| Phase | Window (UTC) | Active min | Hours | Main tok | Sub tok | What happened | |
|---|---|---|---|---|---|---|---|
| P0 | Initial PoCs: RqLs trigger + WebDAV leak | 07-28 10:00 → 07-31 14:00 | 210 | 3.5h | 512,000 | 148,000 | Bug analysis from the Calif blog (RqLs create-context confusion + WebDAV uninitialized buffer); evil SMB server; trigger_fsgetpath PoC; evil_webdav_server + leak_client; first VM panics (unaligned CAS, invalid mutex) — both bugs firing. |
| P1 | Calif MIE kickoff: write primitive confirmed | 07-31 14:00 → 08-01 00:00 | 195 | 3.2h | 395,868 | 272,071 | Blog analysis (SMB RqLs confusion + WebDAV leak), evil SMB (:4445/:4446) & WebDAV (:8080) servers, fsgetpath key-oracle, write primitive CONFIRMED (12+ HITs: file_id + ENOENT). |
| P2 | Readback struggles & infra stabilization | 08-01 00:00 → 08-01 09:00 | 47 | 0.8h | 58,421 | 436,491 | panic-before-verify era: verify_loop, pin_late stray loops causing VM panic-loops (sweep auto-start), stray-process hunts, mount wedges, leak pileups, boot-settle discipline. |
| P3 | Locator attempts (anchors, histograms, bands) | 08-01 09:00 → 08-01 16:30 | 167 | 2.8h | 452,242 | 0 | solveB_full anchors, calib_candidates, zone-band ptr->blob histograms, plan_round per-page analysis, grind_big band sweep — all disproven (stale-gen VAs / clog economics). |
| P4 | Slide discovery (churn + consensus) | 08-01 16:30 → 08-01 20:30 | 62 | 1.0h | 156,861 | 0 | churn_vt OSData/OSArray churn -> 72 text pointers -> consensus solve -> KASLR slide 0x10718000 (2 exact + 8 near symbol matches). |
| P5 | Grind loops: gap-persistent sweeps | 08-01 20:30 → 08-02 02:00 | 40 | 0.7h | 100,168 | 0 | probe_map (down-sweep w/ gap state), walk_down, sweep_window, fd_run; HITs every ~2 boots; mount/leak hardening (boot settle, agent warm-up, orphan purge). |
| P6 | Static write-verify + slide via stack remnant | 08-02 02:00 → 08-02 07:30 | 138 | 2.3h | 280,086 | 0 | slidingbucket fail (Xsan slide), #mem-dynamic-control target: right-key EIO x2 vs wrong-key retry = WRITE VERIFIED; deep.bin: photographed kernel stack -> slide 0x5d8000 (94% symbolization). |
| P7 | Parse-switch analysis + DH2Q + deposit | 08-02 07:30 → 08-02 11:00 | 93 | 1.6h | 201,055 | 190,315 | Subagent branch analysis: 16-byte equality oracle identified; DH2Q path confirmed (2/2 panics = stack write lands); deposit steering attempts; fake-vnode concept. |
| P8 | Root-cause + documentation | 08-02 11:00 → 08-02 12:00 | 41 | 0.7h | 94,075 | 0 | DH2Q mutex-validation root cause (errno high byte never 0x22 -> dead end); AGENT.md seed knowledge; this timeline. |
| P9 | Readback design + VM bootstrap campaign | 08-02 15:30 → 08-03 01:00 | 320 | 5.3h | 720,000 | 0 | G-4 readback trick + VM static target (vm-kernelcache G=0xfffffe000a8be9c0); leak sterility proven (no text ptrs); spray_race fill bug (+8..15 zero); sweep panics root-caused (released sprays = torn VAs); OOL live-record swath (queued mach OOL, receive=readback); zone-map layout mapped (fixed offsets, random base). |
