啟動(dòng)之后首先會(huì)去查詢可用的簽名證書,這里用到了NSTask,NSTask是可以在APP里調(diào)用終端命令的。而終端是另外一個(gè)進(jìn)程,需要進(jìn)程間通信,可以使用NSPipe,security find-identity -v -p codesigning
則可以查詢到當(dāng)前設(shè)備下所有證書:
certTask = [[NSTask alloc] init];
[certTask setLaunchPath:@"/usr/bin/security"];
[certTask setArguments:[NSArray arrayWithObjects:@"find-identity", @"-v", @"-p", @"codesigning", nil]];
[NSTimer scheduledTimerWithTimeInterval:1.0 target:self selector:@selector(checkCerts:) userInfo:nil repeats:TRUE];
NSPipe *pipe=[NSPipe pipe];
[certTask setStandardOutput:pipe];
[certTask setStandardError:pipe];
NSFileHandle *handle=[pipe fileHandleForReading];
[certTask launch];
//創(chuàng)建子線程,將讀取的結(jié)果返回給watchGetCerts方法
[NSThread detachNewThreadSelector:@selector(watchGetCerts:) toTarget:self withObject:handle];
//watchGetCerts沒啥特別之處,根據(jù)返回的字符串進(jìn)行解析,由于結(jié)果是證書uuid+賬號(hào)的形式,所以字符串分割之后遍歷的時(shí)候是+2的步長
- (void)watchGetCerts:(NSFileHandle*)streamHandle {
@autoreleasepool {
NSString *securityResult = [[NSString alloc] initWithData:[streamHandle readDataToEndOfFile] encoding:NSASCIIStringEncoding];
// Verify the security result
if (securityResult == nil || securityResult.length < 1) {
// Nothing in the result, return
return;
}
NSArray *rawResult = [securityResult componentsSeparatedByString:@"\""];
NSMutableArray *tempGetCertsResult = [NSMutableArray arrayWithCapacity:20];
for (int i = 0; i <= [rawResult count] - 2; i+=2) {
NSLog(@"i:%d", i+1);
if (rawResult.count - 1 < i + 1) {
// Invalid array, don't add an object to that position
} else {
// Valid object
[tempGetCertsResult addObject:[rawResult objectAtIndex:i+1]];
}
}
certComboBoxItems = [NSMutableArray arrayWithArray:tempGetCertsResult];
[certComboBox reloadData];
}
}
certTask執(zhí)行完之后,會(huì)把timer取消,然后設(shè)置默認(rèn)選中狀態(tài)。接下來幾個(gè)設(shè)置都是使用的NSOpenPanel類增加類型而已,直接來到resign方法:
- (IBAction)resign:(id)sender {
//Save cert name
[defaults setValue:[NSNumber numberWithInteger:[certComboBox indexOfSelectedItem]] forKey:@"CERT_INDEX"];
[defaults setValue:[entitlementField stringValue] forKey:@"ENTITLEMENT_PATH"];
[defaults setValue:[provisioningPathField stringValue] forKey:@"MOBILEPROVISION_PATH"];
[defaults setValue:[bundleIDField stringValue] forKey:kKeyPrefsBundleIDChange];
[defaults synchronize];
codesigningResult = nil;
verificationResult = nil;
//源ipa路徑
sourcePath = [pathField stringValue];
//工作區(qū)路徑
workingPath = [NSTemporaryDirectory() stringByAppendingPathComponent:@"com.appulize.iresign"];
if ([certComboBox objectValue]) {
//重簽的對(duì)象必須為ipa或者xcarchive文件,也就是簽名之后的產(chǎn)物
if (([[[sourcePath pathExtension] lowercaseString] isEqualToString:@"ipa"]) ||
([[[sourcePath pathExtension] lowercaseString] isEqualToString:@"xcarchive"])) {
[self disableControls];
NSLog(@"Setting up working directory in %@",workingPath);
[statusLabel setHidden:NO];
[statusLabel setStringValue:@"Setting up working directory"];
//先移除緩存,再創(chuàng)建該路徑的文件夾
[[NSFileManager defaultManager] removeItemAtPath:workingPath error:nil];
[[NSFileManager defaultManager] createDirectoryAtPath:workingPath withIntermediateDirectories:TRUE attributes:nil error:nil];
if ([[[sourcePath pathExtension] lowercaseString] isEqualToString:@"ipa"]) {
if (sourcePath && [sourcePath length] > 0) {
NSLog(@"Unzipping %@",sourcePath);
[statusLabel setStringValue:@"Extracting original app"];
}
//ipa執(zhí)行解壓操作,同理結(jié)果在checkUnzip
unzipTask = [[NSTask alloc] init];
[unzipTask setLaunchPath:@"/usr/bin/unzip"];
[unzipTask setArguments:[NSArray arrayWithObjects:@"-q", sourcePath, @"-d", workingPath, nil]];
[NSTimer scheduledTimerWithTimeInterval:1.0 target:self selector:@selector(checkUnzip:) userInfo:nil repeats:TRUE];
[unzipTask launch];
}
else {
//否則為xcarchive,不需要unzip,其他同理
NSString* payloadPath = [workingPath stringByAppendingPathComponent:kPayloadDirName];
if (infoPListDict != nil) {
NSString* applicationPath = nil;
NSDictionary* applicationPropertiesDict = [infoPListDict objectForKey:kKeyInfoPlistApplicationProperties];
if (applicationPath != nil) {
applicationPath = [[sourcePath stringByAppendingPathComponent:kProductsDirName] stringByAppendingPathComponent:applicationPath];
NSLog(@"Copying %@ to %@ path in %@", applicationPath, kPayloadDirName, payloadPath);
[statusLabel setStringValue:[NSString stringWithFormat:@"Copying .xcarchive app to %@ path", kPayloadDirName]];
copyTask = [[NSTask alloc] init];
[copyTask setLaunchPath:@"/bin/cp"];
[copyTask setArguments:[NSArray arrayWithObjects:@"-r", applicationPath, payloadPath, nil]];
[NSTimer scheduledTimerWithTimeInterval:1.0 target:self selector:@selector(checkCopy:) userInfo:nil repeats:TRUE];
[copyTask launch];
}
}
}
}
else {
[self showAlertOfKind:NSCriticalAlertStyle WithTitle:@"Error" AndMessage:@"You must choose an *.ipa or *.xcarchive file"];
[self enableControls];
[statusLabel setStringValue:@"Please try again"];
}
} else {
[self showAlertOfKind:NSCriticalAlertStyle WithTitle:@"Error" AndMessage:@"You must choose an signing certificate from dropdown."];
[self enableControls];
[statusLabel setStringValue:@"Please try again"];
}
}
- (void)checkUnzip:(NSTimer *)timer {
if ([unzipTask isRunning] == 0) {
[timer invalidate];
unzipTask = nil;
if ([[NSFileManager defaultManager] fileExistsAtPath:[workingPath stringByAppendingPathComponent:kPayloadDirName]]) {
NSLog(@"Unzipping done");
[statusLabel setStringValue:@"Original app extracted"];
if (changeBundleIDCheckbox.state == NSOnState) {
//如果修改了bundleID,則需要將新的bundleID覆蓋掉原本Info.plist中的CFBundleIdentifier
[self doBundleIDChange:bundleIDField.stringValue];
}
if ([[provisioningPathField stringValue] isEqualTo:@""]) {
[self doCodeSigning];
} else {
//如果本地存在embedded.mobileprovision,則需要先刪除;然后將mobileprovision拷貝到.app路徑下
//其中會(huì)解析embedded.mobileprovision,進(jìn)行校驗(yàn):取出application-identifier對(duì)應(yīng)的內(nèi)容與Info.plist的CFBundleIdentifier
[self doProvisioning];
}
} else {
[self showAlertOfKind:NSCriticalAlertStyle WithTitle:@"Error" AndMessage:@"Unzip failed"];
[self enableControls];
[statusLabel setStringValue:@"Ready"];
}
}
}
- (void)doEntitlementsFixing
{
//最后調(diào)用doEntitlementsFixing,如何不存在entitlements.plist則直接codesign
if (![entitlementField.stringValue isEqualToString:@""] || [provisioningPathField.stringValue isEqualToString:@""]) {
[self doCodeSigning];
return; // Using a pre-made entitlements file or we're not re-provisioning.
