feat(cargo-nx): read, verify, and extract an NCA or NSP - #78
Merged
Merged
Conversation
The workspace could pack a title but never open one, so nothing checked that what `hacbrewpack` sealed could be read back. This adds the inverse path on top of `nx-object`'s new read modules, and keeps the crypto on this side of that boundary, since a keyset is secret material the crate deliberately refuses to hold. - Add `unpack::nca`, decrypting a header with AES-XTS, unwrapping the key area at the generation the archive itself names, and applying AES-CTR to the sections the header marks - Add `unpack::verify`, checking the header signature, each FS header's recorded hash, and each section's contents against the PFS0 hash table or IVFC tree covering them - Add the `hactool` subcommand, reporting an archive and extracting its executable partition, filesystem, or raw sections; entry names are rejected before they reach the filesystem so a crafted image cannot write outside the output directory - Report an unsigned header as absent rather than failed, because only a title's program archive is signed and calling the others broken misreads a correctly packed title - Move `keyset::file` and `signing` to the crate root, now that packing and reading share the keyset search path and the built-in keypair Signed-off-by: Lorenzo Delgado <lnsdev@proton.me>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The workspace could pack a title but never open one, so nothing checked that what
hacbrewpacksealed could be read back. This adds the inverse path on top ofnx-object's new read modules, and keeps the crypto on this side of that boundary, since a keyset is secret material the crate deliberately refuses to hold.unpack::nca, decrypting a header with AES-XTS, unwrapping the key area at the generation the archive itself names, and applying AES-CTR to the sections the header marksunpack::verify, checking the header signature, each FS header's recorded hash, and each section's contents against the PFS0 hash table or IVFC tree covering themhactoolsubcommand, reporting an archive and extracting its executable partition, filesystem, or raw sections; entry names are rejected before they reach the filesystem so a crafted image cannot write outside the output directorykeyset::fileandsigningto the crate root, now that packing and reading share the keyset search path and the built-in keypair