Skip to content

AltStore crashes on launch on iOS/ipadOS 26.4 #131

Description

@ytarakji

After updating to iOS / iPadOS 26.4, AltStore crashes on launch.

It seems that they fixed the Windows version of AltServer to overcome this issue:
https://faq.altstore.io/release-notes/altserver#altserver-1.7.4-windows-only

Has anyone else experienced this or found a fix?

Activity

  1. ondrej-simon commented on Jun 14, 2026

    @ondrej-simon

    Confirmed and fixed on iOS 26.5 (iPhone 15 Pro). Posting the full diagnosis + a working fork in case it helps.

    Root cause. App installs but crashes instantly on launch, no crash report. idevicesyslog during launch shows the kernel rejecting the signature:

    kernel  TXM [Error]: CodeSignature: selector: 24 | 0x53 | 0x23 | 9
    SpringBoard(FrontBoard)  [app<…>:-1] Now flagged as pending exit for reason: Bootstrap failed
    

    AMFI accepts the profile (AMFI: profile validated the code signature), but the kernel's TXM rejects the signature ldid produces. iOS 26 enforces several things ldid (vendored ~2022) gets wrong, and I verified each by diffing against a known-good rcodesign signature:

    • DER entitlements emitted as a bare ASN.1 SET instead of [APPLICATION 16] { INTEGER version, [CONTEXT 16] {…} } (and DER booleans as 0x01 instead of 0xFF).
    • A legacy SHA-1-primary CodeDirectory instead of SHA-256-only.
    • Empty designated requirements (app + every framework).
    • An older CodeResources resource-sealing format.

    You can patch ldid for the first three (I did — the Mach-O signatures become byte-identical to rcodesign), but CodeResources still diverges, so with stricter signing the install fails (0xe8008016 → 0xe8008001) instead of crashing at launch. (An RFC3161 timestamp is not required — rcodesign --timestamp-url none installs fine.)

    Fix that works. Rather than reimplement modern codesign inside ldid, sign with rcodesign (apple-codesign) instead. AltServer already prepares the bundle (embeds the profile, computes entitlements) and builds a cert chain p12 — so in AltSign's Signer::SignApp I just replaced the ldid::Sign(...) call with a shell-out to rcodesign sign. Everything else (auth, certificate, provisioning, install) is unchanged.

    👉 Fork + details: https://github.com/ondrej-simon/AltServer-Linux — see IOS26.md

    With that, AltServer installs and launches directly on iOS 26 (Installation Succeeded), no extra steps. Requirements: rcodesign + openssl on the host (path via ALTSERVER_RCODESIGN).

  2. ytarakji commented on Jun 15, 2026

    @ytarakji
    Author

    I switched to sidestore and NEVER looked back, everything works and on-device-refresh

  3. jaakkopalvaila commented on Sep 13, 2026

    @jaakkopalvaila

    Second data point plus a fix that keeps ldid in-process, no external signer needed.

    Symptom on iOS 27 / 26.4+: install succeeds, app flashes and exits. idevicesyslog:

    kernel  AMFI: cmsBlobVerifyWithAgilityHash failed ... Unrecoverable CT signature issue
    launchd Bad executable (85)
    

    Root cause. I built the vendored ldid.cpp (AltServer-Windows pinned at 071b1dd, 2022) as a CLI, signed a test binary and dumped the CMS with openssl cms -cmsout -print. The hash-agility attribute 1.2.840.113635.100.9.2 is present but carries the SHA-256 CodeDirectory hash truncated to 20 bytes; CoreTrust expects the full 32, so the agility hash never matches and the signature is rejected. The designated requirement is also empty. DER entitlements, the SHA-256 alternate CodeDirectory and CD version 0x20400 are already emitted, so those were not the blocker here.

    Fix. Riley already fixed this for AltServer for Windows 1.7.4 in rileytestut/AltServer-Windows commit 62a7a2b "[ldid] Updates ldid to match AltStore + AltServer macOS' version" (branches 26.4_fix / 1.7.4 / develop); this repo's upstream_repo submodule never picked it up. Only ldid/ldid.cpp and ldid/ldid.hpp change, plus two lines in AltSign/Signer.cpp: ldid::Sign now takes a single ldid::Progress object, and DiskFolder needs a trailing "/" (not "\\", the Linux source rewriter doesn't translate backslashes). It compiles unchanged against the existing Alpine/LibreSSL builder image. With it, AltStore installed from Linux over Wi-Fi launches on iOS 27 with zero CoreTrust errors in the log.

    Fork with this plus the September 2026 Apple ID sign-in fix (com.apple.dt.Xcode → com.apple.akd in client-info, AuthKit User-Agent, no keep-alive, cf. #135) and netmuxd ≥ 0.3 address support: https://github.com/jaakkopalvaila/AltServer-Linux (branch ng, see README-NG.md). Submodules point at patched forks, so git clone --recursive builds as-is.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions