Sploitus

Exploit for W0lfSword

githubexploit Β· 2026-08-10

Exploit Code

README585 lines
## https://sploitus.com/exploit?id=C0BCFFC1-7654-577E-A8FF-355FCC99E4E3
# W0lfSword β€” iOS Kernel Exploit Toolkit

```
                             __
                         .d$$b
                       .' TO$;\
                      /  : TP._;
                     / _.;  :Tb|
                    /   /   ;j$j
                _.-"       d$$$$
              .' ..       d$$$$;
             /  /P'      d$$$$P. |\
            /   "      .d$$$P' |\^"l
          .'           `T$P^"""""  :
      ._.'      _.'                ;
   `-.-".-'-' ._.       _.-"    .-"
 `.-" _____  ._              .-"
-.(g$$$$$$$b.              .'
  ""^^T$$$P^)            .(:
    _/  -"  /.'         /:/;
 ._.'-'`-'  ")/         /;/;
`-.-"..--""   " /         /  ;
.-" ..--""        -'          :
..--""--.-"         (\      .-(\
  ..--""              `-\(\/;`
    _.                      :
                            ;`-
                           :\
                           ;
```

> **Made by [kaffeindecaf](https://github.com/kaffeindecaf)**  
> Kernel-level sandbox escape + Signed System Volume bypass for iOS 17.0–26.0.1  
> Powered by the **DarkSword** exploit engine β€” ICMPv6 + IOSurface β†’ kernel R/W

---

## Table of Contents

- [Credits & Attribution](#credits--attribution)
- [Features](#features)
- [Supported Devices](#supported-devices--ios-versions)
- [Project Layout](#project-layout)
- [Architecture](#architecture)
- [Quick Start](#quick-start)
- [Scripts](#scripts)
  - [W0lfSword (Project CLI)](#filza-toolsh-project-cli)
  - [build_and_extract.sh](#build_and_extractsh)
- [Build Guide](#build-guide)
- [Installation](#installation)
- [Diagnostics](#diagnostics)
- [Troubleshooting](#troubleshooting)
- [Documentation Files](#documentation-files)
- [Known Issues](#known-issues)
- [Contributing](#contributing)
- [License](#license)

---

## Credits & Attribution

This project builds on the work of many people in the jailbreak community.  
All original research, exploitation techniques, and core infrastructure were developed by:

| Person | Contribution |
|--------|-------------|
| **[Huy Nguyen](https://github.com/34306/)** | **Original repository author** β€” created the initial FilzaJailedDS project |
| **[wh1te4ever](https://github.com/wh1te4ever/)** | DarkSword kernel exploit (ICMPv6 + IOSurface) & XPF offset resolution engine |
| **[opa334](https://github.com/opa334/)** | XPF patchfinder, kernel read/write primitives, sandbox extension structures |
| **[Duy Tran](https://github.com/khanhduytran0/)** | Sandbox hook token technique |
| **[CrazyMind90](https://github.com/crazymind90/)** | Sandbox token acquisition via kernel R/W only |
| **[XEmaz](https://x.com/XEmaz_)** | SVV bypass integration, root chown, padlock bypass, license bypass, zip hooks |
| **[kaffeindecaf](https://github.com/kaffeindecaf)** | iOS 26.0.1 optimization, retry logic, thread safety, logging consolidation, tooling |

> **This repository:** [`XEmaz/W0lfSword`](https://github.com/XEmaz/W0lfSword)  
> **Original source:** [`34306/FilzaJailedDS`](https://github.com/34306/FilzaJailedDS)  
> **Informed by:** [`felix-pb/kfd`](https://github.com/felix-pb/kfd) (PUAF primitives), [`opa334/TrollStore`](https://github.com/opa334/TrollStore) (CoreTrust bypass), [`opa334/opainject`](https://github.com/opa334/opainject) (ROP injection)

