Experimental Linux 6.6 bring-up for the Apple iPhone 4S (iPhone4,1,
N94AP, S5L8940X). The current development chain reaches an ARMv7 Alpine
userspace on physical hardware and can expose USB serial, USB Ethernet, and
SSH.
This repository contains source code and reproducible patches only. It does not contain Apple firmware, decrypted boot components, IPSW files, jailbreak payloads, device dumps, credentials, or prebuilt operating-system images.
| Component | Status |
|---|---|
| ARMv7 kernel entry and paging | Working on hardware |
| Linux 6.6 userspace / PID 1 | Working on hardware |
| Simple framebuffer and fbcon | Working on hardware |
| Alpine ARMv7 initramfs | Working on hardware |
| Xorg fbdev and XFCE userspace | Starts on hardware; no GPU acceleration |
| Clocksource and clockevent | Working with the current polling implementation |
| Apple AIC interrupt dispatch | Working for the tested USB path |
| Synopsys DWC2 peripheral mode | Working on hardware |
| CDC ACM serial | Working on hardware |
| CDC ECM Ethernet and SSH | Working on hardware |
| Multitouch | Not implemented |
| NAND/root filesystem | Not implemented |
| Wi-Fi, audio, battery, charging | Not implemented |
| GPU acceleration | Not available |
| Persistent or device-only boot | Not implemented or published |
The verified workflow is a host-assisted, volatile RAM boot. It does not modify NAND and is not a dual-boot installer.
patches/linux-6.6-n94.patch— changes against upstream Linux 6.6.configs/n94.config— configuration used for the current bring-up kernel.boot/— ARM stages, image headers, linker scripts, and N94 device tree.rootfs/minimal/— minimal no-libc PID 1 source and initramfs manifest.rootfs/alpine/— Alpine ARMv7/Xorg/XFCE rootfs builder.tools/— image packer and read-only Apple DeviceTree/PMGR inspection tools.docs/— build, hardware, status, and contribution notes.
- Obtain Linux 6.6 from an official kernel source.
- Apply
patches/linux-6.6-n94.patch. - Copy
configs/n94.configto the kernel tree as.configand select an initramfs source appropriate for the intended test. - Build an ARMv7
zImagewith a suitable cross compiler. - Use
tools/n94_pack.pyto assemble the N94 boot bundle.
See docs/BUILD.md for the expected directory layout and verification steps. The boot procedure intentionally omits redistribution of Apple components; researchers must obtain any required firmware lawfully from their own device or Apple-provided restore image.
This is early hardware-enablement work. A failed RAM boot should be recoverable through DFU, but experimental boot code can hang the device and may cause data loss if extended to storage writes. The published code does not require or perform persistent boot configuration changes.
The project is licensed under GPL-2.0-only. Linux-derived files remain subject to the Linux kernel's license and copyright notices. Third-party projects are not vendored; see NOTICE.md.