Age | Commit message (Collapse) | Author | Files | Lines | |
---|---|---|---|---|---|
2023-11-15 | restore: Fix UaF | tihmstar | 1 | -2/+2 | |
`fsname_base` points inside the dynamically allocated `path` which is freed before `fsname_base` is used, creating a use-after-free condition. This commits makes sure to free `path` only after it is no longer needed. | |||||
2023-11-15 | asr: Fix sending payload without checksum | tihmstar | 1 | -4/+6 | |
2023-11-09 | Fix update restore by making sure the premanifest is properly generated | Nikias Bassen | 3 | -14/+32 | |
2023-11-09 | Print progress for large components (e.g. Cryptex) | Nikias Bassen | 5 | -13/+41 | |
2023-11-08 | .gitignore: Add src/idevicerestore.exe | Nikias Bassen | 1 | -0/+1 | |
2023-11-07 | Print device Product and Build Version and IPSW Product and Build Version | Nikias Bassen | 2 | -18/+26 | |
It wasn't entirely clear what "Product Version" and "Product Build" would be so prefixing it with "IPSW" makes it clear it's the version being restored. | |||||
2023-11-02 | Extract OS component when using older ipsw archives | Nikias Bassen | 7 | -11/+143 | |
Older ipsw archives have the root filesystem stored in compressed format rather than just "stored". The "Verifying Filesystem" step would then fail as compressed files are not seekable in ZIP files. This commit introduces a detection for this and has the filesystem extracted should it be required. If not using a cache path, the temp file used for extraction will be deleted after the procedure is completed. | |||||
2023-10-09 | tss: Add USBPortController1,* entries to parameters | Nikias Bassen | 1 | -0/+4 | |
2023-10-07 | Improve debug output by suppressing libimobiledevice and libirecovery debug ↵ | Nikias Bassen | 2 | -3/+7 | |
output by default To get libimobiledevice and libirecovery output, add -d or --debug twice. | |||||
2023-10-06 | restore: Also print checkpoint warning messages | Nikias Bassen | 1 | -0/+4 | |
2023-10-06 | restore: Add Ace3 as known updater name to suppress error message | Nikias Bassen | 1 | -0/+6 | |
2023-10-06 | restore: Skip adding FirmwareData to FirmwareResponseData for Rose | Nikias Bassen | 1 | -0/+6 | |
2023-10-04 | restore: Improve checkpoint log output again, make sure to always check for ↵ | Nikias Bassen | 1 | -5/+8 | |
errors Turns out even with a CHECKPOINT_RESULT of 0 we can still have a CHECKPOINT_ERROR string. | |||||
2023-10-04 | restore: Refine checkpoint log output | Nikias Bassen | 1 | -6/+15 | |
2023-10-04 | restore/tss: Prefer DeviceGeneratedRequest for Rose TSS request, and add ↵ | Nikias Bassen | 2 | -4/+11 | |
missing tag | |||||
2023-10-02 | restore: Add new SE,ChipID 0x36 to list of known values | Nikias Bassen | 1 | -1/+1 | |
2023-10-02 | restore: Attributed status code 50 with SEP load failure | Nikias Bassen | 1 | -0/+1 | |
2023-10-02 | restore: Handle SepStage1 (SEPPatchImageData) in NORImageData | Nikias Bassen | 1 | -0/+25 | |
2023-09-29 | tss: Add Ap,SikaFuse to TSS request as seen for iPhone 14/15 devices | Nikias Bassen | 1 | -0/+8 | |
This is currently implemented as a workaround as the evaluation of when this value should be set is unclear. Right now we set it when UID_MODE is set too. | |||||
2023-09-14 | Refactor ipsw code to transparently stream images directly from ZIP or ↵ | Nikias Bassen | 9 | -355/+272 | |
extracted ipsw This allows flashing directly from IPSW archive without having to extract it first, and ultimately removes the "Extracting filesystem from IPSW" part. Restoring from extracted IPSW is also supported, just pass the path to the directory that has all the files from a given IPSW. | |||||
2023-09-14 | [github-actions] Updated to use upload-artifact@v3 | Nikias Bassen | 1 | -3/+3 | |
2023-09-14 | autoconf: Link against libusbmuxd too | Nikias Bassen | 2 | -0/+5 | |
