mirror of
https://github.com/Lakr233/vphone-cli.git
synced 2026-10-02 08:04:32 +08:00
docs: fix current research source paths
This commit is contained in:
@@ -371,7 +371,7 @@ The tests asserting a frozen digest moved off it first, onto the real 24A435
|
||||
`seputil`; the rest of `CFWMachOTests` — structural cases that only needed *some*
|
||||
signed Mach-O — kept pointing at the build product, and that stopped being viable
|
||||
when `vphone-letmein` was deleted from the tree (see
|
||||
`research/host/host_binary_split.md`). All of `CFWMachOTests` now takes its fixture
|
||||
`Research/Host/host_binary_split.md`). All of `CFWMachOTests` now takes its fixture
|
||||
the way the sibling CFW parity suites do: `macho_pristine/seputil`, resolved
|
||||
through `VPHONE_MACHO_PRISTINE` with `ipsws/ref_extract/macho_pristine` as the
|
||||
default, **failing** rather than skipping when it is absent, since a skipped test
|
||||
@@ -456,7 +456,7 @@ consumers, ~15 entries). Patched dylibs query the renamed OID and get the
|
||||
truthful 1 (graphics + accel passthrough); blacklisted dylibs keep the
|
||||
original cstring, hit ENOENT on the renamed kernel, and defensively cache 0
|
||||
("not running on a VM") for sign-in / device-attestation surfaces.
|
||||
Source-of-truth research: `research/patches/hv_vmm_present_usermode_xrefs.md`.
|
||||
Source-of-truth research: `Research/Patches/hv_vmm_present_usermode_xrefs.md`.
|
||||
|
||||
JB and other variants are NOT affected by this patcher.
|
||||
|
||||
|
||||
@@ -3,7 +3,7 @@
|
||||
> 2026-09-23, branch `vphone-intg-update`. libarchive 3.8.9 from
|
||||
> `Lakr233/libarchive.xcframework` 0.1.1, macOS 26 (26A428).
|
||||
>
|
||||
> Companion to `research/host/libarchive_xcframework_validation.md`, which covers
|
||||
> Companion to `Research/Host/libarchive_xcframework_validation.md`, which covers
|
||||
> whether libzstd and the liblzma MT encoder are compiled in. This one is
|
||||
> about behaviour on disk.
|
||||
|
||||
|
||||
@@ -233,7 +233,7 @@ nothing in the tree now.
|
||||
2. **That the instructions printed on a refusal are the ones that work**, on a
|
||||
host with `vm.cs_system_enforcement` = 1 and nothing installed yet. The
|
||||
`amfidont` install and daemon invocation were measured on this machine (see
|
||||
`research/0_binary_patch_comparison.md`); the CLI's rendering of them into
|
||||
`Research/0_binary_patch_comparison.md`); the CLI's rendering of them into
|
||||
an error message was not measured against a fresh host.
|
||||
3. **Location and TouchID**, which depend on TCC attributing the usage strings
|
||||
to `vphone-vm`. It is `CFBundleExecutable`, so it should — but TCC's view of
|
||||
|
||||
@@ -375,7 +375,7 @@ Should have moderate caller count (hundreds).
|
||||
|
||||
**Historical problem**: the earlier repo-side “fix” still matched the wrong place. Runtime verification later showed the old hit landed in `_profile_syscallmask_destroy` underflow handling, not the real syscallmask apply wrapper.
|
||||
**Current understanding**: faithful upstream C22 is a low-wrapper shellcode patch that mutates the effective Unix/Mach/KOBJ mask bytes to all `0xFF`, then continues into the normal setter. It is not a `NULL`-mask install and not an early-return patch.
|
||||
**Current status**: rebuilt structurally as a 3-write retarget (`save selector`, `branch to cave`, `all-ones cave + setter tail`) and separately documented in `research/kernel_jailbreak_patches/patch_syscallmask_apply_to_proc.md`; user reported boot success with the rebuilt C22 on `2026-03-06`.
|
||||
**Current status**: rebuilt structurally as a 3-write retarget (`save selector`, `branch to cave`, `all-ones cave + setter tail`) and separately documented in `Research/KernelJailbreakPatches/patch_syscallmask_apply_to_proc.md`; user reported boot success with the rebuilt C22 on `2026-03-06`.
|
||||
|
||||
### patch_iouc_failed_macf — RETARGETED
|
||||
|
||||
@@ -402,19 +402,19 @@ Should have moderate caller count (hundreds).
