mirror of
https://github.com/patchzyy/wiicompiled
synced 2026-10-04 08:31:05 -04:00
b59e035b87
* Implement real TLS for non-Windows via vendored mbed TLS Windows gets TLS for the guest network HLE's SSL ioctlvs for free from Schannel; every other platform fell into a stub that always returned failure, meaning any HTTPS-based network feature (WFC login, fetching the Retro-WFC payload) silently could not work at all on those platforms regardless of server availability. Vendors mbed TLS 3.6.7 LTS under runtime/third_party/mbedtls (same convention as Crypto++/pugixml - a real source checkout, not a submodule/FetchContent download) and a standard Mozilla CA bundle (runtime/assets/certs/cacert.pem, via curl.se's redistribution) copied next to the built product the same way dsp_coef.bin already is. Verified against real HTTPS servers: a valid certificate completes the handshake and an HTTP round-trip; a known-expired certificate is correctly rejected with a real X509 verification failure, not silently accepted. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qmdewk7VfVVJTfCVd2WStu * Fix TLS handshake hang and partial-write truncation on non-Windows Add a POSIX socket timeout to match Windows' existing 15s one, plus a deadline on the handshake retry loop itself, so a peer that accepts the TCP connection but never sends TLS data can no longer hang the thread forever. Also fix SslWrite to loop on partial mbedTLS writes instead of returning the first partial count, and add mbedTLS to THIRD-PARTY-NOTICES.md. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * Fetch mbedTLS from a pinned, checksum-verified release instead of vendoring it Replace the committed mbedTLS source tree with a CMake FetchContent download of the official mbedtls-3.6.7 release tarball, verified against its signed SHA-256, matching how aurora-main's own dependencies (SDL, zlib, etc.) are pulled in. Ships the compiled dependency instead of ~280 tracked upstream files. CA bundle packaging and THIRD-PARTY-NOTICES.md coverage are unchanged. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * Limit the mbedTLS dependency to the platforms that use it The FetchContent block ran on every platform, including Windows, whose builds configure with FETCHCONTENT_FULLY_DISCONNECTED=ON against the offline dependency set from Launcher/Prepare-Dependencies.ps1 - which has no mkw_mbedtls_upstream entry, so a clean Windows configure failed. Windows compiles the Schannel path (network_ssl.cpp is `#ifndef _WIN32` for mbed TLS) and never links mbed TLS, so nothing needs preparing there: the fetch, the linkage and the cacert.pem copy are now guarded to non-Windows, while the mkw::mbedtls alias stays defined everywhere so the link lines in PublicProducts.cmake remain platform-independent. Also copy cacert.pem alongside the installed executable in the Linux and macOS publication paths (Launcher/local-build.sh and Launcher/macos/publish-app.command), which already copied the other runtime assets but left the TLS root bundle in the build directory, so published builds could not verify any certificate. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * Harden mbed TLS socket I/O handling * delete wii socket --------- Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> Co-authored-by: patchzyy <64382339+patchzyy@users.noreply.github.com>
93 lines
4.1 KiB
Bash
Executable File
93 lines
4.1 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# Turn one locally compiled macOS product into a self-contained .app bundle.
|
|
set -euo pipefail
|
|
|
|
fail() { printf 'publish-app.command: error: %s\n' "$*" >&2; exit 1; }
|
|
usage() {
|
|
cat <<'EOF'
|
|
Usage: publish-app.command --build-dir DIR --product {WiiCompiled|RetroRewind} --output-dir DIR
|
|
|
|
Copies a locally built product and its runtime assets into OUTPUT-DIR/<product>.app.
|
|
It bundles non-system dylibs, rewrites their install names, and ad-hoc signs the
|
|
result. This is suitable for local use; a release must replace ad-hoc signing
|
|
with the project's Developer ID signing and notarization process.
