Palera1n-c: itl go to pongo os, say booting kernel and do alot of text, followed by a full screen solid red flash, it wont jb and sileo wouldnt open when i did have it
Palera1n.sh: used to work awhile ago, but the whole script is broken and says parse error: Invalid numeric literal at line 1, column 10
Chimera: Crashes at step 1/3
Chimera Patch: asks to reboot, reboots, and doesnt jb
Unc0ver: too new ios
#IPad Air 1 / IPad Air 2 is le sad :<
1 messages · Page 1 of 1 (latest)
palera1n.sh is deprecated
and palera1n does not support below iOS 15 so palera1n will not work
we said that already in #palera1n
ik just listing what everything does
and that sh worked b4
that air 2 also now refuses to be jb-d by anything -w-
try reseting the air 2
it boots straight to rec
it was running sh
but freezes at Extracted Image4 payload data to: work/kcache.raw Bad magic: 20206d6f
it boots straight to recovery mode like it does
ios 15 smth smth
palera1n.sh says that after awhile, nd freezes, the air 2 at the disk palera1n screen thing
again you should not be using palera1n.sh anymore
please follow https://ios.cfw.guide/installing-palera1n/
Guide to installing palera1n
if it boots straight to recovery you can just reset it
if that doesn't work then go into DFU mode and reset
can -c boot a .sh palera1n install?
no
-c, --setup-fakefs
When used with -f, --fakefs, Create the new APFS volume required for rootful. Will fail if one already exists.
you should not be using rootful anymore
you should just remove any existing installation of rootful, then reinstall using the guide https://ios.cfw.guide/installing-palera1n/
Guide to installing palera1n
WHY in the name of jesus christ are you using palera1n.sh on 12.5.6
better yet why palera1n.sh
@lethal gate ur looking for https://ios.cfw.guide/installing-odysseyra1n maybe
Guide to installing Odysseyra1n
but like it already is all tweaked up i dont wanna do it all again
nd how is it better
are we talking about the air 1 or 2 :3
it’s not tethered (i assume what ur using is tethered)
i assume air 1
the one that doesnt work at all or the one that is running .sh but not working
air 2 is tethered i think yea, nd it used to work but doesnt anymor nd it freezes at Bad magic: 20206d6f
air 1 used to run .sh but it just crashes out of .sh when trynna jb it
something is very scuffed
mhms :3
the air 1, as said in this msg, has no jb that workies
this im not agreeing w btw
rootless is dumb
Guide to installing Odysseyra1n
ill twy tmr :3
is the air 2 really frozen or is it making the fakefs
it says at that bad magic error for more than 10 mins
hehe
dumb question, whats the diff between one checkra1n based jb and another
why is there a diff where palera1n.sh and -c cant boot eachother, why isnt it just the same jb rewriten in C
well
there’s also the fact that palera1n.sh is true rootful
and palera1n-c isn’t
first of all every single other rootful jailbreak besides palera1n doesnt use fakefs on 12 because that is extremely dumb, the reason fakefs was even created in the first place was to “mitigate” against SSV which was added in 15
Palera1n never even officially supported 12 pretty sure
Whar
it ran b4 tho
sorry that means i’m agreeing with you
maybe a year ago but it did run on the air 1
so how are they similar
its a diff loader, diff app, diff core in how it works
Ran doesn’t necessarily mean you should use it
if it works idc
what injector/hooker does palera1n.sh use
i kno that .sh doesnt use pongoOS
Palera1n should ONLY be used on 15+ because it was never made or designed to run on 14-, so you will run into big issues with it most likely even if it “works”, an update to palera1n can break everything.
There’s genuinely no reason as to why you should use palera1n on 14- instead of something like checkra1n which doesnt use a fakefs, unlike palera1n
jb with checkra1n 
palera1n.sh doesn’t use a fakefs btw
Still
ive always been on the last version of .sh
never updated, it just shit its pants
Never was made or designed for 12
you don’t have to remove anything just jb with checkra1n and see if it works
(also don’t install cydia or anything in the loader app)
ys that
Genuine question why would you use palera1n.sh over checkra1n/odysseyra1n on 12 even if it “works”
that too
checkrains last update was when ios 14 came out, and i didnt know odysseyra1n even existed
i knew that palera1n worked nd its what i used on everything
omg hello mocha cat
hewwo!!
Fair enough
nd again, it worked so, why stop using it??
it worked
is it still working
Because you’ll probably run into bigger issues in the future + it clearly isn’t working anymore so
ive never got -c to work nd its jankier in my testing
On unsupported iOS? Yeah
no on supported
tbf it was designed for rootless, rootful was just an afterthought
-# dont fact check this, because it is wrong
i tried rootless
er technically, didnt know it was using smth else
it wouldnt get to pongoos before just not working
Rootless on 12 would be beyond problematic anyways (even if it worked) because most rootless packages are designed for 15.0+, also rootless only exists because of SSV which was added in 15.0
im not talking about janky on 12
stuck in 🅱️ongoOS -> ctrl + c -> run palera1n again
im saying on 15 and 16
Oh
did that
uhhhhhhhhhhhhhhhhhhhhhh
no one could help me bac then either

just pretty much got a Neko_Shrug from everyone
???
Just use .sh on supported ios if you’re more comfortable with it and it works for you
Its your choice
i mean id like to get sh working -w-
But yeah using it on unsupported ios really isnt a good idea
like wtf dus Bad magic: 20206d6f even mean
When you use software built for a newer version of iOS and the unintended backward compatibility breaks yeah you’ll get very weird and cryptic errors
that error is on ios 15
Well
the air 1 on ios 12 doesnt get anywhere near that far
dis comes from an air 2 that was running .sh tethered up until recently, where it just gives dis error nd freezes
ios 15.smth.smth
Yeah i get it that it must be frustrating for it to not work but just use dopamine
i cant cuz its tethered nd cant get to a homescreen
Oh
i think tethered, whatever just goes to the recovery mode screen and cant boot w/o the jailbreak
bad magic 
something is corrupted
who knows what happened
it ran fine, sat around for maybe half a year
:<
Ok so the palera1n.sh script doesn’t work at all now, correct?
mhms
Why not just clone it again
its always dun dis btw
?
Yeah it’s normal palera1n.sh is tethered
mkmk
- delete the old palera1n.sh directory
- cd to the directory you want to have the new palera1n.sh directory in
- git clone -b legacy --recursive --depth=1 --shallow-submodules https://github.com/palera1n/palera1n && cd palera1n
y tho
No idea but the current script seems to be corrupted idk
oh the script is corrupt??
the device is, not the script
well
Oh whay
How does one
Corrupt a device
????
it sat around, i did nothing
storage
i wasnt using it as a seat or smth
for me that happened after i installed kde (real) and arch couldn’t determine fs type
peak arch moment
Is the storage full or anything
nope
@eager briar 
blame mineek and move on
n0
well blaming some1 doesnt solve it not workin
how much do you care about your data? 
Good question
jk!
i mean
never blame mineek
id prefer it to stay
So palera1n.sh no worky anymore, how does one recover the data
😭
i mean, can we got it to workie
update the device, overwrites rootfs and device boots but no jb
load up sshrd and become super schizo
if i re jb-d w sh would tweaks stay?
no
How does palera1n.sh work again @eager briar
Does it just shamelessly break the ssv seal
yes
that’s why it’s tethered
it is :3
Wouldn’t trying to ipsw update in an SSV bricked state just fail
fuck i forgot it checked that
i truly love restored_external
seprmvr64v2 step 4 🥺
on a scale of 0 to dildo how fucked am i
terry davis
Probably like triple dildo
Ok so
ideas
@eager briar i have an idea
or unplug + replug
worked for me
also do that
that’s how you fix it yes
i wann my tweaks tho :<
wait what did u do
it sounds like getting sh to work is the only option,,
did*
tf is that
Nuking the whole nand seems like a very viable option in this case if we can’t get that to work

sshrd - secure shell ramdisk
what the duck id a whoogle
that’s what i said
self hostable google
anyways
then whats PlaneraJB??????
funni reddit comment
bro leaked secret jb frfr
Funny thing null likes to say idk
then lets try to get wut i said working before hitting a 9/11 on my nand
Then what
first we need to look at palera1n.sh as a script
both creation of jb files and boot process
What does that even mean
do u need that folder palera1n.sh makes for every device
not sure at this moment
if ur not sore thats pretty good
ima let xrt do whatever tf i just said and yes
What
Man we don’t know what the fuck we’re doing
💔💔💔
well we can find out :3
that’s why we have to find out silly
exactlyy
Is this a reasonable reason to ping the one and only mineek
‼️
yes but it’s 3 am for him
sounds like the perfect time to ping imo
He’ll see it when he wakes up smh
exactlyy
@lethal gate i’ve just realized something
ya
how does it work
it’s possible that the ramdisk is the thing that’s corrupted
Why did the ramdisk corrupt itself
idk ask it
can we just
make
a new
one
:3
definitely
:o
Extracted extra Image4 payload data: to work/kpp.bin.
Extracted Image4 payload data to: work/kcache.raw
Bad magic: 20206d6f```
more of the err
Well that helps a bit
@marsh citrus if i pwn my 7 then pass it to maxos vm will it work for checkm8/other shit
its extracting shit, then dus an err u say means smth is corrupt
work is sshrd related
we are doing tech shit, not chess
smh
bros loosing it,,,
look at checkra1n icon 
Idk
Gir > esmbot :/
yesh
bot tuah*
lets start fresh
hi who are you?
- make a new directory we can test out things in
- git clone -b legacy --recursive --depth=1 --shallow-submodules https://github.com/palera1n/palera1n && cd palera1n
- dont ask what happened to number 2
Oh wait
There js a number 2
bozo
Nvm
i know it dw
Thank god
./palera1n.sh --tweaks [ur ios ver]
holy shit how do i get more ram and better. cpu on this bitch
one sec homie
Shut the hell up stop venting about your assMac Pro
ok so do this #1318714322658005082 message then just run that
mhms 1 sec
启用对中国大陆网络环境的替代办法
‼️
ram successfully doubled
les goo
Hold home + power button (0)
Release power button, but keep holding home button (3)
[*] Device entered DFU!
