<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://switchbrew.org/w/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Yellows8</id>
	<title>Nintendo Switch Brew - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://switchbrew.org/w/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Yellows8"/>
	<link rel="alternate" type="text/html" href="https://switchbrew.org/wiki/Special:Contributions/Yellows8"/>
	<updated>2026-08-12T22:35:15Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.43.1</generator>
	<entry>
		<id>https://switchbrew.org/w/index.php?title=NS_services&amp;diff=14935</id>
		<title>NS services</title>
		<link rel="alternate" type="text/html" href="https://switchbrew.org/w/index.php?title=NS_services&amp;diff=14935"/>
		<updated>2026-08-09T17:53:08Z</updated>

		<summary type="html">&lt;p&gt;Yellows8: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= aoc:u =&lt;br /&gt;
This is &amp;quot;nn::aocsrv::detail::IAddOnContentManager&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This is only available when [[Process_Manager_services|pm:bm]] GetBootMode returns output 0 (Normal).&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [1.0.0-6.2.0] CountAddOnContentByApplicationId&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [1.0.0-6.2.0] ListAddOnContentByApplicationId&lt;br /&gt;
|-&lt;br /&gt;
| 2 || CountAddOnContent&lt;br /&gt;
|-&lt;br /&gt;
| 3 || ListAddOnContent&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [1.0.0-6.2.0] GetAddOnContentBaseIdByApplicationId&lt;br /&gt;
|-&lt;br /&gt;
| 5 || GetAddOnContentBaseId&lt;br /&gt;
|-&lt;br /&gt;
| 6 || [1.0.0-6.2.0] PrepareAddOnContentByApplicationId&lt;br /&gt;
|-&lt;br /&gt;
| 7 || PrepareAddOnContent&lt;br /&gt;
|-&lt;br /&gt;
| 8 || [4.0.0+] GetAddOnContentListChangedEvent&lt;br /&gt;
|-&lt;br /&gt;
| 9 || [10.0.0+] GetAddOnContentLostErrorCode&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [11.0.0+] GetAddOnContentListChangedEventWithProcessId&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [13.0.0+] NotifyMountAddOnContent&lt;br /&gt;
|-&lt;br /&gt;
| 12 || [13.0.0+] NotifyUnmountAddOnContent&lt;br /&gt;
|-&lt;br /&gt;
| 13 || [13.0.0+] IsAddOnContentMountedForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 50 || [13.0.0+] CheckAddOnContentMountStatus&lt;br /&gt;
|-&lt;br /&gt;
| 100 || [7.0.0+] [[#IPurchaseEventManager|CreateEcPurchasedEventManager]]&lt;br /&gt;
|-&lt;br /&gt;
| 101 || [9.0.0+] [[#IPurchaseEventManager|CreatePermanentEcPurchasedEventManager]]&lt;br /&gt;
|-&lt;br /&gt;
| 110 || [12.0.0+] [[#IContentsServiceManager|CreateContentsServiceManager]]&lt;br /&gt;
|-&lt;br /&gt;
| 200 || [13.1.0+] SetRequiredAddOnContentsOnContentsAvailabilityTransition&lt;br /&gt;
|-&lt;br /&gt;
| 300 || [16.0.0+] SetupHostAddOnContent&lt;br /&gt;
|-&lt;br /&gt;
| 301 || [16.0.0+] GetRegisteredAddOnContentPath&lt;br /&gt;
|-&lt;br /&gt;
| 302 || [16.0.0+] UpdateCachedList&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IPurchaseEventManager ==&lt;br /&gt;
This is &amp;quot;nn::ec::IPurchaseEventManager&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || SetDefaultDeliveryTarget&lt;br /&gt;
|-&lt;br /&gt;
| 1 || SetDeliveryTarget&lt;br /&gt;
|-&lt;br /&gt;
| 2 || GetPurchasedEventReadableHandle&lt;br /&gt;
|-&lt;br /&gt;
| 3 || PopPurchasedProductInfo&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [9.0.0+] PopPurchasedProductInfoWithUid&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IContentsServiceManager ==&lt;br /&gt;
This is &amp;quot;nn::ec::IContentsServiceManager&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [12.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [16.0.0+] RequestContentsAuthorizationTokenDeprecated ([12.0.0-15.0.1] [[#RequestContentsAuthorizationToken]])&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [16.0.0+] RequestContentsAuthorizationToken&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== RequestContentsAuthorizationToken ===&lt;br /&gt;
Takes a total of 0x50-bytes of input, a PID, a type-0x5 input buffer. Returns an [[#IAsyncData|IAsyncData]] and an output handle.&lt;br /&gt;
&lt;br /&gt;
== IAsyncData ==&lt;br /&gt;
This is &amp;quot;nn::ec::detail::IAsyncData&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [12.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetSize&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Get&lt;br /&gt;
|-&lt;br /&gt;
| 2 || Cancel&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ns:am =&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IApplicationManagerInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
[3.0.0+] This service was replaced by [[#ns:am2, ns:ec, ns:rid, ns:rt, ns:web, ns:ro, ns:sweb|ns:am2]].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#ListApplicationRecord]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GenerateApplicationRecordCount&lt;br /&gt;
|-&lt;br /&gt;
| 2 || GetApplicationRecordUpdateSystemEvent&lt;br /&gt;
|-&lt;br /&gt;
| 3 || GetApplicationView&lt;br /&gt;
|-&lt;br /&gt;
| 4 || DeleteApplicationEntity&lt;br /&gt;
|-&lt;br /&gt;
| 5 || DeleteApplicationCompletely&lt;br /&gt;
|-&lt;br /&gt;
| 6 || IsAnyApplicationEntityRedundant&lt;br /&gt;
|-&lt;br /&gt;
| 7 || DeleteRedundantApplicationEntity&lt;br /&gt;
|-&lt;br /&gt;
| 8 || IsApplicationEntityMovable&lt;br /&gt;
|-&lt;br /&gt;
| 9 || MoveApplicationEntity&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [[#CalculateApplicationOccupiedSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 16 || PushApplicationRecord&lt;br /&gt;
|-&lt;br /&gt;
| 17 || ListApplicationRecordContentMeta&lt;br /&gt;
|-&lt;br /&gt;
| 18 || CheckLaunchRights&lt;br /&gt;
|-&lt;br /&gt;
| 19 || [[#LaunchApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 21 || [[#GetApplicationContentPath]]&lt;br /&gt;
|-&lt;br /&gt;
| 22 || TerminateApplication&lt;br /&gt;
|-&lt;br /&gt;
| 23 || [2.0.0+] ResolveApplicationContentPath&lt;br /&gt;
|-&lt;br /&gt;
| 26 || BeginInstallApplication&lt;br /&gt;
|-&lt;br /&gt;
| 27 || DeleteApplicationRecord&lt;br /&gt;
|-&lt;br /&gt;
| 30 || RequestApplicationUpdateInfo&lt;br /&gt;
|-&lt;br /&gt;
| 31 || RequestUpdateApplication&lt;br /&gt;
|-&lt;br /&gt;
| 32 || CancelApplicationDownload&lt;br /&gt;
|-&lt;br /&gt;
| 33 || ResumeApplicationDownload&lt;br /&gt;
|-&lt;br /&gt;
| 34 || ClearTaskStatusList&lt;br /&gt;
|-&lt;br /&gt;
| 35 || UpdateVersionList&lt;br /&gt;
|-&lt;br /&gt;
| 36 || PushLaunchVersion&lt;br /&gt;
|-&lt;br /&gt;
| 37 || ListRequiredVersion&lt;br /&gt;
|-&lt;br /&gt;
| 38 || CheckApplicationLaunchVersion&lt;br /&gt;
|-&lt;br /&gt;
| 39 || CheckApplicationLaunchRights&lt;br /&gt;
|-&lt;br /&gt;
| 40 || GetApplicationLogoData&lt;br /&gt;
|-&lt;br /&gt;
| 41 || CalculateApplicationDownloadRequiredSize&lt;br /&gt;
|-&lt;br /&gt;
| 42 || CleanupSdCard&lt;br /&gt;
|-&lt;br /&gt;
| 43 || [[#CheckSdCardMountStatus]]&lt;br /&gt;
|-&lt;br /&gt;
| 44 || GetSdCardMountStatusChangedEvent&lt;br /&gt;
|-&lt;br /&gt;
| 45 || GetGameCardAttachmentEvent&lt;br /&gt;
|-&lt;br /&gt;
| 46 || GetGameCardAttachmentInfo&lt;br /&gt;
|-&lt;br /&gt;
| 47 || [[#GetTotalSpaceSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 48 || [[#GetFreeSpaceSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 49 || GetSdCardRemovedEvent&lt;br /&gt;
|-&lt;br /&gt;
| 52 || GetGameCardUpdateDetectionEvent&lt;br /&gt;
|-&lt;br /&gt;
| 53 || DisableApplicationAutoDelete&lt;br /&gt;
|-&lt;br /&gt;
| 54 || EnableApplicationAutoDelete&lt;br /&gt;
|-&lt;br /&gt;
| 55 || [[#GetApplicationDesiredLanguage]]&lt;br /&gt;
|-&lt;br /&gt;
| 56 || SetApplicationTerminateResult&lt;br /&gt;
|-&lt;br /&gt;
| 57 || ClearApplicationTerminateResult&lt;br /&gt;
|-&lt;br /&gt;
| 58 || GetLastSdCardMountUnexpectedResult&lt;br /&gt;
|-&lt;br /&gt;
| 59 || ConvertApplicationLanguageToLanguageCode&lt;br /&gt;
|-&lt;br /&gt;
| 60 || [[#ConvertLanguageCodeToApplicationLanguage]]&lt;br /&gt;
|-&lt;br /&gt;
| 61 || GetBackgroundDownloadStressTaskInfo&lt;br /&gt;
|-&lt;br /&gt;
| 62 || GetGameCardStopper&lt;br /&gt;
|-&lt;br /&gt;
| 63 || IsSystemProgramInstalled&lt;br /&gt;
|-&lt;br /&gt;
| 64 || [2.0.0+] StartApplyDeltaTask&lt;br /&gt;
|-&lt;br /&gt;
| 65 || [2.0.0+] GetRequestServerStopper&lt;br /&gt;
|-&lt;br /&gt;
| 100 || ResetToFactorySettings&lt;br /&gt;
|-&lt;br /&gt;
| 101 || ResetToFactorySettingsWithoutUserSaveData&lt;br /&gt;
|-&lt;br /&gt;
| 102 || [2.0.0+] ResetToFactorySettingsForRefurbishment&lt;br /&gt;
|-&lt;br /&gt;
| 200 || CalculateUserSaveDataStatistics&lt;br /&gt;
|-&lt;br /&gt;
| 201 || DeleteUserSaveDataAll&lt;br /&gt;
|-&lt;br /&gt;
| 210 || DeleteUserSystemSaveData&lt;br /&gt;
|-&lt;br /&gt;
| 220 || UnregisterNetworkServiceAccount&lt;br /&gt;
|-&lt;br /&gt;
| 300 || GetApplicationShellEvent&lt;br /&gt;
|-&lt;br /&gt;
| 301 || PopApplicationShellEventInfo&lt;br /&gt;
|-&lt;br /&gt;
| 302 || LaunchLibraryApplet&lt;br /&gt;
|-&lt;br /&gt;
| 303 || TerminateLibraryApplet&lt;br /&gt;
|-&lt;br /&gt;
| 304 || LaunchSystemApplet&lt;br /&gt;
|-&lt;br /&gt;
| 305 || TerminateSystemApplet&lt;br /&gt;
|-&lt;br /&gt;
| 306 || LaunchOverlayApplet&lt;br /&gt;
|-&lt;br /&gt;
| 307 || TerminateOverlayApplet&lt;br /&gt;
|-&lt;br /&gt;
| 400 || [[#GetApplicationControlData]]&lt;br /&gt;
|-&lt;br /&gt;
| 401 || InvalidateAllApplicationControlCache&lt;br /&gt;
|-&lt;br /&gt;
| 402 || RequestDownloadApplicationControlData&lt;br /&gt;
|-&lt;br /&gt;
| 403 || GetMaxApplicationControlCacheCount&lt;br /&gt;
|-&lt;br /&gt;
| 404 || [2.0.0+] InvalidateApplicationControlCache&lt;br /&gt;
|-&lt;br /&gt;
| 405 || [2.0.0+] ListApplicationControlCacheEntryInfo&lt;br /&gt;
|-&lt;br /&gt;
| 502 || [2.0.0+] RequestCheckGameCardRegistration&lt;br /&gt;
|-&lt;br /&gt;
| 503 || [2.0.0+] RequestGameCardRegistrationGoldPoint&lt;br /&gt;
|-&lt;br /&gt;
| 504 || [2.0.0+] RequestRegisterGameCard&lt;br /&gt;
|-&lt;br /&gt;
| 600 || [2.0.0+] [[#CountApplicationContentMeta]]&lt;br /&gt;
|-&lt;br /&gt;
| 601 || [2.0.0+] [[#ListApplicationContentMetaStatus]]&lt;br /&gt;
|-&lt;br /&gt;
| 602 || [2.0.0+] ListOwnedAndInstalledAddOnContent&lt;br /&gt;
|-&lt;br /&gt;
| 603 || [2.0.0+] GetOwnedApplicationContentMetaStatus&lt;br /&gt;
|-&lt;br /&gt;
| 604 || [2.0.0+] RegisterContentsExternalKey&lt;br /&gt;
|-&lt;br /&gt;
| 605 || [2.0.0+] ListApplicationContentMetaStatusWithRightsCheck&lt;br /&gt;
|-&lt;br /&gt;
| 700 || [2.0.0+] PushDownloadTaskList&lt;br /&gt;
|-&lt;br /&gt;
| 701 || [2.0.0+] [[#ClearTaskStatusList]]&lt;br /&gt;
|-&lt;br /&gt;
| 702 || [2.0.0+] [[#RequestDownloadTaskList]]&lt;br /&gt;
|-&lt;br /&gt;
| 703 || [2.0.0+] [[#RequestEnsureDownloadTask]]&lt;br /&gt;
|-&lt;br /&gt;
| 704 || [2.0.0+] [[#ListDownloadTaskStatus]]&lt;br /&gt;
|-&lt;br /&gt;
| 705 || [2.0.0+] RequestDownloadTaskListData&lt;br /&gt;
|-&lt;br /&gt;
| 800 || [2.0.0+] RequestVersionList&lt;br /&gt;
|-&lt;br /&gt;
| 801 || [2.0.0+] ListVersionList&lt;br /&gt;
|-&lt;br /&gt;
| 900 || [2.0.0+] GetApplicationRecord&lt;br /&gt;
|-&lt;br /&gt;
| 901 || [2.0.0+] GetApplicationRecordProperty&lt;br /&gt;
|-&lt;br /&gt;
| 902 || [2.0.0+] EnableApplicationAutoUpdate&lt;br /&gt;
|-&lt;br /&gt;
| 903 || [2.0.0+] DisableApplicationAutoUpdate&lt;br /&gt;
|-&lt;br /&gt;
| 904 || [2.0.0+] TouchApplication&lt;br /&gt;
|-&lt;br /&gt;
| 905 || [2.0.0+] RequestApplicationUpdate&lt;br /&gt;
|-&lt;br /&gt;
| 906 || [2.0.0+] IsApplicationUpdateRequested&lt;br /&gt;
|-&lt;br /&gt;
| 907 || [2.0.0+] WithdrawApplicationUpdateRequest&lt;br /&gt;
|-&lt;br /&gt;
| 908 || [2.0.0+] ListApplicationRecordInstalledContentMeta&lt;br /&gt;
|-&lt;br /&gt;
| 1000 || [2.0.0+] RequestVerifyApplication&lt;br /&gt;
|-&lt;br /&gt;
| 1001 || [2.0.0+] CorruptApplicationForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 1200 || [2.0.0+] [[#NeedsUpdateVulnerability]]&lt;br /&gt;
|-&lt;br /&gt;
| 1300 || [2.0.0+] IsAnyApplicationEntityInstalled&lt;br /&gt;
|-&lt;br /&gt;
| 1301 || [2.0.0+] DeleteApplicationContentEntities&lt;br /&gt;
|-&lt;br /&gt;
| 1302 || [2.0.0+] CleanupUnrecordedApplicationEntity&lt;br /&gt;
|-&lt;br /&gt;
| 1400 || [2.0.0+] PrepareShutdown&lt;br /&gt;
|-&lt;br /&gt;
| 1500 || [2.0.0+] FormatSdCard&lt;br /&gt;
|-&lt;br /&gt;
| 1501 || [2.0.0+] NeedsSystemUpdateToFormatSdCard&lt;br /&gt;
|-&lt;br /&gt;
| 1502 || [2.0.0+] GetLastSdCardFormatUnexpectedResult&lt;br /&gt;
|-&lt;br /&gt;
| 1503 || [2.0.0+] DetachSdCard&lt;br /&gt;
|-&lt;br /&gt;
| 1600 || [2.0.0+] GetSystemSeedForPseudoDeviceId&lt;br /&gt;
|-&lt;br /&gt;
| 1700 || [2.0.0+] ListApplicationDownloadingContentMeta&lt;br /&gt;
|-&lt;br /&gt;
| 1800 || [2.0.0+] IsNotificationSetupCompleted&lt;br /&gt;
|-&lt;br /&gt;
| 1801 || [2.0.0+] GetLastNotificationInfoCount&lt;br /&gt;
|-&lt;br /&gt;
| 1802 || [2.0.0+] ListLastNotificationInfo&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== ListApplicationRecord ==&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of [[#ApplicationRecord]] and an s32 entry_offset, returns an output s32 out_entrycount.&lt;br /&gt;
&lt;br /&gt;
Returns an array of entries with the below format using the specified offset and count.&lt;br /&gt;
&lt;br /&gt;
== LaunchApplication ==&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output u64 PID.&lt;br /&gt;
&lt;br /&gt;
Launches an application title which is registered with NS.&lt;br /&gt;
&lt;br /&gt;
== GetApplicationContentPath ==&lt;br /&gt;
Takes a 0x16-type output buffer, an u8 [[NCM_services#ContentType|ContentType]], and an [[NCM_services#ApplicationId|ApplicationId]].&lt;br /&gt;
&lt;br /&gt;
The input [[NCM_services#ApplicationId|ApplicationId]] is used with the application-title table like various other cmds, anything not in that table can&#039;t be used with this.&lt;br /&gt;
&lt;br /&gt;
Returns a string path for the specified type of patch content with this [[NCM_services#ApplicationId|ApplicationId]], otherwise returns regular-application paths when update-title not installed. Returns an error when the specified type of content doesn&#039;t exist for this title. Starts with &amp;quot;@{SdCardContent,UserContent}://&amp;quot; and ends in &amp;quot;.nca&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
For gamecard content, the output path is: &amp;quot;@GcSXXXXXXXX:/&amp;lt;NcaId&amp;gt;.nca&amp;quot;. NCA-type0 with gamecard returns 0 with an empty output string.&lt;br /&gt;
&lt;br /&gt;
The output string is then used by the user-process with [[Filesystem_services|FS]] to mount the content.&lt;br /&gt;
&lt;br /&gt;
== GetTotalSpaceSize ==&lt;br /&gt;
Takes an input u8 [[NCM_services#StorageId|StorageId]], no output.&lt;br /&gt;
&lt;br /&gt;
The StorageId must be SdCard.&lt;br /&gt;
&lt;br /&gt;
Returns the s64 from [[NCM_services#IContentStorage]] GetFreeSpaceSize.&lt;br /&gt;
&lt;br /&gt;
== GetFreeSpaceSize ==&lt;br /&gt;
Takes an input u8 [[NCM_services#StorageId|StorageId]], no output.&lt;br /&gt;
&lt;br /&gt;
The StorageId must be SdCard.&lt;br /&gt;
&lt;br /&gt;
Returns the s64 from [[NCM_services#IContentStorage]] GetTotalSpaceSize.&lt;br /&gt;
&lt;br /&gt;
== GetApplicationDesiredLanguage ==&lt;br /&gt;
Takes an input u8 language-bitmask, returns an output u8 [[control.nacp]] langentry index.&lt;br /&gt;
&lt;br /&gt;
User-processes generate the language-bitmask with the following for all 16 lang-entries: &amp;lt;code&amp;gt;if(&amp;lt;either string in langentry[i] is non-empty&amp;gt;)bitmask |= 1&amp;lt;&amp;lt;i&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== ConvertLanguageCodeToApplicationLanguage ==&lt;br /&gt;
Takes an input u8 pointer for the resulting Id to be written to and a string represented as a u64 (i.e 0x53552D6E65 for &#039;en-US&#039;).&lt;br /&gt;
&lt;br /&gt;
Returns 0 if an ID was successfully found, otherwise returns 0x25810.&lt;br /&gt;
&lt;br /&gt;
== GetApplicationControlData ==&lt;br /&gt;
Takes an input u8 [[#ApplicationControlSource]], an [[NCM_services#ApplicationId|ApplicationId]], and a type-0x6 output buffer. Returns an output u32 for actual_size. Official user-processes use buffer size 0x24000. [[qlaunch]] only uses source value 0x1 (Storage if not in cache).&lt;br /&gt;
&lt;br /&gt;
Loads cached [[control.nacp]] to buf+0 and the cached icon to buf+0x4000. Returns an error if the buffer is too small.&lt;br /&gt;
&lt;br /&gt;
== ListApplicationContentMetaStatus ==&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of [[#ApplicationContentMetaStatus]], an input s32 index and [[NCM_services#ApplicationId|ApplicationId]], returns an output s32 out_entrycount.&lt;br /&gt;
&lt;br /&gt;
Returns 0x10-byte entries using the specified [[NCM_services#ApplicationId|ApplicationId]] starting at the specified index. Can only return game titles. The second entry if any is the update-title usually. When the input entryindex is &amp;gt;= totalentries, this will return 0 with out_entrycount=0.&lt;br /&gt;
&lt;br /&gt;
= ns:am2, ns:ec, ns:rid, ns:rt, ns:web, ns:ro, ns:sweb =&lt;br /&gt;
These are &amp;quot;nn::ns::detail::IServiceGetterInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
These commands check a state field for a command-specific bit and returns an error if not set, this is a permissions check for service+command.&lt;br /&gt;
&lt;br /&gt;
[11.0.0+] ns:ro was added.&lt;br /&gt;
&lt;br /&gt;
[15.0.0+] ns:sweb was added.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Permission bit&lt;br /&gt;
|-&lt;br /&gt;
| 7988 || [6.0.0+] [[#IDynamicRightsInterface|GetDynamicRightsInterface]] || 10&lt;br /&gt;
|-&lt;br /&gt;
| 7989 || [5.1.0+] [[#IReadOnlyApplicationControlDataInterface|GetReadOnlyApplicationControlDataInterface]] || 9&lt;br /&gt;
|-&lt;br /&gt;
| 7991 || [5.0.0+] [[#IReadOnlyApplicationRecordInterface|GetReadOnlyApplicationRecordInterface]] || 8&lt;br /&gt;
|-&lt;br /&gt;
| 7992 || [4.0.0+] [[#IECommerceInterface|GetECommerceInterface]] || 7&lt;br /&gt;
|-&lt;br /&gt;
| 7993 || [4.0.0+] [[#IApplicationVersionInterface|GetApplicationVersionInterface]] || 6&lt;br /&gt;
|-&lt;br /&gt;
| 7994 || [[#IFactoryResetInterface|GetFactoryResetInterface]] || 5&lt;br /&gt;
|-&lt;br /&gt;
| 7995 || [[#IAccountProxyInterface|GetAccountProxyInterface]] || 4&lt;br /&gt;
|-&lt;br /&gt;
| 7996 || [[#IApplicationManagerInterface|GetApplicationManagerInterface]] || 3&lt;br /&gt;
|-&lt;br /&gt;
| 7997 || [[#IDownloadTaskInterface|GetDownloadTaskInterface]] || 1&lt;br /&gt;
|-&lt;br /&gt;
| 7998 || [[#IContentManagementInterface|GetContentManagementInterface]] || 0&lt;br /&gt;
|-&lt;br /&gt;
| 7999 || [[#IDocumentInterface|GetDocumentInterface]] || 2&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Permissions state field with each service:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Service || Permissions&lt;br /&gt;
|-&lt;br /&gt;
| ns:web || 0x304&lt;br /&gt;
|-&lt;br /&gt;
| ns:ec || 0x83&lt;br /&gt;
|-&lt;br /&gt;
| ns:sweb || 0x387&lt;br /&gt;
|-&lt;br /&gt;
| ns:rid || 0x10&lt;br /&gt;
|-&lt;br /&gt;
| ns:rt || 0x20&lt;br /&gt;
|-&lt;br /&gt;
| ns:ro || 0x301&lt;br /&gt;
|-&lt;br /&gt;
| ns:am2 || 0x7FF&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IAccountProxyInterface ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IAccountProxyInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || CreateUserAccount&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IApplicationManagerInterface ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IApplicationManagerInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#ListApplicationRecord]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GenerateApplicationRecordCount&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [[#GetApplicationRecordUpdateSystemEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [[#GetApplicationViewDeprecated]]&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [[#DeleteApplicationEntity]]&lt;br /&gt;
|-&lt;br /&gt;
| 5 || [[#DeleteApplicationCompletely]]&lt;br /&gt;
|-&lt;br /&gt;
| 6 || IsAnyApplicationEntityRedundant&lt;br /&gt;
|-&lt;br /&gt;
| 7 || [[#DeleteRedundantApplicationEntity]]&lt;br /&gt;
|-&lt;br /&gt;
| 8 || [[#IsApplicationEntityMovable]]&lt;br /&gt;
|-&lt;br /&gt;
| 9 || [1.0.0-9.2.0] [[#MoveApplicationEntity]]&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [[#CalculateApplicationOccupiedSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 16 || PushApplicationRecord&lt;br /&gt;
|-&lt;br /&gt;
| 17 || ListApplicationRecordContentMeta&lt;br /&gt;
|-&lt;br /&gt;
| 19 || [1.0.0-5.1.0] LaunchApplicationOld&lt;br /&gt;
|-&lt;br /&gt;
| 21 || [[#GetApplicationContentPath]]&lt;br /&gt;
|-&lt;br /&gt;
| 22 || TerminateApplication&lt;br /&gt;
|-&lt;br /&gt;
| 23 || ResolveApplicationContentPath&lt;br /&gt;
|-&lt;br /&gt;
| 26 || BeginInstallApplication&lt;br /&gt;
|-&lt;br /&gt;
| 27 || DeleteApplicationRecord&lt;br /&gt;
|-&lt;br /&gt;
| 30 || [[#RequestApplicationUpdateInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 31 || [1.0.0-3.0.2] RequestUpdateApplication&lt;br /&gt;
|-&lt;br /&gt;
| 32 || [[#CancelApplicationDownload]]&lt;br /&gt;
|-&lt;br /&gt;
| 33 || [[#ResumeApplicationDownload]]&lt;br /&gt;
|-&lt;br /&gt;
| 35 || UpdateVersionList&lt;br /&gt;
|-&lt;br /&gt;
| 36 || PushLaunchVersion&lt;br /&gt;
|-&lt;br /&gt;
| 37 || ListRequiredVersion&lt;br /&gt;
|-&lt;br /&gt;
| 38 || [[#CheckApplicationLaunchVersion]]&lt;br /&gt;
|-&lt;br /&gt;
| 39 || [1.0.0-6.2.0] CheckApplicationLaunchRights&lt;br /&gt;
|-&lt;br /&gt;
| 40 || GetApplicationLogoData&lt;br /&gt;
|-&lt;br /&gt;
| 41 || CalculateApplicationDownloadRequiredSize&lt;br /&gt;
|-&lt;br /&gt;
| 42 || [[#CleanupSdCard]]&lt;br /&gt;
|-&lt;br /&gt;
| 43 || [[#CheckSdCardMountStatus]]&lt;br /&gt;
|-&lt;br /&gt;
| 44 || [[#GetSdCardMountStatusChangedEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 45 || GetGameCardAttachmentEvent&lt;br /&gt;
|-&lt;br /&gt;
| 46 || GetGameCardAttachmentInfo&lt;br /&gt;
|-&lt;br /&gt;
| 47 || [[#GetTotalSpaceSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 48 || [[#GetFreeSpaceSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 49 || GetSdCardRemovedEvent&lt;br /&gt;
|-&lt;br /&gt;
| 52 || [[#GetGameCardUpdateDetectionEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 53 || [[#DisableApplicationAutoDelete]]&lt;br /&gt;
|-&lt;br /&gt;
| 54 || [[#EnableApplicationAutoDelete]]&lt;br /&gt;
|-&lt;br /&gt;
| 55 || GetApplicationDesiredLanguage&lt;br /&gt;
|-&lt;br /&gt;
| 56 || [[#SetApplicationTerminateResult]]&lt;br /&gt;
|-&lt;br /&gt;
| 57 || [[#ClearApplicationTerminateResult]]&lt;br /&gt;
|-&lt;br /&gt;
| 58 || [[#GetLastSdCardMountUnexpectedResult]]&lt;br /&gt;
|-&lt;br /&gt;
| 59 || ConvertApplicationLanguageToLanguageCode&lt;br /&gt;
|-&lt;br /&gt;
| 60 || [[#ConvertLanguageCodeToApplicationLanguage]]&lt;br /&gt;
|-&lt;br /&gt;
| 61 || GetBackgroundDownloadStressTaskInfo&lt;br /&gt;
|-&lt;br /&gt;
| 62 || GetGameCardStopper&lt;br /&gt;
|-&lt;br /&gt;
| 63 || IsSystemProgramInstalled&lt;br /&gt;
|-&lt;br /&gt;
| 64 || StartApplyDeltaTask&lt;br /&gt;
|-&lt;br /&gt;
| 65 || [[#GetRequestServerStopper]]&lt;br /&gt;
|-&lt;br /&gt;
| 66 || [3.0.0+] GetBackgroundApplyDeltaStressTaskInfo&lt;br /&gt;
|-&lt;br /&gt;
| 67 || [3.0.0+] [[#CancelApplicationApplyDelta]]&lt;br /&gt;
|-&lt;br /&gt;
| 68 || [3.0.0+] [[#ResumeApplicationApplyDelta]]&lt;br /&gt;
|-&lt;br /&gt;
| 69 || [3.0.0+] [[#CalculateApplicationApplyDeltaRequiredSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 70 || [3.0.0+] [[#ResumeAll]]&lt;br /&gt;
|-&lt;br /&gt;
| 71 || [3.0.0+] [[#GetStorageSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 80 || [3.0.0+] RequestDownloadApplication&lt;br /&gt;
|-&lt;br /&gt;
| 81 || [3.0.0+] RequestDownloadAddOnContent&lt;br /&gt;
|-&lt;br /&gt;
| 82 || [3.0.0+] DownloadApplication&lt;br /&gt;
|-&lt;br /&gt;
| 83 || [4.0.0-6.2.0] CheckApplicationResumeRights&lt;br /&gt;
|-&lt;br /&gt;
| 84 || [4.0.0-16.1.0] GetDynamicCommitEvent&lt;br /&gt;
|-&lt;br /&gt;
| 85 || [4.0.0+] [[#RequestUpdateApplication2]]&lt;br /&gt;
|-&lt;br /&gt;
| 86 || [4.0.0+] EnableApplicationCrashReport&lt;br /&gt;
|-&lt;br /&gt;
| 87 || [4.0.0+] IsApplicationCrashReportEnabled&lt;br /&gt;
|-&lt;br /&gt;
| 90 || [15.0.0+] BoostSystemMemoryResourceLimit ([4.0.0-8.1.0] BoostSystemMemoryResourceLimit)&lt;br /&gt;
|-&lt;br /&gt;
| 91 || [5.0.0+] DeprecatedLaunchApplication&lt;br /&gt;
|-&lt;br /&gt;
| 92 || [5.0.0+] GetRunningApplicationProgramId&lt;br /&gt;
|-&lt;br /&gt;
| 93 || [5.0.0+] GetMainApplicationProgramIndex&lt;br /&gt;
|-&lt;br /&gt;
| 94 || [6.0.0+] [[#LaunchApplication_2|LaunchApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 95 || [6.0.0+] [[#GetApplicationLaunchInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 96 || [6.0.0+] [[#AcquireApplicationLaunchInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 97 || [6.0.0+] [[#GetMainApplicationProgramIndexByApplicationLaunchInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 98 || [6.0.0+] EnableApplicationAllThreadDumpOnCrash&lt;br /&gt;
|-&lt;br /&gt;
| 99 || [8.0.0+] [[#LaunchDevMenu]]&lt;br /&gt;
|-&lt;br /&gt;
| 100 || [[#ResetToFactorySettings]]&lt;br /&gt;
|-&lt;br /&gt;
| 101 || [[#ResetToFactorySettingsWithoutUserSaveData]]&lt;br /&gt;
|-&lt;br /&gt;
| 102 || [[#ResetToFactorySettingsForRefurbishment]]&lt;br /&gt;
|-&lt;br /&gt;
| 103 || [9.1.0+] [[#ResetToFactorySettingsWithPlatformRegion]]&lt;br /&gt;
|-&lt;br /&gt;
| 104 || [9.1.0+] [[#ResetToFactorySettingsWithPlatformRegionAuthentication]]&lt;br /&gt;
|-&lt;br /&gt;
| 105 || [10.0.0+] [[#RequestResetToFactorySettingsSecurely]]&lt;br /&gt;
|-&lt;br /&gt;
| 106 || [10.0.0+] [[#RequestResetToFactorySettingsWithPlatformRegionAuthenticationSecurely]]&lt;br /&gt;
|-&lt;br /&gt;
| 200 || CalculateUserSaveDataStatistics&lt;br /&gt;
|-&lt;br /&gt;
| 201 || [[#DeleteUserSaveDataAll]]&lt;br /&gt;
|-&lt;br /&gt;
| 210 || [[#DeleteUserSystemSaveData]]&lt;br /&gt;
|-&lt;br /&gt;
| 211 || [6.0.0+] [[#DeleteSaveData]]&lt;br /&gt;
|-&lt;br /&gt;
| 220 || [[#UnregisterNetworkServiceAccount]]&lt;br /&gt;
|-&lt;br /&gt;
| 221 || [6.0.0+] [[#UnregisterNetworkServiceAccountWithUserSaveDataDeletion]]&lt;br /&gt;
|-&lt;br /&gt;
| 300 || GetApplicationShellEvent&lt;br /&gt;
|-&lt;br /&gt;
| 301 || PopApplicationShellEventInfo&lt;br /&gt;
|-&lt;br /&gt;
| 302 || [[#LaunchLibraryApplet]]&lt;br /&gt;
|-&lt;br /&gt;
| 303 || TerminateLibraryApplet&lt;br /&gt;
|-&lt;br /&gt;
| 304 || [[#LaunchSystemApplet]]&lt;br /&gt;
|-&lt;br /&gt;
| 305 || TerminateSystemApplet&lt;br /&gt;
|-&lt;br /&gt;
| 306 || [[#LaunchOverlayApplet]]&lt;br /&gt;
|-&lt;br /&gt;
| 307 || TerminateOverlayApplet&lt;br /&gt;
|-&lt;br /&gt;
| 308 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 309 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 400 || [[#GetApplicationControlData]]&lt;br /&gt;
|-&lt;br /&gt;
| 401 || InvalidateAllApplicationControlCache&lt;br /&gt;
|-&lt;br /&gt;
| 402 || [[#RequestDownloadApplicationControlData]]&lt;br /&gt;
|-&lt;br /&gt;
| 403 || GetMaxApplicationControlCacheCount&lt;br /&gt;
|-&lt;br /&gt;
| 404 || InvalidateApplicationControlCache&lt;br /&gt;
|-&lt;br /&gt;
| 405 || ListApplicationControlCacheEntryInfo&lt;br /&gt;
|-&lt;br /&gt;
| 406 || [6.0.0-18.1.0] [[#GetApplicationControlProperty]]&lt;br /&gt;
|-&lt;br /&gt;
| 407 || [8.0.0+] [[#ListApplicationTitle]]&lt;br /&gt;
|-&lt;br /&gt;
| 408 || [8.0.0+] [[#ListApplicationIcon]]&lt;br /&gt;
|-&lt;br /&gt;
| 409 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 410 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 411 || [19.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 412 || [19.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 413 || [19.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 414 || [19.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 415 || [19.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 416 || [19.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 417 || [19.0.0+] InvalidateAllApplicationControlCacheOfTheStage&lt;br /&gt;
|-&lt;br /&gt;
| 418 || [19.0.0+] InvalidateApplicationControlCacheOfTheStage&lt;br /&gt;
|-&lt;br /&gt;
| 419 || [19.0.0+] RequestDownloadApplicationControlDataInBackground&lt;br /&gt;
|-&lt;br /&gt;
| 420 || [19.0.0+] CloneApplicationControlDataCacheForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 421 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 422 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 423 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 424 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 425 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 426 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 427 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 428 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 429 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 430 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 502 || [[#RequestCheckGameCardRegistration]]&lt;br /&gt;
|-&lt;br /&gt;
| 503 || [[#RequestGameCardRegistrationGoldPoint]]&lt;br /&gt;
|-&lt;br /&gt;
| 504 || [[#RequestRegisterGameCard]]&lt;br /&gt;
|-&lt;br /&gt;
| 505 || [3.0.0+] [[#GetGameCardMountFailureEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 506 || [3.0.0+] [[#IsGameCardInserted]]&lt;br /&gt;
|-&lt;br /&gt;
| 507 || [3.0.0+] [[#EnsureGameCardAccess]]&lt;br /&gt;
|-&lt;br /&gt;
| 508 || [3.0.0+] [[#GetLastGameCardMountFailureResult]]&lt;br /&gt;
|-&lt;br /&gt;
| 509 || [5.0.0+] [[#ListApplicationIdOnGameCard]]&lt;br /&gt;
|-&lt;br /&gt;
| 510 || [9.0.0+] [[#GetGameCardPlatformRegion]]&lt;br /&gt;
|-&lt;br /&gt;
| 511 || [19.0.0+] GetGameCardWakenReadyEvent&lt;br /&gt;
|-&lt;br /&gt;
| 512 || [19.0.0+] IsGameCardApplicationRunning&lt;br /&gt;
|-&lt;br /&gt;
| 513 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 514 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 515 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 516 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 517 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 518 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 519 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 600 || [[#CountApplicationContentMeta]]&lt;br /&gt;
|-&lt;br /&gt;
| 601 || [[#ListApplicationContentMetaStatus]]&lt;br /&gt;
|-&lt;br /&gt;
| 602 || [2.0.0-5.1.0] ListAvailableAddOnContent&lt;br /&gt;
|-&lt;br /&gt;
| 603 || GetOwnedApplicationContentMetaStatus&lt;br /&gt;
|-&lt;br /&gt;
| 604 || [1.0.0-15.0.1] RegisterContentsExternalKey&lt;br /&gt;
|-&lt;br /&gt;
| 605 || ListApplicationContentMetaStatusWithRightsCheck&lt;br /&gt;
|-&lt;br /&gt;
| 606 || [3.0.0+] GetContentMetaStorage&lt;br /&gt;
|-&lt;br /&gt;
| 607 || [6.0.0+] [[#ListAvailableAddOnContent]]&lt;br /&gt;
|-&lt;br /&gt;
| 609 || [13.0.0+] ListAvailabilityAssuredAddOnContent&lt;br /&gt;
|-&lt;br /&gt;
| 610 || [14.0.0+] GetInstalledContentMetaStorage&lt;br /&gt;
|-&lt;br /&gt;
| 611 || [16.0.0+] PrepareAddOnContent&lt;br /&gt;
|-&lt;br /&gt;
| 700 || PushDownloadTaskList&lt;br /&gt;
|-&lt;br /&gt;
| 701 || [[#ClearTaskStatusList]]&lt;br /&gt;
|-&lt;br /&gt;
| 702 || [[#RequestDownloadTaskList]]&lt;br /&gt;
|-&lt;br /&gt;
| 703 || [[#RequestEnsureDownloadTask]]&lt;br /&gt;
|-&lt;br /&gt;
| 704 || [[#ListDownloadTaskStatus]]&lt;br /&gt;
|-&lt;br /&gt;
| 705 || [[#RequestDownloadTaskListData]]&lt;br /&gt;
|-&lt;br /&gt;
| 800 || RequestVersionList&lt;br /&gt;
|-&lt;br /&gt;
| 801 || ListVersionList&lt;br /&gt;
|-&lt;br /&gt;
| 802 || [3.0.0+] [[#RequestVersionListData]]&lt;br /&gt;
|-&lt;br /&gt;
| 900 || GetApplicationRecord&lt;br /&gt;
|-&lt;br /&gt;
| 901 || GetApplicationRecordProperty&lt;br /&gt;
|-&lt;br /&gt;
| 902 || EnableApplicationAutoUpdate&lt;br /&gt;
|-&lt;br /&gt;
| 903 || DisableApplicationAutoUpdate&lt;br /&gt;
|-&lt;br /&gt;
| 904 || [[#TouchApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 905 || RequestApplicationUpdate&lt;br /&gt;
|-&lt;br /&gt;
| 906 || [[#IsApplicationUpdateRequested]]&lt;br /&gt;
|-&lt;br /&gt;
| 907 || [[#WithdrawApplicationUpdateRequest]]&lt;br /&gt;
|-&lt;br /&gt;
| 908 || ListApplicationRecordInstalledContentMeta&lt;br /&gt;
|-&lt;br /&gt;
| 909 || [3.0.0-14.1.2] WithdrawCleanupAddOnContentsWithNoRightsRecommendation&lt;br /&gt;
|-&lt;br /&gt;
| 910 || [5.0.0+] HasApplicationRecord&lt;br /&gt;
|-&lt;br /&gt;
| 911 || [5.1.0+] SetPreInstalledApplication&lt;br /&gt;
|-&lt;br /&gt;
| 912 || [5.1.0+] ClearPreInstalledApplicationFlag&lt;br /&gt;
|-&lt;br /&gt;
| 913 || [9.0.0+] ListAllApplicationRecord&lt;br /&gt;
|-&lt;br /&gt;
| 914 || [9.0.0+] HideApplicationRecord&lt;br /&gt;
|-&lt;br /&gt;
| 915 || [9.0.0+] ShowApplicationRecord&lt;br /&gt;
|-&lt;br /&gt;
| 916 || [11.0.0+] IsApplicationAutoDeleteDisabled&lt;br /&gt;
|-&lt;br /&gt;
| 917 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 918 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 919 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 920 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 921 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 922 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 923 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 924 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 925 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 926 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 927 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 928 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 929 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 930 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 931 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 933 || [20.1.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 934 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 935 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 936 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 1000 || [[#RequestVerifyApplicationDeprecated]]&lt;br /&gt;
|-&lt;br /&gt;
| 1001 || CorruptApplicationForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 1002 || [3.0.0-9.2.0] [[#RequestVerifyAddOnContentsRights]]&lt;br /&gt;
|-&lt;br /&gt;
| 1003 || [5.0.0+] [[#RequestVerifyApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 1004 || [5.0.0+] CorruptContentForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 1200 || [[#NeedsUpdateVulnerability]]&lt;br /&gt;
|-&lt;br /&gt;
| 1300 || [[#IsAnyApplicationEntityInstalled]]&lt;br /&gt;
|-&lt;br /&gt;
| 1301 || DeleteApplicationContentEntities&lt;br /&gt;
|-&lt;br /&gt;
| 1302 || CleanupUnrecordedApplicationEntity&lt;br /&gt;
|-&lt;br /&gt;
| 1303 || [3.0.0-9.2.0] CleanupAddOnContentsWithNoRights&lt;br /&gt;
|-&lt;br /&gt;
| 1304 || [3.0.0+] DeleteApplicationContentEntity&lt;br /&gt;
|-&lt;br /&gt;
| 1308 || [5.0.0+] DeleteApplicationCompletelyForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 1309 || [6.0.0+] [[#CleanupUnavailableAddOnContents]]&lt;br /&gt;
|-&lt;br /&gt;
| 1310 || [10.0.0+] [[#RequestMoveApplicationEntity]]&lt;br /&gt;
|-&lt;br /&gt;
| 1311 || [10.0.0+] [[#EstimateSizeToMove]]&lt;br /&gt;
|-&lt;br /&gt;
| 1312 || [10.0.0+] HasMovableEntity&lt;br /&gt;
|-&lt;br /&gt;
| 1313 || [11.0.0+] CleanupOrphanContents&lt;br /&gt;
|-&lt;br /&gt;
| 1314 || [11.0.0+] CheckPreconditionSatisfiedToMove&lt;br /&gt;
|-&lt;br /&gt;
| 1400 || PrepareShutdown&lt;br /&gt;
|-&lt;br /&gt;
| 1500 || [[#FormatSdCard]]&lt;br /&gt;
|-&lt;br /&gt;
| 1501 || [[#NeedsSystemUpdateToFormatSdCard]]&lt;br /&gt;
|-&lt;br /&gt;
| 1502 || [[#GetLastSdCardFormatUnexpectedResult]]&lt;br /&gt;
|-&lt;br /&gt;
| 1504 || [3.0.0+] InsertSdCard&lt;br /&gt;
|-&lt;br /&gt;
| 1505 || [3.0.0+] RemoveSdCard&lt;br /&gt;
|-&lt;br /&gt;
| 1506 || [9.0.0+] GetSdCardStartupStatus&lt;br /&gt;
|-&lt;br /&gt;
| 1508 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 1509 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 1510 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 1511 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 1512 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 1600 || GetSystemSeedForPseudoDeviceId&lt;br /&gt;
|-&lt;br /&gt;
| 1601 || [3.0.0+] ResetSystemSeedForPseudoDeviceId&lt;br /&gt;
|-&lt;br /&gt;
| 1700 || ListApplicationDownloadingContentMeta&lt;br /&gt;
|-&lt;br /&gt;
| 1701 || [3.0.0+] [[#GetApplicationView]]&lt;br /&gt;
|-&lt;br /&gt;
| 1702 || [3.0.0+] GetApplicationDownloadTaskStatus&lt;br /&gt;
|-&lt;br /&gt;
| 1703 || [4.0.0+] [[#GetApplicationViewDownloadErrorContext]]&lt;br /&gt;
|-&lt;br /&gt;
| 1704 || [8.0.0+] [[#GetApplicationViewWithPromotionInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 1705 || [11.0.0+] [[#IsPatchAutoDeletableApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 1706 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 1800 || IsNotificationSetupCompleted&lt;br /&gt;
|-&lt;br /&gt;
| 1801 || GetLastNotificationInfoCount&lt;br /&gt;
|-&lt;br /&gt;
| 1802 || [[#ListLastNotificationInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 1803 || [3.0.0+] [[#ListNotificationTask]]&lt;br /&gt;
|-&lt;br /&gt;
| 1900 || [3.0.0-12.1.0] IsActiveAccount&lt;br /&gt;
|-&lt;br /&gt;
| 1901 || [4.0.0+] [[#RequestDownloadApplicationPrepurchasedRights]]&lt;br /&gt;
|-&lt;br /&gt;
| 1902 || [5.0.0+] GetApplicationTicketInfo&lt;br /&gt;
|-&lt;br /&gt;
| 1903 || [13.1.0+] RequestDownloadApplicationPrepurchasedRightsForAccount&lt;br /&gt;
|-&lt;br /&gt;
| 1904 || [22.0.0+] &lt;br /&gt;
|-&lt;br /&gt;
| 2000 || [4.0.0+] [[#GetSystemDeliveryInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 2001 || [4.0.0+] [[#SelectLatestSystemDeliveryInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 2002 || [4.0.0+] [[#VerifyDeliveryProtocolVersion]]&lt;br /&gt;
|-&lt;br /&gt;
| 2003 || [4.0.0+] [[#GetApplicationDeliveryInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 2004 || [4.0.0+] [[#HasAllContentsToDeliver]]&lt;br /&gt;
|-&lt;br /&gt;
| 2005 || [4.0.0+] [[#CompareApplicationDeliveryInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 2006 || [4.0.0+] [[#CanDeliverApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 2007 || [4.0.0+] [[#ListContentMetaKeyToDeliverApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 2008 || [4.0.0+] [[#NeedsSystemUpdateToDeliverApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 2009 || [4.0.0+] [[#EstimateRequiredSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 2010 || [4.0.0+] [[#RequestReceiveApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 2011 || [4.0.0+] [[#CommitReceiveApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 2012 || [4.0.0+] [[#GetReceiveApplicationProgress]]&lt;br /&gt;
|-&lt;br /&gt;
| 2013 || [4.0.0+] [[#RequestSendApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 2014 || [4.0.0+] [[#GetSendApplicationProgress]]&lt;br /&gt;
|-&lt;br /&gt;
| 2015 || [4.0.0+] [[#CompareSystemDeliveryInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 2016 || [4.0.0+] [[#ListNotCommittedContentMeta]]&lt;br /&gt;
|-&lt;br /&gt;
| 2017 || [4.0.0+] [[#RecoverDownloadTask]]&lt;br /&gt;
|-&lt;br /&gt;
| 2018 || [5.0.0+] [[#GetApplicationDeliveryInfoHash]]&lt;br /&gt;
|-&lt;br /&gt;
| 2019 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2050 || [6.0.0+] [[#GetApplicationRightsOnClient]]&lt;br /&gt;
|-&lt;br /&gt;
| 2051 || [9.0.0+] InvalidateRightsIdCache&lt;br /&gt;
|-&lt;br /&gt;
| 2052 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2053 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2100 || [6.0.0+] [[#GetApplicationTerminateResult]]&lt;br /&gt;
|-&lt;br /&gt;
| 2101 || [6.0.0+] GetRawApplicationTerminateResult&lt;br /&gt;
|-&lt;br /&gt;
| 2150 || [6.0.0+] CreateRightsEnvironment&lt;br /&gt;
|-&lt;br /&gt;
| 2151 || [6.0.0+] DestroyRightsEnvironment&lt;br /&gt;
|-&lt;br /&gt;
| 2152 || [6.0.0+] ActivateRightsEnvironment&lt;br /&gt;
|-&lt;br /&gt;
| 2153 || [6.0.0+] DeactivateRightsEnvironment&lt;br /&gt;
|-&lt;br /&gt;
| 2154 || [6.0.0+] ForceActivateRightsContextForExit&lt;br /&gt;
|-&lt;br /&gt;
| 2155 || [7.0.0+] UpdateRightsEnvironmentStatus&lt;br /&gt;
|-&lt;br /&gt;
| 2156 || [10.0.0-12.1.0] CreateRightsEnvironmentForMicroApplication ([9.0.0-9.2.0] CreateRightsEnvironmentForPreomia)&lt;br /&gt;
|-&lt;br /&gt;
| 2160 || [6.0.0+] AddTargetApplicationToRightsEnvironment&lt;br /&gt;
|-&lt;br /&gt;
| 2161 || [6.0.0+] SetUsersToRightsEnvironment&lt;br /&gt;
|-&lt;br /&gt;
| 2170 || [6.0.0+] GetRightsEnvironmentStatus&lt;br /&gt;
|-&lt;br /&gt;
| 2171 || [6.0.0+] GetRightsEnvironmentStatusChangedEvent&lt;br /&gt;
|-&lt;br /&gt;
| 2180 || [6.0.0+] RequestExtendExpirationInRightsEnvironment&lt;br /&gt;
|-&lt;br /&gt;
| 2181 || [6.0.0+] GetResultOfExtendExpirationInRightsEnvironment&lt;br /&gt;
|-&lt;br /&gt;
| 2182 || [6.0.0+] SetActiveRightsContextUsingStateToRightsEnvironment&lt;br /&gt;
|-&lt;br /&gt;
| 2183 || [20.1.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2190 || [6.0.0+] [[#GetRightsEnvironmentHandleForApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 2199 || [6.0.0+] GetRightsEnvironmentCountForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 2200 || [6.0.0-9.2.0] GetGameCardApplicationCopyIdentifier&lt;br /&gt;
|-&lt;br /&gt;
| 2201 || [6.0.0-9.2.0] GetInstalledApplicationCopyIdentifier&lt;br /&gt;
|-&lt;br /&gt;
| 2250 || [6.0.0-6.2.0] RequestReportActiveELicence&lt;br /&gt;
|-&lt;br /&gt;
| 2300 || [6.0.0-8.1.0] ListEventLog&lt;br /&gt;
|-&lt;br /&gt;
| 2350 || [7.0.0+] PerformAutoUpdateByApplicationId&lt;br /&gt;
|-&lt;br /&gt;
| 2351 || [9.0.0+] [[#RequestNoDownloadRightsErrorResolution]]&lt;br /&gt;
|-&lt;br /&gt;
| 2352 || [9.0.0+] [[#RequestResolveNoDownloadRightsError]]&lt;br /&gt;
|-&lt;br /&gt;
| 2353 || [10.0.0+] GetApplicationDownloadTaskInfo&lt;br /&gt;
|-&lt;br /&gt;
| 2354 || [11.0.0+] PrioritizeApplicationBackgroundTask&lt;br /&gt;
|-&lt;br /&gt;
| 2355 || [12.0.0+] PreferStorageEfficientUpdate&lt;br /&gt;
|-&lt;br /&gt;
| 2356 || [12.0.0+] RequestStorageEfficientUpdatePreferable&lt;br /&gt;
|-&lt;br /&gt;
| 2357 || [15.0.0+] EnableMultiCoreDownload&lt;br /&gt;
|-&lt;br /&gt;
| 2358 || [15.0.0+] DisableMultiCoreDownload&lt;br /&gt;
|-&lt;br /&gt;
| 2359 || [15.0.0+] IsMultiCoreDownloadEnabled&lt;br /&gt;
|-&lt;br /&gt;
| 2360 || [19.0.0+] GetApplicationDownloadTaskCount&lt;br /&gt;
|-&lt;br /&gt;
| 2361 || [19.0.0+] GetMaxApplicationDownloadTaskCount&lt;br /&gt;
|-&lt;br /&gt;
| 2362 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2363 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2364 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2365 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2366 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2367 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2368 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2369 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2400 || [8.0.0+] [[#GetPromotionInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 2401 || [8.0.0+] CountPromotionInfo&lt;br /&gt;
|-&lt;br /&gt;
| 2402 || [8.0.0+] [[#ListPromotionInfo|ListPromotionInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 2403 || [8.0.0+] [[#ImportPromotionJsonForDebug]]&lt;br /&gt;
|-&lt;br /&gt;
| 2404 || [8.0.0+] [[#ClearPromotionInfoForDebug]]&lt;br /&gt;
|-&lt;br /&gt;
| 2500 || [8.0.0+] ConfirmAvailableTime&lt;br /&gt;
|-&lt;br /&gt;
| 2510 || [9.0.0+] [[#CreateApplicationResource]]&lt;br /&gt;
|-&lt;br /&gt;
| 2511 || [9.0.0+] [[#GetApplicationResource]]&lt;br /&gt;
|-&lt;br /&gt;
| 2513 || [10.0.0+] [[#LaunchMicroApplication]] ([9.0.0-9.2.0] LaunchPreomia)&lt;br /&gt;
|-&lt;br /&gt;
| 2514 || [9.0.0+] ClearTaskOfAsyncTaskManager&lt;br /&gt;
|-&lt;br /&gt;
| 2515 || [10.0.0+] CleanupAllPlaceHolderAndFragmentsIfNoTask&lt;br /&gt;
|-&lt;br /&gt;
| 2516 || [10.0.0-14.1.2] EnsureApplicationCertificate&lt;br /&gt;
|-&lt;br /&gt;
| 2517 || [13.0.0+] [[#CreateApplicationInstance]]&lt;br /&gt;
|-&lt;br /&gt;
| 2518 || [13.0.0+] UpdateQualificationForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 2519 || [13.0.0+] IsQualificationTransitionSupported&lt;br /&gt;
|-&lt;br /&gt;
| 2520 || [13.0.0+] IsQualificationTransitionSupportedByProcessId&lt;br /&gt;
|-&lt;br /&gt;
| 2521 || [13.0.0-16.1.0] GetRightsUserChangedEvent&lt;br /&gt;
|-&lt;br /&gt;
| 2522 || [14.0.0+] IsRomRedirectionAvailable&lt;br /&gt;
|-&lt;br /&gt;
| 2523 || [17.0.0+] GetProgramId&lt;br /&gt;
|-&lt;br /&gt;
| 2524 || [19.0.0+] &lt;br /&gt;
|-&lt;br /&gt;
| 2525 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2526 || [22.0.0+] &lt;br /&gt;
|-&lt;br /&gt;
| 2800 || [9.0.0+] GetApplicationIdOfPreomia&lt;br /&gt;
|-&lt;br /&gt;
| 3000 || [11.0.0+] [[#RegisterDeviceLockKey]]&lt;br /&gt;
|-&lt;br /&gt;
| 3001 || [11.0.0+] [[#UnregisterDeviceLockKey]]&lt;br /&gt;
|-&lt;br /&gt;
| 3002 || [11.0.0+] [[#VerifyDeviceLockKey]]&lt;br /&gt;
|-&lt;br /&gt;
| 3003 || [11.0.0+] [[#HideApplicationIcon]]&lt;br /&gt;
|-&lt;br /&gt;
| 3004 || [11.0.0+] [[#ShowApplicationIcon]]&lt;br /&gt;
|-&lt;br /&gt;
| 3005 || [11.0.0+] [[#HideApplicationTitle]]&lt;br /&gt;
|-&lt;br /&gt;
| 3006 || [11.0.0+] [[#ShowApplicationTitle]]&lt;br /&gt;
|-&lt;br /&gt;
| 3007 || [11.0.0+] [[#EnableGameCard]]&lt;br /&gt;
|-&lt;br /&gt;
| 3008 || [11.0.0+] [[#DisableGameCard]]&lt;br /&gt;
|-&lt;br /&gt;
| 3009 || [11.0.0+] [[#EnableLocalContentShare]]&lt;br /&gt;
|-&lt;br /&gt;
| 3010 || [11.0.0+] [[#DisableLocalContentShare]]&lt;br /&gt;
|-&lt;br /&gt;
| 3011 || [11.0.0+] [[#IsApplicationIconHidden]]&lt;br /&gt;
|-&lt;br /&gt;
| 3012 || [11.0.0+] [[#IsApplicationTitleHidden]]&lt;br /&gt;
|-&lt;br /&gt;
| 3013 || [11.0.0+] [[#IsGameCardEnabled]]&lt;br /&gt;
|-&lt;br /&gt;
| 3014 || [11.0.0+] [[#IsLocalContentShareEnabled]]&lt;br /&gt;
|-&lt;br /&gt;
| 3015 || [18.0.0+] GetNetworkUpdateRequiredByGameCardDetectionEvent&lt;br /&gt;
|-&lt;br /&gt;
| 3050 || [14.0.0+] ListAssignELicenseTaskResult&lt;br /&gt;
|-&lt;br /&gt;
| 3100 || [17.0.0+] [[#GetSafeSystemVersionCheckInfoOld|GetSafeSystemVersionCheckInfoOld]] ([17.0.0-21.2.0] [[#GetSafeSystemVersionCheckInfo|GetSafeSystemVersionCheckInfo]])&lt;br /&gt;
|-&lt;br /&gt;
| 3101 || [17.0.0+] [[#RequestUpdateSafeSystemVersionCheckInfo|RequestUpdateSafeSystemVersionCheckInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 3102 || [17.0.0+] [[#ResetSafeSystemVersionCheckInfo|ResetSafeSystemVersionCheckInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 3104 || [18.0.0+] GetApplicationNintendoLogo&lt;br /&gt;
|-&lt;br /&gt;
| 3105 || [18.0.0+] GetApplicationStartupMovie&lt;br /&gt;
|-&lt;br /&gt;
| 3106 || [22.0.0+] [[#GetSafeSystemVersionCheckInfo|GetSafeSystemVersionCheckInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 3150 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 4000 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4004 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4006 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4007 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4008 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4009 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4010 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4011 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4012 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4013 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4015 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4017 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4019 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4020 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4021 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4022 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4023 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4024 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4025 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4026 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4027 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4028 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4029 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4030 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4031 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4032 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4033 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4034 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4035 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4037 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4038 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4039 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4040 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4041 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4042 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4043 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4044 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4045 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4046 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4049 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4050 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4051 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4052 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4053 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4054 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4055 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4056 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4057 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4058 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4059 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4060 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4061 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4062 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4063 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4064 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4065 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4066 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4067 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4068 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4069 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4070 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4071 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4072 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4073 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4074 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4075 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4076 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4077 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4078 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4079 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4080 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4081 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4083 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4084 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4085 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4086 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4087 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4088 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4089 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4090 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4091 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4092 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4093 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4094 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4095 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4096 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4097 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4099 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 5000 || [18.0.0+] &lt;br /&gt;
|-&lt;br /&gt;
| 5001 || [18.0.0+] &lt;br /&gt;
|-&lt;br /&gt;
| 9999 || [10.0.0-10.2.0] GetApplicationCertificate&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[4.0.0+] RequestDownloadAddOnContent now takes an additional 8-bytes of input.&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationRecordUpdateSystemEvent ====&lt;br /&gt;
No input, returns an output Event handle with EventClearMode=1.&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationViewDeprecated ====&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of [[#ApplicationViewDeprecated]], a type-0x5 input buffer containing an array of u64 [[NCM_services#ApplicationId|ApplicationIds]], no output.&lt;br /&gt;
&lt;br /&gt;
On newer system-versions this is the same as [[#GetApplicationView]], except this converts the output from the func called in the loop from [[#ApplicationView]] to [[#ApplicationViewDeprecated]].&lt;br /&gt;
&lt;br /&gt;
==== DeleteApplicationEntity ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== DeleteApplicationCompletely ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== DeleteRedundantApplicationEntity ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== IsApplicationEntityMovable ====&lt;br /&gt;
Takes an input u8 [[NCM_services#StorageId|StorageId]], an [[NCM_services#ApplicationId|ApplicationId]], returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
==== MoveApplicationEntity ====&lt;br /&gt;
Takes an input u8 [[NCM_services#StorageId|StorageId]], an [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== RequestApplicationUpdateInfo ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
The data that can be read from the [[#IAsyncValue]] is [[#ApplicationUpdateInfo]].&lt;br /&gt;
&lt;br /&gt;
Before using the cmd, official sw uses [[Network_Interface_services#IsAnyInternetRequestAccepted|IsAnyInternetRequestAccepted]] with the output from [[Network_Interface_services#GetClientId|GetClientId]], throwing an error when the returned bool is false.&lt;br /&gt;
&lt;br /&gt;
==== CancelApplicationDownload ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== ResumeApplicationDownload ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== CheckApplicationLaunchVersion ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== CalculateApplicationDownloadRequiredSize ====&lt;br /&gt;
Takes an input u8 [[NCM_services#StorageId|StorageId]], an [[NCM_services#ApplicationId|ApplicationId]], returns an output s64.&lt;br /&gt;
&lt;br /&gt;
==== CleanupSdCard ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== GetSdCardMountStatusChangedEvent ====&lt;br /&gt;
No input, returns an output Event handle with EventClearMode=0.&lt;br /&gt;
&lt;br /&gt;
==== GetGameCardUpdateDetectionEvent ====&lt;br /&gt;
No input, returns an output Event handle with EventClearMode=0.&lt;br /&gt;
&lt;br /&gt;
This Event is used by [[qlaunch]] to check whether a card-sysupdate is required.&lt;br /&gt;
&lt;br /&gt;
==== DisableApplicationAutoDelete ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== EnableApplicationAutoDelete ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== SetApplicationTerminateResult ====&lt;br /&gt;
Takes an input u32 Result, an [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== ClearApplicationTerminateResult ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== GetLastSdCardMountUnexpectedResult ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== GetRequestServerStopper ====&lt;br /&gt;
No input, returns an output [[#IRequestServerStopper]].&lt;br /&gt;
&lt;br /&gt;
This increfs a state ref-count, with decref being handled when the object is closed. This ref-count is checked by [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]] and related cmds.&lt;br /&gt;
&lt;br /&gt;
==== CancelApplicationApplyDelta ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== ResumeApplicationApplyDelta ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== CalculateApplicationApplyDeltaRequiredSize ====&lt;br /&gt;
Takes an input u8 [[NCM_services#StorageId|StorageId]], an [[NCM_services#ApplicationId|ApplicationId]], returns an output s64.&lt;br /&gt;
&lt;br /&gt;
==== ResumeAll ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== GetStorageSize ====&lt;br /&gt;
Takes an input u8 [[NCM_services#StorageId|StorageId]], returns two output s64s.&lt;br /&gt;
&lt;br /&gt;
This temporarily mounts the [[Filesystem_services#OpenContentStorageFileSystem|ContentStorage]] specified by the StorageId (must be BuiltInUser or SdCard). The two output s64s are the output from [[Filesystem_services#GetTotalSpaceSize|GetTotalSpaceSize]] and [[Filesystem_services#GetFreeSpaceSize|GetFreeSpaceSize]] with this ContentStorage, with it this being unmounted afterwards.&lt;br /&gt;
&lt;br /&gt;
==== RequestUpdateApplication2 ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
See [[#RequestApplicationUpdateInfo]] regarding nifm.&lt;br /&gt;
&lt;br /&gt;
==== LaunchApplication ====&lt;br /&gt;
Takes an input u8 ProgramIndex, an input [[#ApplicationLaunchInfo]], returns an output u64.&lt;br /&gt;
&lt;br /&gt;
[18.0.0+] Now takes a total of 0x58 bytes of input.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] Now takes a total of 0x88 bytes of input.&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationLaunchInfo ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output [[#ApplicationLaunchInfo]].&lt;br /&gt;
&lt;br /&gt;
[18.0.0+] Now returns a total of 0x50 bytes of output.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] Now returns a total of 0x80 bytes of output.&lt;br /&gt;
&lt;br /&gt;
==== AcquireApplicationLaunchInfo ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output [[#ApplicationLaunchInfo]].&lt;br /&gt;
&lt;br /&gt;
This verifies that a state flag is set and that a state field matches the input ApplicationId, throwing an error otherwise. The [[#ApplicationLaunchInfo]] from state is copied to output, then the state flag is cleared.&lt;br /&gt;
&lt;br /&gt;
[18.0.0+] Now returns a total of 0x50 bytes of output.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] Now returns a total of 0x80 bytes of output.&lt;br /&gt;
&lt;br /&gt;
==== GetMainApplicationProgramIndexByApplicationLaunchInfo ====&lt;br /&gt;
[18.0.0+] Now takes a total of 0x50 bytes of input.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] Now returns a total of 0x80 bytes of output.&lt;br /&gt;
&lt;br /&gt;
==== LaunchDevMenu ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
This is used by AM cmd [[Applet_Manager_services#LaunchDevMenu|LaunchDevMenu]].&lt;br /&gt;
&lt;br /&gt;
This loads ProgramIds from [[System_Settings|system-settings]] &amp;lt;code&amp;gt;ns.applet!devmenu_id&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;ns.applet!devoverlaydisp_id&amp;lt;/code&amp;gt;, which only exists on devunits. An error is thrown if loading these fail.&lt;br /&gt;
&lt;br /&gt;
[[NCM_services#ncm|OpenContentMetaDatabase]] is used with StorageId = NandSystem, then IContentMetaDatabase GetLatestContentMetaKey is used with both of the above ProgramIds to verify that the cmd is successful.&lt;br /&gt;
&lt;br /&gt;
Then if the above succeeds, the above titles are launched with the above StorageId via [[Process_Manager_services|pmshell]] LaunchProgram ([10.0.0+] [[PGL_services#LaunchProgram|pgl]] with pgl_launch_flags=0), with a 0.5s sleep-thread afterwards on success. [[Process_Manager_services#LaunchFlags|LaunchFlags]] value 0xB is used here.&lt;br /&gt;
&lt;br /&gt;
==== DeleteUserSaveDataAll ====&lt;br /&gt;
Takes an input [[Account_services#Uid|Uid]], returns an output [[#IProgressMonitorForDeleteUserSaveDataAll]].&lt;br /&gt;
&lt;br /&gt;
On success, [[#IProgressMonitorForDeleteUserSaveDataAll]] GetProgress is used with the output being copied into object state.&lt;br /&gt;
&lt;br /&gt;
==== DeleteUserSystemSaveData ====&lt;br /&gt;
Takes an input [[Account_services#Uid|Uid]], an u64 SystemSaveDataId, no output.&lt;br /&gt;
&lt;br /&gt;
==== DeleteSaveData ====&lt;br /&gt;
Takes an input u8 [[Filesystem_services#SaveDataSpaceId|SaveDataSpaceId]], an u64 SaveDataId, no output.&lt;br /&gt;
&lt;br /&gt;
==== UnregisterNetworkServiceAccount ====&lt;br /&gt;
Takes an input [[Account_services#Uid|Uid]], no output.&lt;br /&gt;
&lt;br /&gt;
==== UnregisterNetworkServiceAccountWithUserSaveDataDeletion ====&lt;br /&gt;
Takes an input [[Account_services#Uid|Uid]], no output.&lt;br /&gt;
&lt;br /&gt;
==== LaunchLibraryApplet ====&lt;br /&gt;
Takes an input u64 [[NCM_services#ProgramId|ProgramId]], returns an output u64.&lt;br /&gt;
&lt;br /&gt;
The specified program is launched with StorageId=BuiltInSystem via [[Process_Manager_services|pmshell]] LaunchProgram ([10.0.0+] [[PGL_services#LaunchProgram|pgl]] with pgl_launch_flags=0). [[Process_Manager_services#LaunchFlags|LaunchFlags]] value 0x9 is used here. The output u64 from here is written to the output for this cmd, on success.&lt;br /&gt;
&lt;br /&gt;
This is used by [[Applet_Manager_services|AM]].&lt;br /&gt;
&lt;br /&gt;
==== LaunchSystemApplet ====&lt;br /&gt;
No input, returns an output u64.&lt;br /&gt;
&lt;br /&gt;
A state flag must be non-zero, otherwise an error is thrown. When a state field is value 1, a hard-coded ProgramId for MaintenanceMenu is used. Otherwise, the ProgramId is loaded from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;ns.applet!system_applet_id&amp;lt;/code&amp;gt; ([20.0.0+] &amp;lt;code&amp;gt;ns.applet!system_applet_id_gen2&amp;lt;/code&amp;gt;).&lt;br /&gt;
&lt;br /&gt;
The SystemApplet is launched with StorageId=BuiltInSystem via [[Process_Manager_services|pmshell]] LaunchProgram ([10.0.0+] [[PGL_services#LaunchProgram|pgl]] with pgl_launch_flags=0). [[Process_Manager_services#LaunchFlags|LaunchFlags]] value 0x9 is used here. The output u64 from here is written to the output for this cmd, on success.&lt;br /&gt;
&lt;br /&gt;
This is used by [[Applet_Manager_services|AM]].&lt;br /&gt;
&lt;br /&gt;
==== LaunchOverlayApplet ====&lt;br /&gt;
No input, returns an output u64.&lt;br /&gt;
&lt;br /&gt;
A state flag must be non-zero, otherwise an error is thrown. The ProgramId is loaded from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;ns.applet!overlay_applet_id&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
The OverlayApplet is launched with StorageId=BuiltInSystem via [[Process_Manager_services|pmshell]] LaunchProgram ([10.0.0+] [[PGL_services#LaunchProgram|pgl]] with pgl_launch_flags=0). [[Process_Manager_services#LaunchFlags|LaunchFlags]] value 0x9 is used here. The output u64 from here is written to the output for this cmd, on success.&lt;br /&gt;
&lt;br /&gt;
This is used by [[Applet_Manager_services|AM]].&lt;br /&gt;
&lt;br /&gt;
==== RequestDownloadApplicationControlData ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
See [[#RequestApplicationUpdateInfo]] regarding nifm.&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationControlProperty ====&lt;br /&gt;
[18.0.0+] Now takes a total of 0x58 bytes of input.&lt;br /&gt;
&lt;br /&gt;
==== ListApplicationTitle ====&lt;br /&gt;
Takes an input TransferMemory handle, a type-0x5 input buffer containing an array of u64 [[NCM_services#ApplicationId|ApplicationIds]], an u8 [[#ApplicationControlSource]], an u64 size, returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
[[qlaunch]] uses value 0x1 for the u8.&lt;br /&gt;
&lt;br /&gt;
The user-process creates the TransferMemory with permissions=R--.&lt;br /&gt;
&lt;br /&gt;
The data available with [[#IAsyncValue]] Get is a s32 for the offset within the TransferMemory where the output data is located, GetSize returns the total byte-size of the data located here. The data located here is the [[NACP_Format|NACP]] title-entry for each specified ApplicationId.&lt;br /&gt;
&lt;br /&gt;
The TransferMemory size must be at least: count*sizeof([[NACP_Format|title-entry]]) + count*sizeof(u64) + count*[[#GetApplicationControlData|0x24000]].&lt;br /&gt;
&lt;br /&gt;
This is essentially an async wrapper for [[#GetApplicationControlData]], with support for multiple ApplicationIds.&lt;br /&gt;
&lt;br /&gt;
==== ListApplicationIcon ====&lt;br /&gt;
Takes an input TransferMemory handle, a type-0x5 input buffer containing an array of u64 [[NCM_services#ApplicationId|ApplicationIds]], an u8 [[#ApplicationControlSource]], an u64 size, returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
The user-process creates the TransferMemory with permissions=R--.&lt;br /&gt;
&lt;br /&gt;
The data available with [[#IAsyncValue]] Get is a s32 for the offset within the TransferMemory where the output data is located, GetSize returns the total byte-size of the data located here. This data is: an u64 for total entries, an array of u64s for each icon size, then the icon JPEGs for the specified ApplicationIds.&lt;br /&gt;
&lt;br /&gt;
The TransferMemory size must be at least: 0x4 + count*sizeof(u64) + count*[[#GetApplicationControlData|0x20000]] + count*sizeof(u64) + [[#GetApplicationControlData|0x24000]].&lt;br /&gt;
&lt;br /&gt;
This is essentially an async wrapper for [[#GetApplicationControlData]], with support for multiple ApplicationIds.&lt;br /&gt;
&lt;br /&gt;
==== Cmd421 ====&lt;br /&gt;
Takes an input TransferMemory handle, a type-0x5 input buffer containing an array of u64 [[NCM_services#ApplicationId|ApplicationIds]], an u8 [[#ApplicationControlSource]], an u64 size, returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
This is essentially the same as [[#ListApplicationTitle|ListApplicationTitle]] except the ApplicationControlSource is used here (ListApplicationTitle ignores it and uses 0xF0 instead).&lt;br /&gt;
&lt;br /&gt;
The TransferMemory size must be at least: count*sizeof(u64) + count*[[NACP#ApplicationTitle|0x300]] + [[#GetApplicationControlData|0x1d000]].&lt;br /&gt;
&lt;br /&gt;
The async task impl code eventually compares ApplicationControlSource with 0xF0, with a separate code-path being used when it doesn&#039;t match (which also handles [[NACP|compression]] when needed).&lt;br /&gt;
&lt;br /&gt;
==== RequestCheckGameCardRegistration ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
See [[#RequestApplicationUpdateInfo]] regarding nifm.&lt;br /&gt;
&lt;br /&gt;
==== RequestGameCardRegistrationGoldPoint ====&lt;br /&gt;
Takes an input [[Account_services#Uid|Uid]], an [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
The data that can be read from the [[#IAsyncValue]] is 4-bytes.&lt;br /&gt;
&lt;br /&gt;
See [[#RequestApplicationUpdateInfo]] regarding nifm.&lt;br /&gt;
&lt;br /&gt;
==== RequestRegisterGameCard ====&lt;br /&gt;
Takes an input s32, an [[Account_services#Uid|Uid]], an [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
See [[#RequestApplicationUpdateInfo]] regarding nifm.&lt;br /&gt;
&lt;br /&gt;
==== GetGameCardMountFailureEvent ====&lt;br /&gt;
No input, returns an output Event handle with EventClearMode=0.&lt;br /&gt;
&lt;br /&gt;
==== IsGameCardInserted ====&lt;br /&gt;
No input, returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
==== EnsureGameCardAccess ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== GetLastGameCardMountFailureResult ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== ListApplicationIdOnGameCard ====&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of u64 [[NCM_services#ApplicationId|ApplicationIds]], returns an output s32 for total output entries.&lt;br /&gt;
&lt;br /&gt;
==== GetGameCardPlatformRegion ====&lt;br /&gt;
No input, returns an u8 &#039;&#039;&#039;GameCardPlatformRegion&#039;&#039;&#039; (0x00 = Global, 0x01 = China).&lt;br /&gt;
&lt;br /&gt;
This calls [[Filesystem_services#IDeviceOperator|fsp-srv IDeviceOperator]] GetGameCardCompatibilityType and returns the result.&lt;br /&gt;
&lt;br /&gt;
==== ListAvailableAddOnContent ====&lt;br /&gt;
[10.0.0+] This now takes a total of 0x10-bytes of input instead of a total of 0x18-bytes of input.&lt;br /&gt;
&lt;br /&gt;
[15.0.0+] This now takes a total of 0x8-bytes of input instead of a total of 0x10-bytes of input.&lt;br /&gt;
&lt;br /&gt;
==== RequestDownloadTaskListData ====&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
==== TouchApplication ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== IsApplicationUpdateRequested ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output u8 bool and an u32.&lt;br /&gt;
&lt;br /&gt;
The output u32 is only valid when the output bool is set.&lt;br /&gt;
&lt;br /&gt;
==== WithdrawApplicationUpdateRequest ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== RequestVerifyApplicationDeprecated ====&lt;br /&gt;
Takes an input TransferMemory handle, an [[NCM_services#ApplicationId|ApplicationId]], an u64 size, returns an output Event handle and an [[#IProgressAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
On newer system-versions this calls the same func as [[#RequestVerifyApplication]], with the u32 value set to 0x7.&lt;br /&gt;
&lt;br /&gt;
==== RequestVerifyAddOnContentsRights ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IProgressAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
==== RequestVerifyApplication ====&lt;br /&gt;
Takes an input TransferMemory handle, an u32, an [[NCM_services#ApplicationId|ApplicationId]], an u64 size, returns an output Event handle and an [[#IProgressAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
Official sw creates the TransferMemory with an user-specified buffer with permissions=0. [[qlaunch]] uses buffer size 0x100000.&lt;br /&gt;
&lt;br /&gt;
Official sw has an additional wrapper func which calls the original wrapper func, this uses value 0x7 for the u32. This is the same func used by [[qlaunch]].&lt;br /&gt;
&lt;br /&gt;
==== IsAnyApplicationEntityInstalled ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
==== CleanupUnavailableAddOnContents ====&lt;br /&gt;
Takes an input u64 [[NCM_services#ApplicationId|ApplicationId]], an [[Account_services#Uid|Uid]], no output.&lt;br /&gt;
&lt;br /&gt;
==== RequestMoveApplicationEntity ====&lt;br /&gt;
Takes an input TransferMemory handle, a type-0x5 input buffer containing an array of [[NCM_services#StorageId|StorageId]], a [[NCM_services#StorageId|StorageId]], an u32 bitfield of &amp;quot;nn::ns::KeepApplicationEntityFlagTag&amp;quot;, an [[NCM_services#ApplicationId|ApplicationId]], an u64 tmem_size, returns an output Event handle and an [[#IProgressAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
The TransferMemory uses permissions=0.&lt;br /&gt;
&lt;br /&gt;
==== EstimateSizeToMove ====&lt;br /&gt;
Takes a type-0x5 input buffer containing an array of [[NCM_services#StorageId|StorageId]], a [[NCM_services#StorageId|StorageId]], an u32 bitfield of &amp;quot;nn::ns::KeepApplicationEntityFlagTag&amp;quot;, an [[NCM_services#ApplicationId|ApplicationId]], returns an output s64.&lt;br /&gt;
&lt;br /&gt;
This calls a func also used by [[#RequestMoveApplicationEntity]], then calls another func.&lt;br /&gt;
&lt;br /&gt;
==== FormatSdCard ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== NeedsSystemUpdateToFormatSdCard ====&lt;br /&gt;
No input, returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
==== GetLastSdCardFormatUnexpectedResult ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationView ====&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of [[#ApplicationView]], a type-0x5 input buffer containing an array of u64 [[NCM_services#ApplicationId|ApplicationIds]], no output.&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationViewDownloadErrorContext ====&lt;br /&gt;
Takes a type-0x16 output buffer containg an [[Error_Applet#ErrorContext|ErrorContext]], an u64 [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationViewWithPromotionInfo ====&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of [[#ApplicationViewWithPromotionInfo]], a type-0x5 input buffer containing an array of u64 [[NCM_services#ApplicationId|ApplicationIds]], no output.&lt;br /&gt;
&lt;br /&gt;
==== IsPatchAutoDeletableApplication ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output bool.&lt;br /&gt;
&lt;br /&gt;
Compares the input ApplicationId with the value of [[System_Settings|system-setting]] &amp;lt;code&amp;gt;ns.application!auto_deletable_application_id_on_not_enough_space&amp;lt;/code&amp;gt;, with the bool being set to the comparsion result.&lt;br /&gt;
&lt;br /&gt;
==== ListLastNotificationInfo ====&lt;br /&gt;
Takes a type-0x6 buffer containing an array with struct entry size 0x90-bytes. Returns 4-bytes of output.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] The struct size is now 0x98-bytes.&lt;br /&gt;
&lt;br /&gt;
==== ListNotificationTask ====&lt;br /&gt;
Takes a type-0x6 buffer containing an array with struct entry size 0xB0-bytes. Returns 4-bytes of output.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] The struct size is now 0xB8-bytes.&lt;br /&gt;
&lt;br /&gt;
==== RequestDownloadApplicationPrepurchasedRights ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
See [[#RequestApplicationUpdateInfo]] regarding nifm.&lt;br /&gt;
&lt;br /&gt;
==== GetSystemDeliveryInfo ====&lt;br /&gt;
Takes a type-0x16 output buffer containing a [[#SystemDeliveryInfo]], no output.&lt;br /&gt;
&lt;br /&gt;
This generates a [[#SystemDeliveryInfo]] using the currently installed SystemUpdate meta title.&lt;br /&gt;
&lt;br /&gt;
==== SelectLatestSystemDeliveryInfo ====&lt;br /&gt;
Takes a type-0x15 input buffer containing a [[#SystemDeliveryInfo]], a type-0x5 input buffer containing an array of [[#SystemDeliveryInfo]], a type-0x5 input buffer containing an array of [[#ApplicationDeliveryInfo]], and returns an output s32.&lt;br /&gt;
&lt;br /&gt;
This determines the latest version (RequiredSystemVersion) from the input [[#ApplicationDeliveryInfo]] array (ApplicationDeliveryProtocolVersion and the HMAC are also validated), using value 0 if the array is empty.&lt;br /&gt;
&lt;br /&gt;
* [20.0.0+] The following code block now only runs when the SystemDeliveryInfoPlatform from the type-0x15 [[#SystemDeliveryInfo]] buffer matches the [[System_Settings|sys-setting]].&lt;br /&gt;
** It then loops through the [[#ApplicationDeliveryInfo]] array again:&lt;br /&gt;
** This uses functionality which essentially uses [[Shared_Database_services|pl:s]] GetFunctionBlackListSystemVersionToAuthorize with the [[#ApplicationDeliveryInfo]] ApplicationId and ApplicationFunctionAuthorizationId=0x5 then parses the output, using cached data if available. The error is returned on failure.&lt;br /&gt;
** tmp_version = out_u8 == 0 ? 0 : out_u32 + 0x10000;&lt;br /&gt;
** Then the current latest-version value is updated with tmp_version, if tmp_version is higher.&lt;br /&gt;
&lt;br /&gt;
If this version value is less than a state field, the state field value is used instead (state field originates from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;contents_delivery!required_system_version_to_deliver_application&amp;lt;/code&amp;gt;).&lt;br /&gt;
&lt;br /&gt;
Then this selects the [[#SystemDeliveryInfo]] with the latest version from the input array. The output s32 is an index in that array for the selected entry, -1 if none found.&lt;br /&gt;
&lt;br /&gt;
During the above loop it first calls the [[#SystemDeliveryInfo]] validation func, returning the Result on failure. Then it runs additional validation, with the [[#SystemDeliveryInfo]] entry being ignored on failure:&lt;br /&gt;
* The above latest-version value must be at least the version value from the type-0x15 [[#SystemDeliveryInfo]] buffer and the [[#SystemDeliveryInfo]] array entry.&lt;br /&gt;
* When HasExFat is set in the type-0x15 [[#SystemDeliveryInfo]] buffer, it must be set in the [[#SystemDeliveryInfo]] array entry.&lt;br /&gt;
* FirmwareVariationId in the type-0x15 [[#SystemDeliveryInfo]] buffer must not be 0xFF.&lt;br /&gt;
* UpdatableFirmwareGroupId in the [[#SystemDeliveryInfo]] array entry must not be 0xFF. The value must be within bounds of the settings array ([[System_Settings|sys-settings]] &amp;lt;code&amp;gt;contents_delivery!updatable_firmware_group_string&amp;lt;/code&amp;gt;).&lt;br /&gt;
* PlatformRegion in the [[#SystemDeliveryInfo]] array entry and the type-0x15 [[#SystemDeliveryInfo]] buffer must match.&lt;br /&gt;
* Lastly when the following is true, this indicates success: (settings_array[UpdatableFirmwareGroupId] &amp;gt;&amp;gt; {above FirmwareVariationId}) &amp;amp; 1.&lt;br /&gt;
&lt;br /&gt;
==== VerifyDeliveryProtocolVersion ====&lt;br /&gt;
Takes a type-0x15 input buffer containing a [[#SystemDeliveryInfo]], no output.&lt;br /&gt;
&lt;br /&gt;
This validates the [[#SystemDeliveryInfo]] HMAC and the protocol-version fields. Then an error is returned when SystemUpdateVersion is less than a state field, otherwise 0 is returned (state field originates from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;contents_delivery!required_system_version_to_deliver_application&amp;lt;/code&amp;gt;).&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationDeliveryInfo ====&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of [[#ApplicationDeliveryInfo|ApplicationDeliveryInfo]], an input u32 bitmask &amp;lt;code&amp;gt;nn::ns::ApplicationDeliveryAttributeTag&amp;lt;/code&amp;gt;, an [[NCM_services#ApplicationId|ApplicationId]], and returns an output s32 total_out.&lt;br /&gt;
&lt;br /&gt;
[11.0.0+] An error is thrown if LocalContentShare is not [[#IsLocalContentShareEnabled|enabled]].&lt;br /&gt;
&lt;br /&gt;
An error is thrown if any bit is set in ApplicationDeliveryAttributeTag besides bit1, this must also be &amp;lt;=0x3. The output array-count must be at least 1: only 1 entry will be written to this array (hence on success total_out will also only be 1 on success).&lt;br /&gt;
&lt;br /&gt;
[7.0.0+] An error is thrown if the state ref-count for [[#GetRequestServerStopper|RequestServerStopper]] is zero. [7.0.0-7.0.1] The func which checks this would also return success when a field prior to the previously mentioned field is 0 (checked before the ref-count).&lt;br /&gt;
&lt;br /&gt;
An error is thrown if [[NIM_services|nim]] ListApplicationApplyDeltaTask returns a task.&lt;br /&gt;
&lt;br /&gt;
HasApplicationRecord is called with the input [[NCM_services#ApplicationId|ApplicationId]], an error is returned if the record isn&#039;t found.&lt;br /&gt;
&lt;br /&gt;
[[#ApplicationDeliveryInfo|RequiredApplicationVersion]] is initially set to the output version from [[Shared_Database_services|avm]] GetLaunchRequiredVersion. Later when ContentMetaType == Application etc, it calls a func. This func uses [[NCM_services|ncm]] IContentMetaDatabase GetRequiredApplicationVersion. If the output version is higher than the [[#ApplicationDeliveryInfo|RequiredApplicationVersion]] field then the output version is written here. Immediately aferwards, it also checks whether the bit for Compacted is set from [[NCM_services|ncm]] IContentMetaDatabase GetAttributes, clearing [[#ApplicationDeliveryInfo|ApplicationVersion]] if the attribute is set.&lt;br /&gt;
&lt;br /&gt;
[20.0.0+] [[#ApplicationDeliveryInfo|ApplicationDeliveryInfo]] ContentMetaPlatform and ProperProgramExists are now set using data from [[NCM_services|ncm]].&lt;br /&gt;
&lt;br /&gt;
[20.0.0+] [[Shared_Database_services|pl:s]] GetFunctionBlackListSystemVersionToAuthorize with ApplicationFunctionAuthorizationId=0x5 is now used, the output version is written to [[#ApplicationDeliveryInfo|RequiredSystemVersion]] when it&#039;s higher than the value previously written here.&lt;br /&gt;
&lt;br /&gt;
[20.0.0+] [[Shared_Database_services|pl:s]] GetRequiredApplicationVersion with ApplicationFunctionAuthorizationId=0x5 is now used, the output version is written to [[#ApplicationDeliveryInfo|RequiredApplicationVersion]] when it&#039;s higher than the value previously written here.&lt;br /&gt;
&lt;br /&gt;
==== HasAllContentsToDeliver ====&lt;br /&gt;
Takes a type-0x5 input buffer containing an array of [[#ApplicationDeliveryInfo]], returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
The array-count must match 1.&lt;br /&gt;
&lt;br /&gt;
This uses the same LocalContentShare check as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
After validating the [[#ApplicationDeliveryInfo]], the output bool is set to [[#ApplicationDeliveryInfo|ApplicationDeliveryAttributeTag]] &amp;amp; 0x10000002 != 0x2, then this returns 0.&lt;br /&gt;
&lt;br /&gt;
==== CompareApplicationDeliveryInfo ====&lt;br /&gt;
Takes two type-0x5 input buffers containing an array of [[#ApplicationDeliveryInfo]], returns an output s32.&lt;br /&gt;
&lt;br /&gt;
This uses the same LocalContentShare check as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
The array-count for both buffers must be 1, otherwise an error is returned.&lt;br /&gt;
&lt;br /&gt;
Both [[#ApplicationDeliveryInfo]] are validated, then the application-version in the first/second buffer are compared. The output s32 is set to the comparison result: -1 for less than, 0 for equal, and 1 for higher than.&lt;br /&gt;
&lt;br /&gt;
==== CanDeliverApplication ====&lt;br /&gt;
Takes two type-0x5 input buffers containing an array of [[#ApplicationDeliveryInfo]], returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
The array-count for the second buffer must be 1, otherwise an error is returned.&lt;br /&gt;
&lt;br /&gt;
This uses the same LocalContentShare check as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
The second [[#ApplicationDeliveryInfo]] buffer is validated. An error is thrown when [[#ApplicationDeliveryInfo|ApplicationDeliveryAttributeTag]] (second buffer) &amp;amp; 0x3 != 0x2, likewise when bit28 is clear in this field (bitmask 0x10000000).&lt;br /&gt;
&lt;br /&gt;
The array-count for the first buffer must be &amp;lt;=1, otherwise an error is returned. If the array-count for the first buffer is 0, this will return 0 with the output bool set to 0. The first [[#ApplicationDeliveryInfo]] buffer is validated. An error is thrown when [[#ApplicationDeliveryInfo|ApplicationDeliveryAttributeTag]] (first buffer) bit1 is clear or bit0 set. An error is thrown when [[#ApplicationDeliveryInfo|ApplicationDeliveryAttributeTag]] (second buffer) bit1 is clear.&lt;br /&gt;
&lt;br /&gt;
When [[#ApplicationDeliveryInfo|RequiredApplicationVersion]] (first or second buffer) is higher than [[#ApplicationDeliveryInfo|ApplicationVersion]] (second buffer), this will return 0 with the output bool set to 0.&lt;br /&gt;
&lt;br /&gt;
When [[#ApplicationDeliveryInfo|ApplicationDeliveryAttributeTag]] (first buffer) bit28 is set (bitmask 0x10000000):&lt;br /&gt;
* When [[#ApplicationDeliveryInfo|ApplicationVersion]] (first buffer) &amp;gt;= [[#ApplicationDeliveryInfo|ApplicationVersion]] (second buffer), write 0 to the output bool, otherwise write 1. Then return 0.&lt;br /&gt;
Otherwise when the above bit28 is clear:&lt;br /&gt;
* When [[#ApplicationDeliveryInfo|ApplicationVersion]] (first buffer) &amp;gt; [[#ApplicationDeliveryInfo|ApplicationVersion]] (second buffer), write 0 to the output bool, otherwise write 1. Then return 0.&lt;br /&gt;
&lt;br /&gt;
==== ListContentMetaKeyToDeliverApplication ====&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of [[NCM_services#ContentMetaKey|ContentMetaKey]], a type-0x5 input buffer containing an array of [[#ApplicationDeliveryInfo]], a s32, and returns an output s32 total_out.&lt;br /&gt;
&lt;br /&gt;
This uses the same LocalContentShare check as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
The array-count for ContentMetaKey must be at least 1, and for ApplicationDeliveryInfo it must match 1.&lt;br /&gt;
&lt;br /&gt;
The [[#ApplicationDeliveryInfo|ApplicationDeliveryInfo]] is validated (ApplicationDeliveryProtocolVersion/HMAC). An error is thrown when [[#ApplicationDeliveryInfo|ApplicationDeliveryAttributeTag]] bit0 is set.&lt;br /&gt;
&lt;br /&gt;
This uses the same ref-count check as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
An error is thrown if [[NIM_services|nim]] ListApplicationApplyDeltaTask returns a task.&lt;br /&gt;
&lt;br /&gt;
This will only return 1 ContentMetaKey entry. This will not output the entry when the input s32 is larger than 0, or when [[#ApplicationDeliveryInfo|ApplicationDeliveryAttributeTag]] bit1 is clear.&lt;br /&gt;
&lt;br /&gt;
==== NeedsSystemUpdateToDeliverApplication ====&lt;br /&gt;
Takes a type-0x15 input buffer containing a [[#SystemDeliveryInfo]], a type-0x5 input buffer containing an array of [[#ApplicationDeliveryInfo]], and returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
This uses the same LocalContentShare check as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
The [[#SystemDeliveryInfo]] is validated (validation for ApplicationDeliveryProtocolVersion is enabled).&lt;br /&gt;
&lt;br /&gt;
The array-count must match 1.&lt;br /&gt;
&lt;br /&gt;
The [[#ApplicationDeliveryInfo]] is validated (ApplicationDeliveryProtocolVersion/HMAC).&lt;br /&gt;
&lt;br /&gt;
This then runs functionality similar to [[#SelectLatestSystemDeliveryInfo]]:&lt;br /&gt;
* [20.0.0+] The following code block now only runs when the SystemDeliveryInfoPlatform from the input [[#SystemDeliveryInfo]] matches the [[System_Settings|sys-setting]].&lt;br /&gt;
* Uses the same functionality as [[#SelectLatestSystemDeliveryInfo]] for GetFunctionBlackListSystemVersionToAuthorize, returning the Result on failure.&lt;br /&gt;
* The output bool is set to: out_u8!=0 &amp;amp;&amp;amp; out_u32 &amp;gt;= [[#SystemDeliveryInfo]] SystemUpdateVersion (only the upper 16bits are used from the SystemUpdateVersion).&lt;br /&gt;
&lt;br /&gt;
Otherwise when the output bool is still false, this sets the output bool by comparing system-version fields in the [[#SystemDeliveryInfo]]/[[#ApplicationDeliveryInfo]] and with a state field (state field originates from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;contents_delivery!required_system_version_to_deliver_application&amp;lt;/code&amp;gt;).&lt;br /&gt;
&lt;br /&gt;
==== EstimateRequiredSize ====&lt;br /&gt;
Takes a type-0x5 input buffer containing an array of [[NCM_services#ContentMetaKey|ContentMetaKey]], returns an output s64.&lt;br /&gt;
&lt;br /&gt;
When the array-count is less than 1, this will return 0 with the s64 set to 0.&lt;br /&gt;
&lt;br /&gt;
==== RequestReceiveApplication ====&lt;br /&gt;
Takes a type-0x5 input buffer containing an array of [[NCM_services#ContentMetaKey|ContentMetaKey]], a [[NCM_services#StorageId|StorageId]], an u16 port, an u32 Ipv4Address, an [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
[[qlaunch]] uses value Any for the StorageId, and value 55556 for the port.&lt;br /&gt;
&lt;br /&gt;
This uses the same LocalContentShare and ref-count checks as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
An error is thrown if [[NIM_services|nim]] ListApplicationApplyDeltaTask returns a task.&lt;br /&gt;
&lt;br /&gt;
HasApplicationRecord is called with the input [[NCM_services#ApplicationId|ApplicationId]], an error is returned if the record isn&#039;t found.&lt;br /&gt;
&lt;br /&gt;
This loops through the input [[NCM_services#ContentMetaKey|ContentMetaKey]] array, throwing an error if the [[NCM_services#ContentMetaType|ContentMetaType]] doesn&#039;t match Patch. The input array is copied into state which is used later by the thread for [[NIM_services|nim]] CreateLocalCommunicationReceiveApplicationTask, max entries is 0x12.&lt;br /&gt;
&lt;br /&gt;
This does various setup then creates the [[#IAsyncResult]] + the async thread which handles the [[#IAsyncResult]] operation. Then the thread does:&lt;br /&gt;
&lt;br /&gt;
* Calls a func which does:&lt;br /&gt;
** Throws an error if a state flag is set.&lt;br /&gt;
** Uses [[NIM_services|nim]] CreateLocalCommunicationReceiveApplicationTask, returning the Result on failure.&lt;br /&gt;
** Uses [[NIM_services|nim]] RequestLocalCommunicationReceiveApplicationTaskRun, returning the Result on failure. Waits for the IAsyncResult operation from this to finish, then uses the Get cmd to get the output Result.&lt;br /&gt;
*** When the Result from Get is an error, a func is called for filling in the [[#IAsyncResult|IAsyncResult]] ErrorContext with Type4.&lt;br /&gt;
** Handles cleanup and returns.&lt;br /&gt;
* On success, this loads various data which is then used for saving a SystemPlayReport when the cached [[System_Settings|system-setting]] &amp;quot;systemreport!enabled&amp;quot; is set.&lt;br /&gt;
** The EventId is &amp;quot;receive_app_contents&amp;quot; with ApplicationId &amp;lt;NS ProgramId&amp;gt;.&lt;br /&gt;
** This report has the following fields:&lt;br /&gt;
*** &amp;quot;ApplicationId&amp;quot;&lt;br /&gt;
*** &amp;quot;DestinationVersion&amp;quot;&lt;br /&gt;
*** &amp;quot;SourceVersion&amp;quot;&lt;br /&gt;
*** &amp;quot;HasApplicationEntity&amp;quot;&lt;br /&gt;
*** &amp;quot;HasPatchEntity&amp;quot;&lt;br /&gt;
*** &amp;quot;ApplicationStorageId&amp;quot;&lt;br /&gt;
*** &amp;quot;PatchStorageId&amp;quot;&lt;br /&gt;
*** &amp;quot;Size&amp;quot;&lt;br /&gt;
*** &amp;quot;ThroughputKBps&amp;quot;&lt;br /&gt;
&lt;br /&gt;
==== CommitReceiveApplication ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
This uses the same LocalContentShare and ref-count checks as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
An error is thrown if [[NIM_services|nim]] ListApplicationApplyDeltaTask returns a task.&lt;br /&gt;
&lt;br /&gt;
==== GetReceiveApplicationProgress ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output [[#ReceiveApplicationProgress]].&lt;br /&gt;
&lt;br /&gt;
This uses the same ref-count check as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
An error is thrown if [[NIM_services|nim]] ListApplicationApplyDeltaTask returns a task.&lt;br /&gt;
&lt;br /&gt;
Uses [[NIM_services|nim]] ListApplicationLocalCommunicationReceiveApplicationTask, throwing an error if no task is returned. Then [[NIM_services|nim]] GetLocalCommunicationReceiveApplicationTaskInfo is used, returning the error from there on failure. Lastly, this writes the 0x10-bytes from output+8 from the latter cmd to the output [[#ReceiveApplicationProgress]], and returns 0.&lt;br /&gt;
&lt;br /&gt;
==== RequestSendApplication ====&lt;br /&gt;
Takes a type-0x5 input buffer containing an array of [[NCM_services#ContentMetaKey|ContentMetaKey]], an u16 port, an u32 Ipv4Address, an [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
[[qlaunch]] uses value 55556 for the port.&lt;br /&gt;
&lt;br /&gt;
This uses the same LocalContentShare and ref-count checks as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
An error is thrown if [[NIM_services|nim]] ListApplicationApplyDeltaTask returns a task.&lt;br /&gt;
&lt;br /&gt;
This does various setup and loops through the input ContentMetaKey array for initializing the array passed to the nim cmd during the async task. This loop does the following:&lt;br /&gt;
* Throws an error if the [[NCM_services#ContentMetaType|ContentMetaType]] in the ContentMetaKey doesn&#039;t match Patch.&lt;br /&gt;
* Calls a func with the ContentMetaKey and the ApplicationId, throwing an error if the output value is 0.&lt;br /&gt;
* Calls a func with the ContentMetaKey for getting the StorageId. This essentially loops through each valid ncm [[NCM_services|IContentMetaDatabase]] using cmd [[NCM_services|Has]] with the input ContentMetaKey, returning the relevant StorageId when found.&lt;br /&gt;
* The ContentMetaKey and the StorageId are copied into a tmp struct.&lt;br /&gt;
* if (ContentMetaType==Patch &amp;amp;&amp;amp; StorageId==GameCard) { &amp;lt;call a func etc&amp;gt; }&lt;br /&gt;
* Copies the above tmp struct into the async task state array.&lt;br /&gt;
&lt;br /&gt;
This then creates the [[#IAsyncResult]] + the async thread which handles the [[#IAsyncResult]] operation. Then the thread does:&lt;br /&gt;
&lt;br /&gt;
* Calls a func which does:&lt;br /&gt;
** Throws an error if a state flag is set.&lt;br /&gt;
** Uses [[NIM_services|nim]] CreateLocalCommunicationSendApplicationTask, returning the Result on failure.&lt;br /&gt;
** Uses [[NIM_services|nim]] RequestLocalCommunicationSendApplicationTaskRun, returning the Result on failure. Waits for the IAsyncResult operation from this to finish, then uses the Get cmd to get the output Result.&lt;br /&gt;
*** When the Result from Get is an error, a func is called for filling in the [[#IAsyncResult|IAsyncResult]] ErrorContext with Type4.&lt;br /&gt;
** Handles cleanup and returns.&lt;br /&gt;
* On success, this loads various data which is then used for saving a SystemPlayReport when the cached [[System_Settings|system-setting]] &amp;quot;systemreport!enabled&amp;quot; is set.&lt;br /&gt;
** The EventId is &amp;quot;send_app_contents&amp;quot; with ApplicationId &amp;lt;NS ProgramId&amp;gt;.&lt;br /&gt;
** This report has the following fields:&lt;br /&gt;
*** &amp;quot;ApplicationId&amp;quot;&lt;br /&gt;
*** &amp;quot;Version&amp;quot;&lt;br /&gt;
*** &amp;quot;ApplicationStorageId&amp;quot;&lt;br /&gt;
*** &amp;quot;PatchStorageId&amp;quot;&lt;br /&gt;
&lt;br /&gt;
==== GetSendApplicationProgress ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output [[#SendApplicationProgress]].&lt;br /&gt;
&lt;br /&gt;
Same as [[#GetReceiveApplicationProgress]] except this is the Send version, and uses [[NIM_services|nim]] ListApplicationLocalCommunicationSendApplicationTask/GetLocalCommunicationSendApplicationTaskInfo instead. The data copied to output is also swapped: u64 nim_out+0x8 is copied to out+0x8, and u64 nim_out+0x10 is copied to out+0x0.&lt;br /&gt;
&lt;br /&gt;
==== CompareSystemDeliveryInfo ====&lt;br /&gt;
Takes two type-0x15 input buffers containing a [[#SystemDeliveryInfo]], returns an output s32.&lt;br /&gt;
&lt;br /&gt;
This is essentially the same as [[#CompareApplicationDeliveryInfo]], except this compares the [[#SystemDeliveryInfo]] SystemUpdate version.&lt;br /&gt;
&lt;br /&gt;
==== ListNotCommittedContentMeta ====&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of [[NCM_services#ContentMetaKey|ContentMetaKey]], a s32, an [[NCM_services#ApplicationId|ApplicationId]], returns an output s32 total_out.&lt;br /&gt;
&lt;br /&gt;
This uses the same ref-count check as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
An error is thrown if [[NIM_services|nim]] ListApplicationApplyDeltaTask returns a task.&lt;br /&gt;
&lt;br /&gt;
==== RecoverDownloadTask ====&lt;br /&gt;
Takes a type-0x5 input buffer containing an array of {unknown} and an input u64, no output.&lt;br /&gt;
&lt;br /&gt;
This uses the same LocalContentShare and ref-count checks as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationDeliveryInfoHash ====&lt;br /&gt;
Takes a type-0x5 input buffer containing an array of [[#ApplicationDeliveryInfo]], returns an output 0x20-byte SHA256 hash.&lt;br /&gt;
&lt;br /&gt;
This uses the same LocalContentShare check as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
This extracts data from the input array for hashing with SHA256, with validation being done when handling each entry (ApplicationDeliveryProtocolVersion/HMAC).&lt;br /&gt;
&lt;br /&gt;
The 0x14-bytes from [[#ApplicationDeliveryInfo|ApplicationDeliveryInfo]]+0x8 are copied into a 0x18-byte struct entry in an array buffer, with the last 4-bytes being cleared. Then each 0x18-byte struct entry is hashed.&lt;br /&gt;
&lt;br /&gt;
==== Cmd2019 ====&lt;br /&gt;
Takes a type-0x15 input buffer containing a [[#SystemDeliveryInfo]], a type-0x5 input buffer containing an array of [[#ApplicationDeliveryInfo]], a type-0x5 input buffer containing an array of [[#ApplicationDeliveryInfo]], returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
This is essentially an extended version of [[#CanDeliverApplication|CanDeliverApplication]], with additional functionality for determining platform compatibility.&lt;br /&gt;
&lt;br /&gt;
This calls a func for validating the [[#SystemDeliveryInfo]] from the type-0x15 buffer, returning the Result on failure.&lt;br /&gt;
&lt;br /&gt;
Then [[#CanDeliverApplication|CanDeliverApplication]] is called with the output bool and the input arrays, returning the Result on failure.&lt;br /&gt;
&lt;br /&gt;
If the output bool is set after calling the above, it then calls a func with the output bool, the second [[#ApplicationDeliveryInfo]] buffer, and the [[#SystemDeliveryInfo]] from the type-0x15 buffer. This func does the following:&lt;br /&gt;
* When the SystemDeliveryInfoPlatform from the input [[#SystemDeliveryInfo]] matches the [[System_Settings|sys-setting]], it does the following:&lt;br /&gt;
** Uses [[Shared_Database_services|pl:s]] RequestApplicationFunctionAuthorizationByApplicationId with the [[#ApplicationDeliveryInfo]] ApplicationId/ApplicationVersion and ApplicationFunctionAuthorizationId=0x5, handling the Result on failure.&lt;br /&gt;
* When the platform fields from the input [[#SystemDeliveryInfo]]/[[#ApplicationDeliveryInfo]] match, write 1 to the output bool and return 0. Otherwise:&lt;br /&gt;
** When the [[#SystemDeliveryInfo]] SystemDeliveryInfoPlatform is 0x1 (Ounce): *output = [[#ApplicationDeliveryInfo|ContentMetaPlatform]] == 0 &amp;amp;&amp;amp; [[#ApplicationDeliveryInfo|ProperProgramExists]] == 0;&lt;br /&gt;
** When the [[#SystemDeliveryInfo]] SystemDeliveryInfoPlatform is 0x0 (NX): write 0 to the output bool and return 0.&lt;br /&gt;
** Otherwise, Abort.&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationRightsOnClient ====&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of [[#ApplicationRightsOnClient]], an input u32 flags, an [[NCM_services#ApplicationId|ApplicationId]], an [[Account_services#Uid|Uid]], returns 4-bytes of output for total output entries.&lt;br /&gt;
&lt;br /&gt;
Official sw has at least two wrappers which use this cmd: one with an all-zero Uid, one with an user-specified Uid. With both of these, the passed flags are hard-coded to value 0x3.&lt;br /&gt;
&lt;br /&gt;
For the output array count, [[qlaunch]] uses value 3.&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationTerminateResult ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output u32 Result.&lt;br /&gt;
&lt;br /&gt;
==== GetRightsEnvironmentHandleForApplication ====&lt;br /&gt;
No input, returns a total of 8-bytes of output.&lt;br /&gt;
&lt;br /&gt;
[9.0.0+] Now takes a total of 8-bytes of input, returns a total of 8-bytes of output.&lt;br /&gt;
&lt;br /&gt;
==== RequestNoDownloadRightsErrorResolution ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
The data that can be read from the [[#IAsyncValue]] is [[#NoDownloadRightsErrorResolution]].&lt;br /&gt;
&lt;br /&gt;
See [[#RequestApplicationUpdateInfo]] regarding nifm.&lt;br /&gt;
&lt;br /&gt;
==== RequestResolveNoDownloadRightsError ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
The data that can be read from the [[#IAsyncValue]] is [[#NoDownloadRightsErrorResolution]].&lt;br /&gt;
&lt;br /&gt;
See [[#RequestApplicationUpdateInfo]] regarding nifm.&lt;br /&gt;
&lt;br /&gt;
==== GetPromotionInfo ====&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of [[#PromotionInfo]], a type-0x5 input buffer containing an array of u64 [[NCM_services#ApplicationId|ApplicationIds]], a type-0x5 input buffer containing an array of [[Account_services#Uid|Uids]], no output.&lt;br /&gt;
&lt;br /&gt;
Official sw uses hard-coded value 1 for the count with each of these arrays.&lt;br /&gt;
&lt;br /&gt;
==== ListPromotionInfo ====&lt;br /&gt;
[20.0.0+] The struct size for the output buffer array is now 0x28-bytes instead of 0x20-bytes.&lt;br /&gt;
&lt;br /&gt;
==== ImportPromotionJsonForDebug ====&lt;br /&gt;
Takes a type-0x5 input buffer, no output.&lt;br /&gt;
&lt;br /&gt;
The output from [[Settings_services#GetDebugModeFlag]] must be 1, otherwise an error is returned.&lt;br /&gt;
&lt;br /&gt;
==== ClearPromotionInfoForDebug ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
The output from [[Settings_services#GetDebugModeFlag]] must be 1, otherwise an error is returned.&lt;br /&gt;
&lt;br /&gt;
This just clears 0xC-bytes in state.&lt;br /&gt;
&lt;br /&gt;
==== CreateApplicationResource ====&lt;br /&gt;
Takes an input [[#ApplicationResourceType]]. Returns an [[#IApplicationResource]].&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationResource ====&lt;br /&gt;
Takes an input u64 ProcessId and an input [[#ApplicationResourceType]]. Returns an [[#IApplicationResource]].&lt;br /&gt;
&lt;br /&gt;
==== LaunchMicroApplication ====&lt;br /&gt;
[18.0.0+] Now takes a total of 0x50 bytes of input.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] Now takes a total of 0x80 bytes of input.&lt;br /&gt;
&lt;br /&gt;
==== CreateApplicationInstance ====&lt;br /&gt;
[18.0.0+] Now takes a total of 0x50 bytes of input.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] Now takes a total of 0x80 bytes of input.&lt;br /&gt;
&lt;br /&gt;
==== RegisterDeviceLockKey ====&lt;br /&gt;
Takes a type-0x5 input buffer containing an InArray of u8, no output.&lt;br /&gt;
&lt;br /&gt;
User-processes expose this with two funcs: one which uses an user-specified u8 array directly, while the other uses [[HID_services#NpadButtonSet|NpadButton]].&lt;br /&gt;
&lt;br /&gt;
This does SHA256 hashing, etc.&lt;br /&gt;
&lt;br /&gt;
==== UnregisterDeviceLockKey ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Runs code identical to [[#RegisterDeviceLockKey]], except the passed buffer/size are 0.&lt;br /&gt;
&lt;br /&gt;
==== VerifyDeviceLockKey ====&lt;br /&gt;
Takes a type-0x5 input buffer containing an InArray of u8, no output.&lt;br /&gt;
&lt;br /&gt;
User-processes expose this with two funcs: one which uses an user-specified u8 array directly, while the other uses [[HID_services#NpadButtonSet|NpadButton]].&lt;br /&gt;
&lt;br /&gt;
This runs hashing similar to [[#RegisterDeviceLockKey]], with the calculated hash being verified with the one from state.&lt;br /&gt;
&lt;br /&gt;
==== HideApplicationIcon ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== ShowApplicationIcon ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== HideApplicationTitle ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== ShowApplicationTitle ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== EnableGameCard ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== DisableGameCard ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== EnableLocalContentShare ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== DisableLocalContentShare ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== IsApplicationIconHidden ====&lt;br /&gt;
No input, returns an output bool.&lt;br /&gt;
&lt;br /&gt;
==== IsApplicationTitleHidden ====&lt;br /&gt;
No input, returns an output bool.&lt;br /&gt;
&lt;br /&gt;
==== IsGameCardEnabled ====&lt;br /&gt;
No input, returns an output bool.&lt;br /&gt;
&lt;br /&gt;
==== IsLocalContentShareEnabled ====&lt;br /&gt;
No input, returns an output bool.&lt;br /&gt;
&lt;br /&gt;
Various Deliver cmds now run essentially the same code as IsLocalContentShareEnabled, with an error being returned when it&#039;s not enabled.&lt;br /&gt;
&lt;br /&gt;
==== GetSafeSystemVersionCheckInfoOld ====&lt;br /&gt;
Unofficial name.&lt;br /&gt;
&lt;br /&gt;
No input, returns 0x10-bytes of output.&lt;br /&gt;
&lt;br /&gt;
[22.0.0+] Wraps [[#GetSafeSystemVersionCheckInfo|GetSafeSystemVersionCheckInfo]].&lt;br /&gt;
&lt;br /&gt;
==== Cmd4026 ====&lt;br /&gt;
Takes an input u64, returns an [[#IHostSession|IHostSession]].&lt;br /&gt;
&lt;br /&gt;
The input u64 must match a state field.&lt;br /&gt;
&lt;br /&gt;
This initializes [[LDN_services|ldn]] etc, and creates a network.&lt;br /&gt;
&lt;br /&gt;
==== Cmd4027 ====&lt;br /&gt;
Takes an input u64, returns an [[#IClientSession|IClientSession]].&lt;br /&gt;
&lt;br /&gt;
The input u64 must match a state field.&lt;br /&gt;
&lt;br /&gt;
This initializes [[LDN_services|ldn]] etc.&lt;br /&gt;
&lt;br /&gt;
=== IGameCardStopper ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IGameCardStopper&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This interface has no commands.&lt;br /&gt;
&lt;br /&gt;
=== IRequestServerStopper ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IRequestServerStopper&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This interface has no commands.&lt;br /&gt;
&lt;br /&gt;
=== IProgressMonitorForDeleteUserSaveDataAll ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IProgressMonitorForDeleteUserSaveDataAll&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetSystemEvent&lt;br /&gt;
|-&lt;br /&gt;
| 1 || IsFinished&lt;br /&gt;
|-&lt;br /&gt;
| 2 || GetResult&lt;br /&gt;
|-&lt;br /&gt;
| 10 || GetProgress&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
When closing the object, official sw uses IsFinished first, asserting when the output bool is false.&lt;br /&gt;
&lt;br /&gt;
* GetSystemEvent: No input, returns an output Event handle. [[qlaunch]] doesn&#039;t use this.&lt;br /&gt;
&lt;br /&gt;
* IsFinished: No input, returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
* GetResult: No input/output.&lt;br /&gt;
&lt;br /&gt;
* GetProgress: No input, returns an output [[#ProgressForDeleteUserSaveDataAll]]. Official sw writes this struct directly to object state.&lt;br /&gt;
&lt;br /&gt;
=== IProgressAsyncResult ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IProgressAsyncResult&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || Get&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Cancel&lt;br /&gt;
|-&lt;br /&gt;
| 2 || GetProgress&lt;br /&gt;
|-&lt;br /&gt;
| 3 || GetDetailResult&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [4.0.0+] GetErrorContext&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IHostSession ===&lt;br /&gt;
This is &amp;quot;nn::ns::vphym::detail::IHostSession&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [20.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || &lt;br /&gt;
|-&lt;br /&gt;
| 1 || &lt;br /&gt;
|-&lt;br /&gt;
| 2 || &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Cmd0 ====&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
The async task does the following:&lt;br /&gt;
* This waits for a client to connect.&lt;br /&gt;
* The [[LDN_services|NodeInfo]] UserName is converted into two u64s, which are used to locate a state entry with matching values.&lt;br /&gt;
* The client [[LDN_services|NodeInfo]] Ipv4Address is copied into state.&lt;br /&gt;
* Then a ptr to the above located state entry is also written into state.&lt;br /&gt;
&lt;br /&gt;
==== Cmd1 ====&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
The async task uses [[NIM_services|nim]] cmd2018 or cmd2027, depending on a state field. Once finished when a state flag is set, [[LDN_services|ldn]] is finalized and that state flag is cleared.&lt;br /&gt;
&lt;br /&gt;
==== Cmd2 ====&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
The async task uses [[NIM_sevices|nim]] cmd2024.&lt;br /&gt;
&lt;br /&gt;
=== IClientSession ===&lt;br /&gt;
This is &amp;quot;nn::ns::vphym::detail::IClientSession&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [20.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || &lt;br /&gt;
|-&lt;br /&gt;
| 1 || &lt;br /&gt;
|-&lt;br /&gt;
| 2 || &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Cmd0 ====&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
The async task does the following:&lt;br /&gt;
* Uses [[LDN_services|ldn]] Scan.&lt;br /&gt;
* After a [[LDN_services|NodeInfo]] is found with a matching UserName, the Ipv4Address for it is copied into state.&lt;br /&gt;
* If a timeout didn&#039;t occur and a valid NodeInfo was found, it proceeds with connecting to the network.&lt;br /&gt;
&lt;br /&gt;
==== Cmd1 ====&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
The async task uses [[NIM_services|nim]] cmd2019 or cmd2028, depending on a state field. Once finished when a state flag is set, [[LDN_services|ldn]] is finalized and that state flag is cleared.&lt;br /&gt;
&lt;br /&gt;
==== Cmd2 ====&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
This is identical to [[#IHostSession|IHostSession]] Cmd2.&lt;br /&gt;
&lt;br /&gt;
=== IApplicationVersionInterface ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IApplicationVersionInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [4.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetLaunchRequiredVersion&lt;br /&gt;
|-&lt;br /&gt;
| 1 || UpgradeLaunchRequiredVersion&lt;br /&gt;
|-&lt;br /&gt;
| 35 || UpdateVersionList&lt;br /&gt;
|-&lt;br /&gt;
| 36 || PushLaunchVersion&lt;br /&gt;
|-&lt;br /&gt;
| 37 || ListRequiredVersion&lt;br /&gt;
|-&lt;br /&gt;
| 38 || [22.0.0+] &lt;br /&gt;
|-&lt;br /&gt;
| 800 || RequestVersionList&lt;br /&gt;
|-&lt;br /&gt;
| 801 || ListVersionList&lt;br /&gt;
|-&lt;br /&gt;
| 802 || [[#RequestVersionListData]]&lt;br /&gt;
|-&lt;br /&gt;
| 900 || [12.0.0+] ImportAutoUpdatePolicyJsonForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 901 || [12.0.0+] ListDefaultAutoUpdatePolicy&lt;br /&gt;
|-&lt;br /&gt;
| 902 || [12.0.0+] ListAutoUpdatePolicyForSpecificApplication&lt;br /&gt;
|-&lt;br /&gt;
| 1000 || PerformAutoUpdate&lt;br /&gt;
|-&lt;br /&gt;
| 1001 || [11.0.0+] ListAutoUpdateSchedule&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== RequestVersionListData ====&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
The data that can be read from the [[#IAsyncValue]] is [[#VersionListData]].&lt;br /&gt;
&lt;br /&gt;
=== IContentManagementInterface ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IContentManagementInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [[#CalculateApplicationOccupiedSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 43 || [[#CheckSdCardMountStatus]]&lt;br /&gt;
|-&lt;br /&gt;
| 47 || [[#GetTotalSpaceSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 48 || [[#GetFreeSpaceSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 58 || [20.1.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 71 || [20.1.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 600 || [[#CountApplicationContentMeta]]&lt;br /&gt;
|-&lt;br /&gt;
| 601 || [[#ListApplicationContentMetaStatus]]&lt;br /&gt;
|-&lt;br /&gt;
| 605 || [[#ListApplicationContentMetaStatusWithRightsCheck]]&lt;br /&gt;
|-&lt;br /&gt;
| 607 || [[#IsAnyApplicationRunning]]&lt;br /&gt;
|-&lt;br /&gt;
| 608 || [21.0.0+]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== CalculateApplicationOccupiedSize ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output [[#ApplicationOccupiedSize]].&lt;br /&gt;
&lt;br /&gt;
==== CheckSdCardMountStatus ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== CountApplicationContentMeta ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output s32.&lt;br /&gt;
&lt;br /&gt;
==== ListApplicationContentMetaStatusWithRightsCheck ====&lt;br /&gt;
Same input/output as [[#ListApplicationContentMetaStatus]].&lt;br /&gt;
&lt;br /&gt;
==== IsAnyApplicationRunning ====&lt;br /&gt;
No input, returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
=== IDocumentInterface ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IDocumentInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 21 || GetApplicationContentPath&lt;br /&gt;
|-&lt;br /&gt;
| 23 || ResolveApplicationContentPath&lt;br /&gt;
|-&lt;br /&gt;
| 92 || [5.0.0+] GetRunningApplicationProgramId&lt;br /&gt;
|-&lt;br /&gt;
| 100 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 101 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 2524 || [19.0.0+] &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Cmd100 ====&lt;br /&gt;
Takes a type-0x16 output buffer containing a 0x300-byte struct, an input u8, an u64. Returns two output u8s.&lt;br /&gt;
&lt;br /&gt;
==== Cmd101 ====&lt;br /&gt;
Takes a type-0x16 output buffer containing a 0x300-byte struct, an input u8, an u64. Returns an output u8, an u8 [[Filesystem_services|ContentAttributes]], and a [[NCM_services#ProgramId|ProgramId]].&lt;br /&gt;
&lt;br /&gt;
This is similar to Cmd2524. On [S2] this is used instead of Cmd2524.&lt;br /&gt;
&lt;br /&gt;
==== Cmd2524 ====&lt;br /&gt;
Takes a type-0x16 output buffer containing a 0x300-byte struct, an input u8, an u64. Returns an output u8 [[Filesystem_services|ContentAttributes]] and a [[NCM_services#ProgramId|ProgramId]].&lt;br /&gt;
&lt;br /&gt;
The user-process uses the output from this as the input for [[Filesystem_services|OpenFileSystemWithId]] (out-buffer is used as the [[Filesystem_services|FspPath]]).&lt;br /&gt;
&lt;br /&gt;
=== IDownloadTaskInterface ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IDownloadTaskInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 701 || [[#ClearTaskStatusList]]&lt;br /&gt;
|-&lt;br /&gt;
| 702 || [[#RequestDownloadTaskList]]&lt;br /&gt;
|-&lt;br /&gt;
| 703 || [[#RequestEnsureDownloadTask]]&lt;br /&gt;
|-&lt;br /&gt;
| 704 || [[#ListDownloadTaskStatus]]&lt;br /&gt;
|-&lt;br /&gt;
| 705 || [[#RequestDownloadTaskListData]]&lt;br /&gt;
|-&lt;br /&gt;
| 706 || [4.0.0+] [[#TryCommitCurrentApplicationDownloadTask]]&lt;br /&gt;
|-&lt;br /&gt;
| 707 || [4.0.0+] [[#EnableAutoCommit]]&lt;br /&gt;
|-&lt;br /&gt;
| 708 || [4.0.0+] [[#DisableAutoCommit]]&lt;br /&gt;
|-&lt;br /&gt;
| 709 || [4.0.0+] [[#TriggerDynamicCommitEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 710 || [20.0.0+]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== ClearTaskStatusList ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== RequestDownloadTaskList ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== RequestEnsureDownloadTask ====&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
==== ListDownloadTaskStatus ====&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of [[#DownloadTaskStatus]], returns an output s32 total_out.&lt;br /&gt;
&lt;br /&gt;
A maximum of 0x100 tasks can be stored in state.&lt;br /&gt;
&lt;br /&gt;
==== TryCommitCurrentApplicationDownloadTask ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== EnableAutoCommit ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== DisableAutoCommit ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== TriggerDynamicCommitEvent ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
=== IReadOnlyApplicationRecordInterface ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IReadOnlyApplicationRecordInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [5.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || HasApplicationRecord || Same as [[#IApplicationManagerInterface]] cmd 910&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [10.0.0+] NotifyApplicationFailure ||&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [10.0.0+] IsDataCorruptedResult ||&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [20.0.0+] [[#ListApplicationRecord|ListApplicationRecord]] ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IReadOnlyApplicationControlDataInterface ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IReadOnlyApplicationControlDataInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [5.1.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#GetApplicationControlData]] || Same as [[#IApplicationManagerInterface]] cmd 400&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#GetApplicationDesiredLanguage]] || Same as [[#IApplicationManagerInterface]] cmd 55&lt;br /&gt;
|-&lt;br /&gt;
| 2 || ConvertApplicationLanguageToLanguageCode || Same as [[#IApplicationManagerInterface]] cmd 59&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [[#ConvertLanguageCodeToApplicationLanguage]] || Same as [[#IApplicationManagerInterface]] cmd 60&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [9.0.0+] SelectApplicationDesiredLanguage ||&lt;br /&gt;
|-&lt;br /&gt;
| 5 || [19.0.0+] || Same as [[#IApplicationManagerInterface]] cmd 411&lt;br /&gt;
|-&lt;br /&gt;
| 6 || [19.0.0+] || Same as [[#IApplicationManagerInterface]] cmd 416&lt;br /&gt;
|-&lt;br /&gt;
| 7 || [20.0.0+] || Same as [[#IApplicationManagerInterface]] cmd 921&lt;br /&gt;
|-&lt;br /&gt;
| 8 || [20.0.0+] || Same as [[#IApplicationManagerInterface]] cmd 922&lt;br /&gt;
|-&lt;br /&gt;
| 9 || [20.0.0+] || Same as [[#IApplicationManagerInterface]] cmd 923&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [20.0.0+] || Same as [[#IApplicationManagerInterface]] cmd 421&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [20.0.0+] || Same as [[#IApplicationManagerInterface]] cmd 422&lt;br /&gt;
|-&lt;br /&gt;
| 12 || [20.0.0+] || Same as [[#IApplicationManagerInterface]] cmd 423&lt;br /&gt;
|-&lt;br /&gt;
| 13 || [20.0.0+] || Same as [[#IApplicationManagerInterface]] cmd 407&lt;br /&gt;
|-&lt;br /&gt;
| 14 || [20.0.0+] || Same as [[#IApplicationManagerInterface]] cmd 408&lt;br /&gt;
|-&lt;br /&gt;
| 15 || [20.0.0+] || Same as [[#IApplicationManagerInterface]] cmd 415&lt;br /&gt;
|-&lt;br /&gt;
| 16 || [20.0.0+] ||&lt;br /&gt;
|-&lt;br /&gt;
| 17 || [20.1.0+] || Same as [[#IApplicationManagerInterface]] cmd 933&lt;br /&gt;
|-&lt;br /&gt;
| 18 || [21.0.0+] ||&lt;br /&gt;
|-&lt;br /&gt;
| 19 || [21.0.0+] ||&lt;br /&gt;
|-&lt;br /&gt;
| 20 || [21.0.0+] ||&lt;br /&gt;
|-&lt;br /&gt;
| 21 || [21.0.0+] ||&lt;br /&gt;
|-&lt;br /&gt;
| 22 || [21.0.0+] ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IDynamicRightsInterface ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IDynamicRightsInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [6.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#RequestApplicationRightsOnServer]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#RequestAssignRights]]&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [[#DeprecatedRequestAssignRightsToResume]]&lt;br /&gt;
|-&lt;br /&gt;
| 5 || [[#VerifyActivatedRightsOwners]]&lt;br /&gt;
|-&lt;br /&gt;
| 6 || [[#DeprecatedGetApplicationRightsStatus]]&lt;br /&gt;
|-&lt;br /&gt;
| 7 || [[#RequestPrefetchForDynamicRights]]&lt;br /&gt;
|-&lt;br /&gt;
| 8 || [[#GetDynamicRightsState]]&lt;br /&gt;
|-&lt;br /&gt;
| 9 || [7.0.0+] [[#RequestApplicationRightsOnServerToResume]]&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [7.0.0+] [[#RequestAssignRightsToResume]]&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [7.0.0+] [[#GetActivatedRightsUsers]]&lt;br /&gt;
|-&lt;br /&gt;
| 12 || [8.0.0+] [[#GetApplicationRightsStatus]]&lt;br /&gt;
|-&lt;br /&gt;
| 13 || [8.0.0+] [[#GetRunningApplicationStatus]]&lt;br /&gt;
|-&lt;br /&gt;
| 14 || [10.0.0-15.0.1] SelectApplicationLicense&lt;br /&gt;
|-&lt;br /&gt;
| 15 || [12.0.0+] [[#RequestContentsAuthorizationToken]]&lt;br /&gt;
|-&lt;br /&gt;
| 16 || [13.0.0+] QualifyUser&lt;br /&gt;
|-&lt;br /&gt;
| 17 || [13.0.0+] QualifyUserWithProcessId&lt;br /&gt;
|-&lt;br /&gt;
| 18 || [13.0.0+] NotifyApplicationRightsCheckStart&lt;br /&gt;
|-&lt;br /&gt;
| 19 || [13.0.0+] UpdateUserList&lt;br /&gt;
|-&lt;br /&gt;
| 20 || [13.0.0+] IsRightsLostUser&lt;br /&gt;
|-&lt;br /&gt;
| 21 || [13.1.0+] SetRequiredAddOnContentsOnContentsAvailabilityTransition&lt;br /&gt;
|-&lt;br /&gt;
| 22 || [14.0.0+] GetLimitedApplicationLicense&lt;br /&gt;
|-&lt;br /&gt;
| 23 || [14.0.0+] GetLimitedApplicationLicenseUpgradableEvent&lt;br /&gt;
|-&lt;br /&gt;
| 24 || [14.0.0+] NotifyLimitedApplicationLicenseUpgradableEventForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 25 || [14.0.0+] RequestProceedDynamicRightsState&lt;br /&gt;
|-&lt;br /&gt;
| 26 || [18.0.0+] HasAccountRestrictedRightsInRunningApplications&lt;br /&gt;
|-&lt;br /&gt;
| 27 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 28 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 29 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 30 || [21.0.0+]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== RequestApplicationRightsOnServer ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], an [[Account_services#Uid|Uid]] and an u32. Returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
==== RequestAssignRights ====&lt;br /&gt;
Takes a type-0x5 input buffer containing an array of &amp;quot;nn::ns::ApplicationRightsOnServer&amp;quot;. Returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
==== DeprecatedRequestAssignRightsToResume ====&lt;br /&gt;
Takes an input u64 &amp;quot;nn::ns::RightsEnvironmentHandle&amp;quot; and an [[Account_services#Uid|Uid]]. Returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
==== VerifyActivatedRightsOwners ====&lt;br /&gt;
Takes an input u64 &amp;quot;nn::ns::RightsEnvironmentHandle&amp;quot;. No output.&lt;br /&gt;
&lt;br /&gt;
==== DeprecatedGetApplicationRightsStatus ====&lt;br /&gt;
Takes an input u64 &amp;quot;nn::ns::RightsEnvironmentHandle&amp;quot;. Returns a bool &amp;quot;nn::ns::ApplicationRightsStatus&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==== RequestPrefetchForDynamicRights ====&lt;br /&gt;
Takes an input [[Account_services#Uid|Uid]]. Returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
==== GetDynamicRightsState ====&lt;br /&gt;
No input. Returns a bool &amp;quot;nn::ns::DynamicRightsState&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==== RequestApplicationRightsOnServerToResume ====&lt;br /&gt;
Takes an input u64 &amp;quot;nn::ns::RightsEnvironmentHandle&amp;quot;. Returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
==== RequestAssignRightsToResume ====&lt;br /&gt;
Takes an input u64 &amp;quot;nn::ns::RightsEnvironmentHandle&amp;quot;. Returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
==== GetActivatedRightsUsers ====&lt;br /&gt;
Takes an input u64 &amp;quot;nn::ns::RightsEnvironmentHandle&amp;quot;. Returns a bool, an u32 and a type-0x6 output buffer containing an array of [[Account_services#Uid|Uid]].&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationRightsStatus ====&lt;br /&gt;
Takes an input &amp;quot;nn::ns::RightsEnvironmentHandle&amp;quot;. Returns 2 bools &amp;quot;nn::ns::ApplicationRightsStatus&amp;quot; and &amp;quot;nn::ns::ApplicationLicenseType&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==== GetRunningApplicationStatus ====&lt;br /&gt;
Takes an input u64 &amp;quot;nn::ns::RightsEnvironmentHandle&amp;quot;. Returns an u32 &amp;quot;nn::ns::RunningApplicationStatus&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==== RequestContentsAuthorizationToken ====&lt;br /&gt;
Takes a total of 0x50-bytes of input, a type-0x5 input buffer. Returns an [[#IAsyncData_2|IAsyncData]] and an output handle.&lt;br /&gt;
&lt;br /&gt;
==== IAsyncData ====&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IAsyncData&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [12.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetSize&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Get&lt;br /&gt;
|-&lt;br /&gt;
| 2 || Cancel&lt;br /&gt;
|-&lt;br /&gt;
| 3 || GetErrorContext&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IECommerceInterface===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IECommerceInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [4.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#RequestLinkDevice]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [6.0.0+] [[#RequestCleanupAllPreInstalledApplications]]&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [6.0.0+] [[#RequestCleanupPreInstalledApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [6.0.0+] [[#RequestSyncRights]]&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [6.0.0+] [[#RequestUnlinkDevice]]&lt;br /&gt;
|-&lt;br /&gt;
| 5 || [6.1.0+] [[#RequestRevokeAllELicense]]&lt;br /&gt;
|-&lt;br /&gt;
| 6 || [9.0.0+] [[#RequestSyncRightsBasedOnAssignedELicenses]]&lt;br /&gt;
|-&lt;br /&gt;
| 7 || [14.0.0+] RequestOnlineSubscriptionFreeTrialAvailability&lt;br /&gt;
|-&lt;br /&gt;
| 8 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 9 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 12 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 13 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 14 || [21.0.0+]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== RequestLinkDevice ====&lt;br /&gt;
Takes an input [[Account_services#Uid|Uid]], returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
See [[#RequestApplicationUpdateInfo]] regarding nifm.&lt;br /&gt;
&lt;br /&gt;
==== RequestCleanupAllPreInstalledApplications ====&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
==== RequestCleanupPreInstalledApplication ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
==== RequestSyncRights ====&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
==== RequestUnlinkDevice ====&lt;br /&gt;
Takes an input [[Account_services#Uid|Uid]], returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
See [[#RequestApplicationUpdateInfo]] regarding nifm.&lt;br /&gt;
&lt;br /&gt;
==== RequestRevokeAllELicense ====&lt;br /&gt;
Takes an input [[Account_services#Uid|Uid]], returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
==== RequestSyncRightsBasedOnAssignedELicenses ====&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
=== IFactoryResetInterface ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IFactoryResetInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 100 || [[#ResetToFactorySettings]]&lt;br /&gt;
|-&lt;br /&gt;
| 101 || [[#ResetToFactorySettingsWithoutUserSaveData]]&lt;br /&gt;
|-&lt;br /&gt;
| 102 || [[#ResetToFactorySettingsForRefurbishment]]&lt;br /&gt;
|-&lt;br /&gt;
| 103 || [9.1.0+] [[#ResetToFactorySettingsWithPlatformRegion]]&lt;br /&gt;
|-&lt;br /&gt;
| 104 || [9.1.0+] [[#ResetToFactorySettingsWithPlatformRegionAuthentication]]&lt;br /&gt;
|-&lt;br /&gt;
| 105 || [10.0.0+] [[#RequestResetToFactorySettingsSecurely]]&lt;br /&gt;
|-&lt;br /&gt;
| 106 || [10.0.0+] [[#RequestResetToFactorySettingsWithPlatformRegionAuthenticationSecurely]]&lt;br /&gt;
|-&lt;br /&gt;
| 107 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 108 || [20.0.0+]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== ResetToFactorySettings ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
As of [9.1.0] this is the only [[#IFactoryResetInterface]] cmd used by [[qlaunch]].&lt;br /&gt;
&lt;br /&gt;
==== ResetToFactorySettingsWithoutUserSaveData ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== ResetToFactorySettingsForRefurbishment ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== ResetToFactorySettingsWithPlatformRegion ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== ResetToFactorySettingsWithPlatformRegionAuthentication ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== RequestResetToFactorySettingsSecurely ====&lt;br /&gt;
Takes an input u64 tmem_size, a TransferMemory handle, returns an output [[#IAsyncValueAndProgress]] and an Event handle.&lt;br /&gt;
&lt;br /&gt;
The TransferMemory uses permissions=0.&lt;br /&gt;
&lt;br /&gt;
==== RequestResetToFactorySettingsWithPlatformRegionAuthenticationSecurely ====&lt;br /&gt;
Takes an input u32 &amp;quot;nn::ae::PlatformRegion&amp;quot;, an u64 tmem_size, a TransferMemory handle, returns an output [[#IAsyncValueAndProgress]] and an Event handle.&lt;br /&gt;
&lt;br /&gt;
The TransferMemory uses permissions=0.&lt;br /&gt;
&lt;br /&gt;
===== IAsyncValueAndProgress =====&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IAsyncValueAndProgress&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [10.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetSize&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Get&lt;br /&gt;
|-&lt;br /&gt;
| 2 || Cancel&lt;br /&gt;
|-&lt;br /&gt;
| 3 || GetErrorContext&lt;br /&gt;
|-&lt;br /&gt;
| 4 || GetProgress&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IApplicationResource ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IApplicationResource&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [9.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || Attach&lt;br /&gt;
|-&lt;br /&gt;
| 1 || BoostSystemMemoryResourceLimit&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ns:vm =&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IVulnerabilityManagerInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 1200 || [3.0.0+] [[#NeedsUpdateVulnerability]]&lt;br /&gt;
|-&lt;br /&gt;
| 1201 || [4.0.0+] [[#UpdateSafeSystemVersionForDebug]]&lt;br /&gt;
|-&lt;br /&gt;
| 1202 || [4.0.0+] [[#GetSafeSystemVersion]]&lt;br /&gt;
|-&lt;br /&gt;
| 3100 || [18.0.0+] [[#GetSafeSystemVersionCheckInfo|GetSafeSystemVersionCheckInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 3101 || [18.0.0+] [[#RequestUpdateSafeSystemVersionCheckInfo|RequestUpdateSafeSystemVersionCheckInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 3102 || [18.0.0+] [[#ResetSafeSystemVersionCheckInfo|ResetSafeSystemVersionCheckInfo]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== NeedsUpdateVulnerability ==&lt;br /&gt;
No input, returns an output u8 bool flag.&lt;br /&gt;
&lt;br /&gt;
[S1] Web-applets use this command to check if the system needs an update.&lt;br /&gt;
&lt;br /&gt;
== UpdateSafeSystemVersionForDebug ==&lt;br /&gt;
Takes an input u32 &#039;&#039;&#039;version&#039;&#039;&#039; and an [[NCM_services#ApplicationId|ApplicationId]].&lt;br /&gt;
&lt;br /&gt;
This command is not available for retail units. On a debug unit, if the [[System_Settings|system setting]] &amp;lt;code&amp;gt;vulnerability!enable_debug&amp;lt;/code&amp;gt; is set, this mounts the system savegame [[Flash_Filesystem#System_Savegames|0x8000000000000049]] as &amp;quot;ns_ssversion:/&amp;quot;, opens the file &amp;quot;ns_ssversion:/entry&amp;quot; and writes the supplied [[NCM_services#ApplicationId|ApplicationId]] and &#039;&#039;&#039;version&#039;&#039;&#039; in it.&lt;br /&gt;
&lt;br /&gt;
Finally, it calls [[NCM_services#ncm|OpenContentMetaDatabase]] with [[NCM_services#StorageId|StorageId]] 3, then calls [[NCM_services#IContentMetaDatabase|GetLatestContentMetaKey]] with the supplied [[NCM_services#ApplicationId|ApplicationId]] and compares the version field from the returned [[CNMT#Content_Meta_Records|Content Meta Record]] with the supplied &#039;&#039;&#039;version&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
If the supplied &#039;&#039;&#039;version&#039;&#039;&#039; is higher than the one in NCM&#039;s database, the value returned by [[NS_Services#NeedsUpdateVulnerability|NeedsUpdateVulnerability]] is set to &amp;quot;true&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== GetSafeSystemVersion ==&lt;br /&gt;
No input, returns an output [[NCM_services#ContentMetaKey|ContentMetaKey]] with the cached contents of &amp;quot;ns_ssversion:/entry&amp;quot; ([[NCM_services#ApplicationId|ApplicationId]], u32 &#039;&#039;&#039;version&#039;&#039;&#039; and u32 &#039;&#039;&#039;policy&#039;&#039;&#039; from &amp;lt;code&amp;gt;vulnerability!needs_update_vulnerability_policy&amp;lt;/code&amp;gt;).&lt;br /&gt;
&lt;br /&gt;
== GetSafeSystemVersionCheckInfo ==&lt;br /&gt;
No input, returns 0x10-bytes of output.&lt;br /&gt;
&lt;br /&gt;
[22.0.0+] Now returns 0x20-bytes of output.&lt;br /&gt;
&lt;br /&gt;
[S2] Used by web-applets via ns:vm.&lt;br /&gt;
&lt;br /&gt;
== RequestUpdateSafeSystemVersionCheckInfo ==&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncResult|IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
[S2] Used by web-applets via ns:vm.&lt;br /&gt;
&lt;br /&gt;
The async task thread uses [[NIM_services|nim]] RequestCheckSafeSystemVersion, etc.&lt;br /&gt;
&lt;br /&gt;
== ResetSafeSystemVersionCheckInfo ==&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
This throws an error if [[Settings_services|GetDebugModeFlag]] returns false.&lt;br /&gt;
&lt;br /&gt;
= ns:su =&lt;br /&gt;
This is &amp;quot;nn::ns::detail::ISystemUpdateInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#GetBackgroundNetworkUpdateState]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#OpenSystemUpdateControl]]&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [[#NotifyExFatDriverRequired]]&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [[#ClearExFatDriverStatusForDebug]]&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [[#RequestBackgroundNetworkUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 5 || [[#NotifyBackgroundNetworkUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 6 || [[#NotifyExFatDriverDownloadedForDebug]]&lt;br /&gt;
|-&lt;br /&gt;
| 9 || [[#GetSystemUpdateNotificationEventForContentDelivery]]&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [[#NotifySystemUpdateForContentDelivery]]&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [3.0.0+] [[#PrepareShutdown]]&lt;br /&gt;
|-&lt;br /&gt;
| 12 || [3.0.0-3.0.2]&lt;br /&gt;
|-&lt;br /&gt;
| 13 || [3.0.0-3.0.2]&lt;br /&gt;
|-&lt;br /&gt;
| 14 || [3.0.0-3.0.2]&lt;br /&gt;
|-&lt;br /&gt;
| 15 || [3.0.0-3.0.2]&lt;br /&gt;
|-&lt;br /&gt;
| 16 || [4.0.0+] [[#DestroySystemUpdateTask]]&lt;br /&gt;
|-&lt;br /&gt;
| 17 || [4.0.0+] [[#RequestSendSystemUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 18 || [4.0.0+] [[#GetSendSystemUpdateProgress]]&lt;br /&gt;
|-&lt;br /&gt;
| 19 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 20 || [S2]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== GetBackgroundNetworkUpdateState ==&lt;br /&gt;
No input, returns an output [[#BackgroundNetworkUpdateState]].&lt;br /&gt;
&lt;br /&gt;
This is similar to [[#HasDownloaded]], see [[#BackgroundNetworkUpdateState]].&lt;br /&gt;
&lt;br /&gt;
== OpenSystemUpdateControl ==&lt;br /&gt;
No input, returns an [[#ISystemUpdateControl]].&lt;br /&gt;
&lt;br /&gt;
Only 1 ISystemUpdateControl can be open at a time.&lt;br /&gt;
&lt;br /&gt;
== NotifyExFatDriverRequired ==&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Only usable when an [[#ISystemUpdateControl]] isn&#039;t open.&lt;br /&gt;
&lt;br /&gt;
This uses [[NIM_services|nim]] ListSystemUpdateTask, then when a task is returned uses it with DestroySystemUpdateTask.&lt;br /&gt;
&lt;br /&gt;
Then this runs ExFat handling, updates state, and sets the same state flag as [[#RequestBackgroundNetworkUpdate]].&lt;br /&gt;
&lt;br /&gt;
== ClearExFatDriverStatusForDebug ==&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
== RequestBackgroundNetworkUpdate ==&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Only usable when an [[#ISystemUpdateControl]] isn&#039;t open.&lt;br /&gt;
&lt;br /&gt;
This sets a state flag to value 1.&lt;br /&gt;
&lt;br /&gt;
== NotifyBackgroundNetworkUpdate ==&lt;br /&gt;
Takes an input [[NCM_services#ContentMetaKey|ContentMetaKey]], no output.&lt;br /&gt;
&lt;br /&gt;
This checks whether a sysupdate is needed with the input ContentMetaKey using [[NCM_services|NCM]] commands, if not this will just return 0. Otherwise, this will then run code which is identical to [[#RequestBackgroundNetworkUpdate]].&lt;br /&gt;
&lt;br /&gt;
== NotifyExFatDriverDownloadedForDebug ==&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
== GetSystemUpdateNotificationEventForContentDelivery ==&lt;br /&gt;
No input, returns an output Event handle with EventClearMode=0.&lt;br /&gt;
&lt;br /&gt;
== NotifySystemUpdateForContentDelivery ==&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Signals the Event returned by [[#GetSystemUpdateNotificationEventForContentDelivery]].&lt;br /&gt;
&lt;br /&gt;
== PrepareShutdown ==&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
This is used by [[AM_services|AM]].&lt;br /&gt;
&lt;br /&gt;
Just returns 0 when an [[#ISystemUpdateControl]] is open. &lt;br /&gt;
&lt;br /&gt;
This does various cleanup / uses various service-cmds etc for shutdown preparation.&lt;br /&gt;
&lt;br /&gt;
== DestroySystemUpdateTask ==&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Only usable when an [[#ISystemUpdateControl]] isn&#039;t open.&lt;br /&gt;
&lt;br /&gt;
This uses [[NIM_services|nim]] ListSystemUpdateTask, then when a task is returned uses it with DestroySystemUpdateTask.&lt;br /&gt;
&lt;br /&gt;
== RequestSendSystemUpdate ==&lt;br /&gt;
Takes a type-0x15 input buffer containing a [[#SystemDeliveryInfo]], an u16 port, an u32 Ipv4Address, returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
[[qlaunch]] uses value 55556 for the port. IP is normally a local-WLAN address, however this can be any address. port/addr are little-endian.&lt;br /&gt;
&lt;br /&gt;
See [[NIM_services|nim]] regarding the input addr/port usage, etc.&lt;br /&gt;
&lt;br /&gt;
[11.0.0+] An error is thrown if LocalContentShare is not [[#IsLocalContentShareEnabled|enabled]].&lt;br /&gt;
&lt;br /&gt;
This validates the [[#SystemDeliveryInfo]] and generates a [[NCM_services#ContentMetaKey|ContentMetaKey]] from that, and creates the [[#IAsyncResult]] + the async thread which handles the [[#IAsyncResult]] operation.&lt;br /&gt;
&lt;br /&gt;
The above validation verifies that the HMAC and SystemDeliveryProtocolVersion are valid. The OldSystemUpdateId ([20.0.0+] SystemUpdateId, SystemUpdateIdFlag ignored) must match the Id for the installed SystemUpdate as returned by [[NCM_services|ncm]].&lt;br /&gt;
&lt;br /&gt;
Then the thread does:&lt;br /&gt;
* Calls a func which does:&lt;br /&gt;
** Uses [[NIM_services|nim]] CreateLocalCommunicationSendSystemUpdateTask, returning the Result on failure.&lt;br /&gt;
*** The input firmware_variation is from the [[#SystemDeliveryInfo|FirmwareVariationId]].&lt;br /&gt;
** Uses [[NIM_services|nim]] RequestLocalCommunicationSendSystemUpdateTaskRun, returning the Result on failure. Waits for the IAsyncResult operation from this to finish, then uses the Get cmd to get the output Result.&lt;br /&gt;
*** When the Result from Get is an error, a func is called for filling in the [[#IAsyncResult|IAsyncResult]] ErrorContext with Type4.&lt;br /&gt;
** Handles cleanup and returns.&lt;br /&gt;
* Unlike [[#RequestReceiveSystemUpdate]], this doesn&#039;t save a SystemPlayReport.&lt;br /&gt;
&lt;br /&gt;
== GetSendSystemUpdateProgress ==&lt;br /&gt;
No input, returns an output [[#SystemUpdateProgress]].&lt;br /&gt;
&lt;br /&gt;
Same as [[#GetReceiveProgress]] except this uses nim ListLocalCommunicationSendSystemUpdateTask and GetLocalCommunicationSendSystemUpdateTaskInfo. The data copied to output is also swapped: u64 nim_out+0x8 is copied to out+0x8, and u64 nim_out+0x10 is copied to out+0x0.&lt;br /&gt;
&lt;br /&gt;
== Cmd19 ==&lt;br /&gt;
This is exclusive to S2.&lt;br /&gt;
&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
== Cmd20 ==&lt;br /&gt;
This is exclusive to S2.&lt;br /&gt;
&lt;br /&gt;
No input, returns an output u8.&lt;br /&gt;
&lt;br /&gt;
== ISystemUpdateControl ==&lt;br /&gt;
This is &amp;quot;nn::ns::detail::ISystemUpdateControl&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#HasDownloaded]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#RequestCheckLatestUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [[#RequestDownloadLatestUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [[#GetDownloadProgress]]&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [[#ApplyDownloadedUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 5 || [[#RequestPrepareCardUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 6 || [[#GetPrepareCardUpdateProgress]]&lt;br /&gt;
|-&lt;br /&gt;
| 7 || [[#HasPreparedCardUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 8 || [[#ApplyCardUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 9 || [[#GetDownloadedEulaDataSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [[#GetDownloadedEulaData]]&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [[#SetupCardUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 12 || [[#GetPreparedCardUpdateEulaDataSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 13 || [[#GetPreparedCardUpdateEulaData]]&lt;br /&gt;
|-&lt;br /&gt;
| 14 || [4.0.0+] [[#SetupCardUpdateViaSystemUpdater]]&lt;br /&gt;
|-&lt;br /&gt;
| 15 || [4.0.0+] [[#HasReceived]]&lt;br /&gt;
|-&lt;br /&gt;
| 16 || [4.0.0+] [[#RequestReceiveSystemUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 17 || [4.0.0+] [[#GetReceiveProgress]]&lt;br /&gt;
|-&lt;br /&gt;
| 18 || [4.0.0+] [[#ApplyReceivedUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 19 || [4.0.0+] [[#GetReceivedEulaDataSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 20 || [4.0.0+] [[#GetReceivedEulaData]]&lt;br /&gt;
|-&lt;br /&gt;
| 21 || [4.0.0+] [[#SetupToReceiveSystemUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 22 || [6.0.0+] [[#RequestCheckLatestUpdateIncludesRebootlessUpdate]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
All Card cmds except SetupCardUpdate* require [[#SetupCardUpdate]]/[[#SetupCardUpdateViaSystemUpdater]] to be used previously. [[#GetPreparedCardUpdateEulaDataSize]]/[[#GetPreparedCardUpdateEulaData]] checks a different state flag.&lt;br /&gt;
&lt;br /&gt;
=== HasDownloaded ===&lt;br /&gt;
No input, returns an output u8 bool flag.&lt;br /&gt;
&lt;br /&gt;
Gets whether a network sysupdate was downloaded, with install pending.&lt;br /&gt;
&lt;br /&gt;
Uses [[NIM_services|nim]] ListSystemUpdateTask and [[NIM_services|nim]] GetSystemUpdateTaskInfo. When ListSystemUpdateTask successfully returns a task and GetSystemUpdateTaskInfo is successful, the output flag is set to: &amp;lt;code&amp;gt;*((u8*)(taskinfo+0) == 0x3&amp;lt;/code&amp;gt;. Otherwise, flag=0.&lt;br /&gt;
&lt;br /&gt;
This always returns 0, however this will assert if GetSystemUpdateTaskInfo fails with ret!=0x3C89.&lt;br /&gt;
&lt;br /&gt;
=== RequestCheckLatestUpdate ===&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
The data that can be read from the [[#IAsyncValue]] is [[#LatestSystemUpdate]].&lt;br /&gt;
&lt;br /&gt;
=== RequestDownloadLatestUpdate ===&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
=== GetDownloadProgress ===&lt;br /&gt;
No input, returns an output [[#SystemUpdateProgress]].&lt;br /&gt;
&lt;br /&gt;
Similar to [[#HasDownloaded]] except instead of a flag, this returns the 0x10-bytes from taskinfo+8. The output struct is cleared when the task(info) isn&#039;t available.&lt;br /&gt;
&lt;br /&gt;
=== ApplyDownloadedUpdate ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Runs code similar to [[#HasDownloaded]], throwing an error if a network sysupdate isn&#039;t ready for install. Then the sysupdate is installed:&lt;br /&gt;
&lt;br /&gt;
* Uses ListSystemUpdateTask again, then [[NIM_services|nim]] IsExFatDriverIncluded. Runs ExFat handling when the output flag is set.&lt;br /&gt;
* On newer system-versions, this uses [[NIM_services|nim]] GetSystemUpdateTaskInfo then on success uses data from there to save a SystemPlayReport when the cached [[System_Settings|system-setting]] &amp;quot;systemreport!enabled&amp;quot; is set.&lt;br /&gt;
** The EventId is &amp;quot;systemupdate_dl_throughput&amp;quot; with ApplicationId 0100000000001018.&lt;br /&gt;
** The following fields are added to the report, see [[NIM_services#SystemUpdateTaskInfo|nim SystemUpdateTaskInfo]]: &amp;quot;ContentMetaId&amp;quot;, &amp;quot;Version&amp;quot;, &amp;quot;DownloadSize&amp;quot;, and &amp;quot;ThroughputKBps&amp;quot;.&lt;br /&gt;
* On newer system-versions, this saves another SystemPlayReport when a state flag is set (same flag mentioned above).&lt;br /&gt;
** The EventId is &amp;quot;systemupdate_pass&amp;quot; with ApplicationId 0100000000001021.&lt;br /&gt;
** This report has the following fields:&lt;br /&gt;
*** &amp;quot;Type&amp;quot;&lt;br /&gt;
*** &amp;quot;SourceSystemUpdateMetaId&amp;quot;&lt;br /&gt;
*** &amp;quot;SourceSystemUpdateMetaVersion&amp;quot;&lt;br /&gt;
*** &amp;quot;SourceExFatStatus&amp;quot;&lt;br /&gt;
*** &amp;quot;DestinationSystemUpdateMetaId&amp;quot;&lt;br /&gt;
*** &amp;quot;DestinationSystemUpdateMetaVersion&amp;quot;&lt;br /&gt;
*** &amp;quot;DestinationExFatStatus&amp;quot;&lt;br /&gt;
*** &amp;quot;Rebootless&amp;quot;&lt;br /&gt;
* Since BootImagePackage will be installed later, the two flags in [[Flash_Filesystem#System_Update_Control]] are set to 1.&lt;br /&gt;
* Uses [[NIM_services|nim]] CommitSystemUpdateTask and [[NIM_services|nim]] DestroySystemUpdateTask.&lt;br /&gt;
* Installs BootImagePackage. After installing each BootImagePackage, the associated flag in [[Flash_Filesystem#System_Update_Control]] is set to 0.&lt;br /&gt;
* On newer system versions when an input flag is set, this uses [[Filesystem_services|NotifySystemDataUpdateEvent]], however this doesn&#039;t happen with ApplyDownloadedUpdate since that input flag is 0.&lt;br /&gt;
&lt;br /&gt;
=== RequestPrepareCardUpdate ===&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
=== GetPrepareCardUpdateProgress ===&lt;br /&gt;
No input, returns an output [[#SystemUpdateProgress]].&lt;br /&gt;
&lt;br /&gt;
=== HasPreparedCardUpdate ===&lt;br /&gt;
No input, returns an output u8 bool flag.&lt;br /&gt;
&lt;br /&gt;
=== ApplyCardUpdate ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
=== GetDownloadedEulaDataSize ===&lt;br /&gt;
Takes a type-0x15 input buffer [[#EulaDataPath]], returns an output u64 &#039;&#039;&#039;filesize&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
Runs code similar to [[#HasDownloaded]], throwing an error if a network sysupdate isn&#039;t ready for install.&lt;br /&gt;
&lt;br /&gt;
Uses ListSystemUpdateTask again. Then [[NIM_services|nim]] GetDownloadedSystemDataPath, with the output ContentPath being used to mount the EULA title with FS.&lt;br /&gt;
&lt;br /&gt;
Then &amp;quot;&amp;lt;mountname&amp;gt;:/&amp;lt;[[#EulaDataPath]]&amp;gt;&amp;quot; is opened, gets the &#039;&#039;&#039;filesize&#039;&#039;&#039;, then runs cleanup.&lt;br /&gt;
&lt;br /&gt;
=== GetDownloadedEulaData ===&lt;br /&gt;
Takes a type-0x15 input buffer [[#EulaDataPath]] and a type-0x6 output buffer, returns an output u64 &#039;&#039;&#039;filesize&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
Similar to [[#GetDownloadedEulaDataSize]] except this reads the file instead, using the specified output buffer with size=filesize. This will throw an error if the filesize is larger than the buffer size.&lt;br /&gt;
&lt;br /&gt;
=== SetupCardUpdate ===&lt;br /&gt;
Takes an input u64 size and a TransferMemory handle, no output.&lt;br /&gt;
&lt;br /&gt;
Official sw creates the TransferMemory with an user-specified buffer, with permissions=None.&lt;br /&gt;
&lt;br /&gt;
[[qlaunch]] uses size 0x100000 for the TransferMemory buffer.&lt;br /&gt;
&lt;br /&gt;
=== GetPreparedCardUpdateEulaDataSize ===&lt;br /&gt;
Takes a type-0x15 input buffer [[#EulaDataPath]], returns an output u64 &#039;&#039;&#039;filesize&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
This is similar to [[#GetDownloadedEulaDataSize]].&lt;br /&gt;
&lt;br /&gt;
=== GetPreparedCardUpdateEulaData ===&lt;br /&gt;
Takes a type-0x15 input buffer [[#EulaDataPath]] and a type-0x6 output buffer, returns an output u64 &#039;&#039;&#039;filesize&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
This is similar to [[#GetDownloadedEulaData]].&lt;br /&gt;
&lt;br /&gt;
=== SetupCardUpdateViaSystemUpdater ===&lt;br /&gt;
Takes an input u64 size and a TransferMemory handle, no output.&lt;br /&gt;
&lt;br /&gt;
The permissions for the TransferMemory is None.&lt;br /&gt;
&lt;br /&gt;
Same as [[#SetupCardUpdate]], except this doesn&#039;t have the code for [[Filesystem_services|GetGameCardHandle/GetGameCardUpdatePartitionInfo]], and uses [[Filesystem_services|OpenRegisteredUpdatePartition]] instead of [[Filesystem_services|OpenGameCardFileSystem]]. This uses the same is_initialized bool state flag.&lt;br /&gt;
&lt;br /&gt;
=== HasReceived ===&lt;br /&gt;
No input, returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
Same as [[#HasDownloaded]] except this uses [[NIM_services|nim]] ListLocalCommunicationReceiveSystemUpdateTask and GetLocalCommunicationReceiveSystemUpdateTaskInfo.&lt;br /&gt;
&lt;br /&gt;
=== RequestReceiveSystemUpdate ===&lt;br /&gt;
Takes a type-0x15 input buffer containing a [[#SystemDeliveryInfo]], an u16 port, an u32 Ipv4Address, returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
[[qlaunch]] uses the same value for the port as [[#RequestSendSystemUpdate]] (see [[#RequestSendSystemUpdate]] for addr as well).&lt;br /&gt;
&lt;br /&gt;
See [[NIM_services|nim]] regarding the input addr/port usage, etc.&lt;br /&gt;
&lt;br /&gt;
This uses the same LocalContentShare check as [[#RequestSendSystemUpdate|RequestSendSystemUpdate]].&lt;br /&gt;
&lt;br /&gt;
An error is thrown if a state flag is clear.&lt;br /&gt;
&lt;br /&gt;
This validates the [[#SystemDeliveryInfo]] (same as [[#RequestSendSystemUpdate|RequestSendSystemUpdate]]) and generates a [[NCM_services#ContentMetaKey|ContentMetaKey]] from that, and creates the [[#IAsyncResult]] + the async thread which handles the [[#IAsyncResult]] operation.&lt;br /&gt;
&lt;br /&gt;
Then the thread does:&lt;br /&gt;
&lt;br /&gt;
* Calls a func which does:&lt;br /&gt;
** Throws an error if [[NIM_services#ListSystemUpdateTask|ListSystemUpdateTask]] returns any task.&lt;br /&gt;
** Checks whether a sysupdate is actually required using the previously generated [[NCM_services#ContentMetaKey|ContentMetaKey]] (this func is also passed the below statefield as the last param), throwing an error if not.&lt;br /&gt;
*** [20.0.0+] The above check-sysupdate func was updated (which is also used elsewhere), flag handling during the loop was updated (which uses the last input param).&lt;br /&gt;
** Uses [[NIM_services|nim]] CreateLocalCommunicationReceiveSystemUpdateTask, returning the Result on failure.&lt;br /&gt;
*** The input firmware_variation is from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;ns.systemupdate!firmware_variation&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;ns.systemupdate!t_firmware_variation&amp;lt;/code&amp;gt;, depending on the [[Settings_services|PlatformRegion]] (value 0xFF is used when the output setting-size is invalid).&lt;br /&gt;
*** The input &#039;&#039;&#039;unk&#039;&#039;&#039; is set to: &amp;lt;code&amp;gt;unk = statefield == 0 ? 0x4 : 0xC&amp;lt;/code&amp;gt; ([20.0.0+] uses statefield &amp;amp; 1 == 0). [20.0.0+] Additional data is now ORRed with unk afterwards: &amp;lt;code&amp;gt;unk |= ((statefield&amp;gt;&amp;gt;1) &amp;amp; 0x3) &amp;lt;&amp;lt; 8;&amp;lt;/code&amp;gt; (same statefield as before)&lt;br /&gt;
** Uses [[NIM_services|nim]] RequestLocalCommunicationReceiveSystemUpdateTaskRun, returning the Result on failure. Waits for the IAsyncResult operation from this to finish, then uses the Get cmd to get the output Result.&lt;br /&gt;
*** When the Result from Get is an error, a func is called for filling in the [[#IAsyncResult|IAsyncResult]] ErrorContext with Type4.&lt;br /&gt;
** Handles cleanup and returns.&lt;br /&gt;
* On success, this loads various data which is then used for saving a SystemPlayReport when the cached [[System_Settings|system-setting]] &amp;quot;systemreport!enabled&amp;quot; is set.&lt;br /&gt;
** The EventId is &amp;quot;receive_system_update&amp;quot; with ApplicationId &amp;lt;NS ProgramId&amp;gt;.&lt;br /&gt;
** This report has the following fields: &lt;br /&gt;
*** &amp;quot;SourceSystemUpdateId&amp;quot;&lt;br /&gt;
*** &amp;quot;DestinationSystemUpdateId&amp;quot;&lt;br /&gt;
*** &amp;quot;SourceSystemUpdateVersion&amp;quot;&lt;br /&gt;
*** &amp;quot;DestinationSystemUpdateVersion&amp;quot;&lt;br /&gt;
*** &amp;quot;SenderFirmwareVariationId&amp;quot;&lt;br /&gt;
*** &amp;quot;ReceiverFirmwareVariationId&amp;quot;&lt;br /&gt;
*** &amp;quot;SenderPlatformRegion&amp;quot;&lt;br /&gt;
*** &amp;quot;ReceiverPlatformRegion&amp;quot;&lt;br /&gt;
*** &amp;quot;SenderHasExFat&amp;quot;&lt;br /&gt;
*** &amp;quot;ReceiverHasExFat&amp;quot;&lt;br /&gt;
*** &amp;quot;Size&amp;quot;&lt;br /&gt;
*** &amp;quot;ThroughputKBps&amp;quot;&lt;br /&gt;
&lt;br /&gt;
=== GetReceiveProgress ===&lt;br /&gt;
No input, returns an output [[#SystemUpdateProgress]].&lt;br /&gt;
&lt;br /&gt;
Same as [[#GetDownloadProgress]] except this uses [[NIM_services|nim]] ListLocalCommunicationReceiveSystemUpdateTask and GetLocalCommunicationReceiveSystemUpdateTaskInfo.&lt;br /&gt;
&lt;br /&gt;
=== ApplyReceivedUpdate ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
This uses the same LocalContentShare check as [[#RequestSendSystemUpdate|RequestSendSystemUpdate]].&lt;br /&gt;
&lt;br /&gt;
=== GetReceivedEulaDataSize ===&lt;br /&gt;
Takes a type-0x15 input buffer [[#EulaDataPath]], returns an output u64 &#039;&#039;&#039;filesize&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
This is similar to [[#GetDownloadedEulaDataSize]].&lt;br /&gt;
&lt;br /&gt;
=== GetReceivedEulaData ===&lt;br /&gt;
Takes a type-0x15 input buffer [[#EulaDataPath]] and a type-0x6 output buffer, returns an output u64 &#039;&#039;&#039;filesize&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
This is similar to [[#GetDownloadedEulaData]].&lt;br /&gt;
&lt;br /&gt;
=== SetupToReceiveSystemUpdate ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
This just uses [[NIM_services|nim]] ListSystemUpdateTask, then when a task is returned uses it with DestroySystemUpdateTask.&lt;br /&gt;
&lt;br /&gt;
[[qlaunch]] uses this before [[#RequestReceiveSystemUpdate]].&lt;br /&gt;
&lt;br /&gt;
=== RequestCheckLatestUpdateIncludesRebootlessUpdate ===&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
= IAsyncValue =&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IAsyncValue&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetSize&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Get&lt;br /&gt;
|-&lt;br /&gt;
| 2 || Cancel&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [4.0.0+] GetErrorContext&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Official sw creates a container object for this using the output from the service commands, which contains the IAsyncValue object, and the Event with EventClearMode=0.&lt;br /&gt;
&lt;br /&gt;
* GetSize: No input, returns an output u64.&lt;br /&gt;
* Get: Takes a type-0x6 output buffer, no output. Official sw waits on the Event prior to using this cmd.&lt;br /&gt;
* Cancel: No input/output. Used by official sw when closing the object, when the serv-obj is initialized (after using the cmd, official sw will also wait on the Event). This cmd is also used in other official sw funcs.&lt;br /&gt;
* GetErrorContext: No input/output, takes a type-0x16 output buffer containing an [[Error_Applet#ErrorContext|ErrorContext]].&lt;br /&gt;
&lt;br /&gt;
= IAsyncResult =&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IAsyncResult&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || Get&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Cancel&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [4.0.0+] GetErrorContext&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Official sw creates a container object for this using the output from the service commands, which contains the IAsyncResult object, and the Event with EventClearMode=0.&lt;br /&gt;
&lt;br /&gt;
* Get: No input/output. Official sw waits on the Event prior to using this cmd.&lt;br /&gt;
* Cancel: No input/output. Used by official sw when closing the object, when the serv-obj is initialized (after using the cmd, official sw will also wait on the Event). This cmd is also used in other official sw funcs.&lt;br /&gt;
* GetErrorContext: No input/output, takes a type-0x16 output buffer containing an [[Error_Applet#ErrorContext|ErrorContext]].&lt;br /&gt;
&lt;br /&gt;
= ns:dev =&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IDevelopInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
[10.0.0+] Some of these cmds were replaced by the [[PGL_services|pgl]] system module.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [1.0.0-9.2.0] [[#LaunchProgram]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#TerminateProcess]]&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [1.0.0-9.2.0] [[#TerminateProgram]]&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [1.0.0-9.2.0] [[#GetShellEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 5 || [1.0.0-9.2.0] [[#GetShellEventInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 6 || [[#TerminateApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 7 || [1.0.0-9.2.0] [[#PrepareLaunchProgramFromHost]]&lt;br /&gt;
|-&lt;br /&gt;
| 8 || [10.0.0-17.0.1] [[#LaunchApplicationFromHost]] ([1.0.0-9.2.0] LaunchApplication)&lt;br /&gt;
|-&lt;br /&gt;
| 9 || [1.0.0-17.0.1] [[#LaunchApplicationWithStorageId]]&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [6.0.0-8.1.0] [[#IsSystemMemoryResourceLimitBoosted]]&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [6.0.0+] [[#GetRunningApplicationProcessId]]&lt;br /&gt;
|-&lt;br /&gt;
| 12 || [6.0.0+] [[#SetCurrentApplicationRightsEnvironmentCanBeActive]]&lt;br /&gt;
|-&lt;br /&gt;
| 13 || [9.0.0+] [[#CreateApplicationResource]]&lt;br /&gt;
|-&lt;br /&gt;
| 14 || [9.0.0+] [[#IsPreomia]]&lt;br /&gt;
|-&lt;br /&gt;
| 15 || [10.0.0-17.0.1] [[#GetApplicationProgramIdFromHost]]&lt;br /&gt;
|-&lt;br /&gt;
| 16 || [12.0.0+] RefreshCachedDebugValues&lt;br /&gt;
|-&lt;br /&gt;
| 17 || [12.0.0+] [[#PrepareLaunchApplicationFromHost]]&lt;br /&gt;
|-&lt;br /&gt;
| 18 || [12.0.0+] [[#GetLaunchEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 19 || [12.0.0+] [[#GetLaunchResult]]&lt;br /&gt;
|-&lt;br /&gt;
| 20 || [14.0.0+] GetProgramId&lt;br /&gt;
|-&lt;br /&gt;
| 21 || [18.0.0+] [[#PrepareLaunchApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 22 || [18.0.0+] [[#LaunchApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 23 || [18.0.0+] [[#GetProgramIdByApplicationLaunchInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 24 || [18.0.0+] DestroyApplicationLaunchPreparation&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== LaunchProgram ==&lt;br /&gt;
Wrapper for &amp;quot;pm:shell&amp;quot; [[Process_Manager_services#pm:shell|LaunchProcess]].&lt;br /&gt;
&lt;br /&gt;
== TerminateProcess ==&lt;br /&gt;
Wrapper for &amp;quot;pm:shell&amp;quot; [[Process_Manager_services#pm:shell|TerminateProcess]].&lt;br /&gt;
&lt;br /&gt;
== TerminateProgram ==&lt;br /&gt;
Wrapper for &amp;quot;pm:shell&amp;quot; [[Process_Manager_services#pm:shell|TerminateProgram]].&lt;br /&gt;
&lt;br /&gt;
== GetShellEvent ==&lt;br /&gt;
Wrapper for &amp;quot;pm:shell&amp;quot; [[Process_Manager_services#pm:shell|GetProcessEventHandle]].&lt;br /&gt;
&lt;br /&gt;
== GetShellEventInfo ==&lt;br /&gt;
Wrapper for &amp;quot;pm:shell&amp;quot; [[Process_Manager_services#pm:shell|GetProcessEventInfo]].&lt;br /&gt;
&lt;br /&gt;
== TerminateApplication ==&lt;br /&gt;
Calls &amp;quot;pm:shell&amp;quot; [[Process_Manager_services#pm:shell|GetApplicationProcessIdForShell]] and sends the ProcessId to [[Process_Manager_services#pm:shell|TerminateProcess]].&lt;br /&gt;
&lt;br /&gt;
== PrepareLaunchProgramFromHost ==&lt;br /&gt;
Takes a type-0x5 input buffer containing the [[Filesystem_services#FspPath|FspPath]], returns an output 0x10-byte struct.&lt;br /&gt;
&lt;br /&gt;
Calls [[NCM_services#IPathResolverForStorage|IPathResolverForStorage]] Set...NcaPath functions.&lt;br /&gt;
&lt;br /&gt;
== LaunchApplicationFromHost ==&lt;br /&gt;
Takes an input u32 [[Process_Manager_services#LaunchFlags|LaunchFlags]] and a type-0x5 input buffer containing the [[Filesystem_services#FspPath|FspPath]]. Returns an output u64 ProcessId.&lt;br /&gt;
&lt;br /&gt;
== LaunchApplicationWithStorageId ==&lt;br /&gt;
Takes 2 input u8 [[NCM_services#StorageId|StorageIds]], an u32 [[Process_Manager_services#LaunchFlags|LaunchFlags]], and an [[NCM_services#ApplicationId|ApplicationId]]. Returns an output u64 ProcessId.&lt;br /&gt;
&lt;br /&gt;
Launches an application title which is registered with NS.&lt;br /&gt;
&lt;br /&gt;
== IsSystemMemoryResourceLimitBoosted ==&lt;br /&gt;
No input. Returns a bool.&lt;br /&gt;
&lt;br /&gt;
== GetRunningApplicationProcessId ==&lt;br /&gt;
Returns an output u64 ProcessId.&lt;br /&gt;
&lt;br /&gt;
== SetCurrentApplicationRightsEnvironmentCanBeActive ==&lt;br /&gt;
Takes an input bool. No output.&lt;br /&gt;
&lt;br /&gt;
== CreateApplicationResource ==&lt;br /&gt;
Takes an input u32 (1 = Preomia/MicroApplication). Returns an [[#IApplicationResource]].&lt;br /&gt;
&lt;br /&gt;
== IsPreomia ==&lt;br /&gt;
Takes an input u64 [[NCM_services#ProgramId|ProgramId]]. Returns a bool.&lt;br /&gt;
&lt;br /&gt;
== GetApplicationProgramIdFromHost ==&lt;br /&gt;
Takes a type-0x5 input buffer containing the [[Filesystem_services#FspPath|FspPath]]. Returns an u64 [[NCM_services#ProgramId|ProgramId]].&lt;br /&gt;
&lt;br /&gt;
== PrepareLaunchApplicationFromHost ==&lt;br /&gt;
[18.0.0+] Now returns a total of 0x50 bytes of output.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] Now returns a total of 0x80 bytes of output.&lt;br /&gt;
&lt;br /&gt;
== GetLaunchEvent ==&lt;br /&gt;
[18.0.0+] Now takes a total of 0x50 bytes of input.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] Now takes a total of 0x80 bytes of input.&lt;br /&gt;
&lt;br /&gt;
== GetLaunchResult ==&lt;br /&gt;
[18.0.0+] Now takes a total of 0x50 bytes of input.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] Now takes a total of 0x80 bytes of input.&lt;br /&gt;
&lt;br /&gt;
== PrepareLaunchApplication ==&lt;br /&gt;
Takes a total of 0x10-bytes of input. Returns a total of 0x50-bytes of output.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] Now returns a total of 0x80-bytes of output.&lt;br /&gt;
&lt;br /&gt;
== LaunchApplication ==&lt;br /&gt;
Takes a total of 0x50-bytes of input. Returns a total of 8-bytes of output.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] Now takes a total of 0x80 bytes of input.&lt;br /&gt;
&lt;br /&gt;
== GetProgramIdByApplicationLaunchInfo ==&lt;br /&gt;
Takes a total of 0x50-bytes of input. Returns a total of 8-bytes of output.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] Now takes a total of 0x80 bytes of input.&lt;br /&gt;
&lt;br /&gt;
= acc:su =&lt;br /&gt;
This is &amp;quot;nn::account::IAccountServiceForAdministrator&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
[13.0.0+] This was moved from [[Account_services|account]].&lt;br /&gt;
&lt;br /&gt;
This is only available when the output from [[Process_Manager_services|pm:bm]] GetBootMode is Normal/Maintenance.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetUserCount ||&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GetUserExistence ||&lt;br /&gt;
|-&lt;br /&gt;
| 2 || ListAllUsers ||&lt;br /&gt;
|-&lt;br /&gt;
| 3 || ListOpenUsers ||&lt;br /&gt;
|-&lt;br /&gt;
| 4 || GetLastOpenedUser ||&lt;br /&gt;
|-&lt;br /&gt;
| 5 || GetProfile || Returns an [[#IProfile]].&lt;br /&gt;
|-&lt;br /&gt;
| 6 || [3.0.0+] GetProfileDigest ||&lt;br /&gt;
|-&lt;br /&gt;
| 50 || [[#IsUserRegistrationRequestPermitted]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 51 || TrySelectUserWithoutInteractionDeprecated ([1.0.0-18.1.0] [[#TrySelectUserWithoutInteraction]]) ||&lt;br /&gt;
|-&lt;br /&gt;
| 52 || [19.0.0+] TrySelectUserWithoutInteraction ||&lt;br /&gt;
|-&lt;br /&gt;
| 60 || [5.0.0-5.1.0] ListOpenContextStoredUsers ||&lt;br /&gt;
|-&lt;br /&gt;
| 99 || [6.0.0+] DebugActivateOpenContextRetention || No input, returns an [[#ISessionObject]].&lt;br /&gt;
|-&lt;br /&gt;
| 100 || GetUserRegistrationNotifier || Returns an [[#INotifier]].&lt;br /&gt;
|-&lt;br /&gt;
| 101 || GetUserStateChangeNotifier || Returns an [[#INotifier]].&lt;br /&gt;
|-&lt;br /&gt;
| 102 || GetBaasAccountManagerForSystemService || Returns an [[#IManagerForSystemService]].&lt;br /&gt;
|-&lt;br /&gt;
| 103 || GetBaasUserAvailabilityChangeNotifier || Returns an [[#INotifier]].&lt;br /&gt;
|-&lt;br /&gt;
| 104 || GetProfileUpdateNotifier || Returns an [[#INotifier]].&lt;br /&gt;
|-&lt;br /&gt;
| 105 || [4.0.0+] CheckNetworkServiceAvailabilityAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 106 || [9.0.0+] GetProfileSyncNotifier ||&lt;br /&gt;
|-&lt;br /&gt;
| 110 || StoreSaveDataThumbnail ||&lt;br /&gt;
|-&lt;br /&gt;
| 111 || ClearSaveDataThumbnail ||&lt;br /&gt;
|-&lt;br /&gt;
| 112 || LoadSaveDataThumbnail ||&lt;br /&gt;
|-&lt;br /&gt;
| 113 || [5.0.0+] GetSaveDataThumbnailExistence ||&lt;br /&gt;
|-&lt;br /&gt;
| 120 || [10.0.0+] ListOpenUsersInApplication ||&lt;br /&gt;
|-&lt;br /&gt;
| 130 || [6.0.0+] ActivateOpenContextRetention || Takes a total of 0x8-bytes of input, returns an [[#ISessionObject]].&lt;br /&gt;
|-&lt;br /&gt;
| 140 || [6.0.0+] ListQualifiedUsers || &lt;br /&gt;
|-&lt;br /&gt;
| 150 || [10.0.0-10.2.0] AuthenticateApplicationAsync || &lt;br /&gt;
|-&lt;br /&gt;
| 151 || [12.0.0+] EnsureSignedDeviceIdentifierCacheForNintendoAccountAsync || &lt;br /&gt;
|-&lt;br /&gt;
| 152 || [12.0.0+] LoadSignedDeviceIdentifierCacheForNintendoAccount ||&lt;br /&gt;
|-&lt;br /&gt;
| 170 || [13.0.0+] GetNasOp2MembershipStateChangeNotifier ||&lt;br /&gt;
|-&lt;br /&gt;
| 190 || [1.0.0-9.2.0] GetUserLastOpenedApplication ||&lt;br /&gt;
|-&lt;br /&gt;
| 191 || [7.0.0-19.0.1] UpdateNotificationReceiverInfo ([5.0.0-5.1.0] ActivateOpenContextHolder) ||&lt;br /&gt;
|-&lt;br /&gt;
| 200 || BeginUserRegistration ||&lt;br /&gt;
|-&lt;br /&gt;
| 201 || CompleteUserRegistration ||&lt;br /&gt;
|-&lt;br /&gt;
| 202 || CancelUserRegistration ||&lt;br /&gt;
|-&lt;br /&gt;
| 203 || DeleteUser ||&lt;br /&gt;
|-&lt;br /&gt;
| 204 || SetUserPosition ||&lt;br /&gt;
|-&lt;br /&gt;
| 205 || GetProfileEditor || Takes an input userID and returns an [[#IProfileEditor]].&lt;br /&gt;
|-&lt;br /&gt;
| 206 || CompleteUserRegistrationForcibly ||&lt;br /&gt;
|-&lt;br /&gt;
| 210 || [3.0.0+] CreateFloatingRegistrationRequest || Returns an [[#IFloatingRegistrationRequest]].&lt;br /&gt;
|-&lt;br /&gt;
| 211 || [8.0.0+] CreateProcedureToRegisterUserWithNintendoAccount || Takes a total of 0x4-bytes of input and a handle, returns an [[#IOAuthProcedureForUserRegistration]].&lt;br /&gt;
|-&lt;br /&gt;
| 212 || [8.0.0+] ResumeProcedureToRegisterUserWithNintendoAccount || Takes a total of 0x14-bytes of input and a handle, returns an [[#IOAuthProcedureForUserRegistration]].&lt;br /&gt;
|-&lt;br /&gt;
| 213 || [17.0.0+] CreateProcedureToCreateUserWithNintendoAccount ||&lt;br /&gt;
|-&lt;br /&gt;
| 214 || [17.0.0+] ResumeProcedureToCreateUserWithNintendoAccount ||&lt;br /&gt;
|-&lt;br /&gt;
| 215 || [17.0.0+] ResumeProcedureToCreateUserWithNintendoAccountAfterApplyResponse ||&lt;br /&gt;
|-&lt;br /&gt;
| 230 || AuthenticateServiceAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 250 || GetBaasAccountAdministrator || Returns an [[#IAdministrator]].&lt;br /&gt;
|-&lt;br /&gt;
| 251 || [20.0.0+] SynchronizeNetworkServiceAccountsSnapshotAsync ||&lt;br /&gt;
|-&lt;br /&gt;
| 290 || ProxyProcedureForGuestLoginWithNintendoAccount || Returns an [[#IOAuthProcedureForExternalNsa]] (formerly [[#IOAuthProcedureForGuestLogin]] with [1.0.0-2.3.0]).&lt;br /&gt;
|-&lt;br /&gt;
| 291 || [3.0.0+] ProxyProcedureForFloatingRegistrationWithNintendoAccount || Returns an [[#IOAuthProcedureForExternalNsa]].&lt;br /&gt;
|-&lt;br /&gt;
| 292 || [20.0.0+] ProxyProcedureForDeviceMigrationAuthenticatingOperatingUser ||&lt;br /&gt;
|-&lt;br /&gt;
| 293 || [20.0.0+] ProxyProcedureForDeviceMigrationDownload ||&lt;br /&gt;
|-&lt;br /&gt;
| 299 || SuspendBackgroundDaemon || Returns an [[#ISessionObject]].&lt;br /&gt;
|-&lt;br /&gt;
| 350 || [20.0.0+] CreateDeviceMigrationUserExportRequest ||&lt;br /&gt;
|-&lt;br /&gt;
| 351 || [20.0.0+] UploadNasCredential ||&lt;br /&gt;
|-&lt;br /&gt;
| 352 || [20.0.0+] CreateDeviceMigrationUserImportRequest ||&lt;br /&gt;
|-&lt;br /&gt;
| 353 || [20.0.0+] DeleteUserMigrationSaveData ||&lt;br /&gt;
|-&lt;br /&gt;
| 400 || [18.0.0+] SetPinCode ||&lt;br /&gt;
|-&lt;br /&gt;
| 401 || [18.0.0+] GetPinCodeLength ||&lt;br /&gt;
|-&lt;br /&gt;
| 402 || [18.0.0-19.0.1] GetPinCode ||&lt;br /&gt;
|-&lt;br /&gt;
| 403 || [20.0.0+] GetPinCodeParity ||&lt;br /&gt;
|-&lt;br /&gt;
| 404 || [20.0.0+] VerifyPinCode ||&lt;br /&gt;
|-&lt;br /&gt;
| 405 || [20.0.0+] IsPinCodeVerificationForbidden ||&lt;br /&gt;
|-&lt;br /&gt;
| 410 || [18.0.0+] GetPinCodeErrorCount ||&lt;br /&gt;
|-&lt;br /&gt;
| 411 || [18.0.0-19.0.1] ResetPinCodeErrorCount ||&lt;br /&gt;
|-&lt;br /&gt;
| 412 || [18.0.0-19.0.1] IncrementPinCodeErrorCount ||&lt;br /&gt;
|-&lt;br /&gt;
| 413 || [20.0.0+] SetPinCodeErrorCount ||&lt;br /&gt;
|-&lt;br /&gt;
| 420 || [19.0.0+] SetStartPenaltyTime || &lt;br /&gt;
|-&lt;br /&gt;
| 421 || [19.0.0+] GetStartPenaltyTime || &lt;br /&gt;
|-&lt;br /&gt;
| 900 || [13.0.0+] SetUserUnqualifiedForDebug ||&lt;br /&gt;
|-&lt;br /&gt;
| 901 || [13.0.0+] UnsetUserUnqualifiedForDebug ||&lt;br /&gt;
|-&lt;br /&gt;
| 902 || [13.0.0+] ListUsersUnqualifiedForDebug ||&lt;br /&gt;
|-&lt;br /&gt;
| 910 || [16.0.0+] RefreshFirmwareSettingsForDebug ||&lt;br /&gt;
|-&lt;br /&gt;
| 997 || [3.0.0+] DebugInvalidateTokenCacheForUser ||&lt;br /&gt;
|-&lt;br /&gt;
| 998 || DebugSetUserStateClose ||&lt;br /&gt;
|-&lt;br /&gt;
| 999 || DebugSetUserStateOpen ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[10.0.0+] DebugSetUserStateClose/DebugSetUserStateOpen now takes an additional 8-bytes of input.&lt;br /&gt;
&lt;br /&gt;
== IsUserRegistrationRequestPermitted ==&lt;br /&gt;
Takes a PID, an input u64 pid_reserved, and returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
== TrySelectUserWithoutInteraction ==&lt;br /&gt;
Takes an input u8 bool isNetworkServiceAccountRequired, returns an output Uid.&lt;br /&gt;
&lt;br /&gt;
== IManagerForSystemService ==&lt;br /&gt;
This is &amp;quot;nn::account::baas::IManagerForSystemService&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || CheckAvailability ||&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GetAccountId ||&lt;br /&gt;
|-&lt;br /&gt;
| 2 || EnsureIdTokenCacheAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [19.0.0+] LoadIdTokenCacheDeprecated ([1.0.0-18.1.0] LoadIdTokenCache) ||&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [19.0.0+] LoadIdTokenCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 100 || SetSystemProgramIdentification ||&lt;br /&gt;
|-&lt;br /&gt;
| 101 || RefreshNotificationTokenAsync || &lt;br /&gt;
|-&lt;br /&gt;
| 110 || GetServiceEntryRequirementCacheForLogin ||&lt;br /&gt;
|-&lt;br /&gt;
| 111 || InvalidateServiceEntryRequirementCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 113 || GetServiceEntryRequirementCacheForOnlinePlay || Takes a total of 0x8-bytes of input, returns a total of 0x4-bytes of output.&lt;br /&gt;
|-&lt;br /&gt;
| 120 || GetNintendoAccountId ||&lt;br /&gt;
|-&lt;br /&gt;
| 121 || CalculateNintendoAccountAuthenticationFingerprint ||&lt;br /&gt;
|-&lt;br /&gt;
| 130 || GetNintendoAccountUserResourceCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 131 || RefreshNintendoAccountUserResourceCacheAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 132 || RefreshNintendoAccountUserResourceCacheAsyncIfSecondsElapsed || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 133 || GetNintendoAccountVerificationUrlCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 134 || RefreshNintendoAccountVerificationUrlCacheAsync ||&lt;br /&gt;
|-&lt;br /&gt;
| 135 || RefreshNintendoAccountVerificationUrlCacheAsyncIfSecondsElapsed ||&lt;br /&gt;
|-&lt;br /&gt;
| 136 || [19.0.0+] GetNintendoAccountUserResourceCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 140 || GetNetworkServiceLicenseCache || &lt;br /&gt;
|-&lt;br /&gt;
| 141 || RefreshNetworkServiceLicenseCacheAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 142 || RefreshNetworkServiceLicenseCacheAsyncIfSecondsElapsed || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 143 || [15.0.0+] GetNetworkServiceLicenseCacheEx ||&lt;br /&gt;
|-&lt;br /&gt;
| 150 || CreateAuthorizationRequest || Returns an [[#IAuthorizationRequest]].&lt;br /&gt;
|-&lt;br /&gt;
| 151 || [22.5.0+] || &lt;br /&gt;
|-&lt;br /&gt;
| 152 || [22.5.0+] || &lt;br /&gt;
|-&lt;br /&gt;
| 153 || [22.5.0+] || &lt;br /&gt;
|-&lt;br /&gt;
| 160 || [15.0.0+] RequiresUpdateNetworkServiceAccountIdTokenCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 161 || [16.0.0+] RequireReauthenticationOfNetworkServiceAccount ||&lt;br /&gt;
|-&lt;br /&gt;
| 180 || [18.0.0-19.0.1] GetRequestForNintendoAccountReauthentication ||&lt;br /&gt;
|-&lt;br /&gt;
| 181 || [20.0.0+] CreateProcedureToReauthenticateNintendoAccount ||&lt;br /&gt;
|-&lt;br /&gt;
| 182 || [20.0.0+] ResumeProcedureToReauthenticateNintendoAccount ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IFloatingRegistrationRequest ==&lt;br /&gt;
This is &amp;quot;nn::account::baas::IFloatingRegistrationRequest&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
Added with [3.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetSessionId ||&lt;br /&gt;
|-&lt;br /&gt;
| 12 || GetAccountId ||&lt;br /&gt;
|-&lt;br /&gt;
| 13 || GetLinkedNintendoAccountId ||&lt;br /&gt;
|-&lt;br /&gt;
| 14 || GetNickname ||&lt;br /&gt;
|-&lt;br /&gt;
| 15 || GetProfileImage ||&lt;br /&gt;
|-&lt;br /&gt;
| 16 || [18.0.0+] GetProfileLargeImage ||&lt;br /&gt;
|-&lt;br /&gt;
| 21 || LoadIdTokenCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 100 || RegisterUser ([1.0.0-3.0.2] RegisterAsync) || [1.0.0-3.0.2] Used to return an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 101 || RegisterUserWithUid ([1.0.0-3.0.2] RegisterWithUidAsync) || [1.0.0-3.0.2] Used to return an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 102 || [4.0.0+] RegisterNetworkServiceAccountAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 103 || [4.0.0+] RegisterNetworkServiceAccountWithUidAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 110 || SetSystemProgramIdentification ||&lt;br /&gt;
|-&lt;br /&gt;
| 111 || EnsureIdTokenCacheAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IAdministrator ==&lt;br /&gt;
This is &amp;quot;nn::account::baas::IAdministrator&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || CheckAvailability ||&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GetAccountId ||&lt;br /&gt;
|-&lt;br /&gt;
| 2 || EnsureIdTokenCacheAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [19.0.0+] LoadIdTokenCacheDeprecated ([1.0.0-18.1.0] LoadIdTokenCache) ||&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [19.0.0+] LoadIdTokenCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 100 || SetSystemProgramIdentification ||&lt;br /&gt;
|-&lt;br /&gt;
| 101 || [7.0.0+] RefreshNotificationTokenAsync&lt;br /&gt;
|-&lt;br /&gt;
| 110 || [4.0.0+] GetServiceEntryRequirementCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 111 || [4.0.0+] InvalidateServiceEntryRequirementCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 112 || [4.0.0-6.2.0] InvalidateTokenCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 113 || [6.1.0+] GetServiceEntryRequirementCacheForOnlinePlay || Takes a total of 0x8-bytes of input, returns a total of 0x4-bytes of output.&lt;br /&gt;
|-&lt;br /&gt;
| 120 || GetNintendoAccountId ||&lt;br /&gt;
|-&lt;br /&gt;
| 121 || [9.0.0+] CalculateNintendoAccountAuthenticationFingerprint ||&lt;br /&gt;
|-&lt;br /&gt;
| 130 || GetNintendoAccountUserResourceCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 131 || RefreshNintendoAccountUserResourceCacheAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 132 || RefreshNintendoAccountUserResourceCacheAsyncIfSecondsElapsed || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 133 || [9.0.0+] GetNintendoAccountVerificationUrlCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 134 || [9.0.0+] RefreshNintendoAccountVerificationUrlCacheAsync ||&lt;br /&gt;
|-&lt;br /&gt;
| 135 || [9.0.0+] RefreshNintendoAccountVerificationUrlCacheAsyncIfSecondsElapsed ||&lt;br /&gt;
|-&lt;br /&gt;
| 136 || [19.0.0+] GetNintendoAccountUserResourceCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 140 || [5.0.0+] GetNetworkServiceLicenseCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 141 || [5.0.0+] RefreshNetworkServiceLicenseCacheAsync ||&lt;br /&gt;
|-&lt;br /&gt;
| 142 || [5.0.0+] RefreshNetworkServiceLicenseCacheAsyncIfSecondsElapsed ||&lt;br /&gt;
|-&lt;br /&gt;
| 143 || [15.0.0+] GetNetworkServiceLicenseCacheEx ||&lt;br /&gt;
|-&lt;br /&gt;
| 150 || CreateAuthorizationRequest || Returns an [[#IAuthorizationRequest]].&lt;br /&gt;
|-&lt;br /&gt;
| 151 || [22.5.0+] || &lt;br /&gt;
|-&lt;br /&gt;
| 152 || [22.5.0+] || &lt;br /&gt;
|-&lt;br /&gt;
| 153 || [22.5.0+] || &lt;br /&gt;
|-&lt;br /&gt;
| 160 || [15.0.0+] RequiresUpdateNetworkServiceAccountIdTokenCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 161 || [16.0.0+] RequireReauthenticationOfNetworkServiceAccount ||&lt;br /&gt;
|-&lt;br /&gt;
| 180 || [18.0.0-19.0.1] GetRequestForNintendoAccountReauthentication ||&lt;br /&gt;
|-&lt;br /&gt;
| 181 || [20.0.0+] CreateProcedureToReauthenticateNintendoAccount ||&lt;br /&gt;
|-&lt;br /&gt;
| 182 || [20.0.0+] ResumeProcedureToReauthenticateNintendoAccount ||&lt;br /&gt;
|-&lt;br /&gt;
| 200 || IsRegistered ||&lt;br /&gt;
|-&lt;br /&gt;
| 201 || RegisterAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 202 || UnregisterAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 203 || DeleteRegistrationInfoLocally ||&lt;br /&gt;
|-&lt;br /&gt;
| 204 || [19.0.0-19.0.1] UnregisterDeviceAsync ||&lt;br /&gt;
|-&lt;br /&gt;
| 220 || SynchronizeProfileAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 221 || UploadProfileAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 222 || SynchronizeProfileAsyncIfSecondsElapsed || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 223 || [19.0.0+] DownloadProfileAsync ||&lt;br /&gt;
|-&lt;br /&gt;
| 250 || IsLinkedWithNintendoAccount ||&lt;br /&gt;
|-&lt;br /&gt;
| 251 || CreateProcedureToLinkWithNintendoAccount || Returns an [[#IOAuthProcedureForNintendoAccountLinkage]].&lt;br /&gt;
|-&lt;br /&gt;
| 252 || ResumeProcedureToLinkWithNintendoAccount || Returns an [[#IOAuthProcedureForNintendoAccountLinkage]].&lt;br /&gt;
|-&lt;br /&gt;
| 255 || CreateProcedureToUpdateLinkageStateOfNintendoAccount || Returns an [[#IOAuthProcedure]].&lt;br /&gt;
|-&lt;br /&gt;
| 256 || ResumeProcedureToUpdateLinkageStateOfNintendoAccount || Returns an [[#IOAuthProcedure]].&lt;br /&gt;
|-&lt;br /&gt;
| 260 || [3.0.0+] CreateProcedureToLinkNnidWithNintendoAccount || Returns an [[#IOAuthProcedure]].&lt;br /&gt;
|-&lt;br /&gt;
| 261 || [3.0.0+] ResumeProcedureToLinkNnidWithNintendoAccount || Returns an [[#IOAuthProcedure]].&lt;br /&gt;
|-&lt;br /&gt;
| 280 || ProxyProcedureToAcquireApplicationAuthorizationForNintendoAccount || Returns an [[#IOAuthProcedure]].&lt;br /&gt;
|-&lt;br /&gt;
| 290 || [8.0.0+] GetRequestForNintendoAccountUserResourceView || &lt;br /&gt;
|-&lt;br /&gt;
| 300 || [6.0.0+] TryRecoverNintendoAccountUserStateAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 400 || [6.1.0+] IsServiceEntryRequirementCacheRefreshRequiredForOnlinePlay || Takes a total of 0x8-bytes of input, returns an output u8.&lt;br /&gt;
|-&lt;br /&gt;
| 401 || [6.1.0+] RefreshServiceEntryRequirementCacheForOnlinePlayAsync || Takes a total of 0x8-bytes of input, returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 900 || [9.0.0+] GetAuthenticationInfoForWin ||&lt;br /&gt;
|-&lt;br /&gt;
| 901 || [9.0.0+] ImportAsyncForWin ||&lt;br /&gt;
|-&lt;br /&gt;
| 997 || DebugUnlinkNintendoAccountAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 998 || DebugSetAvailabilityErrorDetail ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IAuthorizationRequest ==&lt;br /&gt;
This is &amp;quot;nn::account::nas::IAuthorizationRequest&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetSessionId ||&lt;br /&gt;
|-&lt;br /&gt;
| 10 || InvokeWithoutInteractionAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 19 || IsAuthorized ||&lt;br /&gt;
|-&lt;br /&gt;
| 20 || GetAuthorizationCode ||&lt;br /&gt;
|-&lt;br /&gt;
| 21 || GetIdToken ||&lt;br /&gt;
|-&lt;br /&gt;
| 22 || GetState ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IOAuthProcedure ==&lt;br /&gt;
This is &amp;quot;nn::account::http::IOAuthProcedure&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || PrepareAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GetRequest ||&lt;br /&gt;
|-&lt;br /&gt;
| 2 || ApplyResponse ||&lt;br /&gt;
|-&lt;br /&gt;
| 3 || ApplyResponseAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 10 || Suspend ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IOAuthProcedureForExternalNsa ==&lt;br /&gt;
This is &amp;quot;nn::account::nas::IOAuthProcedureForExternalNsa&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
Added with [3.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || PrepareAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GetRequest ||&lt;br /&gt;
|-&lt;br /&gt;
| 2 || ApplyResponse ||&lt;br /&gt;
|-&lt;br /&gt;
| 3 || ApplyResponseAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 10 || Suspend ||&lt;br /&gt;
|-&lt;br /&gt;
| 100 || GetAccountId ||&lt;br /&gt;
|-&lt;br /&gt;
| 101 || GetLinkedNintendoAccountId ||&lt;br /&gt;
|-&lt;br /&gt;
| 102 || GetNickname ||&lt;br /&gt;
|-&lt;br /&gt;
| 103 || GetProfileImage ||&lt;br /&gt;
|-&lt;br /&gt;
| 104 || [18.0.0+] GetProfileLargeImage ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IOAuthProcedureForNintendoAccountLinkage ==&lt;br /&gt;
This is &amp;quot;nn::account::nas::IOAuthProcedureForNintendoAccountLinkage&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || PrepareAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GetRequest ||&lt;br /&gt;
|-&lt;br /&gt;
| 2 || ApplyResponse ||&lt;br /&gt;
|-&lt;br /&gt;
| 3 || ApplyResponseAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 10 || Suspend ||&lt;br /&gt;
|-&lt;br /&gt;
| 100 || GetRequestWithTheme ||&lt;br /&gt;
|-&lt;br /&gt;
| 101 || IsNetworkServiceAccountReplaced ||&lt;br /&gt;
|-&lt;br /&gt;
| 199 || [2.0.0-5.1.0] GetUrlForIntroductionOfExtraMembership ||&lt;br /&gt;
|-&lt;br /&gt;
| 200 || [16.0.0+] ApplyAsyncWithAuthorizedToken ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== INotifier ==&lt;br /&gt;
This is &amp;quot;nn::account::detail::INotifier&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetSystemEvent&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IProfile ==&lt;br /&gt;
This is &amp;quot;nn::account::profile::IProfile&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#Get]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#GetBase]]&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [[#GetImageSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [[#LoadImage]]&lt;br /&gt;
|-&lt;br /&gt;
| 20 || [18.0.0+] GetLargeImageSize&lt;br /&gt;
|-&lt;br /&gt;
| 21 || [18.0.0+] LoadLargeImage&lt;br /&gt;
|-&lt;br /&gt;
| 30 || [18.0.0+] GetImageId&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Get ===&lt;br /&gt;
Takes an output type-0x1A buffer for [[#UserData]], returns an output [[#ProfileBase]].&lt;br /&gt;
&lt;br /&gt;
=== GetBase ===&lt;br /&gt;
No input, returns an output [[#ProfileBase]].&lt;br /&gt;
&lt;br /&gt;
=== GetImageSize ===&lt;br /&gt;
No input, returns an output u32 for the size of the image buffer.&lt;br /&gt;
&lt;br /&gt;
=== LoadImage === &lt;br /&gt;
Takes an output type-0x6 buffer, returns the same output u32 as [[#GetImageSize]].&lt;br /&gt;
&lt;br /&gt;
The output buffer contains the JPEG profile image icon. This is valid for both Miis and character icons.&lt;br /&gt;
&lt;br /&gt;
== IProfileEditor ==&lt;br /&gt;
This is &amp;quot;nn::account::profile::IProfileEditor&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#Get]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#GetBase]]&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [[#GetImageSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [[#LoadImage]]&lt;br /&gt;
|-&lt;br /&gt;
| 20 || [18.0.0+] GetLargeImageSize&lt;br /&gt;
|-&lt;br /&gt;
| 21 || [18.0.0+] LoadLargeImage&lt;br /&gt;
|-&lt;br /&gt;
| 30 || [18.0.0+] GetImageId&lt;br /&gt;
|-&lt;br /&gt;
| 100 || [[#Store]]&lt;br /&gt;
|-&lt;br /&gt;
| 101 || [[#StoreWithImage]]&lt;br /&gt;
|-&lt;br /&gt;
| 110 || [18.0.0+] StoreWithLargeImage&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Store ===&lt;br /&gt;
Takes a [[#ProfileBase]] and an input type-0x19 buffer for [[#UserData]].&lt;br /&gt;
&lt;br /&gt;
=== StoreWithImage ===&lt;br /&gt;
Takes a [[#ProfileBase]], an input type-0x19 buffer for [[#UserData]], and an input type-0x5 buffer.&lt;br /&gt;
&lt;br /&gt;
== IAsyncContext ==&lt;br /&gt;
This is &amp;quot;nn::account::detail::IAsyncContext&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetSystemEvent&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Cancel&lt;br /&gt;
|-&lt;br /&gt;
| 2 || HasDone&lt;br /&gt;
|-&lt;br /&gt;
| 3 || GetResult&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== ISessionObject ==&lt;br /&gt;
This is &amp;quot;nn::account::detail::ISessionObject&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 999 || Dummy&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= acc:u0 =&lt;br /&gt;
This is &amp;quot;nn::account::IAccountServiceForApplication&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
[13.0.0+] This was moved from [[Account_services|account]].&lt;br /&gt;
&lt;br /&gt;
This is only available when the output from [[Process_Manager_services|pm:bm]] GetBootMode is Normal/Maintenance.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetUserCount ||&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GetUserExistence ||&lt;br /&gt;
|-&lt;br /&gt;
| 2 || ListAllUsers ||&lt;br /&gt;
|-&lt;br /&gt;
| 3 || ListOpenUsers ||&lt;br /&gt;
|-&lt;br /&gt;
| 4 || GetLastOpenedUser ||&lt;br /&gt;
|-&lt;br /&gt;
| 5 || GetProfile || Takes an input userID, returns an [[#IProfile]].&lt;br /&gt;
|-&lt;br /&gt;
| 6 || [3.0.0+] GetProfileDigest ||&lt;br /&gt;
|-&lt;br /&gt;
| 50 || [[#IsUserRegistrationRequestPermitted]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 51 || TrySelectUserWithoutInteractionDeprecated ([1.0.0-18.1.0] [[#TrySelectUserWithoutInteraction]]) ||&lt;br /&gt;
|-&lt;br /&gt;
| 52 || [19.0.0+] TrySelectUserWithoutInteraction ||&lt;br /&gt;
|-&lt;br /&gt;
| 60 || [5.0.0-5.1.0] ListOpenContextStoredUsers ||&lt;br /&gt;
|-&lt;br /&gt;
| 99 || [6.0.0+] DebugActivateOpenContextRetention || No input, returns an [[#ISessionObject]].&lt;br /&gt;
|-&lt;br /&gt;
| 100 || [[#InitializeApplicationInfoV0]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 101 || GetBaasAccountManagerForApplication || Takes an input userID, returns an [[#IManagerForApplication]].&lt;br /&gt;
|-&lt;br /&gt;
| 102 || AuthenticateApplicationAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 103 || [4.0.0+] CheckNetworkServiceAvailabilityAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 110 || StoreSaveDataThumbnail ||&lt;br /&gt;
|-&lt;br /&gt;
| 111 || ClearSaveDataThumbnail ||&lt;br /&gt;
|-&lt;br /&gt;
| 120 || CreateGuestLoginRequest || Returns an [[#IGuestLoginRequest]].&lt;br /&gt;
|-&lt;br /&gt;
| 130 || [5.0.0+] LoadOpenContext ||&lt;br /&gt;
|-&lt;br /&gt;
| 131 || [6.0.0+] ListOpenContextStoredUsers || &lt;br /&gt;
|-&lt;br /&gt;
| 140 || [6.0.0+] [[#InitializeApplicationInfoV1]] || &lt;br /&gt;
|-&lt;br /&gt;
| 141 || [6.0.0+] ListQualifiedUsers || &lt;br /&gt;
|-&lt;br /&gt;
| 150 || [6.0.0+] IsUserAccountSwitchLocked || &lt;br /&gt;
|-&lt;br /&gt;
| 160 || [13.0.0+] InitializeApplicationInfoV2 || &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
InitializeApplicationInfo* is used by the user-process during service init.&lt;br /&gt;
&lt;br /&gt;
== InitializeApplicationInfoV0 ==&lt;br /&gt;
Takes a PID and an input u64 pid_placeholder, no output.&lt;br /&gt;
&lt;br /&gt;
== InitializeApplicationInfoV1 ==&lt;br /&gt;
Takes a PID and an input u64 pid_placeholder, no output.&lt;br /&gt;
&lt;br /&gt;
== IGuestLoginRequest ==&lt;br /&gt;
This is &amp;quot;nn::account::baas::IGuestLoginRequest&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetSessionId&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [1.0.0-2.3.0] &lt;br /&gt;
|-&lt;br /&gt;
| 12 || GetAccountId&lt;br /&gt;
|-&lt;br /&gt;
| 13 || GetLinkedNintendoAccountId&lt;br /&gt;
|-&lt;br /&gt;
| 14 || GetNickname&lt;br /&gt;
|-&lt;br /&gt;
| 15 || GetProfileImage&lt;br /&gt;
|-&lt;br /&gt;
| 16 || [18.0.0+] GetProfileLargeImage&lt;br /&gt;
|-&lt;br /&gt;
| 21 || [3.0.0+] LoadIdTokenCache&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IManagerForApplication ==&lt;br /&gt;
This is &amp;quot;nn::account::baas::IManagerForApplication&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || CheckAvailability ||&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GetAccountId ||&lt;br /&gt;
|-&lt;br /&gt;
| 2 || EnsureIdTokenCacheAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 3 || LoadIdTokenCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 130 || GetNintendoAccountUserResourceCacheForApplication ||&lt;br /&gt;
|-&lt;br /&gt;
| 150 || CreateAuthorizationRequest || Returns an [[#IAuthorizationRequest]].&lt;br /&gt;
|-&lt;br /&gt;
| 160 || [5.0.0+] StoreOpenContext ||&lt;br /&gt;
|-&lt;br /&gt;
| 170 || [13.0.0+] EnsureIdTokenCacheForOnlinePlayAsync ([6.0.0-12.1.0] LoadNetworkServiceLicenseKindAsync) || No input, returns an [[#IAsyncContextForLoginForOnlinePlay]] ([6.0.0-12.1.0] [[#IAsyncNetworkServiceLicenseKindContext]]).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IAsyncNetworkServiceLicenseKindContext ==&lt;br /&gt;
This is &amp;quot;nn::account::detail::IAsyncNetworkServiceLicenseKindContext&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [6.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetSystemEvent || &lt;br /&gt;
|-&lt;br /&gt;
| 1 || Cancel || &lt;br /&gt;
|-&lt;br /&gt;
| 2 || HasDone || &lt;br /&gt;
|-&lt;br /&gt;
| 3 || GetResult || &lt;br /&gt;
|-&lt;br /&gt;
| 100 || GetNetworkServiceLicenseKind || &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IAsyncContextForLoginForOnlinePlay ==&lt;br /&gt;
This is &amp;quot;nn::account::baas::IAsyncContextForLoginForOnlinePlay&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [13.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetSystemEvent || &lt;br /&gt;
|-&lt;br /&gt;
| 1 || Cancel || &lt;br /&gt;
|-&lt;br /&gt;
| 2 || HasDone || &lt;br /&gt;
|-&lt;br /&gt;
| 3 || GetResult || &lt;br /&gt;
|-&lt;br /&gt;
| 100 || GetNetworkServiceLicenseInfoForOnlinePlay || &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= acc:u1 =&lt;br /&gt;
This is &amp;quot;nn::account::IAccountServiceForSystemService&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
[13.0.0+] This was moved from [[Account_services|account]].&lt;br /&gt;
&lt;br /&gt;
This is only available when the output from [[Process_Manager_services|pm:bm]] GetBootMode is Normal/Maintenance.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetUserCount ||&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GetUserExistence ||&lt;br /&gt;
|-&lt;br /&gt;
| 2 || ListAllUsers ||&lt;br /&gt;
|-&lt;br /&gt;
| 3 || ListOpenUsers ||&lt;br /&gt;
|-&lt;br /&gt;
| 4 || GetLastOpenedUser ||&lt;br /&gt;
|-&lt;br /&gt;
| 5 || GetProfile || Returns an [[#IProfile]].&lt;br /&gt;
|-&lt;br /&gt;
| 6 || [3.0.0+] GetProfileDigest ||&lt;br /&gt;
|-&lt;br /&gt;
| 50 || [[#IsUserRegistrationRequestPermitted]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 51 || TrySelectUserWithoutInteractionDeprecated ([1.0.0-18.1.0] [[#TrySelectUserWithoutInteraction]]) ||&lt;br /&gt;
|-&lt;br /&gt;
| 52 || [19.0.0+] TrySelectUserWithoutInteraction ||&lt;br /&gt;
|-&lt;br /&gt;
| 60 || [5.0.0-5.1.0] ListOpenContextStoredUsers ||&lt;br /&gt;
|-&lt;br /&gt;
| 99 || [6.0.0+] DebugActivateOpenContextRetention || No input, returns an [[#ISessionObject]].&lt;br /&gt;
|-&lt;br /&gt;
| 100 || GetUserRegistrationNotifier || Returns an [[#INotifier]].&lt;br /&gt;
|-&lt;br /&gt;
| 101 || GetUserStateChangeNotifier || Returns an [[#INotifier]].&lt;br /&gt;
|-&lt;br /&gt;
| 102 || GetBaasAccountManagerForSystemService || Returns an [[#IManagerForSystemService]].&lt;br /&gt;
|-&lt;br /&gt;
| 103 || GetBaasUserAvailabilityChangeNotifier || Returns an [[#INotifier]].&lt;br /&gt;
|-&lt;br /&gt;
| 104 || GetProfileUpdateNotifier || Returns an [[#INotifier]].&lt;br /&gt;
|-&lt;br /&gt;
| 105 || [4.0.0+] CheckNetworkServiceAvailabilityAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 106 || [9.0.0+] GetProfileSyncNotifier ||&lt;br /&gt;
|-&lt;br /&gt;
| 110 || StoreSaveDataThumbnail ||&lt;br /&gt;
|-&lt;br /&gt;
| 111 || ClearSaveDataThumbnail ||&lt;br /&gt;
|-&lt;br /&gt;
| 112 || LoadSaveDataThumbnail ||&lt;br /&gt;
|-&lt;br /&gt;
| 113 || [5.0.0+] GetSaveDataThumbnailExistence ||&lt;br /&gt;
|-&lt;br /&gt;
| 120 || [10.0.0+] ListOpenUsersInApplication ||&lt;br /&gt;
|-&lt;br /&gt;
| 130 || [6.0.0+] ActivateOpenContextRetention || Takes a total of 0x8-bytes of input, returns an [[#ISessionObject]].&lt;br /&gt;
|-&lt;br /&gt;
| 140 || [6.0.0+] ListQualifiedUsers || &lt;br /&gt;
|-&lt;br /&gt;
| 150 || [10.0.0-10.2.0] AuthenticateApplicationAsync ||&lt;br /&gt;
|-&lt;br /&gt;
| 151 || [12.0.0+] EnsureSignedDeviceIdentifierCacheForNintendoAccountAsync || &lt;br /&gt;
|-&lt;br /&gt;
| 152 || [12.0.0+] LoadSignedDeviceIdentifierCacheForNintendoAccount ||&lt;br /&gt;
|-&lt;br /&gt;
| 170 || [13.0.0+] GetNasOp2MembershipStateChangeNotifier ||&lt;br /&gt;
|-&lt;br /&gt;
| 190 || [1.0.0-9.2.0] GetUserLastOpenedApplication ||&lt;br /&gt;
|-&lt;br /&gt;
| 191 || [7.0.0-19.0.1] UpdateNotificationReceiverInfo ([5.0.0-5.1.0] ActivateOpenContextHolder) ||&lt;br /&gt;
|-&lt;br /&gt;
| 401 || [18.0.0+] GetPinCodeLength ||&lt;br /&gt;
|-&lt;br /&gt;
| 402 || [18.0.0-19.0.1] GetPinCode ||&lt;br /&gt;
|-&lt;br /&gt;
| 403 || [20.0.0+] GetPinCodeParity ||&lt;br /&gt;
|-&lt;br /&gt;
| 404 || [20.0.0+] VerifyPinCode ||&lt;br /&gt;
|-&lt;br /&gt;
| 405 || [20.0.0+] IsPinCodeVerificationForbidden ||&lt;br /&gt;
|-&lt;br /&gt;
| 997 || [3.0.0+] DebugInvalidateTokenCacheForUser ||&lt;br /&gt;
|-&lt;br /&gt;
| 998 || DebugSetUserStateClose ||&lt;br /&gt;
|-&lt;br /&gt;
| 999 || DebugSetUserStateOpen ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[10.0.0+] DebugSetUserStateClose/DebugSetUserStateOpen now takes an additional 8-bytes of input. &lt;br /&gt;
&lt;br /&gt;
== IOAuthProcedureForUserRegistration ==&lt;br /&gt;
This is &amp;quot;nn::account::nas::IOAuthProcedureForUserRegistration&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [8.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || PrepareAsync || No input, returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GetRequest || &lt;br /&gt;
|-&lt;br /&gt;
| 2 || ApplyResponse || &lt;br /&gt;
|-&lt;br /&gt;
| 3 || ApplyResponseAsync || Takes a type-0x9 input buffer, returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 10 || Suspend || &lt;br /&gt;
|-&lt;br /&gt;
| 100 || GetAccountId || &lt;br /&gt;
|-&lt;br /&gt;
| 101 || GetLinkedNintendoAccountId || &lt;br /&gt;
|-&lt;br /&gt;
| 102 || GetNickname || &lt;br /&gt;
|-&lt;br /&gt;
| 103 || GetProfileImage || &lt;br /&gt;
|-&lt;br /&gt;
| 104 || [18.0.0+] GetProfileLargeImage || &lt;br /&gt;
|-&lt;br /&gt;
| 110 || RegisterUserAsync || No input, returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 111 || GetUid || &lt;br /&gt;
|-&lt;br /&gt;
| 200 || [17.0.0+] ApplyResponseForUserCreationAsync || &lt;br /&gt;
|-&lt;br /&gt;
| 205 || [17.0.0+] SuspendAfterApplyResponse || &lt;br /&gt;
|-&lt;br /&gt;
| 210 || [17.0.0+] IsProfileAvailable || &lt;br /&gt;
|-&lt;br /&gt;
| 220 || [17.0.0+] RegisterUserAsyncWithoutProfile || &lt;br /&gt;
|-&lt;br /&gt;
| 221 || [17.0.0+] RegisterUserWithProfileAsync || &lt;br /&gt;
|-&lt;br /&gt;
| 230 || [18.0.0+] RegisterUserWithLargeImageProfileAsync || &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationRecord =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationRecord&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0&lt;br /&gt;
| 0x8&lt;br /&gt;
| [[NCM_services#ApplicationId|Id]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x8&lt;br /&gt;
| 0x1&lt;br /&gt;
| [[#ApplicationEvent|LastEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x9&lt;br /&gt;
| 0x1&lt;br /&gt;
| Attributes&lt;br /&gt;
|-&lt;br /&gt;
| 0xA&lt;br /&gt;
| 0x6&lt;br /&gt;
| Reserved&lt;br /&gt;
|-&lt;br /&gt;
| 0x10&lt;br /&gt;
| 0x8&lt;br /&gt;
| LastUpdated&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationEvent =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationEvent&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || Launched&lt;br /&gt;
|-&lt;br /&gt;
| 1 || LocalInstalled&lt;br /&gt;
|-&lt;br /&gt;
| 2 || DownloadStarted&lt;br /&gt;
|-&lt;br /&gt;
| 3 || GameCardInserted&lt;br /&gt;
|-&lt;br /&gt;
| 4 || Touched&lt;br /&gt;
|-&lt;br /&gt;
| 5 || &lt;br /&gt;
|-&lt;br /&gt;
| 6 || &lt;br /&gt;
|-&lt;br /&gt;
| 7 || &lt;br /&gt;
|-&lt;br /&gt;
| 8 || &lt;br /&gt;
|-&lt;br /&gt;
| 9 || &lt;br /&gt;
|-&lt;br /&gt;
| 10 || &lt;br /&gt;
|-&lt;br /&gt;
| 11 || &lt;br /&gt;
|-&lt;br /&gt;
| 12 || &lt;br /&gt;
|-&lt;br /&gt;
| 13 || &lt;br /&gt;
|-&lt;br /&gt;
| 14 || &lt;br /&gt;
|-&lt;br /&gt;
| 15 || &lt;br /&gt;
|-&lt;br /&gt;
| 16 || &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationControlSource =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationControlSource&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0&lt;br /&gt;
| CacheOnly&lt;br /&gt;
|-&lt;br /&gt;
| 1&lt;br /&gt;
| Storage&lt;br /&gt;
|-&lt;br /&gt;
| 2&lt;br /&gt;
| StorageOnly&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationContentMetaStatus =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationContentMetaStatus&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0&lt;br /&gt;
| 0x1&lt;br /&gt;
| [[NCM_services#ContentMetaType|Type]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x1&lt;br /&gt;
| 0x1&lt;br /&gt;
| [[NCM_services#StorageId|InstalledStorage]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x2&lt;br /&gt;
| 0x1&lt;br /&gt;
| [[#ContentMetaRightsCheck|RightsCheck]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x3&lt;br /&gt;
| 0x1&lt;br /&gt;
| Reserved&lt;br /&gt;
|-&lt;br /&gt;
| 0x4&lt;br /&gt;
| 0x4&lt;br /&gt;
| Version&lt;br /&gt;
|-&lt;br /&gt;
| 0x8&lt;br /&gt;
| 0x8&lt;br /&gt;
| [[NCM_services#ApplicationId|Id]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ContentMetaRightsCheck =&lt;br /&gt;
This is &amp;quot;nn::ns::ContentMetaRightsCheck&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0&lt;br /&gt;
| NotChecked&lt;br /&gt;
|-&lt;br /&gt;
| 1&lt;br /&gt;
| NotNeeded&lt;br /&gt;
|-&lt;br /&gt;
| 2&lt;br /&gt;
| CommonRights&lt;br /&gt;
|-&lt;br /&gt;
| 3&lt;br /&gt;
| PersonalizedRights&lt;br /&gt;
|-&lt;br /&gt;
| 4&lt;br /&gt;
| NoRights&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= VersionListData =&lt;br /&gt;
This is &amp;quot;nn::ns::VersionListData&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
= ApplicationUpdateInfo =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationUpdateInfo&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || UpToDate&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Updatable&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationOccupiedSize =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationOccupiedSize&amp;quot;. This is a 0x80-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x20 * 4 || Array of [[#ApplicationOccupiedSizeEntity]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationOccupiedSizeEntity =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationOccupiedSizeEntity&amp;quot;. This is a 0x20-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x1 || [[NCM_services#StorageId|StorageId]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x1 || 0x7 || Reserved&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x8 || AppSize&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x8 || PatchSize&lt;br /&gt;
|-&lt;br /&gt;
| 0x18 || 0x8 || AocSize&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ProgressForDeleteUserSaveDataAll =&lt;br /&gt;
This is &amp;quot;nn::ns::detail::ProgressForDeleteUserSaveDataAll&amp;quot;. This is a 0x28-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x8 || StartedAt&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x4 || Count&lt;br /&gt;
|-&lt;br /&gt;
| 0xC || 0x4 || Reserved&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x8 || SizeInBytes&lt;br /&gt;
|-&lt;br /&gt;
| 0x18 || 0x1 || IsSystem&lt;br /&gt;
|-&lt;br /&gt;
| 0x19 || 0x7 || Reserved&lt;br /&gt;
|-&lt;br /&gt;
| 0x20 || 0x8 || ApplicationId&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationViewDeprecated =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationViewDeprecated&amp;quot;. This is a 0x40-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x8 || [[NCM_services#ApplicationId|ApplicationId]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x4 || Version&lt;br /&gt;
|-&lt;br /&gt;
| 0xC || 0x4 || [[#ApplicationViewFlag|Flag]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x18 || [[#ApplicationDownloadProgress|Progress]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x28 || 0x18 || [[#ApplicationApplyDeltaProgress|ApplyProgress]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
This is converted from [[#ApplicationView]] by [[#GetApplicationViewDeprecated]] on newer system-versions as follows:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x20 || Same as [[#ApplicationView]] +0x0.&lt;br /&gt;
|-&lt;br /&gt;
| 0x20 || 0x4 || Same as [[#ApplicationView]] +0x20.&lt;br /&gt;
|-&lt;br /&gt;
| 0x24 || 0x2 || Same as [[#ApplicationView]] +0x24.&lt;br /&gt;
|-&lt;br /&gt;
| 0x26 || 0x2 || Cleared to 0.&lt;br /&gt;
|-&lt;br /&gt;
| 0x28 || 0x10 || Same as [[#ApplicationView]] +0x30.&lt;br /&gt;
|-&lt;br /&gt;
| 0x38 || 0x4 || Same as [[#ApplicationView]] +0x40.&lt;br /&gt;
|-&lt;br /&gt;
| 0x3C || 0x1 || Same as [[#ApplicationView]] +0x44.&lt;br /&gt;
|-&lt;br /&gt;
| 0x3D || 0x2 || Cleared to 0.&lt;br /&gt;
|-&lt;br /&gt;
| 0x3F || 0x1 || Cleared to 0.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationViewFlag =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationViewFlag&amp;quot;. This is a 32-bit flag.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Bit&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 1&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 2&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 3&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 4&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 5&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 6&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 7&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 8&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 9&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 10&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 11&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 12&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 13&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 14&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 15&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 16&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 17&lt;br /&gt;
| &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationDownloadProgress =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationDownloadProgress&amp;quot;. This is a 0x18-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x8 || Downloaded&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x8 || Total&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x4 || LastResult&lt;br /&gt;
|-&lt;br /&gt;
| 0x14 || 0x1 || [[#ApplicationDownloadState|State]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x15 || 0x3 || Reserved&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationApplyDeltaProgress =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationApplyDeltaProgress&amp;quot;. This is a 0x18-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x8 || Applied&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x8 || Total&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x4 || LastResult&lt;br /&gt;
|-&lt;br /&gt;
| 0x14 || 0x1 || [[#ApplicationApplyDeltaState|State]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x15 || 0x3 || Reserved&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationDownloadState =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationDownloadState&amp;quot;. This is an u8.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || Runnable&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Suspended&lt;br /&gt;
|-&lt;br /&gt;
| 2 || NotEnoughSpace&lt;br /&gt;
|-&lt;br /&gt;
| 3 || Fatal&lt;br /&gt;
|-&lt;br /&gt;
| 4 || Finished&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationApplyDeltaState =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationApplyDeltaState&amp;quot;. This is an u8.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || Applying&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Suspended&lt;br /&gt;
|-&lt;br /&gt;
| 2 || NotEnoughSpace&lt;br /&gt;
|-&lt;br /&gt;
| 3 || Fatal&lt;br /&gt;
|-&lt;br /&gt;
| 4 || NoTask&lt;br /&gt;
|-&lt;br /&gt;
| 5 || WaitApply&lt;br /&gt;
|-&lt;br /&gt;
| 6 || Applied&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationView =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationView&amp;quot;. This is a 0x50-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x8 || [[NCM_services#ApplicationId|ApplicationId]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x4 || ?&lt;br /&gt;
|-&lt;br /&gt;
| 0xC || 0x4 || Flags&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x40 || ?&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationViewWithPromotionInfo =&lt;br /&gt;
This is a 0x70-byte struct.&lt;br /&gt;
&lt;br /&gt;
[20.0.0+] This is a 0x78-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x50 || [[#ApplicationView]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x50 || 0x20 || [[#PromotionInfo]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= PromotionInfo =&lt;br /&gt;
This is a 0x20-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x8 || PosixTime start_timestamp.&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x8 || PosixTime end_timestamp.&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x8 || Remaining time until the promotion ends, in nanoseconds ({end_timestamp - current_time} converted to nanoseconds).&lt;br /&gt;
|-&lt;br /&gt;
| 0x18 || 0x4 || Not set, left at zero.&lt;br /&gt;
|-&lt;br /&gt;
| 0x1C || 0x1 || Flags. Bit0: whether the PromotionInfo is valid (including bit1). Bit1 clear: u64 +0x10 is set.&lt;br /&gt;
|-&lt;br /&gt;
| 0x1D || 0x3 || Padding&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationResourceType =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationResourceType&amp;quot;. This is an u8.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || ApplicationResource&lt;br /&gt;
|-&lt;br /&gt;
| 1 || MicroApplicationResource&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationErrorCodeCategory =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationErrorCodeCategory&amp;quot;. This is an u64.&lt;br /&gt;
&lt;br /&gt;
= NoDownloadRightsErrorResolution =&lt;br /&gt;
This is &amp;quot;nn::ns::NoDownloadRightsErrorResolution&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
= BackgroundNetworkUpdateState =&lt;br /&gt;
This is &amp;quot;nn::ns::BackgroundNetworkUpdateState&amp;quot;. This is an u8.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || None&lt;br /&gt;
|-&lt;br /&gt;
| 1 || InProgress&lt;br /&gt;
|-&lt;br /&gt;
| 2 || Ready&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Similar to [[#HasDownloaded]], [[#GetBackgroundNetworkUpdateState]] uses [[NIM_services|nim]] ListSystemUpdateTask and [[NIM_services|nim]] GetSystemUpdateTaskInfo. When ListSystemUpdateTask successfully returns a task and GetSystemUpdateTaskInfo is successful, the output value is set to: &amp;lt;code&amp;gt;1 + *((u8*)(taskinfo+0) == 0x3&amp;lt;/code&amp;gt;. Otherwise, value=0.&lt;br /&gt;
&lt;br /&gt;
[[#GetBackgroundNetworkUpdateState]] always returns Result 0, however this will assert if GetSystemUpdateTaskInfo fails with ret!=0x3C89.&lt;br /&gt;
&lt;br /&gt;
= SystemUpdateProgress =&lt;br /&gt;
This is &amp;quot;nn::ns::SystemUpdateProgress&amp;quot;. This is a 0x10-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x8 || Loaded (this value can be larger than total_size when the async operation is finishing and when total_size is &amp;lt;=0, this current_size field may contain a progress value for when the total_size is not yet determined)&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x8 || Total (this field is only valid when &amp;gt;0)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Commands which have this as output will return 0 with the output cleared, when no task is available.&lt;br /&gt;
&lt;br /&gt;
= EulaDataPath =&lt;br /&gt;
This is &amp;quot;nn::ns::detail::EulaDataPath&amp;quot;. This is a 0x100-byte struct.&lt;br /&gt;
&lt;br /&gt;
This contains a file path.&lt;br /&gt;
&lt;br /&gt;
= SystemDeliveryInfo =&lt;br /&gt;
This is &amp;quot;nn::ns::SystemDeliveryInfo&amp;quot;. This is a 0x100-byte struct.&lt;br /&gt;
&lt;br /&gt;
Originally the SystemDeliveryInfo validation func verified that OldSystemUpdateId matched the installed SystemUpdate Id. [20.0.0+] The used (Old)SystemUpdateId as selected by SystemUpdateIdFlag must now match one of the Ids in [[System_Settings|system-setting]] &amp;lt;code&amp;gt;contents_delivery!acceptable_system_update_ids_string&amp;lt;/code&amp;gt; (replaces the previously mentioned installed-SystemUpdate check).&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x4 || SystemDeliveryProtocolVersion. Must be &amp;lt;= to and match [[System_Settings|system-setting]] &amp;lt;code&amp;gt;contents_delivery!system_delivery_protocol_version&amp;lt;/code&amp;gt;.&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || 0x4 || ApplicationDeliveryProtocolVersion. Loaded from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;contents_delivery!application_delivery_protocol_version&amp;lt;/code&amp;gt;. Unused by [[#RequestSendSystemUpdate]]/[[#RequestReceiveSystemUpdate]], besides HMAC validation.&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x1 || HasExFat. Unused by [[#RequestSendSystemUpdate]]/[[#RequestReceiveSystemUpdate]], besides HMAC validation.&lt;br /&gt;
|-&lt;br /&gt;
| 0x9 || 0x3 || Reserved.&lt;br /&gt;
|-&lt;br /&gt;
| 0xC || 0x4 || SystemUpdateVersion.&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x8 || OldSystemUpdateId. [20.0.0+] Always the NX Id: this is loaded from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;contents_delivery!old_system_update_id&amp;lt;/code&amp;gt;.&lt;br /&gt;
|-&lt;br /&gt;
| 0x18 || 0x1 || FirmwareVariationId. Used by [[#RequestSendSystemUpdate]]. Loaded from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;ns.systemupdate!firmware_variation&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;ns.systemupdate!t_firmware_variation&amp;lt;/code&amp;gt;, depending on the [[Settings_services|PlatformRegion]].&lt;br /&gt;
|-&lt;br /&gt;
| 0x19 || 0x1 || UpdatableFirmwareGroupId. Unused by [[#RequestSendSystemUpdate]]/[[#RequestReceiveSystemUpdate]], besides HMAC validation. Loaded from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;ns.systemupdate!updatable_firmware_group_id&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;ns.systemupdate!t_updatable_firmware_group_id&amp;lt;/code&amp;gt;, depending on the [[Settings_services|PlatformRegion]].&lt;br /&gt;
|-&lt;br /&gt;
| 0x1A || 0x1 || PlatformRegion (0x00 = Unknown/Global, 0x01 = China).&lt;br /&gt;
|-&lt;br /&gt;
| 0x1B || 0x1 || [20.0.0+] SystemDeliveryInfoPlatform. Loaded from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;ns.systemupdate!system_delivery_info_platform&amp;lt;/code&amp;gt;. Elsewhere this is compared against the sys-setting, etc.&lt;br /&gt;
|-&lt;br /&gt;
| 0x1C || 0x1 || [20.0.0+] SystemUpdateIdFlag. When non-zero, SystemUpdateId is used instead of OldSystemUpdateId. Always set to 0x1 by [[#GetSystemDeliveryInfo]] with [20.0.0+].&lt;br /&gt;
|-&lt;br /&gt;
| 0x1D || 0x3 || Padding&lt;br /&gt;
|-&lt;br /&gt;
| 0x20 || 0x8 || [20.0.0+] SystemUpdateId. See above. With [20.0.0+] [[#GetSystemDeliveryInfo]] now writes the Id here instead of OldSystemUpdateId (for the installed SystemUpdate). On S2 this is set to the Ounce Id.&lt;br /&gt;
|-&lt;br /&gt;
| 0x28 || 0xB8 || Reserved&lt;br /&gt;
|-&lt;br /&gt;
| 0xE0 || 0x20 || HMAC-SHA256 over the previous 0xE0-bytes.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationDeliveryInfo =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationDeliveryInfo&amp;quot;. This is a 0x100-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x4 || ApplicationDeliveryProtocolVersion. Loaded from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;contents_delivery!application_delivery_protocol_version&amp;lt;/code&amp;gt;. An error is thrown when [[System_Settings|system-setting]] &amp;lt;code&amp;gt;contents_delivery!application_delivery_protocol_version&amp;lt;/code&amp;gt; &amp;lt; version, or when [[System_Settings|system-setting]] &amp;lt;code&amp;gt;contents_delivery!acceptable_application_delivery_protocol_version&amp;lt;/code&amp;gt; &amp;gt; version.&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || 0x4 || Padding&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x8 || ApplicationId.&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x4 || ApplicationVersion.&lt;br /&gt;
|-&lt;br /&gt;
| 0x14 || 0x4 || RequiredApplicationVersion.&lt;br /&gt;
|-&lt;br /&gt;
| 0x18 || 0x4 || RequiredSystemVersion.&lt;br /&gt;
|-&lt;br /&gt;
| 0x1C || 0x4 || u32 bitmask &amp;lt;code&amp;gt;nn::ns::ApplicationDeliveryAttributeTag&amp;lt;/code&amp;gt;. [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]] sets this to the input u32. Bit30 and bit28 are additionally set, depending on [[NCM_services|ContentMetaType]] == Patch, etc.&lt;br /&gt;
|-&lt;br /&gt;
| 0x20 || 0x1 || [20.0.0+] [[NCM_services|ContentMetaPlatform]]. Loaded from [[NCM_services|ncm]] IContentMetaDatabase GetPlatform.&lt;br /&gt;
|-&lt;br /&gt;
| 0x21 || 0x1 || [20.0.0+] ProperProgramExists. Set to whether the bit for ProperProgramExists is set from [[NCM_services|ncm]] IContentMetaDatabase GetAttributes.&lt;br /&gt;
|-&lt;br /&gt;
| 0x22 || 0x1 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 0x23 || 0xBD || Reserved&lt;br /&gt;
|-&lt;br /&gt;
| 0xE0 || 0x20 || HMAC-SHA256 over the previous 0xE0-bytes. Uses a different key than [[#SystemDeliveryInfo]].&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= LatestSystemUpdate =&lt;br /&gt;
This is &amp;quot;nn::ns::LatestSystemUpdate&amp;quot;. This is an u8.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || UpToDate&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Downloaded&lt;br /&gt;
|-&lt;br /&gt;
| 2 || NeedsDownload&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ReceiveApplicationProgress =&lt;br /&gt;
This is &amp;quot;nn::ns::ReceiveApplicationProgress&amp;quot;. This is a 0x10-byte struct.&lt;br /&gt;
&lt;br /&gt;
= SendApplicationProgress =&lt;br /&gt;
This is &amp;quot;nn::ns::SendApplicationProgress&amp;quot;. This is a 0x10-byte struct.&lt;br /&gt;
&lt;br /&gt;
= ApplicationRightsOnClient =&lt;br /&gt;
This is a 0x20-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x8 || [[NCM_services#ApplicationId|ApplicationId]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x10 || [[Account_services#Uid|Uid]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x18 || 0x1 || Flags, [[qlaunch]] only uses bit0-bit4 and bit7.&lt;br /&gt;
|-&lt;br /&gt;
| 0x19 || 0x1 || Flags, [[qlaunch]] only uses bit0.&lt;br /&gt;
|-&lt;br /&gt;
| 0x1A || 0x6 || Unknown&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[[qlaunch]] only uses +0x18/+0x19 in this struct.&lt;br /&gt;
&lt;br /&gt;
= DownloadTaskStatus =&lt;br /&gt;
This is &amp;quot;nn::ns::DownloadTaskStatus&amp;quot;. This is a 0x20-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x10 || Uuid&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x8 || [[NCM_services#ApplicationId|ApplicationId]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x18 || 0x1 || [[#DownloadTaskStatusDetail|Detail]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x19 || 0x1 || NeedsCleanup&lt;br /&gt;
|-&lt;br /&gt;
| 0x1A || 0x2 || Reserved&lt;br /&gt;
|-&lt;br /&gt;
| 0x1C || 0x4 || Result&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= DownloadTaskStatusDetail =&lt;br /&gt;
This is &amp;quot;nn::ns::DownloadTaskStatusDetail&amp;quot;. This is an u8.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || Created&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Added&lt;br /&gt;
|-&lt;br /&gt;
| 2 || AlreadyExists&lt;br /&gt;
|-&lt;br /&gt;
| 3 || Failed&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationLaunchInfo =&lt;br /&gt;
This is a 0x40-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x8 || [[NCM_services#ApplicationId|ApplicationId]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x4 || Application version&lt;br /&gt;
|-&lt;br /&gt;
| 0xC || 0x4 || [[Process_Manager_services#LaunchFlags|LaunchFlags]], set to hard-coded value 0xB by [[#GetApplicationLaunchInfo]].&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x1 || Application [[NCM_services#StorageId|StorageId]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x11 || 0x1 || Update [[NCM_services#StorageId|StorageId]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x12 || 0x2E || &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= UserData =&lt;br /&gt;
This is a 0x80-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset || Size || Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x4? || ?&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || 0x4? || Icon ID. 0 = Mii, the rest are character icon IDs.&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x1? || Profile icon background color ID&lt;br /&gt;
|-&lt;br /&gt;
| 0x9 || 0x7 || ?&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x10 || Some ID related to the Mii? All zeros when a character icon is used.&lt;br /&gt;
|-&lt;br /&gt;
| 0x20 || 0x60 || Usually zeros?&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ProfileBase =&lt;br /&gt;
This is a 0x38-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset || Size || Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x10 || userID&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x8 || POSIX UTC timestamp, for last account edit.&lt;br /&gt;
|-&lt;br /&gt;
| 0x18 || 0x20 || UTF-8 Nickname. Official sw uses strncpy to copy this into another struct (&amp;lt;code&amp;gt;nn::account::Nickname&amp;lt;/code&amp;gt;), with a NUL-byte written after the copied data.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Uid =&lt;br /&gt;
This is &amp;quot;nn::account::Uid&amp;quot;. This is a 0x10-byte struct. This contains 2 u64s for the UserId.&lt;br /&gt;
&lt;br /&gt;
= Notes =&lt;br /&gt;
[[Process_Manager_services|pm:bm]] GetBootMode is used to determine whether aoc:u is available (see above). This value is also passed to thread &amp;quot;nn.ns.DelayedInitialization&amp;quot;, which calls various funcs depending on the BootMode in various cases.&lt;br /&gt;
&lt;br /&gt;
The &amp;quot;nn.ns.DelayedInitialization&amp;quot; thread uses BootMode as follows (this also handles various other initialization):&lt;br /&gt;
* Initializes [[NPNS_services|npns:s]] only for BootMode Normal/Maintenance.&lt;br /&gt;
* Initializes the hosted acc:* services and service [[Account_services|acc:su]] only for BootMode Normal/Maintenance.&lt;br /&gt;
* Calls a func only for BootMode Normal.&lt;br /&gt;
* Initializes [[ETicket_services|es]] and [[Shared_Database_services|avm]] only for BootMode Normal/Maintenance.&lt;br /&gt;
&lt;br /&gt;
The output of GetBootMode is also written into state. This same func later enters a code block when BootMode is Maintenance/SafeMode: various [[NCM_services|ncm]] cmds are used with input StorageId=BuiltInUser (VerifyContentMetaDatabase, VerifyContentStorage, ActivateContentMetaDatabase, ActivateContentStorage, InactivateContentMetaDatabase, InactivateContentStorage) and state fields are written. Then if the BootMode is Maintenance the savedata for [[Flash_Filesystem|ns_rightsid]] (0x800000000000004A) is deleted. Then 0 is returned. Otherwise for BootMode Normal it continues with various initialization, including gamecard handling which handles launching the gamecard title in certain conditions (this is the only time ns launches anything with pgl outside of service cmds).&lt;br /&gt;
&lt;br /&gt;
In the above block, InactivateContentMetaDatabase/InactivateContentStorage are only used if using ActivateContentMetaDatabase/ActivateContentStorage failed (error is only checked after using both cmds). If any of the ncm cmds prior to this fail, it will skip using the rest of the ncm cmds.&lt;br /&gt;
&lt;br /&gt;
[[Category:Services]]&lt;/div&gt;</summary>
		<author><name>Yellows8</name></author>
	</entry>
	<entry>
		<id>https://switchbrew.org/w/index.php?title=NS_services&amp;diff=14934</id>
		<title>NS services</title>
		<link rel="alternate" type="text/html" href="https://switchbrew.org/w/index.php?title=NS_services&amp;diff=14934"/>
		<updated>2026-08-09T16:19:04Z</updated>

		<summary type="html">&lt;p&gt;Yellows8: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= aoc:u =&lt;br /&gt;
This is &amp;quot;nn::aocsrv::detail::IAddOnContentManager&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This is only available when [[Process_Manager_services|pm:bm]] GetBootMode returns output 0 (Normal).&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [1.0.0-6.2.0] CountAddOnContentByApplicationId&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [1.0.0-6.2.0] ListAddOnContentByApplicationId&lt;br /&gt;
|-&lt;br /&gt;
| 2 || CountAddOnContent&lt;br /&gt;
|-&lt;br /&gt;
| 3 || ListAddOnContent&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [1.0.0-6.2.0] GetAddOnContentBaseIdByApplicationId&lt;br /&gt;
|-&lt;br /&gt;
| 5 || GetAddOnContentBaseId&lt;br /&gt;
|-&lt;br /&gt;
| 6 || [1.0.0-6.2.0] PrepareAddOnContentByApplicationId&lt;br /&gt;
|-&lt;br /&gt;
| 7 || PrepareAddOnContent&lt;br /&gt;
|-&lt;br /&gt;
| 8 || [4.0.0+] GetAddOnContentListChangedEvent&lt;br /&gt;
|-&lt;br /&gt;
| 9 || [10.0.0+] GetAddOnContentLostErrorCode&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [11.0.0+] GetAddOnContentListChangedEventWithProcessId&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [13.0.0+] NotifyMountAddOnContent&lt;br /&gt;
|-&lt;br /&gt;
| 12 || [13.0.0+] NotifyUnmountAddOnContent&lt;br /&gt;
|-&lt;br /&gt;
| 13 || [13.0.0+] IsAddOnContentMountedForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 50 || [13.0.0+] CheckAddOnContentMountStatus&lt;br /&gt;
|-&lt;br /&gt;
| 100 || [7.0.0+] [[#IPurchaseEventManager|CreateEcPurchasedEventManager]]&lt;br /&gt;
|-&lt;br /&gt;
| 101 || [9.0.0+] [[#IPurchaseEventManager|CreatePermanentEcPurchasedEventManager]]&lt;br /&gt;
|-&lt;br /&gt;
| 110 || [12.0.0+] [[#IContentsServiceManager|CreateContentsServiceManager]]&lt;br /&gt;
|-&lt;br /&gt;
| 200 || [13.1.0+] SetRequiredAddOnContentsOnContentsAvailabilityTransition&lt;br /&gt;
|-&lt;br /&gt;
| 300 || [16.0.0+] SetupHostAddOnContent&lt;br /&gt;
|-&lt;br /&gt;
| 301 || [16.0.0+] GetRegisteredAddOnContentPath&lt;br /&gt;
|-&lt;br /&gt;
| 302 || [16.0.0+] UpdateCachedList&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IPurchaseEventManager ==&lt;br /&gt;
This is &amp;quot;nn::ec::IPurchaseEventManager&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || SetDefaultDeliveryTarget&lt;br /&gt;
|-&lt;br /&gt;
| 1 || SetDeliveryTarget&lt;br /&gt;
|-&lt;br /&gt;
| 2 || GetPurchasedEventReadableHandle&lt;br /&gt;
|-&lt;br /&gt;
| 3 || PopPurchasedProductInfo&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [9.0.0+] PopPurchasedProductInfoWithUid&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IContentsServiceManager ==&lt;br /&gt;
This is &amp;quot;nn::ec::IContentsServiceManager&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [12.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [16.0.0+] RequestContentsAuthorizationTokenDeprecated ([12.0.0-15.0.1] [[#RequestContentsAuthorizationToken]])&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [16.0.0+] RequestContentsAuthorizationToken&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== RequestContentsAuthorizationToken ===&lt;br /&gt;
Takes a total of 0x50-bytes of input, a PID, a type-0x5 input buffer. Returns an [[#IAsyncData|IAsyncData]] and an output handle.&lt;br /&gt;
&lt;br /&gt;
== IAsyncData ==&lt;br /&gt;
This is &amp;quot;nn::ec::detail::IAsyncData&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [12.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetSize&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Get&lt;br /&gt;
|-&lt;br /&gt;
| 2 || Cancel&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ns:am =&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IApplicationManagerInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
[3.0.0+] This service was replaced by [[#ns:am2, ns:ec, ns:rid, ns:rt, ns:web, ns:ro, ns:sweb|ns:am2]].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#ListApplicationRecord]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GenerateApplicationRecordCount&lt;br /&gt;
|-&lt;br /&gt;
| 2 || GetApplicationRecordUpdateSystemEvent&lt;br /&gt;
|-&lt;br /&gt;
| 3 || GetApplicationView&lt;br /&gt;
|-&lt;br /&gt;
| 4 || DeleteApplicationEntity&lt;br /&gt;
|-&lt;br /&gt;
| 5 || DeleteApplicationCompletely&lt;br /&gt;
|-&lt;br /&gt;
| 6 || IsAnyApplicationEntityRedundant&lt;br /&gt;
|-&lt;br /&gt;
| 7 || DeleteRedundantApplicationEntity&lt;br /&gt;
|-&lt;br /&gt;
| 8 || IsApplicationEntityMovable&lt;br /&gt;
|-&lt;br /&gt;
| 9 || MoveApplicationEntity&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [[#CalculateApplicationOccupiedSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 16 || PushApplicationRecord&lt;br /&gt;
|-&lt;br /&gt;
| 17 || ListApplicationRecordContentMeta&lt;br /&gt;
|-&lt;br /&gt;
| 18 || CheckLaunchRights&lt;br /&gt;
|-&lt;br /&gt;
| 19 || [[#LaunchApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 21 || [[#GetApplicationContentPath]]&lt;br /&gt;
|-&lt;br /&gt;
| 22 || TerminateApplication&lt;br /&gt;
|-&lt;br /&gt;
| 23 || [2.0.0+] ResolveApplicationContentPath&lt;br /&gt;
|-&lt;br /&gt;
| 26 || BeginInstallApplication&lt;br /&gt;
|-&lt;br /&gt;
| 27 || DeleteApplicationRecord&lt;br /&gt;
|-&lt;br /&gt;
| 30 || RequestApplicationUpdateInfo&lt;br /&gt;
|-&lt;br /&gt;
| 31 || RequestUpdateApplication&lt;br /&gt;
|-&lt;br /&gt;
| 32 || CancelApplicationDownload&lt;br /&gt;
|-&lt;br /&gt;
| 33 || ResumeApplicationDownload&lt;br /&gt;
|-&lt;br /&gt;
| 34 || ClearTaskStatusList&lt;br /&gt;
|-&lt;br /&gt;
| 35 || UpdateVersionList&lt;br /&gt;
|-&lt;br /&gt;
| 36 || PushLaunchVersion&lt;br /&gt;
|-&lt;br /&gt;
| 37 || ListRequiredVersion&lt;br /&gt;
|-&lt;br /&gt;
| 38 || CheckApplicationLaunchVersion&lt;br /&gt;
|-&lt;br /&gt;
| 39 || CheckApplicationLaunchRights&lt;br /&gt;
|-&lt;br /&gt;
| 40 || GetApplicationLogoData&lt;br /&gt;
|-&lt;br /&gt;
| 41 || CalculateApplicationDownloadRequiredSize&lt;br /&gt;
|-&lt;br /&gt;
| 42 || CleanupSdCard&lt;br /&gt;
|-&lt;br /&gt;
| 43 || [[#CheckSdCardMountStatus]]&lt;br /&gt;
|-&lt;br /&gt;
| 44 || GetSdCardMountStatusChangedEvent&lt;br /&gt;
|-&lt;br /&gt;
| 45 || GetGameCardAttachmentEvent&lt;br /&gt;
|-&lt;br /&gt;
| 46 || GetGameCardAttachmentInfo&lt;br /&gt;
|-&lt;br /&gt;
| 47 || [[#GetTotalSpaceSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 48 || [[#GetFreeSpaceSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 49 || GetSdCardRemovedEvent&lt;br /&gt;
|-&lt;br /&gt;
| 52 || GetGameCardUpdateDetectionEvent&lt;br /&gt;
|-&lt;br /&gt;
| 53 || DisableApplicationAutoDelete&lt;br /&gt;
|-&lt;br /&gt;
| 54 || EnableApplicationAutoDelete&lt;br /&gt;
|-&lt;br /&gt;
| 55 || [[#GetApplicationDesiredLanguage]]&lt;br /&gt;
|-&lt;br /&gt;
| 56 || SetApplicationTerminateResult&lt;br /&gt;
|-&lt;br /&gt;
| 57 || ClearApplicationTerminateResult&lt;br /&gt;
|-&lt;br /&gt;
| 58 || GetLastSdCardMountUnexpectedResult&lt;br /&gt;
|-&lt;br /&gt;
| 59 || ConvertApplicationLanguageToLanguageCode&lt;br /&gt;
|-&lt;br /&gt;
| 60 || [[#ConvertLanguageCodeToApplicationLanguage]]&lt;br /&gt;
|-&lt;br /&gt;
| 61 || GetBackgroundDownloadStressTaskInfo&lt;br /&gt;
|-&lt;br /&gt;
| 62 || GetGameCardStopper&lt;br /&gt;
|-&lt;br /&gt;
| 63 || IsSystemProgramInstalled&lt;br /&gt;
|-&lt;br /&gt;
| 64 || [2.0.0+] StartApplyDeltaTask&lt;br /&gt;
|-&lt;br /&gt;
| 65 || [2.0.0+] GetRequestServerStopper&lt;br /&gt;
|-&lt;br /&gt;
| 100 || ResetToFactorySettings&lt;br /&gt;
|-&lt;br /&gt;
| 101 || ResetToFactorySettingsWithoutUserSaveData&lt;br /&gt;
|-&lt;br /&gt;
| 102 || [2.0.0+] ResetToFactorySettingsForRefurbishment&lt;br /&gt;
|-&lt;br /&gt;
| 200 || CalculateUserSaveDataStatistics&lt;br /&gt;
|-&lt;br /&gt;
| 201 || DeleteUserSaveDataAll&lt;br /&gt;
|-&lt;br /&gt;
| 210 || DeleteUserSystemSaveData&lt;br /&gt;
|-&lt;br /&gt;
| 220 || UnregisterNetworkServiceAccount&lt;br /&gt;
|-&lt;br /&gt;
| 300 || GetApplicationShellEvent&lt;br /&gt;
|-&lt;br /&gt;
| 301 || PopApplicationShellEventInfo&lt;br /&gt;
|-&lt;br /&gt;
| 302 || LaunchLibraryApplet&lt;br /&gt;
|-&lt;br /&gt;
| 303 || TerminateLibraryApplet&lt;br /&gt;
|-&lt;br /&gt;
| 304 || LaunchSystemApplet&lt;br /&gt;
|-&lt;br /&gt;
| 305 || TerminateSystemApplet&lt;br /&gt;
|-&lt;br /&gt;
| 306 || LaunchOverlayApplet&lt;br /&gt;
|-&lt;br /&gt;
| 307 || TerminateOverlayApplet&lt;br /&gt;
|-&lt;br /&gt;
| 400 || [[#GetApplicationControlData]]&lt;br /&gt;
|-&lt;br /&gt;
| 401 || InvalidateAllApplicationControlCache&lt;br /&gt;
|-&lt;br /&gt;
| 402 || RequestDownloadApplicationControlData&lt;br /&gt;
|-&lt;br /&gt;
| 403 || GetMaxApplicationControlCacheCount&lt;br /&gt;
|-&lt;br /&gt;
| 404 || [2.0.0+] InvalidateApplicationControlCache&lt;br /&gt;
|-&lt;br /&gt;
| 405 || [2.0.0+] ListApplicationControlCacheEntryInfo&lt;br /&gt;
|-&lt;br /&gt;
| 502 || [2.0.0+] RequestCheckGameCardRegistration&lt;br /&gt;
|-&lt;br /&gt;
| 503 || [2.0.0+] RequestGameCardRegistrationGoldPoint&lt;br /&gt;
|-&lt;br /&gt;
| 504 || [2.0.0+] RequestRegisterGameCard&lt;br /&gt;
|-&lt;br /&gt;
| 600 || [2.0.0+] [[#CountApplicationContentMeta]]&lt;br /&gt;
|-&lt;br /&gt;
| 601 || [2.0.0+] [[#ListApplicationContentMetaStatus]]&lt;br /&gt;
|-&lt;br /&gt;
| 602 || [2.0.0+] ListOwnedAndInstalledAddOnContent&lt;br /&gt;
|-&lt;br /&gt;
| 603 || [2.0.0+] GetOwnedApplicationContentMetaStatus&lt;br /&gt;
|-&lt;br /&gt;
| 604 || [2.0.0+] RegisterContentsExternalKey&lt;br /&gt;
|-&lt;br /&gt;
| 605 || [2.0.0+] ListApplicationContentMetaStatusWithRightsCheck&lt;br /&gt;
|-&lt;br /&gt;
| 700 || [2.0.0+] PushDownloadTaskList&lt;br /&gt;
|-&lt;br /&gt;
| 701 || [2.0.0+] [[#ClearTaskStatusList]]&lt;br /&gt;
|-&lt;br /&gt;
| 702 || [2.0.0+] [[#RequestDownloadTaskList]]&lt;br /&gt;
|-&lt;br /&gt;
| 703 || [2.0.0+] [[#RequestEnsureDownloadTask]]&lt;br /&gt;
|-&lt;br /&gt;
| 704 || [2.0.0+] [[#ListDownloadTaskStatus]]&lt;br /&gt;
|-&lt;br /&gt;
| 705 || [2.0.0+] RequestDownloadTaskListData&lt;br /&gt;
|-&lt;br /&gt;
| 800 || [2.0.0+] RequestVersionList&lt;br /&gt;
|-&lt;br /&gt;
| 801 || [2.0.0+] ListVersionList&lt;br /&gt;
|-&lt;br /&gt;
| 900 || [2.0.0+] GetApplicationRecord&lt;br /&gt;
|-&lt;br /&gt;
| 901 || [2.0.0+] GetApplicationRecordProperty&lt;br /&gt;
|-&lt;br /&gt;
| 902 || [2.0.0+] EnableApplicationAutoUpdate&lt;br /&gt;
|-&lt;br /&gt;
| 903 || [2.0.0+] DisableApplicationAutoUpdate&lt;br /&gt;
|-&lt;br /&gt;
| 904 || [2.0.0+] TouchApplication&lt;br /&gt;
|-&lt;br /&gt;
| 905 || [2.0.0+] RequestApplicationUpdate&lt;br /&gt;
|-&lt;br /&gt;
| 906 || [2.0.0+] IsApplicationUpdateRequested&lt;br /&gt;
|-&lt;br /&gt;
| 907 || [2.0.0+] WithdrawApplicationUpdateRequest&lt;br /&gt;
|-&lt;br /&gt;
| 908 || [2.0.0+] ListApplicationRecordInstalledContentMeta&lt;br /&gt;
|-&lt;br /&gt;
| 1000 || [2.0.0+] RequestVerifyApplication&lt;br /&gt;
|-&lt;br /&gt;
| 1001 || [2.0.0+] CorruptApplicationForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 1200 || [2.0.0+] [[#NeedsUpdateVulnerability]]&lt;br /&gt;
|-&lt;br /&gt;
| 1300 || [2.0.0+] IsAnyApplicationEntityInstalled&lt;br /&gt;
|-&lt;br /&gt;
| 1301 || [2.0.0+] DeleteApplicationContentEntities&lt;br /&gt;
|-&lt;br /&gt;
| 1302 || [2.0.0+] CleanupUnrecordedApplicationEntity&lt;br /&gt;
|-&lt;br /&gt;
| 1400 || [2.0.0+] PrepareShutdown&lt;br /&gt;
|-&lt;br /&gt;
| 1500 || [2.0.0+] FormatSdCard&lt;br /&gt;
|-&lt;br /&gt;
| 1501 || [2.0.0+] NeedsSystemUpdateToFormatSdCard&lt;br /&gt;
|-&lt;br /&gt;
| 1502 || [2.0.0+] GetLastSdCardFormatUnexpectedResult&lt;br /&gt;
|-&lt;br /&gt;
| 1503 || [2.0.0+] DetachSdCard&lt;br /&gt;
|-&lt;br /&gt;
| 1600 || [2.0.0+] GetSystemSeedForPseudoDeviceId&lt;br /&gt;
|-&lt;br /&gt;
| 1700 || [2.0.0+] ListApplicationDownloadingContentMeta&lt;br /&gt;
|-&lt;br /&gt;
| 1800 || [2.0.0+] IsNotificationSetupCompleted&lt;br /&gt;
|-&lt;br /&gt;
| 1801 || [2.0.0+] GetLastNotificationInfoCount&lt;br /&gt;
|-&lt;br /&gt;
| 1802 || [2.0.0+] ListLastNotificationInfo&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== ListApplicationRecord ==&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of [[#ApplicationRecord]] and an s32 entry_offset, returns an output s32 out_entrycount.&lt;br /&gt;
&lt;br /&gt;
Returns an array of entries with the below format using the specified offset and count.&lt;br /&gt;
&lt;br /&gt;
== LaunchApplication ==&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output u64 PID.&lt;br /&gt;
&lt;br /&gt;
Launches an application title which is registered with NS.&lt;br /&gt;
&lt;br /&gt;
== GetApplicationContentPath ==&lt;br /&gt;
Takes a 0x16-type output buffer, an u8 [[NCM_services#ContentType|ContentType]], and an [[NCM_services#ApplicationId|ApplicationId]].&lt;br /&gt;
&lt;br /&gt;
The input [[NCM_services#ApplicationId|ApplicationId]] is used with the application-title table like various other cmds, anything not in that table can&#039;t be used with this.&lt;br /&gt;
&lt;br /&gt;
Returns a string path for the specified type of patch content with this [[NCM_services#ApplicationId|ApplicationId]], otherwise returns regular-application paths when update-title not installed. Returns an error when the specified type of content doesn&#039;t exist for this title. Starts with &amp;quot;@{SdCardContent,UserContent}://&amp;quot; and ends in &amp;quot;.nca&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
For gamecard content, the output path is: &amp;quot;@GcSXXXXXXXX:/&amp;lt;NcaId&amp;gt;.nca&amp;quot;. NCA-type0 with gamecard returns 0 with an empty output string.&lt;br /&gt;
&lt;br /&gt;
The output string is then used by the user-process with [[Filesystem_services|FS]] to mount the content.&lt;br /&gt;
&lt;br /&gt;
== GetTotalSpaceSize ==&lt;br /&gt;
Takes an input u8 [[NCM_services#StorageId|StorageId]], no output.&lt;br /&gt;
&lt;br /&gt;
The StorageId must be SdCard.&lt;br /&gt;
&lt;br /&gt;
Returns the s64 from [[NCM_services#IContentStorage]] GetFreeSpaceSize.&lt;br /&gt;
&lt;br /&gt;
== GetFreeSpaceSize ==&lt;br /&gt;
Takes an input u8 [[NCM_services#StorageId|StorageId]], no output.&lt;br /&gt;
&lt;br /&gt;
The StorageId must be SdCard.&lt;br /&gt;
&lt;br /&gt;
Returns the s64 from [[NCM_services#IContentStorage]] GetTotalSpaceSize.&lt;br /&gt;
&lt;br /&gt;
== GetApplicationDesiredLanguage ==&lt;br /&gt;
Takes an input u8 language-bitmask, returns an output u8 [[control.nacp]] langentry index.&lt;br /&gt;
&lt;br /&gt;
User-processes generate the language-bitmask with the following for all 16 lang-entries: &amp;lt;code&amp;gt;if(&amp;lt;either string in langentry[i] is non-empty&amp;gt;)bitmask |= 1&amp;lt;&amp;lt;i&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== ConvertLanguageCodeToApplicationLanguage ==&lt;br /&gt;
Takes an input u8 pointer for the resulting Id to be written to and a string represented as a u64 (i.e 0x53552D6E65 for &#039;en-US&#039;).&lt;br /&gt;
&lt;br /&gt;
Returns 0 if an ID was successfully found, otherwise returns 0x25810.&lt;br /&gt;
&lt;br /&gt;
== GetApplicationControlData ==&lt;br /&gt;
Takes an input u8 [[#ApplicationControlSource]], an [[NCM_services#ApplicationId|ApplicationId]], and a type-0x6 output buffer. Returns an output u32 for actual_size. Official user-processes use buffer size 0x24000. [[qlaunch]] only uses source value 0x1 (Storage if not in cache).&lt;br /&gt;
&lt;br /&gt;
Loads cached [[control.nacp]] to buf+0 and the cached icon to buf+0x4000. Returns an error if the buffer is too small.&lt;br /&gt;
&lt;br /&gt;
== ListApplicationContentMetaStatus ==&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of [[#ApplicationContentMetaStatus]], an input s32 index and [[NCM_services#ApplicationId|ApplicationId]], returns an output s32 out_entrycount.&lt;br /&gt;
&lt;br /&gt;
Returns 0x10-byte entries using the specified [[NCM_services#ApplicationId|ApplicationId]] starting at the specified index. Can only return game titles. The second entry if any is the update-title usually. When the input entryindex is &amp;gt;= totalentries, this will return 0 with out_entrycount=0.&lt;br /&gt;
&lt;br /&gt;
= ns:am2, ns:ec, ns:rid, ns:rt, ns:web, ns:ro, ns:sweb =&lt;br /&gt;
These are &amp;quot;nn::ns::detail::IServiceGetterInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
These commands check a state field for a command-specific bit and returns an error if not set, this is a permissions check for service+command.&lt;br /&gt;
&lt;br /&gt;
[11.0.0+] ns:ro was added.&lt;br /&gt;
&lt;br /&gt;
[15.0.0+] ns:sweb was added.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Permission bit&lt;br /&gt;
|-&lt;br /&gt;
| 7988 || [6.0.0+] [[#IDynamicRightsInterface|GetDynamicRightsInterface]] || 10&lt;br /&gt;
|-&lt;br /&gt;
| 7989 || [5.1.0+] [[#IReadOnlyApplicationControlDataInterface|GetReadOnlyApplicationControlDataInterface]] || 9&lt;br /&gt;
|-&lt;br /&gt;
| 7991 || [5.0.0+] [[#IReadOnlyApplicationRecordInterface|GetReadOnlyApplicationRecordInterface]] || 8&lt;br /&gt;
|-&lt;br /&gt;
| 7992 || [4.0.0+] [[#IECommerceInterface|GetECommerceInterface]] || 7&lt;br /&gt;
|-&lt;br /&gt;
| 7993 || [4.0.0+] [[#IApplicationVersionInterface|GetApplicationVersionInterface]] || 6&lt;br /&gt;
|-&lt;br /&gt;
| 7994 || [[#IFactoryResetInterface|GetFactoryResetInterface]] || 5&lt;br /&gt;
|-&lt;br /&gt;
| 7995 || [[#IAccountProxyInterface|GetAccountProxyInterface]] || 4&lt;br /&gt;
|-&lt;br /&gt;
| 7996 || [[#IApplicationManagerInterface|GetApplicationManagerInterface]] || 3&lt;br /&gt;
|-&lt;br /&gt;
| 7997 || [[#IDownloadTaskInterface|GetDownloadTaskInterface]] || 1&lt;br /&gt;
|-&lt;br /&gt;
| 7998 || [[#IContentManagementInterface|GetContentManagementInterface]] || 0&lt;br /&gt;
|-&lt;br /&gt;
| 7999 || [[#IDocumentInterface|GetDocumentInterface]] || 2&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Permissions state field with each service:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Service || Permissions&lt;br /&gt;
|-&lt;br /&gt;
| ns:web || 0x304&lt;br /&gt;
|-&lt;br /&gt;
| ns:ec || 0x83&lt;br /&gt;
|-&lt;br /&gt;
| ns:sweb || 0x387&lt;br /&gt;
|-&lt;br /&gt;
| ns:rid || 0x10&lt;br /&gt;
|-&lt;br /&gt;
| ns:rt || 0x20&lt;br /&gt;
|-&lt;br /&gt;
| ns:ro || 0x301&lt;br /&gt;
|-&lt;br /&gt;
| ns:am2 || 0x7FF&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IAccountProxyInterface ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IAccountProxyInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || CreateUserAccount&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IApplicationManagerInterface ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IApplicationManagerInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#ListApplicationRecord]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GenerateApplicationRecordCount&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [[#GetApplicationRecordUpdateSystemEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [[#GetApplicationViewDeprecated]]&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [[#DeleteApplicationEntity]]&lt;br /&gt;
|-&lt;br /&gt;
| 5 || [[#DeleteApplicationCompletely]]&lt;br /&gt;
|-&lt;br /&gt;
| 6 || IsAnyApplicationEntityRedundant&lt;br /&gt;
|-&lt;br /&gt;
| 7 || [[#DeleteRedundantApplicationEntity]]&lt;br /&gt;
|-&lt;br /&gt;
| 8 || [[#IsApplicationEntityMovable]]&lt;br /&gt;
|-&lt;br /&gt;
| 9 || [1.0.0-9.2.0] [[#MoveApplicationEntity]]&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [[#CalculateApplicationOccupiedSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 16 || PushApplicationRecord&lt;br /&gt;
|-&lt;br /&gt;
| 17 || ListApplicationRecordContentMeta&lt;br /&gt;
|-&lt;br /&gt;
| 19 || [1.0.0-5.1.0] LaunchApplicationOld&lt;br /&gt;
|-&lt;br /&gt;
| 21 || [[#GetApplicationContentPath]]&lt;br /&gt;
|-&lt;br /&gt;
| 22 || TerminateApplication&lt;br /&gt;
|-&lt;br /&gt;
| 23 || ResolveApplicationContentPath&lt;br /&gt;
|-&lt;br /&gt;
| 26 || BeginInstallApplication&lt;br /&gt;
|-&lt;br /&gt;
| 27 || DeleteApplicationRecord&lt;br /&gt;
|-&lt;br /&gt;
| 30 || [[#RequestApplicationUpdateInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 31 || [1.0.0-3.0.2] RequestUpdateApplication&lt;br /&gt;
|-&lt;br /&gt;
| 32 || [[#CancelApplicationDownload]]&lt;br /&gt;
|-&lt;br /&gt;
| 33 || [[#ResumeApplicationDownload]]&lt;br /&gt;
|-&lt;br /&gt;
| 35 || UpdateVersionList&lt;br /&gt;
|-&lt;br /&gt;
| 36 || PushLaunchVersion&lt;br /&gt;
|-&lt;br /&gt;
| 37 || ListRequiredVersion&lt;br /&gt;
|-&lt;br /&gt;
| 38 || [[#CheckApplicationLaunchVersion]]&lt;br /&gt;
|-&lt;br /&gt;
| 39 || [1.0.0-6.2.0] CheckApplicationLaunchRights&lt;br /&gt;
|-&lt;br /&gt;
| 40 || GetApplicationLogoData&lt;br /&gt;
|-&lt;br /&gt;
| 41 || CalculateApplicationDownloadRequiredSize&lt;br /&gt;
|-&lt;br /&gt;
| 42 || [[#CleanupSdCard]]&lt;br /&gt;
|-&lt;br /&gt;
| 43 || [[#CheckSdCardMountStatus]]&lt;br /&gt;
|-&lt;br /&gt;
| 44 || [[#GetSdCardMountStatusChangedEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 45 || GetGameCardAttachmentEvent&lt;br /&gt;
|-&lt;br /&gt;
| 46 || GetGameCardAttachmentInfo&lt;br /&gt;
|-&lt;br /&gt;
| 47 || [[#GetTotalSpaceSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 48 || [[#GetFreeSpaceSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 49 || GetSdCardRemovedEvent&lt;br /&gt;
|-&lt;br /&gt;
| 52 || [[#GetGameCardUpdateDetectionEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 53 || [[#DisableApplicationAutoDelete]]&lt;br /&gt;
|-&lt;br /&gt;
| 54 || [[#EnableApplicationAutoDelete]]&lt;br /&gt;
|-&lt;br /&gt;
| 55 || GetApplicationDesiredLanguage&lt;br /&gt;
|-&lt;br /&gt;
| 56 || [[#SetApplicationTerminateResult]]&lt;br /&gt;
|-&lt;br /&gt;
| 57 || [[#ClearApplicationTerminateResult]]&lt;br /&gt;
|-&lt;br /&gt;
| 58 || [[#GetLastSdCardMountUnexpectedResult]]&lt;br /&gt;
|-&lt;br /&gt;
| 59 || ConvertApplicationLanguageToLanguageCode&lt;br /&gt;
|-&lt;br /&gt;
| 60 || [[#ConvertLanguageCodeToApplicationLanguage]]&lt;br /&gt;
|-&lt;br /&gt;
| 61 || GetBackgroundDownloadStressTaskInfo&lt;br /&gt;
|-&lt;br /&gt;
| 62 || GetGameCardStopper&lt;br /&gt;
|-&lt;br /&gt;
| 63 || IsSystemProgramInstalled&lt;br /&gt;
|-&lt;br /&gt;
| 64 || StartApplyDeltaTask&lt;br /&gt;
|-&lt;br /&gt;
| 65 || [[#GetRequestServerStopper]]&lt;br /&gt;
|-&lt;br /&gt;
| 66 || [3.0.0+] GetBackgroundApplyDeltaStressTaskInfo&lt;br /&gt;
|-&lt;br /&gt;
| 67 || [3.0.0+] [[#CancelApplicationApplyDelta]]&lt;br /&gt;
|-&lt;br /&gt;
| 68 || [3.0.0+] [[#ResumeApplicationApplyDelta]]&lt;br /&gt;
|-&lt;br /&gt;
| 69 || [3.0.0+] [[#CalculateApplicationApplyDeltaRequiredSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 70 || [3.0.0+] [[#ResumeAll]]&lt;br /&gt;
|-&lt;br /&gt;
| 71 || [3.0.0+] [[#GetStorageSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 80 || [3.0.0+] RequestDownloadApplication&lt;br /&gt;
|-&lt;br /&gt;
| 81 || [3.0.0+] RequestDownloadAddOnContent&lt;br /&gt;
|-&lt;br /&gt;
| 82 || [3.0.0+] DownloadApplication&lt;br /&gt;
|-&lt;br /&gt;
| 83 || [4.0.0-6.2.0] CheckApplicationResumeRights&lt;br /&gt;
|-&lt;br /&gt;
| 84 || [4.0.0-16.1.0] GetDynamicCommitEvent&lt;br /&gt;
|-&lt;br /&gt;
| 85 || [4.0.0+] [[#RequestUpdateApplication2]]&lt;br /&gt;
|-&lt;br /&gt;
| 86 || [4.0.0+] EnableApplicationCrashReport&lt;br /&gt;
|-&lt;br /&gt;
| 87 || [4.0.0+] IsApplicationCrashReportEnabled&lt;br /&gt;
|-&lt;br /&gt;
| 90 || [15.0.0+] BoostSystemMemoryResourceLimit ([4.0.0-8.1.0] BoostSystemMemoryResourceLimit)&lt;br /&gt;
|-&lt;br /&gt;
| 91 || [5.0.0+] DeprecatedLaunchApplication&lt;br /&gt;
|-&lt;br /&gt;
| 92 || [5.0.0+] GetRunningApplicationProgramId&lt;br /&gt;
|-&lt;br /&gt;
| 93 || [5.0.0+] GetMainApplicationProgramIndex&lt;br /&gt;
|-&lt;br /&gt;
| 94 || [6.0.0+] [[#LaunchApplication_2|LaunchApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 95 || [6.0.0+] [[#GetApplicationLaunchInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 96 || [6.0.0+] [[#AcquireApplicationLaunchInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 97 || [6.0.0+] [[#GetMainApplicationProgramIndexByApplicationLaunchInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 98 || [6.0.0+] EnableApplicationAllThreadDumpOnCrash&lt;br /&gt;
|-&lt;br /&gt;
| 99 || [8.0.0+] [[#LaunchDevMenu]]&lt;br /&gt;
|-&lt;br /&gt;
| 100 || [[#ResetToFactorySettings]]&lt;br /&gt;
|-&lt;br /&gt;
| 101 || [[#ResetToFactorySettingsWithoutUserSaveData]]&lt;br /&gt;
|-&lt;br /&gt;
| 102 || [[#ResetToFactorySettingsForRefurbishment]]&lt;br /&gt;
|-&lt;br /&gt;
| 103 || [9.1.0+] [[#ResetToFactorySettingsWithPlatformRegion]]&lt;br /&gt;
|-&lt;br /&gt;
| 104 || [9.1.0+] [[#ResetToFactorySettingsWithPlatformRegionAuthentication]]&lt;br /&gt;
|-&lt;br /&gt;
| 105 || [10.0.0+] [[#RequestResetToFactorySettingsSecurely]]&lt;br /&gt;
|-&lt;br /&gt;
| 106 || [10.0.0+] [[#RequestResetToFactorySettingsWithPlatformRegionAuthenticationSecurely]]&lt;br /&gt;
|-&lt;br /&gt;
| 200 || CalculateUserSaveDataStatistics&lt;br /&gt;
|-&lt;br /&gt;
| 201 || [[#DeleteUserSaveDataAll]]&lt;br /&gt;
|-&lt;br /&gt;
| 210 || [[#DeleteUserSystemSaveData]]&lt;br /&gt;
|-&lt;br /&gt;
| 211 || [6.0.0+] [[#DeleteSaveData]]&lt;br /&gt;
|-&lt;br /&gt;
| 220 || [[#UnregisterNetworkServiceAccount]]&lt;br /&gt;
|-&lt;br /&gt;
| 221 || [6.0.0+] [[#UnregisterNetworkServiceAccountWithUserSaveDataDeletion]]&lt;br /&gt;
|-&lt;br /&gt;
| 300 || GetApplicationShellEvent&lt;br /&gt;
|-&lt;br /&gt;
| 301 || PopApplicationShellEventInfo&lt;br /&gt;
|-&lt;br /&gt;
| 302 || [[#LaunchLibraryApplet]]&lt;br /&gt;
|-&lt;br /&gt;
| 303 || TerminateLibraryApplet&lt;br /&gt;
|-&lt;br /&gt;
| 304 || [[#LaunchSystemApplet]]&lt;br /&gt;
|-&lt;br /&gt;
| 305 || TerminateSystemApplet&lt;br /&gt;
|-&lt;br /&gt;
| 306 || [[#LaunchOverlayApplet]]&lt;br /&gt;
|-&lt;br /&gt;
| 307 || TerminateOverlayApplet&lt;br /&gt;
|-&lt;br /&gt;
| 308 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 309 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 400 || [[#GetApplicationControlData]]&lt;br /&gt;
|-&lt;br /&gt;
| 401 || InvalidateAllApplicationControlCache&lt;br /&gt;
|-&lt;br /&gt;
| 402 || [[#RequestDownloadApplicationControlData]]&lt;br /&gt;
|-&lt;br /&gt;
| 403 || GetMaxApplicationControlCacheCount&lt;br /&gt;
|-&lt;br /&gt;
| 404 || InvalidateApplicationControlCache&lt;br /&gt;
|-&lt;br /&gt;
| 405 || ListApplicationControlCacheEntryInfo&lt;br /&gt;
|-&lt;br /&gt;
| 406 || [6.0.0-18.1.0] [[#GetApplicationControlProperty]]&lt;br /&gt;
|-&lt;br /&gt;
| 407 || [8.0.0+] [[#ListApplicationTitle]]&lt;br /&gt;
|-&lt;br /&gt;
| 408 || [8.0.0+] [[#ListApplicationIcon]]&lt;br /&gt;
|-&lt;br /&gt;
| 409 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 410 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 411 || [19.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 412 || [19.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 413 || [19.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 414 || [19.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 415 || [19.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 416 || [19.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 417 || [19.0.0+] InvalidateAllApplicationControlCacheOfTheStage&lt;br /&gt;
|-&lt;br /&gt;
| 418 || [19.0.0+] InvalidateApplicationControlCacheOfTheStage&lt;br /&gt;
|-&lt;br /&gt;
| 419 || [19.0.0+] RequestDownloadApplicationControlDataInBackground&lt;br /&gt;
|-&lt;br /&gt;
| 420 || [19.0.0+] CloneApplicationControlDataCacheForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 421 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 422 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 423 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 424 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 425 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 426 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 427 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 428 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 429 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 430 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 502 || [[#RequestCheckGameCardRegistration]]&lt;br /&gt;
|-&lt;br /&gt;
| 503 || [[#RequestGameCardRegistrationGoldPoint]]&lt;br /&gt;
|-&lt;br /&gt;
| 504 || [[#RequestRegisterGameCard]]&lt;br /&gt;
|-&lt;br /&gt;
| 505 || [3.0.0+] [[#GetGameCardMountFailureEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 506 || [3.0.0+] [[#IsGameCardInserted]]&lt;br /&gt;
|-&lt;br /&gt;
| 507 || [3.0.0+] [[#EnsureGameCardAccess]]&lt;br /&gt;
|-&lt;br /&gt;
| 508 || [3.0.0+] [[#GetLastGameCardMountFailureResult]]&lt;br /&gt;
|-&lt;br /&gt;
| 509 || [5.0.0+] [[#ListApplicationIdOnGameCard]]&lt;br /&gt;
|-&lt;br /&gt;
| 510 || [9.0.0+] [[#GetGameCardPlatformRegion]]&lt;br /&gt;
|-&lt;br /&gt;
| 511 || [19.0.0+] GetGameCardWakenReadyEvent&lt;br /&gt;
|-&lt;br /&gt;
| 512 || [19.0.0+] IsGameCardApplicationRunning&lt;br /&gt;
|-&lt;br /&gt;
| 513 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 514 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 515 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 516 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 517 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 518 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 519 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 600 || [[#CountApplicationContentMeta]]&lt;br /&gt;
|-&lt;br /&gt;
| 601 || [[#ListApplicationContentMetaStatus]]&lt;br /&gt;
|-&lt;br /&gt;
| 602 || [2.0.0-5.1.0] ListAvailableAddOnContent&lt;br /&gt;
|-&lt;br /&gt;
| 603 || GetOwnedApplicationContentMetaStatus&lt;br /&gt;
|-&lt;br /&gt;
| 604 || [1.0.0-15.0.1] RegisterContentsExternalKey&lt;br /&gt;
|-&lt;br /&gt;
| 605 || ListApplicationContentMetaStatusWithRightsCheck&lt;br /&gt;
|-&lt;br /&gt;
| 606 || [3.0.0+] GetContentMetaStorage&lt;br /&gt;
|-&lt;br /&gt;
| 607 || [6.0.0+] [[#ListAvailableAddOnContent]]&lt;br /&gt;
|-&lt;br /&gt;
| 609 || [13.0.0+] ListAvailabilityAssuredAddOnContent&lt;br /&gt;
|-&lt;br /&gt;
| 610 || [14.0.0+] GetInstalledContentMetaStorage&lt;br /&gt;
|-&lt;br /&gt;
| 611 || [16.0.0+] PrepareAddOnContent&lt;br /&gt;
|-&lt;br /&gt;
| 700 || PushDownloadTaskList&lt;br /&gt;
|-&lt;br /&gt;
| 701 || [[#ClearTaskStatusList]]&lt;br /&gt;
|-&lt;br /&gt;
| 702 || [[#RequestDownloadTaskList]]&lt;br /&gt;
|-&lt;br /&gt;
| 703 || [[#RequestEnsureDownloadTask]]&lt;br /&gt;
|-&lt;br /&gt;
| 704 || [[#ListDownloadTaskStatus]]&lt;br /&gt;
|-&lt;br /&gt;
| 705 || [[#RequestDownloadTaskListData]]&lt;br /&gt;
|-&lt;br /&gt;
| 800 || RequestVersionList&lt;br /&gt;
|-&lt;br /&gt;
| 801 || ListVersionList&lt;br /&gt;
|-&lt;br /&gt;
| 802 || [3.0.0+] [[#RequestVersionListData]]&lt;br /&gt;
|-&lt;br /&gt;
| 900 || GetApplicationRecord&lt;br /&gt;
|-&lt;br /&gt;
| 901 || GetApplicationRecordProperty&lt;br /&gt;
|-&lt;br /&gt;
| 902 || EnableApplicationAutoUpdate&lt;br /&gt;
|-&lt;br /&gt;
| 903 || DisableApplicationAutoUpdate&lt;br /&gt;
|-&lt;br /&gt;
| 904 || [[#TouchApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 905 || RequestApplicationUpdate&lt;br /&gt;
|-&lt;br /&gt;
| 906 || [[#IsApplicationUpdateRequested]]&lt;br /&gt;
|-&lt;br /&gt;
| 907 || [[#WithdrawApplicationUpdateRequest]]&lt;br /&gt;
|-&lt;br /&gt;
| 908 || ListApplicationRecordInstalledContentMeta&lt;br /&gt;
|-&lt;br /&gt;
| 909 || [3.0.0-14.1.2] WithdrawCleanupAddOnContentsWithNoRightsRecommendation&lt;br /&gt;
|-&lt;br /&gt;
| 910 || [5.0.0+] HasApplicationRecord&lt;br /&gt;
|-&lt;br /&gt;
| 911 || [5.1.0+] SetPreInstalledApplication&lt;br /&gt;
|-&lt;br /&gt;
| 912 || [5.1.0+] ClearPreInstalledApplicationFlag&lt;br /&gt;
|-&lt;br /&gt;
| 913 || [9.0.0+] ListAllApplicationRecord&lt;br /&gt;
|-&lt;br /&gt;
| 914 || [9.0.0+] HideApplicationRecord&lt;br /&gt;
|-&lt;br /&gt;
| 915 || [9.0.0+] ShowApplicationRecord&lt;br /&gt;
|-&lt;br /&gt;
| 916 || [11.0.0+] IsApplicationAutoDeleteDisabled&lt;br /&gt;
|-&lt;br /&gt;
| 917 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 918 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 919 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 920 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 921 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 922 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 923 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 924 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 925 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 926 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 927 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 928 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 929 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 930 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 931 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 933 || [20.1.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 934 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 935 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 936 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 1000 || [[#RequestVerifyApplicationDeprecated]]&lt;br /&gt;
|-&lt;br /&gt;
| 1001 || CorruptApplicationForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 1002 || [3.0.0-9.2.0] [[#RequestVerifyAddOnContentsRights]]&lt;br /&gt;
|-&lt;br /&gt;
| 1003 || [5.0.0+] [[#RequestVerifyApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 1004 || [5.0.0+] CorruptContentForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 1200 || [[#NeedsUpdateVulnerability]]&lt;br /&gt;
|-&lt;br /&gt;
| 1300 || [[#IsAnyApplicationEntityInstalled]]&lt;br /&gt;
|-&lt;br /&gt;
| 1301 || DeleteApplicationContentEntities&lt;br /&gt;
|-&lt;br /&gt;
| 1302 || CleanupUnrecordedApplicationEntity&lt;br /&gt;
|-&lt;br /&gt;
| 1303 || [3.0.0-9.2.0] CleanupAddOnContentsWithNoRights&lt;br /&gt;
|-&lt;br /&gt;
| 1304 || [3.0.0+] DeleteApplicationContentEntity&lt;br /&gt;
|-&lt;br /&gt;
| 1308 || [5.0.0+] DeleteApplicationCompletelyForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 1309 || [6.0.0+] [[#CleanupUnavailableAddOnContents]]&lt;br /&gt;
|-&lt;br /&gt;
| 1310 || [10.0.0+] [[#RequestMoveApplicationEntity]]&lt;br /&gt;
|-&lt;br /&gt;
| 1311 || [10.0.0+] [[#EstimateSizeToMove]]&lt;br /&gt;
|-&lt;br /&gt;
| 1312 || [10.0.0+] HasMovableEntity&lt;br /&gt;
|-&lt;br /&gt;
| 1313 || [11.0.0+] CleanupOrphanContents&lt;br /&gt;
|-&lt;br /&gt;
| 1314 || [11.0.0+] CheckPreconditionSatisfiedToMove&lt;br /&gt;
|-&lt;br /&gt;
| 1400 || PrepareShutdown&lt;br /&gt;
|-&lt;br /&gt;
| 1500 || [[#FormatSdCard]]&lt;br /&gt;
|-&lt;br /&gt;
| 1501 || [[#NeedsSystemUpdateToFormatSdCard]]&lt;br /&gt;
|-&lt;br /&gt;
| 1502 || [[#GetLastSdCardFormatUnexpectedResult]]&lt;br /&gt;
|-&lt;br /&gt;
| 1504 || [3.0.0+] InsertSdCard&lt;br /&gt;
|-&lt;br /&gt;
| 1505 || [3.0.0+] RemoveSdCard&lt;br /&gt;
|-&lt;br /&gt;
| 1506 || [9.0.0+] GetSdCardStartupStatus&lt;br /&gt;
|-&lt;br /&gt;
| 1508 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 1509 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 1510 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 1511 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 1512 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 1600 || GetSystemSeedForPseudoDeviceId&lt;br /&gt;
|-&lt;br /&gt;
| 1601 || [3.0.0+] ResetSystemSeedForPseudoDeviceId&lt;br /&gt;
|-&lt;br /&gt;
| 1700 || ListApplicationDownloadingContentMeta&lt;br /&gt;
|-&lt;br /&gt;
| 1701 || [3.0.0+] [[#GetApplicationView]]&lt;br /&gt;
|-&lt;br /&gt;
| 1702 || [3.0.0+] GetApplicationDownloadTaskStatus&lt;br /&gt;
|-&lt;br /&gt;
| 1703 || [4.0.0+] [[#GetApplicationViewDownloadErrorContext]]&lt;br /&gt;
|-&lt;br /&gt;
| 1704 || [8.0.0+] [[#GetApplicationViewWithPromotionInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 1705 || [11.0.0+] [[#IsPatchAutoDeletableApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 1706 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 1800 || IsNotificationSetupCompleted&lt;br /&gt;
|-&lt;br /&gt;
| 1801 || GetLastNotificationInfoCount&lt;br /&gt;
|-&lt;br /&gt;
| 1802 || [[#ListLastNotificationInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 1803 || [3.0.0+] [[#ListNotificationTask]]&lt;br /&gt;
|-&lt;br /&gt;
| 1900 || [3.0.0-12.1.0] IsActiveAccount&lt;br /&gt;
|-&lt;br /&gt;
| 1901 || [4.0.0+] [[#RequestDownloadApplicationPrepurchasedRights]]&lt;br /&gt;
|-&lt;br /&gt;
| 1902 || [5.0.0+] GetApplicationTicketInfo&lt;br /&gt;
|-&lt;br /&gt;
| 1903 || [13.1.0+] RequestDownloadApplicationPrepurchasedRightsForAccount&lt;br /&gt;
|-&lt;br /&gt;
| 1904 || [22.0.0+] &lt;br /&gt;
|-&lt;br /&gt;
| 2000 || [4.0.0+] [[#GetSystemDeliveryInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 2001 || [4.0.0+] [[#SelectLatestSystemDeliveryInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 2002 || [4.0.0+] [[#VerifyDeliveryProtocolVersion]]&lt;br /&gt;
|-&lt;br /&gt;
| 2003 || [4.0.0+] [[#GetApplicationDeliveryInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 2004 || [4.0.0+] [[#HasAllContentsToDeliver]]&lt;br /&gt;
|-&lt;br /&gt;
| 2005 || [4.0.0+] [[#CompareApplicationDeliveryInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 2006 || [4.0.0+] [[#CanDeliverApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 2007 || [4.0.0+] [[#ListContentMetaKeyToDeliverApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 2008 || [4.0.0+] [[#NeedsSystemUpdateToDeliverApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 2009 || [4.0.0+] [[#EstimateRequiredSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 2010 || [4.0.0+] [[#RequestReceiveApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 2011 || [4.0.0+] [[#CommitReceiveApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 2012 || [4.0.0+] [[#GetReceiveApplicationProgress]]&lt;br /&gt;
|-&lt;br /&gt;
| 2013 || [4.0.0+] [[#RequestSendApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 2014 || [4.0.0+] [[#GetSendApplicationProgress]]&lt;br /&gt;
|-&lt;br /&gt;
| 2015 || [4.0.0+] [[#CompareSystemDeliveryInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 2016 || [4.0.0+] [[#ListNotCommittedContentMeta]]&lt;br /&gt;
|-&lt;br /&gt;
| 2017 || [4.0.0+] [[#RecoverDownloadTask]]&lt;br /&gt;
|-&lt;br /&gt;
| 2018 || [5.0.0+] [[#GetApplicationDeliveryInfoHash]]&lt;br /&gt;
|-&lt;br /&gt;
| 2019 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2050 || [6.0.0+] [[#GetApplicationRightsOnClient]]&lt;br /&gt;
|-&lt;br /&gt;
| 2051 || [9.0.0+] InvalidateRightsIdCache&lt;br /&gt;
|-&lt;br /&gt;
| 2052 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2053 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2100 || [6.0.0+] [[#GetApplicationTerminateResult]]&lt;br /&gt;
|-&lt;br /&gt;
| 2101 || [6.0.0+] GetRawApplicationTerminateResult&lt;br /&gt;
|-&lt;br /&gt;
| 2150 || [6.0.0+] CreateRightsEnvironment&lt;br /&gt;
|-&lt;br /&gt;
| 2151 || [6.0.0+] DestroyRightsEnvironment&lt;br /&gt;
|-&lt;br /&gt;
| 2152 || [6.0.0+] ActivateRightsEnvironment&lt;br /&gt;
|-&lt;br /&gt;
| 2153 || [6.0.0+] DeactivateRightsEnvironment&lt;br /&gt;
|-&lt;br /&gt;
| 2154 || [6.0.0+] ForceActivateRightsContextForExit&lt;br /&gt;
|-&lt;br /&gt;
| 2155 || [7.0.0+] UpdateRightsEnvironmentStatus&lt;br /&gt;
|-&lt;br /&gt;
| 2156 || [10.0.0-12.1.0] CreateRightsEnvironmentForMicroApplication ([9.0.0-9.2.0] CreateRightsEnvironmentForPreomia)&lt;br /&gt;
|-&lt;br /&gt;
| 2160 || [6.0.0+] AddTargetApplicationToRightsEnvironment&lt;br /&gt;
|-&lt;br /&gt;
| 2161 || [6.0.0+] SetUsersToRightsEnvironment&lt;br /&gt;
|-&lt;br /&gt;
| 2170 || [6.0.0+] GetRightsEnvironmentStatus&lt;br /&gt;
|-&lt;br /&gt;
| 2171 || [6.0.0+] GetRightsEnvironmentStatusChangedEvent&lt;br /&gt;
|-&lt;br /&gt;
| 2180 || [6.0.0+] RequestExtendExpirationInRightsEnvironment&lt;br /&gt;
|-&lt;br /&gt;
| 2181 || [6.0.0+] GetResultOfExtendExpirationInRightsEnvironment&lt;br /&gt;
|-&lt;br /&gt;
| 2182 || [6.0.0+] SetActiveRightsContextUsingStateToRightsEnvironment&lt;br /&gt;
|-&lt;br /&gt;
| 2183 || [20.1.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2190 || [6.0.0+] [[#GetRightsEnvironmentHandleForApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 2199 || [6.0.0+] GetRightsEnvironmentCountForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 2200 || [6.0.0-9.2.0] GetGameCardApplicationCopyIdentifier&lt;br /&gt;
|-&lt;br /&gt;
| 2201 || [6.0.0-9.2.0] GetInstalledApplicationCopyIdentifier&lt;br /&gt;
|-&lt;br /&gt;
| 2250 || [6.0.0-6.2.0] RequestReportActiveELicence&lt;br /&gt;
|-&lt;br /&gt;
| 2300 || [6.0.0-8.1.0] ListEventLog&lt;br /&gt;
|-&lt;br /&gt;
| 2350 || [7.0.0+] PerformAutoUpdateByApplicationId&lt;br /&gt;
|-&lt;br /&gt;
| 2351 || [9.0.0+] [[#RequestNoDownloadRightsErrorResolution]]&lt;br /&gt;
|-&lt;br /&gt;
| 2352 || [9.0.0+] [[#RequestResolveNoDownloadRightsError]]&lt;br /&gt;
|-&lt;br /&gt;
| 2353 || [10.0.0+] GetApplicationDownloadTaskInfo&lt;br /&gt;
|-&lt;br /&gt;
| 2354 || [11.0.0+] PrioritizeApplicationBackgroundTask&lt;br /&gt;
|-&lt;br /&gt;
| 2355 || [12.0.0+] PreferStorageEfficientUpdate&lt;br /&gt;
|-&lt;br /&gt;
| 2356 || [12.0.0+] RequestStorageEfficientUpdatePreferable&lt;br /&gt;
|-&lt;br /&gt;
| 2357 || [15.0.0+] EnableMultiCoreDownload&lt;br /&gt;
|-&lt;br /&gt;
| 2358 || [15.0.0+] DisableMultiCoreDownload&lt;br /&gt;
|-&lt;br /&gt;
| 2359 || [15.0.0+] IsMultiCoreDownloadEnabled&lt;br /&gt;
|-&lt;br /&gt;
| 2360 || [19.0.0+] GetApplicationDownloadTaskCount&lt;br /&gt;
|-&lt;br /&gt;
| 2361 || [19.0.0+] GetMaxApplicationDownloadTaskCount&lt;br /&gt;
|-&lt;br /&gt;
| 2362 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2363 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2364 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2365 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2366 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2367 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2368 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2369 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2400 || [8.0.0+] [[#GetPromotionInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 2401 || [8.0.0+] CountPromotionInfo&lt;br /&gt;
|-&lt;br /&gt;
| 2402 || [8.0.0+] [[#ListPromotionInfo|ListPromotionInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 2403 || [8.0.0+] [[#ImportPromotionJsonForDebug]]&lt;br /&gt;
|-&lt;br /&gt;
| 2404 || [8.0.0+] [[#ClearPromotionInfoForDebug]]&lt;br /&gt;
|-&lt;br /&gt;
| 2500 || [8.0.0+] ConfirmAvailableTime&lt;br /&gt;
|-&lt;br /&gt;
| 2510 || [9.0.0+] [[#CreateApplicationResource]]&lt;br /&gt;
|-&lt;br /&gt;
| 2511 || [9.0.0+] [[#GetApplicationResource]]&lt;br /&gt;
|-&lt;br /&gt;
| 2513 || [10.0.0+] [[#LaunchMicroApplication]] ([9.0.0-9.2.0] LaunchPreomia)&lt;br /&gt;
|-&lt;br /&gt;
| 2514 || [9.0.0+] ClearTaskOfAsyncTaskManager&lt;br /&gt;
|-&lt;br /&gt;
| 2515 || [10.0.0+] CleanupAllPlaceHolderAndFragmentsIfNoTask&lt;br /&gt;
|-&lt;br /&gt;
| 2516 || [10.0.0-14.1.2] EnsureApplicationCertificate&lt;br /&gt;
|-&lt;br /&gt;
| 2517 || [13.0.0+] [[#CreateApplicationInstance]]&lt;br /&gt;
|-&lt;br /&gt;
| 2518 || [13.0.0+] UpdateQualificationForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 2519 || [13.0.0+] IsQualificationTransitionSupported&lt;br /&gt;
|-&lt;br /&gt;
| 2520 || [13.0.0+] IsQualificationTransitionSupportedByProcessId&lt;br /&gt;
|-&lt;br /&gt;
| 2521 || [13.0.0-16.1.0] GetRightsUserChangedEvent&lt;br /&gt;
|-&lt;br /&gt;
| 2522 || [14.0.0+] IsRomRedirectionAvailable&lt;br /&gt;
|-&lt;br /&gt;
| 2523 || [17.0.0+] GetProgramId&lt;br /&gt;
|-&lt;br /&gt;
| 2524 || [19.0.0+] &lt;br /&gt;
|-&lt;br /&gt;
| 2525 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2526 || [22.0.0+] &lt;br /&gt;
|-&lt;br /&gt;
| 2800 || [9.0.0+] GetApplicationIdOfPreomia&lt;br /&gt;
|-&lt;br /&gt;
| 3000 || [11.0.0+] [[#RegisterDeviceLockKey]]&lt;br /&gt;
|-&lt;br /&gt;
| 3001 || [11.0.0+] [[#UnregisterDeviceLockKey]]&lt;br /&gt;
|-&lt;br /&gt;
| 3002 || [11.0.0+] [[#VerifyDeviceLockKey]]&lt;br /&gt;
|-&lt;br /&gt;
| 3003 || [11.0.0+] [[#HideApplicationIcon]]&lt;br /&gt;
|-&lt;br /&gt;
| 3004 || [11.0.0+] [[#ShowApplicationIcon]]&lt;br /&gt;
|-&lt;br /&gt;
| 3005 || [11.0.0+] [[#HideApplicationTitle]]&lt;br /&gt;
|-&lt;br /&gt;
| 3006 || [11.0.0+] [[#ShowApplicationTitle]]&lt;br /&gt;
|-&lt;br /&gt;
| 3007 || [11.0.0+] [[#EnableGameCard]]&lt;br /&gt;
|-&lt;br /&gt;
| 3008 || [11.0.0+] [[#DisableGameCard]]&lt;br /&gt;
|-&lt;br /&gt;
| 3009 || [11.0.0+] [[#EnableLocalContentShare]]&lt;br /&gt;
|-&lt;br /&gt;
| 3010 || [11.0.0+] [[#DisableLocalContentShare]]&lt;br /&gt;
|-&lt;br /&gt;
| 3011 || [11.0.0+] [[#IsApplicationIconHidden]]&lt;br /&gt;
|-&lt;br /&gt;
| 3012 || [11.0.0+] [[#IsApplicationTitleHidden]]&lt;br /&gt;
|-&lt;br /&gt;
| 3013 || [11.0.0+] [[#IsGameCardEnabled]]&lt;br /&gt;
|-&lt;br /&gt;
| 3014 || [11.0.0+] [[#IsLocalContentShareEnabled]]&lt;br /&gt;
|-&lt;br /&gt;
| 3015 || [18.0.0+] GetNetworkUpdateRequiredByGameCardDetectionEvent&lt;br /&gt;
|-&lt;br /&gt;
| 3050 || [14.0.0+] ListAssignELicenseTaskResult&lt;br /&gt;
|-&lt;br /&gt;
| 3100 || [17.0.0+] [[#GetSafeSystemVersionCheckInfo|GetSafeSystemVersionCheckInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 3101 || [17.0.0+] [[#RequestUpdateSafeSystemVersionCheckInfo|RequestUpdateSafeSystemVersionCheckInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 3102 || [17.0.0+] [[#ResetSafeSystemVersionCheckInfo|ResetSafeSystemVersionCheckInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 3104 || [18.0.0+] GetApplicationNintendoLogo&lt;br /&gt;
|-&lt;br /&gt;
| 3105 || [18.0.0+] GetApplicationStartupMovie&lt;br /&gt;
|-&lt;br /&gt;
| 3106 || [22.0.0+] &lt;br /&gt;
|-&lt;br /&gt;
| 3150 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 4000 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4004 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4006 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4007 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4008 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4009 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4010 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4011 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4012 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4013 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4015 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4017 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4019 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4020 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4021 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4022 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4023 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4024 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4025 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4026 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4027 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4028 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4029 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4030 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4031 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4032 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4033 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4034 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4035 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4037 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4038 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4039 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4040 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4041 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4042 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4043 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4044 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4045 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4046 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4049 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4050 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4051 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4052 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4053 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4054 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4055 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4056 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4057 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4058 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4059 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4060 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4061 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4062 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4063 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4064 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4065 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4066 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4067 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4068 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4069 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4070 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4071 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4072 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4073 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4074 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4075 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4076 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4077 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4078 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4079 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4080 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4081 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4083 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4084 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4085 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4086 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4087 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4088 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4089 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4090 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4091 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4092 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4093 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4094 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4095 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4096 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4097 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4099 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 5000 || [18.0.0+] &lt;br /&gt;
|-&lt;br /&gt;
| 5001 || [18.0.0+] &lt;br /&gt;
|-&lt;br /&gt;
| 9999 || [10.0.0-10.2.0] GetApplicationCertificate&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[4.0.0+] RequestDownloadAddOnContent now takes an additional 8-bytes of input.&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationRecordUpdateSystemEvent ====&lt;br /&gt;
No input, returns an output Event handle with EventClearMode=1.&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationViewDeprecated ====&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of [[#ApplicationViewDeprecated]], a type-0x5 input buffer containing an array of u64 [[NCM_services#ApplicationId|ApplicationIds]], no output.&lt;br /&gt;
&lt;br /&gt;
On newer system-versions this is the same as [[#GetApplicationView]], except this converts the output from the func called in the loop from [[#ApplicationView]] to [[#ApplicationViewDeprecated]].&lt;br /&gt;
&lt;br /&gt;
==== DeleteApplicationEntity ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== DeleteApplicationCompletely ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== DeleteRedundantApplicationEntity ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== IsApplicationEntityMovable ====&lt;br /&gt;
Takes an input u8 [[NCM_services#StorageId|StorageId]], an [[NCM_services#ApplicationId|ApplicationId]], returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
==== MoveApplicationEntity ====&lt;br /&gt;
Takes an input u8 [[NCM_services#StorageId|StorageId]], an [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== RequestApplicationUpdateInfo ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
The data that can be read from the [[#IAsyncValue]] is [[#ApplicationUpdateInfo]].&lt;br /&gt;
&lt;br /&gt;
Before using the cmd, official sw uses [[Network_Interface_services#IsAnyInternetRequestAccepted|IsAnyInternetRequestAccepted]] with the output from [[Network_Interface_services#GetClientId|GetClientId]], throwing an error when the returned bool is false.&lt;br /&gt;
&lt;br /&gt;
==== CancelApplicationDownload ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== ResumeApplicationDownload ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== CheckApplicationLaunchVersion ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== CalculateApplicationDownloadRequiredSize ====&lt;br /&gt;
Takes an input u8 [[NCM_services#StorageId|StorageId]], an [[NCM_services#ApplicationId|ApplicationId]], returns an output s64.&lt;br /&gt;
&lt;br /&gt;
==== CleanupSdCard ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== GetSdCardMountStatusChangedEvent ====&lt;br /&gt;
No input, returns an output Event handle with EventClearMode=0.&lt;br /&gt;
&lt;br /&gt;
==== GetGameCardUpdateDetectionEvent ====&lt;br /&gt;
No input, returns an output Event handle with EventClearMode=0.&lt;br /&gt;
&lt;br /&gt;
This Event is used by [[qlaunch]] to check whether a card-sysupdate is required.&lt;br /&gt;
&lt;br /&gt;
==== DisableApplicationAutoDelete ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== EnableApplicationAutoDelete ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== SetApplicationTerminateResult ====&lt;br /&gt;
Takes an input u32 Result, an [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== ClearApplicationTerminateResult ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== GetLastSdCardMountUnexpectedResult ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== GetRequestServerStopper ====&lt;br /&gt;
No input, returns an output [[#IRequestServerStopper]].&lt;br /&gt;
&lt;br /&gt;
This increfs a state ref-count, with decref being handled when the object is closed. This ref-count is checked by [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]] and related cmds.&lt;br /&gt;
&lt;br /&gt;
==== CancelApplicationApplyDelta ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== ResumeApplicationApplyDelta ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== CalculateApplicationApplyDeltaRequiredSize ====&lt;br /&gt;
Takes an input u8 [[NCM_services#StorageId|StorageId]], an [[NCM_services#ApplicationId|ApplicationId]], returns an output s64.&lt;br /&gt;
&lt;br /&gt;
==== ResumeAll ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== GetStorageSize ====&lt;br /&gt;
Takes an input u8 [[NCM_services#StorageId|StorageId]], returns two output s64s.&lt;br /&gt;
&lt;br /&gt;
This temporarily mounts the [[Filesystem_services#OpenContentStorageFileSystem|ContentStorage]] specified by the StorageId (must be BuiltInUser or SdCard). The two output s64s are the output from [[Filesystem_services#GetTotalSpaceSize|GetTotalSpaceSize]] and [[Filesystem_services#GetFreeSpaceSize|GetFreeSpaceSize]] with this ContentStorage, with it this being unmounted afterwards.&lt;br /&gt;
&lt;br /&gt;
==== RequestUpdateApplication2 ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
See [[#RequestApplicationUpdateInfo]] regarding nifm.&lt;br /&gt;
&lt;br /&gt;
==== LaunchApplication ====&lt;br /&gt;
Takes an input u8 ProgramIndex, an input [[#ApplicationLaunchInfo]], returns an output u64.&lt;br /&gt;
&lt;br /&gt;
[18.0.0+] Now takes a total of 0x58 bytes of input.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] Now takes a total of 0x88 bytes of input.&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationLaunchInfo ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output [[#ApplicationLaunchInfo]].&lt;br /&gt;
&lt;br /&gt;
[18.0.0+] Now returns a total of 0x50 bytes of output.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] Now returns a total of 0x80 bytes of output.&lt;br /&gt;
&lt;br /&gt;
==== AcquireApplicationLaunchInfo ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output [[#ApplicationLaunchInfo]].&lt;br /&gt;
&lt;br /&gt;
This verifies that a state flag is set and that a state field matches the input ApplicationId, throwing an error otherwise. The [[#ApplicationLaunchInfo]] from state is copied to output, then the state flag is cleared.&lt;br /&gt;
&lt;br /&gt;
[18.0.0+] Now returns a total of 0x50 bytes of output.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] Now returns a total of 0x80 bytes of output.&lt;br /&gt;
&lt;br /&gt;
==== GetMainApplicationProgramIndexByApplicationLaunchInfo ====&lt;br /&gt;
[18.0.0+] Now takes a total of 0x50 bytes of input.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] Now returns a total of 0x80 bytes of output.&lt;br /&gt;
&lt;br /&gt;
==== LaunchDevMenu ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
This is used by AM cmd [[Applet_Manager_services#LaunchDevMenu|LaunchDevMenu]].&lt;br /&gt;
&lt;br /&gt;
This loads ProgramIds from [[System_Settings|system-settings]] &amp;lt;code&amp;gt;ns.applet!devmenu_id&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;ns.applet!devoverlaydisp_id&amp;lt;/code&amp;gt;, which only exists on devunits. An error is thrown if loading these fail.&lt;br /&gt;
&lt;br /&gt;
[[NCM_services#ncm|OpenContentMetaDatabase]] is used with StorageId = NandSystem, then IContentMetaDatabase GetLatestContentMetaKey is used with both of the above ProgramIds to verify that the cmd is successful.&lt;br /&gt;
&lt;br /&gt;
Then if the above succeeds, the above titles are launched with the above StorageId via [[Process_Manager_services|pmshell]] LaunchProgram ([10.0.0+] [[PGL_services#LaunchProgram|pgl]] with pgl_launch_flags=0), with a 0.5s sleep-thread afterwards on success. [[Process_Manager_services#LaunchFlags|LaunchFlags]] value 0xB is used here.&lt;br /&gt;
&lt;br /&gt;
==== DeleteUserSaveDataAll ====&lt;br /&gt;
Takes an input [[Account_services#Uid|Uid]], returns an output [[#IProgressMonitorForDeleteUserSaveDataAll]].&lt;br /&gt;
&lt;br /&gt;
On success, [[#IProgressMonitorForDeleteUserSaveDataAll]] GetProgress is used with the output being copied into object state.&lt;br /&gt;
&lt;br /&gt;
==== DeleteUserSystemSaveData ====&lt;br /&gt;
Takes an input [[Account_services#Uid|Uid]], an u64 SystemSaveDataId, no output.&lt;br /&gt;
&lt;br /&gt;
==== DeleteSaveData ====&lt;br /&gt;
Takes an input u8 [[Filesystem_services#SaveDataSpaceId|SaveDataSpaceId]], an u64 SaveDataId, no output.&lt;br /&gt;
&lt;br /&gt;
==== UnregisterNetworkServiceAccount ====&lt;br /&gt;
Takes an input [[Account_services#Uid|Uid]], no output.&lt;br /&gt;
&lt;br /&gt;
==== UnregisterNetworkServiceAccountWithUserSaveDataDeletion ====&lt;br /&gt;
Takes an input [[Account_services#Uid|Uid]], no output.&lt;br /&gt;
&lt;br /&gt;
==== LaunchLibraryApplet ====&lt;br /&gt;
Takes an input u64 [[NCM_services#ProgramId|ProgramId]], returns an output u64.&lt;br /&gt;
&lt;br /&gt;
The specified program is launched with StorageId=BuiltInSystem via [[Process_Manager_services|pmshell]] LaunchProgram ([10.0.0+] [[PGL_services#LaunchProgram|pgl]] with pgl_launch_flags=0). [[Process_Manager_services#LaunchFlags|LaunchFlags]] value 0x9 is used here. The output u64 from here is written to the output for this cmd, on success.&lt;br /&gt;
&lt;br /&gt;
This is used by [[Applet_Manager_services|AM]].&lt;br /&gt;
&lt;br /&gt;
==== LaunchSystemApplet ====&lt;br /&gt;
No input, returns an output u64.&lt;br /&gt;
&lt;br /&gt;
A state flag must be non-zero, otherwise an error is thrown. When a state field is value 1, a hard-coded ProgramId for MaintenanceMenu is used. Otherwise, the ProgramId is loaded from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;ns.applet!system_applet_id&amp;lt;/code&amp;gt; ([20.0.0+] &amp;lt;code&amp;gt;ns.applet!system_applet_id_gen2&amp;lt;/code&amp;gt;).&lt;br /&gt;
&lt;br /&gt;
The SystemApplet is launched with StorageId=BuiltInSystem via [[Process_Manager_services|pmshell]] LaunchProgram ([10.0.0+] [[PGL_services#LaunchProgram|pgl]] with pgl_launch_flags=0). [[Process_Manager_services#LaunchFlags|LaunchFlags]] value 0x9 is used here. The output u64 from here is written to the output for this cmd, on success.&lt;br /&gt;
&lt;br /&gt;
This is used by [[Applet_Manager_services|AM]].&lt;br /&gt;
&lt;br /&gt;
==== LaunchOverlayApplet ====&lt;br /&gt;
No input, returns an output u64.&lt;br /&gt;
&lt;br /&gt;
A state flag must be non-zero, otherwise an error is thrown. The ProgramId is loaded from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;ns.applet!overlay_applet_id&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
The OverlayApplet is launched with StorageId=BuiltInSystem via [[Process_Manager_services|pmshell]] LaunchProgram ([10.0.0+] [[PGL_services#LaunchProgram|pgl]] with pgl_launch_flags=0). [[Process_Manager_services#LaunchFlags|LaunchFlags]] value 0x9 is used here. The output u64 from here is written to the output for this cmd, on success.&lt;br /&gt;
&lt;br /&gt;
This is used by [[Applet_Manager_services|AM]].&lt;br /&gt;
&lt;br /&gt;
==== RequestDownloadApplicationControlData ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
See [[#RequestApplicationUpdateInfo]] regarding nifm.&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationControlProperty ====&lt;br /&gt;
[18.0.0+] Now takes a total of 0x58 bytes of input.&lt;br /&gt;
&lt;br /&gt;
==== ListApplicationTitle ====&lt;br /&gt;
Takes an input TransferMemory handle, a type-0x5 input buffer containing an array of u64 [[NCM_services#ApplicationId|ApplicationIds]], an u8 [[#ApplicationControlSource]], an u64 size, returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
[[qlaunch]] uses value 0x1 for the u8.&lt;br /&gt;
&lt;br /&gt;
The user-process creates the TransferMemory with permissions=R--.&lt;br /&gt;
&lt;br /&gt;
The data available with [[#IAsyncValue]] Get is a s32 for the offset within the TransferMemory where the output data is located, GetSize returns the total byte-size of the data located here. The data located here is the [[NACP_Format|NACP]] title-entry for each specified ApplicationId.&lt;br /&gt;
&lt;br /&gt;
The TransferMemory size must be at least: count*sizeof([[NACP_Format|title-entry]]) + count*sizeof(u64) + count*[[#GetApplicationControlData|0x24000]].&lt;br /&gt;
&lt;br /&gt;
This is essentially an async wrapper for [[#GetApplicationControlData]], with support for multiple ApplicationIds.&lt;br /&gt;
&lt;br /&gt;
==== ListApplicationIcon ====&lt;br /&gt;
Takes an input TransferMemory handle, a type-0x5 input buffer containing an array of u64 [[NCM_services#ApplicationId|ApplicationIds]], an u8 [[#ApplicationControlSource]], an u64 size, returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
The user-process creates the TransferMemory with permissions=R--.&lt;br /&gt;
&lt;br /&gt;
The data available with [[#IAsyncValue]] Get is a s32 for the offset within the TransferMemory where the output data is located, GetSize returns the total byte-size of the data located here. This data is: an u64 for total entries, an array of u64s for each icon size, then the icon JPEGs for the specified ApplicationIds.&lt;br /&gt;
&lt;br /&gt;
The TransferMemory size must be at least: 0x4 + count*sizeof(u64) + count*[[#GetApplicationControlData|0x20000]] + count*sizeof(u64) + [[#GetApplicationControlData|0x24000]].&lt;br /&gt;
&lt;br /&gt;
This is essentially an async wrapper for [[#GetApplicationControlData]], with support for multiple ApplicationIds.&lt;br /&gt;
&lt;br /&gt;
==== Cmd421 ====&lt;br /&gt;
Takes an input TransferMemory handle, a type-0x5 input buffer containing an array of u64 [[NCM_services#ApplicationId|ApplicationIds]], an u8 [[#ApplicationControlSource]], an u64 size, returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
This is essentially the same as [[#ListApplicationTitle|ListApplicationTitle]] except the ApplicationControlSource is used here (ListApplicationTitle ignores it and uses 0xF0 instead).&lt;br /&gt;
&lt;br /&gt;
The TransferMemory size must be at least: count*sizeof(u64) + count*[[NACP#ApplicationTitle|0x300]] + [[#GetApplicationControlData|0x1d000]].&lt;br /&gt;
&lt;br /&gt;
The async task impl code eventually compares ApplicationControlSource with 0xF0, with a separate code-path being used when it doesn&#039;t match (which also handles [[NACP|compression]] when needed).&lt;br /&gt;
&lt;br /&gt;
==== RequestCheckGameCardRegistration ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
See [[#RequestApplicationUpdateInfo]] regarding nifm.&lt;br /&gt;
&lt;br /&gt;
==== RequestGameCardRegistrationGoldPoint ====&lt;br /&gt;
Takes an input [[Account_services#Uid|Uid]], an [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
The data that can be read from the [[#IAsyncValue]] is 4-bytes.&lt;br /&gt;
&lt;br /&gt;
See [[#RequestApplicationUpdateInfo]] regarding nifm.&lt;br /&gt;
&lt;br /&gt;
==== RequestRegisterGameCard ====&lt;br /&gt;
Takes an input s32, an [[Account_services#Uid|Uid]], an [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
See [[#RequestApplicationUpdateInfo]] regarding nifm.&lt;br /&gt;
&lt;br /&gt;
==== GetGameCardMountFailureEvent ====&lt;br /&gt;
No input, returns an output Event handle with EventClearMode=0.&lt;br /&gt;
&lt;br /&gt;
==== IsGameCardInserted ====&lt;br /&gt;
No input, returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
==== EnsureGameCardAccess ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== GetLastGameCardMountFailureResult ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== ListApplicationIdOnGameCard ====&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of u64 [[NCM_services#ApplicationId|ApplicationIds]], returns an output s32 for total output entries.&lt;br /&gt;
&lt;br /&gt;
==== GetGameCardPlatformRegion ====&lt;br /&gt;
No input, returns an u8 &#039;&#039;&#039;GameCardPlatformRegion&#039;&#039;&#039; (0x00 = Global, 0x01 = China).&lt;br /&gt;
&lt;br /&gt;
This calls [[Filesystem_services#IDeviceOperator|fsp-srv IDeviceOperator]] GetGameCardCompatibilityType and returns the result.&lt;br /&gt;
&lt;br /&gt;
==== ListAvailableAddOnContent ====&lt;br /&gt;
[10.0.0+] This now takes a total of 0x10-bytes of input instead of a total of 0x18-bytes of input.&lt;br /&gt;
&lt;br /&gt;
[15.0.0+] This now takes a total of 0x8-bytes of input instead of a total of 0x10-bytes of input.&lt;br /&gt;
&lt;br /&gt;
==== RequestDownloadTaskListData ====&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
==== TouchApplication ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== IsApplicationUpdateRequested ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output u8 bool and an u32.&lt;br /&gt;
&lt;br /&gt;
The output u32 is only valid when the output bool is set.&lt;br /&gt;
&lt;br /&gt;
==== WithdrawApplicationUpdateRequest ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== RequestVerifyApplicationDeprecated ====&lt;br /&gt;
Takes an input TransferMemory handle, an [[NCM_services#ApplicationId|ApplicationId]], an u64 size, returns an output Event handle and an [[#IProgressAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
On newer system-versions this calls the same func as [[#RequestVerifyApplication]], with the u32 value set to 0x7.&lt;br /&gt;
&lt;br /&gt;
==== RequestVerifyAddOnContentsRights ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IProgressAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
==== RequestVerifyApplication ====&lt;br /&gt;
Takes an input TransferMemory handle, an u32, an [[NCM_services#ApplicationId|ApplicationId]], an u64 size, returns an output Event handle and an [[#IProgressAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
Official sw creates the TransferMemory with an user-specified buffer with permissions=0. [[qlaunch]] uses buffer size 0x100000.&lt;br /&gt;
&lt;br /&gt;
Official sw has an additional wrapper func which calls the original wrapper func, this uses value 0x7 for the u32. This is the same func used by [[qlaunch]].&lt;br /&gt;
&lt;br /&gt;
==== IsAnyApplicationEntityInstalled ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
==== CleanupUnavailableAddOnContents ====&lt;br /&gt;
Takes an input u64 [[NCM_services#ApplicationId|ApplicationId]], an [[Account_services#Uid|Uid]], no output.&lt;br /&gt;
&lt;br /&gt;
==== RequestMoveApplicationEntity ====&lt;br /&gt;
Takes an input TransferMemory handle, a type-0x5 input buffer containing an array of [[NCM_services#StorageId|StorageId]], a [[NCM_services#StorageId|StorageId]], an u32 bitfield of &amp;quot;nn::ns::KeepApplicationEntityFlagTag&amp;quot;, an [[NCM_services#ApplicationId|ApplicationId]], an u64 tmem_size, returns an output Event handle and an [[#IProgressAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
The TransferMemory uses permissions=0.&lt;br /&gt;
&lt;br /&gt;
==== EstimateSizeToMove ====&lt;br /&gt;
Takes a type-0x5 input buffer containing an array of [[NCM_services#StorageId|StorageId]], a [[NCM_services#StorageId|StorageId]], an u32 bitfield of &amp;quot;nn::ns::KeepApplicationEntityFlagTag&amp;quot;, an [[NCM_services#ApplicationId|ApplicationId]], returns an output s64.&lt;br /&gt;
&lt;br /&gt;
This calls a func also used by [[#RequestMoveApplicationEntity]], then calls another func.&lt;br /&gt;
&lt;br /&gt;
==== FormatSdCard ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== NeedsSystemUpdateToFormatSdCard ====&lt;br /&gt;
No input, returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
==== GetLastSdCardFormatUnexpectedResult ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationView ====&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of [[#ApplicationView]], a type-0x5 input buffer containing an array of u64 [[NCM_services#ApplicationId|ApplicationIds]], no output.&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationViewDownloadErrorContext ====&lt;br /&gt;
Takes a type-0x16 output buffer containg an [[Error_Applet#ErrorContext|ErrorContext]], an u64 [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationViewWithPromotionInfo ====&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of [[#ApplicationViewWithPromotionInfo]], a type-0x5 input buffer containing an array of u64 [[NCM_services#ApplicationId|ApplicationIds]], no output.&lt;br /&gt;
&lt;br /&gt;
==== IsPatchAutoDeletableApplication ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output bool.&lt;br /&gt;
&lt;br /&gt;
Compares the input ApplicationId with the value of [[System_Settings|system-setting]] &amp;lt;code&amp;gt;ns.application!auto_deletable_application_id_on_not_enough_space&amp;lt;/code&amp;gt;, with the bool being set to the comparsion result.&lt;br /&gt;
&lt;br /&gt;
==== ListLastNotificationInfo ====&lt;br /&gt;
Takes a type-0x6 buffer containing an array with struct entry size 0x90-bytes. Returns 4-bytes of output.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] The struct size is now 0x98-bytes.&lt;br /&gt;
&lt;br /&gt;
==== ListNotificationTask ====&lt;br /&gt;
Takes a type-0x6 buffer containing an array with struct entry size 0xB0-bytes. Returns 4-bytes of output.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] The struct size is now 0xB8-bytes.&lt;br /&gt;
&lt;br /&gt;
==== RequestDownloadApplicationPrepurchasedRights ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
See [[#RequestApplicationUpdateInfo]] regarding nifm.&lt;br /&gt;
&lt;br /&gt;
==== GetSystemDeliveryInfo ====&lt;br /&gt;
Takes a type-0x16 output buffer containing a [[#SystemDeliveryInfo]], no output.&lt;br /&gt;
&lt;br /&gt;
This generates a [[#SystemDeliveryInfo]] using the currently installed SystemUpdate meta title.&lt;br /&gt;
&lt;br /&gt;
==== SelectLatestSystemDeliveryInfo ====&lt;br /&gt;
Takes a type-0x15 input buffer containing a [[#SystemDeliveryInfo]], a type-0x5 input buffer containing an array of [[#SystemDeliveryInfo]], a type-0x5 input buffer containing an array of [[#ApplicationDeliveryInfo]], and returns an output s32.&lt;br /&gt;
&lt;br /&gt;
This determines the latest version (RequiredSystemVersion) from the input [[#ApplicationDeliveryInfo]] array (ApplicationDeliveryProtocolVersion and the HMAC are also validated), using value 0 if the array is empty.&lt;br /&gt;
&lt;br /&gt;
* [20.0.0+] The following code block now only runs when the SystemDeliveryInfoPlatform from the type-0x15 [[#SystemDeliveryInfo]] buffer matches the [[System_Settings|sys-setting]].&lt;br /&gt;
** It then loops through the [[#ApplicationDeliveryInfo]] array again:&lt;br /&gt;
** This uses functionality which essentially uses [[Shared_Database_services|pl:s]] GetFunctionBlackListSystemVersionToAuthorize with the [[#ApplicationDeliveryInfo]] ApplicationId and ApplicationFunctionAuthorizationId=0x5 then parses the output, using cached data if available. The error is returned on failure.&lt;br /&gt;
** tmp_version = out_u8 == 0 ? 0 : out_u32 + 0x10000;&lt;br /&gt;
** Then the current latest-version value is updated with tmp_version, if tmp_version is higher.&lt;br /&gt;
&lt;br /&gt;
If this version value is less than a state field, the state field value is used instead (state field originates from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;contents_delivery!required_system_version_to_deliver_application&amp;lt;/code&amp;gt;).&lt;br /&gt;
&lt;br /&gt;
Then this selects the [[#SystemDeliveryInfo]] with the latest version from the input array. The output s32 is an index in that array for the selected entry, -1 if none found.&lt;br /&gt;
&lt;br /&gt;
During the above loop it first calls the [[#SystemDeliveryInfo]] validation func, returning the Result on failure. Then it runs additional validation, with the [[#SystemDeliveryInfo]] entry being ignored on failure:&lt;br /&gt;
* The above latest-version value must be at least the version value from the type-0x15 [[#SystemDeliveryInfo]] buffer and the [[#SystemDeliveryInfo]] array entry.&lt;br /&gt;
* When HasExFat is set in the type-0x15 [[#SystemDeliveryInfo]] buffer, it must be set in the [[#SystemDeliveryInfo]] array entry.&lt;br /&gt;
* FirmwareVariationId in the type-0x15 [[#SystemDeliveryInfo]] buffer must not be 0xFF.&lt;br /&gt;
* UpdatableFirmwareGroupId in the [[#SystemDeliveryInfo]] array entry must not be 0xFF. The value must be within bounds of the settings array ([[System_Settings|sys-settings]] &amp;lt;code&amp;gt;contents_delivery!updatable_firmware_group_string&amp;lt;/code&amp;gt;).&lt;br /&gt;
* PlatformRegion in the [[#SystemDeliveryInfo]] array entry and the type-0x15 [[#SystemDeliveryInfo]] buffer must match.&lt;br /&gt;
* Lastly when the following is true, this indicates success: (settings_array[UpdatableFirmwareGroupId] &amp;gt;&amp;gt; {above FirmwareVariationId}) &amp;amp; 1.&lt;br /&gt;
&lt;br /&gt;
==== VerifyDeliveryProtocolVersion ====&lt;br /&gt;
Takes a type-0x15 input buffer containing a [[#SystemDeliveryInfo]], no output.&lt;br /&gt;
&lt;br /&gt;
This validates the [[#SystemDeliveryInfo]] HMAC and the protocol-version fields. Then an error is returned when SystemUpdateVersion is less than a state field, otherwise 0 is returned (state field originates from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;contents_delivery!required_system_version_to_deliver_application&amp;lt;/code&amp;gt;).&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationDeliveryInfo ====&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of [[#ApplicationDeliveryInfo|ApplicationDeliveryInfo]], an input u32 bitmask &amp;lt;code&amp;gt;nn::ns::ApplicationDeliveryAttributeTag&amp;lt;/code&amp;gt;, an [[NCM_services#ApplicationId|ApplicationId]], and returns an output s32 total_out.&lt;br /&gt;
&lt;br /&gt;
[11.0.0+] An error is thrown if LocalContentShare is not [[#IsLocalContentShareEnabled|enabled]].&lt;br /&gt;
&lt;br /&gt;
An error is thrown if any bit is set in ApplicationDeliveryAttributeTag besides bit1, this must also be &amp;lt;=0x3. The output array-count must be at least 1: only 1 entry will be written to this array (hence on success total_out will also only be 1 on success).&lt;br /&gt;
&lt;br /&gt;
[7.0.0+] An error is thrown if the state ref-count for [[#GetRequestServerStopper|RequestServerStopper]] is zero. [7.0.0-7.0.1] The func which checks this would also return success when a field prior to the previously mentioned field is 0 (checked before the ref-count).&lt;br /&gt;
&lt;br /&gt;
An error is thrown if [[NIM_services|nim]] ListApplicationApplyDeltaTask returns a task.&lt;br /&gt;
&lt;br /&gt;
HasApplicationRecord is called with the input [[NCM_services#ApplicationId|ApplicationId]], an error is returned if the record isn&#039;t found.&lt;br /&gt;
&lt;br /&gt;
[[#ApplicationDeliveryInfo|RequiredApplicationVersion]] is initially set to the output version from [[Shared_Database_services|avm]] GetLaunchRequiredVersion. Later when ContentMetaType == Application etc, it calls a func. This func uses [[NCM_services|ncm]] IContentMetaDatabase GetRequiredApplicationVersion. If the output version is higher than the [[#ApplicationDeliveryInfo|RequiredApplicationVersion]] field then the output version is written here. Immediately aferwards, it also checks whether the bit for Compacted is set from [[NCM_services|ncm]] IContentMetaDatabase GetAttributes, clearing [[#ApplicationDeliveryInfo|ApplicationVersion]] if the attribute is set.&lt;br /&gt;
&lt;br /&gt;
[20.0.0+] [[#ApplicationDeliveryInfo|ApplicationDeliveryInfo]] ContentMetaPlatform and ProperProgramExists are now set using data from [[NCM_services|ncm]].&lt;br /&gt;
&lt;br /&gt;
[20.0.0+] [[Shared_Database_services|pl:s]] GetFunctionBlackListSystemVersionToAuthorize with ApplicationFunctionAuthorizationId=0x5 is now used, the output version is written to [[#ApplicationDeliveryInfo|RequiredSystemVersion]] when it&#039;s higher than the value previously written here.&lt;br /&gt;
&lt;br /&gt;
[20.0.0+] [[Shared_Database_services|pl:s]] GetRequiredApplicationVersion with ApplicationFunctionAuthorizationId=0x5 is now used, the output version is written to [[#ApplicationDeliveryInfo|RequiredApplicationVersion]] when it&#039;s higher than the value previously written here.&lt;br /&gt;
&lt;br /&gt;
==== HasAllContentsToDeliver ====&lt;br /&gt;
Takes a type-0x5 input buffer containing an array of [[#ApplicationDeliveryInfo]], returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
The array-count must match 1.&lt;br /&gt;
&lt;br /&gt;
This uses the same LocalContentShare check as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
After validating the [[#ApplicationDeliveryInfo]], the output bool is set to [[#ApplicationDeliveryInfo|ApplicationDeliveryAttributeTag]] &amp;amp; 0x10000002 != 0x2, then this returns 0.&lt;br /&gt;
&lt;br /&gt;
==== CompareApplicationDeliveryInfo ====&lt;br /&gt;
Takes two type-0x5 input buffers containing an array of [[#ApplicationDeliveryInfo]], returns an output s32.&lt;br /&gt;
&lt;br /&gt;
This uses the same LocalContentShare check as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
The array-count for both buffers must be 1, otherwise an error is returned.&lt;br /&gt;
&lt;br /&gt;
Both [[#ApplicationDeliveryInfo]] are validated, then the application-version in the first/second buffer are compared. The output s32 is set to the comparison result: -1 for less than, 0 for equal, and 1 for higher than.&lt;br /&gt;
&lt;br /&gt;
==== CanDeliverApplication ====&lt;br /&gt;
Takes two type-0x5 input buffers containing an array of [[#ApplicationDeliveryInfo]], returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
The array-count for the second buffer must be 1, otherwise an error is returned.&lt;br /&gt;
&lt;br /&gt;
This uses the same LocalContentShare check as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
The second [[#ApplicationDeliveryInfo]] buffer is validated. An error is thrown when [[#ApplicationDeliveryInfo|ApplicationDeliveryAttributeTag]] (second buffer) &amp;amp; 0x3 != 0x2, likewise when bit28 is clear in this field (bitmask 0x10000000).&lt;br /&gt;
&lt;br /&gt;
The array-count for the first buffer must be &amp;lt;=1, otherwise an error is returned. If the array-count for the first buffer is 0, this will return 0 with the output bool set to 0. The first [[#ApplicationDeliveryInfo]] buffer is validated. An error is thrown when [[#ApplicationDeliveryInfo|ApplicationDeliveryAttributeTag]] (first buffer) bit1 is clear or bit0 set. An error is thrown when [[#ApplicationDeliveryInfo|ApplicationDeliveryAttributeTag]] (second buffer) bit1 is clear.&lt;br /&gt;
&lt;br /&gt;
When [[#ApplicationDeliveryInfo|RequiredApplicationVersion]] (first or second buffer) is higher than [[#ApplicationDeliveryInfo|ApplicationVersion]] (second buffer), this will return 0 with the output bool set to 0.&lt;br /&gt;
&lt;br /&gt;
When [[#ApplicationDeliveryInfo|ApplicationDeliveryAttributeTag]] (first buffer) bit28 is set (bitmask 0x10000000):&lt;br /&gt;
* When [[#ApplicationDeliveryInfo|ApplicationVersion]] (first buffer) &amp;gt;= [[#ApplicationDeliveryInfo|ApplicationVersion]] (second buffer), write 0 to the output bool, otherwise write 1. Then return 0.&lt;br /&gt;
Otherwise when the above bit28 is clear:&lt;br /&gt;
* When [[#ApplicationDeliveryInfo|ApplicationVersion]] (first buffer) &amp;gt; [[#ApplicationDeliveryInfo|ApplicationVersion]] (second buffer), write 0 to the output bool, otherwise write 1. Then return 0.&lt;br /&gt;
&lt;br /&gt;
==== ListContentMetaKeyToDeliverApplication ====&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of [[NCM_services#ContentMetaKey|ContentMetaKey]], a type-0x5 input buffer containing an array of [[#ApplicationDeliveryInfo]], a s32, and returns an output s32 total_out.&lt;br /&gt;
&lt;br /&gt;
This uses the same LocalContentShare check as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
The array-count for ContentMetaKey must be at least 1, and for ApplicationDeliveryInfo it must match 1.&lt;br /&gt;
&lt;br /&gt;
The [[#ApplicationDeliveryInfo|ApplicationDeliveryInfo]] is validated (ApplicationDeliveryProtocolVersion/HMAC). An error is thrown when [[#ApplicationDeliveryInfo|ApplicationDeliveryAttributeTag]] bit0 is set.&lt;br /&gt;
&lt;br /&gt;
This uses the same ref-count check as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
An error is thrown if [[NIM_services|nim]] ListApplicationApplyDeltaTask returns a task.&lt;br /&gt;
&lt;br /&gt;
This will only return 1 ContentMetaKey entry. This will not output the entry when the input s32 is larger than 0, or when [[#ApplicationDeliveryInfo|ApplicationDeliveryAttributeTag]] bit1 is clear.&lt;br /&gt;
&lt;br /&gt;
==== NeedsSystemUpdateToDeliverApplication ====&lt;br /&gt;
Takes a type-0x15 input buffer containing a [[#SystemDeliveryInfo]], a type-0x5 input buffer containing an array of [[#ApplicationDeliveryInfo]], and returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
This uses the same LocalContentShare check as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
The [[#SystemDeliveryInfo]] is validated (validation for ApplicationDeliveryProtocolVersion is enabled).&lt;br /&gt;
&lt;br /&gt;
The array-count must match 1.&lt;br /&gt;
&lt;br /&gt;
The [[#ApplicationDeliveryInfo]] is validated (ApplicationDeliveryProtocolVersion/HMAC).&lt;br /&gt;
&lt;br /&gt;
This then runs functionality similar to [[#SelectLatestSystemDeliveryInfo]]:&lt;br /&gt;
* [20.0.0+] The following code block now only runs when the SystemDeliveryInfoPlatform from the input [[#SystemDeliveryInfo]] matches the [[System_Settings|sys-setting]].&lt;br /&gt;
* Uses the same functionality as [[#SelectLatestSystemDeliveryInfo]] for GetFunctionBlackListSystemVersionToAuthorize, returning the Result on failure.&lt;br /&gt;
* The output bool is set to: out_u8!=0 &amp;amp;&amp;amp; out_u32 &amp;gt;= [[#SystemDeliveryInfo]] SystemUpdateVersion (only the upper 16bits are used from the SystemUpdateVersion).&lt;br /&gt;
&lt;br /&gt;
Otherwise when the output bool is still false, this sets the output bool by comparing system-version fields in the [[#SystemDeliveryInfo]]/[[#ApplicationDeliveryInfo]] and with a state field (state field originates from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;contents_delivery!required_system_version_to_deliver_application&amp;lt;/code&amp;gt;).&lt;br /&gt;
&lt;br /&gt;
==== EstimateRequiredSize ====&lt;br /&gt;
Takes a type-0x5 input buffer containing an array of [[NCM_services#ContentMetaKey|ContentMetaKey]], returns an output s64.&lt;br /&gt;
&lt;br /&gt;
When the array-count is less than 1, this will return 0 with the s64 set to 0.&lt;br /&gt;
&lt;br /&gt;
==== RequestReceiveApplication ====&lt;br /&gt;
Takes a type-0x5 input buffer containing an array of [[NCM_services#ContentMetaKey|ContentMetaKey]], a [[NCM_services#StorageId|StorageId]], an u16 port, an u32 Ipv4Address, an [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
[[qlaunch]] uses value Any for the StorageId, and value 55556 for the port.&lt;br /&gt;
&lt;br /&gt;
This uses the same LocalContentShare and ref-count checks as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
An error is thrown if [[NIM_services|nim]] ListApplicationApplyDeltaTask returns a task.&lt;br /&gt;
&lt;br /&gt;
HasApplicationRecord is called with the input [[NCM_services#ApplicationId|ApplicationId]], an error is returned if the record isn&#039;t found.&lt;br /&gt;
&lt;br /&gt;
This loops through the input [[NCM_services#ContentMetaKey|ContentMetaKey]] array, throwing an error if the [[NCM_services#ContentMetaType|ContentMetaType]] doesn&#039;t match Patch. The input array is copied into state which is used later by the thread for [[NIM_services|nim]] CreateLocalCommunicationReceiveApplicationTask, max entries is 0x12.&lt;br /&gt;
&lt;br /&gt;
This does various setup then creates the [[#IAsyncResult]] + the async thread which handles the [[#IAsyncResult]] operation. Then the thread does:&lt;br /&gt;
&lt;br /&gt;
* Calls a func which does:&lt;br /&gt;
** Throws an error if a state flag is set.&lt;br /&gt;
** Uses [[NIM_services|nim]] CreateLocalCommunicationReceiveApplicationTask, returning the Result on failure.&lt;br /&gt;
** Uses [[NIM_services|nim]] RequestLocalCommunicationReceiveApplicationTaskRun, returning the Result on failure. Waits for the IAsyncResult operation from this to finish, then uses the Get cmd to get the output Result.&lt;br /&gt;
*** When the Result from Get is an error, a func is called for filling in the [[#IAsyncResult|IAsyncResult]] ErrorContext with Type4.&lt;br /&gt;
** Handles cleanup and returns.&lt;br /&gt;
* On success, this loads various data which is then used for saving a SystemPlayReport when the cached [[System_Settings|system-setting]] &amp;quot;systemreport!enabled&amp;quot; is set.&lt;br /&gt;
** The EventId is &amp;quot;receive_app_contents&amp;quot; with ApplicationId &amp;lt;NS ProgramId&amp;gt;.&lt;br /&gt;
** This report has the following fields:&lt;br /&gt;
*** &amp;quot;ApplicationId&amp;quot;&lt;br /&gt;
*** &amp;quot;DestinationVersion&amp;quot;&lt;br /&gt;
*** &amp;quot;SourceVersion&amp;quot;&lt;br /&gt;
*** &amp;quot;HasApplicationEntity&amp;quot;&lt;br /&gt;
*** &amp;quot;HasPatchEntity&amp;quot;&lt;br /&gt;
*** &amp;quot;ApplicationStorageId&amp;quot;&lt;br /&gt;
*** &amp;quot;PatchStorageId&amp;quot;&lt;br /&gt;
*** &amp;quot;Size&amp;quot;&lt;br /&gt;
*** &amp;quot;ThroughputKBps&amp;quot;&lt;br /&gt;
&lt;br /&gt;
==== CommitReceiveApplication ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
This uses the same LocalContentShare and ref-count checks as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
An error is thrown if [[NIM_services|nim]] ListApplicationApplyDeltaTask returns a task.&lt;br /&gt;
&lt;br /&gt;
==== GetReceiveApplicationProgress ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output [[#ReceiveApplicationProgress]].&lt;br /&gt;
&lt;br /&gt;
This uses the same ref-count check as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
An error is thrown if [[NIM_services|nim]] ListApplicationApplyDeltaTask returns a task.&lt;br /&gt;
&lt;br /&gt;
Uses [[NIM_services|nim]] ListApplicationLocalCommunicationReceiveApplicationTask, throwing an error if no task is returned. Then [[NIM_services|nim]] GetLocalCommunicationReceiveApplicationTaskInfo is used, returning the error from there on failure. Lastly, this writes the 0x10-bytes from output+8 from the latter cmd to the output [[#ReceiveApplicationProgress]], and returns 0.&lt;br /&gt;
&lt;br /&gt;
==== RequestSendApplication ====&lt;br /&gt;
Takes a type-0x5 input buffer containing an array of [[NCM_services#ContentMetaKey|ContentMetaKey]], an u16 port, an u32 Ipv4Address, an [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
[[qlaunch]] uses value 55556 for the port.&lt;br /&gt;
&lt;br /&gt;
This uses the same LocalContentShare and ref-count checks as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
An error is thrown if [[NIM_services|nim]] ListApplicationApplyDeltaTask returns a task.&lt;br /&gt;
&lt;br /&gt;
This does various setup and loops through the input ContentMetaKey array for initializing the array passed to the nim cmd during the async task. This loop does the following:&lt;br /&gt;
* Throws an error if the [[NCM_services#ContentMetaType|ContentMetaType]] in the ContentMetaKey doesn&#039;t match Patch.&lt;br /&gt;
* Calls a func with the ContentMetaKey and the ApplicationId, throwing an error if the output value is 0.&lt;br /&gt;
* Calls a func with the ContentMetaKey for getting the StorageId. This essentially loops through each valid ncm [[NCM_services|IContentMetaDatabase]] using cmd [[NCM_services|Has]] with the input ContentMetaKey, returning the relevant StorageId when found.&lt;br /&gt;
* The ContentMetaKey and the StorageId are copied into a tmp struct.&lt;br /&gt;
* if (ContentMetaType==Patch &amp;amp;&amp;amp; StorageId==GameCard) { &amp;lt;call a func etc&amp;gt; }&lt;br /&gt;
* Copies the above tmp struct into the async task state array.&lt;br /&gt;
&lt;br /&gt;
This then creates the [[#IAsyncResult]] + the async thread which handles the [[#IAsyncResult]] operation. Then the thread does:&lt;br /&gt;
&lt;br /&gt;
* Calls a func which does:&lt;br /&gt;
** Throws an error if a state flag is set.&lt;br /&gt;
** Uses [[NIM_services|nim]] CreateLocalCommunicationSendApplicationTask, returning the Result on failure.&lt;br /&gt;
** Uses [[NIM_services|nim]] RequestLocalCommunicationSendApplicationTaskRun, returning the Result on failure. Waits for the IAsyncResult operation from this to finish, then uses the Get cmd to get the output Result.&lt;br /&gt;
*** When the Result from Get is an error, a func is called for filling in the [[#IAsyncResult|IAsyncResult]] ErrorContext with Type4.&lt;br /&gt;
** Handles cleanup and returns.&lt;br /&gt;
* On success, this loads various data which is then used for saving a SystemPlayReport when the cached [[System_Settings|system-setting]] &amp;quot;systemreport!enabled&amp;quot; is set.&lt;br /&gt;
** The EventId is &amp;quot;send_app_contents&amp;quot; with ApplicationId &amp;lt;NS ProgramId&amp;gt;.&lt;br /&gt;
** This report has the following fields:&lt;br /&gt;
*** &amp;quot;ApplicationId&amp;quot;&lt;br /&gt;
*** &amp;quot;Version&amp;quot;&lt;br /&gt;
*** &amp;quot;ApplicationStorageId&amp;quot;&lt;br /&gt;
*** &amp;quot;PatchStorageId&amp;quot;&lt;br /&gt;
&lt;br /&gt;
==== GetSendApplicationProgress ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output [[#SendApplicationProgress]].&lt;br /&gt;
&lt;br /&gt;
Same as [[#GetReceiveApplicationProgress]] except this is the Send version, and uses [[NIM_services|nim]] ListApplicationLocalCommunicationSendApplicationTask/GetLocalCommunicationSendApplicationTaskInfo instead. The data copied to output is also swapped: u64 nim_out+0x8 is copied to out+0x8, and u64 nim_out+0x10 is copied to out+0x0.&lt;br /&gt;
&lt;br /&gt;
==== CompareSystemDeliveryInfo ====&lt;br /&gt;
Takes two type-0x15 input buffers containing a [[#SystemDeliveryInfo]], returns an output s32.&lt;br /&gt;
&lt;br /&gt;
This is essentially the same as [[#CompareApplicationDeliveryInfo]], except this compares the [[#SystemDeliveryInfo]] SystemUpdate version.&lt;br /&gt;
&lt;br /&gt;
==== ListNotCommittedContentMeta ====&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of [[NCM_services#ContentMetaKey|ContentMetaKey]], a s32, an [[NCM_services#ApplicationId|ApplicationId]], returns an output s32 total_out.&lt;br /&gt;
&lt;br /&gt;
This uses the same ref-count check as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
An error is thrown if [[NIM_services|nim]] ListApplicationApplyDeltaTask returns a task.&lt;br /&gt;
&lt;br /&gt;
==== RecoverDownloadTask ====&lt;br /&gt;
Takes a type-0x5 input buffer containing an array of {unknown} and an input u64, no output.&lt;br /&gt;
&lt;br /&gt;
This uses the same LocalContentShare and ref-count checks as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationDeliveryInfoHash ====&lt;br /&gt;
Takes a type-0x5 input buffer containing an array of [[#ApplicationDeliveryInfo]], returns an output 0x20-byte SHA256 hash.&lt;br /&gt;
&lt;br /&gt;
This uses the same LocalContentShare check as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
This extracts data from the input array for hashing with SHA256, with validation being done when handling each entry (ApplicationDeliveryProtocolVersion/HMAC).&lt;br /&gt;
&lt;br /&gt;
The 0x14-bytes from [[#ApplicationDeliveryInfo|ApplicationDeliveryInfo]]+0x8 are copied into a 0x18-byte struct entry in an array buffer, with the last 4-bytes being cleared. Then each 0x18-byte struct entry is hashed.&lt;br /&gt;
&lt;br /&gt;
==== Cmd2019 ====&lt;br /&gt;
Takes a type-0x15 input buffer containing a [[#SystemDeliveryInfo]], a type-0x5 input buffer containing an array of [[#ApplicationDeliveryInfo]], a type-0x5 input buffer containing an array of [[#ApplicationDeliveryInfo]], returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
This is essentially an extended version of [[#CanDeliverApplication|CanDeliverApplication]], with additional functionality for determining platform compatibility.&lt;br /&gt;
&lt;br /&gt;
This calls a func for validating the [[#SystemDeliveryInfo]] from the type-0x15 buffer, returning the Result on failure.&lt;br /&gt;
&lt;br /&gt;
Then [[#CanDeliverApplication|CanDeliverApplication]] is called with the output bool and the input arrays, returning the Result on failure.&lt;br /&gt;
&lt;br /&gt;
If the output bool is set after calling the above, it then calls a func with the output bool, the second [[#ApplicationDeliveryInfo]] buffer, and the [[#SystemDeliveryInfo]] from the type-0x15 buffer. This func does the following:&lt;br /&gt;
* When the SystemDeliveryInfoPlatform from the input [[#SystemDeliveryInfo]] matches the [[System_Settings|sys-setting]], it does the following:&lt;br /&gt;
** Uses [[Shared_Database_services|pl:s]] RequestApplicationFunctionAuthorizationByApplicationId with the [[#ApplicationDeliveryInfo]] ApplicationId/ApplicationVersion and ApplicationFunctionAuthorizationId=0x5, handling the Result on failure.&lt;br /&gt;
* When the platform fields from the input [[#SystemDeliveryInfo]]/[[#ApplicationDeliveryInfo]] match, write 1 to the output bool and return 0. Otherwise:&lt;br /&gt;
** When the [[#SystemDeliveryInfo]] SystemDeliveryInfoPlatform is 0x1 (Ounce): *output = [[#ApplicationDeliveryInfo|ContentMetaPlatform]] == 0 &amp;amp;&amp;amp; [[#ApplicationDeliveryInfo|ProperProgramExists]] == 0;&lt;br /&gt;
** When the [[#SystemDeliveryInfo]] SystemDeliveryInfoPlatform is 0x0 (NX): write 0 to the output bool and return 0.&lt;br /&gt;
** Otherwise, Abort.&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationRightsOnClient ====&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of [[#ApplicationRightsOnClient]], an input u32 flags, an [[NCM_services#ApplicationId|ApplicationId]], an [[Account_services#Uid|Uid]], returns 4-bytes of output for total output entries.&lt;br /&gt;
&lt;br /&gt;
Official sw has at least two wrappers which use this cmd: one with an all-zero Uid, one with an user-specified Uid. With both of these, the passed flags are hard-coded to value 0x3.&lt;br /&gt;
&lt;br /&gt;
For the output array count, [[qlaunch]] uses value 3.&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationTerminateResult ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output u32 Result.&lt;br /&gt;
&lt;br /&gt;
==== GetRightsEnvironmentHandleForApplication ====&lt;br /&gt;
No input, returns a total of 8-bytes of output.&lt;br /&gt;
&lt;br /&gt;
[9.0.0+] Now takes a total of 8-bytes of input, returns a total of 8-bytes of output.&lt;br /&gt;
&lt;br /&gt;
==== RequestNoDownloadRightsErrorResolution ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
The data that can be read from the [[#IAsyncValue]] is [[#NoDownloadRightsErrorResolution]].&lt;br /&gt;
&lt;br /&gt;
See [[#RequestApplicationUpdateInfo]] regarding nifm.&lt;br /&gt;
&lt;br /&gt;
==== RequestResolveNoDownloadRightsError ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
The data that can be read from the [[#IAsyncValue]] is [[#NoDownloadRightsErrorResolution]].&lt;br /&gt;
&lt;br /&gt;
See [[#RequestApplicationUpdateInfo]] regarding nifm.&lt;br /&gt;
&lt;br /&gt;
==== GetPromotionInfo ====&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of [[#PromotionInfo]], a type-0x5 input buffer containing an array of u64 [[NCM_services#ApplicationId|ApplicationIds]], a type-0x5 input buffer containing an array of [[Account_services#Uid|Uids]], no output.&lt;br /&gt;
&lt;br /&gt;
Official sw uses hard-coded value 1 for the count with each of these arrays.&lt;br /&gt;
&lt;br /&gt;
==== ListPromotionInfo ====&lt;br /&gt;
[20.0.0+] The struct size for the output buffer array is now 0x28-bytes instead of 0x20-bytes.&lt;br /&gt;
&lt;br /&gt;
==== ImportPromotionJsonForDebug ====&lt;br /&gt;
Takes a type-0x5 input buffer, no output.&lt;br /&gt;
&lt;br /&gt;
The output from [[Settings_services#GetDebugModeFlag]] must be 1, otherwise an error is returned.&lt;br /&gt;
&lt;br /&gt;
==== ClearPromotionInfoForDebug ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
The output from [[Settings_services#GetDebugModeFlag]] must be 1, otherwise an error is returned.&lt;br /&gt;
&lt;br /&gt;
This just clears 0xC-bytes in state.&lt;br /&gt;
&lt;br /&gt;
==== CreateApplicationResource ====&lt;br /&gt;
Takes an input [[#ApplicationResourceType]]. Returns an [[#IApplicationResource]].&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationResource ====&lt;br /&gt;
Takes an input u64 ProcessId and an input [[#ApplicationResourceType]]. Returns an [[#IApplicationResource]].&lt;br /&gt;
&lt;br /&gt;
==== LaunchMicroApplication ====&lt;br /&gt;
[18.0.0+] Now takes a total of 0x50 bytes of input.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] Now takes a total of 0x80 bytes of input.&lt;br /&gt;
&lt;br /&gt;
==== CreateApplicationInstance ====&lt;br /&gt;
[18.0.0+] Now takes a total of 0x50 bytes of input.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] Now takes a total of 0x80 bytes of input.&lt;br /&gt;
&lt;br /&gt;
==== RegisterDeviceLockKey ====&lt;br /&gt;
Takes a type-0x5 input buffer containing an InArray of u8, no output.&lt;br /&gt;
&lt;br /&gt;
User-processes expose this with two funcs: one which uses an user-specified u8 array directly, while the other uses [[HID_services#NpadButtonSet|NpadButton]].&lt;br /&gt;
&lt;br /&gt;
This does SHA256 hashing, etc.&lt;br /&gt;
&lt;br /&gt;
==== UnregisterDeviceLockKey ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Runs code identical to [[#RegisterDeviceLockKey]], except the passed buffer/size are 0.&lt;br /&gt;
&lt;br /&gt;
==== VerifyDeviceLockKey ====&lt;br /&gt;
Takes a type-0x5 input buffer containing an InArray of u8, no output.&lt;br /&gt;
&lt;br /&gt;
User-processes expose this with two funcs: one which uses an user-specified u8 array directly, while the other uses [[HID_services#NpadButtonSet|NpadButton]].&lt;br /&gt;
&lt;br /&gt;
This runs hashing similar to [[#RegisterDeviceLockKey]], with the calculated hash being verified with the one from state.&lt;br /&gt;
&lt;br /&gt;
==== HideApplicationIcon ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== ShowApplicationIcon ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== HideApplicationTitle ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== ShowApplicationTitle ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== EnableGameCard ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== DisableGameCard ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== EnableLocalContentShare ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== DisableLocalContentShare ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== IsApplicationIconHidden ====&lt;br /&gt;
No input, returns an output bool.&lt;br /&gt;
&lt;br /&gt;
==== IsApplicationTitleHidden ====&lt;br /&gt;
No input, returns an output bool.&lt;br /&gt;
&lt;br /&gt;
==== IsGameCardEnabled ====&lt;br /&gt;
No input, returns an output bool.&lt;br /&gt;
&lt;br /&gt;
==== IsLocalContentShareEnabled ====&lt;br /&gt;
No input, returns an output bool.&lt;br /&gt;
&lt;br /&gt;
Various Deliver cmds now run essentially the same code as IsLocalContentShareEnabled, with an error being returned when it&#039;s not enabled.&lt;br /&gt;
&lt;br /&gt;
==== Cmd4026 ====&lt;br /&gt;
Takes an input u64, returns an [[#IHostSession|IHostSession]].&lt;br /&gt;
&lt;br /&gt;
The input u64 must match a state field.&lt;br /&gt;
&lt;br /&gt;
This initializes [[LDN_services|ldn]] etc, and creates a network.&lt;br /&gt;
&lt;br /&gt;
==== Cmd4027 ====&lt;br /&gt;
Takes an input u64, returns an [[#IClientSession|IClientSession]].&lt;br /&gt;
&lt;br /&gt;
The input u64 must match a state field.&lt;br /&gt;
&lt;br /&gt;
This initializes [[LDN_services|ldn]] etc.&lt;br /&gt;
&lt;br /&gt;
=== IGameCardStopper ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IGameCardStopper&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This interface has no commands.&lt;br /&gt;
&lt;br /&gt;
=== IRequestServerStopper ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IRequestServerStopper&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This interface has no commands.&lt;br /&gt;
&lt;br /&gt;
=== IProgressMonitorForDeleteUserSaveDataAll ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IProgressMonitorForDeleteUserSaveDataAll&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetSystemEvent&lt;br /&gt;
|-&lt;br /&gt;
| 1 || IsFinished&lt;br /&gt;
|-&lt;br /&gt;
| 2 || GetResult&lt;br /&gt;
|-&lt;br /&gt;
| 10 || GetProgress&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
When closing the object, official sw uses IsFinished first, asserting when the output bool is false.&lt;br /&gt;
&lt;br /&gt;
* GetSystemEvent: No input, returns an output Event handle. [[qlaunch]] doesn&#039;t use this.&lt;br /&gt;
&lt;br /&gt;
* IsFinished: No input, returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
* GetResult: No input/output.&lt;br /&gt;
&lt;br /&gt;
* GetProgress: No input, returns an output [[#ProgressForDeleteUserSaveDataAll]]. Official sw writes this struct directly to object state.&lt;br /&gt;
&lt;br /&gt;
=== IProgressAsyncResult ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IProgressAsyncResult&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || Get&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Cancel&lt;br /&gt;
|-&lt;br /&gt;
| 2 || GetProgress&lt;br /&gt;
|-&lt;br /&gt;
| 3 || GetDetailResult&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [4.0.0+] GetErrorContext&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IHostSession ===&lt;br /&gt;
This is &amp;quot;nn::ns::vphym::detail::IHostSession&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [20.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || &lt;br /&gt;
|-&lt;br /&gt;
| 1 || &lt;br /&gt;
|-&lt;br /&gt;
| 2 || &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Cmd0 ====&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
The async task does the following:&lt;br /&gt;
* This waits for a client to connect.&lt;br /&gt;
* The [[LDN_services|NodeInfo]] UserName is converted into two u64s, which are used to locate a state entry with matching values.&lt;br /&gt;
* The client [[LDN_services|NodeInfo]] Ipv4Address is copied into state.&lt;br /&gt;
* Then a ptr to the above located state entry is also written into state.&lt;br /&gt;
&lt;br /&gt;
==== Cmd1 ====&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
The async task uses [[NIM_services|nim]] cmd2018 or cmd2027, depending on a state field. Once finished when a state flag is set, [[LDN_services|ldn]] is finalized and that state flag is cleared.&lt;br /&gt;
&lt;br /&gt;
==== Cmd2 ====&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
The async task uses [[NIM_sevices|nim]] cmd2024.&lt;br /&gt;
&lt;br /&gt;
=== IClientSession ===&lt;br /&gt;
This is &amp;quot;nn::ns::vphym::detail::IClientSession&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [20.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || &lt;br /&gt;
|-&lt;br /&gt;
| 1 || &lt;br /&gt;
|-&lt;br /&gt;
| 2 || &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Cmd0 ====&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
The async task does the following:&lt;br /&gt;
* Uses [[LDN_services|ldn]] Scan.&lt;br /&gt;
* After a [[LDN_services|NodeInfo]] is found with a matching UserName, the Ipv4Address for it is copied into state.&lt;br /&gt;
* If a timeout didn&#039;t occur and a valid NodeInfo was found, it proceeds with connecting to the network.&lt;br /&gt;
&lt;br /&gt;
==== Cmd1 ====&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
The async task uses [[NIM_services|nim]] cmd2019 or cmd2028, depending on a state field. Once finished when a state flag is set, [[LDN_services|ldn]] is finalized and that state flag is cleared.&lt;br /&gt;
&lt;br /&gt;
==== Cmd2 ====&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
This is identical to [[#IHostSession|IHostSession]] Cmd2.&lt;br /&gt;
&lt;br /&gt;
=== IApplicationVersionInterface ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IApplicationVersionInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [4.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetLaunchRequiredVersion&lt;br /&gt;
|-&lt;br /&gt;
| 1 || UpgradeLaunchRequiredVersion&lt;br /&gt;
|-&lt;br /&gt;
| 35 || UpdateVersionList&lt;br /&gt;
|-&lt;br /&gt;
| 36 || PushLaunchVersion&lt;br /&gt;
|-&lt;br /&gt;
| 37 || ListRequiredVersion&lt;br /&gt;
|-&lt;br /&gt;
| 38 || [22.0.0+] &lt;br /&gt;
|-&lt;br /&gt;
| 800 || RequestVersionList&lt;br /&gt;
|-&lt;br /&gt;
| 801 || ListVersionList&lt;br /&gt;
|-&lt;br /&gt;
| 802 || [[#RequestVersionListData]]&lt;br /&gt;
|-&lt;br /&gt;
| 900 || [12.0.0+] ImportAutoUpdatePolicyJsonForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 901 || [12.0.0+] ListDefaultAutoUpdatePolicy&lt;br /&gt;
|-&lt;br /&gt;
| 902 || [12.0.0+] ListAutoUpdatePolicyForSpecificApplication&lt;br /&gt;
|-&lt;br /&gt;
| 1000 || PerformAutoUpdate&lt;br /&gt;
|-&lt;br /&gt;
| 1001 || [11.0.0+] ListAutoUpdateSchedule&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== RequestVersionListData ====&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
The data that can be read from the [[#IAsyncValue]] is [[#VersionListData]].&lt;br /&gt;
&lt;br /&gt;
=== IContentManagementInterface ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IContentManagementInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [[#CalculateApplicationOccupiedSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 43 || [[#CheckSdCardMountStatus]]&lt;br /&gt;
|-&lt;br /&gt;
| 47 || [[#GetTotalSpaceSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 48 || [[#GetFreeSpaceSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 58 || [20.1.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 71 || [20.1.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 600 || [[#CountApplicationContentMeta]]&lt;br /&gt;
|-&lt;br /&gt;
| 601 || [[#ListApplicationContentMetaStatus]]&lt;br /&gt;
|-&lt;br /&gt;
| 605 || [[#ListApplicationContentMetaStatusWithRightsCheck]]&lt;br /&gt;
|-&lt;br /&gt;
| 607 || [[#IsAnyApplicationRunning]]&lt;br /&gt;
|-&lt;br /&gt;
| 608 || [21.0.0+]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== CalculateApplicationOccupiedSize ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output [[#ApplicationOccupiedSize]].&lt;br /&gt;
&lt;br /&gt;
==== CheckSdCardMountStatus ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== CountApplicationContentMeta ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output s32.&lt;br /&gt;
&lt;br /&gt;
==== ListApplicationContentMetaStatusWithRightsCheck ====&lt;br /&gt;
Same input/output as [[#ListApplicationContentMetaStatus]].&lt;br /&gt;
&lt;br /&gt;
==== IsAnyApplicationRunning ====&lt;br /&gt;
No input, returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
=== IDocumentInterface ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IDocumentInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 21 || GetApplicationContentPath&lt;br /&gt;
|-&lt;br /&gt;
| 23 || ResolveApplicationContentPath&lt;br /&gt;
|-&lt;br /&gt;
| 92 || [5.0.0+] GetRunningApplicationProgramId&lt;br /&gt;
|-&lt;br /&gt;
| 100 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 101 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 2524 || [19.0.0+] &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Cmd100 ====&lt;br /&gt;
Takes a type-0x16 output buffer containing a 0x300-byte struct, an input u8, an u64. Returns two output u8s.&lt;br /&gt;
&lt;br /&gt;
==== Cmd101 ====&lt;br /&gt;
Takes a type-0x16 output buffer containing a 0x300-byte struct, an input u8, an u64. Returns an output u8, an u8 [[Filesystem_services|ContentAttributes]], and a [[NCM_services#ProgramId|ProgramId]].&lt;br /&gt;
&lt;br /&gt;
This is similar to Cmd2524. On [S2] this is used instead of Cmd2524.&lt;br /&gt;
&lt;br /&gt;
==== Cmd2524 ====&lt;br /&gt;
Takes a type-0x16 output buffer containing a 0x300-byte struct, an input u8, an u64. Returns an output u8 [[Filesystem_services|ContentAttributes]] and a [[NCM_services#ProgramId|ProgramId]].&lt;br /&gt;
&lt;br /&gt;
The user-process uses the output from this as the input for [[Filesystem_services|OpenFileSystemWithId]] (out-buffer is used as the [[Filesystem_services|FspPath]]).&lt;br /&gt;
&lt;br /&gt;
=== IDownloadTaskInterface ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IDownloadTaskInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 701 || [[#ClearTaskStatusList]]&lt;br /&gt;
|-&lt;br /&gt;
| 702 || [[#RequestDownloadTaskList]]&lt;br /&gt;
|-&lt;br /&gt;
| 703 || [[#RequestEnsureDownloadTask]]&lt;br /&gt;
|-&lt;br /&gt;
| 704 || [[#ListDownloadTaskStatus]]&lt;br /&gt;
|-&lt;br /&gt;
| 705 || [[#RequestDownloadTaskListData]]&lt;br /&gt;
|-&lt;br /&gt;
| 706 || [4.0.0+] [[#TryCommitCurrentApplicationDownloadTask]]&lt;br /&gt;
|-&lt;br /&gt;
| 707 || [4.0.0+] [[#EnableAutoCommit]]&lt;br /&gt;
|-&lt;br /&gt;
| 708 || [4.0.0+] [[#DisableAutoCommit]]&lt;br /&gt;
|-&lt;br /&gt;
| 709 || [4.0.0+] [[#TriggerDynamicCommitEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 710 || [20.0.0+]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== ClearTaskStatusList ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== RequestDownloadTaskList ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== RequestEnsureDownloadTask ====&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
==== ListDownloadTaskStatus ====&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of [[#DownloadTaskStatus]], returns an output s32 total_out.&lt;br /&gt;
&lt;br /&gt;
A maximum of 0x100 tasks can be stored in state.&lt;br /&gt;
&lt;br /&gt;
==== TryCommitCurrentApplicationDownloadTask ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== EnableAutoCommit ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== DisableAutoCommit ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== TriggerDynamicCommitEvent ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
=== IReadOnlyApplicationRecordInterface ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IReadOnlyApplicationRecordInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [5.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || HasApplicationRecord || Same as [[#IApplicationManagerInterface]] cmd 910&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [10.0.0+] NotifyApplicationFailure ||&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [10.0.0+] IsDataCorruptedResult ||&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [20.0.0+] [[#ListApplicationRecord|ListApplicationRecord]] ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IReadOnlyApplicationControlDataInterface ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IReadOnlyApplicationControlDataInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [5.1.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#GetApplicationControlData]] || Same as [[#IApplicationManagerInterface]] cmd 400&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#GetApplicationDesiredLanguage]] || Same as [[#IApplicationManagerInterface]] cmd 55&lt;br /&gt;
|-&lt;br /&gt;
| 2 || ConvertApplicationLanguageToLanguageCode || Same as [[#IApplicationManagerInterface]] cmd 59&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [[#ConvertLanguageCodeToApplicationLanguage]] || Same as [[#IApplicationManagerInterface]] cmd 60&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [9.0.0+] SelectApplicationDesiredLanguage ||&lt;br /&gt;
|-&lt;br /&gt;
| 5 || [19.0.0+] || Same as [[#IApplicationManagerInterface]] cmd 411&lt;br /&gt;
|-&lt;br /&gt;
| 6 || [19.0.0+] || Same as [[#IApplicationManagerInterface]] cmd 416&lt;br /&gt;
|-&lt;br /&gt;
| 7 || [20.0.0+] || Same as [[#IApplicationManagerInterface]] cmd 921&lt;br /&gt;
|-&lt;br /&gt;
| 8 || [20.0.0+] || Same as [[#IApplicationManagerInterface]] cmd 922&lt;br /&gt;
|-&lt;br /&gt;
| 9 || [20.0.0+] || Same as [[#IApplicationManagerInterface]] cmd 923&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [20.0.0+] || Same as [[#IApplicationManagerInterface]] cmd 421&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [20.0.0+] || Same as [[#IApplicationManagerInterface]] cmd 422&lt;br /&gt;
|-&lt;br /&gt;
| 12 || [20.0.0+] || Same as [[#IApplicationManagerInterface]] cmd 423&lt;br /&gt;
|-&lt;br /&gt;
| 13 || [20.0.0+] || Same as [[#IApplicationManagerInterface]] cmd 407&lt;br /&gt;
|-&lt;br /&gt;
| 14 || [20.0.0+] || Same as [[#IApplicationManagerInterface]] cmd 408&lt;br /&gt;
|-&lt;br /&gt;
| 15 || [20.0.0+] || Same as [[#IApplicationManagerInterface]] cmd 415&lt;br /&gt;
|-&lt;br /&gt;
| 16 || [20.0.0+] ||&lt;br /&gt;
|-&lt;br /&gt;
| 17 || [20.1.0+] || Same as [[#IApplicationManagerInterface]] cmd 933&lt;br /&gt;
|-&lt;br /&gt;
| 18 || [21.0.0+] ||&lt;br /&gt;
|-&lt;br /&gt;
| 19 || [21.0.0+] ||&lt;br /&gt;
|-&lt;br /&gt;
| 20 || [21.0.0+] ||&lt;br /&gt;
|-&lt;br /&gt;
| 21 || [21.0.0+] ||&lt;br /&gt;
|-&lt;br /&gt;
| 22 || [21.0.0+] ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IDynamicRightsInterface ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IDynamicRightsInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [6.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#RequestApplicationRightsOnServer]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#RequestAssignRights]]&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [[#DeprecatedRequestAssignRightsToResume]]&lt;br /&gt;
|-&lt;br /&gt;
| 5 || [[#VerifyActivatedRightsOwners]]&lt;br /&gt;
|-&lt;br /&gt;
| 6 || [[#DeprecatedGetApplicationRightsStatus]]&lt;br /&gt;
|-&lt;br /&gt;
| 7 || [[#RequestPrefetchForDynamicRights]]&lt;br /&gt;
|-&lt;br /&gt;
| 8 || [[#GetDynamicRightsState]]&lt;br /&gt;
|-&lt;br /&gt;
| 9 || [7.0.0+] [[#RequestApplicationRightsOnServerToResume]]&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [7.0.0+] [[#RequestAssignRightsToResume]]&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [7.0.0+] [[#GetActivatedRightsUsers]]&lt;br /&gt;
|-&lt;br /&gt;
| 12 || [8.0.0+] [[#GetApplicationRightsStatus]]&lt;br /&gt;
|-&lt;br /&gt;
| 13 || [8.0.0+] [[#GetRunningApplicationStatus]]&lt;br /&gt;
|-&lt;br /&gt;
| 14 || [10.0.0-15.0.1] SelectApplicationLicense&lt;br /&gt;
|-&lt;br /&gt;
| 15 || [12.0.0+] [[#RequestContentsAuthorizationToken]]&lt;br /&gt;
|-&lt;br /&gt;
| 16 || [13.0.0+] QualifyUser&lt;br /&gt;
|-&lt;br /&gt;
| 17 || [13.0.0+] QualifyUserWithProcessId&lt;br /&gt;
|-&lt;br /&gt;
| 18 || [13.0.0+] NotifyApplicationRightsCheckStart&lt;br /&gt;
|-&lt;br /&gt;
| 19 || [13.0.0+] UpdateUserList&lt;br /&gt;
|-&lt;br /&gt;
| 20 || [13.0.0+] IsRightsLostUser&lt;br /&gt;
|-&lt;br /&gt;
| 21 || [13.1.0+] SetRequiredAddOnContentsOnContentsAvailabilityTransition&lt;br /&gt;
|-&lt;br /&gt;
| 22 || [14.0.0+] GetLimitedApplicationLicense&lt;br /&gt;
|-&lt;br /&gt;
| 23 || [14.0.0+] GetLimitedApplicationLicenseUpgradableEvent&lt;br /&gt;
|-&lt;br /&gt;
| 24 || [14.0.0+] NotifyLimitedApplicationLicenseUpgradableEventForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 25 || [14.0.0+] RequestProceedDynamicRightsState&lt;br /&gt;
|-&lt;br /&gt;
| 26 || [18.0.0+] HasAccountRestrictedRightsInRunningApplications&lt;br /&gt;
|-&lt;br /&gt;
| 27 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 28 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 29 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 30 || [21.0.0+]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== RequestApplicationRightsOnServer ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], an [[Account_services#Uid|Uid]] and an u32. Returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
==== RequestAssignRights ====&lt;br /&gt;
Takes a type-0x5 input buffer containing an array of &amp;quot;nn::ns::ApplicationRightsOnServer&amp;quot;. Returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
==== DeprecatedRequestAssignRightsToResume ====&lt;br /&gt;
Takes an input u64 &amp;quot;nn::ns::RightsEnvironmentHandle&amp;quot; and an [[Account_services#Uid|Uid]]. Returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
==== VerifyActivatedRightsOwners ====&lt;br /&gt;
Takes an input u64 &amp;quot;nn::ns::RightsEnvironmentHandle&amp;quot;. No output.&lt;br /&gt;
&lt;br /&gt;
==== DeprecatedGetApplicationRightsStatus ====&lt;br /&gt;
Takes an input u64 &amp;quot;nn::ns::RightsEnvironmentHandle&amp;quot;. Returns a bool &amp;quot;nn::ns::ApplicationRightsStatus&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==== RequestPrefetchForDynamicRights ====&lt;br /&gt;
Takes an input [[Account_services#Uid|Uid]]. Returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
==== GetDynamicRightsState ====&lt;br /&gt;
No input. Returns a bool &amp;quot;nn::ns::DynamicRightsState&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==== RequestApplicationRightsOnServerToResume ====&lt;br /&gt;
Takes an input u64 &amp;quot;nn::ns::RightsEnvironmentHandle&amp;quot;. Returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
==== RequestAssignRightsToResume ====&lt;br /&gt;
Takes an input u64 &amp;quot;nn::ns::RightsEnvironmentHandle&amp;quot;. Returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
==== GetActivatedRightsUsers ====&lt;br /&gt;
Takes an input u64 &amp;quot;nn::ns::RightsEnvironmentHandle&amp;quot;. Returns a bool, an u32 and a type-0x6 output buffer containing an array of [[Account_services#Uid|Uid]].&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationRightsStatus ====&lt;br /&gt;
Takes an input &amp;quot;nn::ns::RightsEnvironmentHandle&amp;quot;. Returns 2 bools &amp;quot;nn::ns::ApplicationRightsStatus&amp;quot; and &amp;quot;nn::ns::ApplicationLicenseType&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==== GetRunningApplicationStatus ====&lt;br /&gt;
Takes an input u64 &amp;quot;nn::ns::RightsEnvironmentHandle&amp;quot;. Returns an u32 &amp;quot;nn::ns::RunningApplicationStatus&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==== RequestContentsAuthorizationToken ====&lt;br /&gt;
Takes a total of 0x50-bytes of input, a type-0x5 input buffer. Returns an [[#IAsyncData_2|IAsyncData]] and an output handle.&lt;br /&gt;
&lt;br /&gt;
==== IAsyncData ====&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IAsyncData&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [12.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetSize&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Get&lt;br /&gt;
|-&lt;br /&gt;
| 2 || Cancel&lt;br /&gt;
|-&lt;br /&gt;
| 3 || GetErrorContext&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IECommerceInterface===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IECommerceInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [4.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#RequestLinkDevice]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [6.0.0+] [[#RequestCleanupAllPreInstalledApplications]]&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [6.0.0+] [[#RequestCleanupPreInstalledApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [6.0.0+] [[#RequestSyncRights]]&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [6.0.0+] [[#RequestUnlinkDevice]]&lt;br /&gt;
|-&lt;br /&gt;
| 5 || [6.1.0+] [[#RequestRevokeAllELicense]]&lt;br /&gt;
|-&lt;br /&gt;
| 6 || [9.0.0+] [[#RequestSyncRightsBasedOnAssignedELicenses]]&lt;br /&gt;
|-&lt;br /&gt;
| 7 || [14.0.0+] RequestOnlineSubscriptionFreeTrialAvailability&lt;br /&gt;
|-&lt;br /&gt;
| 8 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 9 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 12 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 13 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 14 || [21.0.0+]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== RequestLinkDevice ====&lt;br /&gt;
Takes an input [[Account_services#Uid|Uid]], returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
See [[#RequestApplicationUpdateInfo]] regarding nifm.&lt;br /&gt;
&lt;br /&gt;
==== RequestCleanupAllPreInstalledApplications ====&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
==== RequestCleanupPreInstalledApplication ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
==== RequestSyncRights ====&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
==== RequestUnlinkDevice ====&lt;br /&gt;
Takes an input [[Account_services#Uid|Uid]], returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
See [[#RequestApplicationUpdateInfo]] regarding nifm.&lt;br /&gt;
&lt;br /&gt;
==== RequestRevokeAllELicense ====&lt;br /&gt;
Takes an input [[Account_services#Uid|Uid]], returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
==== RequestSyncRightsBasedOnAssignedELicenses ====&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
=== IFactoryResetInterface ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IFactoryResetInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 100 || [[#ResetToFactorySettings]]&lt;br /&gt;
|-&lt;br /&gt;
| 101 || [[#ResetToFactorySettingsWithoutUserSaveData]]&lt;br /&gt;
|-&lt;br /&gt;
| 102 || [[#ResetToFactorySettingsForRefurbishment]]&lt;br /&gt;
|-&lt;br /&gt;
| 103 || [9.1.0+] [[#ResetToFactorySettingsWithPlatformRegion]]&lt;br /&gt;
|-&lt;br /&gt;
| 104 || [9.1.0+] [[#ResetToFactorySettingsWithPlatformRegionAuthentication]]&lt;br /&gt;
|-&lt;br /&gt;
| 105 || [10.0.0+] [[#RequestResetToFactorySettingsSecurely]]&lt;br /&gt;
|-&lt;br /&gt;
| 106 || [10.0.0+] [[#RequestResetToFactorySettingsWithPlatformRegionAuthenticationSecurely]]&lt;br /&gt;
|-&lt;br /&gt;
| 107 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 108 || [20.0.0+]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== ResetToFactorySettings ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
As of [9.1.0] this is the only [[#IFactoryResetInterface]] cmd used by [[qlaunch]].&lt;br /&gt;
&lt;br /&gt;
==== ResetToFactorySettingsWithoutUserSaveData ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== ResetToFactorySettingsForRefurbishment ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== ResetToFactorySettingsWithPlatformRegion ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== ResetToFactorySettingsWithPlatformRegionAuthentication ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== RequestResetToFactorySettingsSecurely ====&lt;br /&gt;
Takes an input u64 tmem_size, a TransferMemory handle, returns an output [[#IAsyncValueAndProgress]] and an Event handle.&lt;br /&gt;
&lt;br /&gt;
The TransferMemory uses permissions=0.&lt;br /&gt;
&lt;br /&gt;
==== RequestResetToFactorySettingsWithPlatformRegionAuthenticationSecurely ====&lt;br /&gt;
Takes an input u32 &amp;quot;nn::ae::PlatformRegion&amp;quot;, an u64 tmem_size, a TransferMemory handle, returns an output [[#IAsyncValueAndProgress]] and an Event handle.&lt;br /&gt;
&lt;br /&gt;
The TransferMemory uses permissions=0.&lt;br /&gt;
&lt;br /&gt;
===== IAsyncValueAndProgress =====&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IAsyncValueAndProgress&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [10.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetSize&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Get&lt;br /&gt;
|-&lt;br /&gt;
| 2 || Cancel&lt;br /&gt;
|-&lt;br /&gt;
| 3 || GetErrorContext&lt;br /&gt;
|-&lt;br /&gt;
| 4 || GetProgress&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IApplicationResource ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IApplicationResource&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [9.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || Attach&lt;br /&gt;
|-&lt;br /&gt;
| 1 || BoostSystemMemoryResourceLimit&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ns:vm =&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IVulnerabilityManagerInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 1200 || [3.0.0+] [[#NeedsUpdateVulnerability]]&lt;br /&gt;
|-&lt;br /&gt;
| 1201 || [4.0.0+] [[#UpdateSafeSystemVersionForDebug]]&lt;br /&gt;
|-&lt;br /&gt;
| 1202 || [4.0.0+] [[#GetSafeSystemVersion]]&lt;br /&gt;
|-&lt;br /&gt;
| 3100 || [18.0.0+] [[#GetSafeSystemVersionCheckInfo|GetSafeSystemVersionCheckInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 3101 || [18.0.0+] [[#RequestUpdateSafeSystemVersionCheckInfo|RequestUpdateSafeSystemVersionCheckInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 3102 || [18.0.0+] [[#ResetSafeSystemVersionCheckInfo|ResetSafeSystemVersionCheckInfo]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== NeedsUpdateVulnerability ==&lt;br /&gt;
No input, returns an output u8 bool flag.&lt;br /&gt;
&lt;br /&gt;
[S1] Web-applets use this command to check if the system needs an update.&lt;br /&gt;
&lt;br /&gt;
== UpdateSafeSystemVersionForDebug ==&lt;br /&gt;
Takes an input u32 &#039;&#039;&#039;version&#039;&#039;&#039; and an [[NCM_services#ApplicationId|ApplicationId]].&lt;br /&gt;
&lt;br /&gt;
This command is not available for retail units. On a debug unit, if the [[System_Settings|system setting]] &amp;lt;code&amp;gt;vulnerability!enable_debug&amp;lt;/code&amp;gt; is set, this mounts the system savegame [[Flash_Filesystem#System_Savegames|0x8000000000000049]] as &amp;quot;ns_ssversion:/&amp;quot;, opens the file &amp;quot;ns_ssversion:/entry&amp;quot; and writes the supplied [[NCM_services#ApplicationId|ApplicationId]] and &#039;&#039;&#039;version&#039;&#039;&#039; in it.&lt;br /&gt;
&lt;br /&gt;
Finally, it calls [[NCM_services#ncm|OpenContentMetaDatabase]] with [[NCM_services#StorageId|StorageId]] 3, then calls [[NCM_services#IContentMetaDatabase|GetLatestContentMetaKey]] with the supplied [[NCM_services#ApplicationId|ApplicationId]] and compares the version field from the returned [[CNMT#Content_Meta_Records|Content Meta Record]] with the supplied &#039;&#039;&#039;version&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
If the supplied &#039;&#039;&#039;version&#039;&#039;&#039; is higher than the one in NCM&#039;s database, the value returned by [[NS_Services#NeedsUpdateVulnerability|NeedsUpdateVulnerability]] is set to &amp;quot;true&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== GetSafeSystemVersion ==&lt;br /&gt;
No input, returns an output [[NCM_services#ContentMetaKey|ContentMetaKey]] with the cached contents of &amp;quot;ns_ssversion:/entry&amp;quot; ([[NCM_services#ApplicationId|ApplicationId]], u32 &#039;&#039;&#039;version&#039;&#039;&#039; and u32 &#039;&#039;&#039;policy&#039;&#039;&#039; from &amp;lt;code&amp;gt;vulnerability!needs_update_vulnerability_policy&amp;lt;/code&amp;gt;).&lt;br /&gt;
&lt;br /&gt;
== GetSafeSystemVersionCheckInfo ==&lt;br /&gt;
No input, returns 0x10-bytes of output.&lt;br /&gt;
&lt;br /&gt;
[22.0.0+] Now returns 0x20-bytes of output.&lt;br /&gt;
&lt;br /&gt;
[S2] Used by web-applets via ns:vm.&lt;br /&gt;
&lt;br /&gt;
== RequestUpdateSafeSystemVersionCheckInfo ==&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncResult|IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
[S2] Used by web-applets via ns:vm.&lt;br /&gt;
&lt;br /&gt;
The async task thread uses [[NIM_services|nim]] RequestCheckSafeSystemVersion, etc.&lt;br /&gt;
&lt;br /&gt;
== ResetSafeSystemVersionCheckInfo ==&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
This throws an error if [[Settings_services|GetDebugModeFlag]] returns false.&lt;br /&gt;
&lt;br /&gt;
= ns:su =&lt;br /&gt;
This is &amp;quot;nn::ns::detail::ISystemUpdateInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#GetBackgroundNetworkUpdateState]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#OpenSystemUpdateControl]]&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [[#NotifyExFatDriverRequired]]&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [[#ClearExFatDriverStatusForDebug]]&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [[#RequestBackgroundNetworkUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 5 || [[#NotifyBackgroundNetworkUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 6 || [[#NotifyExFatDriverDownloadedForDebug]]&lt;br /&gt;
|-&lt;br /&gt;
| 9 || [[#GetSystemUpdateNotificationEventForContentDelivery]]&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [[#NotifySystemUpdateForContentDelivery]]&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [3.0.0+] [[#PrepareShutdown]]&lt;br /&gt;
|-&lt;br /&gt;
| 12 || [3.0.0-3.0.2]&lt;br /&gt;
|-&lt;br /&gt;
| 13 || [3.0.0-3.0.2]&lt;br /&gt;
|-&lt;br /&gt;
| 14 || [3.0.0-3.0.2]&lt;br /&gt;
|-&lt;br /&gt;
| 15 || [3.0.0-3.0.2]&lt;br /&gt;
|-&lt;br /&gt;
| 16 || [4.0.0+] [[#DestroySystemUpdateTask]]&lt;br /&gt;
|-&lt;br /&gt;
| 17 || [4.0.0+] [[#RequestSendSystemUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 18 || [4.0.0+] [[#GetSendSystemUpdateProgress]]&lt;br /&gt;
|-&lt;br /&gt;
| 19 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 20 || [S2]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== GetBackgroundNetworkUpdateState ==&lt;br /&gt;
No input, returns an output [[#BackgroundNetworkUpdateState]].&lt;br /&gt;
&lt;br /&gt;
This is similar to [[#HasDownloaded]], see [[#BackgroundNetworkUpdateState]].&lt;br /&gt;
&lt;br /&gt;
== OpenSystemUpdateControl ==&lt;br /&gt;
No input, returns an [[#ISystemUpdateControl]].&lt;br /&gt;
&lt;br /&gt;
Only 1 ISystemUpdateControl can be open at a time.&lt;br /&gt;
&lt;br /&gt;
== NotifyExFatDriverRequired ==&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Only usable when an [[#ISystemUpdateControl]] isn&#039;t open.&lt;br /&gt;
&lt;br /&gt;
This uses [[NIM_services|nim]] ListSystemUpdateTask, then when a task is returned uses it with DestroySystemUpdateTask.&lt;br /&gt;
&lt;br /&gt;
Then this runs ExFat handling, updates state, and sets the same state flag as [[#RequestBackgroundNetworkUpdate]].&lt;br /&gt;
&lt;br /&gt;
== ClearExFatDriverStatusForDebug ==&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
== RequestBackgroundNetworkUpdate ==&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Only usable when an [[#ISystemUpdateControl]] isn&#039;t open.&lt;br /&gt;
&lt;br /&gt;
This sets a state flag to value 1.&lt;br /&gt;
&lt;br /&gt;
== NotifyBackgroundNetworkUpdate ==&lt;br /&gt;
Takes an input [[NCM_services#ContentMetaKey|ContentMetaKey]], no output.&lt;br /&gt;
&lt;br /&gt;
This checks whether a sysupdate is needed with the input ContentMetaKey using [[NCM_services|NCM]] commands, if not this will just return 0. Otherwise, this will then run code which is identical to [[#RequestBackgroundNetworkUpdate]].&lt;br /&gt;
&lt;br /&gt;
== NotifyExFatDriverDownloadedForDebug ==&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
== GetSystemUpdateNotificationEventForContentDelivery ==&lt;br /&gt;
No input, returns an output Event handle with EventClearMode=0.&lt;br /&gt;
&lt;br /&gt;
== NotifySystemUpdateForContentDelivery ==&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Signals the Event returned by [[#GetSystemUpdateNotificationEventForContentDelivery]].&lt;br /&gt;
&lt;br /&gt;
== PrepareShutdown ==&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
This is used by [[AM_services|AM]].&lt;br /&gt;
&lt;br /&gt;
Just returns 0 when an [[#ISystemUpdateControl]] is open. &lt;br /&gt;
&lt;br /&gt;
This does various cleanup / uses various service-cmds etc for shutdown preparation.&lt;br /&gt;
&lt;br /&gt;
== DestroySystemUpdateTask ==&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Only usable when an [[#ISystemUpdateControl]] isn&#039;t open.&lt;br /&gt;
&lt;br /&gt;
This uses [[NIM_services|nim]] ListSystemUpdateTask, then when a task is returned uses it with DestroySystemUpdateTask.&lt;br /&gt;
&lt;br /&gt;
== RequestSendSystemUpdate ==&lt;br /&gt;
Takes a type-0x15 input buffer containing a [[#SystemDeliveryInfo]], an u16 port, an u32 Ipv4Address, returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
[[qlaunch]] uses value 55556 for the port. IP is normally a local-WLAN address, however this can be any address. port/addr are little-endian.&lt;br /&gt;
&lt;br /&gt;
See [[NIM_services|nim]] regarding the input addr/port usage, etc.&lt;br /&gt;
&lt;br /&gt;
[11.0.0+] An error is thrown if LocalContentShare is not [[#IsLocalContentShareEnabled|enabled]].&lt;br /&gt;
&lt;br /&gt;
This validates the [[#SystemDeliveryInfo]] and generates a [[NCM_services#ContentMetaKey|ContentMetaKey]] from that, and creates the [[#IAsyncResult]] + the async thread which handles the [[#IAsyncResult]] operation.&lt;br /&gt;
&lt;br /&gt;
The above validation verifies that the HMAC and SystemDeliveryProtocolVersion are valid. The OldSystemUpdateId ([20.0.0+] SystemUpdateId, SystemUpdateIdFlag ignored) must match the Id for the installed SystemUpdate as returned by [[NCM_services|ncm]].&lt;br /&gt;
&lt;br /&gt;
Then the thread does:&lt;br /&gt;
* Calls a func which does:&lt;br /&gt;
** Uses [[NIM_services|nim]] CreateLocalCommunicationSendSystemUpdateTask, returning the Result on failure.&lt;br /&gt;
*** The input firmware_variation is from the [[#SystemDeliveryInfo|FirmwareVariationId]].&lt;br /&gt;
** Uses [[NIM_services|nim]] RequestLocalCommunicationSendSystemUpdateTaskRun, returning the Result on failure. Waits for the IAsyncResult operation from this to finish, then uses the Get cmd to get the output Result.&lt;br /&gt;
*** When the Result from Get is an error, a func is called for filling in the [[#IAsyncResult|IAsyncResult]] ErrorContext with Type4.&lt;br /&gt;
** Handles cleanup and returns.&lt;br /&gt;
* Unlike [[#RequestReceiveSystemUpdate]], this doesn&#039;t save a SystemPlayReport.&lt;br /&gt;
&lt;br /&gt;
== GetSendSystemUpdateProgress ==&lt;br /&gt;
No input, returns an output [[#SystemUpdateProgress]].&lt;br /&gt;
&lt;br /&gt;
Same as [[#GetReceiveProgress]] except this uses nim ListLocalCommunicationSendSystemUpdateTask and GetLocalCommunicationSendSystemUpdateTaskInfo. The data copied to output is also swapped: u64 nim_out+0x8 is copied to out+0x8, and u64 nim_out+0x10 is copied to out+0x0.&lt;br /&gt;
&lt;br /&gt;
== Cmd19 ==&lt;br /&gt;
This is exclusive to S2.&lt;br /&gt;
&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
== Cmd20 ==&lt;br /&gt;
This is exclusive to S2.&lt;br /&gt;
&lt;br /&gt;
No input, returns an output u8.&lt;br /&gt;
&lt;br /&gt;
== ISystemUpdateControl ==&lt;br /&gt;
This is &amp;quot;nn::ns::detail::ISystemUpdateControl&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#HasDownloaded]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#RequestCheckLatestUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [[#RequestDownloadLatestUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [[#GetDownloadProgress]]&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [[#ApplyDownloadedUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 5 || [[#RequestPrepareCardUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 6 || [[#GetPrepareCardUpdateProgress]]&lt;br /&gt;
|-&lt;br /&gt;
| 7 || [[#HasPreparedCardUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 8 || [[#ApplyCardUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 9 || [[#GetDownloadedEulaDataSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [[#GetDownloadedEulaData]]&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [[#SetupCardUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 12 || [[#GetPreparedCardUpdateEulaDataSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 13 || [[#GetPreparedCardUpdateEulaData]]&lt;br /&gt;
|-&lt;br /&gt;
| 14 || [4.0.0+] [[#SetupCardUpdateViaSystemUpdater]]&lt;br /&gt;
|-&lt;br /&gt;
| 15 || [4.0.0+] [[#HasReceived]]&lt;br /&gt;
|-&lt;br /&gt;
| 16 || [4.0.0+] [[#RequestReceiveSystemUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 17 || [4.0.0+] [[#GetReceiveProgress]]&lt;br /&gt;
|-&lt;br /&gt;
| 18 || [4.0.0+] [[#ApplyReceivedUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 19 || [4.0.0+] [[#GetReceivedEulaDataSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 20 || [4.0.0+] [[#GetReceivedEulaData]]&lt;br /&gt;
|-&lt;br /&gt;
| 21 || [4.0.0+] [[#SetupToReceiveSystemUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 22 || [6.0.0+] [[#RequestCheckLatestUpdateIncludesRebootlessUpdate]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
All Card cmds except SetupCardUpdate* require [[#SetupCardUpdate]]/[[#SetupCardUpdateViaSystemUpdater]] to be used previously. [[#GetPreparedCardUpdateEulaDataSize]]/[[#GetPreparedCardUpdateEulaData]] checks a different state flag.&lt;br /&gt;
&lt;br /&gt;
=== HasDownloaded ===&lt;br /&gt;
No input, returns an output u8 bool flag.&lt;br /&gt;
&lt;br /&gt;
Gets whether a network sysupdate was downloaded, with install pending.&lt;br /&gt;
&lt;br /&gt;
Uses [[NIM_services|nim]] ListSystemUpdateTask and [[NIM_services|nim]] GetSystemUpdateTaskInfo. When ListSystemUpdateTask successfully returns a task and GetSystemUpdateTaskInfo is successful, the output flag is set to: &amp;lt;code&amp;gt;*((u8*)(taskinfo+0) == 0x3&amp;lt;/code&amp;gt;. Otherwise, flag=0.&lt;br /&gt;
&lt;br /&gt;
This always returns 0, however this will assert if GetSystemUpdateTaskInfo fails with ret!=0x3C89.&lt;br /&gt;
&lt;br /&gt;
=== RequestCheckLatestUpdate ===&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
The data that can be read from the [[#IAsyncValue]] is [[#LatestSystemUpdate]].&lt;br /&gt;
&lt;br /&gt;
=== RequestDownloadLatestUpdate ===&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
=== GetDownloadProgress ===&lt;br /&gt;
No input, returns an output [[#SystemUpdateProgress]].&lt;br /&gt;
&lt;br /&gt;
Similar to [[#HasDownloaded]] except instead of a flag, this returns the 0x10-bytes from taskinfo+8. The output struct is cleared when the task(info) isn&#039;t available.&lt;br /&gt;
&lt;br /&gt;
=== ApplyDownloadedUpdate ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Runs code similar to [[#HasDownloaded]], throwing an error if a network sysupdate isn&#039;t ready for install. Then the sysupdate is installed:&lt;br /&gt;
&lt;br /&gt;
* Uses ListSystemUpdateTask again, then [[NIM_services|nim]] IsExFatDriverIncluded. Runs ExFat handling when the output flag is set.&lt;br /&gt;
* On newer system-versions, this uses [[NIM_services|nim]] GetSystemUpdateTaskInfo then on success uses data from there to save a SystemPlayReport when the cached [[System_Settings|system-setting]] &amp;quot;systemreport!enabled&amp;quot; is set.&lt;br /&gt;
** The EventId is &amp;quot;systemupdate_dl_throughput&amp;quot; with ApplicationId 0100000000001018.&lt;br /&gt;
** The following fields are added to the report, see [[NIM_services#SystemUpdateTaskInfo|nim SystemUpdateTaskInfo]]: &amp;quot;ContentMetaId&amp;quot;, &amp;quot;Version&amp;quot;, &amp;quot;DownloadSize&amp;quot;, and &amp;quot;ThroughputKBps&amp;quot;.&lt;br /&gt;
* On newer system-versions, this saves another SystemPlayReport when a state flag is set (same flag mentioned above).&lt;br /&gt;
** The EventId is &amp;quot;systemupdate_pass&amp;quot; with ApplicationId 0100000000001021.&lt;br /&gt;
** This report has the following fields:&lt;br /&gt;
*** &amp;quot;Type&amp;quot;&lt;br /&gt;
*** &amp;quot;SourceSystemUpdateMetaId&amp;quot;&lt;br /&gt;
*** &amp;quot;SourceSystemUpdateMetaVersion&amp;quot;&lt;br /&gt;
*** &amp;quot;SourceExFatStatus&amp;quot;&lt;br /&gt;
*** &amp;quot;DestinationSystemUpdateMetaId&amp;quot;&lt;br /&gt;
*** &amp;quot;DestinationSystemUpdateMetaVersion&amp;quot;&lt;br /&gt;
*** &amp;quot;DestinationExFatStatus&amp;quot;&lt;br /&gt;
*** &amp;quot;Rebootless&amp;quot;&lt;br /&gt;
* Since BootImagePackage will be installed later, the two flags in [[Flash_Filesystem#System_Update_Control]] are set to 1.&lt;br /&gt;
* Uses [[NIM_services|nim]] CommitSystemUpdateTask and [[NIM_services|nim]] DestroySystemUpdateTask.&lt;br /&gt;
* Installs BootImagePackage. After installing each BootImagePackage, the associated flag in [[Flash_Filesystem#System_Update_Control]] is set to 0.&lt;br /&gt;
* On newer system versions when an input flag is set, this uses [[Filesystem_services|NotifySystemDataUpdateEvent]], however this doesn&#039;t happen with ApplyDownloadedUpdate since that input flag is 0.&lt;br /&gt;
&lt;br /&gt;
=== RequestPrepareCardUpdate ===&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
=== GetPrepareCardUpdateProgress ===&lt;br /&gt;
No input, returns an output [[#SystemUpdateProgress]].&lt;br /&gt;
&lt;br /&gt;
=== HasPreparedCardUpdate ===&lt;br /&gt;
No input, returns an output u8 bool flag.&lt;br /&gt;
&lt;br /&gt;
=== ApplyCardUpdate ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
=== GetDownloadedEulaDataSize ===&lt;br /&gt;
Takes a type-0x15 input buffer [[#EulaDataPath]], returns an output u64 &#039;&#039;&#039;filesize&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
Runs code similar to [[#HasDownloaded]], throwing an error if a network sysupdate isn&#039;t ready for install.&lt;br /&gt;
&lt;br /&gt;
Uses ListSystemUpdateTask again. Then [[NIM_services|nim]] GetDownloadedSystemDataPath, with the output ContentPath being used to mount the EULA title with FS.&lt;br /&gt;
&lt;br /&gt;
Then &amp;quot;&amp;lt;mountname&amp;gt;:/&amp;lt;[[#EulaDataPath]]&amp;gt;&amp;quot; is opened, gets the &#039;&#039;&#039;filesize&#039;&#039;&#039;, then runs cleanup.&lt;br /&gt;
&lt;br /&gt;
=== GetDownloadedEulaData ===&lt;br /&gt;
Takes a type-0x15 input buffer [[#EulaDataPath]] and a type-0x6 output buffer, returns an output u64 &#039;&#039;&#039;filesize&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
Similar to [[#GetDownloadedEulaDataSize]] except this reads the file instead, using the specified output buffer with size=filesize. This will throw an error if the filesize is larger than the buffer size.&lt;br /&gt;
&lt;br /&gt;
=== SetupCardUpdate ===&lt;br /&gt;
Takes an input u64 size and a TransferMemory handle, no output.&lt;br /&gt;
&lt;br /&gt;
Official sw creates the TransferMemory with an user-specified buffer, with permissions=None.&lt;br /&gt;
&lt;br /&gt;
[[qlaunch]] uses size 0x100000 for the TransferMemory buffer.&lt;br /&gt;
&lt;br /&gt;
=== GetPreparedCardUpdateEulaDataSize ===&lt;br /&gt;
Takes a type-0x15 input buffer [[#EulaDataPath]], returns an output u64 &#039;&#039;&#039;filesize&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
This is similar to [[#GetDownloadedEulaDataSize]].&lt;br /&gt;
&lt;br /&gt;
=== GetPreparedCardUpdateEulaData ===&lt;br /&gt;
Takes a type-0x15 input buffer [[#EulaDataPath]] and a type-0x6 output buffer, returns an output u64 &#039;&#039;&#039;filesize&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
This is similar to [[#GetDownloadedEulaData]].&lt;br /&gt;
&lt;br /&gt;
=== SetupCardUpdateViaSystemUpdater ===&lt;br /&gt;
Takes an input u64 size and a TransferMemory handle, no output.&lt;br /&gt;
&lt;br /&gt;
The permissions for the TransferMemory is None.&lt;br /&gt;
&lt;br /&gt;
Same as [[#SetupCardUpdate]], except this doesn&#039;t have the code for [[Filesystem_services|GetGameCardHandle/GetGameCardUpdatePartitionInfo]], and uses [[Filesystem_services|OpenRegisteredUpdatePartition]] instead of [[Filesystem_services|OpenGameCardFileSystem]]. This uses the same is_initialized bool state flag.&lt;br /&gt;
&lt;br /&gt;
=== HasReceived ===&lt;br /&gt;
No input, returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
Same as [[#HasDownloaded]] except this uses [[NIM_services|nim]] ListLocalCommunicationReceiveSystemUpdateTask and GetLocalCommunicationReceiveSystemUpdateTaskInfo.&lt;br /&gt;
&lt;br /&gt;
=== RequestReceiveSystemUpdate ===&lt;br /&gt;
Takes a type-0x15 input buffer containing a [[#SystemDeliveryInfo]], an u16 port, an u32 Ipv4Address, returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
[[qlaunch]] uses the same value for the port as [[#RequestSendSystemUpdate]] (see [[#RequestSendSystemUpdate]] for addr as well).&lt;br /&gt;
&lt;br /&gt;
See [[NIM_services|nim]] regarding the input addr/port usage, etc.&lt;br /&gt;
&lt;br /&gt;
This uses the same LocalContentShare check as [[#RequestSendSystemUpdate|RequestSendSystemUpdate]].&lt;br /&gt;
&lt;br /&gt;
An error is thrown if a state flag is clear.&lt;br /&gt;
&lt;br /&gt;
This validates the [[#SystemDeliveryInfo]] (same as [[#RequestSendSystemUpdate|RequestSendSystemUpdate]]) and generates a [[NCM_services#ContentMetaKey|ContentMetaKey]] from that, and creates the [[#IAsyncResult]] + the async thread which handles the [[#IAsyncResult]] operation.&lt;br /&gt;
&lt;br /&gt;
Then the thread does:&lt;br /&gt;
&lt;br /&gt;
* Calls a func which does:&lt;br /&gt;
** Throws an error if [[NIM_services#ListSystemUpdateTask|ListSystemUpdateTask]] returns any task.&lt;br /&gt;
** Checks whether a sysupdate is actually required using the previously generated [[NCM_services#ContentMetaKey|ContentMetaKey]] (this func is also passed the below statefield as the last param), throwing an error if not.&lt;br /&gt;
*** [20.0.0+] The above check-sysupdate func was updated (which is also used elsewhere), flag handling during the loop was updated (which uses the last input param).&lt;br /&gt;
** Uses [[NIM_services|nim]] CreateLocalCommunicationReceiveSystemUpdateTask, returning the Result on failure.&lt;br /&gt;
*** The input firmware_variation is from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;ns.systemupdate!firmware_variation&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;ns.systemupdate!t_firmware_variation&amp;lt;/code&amp;gt;, depending on the [[Settings_services|PlatformRegion]] (value 0xFF is used when the output setting-size is invalid).&lt;br /&gt;
*** The input &#039;&#039;&#039;unk&#039;&#039;&#039; is set to: &amp;lt;code&amp;gt;unk = statefield == 0 ? 0x4 : 0xC&amp;lt;/code&amp;gt; ([20.0.0+] uses statefield &amp;amp; 1 == 0). [20.0.0+] Additional data is now ORRed with unk afterwards: &amp;lt;code&amp;gt;unk |= ((statefield&amp;gt;&amp;gt;1) &amp;amp; 0x3) &amp;lt;&amp;lt; 8;&amp;lt;/code&amp;gt; (same statefield as before)&lt;br /&gt;
** Uses [[NIM_services|nim]] RequestLocalCommunicationReceiveSystemUpdateTaskRun, returning the Result on failure. Waits for the IAsyncResult operation from this to finish, then uses the Get cmd to get the output Result.&lt;br /&gt;
*** When the Result from Get is an error, a func is called for filling in the [[#IAsyncResult|IAsyncResult]] ErrorContext with Type4.&lt;br /&gt;
** Handles cleanup and returns.&lt;br /&gt;
* On success, this loads various data which is then used for saving a SystemPlayReport when the cached [[System_Settings|system-setting]] &amp;quot;systemreport!enabled&amp;quot; is set.&lt;br /&gt;
** The EventId is &amp;quot;receive_system_update&amp;quot; with ApplicationId &amp;lt;NS ProgramId&amp;gt;.&lt;br /&gt;
** This report has the following fields: &lt;br /&gt;
*** &amp;quot;SourceSystemUpdateId&amp;quot;&lt;br /&gt;
*** &amp;quot;DestinationSystemUpdateId&amp;quot;&lt;br /&gt;
*** &amp;quot;SourceSystemUpdateVersion&amp;quot;&lt;br /&gt;
*** &amp;quot;DestinationSystemUpdateVersion&amp;quot;&lt;br /&gt;
*** &amp;quot;SenderFirmwareVariationId&amp;quot;&lt;br /&gt;
*** &amp;quot;ReceiverFirmwareVariationId&amp;quot;&lt;br /&gt;
*** &amp;quot;SenderPlatformRegion&amp;quot;&lt;br /&gt;
*** &amp;quot;ReceiverPlatformRegion&amp;quot;&lt;br /&gt;
*** &amp;quot;SenderHasExFat&amp;quot;&lt;br /&gt;
*** &amp;quot;ReceiverHasExFat&amp;quot;&lt;br /&gt;
*** &amp;quot;Size&amp;quot;&lt;br /&gt;
*** &amp;quot;ThroughputKBps&amp;quot;&lt;br /&gt;
&lt;br /&gt;
=== GetReceiveProgress ===&lt;br /&gt;
No input, returns an output [[#SystemUpdateProgress]].&lt;br /&gt;
&lt;br /&gt;
Same as [[#GetDownloadProgress]] except this uses [[NIM_services|nim]] ListLocalCommunicationReceiveSystemUpdateTask and GetLocalCommunicationReceiveSystemUpdateTaskInfo.&lt;br /&gt;
&lt;br /&gt;
=== ApplyReceivedUpdate ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
This uses the same LocalContentShare check as [[#RequestSendSystemUpdate|RequestSendSystemUpdate]].&lt;br /&gt;
&lt;br /&gt;
=== GetReceivedEulaDataSize ===&lt;br /&gt;
Takes a type-0x15 input buffer [[#EulaDataPath]], returns an output u64 &#039;&#039;&#039;filesize&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
This is similar to [[#GetDownloadedEulaDataSize]].&lt;br /&gt;
&lt;br /&gt;
=== GetReceivedEulaData ===&lt;br /&gt;
Takes a type-0x15 input buffer [[#EulaDataPath]] and a type-0x6 output buffer, returns an output u64 &#039;&#039;&#039;filesize&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
This is similar to [[#GetDownloadedEulaData]].&lt;br /&gt;
&lt;br /&gt;
=== SetupToReceiveSystemUpdate ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
This just uses [[NIM_services|nim]] ListSystemUpdateTask, then when a task is returned uses it with DestroySystemUpdateTask.&lt;br /&gt;
&lt;br /&gt;
[[qlaunch]] uses this before [[#RequestReceiveSystemUpdate]].&lt;br /&gt;
&lt;br /&gt;
=== RequestCheckLatestUpdateIncludesRebootlessUpdate ===&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
= IAsyncValue =&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IAsyncValue&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetSize&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Get&lt;br /&gt;
|-&lt;br /&gt;
| 2 || Cancel&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [4.0.0+] GetErrorContext&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Official sw creates a container object for this using the output from the service commands, which contains the IAsyncValue object, and the Event with EventClearMode=0.&lt;br /&gt;
&lt;br /&gt;
* GetSize: No input, returns an output u64.&lt;br /&gt;
* Get: Takes a type-0x6 output buffer, no output. Official sw waits on the Event prior to using this cmd.&lt;br /&gt;
* Cancel: No input/output. Used by official sw when closing the object, when the serv-obj is initialized (after using the cmd, official sw will also wait on the Event). This cmd is also used in other official sw funcs.&lt;br /&gt;
* GetErrorContext: No input/output, takes a type-0x16 output buffer containing an [[Error_Applet#ErrorContext|ErrorContext]].&lt;br /&gt;
&lt;br /&gt;
= IAsyncResult =&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IAsyncResult&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || Get&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Cancel&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [4.0.0+] GetErrorContext&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Official sw creates a container object for this using the output from the service commands, which contains the IAsyncResult object, and the Event with EventClearMode=0.&lt;br /&gt;
&lt;br /&gt;
* Get: No input/output. Official sw waits on the Event prior to using this cmd.&lt;br /&gt;
* Cancel: No input/output. Used by official sw when closing the object, when the serv-obj is initialized (after using the cmd, official sw will also wait on the Event). This cmd is also used in other official sw funcs.&lt;br /&gt;
* GetErrorContext: No input/output, takes a type-0x16 output buffer containing an [[Error_Applet#ErrorContext|ErrorContext]].&lt;br /&gt;
&lt;br /&gt;
= ns:dev =&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IDevelopInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
[10.0.0+] Some of these cmds were replaced by the [[PGL_services|pgl]] system module.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [1.0.0-9.2.0] [[#LaunchProgram]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#TerminateProcess]]&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [1.0.0-9.2.0] [[#TerminateProgram]]&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [1.0.0-9.2.0] [[#GetShellEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 5 || [1.0.0-9.2.0] [[#GetShellEventInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 6 || [[#TerminateApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 7 || [1.0.0-9.2.0] [[#PrepareLaunchProgramFromHost]]&lt;br /&gt;
|-&lt;br /&gt;
| 8 || [10.0.0-17.0.1] [[#LaunchApplicationFromHost]] ([1.0.0-9.2.0] LaunchApplication)&lt;br /&gt;
|-&lt;br /&gt;
| 9 || [1.0.0-17.0.1] [[#LaunchApplicationWithStorageId]]&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [6.0.0-8.1.0] [[#IsSystemMemoryResourceLimitBoosted]]&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [6.0.0+] [[#GetRunningApplicationProcessId]]&lt;br /&gt;
|-&lt;br /&gt;
| 12 || [6.0.0+] [[#SetCurrentApplicationRightsEnvironmentCanBeActive]]&lt;br /&gt;
|-&lt;br /&gt;
| 13 || [9.0.0+] [[#CreateApplicationResource]]&lt;br /&gt;
|-&lt;br /&gt;
| 14 || [9.0.0+] [[#IsPreomia]]&lt;br /&gt;
|-&lt;br /&gt;
| 15 || [10.0.0-17.0.1] [[#GetApplicationProgramIdFromHost]]&lt;br /&gt;
|-&lt;br /&gt;
| 16 || [12.0.0+] RefreshCachedDebugValues&lt;br /&gt;
|-&lt;br /&gt;
| 17 || [12.0.0+] [[#PrepareLaunchApplicationFromHost]]&lt;br /&gt;
|-&lt;br /&gt;
| 18 || [12.0.0+] [[#GetLaunchEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 19 || [12.0.0+] [[#GetLaunchResult]]&lt;br /&gt;
|-&lt;br /&gt;
| 20 || [14.0.0+] GetProgramId&lt;br /&gt;
|-&lt;br /&gt;
| 21 || [18.0.0+] [[#PrepareLaunchApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 22 || [18.0.0+] [[#LaunchApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 23 || [18.0.0+] [[#GetProgramIdByApplicationLaunchInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 24 || [18.0.0+] DestroyApplicationLaunchPreparation&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== LaunchProgram ==&lt;br /&gt;
Wrapper for &amp;quot;pm:shell&amp;quot; [[Process_Manager_services#pm:shell|LaunchProcess]].&lt;br /&gt;
&lt;br /&gt;
== TerminateProcess ==&lt;br /&gt;
Wrapper for &amp;quot;pm:shell&amp;quot; [[Process_Manager_services#pm:shell|TerminateProcess]].&lt;br /&gt;
&lt;br /&gt;
== TerminateProgram ==&lt;br /&gt;
Wrapper for &amp;quot;pm:shell&amp;quot; [[Process_Manager_services#pm:shell|TerminateProgram]].&lt;br /&gt;
&lt;br /&gt;
== GetShellEvent ==&lt;br /&gt;
Wrapper for &amp;quot;pm:shell&amp;quot; [[Process_Manager_services#pm:shell|GetProcessEventHandle]].&lt;br /&gt;
&lt;br /&gt;
== GetShellEventInfo ==&lt;br /&gt;
Wrapper for &amp;quot;pm:shell&amp;quot; [[Process_Manager_services#pm:shell|GetProcessEventInfo]].&lt;br /&gt;
&lt;br /&gt;
== TerminateApplication ==&lt;br /&gt;
Calls &amp;quot;pm:shell&amp;quot; [[Process_Manager_services#pm:shell|GetApplicationProcessIdForShell]] and sends the ProcessId to [[Process_Manager_services#pm:shell|TerminateProcess]].&lt;br /&gt;
&lt;br /&gt;
== PrepareLaunchProgramFromHost ==&lt;br /&gt;
Takes a type-0x5 input buffer containing the [[Filesystem_services#FspPath|FspPath]], returns an output 0x10-byte struct.&lt;br /&gt;
&lt;br /&gt;
Calls [[NCM_services#IPathResolverForStorage|IPathResolverForStorage]] Set...NcaPath functions.&lt;br /&gt;
&lt;br /&gt;
== LaunchApplicationFromHost ==&lt;br /&gt;
Takes an input u32 [[Process_Manager_services#LaunchFlags|LaunchFlags]] and a type-0x5 input buffer containing the [[Filesystem_services#FspPath|FspPath]]. Returns an output u64 ProcessId.&lt;br /&gt;
&lt;br /&gt;
== LaunchApplicationWithStorageId ==&lt;br /&gt;
Takes 2 input u8 [[NCM_services#StorageId|StorageIds]], an u32 [[Process_Manager_services#LaunchFlags|LaunchFlags]], and an [[NCM_services#ApplicationId|ApplicationId]]. Returns an output u64 ProcessId.&lt;br /&gt;
&lt;br /&gt;
Launches an application title which is registered with NS.&lt;br /&gt;
&lt;br /&gt;
== IsSystemMemoryResourceLimitBoosted ==&lt;br /&gt;
No input. Returns a bool.&lt;br /&gt;
&lt;br /&gt;
== GetRunningApplicationProcessId ==&lt;br /&gt;
Returns an output u64 ProcessId.&lt;br /&gt;
&lt;br /&gt;
== SetCurrentApplicationRightsEnvironmentCanBeActive ==&lt;br /&gt;
Takes an input bool. No output.&lt;br /&gt;
&lt;br /&gt;
== CreateApplicationResource ==&lt;br /&gt;
Takes an input u32 (1 = Preomia/MicroApplication). Returns an [[#IApplicationResource]].&lt;br /&gt;
&lt;br /&gt;
== IsPreomia ==&lt;br /&gt;
Takes an input u64 [[NCM_services#ProgramId|ProgramId]]. Returns a bool.&lt;br /&gt;
&lt;br /&gt;
== GetApplicationProgramIdFromHost ==&lt;br /&gt;
Takes a type-0x5 input buffer containing the [[Filesystem_services#FspPath|FspPath]]. Returns an u64 [[NCM_services#ProgramId|ProgramId]].&lt;br /&gt;
&lt;br /&gt;
== PrepareLaunchApplicationFromHost ==&lt;br /&gt;
[18.0.0+] Now returns a total of 0x50 bytes of output.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] Now returns a total of 0x80 bytes of output.&lt;br /&gt;
&lt;br /&gt;
== GetLaunchEvent ==&lt;br /&gt;
[18.0.0+] Now takes a total of 0x50 bytes of input.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] Now takes a total of 0x80 bytes of input.&lt;br /&gt;
&lt;br /&gt;
== GetLaunchResult ==&lt;br /&gt;
[18.0.0+] Now takes a total of 0x50 bytes of input.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] Now takes a total of 0x80 bytes of input.&lt;br /&gt;
&lt;br /&gt;
== PrepareLaunchApplication ==&lt;br /&gt;
Takes a total of 0x10-bytes of input. Returns a total of 0x50-bytes of output.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] Now returns a total of 0x80-bytes of output.&lt;br /&gt;
&lt;br /&gt;
== LaunchApplication ==&lt;br /&gt;
Takes a total of 0x50-bytes of input. Returns a total of 8-bytes of output.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] Now takes a total of 0x80 bytes of input.&lt;br /&gt;
&lt;br /&gt;
== GetProgramIdByApplicationLaunchInfo ==&lt;br /&gt;
Takes a total of 0x50-bytes of input. Returns a total of 8-bytes of output.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] Now takes a total of 0x80 bytes of input.&lt;br /&gt;
&lt;br /&gt;
= acc:su =&lt;br /&gt;
This is &amp;quot;nn::account::IAccountServiceForAdministrator&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
[13.0.0+] This was moved from [[Account_services|account]].&lt;br /&gt;
&lt;br /&gt;
This is only available when the output from [[Process_Manager_services|pm:bm]] GetBootMode is Normal/Maintenance.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetUserCount ||&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GetUserExistence ||&lt;br /&gt;
|-&lt;br /&gt;
| 2 || ListAllUsers ||&lt;br /&gt;
|-&lt;br /&gt;
| 3 || ListOpenUsers ||&lt;br /&gt;
|-&lt;br /&gt;
| 4 || GetLastOpenedUser ||&lt;br /&gt;
|-&lt;br /&gt;
| 5 || GetProfile || Returns an [[#IProfile]].&lt;br /&gt;
|-&lt;br /&gt;
| 6 || [3.0.0+] GetProfileDigest ||&lt;br /&gt;
|-&lt;br /&gt;
| 50 || [[#IsUserRegistrationRequestPermitted]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 51 || TrySelectUserWithoutInteractionDeprecated ([1.0.0-18.1.0] [[#TrySelectUserWithoutInteraction]]) ||&lt;br /&gt;
|-&lt;br /&gt;
| 52 || [19.0.0+] TrySelectUserWithoutInteraction ||&lt;br /&gt;
|-&lt;br /&gt;
| 60 || [5.0.0-5.1.0] ListOpenContextStoredUsers ||&lt;br /&gt;
|-&lt;br /&gt;
| 99 || [6.0.0+] DebugActivateOpenContextRetention || No input, returns an [[#ISessionObject]].&lt;br /&gt;
|-&lt;br /&gt;
| 100 || GetUserRegistrationNotifier || Returns an [[#INotifier]].&lt;br /&gt;
|-&lt;br /&gt;
| 101 || GetUserStateChangeNotifier || Returns an [[#INotifier]].&lt;br /&gt;
|-&lt;br /&gt;
| 102 || GetBaasAccountManagerForSystemService || Returns an [[#IManagerForSystemService]].&lt;br /&gt;
|-&lt;br /&gt;
| 103 || GetBaasUserAvailabilityChangeNotifier || Returns an [[#INotifier]].&lt;br /&gt;
|-&lt;br /&gt;
| 104 || GetProfileUpdateNotifier || Returns an [[#INotifier]].&lt;br /&gt;
|-&lt;br /&gt;
| 105 || [4.0.0+] CheckNetworkServiceAvailabilityAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 106 || [9.0.0+] GetProfileSyncNotifier ||&lt;br /&gt;
|-&lt;br /&gt;
| 110 || StoreSaveDataThumbnail ||&lt;br /&gt;
|-&lt;br /&gt;
| 111 || ClearSaveDataThumbnail ||&lt;br /&gt;
|-&lt;br /&gt;
| 112 || LoadSaveDataThumbnail ||&lt;br /&gt;
|-&lt;br /&gt;
| 113 || [5.0.0+] GetSaveDataThumbnailExistence ||&lt;br /&gt;
|-&lt;br /&gt;
| 120 || [10.0.0+] ListOpenUsersInApplication ||&lt;br /&gt;
|-&lt;br /&gt;
| 130 || [6.0.0+] ActivateOpenContextRetention || Takes a total of 0x8-bytes of input, returns an [[#ISessionObject]].&lt;br /&gt;
|-&lt;br /&gt;
| 140 || [6.0.0+] ListQualifiedUsers || &lt;br /&gt;
|-&lt;br /&gt;
| 150 || [10.0.0-10.2.0] AuthenticateApplicationAsync || &lt;br /&gt;
|-&lt;br /&gt;
| 151 || [12.0.0+] EnsureSignedDeviceIdentifierCacheForNintendoAccountAsync || &lt;br /&gt;
|-&lt;br /&gt;
| 152 || [12.0.0+] LoadSignedDeviceIdentifierCacheForNintendoAccount ||&lt;br /&gt;
|-&lt;br /&gt;
| 170 || [13.0.0+] GetNasOp2MembershipStateChangeNotifier ||&lt;br /&gt;
|-&lt;br /&gt;
| 190 || [1.0.0-9.2.0] GetUserLastOpenedApplication ||&lt;br /&gt;
|-&lt;br /&gt;
| 191 || [7.0.0-19.0.1] UpdateNotificationReceiverInfo ([5.0.0-5.1.0] ActivateOpenContextHolder) ||&lt;br /&gt;
|-&lt;br /&gt;
| 200 || BeginUserRegistration ||&lt;br /&gt;
|-&lt;br /&gt;
| 201 || CompleteUserRegistration ||&lt;br /&gt;
|-&lt;br /&gt;
| 202 || CancelUserRegistration ||&lt;br /&gt;
|-&lt;br /&gt;
| 203 || DeleteUser ||&lt;br /&gt;
|-&lt;br /&gt;
| 204 || SetUserPosition ||&lt;br /&gt;
|-&lt;br /&gt;
| 205 || GetProfileEditor || Takes an input userID and returns an [[#IProfileEditor]].&lt;br /&gt;
|-&lt;br /&gt;
| 206 || CompleteUserRegistrationForcibly ||&lt;br /&gt;
|-&lt;br /&gt;
| 210 || [3.0.0+] CreateFloatingRegistrationRequest || Returns an [[#IFloatingRegistrationRequest]].&lt;br /&gt;
|-&lt;br /&gt;
| 211 || [8.0.0+] CreateProcedureToRegisterUserWithNintendoAccount || Takes a total of 0x4-bytes of input and a handle, returns an [[#IOAuthProcedureForUserRegistration]].&lt;br /&gt;
|-&lt;br /&gt;
| 212 || [8.0.0+] ResumeProcedureToRegisterUserWithNintendoAccount || Takes a total of 0x14-bytes of input and a handle, returns an [[#IOAuthProcedureForUserRegistration]].&lt;br /&gt;
|-&lt;br /&gt;
| 213 || [17.0.0+] CreateProcedureToCreateUserWithNintendoAccount ||&lt;br /&gt;
|-&lt;br /&gt;
| 214 || [17.0.0+] ResumeProcedureToCreateUserWithNintendoAccount ||&lt;br /&gt;
|-&lt;br /&gt;
| 215 || [17.0.0+] ResumeProcedureToCreateUserWithNintendoAccountAfterApplyResponse ||&lt;br /&gt;
|-&lt;br /&gt;
| 230 || AuthenticateServiceAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 250 || GetBaasAccountAdministrator || Returns an [[#IAdministrator]].&lt;br /&gt;
|-&lt;br /&gt;
| 251 || [20.0.0+] SynchronizeNetworkServiceAccountsSnapshotAsync ||&lt;br /&gt;
|-&lt;br /&gt;
| 290 || ProxyProcedureForGuestLoginWithNintendoAccount || Returns an [[#IOAuthProcedureForExternalNsa]] (formerly [[#IOAuthProcedureForGuestLogin]] with [1.0.0-2.3.0]).&lt;br /&gt;
|-&lt;br /&gt;
| 291 || [3.0.0+] ProxyProcedureForFloatingRegistrationWithNintendoAccount || Returns an [[#IOAuthProcedureForExternalNsa]].&lt;br /&gt;
|-&lt;br /&gt;
| 292 || [20.0.0+] ProxyProcedureForDeviceMigrationAuthenticatingOperatingUser ||&lt;br /&gt;
|-&lt;br /&gt;
| 293 || [20.0.0+] ProxyProcedureForDeviceMigrationDownload ||&lt;br /&gt;
|-&lt;br /&gt;
| 299 || SuspendBackgroundDaemon || Returns an [[#ISessionObject]].&lt;br /&gt;
|-&lt;br /&gt;
| 350 || [20.0.0+] CreateDeviceMigrationUserExportRequest ||&lt;br /&gt;
|-&lt;br /&gt;
| 351 || [20.0.0+] UploadNasCredential ||&lt;br /&gt;
|-&lt;br /&gt;
| 352 || [20.0.0+] CreateDeviceMigrationUserImportRequest ||&lt;br /&gt;
|-&lt;br /&gt;
| 353 || [20.0.0+] DeleteUserMigrationSaveData ||&lt;br /&gt;
|-&lt;br /&gt;
| 400 || [18.0.0+] SetPinCode ||&lt;br /&gt;
|-&lt;br /&gt;
| 401 || [18.0.0+] GetPinCodeLength ||&lt;br /&gt;
|-&lt;br /&gt;
| 402 || [18.0.0-19.0.1] GetPinCode ||&lt;br /&gt;
|-&lt;br /&gt;
| 403 || [20.0.0+] GetPinCodeParity ||&lt;br /&gt;
|-&lt;br /&gt;
| 404 || [20.0.0+] VerifyPinCode ||&lt;br /&gt;
|-&lt;br /&gt;
| 405 || [20.0.0+] IsPinCodeVerificationForbidden ||&lt;br /&gt;
|-&lt;br /&gt;
| 410 || [18.0.0+] GetPinCodeErrorCount ||&lt;br /&gt;
|-&lt;br /&gt;
| 411 || [18.0.0-19.0.1] ResetPinCodeErrorCount ||&lt;br /&gt;
|-&lt;br /&gt;
| 412 || [18.0.0-19.0.1] IncrementPinCodeErrorCount ||&lt;br /&gt;
|-&lt;br /&gt;
| 413 || [20.0.0+] SetPinCodeErrorCount ||&lt;br /&gt;
|-&lt;br /&gt;
| 420 || [19.0.0+] SetStartPenaltyTime || &lt;br /&gt;
|-&lt;br /&gt;
| 421 || [19.0.0+] GetStartPenaltyTime || &lt;br /&gt;
|-&lt;br /&gt;
| 900 || [13.0.0+] SetUserUnqualifiedForDebug ||&lt;br /&gt;
|-&lt;br /&gt;
| 901 || [13.0.0+] UnsetUserUnqualifiedForDebug ||&lt;br /&gt;
|-&lt;br /&gt;
| 902 || [13.0.0+] ListUsersUnqualifiedForDebug ||&lt;br /&gt;
|-&lt;br /&gt;
| 910 || [16.0.0+] RefreshFirmwareSettingsForDebug ||&lt;br /&gt;
|-&lt;br /&gt;
| 997 || [3.0.0+] DebugInvalidateTokenCacheForUser ||&lt;br /&gt;
|-&lt;br /&gt;
| 998 || DebugSetUserStateClose ||&lt;br /&gt;
|-&lt;br /&gt;
| 999 || DebugSetUserStateOpen ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[10.0.0+] DebugSetUserStateClose/DebugSetUserStateOpen now takes an additional 8-bytes of input.&lt;br /&gt;
&lt;br /&gt;
== IsUserRegistrationRequestPermitted ==&lt;br /&gt;
Takes a PID, an input u64 pid_reserved, and returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
== TrySelectUserWithoutInteraction ==&lt;br /&gt;
Takes an input u8 bool isNetworkServiceAccountRequired, returns an output Uid.&lt;br /&gt;
&lt;br /&gt;
== IManagerForSystemService ==&lt;br /&gt;
This is &amp;quot;nn::account::baas::IManagerForSystemService&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || CheckAvailability ||&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GetAccountId ||&lt;br /&gt;
|-&lt;br /&gt;
| 2 || EnsureIdTokenCacheAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [19.0.0+] LoadIdTokenCacheDeprecated ([1.0.0-18.1.0] LoadIdTokenCache) ||&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [19.0.0+] LoadIdTokenCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 100 || SetSystemProgramIdentification ||&lt;br /&gt;
|-&lt;br /&gt;
| 101 || RefreshNotificationTokenAsync || &lt;br /&gt;
|-&lt;br /&gt;
| 110 || GetServiceEntryRequirementCacheForLogin ||&lt;br /&gt;
|-&lt;br /&gt;
| 111 || InvalidateServiceEntryRequirementCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 113 || GetServiceEntryRequirementCacheForOnlinePlay || Takes a total of 0x8-bytes of input, returns a total of 0x4-bytes of output.&lt;br /&gt;
|-&lt;br /&gt;
| 120 || GetNintendoAccountId ||&lt;br /&gt;
|-&lt;br /&gt;
| 121 || CalculateNintendoAccountAuthenticationFingerprint ||&lt;br /&gt;
|-&lt;br /&gt;
| 130 || GetNintendoAccountUserResourceCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 131 || RefreshNintendoAccountUserResourceCacheAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 132 || RefreshNintendoAccountUserResourceCacheAsyncIfSecondsElapsed || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 133 || GetNintendoAccountVerificationUrlCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 134 || RefreshNintendoAccountVerificationUrlCacheAsync ||&lt;br /&gt;
|-&lt;br /&gt;
| 135 || RefreshNintendoAccountVerificationUrlCacheAsyncIfSecondsElapsed ||&lt;br /&gt;
|-&lt;br /&gt;
| 136 || [19.0.0+] GetNintendoAccountUserResourceCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 140 || GetNetworkServiceLicenseCache || &lt;br /&gt;
|-&lt;br /&gt;
| 141 || RefreshNetworkServiceLicenseCacheAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 142 || RefreshNetworkServiceLicenseCacheAsyncIfSecondsElapsed || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 143 || [15.0.0+] GetNetworkServiceLicenseCacheEx ||&lt;br /&gt;
|-&lt;br /&gt;
| 150 || CreateAuthorizationRequest || Returns an [[#IAuthorizationRequest]].&lt;br /&gt;
|-&lt;br /&gt;
| 151 || [22.5.0+] || &lt;br /&gt;
|-&lt;br /&gt;
| 152 || [22.5.0+] || &lt;br /&gt;
|-&lt;br /&gt;
| 153 || [22.5.0+] || &lt;br /&gt;
|-&lt;br /&gt;
| 160 || [15.0.0+] RequiresUpdateNetworkServiceAccountIdTokenCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 161 || [16.0.0+] RequireReauthenticationOfNetworkServiceAccount ||&lt;br /&gt;
|-&lt;br /&gt;
| 180 || [18.0.0-19.0.1] GetRequestForNintendoAccountReauthentication ||&lt;br /&gt;
|-&lt;br /&gt;
| 181 || [20.0.0+] CreateProcedureToReauthenticateNintendoAccount ||&lt;br /&gt;
|-&lt;br /&gt;
| 182 || [20.0.0+] ResumeProcedureToReauthenticateNintendoAccount ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IFloatingRegistrationRequest ==&lt;br /&gt;
This is &amp;quot;nn::account::baas::IFloatingRegistrationRequest&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
Added with [3.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetSessionId ||&lt;br /&gt;
|-&lt;br /&gt;
| 12 || GetAccountId ||&lt;br /&gt;
|-&lt;br /&gt;
| 13 || GetLinkedNintendoAccountId ||&lt;br /&gt;
|-&lt;br /&gt;
| 14 || GetNickname ||&lt;br /&gt;
|-&lt;br /&gt;
| 15 || GetProfileImage ||&lt;br /&gt;
|-&lt;br /&gt;
| 16 || [18.0.0+] GetProfileLargeImage ||&lt;br /&gt;
|-&lt;br /&gt;
| 21 || LoadIdTokenCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 100 || RegisterUser ([1.0.0-3.0.2] RegisterAsync) || [1.0.0-3.0.2] Used to return an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 101 || RegisterUserWithUid ([1.0.0-3.0.2] RegisterWithUidAsync) || [1.0.0-3.0.2] Used to return an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 102 || [4.0.0+] RegisterNetworkServiceAccountAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 103 || [4.0.0+] RegisterNetworkServiceAccountWithUidAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 110 || SetSystemProgramIdentification ||&lt;br /&gt;
|-&lt;br /&gt;
| 111 || EnsureIdTokenCacheAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IAdministrator ==&lt;br /&gt;
This is &amp;quot;nn::account::baas::IAdministrator&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || CheckAvailability ||&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GetAccountId ||&lt;br /&gt;
|-&lt;br /&gt;
| 2 || EnsureIdTokenCacheAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [19.0.0+] LoadIdTokenCacheDeprecated ([1.0.0-18.1.0] LoadIdTokenCache) ||&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [19.0.0+] LoadIdTokenCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 100 || SetSystemProgramIdentification ||&lt;br /&gt;
|-&lt;br /&gt;
| 101 || [7.0.0+] RefreshNotificationTokenAsync&lt;br /&gt;
|-&lt;br /&gt;
| 110 || [4.0.0+] GetServiceEntryRequirementCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 111 || [4.0.0+] InvalidateServiceEntryRequirementCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 112 || [4.0.0-6.2.0] InvalidateTokenCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 113 || [6.1.0+] GetServiceEntryRequirementCacheForOnlinePlay || Takes a total of 0x8-bytes of input, returns a total of 0x4-bytes of output.&lt;br /&gt;
|-&lt;br /&gt;
| 120 || GetNintendoAccountId ||&lt;br /&gt;
|-&lt;br /&gt;
| 121 || [9.0.0+] CalculateNintendoAccountAuthenticationFingerprint ||&lt;br /&gt;
|-&lt;br /&gt;
| 130 || GetNintendoAccountUserResourceCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 131 || RefreshNintendoAccountUserResourceCacheAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 132 || RefreshNintendoAccountUserResourceCacheAsyncIfSecondsElapsed || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 133 || [9.0.0+] GetNintendoAccountVerificationUrlCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 134 || [9.0.0+] RefreshNintendoAccountVerificationUrlCacheAsync ||&lt;br /&gt;
|-&lt;br /&gt;
| 135 || [9.0.0+] RefreshNintendoAccountVerificationUrlCacheAsyncIfSecondsElapsed ||&lt;br /&gt;
|-&lt;br /&gt;
| 136 || [19.0.0+] GetNintendoAccountUserResourceCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 140 || [5.0.0+] GetNetworkServiceLicenseCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 141 || [5.0.0+] RefreshNetworkServiceLicenseCacheAsync ||&lt;br /&gt;
|-&lt;br /&gt;
| 142 || [5.0.0+] RefreshNetworkServiceLicenseCacheAsyncIfSecondsElapsed ||&lt;br /&gt;
|-&lt;br /&gt;
| 143 || [15.0.0+] GetNetworkServiceLicenseCacheEx ||&lt;br /&gt;
|-&lt;br /&gt;
| 150 || CreateAuthorizationRequest || Returns an [[#IAuthorizationRequest]].&lt;br /&gt;
|-&lt;br /&gt;
| 151 || [22.5.0+] || &lt;br /&gt;
|-&lt;br /&gt;
| 152 || [22.5.0+] || &lt;br /&gt;
|-&lt;br /&gt;
| 153 || [22.5.0+] || &lt;br /&gt;
|-&lt;br /&gt;
| 160 || [15.0.0+] RequiresUpdateNetworkServiceAccountIdTokenCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 161 || [16.0.0+] RequireReauthenticationOfNetworkServiceAccount ||&lt;br /&gt;
|-&lt;br /&gt;
| 180 || [18.0.0-19.0.1] GetRequestForNintendoAccountReauthentication ||&lt;br /&gt;
|-&lt;br /&gt;
| 181 || [20.0.0+] CreateProcedureToReauthenticateNintendoAccount ||&lt;br /&gt;
|-&lt;br /&gt;
| 182 || [20.0.0+] ResumeProcedureToReauthenticateNintendoAccount ||&lt;br /&gt;
|-&lt;br /&gt;
| 200 || IsRegistered ||&lt;br /&gt;
|-&lt;br /&gt;
| 201 || RegisterAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 202 || UnregisterAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 203 || DeleteRegistrationInfoLocally ||&lt;br /&gt;
|-&lt;br /&gt;
| 204 || [19.0.0-19.0.1] UnregisterDeviceAsync ||&lt;br /&gt;
|-&lt;br /&gt;
| 220 || SynchronizeProfileAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 221 || UploadProfileAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 222 || SynchronizeProfileAsyncIfSecondsElapsed || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 223 || [19.0.0+] DownloadProfileAsync ||&lt;br /&gt;
|-&lt;br /&gt;
| 250 || IsLinkedWithNintendoAccount ||&lt;br /&gt;
|-&lt;br /&gt;
| 251 || CreateProcedureToLinkWithNintendoAccount || Returns an [[#IOAuthProcedureForNintendoAccountLinkage]].&lt;br /&gt;
|-&lt;br /&gt;
| 252 || ResumeProcedureToLinkWithNintendoAccount || Returns an [[#IOAuthProcedureForNintendoAccountLinkage]].&lt;br /&gt;
|-&lt;br /&gt;
| 255 || CreateProcedureToUpdateLinkageStateOfNintendoAccount || Returns an [[#IOAuthProcedure]].&lt;br /&gt;
|-&lt;br /&gt;
| 256 || ResumeProcedureToUpdateLinkageStateOfNintendoAccount || Returns an [[#IOAuthProcedure]].&lt;br /&gt;
|-&lt;br /&gt;
| 260 || [3.0.0+] CreateProcedureToLinkNnidWithNintendoAccount || Returns an [[#IOAuthProcedure]].&lt;br /&gt;
|-&lt;br /&gt;
| 261 || [3.0.0+] ResumeProcedureToLinkNnidWithNintendoAccount || Returns an [[#IOAuthProcedure]].&lt;br /&gt;
|-&lt;br /&gt;
| 280 || ProxyProcedureToAcquireApplicationAuthorizationForNintendoAccount || Returns an [[#IOAuthProcedure]].&lt;br /&gt;
|-&lt;br /&gt;
| 290 || [8.0.0+] GetRequestForNintendoAccountUserResourceView || &lt;br /&gt;
|-&lt;br /&gt;
| 300 || [6.0.0+] TryRecoverNintendoAccountUserStateAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 400 || [6.1.0+] IsServiceEntryRequirementCacheRefreshRequiredForOnlinePlay || Takes a total of 0x8-bytes of input, returns an output u8.&lt;br /&gt;
|-&lt;br /&gt;
| 401 || [6.1.0+] RefreshServiceEntryRequirementCacheForOnlinePlayAsync || Takes a total of 0x8-bytes of input, returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 900 || [9.0.0+] GetAuthenticationInfoForWin ||&lt;br /&gt;
|-&lt;br /&gt;
| 901 || [9.0.0+] ImportAsyncForWin ||&lt;br /&gt;
|-&lt;br /&gt;
| 997 || DebugUnlinkNintendoAccountAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 998 || DebugSetAvailabilityErrorDetail ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IAuthorizationRequest ==&lt;br /&gt;
This is &amp;quot;nn::account::nas::IAuthorizationRequest&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetSessionId ||&lt;br /&gt;
|-&lt;br /&gt;
| 10 || InvokeWithoutInteractionAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 19 || IsAuthorized ||&lt;br /&gt;
|-&lt;br /&gt;
| 20 || GetAuthorizationCode ||&lt;br /&gt;
|-&lt;br /&gt;
| 21 || GetIdToken ||&lt;br /&gt;
|-&lt;br /&gt;
| 22 || GetState ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IOAuthProcedure ==&lt;br /&gt;
This is &amp;quot;nn::account::http::IOAuthProcedure&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || PrepareAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GetRequest ||&lt;br /&gt;
|-&lt;br /&gt;
| 2 || ApplyResponse ||&lt;br /&gt;
|-&lt;br /&gt;
| 3 || ApplyResponseAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 10 || Suspend ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IOAuthProcedureForExternalNsa ==&lt;br /&gt;
This is &amp;quot;nn::account::nas::IOAuthProcedureForExternalNsa&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
Added with [3.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || PrepareAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GetRequest ||&lt;br /&gt;
|-&lt;br /&gt;
| 2 || ApplyResponse ||&lt;br /&gt;
|-&lt;br /&gt;
| 3 || ApplyResponseAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 10 || Suspend ||&lt;br /&gt;
|-&lt;br /&gt;
| 100 || GetAccountId ||&lt;br /&gt;
|-&lt;br /&gt;
| 101 || GetLinkedNintendoAccountId ||&lt;br /&gt;
|-&lt;br /&gt;
| 102 || GetNickname ||&lt;br /&gt;
|-&lt;br /&gt;
| 103 || GetProfileImage ||&lt;br /&gt;
|-&lt;br /&gt;
| 104 || [18.0.0+] GetProfileLargeImage ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IOAuthProcedureForNintendoAccountLinkage ==&lt;br /&gt;
This is &amp;quot;nn::account::nas::IOAuthProcedureForNintendoAccountLinkage&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || PrepareAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GetRequest ||&lt;br /&gt;
|-&lt;br /&gt;
| 2 || ApplyResponse ||&lt;br /&gt;
|-&lt;br /&gt;
| 3 || ApplyResponseAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 10 || Suspend ||&lt;br /&gt;
|-&lt;br /&gt;
| 100 || GetRequestWithTheme ||&lt;br /&gt;
|-&lt;br /&gt;
| 101 || IsNetworkServiceAccountReplaced ||&lt;br /&gt;
|-&lt;br /&gt;
| 199 || [2.0.0-5.1.0] GetUrlForIntroductionOfExtraMembership ||&lt;br /&gt;
|-&lt;br /&gt;
| 200 || [16.0.0+] ApplyAsyncWithAuthorizedToken ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== INotifier ==&lt;br /&gt;
This is &amp;quot;nn::account::detail::INotifier&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetSystemEvent&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IProfile ==&lt;br /&gt;
This is &amp;quot;nn::account::profile::IProfile&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#Get]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#GetBase]]&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [[#GetImageSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [[#LoadImage]]&lt;br /&gt;
|-&lt;br /&gt;
| 20 || [18.0.0+] GetLargeImageSize&lt;br /&gt;
|-&lt;br /&gt;
| 21 || [18.0.0+] LoadLargeImage&lt;br /&gt;
|-&lt;br /&gt;
| 30 || [18.0.0+] GetImageId&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Get ===&lt;br /&gt;
Takes an output type-0x1A buffer for [[#UserData]], returns an output [[#ProfileBase]].&lt;br /&gt;
&lt;br /&gt;
=== GetBase ===&lt;br /&gt;
No input, returns an output [[#ProfileBase]].&lt;br /&gt;
&lt;br /&gt;
=== GetImageSize ===&lt;br /&gt;
No input, returns an output u32 for the size of the image buffer.&lt;br /&gt;
&lt;br /&gt;
=== LoadImage === &lt;br /&gt;
Takes an output type-0x6 buffer, returns the same output u32 as [[#GetImageSize]].&lt;br /&gt;
&lt;br /&gt;
The output buffer contains the JPEG profile image icon. This is valid for both Miis and character icons.&lt;br /&gt;
&lt;br /&gt;
== IProfileEditor ==&lt;br /&gt;
This is &amp;quot;nn::account::profile::IProfileEditor&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#Get]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#GetBase]]&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [[#GetImageSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [[#LoadImage]]&lt;br /&gt;
|-&lt;br /&gt;
| 20 || [18.0.0+] GetLargeImageSize&lt;br /&gt;
|-&lt;br /&gt;
| 21 || [18.0.0+] LoadLargeImage&lt;br /&gt;
|-&lt;br /&gt;
| 30 || [18.0.0+] GetImageId&lt;br /&gt;
|-&lt;br /&gt;
| 100 || [[#Store]]&lt;br /&gt;
|-&lt;br /&gt;
| 101 || [[#StoreWithImage]]&lt;br /&gt;
|-&lt;br /&gt;
| 110 || [18.0.0+] StoreWithLargeImage&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Store ===&lt;br /&gt;
Takes a [[#ProfileBase]] and an input type-0x19 buffer for [[#UserData]].&lt;br /&gt;
&lt;br /&gt;
=== StoreWithImage ===&lt;br /&gt;
Takes a [[#ProfileBase]], an input type-0x19 buffer for [[#UserData]], and an input type-0x5 buffer.&lt;br /&gt;
&lt;br /&gt;
== IAsyncContext ==&lt;br /&gt;
This is &amp;quot;nn::account::detail::IAsyncContext&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetSystemEvent&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Cancel&lt;br /&gt;
|-&lt;br /&gt;
| 2 || HasDone&lt;br /&gt;
|-&lt;br /&gt;
| 3 || GetResult&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== ISessionObject ==&lt;br /&gt;
This is &amp;quot;nn::account::detail::ISessionObject&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 999 || Dummy&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= acc:u0 =&lt;br /&gt;
This is &amp;quot;nn::account::IAccountServiceForApplication&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
[13.0.0+] This was moved from [[Account_services|account]].&lt;br /&gt;
&lt;br /&gt;
This is only available when the output from [[Process_Manager_services|pm:bm]] GetBootMode is Normal/Maintenance.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetUserCount ||&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GetUserExistence ||&lt;br /&gt;
|-&lt;br /&gt;
| 2 || ListAllUsers ||&lt;br /&gt;
|-&lt;br /&gt;
| 3 || ListOpenUsers ||&lt;br /&gt;
|-&lt;br /&gt;
| 4 || GetLastOpenedUser ||&lt;br /&gt;
|-&lt;br /&gt;
| 5 || GetProfile || Takes an input userID, returns an [[#IProfile]].&lt;br /&gt;
|-&lt;br /&gt;
| 6 || [3.0.0+] GetProfileDigest ||&lt;br /&gt;
|-&lt;br /&gt;
| 50 || [[#IsUserRegistrationRequestPermitted]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 51 || TrySelectUserWithoutInteractionDeprecated ([1.0.0-18.1.0] [[#TrySelectUserWithoutInteraction]]) ||&lt;br /&gt;
|-&lt;br /&gt;
| 52 || [19.0.0+] TrySelectUserWithoutInteraction ||&lt;br /&gt;
|-&lt;br /&gt;
| 60 || [5.0.0-5.1.0] ListOpenContextStoredUsers ||&lt;br /&gt;
|-&lt;br /&gt;
| 99 || [6.0.0+] DebugActivateOpenContextRetention || No input, returns an [[#ISessionObject]].&lt;br /&gt;
|-&lt;br /&gt;
| 100 || [[#InitializeApplicationInfoV0]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 101 || GetBaasAccountManagerForApplication || Takes an input userID, returns an [[#IManagerForApplication]].&lt;br /&gt;
|-&lt;br /&gt;
| 102 || AuthenticateApplicationAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 103 || [4.0.0+] CheckNetworkServiceAvailabilityAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 110 || StoreSaveDataThumbnail ||&lt;br /&gt;
|-&lt;br /&gt;
| 111 || ClearSaveDataThumbnail ||&lt;br /&gt;
|-&lt;br /&gt;
| 120 || CreateGuestLoginRequest || Returns an [[#IGuestLoginRequest]].&lt;br /&gt;
|-&lt;br /&gt;
| 130 || [5.0.0+] LoadOpenContext ||&lt;br /&gt;
|-&lt;br /&gt;
| 131 || [6.0.0+] ListOpenContextStoredUsers || &lt;br /&gt;
|-&lt;br /&gt;
| 140 || [6.0.0+] [[#InitializeApplicationInfoV1]] || &lt;br /&gt;
|-&lt;br /&gt;
| 141 || [6.0.0+] ListQualifiedUsers || &lt;br /&gt;
|-&lt;br /&gt;
| 150 || [6.0.0+] IsUserAccountSwitchLocked || &lt;br /&gt;
|-&lt;br /&gt;
| 160 || [13.0.0+] InitializeApplicationInfoV2 || &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
InitializeApplicationInfo* is used by the user-process during service init.&lt;br /&gt;
&lt;br /&gt;
== InitializeApplicationInfoV0 ==&lt;br /&gt;
Takes a PID and an input u64 pid_placeholder, no output.&lt;br /&gt;
&lt;br /&gt;
== InitializeApplicationInfoV1 ==&lt;br /&gt;
Takes a PID and an input u64 pid_placeholder, no output.&lt;br /&gt;
&lt;br /&gt;
== IGuestLoginRequest ==&lt;br /&gt;
This is &amp;quot;nn::account::baas::IGuestLoginRequest&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetSessionId&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [1.0.0-2.3.0] &lt;br /&gt;
|-&lt;br /&gt;
| 12 || GetAccountId&lt;br /&gt;
|-&lt;br /&gt;
| 13 || GetLinkedNintendoAccountId&lt;br /&gt;
|-&lt;br /&gt;
| 14 || GetNickname&lt;br /&gt;
|-&lt;br /&gt;
| 15 || GetProfileImage&lt;br /&gt;
|-&lt;br /&gt;
| 16 || [18.0.0+] GetProfileLargeImage&lt;br /&gt;
|-&lt;br /&gt;
| 21 || [3.0.0+] LoadIdTokenCache&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IManagerForApplication ==&lt;br /&gt;
This is &amp;quot;nn::account::baas::IManagerForApplication&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || CheckAvailability ||&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GetAccountId ||&lt;br /&gt;
|-&lt;br /&gt;
| 2 || EnsureIdTokenCacheAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 3 || LoadIdTokenCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 130 || GetNintendoAccountUserResourceCacheForApplication ||&lt;br /&gt;
|-&lt;br /&gt;
| 150 || CreateAuthorizationRequest || Returns an [[#IAuthorizationRequest]].&lt;br /&gt;
|-&lt;br /&gt;
| 160 || [5.0.0+] StoreOpenContext ||&lt;br /&gt;
|-&lt;br /&gt;
| 170 || [13.0.0+] EnsureIdTokenCacheForOnlinePlayAsync ([6.0.0-12.1.0] LoadNetworkServiceLicenseKindAsync) || No input, returns an [[#IAsyncContextForLoginForOnlinePlay]] ([6.0.0-12.1.0] [[#IAsyncNetworkServiceLicenseKindContext]]).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IAsyncNetworkServiceLicenseKindContext ==&lt;br /&gt;
This is &amp;quot;nn::account::detail::IAsyncNetworkServiceLicenseKindContext&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [6.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetSystemEvent || &lt;br /&gt;
|-&lt;br /&gt;
| 1 || Cancel || &lt;br /&gt;
|-&lt;br /&gt;
| 2 || HasDone || &lt;br /&gt;
|-&lt;br /&gt;
| 3 || GetResult || &lt;br /&gt;
|-&lt;br /&gt;
| 100 || GetNetworkServiceLicenseKind || &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IAsyncContextForLoginForOnlinePlay ==&lt;br /&gt;
This is &amp;quot;nn::account::baas::IAsyncContextForLoginForOnlinePlay&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [13.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetSystemEvent || &lt;br /&gt;
|-&lt;br /&gt;
| 1 || Cancel || &lt;br /&gt;
|-&lt;br /&gt;
| 2 || HasDone || &lt;br /&gt;
|-&lt;br /&gt;
| 3 || GetResult || &lt;br /&gt;
|-&lt;br /&gt;
| 100 || GetNetworkServiceLicenseInfoForOnlinePlay || &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= acc:u1 =&lt;br /&gt;
This is &amp;quot;nn::account::IAccountServiceForSystemService&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
[13.0.0+] This was moved from [[Account_services|account]].&lt;br /&gt;
&lt;br /&gt;
This is only available when the output from [[Process_Manager_services|pm:bm]] GetBootMode is Normal/Maintenance.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetUserCount ||&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GetUserExistence ||&lt;br /&gt;
|-&lt;br /&gt;
| 2 || ListAllUsers ||&lt;br /&gt;
|-&lt;br /&gt;
| 3 || ListOpenUsers ||&lt;br /&gt;
|-&lt;br /&gt;
| 4 || GetLastOpenedUser ||&lt;br /&gt;
|-&lt;br /&gt;
| 5 || GetProfile || Returns an [[#IProfile]].&lt;br /&gt;
|-&lt;br /&gt;
| 6 || [3.0.0+] GetProfileDigest ||&lt;br /&gt;
|-&lt;br /&gt;
| 50 || [[#IsUserRegistrationRequestPermitted]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 51 || TrySelectUserWithoutInteractionDeprecated ([1.0.0-18.1.0] [[#TrySelectUserWithoutInteraction]]) ||&lt;br /&gt;
|-&lt;br /&gt;
| 52 || [19.0.0+] TrySelectUserWithoutInteraction ||&lt;br /&gt;
|-&lt;br /&gt;
| 60 || [5.0.0-5.1.0] ListOpenContextStoredUsers ||&lt;br /&gt;
|-&lt;br /&gt;
| 99 || [6.0.0+] DebugActivateOpenContextRetention || No input, returns an [[#ISessionObject]].&lt;br /&gt;
|-&lt;br /&gt;
| 100 || GetUserRegistrationNotifier || Returns an [[#INotifier]].&lt;br /&gt;
|-&lt;br /&gt;
| 101 || GetUserStateChangeNotifier || Returns an [[#INotifier]].&lt;br /&gt;
|-&lt;br /&gt;
| 102 || GetBaasAccountManagerForSystemService || Returns an [[#IManagerForSystemService]].&lt;br /&gt;
|-&lt;br /&gt;
| 103 || GetBaasUserAvailabilityChangeNotifier || Returns an [[#INotifier]].&lt;br /&gt;
|-&lt;br /&gt;
| 104 || GetProfileUpdateNotifier || Returns an [[#INotifier]].&lt;br /&gt;
|-&lt;br /&gt;
| 105 || [4.0.0+] CheckNetworkServiceAvailabilityAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 106 || [9.0.0+] GetProfileSyncNotifier ||&lt;br /&gt;
|-&lt;br /&gt;
| 110 || StoreSaveDataThumbnail ||&lt;br /&gt;
|-&lt;br /&gt;
| 111 || ClearSaveDataThumbnail ||&lt;br /&gt;
|-&lt;br /&gt;
| 112 || LoadSaveDataThumbnail ||&lt;br /&gt;
|-&lt;br /&gt;
| 113 || [5.0.0+] GetSaveDataThumbnailExistence ||&lt;br /&gt;
|-&lt;br /&gt;
| 120 || [10.0.0+] ListOpenUsersInApplication ||&lt;br /&gt;
|-&lt;br /&gt;
| 130 || [6.0.0+] ActivateOpenContextRetention || Takes a total of 0x8-bytes of input, returns an [[#ISessionObject]].&lt;br /&gt;
|-&lt;br /&gt;
| 140 || [6.0.0+] ListQualifiedUsers || &lt;br /&gt;
|-&lt;br /&gt;
| 150 || [10.0.0-10.2.0] AuthenticateApplicationAsync ||&lt;br /&gt;
|-&lt;br /&gt;
| 151 || [12.0.0+] EnsureSignedDeviceIdentifierCacheForNintendoAccountAsync || &lt;br /&gt;
|-&lt;br /&gt;
| 152 || [12.0.0+] LoadSignedDeviceIdentifierCacheForNintendoAccount ||&lt;br /&gt;
|-&lt;br /&gt;
| 170 || [13.0.0+] GetNasOp2MembershipStateChangeNotifier ||&lt;br /&gt;
|-&lt;br /&gt;
| 190 || [1.0.0-9.2.0] GetUserLastOpenedApplication ||&lt;br /&gt;
|-&lt;br /&gt;
| 191 || [7.0.0-19.0.1] UpdateNotificationReceiverInfo ([5.0.0-5.1.0] ActivateOpenContextHolder) ||&lt;br /&gt;
|-&lt;br /&gt;
| 401 || [18.0.0+] GetPinCodeLength ||&lt;br /&gt;
|-&lt;br /&gt;
| 402 || [18.0.0-19.0.1] GetPinCode ||&lt;br /&gt;
|-&lt;br /&gt;
| 403 || [20.0.0+] GetPinCodeParity ||&lt;br /&gt;
|-&lt;br /&gt;
| 404 || [20.0.0+] VerifyPinCode ||&lt;br /&gt;
|-&lt;br /&gt;
| 405 || [20.0.0+] IsPinCodeVerificationForbidden ||&lt;br /&gt;
|-&lt;br /&gt;
| 997 || [3.0.0+] DebugInvalidateTokenCacheForUser ||&lt;br /&gt;
|-&lt;br /&gt;
| 998 || DebugSetUserStateClose ||&lt;br /&gt;
|-&lt;br /&gt;
| 999 || DebugSetUserStateOpen ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[10.0.0+] DebugSetUserStateClose/DebugSetUserStateOpen now takes an additional 8-bytes of input. &lt;br /&gt;
&lt;br /&gt;
== IOAuthProcedureForUserRegistration ==&lt;br /&gt;
This is &amp;quot;nn::account::nas::IOAuthProcedureForUserRegistration&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [8.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || PrepareAsync || No input, returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GetRequest || &lt;br /&gt;
|-&lt;br /&gt;
| 2 || ApplyResponse || &lt;br /&gt;
|-&lt;br /&gt;
| 3 || ApplyResponseAsync || Takes a type-0x9 input buffer, returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 10 || Suspend || &lt;br /&gt;
|-&lt;br /&gt;
| 100 || GetAccountId || &lt;br /&gt;
|-&lt;br /&gt;
| 101 || GetLinkedNintendoAccountId || &lt;br /&gt;
|-&lt;br /&gt;
| 102 || GetNickname || &lt;br /&gt;
|-&lt;br /&gt;
| 103 || GetProfileImage || &lt;br /&gt;
|-&lt;br /&gt;
| 104 || [18.0.0+] GetProfileLargeImage || &lt;br /&gt;
|-&lt;br /&gt;
| 110 || RegisterUserAsync || No input, returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 111 || GetUid || &lt;br /&gt;
|-&lt;br /&gt;
| 200 || [17.0.0+] ApplyResponseForUserCreationAsync || &lt;br /&gt;
|-&lt;br /&gt;
| 205 || [17.0.0+] SuspendAfterApplyResponse || &lt;br /&gt;
|-&lt;br /&gt;
| 210 || [17.0.0+] IsProfileAvailable || &lt;br /&gt;
|-&lt;br /&gt;
| 220 || [17.0.0+] RegisterUserAsyncWithoutProfile || &lt;br /&gt;
|-&lt;br /&gt;
| 221 || [17.0.0+] RegisterUserWithProfileAsync || &lt;br /&gt;
|-&lt;br /&gt;
| 230 || [18.0.0+] RegisterUserWithLargeImageProfileAsync || &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationRecord =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationRecord&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0&lt;br /&gt;
| 0x8&lt;br /&gt;
| [[NCM_services#ApplicationId|Id]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x8&lt;br /&gt;
| 0x1&lt;br /&gt;
| [[#ApplicationEvent|LastEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x9&lt;br /&gt;
| 0x1&lt;br /&gt;
| Attributes&lt;br /&gt;
|-&lt;br /&gt;
| 0xA&lt;br /&gt;
| 0x6&lt;br /&gt;
| Reserved&lt;br /&gt;
|-&lt;br /&gt;
| 0x10&lt;br /&gt;
| 0x8&lt;br /&gt;
| LastUpdated&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationEvent =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationEvent&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || Launched&lt;br /&gt;
|-&lt;br /&gt;
| 1 || LocalInstalled&lt;br /&gt;
|-&lt;br /&gt;
| 2 || DownloadStarted&lt;br /&gt;
|-&lt;br /&gt;
| 3 || GameCardInserted&lt;br /&gt;
|-&lt;br /&gt;
| 4 || Touched&lt;br /&gt;
|-&lt;br /&gt;
| 5 || &lt;br /&gt;
|-&lt;br /&gt;
| 6 || &lt;br /&gt;
|-&lt;br /&gt;
| 7 || &lt;br /&gt;
|-&lt;br /&gt;
| 8 || &lt;br /&gt;
|-&lt;br /&gt;
| 9 || &lt;br /&gt;
|-&lt;br /&gt;
| 10 || &lt;br /&gt;
|-&lt;br /&gt;
| 11 || &lt;br /&gt;
|-&lt;br /&gt;
| 12 || &lt;br /&gt;
|-&lt;br /&gt;
| 13 || &lt;br /&gt;
|-&lt;br /&gt;
| 14 || &lt;br /&gt;
|-&lt;br /&gt;
| 15 || &lt;br /&gt;
|-&lt;br /&gt;
| 16 || &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationControlSource =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationControlSource&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0&lt;br /&gt;
| CacheOnly&lt;br /&gt;
|-&lt;br /&gt;
| 1&lt;br /&gt;
| Storage&lt;br /&gt;
|-&lt;br /&gt;
| 2&lt;br /&gt;
| StorageOnly&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationContentMetaStatus =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationContentMetaStatus&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0&lt;br /&gt;
| 0x1&lt;br /&gt;
| [[NCM_services#ContentMetaType|Type]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x1&lt;br /&gt;
| 0x1&lt;br /&gt;
| [[NCM_services#StorageId|InstalledStorage]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x2&lt;br /&gt;
| 0x1&lt;br /&gt;
| [[#ContentMetaRightsCheck|RightsCheck]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x3&lt;br /&gt;
| 0x1&lt;br /&gt;
| Reserved&lt;br /&gt;
|-&lt;br /&gt;
| 0x4&lt;br /&gt;
| 0x4&lt;br /&gt;
| Version&lt;br /&gt;
|-&lt;br /&gt;
| 0x8&lt;br /&gt;
| 0x8&lt;br /&gt;
| [[NCM_services#ApplicationId|Id]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ContentMetaRightsCheck =&lt;br /&gt;
This is &amp;quot;nn::ns::ContentMetaRightsCheck&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0&lt;br /&gt;
| NotChecked&lt;br /&gt;
|-&lt;br /&gt;
| 1&lt;br /&gt;
| NotNeeded&lt;br /&gt;
|-&lt;br /&gt;
| 2&lt;br /&gt;
| CommonRights&lt;br /&gt;
|-&lt;br /&gt;
| 3&lt;br /&gt;
| PersonalizedRights&lt;br /&gt;
|-&lt;br /&gt;
| 4&lt;br /&gt;
| NoRights&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= VersionListData =&lt;br /&gt;
This is &amp;quot;nn::ns::VersionListData&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
= ApplicationUpdateInfo =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationUpdateInfo&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || UpToDate&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Updatable&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationOccupiedSize =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationOccupiedSize&amp;quot;. This is a 0x80-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x20 * 4 || Array of [[#ApplicationOccupiedSizeEntity]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationOccupiedSizeEntity =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationOccupiedSizeEntity&amp;quot;. This is a 0x20-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x1 || [[NCM_services#StorageId|StorageId]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x1 || 0x7 || Reserved&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x8 || AppSize&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x8 || PatchSize&lt;br /&gt;
|-&lt;br /&gt;
| 0x18 || 0x8 || AocSize&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ProgressForDeleteUserSaveDataAll =&lt;br /&gt;
This is &amp;quot;nn::ns::detail::ProgressForDeleteUserSaveDataAll&amp;quot;. This is a 0x28-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x8 || StartedAt&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x4 || Count&lt;br /&gt;
|-&lt;br /&gt;
| 0xC || 0x4 || Reserved&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x8 || SizeInBytes&lt;br /&gt;
|-&lt;br /&gt;
| 0x18 || 0x1 || IsSystem&lt;br /&gt;
|-&lt;br /&gt;
| 0x19 || 0x7 || Reserved&lt;br /&gt;
|-&lt;br /&gt;
| 0x20 || 0x8 || ApplicationId&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationViewDeprecated =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationViewDeprecated&amp;quot;. This is a 0x40-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x8 || [[NCM_services#ApplicationId|ApplicationId]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x4 || Version&lt;br /&gt;
|-&lt;br /&gt;
| 0xC || 0x4 || [[#ApplicationViewFlag|Flag]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x18 || [[#ApplicationDownloadProgress|Progress]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x28 || 0x18 || [[#ApplicationApplyDeltaProgress|ApplyProgress]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
This is converted from [[#ApplicationView]] by [[#GetApplicationViewDeprecated]] on newer system-versions as follows:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x20 || Same as [[#ApplicationView]] +0x0.&lt;br /&gt;
|-&lt;br /&gt;
| 0x20 || 0x4 || Same as [[#ApplicationView]] +0x20.&lt;br /&gt;
|-&lt;br /&gt;
| 0x24 || 0x2 || Same as [[#ApplicationView]] +0x24.&lt;br /&gt;
|-&lt;br /&gt;
| 0x26 || 0x2 || Cleared to 0.&lt;br /&gt;
|-&lt;br /&gt;
| 0x28 || 0x10 || Same as [[#ApplicationView]] +0x30.&lt;br /&gt;
|-&lt;br /&gt;
| 0x38 || 0x4 || Same as [[#ApplicationView]] +0x40.&lt;br /&gt;
|-&lt;br /&gt;
| 0x3C || 0x1 || Same as [[#ApplicationView]] +0x44.&lt;br /&gt;
|-&lt;br /&gt;
| 0x3D || 0x2 || Cleared to 0.&lt;br /&gt;
|-&lt;br /&gt;
| 0x3F || 0x1 || Cleared to 0.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationViewFlag =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationViewFlag&amp;quot;. This is a 32-bit flag.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Bit&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 1&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 2&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 3&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 4&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 5&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 6&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 7&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 8&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 9&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 10&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 11&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 12&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 13&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 14&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 15&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 16&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 17&lt;br /&gt;
| &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationDownloadProgress =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationDownloadProgress&amp;quot;. This is a 0x18-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x8 || Downloaded&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x8 || Total&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x4 || LastResult&lt;br /&gt;
|-&lt;br /&gt;
| 0x14 || 0x1 || [[#ApplicationDownloadState|State]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x15 || 0x3 || Reserved&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationApplyDeltaProgress =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationApplyDeltaProgress&amp;quot;. This is a 0x18-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x8 || Applied&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x8 || Total&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x4 || LastResult&lt;br /&gt;
|-&lt;br /&gt;
| 0x14 || 0x1 || [[#ApplicationApplyDeltaState|State]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x15 || 0x3 || Reserved&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationDownloadState =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationDownloadState&amp;quot;. This is an u8.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || Runnable&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Suspended&lt;br /&gt;
|-&lt;br /&gt;
| 2 || NotEnoughSpace&lt;br /&gt;
|-&lt;br /&gt;
| 3 || Fatal&lt;br /&gt;
|-&lt;br /&gt;
| 4 || Finished&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationApplyDeltaState =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationApplyDeltaState&amp;quot;. This is an u8.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || Applying&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Suspended&lt;br /&gt;
|-&lt;br /&gt;
| 2 || NotEnoughSpace&lt;br /&gt;
|-&lt;br /&gt;
| 3 || Fatal&lt;br /&gt;
|-&lt;br /&gt;
| 4 || NoTask&lt;br /&gt;
|-&lt;br /&gt;
| 5 || WaitApply&lt;br /&gt;
|-&lt;br /&gt;
| 6 || Applied&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationView =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationView&amp;quot;. This is a 0x50-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x8 || [[NCM_services#ApplicationId|ApplicationId]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x4 || ?&lt;br /&gt;
|-&lt;br /&gt;
| 0xC || 0x4 || Flags&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x40 || ?&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationViewWithPromotionInfo =&lt;br /&gt;
This is a 0x70-byte struct.&lt;br /&gt;
&lt;br /&gt;
[20.0.0+] This is a 0x78-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x50 || [[#ApplicationView]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x50 || 0x20 || [[#PromotionInfo]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= PromotionInfo =&lt;br /&gt;
This is a 0x20-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x8 || PosixTime start_timestamp.&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x8 || PosixTime end_timestamp.&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x8 || Remaining time until the promotion ends, in nanoseconds ({end_timestamp - current_time} converted to nanoseconds).&lt;br /&gt;
|-&lt;br /&gt;
| 0x18 || 0x4 || Not set, left at zero.&lt;br /&gt;
|-&lt;br /&gt;
| 0x1C || 0x1 || Flags. Bit0: whether the PromotionInfo is valid (including bit1). Bit1 clear: u64 +0x10 is set.&lt;br /&gt;
|-&lt;br /&gt;
| 0x1D || 0x3 || Padding&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationResourceType =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationResourceType&amp;quot;. This is an u8.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || ApplicationResource&lt;br /&gt;
|-&lt;br /&gt;
| 1 || MicroApplicationResource&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationErrorCodeCategory =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationErrorCodeCategory&amp;quot;. This is an u64.&lt;br /&gt;
&lt;br /&gt;
= NoDownloadRightsErrorResolution =&lt;br /&gt;
This is &amp;quot;nn::ns::NoDownloadRightsErrorResolution&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
= BackgroundNetworkUpdateState =&lt;br /&gt;
This is &amp;quot;nn::ns::BackgroundNetworkUpdateState&amp;quot;. This is an u8.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || None&lt;br /&gt;
|-&lt;br /&gt;
| 1 || InProgress&lt;br /&gt;
|-&lt;br /&gt;
| 2 || Ready&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Similar to [[#HasDownloaded]], [[#GetBackgroundNetworkUpdateState]] uses [[NIM_services|nim]] ListSystemUpdateTask and [[NIM_services|nim]] GetSystemUpdateTaskInfo. When ListSystemUpdateTask successfully returns a task and GetSystemUpdateTaskInfo is successful, the output value is set to: &amp;lt;code&amp;gt;1 + *((u8*)(taskinfo+0) == 0x3&amp;lt;/code&amp;gt;. Otherwise, value=0.&lt;br /&gt;
&lt;br /&gt;
[[#GetBackgroundNetworkUpdateState]] always returns Result 0, however this will assert if GetSystemUpdateTaskInfo fails with ret!=0x3C89.&lt;br /&gt;
&lt;br /&gt;
= SystemUpdateProgress =&lt;br /&gt;
This is &amp;quot;nn::ns::SystemUpdateProgress&amp;quot;. This is a 0x10-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x8 || Loaded (this value can be larger than total_size when the async operation is finishing and when total_size is &amp;lt;=0, this current_size field may contain a progress value for when the total_size is not yet determined)&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x8 || Total (this field is only valid when &amp;gt;0)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Commands which have this as output will return 0 with the output cleared, when no task is available.&lt;br /&gt;
&lt;br /&gt;
= EulaDataPath =&lt;br /&gt;
This is &amp;quot;nn::ns::detail::EulaDataPath&amp;quot;. This is a 0x100-byte struct.&lt;br /&gt;
&lt;br /&gt;
This contains a file path.&lt;br /&gt;
&lt;br /&gt;
= SystemDeliveryInfo =&lt;br /&gt;
This is &amp;quot;nn::ns::SystemDeliveryInfo&amp;quot;. This is a 0x100-byte struct.&lt;br /&gt;
&lt;br /&gt;
Originally the SystemDeliveryInfo validation func verified that OldSystemUpdateId matched the installed SystemUpdate Id. [20.0.0+] The used (Old)SystemUpdateId as selected by SystemUpdateIdFlag must now match one of the Ids in [[System_Settings|system-setting]] &amp;lt;code&amp;gt;contents_delivery!acceptable_system_update_ids_string&amp;lt;/code&amp;gt; (replaces the previously mentioned installed-SystemUpdate check).&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x4 || SystemDeliveryProtocolVersion. Must be &amp;lt;= to and match [[System_Settings|system-setting]] &amp;lt;code&amp;gt;contents_delivery!system_delivery_protocol_version&amp;lt;/code&amp;gt;.&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || 0x4 || ApplicationDeliveryProtocolVersion. Loaded from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;contents_delivery!application_delivery_protocol_version&amp;lt;/code&amp;gt;. Unused by [[#RequestSendSystemUpdate]]/[[#RequestReceiveSystemUpdate]], besides HMAC validation.&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x1 || HasExFat. Unused by [[#RequestSendSystemUpdate]]/[[#RequestReceiveSystemUpdate]], besides HMAC validation.&lt;br /&gt;
|-&lt;br /&gt;
| 0x9 || 0x3 || Reserved.&lt;br /&gt;
|-&lt;br /&gt;
| 0xC || 0x4 || SystemUpdateVersion.&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x8 || OldSystemUpdateId. [20.0.0+] Always the NX Id: this is loaded from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;contents_delivery!old_system_update_id&amp;lt;/code&amp;gt;.&lt;br /&gt;
|-&lt;br /&gt;
| 0x18 || 0x1 || FirmwareVariationId. Used by [[#RequestSendSystemUpdate]]. Loaded from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;ns.systemupdate!firmware_variation&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;ns.systemupdate!t_firmware_variation&amp;lt;/code&amp;gt;, depending on the [[Settings_services|PlatformRegion]].&lt;br /&gt;
|-&lt;br /&gt;
| 0x19 || 0x1 || UpdatableFirmwareGroupId. Unused by [[#RequestSendSystemUpdate]]/[[#RequestReceiveSystemUpdate]], besides HMAC validation. Loaded from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;ns.systemupdate!updatable_firmware_group_id&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;ns.systemupdate!t_updatable_firmware_group_id&amp;lt;/code&amp;gt;, depending on the [[Settings_services|PlatformRegion]].&lt;br /&gt;
|-&lt;br /&gt;
| 0x1A || 0x1 || PlatformRegion (0x00 = Unknown/Global, 0x01 = China).&lt;br /&gt;
|-&lt;br /&gt;
| 0x1B || 0x1 || [20.0.0+] SystemDeliveryInfoPlatform. Loaded from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;ns.systemupdate!system_delivery_info_platform&amp;lt;/code&amp;gt;. Elsewhere this is compared against the sys-setting, etc.&lt;br /&gt;
|-&lt;br /&gt;
| 0x1C || 0x1 || [20.0.0+] SystemUpdateIdFlag. When non-zero, SystemUpdateId is used instead of OldSystemUpdateId. Always set to 0x1 by [[#GetSystemDeliveryInfo]] with [20.0.0+].&lt;br /&gt;
|-&lt;br /&gt;
| 0x1D || 0x3 || Padding&lt;br /&gt;
|-&lt;br /&gt;
| 0x20 || 0x8 || [20.0.0+] SystemUpdateId. See above. With [20.0.0+] [[#GetSystemDeliveryInfo]] now writes the Id here instead of OldSystemUpdateId (for the installed SystemUpdate). On S2 this is set to the Ounce Id.&lt;br /&gt;
|-&lt;br /&gt;
| 0x28 || 0xB8 || Reserved&lt;br /&gt;
|-&lt;br /&gt;
| 0xE0 || 0x20 || HMAC-SHA256 over the previous 0xE0-bytes.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationDeliveryInfo =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationDeliveryInfo&amp;quot;. This is a 0x100-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x4 || ApplicationDeliveryProtocolVersion. Loaded from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;contents_delivery!application_delivery_protocol_version&amp;lt;/code&amp;gt;. An error is thrown when [[System_Settings|system-setting]] &amp;lt;code&amp;gt;contents_delivery!application_delivery_protocol_version&amp;lt;/code&amp;gt; &amp;lt; version, or when [[System_Settings|system-setting]] &amp;lt;code&amp;gt;contents_delivery!acceptable_application_delivery_protocol_version&amp;lt;/code&amp;gt; &amp;gt; version.&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || 0x4 || Padding&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x8 || ApplicationId.&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x4 || ApplicationVersion.&lt;br /&gt;
|-&lt;br /&gt;
| 0x14 || 0x4 || RequiredApplicationVersion.&lt;br /&gt;
|-&lt;br /&gt;
| 0x18 || 0x4 || RequiredSystemVersion.&lt;br /&gt;
|-&lt;br /&gt;
| 0x1C || 0x4 || u32 bitmask &amp;lt;code&amp;gt;nn::ns::ApplicationDeliveryAttributeTag&amp;lt;/code&amp;gt;. [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]] sets this to the input u32. Bit30 and bit28 are additionally set, depending on [[NCM_services|ContentMetaType]] == Patch, etc.&lt;br /&gt;
|-&lt;br /&gt;
| 0x20 || 0x1 || [20.0.0+] [[NCM_services|ContentMetaPlatform]]. Loaded from [[NCM_services|ncm]] IContentMetaDatabase GetPlatform.&lt;br /&gt;
|-&lt;br /&gt;
| 0x21 || 0x1 || [20.0.0+] ProperProgramExists. Set to whether the bit for ProperProgramExists is set from [[NCM_services|ncm]] IContentMetaDatabase GetAttributes.&lt;br /&gt;
|-&lt;br /&gt;
| 0x22 || 0x1 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 0x23 || 0xBD || Reserved&lt;br /&gt;
|-&lt;br /&gt;
| 0xE0 || 0x20 || HMAC-SHA256 over the previous 0xE0-bytes. Uses a different key than [[#SystemDeliveryInfo]].&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= LatestSystemUpdate =&lt;br /&gt;
This is &amp;quot;nn::ns::LatestSystemUpdate&amp;quot;. This is an u8.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || UpToDate&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Downloaded&lt;br /&gt;
|-&lt;br /&gt;
| 2 || NeedsDownload&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ReceiveApplicationProgress =&lt;br /&gt;
This is &amp;quot;nn::ns::ReceiveApplicationProgress&amp;quot;. This is a 0x10-byte struct.&lt;br /&gt;
&lt;br /&gt;
= SendApplicationProgress =&lt;br /&gt;
This is &amp;quot;nn::ns::SendApplicationProgress&amp;quot;. This is a 0x10-byte struct.&lt;br /&gt;
&lt;br /&gt;
= ApplicationRightsOnClient =&lt;br /&gt;
This is a 0x20-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x8 || [[NCM_services#ApplicationId|ApplicationId]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x10 || [[Account_services#Uid|Uid]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x18 || 0x1 || Flags, [[qlaunch]] only uses bit0-bit4 and bit7.&lt;br /&gt;
|-&lt;br /&gt;
| 0x19 || 0x1 || Flags, [[qlaunch]] only uses bit0.&lt;br /&gt;
|-&lt;br /&gt;
| 0x1A || 0x6 || Unknown&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[[qlaunch]] only uses +0x18/+0x19 in this struct.&lt;br /&gt;
&lt;br /&gt;
= DownloadTaskStatus =&lt;br /&gt;
This is &amp;quot;nn::ns::DownloadTaskStatus&amp;quot;. This is a 0x20-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x10 || Uuid&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x8 || [[NCM_services#ApplicationId|ApplicationId]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x18 || 0x1 || [[#DownloadTaskStatusDetail|Detail]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x19 || 0x1 || NeedsCleanup&lt;br /&gt;
|-&lt;br /&gt;
| 0x1A || 0x2 || Reserved&lt;br /&gt;
|-&lt;br /&gt;
| 0x1C || 0x4 || Result&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= DownloadTaskStatusDetail =&lt;br /&gt;
This is &amp;quot;nn::ns::DownloadTaskStatusDetail&amp;quot;. This is an u8.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || Created&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Added&lt;br /&gt;
|-&lt;br /&gt;
| 2 || AlreadyExists&lt;br /&gt;
|-&lt;br /&gt;
| 3 || Failed&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationLaunchInfo =&lt;br /&gt;
This is a 0x40-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x8 || [[NCM_services#ApplicationId|ApplicationId]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x4 || Application version&lt;br /&gt;
|-&lt;br /&gt;
| 0xC || 0x4 || [[Process_Manager_services#LaunchFlags|LaunchFlags]], set to hard-coded value 0xB by [[#GetApplicationLaunchInfo]].&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x1 || Application [[NCM_services#StorageId|StorageId]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x11 || 0x1 || Update [[NCM_services#StorageId|StorageId]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x12 || 0x2E || &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= UserData =&lt;br /&gt;
This is a 0x80-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset || Size || Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x4? || ?&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || 0x4? || Icon ID. 0 = Mii, the rest are character icon IDs.&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x1? || Profile icon background color ID&lt;br /&gt;
|-&lt;br /&gt;
| 0x9 || 0x7 || ?&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x10 || Some ID related to the Mii? All zeros when a character icon is used.&lt;br /&gt;
|-&lt;br /&gt;
| 0x20 || 0x60 || Usually zeros?&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ProfileBase =&lt;br /&gt;
This is a 0x38-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset || Size || Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x10 || userID&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x8 || POSIX UTC timestamp, for last account edit.&lt;br /&gt;
|-&lt;br /&gt;
| 0x18 || 0x20 || UTF-8 Nickname. Official sw uses strncpy to copy this into another struct (&amp;lt;code&amp;gt;nn::account::Nickname&amp;lt;/code&amp;gt;), with a NUL-byte written after the copied data.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Uid =&lt;br /&gt;
This is &amp;quot;nn::account::Uid&amp;quot;. This is a 0x10-byte struct. This contains 2 u64s for the UserId.&lt;br /&gt;
&lt;br /&gt;
= Notes =&lt;br /&gt;
[[Process_Manager_services|pm:bm]] GetBootMode is used to determine whether aoc:u is available (see above). This value is also passed to thread &amp;quot;nn.ns.DelayedInitialization&amp;quot;, which calls various funcs depending on the BootMode in various cases.&lt;br /&gt;
&lt;br /&gt;
The &amp;quot;nn.ns.DelayedInitialization&amp;quot; thread uses BootMode as follows (this also handles various other initialization):&lt;br /&gt;
* Initializes [[NPNS_services|npns:s]] only for BootMode Normal/Maintenance.&lt;br /&gt;
* Initializes the hosted acc:* services and service [[Account_services|acc:su]] only for BootMode Normal/Maintenance.&lt;br /&gt;
* Calls a func only for BootMode Normal.&lt;br /&gt;
* Initializes [[ETicket_services|es]] and [[Shared_Database_services|avm]] only for BootMode Normal/Maintenance.&lt;br /&gt;
&lt;br /&gt;
The output of GetBootMode is also written into state. This same func later enters a code block when BootMode is Maintenance/SafeMode: various [[NCM_services|ncm]] cmds are used with input StorageId=BuiltInUser (VerifyContentMetaDatabase, VerifyContentStorage, ActivateContentMetaDatabase, ActivateContentStorage, InactivateContentMetaDatabase, InactivateContentStorage) and state fields are written. Then if the BootMode is Maintenance the savedata for [[Flash_Filesystem|ns_rightsid]] (0x800000000000004A) is deleted. Then 0 is returned. Otherwise for BootMode Normal it continues with various initialization, including gamecard handling which handles launching the gamecard title in certain conditions (this is the only time ns launches anything with pgl outside of service cmds).&lt;br /&gt;
&lt;br /&gt;
In the above block, InactivateContentMetaDatabase/InactivateContentStorage are only used if using ActivateContentMetaDatabase/ActivateContentStorage failed (error is only checked after using both cmds). If any of the ncm cmds prior to this fail, it will skip using the rest of the ncm cmds.&lt;br /&gt;
&lt;br /&gt;
[[Category:Services]]&lt;/div&gt;</summary>
		<author><name>Yellows8</name></author>
	</entry>
	<entry>
		<id>https://switchbrew.org/w/index.php?title=NS_services&amp;diff=14933</id>
		<title>NS services</title>
		<link rel="alternate" type="text/html" href="https://switchbrew.org/w/index.php?title=NS_services&amp;diff=14933"/>
		<updated>2026-08-09T16:11:39Z</updated>

		<summary type="html">&lt;p&gt;Yellows8: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= aoc:u =&lt;br /&gt;
This is &amp;quot;nn::aocsrv::detail::IAddOnContentManager&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This is only available when [[Process_Manager_services|pm:bm]] GetBootMode returns output 0 (Normal).&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [1.0.0-6.2.0] CountAddOnContentByApplicationId&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [1.0.0-6.2.0] ListAddOnContentByApplicationId&lt;br /&gt;
|-&lt;br /&gt;
| 2 || CountAddOnContent&lt;br /&gt;
|-&lt;br /&gt;
| 3 || ListAddOnContent&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [1.0.0-6.2.0] GetAddOnContentBaseIdByApplicationId&lt;br /&gt;
|-&lt;br /&gt;
| 5 || GetAddOnContentBaseId&lt;br /&gt;
|-&lt;br /&gt;
| 6 || [1.0.0-6.2.0] PrepareAddOnContentByApplicationId&lt;br /&gt;
|-&lt;br /&gt;
| 7 || PrepareAddOnContent&lt;br /&gt;
|-&lt;br /&gt;
| 8 || [4.0.0+] GetAddOnContentListChangedEvent&lt;br /&gt;
|-&lt;br /&gt;
| 9 || [10.0.0+] GetAddOnContentLostErrorCode&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [11.0.0+] GetAddOnContentListChangedEventWithProcessId&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [13.0.0+] NotifyMountAddOnContent&lt;br /&gt;
|-&lt;br /&gt;
| 12 || [13.0.0+] NotifyUnmountAddOnContent&lt;br /&gt;
|-&lt;br /&gt;
| 13 || [13.0.0+] IsAddOnContentMountedForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 50 || [13.0.0+] CheckAddOnContentMountStatus&lt;br /&gt;
|-&lt;br /&gt;
| 100 || [7.0.0+] [[#IPurchaseEventManager|CreateEcPurchasedEventManager]]&lt;br /&gt;
|-&lt;br /&gt;
| 101 || [9.0.0+] [[#IPurchaseEventManager|CreatePermanentEcPurchasedEventManager]]&lt;br /&gt;
|-&lt;br /&gt;
| 110 || [12.0.0+] [[#IContentsServiceManager|CreateContentsServiceManager]]&lt;br /&gt;
|-&lt;br /&gt;
| 200 || [13.1.0+] SetRequiredAddOnContentsOnContentsAvailabilityTransition&lt;br /&gt;
|-&lt;br /&gt;
| 300 || [16.0.0+] SetupHostAddOnContent&lt;br /&gt;
|-&lt;br /&gt;
| 301 || [16.0.0+] GetRegisteredAddOnContentPath&lt;br /&gt;
|-&lt;br /&gt;
| 302 || [16.0.0+] UpdateCachedList&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IPurchaseEventManager ==&lt;br /&gt;
This is &amp;quot;nn::ec::IPurchaseEventManager&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || SetDefaultDeliveryTarget&lt;br /&gt;
|-&lt;br /&gt;
| 1 || SetDeliveryTarget&lt;br /&gt;
|-&lt;br /&gt;
| 2 || GetPurchasedEventReadableHandle&lt;br /&gt;
|-&lt;br /&gt;
| 3 || PopPurchasedProductInfo&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [9.0.0+] PopPurchasedProductInfoWithUid&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IContentsServiceManager ==&lt;br /&gt;
This is &amp;quot;nn::ec::IContentsServiceManager&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [12.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [16.0.0+] RequestContentsAuthorizationTokenDeprecated ([12.0.0-15.0.1] [[#RequestContentsAuthorizationToken]])&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [16.0.0+] RequestContentsAuthorizationToken&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== RequestContentsAuthorizationToken ===&lt;br /&gt;
Takes a total of 0x50-bytes of input, a PID, a type-0x5 input buffer. Returns an [[#IAsyncData|IAsyncData]] and an output handle.&lt;br /&gt;
&lt;br /&gt;
== IAsyncData ==&lt;br /&gt;
This is &amp;quot;nn::ec::detail::IAsyncData&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [12.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetSize&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Get&lt;br /&gt;
|-&lt;br /&gt;
| 2 || Cancel&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ns:am =&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IApplicationManagerInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
[3.0.0+] This service was replaced by [[#ns:am2, ns:ec, ns:rid, ns:rt, ns:web, ns:ro, ns:sweb|ns:am2]].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#ListApplicationRecord]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GenerateApplicationRecordCount&lt;br /&gt;
|-&lt;br /&gt;
| 2 || GetApplicationRecordUpdateSystemEvent&lt;br /&gt;
|-&lt;br /&gt;
| 3 || GetApplicationView&lt;br /&gt;
|-&lt;br /&gt;
| 4 || DeleteApplicationEntity&lt;br /&gt;
|-&lt;br /&gt;
| 5 || DeleteApplicationCompletely&lt;br /&gt;
|-&lt;br /&gt;
| 6 || IsAnyApplicationEntityRedundant&lt;br /&gt;
|-&lt;br /&gt;
| 7 || DeleteRedundantApplicationEntity&lt;br /&gt;
|-&lt;br /&gt;
| 8 || IsApplicationEntityMovable&lt;br /&gt;
|-&lt;br /&gt;
| 9 || MoveApplicationEntity&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [[#CalculateApplicationOccupiedSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 16 || PushApplicationRecord&lt;br /&gt;
|-&lt;br /&gt;
| 17 || ListApplicationRecordContentMeta&lt;br /&gt;
|-&lt;br /&gt;
| 18 || CheckLaunchRights&lt;br /&gt;
|-&lt;br /&gt;
| 19 || [[#LaunchApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 21 || [[#GetApplicationContentPath]]&lt;br /&gt;
|-&lt;br /&gt;
| 22 || TerminateApplication&lt;br /&gt;
|-&lt;br /&gt;
| 23 || [2.0.0+] ResolveApplicationContentPath&lt;br /&gt;
|-&lt;br /&gt;
| 26 || BeginInstallApplication&lt;br /&gt;
|-&lt;br /&gt;
| 27 || DeleteApplicationRecord&lt;br /&gt;
|-&lt;br /&gt;
| 30 || RequestApplicationUpdateInfo&lt;br /&gt;
|-&lt;br /&gt;
| 31 || RequestUpdateApplication&lt;br /&gt;
|-&lt;br /&gt;
| 32 || CancelApplicationDownload&lt;br /&gt;
|-&lt;br /&gt;
| 33 || ResumeApplicationDownload&lt;br /&gt;
|-&lt;br /&gt;
| 34 || ClearTaskStatusList&lt;br /&gt;
|-&lt;br /&gt;
| 35 || UpdateVersionList&lt;br /&gt;
|-&lt;br /&gt;
| 36 || PushLaunchVersion&lt;br /&gt;
|-&lt;br /&gt;
| 37 || ListRequiredVersion&lt;br /&gt;
|-&lt;br /&gt;
| 38 || CheckApplicationLaunchVersion&lt;br /&gt;
|-&lt;br /&gt;
| 39 || CheckApplicationLaunchRights&lt;br /&gt;
|-&lt;br /&gt;
| 40 || GetApplicationLogoData&lt;br /&gt;
|-&lt;br /&gt;
| 41 || CalculateApplicationDownloadRequiredSize&lt;br /&gt;
|-&lt;br /&gt;
| 42 || CleanupSdCard&lt;br /&gt;
|-&lt;br /&gt;
| 43 || [[#CheckSdCardMountStatus]]&lt;br /&gt;
|-&lt;br /&gt;
| 44 || GetSdCardMountStatusChangedEvent&lt;br /&gt;
|-&lt;br /&gt;
| 45 || GetGameCardAttachmentEvent&lt;br /&gt;
|-&lt;br /&gt;
| 46 || GetGameCardAttachmentInfo&lt;br /&gt;
|-&lt;br /&gt;
| 47 || [[#GetTotalSpaceSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 48 || [[#GetFreeSpaceSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 49 || GetSdCardRemovedEvent&lt;br /&gt;
|-&lt;br /&gt;
| 52 || GetGameCardUpdateDetectionEvent&lt;br /&gt;
|-&lt;br /&gt;
| 53 || DisableApplicationAutoDelete&lt;br /&gt;
|-&lt;br /&gt;
| 54 || EnableApplicationAutoDelete&lt;br /&gt;
|-&lt;br /&gt;
| 55 || [[#GetApplicationDesiredLanguage]]&lt;br /&gt;
|-&lt;br /&gt;
| 56 || SetApplicationTerminateResult&lt;br /&gt;
|-&lt;br /&gt;
| 57 || ClearApplicationTerminateResult&lt;br /&gt;
|-&lt;br /&gt;
| 58 || GetLastSdCardMountUnexpectedResult&lt;br /&gt;
|-&lt;br /&gt;
| 59 || ConvertApplicationLanguageToLanguageCode&lt;br /&gt;
|-&lt;br /&gt;
| 60 || [[#ConvertLanguageCodeToApplicationLanguage]]&lt;br /&gt;
|-&lt;br /&gt;
| 61 || GetBackgroundDownloadStressTaskInfo&lt;br /&gt;
|-&lt;br /&gt;
| 62 || GetGameCardStopper&lt;br /&gt;
|-&lt;br /&gt;
| 63 || IsSystemProgramInstalled&lt;br /&gt;
|-&lt;br /&gt;
| 64 || [2.0.0+] StartApplyDeltaTask&lt;br /&gt;
|-&lt;br /&gt;
| 65 || [2.0.0+] GetRequestServerStopper&lt;br /&gt;
|-&lt;br /&gt;
| 100 || ResetToFactorySettings&lt;br /&gt;
|-&lt;br /&gt;
| 101 || ResetToFactorySettingsWithoutUserSaveData&lt;br /&gt;
|-&lt;br /&gt;
| 102 || [2.0.0+] ResetToFactorySettingsForRefurbishment&lt;br /&gt;
|-&lt;br /&gt;
| 200 || CalculateUserSaveDataStatistics&lt;br /&gt;
|-&lt;br /&gt;
| 201 || DeleteUserSaveDataAll&lt;br /&gt;
|-&lt;br /&gt;
| 210 || DeleteUserSystemSaveData&lt;br /&gt;
|-&lt;br /&gt;
| 220 || UnregisterNetworkServiceAccount&lt;br /&gt;
|-&lt;br /&gt;
| 300 || GetApplicationShellEvent&lt;br /&gt;
|-&lt;br /&gt;
| 301 || PopApplicationShellEventInfo&lt;br /&gt;
|-&lt;br /&gt;
| 302 || LaunchLibraryApplet&lt;br /&gt;
|-&lt;br /&gt;
| 303 || TerminateLibraryApplet&lt;br /&gt;
|-&lt;br /&gt;
| 304 || LaunchSystemApplet&lt;br /&gt;
|-&lt;br /&gt;
| 305 || TerminateSystemApplet&lt;br /&gt;
|-&lt;br /&gt;
| 306 || LaunchOverlayApplet&lt;br /&gt;
|-&lt;br /&gt;
| 307 || TerminateOverlayApplet&lt;br /&gt;
|-&lt;br /&gt;
| 400 || [[#GetApplicationControlData]]&lt;br /&gt;
|-&lt;br /&gt;
| 401 || InvalidateAllApplicationControlCache&lt;br /&gt;
|-&lt;br /&gt;
| 402 || RequestDownloadApplicationControlData&lt;br /&gt;
|-&lt;br /&gt;
| 403 || GetMaxApplicationControlCacheCount&lt;br /&gt;
|-&lt;br /&gt;
| 404 || [2.0.0+] InvalidateApplicationControlCache&lt;br /&gt;
|-&lt;br /&gt;
| 405 || [2.0.0+] ListApplicationControlCacheEntryInfo&lt;br /&gt;
|-&lt;br /&gt;
| 502 || [2.0.0+] RequestCheckGameCardRegistration&lt;br /&gt;
|-&lt;br /&gt;
| 503 || [2.0.0+] RequestGameCardRegistrationGoldPoint&lt;br /&gt;
|-&lt;br /&gt;
| 504 || [2.0.0+] RequestRegisterGameCard&lt;br /&gt;
|-&lt;br /&gt;
| 600 || [2.0.0+] [[#CountApplicationContentMeta]]&lt;br /&gt;
|-&lt;br /&gt;
| 601 || [2.0.0+] [[#ListApplicationContentMetaStatus]]&lt;br /&gt;
|-&lt;br /&gt;
| 602 || [2.0.0+] ListOwnedAndInstalledAddOnContent&lt;br /&gt;
|-&lt;br /&gt;
| 603 || [2.0.0+] GetOwnedApplicationContentMetaStatus&lt;br /&gt;
|-&lt;br /&gt;
| 604 || [2.0.0+] RegisterContentsExternalKey&lt;br /&gt;
|-&lt;br /&gt;
| 605 || [2.0.0+] ListApplicationContentMetaStatusWithRightsCheck&lt;br /&gt;
|-&lt;br /&gt;
| 700 || [2.0.0+] PushDownloadTaskList&lt;br /&gt;
|-&lt;br /&gt;
| 701 || [2.0.0+] [[#ClearTaskStatusList]]&lt;br /&gt;
|-&lt;br /&gt;
| 702 || [2.0.0+] [[#RequestDownloadTaskList]]&lt;br /&gt;
|-&lt;br /&gt;
| 703 || [2.0.0+] [[#RequestEnsureDownloadTask]]&lt;br /&gt;
|-&lt;br /&gt;
| 704 || [2.0.0+] [[#ListDownloadTaskStatus]]&lt;br /&gt;
|-&lt;br /&gt;
| 705 || [2.0.0+] RequestDownloadTaskListData&lt;br /&gt;
|-&lt;br /&gt;
| 800 || [2.0.0+] RequestVersionList&lt;br /&gt;
|-&lt;br /&gt;
| 801 || [2.0.0+] ListVersionList&lt;br /&gt;
|-&lt;br /&gt;
| 900 || [2.0.0+] GetApplicationRecord&lt;br /&gt;
|-&lt;br /&gt;
| 901 || [2.0.0+] GetApplicationRecordProperty&lt;br /&gt;
|-&lt;br /&gt;
| 902 || [2.0.0+] EnableApplicationAutoUpdate&lt;br /&gt;
|-&lt;br /&gt;
| 903 || [2.0.0+] DisableApplicationAutoUpdate&lt;br /&gt;
|-&lt;br /&gt;
| 904 || [2.0.0+] TouchApplication&lt;br /&gt;
|-&lt;br /&gt;
| 905 || [2.0.0+] RequestApplicationUpdate&lt;br /&gt;
|-&lt;br /&gt;
| 906 || [2.0.0+] IsApplicationUpdateRequested&lt;br /&gt;
|-&lt;br /&gt;
| 907 || [2.0.0+] WithdrawApplicationUpdateRequest&lt;br /&gt;
|-&lt;br /&gt;
| 908 || [2.0.0+] ListApplicationRecordInstalledContentMeta&lt;br /&gt;
|-&lt;br /&gt;
| 1000 || [2.0.0+] RequestVerifyApplication&lt;br /&gt;
|-&lt;br /&gt;
| 1001 || [2.0.0+] CorruptApplicationForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 1200 || [2.0.0+] [[#NeedsUpdateVulnerability]]&lt;br /&gt;
|-&lt;br /&gt;
| 1300 || [2.0.0+] IsAnyApplicationEntityInstalled&lt;br /&gt;
|-&lt;br /&gt;
| 1301 || [2.0.0+] DeleteApplicationContentEntities&lt;br /&gt;
|-&lt;br /&gt;
| 1302 || [2.0.0+] CleanupUnrecordedApplicationEntity&lt;br /&gt;
|-&lt;br /&gt;
| 1400 || [2.0.0+] PrepareShutdown&lt;br /&gt;
|-&lt;br /&gt;
| 1500 || [2.0.0+] FormatSdCard&lt;br /&gt;
|-&lt;br /&gt;
| 1501 || [2.0.0+] NeedsSystemUpdateToFormatSdCard&lt;br /&gt;
|-&lt;br /&gt;
| 1502 || [2.0.0+] GetLastSdCardFormatUnexpectedResult&lt;br /&gt;
|-&lt;br /&gt;
| 1503 || [2.0.0+] DetachSdCard&lt;br /&gt;
|-&lt;br /&gt;
| 1600 || [2.0.0+] GetSystemSeedForPseudoDeviceId&lt;br /&gt;
|-&lt;br /&gt;
| 1700 || [2.0.0+] ListApplicationDownloadingContentMeta&lt;br /&gt;
|-&lt;br /&gt;
| 1800 || [2.0.0+] IsNotificationSetupCompleted&lt;br /&gt;
|-&lt;br /&gt;
| 1801 || [2.0.0+] GetLastNotificationInfoCount&lt;br /&gt;
|-&lt;br /&gt;
| 1802 || [2.0.0+] ListLastNotificationInfo&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== ListApplicationRecord ==&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of [[#ApplicationRecord]] and an s32 entry_offset, returns an output s32 out_entrycount.&lt;br /&gt;
&lt;br /&gt;
Returns an array of entries with the below format using the specified offset and count.&lt;br /&gt;
&lt;br /&gt;
== LaunchApplication ==&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output u64 PID.&lt;br /&gt;
&lt;br /&gt;
Launches an application title which is registered with NS.&lt;br /&gt;
&lt;br /&gt;
== GetApplicationContentPath ==&lt;br /&gt;
Takes a 0x16-type output buffer, an u8 [[NCM_services#ContentType|ContentType]], and an [[NCM_services#ApplicationId|ApplicationId]].&lt;br /&gt;
&lt;br /&gt;
The input [[NCM_services#ApplicationId|ApplicationId]] is used with the application-title table like various other cmds, anything not in that table can&#039;t be used with this.&lt;br /&gt;
&lt;br /&gt;
Returns a string path for the specified type of patch content with this [[NCM_services#ApplicationId|ApplicationId]], otherwise returns regular-application paths when update-title not installed. Returns an error when the specified type of content doesn&#039;t exist for this title. Starts with &amp;quot;@{SdCardContent,UserContent}://&amp;quot; and ends in &amp;quot;.nca&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
For gamecard content, the output path is: &amp;quot;@GcSXXXXXXXX:/&amp;lt;NcaId&amp;gt;.nca&amp;quot;. NCA-type0 with gamecard returns 0 with an empty output string.&lt;br /&gt;
&lt;br /&gt;
The output string is then used by the user-process with [[Filesystem_services|FS]] to mount the content.&lt;br /&gt;
&lt;br /&gt;
== GetTotalSpaceSize ==&lt;br /&gt;
Takes an input u8 [[NCM_services#StorageId|StorageId]], no output.&lt;br /&gt;
&lt;br /&gt;
The StorageId must be SdCard.&lt;br /&gt;
&lt;br /&gt;
Returns the s64 from [[NCM_services#IContentStorage]] GetFreeSpaceSize.&lt;br /&gt;
&lt;br /&gt;
== GetFreeSpaceSize ==&lt;br /&gt;
Takes an input u8 [[NCM_services#StorageId|StorageId]], no output.&lt;br /&gt;
&lt;br /&gt;
The StorageId must be SdCard.&lt;br /&gt;
&lt;br /&gt;
Returns the s64 from [[NCM_services#IContentStorage]] GetTotalSpaceSize.&lt;br /&gt;
&lt;br /&gt;
== GetApplicationDesiredLanguage ==&lt;br /&gt;
Takes an input u8 language-bitmask, returns an output u8 [[control.nacp]] langentry index.&lt;br /&gt;
&lt;br /&gt;
User-processes generate the language-bitmask with the following for all 16 lang-entries: &amp;lt;code&amp;gt;if(&amp;lt;either string in langentry[i] is non-empty&amp;gt;)bitmask |= 1&amp;lt;&amp;lt;i&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== ConvertLanguageCodeToApplicationLanguage ==&lt;br /&gt;
Takes an input u8 pointer for the resulting Id to be written to and a string represented as a u64 (i.e 0x53552D6E65 for &#039;en-US&#039;).&lt;br /&gt;
&lt;br /&gt;
Returns 0 if an ID was successfully found, otherwise returns 0x25810.&lt;br /&gt;
&lt;br /&gt;
== GetApplicationControlData ==&lt;br /&gt;
Takes an input u8 [[#ApplicationControlSource]], an [[NCM_services#ApplicationId|ApplicationId]], and a type-0x6 output buffer. Returns an output u32 for actual_size. Official user-processes use buffer size 0x24000. [[qlaunch]] only uses source value 0x1 (Storage if not in cache).&lt;br /&gt;
&lt;br /&gt;
Loads cached [[control.nacp]] to buf+0 and the cached icon to buf+0x4000. Returns an error if the buffer is too small.&lt;br /&gt;
&lt;br /&gt;
== ListApplicationContentMetaStatus ==&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of [[#ApplicationContentMetaStatus]], an input s32 index and [[NCM_services#ApplicationId|ApplicationId]], returns an output s32 out_entrycount.&lt;br /&gt;
&lt;br /&gt;
Returns 0x10-byte entries using the specified [[NCM_services#ApplicationId|ApplicationId]] starting at the specified index. Can only return game titles. The second entry if any is the update-title usually. When the input entryindex is &amp;gt;= totalentries, this will return 0 with out_entrycount=0.&lt;br /&gt;
&lt;br /&gt;
= ns:am2, ns:ec, ns:rid, ns:rt, ns:web, ns:ro, ns:sweb =&lt;br /&gt;
These are &amp;quot;nn::ns::detail::IServiceGetterInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
These commands check a state field for a command-specific bit and returns an error if not set, this is a permissions check for service+command.&lt;br /&gt;
&lt;br /&gt;
[11.0.0+] ns:ro was added.&lt;br /&gt;
&lt;br /&gt;
[15.0.0+] ns:sweb was added.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Permission bit&lt;br /&gt;
|-&lt;br /&gt;
| 7988 || [6.0.0+] [[#IDynamicRightsInterface|GetDynamicRightsInterface]] || 10&lt;br /&gt;
|-&lt;br /&gt;
| 7989 || [5.1.0+] [[#IReadOnlyApplicationControlDataInterface|GetReadOnlyApplicationControlDataInterface]] || 9&lt;br /&gt;
|-&lt;br /&gt;
| 7991 || [5.0.0+] [[#IReadOnlyApplicationRecordInterface|GetReadOnlyApplicationRecordInterface]] || 8&lt;br /&gt;
|-&lt;br /&gt;
| 7992 || [4.0.0+] [[#IECommerceInterface|GetECommerceInterface]] || 7&lt;br /&gt;
|-&lt;br /&gt;
| 7993 || [4.0.0+] [[#IApplicationVersionInterface|GetApplicationVersionInterface]] || 6&lt;br /&gt;
|-&lt;br /&gt;
| 7994 || [[#IFactoryResetInterface|GetFactoryResetInterface]] || 5&lt;br /&gt;
|-&lt;br /&gt;
| 7995 || [[#IAccountProxyInterface|GetAccountProxyInterface]] || 4&lt;br /&gt;
|-&lt;br /&gt;
| 7996 || [[#IApplicationManagerInterface|GetApplicationManagerInterface]] || 3&lt;br /&gt;
|-&lt;br /&gt;
| 7997 || [[#IDownloadTaskInterface|GetDownloadTaskInterface]] || 1&lt;br /&gt;
|-&lt;br /&gt;
| 7998 || [[#IContentManagementInterface|GetContentManagementInterface]] || 0&lt;br /&gt;
|-&lt;br /&gt;
| 7999 || [[#IDocumentInterface|GetDocumentInterface]] || 2&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Permissions state field with each service:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Service || Permissions&lt;br /&gt;
|-&lt;br /&gt;
| ns:web || 0x304&lt;br /&gt;
|-&lt;br /&gt;
| ns:ec || 0x83&lt;br /&gt;
|-&lt;br /&gt;
| ns:sweb || 0x387&lt;br /&gt;
|-&lt;br /&gt;
| ns:rid || 0x10&lt;br /&gt;
|-&lt;br /&gt;
| ns:rt || 0x20&lt;br /&gt;
|-&lt;br /&gt;
| ns:ro || 0x301&lt;br /&gt;
|-&lt;br /&gt;
| ns:am2 || 0x7FF&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IAccountProxyInterface ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IAccountProxyInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || CreateUserAccount&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IApplicationManagerInterface ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IApplicationManagerInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#ListApplicationRecord]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GenerateApplicationRecordCount&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [[#GetApplicationRecordUpdateSystemEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [[#GetApplicationViewDeprecated]]&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [[#DeleteApplicationEntity]]&lt;br /&gt;
|-&lt;br /&gt;
| 5 || [[#DeleteApplicationCompletely]]&lt;br /&gt;
|-&lt;br /&gt;
| 6 || IsAnyApplicationEntityRedundant&lt;br /&gt;
|-&lt;br /&gt;
| 7 || [[#DeleteRedundantApplicationEntity]]&lt;br /&gt;
|-&lt;br /&gt;
| 8 || [[#IsApplicationEntityMovable]]&lt;br /&gt;
|-&lt;br /&gt;
| 9 || [1.0.0-9.2.0] [[#MoveApplicationEntity]]&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [[#CalculateApplicationOccupiedSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 16 || PushApplicationRecord&lt;br /&gt;
|-&lt;br /&gt;
| 17 || ListApplicationRecordContentMeta&lt;br /&gt;
|-&lt;br /&gt;
| 19 || [1.0.0-5.1.0] LaunchApplicationOld&lt;br /&gt;
|-&lt;br /&gt;
| 21 || [[#GetApplicationContentPath]]&lt;br /&gt;
|-&lt;br /&gt;
| 22 || TerminateApplication&lt;br /&gt;
|-&lt;br /&gt;
| 23 || ResolveApplicationContentPath&lt;br /&gt;
|-&lt;br /&gt;
| 26 || BeginInstallApplication&lt;br /&gt;
|-&lt;br /&gt;
| 27 || DeleteApplicationRecord&lt;br /&gt;
|-&lt;br /&gt;
| 30 || [[#RequestApplicationUpdateInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 31 || [1.0.0-3.0.2] RequestUpdateApplication&lt;br /&gt;
|-&lt;br /&gt;
| 32 || [[#CancelApplicationDownload]]&lt;br /&gt;
|-&lt;br /&gt;
| 33 || [[#ResumeApplicationDownload]]&lt;br /&gt;
|-&lt;br /&gt;
| 35 || UpdateVersionList&lt;br /&gt;
|-&lt;br /&gt;
| 36 || PushLaunchVersion&lt;br /&gt;
|-&lt;br /&gt;
| 37 || ListRequiredVersion&lt;br /&gt;
|-&lt;br /&gt;
| 38 || [[#CheckApplicationLaunchVersion]]&lt;br /&gt;
|-&lt;br /&gt;
| 39 || [1.0.0-6.2.0] CheckApplicationLaunchRights&lt;br /&gt;
|-&lt;br /&gt;
| 40 || GetApplicationLogoData&lt;br /&gt;
|-&lt;br /&gt;
| 41 || CalculateApplicationDownloadRequiredSize&lt;br /&gt;
|-&lt;br /&gt;
| 42 || [[#CleanupSdCard]]&lt;br /&gt;
|-&lt;br /&gt;
| 43 || [[#CheckSdCardMountStatus]]&lt;br /&gt;
|-&lt;br /&gt;
| 44 || [[#GetSdCardMountStatusChangedEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 45 || GetGameCardAttachmentEvent&lt;br /&gt;
|-&lt;br /&gt;
| 46 || GetGameCardAttachmentInfo&lt;br /&gt;
|-&lt;br /&gt;
| 47 || [[#GetTotalSpaceSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 48 || [[#GetFreeSpaceSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 49 || GetSdCardRemovedEvent&lt;br /&gt;
|-&lt;br /&gt;
| 52 || [[#GetGameCardUpdateDetectionEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 53 || [[#DisableApplicationAutoDelete]]&lt;br /&gt;
|-&lt;br /&gt;
| 54 || [[#EnableApplicationAutoDelete]]&lt;br /&gt;
|-&lt;br /&gt;
| 55 || GetApplicationDesiredLanguage&lt;br /&gt;
|-&lt;br /&gt;
| 56 || [[#SetApplicationTerminateResult]]&lt;br /&gt;
|-&lt;br /&gt;
| 57 || [[#ClearApplicationTerminateResult]]&lt;br /&gt;
|-&lt;br /&gt;
| 58 || [[#GetLastSdCardMountUnexpectedResult]]&lt;br /&gt;
|-&lt;br /&gt;
| 59 || ConvertApplicationLanguageToLanguageCode&lt;br /&gt;
|-&lt;br /&gt;
| 60 || [[#ConvertLanguageCodeToApplicationLanguage]]&lt;br /&gt;
|-&lt;br /&gt;
| 61 || GetBackgroundDownloadStressTaskInfo&lt;br /&gt;
|-&lt;br /&gt;
| 62 || GetGameCardStopper&lt;br /&gt;
|-&lt;br /&gt;
| 63 || IsSystemProgramInstalled&lt;br /&gt;
|-&lt;br /&gt;
| 64 || StartApplyDeltaTask&lt;br /&gt;
|-&lt;br /&gt;
| 65 || [[#GetRequestServerStopper]]&lt;br /&gt;
|-&lt;br /&gt;
| 66 || [3.0.0+] GetBackgroundApplyDeltaStressTaskInfo&lt;br /&gt;
|-&lt;br /&gt;
| 67 || [3.0.0+] [[#CancelApplicationApplyDelta]]&lt;br /&gt;
|-&lt;br /&gt;
| 68 || [3.0.0+] [[#ResumeApplicationApplyDelta]]&lt;br /&gt;
|-&lt;br /&gt;
| 69 || [3.0.0+] [[#CalculateApplicationApplyDeltaRequiredSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 70 || [3.0.0+] [[#ResumeAll]]&lt;br /&gt;
|-&lt;br /&gt;
| 71 || [3.0.0+] [[#GetStorageSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 80 || [3.0.0+] RequestDownloadApplication&lt;br /&gt;
|-&lt;br /&gt;
| 81 || [3.0.0+] RequestDownloadAddOnContent&lt;br /&gt;
|-&lt;br /&gt;
| 82 || [3.0.0+] DownloadApplication&lt;br /&gt;
|-&lt;br /&gt;
| 83 || [4.0.0-6.2.0] CheckApplicationResumeRights&lt;br /&gt;
|-&lt;br /&gt;
| 84 || [4.0.0-16.1.0] GetDynamicCommitEvent&lt;br /&gt;
|-&lt;br /&gt;
| 85 || [4.0.0+] [[#RequestUpdateApplication2]]&lt;br /&gt;
|-&lt;br /&gt;
| 86 || [4.0.0+] EnableApplicationCrashReport&lt;br /&gt;
|-&lt;br /&gt;
| 87 || [4.0.0+] IsApplicationCrashReportEnabled&lt;br /&gt;
|-&lt;br /&gt;
| 90 || [15.0.0+] BoostSystemMemoryResourceLimit ([4.0.0-8.1.0] BoostSystemMemoryResourceLimit)&lt;br /&gt;
|-&lt;br /&gt;
| 91 || [5.0.0+] DeprecatedLaunchApplication&lt;br /&gt;
|-&lt;br /&gt;
| 92 || [5.0.0+] GetRunningApplicationProgramId&lt;br /&gt;
|-&lt;br /&gt;
| 93 || [5.0.0+] GetMainApplicationProgramIndex&lt;br /&gt;
|-&lt;br /&gt;
| 94 || [6.0.0+] [[#LaunchApplication_2|LaunchApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 95 || [6.0.0+] [[#GetApplicationLaunchInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 96 || [6.0.0+] [[#AcquireApplicationLaunchInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 97 || [6.0.0+] [[#GetMainApplicationProgramIndexByApplicationLaunchInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 98 || [6.0.0+] EnableApplicationAllThreadDumpOnCrash&lt;br /&gt;
|-&lt;br /&gt;
| 99 || [8.0.0+] [[#LaunchDevMenu]]&lt;br /&gt;
|-&lt;br /&gt;
| 100 || [[#ResetToFactorySettings]]&lt;br /&gt;
|-&lt;br /&gt;
| 101 || [[#ResetToFactorySettingsWithoutUserSaveData]]&lt;br /&gt;
|-&lt;br /&gt;
| 102 || [[#ResetToFactorySettingsForRefurbishment]]&lt;br /&gt;
|-&lt;br /&gt;
| 103 || [9.1.0+] [[#ResetToFactorySettingsWithPlatformRegion]]&lt;br /&gt;
|-&lt;br /&gt;
| 104 || [9.1.0+] [[#ResetToFactorySettingsWithPlatformRegionAuthentication]]&lt;br /&gt;
|-&lt;br /&gt;
| 105 || [10.0.0+] [[#RequestResetToFactorySettingsSecurely]]&lt;br /&gt;
|-&lt;br /&gt;
| 106 || [10.0.0+] [[#RequestResetToFactorySettingsWithPlatformRegionAuthenticationSecurely]]&lt;br /&gt;
|-&lt;br /&gt;
| 200 || CalculateUserSaveDataStatistics&lt;br /&gt;
|-&lt;br /&gt;
| 201 || [[#DeleteUserSaveDataAll]]&lt;br /&gt;
|-&lt;br /&gt;
| 210 || [[#DeleteUserSystemSaveData]]&lt;br /&gt;
|-&lt;br /&gt;
| 211 || [6.0.0+] [[#DeleteSaveData]]&lt;br /&gt;
|-&lt;br /&gt;
| 220 || [[#UnregisterNetworkServiceAccount]]&lt;br /&gt;
|-&lt;br /&gt;
| 221 || [6.0.0+] [[#UnregisterNetworkServiceAccountWithUserSaveDataDeletion]]&lt;br /&gt;
|-&lt;br /&gt;
| 300 || GetApplicationShellEvent&lt;br /&gt;
|-&lt;br /&gt;
| 301 || PopApplicationShellEventInfo&lt;br /&gt;
|-&lt;br /&gt;
| 302 || [[#LaunchLibraryApplet]]&lt;br /&gt;
|-&lt;br /&gt;
| 303 || TerminateLibraryApplet&lt;br /&gt;
|-&lt;br /&gt;
| 304 || [[#LaunchSystemApplet]]&lt;br /&gt;
|-&lt;br /&gt;
| 305 || TerminateSystemApplet&lt;br /&gt;
|-&lt;br /&gt;
| 306 || [[#LaunchOverlayApplet]]&lt;br /&gt;
|-&lt;br /&gt;
| 307 || TerminateOverlayApplet&lt;br /&gt;
|-&lt;br /&gt;
| 308 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 309 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 400 || [[#GetApplicationControlData]]&lt;br /&gt;
|-&lt;br /&gt;
| 401 || InvalidateAllApplicationControlCache&lt;br /&gt;
|-&lt;br /&gt;
| 402 || [[#RequestDownloadApplicationControlData]]&lt;br /&gt;
|-&lt;br /&gt;
| 403 || GetMaxApplicationControlCacheCount&lt;br /&gt;
|-&lt;br /&gt;
| 404 || InvalidateApplicationControlCache&lt;br /&gt;
|-&lt;br /&gt;
| 405 || ListApplicationControlCacheEntryInfo&lt;br /&gt;
|-&lt;br /&gt;
| 406 || [6.0.0-18.1.0] [[#GetApplicationControlProperty]]&lt;br /&gt;
|-&lt;br /&gt;
| 407 || [8.0.0+] [[#ListApplicationTitle]]&lt;br /&gt;
|-&lt;br /&gt;
| 408 || [8.0.0+] [[#ListApplicationIcon]]&lt;br /&gt;
|-&lt;br /&gt;
| 409 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 410 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 411 || [19.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 412 || [19.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 413 || [19.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 414 || [19.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 415 || [19.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 416 || [19.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 417 || [19.0.0+] InvalidateAllApplicationControlCacheOfTheStage&lt;br /&gt;
|-&lt;br /&gt;
| 418 || [19.0.0+] InvalidateApplicationControlCacheOfTheStage&lt;br /&gt;
|-&lt;br /&gt;
| 419 || [19.0.0+] RequestDownloadApplicationControlDataInBackground&lt;br /&gt;
|-&lt;br /&gt;
| 420 || [19.0.0+] CloneApplicationControlDataCacheForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 421 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 422 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 423 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 424 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 425 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 426 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 427 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 428 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 429 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 430 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 502 || [[#RequestCheckGameCardRegistration]]&lt;br /&gt;
|-&lt;br /&gt;
| 503 || [[#RequestGameCardRegistrationGoldPoint]]&lt;br /&gt;
|-&lt;br /&gt;
| 504 || [[#RequestRegisterGameCard]]&lt;br /&gt;
|-&lt;br /&gt;
| 505 || [3.0.0+] [[#GetGameCardMountFailureEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 506 || [3.0.0+] [[#IsGameCardInserted]]&lt;br /&gt;
|-&lt;br /&gt;
| 507 || [3.0.0+] [[#EnsureGameCardAccess]]&lt;br /&gt;
|-&lt;br /&gt;
| 508 || [3.0.0+] [[#GetLastGameCardMountFailureResult]]&lt;br /&gt;
|-&lt;br /&gt;
| 509 || [5.0.0+] [[#ListApplicationIdOnGameCard]]&lt;br /&gt;
|-&lt;br /&gt;
| 510 || [9.0.0+] [[#GetGameCardPlatformRegion]]&lt;br /&gt;
|-&lt;br /&gt;
| 511 || [19.0.0+] GetGameCardWakenReadyEvent&lt;br /&gt;
|-&lt;br /&gt;
| 512 || [19.0.0+] IsGameCardApplicationRunning&lt;br /&gt;
|-&lt;br /&gt;
| 513 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 514 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 515 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 516 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 517 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 518 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 519 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 600 || [[#CountApplicationContentMeta]]&lt;br /&gt;
|-&lt;br /&gt;
| 601 || [[#ListApplicationContentMetaStatus]]&lt;br /&gt;
|-&lt;br /&gt;
| 602 || [2.0.0-5.1.0] ListAvailableAddOnContent&lt;br /&gt;
|-&lt;br /&gt;
| 603 || GetOwnedApplicationContentMetaStatus&lt;br /&gt;
|-&lt;br /&gt;
| 604 || [1.0.0-15.0.1] RegisterContentsExternalKey&lt;br /&gt;
|-&lt;br /&gt;
| 605 || ListApplicationContentMetaStatusWithRightsCheck&lt;br /&gt;
|-&lt;br /&gt;
| 606 || [3.0.0+] GetContentMetaStorage&lt;br /&gt;
|-&lt;br /&gt;
| 607 || [6.0.0+] [[#ListAvailableAddOnContent]]&lt;br /&gt;
|-&lt;br /&gt;
| 609 || [13.0.0+] ListAvailabilityAssuredAddOnContent&lt;br /&gt;
|-&lt;br /&gt;
| 610 || [14.0.0+] GetInstalledContentMetaStorage&lt;br /&gt;
|-&lt;br /&gt;
| 611 || [16.0.0+] PrepareAddOnContent&lt;br /&gt;
|-&lt;br /&gt;
| 700 || PushDownloadTaskList&lt;br /&gt;
|-&lt;br /&gt;
| 701 || [[#ClearTaskStatusList]]&lt;br /&gt;
|-&lt;br /&gt;
| 702 || [[#RequestDownloadTaskList]]&lt;br /&gt;
|-&lt;br /&gt;
| 703 || [[#RequestEnsureDownloadTask]]&lt;br /&gt;
|-&lt;br /&gt;
| 704 || [[#ListDownloadTaskStatus]]&lt;br /&gt;
|-&lt;br /&gt;
| 705 || [[#RequestDownloadTaskListData]]&lt;br /&gt;
|-&lt;br /&gt;
| 800 || RequestVersionList&lt;br /&gt;
|-&lt;br /&gt;
| 801 || ListVersionList&lt;br /&gt;
|-&lt;br /&gt;
| 802 || [3.0.0+] [[#RequestVersionListData]]&lt;br /&gt;
|-&lt;br /&gt;
| 900 || GetApplicationRecord&lt;br /&gt;
|-&lt;br /&gt;
| 901 || GetApplicationRecordProperty&lt;br /&gt;
|-&lt;br /&gt;
| 902 || EnableApplicationAutoUpdate&lt;br /&gt;
|-&lt;br /&gt;
| 903 || DisableApplicationAutoUpdate&lt;br /&gt;
|-&lt;br /&gt;
| 904 || [[#TouchApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 905 || RequestApplicationUpdate&lt;br /&gt;
|-&lt;br /&gt;
| 906 || [[#IsApplicationUpdateRequested]]&lt;br /&gt;
|-&lt;br /&gt;
| 907 || [[#WithdrawApplicationUpdateRequest]]&lt;br /&gt;
|-&lt;br /&gt;
| 908 || ListApplicationRecordInstalledContentMeta&lt;br /&gt;
|-&lt;br /&gt;
| 909 || [3.0.0-14.1.2] WithdrawCleanupAddOnContentsWithNoRightsRecommendation&lt;br /&gt;
|-&lt;br /&gt;
| 910 || [5.0.0+] HasApplicationRecord&lt;br /&gt;
|-&lt;br /&gt;
| 911 || [5.1.0+] SetPreInstalledApplication&lt;br /&gt;
|-&lt;br /&gt;
| 912 || [5.1.0+] ClearPreInstalledApplicationFlag&lt;br /&gt;
|-&lt;br /&gt;
| 913 || [9.0.0+] ListAllApplicationRecord&lt;br /&gt;
|-&lt;br /&gt;
| 914 || [9.0.0+] HideApplicationRecord&lt;br /&gt;
|-&lt;br /&gt;
| 915 || [9.0.0+] ShowApplicationRecord&lt;br /&gt;
|-&lt;br /&gt;
| 916 || [11.0.0+] IsApplicationAutoDeleteDisabled&lt;br /&gt;
|-&lt;br /&gt;
| 917 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 918 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 919 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 920 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 921 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 922 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 923 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 924 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 925 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 926 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 927 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 928 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 929 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 930 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 931 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 933 || [20.1.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 934 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 935 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 936 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 1000 || [[#RequestVerifyApplicationDeprecated]]&lt;br /&gt;
|-&lt;br /&gt;
| 1001 || CorruptApplicationForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 1002 || [3.0.0-9.2.0] [[#RequestVerifyAddOnContentsRights]]&lt;br /&gt;
|-&lt;br /&gt;
| 1003 || [5.0.0+] [[#RequestVerifyApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 1004 || [5.0.0+] CorruptContentForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 1200 || [[#NeedsUpdateVulnerability]]&lt;br /&gt;
|-&lt;br /&gt;
| 1300 || [[#IsAnyApplicationEntityInstalled]]&lt;br /&gt;
|-&lt;br /&gt;
| 1301 || DeleteApplicationContentEntities&lt;br /&gt;
|-&lt;br /&gt;
| 1302 || CleanupUnrecordedApplicationEntity&lt;br /&gt;
|-&lt;br /&gt;
| 1303 || [3.0.0-9.2.0] CleanupAddOnContentsWithNoRights&lt;br /&gt;
|-&lt;br /&gt;
| 1304 || [3.0.0+] DeleteApplicationContentEntity&lt;br /&gt;
|-&lt;br /&gt;
| 1308 || [5.0.0+] DeleteApplicationCompletelyForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 1309 || [6.0.0+] [[#CleanupUnavailableAddOnContents]]&lt;br /&gt;
|-&lt;br /&gt;
| 1310 || [10.0.0+] [[#RequestMoveApplicationEntity]]&lt;br /&gt;
|-&lt;br /&gt;
| 1311 || [10.0.0+] [[#EstimateSizeToMove]]&lt;br /&gt;
|-&lt;br /&gt;
| 1312 || [10.0.0+] HasMovableEntity&lt;br /&gt;
|-&lt;br /&gt;
| 1313 || [11.0.0+] CleanupOrphanContents&lt;br /&gt;
|-&lt;br /&gt;
| 1314 || [11.0.0+] CheckPreconditionSatisfiedToMove&lt;br /&gt;
|-&lt;br /&gt;
| 1400 || PrepareShutdown&lt;br /&gt;
|-&lt;br /&gt;
| 1500 || [[#FormatSdCard]]&lt;br /&gt;
|-&lt;br /&gt;
| 1501 || [[#NeedsSystemUpdateToFormatSdCard]]&lt;br /&gt;
|-&lt;br /&gt;
| 1502 || [[#GetLastSdCardFormatUnexpectedResult]]&lt;br /&gt;
|-&lt;br /&gt;
| 1504 || [3.0.0+] InsertSdCard&lt;br /&gt;
|-&lt;br /&gt;
| 1505 || [3.0.0+] RemoveSdCard&lt;br /&gt;
|-&lt;br /&gt;
| 1506 || [9.0.0+] GetSdCardStartupStatus&lt;br /&gt;
|-&lt;br /&gt;
| 1508 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 1509 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 1510 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 1511 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 1512 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 1600 || GetSystemSeedForPseudoDeviceId&lt;br /&gt;
|-&lt;br /&gt;
| 1601 || [3.0.0+] ResetSystemSeedForPseudoDeviceId&lt;br /&gt;
|-&lt;br /&gt;
| 1700 || ListApplicationDownloadingContentMeta&lt;br /&gt;
|-&lt;br /&gt;
| 1701 || [3.0.0+] [[#GetApplicationView]]&lt;br /&gt;
|-&lt;br /&gt;
| 1702 || [3.0.0+] GetApplicationDownloadTaskStatus&lt;br /&gt;
|-&lt;br /&gt;
| 1703 || [4.0.0+] [[#GetApplicationViewDownloadErrorContext]]&lt;br /&gt;
|-&lt;br /&gt;
| 1704 || [8.0.0+] [[#GetApplicationViewWithPromotionInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 1705 || [11.0.0+] [[#IsPatchAutoDeletableApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 1706 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 1800 || IsNotificationSetupCompleted&lt;br /&gt;
|-&lt;br /&gt;
| 1801 || GetLastNotificationInfoCount&lt;br /&gt;
|-&lt;br /&gt;
| 1802 || [[#ListLastNotificationInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 1803 || [3.0.0+] [[#ListNotificationTask]]&lt;br /&gt;
|-&lt;br /&gt;
| 1900 || [3.0.0-12.1.0] IsActiveAccount&lt;br /&gt;
|-&lt;br /&gt;
| 1901 || [4.0.0+] [[#RequestDownloadApplicationPrepurchasedRights]]&lt;br /&gt;
|-&lt;br /&gt;
| 1902 || [5.0.0+] GetApplicationTicketInfo&lt;br /&gt;
|-&lt;br /&gt;
| 1903 || [13.1.0+] RequestDownloadApplicationPrepurchasedRightsForAccount&lt;br /&gt;
|-&lt;br /&gt;
| 2000 || [4.0.0+] [[#GetSystemDeliveryInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 2001 || [4.0.0+] [[#SelectLatestSystemDeliveryInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 2002 || [4.0.0+] [[#VerifyDeliveryProtocolVersion]]&lt;br /&gt;
|-&lt;br /&gt;
| 2003 || [4.0.0+] [[#GetApplicationDeliveryInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 2004 || [4.0.0+] [[#HasAllContentsToDeliver]]&lt;br /&gt;
|-&lt;br /&gt;
| 2005 || [4.0.0+] [[#CompareApplicationDeliveryInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 2006 || [4.0.0+] [[#CanDeliverApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 2007 || [4.0.0+] [[#ListContentMetaKeyToDeliverApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 2008 || [4.0.0+] [[#NeedsSystemUpdateToDeliverApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 2009 || [4.0.0+] [[#EstimateRequiredSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 2010 || [4.0.0+] [[#RequestReceiveApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 2011 || [4.0.0+] [[#CommitReceiveApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 2012 || [4.0.0+] [[#GetReceiveApplicationProgress]]&lt;br /&gt;
|-&lt;br /&gt;
| 2013 || [4.0.0+] [[#RequestSendApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 2014 || [4.0.0+] [[#GetSendApplicationProgress]]&lt;br /&gt;
|-&lt;br /&gt;
| 2015 || [4.0.0+] [[#CompareSystemDeliveryInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 2016 || [4.0.0+] [[#ListNotCommittedContentMeta]]&lt;br /&gt;
|-&lt;br /&gt;
| 2017 || [4.0.0+] [[#RecoverDownloadTask]]&lt;br /&gt;
|-&lt;br /&gt;
| 2018 || [5.0.0+] [[#GetApplicationDeliveryInfoHash]]&lt;br /&gt;
|-&lt;br /&gt;
| 2019 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2050 || [6.0.0+] [[#GetApplicationRightsOnClient]]&lt;br /&gt;
|-&lt;br /&gt;
| 2051 || [9.0.0+] InvalidateRightsIdCache&lt;br /&gt;
|-&lt;br /&gt;
| 2052 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2053 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2100 || [6.0.0+] [[#GetApplicationTerminateResult]]&lt;br /&gt;
|-&lt;br /&gt;
| 2101 || [6.0.0+] GetRawApplicationTerminateResult&lt;br /&gt;
|-&lt;br /&gt;
| 2150 || [6.0.0+] CreateRightsEnvironment&lt;br /&gt;
|-&lt;br /&gt;
| 2151 || [6.0.0+] DestroyRightsEnvironment&lt;br /&gt;
|-&lt;br /&gt;
| 2152 || [6.0.0+] ActivateRightsEnvironment&lt;br /&gt;
|-&lt;br /&gt;
| 2153 || [6.0.0+] DeactivateRightsEnvironment&lt;br /&gt;
|-&lt;br /&gt;
| 2154 || [6.0.0+] ForceActivateRightsContextForExit&lt;br /&gt;
|-&lt;br /&gt;
| 2155 || [7.0.0+] UpdateRightsEnvironmentStatus&lt;br /&gt;
|-&lt;br /&gt;
| 2156 || [10.0.0-12.1.0] CreateRightsEnvironmentForMicroApplication ([9.0.0-9.2.0] CreateRightsEnvironmentForPreomia)&lt;br /&gt;
|-&lt;br /&gt;
| 2160 || [6.0.0+] AddTargetApplicationToRightsEnvironment&lt;br /&gt;
|-&lt;br /&gt;
| 2161 || [6.0.0+] SetUsersToRightsEnvironment&lt;br /&gt;
|-&lt;br /&gt;
| 2170 || [6.0.0+] GetRightsEnvironmentStatus&lt;br /&gt;
|-&lt;br /&gt;
| 2171 || [6.0.0+] GetRightsEnvironmentStatusChangedEvent&lt;br /&gt;
|-&lt;br /&gt;
| 2180 || [6.0.0+] RequestExtendExpirationInRightsEnvironment&lt;br /&gt;
|-&lt;br /&gt;
| 2181 || [6.0.0+] GetResultOfExtendExpirationInRightsEnvironment&lt;br /&gt;
|-&lt;br /&gt;
| 2182 || [6.0.0+] SetActiveRightsContextUsingStateToRightsEnvironment&lt;br /&gt;
|-&lt;br /&gt;
| 2183 || [20.1.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2190 || [6.0.0+] [[#GetRightsEnvironmentHandleForApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 2199 || [6.0.0+] GetRightsEnvironmentCountForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 2200 || [6.0.0-9.2.0] GetGameCardApplicationCopyIdentifier&lt;br /&gt;
|-&lt;br /&gt;
| 2201 || [6.0.0-9.2.0] GetInstalledApplicationCopyIdentifier&lt;br /&gt;
|-&lt;br /&gt;
| 2250 || [6.0.0-6.2.0] RequestReportActiveELicence&lt;br /&gt;
|-&lt;br /&gt;
| 2300 || [6.0.0-8.1.0] ListEventLog&lt;br /&gt;
|-&lt;br /&gt;
| 2350 || [7.0.0+] PerformAutoUpdateByApplicationId&lt;br /&gt;
|-&lt;br /&gt;
| 2351 || [9.0.0+] [[#RequestNoDownloadRightsErrorResolution]]&lt;br /&gt;
|-&lt;br /&gt;
| 2352 || [9.0.0+] [[#RequestResolveNoDownloadRightsError]]&lt;br /&gt;
|-&lt;br /&gt;
| 2353 || [10.0.0+] GetApplicationDownloadTaskInfo&lt;br /&gt;
|-&lt;br /&gt;
| 2354 || [11.0.0+] PrioritizeApplicationBackgroundTask&lt;br /&gt;
|-&lt;br /&gt;
| 2355 || [12.0.0+] PreferStorageEfficientUpdate&lt;br /&gt;
|-&lt;br /&gt;
| 2356 || [12.0.0+] RequestStorageEfficientUpdatePreferable&lt;br /&gt;
|-&lt;br /&gt;
| 2357 || [15.0.0+] EnableMultiCoreDownload&lt;br /&gt;
|-&lt;br /&gt;
| 2358 || [15.0.0+] DisableMultiCoreDownload&lt;br /&gt;
|-&lt;br /&gt;
| 2359 || [15.0.0+] IsMultiCoreDownloadEnabled&lt;br /&gt;
|-&lt;br /&gt;
| 2360 || [19.0.0+] GetApplicationDownloadTaskCount&lt;br /&gt;
|-&lt;br /&gt;
| 2361 || [19.0.0+] GetMaxApplicationDownloadTaskCount&lt;br /&gt;
|-&lt;br /&gt;
| 2362 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2363 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2364 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2365 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2366 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2367 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2368 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2369 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2400 || [8.0.0+] [[#GetPromotionInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 2401 || [8.0.0+] CountPromotionInfo&lt;br /&gt;
|-&lt;br /&gt;
| 2402 || [8.0.0+] [[#ListPromotionInfo|ListPromotionInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 2403 || [8.0.0+] [[#ImportPromotionJsonForDebug]]&lt;br /&gt;
|-&lt;br /&gt;
| 2404 || [8.0.0+] [[#ClearPromotionInfoForDebug]]&lt;br /&gt;
|-&lt;br /&gt;
| 2500 || [8.0.0+] ConfirmAvailableTime&lt;br /&gt;
|-&lt;br /&gt;
| 2510 || [9.0.0+] [[#CreateApplicationResource]]&lt;br /&gt;
|-&lt;br /&gt;
| 2511 || [9.0.0+] [[#GetApplicationResource]]&lt;br /&gt;
|-&lt;br /&gt;
| 2513 || [10.0.0+] [[#LaunchMicroApplication]] ([9.0.0-9.2.0] LaunchPreomia)&lt;br /&gt;
|-&lt;br /&gt;
| 2514 || [9.0.0+] ClearTaskOfAsyncTaskManager&lt;br /&gt;
|-&lt;br /&gt;
| 2515 || [10.0.0+] CleanupAllPlaceHolderAndFragmentsIfNoTask&lt;br /&gt;
|-&lt;br /&gt;
| 2516 || [10.0.0-14.1.2] EnsureApplicationCertificate&lt;br /&gt;
|-&lt;br /&gt;
| 2517 || [13.0.0+] [[#CreateApplicationInstance]]&lt;br /&gt;
|-&lt;br /&gt;
| 2518 || [13.0.0+] UpdateQualificationForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 2519 || [13.0.0+] IsQualificationTransitionSupported&lt;br /&gt;
|-&lt;br /&gt;
| 2520 || [13.0.0+] IsQualificationTransitionSupportedByProcessId&lt;br /&gt;
|-&lt;br /&gt;
| 2521 || [13.0.0-16.1.0] GetRightsUserChangedEvent&lt;br /&gt;
|-&lt;br /&gt;
| 2522 || [14.0.0+] IsRomRedirectionAvailable&lt;br /&gt;
|-&lt;br /&gt;
| 2523 || [17.0.0+] GetProgramId&lt;br /&gt;
|-&lt;br /&gt;
| 2524 || [19.0.0+] &lt;br /&gt;
|-&lt;br /&gt;
| 2525 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2800 || [9.0.0+] GetApplicationIdOfPreomia&lt;br /&gt;
|-&lt;br /&gt;
| 3000 || [11.0.0+] [[#RegisterDeviceLockKey]]&lt;br /&gt;
|-&lt;br /&gt;
| 3001 || [11.0.0+] [[#UnregisterDeviceLockKey]]&lt;br /&gt;
|-&lt;br /&gt;
| 3002 || [11.0.0+] [[#VerifyDeviceLockKey]]&lt;br /&gt;
|-&lt;br /&gt;
| 3003 || [11.0.0+] [[#HideApplicationIcon]]&lt;br /&gt;
|-&lt;br /&gt;
| 3004 || [11.0.0+] [[#ShowApplicationIcon]]&lt;br /&gt;
|-&lt;br /&gt;
| 3005 || [11.0.0+] [[#HideApplicationTitle]]&lt;br /&gt;
|-&lt;br /&gt;
| 3006 || [11.0.0+] [[#ShowApplicationTitle]]&lt;br /&gt;
|-&lt;br /&gt;
| 3007 || [11.0.0+] [[#EnableGameCard]]&lt;br /&gt;
|-&lt;br /&gt;
| 3008 || [11.0.0+] [[#DisableGameCard]]&lt;br /&gt;
|-&lt;br /&gt;
| 3009 || [11.0.0+] [[#EnableLocalContentShare]]&lt;br /&gt;
|-&lt;br /&gt;
| 3010 || [11.0.0+] [[#DisableLocalContentShare]]&lt;br /&gt;
|-&lt;br /&gt;
| 3011 || [11.0.0+] [[#IsApplicationIconHidden]]&lt;br /&gt;
|-&lt;br /&gt;
| 3012 || [11.0.0+] [[#IsApplicationTitleHidden]]&lt;br /&gt;
|-&lt;br /&gt;
| 3013 || [11.0.0+] [[#IsGameCardEnabled]]&lt;br /&gt;
|-&lt;br /&gt;
| 3014 || [11.0.0+] [[#IsLocalContentShareEnabled]]&lt;br /&gt;
|-&lt;br /&gt;
| 3015 || [18.0.0+] GetNetworkUpdateRequiredByGameCardDetectionEvent&lt;br /&gt;
|-&lt;br /&gt;
| 3050 || [14.0.0+] ListAssignELicenseTaskResult&lt;br /&gt;
|-&lt;br /&gt;
| 3100 || [17.0.0+] [[#GetSafeSystemVersionCheckInfo|GetSafeSystemVersionCheckInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 3101 || [17.0.0+] [[#RequestUpdateSafeSystemVersionCheckInfo|RequestUpdateSafeSystemVersionCheckInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 3102 || [17.0.0+] [[#ResetSafeSystemVersionCheckInfo|ResetSafeSystemVersionCheckInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 3104 || [18.0.0+] GetApplicationNintendoLogo&lt;br /&gt;
|-&lt;br /&gt;
| 3105 || [18.0.0+] GetApplicationStartupMovie&lt;br /&gt;
|-&lt;br /&gt;
| 3150 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 4000 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4004 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4006 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4007 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4008 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4009 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4010 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4011 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4012 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4013 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4015 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4017 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4019 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4020 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4021 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4022 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4023 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4024 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4025 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4026 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4027 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4028 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4029 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4030 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4031 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4032 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4033 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4034 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4035 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4037 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4038 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4039 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4040 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4041 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4042 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4043 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4044 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4045 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4046 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4049 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4050 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4051 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4052 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4053 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4054 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4055 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4056 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4057 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4058 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4059 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4060 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4061 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4062 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4063 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4064 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4065 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4066 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4067 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4068 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4069 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4070 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4071 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4072 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4073 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4074 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4075 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4076 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4077 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4078 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4079 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4080 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4081 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4083 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4084 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4085 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4086 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4087 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4088 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4089 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4090 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4091 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4092 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4093 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4094 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4095 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4096 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4097 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4099 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 5000 || [18.0.0+] &lt;br /&gt;
|-&lt;br /&gt;
| 5001 || [18.0.0+] &lt;br /&gt;
|-&lt;br /&gt;
| 9999 || [10.0.0-10.2.0] GetApplicationCertificate&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[4.0.0+] RequestDownloadAddOnContent now takes an additional 8-bytes of input.&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationRecordUpdateSystemEvent ====&lt;br /&gt;
No input, returns an output Event handle with EventClearMode=1.&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationViewDeprecated ====&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of [[#ApplicationViewDeprecated]], a type-0x5 input buffer containing an array of u64 [[NCM_services#ApplicationId|ApplicationIds]], no output.&lt;br /&gt;
&lt;br /&gt;
On newer system-versions this is the same as [[#GetApplicationView]], except this converts the output from the func called in the loop from [[#ApplicationView]] to [[#ApplicationViewDeprecated]].&lt;br /&gt;
&lt;br /&gt;
==== DeleteApplicationEntity ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== DeleteApplicationCompletely ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== DeleteRedundantApplicationEntity ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== IsApplicationEntityMovable ====&lt;br /&gt;
Takes an input u8 [[NCM_services#StorageId|StorageId]], an [[NCM_services#ApplicationId|ApplicationId]], returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
==== MoveApplicationEntity ====&lt;br /&gt;
Takes an input u8 [[NCM_services#StorageId|StorageId]], an [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== RequestApplicationUpdateInfo ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
The data that can be read from the [[#IAsyncValue]] is [[#ApplicationUpdateInfo]].&lt;br /&gt;
&lt;br /&gt;
Before using the cmd, official sw uses [[Network_Interface_services#IsAnyInternetRequestAccepted|IsAnyInternetRequestAccepted]] with the output from [[Network_Interface_services#GetClientId|GetClientId]], throwing an error when the returned bool is false.&lt;br /&gt;
&lt;br /&gt;
==== CancelApplicationDownload ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== ResumeApplicationDownload ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== CheckApplicationLaunchVersion ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== CalculateApplicationDownloadRequiredSize ====&lt;br /&gt;
Takes an input u8 [[NCM_services#StorageId|StorageId]], an [[NCM_services#ApplicationId|ApplicationId]], returns an output s64.&lt;br /&gt;
&lt;br /&gt;
==== CleanupSdCard ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== GetSdCardMountStatusChangedEvent ====&lt;br /&gt;
No input, returns an output Event handle with EventClearMode=0.&lt;br /&gt;
&lt;br /&gt;
==== GetGameCardUpdateDetectionEvent ====&lt;br /&gt;
No input, returns an output Event handle with EventClearMode=0.&lt;br /&gt;
&lt;br /&gt;
This Event is used by [[qlaunch]] to check whether a card-sysupdate is required.&lt;br /&gt;
&lt;br /&gt;
==== DisableApplicationAutoDelete ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== EnableApplicationAutoDelete ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== SetApplicationTerminateResult ====&lt;br /&gt;
Takes an input u32 Result, an [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== ClearApplicationTerminateResult ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== GetLastSdCardMountUnexpectedResult ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== GetRequestServerStopper ====&lt;br /&gt;
No input, returns an output [[#IRequestServerStopper]].&lt;br /&gt;
&lt;br /&gt;
This increfs a state ref-count, with decref being handled when the object is closed. This ref-count is checked by [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]] and related cmds.&lt;br /&gt;
&lt;br /&gt;
==== CancelApplicationApplyDelta ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== ResumeApplicationApplyDelta ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== CalculateApplicationApplyDeltaRequiredSize ====&lt;br /&gt;
Takes an input u8 [[NCM_services#StorageId|StorageId]], an [[NCM_services#ApplicationId|ApplicationId]], returns an output s64.&lt;br /&gt;
&lt;br /&gt;
==== ResumeAll ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== GetStorageSize ====&lt;br /&gt;
Takes an input u8 [[NCM_services#StorageId|StorageId]], returns two output s64s.&lt;br /&gt;
&lt;br /&gt;
This temporarily mounts the [[Filesystem_services#OpenContentStorageFileSystem|ContentStorage]] specified by the StorageId (must be BuiltInUser or SdCard). The two output s64s are the output from [[Filesystem_services#GetTotalSpaceSize|GetTotalSpaceSize]] and [[Filesystem_services#GetFreeSpaceSize|GetFreeSpaceSize]] with this ContentStorage, with it this being unmounted afterwards.&lt;br /&gt;
&lt;br /&gt;
==== RequestUpdateApplication2 ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
See [[#RequestApplicationUpdateInfo]] regarding nifm.&lt;br /&gt;
&lt;br /&gt;
==== LaunchApplication ====&lt;br /&gt;
Takes an input u8 ProgramIndex, an input [[#ApplicationLaunchInfo]], returns an output u64.&lt;br /&gt;
&lt;br /&gt;
[18.0.0+] Now takes a total of 0x58 bytes of input.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] Now takes a total of 0x88 bytes of input.&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationLaunchInfo ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output [[#ApplicationLaunchInfo]].&lt;br /&gt;
&lt;br /&gt;
[18.0.0+] Now returns a total of 0x50 bytes of output.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] Now returns a total of 0x80 bytes of output.&lt;br /&gt;
&lt;br /&gt;
==== AcquireApplicationLaunchInfo ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output [[#ApplicationLaunchInfo]].&lt;br /&gt;
&lt;br /&gt;
This verifies that a state flag is set and that a state field matches the input ApplicationId, throwing an error otherwise. The [[#ApplicationLaunchInfo]] from state is copied to output, then the state flag is cleared.&lt;br /&gt;
&lt;br /&gt;
[18.0.0+] Now returns a total of 0x50 bytes of output.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] Now returns a total of 0x80 bytes of output.&lt;br /&gt;
&lt;br /&gt;
==== GetMainApplicationProgramIndexByApplicationLaunchInfo ====&lt;br /&gt;
[18.0.0+] Now takes a total of 0x50 bytes of input.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] Now returns a total of 0x80 bytes of output.&lt;br /&gt;
&lt;br /&gt;
==== LaunchDevMenu ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
This is used by AM cmd [[Applet_Manager_services#LaunchDevMenu|LaunchDevMenu]].&lt;br /&gt;
&lt;br /&gt;
This loads ProgramIds from [[System_Settings|system-settings]] &amp;lt;code&amp;gt;ns.applet!devmenu_id&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;ns.applet!devoverlaydisp_id&amp;lt;/code&amp;gt;, which only exists on devunits. An error is thrown if loading these fail.&lt;br /&gt;
&lt;br /&gt;
[[NCM_services#ncm|OpenContentMetaDatabase]] is used with StorageId = NandSystem, then IContentMetaDatabase GetLatestContentMetaKey is used with both of the above ProgramIds to verify that the cmd is successful.&lt;br /&gt;
&lt;br /&gt;
Then if the above succeeds, the above titles are launched with the above StorageId via [[Process_Manager_services|pmshell]] LaunchProgram ([10.0.0+] [[PGL_services#LaunchProgram|pgl]] with pgl_launch_flags=0), with a 0.5s sleep-thread afterwards on success. [[Process_Manager_services#LaunchFlags|LaunchFlags]] value 0xB is used here.&lt;br /&gt;
&lt;br /&gt;
==== DeleteUserSaveDataAll ====&lt;br /&gt;
Takes an input [[Account_services#Uid|Uid]], returns an output [[#IProgressMonitorForDeleteUserSaveDataAll]].&lt;br /&gt;
&lt;br /&gt;
On success, [[#IProgressMonitorForDeleteUserSaveDataAll]] GetProgress is used with the output being copied into object state.&lt;br /&gt;
&lt;br /&gt;
==== DeleteUserSystemSaveData ====&lt;br /&gt;
Takes an input [[Account_services#Uid|Uid]], an u64 SystemSaveDataId, no output.&lt;br /&gt;
&lt;br /&gt;
==== DeleteSaveData ====&lt;br /&gt;
Takes an input u8 [[Filesystem_services#SaveDataSpaceId|SaveDataSpaceId]], an u64 SaveDataId, no output.&lt;br /&gt;
&lt;br /&gt;
==== UnregisterNetworkServiceAccount ====&lt;br /&gt;
Takes an input [[Account_services#Uid|Uid]], no output.&lt;br /&gt;
&lt;br /&gt;
==== UnregisterNetworkServiceAccountWithUserSaveDataDeletion ====&lt;br /&gt;
Takes an input [[Account_services#Uid|Uid]], no output.&lt;br /&gt;
&lt;br /&gt;
==== LaunchLibraryApplet ====&lt;br /&gt;
Takes an input u64 [[NCM_services#ProgramId|ProgramId]], returns an output u64.&lt;br /&gt;
&lt;br /&gt;
The specified program is launched with StorageId=BuiltInSystem via [[Process_Manager_services|pmshell]] LaunchProgram ([10.0.0+] [[PGL_services#LaunchProgram|pgl]] with pgl_launch_flags=0). [[Process_Manager_services#LaunchFlags|LaunchFlags]] value 0x9 is used here. The output u64 from here is written to the output for this cmd, on success.&lt;br /&gt;
&lt;br /&gt;
This is used by [[Applet_Manager_services|AM]].&lt;br /&gt;
&lt;br /&gt;
==== LaunchSystemApplet ====&lt;br /&gt;
No input, returns an output u64.&lt;br /&gt;
&lt;br /&gt;
A state flag must be non-zero, otherwise an error is thrown. When a state field is value 1, a hard-coded ProgramId for MaintenanceMenu is used. Otherwise, the ProgramId is loaded from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;ns.applet!system_applet_id&amp;lt;/code&amp;gt; ([20.0.0+] &amp;lt;code&amp;gt;ns.applet!system_applet_id_gen2&amp;lt;/code&amp;gt;).&lt;br /&gt;
&lt;br /&gt;
The SystemApplet is launched with StorageId=BuiltInSystem via [[Process_Manager_services|pmshell]] LaunchProgram ([10.0.0+] [[PGL_services#LaunchProgram|pgl]] with pgl_launch_flags=0). [[Process_Manager_services#LaunchFlags|LaunchFlags]] value 0x9 is used here. The output u64 from here is written to the output for this cmd, on success.&lt;br /&gt;
&lt;br /&gt;
This is used by [[Applet_Manager_services|AM]].&lt;br /&gt;
&lt;br /&gt;
==== LaunchOverlayApplet ====&lt;br /&gt;
No input, returns an output u64.&lt;br /&gt;
&lt;br /&gt;
A state flag must be non-zero, otherwise an error is thrown. The ProgramId is loaded from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;ns.applet!overlay_applet_id&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
The OverlayApplet is launched with StorageId=BuiltInSystem via [[Process_Manager_services|pmshell]] LaunchProgram ([10.0.0+] [[PGL_services#LaunchProgram|pgl]] with pgl_launch_flags=0). [[Process_Manager_services#LaunchFlags|LaunchFlags]] value 0x9 is used here. The output u64 from here is written to the output for this cmd, on success.&lt;br /&gt;
&lt;br /&gt;
This is used by [[Applet_Manager_services|AM]].&lt;br /&gt;
&lt;br /&gt;
==== RequestDownloadApplicationControlData ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
See [[#RequestApplicationUpdateInfo]] regarding nifm.&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationControlProperty ====&lt;br /&gt;
[18.0.0+] Now takes a total of 0x58 bytes of input.&lt;br /&gt;
&lt;br /&gt;
==== ListApplicationTitle ====&lt;br /&gt;
Takes an input TransferMemory handle, a type-0x5 input buffer containing an array of u64 [[NCM_services#ApplicationId|ApplicationIds]], an u8 [[#ApplicationControlSource]], an u64 size, returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
[[qlaunch]] uses value 0x1 for the u8.&lt;br /&gt;
&lt;br /&gt;
The user-process creates the TransferMemory with permissions=R--.&lt;br /&gt;
&lt;br /&gt;
The data available with [[#IAsyncValue]] Get is a s32 for the offset within the TransferMemory where the output data is located, GetSize returns the total byte-size of the data located here. The data located here is the [[NACP_Format|NACP]] title-entry for each specified ApplicationId.&lt;br /&gt;
&lt;br /&gt;
The TransferMemory size must be at least: count*sizeof([[NACP_Format|title-entry]]) + count*sizeof(u64) + count*[[#GetApplicationControlData|0x24000]].&lt;br /&gt;
&lt;br /&gt;
This is essentially an async wrapper for [[#GetApplicationControlData]], with support for multiple ApplicationIds.&lt;br /&gt;
&lt;br /&gt;
==== ListApplicationIcon ====&lt;br /&gt;
Takes an input TransferMemory handle, a type-0x5 input buffer containing an array of u64 [[NCM_services#ApplicationId|ApplicationIds]], an u8 [[#ApplicationControlSource]], an u64 size, returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
The user-process creates the TransferMemory with permissions=R--.&lt;br /&gt;
&lt;br /&gt;
The data available with [[#IAsyncValue]] Get is a s32 for the offset within the TransferMemory where the output data is located, GetSize returns the total byte-size of the data located here. This data is: an u64 for total entries, an array of u64s for each icon size, then the icon JPEGs for the specified ApplicationIds.&lt;br /&gt;
&lt;br /&gt;
The TransferMemory size must be at least: 0x4 + count*sizeof(u64) + count*[[#GetApplicationControlData|0x20000]] + count*sizeof(u64) + [[#GetApplicationControlData|0x24000]].&lt;br /&gt;
&lt;br /&gt;
This is essentially an async wrapper for [[#GetApplicationControlData]], with support for multiple ApplicationIds.&lt;br /&gt;
&lt;br /&gt;
==== Cmd421 ====&lt;br /&gt;
Takes an input TransferMemory handle, a type-0x5 input buffer containing an array of u64 [[NCM_services#ApplicationId|ApplicationIds]], an u8 [[#ApplicationControlSource]], an u64 size, returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
This is essentially the same as [[#ListApplicationTitle|ListApplicationTitle]] except the ApplicationControlSource is used here (ListApplicationTitle ignores it and uses 0xF0 instead).&lt;br /&gt;
&lt;br /&gt;
The TransferMemory size must be at least: count*sizeof(u64) + count*[[NACP#ApplicationTitle|0x300]] + [[#GetApplicationControlData|0x1d000]].&lt;br /&gt;
&lt;br /&gt;
The async task impl code eventually compares ApplicationControlSource with 0xF0, with a separate code-path being used when it doesn&#039;t match (which also handles [[NACP|compression]] when needed).&lt;br /&gt;
&lt;br /&gt;
==== RequestCheckGameCardRegistration ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
See [[#RequestApplicationUpdateInfo]] regarding nifm.&lt;br /&gt;
&lt;br /&gt;
==== RequestGameCardRegistrationGoldPoint ====&lt;br /&gt;
Takes an input [[Account_services#Uid|Uid]], an [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
The data that can be read from the [[#IAsyncValue]] is 4-bytes.&lt;br /&gt;
&lt;br /&gt;
See [[#RequestApplicationUpdateInfo]] regarding nifm.&lt;br /&gt;
&lt;br /&gt;
==== RequestRegisterGameCard ====&lt;br /&gt;
Takes an input s32, an [[Account_services#Uid|Uid]], an [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
See [[#RequestApplicationUpdateInfo]] regarding nifm.&lt;br /&gt;
&lt;br /&gt;
==== GetGameCardMountFailureEvent ====&lt;br /&gt;
No input, returns an output Event handle with EventClearMode=0.&lt;br /&gt;
&lt;br /&gt;
==== IsGameCardInserted ====&lt;br /&gt;
No input, returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
==== EnsureGameCardAccess ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== GetLastGameCardMountFailureResult ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== ListApplicationIdOnGameCard ====&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of u64 [[NCM_services#ApplicationId|ApplicationIds]], returns an output s32 for total output entries.&lt;br /&gt;
&lt;br /&gt;
==== GetGameCardPlatformRegion ====&lt;br /&gt;
No input, returns an u8 &#039;&#039;&#039;GameCardPlatformRegion&#039;&#039;&#039; (0x00 = Global, 0x01 = China).&lt;br /&gt;
&lt;br /&gt;
This calls [[Filesystem_services#IDeviceOperator|fsp-srv IDeviceOperator]] GetGameCardCompatibilityType and returns the result.&lt;br /&gt;
&lt;br /&gt;
==== ListAvailableAddOnContent ====&lt;br /&gt;
[10.0.0+] This now takes a total of 0x10-bytes of input instead of a total of 0x18-bytes of input.&lt;br /&gt;
&lt;br /&gt;
[15.0.0+] This now takes a total of 0x8-bytes of input instead of a total of 0x10-bytes of input.&lt;br /&gt;
&lt;br /&gt;
==== RequestDownloadTaskListData ====&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
==== TouchApplication ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== IsApplicationUpdateRequested ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output u8 bool and an u32.&lt;br /&gt;
&lt;br /&gt;
The output u32 is only valid when the output bool is set.&lt;br /&gt;
&lt;br /&gt;
==== WithdrawApplicationUpdateRequest ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== RequestVerifyApplicationDeprecated ====&lt;br /&gt;
Takes an input TransferMemory handle, an [[NCM_services#ApplicationId|ApplicationId]], an u64 size, returns an output Event handle and an [[#IProgressAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
On newer system-versions this calls the same func as [[#RequestVerifyApplication]], with the u32 value set to 0x7.&lt;br /&gt;
&lt;br /&gt;
==== RequestVerifyAddOnContentsRights ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IProgressAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
==== RequestVerifyApplication ====&lt;br /&gt;
Takes an input TransferMemory handle, an u32, an [[NCM_services#ApplicationId|ApplicationId]], an u64 size, returns an output Event handle and an [[#IProgressAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
Official sw creates the TransferMemory with an user-specified buffer with permissions=0. [[qlaunch]] uses buffer size 0x100000.&lt;br /&gt;
&lt;br /&gt;
Official sw has an additional wrapper func which calls the original wrapper func, this uses value 0x7 for the u32. This is the same func used by [[qlaunch]].&lt;br /&gt;
&lt;br /&gt;
==== IsAnyApplicationEntityInstalled ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
==== CleanupUnavailableAddOnContents ====&lt;br /&gt;
Takes an input u64 [[NCM_services#ApplicationId|ApplicationId]], an [[Account_services#Uid|Uid]], no output.&lt;br /&gt;
&lt;br /&gt;
==== RequestMoveApplicationEntity ====&lt;br /&gt;
Takes an input TransferMemory handle, a type-0x5 input buffer containing an array of [[NCM_services#StorageId|StorageId]], a [[NCM_services#StorageId|StorageId]], an u32 bitfield of &amp;quot;nn::ns::KeepApplicationEntityFlagTag&amp;quot;, an [[NCM_services#ApplicationId|ApplicationId]], an u64 tmem_size, returns an output Event handle and an [[#IProgressAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
The TransferMemory uses permissions=0.&lt;br /&gt;
&lt;br /&gt;
==== EstimateSizeToMove ====&lt;br /&gt;
Takes a type-0x5 input buffer containing an array of [[NCM_services#StorageId|StorageId]], a [[NCM_services#StorageId|StorageId]], an u32 bitfield of &amp;quot;nn::ns::KeepApplicationEntityFlagTag&amp;quot;, an [[NCM_services#ApplicationId|ApplicationId]], returns an output s64.&lt;br /&gt;
&lt;br /&gt;
This calls a func also used by [[#RequestMoveApplicationEntity]], then calls another func.&lt;br /&gt;
&lt;br /&gt;
==== FormatSdCard ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== NeedsSystemUpdateToFormatSdCard ====&lt;br /&gt;
No input, returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
==== GetLastSdCardFormatUnexpectedResult ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationView ====&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of [[#ApplicationView]], a type-0x5 input buffer containing an array of u64 [[NCM_services#ApplicationId|ApplicationIds]], no output.&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationViewDownloadErrorContext ====&lt;br /&gt;
Takes a type-0x16 output buffer containg an [[Error_Applet#ErrorContext|ErrorContext]], an u64 [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationViewWithPromotionInfo ====&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of [[#ApplicationViewWithPromotionInfo]], a type-0x5 input buffer containing an array of u64 [[NCM_services#ApplicationId|ApplicationIds]], no output.&lt;br /&gt;
&lt;br /&gt;
==== IsPatchAutoDeletableApplication ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output bool.&lt;br /&gt;
&lt;br /&gt;
Compares the input ApplicationId with the value of [[System_Settings|system-setting]] &amp;lt;code&amp;gt;ns.application!auto_deletable_application_id_on_not_enough_space&amp;lt;/code&amp;gt;, with the bool being set to the comparsion result.&lt;br /&gt;
&lt;br /&gt;
==== ListLastNotificationInfo ====&lt;br /&gt;
Takes a type-0x6 buffer containing an array with struct entry size 0x90-bytes. Returns 4-bytes of output.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] The struct size is now 0x98-bytes.&lt;br /&gt;
&lt;br /&gt;
==== ListNotificationTask ====&lt;br /&gt;
Takes a type-0x6 buffer containing an array with struct entry size 0xB0-bytes. Returns 4-bytes of output.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] The struct size is now 0xB8-bytes.&lt;br /&gt;
&lt;br /&gt;
==== RequestDownloadApplicationPrepurchasedRights ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
See [[#RequestApplicationUpdateInfo]] regarding nifm.&lt;br /&gt;
&lt;br /&gt;
==== GetSystemDeliveryInfo ====&lt;br /&gt;
Takes a type-0x16 output buffer containing a [[#SystemDeliveryInfo]], no output.&lt;br /&gt;
&lt;br /&gt;
This generates a [[#SystemDeliveryInfo]] using the currently installed SystemUpdate meta title.&lt;br /&gt;
&lt;br /&gt;
==== SelectLatestSystemDeliveryInfo ====&lt;br /&gt;
Takes a type-0x15 input buffer containing a [[#SystemDeliveryInfo]], a type-0x5 input buffer containing an array of [[#SystemDeliveryInfo]], a type-0x5 input buffer containing an array of [[#ApplicationDeliveryInfo]], and returns an output s32.&lt;br /&gt;
&lt;br /&gt;
This determines the latest version (RequiredSystemVersion) from the input [[#ApplicationDeliveryInfo]] array (ApplicationDeliveryProtocolVersion and the HMAC are also validated), using value 0 if the array is empty.&lt;br /&gt;
&lt;br /&gt;
* [20.0.0+] The following code block now only runs when the SystemDeliveryInfoPlatform from the type-0x15 [[#SystemDeliveryInfo]] buffer matches the [[System_Settings|sys-setting]].&lt;br /&gt;
** It then loops through the [[#ApplicationDeliveryInfo]] array again:&lt;br /&gt;
** This uses functionality which essentially uses [[Shared_Database_services|pl:s]] GetFunctionBlackListSystemVersionToAuthorize with the [[#ApplicationDeliveryInfo]] ApplicationId and ApplicationFunctionAuthorizationId=0x5 then parses the output, using cached data if available. The error is returned on failure.&lt;br /&gt;
** tmp_version = out_u8 == 0 ? 0 : out_u32 + 0x10000;&lt;br /&gt;
** Then the current latest-version value is updated with tmp_version, if tmp_version is higher.&lt;br /&gt;
&lt;br /&gt;
If this version value is less than a state field, the state field value is used instead (state field originates from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;contents_delivery!required_system_version_to_deliver_application&amp;lt;/code&amp;gt;).&lt;br /&gt;
&lt;br /&gt;
Then this selects the [[#SystemDeliveryInfo]] with the latest version from the input array. The output s32 is an index in that array for the selected entry, -1 if none found.&lt;br /&gt;
&lt;br /&gt;
During the above loop it first calls the [[#SystemDeliveryInfo]] validation func, returning the Result on failure. Then it runs additional validation, with the [[#SystemDeliveryInfo]] entry being ignored on failure:&lt;br /&gt;
* The above latest-version value must be at least the version value from the type-0x15 [[#SystemDeliveryInfo]] buffer and the [[#SystemDeliveryInfo]] array entry.&lt;br /&gt;
* When HasExFat is set in the type-0x15 [[#SystemDeliveryInfo]] buffer, it must be set in the [[#SystemDeliveryInfo]] array entry.&lt;br /&gt;
* FirmwareVariationId in the type-0x15 [[#SystemDeliveryInfo]] buffer must not be 0xFF.&lt;br /&gt;
* UpdatableFirmwareGroupId in the [[#SystemDeliveryInfo]] array entry must not be 0xFF. The value must be within bounds of the settings array ([[System_Settings|sys-settings]] &amp;lt;code&amp;gt;contents_delivery!updatable_firmware_group_string&amp;lt;/code&amp;gt;).&lt;br /&gt;
* PlatformRegion in the [[#SystemDeliveryInfo]] array entry and the type-0x15 [[#SystemDeliveryInfo]] buffer must match.&lt;br /&gt;
* Lastly when the following is true, this indicates success: (settings_array[UpdatableFirmwareGroupId] &amp;gt;&amp;gt; {above FirmwareVariationId}) &amp;amp; 1.&lt;br /&gt;
&lt;br /&gt;
==== VerifyDeliveryProtocolVersion ====&lt;br /&gt;
Takes a type-0x15 input buffer containing a [[#SystemDeliveryInfo]], no output.&lt;br /&gt;
&lt;br /&gt;
This validates the [[#SystemDeliveryInfo]] HMAC and the protocol-version fields. Then an error is returned when SystemUpdateVersion is less than a state field, otherwise 0 is returned (state field originates from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;contents_delivery!required_system_version_to_deliver_application&amp;lt;/code&amp;gt;).&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationDeliveryInfo ====&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of [[#ApplicationDeliveryInfo|ApplicationDeliveryInfo]], an input u32 bitmask &amp;lt;code&amp;gt;nn::ns::ApplicationDeliveryAttributeTag&amp;lt;/code&amp;gt;, an [[NCM_services#ApplicationId|ApplicationId]], and returns an output s32 total_out.&lt;br /&gt;
&lt;br /&gt;
[11.0.0+] An error is thrown if LocalContentShare is not [[#IsLocalContentShareEnabled|enabled]].&lt;br /&gt;
&lt;br /&gt;
An error is thrown if any bit is set in ApplicationDeliveryAttributeTag besides bit1, this must also be &amp;lt;=0x3. The output array-count must be at least 1: only 1 entry will be written to this array (hence on success total_out will also only be 1 on success).&lt;br /&gt;
&lt;br /&gt;
[7.0.0+] An error is thrown if the state ref-count for [[#GetRequestServerStopper|RequestServerStopper]] is zero. [7.0.0-7.0.1] The func which checks this would also return success when a field prior to the previously mentioned field is 0 (checked before the ref-count).&lt;br /&gt;
&lt;br /&gt;
An error is thrown if [[NIM_services|nim]] ListApplicationApplyDeltaTask returns a task.&lt;br /&gt;
&lt;br /&gt;
HasApplicationRecord is called with the input [[NCM_services#ApplicationId|ApplicationId]], an error is returned if the record isn&#039;t found.&lt;br /&gt;
&lt;br /&gt;
[[#ApplicationDeliveryInfo|RequiredApplicationVersion]] is initially set to the output version from [[Shared_Database_services|avm]] GetLaunchRequiredVersion. Later when ContentMetaType == Application etc, it calls a func. This func uses [[NCM_services|ncm]] IContentMetaDatabase GetRequiredApplicationVersion. If the output version is higher than the [[#ApplicationDeliveryInfo|RequiredApplicationVersion]] field then the output version is written here. Immediately aferwards, it also checks whether the bit for Compacted is set from [[NCM_services|ncm]] IContentMetaDatabase GetAttributes, clearing [[#ApplicationDeliveryInfo|ApplicationVersion]] if the attribute is set.&lt;br /&gt;
&lt;br /&gt;
[20.0.0+] [[#ApplicationDeliveryInfo|ApplicationDeliveryInfo]] ContentMetaPlatform and ProperProgramExists are now set using data from [[NCM_services|ncm]].&lt;br /&gt;
&lt;br /&gt;
[20.0.0+] [[Shared_Database_services|pl:s]] GetFunctionBlackListSystemVersionToAuthorize with ApplicationFunctionAuthorizationId=0x5 is now used, the output version is written to [[#ApplicationDeliveryInfo|RequiredSystemVersion]] when it&#039;s higher than the value previously written here.&lt;br /&gt;
&lt;br /&gt;
[20.0.0+] [[Shared_Database_services|pl:s]] GetRequiredApplicationVersion with ApplicationFunctionAuthorizationId=0x5 is now used, the output version is written to [[#ApplicationDeliveryInfo|RequiredApplicationVersion]] when it&#039;s higher than the value previously written here.&lt;br /&gt;
&lt;br /&gt;
==== HasAllContentsToDeliver ====&lt;br /&gt;
Takes a type-0x5 input buffer containing an array of [[#ApplicationDeliveryInfo]], returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
The array-count must match 1.&lt;br /&gt;
&lt;br /&gt;
This uses the same LocalContentShare check as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
After validating the [[#ApplicationDeliveryInfo]], the output bool is set to [[#ApplicationDeliveryInfo|ApplicationDeliveryAttributeTag]] &amp;amp; 0x10000002 != 0x2, then this returns 0.&lt;br /&gt;
&lt;br /&gt;
==== CompareApplicationDeliveryInfo ====&lt;br /&gt;
Takes two type-0x5 input buffers containing an array of [[#ApplicationDeliveryInfo]], returns an output s32.&lt;br /&gt;
&lt;br /&gt;
This uses the same LocalContentShare check as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
The array-count for both buffers must be 1, otherwise an error is returned.&lt;br /&gt;
&lt;br /&gt;
Both [[#ApplicationDeliveryInfo]] are validated, then the application-version in the first/second buffer are compared. The output s32 is set to the comparison result: -1 for less than, 0 for equal, and 1 for higher than.&lt;br /&gt;
&lt;br /&gt;
==== CanDeliverApplication ====&lt;br /&gt;
Takes two type-0x5 input buffers containing an array of [[#ApplicationDeliveryInfo]], returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
The array-count for the second buffer must be 1, otherwise an error is returned.&lt;br /&gt;
&lt;br /&gt;
This uses the same LocalContentShare check as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
The second [[#ApplicationDeliveryInfo]] buffer is validated. An error is thrown when [[#ApplicationDeliveryInfo|ApplicationDeliveryAttributeTag]] (second buffer) &amp;amp; 0x3 != 0x2, likewise when bit28 is clear in this field (bitmask 0x10000000).&lt;br /&gt;
&lt;br /&gt;
The array-count for the first buffer must be &amp;lt;=1, otherwise an error is returned. If the array-count for the first buffer is 0, this will return 0 with the output bool set to 0. The first [[#ApplicationDeliveryInfo]] buffer is validated. An error is thrown when [[#ApplicationDeliveryInfo|ApplicationDeliveryAttributeTag]] (first buffer) bit1 is clear or bit0 set. An error is thrown when [[#ApplicationDeliveryInfo|ApplicationDeliveryAttributeTag]] (second buffer) bit1 is clear.&lt;br /&gt;
&lt;br /&gt;
When [[#ApplicationDeliveryInfo|RequiredApplicationVersion]] (first or second buffer) is higher than [[#ApplicationDeliveryInfo|ApplicationVersion]] (second buffer), this will return 0 with the output bool set to 0.&lt;br /&gt;
&lt;br /&gt;
When [[#ApplicationDeliveryInfo|ApplicationDeliveryAttributeTag]] (first buffer) bit28 is set (bitmask 0x10000000):&lt;br /&gt;
* When [[#ApplicationDeliveryInfo|ApplicationVersion]] (first buffer) &amp;gt;= [[#ApplicationDeliveryInfo|ApplicationVersion]] (second buffer), write 0 to the output bool, otherwise write 1. Then return 0.&lt;br /&gt;
Otherwise when the above bit28 is clear:&lt;br /&gt;
* When [[#ApplicationDeliveryInfo|ApplicationVersion]] (first buffer) &amp;gt; [[#ApplicationDeliveryInfo|ApplicationVersion]] (second buffer), write 0 to the output bool, otherwise write 1. Then return 0.&lt;br /&gt;
&lt;br /&gt;
==== ListContentMetaKeyToDeliverApplication ====&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of [[NCM_services#ContentMetaKey|ContentMetaKey]], a type-0x5 input buffer containing an array of [[#ApplicationDeliveryInfo]], a s32, and returns an output s32 total_out.&lt;br /&gt;
&lt;br /&gt;
This uses the same LocalContentShare check as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
The array-count for ContentMetaKey must be at least 1, and for ApplicationDeliveryInfo it must match 1.&lt;br /&gt;
&lt;br /&gt;
The [[#ApplicationDeliveryInfo|ApplicationDeliveryInfo]] is validated (ApplicationDeliveryProtocolVersion/HMAC). An error is thrown when [[#ApplicationDeliveryInfo|ApplicationDeliveryAttributeTag]] bit0 is set.&lt;br /&gt;
&lt;br /&gt;
This uses the same ref-count check as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
An error is thrown if [[NIM_services|nim]] ListApplicationApplyDeltaTask returns a task.&lt;br /&gt;
&lt;br /&gt;
This will only return 1 ContentMetaKey entry. This will not output the entry when the input s32 is larger than 0, or when [[#ApplicationDeliveryInfo|ApplicationDeliveryAttributeTag]] bit1 is clear.&lt;br /&gt;
&lt;br /&gt;
==== NeedsSystemUpdateToDeliverApplication ====&lt;br /&gt;
Takes a type-0x15 input buffer containing a [[#SystemDeliveryInfo]], a type-0x5 input buffer containing an array of [[#ApplicationDeliveryInfo]], and returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
This uses the same LocalContentShare check as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
The [[#SystemDeliveryInfo]] is validated (validation for ApplicationDeliveryProtocolVersion is enabled).&lt;br /&gt;
&lt;br /&gt;
The array-count must match 1.&lt;br /&gt;
&lt;br /&gt;
The [[#ApplicationDeliveryInfo]] is validated (ApplicationDeliveryProtocolVersion/HMAC).&lt;br /&gt;
&lt;br /&gt;
This then runs functionality similar to [[#SelectLatestSystemDeliveryInfo]]:&lt;br /&gt;
* [20.0.0+] The following code block now only runs when the SystemDeliveryInfoPlatform from the input [[#SystemDeliveryInfo]] matches the [[System_Settings|sys-setting]].&lt;br /&gt;
* Uses the same functionality as [[#SelectLatestSystemDeliveryInfo]] for GetFunctionBlackListSystemVersionToAuthorize, returning the Result on failure.&lt;br /&gt;
* The output bool is set to: out_u8!=0 &amp;amp;&amp;amp; out_u32 &amp;gt;= [[#SystemDeliveryInfo]] SystemUpdateVersion (only the upper 16bits are used from the SystemUpdateVersion).&lt;br /&gt;
&lt;br /&gt;
Otherwise when the output bool is still false, this sets the output bool by comparing system-version fields in the [[#SystemDeliveryInfo]]/[[#ApplicationDeliveryInfo]] and with a state field (state field originates from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;contents_delivery!required_system_version_to_deliver_application&amp;lt;/code&amp;gt;).&lt;br /&gt;
&lt;br /&gt;
==== EstimateRequiredSize ====&lt;br /&gt;
Takes a type-0x5 input buffer containing an array of [[NCM_services#ContentMetaKey|ContentMetaKey]], returns an output s64.&lt;br /&gt;
&lt;br /&gt;
When the array-count is less than 1, this will return 0 with the s64 set to 0.&lt;br /&gt;
&lt;br /&gt;
==== RequestReceiveApplication ====&lt;br /&gt;
Takes a type-0x5 input buffer containing an array of [[NCM_services#ContentMetaKey|ContentMetaKey]], a [[NCM_services#StorageId|StorageId]], an u16 port, an u32 Ipv4Address, an [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
[[qlaunch]] uses value Any for the StorageId, and value 55556 for the port.&lt;br /&gt;
&lt;br /&gt;
This uses the same LocalContentShare and ref-count checks as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
An error is thrown if [[NIM_services|nim]] ListApplicationApplyDeltaTask returns a task.&lt;br /&gt;
&lt;br /&gt;
HasApplicationRecord is called with the input [[NCM_services#ApplicationId|ApplicationId]], an error is returned if the record isn&#039;t found.&lt;br /&gt;
&lt;br /&gt;
This loops through the input [[NCM_services#ContentMetaKey|ContentMetaKey]] array, throwing an error if the [[NCM_services#ContentMetaType|ContentMetaType]] doesn&#039;t match Patch. The input array is copied into state which is used later by the thread for [[NIM_services|nim]] CreateLocalCommunicationReceiveApplicationTask, max entries is 0x12.&lt;br /&gt;
&lt;br /&gt;
This does various setup then creates the [[#IAsyncResult]] + the async thread which handles the [[#IAsyncResult]] operation. Then the thread does:&lt;br /&gt;
&lt;br /&gt;
* Calls a func which does:&lt;br /&gt;
** Throws an error if a state flag is set.&lt;br /&gt;
** Uses [[NIM_services|nim]] CreateLocalCommunicationReceiveApplicationTask, returning the Result on failure.&lt;br /&gt;
** Uses [[NIM_services|nim]] RequestLocalCommunicationReceiveApplicationTaskRun, returning the Result on failure. Waits for the IAsyncResult operation from this to finish, then uses the Get cmd to get the output Result.&lt;br /&gt;
*** When the Result from Get is an error, a func is called for filling in the [[#IAsyncResult|IAsyncResult]] ErrorContext with Type4.&lt;br /&gt;
** Handles cleanup and returns.&lt;br /&gt;
* On success, this loads various data which is then used for saving a SystemPlayReport when the cached [[System_Settings|system-setting]] &amp;quot;systemreport!enabled&amp;quot; is set.&lt;br /&gt;
** The EventId is &amp;quot;receive_app_contents&amp;quot; with ApplicationId &amp;lt;NS ProgramId&amp;gt;.&lt;br /&gt;
** This report has the following fields:&lt;br /&gt;
*** &amp;quot;ApplicationId&amp;quot;&lt;br /&gt;
*** &amp;quot;DestinationVersion&amp;quot;&lt;br /&gt;
*** &amp;quot;SourceVersion&amp;quot;&lt;br /&gt;
*** &amp;quot;HasApplicationEntity&amp;quot;&lt;br /&gt;
*** &amp;quot;HasPatchEntity&amp;quot;&lt;br /&gt;
*** &amp;quot;ApplicationStorageId&amp;quot;&lt;br /&gt;
*** &amp;quot;PatchStorageId&amp;quot;&lt;br /&gt;
*** &amp;quot;Size&amp;quot;&lt;br /&gt;
*** &amp;quot;ThroughputKBps&amp;quot;&lt;br /&gt;
&lt;br /&gt;
==== CommitReceiveApplication ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
This uses the same LocalContentShare and ref-count checks as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
An error is thrown if [[NIM_services|nim]] ListApplicationApplyDeltaTask returns a task.&lt;br /&gt;
&lt;br /&gt;
==== GetReceiveApplicationProgress ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output [[#ReceiveApplicationProgress]].&lt;br /&gt;
&lt;br /&gt;
This uses the same ref-count check as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
An error is thrown if [[NIM_services|nim]] ListApplicationApplyDeltaTask returns a task.&lt;br /&gt;
&lt;br /&gt;
Uses [[NIM_services|nim]] ListApplicationLocalCommunicationReceiveApplicationTask, throwing an error if no task is returned. Then [[NIM_services|nim]] GetLocalCommunicationReceiveApplicationTaskInfo is used, returning the error from there on failure. Lastly, this writes the 0x10-bytes from output+8 from the latter cmd to the output [[#ReceiveApplicationProgress]], and returns 0.&lt;br /&gt;
&lt;br /&gt;
==== RequestSendApplication ====&lt;br /&gt;
Takes a type-0x5 input buffer containing an array of [[NCM_services#ContentMetaKey|ContentMetaKey]], an u16 port, an u32 Ipv4Address, an [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
[[qlaunch]] uses value 55556 for the port.&lt;br /&gt;
&lt;br /&gt;
This uses the same LocalContentShare and ref-count checks as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
An error is thrown if [[NIM_services|nim]] ListApplicationApplyDeltaTask returns a task.&lt;br /&gt;
&lt;br /&gt;
This does various setup and loops through the input ContentMetaKey array for initializing the array passed to the nim cmd during the async task. This loop does the following:&lt;br /&gt;
* Throws an error if the [[NCM_services#ContentMetaType|ContentMetaType]] in the ContentMetaKey doesn&#039;t match Patch.&lt;br /&gt;
* Calls a func with the ContentMetaKey and the ApplicationId, throwing an error if the output value is 0.&lt;br /&gt;
* Calls a func with the ContentMetaKey for getting the StorageId. This essentially loops through each valid ncm [[NCM_services|IContentMetaDatabase]] using cmd [[NCM_services|Has]] with the input ContentMetaKey, returning the relevant StorageId when found.&lt;br /&gt;
* The ContentMetaKey and the StorageId are copied into a tmp struct.&lt;br /&gt;
* if (ContentMetaType==Patch &amp;amp;&amp;amp; StorageId==GameCard) { &amp;lt;call a func etc&amp;gt; }&lt;br /&gt;
* Copies the above tmp struct into the async task state array.&lt;br /&gt;
&lt;br /&gt;
This then creates the [[#IAsyncResult]] + the async thread which handles the [[#IAsyncResult]] operation. Then the thread does:&lt;br /&gt;
&lt;br /&gt;
* Calls a func which does:&lt;br /&gt;
** Throws an error if a state flag is set.&lt;br /&gt;
** Uses [[NIM_services|nim]] CreateLocalCommunicationSendApplicationTask, returning the Result on failure.&lt;br /&gt;
** Uses [[NIM_services|nim]] RequestLocalCommunicationSendApplicationTaskRun, returning the Result on failure. Waits for the IAsyncResult operation from this to finish, then uses the Get cmd to get the output Result.&lt;br /&gt;
*** When the Result from Get is an error, a func is called for filling in the [[#IAsyncResult|IAsyncResult]] ErrorContext with Type4.&lt;br /&gt;
** Handles cleanup and returns.&lt;br /&gt;
* On success, this loads various data which is then used for saving a SystemPlayReport when the cached [[System_Settings|system-setting]] &amp;quot;systemreport!enabled&amp;quot; is set.&lt;br /&gt;
** The EventId is &amp;quot;send_app_contents&amp;quot; with ApplicationId &amp;lt;NS ProgramId&amp;gt;.&lt;br /&gt;
** This report has the following fields:&lt;br /&gt;
*** &amp;quot;ApplicationId&amp;quot;&lt;br /&gt;
*** &amp;quot;Version&amp;quot;&lt;br /&gt;
*** &amp;quot;ApplicationStorageId&amp;quot;&lt;br /&gt;
*** &amp;quot;PatchStorageId&amp;quot;&lt;br /&gt;
&lt;br /&gt;
==== GetSendApplicationProgress ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output [[#SendApplicationProgress]].&lt;br /&gt;
&lt;br /&gt;
Same as [[#GetReceiveApplicationProgress]] except this is the Send version, and uses [[NIM_services|nim]] ListApplicationLocalCommunicationSendApplicationTask/GetLocalCommunicationSendApplicationTaskInfo instead. The data copied to output is also swapped: u64 nim_out+0x8 is copied to out+0x8, and u64 nim_out+0x10 is copied to out+0x0.&lt;br /&gt;
&lt;br /&gt;
==== CompareSystemDeliveryInfo ====&lt;br /&gt;
Takes two type-0x15 input buffers containing a [[#SystemDeliveryInfo]], returns an output s32.&lt;br /&gt;
&lt;br /&gt;
This is essentially the same as [[#CompareApplicationDeliveryInfo]], except this compares the [[#SystemDeliveryInfo]] SystemUpdate version.&lt;br /&gt;
&lt;br /&gt;
==== ListNotCommittedContentMeta ====&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of [[NCM_services#ContentMetaKey|ContentMetaKey]], a s32, an [[NCM_services#ApplicationId|ApplicationId]], returns an output s32 total_out.&lt;br /&gt;
&lt;br /&gt;
This uses the same ref-count check as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
An error is thrown if [[NIM_services|nim]] ListApplicationApplyDeltaTask returns a task.&lt;br /&gt;
&lt;br /&gt;
==== RecoverDownloadTask ====&lt;br /&gt;
Takes a type-0x5 input buffer containing an array of {unknown} and an input u64, no output.&lt;br /&gt;
&lt;br /&gt;
This uses the same LocalContentShare and ref-count checks as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationDeliveryInfoHash ====&lt;br /&gt;
Takes a type-0x5 input buffer containing an array of [[#ApplicationDeliveryInfo]], returns an output 0x20-byte SHA256 hash.&lt;br /&gt;
&lt;br /&gt;
This uses the same LocalContentShare check as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
This extracts data from the input array for hashing with SHA256, with validation being done when handling each entry (ApplicationDeliveryProtocolVersion/HMAC).&lt;br /&gt;
&lt;br /&gt;
The 0x14-bytes from [[#ApplicationDeliveryInfo|ApplicationDeliveryInfo]]+0x8 are copied into a 0x18-byte struct entry in an array buffer, with the last 4-bytes being cleared. Then each 0x18-byte struct entry is hashed.&lt;br /&gt;
&lt;br /&gt;
==== Cmd2019 ====&lt;br /&gt;
Takes a type-0x15 input buffer containing a [[#SystemDeliveryInfo]], a type-0x5 input buffer containing an array of [[#ApplicationDeliveryInfo]], a type-0x5 input buffer containing an array of [[#ApplicationDeliveryInfo]], returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
This is essentially an extended version of [[#CanDeliverApplication|CanDeliverApplication]], with additional functionality for determining platform compatibility.&lt;br /&gt;
&lt;br /&gt;
This calls a func for validating the [[#SystemDeliveryInfo]] from the type-0x15 buffer, returning the Result on failure.&lt;br /&gt;
&lt;br /&gt;
Then [[#CanDeliverApplication|CanDeliverApplication]] is called with the output bool and the input arrays, returning the Result on failure.&lt;br /&gt;
&lt;br /&gt;
If the output bool is set after calling the above, it then calls a func with the output bool, the second [[#ApplicationDeliveryInfo]] buffer, and the [[#SystemDeliveryInfo]] from the type-0x15 buffer. This func does the following:&lt;br /&gt;
* When the SystemDeliveryInfoPlatform from the input [[#SystemDeliveryInfo]] matches the [[System_Settings|sys-setting]], it does the following:&lt;br /&gt;
** Uses [[Shared_Database_services|pl:s]] RequestApplicationFunctionAuthorizationByApplicationId with the [[#ApplicationDeliveryInfo]] ApplicationId/ApplicationVersion and ApplicationFunctionAuthorizationId=0x5, handling the Result on failure.&lt;br /&gt;
* When the platform fields from the input [[#SystemDeliveryInfo]]/[[#ApplicationDeliveryInfo]] match, write 1 to the output bool and return 0. Otherwise:&lt;br /&gt;
** When the [[#SystemDeliveryInfo]] SystemDeliveryInfoPlatform is 0x1 (Ounce): *output = [[#ApplicationDeliveryInfo|ContentMetaPlatform]] == 0 &amp;amp;&amp;amp; [[#ApplicationDeliveryInfo|ProperProgramExists]] == 0;&lt;br /&gt;
** When the [[#SystemDeliveryInfo]] SystemDeliveryInfoPlatform is 0x0 (NX): write 0 to the output bool and return 0.&lt;br /&gt;
** Otherwise, Abort.&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationRightsOnClient ====&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of [[#ApplicationRightsOnClient]], an input u32 flags, an [[NCM_services#ApplicationId|ApplicationId]], an [[Account_services#Uid|Uid]], returns 4-bytes of output for total output entries.&lt;br /&gt;
&lt;br /&gt;
Official sw has at least two wrappers which use this cmd: one with an all-zero Uid, one with an user-specified Uid. With both of these, the passed flags are hard-coded to value 0x3.&lt;br /&gt;
&lt;br /&gt;
For the output array count, [[qlaunch]] uses value 3.&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationTerminateResult ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output u32 Result.&lt;br /&gt;
&lt;br /&gt;
==== GetRightsEnvironmentHandleForApplication ====&lt;br /&gt;
No input, returns a total of 8-bytes of output.&lt;br /&gt;
&lt;br /&gt;
[9.0.0+] Now takes a total of 8-bytes of input, returns a total of 8-bytes of output.&lt;br /&gt;
&lt;br /&gt;
==== RequestNoDownloadRightsErrorResolution ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
The data that can be read from the [[#IAsyncValue]] is [[#NoDownloadRightsErrorResolution]].&lt;br /&gt;
&lt;br /&gt;
See [[#RequestApplicationUpdateInfo]] regarding nifm.&lt;br /&gt;
&lt;br /&gt;
==== RequestResolveNoDownloadRightsError ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
The data that can be read from the [[#IAsyncValue]] is [[#NoDownloadRightsErrorResolution]].&lt;br /&gt;
&lt;br /&gt;
See [[#RequestApplicationUpdateInfo]] regarding nifm.&lt;br /&gt;
&lt;br /&gt;
==== GetPromotionInfo ====&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of [[#PromotionInfo]], a type-0x5 input buffer containing an array of u64 [[NCM_services#ApplicationId|ApplicationIds]], a type-0x5 input buffer containing an array of [[Account_services#Uid|Uids]], no output.&lt;br /&gt;
&lt;br /&gt;
Official sw uses hard-coded value 1 for the count with each of these arrays.&lt;br /&gt;
&lt;br /&gt;
==== ListPromotionInfo ====&lt;br /&gt;
[20.0.0+] The struct size for the output buffer array is now 0x28-bytes instead of 0x20-bytes.&lt;br /&gt;
&lt;br /&gt;
==== ImportPromotionJsonForDebug ====&lt;br /&gt;
Takes a type-0x5 input buffer, no output.&lt;br /&gt;
&lt;br /&gt;
The output from [[Settings_services#GetDebugModeFlag]] must be 1, otherwise an error is returned.&lt;br /&gt;
&lt;br /&gt;
==== ClearPromotionInfoForDebug ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
The output from [[Settings_services#GetDebugModeFlag]] must be 1, otherwise an error is returned.&lt;br /&gt;
&lt;br /&gt;
This just clears 0xC-bytes in state.&lt;br /&gt;
&lt;br /&gt;
==== CreateApplicationResource ====&lt;br /&gt;
Takes an input [[#ApplicationResourceType]]. Returns an [[#IApplicationResource]].&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationResource ====&lt;br /&gt;
Takes an input u64 ProcessId and an input [[#ApplicationResourceType]]. Returns an [[#IApplicationResource]].&lt;br /&gt;
&lt;br /&gt;
==== LaunchMicroApplication ====&lt;br /&gt;
[18.0.0+] Now takes a total of 0x50 bytes of input.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] Now takes a total of 0x80 bytes of input.&lt;br /&gt;
&lt;br /&gt;
==== CreateApplicationInstance ====&lt;br /&gt;
[18.0.0+] Now takes a total of 0x50 bytes of input.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] Now takes a total of 0x80 bytes of input.&lt;br /&gt;
&lt;br /&gt;
==== RegisterDeviceLockKey ====&lt;br /&gt;
Takes a type-0x5 input buffer containing an InArray of u8, no output.&lt;br /&gt;
&lt;br /&gt;
User-processes expose this with two funcs: one which uses an user-specified u8 array directly, while the other uses [[HID_services#NpadButtonSet|NpadButton]].&lt;br /&gt;
&lt;br /&gt;
This does SHA256 hashing, etc.&lt;br /&gt;
&lt;br /&gt;
==== UnregisterDeviceLockKey ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Runs code identical to [[#RegisterDeviceLockKey]], except the passed buffer/size are 0.&lt;br /&gt;
&lt;br /&gt;
==== VerifyDeviceLockKey ====&lt;br /&gt;
Takes a type-0x5 input buffer containing an InArray of u8, no output.&lt;br /&gt;
&lt;br /&gt;
User-processes expose this with two funcs: one which uses an user-specified u8 array directly, while the other uses [[HID_services#NpadButtonSet|NpadButton]].&lt;br /&gt;
&lt;br /&gt;
This runs hashing similar to [[#RegisterDeviceLockKey]], with the calculated hash being verified with the one from state.&lt;br /&gt;
&lt;br /&gt;
==== HideApplicationIcon ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== ShowApplicationIcon ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== HideApplicationTitle ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== ShowApplicationTitle ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== EnableGameCard ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== DisableGameCard ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== EnableLocalContentShare ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== DisableLocalContentShare ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== IsApplicationIconHidden ====&lt;br /&gt;
No input, returns an output bool.&lt;br /&gt;
&lt;br /&gt;
==== IsApplicationTitleHidden ====&lt;br /&gt;
No input, returns an output bool.&lt;br /&gt;
&lt;br /&gt;
==== IsGameCardEnabled ====&lt;br /&gt;
No input, returns an output bool.&lt;br /&gt;
&lt;br /&gt;
==== IsLocalContentShareEnabled ====&lt;br /&gt;
No input, returns an output bool.&lt;br /&gt;
&lt;br /&gt;
Various Deliver cmds now run essentially the same code as IsLocalContentShareEnabled, with an error being returned when it&#039;s not enabled.&lt;br /&gt;
&lt;br /&gt;
==== Cmd4026 ====&lt;br /&gt;
Takes an input u64, returns an [[#IHostSession|IHostSession]].&lt;br /&gt;
&lt;br /&gt;
The input u64 must match a state field.&lt;br /&gt;
&lt;br /&gt;
This initializes [[LDN_services|ldn]] etc, and creates a network.&lt;br /&gt;
&lt;br /&gt;
==== Cmd4027 ====&lt;br /&gt;
Takes an input u64, returns an [[#IClientSession|IClientSession]].&lt;br /&gt;
&lt;br /&gt;
The input u64 must match a state field.&lt;br /&gt;
&lt;br /&gt;
This initializes [[LDN_services|ldn]] etc.&lt;br /&gt;
&lt;br /&gt;
=== IGameCardStopper ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IGameCardStopper&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This interface has no commands.&lt;br /&gt;
&lt;br /&gt;
=== IRequestServerStopper ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IRequestServerStopper&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This interface has no commands.&lt;br /&gt;
&lt;br /&gt;
=== IProgressMonitorForDeleteUserSaveDataAll ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IProgressMonitorForDeleteUserSaveDataAll&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetSystemEvent&lt;br /&gt;
|-&lt;br /&gt;
| 1 || IsFinished&lt;br /&gt;
|-&lt;br /&gt;
| 2 || GetResult&lt;br /&gt;
|-&lt;br /&gt;
| 10 || GetProgress&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
When closing the object, official sw uses IsFinished first, asserting when the output bool is false.&lt;br /&gt;
&lt;br /&gt;
* GetSystemEvent: No input, returns an output Event handle. [[qlaunch]] doesn&#039;t use this.&lt;br /&gt;
&lt;br /&gt;
* IsFinished: No input, returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
* GetResult: No input/output.&lt;br /&gt;
&lt;br /&gt;
* GetProgress: No input, returns an output [[#ProgressForDeleteUserSaveDataAll]]. Official sw writes this struct directly to object state.&lt;br /&gt;
&lt;br /&gt;
=== IProgressAsyncResult ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IProgressAsyncResult&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || Get&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Cancel&lt;br /&gt;
|-&lt;br /&gt;
| 2 || GetProgress&lt;br /&gt;
|-&lt;br /&gt;
| 3 || GetDetailResult&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [4.0.0+] GetErrorContext&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IHostSession ===&lt;br /&gt;
This is &amp;quot;nn::ns::vphym::detail::IHostSession&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [20.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || &lt;br /&gt;
|-&lt;br /&gt;
| 1 || &lt;br /&gt;
|-&lt;br /&gt;
| 2 || &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Cmd0 ====&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
The async task does the following:&lt;br /&gt;
* This waits for a client to connect.&lt;br /&gt;
* The [[LDN_services|NodeInfo]] UserName is converted into two u64s, which are used to locate a state entry with matching values.&lt;br /&gt;
* The client [[LDN_services|NodeInfo]] Ipv4Address is copied into state.&lt;br /&gt;
* Then a ptr to the above located state entry is also written into state.&lt;br /&gt;
&lt;br /&gt;
==== Cmd1 ====&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
The async task uses [[NIM_services|nim]] cmd2018 or cmd2027, depending on a state field. Once finished when a state flag is set, [[LDN_services|ldn]] is finalized and that state flag is cleared.&lt;br /&gt;
&lt;br /&gt;
==== Cmd2 ====&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
The async task uses [[NIM_sevices|nim]] cmd2024.&lt;br /&gt;
&lt;br /&gt;
=== IClientSession ===&lt;br /&gt;
This is &amp;quot;nn::ns::vphym::detail::IClientSession&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [20.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || &lt;br /&gt;
|-&lt;br /&gt;
| 1 || &lt;br /&gt;
|-&lt;br /&gt;
| 2 || &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Cmd0 ====&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
The async task does the following:&lt;br /&gt;
* Uses [[LDN_services|ldn]] Scan.&lt;br /&gt;
* After a [[LDN_services|NodeInfo]] is found with a matching UserName, the Ipv4Address for it is copied into state.&lt;br /&gt;
* If a timeout didn&#039;t occur and a valid NodeInfo was found, it proceeds with connecting to the network.&lt;br /&gt;
&lt;br /&gt;
==== Cmd1 ====&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
The async task uses [[NIM_services|nim]] cmd2019 or cmd2028, depending on a state field. Once finished when a state flag is set, [[LDN_services|ldn]] is finalized and that state flag is cleared.&lt;br /&gt;
&lt;br /&gt;
==== Cmd2 ====&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
This is identical to [[#IHostSession|IHostSession]] Cmd2.&lt;br /&gt;
&lt;br /&gt;
=== IApplicationVersionInterface ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IApplicationVersionInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [4.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetLaunchRequiredVersion&lt;br /&gt;
|-&lt;br /&gt;
| 1 || UpgradeLaunchRequiredVersion&lt;br /&gt;
|-&lt;br /&gt;
| 35 || UpdateVersionList&lt;br /&gt;
|-&lt;br /&gt;
| 36 || PushLaunchVersion&lt;br /&gt;
|-&lt;br /&gt;
| 37 || ListRequiredVersion&lt;br /&gt;
|-&lt;br /&gt;
| 800 || RequestVersionList&lt;br /&gt;
|-&lt;br /&gt;
| 801 || ListVersionList&lt;br /&gt;
|-&lt;br /&gt;
| 802 || [[#RequestVersionListData]]&lt;br /&gt;
|-&lt;br /&gt;
| 900 || [12.0.0+] ImportAutoUpdatePolicyJsonForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 901 || [12.0.0+] ListDefaultAutoUpdatePolicy&lt;br /&gt;
|-&lt;br /&gt;
| 902 || [12.0.0+] ListAutoUpdatePolicyForSpecificApplication&lt;br /&gt;
|-&lt;br /&gt;
| 1000 || PerformAutoUpdate&lt;br /&gt;
|-&lt;br /&gt;
| 1001 || [11.0.0+] ListAutoUpdateSchedule&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== RequestVersionListData ====&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
The data that can be read from the [[#IAsyncValue]] is [[#VersionListData]].&lt;br /&gt;
&lt;br /&gt;
=== IContentManagementInterface ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IContentManagementInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [[#CalculateApplicationOccupiedSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 43 || [[#CheckSdCardMountStatus]]&lt;br /&gt;
|-&lt;br /&gt;
| 47 || [[#GetTotalSpaceSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 48 || [[#GetFreeSpaceSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 58 || [20.1.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 71 || [20.1.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 600 || [[#CountApplicationContentMeta]]&lt;br /&gt;
|-&lt;br /&gt;
| 601 || [[#ListApplicationContentMetaStatus]]&lt;br /&gt;
|-&lt;br /&gt;
| 605 || [[#ListApplicationContentMetaStatusWithRightsCheck]]&lt;br /&gt;
|-&lt;br /&gt;
| 607 || [[#IsAnyApplicationRunning]]&lt;br /&gt;
|-&lt;br /&gt;
| 608 || [21.0.0+]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== CalculateApplicationOccupiedSize ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output [[#ApplicationOccupiedSize]].&lt;br /&gt;
&lt;br /&gt;
==== CheckSdCardMountStatus ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== CountApplicationContentMeta ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output s32.&lt;br /&gt;
&lt;br /&gt;
==== ListApplicationContentMetaStatusWithRightsCheck ====&lt;br /&gt;
Same input/output as [[#ListApplicationContentMetaStatus]].&lt;br /&gt;
&lt;br /&gt;
==== IsAnyApplicationRunning ====&lt;br /&gt;
No input, returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
=== IDocumentInterface ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IDocumentInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 21 || GetApplicationContentPath&lt;br /&gt;
|-&lt;br /&gt;
| 23 || ResolveApplicationContentPath&lt;br /&gt;
|-&lt;br /&gt;
| 92 || [5.0.0+] GetRunningApplicationProgramId&lt;br /&gt;
|-&lt;br /&gt;
| 100 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 101 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 2524 || [19.0.0+] &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Cmd100 ====&lt;br /&gt;
Takes a type-0x16 output buffer containing a 0x300-byte struct, an input u8, an u64. Returns two output u8s.&lt;br /&gt;
&lt;br /&gt;
==== Cmd101 ====&lt;br /&gt;
Takes a type-0x16 output buffer containing a 0x300-byte struct, an input u8, an u64. Returns an output u8, an u8 [[Filesystem_services|ContentAttributes]], and a [[NCM_services#ProgramId|ProgramId]].&lt;br /&gt;
&lt;br /&gt;
This is similar to Cmd2524. On [S2] this is used instead of Cmd2524.&lt;br /&gt;
&lt;br /&gt;
==== Cmd2524 ====&lt;br /&gt;
Takes a type-0x16 output buffer containing a 0x300-byte struct, an input u8, an u64. Returns an output u8 [[Filesystem_services|ContentAttributes]] and a [[NCM_services#ProgramId|ProgramId]].&lt;br /&gt;
&lt;br /&gt;
The user-process uses the output from this as the input for [[Filesystem_services|OpenFileSystemWithId]] (out-buffer is used as the [[Filesystem_services|FspPath]]).&lt;br /&gt;
&lt;br /&gt;
=== IDownloadTaskInterface ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IDownloadTaskInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 701 || [[#ClearTaskStatusList]]&lt;br /&gt;
|-&lt;br /&gt;
| 702 || [[#RequestDownloadTaskList]]&lt;br /&gt;
|-&lt;br /&gt;
| 703 || [[#RequestEnsureDownloadTask]]&lt;br /&gt;
|-&lt;br /&gt;
| 704 || [[#ListDownloadTaskStatus]]&lt;br /&gt;
|-&lt;br /&gt;
| 705 || [[#RequestDownloadTaskListData]]&lt;br /&gt;
|-&lt;br /&gt;
| 706 || [4.0.0+] [[#TryCommitCurrentApplicationDownloadTask]]&lt;br /&gt;
|-&lt;br /&gt;
| 707 || [4.0.0+] [[#EnableAutoCommit]]&lt;br /&gt;
|-&lt;br /&gt;
| 708 || [4.0.0+] [[#DisableAutoCommit]]&lt;br /&gt;
|-&lt;br /&gt;
| 709 || [4.0.0+] [[#TriggerDynamicCommitEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 710 || [20.0.0+]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== ClearTaskStatusList ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== RequestDownloadTaskList ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== RequestEnsureDownloadTask ====&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
==== ListDownloadTaskStatus ====&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of [[#DownloadTaskStatus]], returns an output s32 total_out.&lt;br /&gt;
&lt;br /&gt;
A maximum of 0x100 tasks can be stored in state.&lt;br /&gt;
&lt;br /&gt;
==== TryCommitCurrentApplicationDownloadTask ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== EnableAutoCommit ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== DisableAutoCommit ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== TriggerDynamicCommitEvent ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
=== IReadOnlyApplicationRecordInterface ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IReadOnlyApplicationRecordInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [5.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || HasApplicationRecord || Same as [[#IApplicationManagerInterface]] cmd 910&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [10.0.0+] NotifyApplicationFailure ||&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [10.0.0+] IsDataCorruptedResult ||&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [20.0.0+] [[#ListApplicationRecord|ListApplicationRecord]] ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IReadOnlyApplicationControlDataInterface ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IReadOnlyApplicationControlDataInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [5.1.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#GetApplicationControlData]] || Same as [[#IApplicationManagerInterface]] cmd 400&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#GetApplicationDesiredLanguage]] || Same as [[#IApplicationManagerInterface]] cmd 55&lt;br /&gt;
|-&lt;br /&gt;
| 2 || ConvertApplicationLanguageToLanguageCode || Same as [[#IApplicationManagerInterface]] cmd 59&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [[#ConvertLanguageCodeToApplicationLanguage]] || Same as [[#IApplicationManagerInterface]] cmd 60&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [9.0.0+] SelectApplicationDesiredLanguage ||&lt;br /&gt;
|-&lt;br /&gt;
| 5 || [19.0.0+] || Same as [[#IApplicationManagerInterface]] cmd 411&lt;br /&gt;
|-&lt;br /&gt;
| 6 || [19.0.0+] || Same as [[#IApplicationManagerInterface]] cmd 416&lt;br /&gt;
|-&lt;br /&gt;
| 7 || [20.0.0+] || Same as [[#IApplicationManagerInterface]] cmd 921&lt;br /&gt;
|-&lt;br /&gt;
| 8 || [20.0.0+] || Same as [[#IApplicationManagerInterface]] cmd 922&lt;br /&gt;
|-&lt;br /&gt;
| 9 || [20.0.0+] || Same as [[#IApplicationManagerInterface]] cmd 923&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [20.0.0+] || Same as [[#IApplicationManagerInterface]] cmd 421&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [20.0.0+] || Same as [[#IApplicationManagerInterface]] cmd 422&lt;br /&gt;
|-&lt;br /&gt;
| 12 || [20.0.0+] || Same as [[#IApplicationManagerInterface]] cmd 423&lt;br /&gt;
|-&lt;br /&gt;
| 13 || [20.0.0+] || Same as [[#IApplicationManagerInterface]] cmd 407&lt;br /&gt;
|-&lt;br /&gt;
| 14 || [20.0.0+] || Same as [[#IApplicationManagerInterface]] cmd 408&lt;br /&gt;
|-&lt;br /&gt;
| 15 || [20.0.0+] || Same as [[#IApplicationManagerInterface]] cmd 415&lt;br /&gt;
|-&lt;br /&gt;
| 16 || [20.0.0+] ||&lt;br /&gt;
|-&lt;br /&gt;
| 17 || [20.1.0+] || Same as [[#IApplicationManagerInterface]] cmd 933&lt;br /&gt;
|-&lt;br /&gt;
| 18 || [21.0.0+] ||&lt;br /&gt;
|-&lt;br /&gt;
| 19 || [21.0.0+] ||&lt;br /&gt;
|-&lt;br /&gt;
| 20 || [21.0.0+] ||&lt;br /&gt;
|-&lt;br /&gt;
| 21 || [21.0.0+] ||&lt;br /&gt;
|-&lt;br /&gt;
| 22 || [21.0.0+] ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IDynamicRightsInterface ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IDynamicRightsInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [6.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#RequestApplicationRightsOnServer]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#RequestAssignRights]]&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [[#DeprecatedRequestAssignRightsToResume]]&lt;br /&gt;
|-&lt;br /&gt;
| 5 || [[#VerifyActivatedRightsOwners]]&lt;br /&gt;
|-&lt;br /&gt;
| 6 || [[#DeprecatedGetApplicationRightsStatus]]&lt;br /&gt;
|-&lt;br /&gt;
| 7 || [[#RequestPrefetchForDynamicRights]]&lt;br /&gt;
|-&lt;br /&gt;
| 8 || [[#GetDynamicRightsState]]&lt;br /&gt;
|-&lt;br /&gt;
| 9 || [7.0.0+] [[#RequestApplicationRightsOnServerToResume]]&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [7.0.0+] [[#RequestAssignRightsToResume]]&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [7.0.0+] [[#GetActivatedRightsUsers]]&lt;br /&gt;
|-&lt;br /&gt;
| 12 || [8.0.0+] [[#GetApplicationRightsStatus]]&lt;br /&gt;
|-&lt;br /&gt;
| 13 || [8.0.0+] [[#GetRunningApplicationStatus]]&lt;br /&gt;
|-&lt;br /&gt;
| 14 || [10.0.0-15.0.1] SelectApplicationLicense&lt;br /&gt;
|-&lt;br /&gt;
| 15 || [12.0.0+] [[#RequestContentsAuthorizationToken]]&lt;br /&gt;
|-&lt;br /&gt;
| 16 || [13.0.0+] QualifyUser&lt;br /&gt;
|-&lt;br /&gt;
| 17 || [13.0.0+] QualifyUserWithProcessId&lt;br /&gt;
|-&lt;br /&gt;
| 18 || [13.0.0+] NotifyApplicationRightsCheckStart&lt;br /&gt;
|-&lt;br /&gt;
| 19 || [13.0.0+] UpdateUserList&lt;br /&gt;
|-&lt;br /&gt;
| 20 || [13.0.0+] IsRightsLostUser&lt;br /&gt;
|-&lt;br /&gt;
| 21 || [13.1.0+] SetRequiredAddOnContentsOnContentsAvailabilityTransition&lt;br /&gt;
|-&lt;br /&gt;
| 22 || [14.0.0+] GetLimitedApplicationLicense&lt;br /&gt;
|-&lt;br /&gt;
| 23 || [14.0.0+] GetLimitedApplicationLicenseUpgradableEvent&lt;br /&gt;
|-&lt;br /&gt;
| 24 || [14.0.0+] NotifyLimitedApplicationLicenseUpgradableEventForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 25 || [14.0.0+] RequestProceedDynamicRightsState&lt;br /&gt;
|-&lt;br /&gt;
| 26 || [18.0.0+] HasAccountRestrictedRightsInRunningApplications&lt;br /&gt;
|-&lt;br /&gt;
| 27 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 28 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 29 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 30 || [21.0.0+]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== RequestApplicationRightsOnServer ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], an [[Account_services#Uid|Uid]] and an u32. Returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
==== RequestAssignRights ====&lt;br /&gt;
Takes a type-0x5 input buffer containing an array of &amp;quot;nn::ns::ApplicationRightsOnServer&amp;quot;. Returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
==== DeprecatedRequestAssignRightsToResume ====&lt;br /&gt;
Takes an input u64 &amp;quot;nn::ns::RightsEnvironmentHandle&amp;quot; and an [[Account_services#Uid|Uid]]. Returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
==== VerifyActivatedRightsOwners ====&lt;br /&gt;
Takes an input u64 &amp;quot;nn::ns::RightsEnvironmentHandle&amp;quot;. No output.&lt;br /&gt;
&lt;br /&gt;
==== DeprecatedGetApplicationRightsStatus ====&lt;br /&gt;
Takes an input u64 &amp;quot;nn::ns::RightsEnvironmentHandle&amp;quot;. Returns a bool &amp;quot;nn::ns::ApplicationRightsStatus&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==== RequestPrefetchForDynamicRights ====&lt;br /&gt;
Takes an input [[Account_services#Uid|Uid]]. Returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
==== GetDynamicRightsState ====&lt;br /&gt;
No input. Returns a bool &amp;quot;nn::ns::DynamicRightsState&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==== RequestApplicationRightsOnServerToResume ====&lt;br /&gt;
Takes an input u64 &amp;quot;nn::ns::RightsEnvironmentHandle&amp;quot;. Returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
==== RequestAssignRightsToResume ====&lt;br /&gt;
Takes an input u64 &amp;quot;nn::ns::RightsEnvironmentHandle&amp;quot;. Returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
==== GetActivatedRightsUsers ====&lt;br /&gt;
Takes an input u64 &amp;quot;nn::ns::RightsEnvironmentHandle&amp;quot;. Returns a bool, an u32 and a type-0x6 output buffer containing an array of [[Account_services#Uid|Uid]].&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationRightsStatus ====&lt;br /&gt;
Takes an input &amp;quot;nn::ns::RightsEnvironmentHandle&amp;quot;. Returns 2 bools &amp;quot;nn::ns::ApplicationRightsStatus&amp;quot; and &amp;quot;nn::ns::ApplicationLicenseType&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==== GetRunningApplicationStatus ====&lt;br /&gt;
Takes an input u64 &amp;quot;nn::ns::RightsEnvironmentHandle&amp;quot;. Returns an u32 &amp;quot;nn::ns::RunningApplicationStatus&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==== RequestContentsAuthorizationToken ====&lt;br /&gt;
Takes a total of 0x50-bytes of input, a type-0x5 input buffer. Returns an [[#IAsyncData_2|IAsyncData]] and an output handle.&lt;br /&gt;
&lt;br /&gt;
==== IAsyncData ====&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IAsyncData&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [12.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetSize&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Get&lt;br /&gt;
|-&lt;br /&gt;
| 2 || Cancel&lt;br /&gt;
|-&lt;br /&gt;
| 3 || GetErrorContext&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IECommerceInterface===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IECommerceInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [4.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#RequestLinkDevice]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [6.0.0+] [[#RequestCleanupAllPreInstalledApplications]]&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [6.0.0+] [[#RequestCleanupPreInstalledApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [6.0.0+] [[#RequestSyncRights]]&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [6.0.0+] [[#RequestUnlinkDevice]]&lt;br /&gt;
|-&lt;br /&gt;
| 5 || [6.1.0+] [[#RequestRevokeAllELicense]]&lt;br /&gt;
|-&lt;br /&gt;
| 6 || [9.0.0+] [[#RequestSyncRightsBasedOnAssignedELicenses]]&lt;br /&gt;
|-&lt;br /&gt;
| 7 || [14.0.0+] RequestOnlineSubscriptionFreeTrialAvailability&lt;br /&gt;
|-&lt;br /&gt;
| 8 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 9 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 12 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 13 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 14 || [21.0.0+]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== RequestLinkDevice ====&lt;br /&gt;
Takes an input [[Account_services#Uid|Uid]], returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
See [[#RequestApplicationUpdateInfo]] regarding nifm.&lt;br /&gt;
&lt;br /&gt;
==== RequestCleanupAllPreInstalledApplications ====&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
==== RequestCleanupPreInstalledApplication ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
==== RequestSyncRights ====&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
==== RequestUnlinkDevice ====&lt;br /&gt;
Takes an input [[Account_services#Uid|Uid]], returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
See [[#RequestApplicationUpdateInfo]] regarding nifm.&lt;br /&gt;
&lt;br /&gt;
==== RequestRevokeAllELicense ====&lt;br /&gt;
Takes an input [[Account_services#Uid|Uid]], returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
==== RequestSyncRightsBasedOnAssignedELicenses ====&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
=== IFactoryResetInterface ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IFactoryResetInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 100 || [[#ResetToFactorySettings]]&lt;br /&gt;
|-&lt;br /&gt;
| 101 || [[#ResetToFactorySettingsWithoutUserSaveData]]&lt;br /&gt;
|-&lt;br /&gt;
| 102 || [[#ResetToFactorySettingsForRefurbishment]]&lt;br /&gt;
|-&lt;br /&gt;
| 103 || [9.1.0+] [[#ResetToFactorySettingsWithPlatformRegion]]&lt;br /&gt;
|-&lt;br /&gt;
| 104 || [9.1.0+] [[#ResetToFactorySettingsWithPlatformRegionAuthentication]]&lt;br /&gt;
|-&lt;br /&gt;
| 105 || [10.0.0+] [[#RequestResetToFactorySettingsSecurely]]&lt;br /&gt;
|-&lt;br /&gt;
| 106 || [10.0.0+] [[#RequestResetToFactorySettingsWithPlatformRegionAuthenticationSecurely]]&lt;br /&gt;
|-&lt;br /&gt;
| 107 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 108 || [20.0.0+]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== ResetToFactorySettings ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
As of [9.1.0] this is the only [[#IFactoryResetInterface]] cmd used by [[qlaunch]].&lt;br /&gt;
&lt;br /&gt;
==== ResetToFactorySettingsWithoutUserSaveData ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== ResetToFactorySettingsForRefurbishment ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== ResetToFactorySettingsWithPlatformRegion ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== ResetToFactorySettingsWithPlatformRegionAuthentication ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== RequestResetToFactorySettingsSecurely ====&lt;br /&gt;
Takes an input u64 tmem_size, a TransferMemory handle, returns an output [[#IAsyncValueAndProgress]] and an Event handle.&lt;br /&gt;
&lt;br /&gt;
The TransferMemory uses permissions=0.&lt;br /&gt;
&lt;br /&gt;
==== RequestResetToFactorySettingsWithPlatformRegionAuthenticationSecurely ====&lt;br /&gt;
Takes an input u32 &amp;quot;nn::ae::PlatformRegion&amp;quot;, an u64 tmem_size, a TransferMemory handle, returns an output [[#IAsyncValueAndProgress]] and an Event handle.&lt;br /&gt;
&lt;br /&gt;
The TransferMemory uses permissions=0.&lt;br /&gt;
&lt;br /&gt;
===== IAsyncValueAndProgress =====&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IAsyncValueAndProgress&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [10.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetSize&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Get&lt;br /&gt;
|-&lt;br /&gt;
| 2 || Cancel&lt;br /&gt;
|-&lt;br /&gt;
| 3 || GetErrorContext&lt;br /&gt;
|-&lt;br /&gt;
| 4 || GetProgress&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IApplicationResource ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IApplicationResource&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [9.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || Attach&lt;br /&gt;
|-&lt;br /&gt;
| 1 || BoostSystemMemoryResourceLimit&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ns:vm =&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IVulnerabilityManagerInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 1200 || [3.0.0+] [[#NeedsUpdateVulnerability]]&lt;br /&gt;
|-&lt;br /&gt;
| 1201 || [4.0.0+] [[#UpdateSafeSystemVersionForDebug]]&lt;br /&gt;
|-&lt;br /&gt;
| 1202 || [4.0.0+] [[#GetSafeSystemVersion]]&lt;br /&gt;
|-&lt;br /&gt;
| 3100 || [18.0.0+] [[#GetSafeSystemVersionCheckInfo|GetSafeSystemVersionCheckInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 3101 || [18.0.0+] [[#RequestUpdateSafeSystemVersionCheckInfo|RequestUpdateSafeSystemVersionCheckInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 3102 || [18.0.0+] [[#ResetSafeSystemVersionCheckInfo|ResetSafeSystemVersionCheckInfo]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== NeedsUpdateVulnerability ==&lt;br /&gt;
No input, returns an output u8 bool flag.&lt;br /&gt;
&lt;br /&gt;
[S1] Web-applets use this command to check if the system needs an update.&lt;br /&gt;
&lt;br /&gt;
== UpdateSafeSystemVersionForDebug ==&lt;br /&gt;
Takes an input u32 &#039;&#039;&#039;version&#039;&#039;&#039; and an [[NCM_services#ApplicationId|ApplicationId]].&lt;br /&gt;
&lt;br /&gt;
This command is not available for retail units. On a debug unit, if the [[System_Settings|system setting]] &amp;lt;code&amp;gt;vulnerability!enable_debug&amp;lt;/code&amp;gt; is set, this mounts the system savegame [[Flash_Filesystem#System_Savegames|0x8000000000000049]] as &amp;quot;ns_ssversion:/&amp;quot;, opens the file &amp;quot;ns_ssversion:/entry&amp;quot; and writes the supplied [[NCM_services#ApplicationId|ApplicationId]] and &#039;&#039;&#039;version&#039;&#039;&#039; in it.&lt;br /&gt;
&lt;br /&gt;
Finally, it calls [[NCM_services#ncm|OpenContentMetaDatabase]] with [[NCM_services#StorageId|StorageId]] 3, then calls [[NCM_services#IContentMetaDatabase|GetLatestContentMetaKey]] with the supplied [[NCM_services#ApplicationId|ApplicationId]] and compares the version field from the returned [[CNMT#Content_Meta_Records|Content Meta Record]] with the supplied &#039;&#039;&#039;version&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
If the supplied &#039;&#039;&#039;version&#039;&#039;&#039; is higher than the one in NCM&#039;s database, the value returned by [[NS_Services#NeedsUpdateVulnerability|NeedsUpdateVulnerability]] is set to &amp;quot;true&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== GetSafeSystemVersion ==&lt;br /&gt;
No input, returns an output [[NCM_services#ContentMetaKey|ContentMetaKey]] with the cached contents of &amp;quot;ns_ssversion:/entry&amp;quot; ([[NCM_services#ApplicationId|ApplicationId]], u32 &#039;&#039;&#039;version&#039;&#039;&#039; and u32 &#039;&#039;&#039;policy&#039;&#039;&#039; from &amp;lt;code&amp;gt;vulnerability!needs_update_vulnerability_policy&amp;lt;/code&amp;gt;).&lt;br /&gt;
&lt;br /&gt;
== GetSafeSystemVersionCheckInfo ==&lt;br /&gt;
No input, returns 0x10-bytes of output.&lt;br /&gt;
&lt;br /&gt;
[S2] Used by web-applets via ns:vm.&lt;br /&gt;
&lt;br /&gt;
== RequestUpdateSafeSystemVersionCheckInfo ==&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncResult|IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
[S2] Used by web-applets via ns:vm.&lt;br /&gt;
&lt;br /&gt;
The async task thread uses [[NIM_services|nim]] RequestCheckSafeSystemVersion, etc.&lt;br /&gt;
&lt;br /&gt;
== ResetSafeSystemVersionCheckInfo ==&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
This throws an error if [[Settings_services|GetDebugModeFlag]] returns false.&lt;br /&gt;
&lt;br /&gt;
= ns:su =&lt;br /&gt;
This is &amp;quot;nn::ns::detail::ISystemUpdateInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#GetBackgroundNetworkUpdateState]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#OpenSystemUpdateControl]]&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [[#NotifyExFatDriverRequired]]&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [[#ClearExFatDriverStatusForDebug]]&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [[#RequestBackgroundNetworkUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 5 || [[#NotifyBackgroundNetworkUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 6 || [[#NotifyExFatDriverDownloadedForDebug]]&lt;br /&gt;
|-&lt;br /&gt;
| 9 || [[#GetSystemUpdateNotificationEventForContentDelivery]]&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [[#NotifySystemUpdateForContentDelivery]]&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [3.0.0+] [[#PrepareShutdown]]&lt;br /&gt;
|-&lt;br /&gt;
| 12 || [3.0.0-3.0.2]&lt;br /&gt;
|-&lt;br /&gt;
| 13 || [3.0.0-3.0.2]&lt;br /&gt;
|-&lt;br /&gt;
| 14 || [3.0.0-3.0.2]&lt;br /&gt;
|-&lt;br /&gt;
| 15 || [3.0.0-3.0.2]&lt;br /&gt;
|-&lt;br /&gt;
| 16 || [4.0.0+] [[#DestroySystemUpdateTask]]&lt;br /&gt;
|-&lt;br /&gt;
| 17 || [4.0.0+] [[#RequestSendSystemUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 18 || [4.0.0+] [[#GetSendSystemUpdateProgress]]&lt;br /&gt;
|-&lt;br /&gt;
| 19 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 20 || [S2]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== GetBackgroundNetworkUpdateState ==&lt;br /&gt;
No input, returns an output [[#BackgroundNetworkUpdateState]].&lt;br /&gt;
&lt;br /&gt;
This is similar to [[#HasDownloaded]], see [[#BackgroundNetworkUpdateState]].&lt;br /&gt;
&lt;br /&gt;
== OpenSystemUpdateControl ==&lt;br /&gt;
No input, returns an [[#ISystemUpdateControl]].&lt;br /&gt;
&lt;br /&gt;
Only 1 ISystemUpdateControl can be open at a time.&lt;br /&gt;
&lt;br /&gt;
== NotifyExFatDriverRequired ==&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Only usable when an [[#ISystemUpdateControl]] isn&#039;t open.&lt;br /&gt;
&lt;br /&gt;
This uses [[NIM_services|nim]] ListSystemUpdateTask, then when a task is returned uses it with DestroySystemUpdateTask.&lt;br /&gt;
&lt;br /&gt;
Then this runs ExFat handling, updates state, and sets the same state flag as [[#RequestBackgroundNetworkUpdate]].&lt;br /&gt;
&lt;br /&gt;
== ClearExFatDriverStatusForDebug ==&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
== RequestBackgroundNetworkUpdate ==&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Only usable when an [[#ISystemUpdateControl]] isn&#039;t open.&lt;br /&gt;
&lt;br /&gt;
This sets a state flag to value 1.&lt;br /&gt;
&lt;br /&gt;
== NotifyBackgroundNetworkUpdate ==&lt;br /&gt;
Takes an input [[NCM_services#ContentMetaKey|ContentMetaKey]], no output.&lt;br /&gt;
&lt;br /&gt;
This checks whether a sysupdate is needed with the input ContentMetaKey using [[NCM_services|NCM]] commands, if not this will just return 0. Otherwise, this will then run code which is identical to [[#RequestBackgroundNetworkUpdate]].&lt;br /&gt;
&lt;br /&gt;
== NotifyExFatDriverDownloadedForDebug ==&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
== GetSystemUpdateNotificationEventForContentDelivery ==&lt;br /&gt;
No input, returns an output Event handle with EventClearMode=0.&lt;br /&gt;
&lt;br /&gt;
== NotifySystemUpdateForContentDelivery ==&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Signals the Event returned by [[#GetSystemUpdateNotificationEventForContentDelivery]].&lt;br /&gt;
&lt;br /&gt;
== PrepareShutdown ==&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
This is used by [[AM_services|AM]].&lt;br /&gt;
&lt;br /&gt;
Just returns 0 when an [[#ISystemUpdateControl]] is open. &lt;br /&gt;
&lt;br /&gt;
This does various cleanup / uses various service-cmds etc for shutdown preparation.&lt;br /&gt;
&lt;br /&gt;
== DestroySystemUpdateTask ==&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Only usable when an [[#ISystemUpdateControl]] isn&#039;t open.&lt;br /&gt;
&lt;br /&gt;
This uses [[NIM_services|nim]] ListSystemUpdateTask, then when a task is returned uses it with DestroySystemUpdateTask.&lt;br /&gt;
&lt;br /&gt;
== RequestSendSystemUpdate ==&lt;br /&gt;
Takes a type-0x15 input buffer containing a [[#SystemDeliveryInfo]], an u16 port, an u32 Ipv4Address, returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
[[qlaunch]] uses value 55556 for the port. IP is normally a local-WLAN address, however this can be any address. port/addr are little-endian.&lt;br /&gt;
&lt;br /&gt;
See [[NIM_services|nim]] regarding the input addr/port usage, etc.&lt;br /&gt;
&lt;br /&gt;
[11.0.0+] An error is thrown if LocalContentShare is not [[#IsLocalContentShareEnabled|enabled]].&lt;br /&gt;
&lt;br /&gt;
This validates the [[#SystemDeliveryInfo]] and generates a [[NCM_services#ContentMetaKey|ContentMetaKey]] from that, and creates the [[#IAsyncResult]] + the async thread which handles the [[#IAsyncResult]] operation.&lt;br /&gt;
&lt;br /&gt;
The above validation verifies that the HMAC and SystemDeliveryProtocolVersion are valid. The OldSystemUpdateId ([20.0.0+] SystemUpdateId, SystemUpdateIdFlag ignored) must match the Id for the installed SystemUpdate as returned by [[NCM_services|ncm]].&lt;br /&gt;
&lt;br /&gt;
Then the thread does:&lt;br /&gt;
* Calls a func which does:&lt;br /&gt;
** Uses [[NIM_services|nim]] CreateLocalCommunicationSendSystemUpdateTask, returning the Result on failure.&lt;br /&gt;
*** The input firmware_variation is from the [[#SystemDeliveryInfo|FirmwareVariationId]].&lt;br /&gt;
** Uses [[NIM_services|nim]] RequestLocalCommunicationSendSystemUpdateTaskRun, returning the Result on failure. Waits for the IAsyncResult operation from this to finish, then uses the Get cmd to get the output Result.&lt;br /&gt;
*** When the Result from Get is an error, a func is called for filling in the [[#IAsyncResult|IAsyncResult]] ErrorContext with Type4.&lt;br /&gt;
** Handles cleanup and returns.&lt;br /&gt;
* Unlike [[#RequestReceiveSystemUpdate]], this doesn&#039;t save a SystemPlayReport.&lt;br /&gt;
&lt;br /&gt;
== GetSendSystemUpdateProgress ==&lt;br /&gt;
No input, returns an output [[#SystemUpdateProgress]].&lt;br /&gt;
&lt;br /&gt;
Same as [[#GetReceiveProgress]] except this uses nim ListLocalCommunicationSendSystemUpdateTask and GetLocalCommunicationSendSystemUpdateTaskInfo. The data copied to output is also swapped: u64 nim_out+0x8 is copied to out+0x8, and u64 nim_out+0x10 is copied to out+0x0.&lt;br /&gt;
&lt;br /&gt;
== Cmd19 ==&lt;br /&gt;
This is exclusive to S2.&lt;br /&gt;
&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
== Cmd20 ==&lt;br /&gt;
This is exclusive to S2.&lt;br /&gt;
&lt;br /&gt;
No input, returns an output u8.&lt;br /&gt;
&lt;br /&gt;
== ISystemUpdateControl ==&lt;br /&gt;
This is &amp;quot;nn::ns::detail::ISystemUpdateControl&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#HasDownloaded]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#RequestCheckLatestUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [[#RequestDownloadLatestUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [[#GetDownloadProgress]]&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [[#ApplyDownloadedUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 5 || [[#RequestPrepareCardUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 6 || [[#GetPrepareCardUpdateProgress]]&lt;br /&gt;
|-&lt;br /&gt;
| 7 || [[#HasPreparedCardUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 8 || [[#ApplyCardUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 9 || [[#GetDownloadedEulaDataSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [[#GetDownloadedEulaData]]&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [[#SetupCardUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 12 || [[#GetPreparedCardUpdateEulaDataSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 13 || [[#GetPreparedCardUpdateEulaData]]&lt;br /&gt;
|-&lt;br /&gt;
| 14 || [4.0.0+] [[#SetupCardUpdateViaSystemUpdater]]&lt;br /&gt;
|-&lt;br /&gt;
| 15 || [4.0.0+] [[#HasReceived]]&lt;br /&gt;
|-&lt;br /&gt;
| 16 || [4.0.0+] [[#RequestReceiveSystemUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 17 || [4.0.0+] [[#GetReceiveProgress]]&lt;br /&gt;
|-&lt;br /&gt;
| 18 || [4.0.0+] [[#ApplyReceivedUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 19 || [4.0.0+] [[#GetReceivedEulaDataSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 20 || [4.0.0+] [[#GetReceivedEulaData]]&lt;br /&gt;
|-&lt;br /&gt;
| 21 || [4.0.0+] [[#SetupToReceiveSystemUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 22 || [6.0.0+] [[#RequestCheckLatestUpdateIncludesRebootlessUpdate]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
All Card cmds except SetupCardUpdate* require [[#SetupCardUpdate]]/[[#SetupCardUpdateViaSystemUpdater]] to be used previously. [[#GetPreparedCardUpdateEulaDataSize]]/[[#GetPreparedCardUpdateEulaData]] checks a different state flag.&lt;br /&gt;
&lt;br /&gt;
=== HasDownloaded ===&lt;br /&gt;
No input, returns an output u8 bool flag.&lt;br /&gt;
&lt;br /&gt;
Gets whether a network sysupdate was downloaded, with install pending.&lt;br /&gt;
&lt;br /&gt;
Uses [[NIM_services|nim]] ListSystemUpdateTask and [[NIM_services|nim]] GetSystemUpdateTaskInfo. When ListSystemUpdateTask successfully returns a task and GetSystemUpdateTaskInfo is successful, the output flag is set to: &amp;lt;code&amp;gt;*((u8*)(taskinfo+0) == 0x3&amp;lt;/code&amp;gt;. Otherwise, flag=0.&lt;br /&gt;
&lt;br /&gt;
This always returns 0, however this will assert if GetSystemUpdateTaskInfo fails with ret!=0x3C89.&lt;br /&gt;
&lt;br /&gt;
=== RequestCheckLatestUpdate ===&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
The data that can be read from the [[#IAsyncValue]] is [[#LatestSystemUpdate]].&lt;br /&gt;
&lt;br /&gt;
=== RequestDownloadLatestUpdate ===&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
=== GetDownloadProgress ===&lt;br /&gt;
No input, returns an output [[#SystemUpdateProgress]].&lt;br /&gt;
&lt;br /&gt;
Similar to [[#HasDownloaded]] except instead of a flag, this returns the 0x10-bytes from taskinfo+8. The output struct is cleared when the task(info) isn&#039;t available.&lt;br /&gt;
&lt;br /&gt;
=== ApplyDownloadedUpdate ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Runs code similar to [[#HasDownloaded]], throwing an error if a network sysupdate isn&#039;t ready for install. Then the sysupdate is installed:&lt;br /&gt;
&lt;br /&gt;
* Uses ListSystemUpdateTask again, then [[NIM_services|nim]] IsExFatDriverIncluded. Runs ExFat handling when the output flag is set.&lt;br /&gt;
* On newer system-versions, this uses [[NIM_services|nim]] GetSystemUpdateTaskInfo then on success uses data from there to save a SystemPlayReport when the cached [[System_Settings|system-setting]] &amp;quot;systemreport!enabled&amp;quot; is set.&lt;br /&gt;
** The EventId is &amp;quot;systemupdate_dl_throughput&amp;quot; with ApplicationId 0100000000001018.&lt;br /&gt;
** The following fields are added to the report, see [[NIM_services#SystemUpdateTaskInfo|nim SystemUpdateTaskInfo]]: &amp;quot;ContentMetaId&amp;quot;, &amp;quot;Version&amp;quot;, &amp;quot;DownloadSize&amp;quot;, and &amp;quot;ThroughputKBps&amp;quot;.&lt;br /&gt;
* On newer system-versions, this saves another SystemPlayReport when a state flag is set (same flag mentioned above).&lt;br /&gt;
** The EventId is &amp;quot;systemupdate_pass&amp;quot; with ApplicationId 0100000000001021.&lt;br /&gt;
** This report has the following fields:&lt;br /&gt;
*** &amp;quot;Type&amp;quot;&lt;br /&gt;
*** &amp;quot;SourceSystemUpdateMetaId&amp;quot;&lt;br /&gt;
*** &amp;quot;SourceSystemUpdateMetaVersion&amp;quot;&lt;br /&gt;
*** &amp;quot;SourceExFatStatus&amp;quot;&lt;br /&gt;
*** &amp;quot;DestinationSystemUpdateMetaId&amp;quot;&lt;br /&gt;
*** &amp;quot;DestinationSystemUpdateMetaVersion&amp;quot;&lt;br /&gt;
*** &amp;quot;DestinationExFatStatus&amp;quot;&lt;br /&gt;
*** &amp;quot;Rebootless&amp;quot;&lt;br /&gt;
* Since BootImagePackage will be installed later, the two flags in [[Flash_Filesystem#System_Update_Control]] are set to 1.&lt;br /&gt;
* Uses [[NIM_services|nim]] CommitSystemUpdateTask and [[NIM_services|nim]] DestroySystemUpdateTask.&lt;br /&gt;
* Installs BootImagePackage. After installing each BootImagePackage, the associated flag in [[Flash_Filesystem#System_Update_Control]] is set to 0.&lt;br /&gt;
* On newer system versions when an input flag is set, this uses [[Filesystem_services|NotifySystemDataUpdateEvent]], however this doesn&#039;t happen with ApplyDownloadedUpdate since that input flag is 0.&lt;br /&gt;
&lt;br /&gt;
=== RequestPrepareCardUpdate ===&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
=== GetPrepareCardUpdateProgress ===&lt;br /&gt;
No input, returns an output [[#SystemUpdateProgress]].&lt;br /&gt;
&lt;br /&gt;
=== HasPreparedCardUpdate ===&lt;br /&gt;
No input, returns an output u8 bool flag.&lt;br /&gt;
&lt;br /&gt;
=== ApplyCardUpdate ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
=== GetDownloadedEulaDataSize ===&lt;br /&gt;
Takes a type-0x15 input buffer [[#EulaDataPath]], returns an output u64 &#039;&#039;&#039;filesize&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
Runs code similar to [[#HasDownloaded]], throwing an error if a network sysupdate isn&#039;t ready for install.&lt;br /&gt;
&lt;br /&gt;
Uses ListSystemUpdateTask again. Then [[NIM_services|nim]] GetDownloadedSystemDataPath, with the output ContentPath being used to mount the EULA title with FS.&lt;br /&gt;
&lt;br /&gt;
Then &amp;quot;&amp;lt;mountname&amp;gt;:/&amp;lt;[[#EulaDataPath]]&amp;gt;&amp;quot; is opened, gets the &#039;&#039;&#039;filesize&#039;&#039;&#039;, then runs cleanup.&lt;br /&gt;
&lt;br /&gt;
=== GetDownloadedEulaData ===&lt;br /&gt;
Takes a type-0x15 input buffer [[#EulaDataPath]] and a type-0x6 output buffer, returns an output u64 &#039;&#039;&#039;filesize&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
Similar to [[#GetDownloadedEulaDataSize]] except this reads the file instead, using the specified output buffer with size=filesize. This will throw an error if the filesize is larger than the buffer size.&lt;br /&gt;
&lt;br /&gt;
=== SetupCardUpdate ===&lt;br /&gt;
Takes an input u64 size and a TransferMemory handle, no output.&lt;br /&gt;
&lt;br /&gt;
Official sw creates the TransferMemory with an user-specified buffer, with permissions=None.&lt;br /&gt;
&lt;br /&gt;
[[qlaunch]] uses size 0x100000 for the TransferMemory buffer.&lt;br /&gt;
&lt;br /&gt;
=== GetPreparedCardUpdateEulaDataSize ===&lt;br /&gt;
Takes a type-0x15 input buffer [[#EulaDataPath]], returns an output u64 &#039;&#039;&#039;filesize&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
This is similar to [[#GetDownloadedEulaDataSize]].&lt;br /&gt;
&lt;br /&gt;
=== GetPreparedCardUpdateEulaData ===&lt;br /&gt;
Takes a type-0x15 input buffer [[#EulaDataPath]] and a type-0x6 output buffer, returns an output u64 &#039;&#039;&#039;filesize&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
This is similar to [[#GetDownloadedEulaData]].&lt;br /&gt;
&lt;br /&gt;
=== SetupCardUpdateViaSystemUpdater ===&lt;br /&gt;
Takes an input u64 size and a TransferMemory handle, no output.&lt;br /&gt;
&lt;br /&gt;
The permissions for the TransferMemory is None.&lt;br /&gt;
&lt;br /&gt;
Same as [[#SetupCardUpdate]], except this doesn&#039;t have the code for [[Filesystem_services|GetGameCardHandle/GetGameCardUpdatePartitionInfo]], and uses [[Filesystem_services|OpenRegisteredUpdatePartition]] instead of [[Filesystem_services|OpenGameCardFileSystem]]. This uses the same is_initialized bool state flag.&lt;br /&gt;
&lt;br /&gt;
=== HasReceived ===&lt;br /&gt;
No input, returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
Same as [[#HasDownloaded]] except this uses [[NIM_services|nim]] ListLocalCommunicationReceiveSystemUpdateTask and GetLocalCommunicationReceiveSystemUpdateTaskInfo.&lt;br /&gt;
&lt;br /&gt;
=== RequestReceiveSystemUpdate ===&lt;br /&gt;
Takes a type-0x15 input buffer containing a [[#SystemDeliveryInfo]], an u16 port, an u32 Ipv4Address, returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
[[qlaunch]] uses the same value for the port as [[#RequestSendSystemUpdate]] (see [[#RequestSendSystemUpdate]] for addr as well).&lt;br /&gt;
&lt;br /&gt;
See [[NIM_services|nim]] regarding the input addr/port usage, etc.&lt;br /&gt;
&lt;br /&gt;
This uses the same LocalContentShare check as [[#RequestSendSystemUpdate|RequestSendSystemUpdate]].&lt;br /&gt;
&lt;br /&gt;
An error is thrown if a state flag is clear.&lt;br /&gt;
&lt;br /&gt;
This validates the [[#SystemDeliveryInfo]] (same as [[#RequestSendSystemUpdate|RequestSendSystemUpdate]]) and generates a [[NCM_services#ContentMetaKey|ContentMetaKey]] from that, and creates the [[#IAsyncResult]] + the async thread which handles the [[#IAsyncResult]] operation.&lt;br /&gt;
&lt;br /&gt;
Then the thread does:&lt;br /&gt;
&lt;br /&gt;
* Calls a func which does:&lt;br /&gt;
** Throws an error if [[NIM_services#ListSystemUpdateTask|ListSystemUpdateTask]] returns any task.&lt;br /&gt;
** Checks whether a sysupdate is actually required using the previously generated [[NCM_services#ContentMetaKey|ContentMetaKey]] (this func is also passed the below statefield as the last param), throwing an error if not.&lt;br /&gt;
*** [20.0.0+] The above check-sysupdate func was updated (which is also used elsewhere), flag handling during the loop was updated (which uses the last input param).&lt;br /&gt;
** Uses [[NIM_services|nim]] CreateLocalCommunicationReceiveSystemUpdateTask, returning the Result on failure.&lt;br /&gt;
*** The input firmware_variation is from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;ns.systemupdate!firmware_variation&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;ns.systemupdate!t_firmware_variation&amp;lt;/code&amp;gt;, depending on the [[Settings_services|PlatformRegion]] (value 0xFF is used when the output setting-size is invalid).&lt;br /&gt;
*** The input &#039;&#039;&#039;unk&#039;&#039;&#039; is set to: &amp;lt;code&amp;gt;unk = statefield == 0 ? 0x4 : 0xC&amp;lt;/code&amp;gt; ([20.0.0+] uses statefield &amp;amp; 1 == 0). [20.0.0+] Additional data is now ORRed with unk afterwards: &amp;lt;code&amp;gt;unk |= ((statefield&amp;gt;&amp;gt;1) &amp;amp; 0x3) &amp;lt;&amp;lt; 8;&amp;lt;/code&amp;gt; (same statefield as before)&lt;br /&gt;
** Uses [[NIM_services|nim]] RequestLocalCommunicationReceiveSystemUpdateTaskRun, returning the Result on failure. Waits for the IAsyncResult operation from this to finish, then uses the Get cmd to get the output Result.&lt;br /&gt;
*** When the Result from Get is an error, a func is called for filling in the [[#IAsyncResult|IAsyncResult]] ErrorContext with Type4.&lt;br /&gt;
** Handles cleanup and returns.&lt;br /&gt;
* On success, this loads various data which is then used for saving a SystemPlayReport when the cached [[System_Settings|system-setting]] &amp;quot;systemreport!enabled&amp;quot; is set.&lt;br /&gt;
** The EventId is &amp;quot;receive_system_update&amp;quot; with ApplicationId &amp;lt;NS ProgramId&amp;gt;.&lt;br /&gt;
** This report has the following fields: &lt;br /&gt;
*** &amp;quot;SourceSystemUpdateId&amp;quot;&lt;br /&gt;
*** &amp;quot;DestinationSystemUpdateId&amp;quot;&lt;br /&gt;
*** &amp;quot;SourceSystemUpdateVersion&amp;quot;&lt;br /&gt;
*** &amp;quot;DestinationSystemUpdateVersion&amp;quot;&lt;br /&gt;
*** &amp;quot;SenderFirmwareVariationId&amp;quot;&lt;br /&gt;
*** &amp;quot;ReceiverFirmwareVariationId&amp;quot;&lt;br /&gt;
*** &amp;quot;SenderPlatformRegion&amp;quot;&lt;br /&gt;
*** &amp;quot;ReceiverPlatformRegion&amp;quot;&lt;br /&gt;
*** &amp;quot;SenderHasExFat&amp;quot;&lt;br /&gt;
*** &amp;quot;ReceiverHasExFat&amp;quot;&lt;br /&gt;
*** &amp;quot;Size&amp;quot;&lt;br /&gt;
*** &amp;quot;ThroughputKBps&amp;quot;&lt;br /&gt;
&lt;br /&gt;
=== GetReceiveProgress ===&lt;br /&gt;
No input, returns an output [[#SystemUpdateProgress]].&lt;br /&gt;
&lt;br /&gt;
Same as [[#GetDownloadProgress]] except this uses [[NIM_services|nim]] ListLocalCommunicationReceiveSystemUpdateTask and GetLocalCommunicationReceiveSystemUpdateTaskInfo.&lt;br /&gt;
&lt;br /&gt;
=== ApplyReceivedUpdate ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
This uses the same LocalContentShare check as [[#RequestSendSystemUpdate|RequestSendSystemUpdate]].&lt;br /&gt;
&lt;br /&gt;
=== GetReceivedEulaDataSize ===&lt;br /&gt;
Takes a type-0x15 input buffer [[#EulaDataPath]], returns an output u64 &#039;&#039;&#039;filesize&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
This is similar to [[#GetDownloadedEulaDataSize]].&lt;br /&gt;
&lt;br /&gt;
=== GetReceivedEulaData ===&lt;br /&gt;
Takes a type-0x15 input buffer [[#EulaDataPath]] and a type-0x6 output buffer, returns an output u64 &#039;&#039;&#039;filesize&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
This is similar to [[#GetDownloadedEulaData]].&lt;br /&gt;
&lt;br /&gt;
=== SetupToReceiveSystemUpdate ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
This just uses [[NIM_services|nim]] ListSystemUpdateTask, then when a task is returned uses it with DestroySystemUpdateTask.&lt;br /&gt;
&lt;br /&gt;
[[qlaunch]] uses this before [[#RequestReceiveSystemUpdate]].&lt;br /&gt;
&lt;br /&gt;
=== RequestCheckLatestUpdateIncludesRebootlessUpdate ===&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
= IAsyncValue =&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IAsyncValue&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetSize&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Get&lt;br /&gt;
|-&lt;br /&gt;
| 2 || Cancel&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [4.0.0+] GetErrorContext&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Official sw creates a container object for this using the output from the service commands, which contains the IAsyncValue object, and the Event with EventClearMode=0.&lt;br /&gt;
&lt;br /&gt;
* GetSize: No input, returns an output u64.&lt;br /&gt;
* Get: Takes a type-0x6 output buffer, no output. Official sw waits on the Event prior to using this cmd.&lt;br /&gt;
* Cancel: No input/output. Used by official sw when closing the object, when the serv-obj is initialized (after using the cmd, official sw will also wait on the Event). This cmd is also used in other official sw funcs.&lt;br /&gt;
* GetErrorContext: No input/output, takes a type-0x16 output buffer containing an [[Error_Applet#ErrorContext|ErrorContext]].&lt;br /&gt;
&lt;br /&gt;
= IAsyncResult =&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IAsyncResult&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || Get&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Cancel&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [4.0.0+] GetErrorContext&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Official sw creates a container object for this using the output from the service commands, which contains the IAsyncResult object, and the Event with EventClearMode=0.&lt;br /&gt;
&lt;br /&gt;
* Get: No input/output. Official sw waits on the Event prior to using this cmd.&lt;br /&gt;
* Cancel: No input/output. Used by official sw when closing the object, when the serv-obj is initialized (after using the cmd, official sw will also wait on the Event). This cmd is also used in other official sw funcs.&lt;br /&gt;
* GetErrorContext: No input/output, takes a type-0x16 output buffer containing an [[Error_Applet#ErrorContext|ErrorContext]].&lt;br /&gt;
&lt;br /&gt;
= ns:dev =&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IDevelopInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
[10.0.0+] Some of these cmds were replaced by the [[PGL_services|pgl]] system module.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [1.0.0-9.2.0] [[#LaunchProgram]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#TerminateProcess]]&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [1.0.0-9.2.0] [[#TerminateProgram]]&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [1.0.0-9.2.0] [[#GetShellEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 5 || [1.0.0-9.2.0] [[#GetShellEventInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 6 || [[#TerminateApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 7 || [1.0.0-9.2.0] [[#PrepareLaunchProgramFromHost]]&lt;br /&gt;
|-&lt;br /&gt;
| 8 || [10.0.0-17.0.1] [[#LaunchApplicationFromHost]] ([1.0.0-9.2.0] LaunchApplication)&lt;br /&gt;
|-&lt;br /&gt;
| 9 || [1.0.0-17.0.1] [[#LaunchApplicationWithStorageId]]&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [6.0.0-8.1.0] [[#IsSystemMemoryResourceLimitBoosted]]&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [6.0.0+] [[#GetRunningApplicationProcessId]]&lt;br /&gt;
|-&lt;br /&gt;
| 12 || [6.0.0+] [[#SetCurrentApplicationRightsEnvironmentCanBeActive]]&lt;br /&gt;
|-&lt;br /&gt;
| 13 || [9.0.0+] [[#CreateApplicationResource]]&lt;br /&gt;
|-&lt;br /&gt;
| 14 || [9.0.0+] [[#IsPreomia]]&lt;br /&gt;
|-&lt;br /&gt;
| 15 || [10.0.0-17.0.1] [[#GetApplicationProgramIdFromHost]]&lt;br /&gt;
|-&lt;br /&gt;
| 16 || [12.0.0+] RefreshCachedDebugValues&lt;br /&gt;
|-&lt;br /&gt;
| 17 || [12.0.0+] [[#PrepareLaunchApplicationFromHost]]&lt;br /&gt;
|-&lt;br /&gt;
| 18 || [12.0.0+] [[#GetLaunchEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 19 || [12.0.0+] [[#GetLaunchResult]]&lt;br /&gt;
|-&lt;br /&gt;
| 20 || [14.0.0+] GetProgramId&lt;br /&gt;
|-&lt;br /&gt;
| 21 || [18.0.0+] [[#PrepareLaunchApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 22 || [18.0.0+] [[#LaunchApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 23 || [18.0.0+] [[#GetProgramIdByApplicationLaunchInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 24 || [18.0.0+] DestroyApplicationLaunchPreparation&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== LaunchProgram ==&lt;br /&gt;
Wrapper for &amp;quot;pm:shell&amp;quot; [[Process_Manager_services#pm:shell|LaunchProcess]].&lt;br /&gt;
&lt;br /&gt;
== TerminateProcess ==&lt;br /&gt;
Wrapper for &amp;quot;pm:shell&amp;quot; [[Process_Manager_services#pm:shell|TerminateProcess]].&lt;br /&gt;
&lt;br /&gt;
== TerminateProgram ==&lt;br /&gt;
Wrapper for &amp;quot;pm:shell&amp;quot; [[Process_Manager_services#pm:shell|TerminateProgram]].&lt;br /&gt;
&lt;br /&gt;
== GetShellEvent ==&lt;br /&gt;
Wrapper for &amp;quot;pm:shell&amp;quot; [[Process_Manager_services#pm:shell|GetProcessEventHandle]].&lt;br /&gt;
&lt;br /&gt;
== GetShellEventInfo ==&lt;br /&gt;
Wrapper for &amp;quot;pm:shell&amp;quot; [[Process_Manager_services#pm:shell|GetProcessEventInfo]].&lt;br /&gt;
&lt;br /&gt;
== TerminateApplication ==&lt;br /&gt;
Calls &amp;quot;pm:shell&amp;quot; [[Process_Manager_services#pm:shell|GetApplicationProcessIdForShell]] and sends the ProcessId to [[Process_Manager_services#pm:shell|TerminateProcess]].&lt;br /&gt;
&lt;br /&gt;
== PrepareLaunchProgramFromHost ==&lt;br /&gt;
Takes a type-0x5 input buffer containing the [[Filesystem_services#FspPath|FspPath]], returns an output 0x10-byte struct.&lt;br /&gt;
&lt;br /&gt;
Calls [[NCM_services#IPathResolverForStorage|IPathResolverForStorage]] Set...NcaPath functions.&lt;br /&gt;
&lt;br /&gt;
== LaunchApplicationFromHost ==&lt;br /&gt;
Takes an input u32 [[Process_Manager_services#LaunchFlags|LaunchFlags]] and a type-0x5 input buffer containing the [[Filesystem_services#FspPath|FspPath]]. Returns an output u64 ProcessId.&lt;br /&gt;
&lt;br /&gt;
== LaunchApplicationWithStorageId ==&lt;br /&gt;
Takes 2 input u8 [[NCM_services#StorageId|StorageIds]], an u32 [[Process_Manager_services#LaunchFlags|LaunchFlags]], and an [[NCM_services#ApplicationId|ApplicationId]]. Returns an output u64 ProcessId.&lt;br /&gt;
&lt;br /&gt;
Launches an application title which is registered with NS.&lt;br /&gt;
&lt;br /&gt;
== IsSystemMemoryResourceLimitBoosted ==&lt;br /&gt;
No input. Returns a bool.&lt;br /&gt;
&lt;br /&gt;
== GetRunningApplicationProcessId ==&lt;br /&gt;
Returns an output u64 ProcessId.&lt;br /&gt;
&lt;br /&gt;
== SetCurrentApplicationRightsEnvironmentCanBeActive ==&lt;br /&gt;
Takes an input bool. No output.&lt;br /&gt;
&lt;br /&gt;
== CreateApplicationResource ==&lt;br /&gt;
Takes an input u32 (1 = Preomia/MicroApplication). Returns an [[#IApplicationResource]].&lt;br /&gt;
&lt;br /&gt;
== IsPreomia ==&lt;br /&gt;
Takes an input u64 [[NCM_services#ProgramId|ProgramId]]. Returns a bool.&lt;br /&gt;
&lt;br /&gt;
== GetApplicationProgramIdFromHost ==&lt;br /&gt;
Takes a type-0x5 input buffer containing the [[Filesystem_services#FspPath|FspPath]]. Returns an u64 [[NCM_services#ProgramId|ProgramId]].&lt;br /&gt;
&lt;br /&gt;
== PrepareLaunchApplicationFromHost ==&lt;br /&gt;
[18.0.0+] Now returns a total of 0x50 bytes of output.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] Now returns a total of 0x80 bytes of output.&lt;br /&gt;
&lt;br /&gt;
== GetLaunchEvent ==&lt;br /&gt;
[18.0.0+] Now takes a total of 0x50 bytes of input.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] Now takes a total of 0x80 bytes of input.&lt;br /&gt;
&lt;br /&gt;
== GetLaunchResult ==&lt;br /&gt;
[18.0.0+] Now takes a total of 0x50 bytes of input.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] Now takes a total of 0x80 bytes of input.&lt;br /&gt;
&lt;br /&gt;
== PrepareLaunchApplication ==&lt;br /&gt;
Takes a total of 0x10-bytes of input. Returns a total of 0x50-bytes of output.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] Now returns a total of 0x80-bytes of output.&lt;br /&gt;
&lt;br /&gt;
== LaunchApplication ==&lt;br /&gt;
Takes a total of 0x50-bytes of input. Returns a total of 8-bytes of output.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] Now takes a total of 0x80 bytes of input.&lt;br /&gt;
&lt;br /&gt;
== GetProgramIdByApplicationLaunchInfo ==&lt;br /&gt;
Takes a total of 0x50-bytes of input. Returns a total of 8-bytes of output.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] Now takes a total of 0x80 bytes of input.&lt;br /&gt;
&lt;br /&gt;
= acc:su =&lt;br /&gt;
This is &amp;quot;nn::account::IAccountServiceForAdministrator&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
[13.0.0+] This was moved from [[Account_services|account]].&lt;br /&gt;
&lt;br /&gt;
This is only available when the output from [[Process_Manager_services|pm:bm]] GetBootMode is Normal/Maintenance.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetUserCount ||&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GetUserExistence ||&lt;br /&gt;
|-&lt;br /&gt;
| 2 || ListAllUsers ||&lt;br /&gt;
|-&lt;br /&gt;
| 3 || ListOpenUsers ||&lt;br /&gt;
|-&lt;br /&gt;
| 4 || GetLastOpenedUser ||&lt;br /&gt;
|-&lt;br /&gt;
| 5 || GetProfile || Returns an [[#IProfile]].&lt;br /&gt;
|-&lt;br /&gt;
| 6 || [3.0.0+] GetProfileDigest ||&lt;br /&gt;
|-&lt;br /&gt;
| 50 || [[#IsUserRegistrationRequestPermitted]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 51 || TrySelectUserWithoutInteractionDeprecated ([1.0.0-18.1.0] [[#TrySelectUserWithoutInteraction]]) ||&lt;br /&gt;
|-&lt;br /&gt;
| 52 || [19.0.0+] TrySelectUserWithoutInteraction ||&lt;br /&gt;
|-&lt;br /&gt;
| 60 || [5.0.0-5.1.0] ListOpenContextStoredUsers ||&lt;br /&gt;
|-&lt;br /&gt;
| 99 || [6.0.0+] DebugActivateOpenContextRetention || No input, returns an [[#ISessionObject]].&lt;br /&gt;
|-&lt;br /&gt;
| 100 || GetUserRegistrationNotifier || Returns an [[#INotifier]].&lt;br /&gt;
|-&lt;br /&gt;
| 101 || GetUserStateChangeNotifier || Returns an [[#INotifier]].&lt;br /&gt;
|-&lt;br /&gt;
| 102 || GetBaasAccountManagerForSystemService || Returns an [[#IManagerForSystemService]].&lt;br /&gt;
|-&lt;br /&gt;
| 103 || GetBaasUserAvailabilityChangeNotifier || Returns an [[#INotifier]].&lt;br /&gt;
|-&lt;br /&gt;
| 104 || GetProfileUpdateNotifier || Returns an [[#INotifier]].&lt;br /&gt;
|-&lt;br /&gt;
| 105 || [4.0.0+] CheckNetworkServiceAvailabilityAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 106 || [9.0.0+] GetProfileSyncNotifier ||&lt;br /&gt;
|-&lt;br /&gt;
| 110 || StoreSaveDataThumbnail ||&lt;br /&gt;
|-&lt;br /&gt;
| 111 || ClearSaveDataThumbnail ||&lt;br /&gt;
|-&lt;br /&gt;
| 112 || LoadSaveDataThumbnail ||&lt;br /&gt;
|-&lt;br /&gt;
| 113 || [5.0.0+] GetSaveDataThumbnailExistence ||&lt;br /&gt;
|-&lt;br /&gt;
| 120 || [10.0.0+] ListOpenUsersInApplication ||&lt;br /&gt;
|-&lt;br /&gt;
| 130 || [6.0.0+] ActivateOpenContextRetention || Takes a total of 0x8-bytes of input, returns an [[#ISessionObject]].&lt;br /&gt;
|-&lt;br /&gt;
| 140 || [6.0.0+] ListQualifiedUsers || &lt;br /&gt;
|-&lt;br /&gt;
| 150 || [10.0.0-10.2.0] AuthenticateApplicationAsync || &lt;br /&gt;
|-&lt;br /&gt;
| 151 || [12.0.0+] EnsureSignedDeviceIdentifierCacheForNintendoAccountAsync || &lt;br /&gt;
|-&lt;br /&gt;
| 152 || [12.0.0+] LoadSignedDeviceIdentifierCacheForNintendoAccount ||&lt;br /&gt;
|-&lt;br /&gt;
| 170 || [13.0.0+] GetNasOp2MembershipStateChangeNotifier ||&lt;br /&gt;
|-&lt;br /&gt;
| 190 || [1.0.0-9.2.0] GetUserLastOpenedApplication ||&lt;br /&gt;
|-&lt;br /&gt;
| 191 || [7.0.0-19.0.1] UpdateNotificationReceiverInfo ([5.0.0-5.1.0] ActivateOpenContextHolder) ||&lt;br /&gt;
|-&lt;br /&gt;
| 200 || BeginUserRegistration ||&lt;br /&gt;
|-&lt;br /&gt;
| 201 || CompleteUserRegistration ||&lt;br /&gt;
|-&lt;br /&gt;
| 202 || CancelUserRegistration ||&lt;br /&gt;
|-&lt;br /&gt;
| 203 || DeleteUser ||&lt;br /&gt;
|-&lt;br /&gt;
| 204 || SetUserPosition ||&lt;br /&gt;
|-&lt;br /&gt;
| 205 || GetProfileEditor || Takes an input userID and returns an [[#IProfileEditor]].&lt;br /&gt;
|-&lt;br /&gt;
| 206 || CompleteUserRegistrationForcibly ||&lt;br /&gt;
|-&lt;br /&gt;
| 210 || [3.0.0+] CreateFloatingRegistrationRequest || Returns an [[#IFloatingRegistrationRequest]].&lt;br /&gt;
|-&lt;br /&gt;
| 211 || [8.0.0+] CreateProcedureToRegisterUserWithNintendoAccount || Takes a total of 0x4-bytes of input and a handle, returns an [[#IOAuthProcedureForUserRegistration]].&lt;br /&gt;
|-&lt;br /&gt;
| 212 || [8.0.0+] ResumeProcedureToRegisterUserWithNintendoAccount || Takes a total of 0x14-bytes of input and a handle, returns an [[#IOAuthProcedureForUserRegistration]].&lt;br /&gt;
|-&lt;br /&gt;
| 213 || [17.0.0+] CreateProcedureToCreateUserWithNintendoAccount ||&lt;br /&gt;
|-&lt;br /&gt;
| 214 || [17.0.0+] ResumeProcedureToCreateUserWithNintendoAccount ||&lt;br /&gt;
|-&lt;br /&gt;
| 215 || [17.0.0+] ResumeProcedureToCreateUserWithNintendoAccountAfterApplyResponse ||&lt;br /&gt;
|-&lt;br /&gt;
| 230 || AuthenticateServiceAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 250 || GetBaasAccountAdministrator || Returns an [[#IAdministrator]].&lt;br /&gt;
|-&lt;br /&gt;
| 251 || [20.0.0+] SynchronizeNetworkServiceAccountsSnapshotAsync ||&lt;br /&gt;
|-&lt;br /&gt;
| 290 || ProxyProcedureForGuestLoginWithNintendoAccount || Returns an [[#IOAuthProcedureForExternalNsa]] (formerly [[#IOAuthProcedureForGuestLogin]] with [1.0.0-2.3.0]).&lt;br /&gt;
|-&lt;br /&gt;
| 291 || [3.0.0+] ProxyProcedureForFloatingRegistrationWithNintendoAccount || Returns an [[#IOAuthProcedureForExternalNsa]].&lt;br /&gt;
|-&lt;br /&gt;
| 292 || [20.0.0+] ProxyProcedureForDeviceMigrationAuthenticatingOperatingUser ||&lt;br /&gt;
|-&lt;br /&gt;
| 293 || [20.0.0+] ProxyProcedureForDeviceMigrationDownload ||&lt;br /&gt;
|-&lt;br /&gt;
| 299 || SuspendBackgroundDaemon || Returns an [[#ISessionObject]].&lt;br /&gt;
|-&lt;br /&gt;
| 350 || [20.0.0+] CreateDeviceMigrationUserExportRequest ||&lt;br /&gt;
|-&lt;br /&gt;
| 351 || [20.0.0+] UploadNasCredential ||&lt;br /&gt;
|-&lt;br /&gt;
| 352 || [20.0.0+] CreateDeviceMigrationUserImportRequest ||&lt;br /&gt;
|-&lt;br /&gt;
| 353 || [20.0.0+] DeleteUserMigrationSaveData ||&lt;br /&gt;
|-&lt;br /&gt;
| 400 || [18.0.0+] SetPinCode ||&lt;br /&gt;
|-&lt;br /&gt;
| 401 || [18.0.0+] GetPinCodeLength ||&lt;br /&gt;
|-&lt;br /&gt;
| 402 || [18.0.0-19.0.1] GetPinCode ||&lt;br /&gt;
|-&lt;br /&gt;
| 403 || [20.0.0+] GetPinCodeParity ||&lt;br /&gt;
|-&lt;br /&gt;
| 404 || [20.0.0+] VerifyPinCode ||&lt;br /&gt;
|-&lt;br /&gt;
| 405 || [20.0.0+] IsPinCodeVerificationForbidden ||&lt;br /&gt;
|-&lt;br /&gt;
| 410 || [18.0.0+] GetPinCodeErrorCount ||&lt;br /&gt;
|-&lt;br /&gt;
| 411 || [18.0.0-19.0.1] ResetPinCodeErrorCount ||&lt;br /&gt;
|-&lt;br /&gt;
| 412 || [18.0.0-19.0.1] IncrementPinCodeErrorCount ||&lt;br /&gt;
|-&lt;br /&gt;
| 413 || [20.0.0+] SetPinCodeErrorCount ||&lt;br /&gt;
|-&lt;br /&gt;
| 420 || [19.0.0+] SetStartPenaltyTime || &lt;br /&gt;
|-&lt;br /&gt;
| 421 || [19.0.0+] GetStartPenaltyTime || &lt;br /&gt;
|-&lt;br /&gt;
| 900 || [13.0.0+] SetUserUnqualifiedForDebug ||&lt;br /&gt;
|-&lt;br /&gt;
| 901 || [13.0.0+] UnsetUserUnqualifiedForDebug ||&lt;br /&gt;
|-&lt;br /&gt;
| 902 || [13.0.0+] ListUsersUnqualifiedForDebug ||&lt;br /&gt;
|-&lt;br /&gt;
| 910 || [16.0.0+] RefreshFirmwareSettingsForDebug ||&lt;br /&gt;
|-&lt;br /&gt;
| 997 || [3.0.0+] DebugInvalidateTokenCacheForUser ||&lt;br /&gt;
|-&lt;br /&gt;
| 998 || DebugSetUserStateClose ||&lt;br /&gt;
|-&lt;br /&gt;
| 999 || DebugSetUserStateOpen ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[10.0.0+] DebugSetUserStateClose/DebugSetUserStateOpen now takes an additional 8-bytes of input.&lt;br /&gt;
&lt;br /&gt;
== IsUserRegistrationRequestPermitted ==&lt;br /&gt;
Takes a PID, an input u64 pid_reserved, and returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
== TrySelectUserWithoutInteraction ==&lt;br /&gt;
Takes an input u8 bool isNetworkServiceAccountRequired, returns an output Uid.&lt;br /&gt;
&lt;br /&gt;
== IManagerForSystemService ==&lt;br /&gt;
This is &amp;quot;nn::account::baas::IManagerForSystemService&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || CheckAvailability ||&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GetAccountId ||&lt;br /&gt;
|-&lt;br /&gt;
| 2 || EnsureIdTokenCacheAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [19.0.0+] LoadIdTokenCacheDeprecated ([1.0.0-18.1.0] LoadIdTokenCache) ||&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [19.0.0+] LoadIdTokenCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 100 || SetSystemProgramIdentification ||&lt;br /&gt;
|-&lt;br /&gt;
| 101 || RefreshNotificationTokenAsync || &lt;br /&gt;
|-&lt;br /&gt;
| 110 || GetServiceEntryRequirementCacheForLogin ||&lt;br /&gt;
|-&lt;br /&gt;
| 111 || InvalidateServiceEntryRequirementCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 113 || GetServiceEntryRequirementCacheForOnlinePlay || Takes a total of 0x8-bytes of input, returns a total of 0x4-bytes of output.&lt;br /&gt;
|-&lt;br /&gt;
| 120 || GetNintendoAccountId ||&lt;br /&gt;
|-&lt;br /&gt;
| 121 || CalculateNintendoAccountAuthenticationFingerprint ||&lt;br /&gt;
|-&lt;br /&gt;
| 130 || GetNintendoAccountUserResourceCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 131 || RefreshNintendoAccountUserResourceCacheAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 132 || RefreshNintendoAccountUserResourceCacheAsyncIfSecondsElapsed || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 133 || GetNintendoAccountVerificationUrlCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 134 || RefreshNintendoAccountVerificationUrlCacheAsync ||&lt;br /&gt;
|-&lt;br /&gt;
| 135 || RefreshNintendoAccountVerificationUrlCacheAsyncIfSecondsElapsed ||&lt;br /&gt;
|-&lt;br /&gt;
| 136 || [19.0.0+] GetNintendoAccountUserResourceCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 140 || GetNetworkServiceLicenseCache || &lt;br /&gt;
|-&lt;br /&gt;
| 141 || RefreshNetworkServiceLicenseCacheAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 142 || RefreshNetworkServiceLicenseCacheAsyncIfSecondsElapsed || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 143 || [15.0.0+] GetNetworkServiceLicenseCacheEx ||&lt;br /&gt;
|-&lt;br /&gt;
| 150 || CreateAuthorizationRequest || Returns an [[#IAuthorizationRequest]].&lt;br /&gt;
|-&lt;br /&gt;
| 151 || [22.5.0+] || &lt;br /&gt;
|-&lt;br /&gt;
| 152 || [22.5.0+] || &lt;br /&gt;
|-&lt;br /&gt;
| 153 || [22.5.0+] || &lt;br /&gt;
|-&lt;br /&gt;
| 160 || [15.0.0+] RequiresUpdateNetworkServiceAccountIdTokenCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 161 || [16.0.0+] RequireReauthenticationOfNetworkServiceAccount ||&lt;br /&gt;
|-&lt;br /&gt;
| 180 || [18.0.0-19.0.1] GetRequestForNintendoAccountReauthentication ||&lt;br /&gt;
|-&lt;br /&gt;
| 181 || [20.0.0+] CreateProcedureToReauthenticateNintendoAccount ||&lt;br /&gt;
|-&lt;br /&gt;
| 182 || [20.0.0+] ResumeProcedureToReauthenticateNintendoAccount ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IFloatingRegistrationRequest ==&lt;br /&gt;
This is &amp;quot;nn::account::baas::IFloatingRegistrationRequest&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
Added with [3.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetSessionId ||&lt;br /&gt;
|-&lt;br /&gt;
| 12 || GetAccountId ||&lt;br /&gt;
|-&lt;br /&gt;
| 13 || GetLinkedNintendoAccountId ||&lt;br /&gt;
|-&lt;br /&gt;
| 14 || GetNickname ||&lt;br /&gt;
|-&lt;br /&gt;
| 15 || GetProfileImage ||&lt;br /&gt;
|-&lt;br /&gt;
| 16 || [18.0.0+] GetProfileLargeImage ||&lt;br /&gt;
|-&lt;br /&gt;
| 21 || LoadIdTokenCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 100 || RegisterUser ([1.0.0-3.0.2] RegisterAsync) || [1.0.0-3.0.2] Used to return an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 101 || RegisterUserWithUid ([1.0.0-3.0.2] RegisterWithUidAsync) || [1.0.0-3.0.2] Used to return an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 102 || [4.0.0+] RegisterNetworkServiceAccountAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 103 || [4.0.0+] RegisterNetworkServiceAccountWithUidAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 110 || SetSystemProgramIdentification ||&lt;br /&gt;
|-&lt;br /&gt;
| 111 || EnsureIdTokenCacheAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IAdministrator ==&lt;br /&gt;
This is &amp;quot;nn::account::baas::IAdministrator&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || CheckAvailability ||&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GetAccountId ||&lt;br /&gt;
|-&lt;br /&gt;
| 2 || EnsureIdTokenCacheAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [19.0.0+] LoadIdTokenCacheDeprecated ([1.0.0-18.1.0] LoadIdTokenCache) ||&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [19.0.0+] LoadIdTokenCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 100 || SetSystemProgramIdentification ||&lt;br /&gt;
|-&lt;br /&gt;
| 101 || [7.0.0+] RefreshNotificationTokenAsync&lt;br /&gt;
|-&lt;br /&gt;
| 110 || [4.0.0+] GetServiceEntryRequirementCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 111 || [4.0.0+] InvalidateServiceEntryRequirementCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 112 || [4.0.0-6.2.0] InvalidateTokenCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 113 || [6.1.0+] GetServiceEntryRequirementCacheForOnlinePlay || Takes a total of 0x8-bytes of input, returns a total of 0x4-bytes of output.&lt;br /&gt;
|-&lt;br /&gt;
| 120 || GetNintendoAccountId ||&lt;br /&gt;
|-&lt;br /&gt;
| 121 || [9.0.0+] CalculateNintendoAccountAuthenticationFingerprint ||&lt;br /&gt;
|-&lt;br /&gt;
| 130 || GetNintendoAccountUserResourceCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 131 || RefreshNintendoAccountUserResourceCacheAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 132 || RefreshNintendoAccountUserResourceCacheAsyncIfSecondsElapsed || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 133 || [9.0.0+] GetNintendoAccountVerificationUrlCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 134 || [9.0.0+] RefreshNintendoAccountVerificationUrlCacheAsync ||&lt;br /&gt;
|-&lt;br /&gt;
| 135 || [9.0.0+] RefreshNintendoAccountVerificationUrlCacheAsyncIfSecondsElapsed ||&lt;br /&gt;
|-&lt;br /&gt;
| 136 || [19.0.0+] GetNintendoAccountUserResourceCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 140 || [5.0.0+] GetNetworkServiceLicenseCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 141 || [5.0.0+] RefreshNetworkServiceLicenseCacheAsync ||&lt;br /&gt;
|-&lt;br /&gt;
| 142 || [5.0.0+] RefreshNetworkServiceLicenseCacheAsyncIfSecondsElapsed ||&lt;br /&gt;
|-&lt;br /&gt;
| 143 || [15.0.0+] GetNetworkServiceLicenseCacheEx ||&lt;br /&gt;
|-&lt;br /&gt;
| 150 || CreateAuthorizationRequest || Returns an [[#IAuthorizationRequest]].&lt;br /&gt;
|-&lt;br /&gt;
| 151 || [22.5.0+] || &lt;br /&gt;
|-&lt;br /&gt;
| 152 || [22.5.0+] || &lt;br /&gt;
|-&lt;br /&gt;
| 153 || [22.5.0+] || &lt;br /&gt;
|-&lt;br /&gt;
| 160 || [15.0.0+] RequiresUpdateNetworkServiceAccountIdTokenCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 161 || [16.0.0+] RequireReauthenticationOfNetworkServiceAccount ||&lt;br /&gt;
|-&lt;br /&gt;
| 180 || [18.0.0-19.0.1] GetRequestForNintendoAccountReauthentication ||&lt;br /&gt;
|-&lt;br /&gt;
| 181 || [20.0.0+] CreateProcedureToReauthenticateNintendoAccount ||&lt;br /&gt;
|-&lt;br /&gt;
| 182 || [20.0.0+] ResumeProcedureToReauthenticateNintendoAccount ||&lt;br /&gt;
|-&lt;br /&gt;
| 200 || IsRegistered ||&lt;br /&gt;
|-&lt;br /&gt;
| 201 || RegisterAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 202 || UnregisterAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 203 || DeleteRegistrationInfoLocally ||&lt;br /&gt;
|-&lt;br /&gt;
| 204 || [19.0.0-19.0.1] UnregisterDeviceAsync ||&lt;br /&gt;
|-&lt;br /&gt;
| 220 || SynchronizeProfileAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 221 || UploadProfileAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 222 || SynchronizeProfileAsyncIfSecondsElapsed || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 223 || [19.0.0+] DownloadProfileAsync ||&lt;br /&gt;
|-&lt;br /&gt;
| 250 || IsLinkedWithNintendoAccount ||&lt;br /&gt;
|-&lt;br /&gt;
| 251 || CreateProcedureToLinkWithNintendoAccount || Returns an [[#IOAuthProcedureForNintendoAccountLinkage]].&lt;br /&gt;
|-&lt;br /&gt;
| 252 || ResumeProcedureToLinkWithNintendoAccount || Returns an [[#IOAuthProcedureForNintendoAccountLinkage]].&lt;br /&gt;
|-&lt;br /&gt;
| 255 || CreateProcedureToUpdateLinkageStateOfNintendoAccount || Returns an [[#IOAuthProcedure]].&lt;br /&gt;
|-&lt;br /&gt;
| 256 || ResumeProcedureToUpdateLinkageStateOfNintendoAccount || Returns an [[#IOAuthProcedure]].&lt;br /&gt;
|-&lt;br /&gt;
| 260 || [3.0.0+] CreateProcedureToLinkNnidWithNintendoAccount || Returns an [[#IOAuthProcedure]].&lt;br /&gt;
|-&lt;br /&gt;
| 261 || [3.0.0+] ResumeProcedureToLinkNnidWithNintendoAccount || Returns an [[#IOAuthProcedure]].&lt;br /&gt;
|-&lt;br /&gt;
| 280 || ProxyProcedureToAcquireApplicationAuthorizationForNintendoAccount || Returns an [[#IOAuthProcedure]].&lt;br /&gt;
|-&lt;br /&gt;
| 290 || [8.0.0+] GetRequestForNintendoAccountUserResourceView || &lt;br /&gt;
|-&lt;br /&gt;
| 300 || [6.0.0+] TryRecoverNintendoAccountUserStateAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 400 || [6.1.0+] IsServiceEntryRequirementCacheRefreshRequiredForOnlinePlay || Takes a total of 0x8-bytes of input, returns an output u8.&lt;br /&gt;
|-&lt;br /&gt;
| 401 || [6.1.0+] RefreshServiceEntryRequirementCacheForOnlinePlayAsync || Takes a total of 0x8-bytes of input, returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 900 || [9.0.0+] GetAuthenticationInfoForWin ||&lt;br /&gt;
|-&lt;br /&gt;
| 901 || [9.0.0+] ImportAsyncForWin ||&lt;br /&gt;
|-&lt;br /&gt;
| 997 || DebugUnlinkNintendoAccountAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 998 || DebugSetAvailabilityErrorDetail ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IAuthorizationRequest ==&lt;br /&gt;
This is &amp;quot;nn::account::nas::IAuthorizationRequest&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetSessionId ||&lt;br /&gt;
|-&lt;br /&gt;
| 10 || InvokeWithoutInteractionAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 19 || IsAuthorized ||&lt;br /&gt;
|-&lt;br /&gt;
| 20 || GetAuthorizationCode ||&lt;br /&gt;
|-&lt;br /&gt;
| 21 || GetIdToken ||&lt;br /&gt;
|-&lt;br /&gt;
| 22 || GetState ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IOAuthProcedure ==&lt;br /&gt;
This is &amp;quot;nn::account::http::IOAuthProcedure&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || PrepareAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GetRequest ||&lt;br /&gt;
|-&lt;br /&gt;
| 2 || ApplyResponse ||&lt;br /&gt;
|-&lt;br /&gt;
| 3 || ApplyResponseAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 10 || Suspend ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IOAuthProcedureForExternalNsa ==&lt;br /&gt;
This is &amp;quot;nn::account::nas::IOAuthProcedureForExternalNsa&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
Added with [3.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || PrepareAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GetRequest ||&lt;br /&gt;
|-&lt;br /&gt;
| 2 || ApplyResponse ||&lt;br /&gt;
|-&lt;br /&gt;
| 3 || ApplyResponseAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 10 || Suspend ||&lt;br /&gt;
|-&lt;br /&gt;
| 100 || GetAccountId ||&lt;br /&gt;
|-&lt;br /&gt;
| 101 || GetLinkedNintendoAccountId ||&lt;br /&gt;
|-&lt;br /&gt;
| 102 || GetNickname ||&lt;br /&gt;
|-&lt;br /&gt;
| 103 || GetProfileImage ||&lt;br /&gt;
|-&lt;br /&gt;
| 104 || [18.0.0+] GetProfileLargeImage ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IOAuthProcedureForNintendoAccountLinkage ==&lt;br /&gt;
This is &amp;quot;nn::account::nas::IOAuthProcedureForNintendoAccountLinkage&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || PrepareAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GetRequest ||&lt;br /&gt;
|-&lt;br /&gt;
| 2 || ApplyResponse ||&lt;br /&gt;
|-&lt;br /&gt;
| 3 || ApplyResponseAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 10 || Suspend ||&lt;br /&gt;
|-&lt;br /&gt;
| 100 || GetRequestWithTheme ||&lt;br /&gt;
|-&lt;br /&gt;
| 101 || IsNetworkServiceAccountReplaced ||&lt;br /&gt;
|-&lt;br /&gt;
| 199 || [2.0.0-5.1.0] GetUrlForIntroductionOfExtraMembership ||&lt;br /&gt;
|-&lt;br /&gt;
| 200 || [16.0.0+] ApplyAsyncWithAuthorizedToken ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== INotifier ==&lt;br /&gt;
This is &amp;quot;nn::account::detail::INotifier&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetSystemEvent&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IProfile ==&lt;br /&gt;
This is &amp;quot;nn::account::profile::IProfile&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#Get]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#GetBase]]&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [[#GetImageSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [[#LoadImage]]&lt;br /&gt;
|-&lt;br /&gt;
| 20 || [18.0.0+] GetLargeImageSize&lt;br /&gt;
|-&lt;br /&gt;
| 21 || [18.0.0+] LoadLargeImage&lt;br /&gt;
|-&lt;br /&gt;
| 30 || [18.0.0+] GetImageId&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Get ===&lt;br /&gt;
Takes an output type-0x1A buffer for [[#UserData]], returns an output [[#ProfileBase]].&lt;br /&gt;
&lt;br /&gt;
=== GetBase ===&lt;br /&gt;
No input, returns an output [[#ProfileBase]].&lt;br /&gt;
&lt;br /&gt;
=== GetImageSize ===&lt;br /&gt;
No input, returns an output u32 for the size of the image buffer.&lt;br /&gt;
&lt;br /&gt;
=== LoadImage === &lt;br /&gt;
Takes an output type-0x6 buffer, returns the same output u32 as [[#GetImageSize]].&lt;br /&gt;
&lt;br /&gt;
The output buffer contains the JPEG profile image icon. This is valid for both Miis and character icons.&lt;br /&gt;
&lt;br /&gt;
== IProfileEditor ==&lt;br /&gt;
This is &amp;quot;nn::account::profile::IProfileEditor&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#Get]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#GetBase]]&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [[#GetImageSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [[#LoadImage]]&lt;br /&gt;
|-&lt;br /&gt;
| 20 || [18.0.0+] GetLargeImageSize&lt;br /&gt;
|-&lt;br /&gt;
| 21 || [18.0.0+] LoadLargeImage&lt;br /&gt;
|-&lt;br /&gt;
| 30 || [18.0.0+] GetImageId&lt;br /&gt;
|-&lt;br /&gt;
| 100 || [[#Store]]&lt;br /&gt;
|-&lt;br /&gt;
| 101 || [[#StoreWithImage]]&lt;br /&gt;
|-&lt;br /&gt;
| 110 || [18.0.0+] StoreWithLargeImage&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Store ===&lt;br /&gt;
Takes a [[#ProfileBase]] and an input type-0x19 buffer for [[#UserData]].&lt;br /&gt;
&lt;br /&gt;
=== StoreWithImage ===&lt;br /&gt;
Takes a [[#ProfileBase]], an input type-0x19 buffer for [[#UserData]], and an input type-0x5 buffer.&lt;br /&gt;
&lt;br /&gt;
== IAsyncContext ==&lt;br /&gt;
This is &amp;quot;nn::account::detail::IAsyncContext&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetSystemEvent&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Cancel&lt;br /&gt;
|-&lt;br /&gt;
| 2 || HasDone&lt;br /&gt;
|-&lt;br /&gt;
| 3 || GetResult&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== ISessionObject ==&lt;br /&gt;
This is &amp;quot;nn::account::detail::ISessionObject&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 999 || Dummy&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= acc:u0 =&lt;br /&gt;
This is &amp;quot;nn::account::IAccountServiceForApplication&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
[13.0.0+] This was moved from [[Account_services|account]].&lt;br /&gt;
&lt;br /&gt;
This is only available when the output from [[Process_Manager_services|pm:bm]] GetBootMode is Normal/Maintenance.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetUserCount ||&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GetUserExistence ||&lt;br /&gt;
|-&lt;br /&gt;
| 2 || ListAllUsers ||&lt;br /&gt;
|-&lt;br /&gt;
| 3 || ListOpenUsers ||&lt;br /&gt;
|-&lt;br /&gt;
| 4 || GetLastOpenedUser ||&lt;br /&gt;
|-&lt;br /&gt;
| 5 || GetProfile || Takes an input userID, returns an [[#IProfile]].&lt;br /&gt;
|-&lt;br /&gt;
| 6 || [3.0.0+] GetProfileDigest ||&lt;br /&gt;
|-&lt;br /&gt;
| 50 || [[#IsUserRegistrationRequestPermitted]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 51 || TrySelectUserWithoutInteractionDeprecated ([1.0.0-18.1.0] [[#TrySelectUserWithoutInteraction]]) ||&lt;br /&gt;
|-&lt;br /&gt;
| 52 || [19.0.0+] TrySelectUserWithoutInteraction ||&lt;br /&gt;
|-&lt;br /&gt;
| 60 || [5.0.0-5.1.0] ListOpenContextStoredUsers ||&lt;br /&gt;
|-&lt;br /&gt;
| 99 || [6.0.0+] DebugActivateOpenContextRetention || No input, returns an [[#ISessionObject]].&lt;br /&gt;
|-&lt;br /&gt;
| 100 || [[#InitializeApplicationInfoV0]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 101 || GetBaasAccountManagerForApplication || Takes an input userID, returns an [[#IManagerForApplication]].&lt;br /&gt;
|-&lt;br /&gt;
| 102 || AuthenticateApplicationAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 103 || [4.0.0+] CheckNetworkServiceAvailabilityAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 110 || StoreSaveDataThumbnail ||&lt;br /&gt;
|-&lt;br /&gt;
| 111 || ClearSaveDataThumbnail ||&lt;br /&gt;
|-&lt;br /&gt;
| 120 || CreateGuestLoginRequest || Returns an [[#IGuestLoginRequest]].&lt;br /&gt;
|-&lt;br /&gt;
| 130 || [5.0.0+] LoadOpenContext ||&lt;br /&gt;
|-&lt;br /&gt;
| 131 || [6.0.0+] ListOpenContextStoredUsers || &lt;br /&gt;
|-&lt;br /&gt;
| 140 || [6.0.0+] [[#InitializeApplicationInfoV1]] || &lt;br /&gt;
|-&lt;br /&gt;
| 141 || [6.0.0+] ListQualifiedUsers || &lt;br /&gt;
|-&lt;br /&gt;
| 150 || [6.0.0+] IsUserAccountSwitchLocked || &lt;br /&gt;
|-&lt;br /&gt;
| 160 || [13.0.0+] InitializeApplicationInfoV2 || &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
InitializeApplicationInfo* is used by the user-process during service init.&lt;br /&gt;
&lt;br /&gt;
== InitializeApplicationInfoV0 ==&lt;br /&gt;
Takes a PID and an input u64 pid_placeholder, no output.&lt;br /&gt;
&lt;br /&gt;
== InitializeApplicationInfoV1 ==&lt;br /&gt;
Takes a PID and an input u64 pid_placeholder, no output.&lt;br /&gt;
&lt;br /&gt;
== IGuestLoginRequest ==&lt;br /&gt;
This is &amp;quot;nn::account::baas::IGuestLoginRequest&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetSessionId&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [1.0.0-2.3.0] &lt;br /&gt;
|-&lt;br /&gt;
| 12 || GetAccountId&lt;br /&gt;
|-&lt;br /&gt;
| 13 || GetLinkedNintendoAccountId&lt;br /&gt;
|-&lt;br /&gt;
| 14 || GetNickname&lt;br /&gt;
|-&lt;br /&gt;
| 15 || GetProfileImage&lt;br /&gt;
|-&lt;br /&gt;
| 16 || [18.0.0+] GetProfileLargeImage&lt;br /&gt;
|-&lt;br /&gt;
| 21 || [3.0.0+] LoadIdTokenCache&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IManagerForApplication ==&lt;br /&gt;
This is &amp;quot;nn::account::baas::IManagerForApplication&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || CheckAvailability ||&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GetAccountId ||&lt;br /&gt;
|-&lt;br /&gt;
| 2 || EnsureIdTokenCacheAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 3 || LoadIdTokenCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 130 || GetNintendoAccountUserResourceCacheForApplication ||&lt;br /&gt;
|-&lt;br /&gt;
| 150 || CreateAuthorizationRequest || Returns an [[#IAuthorizationRequest]].&lt;br /&gt;
|-&lt;br /&gt;
| 160 || [5.0.0+] StoreOpenContext ||&lt;br /&gt;
|-&lt;br /&gt;
| 170 || [13.0.0+] EnsureIdTokenCacheForOnlinePlayAsync ([6.0.0-12.1.0] LoadNetworkServiceLicenseKindAsync) || No input, returns an [[#IAsyncContextForLoginForOnlinePlay]] ([6.0.0-12.1.0] [[#IAsyncNetworkServiceLicenseKindContext]]).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IAsyncNetworkServiceLicenseKindContext ==&lt;br /&gt;
This is &amp;quot;nn::account::detail::IAsyncNetworkServiceLicenseKindContext&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [6.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetSystemEvent || &lt;br /&gt;
|-&lt;br /&gt;
| 1 || Cancel || &lt;br /&gt;
|-&lt;br /&gt;
| 2 || HasDone || &lt;br /&gt;
|-&lt;br /&gt;
| 3 || GetResult || &lt;br /&gt;
|-&lt;br /&gt;
| 100 || GetNetworkServiceLicenseKind || &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IAsyncContextForLoginForOnlinePlay ==&lt;br /&gt;
This is &amp;quot;nn::account::baas::IAsyncContextForLoginForOnlinePlay&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [13.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetSystemEvent || &lt;br /&gt;
|-&lt;br /&gt;
| 1 || Cancel || &lt;br /&gt;
|-&lt;br /&gt;
| 2 || HasDone || &lt;br /&gt;
|-&lt;br /&gt;
| 3 || GetResult || &lt;br /&gt;
|-&lt;br /&gt;
| 100 || GetNetworkServiceLicenseInfoForOnlinePlay || &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= acc:u1 =&lt;br /&gt;
This is &amp;quot;nn::account::IAccountServiceForSystemService&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
[13.0.0+] This was moved from [[Account_services|account]].&lt;br /&gt;
&lt;br /&gt;
This is only available when the output from [[Process_Manager_services|pm:bm]] GetBootMode is Normal/Maintenance.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetUserCount ||&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GetUserExistence ||&lt;br /&gt;
|-&lt;br /&gt;
| 2 || ListAllUsers ||&lt;br /&gt;
|-&lt;br /&gt;
| 3 || ListOpenUsers ||&lt;br /&gt;
|-&lt;br /&gt;
| 4 || GetLastOpenedUser ||&lt;br /&gt;
|-&lt;br /&gt;
| 5 || GetProfile || Returns an [[#IProfile]].&lt;br /&gt;
|-&lt;br /&gt;
| 6 || [3.0.0+] GetProfileDigest ||&lt;br /&gt;
|-&lt;br /&gt;
| 50 || [[#IsUserRegistrationRequestPermitted]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 51 || TrySelectUserWithoutInteractionDeprecated ([1.0.0-18.1.0] [[#TrySelectUserWithoutInteraction]]) ||&lt;br /&gt;
|-&lt;br /&gt;
| 52 || [19.0.0+] TrySelectUserWithoutInteraction ||&lt;br /&gt;
|-&lt;br /&gt;
| 60 || [5.0.0-5.1.0] ListOpenContextStoredUsers ||&lt;br /&gt;
|-&lt;br /&gt;
| 99 || [6.0.0+] DebugActivateOpenContextRetention || No input, returns an [[#ISessionObject]].&lt;br /&gt;
|-&lt;br /&gt;
| 100 || GetUserRegistrationNotifier || Returns an [[#INotifier]].&lt;br /&gt;
|-&lt;br /&gt;
| 101 || GetUserStateChangeNotifier || Returns an [[#INotifier]].&lt;br /&gt;
|-&lt;br /&gt;
| 102 || GetBaasAccountManagerForSystemService || Returns an [[#IManagerForSystemService]].&lt;br /&gt;
|-&lt;br /&gt;
| 103 || GetBaasUserAvailabilityChangeNotifier || Returns an [[#INotifier]].&lt;br /&gt;
|-&lt;br /&gt;
| 104 || GetProfileUpdateNotifier || Returns an [[#INotifier]].&lt;br /&gt;
|-&lt;br /&gt;
| 105 || [4.0.0+] CheckNetworkServiceAvailabilityAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 106 || [9.0.0+] GetProfileSyncNotifier ||&lt;br /&gt;
|-&lt;br /&gt;
| 110 || StoreSaveDataThumbnail ||&lt;br /&gt;
|-&lt;br /&gt;
| 111 || ClearSaveDataThumbnail ||&lt;br /&gt;
|-&lt;br /&gt;
| 112 || LoadSaveDataThumbnail ||&lt;br /&gt;
|-&lt;br /&gt;
| 113 || [5.0.0+] GetSaveDataThumbnailExistence ||&lt;br /&gt;
|-&lt;br /&gt;
| 120 || [10.0.0+] ListOpenUsersInApplication ||&lt;br /&gt;
|-&lt;br /&gt;
| 130 || [6.0.0+] ActivateOpenContextRetention || Takes a total of 0x8-bytes of input, returns an [[#ISessionObject]].&lt;br /&gt;
|-&lt;br /&gt;
| 140 || [6.0.0+] ListQualifiedUsers || &lt;br /&gt;
|-&lt;br /&gt;
| 150 || [10.0.0-10.2.0] AuthenticateApplicationAsync ||&lt;br /&gt;
|-&lt;br /&gt;
| 151 || [12.0.0+] EnsureSignedDeviceIdentifierCacheForNintendoAccountAsync || &lt;br /&gt;
|-&lt;br /&gt;
| 152 || [12.0.0+] LoadSignedDeviceIdentifierCacheForNintendoAccount ||&lt;br /&gt;
|-&lt;br /&gt;
| 170 || [13.0.0+] GetNasOp2MembershipStateChangeNotifier ||&lt;br /&gt;
|-&lt;br /&gt;
| 190 || [1.0.0-9.2.0] GetUserLastOpenedApplication ||&lt;br /&gt;
|-&lt;br /&gt;
| 191 || [7.0.0-19.0.1] UpdateNotificationReceiverInfo ([5.0.0-5.1.0] ActivateOpenContextHolder) ||&lt;br /&gt;
|-&lt;br /&gt;
| 401 || [18.0.0+] GetPinCodeLength ||&lt;br /&gt;
|-&lt;br /&gt;
| 402 || [18.0.0-19.0.1] GetPinCode ||&lt;br /&gt;
|-&lt;br /&gt;
| 403 || [20.0.0+] GetPinCodeParity ||&lt;br /&gt;
|-&lt;br /&gt;
| 404 || [20.0.0+] VerifyPinCode ||&lt;br /&gt;
|-&lt;br /&gt;
| 405 || [20.0.0+] IsPinCodeVerificationForbidden ||&lt;br /&gt;
|-&lt;br /&gt;
| 997 || [3.0.0+] DebugInvalidateTokenCacheForUser ||&lt;br /&gt;
|-&lt;br /&gt;
| 998 || DebugSetUserStateClose ||&lt;br /&gt;
|-&lt;br /&gt;
| 999 || DebugSetUserStateOpen ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[10.0.0+] DebugSetUserStateClose/DebugSetUserStateOpen now takes an additional 8-bytes of input. &lt;br /&gt;
&lt;br /&gt;
== IOAuthProcedureForUserRegistration ==&lt;br /&gt;
This is &amp;quot;nn::account::nas::IOAuthProcedureForUserRegistration&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [8.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || PrepareAsync || No input, returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GetRequest || &lt;br /&gt;
|-&lt;br /&gt;
| 2 || ApplyResponse || &lt;br /&gt;
|-&lt;br /&gt;
| 3 || ApplyResponseAsync || Takes a type-0x9 input buffer, returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 10 || Suspend || &lt;br /&gt;
|-&lt;br /&gt;
| 100 || GetAccountId || &lt;br /&gt;
|-&lt;br /&gt;
| 101 || GetLinkedNintendoAccountId || &lt;br /&gt;
|-&lt;br /&gt;
| 102 || GetNickname || &lt;br /&gt;
|-&lt;br /&gt;
| 103 || GetProfileImage || &lt;br /&gt;
|-&lt;br /&gt;
| 104 || [18.0.0+] GetProfileLargeImage || &lt;br /&gt;
|-&lt;br /&gt;
| 110 || RegisterUserAsync || No input, returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 111 || GetUid || &lt;br /&gt;
|-&lt;br /&gt;
| 200 || [17.0.0+] ApplyResponseForUserCreationAsync || &lt;br /&gt;
|-&lt;br /&gt;
| 205 || [17.0.0+] SuspendAfterApplyResponse || &lt;br /&gt;
|-&lt;br /&gt;
| 210 || [17.0.0+] IsProfileAvailable || &lt;br /&gt;
|-&lt;br /&gt;
| 220 || [17.0.0+] RegisterUserAsyncWithoutProfile || &lt;br /&gt;
|-&lt;br /&gt;
| 221 || [17.0.0+] RegisterUserWithProfileAsync || &lt;br /&gt;
|-&lt;br /&gt;
| 230 || [18.0.0+] RegisterUserWithLargeImageProfileAsync || &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationRecord =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationRecord&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0&lt;br /&gt;
| 0x8&lt;br /&gt;
| [[NCM_services#ApplicationId|Id]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x8&lt;br /&gt;
| 0x1&lt;br /&gt;
| [[#ApplicationEvent|LastEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x9&lt;br /&gt;
| 0x1&lt;br /&gt;
| Attributes&lt;br /&gt;
|-&lt;br /&gt;
| 0xA&lt;br /&gt;
| 0x6&lt;br /&gt;
| Reserved&lt;br /&gt;
|-&lt;br /&gt;
| 0x10&lt;br /&gt;
| 0x8&lt;br /&gt;
| LastUpdated&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationEvent =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationEvent&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || Launched&lt;br /&gt;
|-&lt;br /&gt;
| 1 || LocalInstalled&lt;br /&gt;
|-&lt;br /&gt;
| 2 || DownloadStarted&lt;br /&gt;
|-&lt;br /&gt;
| 3 || GameCardInserted&lt;br /&gt;
|-&lt;br /&gt;
| 4 || Touched&lt;br /&gt;
|-&lt;br /&gt;
| 5 || &lt;br /&gt;
|-&lt;br /&gt;
| 6 || &lt;br /&gt;
|-&lt;br /&gt;
| 7 || &lt;br /&gt;
|-&lt;br /&gt;
| 8 || &lt;br /&gt;
|-&lt;br /&gt;
| 9 || &lt;br /&gt;
|-&lt;br /&gt;
| 10 || &lt;br /&gt;
|-&lt;br /&gt;
| 11 || &lt;br /&gt;
|-&lt;br /&gt;
| 12 || &lt;br /&gt;
|-&lt;br /&gt;
| 13 || &lt;br /&gt;
|-&lt;br /&gt;
| 14 || &lt;br /&gt;
|-&lt;br /&gt;
| 15 || &lt;br /&gt;
|-&lt;br /&gt;
| 16 || &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationControlSource =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationControlSource&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0&lt;br /&gt;
| CacheOnly&lt;br /&gt;
|-&lt;br /&gt;
| 1&lt;br /&gt;
| Storage&lt;br /&gt;
|-&lt;br /&gt;
| 2&lt;br /&gt;
| StorageOnly&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationContentMetaStatus =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationContentMetaStatus&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0&lt;br /&gt;
| 0x1&lt;br /&gt;
| [[NCM_services#ContentMetaType|Type]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x1&lt;br /&gt;
| 0x1&lt;br /&gt;
| [[NCM_services#StorageId|InstalledStorage]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x2&lt;br /&gt;
| 0x1&lt;br /&gt;
| [[#ContentMetaRightsCheck|RightsCheck]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x3&lt;br /&gt;
| 0x1&lt;br /&gt;
| Reserved&lt;br /&gt;
|-&lt;br /&gt;
| 0x4&lt;br /&gt;
| 0x4&lt;br /&gt;
| Version&lt;br /&gt;
|-&lt;br /&gt;
| 0x8&lt;br /&gt;
| 0x8&lt;br /&gt;
| [[NCM_services#ApplicationId|Id]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ContentMetaRightsCheck =&lt;br /&gt;
This is &amp;quot;nn::ns::ContentMetaRightsCheck&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0&lt;br /&gt;
| NotChecked&lt;br /&gt;
|-&lt;br /&gt;
| 1&lt;br /&gt;
| NotNeeded&lt;br /&gt;
|-&lt;br /&gt;
| 2&lt;br /&gt;
| CommonRights&lt;br /&gt;
|-&lt;br /&gt;
| 3&lt;br /&gt;
| PersonalizedRights&lt;br /&gt;
|-&lt;br /&gt;
| 4&lt;br /&gt;
| NoRights&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= VersionListData =&lt;br /&gt;
This is &amp;quot;nn::ns::VersionListData&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
= ApplicationUpdateInfo =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationUpdateInfo&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || UpToDate&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Updatable&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationOccupiedSize =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationOccupiedSize&amp;quot;. This is a 0x80-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x20 * 4 || Array of [[#ApplicationOccupiedSizeEntity]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationOccupiedSizeEntity =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationOccupiedSizeEntity&amp;quot;. This is a 0x20-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x1 || [[NCM_services#StorageId|StorageId]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x1 || 0x7 || Reserved&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x8 || AppSize&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x8 || PatchSize&lt;br /&gt;
|-&lt;br /&gt;
| 0x18 || 0x8 || AocSize&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ProgressForDeleteUserSaveDataAll =&lt;br /&gt;
This is &amp;quot;nn::ns::detail::ProgressForDeleteUserSaveDataAll&amp;quot;. This is a 0x28-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x8 || StartedAt&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x4 || Count&lt;br /&gt;
|-&lt;br /&gt;
| 0xC || 0x4 || Reserved&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x8 || SizeInBytes&lt;br /&gt;
|-&lt;br /&gt;
| 0x18 || 0x1 || IsSystem&lt;br /&gt;
|-&lt;br /&gt;
| 0x19 || 0x7 || Reserved&lt;br /&gt;
|-&lt;br /&gt;
| 0x20 || 0x8 || ApplicationId&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationViewDeprecated =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationViewDeprecated&amp;quot;. This is a 0x40-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x8 || [[NCM_services#ApplicationId|ApplicationId]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x4 || Version&lt;br /&gt;
|-&lt;br /&gt;
| 0xC || 0x4 || [[#ApplicationViewFlag|Flag]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x18 || [[#ApplicationDownloadProgress|Progress]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x28 || 0x18 || [[#ApplicationApplyDeltaProgress|ApplyProgress]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
This is converted from [[#ApplicationView]] by [[#GetApplicationViewDeprecated]] on newer system-versions as follows:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x20 || Same as [[#ApplicationView]] +0x0.&lt;br /&gt;
|-&lt;br /&gt;
| 0x20 || 0x4 || Same as [[#ApplicationView]] +0x20.&lt;br /&gt;
|-&lt;br /&gt;
| 0x24 || 0x2 || Same as [[#ApplicationView]] +0x24.&lt;br /&gt;
|-&lt;br /&gt;
| 0x26 || 0x2 || Cleared to 0.&lt;br /&gt;
|-&lt;br /&gt;
| 0x28 || 0x10 || Same as [[#ApplicationView]] +0x30.&lt;br /&gt;
|-&lt;br /&gt;
| 0x38 || 0x4 || Same as [[#ApplicationView]] +0x40.&lt;br /&gt;
|-&lt;br /&gt;
| 0x3C || 0x1 || Same as [[#ApplicationView]] +0x44.&lt;br /&gt;
|-&lt;br /&gt;
| 0x3D || 0x2 || Cleared to 0.&lt;br /&gt;
|-&lt;br /&gt;
| 0x3F || 0x1 || Cleared to 0.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationViewFlag =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationViewFlag&amp;quot;. This is a 32-bit flag.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Bit&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 1&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 2&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 3&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 4&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 5&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 6&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 7&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 8&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 9&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 10&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 11&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 12&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 13&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 14&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 15&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 16&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 17&lt;br /&gt;
| &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationDownloadProgress =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationDownloadProgress&amp;quot;. This is a 0x18-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x8 || Downloaded&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x8 || Total&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x4 || LastResult&lt;br /&gt;
|-&lt;br /&gt;
| 0x14 || 0x1 || [[#ApplicationDownloadState|State]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x15 || 0x3 || Reserved&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationApplyDeltaProgress =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationApplyDeltaProgress&amp;quot;. This is a 0x18-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x8 || Applied&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x8 || Total&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x4 || LastResult&lt;br /&gt;
|-&lt;br /&gt;
| 0x14 || 0x1 || [[#ApplicationApplyDeltaState|State]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x15 || 0x3 || Reserved&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationDownloadState =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationDownloadState&amp;quot;. This is an u8.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || Runnable&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Suspended&lt;br /&gt;
|-&lt;br /&gt;
| 2 || NotEnoughSpace&lt;br /&gt;
|-&lt;br /&gt;
| 3 || Fatal&lt;br /&gt;
|-&lt;br /&gt;
| 4 || Finished&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationApplyDeltaState =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationApplyDeltaState&amp;quot;. This is an u8.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || Applying&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Suspended&lt;br /&gt;
|-&lt;br /&gt;
| 2 || NotEnoughSpace&lt;br /&gt;
|-&lt;br /&gt;
| 3 || Fatal&lt;br /&gt;
|-&lt;br /&gt;
| 4 || NoTask&lt;br /&gt;
|-&lt;br /&gt;
| 5 || WaitApply&lt;br /&gt;
|-&lt;br /&gt;
| 6 || Applied&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationView =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationView&amp;quot;. This is a 0x50-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x8 || [[NCM_services#ApplicationId|ApplicationId]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x4 || ?&lt;br /&gt;
|-&lt;br /&gt;
| 0xC || 0x4 || Flags&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x40 || ?&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationViewWithPromotionInfo =&lt;br /&gt;
This is a 0x70-byte struct.&lt;br /&gt;
&lt;br /&gt;
[20.0.0+] This is a 0x78-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x50 || [[#ApplicationView]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x50 || 0x20 || [[#PromotionInfo]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= PromotionInfo =&lt;br /&gt;
This is a 0x20-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x8 || PosixTime start_timestamp.&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x8 || PosixTime end_timestamp.&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x8 || Remaining time until the promotion ends, in nanoseconds ({end_timestamp - current_time} converted to nanoseconds).&lt;br /&gt;
|-&lt;br /&gt;
| 0x18 || 0x4 || Not set, left at zero.&lt;br /&gt;
|-&lt;br /&gt;
| 0x1C || 0x1 || Flags. Bit0: whether the PromotionInfo is valid (including bit1). Bit1 clear: u64 +0x10 is set.&lt;br /&gt;
|-&lt;br /&gt;
| 0x1D || 0x3 || Padding&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationResourceType =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationResourceType&amp;quot;. This is an u8.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || ApplicationResource&lt;br /&gt;
|-&lt;br /&gt;
| 1 || MicroApplicationResource&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationErrorCodeCategory =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationErrorCodeCategory&amp;quot;. This is an u64.&lt;br /&gt;
&lt;br /&gt;
= NoDownloadRightsErrorResolution =&lt;br /&gt;
This is &amp;quot;nn::ns::NoDownloadRightsErrorResolution&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
= BackgroundNetworkUpdateState =&lt;br /&gt;
This is &amp;quot;nn::ns::BackgroundNetworkUpdateState&amp;quot;. This is an u8.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || None&lt;br /&gt;
|-&lt;br /&gt;
| 1 || InProgress&lt;br /&gt;
|-&lt;br /&gt;
| 2 || Ready&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Similar to [[#HasDownloaded]], [[#GetBackgroundNetworkUpdateState]] uses [[NIM_services|nim]] ListSystemUpdateTask and [[NIM_services|nim]] GetSystemUpdateTaskInfo. When ListSystemUpdateTask successfully returns a task and GetSystemUpdateTaskInfo is successful, the output value is set to: &amp;lt;code&amp;gt;1 + *((u8*)(taskinfo+0) == 0x3&amp;lt;/code&amp;gt;. Otherwise, value=0.&lt;br /&gt;
&lt;br /&gt;
[[#GetBackgroundNetworkUpdateState]] always returns Result 0, however this will assert if GetSystemUpdateTaskInfo fails with ret!=0x3C89.&lt;br /&gt;
&lt;br /&gt;
= SystemUpdateProgress =&lt;br /&gt;
This is &amp;quot;nn::ns::SystemUpdateProgress&amp;quot;. This is a 0x10-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x8 || Loaded (this value can be larger than total_size when the async operation is finishing and when total_size is &amp;lt;=0, this current_size field may contain a progress value for when the total_size is not yet determined)&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x8 || Total (this field is only valid when &amp;gt;0)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Commands which have this as output will return 0 with the output cleared, when no task is available.&lt;br /&gt;
&lt;br /&gt;
= EulaDataPath =&lt;br /&gt;
This is &amp;quot;nn::ns::detail::EulaDataPath&amp;quot;. This is a 0x100-byte struct.&lt;br /&gt;
&lt;br /&gt;
This contains a file path.&lt;br /&gt;
&lt;br /&gt;
= SystemDeliveryInfo =&lt;br /&gt;
This is &amp;quot;nn::ns::SystemDeliveryInfo&amp;quot;. This is a 0x100-byte struct.&lt;br /&gt;
&lt;br /&gt;
Originally the SystemDeliveryInfo validation func verified that OldSystemUpdateId matched the installed SystemUpdate Id. [20.0.0+] The used (Old)SystemUpdateId as selected by SystemUpdateIdFlag must now match one of the Ids in [[System_Settings|system-setting]] &amp;lt;code&amp;gt;contents_delivery!acceptable_system_update_ids_string&amp;lt;/code&amp;gt; (replaces the previously mentioned installed-SystemUpdate check).&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x4 || SystemDeliveryProtocolVersion. Must be &amp;lt;= to and match [[System_Settings|system-setting]] &amp;lt;code&amp;gt;contents_delivery!system_delivery_protocol_version&amp;lt;/code&amp;gt;.&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || 0x4 || ApplicationDeliveryProtocolVersion. Loaded from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;contents_delivery!application_delivery_protocol_version&amp;lt;/code&amp;gt;. Unused by [[#RequestSendSystemUpdate]]/[[#RequestReceiveSystemUpdate]], besides HMAC validation.&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x1 || HasExFat. Unused by [[#RequestSendSystemUpdate]]/[[#RequestReceiveSystemUpdate]], besides HMAC validation.&lt;br /&gt;
|-&lt;br /&gt;
| 0x9 || 0x3 || Reserved.&lt;br /&gt;
|-&lt;br /&gt;
| 0xC || 0x4 || SystemUpdateVersion.&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x8 || OldSystemUpdateId. [20.0.0+] Always the NX Id: this is loaded from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;contents_delivery!old_system_update_id&amp;lt;/code&amp;gt;.&lt;br /&gt;
|-&lt;br /&gt;
| 0x18 || 0x1 || FirmwareVariationId. Used by [[#RequestSendSystemUpdate]]. Loaded from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;ns.systemupdate!firmware_variation&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;ns.systemupdate!t_firmware_variation&amp;lt;/code&amp;gt;, depending on the [[Settings_services|PlatformRegion]].&lt;br /&gt;
|-&lt;br /&gt;
| 0x19 || 0x1 || UpdatableFirmwareGroupId. Unused by [[#RequestSendSystemUpdate]]/[[#RequestReceiveSystemUpdate]], besides HMAC validation. Loaded from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;ns.systemupdate!updatable_firmware_group_id&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;ns.systemupdate!t_updatable_firmware_group_id&amp;lt;/code&amp;gt;, depending on the [[Settings_services|PlatformRegion]].&lt;br /&gt;
|-&lt;br /&gt;
| 0x1A || 0x1 || PlatformRegion (0x00 = Unknown/Global, 0x01 = China).&lt;br /&gt;
|-&lt;br /&gt;
| 0x1B || 0x1 || [20.0.0+] SystemDeliveryInfoPlatform. Loaded from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;ns.systemupdate!system_delivery_info_platform&amp;lt;/code&amp;gt;. Elsewhere this is compared against the sys-setting, etc.&lt;br /&gt;
|-&lt;br /&gt;
| 0x1C || 0x1 || [20.0.0+] SystemUpdateIdFlag. When non-zero, SystemUpdateId is used instead of OldSystemUpdateId. Always set to 0x1 by [[#GetSystemDeliveryInfo]] with [20.0.0+].&lt;br /&gt;
|-&lt;br /&gt;
| 0x1D || 0x3 || Padding&lt;br /&gt;
|-&lt;br /&gt;
| 0x20 || 0x8 || [20.0.0+] SystemUpdateId. See above. With [20.0.0+] [[#GetSystemDeliveryInfo]] now writes the Id here instead of OldSystemUpdateId (for the installed SystemUpdate). On S2 this is set to the Ounce Id.&lt;br /&gt;
|-&lt;br /&gt;
| 0x28 || 0xB8 || Reserved&lt;br /&gt;
|-&lt;br /&gt;
| 0xE0 || 0x20 || HMAC-SHA256 over the previous 0xE0-bytes.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationDeliveryInfo =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationDeliveryInfo&amp;quot;. This is a 0x100-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x4 || ApplicationDeliveryProtocolVersion. Loaded from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;contents_delivery!application_delivery_protocol_version&amp;lt;/code&amp;gt;. An error is thrown when [[System_Settings|system-setting]] &amp;lt;code&amp;gt;contents_delivery!application_delivery_protocol_version&amp;lt;/code&amp;gt; &amp;lt; version, or when [[System_Settings|system-setting]] &amp;lt;code&amp;gt;contents_delivery!acceptable_application_delivery_protocol_version&amp;lt;/code&amp;gt; &amp;gt; version.&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || 0x4 || Padding&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x8 || ApplicationId.&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x4 || ApplicationVersion.&lt;br /&gt;
|-&lt;br /&gt;
| 0x14 || 0x4 || RequiredApplicationVersion.&lt;br /&gt;
|-&lt;br /&gt;
| 0x18 || 0x4 || RequiredSystemVersion.&lt;br /&gt;
|-&lt;br /&gt;
| 0x1C || 0x4 || u32 bitmask &amp;lt;code&amp;gt;nn::ns::ApplicationDeliveryAttributeTag&amp;lt;/code&amp;gt;. [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]] sets this to the input u32. Bit30 and bit28 are additionally set, depending on [[NCM_services|ContentMetaType]] == Patch, etc.&lt;br /&gt;
|-&lt;br /&gt;
| 0x20 || 0x1 || [20.0.0+] [[NCM_services|ContentMetaPlatform]]. Loaded from [[NCM_services|ncm]] IContentMetaDatabase GetPlatform.&lt;br /&gt;
|-&lt;br /&gt;
| 0x21 || 0x1 || [20.0.0+] ProperProgramExists. Set to whether the bit for ProperProgramExists is set from [[NCM_services|ncm]] IContentMetaDatabase GetAttributes.&lt;br /&gt;
|-&lt;br /&gt;
| 0x22 || 0x1 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 0x23 || 0xBD || Reserved&lt;br /&gt;
|-&lt;br /&gt;
| 0xE0 || 0x20 || HMAC-SHA256 over the previous 0xE0-bytes. Uses a different key than [[#SystemDeliveryInfo]].&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= LatestSystemUpdate =&lt;br /&gt;
This is &amp;quot;nn::ns::LatestSystemUpdate&amp;quot;. This is an u8.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || UpToDate&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Downloaded&lt;br /&gt;
|-&lt;br /&gt;
| 2 || NeedsDownload&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ReceiveApplicationProgress =&lt;br /&gt;
This is &amp;quot;nn::ns::ReceiveApplicationProgress&amp;quot;. This is a 0x10-byte struct.&lt;br /&gt;
&lt;br /&gt;
= SendApplicationProgress =&lt;br /&gt;
This is &amp;quot;nn::ns::SendApplicationProgress&amp;quot;. This is a 0x10-byte struct.&lt;br /&gt;
&lt;br /&gt;
= ApplicationRightsOnClient =&lt;br /&gt;
This is a 0x20-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x8 || [[NCM_services#ApplicationId|ApplicationId]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x10 || [[Account_services#Uid|Uid]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x18 || 0x1 || Flags, [[qlaunch]] only uses bit0-bit4 and bit7.&lt;br /&gt;
|-&lt;br /&gt;
| 0x19 || 0x1 || Flags, [[qlaunch]] only uses bit0.&lt;br /&gt;
|-&lt;br /&gt;
| 0x1A || 0x6 || Unknown&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[[qlaunch]] only uses +0x18/+0x19 in this struct.&lt;br /&gt;
&lt;br /&gt;
= DownloadTaskStatus =&lt;br /&gt;
This is &amp;quot;nn::ns::DownloadTaskStatus&amp;quot;. This is a 0x20-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x10 || Uuid&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x8 || [[NCM_services#ApplicationId|ApplicationId]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x18 || 0x1 || [[#DownloadTaskStatusDetail|Detail]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x19 || 0x1 || NeedsCleanup&lt;br /&gt;
|-&lt;br /&gt;
| 0x1A || 0x2 || Reserved&lt;br /&gt;
|-&lt;br /&gt;
| 0x1C || 0x4 || Result&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= DownloadTaskStatusDetail =&lt;br /&gt;
This is &amp;quot;nn::ns::DownloadTaskStatusDetail&amp;quot;. This is an u8.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || Created&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Added&lt;br /&gt;
|-&lt;br /&gt;
| 2 || AlreadyExists&lt;br /&gt;
|-&lt;br /&gt;
| 3 || Failed&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationLaunchInfo =&lt;br /&gt;
This is a 0x40-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x8 || [[NCM_services#ApplicationId|ApplicationId]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x4 || Application version&lt;br /&gt;
|-&lt;br /&gt;
| 0xC || 0x4 || [[Process_Manager_services#LaunchFlags|LaunchFlags]], set to hard-coded value 0xB by [[#GetApplicationLaunchInfo]].&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x1 || Application [[NCM_services#StorageId|StorageId]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x11 || 0x1 || Update [[NCM_services#StorageId|StorageId]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x12 || 0x2E || &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= UserData =&lt;br /&gt;
This is a 0x80-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset || Size || Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x4? || ?&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || 0x4? || Icon ID. 0 = Mii, the rest are character icon IDs.&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x1? || Profile icon background color ID&lt;br /&gt;
|-&lt;br /&gt;
| 0x9 || 0x7 || ?&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x10 || Some ID related to the Mii? All zeros when a character icon is used.&lt;br /&gt;
|-&lt;br /&gt;
| 0x20 || 0x60 || Usually zeros?&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ProfileBase =&lt;br /&gt;
This is a 0x38-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset || Size || Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x10 || userID&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x8 || POSIX UTC timestamp, for last account edit.&lt;br /&gt;
|-&lt;br /&gt;
| 0x18 || 0x20 || UTF-8 Nickname. Official sw uses strncpy to copy this into another struct (&amp;lt;code&amp;gt;nn::account::Nickname&amp;lt;/code&amp;gt;), with a NUL-byte written after the copied data.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Uid =&lt;br /&gt;
This is &amp;quot;nn::account::Uid&amp;quot;. This is a 0x10-byte struct. This contains 2 u64s for the UserId.&lt;br /&gt;
&lt;br /&gt;
= Notes =&lt;br /&gt;
[[Process_Manager_services|pm:bm]] GetBootMode is used to determine whether aoc:u is available (see above). This value is also passed to thread &amp;quot;nn.ns.DelayedInitialization&amp;quot;, which calls various funcs depending on the BootMode in various cases.&lt;br /&gt;
&lt;br /&gt;
The &amp;quot;nn.ns.DelayedInitialization&amp;quot; thread uses BootMode as follows (this also handles various other initialization):&lt;br /&gt;
* Initializes [[NPNS_services|npns:s]] only for BootMode Normal/Maintenance.&lt;br /&gt;
* Initializes the hosted acc:* services and service [[Account_services|acc:su]] only for BootMode Normal/Maintenance.&lt;br /&gt;
* Calls a func only for BootMode Normal.&lt;br /&gt;
* Initializes [[ETicket_services|es]] and [[Shared_Database_services|avm]] only for BootMode Normal/Maintenance.&lt;br /&gt;
&lt;br /&gt;
The output of GetBootMode is also written into state. This same func later enters a code block when BootMode is Maintenance/SafeMode: various [[NCM_services|ncm]] cmds are used with input StorageId=BuiltInUser (VerifyContentMetaDatabase, VerifyContentStorage, ActivateContentMetaDatabase, ActivateContentStorage, InactivateContentMetaDatabase, InactivateContentStorage) and state fields are written. Then if the BootMode is Maintenance the savedata for [[Flash_Filesystem|ns_rightsid]] (0x800000000000004A) is deleted. Then 0 is returned. Otherwise for BootMode Normal it continues with various initialization, including gamecard handling which handles launching the gamecard title in certain conditions (this is the only time ns launches anything with pgl outside of service cmds).&lt;br /&gt;
&lt;br /&gt;
In the above block, InactivateContentMetaDatabase/InactivateContentStorage are only used if using ActivateContentMetaDatabase/ActivateContentStorage failed (error is only checked after using both cmds). If any of the ncm cmds prior to this fail, it will skip using the rest of the ncm cmds.&lt;br /&gt;
&lt;br /&gt;
[[Category:Services]]&lt;/div&gt;</summary>
		<author><name>Yellows8</name></author>
	</entry>
	<entry>
		<id>https://switchbrew.org/w/index.php?title=Switch_System_Flaws&amp;diff=14929</id>
		<title>Switch System Flaws</title>
		<link rel="alternate" type="text/html" href="https://switchbrew.org/w/index.php?title=Switch_System_Flaws&amp;diff=14929"/>
		<updated>2026-08-07T02:51:39Z</updated>