}
[statusLabel setStringValue:@"Generating entitlements"];
//否則security cms -D -i XXX 對(duì)Entitlements進(jìn)行修復(fù),最后寫入到entitlements.plist
if (appPath) {
generateEntitlementsTask = [[NSTask alloc] init];
[generateEntitlementsTask setLaunchPath:@"/usr/bin/security"];
[generateEntitlementsTask setArguments:@[@"cms", @"-D", @"-i", provisioningPathField.stringValue]];
[generateEntitlementsTask setCurrentDirectoryPath:workingPath];
[NSTimer scheduledTimerWithTimeInterval:1.0 target:self selector:@selector(checkEntitlementsFix:) userInfo:nil repeats:TRUE];
NSPipe *pipe=[NSPipe pipe];
[generateEntitlementsTask setStandardOutput:pipe];
[generateEntitlementsTask setStandardError:pipe];
NSFileHandle *handle = [pipe fileHandleForReading];
[generateEntitlementsTask launch];
[NSThread detachNewThreadSelector:@selector(watchEntitlements:)
toTarget:self withObject:handle];
}
}
- (void)doCodeSigning {
appPath = nil;
frameworksDirPath = nil;
hasFrameworks = NO;
frameworks = [[NSMutableArray alloc] init];
NSArray *dirContents = [[NSFileManager defaultManager] contentsOfDirectoryAtPath:[workingPath stringByAppendingPathComponent:kPayloadDirName] error:nil];
for (NSString *file in dirContents) {
if ([[[file pathExtension] lowercaseString] isEqualToString:@"app"]) {
appPath = [[workingPath stringByAppendingPathComponent:kPayloadDirName] stringByAppendingPathComponent:file];
frameworksDirPath = [appPath stringByAppendingPathComponent:kFrameworksDirName];
NSLog(@"Found %@",appPath);
appName = file;
if ([[NSFileManager defaultManager] fileExistsAtPath:frameworksDirPath]) {
NSLog(@"Found %@",frameworksDirPath);
hasFrameworks = YES;
NSArray *frameworksContents = [[NSFileManager defaultManager] contentsOfDirectoryAtPath:frameworksDirPath error:nil];
for (NSString *frameworkFile in frameworksContents) {
//如果存在framework或者dylib,則需要對(duì)每一個(gè)framework中的Info.plist進(jìn)行更新,并調(diào)用codesign對(duì)庫逐一進(jìn)行簽名
NSString *extension = [[frameworkFile pathExtension] lowercaseString];
if ([extension isEqualTo:@"framework"] || [extension isEqualTo:@"dylib"]) {
frameworkPath = [frameworksDirPath stringByAppendingPathComponent:frameworkFile];
NSLog(@"Found %@",frameworkPath);
[frameworks addObject:frameworkPath];
}
}
}
[statusLabel setStringValue:[NSString stringWithFormat:@"Codesigning %@",file]];
break;
}
}
if (appPath) {
if (hasFrameworks) {
//然后codesign -v XXX 進(jìn)行校驗(yàn)
//最后校驗(yàn)通過則對(duì)ipa進(jìn)行重命名XXX-resigned.ipa,并zip到原路徑下
[self signFile:[frameworks lastObject]];
[frameworks removeLastObject];
} else {
//app同理
[self signFile:appPath];
}
}
}