[*] Creating ramdisk
<string>:1: DeprecationWarning: 'pkgutil.find_loader' is deprecated and slated for removal in Python 3.14; use importlib.util.find_spec() instead
import pkgutil; exit(not pkgutil.find_loader("pyimg4"))
Archive: gaster-Darwin.zip
End-of-central-directory signature not found. Either this file is not
a zipfile, or it constitutes one disk of a multi-part archive. In the
latter case the central directory and zipfile comment will be found on
the last disk(s) of this archive.
unzip: cannot find zipfile directory in one of gaster-Darwin.zip or
gaster-Darwin.zip.zip, and cannot find gaster-Darwin.zip.ZIP, period.
[-] An error occurred
(venv) arcane@arcanes-MacBook-Pro:~/palera1n|legacy⚡*
➤```
What the fuck does this mean
also ratio, i have a kitty cat
What is even happening
Do you keep a source of radiation near your computer because how the fuck did that get corrupted
deleting it and it redownloading downloads the 0 byte one again
gaster-Darwin.zip works on my machine L bozo skill issue
Are u sure u have space
it downloads it
On uhh your mac
What the actual fuck
im just saying
whar
> palera1n.sh throws weird error
> redownloading it throws more errors
> cant restore because palera1n.sh effectively ssv bricks you
> i cant just nuke the nand because there’s data
🫃
What are we supposed to do
that's what i'm saying
we are on a diff ipad rn
i know
but also i already answered that question
regardless palera1n.sh should not be used
g
hmph
Do it.
fine :<
@ember rapids @cold reef @eager briar any opinions
step 2
Before the great nand nuke of 24
I need to consult with my fellow idiots geniuses first sorry
i am an idiot sometimes not offended
this section can be commented out, assuming you have pyimg4 installed
if ! python3 -c 'import pkgutil; exit(not pkgutil.find_loader("pyimg4"))'; then
echo '[-] pyimg4 not installed. Press any key to install it, or press ctrl + c to cancel'
read -n 1 -s
_check_network_connection
python3 -m pip install pyimg4
fi```
at the idiotbar
chat got
got
gpt
autocrat
Oh my god are you ok mentally
autocorrect 😭
what
fr
nope
ok great!
sudo rm rf / to make it funnier
?
sep test reference
(also xrt thats to help running the script, not doing it manually)
he he
Im going to paint the walls with my brains
still has the pkgutil.find_loader err :3
启用对中国大陆网络环境的替代办法
wtf
ill brb while u 3-4 jabber for a sec
Solar rays corrupting the code to emit the #
i deleted the whole section
h
the string "Bad Magic" doesnt appear anywhere in the whole folder according to finderp
mocha what r u. even tryong to do
makes sense
generic error
How is that generic
also does this script save all bins in it's root
jailbreak my air 2, or, erase it to jb it again
generic as in it can happen everywhere
and why cant u use chimera
whar
already jailbroken w .sh tethered
dopamine
i cant get to the homescreen
then do it
we decided itd be best to try to not
why
brother
well no he has a point
but we would not like to lose data
also
@molten epoch another thread
why
fun fact: palera1n.sh is over 1.1k lines long
if he cant get to homescreen whats the poiny of even trying to save data
fun

curiosity
booting so i can still use it w my data...?

also she*
why yall in a rush
o sorry
:3
Ok so
its literally in my name-
me too
ight
Or is it just yap
its called sudo rm -rf /
extra line, unnecessary , will pr fix soon
mocha can u even get to dfu lol
not just yapping, but uselessness that hasnt furtured society
yea yea its in dfu rn
restore 👍
How 2 nuke nand to avoid SSV brick
- Clone and cd into this repository: git clone https://github.com/verygenericname/SSHRD_Script --recursive && cd SSHRD_Script
- Never ask about step 2
- Run ./sshrd.sh <iOS version for ramdisk>, without the <>.
- Run ./sshrd.sh boot to boot the ramdisk
- Run ./sshrd.sh ssh to connect to SSH on your device
- Finally, to mount the filesystems, run mount_filesystems
- Type in dd if=/dev/zero of=/dev/disk0 bs=1M
Im sorry moderators
It had to be done
To avoid SSV
.
i mean, null seems to be on path #uno
palera1n.sh breaks the ssv seal
aka, not wiping it
Whar.
Restore no worky
oh
as we already said
i do. not want ot read all 485 messgaes at 4 am
After doing these
Reboot (you should be in either recovery or DFU, probably DFU) then restore to latest
!t reboot
reboot
This will force reboot the device. For normal rebooting instructions, see the normalreboot tag.
iPhone 8 or newer (including all notched devices, iPhone SE 2020 and newer):
- Press and release volume up
- Press and release volume down
- Press and hold the side button for 10-20 seconds until the Apple logo appears
iPhone 7:
- Press and hold the volume down and power buttons for 10-20 seconds until the Apple logo appears
iPhone 6S/SE 2016/iPad 8th or older:
- Press and hold the home and power buttons for 10-20 seconds until the Apple logo appears
Added by JTV#5846 | Used 1,940 times
·
meow meow meow meow meow meow meow meow meow meow meow meow
ok then shush it and help someone else..?
ok!!!
@eager briar update on plan A?
yea lets put a pin in plan b :P
!!!
real
palera1n.sh SSV brick tuah wipe nand on that thang
palera1n.sh SSV brick tuah wipe nand on that thang
you will go missing on 5/30/25
fuck palera1n.sh needing normal mode
mods
i wanna ssv brick one of my devices
@marsh citrus teach
IPad Air 1 / IPad Air 2 is le sad :<
@eager briar any updates?????
i forgot to save changes and did the same script 3 times
question
idfm cuz its just a warning
i think we need to be more worried on how it zeros out a zip it wants
who
Yeah that’s quite concerning
that's also a valid concern however i was planning on bypassing that and just giving it the bin it wants
smort
curl -LO https://alexia.lol/gaster/gaster-Darwin.zip && unzip gaster-Darwin.zip && chmod +x gaster
btw
run dat?
oh
Or just compile gaster from source smh

run again in palera1n/ramdisk/Darwin
same about that pkgutil error, edit sshrd.sh
[*] Creating ramdisk
slowly but surely
fuck its the ipad
[==================================================] 100.0%
[==================================================] 100.0%
[==================================================] 100.0%
[==================================================] 100.0%
[==================================================] 100.0%
[==================================================] 100.0%
[==================================================] 100.0%
Error connecting to device: No such file or directory
[*] Dumping apticket
[*] Patching the kernel
mv: /mnt6/5F52C212F3FDD3BE6B772FD95E646436D0579506/System/Library/Caches/com.apple.kernelcaches/kernelcache: No such file or directory
[*] Downloading BuildManifest
Version: 9bfdde2b2456181045f74631683fba491d8bf4f2 - 38
libfragmentzip version: 0.64-aaf6fae83a0aa6f7aae1c94721857076d04a14e8-RELEASE
init pzb: https://updates.cdn-apple.com/2022SummerFCS/fullrestores/012-41685/A12D2F85-A629-49EF-B5F7-FDF71C040564/iPad_64bit_TouchID_15.6_19G71_Restore.ipsw
init done
getting: BuildManifest.plist
100% [===================================================================================================>]
download succeeded
[*] Downloading kernelcache
Version: 9bfdde2b2456181045f74631683fba491d8bf4f2 - 38
libfragmentzip version: 0.64-aaf6fae83a0aa6f7aae1c94721857076d04a14e8-RELEASE
init pzb: https://updates.cdn-apple.com/2022SummerFCS/fullrestores/012-41685/A12D2F85-A629-49EF-B5F7-FDF71C040564/iPad_64bit_TouchID_15.6_19G71_Restore.ipsw
init done
getting: kernelcache.release.ipad5b
100% [===================================================================================================>]
download succeeded
[*] Patching kernelcache
Reading work/kernelcache...
[NOTE] Image4 payload data is LZSS compressed, decompressing...
Extracted extra Image4 payload data: to work/kpp.bin.
Extracted Image4 payload data to: work/kcache.raw
Bad magic: 20206d6f
actually
⁉️
So is the ipad a paperweight or not
remote_cmd "/mnt6/$active/kpf /mnt6/$active/System/Library/Caches/com.apple.kernelcaches/kcache.raw /mnt6/$active/System/Library/Caches/com.apple.kernelcaches/kcache.patched"
remote_cp root@localhost:/mnt6/$active/System/Library/Caches/com.apple.kernelcaches/kcache.patched work/```
what does this mean 🤔
you tell me!!!
@lethal gate @cold reef @ember rapids @molten epoch Gn
Gn to you too null
I need sleep sorry
:/
nini
well that sucks
?
unrelated... null ramblings...
:3
question
could it be saying bad 🧙♂️ bcuz of Error connecting to device: No such file or directory

nope its not
run the command with zsh +x infront of it so i can see which command it’s failing on pls pls pls
bet
who needs kb input,,,
wait wtf whys it asking for gasted
wait you shouldn’t even be seeing that error
those damn space aliens added in gaster check and removed gaster bin 😡
REAL
wait we never got rid of gaster check we just placed the bin which passed the check
but why’s it gone
omg it has demetia
joe biden,,,
we wont have to do all 1.1k lines that would just be stupid
😭
ok
well
isnt making our own sh better
so its not
copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste, copy paste,
whar
when we find the problem section we can fafo and maybe fix something
whereas making our own sh is
harder to trace
just add a log at every single line
essentially

:p
i’ll put stuff here as i go along reading this but to start off
- im an idiot
gaster doesn’t belong in current working directory
extending on 1 i have a few questions:
- did it ever actually fucking cuz how tf
- “dir” is a misleading name
solution:
mv gaster ./binaries/Darwin/
or
run the gaster script in that directory
what this tells me is that even without that fix something was going right for some reason
- palera1n.sh has logs
no clue how useful they are but they exist in, well, /logs
sidenote --debug also exist
+ mv kernelcache.release.ipad5b work/kernelcache
+ [[ iPad5,4 == \i\P\h\o\n\e\8* ]]
+ [[ iPad5,4 == \i\P\a\d\6* ]]
+ [[ iPad5,4 == *\i\P\a\d\5* ]]
+ python3 -m pyimg4 im4p extract -i work/kernelcache -o work/kcache.raw --extra work/kpp.bin
Reading work/kernelcache...
[NOTE] Image4 payload data is LZSS compressed, decompressing...
Extracted extra Image4 payload data: to work/kpp.bin.
Extracted Image4 payload data to: work/kcache.raw
+ sleep 1
+ remote_cp work/kcache.raw root@localhost:/mnt6/5F52C212F3FDD3BE6B772FD95E646436D0579506/System/Library/Caches/com.apple.kernelcaches/
+ /Users/arcane/palera1n/binaries/Darwin/sshpass -p alpine scp -o StrictHostKeyChecking=no -P6413 work/kcache.raw root@localhost:/mnt6/5F52C212F3FDD3BE6B772FD95E646436D0579506/System/Library/Caches/com.apple.kernelcaches/
+ remote_cmd '/mnt6/5F52C212F3FDD3BE6B772FD95E646436D0579506/kpf /mnt6/5F52C212F3FDD3BE6B772FD95E646436D0579506/System/Library/Caches/com.apple.kernelcaches/kcache.raw /mnt6/5F52C212F3FDD3BE6B772FD95E646436D0579506/System/Library/Caches/com.apple.kernelcaches/kcache.patched'
+ /Users/arcane/palera1n/binaries/Darwin/sshpass -p alpine ssh -o StrictHostKeyChecking=no -p6413 root@localhost '/mnt6/5F52C212F3FDD3BE6B772FD95E646436D0579506/kpf /mnt6/5F52C212F3FDD3BE6B772FD95E646436D0579506/System/Library/Caches/com.apple.kernelcaches/kcache.raw /mnt6/5F52C212F3FDD3BE6B772FD95E646436D0579506/System/Library/Caches/com.apple.kernelcaches/kcache.patched'
Bad magic: 20206d6f
+ _exit_handler
+ '[' Darwin = Darwin ']'
+ killall -CONT AMPDevicesAgent AMPDeviceDiscoveryAgent MobileDeviceUpdater
+ '[' 0 -eq 0 ']'
+ exit
whereever kcache.raw comes from is instead returning a file without its headers/'magic number'
indeed
kcache.raw comes from kernelcache in work/
nodnod
you should try verifying kernelcache by img4 -i work/kernelcache -d
➤ img4 -i work/kernelcache -d 23:16:42
fish: Unknown command: img4
(venv) arcane@arcanes-MacBook-Pro:~/palera1n|legacy⚡*?
➤
wtf no img4lib?!
brew has never heard of it
compile from source!
https://github.com/xerub/img4lib
booo
(imagine no aur lmao L bozo)
no M1 lmao L bozo)
define more errors
????
make COMMONCRYPTO=1
fatal error: 'lzfse.h' file not found
git submodule init && git submodule update && make -C lzfse
clang -o libvfs/vfs_lzfse.o -Wall -W -pedantic -Wno-variadic-macros -Wno-multichar -Wno-four-char-constants -Wno-unused-parameter -O2 -I. -g -DiOS10 -DDER_MULTIBYTE_TAGS=1 -DDER_TAG_SIZE=8 -D__unused="__attribute__((unused))" -Ilzfse/src -DUSE_COMMONCRYPTO -c libvfs/vfs_lzfse.c
In file included from libvfs/vfs_lzfse.c:17:
lzfse/src/lzfse.h:56:43: warning: a function declaration without a prototype is deprecated in all versions of C [-Wstrict-prototypes]
56 | LZFSE_API size_t lzfse_encode_scratch_size();
| ^
| void
lzfse/src/lzfse.h:94:43: warning: a function declaration without a prototype is deprecated in all versions of C [-Wstrict-prototypes]
94 | LZFSE_API size_t lzfse_decode_scratch_size();
| ^
| void
2 warnings generated.
clang -o libvfs/vfs_img4.o -Wall -W -pedantic -Wno-variadic-macros -Wno-multichar -Wno-four-char-constants -Wno-unused-parameter -O2 -I. -g -DiOS10 -DDER_MULTIBYTE_TAGS=1 -DDER_TAG_SIZE=8 -D__unused="__attribute__((unused))" -Ilzfse/src -DUSE_COMMONCRYPTO -c libvfs/vfs_img4.c
ar crus libimg4.a lzss.o libDER/DER_Encode.o libDER/DER_Decode.o libDER/oids.o libvfs/vfs_file.o libvfs/vfs_mem.o libvfs/vfs_sub.o libvfs/vfs_enc.o libvfs/vfs_lzss.o libvfs/vfs_lzfse.o libvfs/vfs_img4.o
gcc -o img4 -g -Llzfse/build/bin img4.o lzss.o libDER/DER_Encode.o libDER/DER_Decode.o libDER/oids.o libvfs/vfs_file.o libvfs/vfs_mem.o libvfs/vfs_sub.o libvfs/vfs_enc.o libvfs/vfs_lzss.o libvfs/vfs_lzfse.o libvfs/vfs_img4.o libimg4.a -llzfse -framework Security -framework CoreFoundation
(venv) arcane@arcanes-MacBook-Pro:~/p/img4lib|master✓
➤```
this thread is surprisingly short compared to some of my others
LMFAO
wont be by the end
question right
can we copy the jb shit
wipe it
install 15.7.3, jb, and transplant the jb shit
i mean that could work
it could also break a bunch of shit
like?
i’ll let xrt explain this
besides you’ll probably have the same issue
deleting the whole work folder and running thr script has a chance of working
bet
:3 nyo
36D0579506/kpf /mnt6/5F52C212F3FDD3BE6B772FD95E646436D0579506/System/Library/Caches/com.apple.kernelcaches/kcache.raw /mnt6/5F52C212F3FDD3BE6B772FD95E646436D0579506/System/Library/Caches/com.apple.kernelcaches/kcache.patched'
Bad magic: 20206d6f
- _exit_handler
- '[' Darwin = Darwin ']'
- killall -CONT AMPDevicesAgent AMPDeviceDiscoveryAgent MobileDeviceUpdater
- '[' 0 -eq 0 ']'
- exit
so
how wipe
fucking magic number
boot up sshrd
(dont run yet) dd if=/dev/zero of=/dev/disk bs=4M
girlie (i think???) idk wtf that is or how to do that
u cant say dont run yet to me! i gotta have fucking step by step shit
in order
luckily joera1n has a ramdisk for us
./ramdisk/sshrd.sh boot
./ramdisk/sshrd.sh ssh
gotta mske sure disk0 is real and not a space alien again
what folder r u in
~/palera1n/
also should i leave the 👁️ pad where it is on the palera1n icon or put it in rec
or put in dfu
put in dfu
cd ramdisk
sudo ./sshrd.sh boot
sudo ./sshrd.sh ssh
sudo ./sshrd.sh boot
sudo ./sshrd.sh ssh
Password:
<string>:1: DeprecationWarning: 'pkgutil.find_loader' is deprecated and slated for removal in Python 3.14; use importlib.util.find_spec() instead
import pkgutil; exit(not pkgutil.find_loader("pyimg4"))
usb_timeout: 5
usb_abort_timeout_min: 0
[IOKit] Waiting for the USB handle with VID: 0x5AC, PID: 0x1227
CPID: 0x7001
Found the USB handle.
Stage: RESET
ret: true
[IOKit] Waiting for the USB handle with VID: 0x5AC, PID: 0x1227
CPID: 0x7001
Found the USB handle.
Stage: SETUP
ret: true
[IOKit] Waiting for the USB handle with VID: 0x5AC, PID: 0x1227
CPID: 0x7001
Found the USB handle.
Stage: SPRAY
ret: true
[IOKit] Waiting for the USB handle with VID: 0x5AC, PID: 0x1227
CPID: 0x7001
Found the USB handle.
Stage: PATCH
ret: true
[IOKit] Waiting for the USB handle with VID: 0x5AC, PID: 0x1227
CPID: 0x7001
Found the USB handle.
Now you can boot untrusted images.
usb_timeout: 5
usb_abort_timeout_min: 0
[IOKit] Waiting for the USB handle with VID: 0x5AC, PID: 0x1227
Found the USB handle.
[==================================================] 100.0%
[==================================================] 100.0%
[==================================================] 100.0%
[==================================================] 100.0%
[==================================================] 100.0%
[==================================================] 100.0%
[==================================================] 100.0%
<string>:1: DeprecationWarning: 'pkgutil.find_loader' is deprecated and slated for removal in Python 3.14; use importlib.util.find_spec() instead
import pkgutil; exit(not pkgutil.find_loader("pyimg4"))
[*] Waiting for device in DFU mode
does the ipad have nathan on it
why must ramra1n be like this 
ssh is probably still possible
idfk whats happening girlie
k wait
ok try diskramplanerajb or exit and use real sshrd or wait for mineek to lend his wisdom
[*] Command ran: ./palera1n.sh --tweaks 15.7.3
palera1n | Version 1.4.2-legacy-4fb51a7
Made with ❤ by Nebula, Mineek, Nathan, llsc12, Ploosh, and Nick Chan
[*] Waiting for devices
[*] Detected ramdisk mode device
[*] Rebooting device in SSH Ramdisk
./palera1n.sh: line 341: 41419 Terminated: 15 "$dir"/iproxy 6413 22 > /dev/null
[*] Waiting for device in recovery mode
^C⏎
(venv) arcane@arcanes-MacBook-Pro:~/palera1n|legacy:zap:*?