		<summary type="html">&lt;p&gt;Yellows8: /* Games */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This page is a list of publicly known Switch / Switch 2 (S2) flaws.&lt;br /&gt;
&lt;br /&gt;
= Hardware =&lt;br /&gt;
Flaws in this category pertain to the underlying hardware that powers the Switch.&lt;br /&gt;
&lt;br /&gt;
This includes components shared across Tegra based devices such as the [[TSEC]], the [[Security_Engine|Security Engine]], the [[GPU]] and so on.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
!  Summary&lt;br /&gt;
!  Description&lt;br /&gt;
!  Fixed with hardware model/revision&lt;br /&gt;
!  Newest hardware model/revision this flaw was checked for&lt;br /&gt;
!  Timeframe this was discovered&lt;br /&gt;
!  Public disclosure timeframe&lt;br /&gt;
!  Discovered by&lt;br /&gt;
|-&lt;br /&gt;
| GMMU DMA attack&lt;br /&gt;
| The Switch&#039;s GPU includes a separate MMU (GMMU) that is allowed to bypass the system&#039;s IOMMU (SMMU). By accessing the GPU&#039;s MMIO region and manipulating the page table entries in the GMMU, an attacker can read/write any portion of the DRAM (except memory carveouts).&lt;br /&gt;
&lt;br /&gt;
[5.0.0+] Works around this hardware flaw by using memory pool partitioning. You can no longer escalate into sysmodules with GPU DMA because all their memory is allocated using heap that&#039;s carved out.&lt;br /&gt;
&lt;br /&gt;
HAC-001-01 (Mariko/Tegra214/Tegra210b01): Fixes this by adding a new register which restricts what memory untranslated DMA requests may access. Untranslated GPU DMA may now only access the GPU carveout (physmem 0x80002000-0x80006000), which the GPU already has legitimate and exclusive access to.&lt;br /&gt;
| HAC-001-01 (Mariko/Tegra214/Tegra210b01)&lt;br /&gt;
| HAC-001 (Tegra210)&lt;br /&gt;
| Summer 2017&lt;br /&gt;
| December 28, 2017&lt;br /&gt;
| [[User:hexkyz|hexkyz]], [[User:SciresM|SciresM]] and [[User:qlutoo|qlutoo]]&lt;br /&gt;
|-&lt;br /&gt;
| Weak Security Engine context validation&lt;br /&gt;
| The Tegra X1 supports a &amp;quot;deep sleep&amp;quot; feature, where everything but DRAM and the PMC registers lose their content (and the SoC loses power). Upon awaking, the bootrom re-executes, restoring system state. Among these stored states is the Security Engine&#039;s saved state, which uses AES-128-CBC with a random key and all-zeroes IV. However, the bootrom doesn&#039;t perform a MAC on this data, and only validates the last block. This allows one to control most of security engine&#039;s state upon wakeup, if one has a way to modify the encrypted state buffer.&lt;br /&gt;
&lt;br /&gt;
With a way to modify the encrypted state buffer, one can thus dump keys from &amp;quot;write-only&amp;quot; keyslots, etc.&lt;br /&gt;
&lt;br /&gt;
This also bypasses the SBK protection of the bootROM: indeed, at warmboot, bootROM will always clear keyslot 0xE to prevent malicious code from saving the SBK. Moving the SBK to another keyslot in the saved context renders this protection moot.&lt;br /&gt;
&lt;br /&gt;
HAC-001-01 (Mariko/Tegra214/Tegra210b01): Fixes this by streamlining the context save process; security engine contexts are now saved to protected memory which the CPU cannot access or modify.&lt;br /&gt;
| HAC-001-01 (Mariko/Tegra214/Tegra210b01)&lt;br /&gt;
| HAC-001 (Tegra210)&lt;br /&gt;
| December 2017&lt;br /&gt;
| January 20, 2018&lt;br /&gt;
| [[User:SciresM|SciresM]] and [[User:motezazer|motezazer]]&lt;br /&gt;
|-&lt;br /&gt;
| Security Engine keyslots vulnerable to partial overwrite attack&lt;br /&gt;
| &lt;br /&gt;
The Tegra X1 security engine supports writing keyslot data to the engine with syntax as follows: &lt;br /&gt;
&lt;br /&gt;
SECURITY_ENGINE-&amp;gt;AES_KEYTABLE_ADDR = (keyslot &amp;lt;&amp;lt; 4) | (dword_index_in_keyslot); &lt;br /&gt;
&lt;br /&gt;
SECURITY_ENGINE-&amp;gt;AES_KEYTABLE_DATA = readle32(key, dword_index_in_keyslot * 4); &lt;br /&gt;
&lt;br /&gt;
However, the Security Engine flushes writes to the internal key tables immediately when AES_KEYTABLE_DATA is written -- this allows one to overwrite a single dword of a key at a time, and thus brute force the contents of keyslots in time (2^32 * 8) = 2^35 instead of 2^256.&lt;br /&gt;
| None&lt;br /&gt;
| HAC-001 (Tegra210)&lt;br /&gt;
| Theorized Summer 2017 due to suggestive syntax, confirmed April 9, 2018&lt;br /&gt;
| April 9, 2018&lt;br /&gt;
| [[User:SciresM|SciresM]], almost surely others (independently).&lt;br /&gt;
|-&lt;br /&gt;
| CVE-2018-6242 (leveraged by the ShofEL2 and Fusée Gelée exploits)&lt;br /&gt;
| The USB software stack provided inside the boot instruction rom (IROM/bootROM) contains a copy operation whose length can be controlled by an attacker. By carefully constructing a USB control request, an attacker can leverage this vulnerability to copy the contents of an attacker-controlled buffer over the active execution stack, gaining control of the Boot and Power Management processor (BPMP) before any lock-outs or privilege reductions occur. This execution can then be used to exfiltrate secrets and to load arbitrary code onto the main CPU Complex (CCPLEX) &amp;quot;application processors&amp;quot; at the highest possible level of privilege (typically as the TrustZone Secure Monitor at PL3/EL3).&lt;br /&gt;
| HAC-001-01 (Mariko/Tegra214/Tegra210b01) (also fixed independently on Tegra186).&lt;br /&gt;
| HAC-001 (Tegra210)&lt;br /&gt;
| January 2018&lt;br /&gt;
| April 23, 2018&lt;br /&gt;
| [[User:Shuffle2|shuffle2]] and fail0verflow (originally),&amp;lt;br&amp;gt; [[User:Ktemkin|ktemkin]] and ReSwitched Team (independently),&amp;lt;br&amp;gt; [[User:Naehrwert|naehrwert]] (independently),&amp;lt;br&amp;gt; [[User:Hexkyz|hexkyz]] (independently),&amp;lt;br&amp;gt; st4rk with [[User:Shinyquagsire23|Shiny Quagsire]] and Dazzozo (independently),&amp;lt;br&amp;gt; and many others (independently).&lt;br /&gt;
|-&lt;br /&gt;
| Poor validation of bootrom SDRAM configuration parameters leads to arbitrary writes in bootrom&lt;br /&gt;
| &lt;br /&gt;
The Tegra X1 bootrom supports saving SDRAM parameters to scratch registers, and using the saved configuration to enable DRAM during warmboot.&lt;br /&gt;
&lt;br /&gt;
The code that parses these parameters does if (params-&amp;gt;EmcBctSpareN) *params-&amp;gt;EmcBctSpareN = params-&amp;gt;EmcBctSpareNPlusOne for most N, without validating either the address or value written to it.&lt;br /&gt;
There are other arbitrary writes in this code, as well (e.g. BootromPatch parameters intended for patching MISC registers do not check a relative offset to 0x7000000, etc).&lt;br /&gt;
&lt;br /&gt;
This allows a user with access to the PMC registers (via pre-sleep bpmp execution, or otherwise) to gain arbitrary bootrom code execution.&lt;br /&gt;
&lt;br /&gt;
HAC-001-01 (Mariko/Tegra214/Tegra210b01): Fixes this by validating that the spare writes/bootrom patch before performing them.&lt;br /&gt;
| HAC-001-01 (Mariko/Tegra214/Tegra210b01)&lt;br /&gt;
| HAC-001 (Tegra210)&lt;br /&gt;
| 2017&lt;br /&gt;
| December 16, 2018&lt;br /&gt;
| Everyone (independently).&lt;br /&gt;
|-&lt;br /&gt;
| TSEC ROM does not clear crypto registers after signature verification&lt;br /&gt;
|&lt;br /&gt;
TSEC supports executing signed-microcode at a greater privilege level than normal payloads.&lt;br /&gt;
&lt;br /&gt;
When jumping to signed microcode, the caller is expected to load hardware crypto register $c6 = &amp;lt;signature&amp;gt;, $c7 = &amp;lt;seed (zero for all officially-signed microcode)&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
TSEC ROM then calculates the expected signature and compares it to the user-supplied one in $c6. On match, the secure payload is executed, and on failure an exception is raised.&lt;br /&gt;
&lt;br /&gt;
However, TSEC ROM fails to clear the crypto registers used to calculate the expected signature in either of the success/failure cases.&lt;br /&gt;
&lt;br /&gt;
Thus, with some way of obtaining the contents of crypto registers (e.g. ROP under some secure payload), an attacker can dump intermediary values from signature calculation.&lt;br /&gt;
&lt;br /&gt;
With enough data/trial/error, this is enough to reconstruct the signature algorithm:&lt;br /&gt;
* mac = &amp;lt;davies meyer hash of (page || address of page) for each 0x100 page in the payload&amp;gt;&lt;br /&gt;
* key = AES-ENCRYPT(hardware csecret 0x1, seed)&lt;br /&gt;
* signature = AES-ENCRYPT(key, mac)&lt;br /&gt;
&lt;br /&gt;
| None&lt;br /&gt;
| HAC-001 (Tegra210)&lt;br /&gt;
| Late 2018/Early 2019&lt;br /&gt;
| August 2020&lt;br /&gt;
| [[User:qlutoo|qlutoo]]/[[User:Hexkyz|hexkyz]]/[[User:Shuffle2|shuffle2]], [[User:SciresM|SciresM]]/[[User:motezazer|motezazer]] (independently).&lt;br /&gt;
|-&lt;br /&gt;
| TSEC signature validation design flaw leads to fake-signing&lt;br /&gt;
|&lt;br /&gt;
As mentioned above, when jumping to signed microcode the caller is expected to load hardware crypto register $c6 = &amp;lt;signature&amp;gt;, $c7 = &amp;lt;seed (zero for all officially-signed microcode)&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
However, TSEC ROM performs no validation on the input seed used to generate the signing key.&lt;br /&gt;
&lt;br /&gt;
This leads to the following attack:&lt;br /&gt;
* Attacker gains rop under any secure microcode payload with signature = S.&lt;br /&gt;
* Attacker uses the &amp;quot;csigenc&amp;quot; instruction to obtain K = AES-ENCRYPT(hardware csecret 0x1, S).&lt;br /&gt;
* Attacker jumps to their own microcode with $c6 = &amp;lt;signature calculated on pc using K&amp;gt;, $c7 = S&lt;br /&gt;
* TSEC ROM calculates key = AES-ENCRYPT(hardware csecret 0x1, S) = K, and the signature check passes.&lt;br /&gt;
* Attackers microcode is executed in secure mode as though it were signed by NVidia.&lt;br /&gt;
&lt;br /&gt;
Thus an attacker who has exploited *any* secure payload may use this to obtain a &amp;quot;fake signature key&amp;quot;, which can be used to sign and execute arbitrary microcode in secure mode.&lt;br /&gt;
&lt;br /&gt;
Note: this does not break the TSEC cryptosystem, as the csigenc mechanism relies on the signature of the executing microcode, and fakesigning produces different signatures from NVidia that cannot be controlled.&lt;br /&gt;
| None&lt;br /&gt;
| HAC-001 (Tegra210)&lt;br /&gt;
| Late 2018/Early 2019&lt;br /&gt;
| August 2020&lt;br /&gt;
| [[User:qlutoo|qlutoo]]/[[User:Hexkyz|hexkyz]]/[[User:Shuffle2|shuffle2]], [[User:SciresM|SciresM]]/[[User:motezazer|motezazer]] (independently).&lt;br /&gt;
|-&lt;br /&gt;
| ROP under TSEC secure bootrom via DMA engine stack overwrite (--xploit)&lt;br /&gt;
| TSEC DMA engine does not stop when entering TSEC secure bootrom. By pointing TSEC DMA to current stack before secure bootrom entry, stack can be controlled. &lt;br /&gt;
&lt;br /&gt;
One can then use blind ROP against the TSEC secure bootrom (which is execute only, and cannot be dumped).&lt;br /&gt;
&lt;br /&gt;
With sufficient effort, an attacker can construct a ROP chain that leads to csigcmp being executed with fully controlled arguments.&lt;br /&gt;
&lt;br /&gt;
This allows for arbitrary heavy secure mode code execution with the current signature set to an arbitrary value.&lt;br /&gt;
&lt;br /&gt;
This completely breaks the TSEC cryptosystem, by allowing one to obtain the result of csigenc with signature = &amp;lt;any desired value&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
This has many uses/results, notably including dumping the &amp;quot;true&amp;quot; signature key (set signature = zeroes, perform csigenc using csecret 0x1).&lt;br /&gt;
| None&lt;br /&gt;
| TSEC for all Tegra devices&lt;br /&gt;
| Late 2018&lt;br /&gt;
| January 2021&lt;br /&gt;
| [[User:Hexkyz|hexkyz]]/[[User:SciresM|SciresM]], [[User:Vale|Vale]]/[[User:Thog|Thog]] (independently), [[User:Tatsuko|Tatsuko]] (independently), possibly others (independently).&lt;br /&gt;
|-&lt;br /&gt;
| Boot straps are not relatched on watchdog resets (strapwn)&lt;br /&gt;
| On boot, the BOOTSELECT, RCM and RAM_CODE straps are latched from external GPIO to determine which boot medium to use and verify from in bootrom. However, APB_MISC_PP_STRAPPING_OPT_A can be overwritten with arbitrary values following bootrom. Write access to PP_STRAPPING_OPT_A would otherwise be mundane, however these straps are not relatched during a watchdog reset (despite being latched during other software resets), allowing for arbitrary straps to be selected and executed in bootrom.&lt;br /&gt;
&lt;br /&gt;
This allows setting NVPROD_UART on some hardware configurations where it would normally be unavailable (ie on Jetson Nano boards), but is otherwise mostly useless and/or useful for testing unintended boot options (such as USB Mass Storage boot) without having to move boot strap resistors.&lt;br /&gt;
| Unknown&lt;br /&gt;
| HAC-001 (Tegra210)&lt;br /&gt;
| May 2020&lt;br /&gt;
| April 30, 2021&lt;br /&gt;
| [[User:Shinyquagsire23|Shiny Quagsire]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Firmware =&lt;br /&gt;
Flaws in this category pertain to the firmware running on hardware devices, such as wifi/bluetooth, etc. Firmware is generally uploaded by sysmodules.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Summary&lt;br /&gt;
!  Description&lt;br /&gt;
!  Successful exploitation result&lt;br /&gt;
!  Fixed in system version&lt;br /&gt;
!  Last system version this flaw was checked for&lt;br /&gt;
!  Timeframe this was discovered&lt;br /&gt;
!  Public disclosure timeframe&lt;br /&gt;
!  Discovered by&lt;br /&gt;
|-&lt;br /&gt;
| Broadpwn (CVE-2017-9417)&lt;br /&gt;
| See [https://blog.exodusintel.com/2017/07/26/broadpwn/ here] and [https://www.blackhat.com/docs/us-17/thursday/us-17-Artenstein-Broadpwn-Remotely-Compromising-Android-And-iOS-Via-A-Bug-In-Broadcoms-Wifi-Chipsets.pdf here].&lt;br /&gt;
| Code execution on the wifi controller (untested on Switch).&lt;br /&gt;
| [[4.0.0]]&lt;br /&gt;
| [[4.0.0]]&lt;br /&gt;
| Switch: July 2022&lt;br /&gt;
| Switch: July 30, 2022&lt;br /&gt;
| Switch: [[User:Yellows8|yellows8]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Software =&lt;br /&gt;
== Bootloader ==&lt;br /&gt;
Flaws in this category pertain to any bootloader component such as the [[Package1#Package1ldr|package1ldr]], the [[Package1#Section_1|NX bootloader]] or the [[Package1#Section_0|warmboot binary]].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Summary&lt;br /&gt;
!  Description&lt;br /&gt;
!  Successful exploitation result&lt;br /&gt;
!  Fixed in system version&lt;br /&gt;
!  Last system version this flaw was checked for&lt;br /&gt;
!  Timeframe this was discovered&lt;br /&gt;
!  Public disclosure timeframe&lt;br /&gt;
!  Discovered by&lt;br /&gt;
|-&lt;br /&gt;
| Null-dereference in panic()&lt;br /&gt;
| The Switch&#039;s stage 1 bootloader, on panic(), clears the stack and then attempts to clear the Security Engine. However, it does so by dereferencing a pointer to the SE in .bss (initially NULL), and this pointer doesn&#039;t get initialized until partway into the bootloader&#039;s main() after several functions that might panic() are called. Thus, a panic() caused prior to SE initialization would result in the SE pointer still being NULL when dereferenced. &lt;br /&gt;
The BPMP doesn&#039;t have an active MPU and the bus won&#039;t data abort on an invalid address, so no exception will be entered: it&#039;ll end up overwriting some exception vectors with NULL before halting.&lt;br /&gt;
&lt;br /&gt;
In 3.0.0, this was fixed by moving the security engine initialization earlier in main(), before the first function that could potentially panic().&lt;br /&gt;
| Some exception vectors overwritten with NULL, before SBK/other keyslots are cleared. Probably useless for anything more interesting.&lt;br /&gt;
| [[3.0.0]]&lt;br /&gt;
| [[3.0.0]]&lt;br /&gt;
| Early July, 2017&lt;br /&gt;
| July 30, 2017&lt;br /&gt;
| Everyone who diff&#039;d 2.3.0 and 3.0.0 Package1&lt;br /&gt;
|-&lt;br /&gt;
| FUSE_DIS_PGM not written by package1 &lt;br /&gt;
| The switch&#039;s hardware fuse driver contains a write-once bit in a register called &amp;quot;FUSE_DIS_PGM&amp;quot;, which disables burning fuses until the next reboot. While Nintendo&#039;s bootloader code for waking up from sleep writes this on all firmware, the actual package1 initial bootloader forgets to write to it on cold reboot. &lt;br /&gt;
&lt;br /&gt;
This isn&#039;t too big of a problem because another fuse is burnt on retail devices (production mode), which prevents burning *all* fuses other than ODM_RESERVED ones in hardware.&lt;br /&gt;
&lt;br /&gt;
This was fixed in 3.0.0 by writing to the register on cold boot (although the write happens in TZ instead of package1 where it should take place, possibly to obfuscate the fact that they made this mistake).&lt;br /&gt;
| Burning arbitrary ODM reserved fuses with TZ code execution, which should never be possible for non-bootloader code.&lt;br /&gt;
&lt;br /&gt;
Warning: one could irreparably brick one&#039;s console by playing with this.&lt;br /&gt;
| [[3.0.0]]&lt;br /&gt;
| [[3.0.0]]&lt;br /&gt;
| Late summer/early fall 2017&lt;br /&gt;
| December 31, 2017&lt;br /&gt;
| [[User:SciresM|SciresM]], [[User:motezazer|motezazer]]&lt;br /&gt;
|-&lt;br /&gt;
| maconstack (TSEC firmware leaves MAC on the stack)&lt;br /&gt;
| Package1ldr loads a firmware blob into TSEC early on boot. This piece of code runs on the TSEC in Authenticated Mode and has the sole purpose of generating the per-console TSEC key (see [[Cryptosystem]]).&lt;br /&gt;
&lt;br /&gt;
As a way to mitigate attacks, the TSEC firmware blob is split into 3 stages: [[TSEC_Firmware#Boot|Boot]] which is unencrypted and unsigned, [[TSEC_Firmware#KeygenLdr|KeygenLdr]] which is unencrypted but signed and [[TSEC_Firmware#Keygen|Keygen]] which is encrypted and signed.&lt;br /&gt;
Boot loads a static pre-generated signature into the Falcon&#039;s CPU crypto registers, loads KeygenLdr into the Falcon&#039;s CODE region and jumps to it. Execution will proceed into KeygenLdr in Heavy Secure Mode if, and only if, the loaded signature matches the one Falcon calculates internally for KeygenLdr.&lt;br /&gt;
&lt;br /&gt;
Among various things, KeygenLdr will attempt to do a &amp;quot;backwards&amp;quot; security check by calculating a CMAC over Boot and comparing it with a known hash stored in the TSEC firmware&#039;s key data (a small buffer stored after Boot&#039;s code). If the hashes don&#039;t match, execution aborts.&lt;br /&gt;
&lt;br /&gt;
KeygenLdr stores the calculated Boot&#039;s CMAC in the stack, but forgets to clear it. Since the stack is located in Falcon&#039;s DATA region, loading the TSEC firmware blob and dumping the DATA region afterwards (via MMIO) will reveal the calculated hash.&lt;br /&gt;
This allows using KeygenLdr as an oracle to generate a valid CMAC for arbitrary Boot code. Replacing the CMAC in the TSEC firmware&#039;s key data region results in KeygenLdr accepting any Boot code, thus rendering this security measure useless.&lt;br /&gt;
&lt;br /&gt;
Additionally, since signed Falcon code can&#039;t be revoked without an hardware revision, an attacker can always reuse the flawed KeygenLdr code even if a fix is issued.&lt;br /&gt;
| Running TSEC firmware&#039;s KeygenLdr in a user controlled environment.&lt;br /&gt;
| None&lt;br /&gt;
| [[5.0.2]]&lt;br /&gt;
| January 2018&lt;br /&gt;
| April 29, 2018&lt;br /&gt;
| [[User:Hexkyz|hexkyz]], [[User:Rei|Reisyukaku]] (independently), probably others (independently).&lt;br /&gt;
|-&lt;br /&gt;
| pk1ldrhax&lt;br /&gt;
| Package1ldr decrypts and verifies the keyblob inside of the current BCT in order to get the package1 key, and then uses the package1 key to decrypt package1. It then validates package1 before jumping to it by checking the PK11 magic number, and that the section sizes sum to the expected size (and are individually less than the expected size). &lt;br /&gt;
&lt;br /&gt;
However, package1ldr does not actually validate the package1 key against a fixed vector (much like kernel9loader forgot to do so on the 3ds). This would normally not matter, as keyblobs are validated -- however, with bootrom code execution one can dump SBK and forge keyblobs, and thus control the package1 key. &lt;br /&gt;
&lt;br /&gt;
Thus (&#039;&#039;&#039;in theory, but not in practice due to the size of the brute force required&#039;&#039;&#039;) one can replace the package1 key with garbage, causing package1 to decrypt into garbage, and hope that this garbage passes validation checks and that package1ldr jumping into the garbage will do something useful.&lt;br /&gt;
&lt;br /&gt;
This was fixed incidentally in [[6.2.0]], as pk1ldr does not use keyblob data to decrypt package1 any more.&lt;br /&gt;
&lt;br /&gt;
| With a large enough brute force: arbitrary package1 code execution from coldboot.&lt;br /&gt;
&lt;br /&gt;
However, a usable brute force is on the order of &amp;gt;= ~2^80, so &#039;&#039;&#039;this is almost certainly not actually usable in any meaningful context&#039;&#039;&#039;.&lt;br /&gt;
| [[6.2.0]]&lt;br /&gt;
| [[6.2.0]]&lt;br /&gt;
| Early 2017 (as soon as plaintext package1ldr was first dumped)&lt;br /&gt;
| November 20, 2018&lt;br /&gt;
| Everyone&lt;br /&gt;
|-&lt;br /&gt;
| Stack smash in TSEC firmware&#039;s KeygenLdr&lt;br /&gt;
| Given that we can control the [[TSEC_Firmware#Key_data|key data]] (which is not authenticated) and the [[TSEC_Firmware#Boot|Boot]] blob (see &amp;quot;maconstack&amp;quot;), as well as the fact Non-secure and Heavy Secure code share the same stack, we can use this to attack KeygenLdr. KeygenLdr uses memcpy to copy over a payload to DMEM to verify it, which can be abused to smash the stack (in DMEM) and write over the return address of said function.&lt;br /&gt;
| ROP under KeygenLdr in Heavy Secure mode.&lt;br /&gt;
| None&lt;br /&gt;
| [[8.0.1]]&lt;br /&gt;
| Early 2018&lt;br /&gt;
| May 21, 2019&lt;br /&gt;
| Everyone (independently).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== TrustZone ==&lt;br /&gt;
Flaws in this category pertain exclusively to the [[Package1#Section_2|Secure Monitor]].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Summary&lt;br /&gt;
!  Description&lt;br /&gt;
!  Successful exploitation result&lt;br /&gt;
!  Fixed in system version&lt;br /&gt;
!  Last system version this flaw was checked for&lt;br /&gt;
!  Timeframe this was discovered&lt;br /&gt;
!  Public disclosure timeframe&lt;br /&gt;
!  Discovered by&lt;br /&gt;
|-&lt;br /&gt;
| Non-atomic mutexes&lt;br /&gt;
| When an [[SMC]] is called, TrustZone sets a global variable to mark that an SMC is in progress, so that two SMCs using shared resources (like the security engine) do not trample on one another. On 1.0.0, this global variable was written using non-atomic writes, and thus a race condition is possible.&lt;br /&gt;
&lt;br /&gt;
However, the SMC handler enforces that all SMCs must be called from core #3, unless the top-level handler ID is 1 (SMCs internal to the kernel). Thus, the only SMCs that can be run side-by-side are [any userland smc] and smcGetRandomBytesForKernel, and this turns out to not really be abusable.&lt;br /&gt;
| Mostly useless. Maybe some oob-write into unused (and thus useless) memory if running smcGetRandomBytesForKernel and smcGetRandomBytesForUser at the same time.&lt;br /&gt;
| [[2.0.0]]&lt;br /&gt;
| [[2.0.0]]&lt;br /&gt;
| December 2017 (Probably earlier by others)&lt;br /&gt;
| January 18, 2018&lt;br /&gt;
| [[User:SciresM|SciresM]], probably others (independently).&lt;br /&gt;
|-&lt;br /&gt;
| jamais vu (non-secure world access to PMC MMIO and pre-deep sleep firmware)&lt;br /&gt;
| On [[1.0.0]], one could map in the PMC registers in userland. In addition, [[AM_services|am]] ran a little-kernel based firmware on the BPMP at runtime. With code execution under am, one could modify the BPMP&#039;s little-kernel firmware to hook deep sleep entry, and modify TrustZone/Security engine state. &lt;br /&gt;
&lt;br /&gt;
This was fixed in [[2.0.0]] by making the PMC secure-world only, blacklisting the BPMP&#039;s exception vectors from being mapped, and thoroughly checking for malicious behavior on deep sleep entry.&lt;br /&gt;
| Arbitrary TrustZone code execution.&lt;br /&gt;
| [[2.0.0]]&lt;br /&gt;
| [[2.0.0]]&lt;br /&gt;
| December, 2017&lt;br /&gt;
| January 20, 2018&lt;br /&gt;
| [[User:SciresM|SciresM]] and [[User:motezazer|motezazer]]&lt;br /&gt;
|-&lt;br /&gt;
| Missed BPMP Exception Vector Writes&lt;br /&gt;
| Starting in [[2.0.0]], the BPMP is asleep at runtime, and is turned on by TrustZone during [[SMC|smcCpuSuspend]] in order to initiate the deep sleep process. When it does so, it is held in RESET, and TrustZone attempts to write to the BPMP exception vectors at 0x6000F200 to register EVP_RESET = lp0_entry_fw_crt0, and all other EVPs to a function that simply reboots. However, while they successfully write EVP_RESET, they miss all the other vectors, accidentally writing to the 0x6000F004-0x6000F020 region instead of the 0x6000F204-0x6000F220 region they want to write to. This results in all the exception vectors for the BPMP other than RESET being &amp;quot;undefined&amp;quot; (attacker controlled).&lt;br /&gt;
&lt;br /&gt;
With some way of causing an exception vector to be taken at the right time, this would give pre-sleep code execution (and thus arbitrary TrustZone code execution, via the security engine flaw). However, none of the abort vectors are really triggerable, and interrupts are disabled for the BPMP when it is taken out of reset. Thus, this is useless in practice.&lt;br /&gt;
&lt;br /&gt;
This was fixed in [[4.0.0]] by writing to the correct registers.&lt;br /&gt;
| Theoretically: Arbitrary TrustZone code execution. In practice: Useless.&lt;br /&gt;
| [[4.0.0]]&lt;br /&gt;
| [[4.0.0]]&lt;br /&gt;
| January, 2018&lt;br /&gt;
| February 23, 2018&lt;br /&gt;
| [[User:SciresM|SciresM]] and [[User:motezazer|motezazer]], [[User:Naehrwert|naehrwert]], [[User:Hexkyz|hexkyz]], probably others (independently).&lt;br /&gt;
|-&lt;br /&gt;
| TSEC has access to the secure kernel carveout &lt;br /&gt;
| TrustZone is responsible for managing security carveouts to prevent DMA controllers from accessing the carveout which contains the kernel, sysmodules, and other critical operating system data.&lt;br /&gt;
&lt;br /&gt;
Until [[8.0.0]], the list of devices that could access the carveout included the TSEC. However, the TSEC can bypass the SMMU when in authenticated mode by writing to a certain register. Thus, pwning nvservices would allow one to take over the TSEC, and use it to write to normally protected mmio/memory.&lt;br /&gt;
&lt;br /&gt;
In [[8.0.0]], this was fixed by removing TSEC access, and adding TSECB access (TSECB cannot bypass the SMMU).&lt;br /&gt;
| With access to the TSEC mmio (nvservices ROP) and code execution in TSEC Heavy Secure mode, kernel code execution, probably.&lt;br /&gt;
| [[8.0.0]]&lt;br /&gt;
| [[8.0.0]]&lt;br /&gt;
| 2017 (when TrustZone code plaintext was first obtained).&lt;br /&gt;
| April 15, 2019&lt;br /&gt;
| Everyone&lt;br /&gt;
|-&lt;br /&gt;
| deja vu (insufficient system state validation on suspend leads to pre-sleep BPMP code execution)&lt;br /&gt;
| Jamais Vu was fixed in [[2.0.0]] by making the PMC secure-world only, blacklisting the BPMP&#039;s exception vectors from being mapped, and thoroughly checking for malicious behavior on deep sleep entry, since gaining pre-sleep code execution on the BPMP compromises the system.&lt;br /&gt;
&lt;br /&gt;
However, the state validation performed by Nintendo&#039;s Secure Monitor was insufficient to prevent pre-sleep execution from being obtained.&lt;br /&gt;
&lt;br /&gt;
Prior to [[6.0.0]], one could use a DMA controller that had access to IRAM and was not held in reset (there were multiple) to race TrustZone&#039;s writes to the BPMP firmware in IRAM, and thus overwrite Nintendo&#039;s firmware with an attacker&#039;s to gain pre-sleep code execution.&lt;br /&gt;
&lt;br /&gt;
[[6.0.0]] addressed this by performing TrustZone state MAC writes and locking PMC scratch *before* turning on the BPMP, fixing the original Jamais Vu exploit entirely. In addition, the BPMP firmware in TrustZone&#039;s .rodata is now memcmp&#039;d to the actual data after it is written to IRAM. This mitigates race attacks that modify the firmware.&lt;br /&gt;
&lt;br /&gt;
However, Nintendo both forgot to validate the BPMP exception vectors after writing them, and forgot to hold in reset a DMA controller that can write to the BPMP&#039;s exception vectors.&lt;br /&gt;
&lt;br /&gt;
AHB-DMA is not blacklisted by kernel mapping whitelist (Nintendo probably forgot it, because the TX1 TRM does not really document that it&#039;s present, although the MMIO works as documented in older (Tegra 3 and before) TRMs).&lt;br /&gt;
&lt;br /&gt;
Thus, with kernel code execution (or some other way of accessing AHB-DMA, e.g. nspwn on &amp;lt;= 4.1.0, TSEC hax, or other arbitrary mmio access flaws), one can DMA to the BPMP&#039;s exception vectors as they are written, causing TrustZone to start the BPMP executing an attacker&#039;s firmware at a different location than TrustZone intends/validates.&lt;br /&gt;
&lt;br /&gt;
This was fixed in [[8.0.0]] by blocking AHB-DMA arbitration and verifying it is held in reset during suspend, and thus there are no more devices that can write to the relevant MMIO at the right time.&lt;br /&gt;
&lt;br /&gt;
| Arbitrary TrustZone/BootROM code execution, by using either the original Jamais Vu flaw (prior to [[6.0.0]] or a warmboot bootrom exploit (any firmware where pre-sleep execution can be gained).&lt;br /&gt;
| [[8.0.0]]&lt;br /&gt;
| [[8.0.0]]&lt;br /&gt;
| December 2017&lt;br /&gt;
| April 15, 2019&lt;br /&gt;
| [[User:SciresM|SciresM]], [[User:motezazer|motezazer]] and ktemkin,  [[User:Naehrwert|naehrwert]] (independently), almost certainly others (independently)&lt;br /&gt;
|-&lt;br /&gt;
| TrustZone allows using imported RSA exponents with arbitrary modulus&lt;br /&gt;
| TrustZone supports &amp;quot;importing&amp;quot; RSA private exponents for use by userland -- these are stored encrypted with TrustZone only keydata in NAND, and decrypted only to TZRAM. This prevents a console that has compromised userland from learning the private exponents of these keys and doing calculations with them offline. In practice, this is used for FS (gamecard communications), ES (drm), and SSL (console client cert communications).&lt;br /&gt;
&lt;br /&gt;
However, the actual SMC API only imports the RSA exponent, and not the modulus, which is passed separately by userland in each call. There is no validation done on the modulus passed in -- this means that userland can pass in any message and modulus it chooses, and obtain the result of (message ^ private exponent) % modulus back from the secure monitor.&lt;br /&gt;
&lt;br /&gt;
By choosing a prime number modulus P such that P has &amp;quot;smooth&amp;quot; order (totient(P) == P-1 is divisible only by &amp;quot;small&amp;quot; primes), one can efficiently use the [[wikipedia:Pohlig-Hellman algorithm|Pohlig-Hellman algorithm]] to calculate the discrete logarithm of such a result directly, and thus obtain the private exponent.&lt;br /&gt;
&lt;br /&gt;
This is mostly useless in practice, given the general availability of other exploits to obtain these decrypted exponents.&lt;br /&gt;
&lt;br /&gt;
This was fixed in 10.0.0 by importing the modulus in addition to the exponent for the ES device key and ES client cert key. For backwards compatibility reasons the SSL key and Lotus key still only import the exponent.&lt;br /&gt;
&lt;br /&gt;
StorageExpMod also now validates that the exponentiation of &amp;quot;DDDDD...&amp;quot; about the provided modulus by the imported exponent and then the fixed public exponent returns &amp;quot;DDDDD...&amp;quot;, and returns invalid argument if validation fails.&lt;br /&gt;
| With userland privileges sufficient to use an imported RSA key: obtaining that RSA key&#039;s private exponent.&lt;br /&gt;
| [[10.0.0]]&lt;br /&gt;
| [[10.0.0]]&lt;br /&gt;
| August 14, 2019&lt;br /&gt;
| August 14, 2019&lt;br /&gt;
| [[User:SciresM|SciresM]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Kernel ==&lt;br /&gt;
Flaws in this category pertain exclusively to the [[Package2#Section_0|HorizonOS Kernel]].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Summary&lt;br /&gt;
!  Description&lt;br /&gt;
!  Successful exploitation result&lt;br /&gt;
!  Fixed in system version&lt;br /&gt;
!  Last system version this flaw was checked for&lt;br /&gt;
!  Timeframe this was discovered&lt;br /&gt;
!  Public disclosure timeframe&lt;br /&gt;
!  Discovered by&lt;br /&gt;
|-&lt;br /&gt;
| Syscall Infoleaks&lt;br /&gt;
| Many syscalls leaked kernel pointers on sad paths (for example svcSetHeapSize and svcQueryMemory), until they landed a bunch of fixes in 2.0.0.&lt;br /&gt;
| Nothing really.&lt;br /&gt;
| [[2.0.0]]&lt;br /&gt;
| [[2.0.0]]&lt;br /&gt;
| &lt;br /&gt;
| 2017&lt;br /&gt;
| Everyone&lt;br /&gt;
|-&lt;br /&gt;
| svcWaitSynchronization/svcReplyAndReceive bad cleanup on error&lt;br /&gt;
| If there is a page fault when fetching handles from the userspace array, it cleans up by dereferencing all objects despite having only loaded first N. Allows the attacker to make arbitrary decrefs on any kernel synchronization object, and thus can be used to get UAF. Haven&#039;t actually been tried on real HW though, but should work (tm).&lt;br /&gt;
| Kernel code execution&lt;br /&gt;
| [[2.0.0]]&lt;br /&gt;
| [[2.0.0]]&lt;br /&gt;
| &lt;br /&gt;
| April 24, 2017&lt;br /&gt;
| [[User:qlutoo|qlutoo]]&lt;br /&gt;
|-&lt;br /&gt;
| Bad irq_id check in CreateInterruptEvent&lt;br /&gt;
| CreateInterruptEvent syscall is designed to work only for irq_id &amp;gt;= 32. All irq_ids &amp;lt; 32 are &amp;quot;per-core&amp;quot; and reserved for kernel use (watchdog/scheduling/core communications).&lt;br /&gt;
On 1.0.0 you could supply irq_id &amp;lt; 32 and it would write outside the SharedIrqs table.&lt;br /&gt;
| You can register irq&#039;s in the Core3Irqs table, and thus register per-core irqs for core3, that are normally reserved for kernel. Useless.&lt;br /&gt;
| [[2.0.0]]&lt;br /&gt;
| [[2.0.0]]&lt;br /&gt;
| October 2017&lt;br /&gt;
| October 17, 2017&lt;br /&gt;
| [[User:qlutoo|qlutoo]]&lt;br /&gt;
|-&lt;br /&gt;
| Kernel .text mapped executable in usermode&lt;br /&gt;
| Prior to [[3.0.2]] the kernel .text was [[Memory_layout|mapped]] in usermode as executable. This can be used for usermode ROP for bypassing ASLR, but SVCs/IPC are not usable by running kernel .text in usermode.&lt;br /&gt;
| Executing kernel .text in usermode&lt;br /&gt;
| [[3.0.2]]&lt;br /&gt;
| [[3.0.2]]&lt;br /&gt;
| &lt;br /&gt;
| December 28, 2017 (34c3)&lt;br /&gt;
| [[User:qlutoo|qlutoo]]&lt;br /&gt;
|-&lt;br /&gt;
| Memory Controller not properly secured&lt;br /&gt;
| The Switch OS originally had the memory controller not set to be accessible only by the secure-world, which was problematic because insecure access can compromise the kernel.&lt;br /&gt;
&lt;br /&gt;
This was fixed partially in [[2.0.0]] by blacklisting the memory controller from being mapped by user-processes, and was fixed entirely in [[4.0.0]] by making the memory controller TZ-only and making all kernel accesses go through [[SMC|smcReadWriteRegister]].&lt;br /&gt;
| With some way to access the memory controller MMIO, arbitrary kernel code execution.&lt;br /&gt;
| [[4.0.0]]&lt;br /&gt;
| [[4.0.0]]&lt;br /&gt;
| January 2018&lt;br /&gt;
| January 2018&lt;br /&gt;
| [[User:SciresM|SciresM]], [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| Potential [[SVC|svcWaitForAddress]] thread use-after-free&lt;br /&gt;
| Between [[4.0.0]], where svcWaitForAddress was introduced, and [[7.0.0]], there was a second intrusive rbtree node in KThread for the WaitForAddress tree (the key being (address, priority), sorted lexicographically). Unlike the WaitProcessWideKeyAtomic tree, the kernel forgot to reinsert the WaitForAddress node when the thread&#039;s priority changed (priority inheritance and/or SetPriority), breaking the rbtree invariants; and since the kernel walks through the entire tree to remove intrusive nodes, you could cause threads to stay in the tree even after their deletion.&lt;br /&gt;
&lt;br /&gt;
[[7.0.0]] fixed the issue by using the same intrusive node for both trees. The thread/node knows which tree it is in, and the latter is correctly updated when thread priority changes.&lt;br /&gt;
| It unluckily didn&#039;t look exploitable&lt;br /&gt;
| [[7.0.0]]&lt;br /&gt;
| [[7.0.0]]&lt;br /&gt;
| July 2018&lt;br /&gt;
| February 2019&lt;br /&gt;
| [[User:TuxSH|TuxSH]]&lt;br /&gt;
|-&lt;br /&gt;
| Kernel RWX identity mapping never unmapped&lt;br /&gt;
| During init, the kernel binary is identity-mapped as RWX at 0x80060000; this is necessary to facilitate the transitionary period while the MMU is being enabled but mappings for e.g. KASLR are not yet determined, and also to enable smooth MMU enable transition during wake-from-sleep.&lt;br /&gt;
&lt;br /&gt;
However, the identity mapping was never unmapped, and thus the whole kernel code bin remained permanently mapped as RWX for all kernel threads (any thread which does not have an owner process and thus uses the KSupervisorPageTable TTBR0).&lt;br /&gt;
&lt;br /&gt;
Thus, any theoretical exploit which would give kernel memory corruption or ROP under a kernel thread would allow making use of this mapping to modify kernel text + bypass KASLR.&lt;br /&gt;
&lt;br /&gt;
This was fixed in [[16.0.0]] by unmapping the identity-mapping during init, and re identity-mapping only the very first page of kernel .text as R-X (for use by wake-from-sleep), which fixes the shellcode problem and mostly fixes the ROP problem, since this page mostly lacks interesting gadgets.&lt;br /&gt;
| In theory, with another exploitable kernel memory corruption (or ROP under kernel thread) bug: bypassing KASLR + modifying kernel .text. &lt;br /&gt;
&lt;br /&gt;
However, no such bugs are known.&lt;br /&gt;
| [[16.0.0]]&lt;br /&gt;
| [[16.0.0]]&lt;br /&gt;
| Summer 2018&lt;br /&gt;
| February 2023&lt;br /&gt;
| Everyone&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== BootImagePackage System Modules ==&lt;br /&gt;
Flaws in this category pertain to any of the [[Package2#Section_1|built-in system modules]].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Summary&lt;br /&gt;
!  Description&lt;br /&gt;
!  Successful exploitation result&lt;br /&gt;
!  Fixed in system version&lt;br /&gt;
!  Last system version this flaw was checked for&lt;br /&gt;
!  Timeframe this was discovered&lt;br /&gt;
!  Public disclosure timeframe&lt;br /&gt;
!  Discovered by&lt;br /&gt;
|-&lt;br /&gt;
| Service access control bypass (sm:h, smhax, probably other names)&lt;br /&gt;
| Prior to [[3.0.1]], the &#039;&#039;service manager&#039;&#039; (sm) built-in system module treats a user as though it has full permissions if the user creates a new &amp;quot;sm:&amp;quot; port session but bypasses [[Services_API#Initialize|initialization]]. This is due to the other sm commands skipping the service ACL check for Pids &amp;lt;= 7 (i.e. all kernel bundled modules) and that skipping the initialization command leaves the Pid field uninitialized.&lt;br /&gt;
In [[3.0.1]], sm returns error code 0x415 if [[Services_API#Initialize|Initialize]] has not been called yet.&lt;br /&gt;
| Acquiring, registering, and unregistering arbitrary services&lt;br /&gt;
| [[3.0.1]]&lt;br /&gt;
| [[3.0.1]]&lt;br /&gt;
| May 2017&lt;br /&gt;
| August 17, 2017&lt;br /&gt;
| Everyone&lt;br /&gt;
|-&lt;br /&gt;
| Overly permissive SPL service&lt;br /&gt;
| The concept behind the switch&#039;s [[SMC|Secure Monitor]] is that all cryptographic keydata is located in userspace, but stored as &amp;quot;access keys&amp;quot; encrypted with &amp;quot;keks&amp;quot; that never leave TrustZone. The [[SPL services|spl]] (&amp;quot;security processor liaison&amp;quot;?) service serves as an interface between the rest of the system and the secure monitor. Prior to [[4.0.0]], spl exposed only a single service &amp;quot;spl:&amp;quot;, which provided all TrustZone wrapper functions to all sysmodules with access to it. Thus anyone with access to the spl: service (via smhax or by pwning a sysmodule with access) could do crypto with any access keys they knew. &lt;br /&gt;
&lt;br /&gt;
This was fixed in [[4.0.0]] by splitting spl: into spl:, spl:mig, spl:ssl, spl:es, and spl:fs.&lt;br /&gt;
| Arbitrary spl: crypto with any access keys one knows. For example, one could use the SSL module&#039;s access keys to decrypt their console&#039;s SSL certificate private key without having to pwn the SSL sysmodule.&lt;br /&gt;
| [[4.0.0]]&lt;br /&gt;
| [[4.0.0]]&lt;br /&gt;
| Summer 2017 (after smhax was discovered).&lt;br /&gt;
| December 23, 2017&lt;br /&gt;
| Everyone&lt;br /&gt;
|-&lt;br /&gt;
| Single session services not really single session&lt;br /&gt;
| Several &amp;quot;critical&amp;quot; services (like fsp-ldr, fsp-pr, sm:m, etc) are meant to only ever hold a single session with a specific sysmodule. However, when a sysmodule dies, all its service session handles are released -- and thus killing the holder of a single session handle would allow one (via sm:hax etc) to get access to that service. &lt;br /&gt;
&lt;br /&gt;
This was fixed in [[4.0.0]] by adding a semaphore to these critical single-session services, so that even if one gets access to them an error code will be returned when attempting to use any of their commands.&lt;br /&gt;
| With some way to access these services and kill their session holders (like expLDR): dumping sysmodule code, arbitrary service access, elevated filesystem permissions, etc.&lt;br /&gt;
| [[4.0.0]]&lt;br /&gt;
| [[4.0.0]]&lt;br /&gt;
| May/June 2017 (basically immediately after smhax was discovered)&lt;br /&gt;
| December 30, 2017&lt;br /&gt;
| Everyone&lt;br /&gt;
|-&lt;br /&gt;
| nspwn&lt;br /&gt;
| fsp-ldr command 0 &amp;quot;MountCode&amp;quot; takes in a Content Path (retrieved from NCM by Loader), and returns an IFileSystem for the resulting ExeFS. These content paths, are normally NCAs, but MountCode also supports a number of other formats, including &amp;quot;.nsp&amp;quot; -- which is just a PFS0.&lt;br /&gt;
&lt;br /&gt;
When a path ending in &amp;quot;.nsp&amp;quot; is parsed by MountCode, the PFS0 is treated as a raw ExeFS. Because there is no NCA header, the ACID signatures are not validated -- and because there are no other signatures in a PFS0, this results in no signature checking happening at all.&lt;br /&gt;
&lt;br /&gt;
The actual .nsp handling is eventually done by {content mounting function} called by MountCode and other FS commands.&lt;br /&gt;
&lt;br /&gt;
Thus, by placing an ExeFS (NSOs + &amp;quot;main.npdm&amp;quot;) and setting one&#039;s desired title ID to &amp;quot;@Sdcard:/some_title.nsp&amp;quot; or &amp;quot;@User:/some_title.nsp&amp;quot; etc one can launch arbitrary unsigned code, with arbitrary unsigned NPDMs.&lt;br /&gt;
&lt;br /&gt;
This appears to have been fixed by only allowing .nsp when the input fstype==7 for the internal content-mounting function, returning 0x2EE202 otherwise.&lt;br /&gt;
| With access to &amp;quot;lr&amp;quot;: Arbitrary code execution with full system privileges.&lt;br /&gt;
| [[5.0.0]]&lt;br /&gt;
| [[5.0.0]]&lt;br /&gt;
| Late 2017&lt;br /&gt;
| April 23, 2018&lt;br /&gt;
| Everyone&lt;br /&gt;
|-&lt;br /&gt;
| Single null-byte stack overflow in Loader ContentPath parsing&lt;br /&gt;
| Previously, loader content path parsing looked like this, where path_from_lr was up to 0x300 bytes and not necessarily null-terminated:&lt;br /&gt;
&lt;br /&gt;
  char nca_path[0x300] = {0};&lt;br /&gt;
  strcat(nca_path, path_from_lr);&lt;br /&gt;
  for (int i = 0; nca_path[i]; i++) {&lt;br /&gt;
      if (nca_path[i] == &#039;\\&#039;) { nca_path[i] = &#039;/&#039;); }&lt;br /&gt;
  }&lt;br /&gt;
&lt;br /&gt;
Thus, a content path of the maximum length (0x300 bytes) would result in strcat writing a NULL terminator past the end of the nca_path buffer.&lt;br /&gt;
&lt;br /&gt;
This was fixed in [[6.0.0]], the new code looks like this:&lt;br /&gt;
&lt;br /&gt;
  char nca_path[0x300];&lt;br /&gt;
  strncpy(nca_path, path_from_lr, sizeof(nca_path));&lt;br /&gt;
  for (int i = 0; i  &amp;lt; sizeof(nca_path) &amp;amp;&amp;amp; nca_path[i]; i++) {&lt;br /&gt;
      if (nca_path[i] == &#039;\\&#039;) { nca_path[i] = &#039;/&#039;); }&lt;br /&gt;
  }&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| With access to &amp;quot;lr&amp;quot;: single null-byte stack overflow in Loader. Maybe (but probably not) loader code execution.&lt;br /&gt;
| [[6.0.0]]&lt;br /&gt;
| [[6.0.0]]&lt;br /&gt;
| September 2, 2018&lt;br /&gt;
| September 19, 2018&lt;br /&gt;
| [[User:SciresM|SciresM]]&lt;br /&gt;
|-&lt;br /&gt;
| System modules vulnerable to selective downgrade attacks&lt;br /&gt;
| Horizon has no mechanism for specifying the specific title version to Loader on process creation.&lt;br /&gt;
&lt;br /&gt;
Observing this, one can note that after a system update one could install a downgraded version of a specific system module (e.g. nvservices) while leaving the rest of the OS at the same version.&lt;br /&gt;
&lt;br /&gt;
Unless there was some breaking API change, this allows one to make a console vulnerable once more to an exploit in a sysmodule by downgrading it and nothing else.&lt;br /&gt;
&lt;br /&gt;
This was fixed in [[8.1.0]] by incrementing a version field in NPDM, and checking it against a hardcoded list for certain titles in Loader&#039;s process creation func.&lt;br /&gt;
| With access to content installation commands (or a vulnerable lower version to selectively install newer titles), reintroducing bugs in vulnerable system modules on newer firmware versions.&lt;br /&gt;
| [[8.1.0]]&lt;br /&gt;
| [[8.1.0]]&lt;br /&gt;
| When FIRM was first dumped in 2017.&lt;br /&gt;
| June 17, 2019&lt;br /&gt;
| Everyone&lt;br /&gt;
|-&lt;br /&gt;
| Broken RNG for [[Loader_services|Loader]] ASLR&lt;br /&gt;
| The RNG used for generating the ASLR slide is only seeded with 32bits, with the data from [[SVC|svcGetInfo]]. Hence, one could bruteforce the seed if one has infoleaks from any programs. This can be successfully bruteforced with at least 2 sample codebin addrs from different programs (with only 1 sample a lot of invalid seeds are found), however in some cases more than 1 seed might be found.&lt;br /&gt;
&lt;br /&gt;
With [15.0.0+] Loader now uses csrng_GenerateRandomBytes for determining the ASLR slide.&lt;br /&gt;
&lt;br /&gt;
See also [https://github.com/switchbrew/loader-aslr-solver loader-aslr-solver].&lt;br /&gt;
| Breaking ASLR for all non-KIP processes, allowing predicting the main-codebin base addr for all non-KIP processes until the next reboot.&lt;br /&gt;
| [[15.0.0]]&lt;br /&gt;
| [[15.0.0]]&lt;br /&gt;
| January 30, 2022 (presumably found much earlier?)&lt;br /&gt;
| October 11, 2022&lt;br /&gt;
| Everyone&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== System Modules ==&lt;br /&gt;
Flaws in this category pertain to any non-built-in system module.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Summary&lt;br /&gt;
!  Description&lt;br /&gt;
!  Successful exploitation result&lt;br /&gt;
!  Fixed in system version&lt;br /&gt;
!  Last system version this flaw was checked for&lt;br /&gt;
!  Timeframe this was discovered&lt;br /&gt;
!  Public disclosure timeframe&lt;br /&gt;
!  Discovered by&lt;br /&gt;
|-&lt;br /&gt;
| OOB Read in NS system module (pl:utoohax, pl:utonium, maybe other names)&lt;br /&gt;
| Prior to [[3.0.0]], pl:u (Shared Font services implemented in the NS sysmodule) service commands 1,2,3 took in a signed 32-bit index and returned that index of an array but did not check that index at all. This allowed for an arbitrary read within a 34-bit range (33-bit signed) from NS .bss. In [[3.0.0]], sending out of range indexes causes error code 0x60A to be returned.&lt;br /&gt;
| Dumping full NS .text, .rodata and .data, infoleak, etc&lt;br /&gt;
| [[3.0.0]]&lt;br /&gt;
| [[3.0.0]]&lt;br /&gt;
| April 2017&lt;br /&gt;
| June 19, 2017&lt;br /&gt;
| [[User:qlutoo|qlutoo]], ReSwitched Team (independently)&lt;br /&gt;
|-&lt;br /&gt;
| Unchecked domain ID in common IPC code&lt;br /&gt;
| Prior to [[2.0.0]], object IDs in [[IPC_Marshalling#Domain_message|domain messages]] are not bounds checked. This out-of-bounds read could be exploited to brute-force ASLR and get PC control in some services that support domain messages.&lt;br /&gt;
|&lt;br /&gt;
| [[2.0.0]]&lt;br /&gt;
| [[2.0.0]]&lt;br /&gt;
| July 2017&lt;br /&gt;
| July 20, 2017‎&lt;br /&gt;
| [[User:hthh|hthh]]&lt;br /&gt;
|-&lt;br /&gt;
| Out-of-bounds array read for [[BCAT_Content_Container]] secret-data index&lt;br /&gt;
| The [[BCAT_Content_Container]] secret-data index is not validated at all. This is handled before the RSA-signature(?) is ever used. Since the field is an u8, a total of 0x800-bytes relative to the array start can be accessed.&lt;br /&gt;
This is not useful since the string loaded from this array is only involved with key-generation.&lt;br /&gt;
| &lt;br /&gt;
| Unknown&lt;br /&gt;
| [[2.0.0]]&lt;br /&gt;
| August 4, 2017&lt;br /&gt;
| August 6, 2017&lt;br /&gt;
| [[User: shinyquagsire23|Shiny Quagsire]], [[User:Yellows8|yellows8]] (independently)&lt;br /&gt;
|-&lt;br /&gt;
| expLDR (sysmodule handle table exhaustion)&lt;br /&gt;
| Most sysmodules share common template code to handle IPC control messages. The command DuplicateSession (type 5 command 2)&#039;s template code will abort() if it fails to duplicate a session&#039;s handle for the requester. Because many sysmodules have limited handle table size (smaller than the browser/other entrypoints), repeatedly requesting to duplicate one&#039;s session will cause the sysmodule to run out of handle table space and abort, causing the service to release all its handles cleanly.&lt;br /&gt;
| Sysmodule crashes.  Most usefully, crashing ldr allows access to fsp-ldr and crashing pm allows access to fsp-pr. Useless after [[4.0.0]], which mitigated a number of single-session service access issues.&lt;br /&gt;
| Unfixed&lt;br /&gt;
| [[4.1.0]]&lt;br /&gt;
| June 24, 2017&lt;br /&gt;
| March 8, 2018&lt;br /&gt;
| [[User:daeken|daeken]]&lt;br /&gt;
|-&lt;br /&gt;
| Transfer Memory leak in nvservices system module&lt;br /&gt;
| The nvservices sysmodule does not clear most of its transfer memory prior to release.&lt;br /&gt;
| The calling process can read key bits of memory, including breaking ASLR (by revealing the image base) and exposing the address of other transfer memory to set up attacks. More details here: [https://daeken.svbtle.com/nintendo-switch-nvservices-info-leak transfermeme (nvservices info leak)] by [[User:daeken|daeken]]&lt;br /&gt;
| [[6.0.0]]&lt;br /&gt;
| [[6.0.0]]&lt;br /&gt;
| June 2017&lt;br /&gt;
| October 16, 2018&lt;br /&gt;
| [[User:qlutoo|qlutoo]] and [[User:hexkyz|hexkyz]],&lt;br /&gt;
[[User:daeken|daeken]] (independently)&lt;br /&gt;
|-&lt;br /&gt;
| OOB write in audio system module&lt;br /&gt;
| Prior to [[2.0.0]], the [[Audio_services#audout:u|AppendAudioOutBuffer]] and [[Audio_services#audin:u|AppendAudioInBuffer]] IPC commands would blindly increment the appended buffers&#039; count while using said count value as an index to where the user data should be copied into. This resulted in an 0x28 bytes, user controlled, out-of-bounds memory write into the [[Audio_services|audio]] sysmodule&#039;s memory space.&lt;br /&gt;
Combined with the [[Audio_services#audout:u|GetReleasedAudioOutBuffer]] or [[Audio_services#audin:u|GetReleasedAudioInBuffer]] commands, this could also be used as an 8 byte infoleak.&lt;br /&gt;
&lt;br /&gt;
In [[2.0.0]], the commands now return error code 0x1099 if the number of unreleased buffers exceeds 0x1F.&lt;br /&gt;
| Code execution under audio sysmodule&lt;br /&gt;
| [[2.0.0]]&lt;br /&gt;
| [[2.0.0]]&lt;br /&gt;
| &lt;br /&gt;
| November 2, 2018&lt;br /&gt;
| [[User:hexkyz|hexkyz]], probably others (independently).&lt;br /&gt;
|-&lt;br /&gt;
| Infoleak in nvservices system module&lt;br /&gt;
| The [[NV_services|nvservices]] ioctl [[NV_services#NVMAP_IOC_ALLOC|NVMAP_IOC_ALLOC]] takes an optional argument &amp;quot;addr&amp;quot; which allows the calling process to pass a pointer to user allocated memory for backing a nvmap object. If &amp;quot;addr&amp;quot; is left as 0, nvservices uses the transfer memory region (donated by the user during initialization) instead, when allocating memory for the nvmap object.&lt;br /&gt;
By design, freeing the nvmap object by calling the ioctl [[NV_services#NVMAP_IOC_FREE|NVMAP_IOC_FREE]] returns, in its &amp;quot;refcount&amp;quot; argument, the user address previously supplied if the reference count reaches 0.&lt;br /&gt;
However, prior to [[6.2.0]], the case where the transfer memory region is used to allocate the nvmap object was not taken into account, thus resulting in [[NV_services#NVMAP_IOC_FREE|NVMAP_IOC_FREE]] leaking back an address from within the transfer memory region mapped in nvservices&#039; memory space.&lt;br /&gt;
&lt;br /&gt;
In [[6.2.0]], [[NV_services#NVMAP_IOC_FREE|NVMAP_IOC_FREE]] no longer returns the address when the transfer memory region is used instead of user supplied memory.&lt;br /&gt;
| Combined with other vulnerabilities: Defeating ASLR in nvservices sysmodule.&lt;br /&gt;
| [[6.2.0]]&lt;br /&gt;
| [[6.2.0]]&lt;br /&gt;
| April 2017&lt;br /&gt;
| November 24, 2018&lt;br /&gt;
| Everyone&lt;br /&gt;
|-&lt;br /&gt;
| nvhax (memory corruption in nvservices system module)&lt;br /&gt;
| Prior to [[6.2.0]], the [[NV_services|nvservices]] ioctl [[NV_services#.2Fdev.2Fnvhost-ctrl-gpu|NVGPU_GPU_IOCTL_WAIT_FOR_PAUSE]] would take a single &amp;quot;pwarpstate&amp;quot; argument which would be interpreted by nvservices as a memory pointer for writing 2 &amp;quot;warpstate&amp;quot; structs (one for each Streaming Multiprocessor).&lt;br /&gt;
This resulted in nvservices attempting to blindly memcpy into this user supplied address and trigger a crash. However, if paired with an infoleak, this could be used to arbitrarily write 0x30 bytes anywhere in nvservices&#039; memory space.&lt;br /&gt;
Additionally, the &amp;quot;warpstate&amp;quot; struct itself was never initialized, which means nvservices would leak the 0x30 bytes from the stack. By invoking other ioctls it was also possible to partially control the stack contents and achieve a usable arbitrary memory write primitive.&lt;br /&gt;
&lt;br /&gt;
In [[6.2.0]], [[NV_services#.2Fdev.2Fnvhost-ctrl-gpu|NVGPU_GPU_IOCTL_WAIT_FOR_PAUSE]] now takes 2 inline &amp;quot;warpstate&amp;quot; structs instead of a &amp;quot;pwarpstate&amp;quot; pointer, thus effectively avoiding the bad memcpy.&lt;br /&gt;
| Code execution under nvservices sysmodule&lt;br /&gt;
| [[6.2.0]]&lt;br /&gt;
| [[6.2.0]]&lt;br /&gt;
| April 5, 2017&lt;br /&gt;
| November 24, 2018&lt;br /&gt;
| [[User:hexkyz|hexkyz]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Applet_Manager_services#IStorage|AM IStorage]] infoleak&lt;br /&gt;
| Originally the buffer allocated by [[Applet_Manager_services#CreateStorage|CreateStorage]] using the specified input size was not cleared. With [8.0.0+] this was fixed by adding a memset() for the buffer after successful allocation.&lt;br /&gt;
&lt;br /&gt;
Hence, IStorage-&amp;gt;IStorageAccessor-&amp;gt;Read will return uninitialized memory when the Write cmd was not previously used with the specified region.&lt;br /&gt;
| Infoleak from the main [[Applet_Manager_services#IStorage|AM]] heap, allowing defeating ASLR by reading addresses from previously allocated objects.&lt;br /&gt;
| [[8.0.0]]&lt;br /&gt;
| [[8.1.0]]&lt;br /&gt;
| December 2018&lt;br /&gt;
| August 9, 2019&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[HID_services#hid:sys|hid:sys]] ButtonConfig s32 array-index not validated&lt;br /&gt;
| The input s32 array-index for [[HID_services#hid:sys|hid:sys]] ButtonConfig cmds 1255-1270 was originally not validated. Using a negative or &amp;gt;=5 index results in accessing out-of-bounds data, with an array stored on stack.&lt;br /&gt;
[10.1.0-10.2.0] Each of these cmds will now Abort if the s32 is negative or &amp;gt;=5. [11.0.0+] Now an unsigned compare is used, with 0 or an error being immediately returned when the value is invalid.&lt;br /&gt;
| hid infoleak, out-of-bounds mem-write anywhere in hid address-space relative to the stack array (with constraints on the data).&lt;br /&gt;
| [[10.1.0]]&lt;br /&gt;
| [[11.0.1]]&lt;br /&gt;
| April 18, 2020&lt;br /&gt;
| July 14, 2020&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Bluetooth_Driver_services|Bluetooth]] sdp_server.cc process_service_search() continuation request p_req validation&lt;br /&gt;
| With [5.0.0+], the following was added to the if-block prior to loading cont_offset from p_req: &amp;lt;code&amp;gt;(p_req + sizeof(cont_offset) &amp;gt; p_req_end)&amp;lt;/code&amp;gt; (which verifies that cont_offset is within message bounds).&lt;br /&gt;
| Bluetooth-sysmodule out-of-bounds read from heap, probably not useful since the read value must match a state field, etc.&lt;br /&gt;
| [[5.0.0]]&lt;br /&gt;
| [[11.0.0]]&lt;br /&gt;
| Switch: December 2020&lt;br /&gt;
| Switch: December 25, 2020&lt;br /&gt;
| Switch: [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Bluetooth_Driver_services|Bluetooth]] A-63146698&lt;br /&gt;
| [https://android.googlesource.com/platform/system/bt/+/226ea26684d4cd609a5b456d3d2cc762453c2d75 A-63146698] / CVE-2017-0785. See also [https://info.armis.com/rs/645-PDC-047/images/BlueBorne%20Technical%20White%20Paper_20171130.pdf here].&lt;br /&gt;
| Bluetooth-sysmodule stack infoleak, which allows defeating ASLR (note: not tested on hw).&lt;br /&gt;
| [[5.0.0]]&lt;br /&gt;
| [[11.0.0]]&lt;br /&gt;
| Switch: December 2020&lt;br /&gt;
| Switch: December 25, 2020&lt;br /&gt;
| Switch: [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Bluetooth_Driver_services|bluetooth]] GetAdapterProperty/SetAdapterProperty unchecked memcpy size&lt;br /&gt;
| GetAdapterProperty copies data from stack to the output buffer using the buffer size, without checking the size (when not handling the Name type). SetAdapterProperty copies data to stack from the input buffer using the buffer size, without checking the size.&lt;br /&gt;
This requires access to the btdrv service, only hid and btm have access.&lt;br /&gt;
&lt;br /&gt;
This was fixed with [[12.0.0]] by replacing the buffer data with a fixed-size-struct.&lt;br /&gt;
| Stack infoleak with GetAdapterProperty, stack buffer overflow (and hence ROP) with SetAdapterProperty.&lt;br /&gt;
| [[12.0.0]]&lt;br /&gt;
| [[12.0.0]]&lt;br /&gt;
| July 17, 2020&lt;br /&gt;
| April 7, 2021&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Bluetooth_Driver_services|bluetooth]] stack buffer overflow with HID DATA packets&lt;br /&gt;
| The BSA (bt-stack) func bta_hh_co_data copies data from a HID DATA packet to stack without checking the size, then sends it over Uipc. [7.0.0+] The user Uipc callback also copies the input data to stack without checking the size, then sends it to the sharedmem CircularBuffer.&lt;br /&gt;
With [12.0.2+] this was fixed in bta_hh_co_data by clamping the size to a maximum of 0x2BB. The aforementioned buffer overflow in the Uipc callback can&#039;t be triggered since at that point the size was already clamped.&lt;br /&gt;
&lt;br /&gt;
Before this bta_hh_co_data func is reached, there is no validation of the size (such as comparing against the L2CAP MTU) when Basic Mode is being used.&lt;br /&gt;
&lt;br /&gt;
Actually triggering this requires using a data-size larger than the normal L2CAP MTU. This can be done by for example, using raw HCI to send the packet from the remote bluetooth device.&lt;br /&gt;
&lt;br /&gt;
Note that when the remote device is configured as an audio device for [12.0.0+] where [[Settings_services#BluetoothDevicesSettings|BluetoothDevicesSettings]].TrustedServices was only ever set for audio since system-boot, it is not possible for the remote device to connect to the Switch for HID.&lt;br /&gt;
| ROP under [[Bluetooth_Driver_services|bluetooth]] via HID DATA packet sent by a paired HID bluetooth device. This can be triggered at any time while not in sleep-mode, when not in airplane-mode. The earliest is while the Nintendo Switch logo screen is displayed during system boot.&lt;br /&gt;
| [[12.0.2]]&lt;br /&gt;
| [[12.0.2]]&lt;br /&gt;
| July-August 2020&lt;br /&gt;
| May 11, 2021&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Bluetooth_Driver_services|bluetooth]] WriteHidData/WriteHidData2/SetHidReport unchecked memcpy size&lt;br /&gt;
| WriteHidData/SetHidReport copies the input struct to stack, then passes it to the funcptr/vfunc call. WriteHidData2 passes the input buffer addr directly to the funcptr/vfunc call. The called func eventually copies the input data to the stack struct using the specified size without validating it.&lt;br /&gt;
This requires access to the btdrv service, only hid and btm have access.&lt;br /&gt;
&lt;br /&gt;
This was fixed with [[12.1.0]] in WriteHidData/SetHidReport by doing a fixed-size copy into another tmp struct, with the size field being clamped to a maximum of 0x2BB afterwards. This struct is then used when calling the vfunc. The vfuncs called by WriteHidData/WriteHidData2/SetHidReport were also updated to clamp the size to the required maximum value.&lt;br /&gt;
| Stack buffer overflow&lt;br /&gt;
| [[12.1.0]]&lt;br /&gt;
| [[12.1.0]]&lt;br /&gt;
| July 16, 2020&lt;br /&gt;
| July 6, 2021&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| Infoleak with [[HID_services|hid:sys]] SetButtonConfigStorage{name}Deprecated&lt;br /&gt;
| These cmds pass a stack ptr for the StorageName when calling the internal func. Nothing is written to this StorageName. Hence, stack infoleak (data is copied as a NUL-terminated string), which can be later read by the GetButtonConfigStorage{name} cmds.&lt;br /&gt;
&lt;br /&gt;
This was fixed by removing the Deprecated cmds in [[13.0.0]].&lt;br /&gt;
| Infoleak of hid stack from a StorageName readable via GetButtonConfigStorage{name}, up to the NUL-terminator.&lt;br /&gt;
| [[13.0.0]]&lt;br /&gt;
| [[13.0.0]]&lt;br /&gt;
| December 11, 2020&lt;br /&gt;
| September 27, 2021&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Bluetooth_Driver_services|bluetooth]] EventInfo infoleak&lt;br /&gt;
| The various funcs which send messages to the thread which handles writing to EventInfo, didn&#039;t clear the stack msgbuf. Hence, the various get-EventInfo cmds could return leaked stack data. This likely affected most (?) get-EventInfo cmds, besides CircularBuffer-GetHidReportEventInfo.&lt;br /&gt;
&lt;br /&gt;
This only matters for events where there&#039;s uninitialized regions of the EventInfo, such as events with variable-size data without a memset.&lt;br /&gt;
&lt;br /&gt;
This was fixed by clearing the msgbuf in a number of funcs.&lt;br /&gt;
| Bluetooth-sysmodule stack infoleak, which allows defeating ASLR&lt;br /&gt;
| [[13.0.0]]&lt;br /&gt;
| [[13.1.0]]&lt;br /&gt;
| &lt;br /&gt;
| During initial [[13.0.0|diff]]. Added to this page on: December 12, 2021&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[SSL_services|ssl]] CVE-2021-43527&lt;br /&gt;
| CVE-2021-43527, see also [https://bugs.chromium.org/p/project-zero/issues/detail?id=2237 here] and [https://googleprojectzero.blogspot.com/2021/12/this-shouldnt-have-happened.html here].&lt;br /&gt;
Using BigSig where the server cert sig is RSA-PSS results in the remote server throwing {no shared cipher} error when Switch connects. If however one creates a rootCA using BigSig (RSA-PSS), which then signs a server cert where the server key is RSA (not PSS), the vuln can be triggered (if the rootCA is trusted, via using the import service-cmd). It&#039;s unknown whether there&#039;s other ways to trigger the vuln.&lt;br /&gt;
&lt;br /&gt;
The crash occurs in VFY_Begin when using the previously overwritten data. A bitsize of &amp;lt;code&amp;gt;$((16384 + 32 + 64 + 64 + 64))&amp;lt;/code&amp;gt; is only enough to overwrite cx-&amp;gt;hashcx, to fully overwrite cx-&amp;gt;hashobj an additional 0xC-bytes (additional 96 bits) is needed.&lt;br /&gt;
Note that partial overwrite isn&#039;t an option: this is the func that initializes those fields to begin with, it just does deinit first before initializing hashcx/hashobj (prior to that these fields would be all-zero when not overwritten by the buf-overflow).&lt;br /&gt;
| Heap buffer overflow in [[SSL_services|ssl]], overwriting data including a ptr to an object which is later used to load a funcptr.&lt;br /&gt;
| [[13.2.1]]&lt;br /&gt;
| [[13.2.1]]&lt;br /&gt;
| Switch: December 1-2, 2021&lt;br /&gt;
| Switch: January 19, 2022&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| [[Bluetooth_Driver_services|bluetooth]] BSA gatt_process_notification stack buffer overflow&lt;br /&gt;
| gatt_process_notification is the GATT handler for processing notification/indication messages. gatt_process_notification does memcpy to stack from the input bt msg data, without size validation. The input len param isn&#039;t validated in this func either - if the remaining len following op_code is less than 2, a negative value will be used for the data copy to stack.&lt;br /&gt;
These were fixed by adding a bounds check for the size, size==0 is also checked for now.&lt;br /&gt;
| Bluetooth-sysmodule stack buffer overflow, with data received from a bluetooth message&lt;br /&gt;
| [[13.2.1]]&lt;br /&gt;
| [[13.2.1]]&lt;br /&gt;
| November 2021&lt;br /&gt;
| January 19, 2022&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Applet_Manager_services#IDisplayController|AM IDisplayController]] TakeScreenShotOfOwnLayer OOB&lt;br /&gt;
| The captureBuf is used as an array index without validation. Data used from this array includes calling a funcptr from the array entry, if set. Eventually this is also used to write bools into this array, one of which is from the command input.&lt;br /&gt;
With [5.0.0+] a func is eventually called to get a ptr determined by the input captureBuf, with nullptr being returned for captureBuf&amp;gt;=0x10. The caller will Abort if nullptr was returned.&lt;br /&gt;
| OOB array access&lt;br /&gt;
| [[5.0.0]]&lt;br /&gt;
| [[13.1.0]]&lt;br /&gt;
| ~July 31, 2019&lt;br /&gt;
| January 26, 2022&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Applet_Manager_services#IDisplayController|AM IDisplayController]] ClearCaptureBuffer OOB&lt;br /&gt;
| The captureBuf is used as an array index without proper validation. There is code validating it, but on failure it just skips over a code-block, with code using captureBuf still being used afterwards. Then this is used to write bools into a global array, one of which is from the command input.&lt;br /&gt;
This was fixed with [9.1.0+] by requiring captureBuf = 0-1.&lt;br /&gt;
| OOB bool writes into an array&lt;br /&gt;
| [[9.1.0]]&lt;br /&gt;
| [[13.1.0]]&lt;br /&gt;
| ~July 31, 2019&lt;br /&gt;
| January 26, 2022&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Sockets_services|bsdsockets]] ioctl SIOCGIFCONF infoleak&lt;br /&gt;
| Originally bsd ioctl SIOCGIFCONF was handled by setting the data in IPC outbuf0 to the size/addr of IPC outbuf1. These buffers are HipcAutoSelect, so if buf1 is small enough for HipcPointer (otherwise it would be HipcMapAlias) the IPC-buf-ptr leaked into outbuf0 would be located in the codebin-region. Since this is done before the actual ioctl-handling, it doesn&#039;t matter whether the fd is valid.&lt;br /&gt;
This was fixed in [5.0.0+] by using a tmp struct on stack instead of buf0.&lt;br /&gt;
| bsdsockets-sysmodule codebin-region addr infoleak, which allows defeating ASLR.&lt;br /&gt;
| [[5.0.0]]&lt;br /&gt;
| [[13.1.0]]&lt;br /&gt;
| February 14, 2022 (probably earlier)&lt;br /&gt;
| February 14, 2022&lt;br /&gt;
| [[User:Yellows8|yellows8]], probably others&lt;br /&gt;
|-&lt;br /&gt;
| [[Sockets_services|bsdsockets]] ioctl SIOCGIFMEDIA input can contain ptr&lt;br /&gt;
| Originally bsd ioctl SIOCGIFMEDIA used the user-specified ifmediareq structure directly from the input buffer. This includes a ptr. This ptr probably isn&#039;t actually used?&lt;br /&gt;
With [5.0.0+] the structure used as input for the ioctl was changed to using &amp;lt;code&amp;gt;int ifm_ulist[1]&amp;lt;/code&amp;gt; instead of &amp;lt;code&amp;gt;int *ifm_ulist&amp;lt;/code&amp;gt; (which is unused). The input structure is copied to a tmp struct which is used as the original ifmediareq structure, with ifm_ulist always NULL. The user can still specify a non-zero ifm_count value, however that&#039;s not useful with ifm_ulist being always NULL.&lt;br /&gt;
| Useless?&lt;br /&gt;
| [[5.0.0]]&lt;br /&gt;
| [[13.1.0]]&lt;br /&gt;
| February 14, 2022&lt;br /&gt;
| February 14, 2022&lt;br /&gt;
| [[User:Yellows8|yellows8]], probably others&lt;br /&gt;
|-&lt;br /&gt;
| Infoleak with [[Joy-Con]] HidCommand PairingIn&lt;br /&gt;
| The joycon protocol handler for PairingIn copies data from stack to the response cmd-buf for sending PairingOut. Only the first byte is set to a type value, the rest is uninitialized stack data.&lt;br /&gt;
&lt;br /&gt;
This was fixed with [15.0.0+] by directly writing to the response data without using stack data.&lt;br /&gt;
| Infoleak of hid stack via a bluetooth/uart message+response with a connected hid controller. This returns addrs for the main-codebin/stack, which allows defeating ASLR.&lt;br /&gt;
| [[15.0.0]]&lt;br /&gt;
| [[15.0.0]]&lt;br /&gt;
| September 4, 2020&lt;br /&gt;
| October 10, 2022&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| Broken RNG for [[RO_services|ro]] ASLR&lt;br /&gt;
| The RNG used to determine where to randomly map NROs in the target process was TinyMT (nn::os::detail::RngManager output, seeded by 128 bits of entropy). However, TinyMT is not cryptographically secure (and can in fact be analytically solved). &lt;br /&gt;
&lt;br /&gt;
Thus, with a few NRO mapping addresses, one could learn the TinyMT state and derive all previous/future RNG outputs, breaking NRO aslr for all processes. &lt;br /&gt;
&lt;br /&gt;
With [15.0.0+] ro now uses csrng_GenerateRandomBytes to determine the random map address for NROs.&lt;br /&gt;
| Breaking ASLR for all NROs loaded in all processes, allowing predicting all NRO mappings for all processes until the next reboot.&lt;br /&gt;
| [[15.0.0]]&lt;br /&gt;
| [[15.0.0]]&lt;br /&gt;
| Late 2021/Early 2022&lt;br /&gt;
| October 11, 2022&lt;br /&gt;
| Everyone&lt;br /&gt;
|-&lt;br /&gt;
| Broken RNG used by [[NS_Services|ns]]&lt;br /&gt;
| The code generating the sd seed and the data for the [[SD_Filesystem|sd]] private/private1 file, all use nn::os::GenerateRandomBytes, not csrng. The sd-seed is generated first, then private, then private1. This allows deriving sd-seed from private since this uses TinyMT, as long as the system shipped from factory on [2.0.0+]. private1 is only useful if the system shipped with [4.0.0+].&lt;br /&gt;
&lt;br /&gt;
There&#039;s various other code in ns using nn::os::GenerateRandomBytes as well. This includes the code generating ns_systemseed when it doesn&#039;t exist. ns_systemseed is generated at some point after the various sd-seed-related code (both are called from the same func). Hence, ns_systemseed can be recovered with the above method as well, if it wasn&#039;t recreated at some point without regenerating the above nand-save used with the above.&lt;br /&gt;
&lt;br /&gt;
With [15.0.0+] ns now uses csrng_GenerateRandomBytes for sd-seed/private and ns_systemseed, etc. This only matters when the file is newly generated, which is usually only for factory-fresh systems which ship with this version. This would also apply after being deleted during {System Settings -&amp;gt; Formatting Options -&amp;gt; Initialize Console}, and also with a refurbished console.&lt;br /&gt;
| Generation of a system&#039;s sd-seed allowing decryption of the NAX0 layer of data on [[SD_Filesystem|SD]], derived using the private file from SD. Applies to systems which factory-shipped with a system-version prior to [[15.0.0]] (that is, [2.0.0-14.1.2]).&lt;br /&gt;
| [[15.0.0]], for newly generated files&lt;br /&gt;
| [[15.0.0]]&lt;br /&gt;
| December ~12, 2021&lt;br /&gt;
| October 11, 2022&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Bluetooth_Driver_services|bluetooth]] BSA bsa_sv_av_cback stack buffer overflow&lt;br /&gt;
| bsa_sv_av_cback checks for two input type values (0xC/0xD), on match it copies the input data to stack without size validation. Then it sends an internal request with this data (likewise when the type values don&#039;t match, except the input data is passed directly with a small size), then it returns.&lt;br /&gt;
This requires the AV functionality added with [13.0.0+], however this func is only reachable with [14.0.0+] where the required functionality was enabled.&lt;br /&gt;
&lt;br /&gt;
This requires message data that&#039;s larger than the MTU, so fragmentation must be used, or manually send the ACL data to bypass the MTU.&lt;br /&gt;
&lt;br /&gt;
This can be triggered via an AVRC message with opcode=0x0 (vendor). The above type 0xC is reached via AVRC ctype 0..4, while 0xD is reached with ctype&amp;gt;=0x9.&lt;br /&gt;
&lt;br /&gt;
With [15.0.0+] the size value for the memcpy (which is also written to the request struct) is clamped to a max value.&lt;br /&gt;
| Bluetooth-sysmodule stack buffer overflow on [14.0.0-14.1.2], with data received from an AVRC bluetooth message with a bluetooth-audio device.&lt;br /&gt;
| [[15.0.0]]&lt;br /&gt;
| [[15.0.0]]&lt;br /&gt;
| November 2021&lt;br /&gt;
| October 11, 2022&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[WLAN_services|wlan]] SetMulticastList heap buffer overflow&lt;br /&gt;
| The [[WLAN_services#SetMulticastList|SetMulticastList]] command allocates a 0x31-bytes sized buffer and copies to it as much [[WLAN_services#MacAddress|MacAddress]] values from the input [[WLAN_services#MulticastList|MulticastList]] as specified by the &amp;quot;Count&amp;quot; field, but this field is never validated. &lt;br /&gt;
&lt;br /&gt;
With [15.0.0+] error code 0x1906B is now returned if &amp;quot;Count&amp;quot; is larger than 8.&lt;br /&gt;
| wlan-sysmodule heap buffer overflow.&lt;br /&gt;
| [[15.0.0]]&lt;br /&gt;
| [[15.0.0]]&lt;br /&gt;
| June 6, 2022&lt;br /&gt;
| November 9, 2022&lt;br /&gt;
| [[User:Hexkyz|hexkyz]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Bluetooth_Driver_services|bluetooth]] WriteGattCharacteristic/WriteGattDescriptor stack buffer overflow regression&lt;br /&gt;
| Originally btdrv WriteGattCharacteristic/WriteGattDescriptor (bt service LeClientWriteCharacteristic/LeClientWriteDescriptor are the same) validated the input buffer size. However the size check was removed with [12.0.0+] (which was also when bluetooth was refactored), hence stack buffer overflow. Anything with btdrv/bt services access can trigger it. While this is intended to require a BLE connection, it seems to be possible to trigger the buffer overflow without any BLE connection by passing ConnectionHandle=0xFFFFFFFF (handle not tested on hardware).&lt;br /&gt;
| Bluetooth-sysmodule stack buffer overflow on [12.0.0-15.0.1], with data from BLE IPC cmds.&lt;br /&gt;
| [[16.0.0]]&lt;br /&gt;
| [[16.0.0]]&lt;br /&gt;
| December 10, 2021&lt;br /&gt;
| February 23, 2023&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[JIT_services|JIT]] usability issues&lt;br /&gt;
| CreateJitEnvironment will enter infinite-loops using nn::jitsrv::detail::AslrAllocator::GetAslrRegion when either of the input CodeMemory sizes are zero. Also the second CodeMemory is useless for the user-process since the second addr returned by GetCodeAddress is a dup of the first one, set during state init by CreateJitEnvironment.&lt;br /&gt;
With [14.0.0+] size=0 is now properly handled, and also the state for the second addr from GetCodeAddress is now properly initialized.&lt;br /&gt;
| Minor usability issues, not useful for exploitation (size=0 will cause jit-sysmodule to hang in a loop).&lt;br /&gt;
| [[14.0.0]]&lt;br /&gt;
| [[14.0.0]]&lt;br /&gt;
| October 1, 2020&lt;br /&gt;
| February 26, 2023&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[USB_services|usbhs]] uninitialized IClientEpSession&lt;br /&gt;
| usbhs IClientIfSession OpenUsbEp creates an IClientEpSession object. The allocated object from ExpHeap is not memset, only select fields are cleared. The rest of initialization is done by PopulateRing - however the user-process could skip using that if wanted (official sw always uses it).&lt;br /&gt;
&lt;br /&gt;
ShareReportRing maps tmem and writes the ring buffer/count field into object state. PopulateRing also eventually initializes these fields, with the buffer being allocated from ExpHeap instead of tmem. These fields are not cleared during object creation from OpenUsbEp.&lt;br /&gt;
&lt;br /&gt;
GetXferReport after validating the cmd input, just uses object state assuming it was initialized. This runs code which is the same as the user-process code handling the tmem ringbuf.&lt;br /&gt;
&lt;br /&gt;
Therefore, by skipping using PopulateRing and then using GetXferReport the sysmodule will use an uninitialized ringbuf ptr, and an uninitialized count field. If one could control these fields by doing ExpHeap allocations prior to OpenUsbEp so that {target fields} would be located at {IClientEpSession ring fields}, then one could read usb-sysmodule memory at the target buffer address.&lt;br /&gt;
&lt;br /&gt;
See [[USB_services#ShareReportRing|here]] for ringbuf format. The sysmodule will Abort if read_index is &amp;gt;= {ring count field from object state}. Otherwise it copies an entry from that index to output, and updates read_index.&lt;br /&gt;
&lt;br /&gt;
This is probably tricky to abuse as the ringbuf ptr has to be valid, and {see above} (likewise for write_index when the report-ringbuf-writing func runs).&lt;br /&gt;
&lt;br /&gt;
PostBufferAsync/BatchBufferAsync also use seperate object ring fields which are left uninitialized from OpenUsbEp. Targeting this would be tricky with the ring restrictions - this would allow writing data to a ring addr however.&lt;br /&gt;
&lt;br /&gt;
Pre-4.0.0 (only 2.0.0 checked) is not affected by these. The ring fields in the object are cleared during object creation (no memset of the entire object however). GetXferReport would null-deref if PopulateRing was skipped. PostBufferAsync/BatchBufferAsync will throw an error if PopulateRing was skipped. Pre-4.0.0 also has different ring handling as well.&lt;br /&gt;
&lt;br /&gt;
[16.0.0+] The IClientEpSession init func now clears the remaining previously uninitialized fields. The cmds using the ring fields still don&#039;t check for NULL, so using GetXferReport/PostBufferAsync/BatchBufferAsync without PopulateRing will just trigger null-deref. Even if the ptr were somehow valid but ring-count field was left at 0, this would then Abort due to: &amp;lt;code&amp;gt;if (ring_count &amp;lt;= index_loaded_from_ringptr) &amp;lt;Abort&amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
| [4.0.0-15.0.1] If one can trigger using {target values} as the unintialized fields: memory reads from the target addr with GetXferReport, and memory R/W with PostBufferAsync/BatchBufferAsync. This requires access to usb:hs, and an usb device must be connected which is not being used by {other sessions}. If successful, this might (?) result in usb-sysmodule compromise.&lt;br /&gt;
| [[16.0.0]]&lt;br /&gt;
| [[16.0.0]]&lt;br /&gt;
| January 30, 2023&lt;br /&gt;
| February 26, 2023&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[NS_services|ns]] RequestMoveApplicationEntity/EstimateSizeToMove buffer overflow&lt;br /&gt;
| ns RequestMoveApplicationEntity eventually calls a func which: Loops through the input buffer. If any entry has value 6, it will call another func to copy data from state to output safely (uses the max_count param). Otherwise, it copies the input buffer to an outbuf (located on caller&#039;s stack) without any size validation (inlined memcpy), even though there is a max_count param.&lt;br /&gt;
&lt;br /&gt;
Additional memwrites are also done to the above outbuf following the initial memcopy. This can be avoided if the buffer doesn&#039;t contain bytes with values 3-6 (if using values in that range is really needed, the cmd input StorageId param can be set to the required value so that the specified value doesn&#039;t trigger the memwrite). Value 6 shouldn&#039;t be used anyway (see above).&lt;br /&gt;
&lt;br /&gt;
ns EstimateSizeToMove first calls the same func which does the copy above (outbuf is also located on stack), then it calls another func. Hence, same vuln here.&lt;br /&gt;
&lt;br /&gt;
By corrupting just the first byte of x29 with EstimateSizeToMove, one can obtain infoleaks. This method with x29 essentially only works with [15.0.0+]. Pre-15.0.0 would require a different method with partial overwrite of retaddr, however it&#039;s unknown whether this would actually work for infoleak (would require [12.0.0+] for the stack layout change).&lt;br /&gt;
With EstimateSizeToMove where x29 is overwritten, the output u64 is the leaked ptr (can be codebin-region). Note that the cmd has to return Result=0 for this to work. x29 is used to load the value which is copied to the cmdreply rawdata.&lt;br /&gt;
&lt;br /&gt;
As of [17.0.0+] an error is thrown if the input array count is larger than 8 (size of the stack dst-array).&lt;br /&gt;
| ns-sysmodule stack buffer overflow, allowing ns infoleak+ROP.&lt;br /&gt;
| [[17.0.0]]&lt;br /&gt;
| [[17.0.0]]&lt;br /&gt;
| January 2, 2023&lt;br /&gt;
| October 17, 2023&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[PSC_services|ovln:snd]] OpenSender unvalidated count&lt;br /&gt;
| ovln:snd OpenSender has a count param. This count is used to allocate the specified number of objects in a linked-list for storing the data from Send. If count is 0, the linked-list is left empty, with ptrs to itself within the ISender object.&lt;br /&gt;
&lt;br /&gt;
ISender Send when the above linked-list is empty, runs a switch-statement with &amp;lt;code&amp;gt;(inval&amp;gt;&amp;gt;8)&amp;amp;0xFF&amp;lt;/code&amp;gt;. This uses another linked-list where the ptrs are initially {within ISender obj}.&lt;br /&gt;
No space is allocated in the ISender obj for the linked-list object-data. Therefore using Send with val 1&amp;lt;&amp;lt;8 or 2&amp;lt;&amp;lt;8 (other values throw error) results in the specified input struct being copied into the ISender obj, which then overwrites heap data OOB.&lt;br /&gt;
If for example one used OpenSender again right after the first OpenSender usage, then used Send as described above, this would corrupt the second ISender which includes overwriting the vtable.&lt;br /&gt;
If one would use Send twice in a row like this, the second one would use a corrupted linked-list (written from the first Send). If the linked-list ptrs would be valid (no crash triggered) this would allow one to copy the input data to a controlled addr, though it&#039;s restricted with the linked-list usage.&lt;br /&gt;
&lt;br /&gt;
Using GetUnreceivedMessageCount afterwards is of no interest.&lt;br /&gt;
&lt;br /&gt;
Besides ovln, the only other allocs on this heap is from IPmModule Initialize. This heap is also used for psc:* services (object allocs).&lt;br /&gt;
&lt;br /&gt;
In theory (untested) it may be possible to also use this to obtain infoleaks, however it would only return the high-u32 of ptrs not the low u32. Essentially, one would trigger object allocations so that ExpHeap has layout: {ISender} -&amp;gt; {RF chunk from freeing an object} -&amp;gt; {module object from IPmModule Initialize}. Then one would use the Send vuln to corrupt the RF chunk, changing the size to a larger value. Then one would trigger an object allocation (probably same object which was previously freed), then another object for overwriting the module object (ISender would work) with ptrs at the target offsets in the module object. Then once IPmModule GetRequest is used, the returned u32s would be the high-u32 from ptrs. Due to alignment requirements with each allocation, it isn&#039;t possible to shift the allocations in order to leak ptr low-u32.&lt;br /&gt;
&lt;br /&gt;
[17.0.0+] Now throws an error if the input count for OpenSender is 0.&lt;br /&gt;
| [[PSC_services|psc]]-sysmodule heap memory corruption ([[NS_services|ns]]-sysmodule on pre-8.0.0).&lt;br /&gt;
| [[17.0.0]]&lt;br /&gt;
| [[17.0.0]]&lt;br /&gt;
| January 13, 2023&lt;br /&gt;
| October 20, 2023&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[NV_services|nv]] NVGPU_GPU_IOCTL_GET_CHARACTERISTICS Ioctl3 infoleak&lt;br /&gt;
| The handler code for NVGPU_GPU_IOCTL_GET_CHARACTERISTICS for Ioctl/Ioctl3 are essentially the same, except for the value used for the max-size clamp: Ioctl uses constant 0xA0, while Ioctl3 uses the outbuf1_size. So if one uses this with Ioctl3 and a large outbuf1, this will memcpy data OOB from the source buffer, hence infoleak.&lt;br /&gt;
With [17.0.0+] the second block of csel code which previouly essentially used the clamped size from above, was replaced with code which properly clamps to the max-size constant.&lt;br /&gt;
| nvservices-sysmodule infoleak, which allows defeating ASLR.&lt;br /&gt;
| [[17.0.0]]&lt;br /&gt;
| [[17.0.0]]&lt;br /&gt;
| February 25, 2022&lt;br /&gt;
| October 24, 2023&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Audio_services|audctl]] GetTargetDeviceInfo infoleak&lt;br /&gt;
| audctl GetTargetDeviceInfo calls an impl func with a ptr to a stackbuf, then if successful memcpys the 0x100-bytes from that buffer to output. This stackbuf is not memset. This func (after doing various state checks) copies a string to output, other than always writing a NUL-terminator there&#039;s no clearing of the buffer.&lt;br /&gt;
&lt;br /&gt;
This will leak audio-sysmodule stack into the output buffer as long as the state/input checks pass (for the remainder of the buffer following the string NUL-terminator).&lt;br /&gt;
&lt;br /&gt;
With [18.0.0+] data is written directly to the outbuf instead of the stack tmpbuf.&lt;br /&gt;
| audio-sysmodule infoleak, which allows defeating ASLR.&lt;br /&gt;
| [[18.0.0]]&lt;br /&gt;
| [[18.0.0]]&lt;br /&gt;
| December 24, 2022&lt;br /&gt;
| March 26, 2024&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Audio_services|audctl]] GetSystemInformationForDebug infoleak / buffer overflow&lt;br /&gt;
| audctl GetSystemInformationForDebug calls a func with a 0x1000-byte stack tmpbuf, then afterwards that buffer is memcpy&#039;d into the cmd outbuf. This called func doesn&#039;t clear the buffer. This func eventually uses [[BTM_services|btm]] cmd75 with outarray={global ptr} and count=10. Then if the outcount is s32 &amp;gt;=1, it loops through the output using the outcount, without validating it besides the &amp;lt;1 check. Data from that outarray is copied into the array in the func output buffer (tmpbuf above).&lt;br /&gt;
&lt;br /&gt;
With btm comprimised, one could return a large output count and trigger a stack buffer overflow with data following that global array, however exploiting this would be difficult since that data would be uncontrolled (can&#039;t directly control it from this cmd at least).&lt;br /&gt;
&lt;br /&gt;
A stack infoleak can be obtained with this as well (assuming the above output array isn&#039;t full).&lt;br /&gt;
&lt;br /&gt;
Even though the name has &amp;quot;ForDebug&amp;quot;, there&#039;s no checks which would trigger an error / return early (this also always returns 0).&lt;br /&gt;
&lt;br /&gt;
[18.0.0+] now clears the output buffer, and also now prints strings into the buffer instead of writing binary data (overflow no longer possible).&lt;br /&gt;
| audio-sysmodule infoleak, which allows defeating ASLR. Also audio-sysmodule memory corruption, likely not useful unless there&#039;s a way to control the data.&lt;br /&gt;
| [[18.0.0]]&lt;br /&gt;
| [[18.0.0]]&lt;br /&gt;
| December 7, 2022&lt;br /&gt;
| March 27, 2024&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Migration_services|migration]] nn::migration::savedata::IServer cmd1 buffer overflow&lt;br /&gt;
| nn::migration::savedata::IServer cmd1 with [18.0.0-18.0.1] copies data from an array to the output ptr. As the output is an u64 field for the IPC cmd output, this is a field on stack. Hence, if more than 1 entry (8-bytes) are copied a stack buffer overflow will occur. Note that cmd3 loads the same data, except this has a proper output array.&lt;br /&gt;
It&#039;s unknown whether there&#039;s a way to actually control this data with a large enough enough size.&lt;br /&gt;
&lt;br /&gt;
See [[18.1.0]] for the diff/fix.&lt;br /&gt;
| [[Migration_services|migration]] stack buffer overflow, only on [18.0.0-18.0.1].&lt;br /&gt;
| [[18.1.0]]&lt;br /&gt;
| [[18.1.0]]&lt;br /&gt;
| June 11, 2024&lt;br /&gt;
| June 11, 2024&lt;br /&gt;
| [[User:Yellows8|yellows8]] (sysupdate diff)&lt;br /&gt;
|-&lt;br /&gt;
| [[SSL_services|ssl]] broken RNG&lt;br /&gt;
| [[SSL_services|ssl]] uses nn::os::GenerateRandomBytes, but not [[SPL_services|spl]] GenerateRandomBytes. See the RNG entries elsewhere. This is used to seed the NSS global RNG (drbg.c, RNG_GenerateGlobalRandomBytes etc).&lt;br /&gt;
&lt;br /&gt;
If one could somehow determine the data which was returned by nn::os::GenerateRandomBytes during seeding (which is likely difficult), the global RNG would be broken.&lt;br /&gt;
&lt;br /&gt;
With [19.0.0+] nn::os::GenerateRandomBytes usage was replaced with [[SPL_services|spl]] GenerateRandomBytes.&lt;br /&gt;
| Breaking [[SSL_services|ssl]] global RNG -&amp;gt; potentially predict RNG data (keys(?)) during TLS comms.&lt;br /&gt;
| [[19.0.0]]&lt;br /&gt;
| [[19.0.0]]&lt;br /&gt;
| December 14, 2021&lt;br /&gt;
| October 8, 2024&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Audio_services|audren]] uncleared TransferMemory&lt;br /&gt;
| audren OpenAudioRenderer uses the input tmem as workmem. The IAudioRenderer dtor doesn&#039;t clear the workmem properly. Depending on input params, certain objects stored here have vtables - hence infoleak.&lt;br /&gt;
The exact location in the workmem will vary depending on the input params - these objects are dynamically allocated in the workmem.&lt;br /&gt;
The following will leak vtables: Sink, Effect.&lt;br /&gt;
&lt;br /&gt;
If the initialization func fails, the tmem is unmapped without clearing it first. It&#039;s unknown whether there&#039;s a way to actually trigger an infoleak with this however. With [19.0.0+] it&#039;s now cleared on failure.&lt;br /&gt;
&lt;br /&gt;
With [19.0.0+] the dtor now clears the workmem when needed.&lt;br /&gt;
| Reading leaked data/ptrs from TransferMemory -&amp;gt; defeating ASLR in [[Audio_services|audio]]-sysmodule.&lt;br /&gt;
| [[19.0.0]]&lt;br /&gt;
| [[19.0.0]]&lt;br /&gt;
| December 17, 2022&lt;br /&gt;
| October 13, 2024&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Audio_services|audren]] UpdateMixes OOB mem-copy&lt;br /&gt;
| With nn::audio::server::InfoUpdater::UpdateMixes when nn::audio::server::BehaviorInfo::IsMixInParameterDirtyOnlyUpdateSupported() returns true (requires REV7, which is [7.0.0+]), the mix_id from user input is used without validation as input to &amp;lt;code&amp;gt;&amp;lt;nn::audio::server::MixContext::GetInfo(int) const&amp;gt;&amp;lt;/code&amp;gt;, instead of the counter from the for-loop. This allows one to control the destination MixInfo index which the user-input data is written into. If too large, this will trigger OOB data-copy. Note that the u8 at dest_MixInfo+12 must be non-zero.&lt;br /&gt;
Also note that a field is loaded from dest_MixInfo which is used as a splitter_id, so splitters need to be initialized where count is large enough for that id.&lt;br /&gt;
&lt;br /&gt;
With [19.0.0+] after getting the mix_id (loop-index/input) it now does: &amp;lt;code&amp;gt;if (mix_id &amp;lt; 0 || mix_id &amp;gt;= nn::audio::server::MixContext::GetCount()) continue;&amp;lt;/code&amp;gt;&lt;br /&gt;
| OOB mem-copy in [[Audio_services|audio]]-sysmodule, which for example can be used to overwrite a vtable used immediately after UpdateMixes.&lt;br /&gt;
| [[19.0.0]]&lt;br /&gt;
| [[19.0.0]]&lt;br /&gt;
| December 19, 2022&lt;br /&gt;
| October 13, 2024&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Bus_services|sasbus]] StartPeriodicReceiveMode infoleak&lt;br /&gt;
| StartPeriodicReceiveMode writes a vtable ptr into the mapped tmem at +0. The tmem is mapped RW in the user-process. There is no clearing of tmem during tmem cleanup. Hence, the user-process can read the tmem to obtain a Bus-sysmodule codebin-region infoleak. This vtable-ptr seems to be unused - it&#039;s also empty after the first two entries (stubbed incref/decref).&lt;br /&gt;
[20.0.0+] Removed the vtable ptr, with data intended for the user-process being moved from tmem+0x8 to +0x0. Also, instead of calling memset, funcs are called for manually clearing tmem.&lt;br /&gt;
| Bus-sysmodule infoleak, which allows defeating ASLR.&lt;br /&gt;
| [[20.0.0]]&lt;br /&gt;
| [[20.0.0]]&lt;br /&gt;
| February 22, 2022&lt;br /&gt;
| May 3, 2025&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[NFC_services|nfc]] SendCommandByPassThrough buffer overflow&lt;br /&gt;
| SendCommandByPassThrough eventually copies the input buffer into a fixed-size heap buffer, without size validation.&lt;br /&gt;
This was fixed with [20.0.0+] by clamping the size.&lt;br /&gt;
| nfc-sysmodule heap buffer overflow.&lt;br /&gt;
| [[20.0.0]]&lt;br /&gt;
| [[20.0.0]]&lt;br /&gt;
| Late November 2021&lt;br /&gt;
| May 3, 2025&lt;br /&gt;
| [[User:Yellows8|yellows8]] (maybe others?)&lt;br /&gt;
|-&lt;br /&gt;
| [[HID_services|hidbus]] EnableJoyPollingReceiveMode infoleak&lt;br /&gt;
| The tmem initialized by hidbus EnableJoyPollingReceiveMode contains a vtable ptr (tmem+0x10), hence infoleak. With [20.0.0+] the vtable ptr write was removed, and tmem is now memset starting at tmem+0x10 instead of +0x20.&lt;br /&gt;
| hid-sysmodule infoleak, which allows defeating ASLR.&lt;br /&gt;
| [[20.0.0]]&lt;br /&gt;
| [[20.0.0]]&lt;br /&gt;
| March 2020&lt;br /&gt;
| May 4, 2025&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[SSL_services|ssl]] Certificate verification bypass&lt;br /&gt;
| The ssl sysmodule keeps a list of trusted certificates, that are imported by an app with ImportServerPki. During certificate verification, if the certificate that is provided by the server has the same subject key id as a trusted certificate, the certificate is accepted, even if self-signed. A blog post about this vulnerability can be found [https://reversing.live/sslbypass.html here].&lt;br /&gt;
| Man-in-the-middle for any connection that uses ImportServerPki.&lt;br /&gt;
| [[20.2.0]]&lt;br /&gt;
| [[20.2.0]]&lt;br /&gt;
| June 6, 2025&lt;br /&gt;
| August 8, 2025&lt;br /&gt;
| [https://github.com/kinnay Yannik]&lt;br /&gt;
|-&lt;br /&gt;
| [[LDN_services|ldn]] AdvertiseData OOB-memcpy with EncryptionType3 (AES-128-GCM) actionframes (ldnhax)&lt;br /&gt;
| The ldn action-frame parser object for AES-128-GCM (used with [[LDN_services|EncryptionType3]]), when it does validation once finished, only verifies that the sizes are within bounds of the input buffer. There&#039;s no validation against constants, which the other EncryptionType objects have. The caller code doesn&#039;t validate the size either.&lt;br /&gt;
&lt;br /&gt;
[21.0.0+] Now validates the advert-size with sizeof(NetworkInfo.AdvertiseData).&lt;br /&gt;
&lt;br /&gt;
For more details see [https://gist.github.com/yellows8/16bb56343d085d2db2ab0adc5d4cef99 here].&lt;br /&gt;
| Compromise of ldn starting from OOB-memcpy, even on S2: stack infoleak (ASLR defeat), arbitrary memory read/write (which also allows handle-leak), vfunc-calls with arbitrary [[Security_Mitigations|vtable]].&lt;br /&gt;
| [[21.0.0]]&lt;br /&gt;
| [[21.0.0]]&lt;br /&gt;
| June ~13, 2025&lt;br /&gt;
| November 11, 2025&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[HID_services|hid:dbg]] AttachHdlsVirtualDevice unvalidated DeviceTypeInternal&lt;br /&gt;
| hid:dbg AttachHdlsVirtualDevice eventually passes the input from HdlsDeviceInfo into a func without any validation. The DeviceTypeInternal field is used as the index for loading a ptr from a global array. The only validation occurs when the loaded ptr is NULL - this is just for initializing the ptr in the array when it&#039;s not already set.&lt;br /&gt;
&lt;br /&gt;
Since the highest DeviceTypeInternal is value 30, using &amp;gt;=31 will load an OOB ptr. This ptr is written to state, and also immediately passed to a called func. As long as ptr is valid it should be fine with this func.&lt;br /&gt;
&lt;br /&gt;
This functionality is also used eventually by ApplyHdlsNpadAssignmentState and ApplyHdlsStateList.&lt;br /&gt;
&lt;br /&gt;
It&#039;s unknown whether there&#039;s a way to exploit this. Also note that hid:dbg is not normally accessible to retail titles.&lt;br /&gt;
&lt;br /&gt;
[21.0.0+] Arrayindex=0 is now used when the input is invalid.&lt;br /&gt;
| Likely useless, even if reachable?&lt;br /&gt;
| [[21.0.0]]&lt;br /&gt;
| [[21.0.0]]&lt;br /&gt;
| June 3, 2024 (possibly eariler(?))&lt;br /&gt;
| November 14, 2025&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Bluetooth_Driver_services|bluetooth]] BSA allowed ATT MTU is too large&lt;br /&gt;
| GATT-handler stack buffer overflows with a large input size are only possible if the payload_size (MTU) field in state is large enough. gatt_client_handle_server_rsp/gatt_server_handle_client_req will drop messages where the size is &amp;gt;= payload_size (though unless the request opcode matches certain values it will also send an error-response for invalid-PDU). Both of these handle updating this field when needed, however that&#039;s handled properly.&lt;br /&gt;
&lt;br /&gt;
With bluetooth-classic via L2CAP, a hard-coded MTU of 0x205 is sent in the configure request. However the code handling received configure requests will set payload_size to 0x2A0 if no MTU is specified, or the input MTU if it&#039;s within range 0x30..0x2A0. Hence, sending data large enough for buffer overflows requires bluetooth-classic via L2CAP + manually sending large ACL data.&lt;br /&gt;
&lt;br /&gt;
[15.0.0+] gatt_l2cif_config_ind_cback which handles the received configure-requests with bluetooth-classic mentioned above, now uses MTU range 0x30..0x205 with the default MTU being 0x205. It is therefore no longer possible to trigger the previously mentioned buffer-overflows with bluetooth-classic.&lt;br /&gt;
| Stack buffer overflows in bluetooth-sysmodule due to the allowed MTU for ATT being larger than the stack data.&lt;br /&gt;
| [[15.0.0]]&lt;br /&gt;
| [[20.0.0]]&lt;br /&gt;
| November 2021?&lt;br /&gt;
| November 26, 2025&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Bluetooth_Driver_services|bluetooth]] BSA gatt_process_prep_write_rsp stack buffer overflow&lt;br /&gt;
| BSA gatt_process_prep_write_rsp memcpys to stack without size validation (the input len param which is subtracted to determine the copy-size is also unvalidated). Triggering this is only possible if the system sent ATT_PREPARE_WRITE_REQ, and then received ATT_PREPARE_WRITE_RSP with a large size.&lt;br /&gt;
&lt;br /&gt;
The size used with memcpy is (u16)(insize-4), so when insize is less than 4 the copy size will be {negative value masked to u16}. This will therefore eventually crash when the stacktop is reached during memcpy.&lt;br /&gt;
&lt;br /&gt;
[15.0.0+] Paritially fixed due to corrected MTU handling (doesn&#039;t apply to negative-copysize). [21.0.0+] Fully fixed with proper size validation.&lt;br /&gt;
| Stack buffer overflow in bluetooth-sysmodule when the required ATT messages are sent/received.&lt;br /&gt;
| [[21.0.0]]&lt;br /&gt;
| [[21.0.0]]&lt;br /&gt;
| November 2021?&lt;br /&gt;
| January 19, 2026&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[NFC_services|nfc]] Initialize buffer overflow&lt;br /&gt;
| All Initialize* cmds for nn::nfc::detail::IUser (nfc:user), nn::nfc::detail::ISystem (nfc:sys), nn::nfp::detail::IUser (nfp:user), nn::nfp::detail::ISystem (nfp:sys), nn::nfp::detail::IDebug (nfp:dbg), nn::nfc::mifare::detail::IUser (nfc:mf:u): these copy the input array into _this, without validating the array count.&lt;br /&gt;
The data is copied to obj_impl+0x8+0x28, with each entry being 0x20-bytes. The event handle returned by AttachAvailabilityChangeEvent is at obj_impl+0x8+0xB8+0x14 (Same with nfc/nfp interfaces). This therefore means +0xA4 in the input buffer will overwrite the handle returned by that cmd, allowing one to leak any handle with the specified value. This can be done with count=0x6. The object is large enough that this count will only overwrite data within the current object. However during the dtor it will use ptrs which were corrupted with this (located before the event), so one must avoid closing the session unless the input data included valid ptrs.&lt;br /&gt;
&lt;br /&gt;
This can be exploited by just using a 0xC0-byte (array_count=0x6) input buffer with Initialize where each u32 is the target nfc handle value, then using cmd GetAvailabilityChangeEventHandle to leak the handle.&lt;br /&gt;
&lt;br /&gt;
[22.0.0+] This was fixed by clamping the count to a maximum of 0x4.&lt;br /&gt;
| OOB datacopy into object state. Allows leaking arbitary [[NFC_services|handles]], including on [S2] (such as process-handle, sm, fsp-srv (remaining services can also be used via sm)).&lt;br /&gt;
| [[22.0.0]]&lt;br /&gt;
| [[22.0.0]]&lt;br /&gt;
| November 2021&lt;br /&gt;
| March 17, 2026&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Internet Browser == &lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
!  Summary&lt;br /&gt;
!  Description&lt;br /&gt;
!  Successful exploitation result&lt;br /&gt;
!  Fixed in system version&lt;br /&gt;
!  Last system version this flaw was checked for&lt;br /&gt;
!  Timeframe this was discovered&lt;br /&gt;
!  Public disclosure timeframe&lt;br /&gt;
!  Discovered by&lt;br /&gt;
|-&lt;br /&gt;
| CVE-2016-4657&lt;br /&gt;
| WebKit vuln discovered around August 2016. Most notably used in the iOS 9.3.X exploit. A simple PoC can be found [https://github.com/LiveOverflow/lo_nintendoswitch/blob/master/poc1.html here]. This was later exploited by [https://twitter.com/qwertyoruiopz Qwertyoruiop] using an adjusted version of his iOS 9.3 webkit exploit (others exploited this prior to then).&lt;br /&gt;
|&lt;br /&gt;
| [[2.1.0]]&lt;br /&gt;
| [[2.0.0]]&lt;br /&gt;
| Original: August 2016&lt;br /&gt;
Switch: March 3rd-4th 2017&lt;br /&gt;
|&lt;br /&gt;
| Everyone&lt;br /&gt;
|-&lt;br /&gt;
| CVE-2017-7005&lt;br /&gt;
| WebKit type confusion.&lt;br /&gt;
|&lt;br /&gt;
| [[3.0.1]]&lt;br /&gt;
| [[3.0.1]]&lt;br /&gt;
|&lt;br /&gt;
| &lt;br /&gt;
| Everyone&lt;br /&gt;
|-&lt;br /&gt;
| CVE-2016-4622&lt;br /&gt;
| WebKit memory corruption bug. This bug was incorrectly re-introduced in [[4.0.0]]. See [http://www.phrack.org/papers/attacking_javascript_engines.html here] for a detailed write-up from the author.&lt;br /&gt;
|&lt;br /&gt;
| [[6.1.0]]&lt;br /&gt;
| [[6.1.0]]&lt;br /&gt;
|&lt;br /&gt;
| &lt;br /&gt;
| Everyone&lt;br /&gt;
|-&lt;br /&gt;
| CVE-2018-4441&lt;br /&gt;
| WebKit memory corruption bug. See [https://bugs.chromium.org/p/project-zero/issues/detail?id=1685&amp;amp;desc=2 here].&lt;br /&gt;
|&lt;br /&gt;
| [[7.0.0]]&lt;br /&gt;
| [[7.0.0]]&lt;br /&gt;
| &lt;br /&gt;
|&lt;br /&gt;
| Everyone&lt;br /&gt;
|-&lt;br /&gt;
| Web-applets OpenSSL broken RNG&lt;br /&gt;
| [[SPL_services|csrng]] access was added to web-applets with [12.1.0+]. Prior to that, csrng and nn::os::GenerateRandomBytes were not used (besides sdk heap code).&lt;br /&gt;
nn::os::GetSystemTick is used to seed the OpenSSL RNG, among other data. Hence, it&#039;s probably (?) possible to bruteforce the RNG initial state, allowing predicting RNG output.&lt;br /&gt;
&lt;br /&gt;
The RNG code is wkcRandomNumbersPeer (peer_wkc nro), with the initialization code using GetSystemTick located in the func immediately before wkcGetTickCountPeer. The former is called from wkcOsslRandFilefReadPeer. wkcOsslRandFilefReadPeer is called for seeding the OpenSSL RNG.&lt;br /&gt;
&lt;br /&gt;
With [12.1.0+], wkcRandomNumberPeer/wkcRandomNumbersPeer wrap nn::os::GenerateRandomBytes. wkcCryptographicallyRandomValuesPeer was added which wraps nn::crypto::GenerateCryptographicallyRandomBytes. wkcOsslRandFilefReadPeer now calls nn::crypto::GenerateCryptographicallyRandomBytes instead of wkcRandomNumbersPeer.&lt;br /&gt;
| Breaking web-applets OpenSSL RNG -&amp;gt; potentially predict RNG data (keys(?)) during TLS comms.&lt;br /&gt;
| [[12.1.0]]&lt;br /&gt;
| [[12.1.0]]&lt;br /&gt;
| January 28, 2022&lt;br /&gt;
| October 8, 2024&lt;br /&gt;
| [[User:Yellows8|yellows8]], likely (?) others&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Whitelist ===&lt;br /&gt;
This section documents [[Internet_Browser|WebApplet]] whitelist issues in applications. These can be used to load your own browser content over plain HTTP, which then for example could be used for web-applet exploitation.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
!  Application&lt;br /&gt;
!  Description&lt;br /&gt;
!  Fixed with app version&lt;br /&gt;
!  Newest app version this flaw was checked for&lt;br /&gt;
!  Timeframe this was discovered&lt;br /&gt;
!  Public disclosure timeframe&lt;br /&gt;
!  Discovered by&lt;br /&gt;
|-&lt;br /&gt;
| Sonic Mania&lt;br /&gt;
| Originally this game launched web-applet with a plain-http URL for displaying the manual, this was later changed to https. Originally the whitelist only had 1 entry for a http URL, this was later replaced with various https-only URLs.&lt;br /&gt;
| 1.04, unknown if fixed with an earlier update&lt;br /&gt;
| 1.04&lt;br /&gt;
| January (?) 2022&lt;br /&gt;
| February 23, 2022&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| ぷよぷよ™テトリス®Ｓ (JPN Puyo Puyo Tetris)&lt;br /&gt;
| The JPN Tetris game/demo can be used to launch the online-WebApplet.&lt;br /&gt;
&lt;br /&gt;
First, launch the offline-WebApplet for the manual:&lt;br /&gt;
* Game: Main-menu -&amp;gt; press A with the already selected top menu button -&amp;gt; press the R button.&lt;br /&gt;
* Demo: Main-menu -&amp;gt; select menu button on the right side -&amp;gt; press A.&lt;br /&gt;
&lt;br /&gt;
Then in the manual:&lt;br /&gt;
* Press A -&amp;gt; select the bottom menu entry in the list.&lt;br /&gt;
* Select the SEGA icon -&amp;gt; press A.&lt;br /&gt;
&lt;br /&gt;
This will then trigger launching the online-WebApplet with the plain-http &amp;lt;nowiki&amp;gt;&amp;quot;http://sega.jp/&amp;quot;&amp;lt;/nowiki&amp;gt; URL.&lt;br /&gt;
&lt;br /&gt;
With game-update v1.1.3 the whitelist no longer allows plain-http. The plain-http links appear to have been changed to https.&lt;br /&gt;
| 1.1.3&lt;br /&gt;
| 1.1.3&lt;br /&gt;
| 2017&lt;br /&gt;
| 2017&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== NintendoSDK ==&lt;br /&gt;
This section documents vulnerabilities for NSOs in NintendoSDK.&lt;br /&gt;
&lt;br /&gt;
=== nnSdk ===&lt;br /&gt;
This section documents vulnerabilities for nnSdk (sdknso).&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Summary&lt;br /&gt;
!  Description&lt;br /&gt;
!  Successful exploitation result&lt;br /&gt;
!  Fixed in SDK [[System_Versions|version]]&lt;br /&gt;
!  Last SDK version this flaw was checked for&lt;br /&gt;
!  Timeframe this was discovered&lt;br /&gt;
!  Public disclosure timeframe&lt;br /&gt;
!  Discovered by&lt;br /&gt;
|-&lt;br /&gt;
| [[HID_services|hidbus]] GetJoyPollingReceivedData buffer overflow&lt;br /&gt;
| hidbus GetJoyPollingReceivedData doesn&#039;t validate the u8 size used for memcpy, when copying the data to the output JoyPollingReceivedData. With 11.x, the size is now clamped to a maximum of 0x2C (regardless of polling-mode). Note that 0x2C is the data-size for JoyButtonOnlyPollingDataAccessor, the other polling-modes have a smaller size.&lt;br /&gt;
&lt;br /&gt;
The hid-sysmodule code which writes data here does handle it properly: size is clamped to a max size, and the data-read uses a fixed-size anyway (hence there&#039;s no way to trigger this sdknso vuln with the hid-sysmodule tmem writing code).&lt;br /&gt;
&lt;br /&gt;
This could only be exploited if one directly writes to the tmem when one has previously compromised hid-sysmodule, without using the normal tmem-writing func for this.&lt;br /&gt;
&lt;br /&gt;
There are only a few [[HID_services#ExternalDevices|apps]] which use hidbus.&lt;br /&gt;
| Triggering a buffer overflow in an application which uses hidbus GetJoyPollingReceivedData, from a previously compromised hid-sysmodule.&lt;br /&gt;
| 11.x.0&lt;br /&gt;
| 11.4.0&lt;br /&gt;
| March 2020&lt;br /&gt;
| December 3, 2020&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Profile_Selector|Profile Selector]] uninitialized input data&lt;br /&gt;
| Originally unused regions of [[Profile_Selector]] UiSettings/UserSelectionSettings were not cleared prior to being sent to the applet. With 1.x.x these are now properly memset().&lt;br /&gt;
| Stack infoleak from user-process, sent to the applet.&lt;br /&gt;
| 1.x.x&lt;br /&gt;
| 11.4.0&lt;br /&gt;
| November-December 2019&lt;br /&gt;
| December 31, 2020&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== NEX ===&lt;br /&gt;
This section documents client-side vulnerabilities for [https://github.com/Kinnay/NintendoClients/wiki/NEX-Overview-(Game-Servers) NEX].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Summary&lt;br /&gt;
!  Description&lt;br /&gt;
!  Successful exploitation result&lt;br /&gt;
!  Fixed in version&lt;br /&gt;
!  Timeframe this was discovered&lt;br /&gt;
!  Public disclosure timeframe&lt;br /&gt;
!  Discovered by&lt;br /&gt;
|-&lt;br /&gt;
| Buffer overflow in StringConversion::T2Char8&lt;br /&gt;
| StringConversion::T2Char8 is used to convert IP addresses from a platform-specific encoding to UTF-8. On the 3DS and Switch, the implementation is simply a strcpy. By sending a long IP address string, a buffer overflow can be triggered on the stack. The vulnerability can be triggered through the NAT traversal protocol. A blog post about this vulnerable can be found [https://reversing.live/hacking-hundreds-of-wii-us-at-once.html here].&lt;br /&gt;
| Stack overflow in any game that uses NEX for matchmaking&lt;br /&gt;
| Fixed server-side&lt;br /&gt;
| December, 2022&lt;br /&gt;
| May, 2024&lt;br /&gt;
| [https://github.com/kinnay Yannik]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Pia ===&lt;br /&gt;
This section documents vulnerabilities for [https://github.com/Kinnay/NintendoClients/wiki/Pia-Overview Pia].&lt;br /&gt;
&lt;br /&gt;
In v5.11.3 (exact starting version unknown) the fixes aren&#039;t present for the below vulns which were fixed in v5.9.3, while in v5.18.98 these are present (exact starting version unknown). This probably indicates that the vuln fixes were backported from a newer Pia version to v5.9.3.&lt;br /&gt;
&lt;br /&gt;
The Pia packet handlers are only active when the game is using multiplayer. LanProtocol is only active in the games which are actively using the LAN-mode option (not Ldn) - only certain games support LAN-mode. The LanProtocol Pia packet handler can be reached while in a lobby or searching for one.&lt;br /&gt;
&lt;br /&gt;
Most Pia packets require an active StationProtocol connection to be active with {InetAddr which the packet was received from}, otherwise the packet is filtered out. The only protocols which don&#039;t use filtering are the following: NatTraversalProtocol, LanProtocol, StationProtocol, LocalProtocol.&lt;br /&gt;
&lt;br /&gt;
Note that broadcast IP-dest Pia packets are accepted - this can be used to target every device on the network which is using Pia (which is really only useful with {above protocols} due to the filtering mentioned above, unless one also handles StationProtocol).&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Summary&lt;br /&gt;
!  Description&lt;br /&gt;
!  Successful exploitation result&lt;br /&gt;
!  Fixed in Pia version&lt;br /&gt;
!  Last Pia version this flaw was checked for&lt;br /&gt;
!  Timeframe this was discovered&lt;br /&gt;
!  Public disclosure timeframe&lt;br /&gt;
!  Discovered by&lt;br /&gt;
|-&lt;br /&gt;
| nn::pia::session::RelayRouteManageJob::UpdateConnectionReport buffer overflow&lt;br /&gt;
| nn::pia::session::RelayRouteManageJob::UpdateConnectionReport() checks that the input size is at least {value}, but there&#039;s no max size check. This is used to memcpy from the input to elsewhere - hence buf-overflow if size is too large. The dst buffer is allocated on the pead heap - this buffer is probably small.&lt;br /&gt;
Note that there&#039;s various requirements before it would actually reach the memcpy, such as &amp;lt;code&amp;gt;&amp;lt;nn::pia::session::Mesh::IsHost() const&amp;gt;&amp;lt;/code&amp;gt; must return true.&lt;br /&gt;
&lt;br /&gt;
This is called from nn::pia::session::MeshProtocol::ParseConnectionReport().&lt;br /&gt;
&lt;br /&gt;
ParseConnectionReport uses a state ptr for object nn::pia::session::RelayRouteManageJob, it will return if not set. nn::pia::session::Mesh::Initialize handles setup for this, depending on an input field from nn::pia::session::Mesh::Setting. These settings originate from &amp;lt;code&amp;gt;&amp;lt;nn::pia::session::Session::CreateInstance(nn::pia::session::Session::Setting const&amp;amp;)&amp;gt;&amp;lt;/code&amp;gt;, which is called by user-code with the needed settings.&lt;br /&gt;
ParseConnectionReport is therefore only usable if the game explicitly enables the Relay functionality.&lt;br /&gt;
&lt;br /&gt;
In fixed versions immediately after the StationIndex validation it now does: &amp;lt;code&amp;gt;if(statefield+0x10&amp;lt;input_size) return;&amp;lt;/code&amp;gt;&lt;br /&gt;
| Heap buffer overflow triggered by a Pia MeshProtocol message sent to a host device.&lt;br /&gt;
| v5.9.3, see above.&lt;br /&gt;
| v5.9.1/v5.9.2/v5.9.3&lt;br /&gt;
| November 11, 2022&lt;br /&gt;
| November 15, 2022&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| nn::pia::lan::LanProtocol::ParseSessionMessage buffer overflow&lt;br /&gt;
| nn::pia::lan::LanProtocol::ParseSessionMessage() calls nn::pia::lan::LanSessionMessage::Deserialize() to deserialize the message payload data buffer into the LanSessionMessage object on stack. LanSessionMessage::Deserialize (among other things) memcpys data from the input buffer to the object, using an u32 from the input buffer - there is no size validation in Deserialize itself.&lt;br /&gt;
There is a size check immediately after calling Deserialize() to verify &amp;lt;code&amp;gt;payloadsize=={u32val}+{constant}&amp;lt;/code&amp;gt;, returning on fail - but this doesn&#039;t matter for too-large-size.&lt;br /&gt;
&lt;br /&gt;
In fixed versions Deserialize now does bounds checking, both for the minimum message size and clamping the memcpy size to a constant. An error is thrown if the clamped memcpy size is larger than the message size. The caller now checks the ret properly, previously it was ignored.&lt;br /&gt;
&lt;br /&gt;
Following the size check in ParseSessionMessage() it calls &amp;lt;code&amp;gt;&amp;lt;nn::pia::session::Mesh::IsProcessingLeaveMesh() const&amp;gt;&amp;lt;/code&amp;gt;, returning if ret is false.&lt;br /&gt;
&lt;br /&gt;
Then it calls nn::pia::lan::LanProtocol::ReceivedFragmentData::Receive(), with the memcpy&#039;d buffer/size from the above LanSessionMessage, and other fields from LanSessionMessage. This eventually memcpys the input buffer to object+{offset}+{chunksize_field}*inputu8, there is no validation for size or inputu8 (except for the above size check). Hence, if the u8 is large enough, this would result in a heap buffer overflow.&lt;br /&gt;
&lt;br /&gt;
In fixed versions ReceivedFragmentData::Receive added a bunch of validation before the memcpy.&lt;br /&gt;
| Stack/heap buffer overflow triggered by a Pia LanProtocol message.&lt;br /&gt;
| v5.9.3, see above.&lt;br /&gt;
| v5.9.1/v5.9.2/v5.9.3&lt;br /&gt;
| November 14, 2022&lt;br /&gt;
| November 15, 2022&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| nn::pia::session::SessionProtocol::ParseLeaveMeshInvitation buffer overflow&lt;br /&gt;
| &amp;lt;code&amp;gt;&amp;lt;nn::pia::session::SessionProtocol::ParseLeaveMeshInvitation(nn::pia::transport::ReceivedMessageAccessor const&amp;amp;)&amp;gt;&amp;lt;/code&amp;gt; This immediately returns if *(ReceivedMessageAccessor+16) is 0. Then the input data is deserialized. The input u64 array is deserialized to stack, the u8 arraycount field from input is not validated.&lt;br /&gt;
&lt;br /&gt;
Hence, stack buffer overflow. Note that there&#039;s similar loop code in nearby funcs, which do validate the count properly.&lt;br /&gt;
&lt;br /&gt;
In fixed versions the arraycount field is now validated.&lt;br /&gt;
&lt;br /&gt;
SessionProtocol uses ReliableSlidingWindow MessageHeader, with a maximum message size of 0x100. The allocated size used for the above u64 array is also 0x100-bytes. Hence, when triggering a buf overflow the data after the buffer is uncontrolled data from the SessionProtocol object.&lt;br /&gt;
| Stack buffer overflow triggered by a Pia SessionProtocol message.&lt;br /&gt;
| v5.9.3, see above.&lt;br /&gt;
| v5.9.1/v5.9.2/v5.9.3&lt;br /&gt;
| November 14, 2022&lt;br /&gt;
| November 15, 2022&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| Optional Pia packet encryption&lt;br /&gt;
| Pia packet encryption is optional. If the encryption flag is disabled, the packet handler will accept it and skip crypto.&lt;br /&gt;
In fixed versions immediately after grabbing a packet, it now checks the crypto flag. If it&#039;s plaintext the packet is dropped.&lt;br /&gt;
&lt;br /&gt;
This can be used to send a plaintext Pia packet without needing to handle encryption, especially useful if the session-key can&#039;t be obtained (online-play matchmaking). This could be combined with other vulns if wanted.&lt;br /&gt;
| Sending a plaintext Pia packet without needing to handle encryption.&lt;br /&gt;
| v5.9.3, see above.&lt;br /&gt;
| v5.9.3 (and later versions)&lt;br /&gt;
| &lt;br /&gt;
| November 19, 2022&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| nn::pia::session::{JoinMeshJob/ProcessUpdateMeshJob}::SetStationDataList OOB read/write/vfunc-call&lt;br /&gt;
| &amp;lt;code&amp;gt;nn::pia::session::JoinMeshJob::SetStationDataList&amp;lt;/code&amp;gt;is called by &amp;lt;code&amp;gt;nn::pia::session::MeshProtocol::ParseJoinResponse(nn::pia::transport::ReceivedMessageAccessor const&amp;amp;)&amp;gt;&amp;lt;/code&amp;gt; with the ReceivedMessageAccessor buffer.&lt;br /&gt;
SetStationDataList will update state and immediately return if the join was denied. It will also validate the num_mesh_stations field against state. ParseJoinResponse also essentially verifies that the message was received from the host device.&lt;br /&gt;
&lt;br /&gt;
The input buffer size is ignored.&lt;br /&gt;
&lt;br /&gt;
The num_fragments field must be value 1 or &amp;lt;=3 otherwise it will return, there&#039;s two seperate code blocks handling these.&lt;br /&gt;
&lt;br /&gt;
Other than the checks at the start, there&#039;s no validation for the index fields. So large enough values could result in OOB-reads.&lt;br /&gt;
&lt;br /&gt;
When handling multiple fragments, it will loop through the stationinfo list. There is no validation for the u8 count field or the baseindex field. It calls a vfunc from obj baseptr+index*{entrysize} with data from the buffer, where index starts with the above baseindex field. Afterwards, an u8 is copied into an u32 array (with certain versions an u16 is deserialized into an u16 array).&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;nn::pia::session::ProcessUpdateMeshJob::UpdateStationDataList&amp;lt;/code&amp;gt; is (eventually) called from &amp;lt;code&amp;gt;nn::pia::session::MeshProtocol::ParseUpdateMesh&amp;lt;/code&amp;gt;, which has similar issues to the above.&lt;br /&gt;
&lt;br /&gt;
Note that ParseJoinResponse/ParseUpdateMesh essentially require the message to be received from the host device.&lt;br /&gt;
&lt;br /&gt;
With fixed versions (v5.18.98, exact version unknown) various validation was added. Additional/updated validation was added in a later version (v5.31.0, exact version unknown).&lt;br /&gt;
| OOB read/write / vfunc call where the object is selected by an OOB index, triggered by a Pia MeshProtocol message.&lt;br /&gt;
| v5.18.98 and v5.31.0 (exact versions unknown).&lt;br /&gt;
| v5.31.0&lt;br /&gt;
| November 18, 2022&lt;br /&gt;
| November 21, 2022&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| Insecure encryption&lt;br /&gt;
| Originally Pia packets used AES-ECB encryption. As documented [https://github.com/Kinnay/NintendoClients/wiki/Pia-Overview here] it was later changed with v5.7.0 to AES-GCM. Each 0x10-byte block would have the same encrypted block output where the plaintext 0x10-byte data is the same.&lt;br /&gt;
The mechanism for generating the Pia SessionKey for LAN has also changed over time.&lt;br /&gt;
&lt;br /&gt;
The [https://github.com/Kinnay/NintendoClients/wiki/LAN-Protocol LAN] non-Pia-encapsulated packets were also originally sent in plaintext, however at some point it was changed to mostly encrypted.&lt;br /&gt;
| &lt;br /&gt;
| AES-GCM fix: v5.7.0&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| nn::pia::transport::UnreliableProtocol::Dispatch buffer overflow&lt;br /&gt;
| &amp;lt;code&amp;gt;nn::pia::transport::UnreliableProtocol::Dispatch&amp;lt;/code&amp;gt; memcpys data from the message into a list entry, without size validation. If the pia packet is the max size, it will only overwrite the 0xC-bytes which were written to immediately before the memcpy: the u32 size and the 8-byte StationAddress (depending on the version there can also be 4-byte padding after the size for alignment).&lt;br /&gt;
However, nn::pia::transport::UnreliableProtocol::Receive will clamp the size from the list entry to the outbuf size when doing the memcpy. So this is probably useless.&lt;br /&gt;
&lt;br /&gt;
It&#039;s unknown whether there&#039;s a version where more data could be overwritten, and whether that would be useful.&lt;br /&gt;
&lt;br /&gt;
This is fixed in v5.31.0, exact version unknown. The message is dropped if too large in Dispatch.&lt;br /&gt;
| Small buffer overflow triggered by a Pia UnreliableProtocol message.&lt;br /&gt;
| v5.31.0, exact version unknown.&lt;br /&gt;
| v5.18.98/v5.31.0&lt;br /&gt;
| November 2022&lt;br /&gt;
| November 29, 2022&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| Uncleared input structs for [[LDN_services|LDN]]&lt;br /&gt;
| The Pia code using ldn CreateNetwork*/ConnectNetwork*/Scan doesn&#039;t properly memset the input data for SecurityConfig/ScanFilter (when keysize is less than 0x40 for the former). Hence, infoleak from games is sent to ldn (structs are located on stack, so stack data is leaked). This requires ldn compromise/mitm to obtain the leaked data - these are not sent over the network.&lt;br /&gt;
With v6.20.1 (exact version unknown - fix isn&#039;t present in v5.32.0), the code using Scan* now clears the input ScanFilter properly. With v6.25.1 (exact version unknown - fix isn&#039;t present in v6.23.3), the code using CreateNetwork*/ConnectNetwork* now clears the input SecurityConfig properly.&lt;br /&gt;
| Infoleak from games with LDN cmds, requires compromised sysmodule/mitm.&lt;br /&gt;
| v6.20.1 and v6.25.1, exact versions unknown.&lt;br /&gt;
| v5.32.0/v6.20.1/v6.23.3/v6.25.1&lt;br /&gt;
| &lt;br /&gt;
| December 7, 2022&lt;br /&gt;
| &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== ENL ===&lt;br /&gt;
This section documents vulnerabilities for [https://github.com/kinnay/NintendoClients/wiki/ENL-Protocol ENL].&lt;br /&gt;
A framework used by Nintendo games including Mario Kart 8 Deluxe, Splatoon 2 / 3, Mario Maker 2, and more.&lt;br /&gt;
&lt;br /&gt;
Fun fact, this library appears to re-use network code and concepts from older Nintendo titles such as Mario Kart 7 and some Wii multiplayer games.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Summary&lt;br /&gt;
!  Description&lt;br /&gt;
!  Successful exploitation result&lt;br /&gt;
!  Fixed in Enl version&lt;br /&gt;
!  Last Enl version this flaw was checked for&lt;br /&gt;
!  Timeframe this was discovered&lt;br /&gt;
!  Public disclosure timeframe&lt;br /&gt;
!  Discovered by&lt;br /&gt;
|-&lt;br /&gt;
| enl::TransportManager::updateReceiveBuffer_() nullptr deref&lt;br /&gt;
| enl::TransportManager::updateReceiveBuffer_() is called when the ENL framework receives a PIA packet from a client, it will fully trust the ENL header which includes a &amp;quot;ContentTransporter&amp;quot; type (ID) and a length.&lt;br /&gt;
The function will try to fetch the content transporter by ID using &amp;lt;code&amp;gt;enl::TransportManager::getContentTransporter(unsigned char const &amp;amp;)&amp;lt;/code&amp;gt;, it returns NULL if there&#039;s no content transporter with the same ID&lt;br /&gt;
&lt;br /&gt;
*NOTE: The function may be inlined&lt;br /&gt;
&lt;br /&gt;
Then it will try to call a virtual method: &amp;lt;code&amp;gt;virtual size_t readyReceiveStream(enl::RamReadStream&amp;amp;, enl::Buffer*, size_t)&amp;lt;/code&amp;gt;, dereferencing the pointer to fetch the vtable ptr&lt;br /&gt;
&lt;br /&gt;
[https://gist.github.com/Rambo6Glaz/c088e2ed7a12db08f6322e9f7a3c4911 Pseudocode of the function before it was fixed]&lt;br /&gt;
&lt;br /&gt;
| nullptr dereference triggered by an invalid content transporter type in the ENL header (it will crash the game/process)&lt;br /&gt;
| Unknown&lt;br /&gt;
| Depends on the game&lt;br /&gt;
| Early April 2022&lt;br /&gt;
| November 16, 2022&lt;br /&gt;
| [[User:Rambo6Glaz|Rambo6Glaz]], [https://github.com/kinnay Yannik] (massive RE help)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
There&#039;s another one more interesting but it will have to wait a bit :)&lt;br /&gt;
&lt;br /&gt;
== Games ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Game&lt;br /&gt;
!  Summary&lt;br /&gt;
!  Description&lt;br /&gt;
!  Impact&lt;br /&gt;
!  Fixed in version&lt;br /&gt;
!  Timeframe this was discovered&lt;br /&gt;
!  Public disclosure timeframe&lt;br /&gt;
!  Discovered by&lt;br /&gt;
|-&lt;br /&gt;
| Mario Kart World&lt;br /&gt;
| ASLR leak in application data&lt;br /&gt;
| A memory address can be leaked by changing your username to something short, and hosting a network session in LAN mode (press L + R + Left Stick on the main menu to enable this). The memory address can be found in bytes 12 - 19 of the application data that is transmitted in response to a browse request.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note:&#039;&#039;&#039; there is more uninitialized data in the packet, but the memory address is probably the most interesting part. The vulnerability was fixed by clearing the application data with zeros, before filling in the information.&lt;br /&gt;
&lt;br /&gt;
[https://hackerone.com/reports/3463719 HackerOne report]&lt;br /&gt;
&lt;br /&gt;
This stack infoleak was also present in the [[LDN_services|ldn]] AdvertiseData.&lt;br /&gt;
| A memory address can leaked (this is a requirement for many types of attacks).&lt;br /&gt;
| 1.5.0&lt;br /&gt;
| December 12, 2025&lt;br /&gt;
| February 19, 2026&lt;br /&gt;
| [https://github.com/kinnay Yannik], yellows8 (ldn)&lt;br /&gt;
|-&lt;br /&gt;
| Splatoon 3&lt;br /&gt;
| Anticheat Seed Randomization Weakness&lt;br /&gt;
| This oversight of seed generation would allow an attacker to quickly compute all code hashes, and modify game code, while still producing a valid ch1 hash.&lt;br /&gt;
&lt;br /&gt;
[https://hackerone.com/reports/3042475 HackerOne report]&lt;br /&gt;
| Allows an attacker to bypass the ch1 anti-cheat hashing mechanism.&lt;br /&gt;
| 10.0.0&lt;br /&gt;
| March 17, 2025&lt;br /&gt;
| February 19, 2026&lt;br /&gt;
| hana2736&lt;br /&gt;
|-&lt;br /&gt;
| Splatoon Raiders&lt;br /&gt;
| Infoleak in application data&lt;br /&gt;
| A ptr can be leaked by hosting a network session in local (at least ldn) mode. The uninitialized data follows the last username in the appdata ([[LDN_services|ldn]] AdvertiseData). With account username short even more data/ptrs are leaked.&lt;br /&gt;
With v1.1.1 that data is now cleared.&lt;br /&gt;
| Game infoleak, which allows defeating ASLR.&lt;br /&gt;
| 1.1.1&lt;br /&gt;
| July 25, 2026&lt;br /&gt;
| August 6, 2026&lt;br /&gt;
| [[User:Yellows8|yellows8]] (ldn)&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Yellows8</name></author>
	</entry>
	<entry>
		<id>https://switchbrew.org/w/index.php?title=Switch_System_Flaws&amp;diff=14928</id>
		<title>Switch System Flaws</title>
		<link rel="alternate" type="text/html" href="https://switchbrew.org/w/index.php?title=Switch_System_Flaws&amp;diff=14928"/>
		<updated>2026-08-07T02:48:13Z</updated>

		<summary type="html">&lt;p&gt;Yellows8: /* Games */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This page is a list of publicly known Switch / Switch 2 (S2) flaws.&lt;br /&gt;
&lt;br /&gt;
= Hardware =&lt;br /&gt;
Flaws in this category pertain to the underlying hardware that powers the Switch.&lt;br /&gt;
&lt;br /&gt;
This includes components shared across Tegra based devices such as the [[TSEC]], the [[Security_Engine|Security Engine]], the [[GPU]] and so on.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
!  Summary&lt;br /&gt;
!  Description&lt;br /&gt;
!  Fixed with hardware model/revision&lt;br /&gt;
!  Newest hardware model/revision this flaw was checked for&lt;br /&gt;
!  Timeframe this was discovered&lt;br /&gt;
!  Public disclosure timeframe&lt;br /&gt;
!  Discovered by&lt;br /&gt;
|-&lt;br /&gt;
| GMMU DMA attack&lt;br /&gt;
| The Switch&#039;s GPU includes a separate MMU (GMMU) that is allowed to bypass the system&#039;s IOMMU (SMMU). By accessing the GPU&#039;s MMIO region and manipulating the page table entries in the GMMU, an attacker can read/write any portion of the DRAM (except memory carveouts).&lt;br /&gt;
&lt;br /&gt;
[5.0.0+] Works around this hardware flaw by using memory pool partitioning. You can no longer escalate into sysmodules with GPU DMA because all their memory is allocated using heap that&#039;s carved out.&lt;br /&gt;
&lt;br /&gt;
HAC-001-01 (Mariko/Tegra214/Tegra210b01): Fixes this by adding a new register which restricts what memory untranslated DMA requests may access. Untranslated GPU DMA may now only access the GPU carveout (physmem 0x80002000-0x80006000), which the GPU already has legitimate and exclusive access to.&lt;br /&gt;
| HAC-001-01 (Mariko/Tegra214/Tegra210b01)&lt;br /&gt;
| HAC-001 (Tegra210)&lt;br /&gt;
| Summer 2017&lt;br /&gt;
| December 28, 2017&lt;br /&gt;
| [[User:hexkyz|hexkyz]], [[User:SciresM|SciresM]] and [[User:qlutoo|qlutoo]]&lt;br /&gt;
|-&lt;br /&gt;
| Weak Security Engine context validation&lt;br /&gt;
| The Tegra X1 supports a &amp;quot;deep sleep&amp;quot; feature, where everything but DRAM and the PMC registers lose their content (and the SoC loses power). Upon awaking, the bootrom re-executes, restoring system state. Among these stored states is the Security Engine&#039;s saved state, which uses AES-128-CBC with a random key and all-zeroes IV. However, the bootrom doesn&#039;t perform a MAC on this data, and only validates the last block. This allows one to control most of security engine&#039;s state upon wakeup, if one has a way to modify the encrypted state buffer.&lt;br /&gt;
&lt;br /&gt;
With a way to modify the encrypted state buffer, one can thus dump keys from &amp;quot;write-only&amp;quot; keyslots, etc.&lt;br /&gt;
&lt;br /&gt;
This also bypasses the SBK protection of the bootROM: indeed, at warmboot, bootROM will always clear keyslot 0xE to prevent malicious code from saving the SBK. Moving the SBK to another keyslot in the saved context renders this protection moot.&lt;br /&gt;
&lt;br /&gt;
HAC-001-01 (Mariko/Tegra214/Tegra210b01): Fixes this by streamlining the context save process; security engine contexts are now saved to protected memory which the CPU cannot access or modify.&lt;br /&gt;
| HAC-001-01 (Mariko/Tegra214/Tegra210b01)&lt;br /&gt;
| HAC-001 (Tegra210)&lt;br /&gt;
| December 2017&lt;br /&gt;
| January 20, 2018&lt;br /&gt;
| [[User:SciresM|SciresM]] and [[User:motezazer|motezazer]]&lt;br /&gt;
|-&lt;br /&gt;
| Security Engine keyslots vulnerable to partial overwrite attack&lt;br /&gt;
| &lt;br /&gt;
The Tegra X1 security engine supports writing keyslot data to the engine with syntax as follows: &lt;br /&gt;
&lt;br /&gt;
SECURITY_ENGINE-&amp;gt;AES_KEYTABLE_ADDR = (keyslot &amp;lt;&amp;lt; 4) | (dword_index_in_keyslot); &lt;br /&gt;
&lt;br /&gt;
SECURITY_ENGINE-&amp;gt;AES_KEYTABLE_DATA = readle32(key, dword_index_in_keyslot * 4); &lt;br /&gt;
&lt;br /&gt;
However, the Security Engine flushes writes to the internal key tables immediately when AES_KEYTABLE_DATA is written -- this allows one to overwrite a single dword of a key at a time, and thus brute force the contents of keyslots in time (2^32 * 8) = 2^35 instead of 2^256.&lt;br /&gt;
| None&lt;br /&gt;
| HAC-001 (Tegra210)&lt;br /&gt;
| Theorized Summer 2017 due to suggestive syntax, confirmed April 9, 2018&lt;br /&gt;
| April 9, 2018&lt;br /&gt;
| [[User:SciresM|SciresM]], almost surely others (independently).&lt;br /&gt;
|-&lt;br /&gt;
| CVE-2018-6242 (leveraged by the ShofEL2 and Fusée Gelée exploits)&lt;br /&gt;
| The USB software stack provided inside the boot instruction rom (IROM/bootROM) contains a copy operation whose length can be controlled by an attacker. By carefully constructing a USB control request, an attacker can leverage this vulnerability to copy the contents of an attacker-controlled buffer over the active execution stack, gaining control of the Boot and Power Management processor (BPMP) before any lock-outs or privilege reductions occur. This execution can then be used to exfiltrate secrets and to load arbitrary code onto the main CPU Complex (CCPLEX) &amp;quot;application processors&amp;quot; at the highest possible level of privilege (typically as the TrustZone Secure Monitor at PL3/EL3).&lt;br /&gt;
| HAC-001-01 (Mariko/Tegra214/Tegra210b01) (also fixed independently on Tegra186).&lt;br /&gt;
| HAC-001 (Tegra210)&lt;br /&gt;
| January 2018&lt;br /&gt;
| April 23, 2018&lt;br /&gt;
| [[User:Shuffle2|shuffle2]] and fail0verflow (originally),&amp;lt;br&amp;gt; [[User:Ktemkin|ktemkin]] and ReSwitched Team (independently),&amp;lt;br&amp;gt; [[User:Naehrwert|naehrwert]] (independently),&amp;lt;br&amp;gt; [[User:Hexkyz|hexkyz]] (independently),&amp;lt;br&amp;gt; st4rk with [[User:Shinyquagsire23|Shiny Quagsire]] and Dazzozo (independently),&amp;lt;br&amp;gt; and many others (independently).&lt;br /&gt;
|-&lt;br /&gt;
| Poor validation of bootrom SDRAM configuration parameters leads to arbitrary writes in bootrom&lt;br /&gt;
| &lt;br /&gt;
The Tegra X1 bootrom supports saving SDRAM parameters to scratch registers, and using the saved configuration to enable DRAM during warmboot.&lt;br /&gt;
&lt;br /&gt;
The code that parses these parameters does if (params-&amp;gt;EmcBctSpareN) *params-&amp;gt;EmcBctSpareN = params-&amp;gt;EmcBctSpareNPlusOne for most N, without validating either the address or value written to it.&lt;br /&gt;
There are other arbitrary writes in this code, as well (e.g. BootromPatch parameters intended for patching MISC registers do not check a relative offset to 0x7000000, etc).&lt;br /&gt;
&lt;br /&gt;
This allows a user with access to the PMC registers (via pre-sleep bpmp execution, or otherwise) to gain arbitrary bootrom code execution.&lt;br /&gt;
&lt;br /&gt;
HAC-001-01 (Mariko/Tegra214/Tegra210b01): Fixes this by validating that the spare writes/bootrom patch before performing them.&lt;br /&gt;
| HAC-001-01 (Mariko/Tegra214/Tegra210b01)&lt;br /&gt;
| HAC-001 (Tegra210)&lt;br /&gt;
| 2017&lt;br /&gt;
| December 16, 2018&lt;br /&gt;
| Everyone (independently).&lt;br /&gt;
|-&lt;br /&gt;
| TSEC ROM does not clear crypto registers after signature verification&lt;br /&gt;
|&lt;br /&gt;
TSEC supports executing signed-microcode at a greater privilege level than normal payloads.&lt;br /&gt;
&lt;br /&gt;
When jumping to signed microcode, the caller is expected to load hardware crypto register $c6 = &amp;lt;signature&amp;gt;, $c7 = &amp;lt;seed (zero for all officially-signed microcode)&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
TSEC ROM then calculates the expected signature and compares it to the user-supplied one in $c6. On match, the secure payload is executed, and on failure an exception is raised.&lt;br /&gt;
&lt;br /&gt;
However, TSEC ROM fails to clear the crypto registers used to calculate the expected signature in either of the success/failure cases.&lt;br /&gt;
&lt;br /&gt;
Thus, with some way of obtaining the contents of crypto registers (e.g. ROP under some secure payload), an attacker can dump intermediary values from signature calculation.&lt;br /&gt;
&lt;br /&gt;
With enough data/trial/error, this is enough to reconstruct the signature algorithm:&lt;br /&gt;
* mac = &amp;lt;davies meyer hash of (page || address of page) for each 0x100 page in the payload&amp;gt;&lt;br /&gt;
* key = AES-ENCRYPT(hardware csecret 0x1, seed)&lt;br /&gt;
* signature = AES-ENCRYPT(key, mac)&lt;br /&gt;
&lt;br /&gt;
| None&lt;br /&gt;
| HAC-001 (Tegra210)&lt;br /&gt;
| Late 2018/Early 2019&lt;br /&gt;
| August 2020&lt;br /&gt;
| [[User:qlutoo|qlutoo]]/[[User:Hexkyz|hexkyz]]/[[User:Shuffle2|shuffle2]], [[User:SciresM|SciresM]]/[[User:motezazer|motezazer]] (independently).&lt;br /&gt;
|-&lt;br /&gt;
| TSEC signature validation design flaw leads to fake-signing&lt;br /&gt;
|&lt;br /&gt;
As mentioned above, when jumping to signed microcode the caller is expected to load hardware crypto register $c6 = &amp;lt;signature&amp;gt;, $c7 = &amp;lt;seed (zero for all officially-signed microcode)&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
However, TSEC ROM performs no validation on the input seed used to generate the signing key.&lt;br /&gt;
&lt;br /&gt;
This leads to the following attack:&lt;br /&gt;
* Attacker gains rop under any secure microcode payload with signature = S.&lt;br /&gt;
* Attacker uses the &amp;quot;csigenc&amp;quot; instruction to obtain K = AES-ENCRYPT(hardware csecret 0x1, S).&lt;br /&gt;
* Attacker jumps to their own microcode with $c6 = &amp;lt;signature calculated on pc using K&amp;gt;, $c7 = S&lt;br /&gt;
* TSEC ROM calculates key = AES-ENCRYPT(hardware csecret 0x1, S) = K, and the signature check passes.&lt;br /&gt;
* Attackers microcode is executed in secure mode as though it were signed by NVidia.&lt;br /&gt;
&lt;br /&gt;
Thus an attacker who has exploited *any* secure payload may use this to obtain a &amp;quot;fake signature key&amp;quot;, which can be used to sign and execute arbitrary microcode in secure mode.&lt;br /&gt;
&lt;br /&gt;
Note: this does not break the TSEC cryptosystem, as the csigenc mechanism relies on the signature of the executing microcode, and fakesigning produces different signatures from NVidia that cannot be controlled.&lt;br /&gt;
| None&lt;br /&gt;
| HAC-001 (Tegra210)&lt;br /&gt;
| Late 2018/Early 2019&lt;br /&gt;
| August 2020&lt;br /&gt;
| [[User:qlutoo|qlutoo]]/[[User:Hexkyz|hexkyz]]/[[User:Shuffle2|shuffle2]], [[User:SciresM|SciresM]]/[[User:motezazer|motezazer]] (independently).&lt;br /&gt;
|-&lt;br /&gt;
| ROP under TSEC secure bootrom via DMA engine stack overwrite (--xploit)&lt;br /&gt;
| TSEC DMA engine does not stop when entering TSEC secure bootrom. By pointing TSEC DMA to current stack before secure bootrom entry, stack can be controlled. &lt;br /&gt;
&lt;br /&gt;
One can then use blind ROP against the TSEC secure bootrom (which is execute only, and cannot be dumped).&lt;br /&gt;
&lt;br /&gt;
With sufficient effort, an attacker can construct a ROP chain that leads to csigcmp being executed with fully controlled arguments.&lt;br /&gt;
&lt;br /&gt;
This allows for arbitrary heavy secure mode code execution with the current signature set to an arbitrary value.&lt;br /&gt;
&lt;br /&gt;
This completely breaks the TSEC cryptosystem, by allowing one to obtain the result of csigenc with signature = &amp;lt;any desired value&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
This has many uses/results, notably including dumping the &amp;quot;true&amp;quot; signature key (set signature = zeroes, perform csigenc using csecret 0x1).&lt;br /&gt;
| None&lt;br /&gt;
| TSEC for all Tegra devices&lt;br /&gt;
| Late 2018&lt;br /&gt;
| January 2021&lt;br /&gt;
| [[User:Hexkyz|hexkyz]]/[[User:SciresM|SciresM]], [[User:Vale|Vale]]/[[User:Thog|Thog]] (independently), [[User:Tatsuko|Tatsuko]] (independently), possibly others (independently).&lt;br /&gt;
|-&lt;br /&gt;
| Boot straps are not relatched on watchdog resets (strapwn)&lt;br /&gt;
| On boot, the BOOTSELECT, RCM and RAM_CODE straps are latched from external GPIO to determine which boot medium to use and verify from in bootrom. However, APB_MISC_PP_STRAPPING_OPT_A can be overwritten with arbitrary values following bootrom. Write access to PP_STRAPPING_OPT_A would otherwise be mundane, however these straps are not relatched during a watchdog reset (despite being latched during other software resets), allowing for arbitrary straps to be selected and executed in bootrom.&lt;br /&gt;
&lt;br /&gt;
This allows setting NVPROD_UART on some hardware configurations where it would normally be unavailable (ie on Jetson Nano boards), but is otherwise mostly useless and/or useful for testing unintended boot options (such as USB Mass Storage boot) without having to move boot strap resistors.&lt;br /&gt;
| Unknown&lt;br /&gt;
| HAC-001 (Tegra210)&lt;br /&gt;
| May 2020&lt;br /&gt;
| April 30, 2021&lt;br /&gt;
| [[User:Shinyquagsire23|Shiny Quagsire]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Firmware =&lt;br /&gt;
Flaws in this category pertain to the firmware running on hardware devices, such as wifi/bluetooth, etc. Firmware is generally uploaded by sysmodules.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Summary&lt;br /&gt;
!  Description&lt;br /&gt;
!  Successful exploitation result&lt;br /&gt;
!  Fixed in system version&lt;br /&gt;
!  Last system version this flaw was checked for&lt;br /&gt;
!  Timeframe this was discovered&lt;br /&gt;
!  Public disclosure timeframe&lt;br /&gt;
!  Discovered by&lt;br /&gt;
|-&lt;br /&gt;
| Broadpwn (CVE-2017-9417)&lt;br /&gt;
| See [https://blog.exodusintel.com/2017/07/26/broadpwn/ here] and [https://www.blackhat.com/docs/us-17/thursday/us-17-Artenstein-Broadpwn-Remotely-Compromising-Android-And-iOS-Via-A-Bug-In-Broadcoms-Wifi-Chipsets.pdf here].&lt;br /&gt;
| Code execution on the wifi controller (untested on Switch).&lt;br /&gt;
| [[4.0.0]]&lt;br /&gt;
| [[4.0.0]]&lt;br /&gt;
| Switch: July 2022&lt;br /&gt;
| Switch: July 30, 2022&lt;br /&gt;
| Switch: [[User:Yellows8|yellows8]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Software =&lt;br /&gt;
== Bootloader ==&lt;br /&gt;
Flaws in this category pertain to any bootloader component such as the [[Package1#Package1ldr|package1ldr]], the [[Package1#Section_1|NX bootloader]] or the [[Package1#Section_0|warmboot binary]].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Summary&lt;br /&gt;
!  Description&lt;br /&gt;
!  Successful exploitation result&lt;br /&gt;
!  Fixed in system version&lt;br /&gt;
!  Last system version this flaw was checked for&lt;br /&gt;
!  Timeframe this was discovered&lt;br /&gt;
!  Public disclosure timeframe&lt;br /&gt;
!  Discovered by&lt;br /&gt;
|-&lt;br /&gt;
| Null-dereference in panic()&lt;br /&gt;
| The Switch&#039;s stage 1 bootloader, on panic(), clears the stack and then attempts to clear the Security Engine. However, it does so by dereferencing a pointer to the SE in .bss (initially NULL), and this pointer doesn&#039;t get initialized until partway into the bootloader&#039;s main() after several functions that might panic() are called. Thus, a panic() caused prior to SE initialization would result in the SE pointer still being NULL when dereferenced. &lt;br /&gt;
The BPMP doesn&#039;t have an active MPU and the bus won&#039;t data abort on an invalid address, so no exception will be entered: it&#039;ll end up overwriting some exception vectors with NULL before halting.&lt;br /&gt;
&lt;br /&gt;
In 3.0.0, this was fixed by moving the security engine initialization earlier in main(), before the first function that could potentially panic().&lt;br /&gt;
| Some exception vectors overwritten with NULL, before SBK/other keyslots are cleared. Probably useless for anything more interesting.&lt;br /&gt;
| [[3.0.0]]&lt;br /&gt;
| [[3.0.0]]&lt;br /&gt;
| Early July, 2017&lt;br /&gt;
| July 30, 2017&lt;br /&gt;
| Everyone who diff&#039;d 2.3.0 and 3.0.0 Package1&lt;br /&gt;
|-&lt;br /&gt;
| FUSE_DIS_PGM not written by package1 &lt;br /&gt;
| The switch&#039;s hardware fuse driver contains a write-once bit in a register called &amp;quot;FUSE_DIS_PGM&amp;quot;, which disables burning fuses until the next reboot. While Nintendo&#039;s bootloader code for waking up from sleep writes this on all firmware, the actual package1 initial bootloader forgets to write to it on cold reboot. &lt;br /&gt;
&lt;br /&gt;
This isn&#039;t too big of a problem because another fuse is burnt on retail devices (production mode), which prevents burning *all* fuses other than ODM_RESERVED ones in hardware.&lt;br /&gt;
&lt;br /&gt;
This was fixed in 3.0.0 by writing to the register on cold boot (although the write happens in TZ instead of package1 where it should take place, possibly to obfuscate the fact that they made this mistake).&lt;br /&gt;
| Burning arbitrary ODM reserved fuses with TZ code execution, which should never be possible for non-bootloader code.&lt;br /&gt;
&lt;br /&gt;
Warning: one could irreparably brick one&#039;s console by playing with this.&lt;br /&gt;
| [[3.0.0]]&lt;br /&gt;
| [[3.0.0]]&lt;br /&gt;
| Late summer/early fall 2017&lt;br /&gt;
| December 31, 2017&lt;br /&gt;
| [[User:SciresM|SciresM]], [[User:motezazer|motezazer]]&lt;br /&gt;
|-&lt;br /&gt;
| maconstack (TSEC firmware leaves MAC on the stack)&lt;br /&gt;
| Package1ldr loads a firmware blob into TSEC early on boot. This piece of code runs on the TSEC in Authenticated Mode and has the sole purpose of generating the per-console TSEC key (see [[Cryptosystem]]).&lt;br /&gt;
&lt;br /&gt;
As a way to mitigate attacks, the TSEC firmware blob is split into 3 stages: [[TSEC_Firmware#Boot|Boot]] which is unencrypted and unsigned, [[TSEC_Firmware#KeygenLdr|KeygenLdr]] which is unencrypted but signed and [[TSEC_Firmware#Keygen|Keygen]] which is encrypted and signed.&lt;br /&gt;
Boot loads a static pre-generated signature into the Falcon&#039;s CPU crypto registers, loads KeygenLdr into the Falcon&#039;s CODE region and jumps to it. Execution will proceed into KeygenLdr in Heavy Secure Mode if, and only if, the loaded signature matches the one Falcon calculates internally for KeygenLdr.&lt;br /&gt;
&lt;br /&gt;
Among various things, KeygenLdr will attempt to do a &amp;quot;backwards&amp;quot; security check by calculating a CMAC over Boot and comparing it with a known hash stored in the TSEC firmware&#039;s key data (a small buffer stored after Boot&#039;s code). If the hashes don&#039;t match, execution aborts.&lt;br /&gt;
&lt;br /&gt;
KeygenLdr stores the calculated Boot&#039;s CMAC in the stack, but forgets to clear it. Since the stack is located in Falcon&#039;s DATA region, loading the TSEC firmware blob and dumping the DATA region afterwards (via MMIO) will reveal the calculated hash.&lt;br /&gt;
This allows using KeygenLdr as an oracle to generate a valid CMAC for arbitrary Boot code. Replacing the CMAC in the TSEC firmware&#039;s key data region results in KeygenLdr accepting any Boot code, thus rendering this security measure useless.&lt;br /&gt;
&lt;br /&gt;
Additionally, since signed Falcon code can&#039;t be revoked without an hardware revision, an attacker can always reuse the flawed KeygenLdr code even if a fix is issued.&lt;br /&gt;
| Running TSEC firmware&#039;s KeygenLdr in a user controlled environment.&lt;br /&gt;
| None&lt;br /&gt;
| [[5.0.2]]&lt;br /&gt;
| January 2018&lt;br /&gt;
| April 29, 2018&lt;br /&gt;
| [[User:Hexkyz|hexkyz]], [[User:Rei|Reisyukaku]] (independently), probably others (independently).&lt;br /&gt;
|-&lt;br /&gt;
| pk1ldrhax&lt;br /&gt;
| Package1ldr decrypts and verifies the keyblob inside of the current BCT in order to get the package1 key, and then uses the package1 key to decrypt package1. It then validates package1 before jumping to it by checking the PK11 magic number, and that the section sizes sum to the expected size (and are individually less than the expected size). &lt;br /&gt;
&lt;br /&gt;
However, package1ldr does not actually validate the package1 key against a fixed vector (much like kernel9loader forgot to do so on the 3ds). This would normally not matter, as keyblobs are validated -- however, with bootrom code execution one can dump SBK and forge keyblobs, and thus control the package1 key. &lt;br /&gt;
&lt;br /&gt;
Thus (&#039;&#039;&#039;in theory, but not in practice due to the size of the brute force required&#039;&#039;&#039;) one can replace the package1 key with garbage, causing package1 to decrypt into garbage, and hope that this garbage passes validation checks and that package1ldr jumping into the garbage will do something useful.&lt;br /&gt;
&lt;br /&gt;
This was fixed incidentally in [[6.2.0]], as pk1ldr does not use keyblob data to decrypt package1 any more.&lt;br /&gt;
&lt;br /&gt;
| With a large enough brute force: arbitrary package1 code execution from coldboot.&lt;br /&gt;
&lt;br /&gt;
However, a usable brute force is on the order of &amp;gt;= ~2^80, so &#039;&#039;&#039;this is almost certainly not actually usable in any meaningful context&#039;&#039;&#039;.&lt;br /&gt;
| [[6.2.0]]&lt;br /&gt;
| [[6.2.0]]&lt;br /&gt;
| Early 2017 (as soon as plaintext package1ldr was first dumped)&lt;br /&gt;
| November 20, 2018&lt;br /&gt;
| Everyone&lt;br /&gt;
|-&lt;br /&gt;
| Stack smash in TSEC firmware&#039;s KeygenLdr&lt;br /&gt;
| Given that we can control the [[TSEC_Firmware#Key_data|key data]] (which is not authenticated) and the [[TSEC_Firmware#Boot|Boot]] blob (see &amp;quot;maconstack&amp;quot;), as well as the fact Non-secure and Heavy Secure code share the same stack, we can use this to attack KeygenLdr. KeygenLdr uses memcpy to copy over a payload to DMEM to verify it, which can be abused to smash the stack (in DMEM) and write over the return address of said function.&lt;br /&gt;
| ROP under KeygenLdr in Heavy Secure mode.&lt;br /&gt;
| None&lt;br /&gt;
| [[8.0.1]]&lt;br /&gt;
| Early 2018&lt;br /&gt;
| May 21, 2019&lt;br /&gt;
| Everyone (independently).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== TrustZone ==&lt;br /&gt;
Flaws in this category pertain exclusively to the [[Package1#Section_2|Secure Monitor]].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Summary&lt;br /&gt;
!  Description&lt;br /&gt;
!  Successful exploitation result&lt;br /&gt;
!  Fixed in system version&lt;br /&gt;
!  Last system version this flaw was checked for&lt;br /&gt;
!  Timeframe this was discovered&lt;br /&gt;
!  Public disclosure timeframe&lt;br /&gt;
!  Discovered by&lt;br /&gt;
|-&lt;br /&gt;
| Non-atomic mutexes&lt;br /&gt;
| When an [[SMC]] is called, TrustZone sets a global variable to mark that an SMC is in progress, so that two SMCs using shared resources (like the security engine) do not trample on one another. On 1.0.0, this global variable was written using non-atomic writes, and thus a race condition is possible.&lt;br /&gt;
&lt;br /&gt;
However, the SMC handler enforces that all SMCs must be called from core #3, unless the top-level handler ID is 1 (SMCs internal to the kernel). Thus, the only SMCs that can be run side-by-side are [any userland smc] and smcGetRandomBytesForKernel, and this turns out to not really be abusable.&lt;br /&gt;
| Mostly useless. Maybe some oob-write into unused (and thus useless) memory if running smcGetRandomBytesForKernel and smcGetRandomBytesForUser at the same time.&lt;br /&gt;
| [[2.0.0]]&lt;br /&gt;
| [[2.0.0]]&lt;br /&gt;
| December 2017 (Probably earlier by others)&lt;br /&gt;
| January 18, 2018&lt;br /&gt;
| [[User:SciresM|SciresM]], probably others (independently).&lt;br /&gt;
|-&lt;br /&gt;
| jamais vu (non-secure world access to PMC MMIO and pre-deep sleep firmware)&lt;br /&gt;
| On [[1.0.0]], one could map in the PMC registers in userland. In addition, [[AM_services|am]] ran a little-kernel based firmware on the BPMP at runtime. With code execution under am, one could modify the BPMP&#039;s little-kernel firmware to hook deep sleep entry, and modify TrustZone/Security engine state. &lt;br /&gt;
&lt;br /&gt;
This was fixed in [[2.0.0]] by making the PMC secure-world only, blacklisting the BPMP&#039;s exception vectors from being mapped, and thoroughly checking for malicious behavior on deep sleep entry.&lt;br /&gt;
| Arbitrary TrustZone code execution.&lt;br /&gt;
| [[2.0.0]]&lt;br /&gt;
| [[2.0.0]]&lt;br /&gt;
| December, 2017&lt;br /&gt;
| January 20, 2018&lt;br /&gt;
| [[User:SciresM|SciresM]] and [[User:motezazer|motezazer]]&lt;br /&gt;
|-&lt;br /&gt;
| Missed BPMP Exception Vector Writes&lt;br /&gt;
| Starting in [[2.0.0]], the BPMP is asleep at runtime, and is turned on by TrustZone during [[SMC|smcCpuSuspend]] in order to initiate the deep sleep process. When it does so, it is held in RESET, and TrustZone attempts to write to the BPMP exception vectors at 0x6000F200 to register EVP_RESET = lp0_entry_fw_crt0, and all other EVPs to a function that simply reboots. However, while they successfully write EVP_RESET, they miss all the other vectors, accidentally writing to the 0x6000F004-0x6000F020 region instead of the 0x6000F204-0x6000F220 region they want to write to. This results in all the exception vectors for the BPMP other than RESET being &amp;quot;undefined&amp;quot; (attacker controlled).&lt;br /&gt;
&lt;br /&gt;
With some way of causing an exception vector to be taken at the right time, this would give pre-sleep code execution (and thus arbitrary TrustZone code execution, via the security engine flaw). However, none of the abort vectors are really triggerable, and interrupts are disabled for the BPMP when it is taken out of reset. Thus, this is useless in practice.&lt;br /&gt;
&lt;br /&gt;
This was fixed in [[4.0.0]] by writing to the correct registers.&lt;br /&gt;
| Theoretically: Arbitrary TrustZone code execution. In practice: Useless.&lt;br /&gt;
| [[4.0.0]]&lt;br /&gt;
| [[4.0.0]]&lt;br /&gt;
| January, 2018&lt;br /&gt;
| February 23, 2018&lt;br /&gt;
| [[User:SciresM|SciresM]] and [[User:motezazer|motezazer]], [[User:Naehrwert|naehrwert]], [[User:Hexkyz|hexkyz]], probably others (independently).&lt;br /&gt;
|-&lt;br /&gt;
| TSEC has access to the secure kernel carveout &lt;br /&gt;
| TrustZone is responsible for managing security carveouts to prevent DMA controllers from accessing the carveout which contains the kernel, sysmodules, and other critical operating system data.&lt;br /&gt;
&lt;br /&gt;
Until [[8.0.0]], the list of devices that could access the carveout included the TSEC. However, the TSEC can bypass the SMMU when in authenticated mode by writing to a certain register. Thus, pwning nvservices would allow one to take over the TSEC, and use it to write to normally protected mmio/memory.&lt;br /&gt;
&lt;br /&gt;
In [[8.0.0]], this was fixed by removing TSEC access, and adding TSECB access (TSECB cannot bypass the SMMU).&lt;br /&gt;
| With access to the TSEC mmio (nvservices ROP) and code execution in TSEC Heavy Secure mode, kernel code execution, probably.&lt;br /&gt;
| [[8.0.0]]&lt;br /&gt;
| [[8.0.0]]&lt;br /&gt;
| 2017 (when TrustZone code plaintext was first obtained).&lt;br /&gt;
| April 15, 2019&lt;br /&gt;
| Everyone&lt;br /&gt;
|-&lt;br /&gt;
| deja vu (insufficient system state validation on suspend leads to pre-sleep BPMP code execution)&lt;br /&gt;
| Jamais Vu was fixed in [[2.0.0]] by making the PMC secure-world only, blacklisting the BPMP&#039;s exception vectors from being mapped, and thoroughly checking for malicious behavior on deep sleep entry, since gaining pre-sleep code execution on the BPMP compromises the system.&lt;br /&gt;
&lt;br /&gt;
However, the state validation performed by Nintendo&#039;s Secure Monitor was insufficient to prevent pre-sleep execution from being obtained.&lt;br /&gt;
&lt;br /&gt;
Prior to [[6.0.0]], one could use a DMA controller that had access to IRAM and was not held in reset (there were multiple) to race TrustZone&#039;s writes to the BPMP firmware in IRAM, and thus overwrite Nintendo&#039;s firmware with an attacker&#039;s to gain pre-sleep code execution.&lt;br /&gt;
&lt;br /&gt;
[[6.0.0]] addressed this by performing TrustZone state MAC writes and locking PMC scratch *before* turning on the BPMP, fixing the original Jamais Vu exploit entirely. In addition, the BPMP firmware in TrustZone&#039;s .rodata is now memcmp&#039;d to the actual data after it is written to IRAM. This mitigates race attacks that modify the firmware.&lt;br /&gt;
&lt;br /&gt;
However, Nintendo both forgot to validate the BPMP exception vectors after writing them, and forgot to hold in reset a DMA controller that can write to the BPMP&#039;s exception vectors.&lt;br /&gt;
&lt;br /&gt;
AHB-DMA is not blacklisted by kernel mapping whitelist (Nintendo probably forgot it, because the TX1 TRM does not really document that it&#039;s present, although the MMIO works as documented in older (Tegra 3 and before) TRMs).&lt;br /&gt;
&lt;br /&gt;
Thus, with kernel code execution (or some other way of accessing AHB-DMA, e.g. nspwn on &amp;lt;= 4.1.0, TSEC hax, or other arbitrary mmio access flaws), one can DMA to the BPMP&#039;s exception vectors as they are written, causing TrustZone to start the BPMP executing an attacker&#039;s firmware at a different location than TrustZone intends/validates.&lt;br /&gt;
&lt;br /&gt;
This was fixed in [[8.0.0]] by blocking AHB-DMA arbitration and verifying it is held in reset during suspend, and thus there are no more devices that can write to the relevant MMIO at the right time.&lt;br /&gt;
&lt;br /&gt;
| Arbitrary TrustZone/BootROM code execution, by using either the original Jamais Vu flaw (prior to [[6.0.0]] or a warmboot bootrom exploit (any firmware where pre-sleep execution can be gained).&lt;br /&gt;
| [[8.0.0]]&lt;br /&gt;
| [[8.0.0]]&lt;br /&gt;
| December 2017&lt;br /&gt;
| April 15, 2019&lt;br /&gt;
| [[User:SciresM|SciresM]], [[User:motezazer|motezazer]] and ktemkin,  [[User:Naehrwert|naehrwert]] (independently), almost certainly others (independently)&lt;br /&gt;
|-&lt;br /&gt;
| TrustZone allows using imported RSA exponents with arbitrary modulus&lt;br /&gt;
| TrustZone supports &amp;quot;importing&amp;quot; RSA private exponents for use by userland -- these are stored encrypted with TrustZone only keydata in NAND, and decrypted only to TZRAM. This prevents a console that has compromised userland from learning the private exponents of these keys and doing calculations with them offline. In practice, this is used for FS (gamecard communications), ES (drm), and SSL (console client cert communications).&lt;br /&gt;
&lt;br /&gt;
However, the actual SMC API only imports the RSA exponent, and not the modulus, which is passed separately by userland in each call. There is no validation done on the modulus passed in -- this means that userland can pass in any message and modulus it chooses, and obtain the result of (message ^ private exponent) % modulus back from the secure monitor.&lt;br /&gt;
&lt;br /&gt;
By choosing a prime number modulus P such that P has &amp;quot;smooth&amp;quot; order (totient(P) == P-1 is divisible only by &amp;quot;small&amp;quot; primes), one can efficiently use the [[wikipedia:Pohlig-Hellman algorithm|Pohlig-Hellman algorithm]] to calculate the discrete logarithm of such a result directly, and thus obtain the private exponent.&lt;br /&gt;
&lt;br /&gt;
This is mostly useless in practice, given the general availability of other exploits to obtain these decrypted exponents.&lt;br /&gt;
&lt;br /&gt;
This was fixed in 10.0.0 by importing the modulus in addition to the exponent for the ES device key and ES client cert key. For backwards compatibility reasons the SSL key and Lotus key still only import the exponent.&lt;br /&gt;
&lt;br /&gt;
StorageExpMod also now validates that the exponentiation of &amp;quot;DDDDD...&amp;quot; about the provided modulus by the imported exponent and then the fixed public exponent returns &amp;quot;DDDDD...&amp;quot;, and returns invalid argument if validation fails.&lt;br /&gt;
| With userland privileges sufficient to use an imported RSA key: obtaining that RSA key&#039;s private exponent.&lt;br /&gt;
| [[10.0.0]]&lt;br /&gt;
| [[10.0.0]]&lt;br /&gt;
| August 14, 2019&lt;br /&gt;
| August 14, 2019&lt;br /&gt;
| [[User:SciresM|SciresM]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Kernel ==&lt;br /&gt;
Flaws in this category pertain exclusively to the [[Package2#Section_0|HorizonOS Kernel]].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Summary&lt;br /&gt;
!  Description&lt;br /&gt;
!  Successful exploitation result&lt;br /&gt;
!  Fixed in system version&lt;br /&gt;
!  Last system version this flaw was checked for&lt;br /&gt;
!  Timeframe this was discovered&lt;br /&gt;
!  Public disclosure timeframe&lt;br /&gt;
!  Discovered by&lt;br /&gt;
|-&lt;br /&gt;
| Syscall Infoleaks&lt;br /&gt;
| Many syscalls leaked kernel pointers on sad paths (for example svcSetHeapSize and svcQueryMemory), until they landed a bunch of fixes in 2.0.0.&lt;br /&gt;
| Nothing really.&lt;br /&gt;
| [[2.0.0]]&lt;br /&gt;
| [[2.0.0]]&lt;br /&gt;
| &lt;br /&gt;
| 2017&lt;br /&gt;
| Everyone&lt;br /&gt;
|-&lt;br /&gt;
| svcWaitSynchronization/svcReplyAndReceive bad cleanup on error&lt;br /&gt;
| If there is a page fault when fetching handles from the userspace array, it cleans up by dereferencing all objects despite having only loaded first N. Allows the attacker to make arbitrary decrefs on any kernel synchronization object, and thus can be used to get UAF. Haven&#039;t actually been tried on real HW though, but should work (tm).&lt;br /&gt;
| Kernel code execution&lt;br /&gt;
| [[2.0.0]]&lt;br /&gt;
| [[2.0.0]]&lt;br /&gt;
| &lt;br /&gt;
| April 24, 2017&lt;br /&gt;
| [[User:qlutoo|qlutoo]]&lt;br /&gt;
|-&lt;br /&gt;
| Bad irq_id check in CreateInterruptEvent&lt;br /&gt;
| CreateInterruptEvent syscall is designed to work only for irq_id &amp;gt;= 32. All irq_ids &amp;lt; 32 are &amp;quot;per-core&amp;quot; and reserved for kernel use (watchdog/scheduling/core communications).&lt;br /&gt;
On 1.0.0 you could supply irq_id &amp;lt; 32 and it would write outside the SharedIrqs table.&lt;br /&gt;
| You can register irq&#039;s in the Core3Irqs table, and thus register per-core irqs for core3, that are normally reserved for kernel. Useless.&lt;br /&gt;
| [[2.0.0]]&lt;br /&gt;
| [[2.0.0]]&lt;br /&gt;
| October 2017&lt;br /&gt;
| October 17, 2017&lt;br /&gt;
| [[User:qlutoo|qlutoo]]&lt;br /&gt;
|-&lt;br /&gt;
| Kernel .text mapped executable in usermode&lt;br /&gt;
| Prior to [[3.0.2]] the kernel .text was [[Memory_layout|mapped]] in usermode as executable. This can be used for usermode ROP for bypassing ASLR, but SVCs/IPC are not usable by running kernel .text in usermode.&lt;br /&gt;
| Executing kernel .text in usermode&lt;br /&gt;
| [[3.0.2]]&lt;br /&gt;
| [[3.0.2]]&lt;br /&gt;
| &lt;br /&gt;
| December 28, 2017 (34c3)&lt;br /&gt;
| [[User:qlutoo|qlutoo]]&lt;br /&gt;
|-&lt;br /&gt;
| Memory Controller not properly secured&lt;br /&gt;
| The Switch OS originally had the memory controller not set to be accessible only by the secure-world, which was problematic because insecure access can compromise the kernel.&lt;br /&gt;
&lt;br /&gt;
This was fixed partially in [[2.0.0]] by blacklisting the memory controller from being mapped by user-processes, and was fixed entirely in [[4.0.0]] by making the memory controller TZ-only and making all kernel accesses go through [[SMC|smcReadWriteRegister]].&lt;br /&gt;
| With some way to access the memory controller MMIO, arbitrary kernel code execution.&lt;br /&gt;
| [[4.0.0]]&lt;br /&gt;
| [[4.0.0]]&lt;br /&gt;
| January 2018&lt;br /&gt;
| January 2018&lt;br /&gt;
| [[User:SciresM|SciresM]], [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| Potential [[SVC|svcWaitForAddress]] thread use-after-free&lt;br /&gt;
| Between [[4.0.0]], where svcWaitForAddress was introduced, and [[7.0.0]], there was a second intrusive rbtree node in KThread for the WaitForAddress tree (the key being (address, priority), sorted lexicographically). Unlike the WaitProcessWideKeyAtomic tree, the kernel forgot to reinsert the WaitForAddress node when the thread&#039;s priority changed (priority inheritance and/or SetPriority), breaking the rbtree invariants; and since the kernel walks through the entire tree to remove intrusive nodes, you could cause threads to stay in the tree even after their deletion.&lt;br /&gt;
&lt;br /&gt;
[[7.0.0]] fixed the issue by using the same intrusive node for both trees. The thread/node knows which tree it is in, and the latter is correctly updated when thread priority changes.&lt;br /&gt;
| It unluckily didn&#039;t look exploitable&lt;br /&gt;
| [[7.0.0]]&lt;br /&gt;
| [[7.0.0]]&lt;br /&gt;
| July 2018&lt;br /&gt;
| February 2019&lt;br /&gt;
| [[User:TuxSH|TuxSH]]&lt;br /&gt;
|-&lt;br /&gt;
| Kernel RWX identity mapping never unmapped&lt;br /&gt;
| During init, the kernel binary is identity-mapped as RWX at 0x80060000; this is necessary to facilitate the transitionary period while the MMU is being enabled but mappings for e.g. KASLR are not yet determined, and also to enable smooth MMU enable transition during wake-from-sleep.&lt;br /&gt;
&lt;br /&gt;
However, the identity mapping was never unmapped, and thus the whole kernel code bin remained permanently mapped as RWX for all kernel threads (any thread which does not have an owner process and thus uses the KSupervisorPageTable TTBR0).&lt;br /&gt;
&lt;br /&gt;
Thus, any theoretical exploit which would give kernel memory corruption or ROP under a kernel thread would allow making use of this mapping to modify kernel text + bypass KASLR.&lt;br /&gt;
&lt;br /&gt;
This was fixed in [[16.0.0]] by unmapping the identity-mapping during init, and re identity-mapping only the very first page of kernel .text as R-X (for use by wake-from-sleep), which fixes the shellcode problem and mostly fixes the ROP problem, since this page mostly lacks interesting gadgets.&lt;br /&gt;
| In theory, with another exploitable kernel memory corruption (or ROP under kernel thread) bug: bypassing KASLR + modifying kernel .text. &lt;br /&gt;
&lt;br /&gt;
However, no such bugs are known.&lt;br /&gt;
| [[16.0.0]]&lt;br /&gt;
| [[16.0.0]]&lt;br /&gt;
| Summer 2018&lt;br /&gt;
| February 2023&lt;br /&gt;
| Everyone&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== BootImagePackage System Modules ==&lt;br /&gt;
Flaws in this category pertain to any of the [[Package2#Section_1|built-in system modules]].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Summary&lt;br /&gt;
!  Description&lt;br /&gt;
!  Successful exploitation result&lt;br /&gt;
!  Fixed in system version&lt;br /&gt;
!  Last system version this flaw was checked for&lt;br /&gt;
!  Timeframe this was discovered&lt;br /&gt;
!  Public disclosure timeframe&lt;br /&gt;
!  Discovered by&lt;br /&gt;
|-&lt;br /&gt;
| Service access control bypass (sm:h, smhax, probably other names)&lt;br /&gt;
| Prior to [[3.0.1]], the &#039;&#039;service manager&#039;&#039; (sm) built-in system module treats a user as though it has full permissions if the user creates a new &amp;quot;sm:&amp;quot; port session but bypasses [[Services_API#Initialize|initialization]]. This is due to the other sm commands skipping the service ACL check for Pids &amp;lt;= 7 (i.e. all kernel bundled modules) and that skipping the initialization command leaves the Pid field uninitialized.&lt;br /&gt;
In [[3.0.1]], sm returns error code 0x415 if [[Services_API#Initialize|Initialize]] has not been called yet.&lt;br /&gt;
| Acquiring, registering, and unregistering arbitrary services&lt;br /&gt;
| [[3.0.1]]&lt;br /&gt;
| [[3.0.1]]&lt;br /&gt;
| May 2017&lt;br /&gt;
| August 17, 2017&lt;br /&gt;
| Everyone&lt;br /&gt;
|-&lt;br /&gt;
| Overly permissive SPL service&lt;br /&gt;
| The concept behind the switch&#039;s [[SMC|Secure Monitor]] is that all cryptographic keydata is located in userspace, but stored as &amp;quot;access keys&amp;quot; encrypted with &amp;quot;keks&amp;quot; that never leave TrustZone. The [[SPL services|spl]] (&amp;quot;security processor liaison&amp;quot;?) service serves as an interface between the rest of the system and the secure monitor. Prior to [[4.0.0]], spl exposed only a single service &amp;quot;spl:&amp;quot;, which provided all TrustZone wrapper functions to all sysmodules with access to it. Thus anyone with access to the spl: service (via smhax or by pwning a sysmodule with access) could do crypto with any access keys they knew. &lt;br /&gt;
&lt;br /&gt;
This was fixed in [[4.0.0]] by splitting spl: into spl:, spl:mig, spl:ssl, spl:es, and spl:fs.&lt;br /&gt;
| Arbitrary spl: crypto with any access keys one knows. For example, one could use the SSL module&#039;s access keys to decrypt their console&#039;s SSL certificate private key without having to pwn the SSL sysmodule.&lt;br /&gt;
| [[4.0.0]]&lt;br /&gt;
| [[4.0.0]]&lt;br /&gt;
| Summer 2017 (after smhax was discovered).&lt;br /&gt;
| December 23, 2017&lt;br /&gt;
| Everyone&lt;br /&gt;
|-&lt;br /&gt;
| Single session services not really single session&lt;br /&gt;
| Several &amp;quot;critical&amp;quot; services (like fsp-ldr, fsp-pr, sm:m, etc) are meant to only ever hold a single session with a specific sysmodule. However, when a sysmodule dies, all its service session handles are released -- and thus killing the holder of a single session handle would allow one (via sm:hax etc) to get access to that service. &lt;br /&gt;
&lt;br /&gt;
This was fixed in [[4.0.0]] by adding a semaphore to these critical single-session services, so that even if one gets access to them an error code will be returned when attempting to use any of their commands.&lt;br /&gt;
| With some way to access these services and kill their session holders (like expLDR): dumping sysmodule code, arbitrary service access, elevated filesystem permissions, etc.&lt;br /&gt;
| [[4.0.0]]&lt;br /&gt;
| [[4.0.0]]&lt;br /&gt;
| May/June 2017 (basically immediately after smhax was discovered)&lt;br /&gt;
| December 30, 2017&lt;br /&gt;
| Everyone&lt;br /&gt;
|-&lt;br /&gt;
| nspwn&lt;br /&gt;
| fsp-ldr command 0 &amp;quot;MountCode&amp;quot; takes in a Content Path (retrieved from NCM by Loader), and returns an IFileSystem for the resulting ExeFS. These content paths, are normally NCAs, but MountCode also supports a number of other formats, including &amp;quot;.nsp&amp;quot; -- which is just a PFS0.&lt;br /&gt;
&lt;br /&gt;
When a path ending in &amp;quot;.nsp&amp;quot; is parsed by MountCode, the PFS0 is treated as a raw ExeFS. Because there is no NCA header, the ACID signatures are not validated -- and because there are no other signatures in a PFS0, this results in no signature checking happening at all.&lt;br /&gt;
&lt;br /&gt;
The actual .nsp handling is eventually done by {content mounting function} called by MountCode and other FS commands.&lt;br /&gt;
&lt;br /&gt;
Thus, by placing an ExeFS (NSOs + &amp;quot;main.npdm&amp;quot;) and setting one&#039;s desired title ID to &amp;quot;@Sdcard:/some_title.nsp&amp;quot; or &amp;quot;@User:/some_title.nsp&amp;quot; etc one can launch arbitrary unsigned code, with arbitrary unsigned NPDMs.&lt;br /&gt;
&lt;br /&gt;
This appears to have been fixed by only allowing .nsp when the input fstype==7 for the internal content-mounting function, returning 0x2EE202 otherwise.&lt;br /&gt;
| With access to &amp;quot;lr&amp;quot;: Arbitrary code execution with full system privileges.&lt;br /&gt;
| [[5.0.0]]&lt;br /&gt;
| [[5.0.0]]&lt;br /&gt;
| Late 2017&lt;br /&gt;
| April 23, 2018&lt;br /&gt;
| Everyone&lt;br /&gt;
|-&lt;br /&gt;
| Single null-byte stack overflow in Loader ContentPath parsing&lt;br /&gt;
| Previously, loader content path parsing looked like this, where path_from_lr was up to 0x300 bytes and not necessarily null-terminated:&lt;br /&gt;
&lt;br /&gt;
  char nca_path[0x300] = {0};&lt;br /&gt;
  strcat(nca_path, path_from_lr);&lt;br /&gt;
  for (int i = 0; nca_path[i]; i++) {&lt;br /&gt;
      if (nca_path[i] == &#039;\\&#039;) { nca_path[i] = &#039;/&#039;); }&lt;br /&gt;
  }&lt;br /&gt;
&lt;br /&gt;
Thus, a content path of the maximum length (0x300 bytes) would result in strcat writing a NULL terminator past the end of the nca_path buffer.&lt;br /&gt;
&lt;br /&gt;
This was fixed in [[6.0.0]], the new code looks like this:&lt;br /&gt;
&lt;br /&gt;
  char nca_path[0x300];&lt;br /&gt;
  strncpy(nca_path, path_from_lr, sizeof(nca_path));&lt;br /&gt;
  for (int i = 0; i  &amp;lt; sizeof(nca_path) &amp;amp;&amp;amp; nca_path[i]; i++) {&lt;br /&gt;
      if (nca_path[i] == &#039;\\&#039;) { nca_path[i] = &#039;/&#039;); }&lt;br /&gt;
  }&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| With access to &amp;quot;lr&amp;quot;: single null-byte stack overflow in Loader. Maybe (but probably not) loader code execution.&lt;br /&gt;
| [[6.0.0]]&lt;br /&gt;
| [[6.0.0]]&lt;br /&gt;
| September 2, 2018&lt;br /&gt;
| September 19, 2018&lt;br /&gt;
| [[User:SciresM|SciresM]]&lt;br /&gt;
|-&lt;br /&gt;
| System modules vulnerable to selective downgrade attacks&lt;br /&gt;
| Horizon has no mechanism for specifying the specific title version to Loader on process creation.&lt;br /&gt;
&lt;br /&gt;
Observing this, one can note that after a system update one could install a downgraded version of a specific system module (e.g. nvservices) while leaving the rest of the OS at the same version.&lt;br /&gt;
&lt;br /&gt;
Unless there was some breaking API change, this allows one to make a console vulnerable once more to an exploit in a sysmodule by downgrading it and nothing else.&lt;br /&gt;
&lt;br /&gt;
This was fixed in [[8.1.0]] by incrementing a version field in NPDM, and checking it against a hardcoded list for certain titles in Loader&#039;s process creation func.&lt;br /&gt;
| With access to content installation commands (or a vulnerable lower version to selectively install newer titles), reintroducing bugs in vulnerable system modules on newer firmware versions.&lt;br /&gt;
| [[8.1.0]]&lt;br /&gt;
| [[8.1.0]]&lt;br /&gt;
| When FIRM was first dumped in 2017.&lt;br /&gt;
| June 17, 2019&lt;br /&gt;
| Everyone&lt;br /&gt;
|-&lt;br /&gt;
| Broken RNG for [[Loader_services|Loader]] ASLR&lt;br /&gt;
| The RNG used for generating the ASLR slide is only seeded with 32bits, with the data from [[SVC|svcGetInfo]]. Hence, one could bruteforce the seed if one has infoleaks from any programs. This can be successfully bruteforced with at least 2 sample codebin addrs from different programs (with only 1 sample a lot of invalid seeds are found), however in some cases more than 1 seed might be found.&lt;br /&gt;
&lt;br /&gt;
With [15.0.0+] Loader now uses csrng_GenerateRandomBytes for determining the ASLR slide.&lt;br /&gt;
&lt;br /&gt;
See also [https://github.com/switchbrew/loader-aslr-solver loader-aslr-solver].&lt;br /&gt;
| Breaking ASLR for all non-KIP processes, allowing predicting the main-codebin base addr for all non-KIP processes until the next reboot.&lt;br /&gt;
| [[15.0.0]]&lt;br /&gt;
| [[15.0.0]]&lt;br /&gt;
| January 30, 2022 (presumably found much earlier?)&lt;br /&gt;
| October 11, 2022&lt;br /&gt;
| Everyone&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== System Modules ==&lt;br /&gt;
Flaws in this category pertain to any non-built-in system module.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Summary&lt;br /&gt;
!  Description&lt;br /&gt;
!  Successful exploitation result&lt;br /&gt;
!  Fixed in system version&lt;br /&gt;
!  Last system version this flaw was checked for&lt;br /&gt;
!  Timeframe this was discovered&lt;br /&gt;
!  Public disclosure timeframe&lt;br /&gt;
!  Discovered by&lt;br /&gt;
|-&lt;br /&gt;
| OOB Read in NS system module (pl:utoohax, pl:utonium, maybe other names)&lt;br /&gt;
| Prior to [[3.0.0]], pl:u (Shared Font services implemented in the NS sysmodule) service commands 1,2,3 took in a signed 32-bit index and returned that index of an array but did not check that index at all. This allowed for an arbitrary read within a 34-bit range (33-bit signed) from NS .bss. In [[3.0.0]], sending out of range indexes causes error code 0x60A to be returned.&lt;br /&gt;
| Dumping full NS .text, .rodata and .data, infoleak, etc&lt;br /&gt;
| [[3.0.0]]&lt;br /&gt;
| [[3.0.0]]&lt;br /&gt;
| April 2017&lt;br /&gt;
| June 19, 2017&lt;br /&gt;
| [[User:qlutoo|qlutoo]], ReSwitched Team (independently)&lt;br /&gt;
|-&lt;br /&gt;
| Unchecked domain ID in common IPC code&lt;br /&gt;
| Prior to [[2.0.0]], object IDs in [[IPC_Marshalling#Domain_message|domain messages]] are not bounds checked. This out-of-bounds read could be exploited to brute-force ASLR and get PC control in some services that support domain messages.&lt;br /&gt;
|&lt;br /&gt;
| [[2.0.0]]&lt;br /&gt;
| [[2.0.0]]&lt;br /&gt;
| July 2017&lt;br /&gt;
| July 20, 2017‎&lt;br /&gt;
| [[User:hthh|hthh]]&lt;br /&gt;
|-&lt;br /&gt;
| Out-of-bounds array read for [[BCAT_Content_Container]] secret-data index&lt;br /&gt;
| The [[BCAT_Content_Container]] secret-data index is not validated at all. This is handled before the RSA-signature(?) is ever used. Since the field is an u8, a total of 0x800-bytes relative to the array start can be accessed.&lt;br /&gt;
This is not useful since the string loaded from this array is only involved with key-generation.&lt;br /&gt;
| &lt;br /&gt;
| Unknown&lt;br /&gt;
| [[2.0.0]]&lt;br /&gt;
| August 4, 2017&lt;br /&gt;
| August 6, 2017&lt;br /&gt;
| [[User: shinyquagsire23|Shiny Quagsire]], [[User:Yellows8|yellows8]] (independently)&lt;br /&gt;
|-&lt;br /&gt;
| expLDR (sysmodule handle table exhaustion)&lt;br /&gt;
| Most sysmodules share common template code to handle IPC control messages. The command DuplicateSession (type 5 command 2)&#039;s template code will abort() if it fails to duplicate a session&#039;s handle for the requester. Because many sysmodules have limited handle table size (smaller than the browser/other entrypoints), repeatedly requesting to duplicate one&#039;s session will cause the sysmodule to run out of handle table space and abort, causing the service to release all its handles cleanly.&lt;br /&gt;
| Sysmodule crashes.  Most usefully, crashing ldr allows access to fsp-ldr and crashing pm allows access to fsp-pr. Useless after [[4.0.0]], which mitigated a number of single-session service access issues.&lt;br /&gt;
| Unfixed&lt;br /&gt;
| [[4.1.0]]&lt;br /&gt;
| June 24, 2017&lt;br /&gt;
| March 8, 2018&lt;br /&gt;
| [[User:daeken|daeken]]&lt;br /&gt;
|-&lt;br /&gt;
| Transfer Memory leak in nvservices system module&lt;br /&gt;
| The nvservices sysmodule does not clear most of its transfer memory prior to release.&lt;br /&gt;
| The calling process can read key bits of memory, including breaking ASLR (by revealing the image base) and exposing the address of other transfer memory to set up attacks. More details here: [https://daeken.svbtle.com/nintendo-switch-nvservices-info-leak transfermeme (nvservices info leak)] by [[User:daeken|daeken]]&lt;br /&gt;
| [[6.0.0]]&lt;br /&gt;
| [[6.0.0]]&lt;br /&gt;
| June 2017&lt;br /&gt;
| October 16, 2018&lt;br /&gt;
| [[User:qlutoo|qlutoo]] and [[User:hexkyz|hexkyz]],&lt;br /&gt;
[[User:daeken|daeken]] (independently)&lt;br /&gt;
|-&lt;br /&gt;
| OOB write in audio system module&lt;br /&gt;
| Prior to [[2.0.0]], the [[Audio_services#audout:u|AppendAudioOutBuffer]] and [[Audio_services#audin:u|AppendAudioInBuffer]] IPC commands would blindly increment the appended buffers&#039; count while using said count value as an index to where the user data should be copied into. This resulted in an 0x28 bytes, user controlled, out-of-bounds memory write into the [[Audio_services|audio]] sysmodule&#039;s memory space.&lt;br /&gt;
Combined with the [[Audio_services#audout:u|GetReleasedAudioOutBuffer]] or [[Audio_services#audin:u|GetReleasedAudioInBuffer]] commands, this could also be used as an 8 byte infoleak.&lt;br /&gt;
&lt;br /&gt;
In [[2.0.0]], the commands now return error code 0x1099 if the number of unreleased buffers exceeds 0x1F.&lt;br /&gt;
| Code execution under audio sysmodule&lt;br /&gt;
| [[2.0.0]]&lt;br /&gt;
| [[2.0.0]]&lt;br /&gt;
| &lt;br /&gt;
| November 2, 2018&lt;br /&gt;
| [[User:hexkyz|hexkyz]], probably others (independently).&lt;br /&gt;
|-&lt;br /&gt;
| Infoleak in nvservices system module&lt;br /&gt;
| The [[NV_services|nvservices]] ioctl [[NV_services#NVMAP_IOC_ALLOC|NVMAP_IOC_ALLOC]] takes an optional argument &amp;quot;addr&amp;quot; which allows the calling process to pass a pointer to user allocated memory for backing a nvmap object. If &amp;quot;addr&amp;quot; is left as 0, nvservices uses the transfer memory region (donated by the user during initialization) instead, when allocating memory for the nvmap object.&lt;br /&gt;
By design, freeing the nvmap object by calling the ioctl [[NV_services#NVMAP_IOC_FREE|NVMAP_IOC_FREE]] returns, in its &amp;quot;refcount&amp;quot; argument, the user address previously supplied if the reference count reaches 0.&lt;br /&gt;
However, prior to [[6.2.0]], the case where the transfer memory region is used to allocate the nvmap object was not taken into account, thus resulting in [[NV_services#NVMAP_IOC_FREE|NVMAP_IOC_FREE]] leaking back an address from within the transfer memory region mapped in nvservices&#039; memory space.&lt;br /&gt;
&lt;br /&gt;
In [[6.2.0]], [[NV_services#NVMAP_IOC_FREE|NVMAP_IOC_FREE]] no longer returns the address when the transfer memory region is used instead of user supplied memory.&lt;br /&gt;
| Combined with other vulnerabilities: Defeating ASLR in nvservices sysmodule.&lt;br /&gt;
| [[6.2.0]]&lt;br /&gt;
| [[6.2.0]]&lt;br /&gt;
| April 2017&lt;br /&gt;
| November 24, 2018&lt;br /&gt;
| Everyone&lt;br /&gt;
|-&lt;br /&gt;
| nvhax (memory corruption in nvservices system module)&lt;br /&gt;
| Prior to [[6.2.0]], the [[NV_services|nvservices]] ioctl [[NV_services#.2Fdev.2Fnvhost-ctrl-gpu|NVGPU_GPU_IOCTL_WAIT_FOR_PAUSE]] would take a single &amp;quot;pwarpstate&amp;quot; argument which would be interpreted by nvservices as a memory pointer for writing 2 &amp;quot;warpstate&amp;quot; structs (one for each Streaming Multiprocessor).&lt;br /&gt;
This resulted in nvservices attempting to blindly memcpy into this user supplied address and trigger a crash. However, if paired with an infoleak, this could be used to arbitrarily write 0x30 bytes anywhere in nvservices&#039; memory space.&lt;br /&gt;
Additionally, the &amp;quot;warpstate&amp;quot; struct itself was never initialized, which means nvservices would leak the 0x30 bytes from the stack. By invoking other ioctls it was also possible to partially control the stack contents and achieve a usable arbitrary memory write primitive.&lt;br /&gt;
&lt;br /&gt;
In [[6.2.0]], [[NV_services#.2Fdev.2Fnvhost-ctrl-gpu|NVGPU_GPU_IOCTL_WAIT_FOR_PAUSE]] now takes 2 inline &amp;quot;warpstate&amp;quot; structs instead of a &amp;quot;pwarpstate&amp;quot; pointer, thus effectively avoiding the bad memcpy.&lt;br /&gt;
| Code execution under nvservices sysmodule&lt;br /&gt;
| [[6.2.0]]&lt;br /&gt;
| [[6.2.0]]&lt;br /&gt;
| April 5, 2017&lt;br /&gt;
| November 24, 2018&lt;br /&gt;
| [[User:hexkyz|hexkyz]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Applet_Manager_services#IStorage|AM IStorage]] infoleak&lt;br /&gt;
| Originally the buffer allocated by [[Applet_Manager_services#CreateStorage|CreateStorage]] using the specified input size was not cleared. With [8.0.0+] this was fixed by adding a memset() for the buffer after successful allocation.&lt;br /&gt;
&lt;br /&gt;
Hence, IStorage-&amp;gt;IStorageAccessor-&amp;gt;Read will return uninitialized memory when the Write cmd was not previously used with the specified region.&lt;br /&gt;
| Infoleak from the main [[Applet_Manager_services#IStorage|AM]] heap, allowing defeating ASLR by reading addresses from previously allocated objects.&lt;br /&gt;
| [[8.0.0]]&lt;br /&gt;
| [[8.1.0]]&lt;br /&gt;
| December 2018&lt;br /&gt;
| August 9, 2019&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[HID_services#hid:sys|hid:sys]] ButtonConfig s32 array-index not validated&lt;br /&gt;
| The input s32 array-index for [[HID_services#hid:sys|hid:sys]] ButtonConfig cmds 1255-1270 was originally not validated. Using a negative or &amp;gt;=5 index results in accessing out-of-bounds data, with an array stored on stack.&lt;br /&gt;
[10.1.0-10.2.0] Each of these cmds will now Abort if the s32 is negative or &amp;gt;=5. [11.0.0+] Now an unsigned compare is used, with 0 or an error being immediately returned when the value is invalid.&lt;br /&gt;
| hid infoleak, out-of-bounds mem-write anywhere in hid address-space relative to the stack array (with constraints on the data).&lt;br /&gt;
| [[10.1.0]]&lt;br /&gt;
| [[11.0.1]]&lt;br /&gt;
| April 18, 2020&lt;br /&gt;
| July 14, 2020&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Bluetooth_Driver_services|Bluetooth]] sdp_server.cc process_service_search() continuation request p_req validation&lt;br /&gt;
| With [5.0.0+], the following was added to the if-block prior to loading cont_offset from p_req: &amp;lt;code&amp;gt;(p_req + sizeof(cont_offset) &amp;gt; p_req_end)&amp;lt;/code&amp;gt; (which verifies that cont_offset is within message bounds).&lt;br /&gt;
| Bluetooth-sysmodule out-of-bounds read from heap, probably not useful since the read value must match a state field, etc.&lt;br /&gt;
| [[5.0.0]]&lt;br /&gt;
| [[11.0.0]]&lt;br /&gt;
| Switch: December 2020&lt;br /&gt;
| Switch: December 25, 2020&lt;br /&gt;
| Switch: [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Bluetooth_Driver_services|Bluetooth]] A-63146698&lt;br /&gt;
| [https://android.googlesource.com/platform/system/bt/+/226ea26684d4cd609a5b456d3d2cc762453c2d75 A-63146698] / CVE-2017-0785. See also [https://info.armis.com/rs/645-PDC-047/images/BlueBorne%20Technical%20White%20Paper_20171130.pdf here].&lt;br /&gt;
| Bluetooth-sysmodule stack infoleak, which allows defeating ASLR (note: not tested on hw).&lt;br /&gt;
| [[5.0.0]]&lt;br /&gt;
| [[11.0.0]]&lt;br /&gt;
| Switch: December 2020&lt;br /&gt;
| Switch: December 25, 2020&lt;br /&gt;
| Switch: [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Bluetooth_Driver_services|bluetooth]] GetAdapterProperty/SetAdapterProperty unchecked memcpy size&lt;br /&gt;
| GetAdapterProperty copies data from stack to the output buffer using the buffer size, without checking the size (when not handling the Name type). SetAdapterProperty copies data to stack from the input buffer using the buffer size, without checking the size.&lt;br /&gt;
This requires access to the btdrv service, only hid and btm have access.&lt;br /&gt;
&lt;br /&gt;
This was fixed with [[12.0.0]] by replacing the buffer data with a fixed-size-struct.&lt;br /&gt;
| Stack infoleak with GetAdapterProperty, stack buffer overflow (and hence ROP) with SetAdapterProperty.&lt;br /&gt;
| [[12.0.0]]&lt;br /&gt;
| [[12.0.0]]&lt;br /&gt;
| July 17, 2020&lt;br /&gt;
| April 7, 2021&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Bluetooth_Driver_services|bluetooth]] stack buffer overflow with HID DATA packets&lt;br /&gt;
| The BSA (bt-stack) func bta_hh_co_data copies data from a HID DATA packet to stack without checking the size, then sends it over Uipc. [7.0.0+] The user Uipc callback also copies the input data to stack without checking the size, then sends it to the sharedmem CircularBuffer.&lt;br /&gt;
With [12.0.2+] this was fixed in bta_hh_co_data by clamping the size to a maximum of 0x2BB. The aforementioned buffer overflow in the Uipc callback can&#039;t be triggered since at that point the size was already clamped.&lt;br /&gt;
&lt;br /&gt;
Before this bta_hh_co_data func is reached, there is no validation of the size (such as comparing against the L2CAP MTU) when Basic Mode is being used.&lt;br /&gt;
&lt;br /&gt;
Actually triggering this requires using a data-size larger than the normal L2CAP MTU. This can be done by for example, using raw HCI to send the packet from the remote bluetooth device.&lt;br /&gt;
&lt;br /&gt;
Note that when the remote device is configured as an audio device for [12.0.0+] where [[Settings_services#BluetoothDevicesSettings|BluetoothDevicesSettings]].TrustedServices was only ever set for audio since system-boot, it is not possible for the remote device to connect to the Switch for HID.&lt;br /&gt;
| ROP under [[Bluetooth_Driver_services|bluetooth]] via HID DATA packet sent by a paired HID bluetooth device. This can be triggered at any time while not in sleep-mode, when not in airplane-mode. The earliest is while the Nintendo Switch logo screen is displayed during system boot.&lt;br /&gt;
| [[12.0.2]]&lt;br /&gt;
| [[12.0.2]]&lt;br /&gt;
| July-August 2020&lt;br /&gt;
| May 11, 2021&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Bluetooth_Driver_services|bluetooth]] WriteHidData/WriteHidData2/SetHidReport unchecked memcpy size&lt;br /&gt;
| WriteHidData/SetHidReport copies the input struct to stack, then passes it to the funcptr/vfunc call. WriteHidData2 passes the input buffer addr directly to the funcptr/vfunc call. The called func eventually copies the input data to the stack struct using the specified size without validating it.&lt;br /&gt;
This requires access to the btdrv service, only hid and btm have access.&lt;br /&gt;
&lt;br /&gt;
This was fixed with [[12.1.0]] in WriteHidData/SetHidReport by doing a fixed-size copy into another tmp struct, with the size field being clamped to a maximum of 0x2BB afterwards. This struct is then used when calling the vfunc. The vfuncs called by WriteHidData/WriteHidData2/SetHidReport were also updated to clamp the size to the required maximum value.&lt;br /&gt;
| Stack buffer overflow&lt;br /&gt;
| [[12.1.0]]&lt;br /&gt;
| [[12.1.0]]&lt;br /&gt;
| July 16, 2020&lt;br /&gt;
| July 6, 2021&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| Infoleak with [[HID_services|hid:sys]] SetButtonConfigStorage{name}Deprecated&lt;br /&gt;
| These cmds pass a stack ptr for the StorageName when calling the internal func. Nothing is written to this StorageName. Hence, stack infoleak (data is copied as a NUL-terminated string), which can be later read by the GetButtonConfigStorage{name} cmds.&lt;br /&gt;
&lt;br /&gt;
This was fixed by removing the Deprecated cmds in [[13.0.0]].&lt;br /&gt;
| Infoleak of hid stack from a StorageName readable via GetButtonConfigStorage{name}, up to the NUL-terminator.&lt;br /&gt;
| [[13.0.0]]&lt;br /&gt;
| [[13.0.0]]&lt;br /&gt;
| December 11, 2020&lt;br /&gt;
| September 27, 2021&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Bluetooth_Driver_services|bluetooth]] EventInfo infoleak&lt;br /&gt;
| The various funcs which send messages to the thread which handles writing to EventInfo, didn&#039;t clear the stack msgbuf. Hence, the various get-EventInfo cmds could return leaked stack data. This likely affected most (?) get-EventInfo cmds, besides CircularBuffer-GetHidReportEventInfo.&lt;br /&gt;
&lt;br /&gt;
This only matters for events where there&#039;s uninitialized regions of the EventInfo, such as events with variable-size data without a memset.&lt;br /&gt;
&lt;br /&gt;
This was fixed by clearing the msgbuf in a number of funcs.&lt;br /&gt;
| Bluetooth-sysmodule stack infoleak, which allows defeating ASLR&lt;br /&gt;
| [[13.0.0]]&lt;br /&gt;
| [[13.1.0]]&lt;br /&gt;
| &lt;br /&gt;
| During initial [[13.0.0|diff]]. Added to this page on: December 12, 2021&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[SSL_services|ssl]] CVE-2021-43527&lt;br /&gt;
| CVE-2021-43527, see also [https://bugs.chromium.org/p/project-zero/issues/detail?id=2237 here] and [https://googleprojectzero.blogspot.com/2021/12/this-shouldnt-have-happened.html here].&lt;br /&gt;
Using BigSig where the server cert sig is RSA-PSS results in the remote server throwing {no shared cipher} error when Switch connects. If however one creates a rootCA using BigSig (RSA-PSS), which then signs a server cert where the server key is RSA (not PSS), the vuln can be triggered (if the rootCA is trusted, via using the import service-cmd). It&#039;s unknown whether there&#039;s other ways to trigger the vuln.&lt;br /&gt;
&lt;br /&gt;
The crash occurs in VFY_Begin when using the previously overwritten data. A bitsize of &amp;lt;code&amp;gt;$((16384 + 32 + 64 + 64 + 64))&amp;lt;/code&amp;gt; is only enough to overwrite cx-&amp;gt;hashcx, to fully overwrite cx-&amp;gt;hashobj an additional 0xC-bytes (additional 96 bits) is needed.&lt;br /&gt;
Note that partial overwrite isn&#039;t an option: this is the func that initializes those fields to begin with, it just does deinit first before initializing hashcx/hashobj (prior to that these fields would be all-zero when not overwritten by the buf-overflow).&lt;br /&gt;
| Heap buffer overflow in [[SSL_services|ssl]], overwriting data including a ptr to an object which is later used to load a funcptr.&lt;br /&gt;
| [[13.2.1]]&lt;br /&gt;
| [[13.2.1]]&lt;br /&gt;
| Switch: December 1-2, 2021&lt;br /&gt;
| Switch: January 19, 2022&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| [[Bluetooth_Driver_services|bluetooth]] BSA gatt_process_notification stack buffer overflow&lt;br /&gt;
| gatt_process_notification is the GATT handler for processing notification/indication messages. gatt_process_notification does memcpy to stack from the input bt msg data, without size validation. The input len param isn&#039;t validated in this func either - if the remaining len following op_code is less than 2, a negative value will be used for the data copy to stack.&lt;br /&gt;
These were fixed by adding a bounds check for the size, size==0 is also checked for now.&lt;br /&gt;
| Bluetooth-sysmodule stack buffer overflow, with data received from a bluetooth message&lt;br /&gt;
| [[13.2.1]]&lt;br /&gt;
| [[13.2.1]]&lt;br /&gt;
| November 2021&lt;br /&gt;
| January 19, 2022&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Applet_Manager_services#IDisplayController|AM IDisplayController]] TakeScreenShotOfOwnLayer OOB&lt;br /&gt;
| The captureBuf is used as an array index without validation. Data used from this array includes calling a funcptr from the array entry, if set. Eventually this is also used to write bools into this array, one of which is from the command input.&lt;br /&gt;
With [5.0.0+] a func is eventually called to get a ptr determined by the input captureBuf, with nullptr being returned for captureBuf&amp;gt;=0x10. The caller will Abort if nullptr was returned.&lt;br /&gt;
| OOB array access&lt;br /&gt;
| [[5.0.0]]&lt;br /&gt;
| [[13.1.0]]&lt;br /&gt;
| ~July 31, 2019&lt;br /&gt;
| January 26, 2022&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Applet_Manager_services#IDisplayController|AM IDisplayController]] ClearCaptureBuffer OOB&lt;br /&gt;
| The captureBuf is used as an array index without proper validation. There is code validating it, but on failure it just skips over a code-block, with code using captureBuf still being used afterwards. Then this is used to write bools into a global array, one of which is from the command input.&lt;br /&gt;
This was fixed with [9.1.0+] by requiring captureBuf = 0-1.&lt;br /&gt;
| OOB bool writes into an array&lt;br /&gt;
| [[9.1.0]]&lt;br /&gt;
| [[13.1.0]]&lt;br /&gt;
| ~July 31, 2019&lt;br /&gt;
| January 26, 2022&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Sockets_services|bsdsockets]] ioctl SIOCGIFCONF infoleak&lt;br /&gt;
| Originally bsd ioctl SIOCGIFCONF was handled by setting the data in IPC outbuf0 to the size/addr of IPC outbuf1. These buffers are HipcAutoSelect, so if buf1 is small enough for HipcPointer (otherwise it would be HipcMapAlias) the IPC-buf-ptr leaked into outbuf0 would be located in the codebin-region. Since this is done before the actual ioctl-handling, it doesn&#039;t matter whether the fd is valid.&lt;br /&gt;
This was fixed in [5.0.0+] by using a tmp struct on stack instead of buf0.&lt;br /&gt;
| bsdsockets-sysmodule codebin-region addr infoleak, which allows defeating ASLR.&lt;br /&gt;
| [[5.0.0]]&lt;br /&gt;
| [[13.1.0]]&lt;br /&gt;
| February 14, 2022 (probably earlier)&lt;br /&gt;
| February 14, 2022&lt;br /&gt;
| [[User:Yellows8|yellows8]], probably others&lt;br /&gt;
|-&lt;br /&gt;
| [[Sockets_services|bsdsockets]] ioctl SIOCGIFMEDIA input can contain ptr&lt;br /&gt;
| Originally bsd ioctl SIOCGIFMEDIA used the user-specified ifmediareq structure directly from the input buffer. This includes a ptr. This ptr probably isn&#039;t actually used?&lt;br /&gt;
With [5.0.0+] the structure used as input for the ioctl was changed to using &amp;lt;code&amp;gt;int ifm_ulist[1]&amp;lt;/code&amp;gt; instead of &amp;lt;code&amp;gt;int *ifm_ulist&amp;lt;/code&amp;gt; (which is unused). The input structure is copied to a tmp struct which is used as the original ifmediareq structure, with ifm_ulist always NULL. The user can still specify a non-zero ifm_count value, however that&#039;s not useful with ifm_ulist being always NULL.&lt;br /&gt;
| Useless?&lt;br /&gt;
| [[5.0.0]]&lt;br /&gt;
| [[13.1.0]]&lt;br /&gt;
| February 14, 2022&lt;br /&gt;
| February 14, 2022&lt;br /&gt;
| [[User:Yellows8|yellows8]], probably others&lt;br /&gt;
|-&lt;br /&gt;
| Infoleak with [[Joy-Con]] HidCommand PairingIn&lt;br /&gt;
| The joycon protocol handler for PairingIn copies data from stack to the response cmd-buf for sending PairingOut. Only the first byte is set to a type value, the rest is uninitialized stack data.&lt;br /&gt;
&lt;br /&gt;
This was fixed with [15.0.0+] by directly writing to the response data without using stack data.&lt;br /&gt;
| Infoleak of hid stack via a bluetooth/uart message+response with a connected hid controller. This returns addrs for the main-codebin/stack, which allows defeating ASLR.&lt;br /&gt;
| [[15.0.0]]&lt;br /&gt;
| [[15.0.0]]&lt;br /&gt;
| September 4, 2020&lt;br /&gt;
| October 10, 2022&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| Broken RNG for [[RO_services|ro]] ASLR&lt;br /&gt;
| The RNG used to determine where to randomly map NROs in the target process was TinyMT (nn::os::detail::RngManager output, seeded by 128 bits of entropy). However, TinyMT is not cryptographically secure (and can in fact be analytically solved). &lt;br /&gt;
&lt;br /&gt;
Thus, with a few NRO mapping addresses, one could learn the TinyMT state and derive all previous/future RNG outputs, breaking NRO aslr for all processes. &lt;br /&gt;
&lt;br /&gt;
With [15.0.0+] ro now uses csrng_GenerateRandomBytes to determine the random map address for NROs.&lt;br /&gt;
| Breaking ASLR for all NROs loaded in all processes, allowing predicting all NRO mappings for all processes until the next reboot.&lt;br /&gt;
| [[15.0.0]]&lt;br /&gt;
| [[15.0.0]]&lt;br /&gt;
| Late 2021/Early 2022&lt;br /&gt;
| October 11, 2022&lt;br /&gt;
| Everyone&lt;br /&gt;
|-&lt;br /&gt;
| Broken RNG used by [[NS_Services|ns]]&lt;br /&gt;
| The code generating the sd seed and the data for the [[SD_Filesystem|sd]] private/private1 file, all use nn::os::GenerateRandomBytes, not csrng. The sd-seed is generated first, then private, then private1. This allows deriving sd-seed from private since this uses TinyMT, as long as the system shipped from factory on [2.0.0+]. private1 is only useful if the system shipped with [4.0.0+].&lt;br /&gt;
&lt;br /&gt;
There&#039;s various other code in ns using nn::os::GenerateRandomBytes as well. This includes the code generating ns_systemseed when it doesn&#039;t exist. ns_systemseed is generated at some point after the various sd-seed-related code (both are called from the same func). Hence, ns_systemseed can be recovered with the above method as well, if it wasn&#039;t recreated at some point without regenerating the above nand-save used with the above.&lt;br /&gt;
&lt;br /&gt;
With [15.0.0+] ns now uses csrng_GenerateRandomBytes for sd-seed/private and ns_systemseed, etc. This only matters when the file is newly generated, which is usually only for factory-fresh systems which ship with this version. This would also apply after being deleted during {System Settings -&amp;gt; Formatting Options -&amp;gt; Initialize Console}, and also with a refurbished console.&lt;br /&gt;
| Generation of a system&#039;s sd-seed allowing decryption of the NAX0 layer of data on [[SD_Filesystem|SD]], derived using the private file from SD. Applies to systems which factory-shipped with a system-version prior to [[15.0.0]] (that is, [2.0.0-14.1.2]).&lt;br /&gt;
| [[15.0.0]], for newly generated files&lt;br /&gt;
| [[15.0.0]]&lt;br /&gt;
| December ~12, 2021&lt;br /&gt;
| October 11, 2022&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Bluetooth_Driver_services|bluetooth]] BSA bsa_sv_av_cback stack buffer overflow&lt;br /&gt;
| bsa_sv_av_cback checks for two input type values (0xC/0xD), on match it copies the input data to stack without size validation. Then it sends an internal request with this data (likewise when the type values don&#039;t match, except the input data is passed directly with a small size), then it returns.&lt;br /&gt;
This requires the AV functionality added with [13.0.0+], however this func is only reachable with [14.0.0+] where the required functionality was enabled.&lt;br /&gt;
&lt;br /&gt;
This requires message data that&#039;s larger than the MTU, so fragmentation must be used, or manually send the ACL data to bypass the MTU.&lt;br /&gt;
&lt;br /&gt;
This can be triggered via an AVRC message with opcode=0x0 (vendor). The above type 0xC is reached via AVRC ctype 0..4, while 0xD is reached with ctype&amp;gt;=0x9.&lt;br /&gt;
&lt;br /&gt;
With [15.0.0+] the size value for the memcpy (which is also written to the request struct) is clamped to a max value.&lt;br /&gt;
| Bluetooth-sysmodule stack buffer overflow on [14.0.0-14.1.2], with data received from an AVRC bluetooth message with a bluetooth-audio device.&lt;br /&gt;
| [[15.0.0]]&lt;br /&gt;
| [[15.0.0]]&lt;br /&gt;
| November 2021&lt;br /&gt;
| October 11, 2022&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[WLAN_services|wlan]] SetMulticastList heap buffer overflow&lt;br /&gt;
| The [[WLAN_services#SetMulticastList|SetMulticastList]] command allocates a 0x31-bytes sized buffer and copies to it as much [[WLAN_services#MacAddress|MacAddress]] values from the input [[WLAN_services#MulticastList|MulticastList]] as specified by the &amp;quot;Count&amp;quot; field, but this field is never validated. &lt;br /&gt;
&lt;br /&gt;
With [15.0.0+] error code 0x1906B is now returned if &amp;quot;Count&amp;quot; is larger than 8.&lt;br /&gt;
| wlan-sysmodule heap buffer overflow.&lt;br /&gt;
| [[15.0.0]]&lt;br /&gt;
| [[15.0.0]]&lt;br /&gt;
| June 6, 2022&lt;br /&gt;
| November 9, 2022&lt;br /&gt;
| [[User:Hexkyz|hexkyz]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Bluetooth_Driver_services|bluetooth]] WriteGattCharacteristic/WriteGattDescriptor stack buffer overflow regression&lt;br /&gt;
| Originally btdrv WriteGattCharacteristic/WriteGattDescriptor (bt service LeClientWriteCharacteristic/LeClientWriteDescriptor are the same) validated the input buffer size. However the size check was removed with [12.0.0+] (which was also when bluetooth was refactored), hence stack buffer overflow. Anything with btdrv/bt services access can trigger it. While this is intended to require a BLE connection, it seems to be possible to trigger the buffer overflow without any BLE connection by passing ConnectionHandle=0xFFFFFFFF (handle not tested on hardware).&lt;br /&gt;
| Bluetooth-sysmodule stack buffer overflow on [12.0.0-15.0.1], with data from BLE IPC cmds.&lt;br /&gt;
| [[16.0.0]]&lt;br /&gt;
| [[16.0.0]]&lt;br /&gt;
| December 10, 2021&lt;br /&gt;
| February 23, 2023&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[JIT_services|JIT]] usability issues&lt;br /&gt;
| CreateJitEnvironment will enter infinite-loops using nn::jitsrv::detail::AslrAllocator::GetAslrRegion when either of the input CodeMemory sizes are zero. Also the second CodeMemory is useless for the user-process since the second addr returned by GetCodeAddress is a dup of the first one, set during state init by CreateJitEnvironment.&lt;br /&gt;
With [14.0.0+] size=0 is now properly handled, and also the state for the second addr from GetCodeAddress is now properly initialized.&lt;br /&gt;
| Minor usability issues, not useful for exploitation (size=0 will cause jit-sysmodule to hang in a loop).&lt;br /&gt;
| [[14.0.0]]&lt;br /&gt;
| [[14.0.0]]&lt;br /&gt;
| October 1, 2020&lt;br /&gt;
| February 26, 2023&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[USB_services|usbhs]] uninitialized IClientEpSession&lt;br /&gt;
| usbhs IClientIfSession OpenUsbEp creates an IClientEpSession object. The allocated object from ExpHeap is not memset, only select fields are cleared. The rest of initialization is done by PopulateRing - however the user-process could skip using that if wanted (official sw always uses it).&lt;br /&gt;
&lt;br /&gt;
ShareReportRing maps tmem and writes the ring buffer/count field into object state. PopulateRing also eventually initializes these fields, with the buffer being allocated from ExpHeap instead of tmem. These fields are not cleared during object creation from OpenUsbEp.&lt;br /&gt;
&lt;br /&gt;
GetXferReport after validating the cmd input, just uses object state assuming it was initialized. This runs code which is the same as the user-process code handling the tmem ringbuf.&lt;br /&gt;
&lt;br /&gt;
Therefore, by skipping using PopulateRing and then using GetXferReport the sysmodule will use an uninitialized ringbuf ptr, and an uninitialized count field. If one could control these fields by doing ExpHeap allocations prior to OpenUsbEp so that {target fields} would be located at {IClientEpSession ring fields}, then one could read usb-sysmodule memory at the target buffer address.&lt;br /&gt;
&lt;br /&gt;
See [[USB_services#ShareReportRing|here]] for ringbuf format. The sysmodule will Abort if read_index is &amp;gt;= {ring count field from object state}. Otherwise it copies an entry from that index to output, and updates read_index.&lt;br /&gt;
&lt;br /&gt;
This is probably tricky to abuse as the ringbuf ptr has to be valid, and {see above} (likewise for write_index when the report-ringbuf-writing func runs).&lt;br /&gt;
&lt;br /&gt;
PostBufferAsync/BatchBufferAsync also use seperate object ring fields which are left uninitialized from OpenUsbEp. Targeting this would be tricky with the ring restrictions - this would allow writing data to a ring addr however.&lt;br /&gt;
&lt;br /&gt;
Pre-4.0.0 (only 2.0.0 checked) is not affected by these. The ring fields in the object are cleared during object creation (no memset of the entire object however). GetXferReport would null-deref if PopulateRing was skipped. PostBufferAsync/BatchBufferAsync will throw an error if PopulateRing was skipped. Pre-4.0.0 also has different ring handling as well.&lt;br /&gt;
&lt;br /&gt;
[16.0.0+] The IClientEpSession init func now clears the remaining previously uninitialized fields. The cmds using the ring fields still don&#039;t check for NULL, so using GetXferReport/PostBufferAsync/BatchBufferAsync without PopulateRing will just trigger null-deref. Even if the ptr were somehow valid but ring-count field was left at 0, this would then Abort due to: &amp;lt;code&amp;gt;if (ring_count &amp;lt;= index_loaded_from_ringptr) &amp;lt;Abort&amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
| [4.0.0-15.0.1] If one can trigger using {target values} as the unintialized fields: memory reads from the target addr with GetXferReport, and memory R/W with PostBufferAsync/BatchBufferAsync. This requires access to usb:hs, and an usb device must be connected which is not being used by {other sessions}. If successful, this might (?) result in usb-sysmodule compromise.&lt;br /&gt;
| [[16.0.0]]&lt;br /&gt;
| [[16.0.0]]&lt;br /&gt;
| January 30, 2023&lt;br /&gt;
| February 26, 2023&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[NS_services|ns]] RequestMoveApplicationEntity/EstimateSizeToMove buffer overflow&lt;br /&gt;
| ns RequestMoveApplicationEntity eventually calls a func which: Loops through the input buffer. If any entry has value 6, it will call another func to copy data from state to output safely (uses the max_count param). Otherwise, it copies the input buffer to an outbuf (located on caller&#039;s stack) without any size validation (inlined memcpy), even though there is a max_count param.&lt;br /&gt;
&lt;br /&gt;
Additional memwrites are also done to the above outbuf following the initial memcopy. This can be avoided if the buffer doesn&#039;t contain bytes with values 3-6 (if using values in that range is really needed, the cmd input StorageId param can be set to the required value so that the specified value doesn&#039;t trigger the memwrite). Value 6 shouldn&#039;t be used anyway (see above).&lt;br /&gt;
&lt;br /&gt;
ns EstimateSizeToMove first calls the same func which does the copy above (outbuf is also located on stack), then it calls another func. Hence, same vuln here.&lt;br /&gt;
&lt;br /&gt;
By corrupting just the first byte of x29 with EstimateSizeToMove, one can obtain infoleaks. This method with x29 essentially only works with [15.0.0+]. Pre-15.0.0 would require a different method with partial overwrite of retaddr, however it&#039;s unknown whether this would actually work for infoleak (would require [12.0.0+] for the stack layout change).&lt;br /&gt;
With EstimateSizeToMove where x29 is overwritten, the output u64 is the leaked ptr (can be codebin-region). Note that the cmd has to return Result=0 for this to work. x29 is used to load the value which is copied to the cmdreply rawdata.&lt;br /&gt;
&lt;br /&gt;
As of [17.0.0+] an error is thrown if the input array count is larger than 8 (size of the stack dst-array).&lt;br /&gt;
| ns-sysmodule stack buffer overflow, allowing ns infoleak+ROP.&lt;br /&gt;
| [[17.0.0]]&lt;br /&gt;
| [[17.0.0]]&lt;br /&gt;
| January 2, 2023&lt;br /&gt;
| October 17, 2023&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[PSC_services|ovln:snd]] OpenSender unvalidated count&lt;br /&gt;
| ovln:snd OpenSender has a count param. This count is used to allocate the specified number of objects in a linked-list for storing the data from Send. If count is 0, the linked-list is left empty, with ptrs to itself within the ISender object.&lt;br /&gt;
&lt;br /&gt;
ISender Send when the above linked-list is empty, runs a switch-statement with &amp;lt;code&amp;gt;(inval&amp;gt;&amp;gt;8)&amp;amp;0xFF&amp;lt;/code&amp;gt;. This uses another linked-list where the ptrs are initially {within ISender obj}.&lt;br /&gt;
No space is allocated in the ISender obj for the linked-list object-data. Therefore using Send with val 1&amp;lt;&amp;lt;8 or 2&amp;lt;&amp;lt;8 (other values throw error) results in the specified input struct being copied into the ISender obj, which then overwrites heap data OOB.&lt;br /&gt;
If for example one used OpenSender again right after the first OpenSender usage, then used Send as described above, this would corrupt the second ISender which includes overwriting the vtable.&lt;br /&gt;
If one would use Send twice in a row like this, the second one would use a corrupted linked-list (written from the first Send). If the linked-list ptrs would be valid (no crash triggered) this would allow one to copy the input data to a controlled addr, though it&#039;s restricted with the linked-list usage.&lt;br /&gt;
&lt;br /&gt;
Using GetUnreceivedMessageCount afterwards is of no interest.&lt;br /&gt;
&lt;br /&gt;
Besides ovln, the only other allocs on this heap is from IPmModule Initialize. This heap is also used for psc:* services (object allocs).&lt;br /&gt;
&lt;br /&gt;
In theory (untested) it may be possible to also use this to obtain infoleaks, however it would only return the high-u32 of ptrs not the low u32. Essentially, one would trigger object allocations so that ExpHeap has layout: {ISender} -&amp;gt; {RF chunk from freeing an object} -&amp;gt; {module object from IPmModule Initialize}. Then one would use the Send vuln to corrupt the RF chunk, changing the size to a larger value. Then one would trigger an object allocation (probably same object which was previously freed), then another object for overwriting the module object (ISender would work) with ptrs at the target offsets in the module object. Then once IPmModule GetRequest is used, the returned u32s would be the high-u32 from ptrs. Due to alignment requirements with each allocation, it isn&#039;t possible to shift the allocations in order to leak ptr low-u32.&lt;br /&gt;
&lt;br /&gt;
[17.0.0+] Now throws an error if the input count for OpenSender is 0.&lt;br /&gt;
| [[PSC_services|psc]]-sysmodule heap memory corruption ([[NS_services|ns]]-sysmodule on pre-8.0.0).&lt;br /&gt;
| [[17.0.0]]&lt;br /&gt;
| [[17.0.0]]&lt;br /&gt;
| January 13, 2023&lt;br /&gt;
| October 20, 2023&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[NV_services|nv]] NVGPU_GPU_IOCTL_GET_CHARACTERISTICS Ioctl3 infoleak&lt;br /&gt;
| The handler code for NVGPU_GPU_IOCTL_GET_CHARACTERISTICS for Ioctl/Ioctl3 are essentially the same, except for the value used for the max-size clamp: Ioctl uses constant 0xA0, while Ioctl3 uses the outbuf1_size. So if one uses this with Ioctl3 and a large outbuf1, this will memcpy data OOB from the source buffer, hence infoleak.&lt;br /&gt;
With [17.0.0+] the second block of csel code which previouly essentially used the clamped size from above, was replaced with code which properly clamps to the max-size constant.&lt;br /&gt;
| nvservices-sysmodule infoleak, which allows defeating ASLR.&lt;br /&gt;
| [[17.0.0]]&lt;br /&gt;
| [[17.0.0]]&lt;br /&gt;
| February 25, 2022&lt;br /&gt;
| October 24, 2023&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Audio_services|audctl]] GetTargetDeviceInfo infoleak&lt;br /&gt;
| audctl GetTargetDeviceInfo calls an impl func with a ptr to a stackbuf, then if successful memcpys the 0x100-bytes from that buffer to output. This stackbuf is not memset. This func (after doing various state checks) copies a string to output, other than always writing a NUL-terminator there&#039;s no clearing of the buffer.&lt;br /&gt;
&lt;br /&gt;
This will leak audio-sysmodule stack into the output buffer as long as the state/input checks pass (for the remainder of the buffer following the string NUL-terminator).&lt;br /&gt;
&lt;br /&gt;
With [18.0.0+] data is written directly to the outbuf instead of the stack tmpbuf.&lt;br /&gt;
| audio-sysmodule infoleak, which allows defeating ASLR.&lt;br /&gt;
| [[18.0.0]]&lt;br /&gt;
| [[18.0.0]]&lt;br /&gt;
| December 24, 2022&lt;br /&gt;
| March 26, 2024&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Audio_services|audctl]] GetSystemInformationForDebug infoleak / buffer overflow&lt;br /&gt;
| audctl GetSystemInformationForDebug calls a func with a 0x1000-byte stack tmpbuf, then afterwards that buffer is memcpy&#039;d into the cmd outbuf. This called func doesn&#039;t clear the buffer. This func eventually uses [[BTM_services|btm]] cmd75 with outarray={global ptr} and count=10. Then if the outcount is s32 &amp;gt;=1, it loops through the output using the outcount, without validating it besides the &amp;lt;1 check. Data from that outarray is copied into the array in the func output buffer (tmpbuf above).&lt;br /&gt;
&lt;br /&gt;
With btm comprimised, one could return a large output count and trigger a stack buffer overflow with data following that global array, however exploiting this would be difficult since that data would be uncontrolled (can&#039;t directly control it from this cmd at least).&lt;br /&gt;
&lt;br /&gt;
A stack infoleak can be obtained with this as well (assuming the above output array isn&#039;t full).&lt;br /&gt;
&lt;br /&gt;
Even though the name has &amp;quot;ForDebug&amp;quot;, there&#039;s no checks which would trigger an error / return early (this also always returns 0).&lt;br /&gt;
&lt;br /&gt;
[18.0.0+] now clears the output buffer, and also now prints strings into the buffer instead of writing binary data (overflow no longer possible).&lt;br /&gt;
| audio-sysmodule infoleak, which allows defeating ASLR. Also audio-sysmodule memory corruption, likely not useful unless there&#039;s a way to control the data.&lt;br /&gt;
| [[18.0.0]]&lt;br /&gt;
| [[18.0.0]]&lt;br /&gt;
| December 7, 2022&lt;br /&gt;
| March 27, 2024&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Migration_services|migration]] nn::migration::savedata::IServer cmd1 buffer overflow&lt;br /&gt;
| nn::migration::savedata::IServer cmd1 with [18.0.0-18.0.1] copies data from an array to the output ptr. As the output is an u64 field for the IPC cmd output, this is a field on stack. Hence, if more than 1 entry (8-bytes) are copied a stack buffer overflow will occur. Note that cmd3 loads the same data, except this has a proper output array.&lt;br /&gt;
It&#039;s unknown whether there&#039;s a way to actually control this data with a large enough enough size.&lt;br /&gt;
&lt;br /&gt;
See [[18.1.0]] for the diff/fix.&lt;br /&gt;
| [[Migration_services|migration]] stack buffer overflow, only on [18.0.0-18.0.1].&lt;br /&gt;
| [[18.1.0]]&lt;br /&gt;
| [[18.1.0]]&lt;br /&gt;
| June 11, 2024&lt;br /&gt;
| June 11, 2024&lt;br /&gt;
| [[User:Yellows8|yellows8]] (sysupdate diff)&lt;br /&gt;
|-&lt;br /&gt;
| [[SSL_services|ssl]] broken RNG&lt;br /&gt;
| [[SSL_services|ssl]] uses nn::os::GenerateRandomBytes, but not [[SPL_services|spl]] GenerateRandomBytes. See the RNG entries elsewhere. This is used to seed the NSS global RNG (drbg.c, RNG_GenerateGlobalRandomBytes etc).&lt;br /&gt;
&lt;br /&gt;
If one could somehow determine the data which was returned by nn::os::GenerateRandomBytes during seeding (which is likely difficult), the global RNG would be broken.&lt;br /&gt;
&lt;br /&gt;
With [19.0.0+] nn::os::GenerateRandomBytes usage was replaced with [[SPL_services|spl]] GenerateRandomBytes.&lt;br /&gt;
| Breaking [[SSL_services|ssl]] global RNG -&amp;gt; potentially predict RNG data (keys(?)) during TLS comms.&lt;br /&gt;
| [[19.0.0]]&lt;br /&gt;
| [[19.0.0]]&lt;br /&gt;
| December 14, 2021&lt;br /&gt;
| October 8, 2024&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Audio_services|audren]] uncleared TransferMemory&lt;br /&gt;
| audren OpenAudioRenderer uses the input tmem as workmem. The IAudioRenderer dtor doesn&#039;t clear the workmem properly. Depending on input params, certain objects stored here have vtables - hence infoleak.&lt;br /&gt;
The exact location in the workmem will vary depending on the input params - these objects are dynamically allocated in the workmem.&lt;br /&gt;
The following will leak vtables: Sink, Effect.&lt;br /&gt;
&lt;br /&gt;
If the initialization func fails, the tmem is unmapped without clearing it first. It&#039;s unknown whether there&#039;s a way to actually trigger an infoleak with this however. With [19.0.0+] it&#039;s now cleared on failure.&lt;br /&gt;
&lt;br /&gt;
With [19.0.0+] the dtor now clears the workmem when needed.&lt;br /&gt;
| Reading leaked data/ptrs from TransferMemory -&amp;gt; defeating ASLR in [[Audio_services|audio]]-sysmodule.&lt;br /&gt;
| [[19.0.0]]&lt;br /&gt;
| [[19.0.0]]&lt;br /&gt;
| December 17, 2022&lt;br /&gt;
| October 13, 2024&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Audio_services|audren]] UpdateMixes OOB mem-copy&lt;br /&gt;
| With nn::audio::server::InfoUpdater::UpdateMixes when nn::audio::server::BehaviorInfo::IsMixInParameterDirtyOnlyUpdateSupported() returns true (requires REV7, which is [7.0.0+]), the mix_id from user input is used without validation as input to &amp;lt;code&amp;gt;&amp;lt;nn::audio::server::MixContext::GetInfo(int) const&amp;gt;&amp;lt;/code&amp;gt;, instead of the counter from the for-loop. This allows one to control the destination MixInfo index which the user-input data is written into. If too large, this will trigger OOB data-copy. Note that the u8 at dest_MixInfo+12 must be non-zero.&lt;br /&gt;
Also note that a field is loaded from dest_MixInfo which is used as a splitter_id, so splitters need to be initialized where count is large enough for that id.&lt;br /&gt;
&lt;br /&gt;
With [19.0.0+] after getting the mix_id (loop-index/input) it now does: &amp;lt;code&amp;gt;if (mix_id &amp;lt; 0 || mix_id &amp;gt;= nn::audio::server::MixContext::GetCount()) continue;&amp;lt;/code&amp;gt;&lt;br /&gt;
| OOB mem-copy in [[Audio_services|audio]]-sysmodule, which for example can be used to overwrite a vtable used immediately after UpdateMixes.&lt;br /&gt;
| [[19.0.0]]&lt;br /&gt;
| [[19.0.0]]&lt;br /&gt;
| December 19, 2022&lt;br /&gt;
| October 13, 2024&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Bus_services|sasbus]] StartPeriodicReceiveMode infoleak&lt;br /&gt;
| StartPeriodicReceiveMode writes a vtable ptr into the mapped tmem at +0. The tmem is mapped RW in the user-process. There is no clearing of tmem during tmem cleanup. Hence, the user-process can read the tmem to obtain a Bus-sysmodule codebin-region infoleak. This vtable-ptr seems to be unused - it&#039;s also empty after the first two entries (stubbed incref/decref).&lt;br /&gt;
[20.0.0+] Removed the vtable ptr, with data intended for the user-process being moved from tmem+0x8 to +0x0. Also, instead of calling memset, funcs are called for manually clearing tmem.&lt;br /&gt;
| Bus-sysmodule infoleak, which allows defeating ASLR.&lt;br /&gt;
| [[20.0.0]]&lt;br /&gt;
| [[20.0.0]]&lt;br /&gt;
| February 22, 2022&lt;br /&gt;
| May 3, 2025&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[NFC_services|nfc]] SendCommandByPassThrough buffer overflow&lt;br /&gt;
| SendCommandByPassThrough eventually copies the input buffer into a fixed-size heap buffer, without size validation.&lt;br /&gt;
This was fixed with [20.0.0+] by clamping the size.&lt;br /&gt;
| nfc-sysmodule heap buffer overflow.&lt;br /&gt;
| [[20.0.0]]&lt;br /&gt;
| [[20.0.0]]&lt;br /&gt;
| Late November 2021&lt;br /&gt;
| May 3, 2025&lt;br /&gt;
| [[User:Yellows8|yellows8]] (maybe others?)&lt;br /&gt;
|-&lt;br /&gt;
| [[HID_services|hidbus]] EnableJoyPollingReceiveMode infoleak&lt;br /&gt;
| The tmem initialized by hidbus EnableJoyPollingReceiveMode contains a vtable ptr (tmem+0x10), hence infoleak. With [20.0.0+] the vtable ptr write was removed, and tmem is now memset starting at tmem+0x10 instead of +0x20.&lt;br /&gt;
| hid-sysmodule infoleak, which allows defeating ASLR.&lt;br /&gt;
| [[20.0.0]]&lt;br /&gt;
| [[20.0.0]]&lt;br /&gt;
| March 2020&lt;br /&gt;
| May 4, 2025&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[SSL_services|ssl]] Certificate verification bypass&lt;br /&gt;
| The ssl sysmodule keeps a list of trusted certificates, that are imported by an app with ImportServerPki. During certificate verification, if the certificate that is provided by the server has the same subject key id as a trusted certificate, the certificate is accepted, even if self-signed. A blog post about this vulnerability can be found [https://reversing.live/sslbypass.html here].&lt;br /&gt;
| Man-in-the-middle for any connection that uses ImportServerPki.&lt;br /&gt;
| [[20.2.0]]&lt;br /&gt;
| [[20.2.0]]&lt;br /&gt;
| June 6, 2025&lt;br /&gt;
| August 8, 2025&lt;br /&gt;
| [https://github.com/kinnay Yannik]&lt;br /&gt;
|-&lt;br /&gt;
| [[LDN_services|ldn]] AdvertiseData OOB-memcpy with EncryptionType3 (AES-128-GCM) actionframes (ldnhax)&lt;br /&gt;
| The ldn action-frame parser object for AES-128-GCM (used with [[LDN_services|EncryptionType3]]), when it does validation once finished, only verifies that the sizes are within bounds of the input buffer. There&#039;s no validation against constants, which the other EncryptionType objects have. The caller code doesn&#039;t validate the size either.&lt;br /&gt;
&lt;br /&gt;
[21.0.0+] Now validates the advert-size with sizeof(NetworkInfo.AdvertiseData).&lt;br /&gt;
&lt;br /&gt;
For more details see [https://gist.github.com/yellows8/16bb56343d085d2db2ab0adc5d4cef99 here].&lt;br /&gt;
| Compromise of ldn starting from OOB-memcpy, even on S2: stack infoleak (ASLR defeat), arbitrary memory read/write (which also allows handle-leak), vfunc-calls with arbitrary [[Security_Mitigations|vtable]].&lt;br /&gt;
| [[21.0.0]]&lt;br /&gt;
| [[21.0.0]]&lt;br /&gt;
| June ~13, 2025&lt;br /&gt;
| November 11, 2025&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[HID_services|hid:dbg]] AttachHdlsVirtualDevice unvalidated DeviceTypeInternal&lt;br /&gt;
| hid:dbg AttachHdlsVirtualDevice eventually passes the input from HdlsDeviceInfo into a func without any validation. The DeviceTypeInternal field is used as the index for loading a ptr from a global array. The only validation occurs when the loaded ptr is NULL - this is just for initializing the ptr in the array when it&#039;s not already set.&lt;br /&gt;
&lt;br /&gt;
Since the highest DeviceTypeInternal is value 30, using &amp;gt;=31 will load an OOB ptr. This ptr is written to state, and also immediately passed to a called func. As long as ptr is valid it should be fine with this func.&lt;br /&gt;
&lt;br /&gt;
This functionality is also used eventually by ApplyHdlsNpadAssignmentState and ApplyHdlsStateList.&lt;br /&gt;
&lt;br /&gt;
It&#039;s unknown whether there&#039;s a way to exploit this. Also note that hid:dbg is not normally accessible to retail titles.&lt;br /&gt;
&lt;br /&gt;
[21.0.0+] Arrayindex=0 is now used when the input is invalid.&lt;br /&gt;
| Likely useless, even if reachable?&lt;br /&gt;
| [[21.0.0]]&lt;br /&gt;
| [[21.0.0]]&lt;br /&gt;
| June 3, 2024 (possibly eariler(?))&lt;br /&gt;
| November 14, 2025&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Bluetooth_Driver_services|bluetooth]] BSA allowed ATT MTU is too large&lt;br /&gt;
| GATT-handler stack buffer overflows with a large input size are only possible if the payload_size (MTU) field in state is large enough. gatt_client_handle_server_rsp/gatt_server_handle_client_req will drop messages where the size is &amp;gt;= payload_size (though unless the request opcode matches certain values it will also send an error-response for invalid-PDU). Both of these handle updating this field when needed, however that&#039;s handled properly.&lt;br /&gt;
&lt;br /&gt;
With bluetooth-classic via L2CAP, a hard-coded MTU of 0x205 is sent in the configure request. However the code handling received configure requests will set payload_size to 0x2A0 if no MTU is specified, or the input MTU if it&#039;s within range 0x30..0x2A0. Hence, sending data large enough for buffer overflows requires bluetooth-classic via L2CAP + manually sending large ACL data.&lt;br /&gt;
&lt;br /&gt;
[15.0.0+] gatt_l2cif_config_ind_cback which handles the received configure-requests with bluetooth-classic mentioned above, now uses MTU range 0x30..0x205 with the default MTU being 0x205. It is therefore no longer possible to trigger the previously mentioned buffer-overflows with bluetooth-classic.&lt;br /&gt;
| Stack buffer overflows in bluetooth-sysmodule due to the allowed MTU for ATT being larger than the stack data.&lt;br /&gt;
| [[15.0.0]]&lt;br /&gt;
| [[20.0.0]]&lt;br /&gt;
| November 2021?&lt;br /&gt;
| November 26, 2025&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Bluetooth_Driver_services|bluetooth]] BSA gatt_process_prep_write_rsp stack buffer overflow&lt;br /&gt;
| BSA gatt_process_prep_write_rsp memcpys to stack without size validation (the input len param which is subtracted to determine the copy-size is also unvalidated). Triggering this is only possible if the system sent ATT_PREPARE_WRITE_REQ, and then received ATT_PREPARE_WRITE_RSP with a large size.&lt;br /&gt;
&lt;br /&gt;
The size used with memcpy is (u16)(insize-4), so when insize is less than 4 the copy size will be {negative value masked to u16}. This will therefore eventually crash when the stacktop is reached during memcpy.&lt;br /&gt;
&lt;br /&gt;
[15.0.0+] Paritially fixed due to corrected MTU handling (doesn&#039;t apply to negative-copysize). [21.0.0+] Fully fixed with proper size validation.&lt;br /&gt;
| Stack buffer overflow in bluetooth-sysmodule when the required ATT messages are sent/received.&lt;br /&gt;
| [[21.0.0]]&lt;br /&gt;
| [[21.0.0]]&lt;br /&gt;
| November 2021?&lt;br /&gt;
| January 19, 2026&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[NFC_services|nfc]] Initialize buffer overflow&lt;br /&gt;
| All Initialize* cmds for nn::nfc::detail::IUser (nfc:user), nn::nfc::detail::ISystem (nfc:sys), nn::nfp::detail::IUser (nfp:user), nn::nfp::detail::ISystem (nfp:sys), nn::nfp::detail::IDebug (nfp:dbg), nn::nfc::mifare::detail::IUser (nfc:mf:u): these copy the input array into _this, without validating the array count.&lt;br /&gt;
The data is copied to obj_impl+0x8+0x28, with each entry being 0x20-bytes. The event handle returned by AttachAvailabilityChangeEvent is at obj_impl+0x8+0xB8+0x14 (Same with nfc/nfp interfaces). This therefore means +0xA4 in the input buffer will overwrite the handle returned by that cmd, allowing one to leak any handle with the specified value. This can be done with count=0x6. The object is large enough that this count will only overwrite data within the current object. However during the dtor it will use ptrs which were corrupted with this (located before the event), so one must avoid closing the session unless the input data included valid ptrs.&lt;br /&gt;
&lt;br /&gt;
This can be exploited by just using a 0xC0-byte (array_count=0x6) input buffer with Initialize where each u32 is the target nfc handle value, then using cmd GetAvailabilityChangeEventHandle to leak the handle.&lt;br /&gt;
&lt;br /&gt;
[22.0.0+] This was fixed by clamping the count to a maximum of 0x4.&lt;br /&gt;
| OOB datacopy into object state. Allows leaking arbitary [[NFC_services|handles]], including on [S2] (such as process-handle, sm, fsp-srv (remaining services can also be used via sm)).&lt;br /&gt;
| [[22.0.0]]&lt;br /&gt;
| [[22.0.0]]&lt;br /&gt;
| November 2021&lt;br /&gt;
| March 17, 2026&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Internet Browser == &lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
!  Summary&lt;br /&gt;
!  Description&lt;br /&gt;
!  Successful exploitation result&lt;br /&gt;
!  Fixed in system version&lt;br /&gt;
!  Last system version this flaw was checked for&lt;br /&gt;
!  Timeframe this was discovered&lt;br /&gt;
!  Public disclosure timeframe&lt;br /&gt;
!  Discovered by&lt;br /&gt;
|-&lt;br /&gt;
| CVE-2016-4657&lt;br /&gt;
| WebKit vuln discovered around August 2016. Most notably used in the iOS 9.3.X exploit. A simple PoC can be found [https://github.com/LiveOverflow/lo_nintendoswitch/blob/master/poc1.html here]. This was later exploited by [https://twitter.com/qwertyoruiopz Qwertyoruiop] using an adjusted version of his iOS 9.3 webkit exploit (others exploited this prior to then).&lt;br /&gt;
|&lt;br /&gt;
| [[2.1.0]]&lt;br /&gt;
| [[2.0.0]]&lt;br /&gt;
| Original: August 2016&lt;br /&gt;
Switch: March 3rd-4th 2017&lt;br /&gt;
|&lt;br /&gt;
| Everyone&lt;br /&gt;
|-&lt;br /&gt;
| CVE-2017-7005&lt;br /&gt;
| WebKit type confusion.&lt;br /&gt;
|&lt;br /&gt;
| [[3.0.1]]&lt;br /&gt;
| [[3.0.1]]&lt;br /&gt;
|&lt;br /&gt;
| &lt;br /&gt;
| Everyone&lt;br /&gt;
|-&lt;br /&gt;
| CVE-2016-4622&lt;br /&gt;
| WebKit memory corruption bug. This bug was incorrectly re-introduced in [[4.0.0]]. See [http://www.phrack.org/papers/attacking_javascript_engines.html here] for a detailed write-up from the author.&lt;br /&gt;
|&lt;br /&gt;
| [[6.1.0]]&lt;br /&gt;
| [[6.1.0]]&lt;br /&gt;
|&lt;br /&gt;
| &lt;br /&gt;
| Everyone&lt;br /&gt;
|-&lt;br /&gt;
| CVE-2018-4441&lt;br /&gt;
| WebKit memory corruption bug. See [https://bugs.chromium.org/p/project-zero/issues/detail?id=1685&amp;amp;desc=2 here].&lt;br /&gt;
|&lt;br /&gt;
| [[7.0.0]]&lt;br /&gt;
| [[7.0.0]]&lt;br /&gt;
| &lt;br /&gt;
|&lt;br /&gt;
| Everyone&lt;br /&gt;
|-&lt;br /&gt;
| Web-applets OpenSSL broken RNG&lt;br /&gt;
| [[SPL_services|csrng]] access was added to web-applets with [12.1.0+]. Prior to that, csrng and nn::os::GenerateRandomBytes were not used (besides sdk heap code).&lt;br /&gt;
nn::os::GetSystemTick is used to seed the OpenSSL RNG, among other data. Hence, it&#039;s probably (?) possible to bruteforce the RNG initial state, allowing predicting RNG output.&lt;br /&gt;
&lt;br /&gt;
The RNG code is wkcRandomNumbersPeer (peer_wkc nro), with the initialization code using GetSystemTick located in the func immediately before wkcGetTickCountPeer. The former is called from wkcOsslRandFilefReadPeer. wkcOsslRandFilefReadPeer is called for seeding the OpenSSL RNG.&lt;br /&gt;
&lt;br /&gt;
With [12.1.0+], wkcRandomNumberPeer/wkcRandomNumbersPeer wrap nn::os::GenerateRandomBytes. wkcCryptographicallyRandomValuesPeer was added which wraps nn::crypto::GenerateCryptographicallyRandomBytes. wkcOsslRandFilefReadPeer now calls nn::crypto::GenerateCryptographicallyRandomBytes instead of wkcRandomNumbersPeer.&lt;br /&gt;
| Breaking web-applets OpenSSL RNG -&amp;gt; potentially predict RNG data (keys(?)) during TLS comms.&lt;br /&gt;
| [[12.1.0]]&lt;br /&gt;
| [[12.1.0]]&lt;br /&gt;
| January 28, 2022&lt;br /&gt;
| October 8, 2024&lt;br /&gt;
| [[User:Yellows8|yellows8]], likely (?) others&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Whitelist ===&lt;br /&gt;
This section documents [[Internet_Browser|WebApplet]] whitelist issues in applications. These can be used to load your own browser content over plain HTTP, which then for example could be used for web-applet exploitation.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
!  Application&lt;br /&gt;
!  Description&lt;br /&gt;
!  Fixed with app version&lt;br /&gt;
!  Newest app version this flaw was checked for&lt;br /&gt;
!  Timeframe this was discovered&lt;br /&gt;
!  Public disclosure timeframe&lt;br /&gt;
!  Discovered by&lt;br /&gt;
|-&lt;br /&gt;
| Sonic Mania&lt;br /&gt;
| Originally this game launched web-applet with a plain-http URL for displaying the manual, this was later changed to https. Originally the whitelist only had 1 entry for a http URL, this was later replaced with various https-only URLs.&lt;br /&gt;
| 1.04, unknown if fixed with an earlier update&lt;br /&gt;
| 1.04&lt;br /&gt;
| January (?) 2022&lt;br /&gt;
| February 23, 2022&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| ぷよぷよ™テトリス®Ｓ (JPN Puyo Puyo Tetris)&lt;br /&gt;
| The JPN Tetris game/demo can be used to launch the online-WebApplet.&lt;br /&gt;
&lt;br /&gt;
First, launch the offline-WebApplet for the manual:&lt;br /&gt;
* Game: Main-menu -&amp;gt; press A with the already selected top menu button -&amp;gt; press the R button.&lt;br /&gt;
* Demo: Main-menu -&amp;gt; select menu button on the right side -&amp;gt; press A.&lt;br /&gt;
&lt;br /&gt;
Then in the manual:&lt;br /&gt;
* Press A -&amp;gt; select the bottom menu entry in the list.&lt;br /&gt;
* Select the SEGA icon -&amp;gt; press A.&lt;br /&gt;
&lt;br /&gt;
This will then trigger launching the online-WebApplet with the plain-http &amp;lt;nowiki&amp;gt;&amp;quot;http://sega.jp/&amp;quot;&amp;lt;/nowiki&amp;gt; URL.&lt;br /&gt;
&lt;br /&gt;
With game-update v1.1.3 the whitelist no longer allows plain-http. The plain-http links appear to have been changed to https.&lt;br /&gt;
| 1.1.3&lt;br /&gt;
| 1.1.3&lt;br /&gt;
| 2017&lt;br /&gt;
| 2017&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== NintendoSDK ==&lt;br /&gt;
This section documents vulnerabilities for NSOs in NintendoSDK.&lt;br /&gt;
&lt;br /&gt;
=== nnSdk ===&lt;br /&gt;
This section documents vulnerabilities for nnSdk (sdknso).&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Summary&lt;br /&gt;
!  Description&lt;br /&gt;
!  Successful exploitation result&lt;br /&gt;
!  Fixed in SDK [[System_Versions|version]]&lt;br /&gt;
!  Last SDK version this flaw was checked for&lt;br /&gt;
!  Timeframe this was discovered&lt;br /&gt;
!  Public disclosure timeframe&lt;br /&gt;
!  Discovered by&lt;br /&gt;
|-&lt;br /&gt;
| [[HID_services|hidbus]] GetJoyPollingReceivedData buffer overflow&lt;br /&gt;
| hidbus GetJoyPollingReceivedData doesn&#039;t validate the u8 size used for memcpy, when copying the data to the output JoyPollingReceivedData. With 11.x, the size is now clamped to a maximum of 0x2C (regardless of polling-mode). Note that 0x2C is the data-size for JoyButtonOnlyPollingDataAccessor, the other polling-modes have a smaller size.&lt;br /&gt;
&lt;br /&gt;
The hid-sysmodule code which writes data here does handle it properly: size is clamped to a max size, and the data-read uses a fixed-size anyway (hence there&#039;s no way to trigger this sdknso vuln with the hid-sysmodule tmem writing code).&lt;br /&gt;
&lt;br /&gt;
This could only be exploited if one directly writes to the tmem when one has previously compromised hid-sysmodule, without using the normal tmem-writing func for this.&lt;br /&gt;
&lt;br /&gt;
There are only a few [[HID_services#ExternalDevices|apps]] which use hidbus.&lt;br /&gt;
| Triggering a buffer overflow in an application which uses hidbus GetJoyPollingReceivedData, from a previously compromised hid-sysmodule.&lt;br /&gt;
| 11.x.0&lt;br /&gt;
| 11.4.0&lt;br /&gt;
| March 2020&lt;br /&gt;
| December 3, 2020&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Profile_Selector|Profile Selector]] uninitialized input data&lt;br /&gt;
| Originally unused regions of [[Profile_Selector]] UiSettings/UserSelectionSettings were not cleared prior to being sent to the applet. With 1.x.x these are now properly memset().&lt;br /&gt;
| Stack infoleak from user-process, sent to the applet.&lt;br /&gt;
| 1.x.x&lt;br /&gt;
| 11.4.0&lt;br /&gt;
| November-December 2019&lt;br /&gt;
| December 31, 2020&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== NEX ===&lt;br /&gt;
This section documents client-side vulnerabilities for [https://github.com/Kinnay/NintendoClients/wiki/NEX-Overview-(Game-Servers) NEX].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Summary&lt;br /&gt;
!  Description&lt;br /&gt;
!  Successful exploitation result&lt;br /&gt;
!  Fixed in version&lt;br /&gt;
!  Timeframe this was discovered&lt;br /&gt;
!  Public disclosure timeframe&lt;br /&gt;
!  Discovered by&lt;br /&gt;
|-&lt;br /&gt;
| Buffer overflow in StringConversion::T2Char8&lt;br /&gt;
| StringConversion::T2Char8 is used to convert IP addresses from a platform-specific encoding to UTF-8. On the 3DS and Switch, the implementation is simply a strcpy. By sending a long IP address string, a buffer overflow can be triggered on the stack. The vulnerability can be triggered through the NAT traversal protocol. A blog post about this vulnerable can be found [https://reversing.live/hacking-hundreds-of-wii-us-at-once.html here].&lt;br /&gt;
| Stack overflow in any game that uses NEX for matchmaking&lt;br /&gt;
| Fixed server-side&lt;br /&gt;
| December, 2022&lt;br /&gt;
| May, 2024&lt;br /&gt;
| [https://github.com/kinnay Yannik]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Pia ===&lt;br /&gt;
This section documents vulnerabilities for [https://github.com/Kinnay/NintendoClients/wiki/Pia-Overview Pia].&lt;br /&gt;
&lt;br /&gt;
In v5.11.3 (exact starting version unknown) the fixes aren&#039;t present for the below vulns which were fixed in v5.9.3, while in v5.18.98 these are present (exact starting version unknown). This probably indicates that the vuln fixes were backported from a newer Pia version to v5.9.3.&lt;br /&gt;
&lt;br /&gt;
The Pia packet handlers are only active when the game is using multiplayer. LanProtocol is only active in the games which are actively using the LAN-mode option (not Ldn) - only certain games support LAN-mode. The LanProtocol Pia packet handler can be reached while in a lobby or searching for one.&lt;br /&gt;
&lt;br /&gt;
Most Pia packets require an active StationProtocol connection to be active with {InetAddr which the packet was received from}, otherwise the packet is filtered out. The only protocols which don&#039;t use filtering are the following: NatTraversalProtocol, LanProtocol, StationProtocol, LocalProtocol.&lt;br /&gt;
&lt;br /&gt;
Note that broadcast IP-dest Pia packets are accepted - this can be used to target every device on the network which is using Pia (which is really only useful with {above protocols} due to the filtering mentioned above, unless one also handles StationProtocol).&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Summary&lt;br /&gt;
!  Description&lt;br /&gt;
!  Successful exploitation result&lt;br /&gt;
!  Fixed in Pia version&lt;br /&gt;
!  Last Pia version this flaw was checked for&lt;br /&gt;
!  Timeframe this was discovered&lt;br /&gt;
!  Public disclosure timeframe&lt;br /&gt;
!  Discovered by&lt;br /&gt;
|-&lt;br /&gt;
| nn::pia::session::RelayRouteManageJob::UpdateConnectionReport buffer overflow&lt;br /&gt;
| nn::pia::session::RelayRouteManageJob::UpdateConnectionReport() checks that the input size is at least {value}, but there&#039;s no max size check. This is used to memcpy from the input to elsewhere - hence buf-overflow if size is too large. The dst buffer is allocated on the pead heap - this buffer is probably small.&lt;br /&gt;
Note that there&#039;s various requirements before it would actually reach the memcpy, such as &amp;lt;code&amp;gt;&amp;lt;nn::pia::session::Mesh::IsHost() const&amp;gt;&amp;lt;/code&amp;gt; must return true.&lt;br /&gt;
&lt;br /&gt;
This is called from nn::pia::session::MeshProtocol::ParseConnectionReport().&lt;br /&gt;
&lt;br /&gt;
ParseConnectionReport uses a state ptr for object nn::pia::session::RelayRouteManageJob, it will return if not set. nn::pia::session::Mesh::Initialize handles setup for this, depending on an input field from nn::pia::session::Mesh::Setting. These settings originate from &amp;lt;code&amp;gt;&amp;lt;nn::pia::session::Session::CreateInstance(nn::pia::session::Session::Setting const&amp;amp;)&amp;gt;&amp;lt;/code&amp;gt;, which is called by user-code with the needed settings.&lt;br /&gt;
ParseConnectionReport is therefore only usable if the game explicitly enables the Relay functionality.&lt;br /&gt;
&lt;br /&gt;
In fixed versions immediately after the StationIndex validation it now does: &amp;lt;code&amp;gt;if(statefield+0x10&amp;lt;input_size) return;&amp;lt;/code&amp;gt;&lt;br /&gt;
| Heap buffer overflow triggered by a Pia MeshProtocol message sent to a host device.&lt;br /&gt;
| v5.9.3, see above.&lt;br /&gt;
| v5.9.1/v5.9.2/v5.9.3&lt;br /&gt;
| November 11, 2022&lt;br /&gt;
| November 15, 2022&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| nn::pia::lan::LanProtocol::ParseSessionMessage buffer overflow&lt;br /&gt;
| nn::pia::lan::LanProtocol::ParseSessionMessage() calls nn::pia::lan::LanSessionMessage::Deserialize() to deserialize the message payload data buffer into the LanSessionMessage object on stack. LanSessionMessage::Deserialize (among other things) memcpys data from the input buffer to the object, using an u32 from the input buffer - there is no size validation in Deserialize itself.&lt;br /&gt;
There is a size check immediately after calling Deserialize() to verify &amp;lt;code&amp;gt;payloadsize=={u32val}+{constant}&amp;lt;/code&amp;gt;, returning on fail - but this doesn&#039;t matter for too-large-size.&lt;br /&gt;
&lt;br /&gt;
In fixed versions Deserialize now does bounds checking, both for the minimum message size and clamping the memcpy size to a constant. An error is thrown if the clamped memcpy size is larger than the message size. The caller now checks the ret properly, previously it was ignored.&lt;br /&gt;
&lt;br /&gt;
Following the size check in ParseSessionMessage() it calls &amp;lt;code&amp;gt;&amp;lt;nn::pia::session::Mesh::IsProcessingLeaveMesh() const&amp;gt;&amp;lt;/code&amp;gt;, returning if ret is false.&lt;br /&gt;
&lt;br /&gt;
Then it calls nn::pia::lan::LanProtocol::ReceivedFragmentData::Receive(), with the memcpy&#039;d buffer/size from the above LanSessionMessage, and other fields from LanSessionMessage. This eventually memcpys the input buffer to object+{offset}+{chunksize_field}*inputu8, there is no validation for size or inputu8 (except for the above size check). Hence, if the u8 is large enough, this would result in a heap buffer overflow.&lt;br /&gt;
&lt;br /&gt;
In fixed versions ReceivedFragmentData::Receive added a bunch of validation before the memcpy.&lt;br /&gt;
| Stack/heap buffer overflow triggered by a Pia LanProtocol message.&lt;br /&gt;
| v5.9.3, see above.&lt;br /&gt;
| v5.9.1/v5.9.2/v5.9.3&lt;br /&gt;
| November 14, 2022&lt;br /&gt;
| November 15, 2022&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| nn::pia::session::SessionProtocol::ParseLeaveMeshInvitation buffer overflow&lt;br /&gt;
| &amp;lt;code&amp;gt;&amp;lt;nn::pia::session::SessionProtocol::ParseLeaveMeshInvitation(nn::pia::transport::ReceivedMessageAccessor const&amp;amp;)&amp;gt;&amp;lt;/code&amp;gt; This immediately returns if *(ReceivedMessageAccessor+16) is 0. Then the input data is deserialized. The input u64 array is deserialized to stack, the u8 arraycount field from input is not validated.&lt;br /&gt;
&lt;br /&gt;
Hence, stack buffer overflow. Note that there&#039;s similar loop code in nearby funcs, which do validate the count properly.&lt;br /&gt;
&lt;br /&gt;
In fixed versions the arraycount field is now validated.&lt;br /&gt;
&lt;br /&gt;
SessionProtocol uses ReliableSlidingWindow MessageHeader, with a maximum message size of 0x100. The allocated size used for the above u64 array is also 0x100-bytes. Hence, when triggering a buf overflow the data after the buffer is uncontrolled data from the SessionProtocol object.&lt;br /&gt;
| Stack buffer overflow triggered by a Pia SessionProtocol message.&lt;br /&gt;
| v5.9.3, see above.&lt;br /&gt;
| v5.9.1/v5.9.2/v5.9.3&lt;br /&gt;
| November 14, 2022&lt;br /&gt;
| November 15, 2022&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| Optional Pia packet encryption&lt;br /&gt;
| Pia packet encryption is optional. If the encryption flag is disabled, the packet handler will accept it and skip crypto.&lt;br /&gt;
In fixed versions immediately after grabbing a packet, it now checks the crypto flag. If it&#039;s plaintext the packet is dropped.&lt;br /&gt;
&lt;br /&gt;
This can be used to send a plaintext Pia packet without needing to handle encryption, especially useful if the session-key can&#039;t be obtained (online-play matchmaking). This could be combined with other vulns if wanted.&lt;br /&gt;
| Sending a plaintext Pia packet without needing to handle encryption.&lt;br /&gt;
| v5.9.3, see above.&lt;br /&gt;
| v5.9.3 (and later versions)&lt;br /&gt;
| &lt;br /&gt;
| November 19, 2022&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| nn::pia::session::{JoinMeshJob/ProcessUpdateMeshJob}::SetStationDataList OOB read/write/vfunc-call&lt;br /&gt;
| &amp;lt;code&amp;gt;nn::pia::session::JoinMeshJob::SetStationDataList&amp;lt;/code&amp;gt;is called by &amp;lt;code&amp;gt;nn::pia::session::MeshProtocol::ParseJoinResponse(nn::pia::transport::ReceivedMessageAccessor const&amp;amp;)&amp;gt;&amp;lt;/code&amp;gt; with the ReceivedMessageAccessor buffer.&lt;br /&gt;
SetStationDataList will update state and immediately return if the join was denied. It will also validate the num_mesh_stations field against state. ParseJoinResponse also essentially verifies that the message was received from the host device.&lt;br /&gt;
&lt;br /&gt;
The input buffer size is ignored.&lt;br /&gt;
&lt;br /&gt;
The num_fragments field must be value 1 or &amp;lt;=3 otherwise it will return, there&#039;s two seperate code blocks handling these.&lt;br /&gt;
&lt;br /&gt;
Other than the checks at the start, there&#039;s no validation for the index fields. So large enough values could result in OOB-reads.&lt;br /&gt;
&lt;br /&gt;
When handling multiple fragments, it will loop through the stationinfo list. There is no validation for the u8 count field or the baseindex field. It calls a vfunc from obj baseptr+index*{entrysize} with data from the buffer, where index starts with the above baseindex field. Afterwards, an u8 is copied into an u32 array (with certain versions an u16 is deserialized into an u16 array).&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;nn::pia::session::ProcessUpdateMeshJob::UpdateStationDataList&amp;lt;/code&amp;gt; is (eventually) called from &amp;lt;code&amp;gt;nn::pia::session::MeshProtocol::ParseUpdateMesh&amp;lt;/code&amp;gt;, which has similar issues to the above.&lt;br /&gt;
&lt;br /&gt;
Note that ParseJoinResponse/ParseUpdateMesh essentially require the message to be received from the host device.&lt;br /&gt;
&lt;br /&gt;
With fixed versions (v5.18.98, exact version unknown) various validation was added. Additional/updated validation was added in a later version (v5.31.0, exact version unknown).&lt;br /&gt;
| OOB read/write / vfunc call where the object is selected by an OOB index, triggered by a Pia MeshProtocol message.&lt;br /&gt;
| v5.18.98 and v5.31.0 (exact versions unknown).&lt;br /&gt;
| v5.31.0&lt;br /&gt;
| November 18, 2022&lt;br /&gt;
| November 21, 2022&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| Insecure encryption&lt;br /&gt;
| Originally Pia packets used AES-ECB encryption. As documented [https://github.com/Kinnay/NintendoClients/wiki/Pia-Overview here] it was later changed with v5.7.0 to AES-GCM. Each 0x10-byte block would have the same encrypted block output where the plaintext 0x10-byte data is the same.&lt;br /&gt;
The mechanism for generating the Pia SessionKey for LAN has also changed over time.&lt;br /&gt;
&lt;br /&gt;
The [https://github.com/Kinnay/NintendoClients/wiki/LAN-Protocol LAN] non-Pia-encapsulated packets were also originally sent in plaintext, however at some point it was changed to mostly encrypted.&lt;br /&gt;
| &lt;br /&gt;
| AES-GCM fix: v5.7.0&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| nn::pia::transport::UnreliableProtocol::Dispatch buffer overflow&lt;br /&gt;
| &amp;lt;code&amp;gt;nn::pia::transport::UnreliableProtocol::Dispatch&amp;lt;/code&amp;gt; memcpys data from the message into a list entry, without size validation. If the pia packet is the max size, it will only overwrite the 0xC-bytes which were written to immediately before the memcpy: the u32 size and the 8-byte StationAddress (depending on the version there can also be 4-byte padding after the size for alignment).&lt;br /&gt;
However, nn::pia::transport::UnreliableProtocol::Receive will clamp the size from the list entry to the outbuf size when doing the memcpy. So this is probably useless.&lt;br /&gt;
&lt;br /&gt;
It&#039;s unknown whether there&#039;s a version where more data could be overwritten, and whether that would be useful.&lt;br /&gt;
&lt;br /&gt;
This is fixed in v5.31.0, exact version unknown. The message is dropped if too large in Dispatch.&lt;br /&gt;
| Small buffer overflow triggered by a Pia UnreliableProtocol message.&lt;br /&gt;
| v5.31.0, exact version unknown.&lt;br /&gt;
| v5.18.98/v5.31.0&lt;br /&gt;
| November 2022&lt;br /&gt;
| November 29, 2022&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| Uncleared input structs for [[LDN_services|LDN]]&lt;br /&gt;
| The Pia code using ldn CreateNetwork*/ConnectNetwork*/Scan doesn&#039;t properly memset the input data for SecurityConfig/ScanFilter (when keysize is less than 0x40 for the former). Hence, infoleak from games is sent to ldn (structs are located on stack, so stack data is leaked). This requires ldn compromise/mitm to obtain the leaked data - these are not sent over the network.&lt;br /&gt;
With v6.20.1 (exact version unknown - fix isn&#039;t present in v5.32.0), the code using Scan* now clears the input ScanFilter properly. With v6.25.1 (exact version unknown - fix isn&#039;t present in v6.23.3), the code using CreateNetwork*/ConnectNetwork* now clears the input SecurityConfig properly.&lt;br /&gt;
| Infoleak from games with LDN cmds, requires compromised sysmodule/mitm.&lt;br /&gt;
| v6.20.1 and v6.25.1, exact versions unknown.&lt;br /&gt;
| v5.32.0/v6.20.1/v6.23.3/v6.25.1&lt;br /&gt;
| &lt;br /&gt;
| December 7, 2022&lt;br /&gt;
| &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== ENL ===&lt;br /&gt;
This section documents vulnerabilities for [https://github.com/kinnay/NintendoClients/wiki/ENL-Protocol ENL].&lt;br /&gt;
A framework used by Nintendo games including Mario Kart 8 Deluxe, Splatoon 2 / 3, Mario Maker 2, and more.&lt;br /&gt;
&lt;br /&gt;
Fun fact, this library appears to re-use network code and concepts from older Nintendo titles such as Mario Kart 7 and some Wii multiplayer games.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Summary&lt;br /&gt;
!  Description&lt;br /&gt;
!  Successful exploitation result&lt;br /&gt;
!  Fixed in Enl version&lt;br /&gt;
!  Last Enl version this flaw was checked for&lt;br /&gt;
!  Timeframe this was discovered&lt;br /&gt;
!  Public disclosure timeframe&lt;br /&gt;
!  Discovered by&lt;br /&gt;
|-&lt;br /&gt;
| enl::TransportManager::updateReceiveBuffer_() nullptr deref&lt;br /&gt;
| enl::TransportManager::updateReceiveBuffer_() is called when the ENL framework receives a PIA packet from a client, it will fully trust the ENL header which includes a &amp;quot;ContentTransporter&amp;quot; type (ID) and a length.&lt;br /&gt;
The function will try to fetch the content transporter by ID using &amp;lt;code&amp;gt;enl::TransportManager::getContentTransporter(unsigned char const &amp;amp;)&amp;lt;/code&amp;gt;, it returns NULL if there&#039;s no content transporter with the same ID&lt;br /&gt;
&lt;br /&gt;
*NOTE: The function may be inlined&lt;br /&gt;
&lt;br /&gt;
Then it will try to call a virtual method: &amp;lt;code&amp;gt;virtual size_t readyReceiveStream(enl::RamReadStream&amp;amp;, enl::Buffer*, size_t)&amp;lt;/code&amp;gt;, dereferencing the pointer to fetch the vtable ptr&lt;br /&gt;
&lt;br /&gt;
[https://gist.github.com/Rambo6Glaz/c088e2ed7a12db08f6322e9f7a3c4911 Pseudocode of the function before it was fixed]&lt;br /&gt;
&lt;br /&gt;
| nullptr dereference triggered by an invalid content transporter type in the ENL header (it will crash the game/process)&lt;br /&gt;
| Unknown&lt;br /&gt;
| Depends on the game&lt;br /&gt;
| Early April 2022&lt;br /&gt;
| November 16, 2022&lt;br /&gt;
| [[User:Rambo6Glaz|Rambo6Glaz]], [https://github.com/kinnay Yannik] (massive RE help)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
There&#039;s another one more interesting but it will have to wait a bit :)&lt;br /&gt;
&lt;br /&gt;
== Games ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Game&lt;br /&gt;
!  Summary&lt;br /&gt;
!  Description&lt;br /&gt;
!  Impact&lt;br /&gt;
!  Fixed in version&lt;br /&gt;
!  Timeframe this was discovered&lt;br /&gt;
!  Public disclosure timeframe&lt;br /&gt;
!  Discovered by&lt;br /&gt;
|-&lt;br /&gt;
| Mario Kart World&lt;br /&gt;
| ASLR leak in application data&lt;br /&gt;
| A memory address can be leaked by changing your username to something short, and hosting a network session in LAN mode (press L + R + Left Stick on the main menu to enable this). The memory address can be found in bytes 12 - 19 of the application data that is transmitted in response to a browse request.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note:&#039;&#039;&#039; there is more uninitialized data in the packet, but the memory address is probably the most interesting part. The vulnerability was fixed by clearing the application data with zeros, before filling in the information.&lt;br /&gt;
&lt;br /&gt;
[https://hackerone.com/reports/3463719 HackerOne report]&lt;br /&gt;
&lt;br /&gt;
This stack infoleak was also present in the [[LDN_services|ldn]] AdvertiseData.&lt;br /&gt;
| A memory address can leaked (this is a requirement for many types of attacks).&lt;br /&gt;
| 1.5.0&lt;br /&gt;
| December 12, 2025&lt;br /&gt;
| February 19, 2026&lt;br /&gt;
| [https://github.com/kinnay Yannik], yellows8 (ldn)&lt;br /&gt;
|-&lt;br /&gt;
| Splatoon 3&lt;br /&gt;
| Anticheat Seed Randomization Weakness&lt;br /&gt;
| This oversight of seed generation would allow an attacker to quickly compute all code hashes, and modify game code, while still producing a valid ch1 hash.&lt;br /&gt;
&lt;br /&gt;
[https://hackerone.com/reports/3042475 HackerOne report]&lt;br /&gt;
| Allows an attacker to bypass the ch1 anti-cheat hashing mechanism.&lt;br /&gt;
| 10.0.0&lt;br /&gt;
| March 17, 2025&lt;br /&gt;
| February 19, 2026&lt;br /&gt;
| hana2736&lt;br /&gt;
|-&lt;br /&gt;
| Splatoon Raiders&lt;br /&gt;
| Infoleak in application data&lt;br /&gt;
| A ptr can be leaked by hosting a network session in local (at least ldn) mode. The uninitialized data follows the last username in the appdata ([[LDN_services|ldn]] AdvertiseData). With account/game username short even more data/ptrs are leaked.&lt;br /&gt;
With v1.1.1 that data is now cleared.&lt;br /&gt;
| Game infoleak, which allows defeating ASLR.&lt;br /&gt;
| 1.1.1&lt;br /&gt;
| July 25, 2026&lt;br /&gt;
| August 6, 2026&lt;br /&gt;
| [[User:Yellows8|yellows8]] (ldn)&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Yellows8</name></author>
	</entry>
	<entry>
		<id>https://switchbrew.org/w/index.php?title=Title_list&amp;diff=14927</id>
		<title>Title list</title>
		<link rel="alternate" type="text/html" href="https://switchbrew.org/w/index.php?title=Title_list&amp;diff=14927"/>
		<updated>2026-08-06T15:31:00Z</updated>

