198 Commits
Author SHA1 Message Date
zqxwce 87f796c62a resources: Update resources reference 2026-09-01 01:33:43 +03:00
zqxwceandClaude Fable 5 2af884b56c resources: Bump storage submodule to fork main (drop ramdisk_input.tar.zst)
Fork main was force-pushed to ae7a0ac, orphaning the previously pinned
ee9a284. Advance the pin so fresh clones resolve against a live ref.

Co-Authored-By: Claude Fable 5 <[email protected]>
2026-08-29 03:44:16 +03:00
zqxwceandClaude Fable 5 3bb6f0fda4 frida: Add build.frida.re as a Sileo/apt source at first boot
The JB first-boot setup adds the Frida repo (deb https://build.frida.re/ ./)
next to the existing Havoc source, so Sileo/apt can install and update Frida
packages. Idempotent — skipped if a build.frida.re source is already present —
and picked up by the same insecure-repo `apt-get update` that follows.

Co-Authored-By: Claude Fable 5 <[email protected]>
2026-08-12 13:29:42 +03:00
zqxwceandClaude Fable 5 ae29e6de84 frida: Install re.frida.server via the extra-debs mechanism
On a --frida build, fetch_debs.sh resolves the latest frida iphoneos-arm64
release deb (== re.frida.server: no Depends, rootless /var/jb layout) into the
debs cache; the existing first-boot `dpkg -i` step installs it. VPHONE_FRIDA is
forwarded through the host CFW install. No APT source or dependency resolution.

Co-Authored-By: Claude Fable 5 <[email protected]>
2026-08-12 11:40:24 +03:00
ZomkaDEV a5d624b613 fix: re-encode signcert.p12 as modern PKCS12 2026-08-11 15:05:35 +03:00
ZomkaDEV 334a558e32 fix: treat LSD embedded-reg gate as idempotent when already NOP'd 2026-08-11 15:05:35 +03:00
zqxwceandClaude Opus 4.8 f48fc29a27 cfw: Patch os_lockdown_mode_enabled to not crash on iOS 27b5
iOS 27's os_lockdown_mode_enabled() resolves Lockdown Mode via
sysctlbyname("security.mac.lockdown_mode_state_public", ...) and os_crashes
on a -1 return. The vphone base kernel (cloudOS 26.x) does not implement that
MAC sysctl, so the call returns -1/ENOENT and the first daemon to query
Lockdown Mode after "Continuing system boot" -- launchd (pid 1) -- aborts,
panicking the system (initproc exited, namespace 2 subcode 6).

Add cfw_patch_lockdown_mode.py: NOP the `cmn w0,#1; b.eq <os_crash>` gate so
the pre-zeroed output buffer path is taken (Lockdown Mode = disabled);
behavior-neutral on a kernel that implements the sysctl. Wire it into cfw.py
(patch-lockdown-mode) and the cfw_install.sh 27.* DSC-patch block. Also fixes
the 0_binary_patch_comparison.md LWCR note and adds row 16.

Co-Authored-By: Claude Opus 4.8 <[email protected]>
Claude-Session: https://claude.ai/code/session_01N2bwKrGJWY7o2ArdxibVPe
2026-08-11 14:50:22 +03:00
zqxwceandClaude Opus 4.8 ab456ac67e cfw: Apply the libxpc LWCR patch on iOS 27 (correct mangled symbol)
The patcher resolved `_xpc_token_satisfies_lwcr`, but libxpc's internal
routine carries the standard extra leading underscore in the DSC symbol
table (`__xpc_token_satisfies_lwcr`), so the lookup missed and the patch
silently no-op'd on every iOS 27 build. Resolve against the mangled name,
falling back to the source name.

Co-Authored-By: Claude Opus 4.8 <[email protected]>
Claude-Session: https://claude.ai/code/session_01N2bwKrGJWY7o2ArdxibVPe
2026-08-11 14:50:22 +03:00
zqxwce 545fd35e0f deps: Add cmake
PyPI has no arm64 macOS wheel for keystone-engine, so pip builds it
from the sdist, whose make-share.sh invokes cmake directly. Without
it the build fails silently and installs bindings with no native
library, which is what the libkeystone repair recovers from.
2026-08-05 18:24:56 +03:00
zqxwceandClaude Opus 4.8 6aef60bd9a vphone-cli: Add --root-popup to elevate CFW host-mount via macOS auth dialog
* feat: add --root-popup to elevate CFW host-mount via macOS auth dialog

Adds --root-popup to `cfw install` and `vm create`, elevating the CFW host-mount through macOS's native authentication dialog (osascript -> do shell script with administrator privileges) instead of the script's sudo re-exec. do shell script runs under a bare env, so the vars the bundled scripts read are forwarded inline, plus SUDO_USER so the script's chown-back still returns artifacts to the invoking user. On `vm create`, --sudo-password takes precedence.

Co-Authored-By: Claude Opus 4.8 <[email protected]>

* cfw: remove entire .cfw_temp on install cleanup

Replaces the selective `rm -f` of individual temp binaries with `rm -rf "$TEMP_DIR"`, dropping the cached Cryptex DMGs along with the temp files.

Co-Authored-By: Claude Opus 4.8 <[email protected]>

---------

Co-authored-by: Claude Opus 4.8 <[email protected]>
2026-08-02 11:20:22 +03:00
zqxwceandClaude Fable 5 744090f694 setup: Remove artifacts when done to save disk space
Delete the three large regenerable intermediates once their consumers
finish, keeping the source archives so nothing needs re-downloading:

- built restore firmware (iPhone*_Restore/) after CFW install (its last
  consumer — it copies the SystemOS/AppOS cryptexes onto Disk.img)
- extracted base-IPSW dirs (iOS + cloudOS) at end of fw prepare; the
  downloaded .ipsw files are kept, so a re-run re-extracts, no re-download
- extracted CFW input dirs (cfw_input/, cfw_jb_input/) after cfw install;
  the resources .tar.zst archives are kept

Opt out with --keep-artifacts on `vm create` / `cfw install`, which
threads VPHONE_KEEP_ARTIFACTS to fw_prepare.sh and cfw_install_host.sh.

