Skip to the content.

Open questions

Home · Documentation · Status

This is the original Q01–Q35 unresolved-question register at the September 27, 2026 snapshot. These are research questions and evidence gaps, not findings of malicious behavior. Names of private evidence files identify retained provenance; those raw files are intentionally not published.

ID Status Question Next evidence or limit
Q01 IN PROGRESS Who can supply DoNotSeal through each reachable client path? Stages 4G/4I trace gates and session registration; next map client identity, handle ownership/expiry, helper forwarding and mutations; existing command entitlement gates do not cover all possible callers.
Q02 IN PROGRESS Does verification-state serialization represent successful verification on every path? Stage 4I finds no normal loader population of flag0x80 and traces serialization-failure cleanup. Stage4J.1 resolves the loaded-context validation-failure free/null return and receiver gate/defaults. Stage4J.2 bounds outer cleanup retention/deletion and partial-success returns. Stage4J.3 bounds target/connection selection (Q31). Stage4J.4 traces constructor free/null on validation failure, snapshot-failure propagation past the new-handle registration branch and an internal asset-staging flag0x80 producer. Remaining: prior handles/aliases/reuse, removal/expiry, nested disposal, transitive cleanup and callback acceptance/exclusion. Also inspect apply-state-write failure return/error interpretation before any finding.
Q03 REQUIRES DYNAMIC TESTING What were Update.plist ownership, ACLs, parent protections and actual contents during this update? Acquire relevant historical evidence if retained; mode0644 requested by code is not measured historical state.
Q04 IN PROGRESS How are downloaded update brains accepted and authenticated before loading? Trace softwareupdated LoadBrain/LoadMABrain and XPC launch/signature validation.
Q05 IN PROGRESS Which signed trust-cache representation is selected at runtime? Trace loader choice for four identical-entry alternate-tag/UUID pairs.
Q06 REQUIRES HARDWARE What decrypts Product.efi and authenticates its trailer? Continue static decoder analysis; required runtime variable/plaintext unavailable in collection. Do not solicit keys.
Q07 IN PROGRESS Which Image4 roots, policy constraints, nonces and rollback rules are actually selected? Trace libimage4/root-selection plus platform loaders; certificate linkage alone is insufficient.
Q08 IN PROGRESS How do all restore checkpoints, retries and rollback paths propagate errors? Extend ramrod/brain call graph beyond sealing.
Q09 IN PROGRESS Are every plist, script, shared-cache library, certificate and unnamed container covered? Path queue covers 147,253 objects; Stage 5A parses 78,465 plists. Resolve 606 protected candidates, unnamed formats, scripts and embedded cache semantics.
Q10 IN PROGRESS Which USB, network and debugging services can be reached and with what authentication? Stage 5B classifies 19 socket groups and finds other-image path candidates for 11 of 36 unresolved declarations. Stage 5C traces CoreDevice entitlement presence and BaseSystem PAM delegation; next trace peer authentication and full policy composition. Candidates do not resolve deployment.
Q11 IN PROGRESS Are CNKL method-2 and BOM signatures independently authenticated? Decode formats and validate against appropriate trust anchors; package signature is a separate layer.
Q12 IN PROGRESS What seal/snapshot/firmlink/Preboot relationships exist in every image? Consolidate saved APFS evidence then collect missing read-only image metadata.
Q13 REQUIRES DYNAMIC TESTING Did any retained capability actually execute on this Mac? Search scoped retained activity evidence and document unavailable history; strings/options do not establish activity.
Q14 IN PROGRESS Can the four original index/boot-label files obtain exact Apple reference counterparts? Keep them outside exact-vendor-match totals until independently matched.
Q15 IN PROGRESS Which inventory fields lack capture, especially ACLs and creation times? Check schemas and field coverage; reacquire originals read-only only if needed and permitted.
Q16 IN PROGRESS Do per-firmware targets, loaders and versions agree across manifests? Extend component relationship matrix, including rollback and personalization where observable.
Q17 REQUIRES DYNAMIC TESTING Was an additional bootloader such as OpenCore installed or used? Not established by this update audit; OpenCore source citations are not detections. Separate host-boot acquisition would be required.
Q18 IN PROGRESS Are public findings reproducible and safe to release without private data or unlicensed binaries? Maintain evidence cross-references and sanitized tools; final release review and publication remain separate.
Q19 IN PROGRESS How does sshd-fvunlock authenticate, select the target and enforce throttling? Stage 5D traces the helper AKS-result gate, APFS loop and logging-only ACM callback. Next trace the imported verifier backend/throttling, full username/target/input mapping, callback failure-state implications, effective SSH includes, PAM module resolution and ARM equivalence.
