Research documentation
Home · Findings · Evidence · Status
The pages below preserve the detailed analysis from the September 27, 2026 audit snapshot. They report measured bytes, selected static paths, and unresolved boundaries separately. Addresses refer to the exact named build and binary, not arbitrary macOS releases.
| Read in this order | Page |
|---|---|
| 1. Scope and results | Audit overview, methodology, coverage, limitations |
| 2. Objects and workflow | Provenance, inventory and images, architecture, RAMDisk/ramrod, installer workflow |
| 3. Trust and boot | Code signing/KCs, Image4/trust/Secure Boot, sealed system volume, OpenCore assessment |
| 4. Device communication | USB/services/TLS, mobile-device components, restore networking/FDR |
| 5. Firmware | Catalog/Option ROMs, PFX, PSF and updater handoff |
| 6. Kernel and policy | Stage 6F.7 NVRAM/EFI, sandbox, AMFI, APFS/Device Tree, reverse-engineering map |
| 7. Reproduce and continue | Findings index, source narrative coverage, reproduction, corrections, open questions, audit status, references |
The finding groups preserve all 100 original IDs across reference, RAMDisk, USB, signatures, firmware, configuration, remote services, and network categories. The source crosswalk, public tables, and evidence index help reviewers trace the published claims without distributing copyrighted binaries or private raw logs.
The diagrams have rendered SVGs and editable Mermaid sources, with text explanations on their subject pages. The local Pages instructions cover the site build and navigation check. The CI workflow validates but does not deploy this draft.