Co-authored-by: Claude Fable 5 <[email protected]>
2026-07-30 15:06:45 +03:00
Kila2 25da0fa24a pymobiledevice3: Skip pairing refused devices 2026-07-30 11:08:25 +03:00
zqxwceandClaude Opus 4.8 8b6ffd2e26 fix: bundle vphone-amfidont in Resources, not MacOS (unbreaks .app signing)
The v1.0.2 release build failed at the bundle codesign step:

  .build/vphone-cli.app/Contents/MacOS/vphone-cli: code object is not signed at all
  In subcomponent: .../Contents/MacOS/vphone-amfidont

Contents/MacOS is the bundle's nested-code directory, so signing the main
executable seals everything there and rejected the vphone-amfidont shell
script as unsigned nested code. (A script only gets a "generic" xattr
signature that wouldn't survive the release zip anyway.)

Move the bundled helper to Contents/Resources/vphone-amfidont, where it is
sealed as an ordinary resource (hashed, survives zip). Resources sits at the
same depth under Contents as MacOS, so the script's `${0:A:h:h:h}` .app
resolution is unchanged. The Homebrew `binary` stanza should point at
Contents/Resources/vphone-amfidont.

Co-Authored-By: Claude Opus 4.8 <[email protected]>
Claude-Session: https://claude.ai/code/session_01Y4VDqWf5pVakcFLqB23CKe
2026-07-28 17:26:26 +03:00
zqxwceandClaude Opus 4.8 766d1555fb feat: add vphone-amfidont helper to allow the .app through amfid
New bundled tool `vphone-amfidont` (zsh script at Contents/MacOS/, exposed
on PATH alongside vphone-cli). It:

- resolves the enclosing vphone-cli.app (`${0:A:h:h:h}`; :A follows a
  Homebrew symlink back into the bundle);
- ensures amfidont is installed, offering `xcrun python3 -m pip install`
  if it is missing;
- checks (without root) whether an amfidont is already running — only one
  can attach to amfid at a time. If so, it escalates to a single sudo to
  read the running process's args and the /var/root config, reports whether
  this .app is already covered (allowed path or --allow-all), and exits;
- otherwise starts `amfidont daemon --spoof-apple --path <app>`, resolving
  amfidont's absolute path first so a pip-user install off root's
  secure_path is still found under sudo.

build.sh bundles it next to vphone-cli/ldid in Contents/MacOS.

Co-Authored-By: Claude Opus 4.8 <[email protected]>
Claude-Session: https://claude.ai/code/session_01Y4VDqWf5pVakcFLqB23CKe
2026-07-28 16:59:26 +03:00
zqxwce 084e239c36 fix: resolve all paths correctly for the bundled / brew-installed app
A whole-codebase audit surfaced path bugs that only bite the bundled .app —
especially when brew puts vphone-cli on $PATH via a symlink, so the process
launches by a bare name from an arbitrary CWD:

- HIGH (crash): CommandLine.arguments[0] was used to locate the running binary
  and the resource base (VPhoneResources.resolve default, vm launch bootBinary,
  vm create selfExe). Under a bare-name PATH launch argv[0] is just
  "vphone-cli", which URL(fileURLWithPath:) resolves against the CWD (e.g.
  $HOME/vphone-cli) — so `vm launch` errored "not found" and `vm create` couldn't
  respawn to boot. Add VPhoneResources.runningExecutable() using
  Bundle.main.executableURL (the kernel-provided path, correct regardless of
  argv[0]/CWD/symlink) and route all three through it. One helper fixes every
  .resolve() consumer.

- MEDIUM (silent): the extra-deb feature resolved its cache + manifest under the
  read-only bundle (Resources/debs, Resources/debs.list). Honor VPHONE_DEBS_DIR
  (a writable ~/.vphone/debs the app now sets, mirroring IPSW_DIR/VPHONE_SEAL_DIR)
  and bundle debs.list.

- LOW (cosmetic): fw_prepare read ../README.md (absent in the bundle → firmwares
  labeled "Not Tested"). Bundle README.md.

Verified: Bundle.main.executableURL yields the real binary under a bare-name
symlink launch (argv[0] → $HOME); build clean; 79 VPhoneCore tests pass.
2026-07-28 15:21:29 +03:00
zqxwceandClaude Opus 4.8 70ff75067a fix: preflight checks the running binary, not a dev .build path
boot_host_preflight.sh hardcoded RELEASE_BIN=$PROJECT_ROOT/.build/release/
vphone-cli. Inside the bundled .app, PROJECT_ROOT resolves to Contents/
Resources, so it looked for Contents/Resources/.build/release/vphone-cli —
which doesn't exist (the binary is at Contents/MacOS/vphone-cli). Under
--assert-bootable that made the preflight fail with "missing release binary",
blocking `vm launch` from a brew-installed or copied .app.

`vm launch` now passes the running executable (CommandLine.arguments[0]) to the
preflight via VPHONE_CLI_BIN and the script checks that binary; it still falls
back to the dev .build/release path for standalone/`make` invocation.

Co-Authored-By: Claude Opus 4.8 <[email protected]>
2026-07-28 14:48:19 +03:00
zqxwceandClaude Opus 4.8 37ee2943c6 feat: guest restore/CFW pipeline updates for the consolidated CLI
- pymobiledevice3_bridge.py: colorized restore logs (coloredlogs.install,
  mirroring pmd3's own CLI) gated by a -v count
- cfw_install*.sh / fw_prepare.sh honor VPHONE_PYTHON/IPSW_DIR/VPHONE_SEAL_DIR
  and forward SPOOF_BUILD / FORCE_DSC_MAXSLIDE from the environment
- patch_camera_userland.sh / patch_hv_vmm_userland.sh adjustments

Co-Authored-By: Claude Opus 4.8 <[email protected]>
Claude-Session: https://claude.ai/code/session_01Y4VDqWf5pVakcFLqB23CKe
2026-07-27 19:46:27 +03:00
zqxwceandClaude Opus 4.8 c5300d0377 feat: standalone .app bundling + versioned resource resolution
- scripts/build.sh builds+signs the binary, bundles a self-contained .app
  (mirrors scripts/patchers/resources/tools/vphoned + requirements.txt into
  Contents/Resources) and re-signs; the signed guest daemon stages under
  .build (not the repo root)
- CryptexFilesystemPatcher resolves assets via VPhoneResources instead of
  CWD-relative paths
- Makefile space-safety; .gitignore updates

