#tvos-jailbreaks
1 messages · Page 20 of 1
why not? its on tvos 14.4
Hello guys
I want to buy an Apple TV for sideloading apps and watching free movies etc but I was wondering, which generation AppleTV do I need to buy?
Because it's for iOS
How about stop pirating
What?
"Watching free movies" = piracy
Aint no way you telling me to not pirate in a jailbreak communirt
It's literally against the rules
Call it sideloading then
I want to sideload apps on a AppleTV
Which one should I buy?
We're not helping you pirate
odysseyn1x is just live bootable checkra1n
odysseyra1n is what doesn't work
indeed but clueless folks try to install the bootstrap which'll mess up their devices
I was just trying to follow the ios.cfw guide
Hey guys I am very new to jailbreaking apple devices, does palera1n work on my apple tv a1625 on tvos 18.3? I know 18.3 is very recent but I accidentally updated it while setting it up
A1625 - HD yes
What’s the latest version im able to jailbreak?
Looks like they left auto updates on 🥲
But it’s an old Apple TV.. if that matters
I actually have this… dope
You mind showing me the steps you used for this?
18.2.1 afaik, maybe 18.3
But it's iffy
Been tryna look for a guide. Came across something saying o can’t use usb c only mac
What Apple TV is it?
A1625 only has Ethernet and usb c
Yeah, you’ll need an adapter
For the Mac
My mac only has usb c ports
Kinda confused lol
I would need to get an adapter to convert to usb-a then back to c? Lol
Indeed why you need an adapter
Would a simple dongle work? Or I need a specific one?
I have one with a few USB ports on it
Maybe?
@ionic copper I messaged you if you have time when you get online I would appreciate it if you could help me thanks bro
With what
I purchased a bricked Apple TV 4K just to get familiar with restoring them I explained the process I go through and the errors I get I followed your guide down everything works but restoring. I tried both methods. There is more information in your DM.
are you trying to restore to 18?
Yep made a 18.3 Ipsw also did 13.4.8
Here is what I have done
Hey so I purchased a Apple TV 4K bricked just to see if I could unbrick it and well I get nothing but errors, first off the Apple TV 4K is stuck in dfu mode I tried the following
Restore using idevicerestore in pwned mode with gaster with 13.4.8 Ipsw I got off you and I get this error
ERROR: Device did not reconnect in DFU or recovery mode. Possibly invalid iBSS. Reset device and try again.
ERROR: Unable to place device into recovery mode from DFU mode
Then I tried the script to make a Ipsw I made 18.3 Ipsw for the 4K tried to restore it using your guide but I get this error with futurerestore
Verified APTicket to be valid for this restore
Variant: Customer Erase Install (IPSW)
This restore will erase all device data.
Device found in DFU Mode.
Getting firmware keys for: j105aap
Cleaning up...
[exception]:
what=getting keys failed with error: 30015503 (assure failed). Are keys publicly available?
code=45088836
line=688
file=/Users/runner/work/futurerestore/futurerestore/src/futurerestore.cpp
commit count=333
commit sha =85b5505fdcf3d5cd1349cf290e6a856339ad6831
Done: restoring failed!
I was just hoping you had a method to fix being stuck in dfu mode
you can't get to 18 on its own because futurerestore isn't updated
your only hope is to restore to 13.4.8
then OTA to 18
make sure you use the right 13.4.8 ipsw. Also, sometimes the ibss/ibec errors are from odd timings or bad USB connections. Try other ports.
but all-in-all the ipsw is confirmed working by muliple sources
it's also not stuck in DFU mode.. I fear the reason for the brick is possibly bad NAND (which is what I have) and this can be verified if/when you restore with the idevicerestore version I gave you up until it says Updating NAND
But time will tell when you do commence the restore
If you're stuck on the restore screen, you can potentially get it out of this mode by using futurerestore --exit-recovery
It will not go into recovery mode, unfortunately
In any case, you have the ipsw, I would try multiple machines.. this will also work on a hackintosh (if it's a PC) but not a virtual machine
I’m using a hackintosh atm
then that's fine
if you use gaster pwn and gaster reset then idevicerestore should immediately pick up the apple tv upon connection and try to restore via the ipsw
I'm not sure the condition of this unit that you purchased.. there could be more than meets the eye, maybe someone dropped/submerged it?
but usually bricks online happen due to bad NAND chips or a broken logic board
Didn’t seem like it had any water damage you may be right however, I can’t even get it to write to the NAND the IPSW I received gives me this error after doing pwn then rest… I tried to make my own but 13.4.8 is a pain, if I can’t just get past this iBBS crap 🙃
I don't know why you're making your own 13.4.8 when you have a fully confirmed working one...
Your right I didn’t know if it got corrupted during the download, so I was just checking that out
what's the sha256 on that ipsw?
Hold up
shasum -a 256 /path/to/13.4.8.ipsw
8161df7807d94ac93afe62f5a50f2e96ef785fe7b884760acc3536fe2ac94cd0
it's not corrupted.
So it’s probably a hardware related since it’s getting stuck on iBSS
either that or logic board problem
or.. dependancy error
either way, the seller made their profit off you 😛
I’ve been trying to jailbreak my Apple TV 4 on 18.2 with palera1n for a few days and I just keep failing. I’ve tried it the way it says on the palera1n website and it boots up normal. I’ve also tried it the way I read on Reddit and after the second palera1n -cf, it boots up normal. Any help?
You only need to do the c once
After that, it's just -f
All right @ionic copper I tried to restore my other working Apple TV 4K because it needed to be reset because it would only boot in jailbreak mode but when running gaster pwn then gaster rest then I ran idevicerestore -y -e “IPSW”
Then it gives me a error
Personalizing IMG4 component RestoreKernelCache...
Sending RestoreKernelCache (11897160 bytes)...
Waiting for device to enter restore mode...
About to restore device...
Connecting now...
Connected to http://com.apple.mobile.restored, version 15
Device ffffffffffffffffffffffffffffffff00000002 has successfully entered restore mode
Hardware Information:
BoardID: 2
ChipID: 32785
UniqueChipID: 4817407327076398
ProductionMode: true
Starting Reverse Proxy
dyld[30546]: missing symbol called
zsh: abort /Users/DXcool223/Desktop/restore/idevicerestore-gcc9c68e -y -e
This error is due to missing dependencies
You'll need libimobiledevice, libusb etc
Man I thought I installed all those okay I’ll look at it and see what I am missing
Go to the idevicerestore github. It shows you what dependencies you need. You might even need to compile the version. I have the guide as to how to compile that version
You’re fucking genius bro it worked !
Ha
Did you manage to unbrick your bricked one?
I haven’t tried it yet I about to try
Something tells me that's a dead end
Yeah bro I get an error saying unable to place the device in recovery mode it’s blocking like it’s in recovery, it’s toast definitely a motherboard issue
Blinking
@ionic copper one more question I have my blobs to 17.2 I can make a Ipsw a restore to 17.2 using your guide right ?
You should be able to. Futurerestore can update to 17.2 but to accomplish this, you need to be on 13
Okay perfect I am already on 13.4.8 😊
Hopefully the blob is valid
I had a friend do it, it should be good I have no clue on how to check besides trying future restore.
To verify is in the guide
This is the guide I am following and it really doesn’t say how to check your blob files https://www.reddit.com/r/jailbreak/comments/1f8of4b/how_to_restore_an_apple_tv_4k_first_generation/ my ECID is 111D680C78002E and here is my blob
I just did it this way and it still booted up normal. I mean I guess it’s normal, there’s no new apps to indicate it’s been jailbroken. I did -cf, then dfu mode, the ctr c, then -f. It took it about ten minutes and then booted up normal
Palera1n is still WIP
I wouldn't jailbreak with it just yet
Not until the bugs are fixed
I'll verify it in a bit
10-4
🚓
I used palera1n last night to jailbreak an apple tv 4 on 18.2
this is what worked for me:
grab this: https://cdn.nickchan.lol/palera1n/artifacts/c-rewrite/main/500/binaries/palera1n-macos-universal
put in dfu (only do this once)
./palera1n-macos-universal -cf
<Info>: Booting PongoOS… <- ctrl + c when it hits this
./palera1n-macos-universal -cf
WAIT UNTIL IT RESTARTS INTO RECOVERY MODE (10 MINS)
to boot:
put in dfu (only do this once)
./palera1n-macos-universal -f
<Info>: Booting PongoOS… <- ctrl + c when it hits this
./palera1n-macos-universal -f
Imagine waiting without being told to wait.
If palera1n is this janky to jailbreak an apple tv, maybe we should make a message for the user to wait @cyan veldt
I was seeing how much of the jank I could remove last night lol
Good luck with that one. May as well rewrite the whole thing
[IMG4TOOL] IM4M is valid for the given BuildManifest for the following restore:
BuildNumber : 21K364
BuildTrain : StarlightC
DeviceClass : j105aap
FDRSupport : YES
MobileDeviceMinVersion : 1600
RestoreBehavior : Update
Variant : Customer Software Update
[IMG4TOOL] APTicket is GOOD!
[IMG4TOOL] SHSH2 contains generator 0x1111111111111111 which is GOOD for nonce in IM4M!```
@analog elk already banned 😛
I tried to go to 17.2 with -u but it said sep was not signed idk lol
this is because you need to specify 18.3 sep seeing as 17.2 is unsigned
I tried to use 18.3 im4p from OTA file but it said the same thing I’ll retry
pzb -g AssetData/boot/Firmware/all_flash/sep-firmware.j105a.RELEASE.im4p https://updates.cdn-apple.com/2025WinterFCS/patches/072-04713/CF68E382-F8BF-45BE-B926-52A5E84D1B78/com_apple_MobileAsset_SoftwareUpdate/046fda00414a59254ebfe7a551c93a7f821c1124.zip
you also might need to use 17.2RC build manifest too
Had to use 18.3 build manifest but it’s updating screen went from yellow to green setting the nonce pretty cool
Dude you’re amazing! Thanks so much for helping me now I am off that crappy firmware
Hey guys, does anyone have the same error as I do on 18.3. Everytime I try to enter DFU mode palera1n says to hold the buttons for 10 seconds then like immediately my screen turns black and I have to restart the process again
what apple tv is it?
its the a1625 so basically the 4th gen HD, just letting you know I also tried the latest beta which didn't fix the issue
use palera1n --cli -cf
then palera1n --cli -c
That was the command I did try but it didn't work. I added the Vv flag to the command so as you can see my device keeps getting disconnected at the 8 second mark when trying to get into dfu
best bet is to get off 18.3 😛
because jailbreaking newer versions of so iffy
oh wait.. 2 questions.. are you using a mac?
fair, last week I was actually able to only jailbreak 10.2.2 but none of the features worked like disabling the update pop up
yes apple silicon macbook pro
this confirms the second question
you can't use usb-c with usb-c
has to be usb-c with usb-a
wow really? Ok I will try that then I do have adapter luckily
!t usbcmoment
Hey @fossil dome, have a look at this!
since the post says usb-a to lightning disregard that when it's usb-c to usb-a in this case
so another question with the cable does it matter which end gets the "usb a" part?
Amazon/eBay stocks rising since apple made usb-c only ports
as long as it's in the adapter for the usb-c port
because the port on apple silicon macs alone aren't all that great for jailbreaking
Ok so I tried the cable but it didn't seem to fix anything, its always struggles at the 8 second mark for some reason
I have this remote I haven't seen anything regarding 3rd party remotes if they are a problem
it can't be a third party remote for dfu
it has to be an original apple remote
does it have to have came in with the apple tv? or can I just buy the one associated with 4th gen?
Apples constructed the remote with SEP to align with the device via bluetooth, using any other remote would be useless for DFU
it can be literally any apple tv remote from the second gen to the newest
oh bet man thank god, was gonna say those 4th gen ones are going for $30+ on ebay, didn't wanna spend that
So I am gonna prob buy a 2nd gen remote and try it, will keep you up to date. Thanks for the help
whatever zenzeq saying about SEP is nonsense for DFU because there's no sepfw when dfu mode is being checked
can I get a source? I mean I already bought a 2nd gen official remote for $10, just waiting for delivery. So I guess if that doesn’t work than your right
I never said there was SEP being used for DFU
I was simply stating that SEP is what's used to pair the remote so you may as well get the original if you're going to do anything of that sort
Also since palera1n is a tethered jailbreak, when do I have to rejailbreak it? Like ik for the ps4 I would have to if I powered it off, is it the same with apple tv?
only when rebooted/powered off
The worse part you'll have to worry about is in the event certain tweaks/apps/features don't play nice and suddenly kernel panic the device
The ps4 jailbreak is so much easier than palera1n imho
especially for the apple tv
alr bet I want to leave it on sleep when I am done using it
just make sure updates are turned off
that makes sense, btw is ssh easy to setup? I barely hear ppl talking about that on newer versions?
interesting, the latest one for ps4 you essentially need a esp32 to jb it, I got one from ali and its seamless
ssh is the same for any device. The only difference is you can no longer log in via root, it must be mobile then once inside, you can use sudo to launch root permissions
I'm still on 7.02 so webkit >>
ok and would I use palera1n to set that up? because I highly doubt apple tv has a terminal app
so lucky lmao, 11 is slowly getting better especially rest mode
once jailbroken, palera1n will ask you to change your password, this can be anything (I just use alpine) and from there, everything sets its self up
bet thats pretty cool, also is there documentation on what other ports are open? Would be cool to play around with it as a test home server
port 22 and 44 I believe?
44 I think is primarily for tunneling
but this can also be changed.. I wouldn't change it though unless you're working with an HD
thats cool, so just curious how are the CLI tools? Like ik a-shell on iOS is good but somewhat constrained with the dash shell being strictly POSIX complaint only. Is bash on aTV available?
does anyone know the folder location of the downloaded Apple TV screensavers? tvOS states that each video is up to 950 MB. I already set the Download New Video option to Never, but some videos already downloaded before I recently changed the option. I counted 50+ videos downloaded, which I counted manually by swiping through all the screensavers while they were running. I want to delete them to recover space and there is no way to do it without resetting. I have ATV 4 HD on tvOS 17.4 JB with palera1n
Deleting the videos won't recover any space. You'll get maybe 200mbs tops
Is this thread not true?: https://www.reddit.com/r/appletv/comments/1exagkk/how_is_that_enough_to_fill_up_a_32_gb_apple_tv/
They say 950mbs based on the resolution. So for example if you're on 4K, they'll take up space
I also have a Apple TV 4K gen 1 on 16.6. I only have 32 GB on that and I want to recover space through the file browser using misaka. I only have 1 GB free space on that ATV
And what this thread fails to realize is that there's not just app space present but also app data which isn't shown in the storage management.. Much like iOS telling you you're out of space but it's all in different folders for cache
How do you know you only have 1 GB free?
TV info app
That's just showing you one partition
Do you know the folder location anyway?
It's in var
found the exact folder: /var/mobile/Library/Caches/com.apple.idleassetsd/Customer/2KAVC
about 16 GB of videos on an Apple TV 4 HD. Largest video is about 700 MB.
Depending on ATV model and resolution used, the folder might be different. There are other folders (e.g. 4KHDR, 4KSDR, etc.) in the parent: /var/mobile/Library/Caches/com.apple.idleassetsd/Customer
Enjoy the black screen during idle
Although, you could just copy the videos off, recompress them to a less higher resolution
Turn 16gbs to 500 mb
I was just going to use the photography from Apple option for screensavers after deleting the videos
I think what'll happen is the apple tv will redownload them
The download option is only applicable to the "Aerial" type screensavers, which are the videos
I can set screensaver type to Aerial, set download option to never, delete videos, then set screensaver type to photography. I just want the space back. If I fuck up i have blobs for 17.3 anyway
I'm just gonna test the method first on the ATV4 HD, then if it works without error, i'll delete the videos off the 4K gen1
Okay tested a bit. Deleted all videos. After setting screensaver type to Aerial, there's one video that still plays which is a downtown LA video. I tried to cycle through to see if the other videos I deleted would play, and it only loops the LA video. So Aerial screensaver type could still be used as a screensaver, albeit only one video that would play. The folder is empty so the LA video is in another location, but I'm okay with the result.
Saved 10 GB on a 4K gen 1 32 GB on tvOS 16.6 and 16 GB on a HD 64 GB on tvOS 17.4
I'm still trying to figure out why anyone would need the space for besides roms and emulators
Yes I wanted to use the tvos appstore version of retroarch. Unforunately tvOS deletes the roms when space is low. I just had it happen on a 32 GB ATV4 G1 with 1 GB free. My 64 GB ATV4 HD with 30 GB free and my 128 GB ATV4 G3 with 100 GB free does not have this problem. I'm hoping this will solve the issue. https://docs.libretro.com/guides/install-ios/#tvos
This is the official RetroArch documentation for users and developers. Information from sources outside of this website may be dated or incorrect.
Move your roms outside of the RA directory
Have mine in mobile/Documents, as well as all the system files
Folks without a jailbreak: how?
Seems @bitter gull is jailbroken no?
Otherwise obviously have to reupload them if they were deleted. Theres this as well https://gist.github.com/warmenhoven/1f9662be7390a2f19063bb21c80c794c
Using Your Own Web Server For ROMs and BIOS Files For RetroArch - RetroArch Assets.md
I'm using Retroarch on 3 Apple TVs. Only one of them is JB. I haven't encountered any issues on my Apple TVs that have a lot of free space. Plus the inclusion of iCloud as a cloud sync backend in the latest Retroarch release means that I only lost the roms when my one ATV self deleted them due to low free space. My saves and settings were restored when that ATV pulled from iCloud.
Yah cloud sync is great for that. Thought you were speaking on roms only
Which ive had the atv randomly delete all the RetroArch stuff many times in the past even with alot of free space. So moved the roms long ago as precaution. That link above could be handy in some extreme cases
and speaking of freeing up space by getting rid of the aerial files… guess i did that while ago. Darn hah
What was the total capacity and free space of the ATV when that deletion happened?
Dunno been Long time since its happened
In other retroarch news, ps2 finally “playable” on tvos
@ionic copper tysm getting the official apple tv remote got me through DFU mode, now I am confused on what else do I do since it just says booting to PongoOS
Press control c
Then redo
alr bet thx just did that also I follow the directions to remove the c flag right?
It’s literally telling you exactly what you’re telling me
😜
okay just making sure if 18.3 is different since before tvos 18 I heard you didnt need to make a fakefs
18.2 they introduced SSV and ever since then, now tvOS is worse
also just letitng yk I finally got in just took a few tries and had to turn off tv and back on to get output from tvos
I could try porting dopamine to tvOS.. then you wouldn't need palera1n for tvOS 15 - 17
15-16*
Dopamine for tvOS would only support 15.0-16.6 (excluding 16.6 for the arm64e Apple TV's)
dopamine doesn't work for 17? unless that's the semi-jailbreaks
there's no semi-untether for 17 at all
sad
the only thing close to that is TS + app injection on 17.0
Roothides bootstrap work tho 14 - 17 just no springboard injection it’s just a bootstrap but that would be dope
not as dope as dopamine /s
True
I should rename it to DopaTV
I could get Lars to help..
I got a problem I can’t quit buying Apple TVs
I have a 4K 3rd gen on 16.6 and it would be amazing to have a dopamine port !
Or i could update misaka to work with 17.0 betas for newer apple tvs
Ya that’s another option but dopamine we be better but more difficult
Would
Man that’s crazy it would be so cool if we could just run iOS apps on tvOS
ignore the ones that are as-is.. they're lost causes
said AFTER the fact that you bought more..
I got parts I think this one can be restored
I like to gamble a little
no it cant, bruh took it apart
I got parts
for all you know, you're making them profit
Technically, he cut it apart 😂
this ones especially a dead end
Ya that was a bad judgment
most people don't know that the nand can break
which is the main reason for bootloops
and those chips cannot be replaced
because they don't make them anymore
Hmm that’s interesting
Probably vga
Sound like you tried you can’t clone a working one probably not because it’s married to the motherboard maybe
I've been able to put my 4k in purple mode to get the sysconfig
but issue with that is; you need a replacement chip to copy the contents on to in order to restore successfully
I hope I can at least restore this one it took me a week to talk him down from the price it’s showing the recovery mode 🤞
only way i can think of is to buy another defective unit with a working nand and rewrite that chip but it's too much of a hassle
I don't feel like desoldering 2 nands, reprogramming one, then resoldering it with a frankenstein 4k just for the hopes it'll downgrade
when buying a fully working one works just fine to test
Well I got a working one and a broken one plus I have a shit ton of parts now 😂 like the shell and fan
I bet this ones where the dude tried to install the breakout board...
lets see restore fail on this
But why would you cut it like that, to me it looks like he didn’t know how to open it
the dudes got a television sitting on a panasonic vcr!
yeah he bruteforced it open and now the fans beaten up so that A10's going to catch fire
I got 2 broken 4K Apple TV with fans I got all the parts
regardless, I bet the logic board is toast
I hope not I guess there only one way to find out :/ I took a gamble
Actually, maybe not.. if it was totally gone, it wouldn't even show the restore screen
That’s why I purchased it lol
but something tells me you're going to run in to restore issues
Well I’ll keep you updated lol 😂
this ones got a broken nand
this one's the only chance you have to getting working
That’s a fully working Apple TV. Nothing wrong with it.
indeed
I know I wanted another one only have one 1st gen working glad I got it, cheapest, I could find them
I did happen to buy another 4k...
just for downgrading testing
thing is: the previous owners forgot to clear their info
at least I got disney+, netflix, apple tv+ for free
luckily i got 18.0 blobs off it, so no SSV
Downgrading worked great for me ! Lol same thing happened with my Apple TV but I eventually format it
also, you can save blobs.. if you give me your ecids
i have a script that saves them
Okay cool what script are you using?
one i made
You be holding out bro 😂
Not really, working on a project for it
it's easier to save manually since it's configured for my setup
Well, I hope it comes out. I would love to be able to save my blobs by myself and right now it’s a little difficult. I kinda got it working, but I have to lean on other people.
the method to saving blobs is actually in this channel
I’ll try to search for it
tsschecker -d AppleTV6,2 -e (ecid) -o -Z (Build Number) -s --save-path ~/Desktop --boardconfig J105aAP --no-baseband --build-manifest BuildManifest.plist
Thank you
This put the nonce in right the 0x11…
I’ll just test it out
@ionic copper so what’s the chance we get Palera1n more stable on 18.2 and up, I bet it will be a pain
Oh and I have one random question do you think replace Apple shitty thermal paste with Grizzly thermal pads would be a good idea keep the chips cooler
the nonce is actually after the x
eg: 0x1a2b3c4s5e6f7g
1a2b3c4s5e6f7g
no.
this isn't a gaming machine capable of running Final Fantasy so there's no point
Best you can do for performance is keep it dust free and save memory
that probably won’t work by the way
iirc ATV 4K 3rd Gen is A13(? - either way it’s some arm64e SoC) and I believe Apple TV’s still include all the same software mitigations (i.e. PPL) and the PPL Bypass (dmaFail) that Dopamine uses was patched in 16.6
realistically Dopamine for tvOS support would likely be:
- ATV HD/ATV 4K 1st Generation: 15.0-16.6
- ATV 4K 2nd/3rd Generation: 15.0-16.5
I think it A15 I might be wrong but trollstore runs great
you’re probably right but I’d have to check
The only thing I hate about this generation is they took the fan out smh it gets pretty hot while playing games
that being said, semi-jailbreak (i.e. nathanlr) would likely be possible for 16.6
following up: yes you’re correct
if tvOS had a 16.5.1 you could split the 4K 2nd and 3rd generations into their own grouping
but thankfully they didn’t
lot of work for a 60 dollar device lol
yeah, not worth it
do these still work?
Yes
some dude a couple days ago told me they don't anymore lol
and he sent me a vid explaining why
is there some tutorial for it or something ?
They don't for newer devices
Depends what device you have
And no, no blobs will work
please
still have that 17.0b3 4kgen3
i wish misaka was opensource
also i still have my 16.5 atv 4k gen3 in case dopamine port is real
and need a tester
well its my brother's now but yea he'd lend for jb testing
How would you update it then
I’d ask the dev for the project file. But I highly doubt they'll give it to me..
F
I think there's a hidden USB port on the HDMI port
It could be that Apple has constructed another Goldeneye for this
I was going to say if you wanted to compare the ports to your other apple tv's.. It should only have so many pins for audio and video
If more pins are present in the new port then I believe that's where apple flashes the firmware
What do u need me to do
I assume open a 2nd or 3rd gen 4k
Not open but take a flashlight to the ports
And see if there's a difference between the two
@ionic copper is this anything? https://www.rxddit.com/r/jailbreak/s/BWaogR6t9M
https://www.youtube.com/watch?v=zzLYTRdPKNM
This guy has an Apple TV 4K 2022 (3rd generation) stuck in recovery mode. He bought a GoldenEye cable by mistake, as it does not work on the 3rd generation.
BUT! He found some unusual metal contacts at the HDMI port!
btw the port is there on the 4kgen2, it just doesnt work with checkra1n obviously
Potentially
i think
oh wait are you taking about this right now
I can't see why you'd need more pins in the HDMI port other than usb and it would make sense since this is where the Goldeneye on the first gen was inserted
Indeed not but I'm not worried about the Ethernet port
It's the HDMI that would show a difference
ok yea, 4kgen3 has those pins on the floor of the hdmi connector
had never noticed em
And knowing apple; they'd hide extra pins on any port (even the power connector)
But are they present on the second gen?
Not that this hidden port means much in terms of jailbreaking but.. Easier for sideloading
And diagnostics
Are you able to inspect the ports closer? Make sure they have identical pins?
In the same positions..
On both floor and ceiling
The pins look slightly shorter on the gen3
What would a goldeneye cable even be useful for, if theres no public bootrom exploit rn
But anyways, yea my goldeneye works on the gen2, is picked up by itools and everything
I guess the only way to confirm is to get a oscillator and start testing points on the board..
Just yea, no checkrain. And on the 4kgen3, it doesnt work. Doesnt go in all the way, no click
Looks like ones dirtier than the other
It would click if you cut off the pins at the end of the Goldeneye /s
seems like apple tv will be the playground once ipad7 dies huh
at least, 4kgen1
Also those pins are on the 4kgen1 lol. Rip
Whatever the 4K gets, the HD gets too
i think HD wont get tvos19
That means, checkm8 might have 2 more years
I said this about 17/18
And look where we are
They did for security
But since tvOS lacks most of it..
did anything ever come out for permasigning unc0verTV. i remember reading saturnz exploit could work on it
idr
also i wonder if unc0vertv could be updated for 13.4.8
in that YT video, description reads :
💡Core issue: Apple has changed the system recovery interface from the previous generation's MicroUSB to USB-C, then to a hidden RJ45 port for recovery, and now to a hidden HDMI recovery port for the latest generation. But I couldn't find any HDMI flashing cables or methods for recovery.
No, unc0ver is the worst semi untether
You're not going to find any anytime soon unless someone leaks the cable
I think it's all speculation. There's no schematics
Yea idt its true either
Other atvs have those pins too
Sigh this just revived my desire to TS this 17.0b3 atv
So sad
It's difficult to imagine that after having these devices for so many years, I too, didn't notice the top and bottom pins of the HDMI (nor the side pins) I thought it was just the center piece
I'm also not entirely convinced that the HDMI port has a hidden USB to it and that Apple is flashing the firmwares using the same method via Apple Watches
which model supposedly has this hdmi port?
3rd gen 4k
A2843
unless it was A2737
Where’d you find out? I’ve taken a few of those apart and don’t recall seeing anything
Gonna check again
isn't that just for shielding purposes?
from cursory inspection it doesn’t look like anything special, but it’s covered in shielding (internally) which may be hiding stuff. I need to get probes on it
It seems weird that those would be present on older models with the rj45 trapdoor. The other models just have little dimples in the hdmi port
on the side, yes, which looks to be the method used to keep the cable inside the port
just talking about the floor and ceiling of the hdmi port, not sides. I think all of them have the dimples on the side
AFAIK, the dimples on the side of the goldeneye and the rj45 port serve no purpose other than keeping the cable inside too
I thought maybe it was used for DFU.. but it seems not
it does seem strange how the pins look different..
