement label 2024-09-16 20:24:13 -04:00
zx
246f6ace80 docs: recommended flags
also issue templates
2024-09-16 20:23:19 -04:00
zx
511cb4bbe3 chore: use unzip and zip when available 2024-09-16 20:07:23 -04:00
zx
d1c3bc6908 chore: bump version to v1.1.5 2024-09-15 15:17:40 -04:00
zx
8fe0fc2984 fix: plist changing operations (#3)
lol, this is so fucking stupid, i was trying to fix #3 but also found that `Plist.change()` was being used incorrectly EVERYWHERE in cyan, LMAO

slight oversight since i forgot i had even changed its usage, but at least it's fixed now
2024-09-15 15:16:43 -04:00
zx
e315454544 docs: acknowledgements 2024-09-14 21:01:04 -04:00
zx
9072c91965 docs(install): remove ensurepath step 2024-09-14 20:51:06 -04:00
zx
06a2ea8dad chore: bump version to v1.1.4 2024-09-13 18:28:35 -04:00
zx
55b2ec9d07 fix: folders ending in / 2024-09-13 18:27:45 -04:00
zx
52b3b11a1a chore: use insert_dylib on more platforms 2024-09-13 18:07:00 -04:00
zx
4375b7f880 docs: update install instructions 2024-09-11 17:33:40 -04:00
zx
8f7db1438a chore: bump version to v1.1.3 2024-09-11 07:15:47 -04:00
zx
5e08afc0ac fix(cgen): folders ending in / 2024-09-11 07:14:50 -04:00
zx
0bd6393e78 chore: bundle cgen 2024-09-10 17:35:42 -04:00
zx
f5a5d7b5ed fix: sub-bundle detection 2024-09-10 17:23:30 -04:00
zx
c3a51e7e03 docs: update install instructions 2024-09-10 16:30:51 -04:00
zx
806db413e2 fix: crashing when jailbroken
i realized azule actually removes the signature (instead of fakesigning) before specific operations, maybe this is the fix?
2024-09-10 07:11:15 -04:00
zx
927df65b55 Merge branch 'main' of github.com:asdfzxcvbn/pyzule-rw 2024-09-09 19:37:24 -04:00
zx
851eedf629 fix: using wrong ldid 2024-09-09 19:36:38 -04:00
zx
126d17924b docs: feature requests 2024-09-09 10:32:34 -04:00
21 changed files with 471 additions and 178 deletions

22
.github/ISSUE_TEMPLATE/bug.yaml vendored Normal file
View File

@@ -0,0 +1,22 @@
# thanks to uYouEnhanced for the issue template:
# https://github.com/arichornlover/uYouEnhanced/blob/main/.github/ISSUE_TEMPLATE/bug.yaml?plain=1
name: bug
description: report a bug in cyan
title: "[bug] "
labels: bug
body:
- type: checkboxes
attributes:
label: have you searched the existing issues?
options:
- label: this is a unique issue. i agree that if this isn't a unique issue, i'll be BLOCKED from the cyan repo
required: true
- type: textarea
attributes:
label: describe the bug.
description: attach videos or screenshots if possible
validations:
required: true

View File

@@ -0,0 +1,22 @@
# thanks to uYouEnhanced for the issue template:
# https://github.com/arichornlover/uYouEnhanced/blob/main/.github/ISSUE_TEMPLATE/bug.yaml?plain=1
name: feature request
description: request a feature to be added to cyan
title: "[feature request] "
labels: enhancement
body:
- type: checkboxes
attributes:
label: have you searched the existing issues?
options:
- label: this is a unique feature request. i agree that if this isn't a unique request, i'll be BLOCKED from the cyan repo
required: true
- type: textarea
attributes:
label: describe the feature request.
description: what exactly are you requesting? can you provide an example where this would be useful?
validations:
required: true

View File

@@ -2,13 +2,11 @@
a rewrite of [pyzule](https://github.com/asdfzxcvbn/pyzule) that doesn't (completely) suck !!
cyan supports **linux, macOS, WSL, and jailbroken iOS!** all either x86_64 or arm64/aarch64 !!
## features
more coming soon! i'm trying to copy pyzule in order to deprecate it in favor of cyan, which is 1000x better
you can open an issue to request a feature :D !! also see my [recommended flags](https://github.com/asdfzxcvbn/pyzule-rw/wiki/recommended-flags)
- generate and use [shareable .cyan files](https://github.com/asdfzxcvbn/cyan-gen) to configure IPAs!
- generate and use shareable .cyan files to configure IPAs!
- inject deb, dylib, framework, bundle, and appex files/folders
- automatically fix dependencies on CydiaSubstrate **(cyan uses [ElleKit](https://github.com/evelyneee/ellekit/)!)**, Cephei*, and Orion
- copy any unknown file/folder types to app root
@@ -17,43 +15,49 @@ more coming soon! i'm trying to copy pyzule in order to deprecate it in favor of
- remove watch app
- change the app icon
- fakesign the output ipa/app
- add custom entitlements to the main executable
- thin all binaries to arm64, it can LARGELY reduce app size sometimes!
- remove all app extensions (or just encrypted ones!)
## install instructions
cyan supports **linux, macOS, WSL, and jailbroken iOS!** all either x86_64 or arm64/aarch64 !!
first, make sure you have [ar](https://command-not-found.com/ar) and [tar](https://command-not-found.com/tar) installed
also obviously install python, version 3.9 or greater is required (the version available on the procursus repo for iOS)
also obviously install python, version 3.9 or greater is required
**if you want to inject dylibs AND ARE NOT ON iOS,** make sure you install lief (you only have to do this once): `pip install -U lief`
the `zip` and `unzip` commands are *optional* dependencies, they may [fix issues when extracting certain IPAs with chinese characters](https://github.com/asdfzxcvbn/pyzule-rw/wiki/file-does-not-exist-(executable)-%3F), etc
**if you want to change app icons (iOS NOT supported),** also make sure you install pillow: `pip install Pillow`
<details>
<summary><b>linux/WSL/macOS instructions</b></summary>
<br/>
<ol>
<li>install <a href="https://github.com/pypa/pipx?tab=readme-ov-file#install-pipx">pipx</a></li>
<li>install OR update cyan: <code>pipx install --force https://github.com/asdfzxcvbn/pyzule-rw/archive/main.zip</code></li>
<li><b>if you want to inject dylibs ON AARCH64 LINUX</b>: <code>pipx inject cyan lief</code></li>
<li><b>if you want to change app icons (iOS NOT supported)</b>: <code>pipx inject cyan Pillow</code></li>
</ol>
</details>
then finally, to install or update cyan, just `pip install --force-reinstall git+https://github.com/asdfzxcvbn/pyzule-rw.git#egg=cyan`
<details>
<summary><b>jailbroken iOS instructions / automated environment (github workflow, etc)</b></summary>
<br/>
<ol>
<li>install OR update cyan: <code>pip install --force-reinstall https://github.com/asdfzxcvbn/pyzule-rw/archive/main.zip</code></li>
</ol>
</details>
note: if you installed cyan before v1.1.3 using `pip`, make sure you `pip uninstall cyan`, then verify you have the latest version with `cyan --version`
## making cyan files
cyan comes bundled with the `cgen` command, which lets you generate `.cyan` files to pass to `-z`/`--cyan` !
## acknowledgements
- [Al4ise](https://github.com/Al4ise) for the original [Azule](https://github.com/Al4ise/Azule)
- [lief-project](https://github.com/lief-project) for [LIEF](https://github.com/lief-project/LIEF)
### todo
[x] refactor: dont prepare, just copy and fix as you go
[x] feat: plist operations (-l and -r wont be implemented)
[x] feat: remove watch app
[x] feat: fakesign
[x] feat: thin binaries
[x] feat: plugin operations (-q, -e)
[x] feat: change app icon
[x] feat: .cyan files (lol rip .pyzule files)
:D
- [tyilo](https://github.com/tyilo) for [insert_dylib](https://github.com/tyilo/insert_dylib/) (macOS/iOS)
- [LeanVel](https://github.com/LeanVel) for [insert_dylib](https://github.com/LeanVel/insert_dylib) (linux)

142
cgen/__main__.py Normal file
View File

@@ -0,0 +1,142 @@
import os
import sys
import json
import zipfile
import argparse
def main() -> None:
if sys.platform == "win32":
sys.exit("[!] windows is not supported")
parser = argparse.ArgumentParser(
description="a tool to generate .cyan files"
)
parser.add_argument(
"-o", "--output", metavar="output", required=True,
help="output of the .cyan file"
)
parser.add_argument(
"-f", metavar="file", nargs="+",
help="a tweak to inject/item to be added to the bundle"
)
parser.add_argument(
"-n", metavar="name",
help="modify the app's name"
)
parser.add_argument(
"-v", metavar="version",
help="modify the app's version"
)
parser.add_argument(
"-b", metavar="bundle id",
help="modify the app's bundle id"
)
parser.add_argument(
"-m", metavar="minimum",
help="modify the app's minimum OS version"
)
parser.add_argument(
"-k", metavar="icon",
help="modify the app's icon"
)
parser.add_argument(
"-u", "--remove-supported-devices", action="store_true",
help="remove UISupportedDevices"
)
parser.add_argument(
"-w", "--no-watch", action="store_true",
help="remove all watch apps"
)
parser.add_argument(
"-d", "--enable-documents", action="store_true",
help="enable documents support"
)
parser.add_argument(
"-s", "--fakesign", action="store_true",
help="fakesign all binaries for use with appsync/trollstore"
)
parser.add_argument(
"-q", "--thin", action="store_true",
help="thin all binaries to arm64, may largely reduce size"
)
parser.add_argument(
"-e", "--remove-extensions", action="store_true",
help="remove all app extensions"
)
parser.add_argument(
"-g", "--remove-encrypted", action="store_true",
help="only remove encrypted app extensions"
)
generate_cyan(parser)
def generate_cyan(parser: argparse.ArgumentParser) -> None:
args = parser.parse_args()
# input validation
if args.m is not None and any(c not in "0123456789." for c in args.m):
parser.error(f"invalid minimum OS version: {args.m}")
if args.k is not None and not os.path.isfile(args.k):
parser.error(f"{args.k} does not exist")
if args.f is not None:
fake = [f for f in args.f if not os.path.exists(f)]
# it would be great if everyone was using python 3.12 !!!
if len(fake) != 0:
parser.error(f"the following file(s) do not exist: {', '.join(fake)}")
if not args.output.endswith(".cyan"):
print("[*] appended cyan file extension to output")
args.output += ".cyan"
if os.path.isfile(args.output):
try:
overwrite = input(
f"[<] {args.output} already exists. overwrite? [Y/n] "
).lower().strip()
except KeyboardInterrupt:
sys.exit("\n[?] guess not")
if overwrite not in ("y", "yes", ""):
sys.exit("[>] quitting.")
real_args = {k: v for k, v in dict(vars(args)).items() if v}
del real_args["output"]
for key in "fk": # these need files
if key in real_args:
real_args[key] = True
print("[*] generating..")
with zipfile.ZipFile(
args.output, "w", zipfile.ZIP_DEFLATED, compresslevel=1
) as zf:
with zf.open("config.json", "w") as f:
f.write(json.dumps(real_args).encode())
if args.f is not None:
for f in args.f:
if os.path.isfile(f):
zf.write(f, f"inject/{os.path.basename(f)}")
else: # G YHUJMNFTGYHNFTGYHTGYHUT6Y7UJM8RFTYHNR564TY
if f.endswith("/"):
f = f[:-1] # yes this is needed to prevent a bug wtf
for dp, _, files in os.walk(f):
for f2 in files:
thing = f"{dp}/{f2}"
zf.write(
thing,
f"inject/{os.path.relpath(thing, os.path.dirname(f))}"
) # no, i don't know what this is doing.
if args.k is not None:
zf.write(args.k, "icon.idk")
if __name__ == "__main__":
main()

View File

@@ -50,6 +50,10 @@ def main() -> None:
"-k", metavar="icon",
help="modify the app's icon"
)
parser.add_argument(
"-x", metavar="entitlements",
help="add or modify entitlements to the main binary"
)
parser.add_argument(
"-u", "--remove-supported-devices", action="store_true",
@@ -95,7 +99,7 @@ def main() -> None:
)
parser.add_argument(
"--version", action="version", version="cyan v1.0"
"--version", action="version", version="cyan v1.2.2"
)
from cyan import logic

View File

@@ -4,24 +4,34 @@
<dict>
<key>CFBundleDevelopmentRegion</key>
<string>English</string>
<key>CFBundleExecutable</key>
<string>Cephei</string>
<key>CFBundleIdentifier</key>
<string>ws.hbang.common</string>
<key>CFBundleInfoDictionaryVersion</key>
<string>6.0</string>
<key>CFBundleName</key>
<string>Cephei</string>
<key>CFBundlePackageType</key>
<string>BNDL</string>
<key>CFBundleShortVersionString</key>
<string>1.0.0</string>
<key>CFBundleSignature</key>
<string>????</string>
<key>CFBundleVersion</key>
<string>1.0</string>
<key>DTPlatformName</key>
<string>iphoneos</string>
<key>HBPackageIdentifier</key>
<string>ws.hbang.common</string>
</dict>

View File

@@ -4,26 +4,37 @@
<dict>
<key>CFBundleDevelopmentRegion</key>
<string>English</string>
<key>CFBundleExecutable</key>
<string>CepheiPrefs</string>
<key>CFBundleIdentifier</key>
<string>ws.hbang.common.prefs</string>
<key>CFBundleInfoDictionaryVersion</key>
<string>6.0</string>
<key>CFBundleName</key>
<string>Cephei</string>
<key>CFBundlePackageType</key>
<string>BNDL</string>
<key>CFBundleShortVersionString</key>
<string>1.0.0</string>
<key>CFBundleSignature</key>
<string>????</string>
<key>CFBundleVersion</key>
<string>1.0</string>
<key>DTPlatformName</key>
<string>iphoneos</string>
<key>HBPackageIdentifier</key>
<string>ws.hbang.common</string>
<key>NSPrincipalClass</key>
<string>HBDemoRootListController</string>
</dict>

View File

@@ -12,7 +12,7 @@
<string>Orion</string>
<key>CFBundleShortVersionString</key>
<string>1.0.1</string>
<string>1.0.2</string>
<key>CFBundleVersion</key>
<string>1</string>

Binary file not shown.

View File

@@ -61,6 +61,8 @@ def main(parser: ArgumentParser) -> None:
app.plist.change_minimum_version(args.m)
if args.k is not None:
app.change_icon(args.k, tmpdir)
if args.x is not None:
app.executable.merge_entitlements(args.x)
if args.remove_supported_devices:
app.plist.remove_uisd()
@@ -86,6 +88,6 @@ def main(parser: ArgumentParser) -> None:
if os.path.isdir(args.o):
shutil.rmtree(args.o)
shutil.move(app_path, args.o)
shutil.move(app.path, args.o)
print(f"[*] generated app at {args.o}")

View File

@@ -1,12 +1,14 @@
from .app_bundle import AppBundle
from .executable import Executable
from .leaving_cm import LeavingCM
from .main_executable import MainExecutable
from .plist import Plist
__all__ = [
"AppBundle",
"Executable",
"LeavingCM",
"MainExecutable",
"Plist"
]

View File

@@ -5,6 +5,7 @@ from uuid import uuid4
from typing import Optional, Literal
from .executable import Executable
from .main_executable import MainExecutable
from .plist import Plist
class AppBundle:
@@ -12,7 +13,7 @@ class AppBundle:
self.path = path
self.plist = Plist(f"{path}/Info.plist", path)
self.executable = Executable(
self.executable = MainExecutable(
f"{path}/{self.plist['CFBundleExecutable']}",
path
)

View File

@@ -1,6 +1,5 @@
import os
import sys
import shutil
import subprocess
from typing import Optional
@@ -18,6 +17,7 @@ class Executable:
ldid = f"{specific}/ldid"
lipo = f"{specific}/lipo"
otool = f"{specific}/otool"
idylib = f"{specific}/insert_dylib"
starters = ("\t/Library/", "\t@rpath", "\t@executable_path")
common = {
@@ -32,20 +32,24 @@ class Executable:
"CepheiPrefs.framework": "CepheiPrefs.framework"
}
def __init__(self, path: str, bundle_path: Optional[str] = None):
def __init__(self, path: str):
if not os.path.isfile(path):
sys.exit(f"[!] {path} does not exist (executable)")
print(f"[!] {path} does not exist (executable)", file=sys.stderr)
sys.exit(
"[?] check the wiki for info: "
"https://github.com/asdfzxcvbn/pyzule-rw/wiki/"
"file-does-not-exist-(executable)-%3F"
)
self.path = path
self.bundle_path = bundle_path
self.bn = os.path.basename(path)
self.inj: Optional = None # type: ignore
if self.specific.endswith("iOS"):
self.inj_func = self.ios_inject
if os.path.isfile(self.idylib):
self.inj_func = self.idyl_inject
else:
self.inj_func = self.insert_cmd
self.inj_func = self.lief_inj
def is_encrypted(self) -> bool:
proc = subprocess.run(
@@ -55,16 +59,14 @@ class Executable:
return b"cryptid 1" in proc.stdout
def inject(self, tweaks: dict[str, str], tmpdir: str) -> None:
# we only inject into the main executable
assert self.bundle_path is not None
def remove_signature(self) -> None:
subprocess.run([self.ldid, "-R", self.path], stderr=subprocess.DEVNULL)
has_entitlements = False
ENT_PATH = f"{self.bundle_path}/cyan.entitlements"
PLUGINS_DIR = f"{self.bundle_path}/PlugIns"
FRAMEWORKS_DIR = f"{self.bundle_path}/Frameworks"
def fakesign(self) -> bool:
return subprocess.run([self.ldid, "-S", "-M", self.path]).returncode == 0
with open(ENT_PATH, "wb") as entf:
def write_entitlements(self, output: str) -> bool:
with open(output, "wb") as entf:
proc = subprocess.run(
[self.ldid, "-e", self.path],
capture_output=True
@@ -72,95 +74,7 @@ class Executable:
entf.write(proc.stdout)
if os.path.getsize(ENT_PATH) > 0:
has_entitlements = True
# iirc, injecting doesnt work (sometimes) if the file isn't signed
self.fakesign(False)
if any(t.endswith(".appex") for t in tweaks):
os.makedirs(PLUGINS_DIR, exist_ok=True)
if any(
t.endswith(k)
for t in tweaks
for k in (".deb", ".dylib", ".framework")
):
os.makedirs(FRAMEWORKS_DIR, exist_ok=True)
# some apps really dont have this lol
subprocess.run(
[self.nt, "-add_rpath", "@executable_path/Frameworks", self.path],
stderr=subprocess.DEVNULL
)
# `extract_deb()` will modify `tweaks`, which is why we make a copy
cwd = os.getcwd()
for bn, path in dict(tweaks).items():
if bn.endswith(".deb"):
tbhutils.extract_deb(path, tweaks, tmpdir)
continue
os.chdir(cwd) # i fucking hate jailbroken iOS utils.
needed: set[str] = set()
for bn, path in tweaks.items():
if bn.endswith(".appex"):
fpath = f"{PLUGINS_DIR}/{bn}"
existed = tbhutils.delete_if_exists(fpath, bn)
shutil.copytree(path, fpath)
elif bn.endswith(".dylib"):
path = shutil.copy2(path, tmpdir)
Executable(path).fix_dependencies(tweaks, needed)
fpath = f"{FRAMEWORKS_DIR}/{bn}"
existed = tbhutils.delete_if_exists(fpath, bn)
self.inj_func(f"@rpath/{bn}")
shutil.move(path, FRAMEWORKS_DIR)
elif bn.endswith(".framework"):
fpath = f"{FRAMEWORKS_DIR}/{bn}"
existed = tbhutils.delete_if_exists(fpath, bn)
self.inj_func(f"@rpath/{bn}/{bn[:-10]}")
shutil.copytree(path, fpath)
else:
fpath = f"{self.bundle_path}/{bn}"
existed = tbhutils.delete_if_exists(fpath, bn)
try:
shutil.copytree(path, fpath)
except NotADirectoryError:
shutil.copy2(path, self.bundle_path)
if not existed:
print(f"[*] injected {bn}")
# orion has a *weak* dependency to substrate,
# but will still crash without it. nice !!!!!!!!!!!
if "Orion.framework" in needed:
needed.add("CydiaSubstrate.framework")
for missing in needed:
real = self.common[missing] # "real" name, thanks substrate!
ip = f"{FRAMEWORKS_DIR}/{real}"
existed = tbhutils.delete_if_exists(ip, real)
shutil.copytree(f"{self.install_dir}/extras/{real}", ip)
if not existed:
print(f"[*] auto-injected {real}")
# FINALLY !!
if self.inj is not None: # type: ignore
self.inj.write(self.path) # type: ignore
if has_entitlements:
subprocess.run(["ldid", f"-S{ENT_PATH}", self.path])
print("[*] restored entitlements")
def fakesign(self, keep_entitlements: bool = True) -> bool:
cmd = [self.ldid, "-S"]
if keep_entitlements:
cmd.append("-M")
subprocess.run(cmd + [self.path])
return True
return os.path.getsize(output) > 0
def thin(self) -> bool:
return subprocess.run(
@@ -174,7 +88,7 @@ class Executable:
stderr=subprocess.DEVNULL
)
def insert_cmd(self, cmd: str) -> None:
def lief_inj(self, cmd: str) -> None:
if self.inj is None: # type: ignore
try:
lief.logging.disable() # type: ignore
@@ -183,19 +97,24 @@ class Executable:
self.inj = lief.parse(self.path) # type: ignore
try:
self.inj.add(lief.MachO.DylibCommand.weak_lib(cmd)) # type: ignore
except AttributeError:
sys.exit("[!] couldn't add LC (lief), did you use a valid app?")
def ios_inject(self, cmd: str) -> None:
subprocess.run(
def idyl_inject(self, cmd: str) -> None:
proc = subprocess.run(
[
f"{self.specific}/insert_dylib",
"--weak", "--inplace", "--no-strip-codesig", "--all-yes",
self.idylib, "--weak", "--inplace", "--strip-codesig", "--all-yes",
cmd, self.path
], stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL
], capture_output=True, text=True
)
if proc.returncode != 0:
sys.exit(f"[!] couldn't add LC (insert_dylib), error:\n{proc.stderr}")
def fix_dependencies(self, tweaks: dict[str, str], need: set[str]) -> None:
self.fakesign() # sometimes it doesnt work if we dont do this
self.remove_signature()
for dep in self.get_dependencies():
for cname in (tweaks | self.common):

View File

@@ -0,0 +1,106 @@
import os
import shutil
import subprocess
from cyan import tbhutils
from .executable import Executable
class MainExecutable(Executable):
def __init__(self, path: str, bundle_path: str):
super().__init__(path)
self.bundle_path = bundle_path
def inject(self, tweaks: dict[str, str], tmpdir: str) -> None:
ENT_PATH = f"{self.bundle_path}/cyan.entitlements"
PLUGINS_DIR = f"{self.bundle_path}/PlugIns"
FRAMEWORKS_DIR = f"{self.bundle_path}/Frameworks"
has_entitlements = self.write_entitlements(ENT_PATH)
# iirc, injecting doesnt work (sometimes) if the file isn't signed
self.remove_signature()
if any(t.endswith(".appex") for t in tweaks):
os.makedirs(PLUGINS_DIR, exist_ok=True)
if any(
t.endswith(k)
for t in tweaks
for k in (".deb", ".dylib", ".framework")
):
os.makedirs(FRAMEWORKS_DIR, exist_ok=True)
# some apps really dont have this lol
subprocess.run(
[self.nt, "-add_rpath", "@executable_path/Frameworks", self.path],
stderr=subprocess.DEVNULL
)
# `extract_deb()` will modify `tweaks`, which is why we make a copy
cwd = os.getcwd()
for bn, path in dict(tweaks).items():
if bn.endswith(".deb"):
tbhutils.extract_deb(path, tweaks, tmpdir)
continue
os.chdir(cwd) # i fucking hate jailbroken iOS utils.
needed: set[str] = set()
for bn, path in tweaks.items():
if bn.endswith(".appex"):
fpath = f"{PLUGINS_DIR}/{bn}"
existed = tbhutils.delete_if_exists(fpath, bn)
shutil.copytree(path, fpath)
elif bn.endswith(".dylib"):
path = shutil.copy2(path, tmpdir)
Executable(path).fix_dependencies(tweaks, needed)
fpath = f"{FRAMEWORKS_DIR}/{bn}"
existed = tbhutils.delete_if_exists(fpath, bn)
self.inj_func(f"@rpath/{bn}")
shutil.move(path, FRAMEWORKS_DIR)
elif bn.endswith(".framework"):
fpath = f"{FRAMEWORKS_DIR}/{bn}"
existed = tbhutils.delete_if_exists(fpath, bn)
self.inj_func(f"@rpath/{bn}/{bn[:-10]}")
shutil.copytree(path, fpath)
else:
fpath = f"{self.bundle_path}/{bn}"
existed = tbhutils.delete_if_exists(fpath, bn)
try:
shutil.copytree(path, fpath)
except NotADirectoryError:
shutil.copy2(path, self.bundle_path)
if not existed:
print(f"[*] injected {bn}")
# orion has a *weak* dependency to substrate,
# but will still crash without it. nice !!!!!!!!!!!
if "Orion.framework" in needed:
needed.add("CydiaSubstrate.framework")
for missing in needed:
real = self.common[missing] # "real" name, thanks substrate!
ip = f"{FRAMEWORKS_DIR}/{real}"
existed = tbhutils.delete_if_exists(ip, real)
shutil.copytree(f"{self.install_dir}/extras/{real}", ip)
if not existed:
print(f"[*] auto-injected {real}")
# FINALLY !!
if self.inj is not None: # type: ignore
self.inj.write(self.path) # type: ignore
if has_entitlements:
self.sign_with_entitlements(ENT_PATH)
print("[*] restored entitlements")
def merge_entitlements(self, entitlements: str) -> None:
self.sign_with_entitlements(entitlements)
print("[*] merged new entitlements")
def sign_with_entitlements(self, entitlements: str) -> bool:
return subprocess.run(
[self.ldid, f"-S{entitlements}", "-M", self.path]
).returncode == 0

