Skip to content

Exporter (iCloud route): escrow record recovers, but only 1/21 shares unwrap (FindMy) — Manatee/ProtectedCloudStorage get no keys #245

Description

@wprzybyla

How are you running it?

CLI from source (uv run python -m exporter.cli --source icloud --no-password -vv -o airtag-export.zip)

Version, or commit

exporter 1.5.1, commit 335b258 (2026-09-19)

Operating system

Windows 11 Pro (26200), Python via uv

Which route?

Signing in to iCloud

What happened

Sign-in, SMS 2FA and the iPhone screen-lock passcode all succeed and the escrow record is recovered, but only the FindMy view share unwraps (1/21). Manatee and ProtectedCloudStorage yield no keys, so zone_keys() fails with KeychainSessionError: No keychain keys are held.

Account: one iPhone 13 (iOS 26.6.2) is the only device; the item to export is a third-party Find My accessory (Silver Monkey TAG iOS) owned by this account. Advanced Data Protection: off during the failing runs (it was later switched on and off again).

Same result before and after refreshing the escrow record by changing the iPhone passcode (escrow date went from 2025-05-23 to 2026-10-03; the recovered record label stayed the same).

After the ADP on/off cycle the result is identical (still 1/21); the trust listing then shows 5 changes and a second peer (<peer-C>) that also "carries no signing key", while the trust circle still holds 1 peer.

Possibly related to #140: the recovered peer id is the escrow label (<peer-A>), while the trust circle holds a single, different peer (<peer-B>) that "carries no signing key".

The log (identifiers replaced)

INFO     findmy.keychain.cuttlefish: Cuttlefish reports 1 viable bottle(s) and 2 partial
INFO     findmy.keychain.escrow: Account holds 5 escrow record(s), 3 of them recoverable
INFO     findmy.keychain.escrow: 2 escrow record(s) are described but not recoverable from, which is ordinary residue rather than a fault.
? Which device's passcode do you have? iPhone, iPhone 13, serial <serial>, escrowed 2026-10-03
INFO     findmy.keychain.recovery: Beginning escrow recovery for com.apple.icdp.record.<peer-A>
DEBUG    findmy.keychain.recovery: srp_init framing: prefix 00000180, header <redacted>, section lengths [8, 64, 256]
INFO     findmy.keychain.recovery: Recovered 715 bytes of sealed material from com.apple.icdp.record.<peer-A>
WARNING  findmy.keychain.peers: Peer <peer-B> carries no signing key
DEBUG    findmy.keychain.peers: Trust page 1: 4 change(s), 1 peer(s) added
DEBUG    findmy.keychain.peers: Trust page 2: 0 change(s), 0 peer(s) added
INFO     findmy.keychain.peers: Trust circle holds 1 peer(s)
INFO     findmy.keychain.shares: Peer <peer-A> is entitled to 22 share(s)
INFO     findmy.keychain.shares: Entry for SE-PTC carries no readable share record. Nothing here reads that view, so this affects nothing.
INFO     findmy.keychain.shares: Read 21 share(s) across views: ApplePay, Applications, AutoUnlock, Backstop, Contacts, CreditCards, DevicePairing, Engram, FindMy, Groups, Health, Home, LimitedPeersAllowed, MFi, Mail, Manatee, Passwords, Photos, ProtectedCloudStorage, SecureObjectSync, WiFi
DEBUG    findmy.keychain.bottle: Peer key layout is point-then-scalar
DEBUG    findmy.keychain.bottle: Peer key layout is point-then-scalar
INFO     findmy.keychain.session: Shares for <peer-A>: 1/21 unwrapped; views: ... (as above)
WARNING  findmy.keychain.session: Could not read the Manatee view: No keys were recovered for the 'Manatee' view, so its items cannot be read. Views that did yield keys: FindMy
WARNING  findmy.keychain.session: Could not read the ProtectedCloudStorage view: No keys were recovered for the 'ProtectedCloudStorage' view, so its items cannot be read. Views that did yield keys: FindMy
INFO     findmy.keychain.session: 0 elliptic-curve key(s) across Manatee, ProtectedCloudStorage
  File "exporter\cli.py", line 870, in run
  File "exporter\cli.py", line 845, in read_icloud
  File "exporter\icloud.py", line 841, in fetch
    zone_keys = await client.zone_keys()
  File "findmy\icloud.py", line 232, in zone_keys
  File "findmy\icloud.py", line 353, in _require_keys
findmy.keychain.session.KeychainSessionError: No keychain keys are held, so nothing can be decrypted.

Before you post

  • I have read the log and replaced identifying values (serial, peer hashes, Apple ID, CloudKit user ids).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    @appIssues regarding the OpenTagViewer Android app@exporter-toolIssues regarding the desktop export tool (wizard and CLI)bugSomething isn't working

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions