#tvos-jailbreaks
1 messages · Page 5 of 1
Oh I see
Block apple update servers on your router and it will stop ask you to update. I did that for my jailbroken Apple TV 4K on 14.7.
How can input that on my asus router
idk i have configured a denylist on my fritzbox on some routers it is not possible you have to ask google or take a look in the manual of your router
Why do people jailbreak for KODI, when better appstore players exist
Like vlc
appstore players support VLC, MPV, FFMPEG
What else is kodi offering
you can use iptv on any player on the appstore
Help
??
Sorry am trying to find if i can JB my apple tv 4k 2nd gen am on TVOS 17 dev 6
you cannot
Kodi supports IPTV simple client with timeshift and socks5 proxy 😉
I have a raspeberry 4 in my local network with a autoconnect running VPN and a socks5 proxy server.
3 or more running Kodi devices all connect to the local running pi's proxy
hadn't considered these sorts of configurations. thankfully my isp is careless
If anyone wants to try alternatives, here is the player Im using https://testflight.apple.com/join/irMsXGg0
Can you set a socks5 proxy in the app?
I have iPhone 14 pro max I want my car play to play YouTube videos and other apps. I’m stuck
you don't
Which car do I have
You*
How do you install kodi on a Apple TV?
depends what apple tv it is
I figured it out, running kodi and seren
seren?
Yea
what's that?
what do you want?
It’s all good, I figured it out
I'm making a restore 13.4.8 IPSW for Apple TV 4K using the still-signed OTA bundle
Got as far as creating an IPSW with RootFS that successfully installs with idevicerestore
But it kernel panics a few seconds after booting, and serial output doesn't work with Alex DCSD and GoldenEye
how tf do i see the panic log
You can't restore with it
there are no public ipsw's
so i'm making mine own one
i just need the serial output to work
It won't work
why?
Because there's no actual ramdisk. You need the entirety of the ipsw, not just OTAs
With what though?
rootfs, recoveryos, restore/update ramdisks (which are shared between hd/4k)
You took an HD ipsw and rewote it for the 4K?
i took the ota bundle
it has everything minus rootfs, restore/update ramdisks and recoveryos
recoveryos for tv 4k is available for download separately
and ramdisks the 4k uses are the same ones as hd
rootfs is all that's needed
Ramdisk for 4K and HD are totally different
no
Download OTA bundle for HD and 4K and compare them
1:1 identical
Besides, why are we discussing this?
I already said the ramdisks work
What makes them different is sep
Ramdisks don't have SEP
No but sep compatibility will fail to install
- Ramdisk images are identical.
- Kernel (kernelcache) is what's "compatible/incompatible" with SEP. OTA bundles have those for both 4K and HD.
What OS are you trying to downgrade the 4K from?
It's not running any version of tvOS at the moment
? How is it not? You have it preinstalled
Well... If you consider that it's currently broken, it's 13.4.8
I did manage to boot it into recoveryOS though (NOT Recovery Mode)
Pretty useless though
I'm guessing you installed it, it bootlooped and now you're stuck on the apple logo
So it loads into the OS?
Console should tell you if you're able to operate it
It doesn't get to that point.
What did you use to construct the ipsw?
hdiutil?
I mean, technically I didn't use anything
the ipsw was constructed by hand
Well you'd have to deconstruct the OTAs to get the file structure for the ipsw to be recognized
What happens when you boot the apple tv?
So like.. Apple logo, then the screen, then reboot?
No screen.
So bootloop
i guess
It doesn't display the logo
It just flashes?
It crashes too soon for it to be displayed
sigh
I just need to debug it
I can't even verbose boot it
And I'm assuming you used checkm8 to upload the images?
Yes.
What command did you use for idevicerestore
Do you have the ipsw? I can probably examine it.. Might have to send it via dms
Well the kernel panic is probably bootchain issue
Why isn't root fs?
Because the original one doesn't exist on the internet.
That could be the issue
bruh
It does have preliminary checks
My current guess is something having to do with trustcache
Is it decrypted?
I think what happens is that some binary not present in the cache gets executed and that by default panics the kernel
I'll try booting it from recovery shell with a patched kernel
Nope, still panics
I'll check if Kong will be able to read the serial output
never used this thing before though
What can you do with a tv jb
Excellent question, my friend.
check the pins
bruh, i did manage to create a rootfs from an ota bundle alone for an ipod touch 6, but when the same method is used for tv4k, it still panics on boot
so hard without serial=3 or -v
ordered myself a different dcsd, hopefully this one will actually work
wiki says this is a newer model
I think Apple's outsmarted that..
I DID IT
APPLE TV 4K RESTORED FROM IPSW
The restore image I have here is rather messy.
I'll clean it up, and then upload it.
Oh, I should see if software updates work
Updating it to 17.0
OTA don't work :/
I'm not surprised
I have a theory as to why
I used Jonathan Levin's tool for extracting the 13.4.8 OTA bundle
However, there were a few files it failed to extract, so I just replaced them with dummy files
Seems like the OTA updater is able to detect that still.
what tool?
or.. you could just name it
What does surprise me though is I thought 13.4.8's SEP would be incompatible on anything higher than HD
Why's that?
If you install tvOS 13.4.8 with SEP from 13.4.8, there cannot be compatibility issues.
We had upgrades/downgrades on something as new as A12
You do realize that because of this possibility.. Apple may stop signing it..
tvOS 13.4.8 cannot be unsigned
yes it can
tvOS 11.0 can't upgrade to anything that's newer than 13.4.8
And you can't update Apple TV 4K through iTunes because no IPSW exist for it.
So signed it will remain.
you're talking about less than .0001% of people who are still on that firmware
i'm talking about a device that doesn't come with 11 and is not manually updatable
Not sure what you're up to
Regardless, I need to figure what to do. I want OTA's to work
ios can be updated manually.. 4k's cannot
I need someone with the real 13.4.8 to send me the files the extractor failed to extract
would being on 13.4.8 via hd work?
No.
Really, there's only 1 file to be extracted that I yoinked from a FS dump from tvOS 14.3
But the problem is, the file was slightly changed in the update
And although it works in 13.4.8, it seemingly breaks OTA
what os did the 4k start with?
you were on 11 and went to 13.4.8?
No. I updated it regularly.
Can't see the point.
I know, what I mean is Apple TV isn't a device where downgrades really change anything.
The home screen hasn't changed since tvOS 9.0
but tweak compatibility
and research
Never needed that personally.
Anyhow
I got an idea.
exploit3dguy is releasing his blackbird tool
I'll tether downgrade to tvOS 11.0, and then forcefully try to install "official" 13.4.8 through OTA
That should give me the original 13.4.8 file system
don't think the ota will work that way
did they release it yet?
No, he did not
Not sure when he does, tbh
I wonder if I should wait, or release what I have right now as beta
No OTA thus stuck on 13.4.8, but at least it can revive bricked Apple TV's
theoretically; if we had some type of tool to automate making the ota into an ipsw, we can restore within a bricked 4K using blobs
Too much work
not really.. it's the same thing, just signing the toolchain with the blob
You'll be needing to recreate the rootfs
which can probably be done via script
if i knew the steps, I could make such script
where will you upload the ipsw?
Do you mind if I announce this? This could be amazing news to those stuck on higher versions..
Np
But make sure to note that OTA functionality is broken, as of right now
This means that whichever Apple TV 4K is restored to 13.4.8 will be kind of stuck on it
Do you have any other screen grabs to prove legitimacy? Not that I don't believe you but others might be skeptical seeing as stuff can be faked since this is a device that's been undowngradable for many years
I mean, what is there to prove? Technically, recovering the system partition from an OTA bundle has been in talks for some time now
It's just that this, as far as I can tell, the first time someone actually did it
I'm meaning probably irecovery, uart, the filesystem screens etc
I'll take a clean screen grab when the TV is still restoring, then
idevicerestore + DCSD + TV showing restore progress
Also, Update restore doesn't work
This means only Erase will work
Would one need both Goldeneye and DCSD? Or just one?
I'm assuming both for checkm8
DCSD + GoldenEye
or
Breakout board (untested, should still work though)
Hm... Do wish we had a test subject...
Gonna be funny if we get "works on my machine" sort of deal
Do you know anyone with a bricked TV4K who's willing to test this bad boy?
I have one person who literally broke their iboot and has been meaning to try to recover it via serial port
Might want to delete that link though
oh
Just on here
Also, the checkm8 tool I always use is gaster
The latest commit is broken on A10X though
My fork has a fix
Checkm8 experiment to understand AP/SEP internals. - GitHub - SpookDome/gaster: Checkm8 experiment to understand AP/SEP internals.
Also, I'm gonna try one thing
tvOS 13.2 and earlier don't have "version specific" OTA updates for tvOS 17.0
That means it will fetch the full delta OTA update and not the 13.4.8 specific one that contains individual file patches
Hopefully this will make the tvOS 17.0 update work
apparently it still ended up downloading a version specific update bundle
and this one was for tvos 16.3 for some reason
i'll try spoofing version to 12.0
Starting with the iOS 17 and tvOS 17 software updates released on Monday, any Apple TV HD or Apple TV 4K model experiencing problems can be restored with a nearby iPhone, according to a new Apple support document.
If a black screen with an iPhone appears on the TV, users can unlock their...
yeah, i'm not liking that
"need to be on the latest" blah blah
i'm sure a tweak to trigger that feature can work
aha, i know how it works
probably via bluetooth i'd imagine
it's recoveryos
i think i can manually try to install and boot it
i'll do it tomorrow, since i don't have tools for working with ios 17
probably same way apple watch updates work
not giving the watch a usb port is still maddening
can't even restore it without forking over a pretty penny for black market stuff
just restore it in the shop ;)
We shouldn't have to
imagine how packed the shops would be if every piece of technology had no way to DIY repair
it would be over burdened.. so much so, they'd have to re-engineer it with a port or an alternative
honestly, this bluetooth restore isn't a bad thing
i think i know how to make it work on any a10x apple tv 4k
I kind of want to buy a bootlooped 4k on ebay or something and try restoring it to see if it works
I have one on 14.7 but don't want to fork that firmware over for the sake of testing
Mine was on 14.3 when it got fucked
what happened for it to be screwed?
the file system got pranked
(i accidentally deleted an essential file)
by the way, how the fuck do i make idevicerestore ignore gs.apple.com considering that i've already specified a ticket with -T
i'm making a cfw
fuck, futurerestore has been dead since ios 15
hm
think i got an idea
@analog elk
Such a shame there is no jb since 14.7. The HD has to be the only apple device to see 9 OS updates, even the latest 17. I am sitting on 16.5 for now but the constant update nags just temp me to go and do it since there appears to be no one working on a current jb.
There are people working on a jailbreak
ok... will continue to wait hopefully none of my apps stop working although seems like 16.5 is still fresh enough
Will the jb work on all version of 16 or just up to 16.5 ?
the first line: Any firmware version should work.
ok I thought it was just to 16.5. I also have a few 1st gen 4k's waiting o 16.5, I guess should have gone for 16.6 before 17 landed two days ago.
I mean; you could update one to 17 to take advantage of FaceTime for tvOS
don't know if you care to video chat on the big screen
@ionic copper
No, I don't care for that feature really
I think 17 will be required in 2024 for most apps imho
Required? As in no apps on 16 will work?
since the 4k 1st gen will be up to tvOS 20, things will shift as 17 being the minimum
If true, then a 16 jb will have little use
Most app developers are supporting at least 1 - 2 older OS versions including the current one.
I'm still laughing that 10.2.2 is still signed, I guess it needs to be for tvos 9 prerequisite.
This would make 15 the minimum for most apps right now although 14 is still seeing good traction for now
I believe Apple is trying their best to eliminate all instances of 14/15 due to the coretrust bug
so keeping the HD and 4k devices compatible with 17/18 will ensure that
issue with this idea: 13.4.8 is signed, so the SEP will be compatible with it
meaning = with blobs, you can update to 14/15 despite apple requiring 17 to run apps, just backup the old versions
Guys is this fr or is it some sort of glitch
its legit
good, then save its blobs
then you'll be able to downgrade.. except for 10.2.2
Why? Incompatible SEP?
yes
only works with blackbird exploit (maybe) or black box packaging
still don’t get why u get the nag, nothing for me. i only get the nag when i’m not jailbroken
I'm on 16.5 so no jailbreak (but waiting for one) and get constant nags
if you have any means of connecting the 4K via usb (goldeneye, dcsd etc) you can use an sshrd to silence the nags
Unfortunately dont have those cables but may order is a solid jb lands
a solid jb will land. I'd order them asap
or the breakout board (if you're okay with soldering)
No soldering for me lol
so then the cables. I'd get on that right away
Which ones again and where?
yo i found an old appletv hd 4th gen
can it be soft modded?
if so please drop a link
tvos 15
it can be downgraded
How
via itunes and usb-c
I'm selling my semi-tethered jailbreak Apple TV 4K with soldered switch/button to inject checkrain jailbreak on boot. It is on 14.7, if anyone is interested send me a PM.
