![]() |
vitasdk
Documentation of the vitasdk
|
Exports for Kernel. More...
Data Structures | |
| struct | SceSblActivationKey |
| struct | SceSblSpsfoContext |
| An SPSFO file mapped by ksceSblSpsfoMgrOpen. More... | |
| struct | SceSblAppKey |
| struct | SceUtoken |
| struct | SceUtokenSelfAuthInfo |
| Complete SELF authorization override stored in Utoken segment type 11. More... | |
| struct | SceSblSealedKey |
| struct | SceSblKeystone |
| struct | SceSblDebugKeystone |
| struct | SceSblCloudDataKeyRing |
| struct | SceSblCloudDataRsaValue |
| struct | SceSblCloudDataSignCryptHandle |
| struct | SceSblRsaDataParam |
| struct | SceSblRsaPublicKeyParam |
| struct | SceSblRsaPrivateKeyParam |
Typedefs | |
| typedef SceSblSpsfoContext | SceSblSpfsoContext |
| Misspelled alias retained for backwards compatibility. | |
Enumerations | |
| enum | SceSblProductMode { SCE_SBL_PRODUCT_MODE_NORMAL = 0 , SCE_SBL_PRODUCT_MODE_MANUFACTURING = 1 } |
| Product modes reported by SceSblPmMgr. More... | |
| enum | SceSblLicenseStatus { SCE_SBL_LICENSE_STATUS_UNINITIALIZED = -1 , SCE_SBL_LICENSE_STATUS_ACTIVATED = 0 , SCE_SBL_LICENSE_STATUS_EXPIRED = 1 , SCE_SBL_LICENSE_STATUS_BACKUP_BATTERY_FAILURE = 2 } |
| Cached development/testing-kit activation states reported by SceSblLicMgr. More... | |
| enum | SceSblRsaHashType { SCE_SBL_RSA_HASH_TYPE_MD2 = 0x2 , SCE_SBL_RSA_HASH_TYPE_MD5 = 0x4 , SCE_SBL_RSA_HASH_TYPE_SHA1 = 0x5 , SCE_SBL_RSA_HASH_TYPE_SHA256 = 0xB , SCE_SBL_RSA_HASH_TYPE_SHA384 = 0xC , SCE_SBL_RSA_HASH_TYPE_SHA512 = 0xD , SCE_SBL_RSA_HASH_TYPE_SHA224 = 0xE } |
| Hash algorithms accepted by the RSA PKCS #1 v1.5 helpers. More... | |
Functions | |
| VITASDK_BUILD_ASSERT_EQ (0x14, SceSblActivationKey) | |
| VITASDK_BUILD_ASSERT_EQ (0xC, SceSblSpsfoContext) | |
| VITASDK_BUILD_ASSERT_EQ (0x24, SceSblAppKey) | |
| VITASDK_BUILD_ASSERT_EQ (0x800, SceUtoken) | |
| VITASDK_BUILD_ASSERT_EQ (0x58, SceUtokenSelfAuthInfo) | |
| VITASDK_BUILD_ASSERT_EQ (0x50, SceSblSealedKey) | |
| VITASDK_BUILD_ASSERT_EQ (0x60, SceSblKeystone) | |
| VITASDK_BUILD_ASSERT_EQ (0x40, SceSblDebugKeystone) | |
| VITASDK_BUILD_ASSERT_EQ (0x2A0, SceSblCloudDataKeyRing) | |
| VITASDK_BUILD_ASSERT_EQ (0x104, SceSblCloudDataRsaValue) | |
| VITASDK_BUILD_ASSERT_EQ (0x208, SceSblCloudDataSignCryptHandle) | |
| VITASDK_BUILD_ASSERT_EQ (8, SceSblRsaDataParam) | |
| VITASDK_BUILD_ASSERT_EQ (8, SceSblRsaPublicKeyParam) | |
| VITASDK_BUILD_ASSERT_EQ (0x24, SceSblRsaPrivateKeyParam) | |
| int | ksceSblRSA2048CreateSignature (SceSblRsaDataParam *rsa_signature, SceSblRsaDataParam *hash, SceSblRsaPrivateKeyParam *private_key, int type) |
| Create an RSA-2048 signature. | |
| int | ksceSblRSA2048VerifySignature (SceSblRsaDataParam *rsa_signature, SceSblRsaDataParam *hash, SceSblRsaPublicKeyParam *public_key, int type) |
| Verify an RSA-2048 signature. | |
| int | ksceSblCoredumpKeyStoreInitialize (void) |
| Initialize the coredump key store. | |
| int | ksceSblCoredumpKeyStoreFinalize (void) |
| Securely clear and finalize the coredump key store. | |
| int | ksceSblCoredumpGetHmacKey (SceUInt32 key_id, SceSize key_size, void *key) |
| Get a coredump HMAC-SHA-256 key. | |
| int | ksceSblCoredumpGetAesKey (SceUInt32 key_id, SceSize key_size, void *key) |
| Get a coredump AES-128 key. | |
