
Quantum-Silicon-Core-Loader — Updated!
Executes at the silicon boundary
Quantum Silicon Core Loader
Primary Core: qslcl.asm (v0.0.2) (under development)
Assistant Module: qslcl.bin (v0.7.4)
Universal Controller: qslcl.py (v2.2.2)
Legally Protected Research - This project operates under established legal frameworks for security research, right to repair, and academic freedom. Learn more
Overview
Quantum Silicon Core Loader (QSLCL) is a post-bootloader, post-vendor, post-os layer operating directly at the silicon boundary.
It executes beyond traditional security models and is capable of surviving firmware transitions, negotiating trust, and interpreting device state without CVEs or patches.
QSLCL runs in:
- Qualcomm EDL / Firehose
- MediaTek BROM / Preloader
- Apple DFU (Dynamic detection - no hardcoded PIDs)
- Engineering / META / Diagnostic Modes
- Any USB/Serial exposed interface
"You don't run QSLCL — silicon interprets it."
What's New in v2.2.2
Slowm8 GETINFO Integration
- After successful code injection, Slowm8 automatically calls GETINFO to verify device state
- Confirms injection didn't crash the device
- Detects and reports abnormal device behavior
- Adds
device_infofield to bug reports with status, code, and error details
Enhanced Bug Confirmation
- Device state verification after every successful injection
- Abnormal state detection - flags if device shows errors post-injection
- Rich output in final results showing device status for each confirmed bug
Improved Error Handling
- Better handling of unresponsive devices after injection
- Clearer error messages when GETINFO fails
- Graceful fallback when device doesn't respond to verification
Example output:
[*] Injection confirmed! Fetching device info...
[*] GETINFO response: SUCCESS - OK
[CONFIRMED BUGS]
1. memory_corruption (conf: 80%)
Unexpected large response: 2048 bytes
Device state after injection: SUCCESS - OK
2. memory_corruption (conf: 75%)
Unexpected large response: 4096 bytes
Device state after injection: SUCCESS - OK
QSLCL Binary Layout (v0.7.4):
┌─────────────────────────────────────────────┐
│ 0x000000 QSLCLBIN (Main Header + Ptrs) │
│ 0x000200+ QSLCLCMD (28 Commands) │
│ 0x004000+ QSLCLDIS (Dispatch Table) │
│ 0x005000+ QSLCLUSB (USB Micro-Engine) │
│ 0x006000+ QSLCLBLK (64 Endpoints) │
│ 0x007000+ QSLCLBST (Bootstrap Engine) │
│ 0x008000+ QSLCLVM5 (Nano-Kernel) │
│ 0x009000+ QSLCLSPT (USB Setup Packets) │
│ 0x00A000+ QSLCLRTF (Runtime Fault Table) │
│ 0x00B000+ QSLCLENC (Encryption Layer) │
│ 0x00C000+ QSLCLDAT (Data Protocol) │
│ 0x00D000+ QSLCLSYN (Sync Block) │
│ 0x00E000+ QSLCLHDR (Certificate) │
│ 0x00F000+ QSLCLINT (Integrity Footer) │
│ 0x010000+ USB4V2MC (USB4 v2.0 80Gbps) │
└─────────────────────────────────────────────┘
Total Size: ~72KB (44% reduction from 128KB)
Commands: 28 (added TEST, FUZZ)
How it works (automatic):
# Build with quantum architecture (recommended)
python build.py qslcl.bin --arch quantum --encrypt --usb4-v2
# Or generic build
python build.py qslcl.bin
# Just run normally - watchdog disables automatically!
python qslcl.py hello --loader=qslcl.bin
# Expected output:
# [+] Loader uploaded.
# [*] Auto-disabling watchdog...
# [*] Detected SoC type: APPLE
# [*] Checking 10 candidate offsets...
# [*] Watchdog detected at 0x20E00000 = 0x00000001
# [+] Watchdog disabled at offset 0x20E00000
# [*] Exposing QSLCL in USB configuration...
Complete Command List (v2.2.1)
Core Memory Operations:
| Command | Description |
|---|---|
read | Partitions Reading |
write | Partitions Writing |
erase | Partitions Erasing |
peek | Memory inspection with type interpretation and pointer analysis |
poke | Precision memory writes with bit operations (AND/OR/XOR) |
patch | Binary patching with backup, verification, and dry-run support |
dump | Bulk memory dumping with compression, verification, and metadata |
Device Interaction:
| Command | Description |
|---|---|
hello | Device handshake and capability detection |
ping | Round-trip latency testing |
getinfo | Shows device, DFU mode, watchdog, loader features |
System Control:
| Command | Description |
|---|---|
reset | System reset |
power | Power management |
config | Configuration management |
Voltage & Hardware:
| Command | Description |
|---|---|
voltage | Voltage read/set/monitor/scale with safety ranges |
rawstate | Low-level hardware state inspection and manipulation |
Security & Analysis:
| Command | Description |
|---|---|
rawmode | Privilege escalation with session audit logging |
bypass | Security bypass with auto-detection and enforcement analysis |
verify | System verification |
footer | Footer analysis with validation and security assessment |
Diagnostic & Testing:
| Command | Description |
|---|---|
crash | Controlled crash injection with recovery monitoring |
glitch | Hardware fault injection with parameter scanning |
bruteforce | Automated testing |
slowm8 | USB stress tester with auto-detection and bug injection |
Manufacturing & ODM:
| Command | Description |
|---|---|
oem | OEM operations |
odm | ODM operations |
Installation & Quick Start
Requirements
pip install pyserial pyusb
pip install pycryptodome # optional, for crypto operations
pip install capstone # optional, for disassembly
Basic Usage
# Build with quantum architecture (recommended)
python build.py qslcl.bin --arch quantum --usb4-v2 --encrypt --debug
# Or standard generic build
python build.py qslcl.bin
# Get detailed device information
python qslcl.py getinfo --loader=qslcl.bin
# Expected output:
# ==================================================
# QSLCL DEVICE INFORMATION
# ==================================================
# [DEVICE]
# Transport: USB
# VID:PID: 05AC:1281
# Product: iPhone 15 Pro
# USB Class: 0xFE (Application Specific)
#
# [DFU MODE]
# Status: ACTIVE
# Generation: A12 or newer (ARM64e, PAC enabled)
#
# [WATCHDOG]
# Detected SoC: Apple A-series
# Typical offset: 0x20E00000
#
# [QSLCL LOADER]
# Architecture: quantum
# Binary size: 73728 bytes (72 KB)
# Features: Encryption, USB4 v2.0 80Gbps
# ==================================================
# Auto-DFU boot + Loader + Hello (All-in-One)
python qslcl.py hello --loader=qslcl.bin --dfu-boot
# Just boot into DFU mode (like palera1n)
python qslcl.py --dfu-boot
# Test basic functionality
python qslcl.py hello --loader=qslcl.bin --usb4
python qslcl.py ping --loader=qslcl.bin
Slowm8 - USB Stress Tester (v2.2.2)
Enhanced with GETINFO verification! After confirming a bug, Slowm8 automatically fetches device state to verify injection success.
# Basic stress test with device verification
python qslcl.py slowm8 --loader=qslcl.bin
# Expected output with GETINFO:
# [*] Injection confirmed! Fetching device info...
# [*] GETINFO response: SUCCESS - OK
# [+] Bug confirmed! Device state: healthy