
iOS 27 kernelcache RE: SEP dispatch map, AMFI diff, Ghidra workflow
Linux-native cross-compiler + PoC for iOS AMFI Developer Mode activation (arm64/arm64e)
Research-grade toolkit. Diff iOS 27.0.1 vs 27.2 firmware, reverse-engineer the AMFI
IOUserClientdispatch table, cross-compile a bare-metal IOKit PoC from Linux — no Xcode required — and enable Developer Mode on iOS 27.0.1 through the stock Apple lockdown protocol (verified persistent at kernel level).
IOExternalMethodDispatch slot, identified selector 11 = armSecurityBootMode.poc/poc.c opens AppleMobileFileIntegrity/AppleCredentialManager, calls armSecurityBootMode, and logs the result. No Foundation/UIKit bloat — pure C + IOKit.poc/build_ipa.sh produces a signed .ipa on CachyOS/Arch using clang + ld64.lld + ldid. Zero Apple/Xcode dependencies.The iOS Developer Mode toggle chain can be driven entirely through the stock Apple
lockdown protocol (com.apple.amfi.lockdown). No jailbreak, no IPA, no entitlement
forging — just pymobiledevice3 on Linux.
Verified: after the chain below, mounter query-developer-mode-status → true and the
DeveloperDiskImage was mounted at /System/Developer — and both survived an independent
reboot (the same checks previously flipped back to false, so persistence is the
real proof; see FINDINGS_LOCK.md).
Remove the passcode (Settings → Face ID & Passcode → Turn Off Passcode).
With a passcode set, AMFI answers action=1/action=2 with Device has a passcode set.
# 1) enable → action=1 → REBOOT #1
flatpak-spawn --host python3 -m pymobiledevice3 amfi enable-developer-mode
# 2) after the device boots: post-restart accept → action=2 → REBOOT #2
# (the CLI has no separate accept command — call the service method directly,
# e.g. via poc/verify_now2.py)
# 3) reveal the Settings toggle → action=0
flatpak-spawn --host python3 -m pymobiledevice3 amfi reveal-developer-mode
flatpak-spawn --host python3 -m pymobiledevice3 mounter query-developer-mode-status # → true
flatpak-spawn --host python3 -m pymobiledevice3 mounter list # → IsMounted: true, /System/Developer
flatpak-spawn --host python3 -m pymobiledevice3 mounter auto-mount # → DeveloperDiskImage mounted successfully
| action | Meaning | Effect |
|---|---|---|
0 | reveal | Shows the Developer Mode toggle in Settings |
1 | enable | Sets the flag, reboots the device |
2 | accept | Post-restart confirmation, reboots again |
⚠️
pymobiledevice3short-circuits: if the status is alreadytrue,enable-developer-modejust logs "Developer mode is already enabled" and sends nothing. The two reboots are part of the Apple protocol, not incidental.
sudo pacman -S clang lld zip # compiler + Mach-O linker
yay -S ldid # entitlement injector (AUR)
# iOS SDK:
mkdir -p poc/SDK
git clone https://github.com/theos/sdks poc/tmp && mv poc/tmp/iPhoneOS*.sdk poc/SDK/iPhoneOS.sdk
cd poc
IOS_SDK=/path/to/iPhoneOS.sdk ./build_ipa.sh
# Output: EnableAMFIDevMode.ipa
# Via ideviceinstaller (libimobiledevice):
ideviceinstaller --install EnableAMFIDevMode.ipa
# Via TrollStore (if jailbroken/CT-bypass device):
# → TrollStore app → "+" → pick EnableAMFIDevMode.ipa
# Via SideStore/AltStore:
# → Add to SideStore → sign with your Apple ID
# On device (SSH / NewTerm):
./EnableAMFIDevMode 1
cat /tmp/amfi_devmode_poc.log
# Then REBOOT to activate Developer Mode
run_dvt.sh)A second, IPA-free path exists: cross-compile the standalone IOKit binary on Linux and
push it to the device through the iOS 17+ CoreDevice / RSD tunnel, then run it with the
DVT process-control service (outside the App Sandbox — no installd, no free-sign IPA).
./run_dvt.sh enable # build (clang + ld64.lld) → deploy → `dvt launch --stream`
run_dvt.sh automates the whole chain:
usbmuxd, checks the device with ideviceinfo (libimobiledevice);poc/poc.c to a bare arm64 Mach-O (no Apple toolchain):
clang -c → ld64.lld -platform_version ios … -syslibroot … -undefined dynamic_lookup;
the SDK version is read from the binary SDKSettings.plist via plistlib;dvt launch --stream.Status: the Linux cross-compile works (a real
arm64Mach-O is produced). The on-device deploy step is still WIP — seeHANDOFF.md«Сессия 12». Also note the PoC’s IOKit path (AppleMobileFileIntegrityselector 11) requires the platform-restricted entitlementcom.apple.private.amfi.developer-mode-control, so a non-Apple-signed binary will be refused by the userclient even when launched via DVT — the supported way to enable Developer Mode is the lockdown protocol documented above.
Two clean steps per architecture slice (avoids clang driver swallowing -arch/-platform_version when delegating to ld64.lld):
-arch arm64 -platform_version ios <min> <sdk>Auto-detects clang-20...15, ld64.lld/lld, llvm-lipo, ldid. Graceful fallback: arm64e → arm64 if toolchain lacks ptrauth support.