Load the camera hooks without a bootstrap and add the environment update

The camera hooks were built and shipped but never reached the guest, so
Camera.app could not show a streamed frame. cfw install now places
libvcamcaptured.dylib and libcamfix.dylib in /usr/lib beside the launchd
hook and SystemHook. SystemHook treats /usr/libexec/cameracaptured as an
injection target and loads the daemon hook there, and loads libcamfix into
app processes that have AVFoundation loaded. Both hooks install their own
Objective-C method replacements, so neither needs ElleKit or a bootstrap.

A running guest gets changed copies of those four libraries through the
new vphoned environment update. environment.status reports the SHA-256 of
each library in /usr/lib; environment.install checks the uploaded copies,
remounts / read-write when needed, renames each library into place and
remounts / read-only again, because jailbreak detection reads a writable
root as rootful. It stops cameracaptured when a camera hook or SystemHook
changed and reports when the launchd hook needs a guest restart. The VM
process runs the update once per connection, after the vphoned
self-update, uploading only libraries whose hashes differ.

Not yet verified in a guest; the validation steps are in
Research/0_binary_patch_comparison.md and Research/vphoned_http_api.md.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
Lakr233
2026-09-25 14:57:12 +07:00
co-authored by Claude Opus 5.5
parent 961f18c075
commit fc57dca56b
12 changed files with 316 additions and 29 deletions
+14
View File
@@ -27,6 +27,20 @@
> second run. The Preboot DT rewrite succeeded on a copy and was likewise
> unchanged on a second run. The original VM disk was not modified or booted.
> **Camera hooks and environment update (2026-09-25; not yet verified in a
> guest):** `cfw install` also places `libvcamcaptured.dylib` and
> `libcamfix.dylib` in `/usr/lib`. SystemHook treats
> `/usr/libexec/cameracaptured` as an injection target and loads
> `/usr/lib/libvcamcaptured.dylib` there, and loads `/usr/lib/libcamfix.dylib`
> into app processes that already have AVFoundation loaded. Neither needs
> ElleKit or a bootstrap: both hooks install their own Objective-C method
> replacements. A missing library is skipped silently; other load failures are
> logged to `vphone-systemhook.log`. A running guest receives changed copies of
> all four `/usr/lib` libraries through the vphoned environment update
> (`Research/vphoned_http_api.md`). Validation: `processes.list` shows
> `cameracaptured`, `vphone-systemhook.log` records `camera-hook=... result=loaded`
> for its PID, and `vcamcaptured.log` shows the hook installing its source.
> **Current launchd hook (2026-09-25; isolated VM verification):**
> `cfw install` now places `launchdhook-vphone.dylib` and a diagnostic
> `SystemHook-vphone.dylib` in `/usr/lib`, links `/vh` to the launchd hook,