Files
LakrandClaude Opus 5.5 1c19bb41da Give libmisfix one route: the spawn hooks, SpringBoard included
SpringBoard did carry SystemHook; what it lacked was libmisfix beside it.
Which libraries a process gets is decided in its parent, and launchd starts
SpringBoard itself, so SystemHook's list naming it was never consulted. A
probe reading KERN_PROCARGS2 showed DYLD_INSERT_LIBRARIES held SystemHook
alone in SpringBoard and both libraries in installd and misagent.

  - vpIsMISFixTarget moves to InjectionEnvironment.h and the launchd hook
    asks it too, inserting libmisfix only when the dylib exists.
  - vpInsertHooks dropped the extra library when the environment already
    named SystemHook; fixed, with make test-injection-environment.
  - No guest binary carries a libmisfix load command. The three declarations
    that added them are gone, cfw install puts each .bak back and removes
    /mf, and inject-dylib --reclaim-source-version goes with its only caller.
  - SystemHook's logs are world-writable: a root-created 0644 file silently
    dropped every line from a mobile process, which is what made SpringBoard
    look as though it never carried the hook.

Measured on test-26.4 and test-27.0, both recreated from local IPSWs: from
the first boot SpringBoard, installd and misagent carry both libraries, and
AirBuild installed through installd opens on both.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-30 22:46:10 +09:00
..