# Common Use Cases for vphone-cli: Automating Virtual iPhone Workflows

> Automate virtual iPhone workflows with vphone-cli. Discover common use cases including VM provisioning, custom firmware, iOS testing, and jailbreak research using Virtualization.framework.

- Repository: [Lakr/vphone-cli](https://github.com/Lakr233/vphone-cli)
- Tags: tutorial
- Published: 2026-09-11

---

**vphone-cli is a Swift-based command-line tool that automates the full lifecycle of virtual iPhones on macOS, enabling one-click VM provisioning, custom firmware development, automated iOS testing, and jailbreak research through Apple’s Virtualization.framework.**

vphone-cli provides a comprehensive command-line interface for managing virtual iOS devices using Apple’s Virtualization.framework. As an open-source project hosted at `Lakr233/vphone-cli`, it bridges low-level VM management with high-level automation workflows. Understanding these common use cases for vphone-cli will help developers and researchers leverage its modular architecture for tasks ranging from CI/CD integration to security analysis.

## One-Click VM Provisioning with vphone-cli

The primary use case for vphone-cli is rapid deployment of pre-configured virtual iPhone environments. The tool orchestrates the entire pipeline from IPSW download to first boot.

### Automated Pipeline Execution

In [`sources/vphone-cli/main.swift`](https://github.com/Lakr233/vphone-cli/blob/main/sources/vphone-cli/main.swift), the CLI parses arguments and dispatches to [`VPhoneVMCreateCLI.swift`](https://github.com/Lakr233/vphone-cli/blob/main/VPhoneVMCreateCLI.swift), which implements the `vm create` command. This single command executes the full lifecycle: downloading IPSWs, merging iPhone and CloudOS images, applying patches, performing a DFU restore, and installing custom firmware (CFW).

```bash
vphone-cli vm create myPhone -V jb
vphone-cli vm launch myPhone

```

The `-V jb` flag selects the jailbreak patch variant, defined in [`FirmwarePatcher/Pipeline/FirmwarePipeline.swift`](https://github.com/Lakr233/vphone-cli/blob/main/FirmwarePatcher/Pipeline/FirmwarePipeline.swift). This pipeline coordinates with [`VPhoneVirtualMachine.swift`](https://github.com/Lakr233/vphone-cli/blob/main/VPhoneVirtualMachine.swift), which configures the hardware model via [`VPhoneHardwareModel.swift`](https://github.com/Lakr233/vphone-cli/blob/main/VPhoneHardwareModel.swift) and manages the underlying `VZVirtualMachine` lifecycle.

### Headless and GUI Boot Modes

vphone-cli supports both interactive GUI sessions and headless DFU mode for automated workflows. The [`VPhoneVMLaunchCLI.swift`](https://github.com/Lakr233/vphone-cli/blob/main/VPhoneVMLaunchCLI.swift) wrapper handles launch parameters, while [`VPhoneVirtualMachine.swift`](https://github.com/Lakr233/vphone-cli/blob/main/VPhoneVirtualMachine.swift) manages VM state transitions. DFU mode is essential for firmware restoration workflows, allowing scripts to execute restores without graphical intervention.

## Custom Firmware Development and Patching Pipelines

Developers iterating on iOS modifications use vphone-cli to run discrete pipeline stages, enabling precise control over the firmware build process without executing the full automated flow.

### FirmwarePipeline Architecture

The `FirmwarePatcher` package implements a stage-based architecture in [`FirmwarePatcher/Pipeline/FirmwarePipeline.swift`](https://github.com/Lakr233/vphone-cli/blob/main/FirmwarePatcher/Pipeline/FirmwarePipeline.swift). Users can execute individual commands to iterate on patches or test specific firmware components:

```bash
vphone-cli vm new myPhone
vphone-cli fw prepare myPhone --iphone-version 26.1
vphone-cli fw patch myPhone --variant dev
vphone-cli vm launch myPhone --dfu &
vphone-cli restore myPhone
vphone-cli cfw install myPhone --variant dev
vphone-cli vm launch myPhone

```

### Patch Variant Selection

The tool supports multiple patch variants: `less`, `regular`, `dev`, `jb`, and `exp`. These variants apply different levels of modification to the base IPSW, ranging from minimal debugging hooks to full jailbreak environments with Sileo and TrollStore. This granularity allows security researchers to test specific mitigations without rebuilding entire images from scratch.

## iOS App Testing and CI/CD Automation

vphone-cli enables automated iOS application testing in continuous integration environments by exposing headless control interfaces and screenshot capabilities via the host-control socket.

### Headless Testing via Host-Control Socket

After DFU restoration and CFW installation (handled by `scripts/cfw_install*.sh`), the running VM exposes a vsock interface at `<bundle>/vphone.sock`. [`VPhoneControl.swift`](https://github.com/Lakr233/vphone-cli/blob/main/VPhoneControl.swift) implements the host-side client for this socket, allowing CI scripts to install IPAs and capture screenshots without GUI dependencies:

```bash
vphone-cli install myPhone MyApp.ipa
curl -X POST -d '{"action":"screenshot"}' \
     unix://$(vphone-cli info myPhone --socket-path)

```

### Automated UI Interaction

The host socket supports touch events, swipes, clipboard operations, and hardware key simulation. These primitives enable end-to-end testing frameworks to execute test suites against the virtual device and capture visual regression data programmatically.

## Jailbreak Research and Security Mitigation Analysis

Security researchers leverage vphone-cli to analyze iOS security mechanisms in controlled, reproducible virtual environments with full kernel access.

