mirror of
https://github.com/Lakr233/vphone-cli.git
synced 2026-10-02 08:04:32 +08:00
A guest restored by this project is hacktivated, so it never receives an activation record and online-auth-agent can never obtain the device identity an authorization request is signed with. libmis's checkTrustAndAuthorization therefore returns 0xE8008026 and the profile stays in "Profile Needs Network Validation" for good: an app signed with a free personal-team Apple Development certificate installs, then refuses to launch, and Settings' "Verify App" cannot clear it because the network step it offers is the step that cannot complete. A paid team's profile is not marked as needing online authorization, which is why this was never seen before. DyldSharedCacheMISTrustAuthPatcher short-circuits the function to return success, writing mov x0, #0; retab after the prologue's pacibsp so the PAC pair stays balanced. The function is static and carries no symbol, so it is anchored on the log string that names it outright and then required to seed 0xE8008026 in its prologue before anything is written: two independent routes that must agree. Replacement bytes are the existing keystone-checked ARM64.movX0_0 and ARM64.retab constants, and the modified page is re-attested. A cache whose libmis lacks the string reports absent and exits 0, an already-patched cache is a no-op, and a cache with the string but no seeding prologue is an error rather than a guess. The declaration mis_trust_auth carries no applicability and is not boot essential: the guest is hacktivated on every base, so the failure exists on every base. cfw install applies it unconditionally. Validated on a fresh iPhone17,3 26.6.2 (23G90) + cloudOS 26.4 guest: the patcher reached the same site through the DSC chunk path that was derived statically from the extracted library, the guest booted normally, and a free-team app now installs, verifies, launches and accepts an Xcode attach. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>