View File

@@ -44,6 +44,7 @@ class Plist:
try:
if all(self[key] == val for key in keys):
return False
raise KeyError # lets pretend this was always here..
except KeyError:
for key in keys:
self[key] = val
@@ -67,15 +68,14 @@ class Plist:
print("[?] documents support was already enabled")
def change_name(self, name: str) -> None:
if self.change("CFBundleName", "CFBundleDisplayName", name):
if self.change(name, "CFBundleName", "CFBundleDisplayName"):
print(f"[*] changed name to \"{name}\"")
changed = 0
for lproj in glob(f"{self.app_path}/*.lproj"):
try:
pl = Plist(f"{lproj}/InfoPlist.strings", None, False)
pl["CFBundleDisplayName"] = name
pl["CFBundleName"] = name
pl.change(name, "CFBundleName", "CFBundleDisplayName")
pl.save()
changed += 1
except Exception:
@@ -87,7 +87,7 @@ class Plist:
print(f"[?] name was already \"{name}\"")
def change_version(self, version: str) -> None:
if self.change("CFBundleVersion", "CFBundleShortVersionString", version):
if self.change(version, "CFBundleVersion", "CFBundleShortVersionString"):
print(f"[*] changed version to \"{version}\"")
else:
print(f"[?] version was already \"{version}\"")
@@ -95,7 +95,7 @@ class Plist:
def change_bundle_id(self, bundle_id: str) -> None:
orig = self["CFBundleIdentifier"]
if self.change("CFBundleIdentifier", bundle_id):
if self.change(bundle_id, "CFBundleIdentifier"):
print(f"[*] changed bundle id to \"{bundle_id}\"")
changed = 0
@@ -116,7 +116,7 @@ class Plist:
print(f"[?] bundle id was already \"{bundle_id}\"")
def change_minimum_version(self, minimum: str) -> None:
if self.change("MinimumOSVersion", minimum):
if self.change(minimum, "MinimumOSVersion"):
print(f"[*] changed minimum version to \"{minimum}\"")
else:
print(f"[?] minimum version was already \"{minimum}\"")