|
||||
|
||||
**Historical repo behavior**: matched `ldr x0,[xN,#0x2b8]; cbz x0; bl` pattern, which landed on `exec_handle_sugid` at `0xFFFFFE0007FB09DC` — a false positive caused by `/dev/null` string overlap in the heuristic scoring.
|
||||
**Problem**: the old matcher targeted the wrong function entirely; patching `exec_handle_sugid` instead of the real `bsd_init` rootauth gate could break boot by mutating an exec/credential path.
|
||||
**Current status**: retargeted to the real `FSIOC_KERNEL_ROOTAUTH` return check in `bsd_init`. The new matcher recovers `bsd_init` via in-kernel string xrefs, locates the rootvp panic block (`"rootvp not authenticated after mounting"`), finds the unique in-function indirect call (`BLRAA`) preceded by the `0x80046833` (`FSIOC_KERNEL_ROOTAUTH`) literal, and NOPs the subsequent `CBNZ W0, panic`. Live patch hit: `0xFFFFFE0007F7B98C` / file offset `0x00F7798C`. See `research/kernel_jailbreak_patches/patch_bsd_init_auth.md`.
|
||||
**Current status**: retargeted to the real `FSIOC_KERNEL_ROOTAUTH` return check in `bsd_init`. The new matcher recovers `bsd_init` via in-kernel string xrefs, locates the rootvp panic block (`"rootvp not authenticated after mounting"`), finds the unique in-function indirect call (`BLRAA`) preceded by the `0x80046833` (`FSIOC_KERNEL_ROOTAUTH`) literal, and NOPs the subsequent `CBNZ W0, panic`. Live patch hit: `0xFFFFFE0007F7B98C` / file offset `0x00F7798C`. See `Research/KernelJailbreakPatches/patch_bsd_init_auth.md`.
|
||||
|
||||
### patch_io_secure_bsd_root — RETARGETED (2026-03-06)
|
||||
|
||||
**Historical repo behavior**: fallback heuristic selected the first `BL* + CBZ W0` site in `AppleARMPE::callPlatformFunction`, landing on the `"SecureRoot"` name-match gate at `0xFFFFFE000836E1F0` / file offset `0x0136A1F0`. This changed generic platform-function dispatch routing, not just the deny return.
|
||||
**Problem**: the patched branch was the `isEqualTo("SecureRoot")` check, not the `"SecureRootName"` policy result used by `IOSecureBSDRoot()`. The old `CBZ->B` rewrite could corrupt control flow for unrelated platform-function calls.
|
||||
**Current status**: retargeted to the final `"SecureRootName"` deny-return selector: `CSEL W22, WZR, W9, NE` at `0xFFFFFE000836E464` / file offset `0x0136A464` is replaced with `MOV W22, #0`. This preserves the string comparison, callback synchronization, and state updates, and only forces the final policy return from `kIOReturnNotPrivileged` to success. See `research/kernel_jailbreak_patches/patch_io_secure_bsd_root.md`.
|
||||
**Current status**: retargeted to the final `"SecureRootName"` deny-return selector: `CSEL W22, WZR, W9, NE` at `0xFFFFFE000836E464` / file offset `0x0136A464` is replaced with `MOV W22, #0`. This preserves the string comparison, callback synchronization, and state updates, and only forces the final policy return from `kIOReturnNotPrivileged` to success. See `Research/KernelJailbreakPatches/patch_io_secure_bsd_root.md`.
|
||||
|
||||
### patch_vm_fault_enter_prepare — RETARGETED (2026-03-06)
|
||||
|
||||
**Historical repo behavior**: matcher looked for `BL(rare) + LDRB [xN,#0x2c] + TBZ` and NOPed the BL at `0xFFFFFE0007BB898C`, which was actually a `pmap_lock_phys_page()` call inside the `VM_PAGE_CONSUME_CLUSTERED` macro — breaking lock/unlock pairing in the VM fault path.
|
||||
**Problem**: the derived matcher overfit the wrong local shape. The upstream 26.1 patch targeted the `cs_bypass` fast-path gate (`TBZ W22, #3`), not the clustered-page lock helper. NOPing only the lock acquire while the unlock still ran caused unbalanced lock state, explaining boot failures.
|
||||
**Current status**: retargeted to the upstream semantic site — `TBZ W22, #3, ...` (where W22 bit 3 = `fault_info->cs_bypass`) at file offset `0x00BA9E1C` / VA `0xFFFFFE0007BADE1C` is replaced with `NOP`, forcing the `cs_bypass` fast path unconditionally. This matches XNU's `vm_fault_cs_check_violation()` logic and preserves lock pairing and page accounting. See `research/kernel_jailbreak_patches/patch_vm_fault_enter_prepare.md`.
