Skip to content

Add firmware: IPSW library, Apple signing status, and installation - #4

Merged
hideouts-io merged 6 commits into
mainfrom
firmware
Sep 30, 2026
Merged

hideouts-io merged 6 commits into
mainfrom
firmware

Conversation

@hideouts-io

Copy link
Copy Markdown
Owner

Adds a Firmware page under Device, and bundles idevicerestore and irecovery from the libimobiledevice project to install firmware.

Firmware page

  • The device and its mode (normal, recovery, or DFU); Enter and Exit Recovery Mode; DFU instructions.
  • Apple's current firmware for the model (Finder's firmware list), whether Apple still signs it, and downloads that resume and are kept only when the SHA-1 matches Apple's.
  • The IPSW library: add, check signing, verify (SHA-1 and SHA-256), show in Finder, move to the Trash.
  • Install: Update keeps data; Restore erases and needs the high-impact confirmation. Check Before Installing (model, install type, Apple signing, device found) changes nothing. Stop is refused once the system is being written.

Helpers

  • scripts/build-restore-helpers.sh builds them from pinned commits and a checksum-verified OpenSSL release as universal executables that link only macOS system libraries.
  • The release places them in Contents/Helpers, signs them with the hardened runtime, checks both architectures, ships their licenses, and attaches their complete source (…-firmware-helpers-source.tar.gz).
  • This is a documented exception to not bundling third-party tools (MIGRATION §10). No exploits are exposed (irecovery -k and --pwn are not used).

Also

  • ZIP64 support in the ZIP reader.
  • The release script's linked-library checks now actually read the app's executable. otool treated a name ending in "(Swift)" as an archive member and silently skipped it.

Testing

  • 213 package tests pass, including 14 new firmware tests.
  • The opt-in network tests pass against Apple's live services. Apple answers "Signed" for iPhone18,1 27.0.1 (24A446).
  • A local release build passes, and the packaged app runs its bundled helpers.
  • The layout check passes at both window sizes.

Not yet tested on a device: entering or leaving recovery mode, DFU detection, Check Before Installing against a device, and Update or Restore. These need a device that can be erased.

hideouts.io

The ZIP reader now handles ZIP64 end records and entries, can locate the
central directory from just the end of a file (so one entry can be read
from a remote archive), and takes a size limit per archive, since an
IPSW holds several gigabytes. The developer-image signing code exposes
its request rules, client version, and reply parsing, and a device
session can ask the device to restart into recovery mode.

hideouts.io
- Apple's firmware list (itunes.apple.com/check/version), cached for a
  day, with Apple's SHA-1 for each IPSW.
- Build manifests read from an IPSW on Apple's CDN with range requests.
- Whether Apple signs a build: a TSS request built as libtatsu builds
  the application-processor request, with a random ECID and nonce.
- A local IPSW library with SHA-1/SHA-256 verification, and resumable
  downloads that are kept only when they match Apple's checksum.
- The bundled idevicerestore and irecovery: locating them, recovery and
  DFU detection, install command vectors, streamed progress, plain
  failure reasons, and the checks made before installing.

Unit tests cover each part without the network; opt-in network tests
check Apple's live list, a remote manifest, and signing.

hideouts.io
scripts/build-restore-helpers.sh builds idevicerestore and irecovery
from pinned libimobiledevice commits, libzip, and a checksum-verified
OpenSSL release, as universal executables that depend only on macOS
system libraries. The release script reuses that build while the script
is unchanged, places the helpers in Contents/Helpers, signs them with
the hardened runtime, checks that they run on both architectures, adds
their licenses, and attaches their complete source to the release.

The linked-library checks now read the app's executable through a link:
otool treated its name ending in "(Swift)" as an archive member and
silently skipped it.

hideouts.io
A new page under Device shows the device and its mode (normal, recovery,
or DFU), Apple's current firmware for it with signing status and
downloads, the IPSW library, and installation: Update keeps data,
Restore erases it and needs the high-impact confirmation, and Check
Before Installing changes nothing. Stop is refused once the system is
being written. Enter and Exit Recovery Mode and DFU instructions are
included. The README, MIGRATION (section 10), architecture, and safety
documents describe it, including the exception to bundling
third-party tools.

hideouts.io
@hideouts-io
hideouts-io enabled auto-merge (squash) September 29, 2026 21:53
The release packaging check builds the firmware helpers too, so it
needs autoconf, automake, libtool, pkg-config, and cmake, and reuses the
helper build from the same pinned sources through the cache, like the
release workflow. Its time limit allows for a first, uncached build.

hideouts.io
xctrace exits with status 2 when it saw problems during a recording but
still wrote a usable trace ("trace is still ready to be viewed"). DVT
logging treated that as a failure; it now reads the trace and shows
Instruments' message as a note. This is what failed the simulator
end-to-end test on the CI runner.

hideouts.io
@hideouts-io
hideouts-io merged commit c74383a into main Sep 30, 2026
7 checks passed
@hideouts-io
hideouts-io deleted the firmware branch September 30, 2026 01:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant