mineek / sunst0rm

iOS Tether Downgrader
GNU General Public License v3.0
294 stars 45 forks source link

iPhone 7 downgraded to iOS 14.0 and don't want exit from dfu #91

Closed hiprivsid closed 1 year ago

hiprivsid commented 1 year ago

Hello, I install iOS 14.0 using tether sunst0rm, ipwndfu doesn't install on phone, working only reboot Hardware: Mac Mini mid 2011 Install log:

Mac-mini-Ivan:sunst0rm hiprivsid$ python3 sunstorm.py -i iPhone_4.7_P3_14.0_18A373_Restore.ipsw -t 673373594124326_iPhone9,3_d101ap_15.7-19H12_15400076bc4c35a7c8caefdcae5bda69c140a11bce870548f0862aac28c194cc.shsh2 -r -d d101ap
sunst0rm
Made by mineek | Some code by m1n1exploit

[*] Extracting IPSW
[*] Extracting ramdisk
rdsk
[*] Mounting ramdisk
/dev/disk1                                              /Users/hiprivsid/sunst0rm/work/ramdisk
[*] Patching ASR in the ramdisk
getting get_asr_patch()
[*] Image failed signature verification 0x10089b77d
[*] Image passed signature verification 0x10089b759
[*] Assembling arm64 branch
[*] Writing out patched file to work/patched_asr
[*] Extracting ASR entitlements
[*] Resigning ASR
[*] Chmoding ASR
[*] Copying patched ASR back to the ramdisk
[*] Patching restored_external
file size: 825664
getting get_skip_sealing_patch()
[*] Skipping sealing system volume string at 0x821b4
[*] Skipping sealing system volume xref at 0x2fac8
[*] Skipping sealing system volume branch to xref at 0x2fa6c
[*] Assembling arm64 branch
[*] Writing out patched file to work/restored_external_patched
[*] Extracting restored_external Ents
[*] Resigning restored_external
[*] Chmoding restored_external
[*] Copying patched restored_external back to the ramdisk
[*] Detaching ramdisk
"disk1" unmounted.
"disk1" ejected.
[*] Creating ramdisk
Reading work/ramdisk.dmg...
IM4P outputted to: work/ramdisk.im4p
[*] Extracting ramdisk
Reading work/kernelcache.release.iphone9...
[NOTE] Image4 payload data is LZFSE compressed, decompressing...
Extracted Image4 payload data to: work/kcache.raw
[*] Patching kernel
main: Starting...
main: Detected fat macho kernel
Kernel: Adding AppleFirmwareUpdate img4 signature check patch...
get_AppleFirmwareUpdate_img4_signature_check: Entering ...
get_AppleFirmwareUpdate_img4_signature_check: Found "%s::%s() Performing img4 validation outside of workloop" str loc at 0x950585
get_AppleFirmwareUpdate_img4_signature_check: Found "%s::%s() Performing img4 validation outside of workloop" xref at 0x116092c
get_AppleFirmwareUpdate_img4_signature_check: Patching "%s::%s() Performing img4 validation outside of workloop" at 0x1160938

Kernel: Adding AMFI_get_out_of_my_way patch...
get_amfi_out_of_my_way_patch: Entering ...
get_amfi_out_of_my_way_patch: Kernel-7195 inputted
get_amfi_out_of_my_way_patch: Found entitlements too small str loc at 0x8b42cb
get_amfi_out_of_my_way_patch: Found entitlements too small str ref at 0xf57bfc
get_amfi_out_of_my_way_patch: Patching AMFI at 0xf52db4
main: Writing out patched file to work/krnl.patched...
main: Quitting...
[*] Rebuilding kernel
Reading work/krnl.patched...
Compressing payload using LZSS...
IM4P outputted to: work/krnl.im4p
[*] Done!
[?] Do you want to restore the device? (y/n)
y
[?] Are you in pwndfu with sigchecks removed? (y/n)
y
[*] Restoring Device
Version: v2.0.0-test(7220525e9f8fa3000d0beb04eb8f30b44b501573-300)
img4tool version: 0.197-aca6cf005c94caf135023263cbb5c61a0081804f-RELEASE
libipatcher version: 0.88-1e855d70c84419014e363bdbcaead7b145fe3e1f-RELEASE
Odysseus for 32-bit support: yes
Odysseus for 64-bit support: yes
Checking for updates...
Futurerestore is up to date!
[INFO] 64-bit device detected
futurerestore init done
reading signing ticket 673373594124326_iPhone9,3_d101ap_15.7-19H12_15400076bc4c35a7c8caefdcae5bda69c140a11bce870548f0862aac28c194cc.shsh2 is done
User specified to use latest signed SEP
Using cached SEP.
Checking if SEP is being signed...
Sending TSS request attempt 1... response successfully received
SEP is being signed!
User specified to use latest signed baseband
Downloading Baseband
100[===================================================================================================>]
Checking if Baseband is being signed...
Sending TSS request attempt 1... response successfully received
Baseband is being signed!
Downloading the latest firmware components...
Finished downloading the latest firmware components!
Found device in DFU mode
requesting to get into pwnRecovery later
Found device in DFU mode
Identified device as d101ap, iPhone9,3
Extracting BuildManifest from iPSW
Product version: 14.0
Product build: 18A373 Major: 18
Device supports Image4: true
checking if the APTicket is valid for this restore...
Verified ECID in APTicket matches the device's ECID
checking if the APTicket is valid for this restore...
Verified ECID in APTicket matches the device's ECID
[IMG4TOOL] checking buildidentity 0:
[IMG4TOOL] checking buildidentity matches board ... YES
[IMG4TOOL] checking buildidentity has all required hashes:
[IMG4TOOL] checking hash for "AOP"                     OK (untrusted)
[IMG4TOOL] checking hash for "Ap,SystemVolumeCanonicalMetadata"BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "AppleLogo"               BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "BasebandFirmware"        IGN (no digest in BuildManifest)
[IMG4TOOL] checking hash for "BatteryCharging0"        BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "BatteryCharging1"        BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "BatteryFull"             BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "BatteryLow0"             BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "BatteryLow1"             BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "BatteryPlugin"           BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "DeviceTree"              BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "Homer"                   OK (untrusted)
[IMG4TOOL] checking hash for "KernelCache"             BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "LLB"                     BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "Liquid"                  BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "OS"                      BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "RecoveryMode"            BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "RestoreDeviceTree"       BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "RestoreKernelCache"      BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "RestoreLogo"             BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "RestoreRamDisk"          BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "RestoreSEP"              BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "RestoreTrustCache"       BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "SEP"                     BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "StaticTrustCache"        BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "SystemVolume"            BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "ftap"                    IGN (no digest in BuildManifest)
[IMG4TOOL] checking hash for "ftsp"                    IGN (no digest in BuildManifest)
[IMG4TOOL] checking hash for "iBEC"                    BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "iBSS"                    BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "iBoot"                   BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "rfta"                    IGN (no digest in BuildManifest)
[IMG4TOOL] checking hash for "rfts"                    IGN (no digest in BuildManifest)

failed verification with error:
[exception]:
what=verification failed!
code=84279308
line=1286
file=img4tool.cpp
commit count=197:
commit sha  =aca6cf005c94caf135023263cbb5c61a0081804f:
[IMG4TOOL] checking buildidentity 1:
[IMG4TOOL] checking buildidentity matches board ... NO
[IMG4TOOL] checking buildidentity 2:
[IMG4TOOL] checking buildidentity matches board ... NO
[IMG4TOOL] checking buildidentity 3:
[IMG4TOOL] checking buildidentity matches board ... NO
[IMG4TOOL] checking buildidentity 4:
[IMG4TOOL] checking buildidentity matches board ... YES
[IMG4TOOL] checking buildidentity has all required hashes:
[IMG4TOOL] checking hash for "AOP"                     OK (untrusted)
[IMG4TOOL] checking hash for "Ap,SystemVolumeCanonicalMetadata"BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "AppleLogo"               BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "BasebandFirmware"        IGN (no digest in BuildManifest)
[IMG4TOOL] checking hash for "BatteryCharging0"        BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "BatteryCharging1"        BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "BatteryFull"             BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "BatteryLow0"             BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "BatteryLow1"             BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "BatteryPlugin"           BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "DeviceTree"              BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "Homer"                   OK (untrusted)
[IMG4TOOL] checking hash for "KernelCache"             BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "LLB"                     BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "Liquid"                  BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "OS"                      BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "RecoveryMode"            BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "RestoreDeviceTree"       BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "RestoreKernelCache"      BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "RestoreLogo"             BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "RestoreRamDisk"          BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "RestoreSEP"              BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "RestoreTrustCache"       BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "SEP"                     BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "StaticTrustCache"        BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "SystemVolume"            BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "ftap"                    IGN (no digest in BuildManifest)
[IMG4TOOL] checking hash for "ftsp"                    IGN (no digest in BuildManifest)
[IMG4TOOL] checking hash for "iBEC"                    BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "iBSS"                    BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "iBoot"                   BAD! (hash not found in im4m)
[IMG4TOOL] checking hash for "rfta"                    IGN (no digest in BuildManifest)
[IMG4TOOL] checking hash for "rfts"                    IGN (no digest in BuildManifest)