Is nitoTV down again? I'm not getting any packages from the sources.
Nope, it works. Make sure to delete the nito tv repo, kill the nitoTV app, then re-enter it
Which one?
This is currently in my /etc/apt/sources.list.d/sources.list
deb https://nitosoft.com/electra/ ./
deb https://joshtv.net/repo ./
deb https://zenzeq.github.io/tv ./
deb https://nito.tv/repo ./
deb https://diatr.us/nito/ ./
deb https://nitosoft.com/checkra1n ./
root@ (/var/root)# apt update
Ign:1 https://zenzeq.github.io/tv ./ InRelease
Hit:2 https://zenzeq.github.io/tv ./ Release
Get:3 https://zenzeq.github.io/tv ./ Release.gpg [488 B]
Ign:3 https://zenzeq.github.io/tv ./ Release.gpg
Reading package lists... Done
W: GPG error: https://zenzeq.github.io/tv ./ Release: The following signatures couldn't be verified because the public key is not available: NO_PUBKEY F9D5F2F553ADFE2F
W: The repository 'https://zenzeq.github.io/tv ./ Release' is not signed.
N: Updating from such a repository can't be done securely, and is therefore disabled by default.
N: See apt-secure(8) manpage for repository creation and user configuration details.
E: Handler silently failed
I also tried apt -o "Acquire::https::Verify-Peer=false" update but it still complains. @ionic copper Is there something wrong with your public key?
interesting..
I'm on an Apple TV 4K (1. Gen) with tvOS 12.1. Jailbroken with ChimeraTV.
Nothing wrong with the key.. but chimera does have a certificate issue
seeing as you have both nitotv electra and checkra1n installed (need only checkra1n)
but I've also seen this error with legit repos too.. it's not the repo it's apt crapping out from an invalid check
I'm unable to jailbreak with Checkra1n because of an error:
An error occured while finding kernel slide.
Only ChimeraTV works.
well you'll need to restore root fs first
then checkra1n will work
you can't install over-top
The error appeared before I've used ChimeraTV.
The checkra1n splash screen says for tvOS 11.0 - 13.4.5. But it definitely doesnt work because of the kernel slide issue.
It's kinda frustrating because I'm halfway there but none of the repos give me packages.
I just noticed that nitotv re-added the default repos.
it's supposed to do that
that way, folks don't need to re-type everything
but with that, you should have 2 which is bingner and nitotv checkra1n
but this way I'm unable to use only your repo.
After I kill nitotv my sources.list looks like this:
deb https://zenzeq.github.io/tv ./
deb https://nito.tv/repo ./
deb https://joshtv.net/repo ./
both will get readded after I kill nitotv.
yeah, because you have the old version of nitotv
Is there a newer version available somewhere?
do you have wget?
yes
wget --no-check-certificate https://nitosoft.com/checkra1n/deb/nitotv_3.4.3-2_appletvos-arm64.deb && dpkg -i ./nitotv_3.4.3-2_appletvos-arm64.deb
copy/paste and that'll update it
nitotv may say there's an update for it but don't update it
it has an issue with killing its self when adding sources
root@ (/var/root)# wget --no-check-certificate https://nitosoft.com/checkra1n/deb/nitotv_3.4.3-2_appletvos-arm64.deb && dpkg -i ./nitotv_3.4.3-2_appletvos-arm64.deb
--2023-09-21 16:59:06-- https://nitosoft.com/checkra1n/deb/nitotv_3.4.3-2_appletvos-arm64.deb
Warning: This version of wget does not support SSL (J hasn't compiled OpenSSL for ARM..
Disabling SSL due to encountered errors.
ah
I will download it on my mac and scp it to the apple tv.
that works too
root@ (/var/root)# dpkg -i ./nitotv_3.4.3-2_appletvos-arm64.deb
(Reading database ... 21067 files and directories currently installed.)
Preparing to unpack .../nitotv_3.4.3-2_appletvos-arm64.deb ...
Unpacking com.nito.nitotv4:appletvos-arm64 (3.4.3-2) over (3.0-39) ...
dpkg: warning: unable to delete old directory '/private/etc/apt/sources.list.d': Directory not empty
dpkg: warning: unable to delete old directory '/private/etc/apt': Directory not empty
dpkg: warning: unable to delete old directory '/private/etc': Directory not empty
dpkg: warning: unable to delete old directory '/private': Directory not empty
dpkg: dependency problems prevent configuration of com.nito.nitotv4:appletvos-arm64:
com.nito.nitotv4:appletvos-arm64 depends on com.morpheus.binpack (>= 1.0-7); however:
Version of com.morpheus.binpack:appletvos-arm64 on system is 1.0-6.
com.nito.nitotv4:appletvos-arm64 depends on uikittools (>= 2.0.1-8); however:
Version of uikittools:appletvos-arm64 on system is 2.0.1-6.
com.nito.nitotv4:appletvos-arm64 depends on com.nito.uicache (>= 0.0.3-26); however:
Version of com.nito.uicache:appletvos-arm64 on system is 0.0.3-11.
com.nito.nitotv4:appletvos-arm64 depends on com.nito.breezy (>= 2.1-32); however:
dpkg: error processing package com.nito.nitotv4:appletvos-arm64 (--install):
dependency problems - leaving unconfigured
Processing triggers for com.nito.tweakinject:appletvos-arm64 (0.0.1-39) ...
Errors were encountered while processing:
com.nito.nitotv4:appletvos-arm64
😦
I guess I will have to download the dependencies one by one and scp it to my apple tv.
the issue with that
is nitotv is trying to delete the old system setup
you could.. try invoking the next update: https://nitosoft.com/checkra1n/deb/nitotv_3.0-81_appletvos-arm64.deb
dpkg -i ./nitotv_3.0-81_appletvos-arm64.deb
dpkg: warning: downgrading com.nito.nitotv4:appletvos-arm64 from 3.4.3-2 to 3.0-81
(Reading database ... 21083 files and directories currently installed.)
