v2.0.5
vphone-cli 2.0.5
Version 2.0.5 hardens the trust boundaries around the Launchpad helper, the root CFW install and the guest agent. It also improves location simulation and adds a few conveniences to the VM window. This note covers the changes since 2.0.4.
Get Started
Download the notarized vphone-launchpad 2.0.5, unzip it, and open the app. If Launchpad is already installed, replace it with this version, then choose Download and Install in Core Bundle to install VPhone.bundle 2.0.5. The Core Bundle asset is available if you use vphone-cli directly.
Host requirements are unchanged. See the README and host setup if you are setting up a new Mac.
Security
A repository-wide security review found issues in the root CFW install, the Launchpad helper, VM bundle handling and the guest boundary. Version 2.0.5 fixes them.
cfw installmounts guest volumes withnosuid,nodev,nobrowsein a root-only folder and reads and writes guest files through an open folder handle without following links. Cryptex paths from the BuildManifest must stay inside the restore folder.- Root no longer changes the owner or mode of the whole VM folder after an install. The permission walk skips hard links, symlinks, special files and other volumes.
- Every Launchpad helper action needs administrator authorization. Only the user who started a CFW install can cancel it, and cancelling never prompts. The helper refuses bundles with setuid, hard-linked, special or escaping symlink entries.
- VM manifests must name regular files inside the bundle, and
vm importrefuses links that leave the bundle. - File names that come from the guest, through the file browser, Quick Look, drag-out and crash logs, are validated. The files are created without overwriting existing ones and are quarantined.
- The guest HTTP client caps response bodies and enforces a per-request deadline.
- The
--api-listenproxy needs a per-launch token.vphonedrefuses requests from browser origins and non-local hosts.
Thanks to @fresh-fx59 for reporting several of these issues in #469.
Improvements
- Location simulation now reaches apps through a guest app hook. Location changes go only to authorized Core Location clients, and the guest hooks stay in sync with the bundle.
- Device > Restart Guest… restarts the guest after you confirm.
- VM window menu items now show icons.
- Launchpad can install a local build: Install Local Build… accepts a
VPhone.bundlefolder or a.zipthat contains one. Local builds are stored as<version>-localand never replace a release.
Fixes
cfw installaccepts cryptex images thatrestore --offlinehas already decrypted, instead of stopping withnotAEA. Thanks to @renegadelink for the original fix in #334.- The Delete button in Uninstall Bootstrap Without Restarting… is now localized.