failed verification with error:
[exception]:
what=verification failed!
code=84279308
line=1286
file=img4tool.cpp
commit count=197:
commit sha  =aca6cf005c94caf135023263cbb5c61a0081804f:
[IMG4TOOL] checking buildidentity 5:
[IMG4TOOL] checking buildidentity matches board ... NO
[IMG4TOOL] checking buildidentity 6:
[IMG4TOOL] checking buildidentity matches board ... NO
[IMG4TOOL] checking buildidentity 7:
[IMG4TOOL] checking buildidentity matches board ... NO
[WARNING] NOT VALIDATING SHSH BLOBS IM4M!
[Error] BuildIdentity selected for restore does not match APTicket

BuildIdentity selected for restore:
BuildNumber : 18A373
BuildTrain : Azul
DeviceClass : d101ap
FDRSupport : YES
MobileDeviceMinVersion : 1253
RestoreBehavior : Erase
Variant : Customer Erase Install (IPSW)

BuildIdentity is valid for the APTicket:
IM4M is not valid for any restore within the Buildmanifest
This APTicket can't be used for restoring this firmware
[WARNING] NOT VALIDATING SHSH BLOBS!
Variant: Customer Erase Install (IPSW)
This restore will erase all device data.
Device found in DFU Mode.
Sending iBSS (522513 bytes)...
[==================================================] 100.0%
Booting iBSS, waiting for device to disconnect...
Booting iBSS, waiting for device to reconnect...
ApNonce pre-hax:
INFO: device serial number is G27YJ015J5KN
Getting ApNonce in recovery mode... fd 0c 75 79 10 00 c2 36 27 52 c2 72 46 b3 a3 b2 58 f0 fc 02 d2 58 5b d4 0e 46 6e 96 e1 f4 3e 4b 
ApNonce from device doesn't match IM4M nonce, applying hax...
Writing generator=0xbd34a880be0b53f3 to nvram!
Sending iBEC (522513 bytes)...
[==================================================] 100.0%
Booting iBEC, waiting for device to disconnect...
Booting iBEC, waiting for device to reconnect...
APnonce post-hax:
Getting ApNonce in recovery mode... 15 40 00 76 bc 4c 35 a7 c8 ca ef dc ae 5b da 69 c1 40 a1 1b ce 87 05 48 f0 86 2a ac 28 c1 94 cc 
Successfully set nonce generator: 0xbd34a880be0b53f3
Extracting filesystem from iPSW
[==================================================] 100.0%
Getting SepNonce in recovery mode... e9 e2 fb 83 59 5c 19 8e 5b 53 7b 32 0e 7a 37 7d 20 d9 84 91 
Getting ApNonce in recovery mode... 15 40 00 76 bc 4c 35 a7 c8 ca ef dc ae 5b da 69 c1 40 a1 1b ce 87 05 48 f0 86 2a ac 28 c1 94 cc 
[WARNING] Setting bgcolor to green! If you don't see a green screen, then your device didn't boot iBEC correctly
Recovery Mode Environment:
iBoot build-version=iBoot-6723.0.48
iBoot build-style=RELEASE
Sending RestoreLogo...
Extracting applelogo@2x~iphone.im4p (Firmware/all_flash/applelogo@2x~iphone.im4p)...
Personalizing IMG4 component RestoreLogo...
Sending RestoreLogo (13544 bytes)...
ramdisk-size=0x20000000
1337 CUSTOM RAMDISK!
Personalizing IMG4 component RestoreRamDisk...
Sending RestoreRamDisk (103028613 bytes)...
Extracting 048-58904-639.dmg.trustcache (Firmware/048-58904-639.dmg.trustcache)...
Personalizing IMG4 component RestoreTrustCache...
Sending RestoreTrustCache (11838 bytes)...
Extracting DeviceTree.d101ap.im4p (Firmware/all_flash/DeviceTree.d101ap.im4p)...
Personalizing IMG4 component RestoreDeviceTree...
Sending RestoreDeviceTree (36553 bytes)...
Extracting sep-firmware.d101.RELEASE.im4p (Firmware/all_flash/sep-firmware.d101.RELEASE.im4p)...
Personalizing IMG4 component RestoreSEP...
Sending RestoreSEP (1362884 bytes)...
