<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Yalu &#8211; Gary&#039;s &#8230;Lasamia</title>
	<atom:link href="https://garynil.tw/tag/yalu/feed/" rel="self" type="application/rss+xml" />
	<link>https://garynil.tw</link>
	<description>🍎 📱 🖥 🔨 😄</description>
	<lastBuildDate>Sat, 07 Jul 2018 13:50:30 +0000</lastBuildDate>
	<language>zh-TW</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.3</generator>

<image>
	<url>https://i0.wp.com/garynil.tw/wp-content/uploads/2017/01/cropped-Gary_v3.0.jpg?fit=32%2C32&#038;ssl=1</url>
	<title>Yalu &#8211; Gary&#039;s &#8230;Lasamia</title>
	<link>https://garynil.tw</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">147732124</site>	<item>
		<title>Yalu102 &#8211; App crash at launched after Jailbreak</title>
		<link>https://garynil.tw/2017/01/301/yalu102-app-crash-at-launched-after-jailbreak/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=yalu102-app-crash-at-launched-after-jailbreak</link>
					<comments>https://garynil.tw/2017/01/301/yalu102-app-crash-at-launched-after-jailbreak/#respond</comments>
		
		<dc:creator><![CDATA[Gary]]></dc:creator>
		<pubDate>Fri, 27 Jan 2017 16:52:28 +0000</pubDate>
				<category><![CDATA[Dev]]></category>
		<category><![CDATA[iOS]]></category>
		<category><![CDATA[iOS 10]]></category>
		<category><![CDATA[Jailbreak]]></category>
		<category><![CDATA[Resign]]></category>
		<category><![CDATA[Yalu]]></category>
		<guid isPermaLink="false">https://garynil.tw/?p=301</guid>

					<description><![CDATA[<p>After I use Yalu beta 1 on iOS 10.2 for jailbreaking my iPhone 6s &#38; 6s plus, as I mentioned in my previous paragraph：Yalu102 &#8211; iOS 10.2 Jailbreak, it works more stable then previous version. I tried to install some tweaks such as iFile、KeyBoard Accio and SwipeSelection to enhance the functionality of my phone. You can try to find out which tweak supported iOS 10.2 here and here I install...</p>
<p>這篇文章 <a rel="nofollow" href="https://garynil.tw/2017/01/301/yalu102-app-crash-at-launched-after-jailbreak/">Yalu102 &#8211; App crash at launched after Jailbreak</a> 最早出現於 <a rel="nofollow" href="https://garynil.tw">Gary&#039;s ...Lasamia</a>。</p>
]]></description>
										<content:encoded><![CDATA[<p>After I use <a href="https://yalu.qwertyoruiop.com/" target="_blank">Yalu beta 1</a> on iOS 10.2 for jailbreaking my iPhone 6s &amp; 6s plus, as I mentioned in my previous paragraph：<a href="https://garynil.tw/2017/01/295" target="_blank">Yalu102 &#8211; iOS 10.2 Jailbreak</a>, it works more stable then previous version.</p>
<p>I tried to install some tweaks such as iFile、KeyBoard Accio and SwipeSelection to enhance the functionality of my phone.<br />
You can try to find out which tweak supported iOS 10.2 <a href="http://www.ios10tweaks.com/p/ios-102-compatible-tweaks.html" target="_blank">here</a> and <a href="https://docs.google.com/spreadsheets/d/14e9GB-PNhDJuKI799InVFWrUQc-qn-Wd3zRJHKGkKr0/pubhtml#" target="_blank">here</a></p>
<p>I installed <strong>Cydia Substrate</strong> for supporting tweaks and <strong>iFile</strong> for debugging. However, after I respring in Cydia, at the next time I start using any other apps, the apps will crash at launch..</p>
<p>Including Yalu it self&#8230;.<br />
[fve]https://youtu.be/AaaNOYl273U[/fve]</p>
<p><span id="more-301"></span></p>
<p>Although system apps can launch normally eg.Preference. But user&#8217;s apps can&#8217;t, such as apps downloaded from AppStore.</p>
<p>And it works normally after rebooting, your phone wasn&#8217;t Jailbreak then due to Yalu is a semi-untethered jailbreak.</p>
<p>[fve]https://youtu.be/fwfNP0ILuxg[/fve]</p>
<p>First, I try to find out what is the problem if it was made by installing iFile or Cydia Substrate.</p>
<p>During testing time, I restore my 6s with ipsw of 10.2 (since SHSH of iOS 10.2 is opening now, I can restore it at anytime) for the purpose of prepainge a clean environment to test.</p>