| int | ksceSblPostSsMgrEncryptSealedkey (SceSblSealedKey *sealed_key) |
| Create a sealed-key blob containing a newly generated secret. | |
| int | ksceSblPostSsMgrDecryptSealedkey (const SceSblSealedKey *sealed_key, SceUInt8 *secret) |
| Authenticate a sealed-key blob and decrypt its secret. | |
| int | ksceSblPostSsMgrDebugEncryptKeystone (const SceUInt8 *secret, SceSblDebugKeystone *keystone) |
| Encrypt a secret into a debug keystone. | |
| int | ksceSblPostSsMgrDebugDecryptKeystone (const SceSblDebugKeystone *keystone, SceUInt8 *secret) |
| Validate the header and decrypt a debug keystone. | |
| int | ksceSblPostSsMgrVerifyKeystone (const SceSblKeystone *keystone, int version) |
| Verify a keystone without a passcode. | |
| int | ksceSblPostSsMgrVerifyKeystoneWithPasscode (const SceSblKeystone *keystone, const SceUInt8 *passcode) |
| Verify a keystone using a passcode. | |
| int | ksceSblPostSsMgrGenerateAppKey (const SceSblAppKey *input, SceSblAppKey *output) |
| Transform an application key using the portability key. | |
| int | ksceSblSsMgrCloudDataGetEncDecCryptHandle (SceSblCloudDataKeyRing *key_ring) |
| Get the cloud-data encryption and decryption key ring. | |
| int | ksceSblSsMgrCloudDataGetSignCryptHandle (SceUInt32 mode, SceUInt32 index, SceSblCloudDataSignCryptHandle *handle) |
| Get one cloud-data RSA signing handle. | |
| int | ksceSblSsMgrCloudDataStop (void) |
| Securely clear the cloud-data encryption and signing key rings. | |
| int | ksceSblFwLoaderLoad (int e_phnum, void *destination, SceSize max_size, SceSize *loaded_size) |
| Load an authenticated firmware image. | |
| int | ksceSblFwLoaderLock (const char *path, int reserved) |
| Lock and authenticate a firmware image. | |
| int | ksceSblFwLoaderUnlock (void) |
| Release the firmware-loader lock and discard the saved path. | |
| int | ksceSblLicMgrGetActivationKey (SceSblActivationKey *key) |
| Get the activation key. | |
| int | ksceSblLicMgrGetLicenseStatus (void) |
| Get the cached license state. | |
| int | ksceSblLicMgrActivateDevkit (const char *afv_path) |
| Activate a development kit from an activation file. | |
| int | ksceSblLicMgrGetExpireDate (int *expire_date, SceBool read_from_nvs) |
| Get the cached activation expiration time or refresh it from NVS. | |
| int | ksceSblPmMgrSetSdModeOff (SceUInt32 reserved) |
| Disable SD mode through the PM secure module. | |
| int | ksceSblPmMgrSetProductMode (SceBool enable) |
| Enter or leave manufacturing mode through the PM secure module. | |
| int | ksceSblPmMgrGetProductModeFromNVS (SceUInt8 *product_mode) |
| Read the raw product-mode byte from NVS through the PM secure module. | |
| int | ksceSblPmMgrAuthEtoI (void) |
Perform the EtoI jig-authentication exchange through pm_sm_sd.self. | |
| int | ksceSblRtcMgrSetCpRtcPhysical (int rtc) |
| Set the 32-bit CP physical RTC value. | |
| int | ksceSblRtcMgrSetCpRtcLogical (int rtc) |
| Set the CP logical RTC. | |
| int | ksceSblRtcMgrGetCpRtcLogical (int *rtc) |
| Get the 32-bit CP logical RTC value. | |
| int | ksceSblRtcMgrGetCpRtcPhysical (int *rtc) |
| Get the 32-bit CP physical RTC value. | |
| int | ksceSblSpsfoMgrOpen (const char *path, SceSblSpsfoContext *context) |
| Open an SPSFO file in a mapped memory block. | |
| int | ksceSblSpsfoMgrClose (SceSblSpsfoContext *context) |
| Close an SPSFO context and release its mapped memory block. | |
| int | ksceSblSpsfoMgrVerify (SceSblSpsfoContext *context, void **payload, SceSize *payload_size) |
| Verify an opened SPSFO file. | |
| int | ksceSblUtMgrVerifyAndStoreUtoken (const SceUtoken *utoken, SceSize size) |
| Verify an encrypted Utoken and write it to storage. | |
| int | ksceSblUtMgrGetSelfAuthInfo (SceUtokenSelfAuthInfo *self_auth_info) |
| Get the Utoken type-11 self-authorization override. | |
| int | ksceSblUtMgrHasComTestFlag (void) |
| Check whether the initialized Utoken contains a COM-test PAID. | |
| int | ksceSblUtMgrHasNpTestFlag (void) |
| Check whether NP-test policy is enabled. | |
| int | ksceSblUtMgrHasStoreFlag (void) |
| Check whether Utoken flag bit 4 enables Store-mode policy. | |
| int | ksceSblUtMgrHasFlag1 (void) |
| Get Utoken flag bit 1. | |
| int | ksceSblUtMgrHasFlag6 (void) |
| Get Utoken flag bit 6. | |
| int | ksceSblUtMgrHasFlag7 (void) |
| Get Utoken flag bit 7. | |
| int | ksceSblUtMgrHasFlag8 (void) |
| Get Utoken flag bit 8. | |
| int | ksceSblUtMgrHasFlag9 (void) |
| Get Utoken flag bit 9. | |
| SceBool | ksceSblUtMgrIsAllowComTest (SceUID pid) |
| Check whether a process is allowed to use COM test mode. | |
| SceBool | ksceSblUtMgrIsAllowProgramDebug (SceUInt64 program_authority_id) |
| Check whether a program authority ID is in the Utoken debug whitelist. | |
| int | ksceSblUtMgrResetUtokenFile (void) |
| Overwrite and remove the stored Utoken file. | |
Exports for Kernel.
Include the header file in your project:
Include the header file in your project:
Link the library to the executable:
| struct SceSblActivationKey |
| Data Fields | ||
|---|---|---|
| SceUInt8 | open_psid[0x10] | A SceOpenPsId value. |
| SceUInt32 | vadd_hash | Four byte-wise sums of the OpenPSID lanes. |
| struct SceSblSpsfoContext |
An SPSFO file mapped by ksceSblSpsfoMgrOpen.
| Data Fields | ||
|---|---|---|
| SceUID | mem_uid | Memory block UID. |
| void * | mem_block_base | Mapped memory block base address. |
| SceSize | file_size | Exact SPSFO file size. |
| struct SceSblAppKey |
| struct SceUtoken |
| Data Fields | ||
|---|---|---|
| SceUInt8 | encrypted_data[0x800] | Encrypted Utoken file contents. |
| struct SceUtokenSelfAuthInfo |
Complete SELF authorization override stored in Utoken segment type 11.
| Data Fields | ||
|---|---|---|
| SceUInt64 | program_authority_id | Replacement program authority ID. |
| SceUInt8 | capability[0x20] | Replacement capability bits. |
| SceUInt8 | attribute[0x20] | Replacement attribute bits. |
| SceUInt8 | shared_secret[0x10] | Replacement shared secret. |
| struct SceSblSealedKey |
| Data Fields | ||
|---|---|---|
| char | magic[8] | Must be "pfsSKKey". |
| SceUInt8 | major_version | Set to 2 when generated; legacy values 0 and 1 are also accepted. |
| SceUInt8 | minor_version | Must be 0 for the supported versions. |
| SceUInt8 | reserved[6] | Set to 0 by ksceSblPostSsMgrEncryptSealedkey. |
| SceUInt8 | iv[0x10] | |
| SceUInt8 | encrypted_key[0x10] | |
| SceUInt8 | hmac[0x20] | |
| struct SceSblKeystone |
| struct SceSblDebugKeystone |
| struct SceSblCloudDataKeyRing |
| Data Fields | ||
|---|---|---|
| char | magic[8] | Magic value "CloudBU" followed by a NUL byte. |
| SceUInt32 | version | Supported values are 0 and 1. |
| SceUInt8 | opaque_header_data[4] | Copied unchanged; not interpreted by the FW 3.60 implementation or known importer. |
| SceUInt8 | p[0x80] | RSA prime p. |
| SceUInt8 | q[0x80] | RSA prime q. |
| SceUInt8 | dp[0x80] | d mod (p - 1). |
| SceUInt8 | dq[0x80] | d mod (q - 1). |
| SceUInt8 | qp[0x80] | q^-1 mod p. |
| SceUInt8 | opaque_trailer_data[0x10] | Copied unchanged; not interpreted by the FW 3.60 implementation or known importer. |
| struct SceSblCloudDataRsaValue |
| struct SceSblCloudDataSignCryptHandle |
| Data Fields | ||
|---|---|---|
| SceSblCloudDataRsaValue | modulus | |
| SceSblCloudDataRsaValue | exponent | |
| struct SceSblRsaDataParam |
| struct SceSblRsaPublicKeyParam |
| struct SceSblRsaPrivateKeyParam |
| #define ksceSblPostSsMgrActivate ksceSblLicMgrActivateDevkit |
| #define ksceSblPostSsMgrGetExpireDate ksceSblLicMgrGetExpireDate |
| #define _ksceSblPostSsMgrExecutePmSmF00dCommand ksceSblPmMgrSetSdModeOff |
| #define ksceSblPostSsMgrExecutePmSmF00dCommand ksceSblPmMgrSetProductMode |
| #define ksceSblPostSsMgrExecutePmSmF00dCommand8 ksceSblPmMgrGetProductModeFromNVS |
| #define ksceSblPostSsMgrExecutePmSmSdF00dCommand ksceSblPmMgrAuthEtoI |
| #define ksceSblPostSsMgrSetCpRtc ksceSblRtcMgrSetCpRtcPhysical |
| #define ksceSblPostSsMgrInitializeSpfsoCtx ksceSblSpsfoMgrOpen |
| #define ksceSblPostSsMgrReleaseSpfsoCtx ksceSblSpsfoMgrClose |
| #define ksceSblPostSsMgrVerifySpfsoCtx ksceSblSpsfoMgrVerify |
| #define ksceSblUtMgrExecuteUtokenSmCommand1 ksceSblUtMgrVerifyAndStoreUtoken |
| #define ksceSblUtMgrGetTrilithiumBuffer ksceSblUtMgrGetSelfAuthInfo |
| #define ksceSblUtMgrHasPSMTestFlag ksceSblUtMgrHasFlag1 |
| #define ksceSblUtMgrHasSystemDataFilePlayReadyFlag ksceSblUtMgrHasFlag8 |
| typedef SceSblSpsfoContext SceSblSpfsoContext |
Misspelled alias retained for backwards compatibility.
| enum SceSblProductMode |
| enum SceSblLicenseStatus |
| enum SceSblRsaHashType |
| VITASDK_BUILD_ASSERT_EQ | ( | 0x14 | , |
| SceSblActivationKey | |||
| ) |
| VITASDK_BUILD_ASSERT_EQ | ( | 0xC | , |
| SceSblSpsfoContext | |||
| ) |
| VITASDK_BUILD_ASSERT_EQ | ( | 0x24 | , |
| SceSblAppKey | |||
| ) |
| VITASDK_BUILD_ASSERT_EQ | ( | 0x800 | , |
| SceUtoken | |||
| ) |
| VITASDK_BUILD_ASSERT_EQ | ( | 0x58 | , |
| SceUtokenSelfAuthInfo | |||
| ) |
| VITASDK_BUILD_ASSERT_EQ | ( | 0x50 | , |
| SceSblSealedKey | |||
| ) |
| VITASDK_BUILD_ASSERT_EQ | ( | 0x60 | , |
| SceSblKeystone | |||
| ) |
| VITASDK_BUILD_ASSERT_EQ | ( | 0x40 | , |
| SceSblDebugKeystone | |||
| ) |
| VITASDK_BUILD_ASSERT_EQ | ( | 0x2A0 | , |
| SceSblCloudDataKeyRing | |||
| ) |
| VITASDK_BUILD_ASSERT_EQ | ( | 0x104 | , |
| SceSblCloudDataRsaValue | |||
| ) |
| VITASDK_BUILD_ASSERT_EQ | ( | 0x208 | , |
| SceSblCloudDataSignCryptHandle | |||
| ) |
| VITASDK_BUILD_ASSERT_EQ | ( | 8 | , |
| SceSblRsaDataParam | |||
| ) |
| VITASDK_BUILD_ASSERT_EQ | ( | 8 | , |
| SceSblRsaPublicKeyParam | |||
| ) |
| VITASDK_BUILD_ASSERT_EQ | ( | 0x24 | , |
| SceSblRsaPrivateKeyParam | |||
| ) |
| int ksceSblRSA2048CreateSignature | ( | SceSblRsaDataParam * | rsa_signature, |
| SceSblRsaDataParam * | hash, | ||
| SceSblRsaPrivateKeyParam * | private_key, | ||
| int | type | ||
| ) |
Create an RSA-2048 signature.
| [out] | rsa_signature | - Receives a 0x100-byte signature. |
| [in] | hash | - Hash to sign. |
| [in] | private_key | - RSA private key. |
| [in] | type | - One of SceSblRsaHashType. Declared as an integer for backwards compatibility. |
| int ksceSblRSA2048VerifySignature | ( | SceSblRsaDataParam * | rsa_signature, |
| SceSblRsaDataParam * | hash, | ||
| SceSblRsaPublicKeyParam * | public_key, | ||
| int | type | ||
| ) |
Verify an RSA-2048 signature.
| [in] | rsa_signature | - 0x100-byte signature. |
| [in] | hash | - Hash to verify. |
| [in] | public_key | - RSA modulus and exponent. |
| [in] | type | - One of SceSblRsaHashType. Declared as an integer for backwards compatibility. |
| int ksceSblCoredumpKeyStoreInitialize | ( | void | ) |
Initialize the coredump key store.
| int ksceSblCoredumpKeyStoreFinalize | ( | void | ) |
Securely clear and finalize the coredump key store.
Get a coredump HMAC-SHA-256 key.
| [in] | key_id | - Key ID from 1 through 3. |
| [in] | key_size | - Must be 0x20. |
| [out] | key | - Receives the key. |
Get a coredump AES-128 key.
| [in] | key_id | - Key ID from 1 through 4, 0x10000001, or 0x10000002. |
| [in] | key_size | - Must be 0x10. |
| [out] | key | - Receives the key. |
| int ksceSblPostSsMgrEncryptSealedkey | ( | SceSblSealedKey * | sealed_key | ) |
Create a sealed-key blob containing a newly generated secret.
| [out] | sealed_key | - Receives a SceSblSealedKey structure. |
| int ksceSblPostSsMgrDecryptSealedkey | ( | const SceSblSealedKey * | sealed_key, |
| SceUInt8 * | secret | ||
| ) |
Authenticate a sealed-key blob and decrypt its secret.
| [in] | sealed_key | - Sealed-key blob to decrypt. |
| [out] | secret | - Receives exactly 0x10 bytes. |
| int ksceSblPostSsMgrDebugEncryptKeystone | ( | const SceUInt8 * | secret, |
| SceSblDebugKeystone * | keystone | ||
| ) |
Encrypt a secret into a debug keystone.
| [in] | secret | - Exactly 0x20 input bytes. |
| [out] | keystone | - Receives a SceSblDebugKeystone structure. |
| int ksceSblPostSsMgrDebugDecryptKeystone | ( | const SceSblDebugKeystone * | keystone, |
| SceUInt8 * | secret | ||
| ) |
Validate the header and decrypt a debug keystone.
Unlike ksceSblPostSsMgrVerifyKeystone, this function does not authenticate the encrypted data or check the version or reserved fields.
| [in] | keystone | - Debug keystone to decrypt. |
| [out] | secret | - Receives exactly 0x20 bytes. |
| int ksceSblPostSsMgrVerifyKeystone | ( | const SceSblKeystone * | keystone, |
| int | version | ||
| ) |
Verify a keystone without a passcode.
| [in] | keystone | - Keystone to verify. |
| [in] | version | - Expected SceSblKeystone::version value. Must be 0 or 1. |
| int ksceSblPostSsMgrVerifyKeystoneWithPasscode | ( | const SceSblKeystone * | keystone, |
| const SceUInt8 * | passcode | ||
| ) |
Verify a keystone using a passcode.
| [in] | keystone | - Keystone to verify. |
| [in] | passcode | - Exactly 0x20 passcode bytes. |
| int ksceSblPostSsMgrGenerateAppKey | ( | const SceSblAppKey * | input, |
| SceSblAppKey * | output | ||
| ) |
Transform an application key using the portability key.
| [in] | input | - Input key. Its size must be 0x10 or 0x20. |
| [out] | output | - Receives the transformed key and copied size. |
| int ksceSblSsMgrCloudDataGetEncDecCryptHandle | ( | SceSblCloudDataKeyRing * | key_ring | ) |
Get the cloud-data encryption and decryption key ring.
| [out] | key_ring | - Receives a SceSblCloudDataKeyRing structure. |
| int ksceSblSsMgrCloudDataGetSignCryptHandle | ( | SceUInt32 | mode, |
| SceUInt32 | index, | ||
| SceSblCloudDataSignCryptHandle * | handle | ||
| ) |
Get one cloud-data RSA signing handle.
| [in] | mode | - Must be 1. |
| [in] | index | - Handle index, 0 or 1. |
| [out] | handle | - Receives the modulus and exponent. |
| int ksceSblSsMgrCloudDataStop | ( | void | ) |
Securely clear the cloud-data encryption and signing key rings.
| int ksceSblFwLoaderLoad | ( | int | e_phnum, |
| void * | destination, | ||
| SceSize | max_size, | ||
| SceSize * | loaded_size | ||
| ) |
Load an authenticated firmware image.