|
||||
**Current status**: retargeted to the upstream semantic site — `TBZ W22, #3, ...` (where W22 bit 3 = `fault_info->cs_bypass`) at file offset `0x00BA9E1C` / VA `0xFFFFFE0007BADE1C` is replaced with `NOP`, forcing the `cs_bypass` fast path unconditionally. This matches XNU's `vm_fault_cs_check_violation()` logic and preserves lock pairing and page accounting. See `Research/KernelJailbreakPatches/patch_vm_fault_enter_prepare.md`.
|
||||
|
||||
---
|
||||
|
||||
|
||||
@@ -217,5 +217,5 @@ here:
|
||||
by subsystem into `CodeSigning/`, `Sandbox/`, `Memory/`, `Process/`, `Storage/`, `Drivers/`
|
||||
and `Frida/`, with shared helpers in
|
||||
`Sources/FirmwarePatcher/Kernel/KernelJailbreakPatcherBase.swift`.
|
||||
- Deeper, per-hook reverse-engineering notes are in `research/kernel_jailbreak_patches/` and the
|
||||
patch inventory is `research/0_binary_patch_comparison.md`.
|
||||
- Deeper, per-hook reverse-engineering notes are in `Research/KernelJailbreakPatches/` and the
|
||||
patch inventory is `Research/0_binary_patch_comparison.md`.
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
# JB Kernel Patch Document Framework
|
||||
|
||||
Use this structure for every `research/kernel_jailbreak_patches/patch_*.md` file.
|
||||
Use this structure for every `Research/KernelJailbreakPatches/patch_*.md` file.
|
||||
|
||||
## 1. Patch Metadata
|
||||
|
||||
|
||||
@@ -219,7 +219,7 @@ return 1;
|
||||
- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/runtime_verification_report.json`
|
||||
- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_runtime_patch_points.json`
|
||||
- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_patch_chain_report.json`
|
||||
- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_patch_chain_report.md`
|
||||
- Artifacts: `Research/KernelJailbreakPatches/RuntimeVerification/ida_patch_chain_report.md`
|
||||
<!-- END_RUNTIME_IDA_VERIFICATION_2026_03_05 -->
|
||||
|
||||
## 2026-03-06 Upstream Rework Review
|
||||
|
||||
@@ -219,5 +219,5 @@ if (kill_condition) {
|
||||
- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/runtime_verification_report.json`
|
||||
- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_runtime_patch_points.json`
|
||||
- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_patch_chain_report.json`
|
||||
- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_patch_chain_report.md`
|
||||
- Artifacts: `Research/KernelJailbreakPatches/RuntimeVerification/ida_patch_chain_report.md`
|
||||
<!-- END_RUNTIME_IDA_VERIFICATION_2026_03_05 -->
|
||||
|
||||
@@ -149,7 +149,7 @@ goto normal_path; // unconditional branch
|
||||
- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/runtime_verification_report.json`
|
||||
- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_runtime_patch_points.json`
|
||||
- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_patch_chain_report.json`
|
||||
- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_patch_chain_report.md`
|
||||
- Artifacts: `Research/KernelJailbreakPatches/RuntimeVerification/ida_patch_chain_report.md`
|
||||
<!-- END_RUNTIME_IDA_VERIFICATION_2026_03_05 -->
|
||||
|
||||
## 2026-03-06 Upstream Rework Review
|
||||
|
||||
@@ -165,7 +165,7 @@ Both variants emit exactly one patch:
|
||||
## Files
|
||||
|
||||
- Patcher: `scripts/patchers/kernel_jb_patch_dounmount.py`
|
||||
- Analysis doc: `research/kernel_jailbreak_patches/patch_dounmount.md`
|
||||
- Analysis doc: `Research/KernelJailbreakPatches/patch_dounmount.md`
|
||||
|
||||
## 2026-03-06 Rework
|
||||
|
||||
|
||||
@@ -132,7 +132,7 @@ Observed output:
|
||||
|
||||
- `scripts/patchers/kernel_jb_patch_hook_cred_label.py` now implements faithful upstream C23 semantics
|
||||
- `scripts/patchers/kernel_jb.py` includes `patch_hook_cred_label_update_execve` in the active Group C schedule
|
||||
- `research/0_binary_patch_comparison.md` should describe C23 as a faithful wrapper trampoline, not as a mis-targeted early-return patch
|
||||
- `Research/0_binary_patch_comparison.md` should describe C23 as a faithful wrapper trampoline, not as a mis-targeted early-return patch
|
||||
|
||||
## Practical Effect
|
||||
|
||||
|
||||
@@ -161,7 +161,7 @@ This gate executes early in image loading. Without bypassing it, binaries can fa
|
||||
- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/runtime_verification_report.json`
|
||||
- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_runtime_patch_points.json`
|
||||
- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_patch_chain_report.json`
|
||||
- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_patch_chain_report.md`
|
||||
- Artifacts: `Research/KernelJailbreakPatches/RuntimeVerification/ida_patch_chain_report.md`
|
||||
<!-- END_RUNTIME_IDA_VERIFICATION_2026_03_05 -->
|
||||
|
||||
## 2026-03-06 Upstream Rework Review
|
||||
|
||||
@@ -149,7 +149,7 @@ if ((perm_flags & BIT0) == 0) {
|
||||
- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/runtime_verification_report.json`
|
||||
- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_runtime_patch_points.json`
|
||||
- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_patch_chain_report.json`
|
||||
- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_patch_chain_report.md`
|
||||
- Artifacts: `Research/KernelJailbreakPatches/RuntimeVerification/ida_patch_chain_report.md`
|
||||
<!-- END_RUNTIME_IDA_VERIFICATION_2026_03_05 -->
|
||||
|
||||
## 2026-03-06 Upstream Rework Review
|
||||
|
||||
@@ -198,7 +198,7 @@ if (hash_type != hash_type) {
|
||||
- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/runtime_verification_report.json`
|
||||
- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_runtime_patch_points.json`
|
||||
- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_patch_chain_report.json`
|
||||
- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_patch_chain_report.md`
|
||||
- Artifacts: `Research/KernelJailbreakPatches/RuntimeVerification/ida_patch_chain_report.md`
|
||||
<!-- END_RUNTIME_IDA_VERIFICATION_2026_03_05 -->
|
||||
|
||||
## 2026-03-06 Upstream Rework Review
|
||||
|
||||
@@ -147,7 +147,7 @@ if (pid_or_flavor_guard == 0) return EINVAL;
|
||||
- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/runtime_verification_report.json`
|
||||
- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_runtime_patch_points.json`
|
||||
- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_patch_chain_report.json`
|
||||
- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_patch_chain_report.md`
|
||||
- Artifacts: `Research/KernelJailbreakPatches/RuntimeVerification/ida_patch_chain_report.md`
|
||||
<!-- END_RUNTIME_IDA_VERIFICATION_2026_03_05 -->
|
||||
|
||||
## 2026-03-06 Upstream Rework Review
|
||||
|
||||
@@ -211,7 +211,7 @@ int proc_security_policy(...) {
|
||||
- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/runtime_verification_report.json`
|
||||
- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_runtime_patch_points.json`
|
||||
- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_patch_chain_report.json`
|
||||
- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_patch_chain_report.md`
|
||||
- Artifacts: `Research/KernelJailbreakPatches/RuntimeVerification/ida_patch_chain_report.md`
|
||||
<!-- END_RUNTIME_IDA_VERIFICATION_2026_03_05 -->
|
||||
|
||||
## 2026-03-06 Upstream Rework Review
|
||||
|
||||
@@ -199,7 +199,7 @@ Interpretation:
|
||||
- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/runtime_verification_report.json`
|
||||
- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_runtime_patch_points.json`
|
||||
- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_patch_chain_report.json`
|
||||
- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_patch_chain_report.md`
|
||||
- Artifacts: `Research/KernelJailbreakPatches/RuntimeVerification/ida_patch_chain_report.md`
|
||||
<!-- END_RUNTIME_IDA_VERIFICATION_2026_03_05 -->
|
||||
|
||||
## 2026-03-06 Upstream Rework Review
|
||||
|
||||
@@ -134,7 +134,7 @@ Both variants emit exactly one patch:
|
||||
## Files
|
||||
|
||||
- Patcher: `scripts/patchers/kernel_jb_patch_shared_region.py`
|
||||
- Analysis doc: `research/kernel_jailbreak_patches/patch_shared_region_map.md`
|
||||
- Analysis doc: `Research/KernelJailbreakPatches/patch_shared_region_map.md`
|
||||
|
||||
## 2026-03-06 Rework
|
||||
|
||||
|
||||
@@ -95,7 +95,7 @@ The upstream pair is the correct semantic gate because:
