Skip to content
hideouts

Type to search every app and research write-up.

macOS9 min readPublished Updated

Inside Apple’s Software Update RAMDisk

T2 DFU restore, the ramrod pipeline, SSV sealing, and firmware Option ROMs.

Forensic and architectural study of the StarSecurityRome21G115 RAMDisk from macOS Monterey 12.6 (x86_64): boot and init, the ramrod restore engine, APFS Sealed System Volume Merkle sealing, Image4 and FDR trust, and controller firmware.

On this page

Key findings

  1. The image is Apple’s restore RAMDisk for macOS Monterey 12.6 (build 21G115) on Intel Macs with the T2 chip, and it runs entirely from memory.
  2. Apple’s ramrod restore engine builds and seals the system volume, and holds entitlements for direct access to the NVMe and SMC controllers.
  3. PurpleReverseProxy listens on localhost ports 1081, 1082, and 1084, consistent with talking to a host Mac over USB.
  4. It embeds firmware for SSD controllers, USB-C power controllers, DisplayPort bridges, and the Secure Enclave, consistent with re-flashing a Mac without a network connection.
  5. The image contains no user folders, credentials, or logs, and every executable is signed by Apple’s code-signing authority.

Summary written for this site. Each point is covered, with its evidence, in the write-up below.


In Apple's unified device recovery model, a Software Update RAMDisk (SURamDisk) is an isolated, memory-resident operating system loaded by iBoot / BridgeOS during Device Firmware Upgrade (DFU) restores, factory refurbishing, and major macOS software updates.

The RAMDisk solves a fundamental chicken-and-egg problem:

  • How does a machine flash corrupt or uninitialized onboard NAND storage controllers when it cannot safely boot from them?
  • How does an updater establish an authenticated data bridge to a host Mac without standard network interfaces?

The StarSecurityRome21G115 environment operates entirely in physical RAM using AppleDiskImagesRAMBackingStore. It bundles an optimized Darwin kernel, hardware updaters for solid-state storage and power controllers, and Apple's unified ramrod restore engine to build and seal the final operating system image.


The artifact provides a complete window into Apple's bare-metal provisioning toolchain:

  • Target Environment: macOS 12.6 Monterey (Build 21G115) on x86_64 (Intel Macs with Apple T2 Security Chip).
  • Isolation Architecture: Single-stage interactive /sbin/launchd environment without standard multi-user services (/Users, /Applications, /Library).
  • Restore Engine: Orchestrated by /usr/libexec/ramrod/ramrod running the ramrod-macos-patchd-plugin.ramrod dynamic plugin.
  • Kernel & Driver Layer: Monolithic 65 MB BootKernelExtensions.kc prelinking 252 kernel extensions covering NVMe, Thunderbolt, SMC, SEP, and crypto accelerators.
  • Firmware Repository: Built-in offline Option ROMs for Apple custom SSD controllers (S4E, t302), USB-C Type-C High Performance Managers (USB-C_HPM), MegaChips DisplayPort bridges (MCDP29XX), and Secure Enclave (SLAM).
  • Cryptographic Sealing: Complete APFS maintenance suite (apfs_sealvolume, apfs_checkseal, slurpAPFSMeta) for Merkle-tree snapshot generation.

Direct Observation vs. Interpretation

Link to section: Direct Observation vs. Interpretation
TypeDirect FindingTechnical Interpretation
Direct observationSystemVersion.plist identifies ProductBuildVersion: 21G115, ReleaseType: Restore, and BridgeOSActivationSupported: YES.Official Apple DFU recovery image built for macOS Monterey 12.6 and BridgeOS 15.7.
Direct observationPurpleReverseProxy binds localhost TCP sockets on ports 1081 (socks), 1082 (ctrl), and 1084 (notify).Employs loopback IPC bridged across USB muxing (usbmuxd) to communicate with Apple Configurator.
Direct observationramrod links patchd_macos_seal_system_volume and holds direct IOKit user-client entitlements (AppleNVMeUpdateUC, AppleSMCClient).Bypasses standard OS file abstraction to execute raw block operations and Merkle-tree root hash generation.
Direct observation/usr/standalone/firmware/ embeds raw binary Option ROMs for Samsung, Toshiba, SanDisk, and SK Hynix NAND flash arrays.Self-contained recovery capability to re-flash bricked SSD controller microcode without an active network connection.
Direct observationImage includes zero user directories, credentials, or transient logs.Pure factory master template generated in a deterministic clean-room build environment.

DiagramDiagram

Forensic & Cryptographic Identification

Link to section: Forensic & Cryptographic Identification
text
Image Name:           StarSecurityRome21G115.x86_64SURamDisk.dmg
Internal Label:       StarSecurityRome21G115.x86_64SURamDisk
Release Type:         Restore
Product Version:      macOS 12.6 Monterey (Build 21G115)
BridgeOS Base:        15.7 (BridgeOSActivationSupported: YES)
Target Architecture:  x86_64 (Mach-O 64-bit thin)
Image Format:         Apple UDIF read-only compressed zlib (UDZO)
Partition Scheme:     GUID Partition Table (GPT) / APFS Container
APFS Partition UUID:  E2237814-AB68-4973-A672-41C1631AB21D
APFS Container UUID:  7C3457EF-0000-11AA-AA11-00306543ECAC
MetricValue
SHA-256 Checksumd5e54a6d9d466db0f76818d29b0a7fa5d729c506fca62e3b5c5d6482ee68166d
MD5 Checksum0fe42a8b6f6fc23991253fb54dc16b01
CRC32 Checksum$11587BAC
Compressed Size159,780,108 bytes (~152.4 MB)
Uncompressed Size421,169,152 bytes (~401.7 MB)
Compression Ratio41.76%
Sector Count822,596 (512 bytes per sector)

Located in /System/Library/LaunchDaemons/, the runtime services operate under single-stage interactive rules:

  1. /sbin/launchd: Executes as PID 1 directly from the RAM backing store.
  2. com.apple.ramrod.plist: Spawns /usr/libexec/ramrod/ramrod with StandardOutPath and StandardErrorPath directed to /dev/console.
  3. com.apple.diskimagesiod.ram.plist: Runs /usr/libexec/diskimagesiod --ram under privilege-separated user _diskimagesiod (UID 271).
  4. com.apple.syslogd.plist: Provides system logging daemon with ASL disabled in favor of Darwin unified logging.

Raw Evidence: PurpleReverseProxy Socket Configuration

Link to section: Raw Evidence: PurpleReverseProxy Socket Configuration

The host-target communication bridge is defined in /System/Library/LaunchDaemons/com.apple.PurpleReverseProxy.ramdisk.plist.

Figure 1 PurpleReverseProxy Sockets
  • Port 1081 (socks): Binary data stream for incoming APFS disk images.
  • Port 1082 (ctrl): Transactional command and control channel.
  • Port 1084 (notify): Real-time progress reporting and event notifications.

ramrod (/usr/libexec/ramrod/ramrod) is a 2.0 MB Mach-O binary compiled with Apple LLVM (SDK macOS 12.6, deployment target macOS 11.0).

Terminal
--restore            # Standard full OS volume restoration
--restore+art        # Restore OS and flash factory ART sensor calibration records
--erase              # Complete disk erasure and partition reconstruction
--preflight          # Pre-restoration integrity and hardware validation
--query              # Interrogate device state and hardware revisions
--reset              # Hardware controller soft reset
--validate           # Cryptographic hash and manifest verification
--sendtunabletables  # Dispatch hardware calibration tables to controllers
--stashExpectedFWVersion # Write expected firmware versions to NVRAM/Preboot

Dynamic routines provided by /usr/libexec/ramrod/plugins/ramrod-macos-patchd-plugin.ramrod:

  • patchd_macos_seal_system_volume
  • patchd_macos_fixup_preboot
  • patchd_macos_check_efi_features
  • patchd_macos_set_bless_to_fail_back
  • patchd_macos_mount_all_filesystems_with_error

Raw Evidence: ramrod Pipeline Architecture

Link to section: Raw Evidence: ramrod Pipeline Architecture
Figure 2 ramrod Pipeline Architecture

ramrod possesses extensive kernel and hardware entitlements:

XML
<!-- Storage Keys & Encryption -->
<key>com.apple.keystore.filevault</key><true/>
<key>com.apple.keystore.fdr-access</key><true/>
<key>com.apple.keystore.sik.access</key><true/>
<key>com.apple.private.security.bootpolicy</key><true/>
<key>com.apple.private.applesepmanager.allow</key><true/>

<!-- APFS Snapshot & SSV Capabilities -->
<key>com.apple.private.apfs.create-sealed-snapshot</key><true/>
<key>com.apple.private.apfs.revert-to-snapshot</key><true/>
<key>com.apple.private.apfs.set-firmlink</key><true/>

<!-- Direct IOKit UserClients -->
<key>com.apple.security.iokit-user-client-class</key>
<array>
    <string>AppleNVMePassThroughUC</string>
    <string>AppleNVMeUpdateUC</string>
    <string>AppleNVMeSMARTUserClient</string>
    <string>AppleImage3NORAccessUserClient</string>
    <string>AppleEmbeddedSimpleSPINORFlasherDriverUC</string>
    <string>AppleHPMUserClient</string>
    <string>AppleSMCClient</string>
    <string>IOThunderboltFamilyUserClient</string>
    <string>IOAESAcceleratorUserClient</string>
</array>

(Full entitlements catalog in docs/entitlements.md)


Kernel Collection (BootKernelExtensions.kc)

Link to section: Kernel Collection (BootKernelExtensions.kc)

The image relies on /System/Library/KernelCollections/BootKernelExtensions.kc (65 MB x86_64 Mach-O prelinked kernel collection) containing 252 kernel extensions:

text
=== Core Storage & Disk Extensions ===
• com.apple.filesystems.apfs (v1934.141.2)
• com.apple.filesystems.hfs.kext (v583.100.10)
• com.apple.iokit.IOAHCIFamily (v333.140.2)
• com.apple.iokit.IOATAFamily (v2.5.3)
• com.apple.iokit.IOUSBMassStorageDriver (v210.120.3)
• com.apple.driver.DiskImages.RAMBackingStore (v493.0.0)

=== Security, SEP & T2 Coprocessor ===
• com.apple.driver.AppleKeyStore (v2)
• com.apple.driver.AppleSEPManager (v1.0.1)
• com.apple.driver.AppleCredentialManager (v1.0)
• com.apple.security.AppleImage4 (v4.2.0)
• com.apple.kext.CoreTrust (v1)

=== SMC & Power Management ===
• com.apple.driver.AppleSMC (v3.1.9)
• com.apple.driver.AppleSMCRTC (v1.0)
• com.apple.driver.AppleEffaceableStorage (v1.0)
• com.apple.driver.AppleEffaceableNOR (v1.0)

=== Thunderbolt & Bus Interconnect ===
• com.apple.iokit.IOThunderboltFamily (v9.3.3)
• com.apple.driver.AppleThunderboltNHI (v7.2.81)
• com.apple.driver.AppleThunderboltPCIAdapters (v4.0.1)
• com.apple.driver.AppleThunderboltUTDM (v3.0.7)

(Complete 252-kext manifest in docs/kext_inventory.md)


Hardware Firmware & Option ROM (OFW) Catalog

Link to section: Hardware Firmware & Option ROM (OFW) Catalog

Located in /usr/standalone/firmware/, the RAMDisk embeds binary microcode images for local offline flashing.

Raw Evidence: Firmware Flashing Matrix

Link to section: Raw Evidence: Firmware Flashing Matrix
Figure 3 Firmware Flashing Matrix

Apple S4E Controller Microcode (Gen 1–4)

Link to section: Apple S4E Controller Microcode (Gen 1–4)
  • Samsung: s4e_ofw_samsung_mlc_3d_g2_2p_256.bin, s4e_ofw_samsung_mlc_3d_g3_2p_256.bin, s4e_ofw_samsung_itlc_3d_g4_2p_256.bin
  • SanDisk: s4e_ofw_sandisk_mlc_2d_1z_4p_128.bin, s4e_ofw_sandisk_mlc_3d_g3_2p_170.bin, s4e_ofw_sandisk_tlc_3d_g3_2p_256.bin, s4e_ofw_sandisk_tlc_3d_g4_2p_512.bin
  • Toshiba / Kioxia: s4e_ofw_toshiba_mlc_3d_g3_2p_170.bin, s4e_ofw_toshiba_tlc_3d_g3_2p_256.bin, s4e_ofw_toshiba_itlc_3d_g4_2p_256.bin
  • SK Hynix: s4e_ofw_hynix_tlc_3d_g3_4p_512.bin, s4e_ofw_hynix_itlc_3d_g3_4p_256.bin, s4e_ofw_hynix_itlc_3d_g4_4p_512.bin

Apple t302 Controller Microcode (Gen 5)

Link to section: Apple t302 Controller Microcode (Gen 5)
  • bfh_ofw.t302.ofw.sandisk_tlc_3d_g5_2p_512gb.bin / 1024gb.bin
  • bfh_ofw.t302.ofw.toshiba_tlc_3d_g5_2p_512gb.bin / 1024gb.bin
  • bfh_ofw.t302.ofw.hynix_tlc_3d_g4_4p_512gb.bin / 1024gb.bin
  • Mapped dynamically via .pak aliases matching board and chip IDs.

USB-C Power Delivery & High Performance Managers

Link to section: USB-C Power Delivery & High Performance Managers
  • USB-C_HPM,30.bin / USB-C_HPM,31.bin
  • USB-C_HPM,33-P01_P-AP.bin / USB-C_HPM,33-P2_P-DEV.bin
  • USB-C_HPM,34-P01_P-AP.bin / USB-C_HPM,34-P5-AP.bin
  • USB-C_HPM,35-P01-AP.bin / USB-C_HPM,35-P45-AP.bin
  • USB-C_HPM,46-P01-AP.bin / USB-C_HPM,55.bin
  • MegaChips DisplayPort Converter (MCDP29XX): app (524 KB), isp (18.5 KB), versions.plist (App v1.136, Driver v1.10).
  • Secure Link Accessory Module (SLAM): SLAM.sefw Secure Enclave firmware image (2.43 MB).

(Detailed package table in docs/firmware_catalog.md)


APFS Sealed System Volume (SSV) Toolchain

Link to section: APFS Sealed System Volume (SSV) Toolchain

Raw Evidence: Merkle-Tree Sealing Sequence

Link to section: Raw Evidence: Merkle-Tree Sealing Sequence
Figure 4 APFS Merkle Sealing

Located in /System/Library/Filesystems/apfs.fs/Contents/Resources/:

  • apfs_sealvolume: Traverses the filesystem tree, computes Merkle SHA-256 digests for all files/directories, and injects the cryptographic seal into the root snapshot superblock.
  • apfs_checkseal: Validates whether the mounted system volume matches its signed seal.
  • apfs_systemsnapshot: Creates and marks the active APFS system boot snapshot.
  • apfs_invert: Performs extent-level inversion during update fallbacks.
  • slurpAPFSMeta: Low-level diagnostic utility to dump APFS superblock and object map records.

USB Composite Emulation Profiles (USBDeviceConfiguration.plist)

Link to section: USB Composite Emulation Profiles (USBDeviceConfiguration.plist)

Located in /System/Library/AppleUSBDevice/USBDeviceConfiguration.plist:

Raw Evidence: Composite USB Descriptors

Link to section: Raw Evidence: Composite USB Descriptors
Figure 5 Composite USB Descriptors
Profile NamePresented USB InterfacesOperational Purpose
standardRestoreAppleUSBMuxBase DFU restore & Apple Configurator link
standardMuxEthernetAppleUSBMux, AppleUSBEthernetHigh-throughput virtual network imaging
stdMuxIDAAppleUSBMux, USBAudio2Control, IDAMInterfaceInter-Device Audio (IDA) pass-through
standardMuxPTPEthernetValeriaAppleUSBMux, AppleUSBEthernet, ValeriaStudio Display camera/video calibration
usbiotestAppleUSBMux, AppleUSBTestControl/Bulk/InterruptHardware USB bus electrical testing

(Detailed interface breakdown in docs/usb_device_modes.md)


Feature Flags & Kernel Domain Toggles

Link to section: Feature Flags & Kernel Domain Toggles

Located in /System/Library/FeatureFlags/Domain/, over 85 property list domain manifests govern runtime feature activation:

  • Networking & Transport: CFNetwork.plist (QuicConnectionMigration, Http3Fallback), APS.plist (ShorterConnectDelayV1).
  • Media & Audio Routing: AudioHAL.plist (Host_ASP_OoP), AVConference.plist (facetime_camera_sifr).
  • Security & Biometrics: LocalAuthentication.plist (BiometricFailover), Security.plist (StrictTrustPolicy), XProtect.plist.

(Full domain manifest in docs/feature_flags.md)


Hardware Discovery & Private Frameworks

Link to section: Hardware Discovery & Private Frameworks
  • ZhuGeSupport.framework (ZhuGe-60.120.2): Apple's internal hardware querying framework (ZhuGeCopyValueWithError). Interrogates MLB serials, chip revisions, and NAND geometry before flashing.
  • MFAAuthentication.framework: Hardware accessory and coprocessor cryptographic handshake framework.
  • RemoteServiceDiscovery.framework & RemoteXPC.framework: Lightweight host-to-device remote procedure call subsystem.

Security, Image4 & FDR Trust Architecture

Link to section: Security, Image4 & FDR Trust Architecture

During a DFU restore, the RAMDisk validates every firmware payload and system image against Apple's Image4 (IMG4) container specifications and Factory Data Recovery (FDR) manifests:

Raw Evidence: Image4 & FDR Trust Chain

Link to section: Raw Evidence: Image4 & FDR Trust Chain
Figure 6 Image4 Trust Chain
  • libimg4.dylib: Evaluates TSS tickets (IM4M) bound to the device's unique ECID and ephemeral T2 Nonce.
  • libauthinstall.dylib: Manages personalization handshakes (AMAuthInstallApEnablePersonalization).
  • System/Library/FDR/fdrtrustobject: Local cryptographic root anchor for restoring factory calibration (ART) records.

(Full security model in docs/security_trust_model.md)


Unlike standard macOS installations that rely on a multi-gigabyte monolithic dyld_shared_cache_x86_64, the RAMDisk operates with a stripped dynamic linker:

  • Direct .dylib Loading: /usr/lib/dyld resolves modular, unbundled shared libraries (154 individual .dylib files) directly in RAM.
  • Trampolines: /usr/lib/libobjc-trampolines.dylib provides fast runtime method dispatch (objc_msgSend) without cache dependencies.
  • Rosetta 2 Emulation Layer: Includes /usr/lib/libRosetta.dylib and /usr/lib/liboah.dylib for cross-architecture translation execution.

