Skip to content

Repository files navigation

FeatureUnlock-Tahoe

Visible outgoing Screen Mirroring from the X299 Hackintosh to a MacBook Pro M1 receiver

CI

This is an independent FeatureUnlock-derived project and is not an official Acidanthera release.

FeatureUnlock-Tahoe is an opt-in Darwin 25 x86_64 remedy for affected Hackintosh systems where outgoing Screen Mirroring to Apple receivers selects Apple's UDP/T2-dependent Screen route and produces black receiver output. For normal Screen Mirroring use, systems that do not reproduce the documented outgoing Apple-receiver black-screen failure should not download, install, load, or use FeatureUnlock 1.3.1 or 1.2.0. FeatureUnlock 2.2.0 and 2.3.1 are separate experts-only exceptions intended solely for their documented Sidecar research scopes.

Why this project exists

Outgoing Screen Mirroring had previously worked on the same test system. The black-screen failure appeared unexpectedly during a later AX210/AirportItlwm/AWDL and OCLP investigation, then persisted after returning to the established Broadcom/OCLP configuration and across multiple independent Tahoe installations. No causal claim is made against those components. The original trigger remains unknown.

The same black-screen result was reproduced with both the established OCLP amfipassbeta configuration and OCLP-Mod 3.1.9, so the persistent failure was not confined to one OCLP-derived patcher or AMFI-handling variant. This exclusion does not identify the original trigger or prove that OCLP was unrelated to the earlier transition.

The investigation ultimately isolated a reproducible AirPlaySender route-selection boundary and restored Apple's existing native classic Screen path. FeatureUnlock-Tahoe does not replace Apple's Screen Mirroring stack. Systems without the documented Screen failure should not install or load FeatureUnlock 1.3.1 or 1.2.0 and should not add -cdfxscreen. FeatureUnlock 2.2.0 and 2.3.1 are separate experts-only research exceptions for their documented Sidecar scopes, not general upstream replacements or Sidecar fixes.

The full chronology and control matrix are in Incident History and Exclusions.

Upstream attribution

This repository retains the official FeatureUnlock history, license, and ordinary plugin behavior. The Tahoe work is maintained independently and is not endorsed by Acidanthera.

See Upstream and License.

Release status

Release Status Implementation Compatibility model Boot arguments
FeatureUnlock 1.3.1 Recommended / Latest Generic Darwin-25 Screen T2 route restoration Designed for Darwin 25 as a family; runtime validated on macOS 26.5 / 25F71, macOS 26.5.2 / 25F84, and macOS 26.6 / 25G72 -cdfxscreen
FeatureUnlock 1.2.0 Conservative exact reference Three exact Screen T2 contexts Activates only on 25F71, 25F84, and 25G72 -cdfxscreen
FeatureUnlock 2.2.0 Pre-release / experts only Generic 1.3.1 Screen T2 plus optional exact Sidecar research Combined package tested only under 25F84 with MacPro7,1 identity; Sidecar output remains black -cdfxscreen and optionally -cdfxsidecar
FeatureUnlock 2.3.1 Current research preview / developers only Generic 1.3.1 Screen T2 plus generic fail-closed Darwin-25 Sidecar research preflight Runtime validated on 25F71, 25F84, and 25G72; stable Sidecar connection with black video; not a Sidecar fix -cdfxscreen and optionally -cdfxsidecar

Downloads

Release Intended use Direct download
FeatureUnlock 1.3.1 Recommended generic Screen Mirroring remedy for affected Darwin-25 x86_64 systems Download FeatureUnlock 1.3.1
FeatureUnlock 1.2.0 Conservative exact-build reference for 25F71, 25F84, and 25G72 Download FeatureUnlock 1.2.0
FeatureUnlock 2.2.0 Experts-only 25F84/MacPro7,1 Sidecar research pre-release Download FeatureUnlock 2.2.0 Research
FeatureUnlock 2.3.1 Current experts-only generic Darwin-25 Sidecar research preview for developers; stable connection with black video; not a Sidecar fix Download FeatureUnlock 2.3.1 Research

If the documented outgoing Screen Mirroring failure is not present, do not download FeatureUnlock 1.3.1 or 1.2.0. FeatureUnlock 2.2.0 and 2.3.1 should be considered only by experienced developers matching their respective documented Sidecar research scopes.

  • FeatureUnlock 1.3.1 is recommended only for an affected Darwin-25 x86_64 system that reproduces the documented outgoing Apple-receiver black-screen failure.
  • FeatureUnlock 1.2.0 is an optional conservative exact-build reference for the same documented failure.
  • FeatureUnlock 2.2.0 is an unresolved research preview and is not a Sidecar fix.
  • FeatureUnlock 2.3.1 is an unresolved developers-only research preview and is not a Sidecar fix.
  • Each link downloads the prepared FeatureUnlock.kext release package directly.
  • No branch or tag selection is required.
  • GitHub's automatically generated Source code ZIP and tar.gz archives are not the prepared FeatureUnlock.kext packages.
  • Download the explicitly named FeatureUnlock ZIP asset for the intended release.

Which release should I use?

  • Use FeatureUnlock 1.3.1 for the normal affected-system Screen Mirroring remedy only when the documented outgoing Apple-receiver black-screen failure is present. It is the recommended implementation and dynamically resolves the validated AirPlaySender structures within the Darwin-25 family.
  • Use FeatureUnlock 1.2.0 only when the conservative build-exact implementation is specifically preferred for that same documented failure. It supports only 25F71, 25F84, and 25G72; unknown builds fail closed.
  • Use FeatureUnlock 2.2.0 only for expert investigation of the unresolved 25F84 MacPro7,1 Sidecar sender path. Its Screen component corresponds to 1.3.1, but the combined package was tested only in the documented 25F84 environment and its optional Sidecar component is not a functional fix.
  • FeatureUnlock 2.2.0 is the historical exact-build research exception to the Screen-failure requirement. Its two components are independently gated, but the retained combined runtime evidence used both -cdfxscreen and -cdfxsidecar; it does not establish a standalone -cdfxsidecar-only runtime validation.
  • FeatureUnlock 2.3.1 is the preferred developer research option for the generic Darwin-25 Sidecar preflight. It is not a Sidecar fix and must remain within its exact documented expert scope.
  • If neither the documented Screen failure nor a documented Sidecar research scope applies, download none of these packages.

Supported contract

FeatureUnlock 1.3.1 is gated to Darwin 25 x86_64 and requires -cdfxscreen. It can tolerate layout-only movement, including image UUID, subcache, function, page, offset, rel32, and RIP-relative displacement changes, only while the complete validated producer, consumer, constructor, route, page-geometry, and cache-format contract remains unchanged.

It is runtime validated on 25F71, 25F84, and 25G72. This is not a guarantee for every future macOS 26.x build. Semantic changes, ambiguous matches, unsupported cache formats, unsafe page geometry, short reads, arithmetic errors, or target arrival before authorization fail closed.

FeatureUnlock 1.2.0 has a narrower contract: it contains exactly three build-specific Screen contexts and activates only on 25F71, 25F84, or 25G72.

The Screen module contained in FeatureUnlock 2.2.0 is byte-identical in source to the generic 1.3.1 Screen implementation. The optional Sidecar component and the validated combined-package scope are exact to 25F84 and the documented MacPro7,1-identity test system. No combined-package claim is made for 25F71, 25G72, or another SMBIOS identity.

FeatureUnlock 2.3.1 retains the generic Screen 1.3.1 component and uses the generic fail-closed Darwin-25 Sidecar semantic preflight. Runtime validation covered 25F71, 25F84, and 25G72, but future Darwin-25 builds remain independent fail-closed compatibility tests; the stable Sidecar connections did not produce visible video.

