This is an independent FeatureUnlock-derived project and is not an official Acidanthera release.
FeatureUnlock-Tahoe is an opt-in Darwin 25 x86_64 remedy for affected Hackintosh systems where outgoing Screen Mirroring to Apple receivers selects Apple's UDP/T2-dependent Screen route and produces black receiver output. For normal Screen Mirroring use, systems that do not reproduce the documented outgoing Apple-receiver black-screen failure should not download, install, load, or use FeatureUnlock 1.3.1 or 1.2.0. FeatureUnlock 2.2.0 and 2.3.1 are separate experts-only exceptions intended solely for their documented Sidecar research scopes.
Outgoing Screen Mirroring had previously worked on the same test system. The black-screen failure appeared unexpectedly during a later AX210/AirportItlwm/AWDL and OCLP investigation, then persisted after returning to the established Broadcom/OCLP configuration and across multiple independent Tahoe installations. No causal claim is made against those components. The original trigger remains unknown.
The same black-screen result was reproduced with both the established OCLP amfipassbeta configuration and OCLP-Mod 3.1.9, so the persistent failure was not confined to one OCLP-derived patcher or AMFI-handling variant. This exclusion does not identify the original trigger or prove that OCLP was unrelated to the earlier transition.
The investigation ultimately isolated a reproducible AirPlaySender
route-selection boundary and restored Apple's existing native classic Screen
path. FeatureUnlock-Tahoe does not replace Apple's Screen Mirroring stack.
Systems without the documented Screen failure should not install or load
FeatureUnlock 1.3.1 or 1.2.0 and should not add -cdfxscreen. FeatureUnlock
2.2.0 and 2.3.1 are separate experts-only research exceptions for their
documented Sidecar scopes, not general upstream replacements or Sidecar
fixes.
The full chronology and control matrix are in Incident History and Exclusions.
This repository retains the official FeatureUnlock history, license, and ordinary plugin behavior. The Tahoe work is maintained independently and is not endorsed by Acidanthera.
See Upstream and License.
| Release | Status | Implementation | Compatibility model | Boot arguments |
|---|---|---|---|---|
| FeatureUnlock 1.3.1 | Recommended / Latest | Generic Darwin-25 Screen T2 route restoration | Designed for Darwin 25 as a family; runtime validated on macOS 26.5 / 25F71, macOS 26.5.2 / 25F84, and macOS 26.6 / 25G72 | -cdfxscreen |
| FeatureUnlock 1.2.0 | Conservative exact reference | Three exact Screen T2 contexts | Activates only on 25F71, 25F84, and 25G72 | -cdfxscreen |
| FeatureUnlock 2.2.0 | Pre-release / experts only | Generic 1.3.1 Screen T2 plus optional exact Sidecar research | Combined package tested only under 25F84 with MacPro7,1 identity; Sidecar output remains black | -cdfxscreen and optionally -cdfxsidecar |
| FeatureUnlock 2.3.1 | Current research preview / developers only | Generic 1.3.1 Screen T2 plus generic fail-closed Darwin-25 Sidecar research preflight | Runtime validated on 25F71, 25F84, and 25G72; stable Sidecar connection with black video; not a Sidecar fix | -cdfxscreen and optionally -cdfxsidecar |
| Release | Intended use | Direct download |
|---|---|---|
| FeatureUnlock 1.3.1 | Recommended generic Screen Mirroring remedy for affected Darwin-25 x86_64 systems | Download FeatureUnlock 1.3.1 |
| FeatureUnlock 1.2.0 | Conservative exact-build reference for 25F71, 25F84, and 25G72 | Download FeatureUnlock 1.2.0 |
| FeatureUnlock 2.2.0 | Experts-only 25F84/MacPro7,1 Sidecar research pre-release | Download FeatureUnlock 2.2.0 Research |
| FeatureUnlock 2.3.1 | Current experts-only generic Darwin-25 Sidecar research preview for developers; stable connection with black video; not a Sidecar fix | Download FeatureUnlock 2.3.1 Research |
If the documented outgoing Screen Mirroring failure is not present, do not download FeatureUnlock 1.3.1 or 1.2.0. FeatureUnlock 2.2.0 and 2.3.1 should be considered only by experienced developers matching their respective documented Sidecar research scopes.
