diff --git a/Research/0_binary_patch_comparison.md b/Research/0_binary_patch_comparison.md index 5076142..4f2c76f 100644 --- a/Research/0_binary_patch_comparison.md +++ b/Research/0_binary_patch_comparison.md @@ -371,7 +371,7 @@ The tests asserting a frozen digest moved off it first, onto the real 24A435 `seputil`; the rest of `CFWMachOTests` — structural cases that only needed *some* signed Mach-O — kept pointing at the build product, and that stopped being viable when `vphone-letmein` was deleted from the tree (see -`research/host/host_binary_split.md`). All of `CFWMachOTests` now takes its fixture +`Research/Host/host_binary_split.md`). All of `CFWMachOTests` now takes its fixture the way the sibling CFW parity suites do: `macho_pristine/seputil`, resolved through `VPHONE_MACHO_PRISTINE` with `ipsws/ref_extract/macho_pristine` as the default, **failing** rather than skipping when it is absent, since a skipped test @@ -456,7 +456,7 @@ consumers, ~15 entries). Patched dylibs query the renamed OID and get the truthful 1 (graphics + accel passthrough); blacklisted dylibs keep the original cstring, hit ENOENT on the renamed kernel, and defensively cache 0 ("not running on a VM") for sign-in / device-attestation surfaces. -Source-of-truth research: `research/patches/hv_vmm_present_usermode_xrefs.md`. +Source-of-truth research: `Research/Patches/hv_vmm_present_usermode_xrefs.md`. JB and other variants are NOT affected by this patcher. diff --git a/Research/Host/archive_extraction_contracts.md b/Research/Host/archive_extraction_contracts.md index 463094a..ba6d38f 100644 --- a/Research/Host/archive_extraction_contracts.md +++ b/Research/Host/archive_extraction_contracts.md @@ -3,7 +3,7 @@ > 2026-09-23, branch `vphone-intg-update`. libarchive 3.8.9 from > `Lakr233/libarchive.xcframework` 0.1.1, macOS 26 (26A428). > -> Companion to `research/host/libarchive_xcframework_validation.md`, which covers +> Companion to `Research/Host/libarchive_xcframework_validation.md`, which covers > whether libzstd and the liblzma MT encoder are compiled in. This one is > about behaviour on disk. diff --git a/Research/Host/host_binary_split.md b/Research/Host/host_binary_split.md index 5a56867..0f10357 100644 --- a/Research/Host/host_binary_split.md +++ b/Research/Host/host_binary_split.md @@ -233,7 +233,7 @@ nothing in the tree now. 2. **That the instructions printed on a refusal are the ones that work**, on a host with `vm.cs_system_enforcement` = 1 and nothing installed yet. The `amfidont` install and daemon invocation were measured on this machine (see - `research/0_binary_patch_comparison.md`); the CLI's rendering of them into + `Research/0_binary_patch_comparison.md`); the CLI's rendering of them into an error message was not measured against a fresh host. 3. **Location and TouchID**, which depend on TCC attributing the usage strings to `vphone-vm`. It is `CFBundleExecutable`, so it should — but TCC's view of diff --git a/Research/Kernel/kernel_jb_patch_notes.md b/Research/Kernel/kernel_jb_patch_notes.md index 6cadb21..afafdf3 100644 --- a/Research/Kernel/kernel_jb_patch_notes.md +++ b/Research/Kernel/kernel_jb_patch_notes.md @@ -375,7 +375,7 @@ Should have moderate caller count (hundreds). **Historical problem**: the earlier repo-side “fix” still matched the wrong place. Runtime verification later showed the old hit landed in `_profile_syscallmask_destroy` underflow handling, not the real syscallmask apply wrapper. **Current understanding**: faithful upstream C22 is a low-wrapper shellcode patch that mutates the effective Unix/Mach/KOBJ mask bytes to all `0xFF`, then continues into the normal setter. It is not a `NULL`-mask install and not an early-return patch. -**Current status**: rebuilt structurally as a 3-write retarget (`save selector`, `branch to cave`, `all-ones cave + setter tail`) and separately documented in `research/kernel_jailbreak_patches/patch_syscallmask_apply_to_proc.md`; user reported boot success with the rebuilt C22 on `2026-03-06`. +**Current status**: rebuilt structurally as a 3-write retarget (`save selector`, `branch to cave`, `all-ones cave + setter tail`) and separately documented in `Research/KernelJailbreakPatches/patch_syscallmask_apply_to_proc.md`; user reported boot success with the rebuilt C22 on `2026-03-06`. ### patch_iouc_failed_macf — RETARGETED @@ -402,19 +402,19 @@ Should have moderate caller count (hundreds). **Historical repo behavior**: matched `ldr x0,[xN,#0x2b8]; cbz x0; bl` pattern, which landed on `exec_handle_sugid` at `0xFFFFFE0007FB09DC` — a false positive caused by `/dev/null` string overlap in the heuristic scoring. **Problem**: the old matcher targeted the wrong function entirely; patching `exec_handle_sugid` instead of the real `bsd_init` rootauth gate could break boot by mutating an exec/credential path. -**Current status**: retargeted to the real `FSIOC_KERNEL_ROOTAUTH` return check in `bsd_init`. The new matcher recovers `bsd_init` via in-kernel string xrefs, locates the rootvp panic block (`"rootvp not authenticated after mounting"`), finds the unique in-function indirect call (`BLRAA`) preceded by the `0x80046833` (`FSIOC_KERNEL_ROOTAUTH`) literal, and NOPs the subsequent `CBNZ W0, panic`. Live patch hit: `0xFFFFFE0007F7B98C` / file offset `0x00F7798C`. See `research/kernel_jailbreak_patches/patch_bsd_init_auth.md`. +**Current status**: retargeted to the real `FSIOC_KERNEL_ROOTAUTH` return check in `bsd_init`. The new matcher recovers `bsd_init` via in-kernel string xrefs, locates the rootvp panic block (`"rootvp not authenticated after mounting"`), finds the unique in-function indirect call (`BLRAA`) preceded by the `0x80046833` (`FSIOC_KERNEL_ROOTAUTH`) literal, and NOPs the subsequent `CBNZ W0, panic`. Live patch hit: `0xFFFFFE0007F7B98C` / file offset `0x00F7798C`. See `Research/KernelJailbreakPatches/patch_bsd_init_auth.md`. ### patch_io_secure_bsd_root — RETARGETED (2026-03-06) **Historical repo behavior**: fallback heuristic selected the first `BL* + CBZ W0` site in `AppleARMPE::callPlatformFunction`, landing on the `"SecureRoot"` name-match gate at `0xFFFFFE000836E1F0` / file offset `0x0136A1F0`. This changed generic platform-function dispatch routing, not just the deny return. **Problem**: the patched branch was the `isEqualTo("SecureRoot")` check, not the `"SecureRootName"` policy result used by `IOSecureBSDRoot()`. The old `CBZ->B` rewrite could corrupt control flow for unrelated platform-function calls. -**Current status**: retargeted to the final `"SecureRootName"` deny-return selector: `CSEL W22, WZR, W9, NE` at `0xFFFFFE000836E464` / file offset `0x0136A464` is replaced with `MOV W22, #0`. This preserves the string comparison, callback synchronization, and state updates, and only forces the final policy return from `kIOReturnNotPrivileged` to success. See `research/kernel_jailbreak_patches/patch_io_secure_bsd_root.md`. +**Current status**: retargeted to the final `"SecureRootName"` deny-return selector: `CSEL W22, WZR, W9, NE` at `0xFFFFFE000836E464` / file offset `0x0136A464` is replaced with `MOV W22, #0`. This preserves the string comparison, callback synchronization, and state updates, and only forces the final policy return from `kIOReturnNotPrivileged` to success. See `Research/KernelJailbreakPatches/patch_io_secure_bsd_root.md`. ### patch_vm_fault_enter_prepare — RETARGETED (2026-03-06) **Historical repo behavior**: matcher looked for `BL(rare) + LDRB [xN,#0x2c] + TBZ` and NOPed the BL at `0xFFFFFE0007BB898C`, which was actually a `pmap_lock_phys_page()` call inside the `VM_PAGE_CONSUME_CLUSTERED` macro — breaking lock/unlock pairing in the VM fault path. **Problem**: the derived matcher overfit the wrong local shape. The upstream 26.1 patch targeted the `cs_bypass` fast-path gate (`TBZ W22, #3`), not the clustered-page lock helper. NOPing only the lock acquire while the unlock still ran caused unbalanced lock state, explaining boot failures. -**Current status**: retargeted to the upstream semantic site — `TBZ W22, #3, ...` (where W22 bit 3 = `fault_info->cs_bypass`) at file offset `0x00BA9E1C` / VA `0xFFFFFE0007BADE1C` is replaced with `NOP`, forcing the `cs_bypass` fast path unconditionally. This matches XNU's `vm_fault_cs_check_violation()` logic and preserves lock pairing and page accounting. See `research/kernel_jailbreak_patches/patch_vm_fault_enter_prepare.md`. +**Current status**: retargeted to the upstream semantic site — `TBZ W22, #3, ...` (where W22 bit 3 = `fault_info->cs_bypass`) at file offset `0x00BA9E1C` / VA `0xFFFFFE0007BADE1C` is replaced with `NOP`, forcing the `cs_bypass` fast path unconditionally. This matches XNU's `vm_fault_cs_check_violation()` logic and preserves lock pairing and page accounting. See `Research/KernelJailbreakPatches/patch_vm_fault_enter_prepare.md`. --- diff --git a/Research/KernelJailbreakPatches/26.5_jb_hook_fixes.md b/Research/KernelJailbreakPatches/26.5_jb_hook_fixes.md index f295600..36c6660 100644 --- a/Research/KernelJailbreakPatches/26.5_jb_hook_fixes.md +++ b/Research/KernelJailbreakPatches/26.5_jb_hook_fixes.md @@ -217,5 +217,5 @@ here: by subsystem into `CodeSigning/`, `Sandbox/`, `Memory/`, `Process/`, `Storage/`, `Drivers/` and `Frida/`, with shared helpers in `Sources/FirmwarePatcher/Kernel/KernelJailbreakPatcherBase.swift`. -- Deeper, per-hook reverse-engineering notes are in `research/kernel_jailbreak_patches/` and the - patch inventory is `research/0_binary_patch_comparison.md`. +- Deeper, per-hook reverse-engineering notes are in `Research/KernelJailbreakPatches/` and the + patch inventory is `Research/0_binary_patch_comparison.md`. diff --git a/Research/KernelJailbreakPatches/PATCH_DOC_FRAMEWORK.md b/Research/KernelJailbreakPatches/PATCH_DOC_FRAMEWORK.md index b30859b..cd9ae9e 100644 --- a/Research/KernelJailbreakPatches/PATCH_DOC_FRAMEWORK.md +++ b/Research/KernelJailbreakPatches/PATCH_DOC_FRAMEWORK.md @@ -1,6 +1,6 @@ # JB Kernel Patch Document Framework -Use this structure for every `research/kernel_jailbreak_patches/patch_*.md` file. +Use this structure for every `Research/KernelJailbreakPatches/patch_*.md` file. ## 1. Patch Metadata diff --git a/Research/KernelJailbreakPatches/patch_amfi_cdhash_in_trustcache.md b/Research/KernelJailbreakPatches/patch_amfi_cdhash_in_trustcache.md index 85617df..a81e56f 100644 --- a/Research/KernelJailbreakPatches/patch_amfi_cdhash_in_trustcache.md +++ b/Research/KernelJailbreakPatches/patch_amfi_cdhash_in_trustcache.md @@ -219,7 +219,7 @@ return 1; - Artifacts: `research/kernel_jailbreak_patches/runtime_verification/runtime_verification_report.json` - Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_runtime_patch_points.json` - Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_patch_chain_report.json` -- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_patch_chain_report.md` +- Artifacts: `Research/KernelJailbreakPatches/RuntimeVerification/ida_patch_chain_report.md` ## 2026-03-06 Upstream Rework Review diff --git a/Research/KernelJailbreakPatches/patch_amfi_execve_kill_path.md b/Research/KernelJailbreakPatches/patch_amfi_execve_kill_path.md index dfe41ab..90df744 100644 --- a/Research/KernelJailbreakPatches/patch_amfi_execve_kill_path.md +++ b/Research/KernelJailbreakPatches/patch_amfi_execve_kill_path.md @@ -219,5 +219,5 @@ if (kill_condition) { - Artifacts: `research/kernel_jailbreak_patches/runtime_verification/runtime_verification_report.json` - Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_runtime_patch_points.json` - Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_patch_chain_report.json` -- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_patch_chain_report.md` +- Artifacts: `Research/KernelJailbreakPatches/RuntimeVerification/ida_patch_chain_report.md` diff --git a/Research/KernelJailbreakPatches/patch_convert_port_to_map.md b/Research/KernelJailbreakPatches/patch_convert_port_to_map.md index b9afc3f..f5a6340 100644 --- a/Research/KernelJailbreakPatches/patch_convert_port_to_map.md +++ b/Research/KernelJailbreakPatches/patch_convert_port_to_map.md @@ -149,7 +149,7 @@ goto normal_path; // unconditional branch - Artifacts: `research/kernel_jailbreak_patches/runtime_verification/runtime_verification_report.json` - Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_runtime_patch_points.json` - Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_patch_chain_report.json` -- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_patch_chain_report.md` +- Artifacts: `Research/KernelJailbreakPatches/RuntimeVerification/ida_patch_chain_report.md` ## 2026-03-06 Upstream Rework Review diff --git a/Research/KernelJailbreakPatches/patch_dounmount.md b/Research/KernelJailbreakPatches/patch_dounmount.md index 59c023b..2fc2f3b 100644 --- a/Research/KernelJailbreakPatches/patch_dounmount.md +++ b/Research/KernelJailbreakPatches/patch_dounmount.md @@ -165,7 +165,7 @@ Both variants emit exactly one patch: ## Files - Patcher: `scripts/patchers/kernel_jb_patch_dounmount.py` -- Analysis doc: `research/kernel_jailbreak_patches/patch_dounmount.md` +- Analysis doc: `Research/KernelJailbreakPatches/patch_dounmount.md` ## 2026-03-06 Rework diff --git a/Research/KernelJailbreakPatches/patch_hook_cred_label_update_execve.md b/Research/KernelJailbreakPatches/patch_hook_cred_label_update_execve.md index 1b2facc..7148b3f 100644 --- a/Research/KernelJailbreakPatches/patch_hook_cred_label_update_execve.md +++ b/Research/KernelJailbreakPatches/patch_hook_cred_label_update_execve.md @@ -132,7 +132,7 @@ Observed output: - `scripts/patchers/kernel_jb_patch_hook_cred_label.py` now implements faithful upstream C23 semantics - `scripts/patchers/kernel_jb.py` includes `patch_hook_cred_label_update_execve` in the active Group C schedule -- `research/0_binary_patch_comparison.md` should describe C23 as a faithful wrapper trampoline, not as a mis-targeted early-return patch +- `Research/0_binary_patch_comparison.md` should describe C23 as a faithful wrapper trampoline, not as a mis-targeted early-return patch ## Practical Effect diff --git a/Research/KernelJailbreakPatches/patch_load_dylinker.md b/Research/KernelJailbreakPatches/patch_load_dylinker.md index 79a72c5..c2a4d04 100644 --- a/Research/KernelJailbreakPatches/patch_load_dylinker.md +++ b/Research/KernelJailbreakPatches/patch_load_dylinker.md @@ -161,7 +161,7 @@ This gate executes early in image loading. Without bypassing it, binaries