➤```
it was in sshrd
well its out of it now
bac at rec screen
i tried it tho
i mean
why not put in dfu like it wants
it’s supposed to be
dfu -> sshrd
not
dfu -> sshrd -> dfu
recursion 
<string>:1: DeprecationWarning: 'pkgutil.find_loader' is deprecated and slated for removal in Python 3.14; use importlib.util.find_spec() instead
import pkgutil; exit(not pkgutil.find_loader("pyimg4"))
usb_timeout: 5
usb_abort_timeout_min: 0
[IOKit] Waiting for the USB handle with VID: 0x5AC, PID: 0x1227
CPID: 0x7001
Found the USB handle.
Stage: RESET
ret: true
[IOKit] Waiting for the USB handle with VID: 0x5AC, PID: 0x1227
CPID: 0x7001
Found the USB handle.
Stage: SETUP
ret: true
[IOKit] Waiting for the USB handle with VID: 0x5AC, PID: 0x1227
CPID: 0x7001
Found the USB handle.
Stage: SPRAY
ret: true
[IOKit] Waiting for the USB handle with VID: 0x5AC, PID: 0x1227
CPID: 0x7001
Found the USB handle.
Stage: PATCH
ret: true
[IOKit] Waiting for the USB handle with VID: 0x5AC, PID: 0x1227
CPID: 0x7001
Found the USB handle.
Now you can boot untrusted images.
img4tool version: 0.197-aca6cf005c94caf135023263cbb5c61a0081804f
Compiled with plist: YES
Saved IM4M to work/IM4M
Version: 9bfdde2b2456181045f74631683fba491d8bf4f2 - 38
libfragmentzip version: 0.64-aaf6fae83a0aa6f7aae1c94721857076d04a14e8-RELEASE
init pzb:
Error init failed
[-] An error occurred
(venv) arcane@arcanes-MacBook-Pro:~/p/ramdisk|(2cff81b1)⚡?
➤```
wait
wait
hold it
_ _
<string>:1: DeprecationWarning: 'pkgutil.find_loader' is deprecated and slated for removal in Python 3.14; use importlib.util.find_spec() instead
import pkgutil; exit(not pkgutil.find_loader("pyimg4"))
usb_timeout: 5
usb_abort_timeout_min: 0
[IOKit] Waiting for the USB handle with VID: 0x5AC, PID: 0x1227
CPID: 0x7001
Found the USB handle.
Now you can boot untrusted images.
usb_timeout: 5
usb_abort_timeout_min: 0
[IOKit] Waiting for the USB handle with VID: 0x5AC, PID: 0x1227
Found the USB handle.
[==================================================] 100.0%
[==================================================] 100.0%
[==================================================] 100.0%
[==================================================] 100.0%
[==================================================] 100.0%
[==================================================] 100.0%
[==================================================] 100.0%
(venv) arcane@arcanes-MacBook-Pro:~/p/ramdisk|(2cff81b1):zap:?
➤```
ok good
ssh cmd?
yep
➤ sudo ./sshrd.sh ssh 23:59:31
<string>:1: DeprecationWarning: 'pkgutil.find_loader' is deprecated and slated for removal in Python 3.14; use importlib.util.find_spec() instead
import pkgutil; exit(not pkgutil.find_loader("pyimg4"))
[*] Waiting for device in DFU mode
its still at the disk
it’s supposed to just connect…
then again joera1n is probably using an outdated sshrd ver…
still at da disk rn
wanna try the most recent sshrd?
git clone https://github.com/verygenericname/SSHRD_Script --recursive && cd SSHRD_Script
mk
be in dfu?
yep
kk
download succeeded
usb_timeout: 5
usb_abort_timeout_min: 0
[IOKit] Waiting for the USB handle with VID: 0x5AC, PID: 0x1227
CPID: 0x7001
Found the USB handle.
Now you can boot untrusted images.
[IOKit] Waiting for the USB handle with VID: 0x5AC, PID: 0x1227
Found the USB handle.
[-] An error occurred
(venv) arcane@arcanes-MacBook-Pro:~/SSHRD_Script|main✓
➤
how are you so cursed 😭
terry. davis.
how
try sshrd.sh 15.9 or whatever again and hope gaster actually pwns
do you live close to a 5g antenna perchance?
uhhh
"disk5" ejected.
none
none
[*] Cleaning up work directory
[*] Finished! Please use ./sshrd.sh boot to boot your device
(venv) arcane@arcanes-MacBook-Pro:~/SSHRD_Script|main✓
➤
REAL
ok great
do wut it said?
yes
before ./sshrd.sh ssh do
sudo ./sshrd.sh dump-blobs
nathan!
Warning: Permanently added '[localhost]:2222' (ECDSA) to the list of known hosts.