- FeatureUnlock 1.3.1 is recommended only for an affected Darwin-25 x86_64 system that reproduces the documented outgoing Apple-receiver black-screen failure.
- FeatureUnlock 1.2.0 is an optional conservative exact-build reference for the same documented failure.
- FeatureUnlock 2.2.0 is an unresolved research preview and is not a Sidecar fix.
- FeatureUnlock 2.3.1 is an unresolved developers-only research preview and is not a Sidecar fix.
- Each link downloads the prepared
FeatureUnlock.kextrelease package directly. - No branch or tag selection is required.
- GitHub's automatically generated Source code ZIP and tar.gz archives
are not the prepared
FeatureUnlock.kextpackages. - Download the explicitly named FeatureUnlock ZIP asset for the intended release.
- Use FeatureUnlock 1.3.1 for the normal affected-system Screen Mirroring remedy only when the documented outgoing Apple-receiver black-screen failure is present. It is the recommended implementation and dynamically resolves the validated AirPlaySender structures within the Darwin-25 family.
- Use FeatureUnlock 1.2.0 only when the conservative build-exact implementation is specifically preferred for that same documented failure. It supports only 25F71, 25F84, and 25G72; unknown builds fail closed.
- Use FeatureUnlock 2.2.0 only for expert investigation of the unresolved 25F84 MacPro7,1 Sidecar sender path. Its Screen component corresponds to 1.3.1, but the combined package was tested only in the documented 25F84 environment and its optional Sidecar component is not a functional fix.
- FeatureUnlock 2.2.0 is the historical exact-build research exception to the
Screen-failure requirement. Its two components are independently gated, but
the retained combined runtime evidence used both
-cdfxscreenand-cdfxsidecar; it does not establish a standalone-cdfxsidecar-only runtime validation. - FeatureUnlock 2.3.1 is the preferred developer research option for the generic Darwin-25 Sidecar preflight. It is not a Sidecar fix and must remain within its exact documented expert scope.
- If neither the documented Screen failure nor a documented Sidecar research scope applies, download none of these packages.
FeatureUnlock 1.3.1 is gated to Darwin 25 x86_64 and requires
-cdfxscreen. It can tolerate layout-only movement, including image UUID,
subcache, function, page, offset, rel32, and RIP-relative displacement
changes, only while the complete validated producer, consumer, constructor,
route, page-geometry, and cache-format contract remains unchanged.
It is runtime validated on 25F71, 25F84, and 25G72. This is not a guarantee for every future macOS 26.x build. Semantic changes, ambiguous matches, unsupported cache formats, unsafe page geometry, short reads, arithmetic errors, or target arrival before authorization fail closed.
FeatureUnlock 1.2.0 has a narrower contract: it contains exactly three build-specific Screen contexts and activates only on 25F71, 25F84, or 25G72.
The Screen module contained in FeatureUnlock 2.2.0 is byte-identical in source to the generic 1.3.1 Screen implementation. The optional Sidecar component and the validated combined-package scope are exact to 25F84 and the documented MacPro7,1-identity test system. No combined-package claim is made for 25F71, 25G72, or another SMBIOS identity.
FeatureUnlock 2.3.1 retains the generic Screen 1.3.1 component and uses the generic fail-closed Darwin-25 Sidecar semantic preflight. Runtime validation covered 25F71, 25F84, and 25G72, but future Darwin-25 builds remain independent fail-closed compatibility tests; the stable Sidecar connections did not produce visible video.
The added Screen T2 and Sidecar extensions have a support contract only on Darwin 25 x86_64. This project does not extend or redefine the compatibility claims of ordinary upstream FeatureUnlock behavior on other Darwin families.
The authoritative validation platform was:
- ASUS WS X299 Sage/10G motherboard;
- Intel Core i9-7980XE;
- AMD Radeon VII 16 GB;
- 128 GB DDR4;
- MacPro7,1 SMBIOS identity;
- OpenCore 1.0.7;
- Broadcom BCM943602CDP Wi-Fi/Bluetooth;
- Lilu 1.7.2;
- CryptexFixup 1.0.6;
- Apple TV 4K A2843 and MacBook Pro M1 Screen Mirroring receivers;
- iPad Pro M4 Sidecar research receiver;
- separate macOS system disks for the tested installations;
- final Screen validation on macOS 26.5 / 25F71, macOS 26.5.2 / 25F84, and macOS 26.6 / 25G72.
OCLP root patches appropriate to the test environment were present where required. CryptexFixup 1.0.6 was part of the validated system configuration and is documented for reproducibility; it is not declared as a required FeatureUnlock-Tahoe dependency and is not part of the Screen route-selector implementation.
-cdfxscreenrequests the Screen route-selector correction.-cdfxsidecarexists only in the FeatureUnlock 2.2.0 and 2.3.1 research tracks. It requests the exact 25F84 policy in 2.2.0 and the generic fail-closed Darwin-25 semantic preflight in 2.3.1.
The arguments and diagnostic state are independent. Do not use
-cdfxsidecar with FeatureUnlock 1.3.1. Never enable the Sidecar research
policy on a genuine Apple MacPro7,1. FeatureUnlock 2.2.0 uses the exact
documented 25F84 Sidecar research contract; FeatureUnlock 2.3.1 uses the
generic fail-closed Darwin-25 Sidecar research contract runtime-validated on
25F71, 25F84, and 25G72. Both implementations retain independent component
gating. The retained Screen A -> Sidecar -> Screen B runtime evidence used
both -cdfxscreen and -cdfxsidecar; standalone -cdfxsidecar-only runtime
validation is not claimed.
For normal Screen Mirroring use, do not install FeatureUnlock 1.3.1 or 1.2.0 unless the documented outgoing Apple-receiver failure is present. FeatureUnlock 2.2.0 and 2.3.1 are separate experts-only exceptions solely for their respective documented Sidecar research scopes.
- Use the
FeatureUnlock.kextfrom the release matching the intended implementation and install it together with a compatibleLilu.kext. - Add the kext to the bootloader configuration using the normal OpenCore or equivalent kext-loading workflow.
- Add
-cdfxscreenonly on an affected Darwin-25 x86_64 system. - Reboot and verify the documented FeatureUnlock diagnostic state before testing outgoing Screen Mirroring.
Do not use -cdfxsidecar with the recommended 1.3.1 release. The argument is
available only in the 2.2.0 and 2.3.1 research tracks. Never enable the
Sidecar research policy on a genuine Apple MacPro7,1.
The recovered AirPlaySender producer ends the decisive path with:
test rax, rax
setne al
Its Boolean is stored at endpoint offset +0x111. The consumer interprets
the field as:
nonzero -> APEndpointStreamScreenUDPCreate
zero -> APEndpointStreamScreenCreate
The sole mutation is:
0F 95 C0 setne al
->
B0 00 90 mov al, 0
nop
It preserves instruction length and Apple's common control flow while forcing the final selector to zero. FeatureUnlock-Tahoe intervenes before the failed UDP/AVConference/bridgeOS encoder architecture is entered.
The captured failing Apple-receiver Screen architecture was:
AirPlaySender
-> APEndpointStreamScreenUDPCreate
-> AVConference / Viceroy
-> VideoProcessing
-> usage 42
-> request_hw = 1
-> payload 100
-> codec type 102
-> HEVC
-> remote bridgeOS/T2 encoder path
-> no usable expected bridgeOS/type-3 device
-> VCPCompressionSessionCreate returns -18
-> no usable encoded video pipeline
-> receiver connection may exist, but visible output remains black
Usage 42, request_hw = 1, payload 100, codec type 102, HEVC, and remote
bridgeOS/T2 selection are characteristics of that captured architecture. The
evidence does not prove that any one value in isolation caused the failure.