|
||||
## Files
|
||||
|
||||
- Patcher: `scripts/patchers/kernel_jb_patch_spawn_persona.py`
|
||||
- Analysis doc: `research/kernel_jailbreak_patches/patch_spawn_validate_persona.md`
|
||||
- Analysis doc: `Research/KernelJailbreakPatches/patch_spawn_validate_persona.md`
|
||||
|
||||
## 2026-03-06 Rework
|
||||
|
||||
|
||||
@@ -156,7 +156,7 @@ if (true) goto allow; // compare neutralized
|
||||
- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/runtime_verification_report.json`
|
||||
- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_runtime_patch_points.json`
|
||||
- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_patch_chain_report.json`
|
||||
- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_patch_chain_report.md`
|
||||
- Artifacts: `Research/KernelJailbreakPatches/RuntimeVerification/ida_patch_chain_report.md`
|
||||
<!-- END_RUNTIME_IDA_VERIFICATION_2026_03_05 -->
|
||||
|
||||
## 2026-03-06 Upstream Rework Review
|
||||
|
||||
@@ -129,7 +129,7 @@ Both variants emit exactly one patch:
|
||||
## Files
|
||||
|
||||
- Patcher: `scripts/patchers/kernel_jb_patch_task_for_pid.py`
|
||||
- Analysis doc: `research/kernel_jailbreak_patches/patch_task_for_pid.md`
|
||||
- Analysis doc: `Research/KernelJailbreakPatches/patch_task_for_pid.md`
|
||||
|
||||
## 2026-03-06 Rework
|
||||
|
||||
|
||||
@@ -190,7 +190,7 @@ return 1;
|
||||
- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/runtime_verification_report.json`
|
||||
- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_runtime_patch_points.json`
|
||||
- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_patch_chain_report.json`
|
||||
- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_patch_chain_report.md`
|
||||
- Artifacts: `Research/KernelJailbreakPatches/RuntimeVerification/ida_patch_chain_report.md`
|
||||
<!-- END_RUNTIME_IDA_VERIFICATION_2026_03_05 -->
|
||||
|
||||
## 2026-03-06 Upstream Rework Review
|
||||
|
||||
@@ -231,7 +231,7 @@ goto guarded_path; // unconditional
|
||||
- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/runtime_verification_report.json`
|
||||
- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_runtime_patch_points.json`
|
||||
- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_patch_chain_report.json`
|
||||
- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_patch_chain_report.md`
|
||||
- Artifacts: `Research/KernelJailbreakPatches/RuntimeVerification/ida_patch_chain_report.md`
|
||||
<!-- END_RUNTIME_IDA_VERIFICATION_2026_03_05 -->
|
||||
|
||||
## 2026-03-06 Rework
|
||||
|
||||
@@ -331,7 +331,7 @@ post-call boolean naturally becomes 0.
|
||||
* `outputs/hv_vmm_present_xref.json` — full per-binary xref dump
|
||||
(string addresses, xref addresses, classification, surrounding
|
||||
disassembly).
|
||||
* `research/hv_vmm_present_xref.json` — same dump committed in-tree.
|
||||
* `Research/hv_vmm_present_xref.json` — same dump committed in-tree.
|
||||
|
||||
## Patcher implementation (Dev + JB only)
|
||||
|
||||
@@ -416,7 +416,7 @@ name-to-MIB translation.
|
||||
was written and no longer does: it and `cfw_patch_hv_vmm_rootfs.py`
|
||||
were removed in the blacklist-flip redesign, which made the
|
||||
standalone rootfs mangle unnecessary. See item 8 in
|
||||
`research/0_binary_patch_comparison.md`.)
|
||||
`Research/0_binary_patch_comparison.md`.)
|
||||
* `scripts/patch_hv_vmm_userland.sh` — thin wrapper used by the
|
||||
install scripts.
|
||||
* `scripts/cfw_install_dev.sh` — DSC patch is applied while the
|
||||
|
||||
@@ -71,7 +71,7 @@ entire point of moving the entitlements off the entry point.
|
||||
> `vm.cs_system_enforcement` reads 1 — the kernel kills amfid for the dirty page
|
||||
> — so the tool was removed the same day. The spike's own findings do not depend
|
||||
> on it: what was shown is that a bypass lasting one exec suffices, not that any
|
||||
> particular tool provides it. `research/host/host_binary_split.md` has the
|
||||
> particular tool provides it. `Research/Host/host_binary_split.md` has the
|
||||
> measurement. The replacement is `amfidont`, below.
|
||||
|
||||
## Reproducing it
|
||||
|
||||
Reference in New Issue
Block a user