Skip to the content.

Reverse-engineering map and reproducibility bounds

Home · Methods · Evidence

Analysis used symbol tables, Mach-O fileset structure, code-signature metadata, imports, chained fixups, original-byte-checked disassembly, strings with offsets, Objective-C selectors, launch configuration, and cross-artifact consumers. A function name or string was treated as a lead. The published claims depend on a checked branch, binding, data structure, or measured content. The full instruction streams remain in private evidence because they include copied Apple code and machine-specific data.

Artifact or code family Exact scope reached Detailed page
ramrod, libramrod.dylib, patch plugin Sealing call binding, arguments, root-hash validation, selected errors and skip control RAMDisk/ramrod
softwareupdated, UpdateBrainLibrary 27-command and seven-command tables, selected entitlement gates, writer/reader, receiver and context guards Installer workflow
remoted, RemoteServiceDiscovery, Security/CTK/AKS Selected service policy, TLS, attestation, identity token and signing routes USB/services
Restore libraries and PFX URL/TLS/FDR/AP-ticket gates, PFX staging and IOKit selector routes Restore, PFX
PSFFlasher, MultiUpdater, bless, FirmwareUpdateLauncher Input selection, PCI mailbox, EFI boot handoff, result/error and helper mappings Flashers/updaters
Intel BootKernelExtensions.kc 204-member fileset indexed; selected AppleEFINVRAM, AppleEFIRuntime, AppleACPIPlatform, sandbox and AMFI functions decoded Stage 6F.7, sandbox, AMFI
EFI/Option ROMs and Image4 Bounded PE signature, wrapper, certificate-role, payload-region and cache representation checks Firmware, Secure Boot

For Stage 6F.7 the x86_64 KC is 67,584,000 bytes, SHA-256 c80161fa3065883753fc285339281361a8469cbb6fb27653c88e2a22eb4807a4. Its 204 fileset entries were indexed, not all analyzed. The published EFI branch table records 22 typed-node branches with required/optional fields, widths and node bytes. The helper table records 11 Mach-O helper paths and 15 EFI flasher paths, but a located/signed path is not proof of invocation.

Selected original-byte-checked ranges include AppleEFINVRAM::verifyPermission at 0xffffff800195f221, EFI path conversion at 0xffffff8001486574 and typed-array converter at 0xffffff80014866a0..0xffffff8001488c94, registry builder at 0xffffff80014890b2..0xffffff800148ae65, AppleEFIRuntime::callEFIRuntime at 0xffffff800195a1f8, and the EFI indirect call at 0xffffff80002ea041. Sandbox operation 0x76 maps to nvram-set; the current continuation begins at _sb_evaluate_internal 0xffffff8003034156. These are artifact-specific virtual addresses and must not be transplanted to another KC/build.

The retained analysis cross-checked selected decoded ranges against original KC bytes and original chained pointer links. Disassembly still has limitations: whole-section decoders may cross padding or misidentify function starts, and inferred Objective-C receivers can be wrong without register/callsite proof. The reproduction guide identifies checks possible with legally obtained matching artifacts. The findings index retains per-finding claims and limits.