(the bottom is A2737)
(For reference about what I was talking about)
the difference is indeed strange
oh wow.. you've got an army of apple tvs
too many. I was helping with a jailbreak for them a while back
nope I have no clue about that. While working on the aforementioned jb , I went on an abrupt hiatus for a few months and have been way out of the loop since
I assume they can all be jailbroken on the latest firmware bc checkm8
was wondering about that.. what happened? (if you don't mind sharing)
Hey @analog elk did you ever update the guide for 18.2? I was watching your YouTube and saw you were in chat
I’ve been so busy bro with family I haven’t had a chance
But I’ll definitely get it out there. I mean the jailbreak still not finished, so it’s definitely going to be buggy.
All good
I was just wondering what point to do the steps in the comment
I saw you pinned a comment
speaking of which, i've got youtube with no ads I might upload to my jailbreak repo soon
Damn I was working on it right now damn bro you beat me to it 🙃
Yeah, it wasn't easy.. had to rewite the entire app
I can tell
Is it the default YouTube app
no, since it's closed source...
Ya I trying to do default with ai tools
you're asking a google product to circumvent a google product
Hold up Google doesn’t own cursor AI or the models, right
Pretty sure they own almost everything search-wise by now
Well, I guess we’ll see how it goes. I got another trick up my sleeve.
Still haven’t got it. Hopefully it gets here tomorrow.
I can see it getting lost in the mail, then someone will take it home to try it out
No, they’re pretty good around here about that. I haven’t lost a package here yet and I’ve had some pretty expensive packages.
I’ve only experienced this on Chinese apps
I’m pretty sure it’s fake tracking
If it doesn’t be lost, I get my money back, so I’m not Trippin 😂
Does
inb4 box contains android tv box
Yeah, if it was something other than an Apple TV, I would be pretty pissed eBay buyers always win. That’s why I buy from eBay hands-down, one of the best sites to buy on. However, I do not recommend selling on it.
The sad part is: folks are already buying up as-is devices in hopes they can restore them but then they complain to me when the restore method fails
as if I'm the cause of it
I tell them "no, it's not the process of restore, the device is garbage"
Yep 99% of the time it’s hardware related
I'm seeing more HDMI issues and NAND issues
one person has a major nand issue where the device boots up just fine but OTA doesn't work and downgrading to the signed 13.4.8 ipsw fails during "unmounting filesystem"
which of course is a nand fault if it can't even re-install the system
Hmm that’s so weird
I don't because a lot of people dislike me here.. even the higher-ups are itching to rack up my warn points just to kick/ban me
but thanks
But great things are coming soon. I promise
oh no, something much greater is coming
you'll see 😉
Hmm I definitely interested can’t wait anyways I gotta hop off here later ✌️
oof, got banned 😦
Awe man, you're going against the rules
Ohh shit my bad

🙃 I will need to look at all the rules I am so sorry it will not happen again
What's strange (but I'm not complaining) is apple tv doesn't have activation lock
Yeah, it’s weird there’s no iCloud lock just mdm I wonder why they did that with Apple TVs so stupid I’m not complaining neither tho lol
You'd think a digital form of media with your purchases in tact on a device with your iCloud would have such lock
Although I can see tvOS 20 having lockable user accounts
Do you really think they could actually add iCloud to an update though? Is that possible or you just talking about passwords on accounts?
If they did that they would have to unsigned 13.4.8
Of course, you're talking about the same company capable of putting iCloud on ear buds
I’m pretty sure they still use 13.4.8 on company Apple TVs and will not update but yeah I can see something like that down the road
They can't unsign it
It's required as a prerequisite to update
Same with 10.2.2 for the HD
That's required to get to 13, which then allows folks to get to 13.4.8 which then allows for 17/18 and so forth
Ohh okay well that’s good to know
I’m glad they can’t unsigned it
(Speaking in the sense of going from OTA - no computer)
They just signed the ipsws in the event that OTA doesn't work and you'd need to restore it manually
@ionic copper is there a way to sideload a deb in a Apple TV ipa I tried every method for iOS and it crashes the app every time but the debit works fine I think I need a dylib cydia substrate for tvOS
Deb stupid AutoCorrect
Anyways, if you can help me out with that would really appreciate it. It’s a Adblock tweak
Idk if ellekit would work but I can’t find the files for the tvOS version
Send the deb and I'll see if I can
I've done it before but I think things changed
Yuck tubi
😆 it’s just something I’ve been working on for a very long time I would really appreciate it. I’m trying to do other apps also.
If you figure it out, can you show me how to do it? I would really appreciate it.
I'll get on it
Did you download it already so I can remove it?
Yeah
I'll probably make a whole new ipa for it to upload that way folks can install it via jailbroken
I was going to upload it to my repo, but yeah, do whatever man but I would really appreciate if you could show me how to inject deb files for tvOS
No prob. I think the server here would neglect your repo seeing as its infamous for potential piracy imho
Whereas mine has none
Sound good bro
The only thing I have on my repo flex 3 and AppStore ++ basically but yeah, definitely upload it to your repo that would be dope
You know AppStore++ works amazingly on 17.2 no problems on tvOS
I think the big problem with making an ipa is they'll update it, then you'll have to keep remaking it
AppStore++ is already on nitoTV
Yeah, that is a problem. That’s why I made a DEB but I would love to inject it
I don’t think I have that repo 😂 I would have to check
Hold up didn’t that repo go down and you hosted it or something I don’t see that repo or AppStore ++ on your repo I talking about the new Palera1n jailbreak
Anyways please keep me updated on how you managed to inject the deb ❤️
Wow Some ppl smh
Imagine people getting mad at you for trying to help them understand 🙄
I've got so much to say but it's irrelevant
Well damn the Apple TV will not restore it always stops here
More money wasted @ionic copper
No more buying broken Apple TVs for me
Broken nand
Ggs
I was trying to save you money..
Was that the apple tv from the person who had the sus one with the tv in the picture on the restore screen?
No picture on restore screen just black I could you save my blob for 13.4.8 I want to fuck with it just for shits and giggles 1A054420E8A83A
Could you
Sure, although you don't need to save it when is signed forever but I'll still do it
I've had one other person with this same issue who refused to believe that it can't be fixed and demands the method to update it to tvOS 18.. Issue with that broken logic is if you can't get to 13 legitimately, how would you expect to update?
It’s all good bro dont worry about It just like to fuck with stuff it’s definitely probably broken I understand that
I
I got 3 of these I might try to reflow the nand chip I have nothing to loose
reflowing won't help. The chip its self is done
although I'd like to see how you're going to do that
easy-bake oven? /s
Heatgun I have tools bro I have a whole solder station
gotta cut away the underfill
Yeah, I don’t know it just might be a waste of time
Well, I guess I’ll just throw these in my dresser. I might as well just probably throw them away. I should’ve just listened to you. You were right.
I'm guessing reflowing did nothing
But yeah, definitely get back with me on the injection method. I’m really curious about injecting deb files 😊
Thanks dude I appreciate it even though it’s not gonna work 😂
broken nand for sure?
it usually is the case. Failure to unmount the filesystem corresponds with OS corruption which deals with hardware configuring issues
someone else had this same issue on an iphone, they found out it was an issue with their logic board
interesting
Im curious to hear if throwing it in the oven does anything (or however he’s gonna try to reflow)
sad part is, seeing as the device is over 5 years old; they don't make those chips anymore so your best bet is to either scrap it, sell it as-is for find another broken one and reprogram the supposedly working chip from the other broken one to the original broken one and pray it restores
reflowing has less than 1% chance of recovery seeing as the chip its self is broken and not the solder joints.. but can't hurt to try
I would for sure scrape away the underfill of the nand, completely remove it, clean up the solder pads, reball it and reinstall it
I didn’t catch which model it was — do they have serial output?
they do, but no access to memory
which then can't have an OS installed
memory or storage, or both? could it boot a ramdisk?
I wonder with said output would it be possible to wipe the nand from the inside, then try to restore it manually
ramdisks will boot, but nothing other than the ramdisk is accessible
(i also have a broken nand)
ram is accessible, memory isn't
one can boot PongoOS but nothing further after
that’s kinda what I was thinking. If ramdisk is possible, and it sees the nand block devices, maybe there’s a few things to try to completely nuke/reset it
I also did try using nvram to wipe but to no avail, it can't be accessed
could you see the nand block device(s)?
there may be some nand testing tools floating around from factory diags
here's a glimpse of what mine looks like with a ramdisk installed on a broken nand:
aes_0 cu.builtin-serial5 perfmon_core ptyp5 ptype ttyp0 ttyp9 uart.builtin-serial5
bpf0 cu.wlan pf ptyp6 ptypf ttyp1 ttypa uart.wlan
bpf1 disk0 pfm ptyp7 random ttyp2 ttypb urandom
bpf2 fsevents ptmx ptyp8 rdisk0 ttyp3 ttypc zero
bpf3 klog ptyp0 ptyp9 rmd0 ttyp4 ttypd
btpoweroff md0 ptyp1 ptypa tty ttyp5 ttype
btwake null ptyp2 ptypb tty.bluetooth ttyp6 ttypf
console oslog ptyp3 ptypc tty.builtin-serial5 ttyp7 ttys000
cu.bluetooth oslog_stream ptyp4 ptypd tty.wlan ttyp8```
keeping in mind disk0 cannot be mounted
there is, if you desolder the nand chip and reprogram it
but you'd need another nand chip to repair
mount_apfs: volume could not be mounted: Invalid argument
mount: /mnt3 failed with 66```
mount_apfs: volume could not be mounted: Block device required
mount: /mnt3 failed with 74```
that doesn’t mean much, the partition headers or layout could just be fucked
that's what I thought too
until I went to restore it and it failed on "Updating nand"
further investigation leads to replacing the nand
it could just be hitting the same mount error and not doing anything to recover (disk utility loves to do that)
also given that the device was already fiddled with when they bought it
according to the listing from where it was purchased from, the middle pic shows the device was partially opened
who knows what happened after that
why would a nand physically break. I know it happens but seems weird
do you have a thermal cam?
indeed, but I'm seeing more and more of these happen. Could be a poorly made chip that breaks from an update
I don't know if software can break hardware though
maybe during the update the device gets hot...
i can do thermal readings
a short seems incredibly unlikely (definitely wouldn’t be directly caused by software) but they do tend to be obvious on thermal cam
I did notice that Apple used a different nand manufacturer in the second gen 4k devices
maybe toshiba is no good
hmm. debugging this would be a purely academic exercise, the hardware is not worth the time lol. but next steps I would try, after ramdisk tinkering, is getting probes on it and looking for activity/oddities on the scope
if only we could use the iphone/ipad equivalent chips to replace..
I don’t trust my smd soldering skills enough to do chip transplants
if it wasn’t fucked before it would be after for certain
This is indeed why i discourage folks from buying broken stuff off ebay to try and fix
you're just profitting the seller...
I could potentially pull off app decryptions from a ramdisk
“potentially” doing a lot of heavy lifting there
there is a slim probability of fixing some things, but 99% of it is like garage sale junk
in which case it may have some value in my decryption farm
decrypting an app from a ramdisk is challenging but not impossible
Depends on what state the device was in before it died
but yeah I’ve done it before as well
although I can't see someone buying a 40 dollar apple tv with a broken nand to spend a week with a soldering station to try to get tvOS installed again
no it would, in this theoretical scenario, only run a ramdisk
they'd be spending that time on their phones making money
I am all game to try any tricks via a ramdisk but I think I've exhausted all possibilities at this point with what is feasible
while we’re on the topic: Apple TVs are the best app decryption devices. Super cheap, super compact, no batteries to deal with. I’ve decrypted tens of terabytes of AppStore iOS apps with Apple TVs
if you’re down maybe we try some stuff this weekend
ah, so you're the reason the price goes up /s
sure
Does anyone know if the breakout for the Apple TV 4K 1st gen still work on tvOS 18 or do I need the goldeneye + dcsd combo?
It works
@bold parrot Could you fix this. Think they accidentally sent 6 links
i plan on jailbreaking my 4k 1st gen, will i be able to use goldeneye + dcsd cables on a macos monterey vm? just to confirm
Oh lord. Seems like a question for you @ionic copper . I assume that it wouldn’t work good in a virtual machine. Your probably in my guess better of just using Linux not a vm on the pc.
Virtual machines won't work
Needs to be a real mac machine or hackintosh.
Partially right, depends what tvOS they're on.. If it's the latest then a mac is preferred
I've had my fair share of issues with Linux
If your tech savvy just do some research on laptops that support hackintosh you will probably have to buy a BCM94360NG WiFi card but this is the model I use super cheap and fast it not the best but it does everything I need it to do Xcode projects jailbreaking my Apple TV 4K but I am using a HP EliteBook 840 G514" Laptop Intel Core i5-7200U
This way you get a better system than a crappy old Mac with 4gb of ram and you will get a faster processor it’s way better than an older MacBook air plus better cooling I highly recommend it!
So hypothetically I could dualboot macOS on my windows PC and get away with that? tvos 17.6 btw
Woah, you're one of the Minecraft for apple TV guys that got me interested in this in the first place 
Umm ya that was me but let’s not talk about that here that’s piracy 🤫
Media preservation bad?? 
Here yes.. if it once was on the App Store then deleted it’s still piracy, I believe
if it cost money
I can understand that
But anyways, yeah, look into getting a hackintosh
Absolutely. That is a hackintosh
Getting famous for something infamous
I know I’m trying to keep it on the down low but apparently it’s not working. Oh well I just like to help people.
We were just talking a while back how they should bring it back but the lite version with no purchase but limited gameplay
It would be a win win but I can see folks complaining about the limited gameplay and asking for the full one
Seeing as "it was discontinued.."
If you want a good affordable hackintosh, buy lenovo
Completely customizable and works with almost all apple services
I’ll definitely check it out. The only reason I would do it is for a better processor everything works really well on mine iMessage camera microphone. I haven’t noticed a problem at all.
You could probably bypass all those functions by setting up sidecar
So I was just wondering (sorry if this is a stupid question) is it possible to mount a usb? Like I saw some articles that apparently Kodi and Plex can recognize it. I plugged one in that is formatted as exfat but it didn't show up on /mnt. So can I solve this issue software wise or is this a low level problem that I can't do anything about?
Forgot to mention obviously through usbc port
no
the usb port is for diagnostics only
palera1n / purepkg still disappear after restarting and jailbreaking again on 16.x ...
is there something im missing here. Its been over a year this has been a problem
@ionic copper
probably the hooking method in the jailbreak
is there a way to fix this
I think i do, but are you able to SSH in?
havent seen others mention it. This is a new / different device too
yeah
have root and all
if you can ssh in, send me the plist files of both apps
tbf, its ANY jailbroken app
like snowboard etc
they dont come back until i force revert and re-jb
(and install again)
whats the location for the plists, theyre not showing up in containers/data
did you update palera1n/purepkg?
im using 500 i think
but its been quite a few revisions and no dice. I remember palera1n loader said v2.1.1
just tried 508. Doesnt restore palera1n / purepkg
i think the best way to fix this is if i downgrade to 16 and rejailbreak, then try the issue and see if i can fix it on my side
i've got all the blobs for the hd and the 4k makes no difference in this
so what exactly happens?
you jb, everything works fine. The moment you respring / reload icon cache (or restart apple tv) , the jailbroken apps disappear
youre still jailbroken, can ssh and everything. But things dont show on pineboard.
Doesnt fix until you force revert and re-jb. (until you respring/ reload icon cache / restart etc)
and yea, purepkg, the palera1n app are examples
hmm
so when this happens.. after everythings said and done..
you then respring from inside palera1n loader
and the apps don't appear?
yeah. jailbroken stuff disappears
does it work after re-jailbreaking or does reverting need to be done
need to force revert
been trying all year to see if an update had fixed it. And i just tried palera1n 508 too.
This is after installing bootstrap of course. Before installing it, idk
i might have an idea
are you gonna dg one of your atv's to see this?
oh 15.x idk. Never had one on 15.x
one of the issues i've seen with newer palera1n versions: they don't work with older oses
i remember downgrading and using older palera1ns to test this, but none worked properly anymore. They presented same behaviour
i assume its some of the stuff it DLs when setting bootstrap up
strange, the palera1n loader app crashes
uh never crashes for me. Just will disappear
had to use palera1n 420 to get it working on 15.1.1
ive used that one before , didnt work
lucky number palera1n so i always used to use
ah, palera1n changed the download URL
i noticed it said v2 or something
go to options
and change download url
what does default give you?
yup
we should keep note of that in case folks are on lower versions
uh so whats the fix here
hold on, I'll see if i can bootstrap it first
and see if this issue is on 15
if not, I'll update and retry
i think i even posted in the palera1n discord asking and i didnt get an answer. Ive just stayed away from jailbreak cuz of this since my atvs are on 16.x
the 1 HD on 17.0 i have does work fine though
yeah i'll update it, hold on
i'll go to 16.0
the things i do... ```Checkpoint 1624 complete with code 0
Checkpoint 1625 complete with code 0
About to send filesystem...
Connected to ASR
Validating the filesystem
Filesystem validated
Sending filesystem now...
[======= ] 13.0%
😛
I think ultimately; the best things of the HD devices are the ability to easily update/downgrade
whereas the 4K is such a chore
given the 4K was never meant to be downgraded
im gonna try a downgrade soon , thats why i bought this one, just to test downgrade stuff
okay, I'm on 16.0.. what vers on palera1n are you using?
its on 16.3.2 rn. But i personally never did the downgrade, nathan did it via teamviewer and i forgot
508
tried 500 too
I'l try 500
kk. then just create password / install bootstrap
and then u can restart pineboard right away and youll see purePKG disappear
ah shoot, selected rootless
yea happens to me too alot lol
although I think palera1n should be able to detect the OS and apply the correct args by message
indeed but palera1n loader is still there
okay i see the issue
and then, on a reset, palera1n will no longer show up
same thing happening to u?
I think i know what happened
did palera1n ever work for you (before this issue?) and if so, what version?
yea before
idr exactly. but around 420 days
400-420
this issue started happening around when 18.0 beta was a thing
but NO CLUE why no one is talking about this issue
because folks are on 18
ye but its not unusual for JB peeps to stay on older tvOS
er i guess update nags on tvOS are too nasty
Actually maybe i only ever jailbroke 17.2+ now that i think about it. Idr about 16.x
hey. i wonder if my old trick would work
?
partially fixed it.. ended up bootlooping myself
I think I have a resolution if I test this idea
So i kind of figured it out
it's not the apps, it's the bootstrap
I could potentially fix it, but it'll take time
can palera1n devs not look into this?
its a legitimate issue no?
It's not just 16
There's issues with the latest too
But there's only so many focused on tvOS because iOS is much more popular
I could make a custom bootstrap just for you to run it and see if it works
Sure ill run if u can
Would i just add a new DL url
No, I have a manifest that does that
I played around with a few bootstraps, the original bootloops and the newer ones produce the issue
so if I can mishmash the older bootstrap with a partial one from the newer one that won't cause bootloops.. maybe it'll fix and stabilize it
lmk
@ionic copper can you help me out here, trying to go to 16.3.2
Once you've got the security out of the way and your Terminal is in the Script directory, just type in ./makeipsw.sh then drag in the OTA zip file of the 4K followed by the IPSW of the HD (example: ./makeipsw.sh ./OTA.zip ./HD Firmware.ipsw). **Keeping in mind, these two files MUST be of the same firmware (for example: 17.6.1 HD IPSW - 17.6.1 OTA 4K) If you wish to go in-between firmwares 14 - 17, then you must also download the matching said firmwares as well
so do how do i add the 16.3.2 ota file in that command
would it be..
./makeipsw.sh ./18.3.zip ./18.3.ipsw ./16.3.2.zip
?
im assuming the command is
./makeipsw.sh ./1632.zip ./1632.ipsw but im confused since you say you must ALSO download matching said FWs too
It would be makeipsw.sh 16ota.zip HD16.ipsw
But CD to the directory first
Then it finds everything
If you get errors, it's usually 1. Low memory 2. Wrong OTA file (use appledb.dev) or some commands don't execute
I don't know why you're putting in 18 when you're making firmware for 16
Im getting a crc error
I think you're confusing the script for futurerestore sep and baseband commands
Screenshot?
Its cuz in the reddit thread u said i had to ALSO dl, so i was assuming i had to add to command
Ye gimme 5, in backyard rn
Yes, the reddit guide says exactly what I just said, ota zip first then HD ipsw
This is to reiterate that it must be (example)16.3 ota and 16.3 ipsw not 16.2 ota and 16.3 ipsw
it ends after though
Except 15.0
Are you using Monterey?
12.7.1 monterrey yea
Then it should go fine
re-DLing ota
You could just ignore the crc if it happens again
I'm sure it'll still restore regardless
Ah
Or you could do it manually
Tbf, never had that error before but I am suspecting incorrectly downloaded
Also @heavy patrol what firmware are you currently on that you're downgrading 16 to?
im at latest but i know i have to go to 13.4.8 after with idevicerestore
but just creating the 4k ipsw atm
Was going to say, yeah.. 18 won't let you
its a tvos 17-18 thing you say
also weird, since you would assume checkm8 would bypass that restriction
It's an update check as introduced in the newest OSes
It could but you'd need a dozen and one patches which is too much work when 13 is signed anyways
Im wondering what will happen when, for example:
HD reaches EoL tvos 18
Trying to restore a 4k to a specific tvos 19 version
Maybe not gonna be possible
ok it passed .040 this time. Strange.
Just to confirm, restoring via this method,
you can keep the custom ipsw for future use, and just grab newest sep/buildmanifest for FR in the future right
@ionic copper
the ipsw creation is still going but idk if itll still be good
There you go, now leave it for 40 mins or so
It takes time to make during this stage
This is normal
Is moving things from the extracted zip to the dmg template
Is this HD or 4K
Unless the issue that was faced for downgrading was because it was a beta..
Cool. I'm assuming you're using futurerestore4k?
Yea everything from your reddit thread
Cool
Really wanted to test this on my own + using cat command onboard blobs
But, so 13.4.8 was needed cuz it was a beta u were using?
Probably, unsure really, it was a pickle
Luckily the dudes downgraded and on 17.2RC though
ye thats good
so for the future, i can keep this 16.3.2 ipsw , and just use newer sep/buildmanifest thru FR?
17.2rc unsigned now tho, couldnt grab that blob for this atv. I wonder why it was signed so long
Yes
Because it was used for testing I'm assuming
I wonder had we not said anything about it being signed and downgraded to such, would it still be signed..
spies smh
but i remember once it stopped being signed. Then a couple days later it got resigned
also, gonna try making a 13.4 ipsw rn
for my unc0vertv 4k
That was for iOS..
You can't make 13 on the script
oof
it hasnt errored, ill wait till it does
Also, are the latest breezy etc working for tvos 17-18 on nito's repo
Not afaik, he's still updating everything
ok thanks
ugh, cant even install TS via trollhelper on your repo since trollhelper will never show up bc of bootstrap bug...
Will do misaka method. Lmk if you find a fix for 16.x bootstrap and want me to test
Working on it
13.4 ipsw creation was going well, i was more than halfway done thru process but ran out of hdd space
now when i try, from very early, it says extraction failed Invalid non-supported archive stream
no clue why it was working first time, cant replicate though
You still can if you revert and install trollstore
You don't have to wait
Yea i did that. I just meant i couldnt do it via jb
I've figured out why the apps dissapear
it's literally one file
Really
So its not the bootstrap?
Also strange it doesnt happen on 15
It is, but it's part of the bootstrap
ohh
So I've made a plan
instead of changing the bootstrap and editing files which would ultimately land me in a fight with the devs...
I'll just make a tweak to undo the changes
Thats a good idea. Altho how would it work if installing stuff dorsnt work
You do have access via ssh
yea but i guess nothing still shows up is what i mean
maybe your tweak will work proper if installed this way
Indeed not but again, you're still jailbroken so there's access to root
I just have to compile the tweak and hope it works
prayge
hello guys can anyone give me any car because my account got stolen
probably a roblox kid
Whats gonna be the future for tvos jailbreaking for those on latest with only rootless as an option?
Stay on latest, and tweaks will slowly change to rootless like what happened on iOS? (Idk if worth for only 2 devices)
Or maybe dualboot 13.4.8 + 17.x could be a solution..
Thats possible to do right without blobs? You need to boot tethered for jailbreak anyways. So its not totally unviable
I mean on 18.2+ you have the fakefs option
now realistically there should be a rootless strap but for whatever reason it sounds as though the palera1n devs don't care (how tf can there be development if there isn't even a strap for it)
doesnt that use alot of storage? Probably a problem on 32gb atv's
(if its like ios)
About 6 gbs
It's significantly reduced because iOS has way more
hmm
I wonder if anyone has tried to take it upon themselves to migrate the nand from the newer models on to the 4K first gens..
Just to get more space without buying a whole new product
Might be possible?
Because I know you can upgrade iPhones from their respective spaces to 1tbs or higher
I've made the tweak.. just gotta test it
on your end, or mine?
I don't know if I need to compile it via rootless? hopefully this works as is if I resign it
no, it's technically rootless i think?
oh uh dunno
either-or it should still work if i did it right
yeah, it's still rootful just with a rootless configuration
kinda iffy
ah
no Zenzeq
tvOS is realfs rootful all the way until 18.1
the arch and everything about the setup is effectively the same
18.2 is the version that implemented SSV to tvOS, and that’s where the rootless matter becomes relevant
Did it work 👀
i just gotta... ```void* PBAppInfo_isEnabled_orig;
void* PBAppState_isEnabledForApplicationWithIdentifier_orig;
void* PBSMutableAppState_isEnabled_orig;
bool returns_true(void) {
return false;
}
with your issue, the problem resides inside universalhooks.dylib
this is the one file I was talking about
problem with this file; it's on a read-only partition meaning you can't change it
but you can hook it
or one could recompile the dylib with said changes
so this file is added in as part of the ramdisk when you load palera1n
then what happens is: when you install the bootstrap, it installs ellekit which activates the dylib
that's when the icons go bye-bye
other than making a tweak, i could just make a ramdisk with the file included.. then just load palera1n with a few additional commands.. then it'll load the correct one with the working icons
hmm
@ionic copper Aye zen how you doing bruthA quick question I got a Apple TV A1625 model I got it for $10 dollars at a garage sale came with HDMi cable and power cord but no remote I was wondering if you recommendation site where I can find the original remote .
Apple TV HD - Any remote that's Siri or Apple TV 2/3 gen remote
I'd plug it in to a computer to see what tvOS it's on
then save the on-board blob
Any possible chances if the Apple TV 4th Gen remote works ?
seeing as a A1625 is a 4th gen; yes
Awesome I’ll keep you updated good looking out bruthA 🤙🏽
The unit on 14.4 which that can be JB in 14.4 but I wanna go higher then that that’s bcuz my other unit already on 14.4
jailbreak it first, grab the blob then you can update it
because with the blob, you can go back anytime
use checkra1n
Saved the blobs completed
what did you use to save them?
Current me if I’m wrong but I did use the BlobSaver
I'm meaning saving on-board blobs
so you can get back to 14.4
Eh I’m naw worried about going back to 14.4 my other unit already on 14.4 and that one jB with chrckM8
okay L
18.3 able to be done with palra1n ?
Aye zen can I get your repo if you don’t mind
yes but it's complicated
Try me lol
@ionic copper any update to the 16.x jb fix?
Tf is this? <@&355145545242902548>
Yeet
Just bumping one last time
The ramdisk can be made.. I just need time making it
I had other ideas.. but they're too much work
Ohhh ok no rush. Just thought u hit a wall or someth
Lmk tho pls if/when u finish
no, there's so many ways to go about doing this.. one thought was using one of the 4.xx versions, then rerouting the bootstrap to work but the manifest is baked in to detect palera1n loader 2.1 or higher which would essentially require recompiling palera1n which I really don't want to do
another thought was getting you to update beyond 16 (whilst keeping the blobs for 16) then you can go back
Btw im having the 16.6 issue on another atv, 4kgen1. Its on 16.3.2. OTA misaka block starts nagging for 16.6. If i nextDNS, it blocks fine. But if i turn on vpn, it nags for 16.6 again
Is there a plist i can use thatll stop nagging for 16.6
This is the <16.4 issue from before
Blocking ota is so easy
You don’t need a VPN
i do for watching stuff out of canada
ive never been able to fix this issue. like i said:
on 16.4 or lower, misaka ota block will start nagging for 16.6 instead of 18.x after being applied
-nextdns block works, but if i turn on vpn, it disables the nextdns block
-this doesnt happen on 16.5/16.6
Is 16.6 also the issue for the bootstrap?
Or is it lower
unrelated i think
No I’m mean the firmware for the icons
wdym. im on 16.3.2
Ok so lower