#development

1 messages · Page 66 of 1

plain python
#

since we got amfid and ct bypass

#

so it's just an annoyance

naive kraken
#

whatever I did didn't work

#

I added the entitlements to the plist, ran make, did zstd ctbypass and replaced ctbypass.gz with the resulting file

#

fails when getting entitlements though

#

also the new file is 12kb, the old one was 6kb

plain python
naive kraken
#
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
    <key>application-identifier</key>
    <string>com.odysseyteam.ctbypass</string>
    <key>com.apple.developer.team-identifier</key>
    <string>odysseyteam</string>
    <key>keychain-access-groups</key>
    <array>
        <string>com.odysseyteam.*</string>
    </array>
    <key>platform-application</key>
    <true/>
    <key>com.apple.private.security.container-required</key>
    <false/>
    <key>com.apple.private.security.no-sandbox</key>
    <false/>
    <key>com.apple.private.security.disk-device-access</key>
    <true/>
    <key>com.apple.private.vfs.snapshot</key>
    <true/>
    <key>com.apple.private.apfs.revert-to-snapshot</key>
    <true/>
    <key>com.apple.rootless.install</key>
    <false/>
    <key>com.apple.rootless.volume.Update</key>
    <true/>
    <key>task_for_pid-allow</key>
    <true/>
    <key>com.apple.security.exception.iokit-user-client-class</key>
    <array>
        <string>AppleMobileApNonceUserClient</string>
        <string>AppleSEPUserClient</string>
        <string>AppleSEPManager</string>
    </array>
</dict>
</plist>

#

oh

#

false

#

lol

plain python
#

lol

naive kraken
#

still same

#

I mean doesn't even get past grabEntitlements

#

if I remove the two new entitlements it works again

plain python
#

huh I could've sworn I had 14.8.x blobs for my iPod touch

#

guess I have 14.7.1 instead

naive kraken
#

should be fine I'm running 14.6

plain python
#

it should say which entitlements it failed to get

naive kraken
#

it doesn't

#

ok it's weird, if I put in only one of the two in the wantedEntitlements, it works

steady nest
#

hum

naive kraken
#

if I put in both it doesn't

steady nest
#

or the debug build doesn't work due to kfd?

slender glade
plain python
plain python
slender glade
plain python
#

so that should tell us which one it's failing on

#

or set a breakpoint on "wantedEntitlements.count == 0"

#

and do "po wantedEntitlements"

#

to see which ones are left

plain python
naive kraken
slender glade
#

ic

plain python
#

in xcode add any additional entitlement to the taurine app

#

doesn't really matter what you add

naive kraken
#

where do you add entitlements in Xcode

native dune
#

you can add an entitlements file somewhere

plain python
#

add a capability

naive kraken
#

yeah found it

plain python
#

maybe we should just call a bin to call mount on our behalf

steady nest
#

ctbypass is the perfect target ig

naive kraken
#

yeah and couldn't you give the bin whatever seatbelt profile you want

naive kraken
#

adding a capatability broke the exploit or something

#

lmao

plain python
#

we can just have another bin for calling mount anyways since amfid is ded

naive kraken
#

nah exploit is just broken now idk anymore

steady nest
#

com.apple.private.persona-mgmt time

steady nest
#

fugu14 doesn't require com.apple.rootless.install so I suppose that's not the cause for the mounting fail

naive kraken
#

keep in mind this is 14.6

#

no idea if this changed in 14.4, 14.5 or 14.6

plain python
steady nest
#

Since it fails on 14.4 I suppose it was there?

naive kraken
#

but as far as I can see 14.5 is the major update

steady nest
plain python
steady nest
#

A10X isn't able to go to 14.5.1 is it?

plain python
#

aka literally give it all of them

steady nest
#

@visual meadow ?

naive kraken
#

ok it seems breakpoints are what break the exploit

visual meadow
#

u just need to dump activation tickets from 16

#

then it works just fine

#

untethered and stuff

#

I restored my pro 10.5 to 14.4.2

#

and placed in 16 tickets

#

it works just fine

steady nest
#

no battery drain, no weird crap?

visual meadow
#

nope

#

I never checked passcode or touchid

#

But other than those it works fine

steady nest
#

those are important

visual meadow
#

Ok

steady nest
#

also fortnight bug

visual meadow
#

Let me check

steady nest
#

please do

#

I don't think I have 15 blobs for this

visual meadow
#

with 16 sep

steady nest
#

idk

#

is 15 compatible with latest sep?

