LukeZGD / Legacy-iOS-Kit

An all-in-one tool to restore/downgrade, save SHSH blobs, and jailbreak legacy iOS devices
GNU General Public License v3.0
1.17k stars 110 forks source link

Failed to tethered downgrade iPhone3,3 #378

Closed Jefferyat closed 8 months ago

Jefferyat commented 8 months ago

Legacy iOS Kit

[Log] Selected IPSW file: /Users/apple/Downloads/iPSW/iPhone 4 iPSW/iPhone 4 CDMA/iPhone3,3_4.2.6_8E200_Restore.ipsw [Log] Getting version from IPSW Archive: /Users/apple/Downloads/iPSW/iPhone 4 iPSW/iPhone 4 CDMA/iPhone3,3_4.2.6_8E200_Restore.ipsw inflating: ./Restore.plist
[Log] Verifying /Users/apple/Downloads/iPSW/iPhone 4 iPSW/iPhone 4 CDMA/iPhone3,3_4.2.6_8E200_Restore.ipsw... [Log] IPSW SHA1sum matches

Legacy iOS Kit

[Input] Memory Option for creating custom IPSW

[Log] Found existing Custom IPSW. Skipping IPSW creation. [Log] Found existing saved 7.1.2 blobs: ../saved/shsh/2728127595308_iPhone3,3_n92ap_7.1.2-11D257_3a88b7c3802f2f0510abc432104a15ebd8bd7154.shsh2 [Input] PwnDFU Tool Option

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

client protocol version 12 unable to open /usr/local/share/restore//options.n92.plist: No such file or directory UUID 951C0569-EE91-DB6B-3E71-A08DC1677D49 Restore options: UpdateBaseband => <CFBoolean 0x20a460 [0x2099fc]>{value = false} UUID => <CFString 0xc0b220 [0x2099fc]>{contents = "951C0569-EE91-DB6B-3E71-A08DC1677D49"} MinimumSystemPartition => <CFNumber 0xc0af10 [0x2099fc]>{value = +1112, type = kCFNumberSInt64Type} SystemPartitionSize => <CFNumber 0xc0b1c0 [0x2099fc]>{value = +1112, type = kCFNumberSInt64Type} FlashNOR => <CFBoolean 0x20a460 [0x2099fc]>{value = false} CreateFilesystemPartitions => <CFBoolean 0x20a458 [0x2099fc]>{value = true} entering partition_nand_device device supports boot-from-NAND AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleUSBDeviceMux::handleConnectResult new session 0x84308b00 established 62078<-lo0->49155 62078<-usb->13886 AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

[FTL:MSG] VSVFL Register [OK] [FTL:MSG] VFL Init [OK] [WMR:INF] Formatting with metadata whitening [FTL:MSG] Calling VFL_FactoryReformat() irst Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

AppleS5L8920XIOPFMI: ERROR: First Failing CE: 0

[VFL:INF] BBT found for CS 0 [VFL:INF] BBT found for CS 1 [VFL:INF] BBT found for CS 2 [VFL:INF] BBT found for CS 3 [FTL:MSG] VFL_Format [OK] [FTL:MSG] YAFTL Register [OK] [FTL:MSG] FTL Init [OK] [FTL:MSG] FTL Format [OK] [FTL:MSG] Write Signature OK 0x43313131 [FTL:MSG] Read back Signature OK [FTL:MSG] VFL_Open [OK] yaFTL::YAFTL_Open(l:2988): CXT is not valid . Performing full NAND R/O restore ...
unrecognized request 'GetValue' AppleUSBDeviceMux::handleConnectResult new session 0x84308f80 established 62078<-lo0->49156 62078<-usb->14142 [FTL:MSG] FTL_Open [OK] [NAND] _borrowSpareBlocks:325 found 0 previously allocated [NAND] _stressBlock:842 CE 3 Block 4149 PASSED [NAND] _stressBlock:842 CE 3 Block 4143 PASSED [NAND] _stressBlock:842 CE 3 Block 4141 PASSED [NAND] _stressBlock:842 CE 3 Block 4139 PASSED [NAND] _stressBlock:842 CE 3 Block 4137 PASSED [NAND] _stressBlock:842 CE 3 Block 4135 PASSED AppleS5L8930XUSBArbitrator::handleUSBCableTypeChange : no change in cable-type AppleImage3NORAccess::start imageVersion: 3 recv(10, 4) failed: connection closed unable to read message size: -1 could not receive message close(caller = 0x5d2f): remote port = 49153 void AppleUSBDeviceMux::handleMuxTCPInput(mbuf*) received reset, closing 0x84306000 unable to check is-bfn-partitioned property nand device is already partitioned entering wait_for_storage_device entering format_effaceable_storage effaceable storage formatted successfully entering ramrod_probe_media find_filesystem_partitions: storage=/dev/disk0 system= data= update= entering check_for_restore_log partition path has not been populated (partition may not exist) entering clean_NAND NAND format complete entering ramrod_probe_media find_filesystem_partitions: storage=/dev/disk0 system= data= update= entering format_storage_for_LwVM use-lwvm property not found entering create_filesystem_partitions unable to open : No such file or directory creating 2 partitions creating encrypted data partition entering ramrod_probe_media device partitioning scheme is GPT find_filesystem_partitions: storage=/dev/disk0 system=/dev/disk0s1 data=/dev/disk0s2s1 update= wipe entire partition: 1 (old = 0 new = 1112) block size for /dev/disk0s1: 8192 /sbin/newfs_hfs -s -v System -b 8192 -n a=8192,c=8192,e=8192 /dev/disk0s1 executing /sbin/newfs_hfs -s -v System -b 8192 -n a=8192,c=8192,e=8192 /dev/disk0s1 Initialized /dev/rdisk0s1 as a 1 GB HFS Plus volume block size for /dev/disk0s2s1: 8192 /sbin/newfs_hfs -s -v Data -J -P -b 8192 -n a=8192,c=8192,e=8192 /dev/disk0s2s1 executing /sbin/newfs_hfs -s -v Data -J -P -b 8192 -n a=8192,c=8192,e=8192 /dev/disk0s2s1 recv(15, 4) failed: connection closed unable to read message size: -1 could not receive message close(caller = 0x5d2f): remote port = 49156 unrecognized request 'GetValue' void AppleUSBDeviceMux::handleMuxTCPInput(mbuf*) received reset, closing 0x84308f80 AppleUSBDeviceMux::handleConnectResult new session 0x84306000 established 62078<-lo0->49157 62078<-usb->14398 Initialized /dev/rdisk0s2s1 as a 14 GB HFS Plus volume with a 8192k journal entering restore_images executing /usr/sbin/asr -source asr://localhost:12345 -target /dev/disk0s1 -erase -noprompt --chunkchecksum --puppetstrings /usr/sbin/asr was terminated by signal 9