|
|
EOF
|
|
}
|
|
|
|
build_dir=""; product=""; output_dir=""
|
|
while (($#)); do
|
|
case "$1" in
|
|
--build-dir) build_dir=${2:-}; shift 2 ;;
|
|
--product) product=${2:-}; shift 2 ;;
|
|
--output-dir) output_dir=${2:-}; shift 2 ;;
|
|
-h|--help) usage; exit 0 ;;
|
|
*) fail "unknown option: $1" ;;
|
|
esac
|
|
done
|
|
[[ "$product" == WiiCompiled || "$product" == RetroRewind ]] || fail '--product must be WiiCompiled or RetroRewind'
|
|
for tool in codesign ditto install_name_tool otool; do command -v "$tool" >/dev/null || fail "required macOS tool is unavailable: $tool"; done
|
|
[[ -x "$build_dir/$product" ]] || fail "missing compiled product: $build_dir/$product"
|
|
for asset in dsp_coef.bin initial_pipeline_cache.db cacert.pem wii_bootstrap; do [[ -e "$build_dir/$asset" ]] || fail "missing runtime asset: $build_dir/$asset"; done
|
|
|
|
app="$output_dir/$product.app"
|
|
macos="$app/Contents/MacOS"
|
|
frameworks="$app/Contents/Frameworks"
|
|
resources="$app/Contents/Resources"
|
|
rm -rf "$app"
|
|
mkdir -p "$macos" "$frameworks" "$resources"
|
|
cat > "$app/Contents/Info.plist" <<EOF
|
|
<?xml version="1.0" encoding="UTF-8"?>
|
|
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
|
|
<plist version="1.0"><dict>
|
|
<key>CFBundleDevelopmentRegion</key><string>en</string>
|
|
<key>CFBundleExecutable</key><string>$product</string>
|
|
<key>CFBundleIdentifier</key><string>org.wiicompiled.$product</string>
|
|
<key>CFBundleInfoDictionaryVersion</key><string>6.0</string>
|
|
<key>CFBundleName</key><string>$product</string>
|
|
<key>CFBundlePackageType</key><string>APPL</string>
|
|
<key>CFBundleShortVersionString</key><string>0.1.0</string>
|
|
<key>CFBundleVersion</key><string>1</string>
|
|
<key>LSMinimumSystemVersion</key><string>14.0</string>
|
|
<key>NSHighResolutionCapable</key><true/>
|
|
</dict></plist>
|
|
EOF
|
|
ditto "$build_dir/$product" "$macos/$product"
|
|
for asset in dsp_coef.bin initial_pipeline_cache.db cacert.pem wii_bootstrap; do
|
|
ditto "$build_dir/$asset" "$resources/$asset"
|
|
ln -s "../Resources/$asset" "$macos/$asset"
|
|
done
|
|
|
|
# Build a closure of Homebrew dylibs. System libraries remain system references.
|
|
queue=("$macos/$product")
|
|
while ((${#queue[@]})); do
|
|
current=${queue[0]}
|
|
queue=("${queue[@]:1}")
|
|
while IFS= read -r dependency; do
|
|
[[ "$dependency" == /opt/homebrew/* || "$dependency" == /usr/local/* ]] || continue
|
|
[[ -f "$dependency" ]] || continue
|
|
name=$(basename "$dependency")
|
|
if [[ ! -f "$frameworks/$name" ]]; then
|
|
ditto "$dependency" "$frameworks/$name"
|
|
install_name_tool -id "@rpath/$name" "$frameworks/$name"
|
|
queue+=("$frameworks/$name")
|
|
fi
|
|
done < <(otool -L "$current" | tail -n +2 | awk '{print $1}')
|
|
done
|
|
while IFS= read -r binary; do
|
|
while IFS= read -r old; do
|
|
[[ "$old" == /opt/homebrew/* || "$old" == /usr/local/* ]] || continue
|
|
name=$(basename "$old")
|
|
[[ -f "$frameworks/$name" ]] || continue
|
|
if [[ "$binary" == "$macos/$product" ]]; then
|
|
install_name_tool -change "$old" "@executable_path/../Frameworks/$name" "$binary"
|
|
else
|
|
install_name_tool -change "$old" "@loader_path/$name" "$binary"
|
|
fi
|
|
done < <(otool -L "$binary" | tail -n +2 | awk '{print $1}')
|
|
done < <(find "$frameworks" -type f -print; printf '%s\n' "$macos/$product")
|
|
|
|
find "$frameworks" -type f -exec codesign --force --sign - {} +
|
|
codesign --force --deep --sign - "$app"
|
|
codesign --verify --deep --strict "$app"
|
|
printf 'MKWCBUILD:APP=%s\n' "$app"
|