1337 CUSTOM KERNEL!
Personalizing IMG4 component RestoreKernelCache...
Sending RestoreKernelCache (19620731 bytes)...
getting SEP ticket
Trying to fetch new SHSH blob
Sending TSS request attempt 1... response successfully received
Received SHSH blobs
About to restore device... 
Connecting now...
Connected to com.apple.mobile.restored, version 15
Device ffffffffffffffffffffffffffffffff00000010 has successfully entered restore mode
Hardware Information:
BoardID: 12
ChipID: 32784
UniqueChipID: 673373594124326
ProductionMode: true
Starting FDR listener thread
Checkpoint 1621 complete with code 0
Checkpoint 1540 complete with code 0
Checkpoint 1679 complete with code 0
Checkpoint 1544 complete with code 0
About to send RootTicket...
Sending RootTicket now...
Done sending RootTicket
Checkpoint 1547 complete with code 0
Waiting for NAND (28)
Checkpoint 1549 complete with code 0
Updating NAND Firmware (58)
Checkpoint 1550 complete with code 0
Checkpoint 1551 complete with code 0
Checkpoint 1628 complete with code 0
Checkpoint 1552 complete with code 0
Checkpoint 1555 complete with code 0
Checkpoint 1662 complete with code 0
About to send NORData...
Found firmware path Firmware/all_flash
Getting firmware manifest from build identity
Extracting LLB.d10.RELEASE.im4p (Firmware/all_flash/LLB.d10.RELEASE.im4p)...
Personalizing IMG4 component LLB...
Extracting applelogo@2x~iphone.im4p (Firmware/all_flash/applelogo@2x~iphone.im4p)...
Personalizing IMG4 component AppleLogo...
Extracting batterycharging0@2x~iphone.im4p (Firmware/all_flash/batterycharging0@2x~iphone.im4p)...
Personalizing IMG4 component BatteryCharging0...
Extracting batterycharging1@2x~iphone.im4p (Firmware/all_flash/batterycharging1@2x~iphone.im4p)...
Personalizing IMG4 component BatteryCharging1...
Extracting batteryfull@2x~iphone.im4p (Firmware/all_flash/batteryfull@2x~iphone.im4p)...
Personalizing IMG4 component BatteryFull...
Extracting batterylow0@2x~iphone.im4p (Firmware/all_flash/batterylow0@2x~iphone.im4p)...
Personalizing IMG4 component BatteryLow0...
Extracting batterylow1@2x~iphone.im4p (Firmware/all_flash/batterylow1@2x~iphone.im4p)...
Personalizing IMG4 component BatteryLow1...
Extracting glyphplugin@1334~iphone-lightning.im4p (Firmware/all_flash/glyphplugin@1334~iphone-lightning.im4p)...
Personalizing IMG4 component BatteryPlugin...
Extracting DeviceTree.d101ap.im4p (Firmware/all_flash/DeviceTree.d101ap.im4p)...
Personalizing IMG4 component DeviceTree...
Extracting liquiddetect@1334~iphone-lightning.im4p (Firmware/all_flash/liquiddetect@1334~iphone-lightning.im4p)...
Personalizing IMG4 component Liquid...
Extracting recoverymode@1334~iphone-lightning.im4p (Firmware/all_flash/recoverymode@1334~iphone-lightning.im4p)...
Personalizing IMG4 component RecoveryMode...
Extracting iBoot.d10.RELEASE.im4p (Firmware/all_flash/iBoot.d10.RELEASE.im4p)...
Personalizing IMG4 component iBoot...
Personalizing IMG4 component RestoreSEP...
Personalizing IMG4 component SEP...
Sending NORData now...
Done sending NORData
Checkpoint 1545 complete with code 0
Checkpoint 1683 complete with code 0
Unmounting filesystems (29)
Unmounting filesystems (29)
Unmounting filesystems (29)
Unmounting filesystems (29)
Unmounting filesystems (29)
Unmounting filesystems (29)
Checkpoint 1637 complete with code 0
Checkpoint 1556 complete with code 0
Checkpoint 1620 complete with code 0
Checkpoint 1557 complete with code 0
About to send FDR Trust data...
Sending FDR Trust data now...
Done sending FDR Trust Data
Checkpoint 1558 complete with code 0
Checkpoint 1559 complete with code 0
Checkpoint 1560 complete with code 0
Checking for uncollected logs (44)
Checkpoint 1561 complete with code 0
Checking for uncollected logs (44)
ERROR: Unable to receive message from FDR 0x7fa27f2e4750 (-2). 0/2 bytes
ERROR: Unable to receive message from FDR 0x7fa27f707c20 (-2). 0/2 bytes
Checkpoint 1562 complete with code 0
ERROR: Unable to receive message from FDR 0x7fa27f2e4750 (-2). 0/2 bytes
Checkpoint 1563 complete with code 0
Checkpoint 1633 complete with code 0
Unmounting filesystems (29)
Unmounting filesystems (29)
Unmounting filesystems (29)
Unmounting filesystems (29)
Unmounting filesystems (29)
Unmounting filesystems (29)
Checkpoint 1565 complete with code 0
Checkpoint 1614 complete with code 0
Checkpoint 1567 complete with code 0
Checkpoint 1674 complete with code 0
Creating partition map (11)
Checkpoint 1569 complete with code 0
Checkpoint 1632 complete with code 0
Checkpoint 1570 complete with code 0
Checkpoint 1629 complete with code 0
Checkpoint 5645 complete with code 0
Creating filesystem (12)
Checkpoint 1624 complete with code 0
Checkpoint 1625 complete with code 0
Checkpoint 1626 complete with code 0
About to send filesystem...
Connected to ASR
Validating the filesystem
Filesystem validated
Sending filesystem now...
[=====                                             ]   9.0%ERROR: Unable to receive message from FDR 0x7fa27f21f110 (-7). 0/2 bytes
[==================================================] 100.0%
Done sending filesystem
Verifying restore (14)
[==================================================] 100.0%
Checkpoint 1627 complete with code 0
Checkpoint 1664 complete with code 0
Checkpoint 1653 complete with code 0
Checkpoint 1676 complete with code 0
Unmounting filesystems (29)
Unmounting filesystems (29)
Unmounting filesystems (29)
Unmounting filesystems (29)
Unmounting filesystems (29)
Unmounting filesystems (29)
Checking filesystems (15)
Checking filesystems (15)
Checking filesystems (15)
Mounting filesystems (16)
Mounting filesystems (16)
Mounting filesystems (16)
Mounting filesystems (16)
Checkpoint 1574 complete with code 0
Checkpoint 1634 complete with code 0
Checkpoint 1655 complete with code 0
Checkpoint 1658 complete with code 0
Checkpoint 113722144065063 complete with code 0
Checkpoint 4294968914 complete with code 0
Checkpoint 1661 complete with code 0
Checkpoint 1588 complete with code 0
Unknown operation (80)
Sending IsiBootEANFirmware image list
Sending IsiBootNonEssentialFirmware image list
Flashing firmware (18)
[==================================================] 100.0%
Checkpoint 4294972160 complete with code 0
Unknown operation (80)
Sending IsEarlyAccessFirmware image list
Sending IsiBootEANFirmware image list
Sending IsiBootNonEssentialFirmware image list
Checkpoint 4882 complete with code 0
Requesting FUD data (36)
Found IsFUDFirmware component AOP
Found IsFUDFirmware component Homer
Found IsFUDFirmware component RestoreTrustCache
Found IsFUDFirmware component StaticTrustCache
Sending IsFUDFirmware image list
Extracting aopfw-t8010aop.im4p (Firmware/AOP/aopfw-t8010aop.im4p)...
Personalizing IMG4 component AOP...