naive kraken
#

I added capatabilities but I'm still running into that issue

visual meadow
faint timber
#

17 is 16 compat idk about 16 15

steady nest
naive kraken
plain python
visual meadow
#

ok

#

its setting

#

passcode

#

Ok

#

it set

steady nest
visual meadow
#

passcode and touchid work

#

it doesn't activate yea

#

you have to place tickets in

steady nest
#

huum

visual meadow
#

Everything works after u do that tho

steady nest
#

I can't do much on 14.3

visual meadow
#

Im testing reboot after setting passcode

#

Wtf

#

it wiped its tickets

#

lol

#

whatever

naive kraken
steady nest
#

yeah so I'm good on 14.3

visual meadow
steady nest
plain python
visual meadow
#

you could boot a later kernel with checkra1n or something

plain python
#

homekit/healthkit/keychain stuff should work

primal perch
#

nelectra

naive kraken
#

ok worked

#

still same mount issue

#

Aug 21 22:50:45 kernel(Sandbox)[0] <Error>: System Policy: Taurine(297) deny(1) file-mount /private/var/MobileSoftwareUpdate/rootfsmnt

steady nest
#

yeah it's going to be the ct bypass approach then

#

annoying

visual meadow
#

Why not repurpose the other binary

#

it steals entitlements from

#

for entitlements and mounting

naive kraken
#

inb4 apple took fugu14 too seriously and that's what caused them to mitigate the remount technique

steady nest
#

oh damn I have all blobs since 12.4

naive kraken
#

I have an SE that I can restore to 14.x

steady nest
#

well, basically all blobs

naive kraken
#

but I'm going to bed now

visual meadow
#

cya

tepid olive
#

make taurine rootless ez

steady nest
#

but restoring those to 14 will encounter the same bug?

#

ah, those have 15 signed

#

zzzzzzz

visual meadow
#

lol

#

i accidentally command q'd disc

plain python
visual meadow
#

O

#

Well then that works too

#

opa going to bed tho

#

Also it compiles fine on 13.2.1

#

and the issue with debug doesn't happen

#

so lol

plain python
steady nest
#

@visual meadow is your ipad wifi or cel

visual meadow
#

which

#

11 inch or 10.5

steady nest
#

10.5

visual meadow
#

wifi

steady nest
#

huh why's it deleting tickets then

visual meadow
#

Idk

#

deleted tickets when i rebooted after setting passcode

steady nest
indigo peak
#

@lime pivot

While building module 'Cephei' imported from Tweak.xm:1:
In file included from <module-includes>:2:
/Users/fiore/theos/vendor/lib/iphone/rootless/Cephei.framework/Headers/Cephei-Swift.h:221:13: error: alias declarations are a C++11 extension [-Werror,-Wc++11-extensions]
using Int = ptrdiff_t;
            ^
/Users/fiore/theos/vendor/lib/iphone/rootless/Cephei.framework/Headers/Cephei-Swift.h:222:14: error: alias declarations are a C++11 extension [-Werror,-Wc++11-extensions]
using UInt = size_t;
             ^
Tweak.xm:1:9: fatal error: could not build module 'Cephei'
#import <Cephei/HBPreferences.h>

only when building for rootless does this happen, should i just add -Wno-c++11-extensions to my makefile?

slender glade
#

or at least the flag

indigo peak
#

huh

#

no

slender glade
#

i'm pretty sure that like

#

using is not valid in c

#

so why is the swift generated header using cpp syntax

wicked summit
#

hit the typedef

late ridge
#

anyone know how I could get camera access within a springboard tweak, cause i'm not doing the whole requesting perms thing like I would in an app so I'm not sure what to do

unkempt magnet
plain python
#

@unkempt magnet @naive kraken turns out there was a much simpler fix

#
/dev/disk2 on /Developer (hfs, local, nosuid, read-only)
/dev/disk0s1s1 on /private/var/MobileSoftwareUpdate/mnt1 (apfs, sealed, local, nosuid, journaled, noatime)
unkempt magnet
#

Nice

velvet path
#

is it worth me pulling out my 14.6 6S to look into this or no

visual meadow
#

cs is testing on 14.7.1

velvet path
#

that's on their Touch 7 though iirc

velvet path
#

really the ideal thing would be A11 since it weirdly works on 0 versions with the wh1te4ever fork and I have no idea if this branch works or not

velvet path
#

now I just need to figure out how to compile this

fiery seal
#

taurine has epic makefile

plain python
visual meadow
#

prob even 14.8.1

#

well yeah

#

all it changes is that one exploit u0 uses

#

afaik

#

Idk if u saw my dm but what did you change to get it to mount?

plain python
#

it's called the Nathan be quiet change

visual meadow
#

That's crazy

#

My fault

tepid olive
#

ate u up

visual meadow
#

lol

hexed knot
#

thats what fixed it for me

indigo peak
#

@lime pivot or anyone else
where does rootless cephei's HBPreferences create preference file?

late ridge
plain python
#

@naive kraken @unkempt magnet pushed again to kfd branch. It remounts successfully now, amfi is debilitated, and it gets right up to where it starts jailbreakd now

hasty marsh
#

@fiery seal

atomic widget
#

I will check it out now. Wait for me

#

I try on iphone 12 promax 14.8

hexed knot
#

I delete the prefs file yet it stays

lime pivot
atomic widget
hexed knot
#

Word

#

Wasnt like that when i had it tested on rootful

atomic widget
#

Created Rootfs snapshot successfully but not working with other features yet

plain python
#

@naive kraken @unkempt magnet it is done

native dune
#

why is the signing tab just not there

#

xcode 15 beta 3

native orbit
plain python
#

ok pushed

#

should be working up to 14.8.1 on arm64 now

native dune
#

the signing and capabilities editor

#

where is that

plain python
#

wtf I leave for a few months and this is what Sileo turns into

#

@grim sparrow what is this

native orbit
#

are u on the right scheme neb?

