Procházet zdrojové kódy

starting to find important differences and things that are missing from meridian JBD and adding them in, about to make a major change so wanted to commit first

Kevin Bradley před 8 roky
rodič
revize
78868b9979
24 změnil soubory, kde provedl 83 přidání a 49 odebrání
  1. 2 4
      Meridian/Meridian/helpers/helpers.m
  2. 11 9
      Meridian/Meridian/jailbreak.m
  3. binární
      Meridian/jailbreakd/bin/jailbreakd
  4. 19 2
      Meridian/jailbreakd/kern_utils.m
  5. 9 0
      Meridian/jailbreakd/make.sh
  6. 2 0
      Meridian/meridian.xcodeproj/project.pbxproj
  7. binární
      Meridian/meridian.xcodeproj/project.xcworkspace/xcuserdata/kevinbradley.xcuserdatad/UserInterfaceState.xcuserstate
  8. 0 18
      Meridian/meridian.xcodeproj/xcuserdata/kevinbradley.xcuserdatad/xcdebugger/Breakpoints_v2.xcbkptlist
  9. 2 0
      Meridian/meridianTV/Info.plist
  10. 8 8
      Meridian/meridianTV/ViewController.m
  11. binární
      Meridian/meridianTV/bootstrap.tar.gz
  12. 4 1
      Meridian/meridianTV/electra_extras/libsubstrate/Makefile
  13. 1 1
      Meridian/meridianTV/electra_extras/libsubstrate/control
  14. 1 1
      Meridian/meridianTV/electra_extras/sbinject/.theos/_/DEBIAN/control
  15. binární
      Meridian/meridianTV/electra_extras/sbinject/.theos/_/usr/lib/TweakInject.dylib
  16. 1 1
      Meridian/meridianTV/electra_extras/sbinject/.theos/last_package
  17. binární
      Meridian/meridianTV/electra_extras/sbinject/.theos/obj/appletv/debug/TweakInject.dylib
  18. binární
      Meridian/meridianTV/electra_extras/sbinject/.theos/obj/appletv/debug/arm64/SBInject.x.09271890.o
  19. binární
      Meridian/meridianTV/electra_extras/sbinject/.theos/obj/appletv/debug/arm64/SBInject.x.cb64146a.o
  20. binární
      Meridian/meridianTV/electra_extras/sbinject/.theos/obj/appletv/debug/arm64/TweakInject.dylib
  21. 1 1
      Meridian/meridianTV/electra_extras/sbinject/.theos/packages/com.yourcompany.sbinject-0.0.1
  22. 2 0
      Meridian/meridianTV/electra_extras/sbinject/Makefile
  23. 20 3
      Meridian/meridianTV/electra_extras/sbinject/SBInject.x
  24. binární
      Meridian/meridianTV/meridian-bootstrap.tar

+ 2 - 4
Meridian/Meridian/helpers/helpers.m

@@ -333,8 +333,7 @@ int extract_tar(const char *file_path) {
     return execprog("/meridian/tar", (const char **)&(const char*[]) {
         "/meridian/tar",
         "--preserve-permissions",
-        "--no-overwrite-dir",
-        "-keep-newer-files",
+        "--keep-newer-files",
         "--no-xattrs",
         "-C",
         "/",
@@ -368,8 +367,7 @@ int extract_bundle_tar(const char *bundle_name) {
     return execprog("/meridian/tar", (const char **)&(const char*[]) {
         "/meridian/tar",
         "--preserve-permissions",
-        "--no-overwrite-dir",
-        "-keep-newer-files",
+        "--keep-newer-files",
         "-C",
         "/",
         "-xvf",

+ 11 - 9
Meridian/Meridian/jailbreak.m

@@ -82,7 +82,7 @@ int makeShitHappen(ViewController *view) {
     // Remove /meridian in the case of PB's
     if (file_exists("/meridian") == 0 &&
         file_exists("/meridian/.bootstrap") != 0) {
-        [fileMgr removeItemAtPath:@"/meridian" error:nil];
+        [[NSFileManager defaultManager] removeItemAtPath:@"/meridian" error:nil];
     }
     
     if (file_exists("/Library/LaunchDaemons/._dropbear.plist") == 0) {
@@ -322,7 +322,7 @@ int makeShitHappen(ViewController *view) {
     