### Jailbreak Environment Provisioning

The `jb` and `exp` patch variants provide pre-configured jailbreak environments with anti-VM detection patches. When combined with the automated pipeline, researchers can spawn isolated instances with specific kernel patches. The [`VPhoneMenuController.swift`](https://github.com/Lakr233/vphone-cli/blob/main/VPhoneMenuController.swift) file implements menu-bar extensions found in the GUI for triggering hardware keys, location changes, and power cycles—essential for testing exploit reliability.

### Kernel Debugging Workflows

In GUI mode (`vphone-cli vm launch` without `--dfu`), developers attach debuggers to the virtual device and inspect kernel logs. The separation between host-side control logic in [`VPhoneControl.swift`](https://github.com/Lakr233/vphone-cli/blob/main/VPhoneControl.swift) and the guest-side daemon (`vphoned`) ensures that debugging tools remain responsive even during kernel panics.

## File Transfer and Interactive Guest Management

Beyond automation, vphone-cli provides interactive tooling for file system operations and real-time device state management through both GUI and CLI interfaces.

### File Browser UI and CLI Commands

The SwiftUI-based file browser, implemented in [`VPhoneFileBrowserView.swift`](https://github.com/Lakr233/vphone-cli/blob/main/VPhoneFileBrowserView.swift) and [`VPhoneFileBrowserModel.swift`](https://github.com/Lakr233/vphone-cli/blob/main/VPhoneFileBrowserModel.swift), allows drag-and-drop file transfers. Corresponding CLI commands enable scriptable file operations using the vsock transport:

```bash
vphone-cli file push myPhone local.txt /var/mobile/
vphone-cli file pull myPhone /var/log/syslog.log ./

```

These operations utilize the high-performance vsock communication channel established by [`VPhoneControl.swift`](https://github.com/Lakr233/vphone-cli/blob/main/VPhoneControl.swift), eliminating network stack dependencies.

## AI-Driven Automation and External Integration

The exposed socket API and structured command interface make vphone-cli suitable for AI-driven testing frameworks and third-party automation tools.

### Integration with External AI Frameworks

Projects such as `vphone-mcp` wrap the `vphone.sock` interface to expose VM control to AI agents. The socket actions—screenshot, touch, clipboard, and application lifecycle events—provide the sensory input and actuator output required for autonomous testing systems. This architecture decouples AI decision-making from the virtualization layer, allowing vphone-cli to focus on stable VM management while external systems handle complex test logic.

## Summary

- **vphone-cli** automates the complete virtual iPhone lifecycle, from IPSW download to custom firmware installation, through commands implemented in [`VPhoneVMCreateCLI.swift`](https://github.com/Lakr233/vphone-cli/blob/main/VPhoneVMCreateCLI.swift) and [`VPhoneVirtualMachine.swift`](https://github.com/Lakr233/vphone-cli/blob/main/VPhoneVirtualMachine.swift).
- The **FirmwarePatcher** pipeline supports iterative development with discrete stages for preparation, patching with variants (`dev`, `jb`, `exp`), and restoration via [`FirmwarePatcher/Pipeline/FirmwarePipeline.swift`](https://github.com/Lakr233/vphone-cli/blob/main/FirmwarePatcher/Pipeline/FirmwarePipeline.swift).
- **CI/CD integration** relies on headless DFU mode and the vsock-based host-control socket ([`VPhoneControl.swift`](https://github.com/Lakr233/vphone-cli/blob/main/VPhoneControl.swift)) for screenshot capture, IPA installation, and automated UI interaction.
- **Jailbreak research** benefits from pre-configured patch variants and robust debugging capabilities via the [`VPhoneMenuController.swift`](https://github.com/Lakr233/vphone-cli/blob/main/VPhoneMenuController.swift) menu system and GUI launch mode.
- **File operations** and guest management are available through both interactive SwiftUI components ([`VPhoneFileBrowserView.swift`](https://github.com/Lakr233/vphone-cli/blob/main/VPhoneFileBrowserView.swift)) and scriptable CLI commands using the vsock transport.

## Frequently Asked Questions

### What hardware requirements are needed to run vphone-cli?

vphone-cli requires a Mac with Apple Silicon (M1 or later) and macOS Sonoma or later, as it depends on Apple's Virtualization.framework. The tool allocates significant storage for IPSW images and VM bundles, so ensure at least 50GB of free space for firmware preparation and patching workflows.

### How does vphone-cli differ from standard iOS Simulator testing?

Unlike the iOS Simulator, which runs a modified x86_64/arm64 binary translation layer, vphone-cli virtualizes actual iOS firmware images using Virtualization.framework. This provides a genuine iOS kernel and userland environment, enabling testing of kernel-level features, jailbreak exploits, and hardware-dependent APIs that the Simulator cannot replicate.

### Can vphone-cli be used for automated regression testing in CI pipelines?

Yes. The headless DFU mode and host-control socket (`<bundle>/vphone.sock`) expose screenshot, touch, and installation APIs that integrate with CI systems. By scripting the `vphone-cli install` command and socket-based interactions, teams can execute automated test suites without manual GUI intervention or physical device labs.

### Where are the patch variants defined in the source code?

Patch variants (`less`, `regular`, `dev`, `jb`, `exp`) are processed in [`FirmwarePatcher/Pipeline/FirmwarePipeline.swift`](https://github.com/Lakr233/vphone-cli/blob/main/FirmwarePatcher/Pipeline/FirmwarePipeline.swift), which orchestrates the merge and patch logic. The CLI interface for selecting variants is handled in [`main.swift`](https://github.com/Lakr233/vphone-cli/blob/main/main.swift) and the VM creation wrappers, while the actual patch payloads reside within the broader `FirmwarePatcher` package directory.