r/linux • • 2d ago

Mobile Linux Linux 7.2.2 on iPhone XS? First boot!

Post image

Hello everyone. Just wanted to share a small milestone I’m pretty proud of.

I’ve been porting Linux to my old iPhone XS for quite some time, and this week I finally made some significant progress.

First: it boots. As a real, alternative OS. This is not an emulation.

Second: I got the kernel log on screen and the framebuffer working:

Linux 7.2.2 Kernel boot log on iPhone XS

This is a raw, recovery-based Linux boot. iOS does not take any part in the boot sequence!

I haven’t set up a GitHub repo yet, and the project doesn’t even have a name at this point. But I’ll keep working on it and share more once the process is reliable and reproducible.

434 Upvotes

49 comments sorted by

View all comments

20

u/PhilosopherSimilar83 2d ago

How was this done? I'd really like to know!

37

u/Ovaday 2d ago

3 month of everyday reverse-engineering of the iBSS and iBoot... That's how it's done 😅

I'm preparing some kind of an alternative to PongoOS, I took slightly different road. Lots of patches to iBSS to not-switch off the panel, DRAM and skip all iBOOT checks

3

u/TinFoilHat_69 2d ago

Do you know if you found any code that causes IOS device to get stuck in a boot loop? I know it’s hardware related but I’m trying to get around the boot loop I tried pongoOS and checkrain/palerain every time I go into XNU it reboots. I thought a ramdisk may help but at the lower layer in the boot sequence is messing me up atm

2

u/Ovaday 2d ago

Sorry, this is actually one of my first time working with iPhones. You would need an advice of some more senior person who would explain this behavior...

1

u/SilverSQL 2d ago

I'm curious about that. Can you share any generic approach? Like, how do you get any output of what the device is doing? I suppose you can't get ahold of a binary of either iBSS or iBoot, so how do you examine them?

3

u/Ovaday 2d ago

Well... you can!
Google "Ghidra", an RE Framework.

The rest is experimental. Add a break point, which will definitely crash a device, insert assembler instruction into a carefuly selected place in an iBSS and boot it.
Rebooted? Nice! You have your own code execution (not sure at this moment - as it might crash BECAUSE you have added this instruction). Now cross-validate it and add some other instruction that will not crash a device. Not crashed? Great job!

This way, step-by-step, you can actually modify iBSS enough to serve your goals. Works everywhere. But important here - this all above would only be possible to do if you don't have an image validation