Lakr233/vphone-cli
52.5
Adequate · 27 September 2026
63.5k
lines of production code
Swift
with Objective-C
4
measurements over time
What this system is
This system is a macOS-native virtualization platform that runs virtualized iPhones (iOS/iPadOS) on Apple Silicon Macs. It provides a comprehensive host application for managing VM lifecycles, including device configuration, app installation, and hardware feature forwarding such as location, camera, and Touch ID. The architecture includes a background daemon that exposes a WebSocket API for deep guest control, enabling features like app management, file browsing, keychain inspection, and real-time log streaming.
Features
Introduce VPhone Launchpad for managing virtual iPhone machines
VPhone Launchpad is a new macOS application that provides a graphical interface for managing virtual iPhone (vphone) machines. It guides users through host setup, core bundle installation, and machine lifecycle management (creation, cloning, exporting, and console access). The app includes a privileged helper for system-level operations, integrates a Ghostty terminal for viewing logs and consoles, and supports multiple languages including English, Chinese, Japanese, Korean, and Vietnamese.
VPhoneLaunchpad · high confidence
Introduce structured guest app lifecycle and host automation server
The VPhone application now uses a dedicated entry point (VPhoneGuestApp) to manage the guest virtual machine lifecycle, separating the command-line parsing logic from the AppKit application wiring. This change also introduces a host automation server that exposes a Unix domain socket for local process control, allowing external tools to send commands such as screenshots, input simulation (tap, swipe, key press), and clipboard operations, with responses including compact base64-encoded screen images.
VPhoneExecutable/VPhoneVirtualization/UI · high confidence
Introduce vphone virtual machine with drag-and-drop app installation
The VPhone interface now includes a new virtual machine implementation that boots a virtual iPhone in DFU mode, preserving the VM's boot state (including machine identifier and NVRAM) when cloning or launching to maintain consistent device identity. Users can now install iOS app packages by dragging and dropping .ipa files directly onto the VM window, which triggers an installation via the guest agent. The VM configuration supports custom hardware models (PV=3), serial output for debugging, and configurable network modes, with specific error messages guiding users on requirements like macOS 15.0 and necessary entitlements if the hardware model is unsupported.
VPhoneExecutable/VPhoneVirtualization/UI/VirtualMachine · high confidence
Introduces VPhoneArchiveKit for VM bundle export and import
VPhoneKit now includes a new VPhoneArchiveKit module that handles VM bundle export and import operations. This replaces the previous shell-out to system tar with a native Swift implementation using libarchive, providing better control over archive formats (gnutar, pax, ustar), compression (zstd, xz, gzip), and file metadata preservation. The new system supports exporting VM bundles with configurable compression levels and importing them with proper ownership and permission handling, including support for hardlinks, extended attributes, and ACLs. It also includes an IPSW cache for managing iOS firmware downloads and a tree fingerprinting system for comparing directory structures.
VPhoneKit · high confidence
Major v2.0 release: native Swift architecture, Launchpad UI, and simplified setup
This release introduces v2.0, replacing the previous Python-based toolchain with a fully native Swift implementation. The project now ships a self-contained \VPhone.bundle\ and a new \vphone-launchpad\ workstation app that guides users through host setup, bundle installation, and VM creation. The setup workflow is significantly simplified: users no longer need to disable SIP or use \amfi\_get\_out\_of\_my\_way=1\; instead, the recommended configuration keeps SIP enabled with debugging restrictions relaxed, and the Launchpad helper manages AMFI allowlisting for verified VMs. The legacy shell scripts (\boot.sh\, \build\_and\_sign.sh\) and Python dependencies have been removed. The license has also changed from WTFPL to MIT.
(repo-wide) · high confidence
Native API for app signing and process monitoring
The VPhoneDaemon now exposes a native C interface (VphonedNative) that allows guest applications to sign extracted apps for installation and retrieve detailed resource usage and identity information for running processes. This includes functions for signing app bundles, managing cached binaries, and querying process metrics such as CPU time and memory footprint, facilitating deeper integration between the guest environment and the host daemon.
VPhoneDaemon/Native/Include · high confidence
New guest control API and communication layer
This change introduces a new guest communication subsystem that enables the host to manage the virtualized guest OS. It includes a secure TCP-to-VSOCK proxy (VPhoneAPIProxy) for exposing guest HTTP/WebSocket APIs, a central control client (VPhoneGuestControl) for health checks and automatic updates, and specific extensions for app management (list, launch, terminate, uninstall), environment library synchronization, keychain operations, system settings, and accessibility tree inspection.
VPhoneExecutable/VPhoneVirtualization/UI/GuestCommunication · high confidence
New guest inspection panels for logs, controls, and crash reports
The VPhone interface now includes three new inspection panels accessible from the menu bar. The Console panel streams the guest's unified log in real-time, allowing users to filter by process, log level, and search text, with options to pause, refresh, and save logs. The Controls panel provides a unified view to monitor and adjust guest display settings (brightness, orientation, rotation lock), audio volume and categories, power mode, and hardware buttons (home, lock, wake, volume), as well as a keyboard interface for sending text and special keys. The Crash Logs panel lists, searches, and exports crash reports from the guest, enabling users to view report details and copy or save them to the Mac.
VPhoneExecutable/VPhoneVirtualization/UI/UserInterface/Panels · high confidence
New guest-side App, File, and Keychain browsers
VPhone now includes three new guest tools accessible from the VM interface: an App Browser to list, search, launch, terminate, and uninstall guest apps (with an inspector showing bundle details, entitlements, and network policy); a File Browser to navigate the guest filesystem, preview files via Quick Look, and download files to the host; and a Keychain Browser to view and search guest keychain items (passwords, certificates, keys) with class filtering. These tools provide direct visibility and management of the guest environment's applications, files, and credentials.
VPhoneExecutable/VPhoneVirtualization/UI/UserInterface/Browsers · high confidence
New host-side device forwarding capabilities for virtual camera, location, screen recording, and Touch ID
This update introduces several new host-side components in the VPhoneVirtualization UI to bridge macOS hardware features to the guest VM. A new virtual camera server streams BGRA frames via vsock, supporting test patterns and letterboxed video file playback. Host location data is now forwarded to the guest using CoreLocation, including support for preset coordinates and location replays. The system also adds a screen recorder that captures the VM display to H.264 video files, and a Touch ID monitor that intercepts macOS BiometricKit sensor events to simulate fingerprint taps for the guest.
VPhoneExecutable/VPhoneVirtualization/UI/HostDevices · high confidence
New localized UI infrastructure and VM window management
This change introduces the core UI components for the VPhone virtual machine interface. It adds a localization system (VPhoneLocalization) that loads strings from the application bundle and applies them to menus and alerts, ensuring the interface is translatable. A new alert handler (VPhoneAlert) manages presenting sheets and modals relative to the VM window or app-modal if no window is visible. The VM window controller (VPhoneVirtualMachineWindowController) now manages the VM display window, including per-VM window frame persistence, a unified toolbar with a Home button, and a key event monitor that prioritizes menu shortcuts over VM input. Additionally, a key sender (VPhoneVirtualMachineKeySender) is introduced to handle hardware key injection (Home, Power, Volume) and ASCII text typing into the guest via clipboard, with connection status checks.
VPhoneExecutable/VPhoneVirtualization/UI/UserInterface · high confidence
New macOS menu bar for guest control and inspection
The application now provides a native macOS menu bar for managing the virtual phone, replacing previous UI mechanisms. The Device menu allows sending hardware inputs (Home, Power, Volume), restarting the guest, and configuring Location, Battery, and Camera sources. The Guest menu enables file and keychain browsing, clipboard management, and reading/writing preferences. A new Bootstrap section lets users install or uninstall the Irisin jailbreak environment with progress tracking. The Diagnostics menu offers inspection panels for device info, processes, services, console logs, and crash logs, along with connectivity checks. The Capture menu supports screen recording and screenshots, while the Apps menu provides an app browser and IPA installation.
VPhoneExecutable/VPhoneVirtualization/UI/UserInterface/Menu · high confidence
New research documentation for firmware patching and jailbreak internals
Added a set of Markdown files in the Research directory that document the firmware patching pipeline and jailbreak implementation details. These include a binary patch comparison table, a firmware manifest and component origin guide, detailed iBoot patch analysis, and in-depth TXM (Trusted Execution Monitor) code signature validation and jailbreak patch analysis. The documentation covers the hybrid IPSW strategy, specific binary patches applied to boot components and the kernel, and the logic behind TXM selector 24 bypasses.
Research · high confidence
New vphoned daemon exposes comprehensive guest control API
The VPhoneDaemon now includes a new vphoned service that provides a WebSocket-based API for managing the guest environment. This daemon exposes capabilities for device control (display, audio, network), input simulation (touch, gestures), application management (install, launch, uninstall), file operations, and system inspection (processes, logs, keychain). It also handles environment updates for jailbreak libraries and publishes real-time state events to connected clients.
VPhoneDaemon/Daemon · high confidence
VPhone bundle 2.0.8 adds location sharing and updates entitlements
The VPhone virtualization bundle (version 2.0.8) now requests and supports location permissions, allowing the host's location to be shared with the virtual iPhone so that apps inside the VM see the same location. This is enabled by new \NSLocation\*UsageDescription\ strings in the bundle's \Info.plist\ and corresponding localizations in \InfoPlist.xcstrings\. The bundle's entitlements file has been updated to include \com.apple.security.personal-information.location\ and \com.apple.private.bmk.allow\, and the resource files have been reorganized into the \Resources\ directory.
VPhoneExecutable/VPhoneVirtualization/Resources · high confidence
VPhoneEscalator tool added to bypass amfid restrictions for ad-hoc signed binaries
A new Xcode project and C source file for the 'vphone-escalator' helper tool have been added to the VPhoneExecutable/VPhoneEscalator location. This tool allows ad-hoc signed binaries carrying Apple-private entitlements to run on macOS by modifying the AMFIRequirementsManager singleton in the amfid process, avoiding the need to patch amfid's code directly. The implementation targets arm64e, requires root and task\_for\_pid privileges, and is built as a standalone executable linked against CoreFoundation and Security frameworks.
VPhoneExecutable/VPhoneEscalator · high confidence
Removals
Removal of vphone CLI and private Virtualization.framework wrappers
The vphone CLI tool and its supporting Objective-C wrappers for private Virtualization.framework APIs have been removed from the Sources directory. This deletes the command-line interface used to boot a virtual iPhone (PV=3) in DFU mode, along with the underlying implementation that configured private hardware models, boot loaders, NVRAM variables, serial ports, and multi-touch input handling.
Sources · high confidence
Removal of vphone600 firmware patching and installation scripts
The Scripts directory has been cleaned up by deleting the legacy toolchain used for vphone600 custom firmware (CFW) operations. Specifically, the build\_ramdisk.py, install\_cfw.sh, patch\_cfw.py, patch\_firmware.py, prepare\_firmware.sh, and ramdisk\_send.sh files have been removed. These scripts previously handled downloading hybrid firmware, patching boot-chain components (AVPBooter, iBSS, iBEC, LLB, TXM, kernelcache), building signed SSH ramdisks, and installing CFW modifications via SSH. This change eliminates the manual firmware patching and ramdisk-based installation workflow for this device.