<p>After testing, I found that if I try to install Cydia Substrate with other tweaks and respring, it caused the problem.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><strong>But the result is incorrect.</strong></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>In previous testing, I tried to use the <a href="https://yalu.qwertyoruiop.com/yalu102_alpha.ipa" target="_blank">public version ipa</a> of Yalu which <a href="https://twitter.com/qwertyoruiopz" target="_blank">qwertyoruiop</a> released on <a href="https://yalu.qwertyoruiop.com/" target="_blank">his site</a>.</p>
<p>But at the first time I jailbreak my phone, I used the version builded by myself from the code qwertyoruiop released on <a href="https://github.com/kpwn/yalu102" target="_blank">Github</a>. Besides, I&#8217;ve tried two version of it (<a href="https://github.com/kpwn/yalu102/commit/04b574267e65c13682ecd8771cff5353732178a1" target="_blank">04b574267e65c13682ecd8771cff5353732178a1</a> &amp; <a href="https://github.com/kpwn/yalu102/commit/24723830b74aac9825d53a3cd38d53439f52ad57" target="_blank">24723830b74aac9825d53a3cd38d53439f52ad57</a>)</p>
<p>At last, I found out the problem is caused by the different version of Yalu (the recent version on Github will make apps can&#8217;t launch).</p>
<p>So here is the way to solve the problem (remove Yalu and install the previous version of Yalu102)</p>
<ul>
<li>Delete the old version of Yalu from your phone</li>
<li>Resign <a href="https://yalu.qwertyoruiop.com/yalu102_alpha.ipa" target="_blank">public version ipa</a> of Yalu (<a href="https://garynil.tw/2017/01/295" target="_blank">tutorial</a>)</li>
<li>Install it into your phone then reboot</li>
<li>Jailbreak your phone again, Cydia will works normally, if not, you can solve by <a href="https://www.reddit.com/r/jailbreak/comments/5jv0ag/tutorial_how_to_rejailbreak_your_device_after/" target="_blank">this way</a></li>
<li>Done</li>
</ul>
<p>[fve]https://youtu.be/CzL70D5FTgI[/fve]</p>
<p>這篇文章 <a rel="nofollow" href="https://garynil.tw/2017/01/301/yalu102-app-crash-at-launched-after-jailbreak/">Yalu102 &#8211; App crash at launched after Jailbreak</a> 最早出現於 <a rel="nofollow" href="https://garynil.tw">Gary&#039;s ...Lasamia</a>。</p>
]]></content:encoded>
					
					<wfw:commentRss>https://garynil.tw/2017/01/301/yalu102-app-crash-at-launched-after-jailbreak/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">301</post-id>	</item>
		<item>
		<title>[Tutorial] Import IOKit framework into Xcode project</title>
		<link>https://garynil.tw/2017/01/298/tutorial-import-iokit-framework-into-xcode-project/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=tutorial-import-iokit-framework-into-xcode-project</link>
					<comments>https://garynil.tw/2017/01/298/tutorial-import-iokit-framework-into-xcode-project/#comments</comments>
		
		<dc:creator><![CDATA[Gary]]></dc:creator>
		<pubDate>Thu, 26 Jan 2017 18:44:03 +0000</pubDate>
				<category><![CDATA[Dev]]></category>
		<category><![CDATA[iOS]]></category>
		<category><![CDATA[framework]]></category>
		<category><![CDATA[IOKit]]></category>
		<category><![CDATA[Xcode]]></category>
		<category><![CDATA[Yalu]]></category>
		<guid isPermaLink="false">https://garynil.tw/?p=298</guid>

					<description><![CDATA[<p>While you&#8217;re developing iOS project on Xcode, you may need IOKit framework for some reason, such as get UDID of iDevice &#8230;etc, or using on Yalu&#8217;s project&#8230; The I/O Kit framework implements non-kernel access to I/O Kit objects (drivers and nubs) through the device-interface mechanism. So, in this article, I tried to write down how I import IOKit framework into a Xcode project....</p>
<p>這篇文章 <a rel="nofollow" href="https://garynil.tw/2017/01/298/tutorial-import-iokit-framework-into-xcode-project/">[Tutorial] Import IOKit framework into Xcode project</a> 最早出現於 <a rel="nofollow" href="https://garynil.tw">Gary&#039;s ...Lasamia</a>。</p>
]]></description>
										<content:encoded><![CDATA[<p>While you&#8217;re developing iOS project on Xcode, you may need IOKit framework for some reason, such as <a href="http://www.cnblogs.com/liyy2015/p/6090204.html" target="_blank">get UDID of iDevice</a> &#8230;etc, or using on <a href="https://garynil.tw/2017/01/295" target="_blank">Yalu&#8217;s project</a>&#8230;</p>
<p><citation>The I/O Kit framework implements non-kernel access to I/O Kit objects (drivers and nubs) through the device-interface mechanism.</citation></p>
<p>So, in this article, I tried to write down how I import IOKit framework into a Xcode project.</p>
<p>Things you need are：</p>
<ul>
<li>Xcode 8 (This sample was builded on Xcode version 8 in macOS 10.12)</li>
<li>iOS SDK (It should be installed with your Xcode)</li>
<li><a href="https://github.com/benjamin-42/Trident" target="_blank">Trident</a> &#8211; IOKit header files</li>
</ul>
<h3>Import Error</h3>
<p>When you try to use IOKit, for instance：<br />
<code>#import &lt;IOKit/IOKitLib.h&gt;</code></p>
<p>you may meet error like this：<br />
<a href="https://flic.kr/p/RkUc9q"><img data-recalc-dims="1" fetchpriority="high" decoding="async" src="https://i0.wp.com/farm1.staticflickr.com/746/32386678372_f82d859a17_z.jpg?resize=640%2C425&#038;ssl=1" alt="螢幕快照 2017-01-27 上午1.32.08" width="640" height="425" /></a></p>
<p><span id="more-298"></span></p>
<h3>Step 1：Import IOKit Framework</h3>
<p>Different from IOKit as a libraries on iOS 5, <a href="https://developer.apple.com/library/content/documentation/DeviceDrivers/Conceptual/IOKitFundamentals/Introduction/Introduction.html" target="_blank">Apple</a> change IOKit from library into framework on iOS 7.<br />
So first of all, we need to import the IOKit framework in Xcode.app into our project</p>
<p>if you try to type in your terminal<br />
<code>$ find /Applications/Xcode.app/ -name IOKit.framework</code><br />
you will find 5 different IOKit framework of 5 different platforms in Xcode.app<br />
<a href="https://flic.kr/p/QhPHhQ"><img data-recalc-dims="1" decoding="async" src="https://i0.wp.com/farm1.staticflickr.com/667/31695497964_c298971de2_z.jpg?resize=640%2C495&#038;ssl=1" alt="螢幕快照_2017-01-27_上午1_42_38" width="640" height="495" /></a></p>
<p>We need &#8220;<em>iPhoneOS.platform</em>&#8221; recently, the path is：</p><pre class="urvanov-syntax-highlighter-plain-tag">/Applications/Xcode.app/Contents/Developer/Platforms/iPhoneOS.platform/Developer/SDKs/iPhoneOS.sdk/System/Library/Frameworks/IOKit.framework</pre><p><a href="https://flic.kr/p/RzoiHB"><img data-recalc-dims="1" decoding="async" src="https://i0.wp.com/farm1.staticflickr.com/702/32539278065_09c7ae89df_z.jpg?resize=640%2C396&#038;ssl=1" alt="螢幕快照_2017-01-27_上午1_45_25" width="640" height="396" /></a></p>
<p>Then go to application Target → General in Xcode project tab, and find &#8220;<em>Link Frameworks and Libraries</em>&#8220;.<br />
<a href="https://flic.kr/p/QhPHbC"><img data-recalc-dims="1" loading="lazy" decoding="async" src="https://i0.wp.com/farm1.staticflickr.com/496/31695497604_2600718c01_z.jpg?resize=640%2C364&#038;ssl=1" alt="螢幕快照_2017-01-27_上午1_49_33" width="640" height="364" /></a></p>
<p>Press the add button on the bottom left and use &#8220;<em>Add Other</em>&#8221; button to find the framework in the specific path.<br />
<a href="https://flic.kr/p/QhPHvq"><img data-recalc-dims="1" loading="lazy" decoding="async" src="https://i0.wp.com/farm1.staticflickr.com/680/31695498694_73e3f57dd2_z.jpg?resize=640%2C364&#038;ssl=1" alt="螢幕快照 2017-01-27 上午1.54.51" width="640" height="364" /></a></p>
<p>Find the IOKit.framework on the path I mentioned above and add it, after you finish it, it will show up in the area of &#8220;<em>Link Frameworks and Libraries</em>&#8221;</p>
<p>Also remember check if the IOKit.framework also shows up at the area of &#8220;<em>Link Binary with Libraries</em>&#8221; at application Target → Build Phases in Xcode project tab<br />
<a href="https://flic.kr/p/RzoiDZ"><img data-recalc-dims="1" loading="lazy" decoding="async" src="https://i0.wp.com/farm1.staticflickr.com/346/32539277855_ecf3a74c2f_z.jpg?resize=640%2C364&#038;ssl=1" alt="螢幕快照_2017-01-27_上午1_55_00" width="640" height="364" /></a></p>
<h3>Step 2：Add header files of IOKit</h3>
<p>I read some article on internet said that header files of IOKit framework will be at</p><pre class="urvanov-syntax-highlighter-plain-tag">Applications/Xcode.app/Contents/Developer/Platforms/iPhoneSimulator.platform/Developer/SDKs/iPhoneSimulator.sdk/System/Library/Frameworks/IOKit.framework/Headers</pre><p>but I couldn&#8217;t find any header files in the path, so I tried another way.<br />
