
Executes at the silicon boundary
Primary Core: qslcl.asm (v0.0.2) (under development)
Assistant Module: qslcl.bin (v0.7.4)
Universal Controller: qslcl.py (v2.2.2)
Legally Protected Research - This project operates under established legal frameworks for security research, right to repair, and academic freedom. Learn more
Quantum Silicon Core Loader (QSLCL) is a post-bootloader, post-vendor, post-os layer operating directly at the silicon boundary.
It executes beyond traditional security models and is capable of surviving firmware transitions, negotiating trust, and interpreting device state without CVEs or patches.
QSLCL runs in:
"You don't run QSLCL — silicon interprets it."
device_info field to bug reports with status, code, and error detailsExample output:
[*] Injection confirmed! Fetching device info...
[*] GETINFO response: SUCCESS - OK
[CONFIRMED BUGS]
1. memory_corruption (conf: 80%)
Unexpected large response: 2048 bytes
Device state after injection: SUCCESS - OK
2. memory_corruption (conf: 75%)
Unexpected large response: 4096 bytes
Device state after injection: SUCCESS - OK
QSLCL Binary Layout (v0.7.4):
┌─────────────────────────────────────────────┐
│ 0x000000 QSLCLBIN (Main Header + Ptrs) │
│ 0x000200+ QSLCLCMD (28 Commands) │
│ 0x004000+ QSLCLDIS (Dispatch Table) │
│ 0x005000+ QSLCLUSB (USB Micro-Engine) │
│ 0x006000+ QSLCLBLK (64 Endpoints) │
│ 0x007000+ QSLCLBST (Bootstrap Engine) │
│ 0x008000+ QSLCLVM5 (Nano-Kernel) │
│ 0x009000+ QSLCLSPT (USB Setup Packets) │
│ 0x00A000+ QSLCLRTF (Runtime Fault Table) │
│ 0x00B000+ QSLCLENC (Encryption Layer) │
│ 0x00C000+ QSLCLDAT (Data Protocol) │
│ 0x00D000+ QSLCLSYN (Sync Block) │
│ 0x00E000+ QSLCLHDR (Certificate) │
│ 0x00F000+ QSLCLINT (Integrity Footer) │
│ 0x010000+ USB4V2MC (USB4 v2.0 80Gbps) │
└─────────────────────────────────────────────┘
Total Size: ~72KB (44% reduction from 128KB)
Commands: 28 (added TEST, FUZZ)
How it works (automatic):
# Build with quantum architecture (recommended)
python build.py qslcl.bin --arch quantum --encrypt --usb4-v2
# Or generic build
python build.py qslcl.bin
# Just run normally - watchdog disables automatically!
python qslcl.py hello --loader=qslcl.bin
# Expected output:
# [+] Loader uploaded.
# [*] Auto-disabling watchdog...
# [*] Detected SoC type: APPLE
# [*] Checking 10 candidate offsets...
# [*] Watchdog detected at 0x20E00000 = 0x00000001
# [+] Watchdog disabled at offset 0x20E00000
# [*] Exposing QSLCL in USB configuration...
Core Memory Operations:
| Command | Description |
|---|---|
read | Partitions Reading |
write | Partitions Writing |
erase | Partitions Erasing |
peek | Memory inspection with type interpretation and pointer analysis |
poke | Precision memory writes with bit operations (AND/OR/XOR) |
patch | Binary patching with backup, verification, and dry-run support |
dump | Bulk memory dumping with compression, verification, and metadata |
Device Interaction:
| Command | Description |
|---|---|
hello | Device handshake and capability detection |
ping | Round-trip latency testing |
getinfo | Shows device, DFU mode, watchdog, loader features |
System Control:
| Command | Description |
|---|---|
reset | System reset |
power | Power management |
config | Configuration management |
Voltage & Hardware:
| Command | Description |
|---|---|
voltage | Voltage read/set/monitor/scale with safety ranges |
rawstate | Low-level hardware state inspection and manipulation |
Security & Analysis:
| Command | Description |
|---|---|
rawmode | Privilege escalation with session audit logging |
bypass | Security bypass with auto-detection and enforcement analysis |
verify | System verification |
footer | Footer analysis with validation and security assessment |
Diagnostic & Testing:
| Command | Description |
|---|---|
crash | Controlled crash injection with recovery monitoring |
glitch | Hardware fault injection with parameter scanning |
bruteforce | Automated testing |
slowm8 | USB stress tester with auto-detection and bug injection |
Manufacturing & ODM:
| Command | Description |
|---|---|
oem | OEM operations |
odm | ODM operations |
pip install pyserial pyusb
pip install pycryptodome # optional, for crypto operations
pip install capstone # optional, for disassembly
# Build with quantum architecture (recommended)
python build.py qslcl.bin --arch quantum --usb4-v2 --encrypt --debug
# Or standard generic build
python build.py qslcl.bin
# Get detailed device information
python qslcl.py getinfo --loader=qslcl.bin
# Expected output:
# ==================================================
# QSLCL DEVICE INFORMATION
# ==================================================
# [DEVICE]
# Transport: USB
# VID:PID: 05AC:1281
# Product: iPhone 15 Pro
# USB Class: 0xFE (Application Specific)
#
# [DFU MODE]
# Status: ACTIVE
# Generation: A12 or newer (ARM64e, PAC enabled)
#
# [WATCHDOG]
# Detected SoC: Apple A-series
# Typical offset: 0x20E00000
#
# [QSLCL LOADER]
# Architecture: quantum
# Binary size: 73728 bytes (72 KB)
# Features: Encryption, USB4 v2.0 80Gbps
# ==================================================
# Auto-DFU boot + Loader + Hello (All-in-One)
python qslcl.py hello --loader=qslcl.bin --dfu-boot
# Just boot into DFU mode (like palera1n)
python qslcl.py --dfu-boot
# Test basic functionality
python qslcl.py hello --loader=qslcl.bin --usb4
python qslcl.py ping --loader=qslcl.bin
Enhanced with GETINFO verification! After confirming a bug, Slowm8 automatically fetches device state to verify injection success.
# Basic stress test with device verification
python qslcl.py slowm8 --loader=qslcl.bin
# Expected output with GETINFO:
# [*] Injection confirmed! Fetching device info...
# [*] GETINFO response: SUCCESS - OK
# [+] Bug confirmed! Device state: healthy