Experimental tooling for running and observing Tahoe's SPTM/TXM/XNU path on an Apple M3 (J613/T8122) through a patched Asahi Linux m1n1 hypervisor.
This repository is a research snapshot, not a macOS boot solution. It contains host tooling, tests, two pinned m1n1 patch series, and concise technical notes. It does not contain Apple firmware, kernel collections, device trees, raw traces, credentials, or a prebuilt boot image.
| You want to… | Read |
|---|---|
| Understand the project and terminology | Overview |
| See what works and what remains open | Current status and evidence |
| Explore without a physical target | Host test guide |
| Find a script or understand code organization | Script map · Maintenance review |
| Trace a research finding | Complete documentation index |
| Reproduce the source environment | Setup guide |
| Make a contribution | Contributing |
Attempt 119 completed the bounded Phase 5.3 objective on an M3/J613: one kernel-driven allocation and ownership-transfer chain was tied to a live selector-3 L3 table installation and selector-2 leaf PTE insertion. The exact 16 KiB table changed only at the independently computed slot, both services returned status zero, the guest returned cleanly, and the proxy remained alive.
A macOS boot has not been demonstrated. This is one bounded dynamic Stage-1 mutation chain, not general SPTM compatibility. Phase 5.4 AIC initialization is the next frontier. STATUS.md distinguishes the verified scope from open work and links the leaf-binding evidence.
Hardware findings are documented here, but raw captures and proprietary inputs are retained outside Git. A fresh clone can run synthetic host checks; it cannot independently replay every hardware finding. Read the evidence model when assessing claims.
The latest accelerator validation completed 14 source-gated retype calls, one complete nested GL1 transition sequence, and 20 exact permission windows before a clean watchdog return. It observed no AIC access and does not expand the bounded Phase 5.3 claim.
| Path | Contents |
|---|---|
| scripts/ | Host analysis, evidence tools, and experimental runners |
| tests/ | Synthetic regression coverage and source-dependent checks |
| docs/ | Current orientation plus historical evidence and design notes |
| setup/ | Source checkout and Python environment setup |
| patches/m1n1/ | Two separate patch tracks, each pinned by its own lock file |
| upstream.lock | Loader-validation baseline and patch hashes |
| upstream-vel2.lock | Experimental runtime baseline and patch hashes |
The patches apply to different upstream revisions, not sequentially to one tree. Setup creates separate local checkouts. Building or passing tests does not establish hardware readiness.
Apple payloads are intentionally excluded. setup/restore-payloads.py accepts a
locally supplied, checksum-manifested evidence directory and recreates disposable
extracted payloads under ignored local/payload/. It neither downloads nor
redistributes proprietary inputs.
The lock files identify exact upstream repositories, commits, expected source hashes, and patch hashes. See licensing and provenance before redistribution. Original work is MIT licensed, with a GPL-2.0-or-later exception for the QEMU-derived layout module and preserved upstream notices. See third-party credits and the public-release review.
Maintained by Satya Benson. For questions, collaboration, or research feedback, use my contact page.
This is an independent research project built on Asahi Linux’s m1n1 and Apple Silicon reverse-engineering work. We thank the Asahi Linux contributors for the bootloader, hypervisor, proxy tools, and public hardware documentation that make this work possible. The layout work also builds on jprx/qemu-sptm.
This project is not affiliated with or endorsed by Asahi Linux, Apple, QEMU, or Omarchy. Their names identify upstream work, references, and compatible hardware/software; their logos are not this project’s branding. The source release contains no logo assets. Locally built upstream m1n1 images still include upstream artwork and are not covered by this source-release review.