native dune
#

its supposed to be Analytics

plain python
#

11/10

native dune
primal perch
#

download anal

native dune
primal perch
#

need

primal perch
native dune
#

im not a furry but gm

plain python
native orbit
#

blurry one to

native dune
#

i swear xcode hates me

#

@native orbit can u build ipa pls

native orbit
#

mhm

native dune
#

it keeps panicking lol

#

the A9 experience

plain python
#

alright Ventana works

unkempt magnet
#

Nice

fiery seal
#

Works on A8X (air 2) 14.8.1 (haven't rebootstrapped with it but it works with odysseyra1n in place)

native dune
#

taurine logo!!!

winged lantern
native dune
#

thats the userspace reboot logo i assume

native dune
#

took 3 tries on my 6s

fiery seal
#

taurine splash is so nice

winged lantern
native orbit
#

how they do the splash screen, never looked into it

atomic widget
#

Cry, not working on arm64e ios 14.8 lmao3D

native dune
native dune
#

it seems more reliable

plain python
native dune
#

because odysseyra1n strap but whatever

#

does bootstrapping work?

plain python
# plain python

that should be as good as it can get

Xcode 13.2.1 w/ release build

winged lantern
native orbit
#

xcode 13 >>

native dune
#

turn off the device, let it sit for like 20 seconds, turn it on, make sure wifi icon is not greyed out, and run taurine

#

if the wifi icon is greyed out it doesnt work for me, not sure why that happens

#

restoring rootfs works @plain python

plain python
plain python
native dune
#

nice

#

bootstrapping rn

plain python
#

only thing not tested is arm64e on 14.4+

#

but arm64 should be all set

native dune
#

i doubt that will work because of ppl

native orbit
#

should update the procursus strap if ur gonna release

native dune
#

^

native orbit
#

like 60 packages to update lmao

serene ridge
#

gonna try using this on my 8 that’s running 14.8.1

native dune
#

smith exploit has worked first try for me 4 times in a row

#

and its really fucking fast

#

who wanna make an untether

native orbit
native dune
#

60 packages lmao

winged lantern
serene ridge
#

works on 14.8.1 (says i’m jailbroken cos I was already strapped with odysseyra1n)

#

does restoring rootfs and bootstrapping work

native dune
#

yes

#

need to tell Amy that it's saying odysseyra1n on a fresh taurine install

plain python
#

anyways, I got another chromebook in the mail so that's my queue to get off lol

lmk if there's anything else needed for arm64 14.x otherwise I think it can be considered complete

exotic spire
native dune
#

jailbreakd source /s

native dune
#

I'm not sure

#

I wonder if flower ever made the pr

plain python
#

lol

exotic spire
#

arm64 only right

native dune
#

that's why I said sarcasm

native dune
#

is the ppl bypass in taurine confirmed for only up to 14.3

serene ridge
native dune
#

nothing I was joking

#

lmao

plain python
#

otherwise it was just updating offsets

serene ridge
#

damm the exploit is super fast

native orbit
#

c++ ware

hasty marsh
velvet path
hasty marsh
plain python
velvet path
#

oh it got posted there

#

let's see if this works on arm64e (and if it doesn't, where)

velvet path
#

oh I don't have a device to test

lime pivot
velvet path
#

I'm just saying we'll see if somebody tries it

hasty marsh
#

download anal

lime pivot
#

@grim sparrow pls label.numberOfLines = 0 lmao

hasty marsh
#

no its good like that

#

make it download anal on all devices

#

dammit the jailbreak keeps failling

velvet path
#

has anybody tested on A11, cause I know that was being broken earlier?

#

that's what's holding me up on updating the guide (and A12+ but that can be validated later)

hasty marsh
#

legend says if you play minecraft before jailbreaking your success rates go up

hasty marsh
#

pojav gonna make your phone into a soldering iron troll

plain python
hasty marsh
#

true, just buy an iPhone 7 with dead baseband troll

#

i really hope success rates grow over time 😭

native dune
#

worked 1st try 4 times straight for me

#

if it panics you can't immediately run it again you have to reboot

fiery seal
#

SE2 (A13) 14.7.1 part 1 log, will update when i get a part 2 exploit success

hasty marsh
fiery seal
#

part 2

native dune
#

wtf lol

velvet path
#

so arm64 is fine (though somebody has to test A11) but arm64e is still broken for 14.4+

winged lantern
severe ridge
radiant idol
velvet path
severe ridge
velvet path
#

once A11 works on 14.0-14.8.1 for somebody everything is fine

hasty marsh
#

me over here in my reboot kingdom 😭

native orbit
velvet path
blazing warren
velvet path
#

the old fork A11 was just completely broken

#

didn't work, even on 14.0-14.3

native orbit
#

that was broke on everything lol

velvet path
#

no

native orbit
#

o

velvet path
#

that worked fine for all other devices on 14.0-14.3 and A10(X) and earlier 14.4.x

native dune
#

I wonder if the fugu15 ppl bypass can be backported

hasty marsh
#

dammit i got past the first line of text but then it rebooted woeis

native dune
#

@native orbit @crisp frost y'all wanna make an untether

pine holly
#

Use Fugu14...

native dune
#

arm64e

pine holly
#

Fugu14 why 15

winged lantern
#

more than 10 attempts.. of these, only 3 showed an error, the rest - reboot

native dune
#

that would only be up to 14.5.1

native dune
#

it's like 3 seconds for me

pine holly
hasty marsh
#

lmfao

#

guys

#

i tapped on the screen repeteldy

#

but hey it worked

hasty marsh
#

with smith

#

so uh what is it supposed to do on the second part

native dune
#

bootstrap

hasty marsh
#

because i opened the app and hit jailbreak and it rebooted troll

#

do i have to get 2 successes in a row

native dune
#

no

native dune
#

it panicked right?