Scripts · high confidence
Architecture
Introduced Xcode project for VPhoneVirtualization with Swift Package dependencies
The VPhoneVirtualization location now includes a native Xcode project (project.pbxproj) that defines three build targets: the VPhone bundle, the VPhoneVirtualMachineKit static library, and the vphone-vm executable tool. This configuration integrates remote Swift Package dependencies for ArgumentParser, Dynamic, and swift-nio (NIOCore/NIOPosix), establishing the build structure for the virtualization component.
VPhoneExecutable/VPhoneVirtualization/VPhoneVirtualization.xcodeproj · high confidence
Migrated VPhoneDaemon to Xcode project structure
The VPhoneDaemon build system has been migrated to an Xcode project (project.pbxproj), replacing previous build configurations. This change introduces a new 'vphoned' target that links against IcliKit, swift-nio (NIOCore, NIOHTTP1, NIOPosix, NIOWebSocket), and IcliSystem frameworks, and includes a 'Build Guest Signer' shell script phase to compile the VPhoneSign scheme. The project also defines a 'VphonedNative' static library target and configures remote Swift package references for icli, swift-nio, and swift-collections.
VPhoneDaemon/VPhoneDaemon.xcodeproj · high confidence
Behavioural changes
Added VPhoneLaunchpad to the Xcode workspace
The VPhoneLaunchpad project has been added to the VPhone.xcworkspace, grouping it alongside the existing VPhoneCommand, VPhoneRestore, VPhoneVirtualization, VPhoneKit, VPhoneDaemon, and VPhoneEscalator projects. This change integrates the new workstation app for bundles and VMs into the unified development environment.
VPhone.xcworkspace · high confidence
Firmware patching engine migrated to Swift
The firmware patching logic in VPhoneCommand has been rewritten in Swift, replacing the previous Python-based implementation. This new engine includes ARM64 instruction encoding and disassembly utilities, binary parsing for Mach-O and IM4P formats, and specific patchers for AVPBooter and CryptexFilesystem, enabling the tool to modify and merge firmware components directly.
VPhoneExecutable/VPhoneCommand · high confidence
New build pipeline for VPhone bundle staging and validation
The VPhone build process now includes a dedicated staging script that assembles the final application bundle by compiling and copying host executables (vphone-vm, vphone-cli, vphone-escalator) into Contents/MacOS and guest payloads (vphoned, hooks, libraries) into a new Contents/Resources/guest-resources directory. This change introduces a strict validation phase that verifies code signatures, ensures correct platform separation (iOS binaries only in guest-resources), checks entitlements, and performs a round-trip archive test to guarantee bundle integrity before release.
VPhoneExecutable/VPhoneVirtualization/Build · high confidence
Virtual camera preview, photo capture, and session stability fixes
The VPhoneGuestComponents library now intercepts AVFoundation internals to make the virtual camera fully functional in apps like Camera.app. It patches AVCaptureVideoPreviewLayer to pump frames from the shared memory data plane into the preview UI, and overrides photo capture paths (including Camera.app's moment-capture sequence) to synthesize valid AVCapturePhoto objects from the virtual frame instead of crashing. Additionally, it guards the capture session against being marked as interrupted or stopped when no real hardware frames are flowing, ensuring the session remains active and stable.
VPhoneGuestComponents · high confidence
Dependencies
Adopts Swift Package Manager lock files for dependency resolution
The project now uses resolved Package.resolved files for each component (VPhone, VPhoneDaemon, VPhoneCommand, VPhoneRestore, VPhoneVirtualization, VPhoneKit, VPhoneLaunchpad) to pin specific versions of dependencies such as icli 0.6.9, libarchive.xcframework 1.0.0, swift-nio 2.83.0, and swift-crypto 3.15.1, ensuring reproducible builds. The root Package.swift manifest for the vphone-cli tool has been removed, indicating a shift away from a single top-level SPM package structure toward per-target dependency management.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 48 → 52 (+4.3)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 90 → 83 (-7.2)
- Architecture 96 → 96 (+0.5)
- Maturity 63 → 60 (-3.7)
- Readiness 26 → 51 (+25.4)
- Security 60 → 42 (-18.0)
Resolved (9)
- Coverage not measured — test suite did not build
- Dimension evaluation failed
- High: security finding (details withheld)
- LLM evaluation failed
- Medium: security finding (details withheld)
- No artifact signing
- No exposed public API
- No tests found
- Test reliability not included
New (476)
- AVPBooterPatcher.patchDGSTBypass (cognitive 21) (VPhoneExecutable/VPhoneCommand/FirmwarePatcher/AVPBooter/AVPBooterPatcher.swift)
- AVPBooterPatcher.patchDGSTBypass (cyclomatic 19) (VPhoneExecutable/VPhoneCommand/FirmwarePatcher/AVPBooter/AVPBooterPatcher.swift)
- ClassTooLong: GuestIrisinInstaller (VPhoneDaemon/Daemon/GuestIrisinInstaller.swift)
- ClassTooLong: VPhoneCustomFirmwareInstaller (VPhoneExecutable/VPhoneCommand/VPhoneCommand/Firmware/VPhoneCustomFirmwareInstaller.swift)
- CryptexFilesystemPatcher.attachImage (cognitive 19) (VPhoneExecutable/VPhoneCommand/FirmwarePatcher/CryptexFilesystem/CryptexFilesystemPatcher.swift)
- CryptexFilesystemPatcher.copyImageContents (cognitive 19) (VPhoneExecutable/VPhoneCommand/FirmwarePatcher/CryptexFilesystem/CryptexFilesystemPatcher.swift)
- CustomFirmwareCacheLoaderPatcher.findGate (cognitive 16) (VPhoneExecutable/VPhoneCommand/FirmwarePatcher/CustomFirmware/ExecutablePatches/CacheLoader/CustomFirmwareCacheLoader.swift)
- CustomFirmwareCacheLoaderPatcher.findStringReference (cognitive 21) (VPhoneExecutable/VPhoneCommand/FirmwarePatcher/CustomFirmware/ExecutablePatches/CacheLoader/CustomFirmwareCacheLoader.swift)
- CustomFirmwareCacheLoaderPatcher.findStringReference (cyclomatic 16) (VPhoneExecutable/VPhoneCommand/FirmwarePatcher/CustomFirmware/ExecutablePatches/CacheLoader/CustomFirmwareCacheLoader.swift)
- CustomFirmwareCacheLoaderPatcher.patch (cognitive 16) (VPhoneExecutable/VPhoneCommand/FirmwarePatcher/CustomFirmware/ExecutablePatches/CacheLoader/CustomFirmwareCacheLoader.swift)
- CustomFirmwareInjectDylib.scanLoadCommands (cognitive 21) (VPhoneExecutable/VPhoneCommand/FirmwarePatcher/CustomFirmware/CustomFirmwareInjectDylib.swift)
- CustomFirmwareJetsamPatcher.findReturnGate (cognitive 23) (VPhoneExecutable/VPhoneCommand/FirmwarePatcher/CustomFirmware/ExecutablePatches/Jetsam/CustomFirmwareJetsam.swift)
- CustomFirmwareJetsamPatcher.findReturnGate (cyclomatic 18) (VPhoneExecutable/VPhoneCommand/FirmwarePatcher/CustomFirmware/ExecutablePatches/Jetsam/CustomFirmwareJetsam.swift)
- CustomFirmwareMachOCodeSignature.reattest (cognitive 25) (VPhoneExecutable/VPhoneCommand/FirmwarePatcher/CustomFirmware/CustomFirmwareMachOCodeSignature.swift)
