Difference between revisions of "NPDM"

From Nintendo Switch Brew
Jump to: navigation, search
(META)
(FS Access Control)
 
(7 intermediate revisions by 2 users not shown)
Line 91: Line 91:
 
| [[#FS Access Control]] offset
 
| [[#FS Access Control]] offset
 
|-
 
|-
| 0x24
+
| 0x224
 
| 0x4
 
| 0x4
 
| [[#FS Access Control]] size
 
| [[#FS Access Control]] size
 
|-
 
|-
| 0x28
+
| 0x228
 
| 0x4
 
| 0x4
 
| [[#Service Access Control]] offset
 
| [[#Service Access Control]] offset
 
|-
 
|-
| 0x2C
+
| 0x22C
 
| 0x4
 
| 0x4
 
| [[#Service Access Control]] size
 
| [[#Service Access Control]] size
 
|-
 
|-
| 0x30
+
| 0x230
 
| 4
 
| 4
 
| [[#Kernel Access Control]] offset
 
| [[#Kernel Access Control]] offset
 
|-
 
|-
| 0x34
+
| 0x234
 
| 4
 
| 4
 
| [[#Kernel Access Control]] size
 
| [[#Kernel Access Control]] size
 
|-
 
|-
| 0x38
+
| 0x238
 
| 0x8
 
| 0x8
 
| Padding
 
| Padding
Line 120: Line 120:
  
 
= FS Access Control =
 
= FS Access Control =
 +
 
{| class="wikitable" border="1"
 
{| class="wikitable" border="1"
 
|-
 
|-
 +
! Word
 
! Bit
 
! Bit
 
! Description
 
! Description
 
|-
 
|-
 +
| 0
 +
|
 +
| Version? Always 1.
 +
|-
 +
| 1
 
| 0
 
| 0
 
| MountContent* is accessible when set.
 
| MountContent* is accessible when set.
 
|-
 
|-
| 3
+
| 1
| This is only bit set for ShopN in the permissions-u32.
+
| 2
 +
| Enables access to [[Filesystem_services|Bis]] partitionID 27 and 28?
 
|}
 
|}
 +
 +
Web-applets access control:
 +
* "LibAppletWeb" and "LibAppletOff" have same access control: word0 bit0 set, word1 bit0 and bit3 set, and word2 bit30 set.
 +
* Rest of the web-applets: Same as above except word1 bit0 isn't set.
  
 
= Service Access Control =
 
= Service Access Control =
Line 144: Line 156:
  
 
= Kernel Access Control =
 
= Kernel Access Control =
Like the 3DS, the switch has a number of kernel capability descriptors. Unlike 3ds, where descriptors were identified by pattern 11..10 in high bits, on switch descriptors are identified by pattern 01..11 in low bits.
+
On Switch, descriptors are identified by pattern 01..11 in low bits.
  
 
{| class="wikitable" border="1"
 
{| class="wikitable" border="1"
 
|-
 
|-
! Pattern of bits 20-31
+
! Pattern of bits 15-0
 
! Type
 
! Type
 
! Fields
 
! Fields
 
|-
 
|-
| <code>0bxxxxxxxx0111?</code>
+
| <code>0bxxxxxxxxxxxx0111</code>
| Interrupt info?
+
| Kernel flags
| ?
+
| 5-0: Main thread priority?
|-
 
| <code>0bxxxxxxx01111</code>
 
| System call mask
 
| Bits 29-31: System call mask table index; Bits 5-28: mask
 
|-
 
| <code>0bxxxxx0111111?</code>
 
| Kernel release version?
 
| ?
 
 
|-
 
|-
| <code>0bxxxx01111111?</code>
+
| <code>0bxxxxxxxxxxx01111</code>
| Handle table size?
+
| Syscall mask
| ?
+
| Bits 29-31: Syscall mask table index; Bits 5-28: mask
 
|-
 
|-
| <code>0bxxx011111111?</code>
+
| <code>0bxxxxxxxxx0111111</code>
| Kernel flags?
+
| Map IO page
| ?
+
| Bits 7-31: page
 
|-
 
|-
| <code>0bx0111111111?</code>
+
| <code>0bxxxxxxxx01111111</code>
| Map address range?
+
| Map IO range
| ?
+
| Bits 7-31: page then size alternating
 
|-
 
|-
| <code>0b011111111111?</code>
+
| <code>0bxxxx011111111111</code>
| Map memory page?
+
| Interrupt pair
| ?
+
| Bits 12-21: irq0, bits 20-31: irq1, 0x3FF means empty. 
 
|}
 
|}

Latest revision as of 21:26, 5 July 2017

This is the Switch equivalent of 3DS exheader. This is the file with extension ".npdm" in {Switch ExeFS}. The size of this file varies.

Offset Size Description
0x0 0x80 META
0x80 <Varies> ACID
<See META> <See META> ACI0

META

Offset Size Description
0x0 0x4 Magic "META".
0x20  ? Title name
0x70 0x4 #ACI0 offset
0x74 0x4 #ACI0 size
0x78 0x4 #ACID offset
0x7C 0x4 #ACID size

ACID

Offset Size Description
0 0x100 RSA-2048 signature
0x100 0x100 RSA-2048 public key
0x200 0x4 Magic "ACID".
0x204 0x8 Zeroes
0x20C 0x4 Format version? (1)
0x210 0x8 Title id
0x218 0x8 Title id again
0x220 0x4 #FS Access Control offset
0x224 0x4 #FS Access Control size
0x228 0x4 #Service Access Control offset
0x22C 0x4 #Service Access Control size
0x230 4 #Kernel Access Control offset
0x234 4 #Kernel Access Control size
0x238 0x8 Padding

ACI0

Looks like an old crappy version of ACID. It has the guessed version field 0 instead of 1.

FS Access Control

Word Bit Description
0 Version? Always 1.
1 0 MountContent* is accessible when set.
1 2 Enables access to Bis partitionID 27 and 28?

Web-applets access control:

  • "LibAppletWeb" and "LibAppletOff" have same access control: word0 bit0 set, word1 bit0 and bit3 set, and word2 bit30 set.
  • Rest of the web-applets: Same as above except word1 bit0 isn't set.

Service Access Control

This is a list of service-name strings which the title has access to, with the following structure:

 +0: control_byte
 +1: {service-name without nul-terminator}

Bitmask 0x0F in control_byte is the {length of the service-name without nul-terminator} - 1.

Bitmask 0x80 in control_byte means service is allowed to be registered.

The service string can contain a wildcard * character.

Kernel Access Control

On Switch, descriptors are identified by pattern 01..11 in low bits.

Pattern of bits 15-0 Type Fields
0bxxxxxxxxxxxx0111 Kernel flags 5-0: Main thread priority?
0bxxxxxxxxxxx01111 Syscall mask Bits 29-31: Syscall mask table index; Bits 5-28: mask
0bxxxxxxxxx0111111 Map IO page Bits 7-31: page
0bxxxxxxxx01111111 Map IO range Bits 7-31: page then size alternating
0bxxxx011111111111 Interrupt pair Bits 12-21: irq0, bits 20-31: irq1, 0x3FF means empty.