The added Screen T2 and Sidecar extensions have a support contract only on Darwin 25 x86_64. This project does not extend or redefine the compatibility claims of ordinary upstream FeatureUnlock behavior on other Darwin families.

Validation environment

The authoritative validation platform was:

  • ASUS WS X299 Sage/10G motherboard;
  • Intel Core i9-7980XE;
  • AMD Radeon VII 16 GB;
  • 128 GB DDR4;
  • MacPro7,1 SMBIOS identity;
  • OpenCore 1.0.7;
  • Broadcom BCM943602CDP Wi-Fi/Bluetooth;
  • Lilu 1.7.2;
  • CryptexFixup 1.0.6;
  • Apple TV 4K A2843 and MacBook Pro M1 Screen Mirroring receivers;
  • iPad Pro M4 Sidecar research receiver;
  • separate macOS system disks for the tested installations;
  • final Screen validation on macOS 26.5 / 25F71, macOS 26.5.2 / 25F84, and macOS 26.6 / 25G72.

OCLP root patches appropriate to the test environment were present where required. CryptexFixup 1.0.6 was part of the validated system configuration and is documented for reproducibility; it is not declared as a required FeatureUnlock-Tahoe dependency and is not part of the Screen route-selector implementation.

Boot arguments

  • -cdfxscreen requests the Screen route-selector correction.
  • -cdfxsidecar exists only in the FeatureUnlock 2.2.0 and 2.3.1 research tracks. It requests the exact 25F84 policy in 2.2.0 and the generic fail-closed Darwin-25 semantic preflight in 2.3.1.

The arguments and diagnostic state are independent. Do not use -cdfxsidecar with FeatureUnlock 1.3.1. Never enable the Sidecar research policy on a genuine Apple MacPro7,1. FeatureUnlock 2.2.0 uses the exact documented 25F84 Sidecar research contract; FeatureUnlock 2.3.1 uses the generic fail-closed Darwin-25 Sidecar research contract runtime-validated on 25F71, 25F84, and 25G72. Both implementations retain independent component gating. The retained Screen A -> Sidecar -> Screen B runtime evidence used both -cdfxscreen and -cdfxsidecar; standalone -cdfxsidecar-only runtime validation is not claimed.

Installation summary

For normal Screen Mirroring use, do not install FeatureUnlock 1.3.1 or 1.2.0 unless the documented outgoing Apple-receiver failure is present. FeatureUnlock 2.2.0 and 2.3.1 are separate experts-only exceptions solely for their respective documented Sidecar research scopes.

  1. Use the FeatureUnlock.kext from the release matching the intended implementation and install it together with a compatible Lilu.kext.
  2. Add the kext to the bootloader configuration using the normal OpenCore or equivalent kext-loading workflow.
  3. Add -cdfxscreen only on an affected Darwin-25 x86_64 system.
  4. Reboot and verify the documented FeatureUnlock diagnostic state before testing outgoing Screen Mirroring.

Do not use -cdfxsidecar with the recommended 1.3.1 release. The argument is available only in the 2.2.0 and 2.3.1 research tracks. Never enable the Sidecar research policy on a genuine Apple MacPro7,1.

What the Screen patch does

The recovered AirPlaySender producer ends the decisive path with:

test rax, rax
setne al

Its Boolean is stored at endpoint offset +0x111. The consumer interprets the field as:

nonzero -> APEndpointStreamScreenUDPCreate
zero    -> APEndpointStreamScreenCreate

The sole mutation is:

0F 95 C0        setne al
    ->
B0 00 90        mov al, 0
                nop

It preserves instruction length and Apple's common control flow while forcing the final selector to zero. FeatureUnlock-Tahoe intervenes before the failed UDP/AVConference/bridgeOS encoder architecture is entered.

