Difference between revisions of "Kernel Symbols"

From The iPhone Wiki
Jump to: navigation, search
(Started updating iPhone4S symbols, too. People - why am I the only one adding?)
Line 9: Line 9:
 
!symbol
 
!symbol
 
!5.0.x [[N81ap|iPod touch 4G]]
 
!5.0.x [[N81ap|iPod touch 4G]]
!5.1.b3 iPad 1
+
!5.0.1 iPhone 4S
 
!5.1 [[N81ap|iPod touch 4G]]
 
!5.1 [[N81ap|iPod touch 4G]]
 
!Notes
 
!Notes
Line 15: Line 15:
 
|_exception_triage
 
|_exception_triage
 
|0x80016C34
 
|0x80016C34
| ...
+
| ???
 
| ...
 
| ...
 
|The Mach exception processing logic.
 
|The Mach exception processing logic.
Line 21: Line 21:
 
|sysent
 
|sysent
 
|0x802CCBAC
 
|0x802CCBAC
  +
|???
|0x802CDBAC
 
 
|0x802CCBAC
 
|0x802CCBAC
 
|Through this you can obtain all of XNU's 438 system calls, e.g. _exit @0x8019DE04
 
|Through this you can obtain all of XNU's 438 system calls, e.g. _exit @0x8019DE04
Line 27: Line 27:
 
|syscall_names
 
|syscall_names
 
|0x802D2C6C
 
|0x802D2C6C
  +
|???
|0x802D3C5C-0x802D4338
 
 
|0x802D2C5C-0x802D4338
 
|0x802D2C5C-0x802D4338
 
|The char[][] containing the textual names of all system calls
 
|The char[][] containing the textual names of all system calls
Line 33: Line 33:
 
|AppleMobileFileIntegrity_Start
 
|AppleMobileFileIntegrity_Start
 
|0x805E499C
 
|0x805E499C
| ...
+
| ???
| ...
 
 
|0x805D5B94
 
|0x805D5B94
 
|Initialization of AMFI, the kext responsible for [[sandbox]] policies and entitlements
 
|Initialization of AMFI, the kext responsible for [[sandbox]] policies and entitlements
Line 40: Line 39:
 
|bsd_init
 
|bsd_init
 
|0x802B77C0
 
|0x802B77C0
  +
| ???
|0x802B8A24
 
  +
|0x802B8A24
| ...
 
 
|BSD layer initialization logic. Branches out to initialize virtually every BSD subsystem. Same as OS X XNU, with minor exception (e.g. kernel_memorystatus/jetsam, iptap..)
 
|BSD layer initialization logic. Branches out to initialize virtually every BSD subsystem. Same as OS X XNU, with minor exception (e.g. kernel_memorystatus/jetsam, iptap..)
 
|-
 
|-
Line 51: Line 50:
 
|}
 
|}
   
Note: For most of the above symbols, a fairly decent source code can be obtained from the public open source XNU at opensource.apple. Bear in mind that ml_, PE_ and other machine specific functions will naturally be implemented quite differently. (but, it's a start!)
+
Note: For most of the above symbols, a fairly decent source code can be obtained from the public open source XNU at opensource.apple. Bear in mind that ml_, PE_ and other machine specific functions will naturally be implemented quite differently. (but, it's a start!).

Revision as of 15:08, 11 May 2012

iOS's XNU is largely stripped, and contains fewer and fewer symbols with its newer versions. Whereas in pre 3.0 most symbols were visible, nowadays only symbols required for KExt linkage remain so.

This page is started in the hopes of bringing together efforts of the various jailbreakers so as to pool already symbolified sections of the kernel. Because addresses change along with the different builds, please add the symbols under the right kernel version (i.e. release + device). If not 100% sure about a symbol, indicate the level of confidence.

Started with iPod touch 4G, because this is the main kernel the author has largely (>80%) symbolicated. Please add your own. Even if your build is different, the address space doesn't change that much. Bear in mind that - if Mountain Lion is any indication - iOS will soon introduce kernel level ASLR, as well.

symbol 5.0.x iPod touch 4G 5.0.1 iPhone 4S 5.1 iPod touch 4G Notes
_exception_triage 0x80016C34 ??? ... The Mach exception processing logic.
sysent 0x802CCBAC ??? 0x802CCBAC Through this you can obtain all of XNU's 438 system calls, e.g. _exit @0x8019DE04
syscall_names 0x802D2C6C ??? 0x802D2C5C-0x802D4338 The char[][] containing the textual names of all system calls
AppleMobileFileIntegrity_Start 0x805E499C ??? 0x805D5B94 Initialization of AMFI, the kext responsible for sandbox policies and entitlements
bsd_init 0x802B77C0 ??? 0x802B8A24 BSD layer initialization logic. Branches out to initialize virtually every BSD subsystem. Same as OS X XNU, with minor exception (e.g. kernel_memorystatus/jetsam, iptap..)
ExceptionVectorsBase 0x80078000 0x80078000 0x80078000 Address of CPU exception handlers in kernel space: fleh_reset, fleh_undef, fleh_swi, fleh_prefabt, _fleh_dataabt, _fleh_addrexc and fleh_irq can be obtained from here

Note: For most of the above symbols, a fairly decent source code can be obtained from the public open source XNU at opensource.apple. Bear in mind that ml_, PE_ and other machine specific functions will naturally be implemented quite differently. (but, it's a start!).