Call ksceSblFwLoaderLock first and ksceSblFwLoaderUnlock afterward. On FW 3.60, the saved path can be used for only one load attempt. To load another image, repeat the lock/load/unlock sequence.
| [in] | e_phnum | - Must be 1 on FW 3.60. |
| [out] | destination | - Destination buffer. |
| [in] | max_size | - Destination capacity. |
| [out] | loaded_size | - Receives the number of bytes loaded. |
| int ksceSblFwLoaderLock | ( | const char * | path, |
| int | reserved | ||
| ) |
Lock and authenticate a firmware image.
This function acquires the module's shared lock, which is held until ksceSblFwLoaderUnlock is called.
| [in] | path | - NUL-terminated firmware SELF path of at most 255 bytes. |
| [in] | reserved | - Must be zero on FW 3.60. |
| int ksceSblFwLoaderUnlock | ( | void | ) |
Release the firmware-loader lock and discard the saved path.
| int ksceSblLicMgrGetActivationKey | ( | SceSblActivationKey * | key | ) |
Get the activation key.
| [out] | key | - Receives a SceSblActivationKey structure. |
| int ksceSblLicMgrGetLicenseStatus | ( | void | ) |
Get the cached license state.
| int ksceSblLicMgrActivateDevkit | ( | const char * | afv_path | ) |
Activate a development kit from an activation file.
| [in] | afv_path | - NUL-terminated path, at most 255 bytes excluding the terminating NUL. FW 3.60 accepts paths under host0:, ux0:/data/activate/, and ur0:/temp/activation. |
| int ksceSblLicMgrGetExpireDate | ( | int * | expire_date, |
| SceBool | read_from_nvs | ||
| ) |
Get the cached activation expiration time or refresh it from NVS.
| [out] | expire_date | - When read_from_nvs is zero, receives the cached absolute expiration time. Otherwise receives the refreshed number of seconds remaining. |
| [in] | read_from_nvs | - Nonzero reads and verifies the NVS activation data. |
| int ksceSblPmMgrSetSdModeOff | ( | SceUInt32 | reserved | ) |
Disable SD mode through the PM secure module.
| [in] | reserved | - Must be zero on FW 3.60. |
| int ksceSblPmMgrSetProductMode | ( | SceBool | enable | ) |
Enter or leave manufacturing mode through the PM secure module.
Only bit 0 of enable is used on FW 3.60. The boot-time cached value returned by the user getters is not updated.
| [in] | enable | - Nonzero to enter manufacturing mode; zero to leave it. |
| int ksceSblPmMgrGetProductModeFromNVS | ( | SceUInt8 * | product_mode | ) |
Read the raw product-mode byte from NVS through the PM secure module.
Values written by the FW 3.60 product-mode operations correspond to SceSblProductMode.
| [out] | product_mode | - Receives exactly one byte. |
| int ksceSblPmMgrAuthEtoI | ( | void | ) |
Perform the EtoI jig-authentication exchange through pm_sm_sd.self.
| int ksceSblRtcMgrSetCpRtcPhysical | ( | int | rtc | ) |
Set the 32-bit CP physical RTC value.
| [in] | rtc | - New physical RTC value. |
| int ksceSblRtcMgrSetCpRtcLogical | ( | int | rtc | ) |
Set the CP logical RTC.
| [in] | rtc | - Logical RTC value on implementations that support the operation. |
| int ksceSblRtcMgrGetCpRtcLogical | ( | int * | rtc | ) |
Get the 32-bit CP logical RTC value.
| [out] | rtc | - Receives the logical RTC value. |
| int ksceSblRtcMgrGetCpRtcPhysical | ( | int * | rtc | ) |
Get the 32-bit CP physical RTC value.
| [out] | rtc | - Receives the physical RTC value. |
| int ksceSblSpsfoMgrOpen | ( | const char * | path, |
| SceSblSpsfoContext * | context | ||
| ) |
Open an SPSFO file in a mapped memory block.
FW 3.60 accepts files up to 0x8000 bytes on gro0:, ur0:, and ux0:. host0: is accepted on non-CEX systems when QAF permits host access.
| [in] | path | - NUL-terminated SPSFO path of at most 255 bytes. |
| [out] | context | - Receives the opened context. |
| int ksceSblSpsfoMgrClose | ( | SceSblSpsfoContext * | context | ) |
Close an SPSFO context and release its mapped memory block.
