14 Commits

Author SHA1 Message Date
zx
eba32c22e6 chore: bump version to v1.4.2 (stable) 2025-01-08 19:10:32 -05:00
zx
a96632f1b0 chore: ignore DS_Store
macos moment
2025-01-08 19:06:52 -05:00
zx
86e45cc186 feat(cgen): plist and entitlement merging 2024-11-26 22:21:13 -05:00
zx
e09351287b feat: plist merging 2024-11-26 22:07:22 -05:00
zx
403e5d65a5 chore: bump version to v1.4.1 2024-11-07 22:32:58 -05:00
zx
354a1d9ac5 fix: not auto-injecting already fixed dependency names
whoops
2024-11-07 22:31:43 -05:00
zx
73d1495eff chore: bump version to v1.4 (stable) 2024-11-02 10:43:45 -04:00
zx
31169d6c65 refactor: move orion check out of loop 2024-11-02 10:42:47 -04:00
zx
0808fd8c1b feat: manually modified dylib support (#6) 2024-10-31 14:35:22 -04:00
zx
8c873a84c8 chore: bump version to v1.3 2024-10-28 17:31:19 -04:00
zx
7543bb3d8d fix: can't extract entitlements with codesign (ProcursusTeam/ldid#45)
this issue was originally reported in #8
2024-10-28 17:27:02 -04:00
zx
c0b0324a12 chore: move injection functions to MainExecutable 2024-10-25 23:04:40 -04:00
zx
42517c90fb chore: move write_entitlements() to MainExecutable
the func is only used in `MainExecutable`, so we should move it there to make it a bit more "clean"
2024-10-25 22:44:25 -04:00
zx
b4e3e6aaf5 chore: add question issue template 2024-10-15 12:14:53 -04:00
12 changed files with 190 additions and 79 deletions

22
.github/ISSUE_TEMPLATE/question.yaml vendored Normal file
View File

@@ -0,0 +1,22 @@
# thanks to uYouEnhanced for the issue template:
# https://github.com/arichornlover/uYouEnhanced/blob/main/.github/ISSUE_TEMPLATE/bug.yaml?plain=1
name: question
description: have a question about cyan or its code? use this template!
title: "[question] "
labels: question
body:
- type: checkboxes
attributes:
label: have you searched the existing issues?
options:
- label: this is a unique question. i agree that if this isn't a unique question, i'll be BLOCKED from the cyan repo
required: true
- type: textarea
attributes:
label: what's up?
description: what's the question?
validations:
required: true

5
.gitignore vendored
View File

@@ -1,5 +1,8 @@
__pycache__/ __pycache__/
build/ build/
*.egg-info *.egg-info/
*.cyan
.DS_Store

View File

@@ -15,6 +15,7 @@ you can open an issue to request a feature :D !! also see my [recommended flags]
- remove watch app - remove watch app
- change the app icon - change the app icon
- fakesign the output ipa/tipa/app - fakesign the output ipa/tipa/app
- merge a plist into the app's existing Info.plist
- add custom entitlements to the main executable - add custom entitlements to the main executable
- thin all binaries to arm64, it can LARGELY reduce app size sometimes! - thin all binaries to arm64, it can LARGELY reduce app size sometimes!
- remove all app extensions (or just encrypted ones!) - remove all app extensions (or just encrypted ones!)

