mirror of
https://github.com/Lakr233/vphone-cli.git
synced 2026-10-02 08:04:32 +08:00
Patches were scattered across the patchers that applied them: nothing listed what a run would do, and nothing could turn one off. This adds the manifest layer that names them and the preset layer that chooses. VPhonePatchKit is a distribution framework (library evolution on) holding the model: VPhoneVersion, VPhoneVersionRequirement, VPhonePatchDeclaration, VPhonePatchSetManifest, VPhonePatchPreset, VPhonePatchPlan and the gate a patcher consults before each write. Capstone and the ARM64 encoder moved in behind an internal import, so nothing downstream sees the package. Ten bundled sets in FirmwarePatcher/PatchSets declare every existing patch, checked against the patchers by FirmwarePatchSetCatalogTests. Two presets ship in VPhone.bundle: standard, and extended for the experimental sets. A version-pinned patch is present in the manifest but off unless a preset or a per-VM checkmark asks for it, and neither can widen its version gate. Patch sets also load from outside the tool. A .vphonepatchset is a macOS loadable bundle whose Contents/Resources/Manifest.plist is read before any of its code is mapped, and whose executable exports one symbol, vphone_patch_set_principal, returning a VPhonePatchSetPrincipal that hands the pipeline one BufferedPatcher per component the plan enabled. Not NSPrincipalClass, which is how a loadable bundle normally names its entry point: library evolution makes VPhonePatchSetPrincipal a resilient superclass, so a subclass of it needs runtime metadata initialization and is not registered with the ObjC runtime when the image is mapped. NSClassFromString cannot find it, and Bundle.principalClass then silently returns whichever class was registered — the example set's patcher rather than its principal. A @_cdecl symbol found with dlsym has none of that. External sets are boot-chain only, because root cfw install loads no external set; a preset that names one lives in ~/.vphone/patches_presets and cannot shadow a shipped identifier. `vphone-cli patchset import` copies a set into ~/.vphone/patchsets and ad hoc signs it if it arrived unsigned, so a bundle straight out of Xcode loads: the linker signs its Mach-O but seals no resources, which codesign rejects until one pass over the bundle fixes it. The signature is re-checked from disk at every load, and PatchSetLoaderTests proves that over the example set — inspect, validate, tamper, load, patch, gate off. BufferedPatcher replaces the nine concrete downcasts the pipeline used to read patched bytes back with, which is what lets an out-of-tree patcher return any. Launchpad gains a patch table per machine, `vphone-cli fw set-patches` writes the selection, and Skills/authoring-patch-sets documents the whole flow. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>