I use the header files in <a href="https://github.com/benjamin-42/Trident" target="_blank">Trident</a> and add it to my project.<br />
First, download it form GitHub, what we need is a folder in it <code>Trident-master/Headers/IOKit</code> called IOKit<br />
<a href="https://flic.kr/p/RkUbPh"><img data-recalc-dims="1" loading="lazy" decoding="async" src="https://i0.wp.com/farm1.staticflickr.com/363/32386677262_71be98136d_z.jpg?resize=640%2C327&#038;ssl=1" alt="螢幕快照_2017-01-27_上午2_01_45" width="640" height="327" /></a></p>
<p>Copy the IOKit folder to $(SRCROOT) &#8211; the path to the directory containing your Xcode project<br />
<a href="https://flic.kr/p/QhQ2zw"><img data-recalc-dims="1" loading="lazy" decoding="async" src="https://i0.wp.com/farm1.staticflickr.com/566/31695559484_917c7d9dd0_z.jpg?resize=640%2C327&#038;ssl=1" alt="螢幕快照_2017-01-27_上午2_02_05" width="640" height="327" /></a></p>
<p><a href="https://flic.kr/p/RzoizF"><img data-recalc-dims="1" loading="lazy" decoding="async" src="https://i0.wp.com/farm1.staticflickr.com/658/32539277605_84c0909ec7_z.jpg?resize=640%2C347&#038;ssl=1" alt="螢幕快照_2017-01-27_上午2_11_45" width="640" height="347" /></a><br />
Then link the folder to your project, drag the folder to the project&#8217;s &#8220;Groups &amp; Files&#8221; area</p>
<p><a href="https://flic.kr/p/RzoiKv"><img data-recalc-dims="1" loading="lazy" decoding="async" src="https://i0.wp.com/farm1.staticflickr.com/770/32539278175_44154a11d6_z.jpg?resize=640%2C364&#038;ssl=1" alt="螢幕快照 2017-01-27 上午2.13.46" width="640" height="364" /></a></p>
<h3>Step 3：Make Xcode find header files you added</h3>
<p>Go to application Target → Build Setting in Xcode project tab, and search &#8220;<code2>Header Search Paths</code2>&#8221; by search bar on the top right of navigator.<br />
<a href="https://flic.kr/p/RkWqf1"><img data-recalc-dims="1" loading="lazy" decoding="async" src="https://i0.wp.com/farm1.staticflickr.com/278/32387112652_b665723ba9_z.jpg?resize=640%2C364&#038;ssl=1" alt="螢幕快照_2017-01-27_上午2_31_26" width="640" height="364" /></a></p>
<p>and add <code>$(SRCROOT)</code> into the item, remember change the option to &#8220;recursive&#8221;<br />
<a href="https://flic.kr/p/RozLaz"><img data-recalc-dims="1" loading="lazy" decoding="async" src="https://i0.wp.com/farm1.staticflickr.com/473/32417031811_b96b2c0c71_z.jpg?resize=640%2C429&#038;ssl=1" alt="螢幕快照 2017-01-27 上午2.50.58" width="640" height="429" /></a></p>
<p>Then it done.<br />
Remember to clean your project (CMD+SHIFT+K) and build it again</p>
<p>這篇文章 <a rel="nofollow" href="https://garynil.tw/2017/01/298/tutorial-import-iokit-framework-into-xcode-project/">[Tutorial] Import IOKit framework into Xcode project</a> 最早出現於 <a rel="nofollow" href="https://garynil.tw">Gary&#039;s ...Lasamia</a>。</p>
]]></content:encoded>
					
					<wfw:commentRss>https://garynil.tw/2017/01/298/tutorial-import-iokit-framework-into-xcode-project/feed/</wfw:commentRss>
			<slash:comments>6</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">298</post-id>	</item>
		<item>
		<title>Yalu102 &#8211; iOS 10.2 Jailbreak</title>
		<link>https://garynil.tw/2017/01/295/yalu-ios-10-jailbreak/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=yalu-ios-10-jailbreak</link>
					<comments>https://garynil.tw/2017/01/295/yalu-ios-10-jailbreak/#comments</comments>
		
		<dc:creator><![CDATA[Gary]]></dc:creator>
		<pubDate>Thu, 26 Jan 2017 14:49:18 +0000</pubDate>
				<category><![CDATA[Dev]]></category>
		<category><![CDATA[iOS]]></category>
		<category><![CDATA[Cydia]]></category>
		<category><![CDATA[iOS 10]]></category>
		<category><![CDATA[Jailbreak]]></category>
		<category><![CDATA[JB]]></category>
		<category><![CDATA[Lucas]]></category>
		<category><![CDATA[qwertyoruiopz]]></category>
		<category><![CDATA[Resign]]></category>
		<category><![CDATA[Yalu]]></category>
		<guid isPermaLink="false">https://garynil.tw/?p=295</guid>

					<description><![CDATA[<p>繼上次寫了 iOS 10.1.x 越獄 &#8211; Yalu beta 3 也快過了一個月，悲觀的 Lucas 終於釋出了新的 beta 1 版本。 這裡補充一下，請大家尊重一下開發者大大們，不要去騷擾拍打、催促他完成 Jailbreak。他是沒有義務要完成這些的，這些騷擾讓他的氫碘鈉化碳碎了..，也聲稱 10.2 版本釋出之後將不會再投入研究 在新版本中， Lucas 加入了對 MobileSubstrate 的相容性 (來源) 有比較深入研究，或者再追蹤 reddit 的人應該都知道在 10.1.x 時，Lucas 釋出的版本是不支援 MobileSubstrate 的 因為目前大部分的 tweak 都依賴 MobileSubstrate，當時大部分的 tweaks 是無法使用的。 &#160; 當時也有人推出 Substrate Fix (iOS 10) Source：http:...</p>
<p>這篇文章 <a rel="nofollow" href="https://garynil.tw/2017/01/295/yalu-ios-10-jailbreak/">Yalu102 &#8211; iOS 10.2 Jailbreak</a> 最早出現於 <a rel="nofollow" href="https://garynil.tw">Gary&#039;s ...Lasamia</a>。</p>
]]></description>
										<content:encoded><![CDATA[<p>繼上次寫了 <a href="https://garynil.tw/2016/12/234" target="_blank">iOS 10.1.x 越獄 &#8211; Yalu beta 3</a> 也快過了一個月，悲觀的 <a href="https://twitter.com/qwertyoruiopz" target="_blank">Lucas</a> 終於釋出了新的 <a href="https://yalu.qwertyoruiop.com/yalu102_alpha.ipa" target="_blank">beta 1</a> 版本。</p>
<p>這裡補充一下，請大家尊重一下開發者大大們，不要去騷擾<del datetime="2017-01-26T13:44:53+00:00">拍打</del>、催促他完成 Jailbreak。他是沒有義務要完成這些的，這些騷擾<del datetime="2017-01-26T15:14:31+00:00">讓他的氫碘鈉化碳碎了..</del>，也<a href="https://twitter.com/qwertyoruiopz/status/823293730857820160" target="_blank">聲稱</a> 10.2 版本釋出之後將不會再投入研究</p>
<p>在新版本中， Lucas 加入了對 MobileSubstrate 的相容性 <a href="https://twitter.com/qwertyoruiopz/status/824508945695997952" target="_blank">(來源)<br />
</a>有比較深入研究，或者再追蹤 reddit 的人應該都知道在 10.1.x 時，Lucas 釋出的版本是不支援 MobileSubstrate 的<br />
因為目前大部分的 tweak 都依賴 MobileSubstrate，當時大部分的 tweaks 是無法使用的。<br />
<span id="more-295"></span></p>
<p>&nbsp;</p>
<p>當時也有人推出 Substrate Fix (iOS 10) Source：<a href="cydia://url/https://cydia.saurik.com/api/share#?source=http://83.218.67.215/~ijapija00/cydia" target="_blank">http://83.218.67.215/~ijapija00/cydia</a><br />
但在當時我自己測試之下，是蠻不穩定的.. 不過目前 iOS 10.1.1 使用 Yalu beta 3 的人只能使用這套來支援 Cydia Substrate<br />
而使用 Yalu 102 新版的人，直接安裝 Cydia Substrate 即可，在 1 月底也有為了 iOS 10 釋出的 0.96301 的更新檔</p>
<p>&nbsp;</p>
<p>而此次 beta 1 版本，修正了這些不穩定性，就我自己使用上知道改正了以下錯誤：</p>
<ul>
<li>可以正常 Log 出錯誤訊息，NSLog 和 printf 正常使用</li>
<li>支援 MobileSubstrate</li>
<li><code>killall -9 Springboard</code> 在我的機器上是穩定的，這有待換到別的機器測試</li>
<li><code>killall -9 backboardd</code> 可以正常使用，不會讓手機重啟</li>
</ul>
<p>但透過 Yalu app 越獄失敗的情況還是存在，需要多嘗試一兩次才能成功</p>
<p><a href="https://flic.kr/p/RkDR2E"><img data-recalc-dims="1" loading="lazy" decoding="async" src="https://i0.wp.com/farm1.staticflickr.com/474/32383879132_986dccfb52_z.jpg?resize=640%2C418&#038;ssl=1" alt="螢幕快照 2017-01-26 下午7.41.25" width="640" height="418" /></a><br />
&nbsp;</p>
<p>================== 更新 ====================</p>
<p><strong>2017/02/01 更新</strong><br />
現在設備情況分為兩種：是 iPhone 7 以及非 iPhone 7 系列</p>
<ul>
<li>如果你是使用 iPhone 7 在 iOS 10.1.1 ，請使用<a href="https://garynil.tw/2016/12/234" target="_blank">這篇教學</a>配上 <a href="https://yalu.qwertyoruiop.com/mach_portal+yalu-b3.ipa" target="_blank">Yalu beta 3</a> (註：beta 4-1 作者沒有包好，也註明是損毀的，不要聽信網路傳言用 4-1 。)。</p>
</li>
<li>
<p>如果你是使用其他 64 bit 裝置並在 iOS 10，請使用 <a href="https://yalu.qwertyoruiop.com/yalu102_beta7.ipa" target="_blank">Yalu 102 beta 7</a>，詳請再參照此篇教學</a></p>
</li>
</ul>
<p><strong>2017/01/30 更新</strong><br />
推出 <a href="https://yalu.qwertyoruiop.com/yalu102_beta6.ipa" target="_blank">beta 6 版本</a><br />
現已支援所有 iOS 10 64 bit 的裝置除了 iPhone7, iPad Air 2 和 iPad Mini 4<br />
<em>fixes some issues some device/fw combos were having with the tfp0 / nonceEnabler patch</em></p>
<p>iPhone 7 可以使用 Yalu 舊版 <a href="https://yalu.qwertyoruiop.com/mach_portal+yalu-b3.ipa" target="_blank">beta 3</a></p>
<p>詳細更新項目可以參照<a href="https://yalu.qwertyoruiop.com" target="_blank">原始網頁</a></p>
<p><strong>2017/01/29 更新</strong><br />
推出 beta 5 版本<br />
<em>placebo effect</em></p>
<p><strong>2017/01/26 補充</strong><br />
我用兩台裝置 6s (iOS 10.2) 及 6s Plus (iOS 10.1.1) 做的測試<br />
在 6s Plus (iOS 10.1.1) 上使用 Yalu102 會出現幾個不能運作的情況：<br />
1.OpenSSH 無法運作，完全連不進去<br />
2.Log 失效</p>
<p>#註：後來證實是自己用 Github 上的版本 build 出來才會有問題，用官方版本是正常的</p>
<p>&nbsp;<br />
&nbsp;<br />
<del datetime="2017-02-04T14:39:21+00:00">但這些問題在 6s (iOS 10.2) 上一切正常<br />
而 OpenSSH 問題，只要透過 Yalu beta 3 就可以解決，但舊版又超不穩定..</del></p>
<p><strong>0127 補充</strong><br />
在 10.2 越獄之後，我有遇到裝完 iFile 和 Cydia Substrate 之後，除了系統 app 以外其他 app 點開馬上閃退的情況<br />