Co-Authored-By: Claude Opus 4.8 <[email protected]>
Claude-Session: https://claude.ai/code/session_01Y4VDqWf5pVakcFLqB23CKe
2026-07-27 19:46:27 +03:00
zqxwceandClaude Fable 5 c9ad3c7519 cfw: dsc: Add FORCE_DSC_MAXSLIDE opt-in to zero maxSlide on non-27 bases
patch-dsc-maxslide self-gates to a no-op when the shared cache fits the
vphone600 26.x kernel's 6 GiB region, which 26.x/18.x bases always do, so
it only fires on 27. Add a --force flag that bypasses the fits-check and
zeroes maxSlide unconditionally (still idempotent), and a
FORCE_DSC_MAXSLIDE=1 env opt-in in cfw_install.sh that runs it on non-27
bases. Default off; 27 behavior unchanged.

Also fix the installer env-threading in cfw_install_host.sh: a
${VAR:+NAME=val} word produced by expansion is not parsed as a shell
assignment (zsh runs it as a command), so route the assignments through
env. This makes FORCE_DSC_MAXSLIDE reach the installer and repairs the
same latent bug for SPOOF_BUILD.

Verified on a 26.4 JB VM: FORCE_DSC_MAXSLIDE=1 yields on-disk maxSlide=0
and a live shared-cache slide of 0x0 (dyld maps the cache at its
preferred base 0x180000000 in rpcserver_ios), versus the nonzero slide a
stock 26.4 boot picks.

Docs + research/0_binary_patch_comparison.md updated (README and the ja/ko/zh
translations).

Co-Authored-By: Claude Fable 5 <[email protected]>
2026-07-23 17:46:40 +03:00
zqxwceandClaude Fable 5 0827e0ad53 cfw: jb: Fix iOS 27 daemon crash-loop (libxpc LWCR self-check abort)
iOS 27 XPC servers pin a Lightweight Code Requirement on their listener
(xpc_connection_set_peer_lightweight_code_requirement / the Swift
XPCPeerRequirement.hasEntitlement wrapper). Creating one self-checks via
libxpc _xpc_token_satisfies_lwcr, whose matcher returns a "matched" bool
plus a match_result.error_code and then hard-asserts they agree
(matched == (error_code == AICMR_MATCH), where AICMR_MATCH == 0) via
_os_crash_msg -> brk #1.

Under our JB code-signing environment the matcher writes error_code =
MATCH(0) but returns a failure status, producing the forbidden
(matched=0, error_code=0) pair, so libxpc aborts. Every daemon that pins
an entitlement peer-requirement at startup crash-loops continuously from
boot: intelligencetasksd, searchpartyd, transparencyd, bluetoothd, ...

Fix (cfw_patch_xpc_lwcr.py, 27.*-gated in cfw_install.sh, self-gating on
the symbol): derive "matched" from error_code and drop the abort. The
three instructions "cset w8,ne; eor w8,w0,w8; tbz w8,#0,<abort>" become
"cset w0,eq; nop; nop". The function then returns (error_code == 0),
reproducing stock behavior when the two agree and resolving the
contradiction toward "satisfied" when error_code says MATCH; genuine
allow/deny (error_code != 0) is unchanged. Symbol resolved from the DSC
.symbols table, site located by control-flow shape (Capstone),
replacements from Keystone, modified 16 KiB page re-attested
(cfw_dsc_codesign; CDHash change accepted by the JB AMFI cdhash-trust
patch).

Validated on 17,3_27.0_24A5390f + cloudOS 26.4 (JB, host-mount deploy):
the four crash-loopers disappear from the crash census after boot;
launchd (which links libxpc) boots clean past first unlock.

Co-Authored-By: Claude Fable 5 <[email protected]>
2026-07-23 16:50:41 +03:00
zqxwceandClaude Opus 4.8 decda02ab4 cfw: jb/exp: Fix iOS 27 Campo crash-loop (sandbox mach-lookup exceptions)
iOS 27's Campo (wallpaper renderer) runs under the temporary-sandbox profile
(its own com.apple.private.sandbox.profile:embedded + no-container). On the 26.4
vphone600 kernel that builtin profile predates 27 and denies the backboard/
frontboard launch mach-services, so BKSDisplayServicesStart and then
+[BKSHIDEventDeliveryManager sharedInstance] fail their mach-lookups, log
"backboardd isn't running -- or we couldn't talk to it", and brk ~34ms after
launch -> continuous crash-loop, no wallpaper. JB-02d's container-upcall
force-success stops the exec-time autobox kill but does not grant these services.

Grant them through Campo's own com.apple.security.exception.mach-lookup.global-name
array (the sanctioned escape hatch, honored by temporary-sandbox -- Campo already
ships ~20 such exceptions; these launch services just aren't among them because
27's profile allows them directly). Applied at host-mount build time as step
JB-3b in cfw_install_jb.sh / cfw_install_exp.sh, re-signed with signcert.p12 via
ldid_sign_ent. The service list is merged by the external helper
scripts/patchers/campo_mach_lookup_exceptions.py (plistlib, not plutil -- the
entitlement key's dots would break plutil keypaths).

Hard-gated to 27.* on the mounted rootfs SystemVersion.plist (same gate as the
vpregister/DSC patches): skipped on 26.x/18.x, which don't need it and where
Campo.app also exists.

Verified on-device (17,3_27.0_24A5390f + cloudOS 26.4, JB): Campo launches and
stays up, no BKSDisplayServicesStart/BKSHIDEventDeliveryManager trap. Documented
as entry #14 in research/0_binary_patch_comparison.md.

Co-Authored-By: Claude Opus 4.8 <[email protected]>
Claude-Session: https://claude.ai/code/session_014McnrLRb5cZsTrpcBkvkj3
2026-07-23 16:50:41 +03:00
zqxwceandClaude Opus 4.8 9becab4031 cfw: Fix iOS 27 DDI (/System/Developer) auto-mount
Productionize the 3-part fix that makes `pymobiledevice3 mounter auto-mount`
land the personalized DDI at /System/Developer on the iOS-27-userland /
26.4-vphone600-kernel (c0ecdb4b) JB hybrid.