View File

@@ -42,6 +42,14 @@ def main() -> None:
"-k", metavar="icon", "-k", metavar="icon",
help="modify the app's icon" help="modify the app's icon"
) )
parser.add_argument(
"-l", metavar="plist",
help="a plist to merge with the app's Info.plist"
)
parser.add_argument(
"-x", metavar="entitlements",
help="add or modify entitlements to the main binary"
)
parser.add_argument( parser.add_argument(
"-u", "--remove-supported-devices", action="store_true", "-u", "--remove-supported-devices", action="store_true",
@@ -83,6 +91,10 @@ def generate_cyan(parser: argparse.ArgumentParser) -> None:
parser.error(f"invalid minimum OS version: {args.m}") parser.error(f"invalid minimum OS version: {args.m}")
if args.k is not None and not os.path.isfile(args.k): if args.k is not None and not os.path.isfile(args.k):
parser.error(f"{args.k} does not exist") parser.error(f"{args.k} does not exist")
if args.l is not None and not os.path.isfile(args.l):
parser.error(f"{args.l} does not exist")
if args.x is not None and not os.path.isfile(args.x):
parser.error(f"{args.x} does not exist")
if args.f is not None: if args.f is not None:
fake = [f for f in args.f if not os.path.exists(f)] fake = [f for f in args.f if not os.path.exists(f)]
@@ -107,7 +119,7 @@ def generate_cyan(parser: argparse.ArgumentParser) -> None:
real_args = {k: v for k, v in dict(vars(args)).items() if v} real_args = {k: v for k, v in dict(vars(args)).items() if v}
del real_args["output"] del real_args["output"]
for key in "fk": # these need files for key in "fkxl": # these need files
if key in real_args: if key in real_args:
real_args[key] = True real_args[key] = True
@@ -136,6 +148,12 @@ def generate_cyan(parser: argparse.ArgumentParser) -> None:
if args.k is not None: if args.k is not None:
zf.write(args.k, "icon.idk") zf.write(args.k, "icon.idk")
if args.l:
zf.write(args.l, "merge.plist")
if args.x:
zf.write(args.x, "new.entitlements")
if __name__ == "__main__": if __name__ == "__main__":
main() main()

View File

@@ -50,6 +50,10 @@ def main() -> None:
"-k", metavar="icon", "-k", metavar="icon",
help="modify the app's icon" help="modify the app's icon"
) )
parser.add_argument(
"-l", metavar="plist",
help="a plist to merge with the app's Info.plist"
)
parser.add_argument( parser.add_argument(
"-x", metavar="entitlements", "-x", metavar="entitlements",
help="add or modify entitlements to the main binary" help="add or modify entitlements to the main binary"
@@ -99,7 +103,7 @@ def main() -> None:
) )
parser.add_argument( parser.add_argument(
"--version", action="version", version="cyan v1.2.3" "--version", action="version", version="cyan v1.4.2"
) )
from cyan import logic from cyan import logic

View File

@@ -66,6 +66,8 @@ def main(parser: ArgumentParser) -> None:
app.plist.change_minimum_version(args.m) app.plist.change_minimum_version(args.m)
if args.k is not None: if args.k is not None:
app.change_icon(args.k, tmpdir) app.change_icon(args.k, tmpdir)
if args.l is not None:
app.plist.merge_plist(args.l)
if args.x is not None: if args.x is not None:
app.executable.merge_entitlements(args.x) app.executable.merge_entitlements(args.x)

View File

@@ -105,7 +105,7 @@ class AppBundle:
def change_icon(self, path: str, tmpdir: str) -> None: def change_icon(self, path: str, tmpdir: str) -> None:
try: try:
from PIL import Image from PIL import Image # type: ignore
except Exception: except Exception:
return print("[?] pillow is not installed, -k is not available") return print("[?] pillow is not installed, -k is not available")