		<summary type="html">&lt;p&gt;Yellows8: /* System Applets */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= System Modules =&lt;br /&gt;
Note: Unlike 3DS, Switch doesn&#039;t have a dedicated HTTP-sysmodule. Instead, processes using HTTP(S) just use libcurl + socket/ssl services.&lt;br /&gt;
&lt;br /&gt;
From [[2.0.0]] to [[9.2.0]], [[HID_services|hid-sysmodule]] was the only sysmodule with a RomFS.&lt;br /&gt;
As of [[10.0.0]], no sysmodules have a RomFS.&lt;br /&gt;
&lt;br /&gt;
Decimal versions use the format:&lt;br /&gt;
* Bit31-Bit26: Major&lt;br /&gt;
* Bit25-Bit20: Minor&lt;br /&gt;
* Bit19-Bit16: Micro&lt;br /&gt;
* Bit15-Bit0: Relstep&lt;br /&gt;
&lt;br /&gt;
{| class=wikitable&lt;br /&gt;
! ProgramId || Versions || Description || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000000 || [bundled with kernel] || [[Filesystem_services|fs]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000001 || [bundled with kernel] || [[Loader_services|ldr (Loader)]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000002 || [bundled with kernel] || [[NCM_services|ncm]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000003 || [bundled with kernel] || [[Process_Manager_services|pm (ProcessMana)]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000004 || [bundled with kernel] || [[Services_API|sm]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000005 || [bundled with kernel] || [[boot]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000006 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.1.0|v403701850]] (6.1.0.90)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100)&amp;lt;br/&amp;gt; [[22.5.0|v1481638368]] (22.5.0.480) || [[USB_services|usb]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000007 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [[TMA_services|tma]] (debug)&amp;lt;br/&amp;gt;[1.0.0-10.2.0] [[TMA_services|tma.stub]] (retail)&amp;lt;br/&amp;gt;[11.0.0+] [[TMA_services|htc.stub]] (retail) ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000008 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [[Boot2|boot2]] (debug)&amp;lt;br/&amp;gt; [[Boot2|boot2.SafeMode]] (safe)&amp;lt;br/&amp;gt;  [[Boot2|boot2.FromHost]] (develop)&amp;lt;br/&amp;gt; [[Boot2|boot2.prodBoot]] (retail)&amp;lt;br/&amp;gt;[[Boot2|boot2.manuBoot]] (factory)&amp;lt;br/&amp;gt;[[Boot2|boot2.Manu1st]] (factory) ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000009 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.1.0|v537919608]] (8.1.0.120)&amp;lt;br/&amp;gt; [[8.1.1|v537919608]] (8.1.0.122)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[10.1.0|v672137336]] (10.1.0.120)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100)&amp;lt;br/&amp;gt; [[22.5.0|v1481638368]] (22.5.0.480) || [[Settings_services|settings]] &amp;lt;br/&amp;gt; [[Settings_services|settings_hoag]] ([[8.1.1]]) ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000000A || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.1.0|v537919608]] (8.1.0.120)&amp;lt;br/&amp;gt; [[8.1.1|v537919608]] (8.1.0.122)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[14.1.2|v940703804]] (14.1.2.60)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [[Bus_services|Bus]] &amp;lt;br/&amp;gt; [[Bus_services|Bus_hoag]] ([[8.1.1]]) ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000000B || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.0.1|v805371944]] (12.0.1.40)&amp;lt;br/&amp;gt; [[12.0.2|v805437460]] (12.0.2.20)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[13.1.0|v873463948]] (13.1.0.140)&amp;lt;br/&amp;gt; [[13.2.1|v874578000]] (13.2.1.80)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[16.1.0|v1074790880]] (16.1.0.480)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[19.0.2|v1275199548]] (19.0.2.60)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [1.0.0-19.0.1] [[Bluetooth_Driver_services|bluetooth]]&amp;lt;br/&amp;gt;[20.0.0+] [[Bluetooth_Driver_services|bluetooth.autog]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000000C || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[3.0.2|v201457684]] (3.0.2.20)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[7.0.1|v469827614]] (7.0.1.30)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.1.0|v537919608]] (8.1.0.120)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.1.0|v605028512]] (9.1.0.160)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220))&amp;lt;br/&amp;gt; [[13.1.0|v873463948]] (13.1.0.140)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[14.1.0|v940572692]] (14.1.0.20)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[16.0.1|v1073807420]] (16.0.1.60)&amp;lt;br/&amp;gt; [[16.1.0|v1074790880]] (16.1.0.480)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[21.1.0|v1410335000]] (21.1.0.280)&amp;lt;br/&amp;gt; [[19.0.2|v1275199548]] (19.0.2.60)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [[BCAT_services|bcat]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000000D || || dmnt (currently not present on retail devices) ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000000E || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.1.0|v605028512]] (9.1.0.160)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[10.1.0|v672137336]] (10.1.0.120)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [[Friend_services|friends]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000000F || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[2.1.0|v131082]] (0.0.2.10)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.1.0|v403701850]] (6.1.0.90)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.1.0|v605028512]] (9.1.0.160)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220))&amp;lt;br/&amp;gt; [[13.1.0|v873463948]] (13.1.0.140)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634160]] (15.0.0.1200)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[18.0.1|v1208025188]] (18.0.1.100)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[21.1.0|v1410335000]] (21.1.0.280)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [[Network_Interface_services|nifm]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000010 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[2.1.0|v131132]] (0.0.2.60)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.0.2|v335675432]] (5.0.2.40)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.1.1|v536936550]] (8.0.1.102)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[10.0.2|v671219752]] (10.0.2.40)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [[PTM_services|ptm]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000011 || || shell (currently not present on retail devices) ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000012 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[2.3.0|v131092]] (0.0.2.20)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[3.0.2|v201457684]] (3.0.2.20)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.0.2|v335675432]] (5.0.2.40)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.0.1|v536936528]] (8.0.1.80)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.1.0|v605028512]] (9.1.0.160)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.0.1|v805371944]] (12.0.1.40)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220))&amp;lt;br/&amp;gt; [[13.1.0|v873463948]] (13.1.0.140)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[15.0.1|v1006698596]] (15.0.1.100)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[19.0.2|v1275199548]] (19.0.2.60)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100)&amp;lt;br/&amp;gt; [[22.5.0|v1481638368]] (22.5.0.480) || [[Sockets_services|bsdsocket]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000013 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[2.1.0|v131132]] (0.0.2.60)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[4.1.0|v269484082]] (4.1.0.50)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.0.2|v335675432]] (5.0.2.40)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.0.1|v402718730]] (6.0.1.10)&amp;lt;br/&amp;gt; [[6.1.0|v403701850]] (6.1.0.90)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.0.1|v536936528]] (8.0.1.80)&amp;lt;br/&amp;gt; [[8.1.0|v537919608]] (8.1.0.120)&amp;lt;br/&amp;gt; [[8.1.1|v537919608]] (8.1.0.122)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.0.1|v604045372]] (9.0.1.60)&amp;lt;br/&amp;gt; [[9.1.0|v605028512]] (9.1.0.160)&amp;lt;br/&amp;gt; [[10.0.0|v671088980]] (10.0.0.340)&amp;lt;br/&amp;gt; [[10.0.1|v671154196]] (10.0.1.20)&amp;lt;br/&amp;gt; [[10.0.2|v671219752]] (10.0.2.40)&amp;lt;br/&amp;gt; [[10.1.0|v672137336]] (10.1.0.120)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[11.0.1|v738263060]] (11.0.1.20)&amp;lt;br/&amp;gt; [[12.0.0|v805308888]] (12.0.0.2520)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220))&amp;lt;br/&amp;gt; [[13.1.0|v873463948]] (13.1.0.140)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[17.0.1|v1140916284]] (17.0.1.60)&amp;lt;br/&amp;gt; [[18.0.0|v1207960692]] (18.0.0.1140)&amp;lt;br/&amp;gt; [[18.1.0|v1209008288]] (18.1.0.160)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[19.0.1|v1275133992]] (19.0.1.40)&amp;lt;br/&amp;gt; [[20.0.0|v1342178960]] (20.0.0.1680)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[20.4.0|v1346371784]] (20.4.0.200)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100)&amp;lt;br/&amp;gt; [[22.5.0|v1481638368]] (22.5.0.480) || [[HID_services|hid]]&amp;lt;br/&amp;gt;[[HID_services|hid_EdevLogEnab]] (factory) &amp;lt;br/&amp;gt; [[HID_services|hid_hoag]] ([[8.1.1]]) ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000014 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.0.1|v402718730]] (6.0.1.10)&amp;lt;br/&amp;gt; [[6.1.0|v403701850]] (6.1.0.90)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.1.1|v537919608]] (8.1.0.122)&amp;lt;br/&amp;gt; [[8.1.0|v537919608]] (8.1.0.120)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[16.1.0|v1074790880]] (16.1.0.480)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [[Audio_services|audio]] &amp;lt;br/&amp;gt; [[Audio_services|audio_hoag]] ([[8.1.1]]) ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000015 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [[Log_services|LogManager]] (debug)&amp;lt;br/&amp;gt;[[Log_services|LogManager.Prod]] (retail) ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000016 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[2.1.0|v131082]] (0.0.2.10)&amp;lt;br/&amp;gt; [[2.2.0|v196608]] (0.0.3.0)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[3.0.2|v201457684]] (3.0.2.20)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.1.0|v537919608]] (8.1.0.120)&amp;lt;br/&amp;gt; [[8.1.1|v537985046]] (8.1.1.22)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.1.0|v605028512]] (9.1.0.160)&amp;lt;br/&amp;gt; [[10.0.0|v671089000]] (10.0.0.360)&amp;lt;br/&amp;gt; [[10.1.0|v672137336]] (10.1.0.120)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[20.2.0|v1344274732]] (20.2.0.300)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100)&amp;lt;br/&amp;gt; [[22.5.0|v1481638368]] (22.5.0.480) || [[WLAN_services|wlan]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000017 || || cs (currently not present on retail devices) ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000018 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.1.0|v605028512]] (9.1.0.160)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197944]] (11.0.0.440)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220))&amp;lt;br/&amp;gt; [[13.1.0|v873463948]] (13.1.0.140)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[17.0.1|v1140916284]] (17.0.1.60)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[20.2.0|v1344274732]] (20.2.0.300)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [[LDN_services|ldn]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000019 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[2.1.0|v131082]] (0.0.2.10)&amp;lt;br/&amp;gt; [[2.3.0|v196628]] (0.0.3.20)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[3.0.2|v201457684]] (3.0.2.20)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[4.0.1|v268501002]] (4.0.1.10)&amp;lt;br/&amp;gt; [[4.1.0|v269484082]] (4.1.0.50)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.1.0|v537919608]] (8.1.0.120)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[10.1.0|v672137336]] (10.1.0.120)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220))&amp;lt;br/&amp;gt; [[13.1.0|v873463948]] (13.1.0.140)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [[NV_services|nvservices]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000001A || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [[PCV_services|pcv]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000001B || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.0.2|v335675432]] (5.0.2.40)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [1.0.0-7.0.1] [[PPC_services|ppc]]&amp;lt;br/&amp;gt; [11.0.0+] [[Capmtp_services|capmtp]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000001C || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[2.1.0|v131082]] (0.0.2.10)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[4.1.0|v269484082]] (4.1.0.50)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.1.0|v537919608]] (8.1.0.120)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [[Nvnflinger_services|nvnflinger]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000001D || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.1.0|v403701850]] (6.1.0.90)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [1.0.0-9.2.0] [[PCIe_services|pcie.withoutHb]] (retail)&amp;lt;br/&amp;gt;[10.0.0+] [[PCIe_services|pcie]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000001E || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[3.0.2|v201457684]] (3.0.2.20)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.1.0|v403701850]] (6.1.0.90)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[7.0.1|v469827614]] (7.0.1.30)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.0.1|v536936528]] (8.0.1.80)&amp;lt;br/&amp;gt; [[8.1.0|v537919608]] (8.1.0.120)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.1.0|v605028512]] (9.1.0.160)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220))&amp;lt;br/&amp;gt; [[13.1.0|v873463948]] (13.1.0.140)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178960]] (20.0.0.1680)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[20.1.5|v1343553696]] (20.1.5.160)&amp;lt;br/&amp;gt; [[20.2.0|v1344274732]] (20.2.0.300)&amp;lt;br/&amp;gt; [[20.5.0|v1347420260]] (20.5.0.100)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100)&amp;lt;br/&amp;gt; [[22.5.0|v1481638368]] (22.5.0.480) || [[Account_services|account]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000001F || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[2.1.0|v131132]] (0.0.2.60)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.1.0|v403701850]] (6.1.0.90)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[7.0.1|v469827614]] (7.0.1.30)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.1.0|v537919608]] (8.1.0.120)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.0.1|v604045372]] (9.0.1.60)&amp;lt;br/&amp;gt; [[9.1.0|v605028512]] (9.1.0.160)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[10.1.0|v672137336]] (10.1.0.120)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220))&amp;lt;br/&amp;gt; [[13.1.0|v873463968]] (13.1.0.160)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[14.1.1|v940638228]] (14.1.1.20)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[15.0.1|v1006698596]] (15.0.1.100)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[18.0.1|v1208025188]] (18.0.1.100)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[19.0.1|v1275134052]] (19.0.1.100)&amp;lt;br/&amp;gt; [[20.0.0|v1342179000]] (20.0.0.1720)&amp;lt;br/&amp;gt; [[20.0.1|v1342242836]] (20.0.1.20)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[20.1.1|v1343291412]] (20.1.1.20)&amp;lt;br/&amp;gt; [[20.1.5|v1343553696]] (20.1.5.160)&amp;lt;br/&amp;gt; [[20.2.0|v1344274732]] (20.2.0.300)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[21.1.0|v1410335000]] (21.1.0.280)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100)&amp;lt;br/&amp;gt; [[22.5.0|v1481638368]] (22.5.0.480) || [[NS_Services|ns]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000020 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[2.2.0|v131072]] (0.0.2.0)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.1.1|v536871444]] (8.0.0.532)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.1.0|v605028512]] (9.1.0.160)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [[NFC_services|nfc]] &amp;lt;br/&amp;gt; [[NFC_services|nfc_Hoag]] ([[8.1.1]]) ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000021 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[21.1.0|v1410335000]] (21.1.0.280)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [[PSC_services|psc]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000022 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [[Capture_services|capsrv]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000023 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[2.1.0|v131132]] (0.0.2.60)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.1.0|v403701850]] (6.1.0.90)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.1.0|v537919608]] (8.1.0.120)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.1.0|v605028512]] (9.1.0.160)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[10.1.0|v672137336]] (10.1.0.120)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220))&amp;lt;br/&amp;gt; [[13.1.0|v873463948]] (13.1.0.140)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[15.0.1|v1006698596]] (15.0.1.100)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[19.0.1|v1275133992]] (19.0.1.40)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[20.2.0|v1344274732]] (20.2.0.300)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100)&amp;lt;br/&amp;gt; [[22.5.0|v1481638368]] (22.5.0.480) || [[AM_services|am]]&amp;lt;br/&amp;gt;[[AM_services|am.withoutPscWa]] (factory) ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000024 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.1.0|v537919608]] (8.1.0.120)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.0.3|v805502996]] (12.0.3.20)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[13.2.1|v874578000]] (13.2.1.80)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[16.0.2|v1073872936]] (16.0.2.40)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[20.2.0|v1344274732]] (20.2.0.300)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[19.0.2|v1275199548]] (19.0.2.60)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100)&amp;lt;br/&amp;gt; [[22.5.0|v1481638368]] (22.5.0.480) || [[SSL_services|ssl]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000025 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[2.1.0|v131082]] (0.0.2.10)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[4.1.0|v269484082]] (4.1.0.50)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.1.0|v403701850]] (6.1.0.90)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.0.1|v536936528]] (8.0.1.80)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.1.0|v605028512]] (9.1.0.160)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[10.1.0|v672137336]] (10.1.0.120)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220))&amp;lt;br/&amp;gt; [[13.1.0|v873463948]] (13.1.0.140))&amp;lt;br/&amp;gt; [[13.1.0|v873463948]] (13.1.0.140)&amp;lt;br/&amp;gt; [[13.2.0|v874512404]] (13.2.0.20)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[15.0.1|v1006698596]] (15.0.1.100)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[20.2.0|v1344274732]] (20.2.0.300)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[21.1.0|v1410335000]] (21.1.0.280)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [[NIM_services|nim]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000026 || || cec (currently not present on retail devices) ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000027 || || tspm (currently not present on retail devices) ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000028 || [bundled with kernel] || [[SPL_services|spl]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000029 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300) || [1.0.0-9.2.0] [[Backlight_services|lbl]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000002A || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.1.0|v403701850]] (6.1.0.90)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[7.0.1|v469827614]] (7.0.1.30)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[10.1.0|v672137336]] (10.1.0.120)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220))&amp;lt;br/&amp;gt; [[13.1.0|v873463948]] (13.1.0.140)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[14.1.2|v940703804]] (14.1.2.60)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[16.1.0|v1074790880]] (16.1.0.480)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [[BTM_services|btm]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000002B || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[2.1.0|v131132]] (0.0.2.60)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.1.0|v605028512]] (9.1.0.160)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220))&amp;lt;br/&amp;gt; [[13.1.0|v873463948]] (13.1.0.140)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[19.0.1|v1275133992]] (19.0.1.40)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[20.1.5|v1343553696]] (20.1.5.160)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100)&amp;lt;br/&amp;gt; [[22.5.0|v1481638368]] (22.5.0.480) || [[Error_Report_services|erpt]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000002C || || time (currently not present on retail devices) ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000002D || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.1.0|v537919608]] (8.1.0.120)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[11.0.1|v738263060]] (11.0.1.20)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [[Display_services|vi]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000002E || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[2.1.0|v131082]] (0.0.2.10)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[16.1.0|v1074790880]] (16.1.0.480)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[20.1.5|v1343553696]] (20.1.5.160)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[21.0.1|v1409351720]] (21.0.1.40)&amp;lt;br/&amp;gt; [[21.1.0|v1410335000]] (21.1.0.280)&amp;lt;br/&amp;gt; [[21.2.0|v1411383436]] (21.2.0.140)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [[Parental_Control_services|pctl]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000002F || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.0.1|v536936528]] (8.0.1.80)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[10.1.0|v672137336]] (10.1.0.120)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960692]] (18.0.0.1140)&amp;lt;br/&amp;gt; [[18.1.0|v1209008288]] (18.1.0.160)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[19.0.1|v1275133992]] (19.0.1.40)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[20.2.0|v1344274732]] (20.2.0.300)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [[NPNS_services|npns]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000030 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[2.1.0|v131132]] (0.0.2.60)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[19.0.1|v1275133992]] (19.0.1.40)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [[Error_Upload_services|eupld]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000031 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[20.5.0|v1347420260]] (20.5.0.100)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [1.0.0] arp&amp;lt;br/&amp;gt;[2.0.0+] [[Glue_services|glue]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000032 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || eclct ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000033 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.1.0|v403701850]] (6.1.0.90)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[7.0.1|v469827614]] (7.0.1.30)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.1.0|v537919608]] (8.1.0.120)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[10.1.0|v672137336]] (10.1.0.120)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220))&amp;lt;br/&amp;gt; [[13.1.0|v873463948]] (13.1.0.140)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100)&amp;lt;br/&amp;gt; [[22.1.0|v1477443784]] (22.1.0.200)&amp;lt;br/&amp;gt; [[22.5.0|v1481638368]] (22.5.0.480) || [[ETicket_services|es]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000034 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[2.1.0|v131132]] (0.0.2.60)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[4.1.0|v269484082]] (4.1.0.50)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.1.0|v537919608]] (8.1.0.120)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [[Fatal_services|fatal]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000035 || [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.1.0|v537919608]] (8.1.0.120)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[20.2.0|v1344274732]] (20.2.0.300)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [4.0.0+] [[GRC_services|grc]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000036 || [[2.0.0|v260]] (0.0.0.260)&amp;lt;br/&amp;gt; [[2.1.0|v65596]] (0.0.1.60)&amp;lt;br/&amp;gt; [[2.3.0|v131092]] (0.0.2.20)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[3.0.2|v201457684]] (3.0.2.20)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.1.0|v403701850]] (6.1.0.90)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.1.0|v537919608]] (8.1.0.120)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.0.1|v604045372]] (9.0.1.60)&amp;lt;br/&amp;gt; [[9.1.0|v605028512]] (9.1.0.160)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197944]] (11.0.0.440)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[17.0.1|v1140916284]] (17.0.1.60)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[21.1.0|v1410335000]] (21.1.0.280)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [[creport]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000037 || [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.1.0|v537919608]] (8.1.0.120)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.1.0|v605028512]] (9.1.0.160)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [3.0.0+] [[RO_services|ro]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000038 || || [[Profiler services|profiler]] (currently not present on retail devices) ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000039 || [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[10.2.0|v673185832]] (10.2.0.40)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[20.2.0|v1344274732]] (20.2.0.300)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[21.2.0|v1411383436]] (21.2.0.140)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100)&amp;lt;br/&amp;gt; [[22.1.0|v1477443784]] (22.1.0.200) || [3.0.0+] [[Shared_Database_services|sdb]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000003A || [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.1.0|v605028512]] (9.1.0.160)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[10.1.0|v672137336]] (10.1.0.120)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[18.1.0|v1209008288]] (18.1.0.160)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[19.0.1|v1275134052]] (19.0.1.100)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[20.1.5|v1343553696]] (20.1.5.160)&amp;lt;br/&amp;gt; [[20.2.0|v1344274732]] (20.2.0.300)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[21.0.1|v1409351720]] (21.0.1.40)&amp;lt;br/&amp;gt; [[21.1.0|v1410335000]] (21.1.0.280)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100)&amp;lt;br/&amp;gt; [[22.1.0|v1477443784]] (22.1.0.200)&amp;lt;br/&amp;gt; [[22.5.0|v1481638368]] (22.5.0.480) || [4.0.0+] [[Migration_services|migration]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000003B || [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [10.0.0+] [[JIT_services|jit]] (retail) ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000003C || [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [4.0.0+] [[Jpegdec_services|jpegdec]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000003D || [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [4.0.0+] [[safemode]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000003E || [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.1.0|v403701850]] (6.1.0.90)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.1.0|v605028512]] (9.1.0.160)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[10.1.0|v672137336]] (10.1.0.120)&amp;lt;br/&amp;gt; [[10.2.0|v673185832]] (10.2.0.40)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220))&amp;lt;br/&amp;gt; [[13.1.0|v873463948]] (13.1.0.140)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[16.1.0|v1074790880]] (16.1.0.480)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[20.2.0|v1344274732]] (20.2.0.300)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[21.1.0|v1410335000]] (21.1.0.280)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [6.0.0+] [[OLSC_services|olsc]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000003F || || dt (currently not present on retail devices) ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000040 || || nd (currently not present on retail devices) ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000041 || [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.1.0|v605028512]] (9.1.0.160)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[16.1.0|v1074790880]] (16.1.0.480)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940) || [9.0.0-20.5.0] [[NGCT_services|ngct]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000042 || [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.0.2|v805437460]] (12.0.2.20)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [10.0.0+] [[PGL_services|pgl]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000043 || || (currently not present on retail devices) ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000044 || || (currently not present on retail devices) ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000045 || [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[17.0.1|v1140916284]] (17.0.1.60)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[19.0.1|v1275134052]] (19.0.1.100)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [14.0.0+] [[OMM_services|omm]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000046 || [[15.0.0|v1006634160]] (15.0.0.1200)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [15.0.0+] [[Ethernet_services|eth]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000047 || || (currently not present on retail devices) ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000048 || || (currently not present on retail devices) ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000049 || || (currently not present on retail devices) ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000004A || || (currently not present on retail devices) ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000004B || || (currently not present on retail devices) ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000004C || || netTc (currently not present on retail devices) ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000004D || || (currently not present on retail devices) ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000004E || || (currently not present on retail devices) ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000004F || || (currently not present on retail devices) ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000050 || [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [16.0.0+] [[NGC_services|ngc]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000051 || || dmgr (currently not present on retail devices) ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= System Data Archives =&lt;br /&gt;
{| class=wikitable&lt;br /&gt;
! ProgramId || Versions || Description || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000800 || [[1.0.0|v260]] (0.0.0.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[10.0.3|v671285268]] (10.0.3.20)&amp;lt;br/&amp;gt; [[10.1.0|v672137336]] (10.1.0.120)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [[SSL_services#CertStore|CertStore]] || SSL trusted certificates.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000801 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[2.2.0|v196628]] (0.0.3.20)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.2|v201457684]] (3.0.2.20)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.1.0|v403701850]] (6.1.0.90)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.1.0|v537919608]] (8.1.0.120)&amp;lt;br/&amp;gt; [[8.1.1|v537919608]] (8.1.0.122)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.1.0|v605028512]] (9.1.0.160)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[10.1.0|v672137336]] (10.1.0.120)&amp;lt;br/&amp;gt; [[11.0.0|v738197804]] (11.0.0.300)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[13.1.0|v873463908]] (13.1.0.100)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851668]] (17.0.0.980)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || ErrorMessage || Stores the message strings for Support Error Codes. There&#039;s &amp;quot;/DatabaseInfo&amp;quot; at FS root, then the rest is stored at &amp;quot;/{first 4 error digits}/{last 4 error digits}/&amp;quot;.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000802 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || MiiModel ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000803 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[2.1.0|v196628]] (0.0.3.20)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.1.0|v403701850]] (6.1.0.90)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.1.0|v537919608]] (8.1.0.120)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.0.1|v604045412]] (9.0.1.100)&amp;lt;br/&amp;gt; [[9.1.0|v605028592]] (9.1.0.240)&amp;lt;br/&amp;gt; [[10.0.0|v671088960]] (10.0.0.320)&amp;lt;br/&amp;gt; [[10.0.4|v671350804]] (10.0.4.20)&amp;lt;br/&amp;gt; [[11.0.0|v738197864]] (11.0.0.360)&amp;lt;br/&amp;gt; [[12.0.0|v805307608]] (12.0.0.1240)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.1.0|v873463908]] (13.1.0.100)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[14.1.1|v940638228]] (14.1.1.20)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[15.0.1|v1006698596]] (15.0.1.100)&amp;lt;br/&amp;gt; [[16.0.0|v1073742904]] (16.0.0.1080)&amp;lt;br/&amp;gt; [[16.1.0|v1074790880]] (16.1.0.480)&amp;lt;br/&amp;gt; [[17.0.0|v1140851708]] (17.0.0.1020)&amp;lt;br/&amp;gt; [[18.1.0|v1209008288]] (18.1.0.160)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[20.2.0|v1344274732]] (20.2.0.300)&amp;lt;br/&amp;gt; [[20.3.0|v1345323088]] (20.3.0.80)&amp;lt;br/&amp;gt; [[20.4.0|v1346371784]] (20.4.0.200)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[21.1.0|v1410335000]] (21.1.0.280)&amp;lt;br/&amp;gt; [[21.2.0|v1411383436]] (21.2.0.140)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100)&amp;lt;br/&amp;gt; [[22.5.0|v1481638368]] (22.5.0.480) || BrowserDll || Mounted as &amp;quot;shareddata:/&amp;quot;. Contains various browser data: emojis, OSS NROs, &amp;quot;buildinfo/buildinfo.dat&amp;quot;, ...&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000804 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.1.1|v536871444]] (8.0.0.532)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.1.0|v605028512]] (9.1.0.160)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197804]] (11.0.0.300)&amp;lt;br/&amp;gt; [[12.0.0|v805307608]] (12.0.0.1240)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[13.1.0|v873463908]] (13.1.0.100)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851668]] (17.0.0.980)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[18.1.0|v1209008288]] (18.1.0.160)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.4.0|v1346371784]] (20.4.0.200)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100)&amp;lt;br/&amp;gt; [[22.5.0|v1481638368]] (22.5.0.480) || Help || HTML resources: Open-source licenses (&amp;quot;Intellectual Property Notices&amp;quot;) and seizure warnings(&amp;quot;Health &amp;amp; Safety Information&amp;quot;). The former is stored at FS &amp;quot;/legallines.htdocs/&amp;quot;&amp;lt;br/&amp;gt; while the latter is at &amp;quot;/safe.htdocs/&amp;quot;.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000805 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.1.0|v605028512]] (9.1.0.160)&amp;lt;br/&amp;gt; [[16.1.0|v1074790880]] (16.1.0.480) || SharedFont || Chinese and Korean dictionaries.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000806 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.2|v201457684]] (3.0.2.20)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[10.2.0|v673185832]] (10.2.0.40)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[11.0.1|v738264040]] (11.0.1.1000)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.0.1|v805371944]] (12.0.1.40)&amp;lt;br/&amp;gt; [[12.0.3|v805502996]] (12.0.3.20)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[14.1.1|v940638228]] (14.1.1.20)&amp;lt;br/&amp;gt; [[14.1.2|v940703804]] (14.1.2.60)&amp;lt;br/&amp;gt; [[14.1.2|v940708804]] (14.1.2.5060)&amp;lt;br/&amp;gt; [[14.1.2|v940709764]] (14.1.2.6020)&amp;lt;br/&amp;gt; [[14.1.2|v940711764]] (14.1.2.8020)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[15.0.1|v1006698596]] (15.0.1.100)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[16.0.1|v1073807420]] (16.0.1.60)&amp;lt;br/&amp;gt; [[16.0.2|v1073872936]] (16.0.2.40)&amp;lt;br/&amp;gt; [[16.0.3|v1073943452]] (16.0.3.5020)&amp;lt;br/&amp;gt; [[16.0.3|v1073944452]] (16.0.3.6020)&amp;lt;br/&amp;gt; [[16.1.0|v1074790880]] (16.1.0.480)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[17.0.0|v1140855708]] (17.0.0.5020)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[18.1.0|v1209008288]] (18.1.0.160)&amp;lt;br/&amp;gt; [[18.1.0|v1209013148]] (18.1.0.5020)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[19.0.1|v1275133992]] (19.0.1.40)&amp;lt;br/&amp;gt; [[19.0.1|v1275138972]] (19.0.1.5020)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[19.0.2|v1275199548]] (19.0.2.60)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || NgWord || Bad words.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000807 || [[1.0.0|v260]] (0.0.0.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[10.1.0|v672137336]] (10.1.0.120)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || SsidList || [[Hotspot List]].&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000808 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40) || Dictionary || European, English, and Japanese dictionaries.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000809 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[2.1.0|v196628]] (0.0.3.20)&amp;lt;br/&amp;gt; [[2.2.0|v196628]] (0.0.3.20)&amp;lt;br/&amp;gt; [[2.3.0|v262164]] (0.0.4.20)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[3.0.2|v201457684]] (3.0.2.20)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[4.0.1|v268501002]] (4.0.1.10)&amp;lt;br/&amp;gt; [[4.1.0|v269484082]] (4.1.0.50)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.0.1|v335609886]] (5.0.1.30)&amp;lt;br/&amp;gt; [[5.0.2|v335675432]] (5.0.2.40)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.0.1|v402718730]] (6.0.1.10)&amp;lt;br/&amp;gt; [[6.1.0|v403701850]] (6.1.0.90)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[7.0.1|v469827614]] (7.0.1.30)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.0.1|v536936528]] (8.0.1.80)&amp;lt;br/&amp;gt; [[8.1.0|v537919608]] (8.1.0.120)&amp;lt;br/&amp;gt; [[8.1.1|v537985054]] (8.1.1.30)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.0.1|v604045412]] (9.0.1.100)&amp;lt;br/&amp;gt; [[9.1.0|v6050285192]] (9.1.0.240)&amp;lt;br/&amp;gt; [[9.2.0|v606076948]] (9.2.0.20)&amp;lt;br/&amp;gt; [[10.0.0|v671089000]] (10.0.0.360)&amp;lt;br/&amp;gt; [[10.0.1|v671154196]] (10.0.1.20)&amp;lt;br/&amp;gt; [[10.0.2|v671219752]] (10.0.2.40)&amp;lt;br/&amp;gt; [[10.0.3|v671285268]] (10.0.3.20)&amp;lt;br/&amp;gt; [[10.0.4|v671350804]] (10.0.4.20)&amp;lt;br/&amp;gt; [[10.1.0|v672137336]] (10.1.0.120)&amp;lt;br/&amp;gt; [[10.1.1|v672202772]] (10.1.1.20)&amp;lt;br/&amp;gt; [[10.2.0|v673185852]] (10.2.0.60)&amp;lt;br/&amp;gt; [[11.0.0|v738197944]] (11.0.0.440)&amp;lt;br/&amp;gt; [[11.0.1|v738263060]] (11.0.1.20)&amp;lt;br/&amp;gt; [[12.0.0|v805308888]] (12.0.0.2520)&amp;lt;br/&amp;gt; [[12.0.1|v805371944]] (12.0.1.40)&amp;lt;br/&amp;gt; [[12.0.2|v805437460]] (12.0.2.20)&amp;lt;br/&amp;gt; [[12.0.3|v805502996]] (12.0.3.20)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[13.1.0|v873463968]] (13.1.0.160)&amp;lt;br/&amp;gt; [[13.2.0|v874512404]] (13.2.0.20)&amp;lt;br/&amp;gt; [[13.2.1|v874578000]] (13.2.1.80)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[14.1.0|v940572692]] (14.1.0.20)&amp;lt;br/&amp;gt; [[14.1.1|v940638228]] (14.1.1.20)&amp;lt;br/&amp;gt; [[14.1.2|v940703804]] (14.1.2.60)&amp;lt;br/&amp;gt; [[15.0.0|v1006634160]] (15.0.0.1200)&amp;lt;br/&amp;gt; [[15.0.1|v1006698596]] (15.0.1.100)&amp;lt;br/&amp;gt; [[16.0.0|v1073742904]] (16.0.0.1080)&amp;lt;br/&amp;gt; [[16.0.1|v1073807420]] (16.0.1.60)&amp;lt;br/&amp;gt; [[16.0.2|v1073872936]] (16.0.2.40)&amp;lt;br/&amp;gt; [[16.0.3|v1073938452]] (16.0.3.20)&amp;lt;br/&amp;gt; [[16.1.0|v1074790880]] (16.1.0.480)&amp;lt;br/&amp;gt; [[17.0.0|v1140851708]] (17.0.0.1020)&amp;lt;br/&amp;gt; [[17.0.1|v1140916284]] (17.0.1.60)&amp;lt;br/&amp;gt; [[18.0.0|v1207960692]] (18.0.0.1140)&amp;lt;br/&amp;gt; [[18.0.1|v1208025188]] (18.0.1.100)&amp;lt;br/&amp;gt; [[18.1.0|v1209008288]] (18.1.0.160)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[19.0.1|v1275134052]] (19.0.1.100)&amp;lt;br/&amp;gt; [[20.0.0|v1342179000]] (20.0.0.1720)&amp;lt;br/&amp;gt; [[20.0.1|v1342242836]] (20.0.1.20)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[20.1.1|v1343291412]] (20.1.1.20)&amp;lt;br/&amp;gt; [[20.1.5|v1343553696]] (20.1.5.160)&amp;lt;br/&amp;gt; [[20.2.0|v1344274732]] (20.2.0.300)&amp;lt;br/&amp;gt; [[20.3.0|v1345323088]] (20.3.0.80)&amp;lt;br/&amp;gt; [[20.4.0|v1346371784]] (20.4.0.200)&amp;lt;br/&amp;gt; [[20.5.0|v1347420260]] (20.5.0.100)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[21.0.1|v1409351720]] (21.0.1.40)&amp;lt;br/&amp;gt; [[21.1.0|v1410335000]] (21.1.0.280)&amp;lt;br/&amp;gt; [[21.2.0|v1411383436]] (21.2.0.140)&amp;lt;br/&amp;gt; [[19.0.2|v1275199548]] (19.0.2.60)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100)&amp;lt;br/&amp;gt; [[22.1.0|v1477443784]] (22.1.0.200)&amp;lt;br/&amp;gt; [[22.5.0|v1481638368]] (22.5.0.480) || SystemVersion || [[System Version Title]].&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000080A || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.1.1|v536871444]] (8.0.0.532)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197804]] (11.0.0.300)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || AvatarImage || Background and Character images for user avatars (RGBA format &amp;amp; Yaz0 compression).&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000080B || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.1.0|v403701850]] (6.1.0.90)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.1.1|v536871444]] (8.0.0.532)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.1.0|v605028512]] (9.1.0.160)&amp;lt;br/&amp;gt; [[11.0.0|v738197804]] (11.0.0.300)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[13.1.0|v873463908]] (13.1.0.100)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360) || LocalNews || Tutorial images and strings. Used for the offline news by the News applet.&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000080C || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.1.1|v536871444]] (8.0.0.532)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.1.0|v605028512]] (9.1.0.160)&amp;lt;br/&amp;gt; [[11.0.0|v738197804]] (11.0.0.300)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040) || Eula (Eura) || Accessed by [[NS_Services|NS]].&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000080D || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[10.2.0|v673185852]] (10.2.0.60)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640) || UrlBlackList ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000080E || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || TimeZoneBinary ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000080F || || CertStoreCruiser (BrowserCertStore) || Currently not present on retail devices.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000810 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[16.1.0|v1074790880]] (16.1.0.480)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || FontNintendoExtension ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000811 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || FontStandard ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000812 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || FontKorean ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000813 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || FontChineseTraditional ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000814 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[16.1.0|v1074790880]] (16.1.0.480)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || FontChineseSimple ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000815 || || FontBfcpx || Currently not present on retail devices.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000816 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt;  [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[2.1.0|v131162]] (0.0.2.90)&amp;lt;br/&amp;gt; [[2.2.0|v196628]] (0.0.3.20)&amp;lt;br/&amp;gt; [[2.3.0|v262164]] (0.0.4.20)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[3.0.2|v201457684]] (3.0.2.20)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[4.0.1|v268501002]] (4.0.1.10)&amp;lt;br/&amp;gt; [[4.1.0|v269484082]] (4.1.0.50)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.0.1|v335609886]] (5.0.1.30)&amp;lt;br/&amp;gt; [[5.0.2|v335675432]] (5.0.2.40)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.0.1|v402718730]] (6.0.1.10)&amp;lt;br/&amp;gt; [[6.1.0|v403701850]] (6.1.0.90)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[7.0.1|v469827614]] (7.0.1.30)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.0.1|v536936528]] (8.0.1.80)&amp;lt;br/&amp;gt; [[8.1.0|v537919608]] (8.1.0.120)&amp;lt;br/&amp;gt; [[8.1.1|v537985054]] (8.1.1.30)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.0.1|v604045412]] (9.0.1.100)&amp;lt;br/&amp;gt; [[9.1.0|v605028592]] (9.1.0.240)&amp;lt;br/&amp;gt; [[9.2.0|v606076948]] (9.2.0.20)&amp;lt;br/&amp;gt; [[10.0.0|v671089000]] (10.0.0.360)&amp;lt;br/&amp;gt; [[10.0.1|v671154196]] (10.0.1.20)&amp;lt;br/&amp;gt; [[10.0.2|v671219752]] (10.0.2.40)&amp;lt;br/&amp;gt; [[10.0.3|v671285268]] (10.0.3.20)&amp;lt;br/&amp;gt; [[10.0.4|v671350804]] (10.0.4.20)&amp;lt;br/&amp;gt; [[10.1.0|v672137336]] (10.1.0.120)&amp;lt;br/&amp;gt; [[10.1.1|v672202772]] (10.1.1.20)&amp;lt;br/&amp;gt; [[10.2.0|v673185852]] (10.2.0.60)&amp;lt;br/&amp;gt; [[11.0.0|v738197944]] (11.0.0.440)&amp;lt;br/&amp;gt; [[11.0.1|v738263060]] (11.0.1.20)&amp;lt;br/&amp;gt; [[11.0.1|v738264040]] (11.0.1.1000)&amp;lt;br/&amp;gt; [[12.0.0|v805308888]] (12.0.0.2520)&amp;lt;br/&amp;gt; [[12.0.1|v805371944]] (12.0.1.40)&amp;lt;br/&amp;gt; [[12.0.2|v805437460]] (12.0.2.20)&amp;lt;br/&amp;gt; [[12.0.3|v805502996]] (12.0.3.20)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[13.1.0|v873463968]] (13.1.0.160)&amp;lt;br/&amp;gt; [[13.2.0|v874512404]] (13.2.0.20)&amp;lt;br/&amp;gt; [[13.2.1|v874578000]] (13.2.1.80)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[14.1.0|v940572692]] (14.1.0.20)&amp;lt;br/&amp;gt; [[14.1.1|v940638228]] (14.1.1.20)&amp;lt;br/&amp;gt; [[14.1.2|v940703804]] (14.1.2.60)&amp;lt;br/&amp;gt; [[14.1.2|v940708804]] (14.1.2.5060)&amp;lt;br/&amp;gt; [[14.1.2|v940709764]] (14.1.2.6020)&amp;lt;br/&amp;gt; [[14.1.2|v940711764]] (14.1.2.8020)&amp;lt;br/&amp;gt; [[15.0.0|v1006634160]] (15.0.0.1200)&amp;lt;br/&amp;gt; [[15.0.1|v1006698596]] (15.0.1.100)&amp;lt;br/&amp;gt; [[16.0.0|v1073742904]] (16.0.0.1080)&amp;lt;br/&amp;gt; [[16.0.1|v1073807420]] (16.0.1.60)&amp;lt;br/&amp;gt; [[16.0.2|v1073872936]] (16.0.2.40)&amp;lt;br/&amp;gt; [[16.0.3|v1073938452]] (16.0.3.20)&amp;lt;br/&amp;gt; [[16.0.3|v1073943452]] (16.0.3.5020)&amp;lt;br/&amp;gt; [[16.0.3|v1073944452]] (16.0.3.6020)&amp;lt;br/&amp;gt; [[16.1.0|v1074790880]] (16.1.0.480)&amp;lt;br/&amp;gt; [[17.0.0|v1140851708]] (17.0.0.1020)&amp;lt;br/&amp;gt; [[17.0.0|v1140855708]] (17.0.0.5020)&amp;lt;br/&amp;gt; [[17.0.1|v1140916284]] (17.0.1.60)&amp;lt;br/&amp;gt; [[18.0.0|v1207960692]] (18.0.0.1140)&amp;lt;br/&amp;gt; [[18.0.1|v1208025188]] (18.0.1.100)&amp;lt;br/&amp;gt; [[18.1.0|v1209008288]] (18.1.0.160)&amp;lt;br/&amp;gt; [[18.1.0|v1209013148]] (18.1.0.5020)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[19.0.1|v1275134052]] (19.0.1.100)&amp;lt;br/&amp;gt; [[19.0.1|v1275138972]] (19.0.1.5020)&amp;lt;br/&amp;gt; [[20.0.0|v1342179000]] (20.0.0.1720)&amp;lt;br/&amp;gt; [[20.0.1|v1342242836]] (20.0.1.20)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[20.1.1|v1343291412]] (20.1.1.20)&amp;lt;br/&amp;gt; [[20.1.5|v1343553696]] (20.1.5.160)&amp;lt;br/&amp;gt; [[20.2.0|v1344274732]] (20.2.0.300)&amp;lt;br/&amp;gt; [[20.3.0|v1345323088]] (20.3.0.80)&amp;lt;br/&amp;gt; [[20.4.0|v1346371784]] (20.4.0.200)&amp;lt;br/&amp;gt; [[20.5.0|v1347420260]] (20.5.0.100)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[21.0.1|v1409351720]] (21.0.1.40)&amp;lt;br/&amp;gt; [[21.1.0|v1410335000]] (21.1.0.280)&amp;lt;br/&amp;gt; [[21.2.0|v1411383436]] (21.2.0.140)&amp;lt;br/&amp;gt; [[19.0.2|v1275199548]] (19.0.2.60)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100)&amp;lt;br/&amp;gt; [[22.1.0|v1477443784]] (22.1.0.200)&amp;lt;br/&amp;gt; [[22.5.0|v1481638368]] (22.5.0.480) || SystemUpdate || Contains the title-listing for the associated sysupdate in the [[NCA]]-type0 .cnmt.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000818 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[2.3.0|v131082]] (0.0.2.10)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[4.1.0|v269484082]] (4.1.0.50)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.0.1|v335609886]] (5.0.1.30)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.1.0|v403701850]] (6.1.0.90)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.1.0|v605028512]] (9.1.0.160)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[10.1.0|v672137336]] (10.1.0.120)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220))&amp;lt;br/&amp;gt; [[13.1.0|v873463948]] (13.1.0.140)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100)&amp;lt;br/&amp;gt; [[22.5.0|v1481638368]] (22.5.0.480) || FirmwareDebugSettings || [[System Settings|System config]].&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000819 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[2.1.0|v131082]] (0.0.2.10)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[3.0.2|v201457684]] (3.0.2.20)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[4.1.0|v269484082]] (4.1.0.50)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[7.0.1|v469827614]] (7.0.1.30)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.1.0|v537919608]] (8.1.0.120)&amp;lt;br/&amp;gt; [[8.1.1|v537919608]] (8.1.0.122)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.1.0|v605028512]] (9.1.0.160)&amp;lt;br/&amp;gt; [[9.2.0|v606076948]] (9.2.0.20)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[10.1.0|v672137336]] (10.1.0.120)&amp;lt;br/&amp;gt; [[10.2.0|v673185832]] (10.2.0.40)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[11.0.1|v738263060]] (11.0.1.20)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.0.2|v805437460]] (12.0.2.20)&amp;lt;br/&amp;gt; [[12.0.3|v805502996]] (12.0.3.20)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220))&amp;lt;br/&amp;gt; [[13.1.0|v873463948]] (13.1.0.140)&amp;lt;br/&amp;gt; [[13.2.1|v874578000]] (13.2.1.80)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[14.1.2|v940703804]] (14.1.2.60)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[16.0.3|v1073938452]] (16.0.3.20)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[18.1.0|v1209008288]] (18.1.0.160)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342179000]] (20.0.0.1720)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[21.2.0|v1411383436]] (21.2.0.140)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100)&amp;lt;br/&amp;gt; [[22.5.0|v1481638368]] (22.5.0.480) || BootImagePackage || Firmware Package A: Normal Firmware.&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000081A || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[2.1.0|v131082]] (0.0.2.10)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[3.0.2|v201457684]] (3.0.2.20)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[4.1.0|v269484082]] (4.1.0.50)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[7.0.1|v469827614]] (7.0.1.30)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.1.0|v537919608]] (8.1.0.120)&amp;lt;br/&amp;gt; [[8.1.1|v537919608]] (8.1.0.122)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.1.0|v605028512]] (9.1.0.160)&amp;lt;br/&amp;gt; [[9.2.0|v606076948]] (9.2.0.20)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[10.1.0|v672137336]] (10.1.0.120)&amp;lt;br/&amp;gt; [[10.2.0|v673185832]] (10.2.0.40)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[11.0.1|v738263060]] (11.0.1.20)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.0.2|v805437460]] (12.0.2.20)&amp;lt;br/&amp;gt; [[12.0.3|v805502996]] (12.0.3.20)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220))&amp;lt;br/&amp;gt; [[13.1.0|v873463948]] (13.1.0.140)&amp;lt;br/&amp;gt; [[13.2.1|v874578000]] (13.2.1.80)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[14.1.2|v940703804]] (14.1.2.60)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[16.0.3|v1073938452]] (16.0.3.20)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[18.1.0|v1209008288]] (18.1.0.160)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342179000]] (20.0.0.1720)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[21.2.0|v1411383436]] (21.2.0.140)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100)&amp;lt;br/&amp;gt; [[22.5.0|v1481638368]] (22.5.0.480) || BootImagePackageSafe || Firmware Package B: SafeMode Firmware. See [[Boot_Modes#Safe_Mode|Safe Mode]].&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000081B || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[2.1.0|v131082]] (0.0.2.10)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[3.0.2|v201457684]] (3.0.2.20)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[4.1.0|v269484082]] (4.1.0.50)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[7.0.1|v469827614]] (7.0.1.30)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.1.0|v537919608]] (8.1.0.120)&amp;lt;br/&amp;gt; [[8.1.1|v537919608]] (8.1.0.122)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.1.0|v605028512]] (9.1.0.160)&amp;lt;br/&amp;gt; [[9.2.0|v606076948]] (9.2.0.20)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[10.1.0|v672137336]] (10.1.0.120)&amp;lt;br/&amp;gt; [[10.2.0|v673185832]] (10.2.0.40)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[11.0.1|v738263060]] (11.0.1.20)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.0.2|v805437460]] (12.0.2.20)&amp;lt;br/&amp;gt; [[12.0.3|v805502996]] (12.0.3.20)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220))&amp;lt;br/&amp;gt; [[13.1.0|v873463948]] (13.1.0.140)&amp;lt;br/&amp;gt; [[13.2.1|v874578000]] (13.2.1.80)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[14.1.2|v940703804]] (14.1.2.60)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[16.0.3|v1073938452]] (16.0.3.20)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[18.1.0|v1209008288]] (18.1.0.160)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342179000]] (20.0.0.1720)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[21.2.0|v1411383436]] (21.2.0.140)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100)&amp;lt;br/&amp;gt; [[22.5.0|v1481638368]] (22.5.0.480) || BootImagePackageExFat || Firmware Package C: Normal Firmware (exFAT variant). Identical to 0100000000000819 with different FS sysmodule. Requires a device ID to download from CDN.&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000081C || [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[4.1.0|v269484082]] (4.1.0.50)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[7.0.1|v469827614]] (7.0.1.30)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.1.0|v537919608]] (8.1.0.120)&amp;lt;br/&amp;gt; [[8.1.1|v537919608]] (8.1.0.122)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.1.0|v605028512]] (9.1.0.160)&amp;lt;br/&amp;gt; [[9.2.0|v606076948]] (9.2.0.20)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[10.1.0|v672137336]] (10.1.0.120)&amp;lt;br/&amp;gt; [[10.2.0|v673185832]] (10.2.0.40)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[11.0.1|v738263060]] (11.0.1.20)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.0.2|v805437460]] (12.0.2.20)&amp;lt;br/&amp;gt; [[12.0.3|v805502996]] (12.0.3.20)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220))&amp;lt;br/&amp;gt; [[13.1.0|v873463948]] (13.1.0.140)&amp;lt;br/&amp;gt; [[13.2.1|v874578000]] (13.2.1.80)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[14.1.2|v940703804]] (14.1.2.60)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[16.0.3|v1073938452]] (16.0.3.20)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[18.1.0|v1209008288]] (18.1.0.160)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342179000]] (20.0.0.1720)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[21.2.0|v1411383436]] (21.2.0.140)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100)&amp;lt;br/&amp;gt; [[22.5.0|v1481638368]] (22.5.0.480) || [4.0.0+] BootImagePackageExFatSafe || Firmware Package D: SafeMode Firmware (exFAT variant). Identical to 010000000000081A with different FS sysmodule. Requires a device ID to download from CDN.&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000081D || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[10.1.0|v672137336]] (10.1.0.120)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || FatalMessage || Errdisp strings.&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000081E || [[2.0.0|v260]] (0.0.0.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.1.1|v536871444]] (8.0.0.532)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[11.0.0|v738197804]] (11.0.0.300)&amp;lt;br/&amp;gt; [[13.1.0|v873463908]] (13.1.0.100)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360) || [2.0.0+] ControllerIcon || Controller gfx/icon data + dummy file.&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000081F || [[2.0.0|v260]] (0.0.0.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.1.0|v605028512]] (9.1.0.160)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [2.0.0+] PlatformConfigIcosa || Icosa system config.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000820 || [[2.0.0|v260]] (0.0.0.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.1.0|v605028512]] (9.1.0.160)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [2.0.0+] PlatformConfigCopper || Copper system config.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000821 || [[2.0.0|v260]] (0.0.0.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[8.1.1|v536871444]] (8.0.0.532)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.1.0|v605028512]] (9.1.0.160)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [2.0.0+] PlatformConfigHoag || Hoag system config.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000822 || [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.2|v201457684]] (3.0.2.20)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.1.1|v536871444]] (8.0.0.532)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[10.0.2|v671219752]] (10.0.2.40)&amp;lt;br/&amp;gt; [[10.1.0|v672137336]] (10.1.0.120)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220))&amp;lt;br/&amp;gt; [[13.1.0|v873463948]] (13.1.0.140)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [3.0.0+] ControllerFirmware || Firmware binaries for peripherals (hardware within Joy-Cons/etc).&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000823 || [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[10.2.0|v673185832]] (10.2.0.40)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[11.0.1|v738264040]] (11.0.1.1000)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.0.1|v805371944]] (12.0.1.40)&amp;lt;br/&amp;gt; [[12.0.3|v805502996]] (12.0.3.20)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[14.1.1|v940638228]] (14.1.1.20)&amp;lt;br/&amp;gt; [[14.1.2|v940703804]] (14.1.2.60)&amp;lt;br/&amp;gt; [[14.1.2|v940708804]] (14.1.2.5060)&amp;lt;br/&amp;gt; [[14.1.2|v940709764]] (14.1.2.6020)&amp;lt;br/&amp;gt; [[14.1.2|v940711764]] (14.1.2.8020)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[15.0.1|v1006698596]] (15.0.1.100)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[16.0.1|v1073807420]] (16.0.1.60)&amp;lt;br/&amp;gt; [[16.0.2|v1073872936]] (16.0.2.40)&amp;lt;br/&amp;gt; [[16.0.3|v1073943452]] (16.0.3.5020)&amp;lt;br/&amp;gt; [[16.0.3|v1073944452]] (16.0.3.6020)&amp;lt;br/&amp;gt; [[16.1.0|v1074790880]] (16.1.0.480)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[17.0.0|v1140855708]] (17.0.0.5020)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[18.1.0|v1209008288]] (18.1.0.160)&amp;lt;br/&amp;gt; [[18.1.0|v1209013148]] (18.1.0.5020)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[19.0.1|v1275133992]] (19.0.1.40)&amp;lt;br/&amp;gt; [[19.0.1|v1275138972]] (19.0.1.5020)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[19.0.2|v1275199548]] (19.0.2.60)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [3.0.0+] NgWord2 || Contains version.dat and ac_*_nx files. All of the *_nx files stored under here are compressed with gzip.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000824 || [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.1.0|v605028512]] (9.1.0.160)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [5.0.0+] PlatformConfigIcosaMariko || IcosaMariko system config.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000825 || [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197804]] (11.0.0.300) || [5.0.0+] ApplicationBlackList || Used by [[NS_Services|NS]] for restricting application installation and updates.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000826 || [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.1.0|v403701850]] (6.1.0.90)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.1.0|v537919608]] (8.1.0.120)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.1.0|v605028512]] (9.1.0.160)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[10.1.0|v672137336]] (10.1.0.120)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[11.0.1|v738264040]] (11.0.1.1000)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.0.1|v805371944]] (12.0.1.40)&amp;lt;br/&amp;gt; [[12.0.3|v805502996]] (12.0.3.20)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[13.1.0|v873463908]] (13.1.0.100)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[14.1.1|v940638228]] (14.1.1.20)&amp;lt;br/&amp;gt; [[14.1.2|v940703804]] (14.1.2.60)&amp;lt;br/&amp;gt; [[14.1.2|v940708804]] (14.1.2.5060)&amp;lt;br/&amp;gt; [[14.1.2|v940709764]] (14.1.2.6020)&amp;lt;br/&amp;gt; [[14.1.2|v940711764]] (14.1.2.8020)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[15.0.1|v1006698596]] (15.0.1.100)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[16.0.1|v1073807420]] (16.0.1.60)&amp;lt;br/&amp;gt; [[16.0.2|v1073872936]] (16.0.2.40)&amp;lt;br/&amp;gt; [[16.0.3|v1073943452]] (16.0.3.5020)&amp;lt;br/&amp;gt; [[16.0.3|v1073944452]] (16.0.3.6020)&amp;lt;br/&amp;gt; [[16.1.0|v1074790880]] (16.1.0.480)&amp;lt;br/&amp;gt; [[17.0.0|v1140851668]] (17.0.0.980)&amp;lt;br/&amp;gt; [[17.0.0|v1140855708]] (17.0.0.5020)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[18.1.0|v1209008288]] (18.1.0.160)&amp;lt;br/&amp;gt; [[18.1.0|v1209013148]] (18.1.0.5020)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[19.0.1|v1275133992]] (19.0.1.40)&amp;lt;br/&amp;gt; [[19.0.1|v1275138972]] (19.0.1.5020)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[19.0.2|v1275199548]] (19.0.2.60)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [5.0.0+] RebootlessSystemUpdateVersion || Rebootless system update version file.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000827 || [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [5.1.0+] ContentActionTable || Used by [[AM_services|AM]].&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000828 || [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197804]] (11.0.0.300) || [8.0.0+] FunctionBlackList || Used for restricting specific features in applications.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000829 || || PlatformConfigCalcio || Calcio system config. Currently not present on retail devices.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000830 || [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.1.0|v605028512]] (9.1.0.160)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197904]] (11.0.0.400)&amp;lt;br/&amp;gt; [[12.0.0|v805308868]] (12.0.0.2500)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [9.0.0+] NgWordT || Bad words for China region (Tencent).&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000831 || [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [13.0.0+] PlatformConfigAula || Aula system config.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000832 || [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851648]] (17.0.0.960)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [13.0.0+] CradleFirmware || Firmware binaries for Aula&#039;s dock.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000835 || || [16.0.0+] ErrorMessageUtf8 || Currently not present on NX retail devices. Used by &amp;lt;code&amp;gt;nn::err::detail::MountErrorMessageSystemData&amp;lt;/code&amp;gt; when the input &amp;lt;code&amp;gt;nn::err::ErrorMessageDatabaseType&amp;lt;/code&amp;gt; is non-zero (retail NX [[Error_Applet|LibraryAppletError]] passes hard-coded value 0).&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000000859 || [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[20.2.0|v1344274732]] (20.2.0.300)&amp;lt;br/&amp;gt; [[20.3.0|v1345323088]] (20.3.0.80)&amp;lt;br/&amp;gt; [[20.4.0|v1346371784]] (20.4.0.200)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[21.1.0|v1410335000]] (21.1.0.280)&amp;lt;br/&amp;gt; [[21.2.0|v1411383436]] (21.2.0.140)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100)&amp;lt;br/&amp;gt; [[22.5.0|v1481638368]] (22.5.0.480) || [20.0.0+] ClientCertData || [22.5.0+] Contains &amp;quot;meta.json&amp;quot;, &amp;quot;eshop_hac_prod.p12&amp;quot; and &amp;quot;eshop_hac_urls.txt&amp;quot; ([20.0.0-22.1.0] contains an empty &amp;quot;meta.json&amp;quot;, web applets try to use this for constructing a SSL client certificate).&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000085C || [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [20.0.0+] GameCardConfigurationData ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= System Applets =&lt;br /&gt;
{| class=wikitable&lt;br /&gt;
! ProgramId || Versions || Description || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000001000 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[2.1.0|v131162]] (0.0.2.90)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.0.1|v335609886]] (5.0.1.30)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.0.1|v402718730]] (6.0.1.10)&amp;lt;br/&amp;gt; [[6.1.0|v403701850]] (6.1.0.90)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.0.1|v536936528]] (8.0.1.80)&amp;lt;br/&amp;gt; [[8.1.0|v537919608]] (8.1.0.120)&amp;lt;br/&amp;gt;[[8.1.1|v537919570]] (8.1.0.82)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.1.0|v605028512]] (9.1.0.160)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[10.1.0|v672137336]] (10.1.0.120)&amp;lt;br/&amp;gt; [[10.1.1|v672202772]] (10.1.1.20)&amp;lt;br/&amp;gt; [[11.0.0|v738197944]] (11.0.0.440)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[13.1.0|v873463908]] (13.1.0.100)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[16.1.0|v1074790860]] (16.1.0.460)&amp;lt;br/&amp;gt; [[17.0.0|v1140851668]] (17.0.0.980)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[18.1.0|v1209008288]] (18.1.0.160)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342179000]] (20.0.0.1720)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[20.1.5|v1343553676]] (20.1.5.140)&amp;lt;br/&amp;gt; [[20.2.0|v1344274732]] (20.2.0.300)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[21.1.0|v1410335000]] (21.1.0.280)&amp;lt;br/&amp;gt; [[21.2.0|v1411383436]] (21.2.0.140)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100)&amp;lt;br/&amp;gt; [[22.1.0|v1477443784]] (22.1.0.200)&amp;lt;br/&amp;gt; [[22.5.0|v1481638368]] (22.5.0.480) || qlaunch (SystemAppletMenu) || [[qlaunch]] system applet. Launched by [[NS_Services#LaunchSystemApplet|ns]].&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000001001 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.1.1|v536871444]] (8.0.0.532)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.1.0|v605028512]] (9.1.0.160)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197804]] (11.0.0.300)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[20.2.0|v1344274732]] (20.2.0.300)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100)&amp;lt;br/&amp;gt; [[22.5.0|v1481638368]] (22.5.0.480) || [[Auth_Applet|auth]] (LibraryAppletAuth)|| &lt;br /&gt;
|-&lt;br /&gt;
| 0100000000001002 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.1.1|v536871444]] (8.0.0.532)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.1.0|v605028512]] (9.1.0.160)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197804]] (11.0.0.300)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || cabinet (LibraryAppletCabinet) ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000001003 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.1.1|v536871464]] (8.0.0.552)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.1.0|v605028512]] (9.1.0.160)&amp;lt;br/&amp;gt; [[10.0.0|v671088960]] (10.0.0.320)&amp;lt;br/&amp;gt; [[10.1.0|v672137336]] (10.1.0.120)&amp;lt;br/&amp;gt; [[11.0.0|v738197804]] (11.0.0.300)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[13.1.0|v873463908]] (13.1.0.100)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.1.0|v1074790860]] (16.1.0.460)&amp;lt;br/&amp;gt; [[17.0.0|v1140851668]] (17.0.0.980)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [[Controller_Applet|controller]] (LibraryAppletController) || &lt;br /&gt;
|-&lt;br /&gt;
| 0100000000001004 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.1.1|v536871444]] (8.0.0.532)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.1.0|v605028512]] (9.1.0.160)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[10.2.0|v673185852]] (10.2.0.60)&amp;lt;br/&amp;gt; [[11.0.0|v738197804]] (11.0.0.300)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || dataErase (LibraryAppletDataErase) ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000001005 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.1.1|v536871444]] (8.0.0.532)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.1.0|v605028512]] (9.1.0.160)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197804]] (11.0.0.300)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851668]] (17.0.0.980)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[20.2.0|v1344274732]] (20.2.0.300)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100)&amp;lt;br/&amp;gt; [[22.5.0|v1481638368]] (22.5.0.480) || [[Error_Applet|error]] (LibraryAppletError) ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000001006 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.1.1|v536871444]] (8.0.0.532)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.1.0|v605028512]] (9.1.0.160)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197804]] (11.0.0.300)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.1.0|v1074790860]] (16.1.0.460)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[20.2.0|v1344274732]] (20.2.0.300)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || netConnect (LibraryAppletNetConnect) || &lt;br /&gt;
|-&lt;br /&gt;
| 0100000000001007 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.1.0|v403701850]] (6.1.0.90)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.1.1|v536871444]] (8.0.0.532)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.1.0|v605028512]] (9.1.0.160)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197804]] (11.0.0.300)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[13.1.0|v873463908]] (13.1.0.100)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[17.0.0|v1140851668]] (17.0.0.980)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[18.1.0|v1209008288]] (18.1.0.160)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[20.2.0|v1344274732]] (20.2.0.300)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100)&amp;lt;br/&amp;gt; [[22.5.0|v1481638368]] (22.5.0.480) || [[Profile Selector|playerSelect (LibraryAppletPlayerSelect)]] || &lt;br /&gt;
|-&lt;br /&gt;
| 0100000000001008 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[2.1.0|v131132]] (0.0.2.60)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.1.1|v536871444]] (8.0.0.532)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.1.0|v605028512]] (9.1.0.160)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[10.1.0|v672137336]] (10.1.0.120)&amp;lt;br/&amp;gt; [[11.0.0|v738197864]] (11.0.0.360)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[16.1.0|v1074790860]] (16.1.0.460)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100)&amp;lt;br/&amp;gt; [[22.5.0|v1481638368]] (22.5.0.480) || [[Software Keyboard|swkbd (LibraryAppletSwkbd)]] || &lt;br /&gt;
|-&lt;br /&gt;
| 0100000000001009 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.1.1|v536871444]] (8.0.0.532)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.1.0|v605028512]] (9.1.0.160)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[10.2.0|v673185852]] (10.2.0.60)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940) || miiEdit (LibraryAppletMiiEdit) || &lt;br /&gt;
|-&lt;br /&gt;
| 010000000000100A || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[2.1.0|v131162]] (0.0.2.90)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.1.0|v403701850]] (6.1.0.90)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.1.0|v537919608]] (8.1.0.120)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.0.1|v604045412]] (9.0.1.100)&amp;lt;br/&amp;gt; [[9.1.0|v605028592]] (9.1.0.240)&amp;lt;br/&amp;gt; [[10.0.0|v671088960]] (10.0.0.320)&amp;lt;br/&amp;gt; [[10.0.4|v671350804]] (10.0.4.20)&amp;lt;br/&amp;gt; [[11.0.0|v738197864]] (11.0.0.360)&amp;lt;br/&amp;gt; [[12.0.0|v805307608]] (12.0.0.1240)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.1.0|v873463908]] (13.1.0.100)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[14.1.1|v940638228]] (14.1.1.20)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[15.0.1|v1006698596]] (15.0.1.100)&amp;lt;br/&amp;gt; [[16.0.0|v1073742904]] (16.0.0.1080)&amp;lt;br/&amp;gt; [[16.1.0|v1074790860]] (16.1.0.460)&amp;lt;br/&amp;gt; [[17.0.0|v1140851708]] (17.0.0.1020)&amp;lt;br/&amp;gt; [[18.1.0|v1209008288]] (18.1.0.160)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[20.2.0|v1344274732]] (20.2.0.300)&amp;lt;br/&amp;gt; [[20.3.0|v1345323088]] (20.3.0.80)&amp;lt;br/&amp;gt; [[20.4.0|v1346371784]] (20.4.0.200)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[21.1.0|v1410335000]] (21.1.0.280)&amp;lt;br/&amp;gt; [[21.2.0|v1411383436]] (21.2.0.140)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || LibAppletWeb (LibraryAppletWeb) || [[Internet_Browser|WebApplet]]. [22.0.0+] Stubbed.&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000100B || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[2.1.0|v131162]] (0.0.2.90)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.1.0|v403701850]] (6.1.0.90)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.1.0|v537919608]] (8.1.0.120)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.0.1|v604045412]] (9.0.1.100)&amp;lt;br/&amp;gt; [[9.1.0|v605028592]] (9.1.0.240)&amp;lt;br/&amp;gt; [[10.0.0|v671088960]] (10.0.0.320)&amp;lt;br/&amp;gt; [[10.0.4|v671350804]] (10.0.4.20)&amp;lt;br/&amp;gt; [[11.0.0|v738197864]] (11.0.0.360)&amp;lt;br/&amp;gt; [[12.0.0|v805307608]] (12.0.0.1240)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.1.0|v873463908]] (13.1.0.100)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[14.1.1|v940638228]] (14.1.1.20)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[15.0.1|v1006698596]] (15.0.1.100)&amp;lt;br/&amp;gt; [[16.0.0|v1073742904]] (16.0.0.1080)&amp;lt;br/&amp;gt; [[16.1.0|v1074790860]] (16.1.0.460)&amp;lt;br/&amp;gt; [[17.0.0|v1140851708]] (17.0.0.1020)&amp;lt;br/&amp;gt; [[18.1.0|v1209008288]] (18.1.0.160)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[20.2.0|v1344274732]] (20.2.0.300)&amp;lt;br/&amp;gt; [[20.3.0|v1345323088]] (20.3.0.80)&amp;lt;br/&amp;gt; [[20.4.0|v1346371784]] (20.4.0.200)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[21.1.0|v1410335000]] (21.1.0.280)&amp;lt;br/&amp;gt; [[21.2.0|v1411383436]] (21.2.0.140)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || LibAppletShop (LibraryAppletShop) || [[Internet_Browser|ShopN]] applet. [22.0.0+] Stubbed.&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000100C || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.1.0|v403701850]] (6.1.0.90)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.1.1|v536871444]] (8.0.0.532)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.1.0|v605028512]] (9.1.0.160)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197804]] (11.0.0.300)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[13.1.0|v873463908]] (13.1.0.100)&amp;lt;br/&amp;gt; [[13.2.0|v874512404]] (13.2.0.20)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[16.1.0|v1074790860]] (16.1.0.460)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[20.2.0|v1344274732]] (20.2.0.300)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || overlayDisp (OverlayApplet) || ProgramId is loaded by [[NS_Services|ns]] from system-config-title.&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000100D || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.1.1|v536871444]] (8.0.0.532)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.1.0|v605028512]] (9.1.0.160)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197804]] (11.0.0.300)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[13.1.0|v873463908]] (13.1.0.100)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[16.1.0|v1074790860]] (16.1.0.460)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || [[Album_Applet|photoViewer (LibraryAppletPhotoViewer)]]&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000100E || || set (LibraryAppletSet) || Not present on retail devices.&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000100F || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[2.1.0|v131162]] (0.0.2.90)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.1.0|v403701850]] (6.1.0.90)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.1.0|v537919608]] (8.1.0.120)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.0.1|v604045412]] (9.0.1.100)&amp;lt;br/&amp;gt; [[9.1.0|v605028592]] (9.1.0.240)&amp;lt;br/&amp;gt; [[10.0.0|v671088960]] (10.0.0.320)&amp;lt;br/&amp;gt; [[10.0.4|v671350804]] (10.0.4.20)&amp;lt;br/&amp;gt; [[11.0.0|v738197864]] (11.0.0.360)&amp;lt;br/&amp;gt; [[12.0.0|v805307608]] (12.0.0.1240)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.1.0|v873463908]] (13.1.0.100)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[14.1.1|v940638228]] (14.1.1.20)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[15.0.1|v1006698596]] (15.0.1.100)&amp;lt;br/&amp;gt; [[16.0.0|v1073742904]] (16.0.0.1080)&amp;lt;br/&amp;gt; [[16.1.0|v1074790860]] (16.1.0.460)&amp;lt;br/&amp;gt; [[17.0.0|v1140851708]] (17.0.0.1020)&amp;lt;br/&amp;gt; [[18.1.0|v1209008288]] (18.1.0.160)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[20.2.0|v1344274732]] (20.2.0.300)&amp;lt;br/&amp;gt; [[20.3.0|v1345323088]] (20.3.0.80)&amp;lt;br/&amp;gt; [[20.4.0|v1346371784]] (20.4.0.200)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[21.1.0|v1410335000]] (21.1.0.280)&amp;lt;br/&amp;gt; [[21.2.0|v1411383436]] (21.2.0.140)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100)&amp;lt;br/&amp;gt; [[22.5.0|v1481638368]] (22.5.0.480) || LibAppletOff (LibraryAppletOfflineWeb) || [[Internet_Browser|Offline]] web-applet.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000001010 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[2.1.0|v131162]] (0.0.2.90)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.1.0|v403701850]] (6.1.0.90)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.1.0|v537919608]] (8.1.0.120)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.0.1|v604045412]] (9.0.1.100)&amp;lt;br/&amp;gt; [[9.1.0|v605028592]] (9.1.0.240)&amp;lt;br/&amp;gt; [[10.0.0|v671088960]] (10.0.0.320)&amp;lt;br/&amp;gt; [[10.0.4|v671350804]] (10.0.4.20)&amp;lt;br/&amp;gt; [[11.0.0|v738197864]] (11.0.0.360)&amp;lt;br/&amp;gt; [[12.0.0|v805307608]] (12.0.0.1240)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.1.0|v873463908]] (13.1.0.100)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[14.1.1|v940638228]] (14.1.1.20)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[15.0.1|v1006698596]] (15.0.1.100)&amp;lt;br/&amp;gt; [[16.0.0|v1073742904]] (16.0.0.1080)&amp;lt;br/&amp;gt; [[16.1.0|v1074790860]] (16.1.0.460)&amp;lt;br/&amp;gt; [[17.0.0|v1140851708]] (17.0.0.1020)&amp;lt;br/&amp;gt; [[18.1.0|v1209008288]] (18.1.0.160)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[20.2.0|v1344274732]] (20.2.0.300)&amp;lt;br/&amp;gt; [[20.3.0|v1345323088]] (20.3.0.80)&amp;lt;br/&amp;gt; [[20.4.0|v1346371784]] (20.4.0.200)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[21.1.0|v1410335000]] (21.1.0.280)&amp;lt;br/&amp;gt; [[21.2.0|v1411383436]] (21.2.0.140)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || LibAppletLns (LibraryAppletLoginShare) || [[Internet_Browser|Whitelisted]] applet. (LoginApplet+ShareApplet+LobbyApplet) [22.0.0+] Stubbed.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000001011 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[2.1.0|v131162]] (0.0.2.90)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[3.0.1|v201392178]] (3.0.1.50)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.1.0|v403701850]] (6.1.0.90)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.1.0|v537919608]] (8.1.0.120)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.0.1|v604045412]] (9.0.1.100)&amp;lt;br/&amp;gt; [[9.1.0|v605028592]] (9.1.0.240)&amp;lt;br/&amp;gt; [[10.0.0|v671088960]] (10.0.0.320)&amp;lt;br/&amp;gt; [[10.0.4|v671350804]] (10.0.4.20)&amp;lt;br/&amp;gt; [[11.0.0|v738197864]] (11.0.0.360)&amp;lt;br/&amp;gt; [[12.0.0|v805307608]] (12.0.0.1240)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.1.0|v873463908]] (13.1.0.100)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[14.1.1|v940638228]] (14.1.1.20)&amp;lt;br/&amp;gt; [[15.0.0|v1006634080]] (15.0.0.1120)&amp;lt;br/&amp;gt; [[15.0.1|v1006698596]] (15.0.1.100)&amp;lt;br/&amp;gt; [[16.0.0|v1073742904]] (16.0.0.1080)&amp;lt;br/&amp;gt; [[16.1.0|v1074790860]] (16.1.0.460)&amp;lt;br/&amp;gt; [[17.0.0|v1140851708]] (17.0.0.1020)&amp;lt;br/&amp;gt; [[18.1.0|v1209008288]] (18.1.0.160)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[20.2.0|v1344274732]] (20.2.0.300)&amp;lt;br/&amp;gt; [[20.3.0|v1345323088]] (20.3.0.80)&amp;lt;br/&amp;gt; [[20.4.0|v1346371784]] (20.4.0.200)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[21.1.0|v1410335000]] (21.1.0.280)&amp;lt;br/&amp;gt; [[21.2.0|v1411383436]] (21.2.0.140)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || LibAppletAuth (LibraryAppletWifiWebAuth) || [[Internet_Browser|WifiWebAuth]] applet. [22.0.0+] Stubbed.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000001012 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.1.1|v536871444]] (8.0.0.532)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.0.1|v604045412]] (9.0.1.100)&amp;lt;br/&amp;gt; [[9.1.0|v605028512]] (9.1.0.160)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197804]] (11.0.0.300)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[18.0.0|v1207960612]] (18.0.0.1060)&amp;lt;br/&amp;gt; [[18.1.0|v1209008288]] (18.1.0.160)&amp;lt;br/&amp;gt; [[19.0.0|v1275069496]] (19.0.0.1080)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[20.2.0|v1344274732]] (20.2.0.300)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || starter (DummyStarter) ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000001013 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[5.0.1|v335609886]] (5.0.1.30)&amp;lt;br/&amp;gt; [[5.0.2|v335675432]] (5.0.2.40)&amp;lt;br/&amp;gt; [[5.1.0|v336592976]] (5.1.0.80)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.1.1|v536871444]] (8.0.0.532)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.1.0|v605028512]] (9.1.0.160)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[10.1.0|v672137336]] (10.1.0.120)&amp;lt;br/&amp;gt; [[11.0.0|v738197924]] (11.0.0.420)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[13.1.0|v873463908]] (13.1.0.100)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[16.0.0|v1073742864]] (16.0.0.1040)&amp;lt;br/&amp;gt; [[16.1.0|v1074790860]] (16.1.0.460)&amp;lt;br/&amp;gt; [[18.1.0|v1209008288]] (18.1.0.160)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100)&amp;lt;br/&amp;gt; [[22.5.0|v1481638368]] (22.5.0.480) || [[MyPage_Applet|myPage (LibraryAppletMyPage)]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000001014 || || PlayReport || Not present on retail devices.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000001015 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[2.0.0|v65796]] (0.0.1.260)&amp;lt;br/&amp;gt; [[3.0.0|v201327002]] (3.0.0.410)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[5.0.0|v335544750]] (5.0.0.430)&amp;lt;br/&amp;gt; [[6.0.0|v402653544]] (6.0.0.360)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40)&amp;lt;br/&amp;gt; [[7.0.0|v469762248]] (7.0.0.200)&amp;lt;br/&amp;gt; [[8.0.0|v536871442]] (8.0.0.530)&amp;lt;br/&amp;gt; [[8.1.1|v536871444]] (8.0.0.532)&amp;lt;br/&amp;gt; [[9.0.0|v603980216]] (9.0.0.440)&amp;lt;br/&amp;gt; [[9.1.0|v605028512]] (9.1.0.160)&amp;lt;br/&amp;gt; [[10.0.0|v671088940]] (10.0.0.300)&amp;lt;br/&amp;gt; [[11.0.0|v738197804]] (11.0.0.300)&amp;lt;br/&amp;gt; [[12.1.0|v806355064]] (12.1.0.120)&amp;lt;br/&amp;gt; [[13.0.0|v872415452]] (13.0.0.220)&amp;lt;br/&amp;gt; [[14.0.0|v939525336]] (14.0.0.1240)&amp;lt;br/&amp;gt; [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100) || maintenance (MaintenanceMenu) || Initial applet displayed when booting into [[Recovery_Mode|recovery mode]]. Launched by [[NS_Services#LaunchSystemApplet|ns]].&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000001016 || || || This ProgramId is used by [[NS_Services|ns]] when a certain flag is non-zero, in multiple places including around code using the string &amp;quot;application_install&amp;quot;. The program itself doesn&#039;t seem to exist.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000001017 || || || This ProgramId is used by [5.0.0+] [[Applet_Manager_services|am]] for the &amp;quot;nn.am.SystemReportTask&amp;quot; thread. The program itself doesn&#039;t seem to exist.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000001018 || || || This ProgramId is used by [5.0.0+] [[NS_Services|ns]] when saving a SystemPlayReport with EventId &amp;quot;systemupdate_dl_throughput&amp;quot;. The program itself doesn&#039;t seem to exist.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000001019 || || || This ProgramId is used by [5.0.0+] [[NS_Services|ns]] when saving a SystemPlayReport with EventId &amp;quot;volume_update&amp;quot; or &amp;quot;output_target_update&amp;quot;. The program itself doesn&#039;t seem to exist.&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000101A || || gift (LibraryAppletGift) || Not present on retail devices.&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000101B || || DummyECApplet (LibraryAppletDummyShop) || Not present on retail devices.&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000101C || || userMigration (LibraryAppletUserMigration) || Not present on retail devices.&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000101D || || EncounterSys (LibraryAppletPreomiaSys) || Not present on retail devices.&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000101E || || || This ProgramId is used by [5.0.0+] [[NIM_services|nim]] when it accesses the [[Network#pearljam|pearljam]] server. The program itself doesn&#039;t seem to exist.&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000101F || || || This ProgramId is used by [6.0.0+] [[NIM_services|nim]] and [9.0.0+] [[Glue_services|glue]]. The program itself doesn&#039;t seem to exist.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000001020 || || story (LibraryAppletStory) || Not present on retail devices.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000001021 || || || This ProgramId is used by [6.0.0+] [[NS_Services|ns]] when saving a SystemPlayReport with EventId &amp;quot;systemupdate_pass&amp;quot;. The program itself doesn&#039;t seem to exist.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000001023 || || || This ProgramId is used by [5.0.0+] [[BCAT_services|bcat]] around code using the string &amp;quot;statistics&amp;quot;. The program itself doesn&#039;t seem to exist.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000001024 || || || This ProgramId is used by [5.0.0+] [[PSC_services|psc]] around code using the string &amp;quot;syslog&amp;quot;. The program itself doesn&#039;t seem to exist.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000001025 || || || This ProgramId is used by [6.0.0+] [[Applet_Manager_services|am]]. The program itself doesn&#039;t seem to exist.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000001026 || || || This ProgramId is used by [6.0.0+] [[OLSC_services|olsc]]. The program itself doesn&#039;t seem to exist.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000001027 || || || This ProgramId is used by [8.0.0+] [[Account_services|account]]. The program itself doesn&#039;t seem to exist.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000001028 || || || This ProgramId is used by [8.0.0+] [[NS_Services|ns]]. The program itself doesn&#039;t seem to exist.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000001029 || || || This ProgramId is used by [8.0.0+] [[Network_Interface_services|nifm]] around code using the string &amp;quot;request_count&amp;quot;. The program itself doesn&#039;t seem to exist.&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000102A || || || This ProgramId is used by [6.0.0+] [[Applet_Manager_services|am]]. The program itself doesn&#039;t seem to exist.&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000102B || || || This ProgramId is used by [9.0.0+] [[Glue_services|glue]]. The program itself doesn&#039;t seem to exist.&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000102C || || || This ProgramId is used by [9.0.0+] [[Applet_Manager_services|am]]. The program itself doesn&#039;t seem to exist.&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000102E || || || This ProgramId is used by [8.0.0+] [[Shared_Database_services|sdb]] around code using the string &amp;quot;blacklist&amp;quot;. The program itself doesn&#039;t seem to exist.&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000102F || || || This ProgramId is used by [8.0.0+] [[NS_Services|ns]] around code using the string &amp;quot;content_delivery&amp;quot;. The program itself doesn&#039;t seem to exist.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000001030 || || || This ProgramId is used by [8.0.0+] [[Parental_Control_services|pctl]] around code using the string &amp;quot;npns_create_token&amp;quot;. The program itself doesn&#039;t seem to exist.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000001031 || || || This ProgramId is used by [8.0.0+] [[NS_Services|ns]]. The program itself doesn&#039;t seem to exist.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000001032 || || || This ProgramId is used by [8.0.0+] [[Glue_services|glue]]. The program itself doesn&#039;t seem to exist.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000001033 || || || This ProgramId is used by [8.0.0+] [[NS_Services|ns]] and [8.0.0+] [[BCAT_services|bcat]] around code using the string &amp;quot;promotion&amp;quot;. The program itself doesn&#039;t seem to exist.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000001034 || || || This ProgramId is used by [9.0.0+] [[NGCT_services|ngct]] and [9.0.0+] [[BCAT_services|bcat]]. The program itself doesn&#039;t seem to exist.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000001037 || || || This ProgramId is used by [9.0.0+] [[NIM_services|nim]]. The program itself doesn&#039;t seem to exist.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000001038 || || sample (LibraryAppletSample) || Not present on retail devices.&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000103C || || || This ProgramId is used by [13.0.0+] [[BCAT_services|bcat]] around code using the string &amp;quot;mnpp&amp;quot;. The program itself doesn&#039;t seem to exist.&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000103D || || || This ProgramId is used by [13.0.0+] [[Sockets_services|bsdsocket]] around code using the string &amp;quot;setting&amp;quot;. The program itself doesn&#039;t seem to exist.&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000103E || || || This ProgramId is used by [13.1.0+] [[BCAT_services|bcat]] around code using the strings &amp;quot;recv_push_ntf_mission_completed&amp;quot; and &amp;quot;send_ovl_ntf_mission_completed&amp;quot;. The program itself doesn&#039;t seem to exist.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000001042 || [[22.0.0|v1476396108]] (22.0.0.1100)&amp;lt;br/&amp;gt; [[22.5.0|v1481638368]] (22.5.0.480) || [22.0.0+] [[Internet_Browser|systemWeb]] || This ProgramId is used by [16.0.0+] [[Applet_Manager_services|am]].&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000001043 || [[22.0.0|v1476396108]] (22.0.0.1100)&amp;lt;br/&amp;gt; [[22.5.0|v1481638368]] (22.5.0.480) || [22.0.0+] [[Internet_Browser|openWeb]] || This ProgramId is used by [16.0.0+] [[Applet_Manager_services|am]].&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000001048 || [[20.0.0|v1342178920]] (20.0.0.1640)&amp;lt;br/&amp;gt; [[20.1.0|v1343226216]] (20.1.0.360)&amp;lt;br/&amp;gt; [[20.2.0|v1344274732]] (20.2.0.300)&amp;lt;br/&amp;gt; [[21.0.0|v1409287084]] (21.0.0.940)&amp;lt;br/&amp;gt; [[22.0.0|v1476396108]] (22.0.0.1100)&amp;lt;br/&amp;gt; [[22.5.0|v1481638368]] (22.5.0.480) || [20.0.0+] [[Splay_Applet|splay]] || &lt;br /&gt;
|-&lt;br /&gt;
| 0100000000001FFF || || EndOceanProgramId || Placeholder for the last valid applet ID.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Development System Applets =&lt;br /&gt;
{| class=wikitable&lt;br /&gt;
! ProgramId || Versions || Description || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002000 || || A2BoardFunction ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002001 || || A3Wireless ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002002 || || C1LcdAndKey (LcdAndKey) || LCD/Keyboard testing.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002003 || || C2UsbHpmic (UsbAndHPMicTest) || USB and audio testing.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002004 || || C3Aging (Aging) || Graphics/Framerate testing.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002005 || || C4SixAxis (6axisTest) || Sixaxis (controller peripheral) testing.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002006 || || C5Wireless (AssembledWireless) || Wireless testing.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002007 || || C7FinalCheck (FinalCheck) ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000203F || || AutoCapture ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002040 || || DevMenuCommandSystem ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002041 || || recovery ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002042 || || DevMenuSystem ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002044 || || HB-TBIntegrationTest ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000204D || || BackupSaveData ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000204E || || A4BoardCalWriti (BoardCalWriting) || Writes calibration data to NAND.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002054 || || RepairSslCertificate ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002055 || || GameCardWriter ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002056 || || UsbPdTestTool ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002057 || || RepairDeletePctl ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002058 || || RepairBackup ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002059 || || RepairRestore ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000205A || || RepairAccountTransfer ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000205B || || RepairAutoNetworkUpdater ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000205C || || RefurbishReset ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000205D || || RepairAssistCup ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000205E || || RepairPairingCutter ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002064 || || DevMenu ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002065 || || DevMenuApp ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002066 || || GetGameCardAsicInfo ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002068 || || NfpDebugToolSystem ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002069 || || AlbumSynchronizer ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002071 || || SnapShotDumper || Used by [[NS_Services|NS]].&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002073 || || DevMenuSystemApp ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002099 || || DevOverlayDisp ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000209A || || NandVerifier ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000209B || || GpuCoreDumper || Used by [[AM_services|AM]].&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000209C || || TestApplication (TestApplicationLauncher) || Factory qlaunch replacement, used to launch other tests.&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000209E || || HelloWorld ||&lt;br /&gt;
|-&lt;br /&gt;
| 01000000000020A0 || || XcieWriter ||&lt;br /&gt;
|-&lt;br /&gt;
| 01000000000020A1 || || GpuOverrunNotifier ||&lt;br /&gt;
|-&lt;br /&gt;
| 01000000000020C8 || || NfpDebugTool ||&lt;br /&gt;
|-&lt;br /&gt;
| 01000000000020CA || || NoftWriter ||&lt;br /&gt;
|-&lt;br /&gt;
| 01000000000020D0 || || BcatSystemDebugTool ||&lt;br /&gt;
|-&lt;br /&gt;
| 01000000000020D1 || || DevSafeModeUpdater ||&lt;br /&gt;
|-&lt;br /&gt;
| 01000000000020D3 || || ControllerConnectionAnalyzer ||&lt;br /&gt;
|-&lt;br /&gt;
| 01000000000020D4 || || DevKitUpdater ||&lt;br /&gt;
|-&lt;br /&gt;
| 01000000000020D6 || || RepairTimeReviser ||&lt;br /&gt;
|-&lt;br /&gt;
| 01000000000020D7 || || RepairReinitializeFuelGauge ||&lt;br /&gt;
|-&lt;br /&gt;
| 01000000000020DA || || RepairAbortMigration ||&lt;br /&gt;
|-&lt;br /&gt;
| 01000000000020DC || || RepairShowDeviceId ||&lt;br /&gt;
|-&lt;br /&gt;
| 01000000000020DD || || RepairSetCycleCountReliability ||&lt;br /&gt;
|-&lt;br /&gt;
| 01000000000020E0 || || Interface ||&lt;br /&gt;
|-&lt;br /&gt;
| 01000000000020E1 || || AlbumDownloader ||&lt;br /&gt;
|-&lt;br /&gt;
| 01000000000020E3 || || FuelGaugeDumper ||&lt;br /&gt;
|-&lt;br /&gt;
| 01000000000020E4 || || UnsafeExtract ||&lt;br /&gt;
|-&lt;br /&gt;
| 01000000000020E5 || || UnsafeEngrave ||&lt;br /&gt;
|-&lt;br /&gt;
| 01000000000020EE || || BluetoothSettingTool ||&lt;br /&gt;
|-&lt;br /&gt;
| 01000000000020F0 || || ApplicationInstallerRomfs (devmenuapp_installer) || Launched by [[Boot2|boot2]].&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002100 || || DevMenuLotcheckDownloader ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002101 || || DevMenuCommand ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002102 || || ExportPartition ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002103 || || [[Factory Setup|SystemInitializer]] (SystemInitializ) ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002104 || || SystemUpdaterHostFs ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002105 || || WriteToStorage ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002106 || || [[Factory Setup|CalWriter]] (CalWriterManu) ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002107 || || SettingsManager ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002109 || || testBuildSystemIris ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000210A || || SystemUpdater ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000210B || || nvnflinger_util ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000210C || || ControllerFirmwareUpdater ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000210D || || testBuildSystemNintendoWare (Test) ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002110 || || TestSaveDataCreator ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002111 || || C9LcdSpker ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002114 || || RankTurn ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002116 || || BleTestTool ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000211A || || PreinstallAppWriter ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000211C || || ControllerSerialFlashTool ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000211D || || ControllerFlashWriter ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000211E || || C13Handling ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000211F || || HidTest ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002120 || || ControllerTestApp ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002121 || || HidInspectionTool ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002124 || || BatteryCyclesEditor ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002125 || || UsbFirmwareUpdater ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002126 || || PalmaSerialCodeTool ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002127 || || renderdoccmd ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002128 || || HidInspectionToolProd ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000212C || || ExhibitionMenu ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000212F || || ExhibitionSaveData ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002130 || || LuciaConverter ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002133 || || CalDumper ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002134 || || AnalogStickEvaluationTool ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000216A || || ButtonTest ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000216D || || ExhibitionSaveDataSnapshot || Unofficial name.&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000216E || || HandlingA ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002178 || || SecureStartupSettings || Unofficial name.&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000217A || || WirelessInterference ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000217D || || CradleFirmwareUpdater ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002184 || || HttpInstallSettings || Unofficial name.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002187 || || ExhibitionMovieAssetData || Unofficial name.&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000002191 || || ExhibitionPlayData || Unofficial name.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Debug System Modules =&lt;br /&gt;
{| class=wikitable&lt;br /&gt;
! ProgramId || Versions || Description || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000003002 || || DummyProcess ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000003003 || || DebugMonitor0 ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100000000003004 || || SystemHelloWorld ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Development System Modules =&lt;br /&gt;
{| class=wikitable&lt;br /&gt;
! ProgramId || Versions || Description || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000B120 || || nvdbgsvc || Launched by maintenance mode [[Boot2|boot2.manuBoot]], but not present in retail or [[Factory Setup|factory firmware]].&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000B123 || || acc:CORNX ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000B14A || || [[Manu Services|manu]] || Installed in [[Factory Setup|factory firmware]].&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000B14B || || ManuUsbLoopBack ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000B1B8 || || DevFwdbgHbPackage ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000B1B9 || || DevFwdbgUsbPackage ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000B1BA || || ProdFwdbgPackage ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000B22A || || scs ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000B22B || || ControllerFirmwareDebug ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000B23D || || dt0 ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000B240 || || htc ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Bdk System Modules =&lt;br /&gt;
{| class=wikitable&lt;br /&gt;
! ProgramId || Versions || Description || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000C600 || || BdkSample01 ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000C601 || || BdkSample02 ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000C602 || || BdkSample03 ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000C603 || || BdkSample04 ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= New Development System Modules =&lt;br /&gt;
{| class=wikitable&lt;br /&gt;
! ProgramId || Versions || Description || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000D609 || || dmnt.gen2 ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000D60A || || ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000D60B || || ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000D60C || || ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000D60D || || ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000D60E || || ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000D610 || || ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000D611 || || ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000D612 || || ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000D613 || || ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000D614 || || ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000D615 || || ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000D616 || || ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000D617 || || ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000D619 || || ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000D621 || || ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000D623 || || DevServer ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000D62F || || WlanControlDaemon ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000D633 || || ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000D640 || || htcnet ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000D65A || || netTcDev ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000D65B || || ||&lt;br /&gt;
|-&lt;br /&gt;
| 010000000000D65C || || ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= System Applications =&lt;br /&gt;
{| class=wikitable&lt;br /&gt;
! ProgramId || Versions || Description || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 01008BB00013C000 || [[1.0.0|v450]] (0.0.0.450)&amp;lt;br/&amp;gt; [[4.0.0|v268435656]] (4.0.0.200)&amp;lt;br/&amp;gt; [[6.2.0|v404750376]] (6.2.0.40) || Application ([[flog]]) || NES emulator.&lt;br /&gt;
|-&lt;br /&gt;
| 0100069000078000 || v0 || RetailInteractiveDisplayMenu (DevQuestMenu) || This program can be launched by [[qlaunch]], but is not normally installed on retail systems.&lt;br /&gt;
|-&lt;br /&gt;
| 010000B003486000 || || AudioUsbMicDebugTool ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100458001E04000 || || BcatTestApp01 ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100F910020F8000 || || BcatTestApp02 ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100B7D0020FC000 || || BcatTestApp03 ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100132002100000 || || BcatTestApp04 ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100935002116000 || || BcatTestApp05 ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100DA4002130000 || || BcatTestApp06 ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100B0F002104000 || || BcatTestApp07 ||&lt;br /&gt;
|-&lt;br /&gt;
| 010051E002132000 || || BcatTestApp08 ||&lt;br /&gt;
|-&lt;br /&gt;
| 01004CB0015C8000 || || BcatTestApp09 ||&lt;br /&gt;
|-&lt;br /&gt;
| 01009720015CA000 || || BcatTestApp10 ||&lt;br /&gt;
|-&lt;br /&gt;
| 01002F20015C6000 || || BcatTestApp11 ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100204001F90000 || || BcatTestApp12 ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100060001F92000 || || BcatTestApp13 ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100C26001F94000 || || BcatTestApp14 ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100462001F96000 || || BcatTestApp15 ||&lt;br /&gt;
|-&lt;br /&gt;
| 01005C6001F98000 || || BcatTestApp16 ||&lt;br /&gt;
|-&lt;br /&gt;
| 010070000E3C0000 || || EncounterUsr (LibraryAppletPreomiaUsr) ||&lt;br /&gt;
|-&lt;br /&gt;
| 010086000E49C000 || || EncounterUsrDummy (LibraryAppletPreomiaUsrDummy) ||&lt;br /&gt;
|-&lt;br /&gt;
| 0100810002D5A000 || || ShopMonitaringTool ||&lt;br /&gt;
|-&lt;br /&gt;
| 010023D002B98000 || || DeltaStress ||&lt;br /&gt;
|-&lt;br /&gt;
| 010099F00D810000 || || || This ProgramId is used by [[BCAT_services|bcat]]. The program itself doesn&#039;t seem to exist.&lt;br /&gt;
|-&lt;br /&gt;
| 0100E6C01163C000 || || || This ProgramId is used by [[OLSC_services|olsc]]. The program itself doesn&#039;t seem to exist.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Pre-release System Applets =&lt;br /&gt;
{| class=wikitable&lt;br /&gt;
! ProgramId || Versions || Description || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 1000000000000001 || || [[Factory Setup|SystemInitializer]] (SystemInitializ)  ||&lt;br /&gt;
|-&lt;br /&gt;
| 1000000000000004 || || [[Factory Setup|CalWriter]] (CalWriterManu) ||&lt;br /&gt;
|-&lt;br /&gt;
| 1000000000000005 || || DevMenuCommand ||&lt;br /&gt;
|-&lt;br /&gt;
| 1000000000000006 || || SettingsManager ||&lt;br /&gt;
|-&lt;br /&gt;
| 1000000000000007 || || DevMenu (debug)&amp;lt;br/&amp;gt;TestApplication (factory) ||&lt;br /&gt;
|-&lt;br /&gt;
| 100000000000000B || || SnapShotDumper ||&lt;br /&gt;
|-&lt;br /&gt;
| 100000000000000C || || SystemUpdater ||&lt;br /&gt;
|-&lt;br /&gt;
| 100000000000000E || || ControllerFirmwareUpdater ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Pre-release System Modules =&lt;br /&gt;
{| class=wikitable&lt;br /&gt;
! ProgramId || Versions || Description || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 1000000000000201 || || usb ||&lt;br /&gt;
|-&lt;br /&gt;
| 1000000000000202 || || tma ||&lt;br /&gt;
|-&lt;br /&gt;
| 1000000000000203 || || boot2 ||&lt;br /&gt;
|-&lt;br /&gt;
| 1000000000000204 || || settings ||&lt;br /&gt;
|-&lt;br /&gt;
| 1000000000000205 || || Bus ||&lt;br /&gt;
|-&lt;br /&gt;
| 1000000000000206 || || bluetooth ||&lt;br /&gt;
|-&lt;br /&gt;
| 1000000000000208 || || DebugMonitor0 ||&lt;br /&gt;
|-&lt;br /&gt;
| 1000000000000209 || || dmnt ||&lt;br /&gt;
|-&lt;br /&gt;
| 100000000000020B || || nifm ||&lt;br /&gt;
|-&lt;br /&gt;
| 100000000000020C || || ptm ||&lt;br /&gt;
|-&lt;br /&gt;
| 100000000000020E || || bsdsocket ||&lt;br /&gt;
|-&lt;br /&gt;
| 100000000000020F || || hid ||&lt;br /&gt;
|-&lt;br /&gt;
| 1000000000000210 || || audio ||&lt;br /&gt;
|-&lt;br /&gt;
| 1000000000000212 || || LogManager ||&lt;br /&gt;
|-&lt;br /&gt;
| 1000000000000213 || || wlan ||&lt;br /&gt;
|-&lt;br /&gt;
| 1000000000000214 || || cs ||&lt;br /&gt;
|-&lt;br /&gt;
| 1000000000000215 || || ldn ||&lt;br /&gt;
|-&lt;br /&gt;
| 1000000000000216 || || nvservices ||&lt;br /&gt;
|-&lt;br /&gt;
| 1000000000000217 || || pcv ||&lt;br /&gt;
|-&lt;br /&gt;
| 1000000000000218 || || ppc ||&lt;br /&gt;
|-&lt;br /&gt;
| 100000000000021A || || lbl0 ||&lt;br /&gt;
|-&lt;br /&gt;
| 100000000000021B || || nvnflinger ||&lt;br /&gt;
|-&lt;br /&gt;
| 100000000000021C || || pcie ||&lt;br /&gt;
|-&lt;br /&gt;
| 100000000000021D || || account ||&lt;br /&gt;
|-&lt;br /&gt;
| 100000000000021E || || ns ||&lt;br /&gt;
|-&lt;br /&gt;
| 100000000000021F || || nfc ||&lt;br /&gt;
|-&lt;br /&gt;
| 1000000000000220 || || psc ||&lt;br /&gt;
|-&lt;br /&gt;
| 1000000000000221 || || capsrv ||&lt;br /&gt;
|-&lt;br /&gt;
| 1000000000000222 || || am ||&lt;br /&gt;
|-&lt;br /&gt;
| 1000000000000223 || || ssl ||&lt;br /&gt;
|-&lt;br /&gt;
| 1000000000000224 || || nim ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= User Applications =&lt;br /&gt;
Nintendo Switch game and application programs follow a higher entropy ProgramId scheme than previous generation consoles. &amp;lt;br/&amp;gt; Refer to the [[Title_list/Games|Games List]] for more information.&lt;/div&gt;</summary>
		<author><name>Yellows8</name></author>
	</entry>
	<entry>
		<id>https://switchbrew.org/w/index.php?title=Switch_2:_Title_list&amp;diff=14926</id>
		<title>Switch 2: Title list</title>
		<link rel="alternate" type="text/html" href="https://switchbrew.org/w/index.php?title=Switch_2:_Title_list&amp;diff=14926"/>
		<updated>2026-08-06T15:22:22Z</updated>

		<summary type="html">&lt;p&gt;Yellows8: /* System Applets */ Sync with NX.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= System Modules =&lt;br /&gt;
{| class=wikitable&lt;br /&gt;
! ProgramId || Versions || Description || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000006 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 20.2.0|v1344304624]] (20.2.0.30192)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || [[USB_services|usb]] || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000008 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || [[Boot2|boot2]] (debug)&amp;lt;br/&amp;gt; [[Boot2|boot2.SafeMode]] (safe)&amp;lt;br/&amp;gt;  [[Boot2|boot2.FromHost]] (develop)&amp;lt;br/&amp;gt; [[Boot2|boot2.prodBoot]] (retail)&amp;lt;br/&amp;gt;[[Boot2|boot2.manuBoot]] (factory)&amp;lt;br/&amp;gt;[[Boot2|boot2.Manu1st]] (factory) || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000009 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 20.2.0|v1344304624]] (20.2.0.30192)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || [[Settings_services|settings]] || &lt;br /&gt;
|-&lt;br /&gt;
| 040000000000000A || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || [[Bus_services|Bus]] || &lt;br /&gt;
|-&lt;br /&gt;
| 040000000000000B || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.1|v1343321424]] (20.1.1.30032)&amp;lt;br/&amp;gt; [[Switch 2: 20.2.0|v1344304624]] (20.2.0.30192)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || [[Bluetooth_Driver_services|bluetooth.autog]] || &lt;br /&gt;
|-&lt;br /&gt;
| 040000000000000C || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 20.2.0|v1344304624]] (20.2.0.30192)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || [[BCAT_services|bcat]] || &lt;br /&gt;
|-&lt;br /&gt;
| 040000000000000E || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || [[Friend_services|friends]] || &lt;br /&gt;
|-&lt;br /&gt;
| 040000000000000F || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 20.2.0|v1344304624]] (20.2.0.30192)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || [[Network_Interface_services|nifm]] || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000010 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || [[PTM_services|ptm]] || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000012 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || [[Sockets_services|bsdsocket]] || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000013 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 20.4.0|v1346401916]] (20.4.0.30332)&amp;lt;br/&amp;gt; [[Switch 2: 22.1.0|v1477473756]] (22.1.0.30172)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || [[HID_services|hid]] || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000014 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 20.4.0|v1346401916]] (20.4.0.30332)&amp;lt;br/&amp;gt; [[Switch 2: 22.1.0|v1477473756]] (22.1.0.30172)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || [[Audio_services|audio]] || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000015 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || [[Log_services|LogManager]] (debug)&amp;lt;br/&amp;gt;[[Log_services|LogManager.Prod]] (retail) || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000016 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 20.5.0|v1347450282]] (20.5.0.30122)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || [[WLAN_services|wlan]] || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000018 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 20.2.0|v1344304624]] (20.2.0.30192)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || [[LDN_services|ldn]] || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000019 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || [[NV_services|nvservices]] || &lt;br /&gt;
|-&lt;br /&gt;
| 040000000000001A || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || [[PCV_services|pcv]] || &lt;br /&gt;
|-&lt;br /&gt;
| 040000000000001B || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || [[Capmtp_services|capmtp]] || &lt;br /&gt;
|-&lt;br /&gt;
| 040000000000001D || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || [[PCIe_services|pcie]] || &lt;br /&gt;
|-&lt;br /&gt;
| 040000000000001E || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 20.5.0|v1347450282]] (20.5.0.30122)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || [[Account_services|account]] || &lt;br /&gt;
|-&lt;br /&gt;
| 040000000000001F || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 20.2.0|v1344304624]] (20.2.0.30192)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || [[NS_Services|ns]] || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000020 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || [[NFC_services|nfc]] || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000021 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || [[PSC_services|psc]] || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000022 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || [[Capture_services|capsrv]] || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000023 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 20.2.0|v1344304624]] (20.2.0.30192)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || [[AM_services|am]] || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000024 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 20.2.0|v1344304624]] (20.2.0.30192)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || [[SSL_services|ssl]] || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000025 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 20.2.0|v1344304624]] (20.2.0.30192)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || [[NIM_services|nim]] || &lt;br /&gt;
|-&lt;br /&gt;
| 040000000000002B || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 20.2.0|v1344304624]] (20.2.0.30192)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || [[Error_Report_services|erpt]] || &lt;br /&gt;
|-&lt;br /&gt;
| 040000000000002E || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 20.4.0|v1346401916]] (20.4.0.30332)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || [[Parental_Control_services|pctl]] || &lt;br /&gt;
|-&lt;br /&gt;
| 040000000000002F || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 20.2.0|v1344304624]] (20.2.0.30192)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || [[NPNS_services|npns]] || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000030 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || [[Error_Upload_services|eupld]] || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000031 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 20.5.0|v1347450282]] (20.5.0.30122)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || [[Glue_services|glue]] || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000032 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 20.2.0|v1344304624]] (20.2.0.30192)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || eclct || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000033 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.1.0|v1477473756]] (22.1.0.30172)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || [[ETicket_services|es]] || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000034 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 20.1.5|v1343583688]] (20.1.5.30152)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || [[Fatal_services|fatal]] || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000035 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 20.2.0|v1344304624]] (20.2.0.30192)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || [[GRC_services|grc]] || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000036 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 20.2.0|v1344304624]] (20.2.0.30192)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || [[creport]] || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000037 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || [[RO_services|ro]] || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000039 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 20.2.0|v1344304624]] (20.2.0.30192)&amp;lt;br/&amp;gt; [[Switch 2: 22.1.0|v1477473756]] (22.1.0.30172) || [[Shared_Database_services|sdb]] || &lt;br /&gt;
|-&lt;br /&gt;
| 040000000000003A || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.1|v1343321424]] (20.1.1.30032)&amp;lt;br/&amp;gt; [[Switch 2: 20.2.0|v1344304624]] (20.2.0.30192)&amp;lt;br/&amp;gt; [[Switch 2: 22.1.0|v1477473756]] (22.1.0.30172)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || [[Migration_services|migration]] || &lt;br /&gt;
|-&lt;br /&gt;
| 040000000000003C || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || [[Jpegdec_services|jpegdec]] || &lt;br /&gt;
|-&lt;br /&gt;
| 040000000000003E || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 20.2.0|v1344304624]] (20.2.0.30192)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || [[OLSC_services|olsc]] || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000042 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || [[PGL_services|pgl]] || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000045 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 20.2.0|v1344304624]] (20.2.0.30192)&amp;lt;br/&amp;gt; [[Switch 2: 22.1.0|v1477473756]] (22.1.0.30172) || [[OMM_services|omm]] || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000046 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || [[Ethernet_services|eth]] || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000047 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || || &lt;br /&gt;
|-&lt;br /&gt;
| 040000000000004A || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 20.4.0|v1346401916]] (20.4.0.30332)&amp;lt;br/&amp;gt; [[Switch 2: 22.1.0|v1477473756]] (22.1.0.30172)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || || &lt;br /&gt;
|-&lt;br /&gt;
| 040000000000004D || [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 20.2.0|v1344304624]] (20.2.0.30192)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || [20.1.0+] || &lt;br /&gt;
|-&lt;br /&gt;
| 040000000000004F || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000050 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || ngc || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000052 || [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 20.4.0|v1346401916]] (20.4.0.30332)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || [20.1.0+] || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000062 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000063 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 20.2.0|v1344304624]] (20.2.0.30192)&amp;lt;br/&amp;gt; [[Switch 2: 22.1.0|v1477473756]] (22.1.0.30172) || || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000065 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000070 || [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 20.2.0|v1344304624]] (20.2.0.30192)&amp;lt;br/&amp;gt; [[Switch 2: 22.1.0|v1477473756]] (22.1.0.30172) || [20.1.0+] || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000071 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 20.2.0|v1344304624]] (20.2.0.30192)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000072 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 20.2.0|v1344304624]] (20.2.0.30192)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000080 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000081 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 20.2.0|v1344304624]] (20.2.0.30192)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000083 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 20.2.0|v1344304624]] (20.2.0.30192)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000084 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 20.2.0|v1344304624]] (20.2.0.30192)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000088 || [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || [20.1.0+] || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000089 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 20.2.0|v1344304624]] (20.2.0.30192)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || || &lt;br /&gt;
|-&lt;br /&gt;
| 040000000000008D || [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || [20.1.0+] || &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= System Data Archives =&lt;br /&gt;
{| class=wikitable&lt;br /&gt;
! ProgramId || Versions || Description || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000800 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || [[SSL_services#CertStore|CertStore]] || Same as NX.&lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000802 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || MiiModel || Same as NX.&lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000803 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257898]] (20.1.0.32042)&amp;lt;br/&amp;gt; [[Switch 2: 20.4.0|v1346401916]] (20.4.0.30332)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || [[Internet_Browser#BrowserDll|BrowserDll]] || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000804 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257748]] (20.1.0.31892)&amp;lt;br/&amp;gt; [[Switch 2: 20.4.0|v1346401916]] (20.4.0.30332)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || Help || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000806 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || NgWord || Same as NX. This has [[NCM_services#ContentMetaAttributes|ContentMetaAttributes]] = Rebootless.&lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000807 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || [[Hotspot_List|SsidList]] || Same as NX. This has [[NCM_services#ContentMetaAttributes|ContentMetaAttributes]] = Rebootless.&lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000808 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1342209022]] (20.0.0.31742)&amp;lt;br/&amp;gt; [[Switch 2: 21.0.0|v1409316656]] (21.0.0.30512)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || Dictionary || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000809 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.1|v1343321424]] (20.1.1.30032)&amp;lt;br/&amp;gt; [[Switch 2: 20.5.0|v1347450282]] (20.5.0.30122)&amp;lt;br/&amp;gt; [[Switch 2: 22.1.0|v1477473756]] (22.1.0.30172)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || [[System_Version_Title|SystemVersion]] || [20.1.1+] The digest file is no longer present.&lt;br /&gt;
|-&lt;br /&gt;
| 040000000000080A || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || AvatarImage || Now just contains &amp;quot;DatabaseInfo.byml.zs&amp;quot; and PNGs in directories &amp;quot;512x512&amp;quot;/&amp;quot;Ocean512x512&amp;quot;.&lt;br /&gt;
|-&lt;br /&gt;
| 040000000000080C || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257808]] (20.1.0.31952) || Eula || &lt;br /&gt;
|-&lt;br /&gt;
| 040000000000080D || [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || [21.0.0+] UrlBlackList || Same as NX.&lt;br /&gt;
|-&lt;br /&gt;
| 040000000000080E || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || TimeZoneBinary || Same as NX.&lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000810 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || FontNintendoExtension || Same as NX except &amp;quot;nintendo_ext2_003.bfttf&amp;quot; was removed.&lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000811 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || FontStandard || Same as NX.&lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000812 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || FontKorean || Same as NX.&lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000813 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || FontChineseTraditional || Same as NX.&lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000814 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || FontChineseSimple || Same as NX.&lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000816 || [[Switch 2: 19.0.0|v1275070438]] (19.0.0.2022)&amp;lt;br/&amp;gt; [[Switch 2: 20.1.1|v1343321424]] (20.1.1.30032)&amp;lt;br/&amp;gt; [[Switch 2: 20.1.5|v1343583688]] (20.1.5.30152)&amp;lt;br/&amp;gt; [[Switch 2: 20.2.0|v1344304624]] (20.2.0.30192)&amp;lt;br/&amp;gt; [[Switch 2: 20.3.0|v1345353070]] (20.3.0.30062)&amp;lt;br/&amp;gt; [[Switch 2: 20.4.0|v1346401921]] (20.4.0.30337)&amp;lt;br/&amp;gt; [[Switch 2: 20.5.0|v1347450282]] (20.5.0.30122)&amp;lt;br/&amp;gt; [[Switch 2: 22.1.0|v1477473756]] (22.1.0.30172)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || SystemUpdate || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000818 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || [[Switch 2: System_Settings|FirmwareDebugSettings]] || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000819 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 20.4.0|v1346401916]] (20.4.0.30332)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || BootImagePackage || &lt;br /&gt;
|-&lt;br /&gt;
| 040000000000081B || [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 20.4.0|v1346401916]] (20.4.0.30332)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || [20.1.0+] BootImagePackageExFat || &lt;br /&gt;
|-&lt;br /&gt;
| 040000000000081D || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || FatalMessage || Compared to NX, &amp;quot;/{lang}/GeneralMessage&amp;quot; were updated, and &amp;quot;zh-CN/&amp;quot; + &amp;quot;zh-TW/&amp;quot; were removed.&lt;br /&gt;
|-&lt;br /&gt;
| 040000000000081E || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.0.0|v1342209022]] (20.0.0.31742) || ControllerIcon || Now just contains &amp;quot;Footer/controllerIcon.bntx&amp;quot; and &amp;quot;Footer/info.dat&amp;quot;.&lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000822 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.1.0|v1477473756]] (22.1.0.30172) || [[HID_services#Firmware_Update|ControllerFirmware]] || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000823 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || NgWord2 || Same as NX. This has [[NCM_services#ContentMetaAttributes|ContentMetaAttributes]] = Rebootless.&lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000826 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257748]] (20.1.0.31892)&amp;lt;br/&amp;gt; [[Switch 2: 20.4.0|v1346401916]] (20.4.0.30332)&amp;lt;br/&amp;gt; [[Switch 2: 21.0.0|v1409316656]] (21.0.0.30512) || RebootlessSystemUpdateVersion || Version fields were reset to starting with value 1. This has [[NCM_services#ContentMetaAttributes|ContentMetaAttributes]] = Rebootless.&lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000827 || [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102))&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || [20.1.0+] ContentActionTable || Same as NX. This has [[NCM_services#ContentMetaAttributes|ContentMetaAttributes]] = Rebootless.&lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000828 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257938]] (20.1.0.32082)&amp;lt;br/&amp;gt; [[Switch 2: 20.4.0|v1346401916]] (20.4.0.30332)&amp;lt;br/&amp;gt; [[Switch 2: 21.0.0|v1409316656]] (21.0.0.30512) || [[#Shared_Database_services#FunctionBlackList|FunctionBlackList]] || This has [[NCM_services#ContentMetaAttributes|ContentMetaAttributes]] = Rebootless.&lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000832 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || CradleFirmware || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000834 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || || Additional [[Switch 2: System_Settings|system-settings]].&lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000835 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257928]] (20.1.0.32072)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || ErrorMessageUtf8 || This has [[NCM_services#ContentMetaAttributes|ContentMetaAttributes]] = Rebootless.&lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000836 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 20.2.0|v1344304624]] (20.2.0.30192)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || || Contains data for the wifi/bluetooth controller, including firmware.&lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000837 || [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 20.4.0|v1346401916]] (20.4.0.30332)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || [20.1.0+] || This is a SystemProgram, so this likely contains the [[Switch 2: Compatibility Mode|compat-modules]].&lt;br /&gt;
|-&lt;br /&gt;
| 040000000000083A || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || || Contains &amp;quot;nintendo_udsg-r_std_004.bfttf&amp;quot;.&lt;br /&gt;
|-&lt;br /&gt;
| 040000000000083B || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || || Contains &amp;quot;nintendo_udsg-db_std_004.bfttf&amp;quot;.&lt;br /&gt;
|-&lt;br /&gt;
| 040000000000083C || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || || Contains &amp;quot;nintendo_udsg-r_ko_004.bfttf&amp;quot;.&lt;br /&gt;
|-&lt;br /&gt;
| 040000000000083D || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || || Contains &amp;quot;nintendo_udsg-db_ko_004.bfttf&amp;quot;.&lt;br /&gt;
|-&lt;br /&gt;
| 040000000000083E || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || || Contains &amp;quot;nintendo_udsg-r_zh-tw_004.bfttf&amp;quot;.&lt;br /&gt;
|-&lt;br /&gt;
| 040000000000083F || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || || Contains &amp;quot;nintendo_udsg-db_zh-tw_004.bfttf&amp;quot;.&lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000840 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || || Contains &amp;quot;nintendo_udsg-r_ext_zh-cn_004.bfttf&amp;quot; and &amp;quot;nintendo_udsg-r_org_zh-cn_004.bfttf&amp;quot;.&lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000841 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || || Contains &amp;quot;nintendo_udsg-db_ext_zh-cn_004.bfttf&amp;quot; and &amp;quot;nintendo_udsg-db_org_zh-cn_004.bfttf&amp;quot;.&lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000842 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || || Contains &amp;quot;nintendo_ext_004.bfttf&amp;quot;.&lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000843 || [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 20.4.0|v1346401916]] (20.4.0.30332)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || [20.1.0+] || This is a SystemProgram, so this likely contains the [[Switch 2: Compatibility Mode|compat-modules]].&lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000844 || [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || [20.1.0+] || Contains data for face detection.&lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000846 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || || [20.1.0+] Contains an empty &amp;quot;Dummy&amp;quot; ([19.0.0] contains 0x3C-byte files: &amp;quot;WrappedKey0Dev.bin&amp;quot;, &amp;quot;WrappedKey0End.bin&amp;quot;, &amp;quot;WrappedKey0EndQuest.bin&amp;quot;).&lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000847 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.0.0|v1342209022]] (20.0.0.31742) || || Contains &amp;quot;MiiBody.dat&amp;quot; and shaders.&lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000848 || [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 20.5.0|v1347450282]] (20.5.0.30122)&amp;lt;br/&amp;gt; [[Switch 2: 22.1.0|v1477473756]] (22.1.0.30172)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || [20.1.0+] [[Switch 2: Compatibility Mode|ApplicationCompatibilityInfo]] || This has [[NCM_services#ContentMetaAttributes|ContentMetaAttributes]] = Rebootless.&lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000849 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || || This appears to be MiiModel updated for Ounce (similar filenames except with &amp;quot;NX&amp;quot; -&amp;gt; &amp;quot;Ounce&amp;quot;, etc).&lt;br /&gt;
|-&lt;br /&gt;
| 040000000000084A || [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || [20.1.0+] || Contains ja-JP voice data.&lt;br /&gt;
|-&lt;br /&gt;
| 040000000000084B || [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || [20.1.0+] || Contains en-US voice data.&lt;br /&gt;
|-&lt;br /&gt;
| 040000000000084C || [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || [20.1.0+] || Contains fr-FR voice data.&lt;br /&gt;
|-&lt;br /&gt;
| 040000000000084D || [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || [20.1.0+] || Contains de-DE voice data.&lt;br /&gt;
|-&lt;br /&gt;
| 040000000000084E || [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || [20.1.0+] || Only on FirmwareVariationId 0xC. This has [[NCM_services#ContentMetaAttributes|ContentMetaAttributes]] value 0x10.&lt;br /&gt;
|-&lt;br /&gt;
| 040000000000084F || [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || [20.1.0+] || Only on FirmwareVariationId 0xC. This has [[NCM_services#ContentMetaAttributes|ContentMetaAttributes]] value 0x10.&lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000850 || [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || [20.1.0+] || Only on FirmwareVariationId 0xC. This has [[NCM_services#ContentMetaAttributes|ContentMetaAttributes]] value 0x10.&lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000851 || [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || [20.1.0+] || Only on FirmwareVariationId 0xC. This has [[NCM_services#ContentMetaAttributes|ContentMetaAttributes]] value 0x10.&lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000852 || [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || [20.1.0+] || Only on FirmwareVariationId 0xC. This has [[NCM_services#ContentMetaAttributes|ContentMetaAttributes]] value 0x10.&lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000853 || [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || [20.1.0+] || Contains en-GB voice data.&lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000854 || [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || [20.1.0+] || Only on FirmwareVariationId 0xC. This has [[NCM_services#ContentMetaAttributes|ContentMetaAttributes]] value 0x10.&lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000855 || [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || [20.1.0+] || Contains es-MX voice data.&lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000858 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || || Same as NgWord2. This has [[NCM_services#ContentMetaAttributes|ContentMetaAttributes]] = Rebootless.&lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000859 || [[Switch 2: 20.1.0|v1343257748]] (20.1.0.31892)&amp;lt;br/&amp;gt; [[Switch 2: 20.5.0|v1347450282]] (20.5.0.30122)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || [20.1.0+] ClientCertData || Compared to NX, &amp;quot;meta.json&amp;quot; was filled in, and &amp;quot;eshop_p01_prod.p12&amp;quot; + &amp;quot;eshop_p01_urls.txt&amp;quot; were added (latter contains a single URL whitelist line).&lt;br /&gt;
|-&lt;br /&gt;
| 040000000000085A || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002) || || Contains &amp;quot;ProductLogo.bin&amp;quot; and &amp;quot;ProductLogoMeta.bin&amp;quot;. This is the raw image data for the logo displayed during system-boot.&lt;br /&gt;
|-&lt;br /&gt;
| 040000000000085B || [[Switch 2: 20.1.0|v1343257898]] (20.1.0.32042)&amp;lt;br/&amp;gt; [[Switch 2: 20.5.0|v1347450282]] (20.5.0.30122)&amp;lt;br/&amp;gt; [[Switch 2: 22.1.0|v1477473756]] (22.1.0.30172)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || [20.1.0+] || Contains &amp;quot;/{lang}/gaiji.lex&amp;quot; and &amp;quot;/{lang}/userdict.csv&amp;quot;. [22.5.0+] This has [[NCM_services#ContentMetaAttributes|ContentMetaAttributes]] = Rebootless.&lt;br /&gt;
|-&lt;br /&gt;
| 040000000000085C || [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || [20.1.0+] GameCardConfigurationData || Contains &amp;quot;GameCardConfigurationData.bin&amp;quot;, which was updated compared to NX. This has [[NCM_services#ContentMetaAttributes|ContentMetaAttributes]] = Rebootless.&lt;br /&gt;
|-&lt;br /&gt;
| 040000000000085D || [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || [21.0.0+] BrowserCoreDll || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000000860 || [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || [21.0.0+] CameraFirmware || Contains &amp;quot;NintendoSwitch2CameraFirmware.bin&amp;quot;, Squashfs image for the Linux camera firmware.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= System Applets =&lt;br /&gt;
{| class=wikitable&lt;br /&gt;
! ProgramId || Versions || Description || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0400000000001000 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.1|v1343321424]] (20.1.1.30032)&amp;lt;br/&amp;gt; [[Switch 2: 20.4.0|v1346401916]] (20.4.0.30332)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || qlaunch (SystemAppletMenu) || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000001001 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257908]] (20.1.0.32052)&amp;lt;br/&amp;gt; [[Switch 2: 20.2.0|v1344304624]] (20.2.0.30192)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || [[Auth_Applet|auth]] (LibraryAppletAuth) || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000001003 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257908]] (20.1.0.32052)&amp;lt;br/&amp;gt; [[Switch 2: 20.2.0|v1344304624]] (20.2.0.30192)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || [[Controller_Applet|controller]] (LibraryAppletController) || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000001005 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257908]] (20.1.0.32052)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || [[Error_Applet|error]] (LibraryAppletError) || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000001007 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257908]] (20.1.0.32052)&amp;lt;br/&amp;gt; [[Switch 2: 20.2.0|v1344304624]] (20.2.0.30192)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || [[Profile Selector|playerSelect (LibraryAppletPlayerSelect)]] || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000001008 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257908]] (20.1.0.32052)&amp;lt;br/&amp;gt; [[Switch 2: 20.2.0|v1344304624]] (20.2.0.30192)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || [[Software Keyboard|swkbd (LibraryAppletSwkbd)]] || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000001009 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257908]] (20.1.0.32052)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || miiEdit (LibraryAppletMiiEdit) || &lt;br /&gt;
|-&lt;br /&gt;
| 040000000000100C || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257928]] (20.1.0.32072)&amp;lt;br/&amp;gt; [[Switch 2: 20.2.0|v1344304624]] (20.2.0.30192)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || overlayDisp (OverlayApplet)  || This is also used for cmenu.&lt;br /&gt;
|-&lt;br /&gt;
| 040000000000100D || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257908]] (20.1.0.32052)&amp;lt;br/&amp;gt; [[Switch 2: 20.2.0|v1344304624]] (20.2.0.30192)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || [[Album_Applet|photoViewer (LibraryAppletPhotoViewer)]] || &lt;br /&gt;
|-&lt;br /&gt;
| 040000000000100E || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257948]] (20.1.0.32092)&amp;lt;br/&amp;gt; [[Switch 2: 20.2.0|v1344304624]] (20.2.0.30192)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || set (LibraryAppletSet) || &lt;br /&gt;
|-&lt;br /&gt;
| 040000000000100F || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257898]] (20.1.0.32042)&amp;lt;br/&amp;gt; [[Switch 2: 20.4.0|v1346401916]] (20.4.0.30332)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000001013 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257908]] (20.1.0.32052)&amp;lt;br/&amp;gt; [[Switch 2: 20.2.0|v1344304624]] (20.2.0.30192)&amp;lt;br/&amp;gt; [[Switch 2: 22.1.0|v1477473756]] (22.1.0.30172)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || [[MyPage_Applet|myPage (LibraryAppletMyPage)]] || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000001015 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257908]] (20.1.0.32052)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || maintenance (MaintenanceMenu) || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000001041 || [[Switch 2: 20.1.0|v1343257908]] (20.1.0.32052)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || [20.1.0+] || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000001042 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257898]] (20.1.0.32042)&amp;lt;br/&amp;gt; [[Switch 2: 20.4.0|v1346401916]] (20.4.0.30332)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || [[Internet_Browser|systemWeb]] || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000001043 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257898]] (20.1.0.32042)&amp;lt;br/&amp;gt; [[Switch 2: 20.4.0|v1346401916]] (20.4.0.30332)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || [[Internet_Browser|openWeb]] || &lt;br /&gt;
|-&lt;br /&gt;
| 0400000000001045 || [[Switch 2: 20.1.1|v1343321424]] (20.1.1.30032)&amp;lt;br/&amp;gt; [[Switch 2: 20.2.0|v1344304624]] (20.2.0.30192)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || [20.1.1+] || Only on FirmwareVariationId 0xB.&lt;br /&gt;
|-&lt;br /&gt;
| 0400000000001048 || [[Switch 2: 20.1.0|v1343257908]] (20.1.0.32052)&amp;lt;br/&amp;gt; [[Switch 2: 20.2.0|v1344304624]] (20.2.0.30192)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || [20.1.0+] splay || Only on FirmwareVariationId 0xB.&lt;br /&gt;
|-&lt;br /&gt;
| 040000000000104B || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257898]] (20.1.0.32042)&amp;lt;br/&amp;gt; [[Switch 2: 20.4.0|v1346401916]] (20.4.0.30332)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || || Only on FirmwareVariationId 0xB.&lt;br /&gt;
|-&lt;br /&gt;
| 040000000000104C || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 20.4.0|v1346401916]] (20.4.0.30332)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || || Only on FirmwareVariationId 0xB.&lt;br /&gt;
|-&lt;br /&gt;
| 040000000000104D || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257908]] (20.1.0.32052)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572)&amp;lt;br/&amp;gt; [[Switch 2: 22.5.0|v1481668160]] (22.5.0.30272) || || Only on FirmwareVariationId 0xB.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Development System Applications =&lt;br /&gt;
{| class=wikitable&lt;br /&gt;
! ProgramId || Versions || Description || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0400000000002065 || || DevMenuApp ||&lt;br /&gt;
|-&lt;br /&gt;
| 040000000000218F || || BluetoothHciRelayTool ||&lt;br /&gt;
|-&lt;br /&gt;
| 040000000000219A || || WlanBtRelayTool ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Development System Modules =&lt;br /&gt;
{| class=wikitable&lt;br /&gt;
! ProgramId || Versions || Description || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 040000000000B240 || [[Switch 2: 19.0.0|v1275070418]] (19.0.0.2002)&amp;lt;/br&amp;gt; [[Switch 2: 20.1.0|v1343257958]] (20.1.0.32102)&amp;lt;br/&amp;gt; [[Switch 2: 22.0.0|v1476425580]] (22.0.0.30572) || || Present on retail devices, likely (?) stubbed. Only on FirmwareVariationId 0xB.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= System Applications =&lt;br /&gt;
{| class=wikitable&lt;br /&gt;
! ProgramId || Versions || Description || Notes&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= User Applications =&lt;br /&gt;
Refer to the [[Switch 2: Title_list/Games|Games List]] for game and application programs.&lt;/div&gt;</summary>
		<author><name>Yellows8</name></author>
	</entry>
	<entry>
		<id>https://switchbrew.org/w/index.php?title=9.0.0&amp;diff=14925</id>
		<title>9.0.0</title>
		<link rel="alternate" type="text/html" href="https://switchbrew.org/w/index.php?title=9.0.0&amp;diff=14925"/>
		<updated>2026-08-06T03:38:33Z</updated>

		<summary type="html">&lt;p&gt;Yellows8: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The Switch 9.0.0 system update was released on September 9, 2019. This Switch update was released for the following regions: ALL.&lt;br /&gt;
&lt;br /&gt;
Security flaws fixed: &amp;lt;fill this in manually later, see the updatedetails page from the ninupdates-report page(s) once available for now&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
==Change-log==&lt;br /&gt;
From [https://en-americas-support.nintendo.com/app/answers/detail/a_id/22525/p/897 official source]:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;blockquote&amp;gt;&lt;br /&gt;
Ver. 9.0.0 (Released September 9, 2019)&lt;br /&gt;
&lt;br /&gt;
Added the following system functionality:&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Added a search feature for the News Channel.&#039;&#039;&#039;&lt;br /&gt;
** Channels can be searched using filters or free text.&lt;br /&gt;
* &#039;&#039;&#039;Added “Display QR Code to Check In” to User Settings.&#039;&#039;&#039;&lt;br /&gt;
** You can display a QR Code on-screen to check in using your Nintendo Account.&lt;br /&gt;
* &#039;&#039;&#039;Alarm Notifications have been added to System Settings &amp;gt; Notifications.&#039;&#039;&#039;&lt;br /&gt;
** You can check or delete pre-set alarms.&lt;br /&gt;
** Alarms can be set up only within supported software (to be added at a later time).&lt;br /&gt;
** A controller firmware update may be required to use this feature.&lt;br /&gt;
* &#039;&#039;&#039;You can now configure touch screen sensitivity settings.&#039;&#039;&#039;&lt;br /&gt;
** Select between Standard and Stylus sensitivity (optimized for stylus input).&lt;br /&gt;
* &#039;&#039;&#039;Added the option to turn on/off the system button input (Nintendo Switch Lite only).&#039;&#039;&#039;&lt;br /&gt;
** When this setting is turned off the system no longer receives input from the console buttons, with the exception of the Capture and HOME Buttons, and can only be operated from a wirelessly paired controller (sold separately).&lt;br /&gt;
** This setting is on by default and can only be turned off if a compatible controller (sold separately) is wirelessly paired to the console.&lt;br /&gt;
** The setting will automatically turn back on when the console is restarted or after returning from sleep mode.&lt;br /&gt;
* &#039;&#039;&#039;Added “Online Play Invites” section to the User&#039;s page.&#039;&#039;&#039;&lt;br /&gt;
** Invites from friends to join online play in supported software will be displayed in this section.&lt;br /&gt;
* &#039;&#039;&#039;General system stability improvements to enhance the user&#039;s experience.&#039;&#039;&#039;&lt;br /&gt;
** Resolved an issue where some users can’t start the Fire Emblem: Three Houses game, and get an error instead.&lt;br /&gt;
&amp;lt;/blockquote&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==System Titles==&lt;br /&gt;
All titles were updated except for the following: Dictionary, UrlBlackList, and [[flog]].&lt;br /&gt;
&lt;br /&gt;
New titles [[NGCT_services|ngct-sysmodule]] and NgWordT were added.&lt;br /&gt;
&lt;br /&gt;
[[NPDM]] changes (besides usual version-bump):&lt;br /&gt;
* usb: Service access: added ins:s, removed hid:sys.&lt;br /&gt;
* settings: Name updated: settings_hoag -&amp;gt; settings.&lt;br /&gt;
* Bus: Name updated: Bus_hoag -&amp;gt; Bus.&lt;br /&gt;
* ptm: Service server access: added fgm*, apm:am, apm:sys. Service access: added bpc, psm, clkrst:i, time:su, removed time:u. KernelCap ThreadInfo: updated HighestPriority = 0x10 -&amp;gt; 0x4. SVC access: added CreateSharedMemory, MapTransferMemory, UnmapTransferMemory, MapDeviceAddressSpaceByForce, MapDeviceAddressSpaceAligned. Interrupt access: added 0x053. KernelCap IoMemoryMap: added BeginAddress=0x700E2000.&lt;br /&gt;
* bsdsocket: Service access: added time:su, removed time:u.&lt;br /&gt;
* hid: Name updated: hid_hoag -&amp;gt; hid. Service server access: removed ahid:hdr, ahid:cd. Service access: added ins:s.&lt;br /&gt;
* audio: Name updated: audio_hoag -&amp;gt; audio. Service access: added ins:s.&lt;br /&gt;
* ldn: Service server access: added lp2p:app, lp2p:sys. Service access: added bsd:s.&lt;br /&gt;
* pcv: Fac.FsAccessFlag updated: cleared bitmask 0x0000000000100400 (SetTime, SystemData). Service server access: removed time:u, time:s, time:a, time:r.&lt;br /&gt;
* ns: Service access: added ins:s, notif:s, time:su, removed hid:sys, time:u.&lt;br /&gt;
* nfc: Name updated: nfc_Hoag -&amp;gt; nfc.&lt;br /&gt;
* psc: Service server access: added time:su, time:s, time:al, time:m, time:p, ins:r, ins:s. Service access: added psc:l. KernelCap HandleTableSize: updated HandleTableSize = 0x100 -&amp;gt; 0x200.&lt;br /&gt;
* am: Service access: added bgtc:t, ins:r, led, notif:s, time:p. KernelCap HandleTableSize: updated HandleTableSize = 0x100 -&amp;gt; 0x200.&lt;br /&gt;
* glue: Fac.FsAccessFlag updated: set bitmask 0x0000000000100408 (SystemSaveData, SetTime, SystemData). Service server access: added notif:a, notif:s, time:a, time:r, time:u. Service access: added arp:r, bgtc:t, fsp-srv, time:m, time:u.&lt;br /&gt;
* creport: Service access: added caps:sc.&lt;br /&gt;
* sdb: Service server access: added pl:s.&lt;br /&gt;
* qlaunch: Service access: added nd:sys, ngct:s, notif:s.&lt;br /&gt;
* cabinet: Service access: added ngct:u.&lt;br /&gt;
* netConnect: Service access: added ngct:u.&lt;br /&gt;
* playerSelect: Service access: added ngct:u.&lt;br /&gt;
* miiEdit: Service access: added ngct:u.&lt;br /&gt;
* LibAppletWeb: SVC access: added SynchronizePreemptionState.&lt;br /&gt;
* LibAppletShop: SVC access: added SynchronizePreemptionState.&lt;br /&gt;
* overlayDisp: Service access: added ngct:u, notif:s.&lt;br /&gt;
* photoViewer: Service access: added ngct:u.&lt;br /&gt;
* LibAppletOff: SVC access: added SynchronizePreemptionState.&lt;br /&gt;
* LibAppletLns: SVC access: added SynchronizePreemptionState.&lt;br /&gt;
* LibAppletAuth: SVC access: added SynchronizePreemptionState.&lt;br /&gt;
* myPage: Service access: added ngct:u.&lt;br /&gt;
&lt;br /&gt;
RomFs changes:&lt;br /&gt;
* hid-sysmodule:&lt;br /&gt;
** &amp;quot;/ftmFwUpdate/FTS_00120100.fts256&amp;quot; added&lt;br /&gt;
** &amp;quot;/ftmFwUpdate/FTS_32000001.fts256&amp;quot; added&lt;br /&gt;
** &amp;quot;/ftmFwUpdate/FTS_32000102.fts256&amp;quot; added&lt;br /&gt;
** &amp;quot;/ftmFwUpdate/FTS_32000302.fts256&amp;quot; added&lt;br /&gt;
** &amp;quot;/ftmFwUpdate/FTS_32000402.fts256&amp;quot; added&lt;br /&gt;
** &amp;quot;/ftmFwUpdate/NTD_4CD_1801.fts256&amp;quot; removed&lt;br /&gt;
** &amp;quot;/ftmFwUpdate/NTD_4CD_2602.fts256&amp;quot; removed&lt;br /&gt;
** &amp;quot;/ftmFwUpdate/NTD_4CD_3801.fts256&amp;quot; removed&lt;br /&gt;
** &amp;quot;/ftmFwUpdate/NTD_4CD_xxxx.fts256&amp;quot; removed&lt;br /&gt;
* ErrorMessage: updated&lt;br /&gt;
** Localization for &amp;quot;zh-HansT&amp;quot; was added. New errors were added. Localization for various errors were updated.&lt;br /&gt;
* BrowserDll:&lt;br /&gt;
** &amp;quot;/browser/DefaultCss.dat&amp;quot; added&lt;br /&gt;
** &amp;quot;/browser/RootCaEtc.pem&amp;quot; updated&lt;br /&gt;
** &amp;quot;/browser/UserCss.dat&amp;quot; updated&lt;br /&gt;
** &amp;quot;/buildinfo/buildinfo.dat&amp;quot; updated&lt;br /&gt;
** &amp;quot;/dll_0/cairo_wkc.nro.lz4&amp;quot; updated&lt;br /&gt;
** &amp;quot;/dll_0/libfont.nro.lz4&amp;quot; updated&lt;br /&gt;
** &amp;quot;/dll_0/oss_wkc.nro.lz4&amp;quot; updated&lt;br /&gt;
** &amp;quot;/dll_0/peer_wkc.nro.lz4&amp;quot; updated&lt;br /&gt;
** &amp;quot;/dll_0/webkit_wkc.nro.lz4&amp;quot; updated&lt;br /&gt;
** &amp;quot;/dll_1/&amp;quot; added&lt;br /&gt;
*** New directory &amp;quot;/dll_1/&amp;quot; was added, which also contains OSS NROs with the same filenames. All web-applets now use this instead of dll_0, except for LibraryAppletOfflineWeb which still uses dll_0. This is likely done so that Offline game manuals etc don&#039;t break.&lt;br /&gt;
*** dll_0 have binary names in the NRO &amp;quot;D:\for_cruiser\release_326\nx\applications\cruiser_sample\build\NX64\Develop_Dll\...&amp;quot;, while dll_1 have &amp;quot;D:\for_cruiser_Safari606\release_31\nx\applications\cruiser_sample\build\NX64\Develop_Dll\...&amp;quot;.&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/CNzhT/&amp;quot; added&lt;br /&gt;
* Help:&lt;br /&gt;
** &amp;quot;/legallines.htdocs/index.html&amp;quot; updated&lt;br /&gt;
** &amp;quot;/safe.htdocs/html/CNzh/&amp;quot; added&lt;br /&gt;
** &amp;quot;/safe.htdocs/html/JPja/index.html&amp;quot; updated&lt;br /&gt;
** &amp;quot;/safe.htdocs/html/JPja/page_02.html&amp;quot; updated&lt;br /&gt;
** &amp;quot;/safe.htdocs/html/JPja/page_04.html&amp;quot; updated&lt;br /&gt;
** &amp;quot;/safe.htdocs/html/KRko/index.html&amp;quot; updated&lt;br /&gt;
** &amp;quot;/safe.htdocs/html/KRko/page_02.html&amp;quot; updated&lt;br /&gt;
** &amp;quot;/safe.htdocs/html/KRko/page_04.html&amp;quot; updated&lt;br /&gt;
** &amp;quot;/safe.htdocs/html/TWzh/index.html&amp;quot; updated&lt;br /&gt;
** &amp;quot;/safe.htdocs/html/TWzh/page_02.html&amp;quot; updated&lt;br /&gt;
** &amp;quot;/safe.htdocs/html/TWzh/page_03.html&amp;quot; updated&lt;br /&gt;
** &amp;quot;/safe.htdocs/html/TWzh/page_04.html&amp;quot; updated&lt;br /&gt;
** &amp;quot;/safe.htdocs/js/chnscript.js&amp;quot; added&lt;br /&gt;
* Chinese and Korean dictionaries:&lt;br /&gt;
** &amp;quot;/Iwnn/KO/njubase1.a&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/KO/njubase2.a&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/CN/pinyin/GB18030/njtan.a&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/CN/pinyin/GB18030/njtan.ad1&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/CN/pinyin/GB2312/njtan.a&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/CN/pinyin/GB2312/njtan.ad1&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/HK/cangjie/njcangjie.a&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/HK/cangjie/quick/njcangjie.a&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/HK/cangjie/quick/njcangjie.ad1&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/HK/jyutping/njtan.a&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/HK/jyutping/njtan.ad1&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/HK/stroke/njstroke.a&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/TW/bopomofo/keisei/njtan.ad1&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/TW/bopomofo/keisei/njubase2.ad1&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/TW/bopomofo/njtan.a&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/TW/bopomofo/njubase1.a&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/TW/bopomofo/njubase2.a&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/TW/bopomofo/no_keisei/njtan.ad1&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/TW/bopomofo/no_keisei/njubase2.ad1&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/TW/cangjie/njcangjie.a&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/TW/cangjie/quick/njcangjie.a&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/TW/cangjie/quick/njcangjie.ad1&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/TW/pinyin/keisei/njtan.ad1&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/TW/pinyin/keisei/njubase2.ad1&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/TW/pinyin/njtan.a&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/TW/pinyin/njubase1.a&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/TW/pinyin/njubase2.a&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/TW/pinyin/no_keisei/njtan.ad1&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/TW/pinyin/no_keisei/njubase2.ad1&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/TW/stroke/njstroke.a&amp;quot; updated&lt;br /&gt;
* NgWord: &amp;quot;/0.txt&amp;quot; updated, &amp;quot;/common.txt&amp;quot; updated, &amp;quot;/version.dat&amp;quot; updated&lt;br /&gt;
* [[System_Version_Title|SystemVersion]]: All files updated.&lt;br /&gt;
* AvatarImage: &amp;quot;/DatabaseInfo.bin&amp;quot; updated&lt;br /&gt;
* LocalNews:&lt;br /&gt;
** &amp;quot;/image/LnShopIntro_Terra/&amp;quot; added&lt;br /&gt;
** &amp;quot;/image/LnSupIntro/main_Other.jpg&amp;quot; updated&lt;br /&gt;
** &amp;quot;/image/LnSupIntro/main_Terra.jpg&amp;quot; added&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/CNzhT/&amp;quot; added&lt;br /&gt;
* Eula: &amp;quot;/CNzhT/&amp;quot; added, &amp;quot;/revision.txt&amp;quot; updated&lt;br /&gt;
* TimeZoneBinary: updated&lt;br /&gt;
* [[System_Settings|FirmwareDebugSettings/PlatformConfigIcosa/PlatformConfigCopper/PlatformConfigHoag/PlatformConfigIcosaMariko]]: All files updated.&lt;br /&gt;
* FatalMessage:&lt;br /&gt;
** &amp;quot;/de/TerraMessage&amp;quot; added&lt;br /&gt;
** &amp;quot;/en-GB/TerraMessage&amp;quot; added&lt;br /&gt;
** &amp;quot;/en-US/TerraMessage&amp;quot; added&lt;br /&gt;
** &amp;quot;/es/TerraMessage&amp;quot; added&lt;br /&gt;
** &amp;quot;/es-419/TerraMessage&amp;quot; added&lt;br /&gt;
** &amp;quot;/fr/TerraMessage&amp;quot; added&lt;br /&gt;
** &amp;quot;/fr-CA/TerraMessage&amp;quot; added&lt;br /&gt;
** &amp;quot;/it/TerraMessage&amp;quot; added&lt;br /&gt;
** &amp;quot;/ja/TerraMessage&amp;quot; added&lt;br /&gt;
** &amp;quot;/ko/TerraMessage&amp;quot; added&lt;br /&gt;
** &amp;quot;/nl/TerraMessage&amp;quot; added&lt;br /&gt;
** &amp;quot;/pt/TerraMessage&amp;quot; added&lt;br /&gt;
** &amp;quot;/ru/TerraMessage&amp;quot; added&lt;br /&gt;
** &amp;quot;/zh-CN/TerraMessage&amp;quot; added&lt;br /&gt;
** &amp;quot;/zh-Hans/TerraMessage&amp;quot; added&lt;br /&gt;
** &amp;quot;/zh-Hant/TerraMessage&amp;quot; added&lt;br /&gt;
** &amp;quot;/zh-TW/TerraMessage&amp;quot; added&lt;br /&gt;
* ControllerIcon: &amp;quot;/lyt/footer/800/controllerIcon.bntx&amp;quot; updated, &amp;quot;/lyt/footer/800/info.dat&amp;quot; updated&lt;br /&gt;
* ControllerFirmware: &amp;quot;/FirmwareInfo.csv&amp;quot; updated, &amp;quot;/ukyosakyo_ep2_ota.bin&amp;quot; updated&lt;br /&gt;
* NgWord2: &amp;quot;/ac_0_not_b_nx&amp;quot; updated, &amp;quot;/ac_common_not_b_nx&amp;quot; updated&lt;br /&gt;
* RebootlessSystemUpdateVersion: All files updated.&lt;br /&gt;
* qlaunch applet:&lt;br /&gt;
** &amp;quot;/common/shader/VarietyOceanShader_Nx.arc.szs&amp;quot; updated&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/CNzh/pshop.msbt.szs&amp;quot; removed&lt;br /&gt;
** &amp;quot;/message/CNzhT/&amp;quot; added&lt;br /&gt;
** &amp;quot;/message/EUde/pshop.msbt.szs&amp;quot; removed&lt;br /&gt;
** &amp;quot;/message/EUen/pshop.msbt.szs&amp;quot; removed&lt;br /&gt;
** &amp;quot;/message/EUes/pshop.msbt.szs&amp;quot; removed&lt;br /&gt;
** &amp;quot;/message/EUfr/pshop.msbt.szs&amp;quot; removed&lt;br /&gt;
** &amp;quot;/message/EUit/pshop.msbt.szs&amp;quot; removed&lt;br /&gt;
** &amp;quot;/message/EUnl/pshop.msbt.szs&amp;quot; removed&lt;br /&gt;
** &amp;quot;/message/EUpt/pshop.msbt.szs&amp;quot; removed&lt;br /&gt;
** &amp;quot;/message/EUru/pshop.msbt.szs&amp;quot; removed&lt;br /&gt;
** &amp;quot;/message/JPja/pshop.msbt.szs&amp;quot; removed&lt;br /&gt;
** &amp;quot;/message/USen/pshop.msbt.szs&amp;quot; removed&lt;br /&gt;
** &amp;quot;/message/USes/pshop.msbt.szs&amp;quot; removed&lt;br /&gt;
** &amp;quot;/message/USfr/pshop.msbt.szs&amp;quot; removed&lt;br /&gt;
** &amp;quot;/sound/qlaunch_action.bksnd&amp;quot; updated&lt;br /&gt;
** &amp;quot;/sound/qlaunch.bfsar&amp;quot; updated&lt;br /&gt;
* auth applet:&lt;br /&gt;
** &amp;quot;/common/shader/VarietyOceanShader_Nx.arc.szs&amp;quot; updated&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/CNzhT/&amp;quot; added&lt;br /&gt;
** &amp;quot;/sound/auth_action.bksnd&amp;quot; updated&lt;br /&gt;
** &amp;quot;/sound/auth.bfsar&amp;quot; updated&lt;br /&gt;
* cabinet applet:&lt;br /&gt;
** &amp;quot;/common/shader/VarietyOceanShader_Nx.arc.szs&amp;quot; updated&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/CNzhT/&amp;quot; added&lt;br /&gt;
** &amp;quot;/sound/cabinet_action.bksnd&amp;quot; updated&lt;br /&gt;
** &amp;quot;/sound/cabinet.bfsar&amp;quot; updated&lt;br /&gt;
* controller applet:&lt;br /&gt;
** &amp;quot;/common/shader/VarietyOceanShader_Nx.arc.szs&amp;quot; updated&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/CNzhT/&amp;quot; added&lt;br /&gt;
** &amp;quot;/sound/controller_action.bksnd&amp;quot; updated&lt;br /&gt;
** &amp;quot;/sound/controller.bfsar&amp;quot; updated&lt;br /&gt;
* dataErase applet:&lt;br /&gt;
** &amp;quot;/common/shader/VarietyOceanShader_Nx.arc.szs&amp;quot; updated&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/CNzhT/&amp;quot; added&lt;br /&gt;
** &amp;quot;/sound/dataErase_action.bksnd&amp;quot; updated&lt;br /&gt;
** &amp;quot;/sound/dataErase.bfsar&amp;quot; updated&lt;br /&gt;
* error applet:&lt;br /&gt;
** &amp;quot;/common/shader/VarietyOceanShader_Nx.arc.szs&amp;quot; updated&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/CNzhT/&amp;quot; added&lt;br /&gt;
** &amp;quot;/sound/error_action.bksnd&amp;quot; updated&lt;br /&gt;
** &amp;quot;/sound/error.bfsar&amp;quot; updated&lt;br /&gt;
* netConnect applet:&lt;br /&gt;
** &amp;quot;/common/shader/VarietyOceanShader_Nx.arc.szs&amp;quot; updated&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/CNzhT/&amp;quot; added&lt;br /&gt;
** &amp;quot;/sound/netConnect_action.bksnd&amp;quot; updated&lt;br /&gt;
** &amp;quot;/sound/netConnect.bfsar&amp;quot; updated&lt;br /&gt;
* playerSelect applet:&lt;br /&gt;
** &amp;quot;/common/shader/VarietyOceanShader_Nx.arc.szs&amp;quot; updated&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/CNzhT/&amp;quot; added&lt;br /&gt;
** &amp;quot;/sound/playerSelect_action.bksnd&amp;quot; updated&lt;br /&gt;
** &amp;quot;/sound/playerSelect.bfsar&amp;quot; updated&lt;br /&gt;
* swkbd applet:&lt;br /&gt;
** &amp;quot;/common/shader/VarietyOceanShader_Nx.arc.szs&amp;quot; updated&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/CNzhT/&amp;quot; added&lt;br /&gt;
** &amp;quot;/sound/swkbd_action.bksnd&amp;quot; updated&lt;br /&gt;
** &amp;quot;/sound/swkbd.bfsar&amp;quot; updated&lt;br /&gt;
* miiEdit (LibraryAppletMiiEdit):&lt;br /&gt;
** &amp;quot;/archive/Gfx.bin.cmp&amp;quot; updated&lt;br /&gt;
** &amp;quot;/archive/Layout.bin.cmp&amp;quot; updated&lt;br /&gt;
** &amp;quot;/archive/Mii.bin.cmp&amp;quot; updated&lt;br /&gt;
** &amp;quot;/archive/Ptcl.bin.cmp&amp;quot; updated&lt;br /&gt;
** &amp;quot;/archive/Shader.bin.cmp&amp;quot; updated&lt;br /&gt;
** &amp;quot;/archive/Yaml.bin.cmp&amp;quot; updated&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/CNzhT/&amp;quot; added&lt;br /&gt;
* [[Internet_Browser|LibAppletShop applet]]: &amp;quot;/buildinfo/buildinfo.dat&amp;quot; updated, &amp;quot;/.nrr/netfront.nrr&amp;quot; updated, &amp;quot;/whitelist/WhitelistEc.txt&amp;quot; updated&lt;br /&gt;
** &amp;quot;/whitelist/WhitelistEc.txt&amp;quot;: &amp;quot;|ch&amp;quot; was added to the main &amp;quot;nintendo&amp;quot; line, for allowing nintendo.ch. Two new lines were added: &amp;lt;nowiki&amp;gt;&amp;quot;^https://([0-9A-Za-z\-]+\.)*nintendoswitch\.cn(/|$)&amp;quot; and &amp;quot;^https://([0-9A-Za-z\-]+\.)*nintendoswitch\.com\.cn(/|$)&amp;quot;&amp;lt;/nowiki&amp;gt;.&lt;br /&gt;
* overlayDisp applet:&lt;br /&gt;
** &amp;quot;/common/shader/SimpleShader_Nx.arc.szs&amp;quot; updated&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/CNzhT/&amp;quot; added&lt;br /&gt;
** &amp;quot;/sound/infoAlarm.raw&amp;quot; added&lt;br /&gt;
** &amp;quot;/sound/overlayDisp_action.bksnd&amp;quot; updated&lt;br /&gt;
* photoViewer applet:&lt;br /&gt;
** &amp;quot;/common/shader/VarietyOceanShader_Nx.arc.szs&amp;quot; updated&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/CNzhT/&amp;quot; added&lt;br /&gt;
** &amp;quot;/sound/photoViewer_action.bksnd&amp;quot; updated&lt;br /&gt;
** &amp;quot;/sound/photoViewer.bfsar&amp;quot; updated&lt;br /&gt;
* [[Internet_Browser|LibAppletOff/LibAppletWeb/LibAppletAuth]]: &amp;quot;/buildinfo/buildinfo.dat&amp;quot; updated, &amp;quot;/.nrr/netfront.nrr&amp;quot; updated&lt;br /&gt;
* [[Internet_Browser|LibAppletLns applet]]: &amp;quot;/buildinfo/buildinfo.dat&amp;quot; updated, &amp;quot;/.nrr/netfront.nrr&amp;quot; updated, &amp;quot;/whitelist/WhitelistLns.txt&amp;quot; updated&lt;br /&gt;
** &amp;quot;/whitelist/WhitelistLns.txt&amp;quot;: A duplicate &amp;quot;ch|&amp;quot; was removed from the main &amp;quot;nintendo&amp;quot; line. The same new &amp;quot;nintendoswitch&amp;quot; lines from WhitelistEc.txt were added. The &amp;quot;... google(\.[A-Za-z]+)*/(search\?|translate&amp;quot; line had &amp;quot;|amp/)&amp;quot; added at the end. The following new line was added: &amp;quot;---- ^https?://([0-9A-Za-z\-]+\.)*(sites|mail|news)\.google(\.[A-Za-z]+)*/&amp;quot;.&lt;br /&gt;
* &amp;quot;starter&amp;quot; application:&lt;br /&gt;
** &amp;quot;/common/shader/VarietyOceanShader_Nx.arc.szs&amp;quot; updated&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/CNzhT/&amp;quot; added&lt;br /&gt;
** &amp;quot;/sound/starter_action.bksnd&amp;quot; updated&lt;br /&gt;
** &amp;quot;/sound/starter.bfsar&amp;quot; updated&lt;br /&gt;
* myPage applet:&lt;br /&gt;
** &amp;quot;/common/shader/VarietyOceanShader_Nx.arc.szs&amp;quot; updated&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/CNzhT/&amp;quot; added&lt;br /&gt;
** &amp;quot;/sound/myPage_action.bksnd&amp;quot; updated&lt;br /&gt;
** &amp;quot;/sound/myPage.bfsar&amp;quot; updated&lt;br /&gt;
* maintenance applet:&lt;br /&gt;
** &amp;quot;/common/shader/VarietyOceanShader_Nx.arc.szs&amp;quot; updated&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/CNzhT/&amp;quot; added&lt;br /&gt;
** &amp;quot;/sound/maintenance_action.bksnd&amp;quot; updated&lt;br /&gt;
** &amp;quot;/sound/maintenance.bfsar&amp;quot; updated&lt;br /&gt;
&lt;br /&gt;
=== BootImagePackages ===&lt;br /&gt;
RomFs changes: BootImagePackage/BootImagePackageSafe: All files updated.&lt;br /&gt;
&lt;br /&gt;
[[Package2|INI1]] changes:&lt;br /&gt;
* BootImagePackageSafe: &lt;br /&gt;
** 0100000000000021 (psc): KernelCap HandleTableSize: updated HandleTableSize = 0x80 -&amp;gt; 0x200.&lt;br /&gt;
&lt;br /&gt;
====NX_BOOTLOADER====&lt;br /&gt;
NX bootloader was updated.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;check back later for diff&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Secure Monitor====&lt;br /&gt;
Secure Monitor was updated.&lt;br /&gt;
&lt;br /&gt;
* CPU Suspend SMC code now explicitly initializes the state of I2C5 before communicating with the PMIC, instead of assuming that it is in a valid state.&lt;br /&gt;
* Code for initializing MMIO inside package2ldr now writes random values to a number of PMC secure scratch registers, and validates that the written values are read back successfully before locking the scratch.&lt;br /&gt;
** This writes to secscratch 4-7 (used to store SRK), then locks them.&lt;br /&gt;
*** The SE will overwrite these values during context save despite the lock.&lt;br /&gt;
** This then writes to secscratch 112-115 and 24-25, used by TZ during context save to store a MAC and a key source, respectively.&lt;br /&gt;
*** These too will be overwritten during context save, as the scratch are not locked.&lt;br /&gt;
** secscratch 4-7 are then locked a second time.&lt;br /&gt;
&lt;br /&gt;
====KernelLdr====&lt;br /&gt;
[[Kernel Loader|KernelLdr]] was updated.&lt;br /&gt;
&lt;br /&gt;
* TPIDR_EL1 is now set to 0, and VBAR_EL1 is now set to a table that infinite loops on all exceptions other than synchronous from same exception level.&lt;br /&gt;
** synch_spx_el1 now restores a number of registers from a context with pointer in TPIDR_EL1.&lt;br /&gt;
* TPIDR_EL1 is now set to a context save struct before manufacturer-specific system registers are set, and validated to be non-0/NULL afterwards. It is then cleared.&lt;br /&gt;
** Support was added for Cortex-A53 specific CPU initialization.&lt;br /&gt;
* Kernel .rodata is now initially mapped as RW- instead of R--, and then reprotected to R-- after relocations are completed.&lt;br /&gt;
** This allows for/implements .rel.ro.&lt;br /&gt;
&lt;br /&gt;
====Kernel====&lt;br /&gt;
Kernel was updated.&lt;br /&gt;
&lt;br /&gt;
* Starting with this version, Kernel .rwdata is now 0x1000 aligned instead of 0x10000 aligned.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;check back later for diff&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Warmboot====&lt;br /&gt;
* The firmware revision magic was changed from 0x14A to 0x16B.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;check back for more diffs later&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====FIRM Sysmodules====&lt;br /&gt;
FIRM sysmodules were updated. Specific diffs available below:&lt;br /&gt;
&lt;br /&gt;
=====[[Filesystem services|FS]]=====&lt;br /&gt;
[[Gamecard_ASIC#User_firmware|Gamecard ASIC firmware]] was updated.&lt;br /&gt;
&lt;br /&gt;
A new field &amp;quot;AcidSignatureKeyGeneration&amp;quot; in the [[NPDM|NPDM]] format is now used to select between different public keys for verifying the [[NPDM#ACID|ACID]] signature.&lt;br /&gt;
&lt;br /&gt;
=====[[Loader services|Loader]]=====&lt;br /&gt;
The anti-downgrade code in CreateProcess was updated.&lt;br /&gt;
* All system modules, and all web applets are now subject to anti-downgrade restrictions.&lt;br /&gt;
* Instead of using 1 as the minimum value, the minimum value is looked up from an array in .rodata on a per-module basis.&lt;br /&gt;
** All current entries use 0x24000000 (9.0.0) as the minimum version.&lt;br /&gt;
&lt;br /&gt;
=====[[Boot]]=====&lt;br /&gt;
Code was added implementing (partial, unfinished) support for a new hardware form-factor. Hardware type for this is 4 (&amp;quot;Calcio&amp;quot;), uses Mariko SoC.&lt;br /&gt;
&lt;br /&gt;
===[[PPC_services|ppc-sysmodule]]===&lt;br /&gt;
This sysmodule was stubbed. This is now a SystemData title with an empty [[CNMT]] list.&lt;br /&gt;
&lt;br /&gt;
The services which were previously hosted by this sysmodule were moved into [[PTM_services|ptm-sysmodule]].&lt;br /&gt;
&lt;br /&gt;
===[[RO_services|ro-sysmodule]]===&lt;br /&gt;
A new field &amp;quot;CertificationSignatureKeyGeneration&amp;quot; in the [[NRR|NRR]] format is now used to select between different public keys for verifying the [[NRR#Certification|Certification]] signature.&lt;br /&gt;
&lt;br /&gt;
==Keys==&lt;br /&gt;
All updated non-FIRM titles use a new masterkey, except for Eula which still uses the keydata from [[1.0.0]].&lt;br /&gt;
&lt;br /&gt;
==See Also==&lt;br /&gt;
System update report(s):&lt;br /&gt;
* [https://yls8.mtheall.com/ninupdates/reports.php?date=09-09-19_08-05-10&amp;amp;sys=hac]&lt;br /&gt;
&lt;br /&gt;
{{NavboxVersions}}&lt;br /&gt;
&lt;br /&gt;
[[Category:System versions]]&lt;/div&gt;</summary>
		<author><name>Yellows8</name></author>
	</entry>
	<entry>
		<id>https://switchbrew.org/w/index.php?title=7.0.0&amp;diff=14924</id>
		<title>7.0.0</title>
		<link rel="alternate" type="text/html" href="https://switchbrew.org/w/index.php?title=7.0.0&amp;diff=14924"/>
		<updated>2026-08-06T02:56:29Z</updated>

		<summary type="html">&lt;p&gt;Yellows8: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The Switch 7.0.0 system update was released on January 28, 2019. This Switch update was released for the following regions: ALL.&lt;br /&gt;
&lt;br /&gt;
Security flaws fixed: &amp;lt;fill this in manually later, see the updatedetails page from the ninupdates-report page(s) once available for now&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
==Change-log==&lt;br /&gt;
[https://en-americas-support.nintendo.com/app/answers/detail/a_id/22525/p/897 Official] ALL change-log:&lt;br /&gt;
* Select from six new New Super Mario Bros.™ U Deluxe icons for your user&lt;br /&gt;
* To edit your user icon, head to your My Page  &amp;amp;gt; Profile on the top left of the HOME menu&lt;br /&gt;
* Added additional language support to the HOME Menu for Chinese, Korean, and Taiwanese&lt;br /&gt;
* To change the language, head to the System Settings  &amp;amp;gt; System &amp;amp;gt; Language&lt;br /&gt;
* General system stability improvements to enhance the user&#039;s experience&lt;br /&gt;
&lt;br /&gt;
==System Titles==&lt;br /&gt;
All titles were updated, except: &amp;quot;Chinese and Korean dictionaries&amp;quot;, &amp;quot;European English and Japanese dictionaries&amp;quot;, EULA, &amp;quot;Blacklist URL&amp;quot;, &amp;quot;Dummy file&amp;quot;, &amp;quot;Hoag system config&amp;quot;, and flog.&lt;br /&gt;
&lt;br /&gt;
NPDM:&lt;br /&gt;
* New services were [[Services_API|added]].&lt;br /&gt;
* bluetooth-sysmodule now has access to svcCreateSharedMemory.&lt;br /&gt;
* HID-sysmodule now has access to new service usb:qdb.&lt;br /&gt;
* ldn-sysmodule now has access to service psc:m.&lt;br /&gt;
* account-sysmodule: now has access to service npns:s.&lt;br /&gt;
* ns-sysmodule: service access to prepo:s was replaced with srepo:u. FS permissions now have bitmask 0x0000000400000000 set (CanFormatSdCard).&lt;br /&gt;
* nfc-sysmodule: now has access to services: psm, i2c, and gpio.&lt;br /&gt;
* am-sysmodule: now has access to services lm and nvgem:cd.&lt;br /&gt;
* btm-sysmodule: now has access to service srepo:u.&lt;br /&gt;
* npns-sysmodule: main thread stack size changed from 0x8000 to 0x4000. Removed service access for acc:aa and acc:u1, added access to pm:bm.&lt;br /&gt;
* glue-sysmodule: now has access to service srepo:u.&lt;br /&gt;
* Various applets now have access to service &amp;quot;banana&amp;quot; (which still doesn&#039;t exist on retail).&lt;br /&gt;
&lt;br /&gt;
RomFs changes:&lt;br /&gt;
* hid-sysmodule: &amp;quot;/ftmFwUpdate/NTD_4CD_xxxx.fts256&amp;quot; added&lt;br /&gt;
* ErrorMessage: updated&lt;br /&gt;
* BrowserDll:&lt;br /&gt;
** &amp;quot;/browser/ErrorPageTemplate.html&amp;quot; updated&lt;br /&gt;
** &amp;quot;/browser/UserCss.dat&amp;quot; updated&lt;br /&gt;
** &amp;quot;/buildinfo/buildinfo.dat&amp;quot; updated&lt;br /&gt;
** &amp;quot;/dll/cairo_wkc.nro.lz4&amp;quot; updated&lt;br /&gt;
** &amp;quot;/dll/libfont.nro.lz4&amp;quot; updated&lt;br /&gt;
** &amp;quot;/dll/oss_wkc.nro.lz4&amp;quot; updated&lt;br /&gt;
** &amp;quot;/dll/peer_wkc.nro.lz4&amp;quot; updated&lt;br /&gt;
** &amp;quot;/dll/webkit_wkc.nro.lz4&amp;quot; updated&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/lyt/Browse/SwkbdCaret.arc&amp;quot; added&lt;br /&gt;
** &amp;quot;/lyt/Keyboard/&amp;quot; removed&lt;br /&gt;
** &amp;quot;/message/CNzh/&amp;quot; added&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/KRko/&amp;quot; added&lt;br /&gt;
** &amp;quot;/message/TWzh/&amp;quot; added&lt;br /&gt;
** &amp;quot;/shader/OceanShader.arc&amp;quot; updated&lt;br /&gt;
* Help: &amp;quot;/legallines.htdocs/index.html&amp;quot; updated&lt;br /&gt;
* NgWord: &amp;quot;/0.txt&amp;quot; updated, &amp;quot;/13.txt&amp;quot; updated, &amp;quot;/version.dat&amp;quot; updated&lt;br /&gt;
* [[System_Version_Title|SystemVersion]]: All files updated.&lt;br /&gt;
* AvatarImage:&lt;br /&gt;
** &amp;quot;/chara/0000006D.szs&amp;quot; added&lt;br /&gt;
** &amp;quot;/chara/0000006E.szs&amp;quot; added&lt;br /&gt;
** &amp;quot;/chara/0000006F.szs&amp;quot; added&lt;br /&gt;
** &amp;quot;/chara/00000070.szs&amp;quot; added&lt;br /&gt;
** &amp;quot;/chara/00000071.szs&amp;quot; added&lt;br /&gt;
** &amp;quot;/chara/00000072.szs&amp;quot; added&lt;br /&gt;
** &amp;quot;/chara/table.bin&amp;quot; updated&lt;br /&gt;
** &amp;quot;/DatabaseInfo.bin&amp;quot; updated&lt;br /&gt;
* LocalNews: &amp;quot;/message/CNzh/&amp;quot; added, &amp;quot;/message/KRko/&amp;quot; added, &amp;quot;/message/revision.txt&amp;quot; updated, &amp;quot;/message/TWzh/&amp;quot; added&lt;br /&gt;
* [[System_Settings|FirmwareDebugSettings]]: All files updated.&lt;br /&gt;
* FatalMessage:&lt;br /&gt;
** &amp;quot;/ko/ErrorCode&amp;quot; updated&lt;br /&gt;
** &amp;quot;/ko/GeneralMessage&amp;quot; updated&lt;br /&gt;
** &amp;quot;/ko/QuestMessage&amp;quot; updated&lt;br /&gt;
** &amp;quot;/zh-CN/ErrorCode&amp;quot; updated&lt;br /&gt;
** &amp;quot;/zh-CN/GeneralMessage&amp;quot; updated&lt;br /&gt;
** &amp;quot;/zh-CN/QuestMessage&amp;quot; updated&lt;br /&gt;
** &amp;quot;/zh-Hans/ErrorCode&amp;quot; updated&lt;br /&gt;
** &amp;quot;/zh-Hans/GeneralMessage&amp;quot; updated&lt;br /&gt;
** &amp;quot;/zh-Hans/QuestMessage&amp;quot; updated&lt;br /&gt;
** &amp;quot;/zh-Hant/ErrorCode&amp;quot; updated&lt;br /&gt;
** &amp;quot;/zh-Hant/GeneralMessage&amp;quot; updated&lt;br /&gt;
** &amp;quot;/zh-Hant/QuestMessage&amp;quot; updated&lt;br /&gt;
** &amp;quot;/zh-TW/ErrorCode&amp;quot; updated&lt;br /&gt;
** &amp;quot;/zh-TW/GeneralMessage&amp;quot; updated&lt;br /&gt;
** &amp;quot;/zh-TW/QuestMessage&amp;quot; updated&lt;br /&gt;
* ControllerFirmware: &amp;quot;/FirmwareInfo.csv&amp;quot; updated, &amp;quot;/ukyosakyo_ep2_ota.bin&amp;quot; updated&lt;br /&gt;
* NgWord2: &amp;quot;/ac_0_b1_nx&amp;quot; updated, &amp;quot;/ac_0_b2_nx&amp;quot; updated, &amp;quot;/ac_0_not_b_nx&amp;quot; updated, &amp;quot;/ac_13_b1_nx&amp;quot; updated, &amp;quot;/ac_13_b2_nx&amp;quot; updated&lt;br /&gt;
* RebootlessSystemUpdateVersion: All files updated.&lt;br /&gt;
* ContentActionTable: &amp;quot;/table/&amp;quot; added&lt;br /&gt;
** The new file &amp;quot;/table/431FA316E20941779452DD0EBFA05E0E/ApplicationId&amp;quot; contains string &amp;quot;0x01003a400c3da000&amp;quot; - &amp;quot;YouTube&amp;quot;.&lt;br /&gt;
* qlaunch applet:&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/CNzh/&amp;quot; added&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/EUde/pshop.msbt.szs&amp;quot; added&lt;br /&gt;
** &amp;quot;/message/EUen/pshop.msbt.szs&amp;quot; added&lt;br /&gt;
** &amp;quot;/message/EUes/pshop.msbt.szs&amp;quot; added&lt;br /&gt;
** &amp;quot;/message/EUfr/pshop.msbt.szs&amp;quot; added&lt;br /&gt;
** &amp;quot;/message/EUit/pshop.msbt.szs&amp;quot; added&lt;br /&gt;
** &amp;quot;/message/EUnl/pshop.msbt.szs&amp;quot; added&lt;br /&gt;
** &amp;quot;/message/EUpt/pshop.msbt.szs&amp;quot; added&lt;br /&gt;
** &amp;quot;/message/EUru/pshop.msbt.szs&amp;quot; added&lt;br /&gt;
** &amp;quot;/message/JPja/pshop.msbt.szs&amp;quot; added&lt;br /&gt;
** &amp;quot;/message/KRko/&amp;quot; added&lt;br /&gt;
** &amp;quot;/message/TWzh/&amp;quot; added&lt;br /&gt;
** &amp;quot;/message/USen/pshop.msbt.szs&amp;quot; added&lt;br /&gt;
** &amp;quot;/message/USes/pshop.msbt.szs&amp;quot; added&lt;br /&gt;
** &amp;quot;/message/USfr/pshop.msbt.szs&amp;quot; added&lt;br /&gt;
** &amp;quot;/sound/qlaunch_action.bksnd&amp;quot; updated&lt;br /&gt;
* auth applet:&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/CNzh/&amp;quot; added&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/KRko/&amp;quot; added&lt;br /&gt;
** &amp;quot;/message/TWzh/&amp;quot; added&lt;br /&gt;
** &amp;quot;/sound/auth_action.bksnd&amp;quot; updated&lt;br /&gt;
* cabinet applet:&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/CNzh/&amp;quot; added&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/KRko/&amp;quot; added&lt;br /&gt;
** &amp;quot;/message/TWzh/&amp;quot; added&lt;br /&gt;
** &amp;quot;/sound/cabinet_action.bksnd&amp;quot; updated&lt;br /&gt;
* controller applet:&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/CNzh/&amp;quot; added&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/KRko/&amp;quot; added&lt;br /&gt;
** &amp;quot;/message/TWzh/&amp;quot; added&lt;br /&gt;
** &amp;quot;/sound/controller_action.bksnd&amp;quot; updated&lt;br /&gt;
* dataErase applet:&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/CNzh/&amp;quot; added&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/KRko/&amp;quot; added&lt;br /&gt;
** &amp;quot;/message/TWzh/&amp;quot; added&lt;br /&gt;
** &amp;quot;/sound/dataErase_action.bksnd&amp;quot; updated&lt;br /&gt;
* error applet:&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/CNzh/&amp;quot; added&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/KRko/&amp;quot; added&lt;br /&gt;
** &amp;quot;/message/TWzh/&amp;quot; added&lt;br /&gt;
** &amp;quot;/sound/error_action.bksnd&amp;quot; updated&lt;br /&gt;
* netConnect applet:&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/CNzh/&amp;quot; added&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/KRko/&amp;quot; added&lt;br /&gt;
** &amp;quot;/message/TWzh/&amp;quot; added&lt;br /&gt;
** &amp;quot;/sound/netConnect_action.bksnd&amp;quot; updated&lt;br /&gt;
* playerSelect applet:&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/CNzh/&amp;quot; added&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/KRko/&amp;quot; added&lt;br /&gt;
** &amp;quot;/message/TWzh/&amp;quot; added&lt;br /&gt;
** &amp;quot;/sound/playerSelect_action.bksnd&amp;quot; updated&lt;br /&gt;
* swkbd applet:&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/CNzh/&amp;quot; added&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/KRko/&amp;quot; added&lt;br /&gt;
** &amp;quot;/message/TWzh/&amp;quot; added&lt;br /&gt;
** &amp;quot;/sound/swkbd_action.bksnd&amp;quot; updated&lt;br /&gt;
* miiEdit (LibraryAppletMiiEdit):&lt;br /&gt;
** &amp;quot;/archive/Gfx.bin.cmp&amp;quot; updated&lt;br /&gt;
** &amp;quot;/archive/Layout.bin.cmp&amp;quot; updated&lt;br /&gt;
** &amp;quot;/archive/Mii.bin.cmp&amp;quot; updated&lt;br /&gt;
** &amp;quot;/archive/Ptcl.bin.cmp&amp;quot; updated&lt;br /&gt;
** &amp;quot;/archive/Shader.bin.cmp&amp;quot; updated&lt;br /&gt;
** &amp;quot;/archive/Yaml.bin.cmp&amp;quot; updated&lt;br /&gt;
** &amp;quot;/message/CNzh/&amp;quot; added&lt;br /&gt;
** &amp;quot;/message/KRko/&amp;quot; added&lt;br /&gt;
** &amp;quot;/message/TWzh/&amp;quot; added&lt;br /&gt;
* [[Internet_Browser|LibAppletShop applet]]: &amp;quot;/buildinfo/buildinfo.dat&amp;quot; updated, &amp;quot;/.nrr/netfront.nrr&amp;quot; updated, &amp;quot;/whitelist/WhitelistEc.txt&amp;quot; updated&lt;br /&gt;
** &amp;quot;/whitelist/WhitelistEc.txt&amp;quot;: &amp;lt;nowiki&amp;gt;&amp;quot;^https://([0-9A-Za-z\-]+\.)*eshop\.nintendo\.net($|/)&amp;quot; was changed to &amp;quot;^https://([0-9A-Za-z\-]+\.)*nintendo\.net(/|$)&amp;quot;&amp;lt;/nowiki&amp;gt;.&lt;br /&gt;
* overlayDisp applet:&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/CNzh/&amp;quot; added&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/KRko/&amp;quot; added&lt;br /&gt;
** &amp;quot;/message/TWzh/&amp;quot; added&lt;br /&gt;
** &amp;quot;/sound/overlayDisp_action.bksnd&amp;quot; updated&lt;br /&gt;
* photoViewer applet:&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/CNzh/&amp;quot; added&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/KRko/&amp;quot; added&lt;br /&gt;
** &amp;quot;/message/TWzh/&amp;quot; added&lt;br /&gt;
** &amp;quot;/sound/photoViewer_action.bksnd&amp;quot; updated&lt;br /&gt;
* [[Internet_Browser|LibAppletOff/LibAppletWeb/LibAppletLns/LibAppletAuth]]: &amp;quot;/buildinfo/buildinfo.dat&amp;quot; updated, &amp;quot;/.nrr/netfront.nrr&amp;quot; updated&lt;br /&gt;
* &amp;quot;starter&amp;quot; application:&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/CNzh/&amp;quot; added&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/KRko/&amp;quot; added&lt;br /&gt;
** &amp;quot;/message/TWzh/&amp;quot; added&lt;br /&gt;
** &amp;quot;/sound/starter_action.bksnd&amp;quot; updated&lt;br /&gt;
* myPage applet:&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/CNzh/&amp;quot; added&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/KRko/&amp;quot; added&lt;br /&gt;
** &amp;quot;/message/TWzh/&amp;quot; added&lt;br /&gt;
** &amp;quot;/sound/myPage_action.bksnd&amp;quot; updated&lt;br /&gt;
* maintenance applet:&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/CNzh/&amp;quot; added&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/KRko/&amp;quot; added&lt;br /&gt;
** &amp;quot;/message/TWzh/&amp;quot; added&lt;br /&gt;
** &amp;quot;/sound/maintenance_action.bksnd&amp;quot; updated&lt;br /&gt;
&lt;br /&gt;
=== BootImagePackages ===&lt;br /&gt;
RomFs changes: all files updated.&lt;br /&gt;
&lt;br /&gt;
====Package1ldr====&lt;br /&gt;
Since [[6.2.0]], the following was changed (besides the usual constant changes for new fuse burnt, incremented version, etc):&lt;br /&gt;
* A function that returns a hardware type now returns 0xF whenever it would previously have returned a non-zero value.&lt;br /&gt;
** Code validating hardware type has been simplified accordingly.&lt;br /&gt;
* The function validating the bootloader version by parsing the BCT no longer hardcodes the BCT address as 0x40000100, and instead adds a relative offset to a BCT address specified via argument.&lt;br /&gt;
* The [[TSEC Firmware#SecureBoot|SecureBoot TSEC firmware]] was updated to prevent SMMU virtualization attacks.&lt;br /&gt;
&lt;br /&gt;
====NX_BOOTLOADER====&lt;br /&gt;
NX bootloader was updated, and is now stored compressed. Before executing, a small stub now uncompresses the bootloader to 0x40004000, size 0x1C000.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
====Secure Monitor====&lt;br /&gt;
The Secure Monitor was updated, and is now stored compressed. Before executing, a small stub now uncompresses the main TrustZone image to 0x7C010800 size 0xC800, and environment setup code to 0x40032000 size 0xC000.&lt;br /&gt;
&lt;br /&gt;
* The 0x100 region used for NX_BOOTLOADER &amp;lt;-&amp;gt; SecureMonitor communications is now 0x40000000 instead of 0x40002E00.&lt;br /&gt;
* Memory permissions for .rodata have been fixed, it is now correctly mapped R-- instead of RW-.&lt;br /&gt;
* Sealed old keys are now stored in the auxilliary data page (0x1F01FA000) instead of in .rwdata.&lt;br /&gt;
** An 0x10 block in the auxilliary page is now used for intermediate key derivation, instead of a block on the stack. This block is only memcleared once at the end, instead of after every time it is used.&lt;br /&gt;
* TrustZone code is now cleared from IRAM before signalling to NX_BOOTLOADER that the SecMon is awake.&lt;br /&gt;
* A function for getting HardwareType based on fuses now returns 0xF whenever it would previously have returned a non-zero value.&lt;br /&gt;
** This function is called by [[SMC|smcGetConfig]] when ConfigItem_HardwareType is passed in.&lt;br /&gt;
* Warmboot.bin has been moved again, and is now copied from 0x4003E000 size 0x17F0 instead of 0x4003D800 size 0x1FF0&lt;br /&gt;
* Code configuring what peripherals to set secure-world only now assumes that the code is a retail unit.&lt;br /&gt;
** GetRetailType() is still called (though result is discarded), this probably means they now have compile-time switches for retail vs dev.&lt;br /&gt;
&lt;br /&gt;
====Warmboot====&lt;br /&gt;
* The firmware revision magic was changed from 0xA8 to 0x129.&lt;br /&gt;
&lt;br /&gt;
====FIRM Sysmodules====&lt;br /&gt;
All FIRM sysmodules were updated. The only FIRM sysmodules with IPC changes were [[Filesystem_services|FS]], [[Process_Manager_services|pm]], and [[NCM_services|NCM]]. Specific diffs for a few sysmodules are below:&lt;br /&gt;
&lt;br /&gt;
=====[[Process Manager services|PM]]=====&lt;br /&gt;
Resource limit initialization was changed:&lt;br /&gt;
* PM now dynamically calculates the number of extra threads available in the kernel&#039;s slab heap compared to the amount it is expecting.&lt;br /&gt;
** A [[Process Manager services#BoostApplicationThreadResourceLimit|new command]] was added to pm:shell to make these extra threads available to applications, on retail this doubles the number of threads creatable to 0xC0.&lt;br /&gt;
&lt;br /&gt;
=====[[Filesystem services|FS]]=====&lt;br /&gt;
* Device Address Space initialization for nn::sdmmc is now handled differently.&lt;br /&gt;
** Previously, the shared SDMMC device address space handle was attached to all devices during global init prior to service registration.&lt;br /&gt;
** Now, the handle is attached to specific devices during their relevant DeviceAccessor::Initialize() call, which only happens when the relevant device is ready for access.&lt;br /&gt;
* (Many other differences not yet reversed/noted here.)&lt;br /&gt;
&lt;br /&gt;
=====[[NCM services|NCM]]=====&lt;br /&gt;
* The ExpHeap used for generic and fs allocations was reduced from 3 MB to 1 MB in size.&lt;br /&gt;
&lt;br /&gt;
=== [[USB_services|usb-sysmodule]] ===&lt;br /&gt;
* New services / commands were added.&lt;br /&gt;
* The codebin now has .json data embedded in the codebin for [[USB_services#HidGamepad|HidGamepad]] USB-devices.&lt;br /&gt;
&lt;br /&gt;
=== [[Account_services|account-sysmodule]] ===&lt;br /&gt;
* Various .text changes. Besides those:&lt;br /&gt;
* The &amp;quot;v4-&amp;lt;hexstr&amp;gt;&amp;quot; URLs were changed to &amp;quot;v5&amp;quot; URLs.&lt;br /&gt;
* User-agent was changed to &amp;quot;libcurl (nnDauth; &amp;lt;hex&amp;gt;; SDK 7.3.0.0)&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;fill this in (manually) later&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==See Also==&lt;br /&gt;
System update report(s):&lt;br /&gt;
* [https://yls8.mtheall.com/ninupdates/reports.php?date=01-28-19_07-05-12&amp;amp;sys=hac]&lt;br /&gt;
&lt;br /&gt;
{{NavboxVersions}}&lt;br /&gt;
&lt;br /&gt;
[[Category:System versions]]&lt;/div&gt;</summary>
		<author><name>Yellows8</name></author>
	</entry>
	<entry>
		<id>https://switchbrew.org/w/index.php?title=5.0.0&amp;diff=14923</id>
		<title>5.0.0</title>
		<link rel="alternate" type="text/html" href="https://switchbrew.org/w/index.php?title=5.0.0&amp;diff=14923"/>
		<updated>2026-08-06T02:44:23Z</updated>

		<summary type="html">&lt;p&gt;Yellows8: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The Switch 5.0.0 system update was released on March 12, 2018. This Switch update was released for the following regions: ALL.&lt;br /&gt;
&lt;br /&gt;
Security flaws fixed: &amp;lt;fill this in manually later, see the updatedetails page from the ninupdates-report page(s) once available for now&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
==Change-log==&lt;br /&gt;
[http://en-americas-support.nintendo.com/app/answers/detail/a_id/22525/p/897 Official] ALL change-log:&lt;br /&gt;
*Added the following system functionality&lt;br /&gt;
:* Facebook and Twitter friends that also use Nintendo Switch can now be added through Friend Suggestions &lt;br /&gt;
::* Friend suggestions are based on the Facebook and Twitter accounts you &#039;&#039;have linked to your Nintendo Account&#039;&#039;&lt;br /&gt;
::* To view your friend suggestions, from the top left of the HOME Menu head to your User Page  &amp;gt; Friend Suggestions&lt;br /&gt;
::* You must be 13 or older to use this feature&lt;br /&gt;
:* Select from 24 new ARMS and the Kirby series icons for your user&lt;br /&gt;
::* To edit your user icon, head to your My Page on the top left of the Home Menu &amp;gt; Profile&lt;br /&gt;
:* Digital software purchases made from a PC or smart device will start downloading sooner than previously, even if the Nintendo Switch console is in Sleep Mode&lt;br /&gt;
:* Filter News to view only unread news or news from specific channels&lt;br /&gt;
:* To keep the Parental Controls PIN private, the default method for PIN entry has been changed to entering using the Control Stick and buttons instead of the on-screen number pad&lt;br /&gt;
::* When prompted to enter you Parental Controls PIN, press and hold the + Button to change between input methods &lt;br /&gt;
:* Captured videos in the Album will be restricted by Parental Controls depending on the Restricted Software setting and Software Rating Organization&lt;br /&gt;
:* &#039;&#039;Using the Nintendo Switch Parental Controls app&#039;&#039;, add specific software titles to your whitelist to exclude them from the console’s Parental Controls Restricted Software setting&lt;br /&gt;
::* Play-Time Limit restrictions will still apply even when the software title has been whitelisted.&lt;br /&gt;
:* Receive notification when pre-purchased software is ready to play&lt;br /&gt;
:* Nintendo Switch Pro Controller grip colors will now display in the Controllers menu&lt;br /&gt;
* General system stability improvements to enhance the user&#039;s experience, including:&lt;br /&gt;
:* Resolved an issue that caused Play Activity to display incorrectly in the Profile section of your User Page&lt;br /&gt;
&lt;br /&gt;
==System Titles==&lt;br /&gt;
All 01000000000010XX titles and most 01000000000008XX titles were updated. Some 8XX titles were just rebuilt with the new NCA crypto without actual RomFS-content changes.&lt;br /&gt;
&lt;br /&gt;
* 0100000000000824(Mariko Config), 0100000000000825, 0100000000000826 were added.&lt;br /&gt;
** 0100000000000824 provides configuration for the new &amp;quot;T214&amp;quot; SoC.&lt;br /&gt;
** 0100000000000825 contains an empty &amp;quot;/blacklist.dat&amp;quot; file.&lt;br /&gt;
** 0100000000000826 contains a 0x40-byte &amp;quot;/version&amp;quot; file, this is all-zero except for &#039;0&#039; at offset 0x20.&lt;br /&gt;
&lt;br /&gt;
The built codebins now have padding in .text after every function for 0x10-byte alignment (and other compiler changes).&lt;br /&gt;
&lt;br /&gt;
The SDK included with titles (main-codebin) for NV changed/updated NVIDIA hw strings:&lt;br /&gt;
&lt;br /&gt;
Previous version:&lt;br /&gt;
  00000000: 4e56 4944 4941 2054 6567 7261 204b 3100  NVIDIA Tegra K1.&lt;br /&gt;
  00000010: 4e56 4944 4941 2054 6567 7261 2058 31    NVIDIA Tegra X1&lt;br /&gt;
&lt;br /&gt;
Current version:&lt;br /&gt;
  00000000: 4e56 4944 4941 2054 6567 7261 2f4e 696e  NVIDIA Tegra/Nin&lt;br /&gt;
  00000010: 7465 6e64 6f20 5377 6974 6368 004e 5649  tendo Switch.NVI&lt;br /&gt;
  00000020: 4449 4120 5465 6772 6120 5832 0047 5031  DIA Tegra X2.GP1&lt;br /&gt;
  00000030: 3042 0047 5031 3036 0047 5031 3036 2d41  0B.GP106.GP106-A&lt;br /&gt;
  00000040: 0047 6546 6f72 6365 2047 5458 2031 3036  .GeForce GTX 106&lt;br /&gt;
  00000050: 3020 3347 4200 4765 466f 7263 6520 4754  0 3GB.GeForce GT&lt;br /&gt;
  00000060: 5820 3130 3630 2036 4742 0047 6546 6f72  X 1060 6GB.GeFor&lt;br /&gt;
  00000070: 6365 2047 5458 2031 3035 3000 4765 466f  ce GTX 1050.GeFo&lt;br /&gt;
  00000080: 7263 6520 4754 5820 3130 3630 0047 6546  rce GTX 1060.GeF&lt;br /&gt;
  00000090: 6f72 6365 2047 5458 2031 3035 3020 5469  orce GTX 1050 Ti&lt;br /&gt;
  000000a0: 0047 5031 3036 474c 2d41 0051 7561 6472  .GP106GL-A.Quadr&lt;br /&gt;
  000000b0: 6f20 5032 3030 3000 4750 3130 362d 4200  o P2000.GP106-B.&lt;br /&gt;
  000000c0: 4750 3130 3647 4c2d 42                   GP106GL-B&lt;br /&gt;
&lt;br /&gt;
[[NPDM]] changes (besides usual version-bump):&lt;br /&gt;
* usb: Acid.Flags updated: 0x1 -&amp;gt; 0x9. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* htc.stub: Acid.Flags updated: 0x1 -&amp;gt; 0x9. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* boot2.ProdBoot: Acid.Flags updated: 0x1 -&amp;gt; 0x9. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* settings: Acid.Flags updated: 0x1 -&amp;gt; 0x9. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* Bus: Acid.Flags updated: 0x1 -&amp;gt; 0x9. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* bluetooth: Acid.Flags updated: 0x1 -&amp;gt; 0x9. Service server access: added bt. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* bcat: Acid.Flags updated: 0x1 -&amp;gt; 0x9. Service access: added dauth:0, srepo:a. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* friends: Acid.Flags updated: 0x1 -&amp;gt; 0x9. Service server access: added nd:app, nd:sys. Service access: added ndd, set. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* nifm: Acid.Flags updated: 0x1 -&amp;gt; 0x9. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* ptm: Acid.Flags updated: 0x1 -&amp;gt; 0x9. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* bsdsocket: Acid.Flags updated: 0x1 -&amp;gt; 0x9. KernelCap ThreadInfo: updated MinCoreNumber = 0x0 -&amp;gt; 0x3. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* hid: MainThreadStackSize updated: 0x2000 -&amp;gt; 0x3000. Acid.Flags updated: 0x1 -&amp;gt; 0x9. Service server access: added hidbus. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* audio: Acid.Flags updated: 0x1 -&amp;gt; 0x9. Service server access: removed audrec:a, audrec:d. Service access: added lm. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* LogManager.Prod: Acid.Flags updated: 0x1 -&amp;gt; 0x9. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* wlan: Acid.Flags updated: 0x1 -&amp;gt; 0x9. Service access: added psm. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* ldn: Acid.Flags updated: 0x1 -&amp;gt; 0x9. Service server access: added ndd. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* nvservices: Acid.Flags updated: 0x1 -&amp;gt; 0xD. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0. SVC access: removed QueryPhysicalAddress.&lt;br /&gt;
* pcv: Acid.Flags updated: 0x1 -&amp;gt; 0x9. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* capmtp: Acid.Flags updated: 0x1 -&amp;gt; 0x9. Service access: removed lm. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* nvnflinger: Acid.Flags updated: 0x1 -&amp;gt; 0x9. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* pcie: Acid.Flags updated: 0x1 -&amp;gt; 0x9. Service access: added set:sys. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* account: Acid.Flags updated: 0x1 -&amp;gt; 0x9. Service server access: added dauth:0. Service access: added ovln:snd, spl:mig. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* ns: Acid.Flags updated: 0x1 -&amp;gt; 0x9. Service access: added erpt:c. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* nfc: Acid.Flags updated: 0x1 -&amp;gt; 0x9. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* psc: Acid.Flags updated: 0x1 -&amp;gt; 0x9. Service server access: added srepo:*. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* capsrv: MainThreadStackSize updated: 0x4000 -&amp;gt; 0x5000. Acid.Flags updated: 0x1 -&amp;gt; 0x9. Fac.FsAccessFlag updated: set bitmask 0x4000000000000000 (Debug (ignored on non-DebugMode, see [[SPL_services#GetConfig|here]])). Service server access: added caps:u. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* am: Acid.Flags updated: 0x1 -&amp;gt; 0x9. Fac.FsAccessFlag updated: set bitmask 0x0000000080000000 (DeviceDetection). Service server access: added tcap. Service access: added acc:u1, pdm:qry. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0. SVC access: added MapPhysicalMemoryUnsafe, UnmapPhysicalMemoryUnsafe.&lt;br /&gt;
* ssl: Acid.Flags updated: 0x1 -&amp;gt; 0x9. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* nim: Acid.Flags updated: 0x1 -&amp;gt; 0x9. Service server access: added nim:eca. Service access: added arp:r, dauth:0, srepo:u. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0. SVC access: added MapTransferMemory, UnmapTransferMemory.&lt;br /&gt;
* lbl: Acid.Flags updated: 0x1 -&amp;gt; 0x9. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* btm: Acid.Flags updated: 0x1 -&amp;gt; 0x9. Service server access: added btm:u. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* erpt: Acid.Flags updated: 0x1 -&amp;gt; 0x9. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* vi: Acid.Flags updated: 0x1 -&amp;gt; 0xD. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0. KernelCap HandleTableSize: updated HandleTableSize = 0x80 -&amp;gt; 0xA0. SVC access: added MapTransferMemory, UnmapTransferMemory.&lt;br /&gt;
* pctl: Acid.Flags updated: 0x1 -&amp;gt; 0x9. Service access: added dauth:0. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* npns: Acid.Flags updated: 0x1 -&amp;gt; 0x9. Service access: added arp:r, dauth:0. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* eupld: Acid.Flags updated: 0x1 -&amp;gt; 0x9. Service access: added bgtc:t, dauth:0. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* glue: Acid.Flags updated: 0x1 -&amp;gt; 0x9. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* eclct: Acid.Flags updated: 0x1 -&amp;gt; 0x9. Fac.FsAccessFlag updated: set bitmask 0x0000000000100000 (SystemData). Service access: added erpt:r, fsp-srv, omm, time:u. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* es: Acid.Flags updated: 0x5 -&amp;gt; 0x9. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* fatal: Acid.Flags updated: 0x1 -&amp;gt; 0x9. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* grc: Acid.Flags updated: 0x1 -&amp;gt; 0x9. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* creport: Acid.Flags updated: 0x1 -&amp;gt; 0x9. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* ro: Acid.Flags updated: 0x1 -&amp;gt; 0x9. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* sdb: Acid.Flags updated: 0x1 -&amp;gt; 0x9. Fac.SaveDataOwnerInfo added 0100000000001009 (miiEdit) access 0x3 (RW). Service server access: added miiimg. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* migration: Acid.Flags updated: 0x1 -&amp;gt; 0x9. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* jpegdec: Acid.Flags updated: 0x1 -&amp;gt; 0x9. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* safemode: Acid.Flags updated: 0x1 -&amp;gt; 0x9. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* qlaunch: Acid.Flags updated: 0x1 -&amp;gt; 0x5. Service access: added miiimg. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* auth: Acid.Flags updated: 0x1 -&amp;gt; 0x5. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* cabinet: Acid.Flags updated: 0x1 -&amp;gt; 0x5. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* controller: Acid.Flags updated: 0x1 -&amp;gt; 0x5. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* dataErase: Acid.Flags updated: 0x1 -&amp;gt; 0x5. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* error: Acid.Flags updated: 0x1 -&amp;gt; 0x5. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* netConnect: Acid.Flags updated: 0x1 -&amp;gt; 0x5. Service access: added ntc. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* playerSelect: Acid.Flags updated: 0x1 -&amp;gt; 0x5. Service access: added miiimg. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* swkbd: Acid.Flags updated: 0x1 -&amp;gt; 0x5. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* miiEdit: Acid.Flags updated: 0x1 -&amp;gt; 0x5. Service access: added miiimg. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* LibAppletWeb: Acid.Flags updated: 0x1 -&amp;gt; 0x5. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* LibAppletShop: Acid.Flags updated: 0x1 -&amp;gt; 0x5. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* overlayDisp: Acid.Flags updated: 0x1 -&amp;gt; 0x5. Service access: added erpt:c. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* photoViewer: Acid.Flags updated: 0x1 -&amp;gt; 0x5. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* LibAppletOff: Acid.Flags updated: 0x1 -&amp;gt; 0x5. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* LibAppletLns: Acid.Flags updated: 0x1 -&amp;gt; 0x5. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* LibAppletAuth: Acid.Flags updated: 0x1 -&amp;gt; 0x5. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* &amp;quot;starter&amp;quot; application: KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* myPage: Acid.Flags updated: 0x1 -&amp;gt; 0x5. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
* maintenance: Acid.Flags updated: 0x1 -&amp;gt; 0x5. KernelCap KernelVersion: updated Version = 6.0 -&amp;gt; 9.0.&lt;br /&gt;
&lt;br /&gt;
RomFs changes:&lt;br /&gt;
* [[System_Version_Title|SystemVersion]]: All files updated.&lt;br /&gt;
* [[System_Settings|FirmwareDebugSettings]]: All files updated.&lt;br /&gt;
* 801 (Support Error Codes)&lt;br /&gt;
* 803 (web-applet &amp;quot;shareddata:/&amp;quot;)&lt;br /&gt;
* 804 (HTML resources for &amp;quot;Intellectual Property Notices&amp;quot; / &amp;quot;Health &amp;amp; Safety Information&amp;quot;)&lt;br /&gt;
** &amp;quot;/legallines.htdocs/index.html&amp;quot; was updated with a Twitter mention, and a license section for &amp;quot;Software License for The Fraunhofer FDK AAC Codec Library for Android&amp;quot; was added.&lt;br /&gt;
** &amp;quot;/safe.htdocs/html/EU{XX}/index.html&amp;quot; was updated.&lt;br /&gt;
* 806 (Bad words)&lt;br /&gt;
* 807 ([[Hotspot List]])&lt;br /&gt;
** This was updated with more hotspots (these networks use encryption): &amp;quot;nintendoappdebug1&amp;quot;, &amp;quot;Nintendo App Debug2&amp;quot;, &amp;quot;Nintendo App Debug3&amp;quot;, and &amp;quot;NCL-NZSERVICE1-5GHZ&amp;quot;.&lt;br /&gt;
* 80A (Chara)&lt;br /&gt;
* 80B (Offline news)&lt;br /&gt;
* 80E (Geo Zoneinfo)&lt;br /&gt;
* 810-814 (All fonts)&lt;br /&gt;
* 818 (System-config)&lt;br /&gt;
* 81E (Controller gfx/icon data + dummy file)&lt;br /&gt;
** &amp;quot;/lyt/ColorTable&amp;quot; and &amp;quot;/lyt/footer/controllerIcon.bntx&amp;quot; were updated. The &amp;quot;01-00&amp;quot; image showing handheld-mode with detached joy-cons was replaced with a blank image.&lt;br /&gt;
* 81F (Icosa system config)&lt;br /&gt;
* 820 (Copper system config)&lt;br /&gt;
* 821 (Hoag system config)&lt;br /&gt;
* 822 (Firmware binaries for peripherals)&lt;br /&gt;
** The following was updated: &amp;quot;FirmwareInfo.csv&amp;quot;, &amp;quot;tera_ota.bin&amp;quot;, &amp;quot;tera_ota_iap.bin&amp;quot;, and &amp;quot;ukyosakyo_ep2_ota.bin&amp;quot;.&lt;br /&gt;
* 823&lt;br /&gt;
&lt;br /&gt;
=== BootImagePackages ===&lt;br /&gt;
RomFs changes:&lt;br /&gt;
* &amp;quot;/a/&amp;quot; added, &amp;quot;/nx/bct&amp;quot; updated, &amp;quot;/nx/package1&amp;quot; updated, &amp;quot;/nx/package1.dec&amp;quot; updated, &amp;quot;/nx/package2&amp;quot; updated&lt;br /&gt;
&lt;br /&gt;
[[Package2|INI1]] changes:&lt;br /&gt;
* BootImagePackage: &lt;br /&gt;
** 0100000000000000 (FS): KernelCap HandleTableSize: updated HandleTableSize = 0x80 -&amp;gt; 0x100. SVC access: added GetSystemInfo, removed QueryPhysicalAddress.&lt;br /&gt;
** 0100000000000003 (ProcessMana): SVC access: added SetUnsafeLimit, GetSystemInfo.&lt;br /&gt;
** 0100000000000004 (sm): SVC access: added GetSystemInfo.&lt;br /&gt;
* BootImagePackageSafe: &lt;br /&gt;
** 0100000000000000 (FS): KernelCap HandleTableSize: updated HandleTableSize = 0x80 -&amp;gt; 0x100. SVC access: added GetSystemInfo, removed QueryPhysicalAddress.&lt;br /&gt;
** 0100000000000003 (ProcessMana): SVC access: added SetUnsafeLimit, GetSystemInfo.&lt;br /&gt;
** 0100000000000004 (sm): SVC access: added GetSystemInfo.&lt;br /&gt;
* BootImagePackageExFat: &lt;br /&gt;
** 0100000000000000 (FS): KernelCap HandleTableSize: updated HandleTableSize = 0x80 -&amp;gt; 0x100. SVC access: added GetSystemInfo, removed QueryPhysicalAddress.&lt;br /&gt;
** 0100000000000003 (ProcessMana): SVC access: added SetUnsafeLimit, GetSystemInfo.&lt;br /&gt;
** 0100000000000004 (sm): SVC access: added GetSystemInfo.&lt;br /&gt;
* BootImagePackageExFatSafe: &lt;br /&gt;
** 0100000000000000 (FS): KernelCap HandleTableSize: updated HandleTableSize = 0x80 -&amp;gt; 0x100. SVC access: added GetSystemInfo, removed QueryPhysicalAddress.&lt;br /&gt;
** 0100000000000003 (ProcessMana): SVC access: added SetUnsafeLimit, GetSystemInfo.&lt;br /&gt;
** 0100000000000004 (sm): SVC access: added GetSystemInfo.&lt;br /&gt;
&lt;br /&gt;
A new folder &amp;quot;a&amp;quot; was added, in addition to the existing &amp;quot;nx&amp;quot; folder, containing a separate &amp;quot;bct&amp;quot; and &amp;quot;package1&amp;quot;. Both of these seem encrypted/meant for the new &amp;quot;Mariko&amp;quot; hardware that support was added for.&lt;br /&gt;
&lt;br /&gt;
====Secure Monitor====&lt;br /&gt;
The [[Memory_layout|Memory layout]] was changed significantly:&lt;br /&gt;
* .text, .rodata, and .data are now separate sections, mapped with correct permissions (RX, RO, RW, respectively), instead of being mapped RWX.&lt;br /&gt;
* Physical layout in TZRAM changed significantly, with pk2ldr being in low TZRAM instead of high TZRAM, etc.&lt;br /&gt;
&lt;br /&gt;
In addition, there were changes to the [[SMC]] interface:&lt;br /&gt;
&lt;br /&gt;
* smcGenerateSpecificAesKey was updated to support generating previous 4.x+ device key(s). &lt;br /&gt;
* smcLoadSecureExpModKey/smcLoadRsaOaepKey/smcDecryptRsaPrivateKey no longer exist.&lt;br /&gt;
* smcLoadRsaOaepKey was replaced with smcEncryptRsaPrivateKeyForImport.&lt;br /&gt;
* smcDecryptRsaPrivateKey was replaced with smcDecryptOrImportRsaPrivateKey.&lt;br /&gt;
** All keys which were previously imported with specific keys now first call smcEncryptRsaPrivateKeyForImport with the appopriate enum member to get a sealed copy of the RSA key, then smcDecryptOrImportRsaPrivateKey to import/unseal the key when needed.&lt;br /&gt;
* smcGetConfig was extended with two new config items:&lt;br /&gt;
** GetConfig(16), which seems to check whether the Switch is running on a Tegra 210:&lt;br /&gt;
    return (FUSE_RESERVED_ODM4 &amp;amp; 0x800) &amp;amp;&amp;amp;  FUSE_RESERVED_ODM0 == 0x8E61ECAE &amp;amp;&amp;amp;  FUSE_RESERVED_ODM1  == 0xF2BA3BB2 ?  (FUSE_RESERVED_ODM2 &amp;amp; 0x1F) : 0&lt;br /&gt;
** Getconfig(17), which returns the Package2 hash if booting from recovery mode.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;fill in the rest later&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Kernel====&lt;br /&gt;
* Kernel Address Space Layout Randomization was added.&lt;br /&gt;
** Instead of using a hardcoded address for per-CPU region, they now use x18 to point to the per-CPU region.&lt;br /&gt;
* When using most [[SMC]]s, IRQs are now disabled first then restored to original state afterwards. x18 is also reinitialized right after most SMCs (see above).&lt;br /&gt;
* 5 new syscalls.&lt;br /&gt;
** Syscalls 0x48+0x49 (svcAllocateUserHeapMemory+svcFreeUserHeapMemory) are used by [[AM_services|AM]]-sysmodule.&lt;br /&gt;
*** This is used to allocate Application pool.&lt;br /&gt;
** Syscall 0x4A (svcSetUserHeapMemoryAllocationMax) is used by [[Process_Manager_services|PM]]-sysmodule.&lt;br /&gt;
*** This allows PM to set a limit on the number of bytes AM can allocate from Application pool.&lt;br /&gt;
** Syscall 0x6F (svcGetMemoryInfo) is used by FS, SM, and PM.&lt;br /&gt;
** Syscall 0x2E (svcGetNextThreadInfo) was added, but it only works on dev units.&lt;br /&gt;
*** Allows fetching how many bytes free/occupied by the different pools.&lt;br /&gt;
** svcControlCodeMemory was [[SVC#svcControlCodeMemory|updated]].&lt;br /&gt;
* NPDM irq_id&#039;s are no longer checked to be &amp;lt; 0x100, instead max-value is loaded from per-cpu state.&lt;br /&gt;
* The order slabheaps are laid out in memory is now randomized.&lt;br /&gt;
* There are now 4 memory pool partitions.&lt;br /&gt;
** This fixes sysmodule takeover with GMMU hax.&lt;br /&gt;
&lt;br /&gt;
===[[Internet Browser]]===&lt;br /&gt;
OSS/WebKit was updated.&lt;br /&gt;
&lt;br /&gt;
In the [[NPDM]], besides the RSA region the only changes were the kernel-release-version descriptor + {new ACID flag is set}.&lt;br /&gt;
&lt;br /&gt;
In the &amp;quot;shareddata:/&amp;quot; title, the NROs are now compressed: &amp;quot;{name}.nro.lz4&amp;quot; instead of &amp;quot;{name}.nro&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
===[[qlaunch]]===&lt;br /&gt;
RomFS changes:&lt;br /&gt;
* &amp;quot;/common/shader/VarietyOceanShader_Nx.arc.szs&amp;quot; updated&lt;br /&gt;
* &amp;quot;/lyt/common.szs&amp;quot; updated&lt;br /&gt;
* &amp;quot;/lyt/DummyGameA.szs&amp;quot; and &amp;quot;/lyt/DummyGame.szs&amp;quot; were removed.&lt;br /&gt;
* &amp;quot;/lyt/Entrance.szs&amp;quot; updated&lt;br /&gt;
* &amp;quot;/lyt/Eula.szs&amp;quot; added&lt;br /&gt;
* &amp;quot;/lyt/Flaunch.szs&amp;quot; updated&lt;br /&gt;
* &amp;quot;/lyt/Gift.szs&amp;quot; updated&lt;br /&gt;
* &amp;quot;/lyt/Interrupt.szs&amp;quot; updated&lt;br /&gt;
* &amp;quot;/lyt/Migration.szs&amp;quot; updated&lt;br /&gt;
* &amp;quot;/lyt/Notification.szs&amp;quot; updated&lt;br /&gt;
* &amp;quot;/lyt/Option.szs&amp;quot;&lt;br /&gt;
* &amp;quot;/lyt/ResidentMenu.szs&amp;quot;&lt;br /&gt;
* &amp;quot;/lyt/Set.szs&amp;quot;&lt;br /&gt;
* &amp;quot;/message/&amp;quot; Everything under here was updated.&lt;br /&gt;
* &amp;quot;/message/Ocean.msbp.szs&amp;quot; added&lt;br /&gt;
* &amp;quot;/sound/qlaunch_action.bksnd&amp;quot; and &amp;quot;/sound/qlaunch.bfsar&amp;quot; were updated.&lt;br /&gt;
* &amp;quot;/texture&amp;quot; Directory was added, which contains images for Nintendo Switch Parental Controls:&lt;br /&gt;
** &amp;quot;IcoPctl.bntx&amp;quot;&lt;br /&gt;
** &amp;quot;LogoMoon{region/language-text}.bntx&amp;quot;, for every region/language.&lt;br /&gt;
&lt;br /&gt;
===System Config===&lt;br /&gt;
New fields were added to [[Settings_services#System_Config|System Config]].&lt;br /&gt;
&lt;br /&gt;
==[[NPDM]]==&lt;br /&gt;
New flags bit2/bit3 were added to the flags at ACID+0xC.&lt;br /&gt;
&lt;br /&gt;
==Keys==&lt;br /&gt;
[[Flash_Filesystem|Keyblob]] 5 is now used, instead of 4. New NCA keydata is now used as well.&lt;br /&gt;
&lt;br /&gt;
==See Also==&lt;br /&gt;
System update report(s):&lt;br /&gt;
* [https://yls8.mtheall.com/ninupdates/reports.php?date=03-12-18_08-05-11&amp;amp;sys=hac]&lt;br /&gt;
&lt;br /&gt;
{{NavboxVersions}}&lt;br /&gt;
&lt;br /&gt;
[[Category:System versions]]&lt;/div&gt;</summary>
		<author><name>Yellows8</name></author>
	</entry>
	<entry>
		<id>https://switchbrew.org/w/index.php?title=12.1.0&amp;diff=14922</id>
		<title>12.1.0</title>
		<link rel="alternate" type="text/html" href="https://switchbrew.org/w/index.php?title=12.1.0&amp;diff=14922"/>
		<updated>2026-08-06T02:20:22Z</updated>

		<summary type="html">&lt;p&gt;Yellows8: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The Switch 12.1.0 system update was released on July 6, 2021 (UTC). This Switch update was released for the following regions: ALL.&lt;br /&gt;
&lt;br /&gt;
Security flaws fixed: yes.&lt;br /&gt;
&lt;br /&gt;
==Change-log==&lt;br /&gt;
[https://en-americas-support.nintendo.com/app/answers/detail/a_id/22525/kw/nintendo%20switch%20system%20update Official] ALL change-log:&lt;br /&gt;
* Added the following system functionality:&lt;br /&gt;
* 	&lt;br /&gt;
*       If there is not enough space remaining on the system memory (internal storage) or microSD card when downloading game software update data, you can now delete old data for that software, enabling you to download the new data.&lt;br /&gt;
*       	&lt;br /&gt;
*           When deleting the old data, you won&#039;t be able to play the game until the new data has finished downloading.&lt;br /&gt;
*         &lt;br /&gt;
*       &lt;br /&gt;
*     &lt;br /&gt;
* General system stability improvements have been made to enhance the user&#039;s experience.&lt;br /&gt;
&lt;br /&gt;
==System Titles==&lt;br /&gt;
* Every sysmodule (besides stubs) were updated.&lt;br /&gt;
* All SystemData was updated, except for the Dictionary titles, AvatarImage, Eula, ControllerIcon, ApplicationBlackList, FunctionBlackList.&lt;br /&gt;
* All applets were updated, except for LibraryAppletCabinet, LibraryAppletSwkbd, LibraryAppletMiiEdit.&lt;br /&gt;
&lt;br /&gt;
The only NPDM changes besides the usual version-bump was adding [[SPL_services|csrng]] service access to the [[Internet_browser|web-applets]]: LibAppletWeb, LibAppletShop, LibAppletOff, LibAppletLns, LibAppletAuth.&lt;br /&gt;
&lt;br /&gt;
There were no sysmodule IPC changes.&lt;br /&gt;
&lt;br /&gt;
The ssl sysmodule codebin was not changed.&lt;br /&gt;
&lt;br /&gt;
RomFs changes:&lt;br /&gt;
* ErrorMessage: updated&lt;br /&gt;
* BrowserDll:&lt;br /&gt;
** &amp;quot;/browser/certBlocklistCommon.json&amp;quot; added&lt;br /&gt;
** &amp;quot;/browser/ErrorPageTemplate.html&amp;quot; updated&lt;br /&gt;
** &amp;quot;/browser/MediaControlsInline.css&amp;quot; updated&lt;br /&gt;
** &amp;quot;/browser/MediaControlsInline.js&amp;quot; updated&lt;br /&gt;
** &amp;quot;/browser/RootCaEtc.pem&amp;quot; updated&lt;br /&gt;
** &amp;quot;/buildinfo/buildinfo.dat&amp;quot; updated&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/nro/netfront/core_0/&amp;quot; added&lt;br /&gt;
** &amp;quot;/nro/netfront/core_1/&amp;quot; added&lt;br /&gt;
** &amp;quot;/nro/netfront/dll_0/&amp;quot; removed&lt;br /&gt;
** &amp;quot;/nro/netfront/dll_1/&amp;quot; removed&lt;br /&gt;
* Help: &amp;quot;/legallines.htdocs/index.html&amp;quot; updated&lt;br /&gt;
* [[System_Version_Title|SystemVersion]]: All files updated.&lt;br /&gt;
* LocalNews:&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
* UrlBlackList: &amp;quot;/listLnsChina.txt&amp;quot; updated&lt;br /&gt;
* ControllerFirmware: &amp;quot;/FirmwareInfo.csv&amp;quot; updated, &amp;quot;/ukyosakyo_ep2_ota.bin&amp;quot; updated&lt;br /&gt;
* RebootlessSystemUpdateVersion: All files updated.&lt;br /&gt;
* qlaunch applet:&lt;br /&gt;
** &amp;quot;/common/shader/VarietyOceanShader_Nx.arc.szs&amp;quot; updated&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/sound/qlaunch_action.bksnd&amp;quot; updated&lt;br /&gt;
* auth applet:&lt;br /&gt;
** &amp;quot;/common/shader/VarietyOceanShader_Nx.arc.szs&amp;quot; updated&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
* controller applet:&lt;br /&gt;
** &amp;quot;/common/shader/VarietyOceanShader_Nx.arc.szs&amp;quot; updated&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/sound/controller_action.bksnd&amp;quot; updated&lt;br /&gt;
* dataErase applet:&lt;br /&gt;
** &amp;quot;/common/shader/VarietyOceanShader_Nx.arc.szs&amp;quot; updated&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
* error applet:&lt;br /&gt;
** &amp;quot;/common/shader/VarietyOceanShader_Nx.arc.szs&amp;quot; updated&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
* netConnect applet:&lt;br /&gt;
** &amp;quot;/common/shader/VarietyOceanShader_Nx.arc.szs&amp;quot; updated&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
* playerSelect applet:&lt;br /&gt;
** &amp;quot;/common/shader/VarietyOceanShader_Nx.arc.szs&amp;quot; updated&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
* overlayDisp applet:&lt;br /&gt;
** &amp;quot;/common/shader/SimpleShader_Nx.arc.szs&amp;quot; updated&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
* photoViewer applet:&lt;br /&gt;
** &amp;quot;/common/shader/VarietyOceanShader_Nx.arc.szs&amp;quot; updated&lt;br /&gt;
** &amp;quot;/http/js/index.js&amp;quot; updated&lt;br /&gt;
** &amp;quot;/http/styles/index.css&amp;quot; updated&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/sound/photoViewer_action.bksnd&amp;quot; updated&lt;br /&gt;
* [[Internet_Browser|LibAppletOff/LibAppletWeb/LibAppletShop/LibAppletLns/LibAppletAuth]]: &amp;quot;/buildinfo/buildinfo.dat&amp;quot; updated, &amp;quot;/.nrr/dll.nrr&amp;quot; was renamed to &amp;quot;/.nrr/modules.nrr&amp;quot;&lt;br /&gt;
* &amp;quot;starter&amp;quot; application:&lt;br /&gt;
** &amp;quot;/common/shader/VarietyOceanShader_Nx.arc.szs&amp;quot; updated&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
* myPage applet:&lt;br /&gt;
** &amp;quot;/common/shader/VarietyOceanShader_Nx.arc.szs&amp;quot; updated&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/sound/myPage_action.bksnd&amp;quot; updated&lt;br /&gt;
* maintenance applet:&lt;br /&gt;
** &amp;quot;/common/shader/VarietyOceanShader_Nx.arc.szs&amp;quot; updated&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/sound/maintenance_action.bksnd&amp;quot; updated&lt;br /&gt;
&lt;br /&gt;
=== BootImagePackages ===&lt;br /&gt;
RomFs changes: all files updated.&lt;br /&gt;
&lt;br /&gt;
===[[USB_services|usb]]===&lt;br /&gt;
The only change was updating the [[USB_services#HidGamepad|json]].&lt;br /&gt;
&lt;br /&gt;
===[[Bluetooth_Driver_services|bluetooth]]===&lt;br /&gt;
The func for [[Bluetooth_Driver_services#DisableBluetooth|DisableBluetooth]] was updated. Two funcs which handle [[Bluetooth_Driver_services#FatalReason|FatalReason]] no longer clear a global state field.&lt;br /&gt;
&lt;br /&gt;
The remaining changes fixed IPC cmd [[Switch_System_Flaws|vulns]].&lt;br /&gt;
&lt;br /&gt;
===[[Internet_Browser|Web-applets]]===&lt;br /&gt;
The [[11.0.0|CFI]] code was updated.&lt;br /&gt;
&lt;br /&gt;
The add/sub instruction was replaced with eor. Hence, the additional code at func entry/exit is now identical. The code now does:&lt;br /&gt;
* The low 40-bits of x30 are extracted, then multiplied with x18.&lt;br /&gt;
* &amp;lt;code&amp;gt;crc32x w17, w16, x17&amp;lt;/code&amp;gt; (which uses the above value - x16 was set to sp after the above bitfield-extract)&lt;br /&gt;
* x17 is multiplied with x18 again.&lt;br /&gt;
* &amp;lt;code&amp;gt;crc32x w17, wzr, x17&amp;lt;/code&amp;gt;&lt;br /&gt;
* Then lastly the eor instruction is used with x30, with x17 shifted to bit40.&lt;br /&gt;
&lt;br /&gt;
A vuln with RNG was [[Switch_System_Flaws|fixed]].&lt;br /&gt;
&lt;br /&gt;
==See Also==&lt;br /&gt;
System update report(s):&lt;br /&gt;
* [https://yls8.mtheall.com/ninupdates/reports.php?date=2021-07-06_00-05-06&amp;amp;sys=hac]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{NavboxVersions}}&lt;br /&gt;
&lt;br /&gt;
[[Category:System versions]]&lt;/div&gt;</summary>
		<author><name>Yellows8</name></author>
	</entry>
	<entry>
		<id>https://switchbrew.org/w/index.php?title=9.1.0&amp;diff=14921</id>
		<title>9.1.0</title>
		<link rel="alternate" type="text/html" href="https://switchbrew.org/w/index.php?title=9.1.0&amp;diff=14921"/>
		<updated>2026-08-06T02:14:27Z</updated>

		<summary type="html">&lt;p&gt;Yellows8: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The Switch 9.1.0 system update was released on December 4, 2019. This Switch update was released for the following regions: ALL.&lt;br /&gt;
&lt;br /&gt;
Security flaws fixed: yes.&lt;br /&gt;
&lt;br /&gt;
==Change-log==&lt;br /&gt;
[https://en-americas-support.nintendo.com/app/answers/detail/a_id/22525/kw/nintendo%20switch%20system%20update Official] ALL change-log:&lt;br /&gt;
*  General system stability improvements to enhance the user&#039;s experience, including a solution for the following:&lt;br /&gt;
* 	&lt;br /&gt;
* 	Resolved an issue where the color animation was not displaying correctly when attaching a Joy-Con controller to the Nintendo Switch console.&lt;br /&gt;
* 	&lt;br /&gt;
&lt;br /&gt;
See the [https://www.nintendoswitch.com.cn/support/system_update/index.html official] China changelog for the China-specific changelog.&lt;br /&gt;
&lt;br /&gt;
==System Titles==&lt;br /&gt;
The following was updated:&lt;br /&gt;
* All applets.&lt;br /&gt;
* Sysmodules: [[BCAT_services|bcat]], [[Friend_services|friends]], [[Network_Interface_services|nifm]], [[Sockets_services|bsdsockets]], [[HID_services|hid]], [[WLAN_services|wlan]], [[LDN_services|ldn]], [[Account_services|account]], [[NS_Services|ns]], [[NFC_services|nfc]], [[Applet_Manager_services|am]], [[NIM_services|nim]], [[Error_Report_services|erpt]], [[creport]], [[RO_services|ro]], [[Migration_services|migration]], [[OLSC_services|olsc]], and [[NGCT_services|ngct]].&lt;br /&gt;
* SystemData (besides the sysver SystemData): ErrorMessage, BrowserDll, Help, SharedFont, LocalNews, Eula, FirmwareDebugSettings, all BootImagePackages, PlatformConfigIcosa, PlatformConfigCopper, PlatformConfigHoag, PlatformConfigIcosaMariko, and NgWordT.&lt;br /&gt;
&lt;br /&gt;
See [[Services_API]] for the new lp2p:m service.&lt;br /&gt;
&lt;br /&gt;
NPDM changes:&lt;br /&gt;
* migration: Now has access to srepo:u.&lt;br /&gt;
* The following now have access to the new lp2p:m service: qlaunch, LibraryAppletCabinet, LibraryAppletController, LibraryAppletNetConnect, LibraryAppletPlayerSelect, LibraryAppletMiiEdit, all web-applets except for LibraryAppletOfflineWeb, OverlayApplet, and LibraryAppletMyPage.&lt;br /&gt;
&lt;br /&gt;
RomFs changes:&lt;br /&gt;
* ErrorMessage: updated&lt;br /&gt;
* BrowserDll:&lt;br /&gt;
** &amp;quot;/buildinfo/buildinfo.dat&amp;quot; updated&lt;br /&gt;
** &amp;quot;/dll_0/cairo_wkc.nro.lz4&amp;quot; updated&lt;br /&gt;
** &amp;quot;/dll_0/libfont.nro.lz4&amp;quot; updated&lt;br /&gt;
** &amp;quot;/dll_0/oss_wkc.nro.lz4&amp;quot; updated&lt;br /&gt;
** &amp;quot;/dll_0/peer_wkc.nro.lz4&amp;quot; updated&lt;br /&gt;
** &amp;quot;/dll_0/webkit_wkc.nro.lz4&amp;quot; updated&lt;br /&gt;
** &amp;quot;/dll_1/cairo_wkc.nro.lz4&amp;quot; updated&lt;br /&gt;
** &amp;quot;/dll_1/libfont.nro.lz4&amp;quot; updated&lt;br /&gt;
** &amp;quot;/dll_1/oss_wkc.nro.lz4&amp;quot; updated&lt;br /&gt;
** &amp;quot;/dll_1/peer_wkc.nro.lz4&amp;quot; updated&lt;br /&gt;
** &amp;quot;/dll_1/webkit_wkc.nro.lz4&amp;quot; updated&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
* Help: &amp;quot;/safe.htdocs/html/USen/index.html&amp;quot; updated, &amp;quot;/safe.htdocs/html/USen/page_02.html&amp;quot; updated, &amp;quot;/safe.htdocs/html/USes/index.html&amp;quot; updated, &amp;quot;/safe.htdocs/html/USes/page_02.html&amp;quot; updated, &amp;quot;/safe.htdocs/html/USfr/index.html&amp;quot; updated, &amp;quot;/safe.htdocs/html/USfr/page_02.html&amp;quot; updated&lt;br /&gt;
* Chinese and Korean dictionaries: &amp;quot;/Iwnn/ZH/TW/bopomofo/keisei/njtan.ad1&amp;quot; updated, &amp;quot;/Iwnn/ZH/TW/bopomofo/njtan.a&amp;quot; updated, &amp;quot;/Iwnn/ZH/TW/bopomofo/no_keisei/njtan.ad1&amp;quot; updated&lt;br /&gt;
* [[System_Version_Title|SystemVersion]]: All files updated.&lt;br /&gt;
* LocalNews: &amp;quot;/message/CNzhT/localNews.msbt.szs&amp;quot; updated, &amp;quot;/message/revision.txt&amp;quot; updated, &amp;quot;/message/TWzh/localNews.msbt.szs&amp;quot; updated&lt;br /&gt;
* [[System_Settings|FirmwareDebugSettings/PlatformConfigIcosa/PlatformConfigHoag/PlatformConfigIcosaMariko]]: All files updated.&lt;br /&gt;
* RebootlessSystemUpdateVersion: All files updated.&lt;br /&gt;
* NgWordT: All files updated.&lt;br /&gt;
* qlaunch applet:&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/sound/qlaunch_action.bksnd&amp;quot; updated&lt;br /&gt;
* auth applet: &amp;quot;/message/EUes/common.msbt.szs&amp;quot; updated, &amp;quot;/message/EUfr/common.msbt.szs&amp;quot; updated, &amp;quot;/message/EUit/common.msbt.szs&amp;quot; updated, &amp;quot;/message/EUpt/common.msbt.szs&amp;quot; updated, &amp;quot;/message/Ocean.msbp.szs&amp;quot; updated&lt;br /&gt;
* cabinet applet: &amp;quot;/message/EUes/common.msbt.szs&amp;quot; updated, &amp;quot;/message/EUfr/common.msbt.szs&amp;quot; updated, &amp;quot;/message/EUit/common.msbt.szs&amp;quot; updated, &amp;quot;/message/EUpt/common.msbt.szs&amp;quot; updated, &amp;quot;/message/Ocean.msbp.szs&amp;quot; updated&lt;br /&gt;
* controller applet:&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/sound/controller_action.bksnd&amp;quot; updated&lt;br /&gt;
* dataErase applet: &amp;quot;/message/EUes/common.msbt.szs&amp;quot; updated, &amp;quot;/message/EUfr/common.msbt.szs&amp;quot; updated, &amp;quot;/message/EUit/common.msbt.szs&amp;quot; updated, &amp;quot;/message/EUpt/common.msbt.szs&amp;quot; updated, &amp;quot;/message/Ocean.msbp.szs&amp;quot; updated&lt;br /&gt;
* error applet: &amp;quot;/message/EUes/common.msbt.szs&amp;quot; updated, &amp;quot;/message/EUfr/common.msbt.szs&amp;quot; updated, &amp;quot;/message/EUit/common.msbt.szs&amp;quot; updated, &amp;quot;/message/EUpt/common.msbt.szs&amp;quot; updated, &amp;quot;/message/Ocean.msbp.szs&amp;quot; updated&lt;br /&gt;
* netConnect applet:&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/sound/netConnect_action.bksnd&amp;quot; updated&lt;br /&gt;
* playerSelect applet:&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/sound/playerSelect_action.bksnd&amp;quot; updated&lt;br /&gt;
* swkbd applet: &amp;quot;/message/EUes/common.msbt.szs&amp;quot; updated, &amp;quot;/message/EUfr/common.msbt.szs&amp;quot; updated, &amp;quot;/message/EUit/common.msbt.szs&amp;quot; updated, &amp;quot;/message/EUpt/common.msbt.szs&amp;quot; updated, &amp;quot;/message/Ocean.msbp.szs&amp;quot; updated&lt;br /&gt;
* overlayDisp applet: &amp;quot;/lyt/MiniSet.szs&amp;quot; updated, &amp;quot;/message/EUes/common.msbt.szs&amp;quot; updated, &amp;quot;/message/EUfr/common.msbt.szs&amp;quot; updated, &amp;quot;/message/EUit/common.msbt.szs&amp;quot; updated, &amp;quot;/message/EUpt/common.msbt.szs&amp;quot; updated, &amp;quot;/message/TWzh/overlayDisp.msbt.szs&amp;quot; updated&lt;br /&gt;
* photoViewer applet: &amp;quot;/message/EUes/common.msbt.szs&amp;quot; updated, &amp;quot;/message/EUfr/common.msbt.szs&amp;quot; updated, &amp;quot;/message/EUit/common.msbt.szs&amp;quot; updated, &amp;quot;/message/EUpt/common.msbt.szs&amp;quot; updated, &amp;quot;/message/Ocean.msbp.szs&amp;quot; updated&lt;br /&gt;
* [[Internet_Browser|LibAppletOff/LibAppletWeb/LibAppletShop/LibAppletLns/LibAppletAuth]]: &amp;quot;/buildinfo/buildinfo.dat&amp;quot; updated, &amp;quot;/.nrr/netfront.nrr&amp;quot; updated&lt;br /&gt;
* &amp;quot;starter&amp;quot; application:&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/sound/starter_action.bksnd&amp;quot; updated&lt;br /&gt;
* myPage applet:&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/sound/myPage_action.bksnd&amp;quot; updated&lt;br /&gt;
* maintenance applet:&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/sound/maintenance_action.bksnd&amp;quot; updated&lt;br /&gt;
&lt;br /&gt;
=== BootImagePackages ===&lt;br /&gt;
RomFs changes: all files updated.&lt;br /&gt;
&lt;br /&gt;
====Secure Monitor====&lt;br /&gt;
Secure Monitor was updated.&lt;br /&gt;
&lt;br /&gt;
* System register configuration now sets CPUACTLR_EL1.&lt;br /&gt;
** This sets CPUACTLR_EL1 to the same value as in [[Kernel_Loader#KernelLdr_MapInitialIdentityMapping|KernelLdr]], previously this code only configured CPUECTLR_EL1.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
====Warmboot====&lt;br /&gt;
* The firmware revision magic was changed from 0x16B to 0x18C.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;check back for more diffs later&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====FIRM Sysmodules====&lt;br /&gt;
FIRM sysmodules were updated. Specific diffs available below:&lt;br /&gt;
&lt;br /&gt;
=====[[Filesystem services|FS]]=====&lt;br /&gt;
The only difference is that nn::crypto::VerifyRsa2048PssSha256 now memsets the decrypted signature buffer to zero after extracting the hash.&lt;br /&gt;
&lt;br /&gt;
=====[[Loader services|Loader]]=====&lt;br /&gt;
The only difference besides GNU build hash update is that the Anti-Downgrade arrays were updated to the new title versions.&lt;br /&gt;
&lt;br /&gt;
==See Also==&lt;br /&gt;
System update report(s):&lt;br /&gt;
* [https://yls8.mtheall.com/ninupdates/reports.php?date=12-04-19_07-05-11&amp;amp;sys=hac]&lt;br /&gt;
&lt;br /&gt;
{{NavboxVersions}}&lt;br /&gt;
&lt;br /&gt;
[[Category:System versions]]&lt;/div&gt;</summary>
		<author><name>Yellows8</name></author>
	</entry>
	<entry>
		<id>https://switchbrew.org/w/index.php?title=3.0.2&amp;diff=14920</id>
		<title>3.0.2</title>
		<link rel="alternate" type="text/html" href="https://switchbrew.org/w/index.php?title=3.0.2&amp;diff=14920"/>
		<updated>2026-08-06T01:51:47Z</updated>

		<summary type="html">&lt;p&gt;Yellows8: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The Switch 3.0.2 system update was released on September 5, 2017. This Switch update was released for the following regions: ALL.&lt;br /&gt;
&lt;br /&gt;
Security flaws fixed: &amp;lt;fill this in manually later, see the updatedetails page from the ninupdates-report page(s) once available for now&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
==Change-log==&lt;br /&gt;
[http://en-americas-support.nintendo.com/app/answers/detail/a_id/22525/p/897 Official] ALL change-log:&lt;br /&gt;
* Nintendo Switch Online &lt;br /&gt;
** Added online play in Argentina, Brazil, Chile, Colombia, and Peru. This is currently available for free until the paid online service launches in 2018. &lt;br /&gt;
* General system stability improvements to enhance the user&#039;s experience&lt;br /&gt;
&lt;br /&gt;
==System Titles==&lt;br /&gt;
&amp;lt;fill this in (manually) later&amp;gt;&lt;br /&gt;
&lt;br /&gt;
RomFs changes:&lt;br /&gt;
* ErrorMessage: updated&lt;br /&gt;
* NgWord: &amp;quot;/0.txt&amp;quot; updated, &amp;quot;/1.txt&amp;quot; updated, &amp;quot;/2.txt&amp;quot; updated, &amp;quot;/3.txt&amp;quot; updated, &amp;quot;/version.dat&amp;quot; updated&lt;br /&gt;
* [[System_Version_Title|SystemVersion]]: All files updated.&lt;br /&gt;
* NgWord2: &amp;quot;/ac_0_not_b_nx&amp;quot; updated, &amp;quot;/ac_1_not_b_nx&amp;quot; updated, &amp;quot;/ac_2_not_b_nx&amp;quot; updated, &amp;quot;/ac_3_b1_nx&amp;quot; updated, &amp;quot;/ac_3_b2_nx&amp;quot; updated, &amp;quot;/ac_3_not_b_nx&amp;quot; updated&lt;br /&gt;
&lt;br /&gt;
=== BootImagePackages ===&lt;br /&gt;
RomFs changes:&lt;br /&gt;
* BootImagePackage/BootImagePackageSafe/BootImagePackageExFat: &amp;quot;/nx/package2&amp;quot; updated&lt;br /&gt;
&lt;br /&gt;
Kernel was updated. FIRM-sysmodules were not updated.&lt;br /&gt;
&lt;br /&gt;
====Kernel====&lt;br /&gt;
* The mmutable init code was updated.&lt;br /&gt;
** Some table addrs were updated.&lt;br /&gt;
** For the first DRAM mapping loop, the descriptor-ORR value now has bitmask 0x40000000000000 set. This is for TTBR0 vmem 0x80000000. This enables usermode XN for the temporary DRAM mapping only used during kernel boot.&lt;br /&gt;
** The descriptor ORR-value for this now has bitmask 0x3000000000000000 set: *(addr+0xf8) = tableaddr | &amp;lt;orrvalue&amp;gt;;//(level2 pagetable descriptor for vmem 0xFFFFFFF7C0000000)&lt;br /&gt;
** Descriptor ORR-value bitmask 0x3000000000000000 is now also set for sometable+0xfb0, +0xfc0, and othertable+0xff0.&lt;br /&gt;
** Kernel .text descriptor ORR-value now has bitmask 0x40000000000000 set. This enables usermode XN for kernel .text, previously kernel .text was executable from usermode.&lt;br /&gt;
&lt;br /&gt;
* The below code is probably memory-management related?&lt;br /&gt;
&lt;br /&gt;
* L_fffffff7ffc3e9c8&lt;br /&gt;
** Updated, prev ver @ L_fffffff7ffc3e9c8&lt;br /&gt;
** 0xfffffff7ffc3eed0: &amp;quot;csel	x9, xzr, x9, ne&amp;quot; was changed to &amp;quot;csel	x9, x11, x9, ne&amp;quot;, where x11 is 0x1000000000000000.&lt;br /&gt;
** Nothing else changed.&lt;br /&gt;
&lt;br /&gt;
* L_fffffff7ffc3f40c&lt;br /&gt;
** Updated, prev ver @ L_fffffff7ffc3f408&lt;br /&gt;
** 0xfffffff7ffc3f74c: Same change as L_fffffff7ffc3e9c8.&lt;br /&gt;
** Nothing else changed.&lt;br /&gt;
&lt;br /&gt;
* L_fffffff7ffc3faac&lt;br /&gt;
** Updated, prev ver @ L_fffffff7ffc3faa4&lt;br /&gt;
** Same change as L_fffffff7ffc3e9c8 @ 0xfffffff7ffc3fecc&lt;br /&gt;
** Nothing else changed.&lt;br /&gt;
&lt;br /&gt;
* L_fffffff7ffc40088&lt;br /&gt;
** Updated, prev ver @ L_fffffff7ffc4007c&lt;br /&gt;
** Same change as L_fffffff7ffc3e9c8 @ 0xfffffff7ffc40160&lt;br /&gt;
** Nothing else changed.&lt;br /&gt;
&lt;br /&gt;
* L_fffffff7ffc4028c&lt;br /&gt;
** Updated, prev ver @ L_fffffff7ffc4027c&lt;br /&gt;
** Same change as L_fffffff7ffc3e9c8 @ 0xfffffff7ffc403a0&lt;br /&gt;
** Nothing else changed.&lt;br /&gt;
&lt;br /&gt;
* L_fffffff7ffc406f0&lt;br /&gt;
** Updated, prev ver @ L_fffffff7ffc406dc&lt;br /&gt;
** Same change as L_fffffff7ffc3e9c8, except with value 0x1000000000000001 instead.&lt;br /&gt;
&lt;br /&gt;
==See Also==&lt;br /&gt;
System update report(s):&lt;br /&gt;
* [https://yls8.mtheall.com/ninupdates/reports.php?date=09-05-17_08-05-14&amp;amp;sys=hac]&lt;br /&gt;
&lt;br /&gt;
{{NavboxVersions}}&lt;/div&gt;</summary>
		<author><name>Yellows8</name></author>
	</entry>
	<entry>
		<id>https://switchbrew.org/w/index.php?title=5.1.0&amp;diff=14919</id>
		<title>5.1.0</title>
		<link rel="alternate" type="text/html" href="https://switchbrew.org/w/index.php?title=5.1.0&amp;diff=14919"/>
		<updated>2026-08-06T01:47:49Z</updated>

		<summary type="html">&lt;p&gt;Yellows8: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The Switch 5.1.0 system update was released on May 30, 2018. This Switch update was released for the following regions: ALL.&lt;br /&gt;
&lt;br /&gt;
Security flaws fixed: &amp;lt;fill this in manually later, see the updatedetails page from the ninupdates-report page(s) once available for now&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
==Change-log==&lt;br /&gt;
[http://en-americas-support.nintendo.com/app/answers/detail/a_id/22525/p/897 Official] ALL change-log:&lt;br /&gt;
* General system stability improvements to enhance the user&#039;s experience&lt;br /&gt;
&lt;br /&gt;
==System Titles==&lt;br /&gt;
&amp;lt;fill this in (manually) later&amp;gt;&lt;br /&gt;
&lt;br /&gt;
System-config / IcosaMariko system-config was updated, however this was just a rebuild (nothing in NCA header changed besides signature+keyarea).&lt;br /&gt;
&lt;br /&gt;
[[NPDM]] changes (besides usual version-bump):&lt;br /&gt;
* ptm: Service access: added srepo:u, time:u.&lt;br /&gt;
* am: Fac.FsAccessFlag updated: set bitmask 0x0000000000100000 (SystemData).&lt;br /&gt;
* eclct: Service access: removed omm.&lt;br /&gt;
&lt;br /&gt;
RomFs changes:&lt;br /&gt;
* ErrorMessage: updated&lt;br /&gt;
* BrowserDll:&lt;br /&gt;
** &amp;quot;/buildinfo/buildinfo.dat&amp;quot; updated&lt;br /&gt;
** &amp;quot;/dll/cairo_wkc.nro.lz4&amp;quot; updated&lt;br /&gt;
** &amp;quot;/dll/libfont.nro.lz4&amp;quot; updated&lt;br /&gt;
** &amp;quot;/dll/oss_wkc.nro.lz4&amp;quot; updated&lt;br /&gt;
** &amp;quot;/dll/peer_wkc.nro.lz4&amp;quot; updated&lt;br /&gt;
** &amp;quot;/dll/webkit_wkc.nro.lz4&amp;quot; updated&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
* Help:&lt;br /&gt;
** &amp;quot;/legallines.htdocs/index.html&amp;quot; updated&lt;br /&gt;
** &amp;quot;/safe.htdocs/html/USen/index.html&amp;quot; updated&lt;br /&gt;
** &amp;quot;/safe.htdocs/html/USen/page_02.html&amp;quot; updated&lt;br /&gt;
** &amp;quot;/safe.htdocs/html/USes/index.html&amp;quot; updated&lt;br /&gt;
** &amp;quot;/safe.htdocs/html/USes/page_02.html&amp;quot; updated&lt;br /&gt;
** &amp;quot;/safe.htdocs/html/USfr/index.html&amp;quot; updated&lt;br /&gt;
** &amp;quot;/safe.htdocs/html/USfr/page_02.html&amp;quot; updated&lt;br /&gt;
* Chinese and Korean dictionaries:&lt;br /&gt;
** &amp;quot;/Iwnn/KO/njexyomi.a&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/KO/njubase1.a&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/CN/pinyin/GB18030/njexyomi.a&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/CN/pinyin/GB18030/njexyomi.ad1&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/CN/pinyin/GB18030/njtan.a&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/CN/pinyin/GB18030/njtan.ad1&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/CN/pinyin/GB18030/njubase1.a&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/CN/pinyin/GB18030/njubase1.ad1&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/CN/pinyin/GB18030/njubase2.a&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/CN/pinyin/GB18030/njubase2.ad1&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/CN/pinyin/GB18030/njubase3.a&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/CN/pinyin/GB18030/njubase3.ad1&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/CN/pinyin/GB2312/njexyomi.a&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/CN/pinyin/GB2312/njexyomi.ad1&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/CN/pinyin/GB2312/njtan.a&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/CN/pinyin/GB2312/njtan.ad1&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/CN/pinyin/GB2312/njubase1.a&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/CN/pinyin/GB2312/njubase1.ad1&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/CN/pinyin/GB2312/njubase2.a&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/CN/pinyin/GB2312/njubase2.ad1&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/CN/pinyin/GB2312/njubase3.a&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/CN/pinyin/GB2312/njubase3.ad1&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/CN/stroke/GB18030/njstroke.a&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/CN/stroke/GB2312/njstroke.a&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/HK/cangjie/njcangjie.a&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/HK/cangjie/njexyomi.a&amp;quot; added&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/HK/cangjie/quick/&amp;quot; added&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/HK/jyutping/njexyomi.a&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/HK/jyutping/njexyomi.ad1&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/HK/jyutping/njtan.a&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/HK/jyutping/njtan.ad1&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/HK/jyutping/njubase1.a&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/HK/jyutping/njubase1.ad1&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/HK/jyutping/njubase2.a&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/HK/jyutping/njubase2.ad1&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/HK/stroke/njstroke.a&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/TW/bopomofo/keisei/njexyomi.ad1&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/TW/bopomofo/keisei/njtan.ad1&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/TW/bopomofo/keisei/njubase1.ad1&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/TW/bopomofo/keisei/njubase2.ad1&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/TW/bopomofo/njexyomi.a&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/TW/bopomofo/njtan.a&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/TW/bopomofo/njubase1.a&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/TW/bopomofo/njubase2.a&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/TW/bopomofo/no_keisei/njexyomi.ad1&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/TW/bopomofo/no_keisei/njtan.ad1&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/TW/bopomofo/no_keisei/njubase1.ad1&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/TW/bopomofo/no_keisei/njubase2.ad1&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/TW/cangjie/njcangjie.a&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/TW/cangjie/njexyomi.a&amp;quot; added&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/TW/cangjie/quick/&amp;quot; added&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/TW/pinyin/keisei/njexyomi.ad1&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/TW/pinyin/keisei/njtan.ad1&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/TW/pinyin/keisei/njubase1.ad1&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/TW/pinyin/keisei/njubase2.ad1&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/TW/pinyin/njexyomi.a&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/TW/pinyin/njtan.a&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/TW/pinyin/njubase1.a&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/TW/pinyin/njubase2.a&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/TW/pinyin/no_keisei/njexyomi.ad1&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/TW/pinyin/no_keisei/njtan.ad1&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/TW/pinyin/no_keisei/njubase1.ad1&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/TW/pinyin/no_keisei/njubase2.ad1&amp;quot; updated&lt;br /&gt;
** &amp;quot;/Iwnn/ZH/TW/stroke/njstroke.a&amp;quot; updated&lt;br /&gt;
* [[System_Version_Title|SystemVersion]]: All files updated.&lt;br /&gt;
* RebootlessSystemUpdateVersion: All files updated.&lt;br /&gt;
* qlaunch applet:&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/sound/qlaunch_action.bksnd&amp;quot; updated&lt;br /&gt;
* controller applet:&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/sound/controller_action.bksnd&amp;quot; updated&lt;br /&gt;
* playerSelect applet:&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/sound/playerSelect_action.bksnd&amp;quot; updated&lt;br /&gt;
* swkbd applet:&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/sound/swkbd_action.bksnd&amp;quot; updated&lt;br /&gt;
* overlayDisp applet:&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/sound/overlayDisp_action.bksnd&amp;quot; updated&lt;br /&gt;
* photoViewer applet:&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/sound/photoViewer_action.bksnd&amp;quot; updated&lt;br /&gt;
* [[Internet_Browser|LibAppletOff/LibAppletWeb/LibAppletShop/LibAppletLns/LibAppletAuth]]: &amp;quot;/buildinfo/buildinfo.dat&amp;quot; updated, &amp;quot;/.nrr/netfront.nrr&amp;quot; updated&lt;br /&gt;
* myPage applet:&lt;br /&gt;
** &amp;quot;/lyt/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: Various data updated.&lt;br /&gt;
** &amp;quot;/sound/myPage_action.bksnd&amp;quot; updated&lt;br /&gt;
&lt;br /&gt;
=== BootImagePackages ===&lt;br /&gt;
RomFs changes:&lt;br /&gt;
* &amp;quot;/nx/package2&amp;quot; updated&lt;br /&gt;
&lt;br /&gt;
Only BootImagePackages that use FS ([[Filesystem_services|FS]], [[NCM_services|NCM]], [[Boot]], [[Loader_services|Loader]] and [[Process_Manager_services|PM]]) were updated. This was solely due to the new cmd 1010 in FS.&lt;br /&gt;
&lt;br /&gt;
===[[qlaunch]]===&lt;br /&gt;
The following files were updated in RomFS:&lt;br /&gt;
&lt;br /&gt;
  /lyt/common.szs&lt;br /&gt;
  /lyt/Interrupt.szs&lt;br /&gt;
  /lyt/Set.szs&lt;br /&gt;
  /message/&amp;lt;regionlanguage-dirname&amp;gt;/common.msbt.szs&lt;br /&gt;
  /message/&amp;lt;regionlanguage-dirname&amp;gt;/interrupt.msbt.szs&lt;br /&gt;
  /message/&amp;lt;regionlanguage-dirname&amp;gt;/option.msbt.szs&lt;br /&gt;
  /message/&amp;lt;regionlanguage-dirname&amp;gt;/setting.msbt.szs&lt;br /&gt;
  /sound/qlaunch_action.bksnd&lt;br /&gt;
&lt;br /&gt;
==See Also==&lt;br /&gt;
System update report(s):&lt;br /&gt;
* [https://yls8.mtheall.com/ninupdates/reports.php?date=05-30-18_08-05-10&amp;amp;sys=hac]&lt;br /&gt;
&lt;br /&gt;
{{NavboxVersions}}&lt;br /&gt;
&lt;br /&gt;
[[Category:System versions]]&lt;/div&gt;</summary>
		<author><name>Yellows8</name></author>
	</entry>
	<entry>
		<id>https://switchbrew.org/w/index.php?title=6.2.0&amp;diff=14918</id>
		<title>6.2.0</title>
		<link rel="alternate" type="text/html" href="https://switchbrew.org/w/index.php?title=6.2.0&amp;diff=14918"/>
		<updated>2026-08-06T01:39:28Z</updated>

		<summary type="html">&lt;p&gt;Yellows8: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The Switch 6.2.0 system update was released on November 19, 2018. This Switch update was released for the following regions: ALL.&lt;br /&gt;
&lt;br /&gt;
Security flaws fixed: Yes&lt;br /&gt;
&lt;br /&gt;
This update burns an additional fuse and has a fuse count of 8.&lt;br /&gt;
&lt;br /&gt;
6.2.0 changes fundamental key generation, no longer using keyblobs at all (the OS will boot successfully even if both copies of keyblob are replaced with FFs in NAND).&lt;br /&gt;
&lt;br /&gt;
==Change-log==&lt;br /&gt;
[https://en-americas-support.nintendo.com/app/answers/detail/a_id/22525/p/897 Official] ALL change-log:&lt;br /&gt;
* 	General system stability improvements to enhance the user&#039;s experience.&lt;br /&gt;
&lt;br /&gt;
==System Titles==&lt;br /&gt;
&#039;&#039;All&#039;&#039; titles were updated (including flog) except for EULA, to use the new keydata.&lt;br /&gt;
&lt;br /&gt;
The following sysmodules were updated with actual changes:&lt;br /&gt;
* bcat, friends, hid, nvservices, account&lt;br /&gt;
&lt;br /&gt;
There seems to be no new service IPC commands.&lt;br /&gt;
&lt;br /&gt;
* bcat: The codebin was updated, but no strings were added/changed.&lt;br /&gt;
* account: Besides .text changes: String &amp;quot;libcurl (nnDauth; &amp;lt;hex&amp;gt;; SDK 6.4.0.0)&amp;quot; was added. The &amp;quot;v3-&amp;lt;oldhexstr&amp;gt;&amp;quot; in the dauth URLs were changed to &amp;quot;v4-&amp;lt;newhexstr&amp;gt;&amp;quot;.&lt;br /&gt;
* nvservices: At least 2 vulnerabilities have been patched. See [[Switch_System_Flaws#System_Modules|here]].&lt;br /&gt;
&lt;br /&gt;
RomFs changes:&lt;br /&gt;
* [[System_Version_Title|SystemVersion]]: All files updated.&lt;br /&gt;
* RebootlessSystemUpdateVersion: All files updated.&lt;br /&gt;
* [[Internet_Browser|LibAppletOff/LibAppletWeb/LibAppletShop/LibAppletLns/LibAppletAuth]]: &amp;quot;/.nrr/netfront.nrr&amp;quot; updated&lt;br /&gt;
** Only RSA data was changed here.&lt;br /&gt;
&lt;br /&gt;
=== BootImagePackages ===&lt;br /&gt;
RomFs changes: all files updated.&lt;br /&gt;
&lt;br /&gt;
====NX_BOOTLOADER====&lt;br /&gt;
NX bootloader was updated, and is now stored compressed. Before executing, a small stub now uncompresses the bootloader to 0x40004000, size 0x1C000.&lt;br /&gt;
&lt;br /&gt;
[more details to be filled in later].&lt;br /&gt;
&lt;br /&gt;
====Secure Monitor====&lt;br /&gt;
The Secure Monitor was updated:&lt;br /&gt;
&lt;br /&gt;
* BootReason is now saved before security engine/warmboot firmware setup.&lt;br /&gt;
* The SYSCTR0 registers are now validated to contain expected values on bootup.&lt;br /&gt;
* generate_srk() is now called before any other security engine key derivation is done.&lt;br /&gt;
* Code was added to implement new key gen inside initialize_se_derive_keys(), deriving the firmware&#039;s master kek and device key using keyslots initialized by the TSEC firmware.&lt;br /&gt;
* Keyslots were shuffled around, the master key is now stored inside keyslot 0xD, and the device master key is now stored inside keyslot 0xC.&lt;br /&gt;
* The usual code changes for adding a new master key/device master key are in place.&lt;br /&gt;
&lt;br /&gt;
There are zero changes to code outside of the coldboot .init section (pk2ldr).&lt;br /&gt;
&lt;br /&gt;
====Kernel====&lt;br /&gt;
* Kernel was not updated.&lt;br /&gt;
&lt;br /&gt;
====FIRM Sysmodules====&lt;br /&gt;
* No FIRM sysmodules were updated.&lt;br /&gt;
&lt;br /&gt;
====Warmboot====&lt;br /&gt;
* The firmware revision magic was changed from 0x87 to 0xA8.&lt;br /&gt;
&lt;br /&gt;
==See Also==&lt;br /&gt;
System update report(s):&lt;br /&gt;
* [https://yls8.mtheall.com/ninupdates/reports.php?date=11-19-18_07-05-09&amp;amp;sys=hac]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{NavboxVersions}}&lt;br /&gt;
&lt;br /&gt;
[[Category:System versions]]&lt;/div&gt;</summary>
		<author><name>Yellows8</name></author>
	</entry>
	<entry>
		<id>https://switchbrew.org/w/index.php?title=8.1.0&amp;diff=14917</id>
		<title>8.1.0</title>
		<link rel="alternate" type="text/html" href="https://switchbrew.org/w/index.php?title=8.1.0&amp;diff=14917"/>
		<updated>2026-08-06T01:32:43Z</updated>