Preparing to unpack .../nitotv_3.0-81_appletvos-arm64.deb ...
Unpacking com.nito.nitotv4:appletvos-arm64 (3.0-81) over (3.4.3-2) ...
dpkg: warning: unable to delete old directory '/var/mobile': Directory not empty
dpkg: warning: unable to delete old directory '/etc/apt/sources.list.d': Directory not empty
dpkg: warning: unable to delete old directory '/etc/apt': Directory not empty
dpkg: error processing archive ./nitotv_3.0-81_appletvos-arm64.deb (--install):
unable to create new file '/var/lib/dpkg/info/com.nito.nitotv4.list-new': No such file or directory
Processing triggers for com.nito.tweakinject:appletvos-arm64 (0.0.1-39) ...
dpkg: unrecoverable fatal error, aborting:
unable to install updated status of 'com.nito.tweakinject:appletvos-arm64': No such file or directory
yeah...
one thing you do need.. https://nitosoft.com/checkra1n/deb/com.morpheus.binpack_1.0-9_appletvos-arm64.deb
why nitotv is trying to delete /var/mobile is beyond me.. quite scary really
Yeah
root@ (/var/root)# dpkg -i ./com.morpheus.binpack_1.0-9.deb
(Reading database ... 21083 files and directories currently installed.)
Preparing to unpack .../com.morpheus.binpack_1.0-9.deb ...
Unpacking com.morpheus.binpack:appletvos-arm64 (1.0-9) over (1.0-6) ...
Setting up com.morpheus.binpack:appletvos-arm64 (1.0-9) ...
root@ (/var/root)# dpkg -i ./nitotv_3.0-81_appletvos-arm64.deb
(Reading database ... 21086 files and directories currently installed.)
Preparing to unpack .../nitotv_3.0-81_appletvos-arm64.deb ...
Unpacking com.nito.nitotv4:appletvos-arm64 (3.0-81) over (3.4.3-2) ...
dpkg: warning: unable to delete old directory '/var/mobile': Directory not empty
dpkg: warning: unable to delete old directory '/etc/apt/sources.list.d': Directory not empty
dpkg: warning: unable to delete old directory '/etc/apt': Directory not empty
dpkg: error processing archive ./nitotv_3.0-81_appletvos-arm64.deb (--install):
unable to create new file '/var/lib/dpkg/info/com.nito.nitotv4.list-new': No such file or directory
Processing triggers for com.nito.tweakinject:appletvos-arm64 (0.0.1-39) ...
dpkg: unrecoverable fatal error, aborting:
unable to install updated status of 'com.nito.tweakinject:appletvos-arm64': No such file or directory
at least the binpack set up
what version of checkra1n are you using?
unc0verTV_5.3.0.ipa
are you using this to jailbreak??
and getting kernel slide issue
My bad I have mistaken checkra1n and unc0ver. At first I tried with unc0verTV_5.3.0.ipa and got the kernel slide error. Than I succeded with ChimeraTV.
yeah, unc0vertv won't work with tvos 12
restore root fs with chimera
then use checkra1n
I can't because I have no golden eye cable.
Ah, you can buy one
and dcsd
they're like 80 bucks
but then again; kevin needs to fix chimera nitotv
I would prefer to stick chimeratv because I dont want to spent another 80 bucks.
I scp the dependencies one by one and was able to update NitoTV:
dpkg -i ./nitotv_3.4.3-2_appletvos-arm64.deb
(Reading database ... 21115 files and directories currently installed.)
Preparing to unpack .../nitotv_3.4.3-2_appletvos-arm64.deb ...
Unpacking com.nito.nitotv4:appletvos-arm64 (3.4.3-2) over (3.4.3-2) ...
Setting up com.nito.nitotv4:appletvos-arm64 (3.4.3-2) ...
finish:uicache
Processing triggers for com.nito.tweakinject:appletvos-arm64 (0.0.1-39) ..
Is it still possible to install nControl?
I'm still getting errors:
root@ (/var/root)# apt update
Ign:1 https://zenzeq.github.io/tv ./ InRelease
Hit:2 https://zenzeq.github.io/tv ./ Release
Get:3 https://zenzeq.github.io/tv ./ Release.gpg [488 B]
Ign:4 https://apt.bingner.com ./ InRelease
Ign:5 https://nito.tv/repo ./ InRelease
Err:6 https://apt.bingner.com ./ Release
SSL certificate problem: unable to get local issuer certificate
Err:7 https://nito.tv/repo ./ Release
SSL certificate problem: certificate has expired
Reading package lists... Done
W: The repository 'https://apt.bingner.com ./ Release' does not have a Release file.
N: Updating from such a repository can't be done securely, and is therefore disabled by default.
N: See apt-secure(8) manpage for repository creation and user configuration details.
W: The repository 'https://nito.tv/repo ./ Release' does not have a Release file.
N: Updating from such a repository can't be done securely, and is therefore disabled by default.
N: See apt-secure(8) manpage for repository creation and user configuration details.
W: Invalid 'Date' entry in Release file /var/lib/apt/lists/zenzeq.github.io_tv_._Release
E: Handler silently failed
it is if paid separately and installed separately too
but in this case, ssl flaked out
Anything I can do about it?
can try apt upgrade
since the binpack is installed, it should catch any other updates
Nothing to upgrade ...
root@ (/var/root)# apt upgrade
Reading package lists... Done
Building dependency tree... Done
Calculating upgrade... Done
0 upgraded, 0 newly installed, 0 to remove and 0 not upgraded.
Still the same ssl error.
i know but now nitotv should install
It did but I'm unable to install any packages.
E: Unable to locate package com.sts.browser
...
what version of nitotv did you install?
nitotv_3.4.3-2_appletvos-arm64.deb
I did but I'm still unable to locate any package.
Ah it deleted your repo again. Will re-add it again.
No wait it still is there.
