Watch3 SSH Ramdisk Maker
Short Description A tool for building and loading SSH ramdisks for Apple Watch Series 3 (Watch3,1–Watch3,4) on watchOS 8.8.1 / 19U512. It patches iBEC, iBSS, kernelcache, and NVRAM, signs the bootchain with IM4M, compresses kernelcache with LZSS, and enables SSH access via checkm8.
Detailed Description Watch3 SSH Ramdisk Maker is a multi-device ramdisk builder for Apple Watch S3. It extracts the required components from an IPSW (URL, local .zip/.ipsw, or unpacked directory), applies device-specific IV/KEY decryption for iBEC/iBSS, patches the boot chain, prepares a ramdisk payload, and packs signed .img4 files.
Key Features
Devices: Watch3,1, Watch3,2, Watch3,3, Watch3,4
Firmware: watchOS 8.8.1 / build 19U512
iBEC/iBSS patching: Image4 validator bypass, fail-path patches, NVRAM unlock, kernelcache guards
Kernel patching: AMFI, CodeSigning, PMAP, debugger, trust cache patches
Kernelcache compression: LZSS/LZFSE via pyimg4 (required to avoid iBEC rejecting a ~32 MB payload)
Ramdisk assembly: HFS+ grow, payload extraction, mount.sh, SSH autostart
TrustCache: appends executables from the SSH payload
Signing: all .img4 components signed with manifest.im4m
NVRAM unlock: enables setenv / saveenv
DeviceTree: original, no perl patch
Decryption Keys (iBEC / iBSS) IV and KEY values for decrypting iBEC and iBSS are not bundled with this tool. They must be obtained from The Apple Wiki.
Find your device and build on the wiki:
Example: Keys:JupiterUpdate 19U512 (Watch3,3) https://theapplewiki.com/wiki/Keys:JupiterUpdate_19U512_(Watch3,3)
Browse all available key pages:
Category: All Key Pages https://theapplewiki.com/index.php?title=Category:All_Key_Pages&pageuntil=ArcherHomePodSeed+18J6370e+%2528AudioAccessory1%252C1%2529#mw-pages
Copy the IV and KEY values for iBEC.n121s.RELEASE.im4p and iBSS.n121s.RELEASE.im4p into the script's device tables (get_ibec_iv, get_ibec_key, get_ibss_iv, get_ibss_key).
Requirements
macOS or Linux
Python 3.8+
pyimg4 installed: pip3 install pyimg4
Required binaries in bin//: pzb, img4tool, gtar, trustcache, hfsplus
Optional: img4 at /usr/local/bin/img4
resources/manifests/manifest.im4m for signing
resources/ssh.tar for the SSH payload
Build Example
bash
./ramdisk_maker2.sh -d Watch3,3
-u "/Users/rustam/Downloads/b319c5f804bb34226cfdbb26badc4dd2fc5548ae/"
--ibec-level 4 --ibss-level 4
--safe-validator --unlock-nvram --kernelcache-fix
--kernel patched -k
This command:
targets Watch3,3
uses an unpacked IPSW directory
patches iBEC/iBSS at level 4
applies safe validator bypass
unlocks NVRAM
applies kernelcache fixes
patches the kernel
keeps the work/ directory for debugging
Output After a successful build:
text SSH-Ramdisk-Watch3,3/bootchain/ ├── iBEC.img4 ├── iBSS.img4 ├── kernelcache.img4 ├── devicetree.img4 ├── ramdisk.img4 ├── trustcache.img4 ├── sep-firmware.img4 ├── AOP.img4 └── chain.info Load Example
bash ./ramdisk_loader.sh -d Watch3,3 This sends the patched bootchain to the device via checkm8/irecovery and boots the SSH ramdisk.
Notes
Ensure ramdisk_loader.sh is present in the repository.
Do not use --no-kernel-lzss unless debugging; without compression iBEC may reject the kernelcache.
Use --scan-nvram and --scan-cmd-table for diagnostics.
Use --list-patches to view available patch levels and options.
IV/KEY values must be sourced from The Apple Wiki and inserted into the script before building for a specific device.
Disclaimer This project is intended for educational purposes and for restoring/modifying your own device. Use it only on hardware you own. The authors are not responsible for bricked devices, data loss, or warranty violations.