Files
LakrandClaude Opus 5.5 235272673a Keep only the camera from EXP and drop the location app hook
Issue #438: guests built after the former EXP patches joined the JB flow
lost location. standard is now the JB baseline plus the virtual camera.

- watchdogd.hv_vmm_cache joins the hv_vmm_present concealment group and
  loses bootEssential: watchdogd only panics once the OID is renamed.
- The eight DeviceTree identity rewrites and the Preboot DeviceTree
  rewrite, newly declared as preboot_devicetree.identity, are blocked in
  standard. cfw install now asks the plan before the Preboot rewrite.
- Camera DT nodes, cam offsets and camera_dsc stay on.
- libvlocation.dylib and its SystemHook load are removed. location.set,
  clear and current call IcliKit directly again, which confirms a request
  by reading back a fresh, software-simulated fix at that coordinate.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-28 22:12:15 +09:00

2.2 KiB

Sibling guest components

make -C VPhoneGuestComponents package cross-compiles guest components with Xcode's iPhoneOS SDK. The archive contains signed arm64e binaries, two camera tweak filter plists, and the GPU provenance note:

Component Archive contents
Camera app hook camfix/libcamfix.dylib, camfix/libcamfix.plist
Camera daemon hook vcamcaptured/libvcamcaptured.dylib, vcamcaptured/libvcamcaptured.plist
Launchd hook launchhook/launchdhook-vphone.dylib
Process injection bridge systemhook/SystemHook-vphone.dylib
iOS 27 app registrar vpregister/vpregister
PCC GPU driver gpu/README.md (source and extraction flow; no Apple binary)

The archive is a local build artifact, not a VM bootstrap. cfw install places the launchd hook, SystemHook, and camera hooks in /usr/lib, and the vphoned environment update replaces changed copies in a running guest. SystemHook loads libvcamcaptured.dylib into /usr/libexec/cameracaptured and libcamfix.dylib into apps that have AVFoundation loaded; neither camera hook needs ElleKit or a bootstrap. After a bootstrap installs ElleKit, the launchd hook inserts SystemHook into xpcproxy, bootstrap executables, and apps started directly by launchd. Inside xpcproxy, SystemHook carries itself into the final executable through posix_spawnp. Injected App and bootstrap processes carry the hook to their child executables through posix_spawn, posix_spawnp, and execve. SystemHook loads the selected bootstrap's usr/lib/TweakLoader.dylib in App and bootstrap processes when it exists; ElleKit owns tweak selection and loading. It logs PID and executable path to /var/mobile/Library/Caches/vphone-systemhook.log, falling back to the app's own Library/Caches when sandboxed. DISABLE_TWEAKS=1 and the safe-mode flags skip injection. Irisin installs ElleKit's own TweakLoader.dylib in the selected bootstrap. The required GPU bundle is extracted from the selected PCC firmware by vphone-cli fw prepare and copied into the VM during JB installation. No Apple GPU binary is stored in this directory, the archive, or the shipped app.

See Research/Guest/virtual_camera_transport.md for the camera transport validation and the hook installation prerequisites.