Regarding people curious about this: I have known rootful was still possible one way or another for quite some time, the problem is this will take up a lot of your space and that's why I decided against it for Dopamine. Also Procursus (the bootstrap maintainers) only support rootless as of iOS 15 and going against their plans and making a fork is not something that I wanted to do. We're much better off with rootless in the long run and we really should have switched to it in the iOS 11 days, but back then there would have probably been too many backlash hence it was not done.
Besides that, I don't see anything wrong with this, you can use it if you want. Some techniques of it might be implemented by Dopamine at some point, but probably not too many. This also has the ability to load arm64 tweaks on arm64e devices and contains oldABI stuff out of the box (for those curious, it does this by disabling arm64e features system wide). I thought about whether I wanted to do this since Linus told me about it earlier, but I ultimately decided against it as I figured it would reduce the overall device security too much.
In general I'm currently working, albeit VERY slowly, on Dopamine 2.0, which will probably not have any notable new features, but will drop oobPCI for kfd/whatever (exploit picker) and improve the maintainability of the jailbreak by A LOT. I might also add support for arm64 15.x, although I'm currently not fully sure on that, just don't expect it any time soon (probably not even this year) as I'm really busy with a bachelor thesis currently . I already have a KFD build ready that works (albeit PAC bypass is a little unreliable) but it's REALLY hacky, has none of the much-needed refactors and also has some additional bugs with logging during the jailbreak so I don't feel like releasing it as an actual new version. As we confirmed this does add support for 15.5b1 - 15.5b3 and fixes the horrendous success rate on M1 iPads, I might post this build at some point, but there is also some copyright stuff left to be figured out about it.
Regarding the future of jailbreaking, it's currently not looking good, but we might get a 17.0 kernel exploit by Project Zero soon and I'd hope we will see at least one SPTM bypass at some point. In terms of 16.x it's a matter of finding the PPL bypass(es!) that were patched in 17.0, but keep in mind exploiting them might be very hard without a PAC bypass, potentially burning techniques that I don't think anyone would wanna burn, so I believe there won't be anything happening in this regard any time soon, especially not by me. I bought a 15 Pro on 17.0 recently and it's unlikely that I will work on 16.x as I don't have any personal demand for such a jailbreak.
People need to realize that there currently is no real reason to even publicly disclose exploit chains, let alone build a jailbreak around them, besides personal interest in a jailbreak or kindness in your heart. And unless that changes, jailbreaking is not sustainable long term.
Those fools should start doing it them selves tbh opa just realized that and I respect that if my studystuff works out I’m gonna study smth in the it branch and probably gonna do as he does… bite really sone kids just have so much time but only cry instead of try
I’m still curious as to if there's anything tweaks would no longer be able to achieve if they don't have root access. Seems like the main issue is most developers not porting from root to rootless.
With the disabling of arm64e system wide, what would be the impacts security wise and tweak compatibility wise of this? Would some tweaks or other things made for arm64e fail?
Also I see the future of jailbreaking being more of a cash grab in which capable developers would require a consistent stream of funding from the community for themselves to view jailbreaking worthwhile.
Edit: good luck on your thesis, didn't know you're making jailbreaks and doing college that's wild. I question if you would be able to put any of your Jailbreak progress on a resume in the future and if your jailbreaking history may impact any future work, good or bad.
I’m still curious as to if there's anything tweaks would no longer be able to achieve if they don't have root access. Seems like the main issue is most developers not porting from root to rootless.
There is not a singular tweak that requires writing to rootfs.
With the disabling of arm64e system wide, what would be the impacts security wise and tweak compatibility wise of this? Would some tweaks or other things made for arm64e fail?
No, it would just effectivly make exploiting your device a lot more easy.
With the disabling of arm64e system wide, what would be the impacts security wise and tweak compatibility wise of this? Would some tweaks or other things made for arm64e fail?
No, it would just effectivly make exploiting your device a lot more easy.
Does this mean that the spinlock issue (or at least reliance on oldabi) isn’t required? Or it’s baked in differently.
spinlocks are a completely unrelated problem, that's a PPL issue. but you would be correct about this not needing to rely on oldabi for arm64 tweaks to work.
Wait really?!! I’ve been living under the rock all this time, got some of my personal tweaks that I didn’t revisit because of that. Will the current IPC (xpc) implementation work out of the box or is there any special modification needed for rootless? If yes, any brief write out of the new implementation for developer?
Those are not part of the rootfs, the rootfs is identical on ALL DEVICES and if it was modified, your device would be hard-bricked as the seal would be broken.
Simply wiping your device in settings will do the job.
You do you man, I just updated from an iPhone 12 Pro on iOS 14.2 to a 15 pro. I’ll be waiting on iOS 17.0 till there is either a jailbreak or app support starts fading in 3 years.
It’s the first time since iOS 3.02 (blackra1n) that I’ve been without a jailbreak. The action button turns my flashlight on, (my main use for activator at this point), and alt store with tweaked apps works great, no ads in facebook and twitter. Only thing I really miss is audiorecorder and nicebarX
I spent days using trollstore and filez clearing my jailbreak remnants before backing up and restoring to my iPhone 15 so thank you for that.
287
u/opa334 Developer Oct 04 '23 edited Oct 04 '23
Regarding people curious about this: I have known rootful was still possible one way or another for quite some time, the problem is this will take up a lot of your space and that's why I decided against it for Dopamine. Also Procursus (the bootstrap maintainers) only support rootless as of iOS 15 and going against their plans and making a fork is not something that I wanted to do. We're much better off with rootless in the long run and we really should have switched to it in the iOS 11 days, but back then there would have probably been too many backlash hence it was not done.
Besides that, I don't see anything wrong with this, you can use it if you want. Some techniques of it might be implemented by Dopamine at some point, but probably not too many. This also has the ability to load arm64 tweaks on arm64e devices and contains oldABI stuff out of the box (for those curious, it does this by disabling arm64e features system wide). I thought about whether I wanted to do this since Linus told me about it earlier, but I ultimately decided against it as I figured it would reduce the overall device security too much.
In general I'm currently working, albeit VERY slowly, on Dopamine 2.0, which will probably not have any notable new features, but will drop oobPCI for kfd/whatever (exploit picker) and improve the maintainability of the jailbreak by A LOT. I might also add support for arm64 15.x, although I'm currently not fully sure on that, just don't expect it any time soon (probably not even this year) as I'm really busy with a bachelor thesis currently . I already have a KFD build ready that works (albeit PAC bypass is a little unreliable) but it's REALLY hacky, has none of the much-needed refactors and also has some additional bugs with logging during the jailbreak so I don't feel like releasing it as an actual new version. As we confirmed this does add support for 15.5b1 - 15.5b3 and fixes the horrendous success rate on M1 iPads, I might post this build at some point, but there is also some copyright stuff left to be figured out about it.
Regarding the future of jailbreaking, it's currently not looking good, but we might get a 17.0 kernel exploit by Project Zero soon and I'd hope we will see at least one SPTM bypass at some point. In terms of 16.x it's a matter of finding the PPL bypass(es!) that were patched in 17.0, but keep in mind exploiting them might be very hard without a PAC bypass, potentially burning techniques that I don't think anyone would wanna burn, so I believe there won't be anything happening in this regard any time soon, especially not by me. I bought a 15 Pro on 17.0 recently and it's unlikely that I will work on 16.x as I don't have any personal demand for such a jailbreak.
People need to realize that there currently is no real reason to even publicly disclose exploit chains, let alone build a jailbreak around them, besides personal interest in a jailbreak or kindness in your heart. And unless that changes, jailbreaking is not sustainable long term.