		<summary type="html">&lt;p&gt;Yellows8: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The Switch 8.1.0 system update was released on June 17, 2019. This Switch update was released for the following regions: ALL.&lt;br /&gt;
&lt;br /&gt;
Security flaws fixed: yes.&lt;br /&gt;
&lt;br /&gt;
==Change-log==&lt;br /&gt;
[https://en-americas-support.nintendo.com/app/answers/detail/a_id/22525/p/897 Official] ALL change-log:&lt;br /&gt;
* General system stability improvements to enhance the user&#039;s experience.&lt;br /&gt;
*     &lt;br /&gt;
&lt;br /&gt;
==System Titles==&lt;br /&gt;
Updated titles:&lt;br /&gt;
* Sysmodules: &lt;br /&gt;
** settings Rebuilt.&lt;br /&gt;
** bus Identical codebin.&lt;br /&gt;
** bcat .text updated.&lt;br /&gt;
** hid .text updated.&lt;br /&gt;
** audio Identical codebin.&lt;br /&gt;
** wlan .text updated.&lt;br /&gt;
** nvservices Only GNU build hash was updated.&lt;br /&gt;
** nvnflinger .text updated.&lt;br /&gt;
** account .text updated.&lt;br /&gt;
** ns .text updated.&lt;br /&gt;
** am .text updated.&lt;br /&gt;
** ssl Rebuilt.&lt;br /&gt;
** vi .text updated.&lt;br /&gt;
** es .text updated.&lt;br /&gt;
** fatal .text updated.&lt;br /&gt;
** creport Identical codebin.&lt;br /&gt;
** ro Identical codebin.&lt;br /&gt;
** grc .text updated.&lt;br /&gt;
* ErrorMessage, BrowserDll, [[System_Version_Title]], FIRM, qlaunch, web-applets (main codebin rebuilt), and RebootlessSystemUpdateVersion.&lt;br /&gt;
&lt;br /&gt;
No changes with IPC service commands.&lt;br /&gt;
&lt;br /&gt;
RomFs changes:&lt;br /&gt;
* ErrorMessage: updated&lt;br /&gt;
** Error 2124-4517 was updated with actual strings etc. &amp;quot;/2181/4017/common&amp;quot; and &amp;quot;/DatabaseInfo&amp;quot; were updated.&lt;br /&gt;
* BrowserDll: &amp;quot;/buildinfo/buildinfo.dat&amp;quot; updated, &amp;quot;/dll_0/cairo_wkc.nro.lz4&amp;quot; updated, &amp;quot;/dll_0/libfont.nro.lz4&amp;quot; updated, &amp;quot;/dll_0/oss_wkc.nro.lz4&amp;quot; updated, &amp;quot;/dll_0/peer_wkc.nro.lz4&amp;quot; updated, &amp;quot;/dll_0/webkit_wkc.nro.lz4&amp;quot; updated&lt;br /&gt;
* [[System_Version_Title|SystemVersion]]: All files updated.&lt;br /&gt;
* RebootlessSystemUpdateVersion: All files updated.&lt;br /&gt;
* qlaunch applet: &amp;quot;/lyt/Notification.szs&amp;quot; updated&lt;br /&gt;
* [[Internet_Browser|LibAppletOff/LibAppletWeb/LibAppletShop/LibAppletLns/LibAppletAuth]]: &amp;quot;/buildinfo/buildinfo.dat&amp;quot; updated, &amp;quot;/.nrr/netfront.nrr&amp;quot; updated&lt;br /&gt;
&lt;br /&gt;
=== BootImagePackages ===&lt;br /&gt;
RomFs changes: all files updated.&lt;br /&gt;
&lt;br /&gt;
====Package1ldr====&lt;br /&gt;
package1ldr was updated. The TSEC secureboot firmware was updated.&lt;br /&gt;
&lt;br /&gt;
====NX_BOOTLOADER====&lt;br /&gt;
NX bootloader was updated.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;check back later for diff&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Secure Monitor====&lt;br /&gt;
The Secure Monitor was updated.&lt;br /&gt;
&lt;br /&gt;
* The SE key read disable function no longer writes zero to AES_KEY_READ_DISABLE/RSA_KEY_READ_DISABLE.&lt;br /&gt;
* Functions for locking/checking PMC secure scratch now have additional bitmasks 0x40/0x80 for locking more secure scratch registers.&lt;br /&gt;
* NVDEC/TSECB access to the kernel carveout was removed.&lt;br /&gt;
* On suspend (SC7 Entry), SWR_USBD_RST is now checked, and AHB arbitration disable is now checked to be COP, ARC, USB, USB2.&lt;br /&gt;
** This further mitigates against Deja Vu.&lt;br /&gt;
* TZ/SE context save logic has been changed.&lt;br /&gt;
** The context save function now first generates 16 random bytes, and securely saves them to scratch (using the usual write-writelock-check-readlock-checklocked pattern).&lt;br /&gt;
** It then generates a random aes-256 key, and derives an actual encryption/MAC key by decrypting the random data with that key.&lt;br /&gt;
*** Previously, it generated a random aes-256 key and used it directly.&lt;br /&gt;
*** This prevents attacks that might coerce the usage of a specific aes-256 key instead of a random one.&lt;br /&gt;
** Calls into the check scratch locked/lock scratch function which previously passed one bitmask at a time now pass multiple&lt;br /&gt;
*** Accordingly, the lock/check locked functions now support multiple bitmasks instead of single bitmasks at a time.&lt;br /&gt;
* The function that initializes the SE/derives keys now sets flag 0x100 on AES keyslots 8-15, and RSA keyslots 0-1.&lt;br /&gt;
&lt;br /&gt;
====Kernel====&lt;br /&gt;
Kernel was not changed.&lt;br /&gt;
&lt;br /&gt;
====Warmboot====&lt;br /&gt;
* The firmware revision magic was changed from 0x129 to 0x14A.&lt;br /&gt;
* Security Engine state validation was changed (first six keyslots now expected to read zeroes instead of FFs).&lt;br /&gt;
* &amp;lt;check back for more diffs later&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====FIRM Sysmodules====&lt;br /&gt;
FIRM sysmodules were updated. Specific diffs available below:&lt;br /&gt;
&lt;br /&gt;
=====[[Boot]]=====&lt;br /&gt;
Only GNU build hash was updated.&lt;br /&gt;
&lt;br /&gt;
=====[[Filesystem services|FS]]=====&lt;br /&gt;
Only GNU build hash was updated.&lt;br /&gt;
&lt;br /&gt;
=====[[Loader services|Loader]]=====&lt;br /&gt;
*ldr:pm-&amp;gt;CreateProcess() now performs additional validation on the NPDM header.&lt;br /&gt;
** When the title id is one of certain hardcoded titles, Loader now validates that the version field at NPDM header is non-zero. This prevents selectively downgrading those titles to versions vulnerable to known exploits.&lt;br /&gt;
** The titles checked are:&lt;br /&gt;
*** settings&lt;br /&gt;
*** bus&lt;br /&gt;
*** audio&lt;br /&gt;
*** nvservices&lt;br /&gt;
*** ns&lt;br /&gt;
*** ssl&lt;br /&gt;
*** es&lt;br /&gt;
*** creport&lt;br /&gt;
*** ro&lt;br /&gt;
&lt;br /&gt;
=====[[NCM services|NCM]]=====&lt;br /&gt;
Only GNU build hash was updated.&lt;br /&gt;
&lt;br /&gt;
=====[[Process Manager services|PM]]=====&lt;br /&gt;
Only GNU build hash was updated.&lt;br /&gt;
&lt;br /&gt;
=====[[Services_API|SM]]=====&lt;br /&gt;
SM was not updated.&lt;br /&gt;
&lt;br /&gt;
=====[[SPL services|SPL]]=====&lt;br /&gt;
SPL was not updated.&lt;br /&gt;
&lt;br /&gt;
==Keys==&lt;br /&gt;
Keys were updated.&lt;br /&gt;
&lt;br /&gt;
==See Also==&lt;br /&gt;
System update report(s):&lt;br /&gt;
* [https://yls8.mtheall.com/ninupdates/reports.php?date=06-17-19_08-05-09&amp;amp;sys=hac]&lt;br /&gt;
&lt;br /&gt;
{{NavboxVersions}}&lt;br /&gt;
&lt;br /&gt;
[[Category:System versions]]&lt;/div&gt;</summary>
		<author><name>Yellows8</name></author>
	</entry>
	<entry>
		<id>https://switchbrew.org/w/index.php?title=10.1.0&amp;diff=14916</id>
		<title>10.1.0</title>
		<link rel="alternate" type="text/html" href="https://switchbrew.org/w/index.php?title=10.1.0&amp;diff=14916"/>
		<updated>2026-08-06T01:15:30Z</updated>

		<summary type="html">&lt;p&gt;Yellows8: /* System Titles */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The Switch 10.1.0 system update was released on July 14, 2020 (UTC). This Switch update was released for the following regions: ALL.&lt;br /&gt;
&lt;br /&gt;
Security flaws fixed: yes.&lt;br /&gt;
&lt;br /&gt;
==Change-log==&lt;br /&gt;
[https://en-americas-support.nintendo.com/app/answers/detail/a_id/22525/kw/nintendo%20switch%20system%20update Official] ALL change-log:&lt;br /&gt;
* General system stability improvements to enhance the user&#039;s experience.&lt;br /&gt;
&lt;br /&gt;
==System Titles==&lt;br /&gt;
* The following sysmodules were updated: [[Settings_services|settings]], [[Friend_services|friends]], [[HID_services|hid]], [[WLAN_services|wlan]], [[NV_services|nvservices]], [[NS_Services|ns]], [[Applet_Manager_services|am]], [[NIM_services|nim]], [[BTM_services|btm]], [[NPNS_services|npns]], [[ETicket_services|es]], [[Migration_services|migration]], [[OLSC_services|olsc]].&lt;br /&gt;
* The following SystemData were updated (besides SystemVersion/RebootlessSystemUpdateVersion): [[SSL_services#CertStore|CertStore]], ErrorMessage, SsidList, FirmwareDebugSettings, all BootImagePackages, FatalMessage, [[HID_services#Firmware_update|ControllerFirmware]].&lt;br /&gt;
* The following applets were updated: [[qlaunch]], [[Controller_Applet|controller]], [[Software_Keyboard|swkbd]], [[MyPage_Applet|myPage]].&lt;br /&gt;
&lt;br /&gt;
[[NPDM]] changes: version was updated. The Handle Table Size for npns was changed from 100 to 128.&lt;br /&gt;
&lt;br /&gt;
The only sysmodules with IPC changes were: [[Settings_services|settings]], [[Applet_Manager_services|am]], [[NIM_services|nim]], [[OLSC_services|olsc]].&lt;br /&gt;
&lt;br /&gt;
The sysmodules are built with the updated SDK, even though the sdkver wasn&#039;t changed.&lt;br /&gt;
&lt;br /&gt;
RomFs changes (besides SystemVersion/RebootlessSystemUpdateVersion):&lt;br /&gt;
* [[SSL_services#CertStore|CertStore]]: &amp;quot;/ssl_CaFingerprints.bdf&amp;quot; and &amp;quot;/ssl_TrustedCerts.bdf&amp;quot; were updated.&lt;br /&gt;
* ErrorMessage: New errors were added.&lt;br /&gt;
* SsidList: &amp;quot;/ssid_list.csv&amp;quot; was updated.&lt;br /&gt;
* FirmwareDebugSettings: &amp;quot;/file&amp;quot; was [[System_Settings|updated]].&lt;br /&gt;
* FatalMessage: Added &amp;quot;/pt-BR/&amp;quot;.&lt;br /&gt;
* [[HID_services#Firmware_update|ControllerFirmware]]: &amp;quot;/FirmwareInfo.csv&amp;quot; and &amp;quot;/ukyosakyo_ep2_ota.bin&amp;quot; were updated.&lt;br /&gt;
* [[qlaunch]]: &amp;quot;/lyt/Set.szs&amp;quot;, &amp;quot;/message/{language}/qlaunch.msbt.szs&amp;quot;, &amp;quot;/message/{language}/setting.msbt.szs&amp;quot; were updated.&lt;br /&gt;
* [[Controller_Applet|controller]]: &amp;quot;/lyt/Controller.szs&amp;quot;, &amp;quot;/message/Ocean.msbp.szs&amp;quot;, &amp;quot;/message/USen/controller.msbt.szs&amp;quot;, &amp;quot;/message/USes/controller.msbt.szs&amp;quot;, &amp;quot;/message/USfr/controller.msbt.szs&amp;quot; were updated.&lt;br /&gt;
* [[Software_Keyboard|swkbd]]: &amp;quot;/message/Ocean.msbp.szs&amp;quot; was updated.&lt;br /&gt;
* [[MyPage_Applet|myPage]]: &amp;quot;/lyt/MyPage.szs&amp;quot;, &amp;quot;/lyt/Set.szs&amp;quot;, &amp;quot;/message/{language}/myPage.msbt.szs&amp;quot;, &amp;quot;/message/{language}/setting.msbt.szs&amp;quot;, &amp;quot;/message/Ocean.msbp.szs&amp;quot;, &amp;quot;/sound/myPage_action.bksnd&amp;quot; were updated.&lt;br /&gt;
&lt;br /&gt;
=== BootImagePackages ===&lt;br /&gt;
RomFs changes:&lt;br /&gt;
* &amp;quot;/nx/package2&amp;quot; updated&lt;br /&gt;
&lt;br /&gt;
=== [[HID_services|hid]]-sysmodule ===&lt;br /&gt;
All hidsys ButtonConfig cmds which use an input s32 were updated, the s32 is now [[Switch_System_Flaws#System_Modules|validated]].&lt;br /&gt;
&lt;br /&gt;
Various other funcs were also updated.&lt;br /&gt;
&lt;br /&gt;
=== [[BTM_services|btm]]-sysmodule ===&lt;br /&gt;
Two funcs changed:&lt;br /&gt;
&lt;br /&gt;
* First func: This will no longer Abort when [[Bluetooth_Driver_services#StopInquiry|StopInquiry]] fails, the Result is now ignored. Added a call to the below func with arg=8 which is used in some cases, Aborting on fail.&lt;br /&gt;
* Second func: Two func calls were removed. A func call was added, for setting a bool flag to false with mutex-locking.&lt;br /&gt;
&lt;br /&gt;
=== [[Migration_services|migration]]-sysmodule ===&lt;br /&gt;
Various [[OLSC_services|olsc]] service cmd usage was updated, for using different cmds instead of the previously used cmds, and a new func call which uses an additional cmd was added.&lt;br /&gt;
&lt;br /&gt;
==See Also==&lt;br /&gt;
System update report(s):&lt;br /&gt;
* [https://yls8.mtheall.com/ninupdates/reports.php?date=2020-07-14_00-05-05&amp;amp;sys=hac]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{NavboxVersions}}&lt;br /&gt;
&lt;br /&gt;
[[Category:System versions]]&lt;/div&gt;</summary>
		<author><name>Yellows8</name></author>
	</entry>
	<entry>
		<id>https://switchbrew.org/w/index.php?title=11.0.0&amp;diff=14915</id>
		<title>11.0.0</title>
		<link rel="alternate" type="text/html" href="https://switchbrew.org/w/index.php?title=11.0.0&amp;diff=14915"/>
		<updated>2026-08-06T01:13:41Z</updated>

		<summary type="html">&lt;p&gt;Yellows8: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The Switch 11.0.0 system update was released on December 1, 2020 (UTC). This Switch update was released for the following regions: ALL, and CHN.&lt;br /&gt;
&lt;br /&gt;
Security flaws fixed: &amp;lt;fill this in manually later, see the updatedetails page from the ninupdates-report page(s) once available for now&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
==Change-log==&lt;br /&gt;
[https://en-americas-support.nintendo.com/app/answers/detail/a_id/22525/kw/nintendo%20switch%20system%20update Official] ALL change-log:&lt;br /&gt;
* Nintendo Switch Online was added to the HOME Menu.&lt;br /&gt;
* 	&lt;br /&gt;
* 	Access all Nintendo Switch Online services, from getting the latest information to checking your membership status.&lt;br /&gt;
* 	*This feature is not available in some countries/regions.&lt;br /&gt;
* 	&lt;br /&gt;
* A new feature that automatically downloads backed up save data was added to the Save Data Cloud.&lt;br /&gt;
* 	&lt;br /&gt;
* 	When using software with the same Nintendo Account linked to multiple systems, save data backed up from one console will automatically be downloaded to your other system(s).&lt;br /&gt;
* 	*To use this feature, it must be enabled under System Settings &amp;gt; Data Management &amp;gt; Save Data Cloud.&lt;br /&gt;
* 	*Save data will not be downloaded automatically unless save data for that software exists on the console. The first time only, users must download the save data manually.&lt;br /&gt;
* 	*A Nintendo Switch Online membership is required to use the Save Data Cloud service.&lt;br /&gt;
* 	&lt;br /&gt;
* A new Trending feature was added to the User Page.&lt;br /&gt;
* 	&lt;br /&gt;
* 	Users can check what software their friends are playing or have started playing recently.&lt;br /&gt;
* 	Information will not be displayed for friends who have their online status set to display to no one.&lt;br /&gt;
* 	&lt;br /&gt;
* Users can now transfer screenshots and videos from Album to their smart devices.&lt;br /&gt;
* 	&lt;br /&gt;
* 	Users can wirelessly connect their smart devices to Nintendo Switch to transfer the screenshots and videos saved within their Album.&lt;br /&gt;
* 	For screenshots, users can transfer a maximum of 10 screenshots and 1 video capture at once.&lt;br /&gt;
* 	*To connect, users must use their smart device to scan the QR Code displayed on the Nintendo Switch screen.&lt;br /&gt;
* 	For more information, please refer to the Nintendo Support website.&lt;br /&gt;
* 	*“QR Code” is a registered trademark of DENSO WAVE INCORPORATED.&lt;br /&gt;
* 	&lt;br /&gt;
* 	&lt;br /&gt;
* A new Copy to a Computer via USB Connection feature was added under System Settings &amp;gt; Data Management &amp;gt; Manage Screenshots and Videos.&lt;br /&gt;
* 	&lt;br /&gt;
* 	Users can use a USB cable to connect Nintendo Switch to their computers to copy the screenshots and videos saved under Album.&lt;br /&gt;
* 	* A USB charging cable [model HAC-010] or a USB-IF certified USB cable that supports data transfer is required to connect to a computer.&lt;br /&gt;
* 	For more information, please refer to the Nintendo Support website.&lt;br /&gt;
* 	* Connection via the Nintendo Switch dock is not supported. Please connect the Nintendo Switch system directly to the computer.&lt;br /&gt;
* 	&lt;br /&gt;
* 	&lt;br /&gt;
* Users can now select what download to prioritize when there are multiple downloads in progress.&lt;br /&gt;
* 	&lt;br /&gt;
* 	When there are multiple software, update data, or downloadable content downloads in progress, users can now select which they want to download first.&lt;br /&gt;
* 	You can set this under Download Options by selecting the icon for the software you want to download first on the HOME Menu.&lt;br /&gt;
* 	&lt;br /&gt;
* 	&lt;br /&gt;
* User icons were added.&lt;br /&gt;
* 	&lt;br /&gt;
* 	12 user icons that commemorate the 35th anniversary of the Super Mario Bros. series were added.&lt;br /&gt;
* 	&lt;br /&gt;
* Users can now name preset button mappings with the Change Button Mapping feature.&lt;br /&gt;
* Brazilian Portuguese was added as a supported language.&lt;br /&gt;
* 	&lt;br /&gt;
* 	When users set their region to the Americas and their language to Português, the language used on the HOME Menu and in certain software will be displayed in Brazilian Portuguese.&lt;br /&gt;
* 	&lt;br /&gt;
* Several issues were fixed, and usability and stability were improved.&lt;br /&gt;
&lt;br /&gt;
==System Titles==&lt;br /&gt;
* All titles were updated, except for the following (minus stubbed titles): SharedFont, Dictionary, UrlBlackList, LibraryAppletMiiEdit.&lt;br /&gt;
* The previously stubbed 010000000000001B sysmodule was replaced with [[Capmtp_services|capmtp]].&lt;br /&gt;
&lt;br /&gt;
The following sysmodules had IPC changes: [[USB_services|usb]], [[Settings_services|settings]], [[BCAT_services|bcat]], [[PTM_services|ptm]], [[Sockets_services|bsdsockets]], [[HID_services|hid]], [[Audio_services|audio]], [[WLAN_services|wlan]], [[Account_services|account]], [[NS_Services|ns]], [[PSC_services|psc]], [[Applet_Manager_services|am]], [[NIM_services|nim]], [[Display_services|vi]], [[Parental_Control_services|pctl]], [[Glue_services|glue]], [[ETicket_services|es]], [[Shared_Database_services|sdb]], [[OLSC_services|olsc]], [[PGL_services|pgl]], [[Filesystem_services|fs]], [[Loader_services|loader]], [[Services_API|sm]], [[Capture_services|capsrv]].&lt;br /&gt;
&lt;br /&gt;
[[NPDM]] changes (see [[Services_API]] for service-hosting changes):&lt;br /&gt;
* All updated NPDMs now have [[NPDM#Flags|Flags]] bit5 set.&lt;br /&gt;
* ptm: Access to hshl:set and ins:r were added.&lt;br /&gt;
* ptm/hid: Various services were re-ordered in the Service Access Control.&lt;br /&gt;
* wlan now has access to csrng.&lt;br /&gt;
* ldn now has access to pl:u.&lt;br /&gt;
* pcv now has access to hshl:set.&lt;br /&gt;
* account now has access to ectx:w.&lt;br /&gt;
* ns now has access to pl:u.&lt;br /&gt;
* am: Access to the following was added: arp:r, aud:a, aud:d. Access to the following was removed: audin:a, audin:d, audout:a, audout:d, audren:a, audren:d. Access to hshl:set/hshl:sys was added.&lt;br /&gt;
* erpt: Access to svcGetResourceLimitLimitValue and svc 0x37 were added. Access to ectx:r was added.&lt;br /&gt;
* vi: The Handle Table Size was changed from 160 to 192. Access to the following services were added: erpt:c, gpio, i2c, lm, psc:m, pwm.&lt;br /&gt;
* glue now has access to hshl:sys, and access to psm was removed.&lt;br /&gt;
* creport now has access to fsp-srv.&lt;br /&gt;
* sdb now has access to bcat:s and pm:info.&lt;br /&gt;
* migration now has access to prepo:u.&lt;br /&gt;
* qlaunch now has access to [[Capmtp_services|capmtp]].&lt;br /&gt;
* [[Controller_Applet|LibraryAppletController]] now has access to [[NGCT_services|ngct:u]].&lt;br /&gt;
* [[Profile_Selector|LibraryAppletPlayerSelect]] now has access to [[OLSC_services|olsc:s]].&lt;br /&gt;
* [[Album_Applet|LibraryAppletPhotoViewer]]: Access to [[Sockets_services|bsd:u]] was replaced with [[Sockets_services|bsd:s]]. Access to [[LDN_services|lp2p:sys]] was added. Access to [[NS_Services|ns:am2]] was replaced with [[NS_Services|ns:ro]]. FS permission bit0 is now clear, MountContent* is no longer accessible.&lt;br /&gt;
* [[Internet_Browser|LibraryAppletLoginShare]] now has access to [[NS_Services|ns:web]].&lt;br /&gt;
&lt;br /&gt;
RomFs changes:&lt;br /&gt;
* CertStore was [[SSL_services#CertStore|updated]].&lt;br /&gt;
* ErrorMessage: New errors were added / localization changes.&lt;br /&gt;
* BrowserDll: The following was updated: &amp;quot;/browser/ErrorPageFilteringTemplate.html&amp;quot;, &amp;quot;/browser/MediaControls.css&amp;quot;, &amp;quot;/browser/MediaControls.js&amp;quot;, &amp;quot;/browser/RootCaEtc.pem&amp;quot;, &amp;quot;/browser/RootCaSdkAdditional.pem&amp;quot;, &amp;quot;/buildinfo/buildinfo.dat&amp;quot;. The following was added: &amp;quot;/browser/MediaControlsInline.css&amp;quot;, &amp;quot;/browser/MediaControlsInline.js&amp;quot;.&lt;br /&gt;
** &amp;quot;/dll_0&amp;quot; and &amp;quot;/dll_1&amp;quot; were moved into &amp;quot;/nro/netfront/dll_{0/1}&amp;quot;.&lt;br /&gt;
** &amp;quot;/lyt/Lhub.arc&amp;quot; was added.&lt;br /&gt;
** &amp;quot;/message/USpt/&amp;quot; was added.&lt;br /&gt;
* Help:&lt;br /&gt;
** &amp;quot;/legallines.htdocs/index.html&amp;quot; updated&lt;br /&gt;
** &amp;quot;/safe.htdocs/html/USpt/&amp;quot; added&lt;br /&gt;
** &amp;quot;/safe.htdocs/img/recyclenintendo.jpg&amp;quot; updated&lt;br /&gt;
** &amp;quot;/safe.htdocs/js/tapaction.js&amp;quot; updated&lt;br /&gt;
* NgWord: updated&lt;br /&gt;
* AvatarImage: More icons added.&lt;br /&gt;
* LocalNews: Added &amp;quot;/message/revision.txt&amp;quot; and &amp;quot;/message/USpt/&amp;quot;.&lt;br /&gt;
* Eula:&lt;br /&gt;
** &amp;quot;/revision.txt&amp;quot; updated&lt;br /&gt;
** Updated &amp;quot;/EUru/Eula.msbt.szs&amp;quot;, &amp;quot;/JPja/Eula.msbt.szs&amp;quot;.&lt;br /&gt;
** Added &amp;quot;/USpt/&amp;quot;.&lt;br /&gt;
* TimeZoneBinary: TZ info updated.&lt;br /&gt;
* FontNintendoExtension: &amp;quot;/nintendo_ext_003.bfttf&amp;quot; and &amp;quot;/nintendo_ext2_003.bfttf&amp;quot; were updated.&lt;br /&gt;
* FirmwareDebugSettings: updated&lt;br /&gt;
* FatalMessage: Updated &amp;quot;/pt-BR/GeneralMessage&amp;quot; and &amp;quot;/pt-BR/QuestMessage&amp;quot; were updated.&lt;br /&gt;
* ControllerIcon: &amp;quot;/lyt/ColorTable&amp;quot; updated&lt;br /&gt;
* PlatformConfigIcosa/PlatformConfigCopper/PlatformConfigHoag/PlatformConfigIcosaMariko: updated&lt;br /&gt;
* ControllerFirmware: &amp;quot;/TouchScreenFirmwareInfo.csv&amp;quot; updated&lt;br /&gt;
* NgWord2: updated&lt;br /&gt;
* FunctionBlackList:&lt;br /&gt;
** &amp;quot;/blacklist.dat&amp;quot; was replaced with &amp;quot;/blacklist.json&amp;quot;.&lt;br /&gt;
* NgWordT: updated&lt;br /&gt;
* Applets: Various UI/graphics/sound/localization changes.&lt;br /&gt;
* Web-applets: &amp;quot;/buildinfo/buildinfo.dat&amp;quot; was updated, and &amp;quot;/.nrr/netfront.nrr&amp;quot; was renamed to &amp;quot;/.nrr/dll.nrr&amp;quot;.&lt;br /&gt;
* [[Album_Applet|LibraryAppletPhotoViewer]]: In addition to the above, &amp;quot;/http/&amp;quot; was added, which contains the following:&lt;br /&gt;
** &amp;quot;index.html&amp;quot;&lt;br /&gt;
** &amp;quot;js/index.js&amp;quot;&lt;br /&gt;
** &amp;quot;styles/index.css&amp;quot;&lt;br /&gt;
&lt;br /&gt;
The new Nintendo Switch Online menu (which can be launched via qlaunch) is handled by [[Internet_Browser#Whitelisted_Applets|LibraryAppletLoginShare]].&lt;br /&gt;
&lt;br /&gt;
=== BootImagePackages ===&lt;br /&gt;
RomFs changes: all files updated.&lt;br /&gt;
&lt;br /&gt;
[[Package2|INI1]] changes:&lt;br /&gt;
* BootImagePackageSafe: &lt;br /&gt;
** 010000000000001A (PCV): Flags updated: 0x1F -&amp;gt; 0x3F.&lt;br /&gt;
** 010000000000000A (Bus): Flags updated: 0x1F -&amp;gt; 0x3F.&lt;br /&gt;
** 0100000000000021 (psc): Flags updated: 0x1F -&amp;gt; 0x3F.&lt;br /&gt;
* BootImagePackageExFatSafe: &lt;br /&gt;
** 010000000000001A (PCV): Flags updated: 0x1F -&amp;gt; 0x3F.&lt;br /&gt;
** 010000000000000A (Bus): Flags updated: 0x1F -&amp;gt; 0x3F.&lt;br /&gt;
** 0100000000000021 (psc): Flags updated: 0x1F -&amp;gt; 0x3F.&lt;br /&gt;
&lt;br /&gt;
====Secure Monitor====&lt;br /&gt;
Secure Monitor was updated.&lt;br /&gt;
&lt;br /&gt;
* The firmware revision magic was changed from 0x1AD to 0x1CE.&lt;br /&gt;
* Support was added for an additional DRAM model.&lt;br /&gt;
&lt;br /&gt;
====Warmboot====&lt;br /&gt;
* The firmware revision magic was changed from 0x1AD to 0x1CE.&lt;br /&gt;
&lt;br /&gt;
====Kernel====&lt;br /&gt;
* Kernel is now built with -Os instead of -O3&lt;br /&gt;
** Many functions are no longer inlined.&lt;br /&gt;
* crt0 deprivileging code now sets hypervisor EL2 registers.&lt;br /&gt;
* Logic for flushing entire data cache and invalidating entire TLB during init is now a function called by JumpFromEL2ToEL1 and DisableMmuICacheAndDCache instead of being duplicated.&lt;br /&gt;
* Initialize0 has had several things re-ordered/shuffled:&lt;br /&gt;
** InsertDevicePhysicalMemoryBlocks is now called immediately after the KernelCode region is inserted.&lt;br /&gt;
** &amp;quot;Needed device virtual space&amp;quot; is now calculated as 3 * (0x18000 + { sum of KernelAutoMap physical device regions } + GetUnknownDebugDeviceRegionSize()&lt;br /&gt;
** KernelMisc region size is now util::AlignUp(std::max(needed_device_virtual_space, 32_MB), 2_MB).&lt;br /&gt;
** Code for mapping the unknown debug address as UnknownDebug is no longer present.&lt;br /&gt;
** Slab region is now memset to zero after the linear region is mapped instead of before.&lt;br /&gt;
** Ranges are now more uniform; value in [range address / 2_MB, last_address / 2_MB] is generated and multipled by 2 MB instead of aligning down result.&lt;br /&gt;
* KMemoryRegion now has a &amp;quot;last_address&amp;quot; member replacing its &amp;quot;size&amp;quot; member.&lt;br /&gt;
** GetSize() now calculated as (last_address - address + 1)&lt;br /&gt;
* KMemoryRegionTree::Insert now takes in last address instead of size.&lt;br /&gt;
** Several callsites now verify that last_address != 0xFFFF...&lt;br /&gt;
* KMemoryRegionAllocator now uses a slabheap of count 200 instead of 1000.&lt;br /&gt;
* KLinkedListNode now has slab size = #KThreads instead of #KThreads * 17.&lt;br /&gt;
* &amp;quot;Virtual&amp;quot; cores now supported, KThread now stores core ID/affinity for both virtual and physical.&lt;br /&gt;
* New SVC 0x37 &amp;quot;GetResourceLimitPeakValue&amp;quot;&lt;br /&gt;
** Returns the highest value that a resource limit&#039;s current has ever achieved.&lt;br /&gt;
** KResourceLimit now stores an array of peak values to enable this&lt;br /&gt;
* Two new kernel objects, KAlpha and KBeta (placeholder names, true object names are unknown and cannot be guessed without observing purpose).&lt;br /&gt;
** KAlpha has size 0x50, KBeta has size 0x88&lt;br /&gt;
** KObjectAllocators for KAlpha/KBeta receive counts 1, 6.&lt;br /&gt;
** KProcess has a list of KBeta, intrusive list node is at KBeta + 0x68.&lt;br /&gt;
* Four new SVCs, ID 0x39, 0x3A, 0x46, 0x47&lt;br /&gt;
** These are likely for interacting with KAlpha and KBeta, but on NX they are (presumably) if-def&#039;d to be &amp;quot;return svc::ResultNotImplemented()&amp;quot;&lt;br /&gt;
* KThread had all of its members reordered and its unused members deleted&lt;br /&gt;
* Most KThread waits now use KThreadWaiterListIntrusiveNode instead of KThreadQueue&lt;br /&gt;
* KConditionVariable no longer uses global threads for the call to .nfind()&lt;br /&gt;
* KConditionVariable now sets the cv_key u32 value in userspace to 1 when a condvar has waiters, and to 0 when it does not.&lt;br /&gt;
** New nnSdk code relies on this behavior.&lt;br /&gt;
* SetupStackForUserModeThreadStarter (KThreadContext::Initialize) now sets X18 to (&amp;lt;cryptographically random u64&amp;gt; | 1), this value is unique for each thread.&lt;br /&gt;
** This is used for Pointer Authentication changes in web browser.&lt;br /&gt;
* KCoreLocalRegion deleted, replaced with pointer-to-current-thread&lt;br /&gt;
** TPIDR_EL1 != X18 now, and TPIDR_EL1 now always points to the exception thread stack.&lt;br /&gt;
* KSynchronization was deleted, replaced with namespaced or static-on-ksynchronization-object functions&lt;br /&gt;
* KSynchronizationObject now contains a pointer to thread queue, instead of an inline list&lt;br /&gt;
* KInterruptEvent no longer has an InterruptEventTask member&lt;br /&gt;
* KInterruptEventTask::Reset no longer calls KInterruptManager::ClearInterrupt, instead it calls a new function which returns a result&lt;br /&gt;
* KInterruptEventTask now has a KLightLock member&lt;br /&gt;
* KHardwareTimer is now an interrupt task again&lt;br /&gt;
* KHardwareTimer now has a new member &amp;quot;maximum_time&amp;quot;, set to std::numeric_limits&amp;lt;s64&amp;gt;::value().&lt;br /&gt;
** Tasks will only be added to the task list if their time is &amp;lt;= maximum_time, this is in addition to the &amp;gt;= 1 checks previously.&lt;br /&gt;
* KIntrusiveRedBlackTreeNode now has common member functions instead of templated, size is now packed to 0x1C instead of 0x20.&lt;br /&gt;
** All Insert/Remove/etc operations are common regardless of the type the node is intrusive in.&lt;br /&gt;
* KDebugLogImpl::Initialize() now assumes uart has been configured for logging by the secure monitor, and does not perform tegra uart init sequence&lt;br /&gt;
* vsprintf, KDebugString::PutString are now fully inlined inside KVPrintf.&lt;br /&gt;
* KObjectContainer::Insert now returns void instead of Result&lt;br /&gt;
** Code which previously did R_TRY() now just calls.&lt;br /&gt;
* KPageHeapBitmapRng now has TinyMt as a data member, instead of directly implementing KPageHeap.&lt;br /&gt;
** This affects how constructor is invoked.&lt;br /&gt;
* New InfoType 24 (&amp;quot;FreeThreadCount&amp;quot;) was added, gets the number of threads a process can allocate before exhausting its resource limit.&lt;br /&gt;
* KMemoryBlock/KMemoryInfo now has extra members tracking u8 non_contig_bitflags, u16 ipc_non_contig_lock_count, u16 device_non_contig_lock_count&lt;br /&gt;
* KMemoryBlockManager Update now takes non-contig flags to determine where to coalesce (all coalescing must now happen forwards instead of either direction)&lt;br /&gt;
* KMemoryBlockManagerUpdateAllocator no longer has a result member, instead it has -&amp;gt;Initialize() which takes in a number of blocks to allocate&lt;br /&gt;
* KMemoryManager::Allocate, KMemoryManager::AllocatePageGroup, KMemoryManager::AllocatePageGroupForProcess, now call KPageGroup::Open on the returned page group.&lt;br /&gt;
** All callsites for these functions no longer call open after allocating.&lt;br /&gt;
* KMemoryManager::Open is now KMemoryManager::OpenAdditionalReference, now checks that refcount is &amp;gt;= 1 instead of &amp;gt;= 0&lt;br /&gt;
* KPageTableBase now has an additional data member &amp;quot;disable_device_address_space_merge&amp;quot;&lt;br /&gt;
** KProcessPageTable::Initialize now takes in (process flags &amp;amp; 0x1000) as a bool argument to set this.&lt;br /&gt;
* Page table Query operations now return a number of blocks required to support the above when relevant&lt;br /&gt;
* KPageTable now uses 4 sw-reserved bits instead of 1&lt;br /&gt;
** Former bit 0x01.... (&amp;quot;Is Mapped&amp;quot;) is now bit 0x40..... (PTE bit 58)&lt;br /&gt;
** PTE bit 55 &amp;quot;contiguous not allowed&amp;quot; was reworked for significantly more fine-grained control&lt;br /&gt;
*** PTE bit 55 is now &amp;quot;start of block non-contiguous&amp;quot;, coalescing cannot occur if the first block in a coalesce has this block set.&lt;br /&gt;
*** PTE bit 56 is now &amp;quot;not-end-of-block non-contiguous&amp;quot;, coalescing cannot occur if a block other than the last in a coalesce has this bit set&lt;br /&gt;
*** PTE bit 57 is now &amp;quot;end of block non-contiguous&amp;quot;, coalescing cannot occur if the last block in a coalesce has this bit set&lt;br /&gt;
*** The old non-contiguous semantics are equivalent to 56 + 57 together.&lt;br /&gt;
** These bits are now returned by KPageTableImpl::Traverse&lt;br /&gt;
** Upper byte of KPageProperties is now bitflags to control management of these bits.&lt;br /&gt;
** Bit 0x1 = &amp;quot;Set/Clear PTE Bit55&amp;quot;&lt;br /&gt;
** Bit 0x2 = &amp;quot;Set PTE Bit56&amp;quot;&lt;br /&gt;
** Bit 0x4 = &amp;quot;Clear PTE Bit56&amp;quot;&lt;br /&gt;
** Bit 0x8 = &amp;quot;Set PTE Bit57&amp;quot;&lt;br /&gt;
** Bit 0x10 = &amp;quot;Clear PTE Bit57&amp;quot;&lt;br /&gt;
** Bit 0x20 = Force-Clear 56+57 + attempt to merge&lt;br /&gt;
* KMemoryBlockManager/KPageTable now prevent coalescing of blocks which are reprotected --- (for transfer memory, ipc, ...)&lt;br /&gt;
* They also do not coalesce adjacent GPU mappings that were mapped separately.&lt;br /&gt;
* They removed the 0x80 &amp;quot;AnyLocked&amp;quot; bit from KMemoryAttribute&lt;br /&gt;
* KMemoryBlock/KMemoryInfo now have additional u16 &amp;quot;device_non_coalesce_right_count&amp;quot;.&lt;br /&gt;
** Like device_non_coalesce_left_count from previous 11.x, this now prevents merging with block to the right if set.&lt;br /&gt;
* KMemoryBlock::Add now takes in the memory block to the right instead of the size of the block to the right.&lt;br /&gt;
** This facilitates combining flags for the newly coalesced blocks.&lt;br /&gt;
* KPageTableBase::SetProcessMemoryPermission no longer sets non-coalesce bit 24.&lt;br /&gt;
* KDeviceAddressSpace::Map/KDeviceAddressSpace::Unmap now call new KPageTableBase function to update non-coalesce state according to partial map state.&lt;br /&gt;
* KDevicePageTable::UnmapImpl now invalidates TlbGroup in the failure case of adding to the page group.&lt;br /&gt;
* KPageTableBase::MakeAndOpenContiguousPageGroup is now KPageTableBase::MakePageGroupForDeviceAddressSpace, and now prevents coalescing until call completion.&lt;br /&gt;
** non_coalesce_mask 0x10 is used for this.&lt;br /&gt;
* KPageTableBase::UnmapCodeMemory no longer requires the whole range have the same state.&lt;br /&gt;
** It now invalidates instruction cache if any pages are code.&lt;br /&gt;
* KPageTable::UnknownVirtualFunction10 now takes in more arguments: _QWORD (address probably), _QWORD (size probably), two bools, _QWORD (address2 probably), _QWORD (size2 probably), void * (probably KAlpha * or KBeta *)&lt;br /&gt;
** Returns whether a comparison between address_probably and address_2_probably holds depending on flags at pointer + 0x10.&lt;br /&gt;
* KMemoryState_Io now goes to the alias code region in GetRegionAddress/Size (weird, seems like incorrect behavior)&lt;br /&gt;
** Also very weird: KPageTableBase::MapIo maps IO into the kernel map region, but KPageTableBase::QueryMapping panics if it is not in the alias code region.&lt;br /&gt;
** This &amp;quot;probably&amp;quot; causes kernel panic if mapping IO into process with 32-bit-no-alias address space type?&lt;br /&gt;
&lt;br /&gt;
====FIRM Sysmodules====&lt;br /&gt;
FIRM sysmodules were updated. Specific diffs available below:&lt;br /&gt;
&amp;lt;check back for more diffs later&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== [[HID_services|hid]]-sysmodule ===&lt;br /&gt;
Besides IPC changes, the ButtonConfig cmds updated the input s32 validation: when the input s32 is invalid (which now uses an unsigned compare), it now returns 0 or an error immediately, instead of Aborting.&lt;br /&gt;
&lt;br /&gt;
=== [[LDN_services|ldn]]-sysmodule ===&lt;br /&gt;
lp2p now supports using standard WPA2-PSK, which is used by [[#LibraryAppletPhotoViewer]].&lt;br /&gt;
&lt;br /&gt;
=== [[SSL_services|ssl]]-sysmodule ===&lt;br /&gt;
TLS 1.3 is now [[SSL_services#SslVersion|supported]] if the user-process enables it.&lt;br /&gt;
&lt;br /&gt;
See also [[#OSS]].&lt;br /&gt;
&lt;br /&gt;
=== [[PGL_services|pgl]]-sysmodule ===&lt;br /&gt;
* pgl now has a new ipc command, which just returns &amp;quot;ResultNotImplemented()&amp;quot;&lt;br /&gt;
* pgl now detects when SnapShotDumper crashes, and launches creport in that case.&lt;br /&gt;
* pgl now passes an additional argument to creport (&amp;quot;%d&amp;quot;, formatted with the value of jit_debug!enable_jit_debug).&lt;br /&gt;
&lt;br /&gt;
=== [[Creport|creport]]-sysmodule ===&lt;br /&gt;
* creport now takes in an additional argument &amp;quot;jit_debug_enabled&amp;quot;, when this is &amp;quot;1&amp;quot; the target process is not terminated on report completion.&lt;br /&gt;
* creport now has access to fsp-srv, this is used to retrieve debugging information that is now attached to error reports. The following functions are called (with output/info attached to erpts):&lt;br /&gt;
** GetSdCardSpeedMode&lt;br /&gt;
** GetSdCardCid&lt;br /&gt;
** GetSdCardUserAreaSize&lt;br /&gt;
** GetSdCardProtectedAreaSize&lt;br /&gt;
** GetAndClearSdCardErrorInfo&lt;br /&gt;
** IsGameCardInserted&lt;br /&gt;
** GetGameCardCid&lt;br /&gt;
** GetGameCardErrorReportInfo&lt;br /&gt;
** GetGameCardDeviceId&lt;br /&gt;
** GetMmcSpeedMode&lt;br /&gt;
** GetMmcCid&lt;br /&gt;
** GetMmcPatrolCount&lt;br /&gt;
** GetAndClearMmcErrorInfo&lt;br /&gt;
** GetMmcExtendedCsd&lt;br /&gt;
** GetAndClearMemoryReportInfo&lt;br /&gt;
** GetAndClearFileSystemProxyErrorInfo&lt;br /&gt;
&lt;br /&gt;
=== [[Internet_Browser|Web-applets]] ===&lt;br /&gt;
These are now compiled with compiler Pointer Authentication / CFI mitigations enabled. This does not apply to non-web-applets.&lt;br /&gt;
&lt;br /&gt;
Pointer Authentication uses the crc32x instruction, and x18 as a cryptographically-random u64 provided by the kernel. The only userland code using x18 is the mul instruction for this, nothing else (applies to all NSOs/NROs).&lt;br /&gt;
&lt;br /&gt;
This is used to add/subtract x30 starting with bit40, during functions entry/exit. The code for entry/exit is identical, except that entry does add, and exit uses subtract:&lt;br /&gt;
* The low 40-bits of x30 are extracted, then multiplied with x18.&lt;br /&gt;
* &amp;lt;code&amp;gt;crc32x w17, wzr, x17&amp;lt;/code&amp;gt; (which uses the above value)&lt;br /&gt;
* Then the previously mentioned add/subtraction operation is done, with the output from the above shifted to bit40.&lt;br /&gt;
&lt;br /&gt;
The x18 is OR&#039;d by kernel with 1, to make sure it is odd. This means that the multiply is a bijection; in other words, no entropy is lost when doing the multiply. If this had not been done, a random value that is divisible by a large power of two (the attacker can just keep spawning threads until gets such a one), would have weak cookies that allows the scheme to be trivially broken.&lt;br /&gt;
&lt;br /&gt;
CFI is implemented as follows: blr instructions no longer exist. When funcptrs are called, new functions are now called instead which handles the call. The u32 at funcptr_addr-4 must match 0xe7ffdefe, otherwise it will branch to undefined instruction 0x0000dead. Otherwise, it will jump to the funcptr_addr.&lt;br /&gt;
&lt;br /&gt;
Almost all functions now have the above u32 at -4, therefore funcptr calls now have to start at the actual funcptr start. However, this doesn&#039;t apply to calls done during functions&#039; exit: these directly br to the funcptr_addr without extra validation. The br instructions in the .plt were also replaced with branches to the function described above.&lt;br /&gt;
&lt;br /&gt;
The above applies to all NSOs in ExeFs, except for LibraryAppletOfflineWeb which doesn&#039;t have it enabled. The NROs in the BrowserDll SystemData have it enabled for &amp;quot;/nro/netfront/dll_1/&amp;quot;, however &amp;quot;dll_0&amp;quot; doesn&#039;t have it enabled (which is used by LibraryAppletOfflineWeb).&lt;br /&gt;
&lt;br /&gt;
This is referred to in the build-path strings as &amp;quot;NX-NXFP2-a64-cfi&amp;quot; (nnSdkEmpty), and &amp;quot;NX64-cfi&amp;quot; (OSS).&lt;br /&gt;
&lt;br /&gt;
=== LibraryAppletPhotoViewer ===&lt;br /&gt;
For details on the new sharing functionality in the Album applet, see [[Album_Applet|here]].&lt;br /&gt;
&lt;br /&gt;
== OSS ==&lt;br /&gt;
[https://www.nintendo.co.jp/support/oss/index.html OSS] was updated.&lt;br /&gt;
&lt;br /&gt;
Besides WebKit, [[SSL_services|NSS/NSPR]] was updated:&lt;br /&gt;
* NSPR was updated from 4.12 to 4.24.&lt;br /&gt;
* &amp;lt;code&amp;gt;#define NSSUTIL_VERSION  &amp;quot;3.26&amp;quot;&amp;lt;/code&amp;gt; was changed to &amp;lt;code&amp;gt;#define NSSUTIL_VERSION &amp;quot;3.49.1&amp;quot;&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Both src_{versions} directories were updated, with the same changes:&lt;br /&gt;
* &amp;quot;rocrt_nro.cpp&amp;quot; updated&lt;br /&gt;
* &amp;quot;NX-NXFP2-a64-cfi/rocrt.AssemblyOffset.h&amp;quot; Addded, identical to &amp;quot;NX-NXFP2-a64/rocrt.AssemblyOffset.h&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==See Also==&lt;br /&gt;
System update report(s):&lt;br /&gt;
* [https://yls8.mtheall.com/ninupdates/reports.php?date=2020-12-01_00-02-35&amp;amp;sys=hac]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{NavboxVersions}}&lt;br /&gt;
&lt;br /&gt;
[[Category:System versions]]&lt;/div&gt;</summary>
		<author><name>Yellows8</name></author>
	</entry>
	<entry>
		<id>https://switchbrew.org/w/index.php?title=News&amp;diff=14914</id>
		<title>News</title>
		<link rel="alternate" type="text/html" href="https://switchbrew.org/w/index.php?title=News&amp;diff=14914"/>
		<updated>2026-08-06T01:10:05Z</updated>

		<summary type="html">&lt;p&gt;Yellows8: Reverted edits by Yls8bot (talk) to last revision by Yellows8&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;noinclude&amp;gt;&lt;br /&gt;
==Adding an item==&lt;br /&gt;
* Log in to the wiki. Editing is disabled if you don&#039;t have an account.&lt;br /&gt;
* Add the news event to the top of the list, using this format for the date: &amp;lt;tt&amp;gt;&amp;lt;nowiki&amp;gt;&#039;&#039;&#039;&amp;lt;/nowiki&amp;gt;{{#time: d F y}}&amp;lt;nowiki&amp;gt;&#039;&#039;&#039; &amp;lt;/nowiki&amp;gt;&amp;lt;/tt&amp;gt;. Please include the application&#039;s creator, version number, and a link to a page on 3DBrew about the application. No external links please.&lt;br /&gt;
* &#039;&#039;&#039;Move the last entry to the [[:News/Archive|news archive]]. There should be no more than 4 entries in the list.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==Archives==&lt;br /&gt;
For older news, see the [[:News/Archive|news archive]].&lt;br /&gt;
&lt;br /&gt;
=== News ===&lt;br /&gt;
&amp;lt;!-- Add news below --&amp;gt;&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
*&#039;&#039;&#039;16 June 26&#039;&#039;&#039; Nintendo released system update [[22.5.0]].&lt;br /&gt;
*&#039;&#039;&#039;7 April 26&#039;&#039;&#039; Nintendo released system update [[22.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;17 March 26&#039;&#039;&#039; Nintendo released system update [[22.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;20 January 26&#039;&#039;&#039; Nintendo released system update [[19.0.2]] for CHN region.&lt;/div&gt;</summary>
		<author><name>Yellows8</name></author>
	</entry>
	<entry>
		<id>https://switchbrew.org/w/index.php?title=News/Archive&amp;diff=14913</id>
		<title>News/Archive</title>
		<link rel="alternate" type="text/html" href="https://switchbrew.org/w/index.php?title=News/Archive&amp;diff=14913"/>
		<updated>2026-08-06T01:09:28Z</updated>

		<summary type="html">&lt;p&gt;Yellows8: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*&#039;&#039;&#039;13 January 26&#039;&#039;&#039; Nintendo released system update [[21.2.0]].&lt;br /&gt;
*&#039;&#039;&#039;9 December 25&#039;&#039;&#039; Nintendo released system update [[21.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;25 November 25&#039;&#039;&#039; Nintendo released system update [[21.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;11 November 25&#039;&#039;&#039; Nintendo released system update [[21.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;30 September 25&#039;&#039;&#039; Nintendo released system update [[20.5.0]].&lt;br /&gt;
*&#039;&#039;&#039;2 September 25&#039;&#039;&#039; Nintendo released system update [[20.4.0]].&lt;br /&gt;
*&#039;&#039;&#039;29 July 25&#039;&#039;&#039; Nintendo released system update [[20.3.0]].&lt;br /&gt;
*&#039;&#039;&#039;15 July 25&#039;&#039;&#039; Nintendo released system update [[20.2.0]].&lt;br /&gt;
*&#039;&#039;&#039;19 June 25&#039;&#039;&#039; Nintendo released system update [[20.1.5]].&lt;br /&gt;
*&#039;&#039;&#039;3 June 25&#039;&#039;&#039; Nintendo released system update [[20.1.1]].&lt;br /&gt;
*&#039;&#039;&#039;28 May 25&#039;&#039;&#039; Nintendo released system update [[20.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;2 May 25&#039;&#039;&#039; Nintendo released system update [[20.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;30 April 25&#039;&#039;&#039; Nintendo released system update [[20.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;7 January 25&#039;&#039;&#039; Nintendo released a rebootless system update for [[19.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;29 October 24&#039;&#039;&#039; Nintendo released system update [[19.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;8 October 24&#039;&#039;&#039; Nintendo released system update [[19.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;2 July 24&#039;&#039;&#039; Nintendo released a rebootless system update for [[18.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;11 June 24&#039;&#039;&#039; Nintendo released system update [[18.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;23 April 24&#039;&#039;&#039; Nintendo released system update [[18.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;26 March 24&#039;&#039;&#039; Nintendo released system update [[18.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;20 February 24&#039;&#039;&#039; Nintendo released a rebootless system update for [[17.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;5 December 23&#039;&#039;&#039; Nintendo released system update [[17.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;21 November 23&#039;&#039;&#039; Nintendo released a rebootless system update for [[17.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;11 October 23&#039;&#039;&#039; Nintendo released system update [[17.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;22 August 23&#039;&#039;&#039; Nintendo released system update [[16.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;27 June 23&#039;&#039;&#039; Nintendo released a rebootless system update for [[16.0.3]].&lt;br /&gt;
*&#039;&#039;&#039;30 May 23&#039;&#039;&#039; Nintendo released a rebootless system update for [[16.0.3]].&lt;br /&gt;
*&#039;&#039;&#039;9 May 23&#039;&#039;&#039; Nintendo released system update [[16.0.3]].&lt;br /&gt;
*&#039;&#039;&#039;18 April 23&#039;&#039;&#039; Nintendo released system update [[16.0.2]].&lt;br /&gt;
*&#039;&#039;&#039;23 March 23&#039;&#039;&#039; Nintendo released system update [[16.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;21 February 23&#039;&#039;&#039; Nintendo released system update [[16.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;20 December 22&#039;&#039;&#039; Nintendo released a rebootless system update for [[15.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;1 November 22&#039;&#039;&#039; Nintendo released system update [[15.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;11 October 22&#039;&#039;&#039; Nintendo released system update [[15.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;31 August 22&#039;&#039;&#039; Nintendo released a rebootless system update for [[14.1.2]].&lt;br /&gt;
*&#039;&#039;&#039;26 July 22&#039;&#039;&#039; Nintendo released a rebootless system update for [[14.1.2]].&lt;br /&gt;
*&#039;&#039;&#039;28 June 22&#039;&#039;&#039; Nintendo released a rebootless system update for [[14.1.2]].&lt;br /&gt;
*&#039;&#039;&#039;14 June 22&#039;&#039;&#039; Nintendo released system update [[14.1.2]].&lt;br /&gt;
*&#039;&#039;&#039;19 April 22&#039;&#039;&#039; Nintendo released system update [[14.1.1]].&lt;br /&gt;
*&#039;&#039;&#039;5 April 22&#039;&#039;&#039; Nintendo released system update [[14.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;22 March 22&#039;&#039;&#039; Nintendo released system update [[14.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;20 January 22&#039;&#039;&#039; Nintendo released system update [[13.2.1]].&lt;br /&gt;
*&#039;&#039;&#039;1 December 21&#039;&#039;&#039; Nintendo released system update [[13.2.0]].&lt;br /&gt;
*&#039;&#039;&#039;26 October 21&#039;&#039;&#039; Nintendo released system update [[13.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;15 September 21&#039;&#039;&#039; Nintendo released system update [[13.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;6 July 21&#039;&#039;&#039; Nintendo released system update [[12.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;12 June 21&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=9226&amp;amp;p=17113#p17113 libnx v4.1.0 released].&lt;br /&gt;
*&#039;&#039;&#039;8 June 21&#039;&#039;&#039; Nintendo released system update [[12.0.3]].&lt;br /&gt;
*&#039;&#039;&#039;12 May 21&#039;&#039;&#039; Nintendo released system update [[12.0.2]].&lt;br /&gt;
*&#039;&#039;&#039;20 April 21&#039;&#039;&#039; Nintendo released system update [[12.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;6 April 21&#039;&#039;&#039; Nintendo released system update [[12.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;9 March 21&#039;&#039;&#039; Nintendo released a rebootless system update for [[11.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;11 December 20&#039;&#039;&#039; Nintendo released system update [[11.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;1 December 20&#039;&#039;&#039; Nintendo released system update [[11.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;15 September 20&#039;&#039;&#039; Nintendo released system update [[10.2.0]].&lt;br /&gt;
*&#039;&#039;&#039;28 July 20&#039;&#039;&#039; Nintendo released system update [[10.1.1]].&lt;br /&gt;
*&#039;&#039;&#039;14 July 20&#039;&#039;&#039; Nintendo released system update [[10.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;5 June 20&#039;&#039;&#039; Nintendo released system update [[10.0.4]].&lt;br /&gt;
*&#039;&#039;&#039;26 May 20&#039;&#039;&#039; Nintendo released system update [[10.0.3]].&lt;br /&gt;
*&#039;&#039;&#039;11 May 20&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=9058 devkitA64 r15, libnx v3.2.0, deko3d v0.2.0, switch-examples v20200511] and [https://github.com/switchbrew/nx-hbloader/releases/tag/v2.3.2 nx-hbloader v2.3.2] released.&lt;br /&gt;
*&#039;&#039;&#039;30 April 20&#039;&#039;&#039; Nintendo released system update [[10.0.2]].&lt;br /&gt;
*&#039;&#039;&#039;22 April 20&#039;&#039;&#039; Nintendo released system update [[10.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;14 April 20&#039;&#039;&#039; Nintendo released system update [[10.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;4 April 20&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=9035 libnx v3.1.0, switch-examples v20200404 and deko3d v0.1.0 released]. On the 6th nx-hbmenu v3.3.0 was [https://github.com/switchbrew/nx-hbmenu/releases/latest released].&lt;br /&gt;
*&#039;&#039;&#039;2 April 20&#039;&#039;&#039; [https://github.com/switchbrew/nssu-updater nssu-updater] and [https://github.com/switchbrew/contents-delivery-manager contents-delivery-manager] were released.&lt;br /&gt;
*&#039;&#039;&#039;3 March 20&#039;&#039;&#039; Nintendo released system update [[9.2.0]].&lt;br /&gt;
*&#039;&#039;&#039;10 December 19&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8989 libnx v3.0.0, switch-examples v20191211, Atmosphère v0.10.1, nx-hbmenu v3.2.0, and nx-hbloader v2.3.0 released].&lt;br /&gt;
*&#039;&#039;&#039;4 December 19&#039;&#039;&#039; Nintendo released system update [[9.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;30 September 19&#039;&#039;&#039; Nintendo released system update [[9.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;14 September 19&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8964 libnx v2.5.0 and switch-examples v20190914 released]. nx-hbmenu v3.1.1 [https://github.com/switchbrew/nx-hbmenu/releases/tag/v3.1.1 released]. [https://github.com/Atmosphere-NX/Atmosphere/releases/tag/0.9.4 Atmosphère 0.9.4 released with support for 9.0.0].&lt;br /&gt;
*&#039;&#039;&#039;9 September 19&#039;&#039;&#039; Nintendo released system update [[9.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;10 July 19&#039;&#039;&#039; Nintendo [https://twitter.com/NintendoAmerica/status/1148934589026455552 announced] the Nintendo Switch Lite system.&lt;br /&gt;
*&#039;&#039;&#039;17 June 19&#039;&#039;&#039; Nintendo released system update [[8.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;1 May 19&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8908 libnx v2.2.0 and switch-examples v20190501] released.&lt;br /&gt;
*&#039;&#039;&#039;23 April 19&#039;&#039;&#039; Nintendo released system update [[8.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;15 April 19&#039;&#039;&#039; Nintendo released system update [[8.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;29 March 19&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8891 devkitA64 r13] and [https://github.com/switchbrew/libnx/releases/tag/v2.1.0 libnx v2.1.0] released with pthread/std::thread support.&lt;br /&gt;
*&#039;&#039;&#039;26 March 19&#039;&#039;&#039; [https://github.com/Atmosphere-NX/Atmosphere/releases/tag/0.8.6 Atmosphère v0.8.6] released with lots of bugfixes, more cheat stuff and web applet homebrew support.&lt;br /&gt;
*&#039;&#039;&#039;21 February 19&#039;&#039;&#039; [https://github.com/Atmosphere-NX/Atmosphere/releases/tag/0.8.4 Atmosphère v0.8.4] released with 7.0.x support.&lt;br /&gt;
*&#039;&#039;&#039;18 February 19&#039;&#039;&#039; Nintendo released system update [[7.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;28 January 19&#039;&#039;&#039; Nintendo released system update [[7.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;24 January 19&#039;&#039;&#039; [https://github.com/Atmosphere-NX/Atmosphere/releases/tag/0.8.3 Atmosphère v0.8.3] and [https://github.com/switchbrew/nx-hbloader/releases/tag/v2.1.0 nx-hbloader v2.1.0] were released.&lt;br /&gt;
*&#039;&#039;&#039;2 January 19&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8826 libnx 2.0.0, switch-mesa 18.3 and switch-examples 20190102] were released.&lt;br /&gt;
*&#039;&#039;&#039;29 November 18&#039;&#039;&#039; [https://github.com/Atmosphere-NX/Atmosphere/releases/tag/0.8.0 Atmosphère v0.8.0] was released.&lt;br /&gt;
*&#039;&#039;&#039;29 November 18&#039;&#039;&#039; [https://github.com/switchbrew/nx-hbmenu/releases/latest nx-hbmenu v3.0.1] was released.&lt;br /&gt;
*&#039;&#039;&#039;28 November 18&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8813 libnx 1.6.0 and switch-examples 20181128] were released.&lt;br /&gt;
*&#039;&#039;&#039;19 November 18&#039;&#039;&#039; Nintendo released system update [[6.2.0]].&lt;br /&gt;
*&#039;&#039;&#039;31 October 18&#039;&#039;&#039; [https://github.com/switchbrew/nx-hbloader/releases/tag/v2.0.1 nx-hbloader v2.0.1] was released.&lt;br /&gt;
*&#039;&#039;&#039;29 October 18&#039;&#039;&#039; [https://github.com/switchbrew/nx-hbmenu/releases/latest nx-hbmenu] v3.0.0 was released.&lt;br /&gt;
*&#039;&#039;&#039;29 October 18&#039;&#039;&#039; Nintendo released system update [[6.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;27 October 18&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8798 libnx 1.5.0 and switch-examples 20181027] were released.&lt;br /&gt;
*&#039;&#039;&#039;17 October 18&#039;&#039;&#039; [https://github.com/Atmosphere-NX/Atmosphere/releases/tag/0.7.0 Atmosphère v0.7.0] and [https://github.com/switchbrew/nx-hbloader/releases/tag/v2.0.0 nx-hbloader v2.0.0] were released.&lt;br /&gt;
*&#039;&#039;&#039;8 October 18&#039;&#039;&#039; Nintendo released system update [[6.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;18 September 18&#039;&#039;&#039; Nintendo released system update [[6.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;18 September 18&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8784  libnx 1.4.1, switch-mesa v18.2β and switch-examples 20180918] were released.&lt;br /&gt;
*&#039;&#039;&#039;9 September 18&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8780 libnx v1.4.0] was released alongside a Switch port of mesa/nouveau (GPU library).&lt;br /&gt;
*&#039;&#039;&#039;28 July 18&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8761 devkitA64] r12 and [https://github.com/switchbrew/libnx/releases/tag/v1.3.1 libnx] v1.3.1 were released.&lt;br /&gt;
*&#039;&#039;&#039;8 July 18&#039;&#039;&#039; [https://github.com/switchbrew/libnx/releases/tag/v1.3.0 libnx] v1.3.0 was released.&lt;br /&gt;
*&#039;&#039;&#039;30 May 18&#039;&#039;&#039; Nintendo released system update [[5.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;16 April 18&#039;&#039;&#039; Nintendo released system update [[5.0.2]].&lt;br /&gt;
*&#039;&#039;&#039;26 March 18&#039;&#039;&#039; Nintendo released system update [[5.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;12 March 18&#039;&#039;&#039; Nintendo released system update [[5.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;2 March 18&#039;&#039;&#039; [https://github.com/switchbrew/libnx/releases/tag/v1.1.0 libnx] v1.1.0 was released.&lt;br /&gt;
*&#039;&#039;&#039;28 February 18&#039;&#039;&#039; [https://github.com/switchbrew/nx-hbmenu/releases/latest nx-hbmenu] v2.0.0 was released.&lt;br /&gt;
*&#039;&#039;&#039;22 February 18&#039;&#039;&#039; [http://devkitpro.org devkitPro] released [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8693 devkitA64 alpha7]&lt;br /&gt;
*&#039;&#039;&#039;18 February 18&#039;&#039;&#039; [https://switchbrew.github.io/nx-hbl/ nx-hbl] and [https://github.com/switchbrew/nx-hbmenu nx-hbmenu] were released.&lt;br /&gt;
*&#039;&#039;&#039;28 December 17&#039;&#039;&#039; The 34c3 Switch [https://events.ccc.de/congress/2017/Fahrplan/events/8941.html talk] took place, video available [https://media.ccc.de/v/34c3-8941-console_security_-_switch here].&lt;br /&gt;
*&#039;&#039;&#039;4 December 17&#039;&#039;&#039; Nintendo released system update [[4.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;25 October 17&#039;&#039;&#039; Nintendo released system update [[4.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;18 October 17&#039;&#039;&#039; Nintendo released system update [[4.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;17 September 17&#039;&#039;&#039; [https://github.com/switchbrew/libnx libnx] was made public, with examples available [https://github.com/switchbrew/switch-examples here].&lt;br /&gt;
*&#039;&#039;&#039;5 September 17&#039;&#039;&#039; Nintendo released system update [[3.0.2]].&lt;br /&gt;
*&#039;&#039;&#039;31 July 17&#039;&#039;&#039; Nintendo released system update [[3.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;19 June 17&#039;&#039;&#039; Nintendo released system update [[3.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;15 May 17&#039;&#039;&#039; Nintendo released system update [[2.3.0]].&lt;br /&gt;
*&#039;&#039;&#039;17 April 17&#039;&#039;&#039; Nintendo released system update [[2.2.0]].&lt;br /&gt;
*&#039;&#039;&#039;27 March 17&#039;&#039;&#039; Nintendo released system update [[2.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;2 March 17&#039;&#039;&#039; Nintendo released system update [[2.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;3 March 17&#039;&#039;&#039; Nintendo Switch global release.&lt;/div&gt;</summary>
		<author><name>Yellows8</name></author>
	</entry>
	<entry>
		<id>https://switchbrew.org/w/index.php?title=11.0.1&amp;diff=14912</id>
		<title>11.0.1</title>
		<link rel="alternate" type="text/html" href="https://switchbrew.org/w/index.php?title=11.0.1&amp;diff=14912"/>
		<updated>2026-08-06T01:05:31Z</updated>

		<summary type="html">&lt;p&gt;Yellows8: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The Switch 11.0.1 system update was released on December 11, 2020 (UTC). This Switch update was released for the following regions: ALL, and CHN.&lt;br /&gt;
&lt;br /&gt;
Additionally, a rebootless system update was released revising the &amp;quot;NgWord&amp;quot; list for 11.0.1 on March 9, 2021 (UTC).&lt;br /&gt;
&lt;br /&gt;
Security flaws fixed: &amp;lt;fill this in manually later, see the updatedetails page from the ninupdates-report page(s) once available for now&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
==Change-log==&lt;br /&gt;
[https://en-americas-support.nintendo.com/app/answers/detail/a_id/22525/kw/nintendo%20switch%20system%20update Official] ALL change-log:&lt;br /&gt;
* Corrections for the following problems that occurred with system update version 11.0.0:&lt;br /&gt;
* 	&lt;br /&gt;
*     Corrected a problem where some games couldn&#039;t be played correctly.&lt;br /&gt;
* 	Corrected a problem where, in combination with some TVs, the image would not be displayed in TV mode and an error occurred.&lt;br /&gt;
* 	Corrected a problem which changed how the Control Stick and the C Stick on the Nintendo GameCube controller responded.&lt;br /&gt;
* 	&lt;br /&gt;
&lt;br /&gt;
==System Titles==&lt;br /&gt;
The following was updated: [[System_Version_Title|SystemVersion]], [[HID_services|hid]], [[Display_services|vi]], BootImagePackages.&lt;br /&gt;
&lt;br /&gt;
There was no IPC changes.&lt;br /&gt;
&lt;br /&gt;
RomFs changes:&lt;br /&gt;
* [[System_Version_Title|SystemVersion]]: All files updated.&lt;br /&gt;
&lt;br /&gt;
=== BootImagePackages ===&lt;br /&gt;
RomFs changes:&lt;br /&gt;
* &amp;quot;/nx/package2&amp;quot; updated&lt;br /&gt;
&lt;br /&gt;
====Kernel====&lt;br /&gt;
The kernel was updated.&lt;br /&gt;
* The new thread linked list pointer member in KSynchronizationObject (added in 11.0.0) is now two pointers; it is now a head/tail sentinel pair instead of just a head pointer.&lt;br /&gt;
** KSynchronizationObject::Wait now updates both pointers accordingly.&lt;br /&gt;
* Only other changes are due to KSynchronizationObject (and derivations) increasing in size by 8 bytes.&lt;br /&gt;
&lt;br /&gt;
====FIRM Sysmodules====&lt;br /&gt;
No FIRM sysmodules were updated.&lt;br /&gt;
&lt;br /&gt;
=== [[HID_services|hid]] ===&lt;br /&gt;
Exactly 1 function was updated, nothing else changed. The codebin is identical to the previous version besides this function and the build-id - the function following this one is at the same offset as before.&lt;br /&gt;
&lt;br /&gt;
==See Also==&lt;br /&gt;
System update report(s):&lt;br /&gt;
* [https://yls8.mtheall.com/ninupdates/reports.php?date=2020-12-11_00-15-07&amp;amp;sys=hac]&lt;br /&gt;
* [https://yls8.mtheall.com/ninupdates/reports.php?date=2021-03-09_00-05-06&amp;amp;sys=hac]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{NavboxVersions}}&lt;br /&gt;
&lt;br /&gt;
[[Category:System versions]]&lt;/div&gt;</summary>
		<author><name>Yellows8</name></author>
	</entry>
	<entry>
		<id>https://switchbrew.org/w/index.php?title=12.0.2&amp;diff=14905</id>
		<title>12.0.2</title>
		<link rel="alternate" type="text/html" href="https://switchbrew.org/w/index.php?title=12.0.2&amp;diff=14905"/>
		<updated>2026-08-06T01:03:30Z</updated>

		<summary type="html">&lt;p&gt;Yellows8: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The Switch 12.0.2 system update was released on May 12, 2021 (UTC). This Switch update was released for the following regions: ALL, and CHN.&lt;br /&gt;
&lt;br /&gt;
Security flaws fixed: yes.&lt;br /&gt;
&lt;br /&gt;
==Change-log==&lt;br /&gt;
[https://en-americas-support.nintendo.com/app/answers/detail/a_id/22525/kw/nintendo%20switch%20system%20update Official] ALL change-log:&lt;br /&gt;
*   General system stability improvements to enhance the user&#039;s experience.&lt;br /&gt;
&lt;br /&gt;
==System Titles==&lt;br /&gt;
The following was updated: [[System_Version_Title|SystemVersion]], [[Bluetooth_Driver_services|bluetooth]], [[PGL_services|pgl]], BootImagePackages.&lt;br /&gt;
&lt;br /&gt;
RomFs changes:&lt;br /&gt;
* [[System_Version_Title|SystemVersion]]: All files updated.&lt;br /&gt;
&lt;br /&gt;
=== BootImagePackages ===&lt;br /&gt;
RomFs changes: all files updated.&lt;br /&gt;
&lt;br /&gt;
====Secure Monitor====&lt;br /&gt;
* GetConfig was updated to reflect new number of burnt fuses.&lt;br /&gt;
* Warmboot magic was updated to 0x1EF.&lt;br /&gt;
* Package2 versions were changed from 0xF/0x10 to 0x10/0x11.&lt;br /&gt;
&lt;br /&gt;
====Warmboot====&lt;br /&gt;
* Magic was updated to 0x1EF.&lt;br /&gt;
&lt;br /&gt;
====FIRM Sysmodules====&lt;br /&gt;
Boot, Loader, and SM were updated. Specific diffs available below:&lt;br /&gt;
&lt;br /&gt;
=====SM=====&lt;br /&gt;
tipc autogen was updated, asm for buffer serialization is different now.&lt;br /&gt;
&lt;br /&gt;
=====Loader=====&lt;br /&gt;
Anti-downgrade list was updated.&lt;br /&gt;
&lt;br /&gt;
=====Boot=====&lt;br /&gt;
ChargerDriver::Initialize now sets PINMUX_AUX_CAM_FLASH_EN_0.tristate = PASSTHROUGH. This is the only change.&lt;br /&gt;
&lt;br /&gt;
===[[PGL_services|pgl]]===&lt;br /&gt;
tipc autogen was updated (same as sm).&lt;br /&gt;
&lt;br /&gt;
===[[Bluetooth_Driver_services|bluetooth]]===&lt;br /&gt;
Only 1 func was changed, this fixed a [[Switch_System_Flaws|vuln]].&lt;br /&gt;
&lt;br /&gt;
==See Also==&lt;br /&gt;
System update report(s):&lt;br /&gt;
* [https://yls8.mtheall.com/ninupdates/reports.php?date=2021-05-12_00-05-05&amp;amp;sys=hac]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{NavboxVersions}}&lt;br /&gt;
&lt;br /&gt;
[[Category:System versions]]&lt;/div&gt;</summary>
		<author><name>Yellows8</name></author>
	</entry>
	<entry>
		<id>https://switchbrew.org/w/index.php?title=12.0.3&amp;diff=14904</id>
		<title>12.0.3</title>
		<link rel="alternate" type="text/html" href="https://switchbrew.org/w/index.php?title=12.0.3&amp;diff=14904"/>
		<updated>2026-08-06T01:02:29Z</updated>

		<summary type="html">&lt;p&gt;Yellows8: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The Switch 12.0.3 system update was released on June 8, 2021 (UTC). This Switch update was released for the following regions: ALL, and CHN.&lt;br /&gt;
&lt;br /&gt;
Security flaws fixed: &amp;lt;fill this in manually later, see the updatedetails page from the ninupdates-report page(s) once available for now&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
This sysupdate was temporarily not available via [[Network|sun]], which was later restored.&lt;br /&gt;
&lt;br /&gt;
==Change-log==&lt;br /&gt;
[https://en-americas-support.nintendo.com/app/answers/detail/a_id/22525/kw/nintendo%20switch%20system%20update Official] ALL change-log:&lt;br /&gt;
*   General system stability improvements to enhance the user&#039;s experience.&lt;br /&gt;
&lt;br /&gt;
==System Titles==&lt;br /&gt;
The following was updated: [[System_Version_Title|SystemVersion]]/RebootlessSystemUpdateVersion, NgWord/NgWord2, [[SSL_services|ssl]], BootImagePackages.&lt;br /&gt;
&lt;br /&gt;
RomFs changes:&lt;br /&gt;
* NgWord: &amp;quot;/0.txt&amp;quot; updated, &amp;quot;/version.dat&amp;quot; updated&lt;br /&gt;
* [[System_Version_Title|SystemVersion]]: All files updated.&lt;br /&gt;
* NgWord2: &amp;quot;/ac_0_b1_nx&amp;quot; updated, &amp;quot;/ac_0_b2_nx&amp;quot; updated, &amp;quot;/ac_0_not_b_nx&amp;quot; updated&lt;br /&gt;
* RebootlessSystemUpdateVersion: All files updated.&lt;br /&gt;
&lt;br /&gt;
=== BootImagePackages ===&lt;br /&gt;
RomFs changes:&lt;br /&gt;
* &amp;quot;/nx/package2&amp;quot; updated&lt;br /&gt;
&lt;br /&gt;
Kernel was not updated. The only updated sysmodule (besides buildid) was [[Filesystem_services|FS]].&lt;br /&gt;
&lt;br /&gt;
====[[Filesystem services|FS]]====&lt;br /&gt;
FS was recompiled against SDK 12.3.1 which now catches invalid characters directly after &amp;lt;code&amp;gt;/&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;/.&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;/..&amp;lt;/code&amp;gt; when checking if a path is normalized.&lt;br /&gt;
&lt;br /&gt;
===[[SSL_services|ssl]]===&lt;br /&gt;
Only 1 func was updated, this func is eventually called from [[SSL_services#SetSocketDescriptor|SetSocketDescriptor]]. This handles [[SSL_services#SslVersion|SslVersion]] etc. The code which allowed using TLS 1.3 was removed, the enum bit for V13 is now handled the same as V12.&lt;br /&gt;
&lt;br /&gt;
==See Also==&lt;br /&gt;
System update report(s):&lt;br /&gt;
* [https://yls8.mtheall.com/ninupdates/reports.php?date=2021-06-08_00-05-05&amp;amp;sys=hac]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{NavboxVersions}}&lt;br /&gt;
&lt;br /&gt;
[[Category:System versions]]&lt;/div&gt;</summary>
		<author><name>Yellows8</name></author>
	</entry>
	<entry>
		<id>https://switchbrew.org/w/index.php?title=15.0.0&amp;diff=14902</id>
		<title>15.0.0</title>
		<link rel="alternate" type="text/html" href="https://switchbrew.org/w/index.php?title=15.0.0&amp;diff=14902"/>
		<updated>2026-08-06T00:58:58Z</updated>

		<summary type="html">&lt;p&gt;Yellows8: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The Switch 15.0.0 system update was released on October 11, 2022 (UTC). This Switch update was released for the following regions: ALL, and CHN.&lt;br /&gt;
&lt;br /&gt;
Security flaws fixed: yes.&lt;br /&gt;
&lt;br /&gt;
==Change-log==&lt;br /&gt;
[https://en-americas-support.nintendo.com/app/answers/detail/a_id/22525/kw/nintendo%20switch%20system%20update Official] ALL change-log:&lt;br /&gt;
*   The location of the Bluetooth® Audio menu within System Settings has moved.&lt;br /&gt;
*   Screenshots can be taken using the Capture Button while in the Nintendo Switch Online application found on the Nintendo Switch HOME Menu. Video capture is not supported.&lt;br /&gt;
*   &lt;br /&gt;
*   General system stability improvements to enhance the user&#039;s experience.&lt;br /&gt;
*   &lt;br /&gt;
&lt;br /&gt;
==System Titles==&lt;br /&gt;
* All sysmodules were updated, except for lbl which was previously stubbed. New sysmodule eth was added.&lt;br /&gt;
* All SystemData were updated, except for the following: SharedFont, Dictionary, AvatarImage, Eula, ControllerIcon, ApplicationBlackList, FunctionBlackList.&lt;br /&gt;
* The following applets were updated: qlaunch, [[Controller_Applet|controller]], dataErase, error, netConnect, [[Profile_Selector|playerSelect]], [[Internet_Browser|web-applets]], OverlayApplet, [[Album_Applet|photoViewer]].&lt;br /&gt;
&lt;br /&gt;
NPDM changes (see [[Services_API|here]] for service hosting changes):&lt;br /&gt;
* bluetooth: Access to srepo:u was added.&lt;br /&gt;
* bcat: Access to sprof:sp was removed.&lt;br /&gt;
* nifm: Access to ethc:c, ethc:i, and various wlan:* services were removed. Access to bsd:nu, eth:nd, wlan, and wlan:nd were added.&lt;br /&gt;
* bsdsocket: &amp;quot;Lowest Allowed CPU ID&amp;quot; was changed from 3 to 0. Access to usb:hs and the various wlan:* services were removed.&lt;br /&gt;
* wlan: Access to srepo:u was added.&lt;br /&gt;
* ldn: Access to psc:m and the various wlan:* services were removed. Access to the wlan service was added.&lt;br /&gt;
* ns: Access to audctl was removed. Access to csrng and dauth:0 was added.&lt;br /&gt;
* ssl: &amp;quot;Lowest Allowed CPU ID&amp;quot; was changed from 3 to 0.&lt;br /&gt;
* nim: Access to ssl was replaced with ssl:s.&lt;br /&gt;
* glue: FS permissions now has bitmask 0x0000004000000000 set.&lt;br /&gt;
* ro: Access to csrng was added.&lt;br /&gt;
* omm: FS permissions now has bitmask 0x0000000000100000 set.&lt;br /&gt;
* qlaunch: Access to mnpp:sys and spbg:sp were removed.&lt;br /&gt;
&lt;br /&gt;
RomFs changes (besides sysver titles):&lt;br /&gt;
* [[SSL_services|CertStore]]: &amp;quot;/ssl_TrustedCerts.bdf&amp;quot; updated&lt;br /&gt;
* ErrorMessage: various error messages updated/added&lt;br /&gt;
* BrowserDll:&lt;br /&gt;
** &amp;quot;/browser/MediaControlsInline.css&amp;quot; updated&lt;br /&gt;
** &amp;quot;/browser/MediaControlsInline.js&amp;quot; updated&lt;br /&gt;
** &amp;quot;/buildinfo/buildinfo.dat&amp;quot; updated&lt;br /&gt;
** &amp;quot;/lyt/Browse/FocusNodeFrame.arc&amp;quot; updated&lt;br /&gt;
** &amp;quot;/message/&amp;quot;: localization data updated&lt;br /&gt;
** &amp;quot;/nro/&amp;quot;: The various NROs located under these sub-dirs were updated.&lt;br /&gt;
* Help:&lt;br /&gt;
** &amp;quot;/legallines.htdocs/img/HDMI.png&amp;quot; updated&lt;br /&gt;
** &amp;quot;/legallines.htdocs/index.html&amp;quot; updated&lt;br /&gt;
** &amp;quot;/safe.htdocs/html/{dir}/&amp;quot;, where {dir} is &amp;quot;JPja&amp;quot;, &amp;quot;KRko&amp;quot;, and &amp;quot;TWzh&amp;quot;:&lt;br /&gt;
*** &amp;quot;index.html&amp;quot;, &amp;quot;page_02.html&amp;quot;, &amp;quot;page_04.html&amp;quot;: updated&lt;br /&gt;
* UrlBlackList:&lt;br /&gt;
** &amp;quot;/listCommon.txt&amp;quot; updated&lt;br /&gt;
* TimeZoneBinary: updated&lt;br /&gt;
* FirmwareDebugSettings/PlatformConfigIcosa/PlatformConfigCopper/PlatformConfigHoag/PlatformConfigIcosaMariko/PlatformConfigAula: [[System_Settings|updated]]&lt;br /&gt;
* [[HID_services|ControllerFirmware]]: &amp;quot;/FirmwareInfo.csv&amp;quot; and &amp;quot;/raizo_ep2_ota.bin&amp;quot; updated&lt;br /&gt;
* NgWordT: updated&lt;br /&gt;
* Applets: Various UI/localization data updated. For web-applets, the NRR and buildinfo.dat were also updated.&lt;br /&gt;
&lt;br /&gt;
=== BootImagePackages ===&lt;br /&gt;
RomFs changes: all files updated.&lt;br /&gt;
&lt;br /&gt;
Using updated master-key: master_key_0e (previously master_key_0d). See [[NCA]] for the KeyGeneration listing.&lt;br /&gt;
&lt;br /&gt;
The anti-downgrade fuses were [[Fuses#Anti-downgrade|updated]].&lt;br /&gt;
&lt;br /&gt;
====Kernel====&lt;br /&gt;
* Compiler changes:&lt;br /&gt;
** Compiler upgrade &lt;br /&gt;
*** [What version of clang?]&lt;br /&gt;
*** Clang is optimizing much more aggressively in some places.&lt;br /&gt;
*** Notably, there are many code locations now where clang doesn&#039;t actually increment the KSchedulerLock&#039;s count field, presumably because it sees it will be decremented at end of scope...&lt;br /&gt;
**** This isn&#039;t exploitable, and it is &amp;quot;&amp;quot;&amp;quot;correct&amp;quot;&amp;quot;&amp;quot;, but it is worth noting to other reverse engineers because it is very confusing to see the count field unchanged or reloaded after function calls.&lt;br /&gt;
** Code is now compiled with -fomit-frame-pointer.&lt;br /&gt;
* Initialization changes:&lt;br /&gt;
** When the thread resource limit is increased, 24 MB of virtual space is now reserved for the Kernel stack region instead of 14 MB.&lt;br /&gt;
* In HorizonKernelMain:&lt;br /&gt;
** DoOnEachCoreInOrder is no longer inlined, when setting up the main/interrupt threads. It is still inlined in all other places.&lt;br /&gt;
* Multiple fixed-allocations from the system pool/resource limit were removed/revised, presumably to prevent them from unnecessarily fragmenting the pool forever.&lt;br /&gt;
** AppletSecureMemory is now allocated statically, instead of dynamically.&lt;br /&gt;
*** Previously, 4 MB was allocated from the system pool/resource limit during main.&lt;br /&gt;
*** Initialize0 now reserves the 4 MB immediately after the slab heaps for this.&lt;br /&gt;
**** DRAM layout is now like [tz reserved] [kernel] [slab heaps] [applet secure memory] [pt heap] [init pt] [memory pool partitions].&lt;br /&gt;
**** The virtual memory region type is 0x62; the physical memory region type is 0xC200018E.&lt;br /&gt;
** The KPageBuffer slab heap is no longer dynamically allocated from KMemoryManager.&lt;br /&gt;
*** Previously, the required number of pages were allocated from the system pool/resource limit to setup the heap *immediately* after KMemoryManager was initialized.&lt;br /&gt;
*** Now, it is set up during Kernel::InitializeResourceManagers, after setting up the page manager.&lt;br /&gt;
**** InitializeKPageBufferSlabHeap now takes heap and page manager as arguments; the slab heap&#039;s members are randomly allocated pages from the page manager.&lt;br /&gt;
***** This effectively randomizes the page buffer slabheap&#039;s page locations, where previously they were a contiguous range somewhere in the system pool.&lt;br /&gt;
***** To facilitate this, the page manager now has an Allocate(count) member function in addition to the previous single-page Allocate().&lt;br /&gt;
****** To facilitate this, the page manager now tracks the bitmap ends in addition to the bitmap starts, to enable a linear walk of the lowest bitmap layer.&lt;br /&gt;
*** This has an important knock-on effect: TLS pages are allocated from the page buffer slab, and correspondingly are no longer heap pages.&lt;br /&gt;
**** Correspondingly, KMemoryState_ThreadLocal no longer has the FlagReferenceCounted (0x400000) bit set.&lt;br /&gt;
**** However, removing this bit naively breaks IPC, which previously checked FlagReferenceCounted before copying to/from the message buffer.&lt;br /&gt;
**** Now, FlagReferenceCounted is checked if and only if the message buffer is a UserBuffer. If it is not, a new flag &amp;quot;FlagLinearMapped&amp;quot; (0x4000000) is checked.&lt;br /&gt;
***** This bit is set only on memory types guaranteed to be accessible via the kernel&#039;s linear mapping of non-kernel dram (physical ranges with memory region flag 0x80000000).&lt;br /&gt;
***** This new flag is set on all memory states other than Free, Io, Static, Inaccessible, Kernel, Coverage.&lt;br /&gt;
* Two new SVCs were added for a new &amp;quot;InsecureMemory&amp;quot; concept.&lt;br /&gt;
** Svc 0x90 is Result MapInsecureMemory(uintptr_t address, size_t size);&lt;br /&gt;
*** This allocates the requested size memory from a pool partition/resource limit, and map it with a new memory state (&amp;quot;KMemoryState_Insecure&amp;quot;) at the user-specified address.&lt;br /&gt;
**** The resource limit/pool partition are gotten via new KSystemControl functions (&amp;quot;KSystemControl::GetInsecureMemoryResourceLimit&amp;quot;, &amp;quot;KSystemControl::GetInsecureMemoryPool&amp;quot;).&lt;br /&gt;
***** On NX board, these are the system resource limit, and Pool_SystemNonSecure respectively.&lt;br /&gt;
**** The specified address/size must be within the alias code region.&lt;br /&gt;
**** KMemoryState_Insecure has value 0x5583817.&lt;br /&gt;
***** This is type 0x17 with flags CanUseNonDeviceIpc, CanUseNonSecureIpc, Mapped, CanDeviceMap, CanAlignedDeviceMap, ReferenceCounted, CanChangeAttribute, LinearMapped.&lt;br /&gt;
** Svc 0x91 is Result UnmapInsecureMemory(uintptr_t address, size_t size);&lt;br /&gt;
*** This unmaps/deallocates/releases memory previously mapped with MapInsecureMemory.&lt;br /&gt;
* More changes to SvcMapDeviceAddressSpace(ByForce/Aligned).&lt;br /&gt;
** The argument which was previously a memory permission (&amp;quot;device_perm&amp;quot;) is now an encoded u32 (&amp;quot;option&amp;quot;).&lt;br /&gt;
*** The low 16 bits of this are the device permission.&lt;br /&gt;
*** The upper 16 bits of this are an enum (only defined values are 0 and 1).&lt;br /&gt;
** If the enum-arg is not 0 or 1, svc::ResultInvalidEnumValue() is now returned.&lt;br /&gt;
** If the enum-arg is 1 and the specified memory is IO, svc::ResultInvalidCombination is returned.&lt;br /&gt;
* Partial support was added for the KPageBuffer size being different from the hardware page size.&lt;br /&gt;
** There are now two globals, g_PageBufferSize = 0x1000, g_PageBufferCount = 0.&lt;br /&gt;
** The KPageBuffer slab heap is initialized with g_PageBufferCount blocks of g_PageBufferSize.&lt;br /&gt;
*** if g_PageBufferSize is 0x1000, g_PageBufferCount has the number of required TLS pages added to it (# processes + # threads + (# processes + #threads) / 8).&lt;br /&gt;
** KDynamicPageManager::Initialize now takes in an alignment argument for the page buffer size.&lt;br /&gt;
*** KSecureSystemResource always passes 0x1000.&lt;br /&gt;
** It is possible this is full support but ifdef&#039;d, but on NX board at least all places which allocate/free to the heap panic if g_PageBufferSize != 0x1000...&lt;br /&gt;
* The page table heap now receives all but 64 of the available pages; prior to this, it was all but 70.&lt;br /&gt;
* KSessionRequest&#039;s additional mappings (when sending an IPC request with more than 8 buffers) are now slab-allocated, rather than using KPageBuffers.&lt;br /&gt;
** This slab has a count of 40; object size is 0x4A0 (exactly the maximum required size).&lt;br /&gt;
** 13.0.0+ Dynamic expansion is supported.&lt;br /&gt;
* Scoped setting/clearing of the 14.0.0 exception flag for cache operations has changed.&lt;br /&gt;
** Previously, |= on set, &amp;amp;= ~ on clear. Now, the flag is orr&#039;d in only if it is not already set, and cleared only if it was newly set.&lt;br /&gt;
** This adds support for recursively setting these flags via a scoped setter, although there are no places in kernel where it is possible for this to occur.&lt;br /&gt;
** This applies to cpu::InvalidateDataCache, cpu::StoreDataCache, cpu::FlushDataCache&lt;br /&gt;
* The IsInUsermodeExceptionHandler exception flag management was changed:&lt;br /&gt;
** This is now cleared by RestoreContext (same place it clears other flags) rather than ClearExceptionSvcPermissions. It is still set by SetExceptionSvcPermissions.&lt;br /&gt;
* Changes in and surrounding page table logic:&lt;br /&gt;
** Devices can now theoretically (but not on the NX board) be given access to memory mapped as Io.&lt;br /&gt;
*** Why one would want to do this is unclear.&lt;br /&gt;
*** KMemoryState_Io now supports the CanAlignedDeviceMap and CanDeviceMap flags.&lt;br /&gt;
*** KPageTableBase::GetContiguousMemoryRangeWithState no longer checks that the passed memory address is heap.&lt;br /&gt;
**** KPageTable::MemoryRange now tracks whether the range is reference counted, and Close() only closes the pages if they are.&lt;br /&gt;
*** KPageTableBase::OpenMemoryRangeForMapDeviceAddressSpace no longer checks passes KMemoryState_FlagReferenceCounted.&lt;br /&gt;
*** KPageTableBase::LockForMapDeviceAddressSpace takes two new arguments, an output bool * to write whether the state was io, and a bool for whether to check KMemoryState_FlagReferenceCounted.&lt;br /&gt;
**** The bool is always passed on true on NX board, preventing this feature from being actually used.&lt;br /&gt;
*** KPageTableBase::LockForUnmapDeviceAddressSpace now takes a bool argument for whether to check KMemoryState_FlagReferenceCounted&lt;br /&gt;
**** The bool is always passed on true on NX board, preventing this feature from being actually used.&lt;br /&gt;
** Pages mapped via MapIoRegion now have KMemoryAttribute_Locked instead of KMemoryAttribute_None.&lt;br /&gt;
** Changes were made with respect to the way MapPhysicalMemory/UnmapPhysicalMemory are implemented:&lt;br /&gt;
*** KMemoryManager::AllocatePageGroupForProcess no longer calls KPageGroup::Open on the returned page group (essentially reverting the change in 11.0.0).&lt;br /&gt;
**** Other KMemoryManager::Allocate* functions still call KPageGroup::Open.&lt;br /&gt;
*** KPageTableBase::MapPhysicalMemory now calls a new KPageTable::Operate operation (&amp;quot;MapFirst&amp;quot;), which behaves the same as Map but calls KernelPanic() if the mapped pages have a non-zero reference count.&lt;br /&gt;
**** This enforces that MapPhysicalMemory is the first place the pages being mapped have been allocated/opened.&lt;br /&gt;
*** KPageTableBase::UnmapPhysicalMemory now calls a new KPageTable::Operate operation (&amp;quot;SeparatePages&amp;quot;), which performs page separation on the requested range.&lt;br /&gt;
**** SeparatePages is identical to the separation done at the prologue of ChangePermissions; practically, this just enforces that the pages exist.&lt;br /&gt;
*** KPageTableBase::UnmapPhysicalMemory now calls KernelPanic if the unmapping operation fails (since it is guaranteed to succeed by the success of SeparatePages).&lt;br /&gt;
**** Logic which previously existed for re-mapping on failure has been removed.&lt;br /&gt;
** New Kernel Objects (&amp;quot;KSystemResource&amp;quot;, &amp;quot;KSecureSystemResource&amp;quot;).&lt;br /&gt;
*** Type ID = 0x4600, KSystemResource : public KAutoObject, KSecureSystemResource : public KSystemResource&lt;br /&gt;
*** KSystemResource just stores pointers to the three kinds of dynamic resource managers required by processes/page tables.&lt;br /&gt;
*** KSecureSystemResource stores the pointed-to objects for these as members.&lt;br /&gt;
**** Previously, these were just KProcess members; they are no longer KProcess members and instead live in the KSecureSystemResource object.&lt;br /&gt;
*** The slab heap for KSecureSystemResource has capacity = KProcess slab heap.&lt;br /&gt;
*** When a process is created with system resource size &amp;gt; 0, it now creates a KSecureSystemResource (which manages allocation with KSystemControl).&lt;br /&gt;
**** All actual underlying logic is the same, this just abstracts the KSystemControl/secure memory interaction out of KProcess.&lt;br /&gt;
* KInterruptEventTask was removed and no longer exists.&lt;br /&gt;
** KInterruptEvent now inherits from KInterruptTask directly.&lt;br /&gt;
** There is no longer a global task table; KInterruptManager is expected to return ResultBusy if an interrupt is already bound (it already did this).&lt;br /&gt;
** KInterruptEvent::Finalize now unbinds the interrupt directly, and then calls KDpcManager::Request() with a no-op KDpcTask.&lt;br /&gt;
*** In practice, this unbinds the interrupt, and then creates an ordering to guarantee all cores will see the interrupt as unbound before continuing.&lt;br /&gt;
*** Trivia: this is the first use of KDpcManager::Request on non-debug kernels.&lt;br /&gt;
* Minor changes to KHandleTable:&lt;br /&gt;
** KHandleTable::KHandleTable now initializes the table_size, max_count, and next_id fields to zero, previously they were uninitialized until Initialize was called.&lt;br /&gt;
** KHandleTable::Initialize now instantiates a KScopedDisableDispatch while setting up the table.&lt;br /&gt;
&lt;br /&gt;
====Loader====&lt;br /&gt;
The broken RNG for ASLR was [[Switch_System_Flaws|fixed]].&lt;br /&gt;
&lt;br /&gt;
===[[Bluetooth_Driver_services|bluetooth]]===&lt;br /&gt;
Besides the various IPC changes, security flaws were [[Switch_System_Flaws|fixed]].&lt;br /&gt;
&lt;br /&gt;
===[[HID_services|hid]]===&lt;br /&gt;
Besides the various IPC changes, an infoleak vuln was [[Switch_System_Flaws|fixed]].&lt;br /&gt;
&lt;br /&gt;
===[[WLAN_services|wlan]]===&lt;br /&gt;
Besides the various IPC changes, a vulnerable func was [[Switch_System_Flaws|fixed]].&lt;br /&gt;
&lt;br /&gt;
===[[NS_Services|ns]]===&lt;br /&gt;
Besides the various IPC changes, vulnerable RNG usage was [[Switch_System_Flaws|fixed]] to properly use secure RNG where needed.&lt;br /&gt;
&lt;br /&gt;
===[[RO_services|ro]]===&lt;br /&gt;
The broken RNG for ASLR was [[Switch_System_Flaws|fixed]].&lt;br /&gt;
&lt;br /&gt;
===nnSdk===&lt;br /&gt;
&amp;lt;code&amp;gt;nn::diag::detail::VAbortImpl&amp;lt;/code&amp;gt; when handling the retaddr for storing elsewhere, now uses instruction [https://developer.arm.com/documentation/dui0801/g/A64-General-Instructions/XPACD--XPACI--XPACLRI xpaclri]. PAC instructions are NOPs on ARM hardware which doesn&#039;t support it, which includes current NX consoles.&lt;br /&gt;
&lt;br /&gt;
This is likely due to a LLVM [https://reviews.llvm.org/D84502 patch] where xpaclri is now always emitted and not related to actual Armv8.3 hardware.&lt;br /&gt;
&lt;br /&gt;
=== IPC Interface Changes ===&lt;br /&gt;
* The following new interfaces were removed:&lt;br /&gt;
** nn::eth::sf::IEthInterface&lt;br /&gt;
** nn::eth::sf::IEthInterfaceGroup&lt;br /&gt;
** nn::socket::sf::IClient&lt;br /&gt;
** nn::wlan::detail::IDetectManager&lt;br /&gt;
** nn::wlan::detail::IInfraManager&lt;br /&gt;
** nn::wlan::detail::ILocalGetActionFrame&lt;br /&gt;
** nn::wlan::detail::ILocalGetFrame&lt;br /&gt;
** nn::wlan::detail::ILocalManager&lt;br /&gt;
** nn::wlan::detail::ISocketGetFrame&lt;br /&gt;
** nn::wlan::detail::ISocketManager&lt;br /&gt;
* The following new interfaces were added:&lt;br /&gt;
** nn::anif::detail::ISfAssignedNetworkInterfaceService&lt;br /&gt;
** nn::anif::detail::ISfDriverService&lt;br /&gt;
** nn::anif::detail::ISfDriverServiceCreator&lt;br /&gt;
** nn::anif::detail::ISfNetworkInterfaceService&lt;br /&gt;
** nn::anif::detail::ISfUserService&lt;br /&gt;
** nn::anif::detail::ISfUserServiceCreator&lt;br /&gt;
** nn::pl::detail::IPlatformServiceManager&lt;br /&gt;
** nn::prepo::detail::ipc::IAsyncContext&lt;br /&gt;
** nn::socket::sf::IClient_MC&lt;br /&gt;
** nn::srepo::detail::ipc::IAsyncContext&lt;br /&gt;
** nn::ssl::sf::ISslContextForSystem&lt;br /&gt;
** nn::ssl::sf::ISslServiceForSystem&lt;br /&gt;
** nn::wlan::detail::IGeneralServiceCreator&lt;br /&gt;
** nn::wlan::detail::IPrivateServiceCreator&lt;br /&gt;
** nn::wlan::detail::IPrivateWirelessCommunicationService&lt;br /&gt;
** nn::wlan::detail::IWirelessCommunicationService&lt;br /&gt;
* The following interfaces were changed:&lt;br /&gt;
** nn::account::baas::IAdministrator&lt;br /&gt;
*** Added command 143 - inbytes: 0, outbytes: 16&lt;br /&gt;
*** Added command 160 - inbytes: 0, outbytes: 0&lt;br /&gt;
** nn::account::baas::IManagerForSystemService&lt;br /&gt;
*** Added command 143 - inbytes: 0, outbytes: 16&lt;br /&gt;
*** Added command 160 - inbytes: 0, outbytes: 0&lt;br /&gt;
** nn::am::service::IAppletCommonFunctions&lt;br /&gt;
*** Added command  90 - inbytes: 16, outbytes: 0, outinterfaces: [&#039;nn::am::service::IStorageChannel&#039;]&lt;br /&gt;
*** Added command  91 - inbytes: 16, outbytes: 0, outinterfaces: [&#039;nn::am::service::IStorageChannel&#039;]&lt;br /&gt;
*** Added command 100 - inbytes: 4, outbytes: 0&lt;br /&gt;
** nn::am::service::IDebugFunctions&lt;br /&gt;
*** Added command  50 - inbytes: 16, outbytes: 0&lt;br /&gt;
*** Added command 200 - buffers: [5], inbytes: 8, outbytes: 0, outinterfaces: [&#039;nn::am::service::IAllSystemAppletProxiesService&#039;], pid: True&lt;br /&gt;
** nn::am::service::ILibraryAppletProxy&lt;br /&gt;
*** Added command  22 - inbytes: 0, outbytes: 0, outinterfaces: [&#039;nn::am::service::IHomeMenuFunctions&#039;]&lt;br /&gt;
*** Added command  23 - inbytes: 0, outbytes: 0, outinterfaces: [&#039;nn::am::service::IGlobalStateController&#039;]&lt;br /&gt;
** nn::am::service::IOverlayAppletProxy&lt;br /&gt;
*** Added command  23 - inbytes: 0, outbytes: 0, outinterfaces: [&#039;nn::am::service::IGlobalStateController&#039;]&lt;br /&gt;
** nn::arp::detail::IWriter&lt;br /&gt;
*** Added command   3 - inbytes: 8, outbytes: 0, outinterfaces: [&#039;nn::arp::detail::IUpdater&#039;]&lt;br /&gt;
** nn::audio::detail::IAudioRenderer&lt;br /&gt;
*** Added command  12 - inbytes: 4, outbytes: 0&lt;br /&gt;
*** Added command  13 - inbytes: 0, outbytes: 4&lt;br /&gt;
** nn::audioctrl::detail::IAudioController&lt;br /&gt;
*** Removed command 26 - inbytes: 1, outbytes: 0&lt;br /&gt;
*** Removed command 35 - inbytes: 8, outbytes: 0&lt;br /&gt;
*** Removed command 36 - inbytes: 0, outbytes: 8&lt;br /&gt;
*** Removed command 37 - inbytes: 1, outbytes: 0&lt;br /&gt;
*** Removed command 38 - inbytes: 0, outbytes: 1&lt;br /&gt;
*** Removed command 39 - inbytes: 0, outbytes: 1&lt;br /&gt;
*** Changed command 40 - buffers: [26] -&amp;gt; [22] (final state: buffers: [22], inbytes: 0, outbytes: 0)&lt;br /&gt;
*** Added command  41 - inbytes: 8, outbytes: 0&lt;br /&gt;
*** Added command  42 - inbytes: 8, outbytes: 0&lt;br /&gt;
*** Added command 50000 - inbytes: 4, outbytes: 0&lt;br /&gt;
** nn::bluetooth::IBluetoothDriver&lt;br /&gt;
*** Added command 101 - inbytes: 0, outbytes: 0&lt;br /&gt;
*** Added command 102 - inbytes: 0, outbytes: 0&lt;br /&gt;
*** Added command 155 - inbytes: 6, outbytes: 1&lt;br /&gt;
** nn::btm::IBtm&lt;br /&gt;
*** Removed command 112 - inbytes: 7, outbytes: 0&lt;br /&gt;
*** Removed command 113 - inbytes: 6, outbytes: 1&lt;br /&gt;
*** Added command 116 - inbytes: 7, outbytes: 0&lt;br /&gt;
*** Added command 117 - inbytes: 6, outbytes: 1&lt;br /&gt;
** nn::btm::IBtmDebug&lt;br /&gt;
*** Added command  14 - inbytes: 8, outbytes: 0&lt;br /&gt;
*** Added command  15 - inbytes: 0, outbytes: 0&lt;br /&gt;
*** Added command  16 - inbytes: 0, outbytes: 0&lt;br /&gt;
*** Added command  17 - inbytes: 0, outbytes: 0&lt;br /&gt;
** nn::capsrv::sf::IAlbumAccessorService&lt;br /&gt;
*** Added command 110 - buffers: [6, 5], inbytes: 16, outbytes: 8&lt;br /&gt;
** nn::clkrst::IClkrstManager&lt;br /&gt;
*** Added command   6 - inbytes: 0, outbytes: 0&lt;br /&gt;
** nn::dauth::detail::IService&lt;br /&gt;
*** Added command 1000 - inbytes: 0, outbytes: 0, outhandles: [1]&lt;br /&gt;
*** Added command 9000 - buffers: [5, 5], inbytes: 0, outbytes: 0&lt;br /&gt;
*** Added command 9010 - inbytes: 0, outbytes: 0&lt;br /&gt;
** nn::es::IActiveRightsContext&lt;br /&gt;
*** Removed command  5 - buffers: [5], inbytes: 0, outbytes: 0&lt;br /&gt;
*** Added command 216 - inbytes: 0, outbytes: 0, outhandles: [1]&lt;br /&gt;
** nn::es::IETicketService&lt;br /&gt;
*** Added command 1022 - inbytes: 0, outbytes: 0, outinterfaces: [&#039;nn::es::IActiveRightsContext&#039;]&lt;br /&gt;
** nn::fssrv::sf::IFileSystem&lt;br /&gt;
*** Added command  16 - inbytes: 0, outbytes: 192&lt;br /&gt;
** nn::fssrv::sf::IFileSystemProxy&lt;br /&gt;
*** Added command 207 - inbytes: 16, outbytes: 0, outinterfaces: [&#039;nn::fssrv::sf::IFileSystem&#039;]&lt;br /&gt;
*** Added command 1400 - inbytes: 1, outbytes: 0&lt;br /&gt;
** nn::grcsrv::IGrcService&lt;br /&gt;
*** Changed command  1 - inbytes: 72 -&amp;gt; 32 (final state: inbytes: 32, inhandles: [1], outbytes: 0, outinterfaces: [&#039;nn::grcsrv::IContinuousRecorder&#039;])&lt;br /&gt;
** nn::hid::IHidDebugServer&lt;br /&gt;
*** Added command 137 - inbytes: 16, outbytes: 0, pid: True&lt;br /&gt;
** nn::hid::IHidServer&lt;br /&gt;
*** Added command 3000 - buffers: [26], inbytes: 0, outbytes: 0&lt;br /&gt;
*** Added command 3001 - buffers: [25], inbytes: 0, outbytes: 0&lt;br /&gt;
*** Added command 3002 - inbytes: 0, outbytes: 0&lt;br /&gt;
*** Added command 3003 - inbytes: 0, outbytes: 56&lt;br /&gt;
*** Added command 3004 - inbytes: 56, outbytes: 0&lt;br /&gt;
*** Added command 3005 - inbytes: 0, outbytes: 0&lt;br /&gt;
*** Added command 3006 - buffers: [26], inbytes: 4, outbytes: 0&lt;br /&gt;
*** Added command 3007 - buffers: [25], inbytes: 4, outbytes: 0&lt;br /&gt;
*** Added command 3008 - inbytes: 4, outbytes: 0&lt;br /&gt;
*** Added command 3009 - inbytes: 4, outbytes: 64&lt;br /&gt;
*** Added command 3010 - inbytes: 68, outbytes: 0&lt;br /&gt;
*** Added command 3011 - inbytes: 4, outbytes: 0&lt;br /&gt;
** nn::hid::IHidSystemServer&lt;br /&gt;
*** Added command  32 - inbytes: 48, outbytes: 0, pid: True&lt;br /&gt;
*** Added command  33 - inbytes: 0, outbytes: 0&lt;br /&gt;
*** Added command 1135 - inbytes: 8, outbytes: 0, pid: True&lt;br /&gt;
** nn::lr::IAddOnContentLocationResolver&lt;br /&gt;
*** Added command   5 - buffers: [22, 22], inbytes: 8, outbytes: 0&lt;br /&gt;
*** Added command   6 - buffers: [21], inbytes: 16, outbytes: 0&lt;br /&gt;
*** Added command   7 - buffers: [21, 21], inbytes: 16, outbytes: 0&lt;br /&gt;
** nn::lr::ILocationResolver&lt;br /&gt;
*** Added command  20 - inbytes: 0, outbytes: 0&lt;br /&gt;
** nn::lr::ILocationResolverManager&lt;br /&gt;
*** Added command   4 - buffers: [5], inbytes: 0, outbytes: 0&lt;br /&gt;
** nn::mnpp::detail::ipc::IServiceForSystem&lt;br /&gt;
*** Removed command 300 - inbytes: 0, outbytes: 1&lt;br /&gt;
*** Removed command 400 - inbytes: 0, outbytes: 1&lt;br /&gt;
** nn::ncm::IContentMetaDatabase&lt;br /&gt;
*** Added command  23 - inbytes: 16, outbytes: 1&lt;br /&gt;
*** Added command  24 - inbytes: 24, outbytes: 24&lt;br /&gt;
*** Added command  25 - inbytes: 24, outbytes: 24&lt;br /&gt;
** nn::ndrm::low::detail::INdrmLowAdminInterface&lt;br /&gt;
*** Changed command  3 - inbytes: 8 -&amp;gt; 24 (final state: buffers: [5], inbytes: 24, outbytes: 0)&lt;br /&gt;
*** Added command  40 - buffers: [6], inbytes: 8, outbytes: 4&lt;br /&gt;
*** Added command  42 - buffers: [6], inbytes: 16, outbytes: 4&lt;br /&gt;
*** Added command  43 - buffers: [6], inbytes: 16, outbytes: 4&lt;br /&gt;
*** Added command  44 - buffers: [6], inbytes: 16, outbytes: 4&lt;br /&gt;
** nn::nim::detail::INetworkInstallManager&lt;br /&gt;
*** Removed command 91 - buffers: [5], inbytes: 16, outbytes: 0, outhandles: [1], outinterfaces: [&#039;nn::nim::detail::IAsyncResult&#039;]&lt;br /&gt;
*** Added command 138 - buffers: [5], inbytes: 8, outbytes: 0, outhandles: [1], outinterfaces: [&#039;nn::nim::detail::IAsyncResult&#039;]&lt;br /&gt;
*** Added command 139 - inbytes: 0, outbytes: 0&lt;br /&gt;
*** Added command 140 - inbytes: 0, outbytes: 0&lt;br /&gt;
*** Added command 141 - inbytes: 0, outbytes: 1&lt;br /&gt;
** nn::nim::detail::IShopServiceManager&lt;br /&gt;
*** Removed command 102 - inbytes: 0, outbytes: 0, outhandles: [1], outinterfaces: [&#039;nn::nim::detail::IAsyncValue&#039;]&lt;br /&gt;
*** Removed command 103 - inbytes: 0, outbytes: 32&lt;br /&gt;
*** Removed command 104 - inbytes: 0, outbytes: 0, outhandles: [1], outinterfaces: [&#039;nn::nim::detail::IAsyncValue&#039;]&lt;br /&gt;
*** Removed command 105 - inbytes: 0, outbytes: 0, outhandles: [1], outinterfaces: [&#039;nn::nim::detail::IAsyncResult&#039;]&lt;br /&gt;
*** Removed command 106 - inbytes: 0, outbytes: 0, outhandles: [1], outinterfaces: [&#039;nn::nim::detail::IAsyncResult&#039;]&lt;br /&gt;
*** Removed command 501 - inbytes: 16, outbytes: 0, outhandles: [1], outinterfaces: [&#039;nn::nim::detail::IAsyncResult&#039;]&lt;br /&gt;
** nn::ns::detail::IApplicationManagerInterface&lt;br /&gt;
*** Added command  90 - inbytes: 8, outbytes: 0&lt;br /&gt;
*** Changed command 607 - inbytes: 16 -&amp;gt; 8 (final state: buffers: [6], inbytes: 8, outbytes: 4)&lt;br /&gt;
*** Removed command 909 - inbytes: 8, outbytes: 0&lt;br /&gt;
*** Added command 2357 - inbytes: 0, outbytes: 0&lt;br /&gt;
*** Added command 2358 - inbytes: 0, outbytes: 0&lt;br /&gt;
*** Added command 2359 - inbytes: 0, outbytes: 1&lt;br /&gt;
*** Removed command 2516 - inbytes: 16, outbytes: 0&lt;br /&gt;
** nn::pdm::detail::IQueryService&lt;br /&gt;
*** Removed command  7 - buffers: [6, 5], inbytes: 0, outbytes: 4&lt;br /&gt;
*** Removed command 13 - buffers: [6, 5], inbytes: 0, outbytes: 4&lt;br /&gt;
*** Removed command 14 - buffers: [6], inbytes: 24, outbytes: 4&lt;br /&gt;
*** Removed command 15 - inbytes: 0, outbytes: 0, outhandles: [1]&lt;br /&gt;
*** Removed command 16 - buffers: [6, 5], inbytes: 16, outbytes: 4&lt;br /&gt;
** nn::prepo::detail::ipc::IPrepoService&lt;br /&gt;
*** Added command 10500 - buffers: [9], inbytes: 40, inhandles: [1], outbytes: 0, outinterfaces: [&#039;nn::prepo::detail::ipc::IAsyncContext&#039;], pid: True&lt;br /&gt;
** nn::settings::ISystemSettingsServer&lt;br /&gt;
*** Removed command 119 - inbytes: 1, outbytes: 3&lt;br /&gt;
** nn::srepo::detail::ipc::ISrepoService&lt;br /&gt;
*** Added command 10300 - buffers: [9], inbytes: 40, inhandles: [1], outbytes: 0, outinterfaces: [&#039;nn::srepo::detail::ipc::IAsyncContext&#039;]&lt;br /&gt;
*** Added command 20600 - inbytes: 20, outbytes: 0&lt;br /&gt;
** nn::usb::ds::IDsEndpoint&lt;br /&gt;
*** Removed command  8 - inbytes: 8, inhandles: [1], outbytes: 0&lt;br /&gt;
*** Removed command  9 - inbytes: 16, outbytes: 4&lt;br /&gt;
** nn::usb::ds::IDsInterface&lt;br /&gt;
*** Added command  12 - inbytes: 8, inhandles: [1], outbytes: 0&lt;br /&gt;
** nn::visrv::sf::IManagerDisplayService&lt;br /&gt;
*** Changed command 8293 - inbytes: 16 -&amp;gt; 40 (final state: buffers: [6], inbytes: 40, outbytes: 8)&lt;br /&gt;
&lt;br /&gt;
==See Also==&lt;br /&gt;
System update report(s):&lt;br /&gt;
* [https://yls8.mtheall.com/ninupdates/reports.php?date=2022-10-11_00-15-06&amp;amp;sys=hac]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{NavboxVersions}}&lt;br /&gt;
&lt;br /&gt;
[[Category:System versions]]&lt;/div&gt;</summary>
		<author><name>Yellows8</name></author>
	</entry>
	<entry>
		<id>https://switchbrew.org/w/index.php?title=News&amp;diff=14901</id>
		<title>News</title>
		<link rel="alternate" type="text/html" href="https://switchbrew.org/w/index.php?title=News&amp;diff=14901"/>
		<updated>2026-08-06T00:57:22Z</updated>

		<summary type="html">&lt;p&gt;Yellows8: Undo revision 14897 by Yls8bot (talk)&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;noinclude&amp;gt;&lt;br /&gt;
==Adding an item==&lt;br /&gt;
* Log in to the wiki. Editing is disabled if you don&#039;t have an account.&lt;br /&gt;
* Add the news event to the top of the list, using this format for the date: &amp;lt;tt&amp;gt;&amp;lt;nowiki&amp;gt;&#039;&#039;&#039;&amp;lt;/nowiki&amp;gt;{{#time: d F y}}&amp;lt;nowiki&amp;gt;&#039;&#039;&#039; &amp;lt;/nowiki&amp;gt;&amp;lt;/tt&amp;gt;. Please include the application&#039;s creator, version number, and a link to a page on 3DBrew about the application. No external links please.&lt;br /&gt;
* &#039;&#039;&#039;Move the last entry to the [[:News/Archive|news archive]]. There should be no more than 4 entries in the list.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==Archives==&lt;br /&gt;
For older news, see the [[:News/Archive|news archive]].&lt;br /&gt;
&lt;br /&gt;
=== News ===&lt;br /&gt;
&amp;lt;!-- Add news below --&amp;gt;&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
*&#039;&#039;&#039;16 June 26&#039;&#039;&#039; Nintendo released system update [[22.5.0]].&lt;br /&gt;
*&#039;&#039;&#039;7 April 26&#039;&#039;&#039; Nintendo released system update [[22.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;17 March 26&#039;&#039;&#039; Nintendo released system update [[22.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;20 January 26&#039;&#039;&#039; Nintendo released system update [[19.0.2]] for CHN region.&lt;/div&gt;</summary>
		<author><name>Yellows8</name></author>
	</entry>
	<entry>
		<id>https://switchbrew.org/w/index.php?title=News/Archive&amp;diff=14900</id>
		<title>News/Archive</title>
		<link rel="alternate" type="text/html" href="https://switchbrew.org/w/index.php?title=News/Archive&amp;diff=14900"/>
		<updated>2026-08-06T00:56:50Z</updated>

		<summary type="html">&lt;p&gt;Yellows8: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*&#039;&#039;&#039;13 January 26&#039;&#039;&#039; Nintendo released system update [[21.2.0]].&lt;br /&gt;
*&#039;&#039;&#039;9 December 25&#039;&#039;&#039; Nintendo released system update [[21.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;25 November 25&#039;&#039;&#039; Nintendo released system update [[21.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;11 November 25&#039;&#039;&#039; Nintendo released system update [[21.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;30 September 25&#039;&#039;&#039; Nintendo released system update [[20.5.0]].&lt;br /&gt;
*&#039;&#039;&#039;2 September 25&#039;&#039;&#039; Nintendo released system update [[20.4.0]].&lt;br /&gt;
*&#039;&#039;&#039;29 July 25&#039;&#039;&#039; Nintendo released system update [[20.3.0]].&lt;br /&gt;
*&#039;&#039;&#039;15 July 25&#039;&#039;&#039; Nintendo released system update [[20.2.0]].&lt;br /&gt;
*&#039;&#039;&#039;19 June 25&#039;&#039;&#039; Nintendo released system update [[20.1.5]].&lt;br /&gt;
*&#039;&#039;&#039;3 June 25&#039;&#039;&#039; Nintendo released system update [[20.1.1]].&lt;br /&gt;
*&#039;&#039;&#039;28 May 25&#039;&#039;&#039; Nintendo released system update [[20.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;2 May 25&#039;&#039;&#039; Nintendo released system update [[20.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;30 April 25&#039;&#039;&#039; Nintendo released system update [[20.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;7 January 25&#039;&#039;&#039; Nintendo released a rebootless system update for [[19.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;29 October 24&#039;&#039;&#039; Nintendo released system update [[19.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;8 October 24&#039;&#039;&#039; Nintendo released system update [[19.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;2 July 24&#039;&#039;&#039; Nintendo released a rebootless system update for [[18.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;11 June 24&#039;&#039;&#039; Nintendo released system update [[18.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;23 April 24&#039;&#039;&#039; Nintendo released system update [[18.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;26 March 24&#039;&#039;&#039; Nintendo released system update [[18.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;20 February 24&#039;&#039;&#039; Nintendo released a rebootless system update for [[17.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;5 December 23&#039;&#039;&#039; Nintendo released system update [[17.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;21 November 23&#039;&#039;&#039; Nintendo released a rebootless system update for [[17.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;11 October 23&#039;&#039;&#039; Nintendo released system update [[17.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;22 August 23&#039;&#039;&#039; Nintendo released system update [[16.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;9 May 23&#039;&#039;&#039; Nintendo released system update [[16.0.3]].&lt;br /&gt;
*&#039;&#039;&#039;18 April 23&#039;&#039;&#039; Nintendo released system update [[16.0.2]].&lt;br /&gt;
*&#039;&#039;&#039;23 March 23&#039;&#039;&#039; Nintendo released system update [[16.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;21 February 23&#039;&#039;&#039; Nintendo released system update [[16.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;20 December 22&#039;&#039;&#039; Nintendo released a rebootless system update for [[15.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;1 November 22&#039;&#039;&#039; Nintendo released system update [[15.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;11 October 22&#039;&#039;&#039; Nintendo released system update [[15.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;31 August 22&#039;&#039;&#039; Nintendo released a rebootless system update for [[14.1.2]].&lt;br /&gt;
*&#039;&#039;&#039;26 July 22&#039;&#039;&#039; Nintendo released a rebootless system update for [[14.1.2]].&lt;br /&gt;
*&#039;&#039;&#039;28 June 22&#039;&#039;&#039; Nintendo released a rebootless system update for [[14.1.2]].&lt;br /&gt;
*&#039;&#039;&#039;14 June 22&#039;&#039;&#039; Nintendo released system update [[14.1.2]].&lt;br /&gt;
*&#039;&#039;&#039;19 April 22&#039;&#039;&#039; Nintendo released system update [[14.1.1]].&lt;br /&gt;
*&#039;&#039;&#039;5 April 22&#039;&#039;&#039; Nintendo released system update [[14.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;22 March 22&#039;&#039;&#039; Nintendo released system update [[14.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;20 January 22&#039;&#039;&#039; Nintendo released system update [[13.2.1]].&lt;br /&gt;
*&#039;&#039;&#039;1 December 21&#039;&#039;&#039; Nintendo released system update [[13.2.0]].&lt;br /&gt;
*&#039;&#039;&#039;26 October 21&#039;&#039;&#039; Nintendo released system update [[13.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;15 September 21&#039;&#039;&#039; Nintendo released system update [[13.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;6 July 21&#039;&#039;&#039; Nintendo released system update [[12.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;12 June 21&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=9226&amp;amp;p=17113#p17113 libnx v4.1.0 released].&lt;br /&gt;
*&#039;&#039;&#039;8 June 21&#039;&#039;&#039; Nintendo released system update [[12.0.3]].&lt;br /&gt;
*&#039;&#039;&#039;12 May 21&#039;&#039;&#039; Nintendo released system update [[12.0.2]].&lt;br /&gt;
*&#039;&#039;&#039;20 April 21&#039;&#039;&#039; Nintendo released system update [[12.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;6 April 21&#039;&#039;&#039; Nintendo released system update [[12.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;9 March 21&#039;&#039;&#039; Nintendo released a rebootless system update for [[11.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;11 December 20&#039;&#039;&#039; Nintendo released system update [[11.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;1 December 20&#039;&#039;&#039; Nintendo released system update [[11.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;15 September 20&#039;&#039;&#039; Nintendo released system update [[10.2.0]].&lt;br /&gt;
*&#039;&#039;&#039;28 July 20&#039;&#039;&#039; Nintendo released system update [[10.1.1]].&lt;br /&gt;
*&#039;&#039;&#039;14 July 20&#039;&#039;&#039; Nintendo released system update [[10.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;5 June 20&#039;&#039;&#039; Nintendo released system update [[10.0.4]].&lt;br /&gt;
*&#039;&#039;&#039;26 May 20&#039;&#039;&#039; Nintendo released system update [[10.0.3]].&lt;br /&gt;
*&#039;&#039;&#039;11 May 20&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=9058 devkitA64 r15, libnx v3.2.0, deko3d v0.2.0, switch-examples v20200511] and [https://github.com/switchbrew/nx-hbloader/releases/tag/v2.3.2 nx-hbloader v2.3.2] released.&lt;br /&gt;
*&#039;&#039;&#039;30 April 20&#039;&#039;&#039; Nintendo released system update [[10.0.2]].&lt;br /&gt;
*&#039;&#039;&#039;22 April 20&#039;&#039;&#039; Nintendo released system update [[10.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;14 April 20&#039;&#039;&#039; Nintendo released system update [[10.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;4 April 20&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=9035 libnx v3.1.0, switch-examples v20200404 and deko3d v0.1.0 released]. On the 6th nx-hbmenu v3.3.0 was [https://github.com/switchbrew/nx-hbmenu/releases/latest released].&lt;br /&gt;
*&#039;&#039;&#039;2 April 20&#039;&#039;&#039; [https://github.com/switchbrew/nssu-updater nssu-updater] and [https://github.com/switchbrew/contents-delivery-manager contents-delivery-manager] were released.&lt;br /&gt;
*&#039;&#039;&#039;3 March 20&#039;&#039;&#039; Nintendo released system update [[9.2.0]].&lt;br /&gt;
*&#039;&#039;&#039;10 December 19&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8989 libnx v3.0.0, switch-examples v20191211, Atmosphère v0.10.1, nx-hbmenu v3.2.0, and nx-hbloader v2.3.0 released].&lt;br /&gt;
*&#039;&#039;&#039;4 December 19&#039;&#039;&#039; Nintendo released system update [[9.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;30 September 19&#039;&#039;&#039; Nintendo released system update [[9.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;14 September 19&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8964 libnx v2.5.0 and switch-examples v20190914 released]. nx-hbmenu v3.1.1 [https://github.com/switchbrew/nx-hbmenu/releases/tag/v3.1.1 released]. [https://github.com/Atmosphere-NX/Atmosphere/releases/tag/0.9.4 Atmosphère 0.9.4 released with support for 9.0.0].&lt;br /&gt;
*&#039;&#039;&#039;9 September 19&#039;&#039;&#039; Nintendo released system update [[9.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;10 July 19&#039;&#039;&#039; Nintendo [https://twitter.com/NintendoAmerica/status/1148934589026455552 announced] the Nintendo Switch Lite system.&lt;br /&gt;
*&#039;&#039;&#039;17 June 19&#039;&#039;&#039; Nintendo released system update [[8.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;1 May 19&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8908 libnx v2.2.0 and switch-examples v20190501] released.&lt;br /&gt;
*&#039;&#039;&#039;23 April 19&#039;&#039;&#039; Nintendo released system update [[8.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;15 April 19&#039;&#039;&#039; Nintendo released system update [[8.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;29 March 19&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8891 devkitA64 r13] and [https://github.com/switchbrew/libnx/releases/tag/v2.1.0 libnx v2.1.0] released with pthread/std::thread support.&lt;br /&gt;
*&#039;&#039;&#039;26 March 19&#039;&#039;&#039; [https://github.com/Atmosphere-NX/Atmosphere/releases/tag/0.8.6 Atmosphère v0.8.6] released with lots of bugfixes, more cheat stuff and web applet homebrew support.&lt;br /&gt;
*&#039;&#039;&#039;21 February 19&#039;&#039;&#039; [https://github.com/Atmosphere-NX/Atmosphere/releases/tag/0.8.4 Atmosphère v0.8.4] released with 7.0.x support.&lt;br /&gt;
*&#039;&#039;&#039;18 February 19&#039;&#039;&#039; Nintendo released system update [[7.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;28 January 19&#039;&#039;&#039; Nintendo released system update [[7.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;24 January 19&#039;&#039;&#039; [https://github.com/Atmosphere-NX/Atmosphere/releases/tag/0.8.3 Atmosphère v0.8.3] and [https://github.com/switchbrew/nx-hbloader/releases/tag/v2.1.0 nx-hbloader v2.1.0] were released.&lt;br /&gt;
*&#039;&#039;&#039;2 January 19&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8826 libnx 2.0.0, switch-mesa 18.3 and switch-examples 20190102] were released.&lt;br /&gt;
*&#039;&#039;&#039;29 November 18&#039;&#039;&#039; [https://github.com/Atmosphere-NX/Atmosphere/releases/tag/0.8.0 Atmosphère v0.8.0] was released.&lt;br /&gt;
*&#039;&#039;&#039;29 November 18&#039;&#039;&#039; [https://github.com/switchbrew/nx-hbmenu/releases/latest nx-hbmenu v3.0.1] was released.&lt;br /&gt;
*&#039;&#039;&#039;28 November 18&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8813 libnx 1.6.0 and switch-examples 20181128] were released.&lt;br /&gt;
*&#039;&#039;&#039;19 November 18&#039;&#039;&#039; Nintendo released system update [[6.2.0]].&lt;br /&gt;
*&#039;&#039;&#039;31 October 18&#039;&#039;&#039; [https://github.com/switchbrew/nx-hbloader/releases/tag/v2.0.1 nx-hbloader v2.0.1] was released.&lt;br /&gt;
*&#039;&#039;&#039;29 October 18&#039;&#039;&#039; [https://github.com/switchbrew/nx-hbmenu/releases/latest nx-hbmenu] v3.0.0 was released.&lt;br /&gt;
*&#039;&#039;&#039;29 October 18&#039;&#039;&#039; Nintendo released system update [[6.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;27 October 18&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8798 libnx 1.5.0 and switch-examples 20181027] were released.&lt;br /&gt;
*&#039;&#039;&#039;17 October 18&#039;&#039;&#039; [https://github.com/Atmosphere-NX/Atmosphere/releases/tag/0.7.0 Atmosphère v0.7.0] and [https://github.com/switchbrew/nx-hbloader/releases/tag/v2.0.0 nx-hbloader v2.0.0] were released.&lt;br /&gt;
*&#039;&#039;&#039;8 October 18&#039;&#039;&#039; Nintendo released system update [[6.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;18 September 18&#039;&#039;&#039; Nintendo released system update [[6.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;18 September 18&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8784  libnx 1.4.1, switch-mesa v18.2β and switch-examples 20180918] were released.&lt;br /&gt;
*&#039;&#039;&#039;9 September 18&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8780 libnx v1.4.0] was released alongside a Switch port of mesa/nouveau (GPU library).&lt;br /&gt;
*&#039;&#039;&#039;28 July 18&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8761 devkitA64] r12 and [https://github.com/switchbrew/libnx/releases/tag/v1.3.1 libnx] v1.3.1 were released.&lt;br /&gt;
*&#039;&#039;&#039;8 July 18&#039;&#039;&#039; [https://github.com/switchbrew/libnx/releases/tag/v1.3.0 libnx] v1.3.0 was released.&lt;br /&gt;
*&#039;&#039;&#039;30 May 18&#039;&#039;&#039; Nintendo released system update [[5.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;16 April 18&#039;&#039;&#039; Nintendo released system update [[5.0.2]].&lt;br /&gt;
*&#039;&#039;&#039;26 March 18&#039;&#039;&#039; Nintendo released system update [[5.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;12 March 18&#039;&#039;&#039; Nintendo released system update [[5.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;2 March 18&#039;&#039;&#039; [https://github.com/switchbrew/libnx/releases/tag/v1.1.0 libnx] v1.1.0 was released.&lt;br /&gt;
*&#039;&#039;&#039;28 February 18&#039;&#039;&#039; [https://github.com/switchbrew/nx-hbmenu/releases/latest nx-hbmenu] v2.0.0 was released.&lt;br /&gt;
*&#039;&#039;&#039;22 February 18&#039;&#039;&#039; [http://devkitpro.org devkitPro] released [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8693 devkitA64 alpha7]&lt;br /&gt;
*&#039;&#039;&#039;18 February 18&#039;&#039;&#039; [https://switchbrew.github.io/nx-hbl/ nx-hbl] and [https://github.com/switchbrew/nx-hbmenu nx-hbmenu] were released.&lt;br /&gt;
*&#039;&#039;&#039;28 December 17&#039;&#039;&#039; The 34c3 Switch [https://events.ccc.de/congress/2017/Fahrplan/events/8941.html talk] took place, video available [https://media.ccc.de/v/34c3-8941-console_security_-_switch here].&lt;br /&gt;
*&#039;&#039;&#039;4 December 17&#039;&#039;&#039; Nintendo released system update [[4.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;25 October 17&#039;&#039;&#039; Nintendo released system update [[4.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;18 October 17&#039;&#039;&#039; Nintendo released system update [[4.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;17 September 17&#039;&#039;&#039; [https://github.com/switchbrew/libnx libnx] was made public, with examples available [https://github.com/switchbrew/switch-examples here].&lt;br /&gt;
*&#039;&#039;&#039;5 September 17&#039;&#039;&#039; Nintendo released system update [[3.0.2]].&lt;br /&gt;
*&#039;&#039;&#039;31 July 17&#039;&#039;&#039; Nintendo released system update [[3.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;19 June 17&#039;&#039;&#039; Nintendo released system update [[3.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;15 May 17&#039;&#039;&#039; Nintendo released system update [[2.3.0]].&lt;br /&gt;
*&#039;&#039;&#039;17 April 17&#039;&#039;&#039; Nintendo released system update [[2.2.0]].&lt;br /&gt;
*&#039;&#039;&#039;27 March 17&#039;&#039;&#039; Nintendo released system update [[2.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;2 March 17&#039;&#039;&#039; Nintendo released system update [[2.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;3 March 17&#039;&#039;&#039; Nintendo Switch global release.&lt;/div&gt;</summary>
		<author><name>Yellows8</name></author>
	</entry>
	<entry>
		<id>https://switchbrew.org/w/index.php?title=News&amp;diff=14895</id>
		<title>News</title>
		<link rel="alternate" type="text/html" href="https://switchbrew.org/w/index.php?title=News&amp;diff=14895"/>
		<updated>2026-08-06T00:53:41Z</updated>

		<summary type="html">&lt;p&gt;Yellows8: Reverted edits by Yls8bot (talk) to last revision by Yellows8&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;noinclude&amp;gt;&lt;br /&gt;
==Adding an item==&lt;br /&gt;
* Log in to the wiki. Editing is disabled if you don&#039;t have an account.&lt;br /&gt;
* Add the news event to the top of the list, using this format for the date: &amp;lt;tt&amp;gt;&amp;lt;nowiki&amp;gt;&#039;&#039;&#039;&amp;lt;/nowiki&amp;gt;{{#time: d F y}}&amp;lt;nowiki&amp;gt;&#039;&#039;&#039; &amp;lt;/nowiki&amp;gt;&amp;lt;/tt&amp;gt;. Please include the application&#039;s creator, version number, and a link to a page on 3DBrew about the application. No external links please.&lt;br /&gt;
* &#039;&#039;&#039;Move the last entry to the [[:News/Archive|news archive]]. There should be no more than 4 entries in the list.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==Archives==&lt;br /&gt;
For older news, see the [[:News/Archive|news archive]].&lt;br /&gt;
&lt;br /&gt;
=== News ===&lt;br /&gt;
&amp;lt;!-- Add news below --&amp;gt;&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
*&#039;&#039;&#039;16 June 26&#039;&#039;&#039; Nintendo released system update [[22.5.0]].&lt;br /&gt;
*&#039;&#039;&#039;7 April 26&#039;&#039;&#039; Nintendo released system update [[22.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;17 March 26&#039;&#039;&#039; Nintendo released system update [[22.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;20 January 26&#039;&#039;&#039; Nintendo released system update [[19.0.2]] for CHN region.&lt;/div&gt;</summary>
		<author><name>Yellows8</name></author>
	</entry>
	<entry>
		<id>https://switchbrew.org/w/index.php?title=News/Archive&amp;diff=14894</id>
		<title>News/Archive</title>
		<link rel="alternate" type="text/html" href="https://switchbrew.org/w/index.php?title=News/Archive&amp;diff=14894"/>
		<updated>2026-08-06T00:52:55Z</updated>

		<summary type="html">&lt;p&gt;Yellows8: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*&#039;&#039;&#039;13 January 26&#039;&#039;&#039; Nintendo released system update [[21.2.0]].&lt;br /&gt;
*&#039;&#039;&#039;9 December 25&#039;&#039;&#039; Nintendo released system update [[21.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;25 November 25&#039;&#039;&#039; Nintendo released system update [[21.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;11 November 25&#039;&#039;&#039; Nintendo released system update [[21.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;30 September 25&#039;&#039;&#039; Nintendo released system update [[20.5.0]].&lt;br /&gt;
*&#039;&#039;&#039;2 September 25&#039;&#039;&#039; Nintendo released system update [[20.4.0]].&lt;br /&gt;
*&#039;&#039;&#039;29 July 25&#039;&#039;&#039; Nintendo released system update [[20.3.0]].&lt;br /&gt;
*&#039;&#039;&#039;15 July 25&#039;&#039;&#039; Nintendo released system update [[20.2.0]].&lt;br /&gt;
*&#039;&#039;&#039;19 June 25&#039;&#039;&#039; Nintendo released system update [[20.1.5]].&lt;br /&gt;
*&#039;&#039;&#039;3 June 25&#039;&#039;&#039; Nintendo released system update [[20.1.1]].&lt;br /&gt;
*&#039;&#039;&#039;28 May 25&#039;&#039;&#039; Nintendo released system update [[20.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;2 May 25&#039;&#039;&#039; Nintendo released system update [[20.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;30 April 25&#039;&#039;&#039; Nintendo released system update [[20.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;7 January 25&#039;&#039;&#039; Nintendo released a rebootless system update for [[19.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;29 October 24&#039;&#039;&#039; Nintendo released system update [[19.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;8 October 24&#039;&#039;&#039; Nintendo released system update [[19.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;2 July 24&#039;&#039;&#039; Nintendo released a rebootless system update for [[18.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;11 June 24&#039;&#039;&#039; Nintendo released system update [[18.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;23 April 24&#039;&#039;&#039; Nintendo released system update [[18.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;26 March 24&#039;&#039;&#039; Nintendo released system update [[18.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;20 February 24&#039;&#039;&#039; Nintendo released a rebootless system update for [[17.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;5 December 23&#039;&#039;&#039; Nintendo released system update [[17.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;21 November 23&#039;&#039;&#039; Nintendo released a rebootless system update for [[17.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;11 October 23&#039;&#039;&#039; Nintendo released system update [[17.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;22 August 23&#039;&#039;&#039; Nintendo released system update [[16.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;9 May 23&#039;&#039;&#039; Nintendo released system update [[16.0.3]].&lt;br /&gt;
*&#039;&#039;&#039;18 April 23&#039;&#039;&#039; Nintendo released system update [[16.0.2]].&lt;br /&gt;
*&#039;&#039;&#039;23 March 23&#039;&#039;&#039; Nintendo released system update [[16.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;21 February 23&#039;&#039;&#039; Nintendo released system update [[16.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;1 November 22&#039;&#039;&#039; Nintendo released system update [[15.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;11 October 22&#039;&#039;&#039; Nintendo released system update [[15.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;31 August 22&#039;&#039;&#039; Nintendo released a rebootless system update for [[14.1.2]].&lt;br /&gt;
*&#039;&#039;&#039;26 July 22&#039;&#039;&#039; Nintendo released a rebootless system update for [[14.1.2]].&lt;br /&gt;
*&#039;&#039;&#039;28 June 22&#039;&#039;&#039; Nintendo released a rebootless system update for [[14.1.2]].&lt;br /&gt;
*&#039;&#039;&#039;14 June 22&#039;&#039;&#039; Nintendo released system update [[14.1.2]].&lt;br /&gt;
*&#039;&#039;&#039;19 April 22&#039;&#039;&#039; Nintendo released system update [[14.1.1]].&lt;br /&gt;
*&#039;&#039;&#039;5 April 22&#039;&#039;&#039; Nintendo released system update [[14.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;22 March 22&#039;&#039;&#039; Nintendo released system update [[14.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;20 January 22&#039;&#039;&#039; Nintendo released system update [[13.2.1]].&lt;br /&gt;
*&#039;&#039;&#039;1 December 21&#039;&#039;&#039; Nintendo released system update [[13.2.0]].&lt;br /&gt;
*&#039;&#039;&#039;26 October 21&#039;&#039;&#039; Nintendo released system update [[13.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;15 September 21&#039;&#039;&#039; Nintendo released system update [[13.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;6 July 21&#039;&#039;&#039; Nintendo released system update [[12.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;12 June 21&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=9226&amp;amp;p=17113#p17113 libnx v4.1.0 released].&lt;br /&gt;
*&#039;&#039;&#039;8 June 21&#039;&#039;&#039; Nintendo released system update [[12.0.3]].&lt;br /&gt;
*&#039;&#039;&#039;12 May 21&#039;&#039;&#039; Nintendo released system update [[12.0.2]].&lt;br /&gt;
*&#039;&#039;&#039;20 April 21&#039;&#039;&#039; Nintendo released system update [[12.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;6 April 21&#039;&#039;&#039; Nintendo released system update [[12.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;9 March 21&#039;&#039;&#039; Nintendo released a rebootless system update for [[11.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;11 December 20&#039;&#039;&#039; Nintendo released system update [[11.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;1 December 20&#039;&#039;&#039; Nintendo released system update [[11.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;15 September 20&#039;&#039;&#039; Nintendo released system update [[10.2.0]].&lt;br /&gt;
*&#039;&#039;&#039;28 July 20&#039;&#039;&#039; Nintendo released system update [[10.1.1]].&lt;br /&gt;
*&#039;&#039;&#039;14 July 20&#039;&#039;&#039; Nintendo released system update [[10.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;5 June 20&#039;&#039;&#039; Nintendo released system update [[10.0.4]].&lt;br /&gt;
*&#039;&#039;&#039;26 May 20&#039;&#039;&#039; Nintendo released system update [[10.0.3]].&lt;br /&gt;
*&#039;&#039;&#039;11 May 20&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=9058 devkitA64 r15, libnx v3.2.0, deko3d v0.2.0, switch-examples v20200511] and [https://github.com/switchbrew/nx-hbloader/releases/tag/v2.3.2 nx-hbloader v2.3.2] released.&lt;br /&gt;
*&#039;&#039;&#039;30 April 20&#039;&#039;&#039; Nintendo released system update [[10.0.2]].&lt;br /&gt;
*&#039;&#039;&#039;22 April 20&#039;&#039;&#039; Nintendo released system update [[10.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;14 April 20&#039;&#039;&#039; Nintendo released system update [[10.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;4 April 20&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=9035 libnx v3.1.0, switch-examples v20200404 and deko3d v0.1.0 released]. On the 6th nx-hbmenu v3.3.0 was [https://github.com/switchbrew/nx-hbmenu/releases/latest released].&lt;br /&gt;
*&#039;&#039;&#039;2 April 20&#039;&#039;&#039; [https://github.com/switchbrew/nssu-updater nssu-updater] and [https://github.com/switchbrew/contents-delivery-manager contents-delivery-manager] were released.&lt;br /&gt;
*&#039;&#039;&#039;3 March 20&#039;&#039;&#039; Nintendo released system update [[9.2.0]].&lt;br /&gt;
*&#039;&#039;&#039;10 December 19&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8989 libnx v3.0.0, switch-examples v20191211, Atmosphère v0.10.1, nx-hbmenu v3.2.0, and nx-hbloader v2.3.0 released].&lt;br /&gt;
*&#039;&#039;&#039;4 December 19&#039;&#039;&#039; Nintendo released system update [[9.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;30 September 19&#039;&#039;&#039; Nintendo released system update [[9.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;14 September 19&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8964 libnx v2.5.0 and switch-examples v20190914 released]. nx-hbmenu v3.1.1 [https://github.com/switchbrew/nx-hbmenu/releases/tag/v3.1.1 released]. [https://github.com/Atmosphere-NX/Atmosphere/releases/tag/0.9.4 Atmosphère 0.9.4 released with support for 9.0.0].&lt;br /&gt;
*&#039;&#039;&#039;9 September 19&#039;&#039;&#039; Nintendo released system update [[9.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;10 July 19&#039;&#039;&#039; Nintendo [https://twitter.com/NintendoAmerica/status/1148934589026455552 announced] the Nintendo Switch Lite system.&lt;br /&gt;
*&#039;&#039;&#039;17 June 19&#039;&#039;&#039; Nintendo released system update [[8.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;1 May 19&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8908 libnx v2.2.0 and switch-examples v20190501] released.&lt;br /&gt;
*&#039;&#039;&#039;23 April 19&#039;&#039;&#039; Nintendo released system update [[8.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;15 April 19&#039;&#039;&#039; Nintendo released system update [[8.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;29 March 19&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8891 devkitA64 r13] and [https://github.com/switchbrew/libnx/releases/tag/v2.1.0 libnx v2.1.0] released with pthread/std::thread support.&lt;br /&gt;
*&#039;&#039;&#039;26 March 19&#039;&#039;&#039; [https://github.com/Atmosphere-NX/Atmosphere/releases/tag/0.8.6 Atmosphère v0.8.6] released with lots of bugfixes, more cheat stuff and web applet homebrew support.&lt;br /&gt;
*&#039;&#039;&#039;21 February 19&#039;&#039;&#039; [https://github.com/Atmosphere-NX/Atmosphere/releases/tag/0.8.4 Atmosphère v0.8.4] released with 7.0.x support.&lt;br /&gt;
*&#039;&#039;&#039;18 February 19&#039;&#039;&#039; Nintendo released system update [[7.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;28 January 19&#039;&#039;&#039; Nintendo released system update [[7.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;24 January 19&#039;&#039;&#039; [https://github.com/Atmosphere-NX/Atmosphere/releases/tag/0.8.3 Atmosphère v0.8.3] and [https://github.com/switchbrew/nx-hbloader/releases/tag/v2.1.0 nx-hbloader v2.1.0] were released.&lt;br /&gt;
*&#039;&#039;&#039;2 January 19&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8826 libnx 2.0.0, switch-mesa 18.3 and switch-examples 20190102] were released.&lt;br /&gt;
*&#039;&#039;&#039;29 November 18&#039;&#039;&#039; [https://github.com/Atmosphere-NX/Atmosphere/releases/tag/0.8.0 Atmosphère v0.8.0] was released.&lt;br /&gt;
*&#039;&#039;&#039;29 November 18&#039;&#039;&#039; [https://github.com/switchbrew/nx-hbmenu/releases/latest nx-hbmenu v3.0.1] was released.&lt;br /&gt;
*&#039;&#039;&#039;28 November 18&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8813 libnx 1.6.0 and switch-examples 20181128] were released.&lt;br /&gt;
*&#039;&#039;&#039;19 November 18&#039;&#039;&#039; Nintendo released system update [[6.2.0]].&lt;br /&gt;
*&#039;&#039;&#039;31 October 18&#039;&#039;&#039; [https://github.com/switchbrew/nx-hbloader/releases/tag/v2.0.1 nx-hbloader v2.0.1] was released.&lt;br /&gt;
*&#039;&#039;&#039;29 October 18&#039;&#039;&#039; [https://github.com/switchbrew/nx-hbmenu/releases/latest nx-hbmenu] v3.0.0 was released.&lt;br /&gt;
*&#039;&#039;&#039;29 October 18&#039;&#039;&#039; Nintendo released system update [[6.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;27 October 18&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8798 libnx 1.5.0 and switch-examples 20181027] were released.&lt;br /&gt;
*&#039;&#039;&#039;17 October 18&#039;&#039;&#039; [https://github.com/Atmosphere-NX/Atmosphere/releases/tag/0.7.0 Atmosphère v0.7.0] and [https://github.com/switchbrew/nx-hbloader/releases/tag/v2.0.0 nx-hbloader v2.0.0] were released.&lt;br /&gt;
*&#039;&#039;&#039;8 October 18&#039;&#039;&#039; Nintendo released system update [[6.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;18 September 18&#039;&#039;&#039; Nintendo released system update [[6.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;18 September 18&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8784  libnx 1.4.1, switch-mesa v18.2β and switch-examples 20180918] were released.&lt;br /&gt;
*&#039;&#039;&#039;9 September 18&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8780 libnx v1.4.0] was released alongside a Switch port of mesa/nouveau (GPU library).&lt;br /&gt;
*&#039;&#039;&#039;28 July 18&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8761 devkitA64] r12 and [https://github.com/switchbrew/libnx/releases/tag/v1.3.1 libnx] v1.3.1 were released.&lt;br /&gt;
*&#039;&#039;&#039;8 July 18&#039;&#039;&#039; [https://github.com/switchbrew/libnx/releases/tag/v1.3.0 libnx] v1.3.0 was released.&lt;br /&gt;
*&#039;&#039;&#039;30 May 18&#039;&#039;&#039; Nintendo released system update [[5.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;16 April 18&#039;&#039;&#039; Nintendo released system update [[5.0.2]].&lt;br /&gt;
*&#039;&#039;&#039;26 March 18&#039;&#039;&#039; Nintendo released system update [[5.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;12 March 18&#039;&#039;&#039; Nintendo released system update [[5.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;2 March 18&#039;&#039;&#039; [https://github.com/switchbrew/libnx/releases/tag/v1.1.0 libnx] v1.1.0 was released.&lt;br /&gt;
*&#039;&#039;&#039;28 February 18&#039;&#039;&#039; [https://github.com/switchbrew/nx-hbmenu/releases/latest nx-hbmenu] v2.0.0 was released.&lt;br /&gt;
*&#039;&#039;&#039;22 February 18&#039;&#039;&#039; [http://devkitpro.org devkitPro] released [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8693 devkitA64 alpha7]&lt;br /&gt;
*&#039;&#039;&#039;18 February 18&#039;&#039;&#039; [https://switchbrew.github.io/nx-hbl/ nx-hbl] and [https://github.com/switchbrew/nx-hbmenu nx-hbmenu] were released.&lt;br /&gt;
*&#039;&#039;&#039;28 December 17&#039;&#039;&#039; The 34c3 Switch [https://events.ccc.de/congress/2017/Fahrplan/events/8941.html talk] took place, video available [https://media.ccc.de/v/34c3-8941-console_security_-_switch here].&lt;br /&gt;
*&#039;&#039;&#039;4 December 17&#039;&#039;&#039; Nintendo released system update [[4.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;25 October 17&#039;&#039;&#039; Nintendo released system update [[4.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;18 October 17&#039;&#039;&#039; Nintendo released system update [[4.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;17 September 17&#039;&#039;&#039; [https://github.com/switchbrew/libnx libnx] was made public, with examples available [https://github.com/switchbrew/switch-examples here].&lt;br /&gt;
*&#039;&#039;&#039;5 September 17&#039;&#039;&#039; Nintendo released system update [[3.0.2]].&lt;br /&gt;
*&#039;&#039;&#039;31 July 17&#039;&#039;&#039; Nintendo released system update [[3.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;19 June 17&#039;&#039;&#039; Nintendo released system update [[3.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;15 May 17&#039;&#039;&#039; Nintendo released system update [[2.3.0]].&lt;br /&gt;
*&#039;&#039;&#039;17 April 17&#039;&#039;&#039; Nintendo released system update [[2.2.0]].&lt;br /&gt;
*&#039;&#039;&#039;27 March 17&#039;&#039;&#039; Nintendo released system update [[2.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;2 March 17&#039;&#039;&#039; Nintendo released system update [[2.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;3 March 17&#039;&#039;&#039; Nintendo Switch global release.&lt;/div&gt;</summary>
		<author><name>Yellows8</name></author>
	</entry>
	<entry>
		<id>https://switchbrew.org/w/index.php?title=News/Archive&amp;diff=14893</id>
		<title>News/Archive</title>
		<link rel="alternate" type="text/html" href="https://switchbrew.org/w/index.php?title=News/Archive&amp;diff=14893"/>
		<updated>2026-08-06T00:49:28Z</updated>

		<summary type="html">&lt;p&gt;Yellows8: Reverted edits by Yls8bot (talk) to last revision by Yellows8&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*&#039;&#039;&#039;13 January 26&#039;&#039;&#039; Nintendo released system update [[21.2.0]].&lt;br /&gt;
*&#039;&#039;&#039;9 December 25&#039;&#039;&#039; Nintendo released system update [[21.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;25 November 25&#039;&#039;&#039; Nintendo released system update [[21.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;11 November 25&#039;&#039;&#039; Nintendo released system update [[21.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;30 September 25&#039;&#039;&#039; Nintendo released system update [[20.5.0]].&lt;br /&gt;
*&#039;&#039;&#039;2 September 25&#039;&#039;&#039; Nintendo released system update [[20.4.0]].&lt;br /&gt;
*&#039;&#039;&#039;29 July 25&#039;&#039;&#039; Nintendo released system update [[20.3.0]].&lt;br /&gt;
*&#039;&#039;&#039;15 July 25&#039;&#039;&#039; Nintendo released system update [[20.2.0]].&lt;br /&gt;
*&#039;&#039;&#039;19 June 25&#039;&#039;&#039; Nintendo released system update [[20.1.5]].&lt;br /&gt;
*&#039;&#039;&#039;3 June 25&#039;&#039;&#039; Nintendo released system update [[20.1.1]].&lt;br /&gt;
*&#039;&#039;&#039;28 May 25&#039;&#039;&#039; Nintendo released system update [[20.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;2 May 25&#039;&#039;&#039; Nintendo released system update [[20.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;30 April 25&#039;&#039;&#039; Nintendo released system update [[20.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;7 January 25&#039;&#039;&#039; Nintendo released a rebootless system update for [[19.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;29 October 24&#039;&#039;&#039; Nintendo released system update [[19.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;8 October 24&#039;&#039;&#039; Nintendo released system update [[19.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;2 July 24&#039;&#039;&#039; Nintendo released a rebootless system update for [[18.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;11 June 24&#039;&#039;&#039; Nintendo released system update [[18.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;23 April 24&#039;&#039;&#039; Nintendo released system update [[18.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;26 March 24&#039;&#039;&#039; Nintendo released system update [[18.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;20 February 24&#039;&#039;&#039; Nintendo released a rebootless system update for [[17.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;5 December 23&#039;&#039;&#039; Nintendo released system update [[17.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;21 November 23&#039;&#039;&#039; Nintendo released a rebootless system update for [[17.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;11 October 23&#039;&#039;&#039; Nintendo released system update [[17.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;22 August 23&#039;&#039;&#039; Nintendo released system update [[16.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;9 May 23&#039;&#039;&#039; Nintendo released system update [[16.0.3]].&lt;br /&gt;
*&#039;&#039;&#039;18 April 23&#039;&#039;&#039; Nintendo released system update [[16.0.2]].&lt;br /&gt;
*&#039;&#039;&#039;23 March 23&#039;&#039;&#039; Nintendo released system update [[16.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;21 February 23&#039;&#039;&#039; Nintendo released system update [[16.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;1 November 22&#039;&#039;&#039; Nintendo released system update [[15.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;11 October 22&#039;&#039;&#039; Nintendo released system update [[15.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;14 June 22&#039;&#039;&#039; Nintendo released system update [[14.1.2]].&lt;br /&gt;
*&#039;&#039;&#039;19 April 22&#039;&#039;&#039; Nintendo released system update [[14.1.1]].&lt;br /&gt;
*&#039;&#039;&#039;5 April 22&#039;&#039;&#039; Nintendo released system update [[14.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;22 March 22&#039;&#039;&#039; Nintendo released system update [[14.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;20 January 22&#039;&#039;&#039; Nintendo released system update [[13.2.1]].&lt;br /&gt;
*&#039;&#039;&#039;1 December 21&#039;&#039;&#039; Nintendo released system update [[13.2.0]].&lt;br /&gt;
*&#039;&#039;&#039;26 October 21&#039;&#039;&#039; Nintendo released system update [[13.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;15 September 21&#039;&#039;&#039; Nintendo released system update [[13.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;6 July 21&#039;&#039;&#039; Nintendo released system update [[12.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;12 June 21&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=9226&amp;amp;p=17113#p17113 libnx v4.1.0 released].&lt;br /&gt;
*&#039;&#039;&#039;8 June 21&#039;&#039;&#039; Nintendo released system update [[12.0.3]].&lt;br /&gt;
*&#039;&#039;&#039;12 May 21&#039;&#039;&#039; Nintendo released system update [[12.0.2]].&lt;br /&gt;
*&#039;&#039;&#039;20 April 21&#039;&#039;&#039; Nintendo released system update [[12.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;6 April 21&#039;&#039;&#039; Nintendo released system update [[12.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;9 March 21&#039;&#039;&#039; Nintendo released a rebootless system update for [[11.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;11 December 20&#039;&#039;&#039; Nintendo released system update [[11.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;1 December 20&#039;&#039;&#039; Nintendo released system update [[11.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;15 September 20&#039;&#039;&#039; Nintendo released system update [[10.2.0]].&lt;br /&gt;
*&#039;&#039;&#039;28 July 20&#039;&#039;&#039; Nintendo released system update [[10.1.1]].&lt;br /&gt;
*&#039;&#039;&#039;14 July 20&#039;&#039;&#039; Nintendo released system update [[10.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;5 June 20&#039;&#039;&#039; Nintendo released system update [[10.0.4]].&lt;br /&gt;
*&#039;&#039;&#039;26 May 20&#039;&#039;&#039; Nintendo released system update [[10.0.3]].&lt;br /&gt;
*&#039;&#039;&#039;11 May 20&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=9058 devkitA64 r15, libnx v3.2.0, deko3d v0.2.0, switch-examples v20200511] and [https://github.com/switchbrew/nx-hbloader/releases/tag/v2.3.2 nx-hbloader v2.3.2] released.&lt;br /&gt;
*&#039;&#039;&#039;30 April 20&#039;&#039;&#039; Nintendo released system update [[10.0.2]].&lt;br /&gt;
*&#039;&#039;&#039;22 April 20&#039;&#039;&#039; Nintendo released system update [[10.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;14 April 20&#039;&#039;&#039; Nintendo released system update [[10.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;4 April 20&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=9035 libnx v3.1.0, switch-examples v20200404 and deko3d v0.1.0 released]. On the 6th nx-hbmenu v3.3.0 was [https://github.com/switchbrew/nx-hbmenu/releases/latest released].&lt;br /&gt;
*&#039;&#039;&#039;2 April 20&#039;&#039;&#039; [https://github.com/switchbrew/nssu-updater nssu-updater] and [https://github.com/switchbrew/contents-delivery-manager contents-delivery-manager] were released.&lt;br /&gt;
*&#039;&#039;&#039;3 March 20&#039;&#039;&#039; Nintendo released system update [[9.2.0]].&lt;br /&gt;
*&#039;&#039;&#039;10 December 19&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8989 libnx v3.0.0, switch-examples v20191211, Atmosphère v0.10.1, nx-hbmenu v3.2.0, and nx-hbloader v2.3.0 released].&lt;br /&gt;
*&#039;&#039;&#039;4 December 19&#039;&#039;&#039; Nintendo released system update [[9.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;30 September 19&#039;&#039;&#039; Nintendo released system update [[9.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;14 September 19&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8964 libnx v2.5.0 and switch-examples v20190914 released]. nx-hbmenu v3.1.1 [https://github.com/switchbrew/nx-hbmenu/releases/tag/v3.1.1 released]. [https://github.com/Atmosphere-NX/Atmosphere/releases/tag/0.9.4 Atmosphère 0.9.4 released with support for 9.0.0].&lt;br /&gt;
*&#039;&#039;&#039;9 September 19&#039;&#039;&#039; Nintendo released system update [[9.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;10 July 19&#039;&#039;&#039; Nintendo [https://twitter.com/NintendoAmerica/status/1148934589026455552 announced] the Nintendo Switch Lite system.&lt;br /&gt;
*&#039;&#039;&#039;17 June 19&#039;&#039;&#039; Nintendo released system update [[8.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;1 May 19&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8908 libnx v2.2.0 and switch-examples v20190501] released.&lt;br /&gt;
*&#039;&#039;&#039;23 April 19&#039;&#039;&#039; Nintendo released system update [[8.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;15 April 19&#039;&#039;&#039; Nintendo released system update [[8.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;29 March 19&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8891 devkitA64 r13] and [https://github.com/switchbrew/libnx/releases/tag/v2.1.0 libnx v2.1.0] released with pthread/std::thread support.&lt;br /&gt;
*&#039;&#039;&#039;26 March 19&#039;&#039;&#039; [https://github.com/Atmosphere-NX/Atmosphere/releases/tag/0.8.6 Atmosphère v0.8.6] released with lots of bugfixes, more cheat stuff and web applet homebrew support.&lt;br /&gt;
*&#039;&#039;&#039;21 February 19&#039;&#039;&#039; [https://github.com/Atmosphere-NX/Atmosphere/releases/tag/0.8.4 Atmosphère v0.8.4] released with 7.0.x support.&lt;br /&gt;
*&#039;&#039;&#039;18 February 19&#039;&#039;&#039; Nintendo released system update [[7.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;28 January 19&#039;&#039;&#039; Nintendo released system update [[7.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;24 January 19&#039;&#039;&#039; [https://github.com/Atmosphere-NX/Atmosphere/releases/tag/0.8.3 Atmosphère v0.8.3] and [https://github.com/switchbrew/nx-hbloader/releases/tag/v2.1.0 nx-hbloader v2.1.0] were released.&lt;br /&gt;
*&#039;&#039;&#039;2 January 19&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8826 libnx 2.0.0, switch-mesa 18.3 and switch-examples 20190102] were released.&lt;br /&gt;
*&#039;&#039;&#039;29 November 18&#039;&#039;&#039; [https://github.com/Atmosphere-NX/Atmosphere/releases/tag/0.8.0 Atmosphère v0.8.0] was released.&lt;br /&gt;
*&#039;&#039;&#039;29 November 18&#039;&#039;&#039; [https://github.com/switchbrew/nx-hbmenu/releases/latest nx-hbmenu v3.0.1] was released.&lt;br /&gt;
*&#039;&#039;&#039;28 November 18&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8813 libnx 1.6.0 and switch-examples 20181128] were released.&lt;br /&gt;
*&#039;&#039;&#039;19 November 18&#039;&#039;&#039; Nintendo released system update [[6.2.0]].&lt;br /&gt;
*&#039;&#039;&#039;31 October 18&#039;&#039;&#039; [https://github.com/switchbrew/nx-hbloader/releases/tag/v2.0.1 nx-hbloader v2.0.1] was released.&lt;br /&gt;
*&#039;&#039;&#039;29 October 18&#039;&#039;&#039; [https://github.com/switchbrew/nx-hbmenu/releases/latest nx-hbmenu] v3.0.0 was released.&lt;br /&gt;
*&#039;&#039;&#039;29 October 18&#039;&#039;&#039; Nintendo released system update [[6.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;27 October 18&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8798 libnx 1.5.0 and switch-examples 20181027] were released.&lt;br /&gt;
*&#039;&#039;&#039;17 October 18&#039;&#039;&#039; [https://github.com/Atmosphere-NX/Atmosphere/releases/tag/0.7.0 Atmosphère v0.7.0] and [https://github.com/switchbrew/nx-hbloader/releases/tag/v2.0.0 nx-hbloader v2.0.0] were released.&lt;br /&gt;
*&#039;&#039;&#039;8 October 18&#039;&#039;&#039; Nintendo released system update [[6.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;18 September 18&#039;&#039;&#039; Nintendo released system update [[6.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;18 September 18&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8784  libnx 1.4.1, switch-mesa v18.2β and switch-examples 20180918] were released.&lt;br /&gt;
*&#039;&#039;&#039;9 September 18&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8780 libnx v1.4.0] was released alongside a Switch port of mesa/nouveau (GPU library).&lt;br /&gt;
*&#039;&#039;&#039;28 July 18&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8761 devkitA64] r12 and [https://github.com/switchbrew/libnx/releases/tag/v1.3.1 libnx] v1.3.1 were released.&lt;br /&gt;
*&#039;&#039;&#039;8 July 18&#039;&#039;&#039; [https://github.com/switchbrew/libnx/releases/tag/v1.3.0 libnx] v1.3.0 was released.&lt;br /&gt;
*&#039;&#039;&#039;30 May 18&#039;&#039;&#039; Nintendo released system update [[5.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;16 April 18&#039;&#039;&#039; Nintendo released system update [[5.0.2]].&lt;br /&gt;
*&#039;&#039;&#039;26 March 18&#039;&#039;&#039; Nintendo released system update [[5.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;12 March 18&#039;&#039;&#039; Nintendo released system update [[5.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;2 March 18&#039;&#039;&#039; [https://github.com/switchbrew/libnx/releases/tag/v1.1.0 libnx] v1.1.0 was released.&lt;br /&gt;
*&#039;&#039;&#039;28 February 18&#039;&#039;&#039; [https://github.com/switchbrew/nx-hbmenu/releases/latest nx-hbmenu] v2.0.0 was released.&lt;br /&gt;
*&#039;&#039;&#039;22 February 18&#039;&#039;&#039; [http://devkitpro.org devkitPro] released [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8693 devkitA64 alpha7]&lt;br /&gt;
*&#039;&#039;&#039;18 February 18&#039;&#039;&#039; [https://switchbrew.github.io/nx-hbl/ nx-hbl] and [https://github.com/switchbrew/nx-hbmenu nx-hbmenu] were released.&lt;br /&gt;
*&#039;&#039;&#039;28 December 17&#039;&#039;&#039; The 34c3 Switch [https://events.ccc.de/congress/2017/Fahrplan/events/8941.html talk] took place, video available [https://media.ccc.de/v/34c3-8941-console_security_-_switch here].&lt;br /&gt;
*&#039;&#039;&#039;4 December 17&#039;&#039;&#039; Nintendo released system update [[4.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;25 October 17&#039;&#039;&#039; Nintendo released system update [[4.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;18 October 17&#039;&#039;&#039; Nintendo released system update [[4.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;17 September 17&#039;&#039;&#039; [https://github.com/switchbrew/libnx libnx] was made public, with examples available [https://github.com/switchbrew/switch-examples here].&lt;br /&gt;
*&#039;&#039;&#039;5 September 17&#039;&#039;&#039; Nintendo released system update [[3.0.2]].&lt;br /&gt;
*&#039;&#039;&#039;31 July 17&#039;&#039;&#039; Nintendo released system update [[3.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;19 June 17&#039;&#039;&#039; Nintendo released system update [[3.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;15 May 17&#039;&#039;&#039; Nintendo released system update [[2.3.0]].&lt;br /&gt;
*&#039;&#039;&#039;17 April 17&#039;&#039;&#039; Nintendo released system update [[2.2.0]].&lt;br /&gt;
*&#039;&#039;&#039;27 March 17&#039;&#039;&#039; Nintendo released system update [[2.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;2 March 17&#039;&#039;&#039; Nintendo released system update [[2.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;3 March 17&#039;&#039;&#039; Nintendo Switch global release.&lt;/div&gt;</summary>
		<author><name>Yellows8</name></author>
	</entry>
	<entry>
		<id>https://switchbrew.org/w/index.php?title=13.0.0&amp;diff=14892</id>
		<title>13.0.0</title>
		<link rel="alternate" type="text/html" href="https://switchbrew.org/w/index.php?title=13.0.0&amp;diff=14892"/>
		<updated>2026-08-06T00:46:33Z</updated>

		<summary type="html">&lt;p&gt;Yellows8: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The Switch 13.0.0 system update was released on September 15, 2021 (UTC). This Switch update was released for the following regions: ALL.&lt;br /&gt;
&lt;br /&gt;
Security flaws fixed: &amp;lt;fill this in manually later, see the updatedetails page from the ninupdates-report page(s) once available for now&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
==Change-log==&lt;br /&gt;
[https://en-americas-support.nintendo.com/app/answers/detail/a_id/22525/kw/nintendo%20switch%20system%20update Official] ALL change-log:&lt;br /&gt;
* 	Bluetooth® audio support was added.&lt;br /&gt;
* 		&lt;br /&gt;
* 			Headphones, earbuds, speakers, and other audio devices that connect with Bluetooth can now be paired with Nintendo Switch family systems for audio output. &lt;br /&gt;
* 				&lt;br /&gt;
* 					Bluetooth microphones are not supported.&lt;br /&gt;
* 					Up to two compatible wireless controllers can be connected to the system while using Bluetooth audio.&lt;br /&gt;
* 					Bluetooth audio cannot be used while local wireless communication is active.&lt;br /&gt;
* 					For more information, see How to Pair and Manage Bluetooth Audio Devices.&lt;br /&gt;
* 				&lt;br /&gt;
* 			&lt;br /&gt;
* 		&lt;br /&gt;
* 	&lt;br /&gt;
* 	&lt;br /&gt;
* 	“Update Dock” was added under System in System Settings for Nintendo Switch and Nintendo Switch – OLED Model systems, allowing for software updates to Nintendo Switch docks with a LAN port. &lt;br /&gt;
* 		&lt;br /&gt;
* 			Dock software updates are not available for Nintendo Switch docks without a LAN port. &lt;br /&gt;
* 			This feature was not added to Nintendo Switch Lite. &lt;br /&gt;
* 			For more information, see How to Update the Dock Firmware.&lt;br /&gt;
* 		&lt;br /&gt;
* 	&lt;br /&gt;
* 	&lt;br /&gt;
* 	“Maintain Internet Connection in Sleep Mode” was added under Sleep Mode in System Settings. &lt;br /&gt;
* 		&lt;br /&gt;
* 			When this setting is enabled, systems with wired internet connections will maintain internet connection even while in sleep mode. This allows for software and add-on content to download to the system while the system is in sleep mode. &lt;br /&gt;
* 				&lt;br /&gt;
* 					The setting is enabled by default.&lt;br /&gt;
* 				&lt;br /&gt;
* 			&lt;br /&gt;
* 			When this setting is disabled, the system will connect to the internet only periodically, which decreases power consumption. &lt;br /&gt;
* 		&lt;br /&gt;
* 		Note: Systems that are not updated to version 13.0.0 or later behave as if this setting is enabled.&lt;br /&gt;
* 	&lt;br /&gt;
* 	&lt;br /&gt;
* 	The method to initiate “Calibrate Control Sticks” in System Settings was changed. &lt;br /&gt;
* 		&lt;br /&gt;
* 			From System Settings, go to Controllers and Sensors, select Calibrate Control Sticks, then fully tilt the control stick in any one direction and keep it tilted for a few seconds to begin calibration. &lt;br /&gt;
* 		&lt;br /&gt;
* 	&lt;br /&gt;
* 	&lt;br /&gt;
* 	Users can now view whether their wireless internet connection is using the 2.4 GHz or 5 GHz frequency band under “Connection Status” after selecting Internet in System Settings. &lt;br /&gt;
* 	&lt;br /&gt;
* 	The Bluetooth® word mark and logos are registered trademarks owned by Bluetooth SIG, Inc. and any use of such marks by Nintendo is under license. Other trademarks and trade names are those of their respective owners.&lt;br /&gt;
&lt;br /&gt;
==System Titles==&lt;br /&gt;
* All sysmodules were updated, excluding stubs.&lt;br /&gt;
* All SystemData were updated, except for: BrowserDll, both Dictionary SystemData, AvatarImage, Eula, UrlBlackList, ControllerIcon, ApplicationBlackList, FunctionBlackList.&lt;br /&gt;
* All applets were updated, except for: miiEdit and all web-applets.&lt;br /&gt;
* SystemData PlatformConfigAula and the SystemData for the Aula dock firmware were added.&lt;br /&gt;
&lt;br /&gt;
The following sysmodules had IPC changes: [[USB_services|usb]], [[Settings_services|settings]], [[Bluetooth_Driver_services|bluetooth]], [[BCAT_services|bcat]], [[HID_services|hid]], [[Audio_services|audio]], [[WLAN_services|wlan]], [[PCV_services|pcv]], [[Account_services|account]], [[NS_Services|ns]], [[Applet_Manager_services|am]], [[NIM_services|nim]], [[BTM_services|btm]], [[Error_Report_services|erpt]], [[Display_services|vi]], [[NPNS_services|npns]], [[ETicket_services|es]], [[Filesystem_services|fs]], [[NCM_services|ncm]].&lt;br /&gt;
&lt;br /&gt;
NPDM changes (see [[Services_API]] for the hosted service changes):&lt;br /&gt;
* [[BCAT_services|bcat]]: Access to acc:u1 was replaced with acc:e:u2.&lt;br /&gt;
* [[Friend_services|friends]], [[NIM_services|nim]], [[Parental_Control_services|pctl]], eclct, [[Shared_Database_services|sdb]], [[OLSC_services|olsc]]: Access to acc:u1 was replaced with acc:e:u1.&lt;br /&gt;
* [[PTM_services|ptm]], [[Sockets_services|bsdsocket]], [[HID_services|hid]], [[Audio_services|audio]], [[WLAN_services|wlan]], [[NV_services|nvservices]], [[PCV_services|pcv]], [[PCIe_services|pcie]], [[PSC_services|psc]], [[Safemode|safemode]]: Access to svcMapDeviceAddressSpace was removed.&lt;br /&gt;
* [[HID_services|hid]]: Access to rgltr was added.&lt;br /&gt;
* [[Audio_services|audio]]: Access to btdrv and btm were added.&lt;br /&gt;
* [[NS_Services|ns]]: Access to acc:e, ndrm:la, and ndrm:lu were added.&lt;br /&gt;
* [[Applet_Manager_services|am]]: Access to mnpp:sys was added.&lt;br /&gt;
* [[BTM_services|btm]]: Access to ovln:snd was added.&lt;br /&gt;
* [[JIT_services|jit]]: Access to svcSynchronizePreemptionState was added.&lt;br /&gt;
* [[OLSC_services|olsc]]: Access to sprof:bg and sprof:sp were added.&lt;br /&gt;
* [[Profile_Selector|playerSelect]]: Access to bcat:s was added.&lt;br /&gt;
* [[Album_Applet|photoViewer]]: Access to hwopus was removed.&lt;br /&gt;
&lt;br /&gt;
RomFs changes:&lt;br /&gt;
* ErrorMessage was updated.&lt;br /&gt;
* Help was updated: &amp;quot;/legallines.htdocs/index.html&amp;quot; and the localization html under &amp;quot;/safe.htdocs/html/&amp;quot; was updated.&lt;br /&gt;
* NgWord/NgWord2/NgWordT was updated.&lt;br /&gt;
* LocalNews: message data was updated, and the following directories were added under &amp;quot;/image&amp;quot;: &amp;quot;LnMinIntro_Aula&amp;quot;, &amp;quot;LnSdAdvice_Aula&amp;quot;, &amp;quot;LnSdIntro_Aula&amp;quot;.&lt;br /&gt;
* TimeZoneBinary: timezone data was updated. &amp;quot;/zoneinfo/posixrules&amp;quot; was removed.&lt;br /&gt;
* FontKorean: the font was updated.&lt;br /&gt;
* FirmwareDebugSettings, PlatformConfigIcosa, PlatformConfigHoag, PlatformConfigIcosaMariko: [[System_Settings|updated]].&lt;br /&gt;
* [[HID_services#Firmware_update|ControllerFirmware]]: updated &amp;quot;FirmwareInfo.csv&amp;quot;, &amp;quot;TouchScreenFirmwareInfo.csv&amp;quot;, &amp;quot;ukyosakyo_ep2_ota.bin&amp;quot;. Added &amp;quot;FTS_33000510.fts256&amp;quot; and &amp;quot;FTS_98000004.ftb&amp;quot;.&lt;br /&gt;
* Various applet UI/gfx data was updated.&lt;br /&gt;
&lt;br /&gt;
=== BootImagePackages ===&lt;br /&gt;
RomFs changes: all files updated.&lt;br /&gt;
&lt;br /&gt;
[[Package2|INI1]] changes:&lt;br /&gt;
* BootImagePackageSafe: &lt;br /&gt;
** 010000000000001A (PCV): SVC access: removed MapDeviceAddressSpace.&lt;br /&gt;
** 010000000000000A (Bus): SVC access: removed MapDeviceAddressSpace.&lt;br /&gt;
** 0100000000000021 (psc): SVC access: removed MapDeviceAddressSpace.&lt;br /&gt;
* BootImagePackageExFatSafe: &lt;br /&gt;
** 010000000000001A (PCV): SVC access: removed MapDeviceAddressSpace.&lt;br /&gt;
** 010000000000000A (Bus): SVC access: removed MapDeviceAddressSpace.&lt;br /&gt;
** 0100000000000021 (psc): SVC access: removed MapDeviceAddressSpace.&lt;br /&gt;
&lt;br /&gt;
====Kernel====&lt;br /&gt;
* Compiler upgrade to LLVM 11.1.&lt;br /&gt;
** Most notably, certain code now emits &amp;quot;ands&amp;quot; rather than &amp;quot;and; and; tst&amp;quot; + &amp;quot;bfxil&amp;quot; patterns are more commonly used.&lt;br /&gt;
* C++ language upgrade to C++17.&lt;br /&gt;
** Slab heaps/object containers are now constant initialized, no longer constructed during .init_array.&lt;br /&gt;
* Initialize0 changes:&lt;br /&gt;
** KernelLdr now sends back the initial process binary address in state.&lt;br /&gt;
** Initialize0 now uses a helper function for selecting random virtual regions, and now verifies KInitialPageTable-&amp;gt;IsFree() before selecting regions.&lt;br /&gt;
** Initialize0 now verifies that the initial process binary address is in correct place (pool partition), and sets global=initial address.&lt;br /&gt;
*** This global is now used where GetInitialProcessBinaryAddress() was used previously.&lt;br /&gt;
* KPort limit increased to 0x180 from 0x100.&lt;br /&gt;
* SvcMapDeviceAddressSpace() was removed.&lt;br /&gt;
** Userland only ever used SvcMapDeviceAddressSpaceByForce and SvcMapDeviceAddressSpaceAligned, so this doesn&#039;t break any official software.&lt;br /&gt;
** Map only allowed one page table to be allocated, only partially mapping the desired range if more than one would be used.&lt;br /&gt;
*** Similarly, it returned an output mapped size so a caller could continue mapping partially until the whole range was done, one page table at a time.&lt;br /&gt;
** All parameters required to implement partial mapping have been removed, correspondingly.&lt;br /&gt;
*** No out_mapped_size, out_page_table_count, pt_limit parameters to any KDevicePageTable mapping functions any more.&lt;br /&gt;
*** UnlockForDevicePageTablePartialMap no longer takes in a partially-mapped size.&lt;br /&gt;
**** This code is simplified, since it is no longer possible to have a partially-mapped size other than zero.&lt;br /&gt;
* The two new kernel objects/four new SVCs added in 11.0.0 are finally present/instantiated.&lt;br /&gt;
** Prototypes for the new SVCs:&lt;br /&gt;
*** 0x39: Result CreateIoPool(Handle *out_handle, uint32_t which);&lt;br /&gt;
*** 0x3A: Result CreateIoRegion(Handle *out_handle, Handle io_pool, PhysicalAddress physical_address, size_t size, MemoryMapping mapping, MemoryPermission perm);&lt;br /&gt;
**** MemoryMapping is a new enum, 0 = IO, 1 = Uncached memory, 2 = Normal Memory.&lt;br /&gt;
*** 0x46: Result MapIoRegion(Handle region_handle, uintptr_t address, size_t size, MemoryPermission perm);&lt;br /&gt;
*** 0x47: Result UnmapIoRegion(Handle region_handle, uintptr_t address, size_t size);&lt;br /&gt;
** These SVCs conceptually allow creating an object for mapping in certain physical address ranges at user-specified virtual addresses, without having to include the ranges in npdm/kip capabilities ahead of time.&lt;br /&gt;
*** The only allowed id right now is 0, which corresponds to PCIE_A2 (physical address range 0x12000000-0x1FFFFFFF).&lt;br /&gt;
* KLightLock::Lock now uses simplified logic; KLightLock::LockSlowPath now returns a bool for whether the lock was acquired.&lt;br /&gt;
* KWritableEvent was deleted.&lt;br /&gt;
** Class tokens for types after KWritableEvent have been adjusted downwards to compensate (see mesosphere for class token generation algorithm).&lt;br /&gt;
** Handles which were previously returned to KWritableEvent are now returned directly to KEvent.&lt;br /&gt;
** KEvent has new boolean member to track whether the readable event has been destroyed.&lt;br /&gt;
** KReadableEvent::Initialize now opens reference to the parent event, rather than inline in KEvent::Initialize.&lt;br /&gt;
* KReadableEvent::Signal/Clear are no longer virtual functions.&lt;br /&gt;
* KAutoObject no longer has virtual destructor.&lt;br /&gt;
** This mostly means that base/deleting destructor no longer occur inside vtables.&lt;br /&gt;
* New memory state (0x16/0x2016) &amp;quot;Coverage&amp;quot;, currently not exposed via any SVCs.&lt;br /&gt;
* A number of functions are now devirtualized when possible, indicating either the virtual functions (or the classes) were marked final.&lt;br /&gt;
** KProcess::GetId()&lt;br /&gt;
** KThread::GetId()&lt;br /&gt;
** KSessionRequest::Finalize()&lt;br /&gt;
** KInitialPageAllocator::Free()&lt;br /&gt;
* KConditionVariable::WaitForAddress/KConditionalVariable::SignalToAddress are now static&lt;br /&gt;
* KMemoryManager now operates on physical addresses instead of virtual addresses.&lt;br /&gt;
** KMemoryManager::Initialize now iterates the physical tree rather than the virtual tree, when finding pool regions.&lt;br /&gt;
** KMemoryManager::Allocate now returns a physical address instead of a virtual address.&lt;br /&gt;
** KMemoryManager::Close now takes in a physical address instead of a virtual address.&lt;br /&gt;
** KPageHeap now operates on physical addresses rather than virtual addresses.&lt;br /&gt;
*** New member stores the linear virtual address for the physical range the heap operates on.&lt;br /&gt;
** KBlockInfo now size 0x10 instead of 0x20.&lt;br /&gt;
*** Before: struct { KBlockInfo *prev; KBlockInfo *next; size_t num_pages; KVirtualAddress address; }&lt;br /&gt;
*** Now:    struct { KBlockInfo *next; u32 phys_address_page; u32 num_pages; };&lt;br /&gt;
*** phys_address_page is a KPhysicalAddress / PageSize, to ensure it fits in u32.&lt;br /&gt;
** This halves memory requirements for KBlockInfos system-wide, effectively doubling the KPageGroup capacity.&lt;br /&gt;
** Memory range helper object used by page table functions also now operates on physical addresses.&lt;br /&gt;
* KPageTableBase no longer contains virtual memory region cache.&lt;br /&gt;
** This was only used in KPageTableBase::MapPageGroupImpl to do ABORT_UNLESS(IsHeapVirtualAddress(...));&lt;br /&gt;
** This abort is no longer present, likely because page groups are now physical blocks rather than virtual ones.&lt;br /&gt;
* KPageTable::Unmap now incrementally frees pages, rather than freeing them all at once.&lt;br /&gt;
* KHandleTableEntryInfo no longer stores object class token, KHandleTable::Add/Register no longer takes class token as argument.&lt;br /&gt;
** This reduces KHandleTable size (and thus KProcess size) by 0x800.&lt;br /&gt;
* The following types no longer have (unused) slab heaps:&lt;br /&gt;
** KClientSession, KLightClientSession, KLightServerSession&lt;br /&gt;
* A complete re-work/unification was done for the various kinds of thread waiting operations in the kernel.&lt;br /&gt;
** Previously, there were a number of different ways to initiate and end waits, handled manually in each location by invoking thread-&amp;gt;SetState(...);&lt;br /&gt;
** Now, all waits use a common interface based around thread queue objects with virtual functions for the three kinds of supported waits.&lt;br /&gt;
** Supported queue virtual functions:&lt;br /&gt;
*** void NotifyAvailable(KThread *waiting_thread, KSynchronizationObject *signaled_object, Result wait_result);&lt;br /&gt;
**** This is supported only by the queue used by WaitSynchronization, and sets the signaled object/sync&#039;d index for the thread.&lt;br /&gt;
*** void EndWait(KThread *waiting_thread, Result wait_result);&lt;br /&gt;
**** This conceptually ends a wait &amp;quot;normally&amp;quot;, usually without additional cleanup. This is exclusively called by kernel-handled wait codepaths.&lt;br /&gt;
*** void CancelWait(KThread *waiting_thread, Result wait_result, bool cancel_timer_task);&lt;br /&gt;
**** This conceptually ends a wait &amp;quot;by force&amp;quot;, interrupting it regardless of normal wait completion.&lt;br /&gt;
***** This usually involves extra cleanup.&lt;br /&gt;
**** This is invoked by e.g. CancelSynchronization, thread termination, thread finalize, etc.&lt;br /&gt;
** KThread::SetState is likely private now; it is called only by internal KThread functions.&lt;br /&gt;
** KLightSession was notably reworked substantially to take advantage of the new unified wait semantics.&lt;br /&gt;
** KSynchronizationObject::DumpWaiters() no longer exists.&lt;br /&gt;
* KDebug is now substantially more careful about management of its process pointer.&lt;br /&gt;
** New field &amp;quot;is_attached&amp;quot; explicitly tracks whether the KDebug is attached (instead of m_process != nullptr).&lt;br /&gt;
** m_process replaced by a new helper object containing KProcess * and reference count.&lt;br /&gt;
*** Code which previously used the process field now opens/closes references on m_process_holder.&lt;br /&gt;
*** When m_process_holder&#039;s reference count hits zero, the process is closed and m_pointer is set to 1 instead of nullptr.&lt;br /&gt;
** This makes the way KDebug treats the attached process&#039;s reference count much more correct/consistent.&lt;br /&gt;
*** In particular, &amp;quot;the KDebug is attached&amp;quot; now counts as one reference to the KProcess, no matter what the KDebug is doing with it.&lt;br /&gt;
* Resource management has changed substantially.&lt;br /&gt;
** Dynamic slabheaps no longer contain a pointer to an associated page allocator; instead, a page allocator is now passed as an argument to .Allocate().&lt;br /&gt;
** There are new helper objects which contain a dynamic slab heap pointer and a page allocator pointer, used for conveniently referencing a slab/page resource pair.&lt;br /&gt;
*** There are now helper objects differentiating between KBlockInfo and KPageTableManager allocators for system/application context.&lt;br /&gt;
*** KPageTable now has a helper function to allocate a page from the KPageTableManager helper object.&lt;br /&gt;
** Instead of allocating all unused pages to the page table page heap, all but 70 pages are allocated to the page table page heap.&lt;br /&gt;
** When a new flag from the secure monitor is zero (this is always the case on retail), new logic for &amp;quot;dynamic resource expansion&amp;quot; is enabled.&lt;br /&gt;
*** In particular, this causes the helper objects for the system memory blocks, block infos, and page table managers to be set to the dynamic page allocator.&lt;br /&gt;
**** Thus, the last 70 unused pages are dynamically allocated to (system memory blocks, system block infos, system page table pages) on a first-come basis as the system uses these resources.&lt;br /&gt;
**** NOTE: There is no &amp;quot;free&amp;quot;-ing of these resources back to the unused page heap, once they&#039;ve been allocated to a specific slab they will remain in that slab until reboot.&lt;br /&gt;
*** In addition, when allocating a KSession, KEvent, or KLightSession from the system resource limit fails, an object of the desired type will be allocated from the otherwise unused &amp;quot;gaps&amp;quot; in the slab region.&lt;br /&gt;
**** When allocating a KSession dynamically from gap-space, kernel also allocates two KSessionRequests from gap-space and frees them to the KSessionRequest slabheap.&lt;br /&gt;
**** Allocator for this uses an intrusive red black tree on in-place nodes in the gaps.&lt;br /&gt;
* Minor changes to the atomic operations for slab heaps.&lt;br /&gt;
*** Slab heap initialization now panics if L1 cache is direct-mapped (1-way associative).&lt;br /&gt;
*** Slab heap allocation no longer issues a clrex on failure.&lt;br /&gt;
*** For types supporting the new dynamic allocation, Slab heap free now checks that the object lives within the slab region instead of panicking when object is not within slab extents.&lt;br /&gt;
* The interrupt task manager thread no longer exists, functionality has been rolled into KScheduler.&lt;br /&gt;
** KScheduler now has member pointer to the interrupt task manager for the current core.&lt;br /&gt;
** KScheduler::EnableScheduling now sends scheduler interrupt unconditionally, regardless of disable count.&lt;br /&gt;
** KScheduler::RescheduleCurrentCore now uses double-checked-locking-esque strategy for checking scheduling necessity around interrupt disables.&lt;br /&gt;
** KScheduler::Schedule now processes interrupt tasks directly (calls a KInterruptTaskManager member function) rather than setting the interrupt task thread to runnable.&lt;br /&gt;
* KInterruptEventTask no longer contains a KLightLock member.&lt;br /&gt;
** KSchedulerLock is used in places where interrupt events were locked previously.&lt;br /&gt;
* KSchedulerInterruptTask is now a KInterruptHandler, rather than a KInterruptTask (no ::DoTask() implementation, any more).&lt;br /&gt;
* KProcess::AddSharedMemory now sets all fields in one block/scope, rather than two.&lt;br /&gt;
* KWorkerTaskManager::Initialize now hardcodes id=0 instead of taking it as a parameter.&lt;br /&gt;
** KWorkerTaskManager no longer has &amp;quot;id&amp;quot;/&amp;quot;active&amp;quot; fields.&lt;br /&gt;
* Certain unnecessary conditionals were optimized in KServerSession::SendReply/ReceiveMessage.&lt;br /&gt;
** Code of the form `x = condition ? a : b` with condition&#039;s value fixed for the block was optimized to `x = a`.&lt;br /&gt;
** This may just be a relic of compiler upgrade mentioned above.&lt;br /&gt;
* Minor changes to GetInfo:&lt;br /&gt;
** Logic which previously disabled interrupt for profiling InfoTypes now instead disables dispatch (KScopedDisableDispatch instead of KScopedDisableInterrupt).&lt;br /&gt;
** InfoType_ThreadTickCount has had its value changed from 0xF0000002 to 0x19. This is presumably to generate better asm for the switch statement.&lt;br /&gt;
* SendAsyncRequestWithUserBuffer now accepts ResultThreadTerminating as a success result (it does not unlock memory when it is returned).&lt;br /&gt;
* KClientSession::SendSyncRequest/SendAsyncRequest no longer hold the scheduler lock while calling KServerSession::OnRequest.&lt;br /&gt;
** Lock is now acquired as needed by KServerSession::OnRequest itself.&lt;br /&gt;
* KClientSession, KLightClientSession, KLightServerSession no longer inherit from KSlabAllocated/KAutoObjectWithList, and are now correspondingly smaller.&lt;br /&gt;
* KResourceLimit::Allocate() now calls KAutoObject::Create().&lt;br /&gt;
* KPrintf has been replaced with a function which takes a non-format string, and prints the string, then &amp;lt;current program ID formatted as %016lx&amp;gt;, then a newline.&lt;br /&gt;
** &amp;quot;Break() called. %016lx\n&amp;quot; and &amp;quot;Exception occurred. %016lx\n&amp;quot; are now &amp;quot;Break() called. &amp;quot; and &amp;quot;Exception occurred. &amp;quot;, respectively.&lt;br /&gt;
* StoreDataCacheSharedForInit has slightly different (but equivalent) iteration logic.&lt;br /&gt;
&lt;br /&gt;
===[[Bluetooth_Driver_services|bluetooth]]===&lt;br /&gt;
* New btdrv commands were added.&lt;br /&gt;
* A number of funcs now [[Switch_System_Flaws|clear]] stack buffers before sending it elsewhere.&lt;br /&gt;
* A new system-setting is now used during [[Bluetooth_Driver_services#EnableBluetooth|audio-enabling]].&lt;br /&gt;
* ...&lt;br /&gt;
&lt;br /&gt;
==See Also==&lt;br /&gt;
System update report(s):&lt;br /&gt;
* [https://yls8.mtheall.com/ninupdates/reports.php?date=2021-09-15_00-05-06&amp;amp;sys=hac]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{NavboxVersions}}&lt;br /&gt;
&lt;br /&gt;
[[Category:System versions]]&lt;/div&gt;</summary>
		<author><name>Yellows8</name></author>
	</entry>
	<entry>
		<id>https://switchbrew.org/w/index.php?title=13.1.0&amp;diff=14883</id>
		<title>13.1.0</title>
		<link rel="alternate" type="text/html" href="https://switchbrew.org/w/index.php?title=13.1.0&amp;diff=14883"/>
		<updated>2026-08-06T00:43:29Z</updated>

		<summary type="html">&lt;p&gt;Yellows8: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The Switch 13.1.0 system update was released on October 26, 2021 (UTC). This Switch update was released for the following regions: ALL, and CHN.&lt;br /&gt;
&lt;br /&gt;
Security flaws fixed: &amp;lt;fill this in manually later, see the updatedetails page from the ninupdates-report page(s) once available for now&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
==Change-log==&lt;br /&gt;
[https://en-americas-support.nintendo.com/app/answers/detail/a_id/22525/kw/nintendo%20switch%20system%20update Official] ALL change-log:&lt;br /&gt;
* 	Added support for Nintendo Switch Online + Expansion Pack.&lt;br /&gt;
* 	General system stability improvements to enhance the user&#039;s experience.&lt;br /&gt;
&lt;br /&gt;
==System Titles==&lt;br /&gt;
* The following sysmodules were updated: bluetooth, bcat, nifm, bsdsocket, hid, ldn, nvservices, account, ns, am, nim, btm, erpt, es, olsc.&lt;br /&gt;
* The following SystemData were updated: ErrorMessage, BrowserDll, Help, LocalNews, FirmwareDebugSettings, BootImagePackages, ControllerIcon, ControllerFirmware, SystemVersion/RebootlessSystemUpdateVersion.&lt;br /&gt;
* The following applets were updated: qlaunch, [[Profile_Selector|playerSelect]], [[Internet_Browser|web-applets]], overlayDisp, [[Album_Applet|photoViewer]], [[MyPage_Applet|myPage]].&lt;br /&gt;
&lt;br /&gt;
The following sysmodules had IPC changes: bcat, ldn, account, ns, nim, btm, es, olsc.&lt;br /&gt;
&lt;br /&gt;
NPDM changes:&lt;br /&gt;
* bcat: Access to ovln:snd and sprof:sp were added.&lt;br /&gt;
* olsc: Access to mnpp:sys was added, see [[Services_API]] for the service-host change.&lt;br /&gt;
* qlaunch: Access to mnpp:sys and spbg:sp were added.&lt;br /&gt;
* [[Internet_Browser|LibAppletLns]]: Access to caps:ss and mnpp:web were added.&lt;br /&gt;
&lt;br /&gt;
RomFs changes:&lt;br /&gt;
* ErrorMessage: updated&lt;br /&gt;
* BrowserDll: Updated &amp;quot;/browser/MediaControlsInline.js&amp;quot;, &amp;quot;/buildinfo/buildinfo.dat&amp;quot;, localization data under &amp;quot;/message/&amp;quot;. Updated the NROs under &amp;quot;/nro/netfront/core_0/&amp;quot; and /nro/netfront/core_1/&amp;quot;.&lt;br /&gt;
* Help: Updated &amp;quot;/legallines.htdocs/index.html&amp;quot; and &amp;quot;/safe.htdocs/html/CNzh/index.html&amp;quot;.&lt;br /&gt;
* LocalNews: Updated &amp;quot;/message/CNzh/localNews.msbt.szs&amp;quot; and &amp;quot;/message/revision.txt&amp;quot;.&lt;br /&gt;
* FirmwareDebugSettings: [[System_Settings|updated]]&lt;br /&gt;
* ControllerIcon: Updated &amp;quot;/lyt/footer/800/controllerIcon.bntx&amp;quot; and &amp;quot;/lyt/footer/800/info.dat&amp;quot;.&lt;br /&gt;
* ControllerFirmware: Updated &amp;quot;/TouchScreenFirmwareInfo.csv&amp;quot;. Added &amp;quot;/FTS_50000001.ftb&amp;quot; and removed &amp;quot;/FTS_98000004.ftb&amp;quot;.&lt;br /&gt;
* Applets: Updated various UI data (and for web-applets, updated &amp;quot;/buildinfo/buildinfo.dat&amp;quot; and &amp;quot;/.nrr/modules.nrr&amp;quot;).&lt;br /&gt;
&lt;br /&gt;
=== BootImagePackages ===&lt;br /&gt;
RomFs changes:&lt;br /&gt;
* &amp;quot;/nx/package2&amp;quot; updated&lt;br /&gt;
&lt;br /&gt;
====Kernel====&lt;br /&gt;
* SDK version bump from 13.3.0.0 to 13.4.0.0.&lt;br /&gt;
* KSchedulerLock::Unlock now performs a data memory barrier (inner shareable) before performing scheduling.&lt;br /&gt;
* KScheduler::Scheduler now performs a data memory barrier before returning, when the next thread is the current thread.&lt;br /&gt;
** These changes probably go together, to prevent asynchronous reordering of these operations across cores.&lt;br /&gt;
&lt;br /&gt;
===[[Bluetooth_Driver_services|bluetooth]]===&lt;br /&gt;
Error handling (or minor other changes) in various bt-audio funcs were updated.&lt;br /&gt;
&lt;br /&gt;
The func for the &amp;quot;nn.bluetooth.HidMessageHandler&amp;quot; thread was updated.&lt;br /&gt;
&lt;br /&gt;
==See Also==&lt;br /&gt;
System update report(s):&lt;br /&gt;
* [https://yls8.mtheall.com/ninupdates/reports.php?date=2021-10-26_00-15-05&amp;amp;sys=hac]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{NavboxVersions}}&lt;br /&gt;
&lt;br /&gt;
[[Category:System versions]]&lt;/div&gt;</summary>
		<author><name>Yellows8</name></author>
	</entry>
	<entry>
		<id>https://switchbrew.org/w/index.php?title=13.2.1&amp;diff=14882</id>
		<title>13.2.1</title>
		<link rel="alternate" type="text/html" href="https://switchbrew.org/w/index.php?title=13.2.1&amp;diff=14882"/>
		<updated>2026-08-06T00:42:07Z</updated>

		<summary type="html">&lt;p&gt;Yellows8: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The Switch 13.2.1 system update was released on January 20, 2022 (UTC). This Switch update was released for the following regions: ALL, and CHN.&lt;br /&gt;
&lt;br /&gt;
Security flaws fixed: yes.&lt;br /&gt;
&lt;br /&gt;
==Change-log==&lt;br /&gt;
[https://en-americas-support.nintendo.com/app/answers/detail/a_id/22525/kw/nintendo%20switch%20system%20update Official] ALL change-log:&lt;br /&gt;
* 	General system stability improvements to enhance the user&#039;s experience.&lt;br /&gt;
&lt;br /&gt;
==System Titles==&lt;br /&gt;
The following was updated: [[System_Version_Title|SystemVersion]], BootImagePackages, [[Bluetooth_Driver_services|bluetooth]], [[SSL_services|ssl]].&lt;br /&gt;
&lt;br /&gt;
There were no sysmodule IPC changes, and the only NPDM changes were the usual version bump. The only RomFs changes were the usual SystemVersion changes, and see below for BootImagePackage.&lt;br /&gt;
&lt;br /&gt;
=== BootImagePackages ===&lt;br /&gt;
RomFs changes: all files updated.&lt;br /&gt;
&lt;br /&gt;
The anti-downgrade fuses were [[Fuses#Anti-downgrade|updated]].&lt;br /&gt;
&lt;br /&gt;
=== [[Bluetooth_Driver_services|bluetooth]] ===&lt;br /&gt;
Only 1 func was changed, which fixed a [[Switch_System_Flaws|vuln]].&lt;br /&gt;
&lt;br /&gt;
=== [[SSL_services|ssl]] ===&lt;br /&gt;
The only changes were in NSS, which fixed a [[Switch_System_Flaws|vuln]].&lt;br /&gt;
&lt;br /&gt;
==See Also==&lt;br /&gt;
System update report(s):&lt;br /&gt;
* [https://yls8.mtheall.com/ninupdates/reports.php?date=2022-01-20_00-05-05&amp;amp;sys=hac]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{NavboxVersions}}&lt;br /&gt;
&lt;br /&gt;
[[Category:System versions]]&lt;/div&gt;</summary>
		<author><name>Yellows8</name></author>
	</entry>
	<entry>
		<id>https://switchbrew.org/w/index.php?title=14.0.0&amp;diff=14881</id>
		<title>14.0.0</title>
		<link rel="alternate" type="text/html" href="https://switchbrew.org/w/index.php?title=14.0.0&amp;diff=14881"/>
		<updated>2026-08-06T00:41:11Z</updated>