ERROR: Unable to restore device

[Log] Restoring done! Read the message below if any error has occurred:

Jefferyat commented 8 months ago

This is also a problem with any tethered downgrades on iPad 1 and other devices as well

LukeZGD commented 8 months ago

This will need more checking, I know for sure that the tethered downgrades work fine on A5 and A6 devices

I think the ones with the issues will be:

LukeZGD commented 8 months ago

please test again on v24.01.18 if the issues still occur

Jefferyat commented 8 months ago

in v24.01.18 the issue on my iPhone3,3 still occurs

Legacy iOS Kit

[Log] Selected IPSW file: /Users/apple/Downloads/iPSW/iPhone 4 iPSW/iPhone 4 CDMA/iPhone3,3_4.2.6_8E200_Restore.ipsw [Log] Getting version from IPSW Archive: /Users/apple/Downloads/iPSW/iPhone 4 iPSW/iPhone 4 CDMA/iPhone3,3_4.2.6_8E200_Restore.ipsw inflating: ./Restore.plist
[Log] Verifying /Users/apple/Downloads/iPSW/iPhone 4 iPSW/iPhone 4 CDMA/iPhone3,3_4.2.6_8E200_Restore.ipsw... [Log] IPSW SHA1sum matches

Legacy iOS Kit

[Input] Memory Option for creating custom IPSW

[Log] Found existing Custom IPSW. Skipping IPSW creation. [Log] Found existing saved 7.1.2 blobs: ../saved/shsh/2728127595308_iPhone3,3_n92ap_7.1.2-11D257_3a88b7c3802f2f0510abc432104a15ebd8bd7154.shsh2 [Input] PwnDFU Tool Option

ERROR: Unable to restore device

[Log] Restoring done! Read the message below if any error has occurred:

LukeZGD commented 8 months ago

Have you deleted the old existing custom IPSW before retrying?

Jefferyat commented 8 months ago

Yes i did delete the old custom one and re-tried still same thing

Jefferyat commented 8 months ago

Same issue on iPad 1 iOS 3.2 - new firmware created and still same problems

Legacy iOS Kit

[Log] Selected IPSW file: /Users/apple/Downloads/iPSW/iPad 1 iPSW/iPad1,1_3.2_7B367_Restore.ipsw [Log] Getting version from IPSW Archive: /Users/apple/Downloads/iPSW/iPad 1 iPSW/iPad1,1_3.2_7B367_Restore.ipsw inflating: ./Restore.plist
[Log] Getting SHA1 hash from The Apple Wiki... % Total % Received % Xferd Average Speed Time Time Time Current Dload Upload Total Spent Left Speed 100 30969 0 30969 0 0 31893 0 --:--:-- --:--:-- --:--:-- 31861 [Log] Verifying /Users/apple/Downloads/iPSW/iPad 1 iPSW/iPad1,1_3.2_7B367_Restore.ipsw... [Log] IPSW SHA1sum matches

Legacy iOS Kit

[Log] Checking firmware keys in ../resources/firmware/iPad1,1/7B367 [Log] Preparing config file <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">

FilesystemJailbreak needPref iBootPatches debugEnabled bootArgsInjection bootArgsString -v

[Log] Generating firmware bundle for iPad1,1-3.2 (7B367) ... Archive: /Users/apple/Downloads/iPSW/iPad 1 iPSW/iPad1,1_3.2_7B367_Restore.ipsw inflating: manifest
Archive: /Users/apple/Downloads/iPSW/iPad 1 iPSW/iPad1,1_3.2_7B367_Restore.ipsw inflating: 018-7226-009.dmg
/tmp/xpwn/ipsw-patch/img3.c:createAbstractFileFromImg3:643: 47e8f1574e01af33ba5cfdc45153b0e621f17080f36537179be23db3dd35f893ec01874b621e4b33aa760c9924231922 No such file or directory <?xml version="1.0" encoding="UTF-8"?><!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">