- KernelJBPatchDiskImages2.swift (new; wired into KernelJBPatcher.findAll):
  DiskImages2 ABI acceptance. GATE1/GATE2b NOP the CreateDevice/Connect
  cmp#9/b.ne ABI-version rejects (kernel driver v9 vs iOS-27 controller/daemon
  v11). GATE2 widens the RegisterNotificationPort backing array + both
  bound-check field loads (all-or-nothing) to clear the `type < getMaxPorts`
  off-by-one that otherwise fails the attach ("Can't register notification
  port").
- KernelJBPatchSandboxExtended: retarget mac_policy_ops[124]
  (mpo_proc_check_syscall_unix) to the allow stub so MobileStorageMounter's
  mount_apfs can make the mount(2) syscall (unix 167) — else the kernel
  Sandbox denies it ("Protobox: mount_apfs deny(1) syscall-unix 167").
- cfw_patch_diskimagesiod.py + cfw.py + cfw_install.sh (gated to 27.*):
  force -[DIDiskArb isMountCompleteWithExpectedCount:diskTracker:] -> YES so
  MobileStorageMounter's waitForDAMount returns and it performs the real
  nobrowse mount.

GATE2a anchor fix (the critical one): Capstone on this toolchain decodes the
AllocPortsArray size-shift lsl-immediate (a UBFM alias) as 2 operands, not the
xd,xn,#imm 3-operand shape. The original 3-operand + imm==3 match found 0, so
the all-or-nothing silently skipped GATE2 on every build (only manual dd pokes
ever worked). Now matched on mnemonic + destination x1 — the unique
size-writing lsl in AllocPortsArray; the replacement is a fixed mov x1,#0x4000
so the shift amount is irrelevant. Verified from a clean build on c0ecdb4b via
`patch-component --component kernel-jb --records-out`: all five di2 records
emit (createdevice, connect, allocports_size, notif_boundcheck_d8/e8), and
`pmd3 mounter auto-mount` -> rc=0 with the DDI mounted, no poke.

Documented in research/0_binary_patch_comparison.md (JB-09, JB-28, CFW
binary-patch #13).

Co-Authored-By: Claude Opus 4.8 <[email protected]>
Claude-Session: https://claude.ai/code/session_013pk5tsoBeuu3jhkmnRFtic
2026-07-20 16:20:34 +03:00
zqxwceandClaude Opus 4.8 de725d26aa cfw: Fix iOS 27 Sileo-at-setup — register JB apps via containerized LS API (vpregister)
On iOS 27, -[LSApplicationWorkspace registerApplicationDictionary:] (what the
first-boot `uicache -a` uses) is a deprecated no-op stub — lsd logs "You cannot
use -[LSApplicationWorkspace registerApplicationDictionary:] to register
applications anymore. These interfaces have been deprecated for years." and it
returns NO. So vphone_jb_setup.sh installs Sileo's .deb but never registers it:
the files land in /var/jb/Applications but Sileo never appears on the home
screen. There is no gate to patch here — Apple removed the implementation.

Fix: register JB apps via the modern containerized API instead.
- scripts/vpregister/vpregister.m: standalone helper that registers
  /var/jb/Applications/*.app (or given paths) via
  registerContainerizedApplicationWithInfoDictionaries:...:registrationError:,
  treating a nil error as success (it returns NO even when it registers). Works
  once lsd's embedded-reg gate is patched (cfw_patch_lsd_embedded_reg, applied
  by cfw_install.sh, which cfw_install_jb.sh and cfw_install_exp.sh both chain).
  It lives in its OWN dir (scripts/vpregister/), NOT scripts/vphoned/, so it is
  not swept up by the `scripts/vphoned/*.m` globs that build vphoned
  (cfw_install.sh, cfw_install_dev.sh, and the vphoned Makefile all glob that
  dir) — otherwise its main() collides with vphoned's ("duplicate symbol
  '_main'"). Built separately by the JB/EXP installers.
- cfw_install_jb.sh / cfw_install_exp.sh: build + sign (vphoned entitlements +
  CFW signcert) + deploy vpregister to /cores.
- vphone_jb_setup.sh: after dpkg + uicache -a, invoke /cores/vpregister to
  register JB apps via the containerized path. Guarded by [ -x ].

vpregister verified on 17,3_27.0_24A5380h + cloudOS 26.4 (JB): registers Sileo
via the containerized API (uicache -l 0->1) on the gate-patched VM. The exact
cfw_install.sh vphoned build (VPHONED_SRCS glob + clang) now links cleanly with
vpregister.m relocated. Doc: item 12 in research/0_binary_patch_comparison.md.

Co-Authored-By: Claude Opus 4.8 <[email protected]>
Claude-Session: https://claude.ai/code/session_013pk5tsoBeuu3jhkmnRFtic
2026-07-20 16:20:34 +03:00
zqxwceandClaude Opus 4.8 82485d988d cfw: Fix iOS 27 app registration — patch lsd embedded-reg gate + vphoned containerized fallback
iOS 27 lsd gates app (re)registration behind
-[_LSDModifyClient clientIsEntitledForEmbeddedRegistrationOperations], an
XPC-peer entitlement check for one of three privileged entitlements
(coreservices.lsaw / installcoordinationd.daemon /
coreservices.can-register-install-results). Missing -> NSOSStatusErrorDomain
-54 (permErr, LSDModifyService.mm:1639), so registerApplicationDictionary: and
registerContainerizedApplicationWithInfoDictionaries: fail and no app can
register — blocking vphoned's installer, TrollStore, and uicache/Sileo. The
entitlement route is unsatisfiable: LS registration is proxied, so the peer lsd
inspects is not the caller (even vphoned with all three in its validated csblob
is rejected).

