Target Board & Base Firmware
Pick your board model. If you haven't flashed the base firmware yet, hold BOOTSEL on your board, plug it in, and copy the .uf2 file to the RPI-RP2 drive.
Flash Boot Payload (iBSS.boot)
Provide the iBSS.boot stitched payload generated for your device (e.g. from surrealra1n). The tool compresses it in-browser with LZ4 and writes it to flash offset 0x10020000 over USB Serial.
iBSS.boot
Typically 2.0 – 2.8 MB raw payload
LED Operating Guide
Once flashed, SurrealBoot runs standalone without a computer. Connect the RP2350 to power, plug in the iPhone, and follow the RGB LED states:
-
Solid OrangeIdle / Listening for USB host connection.
-
Solid Magenta (Countdown)Recovery detected. Hold Volume Down + Power. Board injects reboot packet at tick 2.
-
Solid CyanRelease Power, keep holding Volume Down for 8s.
-
Blinking WhiteRelease all buttons. Waiting for DFU enumeration.
-
Solid BlueRunning USBLiter8 exploit.
-
Solid GreenBoot payload streamed to memory. iPhone boots!
Hardware Notes
Waveshare RP2350 USB-A
The USB-A female port is wired directly to VSYS for 5V power and GP12/13 for data. Our firmware automatically handles the board's onboard R13 resistor with active USB bus resets.
Cables & Connection
Use a standard USB-A to Lightning cable connected between the board's USB-A host port and the iPhone. Keep the board powered via USB-C or 5V pin.