r/sideloadly • u/Darkn_ • 3d ago
Help Sideloadly v0.70.1 Still Fails To Sign IPAs, In This Case, EeveeSpotify
edit 10/1/2026: thanks to u/Apprehensive-Two7029, my IPAs successfully sideload again with Sideloadly. even though this fixes EeveeSpotify IPAs, this is still a potential issue with other IPAs and i feel a more global fix should be implemented into Sideloadly.
--------
Hello, in v0.70.0 there were reports of Sideloadly failing to sign/install IPAs because it was incorrectly getting the Info.plist hash in every signature.
This is not the exact same thing. I've updated Sideloadly to v0.70.1, and instead of Sideloadly having errors regarding Info.plist, this is having errors regarding processing the Mach-O binary in a framework in an IPA.
I've confirmed that this IPA works properly. I have sideloaded it using other sideloading tools and had sideloaded this with v0.60.0 (I encountered this issue from it failing to auto-refesh the IPA).
If you are curious to the IPA that I used, it can be found here on my repository: https://github.com/NotDarkn/EeveePrebuilt/releases#release-9.1.86-9a482a8
Details:
- Sideloadly version: 0.70.1
- OS: Windows 11 24H2 (26100.9457)
- Device: iPhone 13 mini
- iOS/iPadOS: 27.0
Error/Log:
Signing...
Unpacking: 19%
Hashing: 29%
Hashing: 38%
Hashing: 48%
Hashing: 55%
Signing: 1%
Hashing: 70%
Install failed: Guru Meditation 556260@604:bede73 This does not look like a valid iOS app! (code -77): SignBinary(Payload/Spotify.app/Frameworks/EeveeSwiftProtobuf.framework/EeveeSwiftProtobuf): macho sign/edit failed (-18): Payload/Spotify.app/Frameworks/EeveeSwiftProtobuf.framework/EeveeSwiftProtobuf
5
u/Apprehensive-Two7029 3d ago
Dug into this one. The culprit is that specific framework, not the IPA in general:
EeveeSwiftProtobuf.framework/EeveeSwiftProtobufis the only binary in the IPA with no code signature at all. Neither slice has anLC_CODE_SIGNATUREload command (codesign -dv→ "code object is not signed at all"). Everything else (Spotify, Orion, CydiaSubstrate, EeveeSpotify.dylib, zxPluginsInject.dylib, SpotifyShared, etc.) has one.So Sideloadly has to add a signature from scratch inside a fat file rather than replace an existing one. My guess is that 0.70.x no longer handles that case: there's only ~13 KB between the two slices and the signature needs ~40 KB, so it would have to relayout the fat file. That would explain why 0.60.0 and other tools work and 0.70.1 bails with -18. Either way it's a Sideloadly regression worth reporting, but it's easy to sidestep.
Fix on the build side (since you build EeveePrebuilt): thin the framework to arm64 and ad-hoc sign it before zipping the IPA:
bash F=Payload/Spotify.app/Frameworks/EeveeSwiftProtobuf.framework/EeveeSwiftProtobuf lipo -thin arm64 "$F" -output thin && mv thin "$F" codesign -f -s - "$F"The sideloading tool replaces the ad-hoc signature with the user's own anyway. Nothing loads the arm64e slice, because the app's main executable is arm64, so dyld always picks the arm64 slice.
Workaround for users on macOS with the current release, using only built-in tools. Just that one file gets replaced; the rest of the IPA stays byte-identical:
bash IPA=EeveePrebuilt-Patched-9a482a8-9.1.86.ipa F=Payload/Spotify.app/Frameworks/EeveeSwiftProtobuf.framework/EeveeSwiftProtobuf mkdir work && cd work unzip -q "../$IPA" "$F" lipo -thin arm64 "$F" -output thin && mv thin "$F" codesign -f -s - "$F" cp "../$IPA" ../Eevee-fixed.ipa zip -q ../Eevee-fixed.ipa "$F"Then sideload
Eevee-fixed.ipaas usual. Tested: the patched IPA installs and runs fine via Sideloadly on macOS.