Fix (two parts):
- cfw_patch_lsd_embedded_reg.py: NOP the gate's final cbz so the check always
  returns YES + re-attest the 16 KiB page (TXM per-page). Wired into cfw.py
  (patch-lsd-embedded-reg) and cfw_install.sh (after patch-dsc-maxslide);
  self-gates on pre-27 userlands (method absent). Method resolved via the DSC's
  own .symbols in-image table (ipsw symaddr/a2s time out on this cache), gate
  located by control-flow shape (cbz/cbnz w0 whose fall-through sets the
  mov w<reg>,#1 result), NOP bytes from Keystone. New CDHash accepted by the JB
  always-true AMFI cdhash-trust patch.
- vphoned vp_register_path: fall back from the (still-gated) plain
  registerApplicationDictionary: to the containerized registration API, which
  works once the gate is patched (treat a nil registrationError as success
  since it returns NO even when it registers).

Verified on 17,3_27.0_24A5380h + cloudOS 26.4 (JB): -54 gone, Sileo registers
(uicache -l 0->1), vphoned installs+registers a test IPA (com.vphone.vptest) to
/var/containers/Bundle/Application end-to-end; clean boot (re-attest correct).
Documented as item 12 in research/0_binary_patch_comparison.md.

Co-Authored-By: Claude Opus 4.8 <[email protected]>
Claude-Session: https://claude.ai/code/session_013pk5tsoBeuu3jhkmnRFtic
2026-07-20 16:20:34 +03:00
zqxwceandClaude Opus 4.8 43b8e75725 cfw: Make force-kern (patch-iomfb-force-kern) idempotent
Recognize entrypoints already rewritten to `b _kern_Swap*` by a prior run (first
insn is `b` targeting the kern address) and count them as `already` covered
instead of aborting. Previously a reinstall / re-patch of an already-forced DSC
raised "did not retarget required entrypoints" because the trampoline shape was
gone. Now: covered = forced | already; require the REQUIRED set to be a subset
of covered; re-attest only when something was newly written (skip cleanly when
all entrypoints are already forced). Enables the host-mount reinstall loop on an
already-patched VM. No behaviour change on a fresh DSC.

Co-Authored-By: Claude Opus 4.8 <[email protected]>
Claude-Session: https://claude.ai/code/session_013pk5tsoBeuu3jhkmnRFtic
2026-07-20 16:20:34 +03:00
zqxwceandClaude Opus 4.8 9c1227f89b kernel: jb: Fix iOS 27 native VZ-view display (force the kern present path)
iOS 27 userland on the 26.4 vphone600 kernel booted with a working GUI over the
in-guest TrollVNC capturer, but the normal vphone-cli window (the host VZ view)
stayed black. Root cause, proven at the instruction level in the 27.0 DSC
IOMobileFramebuffer: the host VZVirtualMachineView is fed by the guest
AppleParavirtGPU scanout, which the 26.4 kernel drives ONLY from the IOMFB
userclient SwapEnd (external method 5) -- the `_kern_Swap*` path that 26.x used
(and that the SwapEnd size patch fixed on 26.0/18.x). iOS 27 defaults the
paravirt display's present to IOMFB's parallel `_virt_Swap*` path: `_virt_SwapEnd`
performs no userclient call -- it invokes an in-process callback and hands the
composited IOSurface to a virtual-display consumer -- so frames never enter the
kernel userclient and the paravirt GPU never scans out (live AppleParavirtGPU
scheduler sat idle). TrollVNC still saw frames because it captures the composited
surface in-guest, independent of the paravirt scanout.

Fix = force the display's present back onto the kern/method-5 path, in two halves:

Userland (DSC), new patcher cfw_patch_iomfb_force_kern.py (cfw.py +
cfw_install.sh, 27-gated): the public `_IOMobileFramebufferSwap*` entrypoints are
thin dispatch trampolines (`cbz x0; ldr xN,[x0,#slot]; cbz xN; braaz xN`) that
tail-call a per-connection swap fp (kern or virt impl). Rewrite each trampoline's
first instruction to `b _kern_Swap<Name>` -- args untouched, so this is
behaviourally identical to the connection having selected the kern fp. Fully
dynamic: public + `_kern_` addrs resolved by name via `ipsw dyld symaddr`,
trampoline shape verified by Capstone, branch bytes from the Keystone `asm_at()`
helper, modified DSC code pages re-attested. Runtime: 31 entrypoints retargeted,
4 non-trampoline setters left on virt, required {SwapBegin,SwapEnd,SwapSetLayer}
present.

Kernel (KernelJBPatchIomfbSwap, re-enabled in KernelJBPatcher.findAll): iOS 27's
native SwapEnd struct is 0x6e0 bytes (26.x sent 0x588) and the 26.4 userclient
exact-checks 0x588 in two places, so method 5 would return kIOReturnBadArgument.
patchIomfbSwapEndVariableSize flips the dispatch-table checkStructureInputSize
0x588 -> kIOUCVariableStructureSize; patchIomfbSwapEndHandlerSize retargets the
handler's internal `cmp w2,#0x588` -> #0x6e0. 27's IOMFBSwapRec prefix matches
26.x, so the paravirt swap handler reads valid fields. patchParavirtDisplayPrimary
stays disabled (wrong theory, harmful -- see JB-02c).

Validated on-device (17,3_27.0_24A5380h + cloudOS 26.4 c0ecdb4b, JB): clean boot,
no kIOReturnBadArgument / SwapEnd rejection / SECURITY_POLICY kill / panic, and
the iOS 27 userland now renders AND is interactive in the native VZ view.

research/0_binary_patch_comparison.md: DSC-patch item 9 corrected (27 no longer
size-truncated), new item 11 (force-kern), JB-26/27 rows added, all marked
validated.

Co-Authored-By: Claude Opus 4.8 <[email protected]>
Claude-Session: https://claude.ai/code/session_013pk5tsoBeuu3jhkmnRFtic
2026-07-20 16:20:34 +03:00
zqxwceandClaude Opus 4.8 c22da90929 kernel: jb: Fix iOS 27 guest display via IOUC sandbox gate bypass
iOS 27 userland on the 26.4 vphone600 kernel had SpringBoard crash-looping
with no display. Root cause: the IOKit user-client open path runs TWO
independent MAC gates -- a MACF-aggregator check (already patched by
patchIoucFailedMacf) and a separate Sandbox check -- and the Sandbox gate
spuriously DENIES the render server (backboardd) its opens of
IOMobileFramebufferUserClient / IOSurfaceRootUserClient / IOHIDEventService.
27-specific: absent on a native 26.4 userland. Denied the framebuffer,
backboardd can't present (no Apple logo) and vends no main display, so
FBSDisplayMonitor asserts on a nil mainDisplay -> crash-loop.