Filename/Users/apple/Downloads/iPSW/iPad 1 iPSW/iPad1,1_3.2_7B367_Restore.ipsw RootFilesystem018-7223-007.dmg RootFilesystemKey2be8f3a0a02f2d259c9b297cb2d156a85adf79fed4ffe88c546a42c2a47aa55f70cadebd RootFilesystemSize1030 RamdiskOptionsPath/usr/local/share/restore/options.plist SHA1172e8297af74b91971a802e6ad137c891f553099 RamdiskPatches asr Fileusr/sbin/asrPatchasr.patch restoredexternal Fileusr/local/bin/restored_externalPatchrestoredexternal.patch FilesystemPatches FirmwarePatches iBSSFileFirmware/dfu/iBSS.k48ap.RELEASE.dfuIVb83ba3ecc1919d4dc80a560230b80910Keyeb3c9eabd45eb5701fe1998d570fa38a31ba2807918345a5c7efe0fff7ce1bea PatchiBSS.k48ap.RELEASE.patch Decrypt iBECFileFirmware/dfu/iBEC.k48ap.RELEASE.dfuIV5e0b3d5aee240120e0c6dcc64034324fKeyd127363289fe0b1b2d6b9f758b0616f0c6751e2b870cc434ac34a57ef64858fa PatchiBEC.k48ap.RELEASE.patch Decrypt Restore RamdiskFile018-7226-009.dmgIV9c051576ddd94f48c324cf7ac3197fe1Key31e7ecd9c364414205a8fa0092cc80c0d67eae40e75ffa27b37048c42335a106 Decrypt RestoreDeviceTreeFileFirmware/all_flash/all_flash.k48ap.production/DeviceTree.k48ap.img3IV0e3fdb2cd018eaab38b427b34cbf556dKey2b5a61188dd993997da958d56b08ae55aea4362a5d29fceb627de91150199d75DecryptPathDowngrade/RestoreDeviceTree Decrypt RestoreLogoFileFirmware/all_flash/all_flash.k48ap.production/applelogo.s5l8930x.img3IVe839ae241b3c2010a13c2031973f7310Keyf6a6c39e8ea1c2bf9d2bd4eef2e7ef4d0d0611d86a6d8511c625b58042e8e31eDecryptPathDowngrade/RestoreLogo Decrypt RestoreKernelCacheFilekernelcache.release.k48IV0ce08a45b54f54bb99f12e582122b992Key8c80ca1a1fb8a1f87b6dfa34d186fd235118025029c0aa8df6a70bd33987c146DecryptPathDowngrade/RestoreKernelCache Decrypt [Log] Preparing custom IPSW: ../bin/macos/ipsw /Users/apple/Downloads/iPSW/iPad 1 iPSW/iPad1,1_3.2_7B367_Restore.ipsw temp.ipsw -memory Hashing IPSW... Matching IPSW in FirmwareBundles/... (172e8297...) checking: FirmwareBundles//Down_iPad1,1_3.2_7B367.bundle/Info.plist loading: 018-7223-007.dmg (452136960) loading: 018-7225-009.dmg (10475844) loading: 018-7226-009.dmg (10484036) loading: BuildManifest.plist (21165) loading: Firmware/ (0) loading: Firmware/all_flash/ (0) loading: Firmware/all_flash/all_flash.k48ap.production/ (0) loading: Firmware/all_flash/all_flash.k48ap.production/applelogo.s5l8930x.img3 (7492) loading: Firmware/all_flash/all_flash.k48ap.production/batterycharging0.s5l8930x.img3 (19780) loading: Firmware/all_flash/all_flash.k48ap.production/batterycharging1.s5l8930x.img3 (24964) loading: Firmware/all_flash/all_flash.k48ap.production/batteryfull.s5l8930x.img3 (76356) loading: Firmware/all_flash/all_flash.k48ap.production/batterylow0.s5l8930x.img3 (56260) loading: Firmware/all_flash/all_flash.k48ap.production/batterylow1.s5l8930x.img3 (64772) loading: Firmware/all_flash/all_flash.k48ap.production/DeviceTree.k48ap.img3 (59716) loading: Firmware/all_flash/all_flash.k48ap.production/glyphcharging.s5l8930x.img3 (20420) loading: Firmware/all_flash/all_flash.k48ap.production/glyphplugin.s5l8930x.img3 (19396) loading: Firmware/all_flash/all_flash.k48ap.production/iBoot.k48ap.RELEASE.img3 (174468) loading: Firmware/all_flash/all_flash.k48ap.production/LLB.k48ap.RELEASE.img3 (72068) loading: Firmware/all_flash/all_flash.k48ap.production/manifest (350) loading: Firmware/all_flash/all_flash.k48ap.production/needservice.s5l8930x.img3 (20612) loading: Firmware/all_flash/all_flash.k48ap.production/recoverymode-768x1024.s5l8930x.img3 (92548) loading: Firmware/dfu/ (0) loading: Firmware/dfu/iBEC.k48ap.RELEASE.dfu (108932) loading: Firmware/dfu/iBSS.k48ap.RELEASE.dfu (108932) loading: kernelcache.release.k48 (4912516) loading: Restore.plist (1795) iBSS: Firmware/dfu/iBSS.k48ap.RELEASE.dfu (FirmwareBundles//Down_iPad1,1_3.2_7B367.bundle/iBSS.k48ap.RELEASE.patch)... encrypted input... /Users/lukee/Desktop/daibutsuCFW/src/xpwn/ipsw-patch/img3.c:createAbstractFileFromImg3:643: 63f4d8a8eb8792fe66a955c6d04e748463e82b8ec967f5a02d76b9ac85125480c39409334eac3791a5f6870b4b28b643 /Users/lukee/Desktop/daibutsuCFW/src/xpwn/ipsw-patch/img3.c:createAbstractFileFromImg3:643: 63f4d8a8eb8792fe66a955c6d04e748463e82b8ec967f5a02d76b9ac85125480c39409334eac3791a5f6870b4b28b643 encrypted output... /Users/lukee/Desktop/daibutsuCFW/src/xpwn/ipsw-patch/img3.c:createAbstractFileFromImg3:643: 63f4d8a8eb8792fe66a955c6d04e748463e82b8ec967f5a02d76b9ac85125480c39409334eac3791a5f6870b4b28b643 writing... success iBSS: /Users/lukee/Desktop/daibutsuCFW/src/xpwn/ipsw-patch/img3.c:createAbstractFileFromImg3:643: 63f4d8a8eb8792fe66a955c6d04e748463e82b8ec967f5a02d76b9ac85125480c39409334eac3791a5f6870b4b28b643 /Users/lukee/Desktop/daibutsuCFW/src/xpwn/ipsw-patch/img3.c:createAbstractFileFromImg3:643: 63f4d8a8eb8792fe66a955c6d04e748463e82b8ec967f5a02d76b9ac85125480c39409334eac3791a5f6870b4b28b643 /Users/lukee/Desktop/daibutsuCFW/src/xpwn/ipsw-patch/img3.c:createAbstractFileFromImg3:643: 63f4d8a8eb8792fe66a955c6d04e748463e82b8ec967f5a02d76b9ac85125480c39409334eac3791a5f6870b4b28b643 writing... success iBEC: Firmware/dfu/iBEC.k48ap.RELEASE.dfu (FirmwareBundles//Down_iPad1,1_3.2_7B367.bundle/iBEC.k48ap.RELEASE.patch)... encrypted input... /Users/lukee/Desktop/daibutsuCFW/src/xpwn/ipsw-patch/img3.c:createAbstractFileFromImg3:643: 61d45a6acbb9a44772eeea80cb39b5ef720dab2834ed163231645c7f4fe23ebee6c64c2b498fa5dbb55008d29abfc40b /Users/lukee/Desktop/daibutsuCFW/src/xpwn/ipsw-patch/img3.c:createAbstractFileFromImg3:643: 61d45a6acbb9a44772eeea80cb39b5ef720dab2834ed163231645c7f4fe23ebee6c64c2b498fa5dbb55008d29abfc40b encrypted output... /Users/lukee/Desktop/daibutsuCFW/src/xpwn/ipsw-patch/img3.c:createAbstractFileFromImg3:643: 61d45a6acbb9a44772eeea80cb39b5ef720dab2834ed163231645c7f4fe23ebee6c64c2b498fa5dbb55008d29abfc40b writing... success iBEC: /Users/lukee/Desktop/daibutsuCFW/src/xpwn/ipsw-patch/img3.c:createAbstractFileFromImg3:643: 61d45a6acbb9a44772eeea80cb39b5ef720dab2834ed163231645c7f4fe23ebee6c64c2b498fa5dbb55008d29abfc40b /Users/lukee/Desktop/daibutsuCFW/src/xpwn/ipsw-patch/img3.c:createAbstractFileFromImg3:643: 61d45a6acbb9a44772eeea80cb39b5ef720dab2834ed163231645c7f4fe23ebee6c64c2b498fa5dbb55008d29abfc40b /Users/lukee/Desktop/daibutsuCFW/src/xpwn/ipsw-patch/img3.c:createAbstractFileFromImg3:643: 61d45a6acbb9a44772eeea80cb39b5ef720dab2834ed163231645c7f4fe23ebee6c64c2b498fa5dbb55008d29abfc40b writing... success Restore Ramdisk: /Users/lukee/Desktop/daibutsuCFW/src/xpwn/ipsw-patch/img3.c:createAbstractFileFromImg3:643: 47e8f1574e01af33ba5cfdc45153b0e621f17080f36537179be23db3dd35f893ec01874b621e4b33aa760c9924231922 /Users/lukee/Desktop/daibutsuCFW/src/xpwn/ipsw-patch/img3.c:createAbstractFileFromImg3:643: 47e8f1574e01af33ba5cfdc45153b0e621f17080f36537179be23db3dd35f893ec01874b621e4b33aa760c9924231922 /Users/lukee/Desktop/daibutsuCFW/src/xpwn/ipsw-patch/img3.c:createAbstractFileFromImg3:643: 47e8f1574e01af33ba5cfdc45153b0e621f17080f36537179be23db3dd35f893ec01874b621e4b33aa760c9924231922 writing... success RestoreDeviceTree: /Users/lukee/Desktop/daibutsuCFW/src/xpwn/ipsw-patch/img3.c:createAbstractFileFromImg3:643: 96b38c3899c10d84c672ee944e3ee2211f5ff645eb6d424eb24264265cccfb5f184900a58a1da0de148fb0c414424cd9 /Users/lukee/Desktop/daibutsuCFW/src/xpwn/ipsw-patch/img3.c:createAbstractFileFromImg3:643: 96b38c3899c10d84c672ee944e3ee2211f5ff645eb6d424eb24264265cccfb5f184900a58a1da0de148fb0c414424cd9 /Users/lukee/Desktop/daibutsuCFW/src/xpwn/ipsw-patch/img3.c:createAbstractFileFromImg3:643: 96b38c3899c10d84c672ee944e3ee2211f5ff645eb6d424eb24264265cccfb5f184900a58a1da0de148fb0c414424cd9 writing... success RestoreLogo: /Users/lukee/Desktop/daibutsuCFW/src/xpwn/ipsw-patch/img3.c:createAbstractFileFromImg3:643: f75ba7d7820f160548a8ca254497d368d3fcb39fa9d5c5302b4d543966c273ece8f303900936941621726aabd408d0fb /Users/lukee/Desktop/daibutsuCFW/src/xpwn/ipsw-patch/img3.c:createAbstractFileFromImg3:643: f75ba7d7820f160548a8ca254497d368d3fcb39fa9d5c5302b4d543966c273ece8f303900936941621726aabd408d0fb /Users/lukee/Desktop/daibutsuCFW/src/xpwn/ipsw-patch/img3.c:createAbstractFileFromImg3:643: f75ba7d7820f160548a8ca254497d368d3fcb39fa9d5c5302b4d543966c273ece8f303900936941621726aabd408d0fb writing... success RestoreKernelCache: /Users/lukee/Desktop/daibutsuCFW/src/xpwn/ipsw-patch/img3.c:createAbstractFileFromImg3:643: ef56f94205d025cf65cce9a6660c491cfcb919daf0ce68a58e8749e3f3a9204604b8615e010425df7e346d6716a28d44 /Users/lukee/Desktop/daibutsuCFW/src/xpwn/ipsw-patch/img3.c:createAbstractFileFromImg3:643: ef56f94205d025cf65cce9a6660c491cfcb919daf0ce68a58e8749e3f3a9204604b8615e010425df7e346d6716a28d44 /Users/lukee/Desktop/daibutsuCFW/src/xpwn/ipsw-patch/img3.c:createAbstractFileFromImg3:643: ef56f94205d025cf65cce9a6660c491cfcb919daf0ce68a58e8749e3f3a9204604b8615e010425df7e346d6716a28d44 writing... success Writing out data.. run 100: start=25952256 sectors=512, length=191357, fileOffset=0x7e8e3e run 200: start=52166656 sectors=512, length=125569, fileOffset=0x15cd764 run 300: start=78381056 sectors=512, length=20597, fileOffset=0x1b238ff run 400: start=104595456 sectors=512, length=1167, fileOffset=0x1e6b14a run 500: start=130809856 sectors=512, length=180966, fileOffset=0x289e3fc run 600: start=157024256 sectors=512, length=243661, fileOffset=0x3a2db30 run 700: start=183238656 sectors=512, length=106465, fileOffset=0x44c6eee run 800: start=209453056 sectors=512, length=146580, fileOffset=0x52786a0 run 900: start=235667456 sectors=512, length=155308, fileOffset=0x5f99a4d run 1000: start=261881856 sectors=512, length=144576, fileOffset=0x6c15f88 run 1100: start=541851648 sectors=512, length=48896, fileOffset=0x7396e23 run 1200: start=568066048 sectors=512, length=141037, fileOffset=0x7d4db28 run 1300: start=594280448 sectors=512, length=262144, fileOffset=0x8e3c964 run 1400: start=620494848 sectors=512, length=262144, fileOffset=0xa6a3eb5 run 1500: start=646709248 sectors=512, length=175018, fileOffset=0xb8901c1 run 1600: start=672923648 sectors=512, length=172637, fileOffset=0xc9926a6 run 1700: start=699138048 sectors=512, length=162859, fileOffset=0xdbc6975 run 1800: start=725352448 sectors=512, length=160385, fileOffset=0xebc0226 run 1900: start=751566848 sectors=512, length=140984, fileOffset=0xfb21b7e run 2000: start=777781248 sectors=512, length=48201, fileOffset=0x10580148 run 2100: start=803995648 sectors=512, length=108081, fileOffset=0x10ea44ba run 2200: start=830210048 sectors=512, length=199417, fileOffset=0x119c3c24 run 2300: start=856424448 sectors=512, length=192846, fileOffset=0x125a14fe run 2400: start=882638848 sectors=512, length=262144, fileOffset=0x131a58a6 run 2500: start=908853248 sectors=512, length=262144, fileOffset=0x1432140c run 2600: start=935067648 sectors=512, length=229807, fileOffset=0x1570e10a run 2700: start=961282048 sectors=512, length=262144, fileOffset=0x170062b9 run 2800: start=987496448 sectors=512, length=262144, fileOffset=0x183bdba0 run 2900: start=1013710848 sectors=512, length=113505, fileOffset=0x19ab0c82 run 3000: start=1039925248 sectors=512, length=171196, fileOffset=0x1a9aca05 Growing root to minimum: 1030 unencrypted ramdisk growing ramdisk: 10481664 -> 10481664 Cannot shrink volume patching usr/sbin/asr (FirmwareBundles//Down_iPad1,1_3.2_7B367.bundle/asr.patch)... retrieving...patching...writing... success patching usr/local/bin/restored_external (FirmwareBundles//Down_iPad1,1_3.2_7B367.bundle/restoredexternal.patch)... retrieving...patching...writing... success got /usr/local/share/restore/options.plist from ramdisk start create restore options MinimumSystemPartition 1030 CreateFilesystemPartitions SystemPartitionSize 1030 UpdateBaseband Creating and writing DDM and partition map... run 0: sectors=1, left=1 run 0: sectors=60, left=60 malloc: 0x7fe8ab82e000 4096 run 0: sectors=4, left=4 Writing main data