- CustomFirmwareMachOCodeSignature.reattest (cyclomatic 16) (VPhoneExecutable/VPhoneCommand/FirmwarePatcher/CustomFirmware/CustomFirmwareMachOCodeSignature.swift)
- CustomFirmwarePostRestoreDeviceTree.patch (cognitive 20) (VPhoneExecutable/VPhoneCommand/FirmwarePatcher/CustomFirmware/CustomFirmwarePostRestoreDeviceTree.swift)
- CustomFirmwarePostRestoreDeviceTree.patch (cyclomatic 18) (VPhoneExecutable/VPhoneCommand/FirmwarePatcher/CustomFirmware/CustomFirmwarePostRestoreDeviceTree.swift)
- CustomFirmwareSeputil.references (cognitive 24) (VPhoneExecutable/VPhoneCommand/FirmwarePatcher/CustomFirmware/ExecutablePatches/Sep/CustomFirmwareSeputil.swift)
- CustomFirmwareSeputil.references (cyclomatic 21) (VPhoneExecutable/VPhoneCommand/FirmwarePatcher/CustomFirmware/ExecutablePatches/Sep/CustomFirmwareSeputil.swift)
- CustomFirmwareWatchDog.locateSites (cognitive 29) (VPhoneExecutable/VPhoneCommand/FirmwarePatcher/CustomFirmware/ExecutablePatches/WatchDog/CustomFirmwareWatchDog.swift)
- …and 456 more
Changes since last survey
- 255 commits — 235 feature/other, 20 fixes
By area
- (root) — 42 commits
- VPhoneExecutable/VPhoneVirtualization — 29 commits
- sources/FirmwarePatcher — 22 commits
- VPhoneExecutable/VPhoneCommand — 19 commits
- (repo) — 17 commits
- sources/vphone-cli — 17 commits
- VPhoneLaunchpad/VPhoneLaunchpad — 13 commits
- VPhoneDaemon/Daemon — 9 commits
- sources/VPhoneCore — 7 commits
- Research/0_binary_patch_comparison.md — 6 commits
- scripts/patchers — 5 commits
- scripts/vphoned — 5 commits
- .github/workflows — 3 commits
- VPhoneDaemon/Native — 3 commits
- VPhoneGuestComponents/LaunchHook — 3 commits
- research/0_binary_patch_comparison.md — 3 commits
- Research/KernelJailbreakPatches — 2 commits
- Research/vphoned_http_api.md — 2 commits
- Scripts/VPhoned — 2 commits
- VPhoneDaemon/VPhoneDaemon.xcodeproj — 2 commits
Notable commits
- fix: Fix RootHide loader links before chained spawns
- fix: Fix VM creation restore lifecycle and verify signed guest
- fix: Fix iOS 26.3 launchd signature space
- fix: Fix runtime lookup for interpolated VM translations
- fix: Fix the remaining Swift, Objective-C and linker warnings
- fix: Fix vphoned startup and VM launch on iOS 26
- fix: Merge branch 'codex/fix-vphone-localization'
- fix: Release 2.0.8 with escalator rename and bootstrap UI fixes
- fix: Revert "Add minimal vphone launchd hook and inert system hook"
- fix: Revert "Simplify launch hook plist loading and root selection"
- fix: Split the camera hooks into compilation units and fix their leaks
- fix: chore: remove the last dead Python, and fix what removing it broke
- fix: fix(cfw): three things the end-to-end review of the verbs found
- fix: fix(gitignore): anchor lib/ so it stops swallowing cfw-kit/lib
- fix: fix(letmein): stop killing amfid on a host that enforces code signing
- fix: fix(patchers): recognise the already-patched shape in two DSC gates
- fix: fix: a broken recipe line, a fake clone, a missing target, a redundant [-]
- fix: fix: re-encode signcert.p12 as modern PKCS12
- fix: fix: treat LSD embedded-reg gate as idempotent when already NOP'd
- fix: fix: validate imported VM manifest before moving into library
- …and 235 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
Lakr233/vphone-cli was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 27 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit cd013c246f64503cf64d71f74836e244b8ffd764 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-d00c643c3f66.