Add patchIoucFailedSandbox (KernelJBPatchIoucSandbox.swift), mirroring
patchIoucFailedMacf: anchor on the "IOUC %s failed sandbox in process %s"
string, find the deny block (the CBNZ target enclosing the fail-log ADRP),
and rewrite its first instruction with an unconditional B to the
NotPermitted allow-proceed target. Structural anchors only, no hardcoded
offsets. No-op where the gate already allows (native 26.x userlands).

Verified: backboardd opens the framebuffer, SpringBoard runs (0 crashes),
display enumerates (LCD/primary), [CADisplay mainDisplay] resolves, and the
guest GUI renders (confirmed visible over VNC).

Disable three earlier wrong-theory display patches (kept in-tree, off in
findAll, for the record):
 - patchParavirtDisplayPrimary: setting primary=1 is actively HARMFUL on 27
   -- it becomes the display NAME suffix ("primary-1") and breaks the render
   server's exact-name match.
 - patchIomfbSwapEnd{VariableSize,HandlerSize}: iOS 27 never uses IOMFB
   method 5 (SwapEnd) for present -- confirmed by kernel trace of the real
   handler (cmp w2,#0x588) with SpringBoard actively presenting -- so these
   are irrelevant on 27 and would break 26.x's native 0x588 SwapEnd.

SwapEnd userland DSC size patch made per-base (cfw_install*, cfw.py,
cfw_patch_iomfb_swapend.py): 26.x validated, harmless on 27.

research/0_binary_patch_comparison.md updated (JB-10b added for the sandbox
gate; JB-02c corrected to disabled/wrong-theory).

Still open: the normal (VZ) render path stays black even though the guest
presents (VNC works) -- 27 uses a present mechanism the 26.4 paravirt-GPU
path doesn't receive. Tracked separately for follow-up.

Co-Authored-By: Claude Opus 4.8 <[email protected]>
2026-07-20 16:20:34 +03:00
zqxwceandClaude Opus 4.8 a38fd3201f cfw: Fit iOS 27 dyld cache in the 26.x kernel shared region (maxSlide=0)
iOS 27.0's dyld shared cache (~5.95 GiB span) plus its 512 MiB header maxSlide
overflows the vphone600 26.x kernel's fixed 6 GiB shared region
(SHARED_REGION_SIZE_ARM64 = 0x180000000). At map time the kernel reserves
span + maxSlide, so _shared_region_map_and_slide returns ENOMEM, dyld cannot map
libSystem, and launchd (pid 1) panics at boot ("initproc failed to start").

Add cfw_patch_dsc_maxslide: zero the dyld_cache_header maxSlide (@0xF0) in the
main chunk when span + maxSlide exceeds the region, so the cache maps at slide 0
(iOS 27.0 fits with ~58 MiB spare). Self-gating (no-op for 26.x/18.x, which fit
with full slide) and no page re-attestation (header metadata, not a cs_validate'd
code page). Wired into cfw_install.sh after the IOMFB SwapEnd gate, so it applies
to regular/jb/exp (jb/exp run cfw_install.sh as their base).

Validated on iPhone17,3_27.0_24A5380h userland + cloudOS 26.4 (c0ecdb4b) JB:
dyld cache maps system-wide, launchd reaches first unlock, vphoned connects as
iOS 27.0.0, 0 panics.

Co-Authored-By: Claude Opus 4.8 <[email protected]>
Claude-Session: https://claude.ai/code/session_013pk5tsoBeuu3jhkmnRFtic
2026-07-20 16:20:34 +03:00
Maximilian Paß 478b44a5b6 Remove boot_less dependency 2026-07-15 08:12:00 +03:00
zqxwceandClaude Opus 4.8 b90f699583 vphone-cli: guest-side touch injection for iOS 18 bases
iOS 18.x userland on the 26.1 vphone600 kernel has no working touch: the
VZ USB touchscreen dext receives input reports (InputReportCount climbs)
but emits zero digitizer events on the 26.1 kernel, so backboardd's event
queue stays empty and the UI never sees touches. The identical device on
a 26.x base produces digitizer events normally, so it is a guest-side
dext<->kernel report->event ABI break, not a host or descriptor issue.

Fix: inject digitizer events guest-side via vphoned, bypassing the broken
dext -- the same IOHIDEventSystemClientDispatchEvent path vphoned already
uses for the Home key. vp_hid_touch() builds a Hand parent + digitizer
finger child event (display-integrated) and dispatches it.

- vphoned_hid.{h,m}: vp_hid_touch(phase,x,y) + digitizer dlsyms.
- vphoned.m: "touch" command; hello now reports the guest iOS version and
  a "touch" capability.
- VPhoneControl: sendTouch(), guestIOSVersion, and useGuestTouchInjection
  (connected && caps has "touch" && iOS major < 26).
- VPhoneVirtualMachineView.sendTouchEvent: routes to vphoned when
  useGuestTouchInjection, else the native VZ USB multitouch path.

Gated to iOS 18 bases: 26.x guests report major >= 26, so the gate is
false and touch uses the unchanged native USB path (no regression). The
new vphoned code is compiled into all builds but stays inert on 26.x.
Ships via the existing vphoned hash-mismatch auto-update; no re-restore.

Verified on 17,3_18.6.2_22G100: socket tap -> correct digitizer event
(coordinates match), swipe unlocks to home, tap on the Settings icon
launches Settings.

Co-Authored-By: Claude Opus 4.8 <[email protected]>
Claude-Session: https://claude.ai/code/session_01Q7gbWrtKLu8rFGmpXHmu9t
2026-07-13 15:40:44 +03:00
zqxwceandClaude Fable 5 a67e0f3939 cfw: extend IOMobileFramebuffer SwapEnd display fix to iOS 18.x
iOS 18.6.2 userland on the 26.1 vphone600 kernel hits the same
IOMobileFramebuffer SwapEnd ABI mismatch as 26.0/26.0.1: userland sends
a smaller external-method-5 SwapEnd state than the 0x560 the userclient
expects, so SwapEnd returns kIOReturnBadArgument and the host VZ display
stays black (the guest still renders — the Apple logo is visible over
VNC, just not in the vphone-cli view). 18.6.2 sends 0x514 (26.0 sent
0x548).

cfw_patch_iomfb_swapend is already semantic + idempotent (it discovers
the source immediate and rewrites it to 0x560), so no patcher change is
needed — only the install-time gate. Extend the gate in cfw_install.sh
and cfw_install_dev.sh to fire when ProductVersion starts with 18. as
well as 26.0.

Scoped to those versions only: 26.1/26.3/26.4/26.5 match neither branch
of the gate and are unaffected. Document the widened scope in
research/0_binary_patch_comparison.md (patch row 9).

Part of ongoing iPhone17,3 18.6.2 + cloudOS 26.1 bring-up. Validated on
17,3_18.6.2_22G100: the Apple logo now renders in the vphone-cli view.
Full boot to the UI additionally needs two kernelcache fixes (keystore
sel-135 force-success and the mach-port EXC_GUARD disable) that are
validated at runtime but not yet folded into KernelPatcher — those will
be gated to iOS 18 bases so the working 26.x variants stay untouched.

Co-Authored-By: Claude Fable 5 <[email protected]>
2026-07-13 15:40:44 +03:00
zqxwce aa39b7194d cfw: patchers: Make iomfb patch dynamic instead of hard coded bytes 2026-07-08 11:28:36 +03:00
Xin Huang d97f4f6045 cfw_install_host: fix SIGPIPE (Error 141) from global apfs list
Under `set -euo pipefail`, `diskutil apfs list | awk '...exit'` returns 141: awk exits on the first match and diskutil is killed by SIGPIPE while still writing its multi-container output (~21KB across 15 containers here). Scope the volume search to the image's own APFS container, derived from the attached base disk's s1 partition via APFSContainerReference, so the piped output is small enough that diskutil finishes before awk exits. This also stops the installer from selecting a System volume that belongs to an unrelated attached container.
2026-07-08 11:28:36 +03:00
Xin Huang 16663a2f5f Fix iOS 26.0 and 26.0.1 GUI boot
Patch the 26.0/26.0.1 IOMobileFramebuffer SwapEnd payload size during CFW install and document the validated 26.0, 26.0.1, and 26.1 host-install matrix.
2026-07-08 11:28:36 +03:00
zqxwceandClaude Opus 4.8 33072cf954 cfw/jb: Add dynamic deb download + install to machine setup
Fetch debs listed in debs.list into a cached debs/ dir (skipping already
-cached files, honoring manually-added ones), stage the whole cache into
the per-boot preboot dir alongside Sileo, and install on first boot.

- fetch_debs.sh: manifest fetch, atomic download, non-fatal on failure,
  chowns cache back to invoking user under sudo
- cfw_install_jb.sh / cfw_install_exp.sh: fetch + stage into $BOOT_HASH/debs
- vphone_jb_setup.sh (5b): idempotent install — skip packages already at
  >= the staged version, install the rest in one dpkg -i so inter-package
  deps resolve in a single pass
- debs.list tracked manifest; debs/ cache gitignored

Co-Authored-By: Claude Opus 4.8 <[email protected]>
2026-07-06 21:41:55 +03:00
zqxwceandClaude Opus 4.8 fcc30e1657 general: Remove SSH-ramdisk CFW install path; host-mount is the sole flow
The ramdisk-based install (build/send an SSH ramdisk, iproxy-forward, then
push CFW files over SSH and flip the boot snapshot with snaputil in-VM) has
been fully replaced by the host-mount path: cfw_install_host.sh mounts the
VM's Disk.img on the host, places every file locally, and flips the boot
snapshot offline via tools/apfs_snap_rename.py. This removes all remaining
ramdisk generation, delivery, and usage — no legacy fallback.

Deleted:
  - scripts/ramdisk_build.py, scripts/ramdisk_send.sh
Renamed:
  - scripts/cfw_host_mode.sh -> scripts/cfw_transport.sh (was a conditional
    "host-mode override"; now the sole, unconditionally-sourced transport)

setup_machine.sh: drop the USE_RAMDISK_CFW=1 branch and every iproxy/ramdisk
helper (usbmux UDID resolution, port picking, start/stop iproxy, wait-for-
ramdisk-ssh), all RAMDISK_*/IPROXY_* vars, the cleanup() iproxy handling, and
the orphaned cfw_install_target var. Only the host-mount cfw_install_host call
remains.

cfw_install{,_dev,_jb,_exp}.sh: delete the SSH transport (SSH_* vars, SSH_OPTS,
sshpass prereq/_sshpass/_ssh_retry, ssh_cmd/scp_to/scp_from/remote_file_exists/
remote_mount, wait_for_device_ssh_ready) and the dead ramdisk-mechanism body
blocks (snaputil snapshot flip, dropbearkey host-key pre-generation, halt-over-
SSH, CFW_SKIP_HALT). The transport is now sourced unconditionally from
cfw_transport.sh. dropbear -R generates host keys at first boot; the offline
apfs_snap_rename.py does the boot-source flip. Dropped the vestigial
CFW_HOST_MODE gate.

Also: pymobiledevice3_bridge.py (ramdisk-send command already gone), Makefile
(ramdisk targets/help/IRECOVERY_ECID removed), README + ja/ko/zh (install flow
rewritten to host-mount), AGENTS.md/CLAUDE.md architecture tree, and stale
comments in vphone_jb_setup.sh, VPhoneCLI.swift, apfs_snap_rename.py,
cfw_patch_post_restore_dt.py.

Verified booting via make setup_machine.

