Architecture
This overview explains how LiveContainer hosts guest apps. It is a rewrite of the public architecture notes for contributors.
Major targets
- LiveContainer - bootstrap, container data, and launching LiveProcess; SwiftUI UI while idle
- LiveContainerSwiftUI - UI surfaces and
Localizable.xcstrings(Crowdin) - LiveProcess - guest loader with matching entitlements but a different bundle ID (multitask + PID JIT); patches the binary, dyld hooks, tweaks, then jumps to the entry point
- MultitaskSupport - floating and native iPad windows, kept in sync with the primary app
- SideStore helpers - refresh/JIT APIs, certificate refresh, sources, URL schemes
- TweakLoader - substrate-style loader injected via a load command (symlink can be overridden)
- ZSign - signing stack derived from Feather/zhlynn work with LiveContainer-specific entitlement and multi-container changes
- Submodules - fishhook, litehook, OpenSSL
Launch pipeline
- Prepare the guest Mach-O: rewrite
__PAGEZERO(vmaddr=0xFFFFC000,vmsize=0x4000), convertMH_EXECUTEtoMH_DYLIB, inject a TweakLoader load command. - Patch
@executable_paththrough litehook/fishhook on_NSGetExecutablePath(older SIGSEGV tricks are retired). - Override
NSBundle.mainBundleso the guest sees its own bundle. - Signing: JIT can bypass checks; JIT-less mode signs with ZSign using the imported certificate.
- LiveProcess
dlopens the guest, TweakLoader runs, then control reachesUIApplicationMain. - Multi-account isolation uses up to 128 keychain access groups; containers choose which groups to isolate.
Known limits
- Guest entitlements are not copied; guests inherit the host's base entitlements.
- Permission prompts are global across guests.
- Guests share a sandbox - a malicious guest can read other guests' data.
- App extensions are not registered for guests.
- Some multitask input paths (hardware keyboard / iPhone Mirroring) are blocked.
- Push notifications and custom URL scheme queries often fail because SpringBoard never registered the guest.
Official sources: Cross-check details on the official documentation and the LiveContainer repository.