Files
vphone-cli/VPhoneExecutable
LakrandClaude Opus 5 61f76f0b4a Read the MIS failure code where 24A435 derives it, and gate the patch to 18/26
Two findings from the pristine 24A435 cache, neither of which changes
what `standard` does — it still blocks this patch.

MIS has not been rewritten; the error message said so and was wrong.
24A435's libmis never materialises 0xE8008026 at all: a whole-image
decode of 94,984 instructions finds no mov-family instruction with
immediate 0x8026 and no such word in the data. It seeds the base
0xE8008001 and *adds* its way up (add w26, w23, #0x25), where 26.6.2
seeded 0xE8008026 and subtracted down. Everything else matched: the
naming literal occurs once, has exactly one adrp+add reference, that
reference is inside the function, and the nearest preceding pacibsp is
the function start. Only findSeededError missed.

It now accepts both, and they are not interchangeable. 0x8026 stands on
its own. 0x8001 is only the bottom of the MIS error range, so it is
accepted only when the same function also holds an add whose result is
arithmetically 0xE8008026, and the scan stops at the next function's
pacibsp. That corroboration is load-bearing: the function preceding
checkTrustAndAuthorization carries the identical seed idiom 18
instructions earlier, which is also why the seed window is forward-only.
Matching is on decoded immediates and registers; nothing new is written,
so there is no new encoder and no keystone trip.

The declaration also gets applicability .oneOf([.major(18), .major(26)]).
experimental is Kind=All, so without it a 27 user would still have the
patch turned on — and after the matcher fix it would now succeed in
bricking their guest rather than failing safe. This is not a preference,
which would belong in a preset's block list; it is the statement
applicability exists for, that applying it there breaks the guest. An
unreadable base satisfies only .any and so skips the patch.

Verified on-device: with the patch out of standard, cfw install
test-27.0 completes and 24A435 + cloudOS 26.4 boots clean — panicked
false, vphoned in 6s, SpringBoard up, 264 apps. Issue #532 is closed and
its cause is confirmed to have been this patch.

Tests: 4 new, 438 total, same 132 pre-existing fixture issues. The
fixture's 32-bit add is derived from the keystone-checked encodeAddImm12
by clearing sf and asserted against Capstone, the same way its movk
already was.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-30 18:26:16 +09:00
..