Skip to content

fix: make openssl PairingFile escrow_bag field Optional#97

Merged
jkcoxson merged 1 commit into
jkcoxson:masterfrom
maxslarsson:fix/openssl-escrow-bag-type
May 7, 2026
Merged

fix: make openssl PairingFile escrow_bag field Optional#97
jkcoxson merged 1 commit into
jkcoxson:masterfrom
maxslarsson:fix/openssl-escrow-bag-type

Conversation

@maxslarsson
Copy link
Copy Markdown
Contributor

Fix openssl PairingFile escrow_bag type mismatch

The openssl-only PairingFile struct defined escrow_bag as Vec<u8>, but the underlying RawPairingFile has it as Option<Data> since escrow_bag can be None (e.g. on Apple Watch). The rustls variant already correctly used Option<Vec<u8>>.

This caused two compile errors when building with --features openssl --no-default-features:

  • Line 244: .map() on Option<Data> returns Option<Vec<u8>>, which doesn't match Vec<u8>
  • Line 292: .map(Data::new) called on Vec<u8>, which doesn't have a .map() method

The fix is just changing the openssl struct field to Option<Vec<u8>> to match. The conversion code was already written expecting Option -- the struct definition was the only thing wrong.

The openssl variant of PairingFile had escrow_bag as Vec<u8> while
RawPairingFile has it as Option<Data> (it's None on Apple Watch).
This caused compile errors in the From/TryFrom impls when building
with the openssl feature. The rustls variant already had the correct
Option<Vec<u8>> type.
@jkcoxson jkcoxson merged commit 0e71ac7 into jkcoxson:master May 7, 2026
3 checks passed
maxslarsson added a commit to maxslarsson/idevice that referenced this pull request May 7, 2026
The openssl variant of PairingFile had escrow_bag as Vec<u8> while
RawPairingFile has it as Option<Data> (it's None on Apple Watch).
This caused compile errors in the From/TryFrom impls when building
with the openssl feature. The rustls variant already had the correct
Option<Vec<u8>> type.
jkcoxson pushed a commit that referenced this pull request May 8, 2026
…gClient (#96)

* refactor: remove pairing_file field and state param from RemotePairingClient

Move pairing_file from a struct field (&'a mut borrow) to a parameter
on connect() and its callees. This removes the lifetime parameter from
the struct and scopes the mutable borrow to the function call.

Also remove the unused state: S generic from connect/pair/request_pair_consent,
since every caller passed 0u8 and ignored it. Callers can capture state
via move closures instead.

* fix: feature gating for error conversions and dead deps (#95)

- Add internal _serde_json and _reqwest features to gate From impls
- Remove unused json and byteorder optional dependencies
- Add missing xpc dependency to remote_pairing feature
- Simplify map_err workarounds in tunnel code to use ? directly

* fix: make openssl PairingFile escrow_bag field Optional (#97)

The openssl variant of PairingFile had escrow_bag as Vec<u8> while
RawPairingFile has it as Option<Data> (it's None on Apple Watch).
This caused compile errors in the From/TryFrom impls when building
with the openssl feature. The rustls variant already had the correct
Option<Vec<u8>> type.

* fix: improve openssl crypto backend (#98)

* fix: make openssl crypto path a first-class backend

Un-gate `ca.rs` and `pair()` from rustls — they only use pure Rust
crates (rsa, x509-cert, sha2) so pairing now works with openssl.
Always detect legacy devices instead of only with openssl feature.
Add openssl feature to FFI crate. Clean up SNI string and gate
rustls-only PEM helpers to fix dead code warnings.

* refactor: return legacy flag from start_session, remove duplicate detection

`LockdownClient::start_session` already queries ProductVersion to
detect legacy devices. Four callers were making the same query
beforehand. Now `start_session` returns the legacy bool so callers
reuse it instead of round-tripping to the device twice.

* Remove rt-multi-thread dependency from AFC file descriptor drop (#93)

AFC's close-on-drop used block_in_place + block_on to synchronously send
a FileClose packet, requiring tokio's rt-multi-thread feature. This is
heavyweight for a best-effort cleanup that already did nothing on wasm
and single-threaded runtimes.

Replace with a simple no-op drop that warns (debug_assert + println) if
.close().await wasn't called. The device reclaims FDs when the AFC
session ends regardless. Also fix the afc tool to explicitly close file
descriptors after use.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants