
دليل لبناء آيفون افتراضي باستخدام مكونات VPHONE600AP من برنامج PCC الخاص بشركة أبل، مع تصحيح البرامج الثابتة (firmware)، وتعديل سلسلة الإقلاع (bootchain)، وتصحيح أخطاء النواة (kernel debugging) لأبحاث أمن iOS.
في أواخر عام 2024، بدأت Apple في تقديم Private Cloud Compute، مدعية فتح آفاق جديدة لخصوصية الذكاء الاصطناعي السحابي. بعد ذلك، في أواخر عام 2025، ظهرت بعض الأخبار المثيرة للاهتمام: أضافت Apple مكونات متعلقة بـ vphone600ap إلى برنامج PCC الثابت، بدءًا من cloudOS 26.

المصدر: https://x.com/matteyeux/status/2006339694783848660/photo/1
"الآلة الافتراضية لبيئة أبحاث iPhone"؟
هل هذه خطوة مخططة من Apple لبناء وتوزيع بيئة iPhone افتراضية لباحثي الأمن الآخرين في المستقبل، أم أنها مجرد خطأ؟ نظرًا لأنه تم اكتشاف نواة بناء DEVELOPMENT/KASAN في تحديثات OTA من iOS 15.0 beta إلى 15.1 beta3 مرة أخرى في عام 2021، فلا يمكن استبعاد احتمال حدوث زلة. في ذلك الوقت، ظلت النواة مضمنة لمدة 4 أشهر تقريبًا، من يونيو إلى أكتوبر 2021 تقريبًا.
ثم، في حوالي يناير من هذا العام، تم نشر تغريدة تُظهر iPhone افتراضيًا قيد الإقلاع باستخدام هذه المكونات المتعلقة بـ vphone600ap.

المصدر: https://x.com/_inside/status/2008951845725548783

مما رأيته، كان كل شيء يعمل بشكل أنيق حقًا. مقارنة بمشروع QEMUAppleSilicon(Inferno) الذي رأيته سابقًا، فإنه يعمل بسرعة وسلاسة أكبر. علاوة على ذلك، بدا أنه يدعم تسريع Metal. في النهاية، كنت مفتونًا به تمامًا، وبدأت في بناء iPhone الافتراضي الخاص بي في 31 يناير.

المشروع المرجعي هو security-pcc. إنه يتوافق مع الكود المصدري للثنائي /System/Library/SecurityResearch/usr/bin/vrevm. نقطة مثيرة للاهتمام هي أنه يستخدم طرقًا خاصة يوفرها إطار Virtualization.framework. في الآلة الافتراضية المستخدمة لأبحاث PCC، يمكنك رؤية أن ISA و PlatformVersion يتم تحديدهما صراحةً أثناء عملية تهيئة نموذج الأجهزة.

بالنسبة للـ bootrom، يتم استخدام AVPBooter.vresearch1.bin (/System/Library/Frameworks/Virtualization.framework/Resources/AVPBooter.vresearch1.bin)

وبالنسبة للـ SEPROM (avpsepbooter)، يتم استخدام AVPSEPBooter.vresearch1.bin، والذي يقوم بتحميل ملف SEPStorage بشكل منفصل يعمل بشكل مشابه لـ AuxiliaryStorage. (/System/Library/Frameworks/Virtualization.framework/Versions/A/Resources/AVPSEPBooter.vresearch1.bin)
نقطة أخرى مثيرة للاهتمام هي أنه إذا نظرت إلى كود ضبط الدقة، فهي مضبوطة على 1290x2796، وهو ما يتوافق مع أجهزة iPhone 14 Pro Max و15 Plus و15 Pro Max و16 Plus.

بهذه المعلومات فقط، يجب أن تكون كافية لتعديل super-tart لإقلاع iPhone الافتراضي. لقد أجريت التعديلات كما هو موضح أدناه.
/Sources/tart/VM.swift```swift ... class VM: NSObject, VZVirtualMachineDelegate, ObservableObject { ... // vzHardwareModel derives the VZMacHardwareModel config specific to the "platform type" // of the VM (currently only vresearch101 supported) static private func vzHardwareModel_VRESEARCH101() throws -> VZMacHardwareModel { var hw_model: VZMacHardwareModel
guard let hw_descriptor = _VZMacHardwareModelDescriptor() else { fatalError("Failed to create hardware descriptor") } hw_descriptor.setPlatformVersion(3) // .appleInternal4 = 3 hw_descriptor.setBoardID(0x90) hw_descriptor.setISA(2) hw_model = VZMacHardwareModel._hardwareModel(withDescriptor: hw_descriptor)
guard hw_model.isSupported else { fatalError("VM hardware config not supported (model.isSupported = false)") }
return hw_model }
static func craftConfiguration( diskURL: URL, nvramURL: URL, romURL: URL, sepromURL: URL? = nil, vmConfig: VMConfig, network: Network = NetworkShared(), additionalStorageDevices: [VZStorageDeviceConfiguration], directorySharingDevices: [VZDirectorySharingDeviceConfiguration], serialPorts: [VZSerialPortConfiguration], suspendable: Bool = false, nested: Bool = false, audio: Bool = true, clipboard: Bool = true, sync: VZDiskImageSynchronizationMode = .full, caching: VZDiskImageCachingMode? = nil ) throws -> VZVirtualMachineConfiguration { let configuration: VZVirtualMachineConfiguration = .init()
// Boot loader let bootloader = try vmConfig.platform.bootLoader(nvramURL: nvramURL) Dynamic(bootloader)._setROMURL(romURL) configuration.bootLoader = bootloader
// SEP ROM let homeURL = FileManager.default.homeDirectoryForCurrentUser var sepstoragePath = homeURL.appendingPathComponent(".tart/vms/vphone/SEPStorage").path let sepstorageURL = URL(fileURLWithPath: sepstoragePath) let sep_config = Dynamic._VZSEPCoprocessorConfiguration(storageURL: sepstorageURL) if let sepromURL { // default AVPSEPBooter.vresearch1.bin from VZ framework sep_config.romBinaryURL = sepromURL } sep_config.debugStub = Dynamic._VZGDBDebugStubConfiguration(port: 8001) configuration._setCoprocessors([sep_config.asObject])
// Some vresearch101 config let pconf = VZMacPlatformConfiguration() pconf.hardwareModel = try vzHardwareModel_VRESEARCH101()
let serial = Dynamic._VZMacSerialNumber.initWithString("AAAAAA1337") let identifier = Dynamic.VZMacMachineIdentifier._machineIdentifierWithECID(0x1111111111111111, serialNumber: serial.asObject) pconf.machineIdentifier = identifier.asObject as! VZMacMachineIdentifier
pconf._setProductionModeEnabled(true) var auxiliaryStoragePath = homeURL.appendingPathComponent(".tart/vms/vphone/nvram.bin").path let auxiliaryStorageURL = URL(fileURLWithPath: auxiliaryStoragePath) pconf.auxiliaryStorage = VZMacAuxiliaryStorage(url: auxiliaryStorageURL)
if #available(macOS 14, *) { let keyboard = VZUSBKeyboardConfiguration() configuration.keyboards = [keyboard] }
if #available(macOS 14, *) { let touch = _VZUSBTouchScreenConfiguration() configuration._setMultiTouchDevices([touch]) } ... configuration.platform = pconf