Co-Authored-By: Claude Opus 4.8 <[email protected]>
Claude-Session: https://claude.ai/code/session_01XZVS9oqVNmHJzpb8mFtKJx
2026-07-06 15:15:01 +03:00
zqxwceandClaude Opus 4.8 321c7117b3 setup_machine: Set ramdisk-free host-mount CFW install as default
Replace the "Ramdisk + CFW phase" (boot_dfu + ramdisk_build/send + iproxy
+ wait_ssh + cfw_install*) with cfw_install_host run after the restore
phase, while the VM is off. The legacy ramdisk path is kept behind
USE_RAMDISK_CFW=1.

Co-Authored-By: Claude Opus 4.8 <[email protected]>
Claude-Session: https://claude.ai/code/session_01XZVS9oqVNmHJzpb8mFtKJx
2026-07-06 15:15:01 +03:00
zqxwceandClaude Opus 4.8 d28754e89e cfw: Implement ramdisk-free host-mount CFW install
Add a host-mount install path that replaces the DFU + ramdisk_send +
iproxy + SSH transport: mount the VM's Disk.img volumes on the host, place
every CFW file locally, then flip the boot snapshot offline
(tools/apfs_snap_rename.py). The resulting VM is identical to the
ramdisk-installed one, minus the round-trips.

- cfw_host_mode.sh: sourced by cfw_install*.sh when CFW_HOST_MODE=1;
  overrides ssh_cmd/scp_to/scp_from/remote_mount/remote_file_exists to run
  locally against volumes mounted at $CFW_HOST_MNT/mnt{1,3,5} (host / is
  read-only, so device /mntN tokens are remapped), routes /usr/bin/tar to
  gtar (bsdtar lacks the GNU flags), and skips snaputil/dropbearkey/halt.
- cfw_install{,_dev,_jb,_exp}.sh: source the shim after their helper defs
  (host-mode is opt-in; the SSH path is unchanged). Also reword progress
  messages that assumed the ramdisk/SSH flow ("~3 minutes" scp, "to
  device", "Reboot the device") to read correctly in both modes.
- cfw_install_host.sh + `make cfw_install_host VARIANT=regular|dev|jb|exp`:
  attach the image, run the chosen installer under CFW_HOST_MODE as root,
  detach, and run the offline snapshot flip. Restores ownership of the
  host-side artifacts it creates (vm/.vphoned.signed, .cfw_temp, ...) to
  the invoking user afterward, so a later user-run `make boot` isn't
  blocked by root-owned files.

Runs as root (owners-honored mounts / chown / cp) via a sudo re-exec. No
authenticated-root/ARV change needed; mount_apfs -o rw honors owners.

Co-Authored-By: Claude Opus 4.8 <[email protected]>
Claude-Session: https://claude.ai/code/session_01XZVS9oqVNmHJzpb8mFtKJx
2026-07-06 15:15:01 +03:00
zqxwceandClaude Fable 5 8d63bbc840 cfw/ramdisk: route hdiutil straight to sudo -A when SUDO_ASKPASS is set
When SUDO_PASSWORD is supplied, setup_machine.sh exports SUDO_ASKPASS.
Previously hdiutil ran unprivileged first (cfw_install.sh, ramdisk_build.py)
or via plain interactive sudo (cfw_install_dev/exp.sh), both of which
triggered a password prompt.

Now, when SUDO_ASKPASS is present, hdiutil goes straight to `sudo -A` so it
never runs unprivileged first and never prompts. When it is absent, every
call site keeps its original behavior verbatim.

Co-Authored-By: Claude Fable 5 <[email protected]>
2026-07-05 18:26:58 +03:00
zqxwceandClaude Fable 5 729c3b644c cfw_install: jb/exp: Flip launchd hook to opt-out via DISABLE_LAUNCHD_HOOK
Inject launchdhook into pid 1 by default again for JB/EXP; set
DISABLE_LAUNCHD_HOOK=1 to skip. Also fixes a doubled-prefix typo in
cfw_install_exp.sh that made the previous env flag unreadable there.

Co-Authored-By: Claude Fable 5 <[email protected]>
2026-07-05 15:09:22 +03:00
xiahouzhen 7c3fdf17c5 Tighten launchdhook opt-in behavior 2026-07-05 15:09:22 +03:00
xiahouzhen 6167567f12 Make launchd hook injection opt-in 2026-07-05 15:09:22 +03:00
zqxwceandClaude Fable 5 421ff3ed23 Generate dropbear host keys with ramdisk's trustcached dropbearkey
The ramdisk-time host-key pre-seed added in c6ed3a1 invoked
/mnt1/iosbinpack64/usr/local/bin/dropbearkey, an iPhone-Distribution-signed
third-party binary. Inside the SSH ramdisk its cdhash is in no active trust
cache, so AMFI SIGKILLs it (exit 137), aborting cfw_install_jb/dev.

Use the ramdisk's own /usr/local/bin/dropbearkey (from ssh.tar.gz, re-signed
and trustcached at build time), which runs and writes fresh keys to the same
Data-volume target. The first-boot generator in vphone_jb_setup.sh is
unaffected — it runs in the JB'd kernel where the iosbinpack64 binary is valid.

Co-Authored-By: Claude Fable 5 <[email protected]>
2026-07-05 14:27:33 +03:00
vnescape 74d0df7254 Utilize APFS CoW to make backups instant 2026-07-05 13:43:43 +03:00
xiahouzhen 82cc1a4d83 Address setup hardening review issues 2026-07-05 13:41:56 +03:00
xiahouzhen c5a498e532 Harden jailbreak first-boot setup 2026-07-05 13:41:56 +03:00
xiahouzhen be9b0d4253 Make install image handling idempotent 2026-07-05 13:41:56 +03:00
xiahouzhen 29d0f803d8 Harden dropbear key setup checks 2026-07-05 13:36:24 +03:00
xiahouzhen c6ed3a1732 Fix dropbear host keys on writable Data 2026-07-05 13:36:24 +03:00
zqxwceandClaude Opus 4.8 3e05c89826 setup: Default to non-interactive, add INTERACTIVE opt-in
setup_machine now runs non-interactive by default (auto-continue first-boot
stages + boot analysis). Pass INTERACTIVE=1 to restore the live prompts.
The old NON_INTERACTIVE external knob is dropped; it remains only as the
internal computed flag the first-boot prompts read.

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
2026-06-22 12:15:06 +03:00