Failing and restored runtime paths

The captured failing Apple-receiver Screen architecture was:

AirPlaySender
  -> APEndpointStreamScreenUDPCreate
  -> AVConference / Viceroy
  -> VideoProcessing
  -> usage 42
  -> request_hw = 1
  -> payload 100
  -> codec type 102
  -> HEVC
  -> remote bridgeOS/T2 encoder path
  -> no usable expected bridgeOS/type-3 device
  -> VCPCompressionSessionCreate returns -18
  -> no usable encoded video pipeline
  -> receiver connection may exist, but visible output remains black

Usage 42, request_hw = 1, payload 100, codec type 102, HEVC, and remote bridgeOS/T2 selection are characteristics of that captured architecture. The evidence does not prove that any one value in isolation caused the failure. Payload type and codec type are distinct fields. FeatureUnlock-Tahoe does not patch or force any of them.

The restored route was:

AirPlaySender
  -> APEndpointStreamScreenCreate
  -> Apple's existing classic Screen architecture
  -> FigVirtualDisplayProcessor
  -> native codec-capability evaluation
  -> local H.264 / avc1 encoding in the retained working proof
  -> VideoToolbox / AppleGVA / AMD encoder
  -> unbuffered TCP Screen media transport
  -> receiver decoding and presentation
  -> visible functional Screen Mirroring

FeatureUnlock-Tahoe does not implement or replace Screen Capture, AirPlaySender, FigVirtualDisplayProcessor, VideoToolbox, AppleGVA, the AMD encoder, codec negotiation, packetization, TCP transport, receiver negotiation, receiver decoding, frame composition, or display presentation. Apple supplies the complete Screen Mirroring implementation; this project restores access to Apple's existing classic Screen route.

Fail-closed safety

FeatureUnlock 1.3.1 performs bounded, read-only cache preflight before publishing one immutable exact vnode/page/offset authorization. It requires:

  • one exact AirPlaySender image;
  • one original producer and zero replacements;
  • one consumer with the endpoint +0x111 witness;
  • exact UDP and classic constructor targets and route meaning;
  • safe page-contained geometry;
  • an exact observed native window at the authorized page.

Apple's original page validator runs first. The callback performs no file access, cache parsing, allocation, logging, lock, wait, or unbounded search. It writes only B0 00 90, verifies the complete expected replacement window, and restores the original selector on verification failure. Ambiguous, unsupported, late, or malformed states do not authorize a write.

FeatureUnlock 1.2.0 applies equivalent mutation and verification rules only to its three exact known contexts.

Sidecar research warning

RESEARCH PREVIEW FOR EXPERIENCED DEVELOPERS ONLY. THIS IS NOT A SIDECAR FIX.

The Sidecar black-screen condition did not arise with the later Screen Mirroring incident. Sidecar had no previously working visible baseline on this Hackintosh and had remained black from the beginning of Sidecar testing. The two investigations are historically separate. They are discussed together only because they expose related Apple display-transmission, bridgeOS/T2-routing, encoder-policy, and receiver-feedback boundaries.

Where the Sidecar research patch intervenes

The Sidecar research mutation does not patch SidecarDisplayAgent, RTP transport, codec negotiation, or the iPad receiver. It operates earlier in a shared platform-policy helper inside Apple's VideoProcessing framework, used by both:

  • _VCPCodecCopyProperties
  • _VCPCompressionSessionCreate

For the MacPro7,1 identity, Apple's native helper takes an immediate-true branch and returns the remote / T2-dependent BridgeEncode policy as enabled:

MacPro7,1 identity match
  -> immediate-true branch
  -> remote / T2-dependent BridgeEncode policy enabled
  -> callers enter the expected bridge-co-processor path

FeatureUnlock 2.2.0 and 2.3.1 neutralize only that immediate-true branch:

74 37
  ->
90 90

Execution then falls through to Apple's existing native policy logic:

MacPro7,1 identity match
  -> immediate-true branch neutralized
  -> com.apple.VideoProcessing / BridgeEncode preference check
  -> Apple's native type-3 remote-device probe
  -> no usable bridge co-processor
  -> native local / false policy result

The mutation does not force H.264, payload type, codec type, usage, request_hw, encoder backend, or media format.

