Skip to content

feat(cargo-nx): read a KIP1 and check a package against its content meta - #79

Merged
LNSD merged 1 commit into
mainfrom
lnsd/hactool-kip-and-cnmt
Aug 18, 2026
Merged

LNSD merged 1 commit into
mainfrom
lnsd/hactool-kip-and-cnmt

Conversation

@LNSD

@LNSD LNSD commented Aug 18, 2026

Copy link
Copy Markdown
Contributor

Extends hactool to the two things a title carries that it could not yet open. Checking a package against its content meta is the one failure a per-archive pass cannot find: an NCA whose own hashes verify can still be the wrong file, the wrong size, or absent, and only the meta says which files belong.

  • Read a KIP1, reporting its segments and extracting them expanded, so a --outdir gives back what elf2kip was handed rather than the BLZ streams
  • Print the content records when the archive read is the one carrying them, which is the only archive of a title that holds a CNMT
  • Check every archive of a package against the meta's recorded hash and size under --verify, which needs the keyset the metadata archive was sealed with
  • Document hactool in the README, including the two limits worth knowing: only the second header signature is checkable, and a package's own metadata archive is covered by no hash, since a content meta cannot list itself

Extends `hactool` to the two things a title carries that it could not yet open. Checking a package against its content meta is the one failure a per-archive pass cannot find: an NCA whose own hashes verify can still be the wrong file, the wrong size, or absent, and only the meta says which files belong.

- Read a KIP1, reporting its segments and extracting them expanded, so a `--outdir` gives back what `elf2kip` was handed rather than the BLZ streams
- Print the content records when the archive read is the one carrying them, which is the only archive of a title that holds a CNMT
- Check every archive of a package against the meta's recorded hash and size under `--verify`, which needs the keyset the metadata archive was sealed with
- Document `hactool` in the README, including the two limits worth knowing: only the second header signature is checkable, and a package's own metadata archive is covered by no hash, since a content meta cannot list itself

Signed-off-by: Lorenzo Delgado <lnsdev@proton.me>
@LNSD
LNSD added this pull request to the merge queue Aug 18, 2026
Merged via the queue into main with commit 6086874 Aug 18, 2026
3 checks passed
@LNSD
LNSD deleted the lnsd/hactool-kip-and-cnmt branch August 18, 2026 09:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant