Skip to content

feat(cargo-nx): pack a homebrew title into an installable NSP - #76

Merged
LNSD merged 3 commits into
mainfrom
lnsd/hacbrewpack
Aug 15, 2026
Merged

LNSD merged 3 commits into
mainfrom
lnsd/hacbrewpack

Conversation

@LNSD

@LNSD LNSD commented Aug 15, 2026 •

Copy link
Copy Markdown
Contributor

Building an NSP was the one step of the homebrew pipeline this workspace could not do, so it was left to an external binary; nx-object now carries the containers, and what remains here is the keyset, the ciphers, and the orchestration none of it belongs in a format crate.

  • Add cargo nx tool hacbrewpack, building the program, control, manual and metadata NCAs in memory and packing them into <titleid>.nsp, with the individual archives written out only under --keepncadir
  • Add keyset, which reads a keyset file and derives the header key and the application key area key from a master key when the file does not list them, stopping short of the console-unique chain a packing keyset never carries
  • Add crypto, holding the three AES modes the containers need, including the big-endian XTS tweak the console uses in place of the standard's
  • Validate and patch main.npdm and control.nacp in place, backing each original up first, and advertise the key that signs the program NCA header so the console's second signature check passes
  • Move the pinned nx-object revision to the one carrying the NCA and CNMT builders

Building an NSP was the one step of the homebrew pipeline this workspace could not do, so it was left to an external binary; `nx-object` now carries the containers, and what remains here is the keyset, the ciphers, and the orchestration none of it belongs in a format crate.

- Add `cargo nx tool hacbrewpack`, building the program, control, manual and metadata NCAs in memory and packing them into `<titleid>.nsp`, with the individual archives written out only under `--keepncadir`
- Add `keyset`, which reads a keyset file and derives the header key and the application key area key from a master key when the file does not list them, stopping short of the console-unique chain a packing keyset never carries
- Add `crypto`, holding the three AES modes the containers need, including the big-endian XTS tweak the console uses in place of the standard's
- Validate and patch `main.npdm` and `control.nacp` in place, backing each original up first, and advertise the key that signs the program NCA header so the console's second signature check passes
- Move the pinned `nx-object` revision to the one carrying the NCA and CNMT builders

Signed-off-by: Lorenzo Delgado <lnsdev@proton.me>
@LNSD
LNSD force-pushed the lnsd/hacbrewpack branch from 80351d6 to 12c4fb1 Compare August 15, 2026 09:46
LNSD added 2 commits August 15, 2026 11:59
The subcommand was added without being written into either place a reader looks for the set of utilities, so it was reachable only by already knowing it existed.

- Add `hacbrewpack` to the utility list `cargo nx tool --help` prints
- Document the subcommand in the README, covering the directories it reads, the keys it needs and where it looks for them, and the files it patches in place
- Record the two ways it departs from what it replaces: intermediates are built in memory, so `--tempdir` is accepted and ignored, and key derivation stops at the master keys
- Move the pinned `nx-object` revision to the one whose field names follow the format

Signed-off-by: Lorenzo Delgado <lnsdev@proton.me>
The revision the packing subcommand was built against lived on a branch, so the pin would have dangled the moment that branch was deleted.

- Move the pinned revision to the squashed commit now on `nx-object`'s `main`

Signed-off-by: Lorenzo Delgado <lnsdev@proton.me>
@LNSD
LNSD added this pull request to the merge queue Aug 15, 2026
Merged via the queue into main with commit 17752b0 Aug 15, 2026
3 checks passed
@LNSD
LNSD deleted the lnsd/hacbrewpack branch August 15, 2026 10:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant