@AdamV2 Sure. Everything below is done on the HOST, with the VM fully shut down (not suspended), on a Finder duplicate of the VM so there is nothing to lose. Do it right after a failed attempt (black screen, then Stop), because that is when the file has both the old and the new firmware in it.
1. Open Terminal and go into the VM bundle. In Parallels the file is aux.bin inside the .macvm. In UTM it is Data/AuxiliaryStorage inside the .utm. Adjust the path to yours:
Code:
cd "/Volumes/YourDisk/Parallels/YourVM copy.macvm"
2. Back the file up first. This is the undo button:
Code:
cp -p aux.bin aux.bin.bak
3. Find the two firmware slots:
Code:
strings -a -t x aux.bin | grep -E '[im]Boot-[0-9]'
You should get two lines, like mine:
2401e mBoot-18000.161.10
22401e mBoot-20457.1.29
The number on the left is a hex offset. Each slot starts 0x1e before the version string, so 2401e means the slot starts at 0x24000 and 22401e means 0x224000. The one with 18000.x is the OLD firmware (good), the one with 20457.x is the NEW firmware (the problem). Which slot holds which can differ between VMs. Mine had old in the first slot and new in the second; Wade Tregaskis's VM was the other way round.
4. Convert the slot starts to 16 KB blocks: 0x24000 is block 9, 0x224000 is block 137. Those are the only two values you will ever see with this layout. Now copy the old slot over the new one. skip is the OLD slot's block, seek is the NEW slot's block:
Old in slot 1, new in slot 2 (my case):
Code:
dd if=aux.bin of=aux.bin bs=16384 skip=9 seek=137 count=128 conv=notrunc
New in slot 1, old in slot 2 (Wade's case):
Code:
dd if=aux.bin of=aux.bin bs=16384 skip=137 seek=9 count=128 conv=notrunc
count=128 is exactly 2 MB, the size of one slot. conv=notrunc is essential; without it dd truncates the file. Nothing outside the slot is touched, which is what keeps the NVRAM variables intact. Deleting NVRAM variables or wiping NVRAM does not fix this; only the firmware bytes matter.
5. Check it worked. Run the strings line from step 3 again. Both lines should now show 18000.161.10.
6. Boot the VM. Inside the guest run:
Code:
sysctl hw.memsize hw.memsize_usable
The two numbers should be within a few dozen MB of each other. If usable is around 1.8 GB the revert did not take. Then run Software Update again. For me it completed, and the guest ended up on 26.7 with the firmware still on 18000.161.10 and full memory.
If anything goes wrong at any point:
Code:
cp -p aux.bin.bak aux.bin
Two cases where you should stop and ask rather than run dd: the offsets in step 3 do not end in 01e, or the two are not exactly 0x200000 apart (that means a layout I have not seen). Or step 3 shows only ONE line and it says 20457: then the old firmware is not in the file any more and you need a pre-update copy of aux.bin, from Time Machine or from a Parallels snapshot's Snapshots/{GUID}.bin, and you copy block 9 from that file instead:
Code:
dd if=/path/to/old/aux.bin of=aux.bin bs=16384 skip=9 seek=137 count=128 conv=notrunc