From 8fb2053b17830da16cbd747737edde375d985cd8 Mon Sep 17 00:00:00 2001 From: "prompt.ac/@jeffrey" Date: Mon, 5 Oct 2026 08:09:01 -0700 Subject: [PATCH] Sign embedded iPhone debug libraries before packaging --- apple/whistlegraph/README.md | 2 ++ apple/whistlegraph/sign-device.sh | 20 ++++++++++++++++++++ 2 files changed, 22 insertions(+) create mode 100644 apple/whistlegraph/sign-device.sh diff --git a/apple/whistlegraph/README.md b/apple/whistlegraph/README.md index 62d08dd4ed..a6e24eb17e 100644 --- a/apple/whistlegraph/README.md +++ b/apple/whistlegraph/README.md @@ -4,6 +4,8 @@ The iPhone app for making AC pieces with voice, sound, and typing. Product domai From this directory, run `./run.sh device` to bundle, build, install, and open the app on a paired iPhone. Use `DEVICE=` if more than one phone is paired. `./run.sh simulator` builds for a simulator; select one with `SIMULATOR=`. XcodeGen generates `Whistlegraph.xcodeproj` from `project.yml`. +For an unsigned build transferred from poorslice, run `bash sign-device.sh ` before packaging or installing. This signs embedded debug libraries before the app and verifies all nested signatures. An install succeeding does not prove launch succeeds: verify the unlocked phone opens the workspace before marking a build launch-verified. + Typing uses AC's `compkey` sample and QWERTY pitch mapping. Enter sends the prompt, pasted line breaks become spaces, and the limit is 96 characters. Account settings control key and button sounds together. ## Story cards diff --git a/apple/whistlegraph/sign-device.sh b/apple/whistlegraph/sign-device.sh new file mode 100644 index 0000000000..fc16516712 --- /dev/null +++ b/apple/whistlegraph/sign-device.sh @@ -0,0 +1,20 @@ +#!/usr/bin/env bash +# Sign a poorslice CODE_SIGNING_ALLOWED=NO build using this Mac's identity. +set -euo pipefail +if [[ $# != 4 ]]; then + echo 'Usage: bash sign-device.sh ' >&2 + exit 1 +fi +app=${1%/} +identity=$2 +profile=$3 +entitlements=$4 +[[ -d "$app" && -f "$app/Info.plist" && -f "$profile" && -f "$entitlements" ]] +cp "$profile" "$app/embedded.mobileprovision" +# Xcode's Debug executable loads the application code from a separate dylib. +# Signing only the .app seals that file without signing its executable code. +while IFS= read -r library; do + codesign --force --sign "$identity" "$library" +done < <(rg --files "$app" -g '*.dylib') +codesign --force --sign "$identity" --entitlements "$entitlements" --generate-entitlement-der "$app" +codesign --verify --deep --strict --verbose=2 "$app" -- 2.51.2