View File

@@ -1,12 +1,6 @@
import os import os
import sys import sys
import subprocess import subprocess
from typing import Optional
try:
import lief
except Exception:
pass
from cyan import tbhutils from cyan import tbhutils
@@ -20,16 +14,31 @@ class Executable:
idylib = f"{specific}/insert_dylib" idylib = f"{specific}/insert_dylib"
starters = ("\t/Library/", "\t@rpath", "\t@executable_path") starters = ("\t/Library/", "\t@rpath", "\t@executable_path")
common = {
# substrate could show up as # substrate could show up as
# CydiaSubstrate.framework, libsubstrate.dylib, EVEN CydiaSubstrate.dylib # CydiaSubstrate.framework, libsubstrate.dylib, EVEN CydiaSubstrate.dylib
# AND PROBABLY EVEN MORE !!!! IT'S CRAZY. # AND PROBABLY EVEN MORE !!!! IT'S CRAZY.
common = {
"CydiaSubstrate.framework": "CydiaSubstrate.framework", "substrate.": {
"Orion.framework": "Orion.framework", "name": "CydiaSubstrate.framework",
"Cephei.framework": "Cephei.framework", "path": "@rpath/CydiaSubstrate.framework/CydiaSubstrate"
"CepheiUI.framework": "CepheiUI.framework", },
"CepheiPrefs.framework": "CepheiPrefs.framework" "orion.": {
"name": "Orion.framework",
"path": "@rpath/Orion.framework/Orion"
},
"cephei.": {
"name": "Cephei.framework",
"path": "@rpath/Cephei.framework/Cephei"
},
"cepheiui.": {
"name": "CepheiUI.framework",
"path": "@rpath/CepheiUI.framework/CepheiUI"
},
"cepheiprefs.": {
"name": "CepheiPrefs.framework",
"path": "@rpath/CepheiPrefs.framework/CepheiPrefs"
}
} }
def __init__(self, path: str): def __init__(self, path: str):
@@ -42,14 +51,7 @@ class Executable:
) )
self.path = path self.path = path
self.bn = os.path.basename(path) self.bn = os.path.basename(path)
self.inj: Optional = None # type: ignore
if os.path.isfile(self.idylib):
self.inj_func = self.idyl_inject
else:
self.inj_func = self.lief_inj
def is_encrypted(self) -> bool: def is_encrypted(self) -> bool:
proc = subprocess.run( proc = subprocess.run(
@@ -65,17 +67,6 @@ class Executable:
def fakesign(self) -> bool: def fakesign(self) -> bool:
return subprocess.run([self.ldid, "-S", "-M", self.path]).returncode == 0 return subprocess.run([self.ldid, "-S", "-M", self.path]).returncode == 0
def write_entitlements(self, output: str) -> bool:
with open(output, "wb") as entf:
proc = subprocess.run(
[self.ldid, "-e", self.path],
capture_output=True
)
entf.write(proc.stdout)
return os.path.getsize(output) > 0
def thin(self) -> bool: def thin(self) -> bool:
return subprocess.run( return subprocess.run(
[self.lipo, "-thin", "arm64", self.path, "-output", self.path], [self.lipo, "-thin", "arm64", self.path, "-output", self.path],
@@ -88,39 +79,29 @@ class Executable:
stderr=subprocess.DEVNULL stderr=subprocess.DEVNULL
) )
def lief_inj(self, cmd: str) -> None: def fix_common_dependencies(self, needed: set[str]) -> None:
if self.inj is None: # type: ignore
try:
lief.logging.disable() # type: ignore
except Exception:
sys.exit("[!] did you forget to install lief?")
self.inj = lief.parse(self.path) # type: ignore
try:
self.inj.add(lief.MachO.DylibCommand.weak_lib(cmd)) # type: ignore
except AttributeError:
sys.exit("[!] couldn't add LC (lief), did you use a valid app?")
def idyl_inject(self, cmd: str) -> None:
proc = subprocess.run(
[
self.idylib, "--weak", "--inplace", "--strip-codesig", "--all-yes",
cmd, self.path
], capture_output=True, text=True
)
if proc.returncode != 0:
sys.exit(f"[!] couldn't add LC (insert_dylib), error:\n{proc.stderr}")
def fix_dependencies(self, tweaks: dict[str, str], need: set[str]) -> None:
self.remove_signature() self.remove_signature()
for dep in self.get_dependencies(): for dep in self.get_dependencies():
for cname in (tweaks | self.common): for common, info in self.common.items():
if common in dep.lower():
needed.add(common)
if dep != info["path"]:
self.change_dependency(dep, info["path"])
print(
f"[*] fixed common dependency in {self.bn}: "
f"{dep} -> {info['path']}"
)
def fix_dependencies(self, tweaks: dict[str, str]) -> None:
for dep in self.get_dependencies():
for cname in tweaks:
if cname in dep: if cname in dep:
# i wonder if there's a better way to do this? # i wonder if there's a better way to do this?
if cname.endswith(".framework"): if cname.endswith(".framework"):
# nah, not gonna parse the plist,
# i've never seen a framework with a "mismatched" name
npath = f"@rpath/{cname}/{cname[:-10]}" npath = f"@rpath/{cname}/{cname[:-10]}"
else: else:
npath = f"@rpath/{cname}" npath = f"@rpath/{cname}"
@@ -129,9 +110,6 @@ class Executable:
self.change_dependency(dep, npath) self.change_dependency(dep, npath)
print(f"[*] fixed dependency in {self.bn}: {dep} -> {npath}") print(f"[*] fixed dependency in {self.bn}: {dep} -> {npath}")
if cname in self.common:
need.add(cname)
def get_dependencies(self) -> list[str]: def get_dependencies(self) -> list[str]:
proc = subprocess.run( proc = subprocess.run(
[self.otool, "-L", self.path], [self.otool, "-L", self.path],