Payload type and codec type are distinct fields. FeatureUnlock-Tahoe does not
patch or force any of them.
The restored route was:
AirPlaySender
-> APEndpointStreamScreenCreate
-> Apple's existing classic Screen architecture
-> FigVirtualDisplayProcessor
-> native codec-capability evaluation
-> local H.264 / avc1 encoding in the retained working proof
-> VideoToolbox / AppleGVA / AMD encoder
-> unbuffered TCP Screen media transport
-> receiver decoding and presentation
-> visible functional Screen Mirroring
FeatureUnlock-Tahoe does not implement or replace Screen Capture, AirPlaySender, FigVirtualDisplayProcessor, VideoToolbox, AppleGVA, the AMD encoder, codec negotiation, packetization, TCP transport, receiver negotiation, receiver decoding, frame composition, or display presentation. Apple supplies the complete Screen Mirroring implementation; this project restores access to Apple's existing classic Screen route.
FeatureUnlock 1.3.1 performs bounded, read-only cache preflight before publishing one immutable exact vnode/page/offset authorization. It requires:
- one exact AirPlaySender image;
- one original producer and zero replacements;
- one consumer with the endpoint
+0x111witness; - exact UDP and classic constructor targets and route meaning;
- safe page-contained geometry;
- an exact observed native window at the authorized page.
Apple's original page validator runs first. The callback performs no file
access, cache parsing, allocation, logging, lock, wait, or unbounded search.
It writes only B0 00 90, verifies the complete expected replacement window,
and restores the original selector on verification failure. Ambiguous,
unsupported, late, or malformed states do not authorize a write.
FeatureUnlock 1.2.0 applies equivalent mutation and verification rules only to its three exact known contexts.
RESEARCH PREVIEW FOR EXPERIENCED DEVELOPERS ONLY. THIS IS NOT A SIDECAR FIX.
The Sidecar black-screen condition did not arise with the later Screen Mirroring incident. Sidecar had no previously working visible baseline on this Hackintosh and had remained black from the beginning of Sidecar testing. The two investigations are historically separate. They are discussed together only because they expose related Apple display-transmission, bridgeOS/T2-routing, encoder-policy, and receiver-feedback boundaries.
The Sidecar research mutation does not patch SidecarDisplayAgent, RTP
transport, codec negotiation, or the iPad receiver. It operates earlier in a
shared platform-policy helper inside Apple's VideoProcessing framework,
used by both:
_VCPCodecCopyProperties_VCPCompressionSessionCreate
For the MacPro7,1 identity, Apple's native helper takes an immediate-true
branch and returns the remote / T2-dependent BridgeEncode policy as enabled:
MacPro7,1 identity match
-> immediate-true branch
-> remote / T2-dependent BridgeEncode policy enabled
-> callers enter the expected bridge-co-processor path
FeatureUnlock 2.2.0 and 2.3.1 neutralize only that immediate-true branch:
74 37
->
90 90
Execution then falls through to Apple's existing native policy logic:
MacPro7,1 identity match
-> immediate-true branch neutralized
-> com.apple.VideoProcessing / BridgeEncode preference check
-> Apple's native type-3 remote-device probe
-> no usable bridge co-processor
-> native local / false policy result
The mutation does not force H.264, payload type, codec type, usage,
request_hw, encoder backend, or media format.
FeatureUnlock 2.2.0 locates this policy branch only in the exact documented 25F84 layout. FeatureUnlock 2.3.1 locates and authorizes the same two-byte mutation through a generic, semantic, fail-closed Darwin-25 preflight.