     // start jailbreakd
     
-    ret = inject_trust("/electra/inject_criticald");
+    ret = inject_trust("/meridian/inject_criticald");
     //ret = inject_trust("/electra/amfid_payload.dylib");
     //ret = inject_trust("/electra/pspawn_payload.dylib");
     //ret = inject_trust("/electra/libjailbreak.dylib");
@@ -469,16 +469,16 @@ void setUpSymLinks() {
     if (file_exists("/Library/MobileSubstrate/DynamicLibraries") == 0 &&
         file_exists("/usr/lib/tweaks") != 0) {
         // Move existing tweaks folder to /usr/lib/tweaks
-        [fileMgr moveItemAtPath:@"/Library/MobileSubstrate/DynamicLibraries" toPath:@"/usr/lib/tweaks" error:nil];
+        [[NSFileManager defaultManager] moveItemAtPath:@"/Library/MobileSubstrate/DynamicLibraries" toPath:@"/usr/lib/tweaks" error:nil];
     } else if (file_exists("/Library/MobileSubstrate/DynamicLibraries") == 0 &&
                file_exists("/usr/lib/tweaks") == 0) {
         // Move existing tweaks to /usr/lib/tweaks and delete the MobSub folder
-        NSArray *fileList = [fileMgr contentsOfDirectoryAtPath:@"/Library/MobileSubstrate/DynamicLibraries" error:nil];
+        NSArray *fileList = [[NSFileManager defaultManager] contentsOfDirectoryAtPath:@"/Library/MobileSubstrate/DynamicLibraries" error:nil];
         for (NSString *item in fileList) {
             NSString *fullPath = [NSString stringWithFormat:@"/Library/MobileSubstrate/DynamicLibraries/%@", item];
-            [fileMgr moveItemAtPath:fullPath toPath:@"/usr/lib/tweaks" error:nil];
+            [[NSFileManager defaultManager] moveItemAtPath:fullPath toPath:@"/usr/lib/tweaks" error:nil];
         }
-        [fileMgr removeItemAtPath:@"/Library/MobileSubstrate/DynamicLibraries" error:nil];
+        [[NSFileManager defaultManager] removeItemAtPath:@"/Library/MobileSubstrate/DynamicLibraries" error:nil];
     } else if (file_exists("/Library/MobileSubstrate/DynamicLibraries") != 0 &&
                file_exists("/usr/lib/tweaks") != 0) {
         // Just create /usr/lib/tweaks - /Lib/MobSub/DynLibs doesn't exist
@@ -511,7 +511,7 @@ int extractBootstrap(int *exitCode) {
     rv = extract_tar("/meridian/bootstrap.tar");
     if (rv != 0) {
         *exitCode = rv;
-        return 1; //FIXME: make sure this is working later.
+        return 1;
     }
     
 //    rv = uicache();
@@ -522,6 +522,8 @@ int extractBootstrap(int *exitCode) {
     
     touch_file("/meridian/.bootstrap");
     
+    touch_file("/var/mobile/Library/Preferences/.kickstart");
+    
     return 0;
 }
 
@@ -653,7 +655,7 @@ int launchDropbear() {
 void setUpSubstitute() {
     // link CydiaSubstrate.framework -> /usr/lib/libsubstrate.dylib
     if (file_exists("/Library/Frameworks/CydiaSubstrate.framework") == 0) {
-        [fileMgr removeItemAtPath:@"/Library/Frameworks/CydiaSubstrate.framework" error:nil];
+        [[NSFileManager defaultManager] removeItemAtPath:@"/Library/Frameworks/CydiaSubstrate.framework" error:nil];
     }
     mkdir("/Library/Frameworks", 0755);
     mkdir("/Library/Frameworks/CydiaSubstrate.framework", 0755);
@@ -745,7 +747,7 @@ int startJailbreakd() {
 }
 
 int loadLaunchDaemons() {
-    NSArray *daemons = [fileMgr contentsOfDirectoryAtPath:@"/Library/LaunchDaemons" error:nil];
+    NSArray *daemons = [[NSFileManager defaultManager] contentsOfDirectoryAtPath:@"/Library/LaunchDaemons" error:nil];
     for (NSString *file in daemons) {
         NSString *path = [NSString stringWithFormat:@"/Library/LaunchDaemons/%@", file];
         NSLog(@"found launchdaemon: %@", path);

binární
Meridian/jailbreakd/bin/jailbreakd


+ 19 - 2
Meridian/jailbreakd/kern_utils.m

@@ -11,6 +11,8 @@
 #define PROC_PIDPATHINFO_MAXSIZE  (4*MAXPATHLEN)
 int proc_pidpath(pid_t pid, void *buffer, uint32_t buffersize);
 
+#define TF_PLATFORM 0x400
+
 #define	CS_VALID		            0x0000001	/* dynamically valid */
 #define CS_ADHOC		            0x0000002	/* ad hoc signed */
 #define CS_GET_TASK_ALLOW	        0x0000004	/* has get-task-allow entitlement */
@@ -102,6 +104,16 @@ void set_csflags(uint64_t proc) {
     wk32(proc + offsetof_p_csflags, csflags);
 }
 
+void set_tfplatform(uint64_t proc) {
+    // task.t_flags & TF_PLATFORM
+    uint64_t task = rk64(proc + offsetof_task);
+    uint32_t t_flags = rk32(task + offsetof_t_flags);
+    fprintf(stderr,"Old t_flags: 0x%x\n", t_flags);
+    t_flags |= TF_PLATFORM;
+    wk32(task+offsetof_t_flags, t_flags);
+    fprintf(stderr,"New t_flags: 0x%x\n", t_flags);
+}
+
 void set_csblob(uint64_t proc) {
     uint64_t textvp = rk64(proc + offsetof_p_textvp); // vnode of executable
     off_t textoff = rk64(proc + offsetof_p_textoff);
@@ -134,6 +146,7 @@ void set_csblob(uint64_t proc) {
     }
 }
 
+
 const char* abs_path_exceptions[] = {
     "/meridian",
     "/Library",
@@ -144,7 +157,7 @@ const char* abs_path_exceptions[] = {
 
 uint64_t get_exception_osarray(void) {
     static uint64_t cached = 0;
-
+    
     if (cached == 0) {
         cached = OSUnserializeXML(
             "<array>"
@@ -242,8 +255,12 @@ int setcsflagsandplatformize(int pid) {
         NSLog(@"Unable to find pid %d to entitle!", pid);
         return 1;
     }
-    
+    fprintf(stderr,"setcsflagsandplatformize start on PID %d\n", pid);
+    char name[40] = {0};
+    kread(proc+0x268, name, 20);
+    fprintf(stderr,"PID %d name is %s\n", pid, name);
     set_csflags(proc);
+    set_tfplatform(proc);
     set_amfi_entitlements(proc);
     set_sandbox_extensions(proc);
     set_csblob(proc);

+ 9 - 0
Meridian/jailbreakd/make.sh

@@ -0,0 +1,9 @@
+#!/bin/bash
+
+make
+cp bin/jailbreakd ../meridianTV/meridian-bootstrap/meridian/jailbreakd/
+pushd ../meridianTV/meridian-bootstrap
+mv ../meridian-bootstrap.tar ../meridian-bootstrap.tar.last
+sudo gtar cp --exclude .DS_Store -f ../meridian-bootstrap.tar bin meridian private usr
+
+

+ 2 - 0
Meridian/meridian.xcodeproj/project.pbxproj

@@ -74,6 +74,7 @@
 		32E5EAF320E8AE7B00346489 /* ent.plist in Resources */ = {isa = PBXBuildFile; fileRef = 32E5EAF120E8AE7600346489 /* ent.plist */; };
 		32E5EAF420E8AE7D00346489 /* launchctl.gz in Resources */ = {isa = PBXBuildFile; fileRef = 32E5EAF220E8AE7600346489 /* launchctl.gz */; };
 		32E5EAF520E8AE8000346489 /* rm.gz in Resources */ = {isa = PBXBuildFile; fileRef = 32E5EAF020E8AE7600346489 /* rm.gz */; };
+		32E5EAF620E8CEC400346489 /* bgTemp.jpg in Resources */ = {isa = PBXBuildFile; fileRef = 32E5EAEF20E8AC7B00346489 /* bgTemp.jpg */; };
 		B50F79571FF2248D000D6015 /* patchfinder64.c in Sources */ = {isa = PBXBuildFile; fileRef = B50F79401FF2248B000D6015 /* patchfinder64.c */; };
 		B50F795C1FF2248D000D6015 /* root-rw.m in Sources */ = {isa = PBXBuildFile; fileRef = B50F79461FF2248B000D6015 /* root-rw.m */; };
 		B50F79601FF2248D000D6015 /* AppDelegate.m in Sources */ = {isa = PBXBuildFile; fileRef = B50F794A1FF2248B000D6015 /* AppDelegate.m */; };
@@ -789,6 +790,7 @@
 				32E5EAF520E8AE8000346489 /* rm.gz in Resources */,
 				320AFA9220E215AD00859485 /* system-base.tar in Resources */,
 				3249301C20E41D5400E99767 /* jailbreakd.plist in Resources */,
+				32E5EAF620E8CEC400346489 /* bgTemp.jpg in Resources */,
 				320AFA9420E215C100859485 /* build_time in Resources */,
 				320AFA8E20E215AD00859485 /* dpkgdb-base.tar in Resources */,
 				320AFA9320E215AD00859485 /* tar.tar in Resources */,

binární
Meridian/meridian.xcodeproj/project.xcworkspace/xcuserdata/kevinbradley.xcuserdatad/UserInterfaceState.xcuserstate


+ 0 - 18
Meridian/meridian.xcodeproj/xcuserdata/kevinbradley.xcuserdatad/xcdebugger/Breakpoints_v2.xcbkptlist

@@ -2,22 +2,4 @@
 <Bucket
    type = "1"
    version = "2.0">
-   <Breakpoints>
-      <BreakpointProxy
-         BreakpointExtensionID = "Xcode.Breakpoint.FileBreakpoint">
-         <BreakpointContent
-            shouldBeEnabled = "Yes"
-            ignoreCount = "0"
-            continueAfterRunningActions = "No"
-            filePath = "Meridian/jailbreak.m"
-            timestampString = "551977791.286967"
-            startingColumnNumber = "9223372036854775807"
-            endingColumnNumber = "9223372036854775807"
-            startingLineNumber = "40"
-            endingLineNumber = "40"
-            landmarkName = "makeShitHappen"
-            landmarkType = "9">
-         </BreakpointContent>
-      </BreakpointProxy>
-   </Breakpoints>
 </Bucket>

+ 2 - 0
Meridian/meridianTV/Info.plist

@@ -4,6 +4,8 @@
 <dict>
 	<key>CFBundleDevelopmentRegion</key>
 	<string>$(DEVELOPMENT_LANGUAGE)</string>
+	<key>CFBundleDisplayName</key>
+	<string>backroom</string>
 	<key>CFBundleExecutable</key>
 	<string>$(EXECUTABLE_NAME)</string>
 	<key>CFBundleIdentifier</key>

+ 8 - 8
Meridian/meridianTV/ViewController.m

@@ -40,7 +40,7 @@ typedef NS_ENUM(NSInteger, BSInstallType) {
 
 
 @property (readwrite, assign) BSInstallType installMode; //0 = meridian 1 = electra
-@property (strong, nonatomic) FocusedButton *goButton;
+@property (strong, nonatomic) UIButton *goButton;
 @property (strong, nonatomic) UIButton *creditsButton;
 @property (strong, nonatomic) UIButton *websiteButton;
 @property (strong, nonatomic) UIActivityIndicatorView *progressSpinner;
@@ -165,11 +165,11 @@ bool jailbreak_has_run = false;
     [meridianTV setText:@"backr00m"];
     [meridianTV setTextColor:[UIColor whiteColor]];
     
-    self.goButton = [[FocusedButton alloc] initForAutoLayout] ;
+    self.goButton = [UIButton buttonWithType:UIButtonTypeSystem];
     [self.goButton autoSetDimensionsToSize:CGSizeMake(250, 100)];
     [self.goButton setTitle:@"jailbreak" forState:UIControlStateFocused];
-    [self.goButton buttonColors:[UIColor colorFromHex:@"DB1E00"]
-                   andUnfocused:[UIColor darkTextColor]];
+    //[self.goButton buttonColors:[UIColor colorFromHex:@"DB1E00"]
+      //             andUnfocused:[UIColor darkTextColor]];
     [self.view addSubview:self.goButton];
     [self.goButton autoCenterInSuperview];
     [self.goButton addTarget:self action:@selector(goButtonPressed:) forControlEvents:UIControlEventPrimaryActionTriggered];
@@ -178,7 +178,7 @@ bool jailbreak_has_run = false;
     self.versionLabel.textColor = [UIColor whiteColor];
     [self.view addSubview:self.versionLabel];
     [self.versionLabel autoAlignAxisToSuperviewAxis:ALAxisVertical];
-    [self.versionLabel autoPinEdge:ALEdgeTop toEdge:ALEdgeBottom ofView:self.goButton withOffset:5];
+    [self.versionLabel autoPinEdge:ALEdgeTop toEdge:ALEdgeBottom ofView:self.goButton withOffset:10];
     
     self.textArea = [[UITextView alloc] initForAutoLayout];
     [self.view addSubview:self.textArea];
@@ -187,9 +187,9 @@ bool jailbreak_has_run = false;
     [self.textArea autoMatchDimension:ALDimensionWidth toDimension:ALDimensionWidth ofView:self.view withMultiplier:0.8];
     [self.textArea autoPinEdgeToSuperviewEdge:ALEdgeBottom withInset:40];
     //[self.goButton setBackgroundColor:[UIColor colorFromHex:@"DB1E00"]];
-    [self.goButton setTitleColor:[UIColor whiteColor] forState:UIControlStateNormal];
-    [self.goButton setTitleColor:[UIColor whiteColor] forState:UIControlStateDisabled];
-    [self.goButton setTitleColor:[UIColor whiteColor] forState:UIControlStateFocused];
+    [self.goButton setTitleColor:[UIColor blackColor] forState:UIControlStateNormal];
+    [self.goButton setTitleColor:[UIColor blackColor] forState:UIControlStateDisabled];
+    [self.goButton setTitleColor:[UIColor blackColor] forState:UIControlStateFocused];
     [self.textArea setBackgroundColor:[UIColor blackColor]];
     [self.textArea setTextColor:[UIColor colorFromHex:@"CACBCA"]];
     //DB1E00

binární
Meridian/meridianTV/bootstrap.tar.gz


+ 4 - 1
Meridian/meridianTV/electra_extras/libsubstrate/Makefile

@@ -1,5 +1,8 @@
 ARCHS=arm64
-include $(THEOS)/makefiles/common.mk
+TARGET = appletv
+#export SDKVERSION=10.1
+include theos/makefiles/common.mk
+THEOS_DEVICE_IP=apple-tv.local
 
 LIBRARY_NAME = libsubstrate
 libsubstrate_FILES = libsubstrate.c

+ 1 - 1
Meridian/meridianTV/electra_extras/libsubstrate/control

@@ -1,4 +1,4 @@
-Package: org.coolstar.substrate-substitute-shim
+Package: mobilesubstrate
 Name: libsubstrate
 Depends: 
 Version: 0.0.1

+ 1 - 1
Meridian/meridianTV/electra_extras/sbinject/.theos/_/DEBIAN/control

@@ -7,5 +7,5 @@ Maintainer: CoolStar
 Author: CoolStar
 Section: System
 Tag: role::developer
-Version: 0.0.1-4
+Version: 0.0.1-11
 Installed-Size: 88

binární
Meridian/meridianTV/electra_extras/sbinject/.theos/_/usr/lib/TweakInject.dylib


+ 1 - 1
Meridian/meridianTV/electra_extras/sbinject/.theos/last_package

@@ -1 +1 @@
-./debs/com.yourcompany.sbinject_0.0.1-4_appletvos-arm64.deb
+./debs/com.yourcompany.sbinject_0.0.1-11_appletvos-arm64.deb

binární
Meridian/meridianTV/electra_extras/sbinject/.theos/obj/appletv/debug/TweakInject.dylib


binární
Meridian/meridianTV/electra_extras/sbinject/.theos/obj/appletv/debug/arm64/SBInject.x.09271890.o


binární
Meridian/meridianTV/electra_extras/sbinject/.theos/obj/appletv/debug/arm64/SBInject.x.cb64146a.o


binární
Meridian/meridianTV/electra_extras/sbinject/.theos/obj/appletv/debug/arm64/TweakInject.dylib


+ 1 - 1
Meridian/meridianTV/electra_extras/sbinject/.theos/packages/com.yourcompany.sbinject-0.0.1

@@ -1 +1 @@
-4
+11

+ 2 - 0
Meridian/meridianTV/electra_extras/sbinject/Makefile

@@ -1,6 +1,8 @@
 ARCHS=arm64
 TARGET = appletv
+export SDKVERSION=10.1
 include theos/makefiles/common.mk
+THEOS_DEVICE_IP=apple-tv.local
 
 LIBRARY_NAME = TweakInject
 TweakInject_LIBRARIES = substrate

+ 20 - 3
Meridian/meridianTV/electra_extras/sbinject/SBInject.x

@@ -35,7 +35,8 @@ NSArray *sbinjectGenerateDylibList() {
         return nil;
     }
     // Read current bundle identifier
-    //NSString *bundleIdentifier = NSBundle.mainBundle.bundleIdentifier;
+    NSString *bundleIdentifier = NSBundle.mainBundle.bundleIdentifier;
+    NSLog(@"bundleID: %@", bundleIdentifier);
     // We're only interested in the plist files
     NSArray *plists = [dylibDirContents filteredArrayUsingPredicate:[NSPredicate predicateWithFormat:@"SELF ENDSWITH %@", @"plist"]];
     // Create an empty mutable array that will contain a list of dylib paths to be injected into the target process
@@ -61,6 +62,19 @@ NSArray *sbinjectGenerateDylibList() {
             }
         }
         // Decide whether or not to load the dylib based on the Bundles values
+        
+        NSArray *injectBundles = filter[@"Filter"][@"Bundles"];
+        //NSLog(@"bundles: %@", injectBundles);
+
+        if ([injectBundles containsObject:bundleIdentifier]){
+
+            //NSLog(@"inject bundles contains object: %@", bundleIdentifier);
+            
+            [dylibsToInject addObject:[[plistPath stringByDeletingPathExtension] stringByAppendingString:@".dylib"]];
+            isInjected = YES;
+            break;
+        }
+        /*
         for (NSString *entry in filter[@"Filter"][@"Bundles"]) {
             // Check to see whether or not this bundle is actually loaded in this application or not
             if (!CFBundleGetBundleWithIdentifier((CFStringRef)entry)) {
@@ -71,6 +85,7 @@ NSArray *sbinjectGenerateDylibList() {
             isInjected = YES;
             break;
         }
+        */
         if (!isInjected) {
             // Decide whether or not to load the dylib based on the Executables values
             for (NSString *process in filter[@"Filter"][@"Executables"]) {
@@ -235,9 +250,11 @@ static void ctor(void) {
 
             if (!safeMode){
 
-                HBLogInfo(@"### TEST LOG");
+                //HBLogInfo(@"In bundle: %@", NSBundle.mainBundle.bundleIdentifier);
 
-                for (NSString *dylib in sbinjectGenerateDylibList()) {
+                NSArray *theList = sbinjectGenerateDylibList();
+                //HBLogInfo(@"theList: %@", theList);
+                for (NSString *dylib in theList) {
                     NSLog(@"Injecting %@", dylib);
                     void *dl = dlopen([dylib UTF8String], RTLD_LAZY | RTLD_GLOBAL);
 

binární
Meridian/meridianTV/meridian-bootstrap.tar