I dont get it.
root@ (/var/root)# cat /etc/apt/sources.list.d/sources.list
deb https://zenzeq.github.io/tv ./
deb https://nito.tv/repo ./
root@ (/var/root)# apt update
Ign:1 https://zenzeq.github.io/tv ./ InRelease
Hit:2 https://zenzeq.github.io/tv ./ Release
Get:3 https://zenzeq.github.io/tv ./ Release.gpg [488 B]
Ign:4 https://apt.bingner.com ./ InRelease
Ign:5 https://nito.tv/repo ./ InRelease
Err:6 https://apt.bingner.com ./ Release
SSL certificate problem: unable to get local issuer certificate
Err:7 https://nito.tv/repo ./ Release
SSL certificate problem: certificate has expired
Reading package lists... Done
W: The repository 'https://apt.bingner.com ./ Release' does not have a Release file.
N: Updating from such a repository can't be done securely, and is therefore disabled by default.
N: See apt-secure(8) manpage for repository creation and user configuration details.
W: The repository 'https://nito.tv/repo ./ Release' does not have a Release file.
N: Updating from such a repository can't be done securely, and is therefore disabled by default.
N: See apt-secure(8) manpage for repository creation and user configuration details.
W: Invalid 'Date' entry in Release file /var/lib/apt/lists/zenzeq.github.io_tv_._Release
E: Handler silently failed
Alright there is nothing I can do about that.
@ionic copper Thanks for your help though. Much appreciated .
If someone has nControl deb file for me, please hit me up. I would also buy it but I'm unable to download it through NitoTV.
that would be piracy
Is there a legal way to obtain it?
jesus fucking christ tvos 17 is annoying as fuck
i got recoveryos from tvos 17 to boot
waving my phone around it doesn't seem to trigger the restore popup though
and i can't currently test what it's showing on screen
i'll try it when i get home
the amount of patching i had to do to fix arbitrary problems is insane
the kernel won't even boot as is without patching it
tvos 13.4.8 was flowers compared to this
also i couldn't fix the ota issue
i'll try one more thing
if it won't work then we may need someone with apple tv 4k on tv 13.4.8 to make a dump of /dev/disk0 and send it to me
i've got tvos 14.6 if ya need it
hmm
with blackbird, we might be able to utilize it
though 13.4.8 will still be more convenient
i think that thing is just buggy the way it is, same as airplay/initial setup etc. not responding sometimes
but it's always signed
i'd try rebooting phone or disable/enable bluetooth/wifi
tell you what – the reason why updates don't work in my opinion has something to do with apfs snapshots
which is why i'll be trying to install os where the file system is hfs
if there's anything i can help with, let me know. I have an ATV4K 1st gen on 14.6.
thank you
I think that only works on newer phones
Hence probably why checkra1n took a hell of a long time to update
I think iPhone 13 mini is new enough
Either way, I must wait before I can continue my experiments
My DCSD is seemingly broken so I ordered a new one, as having to constantly swap between it and KongSWD is annoying af (dcsd i got now doesn't work with any 32-bit lightning devices or my Apple TV 4K)
That, plus my iPod touch 6 doesn't activate due to broken SysCfg, so I ordered myself a working one. I will use to figure out why OTA updates don't work
Ok, so I figured out how to fix OTA updates
I need a legit dump of 13.4.8...
And Jonathan Levin explicitly said he's not going to work on the tool anymore
Guess I'll go ask for volunteers on r/jailbreak?
I don't think anyone's on 13.4.8 since app compatibility nags about being on the latest..
And why do you think I'm fixing the OTA🤦♂️
13.4.8 for HD won't help?
No.
I wonder why if they're the same arch..
Yes.
I mean, I wonder why the HD dump matters
I need the 4K one, not HD
But why does it matter if they're both the same arch?
???
Uhm
Apple TV HD has its assets in 1080p
Apple TV 4K has its ones in, well, 4K
Different files
CPU arch has nothing to do with it
I'll try recovering the files manually by examining the payload file the tool can't extract in a hex editor
It's too bad you can't just call the 13 OTA then intercept the connection to the file and download it from there
ahsdfiuh
i got ota's kind of working
but almost immediately it reboots back into tvos 13.4.8
i need someone to test this for me
thing is, my apple tv 4k has problems with "fdr seal" data
not sure if it's causing ota not to work there
regardless, i'm taking a break
until my new dcsd cable arrives
homepod shell? lol
Just use your gaster version and restore via idevicerestore?, got my DCSD cable connected, do I have to pass an arg to output anything you want while restoring?
Looks like you need a specific version of idevicerestore, latest does not work
@analog elk Good shit! Well done
Will update progress of the OTA
Could only get it to sucessfully restore with idevicerestore 1.0.0-git-cc9c68e
The OTA booted to the install step, progressed… rebooted and ran a bit more and then nuked it and rebooted back into 13.4.8
is the latest os jailbroken?
is there any jailbreak on the newest appletv 4k ?
no (on Apple TV’s) and no
Can't we just jailbreak and patch the OS via using applyota.sh?
We could use checkra1n, apply the patches, wipe then install OTA upgrade as normal?
You'll have no choice but to use this script forever when you want to update
Stock OTA's basically forever become broken unless the FDR issue is solved
As you created a ipsw for tvOS 13.4.8 couldn’t the same be done for 17 as it is signed
Trigger the new recovery mode via iPhone to fully restore it freshly and allow it to continue its life
This could apply to any signed version >= 17
Since the new recovery tool only works on that version and newer
I’ll test with 17 OTA with the patcher later
apple tv 4k's kernel doesn't like being booted from dfu
you need to apply a few patches to make it work
that, plus the strange behavour where no-effeceable-storage patch needs to present during restore, but be absent while tvos is actually booting (aka load the original devicetree), since otherwise, you'll get a sep panic during boot (tvos 17's kernel will also scream at you if you try the same patch with it)
this is stupid in every way imaginable
as for tvos 17 recovery thingy, i wanna use the blackbird exploit to make a single ipsw that can be restored and booted without fuss and muss, since otherwise i'll have to keep making updated versions to work with the latest signed tvos
Are you looking to releasing the information on how you created the 13.4.8 ipsw and patched it all out? I would’ve looked towards creating some automated tool to patch and produce firmware files for signed versions
Eh, maybe
I’ll be on the lookout 🫡
@analog elk 🤝 OTA’d from 13.4.8
Time to test it all again
Since I done two things different this time round when ota’n
Yeah second test confirmed it, you can’t do it directly after restoring
Trying now ota from 17.0 to 17.1
To confirm ota works without the workaround
Yep updated no issues after to 17.1 from 17.0 from 13.4.8
teach me your black magic
You can do it one of two ways
Method 1: You can either boot into recovery mode via booting up, waiting for OS to finish loading and plugging out and it in again, repeating this 6 times will boot into recovery
Allowing you to wipe the device and start again
Method 2: Erase all settings and content from settings menu
Both work, tried both ways
The last method is what I used for 13.4.8->17.0->17.1
First method i only tried from 13.4.8->17.0
i couldn't fix the core of the ota issue
at first i thought simply removing content-protect instead of replacing it with no-effaceable-storage would do the trick, and although tvOS restored with no issues, OTA crashes soon after boot regardless
i might just release it as is since it technically works
it's not such a big deal having to erase all settings and content
it didn't work on my end...