---

## Features

| Feature | Description |
|---------|-------------|
| **Kernel Exploit** | DarkSword (ICMPv6 socket spray + IOSurface physical OOB) β€” kernel read/write |
| **Retry Loop** | Exploit retries up to 5 times with exponential backoff (README said "2-3 attempts needed") |
| **Sandbox Escape** | Walks `proc β†’ ucred β†’ label β†’ sandbox β†’ ext_set`, patches extensions to `"/"` |
| **SSV Bypass** | Vnode data pointer swap β€” writes to `/System/`, `/usr/`, `/bin/`, `/sbin/` |
| **Root Ownership** | Automatically `chown root:wheel` on files created in sealed paths |
| **Root Helper Bypass** | All `TGRootFileManager` XPC calls intercepted β€” no helper needed |
| **Zip/Unzip** | Uses Filza's own minizip symbols via dlsym (13 function pointers validated) |
| **License Bypass** | Suppresses "binary was modified" and activation nag alerts |
| **Padlock Bypass** | Hooks `NZFileBrowserController`, `NZFileItem` β€” always allows edit/delete |
| **Apps Manager Fix** | Filesystem scanner populates app list when LSApplicationWorkspace returns empty |
| **Thread Safety** | `_Atomic bool` with `memory_order_acquire/release` for cross-thread flags |
| **Consolidated Logging** | Single `/tmp/FilzaTweak.log` with 4MB rotation + trylock fallback to stderr |
| **Runtime Toggle** | `touch /var/mobile/Documents/.filza_tweak_disable` to disable without uninstalling |
| **Offset Verification** | Thread kstackptr validated against VM bounds before any kernel writes |

---

## Supported Devices & iOS Versions

| iOS Version | A12-A14 | A15 (SE3, 13) | A16 (14 Pro) | A17 (15 Pro) | A18 (16) | M1-M4 |
|-------------|---------|---------------|--------------|--------------|----------|-------|
| 17.0–17.7 | βœ“ | βœ“ | βœ“ | βœ“ | β€” | βœ“ |
| 18.0–18.7.7 | βœ“ | βœ“ | βœ“ | βœ“ | βœ“ | βœ“ |
| 26.0–26.0.1 | βœ“ | βœ“ | βœ“ | βœ“ | βœ“ | βœ“ |

**Not supported:** iPhone 17 series (A19), iPad M5 β€” Apple added MTE (Memory Tagging Extension) which blocks kernel R/W.

---

## Project Layout

```
W0lfSword/
β”œβ”€β”€ Tweak.m                          # Main orchestrator (1185 lines)
β”œβ”€β”€ sandbox_escape.h / .m            # Sandbox escape via kernel extension patching
β”œβ”€β”€ FilzaPadlockBypass.h / .xm       # Filza UI padlock bypass (Logos hooks)
β”‚
β”œβ”€β”€ kexploit/                        # Kernel Exploit Engine (32 files)
β”‚   β”œβ”€β”€ kexploit_opa334.h / .m       # DarkSword: ICMPv6 spray + IOSurface OOB
β”‚   β”œβ”€β”€ krw.h / .m                   # kread64/kwrite64/kreadbuf post-exploit primitives
β”‚   β”œβ”€β”€ kutils.h / .m                # proc/task/thread lookup, AMFI, label accessors
β”‚   β”œβ”€β”€ offsets.h / .m               # Per-iOS-version kernel struct offset table
β”‚   β”œβ”€β”€ sandbox.h / .m               # Extension patching + multi-daemon borrow fallback
β”‚   β”œβ”€β”€ vnode.h / .m                 # Vnode redirection, child lookup, hide/reveal
β”‚   β”œβ”€β”€ file.h / .m                  # File overwrite via vnode data pointer swap
β”‚   β”œβ”€β”€ PAC.h / .m / xpaci.h         # Pointer Authentication Code stripping (arm64e)
β”‚   β”œβ”€β”€ VM.h / .m                    # Kernel VM map entry/object manipulation
β”‚   β”œβ”€β”€ Thread.h / .m                # Remote thread state + guard exception injection
β”‚   β”œβ”€β”€ Exception.h / .m             # Mach exception port + reply construction
β”‚   β”œβ”€β”€ RemoteCall.h / .m            # Remote function calling via thread hijack + gadgets
β”‚   β”œβ”€β”€ MigFilterBypassThread.h / .m  # MIG sandbox filter bypass
β”‚   β”œβ”€β”€ sandbox_backup.m             # Backup/restore sandbox state
β”‚   β”œβ”€β”€ vnode_research.h / .m         # APFS fsnode structure dump
β”‚   β”œβ”€β”€ apfs_fsnode.h                # Full reverse-engineered APFS inode struct (570 lines)
β”‚   └── machine_info.h               # CPU family constants (A8 through A18 Pro + M1-M4)
β”‚
β”œβ”€β”€ SSV/                             # Signed System Volume Bypass
β”‚   └── SSVUtils.h / .m              # Temp β†’ vnode redirect β†’ write β†’ chown root:wheel
β”‚
β”œβ”€β”€ utils/                           # Utilities
β”‚   β”œβ”€β”€ tweak_log.h                  # Consolidated logging (mutex, trylock, 4MB rotation)
β”‚   β”œβ”€β”€ permission_utils.h / .m      # Kernel-level chown/chmod via fsnode patching
β”‚   β”œβ”€β”€ file.h / .c                  # File hide/reveal via VISSHADOW vnode flag
β”‚   β”œβ”€β”€ hexdump.h / .c              # Hex dump output for debugging
β”‚   └── process.h / .c              # Process crash/watch, ASLR toggle
β”‚
β”œβ”€β”€ kpf/                             # Kernel Patchfinder
β”‚   └── patchfinder.h / .m          # Extract kernelcache β†’ initialize XPF offset engine
β”‚
β”œβ”€β”€ XPF/                             # XPF Offset Patchfinder
β”‚   β”œβ”€β”€ src/                         # Core (12 files): xpf, common, decompress, bad_recovery, non_ppl, ppl
β”‚   └── external/ChOma/src/         # Mach-O + dyld cache parser (34 files)
β”‚
β”œβ”€β”€ research/                        # Reverse-engineered struct definitions
β”‚   └── sandbox_research.h          # Kernel sandbox_label, extension_set, extension structs
β”‚
β”œβ”€β”€ scripts & docs
β”‚   β”œβ”€β”€ W0lfSword                     # Project CLI β€” 12 commands (build, deploy, audit, status, log...)
β”‚   β”œβ”€β”€ W0lfSword-Beta                # Interactive exploit menu β€” superset of W0lfSword
β”‚   β”œβ”€β”€ build_and_extract.sh          # Build + auto-extract .dylib
β”‚   β”œβ”€β”€ Makefile                      # Theos build system (iphone:clang:latest:15.0, arm64)
β”‚   β”œβ”€β”€ control                      # Debian package metadata (v0.7.6)
β”‚   β”œβ”€β”€ FilzaApplySandboxExt.plist   # MobileSubstrate filter (bundle: com.tigisoftware.Filza)
β”‚   β”œβ”€β”€ README.md                    # This file
β”‚   β”œβ”€β”€ CONTEXT.md                   # Full project knowledge base for AI session resumption
β”‚   β”œβ”€β”€ AUDIT_REPORT.md              # 20 findings + 11 fixes applied + PR guide
β”‚   β”œβ”€β”€ BUG_BOUNTY.md                # 14 security findings with Apple bounty ranges
β”‚   β”œβ”€β”€ DEBUG_TRACKING.md            # Every log statement mapped by file:line + strip guide
β”‚   β”œβ”€β”€ ROADMAP.md                   # 98-item checklist for features, bugs, research
β”‚   └── BUILD.md                     # Theos explanation + build instructions + troubleshooting
β”‚
β”œβ”€β”€ .theos/                          # Theos build artifacts (auto-generated)
└── packages/                        # Pre-built .deb packages
```

**Total:** 68 source files (.h/.m/.xm/.c) + 8 documentation files.

---

## Architecture

```
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚                    Filza App (com.tigisoftware.Filza)            β”‚
β”‚                                                                 β”‚
β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”‚
β”‚  β”‚               FilzaApplySandboxExt.dylib                   β”‚  β”‚
β”‚  β”‚          (MobileSubstrate β€” injected at load time)         β”‚  β”‚
β”‚  β”‚                                                            β”‚  β”‚
β”‚  β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”    β”‚  β”‚
β”‚  β”‚  β”‚  Tweak.m    β”‚  β”‚ PadlockBypassβ”‚  β”‚  SSVUtils      β”‚    β”‚  β”‚
β”‚  β”‚  β”‚ (orchestrator)β”‚  β”‚ (.xm hooks) β”‚  β”‚ (vnode redirect)β”‚   β”‚  β”‚
β”‚  β”‚  β””β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”˜  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β””β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”˜    β”‚  β”‚
β”‚  β”‚         β”‚                                    β”‚             β”‚  β”‚
β”‚  β”‚  β”Œβ”€β”€β”€β”€β”€β”€β–Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β–Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”     β”‚  β”‚
β”‚  β”‚  β”‚                kexploit/                           β”‚     β”‚  β”‚
β”‚  β”‚  β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”Œβ”€β”€β”€β”€β”€β”€β”€β”  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”    β”‚     β”‚  β”‚
β”‚  β”‚  β”‚  β”‚ DarkSword β”‚β†’ β”‚ krw   β”‚β†’ β”‚ sandbox ext patchβ”‚   β”‚     β”‚  β”‚
β”‚  β”‚  β”‚  β”‚ ICMPv6+IO β”‚  β”‚(kread β”‚  β”‚ borrow_sandbox  β”‚    β”‚     β”‚  β”‚
β”‚  β”‚  β”‚  β”‚  surface  β”‚  β”‚ kwrite)β”‚  β”‚ (4-daemon fallback)β”‚  β”‚     β”‚  β”‚
β”‚  β”‚  β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β””β”€β”€β”€β”€β”€β”€β”€β”˜  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜    β”‚     β”‚  β”‚
β”‚  β”‚  β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”       β”‚     β”‚  β”‚
β”‚  β”‚  β”‚  β”‚  XPF + ChOma (dynamic offset resolution)β”‚      β”‚     β”‚  β”‚
β”‚  β”‚  β”‚  β”‚  kernelcache β†’ decompress β†’ parse      β”‚       β”‚     β”‚  β”‚
β”‚  β”‚  β”‚  β”‚  β†’ pattern match β†’ struct offsets      β”‚       β”‚     β”‚  β”‚
β”‚  β”‚  β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜       β”‚     β”‚  β”‚
β”‚  β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜     β”‚  β”‚
β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
```

### Exploit Pipeline

```
TweakInit() β†’ installHooks() β†’ scheduleExploitOnce() [1s delay]
β†’ runExploit() [5 retries, exponential backoff]
  β†’ offsets_init()          [resolve kernel struct offsets]
  β†’ kexploit_opa334()       [socket spray + OOB race β†’ kernel R/W]
  → sandbox_escape()        [walk proc→sandbox ext table, patch to "/"]
  β†’ patch_sandbox_ext()     [SSV write activation, 4-daemon borrow fallback]
β†’ All hooks active, SSV writes functional
β†’ thread kstackptr verified against VM_MIN/VM_MAX before writes
```

---

## Quick Start

```bash
# 1. Clone
git clone https://github.com/XEmaz/W0lfSword.git
cd FilzaJailedDS-SSV-Bypass

# 2. Check your environment
./W0lfSword doctor

# 3. Build
./W0lfSword build

# 4. Install on device (set IP once, saved for future)
./W0lfSword deploy 192.168.1.5

# 5. Watch the logs
./W0lfSword log

# 6. Check project status
./W0lfSword status

# 7. Run static analysis before committing
./W0lfSword audit
```

---

## Scripts

### `W0lfSword` β€” Project CLI

```
╔══════════════════════════════════════════════════╗
β•‘  FilzaJailedDS-SSV-Bypass                        β•‘
β•‘  Made by kaffeindecaf                             β•‘
β•šβ•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•

Usage: ./W0lfSword  [args...]
```

| Command | Description | Example |
|---------|-------------|---------|
| `build` | Compile tweak + create .deb | `./W0lfSword build` |
| `extract` | Extract .dylib from built .deb | `./W0lfSword extract` |
| `deploy ` | scp .deb β†’ dpkg -i β†’ killall Filza on device | `./W0lfSword deploy 192.168.1.5` |
| `status` | Project health: git, build, ROADMAP progress | `./W0lfSword status` |
| `audit` | Static analysis: brace balance, printf count, offset coverage | `./W0lfSword audit` |
| `log [n]` | Fetch last n lines of `/tmp/FilzaTweak.log` from device | `./W0lfSword log 100` |
| `toggle on\|off` | Enable/disable tweak on device via flag file | `./W0lfSword toggle off` |
| `offsets [ver]` | Show offset table coverage per iOS version | `./W0lfSword offsets 26.0` |
| `clean` | Clean build artifacts + temp files | `./W0lfSword clean` |
| `doctor` | Check environment: THEOS, SDK, ssh, dpkg, clang, device | `./W0lfSword doctor` |
| `targets` | Show all supported apps + exploit techniques | `./W0lfSword targets` |
| `help` | Show this reference | `./W0lfSword help` |

