Skip to content

About

Watch3 SSH Ramdisk Maker: build & load SSH ramdisks for Apple Watch S3 (Watch3,1-4) on watchOS 8.8.1. Patches iBEC/iBSS/kernel, LZSS-compresses kernelcache, signs with IM4M, unlocks NVRAM. Requires pyimg4. Use ramdisk_maker2.sh to build, ramdisk_loader.sh to load.

Resources

Stars

7 stars

Watchers

0 watching

Forks

Repository files navigation

Watch3 SSH Ramdisk Maker

Short Description A tool for building and loading SSH ramdisks for Apple Watch Series 3 (Watch3,1–Watch3,4) on watchOS 8.8.1 / 19U512. It patches iBEC, iBSS, kernelcache, and NVRAM, signs the bootchain with IM4M, compresses kernelcache with LZSS, and enables SSH access via checkm8.

Detailed Description Watch3 SSH Ramdisk Maker is a multi-device ramdisk builder for Apple Watch S3. It extracts the required components from an IPSW (URL, local .zip/.ipsw, or unpacked directory), applies device-specific IV/KEY decryption for iBEC/iBSS, patches the boot chain, prepares a ramdisk payload, and packs signed .img4 files.

Key Features

Devices: Watch3,1, Watch3,2, Watch3,3, Watch3,4

Firmware: watchOS 8.8.1 / build 19U512

iBEC/iBSS patching: Image4 validator bypass, fail-path patches, NVRAM unlock, kernelcache guards

Kernel patching: AMFI, CodeSigning, PMAP, debugger, trust cache patches

Kernelcache compression: LZSS/LZFSE via pyimg4 (required to avoid iBEC rejecting a ~32 MB payload)

Ramdisk assembly: HFS+ grow, payload extraction, mount.sh, SSH autostart

TrustCache: appends executables from the SSH payload

Signing: all .img4 components signed with manifest.im4m

NVRAM unlock: enables setenv / saveenv

DeviceTree: original, no perl patch

Decryption Keys (iBEC / iBSS) IV and KEY values for decrypting iBEC and iBSS are not bundled with this tool. They must be obtained from The Apple Wiki.

Find your device and build on the wiki:

Example: Keys:JupiterUpdate 19U512 (Watch3,3) https://theapplewiki.com/wiki/Keys:JupiterUpdate_19U512_(Watch3,3)

Browse all available key pages:

Category: All Key Pages https://theapplewiki.com/index.php?title=Category:All_Key_Pages&pageuntil=ArcherHomePodSeed+18J6370e+%2528AudioAccessory1%252C1%2529#mw-pages

Copy the IV and KEY values for iBEC.n121s.RELEASE.im4p and iBSS.n121s.RELEASE.im4p into the script's device tables (get_ibec_iv, get_ibec_key, get_ibss_iv, get_ibss_key).

Requirements

macOS or Linux

Python 3.8+

pyimg4 installed: pip3 install pyimg4

Required binaries in bin//: pzb, img4tool, gtar, trustcache, hfsplus

Optional: img4 at /usr/local/bin/img4

resources/manifests/manifest.im4m for signing

resources/ssh.tar for the SSH payload

Build Example

bash ./ramdisk_maker2.sh -d Watch3,3
-u "/Users/rustam/Downloads/b319c5f804bb34226cfdbb26badc4dd2fc5548ae/"
--ibec-level 4 --ibss-level 4
--safe-validator --unlock-nvram --kernelcache-fix
--kernel patched -k This command:

targets Watch3,3

uses an unpacked IPSW directory

patches iBEC/iBSS at level 4

applies safe validator bypass

unlocks NVRAM

applies kernelcache fixes

patches the kernel

keeps the work/ directory for debugging

Output After a successful build:

text SSH-Ramdisk-Watch3,3/bootchain/ ├── iBEC.img4 ├── iBSS.img4 ├── kernelcache.img4 ├── devicetree.img4 ├── ramdisk.img4 ├── trustcache.img4 ├── sep-firmware.img4 ├── AOP.img4 └── chain.info Load Example

bash ./ramdisk_loader.sh -d Watch3,3 This sends the patched bootchain to the device via checkm8/irecovery and boots the SSH ramdisk.

Notes

Ensure ramdisk_loader.sh is present in the repository.

Do not use --no-kernel-lzss unless debugging; without compression iBEC may reject the kernelcache.

Use --scan-nvram and --scan-cmd-table for diagnostics.

Use --list-patches to view available patch levels and options.

IV/KEY values must be sourced from The Apple Wiki and inserted into the script before building for a specific device.

Disclaimer This project is intended for educational purposes and for restoring/modifying your own device. Use it only on hardware you own. The authors are not responsible for bricked devices, data loss, or warranty violations.

About

Watch3 SSH Ramdisk Maker: build & load SSH ramdisks for Apple Watch S3 (Watch3,1-4) on watchOS 8.8.1. Patches iBEC/iBSS/kernel, LZSS-compresses kernelcache, signs with IM4M, unlocks NVRAM. Requires pyimg4. Use ramdisk_maker2.sh to build, ramdisk_loader.sh to load.

Resources

Stars

7 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages