# Software Supply-Chain Provenance ## Identification The evidence needed to establish where an APK, ROM, ISO, VM image, firmware module, or archive came from and whether it is authentic and appropriate. ## Notebook evidence - [[Scanned_20260730-1719#PDF page 14 — Android root, ROM, app-store, monitoring, and removal tools|PDF page 14: Android root, ROM, app-store, monitoring, and removal tools]] — The author is assembling ways to escape a stock Android environment: obtain root, replace the ROM, bypass an app store, remove bundled software, and remotely observe/control the device. That is consistent with the notebook’s sovereignty theme, but the list collapses liberating tools and high-risk surveillance or piracy-adjacent tools into the same search space. - [[Scanned_20260730-1719#PDF page 31 — Live security distributions, System76 firmware, and Linux VM images|PDF page 31: Live security distributions, System76 firmware, and Linux VM images]] — This is a practical sourcing list: which systems can be booted live, downloaded as VMs, or obtained with open firmware. “Not allowed” may be a hardware policy, blocked download, failed boot, or licensing observation. - [[Scanned_20260730-1719#PDF page 44 — Wineskin, cloud configuration, and Ozmosis|PDF page 44: Wineskin, cloud configuration, and Ozmosis]] — The notebook pivots from contact storage back into compatibility engineering: Windows binaries above macOS through Wine, and macOS boot support below the OS through firmware modules. - [[Scanned_20260730-1719#PDF page 46 — UBU, MMTool, microcode, and AMI Aptio BIOS modding|PDF page 46: UBU, MMTool, microcode, and AMI Aptio BIOS modding]] — The author is researching repeatable module-level firmware maintenance: identify versions, extract components, replace option ROMs or microcode, and rebuild. This is a much more consequential form of “software update” than the Android app list on page 14. - [[Scanned_20260730-1719#PDF page 47 — Ozmosis tooling and firmware image references|PDF page 47: Ozmosis tooling and firmware image references]] — The page ties a specific firmware image/toolchain to a user application. This is important: the firmware work may not be abstract experimentation; it may be in service of preserving a creative software environment. - [[Scanned_20260730-1719#PDF page 49 — Mojave APFS and Hackintosh source repositories|PDF page 49: Mojave APFS and Hackintosh source repositories]] — This is a source-provenance list for making Mojave/APFS boot on non-Apple firmware: ACPI editing, UEFI image inspection, boot-layer projects, and application compatibility. - [[Scanned_20260730-1719#PDF page 50 — AMI Aptio firmware modules and UEFITool|PDF page 50: AMI Aptio firmware modules and UEFITool]] — The author wants firmware that can understand more filesystems and emulate missing services before an OS loads. This is the architectural center of the Ozmosis section: move compatibility functions into UEFI modules so multiple boot paths can use them. - [[Scanned_20260730-1719#PDF page 53 — Ozmosis build components, PXE, and Kext-to-FFS conversion|PDF page 53: Ozmosis build components, PXE, and Kext-to-FFS conversion]] — The intended firmware is not merely “Mac compatible.” It is a universal pre-OS service layer capable of local filesystem access, Mac identity support, shell access, and network boot. ## Relationships and overlays The source places this note in a shared evidence cluster with [[Acidanthera|Acidanthera]] · [[AMI Aptio|AMI Aptio]] · [[Apple File System|Apple File System]] · [[Btrfs|Btrfs]] · [[CPU microcode|CPU microcode]] · [[exFAT|exFAT]] · [[FakeSMC|FakeSMC]] · [[LineageOS|LineageOS]] · [[MaciASL|MaciASL]] · [[macOS Mojave|macOS Mojave]] · [[mSpy|mSpy]] · [[Ozmosis firmware|Ozmosis firmware]] · [[Parrot OS|Parrot OS]] · [[Pop!_OS|Pop!_OS]] · [[Preboot Execution Environment|Preboot Execution Environment]] · [[Scanned_20260730-1706|Scanned_20260730-1706]] · [[Sibelius|Sibelius]] · [[System76 Open Firmware|System76 Open Firmware]]. Within the larger collection, this evidence extends [[Vendor-Agnostic Recovery|vendor-agnostic recovery]] and [[Continuity Architecture|continuity architecture]] by showing how software, hardware, identity, and pre-OS control depend on recoverable interfaces. ## Evidentiary status and open leads A modern reconstruction should add provenance, signatures, source availability, permissions, legal status, and threat-model fit for every tool before execution. ## Source - [[Scanned_20260730-1719|Scanned_20260730-1719]] ## Scanned_20260730-1659 