Skip to content

v2.0.5

Choose a tag to compare

@Lakr233 Lakr233 released this 25 Sep 11:27
· 316 commits to main since this release

vphone-cli 2.0.5

Version 2.0.5 hardens the trust boundaries around the Launchpad helper, the root CFW install and the guest agent. It also improves location simulation and adds a few conveniences to the VM window. This note covers the changes since 2.0.4.

Get Started

Download the notarized vphone-launchpad 2.0.5, unzip it, and open the app. If Launchpad is already installed, replace it with this version, then choose Download and Install in Core Bundle to install VPhone.bundle 2.0.5. The Core Bundle asset is available if you use vphone-cli directly.

Host requirements are unchanged. See the README and host setup if you are setting up a new Mac.

Security

A repository-wide security review found issues in the root CFW install, the Launchpad helper, VM bundle handling and the guest boundary. Version 2.0.5 fixes them.

  • cfw install mounts guest volumes with nosuid,nodev,nobrowse in a root-only folder and reads and writes guest files through an open folder handle without following links. Cryptex paths from the BuildManifest must stay inside the restore folder.
  • Root no longer changes the owner or mode of the whole VM folder after an install. The permission walk skips hard links, symlinks, special files and other volumes.
  • Every Launchpad helper action needs administrator authorization. Only the user who started a CFW install can cancel it, and cancelling never prompts. The helper refuses bundles with setuid, hard-linked, special or escaping symlink entries.
  • VM manifests must name regular files inside the bundle, and vm import refuses links that leave the bundle.
  • File names that come from the guest, through the file browser, Quick Look, drag-out and crash logs, are validated. The files are created without overwriting existing ones and are quarantined.
  • The guest HTTP client caps response bodies and enforces a per-request deadline.
  • The --api-listen proxy needs a per-launch token. vphoned refuses requests from browser origins and non-local hosts.

Thanks to @fresh-fx59 for reporting several of these issues in #469.

Improvements

  • Location simulation now reaches apps through a guest app hook. Location changes go only to authorized Core Location clients, and the guest hooks stay in sync with the bundle.
  • Device > Restart Guest… restarts the guest after you confirm.
  • VM window menu items now show icons.
  • Launchpad can install a local build: Install Local Build… accepts a VPhone.bundle folder or a .zip that contains one. Local builds are stored as <version>-local and never replace a release.

Fixes

  • cfw install accepts cryptex images that restore --offline has already decrypted, instead of stopping with notAEA. Thanks to @renegadelink for the original fix in #334.
  • The Delete button in Uninstall Bootstrap Without Restarting… is now localized.