交叉測試之後發現：<br />
在第一次越獄之後，要先單獨安裝 Cydia Substrate，其他套件等此次安裝完 respring 之後在另外安裝<br />
便不會發升上述問題了<br />
&nbsp;</p>
<p>而進入文章重點，那此次 Jailbreak 要如何安裝使用呢？<br />
其實跟<a href="http://www.pangu.io" target="_blank">盤古 iOS 9 越獄</a> 一樣，是透過安裝一個 app 來觸發漏洞建立越獄環境<br />
當你每次重新啟動手機之後，是需要重新越獄的</p>
<p>而安裝 Yalu App 主要分為以下三個方法：</p>
<h3>方法1：透過 Cydia Impactor 和開發者帳號來安裝 (最簡易懶人)</h3>
<p>你需要準備的是作者編譯好的 <a href="https://yalu.qwertyoruiop.com/yalu102_alpha.ipa" target="_blank">ipa 安裝檔</a>以及 <a href="http://www.cydiaimpactor.com" target="_blank">Cydia Impactor</a><br />
然後使用 Cydia Impactor 將 ipa resign 後裝至你的手機<br />
詳細教學可以看我<a href="https://garynil.tw/2016/12/234" target="_blank">上次這篇</a></p>
<p>缺點就是因為 Apple 佛心讓大家可以成為開發者，但限制是你每 7 天要 resign 一次<br />
然後強烈建議不要使用自己的付費開發者帳號，他會將你 revoke ，之後在 Xcode 開發還要設定一次很麻煩..</p>
<h3>方法2：使用付費開發者帳號 Resign</h3>
<p>相信有付費開發者帳號的人有開發經驗會比較聰明，我也懶得截圖，就將步驟寫的簡易一點：<br />
主要的目的就是透過你的帳號將 ipa resign，</p>
<h1>以下這一小段可以略過，因為使用 Yalu 10.2 beta 1 不需要這麼做</h1>
<p>在 Yalu 第一版除了 ipa 本身以外，還要 resign 裡面的 dylib，先將 ipa 副檔名改為 zip 後打開找到以下檔案<br />
並透過 codesign指令，加上你的 iPhone Developer 描述檔及代號重新簽名<br />
這裡會發生問題有一種特殊情況，你必需要開一個在<a href="http://developer.apple.com/" target="_blank">開發者後台</a>去新增一個 APP ID 符合 ipa 的 bundle idintifier，才可以正常的 resign dylib</p>
<p></p><pre class="urvanov-syntax-highlighter-plain-tag">codesign -f -s "iPhone Developer: XXX (XXXXXXXXXX)" ./Frameworks/libswiftCore.dylib
codesign -f -s "iPhone Developer: XXX (XXXXXXXXXX)" ./Frameworks/libswiftCoreGraphics.dylib
codesign -f -s "iPhone Developer: XXX (XXXXXXXXXX)" ./Frameworks/libswiftCoreImage.dylib
codesign -f -s "iPhone Developer: XXX (XXXXXXXXXX)" ./Frameworks/libswiftDarwin.dylib
codesign -f -s "iPhone Developer: XXX (XXXXXXXXXX)" ./Frameworks/libswiftDispatch.dyli
codesign -f -s "iPhone Developer: XXX (XXXXXXXXXX)" ./Frameworks/libswiftFoundation.dylib
codesign -f -s "iPhone Developer: XXX (XXXXXXXXXX)" ./Frameworks/libswiftObjectiveC.dylib
codesign -f -s "iPhone Developer: XXX (XXXXXXXXXX)" ./Frameworks/libswiftQuartzCore.dylib
codesign -f -s "iPhone Developer: XXX (XXXXXXXXXX)" ./Frameworks/libswiftUIKit.dylib</pre><p></p>
<p>============================================</p>
<p>而 ipa resign 的部分可以透過 <a href="http://mac.softpedia.com/get/Developer-Tools/iModSign.shtml" target="_blank">iModSign</a> 或者 <a href="https://github.com/maciekish/iReSign" target="_blank">iResign</a> 有 GUI 的簽名工具完成<br />
你只需要導入你的開發者帳號的 Provisioning Profile，可以從 Xcode 的設定來尋找，要使用 Provisioning Profile:* 的那一個<br />
路徑在：<code>~/Library/MobileDevice/Provisioning\ Profiles</code></p>
<p><a href="https://flic.kr/p/Qhz9wh"><img data-recalc-dims="1" loading="lazy" decoding="async" src="https://i0.wp.com/farm1.staticflickr.com/519/31692656164_1740abae3a_z.jpg?resize=640%2C539&#038;ssl=1" alt="螢幕快照_2017-01-26_下午10_36_47" width="640" height="539" /></a></p>
<p>之後再透過 <a href="http://www.i-funbox.com" target="_blank">iFunbox</a> 之類的工具安裝 ipa 即可完成</p>
<h3>方法3：當你擁有了原始碼</h3>
<p>因為這次作者直接<a href="https://github.com/kpwn/yalu102">公開原始碼</a>，便可以用這種特殊的形式來操作</p>
<p>以 Xcode 開啟專案，</p>
<p>這裡會有個小問題，作者的 code 中會使用到 IOKit 這個 framework，正常開啟是會顯示失敗無法 build 的，我將解決方法寫在<a href="https://garynil.tw/?p=298" target="_blank">這篇 &#8211; Import IOKit framework into Xcode project</a></p>
<p>1.直接 Archive，Export for development 匯出成擁有你簽名的 ipa ，然後安裝、結束。<br />
2.接上手機直接 build 進去<br />
這方法好處是可以隨時 pull 作者 update 的新版本，隨時 build 保持最新版～</p>
<p><a href="https://flic.kr/p/QZD9rE"><img data-recalc-dims="1" loading="lazy" decoding="async" src="https://i0.wp.com/farm1.staticflickr.com/759/32157412680_c542db0aba_z.jpg?resize=640%2C466&#038;ssl=1" alt="螢幕快照_2017-01-26_下午11_09_13" width="640" height="466" /></a></p>
<p>這篇文章 <a rel="nofollow" href="https://garynil.tw/2017/01/295/yalu-ios-10-jailbreak/">Yalu102 &#8211; iOS 10.2 Jailbreak</a> 最早出現於 <a rel="nofollow" href="https://garynil.tw">Gary&#039;s ...Lasamia</a>。</p>
]]></content:encoded>
					
					<wfw:commentRss>https://garynil.tw/2017/01/295/yalu-ios-10-jailbreak/feed/</wfw:commentRss>
			<slash:comments>3</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">295</post-id>	</item>
		<item>
		<title>iOS 10.1.x 越獄 &#8211; Yalu beta 3</title>
		<link>https://garynil.tw/2016/12/234/ios-10-%e8%b6%8a%e7%8d%84-yalu/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=ios-10-%25e8%25b6%258a%25e7%258d%2584-yalu</link>
					<comments>https://garynil.tw/2016/12/234/ios-10-%e8%b6%8a%e7%8d%84-yalu/#comments</comments>
		
		<dc:creator><![CDATA[Gary]]></dc:creator>
		<pubDate>Fri, 30 Dec 2016 23:13:23 +0000</pubDate>
				<category><![CDATA[Dev]]></category>
		<category><![CDATA[iOS]]></category>
		<category><![CDATA[Cydia]]></category>
		<category><![CDATA[iOS 10]]></category>
		<category><![CDATA[Jailbrake]]></category>
		<category><![CDATA[Yalu]]></category>
		<guid isPermaLink="false">https://garynil.tw/?p=234</guid>

					<description><![CDATA[<p>Luca Todesco (qwertyoruiopz) 透過 Google 資安團隊 Project Zero 公布的 iOS 10.1.x 漏洞發布了第一個 iOS 10.1.x 的越獄工具「 yalu 」。 因為一些因素，也將手邊的 6s plus 越獄來做開發使用， 順便將這些步驟紀錄起來，此篇教學使用 yalu beta 3 版本，文章編輯時 beta 4 版已經釋出，但作者和網友們測試為損毀版本 (那幹嘛發XD)，所以以 beta 3 為基準，後續有更新等會再補上。 最重要的，確認自己有能力再進行這些程序和步驟，後果當然自行負責，千萬先進行備份！ 步驟一：確保系統及設備版本 如同作者網頁表示，這次越獄版本僅支援 iOS 10.1.x，未來會不會放出10.2或以下的版本是個未知數，不過漏洞在 10.2 也被 Apple 修復了，如果要再有越獄工具推出，也是使用別的漏洞了。 而支援...</p>
<p>這篇文章 <a rel="nofollow" href="https://garynil.tw/2016/12/234/ios-10-%e8%b6%8a%e7%8d%84-yalu/">iOS 10.1.x 越獄 &#8211; Yalu beta 3</a> 最早出現於 <a rel="nofollow" href="https://garynil.tw">Gary&#039;s ...Lasamia</a>。</p>
]]></description>
										<content:encoded><![CDATA[<p>Luca Todesco <a href="https://twitter.com/qwertyoruiopz" target="_blank">(qwertyoruiopz)</a> 透過 Google 資安團隊 Project Zero 公布的 iOS 10.1.x 漏洞發布了第一個 iOS 10.1.x 的越獄工具「 yalu 」。</p>
<p>因為一些因素，也將手邊的 6s plus 越獄來做開發使用，<br />
順便將這些步驟紀錄起來，此篇教學使用 yalu beta 3 版本，文章編輯時 beta 4 版已經釋出，但作者和網友們測試為損毀版本 (那幹嘛發XD)，所以以 beta 3 為基準，後續有更新等會再補上。</p>
<p><strong>最重要的，確認自己有能力再進行這些程序和步驟，後果當然自行負責，千萬先進行<strong>備份</strong>！</strong><br />
<span id="more-234"></span></p>
<h3>步驟一：確保系統及設備版本</h3>
<p>如同作者<a href="https://yalu.qwertyoruiop.com" target="_blank">網頁</a>表示，這次越獄版本僅支援 <strong>iOS 10.1.x</strong>，未來會不會放出10.2或以下的版本是個未知數，不過漏洞在 10.2 也被 Apple 修復了，如果要再有越獄工具推出，也是使用別的漏洞了。</p>
<p>而支援設備非常的少，僅有 64 bit 的以下裝置：</p>
<ul>
<li>iPhone 7 &#038; iPhone 7 Plus on 10.1.1</li>
<li>iPhone 6s/6s Plus on 10.0.x &#8211; 10.1.1   (目前因為offset問題，僅支援 Samsung CPU 的裝置：<a href="https://itunes.apple.com/tw/app/cpu-identifier/id1045029477?l=zh&#038;mt=8" target="_blank">N71AP，N66AP</a>)</li>
<li>iPad Pro on 10.0.x &#8211; 10.1.1.</li>
</ul>
<p><strong>2017/02/01 更新</strong><br />
現在設備情況分為兩種：是 iPhone 7 以及非 iPhone 7 系列</p>
<p>&#8211; 如果你是使用 iPhone 7 在 iOS 10.1.1 ，請使用這篇教學配上 <a href="https://yalu.qwertyoruiop.com/mach_portal+yalu-b3.ipa" target="_blank">Yalu beta 3</a> (註：beta 4-1 作者沒有包好，也註明是損毀的，不要聽信網路傳言用 4-1 。)。</p>
<p>&#8211; 如果你是使用其他 64 bit 裝置並在 iOS 10，請使用 <a href="https://yalu.qwertyoruiop.com/yalu102_beta7.ipa" target="_blank">Yalu 102 beta 7</a>，詳請可以看這篇<a href="https://garynil.tw/2017/01/295" target="_blank">教學</a></p>
<h3>步驟二：下載越獄工具</h3>
<p>這次的越獄工具和盤古 9.3.3 越獄有點類似，都是一個手機的 ipa，然後透過程式去處發漏洞。所以首先去作者網頁下載<a href="https://yalu.qwertyoruiop.com/mach_portal+yalu-b3.ipa" target="_blank">最新版本的 ipa</a> (beta 3) 至一台可以 resign 的 MacOS 電腦。</p>
<h3>步驟三：重新簽名</h3>
<p>因為要裝野生的 ipa 至你的手機，只能夠過<a href="https://developer.apple.com" target="_blank">開發者帳號</a>重新簽名後安裝，我是使用 <a href="http://www.cydiaimpactor.com" target="_blank">Cydia Impactor</a> 來進行重新簽名的動作</p>
<p>下載完 Cydia Impactor 之後，將越獄工具的 ipa 拖拉至下方選單 &#8220;Install Super Su&#8221; 上，就會出現輸入開發者帳密提示視窗，建議是用個免費的開發者帳號，因為他會將你帳號 revoke。<br />
<a href="https://flic.kr/p/PvmheX"><img data-recalc-dims="1" loading="lazy" decoding="async" src="https://i0.wp.com/farm1.staticflickr.com/612/31180903353_de6fb0df55_z.jpg?resize=640%2C359&#038;ssl=1" alt="螢幕快照_2016-12-31_上午6_48_40" width="640" height="359" /></a><br />
<br />
註：有用兩步驟驗證的人是需要去產生一組<a href="https://appleid.apple.com/#!&#038;page=signin" target="_blank">應用程式密碼</a>的<br />
<a href="https://flic.kr/p/PsCdmd"><img data-recalc-dims="1" loading="lazy" decoding="async" src="https://i0.wp.com/farm1.staticflickr.com/398/31150062564_c2f890a8c7_z.jpg?resize=640%2C281&#038;ssl=1" alt="螢幕快照 2016-12-31 上午6.48.43" width="640" height="281" /></a></p>
<p>如果一切都運作正常，這時候你手機應當會出現一個 mach_portal 的空白圖示 app<br />
<a href="https://flic.kr/p/PvmgVk"><img data-recalc-dims="1" loading="lazy" decoding="async" src="https://i0.wp.com/farm1.staticflickr.com/529/31180902273_ff434358ef_c.jpg?resize=450%2C800&#038;ssl=1" alt="IMG_2606" width="450" height="800" /></a></p>
<h3>步驟四：開啟 mach_portal，觸發漏洞</h3>
<p>如果你的系統版本，硬體一切正確，開啟 mach_portal 程式之後，程式會出現白色畫面，這是正常的！你只要靜待 20 秒左右 (千萬不要沒耐心退出)，越獄成功桌面應當會出現 Cydia 圖示<br />
<a href="https://flic.kr/p/QvMri9"><img data-recalc-dims="1" loading="lazy" decoding="async" src="https://i0.wp.com/farm1.staticflickr.com/541/31842168382_8960c95e3f_c.jpg?resize=450%2C800&#038;ssl=1" alt="IMG_0001" width="450" height="800" /></a></p>
<p>過程中我有失敗過一次，手機呈現全黑畫面，強制重新啟動後再次開啟就正常了，如果失敗了應該多試幾次就會成功 (?</p>
<h3>步驟五：安裝必要套件</h3>
<p>1. Cydia Substrate (Only for Yalu beta 3)<br />
越獄完當然首先先啟動 Cydia 裝必要套件以防萬一，這次越獄完是沒有 Cydia Substrate 的，要自己手動安裝，而 Bigboss 源的版本暫時不支援 iOS 10 ，必須額外添加：<code>83.218.67.215/~ijapija00/cydia</code> 這個軟體源，去安裝裡面的 Substrate Fix (iOS 10)<br />
<a href="https://flic.kr/p/Pvmh7H"><img data-recalc-dims="1" loading="lazy" decoding="async" src="https://i0.wp.com/farm1.staticflickr.com/704/31180902933_e66c289dcd_c.jpg?resize=450%2C800&#038;ssl=1" alt="IMG_0002" width="450" height="800" /></a><br />
安裝完成之後，桌面應當會出現一個藍色圖示的小程式：Substrate Fix，而每次越獄完都需要啟動他來修復，很麻煩。<br />
<a href="https://flic.kr/p/Pvmha8"><img data-recalc-dims="1" loading="lazy" decoding="async" src="https://i0.wp.com/farm1.staticflickr.com/385/31180903073_17b8a57472_c.jpg?resize=450%2C800&#038;ssl=1" alt="IMG_0003" width="450" height="800" /></a></p>
<p>因此，每次手機重新啟動後要進行的流程是：</p>
<ol>
<li>重開機至主畫面</li>
<li>開啟 mach_portal 等待完成退出</li>
<li>開啟 Substrate Fix</li>
<li>開啟 Cydia 進行操作</li>
</ol>
<p>但這目前版本的 Respring 也非常不穩定，幾乎都會黑畫面需要重開機，因此你安裝完 tweak 需要 respring 時也是需要進行這些步驟。</p>
<p>2.Open SSH<br />
遠端登入手機，預設密碼是 alpine，務必改掉</p>
<p>3.行動數據失效！？<br />
越獄完由於權限的問題，你會發現你行動網路收不到訊號，但電話功能是正常的。由於越獄後的權限問題，必需要開啟數據漫遊才會恢復正常，但可以照皮樂大大<a href="https://www.facebook.com/hiraku.tw/posts/1505972326099196" target="_blank">這篇</a>的方式解決：<br />
先透過 SSH 進入手機之後，輸入以下指令：<br />
<code>chmod 777 /var; </code><br />
<code>chmod 777 /var/mobile; </code><br />
<code>chmod 777 /var/mobile/Library; </code><br />
<code>chmod 777 /var/mobile/Library/Preferences</code><br />
註：不需要 recursive</p>
<p>4.重置所有內容後，Cydia 無法安裝<br />
問題可能為：</p>
<p>Cydia出現紅字：DPKG_LOCKED<br />
Cydia出現紅字：Could not open file /var/lib/dpkg/status<br />
<img data-recalc-dims="1" loading="lazy" decoding="async" src="https://i0.wp.com/i.imgur.com/NZ03UcI.png?resize=700%2C1225&#038;ssl=1" width="700" height="1225" class="alignnone size-medium" /></p>
<p>反正因為這些DPKG的權限問題，重置之後會無法重新安裝 Cydia，或者 Cydia 內無法正常安裝Tweak，有遇到的人解決方法在此：<a href="https://www.reddit.com/r/jailbreak/comments/5jv0ag/tutorial_how_to_rejailbreak_your_device_after/" target="_blank">[Tutorial] How to re-jailbreak your device after erase all content and settings</a></p>
<p>另外因為這次 JB 內建裝了 SSH，所以可以直接使用 Terminal 遠端登入，不需要透過裝一些<a href="http://www.redmondpie.com/fix-cydia-could-not-open-file-varlibdpkgstatus-ios-10-error-after-jailbreak-heres-how/" target="_blank">奇怪的東西</a>來修改檔案，方便很多，不過建議熟悉的人再操作</p>
<p>5.更新 Cydia<br />
12/31號 Saurik 有釋出給 iOS 10 使用的 Cydia beta 版，越獄完可以直接<a href="https://cydia.saurik.com/api/share#?source=http://apt.saurik.com/beta/cydia-arm64/&#038;package=cydia" target="_blank">加入測試源</a> (http://apt.saurik.com/beta/cydia-arm64/) 進行更新。</p>
<p>6.安裝 iFile<br />
必要套件不解釋</p>
<p>7.相容 Tweak<br />
至於現在可以裝什麼，幾乎都不能裝吧XD<br />
可以參照這篇有勇者們去測試：<a href="https://docs.google.com/spreadsheets/d/14e9GB-PNhDJuKI799InVFWrUQc-qn-Wd3zRJHKGkKr0/pubhtml#" target="_blank">iOS 10 Compatibility</a><br />
推薦一下 <a href="http://cydia.saurik.com/package/tw.hiraku.keyboardaccio/" target="_blank">Keyboard Accio</a>，我越獄完第一個必裝&#8230;內建切換太難用。</p>
<p>這篇文章 <a rel="nofollow" href="https://garynil.tw/2016/12/234/ios-10-%e8%b6%8a%e7%8d%84-yalu/">iOS 10.1.x 越獄 &#8211; Yalu beta 3</a> 最早出現於 <a rel="nofollow" href="https://garynil.tw">Gary&#039;s ...Lasamia</a>。</p>
]]></content:encoded>
					
					<wfw:commentRss>https://garynil.tw/2016/12/234/ios-10-%e8%b6%8a%e7%8d%84-yalu/feed/</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">234</post-id>	</item>
	</channel>
</rss>