FeatureUnlock 2.2.0 adds an optional exact 25F84 VideoProcessing policy experiment for a MacPro7,1-identity Hackintosh without the expected T2/bridgeOS device. The mutation affects a shared VideoProcessing policy helper and is not intrinsically Sidecar-only. Do not enable it on a genuine Apple MacPro7,1.
In the retained 25F84 single-boot test, with both -cdfxscreen and
-cdfxsidecar active:
- the exact Sidecar policy mutation applied and was post-write verified;
- Screen Mirroring A produced visible functional output;
- Sidecar reached payload 123, codec type 100, H.264, local
VTEncoderXPCService, RTP setup, limited FIR feedback, then RTCP timeout, error-401, and black iPad output; - Screen Mirroring B again produced visible functional output.
No Screen/Sidecar cross-interference was observed in that captured sequence.
The claim is limited to one 25F84 boot on the documented system. The Sidecar
sender path advanced beyond the earlier remote bridgeOS/VCP -18 boundary,
but functional Sidecar output was not achieved and the receiver/RTCP/
presentation boundary remains unresolved.
FeatureUnlock 2.3.1 combines the existing generic Screen T2 1.3.1 implementation with a generic, fail-closed Darwin 25 Sidecar research preflight. Its parser, semantic locator, authorization, mutation, and post-write verification were runtime-validated on macOS 26.5 / 25F71, macOS 26.5.2 / 25F84, and macOS 26.6 / 25G72.
On all three tested builds, Screen Mirroring remained functional before and after the Sidecar session. Sidecar established a stable connection to the tested iPad, but visible Sidecar video remained black. FeatureUnlock 2.3.1 is therefore not a Sidecar fix; it is intended only for developers and controlled research.
Users who require only the documented Screen Mirroring correction should continue to use FeatureUnlock 1.3.1. FeatureUnlock 2.2.0 remains available as the historical exact-25F84 Sidecar research implementation and runtime reference, while 2.3.1 is preferred for future developer research.
Future Darwin 25 builds remain independent fail-closed compatibility tests. The Sidecar research path must not be used on genuine Apple MacPro7,1 hardware. See the 2.3.1 implementation report and three-build runtime conclusion.
Read Sidecar Research Status and Expert Warning before considering that experts-only research release or branch.
The unresolved Sidecar research would benefit from a functioning reference
capture from a genuine Intel Mac without an Apple T2 Security Chip. The
highest-value comparison is a working local H.264 / payload-123 path on
macOS 26.5.2 / 25F84; other exactly identified macOS 26 builds remain useful.
FeatureUnlock-Tahoe and -cdfxsidecar must not be loaded, and the reference
must produce actual visible Sidecar output.
The purpose is to compare a healthy sender/receiver-feedback sequence with the
current 2.3.1 generic research state, which validates the production parser,
semantic locator, authorization, mutation, and post-write verification on
25F71, 25F84, and 25G72 but still produces black Sidecar video. Historical
2.2.0 evidence separately reached the local H.264 / payload-123 / codec-100 /
VTEncoderXPCService / RTP / FIR / RTCP-timeout / -401 boundary. A
reference may narrow the sender-format, encoder-backend, or RTCP boundary; it
does not guarantee a fix and Mac-side logs may not expose exact SPS/PPS,
decoder creation, or final presentation state.
Privacy warning: do not publicly upload a complete sysdiagnose, a complete unfiltered log archive, an unreviewed collector output directory, serial numbers, Apple ID or account identifiers, hardware UUIDs, personal device names, SSIDs, IP or MAC addresses, other network identifiers, or other private data.
