Purpose of Secure Kernel’s special SPTM gate calls
Determine the purpose and semantics of the Secure Kernel’s special SPTM gate invocations with x16 values 0xff00000000, 0xfe00000000, and 0xfd00000000, including the significance of the pre-call zeroing of general-purpose registers and NEON vectors.
References
Without examining the SPTM handling side of these calls, we cannot yet deduce any clear meaning from them.
— Modern iOS Security Features -- A Deep Dive into SPTM, TXM, and Exclaves
(2510.09272 - Steffin et al., 10 Oct 2025) in Section Calls from the Secure Kernel, paragraph “Special Secure Kernel SPTM Gate”