From ae0024318561fc6f009300901e4c81be1b8f646f Mon Sep 17 00:00:00 2001 From: Hermes Date: Sat, 8 Aug 2026 11:44:40 +0000 Subject: [PATCH 1/6] Add libplist runtime dep (plist-d dlopens it; fixes silent provisioning failure) --- pkgs/anisette-v3-server/default.nix | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/pkgs/anisette-v3-server/default.nix b/pkgs/anisette-v3-server/default.nix index a64ba54..653b1b2 100644 --- a/pkgs/anisette-v3-server/default.nix +++ b/pkgs/anisette-v3-server/default.nix @@ -4,6 +4,7 @@ fetchFromGitHub, zlib, openssl_1_1, + libplist, }: buildDubPackage rec { @@ -19,7 +20,12 @@ buildDubPackage rec { dubLock = ./dub-lock.json; - buildInputs = [ zlib openssl_1_1 ]; + # libplist is dlopen'd at runtime by the plist-d C binding (libplist-2.0.so.3). + # The reference Docker image installs it explicitly (see Dadoum/anisette-v3-server#46: + # "Anisette did build but not run with current Dockerfile, I have added the + # dependencies"). Without it the ADI provisioning step fails silently and the + # server serves unprovisioned data, so Apple rejects the login. + buildInputs = [ zlib openssl_1_1 libplist ]; installPhase = '' runHook preInstall -- 2.55.0 From 59fcec2e6d6860db7068d418f5a72897b974819b Mon Sep 17 00:00:00 2001 From: Hermes Date: Sat, 8 Aug 2026 11:52:14 +0000 Subject: [PATCH 2/6] Build with static D runtime config (matches reference Dockerfile) --- pkgs/anisette-v3-server/default.nix | 15 ++++++++------- 1 file changed, 8 insertions(+), 7 deletions(-) diff --git a/pkgs/anisette-v3-server/default.nix b/pkgs/anisette-v3-server/default.nix index 653b1b2..c2cb824 100644 --- a/pkgs/anisette-v3-server/default.nix +++ b/pkgs/anisette-v3-server/default.nix @@ -4,7 +4,6 @@ fetchFromGitHub, zlib, openssl_1_1, - libplist, }: buildDubPackage rec { @@ -20,12 +19,14 @@ buildDubPackage rec { dubLock = ./dub-lock.json; - # libplist is dlopen'd at runtime by the plist-d C binding (libplist-2.0.so.3). - # The reference Docker image installs it explicitly (see Dadoum/anisette-v3-server#46: - # "Anisette did build but not run with current Dockerfile, I have added the - # dependencies"). Without it the ADI provisioning step fails silently and the - # server serves unprovisioned data, so Apple rejects the login. - buildInputs = [ zlib openssl_1_1 libplist ]; + # The reference Dockerfile builds with `dub build -c "static"` (statically + # linked D runtime). The Android-ELF loader does low-level symbol resolution + # and memory manipulation that is fragile with a dynamically-linked D runtime + # (GC/TLS conflicts), which can make the ADI provisioning step fail silently. + # Match the reference build config. + dubBuildFlags = [ "-c" "static" ]; + + buildInputs = [ zlib openssl_1_1 ]; installPhase = '' runHook preInstall -- 2.55.0 From 6e5860a85129299010c8f793f2d03a8c6ff7c864 Mon Sep 17 00:00:00 2001 From: Hermes Date: Sat, 8 Aug 2026 11:52:47 +0000 Subject: [PATCH 3/6] TEMP: log swallowed provisioning exception for diagnosis --- pkgs/anisette-v3-server/default.nix | 11 +++++------ pkgs/anisette-v3-server/log-provisioning-error.patch | 11 +++++++++++ 2 files changed, 16 insertions(+), 6 deletions(-) create mode 100644 pkgs/anisette-v3-server/log-provisioning-error.patch diff --git a/pkgs/anisette-v3-server/default.nix b/pkgs/anisette-v3-server/default.nix index c2cb824..65ab7ae 100644 --- a/pkgs/anisette-v3-server/default.nix +++ b/pkgs/anisette-v3-server/default.nix @@ -19,12 +19,11 @@ buildDubPackage rec { dubLock = ./dub-lock.json; - # The reference Dockerfile builds with `dub build -c "static"` (statically - # linked D runtime). The Android-ELF loader does low-level symbol resolution - # and memory manipulation that is fragile with a dynamically-linked D runtime - # (GC/TLS conflicts), which can make the ADI provisioning step fail silently. - # Match the reference build config. - dubBuildFlags = [ "-c" "static" ]; + # TEMP diagnostic: log the swallowed provisioning exception to find the real + # cause of the silent provisioning failure. + postPatch = '' + patch -p1 < ${./log-provisioning-error.patch} + ''; buildInputs = [ zlib openssl_1_1 ]; diff --git a/pkgs/anisette-v3-server/log-provisioning-error.patch b/pkgs/anisette-v3-server/log-provisioning-error.patch