FeatureUnlock 2.2.0 locates this policy branch only in the exact documented 25F84 layout. FeatureUnlock 2.3.1 locates and authorizes the same two-byte mutation through a generic, semantic, fail-closed Darwin-25 preflight.

FeatureUnlock 2.2.0 adds an optional exact 25F84 VideoProcessing policy experiment for a MacPro7,1-identity Hackintosh without the expected T2/bridgeOS device. The mutation affects a shared VideoProcessing policy helper and is not intrinsically Sidecar-only. Do not enable it on a genuine Apple MacPro7,1.

In the retained 25F84 single-boot test, with both -cdfxscreen and -cdfxsidecar active:

  1. the exact Sidecar policy mutation applied and was post-write verified;
  2. Screen Mirroring A produced visible functional output;
  3. Sidecar reached payload 123, codec type 100, H.264, local VTEncoderXPCService, RTP setup, limited FIR feedback, then RTCP timeout, error -401, and black iPad output;
  4. Screen Mirroring B again produced visible functional output.

No Screen/Sidecar cross-interference was observed in that captured sequence. The claim is limited to one 25F84 boot on the documented system. The Sidecar sender path advanced beyond the earlier remote bridgeOS/VCP -18 boundary, but functional Sidecar output was not achieved and the receiver/RTCP/ presentation boundary remains unresolved.

FeatureUnlock 2.3.1 developer research preview

FeatureUnlock 2.3.1 combines the existing generic Screen T2 1.3.1 implementation with a generic, fail-closed Darwin 25 Sidecar research preflight. Its parser, semantic locator, authorization, mutation, and post-write verification were runtime-validated on macOS 26.5 / 25F71, macOS 26.5.2 / 25F84, and macOS 26.6 / 25G72.

On all three tested builds, Screen Mirroring remained functional before and after the Sidecar session. Sidecar established a stable connection to the tested iPad, but visible Sidecar video remained black. FeatureUnlock 2.3.1 is therefore not a Sidecar fix; it is intended only for developers and controlled research.

Users who require only the documented Screen Mirroring correction should continue to use FeatureUnlock 1.3.1. FeatureUnlock 2.2.0 remains available as the historical exact-25F84 Sidecar research implementation and runtime reference, while 2.3.1 is preferred for future developer research.

Future Darwin 25 builds remain independent fail-closed compatibility tests. The Sidecar research path must not be used on genuine Apple MacPro7,1 hardware. See the 2.3.1 implementation report and three-build runtime conclusion.

Read Sidecar Research Status and Expert Warning before considering that experts-only research release or branch.

Working Sidecar reference logs requested

The unresolved Sidecar research would benefit from a functioning reference capture from a genuine Intel Mac without an Apple T2 Security Chip. The highest-value comparison is a working local H.264 / payload-123 path on macOS 26.5.2 / 25F84; other exactly identified macOS 26 builds remain useful. FeatureUnlock-Tahoe and -cdfxsidecar must not be loaded, and the reference must produce actual visible Sidecar output.

The purpose is to compare a healthy sender/receiver-feedback sequence with the current 2.3.1 generic research state, which validates the production parser, semantic locator, authorization, mutation, and post-write verification on 25F71, 25F84, and 25G72 but still produces black Sidecar video. Historical 2.2.0 evidence separately reached the local H.264 / payload-123 / codec-100 / VTEncoderXPCService / RTP / FIR / RTCP-timeout / -401 boundary. A reference may narrow the sender-format, encoder-backend, or RTCP boundary; it does not guarantee a fix and Mac-side logs may not expose exact SPS/PPS, decoder creation, or final presentation state.

Privacy warning: do not publicly upload a complete sysdiagnose, a complete unfiltered log archive, an unreviewed collector output directory, serial numbers, Apple ID or account identifiers, hardware UUIDs, personal device names, SSIDs, IP or MAC addresses, other network identifiers, or other private data.

