7 Commits
v1.4.2 ... dev

Author SHA1 Message Date
zx
740d3716dc chore: start satisfying Designated Requirement
the ipas are now more demure

this shouldnt break nor add anything i mean
2025-03-18 19:00:40 -04:00
zx
5ce7a0cb43 fix: unchecked @loader_path dependency
fuck this
2025-02-17 08:22:13 -05:00
zx
04a40f2aa6 chore: bump version to v1.4.4 2025-02-15 09:15:23 -05:00
zx
6845281446 fix: unchecked /usr/lib dependencies
idk why i didnt do this before. either im stupid or there was a reason so im just praying this doesnt break anything rn
2025-02-15 09:14:55 -05:00
zx
54da4485a5 chore: change contact email 2025-02-01 21:52:05 -05:00
zx
f7b0169ee9 chore: bump version to v1.4.3 2025-02-01 21:39:41 -05:00
zx
ffbff5c78d feat: use multiple cyans 2025-02-01 21:38:15 -05:00
9 changed files with 63 additions and 41 deletions

3
.gitignore vendored
View File

@@ -6,3 +6,6 @@ build/
*.cyan *.cyan
.DS_Store .DS_Store
*.ipa
*.app/

View File

@@ -2,6 +2,8 @@
a rewrite of [pyzule](https://github.com/asdfzxcvbn/pyzule) that doesn't (completely) suck !! a rewrite of [pyzule](https://github.com/asdfzxcvbn/pyzule) that doesn't (completely) suck !!
wouldn't a go rewrite be really cool? (or in rust or something, adding features to this makes me realize PYTHONM FUCKING SUCKS SOMEONE PLEASE REWRITE IN LIKE ANY COMPILED AND STATICALLY TYPED LANGUAGE PLEASE!!!!!!!
## features ## features
you can open an issue to request a feature :D !! also see my [recommended flags](https://github.com/asdfzxcvbn/pyzule-rw/wiki/recommended-flags) you can open an issue to request a feature :D !! also see my [recommended flags](https://github.com/asdfzxcvbn/pyzule-rw/wiki/recommended-flags)

View File

@@ -21,15 +21,16 @@ def main() -> None:
"-o", "--output", metavar="output", "-o", "--output", metavar="output",
help="if unspecified, overwrites input" help="if unspecified, overwrites input"
) )
parser.add_argument(
"-z", "--cyan", metavar="cyan",
help="the .cyan file to use"
)
parser.add_argument(
"-z", "--cyan", metavar="cyan", nargs="+",
help="the .cyan file(s) to use"
)
parser.add_argument( parser.add_argument(
"-f", metavar="file", nargs="+", "-f", metavar="file", nargs="+",
help="a tweak to inject/item to be added to the bundle" help="a tweak to inject/item to be added to the bundle"
) )
parser.add_argument( parser.add_argument(
"-n", metavar="name", "-n", metavar="name",
help="modify the app's name" help="modify the app's name"
@@ -103,7 +104,7 @@ def main() -> None:
) )
parser.add_argument( parser.add_argument(
"--version", action="version", version="cyan v1.4.2" "--version", action="version", version="cyan v1.4.4"
) )
from cyan import logic from cyan import logic

Binary file not shown.

View File

@@ -45,7 +45,7 @@ def main(parser: ArgumentParser) -> None:
if args.cyan is not None: if args.cyan is not None:
changing = vars(args) changing = vars(args)
tbhutils.parse_cyan(changing, tmpdir) tbhutils.parse_cyans(changing, tmpdir)
# this goes before injection, # this goes before injection,
# since user might inject their own extensions # since user might inject their own extensions

View File

@@ -13,7 +13,10 @@ class Executable:
otool = f"{specific}/otool" otool = f"{specific}/otool"
idylib = f"{specific}/insert_dylib" idylib = f"{specific}/insert_dylib"
starters = ("\t/Library/", "\t@rpath", "\t@executable_path") # adding /usr/lib/ now, idk why i didnt before. lets hope nothing breaks
## LITERALLY 2 DAYS LATER. WHAT THE FUCK IS @LOADER_PATH HELP
## i will cry if only checking for '@' will break this.
starters = ("\t/Library/", "\t/usr/lib/", "\t@")
# substrate could show up as # substrate could show up as
# CydiaSubstrate.framework, libsubstrate.dylib, EVEN CydiaSubstrate.dylib # CydiaSubstrate.framework, libsubstrate.dylib, EVEN CydiaSubstrate.dylib

