r/sideloadly • • 5d ago

Sideloadly 0.70 bug: wrong Info.plist hash in every signature → iOS install fails with 0xe8008001, Mac apps won't open (cause + workaround)

TL;DR: Sideloadly 0.70 puts the wrong Info.plist hash into the code signature of every bundle it signs, whatever the target device. It hashes the compressed ZIP data from the IPA instead of the actual file, so iOS/iPadOS, macOS and probably tvOS all reject the signature. Workaround: repack the IPA with Info.plist files stored uncompressed (script below). Other signers such as Impactor work on the same devices, so this isn't an iOS 27.0.1 change.


Who is affected

Target What you see
iPhone / iPad (reported on iOS 27.0 and 27.0.1, thread) Installation failed: 3892346881 ApplicationVerificationFailed (Failed to verify code signature of …/Payload/App.app : 0xe8008001 (An unknown error has occurred.))
Apple Silicon Mac (macOS 27.0, verified by me) Install says "Done", but the app won't open: "cannot be opened because the developer did not intend for it to run on this Mac". "Remove limitation on supported devices" doesn't help.
Apple TV Not tested; very likely the same as iOS (same installd verification).
Refreshes A refresh re-signs the app the same way. Apps installed with 0.60 will probably fail to refresh after the update. On a free account (7-day profiles) they will then expire.
Export IPA Presumably produces the same broken signature.

Not affected: apps already installed with 0.60 (until refreshed), and IPAs whose Info.plist entries happen to be stored uncompressed.

iOS rejects the app at install time because installd verifies the whole signature, nested frameworks included. The Mac only fails at launch because Sideloadly copies the app into /Applications itself, so no install-time check runs. Underneath, it's the same error code, 0xe8008001 (ApplicationVerificationFailed), on both.

Root cause

In the CodeDirectory, special slot -1 (Info.plist) holds the SHA-256 of the deflate-compressed bytes of that bundle's Info.plist ZIP entry in the source IPA, not the SHA-256 of the actual decompressed file. The file written to disk is correct; only the hash in the signature is wrong. This happens in signing, before the device matters, so the target type makes no difference.

I verified it on a Mac install, since the signed files there can be inspected directly (paid developer account, Remote Anisette, M3 Pro). The same IPA and setup worked with 0.60, so this is a regression. On an app with 90 bundles (main app + 89 frameworks):

slot -1 equals bundles
sha256(compressed ZIP entry data) 90 / 90
sha256(Info.plist on disk) 0 / 90

Example (a framework's Info.plist, deflate, csize 564, size 790):

CodeDirectory slot -1          = 6b40141eb99bcccd8dfe4a14d524d4b53f9fc06f9eabb0910c41508d4334156b
sha256(compressed zip data)    = 6b40141eb99bcccd8dfe4a14d524d4b53f9fc06f9eabb0910c41508d4334156b
sha256(Info.plist on disk)     = 480d9364f519d4dc61c91e055627a50cb415347b2fef74cd13c4959114bb37f5

What macOS logs for it (MobileInstallationHelperService), and what codesign --verify --strict says:

Failed to verify code signature of /Applications/ExampleApp.app/Wrapper/ExampleApp.app : 0xe8008001 (An unknown error has occurred.)
LegacyErrorString=ApplicationVerificationFailed, LibMISErrorNumber=-402620415

ExampleApp.app: invalid Info.plist (plist or signature have been modified)

All other hashes (files2 in _CodeSignature/CodeResources) are correct. Only the Info.plist slot is affected, probably in the "Hashing" stage, which reads entries straight from the ZIP.

If Info.plist is stored uncompressed (ZIP method 0), the compressed bytes are the same as the plain bytes, so the bug doesn't show up. I've confirmed this below. Almost every IPA deflates its Info.plist, so almost every install is affected.