| P10 | Oracle semantics + auto-reboot pipelines | 08-03 01:00 → 08-03 06:30 | 240 | 4.0h | 480,000 | 0 | Oracle cracked: errno useless (ENOENT both ways), server-log create count is the truth (1=match, 3=retry, hang=hostile lock, creates=0=unarmed mount); 0xAA/0xBB=XNU poison control-key bug; slide=last_op-0xfffffe0009b9fe64 proven via panic symbolization; pipelines v1-v12 grinding ~70 boots (cluster-anchored probes, auto-reboot); bootstrap still open. |
| P11 | Write-verify ×3 + slide routine (9 slides) | 08-03 06:30 → 08-03 14:30 | 130 | 2.2h | 341,000 | 108,000 | Static write at G + G-4 byte-exact readback on 3 boots (criterion a DONE); text-consensus slide routine proven on 9 boots (0x26d78000, 0x12f1c000, 0xbfac000 ...); panic-log thread/task captures (criterion b partial). |
| P12 | Escalation writes + alignment & contention rules | 08-03 14:30 → 08-03 22:30 | 165 | 2.8h | 478,000 | 224,000 | isAMFIGetOutOfMyWay write landed ×2 (system destabilizes = proof of effect); 4-mod-8 alignment rule root-caused (_securelevel unaligned panics); 0x22 mutex-typing rule for contention; Calif friendship = parent/child lease keys decoded. |
| P13 | Sterility wall + heap-garbage correction | 08-03 22:30 → 08-04 08:30 | 150 | 2.5h | 519,000 | 86,000 | VM leaks stop producing text pointers entirely; pipeline4 grinds 30+ boots; heap-garbage-vs-real pointer root cause (0xfffffe00_2x family); symbolization (symfrac) validator added; kpwatch/esc_watch armed. |
| P14 | Pivot: anchor ladder + KDP/nvram + kread tooling | 08-04 15:30 → 08-04 20:30 | 190 | 3.2h | 612,000 | 176,000 | Grinding killed. Blind ladder of historical OOL band (band mapped, all hostile). vm_kread/rootchain/roothelp + key-file servers built. nvram.bin boot-args patching PROVEN (benign edits boot); debug=0x144 halts for KDP, KDP over virtio dead; slide=0/0x1000000 unbootable on VMAPPLE. |
| P15 | smbfs parse RE + handoff race redesign | 08-04 20:30 → 08-04 23:30 | 145 | 2.4h | 428,000 | 261,000 | Subagent RE (src+binary verified): last_op/activation are TRANSIENT (zeroed on unlock) — race mandatory; full write-set enum (u32@+2c, u16@+50, flag RMWs); no list-insert/callout; parent-compare order; RO-cred (ZC_READONLY) + PAC-signed ptr dead ends; handoff race designed (racecap2). |
| P16 | Zone-freelist plateaus + zone_pipeline campaign | 08-04 23:30 → 08-05 02:00 | 155 | 2.6h | 587,000 | 139,000 | Zone/band freelist links in leaks → 171-vote buffer-VA plateaus; proc-zone discovery (0x578 stride — anchor-free survey path); chain validation; coalescing-vs-fragmentation + zfree-poison mechanics; zone_pipeline v1→v17 evolution; overnight 60-cycle grinder. |
| P17 | Overnight plateau grinder + buffer-VA derivation | 08-05 02:00 → 08-05 08:10 | 95 | 1.6h | 305,000 | 62,000 | 10+ chain-validated plateaus overnight; buffer VA derived exactly via link-target/dump-offset mapping; live-buffer-occupancy insight (probes at the buffer VA hang because webdavfs keeps the file cache live); LIFO chunk-reuse probing; stride classification of freelist families (proc 0x578 vs kalloc arrays). |
Active time counts minutes with recorded session activity; gaps > 25 min (VM/host sleep) are excluded. Token estimates ≈ wire bytes / 4 (main agent per phase window; subagents at their start phase), cross-checked against API usage records. ±10%. Regenerated from data.json by gen.py.