See Working Non-T2 Sidecar Reference Log Request for eligibility, a one-session protocol, safe collector use, and submission requirements.
| Release | 25F71 | 25F84 | 25G72 |
|---|---|---|---|
| 1.3.1 Generic Screen | Runtime validated | Runtime validated | Runtime validated |
| 1.2.0 Exact Screen | Human-observed runtime validation | Human-observed runtime validation | Human-observed runtime validation |
| 2.2.0 Generic Screen | Not tested as the combined 2.2.0 package | Visible Screen Mirroring succeeded before and after the Sidecar attempt in the same 25F84 boot | Not tested as the combined 2.2.0 package |
| 2.2.0 Sidecar research | Unsupported | Exact mutation applied and post-write verified; local H.264/payload-123 sender path reached; iPad remained black | Unsupported |
| FeatureUnlock 2.3.1 Generic Screen | Visible Screen Mirroring confirmed before and after the Sidecar attempt | Visible Screen Mirroring confirmed before and after the Sidecar attempt | Visible Screen Mirroring confirmed before and after the Sidecar attempt |
| FeatureUnlock 2.3.1 Sidecar research | Generic parser and semantic mutation applied and post-write verified; final Sidecar connection stable; iPad video remained black | Generic parser and semantic mutation applied and post-write verified; final Sidecar connection stable; iPad video remained black | Generic parser and semantic mutation applied and post-write verified; final Sidecar connection stable; iPad video remained black |
See the full Screen Mirroring Test Matrix.
GitHub Actions runs the public self-contained tests, documentation and contributor-safety checks, and a source buildability probe when compatible dependencies can be prepared. Validation and Tests is the blocking job. The initial unsigned x86_64 build probe is explicitly non-blocking because dependency provisioning on GitHub runners may differ from the retained local build environment.
CI does not replace physical Hackintosh runtime validation. A green badge does not prove Screen Mirroring or Sidecar functionality on arbitrary hardware. Official downloads are the prepared GitHub Release ZIP assets listed above, not temporary unsigned Actions artifacts.
See Continuous Integration for the edition mapping, public test counts, build-probe boundary, and workflow safety contract.
- Incident History and Exclusions
- Final Technical Report
- Screen Mirroring Test Matrix
- Implementation Comparison
- Sidecar Research Status
- Sidecar Receiver Boundary
- Sidecar Expert Warning
- Working Non-T2 Sidecar Reference Log Request
- FeatureUnlock 2.3.1 Generic Darwin 25 Sidecar Research Implementation and Build Report
- FeatureUnlock 2.3.1 Three-Build Runtime Validation and Conclusion
- Evidence Index
- Continuous Integration
- Building
- GitHub Publication Checklist
- FeatureUnlock 1.3.1 Release Notes
- FeatureUnlock 1.2.0 Release Notes
- FeatureUnlock 2.2.0 Research Release Notes
- FeatureUnlock 2.3.1 Research Release Notes
Prepare the compatible Lilu and MacKernelSDK dependencies required by the upstream FeatureUnlock build layout, then build the unsigned Release x86_64 target with Xcode. Exact commands and the dependency boundary are documented in Building.
This project is distributed under BSD-3-Clause. The upstream LICENSE.txt is
preserved unchanged. See
Upstream and License.
- KGP / kgp-macPro — Project lead; original problem identification; experimental design; hardware, operating-system, and multi-build runtime validation; evidence collection; technical review; and publication.
- ChatGPT by OpenAI — Technical research and reasoning partner for evidence analysis, hypothesis refinement, experiment planning, runtime-result interpretation, safety boundaries, and documentation development.
- OpenAI Codex CLI — Repository and source analysis, implementation, static validation, automated testing, build verification, release packaging, Git-history construction, and publication auditing.
- Acidanthera and the original FeatureUnlock contributors — Original FeatureUnlock architecture, source base, upstream history, and continuing development.
- vit9696 and contributors — Lilu and its plugin architecture.
- The OpenCore Legacy Patcher, OpenIntelWireless, and wider Hackintosh development communities — Foundational research, tooling, and community knowledge that informed the investigation.
- Apple — macOS and the native AirPlay and Screen Mirroring implementations used by this project.
ChatGPT and Codex assisted under continuous human direction, testing, review, and final editorial control. Their inclusion does not imply endorsement of this independent project by OpenAI.