new file mode 100644 index 0000000..b005d51 --- /dev/null +++ b/pkgs/anisette-v3-server/log-provisioning-error.patch @@ -0,0 +1,11 @@ +--- a/source/app.d ++++ b/source/app.d +@@ -156,7 +156,9 @@ + ProvisioningSession provisioningSession = new ProvisioningSession(v1Adi, v1Device); + provisioningSession.provision(dsId); + log.info("Provisioning done!"); +- } catch (Exception) {} ++ } catch (Exception e) { ++ log.error("Provisioning failed: %s", e.msg); ++ } + } -- 2.55.0 From a6931f7357e23b6c0e452373c934b59a3039de2a Mon Sep 17 00:00:00 2001 From: Hermes Date: Sat, 8 Aug 2026 11:55:41 +0000 Subject: [PATCH 4/6] Fix diagnostic log format --- pkgs/anisette-v3-server/log-provisioning-error.patch | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/anisette-v3-server/log-provisioning-error.patch b/pkgs/anisette-v3-server/log-provisioning-error.patch index b005d51..a2083e1 100644 --- a/pkgs/anisette-v3-server/log-provisioning-error.patch +++ b/pkgs/anisette-v3-server/log-provisioning-error.patch @@ -6,6 +6,6 @@ log.info("Provisioning done!"); - } catch (Exception) {} + } catch (Exception e) { -+ log.error("Provisioning failed: %s", e.msg); ++ log.error("Provisioning failed: {}", e.msg); + } } -- 2.55.0 From 463817d00c549a3efa0c05e6cae0449182729578 Mon Sep 17 00:00:00 2001 From: Hermes Date: Sat, 8 Aug 2026 11:58:31 +0000 Subject: [PATCH 5/6] Use slf4d error(Exception) signature --- pkgs/anisette-v3-server/log-provisioning-error.patch | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/anisette-v3-server/log-provisioning-error.patch b/pkgs/anisette-v3-server/log-provisioning-error.patch index a2083e1..6d29acc 100644 --- a/pkgs/anisette-v3-server/log-provisioning-error.patch +++ b/pkgs/anisette-v3-server/log-provisioning-error.patch @@ -6,6 +6,6 @@ log.info("Provisioning done!"); - } catch (Exception) {} + } catch (Exception e) { -+ log.error("Provisioning failed: {}", e.msg); ++ log.error(e); + } } -- 2.55.0 From 81de36baa28e934dfad2a8bbbbb3794dcb1d770e Mon Sep 17 00:00:00 2001 From: Hermes Date: Sat, 8 Aug 2026 12:01:40 +0000 Subject: [PATCH 6/6] Add libplist runtime dep via wrapper (fixes silent provisioning failure) --- pkgs/anisette-v3-server/default.nix | 18 +++++++++++++----- .../log-provisioning-error.patch | 11 ----------- 2 files changed, 13 insertions(+), 16 deletions(-) delete mode 100644 pkgs/anisette-v3-server/log-provisioning-error.patch diff --git a/pkgs/anisette-v3-server/default.nix b/pkgs/anisette-v3-server/default.nix index 65ab7ae..ee6a81f 100644 --- a/pkgs/anisette-v3-server/default.nix +++ b/pkgs/anisette-v3-server/default.nix @@ -2,8 +2,10 @@ lib, buildDubPackage, fetchFromGitHub, + makeWrapper, zlib, openssl_1_1, + libplist, }: buildDubPackage rec { @@ -19,14 +21,20 @@ buildDubPackage rec { dubLock = ./dub-lock.json; - # TEMP diagnostic: log the swallowed provisioning exception to find the real - # cause of the silent provisioning failure. - postPatch = '' - patch -p1 < ${./log-provisioning-error.patch} - ''; + nativeBuildInputs = [ makeWrapper ]; buildInputs = [ zlib openssl_1_1 ]; + # libplist is dlopen'd at runtime by the plist-d C binding via dynamic-loader + # (libplist-2.0.so.3). It is NOT linked, so it does not land in the closure + # via buildInputs. Without it the ADI provisioning step throws + # LibraryLoadingException and the server serves unprovisioned data, so Apple + # rejects the login. Wrap the binary with LD_LIBRARY_PATH so dlopen finds it. + postFixup = '' + wrapProgram $out/bin/anisette-v3-server \ + --prefix LD_LIBRARY_PATH : ${lib.makeLibraryPath [ libplist ]} + ''; + installPhase = '' runHook preInstall mkdir -p $out/bin diff --git a/pkgs/anisette-v3-server/log-provisioning-error.patch b/pkgs/anisette-v3-server/log-provisioning-error.patch deleted file mode 100644 index 6d29acc..0000000 --- a/pkgs/anisette-v3-server/log-provisioning-error.patch +++ /dev/null @@ -1,11 +0,0 @@ ---- a/source/app.d -+++ b/source/app.d -@@ -156,7 +156,9 @@ - ProvisioningSession provisioningSession = new ProvisioningSession(v1Adi, v1Device); - provisioningSession.provision(dsId); - log.info("Provisioning done!"); -- } catch (Exception) {} -+ } catch (Exception e) { -+ log.error(e); -+ } - } -- 2.55.0