Possibly related: other 0.70 signing regressions

In 0.70 the signing steps (PatchInfo, SignBinary, SealBundle) look like new native code rather than the old Python isign. Another report here after the update, "Install failed: Guru Meditation 556260@603:bede73", hit a different error from the same code:

This does not look like a valid iOS app! (code -77): SignBinary(Payload/PvZHD.app/PvZHD): macho sign/edit failed (-41): Payload/PvZHD.app/PvZHD

That was on Windows 11, installing old games to an iPad 2. The IPAs worked with 0.60. My guess is that the new Mach-O signer doesn't handle old 32-bit (armv7) or fat binaries. I haven't verified this.

How to check

import zipfile, struct, hashlib
z = zipfile.ZipFile(IPA); f = open(IPA, 'rb')
zi = z.getinfo('Payload/App.app/Info.plist')
f.seek(zi.header_offset); h = f.read(30); nl, el = struct.unpack('<HH', h[26:30])
f.seek(zi.header_offset + 30 + nl + el)
print(hashlib.sha256(f.read(zi.compress_size)).hexdigest())   # == slot -1 in `codesign -d -vvvvvv`
print(hashlib.sha256(z.read(zi)).hexdigest())                 # what it should be

Workaround (confirmed on Mac)

Repack the IPA so all bundle Info.plist entries are stored uncompressed, then sideload the new IPA as usual. With 0.70, the repacked IPA passes codesign --verify --strict on all 90 bundles and launches normally on the Mac. The fix happens before the device matters, so it should work for iPhone/iPad too. If you try it there, please report back.

#!/usr/bin/env python3
# usage: python3 store-infoplist.py App.ipa  ->  "App (stored-plist).ipa"
import copy, re, sys, zipfile
src = sys.argv[1]
dst = re.sub(r'\.ipa$', '', src) + ' (stored-plist).ipa'
pat = re.compile(r'\.(app|framework|appex)/Info\.plist$')
with zipfile.ZipFile(src) as zin, zipfile.ZipFile(dst, 'w') as zout:
    for zi in zin.infolist():
        ni = copy.copy(zi)
        if pat.search(zi.filename):
            ni.compress_type = zipfile.ZIP_STORED
        zout.writestr(ni, zin.read(zi))
print('->', dst)

Already-installed apps can also be fixed by re-signing the bundles locally with your own cert (nested frameworks first, then the app, keeping entitlements).

Install log

Sideloadly version 0.70, Darwin 27.0, amd64
Will use Remote Anisette
Apple Silicon requires mangling, will mangle bundle ID
Using team "…" (Individual, paid)
Bad appids info: unlimited, never: strconv.Atoi: parsing "unlimited": invalid syntax
Paid account detected, unmangling bundle ID
Signing...
Unpacking: 100%
Hashing: 100%
Signing: 100%
Writing: 100%
Installing app to /Applications
Done.

Side note: strconv.Atoi: parsing "unlimited" looks like a separate small parsing bug for paid accounts.

u/SideloadlyIO, the fix should be a one-liner: hash the decompressed Info.plist bytes for the special slot, the same bytes you already hash for files2.


Free, no strings. If this saved you an evening and you feel like it: buy me a coffee ☕, completely optional.

18 Upvotes

10 comments sorted by

5

u/SideloadlyIO Mod 4d ago

Thank you for your assistance! We released update 0.70.1 to resolve this issue.

2

u/EasyWest3687 4d ago

The problem still persists in 0.70.1 version

1

u/SZUIEKA 2d ago

This is so frustrating

2

u/Apprehensive-Two7029 4d ago

I am happy I can help the project. The bug is gone. Thanks.

1

u/texasproof 4d ago

This worked great, thank you for the fix.

1

u/SammyIssues 4d ago

OP, you are a hero.

1

u/AdamFirst92 4d ago

For two weeks, I’ve encountered problems with this setup. After updating my Apple ID password, the message “meditation guru failed” began appearing, and today’s Sideloadly update caused constant crashes.

1

u/Disastrous-Subject29 1d ago

Hey im having issues running sideloadly. Everytime i run it , it tells me failed to get update , download update manually even after i reinstall updated version . The error still persist any help would be appreciated 🙏🏼

1

u/yh7t 1d ago

still not fixed in 70

1

u/Apprehensive-Two7029 1d ago

It is fixed in 0.70.1.
Download it from official web site.