Files
vphone-cli/Research
LakrandClaude Opus 5 2b42bf2bae Install an ad-hoc signed app by turning on the switch that exists
MICodeSigningVerifier carries allowAdhocSigning as a settable property and
installd never sets it, exactly like the MIS option. Forcing the getter makes
the real validation succeed and fill signingInfo, so the caller reads a
signing identifier instead of nil.

Forcing performValidationWithError: to return YES did not work and is gone:
the verifier had already bailed, so its caller refused on a nil identifier. A
refusal can be allowed through; an answer that was never computed cannot be
invented.

The class dump that found the property stays, but now runs only when a
selector this file expects has gone — the one moment it earns its length.

Measured on test-26.4: a codesign --sign - bundle with no certificate and no
profile installs through devicectl and launches, and so does a paid team's
dev-signed IPA.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-30 21:26:42 +09:00
..

Research library

Project overview · User documentation

This directory keeps the evidence behind firmware patches, restore and the self-contained host runtime. The current public workflow is JB only. Many notes record earlier experiments and command names; use the user guides and vphone-cli --help for current instructions.

Start here

  1. Patch comparison is the canonical per-component inventory. Its regular/dev/exp columns are historical.
  2. Firmware manifest and origins explains the hybrid firmware inputs.
  3. CFW kernel patch notes and the individual patch index lead to the kernel evidence.
  4. Native restore design and self-contained runtime explain the host migration.

By subject

Subject Notes
Firmware and boot chain Manifest and origins, iBoot patches, TXM full chain, TXM JB patches, selector 24, variant differences
Kernel CFW overview, patcher verification, FairPlay kexts, base validation 1–5, 11–15, 16–20, sandbox hooks, individual patch notes
Other patches and captures Launchd jetsam, user-mode hypervisor references, reference capture
Restore DFU probe, in-process restore
Host and archives Binary split, runtime dependency tiers, archive extraction contracts, libarchive validation
Guest interaction and VM identity DevMode XPC, keyboard events, machine identifier, RootHide bootstrap base
Historical project records Migration ledger, manifest refactoring summary

KernelSymbols/ holds symbol datasets and indexes; Reference/ holds source references when present. They are evidence inputs, not steps for running the distributed app. The files in History/ are preserved snapshots and may describe scripts or variants that have since been removed.