Files
vphone-cli/VPhoneExecutable/VPhoneCommand/FirmwarePatcher/PatchSets/FirmwareGuestIdentityPatchSet.swift
T
LakrandClaude Opus 5.5 ae5e4531a5 Name every patch {component}-{effect}-{name}
The 117 bundled patch identifiers had grown five naming schemes
(kernel.x, jb.x, kernelcache_jb.x, txm_dev.x, bare names). Each one is now
{component}-{effect}-{name}:

- component: avpbooter, ibss, ibec, llb, txm, kernel, devicetree, dyld,
  preboot, or system-<binary> for a guest binary or file.
- effect: boot when the patch is boot-essential, exp when the standard
  preset leaves it off, cfw otherwise. A catalog test enforces this.
- name: snake_case, no hyphen, so the identifier splits from the right.

Record sites are now always <identifier>.<site>. The underscore-prefix
rule in covers(recordIdentifier:) and in the gate is gone: the new names
contain underscores, so kernel-boot-post_validation would otherwise have
covered kernel-boot-post_validation_unsigned. The 25 records that relied
on it (amfi_trustcache_1, launch_constraints_mov, sandbox_ext_N, ...) now
use a dot.

Old identifiers are not migrated. A VM whose PatchPlan or PatchSelection
names one must be patched again. The bundle becomes 2.2.0 and Launchpad
requires 2.2.0, so it never meets an old identifier from a bundle.

Launchpad's patch table shows Component, Effect and Name columns in place
of Identifier and Patch Set; the set moves to the detail line.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-30 15:20:20 +09:00

73 lines
3.6 KiB
Swift

// FirmwareGuestIdentityPatchSet.swift — Manifest for what the guest sees of itself.
//
// The shared-cache half of the hypervisor concealment that the kernel set starts,
// the watchdogd patch that goes with it, the Preboot device tree identity rewrite,
// plus the camera symbols the virtual camera is published through. These pair with
// `com.vphone.patchset.kernel.hypervisor` and the device tree's identity and camera
// nodes: on their own, each half leaves the guest inconsistent with itself.
//
// Everything here came from the former EXP variant. Only `dyld-cfw-camera` is on in
// `standard`. `dyld-exp-hv_vmm` is off for exactly the reason its kernel half is — see
// `FirmwareKernelHypervisorPatchSet` for what a 26.4 guest does when the OID is
// renamed. The watchdogd patch only matters once the hypervisor is hidden, so it
// moves with that pair (`FirmwarePatchSetCatalog.hypervisorConcealmentPatches`).
// The Preboot rewrite belongs with the device tree identity patches
// (`FirmwarePatchSetCatalog.experimentalIdentityPatches`).
import Foundation
import VPhonePatchKit
public enum FirmwareGuestIdentityPatchSet {
public static let identifier = "com.vphone.patchset.guest.identity"
/// The root `model`, `target-type` and `compatible` rewrite in the restored
/// Preboot device tree, run by `cfw install`.
public static let prebootDeviceTreeIdentity = "preboot-exp-devicetree_identity"
public static let manifest = VPhonePatchSetManifest(
identifier: identifier,
name: "Guest Identity",
summary: "Hypervisor concealment in the shared cache and watchdog, the Preboot identity, and the virtual camera symbols",
patches: [
VPhonePatchDeclaration(
identifier: "dyld-exp-hv_vmm",
title: "Shared cache hypervisor strings",
summary: """
Mangles the hv_vmm_present references in the shared cache, so a userland check \
finds nothing where the kernel set renamed the sysctl. Off by default, and \
pointless without kernel-exp-hv_vmm: enable the two together or neither.
""",
target: .dyldSharedCache,
),
VPhonePatchDeclaration(
identifier: "system-watchdogd-exp-hv_vmm_cache",
title: "watchdogd hypervisor cache",
summary: """
Forces watchdogd's cached hypervisor answer to true. Without it, watchdogd \
panics the guest once kernel-exp-hv_vmm renames the sysctl, so it is \
off by default with the concealment and must be enabled with it.
""",
target: .guestExecutable(path: "/usr/libexec/watchdogd"),
),
VPhonePatchDeclaration(
identifier: prebootDeviceTreeIdentity,
title: "Preboot device tree identity",
summary: """
Rewrites the restored device tree's root model, target-type and compatible \
entries to iPhone17,3 / D47. Off by default with the other identity rewrites.
""",
target: .prebootDeviceTree,
),
VPhonePatchDeclaration(
identifier: "dyld-cfw-camera",
title: "Camera shared cache symbols",
summary: "Redirects the camera symbols the virtual camera publishes frames through.",
target: .dyldSharedCache,
),
],
requires: ["vphone.guest.system"],
provides: ["vphone.guest.identity"],
after: ["vphone.guest.system"],
)
}