Add in other restricted entitlements

This commit is contained in:
Dhinak G 2023-12-02 23:45:41 -05:00
parent 5eecb677a7
commit a56bf738bd
No known key found for this signature in database
1 changed files with 17 additions and 5 deletions

View File

@ -565,8 +565,8 @@ int signApp(NSString* appPath)
} }
} }
// On iOS 16+, any binary with get-task-allow requires developer mode to be enabled, so we will check // On iOS 16+, binaries with certain entitlements requires developer mode to be enabled, so we'll check
// while we're at it // while we're fixing entitlements
BOOL requiresDevMode = NO; BOOL requiresDevMode = NO;
NSURL* fileURL; NSURL* fileURL;
@ -615,9 +615,21 @@ int signApp(NSString* appPath)
// Developer mode does not exist before iOS 16 // Developer mode does not exist before iOS 16
if (@available(iOS 16, *)){ if (@available(iOS 16, *)){
NSObject *getTaskAllowO = entitlementsToUse[@"get-task-allow"]; if (!requiresDevMode) {
if (getTaskAllowO && [getTaskAllowO isKindOfClass:[NSNumber class]]) { for (NSString* restrictedEntitlementKey in @[
requiresDevMode |= [(NSNumber *)getTaskAllowO boolValue]; @"get-task-allow",
@"task_for_pid-allow",
@"com.apple.system-task-ports",
@"com.apple.system-task-ports.control",
@"com.apple.system-task-ports.token.control",
@"com.apple.private.cs.debugger"
]) {
NSObject *restrictedEntitlement = entitlementsToUse[restrictedEntitlementKey];
if (restrictedEntitlement && [restrictedEntitlement isKindOfClass:[NSNumber class]]) {
requiresDevMode |= [(NSNumber *)restrictedEntitlement boolValue];
break;
}
}
} }
} }