mirror of
https://github.com/Lakr233/vphone-cli.git
synced 2026-10-02 08:04:32 +08:00
Two findings from the pristine 24A435 cache, neither of which changes what `standard` does — it still blocks this patch. MIS has not been rewritten; the error message said so and was wrong. 24A435's libmis never materialises 0xE8008026 at all: a whole-image decode of 94,984 instructions finds no mov-family instruction with immediate 0x8026 and no such word in the data. It seeds the base 0xE8008001 and *adds* its way up (add w26, w23, #0x25), where 26.6.2 seeded 0xE8008026 and subtracted down. Everything else matched: the naming literal occurs once, has exactly one adrp+add reference, that reference is inside the function, and the nearest preceding pacibsp is the function start. Only findSeededError missed. It now accepts both, and they are not interchangeable. 0x8026 stands on its own. 0x8001 is only the bottom of the MIS error range, so it is accepted only when the same function also holds an add whose result is arithmetically 0xE8008026, and the scan stops at the next function's pacibsp. That corroboration is load-bearing: the function preceding checkTrustAndAuthorization carries the identical seed idiom 18 instructions earlier, which is also why the seed window is forward-only. Matching is on decoded immediates and registers; nothing new is written, so there is no new encoder and no keystone trip. The declaration also gets applicability .oneOf([.major(18), .major(26)]). experimental is Kind=All, so without it a 27 user would still have the patch turned on — and after the matcher fix it would now succeed in bricking their guest rather than failing safe. This is not a preference, which would belong in a preset's block list; it is the statement applicability exists for, that applying it there breaks the guest. An unreadable base satisfies only .any and so skips the patch. Verified on-device: with the patch out of standard, cfw install test-27.0 completes and 24A435 + cloudOS 26.4 boots clean — panicked false, vphoned in 6s, SpringBoard up, 264 apps. Issue #532 is closed and its cause is confirmed to have been this patch. Tests: 4 new, 438 total, same 132 pre-existing fixture issues. The fixture's 32-bit add is derived from the keystone-checked encodeAddImm12 by clearing sf and asserted against Capstone, the same way its movk already was. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>