.TH "idevicerestore" 1 .SH NAME idevicerestore \- Restore IPSW firmware at PATH to an iOS device .SH SYNOPSIS .B idevicerestore [OPTIONS] PATH .SH DESCRIPTION Restore firmware files to iOS devices while either erasing the device or updating to preserve content and settings. \f[B]PATH\f[] can be a compressed .ipsw file or a directory containing all files extracted from an IPSW. .SH OPTIONS .TP .B \-i, \-\-ecid ECID Target specific device by its ECID, e.g. 0xaabb123456 (hex) or 1234567890 (decimal). .TP .B \-u, \-\-udid UDID Target specific device by its device UDID. \f[B]NOTE\f[]: only works with devices in normal mode. .TP .B \-l, \-\-latest Use latest available firmware (with download on demand). Before performing any action it will interactively ask to select one of the currently signed firmware versions, unless \f[B]\-y\f[] has been given too. The PATH argument is ignored when using this option. \f[B]DO NOT USE\f[] if you need to preserve the baseband/unlock! \f[B]USE WITH CARE\f[] if you want to keep a jailbreakable firmware! .TP .B \-e, \-\-erase Perform full restore instead of update, erasing all data \f[B]DO NOT USE\f[] if you want to preserve user data on the device! .TP .B \-y, \-\-no\-input Non-interactive mode, do not ask for any input. \f[B]WARNING\f[]: This will disable certain checks/prompts that are supposed to prevent DATA LOSS. \f[B]Use with caution\f[]. .TP .B \-n, \-\-no\-action Do not perform any restore action. If combined with \f[B]\-l\f[] option the on-demand ipsw download is performed before exiting. .TP .B \-\-ipsw\-info Print information about the IPSW at PATH and exit. .TP .B \-h, \-\-help Prints usage information. .TP .B \-C, \-\-cache\-path DIR Use specified directory for caching extracted or other reused files. .TP .B \-\-logfile PATH Write logging output to file at PATH. If PATH equals \f[B]NULL\f[] or \f[B]NONE\f[], no log file will be written. This disables automatic log file creation. .TP .B \-d, \-\-debug Enable communication debugging. .TP .B \-v, \-\-version Prints version information. .SH ADVANCED/EXPERIMENTAL OPTIONS .TP .B \-c, \-\-custom Restore with a custom firmware (requires bootrom exploit) .TP .B \-s, \-\-server URL Override the default signing server request URL. If the URL doesn't contain a path component, the default path \f[B]/TSS/controller?action=2\f[] will be added. .TP .B \-x, \-\-exclude Exclude nor/baseband upgrade. \f[B]NOTE\f[]: This option only works with legacy devices and/or custom firmware. .TP .B \-t, \-\-shsh Fetch TSS record and save to .shsh file, then exit. .TP .B \-z, \-\-no\-restore Do not restore and end after booting to the ramdisk. .TP .B \-k, \-\-keep\-pers Write personalized components to files for debugging. .TP .B \-p, \-\-pwn Put device in pwned DFU mode and exit (limera1n devices only). .TP .B \-P, --plain-progress Print progress as plain step and progress .TP .B \-R, \-\-restore\-mode Allow restoring from Restore mode .TP .B \-T, \-\-ticket PATH Use file at PATH to send as AP ticket .TP .B \-\-variant VARIANT Use given VARIANT to match the build identity to use, e.g. 'Customer Erase Install (IPSW)' .TP .B \-\-ignore\-errors Try to continue the restore process after certain errors (like a failed baseband update). \f[B]WARNING\f[]: This might render the device unable to boot or only partially functioning. \f[B]Use with caution\f[]. .TP .B \-\-exclusive\-usb \f[B](macOS only)\f[] Keep the \f[B]deviceinterfaced\f[] system daemon from claiming the USB device during Port DFU-to-DFU re-enumeration, which can otherwise cause idevicerestore to time out waiting for the device to reconnect. idevicerestore itself does not need to run as root for this option. The few \f[B]launchctl\f[](1) subcommands that manage the system-domain \f[B]com.apple.deviceinterfaced\f[] daemon (\f[B]bootout\f[], \f[B]bootstrap\f[], \f[B]kickstart\f[], \f[B]kill\f[]) are elevated individually via \f[B]sudo\f[](8), which may prompt for your password (or Touch ID, if configured) on the controlling terminal. See the \f[B]NOTES\f[] section below for unattended use. \f[B]EXPERIMENTAL\f[]: only use if you are hitting DFU reconnection timeouts. .SH NOTES .SS Passwordless \-\-exclusive\-usb By default, using \f[B]\-\-exclusive\-usb\f[] will prompt for your password via \f[B]sudo\f[](8) whenever idevicerestore needs to boot out, kickstart, or forcibly terminate the \f[B]com.apple.deviceinterfaced\f[] daemon. For unattended/scripted use, you can allow just those specific commands to run without a password by adding a narrowly-scoped rule to \f[B]sudoers\f[](5), e.g. via \f[B]visudo \-f /etc/sudoers.d/idevicerestore\f[]: .nf .RS Cmnd_Alias DEVICEINTERFACED_CTL = \\ /bin/launchctl bootout system/com.apple.deviceinterfaced, \\ /bin/launchctl bootstrap system /Library/Apple/System/Library/PrivateFrameworks/DeviceInterface.framework/Support/com.apple.deviceinterfaced.plist, \\ /bin/launchctl kickstart system/com.apple.deviceinterfaced, \\ /bin/launchctl kill SIGKILL system/com.apple.deviceinterfaced %admin ALL=(root) NOPASSWD: DEVICEINTERFACED_CTL .RE .fi Replace \f[B]%admin\f[] with the specific user or group that should be allowed to run these commands without a password. This grants no broader privileges: only these exact \f[B]launchctl\f[] invocations, against this one system daemon, may be run as root without authentication. .SH AUTHORS Martin Szulecki Nikias Bassen Joshua Hill .SH ON THE WEB https://libimobiledevice.org https://github.com/libimobiledevice/idevicerestore