either i did something wrong, or missing fdr data has come to hunt me again
Can you please verify?
https://drive.google.com/file/d/1JgexqTVslWOnx8rapW54ZkSrHv2zgrS5/view?usp=share_link
- Try updating right away without erasing all content and settings. I just wanna know if it deleting content-protect fixed it.
- If not, then do what you did
Is this a different build?
Okay will report back soon
There's one file changed, I can send it ehre
hold on
Also, just in case...
If 13.4.8 installs successfully, I'll advice you to backup the contents of /System/Library/Caches/com.apple.FactoryData through checkra1n first
If my theory is correct, then losing this data means your TV4K will not be able to update correctly anymore
Usually this info is fetched during IPSW restore, but either my TV4K does not have a magical seal of approval on Apple's servers, or they prohibits you from fetching this data ever again for Apple TV's
In normal circumstances, iOS just copies the folder over during restore, but since my Apple TV 4K was a guinea pig, there were tons of failed restores, and the data was lost
And Apple's FDR servers refuse to regenerate it
I've been trying to reverse engineer the protocol to hopefully try and fetch them and then place them back on the file system
but so far it's been unsuccessful
Yeah the restore went fine
trying to test this but the build of idevicerestore you recommended is looking for the manifest at Firmware/all_flash/all_flash.j105aap.production/manifest
gaster pwn
gaster reset
idevicerestore -e AppleTV6,2_13.4.8_17M61_Restore.ipsw
if you pass -e pass -y
skips asking to enter YES
tbh i do not even do gaster reset
that's cuz you got the earlier build that did it automatically
however, i removed it
resetting breaks a lot of things
which means it needs to be done manually now
cool, it is working
/System/Library/Caches/com.apple.FactoryData
This file/path does not exist
drwxr-xr-x 3 root wheel 96 Sep 28 01:02 com.apple.dyld/
drwxr-xr-x 3 root wheel 96 Sep 28 01:03 com.apple.kernelcaches/
drwxr-xr-x 4 root wheel 128 Sep 24 14:43 com.apple.xpc/
drwxr-xr-x 4 root wheel 128 Sep 24 14:43 com.apple.xpc.launchd/
/var/hardware?
empty
run mount
/dev/md0 on / (hfs, local, nosuid, read-only)
devfs on /dev (devfs, local, nosuid, nobrowse)
/dev/disk0s1s1 on / (apfs, local, nosuid, union, journaled, noatime)
devfs on /dev (devfs, local, nosuid)
/dev/disk3 on /binpack/lib (hfs, local, nosuid, read-only, union)
/dev/disk0s1s3 on /private/xarts (apfs, local, nodev, nosuid, journaled, noatime, nobrowse)
/dev/disk0s1s2 on /private/var (apfs, local, nodev, nosuid, journaled, noatime)
/dev/disk0s1s4 on /private/var/MobileSoftwareUpdate (apfs, local, nodev, nosuid, journaled, noatime, nobrowse)
/dev/disk4 on /binpack (hfs, local, nosuid, read-only, union)
/dev/disk5 on /private/var/binpack (hfs, local, nosuid, read-only)
hum... it's missing
Let me remove checkra1n and see if ota works for me
okey
a clean install might better though
who knows what apfs fuckery checkra1n could've done to 13.4.8
fingers crossed
aaaaaand
drum rolls...
it's going a bit further than usual...
still no reboot
wait, is it actually gonna work now?
bruh
worked
noice
well, it's both good and bad news
🫡
since i have no idea why you need to reset first
but whatever
i'm releasing it, already got reddit text post in notes written out
They might take it down as you'[re linking to and IPSW not from apple
redistributing copyrighted stuff
Well, there's one way to find out
or maybe link to the discord instead of the ipsw
it will probably even be taken down by mods
YOLO
Testing out the reset and update feature now 😄
works for me
Good shit, bet Apple didn’t think you could do it 🤝
thanks everyone
Yeah reset and update doesn’t work, so the other methods still do
in my spare time, i'll be trying to fix the updates thingy
in the meantime, i'll be taking a break
spent 2 weeks getting this mf to work
you've made a lot of repair shops happy I bet
Somehow I ota to 16.6😂
From 13.4.8 it goes to 16.6
If beta updates enabled
But can go to 17.1 if you upgrade normally from 13.4.8->17.0
Then enable beta updates
would be nice if someone pinned this news for everyone
@analog elk nvram oblit-inprogress=5 sync reboot
irecovery -s
setenv oblit-inprogress 5 sync reboot
can we not run this as part of an automated restore tool after we restore
Making it easier for end user
I will test it out
then again would require to patch that in hmm
should be possible to make restored_external run a custom binary that sets these variables in nvram
perhaps we could make a wrapper for /sbin/reboot that runs nvram first, and then calls the original binary
I'm going to guess that Apple is now thinking about pulling the OTAs off their server and making them private
Where they can only be accessed via Apple TV authentication
Problem with that plan is, you can intercept the OTA via proxy
This would be true had an official ipsw existed prior. I don't believe copyright infringement bestows on hacked up/modified firmware files from scratch (especially from extraction tools) to be considered an offence in any way. Just as long as it's not sold
One prime example: corellium
Given they've emulated the real ipsw to virtual devices, it's still not considered copyright
RIP
@analog elk if you've documented the steps I could put together a tool to fetch the components and build the ipsw this weekend. would give us the option of using the latest firmware directly too
if you just like make a script for users to generate the ipsw it wouldn't get removed
similar thing happened with ios 14.8.1
we need to write our own pbzx decompressor, as one written by jonathan levin is sort of broken
i had to manually go through the remaining payload files in a hex editor and extract missing files that way
plus we can only automate the process of creating the RootFS dmg, not the whole ipsw
think i'll do what ppl did back then and create pwnage bundle for 13.4.8 that has bsdiff'ed files to patch and nothing else
alongside with it i'll include a rootfs maker tool which i'll start working on now
but in the meaaantime...
https://drive.google.com/file/d/1JgexqTVslWOnx8rapW54ZkSrHv2zgrS5/view?usp=sharing
gee, mods on reddit really aren't liking this one
somebody left a comment asking for a link since the post got nuked, but it got deleted too in less than an hour
alternatively, can i just upload the ipsw to my site and link that instead of the file?
because it's piracy
well, whatever
I know, but still
i'm writing a builder script
I also figured out partially how you made it
DMCA(TM) friendly
I used ota2tar to extract the OTA payload files. Give that a try
unfortunately, it produces broken results
😭
wait what this exists
has anyone managed to get icloud login working on older apple TVs? seems apple changed something at an API level and I can't see login to icloud for icloud photos or anything, also means that you can't activate it without a device running macos to activate it through apple configurator 2 </3
also anyway to jailbreak apple tv 3rd gen (a1469) on linux? Really don't want to get macos installed on this laptop again
not currently, also is device activation broken or just icloud services?
activation and icloud services both won’t work, you can get around the activation by activating in apple configurator tho
interesting, will have to see for myself
whats this
A code
for?
a tweak
Big spartan update soon! Just need to make sure everything works
Hi i got a tv 4k 1st gen what better to get this breakout or a goldeneye cable? https://gizmite.com/shop/apple-tv-4k-hacks/apple-tv-advanced-breakout-cable/
depends on how good your soldering skills are
yeah i can solder well just wondering whats better
also do you know how long those advanced adapters take it says they are on backroder and the chepaer version is out of stock also
takes a few months or so
it'd be better to buy the cables if you don't want to have a frankenstein-looking apple tv
oh okay ill get the cables then lol, i wanna downgrade asap incase they decide to stop signing 13
they won't.
downgrading is the dumbest idea unless you're in a wreck
there is but app compatibility is limited
yeah i dont care too much
downgrading the 4k is only essential if you're bricked
the only apple tv worth downgrading for fun is the HD
whats the latest jailbreakable tvos version?
i assume up to 14?
or does palera1n support it



This message is for the purpose of XP farming. It is immune to any repercussions and/or reprimands by any: Mods, Admins, Owners, Bloo.py, Bloo dot ts, Bloo.js, Bloo.net, Gir.py. Please ignore this message.This message is for the purpose of XP farming. It is immune to any repercussions and/or reprimands by any: Mods, Admins, Owners, Bloo.py, Bloo dot ts, Bloo.js, Bloo.net, Gir.py. Please ignore this message.
this message is only for xp farming so please ignore thank you
this msegegdste
nexus?
how's progress with the tvOS ota builder?
Wait? I thought downgrading the 4K wasn’t possible?
It wasn't until recently
Oh nice! I might downgrade mine then, updated a while ago so the kids could use Disney+ lol
@ionic copper
How is downgrading possible on ATV 4k when it's impossible on iOS?
Because the Apple TV 4K doesn't have SSV nor cryptex
also 13.4.8 is signed
that would be a terrible idea
Downgrading the 4K is only key if one is bootlooped/bricked and this would come as an emergency recoverable option instead of turning it in to Apple for a newer (non-checkm8) device
As great as this feature is for downgrading, not only do you have app compatibility nagging at you, but also you're missing out on newer features
@ionic copper
Agree, I was on 13.5 until recently and jumped to 16.5. App compatibility was a no go for me especially my paid Sports apps which required 14 as a minimum. I got pinged last night that Linus Henze was scooped up by Apple and now a 16.x jailbreak is unlikely. Does that affect ATV as well?
not at all, ATV is jailbroken via checkra1n already
The only takeaway from linus henze is extra IQ points added to Apple
I'm referring to the 4k. I dont bother with the HD anymore
which sucks but there's other clever devs out there and probably way more in the works.. so we're not SOL
As am I.
Damn! Well hopefully palera1n supports atv soon, or checkra1n gets updated
I can guarantee you that if/when palera1n comes to Apple TV that the bootstrap will not work nor will nitoTV natively
checkra1n is updated, it's just not released
I doubt it will ever be released 😫
It will, the dev is just insanely busy
how do i get blackb0x to work
it says to plug atv into tv
but then its on recovery screen
Try restoring via iTunes
i managed to get it working after several restores/attempts
you gotta pull the usb lead when blackb0x says it waiting for the tv to reboot
otherwise it goes to recovery
sucks the kodi is so old though lol my apple tv 1 has newer
I'd get an Apple TV HD
Which generation?
1st
At least you have the ability to restore if you bootloop
What is tvos?
apple tv
I have the Apple TV 3.1 running tvOS 8.4.4, is there any jailbreak for this for windows or linux?
apple tv 3.1? model number?
the model number starts with an A
I dont see it here in imazing
just look on the bottom
A1427
That one?
you can untether it
Oh
Ok
Can you send me the link to it or something?
Because all I keep finding are forms or Pangu8 viruses
it requires a mac
does a VM work?
it might
okay
Can you tell me what I need to do or send me the link?
yeah I know but its all I have
Hi everyone, I’m totally new in the tvOS Jailbreak and I’m looking for informations about what is it possible to do today, what model can be jailbreak and what tvOs, what are the best tweak on tvOS when they are jailbreak and if one day my A2169 (3rd generation 4k) tvOS 17.0 has a chance to be jailbreak 😄
Where could I find all those informations? 🙂🙏
No chance of a jailbreak. Sell it and get an HD
Also, A2169 is 2nd gen 4K
Thanks so much for your informations 🙂
np
ATV4 if you want to easily pwn shit
ATV4K_1stGen if you can get those cables needed
Ios 16.1.1 jailbreak?
hello, i was wondering as to how this would be possible to do on my ATV4
im on 13.4.8 and yesterday i did a jb using checkra1n/NitoTV but the thing is, when i unplug the power nitotv desnt seem to run again
i want to downgrade so i can install a more persistent jb
also i wanted to know if greeng0blin needs to be sideloaded from my computer every time i rebooted my atv?