#

reboot the device

hasty marsh
native dune
#

manually

#

then wait like 20 seconds when wifi comes on and jailbreak

hasty marsh
#

oop

native dune
#

wifi doesn't affect it but it's a good indicator when to run the jb

hasty marsh
#

imma just keep my method of spamming troll

native dune
#

@frank fossil have you tried running kfd from launchd yet

#

it might need to run a little later

#

I mean fork -> run launchd -> run taurine should just work

frank fossil
#

yeah I did post some progress in Twitter

winged lantern
frank fossil
#

but it never found launchd and amfid

hasty marsh
#

aaa weird text bug happened again

#

gorn

native dune
#

taurine starts amfid if it can't find it

#

I think

#

you should run taurine after you run launchd anyway

hasty marsh
fiery seal
#

i've gotten err_jailbreak but not with the weird text

#

are you sure you're on latest

hasty marsh
#

yes

fiery seal
#

and not bootstrapped with elu or some weird thing like tht

hasty marsh
#

im on the one cs posted

hasty marsh
#

whar is that

fiery seal
#

elucubratus i.e. stock checkra1n or unc0ver

hasty marsh
#

oh

#

ew

#

i restored rootfs

austere pollen
hasty marsh
#

and then my trollstore died

austere pollen
hasty marsh
#

i think i had it in the apple tv app

winged lantern
#

I'm tired..

austere pollen
pine holly
#

For anyone trying taurine on arm64e 14.4+ it’s not working

#

This is known

hasty marsh
#

imma try phys

pine holly
#

What phone you tryibg

#

Don’t you have a 7

hasty marsh
#

iphone 7, 14.6

#

yes

pine holly
#

Valid

#

I’m so excited

#

This is such good news bro I can’t wait for arm64e

#

No more kernel panics 🙏

#

Fugu moment

winged lantern
hasty marsh
#

this iphone 7 is giving me third degree burns

velvet path
#

A11 is apparently still broken

radiant idol
#

pov A14 on iOS 14.6 finally getting a jb

hasty ruin
radiant idol
hasty marsh
#

very cash money of you coolstar

velvet path
#

ok so I'm suspecting A11 not working is an exploit offset thing

#

because the exploit literally doesn't succeed on any 14.x version for A11

pine holly
#

Is this with updated? Cause it’s using Opa’s kfd fork

#

So it should have a ton of offsets (not saying they are perfect)

velvet path
#

yes, this is 1.1.7b1

pine holly
#

Ahh Alr

#

What phone is A11

#

Is that X

#

Idek

velvet path
#

have somebody on Twitter/X with an 8 on 14.7.1 to check as well

though the original person was in Sileo Discord with an iPhone X on 14.4.2

pine holly
#

Ahh

pine holly
velvet path
#

it would be the:

  • first A12+ jailbreak for 14.8.1
  • first A12+ iPad/A14 iPhone jailbreak for 14.6-14.8
winged lantern
radiant idol
#

¯_(ツ)_/¯

hasty marsh
pine holly
#

And you mean like 14.4-14.8.1 right not just 14.8.1

velvet path
#

no

pine holly
hasty marsh
velvet path
#

u0+Fugu14 exists for 14.4-14.5.1 A12+
u0 exists for 14.6-14.8 A12/A13 iPhones

hasty marsh
#

I’ve been trying for an hour 💀

velvet path
#

for me kfd worked first try on my 14.6 6S

pine holly
hasty marsh
#

;-;

pine holly
#

But kfd was still added

velvet path
hasty marsh
velvet path
#

physpuppet

#

that’s what it defaulted to

hasty marsh
pine holly
#

Like why would 14.8.1 be targeted when 14.4.1-14.8.1 exist

#

Only some new security features are added in 14.5 and I think a few more in later version

#

There is no reason not to add 14.4-14.8.1 for arm64e

#

You know what I’m saying?

hasty marsh
#

phys moment

pine holly
velvet path
#

so actually it works for A11 on 14.6

#

what

hasty marsh
#

ok gonna go to sleep in a little bit here, tried for about an hour and a half without success.

#

actually only one successful attempt

#

got to step 2/3

pine holly
#

Never back down NEVER WHAT

hasty marsh
#

never gonna let you down

pine holly
#

Bro

hasty marsh
#

yes bro?

indigo peak
#

has anyone had any issues on rootless where the preference file isnt reloading on disk when it should

#

like on rootful when i press a toggle, registerPreferenceChangeBlock for cephei picks it up and is able to read the change perfectly fine
but on rootless im running into an issue where the code is still using an old value

hasty marsh
#

happy birthday @indigo peak

radiant idol
#

Oh happy birthday man!!

hasty marsh
#

i was first L

radiant idol
#

I don’t have a good comeback to that message

indigo peak
indigo peak
velvet path
#

happy birthday @indigo peak

native dune
#

@indigo peak happy birthday big man

indigo peak
#

ty

#

ty

hasty marsh
#

what was that, 300 attempts for 2 successes? troll

indigo peak
#

ok so back to my issue please

#

i shall ask again

#

has anyone had any issues on rootless where the preference file isnt reloading on disk when it should
like on rootful when i press a toggle, registerPreferenceChangeBlock for cephei picks it up and is able to read the change perfectly fine
but on rootless im running into an issue where the code is still using an old value

#

thank you capt incorporated

stray zenith
pine holly
#

Supports most arm64 14.X

blazing barn
pine holly
primal perch
#

alhamdulillah

pine holly
#

It’s not looking the best rn but

fiery seal
#

it's looking the best in a very long time

blazing barn
blazing barn
native dune
#

never back down never what

pine holly
#

NEVER BACK DOWN NEVER WHAT

pine holly
severe ridge
blazing barn
pine holly
#

Ayo @ star, Tiktok stealing Taurine UI.

#

It’s a blatant rip

oak sand
#

tried 4-5 times

pine holly
#

A11 btw ^^^

oak sand
#

interestingly, the one time where I wasn't plugged in, it rebooted to the battery dead charging screen

grim sparrow
tepid olive
#

What does “ cant turn auto boot back to true “

#

Mean

#

Also btw the device has an issue where it turns off randomly, and requires to be plugged in to turn on

gaunt helm
primal perch
#

(as a 12m user too)

grim sparrow
#

lol

#

I wouldn’t get away with a 12m

primal perch
#

love the size battery is fine too

#

well when its not an old one

#

700 cycles now its starting to fall off

atomic widget
#

Taurine not working on arm64e is it because of AMFI?

native dune
#

because of PPL I think

atomic widget
#

I don't think so, ios 14 can jailbreak without PPL bypass. Unc0ver updated for ios 14.8 which only needs to IOMFB exploit

slender glade
#

They need a ppl bypass too lol

#

They had it

plain python
#

(on 14.5+ especially)

visual meadow
#

How high does it work

#

/did you guys test on

severe ridge
#

didn't ask

radiant idol
#

arm64 doesn’t have PPL in the first place

granite frigate
#

fake ppl

steady nest
past echo
#

Seems kfd doesn't work well on super early boot, it always panics for me

#

So I added an intentional 10 seconds delay
Idk if it's solvable

#

Maybe I should try physpuppet instead of smith

indigo peak
#

I’m not

#

I’m using HBPrefs

past echo
indigo peak
#

HBPrefs isn’t detecting the change in the file properly

#

so I think it’s an issue with the file not reloading properly

#

but it works 100% as intended on rootful

slender glade
#

@indigo peak jbd

#

hbd

indigo peak
#

I’m not touching the prefs file

#

All I’m using is HBPreferences to read the file
and using regular preference loader to write to the file

timid furnace
#

what jailbreak are you on

indigo peak
#

so it worked fine on rootful palera1n

#

but is having issues on rootless dopamine

timid furnace
#

check logs and see what output there is from the cfprefsd hook

#

and using regular preference loader to write to the file
are you specifying the file path or just the domain

#

(hint: it should be the latter)

timid furnace
#

ok yea check cfprefsd hook logs

hasty ruin
#

i blame capt

timid furnace
#

nah

#

this is quite obviously girs fault

native orbit
indigo peak
#

@native orbit I’m doing this


<key>cell</key>
<string>PSSwitchCell</string>
<key>default</key>
<false/>
<key>defaults</key>
<string>com.yourcompany.tweak</string>
<key>key</key>
<string>somePref</string>
<key>label</key>
<string>Some Pref</string>
#

like there shouldn’t be any issues on that front, right?

native orbit
#

what u trying to do

indigo peak
#
HBPreferences *preferences;
bool somePref;

%ctor {
    preferences = [[HBPreferences alloc] initWithIdentifier:@"com.yourcompany.tweak"];
    [preferences registerBool:&somePref default:YES forKey:@"somePref"];

    [preferences registerPreferenceChangeBlock:^() {
        // handle changes here
    }];
}
timid furnace
#

because SomePref != somePref

indigo peak
#

more or less, i simplified it bc otherwise the rest of the tweak code would be there

indigo peak
timid furnace
#

ok

#

ok yes you should check cfprefsd logs then

indigo peak
native orbit
#

should work without any changes

naive kraken
indigo peak
#

it works in rootful and not on rootless which is why I’m confused

indigo peak
#

bc isn’t the xml the way it gets written?

naive kraken
#

check with filza if it gets written and where?

indigo peak
#

it’s getting written to
/var/jb/var/mobile/Library/Preferences/com.yourcompany.tweak.plist

naive kraken
#

I don't see why that code wouldn't work then

indigo peak
#

my main question is why it works perfectly fine on rootful but not on rootless

naive kraken
#

what jailbreaks

indigo peak
#

Dopamine rootless
Palera1n rootful

#

and it’s 2 dopamine devices where it’s not working

naive kraken
#

you can't really compare these

hollow wraith
# plain python offsets are probably wrong on arm64e

I’m happy to provide help and feedback. iOS 14.8 iPad 8th gen, I think a good jailbreak relies on mass feedback from the community. If there’s anything needing testing, I’m happy to execute on my device

astral pine
#

iPad 8 gen iOS 14.7.1

hollow wraith
#

Your mileage varied negatively

astral pine
#

what should I do

fiery seal
#

wait for fix

steady nest
#

was the ipa installed through trollstore?

naive kraken
#

it didn't spawn because error 85

#

which means codesign failure or something

native orbit
#

yep

hollow wraith
#

Tbf I made taurine think the iPad was jailbroken once when I set it to user

steady nest
#

there's err 2 even before

slender glade
#

That’s the error u get trying to spawn a bin without it being in a loaded tc btw

native orbit
#

"Bad executable" my ass

hollow wraith
#

Respring and there was nothing though

steady nest
#

2 -> enoent -> no such file or directory

naive kraken
slender glade
naive kraken
#

anyways maybe the forbidden entitlements put behind trust level 7 are a thing on iOS 14.5 already?

hollow wraith
#

Do you guys need me to test something I get the same errors

steady nest
#

something's failling in takeoverAmfid

#

then it fails again on remount

#

and that's where the second posix spawn fail comes from (?)

#

this is even before amfidebilitate

native orbit
#

it fucking up on arm64e or arm64?

steady nest
#

arm64e

hollow wraith
#

a64e 14.4+

native orbit
#

rip

hollow wraith
#

Indeed

native orbit
#

all my 14 devices are e less

hollow wraith
#

?

#

they are ARM64?

native orbit
#

ye

hollow wraith
#

Mine is ARM64e

#

Ripperoni pepperoni

steady nest
hollow wraith
#

Uh how do I do that

#

@prime ingot believes to know the issue

prime ingot
#

g

hollow wraith
#

I’m the sileo discord guy

#

Tell them about the bootstrapper thing

#

But on ARM64, he had the issue

prime ingot
#

on my ipad it just failed to bootstrap, but when I jbed with checkra1n to use the oddyssey bootstrapper the script and the shortcut failed

steady nest
# steady nest https://github.com/Odyssey-Team/Taurine/blob/ae6af729fa6d3edf952becf2215f9cf080e...

https://developer.apple.com/documentation/xcode/stepping-through-code-and-inspecting-variables-to-isolate-bugs see this, start in the line I said above, and then press on step over until it prints posix spawn fail or failed to get region, and send a screenshot

Apple Developer Documentation

Find the cause of your bugs by watching variables change as you step through your source code in the debugger.

#

meant this message

prime ingot
#

I dunno if that helps in any way

hollow wraith
#

actually the logs do start with an error about no internet

steady nest
#

requires xcode mate

hollow wraith
#

Apologies mate

#

I lack a mac

steady nest
hollow wraith
#

Where is the full log file kept

#

I can send that if this little twat stops kernel panicking

#

My iPad, not the app, I love coolstar and taurine

steady nest
#

we just need the end of the log

#

from the app I guess

#

from console app on Mac would be cool too but intjstage

hollow wraith
steady nest
#

use phys puppet instead of smith

#

seems more reliable to me

naive kraken
#

wrong

#

the root cause of all these issues is that there is an app crash

native orbit
#

smith been better for more

naive kraken
#

in some logging function

naive kraken
#

so half the time it just panics because the app crashes, but it's really weird

hollow wraith
#

I find it’s more than half

native orbit
#

i removed emojis in the logs of kfd and it fixed it fr

hollow wraith
#

Chris doesn’t always do the error popup tbf

prime ingot
hollow wraith
#

No fucking way

native orbit
#

sumn with taurine log system is trying to color the emoji or some shit idk

naive kraken
#

yep that sounds about right

native orbit
#

just the app crashes at time nothing else

slender glade
#

what

slender glade
#

😭

prime ingot
#

that is the funniest bug ive heard of in a while

native orbit
#

mfw a green circle breaks the whole app

hollow wraith
#

Send patched eye pee ayy?

#

Actually is that illegal

prime ingot
hollow wraith
prime ingot
#

sort of

#

but will you actually get in legal trouble

#

no

hollow wraith
#

No but I don’t wanna upset coolstar

#

I mean on the copyright

prime ingot
#

no one in the right mind is gonna try and sue you over an ipa

hollow wraith
#

Redistribution

#

No I mean coolstar might get irritated that we violate her copyright liscence

slender glade
#

oh my god shut up

prime ingot
#

if the source is open and recompiled

#

bruhhh I keep meaning to type more and I kkeep pressing the fucking enter key

#

im just gonna stop talking

hollow wraith
#

Ok

plain python
#

@steady nest @hollow wraith @naive kraken offsets for task flags are wrong on arm64e 14.5+

hollow wraith
#

Confirmed?

plain python
#

and I suspect bsd_info and jop_pid are wrong too

unkempt magnet
#

Oh

plain python
hollow wraith
#

So what result did someone get when disabling emoji in kfd

native orbit
#

thats it

hollow wraith
#

Ooh that’s useful

visual meadow
#

Didnt crash for me when debugging

hollow wraith
#

Also the chris method when working shows emojis

visual meadow
#

Its something with jbexec/libhooker

naive kraken
#

logging emojis seems to work for me

hollow wraith
#

On Chris and the other method?