2023-09-14 | [github-actions] Updated to use checkout@v3 | Nikias Bassen | 1 | -3/+3 | |
2023-09-14 | tss: Make missing ApNonce non-fatal for IMG3 | Nikias Bassen | 1 | -2/+1 | |
For IMG3 devices, DFU does not provide ApNonce, but a valid SHSH is needed to boot into iBSS (which then does provide ApNonce). Thanks to @tihmstar for providing the fix! | |||||
2023-09-13 | normal: Don't do unpair before entering recovery mode, remove pairing record ↵ | Nikias Bassen | 1 | -6/+4 | |
afterwards instead | |||||
2023-09-13 | restore: Remove plist debug print for non-existent UniqueBuildID | Nikias Bassen | 1 | -1/+4 | |
and print it in a better format if it does exist | |||||
2023-09-06 | fdr: Fix a debug log message | Nikias Bassen | 1 | -1/+1 | |
2023-09-06 | tss: Bump auth client version to match iOS 16.5 | Daniel VanBritsom | 1 | -1/+1 | |
Sourced from the iOS 16.5 UpdateBrain.dylib | |||||
2023-07-25 | Add generic TSS request generator | Clément Decoodt | 1 | -2/+67 | |
This uses the DeviceGeneratedRequest and DeviceGeneratedTags to generate the full TSS request. This allows to have a more future-proof approach to new firmware names they add. | |||||
2023-07-25 | Add SE,ChipID 0x2C | Clément Decoodt | 1 | -1/+1 | |
2023-07-25 | Display iBoot boot stage | Clément Decoodt | 2 | -0/+29 | |
This helps debugging cases where the iDevice does not go into stage 2 because of a missing firmware | |||||
2023-07-25 | Add support for incoherent iBoot parameters | Clément Decoodt | 1 | -5/+7 | |
Some firmwares to load during iBoot stage 1 can have both: - isLoadedByiBoot = false - isLoadedByiBootStage1 = true This allows to load it at stage 1 | |||||
2023-05-23 | Use DeviceGeneratedRequest plist for SE TSS requests | Clément Decoodt | 2 | -8/+22 | |
2023-04-30 | Make sure git-version-gen and .tarball-version are included in dist tarball | Nikias Bassen | 1 | -1/+5 | |
2023-04-30 | git-version-gen: Prevent multiple lines of output | Nikias Bassen | 1 | -1/+2 | |
2023-04-21 | Updated to use latest libplist API | Nikias Bassen | 2 | -2/+2 | |
2023-04-14 | docs: Updated man page | Nikias Bassen | 1 | -32/+77 | |
2023-04-14 | Allow setting custom TSS request URL through command line switch | Nikias Bassen | 2 | -6/+34 | |
2023-04-13 | img4: Remove unused debug code | Nikias Bassen | 1 | -31/+0 | |
2022-10-19 | restore: Fix compilation error due to wrong variable name | Nikias Bassen | 1 | -2/+2 | |
2022-10-19 | restore: Only print boot object v3/v4 plist in debug mode | Nikias Bassen | 1 | -2/+8 | |
2022-10-18 | Use limera1n_is_supported instead of compatibility check added with previous ↵ | Nikias Bassen | 1 | -17/+1 | |
commit | |||||
2022-10-12 | Check if device is limera1n-vulnerable for --pwn option | Alfie Cockell Gwinnett | 1 | -8/+30 | |
2022-10-11 | recovery: Also send "go" and "reset" commands with bRequest set to 1 | Nikias Bassen | 1 | -2/+2 | |
2022-10-08 | recovery: Send bootx with bRequest set to 1 for all platforms | Nikias Bassen | 1 | -1/+1 | |
2022-10-07 | [github-actions] Fix MinGW build | Nikias Bassen | 1 | -1/+1 | |
2022-10-05 | recovery: set bRequest to 1 when sending bootx command | Munehisa Kamata | 1 | -1/+1 | |
In macOS 13 beta 8 or newer release, bootx seems to fail if bRequest is 0 in the control transfer setup. Then, the device fails to enter restore mode. Seems like something has changed in iBEC since beta 8 and Apple Configurator 2 has set it to 1, so do the same thing. While this could be applied for all *OS variants, it's limited to macOS for now just to be safe. Signed-off-by: Munehisa Kamata <kamatam@amazon.com> | |||||
2022-10-04 | img4: Add support for stitching with additional TBM data | Nikias Bassen | 3 | -7/+191 | |
2022-10-02 | Reduce memory usage for SourceBootObjectV4 images | Nikias Bassen | 4 | -91/+201 | |
2022-09-25 | tss: Add preliminary code to set UID_MODE | Nikias Bassen | 1 | -0/+12 | |