overlay **Source evidence:** [[Scanned_20260730-1659#PDF page 7 — F-Droid, Tutu, and 3C Android tools|page 7]], [[Scanned_20260730-1659#PDF page 13 — iOS jailbreak sources and FQDN/IP notes|page 13]], [[Scanned_20260730-1659#PDF page 25 — Storage Access Framework and open mobile infrastructure map|page 25]], [[Scanned_20260730-1659#PDF page 27 — Android package names, Dr. Ketan ROM, and Tasker security tools|page 27]], [[Scanned_20260730-1659#PDF page 29 — Browser interception and FOSS download tools|page 29]], [[Scanned_20260730-1659#PDF page 38 — Cloud, analytics, and router-domain blocklist|page 38]], [[Scanned_20260730-1659#PDF page 39 — Telemetry, advertising, payment, and analytics domains|page 39]], [[Scanned_20260730-1659#PDF page 43 — CyanogenMod/AOSP chain to OWASP Goat training systems|page 43]], [[Scanned_20260730-1659#PDF page 65 — Cloud-provider and identity architecture dated August 8, 2021|page 65]]. [[F-Droid|F-Droid]] is an open-source Android repository/client; [[TutuApp|Tutu]] is an alternative mobile-app distribution service; [[3C All-in-One Toolbox|3C All-in-One Toolbox]] is a device-management utility. `F-Droid.apk` uses the [[Android Application Package|APK]] package format; the source word `Toolbar` is normalized only outside the quotation to the known product spelling `Toolbox`. **Relationship overlay:** [[3C All-in-One Toolbox|3C All-in-One Toolbox]] · [[Adobe Typekit|Adobe Typekit]] · [[Amazon S3 Dual-stack Endpoint|Amazon S3 Dual-stack Endpoint]] · [[Android Application Package|Android Application Package]] · [[Android Open Source Project|Android Open Source Project]] · [[Android Package Name|Android Package Name]] · [[Android Rooting|Android Rooting]] · [[APKMirror|APKMirror]] · [[APKPure|APKPure]] · [[Auth0|Auth0]] · [[BidSwitch|BidSwitch]] · [[BLU Products|BLU Products]] · [[Box|Box]] · [[Browser Interception|Browser Interception]] · [[Car Home Ultra|Car Home Ultra]] · [[Cloud API|Cloud API]]. This evidence supplements rather than replaces earlier notebook interpretations. It connects the existing note to [[Identity Continuity|identity continuity]], [[Device Sovereignty|device sovereignty]], and [[Scanned_20260730-1659|Scanned_20260730-1659]]. ## Scanned_20260730-1806 overlay [[Scanned_20260730-1806|Scanned_20260730-1806]] moves supply-chain provenance into a single Android device. Pages 3 and 18–27 connect a Motorola build baseline to embedded Dagger and JSR 305/GWT resources, app-manager states, package IDs, manifests, shared UIDs, carrier libraries, ROM-era applications, F-Droid records, GitHub/Bitbucket repositories, forks, developer handles, and domains. The notebook supplies a manual provenance graph but lacks the cryptographic tuple needed to close it: exact artifact hashes, signing-certificate digests, installer, repository commit, dependency versions, factory-firmware comparison, and capture time. ## Scanned_20260730-1230 hardware-provenance overlay [[Scanned_20260730-1230]] extends the archive's provenance model from software into hardware. PDF page 28 exposes Qisda beneath Dell branding; page 21 binds a BYD battery to an LG handset; pages 24–25 bind an Asian Power Devices adapter to an Intel Compute Stick; page 32 records LOUD/Mackie board and fabrication identifiers. These are manufacturer and component relationships, not proof of purchase channel, authenticity, later modification, custody, compromise, or coordination. See [[Hardware Provenance]]. ## Scanned_20260730-1946 overlay [[Scanned_20260730-1946]] adds a source-era dependency graph—MacPorts/Homebrew through zlib, XZ, Zstandard, libxcb, WebP, Ghostscript, and D-Bus—and an explicit Tukaani URL. This is a manual provenance inquiry spanning package manager, transitive library, upstream project, and portable distribution media. **Owner-supplied retrospective clarification:** Bryant McGill states that the XZ/Tukaani attention was not neutral cataloguing. At the time of writing, he believed the dependency's role and placement were intentional and connected to a larger [[Surveillance|surveillance architecture]], before the 2024 backdoor was publicly disclosed. The later [[CVE-2024-3094]] incident makes XZ a powerful retrospective example of intentional upstream and release-chain subversion. It validates the strategic importance of the dependency layer but does not establish that the notebook identified the later operation: no source-era version, artifact hash, malicious build script, maintainer identity, payload, or runtime trace is recorded.