Q20 IN PROGRESS Who selects remoted service entitlement policy, and how are remote peers authenticated? Stage5E identifies local event/legacy policy producers, description serialization and override precedence, and three helper callers. Stage5F identifies type-trust delegation, required-TLS refusal and callback-result propagation. Stage5G adds conditional DCRT/DAK checks, key binding and Apple-matching roots. Stage5H resolves four required-OID methods and outer chassis policy/exception paths. Stage5I adds numeric matching and preference-wrapper behavior. Stage5J adds backend defaults, setter entitlement-presence checking and identity-slot/startup deletion edges. Stage5K adds conditional generator extensions, checked creation/storage failures and reload/OID metadata boundaries. Stage5L adds callers/completion and handshake serialization. Next trace token consumers/rights, exact RemoteXPC enforcement, remaining metadata mutations and accepted descriptions; distinguish per-service EncryptSocketData default from outer transport and effective policy.
Q21 IN PROGRESS Does the DCRT expiration exception allow only intended time failures? Stage5G proves acceptance after SecTrustIsExpiredOnly OR a top-level NSOSStatusErrorDomain/-67818 match. The second branch does not itself inspect all trust failures. Resolve exact-build Security error aggregation, concurrent failure ordering, rationale and interaction with mandatory OIDs/AKS/chassis constraints. No malformed or expired peer was tested; no bypass established.
Q22 IN PROGRESS When can chassis membership be skipped, and what protects the policy and manifest inputs? Stage5H proves type16 local-manifest-unavailable success and type15 absent-peer-manifest success when chassis policy is false; present but unprocessable manifests fail. Earlier DCRT/DAK requirements remain. Stage5I traces inner numeric comparisons and preference API calls. Trace AMFDR return conditions, provider/parse guarantees, RSDPreferences write protections and setting stability between calls. No hostile control, live setting or unauthorized access established.
Q23 IN PROGRESS Are numeric identity representations and local provider outputs constrained by earlier layers? Stage5I finds checked hex scans without explicit full-consumption checks, unused trailing attestation components in this helper, and unchecked CFNumberGetValue results. Host-only Foundation probe demonstrates prefix acceptance on25G229, not exact target25G83 behavior. Trace exact frameworks and input authenticity/type guarantees; no forged identity acceptance demonstrated.
Q24 IN PROGRESS What guarantees the TLS policy mutation and identity-generation inputs, and when does an identity become usable? Stage5J finds entitlement-object-presence gates for compute policy and an administrative generation caller. Resolve entitlement type/value issuance, remaining writers, remaining generator/framework guarantees, async caller/completion, effective settings and exact-framework behavior. Stage5K resolves ordinary key/ACL and certificate/storage failures; generation can omit extensions, reload lacks a post-generation requested-set check, and null identity does not clear OID metadata in the examined refresh helper. No live keychain/preferences or remote service was invoked.
Q25 IN PROGRESS Can an incomplete regenerated identity or unchanged OID metadata influence a live session? Stage5K proves the local flow can queue a generated/null object without a second requested-OID check; null slot refresh leaves the dictionary key unchanged. Stage5L traces six direct callers and a handshake send route; compute null-identity selects a TLS-disable configuration, while TLS-enabled loopback crashes. Trace other writers, exact framework changes, later enforcement and publication/connection timing. No stale wire advertisement, peer acceptance or bypass demonstrated.
Q26 IN PROGRESS Who can obtain and use the local identity token blob? Stage5L finds no application entitlement/UID gate on the inspected get_local_device_identity listener/getter route. Trace external Mach lookup/sandbox restrictions, legitimate consumers and exact AKS token import/use authorization. Stage5N traces the exact-cache client: privileged Mach lookup, synchronous getter, certificate parse, token-OID/AppleKeyStore import and TLS identity adapter. Stage5O follows Security token dispatch, session parameters, object lookup and the -1002 registered-token deferred-object exception. Stage5P resolves SEP token/session routing and the typed nonzero current-task access-keychain-keys gate for local key selection, with an explicit connection selecting the other implementation. Stage5Q traces unknown-ID-only fallback, typed system-key entitlement/caller routing, reference import/signing status checks and synchronous CTKD attribute IPC. Stage5R bounds Security object reconstruction/single retry and externalized-context plus ACL/caller-group parameters. Stage5S traces server current-connection provenance on cache miss, local initializer forwarding, shared key-cache hits and attribute/sign dispatch; AppleKeyStore companion acquisition is complete. Stage5T bounds parameter setter failure ordering and import/sign preparation; uninspected setter status does not establish omitted-field authority. Next trace operation-block callers, cache-hit caller/context binding (Q29), ACM/AKS enforcement, remote signing and endpoint reachability; route selection and nonnull wrappers alone do not prove signing rights. Do not retrieve a real identity; no plaintext key disclosure established.
Q27 IN PROGRESS Can the compute null-identity TLS-disable configuration reach accepted transport? Trace xpc_remote_connection_setup_nw_parameters effects, NW wrapping flags, base connect/TLS flags, later refusal and framework completion. Stage5M confirms later base-connect crashes on missing identity when enable flag is true, and tlsEnabled is assigned before activation. Layer-specific disable selection is not proof of plaintext or unauthorized session acceptance.
Q28 IN PROGRESS How do callers interpret authenticate_device and what authorizes its endpoint? Stage5M traces certificate parsing and type/OID evaluator result to OK/ERROR. Stage5O traces the client per-device request and null-result-string success branch into a TLS verification adapter. Trace adverse reply producers, endpoint distribution, full transport acceptance and channel binding. Resolve null-chain/lastObject fall-through and exact Security API behavior before any repeated-callback/crash conclusion; no bypass or private-key possession established.
Q29 IN PROGRESS What prevents a CTKD cached key from crossing caller or force-session authority? Stage5S shows shared token-server key storage and object-ID/auth-context equality before reuse; current caller and requested force flag are not explicitly compared in that lookup. Resolve context authenticity/equality, cross-caller availability, token-server instance scope, key lifetime/retained caller and per-operation backend checks. No cross-client use or bypass demonstrated.
Q30 IN PROGRESS Why does the complete inventory-matched cleanup-service bundle fail ordinary and strict codesign with obsolete custom omit rules? Stage4K.1 checks396 page hashes,five populated special slots,two zero slots and CMS integrity with -noverify. CodeResources matches its signed slot and contains blanket omit rules/empty maps; ordinary/strict rejection remains. Stage4K.2 reproduces the exact official image/bundle and policy rejection; Apple-root equality and four bounded certificate-chain evaluations pass; two omitted resource files are identified and reviewed. Remaining: restore-specific acceptance, actual resource integrity enforcement and fresh revocation status. Signed time is not an independently verified timestamp. No local content modification found in this bundle.
Q31 IN PROGRESS Who produces and can forward __CleanupTargetUUID, and what binds mutable target-controller state to the caller and selected media? Stage4J.3 resolves the override consumer, cached named XPC connection, omitted-UUID root/snapshot route and APFS pairing/container setup. Trace upstream writers/forwarding, complete endpoint authorization, controller/session scope and libpartition2 media policy. Setter true can survive some setup failures; no unauthorized target use established.
Q32 IN PROGRESS Which callers control restore trust exceptions, and what establishes authoritative ticket/object and transport acceptance? Stages6A–6E bound census, request/ticket and selected delegate/custom-root paths; FDR validation-disable reaches UseCredential. Option/root/caller authority, full ticket/certificate constraints and Foundation policy remain open. PFX command/local-signing/request-response boundaries are now bounded in6F.1; external signing/loader authority remains open; Q33 tracks exact crypto discrepancy. No actual connection or unauthorized control established.
Q33 IN PROGRESS Can the transport RSA legacy fallback or discarded canary result affect a reachable restore session? Exact AMS0xeac0 ignores legacy false validity after status0 and discards extra canary comparison; Image4 c03e differs. Exact packaged crypto variants supply newer API and propagate primary errors; libSystem reexports default. Establish runtime/loader reachability, root/option authority, exact EMSA/canary constraints and practical effect. Static discrepancy confirmed; no current signature bypass or compromise demonstrated.
Q34 IN PROGRESS What authorizes PFX firmware selection/writes and authenticates the final device payload? Stages6F.1–6F.2 resolve local-signing response branch, normal zeroed options, staging selector4 and later apply flag; packaged UARP/vendor regions and CRCs pass. Caller/user-client policy, equal-version abandon state,32-bit chunk bounds,debug-file/error contracts,signed message and controller trust/rollback remain open. No device operation performed.
Q35 IN PROGRESS What authorizes PSF EFI inputs and enforces controller firmware trust? Stages6F.3–6F.6: exact four-file comparison/6CRCs, PCI/status, input/providers/filename/version paths, missing local bounds and query-result confusion, generic helper-to-bless staging traced. No inventoried psfupdater. Exact bless/MultiUpdater staging, optional IMG4 policy and true verification callback, options, retry/state and static error gaps traced. Stage6F.7 resolves selected permissions, conversion, queue and runtime handoff; remaining internal override/MAC callers, helper authority and conversion-failure effects; then firmware ISA,signed message,key manifests and rollback. No observed flashing or bypass.