View File

@@ -61,6 +61,9 @@ class MainExecutable(Executable):
# inject/fix user things # inject/fix user things
for bn, path in tweaks.items(): for bn, path in tweaks.items():
if os.path.islink(path):
continue # symlinks can potentially have some security implications
if bn.endswith(".appex"): if bn.endswith(".appex"):
fpath = f"{PLUGINS_DIR}/{bn}" fpath = f"{PLUGINS_DIR}/{bn}"
existed = tbhutils.delete_if_exists(fpath, bn) existed = tbhutils.delete_if_exists(fpath, bn)
@@ -94,6 +97,8 @@ class MainExecutable(Executable):
# orion has a *weak* dependency to substrate, # orion has a *weak* dependency to substrate,
# but will still crash without it. nice !!!!!!!!!!! # but will still crash without it. nice !!!!!!!!!!!
## edit: actually, maybe this is in case someone uses Internal backend?
## someone test it pls!!!
if "orion." in needed: if "orion." in needed:
needed.add("substrate.") needed.add("substrate.")
@@ -132,9 +137,12 @@ class MainExecutable(Executable):
print("[!] failed to merge new entitlements, are they valid?") print("[!] failed to merge new entitlements, are they valid?")
def sign_with_entitlements(self, entitlements: str) -> bool: def sign_with_entitlements(self, entitlements: str) -> bool:
return subprocess.run( return subprocess.run([
[self.ldid, f"-S{entitlements}", "-M", "-Cadhoc", self.path] self.ldid,
).returncode == 0 f"-S{entitlements}", "-M", "-Cadhoc",
f"-Q{self.install_dir}/extras/zero.requirements",
self.path
]).returncode == 0
def lief_inject(self, cmd: str) -> None: def lief_inject(self, cmd: str) -> None:
if self.inj is None: # type: ignore if self.inj is None: # type: ignore

View File

@@ -70,8 +70,10 @@ def validate_inputs(args: Namespace) -> Optional[str]:
if args.l is not None and not os.path.isfile(args.l): if args.l is not None and not os.path.isfile(args.l):
sys.exit(f"[!] {args.l} does not exist") sys.exit(f"[!] {args.l} does not exist")
if args.cyan is not None and not os.path.isfile(args.cyan): if args.cyan is not None:
sys.exit(f"[!] {args.cyan} does not exist") for cyan in args.cyan:
if not os.path.isfile(cyan):
sys.exit(f"[!] {cyan} does not exist")
if args.x is not None: if args.x is not None:
if not os.path.isfile(args.x): if not os.path.isfile(args.x):
@@ -189,7 +191,7 @@ def extract_deb(deb: str, tweaks: dict[str, str], tmpdir: str) -> None:
glob(f"{t2}/**/*.framework", recursive=True) glob(f"{t2}/**/*.framework", recursive=True)
), []): # type: ignore ), []): # type: ignore
if ( if (
os.path.islink(hi) # symlinks are broken iirc os.path.islink(hi) # symlinks are broken iirc, also for security
or hi.count(".bundle") > 1 # prevent sub-bundle detection (rip) or hi.count(".bundle") > 1 # prevent sub-bundle detection (rip)
or hi.count(".framework") > 1 or hi.count(".framework") > 1
): ):
@@ -232,34 +234,37 @@ def make_ipa(tmpdir: str, output: str, level: int) -> None:
print(f"[?] was unable to zip {weird} file(s) due to timestamps") print(f"[?] was unable to zip {weird} file(s) due to timestamps")
def parse_cyan(args: dict[str, Any], tmpdir: str) -> None: def parse_cyans(args: dict[str, Any], tmpdir: str) -> None:
print("[*] parsing .cyan file..") for ind, cyan in enumerate(args["cyan"]):
with zipfile.ZipFile(args["cyan"]) as zf: print(f"[*] parsing {os.path.basename(cyan)} ..")
DOT_PATH = f"{tmpdir}/cyan"
os.mkdir(DOT_PATH)
with zf.open("config.json") as f: with zipfile.ZipFile(cyan) as zf:
config = json.load(f) DOT_PATH = f"{tmpdir}/cyan-{ind}"
os.mkdir(DOT_PATH)
if "f" in config: with zf.open("config.json") as f:
NAMES = [n for n in zf.namelist() if n.startswith("inject/")] config = json.load(f)
zf.extractall(DOT_PATH, NAMES)
# ensure not None if "f" in config:
args["f"] = args["f"] if args["f"] is not None else {} NAMES = [n for n in zf.namelist() if n.startswith("inject/")]
for e in os.scandir(f"{DOT_PATH}/inject"): zf.extractall(DOT_PATH, NAMES)
args["f"][e.name] = e.path
del config["f"]
if "k" in config:
args["k"] = zf.extract("icon.idk", DOT_PATH)
del config["k"]
if "l" in config:
args["l"] = zf.extract("merge.plist", DOT_PATH)
del config["l"]
if "x" in config:
args["x"] = zf.extract("new.entitlements", DOT_PATH)
del config["x"]
for k, v in config.items(): # ensure not None
args[k] = v args["f"] = args["f"] if args["f"] is not None else {}
for e in os.scandir(f"{DOT_PATH}/inject"):
args["f"][e.name] = e.path
del config["f"]
if "k" in config:
args["k"] = zf.extract("icon.idk", DOT_PATH)
del config["k"]
if "l" in config:
args["l"] = zf.extract("merge.plist", DOT_PATH)
del config["l"]
if "x" in config:
args["x"] = zf.extract("new.entitlements", DOT_PATH)
del config["x"]
# the rest of the config (not the ones above, we `del` them)
for k, v in config.items():
args[k] = v

View File

@@ -4,10 +4,10 @@ from setuptools import setup
setup( setup(
name="cyan", name="cyan",
version="1.4.2", version="1.4.4",
description="finally, pyzule doesn't suck", description="finally, pyzule doesn't suck",
author="zx", author="zx",
author_email="zx@hrzn.email", author_email="z@zxcvbn.fyi",
packages=["cyan", "cyan.tbhtypes", "cgen"], packages=["cyan", "cyan.tbhtypes", "cgen"],
python_requires=">=3.9", python_requires=">=3.9",
include_package_data=True, include_package_data=True,