Files
vphone-cli/VPhoneGuestComponents
LakrandClaude Opus 5.5 88120ff043 Tell the host the configured UDID, not only the profile check
The UDID override used to reach misagent and installd alone; Xcode, lockdown
and usbmuxd kept seeing the guest's own, so a paid team's profile could not
name the VM. The host reads the UDID in three places, and each is reachable
from userspace:

- lockdownd and remoted join vpIsMISFixTarget, so the spawn hooks insert
  libmisfix into them. Only the MobileGestalt interpose acts there
  (MISFixProcessOnlyNeedsIdentity keeps the MIS detours out). The hook now
  matches the obfuscated key remoted asks with, re6Zb+zwFKJNlkQTUeT+/w.
- MGCopyAnswerWithError takes three arguments; the hook declared two and
  crashed remoted, the first hooked caller of that spelling.
- vphoned sets the USB serial string, which is what usbmuxd names a device
  by (vphoned_usb.m, com.apple.private.usbdevice.setdescription, with
  AllowMultipleCreates), goes off the bus and back, and reapplies it at boot
  once the USB device exists.
- udid.set/clear SIGKILL the hooked daemons (remoted ignores SIGTERM) and
  always re-enumerate, which is also what relaunches remoted.

Measured on test-27.0: idevice_id, lockdown and the RSD handshake over both
transports report the override after udid.set and after a reboot, and the
guest's own after udid.clear.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-30 23:36:55 +09:00
..

Sibling guest components

make -C VPhoneGuestComponents package cross-compiles guest components with Xcode's iPhoneOS SDK. The archive contains signed arm64e binaries, two camera tweak filter plists, and the GPU provenance note:

Component Archive contents
Camera app hook camfix/libcamfix.dylib, camfix/libcamfix.plist
Camera daemon hook vcamcaptured/libvcamcaptured.dylib, vcamcaptured/libvcamcaptured.plist
Launchd hook launchhook/launchdhook-vphone.dylib
Process injection bridge systemhook/SystemHook-vphone.dylib
iOS 27 app registrar vpregister/vpregister
PCC GPU driver gpu/README.md (source and extraction flow; no Apple binary)

The archive is a local build artifact, not a VM bootstrap. cfw install places the launchd hook, SystemHook, and camera hooks in /usr/lib, and the vphoned environment update replaces changed copies in a running guest. SystemHook loads libvcamcaptured.dylib into /usr/libexec/cameracaptured and libcamfix.dylib into apps that have AVFoundation loaded; neither camera hook needs ElleKit or a bootstrap. After a bootstrap installs ElleKit, the launchd hook inserts SystemHook into xpcproxy, bootstrap executables, and apps started directly by launchd. Inside xpcproxy, SystemHook carries itself into the final executable through posix_spawnp. Injected App and bootstrap processes carry the hook to their child executables through posix_spawn, posix_spawnp, and execve. SystemHook loads the selected bootstrap's usr/lib/TweakLoader.dylib in App and bootstrap processes when it exists; ElleKit owns tweak selection and loading. It logs PID and executable path to /var/mobile/Library/Caches/vphone-systemhook.log, falling back to the app's own Library/Caches when sandboxed. DISABLE_TWEAKS=1 and the safe-mode flags skip injection. Irisin installs ElleKit's own TweakLoader.dylib in the selected bootstrap. The required GPU bundle is extracted from the selected PCC firmware by vphone-cli fw prepare and copied into the VM during JB installation. No Apple GPU binary is stored in this directory, the archive, or the shipped app.

See Research/Guest/virtual_camera_transport.md for the camera transport validation and the hook installation prerequisites.