**Device IP configuration:** Run `./W0lfSword deploy ` once to save the IP. Subsequent `log`, `toggle`, and `deploy` commands will use the saved IP automatically. The IP is stored in `.device_ip` (gitignored).

**Color-coded log output:** The `log` command color-codes lines by severity β€” green for success/SANDBOX ESCAPED, red for errors/failures, yellow for warnings/retries, cyan for structural logs, dim for detail.

### `W0lfSword-Beta` β€” Interactive Exploit Menu

W0lfSword-Beta is a **superset** of W0lfSword. It includes every original command unchanged, plus an interactive exploit menu when run with no arguments.

```
                             __
                         .d$$b
                       .' TO$;\
                      /  : TP._;
                     / _.;  :Tb|
                    /   /   ;j$j
                _.-"       d$$$$
              .' ..       d$$$$;
             /  /P'      d$$$$P. |\
            /   "      .d$$$P' |\^"l
          .'           `T$P^"""""  :
      ._.'      _.'                ;
   `-.-".-'-' ._.       _.-"    .-"
 `.-" _____  ._              .-"
-.(g$$$$$$$b.              .'
  ""^^T$$$P^)            .(:
    _/  -"  /.'         /:/;
 ._.'-'`-'  ")/         /;/;
`-.-"..--""   " /         /  ;
.-" ..--""        -'          :
..--""--.-"         (\      .-(\
  ..--""              `-\(\/;`
    _.                      :
                            ;`-
                           :\
                           ;

  W0lfSword-Beta  iOS Exploit Menu
  DarkSword Engine β€” Made by kaffeindecaf
```

```bash
./W0lfSword-Beta                 # Interactive menu (no args)
./W0lfSword-Beta quick           # One-shot: build β†’ deploy β†’ verify
./W0lfSword-Beta profile save    # Save current exploit config
./W0lfSword-Beta device add      # Add/manage test devices
./W0lfSword-Beta monitor         # Real-time log viewer
./W0lfSword-Beta history stats   # Exploit success rate dashboard
./W0lfSword-Beta build           # All original W0lfSword commands work too
```

**Interactive Menu:**
```
  [1] Quick Exploit      Build β†’ Deploy β†’ Verify
  [2] Deploy Only        Install on device
  [3] Device Manager     Add/switch devices
  [4] Live Monitor       Real-time log viewer
  [5] Profiles           Save/load configs
  [6] History            Exploit stats
  [7] Diagnostics        Doctor, audit, status
  [8] Targets            Supported apps
  [q] Quit
```

**New Beta-only commands:**

| Command | Description |
|---------|-------------|
| `quick` | One-command exploit chain: builds, deploys, waits for exploit, verifies log output |
| `profile save ` | Save current device/target/retry settings as a named profile |
| `profile load ` | Load a saved profile |
| `profile list` | Show all profiles with colored status |
| `device add ` | Add a test device to the manager |
| `device list` | Show all devices with ping status |
| `device switch ` | Switch active device |
| `device info [ip]` | Show iOS version, model, kernel version of device |
| `monitor` | Real-time `tail -f` of device log with color coding |
| `history` | Show exploit attempt log with timestamps |
| `history stats` | Dashboard: total attempts, success rate %, ASCII bar chart |

Data stored in `.w0lfsword/` directory (profiles, devices, history β€” gitignored).

### `build_and_extract.sh`

```bash
./build_and_extract.sh              # Build then extract .dylib to project root
./build_and_extract.sh --keep-temp  # Keep the extraction directory for inspection
```

Compiles the tweak via Theos, unpacks the resulting `.deb`, copies `FilzaApplySandboxExt.dylib` to the project root, and prints file type + linked libraries. Made by kaffeindecaf.