See Working Non-T2 Sidecar Reference Log Request for eligibility, a one-session protocol, safe collector use, and submission requirements.

Test matrix

Release 25F71 25F84 25G72
1.3.1 Generic Screen Runtime validated Runtime validated Runtime validated
1.2.0 Exact Screen Human-observed runtime validation Human-observed runtime validation Human-observed runtime validation
2.2.0 Generic Screen Not tested as the combined 2.2.0 package Visible Screen Mirroring succeeded before and after the Sidecar attempt in the same 25F84 boot Not tested as the combined 2.2.0 package
2.2.0 Sidecar research Unsupported Exact mutation applied and post-write verified; local H.264/payload-123 sender path reached; iPad remained black Unsupported
FeatureUnlock 2.3.1 Generic Screen Visible Screen Mirroring confirmed before and after the Sidecar attempt Visible Screen Mirroring confirmed before and after the Sidecar attempt Visible Screen Mirroring confirmed before and after the Sidecar attempt
FeatureUnlock 2.3.1 Sidecar research Generic parser and semantic mutation applied and post-write verified; final Sidecar connection stable; iPad video remained black Generic parser and semantic mutation applied and post-write verified; final Sidecar connection stable; iPad video remained black Generic parser and semantic mutation applied and post-write verified; final Sidecar connection stable; iPad video remained black

See the full Screen Mirroring Test Matrix.

Continuous integration

GitHub Actions runs the public self-contained tests, documentation and contributor-safety checks, and a source buildability probe when compatible dependencies can be prepared. Validation and Tests is the blocking job. The initial unsigned x86_64 build probe is explicitly non-blocking because dependency provisioning on GitHub runners may differ from the retained local build environment.

CI does not replace physical Hackintosh runtime validation. A green badge does not prove Screen Mirroring or Sidecar functionality on arbitrary hardware. Official downloads are the prepared GitHub Release ZIP assets listed above, not temporary unsigned Actions artifacts.

See Continuous Integration for the edition mapping, public test counts, build-probe boundary, and workflow safety contract.

Detailed documentation

Building

Prepare the compatible Lilu and MacKernelSDK dependencies required by the upstream FeatureUnlock build layout, then build the unsigned Release x86_64 target with Xcode. Exact commands and the dependency boundary are documented in Building.

License

This project is distributed under BSD-3-Clause. The upstream LICENSE.txt is preserved unchanged. See Upstream and License.

Credits

  • KGP / kgp-macPro — Project lead; original problem identification; experimental design; hardware, operating-system, and multi-build runtime validation; evidence collection; technical review; and publication.
  • ChatGPT by OpenAI — Technical research and reasoning partner for evidence analysis, hypothesis refinement, experiment planning, runtime-result interpretation, safety boundaries, and documentation development.
  • OpenAI Codex CLI — Repository and source analysis, implementation, static validation, automated testing, build verification, release packaging, Git-history construction, and publication auditing.
  • Acidanthera and the original FeatureUnlock contributors — Original FeatureUnlock architecture, source base, upstream history, and continuing development.
  • vit9696 and contributors — Lilu and its plugin architecture.
  • The OpenCore Legacy Patcher, OpenIntelWireless, and wider Hackintosh development communities — Foundational research, tooling, and community knowledge that informed the investigation.
  • Apple — macOS and the native AirPlay and Screen Mirroring implementations used by this project.

ChatGPT and Codex assisted under continuous human direction, testing, review, and final editorial control. Their inclusion does not imply endorsement of this independent project by OpenAI.

About

Independent FeatureUnlock-derived project for macOS Tahoe x86_64. Provides a generic outgoing AirPlay Screen Mirroring fix and a separate generic Sidecar research implementation, both runtime-validated on 25F71, 25F84 and 25G72. Screen Mirroring is functional; Sidecar connects but video remains black. Not an official Acidanthera release.

Topics

Resources

Stars

5 stars

Watchers

0 watching

Forks

Releases

Contributors

Languages