can fa - Artifacts: `research/kernel_jailbreak_patches/runtime_verification/runtime_verification_report.json` - Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_runtime_patch_points.json` - Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_patch_chain_report.json` -- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_patch_chain_report.md` +- Artifacts: `Research/KernelJailbreakPatches/RuntimeVerification/ida_patch_chain_report.md` ## 2026-03-06 Upstream Rework Review diff --git a/Research/KernelJailbreakPatches/patch_nvram_verify_permission.md b/Research/KernelJailbreakPatches/patch_nvram_verify_permission.md index e2073de..0b447bf 100644 --- a/Research/KernelJailbreakPatches/patch_nvram_verify_permission.md +++ b/Research/KernelJailbreakPatches/patch_nvram_verify_permission.md @@ -149,7 +149,7 @@ if ((perm_flags & BIT0) == 0) { - Artifacts: `research/kernel_jailbreak_patches/runtime_verification/runtime_verification_report.json` - Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_runtime_patch_points.json` - Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_patch_chain_report.json` -- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_patch_chain_report.md` +- Artifacts: `Research/KernelJailbreakPatches/RuntimeVerification/ida_patch_chain_report.md` ## 2026-03-06 Upstream Rework Review diff --git a/Research/KernelJailbreakPatches/patch_post_validation_additional.md b/Research/KernelJailbreakPatches/patch_post_validation_additional.md index 7ba655c..dc520b5 100644 --- a/Research/KernelJailbreakPatches/patch_post_validation_additional.md +++ b/Research/KernelJailbreakPatches/patch_post_validation_additional.md @@ -198,7 +198,7 @@ if (hash_type != hash_type) { - Artifacts: `research/kernel_jailbreak_patches/runtime_verification/runtime_verification_report.json` - Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_runtime_patch_points.json` - Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_patch_chain_report.json` -- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_patch_chain_report.md` +- Artifacts: `Research/KernelJailbreakPatches/RuntimeVerification/ida_patch_chain_report.md` ## 2026-03-06 Upstream Rework Review diff --git a/Research/KernelJailbreakPatches/patch_proc_pidinfo.md b/Research/KernelJailbreakPatches/patch_proc_pidinfo.md index c837cee..1aeb4ba 100644 --- a/Research/KernelJailbreakPatches/patch_proc_pidinfo.md +++ b/Research/KernelJailbreakPatches/patch_proc_pidinfo.md @@ -147,7 +147,7 @@ if (pid_or_flavor_guard == 0) return EINVAL; - Artifacts: `research/kernel_jailbreak_patches/runtime_verification/runtime_verification_report.json` - Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_runtime_patch_points.json` - Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_patch_chain_report.json` -- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_patch_chain_report.md` +- Artifacts: `Research/KernelJailbreakPatches/RuntimeVerification/ida_patch_chain_report.md` ## 2026-03-06 Upstream Rework Review diff --git a/Research/KernelJailbreakPatches/patch_proc_security_policy.md b/Research/KernelJailbreakPatches/patch_proc_security_policy.md index d233eae..442d9a1 100644 --- a/Research/KernelJailbreakPatches/patch_proc_security_policy.md +++ b/Research/KernelJailbreakPatches/patch_proc_security_policy.md @@ -211,7 +211,7 @@ int proc_security_policy(...) { - Artifacts: `research/kernel_jailbreak_patches/runtime_verification/runtime_verification_report.json` - Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_runtime_patch_points.json` - Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_patch_chain_report.json` -- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_patch_chain_report.md` +- Artifacts: `Research/KernelJailbreakPatches/RuntimeVerification/ida_patch_chain_report.md` ## 2026-03-06 Upstream Rework Review diff --git a/Research/KernelJailbreakPatches/patch_sandbox_hooks_extended.md b/Research/KernelJailbreakPatches/patch_sandbox_hooks_extended.md index bc94f74..c78e0da 100644 --- a/Research/KernelJailbreakPatches/patch_sandbox_hooks_extended.md +++ b/Research/KernelJailbreakPatches/patch_sandbox_hooks_extended.md @@ -199,7 +199,7 @@ Interpretation: - Artifacts: `research/kernel_jailbreak_patches/runtime_verification/runtime_verification_report.json` - Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_runtime_patch_points.json` - Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_patch_chain_report.json` -- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_patch_chain_report.md` +- Artifacts: `Research/KernelJailbreakPatches/RuntimeVerification/ida_patch_chain_report.md` ## 2026-03-06 Upstream Rework Review diff --git a/Research/KernelJailbreakPatches/patch_shared_region_map.md b/Research/KernelJailbreakPatches/patch_shared_region_map.md index 3adbbaf..f97472a 100644 --- a/Research/KernelJailbreakPatches/patch_shared_region_map.md +++ b/Research/KernelJailbreakPatches/patch_shared_region_map.md @@ -134,7 +134,7 @@ Both variants emit exactly one patch: ## Files - Patcher: `scripts/patchers/kernel_jb_patch_shared_region.py` -- Analysis doc: `research/kernel_jailbreak_patches/patch_shared_region_map.md` +- Analysis doc: `Research/KernelJailbreakPatches/patch_shared_region_map.md` ## 2026-03-06 Rework diff --git a/Research/KernelJailbreakPatches/patch_spawn_validate_persona.md b/Research/KernelJailbreakPatches/patch_spawn_validate_persona.md index 33ca23f..3eb7057 100644 --- a/Research/KernelJailbreakPatches/patch_spawn_validate_persona.md +++ b/Research/KernelJailbreakPatches/patch_spawn_validate_persona.md @@ -95,7 +95,7 @@ The upstream pair is the correct semantic gate because: ## Files - Patcher: `scripts/patchers/kernel_jb_patch_spawn_persona.py` -- Analysis doc: `research/kernel_jailbreak_patches/patch_spawn_validate_persona.md` +- Analysis doc: `Research/KernelJailbreakPatches/patch_spawn_validate_persona.md` ## 2026-03-06 Rework diff --git a/Research/KernelJailbreakPatches/patch_task_conversion_eval_internal.md b/Research/KernelJailbreakPatches/patch_task_conversion_eval_internal.md index 43cd01d..d9c1310 100644 --- a/Research/KernelJailbreakPatches/patch_task_conversion_eval_internal.md +++ b/Research/KernelJailbreakPatches/patch_task_conversion_eval_internal.md @@ -156,7 +156,7 @@ if (true) goto allow; // compare neutralized - Artifacts: `research/kernel_jailbreak_patches/runtime_verification/runtime_verification_report.json` - Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_runtime_patch_points.json` - Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_patch_chain_report.json` -- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_patch_chain_report.md` +- Artifacts: `Research/KernelJailbreakPatches/RuntimeVerification/ida_patch_chain_report.md` ## 2026-03-06 Upstream Rework Review diff --git a/Research/KernelJailbreakPatches/patch_task_for_pid.md b/Research/KernelJailbreakPatches/patch_task_for_pid.md index 143276a..621fa9d 100644 --- a/Research/KernelJailbreakPatches/patch_task_for_pid.md +++ b/Research/KernelJailbreakPatches/patch_task_for_pid.md @@ -129,7 +129,7 @@ Both variants emit exactly one patch: ## Files - Patcher: `scripts/patchers/kernel_jb_patch_task_for_pid.py` -- Analysis doc: `research/kernel_jailbreak_patches/patch_task_for_pid.md` +- Analysis doc: `Research/KernelJailbreakPatches/patch_task_for_pid.md` ## 2026-03-06 Rework diff --git a/Research/KernelJailbreakPatches/patch_thid_should_crash.md b/Research/KernelJailbreakPatches/patch_thid_should_crash.md index 31b80f1..20dc7f4 100644 --- a/Research/KernelJailbreakPatches/patch_thid_should_crash.md +++ b/Research/KernelJailbreakPatches/patch_thid_should_crash.md @@ -190,7 +190,7 @@ return 1; - Artifacts: `research/kernel_jailbreak_patches/runtime_verification/runtime_verification_report.json` - Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_runtime_patch_points.json` - Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_patch_chain_report.json` -- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_patch_chain_report.md` +- Artifacts: `Research/KernelJailbreakPatches/RuntimeVerification/ida_patch_chain_report.md` ## 2026-03-06 Upstream Rework Review diff --git a/Research/KernelJailbreakPatches/patch_vm_map_protect.md b/Research/KernelJailbreakPatches/patch_vm_map_protect.md index 42daae6..25d5c2c 100644 --- a/Research/KernelJailbreakPatches/patch_vm_map_protect.md +++ b/Research/KernelJailbreakPatches/patch_vm_map_protect.md @@ -231,7 +231,7 @@ goto guarded_path; // unconditional - Artifacts: `research/kernel_jailbreak_patches/runtime_verification/runtime_verification_report.json` - Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_runtime_patch_points.json` - Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_patch_chain_report.json` -- Artifacts: `research/kernel_jailbreak_patches/runtime_verification/ida_patch_chain_report.md` +- Artifacts: `Research/KernelJailbreakPatches/RuntimeVerification/ida_patch_chain_report.md` ## 2026-03-06 Rework diff --git a/Research/Patches/hv_vmm_present_usermode_xrefs.md b/Research/Patches/hv_vmm_present_usermode_xrefs.md index ae837d7..4bec5c1 100644 --- a/Research/Patches/hv_vmm_present_usermode_xrefs.md +++ b/Research/Patches/hv_vmm_present_usermode_xrefs.md @@ -331,7 +331,7 @@ post-call boolean naturally becomes 0. * `outputs/hv_vmm_present_xref.json` — full per-binary xref dump (string addresses, xref addresses, classification, surrounding disassembly). -* `research/hv_vmm_present_xref.json` — same dump committed in-tree. +* `Research/hv_vmm_present_xref.json` — same dump committed in-tree. ## Patcher implementation (Dev + JB only) @@ -416,7 +416,7 @@ name-to-MIB translation. was written and no longer does: it and `cfw_patch_hv_vmm_rootfs.py` were removed in the blacklist-flip redesign, which made the standalone rootfs mangle unnecessary. See item 8 in - `research/0_binary_patch_comparison.md`.) + `Research/0_binary_patch_comparison.md`.) * `scripts/patch_hv_vmm_userland.sh` — thin wrapper used by the install scripts. * `scripts/cfw_install_dev.sh` — DSC patch is applied while the diff --git a/Research/Restore/virtual_dfu_probe.md b/Research/Restore/virtual_dfu_probe.md index 4728bf9..f7ee6a1 100644 --- a/Research/Restore/virtual_dfu_probe.md +++ b/Research/Restore/virtual_dfu_probe.md @@ -71,7 +71,7 @@ entire point of moving the entitlements off the entry point. > `vm.cs_system_enforcement` reads 1 — the kernel kills amfid for the dirty page > — so the tool was removed the same day. The spike's own findings do not depend > on it: what was shown is that a bypass lasting one exec suffices, not that any -> particular tool provides it. `research/host/host_binary_split.md` has the +> particular tool provides it. `Research/Host/host_binary_split.md` has the > measurement. The replacement is `amfidont`, below. ## Reproducing it