---

## Build Guide

### What is Theos?

**Theos** is a cross-platform build system for iOS tweak development. It:

1. **Cross-compiles** Objective-C/C/C++/Logos code for iOS (arm64/arm64e)
2. **Links** against iOS SDKs (UIKit, IOKit, IOSurface, etc.)
3. **Packages** the compiled dylib + plist into a `.deb` for jailbroken devices
4. **Preprocesses Logos** β€” `.xm` files with `%hook`/`%orig`/`%log` syntax become MobileSubstrate hook code

### Prerequisites

**macOS:**
```bash
xcode-select --install
bash -c "$(curl -fsSL https://raw.githubusercontent.com/theos/theos/master/bin/install-theos)"
echo 'export THEOS=~/theos' >> ~/.zshrc && source ~/.zshrc
brew install dpkg
```

**Linux:**
```bash
bash -c "$(curl -fsSL https://raw.githubusercontent.com/theos/theos/master/bin/install-theos)"
echo 'export THEOS=~/theos' >> ~/.bashrc && source ~/.bashrc
# Get iOS SDK from: https://github.com/theos/sdks (place in $THEOS/sdks/)
sudo apt install dpkg fakeroot clang lld
```

### Build

```bash
# Full build + package
make package

# Build only (no .deb)
make

# Build for release (strips debug symbols)
make package FINALPACKAGE=1

# Clean
make clean
```

---

## Installation

```bash
# Option A: Using the CLI (recommended)
./W0lfSword build && ./W0lfSword deploy 192.168.1.5

# Option B: Manual
scp packages/com.local.filzaescaped_*.deb root@:/tmp/
ssh root@ "dpkg -i /tmp/com.local.filzaescaped_*.deb && killall -9 Filza"
```

The tweak injects into `com.tigisoftware.Filza` via MobileSubstrate. Restart Filza β€” the exploit runs automatically within 1-2 seconds.

### What gets installed

```
/Library/MobileSubstrate/DynamicLibraries/
β”œβ”€β”€ FilzaApplySandboxExt.dylib     # The compiled tweak (~540KB, arm64)
└── FilzaApplySandboxExt.plist     # Filter: inject only into Filza
```

---

## Diagnostics

### Log file

All logs go to a single file inside Filza's sandbox:

```
/tmp/FilzaTweak.log        # Main log (4MB max, rotates to .old on overflow)
```

Fetch it from your computer:
```bash
./W0lfSword log        # Last 50 lines
./W0lfSword log 200    # Last 200 lines
```

### What a successful log looks like

```
=== TWEAK LOADED ===
[Tweak] TweakInit started
[Hooks] All hooks installed
[Tweak] Sandbox not yet escaped
[Tweak] Exploit attempt #1...
[Tweak] kexploit succeeded
[SBX] *** SANDBOX ESCAPED (R+W) β€” 3/3 tests passed ***
[SSV] patch_sandbox_ext succeeded
[SSV] check_sandbox_var_rw result r=0 w=0
[SSV] ensureSSVActive set active=1
```

### Debug UI Bypass

To force Filza's UI to show all files as writable (even without kernel support):

```bash
# Enable (dangerous β€” UI lies about write success)
touch /var/mobile/Documents/ui_debug_bypass_on.flag

# Disable (default β€” safe, production mode)
touch /var/mobile/Documents/ui_debug_bypass_off.flag
```

---

## Troubleshooting

### Build Issues

| Symptom | Cause | Fix |
|---------|-------|-----|
| `theos/makefiles/common.mk: No such file` | THEOS not set | `export THEOS=~/theos` |
| `iPhoneOS.sdk not found` | Missing SDK | Download from [theos/sdks](https://github.com/theos/sdks), place in `$THEOS/sdks/` |
| `dpkg-deb: command not found` | dpkg missing | `brew install dpkg` (macOS) / `apt install dpkg` (Linux) |
| `Undefined symbols for architecture arm64` | Missing framework/library | Check Makefile `_FRAMEWORKS` / `_LIBRARIES` |
| `clang: error: no such file: 'XPF/src/xpf.c'` | XPF submodule not initialized | `git submodule update --init` |
| Warning spam during build | Normal β€” the Makefile suppresses most warnings | Intended: `-Wno-unused-function` etc. in CFLAGS |

### Runtime Issues

| Symptom | Cause | Fix |
|---------|-------|-----|
| Filza crashes on launch | Exploit panicked kernel on previous run | Wait for reboot, try again (retry loop handles this) |
| "Sandbox not yet escaped" repeats 5 times | Wrong offsets for this iOS build | Run `./W0lfSword offsets` to check coverage; add new offsets block |
| Files in /System show as writable but writes fail | SSV activation failed | Check log for `ensureSSVActive set active=1` β€” if missing, kernel patch failed |
| `check_sandbox_var_rw FAILED` | Extension patching didn't take effect | Retry loop handles this; check if `borrow_sandbox_ext` was tried as fallback |
| `g_ui_debug_bypass` simulated writes | UI debug is ON | Run `touch /var/mobile/Documents/ui_debug_bypass_off.flag` and restart Filza |
| Tweak does nothing | Disabled by flag file | Run `./W0lfSword toggle off` or `ssh rm /var/mobile/Documents/.filza_tweak_disable` |
| `thread kstackptr outside valid range` | Wrong offsets for this SoC/iOS combo | Add per-SoC offset overrides in offsets.m for your device |
| Filza 4.0.2 crashes | Known incompatibility | Use Filza 4.0.0 |

### Device Issues

| Symptom | Cause | Fix |
|---------|-------|-----|
| `ssh: connect to host ... port 22: Connection refused` | OpenSSH not installed on device | Install OpenSSH via Sileo/Cydia |
| `Permission denied (publickey)` | SSH key mismatch | `ssh -o StrictHostKeyChecking=no root@` |
| Device not discoverable | Different network | Check device Wi-Fi IP in Settings β†’ Wi-Fi β†’ (i) icon |
| `dpkg: error processing package` | Already installed or version conflict | `ssh root@ "dpkg --force-depends -i /tmp/...deb"` |

---

## Documentation Files

| File | Purpose |
|------|---------|
| `CONTEXT.md` | **Start here when resuming a session** β€” full project architecture, decisions, constants, reference repos |
| `ROADMAP.md` | 98-item checklist: bugs, features, exploits, bug bounty, testing, documentation |
| `BUG_BOUNTY.md` | 14 security findings with Apple bounty ranges ($25K-$250K), attack chains, crash scenarios |
| `AUDIT_REPORT.md` | 20 findings ranked CRITICAL→LOW, 13 fixes applied, GitHub PR guide |
| `DEBUG_TRACKING.md` | Every log statement mapped by file:line, 3-layer strip guide, audit trail map |
| `BUILD.md` | Theos explanation, prerequisites, build commands, .deb structure, troubleshooting |

---

## Known Issues

- **Exploit may take 2-3 attempts** β€” the retry loop handles this automatically (up to 5 attempts)
- **Padlock bypass may not work** on all Filza versions β€” hooks target specific class names that could differ
- **Filza v4.0.2 reportedly causes crashes** β€” use v4.0.0
- **SSV writes are best-effort** β€” the kernel patch may not activate on first file operation
- **iPhone 17 / M5 will not work** due to Apple's MTE (Memory Tagging Extension)

---

## Contributing

Found a bug? Open an issue. Want to add support for a new iOS version or device?

1. Get the kernelcache from the target device
2. Run XPF on it to resolve new offsets
3. Add a new `SYSTEM_VERSION_GREATER_THAN_OR_EQUAL_TO` block in `kexploit/offsets.m`
4. Test on real hardware
5. Submit a PR

See `ROADMAP.md` for the full task list. See `AUDIT_REPORT.md` for remaining medium/low items.

Before committing, run:
```bash
./W0lfSword audit    # Check braces, printf count, offset coverage
./W0lfSword status   # Verify nothing in dirty state
```

---

## License

This project incorporates code from multiple open-source projects:
- DarkSword kernel exploit (wh1te4ever)
- XPF offset engine / sandbox structures (opa334)
- ChOma Mach-O parser

All original code remains under the licenses of their respective authors.  
The integration layer and tooling are released as-is for research and testing.

**WARNING:** This is a pre-release testing build. Modifying system files can render your device unbootable β€” use at your own risk.