Documentation
¶
Index ¶
Constants ¶
const ( SignatureSigned = "signed" SignatureAdHoc = "ad-hoc" SignatureUnsigned = "unsigned" SignatureUnreadable = "unreadable" )
Signature statuses reported for a main executable or a flat package.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type ArchitectureSignature ¶
type ArchitectureSignature struct {
CPUType uint32
CPUSubtype uint32
Arch string
CodeSignature string
CodeSignatureError string
Signer *SignerIdentity
}
ArchitectureSignature is the code signature of one Mach-O architecture slice. CPUType and CPUSubtype are the raw values from the universal header, or from the Mach-O header of a thin executable.
type IPAManifest ¶
type IPAManifest struct {
BundleID string
Name string
Version string
BuildNumber string
MinimumOSVersion string
Platforms []string
TeamID string
SignerCommonName string
Status string
NestedBundles []NestedBundle
Entitlements map[string]any
Profile *ProfileSummary
// CodeSignature classifies the main executable's embedded signature. It is
// empty when inspection stopped before the executable was read.
CodeSignature string
CodeSignatureError string
Signer *SignerIdentity
// Architectures lists every slice of the main executable in universal
// header order; a thin executable has one. CodeSignature, CodeSignatureError,
// and Signer describe the slice stored first. It is nil when no slice could
// be identified.
Architectures []ArchitectureSignature
// SignerConsistent reports whether every slice has the same signature
// classification and signer. It is nil when Architectures is nil.
SignerConsistent *bool
}
IPAManifest is the offline manifest for an IPA.
func InspectIPA ¶
func InspectIPA(source io.ReaderAt, size int64, includeEntitlements, includeProfile bool) (IPAManifest, error)
InspectIPA reads a bounded IPA zip and returns a metadata manifest. A missing embedded profile is reported as unsigned. The main executable's signer identity is read from its code signature, which is not verified.
type NestedBundle ¶
NestedBundle is an extension or App Clip inside the IPA.
type PKGManifest ¶
type PKGManifest struct {
ProductID string
Version string
InstallLocation string
BundleIDs []string
SignerCommonName string
TeamID string
Status string
// PackageSignature classifies the xar signature in the table of contents.
PackageSignature string
PackageSignatureError string
Signer *SignerIdentity
}
PKGManifest is the offline manifest for a flat component package.
func InspectPKG ¶
func InspectPKG(source io.ReaderAt, size int64) (PKGManifest, error)
InspectPKG reads PackageInfo from a flat xar component package. The signer identity is read from the package signature certificates, which are not verified.
type ProfileSummary ¶
ProfileSummary is the embedded provisioning profile summary.
type SignerIdentity ¶
type SignerIdentity struct {
CommonName string
TeamID string
Organization string
IssuerCommonName string
SerialNumber string
NotBefore string
NotAfter string
SHA1Fingerprint string
SHA256Fingerprint string
}
SignerIdentity describes the leaf certificate embedded in a signature. It is read from the artifact and is not validated against a trust store.
Directories
¶
| Path | Synopsis |
|---|---|
|
Package artifactstest builds synthetic signed IPA and flat package fixtures.
|
Package artifactstest builds synthetic signed IPA and flat package fixtures. |