mirror of
https://github.com/Lakr233/vphone-cli.git
synced 2026-09-06 01:34:27 +00:00
kernel: jb: Bypass exec ip_mac_return SECURITY_POLICY kill for newer userlands
Running iOS 27.0 userland on the 26.4 vphone600 kernel, every core platform daemon (backboardd, cfprefsd, containermanagerd, locationd, CommCenter, ...) died 3-5ms after xpcproxy spawn with exit reason namespace 9 / code 0x8 (OS_REASON_EXEC / EXEC_EXIT_REASON_SECURITY_POLICY). launchd throttled the respawns and the boot deadlocked (all CPUs idle) before SpringBoard — no UI, no networking. Root cause: AMFI's exec MAC hooks reject the 27.0 binaries' code-sign validation category on the 26.4 kernel, setting imgp->ip_mac_return, and XNU's exec path (kern_exec.c) SIGKILLs on `if (imgp->ip_mac_return != 0)`. patch_exec_security_policy_kill flips the `cbz wN, <skip>` guard preceding the os_reason_create(9,8) call to an unconditional `b <skip>`, making the kill block unreachable — downstream of AMFI/TXM, so it covers the validation-category reject regardless of which hook set the verdict. Anchored structurally (movz w0,#9 ; movz w1,#8 preceded by ldr wN,[xM,#imm] ; cbz wN,<fwd>; W-register cbz distinguishes the ip_mac_return site from the subsystem-root sibling). No-op in effect for version-matched userlands (ip_mac_return == 0, so the cbz already skips). Wired into the JB Group C dispatcher. Validated on iPhone17,3_27.0_24A5380h + cloudOS 26.4 (c0ecdb4b): 0 SECURITY_POLICY kills, core daemons launch, networking + SSH (dropbear :22222) come up. Remaining gate: sandbox denies backboardd the IOMobileFramebuffer/IOSurface user clients, so SpringBoard traps in FBSDisplayMonitor init (no display) -> UI not up yet. Co-Authored-By: Claude Opus 4.8 <[email protected]> Claude-Session: https://claude.ai/code/session_013pk5tsoBeuu3jhkmnRFtic
This commit is contained in:
committed by
zqxwce
co-authored by
Claude Opus 4.8
parent
a38fd3201f
commit
679d3d0476
@@ -126,6 +126,7 @@
|
||||
| ----- | ----- | ------------------------------------- | ---------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | :--------: |
|
||||
| JB-01 | A | `patch_amfi_cdhash_in_trustcache` | `AMFIIsCDHashInTrustCache` | Always return true + store hash | Y |
|
||||
| JB-02 | A | `patch_amfi_execve_kill_path` | AMFI execve kill return site | Convert shared kill return from deny to allow (superseded by C21; standalone only) | N |
|
||||
| JB-02b| C | `patch_exec_security_policy_kill` | XNU exec `imgp->ip_mac_return` gate (kern_exec, `os_reason_create(OS_REASON_EXEC, EXEC_EXIT_REASON_SECURITY_POLICY)` site) | Flip `cbz wN, <skip>` → unconditional `b <skip>` so the exec-time MAC-verdict `SECURITY_POLICY` kill is unreachable. **Needed to run a userland NEWER than the kernel (iOS 27.0 on the 26.4 kernel):** AMFI's exec hooks reject the newer binaries' code-sign validation category, setting `ip_mac_return != 0` → core daemons (backboardd/cfprefsd/containermanagerd/…) die at exec (`namespace 9 / code 0x8`) → boot deadlock. Validated on 27.0/26.4: 0 SECURITY_POLICY kills, daemons launch, networking + SSH come up. No-op-in-effect for version-matched userlands (ip_mac_return == 0 there, so the original cbz already skips). | Y |
|
||||
| JB-03 | C | `patch_cred_label_update_execve` | `_cred_label_update_execve` | Reworked C21-v3: C21-v1 already boots; v3 keeps split late exits and additionally ORs success-only helper bits `0xC` after clearing `0x3F00`; still disabled pending boot validation | N |
|
||||
| JB-04 | C | `patch_hook_cred_label_update_execve` | sandbox `mpo_cred_label_update_execve` wrapper (`ops[18]` -> `sub_FFFFFE00093BDB64`) | Faithful upstream C23 trampoline: copy `VSUID`/`VSGID` owner state into pending cred, set `P_SUGID`, then branch back to wrapper | Y |
|
||||
| JB-05 | C | `patch_kcall10` | `sysent[439]` (`SYS_kas_info` replacement) | Rebuilt ABI-correct kcall cave: `target + 7 args -> uint64 x0`; re-enabled after focused dry-run validation | Y |
|
||||
|
||||
Reference in New Issue
Block a user