naive kraken
#

I think generally it's not a good idea to have the log thread running during the exploit

native orbit
#

idk what was going on with it tbh, just the first thing i thought off and it fixed my issue shrug

hollow wraith
#

physpuppet errors the emojis when it works (most of the time) Chris doesn’t error the emojis when it runs (I’ve had 7 goes in a row and it hasn’t worked again)

visual meadow
#

Physpuppet literally never failed when coolstar was remoted in

#

Like

granite frigate
#

i just changed red to failed, green to success, etc

visual meadow
hollow wraith
#

Not a single kernel panic on iOS 14.4+ A12?

granite frigate
#

physpuppet never failed on me on 12/13 either

naive kraken
#

disabling the logging thread completely seems to increase my success rate by a lot

velvet path
#

physpuppet was also first try on my 6S on 14.6

hollow wraith
#

Is my input helping or slowing this down

velvet path
#

I know smith has to do some extra cleanup (based on what the write up said iirc)

hollow wraith
naive kraken
#

physpuppet never worked for me on 14.6 A11

#

nvm just worked

#

idk what was up with it not working earlier

hollow wraith
#

I find that a little bit ironic

native orbit
#

success rate so good

naive kraken
#

I think logging is the problem

hollow wraith
#

Lemme see if it reaches the end of the break with logs turned off

naive kraken
#

turning off logs isn't going to "turn off logs"

hollow wraith
#

Like the in app logging

naive kraken
#

I commented that out

hollow wraith
#

Yeah but it works sometimes

native orbit
#

i think just pausing all threads the best during exploit

hollow wraith
#

No panic just fails

naive kraken
#

worked 3/3 times with logs commented out

#

trying again now with logs enabled

hollow wraith
#

Hardware software combo?

naive kraken
#

A11, 14.6

granite frigate
#

kfd works on iOS 12.5.7

#

idk wtf I did to fix the weird issue but idc

#

it works

naive kraken
granite frigate
#

Uh

#

💀

#

yes kwrite just hung

#

wtf

hollow wraith
granite frigate
#

Unrelated

#

that happens normally

native orbit
#

mfw unrelated 💀

granite frigate
#

omg now i have to figure out why kwrite doesn't work

hollow wraith
#

Ok

naive kraken
hollow wraith
#

So the only errors are the font and then the end result

naive kraken
#

and with logs commented out I mean outputSource and errorSource

native orbit
#

ios 12 exploits aren't even that bad

indigo peak
#

i genuinely dont know why these prefs wont work

#

rootless bad

granite frigate
native orbit
#

time_saved better shrug

slender glade
hollow wraith
#

Yes

#

I know now

slender glade
#

does taurine just log all stdout messages

visual meadow
#

Afaik, i think?

granite frigate
#

how do I disable the log thread

slender glade
granite frigate
#

Odyssey

slender glade
#

hm

plain python
#

@hollow wraith @naive kraken I found my old arm64e patchfinder; going to grab the 14.5 offsets in a few min

hollow wraith
#

Okie dokie

steady nest
#

huge

hollow wraith
#

I love your work by the way you’re really cool

#

Coolstar

visual meadow
#

Wstar

steady nest
#

gotta ask, any plans for launchd untether

plain python
hollow wraith
#

It hurt itself in confusion

slender glade
granite frigate
#

ok

slender glade
steady nest
#

lol amy already released a fix for that canister issue

plain python
hollow wraith
#

This happens about half the time smith doesn’t panic

#

This is at the end of the Logs

plain python
#

tfw I'd rather grab the asn1 parser from taurine and shove it into a Swift playground instead of bothering to compile tihmstar's shit to get img4tool

timid furnace
#

why do you have an asn1 parser

visual meadow
#

Dependency hell

granite frigate
#

😭

plain python
slender glade
timid furnace
#

that shit is pain

plain python
#

nah it's fine

native orbit
plain python
#

just don't use tihmstar's shit

visual meadow
#

img4lib is good

timid furnace
#

i was using apple private api trol

#

so debugging was hard

hollow wraith
#

What’s your guys thought on bram moolenar dying

slender glade
timid furnace
slender glade
hollow wraith
#

I didn’t use vim but he was so influential

hollow wraith
timid furnace
#

no one likes vim

visual meadow
#

vim exit simulator

hollow wraith
#

I prefer other cli goodies

prime ingot
naive kraken
#

fix for log issue

native orbit
#

exploit run on the main thread ?

slender glade
native orbit
#

o, i run mine on main shrug

hollow wraith
native orbit
#

then hop back to bg thread

granite frigate
#

wen eta socket2...

native orbit
#

shortly

granite frigate
#

that bg animation is so good

native orbit
#

so much fucking code

#

its like 30000 lines now haachamaaaa

slender glade
#

I thought it suspends ur app after a certain time of hanging

prime ingot
#

guys I have an ios 1-17 jb you just gotta send me your devices (icloud logged out and fmi off)

#

(real)

native orbit
#

mainly on 32bit

slender glade
#

how does that impact success rate

native orbit
#

fuck if i know

slender glade
#

lmfao wtf

native orbit
#

32bit just cursed

elder scaffold
#

👀

native orbit
#

gm

prime ingot
elder scaffold
#

gm

slender glade
prime ingot
#

no way

#

thats crazy

native orbit
#

fr just let it cooldown by itself

#

turn it off and wait a few mintues

prime ingot
#

where else am I supposed to put my phone

elder scaffold
native orbit
#

idk what going on with it

#

it a issue to deal with later

slender glade
#

@plain python question

#

why'd u make 0xbd34a880be0b53f3 the default gen for ur jbs

naive kraken
#

because there used to be a way to get nonce collisions

#

and that generator was the one where it happened the most with

#

iirc

slender glade
#

😯

#

but that was just like A9 I think

#

damn that's like 7 years ago now

granite frigate
#

if i'm on a7 i don't actually need the give_ppl_pages function of kfd right

naive kraken
granite frigate
#

true

#

try it and see

elder scaffold
#

thread suspend reminded me of breaking a phoenix exploit with kok3shiv4.0b1...

plain python
#

@hollow wraith @naive kraken @steady nest pushed with fixed arm64e 14.5 offsets for task. Pull and try it and see if amfid works now

hollow wraith
#

Hm?

#

What’s the repo

naive kraken
#

kfd branch in Taurine

plain python
#

bsd_info and flags had wrong offsets, which would cause that error in amfidebilitate

hollow wraith
#

Wait what

elder scaffold
#

I should have saved A14 with 14.8.1... :/

hollow wraith
#

I’m being stupid can someone link 💀

#

Haven’t used github in eons

steady nest
#

you need an ipa

hollow wraith
#

Wow I found it

steady nest
#

you don't have xcode do you

blazing warren
#

so taurine will work on all devices up to 14.5, correct?

hollow wraith
#

I do not

#

Yeah I CANT compile

#

Aww jeepers

#

Can someone compile rq pretty please

#

I have such a device!

timid furnace
#

someone should check whether 13.2.1 is still needed

steady nest
#

this is 14

#

Doesn't work?

naive kraken
#

I'm compiling with latest 14 just fine

hollow wraith
#

I think it kernel panics

steady nest
#

where

hollow wraith
#

What method? Puppet or chris

steady nest
#

whichever works for you

hollow wraith
#

Running exploit 1/3 or 2/3

native orbit
#

i used 13.4.1

hollow wraith
#

RIP

#

iPad 8th gen iOS 14.8

steady nest
#

we need the log mate

visual meadow
#

Idk about arm64e

hollow wraith
#

How do I get it

steady nest
#

open the log window

hollow wraith
steady nest
#

ok exploit failed

hollow wraith
#

Failed 3 attempts

steady nest
#

try another exploit

hollow wraith
#

Panic at 2/3

granite frigate
steady nest
#

oh panic for me too

granite frigate
#

xd

hollow wraith
#

I’ll try like 8 more times

#

Because Chris is unreliable

steady nest
#

nah wait can reproduce

hollow wraith
#

Oh it’s called smith not chris

plain python
hollow wraith
#

Gets farther on smith

steady nest
#

worked this time

plain python
steady nest
#

deleted my build

hollow wraith
plain python
#

because the log window colors it red automatically if it's on stderr

hollow wraith
#

Shit it’s called smith

#

Same thing tbf

naive kraken
#

emojis aren't the problem

granite frigate
#

why did you call it chris

#

hahahaha

naive kraken
#

logs at all are the problem

plain python
hollow wraith
#

5 letter name

naive kraken
#

ah lol

hollow wraith
#

Seems to panic but at a later point

plain python
hollow wraith
#

I lack a Mac :(

#

I’m so sorry I can’t be more help

#

Earlier this time

naive kraken
#

that's just exploit fail

hollow wraith
#

Oh smith no crash just error

steady nest
#

yeah looks like exploit fail

hollow wraith
#

Smith

visual meadow
#

I'll be home in 2 hrs so hopefully cs is able to fix arm64e

steady nest
#

huh

#

same thing

hollow wraith
#

Did you get it to work on the iOS sent by cs or the other guy

steady nest
#

but looks like fixed offsets fixed one of the issues (?)

hollow wraith
#

Seems like every try with physpuppet crashes

steady nest
#

there was a failed to get region: (os/kern) invalid argument that's fixed now

hollow wraith
#

That is gone

#

So what should this build do on A12? Change the errors or actually jailbreak

steady nest
hollow wraith
#

Anyway that’s on a 14.8 iPad 8th (A12)

visual meadow
#

Yeah its not gonna work there for now

plain python
visual meadow
#

If it was

hollow wraith
visual meadow
#

Its not gonna work

hollow wraith
#

Yeah I know

steady nest
hollow wraith
#

Just finding where it gets to

#

That’s smith iPad 8th 14.8

steady nest
#

sometimes it panics, sometimes it doesn't?

plain python
hollow wraith
#

Yeah it sometimes panics sometimes doesn’t

plain python
#

hard to say without hooking up a debugger

steady nest
#

yeah, offsets again? huum

hollow wraith
#

Shit bro I’m so sorry

visual meadow
#

Send us the panic

hollow wraith
#

How lol