blkx... run 100: sectors=512, left=2058752 run 200: sectors=512, left=2007552 run 300: sectors=512, left=1956352 run 400: sectors=512, left=1905152 run 500: sectors=512, left=1853952 run 600: sectors=512, left=1802752 run 700: sectors=512, left=1751552 run 800: sectors=512, left=1700352 run 900: sectors=512, left=1649152 run 1000: sectors=512, left=1597952 run 1080: skipping sectors=496128, left=1556992 run 1100: sectors=512, left=1051136 run 1200: sectors=512, left=999936 run 1242: skipping sectors=64, left=978432 run 1265: skipping sectors=80, left=967104 run 1266: skipping sectors=4, left=967024 run 1270: skipping sectors=16, left=965484 run 1273: skipping sectors=64, left=964444 run 1276: skipping sectors=4, left=963356 run 1279: skipping sectors=1, left=962328 run 1300: sectors=512, left=952087 run 1400: sectors=512, left=900887 run 1500: sectors=512, left=849687 run 1504: skipping sectors=7, left=847639 run 1600: sectors=512, left=798992 run 1700: sectors=512, left=747792 run 1800: sectors=512, left=696592 run 1900: sectors=512, left=645392 run 1928: skipping sectors=2, left=631056 run 1930: skipping sectors=2, left=630542 run 1932: skipping sectors=2, left=630028 run 1934: skipping sectors=2, left=629514 run 1936: skipping sectors=8, left=629000 run 2000: sectors=512, left=596736 run 2100: sectors=512, left=545536 run 2200: sectors=512, left=494336 run 2300: sectors=512, left=443136 run 2400: sectors=512, left=391936 run 2500: sectors=512, left=340736 run 2580: skipping sectors=16, left=299776 run 2600: sectors=512, left=290032 run 2700: sectors=512, left=238832 run 2765: skipping sectors=1, left=205552 run 2800: sectors=512, left=188143 run 2900: sectors=512, left=136943 run 2937: skipping sectors=15, left=117999 run 2961: skipping sectors=9, left=106208 run 2963: skipping sectors=7, left=105687 run 3000: sectors=512, left=87248 run 3051: skipping sectors=61120, left=61136 run 3052: skipping sectors=14, left=16 Inserting main blkx... Inserting cSum data... Inserting nsiz data Writing free partition... Writing XML data... making size data we know to flip this size resource Generating UDIF metadata... Master checksum: a79178b1 Writing out UDIF resource file... Cleaning up... Done. packing: 018-7223-007.dmg (452039631) packing: 018-7225-009.dmg (10475844) packing: 018-7226-009.dmg (10483860) packing: BuildManifest.plist (20999) packing: Downgrade/ (0) packing: Downgrade/RestoreDeviceTree (59552) packing: Downgrade/RestoreKernelCache (4912340) packing: Downgrade/RestoreLogo (7328) packing: Firmware/ (0) packing: Firmware/all_flash/ (0) packing: Firmware/all_flash/all_flash.k48ap.production/ (0) packing: Firmware/all_flash/all_flash.k48ap.production/DeviceTree.k48ap.img3 (59716) packing: Firmware/all_flash/all_flash.k48ap.production/LLB.k48ap.RELEASE.img3 (72068) packing: Firmware/all_flash/all_flash.k48ap.production/applelogo.s5l8930x.img3 (7492) packing: Firmware/all_flash/all_flash.k48ap.production/batterycharging0.s5l8930x.img3 (19780) packing: Firmware/all_flash/all_flash.k48ap.production/batterycharging1.s5l8930x.img3 (24964) packing: Firmware/all_flash/all_flash.k48ap.production/batteryfull.s5l8930x.img3 (76356) packing: Firmware/all_flash/all_flash.k48ap.production/batterylow0.s5l8930x.img3 (56260) packing: Firmware/all_flash/all_flash.k48ap.production/batterylow1.s5l8930x.img3 (64772) packing: Firmware/all_flash/all_flash.k48ap.production/glyphcharging.s5l8930x.img3 (20420) packing: Firmware/all_flash/all_flash.k48ap.production/glyphplugin.s5l8930x.img3 (19396) packing: Firmware/all_flash/all_flash.k48ap.production/iBoot.k48ap.RELEASE.img3 (174468) packing: Firmware/all_flash/all_flash.k48ap.production/manifest (350) packing: Firmware/all_flash/all_flash.k48ap.production/needservice.s5l8930x.img3 (20612) packing: Firmware/all_flash/all_flash.k48ap.production/recoverymode-768x1024.s5l8930x.img3 (92548) packing: Firmware/dfu/ (0) packing: Firmware/dfu/iBEC.k48ap.RELEASE.dfu (108748) packing: Firmware/dfu/iBSS.k48ap.RELEASE.dfu (108748) packing: Restore.plist (1795) packing: kernelcache.release.k48 (4912516) [Log] Extract RestoreRamdisk and options.plist [Log] Checking firmware keys in ../resources/firmware/iPad1,1/7B367 Archive: temp.ipsw inflating: 018-7226-009.dmg [Log] Modify options.plist MinimumSystemPartition 1030 CreateFilesystemPartitions SystemPartitionSize 1030 UpdateBaseband FlashNOR [Log] Repack Restore Ramdisk [Log] Add Restore Ramdisk to IPSW updating: 018-7226-009.dmg (stored 0%) [Log] Found existing saved 5.1.1 blobs: ../saved/shsh/1244837328268_iPad1,1_k48ap_5.1.1-9B206_3a88b7c3802f2f0510abc432104a15ebd8bd7154.shsh2 [Input] PwnDFU Tool Option * Select tool to be used for entering pwned DFU mode. * This option is set to ipwnder32 by default (1). Select this option if unsure. * If the first option does not work, try many times and/or try the other option(s). [Input] Select your option: 1) ipwnder32 2) ipwnder_lite #? 1 [Log] Placing device to pwnDFU mode using: ../bin/macos/ipwnder32 -p ** iPwnder32 - RELEASE v3.2.0 [3C152] by @dora2ios Waiting for device in DFU mode... DFU device infomation iPad [iPad1,1] CPID:0x8930 CPRV:0x20 BDID:0x02 ECID:0x00000121D616358C CPFM:0x03 SCEP:0x01 IBFL:0x00 SRTG:[iBoot-574.4] exploiting with limera1n * based on limera1n exploit (heap overflow) by geohot Device is now in pwned DFU mode! [Log] Device iPad1,1 has no baseband/disabled baseband update [Log] Extracting IPSW: ../iPad1,1_3.2_7B367_CustomT.ipsw Archive: ../iPad1,1_3.2_7B367_CustomT.ipsw inflating: ../iPad1,1_3.2_7B367_CustomT/018-7223-007.dmg inflating: ../iPad1,1_3.2_7B367_CustomT/018-7225-009.dmg extracting: ../iPad1,1_3.2_7B367_CustomT/018-7226-009.dmg inflating: ../iPad1,1_3.2_7B367_CustomT/BuildManifest.plist creating: ../iPad1,1_3.2_7B367_CustomT/Downgrade/ inflating: ../iPad1,1_3.2_7B367_CustomT/Downgrade/RestoreDeviceTree inflating: ../iPad1,1_3.2_7B367_CustomT/Downgrade/RestoreKernelCache inflating: ../iPad1,1_3.2_7B367_CustomT/Downgrade/RestoreLogo creating: ../iPad1,1_3.2_7B367_CustomT/Firmware/ creating: ../iPad1,1_3.2_7B367_CustomT/Firmware/all_flash/ creating: ../iPad1,1_3.2_7B367_CustomT/Firmware/all_flash/all_flash.k48ap.production/ inflating: ../iPad1,1_3.2_7B367_CustomT/Firmware/all_flash/all_flash.k48ap.production/DeviceTree.k48ap.img3 inflating: ../iPad1,1_3.2_7B367_CustomT/Firmware/all_flash/all_flash.k48ap.production/LLB.k48ap.RELEASE.img3 inflating: ../iPad1,1_3.2_7B367_CustomT/Firmware/all_flash/all_flash.k48ap.production/applelogo.s5l8930x.img3 inflating: ../iPad1,1_3.2_7B367_CustomT/Firmware/all_flash/all_flash.k48ap.production/batterycharging0.s5l8930x.img3 inflating: ../iPad1,1_3.2_7B367_CustomT/Firmware/all_flash/all_flash.k48ap.production/batterycharging1.s5l8930x.img3 inflating: ../iPad1,1_3.2_7B367_CustomT/Firmware/all_flash/all_flash.k48ap.production/batteryfull.s5l8930x.img3 inflating: ../iPad1,1_3.2_7B367_CustomT/Firmware/all_flash/all_flash.k48ap.production/batterylow0.s5l8930x.img3 inflating: ../iPad1,1_3.2_7B367_CustomT/Firmware/all_flash/all_flash.k48ap.production/batterylow1.s5l8930x.img3 inflating: ../iPad1,1_3.2_7B367_CustomT/Firmware/all_flash/all_flash.k48ap.production/glyphcharging.s5l8930x.img3 inflating: ../iPad1,1_3.2_7B367_CustomT/Firmware/all_flash/all_flash.k48ap.production/glyphplugin.s5l8930x.img3 inflating: ../iPad1,1_3.2_7B367_CustomT/Firmware/all_flash/all_flash.k48ap.production/iBoot.k48ap.RELEASE.img3 inflating: ../iPad1,1_3.2_7B367_CustomT/Firmware/all_flash/all_flash.k48ap.production/manifest inflating: ../iPad1,1_3.2_7B367_CustomT/Firmware/all_flash/all_flash.k48ap.production/needservice.s5l8930x.img3 inflating: ../iPad1,1_3.2_7B367_CustomT/Firmware/all_flash/all_flash.k48ap.production/recoverymode-768x1024.s5l8930x.img3 creating: ../iPad1,1_3.2_7B367_CustomT/Firmware/dfu/ inflating: ../iPad1,1_3.2_7B367_CustomT/Firmware/dfu/iBEC.k48ap.RELEASE.dfu inflating: ../iPad1,1_3.2_7B367_CustomT/Firmware/dfu/iBSS.k48ap.RELEASE.dfu inflating: ../iPad1,1_3.2_7B367_CustomT/Restore.plist inflating: ../iPad1,1_3.2_7B367_CustomT/kernelcache.release.k48 [Log] Checking firmware keys in ../resources/firmware/iPad1,1/9B206 [Log] Decrypting iBSS... /tmp/xpwn/ipsw-patch/img3.c:createAbstractFileFromImg3:643: dc219cae3a0760e26d1868755e6375f71c764c465503064879e05a8e0c703223cf15325b2e95ad24e2400f25c7869ab5 [Log] Patching iBSS... main: Starting... main: iBoot-1219 inputted. patch_rsa_check: Entering... find_bl_verify_shsh_5_6_7: Entering... find_bl_verify_shsh_5_6_7: Found MOVW instruction at 0x5baa find_bl_verify_shsh_5_6_7: Found BL verify_shsh at 0x613c find_bl_verify_shsh_5_6_7: Leaving... patch_rsa_check: Patching BL verify_shsh at 0x613c... patch_rsa_check: Leaving... main: Writing out patched file to pwnediBSS... main: Quitting... /tmp/xpwn/ipsw-patch/img3.c:createAbstractFileFromImg3:643: dc219cae3a0760e26d1868755e6375f71c764c465503064879e05a8e0c703223cf15325b2e95ad24e2400f25c7869ab5 /tmp/xpwn/ipsw-patch/img3.c:createAbstractFileFromImg3:643: dc219cae3a0760e26d1868755e6375f71c764c465503064879e05a8e0c703223cf15325b2e95ad24e2400f25c7869ab5 [Log] Pwned iBSS saved at: saved/iPad1,1/pwnediBSS [Log] Pwned iBSS img3 saved at: saved/iPad1,1/pwnediBSS.dfu [Log] Sending iBSS... [==================================================] 100.0% [Log] Sending iBEC... [==================================================] 100.0% [Log] Finding device in Recovery mode... [Log] Found device in Recovery mode. [Log] Running idevicerestore with command: ../bin/macos/idevicerestore -ew "../iPad1,1_3.2_7B367_CustomT.ipsw" Found device in Recovery mode INFO: device serial number is GB02873KZ3A Found ECID 1244837328268 Identified device as k48ap, iPad1,1 Extracting BuildManifest from IPSW Product Version: 3.2 Product Build: 7B367 Major: 7 Device supports Image4: false Variant: Customer Erase Install (IPSW) This restore will erase your device data. checking for local shsh Using cached SHSH Using cached filesystem from '../iPad1,1_3.2_7B367_CustomT/018-7223-007.dmg' Extracting iBEC.k48ap.RELEASE.dfu... Personalizing IMG3 component iBEC... reconstructed size: 108769 Sending iBEC (108769 bytes)... Recovery Mode Environment: iBoot build-version=iBoot-817.28 iBoot build-style=RELEASE radio-error=0x10 radio-error-string=Not present ramdisk-size=Not present Extracting 018-7226-009.dmg... Personalizing IMG3 component RestoreRamDisk... reconstructed size: 10483881 Sending RestoreRamDisk (10483881 bytes)... Extracting RestoreDeviceTree... Personalizing IMG3 component RestoreDeviceTree... reconstructed size: 59573 Sending RestoreDeviceTree (59573 bytes)... Extracting RestoreKernelCache... Personalizing IMG3 component RestoreKernelCache... reconstructed size: 4912361 Sending RestoreKernelCache (4912361 bytes)... About to restore device... Waiting for device... ERROR: Unable to connect to device in restore mode ERROR: Unable to open device in restore mode ERROR: Unable to restore device [Log] Restoring done! Read the message below if any error has occurred: * For device activation, go to: Other Utilities -> Attempt Activation * If the restore failed on updating baseband: -> Try disabling baseband update: ./restore.sh --disable-bbupdate * Please read the "Troubleshooting" wiki page in GitHub before opening any issue! * Your problem may have already been addressed within the wiki page. * If opening an issue in GitHub, please provide a FULL log/output. Otherwise, your issue may be dismissed. * Save the terminal output now if needed. * Legacy iOS Kit v24.01.18 (6fd336f)
LukeZGD commented 8 months ago

I can't fix this for some reason, I'll just enable the custom IPSW option on more devices. Just use GeekGrade IPSWs from these:

I didn't create these IPSWs, not sure if all these IPSWs work or not.