summaryrefslogtreecommitdiffstats
path: root/src/idevicerestore.c
diff options
context:
space:
mode:
authorGravatar Peter A2026-08-22 17:07:04 +0200
committerGravatar Nikias Bassen2026-09-07 01:46:30 +0200
commit35dee10f82711101a7d30d03f0ec781ac23221e9 (patch)
tree48098a59895ff0fe346dcbe7ae928ad06b4c0c56 /src/idevicerestore.c
parentd9aa264b673fdd14fc0cb7f7daa1b9127ede4916 (diff)
downloadidevicerestore-35dee10f82711101a7d30d03f0ec781ac23221e9.tar.gz
idevicerestore-35dee10f82711101a7d30d03f0ec781ac23221e9.tar.bz2
macOS: Avoid deviceinterfaced races during DFU reconnect
During Port DFU-to-DFU re-enumeration, macOS deviceinterfaced daemon can acquire the USB interface first, making idevicerestore time out waiting for DFU reconnection. Add experimental flag: --exclusive-usb that keeps deviceinterfaced from claiming the USB device for the duration of the restore, by booting it out or repeatedly terminating it when bootout is denied (SIP on), then reloading and starting it again on exit. idevicerestore itself does not need to run as root for this. Only the launchctl subcommands that manage the system-domain deviceinterfaced daemon (bootout, bootstrap, kickstart, kill) are elevated individually via sudo, which may prompt for a password on the controlling terminal. Read-only queries (print) are run unprivileged. Document how to allow these specific commands via a scoped sudoers(5) NOPASSWD rule for unattended use. Co-authored-by: Nikias Bassen <nikias@gmx.li>
Diffstat (limited to 'src/idevicerestore.c')
-rw-r--r--src/idevicerestore.c39
1 files changed, 39 insertions, 0 deletions
diff --git a/src/idevicerestore.c b/src/idevicerestore.c
index 04070a1..11d7ec4 100644
--- a/src/idevicerestore.c
+++ b/src/idevicerestore.c
@@ -61,6 +61,10 @@
#include "locking.h"
+#ifdef __APPLE__
+#include "deviceinterfaced.h"
+#endif
+
#define VERSION_XML "version.xml"
#ifndef IDEVICERESTORE_NOMAIN
@@ -91,6 +95,9 @@ static struct option longopts[] = {
{ "ignore-errors", no_argument, NULL, 1 },
{ "variant", required_argument, NULL, 2 },
{ "logfile", required_argument, NULL, 3 },
+#ifdef __APPLE__
+ { "exclusive-usb", no_argument, NULL, 4 },
+#endif
{ NULL, 0, NULL, 0 }
};
@@ -101,6 +108,14 @@ static void usage(int argc, char* argv[], int err)
#else
#define PWN_FLAG_LINE ""
#endif
+#ifdef __APPLE__
+#define EXCLUSIVE_USB_ACCESS_FLAG_LINE \
+ " --exclusive-usb Keep deviceinterfaced from claiming the USB device\n" \
+ " during the restore (may prompt for your password\n" \
+ " via sudo)\n"
+#else
+#define EXCLUSIVE_USB_ACCESS_FLAG_LINE ""
+#endif
char* name = strrchr(argv[0], '/');
fprintf((err) ? stderr : stdout,
"Usage: %s [OPTIONS] PATH\n" \
@@ -141,6 +156,7 @@ static void usage(int argc, char* argv[], int err)
" -v, --version Print version information\n" \
"\n" \
"Advanced/experimental options:\n"
+ EXCLUSIVE_USB_ACCESS_FLAG_LINE \
" -c, --custom Restore with a custom firmware (requires bootrom exploit)\n" \
" -s, --server URL Override default signing server request URL\n" \
" -x, --exclude Exclude nor/baseband upgrade (legacy devices)\n" \
@@ -1777,6 +1793,9 @@ int main(int argc, char* argv[])
int ipsw_info = 0;
int result = 0;
const char* logfile = NULL;
+#ifdef __APPLE__
+ int exclusive_usb_access = 0;
+#endif
logger_set_print_func(tty_print);
@@ -1978,6 +1997,12 @@ int main(int argc, char* argv[])
logfile = optarg;
break;
+#ifdef __APPLE__
+ case 4:
+ exclusive_usb_access = 1;
+ break;
+#endif
+
default:
usage(argc, argv, 1);
return EXIT_FAILURE;
@@ -2036,12 +2061,26 @@ int main(int argc, char* argv[])
curl_global_init(CURL_GLOBAL_ALL);
+#ifdef __APPLE__
+ if (exclusive_usb_access && deviceinterfaced_control_start() < 0) {
+ idevicerestore_client_free(client);
+ curl_global_cleanup();
+ return EXIT_FAILURE;
+ }
+#endif
+
client->flags |= FLAG_IN_PROGRESS;
result = idevicerestore_start(client);
client->flags &= ~FLAG_IN_PROGRESS;
idevicerestore_client_free(client);
+#ifdef __APPLE__
+ if (exclusive_usb_access) {
+ deviceinterfaced_control_stop();
+ }
+#endif
+
curl_global_cleanup();
return (result == 0) ? EXIT_SUCCESS : EXIT_FAILURE;