Sending IsFUDFirmware for AOP...
Extracting homer_D101.im4p (Firmware/homer_D101.im4p)...
Personalizing IMG4 component Homer...
Sending IsFUDFirmware for Homer...
Extracting 048-58904-639.dmg.trustcache (Firmware/048-58904-639.dmg.trustcache)...
Personalizing IMG4 component RestoreTrustCache...
Sending IsFUDFirmware for RestoreTrustCache...
Extracting 048-58826-521.dmg.trustcache (Firmware/048-58826-521.dmg.trustcache)...
Personalizing IMG4 component StaticTrustCache...
Sending IsFUDFirmware for StaticTrustCache...
Checkpoint 4874 complete with code 0
Updating gas gauge software (47)
Checkpoint 1231748362240267009 complete with code 0
Updating gas gauge software (47)
Checkpoint 4294972162 complete with code 0
Updating Stockholm (55)
Checkpoint 1231748362240267012 complete with code 0
Requesting FUD data (36)
Found IsFUDFirmware component AOP
Found IsFUDFirmware component Homer
Found IsFUDFirmware component RestoreTrustCache
Found IsFUDFirmware component StaticTrustCache
Sending IsFUDFirmware image list
Checkpoint 1231748362240267020 complete with code 0
Checkpoint 4294972166 complete with code 0
Checkpoint 3906926831986545415 complete with code 0
Checkpoint 4872 complete with code 0
Checkpoint 4294972174 complete with code 0
Checkpoint 4294972175 complete with code 0
Checkpoint 4294972171 complete with code 0
Updating baseband (19)
About to send BasebandData...
sending request without baseband nonce
Sending Baseband TSS request...
Sending TSS request attempt 1... response successfully received
Received Baseband SHSH blobs
WARNING: size mismatch when parsing MBN file. Continuing anyway.
WARNING: size mismatch when parsing MBN file. Continuing anyway.
Sending BasebandData now...
Done sending BasebandData
Updating Baseband in progress...
About to send BasebandData...
Sending Baseband TSS request...
Sending TSS request attempt 1... response successfully received
Received Baseband SHSH blobs
WARNING: size mismatch when parsing MBN file. Continuing anyway.
WARNING: size mismatch when parsing MBN file. Continuing anyway.
Sending BasebandData now...
Done sending BasebandData
Updating Baseband completed.
Checkpoint 4867 complete with code 0
Checkpoint 1231748362240267024 complete with code 0
Updating SE Firmware (59)
Checkpoint 4294972169 complete with code 0
Checkpoint 4877 complete with code 0
Updating Veridian (66)
Checkpoint 4294972177 complete with code 0
Checkpoint 4294972182 complete with code 0
Checkpoint 1231748362240263733 complete with code 0
Checkpoint 1596 complete with code 0
Checkpoint 4294968943 complete with code 0
Creating Protected Volume (67)
Checkpoint 1652 complete with code 0
Checkpoint 18446744069414585951 complete with code 0
About to send KernelCache...
Extracting kernelcache.release.iphone9 (kernelcache.release.iphone9)...
Personalizing IMG4 component KernelCache...
Sending KernelCache now...
Done sending KernelCache
Installing kernelcache (27)
Checkpoint 3584 complete with code 0
About to send DeviceTree...
Extracting DeviceTree.d101ap.im4p (Firmware/all_flash/DeviceTree.d101ap.im4p)...
Personalizing IMG4 component DeviceTree...
Sending DeviceTree now...
Done sending DeviceTree
Installing DeviceTree (61)
Checkpoint 3585 complete with code 0
About to send NORData...
Found firmware path Firmware/all_flash
Getting firmware manifest from build identity
Extracting LLB.d10.RELEASE.im4p (Firmware/all_flash/LLB.d10.RELEASE.im4p)...
Personalizing IMG4 component LLB...
Extracting applelogo@2x~iphone.im4p (Firmware/all_flash/applelogo@2x~iphone.im4p)...
Personalizing IMG4 component AppleLogo...
Extracting batterycharging0@2x~iphone.im4p (Firmware/all_flash/batterycharging0@2x~iphone.im4p)...
Personalizing IMG4 component BatteryCharging0...
Extracting batterycharging1@2x~iphone.im4p (Firmware/all_flash/batterycharging1@2x~iphone.im4p)...
Personalizing IMG4 component BatteryCharging1...
Extracting batteryfull@2x~iphone.im4p (Firmware/all_flash/batteryfull@2x~iphone.im4p)...
Personalizing IMG4 component BatteryFull...
Extracting batterylow0@2x~iphone.im4p (Firmware/all_flash/batterylow0@2x~iphone.im4p)...
Personalizing IMG4 component BatteryLow0...
Extracting batterylow1@2x~iphone.im4p (Firmware/all_flash/batterylow1@2x~iphone.im4p)...
Personalizing IMG4 component BatteryLow1...
Extracting glyphplugin@1334~iphone-lightning.im4p (Firmware/all_flash/glyphplugin@1334~iphone-lightning.im4p)...
Personalizing IMG4 component BatteryPlugin...
Extracting DeviceTree.d101ap.im4p (Firmware/all_flash/DeviceTree.d101ap.im4p)...
Personalizing IMG4 component DeviceTree...
Extracting liquiddetect@1334~iphone-lightning.im4p (Firmware/all_flash/liquiddetect@1334~iphone-lightning.im4p)...
Personalizing IMG4 component Liquid...
Extracting recoverymode@1334~iphone-lightning.im4p (Firmware/all_flash/recoverymode@1334~iphone-lightning.im4p)...
Personalizing IMG4 component RecoveryMode...
Extracting iBoot.d10.RELEASE.im4p (Firmware/all_flash/iBoot.d10.RELEASE.im4p)...
Personalizing IMG4 component iBoot...
Personalizing IMG4 component RestoreSEP...
Personalizing IMG4 component SEP...
Sending NORData now...
Done sending NORData
Checkpoint 3588 complete with code 0
Checkpoint 3589 complete with code 0
Checkpoint 3587 complete with code 0
Checkpoint 4294968872 complete with code 0
Fixing up /var (17)
Creating system key bag (50)
Checkpoint 3840 complete with code 0
Checkpoint 3841 complete with code 0
Checkpoint 3844 complete with code 0
Checkpoint 3849 complete with code 0
Checkpoint 1613 complete with code 0
Checkpoint 4294968891 complete with code 0
Modifying persistent boot-args (25)
Checkpoint 1593 complete with code 0
Checkpoint 1231748362240263774 complete with code 0
Checkpoint 5377 complete with code 0
Checkpoint 5376 complete with code 0
Checkpoint 5379 complete with code 0
Requesting EAN Data (74)
Checkpoint 5380 complete with code 0
Checkpoint 4884 complete with code 0
Checkpoint 1640 complete with code 0
Checkpoint 1597 complete with code 0
Checkpoint 4294968968 complete with code 0
Checkpoint 1659 complete with code 0
Checkpoint 5632 complete with code 0
Checkpoint 1599 complete with code 0
Checkpoint 1600 complete with code 0
Checkpoint 1675 complete with code 0
Checkpoint 1641 complete with code 0
Unmounting filesystems (29)
Unmounting filesystems (29)
Unmounting filesystems (29)
Unmounting filesystems (29)
Unmounting filesystems (29)
Unmounting filesystems (29)
Checkpoint 4294968898 complete with code 0
Checkpoint 1660 complete with code 0
Checkpoint 5651 complete with code 0
Checkpoint 1607 complete with code 0
Got status message
Status: Restore Finished
Cleaning up...
Done: restoring succeeded!
[*] Done!
[*] Cleaning
[*] Done!
hiprivsid commented 1 year ago

its fixes entering to "Real" DFU