vphone‑cli Firmware Variants Explained: All 5 Options for iOS Virtualization
vphone‑cli supports five firmware variants—less, regular, dev, jb, and exp—that control boot‑chain patches and custom firmware installation phases via the --variant or -V flag.
Choosing the right firmware variant is essential when creating iOS virtual machines with vphone‑cli. Each variant applies a specific number of binary patches to the boot chain and runs a corresponding number of custom firmware (CFW) installation phases, ranging from minimal security‑preserving configurations to full jailbreak environments with research‑grade anti‑detection patches.
What Are vphone‑cli Firmware Variants?
Firmware variants in vphone‑cli are predefined patch profiles that determine how aggressively the tool modifies the original iOS firmware. The variant system lives in the repository's scripts/ directory and is documented in README.md#L90‑L99.
When you specify a variant, vphone‑cli:
- Selects the appropriate patch set from
scripts/patchers/ - Applies boot‑chain patches during the
fw patchstep - Executes the matching CFW install phases via
scripts/cfw_install_*.sh
Complete List of vphone‑cli Firmware Variants
| Variant | Boot‑Chain Patches | CFW Phases | Purpose |
|---|---|---|---|
less |
4 patches | 2 phases | Patch‑less — preserves all original iOS security mitigations |
regular |
42 patches | 10 phases | Bypasses AMFI, SSV, Img4, and TXM restrictions |
dev |
53 patches | 12 phases | Adds TXM entitlement and debug‑mode bypass |
jb |
113 patches | 14 phases | Full jailbreak with Sileo and TrollStore installation |
exp |
141 patches | 18 phases | Experimental research patches that defeat VM‑detection |
The patch counts and phase mappings originate from [research/0_binary_patch_comparison.md](https://github.com/Lakr233/vphone-cli/blob/main/research/0_binary_patch_comparison.md), which provides a component‑by‑component breakdown of what each variant modifies.
How to Select a Firmware Variant
Use the --variant or -V flag with vm create to choose your firmware variant at VM creation time:
# Minimal patches, maximum security (recommended for testing)
vphone-cli vm create myphone -V less
# Standard development environment
vphone-cli vm create myphone -V regular
# Full jailbreak with package manager
vphone-cli vm create myphone -V jb
# Experimental anti‑VM research configuration
vphone-cli vm create myphone -V exp
The variant selection propagates through the entire VM lifecycle. The VPhoneVirtualMachine Swift implementation passes this value to subsequent commands.
Manual Firmware Patching by Variant
You can also apply variants directly during the firmware patch step using vphone-cli fw patch:
# Apply development variant patches manually
vphone-cli fw patch myphone --variant dev
This command invokes the patcher scripts in scripts/patchers/ with the specified variant profile. The implementation details reside in [scripts/fw_patch.sh](https://github.com/Lakr233/vphone-cli/blob/main/scripts/fw_patch.sh).
Custom Firmware Installation Phases
After patching, the CFW installer runs variant‑specific phases. Each variant has a dedicated install script that executes the correct number of phases:
# Install CFW for the regular variant (10 phases)
vphone-cli cfw install myphone --variant regular
The jailbreak variant uses [scripts/cfw_install_jb.sh](https://github.com/Lakr233/vphone-cli/blob/main/scripts/cfw_install_jb.sh), which handles all 14 installation phases including Sileo and TrollStore setup on first boot.
Choosing the Right Variant
less — Use when you need authentic iOS behavior with security mitigations intact. Only 4 patches applied.
regular — Balance between functionality and modification. Bypasses core signature checks with 42 patches.
dev — Extended debugging capabilities. The 53 patches include TXM entitlement bypass for advanced development.
jb — Full jailbreak environment. 113 patches install complete userland modifications with package management.
exp — Research and anti‑detection work. 141 patches include experimental modifications that interfere with VM detection mechanisms.
Summary
- vphone‑cli provides five firmware variants:
less,regular,dev,jb, andexp - Variants control boot‑chain patch count (4 to 141 patches) and CFW installation phases (2 to 18 phases)
- Select variants with
--variantor-Vinvm create,fw patch, andcfw installcommands - Variant definitions live in
README.md, patch details inresearch/0_binary_patch_comparison.md, and install logic inscripts/cfw_install_*.sh
Frequently Asked Questions
How do I check which firmware variant my VM is using?
vphone‑cli stores the variant selection in the VM configuration. Check the original creation command or re‑run vphone-cli vm create with the -V flag to verify. The variant propagates automatically through fw patch and cfw install operations.
Can I change the firmware variant after VM creation?
No—variants must be selected at creation time. The boot‑chain patches are applied during initial firmware processing, and CFW phases run during first boot. To use a different variant, create a new VM with vphone-cli vm create specifying your preferred -V option.
What is the difference between jb and exp variants?
The jb variant applies 113 patches for a standard jailbreak with Sileo and TrollStore. The exp variant adds 28 additional research patches (141 total) targeting VM‑detection mechanisms. Use exp only for specific anti‑detection research, as these patches may cause instability.
Which variant preserves original iOS security?
The less variant applies only 4 patches across 2 CFW phases, retaining all original AMFI, SSV, Img4, and TXM security mitigations. This is the closest to stock iOS behavior available in vphone‑cli.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →