Skip to content

[Oasis 3 / 5.18.2.1.1 / SpiderCat] Jailbreak succeeds but KPM/search commands stop working #65

Description

@rbarte

Device

  • Kindle Oasis 3 / Oasis 10th Generation (2019)
  • Firmware: 5.18.2.1.1
  • Platform from logs: juno / stinger_zelda
  • Jailbreak: SpiderCat
  • jb.sh reports version 1.3.7
  • Goal: install KOReader using KPM

Problem

SpiderCat successfully obtained root and jb.sh appears to have installed KMC/KPM, but the post-jailbreak search commands are no longer working.

The initial SpiderCat run displayed:

You are jailbroken!
(jb.sh v1.3.7)
SpiderCat Jailbreak by sparklerfish

JAILBROKEN.txt was created.

privesc_marker.txt also confirms that the exploit reached root:

jb.so constructor: uid=0 euid=0 pid=2053
jb.so constructor: uid=0 euid=0 pid=5696

KMC/KPM installation

The logs from the initial jailbreak contain:

JB_SH 1_0_0:: Setting KMC gandalf permissions
JB_SH 1_0_0:: Establishing Gandalf links
JB_SH 1_0_0:: /usr/lib/ccat detected - deferring sh_integration setup to system patch stage
JB_SH 1_0_0:: /usr/lib/ccat detected, patching sh_integration extractor into system
JB_SH 1_0_0:: Setting up sh_integration

A second jb.sh sequence (JB_SH 1_1_0) also reports the Gandalf links and sh_integration setup.

The logs additionally showed KMC being unpacked and the KMC System Patcher being run.

A later KMC diagnostic confirms that KPM is still present internally:

/var/local/kmc/kindlehf/lib/libkpm.so
/var/local/kmc/kindlepw2/bin/fbdepth
/var/local/kmc/kindlepw2/bin/fbink
/var/local/kmc/kindlepw2/bin/input_scan
/var/local/kmc/kindlepw2/lib/libfbink.so
/var/local/kmc/kindlepw2/lib/libkpm.so

Search command behavior

Initially ;kmclog worked and generated documents/kmc_log/kmc_log.txt.

Currently:

;log — no popup / no apparent action
;kmclog — no longer regenerates kmc_log
;kpm — no apparent action

I verified the kmc_log.txt modification timestamp after testing ;kmclog, and it was not updated.

Testing ;kpm also did not create a new KPPMainAppV2 crash file.

Reboot/persistence observation

During the initial installation the logs show Gandalf and sh_integration being set up.

In the exported logs from subsequent boots I can see normal appreg/framework startup, but I could not find later occurrences of:

run_patch
patch_system
system_patcher
gandalf
sh_integration

I understand that the absence of those strings does not necessarily prove that the scripts did not execute, but it seems consistent with the search commands no longer working.

Second SpiderCat attempt

I tried SpiderCat one more time.

It reached:

JAILBREAK IN PROGRESS
please wait...
executing

and remained at executing for approximately 30 minutes.

I eventually restarted the Kindle with the power button and it booted normally.

I have not attempted SpiderCat again.

Current state

  • Root exploit: successful (uid=0)
  • JAILBROKEN.txt: present
  • jb.sh: executed
  • KMC: installed
  • libkpm.so: present
  • sh_integration: reported as installed during initial jb.sh run
  • ;kmclog: worked initially
  • ;log: currently not working
  • ;kmclog: currently not working
  • ;kpm: currently not working
  • Kindle itself: boots and otherwise works normally
  • SpiderCat retry: hangs at executing

I have NOT factory-reset the Kindle, installed Universal Hotfix/KUAL/MRPI, manually modified KPP/rootfs, or deleted the SpiderCat filler.

Question

What is the recommended recovery procedure for this state?

Is there a supported way to repair/re-run KMC persistence, the system patcher, or sh_integration without factory-resetting the device or running SpiderCat again?

My goal is to restore KPM so that I can install KOReader.

I have the full kmc_log and system logs available, but they contain personal library information, so I prefer not to upload them publicly. I can provide specific sanitized excerpts if particular diagnostics are needed.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions