mirror of
https://github.com/Lakr233/vphone-cli.git
synced 2026-10-02 08:04:32 +08:00
The UDID override used to reach misagent and installd alone; Xcode, lockdown and usbmuxd kept seeing the guest's own, so a paid team's profile could not name the VM. The host reads the UDID in three places, and each is reachable from userspace: - lockdownd and remoted join vpIsMISFixTarget, so the spawn hooks insert libmisfix into them. Only the MobileGestalt interpose acts there (MISFixProcessOnlyNeedsIdentity keeps the MIS detours out). The hook now matches the obfuscated key remoted asks with, re6Zb+zwFKJNlkQTUeT+/w. - MGCopyAnswerWithError takes three arguments; the hook declared two and crashed remoted, the first hooked caller of that spelling. - vphoned sets the USB serial string, which is what usbmuxd names a device by (vphoned_usb.m, com.apple.private.usbdevice.setdescription, with AllowMultipleCreates), goes off the bus and back, and reapplies it at boot once the USB device exists. - udid.set/clear SIGKILL the hooked daemons (remoted ignores SIGTERM) and always re-enumerate, which is also what relaunches remoted. Measured on test-27.0: idevice_id, lockdown and the RSD handshake over both transports report the override after udid.set and after a reboot, and the guest's own after udid.clear. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>