The context is not cleared after its memory block is released.
| [in,out] | context | - Context returned by ksceSblSpsfoMgrOpen. |
| int ksceSblSpsfoMgrVerify | ( | SceSblSpsfoContext * | context, |
| void ** | payload, | ||
| SceSize * | payload_size | ||
| ) |
Verify an opened SPSFO file.
The returned payload points inside the context's mapped memory and remains valid only until ksceSblSpsfoMgrClose is called. AuthMgr requires the mapped base address to be 0x20-byte aligned. It verifies the file through secure command 8 before the payload is returned.
| [in] | context | - Context returned by ksceSblSpsfoMgrOpen. |
| [out] | payload | - Receives the verified payload address. |
| [out] | payload_size | - Receives the verified payload size in bytes. |
Verify an encrypted Utoken and write it to storage.
| [in] | utoken | - Encrypted Utoken. |
| [in] | size | - Must be at least 0x800; exactly 0x800 bytes are used. |
| int ksceSblUtMgrGetSelfAuthInfo | ( | SceUtokenSelfAuthInfo * | self_auth_info | ) |
Get the Utoken type-11 self-authorization override.
The output pointer must be non-NULL. FW 3.60 returns 0x800F1A02 when the initialized Utoken does not contain a valid type-11 segment. AuthMgr uses this override after SELF authentication for programs in the 0x2F0 PAID family, replacing the program authority ID, capability, attribute, and shared-secret fields together.
| [out] | self_auth_info | - Receives a SceUtokenSelfAuthInfo structure. |
| int ksceSblUtMgrHasComTestFlag | ( | void | ) |
Check whether the initialized Utoken contains a COM-test PAID.
| int ksceSblUtMgrHasNpTestFlag | ( | void | ) |
Check whether NP-test policy is enabled.
This is enabled by Utoken flag bit 11 or by the Utoken name UT_TRILITHIUM_FLAG on FW 3.60.
| int ksceSblUtMgrHasStoreFlag | ( | void | ) |
Check whether Utoken flag bit 4 enables Store-mode policy.
Callers use this flag for Store-specific DRM/save-data policy, privileged update authorization, and the alternate advertisement-network clock.
| int ksceSblUtMgrHasFlag1 | ( | void | ) |
Get Utoken flag bit 1.
SceSblACMgr uses this as an additional permission for selected FSELF operations, including PSM-program, USB-serial, and virtual-machine policy.
| int ksceSblUtMgrHasFlag6 | ( | void | ) |
Get Utoken flag bit 6.
SceSblUpdateMgr accepts this flag alongside QAF, COM-test, and Store authorization for update containers marked as requiring privileged update policy.
| int ksceSblUtMgrHasFlag7 | ( | void | ) |
Get Utoken flag bit 7.
AppMgr uses this flag to allow save-data mounting to continue when keystone verification fails.
| int ksceSblUtMgrHasFlag8 | ( | void | ) |
Get Utoken flag bit 8.
SceSblACMgr uses this as the FSELF fallback for its capability-134 policy. The broader purpose of the flag is unknown.
| int ksceSblUtMgrHasFlag9 | ( | void | ) |
Get Utoken flag bit 9.
AppMgr requires this flag for the PAID-specific operation that mounts a special save-data path and reads its ACCOUNT_ID.
Check whether a process is allowed to use COM test mode.
| [in] | pid | - Process whose program authority ID is checked. |
Check whether a program authority ID is in the Utoken debug whitelist.
| [in] | program_authority_id | - Nonzero program authority ID to check against the 32-entry whitelist. |
| int ksceSblUtMgrResetUtokenFile | ( | void | ) |
Overwrite and remove the stored Utoken file.
Already parsed Utoken flags remain cached on FW 3.60 until the module is reinitialized.
| SceUInt8 SceSblActivationKey::open_psid[0x10] |
A SceOpenPsId value.
| SceUInt32 SceSblActivationKey::vadd_hash |
Four byte-wise sums of the OpenPSID lanes.
| SceUID SceSblSpsfoContext::mem_uid |
Memory block UID.
| void* SceSblSpsfoContext::mem_block_base |
Mapped memory block base address.
| SceSize SceSblSpsfoContext::file_size |
Exact SPSFO file size.
| SceSize SceSblAppKey::size |
Number of valid key bytes. Must be 0x10 or 0x20.
| SceUInt8 SceSblAppKey::key[0x20] |
Key data.
| SceUInt8 SceUtoken::encrypted_data[0x800] |
Encrypted Utoken file contents.
| SceUInt64 SceUtokenSelfAuthInfo::program_authority_id |
Replacement program authority ID.
| SceUInt8 SceUtokenSelfAuthInfo::capability[0x20] |
Replacement capability bits.
| SceUInt8 SceUtokenSelfAuthInfo::attribute[0x20] |
Replacement attribute bits.
| SceUInt8 SceUtokenSelfAuthInfo::shared_secret[0x10] |
Replacement shared secret.
| char SceSblSealedKey::magic[8] |
Must be "pfsSKKey".
| SceUInt8 SceSblSealedKey::major_version |
Set to 2 when generated; legacy values 0 and 1 are also accepted.
| SceUInt8 SceSblSealedKey::minor_version |
Must be 0 for the supported versions.
| SceUInt8 SceSblSealedKey::reserved[6] |
Set to 0 by ksceSblPostSsMgrEncryptSealedkey.
| SceUInt8 SceSblSealedKey::iv[0x10] |
| SceUInt8 SceSblSealedKey::encrypted_key[0x10] |
| SceUInt8 SceSblSealedKey::hmac[0x20] |
| char SceSblKeystone::magic[8] |
Must be "keystone".
| SceUInt16 SceSblKeystone::type |
Must be 2.
| SceUInt16 SceSblKeystone::version |
Supported values are 0 and 1.
| SceUInt8 SceSblKeystone::reserved[0x14] |
Included in the keystone HMAC.
| SceUInt8 SceSblKeystone::passcode_digest[0x20] |
| SceUInt8 SceSblKeystone::keystone_digest[0x20] |
| char SceSblDebugKeystone::magic[8] |
Must be "keystone".
| SceUInt16 SceSblDebugKeystone::type |
Must be 1.
| SceUInt16 SceSblDebugKeystone::version |
Set to 0 when encrypted and ignored when decrypted.
| SceUInt8 SceSblDebugKeystone::reserved[4] |
Set to 0 when encrypted and ignored when decrypted.
| SceUInt8 SceSblDebugKeystone::iv[0x10] |
| SceUInt8 SceSblDebugKeystone::encrypted_secret[0x20] |
| char SceSblCloudDataKeyRing::magic[8] |
Magic value "CloudBU" followed by a NUL byte.
| SceUInt32 SceSblCloudDataKeyRing::version |
Supported values are 0 and 1.
| SceUInt8 SceSblCloudDataKeyRing::opaque_header_data[4] |
Copied unchanged; not interpreted by the FW 3.60 implementation or known importer.
| SceUInt8 SceSblCloudDataKeyRing::p[0x80] |
RSA prime p.
| SceUInt8 SceSblCloudDataKeyRing::q[0x80] |
RSA prime q.
| SceUInt8 SceSblCloudDataKeyRing::dp[0x80] |
d mod (p - 1).
| SceUInt8 SceSblCloudDataKeyRing::dq[0x80] |
d mod (q - 1).
| SceUInt8 SceSblCloudDataKeyRing::qp[0x80] |
q^-1 mod p.
| SceUInt8 SceSblCloudDataKeyRing::opaque_trailer_data[0x10] |
Copied unchanged; not interpreted by the FW 3.60 implementation or known importer.
| SceUInt32 SceSblCloudDataRsaValue::words[0x40] |
Zero-padded little-endian 32-bit words.
| SceSize SceSblCloudDataRsaValue::size |
Number of significant source bytes, up to 0x100.
| SceSblCloudDataRsaValue SceSblCloudDataSignCryptHandle::modulus |
| SceSblCloudDataRsaValue SceSblCloudDataSignCryptHandle::exponent |
| void* SceSblRsaDataParam::data |
Data buffer.
| unsigned int SceSblRsaDataParam::size |
Data size in bytes.
| const void* SceSblRsaPublicKeyParam::n |
Pointer to the RSA modulus.
| const void* SceSblRsaPublicKeyParam::k |
Pointer to the RSA exponent.
| int SceSblRsaPrivateKeyParam::unk_0x00 |
| int SceSblRsaPrivateKeyParam::unk_0x04 |
| int SceSblRsaPrivateKeyParam::unk_0x08 |
| int SceSblRsaPrivateKeyParam::unk_0x0C |
| void* SceSblRsaPrivateKeyParam::p |
Pointer to the 0x80-byte RSA prime p.
| void* SceSblRsaPrivateKeyParam::q |
Pointer to the 0x80-byte RSA prime q.
| void* SceSblRsaPrivateKeyParam::dp |
d mod (p - 1).
| void* SceSblRsaPrivateKeyParam::dq |
d mod (q - 1).
| void* SceSblRsaPrivateKeyParam::qp |
q^-1 mod p.