Depends which HD product you have. Did it come in a white box? if so, it cannot be downgraded to 10.2.2
This is normal. Because checkra1n is a semi-tethered jailbreak, the jailbreak and it's features including nitoTV will work again once checkra1n is rerun. This is required after every reboot/shutdown
The only way this is possible is if you have blobs saved for 13.4.5. If you do, you could downgrade it and run unc0verTV but it will not persist after rebooting. What you're looking for is an untethered jailbreaks which hasn't existed since tvOS 9
Greeng0blin has been since discontinued since backr00m exists. This is for 10.2.2 but may not work if your HD unit arrived in a white box
@ionic copper i tried downgrading to 10.2.2 using itunes but no luck.. now i downloaded the shsh blobs for 10.2.2 and im trying to get futurerestore to work on my computer
one question though
do i need to install this from nitotv https://github.com/Halo-Michael/Generator-Auto-Setter
Contribute to Halo-Michael/Generator-Auto-Setter development by creating an account on GitHub.
or i can get by just fine using this command nvram com.apple.System.boot-nonce=(yournonce) ?
"unable to place device in recovery mode"
just when i thought it would finally work 😦
What HD model is it? Does the Siri Remote have a white circle on it?
You don't need to use this if it's signed.
it came without im using an arduino thing to control it 🙂
what's the model number on the apple tv?
a1625
is that the reason futurerestore couldnt restore it?
do i have to wait until it gets unsigned?
I believe your apple tv is this
so?
which means it cann't be downgraded even if it's signed
because the SEP is incompatible
dang where did you get this info btw
Apple reintroduced the Apple TV HD to combat downgrading.
it will work with 13.4.8 which is downgradable and jailbreakable
but checkra1n and a computer is required
but im looking to install retroarch on it and sell it
you can do that
sell*
but if you're looking to sell it as a 'jailbroken' device, then you won't get very much for it
so unless theres a way to sign retroarch forever for free
there isn't.
nothing's forever unless you're on tvOS 14 - 15.4.1
how? link
you need blobs, but impossible because they're unsigned
all you can do is buy a HD apple tv and hope it comes on those versions or in-between
just tell me what i would be looking for here, im curious
I already told you.
Also your Apple TV's value will decrease because you don't have the proper remote for it anyways
ok supposedly i got my hands on one that matches these prerequisites. What method would i have to sign the apps with in order for them to remain indefinitely
dude im only selling it for 20 dollars lol
cause i got it for free
no-ones going to pay 20 bucks for it without the remote that costs 80 bucks
economically, that deal is worthless
yeah well into the pile of idevices it goes then

you havent answered my question yet
you would need a mac for this
perhaps, but this talk is pointless because you have neither
best you can do with it is restore it on 13.4.8 then sell it as a working device
you'll get some kind of money for it
futurerestore not required, just itunes
thank you kindly for all the info
What is tvos jailbreak
a jailbreak for Apple TV's that run tvOS
You must be new here
I wouldn't say new; uninformed
ironically, they've been here longer than you
Im so close to getting spartan RC4 out but I'm getting an index out of range error randomly
I dont know why, Xcode error reporting doesn't know either
What is spartan?
Filza for Apple TV
File manager for tvOS 13+
It was originally just a test to see if the palera1n kpf worked on tvOS but now it's actually quite good
*Santander
Ah nice
what’s the latest version of tvos you can jailbreak
14.7
shit rip
Technically it's 16.6 but it's not out yet
@uneven wraith saw in the spartan release notes that symlinking support was added in?
Yes, it's fully supported
I was having problems with a FileManager api but I was just using it wrong
So now it reads the destination of a symlink and sets the current directory to that
How do you create a link?
Click the file with a plus at the top
That should work
If it doesn't let me know
None of the top row works except for select
Are you on tvOS 14?
Yup forgot to mention that.
Ok that is a bug that I am aware of but have no way to fix
I don't have a tv on 14 so I can't test for it
The top bar works for me on 15
I think I remember you mentioning that issue now my bad
I want to fix it but I don't know what the issue is
Currently I'm being confused at unclear error reporting in Xcode that is preventing me from pushing a fixed hex editor
Hmm im sure a solution will come up. Hopefully someone has an idea
what does it mean
it throws the error on this
so i have no idea what's out of range
I FIXED IT
It was caused by a List updating too slow, so the swiftUI view would access an out of range element before the number of elements in the List would update to the new length
by switching to a manual range, it's fixed
that is the stupidest
thing
ok new build should be up soon
Mainly for attention. I bet it's the type that gives root access but has zero tweak injection
i mean it's not like many people seem to care
however i imagine it sucks for everyone who does
hi
My Apple TV isnt showing up on pair devices can someone help me
what apple tv is it?
Apple TV 4k
Its a model A2843 running tvos 16.6
Paired devices via Apple configurator, im trying to sideload Streamer app on it
But my Mac is on a VM
piracy 
Isnt that the whole point of Appletv sideloading😅😅
no
Im kidding
no you're not
again, no you're not 
I have But its shit

What can i do then
piracy apps are going to be worse
Wdym
well they don't have great service and they'll track you via isp
they also might not have ted lasso

led tasso
How can i get any app on my Apple TV then
sideloadly? idk
Forget about streaming
there's only 2 ways
Thats what i need help with
well, 3
Whats the 2nd and 3de
one is wireless via pairing
one is wired using goldeneye
and the last is via appstore
goldeneye?
yes
oh it's a chinesium cable?
I dont have that
it's usb directly via ethernet port
My Apple TV wont show up on pairing devices on my VM
so instead of relying on crap internet and xcode delimmas.. I use the cable
it does if you go to Settings - General - Devices and remote
i thought they had lightning ports
I have mac on a VM, it dosent show 😦
they do, but it's not the same as ios ports
it will show, you just go to pair a remote and it'll prompt to insert the password
you might need to ensure your internet is connected properly
(on the vm)
Thats what im trynna figure out, should i have on NAT or bridged network for it to work?
bridged should be it
but the thing is.. after 7 days, you gotta do this again
it would probably be better for you to get your uuid registered
and have your apps signed ota
no need for a computer
Accidentally went into the bios, you think this is correct?
google is your friend