Add firmware: IPSW library, Apple signing status, and installation - #4
Merged
Merged
Conversation
The ZIP reader now handles ZIP64 end records and entries, can locate the central directory from just the end of a file (so one entry can be read from a remote archive), and takes a size limit per archive, since an IPSW holds several gigabytes. The developer-image signing code exposes its request rules, client version, and reply parsing, and a device session can ask the device to restart into recovery mode. hideouts.io
- Apple's firmware list (itunes.apple.com/check/version), cached for a day, with Apple's SHA-1 for each IPSW. - Build manifests read from an IPSW on Apple's CDN with range requests. - Whether Apple signs a build: a TSS request built as libtatsu builds the application-processor request, with a random ECID and nonce. - A local IPSW library with SHA-1/SHA-256 verification, and resumable downloads that are kept only when they match Apple's checksum. - The bundled idevicerestore and irecovery: locating them, recovery and DFU detection, install command vectors, streamed progress, plain failure reasons, and the checks made before installing. Unit tests cover each part without the network; opt-in network tests check Apple's live list, a remote manifest, and signing. hideouts.io
scripts/build-restore-helpers.sh builds idevicerestore and irecovery from pinned libimobiledevice commits, libzip, and a checksum-verified OpenSSL release, as universal executables that depend only on macOS system libraries. The release script reuses that build while the script is unchanged, places the helpers in Contents/Helpers, signs them with the hardened runtime, checks that they run on both architectures, adds their licenses, and attaches their complete source to the release. The linked-library checks now read the app's executable through a link: otool treated its name ending in "(Swift)" as an archive member and silently skipped it. hideouts.io
A new page under Device shows the device and its mode (normal, recovery, or DFU), Apple's current firmware for it with signing status and downloads, the IPSW library, and installation: Update keeps data, Restore erases it and needs the high-impact confirmation, and Check Before Installing changes nothing. Stop is refused once the system is being written. Enter and Exit Recovery Mode and DFU instructions are included. The README, MIGRATION (section 10), architecture, and safety documents describe it, including the exception to bundling third-party tools. hideouts.io
hideouts-io
enabled auto-merge (squash)
September 29, 2026 21:53
The release packaging check builds the firmware helpers too, so it needs autoconf, automake, libtool, pkg-config, and cmake, and reuses the helper build from the same pinned sources through the cache, like the release workflow. Its time limit allows for a first, uncached build. hideouts.io
xctrace exits with status 2 when it saw problems during a recording but
still wrote a usable trace ("trace is still ready to be viewed"). DVT
logging treated that as a failure; it now reads the trace and shows
Instruments' message as a note. This is what failed the simulator
end-to-end test on the CI runner.
hideouts.io
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds a Firmware page under Device, and bundles
idevicerestoreandirecoveryfrom the libimobiledevice project to install firmware.Firmware page
Helpers
scripts/build-restore-helpers.shbuilds them from pinned commits and a checksum-verified OpenSSL release as universal executables that link only macOS system libraries.Contents/Helpers, signs them with the hardened runtime, checks both architectures, ships their licenses, and attaches their complete source (…-firmware-helpers-source.tar.gz).irecovery -kand--pwnare not used).Also
otooltreated a name ending in "(Swift)" as an archive member and silently skipped it.Testing
Not yet tested on a device: entering or leaving recovery mode, DFU detection, Check Before Installing against a device, and Update or Restore. These need a device that can be erased.
hideouts.io