View File

@@ -9,6 +9,10 @@ from uuid import uuid4
from glob import glob, iglob
from argparse import Namespace
from typing import Optional, Any
from plistlib import load as pload
HAS_ZIP = shutil.which("zip") is not None
HAS_UNZIP = shutil.which("unzip") is not None
def validate_inputs(args: Namespace) -> Optional[str]:
@@ -39,15 +43,19 @@ def validate_inputs(args: Namespace) -> Optional[str]:
sys.exit(0)
if args.f is not None:
# dictionary ensures unique names
args.f = {os.path.basename(f): os.path.realpath(f) for f in args.f}
nonexistent = [f for f in args.f.values() if not os.path.exists(f)]
new: dict[str, str] = {} # dictionary ensures unique names
if len(nonexistent) != 0:
print("[!] please ensure the following file(s) exist:")
for ne in nonexistent:
print(f"[?] - {ne}")
sys.exit(1)
for f in list(args.f):
if f[-1] == "/": # yeah this is stupid
f = f[:-1]
if not os.path.exists(f):
sys.exit(f"[!] \"{f}\" does not exist")
new[os.path.basename(f)] = os.path.realpath(f)
# i would've modified args.f directly, but it causes type-hinting error :(
args.f = new
if (
args.m is not None
@@ -61,6 +69,16 @@ def validate_inputs(args: Namespace) -> Optional[str]:
if args.cyan is not None and not os.path.isfile(args.cyan):
sys.exit(f"[!] {args.cyan} does not exist")
if args.x is not None:
if not os.path.isfile(args.x):
sys.exit(f"[!] {args.x} does not exist")
try:
with open(args.x, "rb") as f:
pload(f)
except Exception:
sys.exit("[!] couldn't parse given entitlements file")
def get_app(path: str, tmpdir: str, is_ipa: bool) -> str:
payload = f"{tmpdir}/Payload"
@@ -77,7 +95,15 @@ def get_app(path: str, tmpdir: str, is_ipa: bool) -> str:
elif not any(name.endswith(".app/Info.plist") for name in names):
sys.exit("[!] no Info.plist, invalid app")
# using unzip fixes extraction errors in ipas with chinese chars, etc
if HAS_UNZIP:
subprocess.run(
["unzip", path, "-d", tmpdir],
stdout=subprocess.DEVNULL
)
else:
ipa.extractall(tmpdir)
app = glob(f"{payload}/*.app")[0]
except (KeyError, IndexError):
sys.exit("[!] couldn't find either Payload or app folder, invalid ipa")
@@ -106,11 +132,12 @@ def get_tools_dir() -> tuple[str, str]:
# thank god i dont have to use importlib,
# it's the WORST standard library package prior to 3.12
install_dir = os.path.dirname(__file__)
specific_dir = f"{install_dir}/tools/{system}/{mach}"
return (
install_dir,
f"{install_dir}/tools/{system}/{mach}"
)
if not os.path.isdir(specific_dir):
sys.exit(f"[!] cyan is not supported on: {system} {mach}")
return (install_dir, specific_dir)
def delete_if_exists(path: str, bn: str) -> bool:
@@ -153,12 +180,16 @@ def extract_deb(deb: str, tweaks: dict[str, str], tmpdir: str) -> None:
for hi in sum((
glob(f"{t2}/**/*.dylib", recursive=True),
glob(f"{t2}/**/*.bundle", recursive=True),
glob(f"{t2}/**/*.appex", recursive=True),
glob(f"{t2}/**/*.bundle", recursive=True),
glob(f"{t2}/**/*.framework", recursive=True)
), []): # type: ignore
if os.path.islink(hi):
continue # symlinks are broken iirc
if (
os.path.islink(hi) # symlinks are broken iirc
or hi.count(".bundle") > 1 # prevent sub-bundle detection (rip)
or hi.count(".framework") > 1
):
continue
tweaks[os.path.basename(hi)] = hi
@@ -171,6 +202,19 @@ def make_ipa(tmpdir: str, output: str, level: int) -> None:
os.chdir(tmpdir)
weird = 0
if HAS_ZIP:
try:
os.remove(output) # zip command updates zipfiles by default
except FileNotFoundError:
pass
# don't zip hidden files to fix an installd error sometimes
# thanks a lot eevee 😭
subprocess.run(
["zip", f"-{level}", "-r", output, "Payload", "-x", "*/.*"],
stdout=subprocess.DEVNULL
)
else:
with zipfile.ZipFile(
output, "w", zipfile.ZIP_DEFLATED, compresslevel=level
) as zf:

Binary file not shown.

Binary file not shown.

Binary file not shown.

View File

@@ -1,17 +1,21 @@
# type: ignore
from setuptools import setup
setup(
name="cyan",
version="1.1",
version="1.2.2",
description="finally, pyzule doesn't suck",
author="zx",
author_email="zx@hrzn.email",
packages=["cyan", "cyan.tbhtypes"],
# install_requires=["lief"],
packages=["cyan", "cyan.tbhtypes", "cgen"],
python_requires=">=3.9",
include_package_data=True,
entry_points={
"console_scripts": ["cyan=cyan.__main__:main"],
"console_scripts": [
"cyan=cyan.__main__:main",
"cgen=cgen.__main__:main"
],
}
)