palera1n / palera1n
- вторник, 24 января 2023 г. в 00:39:51
iOS 15.0-16.3 (semi-)tethered checkm8 jailbreak
palera1n
Change Log • Discord • Twitter
It boots the device with multiple patches required. On first run, it'll boot a ramdisk which dumps your onboard blob, creates a fakefs (if using semi-tethered), installs the loader app, and patches your kernel.
A checkm8 vulnerable iOS device on iOS 15 or 16 (A8-A11)
A USB-A to Lightning cable
A Linux or macOS computer
A tutorial can be found here.
Please first check the common issues document.
If you still need help, please join our Discord. We disabled issues due to the flood of spam, and difficulty to respond in general. We are much more comfortable on Discord.
Please, please, please, provide necessary info:
iOS version and device (eg. iPhone 6s 15.3.1, iPhone X 16.0)
Computer's OS and version (eg. Ubuntu 22.04, macOS 13.0)
The command you ran
Full log from the logs folder
DO NOT harass tweak devs if tweaks don't work. Refer to here for compatiblity.
You may join here.
Thank you so much to our Patrons that make the future development possible! You may sub here, if you'd like to.
All repos work when using tweaks mode because it uses normal Procursus and not rootless.
Repos need to be updated for rootless, here are some that work currently:
Mineek's repo contains rootless Procursus packages
The official palera1n repo contains miscellaneous packages
If you want to make a rootless repo, use the official palera1n repo for reference. Every deb should use the iphoneos-arm64
architecture, and nothing should be on the rootfs. Everything should be in /var/jb.
The ramdisk that dumps blobs, copies files, and duplicates rootfs is a slimmed down version of SSHRD_Script
For modified restored_external
Also helped Mineek getting the kernel up and running and with the patches
Helping with adding multiple device support
Fixing issues relating to camera.. etc by switching to fsboot
For the patching and booting commands
Adding tweak support
For patchfinders for RELEASE kernels
Work on jbinit, together with Nick Chan
checkra1n for the base of the kpf
nyuszika7h for the script to help get into DFU
the Procursus Team for the amazing bootstrap
F121 for helping test
tihmstar for pzb/original iBoot64Patcher/original liboffsetfinder64/img4tool
Tom for a couple patches and bugfixes
xerub for img4lib and restored_external in the ramdisk
Cryptic for iBoot64Patcher fork, and liboffsetfinder64 fork
libimobiledevice for several tools used in this project (irecovery, ideviceenterrecovery etc), and nikias for keeping it up to date
Nick Chan general help with patches and iBoot payload stuff
Dora for iBoot payload and iBootpatcher2
Serena for helping with boot ramdisk.