16168+216 records in
16375+1 records out
4192148 bytes transferred in 0.572716 secs (7319768 bytes/sec)
img4tool version: 0.197-aca6cf005c94caf135023263cbb5c61a0081804f
Compiled with plist: YES
Found IM4R extracting generator: ok
Saved IM4M to dumped.shsh
./sshrd.sh: line 380: 78606 Terminated: 15 "$oscheck"/iproxy 2222 22 >&/dev/null
[*] Onboard blobs should have dumped to the dumped.shsh file
(venv) arcane@arcanes-MacBook-Pro:~/SSHRD_Script|main:zap:?
➤ ./sshrd.sh ssh 00:10:47```
oo fun
copy all the files then zero the nand
or
eliminate all bytes
ok
heres da thing
most of wut i want
is just it already being tweaked
is it being retweaked faster or slower than finding every file to copy after the fact?
id say faster
so opt 2 pwease
indexnull_'S INSTRUCTIONS ARE PROVIDED “AS IS”, WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE INSTRUCTIONS.
(this is also your opportunity to have any second thoughts or regrets)
dd if=/dev/zero of=/dev/disk0 bs=4M
wont wipe my macbook yea? 😭
make sure ur doing it in the ssh terminal 🙃
dd if=/dev/zero of=/dev/disk0 bs=4M
tee: logs/00:19:08-2024-12-21-Darwin-24.1.0.log: Permission denied
Warning: Permanently added '[localhost]:2222' (ECDSA) to the list of known hosts.
localhost:~ root#```
‼️
it said smth ‼️
-sh: sudo: command not found
say
without sudo
oh my days
try 4096 with no m
it’s probably doing something then
4 kilobytes at a time is insane
WAH??
soon enough the ipad will reveal its true colors as an evil space alien
real
using an ipad as a storage device to run macos nd use the clickbaity half lying title "RUNNING MACOS ON A IPAD!!!!!!!!"
@bright bay would patched restored_external allow for ssv brick bypass no null bytes
this is the most insane support post I've seen wtf is this support
air 1 status is ????
air 2 status is: wiping the nand byte for byte cuz palera1n.sh shat its pants
oh wait you do use palera1n.sh on ios 12 too
maybe that’s why this happened
this isn’t the worst one 😓
yikes,,
clearly the evil ios 12 aliens don’t care
real
i blame them dropping .sh support and switching to a shittier version based on shitty core (rootless)
still not done btw
but
you have to consider that rootless is just better for most people
define root 
most people don’t want a tethered device or a large storage penalty
i go by this definition
i doubt making semi-tethered rootful isnt possible
bet it exists
exactly so
storage penalty
bindfs is like 2 - 5G and fakefs easily 10G+
delete genshin impact or smth
no.
28.1 which is surprisingly small
WHAT
uhm
well
can i unplug da air 2?
well
dis is my only cable
so who knows its batt
ik its batt is shit
prolly not
so why u asking about the air 1???
@eager briar @eager briar @eager briar @eager briar @eager briar @eager briar @eager briar @eager briar
ITS DUN
i uh, i now accidentally unplugged it but i mean it finished
dd if=/dev/zero of=/dev/disk0 bs=4M
tee: logs/00:19:08-2024-12-21-Darwin-24.1.0.log: Permission denied
Warning: Permanently added '[localhost]:2222' (ECDSA) to the list of known hosts.
localhost:~ root# sudo dd if=/dev/zero of=/dev/disk0 bs=4M
-sh: sudo: command not found
localhost:~ root# sudo dd if=/dev/zero of=/dev/disk0 bs=4M
-sh: sudo: command not found
localhost:~ root# dd if=/dev/zero of=/dev/disk0 bs=4M
dd: bs: illegal numeric value
localhost:~ root# dd if=/dev/zero of=/dev/disk0 bs=1M
dd: bs: illegal numeric value
localhost:~ root# dd if=/dev/zero of=/dev/disk0 bs=4096
dd: /dev/disk0: end of device
7812501+0 records in
7812500+0 records out
32000000000 bytes transferred in 3192.563930 secs (10023292 bytes/sec)
localhost:~ root# Connection to localhost closed by remote host.
Connection to localhost closed.
./sshrd.sh: line 380: 97664 Terminated: 15 "$oscheck"/iproxy 2222 22 >&/dev/null
(venv) arcane@arcanes-MacBook-Pro:~/SSHRD_Script|main⚡?
➤ ./sshrd.sh ssh 01:28:04
meow
tee: logs/01:28:32-2024-12-21-Darwin-24.1.0.log: Permission denied
Connection closed by ::1 port 2222
./sshrd.sh: line 380: 55426 Terminated: 15 "$oscheck"/iproxy 2222 22 >&/dev/null
(venv) arcane@arcanes-MacBook-Pro:~/SSHRD_Script|main⚡?
➤```
2 options again
:o?
restore back to 15.7.3 or go to 15.8.3
do you have blobs?
nu
there’s your answer
actually
you use tethered devices don’t you
well you can downgrade to 14 if you’re willing to stay tethered
i mean can i use this bitch wish ios 8
:3
wut it shipped w)
and dualboot cuz ik thats smth that exists
seprmvr64 
im guessing thats a yes!
take a look and see https://github.com/mineek/seprmvr64/tree/v2
(ios 14 downgrade is way better)
14 