(Full runtime analysis in docs/dyld_and_runtime.md)


Before initiating disk imaging, the RAMDisk executes /usr/libexec/cc_fips_test to validate Known Answer Tests (KAT) for /usr/lib/system/libcorecrypto.dylib:

  • Symmetric Encryption: AES-CBC, AES-GCM, AES-XTS (APFS encryption).
  • Digest & MAC: SHA-256, SHA-384, SHA-512, HMAC-SHA256.
  • Asymmetric Signatures: RSA PKCS#1 / PSS, ECDSA P-256 / P-384, HMAC-DRBG entropy generation.

(Full cryptographic suite details in docs/fips_cryptography.md)


Terminal
./scripts/verify_image.sh /path/to/StarSecurityRome21G115.x86_64SURamDisk.dmg
Terminal
./scripts/mount_analysis.sh /path/to/StarSecurityRome21G115.x86_64SURamDisk.dmg /tmp/suramdisk

3. Inspect Prelinked Kernel Extensions

Link to section: 3. Inspect Prelinked Kernel Extensions
Terminal
kmutil inspect -a x86_64 -B /tmp/suramdisk/System/Library/KernelCollections/BootKernelExtensions.kc --no-variant-extension
Terminal
codesign -d --entitlements :- /tmp/suramdisk/usr/libexec/ramrod/ramrod
Terminal
hdiutil detach /tmp/suramdisk

text
StarSecurity-SURamDisk/
├── README.md                 # Master forensic & architectural research paper
├── LICENSE                   # MIT License
├── SOURCES.md                # Attribution & source provenance
├── evidence/                 # Vector SVG architectural diagrams & raw evidence panels
│   ├── purplereverseproxy-sockets.svg
│   ├── ramrod-pipeline-architecture.svg
│   ├── firmware-flashing-matrix.svg
│   ├── apfs-merkle-sealing.svg
│   ├── usb-device-configurations.svg
│   └── image4-trust-model.svg
├── docs/                     # In-depth technical specifications
│   ├── entitlements.md       # Binary entitlements for ramrod, diskimagesiod, asr
│   ├── kext_inventory.md     # Full 252 kernel extension manifest
│   ├── firmware_catalog.md   # S4E, t302, USB-C HPM, and MCDP29XX Option ROMs
│   ├── apfs_toolchain.md     # Deep dive into apfs_sealvolume, checkseal, slurpAPFSMeta
│   ├── usb_device_modes.md   # Complete composite USB descriptor catalog
│   ├── feature_flags.md      # 85+ FeatureFlags domain definitions
│   ├── security_trust_model.md # Image4 (IMG4) evaluation and FDR trust anchoring
│   ├── dyld_and_runtime.md   # Modular dynamic loading and trampoline dispatch
│   └── fips_cryptography.md  # CommonCrypto FIPS 140-2 validation suite
└── scripts/                  # Analysis and verification scripts
    ├── verify_image.sh       # Cryptographic hash validation tool
    └── mount_analysis.sh     # Safe read-only mounting script

Security, Privacy & Responsible Research

Link to section: Security, Privacy & Responsible Research
  • Defensive Forensics: This project contains passive reverse-engineering and architectural documentation. It does not provide exploits, DRM circumvention tools, or activation bypasses.
  • Clean-Room Verification: The analyzed RAMDisk image is a factory master artifact containing zero user directories (/Users), personal keys, passwords, or runtime session logs.
  • Authentic Signatures: Every Mach-O executable in the image is digitally signed by the Apple Code Signing Certification Authority anchored to the Apple Root CA.

  • All findings and structures are verifiable through standard macOS command-line utilities (hdiutil, kmutil, codesign, strings, plutil).
  • For complete upstream attribution and licensing boundaries, see SOURCES.md.

The documentation, research findings, and verification scripts in this repository are licensed under the MIT License.
macOS, APFS, BridgeOS, T2, and Apple are registered trademarks of Apple Inc. All proprietary software and firmware identifiers discussed remain the intellectual property of Apple Inc.

More research