View File

@@ -1,6 +1,13 @@
import os import os
import sys
import shutil import shutil
import subprocess import subprocess
from typing import Optional
try:
import lief # type: ignore
except Exception:
pass
from cyan import tbhutils from cyan import tbhutils
from .executable import Executable from .executable import Executable
@@ -10,13 +17,20 @@ class MainExecutable(Executable):
super().__init__(path) super().__init__(path)
self.bundle_path = bundle_path self.bundle_path = bundle_path
self.inj: Optional = None # type: ignore
if os.path.isfile(self.idylib):
self.inj_func = self.idyl_inject
else:
self.inj_func = self.lief_inject
def inject(self, tweaks: dict[str, str], tmpdir: str) -> None: def inject(self, tweaks: dict[str, str], tmpdir: str) -> None:
ENT_PATH = f"{self.bundle_path}/cyan.entitlements" ENT_PATH = f"{self.bundle_path}/cyan.entitlements"
PLUGINS_DIR = f"{self.bundle_path}/PlugIns" PLUGINS_DIR = f"{self.bundle_path}/PlugIns"
FRAMEWORKS_DIR = f"{self.bundle_path}/Frameworks" FRAMEWORKS_DIR = f"{self.bundle_path}/Frameworks"
has_entitlements = self.write_entitlements(ENT_PATH) has_entitlements = self.write_entitlements(ENT_PATH)
# iirc, injecting doesnt work (sometimes) if the file isn't signed # iirc, injecting doesnt work (sometimes) if the file is signed
self.remove_signature() self.remove_signature()
if any(t.endswith(".appex") for t in tweaks): if any(t.endswith(".appex") for t in tweaks):
@@ -44,6 +58,8 @@ class MainExecutable(Executable):
os.chdir(cwd) # i fucking hate jailbroken iOS utils. os.chdir(cwd) # i fucking hate jailbroken iOS utils.
needed: set[str] = set() needed: set[str] = set()
# inject/fix user things
for bn, path in tweaks.items(): for bn, path in tweaks.items():
if bn.endswith(".appex"): if bn.endswith(".appex"):
fpath = f"{PLUGINS_DIR}/{bn}" fpath = f"{PLUGINS_DIR}/{bn}"
@@ -51,7 +67,10 @@ class MainExecutable(Executable):
shutil.copytree(path, fpath) shutil.copytree(path, fpath)
elif bn.endswith(".dylib"): elif bn.endswith(".dylib"):
path = shutil.copy2(path, tmpdir) path = shutil.copy2(path, tmpdir)
Executable(path).fix_dependencies(tweaks, needed)
e = Executable(path)
e.fix_common_dependencies(needed)
e.fix_dependencies(tweaks)
fpath = f"{FRAMEWORKS_DIR}/{bn}" fpath = f"{FRAMEWORKS_DIR}/{bn}"
existed = tbhutils.delete_if_exists(fpath, bn) existed = tbhutils.delete_if_exists(fpath, bn)
@@ -75,11 +94,11 @@ class MainExecutable(Executable):
# orion has a *weak* dependency to substrate, # orion has a *weak* dependency to substrate,
# but will still crash without it. nice !!!!!!!!!!! # but will still crash without it. nice !!!!!!!!!!!
if "Orion.framework" in needed: if "orion." in needed:
needed.add("CydiaSubstrate.framework") needed.add("substrate.")
for missing in needed: for missing in needed:
real = self.common[missing] # "real" name, thanks substrate! real = self.common[missing]["name"] # e.g. "Orion.framework"
ip = f"{FRAMEWORKS_DIR}/{real}" ip = f"{FRAMEWORKS_DIR}/{real}"
existed = tbhutils.delete_if_exists(ip, real) existed = tbhutils.delete_if_exists(ip, real)
shutil.copytree(f"{self.install_dir}/extras/{real}", ip) shutil.copytree(f"{self.install_dir}/extras/{real}", ip)
@@ -95,12 +114,50 @@ class MainExecutable(Executable):
self.sign_with_entitlements(ENT_PATH) self.sign_with_entitlements(ENT_PATH)
print("[*] restored entitlements") print("[*] restored entitlements")
def write_entitlements(self, output: str) -> bool:
with open(output, "wb") as entf:
proc = subprocess.run(
[self.ldid, "-e", self.path],
capture_output=True
)
entf.write(proc.stdout)
return os.path.getsize(output) > 0
def merge_entitlements(self, entitlements: str) -> None: def merge_entitlements(self, entitlements: str) -> None:
self.sign_with_entitlements(entitlements) if self.sign_with_entitlements(entitlements):
print("[*] merged new entitlements") print("[*] merged new entitlements")
else:
print("[!] failed to merge new entitlements, are they valid?")
def sign_with_entitlements(self, entitlements: str) -> bool: def sign_with_entitlements(self, entitlements: str) -> bool:
return subprocess.run( return subprocess.run(
[self.ldid, f"-S{entitlements}", "-M", self.path] [self.ldid, f"-S{entitlements}", "-M", "-Cadhoc", self.path]
).returncode == 0 ).returncode == 0
def lief_inject(self, cmd: str) -> None:
if self.inj is None: # type: ignore
try:
lief.logging.disable() # type: ignore
except Exception:
sys.exit("[!] did you forget to install lief?")
self.inj = lief.parse(self.path) # type: ignore
try:
self.inj.add(lief.MachO.DylibCommand.weak_lib(cmd)) # type: ignore
except AttributeError:
sys.exit("[!] couldn't add LC (lief), did you use a valid app?")
def idyl_inject(self, cmd: str) -> None:
proc = subprocess.run(
[
self.idylib, "--weak", "--inplace", "--all-yes",
cmd, self.path
], capture_output=True, text=True
)
if proc.returncode != 0:
sys.exit(f"[!] couldn't add LC (insert_dylib), error:\n{proc.stderr}")

View File

@@ -10,11 +10,13 @@ class Plist:
try: try:
with open(path, "rb") as f: with open(path, "rb") as f:
self.data: dict[str, Any] = plistlib.load(f) self.data: dict[str, Any] = plistlib.load(f)
self.success = True
except Exception: except Exception:
if throw: if throw:
sys.exit(f"[!] couldn't read {path}") sys.exit(f"[!] couldn't read {path}")
else:
return None self.success = False
self.path = path self.path = path
self.app_path = app_path self.app_path = app_path
@@ -44,7 +46,7 @@ class Plist:
try: try:
if all(self[key] == val for key in keys): if all(self[key] == val for key in keys):
return False return False
raise KeyError # lets pretend this was always here.. raise KeyError
except KeyError: except KeyError:
for key in keys: for key in keys:
self[key] = val self[key] = val
@@ -121,3 +123,18 @@ class Plist:
else: else:
print(f"[?] minimum version was already \"{minimum}\"") print(f"[?] minimum version was already \"{minimum}\"")
def merge_plist(self, path: str) -> None:
pl = Plist(path, throw=False)
if not pl.success:
return print(f"[!] couldn't parse {path}")
changed = False
for k, v in pl.data.items():
if self.change(v, k):
changed = True
if not changed:
print("[?] no modified plist entries")
else:
print("[*] set plist keys:", ", ".join(pl.data))

View File

@@ -67,6 +67,9 @@ def validate_inputs(args: Namespace) -> Optional[str]:
if args.k is not None and not os.path.isfile(args.k): if args.k is not None and not os.path.isfile(args.k):
sys.exit(f"[!] {args.k} does not exist") sys.exit(f"[!] {args.k} does not exist")
if args.l is not None and not os.path.isfile(args.l):
sys.exit(f"[!] {args.l} does not exist")
if args.cyan is not None and not os.path.isfile(args.cyan): if args.cyan is not None and not os.path.isfile(args.cyan):
sys.exit(f"[!] {args.cyan} does not exist") sys.exit(f"[!] {args.cyan} does not exist")
@@ -250,6 +253,12 @@ def parse_cyan(args: dict[str, Any], tmpdir: str) -> None:
if "k" in config: if "k" in config:
args["k"] = zf.extract("icon.idk", DOT_PATH) args["k"] = zf.extract("icon.idk", DOT_PATH)
del config["k"] del config["k"]
if "l" in config:
args["l"] = zf.extract("merge.plist", DOT_PATH)
del config["l"]
if "x" in config:
args["x"] = zf.extract("new.entitlements", DOT_PATH)
del config["x"]
for k, v in config.items(): for k, v in config.items():
args[k] = v args[k] = v

View File

@@ -4,7 +4,7 @@ from setuptools import setup
setup( setup(
name="cyan", name="cyan",
version="1.2.3", version="1.4.2",
description="finally, pyzule doesn't suck", description="finally, pyzule doesn't suck",
author="zx", author="zx",
author_email="zx@hrzn.email", author_email="zx@hrzn.email",