		<summary type="html">&lt;p&gt;Yellows8: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The Switch 14.0.0 system update was released on March 22, 2022 (UTC). This Switch update was released for the following regions: ALL.&lt;br /&gt;
&lt;br /&gt;
Security flaws fixed: &amp;lt;fill this in manually later, see the updatedetails page from the ninupdates-report page(s) once available for now&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
==Change-log==&lt;br /&gt;
[https://en-americas-support.nintendo.com/app/answers/detail/a_id/22525/kw/nintendo%20switch%20system%20update Official] ALL change-log:&lt;br /&gt;
* &amp;quot;Groups&amp;quot; feature was added to the All Software menu.&lt;br /&gt;
*   &lt;br /&gt;
* 	You can now create groups of software to help organize your software titles.&lt;br /&gt;
*     Making groups for different game genres, developers, or whatever you’d like to organize by may make it easier to find the application you want.&lt;br /&gt;
*     	&lt;br /&gt;
*           Up to 100 groups can be created with a max of 200 titles per group.&lt;br /&gt;
*       &lt;br /&gt;
*     &lt;br /&gt;
*     The button to proceed to the &amp;quot;All Software&amp;quot; screen is displayed only when there are 13 or more software title icons on the system.&lt;br /&gt;
*     For more information, see How to Create Groups of Software. &lt;br /&gt;
*   &lt;br /&gt;
* Bluetooth® Audio volume behavior was changed.&lt;br /&gt;
* 	&lt;br /&gt;
*   		You can now adjust the volume of Bluetooth audio devices using either the Nintendo Switch™ console or through volume control buttons on the Bluetooth audio device. &lt;br /&gt;
*       		&lt;br /&gt;
*               The Bluetooth audio device must support AVRCP profiles for these changes to work.&lt;br /&gt;
*           &lt;br /&gt;
*       	&lt;br /&gt;
*       The volume displayed on the console will reflect the Bluetooth audio volume when using the device’s control buttons.&lt;br /&gt;
*       The maximum volume output for some Bluetooth audio devices has been increased.&lt;br /&gt;
*       	&lt;br /&gt;
*           When first connecting a device, volume will be reduced to avoid sudden loudness.&lt;br /&gt;
*           For more information, see How to Pair and Manage Bluetooth Audio Devices. &lt;br /&gt;
*         &lt;br /&gt;
*       &lt;br /&gt;
* 	  &lt;br /&gt;
*   &lt;br /&gt;
&lt;br /&gt;
==System Titles==&lt;br /&gt;
* New sysmodule omm was added, various hosted services from am were moved here.&lt;br /&gt;
* Most system titles were updated, except for the following (besides stubs): both Dictionary SystemData, AvatarImage, Eula, UrlBlackList, ControllerIcon, ApplicationBlackList, FunctionBlackList.&lt;br /&gt;
&lt;br /&gt;
[[NPDM]] changes:&lt;br /&gt;
* ptm had the order of various accessible-services changed.&lt;br /&gt;
* pcv: access to IO page 0x07009f000 was removed. The order of various hosted/accessible-services changed. Access to fsp-srv, pwm, and set:cal were removed.&lt;br /&gt;
* ns now has access to pm:info.&lt;br /&gt;
* am: access to svcSleepSystem was removed. FS permission bitmask 0x0000000080000000 was removed. Hosted services idle:sys, omm, and spsm were removed. Access to the following services were removed: bgtc:sc, bgtc:t, bpc, cec-mgr, gpio, hshl:set, hshl:sys, led, psc:c, psc:m, psm, tc, time:p, usb:hs, usb:pd, usb:pd:c, vi:m/vi:s, xcd:sys. Access to the following services were added: idle:sys, ommdisp, spsm.&lt;br /&gt;
* qlaunch had access to nd:sys removed.&lt;br /&gt;
* cabinet had a duplicate service-access entry for set:sys removed.&lt;br /&gt;
* playerSelect had a duplicate service-access entry for acc:su removed.&lt;br /&gt;
* starter now has access to audctl.&lt;br /&gt;
&lt;br /&gt;
RomFs changes:&lt;br /&gt;
* ErrorMessage: various errors added / localization updated.&lt;br /&gt;
* BrowserDll:&lt;br /&gt;
** &amp;quot;/browser/ErrorPageFilteringTemplate.html&amp;quot; updated&lt;br /&gt;
** &amp;quot;/browser/ErrorPageSubFrameTemplate.html&amp;quot; updated&lt;br /&gt;
** &amp;quot;/browser/ErrorPageTemplate.html&amp;quot; updated&lt;br /&gt;
** &amp;quot;/browser/MediaControlsInline.css&amp;quot; updated&lt;br /&gt;
** &amp;quot;/browser/MediaControlsInline.js&amp;quot; updated&lt;br /&gt;
** &amp;quot;/browser/RootCaEtc.pem&amp;quot; and &amp;quot;/browser/RootCaSdkAdditional.pem&amp;quot; updated&lt;br /&gt;
** &amp;quot;/buildinfo/buildinfo.dat&amp;quot; updated&lt;br /&gt;
** &amp;quot;/lyt/Dialog/DAuthentication.arc&amp;quot; updated&lt;br /&gt;
** Various localization data under &amp;quot;/message/&amp;quot; was updated.&lt;br /&gt;
** The NROs under &amp;quot;/nro/netfront/core_0/&amp;quot; were moved to &amp;quot;/nro/netfront/core_0/default/cfi_disabled&amp;quot;.&lt;br /&gt;
** The NROs under &amp;quot;/nro/netfront/core_1/&amp;quot; were moved to &amp;quot;/nro/netfront/core_2/default/cfi_enabled&amp;quot; (the core_1 directory was removed).&lt;br /&gt;
** &amp;quot;/sound/&amp;quot; was added, which contains &amp;quot;cruiser.bfsar&amp;quot;.&lt;br /&gt;
* Help: &amp;quot;/legallines.htdocs/index.html&amp;quot; updated&lt;br /&gt;
* LocalNews: &amp;quot;/message/revision.txt&amp;quot; updated&lt;br /&gt;
* FirmwareDebugSettings/PlatformConfigIcosa/PlatformConfigCopper/PlatformConfigHoag/PlatformConfigIcosaMariko/PlatformConfigAula: [[System_Settings|updated]]&lt;br /&gt;
* ControllerFirmware:&lt;br /&gt;
** &amp;quot;/FirmwareInfo.csv&amp;quot; and &amp;quot;/TouchScreenFirmwareInfo.csv&amp;quot; updated&lt;br /&gt;
** &amp;quot;/FTS_50000001.ftb&amp;quot; removed&lt;br /&gt;
** &amp;quot;/FTS_50000002.ftb&amp;quot; added&lt;br /&gt;
** &amp;quot;/ukyosakyo_ep2_ota.bin&amp;quot; updated&lt;br /&gt;
* NgWordT: &amp;quot;/mars_dirty_words_db&amp;quot; updated&lt;br /&gt;
* Various graphics/UI/localization data was updated in various applets.&lt;br /&gt;
* web-applets: &amp;quot;/sound/&amp;quot; was removed, it&#039;s now located in BrowserDll. &amp;quot;/buildinfo/buildinfo.dat&amp;quot; and &amp;quot;/.nrr/modules.nrr&amp;quot; were updated.&lt;br /&gt;
&lt;br /&gt;
=== BootImagePackages ===&lt;br /&gt;
RomFs changes: all files updated.&lt;br /&gt;
&lt;br /&gt;
Using updated master-key: master_key_0d (previously master_key_0c). See [[NCA]] for the KeyGeneration listing.&lt;br /&gt;
&lt;br /&gt;
[[Package2|INI1]] changes:&lt;br /&gt;
* BootImagePackage: &lt;br /&gt;
** 0100000000000003 (ProcessMana): SVC access: added GetResourceLimitPeakValue.&lt;br /&gt;
* BootImagePackageSafe: &lt;br /&gt;
** 0100000000000003 (ProcessMana): SVC access: added GetResourceLimitPeakValue.&lt;br /&gt;
* BootImagePackageExFat: &lt;br /&gt;
** 0100000000000003 (ProcessMana): SVC access: added GetResourceLimitPeakValue.&lt;br /&gt;
* BootImagePackageExFatSafe: &lt;br /&gt;
** 0100000000000003 (ProcessMana): SVC access: added GetResourceLimitPeakValue.&lt;br /&gt;
&lt;br /&gt;
====Secure Monitor====&lt;br /&gt;
* Compiler upgrade to latest llvm (now using same compiler revision as kernel).&lt;br /&gt;
** Secure Monitor is now compiled with -fomit-frame-pointer.&lt;br /&gt;
*** &amp;gt;:(&lt;br /&gt;
* GenerateSeTestVectorImpl now uses a helper to mix each key into the vector.&lt;br /&gt;
* ExceptionHandler is now linked in (@ .text + 0x3E04).&lt;br /&gt;
** Previously, this was garbage collected/only present in debug secure monitors.&lt;br /&gt;
** NOTE: This is unreachable, and stripped (as e.g. logging isn&#039;t emitted, likely because the macros are empty on release builds).&lt;br /&gt;
&lt;br /&gt;
====Kernel====&lt;br /&gt;
* Kernel is now compiled with -O3 again instead of -Os&lt;br /&gt;
** &amp;gt;:(&lt;br /&gt;
* crt0 no longer supports booting in EL2.&lt;br /&gt;
** Infinite Loop/Panic is performed instead.&lt;br /&gt;
* Initialize0 changes:&lt;br /&gt;
** KernelStack setup now uses same helper to determine aslr as other random aligned regions.&lt;br /&gt;
** KernelTemp setup now uses same helper to determine aslr as other random aligned regions.&lt;br /&gt;
* Slab changes:&lt;br /&gt;
** When assigned extra resource, the slab heap is now 0x148000 larger instead of 0x68000 larger.&lt;br /&gt;
** Correspondingly, instead of increasing the thread resource limit by 160, the thread resource limit is now increased by 736.&lt;br /&gt;
*** This corresponds to changes in userland for pm management of resource limits.&lt;br /&gt;
*** Old Intended Resource Limits:&lt;br /&gt;
**** System (96 + 512) -&amp;gt; (256 + 512)&lt;br /&gt;
**** Applet 96 -&amp;gt; 96&lt;br /&gt;
**** Application 96 -&amp;gt; 96&lt;br /&gt;
*** New Intended Resource Limits:&lt;br /&gt;
**** System (96 + 512) -&amp;gt; 1024&lt;br /&gt;
**** Applet 96 -&amp;gt; 256&lt;br /&gt;
**** Application 96 -&amp;gt; 256&lt;br /&gt;
* SetupPoolPartitionMemoryRegions now panics if the end of the pool partition region is not coincidence with the end of dram.&lt;br /&gt;
* KThreadContext was completely revised.&lt;br /&gt;
** Most of KThreadContext is now stored inline in kernel stack.&lt;br /&gt;
*** Kernel stack layout is now u8 stack[0xDB0]; KThreadContext thread_context; KThreadStackParameters stack_parameters;&lt;br /&gt;
** KThreadContext now only stores the 8 callee-save FPU registers.&lt;br /&gt;
*** The remaining 24 caller-save FPU registers are stored inside KThread, where KThreadContext used to be.&lt;br /&gt;
*** NOTE that 32-bit fpu has 4 callee-save FPU registers and 12 caller-save registers, which use the start of the relevant 64-bit storages as usual.&lt;br /&gt;
** KThreadStackParameters was revised to facilitate this.&lt;br /&gt;
*** The pointer to KThreadContext previously stored in stack parameters now points to the external FPU register array.&lt;br /&gt;
*** The members at end of params are now: u16 disable_count; u8 current_svc_id; u8 unused_2c; u8 exception_flags; u8 is_pinned; u8 unused_2f;&lt;br /&gt;
**** The &amp;quot;exception_flags&amp;quot; field is a new set of bitflags (encoding old state was were previously separate bools + new state).&lt;br /&gt;
***** Bit 0x1  = is_calling_svc&lt;br /&gt;
***** Bit 0x2  = is_in_exception_handler&lt;br /&gt;
***** Bit 0x4  = is_fpu_state_restore_needed&lt;br /&gt;
***** Bit 0x8  = is_64_bit_fpu&lt;br /&gt;
***** Bit 0x10 = has_exception_svc_permissions&lt;br /&gt;
***** Bit 0x20 = is_in_cache_operation&lt;br /&gt;
***** Bit 0x40 = is_in_tlb_operation&lt;br /&gt;
** Exception exits now check is_fpu_state_restore_needed, and restore FPU registers only if needed (and clear is_fpu_state_restore_needed on restore).&lt;br /&gt;
*** is_fpu_state_restore_needed is set to true *only* on thread switch with FPU enabled.&lt;br /&gt;
**** Caller-save FPU registers are saved *only* if a thread is in an SVC and does not have exception svc permissions.&lt;br /&gt;
**** All other thread switches save only the 8 (or 4) callee-save FPU registers.&lt;br /&gt;
**** All thread switches now guarantee as post-condition that the fpu is disabled leaving the switch (it will be re-enabled on exception exit if needed).&lt;br /&gt;
*** On SVC exception return, all caller-save FPU registers are set to zero unless the thread has exception svc permissions.&lt;br /&gt;
** KThread::CloneFpuStatus now uses KScopedDisableInterrupt&lt;br /&gt;
* Various hw maintenance changes:&lt;br /&gt;
** KernelLdr no longer does cache maintenance by set/way when setting up initial identity mapping, no longer invalidates instruction cache/tlb, no longer does dsb after setting sctlr_el1.&lt;br /&gt;
** FlushEntireDataCacheLocal/Shared in init now perform dsb sy, FlushEntireDataCacheAndInvalidateTlbForInit no longer does after calling them.&lt;br /&gt;
** dsb sy/isb is now performed after setting sctlr_el1, when disabling mmu/icache.&lt;br /&gt;
** KInitialPageTable::Map no longer does dsb ish after all attribute writes.&lt;br /&gt;
*** Instead does it before writing table entries, and at the end of the function.&lt;br /&gt;
** KInitialPageTable::PhysicallyRandomize no longer does StoreEntireCacheForInit.&lt;br /&gt;
*** Now does dc cvac on randomized virtual address range, dsb ish, ic iallu, dsb ish, isb. (see weaker-barriers section of diff)&lt;br /&gt;
** KInitialPageTable::SwapBlocks now does dsb ish after memcpy to swap blocks.&lt;br /&gt;
** KInitialPageTable::Reprotect no longer does dsb ish before performing reprotection.&lt;br /&gt;
** KInitialProcessReader::Load no longer calls cpu::FlushEntireDataCache/cpu::InvalidateInstructionCache.&lt;br /&gt;
** Set/way cache operations now perform dsb sy before configuring csselr.&lt;br /&gt;
*** This affects InvalidateDataCacheForResumeEntry, FlushEntireDataCache, KCacheHelperInterruptHandler, and the initial cache maintenance when disabling the mmu.&lt;br /&gt;
** FlushEntireDataCache now does dsb sy after doing full set/way cache flush, instead of after each set/way op.&lt;br /&gt;
*** NOTE: This is still only a local flush without coherence guarantees, set/way aren&#039;t supposed to be used after multiple cores are online.&lt;br /&gt;
** KSystemControl::CpuSleepHandler no longer embeds unreachable cache maintenance assembly after CpuSuspend.&lt;br /&gt;
** Kernel now performs different hw maintenance if a thread is in a hw maintenance operation when interrupted:&lt;br /&gt;
*** If a thread is interrupted while performing cache maintenance in EL1 (tracked via new exception flags bit 0x20), KInterruptManager::OnHandleInterrupt performs dsb sy.&lt;br /&gt;
**** Set and cleared for scope of cpu::InvalidateDataCache instead of disabling core migration.&lt;br /&gt;
**** Set and cleared for scope of cpu::StoreDataCache instead of disabling core migration.&lt;br /&gt;
**** Set and cleared for scope of cpu::FlushDataCache instead of disabling core migration.&lt;br /&gt;
*** If a thread is interrupted while performing tlb maintenance in EL1 (tracked via new exception flags bit 0x40), KInterruptManager::OnHandleInterrupt performs dsb ish.&lt;br /&gt;
**** Set and cleared for scope of KPageTable::NoteUpdated&lt;br /&gt;
*** If a thread is interrupted while performing cache maintenance in EL0 (tracked via new bool @ TLS + 0x104), KInterruptManager::OnHandleInterrupt performs dsb sy.&lt;br /&gt;
**** This is equivalent to the EL1 cache maintenance tracking above, providing an opt-in way for userland to ensure its cache maintenance is coherent even when interrupted.&lt;br /&gt;
**** Note that official userland code now sets this bit before performing cache maintenance.&lt;br /&gt;
** Memory barriers were revised in many places -- barriers were weakened in many places, and some functions which previously lacked barriers had them added, including:&lt;br /&gt;
*** cpu::InvalidateEntireInstructionCache: dsb sy -&amp;gt; dsb ish&lt;br /&gt;
*** cpu::EnsureInstructionConsistency: dsb sy; isb; -&amp;gt; dsb ish; isb;&lt;br /&gt;
**** NOTE: Functions written in assembly still use the old pattern for ensuring instruction consistency.&lt;br /&gt;
*** KCacheInterruptHandler::RequestOperation: dsb sy -&amp;gt; dsb ish&lt;br /&gt;
*** KScheduler::EnableScheduling: dsb sy -&amp;gt; dsb ish&lt;br /&gt;
*** KScheduler::SwitchThread no longer does dsb sy before setting ttbr0/contextidr_el1.&lt;br /&gt;
*** KPageTable::NoteUpdated: dsb sy; if (m_kernel) { ... dsb sy; } else { ... dsb sy; isb; } -- dsb ishst; if (m_kernel) { ... dsb ish; } else { ... dsb ish; isb; }&lt;br /&gt;
**** KPageTable::NoteSingleKernelPageUpdated now similarly does dsb ishst for outer and dsb ish for inner barriers.&lt;br /&gt;
*** KPageTable::ClearPageTable: now does dsb ish after clearing page to zero via dc zva&lt;br /&gt;
*** KPageTable::MapContiguous: now does dsb ishst after merging pages.&lt;br /&gt;
*** KPageTable::MapPageGroup: now does dsb ishst after merging pages.&lt;br /&gt;
*** KPageTable::PteDataSynchronizationBarrier: now dmb ishst instead of dsb ish (probably KPageTable::PteDataMemoryBarrier, now?)&lt;br /&gt;
*** KPageTable::MapL2Blocks/MapL3Blocks: pattern for setting entry for new table went from Barrier(); WriteEntry(); Barrier(); -&amp;gt; Barrier(); WriteEntry();&lt;br /&gt;
**** This was PteDataSynchronizationBarrier(), and correspondingly asm is dsb ish; str; dsb ish; -&amp;gt; dmb ishst; str;&lt;br /&gt;
*** KSupervisorPageTable::SetTtbr0 no longer does dsb sy before setting ttbr0/contextidr_el1.&lt;br /&gt;
** UserspaceAccess::InvalidateInstructionCache was removed (previously unused).&lt;br /&gt;
* Various changes to KInterruptName/interrupt management:&lt;br /&gt;
** Enum values for IPIs were revised:&lt;br /&gt;
*** KInterruptName_ThreadTerminate    4 -&amp;gt; 0&lt;br /&gt;
*** KInterruptName_CacheOperation     5 -&amp;gt; 1&lt;br /&gt;
*** KInterruptName_Scheduler          6 -&amp;gt; 2&lt;br /&gt;
** New KInterruptName (KInterruptName_CoreBarrier) = 3&lt;br /&gt;
*** Interrupt handler for this is registered with KInterruptControllerPriority_Scheduler after ThreadTerminate handler is registered.&lt;br /&gt;
** Interrupt handler for the user cycle counter interrupt is no longer registered.&lt;br /&gt;
*** This is presumably now under the same ifdef that enables svc::InfoType_PerformanceCounter.&lt;br /&gt;
* KCapability now has a new member &amp;quot;physical_core_mask&amp;quot;, which tracks what physical cores are allowable.&lt;br /&gt;
** KThread::FinishTermination now calls a new function (cpu::ForceSynchronizeAllCores) after waiting for the thread to not be current on any scheduler.&lt;br /&gt;
*** This function sends an IPI (KInterruptName_CoreBarrier) to all cores in a specified mask (other than the current one), and waits for them to acknowledge the interrupt.&lt;br /&gt;
* Changes to KMemoryManager allocation:&lt;br /&gt;
** KPageHeap now has an additional KPageHeapBitmapRng @ 0x328 to facilitate additional allocation randomization.&lt;br /&gt;
** KMemoryManager::AllocateAndOpenContinuous now uses a new KPageHeap method &amp;quot;AllocateRandomBlock&amp;quot;&lt;br /&gt;
*** KPhysicalAddress KPageHeap::AllocateRandomBlock(s32 index, size_t num_pages, size_t align_pages);&lt;br /&gt;
*** This method allocates `num_pages` pages (aligned to at least `align_pages`) at random.&lt;br /&gt;
**** First, the kernel chooses a random block index to allocate from.&lt;br /&gt;
***** This is done by increasing the block index until there are at least 4 possible random choices for the desired alignment, then selecting the block that corresponds to a random pick from those choices.&lt;br /&gt;
**** Next, the kernel allocates a random block from within that index.&lt;br /&gt;
**** Finally, the kernel selects a random (align_pages)-aligned offset within that block, frees the memory before/after the allocated chunk, and returns the memory.&lt;br /&gt;
** Allocation of KPageGroups still uses a `random` argument, however:&lt;br /&gt;
*** KPageHeap::PopBlock no longer takes a random argument.&lt;br /&gt;
*** KPageHeap::AllocateBlock now calls new new KPageHeap method &amp;quot;AllocateRandomBlock&amp;quot;.&lt;br /&gt;
**** KPageHeap::AllocateRandomBlock(s32 index, size_t num_pages);&lt;br /&gt;
**** This is effectively the same logic as above, but with align_pages == # of pages for the argument block index.&lt;br /&gt;
* CreateProcess now calls a new function to validate the user-capabilities before creating the KProcess.&lt;br /&gt;
** This checks that the capabilities are user-readable and that the map region capabilities correspond to actually-present regions.&lt;br /&gt;
** This corresponds to changes in Loader allowing for map region capabilities (previously, these were only allowed via KIP, and Loader always rejected them).&lt;br /&gt;
* New InfoType 0x1A (&amp;quot;InfoType_IsSvcPermitted&amp;quot;).&lt;br /&gt;
** Returns whether the current process can access a given SVC.&lt;br /&gt;
** Nintendo returns InvalidCombination when checking SVCs other than SynchronizePreemptionState.&lt;br /&gt;
*** Official userland code now aborts if the process does not have permission to use SynchronizePreemptionState before incrementing ThreadLocalRegion-&amp;gt;disable_count for the first time.&lt;br /&gt;
&lt;br /&gt;
=== IPC Interface Changes ===&lt;br /&gt;
* The following new interfaces were added:&lt;br /&gt;
** nn::sprofile::srv::IServiceGetter&lt;br /&gt;
* The following interfaces were changed:&lt;br /&gt;
** nn::account::detail::IUserStateManager&lt;br /&gt;
*** Added command 900 - inbytes: 24, outbytes: 0&lt;br /&gt;
*** Added command 901 - inbytes: 24, outbytes: 0&lt;br /&gt;
*** Added command 902 - buffers: [10], inbytes: 8, outbytes: 4&lt;br /&gt;
** nn::am::service::IAppletCommonFunctions&lt;br /&gt;
*** Added command 80 - inbytes: 1, outbytes: 0&lt;br /&gt;
*** Added command 81 - inbytes: 1, outbytes: 0&lt;br /&gt;
** nn::am::service::IApplicationFunctions&lt;br /&gt;
*** Added command 36 - inbytes: 0, outbytes: 1&lt;br /&gt;
*** Added command 37 - inbytes: 0, outbytes: 0, outhandles: [1]&lt;br /&gt;
** nn::am::service::IDebugFunctions&lt;br /&gt;
*** Added command 140 - inbytes: 0, outbytes: 0&lt;br /&gt;
** nn::am::service::IOverlayFunctions&lt;br /&gt;
*** Added command 21 - inbytes: 1, outbytes: 0&lt;br /&gt;
** nn::audioctrl::detail::IAudioController&lt;br /&gt;
*** Removed command 11 - inbytes: 4, outbytes: 0&lt;br /&gt;
*** Removed command 12 - inbytes: 0, outbytes: 4&lt;br /&gt;
*** Removed command 19 - inbytes: 0, outbytes: 0, outhandles: [1]&lt;br /&gt;
*** Removed command 20 - inbytes: 0, outbytes: 0, outhandles: [1]&lt;br /&gt;
*** Removed command 21 - inbytes: 0, outbytes: 4&lt;br /&gt;
*** Removed command 25 - inbytes: 0, outbytes: 9&lt;br /&gt;
*** Removed command 28 - inbytes: 0, outbytes: 4&lt;br /&gt;
*** Removed command 29 - inbytes: 0, outbytes: 0, outhandles: [1]&lt;br /&gt;
*** Added command 35 - inbytes: 8, outbytes: 0&lt;br /&gt;
*** Added command 36 - inbytes: 0, outbytes: 8&lt;br /&gt;
*** Added command 37 - inbytes: 1, outbytes: 0&lt;br /&gt;
*** Added command 38 - inbytes: 0, outbytes: 1&lt;br /&gt;
*** Added command 39 - inbytes: 0, outbytes: 1&lt;br /&gt;
*** Added command 40 - buffers: [26], inbytes: 0, outbytes: 0&lt;br /&gt;
*** Added command 10100 - inbytes: 0, outbytes: 9&lt;br /&gt;
*** Added command 10101 - inbytes: 0, outbytes: 0, outhandles: [1]&lt;br /&gt;
*** Added command 10102 - inbytes: 0, outbytes: 0, outhandles: [1]&lt;br /&gt;
*** Added command 10103 - inbytes: 0, outbytes: 4&lt;br /&gt;
*** Added command 10104 - inbytes: 0, outbytes: 4&lt;br /&gt;
*** Added command 10105 - inbytes: 0, outbytes: 0, outhandles: [1]&lt;br /&gt;
*** Added command 10106 - inbytes: 0, outbytes: 4&lt;br /&gt;
** nn::bluetooth::IBluetoothDriver&lt;br /&gt;
*** Removed command 144 - inbytes: 0, outbytes: 0, outhandles: [1]&lt;br /&gt;
*** Removed command 145 - buffers: [10], inbytes: 0, outbytes: 4&lt;br /&gt;
*** Added command 150 - inbytes: 4, outbytes: 0, outhandles: [1]&lt;br /&gt;
*** Added command 151 - inbytes: 4, outbytes: 0, outhandles: [1]&lt;br /&gt;
*** Added command 152 - inbytes: 4, outbytes: 1&lt;br /&gt;
*** Added command 153 - inbytes: 8, outbytes: 0&lt;br /&gt;
*** Added command 154 - inbytes: 4, outbytes: 1&lt;br /&gt;
** nn::bpc::IBoardPowerControlManager&lt;br /&gt;
*** Removed command 6 - inbytes: 0, outbytes: 4&lt;br /&gt;
** nn::btm::IBtm&lt;br /&gt;
*** Added command 112 - inbytes: 7, outbytes: 0&lt;br /&gt;
*** Added command 113 - inbytes: 6, outbytes: 1&lt;br /&gt;
*** Added command 114 - inbytes: 6, outbytes: 1&lt;br /&gt;
*** Added command 115 - buffers: [10], inbytes: 4, outbytes: 4&lt;br /&gt;
** nn::clkrst::IClkrstSession&lt;br /&gt;
*** Added command 12 - inbytes: 4, outbytes: 1&lt;br /&gt;
*** Added command 13 - inbytes: 4, outbytes: 0&lt;br /&gt;
** nn::es::IActiveRightsContext&lt;br /&gt;
*** Added command 17 - buffers: [5, 5], inbytes: 1, outbytes: 0&lt;br /&gt;
*** Added command 214 - inbytes: 0, outbytes: 0, outhandles: [1]&lt;br /&gt;
*** Added command 215 - inbytes: 0, outbytes: 0&lt;br /&gt;
** nn::es::IETicketService&lt;br /&gt;
*** Removed command 4 - inbytes: 4, outbytes: 0&lt;br /&gt;
** nn::fatalsrv::IPrivateService&lt;br /&gt;
*** Added command 10 - buffers: [22], inbytes: 0, outbytes: 16&lt;br /&gt;
** nn::fssrv::sf::IFileSystemProxy&lt;br /&gt;
*** Added command 37 - buffers: [25], inbytes: 0, outbytes: 0&lt;br /&gt;
** nn::grcsrv::IRemoteVideoTransfer&lt;br /&gt;
*** Added command 3 - inbytes: 0, outbytes: 1&lt;br /&gt;
** nn::hid::IHidSystemServer&lt;br /&gt;
*** Added command 327 - buffers: [10], inbytes: 4, outbytes: 8&lt;br /&gt;
*** Added command 328 - inbytes: 16, outbytes: 1&lt;br /&gt;
*** Added command 329 - inbytes: 0, outbytes: 0&lt;br /&gt;
*** Added command 330 - inbytes: 8, outbytes: 0&lt;br /&gt;
*** Added command 506 - inbytes: 16, outbytes: 0&lt;br /&gt;
*** Added command 507 - inbytes: 16, outbytes: 0&lt;br /&gt;
** nn::mnpp::detail::ipc::IServiceForSystem&lt;br /&gt;
*** Removed command 200 - inbytes: 0, outbytes: 0&lt;br /&gt;
*** Added command 400 - inbytes: 0, outbytes: 1&lt;br /&gt;
** nn::mnpp::detail::ipc::IServiceForWebBrowser&lt;br /&gt;
*** Added command 1 - buffers: [5, 5, 6], inbytes: 16, outbytes: 0&lt;br /&gt;
*** Added command 10 - buffers: [6], inbytes: 16, outbytes: 1&lt;br /&gt;
*** Added command 20 - inbytes: 16, outbytes: 0&lt;br /&gt;
** nn::ndrm::low::detail::INdrmLowAdminInterface&lt;br /&gt;
*** Added command 37 - inbytes: 8, outbytes: 0, outhandles: [1]&lt;br /&gt;
*** Added command 38 - buffers: [6], inbytes: 8, outbytes: 4&lt;br /&gt;
*** Added command 39 - buffers: [6], inbytes: 8, outbytes: 4&lt;br /&gt;
*** Removed command 8003 - buffers: [6], inbytes: 8, outbytes: 4&lt;br /&gt;
** nn::nim::detail::INetworkInstallManager&lt;br /&gt;
*** Changed command 10 - outbytes: 72 -&amp;gt; 88 (final state: inbytes: 16, outbytes: 88)&lt;br /&gt;
*** Changed command 130 - inbytes: 0 -&amp;gt; 8 (final state: inbytes: 8, outbytes: 0, outhandles: [1], outinterfaces: [&#039;nn::nim::detail::IAsyncData&#039;])&lt;br /&gt;
*** Added command 135 - inbytes: 0, outbytes: 0&lt;br /&gt;
*** Added command 136 - inbytes: 16, outbytes: 0, outhandles: [1], outinterfaces: [&#039;nn::nim::detail::IAsyncValue&#039;]&lt;br /&gt;
*** Added command 137 - inbytes: 16, outbytes: 4&lt;br /&gt;
** nn::nim::detail::IShopServiceManager&lt;br /&gt;
*** Added command 108 - buffers: [5], inbytes: 0, outbytes: 0&lt;br /&gt;
*** Removed command 303 - inbytes: 16, outbytes: 1&lt;br /&gt;
*** Removed command 305 - inbytes: 16, outbytes: 0, outhandles: [1], outinterfaces: [&#039;nn::nim::detail::IAsyncResult&#039;]&lt;br /&gt;
*** Removed command 400 - inbytes: 4, outbytes: 16&lt;br /&gt;
*** Removed command 401 - inbytes: 16, outbytes: 4&lt;br /&gt;
*** Added command 600 - inbytes: 0, outbytes: 1&lt;br /&gt;
*** Added command 601 - inbytes: 0, outbytes: 0&lt;br /&gt;
** nn::ns::detail::IApplicationManagerInterface&lt;br /&gt;
*** Added command 610 - inbytes: 16, outbytes: 1&lt;br /&gt;
*** Added command 2522 - inbytes: 16, outbytes: 0&lt;br /&gt;
*** Added command 3050 - buffers: [6], inbytes: 0, outbytes: 4&lt;br /&gt;
** nn::ns::detail::IDevelopInterface&lt;br /&gt;
*** Added command 20 - inbytes: 8, outbytes: 8&lt;br /&gt;
** nn::ns::detail::IDynamicRightsInterface&lt;br /&gt;
*** Added command 22 - inbytes: 8, outbytes: 1&lt;br /&gt;
*** Added command 23 - inbytes: 8, outbytes: 0, outhandles: [1]&lt;br /&gt;
*** Added command 24 - inbytes: 8, outbytes: 0&lt;br /&gt;
*** Added command 25 - inbytes: 0, outbytes: 0, outhandles: [1], outinterfaces: [&#039;nn::ns::detail::IAsyncResult&#039;]&lt;br /&gt;
** nn::ns::detail::IECommerceInterface&lt;br /&gt;
*** Added command 7 - inbytes: 16, outbytes: 0, outhandles: [1], outinterfaces: [&#039;nn::ns::detail::IAsyncValue&#039;]&lt;br /&gt;
** nn::omm::detail::IOperationModeManager&lt;br /&gt;
*** Added command 500 - inbytes: 8, outbytes: 0&lt;br /&gt;
*** Added command 501 - inbytes: 8, outbytes: 0&lt;br /&gt;
*** Added command 900 - inbytes: 0, outbytes: 0&lt;br /&gt;
** nn::pcie::detail::ISession&lt;br /&gt;
*** Changed command 4 - outbytes: 24 -&amp;gt; 32 (final state: inbytes: 8, outbytes: 32)&lt;br /&gt;
** nn::pm::detail::IDebugMonitorInterface&lt;br /&gt;
*** Added command 7 - inbytes: 8, outbytes: 8&lt;br /&gt;
** nn::pm::detail::IInformationInterface&lt;br /&gt;
*** Added command 1 - inbytes: 0, outbytes: 24&lt;br /&gt;
*** Added command 2 - inbytes: 0, outbytes: 24&lt;br /&gt;
** nn::pm::detail::IShellInterface&lt;br /&gt;
*** Added command 10 - inbytes: 0, outbytes: 0&lt;br /&gt;
** nn::pwm::IChannelSession&lt;br /&gt;
*** Removed command 2 - inbytes: 4, outbytes: 0&lt;br /&gt;
*** Removed command 3 - inbytes: 0, outbytes: 4&lt;br /&gt;
** nn::settings::ISystemSettingsServer&lt;br /&gt;
*** Added command 207 - inbytes: 0, outbytes: 1&lt;br /&gt;
*** Added command 208 - inbytes: 1, outbytes: 0&lt;br /&gt;
*** Added command 209 - inbytes: 0, outbytes: 8&lt;br /&gt;
*** Added command 210 - inbytes: 8, outbytes: 0&lt;br /&gt;
** nn::ssl::sf::ISslService&lt;br /&gt;
*** Added command 9 - inbytes: 0, outbytes: 0&lt;br /&gt;
** nn::ts::server::IMeasurementServer&lt;br /&gt;
*** Removed command 2 - inbytes: 2, outbytes: 0&lt;br /&gt;
*** Removed command 3 - inbytes: 1, outbytes: 4&lt;br /&gt;
** nn::ts::server::ISession&lt;br /&gt;
*** Removed command 1 - inbytes: 0, outbytes: 4&lt;br /&gt;
*** Removed command 3 - inbytes: 0, outbytes: 4&lt;br /&gt;
** nn::uart::IPortSession&lt;br /&gt;
*** Added command 8 - inbytes: 40, inhandles: [1, 1], outbytes: 0&lt;br /&gt;
&lt;br /&gt;
===[[JIT_services|jit]]===&lt;br /&gt;
Some minor [[JIT_services|issues]] were [[Switch_System_Flaws|fixed]].&lt;br /&gt;
&lt;br /&gt;
==See Also==&lt;br /&gt;
System update report(s):&lt;br /&gt;
* [https://yls8.mtheall.com/ninupdates/reports.php?date=2022-03-22_00-05-06&amp;amp;sys=hac]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{NavboxVersions}}&lt;br /&gt;
&lt;br /&gt;
[[Category:System versions]]&lt;/div&gt;</summary>
		<author><name>Yellows8</name></author>
	</entry>
	<entry>
		<id>https://switchbrew.org/w/index.php?title=News&amp;diff=14877</id>
		<title>News</title>
		<link rel="alternate" type="text/html" href="https://switchbrew.org/w/index.php?title=News&amp;diff=14877"/>
		<updated>2026-08-06T00:31:54Z</updated>

		<summary type="html">&lt;p&gt;Yellows8: Undo revision 14870 by Yls8bot (talk)&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;noinclude&amp;gt;&lt;br /&gt;
==Adding an item==&lt;br /&gt;
* Log in to the wiki. Editing is disabled if you don&#039;t have an account.&lt;br /&gt;
* Add the news event to the top of the list, using this format for the date: &amp;lt;tt&amp;gt;&amp;lt;nowiki&amp;gt;&#039;&#039;&#039;&amp;lt;/nowiki&amp;gt;{{#time: d F y}}&amp;lt;nowiki&amp;gt;&#039;&#039;&#039; &amp;lt;/nowiki&amp;gt;&amp;lt;/tt&amp;gt;. Please include the application&#039;s creator, version number, and a link to a page on 3DBrew about the application. No external links please.&lt;br /&gt;
* &#039;&#039;&#039;Move the last entry to the [[:News/Archive|news archive]]. There should be no more than 4 entries in the list.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==Archives==&lt;br /&gt;
For older news, see the [[:News/Archive|news archive]].&lt;br /&gt;
&lt;br /&gt;
=== News ===&lt;br /&gt;
&amp;lt;!-- Add news below --&amp;gt;&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
*&#039;&#039;&#039;16 June 26&#039;&#039;&#039; Nintendo released system update [[22.5.0]].&lt;br /&gt;
*&#039;&#039;&#039;7 April 26&#039;&#039;&#039; Nintendo released system update [[22.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;17 March 26&#039;&#039;&#039; Nintendo released system update [[22.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;20 January 26&#039;&#039;&#039; Nintendo released system update [[19.0.2]] for CHN region.&lt;/div&gt;</summary>
		<author><name>Yellows8</name></author>
	</entry>
	<entry>
		<id>https://switchbrew.org/w/index.php?title=News/Archive&amp;diff=14876</id>
		<title>News/Archive</title>
		<link rel="alternate" type="text/html" href="https://switchbrew.org/w/index.php?title=News/Archive&amp;diff=14876"/>
		<updated>2026-08-06T00:31:42Z</updated>

		<summary type="html">&lt;p&gt;Yellows8: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*&#039;&#039;&#039;13 January 26&#039;&#039;&#039; Nintendo released system update [[21.2.0]].&lt;br /&gt;
*&#039;&#039;&#039;9 December 25&#039;&#039;&#039; Nintendo released system update [[21.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;25 November 25&#039;&#039;&#039; Nintendo released system update [[21.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;11 November 25&#039;&#039;&#039; Nintendo released system update [[21.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;30 September 25&#039;&#039;&#039; Nintendo released system update [[20.5.0]].&lt;br /&gt;
*&#039;&#039;&#039;2 September 25&#039;&#039;&#039; Nintendo released system update [[20.4.0]].&lt;br /&gt;
*&#039;&#039;&#039;29 July 25&#039;&#039;&#039; Nintendo released system update [[20.3.0]].&lt;br /&gt;
*&#039;&#039;&#039;15 July 25&#039;&#039;&#039; Nintendo released system update [[20.2.0]].&lt;br /&gt;
*&#039;&#039;&#039;19 June 25&#039;&#039;&#039; Nintendo released system update [[20.1.5]].&lt;br /&gt;
*&#039;&#039;&#039;3 June 25&#039;&#039;&#039; Nintendo released system update [[20.1.1]].&lt;br /&gt;
*&#039;&#039;&#039;28 May 25&#039;&#039;&#039; Nintendo released system update [[20.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;2 May 25&#039;&#039;&#039; Nintendo released system update [[20.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;30 April 25&#039;&#039;&#039; Nintendo released system update [[20.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;7 January 25&#039;&#039;&#039; Nintendo released a rebootless system update for [[19.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;29 October 24&#039;&#039;&#039; Nintendo released system update [[19.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;8 October 24&#039;&#039;&#039; Nintendo released system update [[19.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;2 July 24&#039;&#039;&#039; Nintendo released a rebootless system update for [[18.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;11 June 24&#039;&#039;&#039; Nintendo released system update [[18.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;23 April 24&#039;&#039;&#039; Nintendo released system update [[18.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;26 March 24&#039;&#039;&#039; Nintendo released system update [[18.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;20 February 24&#039;&#039;&#039; Nintendo released a rebootless system update for [[17.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;5 December 23&#039;&#039;&#039; Nintendo released system update [[17.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;21 November 23&#039;&#039;&#039; Nintendo released a rebootless system update for [[17.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;11 October 23&#039;&#039;&#039; Nintendo released system update [[17.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;22 August 23&#039;&#039;&#039; Nintendo released system update [[16.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;9 May 23&#039;&#039;&#039; Nintendo released system update [[16.0.3]].&lt;br /&gt;
*&#039;&#039;&#039;18 April 23&#039;&#039;&#039; Nintendo released system update [[16.0.2]].&lt;br /&gt;
*&#039;&#039;&#039;23 March 23&#039;&#039;&#039; Nintendo released system update [[16.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;21 February 23&#039;&#039;&#039; Nintendo released system update [[16.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;1 November 22&#039;&#039;&#039; Nintendo released system update [[15.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;11 October 22&#039;&#039;&#039; Nintendo released system update [[15.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;14 June 22&#039;&#039;&#039; Nintendo released system update [[14.1.2]].&lt;br /&gt;
*&#039;&#039;&#039;19 April 22&#039;&#039;&#039; Nintendo released system update [[14.1.1]].&lt;br /&gt;
*&#039;&#039;&#039;5 April 22&#039;&#039;&#039; Nintendo released system update [[14.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;22 March 22&#039;&#039;&#039; Nintendo released system update [[14.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;20 January 22&#039;&#039;&#039; Nintendo released system update [[13.2.1]].&lt;br /&gt;
*&#039;&#039;&#039;1 December 21&#039;&#039;&#039; Nintendo released system update [[13.2.0]].&lt;br /&gt;
*&#039;&#039;&#039;26 October 21&#039;&#039;&#039; Nintendo released system update [[13.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;15 September 21&#039;&#039;&#039; Nintendo released system update [[13.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;6 July 21&#039;&#039;&#039; Nintendo released system update [[12.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;12 June 21&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=9226&amp;amp;p=17113#p17113 libnx v4.1.0 released].&lt;br /&gt;
*&#039;&#039;&#039;8 June 21&#039;&#039;&#039; Nintendo released system update [[12.0.3]].&lt;br /&gt;
*&#039;&#039;&#039;12 May 21&#039;&#039;&#039; Nintendo released system update [[12.0.2]].&lt;br /&gt;
*&#039;&#039;&#039;20 April 21&#039;&#039;&#039; Nintendo released system update [[12.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;6 April 21&#039;&#039;&#039; Nintendo released system update [[12.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;9 March 21&#039;&#039;&#039; Nintendo released a rebootless system update for [[11.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;11 December 20&#039;&#039;&#039; Nintendo released system update [[11.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;1 December 20&#039;&#039;&#039; Nintendo released system update [[11.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;15 September 20&#039;&#039;&#039; Nintendo released system update [[10.2.0]].&lt;br /&gt;
*&#039;&#039;&#039;28 July 20&#039;&#039;&#039; Nintendo released system update [[10.1.1]].&lt;br /&gt;
*&#039;&#039;&#039;14 July 20&#039;&#039;&#039; Nintendo released system update [[10.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;5 June 20&#039;&#039;&#039; Nintendo released system update [[10.0.4]].&lt;br /&gt;
*&#039;&#039;&#039;26 May 20&#039;&#039;&#039; Nintendo released system update [[10.0.3]].&lt;br /&gt;
*&#039;&#039;&#039;11 May 20&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=9058 devkitA64 r15, libnx v3.2.0, deko3d v0.2.0, switch-examples v20200511] and [https://github.com/switchbrew/nx-hbloader/releases/tag/v2.3.2 nx-hbloader v2.3.2] released.&lt;br /&gt;
*&#039;&#039;&#039;30 April 20&#039;&#039;&#039; Nintendo released system update [[10.0.2]].&lt;br /&gt;
*&#039;&#039;&#039;22 April 20&#039;&#039;&#039; Nintendo released system update [[10.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;14 April 20&#039;&#039;&#039; Nintendo released system update [[10.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;4 April 20&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=9035 libnx v3.1.0, switch-examples v20200404 and deko3d v0.1.0 released]. On the 6th nx-hbmenu v3.3.0 was [https://github.com/switchbrew/nx-hbmenu/releases/latest released].&lt;br /&gt;
*&#039;&#039;&#039;2 April 20&#039;&#039;&#039; [https://github.com/switchbrew/nssu-updater nssu-updater] and [https://github.com/switchbrew/contents-delivery-manager contents-delivery-manager] were released.&lt;br /&gt;
*&#039;&#039;&#039;3 March 20&#039;&#039;&#039; Nintendo released system update [[9.2.0]].&lt;br /&gt;
*&#039;&#039;&#039;10 December 19&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8989 libnx v3.0.0, switch-examples v20191211, Atmosphère v0.10.1, nx-hbmenu v3.2.0, and nx-hbloader v2.3.0 released].&lt;br /&gt;
*&#039;&#039;&#039;4 December 19&#039;&#039;&#039; Nintendo released system update [[9.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;30 September 19&#039;&#039;&#039; Nintendo released system update [[9.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;14 September 19&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8964 libnx v2.5.0 and switch-examples v20190914 released]. nx-hbmenu v3.1.1 [https://github.com/switchbrew/nx-hbmenu/releases/tag/v3.1.1 released]. [https://github.com/Atmosphere-NX/Atmosphere/releases/tag/0.9.4 Atmosphère 0.9.4 released with support for 9.0.0].&lt;br /&gt;
*&#039;&#039;&#039;9 September 19&#039;&#039;&#039; Nintendo released system update [[9.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;10 July 19&#039;&#039;&#039; Nintendo [https://twitter.com/NintendoAmerica/status/1148934589026455552 announced] the Nintendo Switch Lite system.&lt;br /&gt;
*&#039;&#039;&#039;17 June 19&#039;&#039;&#039; Nintendo released system update [[8.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;1 May 19&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8908 libnx v2.2.0 and switch-examples v20190501] released.&lt;br /&gt;
*&#039;&#039;&#039;23 April 19&#039;&#039;&#039; Nintendo released system update [[8.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;15 April 19&#039;&#039;&#039; Nintendo released system update [[8.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;29 March 19&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8891 devkitA64 r13] and [https://github.com/switchbrew/libnx/releases/tag/v2.1.0 libnx v2.1.0] released with pthread/std::thread support.&lt;br /&gt;
*&#039;&#039;&#039;26 March 19&#039;&#039;&#039; [https://github.com/Atmosphere-NX/Atmosphere/releases/tag/0.8.6 Atmosphère v0.8.6] released with lots of bugfixes, more cheat stuff and web applet homebrew support.&lt;br /&gt;
*&#039;&#039;&#039;21 February 19&#039;&#039;&#039; [https://github.com/Atmosphere-NX/Atmosphere/releases/tag/0.8.4 Atmosphère v0.8.4] released with 7.0.x support.&lt;br /&gt;
*&#039;&#039;&#039;18 February 19&#039;&#039;&#039; Nintendo released system update [[7.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;28 January 19&#039;&#039;&#039; Nintendo released system update [[7.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;24 January 19&#039;&#039;&#039; [https://github.com/Atmosphere-NX/Atmosphere/releases/tag/0.8.3 Atmosphère v0.8.3] and [https://github.com/switchbrew/nx-hbloader/releases/tag/v2.1.0 nx-hbloader v2.1.0] were released.&lt;br /&gt;
*&#039;&#039;&#039;2 January 19&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8826 libnx 2.0.0, switch-mesa 18.3 and switch-examples 20190102] were released.&lt;br /&gt;
*&#039;&#039;&#039;29 November 18&#039;&#039;&#039; [https://github.com/Atmosphere-NX/Atmosphere/releases/tag/0.8.0 Atmosphère v0.8.0] was released.&lt;br /&gt;
*&#039;&#039;&#039;29 November 18&#039;&#039;&#039; [https://github.com/switchbrew/nx-hbmenu/releases/latest nx-hbmenu v3.0.1] was released.&lt;br /&gt;
*&#039;&#039;&#039;28 November 18&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8813 libnx 1.6.0 and switch-examples 20181128] were released.&lt;br /&gt;
*&#039;&#039;&#039;19 November 18&#039;&#039;&#039; Nintendo released system update [[6.2.0]].&lt;br /&gt;
*&#039;&#039;&#039;31 October 18&#039;&#039;&#039; [https://github.com/switchbrew/nx-hbloader/releases/tag/v2.0.1 nx-hbloader v2.0.1] was released.&lt;br /&gt;
*&#039;&#039;&#039;29 October 18&#039;&#039;&#039; [https://github.com/switchbrew/nx-hbmenu/releases/latest nx-hbmenu] v3.0.0 was released.&lt;br /&gt;
*&#039;&#039;&#039;29 October 18&#039;&#039;&#039; Nintendo released system update [[6.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;27 October 18&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8798 libnx 1.5.0 and switch-examples 20181027] were released.&lt;br /&gt;
*&#039;&#039;&#039;17 October 18&#039;&#039;&#039; [https://github.com/Atmosphere-NX/Atmosphere/releases/tag/0.7.0 Atmosphère v0.7.0] and [https://github.com/switchbrew/nx-hbloader/releases/tag/v2.0.0 nx-hbloader v2.0.0] were released.&lt;br /&gt;
*&#039;&#039;&#039;8 October 18&#039;&#039;&#039; Nintendo released system update [[6.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;18 September 18&#039;&#039;&#039; Nintendo released system update [[6.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;18 September 18&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8784  libnx 1.4.1, switch-mesa v18.2β and switch-examples 20180918] were released.&lt;br /&gt;
*&#039;&#039;&#039;9 September 18&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8780 libnx v1.4.0] was released alongside a Switch port of mesa/nouveau (GPU library).&lt;br /&gt;
*&#039;&#039;&#039;28 July 18&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8761 devkitA64] r12 and [https://github.com/switchbrew/libnx/releases/tag/v1.3.1 libnx] v1.3.1 were released.&lt;br /&gt;
*&#039;&#039;&#039;8 July 18&#039;&#039;&#039; [https://github.com/switchbrew/libnx/releases/tag/v1.3.0 libnx] v1.3.0 was released.&lt;br /&gt;
*&#039;&#039;&#039;30 May 18&#039;&#039;&#039; Nintendo released system update [[5.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;16 April 18&#039;&#039;&#039; Nintendo released system update [[5.0.2]].&lt;br /&gt;
*&#039;&#039;&#039;26 March 18&#039;&#039;&#039; Nintendo released system update [[5.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;12 March 18&#039;&#039;&#039; Nintendo released system update [[5.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;2 March 18&#039;&#039;&#039; [https://github.com/switchbrew/libnx/releases/tag/v1.1.0 libnx] v1.1.0 was released.&lt;br /&gt;
*&#039;&#039;&#039;28 February 18&#039;&#039;&#039; [https://github.com/switchbrew/nx-hbmenu/releases/latest nx-hbmenu] v2.0.0 was released.&lt;br /&gt;
*&#039;&#039;&#039;22 February 18&#039;&#039;&#039; [http://devkitpro.org devkitPro] released [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8693 devkitA64 alpha7]&lt;br /&gt;
*&#039;&#039;&#039;18 February 18&#039;&#039;&#039; [https://switchbrew.github.io/nx-hbl/ nx-hbl] and [https://github.com/switchbrew/nx-hbmenu nx-hbmenu] were released.&lt;br /&gt;
*&#039;&#039;&#039;28 December 17&#039;&#039;&#039; The 34c3 Switch [https://events.ccc.de/congress/2017/Fahrplan/events/8941.html talk] took place, video available [https://media.ccc.de/v/34c3-8941-console_security_-_switch here].&lt;br /&gt;
*&#039;&#039;&#039;4 December 17&#039;&#039;&#039; Nintendo released system update [[4.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;25 October 17&#039;&#039;&#039; Nintendo released system update [[4.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;18 October 17&#039;&#039;&#039; Nintendo released system update [[4.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;17 September 17&#039;&#039;&#039; [https://github.com/switchbrew/libnx libnx] was made public, with examples available [https://github.com/switchbrew/switch-examples here].&lt;br /&gt;
*&#039;&#039;&#039;5 September 17&#039;&#039;&#039; Nintendo released system update [[3.0.2]].&lt;br /&gt;
*&#039;&#039;&#039;31 July 17&#039;&#039;&#039; Nintendo released system update [[3.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;19 June 17&#039;&#039;&#039; Nintendo released system update [[3.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;15 May 17&#039;&#039;&#039; Nintendo released system update [[2.3.0]].&lt;br /&gt;
*&#039;&#039;&#039;17 April 17&#039;&#039;&#039; Nintendo released system update [[2.2.0]].&lt;br /&gt;
*&#039;&#039;&#039;27 March 17&#039;&#039;&#039; Nintendo released system update [[2.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;2 March 17&#039;&#039;&#039; Nintendo released system update [[2.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;3 March 17&#039;&#039;&#039; Nintendo Switch global release.&lt;/div&gt;</summary>
		<author><name>Yellows8</name></author>
	</entry>
	<entry>
		<id>https://switchbrew.org/w/index.php?title=10.0.0&amp;diff=14865</id>
		<title>10.0.0</title>
		<link rel="alternate" type="text/html" href="https://switchbrew.org/w/index.php?title=10.0.0&amp;diff=14865"/>
		<updated>2026-08-05T23:50:13Z</updated>

		<summary type="html">&lt;p&gt;Yellows8: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The Switch 10.0.0 system update was released on April 14, 2020 (UTC). This Switch update was released for the following regions: ALL.&lt;br /&gt;
&lt;br /&gt;
Security flaws fixed: &amp;lt;fill this in manually later, see the updatedetails page from the ninupdates-report page(s) once available for now&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
==Change-log==&lt;br /&gt;
[https://en-americas-support.nintendo.com/app/answers/detail/a_id/22525/kw/nintendo%20switch%20system%20update Official] ALL change-log:&lt;br /&gt;
* 	Added a bookmark feature to News.&lt;br /&gt;
* 	This feature allows you to bookmark your favorite news items.&lt;br /&gt;
* 	&lt;br /&gt;
* 		A maximum of 300 news items can be bookmarked.&lt;br /&gt;
* 		An internet connection is required to view bookmarked News items.&lt;br /&gt;
* 		News items that are no longer available cannot be viewed, even if they were bookmarked.&lt;br /&gt;
* 	&lt;br /&gt;
* 	&lt;br /&gt;
* 	Added an option to transfer software data between the system memory and an SD card.&lt;br /&gt;
* 	&lt;br /&gt;
* 		Users can now transfer downlopadable software, update data, and DLC from the system memory to an SD card (and vice versa).&lt;br /&gt;
* 		Note that save data and some update data cannot be transferred to an SD card.&lt;br /&gt;
* 	&lt;br /&gt;
* 	&lt;br /&gt;
* 	Added an option to remap the controller buttons.&lt;br /&gt;
* 	&lt;br /&gt;
* 		Analog stick and button configurations can now be changed for each paired controller.&lt;br /&gt;
* 		Custom configurations can be saved as favorites in System Settings &amp;amp;gt; Controllers and Sensors.&lt;br /&gt;
* 			&lt;br /&gt;
* 				Custom configurations are stored on the Nintendo Switch system.&lt;br /&gt;
* 				Configurations can be customized for the following controllers: Joy-Con (L), Joy-Con (R), Nintendo Switch Pro Controller. Button configurations can also be customized on the Nintendo Switch Lite system.&lt;br /&gt;
* 				This feature is not available for other controllers.&lt;br /&gt;
* 				On each system, up to five favorite custom configurations can be saved for Joy-Con (L), five for Joy-Con (R), five for Nintendo Switch Pro Controller. Five configurations can also be saved as favorites for Nintendo Switch Lite.&lt;br /&gt;
* 			&lt;br /&gt;
* 		&lt;br /&gt;
* 	&lt;br /&gt;
* 	&lt;br /&gt;
* 	Added a new section in User Settings for Play Activity Settings.&lt;br /&gt;
* 	&lt;br /&gt;
* 		The options for &amp;quot;Display play activity to:&amp;quot; and &amp;quot;Delete Play Activity&amp;quot; have been moved from Friends Settings to the new Play Activity Settings.&lt;br /&gt;
* 	&lt;br /&gt;
* 	&lt;br /&gt;
* 	Added new selections to the lineup of user profile icons.&lt;br /&gt;
* 	&lt;br /&gt;
* 		Select from 6 new icons from the Animal Crossing: New Horizons game for your user.&lt;br /&gt;
* 	&lt;br /&gt;
* 	&lt;br /&gt;
* 	General system stability improvements to enhance the user&#039;s experience.&lt;br /&gt;
&lt;br /&gt;
==System Titles==&lt;br /&gt;
* Sysmodules jit and pgl were added.&lt;br /&gt;
* All titles were updated, except for: ppc (was already stubbed), Chinese and Korean dictionaries, Dictionary, LocalNews, Eula, ControllerIcon, and flog.&lt;br /&gt;
* The following sysmodules had IPC changes: [[Filesystem_services|fs]], [[Loader_services|Loader]], [[NCM_services|ncm]], [[Settings_services|settings]], [[Bus_services|Bus]], [[Bluetooth_Driver_services|bluetooth]], [[BCAT_services|bcat]], [[Friend_services|friends]], [[PTM_services|ptm]], [[Sockets_services|bsdsockets]], [[HID_services|hid]], [[Audio_services|audio]], [[WLAN_services|wlan]], [[NV_services|nvservices]], [[PCV_services|pcv]], [[Account_services|account]], [[NS_Services|ns]], [[PSC_services|psc]], [[Applet_Manager_services|am]], [[NIM_services|nim]], [[Backlight_services|lbl]], [[BTM_services|btm]], [[Display_services|vi]], [[Parental_Control_services|pctl]], [[NPNS_services|npns]], [[Error_Upload_services|eupld]], [[Glue_services|glue]], [[ETicket_services|es]], [[Shared_Database_services|sdb]], [[OLSC_services|olsc]], [[NGCT_services|ngct]].&lt;br /&gt;
&lt;br /&gt;
NPDM changes:&lt;br /&gt;
* The version was bumped. See [[Services_API]] for service-hosting changes.&lt;br /&gt;
* nifm now has access to pl:u.&lt;br /&gt;
* [[PTM_services|ptm]] now hosts lbl. lbl is now stubbed, there&#039;s no content besides the Meta and the ContentMetaType is now SystemData.&lt;br /&gt;
* [[Sockets_services|bsdsocket]] no longer has access to bgtc:t. It now has access to psc:l and time:al.&lt;br /&gt;
* The pcie.withoutHb sysmodule was renamed to pcie.&lt;br /&gt;
* The mapped IO range for wlan and pcie was updated.&lt;br /&gt;
* [[NS_Services|ns]] now has access to arp:w and pgl. Access to ldr:shel, ncm:v, and pm:shell were removed. Bitmask 0x0000001000000000 is now set in the FS permissions.&lt;br /&gt;
* [[SSL_services|ssl]] now has access to lm, but the sysmodule doesn&#039;t actually use it.&lt;br /&gt;
* [[Error_Upload_services|eupld]] now has access to srepo:u.&lt;br /&gt;
* [[Glue_services|glue]] no longer has access to bpc, and access to time:al was added.&lt;br /&gt;
** Prior to this sysupdate, no retail system-titles used time:al.&lt;br /&gt;
* [[GRC_services|grc]] now has access to time:su.&lt;br /&gt;
* [[creport]] no longer has access to ns:dev, and access to pgl was added.&lt;br /&gt;
* [[Shared_Database_services|sdb]] no longer has access to prepo:s, and access to srepo:u was added.&lt;br /&gt;
* [[OLSC_services|olsc]] now hosts a new [[Services_API|service]], and access to arp:r was added. [[SVC]]s svcMapTransferMemory and svcUnmapTransferMemory are now accessible.&lt;br /&gt;
* All web-applets now have access to [[SVC]]s svcMapPhysicalMemoryUnsafe/svcUnmapPhysicalMemoryUnsafe, but these aren&#039;t used in the main-codebin for any of these applets.&lt;br /&gt;
* [[MyPage_Applet|LibraryAppletMyPage]] now has access to npns:s.&lt;br /&gt;
&lt;br /&gt;
RomFs changes:&lt;br /&gt;
* ErrorMessage has a number of new errors/modules, etc.&lt;br /&gt;
* BrowserDll:&lt;br /&gt;
** &amp;quot;/browser/ErrorPageFilteringTemplate.html&amp;quot; was updated.&lt;br /&gt;
** &amp;quot;/buildinfo/buildinfo.dat&amp;quot; was updated.&lt;br /&gt;
** The OSS NROs under /dll_0/ and /dll_1/ were updated.&lt;br /&gt;
** &amp;quot;/font/NintendoCruiserExt.ttf&amp;quot; was updated.&lt;br /&gt;
** &amp;quot;/lyt/Common/BtnFooter.arc&amp;quot; was updated.&lt;br /&gt;
** The localization under /message/ was updated.&lt;br /&gt;
* Help: &amp;quot;/legallines.htdocs/index.html&amp;quot; and &amp;quot;/safe.htdocs/html/CNzh/index.html&amp;quot; were updated.&lt;br /&gt;
* NgWord was updated.&lt;br /&gt;
* SsidList: &amp;quot;/ssid_list.csv&amp;quot; was updated.&lt;br /&gt;
* AvatarImage: new icons were added.&lt;br /&gt;
* UrlBlackList: The whitelists from the web-applets were moved into here:&lt;br /&gt;
**  &amp;quot;/blacklist.txt&amp;quot; was replaced by &amp;quot;/listCommon.txt&amp;quot;, which is the same except the following was inserted at the beginning: &amp;lt;code&amp;gt;---- &amp;lt;/code&amp;gt;&lt;br /&gt;
** &amp;quot;/listEcGlobal.txt&amp;quot; and &amp;quot;/listEcChina.txt&amp;quot; were added, which contain the same content and are the same as the whitelist originally from LibraryAppletShop.&lt;br /&gt;
** &amp;quot;/listLnsGlobal.txt&amp;quot; and &amp;quot;/listLnsChina.txt&amp;quot; were added, these are the same except &amp;quot;/listLnsChina.txt&amp;quot; contains the following additional line: &amp;lt;code&amp;gt;&amp;lt;nowiki&amp;gt;^https://([0-9A-Za-z\-]+\.)*qq\.com(/|$)&amp;lt;/nowiki&amp;gt;&amp;lt;/code&amp;gt; Besides that line, these are the same as the whitelist originally from LibraryAppletLoginShare.&lt;br /&gt;
** &amp;quot;/listWebYouTubePlayerCommon.txt&amp;quot; was added, containing the same youtube whitelist originally from LibraryAppletWeb.&lt;br /&gt;
* TimeZoneBinary was updated with new timezone info.&lt;br /&gt;
* FontNintendoExtension: &amp;quot;/nintendo_ext2_003.bfttf&amp;quot; was updated.&lt;br /&gt;
* The config in FirmwareDebugSettings, PlatformConfigIcosa, PlatformConfigCopper, PlatformConfigHoag, and PlatformConfigIcosaMariko were updated.&lt;br /&gt;
* [[HID_services#Firmware_update|ControllerFirmware]] was updated with new firmware. See that page for the new files, and also regarding hid-sysmodule RomFs. The following files were updated:&lt;br /&gt;
** /ExpectVersionInfo-platform.hoag.csv&lt;br /&gt;
** /FirmwareInfo.csv&lt;br /&gt;
** /FirmwareInfo-platform.hoag.csv&lt;br /&gt;
** /sioh.bin&lt;br /&gt;
** /sioh_iap.bin&lt;br /&gt;
** /ukyosakyo_ep2_ota.bin&lt;br /&gt;
* NgWord2 was updated.&lt;br /&gt;
* NgWordT was updated.&lt;br /&gt;
* &amp;quot;/common/agl/agl_resource_min.Nin_Nx_NVN.release.sarc.szs&amp;quot; and &amp;quot;/common/shader/VarietyOceanShader_Nx.arc.szs&amp;quot; were updated in various applets. Various /lyt/, graphics, localization, and sound files were updated.&lt;br /&gt;
* LibraryAppletWeb, LibraryAppletShop, and LibraryAppletLoginShare: &amp;quot;/buildinfo/buildinfo.dat&amp;quot; and &amp;quot;/.nrr/netfront.nrr&amp;quot; were updated. &amp;quot;/whitelist&amp;quot; was removed, see UrlBlackList above.&lt;br /&gt;
* LibraryAppletOfflineWeb and LibraryAppletWifiWebAuth: &amp;quot;/buildinfo/buildinfo.dat&amp;quot; and &amp;quot;/.nrr/netfront.nrr&amp;quot; were updated.&lt;br /&gt;
&lt;br /&gt;
=== BootImagePackages ===&lt;br /&gt;
RomFs changes: all files updated.&lt;br /&gt;
&lt;br /&gt;
[[Package2|INI1]] changes:&lt;br /&gt;
* BootImagePackage: &lt;br /&gt;
** 0100000000000000 (FS): MainThreadStackSize updated: 0x8000 -&amp;gt; 0xC000. SVC access: added MapTransferMemory, UnmapTransferMemory.&lt;br /&gt;
** 0100000000000005 (boot): KernelCap IoMemoryMap: added BeginAddress=0x7000A000.&lt;br /&gt;
* BootImagePackageSafe: &lt;br /&gt;
** 0100000000000000 (FS): MainThreadStackSize updated: 0x8000 -&amp;gt; 0xC000. SVC access: added MapTransferMemory, UnmapTransferMemory.&lt;br /&gt;
** 0100000000000005 (boot): KernelCap IoMemoryMap: added BeginAddress=0x7000A000.&lt;br /&gt;
* BootImagePackageExFat: &lt;br /&gt;
** 0100000000000000 (FS): MainThreadStackSize updated: 0x8000 -&amp;gt; 0xC000. SVC access: added MapTransferMemory, UnmapTransferMemory.&lt;br /&gt;
** 0100000000000005 (boot): KernelCap IoMemoryMap: added BeginAddress=0x7000A000.&lt;br /&gt;
* BootImagePackageExFatSafe: &lt;br /&gt;
** 0100000000000000 (FS): MainThreadStackSize updated: 0x8000 -&amp;gt; 0xC000. SVC access: added MapTransferMemory, UnmapTransferMemory.&lt;br /&gt;
** 0100000000000005 (boot): KernelCap IoMemoryMap: added BeginAddress=0x7000A000.&lt;br /&gt;
&lt;br /&gt;
====Secure Monitor====&lt;br /&gt;
Secure Monitor was updated.&lt;br /&gt;
&lt;br /&gt;
* Compiler/optimization flags were changed, many functions now use more optimized asm to accomplish the same functionality.&lt;br /&gt;
* The firmware revision magic was changed from 0x18C to 0x1AD.&lt;br /&gt;
* Support was added for an additional 5 DRAM models.&lt;br /&gt;
* Asynchronous RSA SMCs now set a global to the result that GetResult should return instead of setting a bool that GetResult checks.&lt;br /&gt;
* DecryptOrImportRsaPrivateKey now imports the modulus in addition to the exponent for the ES use cases.&lt;br /&gt;
** This fixes a problem where you could specify a &amp;quot;smooth&amp;quot; modulus instead of the correct one when talking to TrustZone and then use Pohlig-Hellman to calculate the discrete logarithm and recover the private key.&lt;br /&gt;
* Passing a use case to StorageExpMod for which DecryptOrImportRsaPrivateKey does not import modulus now validates that the provided modulus is correct for the previously imported exponent.&lt;br /&gt;
** Future invocations of StorageExpMod will ignore the user-provided modulus, and use the imported one.&lt;br /&gt;
* UnwrapTitleKey now returns new result 7 (&amp;quot;NotImported&amp;quot;) when attempting to unwrap a titlekey before importing the exponent and modulus.&lt;br /&gt;
&lt;br /&gt;
====Warmboot====&lt;br /&gt;
* The firmware revision magic was changed from 0x18C to 0x1AD.&lt;br /&gt;
&amp;lt;check back for more diffs later&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Kernel====&lt;br /&gt;
* Kernel crt0 was heavily refactored.&lt;br /&gt;
** Core 0 init vs Core 1/2/3 init are now separate functions.&lt;br /&gt;
** The initial arguments are now stored inside the Core Local regions before those regions are initialized.&lt;br /&gt;
*** This saves a little memory by allowing for reusing that space.&lt;br /&gt;
** The initial arguments now store an entrypoint invocation function pointer in addition to the entrypoint.&lt;br /&gt;
** Core 1/2/3 now panic if cpuactlr/cpuectlr hold a value different than the one in init argument. Previously, they they did if (real value != expected value) { real value = expected value }.&lt;br /&gt;
* The reserved memory size for slab heap aslr gaps was reduced by 64 KB from 2 MB to 0x1F0000.&lt;br /&gt;
* Physical ASLR for certain backing regions (Kernel .text/.rodata/.rwdata/.bss + the Slab Heap region) was implemented.&lt;br /&gt;
** Physical randomization of the kernel image is done by KernelLdr.&lt;br /&gt;
** Randomization of the slab heap region is done by kernel during init.&lt;br /&gt;
** To accommodate this, the virtual/physical memory trees no longer track pair blocks for the kernel/slab heap regions (as they no longer correlate directly).&lt;br /&gt;
* The global rng is now std::mt19937_64 instead of std::mt19937&lt;br /&gt;
* KPageHeap bitmaps now store a small TinyMT rng.&lt;br /&gt;
** This is used to allocate random pages from the bitmap instead of first-available. Thus, KPageHeap allocation order is now random/non-deterministic.&lt;br /&gt;
* KSpinLock was changed. Previously it used two u16s, each aligned to cache line. Now it packs the u16s into a single non-cache-line aligned u32.&lt;br /&gt;
** The new spin lock is identical to the implementation in the ARM Reference Manual.&lt;br /&gt;
** KScheduler&#039;s spin lock still uses the old cache-line aligned u16s.&lt;br /&gt;
** Speculatively, we can consider the following motivation for the change:&lt;br /&gt;
*** The old spin lock cannot atomically update both tickets with a single write. Thus, it is required to do two loops (one to update the current ticket, one to check if the obtained ticket is the active and the lock is taken).&lt;br /&gt;
*** The new spin lock can atomically update both tickets with a single write. Thus, in the case where the lock is not held by another core when it is acquired, the new spin lock only has to do one atomic loop.&lt;br /&gt;
*** From this we can observe that the new spin lock is likely more performant under low contention (where it is expected that the lock is not held), however its downsides are potential false sharing (due to not owning the cache line). It is also probably better when at the start of a cache line and the locked data exists entirely within that cache line.&lt;br /&gt;
*** Most kernel locks are expected to be relatively uncontended (and there aren&#039;t really cases where two locks are in the same cache line so false sharing isn&#039;t such a problem), and thus the switch to the new ARM reference manual style lock should lead to an overall performance upgrade.&lt;br /&gt;
*** However, the scheduler lock is heavily contended (all cores will be locking it and unlocking it pretty much all the time). Thus, it makes more sense for it to continue using the old two-cache-line style lock, which performs better under high contention.&lt;br /&gt;
* KProcess now has an additional data member storing the kernel virtual address of the process local region.&lt;br /&gt;
** This is now used instead of the process virtual address for the tls region when writing context during exception handling.&lt;br /&gt;
** This probably fixes a bug if an exception is being handled for a non-current process and the relevant codepath is taken(?)&lt;br /&gt;
* Page table entry handling code was changed. Bit 56 is now used as an is valid/present flag. Previously checks that checked entries with bitmask 0x3 now check 0x100000000000002.&lt;br /&gt;
* KPageTableBase now has an additional data member storing how much unsafe memory is currently mapped. (This value is incremented/decremented on calls to svcMapPhysicalMemoryUnsafe/svcUnmapPhysicalMemoryUnsafe).&lt;br /&gt;
* KPageTableBase::LockForIpc* now takes a KPhysicalAddress * argument. Mapping code will try to write the physical address of the locked virtual address to this out pointer, KernelPanic() is called if physical address translation fails.&lt;br /&gt;
* KServerSession::SendReply now takes an additional argument for the physical address of the user message buffer. NULL is passed when doing ReplyAndReceive without a user buffer.&lt;br /&gt;
** When this argument is not null, the message buffer is accessed by doing linear phys-to-virt translation on this physaddress, otherwise the message buffer is accessed by doing linear phys-to-virt translation on the TLS physical address.&lt;br /&gt;
** Previously, the process virtual address for the user buffer was accessed directly.&lt;br /&gt;
* Pages allocated from the dynamic page slab heap are no longer memset to zero after being allocated.&lt;br /&gt;
** Instead, they are memset to zero when the heap is first initialized, and when being freed.&lt;br /&gt;
** This fixes the issue that pages were sometimes memset to zero unnecessarily, because they were already zero&#039;d by some previous operation.&lt;br /&gt;
** Newly allocated pages being all-zero is now a kernel invariant.&lt;br /&gt;
* A new KMemoryPermission bit (0x40) was added. When this bit is set, the page is completely unmapped (for both user and kernel). This is done when e.g. memory is mirrored via MapMemory, when memory is locked for IPC usage, etc.&lt;br /&gt;
* KPageTable::ChangePermissions was changed substantially to accommodate this.&lt;br /&gt;
** Previously, it separated pages, iterated over mappings changing permissions as required (and invalidating + flushing cache if bool arg is true), then merged pages.&lt;br /&gt;
** Now, the function has a lambda which iterates over all mappings, changing permissions as required and performing additional operations depending on a bitflag parameter.&lt;br /&gt;
** First, the function separates pages.&lt;br /&gt;
** Then if the input bool is false, this lambda is called with entry template = input entry template, bitflag parameter = 0. This changes all mappings to the new permissions. Pages are then merged, and the function returns.&lt;br /&gt;
** Otherwise if the input bool is true, the lambda is called with entry template = input entry template &amp;amp; ~1 and bitflag parameter = 2. This changes all mappings to be invalid (as low bit of pte is zero). Bitflag &amp;amp; 2 causes entries to be merged during traversal.&lt;br /&gt;
** Next, the scheduling lock is locked and immediately unlocked. This forces a reschedule.&lt;br /&gt;
** Next, the lambda is called with entry template = input entry template, bitflag parameter = 1. This changes all mappings to new permissions, and flushes data cache on all new mappings.&lt;br /&gt;
** Finally, mappings are merged, and the function returns.&lt;br /&gt;
* SvcQueryIoMapping&#039;s ABI was changed. &lt;br /&gt;
** Previously signature was Result QueryIoMapping(uintptr_t *out_address, PhysicalAddress physical_address, size_t size).&lt;br /&gt;
** New signature is Result QueryIoMapping(uintptr_t *out_address, size_t *out_size, PhysicalAddress physical_address, size_t size);&lt;br /&gt;
** For normal IO, out_size is just written with the input size parameter.&lt;br /&gt;
** For special debug regions (mapped using 8.0.0+ memory region descriptor, queried by passing 1/2/3 as phys_addr parameter), out_size is written with the real size of the queried region.&lt;br /&gt;
* SvcQueryPhysicalAddress was stubbed, and now always returns ResultInvalidCurrentMemoryState.&lt;br /&gt;
* KCurrentContext now stores a dereferencable pointer to the current thread&#039;s TLS.&lt;br /&gt;
** This is used to check the user disable count (for thread pinning) in the SvcHandler instead of loading tls from tpidrro_el0.&lt;br /&gt;
&lt;br /&gt;
====FIRM Sysmodules====&lt;br /&gt;
FIRM sysmodules were updated. Specific diffs available below:&lt;br /&gt;
&amp;lt;check back for more diffs later&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==See Also==&lt;br /&gt;
System update report(s):&lt;br /&gt;
* [https://yls8.mtheall.com/ninupdates/reports.php?date=2020-04-14_00-05-09&amp;amp;sys=hac]&lt;br /&gt;
&lt;br /&gt;
{{NavboxVersions}}&lt;br /&gt;
&lt;br /&gt;
[[Category:System versions]]&lt;/div&gt;</summary>
		<author><name>Yellows8</name></author>
	</entry>
	<entry>
		<id>https://switchbrew.org/w/index.php?title=7.0.1&amp;diff=14863</id>
		<title>7.0.1</title>
		<link rel="alternate" type="text/html" href="https://switchbrew.org/w/index.php?title=7.0.1&amp;diff=14863"/>
		<updated>2026-08-05T23:43:11Z</updated>

		<summary type="html">&lt;p&gt;Yellows8: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The Switch 7.0.1 system update was released on February 18, 2019. This Switch update was released for the following regions: ALL.&lt;br /&gt;
&lt;br /&gt;
Security flaws fixed: &amp;lt;fill this in manually later, see the updatedetails page from the ninupdates-report page(s) once available for now&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
==Change-log==&lt;br /&gt;
[https://en-americas-support.nintendo.com/app/answers/detail/a_id/22525/p/897 Official] ALL change-log:&lt;br /&gt;
* General system stability improvements to enhance the user&#039;s experience, including:&lt;br /&gt;
*     &lt;br /&gt;
*     Resolved an issue where the Pokémon: Let&#039;s Go, Pikachu! and Pokémon: Let&#039;s Go, Eevee! games cannot reconnect to the Pokémon GO app if the game software was closed after pairing with the app.&lt;br /&gt;
*     &lt;br /&gt;
&lt;br /&gt;
==System Titles==&lt;br /&gt;
&amp;lt;fill this in (manually) later&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nothing changed for services IPC.&lt;br /&gt;
&lt;br /&gt;
RomFs changes:&lt;br /&gt;
* [[System_Version_Title|SystemVersion]]: All files updated.&lt;br /&gt;
&lt;br /&gt;
=== BootImagePackages ===&lt;br /&gt;
RomFs changes:&lt;br /&gt;
* &amp;quot;/a/bct&amp;quot; updated, &amp;quot;/a/package1&amp;quot; updated, &amp;quot;/nx/bct&amp;quot; updated, &amp;quot;/nx/package1&amp;quot; updated&lt;br /&gt;
&lt;br /&gt;
====Secure Monitor====&lt;br /&gt;
The Secure Monitor was updated.&lt;br /&gt;
&lt;br /&gt;
* The only change in .text (besides relative branch offsets updating) is that four instructions were inserted into the SMC handler.&lt;br /&gt;
** When the bit in boot reason that restricts access to certain SMCs is set, [[SMC#SecureExpMod|smcSecureExpMod]] is now blacklisted. Previously, only [[SMC#DecryptOrImportRsaKey|smcDecryptOrImportRsaKey]] was blacklisted.&lt;br /&gt;
* The only data changes were that smcSecureExpMod is now allowed to be called in recovery mode, and the global pointers for the TIMER, WAIT, and UART-A regions now default to 0 instead of their physical addresses.&lt;br /&gt;
** The default pointer value change is not meaningful, as these are overwritten by initialization code before they are ever used.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==See Also==&lt;br /&gt;
System update report(s):&lt;br /&gt;
* [https://yls8.mtheall.com/ninupdates/reports.php?date=02-18-19_07-05-10&amp;amp;sys=hac]&lt;br /&gt;
&lt;br /&gt;
{{NavboxVersions}}&lt;br /&gt;
&lt;br /&gt;
[[Category:System versions]]&lt;/div&gt;</summary>
		<author><name>Yellows8</name></author>
	</entry>
	<entry>
		<id>https://switchbrew.org/w/index.php?title=9.2.0&amp;diff=14862</id>
		<title>9.2.0</title>
		<link rel="alternate" type="text/html" href="https://switchbrew.org/w/index.php?title=9.2.0&amp;diff=14862"/>
		<updated>2026-08-05T23:39:09Z</updated>

		<summary type="html">&lt;p&gt;Yellows8: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The Switch 9.2.0 system update was released on March 3, 2020 (UTC). This Switch update was released for the following regions: ALL.&lt;br /&gt;
&lt;br /&gt;
Security flaws fixed: no.&lt;br /&gt;
&lt;br /&gt;
==Change-log==&lt;br /&gt;
[https://en-americas-support.nintendo.com/app/answers/detail/a_id/22525/kw/nintendo%20switch%20system%20update Official] ALL change-log:&lt;br /&gt;
*  General system stability improvements to enhance the user&#039;s experience.&lt;br /&gt;
&lt;br /&gt;
==System Titles==&lt;br /&gt;
Besides [[System_Version_Title|SystemVersion]], only the BootImagePackages were updated.&lt;br /&gt;
&lt;br /&gt;
RomFs changes:&lt;br /&gt;
* [[System_Version_Title|SystemVersion]]: All files updated.&lt;br /&gt;
&lt;br /&gt;
=== BootImagePackages ===&lt;br /&gt;
RomFs changes:&lt;br /&gt;
* &amp;quot;/nx/package2&amp;quot; updated&lt;br /&gt;
&lt;br /&gt;
No IPC changes.&lt;br /&gt;
&lt;br /&gt;
====Kernel====&lt;br /&gt;
Kernel was updated.&lt;br /&gt;
&lt;br /&gt;
The only change was to increase the resource limit for KSessions from 900 to 933.&lt;br /&gt;
&lt;br /&gt;
====FIRM Sysmodules====&lt;br /&gt;
The only FIRM sysmodule updated was PM, this was to increase the system resource limit for Sessions to reflect the kernel change.&lt;br /&gt;
&lt;br /&gt;
==See Also==&lt;br /&gt;
System update report(s):&lt;br /&gt;
* [https://yls8.mtheall.com/ninupdates/reports.php?date=2020-03-03_00-05-10&amp;amp;sys=hac]&lt;br /&gt;
&lt;br /&gt;
{{NavboxVersions}}&lt;br /&gt;
&lt;br /&gt;
[[Category:System versions]]&lt;/div&gt;</summary>
		<author><name>Yellows8</name></author>
	</entry>
	<entry>
		<id>https://switchbrew.org/w/index.php?title=News/Archive&amp;diff=14859</id>
		<title>News/Archive</title>
		<link rel="alternate" type="text/html" href="https://switchbrew.org/w/index.php?title=News/Archive&amp;diff=14859"/>
		<updated>2026-08-05T23:25:58Z</updated>

		<summary type="html">&lt;p&gt;Yellows8: Undo revision 14854 by Yls8bot (talk)&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*&#039;&#039;&#039;13 January 26&#039;&#039;&#039; Nintendo released system update [[21.2.0]].&lt;br /&gt;
*&#039;&#039;&#039;9 December 25&#039;&#039;&#039; Nintendo released system update [[21.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;25 November 25&#039;&#039;&#039; Nintendo released system update [[21.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;11 November 25&#039;&#039;&#039; Nintendo released system update [[21.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;30 September 25&#039;&#039;&#039; Nintendo released system update [[20.5.0]].&lt;br /&gt;
*&#039;&#039;&#039;2 September 25&#039;&#039;&#039; Nintendo released system update [[20.4.0]].&lt;br /&gt;
*&#039;&#039;&#039;29 July 25&#039;&#039;&#039; Nintendo released system update [[20.3.0]].&lt;br /&gt;
*&#039;&#039;&#039;15 July 25&#039;&#039;&#039; Nintendo released system update [[20.2.0]].&lt;br /&gt;
*&#039;&#039;&#039;19 June 25&#039;&#039;&#039; Nintendo released system update [[20.1.5]].&lt;br /&gt;
*&#039;&#039;&#039;3 June 25&#039;&#039;&#039; Nintendo released system update [[20.1.1]].&lt;br /&gt;
*&#039;&#039;&#039;28 May 25&#039;&#039;&#039; Nintendo released system update [[20.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;2 May 25&#039;&#039;&#039; Nintendo released system update [[20.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;30 April 25&#039;&#039;&#039; Nintendo released system update [[20.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;7 January 25&#039;&#039;&#039; Nintendo released a rebootless system update for [[19.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;29 October 24&#039;&#039;&#039; Nintendo released system update [[19.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;8 October 24&#039;&#039;&#039; Nintendo released system update [[19.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;2 July 24&#039;&#039;&#039; Nintendo released a rebootless system update for [[18.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;11 June 24&#039;&#039;&#039; Nintendo released system update [[18.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;23 April 24&#039;&#039;&#039; Nintendo released system update [[18.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;26 March 24&#039;&#039;&#039; Nintendo released system update [[18.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;20 February 24&#039;&#039;&#039; Nintendo released a rebootless system update for [[17.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;5 December 23&#039;&#039;&#039; Nintendo released system update [[17.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;21 November 23&#039;&#039;&#039; Nintendo released a rebootless system update for [[17.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;11 October 23&#039;&#039;&#039; Nintendo released system update [[17.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;22 August 23&#039;&#039;&#039; Nintendo released system update [[16.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;9 May 23&#039;&#039;&#039; Nintendo released system update [[16.0.3]].&lt;br /&gt;
*&#039;&#039;&#039;18 April 23&#039;&#039;&#039; Nintendo released system update [[16.0.2]].&lt;br /&gt;
*&#039;&#039;&#039;23 March 23&#039;&#039;&#039; Nintendo released system update [[16.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;21 February 23&#039;&#039;&#039; Nintendo released system update [[16.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;1 November 22&#039;&#039;&#039; Nintendo released system update [[15.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;11 October 22&#039;&#039;&#039; Nintendo released system update [[15.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;14 June 22&#039;&#039;&#039; Nintendo released system update [[14.1.2]].&lt;br /&gt;
*&#039;&#039;&#039;19 April 22&#039;&#039;&#039; Nintendo released system update [[14.1.1]].&lt;br /&gt;
*&#039;&#039;&#039;5 April 22&#039;&#039;&#039; Nintendo released system update [[14.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;22 March 22&#039;&#039;&#039; Nintendo released system update [[14.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;20 January 22&#039;&#039;&#039; Nintendo released system update [[13.2.1]].&lt;br /&gt;
*&#039;&#039;&#039;1 December 21&#039;&#039;&#039; Nintendo released system update [[13.2.0]].&lt;br /&gt;
*&#039;&#039;&#039;26 October 21&#039;&#039;&#039; Nintendo released system update [[13.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;15 September 21&#039;&#039;&#039; Nintendo released system update [[13.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;6 July 21&#039;&#039;&#039; Nintendo released system update [[12.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;12 June 21&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=9226&amp;amp;p=17113#p17113 libnx v4.1.0 released].&lt;br /&gt;
*&#039;&#039;&#039;8 June 21&#039;&#039;&#039; Nintendo released system update [[12.0.3]].&lt;br /&gt;
*&#039;&#039;&#039;12 May 21&#039;&#039;&#039; Nintendo released system update [[12.0.2]].&lt;br /&gt;
*&#039;&#039;&#039;20 April 21&#039;&#039;&#039; Nintendo released system update [[12.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;9 March 21&#039;&#039;&#039; Nintendo released system update [[12.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;11 December 20&#039;&#039;&#039; Nintendo released system update [[11.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;1 December 20&#039;&#039;&#039; Nintendo released system update [[11.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;15 September 20&#039;&#039;&#039; Nintendo released system update [[10.2.0]].&lt;br /&gt;
*&#039;&#039;&#039;28 July 20&#039;&#039;&#039; Nintendo released system update [[10.1.1]].&lt;br /&gt;
*&#039;&#039;&#039;14 July 20&#039;&#039;&#039; Nintendo released system update [[10.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;5 June 20&#039;&#039;&#039; Nintendo released system update [[10.0.4]].&lt;br /&gt;
*&#039;&#039;&#039;26 May 20&#039;&#039;&#039; Nintendo released system update [[10.0.3]].&lt;br /&gt;
*&#039;&#039;&#039;11 May 20&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=9058 devkitA64 r15, libnx v3.2.0, deko3d v0.2.0, switch-examples v20200511] and [https://github.com/switchbrew/nx-hbloader/releases/tag/v2.3.2 nx-hbloader v2.3.2] released.&lt;br /&gt;
*&#039;&#039;&#039;30 April 20&#039;&#039;&#039; Nintendo released system update [[10.0.2]].&lt;br /&gt;
*&#039;&#039;&#039;22 April 20&#039;&#039;&#039; Nintendo released system update [[10.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;14 April 20&#039;&#039;&#039; Nintendo released system update [[10.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;4 April 20&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=9035 libnx v3.1.0, switch-examples v20200404 and deko3d v0.1.0 released]. On the 6th nx-hbmenu v3.3.0 was [https://github.com/switchbrew/nx-hbmenu/releases/latest released].&lt;br /&gt;
*&#039;&#039;&#039;2 April 20&#039;&#039;&#039; [https://github.com/switchbrew/nssu-updater nssu-updater] and [https://github.com/switchbrew/contents-delivery-manager contents-delivery-manager] were released.&lt;br /&gt;
*&#039;&#039;&#039;3 March 20&#039;&#039;&#039; Nintendo released system update [[9.2.0]].&lt;br /&gt;
*&#039;&#039;&#039;10 December 19&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8989 libnx v3.0.0, switch-examples v20191211, Atmosphère v0.10.1, nx-hbmenu v3.2.0, and nx-hbloader v2.3.0 released].&lt;br /&gt;
*&#039;&#039;&#039;4 December 19&#039;&#039;&#039; Nintendo released system update [[9.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;30 September 19&#039;&#039;&#039; Nintendo released system update [[9.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;14 September 19&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8964 libnx v2.5.0 and switch-examples v20190914 released]. nx-hbmenu v3.1.1 [https://github.com/switchbrew/nx-hbmenu/releases/tag/v3.1.1 released]. [https://github.com/Atmosphere-NX/Atmosphere/releases/tag/0.9.4 Atmosphère 0.9.4 released with support for 9.0.0].&lt;br /&gt;
*&#039;&#039;&#039;9 September 19&#039;&#039;&#039; Nintendo released system update [[9.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;10 July 19&#039;&#039;&#039; Nintendo [https://twitter.com/NintendoAmerica/status/1148934589026455552 announced] the Nintendo Switch Lite system.&lt;br /&gt;
*&#039;&#039;&#039;17 June 19&#039;&#039;&#039; Nintendo released system update [[8.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;1 May 19&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8908 libnx v2.2.0 and switch-examples v20190501] released.&lt;br /&gt;
*&#039;&#039;&#039;23 April 19&#039;&#039;&#039; Nintendo released system update [[8.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;15 April 19&#039;&#039;&#039; Nintendo released system update [[8.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;29 March 19&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8891 devkitA64 r13] and [https://github.com/switchbrew/libnx/releases/tag/v2.1.0 libnx v2.1.0] released with pthread/std::thread support.&lt;br /&gt;
*&#039;&#039;&#039;26 March 19&#039;&#039;&#039; [https://github.com/Atmosphere-NX/Atmosphere/releases/tag/0.8.6 Atmosphère v0.8.6] released with lots of bugfixes, more cheat stuff and web applet homebrew support.&lt;br /&gt;
*&#039;&#039;&#039;21 February 19&#039;&#039;&#039; [https://github.com/Atmosphere-NX/Atmosphere/releases/tag/0.8.4 Atmosphère v0.8.4] released with 7.0.x support.&lt;br /&gt;
*&#039;&#039;&#039;18 February 19&#039;&#039;&#039; Nintendo released system update [[7.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;28 January 19&#039;&#039;&#039; Nintendo released system update [[7.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;24 January 19&#039;&#039;&#039; [https://github.com/Atmosphere-NX/Atmosphere/releases/tag/0.8.3 Atmosphère v0.8.3] and [https://github.com/switchbrew/nx-hbloader/releases/tag/v2.1.0 nx-hbloader v2.1.0] were released.&lt;br /&gt;
*&#039;&#039;&#039;2 January 19&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8826 libnx 2.0.0, switch-mesa 18.3 and switch-examples 20190102] were released.&lt;br /&gt;
*&#039;&#039;&#039;29 November 18&#039;&#039;&#039; [https://github.com/Atmosphere-NX/Atmosphere/releases/tag/0.8.0 Atmosphère v0.8.0] was released.&lt;br /&gt;
*&#039;&#039;&#039;29 November 18&#039;&#039;&#039; [https://github.com/switchbrew/nx-hbmenu/releases/latest nx-hbmenu v3.0.1] was released.&lt;br /&gt;
*&#039;&#039;&#039;28 November 18&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8813 libnx 1.6.0 and switch-examples 20181128] were released.&lt;br /&gt;
*&#039;&#039;&#039;19 November 18&#039;&#039;&#039; Nintendo released system update [[6.2.0]].&lt;br /&gt;
*&#039;&#039;&#039;31 October 18&#039;&#039;&#039; [https://github.com/switchbrew/nx-hbloader/releases/tag/v2.0.1 nx-hbloader v2.0.1] was released.&lt;br /&gt;
*&#039;&#039;&#039;29 October 18&#039;&#039;&#039; [https://github.com/switchbrew/nx-hbmenu/releases/latest nx-hbmenu] v3.0.0 was released.&lt;br /&gt;
*&#039;&#039;&#039;29 October 18&#039;&#039;&#039; Nintendo released system update [[6.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;27 October 18&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8798 libnx 1.5.0 and switch-examples 20181027] were released.&lt;br /&gt;
*&#039;&#039;&#039;17 October 18&#039;&#039;&#039; [https://github.com/Atmosphere-NX/Atmosphere/releases/tag/0.7.0 Atmosphère v0.7.0] and [https://github.com/switchbrew/nx-hbloader/releases/tag/v2.0.0 nx-hbloader v2.0.0] were released.&lt;br /&gt;
*&#039;&#039;&#039;8 October 18&#039;&#039;&#039; Nintendo released system update [[6.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;18 September 18&#039;&#039;&#039; Nintendo released system update [[6.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;18 September 18&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8784  libnx 1.4.1, switch-mesa v18.2β and switch-examples 20180918] were released.&lt;br /&gt;
*&#039;&#039;&#039;9 September 18&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8780 libnx v1.4.0] was released alongside a Switch port of mesa/nouveau (GPU library).&lt;br /&gt;
*&#039;&#039;&#039;28 July 18&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8761 devkitA64] r12 and [https://github.com/switchbrew/libnx/releases/tag/v1.3.1 libnx] v1.3.1 were released.&lt;br /&gt;
*&#039;&#039;&#039;8 July 18&#039;&#039;&#039; [https://github.com/switchbrew/libnx/releases/tag/v1.3.0 libnx] v1.3.0 was released.&lt;br /&gt;
*&#039;&#039;&#039;30 May 18&#039;&#039;&#039; Nintendo released system update [[5.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;16 April 18&#039;&#039;&#039; Nintendo released system update [[5.0.2]].&lt;br /&gt;
*&#039;&#039;&#039;26 March 18&#039;&#039;&#039; Nintendo released system update [[5.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;12 March 18&#039;&#039;&#039; Nintendo released system update [[5.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;2 March 18&#039;&#039;&#039; [https://github.com/switchbrew/libnx/releases/tag/v1.1.0 libnx] v1.1.0 was released.&lt;br /&gt;
*&#039;&#039;&#039;28 February 18&#039;&#039;&#039; [https://github.com/switchbrew/nx-hbmenu/releases/latest nx-hbmenu] v2.0.0 was released.&lt;br /&gt;
*&#039;&#039;&#039;22 February 18&#039;&#039;&#039; [http://devkitpro.org devkitPro] released [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8693 devkitA64 alpha7]&lt;br /&gt;
*&#039;&#039;&#039;18 February 18&#039;&#039;&#039; [https://switchbrew.github.io/nx-hbl/ nx-hbl] and [https://github.com/switchbrew/nx-hbmenu nx-hbmenu] were released.&lt;br /&gt;
*&#039;&#039;&#039;28 December 17&#039;&#039;&#039; The 34c3 Switch [https://events.ccc.de/congress/2017/Fahrplan/events/8941.html talk] took place, video available [https://media.ccc.de/v/34c3-8941-console_security_-_switch here].&lt;br /&gt;
*&#039;&#039;&#039;4 December 17&#039;&#039;&#039; Nintendo released system update [[4.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;25 October 17&#039;&#039;&#039; Nintendo released system update [[4.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;18 October 17&#039;&#039;&#039; Nintendo released system update [[4.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;17 September 17&#039;&#039;&#039; [https://github.com/switchbrew/libnx libnx] was made public, with examples available [https://github.com/switchbrew/switch-examples here].&lt;br /&gt;
*&#039;&#039;&#039;5 September 17&#039;&#039;&#039; Nintendo released system update [[3.0.2]].&lt;br /&gt;
*&#039;&#039;&#039;31 July 17&#039;&#039;&#039; Nintendo released system update [[3.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;19 June 17&#039;&#039;&#039; Nintendo released system update [[3.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;15 May 17&#039;&#039;&#039; Nintendo released system update [[2.3.0]].&lt;br /&gt;
*&#039;&#039;&#039;17 April 17&#039;&#039;&#039; Nintendo released system update [[2.2.0]].&lt;br /&gt;
*&#039;&#039;&#039;27 March 17&#039;&#039;&#039; Nintendo released system update [[2.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;2 March 17&#039;&#039;&#039; Nintendo released system update [[2.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;3 March 17&#039;&#039;&#039; Nintendo Switch global release.&lt;/div&gt;</summary>
		<author><name>Yellows8</name></author>
	</entry>
	<entry>
		<id>https://switchbrew.org/w/index.php?title=News&amp;diff=14858</id>
		<title>News</title>
		<link rel="alternate" type="text/html" href="https://switchbrew.org/w/index.php?title=News&amp;diff=14858"/>
		<updated>2026-08-05T23:25:38Z</updated>

		<summary type="html">&lt;p&gt;Yellows8: Undo revision 14853 by Yls8bot (talk)&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;noinclude&amp;gt;&lt;br /&gt;
==Adding an item==&lt;br /&gt;
* Log in to the wiki. Editing is disabled if you don&#039;t have an account.&lt;br /&gt;
* Add the news event to the top of the list, using this format for the date: &amp;lt;tt&amp;gt;&amp;lt;nowiki&amp;gt;&#039;&#039;&#039;&amp;lt;/nowiki&amp;gt;{{#time: d F y}}&amp;lt;nowiki&amp;gt;&#039;&#039;&#039; &amp;lt;/nowiki&amp;gt;&amp;lt;/tt&amp;gt;. Please include the application&#039;s creator, version number, and a link to a page on 3DBrew about the application. No external links please.&lt;br /&gt;
* &#039;&#039;&#039;Move the last entry to the [[:News/Archive|news archive]]. There should be no more than 4 entries in the list.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==Archives==&lt;br /&gt;
For older news, see the [[:News/Archive|news archive]].&lt;br /&gt;
&lt;br /&gt;
=== News ===&lt;br /&gt;
&amp;lt;!-- Add news below --&amp;gt;&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
*&#039;&#039;&#039;16 June 26&#039;&#039;&#039; Nintendo released system update [[22.5.0]].&lt;br /&gt;
*&#039;&#039;&#039;7 April 26&#039;&#039;&#039; Nintendo released system update [[22.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;17 March 26&#039;&#039;&#039; Nintendo released system update [[22.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;20 January 26&#039;&#039;&#039; Nintendo released system update [[19.0.2]] for CHN region.&lt;/div&gt;</summary>
		<author><name>Yellows8</name></author>
	</entry>
	<entry>
		<id>https://switchbrew.org/w/index.php?title=6.0.0&amp;diff=14856</id>
		<title>6.0.0</title>
		<link rel="alternate" type="text/html" href="https://switchbrew.org/w/index.php?title=6.0.0&amp;diff=14856"/>
		<updated>2026-08-05T23:24:46Z</updated>

		<summary type="html">&lt;p&gt;Yellows8: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The Switch 6.0.0 system update was released on September 18, 2018. This Switch update was released for the following regions: ALL.&lt;br /&gt;
&lt;br /&gt;
Security flaws fixed: Yes.&lt;br /&gt;
&lt;br /&gt;
==Change-log==&lt;br /&gt;
[https://en-americas-support.nintendo.com/app/answers/detail/a_id/22525/p/897 Official] ALL change-log:&lt;br /&gt;
* Nintendo Switch Online* features and functionality have been added, including:&lt;br /&gt;
*  Save Data Cloud Backup &lt;br /&gt;
*   &lt;br /&gt;
*    User your internet connection to back up game save data for compatible games&lt;br /&gt;
*    Some games are not compatible with Save Data Cloud&lt;br /&gt;
*    To back up save data or download a previous backup, head to System Settings &amp;amp;gt; Data Management &amp;amp;gt; Save Data Cloud Backup&lt;br /&gt;
*   &lt;br /&gt;
*   *Nintendo Switch Online membership (sold separately) and Nintendo Account required for online play. Not available in all countries. Internet access required for online features. Save Data Cloud backup available in compatible games. Terms apply. To learn more, click here.&lt;br /&gt;
*  &lt;br /&gt;
* Added the following system functionality&lt;br /&gt;
*  Upload up to four Album screenshots at once on supported social network services&lt;br /&gt;
*   &lt;br /&gt;
*    Only one captured video can be uploaded at once&lt;br /&gt;
*   &lt;br /&gt;
*  &lt;br /&gt;
*  Select from six new Captain Toad icons for your user&lt;br /&gt;
*   &lt;br /&gt;
*    To edit your user icon, head to your My Page on the top left of the Home Menu &amp;amp;gt; Profile&lt;br /&gt;
*   &lt;br /&gt;
*  &lt;br /&gt;
*  Play your digital software and content on non-primary consoles by linking your Nintendo Account&lt;br /&gt;
*   &lt;br /&gt;
*    The term &amp;quot;active console&amp;quot; has been renamed &amp;quot;primary console&amp;quot; in Nintendo eShops&lt;br /&gt;
*    Playing software in multiple consoles has certain restrictions&lt;br /&gt;
*   &lt;br /&gt;
*  &lt;br /&gt;
*  Display of Nintendo Switch News articles will be limited to match the restricted software parental controls setting selections&lt;br /&gt;
*   &lt;br /&gt;
*    Please note that the restriction will only apply to News articles distributed after the release of version 6.0.0.&lt;br /&gt;
*   &lt;br /&gt;
*  &lt;br /&gt;
*  Change the layout of the USB keyboard to the desired language&lt;br /&gt;
*   &lt;br /&gt;
*    To change the language, head to the System Settings &amp;amp;gt; System &amp;amp;gt; USB Keyboard &lt;br /&gt;
*   &lt;br /&gt;
*  &lt;br /&gt;
* Removed the following system functionality&lt;br /&gt;
*  After installing the system update, it will no longer be possible to unlink your Nintendo Account from your Nintendo Switch user&lt;br /&gt;
* General system stability improvements to enhance the user&#039;s experience, including:&lt;br /&gt;
*  Compatibility improvements have been made for a controller licensed by Nintendo&lt;br /&gt;
&lt;br /&gt;
==System Titles==&lt;br /&gt;
* All sysmodules were updated.&lt;br /&gt;
* Most 8XX titles were updated.&lt;br /&gt;
* All applets except &amp;quot;error&amp;quot; and &amp;quot;cabinet&amp;quot; were updated.&lt;br /&gt;
* 1 new title was added: olsc-sysmodule.&lt;br /&gt;
* New services were added, see [[Services_API|here]].&lt;br /&gt;
&lt;br /&gt;
[[SSL_services#CertStore|CertStore]] RomFs: &amp;quot;/ssl_CaFingerprints.bdf&amp;quot; was added and &amp;quot;/ssl_TrustedCerts.bdf&amp;quot; was updated.&lt;br /&gt;
&lt;br /&gt;
[[NPDM]] changes (besides usual version-bump):&lt;br /&gt;
* bcat: Service server access: added prepo:a2, removed prepo:a.&lt;br /&gt;
* friends: Service server access: removed nd:app, nd:sys. Service access: added srepo:u, removed ndd. SVC access: added MapTransferMemory, UnmapTransferMemory.&lt;br /&gt;
* nifm: Service access: added arp:r, srepo:u.&lt;br /&gt;
* ptm: Service access: removed fsp-srv.&lt;br /&gt;
* bsdsocket: Service access: added srepo:u.&lt;br /&gt;
* audio: Service server access: added auddev. Service access: added srepo:u.&lt;br /&gt;
* wlan: Service server access: added wlan:dtc. Service access: added lm.&lt;br /&gt;
* ldn: Service server access: removed ndd. Service access: added es.&lt;br /&gt;
* capmtp: Service access: removed fsp-srv.&lt;br /&gt;
* pcie: Service server access: added pcie:log.&lt;br /&gt;
* account: Service access: added srepo:u.&lt;br /&gt;
* ns: Fac.FsAccessFlag updated: set bitmask 0x0000000008000000 (GetRightsId), cleared bitmask 0x0000000010000000 (RegisterExternalKey). Service access: added avm, olsc:s, removed arp:w.&lt;br /&gt;
* psc: Service access: removed fsp-srv.&lt;br /&gt;
* am: Service server access: added caps:su. Service access: added arp:w, olsc:s, srepo:u, removed arp:r.&lt;br /&gt;
* ssl: Service access: added set:sys, erpt:c.&lt;br /&gt;
* vi: Service server access: removed caps:su.&lt;br /&gt;
* pctl: Service access: added srepo:u.&lt;br /&gt;
* npns: Service access: added srepo:u. KernelCap HandleTableSize: updated HandleTableSize = 0x50 -&amp;gt; 0x64.&lt;br /&gt;
* glue: KernelCap HandleTableSize: updated HandleTableSize = 0x80 -&amp;gt; 0x100.&lt;br /&gt;
* eclct: Service access: added bgtc:t, pcie:log.&lt;br /&gt;
* es: Fac.FsAccessFlag updated: set bitmask 0x0000000010000000 (RegisterExternalKey). Service access: added time:u.&lt;br /&gt;
* grc: Service server access: added grc:d.&lt;br /&gt;
* sdb: Service server access: added avm.&lt;br /&gt;
* migration: Service access: added olsc:s.&lt;br /&gt;
* qlaunch: Service access: added banana, olsc:s.&lt;br /&gt;
* auth: Service access: added banana.&lt;br /&gt;
* controller: Service access: added banana.&lt;br /&gt;
* dataErase: Service access: added banana.&lt;br /&gt;
* netConnect: Service access: added banana.&lt;br /&gt;
* playerSelect: Service access: added banana.&lt;br /&gt;
* swkbd: Service access: added banana.&lt;br /&gt;
* miiEdit: Service access: added banana.&lt;br /&gt;
* LibAppletWeb: SystemResourceSize updated: 0x0 -&amp;gt; 0x400000. Service access: added banana. SVC access: added MapPhysicalMemory, UnmapPhysicalMemory.&lt;br /&gt;
* LibAppletShop: SystemResourceSize updated: 0x0 -&amp;gt; 0x400000. Service access: added banana. SVC access: added MapPhysicalMemory, UnmapPhysicalMemory.&lt;br /&gt;
* overlayDisp: Service access: added banana.&lt;br /&gt;
* photoViewer: Service access: added banana.&lt;br /&gt;
* LibAppletOff: SystemResourceSize updated: 0x0 -&amp;gt; 0x400000. Service access: added banana. SVC access: added MapPhysicalMemory, UnmapPhysicalMemory.&lt;br /&gt;
* LibAppletLns: SystemResourceSize updated: 0x0 -&amp;gt; 0x400000. Service access: added banana. SVC access: added MapPhysicalMemory, UnmapPhysicalMemory.&lt;br /&gt;
* LibAppletAuth: SystemResourceSize updated: 0x0 -&amp;gt; 0x400000. Service access: added banana. SVC access: added MapPhysicalMemory, UnmapPhysicalMemory.&lt;br /&gt;
* &amp;quot;starter&amp;quot; application: Service access: added banana.&lt;br /&gt;
* myPage: Service access: added banana.&lt;br /&gt;
* maintenance: Service access: added banana.&lt;br /&gt;
&lt;br /&gt;
=== BootImagePackages ===&lt;br /&gt;
RomFs changes:&lt;br /&gt;
* &amp;quot;/a/bct&amp;quot; updated, &amp;quot;/a/package1&amp;quot; updated, &amp;quot;/nx/bct&amp;quot; updated, &amp;quot;/nx/package1&amp;quot; updated, &amp;quot;/nx/package2&amp;quot; updated&lt;br /&gt;
&lt;br /&gt;
[[Package2|INI1]] changes:&lt;br /&gt;
* BootImagePackage: &lt;br /&gt;
** 0100000000000003 (ProcessMana): SVC access: added GetResourceLimitLimitValue.&lt;br /&gt;
* BootImagePackageSafe: &lt;br /&gt;
** 0100000000000003 (ProcessMana): SVC access: added GetResourceLimitLimitValue.&lt;br /&gt;
* BootImagePackageExFat: &lt;br /&gt;
** 0100000000000003 (ProcessMana): SVC access: added GetResourceLimitLimitValue.&lt;br /&gt;
* BootImagePackageExFatSafe: &lt;br /&gt;
** 0100000000000003 (ProcessMana): SVC access: added GetResourceLimitLimitValue.&lt;br /&gt;
&lt;br /&gt;
====Secure Monitor====&lt;br /&gt;
&lt;br /&gt;
.rwdata was reduced in size from two pages to one page. Additionally:&lt;br /&gt;
&lt;br /&gt;
Changes were made relating to security engine usage:&lt;br /&gt;
* Many functions which previously used an inline GetSecurityEngine() call to get the security engine register address now take in a register base as an argument. This is presumably to facilitate moved Security Engine MMIO on the Mariko SoC.&lt;br /&gt;
* Keyslots 0-8, 0xA, 0xC-0xE now have flags 0x1FF set, and keyslot 0xB now additionally has flags 0x17F set.&lt;br /&gt;
* The Test Vector used to ensure keyslot contents do not change during wake-from-sleep now uses 256-bit AES instead of 128-bit AES (thus the high parts of the keyslot contents are now verified).&lt;br /&gt;
&lt;br /&gt;
Some changes were made to initial SoC setup:&lt;br /&gt;
* Additional magic numbers (0x83 = SKU ID, 0x2 = ?, 0x210 = Tegra 210) are now written into the GPU microcode in DRAM for runtime configuration.&lt;br /&gt;
* The warmboot firmware&#039;s firmware revision magic was changed from 0x6 to 0x87.&lt;br /&gt;
* The GPU microcode carveout setup was moved to later during initialization (after package2 has been fully loaded and verified).&lt;br /&gt;
* The IRAM addresses from which [[BootConfig]] warmboot firmware are loaded were changed.&lt;br /&gt;
&lt;br /&gt;
In addition, there were changes to the [[SMC]] interface:&lt;br /&gt;
&lt;br /&gt;
* SMCs which take in a keyslot parameter have been changed to allow use of up to 6 keyslots instead of 4.&lt;br /&gt;
* smcUnwrapRsaOaepWrappedTitleKey now takes in a &amp;quot;type&amp;quot; parameter, and the kek used in key generation is now selected from an array based on this parameter. (smcUnwrapAesWrappedTitlekey hardcodes type 0.)&lt;br /&gt;
* GetConfig(HardwareType) now returns 4 when it previously would have returned 3.&lt;br /&gt;
&lt;br /&gt;
Additionally, security flaws were addressed in smcCpuSuspend (aiming to further mitigate jamais vu/deja vu):&lt;br /&gt;
&lt;br /&gt;
* The number of devices checked to be held in reset at the time of smcCpuSuspend is called is now greatly increased.&lt;br /&gt;
* BPMP SC7 Entry Firmware is now only started &#039;&#039;after&#039;&#039; the following have been done, instead of before:&lt;br /&gt;
** TZRAM contents have been encrypted and MAC&#039;d with a random AES-256 key&lt;br /&gt;
** The PMC scratch registers where the MAC are stored have been verified not to be read or write-locked.&lt;br /&gt;
** The MAC is written into the PMC scratch registers, which are then write-locked.&lt;br /&gt;
** The PMC scratch registers are verified to have been write-locked.&lt;br /&gt;
** The PMC scratch registers are verified to contain the MAC TZ has written into them.&lt;br /&gt;
** The PMC scratch registers are read-locked.&lt;br /&gt;
** The PMC scratch registers are verified to be both read and write-locked.&lt;br /&gt;
** The BPMP&#039;s firmware is copied from TZRAM into IRAM&lt;br /&gt;
** memcmp(BPMP firmware in IRAM, BPMP firmware in TZRAM, sizeof(BPMP firmware)) is verified to be zero.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
====Kernel====&lt;br /&gt;
* Accidentally exported symbols have been renamed:&lt;br /&gt;
** Namespace &amp;lt;code&amp;gt;nn::kern::ARM64&amp;lt;/code&amp;gt; is now &amp;lt;code&amp;gt;nn::kern::arch::ARM64&amp;lt;/code&amp;gt;&lt;br /&gt;
** Namespace &amp;lt;code&amp;gt;nn::kern::NX&amp;lt;/code&amp;gt; is now &amp;lt;code&amp;gt;nn::kern::board::NX&amp;lt;/code&amp;gt; and now contains the class &amp;lt;code&amp;gt;KSystemControl&amp;lt;/code&amp;gt;&lt;br /&gt;
** &amp;lt;code&amp;gt;ResumeEntry&amp;lt;/code&amp;gt; is now a non-static method of &amp;lt;code&amp;gt;KSystemControl&amp;lt;/code&amp;gt;&lt;br /&gt;
* Kernel now reserves 1024 pages (1MB) of memory in SYSTEM memregion/pool for use by applets (1 at a time) for personal mmheap.&lt;br /&gt;
* Memory regions arrange changed, APPLET has 6MB less in all memory arranges.&lt;br /&gt;
* Maximum number of sessions and events both increased by 100.&lt;br /&gt;
* Kernel mmheap size decreased to 0x10DF000 bytes (was 0x1117000), the both KMemoryBlock pools&#039; capacity is unchanged, but less page tables can be allocated.&lt;br /&gt;
* Kernel now properly reports DRAM size in default reslimit.&lt;br /&gt;
* Two new svcGetInfoTypes: types 21 and 22. These are like type 6 and 7, but without the contiguous, in-security-carveout, personalmmheap allocation.&lt;br /&gt;
* KASLR was changed to invoke smcGetRandomBytes(8) each time, instead of using Mersenne Twister.&lt;br /&gt;
* Another layer of randomization has been added to slabheaps (before, it was just the order of slabheaps): an array of N (= 21 = number of slabheaps) random integers, in range (0, 0x200000) is now constructed, sorted via bubble sort; at each slabheap construction the heap offset is further incremented by &amp;lt;code&amp;gt;array[id+1]-array[id]&amp;lt;/code&amp;gt; , then page rounded.&lt;br /&gt;
* With the exception of KSessionRequest which is not in any KObjectAllocator, all KAutoObject types now use an intrusive rbtree instead of an intrusive list for their KObjectAllocator membership. Comparison key is PID for processes, thread ID for threads, address for others (using a new virtual method).&lt;br /&gt;
* A new anonymous KAutoObject type, which sole purpose is to hold a comparison key, is now used for thread lookup by ID.&lt;br /&gt;
* Breaking changes in svcGetFutureThreadInfo, which has potentially been renamed. Signature and use case have radically changed, it is now: &amp;lt;code&amp;gt;Result svcGetFutureThreadInfo(ThreadInfo *outThreadInfo, u64 *outTid, Handle debugHandle, s64 timeout)&amp;lt;/code&amp;gt;.&lt;br /&gt;
* Huge scheduler force-pause and last thread reporting refactor:&lt;br /&gt;
** Scheduling flags are now u16 and force-pause flags are 3-nibble-long instead of 1.&lt;br /&gt;
** The requirements and mechanism for force-pausing (activity svc, debug, etc.) threads have been considerably simplified:&lt;br /&gt;
*** It used to delay the force-pause after end-of-svc, and used some convoluted mechanism.&lt;br /&gt;
*** The condition is now &amp;amp;quot;a thread is force-pausable iff no thread is waiting for a kernel mutex it is holding&amp;amp;quot;, mechanism is just ORRing scheduling status with force-pause flags now. Appropriate changes have been made to accomodate for this change.&lt;br /&gt;
*** Above mentionned convoluted mechanism has been refactored, too, but remains unused.&lt;br /&gt;
** When the scheduler selects a process&#039;s thread, it now stored the selected thread in an array in the KProcess, for information. It also stores in itself and in array in the selected KProcess the number of times it detected a core being idle before load balancing. Used by BreakDebugProcess.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* All threads created and started in kernel main() are started force-paused with flags=0x100. This fixes the hypotetical case where a compromised KIP would perform gmmuhax and dump the INI1 (which is stored in APPLICATION -- KIPs are only started after all of them have been loaded). They are unpaused after all KIPs have been created.&lt;br /&gt;
* GetThreadContext3 (unprivileged SVC) now dumps TPIDR_EL0.&lt;br /&gt;
* DebugActiveProcess now returns 0xFA01 if an attempt to debug the current process is made -- instead of possibly deadlocking&lt;br /&gt;
* GetDebugThreadContext and SetDebugThreadContext now return 0xF001 if flags &amp;amp;gt; 15. Additionally, their functionality is now restricted to threads that have been force-paused for debug, not just any kind of force-paused threads anymore.&lt;br /&gt;
* ContinueDebugEvent now returns 0xF001 if flags &amp;amp;gt; 15 as well.&lt;br /&gt;
* svcSleepSystem has been refactored. Instead of the initiator thread manually starting the sleep handler threads then storing a weak reference to itself, the handler threads are started in kernel init in main() immediately after their creation, and two mutexes are used: one for the initiator/covering svcSleepSystem, another for the handler threads. This likely fixes an UaF or race condition.&lt;br /&gt;
* If svcReturnFromException passes the exception the KDebug, ie. if the argument errorCode is not 0, and if the latter has DontCatchExceptions set, the process is terminated (unless errorCode is 0x10001).&lt;br /&gt;
* Performance improvements to svcInvalidateProcessDataCache.&lt;br /&gt;
* Redundant calls to smcGetConfig(12) have been reduced (12 calls -&amp;gt; 4 calls) during memory setup&lt;br /&gt;
&lt;br /&gt;
====KIPs====&lt;br /&gt;
All KIPs were updated. Specific diffs for a few sysmodules are below:&lt;br /&gt;
&lt;br /&gt;
=====[[Loader services|Loader]]=====&lt;br /&gt;
* A single null byte stack overflow due to strcat usage was fixed in content path parsing. See [[Switch System Flaws]] for details.&lt;br /&gt;
* System Resource Size ([[NPDM]] +0x14) is now allowed to be non-zero for applets in addition to applications.&lt;br /&gt;
&lt;br /&gt;
=====[[Process Manager services|PM]]=====&lt;br /&gt;
Memory management initialization was greatly changed:&lt;br /&gt;
* PM no longer hardcodes five memory profiles, and no longer calls smcGetConfig to determine which profile to use.&lt;br /&gt;
* Instead, PM now uses [[SVC|svcGetResourceLimitLimitValue]] to determine how much space the kernel has allotted for Application + Applet regions and [[SVC|svcGetSystemInfo]] to determine the total physical memory available, and sets the System region size to (Total Memory Size - Application region size - Applet region size - 5 MiB).&lt;br /&gt;
&lt;br /&gt;
===[[USB_services|USB-sysmodule]]===&lt;br /&gt;
The only sysmodule with any changes for accessible IO in the [[NPDM]] was USB-sysmodule. The IO page for the [[Fuses|fuse registers]] is now accessible by this sysmodule.&lt;br /&gt;
&lt;br /&gt;
===[[NV_services|nvservices-sysmodule]]===&lt;br /&gt;
Among various changes, the [[Switch_System_Flaws#System_Modules|&amp;quot;Transfer Memory leak in nvservices system module&amp;quot;]] system flaw was patched in the following way:&lt;br /&gt;
* [[NV_services#Initialize|Initialize]] and [[NV_services#InitializeDevtools|InitializeDevtools]] now keep track of the size of the transfer memory supplied by the user.&lt;br /&gt;
* L_34B90 (nvdrv&#039;s destructor) now calls L_B4C30 (memset) on the entire transfer memory region (using the size saved previously) before calling [[SVC#svcUnmapTransferMemory|svcUnmapTransferMemory]].&lt;br /&gt;
&lt;br /&gt;
===olsc-sysmodule===&lt;br /&gt;
This new sysmodule handles cloud saves.&lt;br /&gt;
&lt;br /&gt;
==See Also==&lt;br /&gt;
System update report(s):&lt;br /&gt;
* [https://yls8.mtheall.com/ninupdates/reports.php?date=09-18-18_08-35-09&amp;amp;sys=hac]&lt;br /&gt;
&lt;br /&gt;
{{NavboxVersions}}&lt;br /&gt;
&lt;br /&gt;
[[Category:System versions]]&lt;/div&gt;</summary>
		<author><name>Yellows8</name></author>
	</entry>
	<entry>
		<id>https://switchbrew.org/w/index.php?title=News/Archive&amp;diff=14833</id>
		<title>News/Archive</title>
		<link rel="alternate" type="text/html" href="https://switchbrew.org/w/index.php?title=News/Archive&amp;diff=14833"/>
		<updated>2026-08-05T22:39:00Z</updated>

		<summary type="html">&lt;p&gt;Yellows8: Undo revision 14831 by Yls8bot (talk)&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*&#039;&#039;&#039;13 January 26&#039;&#039;&#039; Nintendo released system update [[21.2.0]].&lt;br /&gt;
*&#039;&#039;&#039;9 December 25&#039;&#039;&#039; Nintendo released system update [[21.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;25 November 25&#039;&#039;&#039; Nintendo released system update [[21.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;11 November 25&#039;&#039;&#039; Nintendo released system update [[21.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;30 September 25&#039;&#039;&#039; Nintendo released system update [[20.5.0]].&lt;br /&gt;
*&#039;&#039;&#039;2 September 25&#039;&#039;&#039; Nintendo released system update [[20.4.0]].&lt;br /&gt;
*&#039;&#039;&#039;29 July 25&#039;&#039;&#039; Nintendo released system update [[20.3.0]].&lt;br /&gt;
*&#039;&#039;&#039;15 July 25&#039;&#039;&#039; Nintendo released system update [[20.2.0]].&lt;br /&gt;
*&#039;&#039;&#039;19 June 25&#039;&#039;&#039; Nintendo released system update [[20.1.5]].&lt;br /&gt;
*&#039;&#039;&#039;3 June 25&#039;&#039;&#039; Nintendo released system update [[20.1.1]].&lt;br /&gt;
*&#039;&#039;&#039;28 May 25&#039;&#039;&#039; Nintendo released system update [[20.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;2 May 25&#039;&#039;&#039; Nintendo released system update [[20.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;30 April 25&#039;&#039;&#039; Nintendo released system update [[20.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;7 January 25&#039;&#039;&#039; Nintendo released a rebootless system update for [[19.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;29 October 24&#039;&#039;&#039; Nintendo released system update [[19.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;8 October 24&#039;&#039;&#039; Nintendo released system update [[19.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;2 July 24&#039;&#039;&#039; Nintendo released a rebootless system update for [[18.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;11 June 24&#039;&#039;&#039; Nintendo released system update [[18.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;23 April 24&#039;&#039;&#039; Nintendo released system update [[18.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;26 March 24&#039;&#039;&#039; Nintendo released system update [[18.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;20 February 24&#039;&#039;&#039; Nintendo released a rebootless system update for [[17.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;5 December 23&#039;&#039;&#039; Nintendo released system update [[17.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;21 November 23&#039;&#039;&#039; Nintendo released a rebootless system update for [[17.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;11 October 23&#039;&#039;&#039; Nintendo released system update [[17.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;22 August 23&#039;&#039;&#039; Nintendo released system update [[16.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;9 May 23&#039;&#039;&#039; Nintendo released system update [[16.0.3]].&lt;br /&gt;
*&#039;&#039;&#039;18 April 23&#039;&#039;&#039; Nintendo released system update [[16.0.2]].&lt;br /&gt;
*&#039;&#039;&#039;23 March 23&#039;&#039;&#039; Nintendo released system update [[16.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;21 February 23&#039;&#039;&#039; Nintendo released system update [[16.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;1 November 22&#039;&#039;&#039; Nintendo released system update [[15.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;11 October 22&#039;&#039;&#039; Nintendo released system update [[15.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;14 June 22&#039;&#039;&#039; Nintendo released system update [[14.1.2]].&lt;br /&gt;
*&#039;&#039;&#039;19 April 22&#039;&#039;&#039; Nintendo released system update [[14.1.1]].&lt;br /&gt;
*&#039;&#039;&#039;5 April 22&#039;&#039;&#039; Nintendo released system update [[14.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;22 March 22&#039;&#039;&#039; Nintendo released system update [[14.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;20 January 22&#039;&#039;&#039; Nintendo released system update [[13.2.1]].&lt;br /&gt;
*&#039;&#039;&#039;1 December 21&#039;&#039;&#039; Nintendo released system update [[13.2.0]].&lt;br /&gt;
*&#039;&#039;&#039;26 October 21&#039;&#039;&#039; Nintendo released system update [[13.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;15 September 21&#039;&#039;&#039; Nintendo released system update [[13.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;6 July 21&#039;&#039;&#039; Nintendo released system update [[12.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;12 June 21&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=9226&amp;amp;p=17113#p17113 libnx v4.1.0 released].&lt;br /&gt;
*&#039;&#039;&#039;8 June 21&#039;&#039;&#039; Nintendo released system update [[12.0.3]].&lt;br /&gt;
*&#039;&#039;&#039;12 May 21&#039;&#039;&#039; Nintendo released system update [[12.0.2]].&lt;br /&gt;
*&#039;&#039;&#039;20 April 21&#039;&#039;&#039; Nintendo released system update [[12.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;9 March 21&#039;&#039;&#039; Nintendo released system update [[12.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;11 December 20&#039;&#039;&#039; Nintendo released system update [[11.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;1 December 20&#039;&#039;&#039; Nintendo released system update [[11.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;15 September 20&#039;&#039;&#039; Nintendo released system update [[10.2.0]].&lt;br /&gt;
*&#039;&#039;&#039;28 July 20&#039;&#039;&#039; Nintendo released system update [[10.1.1]].&lt;br /&gt;
*&#039;&#039;&#039;14 July 20&#039;&#039;&#039; Nintendo released system update [[10.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;5 June 20&#039;&#039;&#039; Nintendo released system update [[10.0.4]].&lt;br /&gt;
*&#039;&#039;&#039;26 May 20&#039;&#039;&#039; Nintendo released system update [[10.0.3]].&lt;br /&gt;
*&#039;&#039;&#039;11 May 20&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=9058 devkitA64 r15, libnx v3.2.0, deko3d v0.2.0, switch-examples v20200511] and [https://github.com/switchbrew/nx-hbloader/releases/tag/v2.3.2 nx-hbloader v2.3.2] released.&lt;br /&gt;
*&#039;&#039;&#039;30 April 20&#039;&#039;&#039; Nintendo released system update [[10.0.2]].&lt;br /&gt;
*&#039;&#039;&#039;22 April 20&#039;&#039;&#039; Nintendo released system update [[10.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;14 April 20&#039;&#039;&#039; Nintendo released system update [[10.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;4 April 20&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=9035 libnx v3.1.0, switch-examples v20200404 and deko3d v0.1.0 released]. On the 6th nx-hbmenu v3.3.0 was [https://github.com/switchbrew/nx-hbmenu/releases/latest released].&lt;br /&gt;
*&#039;&#039;&#039;2 April 20&#039;&#039;&#039; [https://github.com/switchbrew/nssu-updater nssu-updater] and [https://github.com/switchbrew/contents-delivery-manager contents-delivery-manager] were released.&lt;br /&gt;
*&#039;&#039;&#039;3 March 20&#039;&#039;&#039; Nintendo released system update [[9.2.0]].&lt;br /&gt;
*&#039;&#039;&#039;10 December 19&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8989 libnx v3.0.0, switch-examples v20191211, Atmosphère v0.10.1, nx-hbmenu v3.2.0, and nx-hbloader v2.3.0 released].&lt;br /&gt;
*&#039;&#039;&#039;4 December 19&#039;&#039;&#039; Nintendo released system update [[9.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;30 September 19&#039;&#039;&#039; Nintendo released system update [[9.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;14 September 19&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8964 libnx v2.5.0 and switch-examples v20190914 released]. nx-hbmenu v3.1.1 [https://github.com/switchbrew/nx-hbmenu/releases/tag/v3.1.1 released]. [https://github.com/Atmosphere-NX/Atmosphere/releases/tag/0.9.4 Atmosphère 0.9.4 released with support for 9.0.0].&lt;br /&gt;
*&#039;&#039;&#039;9 September 19&#039;&#039;&#039; Nintendo released system update [[9.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;10 July 19&#039;&#039;&#039; Nintendo [https://twitter.com/NintendoAmerica/status/1148934589026455552 announced] the Nintendo Switch Lite system.&lt;br /&gt;
*&#039;&#039;&#039;17 June 19&#039;&#039;&#039; Nintendo released system update [[8.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;1 May 19&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8908 libnx v2.2.0 and switch-examples v20190501] released.&lt;br /&gt;
*&#039;&#039;&#039;23 April 19&#039;&#039;&#039; Nintendo released system update [[8.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;15 April 19&#039;&#039;&#039; Nintendo released system update [[8.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;29 March 19&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8891 devkitA64 r13] and [https://github.com/switchbrew/libnx/releases/tag/v2.1.0 libnx v2.1.0] released with pthread/std::thread support.&lt;br /&gt;
*&#039;&#039;&#039;26 March 19&#039;&#039;&#039; [https://github.com/Atmosphere-NX/Atmosphere/releases/tag/0.8.6 Atmosphère v0.8.6] released with lots of bugfixes, more cheat stuff and web applet homebrew support.&lt;br /&gt;
*&#039;&#039;&#039;21 February 19&#039;&#039;&#039; [https://github.com/Atmosphere-NX/Atmosphere/releases/tag/0.8.4 Atmosphère v0.8.4] released with 7.0.x support.&lt;br /&gt;
*&#039;&#039;&#039;18 February 19&#039;&#039;&#039; Nintendo released system update [[7.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;28 January 19&#039;&#039;&#039; Nintendo released system update [[7.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;24 January 19&#039;&#039;&#039; [https://github.com/Atmosphere-NX/Atmosphere/releases/tag/0.8.3 Atmosphère v0.8.3] and [https://github.com/switchbrew/nx-hbloader/releases/tag/v2.1.0 nx-hbloader v2.1.0] were released.&lt;br /&gt;
*&#039;&#039;&#039;2 January 19&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8826 libnx 2.0.0, switch-mesa 18.3 and switch-examples 20190102] were released.&lt;br /&gt;
*&#039;&#039;&#039;29 November 18&#039;&#039;&#039; [https://github.com/Atmosphere-NX/Atmosphere/releases/tag/0.8.0 Atmosphère v0.8.0] was released.&lt;br /&gt;
*&#039;&#039;&#039;29 November 18&#039;&#039;&#039; [https://github.com/switchbrew/nx-hbmenu/releases/latest nx-hbmenu v3.0.1] was released.&lt;br /&gt;
*&#039;&#039;&#039;28 November 18&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8813 libnx 1.6.0 and switch-examples 20181128] were released.&lt;br /&gt;
*&#039;&#039;&#039;19 November 18&#039;&#039;&#039; Nintendo released system update [[6.2.0]].&lt;br /&gt;
*&#039;&#039;&#039;31 October 18&#039;&#039;&#039; [https://github.com/switchbrew/nx-hbloader/releases/tag/v2.0.1 nx-hbloader v2.0.1] was released.&lt;br /&gt;
*&#039;&#039;&#039;29 October 18&#039;&#039;&#039; [https://github.com/switchbrew/nx-hbmenu/releases/latest nx-hbmenu] v3.0.0 was released.&lt;br /&gt;
*&#039;&#039;&#039;29 October 18&#039;&#039;&#039; Nintendo released system update [[6.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;27 October 18&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8798 libnx 1.5.0 and switch-examples 20181027] were released.&lt;br /&gt;
*&#039;&#039;&#039;17 October 18&#039;&#039;&#039; [https://github.com/Atmosphere-NX/Atmosphere/releases/tag/0.7.0 Atmosphère v0.7.0] and [https://github.com/switchbrew/nx-hbloader/releases/tag/v2.0.0 nx-hbloader v2.0.0] were released.&lt;br /&gt;
*&#039;&#039;&#039;8 October 18&#039;&#039;&#039; Nintendo released system update [[6.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;18 September 18&#039;&#039;&#039; Nintendo released system update [[6.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;18 September 18&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8784  libnx 1.4.1, switch-mesa v18.2β and switch-examples 20180918] were released.&lt;br /&gt;
*&#039;&#039;&#039;9 September 18&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8780 libnx v1.4.0] was released alongside a Switch port of mesa/nouveau (GPU library).&lt;br /&gt;
*&#039;&#039;&#039;28 July 18&#039;&#039;&#039; [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8761 devkitA64] r12 and [https://github.com/switchbrew/libnx/releases/tag/v1.3.1 libnx] v1.3.1 were released.&lt;br /&gt;
*&#039;&#039;&#039;8 July 18&#039;&#039;&#039; [https://github.com/switchbrew/libnx/releases/tag/v1.3.0 libnx] v1.3.0 was released.&lt;br /&gt;
*&#039;&#039;&#039;30 May 18&#039;&#039;&#039; Nintendo released system update [[5.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;16 April 18&#039;&#039;&#039; Nintendo released system update [[5.0.2]].&lt;br /&gt;
*&#039;&#039;&#039;26 March 18&#039;&#039;&#039; Nintendo released system update [[5.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;12 March 18&#039;&#039;&#039; Nintendo released system update [[5.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;2 March 18&#039;&#039;&#039; [https://github.com/switchbrew/libnx/releases/tag/v1.1.0 libnx] v1.1.0 was released.&lt;br /&gt;
*&#039;&#039;&#039;28 February 18&#039;&#039;&#039; [https://github.com/switchbrew/nx-hbmenu/releases/latest nx-hbmenu] v2.0.0 was released.&lt;br /&gt;
*&#039;&#039;&#039;22 February 18&#039;&#039;&#039; [http://devkitpro.org devkitPro] released [https://devkitpro.org/viewtopic.php?f=13&amp;amp;t=8693 devkitA64 alpha7]&lt;br /&gt;
*&#039;&#039;&#039;18 February 18&#039;&#039;&#039; [https://switchbrew.github.io/nx-hbl/ nx-hbl] and [https://github.com/switchbrew/nx-hbmenu nx-hbmenu] were released.&lt;br /&gt;
*&#039;&#039;&#039;28 December 17&#039;&#039;&#039; The 34c3 Switch [https://events.ccc.de/congress/2017/Fahrplan/events/8941.html talk] took place, video available [https://media.ccc.de/v/34c3-8941-console_security_-_switch here].&lt;br /&gt;
*&#039;&#039;&#039;4 December 17&#039;&#039;&#039; Nintendo released system update [[4.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;25 October 17&#039;&#039;&#039; Nintendo released system update [[4.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;18 October 17&#039;&#039;&#039; Nintendo released system update [[4.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;17 September 17&#039;&#039;&#039; [https://github.com/switchbrew/libnx libnx] was made public, with examples available [https://github.com/switchbrew/switch-examples here].&lt;br /&gt;
*&#039;&#039;&#039;5 September 17&#039;&#039;&#039; Nintendo released system update [[3.0.2]].&lt;br /&gt;
*&#039;&#039;&#039;31 July 17&#039;&#039;&#039; Nintendo released system update [[3.0.1]].&lt;br /&gt;
*&#039;&#039;&#039;19 June 17&#039;&#039;&#039; Nintendo released system update [[3.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;15 May 17&#039;&#039;&#039; Nintendo released system update [[2.3.0]].&lt;br /&gt;
*&#039;&#039;&#039;17 April 17&#039;&#039;&#039; Nintendo released system update [[2.2.0]].&lt;br /&gt;
*&#039;&#039;&#039;27 March 17&#039;&#039;&#039; Nintendo released system update [[2.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;2 March 17&#039;&#039;&#039; Nintendo released system update [[2.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;3 March 17&#039;&#039;&#039; Nintendo Switch global release.&lt;/div&gt;</summary>
		<author><name>Yellows8</name></author>
	</entry>
	<entry>
		<id>https://switchbrew.org/w/index.php?title=News&amp;diff=14832</id>
		<title>News</title>
		<link rel="alternate" type="text/html" href="https://switchbrew.org/w/index.php?title=News&amp;diff=14832"/>
		<updated>2026-08-05T22:38:43Z</updated>

		<summary type="html">&lt;p&gt;Yellows8: Undo revision 14830 by Yls8bot (talk)&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;noinclude&amp;gt;&lt;br /&gt;
==Adding an item==&lt;br /&gt;
* Log in to the wiki. Editing is disabled if you don&#039;t have an account.&lt;br /&gt;
* Add the news event to the top of the list, using this format for the date: &amp;lt;tt&amp;gt;&amp;lt;nowiki&amp;gt;&#039;&#039;&#039;&amp;lt;/nowiki&amp;gt;{{#time: d F y}}&amp;lt;nowiki&amp;gt;&#039;&#039;&#039; &amp;lt;/nowiki&amp;gt;&amp;lt;/tt&amp;gt;. Please include the application&#039;s creator, version number, and a link to a page on 3DBrew about the application. No external links please.&lt;br /&gt;
* &#039;&#039;&#039;Move the last entry to the [[:News/Archive|news archive]]. There should be no more than 4 entries in the list.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==Archives==&lt;br /&gt;
For older news, see the [[:News/Archive|news archive]].&lt;br /&gt;
&lt;br /&gt;
=== News ===&lt;br /&gt;
&amp;lt;!-- Add news below --&amp;gt;&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
*&#039;&#039;&#039;16 June 26&#039;&#039;&#039; Nintendo released system update [[22.5.0]].&lt;br /&gt;
*&#039;&#039;&#039;7 April 26&#039;&#039;&#039; Nintendo released system update [[22.1.0]].&lt;br /&gt;
*&#039;&#039;&#039;17 March 26&#039;&#039;&#039; Nintendo released system update [[22.0.0]].&lt;br /&gt;
*&#039;&#039;&#039;20 January 26&#039;&#039;&#039; Nintendo released system update [[19.0.2]] for CHN region.&lt;/div&gt;</summary>
		<author><name>Yellows8</name></author>
	</entry>
	<entry>
		<id>https://switchbrew.org/w/index.php?title=LDN_services&amp;diff=14824</id>
		<title>LDN services</title>
		<link rel="alternate" type="text/html" href="https://switchbrew.org/w/index.php?title=LDN_services&amp;diff=14824"/>
		<updated>2026-07-29T18:06:13Z</updated>

		<summary type="html">&lt;p&gt;Yellows8: /* Protocol */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;LDN handles all local network communication.&lt;br /&gt;
&lt;br /&gt;
There&#039;s 2 IPC handler threads for all ldn:* services.&lt;br /&gt;
&lt;br /&gt;
= ldn:m =&lt;br /&gt;
This is &amp;quot;nn::ldn::detail::IMonitorServiceCreator&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This has IPC max_sessions 5.&lt;br /&gt;
&lt;br /&gt;
[20.2.0+] This has max_sessions 6. &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#CreateMonitorService|CreateMonitorService]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== CreateMonitorService ==&lt;br /&gt;
Returns an [[#IMonitorService]].&lt;br /&gt;
&lt;br /&gt;
The user-process closes the IMonitorServiceCreator object immediately after using this cmd.&lt;br /&gt;
&lt;br /&gt;
== IMonitorService ==&lt;br /&gt;
This is &amp;quot;nn::ldn::detail::IMonitorService&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#GetState|GetState]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#GetNetworkInfo|GetNetworkInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [[#GetIpv4Address|GetIpv4Address]]&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [[#GetDisconnectReason|GetDisconnectReason]]&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [[#GetSecurityParameter|GetSecurityParameter]]&lt;br /&gt;
|-&lt;br /&gt;
| 5 || [[#GetNetworkConfig|GetNetworkConfig]]&lt;br /&gt;
|-&lt;br /&gt;
| 100 || [[#Initialize]]&lt;br /&gt;
|-&lt;br /&gt;
| 101 || [[#Finalize]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== GetState ===&lt;br /&gt;
No input, returns an output [[#State|u32]].&lt;br /&gt;
&lt;br /&gt;
sdknso implements this by &amp;lt;code&amp;gt;return&amp;lt;/code&amp;gt;ing the u32, with 0 being returned on error.&lt;br /&gt;
&lt;br /&gt;
=== GetNetworkInfo ===&lt;br /&gt;
Takes a type-0x1A output buffer containing a [[#NetworkInfo]].&lt;br /&gt;
&lt;br /&gt;
=== GetIpv4Address ===&lt;br /&gt;
No input, returns an output [[#Ipv4Address]] and a [[#SubnetMask]].&lt;br /&gt;
&lt;br /&gt;
=== GetDisconnectReason ===&lt;br /&gt;
No input, returns an output s16.&lt;br /&gt;
&lt;br /&gt;
This is not exposed by sdknso.&lt;br /&gt;
&lt;br /&gt;
This just returns 0.&lt;br /&gt;
&lt;br /&gt;
=== GetSecurityParameter ===&lt;br /&gt;
No input, returns an output [[#SecurityParameter]].&lt;br /&gt;
&lt;br /&gt;
This is not exposed by sdknso.&lt;br /&gt;
&lt;br /&gt;
=== GetNetworkConfig ===&lt;br /&gt;
No input, returns an output [[#NetworkConfig]].&lt;br /&gt;
&lt;br /&gt;
This is not exposed by sdknso.&lt;br /&gt;
&lt;br /&gt;
=== Initialize ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
This is used immediately after object creation. Official sw will Abort if this fails.&lt;br /&gt;
&lt;br /&gt;
This just returns 0.&lt;br /&gt;
&lt;br /&gt;
=== Finalize ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
This is used during service exit, prior to closing the object. Official sw will Abort if this fails.&lt;br /&gt;
&lt;br /&gt;
This just returns 0.&lt;br /&gt;
&lt;br /&gt;
= ldn:s =&lt;br /&gt;
This is &amp;quot;nn::ldn::detail::ISystemServiceCreator&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This has IPC max_sessions 5.&lt;br /&gt;
&lt;br /&gt;
[18.0.0+] The sdknso uses SessionManager with this, where the additional session-count is 0x3.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#CreateSystemLocalCommunicationService|CreateSystemLocalCommunicationService]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [18.0.0+] [[#CreateClientProcessMonitor|CreateClientProcessMonitor]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== CreateSystemLocalCommunicationService ==&lt;br /&gt;
No input. Returns an [[#ISystemLocalCommunicationService]].&lt;br /&gt;
&lt;br /&gt;
The user-process closes the ISystemServiceCreator object once finished with it during initialization. Official sw ignores errors from this cmd.&lt;br /&gt;
&lt;br /&gt;
== CreateClientProcessMonitor ==&lt;br /&gt;
No input. Returns an [[#IClientProcessMonitor]].&lt;br /&gt;
&lt;br /&gt;
== ISystemLocalCommunicationService ==&lt;br /&gt;
This is &amp;quot;nn::ldn::detail::ISystemLocalCommunicationService&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#GetState_2|GetState]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#GetNetworkInfo_2|GetNetworkInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [[#GetIpv4Address_2|GetIpv4Address]]&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [[#GetDisconnectReason_2|GetDisconnectReason]]&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [[#GetSecurityParameter_2|GetSecurityParameter]]&lt;br /&gt;
|-&lt;br /&gt;
| 5 || [[#GetNetworkConfig_2|GetNetworkConfig]]&lt;br /&gt;
|-&lt;br /&gt;
| 100 || [[#GetStateChangeEvent|GetStateChangeEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 101 || [[#GetNetworkInfoAndHistory|GetNetworkInfoAndHistory]]&lt;br /&gt;
|-&lt;br /&gt;
| 102 || [[#Scan|Scan]]&lt;br /&gt;
|-&lt;br /&gt;
| 103 || [[#ScanPrivate|ScanPrivate]]&lt;br /&gt;
|-&lt;br /&gt;
| 104 || [5.0.0+] [[#SetWirelessControllerPolicy|SetWirelessControllerPolicy]]&lt;br /&gt;
|-&lt;br /&gt;
| 105 || [13.1.0+] [[#SetWirelessAudioPolicy|SetWirelessAudioPolicy]]&lt;br /&gt;
|-&lt;br /&gt;
| 106 || [18.0.0+] [[#SetProtocol|SetProtocol]]&lt;br /&gt;
|-&lt;br /&gt;
| 200 || [[#OpenAccessPoint|OpenAccessPoint]]&lt;br /&gt;
|-&lt;br /&gt;
| 201 || [[#CloseAccessPoint|CloseAccessPoint]]&lt;br /&gt;
|-&lt;br /&gt;
| 202 || [[#CreateNetwork|CreateNetwork]]&lt;br /&gt;
|-&lt;br /&gt;
| 203 || [[#CreateNetworkPrivate|CreateNetworkPrivate]]&lt;br /&gt;
|-&lt;br /&gt;
| 204 || [[#DestroyNetwork|DestroyNetwork]]&lt;br /&gt;
|-&lt;br /&gt;
| 205 || [[#Reject|Reject]]&lt;br /&gt;
|-&lt;br /&gt;
| 206 || [[#SetAdvertiseData|SetAdvertiseData]]&lt;br /&gt;
|-&lt;br /&gt;
| 207 || [[#SetStationAcceptPolicy|SetStationAcceptPolicy]]&lt;br /&gt;
|-&lt;br /&gt;
| 208 || [[#AddAcceptFilterEntry|AddAcceptFilterEntry]]&lt;br /&gt;
|-&lt;br /&gt;
| 209 || [[#ClearAcceptFilter|ClearAcceptFilter]]&lt;br /&gt;
|-&lt;br /&gt;
| 300 || [[#OpenStation|OpenStation]]&lt;br /&gt;
|-&lt;br /&gt;
| 301 || [[#CloseStation|CloseStation]]&lt;br /&gt;
|-&lt;br /&gt;
| 302 || [[#Connect|Connect]]&lt;br /&gt;
|-&lt;br /&gt;
| 303 || [[#ConnectPrivate|ConnectPrivate]]&lt;br /&gt;
|-&lt;br /&gt;
| 304 || [[#Disconnect|Disconnect]]&lt;br /&gt;
|-&lt;br /&gt;
| 400 || [[#Initialize_2|Initialize]]&lt;br /&gt;
|-&lt;br /&gt;
| 401 || [[#Finalize_2|Finalize]]&lt;br /&gt;
|-&lt;br /&gt;
| 402 || [4.0.0+] [[#SetOperationMode|SetOperationMode]]&lt;br /&gt;
|-&lt;br /&gt;
| 403 || [7.0.0+] [[#InitializeWithVersion|InitializeWithVersion]]&lt;br /&gt;
|-&lt;br /&gt;
| 404 || [19.0.0+] [[#InitializeWithPriority|InitializeWithPriority]]&lt;br /&gt;
|-&lt;br /&gt;
| 500 || [18.0.0+] [[#EnableActionFrame|EnableActionFrame]]&lt;br /&gt;
|-&lt;br /&gt;
| 501 || [18.0.0+] [[#DisableActionFrame|DisableActionFrame]]&lt;br /&gt;
|-&lt;br /&gt;
| 502 || [18.0.0+] [[#SendActionFrame|SendActionFrame]]&lt;br /&gt;
|-&lt;br /&gt;
| 503 || [18.0.0+] [[#RecvActionFrame|RecvActionFrame]]&lt;br /&gt;
|-&lt;br /&gt;
| 505 || [18.0.0+] [[#SetHomeChannel|SetHomeChannel]]&lt;br /&gt;
|-&lt;br /&gt;
| 600 || [18.0.0+] [[#SetTxPower|SetTxPower]]&lt;br /&gt;
|-&lt;br /&gt;
| 601 || [18.0.0+] [[#ResetTxPower|ResetTxPower]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== GetState ===&lt;br /&gt;
No input, returns an output [[#State]].&lt;br /&gt;
&lt;br /&gt;
sdknso implements this by &amp;lt;code&amp;gt;return&amp;lt;/code&amp;gt;ing the u32, with 0 being returned on error / when service isn&#039;t initialized.&lt;br /&gt;
&lt;br /&gt;
=== GetNetworkInfo ===&lt;br /&gt;
Takes a type-0x1A output buffer containing a [[#NetworkInfo]].&lt;br /&gt;
&lt;br /&gt;
[[#GetState|State]] must be 3 or 5.&lt;br /&gt;
&lt;br /&gt;
=== GetIpv4Address ===&lt;br /&gt;
No input, returns an output [[#Ipv4Address]] and a [[#SubnetMask]].&lt;br /&gt;
&lt;br /&gt;
=== GetDisconnectReason ===&lt;br /&gt;
No input, returns an output [[#DisconnectReason]].&lt;br /&gt;
&lt;br /&gt;
sdknso implements this by &amp;lt;code&amp;gt;return&amp;lt;/code&amp;gt;ing the s16 as a s32, with -1 being returned on error.&lt;br /&gt;
&lt;br /&gt;
=== GetSecurityParameter ===&lt;br /&gt;
No input, returns an output [[#SecurityParameter]].&lt;br /&gt;
&lt;br /&gt;
=== GetNetworkConfig ===&lt;br /&gt;
No input, returns an output [[#NetworkConfig]].&lt;br /&gt;
&lt;br /&gt;
=== GetStateChangeEvent ===&lt;br /&gt;
No input, returns an output Event handle.&lt;br /&gt;
&lt;br /&gt;
sdknso uses EventClearMode=1 with this. sdknso will Abort if this cmd fails.&lt;br /&gt;
&lt;br /&gt;
This is signaled when the data returned by [[#GetNetworkInfo]]/[[#GetNetworkInfoAndHistory]] is updated.&lt;br /&gt;
&lt;br /&gt;
=== GetNetworkInfoAndHistory ===&lt;br /&gt;
Takes a type-0x1A output buffer containing a [[#NetworkInfo]] and a type-0xA output buffer containing an array of [[#NodeLatestUpdate]].&lt;br /&gt;
&lt;br /&gt;
The array count must be 8.&lt;br /&gt;
&lt;br /&gt;
=== Scan ===&lt;br /&gt;
Takes a type-0x22 output buffer containing an array of [[#NetworkInfo]], a s16 channel, a [[#ScanFilter]], returns an output s16 total_out.&lt;br /&gt;
&lt;br /&gt;
sdknso copies the output s16 to a s32, the value passed for the input s16 is from an user-specified s32 (user-apps generally use value 0 for this).&lt;br /&gt;
&lt;br /&gt;
This is the same as [[#ScanPrivate]], except this also has the same channel-override functionality as [[#CreateNetwork]].&lt;br /&gt;
&lt;br /&gt;
[[#GetState|State]] must be 3-5.&lt;br /&gt;
&lt;br /&gt;
The array count must be at least 1. This is clamped to a maximum of 0x18.&lt;br /&gt;
&lt;br /&gt;
=== ScanPrivate ===&lt;br /&gt;
Takes a type-0x22 output buffer containing an array of [[#NetworkInfo]], a s16 channel, a [[#ScanFilter]], returns an output s16 total_out.&lt;br /&gt;
&lt;br /&gt;
sdknso copies the output s16 to a s32, the value passed for the input s16 is from an user-specified s32.&lt;br /&gt;
&lt;br /&gt;
See [[#Scan]].&lt;br /&gt;
&lt;br /&gt;
=== SetWirelessControllerPolicy ===&lt;br /&gt;
Takes an input [[#WirelessControllerRestriction]], no output.&lt;br /&gt;
&lt;br /&gt;
[[#GetState|State]] must be 1.&lt;br /&gt;
&lt;br /&gt;
The input value is written into state.&lt;br /&gt;
&lt;br /&gt;
=== SetWirelessAudioPolicy ===&lt;br /&gt;
Takes an input [[#BluetoothAudioDeviceConnectableMode]], no output.&lt;br /&gt;
&lt;br /&gt;
=== SetProtocol ===&lt;br /&gt;
Takes an input [[#Protocol|u32]], no output.&lt;br /&gt;
&lt;br /&gt;
This cmd was implemented with [20.0.0+], prior to that this just returned an error.&lt;br /&gt;
&lt;br /&gt;
The sdk user-process func will pass value 1 (2 on Ounce) to the cmd when the input [[#Protocol|Protocol]] is 0, valid values passed directly when recognized, otherwise Abort. User-processes use SetProtocol immediately after initializing ldn.&lt;br /&gt;
&lt;br /&gt;
[20.0.0+] The ldn initialization functionality in sdknso also uses this with value 1 (NX) eventually after the init cmd was used successfully.&lt;br /&gt;
&lt;br /&gt;
The input is validated, then a vfunc is called.&lt;br /&gt;
&lt;br /&gt;
The cmd_input must be non-zero. BIT(cmd_input) must be set in a state-field, otherwise a separate Result is returned. This is a permission [[#Protocol|bitmask]] which originates from the ldn:* service object being used.&lt;br /&gt;
&lt;br /&gt;
The vfunc sends a message to another thread with the input u32 as the param, and returns the response from that.&lt;br /&gt;
&lt;br /&gt;
The thread msg-queue-handler (besides other validation) uses the input param to select what values to write to state fields. On NX only input value 1 or 3 is allowed, with an error being thrown otherwise. The previously mentioned validation includes verifying that [[#GetState|State]] is Initialized.&lt;br /&gt;
&lt;br /&gt;
=== OpenAccessPoint ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
[[#GetState|State]] must be 1, this cmd eventually sets the State to value 2.&lt;br /&gt;
&lt;br /&gt;
=== CloseAccessPoint ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
[[#GetState|State]] must be 2-3, this cmd eventually sets the State to value 1.&lt;br /&gt;
&lt;br /&gt;
=== CreateNetwork ===&lt;br /&gt;
Takes an input [[#SecurityConfig]], an [[#UserConfig]], a [[#NetworkConfig]], no output.&lt;br /&gt;
&lt;br /&gt;
This is the same as [[#CreateNetworkPrivate]], except the [[#AddressEntry]] params are 0, and the [[#SecurityParameter]] is generated from &amp;quot;nn::util::TinyMt::GenerateRandomBytes&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
Unlike CreateNetworkPrivate, this overwrites the channel field in the [[#NetworkConfig]]. When the cached [[SPL_services#IsDevelopment|IsDevelopment]] value is true, the output from [[Settings_services|GetLdnChannel]] will overwrite that field if the s32 setting value is &amp;gt;=0, otherwise the original value is used. Otherwise when the IsDevelopment field is false (retail), the channel is overwritten with value 0.&lt;br /&gt;
&lt;br /&gt;
This overwrites the u16 field at [[#SecurityConfig]]+0. When the cached [[SPL_services#IsDevelopment|IsDevelopment]] value is false (retail) ([18.0.0+] [[System_Settings|system-setting]] &amp;lt;code&amp;gt;ldn!enable_static_security_mode_configuration&amp;lt;/code&amp;gt; is checked for being true instead), value 1 is used ([18.0.0+] value from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;ldn!static_security_mode&amp;lt;/code&amp;gt; is used, with fallback to value 1 if the setting is &amp;gt;=0x4), otherwise the original value is used.&lt;br /&gt;
&lt;br /&gt;
[[#GetState|State]] must be 2, this cmd eventually sets the State to value 3.&lt;br /&gt;
&lt;br /&gt;
=== CreateNetworkPrivate ===&lt;br /&gt;
Takes an input [[#SecurityConfig]], a [[#SecurityParameter]], an [[#UserConfig]], a [[#NetworkConfig]], a type-0x9 input buffer containing an array of [[#AddressEntry]], no output.&lt;br /&gt;
&lt;br /&gt;
The buffer/count for [[#AddressEntry]] can be 0, in which case the network will be non-Private like [[#CreateNetwork]]. The count must be &amp;lt;=8.&lt;br /&gt;
&lt;br /&gt;
See [[#CreateNetwork]].&lt;br /&gt;
&lt;br /&gt;
=== DestroyNetwork ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
[[#GetState|State]] must be 3, this cmd eventually sets the State to value 2.&lt;br /&gt;
&lt;br /&gt;
=== Reject ===&lt;br /&gt;
Takes an input [[#Ipv4Address]], no output.&lt;br /&gt;
&lt;br /&gt;
[[#GetState|State]] must be 3.&lt;br /&gt;
&lt;br /&gt;
=== SetAdvertiseData ===&lt;br /&gt;
Takes a type-0x21 input buffer, no output.&lt;br /&gt;
&lt;br /&gt;
The input buffer contains arbitrary user data.&lt;br /&gt;
&lt;br /&gt;
The buffer size must be &amp;lt;=0x180. An empty buffer (addr=NULL/size=0) can be used to reset the AdvertiseData size in state to zero.&lt;br /&gt;
&lt;br /&gt;
[[#GetState|State]] must be 2-3.&lt;br /&gt;
&lt;br /&gt;
=== SetStationAcceptPolicy ===&lt;br /&gt;
Takes an input [[#AcceptPolicy]], no output.&lt;br /&gt;
&lt;br /&gt;
[[#GetState|State]] must be 2-3.&lt;br /&gt;
&lt;br /&gt;
=== AddAcceptFilterEntry ===&lt;br /&gt;
Takes an input [[#MacAddress|MacAddress]], no output.&lt;br /&gt;
&lt;br /&gt;
There are two sdknso funcs implementing this: one which takes a [[#MacAddress|MacAddress]] directly, the other loads the [[#MacAddress|MacAddress]] from the input [[#NodeInfo|NodeInfo]].&lt;br /&gt;
&lt;br /&gt;
[[#GetState|State]] must be 2-3.&lt;br /&gt;
&lt;br /&gt;
=== ClearAcceptFilter ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
[[#GetState|State]] must be 2-3.&lt;br /&gt;
&lt;br /&gt;
=== OpenStation ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
[[#GetState|State]] must be 1, this cmd eventually sets the State to value 4.&lt;br /&gt;
&lt;br /&gt;
=== CloseStation ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
[[#GetState|State]] must be 4-5, this cmd eventually sets the State to value 1.&lt;br /&gt;
&lt;br /&gt;
=== Connect ===&lt;br /&gt;
Takes a type-0x19 input buffer containing a [[#NetworkInfo]], a [[#SecurityConfig]], an [[#UserConfig]], a s32 LocalCommunicationVersion, a [[#ConnectOption]], no output.&lt;br /&gt;
&lt;br /&gt;
[[#GetState|State]] must be 4, this cmd eventually sets the State to value 5.&lt;br /&gt;
&lt;br /&gt;
This is identical to [[#ConnectPrivate]] (besides the below), except the data internally passed for [[#SecurityParameter]]/[[#NetworkConfig]] are loaded from the input [[#NetworkInfo]].&lt;br /&gt;
&lt;br /&gt;
[1.0.0-?] This overwrites the u16 field at [[#SecurityConfig]]+0. When the cached [[SPL_services#IsDevelopment|IsDevelopment]] value is false (retail), value 1 is used, otherwise the used value is: original_field == 0 ? {u16 [[#NetworkInfo]]+0x60} : original_field. [18.0.0+] This now uses the same SecurityMode override as [[#CreateNetwork|CreateNetwork]].&lt;br /&gt;
&lt;br /&gt;
u32 LocalCommunicationVersion&amp;gt;&amp;gt;15 must be 0.&lt;br /&gt;
&lt;br /&gt;
=== ConnectPrivate ===&lt;br /&gt;
Takes a [[#SecurityConfig]], [[#SecurityParameter]], an [[#UserConfig]], a s32 LocalCommunicationVersion, a [[#ConnectOption]], a [[#NetworkConfig]], no output.&lt;br /&gt;
&lt;br /&gt;
See [[#Connect]].&lt;br /&gt;
&lt;br /&gt;
[1.0.0-?] This overwrites the u16 field at [[#SecurityConfig]]+0. When the cached [[SPL_services#IsDevelopment|IsDevelopment]] value is false (retail), value 1 is used, otherwise the original value is used. [18.0.0+] This now uses the same SecurityMode override as [[#Connect|Connect]].&lt;br /&gt;
&lt;br /&gt;
=== Disconnect ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
[[#GetState|State]] must be 5, this cmd eventually sets the State to value 4.&lt;br /&gt;
&lt;br /&gt;
=== Initialize ===&lt;br /&gt;
Takes an input PID and an u64 pid_placeholder.&lt;br /&gt;
&lt;br /&gt;
This is used immediately after object creation.&lt;br /&gt;
&lt;br /&gt;
On old sysvers the cmd impl for User/System are identical, except different params are used for the funcs called internally.&lt;br /&gt;
&lt;br /&gt;
With [7.0.0+] [[#InitializeWithVersion|InitializeWithVersion]] is used instead. The cmd impl for Initialize uses [[#InitializeWithVersion|InitializeWithVersion]] with version=0.&lt;br /&gt;
&lt;br /&gt;
=== Finalize ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
This is used during service exit, prior to closing the object. Official sw will Abort if this fails.&lt;br /&gt;
&lt;br /&gt;
If State is set for it, this will run the equivalent of [[#CloseAccessPoint]]/[[#CloseStation]] when needed.&lt;br /&gt;
&lt;br /&gt;
[[#GetState|State]] must be non-zero, this cmd eventually sets the State to value 0.&lt;br /&gt;
&lt;br /&gt;
=== SetOperationMode ===&lt;br /&gt;
Takes an input [[#OperationMode]], no output.&lt;br /&gt;
&lt;br /&gt;
[[#GetState|State]] must be 1.&lt;br /&gt;
&lt;br /&gt;
The input value is written into state.&lt;br /&gt;
&lt;br /&gt;
=== InitializeWithVersion ===&lt;br /&gt;
Takes an input PID, a s32 version, and an u64 pid_placeholder.&lt;br /&gt;
&lt;br /&gt;
The priority is determined by whether the interface is User/System: System = 0x38, User = 0x5A.&lt;br /&gt;
&lt;br /&gt;
It then calls the init func, with the cmd input params and the above priority, returning the Result on failure.&lt;br /&gt;
&lt;br /&gt;
On newer sysvers this then adds an entry for the state array used by [[#RegisterClient|RegisterClient]].&lt;br /&gt;
&lt;br /&gt;
Lastly the input PID and version are written into state, then this returns.&lt;br /&gt;
&lt;br /&gt;
The init func does the following:&lt;br /&gt;
* The PID must be non-zero, and the version must not be negative. The priority must be 0x5A or 0x38.&lt;br /&gt;
* An error is returned if state fields are invalid.&lt;br /&gt;
* The input PID and version are written into state (a state field is also set to interface == User).&lt;br /&gt;
* Lastly, a vfunc is called with the input priority, returning the Result from that.&lt;br /&gt;
&lt;br /&gt;
The vfunc does the following:&lt;br /&gt;
* On newer sysvers, this uses [[Shared_Database_services|pl:s]] RequestApplicationFunctionAuthorizationByProcessId with the input PID and [[Shared_Database_services|ApplicationFunctionAuthorizationId]] = 2 (SecureLdnLocalCommunication), returning the Result on failure.&lt;br /&gt;
* Then a message is sent to a msg-queue with the input priority.&lt;br /&gt;
&lt;br /&gt;
The handler for the above message does the following:&lt;br /&gt;
* When state is already initialized, runs handling for that. An error is also thrown if the input priority is larger than a state field.&lt;br /&gt;
* Initializes state, etc.&lt;br /&gt;
* Various [[Network_Interface_services|nifm]] funcs are eventually used. The input priority is used to determine the value for [[Network_Interface_services#CreateRequest|nn::nifm::RequestParameters]]: value 0x4 or value 0x8 is used, depending on priority &amp;gt; 0x59.&lt;br /&gt;
** Newer versions also handle ldn lan_emulation [[System_Settings|sys-settings]] here. For the above value, when lan_emulation is enabled it uses value 0x17, with 0x18 additionally used for priority &amp;lt;= 0x59.&lt;br /&gt;
* The rest is state init, including setting [[#State|State]] to value 1. Then 0 is returned.&lt;br /&gt;
&lt;br /&gt;
On old sysvers the cmd impl for User/System are identical, except different params are used for the funcs called internally. With newer sysvers the cmd impl is now identical.&lt;br /&gt;
&lt;br /&gt;
Version values passed by official sw:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value || SystemVersion&lt;br /&gt;
|-&lt;br /&gt;
| 0x1 || [7.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 0x2 || [18.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 0x3 || [19.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || [20.0.0+]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== InitializeWithPriority ===&lt;br /&gt;
Takes an input PID, a s32 version, a s32 priority, and an u64 pid_placeholder.&lt;br /&gt;
&lt;br /&gt;
This is similar to [[#InitializeWithVersion|InitializeWithVersion]]. The input priority is passed directly to the init func which is called here, instead of determining it from whether the interface is User/System.&lt;br /&gt;
&lt;br /&gt;
Official sw passes input value 0x38 for the priority as the default, when the user doesn&#039;t specify the priority.&lt;br /&gt;
&lt;br /&gt;
=== EnableActionFrame ===&lt;br /&gt;
Takes an input [[#ActionFrameSettings]]. No output.&lt;br /&gt;
&lt;br /&gt;
[[#State|State]] must be Initialized.&lt;br /&gt;
&lt;br /&gt;
=== DisableActionFrame ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
[[#State|State]] must be Initialized.&lt;br /&gt;
&lt;br /&gt;
=== SendActionFrame ===&lt;br /&gt;
Takes a type-0x21 input buffer, two input [[#MacAddress]], two input s16s (&#039;&#039;&#039;Band&#039;&#039;&#039; and &#039;&#039;&#039;ChannelNumber&#039;&#039;&#039;) and an input [[#MessageFlagSet]]. No output.&lt;br /&gt;
&lt;br /&gt;
[20.0.0+] The input s16s were replaced with a single u16, which has the same format as [[#SetHomeChannel|SetHomeChannel]].&lt;br /&gt;
&lt;br /&gt;
The first [[#MacAddress]] is the destination, the second [[#MacAddress]] is the Bssid.&lt;br /&gt;
&lt;br /&gt;
The ChannelNumber must be non-zero.&lt;br /&gt;
&lt;br /&gt;
[[#State|State]] must be 3-5 (AccessPointCreated/Station/StationConnected).&lt;br /&gt;
&lt;br /&gt;
=== RecvActionFrame ===&lt;br /&gt;
Takes a type-0x22 output buffer and an input [[#MessageFlagSet]]. Returns two output [[#MacAddress]], two output s16s (&#039;&#039;&#039;Band&#039;&#039;&#039; and &#039;&#039;&#039;ChannelNumber&#039;&#039;&#039;), an output u32 &#039;&#039;&#039;Size&#039;&#039;&#039;, and an output s32 &#039;&#039;&#039;LinkLevel&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
[20.0.0+] The output s16s were replaced with a single u16, which has the same format as [[#SetHomeChannel|SetHomeChannel]].&lt;br /&gt;
&lt;br /&gt;
[[#EnableActionFrame|EnableActionFrame]] must be used prior to this.&lt;br /&gt;
&lt;br /&gt;
=== SetHomeChannel ===&lt;br /&gt;
Takes two input s16s &#039;&#039;&#039;Band&#039;&#039;&#039; and &#039;&#039;&#039;ChannelNumber&#039;&#039;&#039;. No output.&lt;br /&gt;
&lt;br /&gt;
[20.0.0+] Now takes an input u16 instead of two s16s, merging the two params. Bitmask 0x3FF (low 10-bits) is the ChannelNumber, while the remaining upper 6-bits is the Band. The Band is used as an array index to load the actual Band for passing to a func. Only the following Band input is valid, others return 0x0/0xFFFF: 2 - &amp;gt; 2400, 5 -&amp;gt; 5000, 6 -&amp;gt; 6000.&lt;br /&gt;
&lt;br /&gt;
On NX Band must be ([20.0.0+] converted Band from the above array) 50 ([20.0.0+] 5000) or 24 ([20.0.0+] 2400).&lt;br /&gt;
&lt;br /&gt;
The ChannelNumber must be non-zero.&lt;br /&gt;
&lt;br /&gt;
The [[#State|State]] must be Station.&lt;br /&gt;
&lt;br /&gt;
sdknso uses the input channel to convert to the input needed by the cmd.&lt;br /&gt;
&lt;br /&gt;
=== SetTxPower ===&lt;br /&gt;
Takes an input s16 &#039;&#039;&#039;Power&#039;&#039;&#039;. No output.&lt;br /&gt;
&lt;br /&gt;
The input must be 0x0..0xFF.&lt;br /&gt;
&lt;br /&gt;
A state field must be non-zero.&lt;br /&gt;
&lt;br /&gt;
The [[#State|State]] must be 2-5 (AccessPoint*/Station*).&lt;br /&gt;
&lt;br /&gt;
=== ResetTxPower ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
The same state field checked by [[#SetTxPower|SetTxPower]] must be non-zero. The [[#State|State]] check is also the same as [[#SetTxPower|SetTxPower]].&lt;br /&gt;
&lt;br /&gt;
== IClientProcessMonitor ==&lt;br /&gt;
This is &amp;quot;nn::ldn::detail::IClientProcessMonitor&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [18.0.0+]. &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || RegisterClient&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== RegisterClient ===&lt;br /&gt;
Takes an input PID and an u64 pid_placeholder.&lt;br /&gt;
&lt;br /&gt;
[18.0.0+] [[#CreateClientProcessMonitor|CreateClientProcessMonitor]] and RegisterClient are used by sdknso at the end of the ldn initialization functionality.&lt;br /&gt;
&lt;br /&gt;
If the objptr in IClientProcessMonitor state is already set from using this cmd previously, this just returns 0.&lt;br /&gt;
&lt;br /&gt;
This goes through global state to locate an entry with a matching PID, if none found 0 is returned. The objptr from the state entry is loaded, if NULL this returns 0. This obj is then incref&#039;d and written into the IClientProcessMonitor state. When PID is 0, 0 is returned. It then locates the above state entry again with a matching PID, clearing the entry which matches. Lastly 0 is returned.&lt;br /&gt;
&lt;br /&gt;
The initialization [[#InitializeWithPriority|cmds]] adds an entry to the above global state.&lt;br /&gt;
&lt;br /&gt;
= ldn:u =&lt;br /&gt;
This is &amp;quot;nn::ldn::detail::IUserServiceCreator&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This has IPC max_sessions 3.&lt;br /&gt;
&lt;br /&gt;
[18.0.0+] The sdknso uses SessionManager with this, where the additional session-count is 0x3.&lt;br /&gt;
&lt;br /&gt;
[S2] There appears to be 2 ldn:u services, this appears to be for having separate [[#Protocol|Protocol]] permissions for NX and Ounce games. The Creator object has the same vtable for both of these. However the vtable for IUserLocalCommunicationService appears to be larger even with NX, which likely indicates there&#039;s new commands? There also appears to be 4 additional max-sessions allocated to ldn*, this is probably for one of these ldn:u services?&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#CreateUserLocalCommunicationService|CreateUserLocalCommunicationService]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [18.0.0+] [[#CreateClientProcessMonitor|CreateClientProcessMonitor]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== CreateUserLocalCommunicationService==&lt;br /&gt;
Returns an [[#IUserLocalCommunicationService]].&lt;br /&gt;
&lt;br /&gt;
The user-process closes the IUserServiceCreator object once finished with it during initialization. Official sw ignores errors from this cmd.&lt;br /&gt;
&lt;br /&gt;
== IUserLocalCommunicationService ==&lt;br /&gt;
This is &amp;quot;nn::ldn::detail::IUserLocalCommunicationService&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#GetState_2|GetState]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#GetNetworkInfo_2|GetNetworkInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [[#GetIpv4Address_2|GetIpv4Address]]&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [[#GetDisconnectReason_2|GetDisconnectReason]]&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [[#GetSecurityParameter_2|GetSecurityParameter]]&lt;br /&gt;
|-&lt;br /&gt;
| 5 || [[#GetNetworkConfig_2|GetNetworkConfig]]&lt;br /&gt;
|-&lt;br /&gt;
| 100 || [[#GetStateChangeEvent|GetStateChangeEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 101 || [[#GetNetworkInfoAndHistory|GetNetworkInfoAndHistory]]&lt;br /&gt;
|-&lt;br /&gt;
| 102 || [[#Scan|Scan]]&lt;br /&gt;
|-&lt;br /&gt;
| 103 || [[#ScanPrivate|ScanPrivate]]&lt;br /&gt;
|-&lt;br /&gt;
| 104 || [5.0.0+] [[#SetWirelessControllerPolicy|SetWirelessControllerPolicy]]&lt;br /&gt;
|-&lt;br /&gt;
| 105 || [13.1.0+] [[#SetWirelessAudioPolicy|SetWirelessAudioPolicy]]&lt;br /&gt;
|-&lt;br /&gt;
| 106 || [18.0.0+] [[#SetProtocol|SetProtocol]]&lt;br /&gt;
|-&lt;br /&gt;
| 200 || [[#OpenAccessPoint|OpenAccessPoint]]&lt;br /&gt;
|-&lt;br /&gt;
| 201 || [[#CloseAccessPoint|CloseAccessPoint]]&lt;br /&gt;
|-&lt;br /&gt;
| 202 || [[#CreateNetwork|CreateNetwork]]&lt;br /&gt;
|-&lt;br /&gt;
| 203 || [[#CreateNetworkPrivate|CreateNetworkPrivate]]&lt;br /&gt;
|-&lt;br /&gt;
| 204 || [[#DestroyNetwork|DestroyNetwork]]&lt;br /&gt;
|-&lt;br /&gt;
| 205 || [[#Reject|Reject]]&lt;br /&gt;
|-&lt;br /&gt;
| 206 || [[#SetAdvertiseData|SetAdvertiseData]]&lt;br /&gt;
|-&lt;br /&gt;
| 207 || [[#SetStationAcceptPolicy|SetStationAcceptPolicy]]&lt;br /&gt;
|-&lt;br /&gt;
| 208 || [[#AddAcceptFilterEntry|AddAcceptFilterEntry]]&lt;br /&gt;
|-&lt;br /&gt;
| 209 || [[#ClearAcceptFilter|ClearAcceptFilter]]&lt;br /&gt;
|-&lt;br /&gt;
| 300 || [[#OpenStation|OpenStation]]&lt;br /&gt;
|-&lt;br /&gt;
| 301 || [[#CloseStation|CloseStation]]&lt;br /&gt;
|-&lt;br /&gt;
| 302 || [[#Connect|Connect]]&lt;br /&gt;
|-&lt;br /&gt;
| 303 || [[#ConnectPrivate|ConnectPrivate]]&lt;br /&gt;
|-&lt;br /&gt;
| 304 || [[#Disconnect|Disconnect]]&lt;br /&gt;
|-&lt;br /&gt;
| 400 || [[#Initialize_2|Initialize]]&lt;br /&gt;
|-&lt;br /&gt;
| 401 || [[#Finalize_2|Finalize]]&lt;br /&gt;
|-&lt;br /&gt;
| 402 || [7.0.0+] [[#InitializeWithVersion|InitializeWithVersion]]&lt;br /&gt;
|-&lt;br /&gt;
| 403 || [19.0.0+] [[#SetOperationMode|SetOperationMode]]&lt;br /&gt;
|-&lt;br /&gt;
| 500 || [18.0.0+] [[#EnableActionFrame|EnableActionFrame]]&lt;br /&gt;
|-&lt;br /&gt;
| 501 || [18.0.0+] [[#DisableActionFrame|DisableActionFrame]]&lt;br /&gt;
|-&lt;br /&gt;
| 502 || [18.0.0+] [[#SendActionFrame|SendActionFrame]]&lt;br /&gt;
|-&lt;br /&gt;
| 503 || [18.0.0+] [[#RecvActionFrame|RecvActionFrame]]&lt;br /&gt;
|-&lt;br /&gt;
| 505 || [18.0.0+] [[#SetHomeChannel|SetHomeChannel]]&lt;br /&gt;
|-&lt;br /&gt;
| 600 || [18.0.0+] [[#SetTxPower|SetTxPower]]&lt;br /&gt;
|-&lt;br /&gt;
| 601 || [18.0.0+] [[#ResetTxPower|ResetTxPower]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ndd =&lt;br /&gt;
This is &amp;quot;nn::ndd::IService&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [5.0.0] and removed with [6.0.0].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || EnableAutoCommunication&lt;br /&gt;
|-&lt;br /&gt;
| 1 || DisableAutoCommunication&lt;br /&gt;
|-&lt;br /&gt;
| 2 || IsAutoCommunicationEnabled&lt;br /&gt;
|-&lt;br /&gt;
| 3 || EnablePowerSave&lt;br /&gt;
|-&lt;br /&gt;
| 4 || DisablePowerSave&lt;br /&gt;
|-&lt;br /&gt;
| 5 || IsPowerSaveEnabled&lt;br /&gt;
|-&lt;br /&gt;
| 6 || IsNetworkActive&lt;br /&gt;
|-&lt;br /&gt;
| 7 || AcquireSendDataUpdateEvent&lt;br /&gt;
|-&lt;br /&gt;
| 8 || AddSendData&lt;br /&gt;
|-&lt;br /&gt;
| 9 || ClearSendData&lt;br /&gt;
|-&lt;br /&gt;
| 10 || GetSendData&lt;br /&gt;
|-&lt;br /&gt;
| 11 || AcquireReceiveDataEvent&lt;br /&gt;
|-&lt;br /&gt;
| 12 || GetCurrentReceiveDataCounter&lt;br /&gt;
|-&lt;br /&gt;
| 13 || GetOldestReceiveDataCounter&lt;br /&gt;
|-&lt;br /&gt;
| 14 || GetNextReceiveDataCounter&lt;br /&gt;
|-&lt;br /&gt;
| 15 || GetAvailableReceiveDataCount&lt;br /&gt;
|-&lt;br /&gt;
| 16 || GetRecentReceiveDataCounter&lt;br /&gt;
|-&lt;br /&gt;
| 17 || GetReceiveData&lt;br /&gt;
|-&lt;br /&gt;
| 18 || AddReceiveData&lt;br /&gt;
|-&lt;br /&gt;
| 19 || ClearReceiveData&lt;br /&gt;
|-&lt;br /&gt;
| 20 || ClearDataIdFilter&lt;br /&gt;
|-&lt;br /&gt;
| 21 || AcquireDeviceScanEvent&lt;br /&gt;
|-&lt;br /&gt;
| 22 || StartDeviceScan&lt;br /&gt;
|-&lt;br /&gt;
| 23 || CancelDeviceScan&lt;br /&gt;
|-&lt;br /&gt;
| 24 || GetDeviceScanResult&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= lp2p:app, lp2p:sys =&lt;br /&gt;
These are &amp;quot;nn::lp2p::detail::ISfServiceCreator&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
These were added with [9.0.0+].&lt;br /&gt;
&lt;br /&gt;
lp2p:app is used by [[Mario Kart Live: Home Circuit]]. lp2p:sys is used by [[Album_Applet|LibraryAppletPhotoViewer]] with [11.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#CreateNetworkService|CreateNetworkService]]&lt;br /&gt;
|-&lt;br /&gt;
| 8 || [[#CreateNetworkServiceMonitor|CreateNetworkServiceMonitor]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== CreateNetworkService ==&lt;br /&gt;
Takes a PID-descriptor, a reserved input u64 and an input u32. Returns an output [[#ISfService]].&lt;br /&gt;
&lt;br /&gt;
The input u32 must be value 0x1.&lt;br /&gt;
&lt;br /&gt;
== CreateNetworkServiceMonitor ==&lt;br /&gt;
Takes a PID-descriptor and a reserved input u64. Returns an output [[#ISfServiceMonitor]].&lt;br /&gt;
&lt;br /&gt;
== ISfService ==&lt;br /&gt;
This is &amp;quot;nn::lp2p::detail::ISfService&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#Initialize_4|Initialize]]&lt;br /&gt;
|-&lt;br /&gt;
| 256 || [9.0.0-9.0.1] [[#AttachNetworkInterfaceStateChangeEvent|AttachNetworkInterfaceStateChangeEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 264 || [9.0.0-9.0.1] [[#GetNetworkInterfaceLastError|GetNetworkInterfaceLastError]]&lt;br /&gt;
|-&lt;br /&gt;
| 272 || [9.0.0-9.0.1] [[#GetRole|GetRole]]&lt;br /&gt;
|-&lt;br /&gt;
| 280 || [9.0.0-9.0.1] [[#GetAdvertiseData|GetAdvertiseData]]&lt;br /&gt;
|-&lt;br /&gt;
| 288 || [9.0.0-9.0.1] [[#GetGroupInfo|GetGroupInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 296 || [9.0.0-9.0.1] [[#GetGroupInfo2|GetGroupInfo2]]&lt;br /&gt;
|-&lt;br /&gt;
| 304 || [9.0.0-9.0.1] [[#GetGroupOwner|GetGroupOwner]]&lt;br /&gt;
|-&lt;br /&gt;
| 312 || [9.0.0-9.0.1] [[#GetIpConfig|GetIpConfig]]&lt;br /&gt;
|-&lt;br /&gt;
| 320 || [9.0.0-9.0.1] [[#GetLinkLevel|GetLinkLevel]]&lt;br /&gt;
|-&lt;br /&gt;
| 512 || [[#Scan_2|Scan]]&lt;br /&gt;
|-&lt;br /&gt;
| 768 || [[#CreateGroup|CreateGroup]]&lt;br /&gt;
|-&lt;br /&gt;
| 776 || [[#DestroyGroup|DestroyGroup]]&lt;br /&gt;
|-&lt;br /&gt;
| 784 || [[#SetAdvertiseData|SetAdvertiseData]]&lt;br /&gt;
|-&lt;br /&gt;
| 1536 || [[#SendToOtherGroup|SendToOtherGroup]]&lt;br /&gt;
|-&lt;br /&gt;
| 1544 || [[#RecvFromOtherGroup|RecvFromOtherGroup]]&lt;br /&gt;
|-&lt;br /&gt;
| 1552 || [[#AddAcceptableGroupId|AddAcceptableGroupId]]&lt;br /&gt;
|-&lt;br /&gt;
| 1560 || [9.1.0+] [[#ClearAcceptableGroupId|ClearAcceptableGroupId]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Initialize ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Returns 0.&lt;br /&gt;
&lt;br /&gt;
Unused by official sw.&lt;br /&gt;
&lt;br /&gt;
=== Scan ===&lt;br /&gt;
Takes a type-0x19 input buffer containing a [[#GroupInfo]] and a type-0x22 output buffer containing an array of [[#ScanResult]]. Returns an output s32 &#039;&#039;&#039;TotalOut&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
=== CreateGroup ===&lt;br /&gt;
Takes a type-0x31 input buffer containing a [[#GroupInfo]]. No output.&lt;br /&gt;
&lt;br /&gt;
[[Mario Kart Live: Home Circuit|mklive]] uses the following string with this: &amp;quot;Failed to create a group: %08X&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
The [[#GetRole|role]] must be 0. This eventually sets the [[#GetRole|role]] to value 1.&lt;br /&gt;
&lt;br /&gt;
=== DestroyGroup ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
This destroys the previously [[#CreateGroup|created]] group. If no group was previously created ([[#GetRole|role]] is not 1), this just returns 0.&lt;br /&gt;
&lt;br /&gt;
=== SetAdvertiseData ===&lt;br /&gt;
Takes a type-0x21 input buffer. No output.&lt;br /&gt;
&lt;br /&gt;
The buffer size must be &amp;lt;=0x80. The [[#GetRole|role]] must be &amp;lt;=1.&lt;br /&gt;
&lt;br /&gt;
A string in [[Mario Kart Live: Home Circuit|mklive]] refers to the buffer data as &amp;quot;scan advertise data&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
=== SendToOtherGroup ===&lt;br /&gt;
Takes an input [[#MacAddress_2|MacAddress]], a [[#GroupId]], a s16 &#039;&#039;&#039;Frequency&#039;&#039;&#039;, a s16 &#039;&#039;&#039;Channel&#039;&#039;&#039;, an u32 &#039;&#039;&#039;MessageFlag&#039;&#039;&#039; and a type-0x21 input buffer. No output.&lt;br /&gt;
&lt;br /&gt;
The buffer size must be &amp;lt;=0x400.&lt;br /&gt;
&lt;br /&gt;
The MacAddress must be non-zero. The s16s must be &amp;gt;=1.&lt;br /&gt;
&lt;br /&gt;
Only bit0 is used from flags: clear = block until the data can be sent, set = return error when the data can&#039;t be sent.&lt;br /&gt;
&lt;br /&gt;
A string in [[Mario Kart Live: Home Circuit|mklive]] refers to the buffer data as &amp;quot;Action frame&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
The [[#GetRole|role]] must be non-zero. The error from [[#GetNetworkInterfaceLastError]] will be returned if it&#039;s set.&lt;br /&gt;
&lt;br /&gt;
[11.0.0+] [[#GroupInfo]]+0x8A must be value 2, otherwise an error is returned.&lt;br /&gt;
&lt;br /&gt;
This sends an Action frame to the specified [[#GroupId]], with the specified destination [[#MacAddress_2|MacAddress]] (can be a broadcast address).&lt;br /&gt;
&lt;br /&gt;
The frequency param is the same as the [[#GroupInfo]]+0x84 field.&lt;br /&gt;
&lt;br /&gt;
=== RecvFromOtherGroup ===&lt;br /&gt;
Takes an input u32 &#039;&#039;&#039;MessageFlag&#039;&#039;&#039; and a type-0x22 output buffer. Returns a [[#MacAddress_2|MacAddress]], an u16 &#039;&#039;&#039;Frequency&#039;&#039;&#039;, a s16 &#039;&#039;&#039;Channel&#039;&#039;&#039;, an u32 &#039;&#039;&#039;OutSize&#039;&#039;&#039; and a s32.&lt;br /&gt;
&lt;br /&gt;
The OutSize is the original size used for copying to the output buffer, before it&#039;s clamped to the output-buffer size.&lt;br /&gt;
&lt;br /&gt;
Only bit0 is used from MessageFlag: clear = block until data is available, set = return error when data is not available.&lt;br /&gt;
&lt;br /&gt;
When data is not available, the error from [[#GetNetworkInterfaceLastError]] will be returned if it&#039;s set.&lt;br /&gt;
&lt;br /&gt;
The [[#GetRole|role]] must be non-zero.&lt;br /&gt;
&lt;br /&gt;
This receives an Action frame.&lt;br /&gt;
&lt;br /&gt;
=== AddAcceptableGroupId ===&lt;br /&gt;
Takes an input [[#GroupId]]. No output.&lt;br /&gt;
&lt;br /&gt;
=== ClearAcceptableGroupId ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
== ISfServiceMonitor ==&lt;br /&gt;
This is &amp;quot;nn::lp2p::detail::ISfServiceMonitor&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This interface has no commands, until [9.1.0+] which added actual commands.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#Initialize_5|Initialize]]&lt;br /&gt;
|-&lt;br /&gt;
| 256 || [[#AttachNetworkInterfaceStateChangeEvent|AttachNetworkInterfaceStateChangeEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 264 || [[#GetNetworkInterfaceLastError|GetNetworkInterfaceLastError]]&lt;br /&gt;
|-&lt;br /&gt;
| 272 || [[#GetRole|GetRole]]&lt;br /&gt;
|-&lt;br /&gt;
| 280 || [[#GetAdvertiseData|GetAdvertiseData]]&lt;br /&gt;
|-&lt;br /&gt;
| 281 || [[#GetAdvertiseData2|GetAdvertiseData2]]&lt;br /&gt;
|-&lt;br /&gt;
| 288 || [[#GetGroupInfo|GetGroupInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 296 || [[#GetGroupInfo2|GetGroupInfo2]]&lt;br /&gt;
|-&lt;br /&gt;
| 304 || [[#GetGroupOwner|GetGroupOwner]]&lt;br /&gt;
|-&lt;br /&gt;
| 312 || [[#GetIpConfig|GetIpConfig]]&lt;br /&gt;
|-&lt;br /&gt;
| 320 || [[#GetLinkLevel|GetLinkLevel]]&lt;br /&gt;
|-&lt;br /&gt;
| 328 || [[#AttachJoinEvent|AttachJoinEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 336 || [[#GetMembers|GetMembers]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Initialize ===&lt;br /&gt;
Returns 0.&lt;br /&gt;
&lt;br /&gt;
Unused by official sw.&lt;br /&gt;
&lt;br /&gt;
=== AttachNetworkInterfaceStateChangeEvent ===&lt;br /&gt;
No input. Returns an output Event handle with EventClearMode=0.&lt;br /&gt;
&lt;br /&gt;
=== GetNetworkInterfaceLastError ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
=== GetRole ===&lt;br /&gt;
No input. Returns an output u8.&lt;br /&gt;
&lt;br /&gt;
=== GetAdvertiseData ===&lt;br /&gt;
Takes a type-0x22 output buffer. Returns two output u16s.&lt;br /&gt;
&lt;br /&gt;
Validates that the [[#GetRole|role]] is value 2, then copies data from state into the output buffer. The first output u16 is the size used for the memcpy, the second u16 is the original size from state.&lt;br /&gt;
&lt;br /&gt;
=== GetAdvertiseData2 ===&lt;br /&gt;
Takes a type-0x22 output buffer. Returns two output u16s.&lt;br /&gt;
&lt;br /&gt;
This is identical to [[#GetAdvertiseData]] except this doesn&#039;t run the role validation.&lt;br /&gt;
&lt;br /&gt;
=== GetGroupInfo ===&lt;br /&gt;
Takes a type-0x32 output buffer containing a [[#GroupInfo]].&lt;br /&gt;
&lt;br /&gt;
Validates that the [[#GetRole|role]] is non-zero, then copies the struct from state into the output buffer.&lt;br /&gt;
&lt;br /&gt;
=== GetGroupInfo2 ===&lt;br /&gt;
Takes a type-0x32 output buffer containing a [[#GroupInfo]] and a type-0x31 input buffer containing a [[#GroupInfo]].&lt;br /&gt;
&lt;br /&gt;
This runs the same code as [[#CreateGroup]] to generate the [[#GroupInfo]] for the input struct (which with [[#CreateGroup]] would be available with [[#GetGroupInfo]]). The input struct is the same as [[#CreateGroup]].&lt;br /&gt;
&lt;br /&gt;
=== GetGroupOwner ===&lt;br /&gt;
No input. Returns an output [[#NodeInfo_2|NodeInfo]].&lt;br /&gt;
&lt;br /&gt;
Validates that the [[#GetRole|role]] is non-zero, then copies the data from state to output.&lt;br /&gt;
&lt;br /&gt;
=== GetIpConfig ===&lt;br /&gt;
Takes a type-0x1A output buffer containing a 0x100-byte struct.&lt;br /&gt;
&lt;br /&gt;
Validates that the [[#GetRole|role]] is non-zero, then copies the struct from state into the output buffer.&lt;br /&gt;
&lt;br /&gt;
+0x20 is the &amp;lt;code&amp;gt;struct sockaddr&amp;lt;/code&amp;gt; IP address, +0x40 is the &amp;lt;code&amp;gt;struct sockaddr&amp;lt;/code&amp;gt; subnet-mask, +0x60 is the &amp;lt;code&amp;gt;struct sockaddr&amp;lt;/code&amp;gt; gateway(?). The address for the last one is set to localhost.&lt;br /&gt;
&lt;br /&gt;
=== GetLinkLevel ===&lt;br /&gt;
No input. Returns an output u32.&lt;br /&gt;
&lt;br /&gt;
=== AttachJoinEvent ===&lt;br /&gt;
No input. Returns an output Event handle with EventClearMode=0.&lt;br /&gt;
&lt;br /&gt;
=== GetMembers ===&lt;br /&gt;
Takes a type-0x22 output buffer containing an array of [[#NodeInfo_2|NodeInfo]]. Returns an output s32 &#039;&#039;&#039;TotalOut&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
Validates that the [[#GetRole|role]] is value 1. Then any entries from state which are available are copied into the output array buffer, if there&#039;s space available. A maximum of 8 entries can be returned.&lt;br /&gt;
&lt;br /&gt;
A string in [[Mario Kart Live: Home Circuit|mklive]] refers to the array data as &amp;quot;connected members&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
= lp2p:m =&lt;br /&gt;
This is &amp;quot;nn::lp2p::monitor::detail::ISfMonitorServiceCreator&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [9.1.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#CreateMonitorService|CreateMonitorService]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== CreateMonitorService ==&lt;br /&gt;
Takes a PID-descriptor, a reserved input u64 and an input u64. Returns an [[#ISfMonitorService]].&lt;br /&gt;
&lt;br /&gt;
== ISfMonitorService ==&lt;br /&gt;
This is &amp;quot;nn::lp2p::monitor::detail::ISfMonitorService&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#Initialize_6|Initialize]]&lt;br /&gt;
|-&lt;br /&gt;
| 288 || [[#GetGroupInfo|GetGroupInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 320 || [[#GetLinkLevel|GetLinkLevel]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Initialize ===&lt;br /&gt;
Returns 0.&lt;br /&gt;
&lt;br /&gt;
= State =&lt;br /&gt;
This is &amp;quot;nn::ldn::State&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Value&lt;br /&gt;
!  Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || None&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Initialized&lt;br /&gt;
|-&lt;br /&gt;
| 2 || AccessPoint&lt;br /&gt;
|-&lt;br /&gt;
| 3 || AccessPointCreated&lt;br /&gt;
|-&lt;br /&gt;
| 4 || Station&lt;br /&gt;
|-&lt;br /&gt;
| 5 || StationConnected&lt;br /&gt;
|-&lt;br /&gt;
| 6 || Error&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Ipv4Address =&lt;br /&gt;
This is &amp;quot;nn::ldn::Ipv4Address&amp;quot;. This is a 0x4-byte struct with 4-byte alignment.&lt;br /&gt;
&lt;br /&gt;
This is essentially the same as &amp;lt;code&amp;gt;struct in_addr&amp;lt;/code&amp;gt;, except this is little-endian.&lt;br /&gt;
&lt;br /&gt;
This is generally &amp;quot;169.254.XXX.{...}&amp;quot;, where XXX is random per created network.&lt;br /&gt;
&lt;br /&gt;
= SubnetMask =&lt;br /&gt;
This is &amp;quot;nn::ldn::SubnetMask&amp;quot;. This is a 0x4-byte struct with 4-byte alignment.&lt;br /&gt;
&lt;br /&gt;
This is essentially the same as &amp;lt;code&amp;gt;struct in_addr&amp;lt;/code&amp;gt;, except this is little-endian.&lt;br /&gt;
&lt;br /&gt;
= Ssid =&lt;br /&gt;
This is &amp;quot;nn::ldn::Ssid&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
When converting a Ssid to a string, the loaded chars from the string must be in the range of 0x20-0x7F, otherwise the byte written to the string will be 0.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x1 || Length (excluding NUL-terminator, must be 0x1-0x20)&lt;br /&gt;
|-&lt;br /&gt;
| 0x1 || 0x21 || Raw (SSID string including NUL-terminator, str[{above length}] must be 0)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= MacAddress =&lt;br /&gt;
This is &amp;quot;nn::ldn::MacAddress&amp;quot;. This is a 6-byte struct with 1-byte alignment.&lt;br /&gt;
&lt;br /&gt;
= NodeInfo =&lt;br /&gt;
This is &amp;quot;nn::ldn::NodeInfo&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
The first node in the nodes array is always the AccessPoint (NodeId 0x0). NodeId is the index of the node in the nodes array.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x4 || [[#Ipv4Address|Ipv4Address]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || 0x6 || [[#MacAddress|MacAddress]]&lt;br /&gt;
|-&lt;br /&gt;
| 0xA || 0x1 || NodeId&lt;br /&gt;
|-&lt;br /&gt;
| 0xB || 0x1 || IsConnected&lt;br /&gt;
|-&lt;br /&gt;
| 0xC || 0x21 || UserName&lt;br /&gt;
|-&lt;br /&gt;
| 0x2D || 0x1 || [19.0.0+] Platform? (0 = NX, 1 = Ounce)&lt;br /&gt;
|-&lt;br /&gt;
| 0x2E || 0x2 || LocalCommunicationVersion&lt;br /&gt;
|-&lt;br /&gt;
| 0x30 || 0x10 || Reserved&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= NodeLatestUpdate =&lt;br /&gt;
This is &amp;quot;nn::ldn::NodeLatestUpdate&amp;quot;. This is a 0x8-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x1 || StateChange&lt;br /&gt;
|-&lt;br /&gt;
| 0x1 || 0x7 || Reserved&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= IntentId =&lt;br /&gt;
This is &amp;quot;nn::ldn::IntentId&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x8 || LocalCommunicationId&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x2 || Reserved&lt;br /&gt;
|-&lt;br /&gt;
| 0xA || 0x2 || SceneId&lt;br /&gt;
|-&lt;br /&gt;
| 0xC || 0x4 || Reserved&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* LocalCommunicationId: [[#CreateNetwork|CreateNetwork]], [[#CreateNetworkPrivate|CreateNetworkPrivate]], [[#Connect|Connect]], [[#ConnectPrivate|ConnectPrivate]] (also [[#ScanFilter|ScanFilter]] when enabled with the flag): When -1, this is overwritten with the first LocalCommunicationId from the user-process [[NACP]], if loading fails value 0 is written instead. Otherwise when not -1, if [[NACP]] loading is successful, this field must match one of the LocalCommunicationIds from there.&lt;br /&gt;
* SceneId: Arbitrary user data, this can be used for filtering with [[#ScanFilter|ScanFilter]] for example.&lt;br /&gt;
&lt;br /&gt;
= SessionId =&lt;br /&gt;
This is &amp;quot;nn::ldn::SessionId&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This is used to generate/overwrite the Ssid when needed.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x10 || Random&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= NetworkId =&lt;br /&gt;
This is &amp;quot;nn::ldn::NetworkId&amp;quot;. This is a 0x20-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x10 || [[#IntentId|IntentId]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x10 || [[#SessionId|SessionId]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= CommonNetworkInfo =&lt;br /&gt;
This is &amp;quot;nn::ldn::CommonNetworkInfo&amp;quot;. This is a 0x30-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x6 || [[#MacAddress|Bssid]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x6 || 0x22 || [[#Ssid|Ssid]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x28 || 0x2 || Channel&lt;br /&gt;
|-&lt;br /&gt;
| 0x2A || 0x1 || LinkLevel&lt;br /&gt;
|-&lt;br /&gt;
| 0x2B || 0x1 || NetworkType&lt;br /&gt;
|-&lt;br /&gt;
| 0x2C || 0x4 || Reserved&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= LdnNetworkInfo =&lt;br /&gt;
This is &amp;quot;nn::ldn::LdnNetworkInfo&amp;quot;. This is a 0x430-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x10 || ServerRandom&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x2 || SecurityMode&lt;br /&gt;
|-&lt;br /&gt;
| 0x12 || 0x1 || StationAcceptPolicy&lt;br /&gt;
|-&lt;br /&gt;
| 0x13 || 0x1 || Version&lt;br /&gt;
|-&lt;br /&gt;
| 0x14 || 0x2 || Reserved&lt;br /&gt;
|-&lt;br /&gt;
| 0x16 || 0x1 || NodeCountMax&lt;br /&gt;
|-&lt;br /&gt;
| 0x17 || 0x1 || NodeCount&lt;br /&gt;
|-&lt;br /&gt;
| 0x18 || 0x200 (0x40 * 8) || [[#NodeInfo|Nodes]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x218 || 0x2 || Reserved&lt;br /&gt;
|-&lt;br /&gt;
| 0x21A || 0x2 || AdvertiseDataSize&lt;br /&gt;
|-&lt;br /&gt;
| 0x21C || 0x180 || AdvertiseData&lt;br /&gt;
|-&lt;br /&gt;
| 0x39C || 0x8C || Reserved&lt;br /&gt;
|-&lt;br /&gt;
| 0x428 || 0x8 || [6.0.0-?] Challenge (set to the output from [[ETicket_services|es]] cmd1501 during network creation) ([?+] only used internally, not exposed in LdnNetworkInfo anymore)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= NetworkInfo =&lt;br /&gt;
This is &amp;quot;nn::ldn::NetworkInfo&amp;quot;. This is a 0x480-byte struct.&lt;br /&gt;
&lt;br /&gt;
The fields listed as Reserved (besides the fields before +0x10) are cleared during the memset and are not written to again afterwards, with cmds which return NetworkInfo.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x20 || [[#NetworkId|NetworkId]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x20 || 0x30 || [[#CommonNetworkInfo|Common]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x50 || 0x430 || [[#LdnNetworkInfo|Ldn]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ScanFilter =&lt;br /&gt;
This is &amp;quot;nn::ldn::ScanFilter&amp;quot;. This is a 0x60-byte struct with 8-byte alignment.&lt;br /&gt;
&lt;br /&gt;
sdknso copies the input ScanFilter to a tmp struct on stack (with [[#ScanFilterFlag|Flag]] masking), which is then used with the cmd. sdknso only copies Bssid with [[#ScanPrivate|ScanPrivate]], with [[#Scan|Scan]] it also masks out the [[#ScanFilterFlag|Flag]] for Bssid.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x20 || [[#NetworkId|NetworkId]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x20 || 0x4 || NetworkType&lt;br /&gt;
|-&lt;br /&gt;
| 0x24 || 0x6 || [[#MacAddress|Bssid]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x2A || 0x22 || [[#Ssid|Ssid]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x4C || 0x10 || Reserved&lt;br /&gt;
|-&lt;br /&gt;
| 0x5C || 0x4 || [[#ScanFilterFlag|Flag]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Each [[#ScanFilterFlag|Flag]] bit when set enables using the corresponding ScanFilter data. This is usually a compare with the ScanFilter data and the internal [[#NetworkInfo|NetworkInfo]] data.&lt;br /&gt;
&lt;br /&gt;
* NetworkType: (ScanFilter_NetworkType &amp;amp; NetworkInfo_NetworkType) must be non-zero.&lt;br /&gt;
* Ssid: The length fields must match, then memcmp is used.&lt;br /&gt;
&lt;br /&gt;
The filtering func also handles validating the Band/Channel, however these fields are internal only and are not exposed in the user ScanFilter.&lt;br /&gt;
&lt;br /&gt;
= ScanFilterFlag =&lt;br /&gt;
This is &amp;quot;nn::ldn::ScanFilterFlag&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Value&lt;br /&gt;
!  Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || None&lt;br /&gt;
|-&lt;br /&gt;
| 0x1 || LocalCommunicationId&lt;br /&gt;
|-&lt;br /&gt;
| 0x2 || SessionId&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || NetworkType&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || Bssid&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || Ssid&lt;br /&gt;
|-&lt;br /&gt;
| 0x20 || SceneId&lt;br /&gt;
|-&lt;br /&gt;
| 0x21 || IntentId&lt;br /&gt;
|-&lt;br /&gt;
| 0x23 || NetworkId&lt;br /&gt;
|-&lt;br /&gt;
| 0x3F || All&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= NetworkConfig =&lt;br /&gt;
This is &amp;quot;nn::ldn::NetworkConfig&amp;quot;. This is a 0x20-byte struct with 8-byte alignment.&lt;br /&gt;
&lt;br /&gt;
sdknso copies the input NetworkConfig to a tmp struct on stack, which is then used with the cmd ([[#CreateNetwork]], [[#CreateNetworkPrivate]], [[#ConnectPrivate]]).&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x10 || [[#IntentId|IntentId]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x2 || Channel&lt;br /&gt;
|-&lt;br /&gt;
| 0x12 || 0x1 || NodeCountMax&lt;br /&gt;
|-&lt;br /&gt;
| 0x13 || 0x1 || Reserved&lt;br /&gt;
|-&lt;br /&gt;
| 0x14 || 0x2 || LocalCommunicationVersion&lt;br /&gt;
|-&lt;br /&gt;
| 0x16 || 0xA || Reserved&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= WirelessControllerRestriction =&lt;br /&gt;
This is &amp;quot;nn::ldn::WirelessControllerRestriction&amp;quot;. This is an u32 enum.&lt;br /&gt;
&lt;br /&gt;
This is used to determine the value passed to [[BTM_services|btm]] SetWlanMode.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Value&lt;br /&gt;
!  Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || Disabled&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Enabled&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= WirelessAudioRestriction =&lt;br /&gt;
This is &amp;quot;nn::ldn::WirelessAudioRestriction&amp;quot;. This is an u32 enum.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Value&lt;br /&gt;
!  Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || Disabled&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Enabled&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= SecurityMode =&lt;br /&gt;
This is &amp;quot;nn::ldn::SecurityMode&amp;quot;. This is an u32 enum.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Value&lt;br /&gt;
!  Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || Any&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Product&lt;br /&gt;
|-&lt;br /&gt;
| 2 || Debug&lt;br /&gt;
|-&lt;br /&gt;
| 3 || SystemDebug&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Value:&lt;br /&gt;
* 1-2: Broadcast Action frame data is encrypted.&lt;br /&gt;
* 3: Broadcast Action frame data is plaintext.&lt;br /&gt;
&lt;br /&gt;
* 1: Data frames are encrypted.&lt;br /&gt;
* 2-3: Data frames for normal data-transfer are plaintext - the network is Open.&lt;br /&gt;
&lt;br /&gt;
= SecurityConfig =&lt;br /&gt;
This is &amp;quot;nn::ldn::SecurityConfig&amp;quot;. This is a 0x44-byte struct with 2-byte alignment.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x2 || [[#SecurityMode|SecurityMode]] (overwritten by [[#CreateNetwork]]/[[#CreateNetworkPrivate]] and [[#Connect]]/[[#ConnectPrivate]], the value used internally by these cmds must be 1-3)&lt;br /&gt;
|-&lt;br /&gt;
| 0x2 || 0x2 || PassphraseSize (must be 0x10-0x40)&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || 0x40 || Passphrase (used with key derivation)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= SecurityParameter =&lt;br /&gt;
This is &amp;quot;nn::ldn::SecurityParameter&amp;quot;. This is a 0x20-byte struct with 1-byte alignment.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x10 || ServerRandom (used with the same key derivation as [[#SecurityConfig]])&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x10 || [[#SessionId|SessionId]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= UserConfig =&lt;br /&gt;
This is &amp;quot;nn::ldn::UserConfig&amp;quot;. This is a 0x30-byte struct with 1-byte alignment.&lt;br /&gt;
&lt;br /&gt;
An error is thrown if UserName+0x20 is non-zero.&lt;br /&gt;
&lt;br /&gt;
sdknso copies the input UserConfig to a tmp struct on stack, which is then used with the cmd. Only the first 0x20-bytes are copied, with the rest cleared.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x21 || UserName (NUL-terminated string for the user name)&lt;br /&gt;
|-&lt;br /&gt;
| 0x21 || 0xF || Reserved&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= AddressEntry =&lt;br /&gt;
This is &amp;quot;nn::ldn::AddressEntry&amp;quot;. This is a 0xC-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x4 || [[#Ipv4Address]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || 0x6 || [[#MacAddress|MacAddress]]&lt;br /&gt;
|-&lt;br /&gt;
| 0xA || 0x2 || Reserved&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= AcceptPolicy =&lt;br /&gt;
This is &amp;quot;nn::ldn::AcceptPolicy&amp;quot;. This is an u8.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Value&lt;br /&gt;
!  Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || AlwaysAccept&lt;br /&gt;
|-&lt;br /&gt;
| 1 || AlwaysReject&lt;br /&gt;
|-&lt;br /&gt;
| 2 || BlackList (addresses in the [[#AddAcceptFilterEntry|list]] are not allowed)&lt;br /&gt;
|-&lt;br /&gt;
| 3 || WhiteList (only addresses in the [[#AddAcceptFilterEntry|list]] are allowed)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ConnectOption =&lt;br /&gt;
This is &amp;quot;nn::ldn::ConnectOption&amp;quot;. This is an u32 bitmask.&lt;br /&gt;
&lt;br /&gt;
There&#039;s two versions of the sdknso funcs for [[#Connect]]/[[#ConnectPrivate]]: the version where the ConnectOption isn&#039;t user-specified uses a default value of 0x1 for it, with the same ShowError code without the bit0 check.&lt;br /&gt;
&lt;br /&gt;
When bit0 here is set after using the above cmds, the sdknso funcs will use [[Error_Applet|ShowError]] with the returned Result if: (rc &amp;amp; 0x3FE1FF) == 0xE0CB.&lt;br /&gt;
&lt;br /&gt;
This must be &amp;lt;=0x1, besides this validation ConnectOption is ignored by [[#Connect]]/[[#ConnectPrivate]].&lt;br /&gt;
&lt;br /&gt;
= DisconnectReason =&lt;br /&gt;
This is &amp;quot;nn::ldn::DisconnectReason&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Value&lt;br /&gt;
!  Description&lt;br /&gt;
|-&lt;br /&gt;
| -1 || Unknown&lt;br /&gt;
|-&lt;br /&gt;
| 0 || None&lt;br /&gt;
|-&lt;br /&gt;
| 1 || DisconnectedByUser&lt;br /&gt;
|-&lt;br /&gt;
| 2 || DisconnectedBySystem&lt;br /&gt;
|-&lt;br /&gt;
| 3 || DestroyedByUser&lt;br /&gt;
|-&lt;br /&gt;
| 4 || DestroyedBySystem&lt;br /&gt;
|-&lt;br /&gt;
| 5 || Rejected&lt;br /&gt;
|-&lt;br /&gt;
| 6 || SignalLost&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= OperationMode =&lt;br /&gt;
This is &amp;quot;nn::ldn::OperationMode&amp;quot;. This is an u32 enum.&lt;br /&gt;
&lt;br /&gt;
This controls bit1 in the value passed to [[WLAN_services|wlan:lcl]] cmd0/cmd1: bit1 = OperationMode==1.&lt;br /&gt;
&lt;br /&gt;
Value 1 seems to affect power (?) related fields in the beacon tags?&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Value&lt;br /&gt;
!  Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || Stable&lt;br /&gt;
|-&lt;br /&gt;
| 1 || HighSpeed&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Protocol =&lt;br /&gt;
This is &amp;quot;nn::ldn::Protocol&amp;quot;. This is an u32 enum.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Value&lt;br /&gt;
!  Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || Default&lt;br /&gt;
|-&lt;br /&gt;
| 1 || NX&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [20.0.0+] (NXAndOunce?)&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [S2] [20.0.0+]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
The Initialize* cmds configure state the same as using [[#SetProtocol|SetProtocol]] with Protocol NX.&lt;br /&gt;
&lt;br /&gt;
There&#039;s S2-only values which enables using Ounce-only keys. The following uses new Ounce-only keys (with S2 hosting):&lt;br /&gt;
* In-game ldn-usage for a S2-only Application.&lt;br /&gt;
* Local-game-update with a S2-only Application.&lt;br /&gt;
* Local-game-update for a S1-game which has a Nintendo Switch 2 Edition available, even without the S2-Edition being installed.&lt;br /&gt;
&lt;br /&gt;
There&#039;s system-titles which [[20.0.0|use]] SetProtocol. While there&#039;s game(s) which use SetProtocol, there&#039;s no known (?) games using Protocol3 (excluding GameShare which is system).&lt;br /&gt;
&lt;br /&gt;
[S2] Protocol2 and Protocol4 appear to be identical to Protocol3 except for using [[SPL_services|Ounce]] keys (?). The [[SPL_services|Generation]] is determined with the Protocol: Protocol2 is Generation 0, Protocol4 Generation 1. The following uses each Protocol:&lt;br /&gt;
* Protocol2: Mario Kart World&lt;br /&gt;
* Protocol4: lcs (local-content-share), Splatoon Raiders (this might be just due to the value used for [[LDN_services#SetProtocol|Default]] being bumped?)&lt;br /&gt;
&lt;br /&gt;
[S2] Keys are generated by passing the SHA256 hash as the KeySource to the relevant [[SPL_services|spl:ldn]] command with the above Generation, with the full hash being passed to the Ounce cmds. Only the first 0x10-bytes of the output key is used, since AES-128 is used even with Ounce.&lt;br /&gt;
&lt;br /&gt;
On NX, the Protocol [[#SetProtocol|permission-bitmask]] is always set to 0xA (1 and 3). On Ounce, all services have this set to 0x1E, except for one which has it set to 0xA (which is likely the one for S1-compat). 0x1E allows additional protocol values 2 and 4.&lt;br /&gt;
&lt;br /&gt;
= ActionFrameSettings =&lt;br /&gt;
This is &amp;quot;nn::ldn::ActionFrameSettings&amp;quot;. This is a 0x80-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x8 || LocalCommunicationId&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x34 || Reserved&lt;br /&gt;
|-&lt;br /&gt;
| 0x3C || 0x2 || SecurityMode&lt;br /&gt;
|-&lt;br /&gt;
| 0x3E || 0x2 || PassphraseSize (Must be 0x10-0x40)&lt;br /&gt;
|-&lt;br /&gt;
| 0x40 || 0x40 || Passphrase&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
SecurityMode must be 1-2. The same SecurityMode override functionality from elsewhere is used later with this.&lt;br /&gt;
&lt;br /&gt;
The same LocalCommunicationId override/validation from elsewhere is used with the input as well.&lt;br /&gt;
&lt;br /&gt;
= MessageFlagSet =&lt;br /&gt;
This is &amp;quot;nn::ldn::MessageFlagSet&amp;quot;. This is a BitFlagSet object for [[#MessageFlag]].&lt;br /&gt;
&lt;br /&gt;
= MessageFlag =&lt;br /&gt;
This is &amp;quot;nn::ldn::MessageFlag&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Value&lt;br /&gt;
!  Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[[#SendActionFrame|SendActionFrame]]/[[#RecvActionFrame|RecvActionFrame]] handles bit0 the same way as the MessageFlag with lp2p [[#SendToOtherGroup|SendToOtherGroup]]/[[#RecvFromOtherGroup|RecvFromOtherGroup]].&lt;br /&gt;
&lt;br /&gt;
= MacAddress =&lt;br /&gt;
This is &amp;quot;nn::lp2p::MacAddress&amp;quot;. Same as [[#MacAddress|MacAddress]].&lt;br /&gt;
&lt;br /&gt;
= GroupId =&lt;br /&gt;
This is &amp;quot;nn::lp2p::GroupId&amp;quot;. This is a 6-byte struct with 1-byte alignment.&lt;br /&gt;
&lt;br /&gt;
This is a WiFi BSSID.&lt;br /&gt;
&lt;br /&gt;
= NodeInfo =&lt;br /&gt;
This is &amp;quot;nn::lp2p::NodeInfo&amp;quot;. This is a 0x80-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || || &amp;lt;code&amp;gt;struct sockaddr&amp;lt;/code&amp;gt; for the IP address.&lt;br /&gt;
|-&lt;br /&gt;
| 0x24 || 0x6 || [[#MacAddress_2|MacAddress]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= GroupInfo =&lt;br /&gt;
This is &amp;quot;nn::lp2p::GroupInfo&amp;quot;. This is a 0x200-byte struct.&lt;br /&gt;
&lt;br /&gt;
[[Mario Kart Live: Home Circuit|mklive]] sets the SSID to a string generated from random data.&lt;br /&gt;
&lt;br /&gt;
[[#Scan_2|Scan]] only uses the following fields for the cmd input struct: SupportedPlatform/Priority, Frequency/Channel, and PresharedKeyBinarySize/PresharedKey.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x10 || Wrapped master key. When zero, set to randomly-generated data. This is decrypted with a &amp;quot;static AES key&amp;quot; and used to derive the 4 encryption keys for the session.&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x8 || LocalCommunicationId. When zero, the value from control.nacp is loaded. This is later validated by [[#Join]]/[[#CreateGroup]] the same way as the [[#NetworkConfig]] field. Used during key derivation to derive keys B and D.&lt;br /&gt;
|-&lt;br /&gt;
| 0x18 || 0x6 || [[#GroupId]] (&amp;quot;GROUP ID  (BSSID)&amp;quot;). When zero, the default is used. The default should be used here: an error is thrown if the data here doesn&#039;t match the output from [[WLAN_services|wlan:lcl]] cmd2.&lt;br /&gt;
|-&lt;br /&gt;
| 0x1E || 0x21 || ServiceName (&amp;quot;GROUP NAME (SSID)&amp;quot;). NUL-terminated string. See below.&lt;br /&gt;
|-&lt;br /&gt;
| 0x3F || 0x1 || s8 Flags count. Must be &amp;lt;=0x3F.&lt;br /&gt;
|-&lt;br /&gt;
| 0x40 || 0x40 || Array of s8 with the above count. Each entry value must be &amp;lt;=0x3F. Each entry is an array index used to load a set of flags from a global array with the specified index. global_flags are also masked with flags loaded from here. User-processes use entryval=1 as the default, with [11.0.0+] entryval=0 can be used for standard WPA2-PSK (see +0x8A).&lt;br /&gt;
|-&lt;br /&gt;
| 0x80 || 0x1 || SupportedPlatform. Must match value 1. 0 is PlatformIdNX, 1 is PlatformIdRcd.&lt;br /&gt;
|-&lt;br /&gt;
| 0x81 || 0x1 || MemberCountMax. s8, Must be &amp;lt;=0x8. During group creation this is passed to [[WLAN_services|wlan:lcl]] cmd40, when this is value 0 a default of value 1 is passed. During group-creation when the below +0x88 field is not value 0x2, the passed [[BTM_services#SetWlanMode|WlanMode]] is &amp;lt;code&amp;gt;x81_field_val &amp;gt; 3&amp;lt;/code&amp;gt;.&lt;br /&gt;
|-&lt;br /&gt;
| 0x82 || 0x1 || &lt;br /&gt;
|-&lt;br /&gt;
| 0x84 || 0x2 || Frequency. Wifi frequency: 24 = 2.4GHz, 50 = 5GHz.&lt;br /&gt;
|-&lt;br /&gt;
| 0x86 || 0x2 || s16 Channel (&amp;quot;CHANNEL&amp;quot;). Wifi channel number. 0 = use default, otherwise this must be one of the following depending on the frequency field:&lt;br /&gt;
* 24: 1, 6, 11.&lt;br /&gt;
* 50: 36, 40, 44, 48.&lt;br /&gt;
|-&lt;br /&gt;
| 0x88 || 0x1 || NetworkMode. Used during group-creation to determine the [[BTM_services#SetWlanMode|WlanMode]] to use. When this is value 0x2, mode=3 is used, otherwise it&#039;s determined via the +0x81 field.&lt;br /&gt;
|-&lt;br /&gt;
| 0x89 || 0x1 || PerformanceRequirement.&lt;br /&gt;
|-&lt;br /&gt;
| 0x8A || 0x1 || Security type, used during key derivation. 0 = use defaults, 1 = plaintext, 2 = encrypted. [11.0.0+] 3: Standard WPA2-PSK.&lt;br /&gt;
|-&lt;br /&gt;
| 0x8B || 0x1 || StaticAesKeyIndex. s8, used as the array-index for selecting the KeySource used with [[SPL_services#GenerateAesKek|GenerateAesKek]] during key derivation. Should be 1-2, otherwise GenerateAesKek is skipped and zeros are used for the AccessKey instead.&lt;br /&gt;
|-&lt;br /&gt;
| 0x8D || 0x1 || Priority. Must match one of the following, depending on the used service (doesn&#039;t apply to [[#Join]]): 55 = SystemPriority (lp2p:sys), 90 = ApplicationPriority (lp2p:app and lp2p:sys).&lt;br /&gt;
|-&lt;br /&gt;
| 0x8E || 0x1 || StealthEnabled. Bool flag, controls whether the SSID is hidden.&lt;br /&gt;
|-&lt;br /&gt;
| 0x8F || 0x1 || If zero, a default value of 0x20 is used.&lt;br /&gt;
|-&lt;br /&gt;
| 0x1C0 || 0x1 || PresharedKeyBinarySize. Must be 0x20 for PresharedKeyBinary. [11.0.0+] With WPA2-PSK, this must be value 1.&lt;br /&gt;
|-&lt;br /&gt;
| 0x1C1 || 0x3F ([9.0.0-10.2.0] 0x20) || PresharedKey. Used to derive encryption keys A and C. [11.0.0+] With WPA2-PSK, this is the passphrase string (length must be at least 8).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
In order for the ServiceName to be valid without a new one being generated, the following checks must pass:&lt;br /&gt;
* It loops through the characters in the string, looking for the first &#039;_&#039; character:&lt;br /&gt;
** The loop will exit once a &#039;_&#039; character is found.&lt;br /&gt;
** The character must be &#039;-&#039;, or alphanumeric (lowercase/uppercase), otherwise the function will immediately return failure.&lt;br /&gt;
** The loop will also exit once string_pos is &amp;gt;19, in which case the function will also immediately return failure.&lt;br /&gt;
* Then it checks the 11 characters which follow the above:&lt;br /&gt;
** The character must be hex: &#039;0&#039;-&#039;9&#039;, or &#039;A-F&#039; / &#039;a-&#039;f.&lt;br /&gt;
* The following character must be a NUL-terminator.&lt;br /&gt;
* The last hex character above, then the characters for the whole string prior to the last hex character are summed. return sum % 0x2B == 0. u32 is used for these calculations. (Return success when sum is a multiple of 0x2B, otherwise return failure)&lt;br /&gt;
&lt;br /&gt;
If the above fails, then the following runs, otherwise it just returns 0:&lt;br /&gt;
* It loops through the characters in the string.&lt;br /&gt;
** The character must be &#039;-&#039;, or alphanumeric (lowercase/uppercase), otherwise the function will immediately return failure.&lt;br /&gt;
** The loop will exit once string_pos&amp;gt;20 is reached, or when a NUL-terminator is reached.&lt;br /&gt;
* Once finished, success is returned if string_pos-1 is &amp;lt;20, otherwise failure is returned (which also immediately occurs if the first character is a NUL-terminator).&lt;br /&gt;
&lt;br /&gt;
If the above fails, an error is returned, otherwise a new ServiceName is generated:&lt;br /&gt;
* Up to 20 characters are copied from the original ServiceName to the output ServiceName, stopping once the limit is reached or when a NUL-terminator is reached.&lt;br /&gt;
* &#039;_&#039; is appended to the string.&lt;br /&gt;
* &amp;lt;code&amp;gt;nn::util::TSNPrintf({strptr following the above character}, {remaining size}, &amp;quot;%02X%02X%02X%02X%02X&amp;quot;, [[#GroupId|GroupId_byte3]], [[#GroupId|GroupId_byte4]], [[#GroupId|GroupId_byte5]], ([[SPL_services#IsDevelopment|IsDevelopment]] ? 0x80 : 0) | 0x1, 0);&amp;lt;/code&amp;gt;&lt;br /&gt;
* Then the last character is set to the output from a calling a function:&lt;br /&gt;
** All string characters which were already written are summed same way as above. Then: &amp;lt;code&amp;gt;return character_lookup_table[sum % 0x2B];&amp;lt;/code&amp;gt; (If the length passed to this function is 0, this will instead just return character_lookup_table[0])&lt;br /&gt;
*** character_lookup_table contains 0x2B entries: [V-A][k-a][5-0][Z-W].&lt;br /&gt;
&lt;br /&gt;
loaded_flags are first loaded from elsewhere, then masked with the above flags when available. loaded_flags are used when +0x8A is 0. global_flags are loaded from global data. These flags are only used with [[#CreateGroup]]/[[#Join]]. Flags (note that the following was updated with [11.0.0+], and differs from below):&lt;br /&gt;
* Bit2 clear:&lt;br /&gt;
** global_flags must be non-zero, and loaded_flags bit1 must be set.&lt;br /&gt;
** u8 +0x8A is set to value 1.&lt;br /&gt;
** When the cached [[SPL_services#IsDevelopment|IsDevelopment]] value is false (retail), an error is thrown.&lt;br /&gt;
** u8 +0x8B is set to value 0.&lt;br /&gt;
* Otherwise, if bit2 is set:&lt;br /&gt;
** u8 +0x8A is set to value 2.&lt;br /&gt;
** global_flags bit1 set:&lt;br /&gt;
*** u8 +0x8B is set to value 1.&lt;br /&gt;
** Otherwise, if global_flags bit2 is set:&lt;br /&gt;
*** u8 +0x8B is set to value 2.&lt;br /&gt;
&lt;br /&gt;
= ScanResult =&lt;br /&gt;
This is &amp;quot;nn::lp2p::ScanResult&amp;quot;. This is a 0x300-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x200 || [[#GroupInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x200 || 0x1 || &lt;br /&gt;
|-&lt;br /&gt;
| 0x206 || 0x2 || AdvertiseData size.&lt;br /&gt;
|-&lt;br /&gt;
| 0x208 || 0x80 || AdvertiseData&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Network protocol =&lt;br /&gt;
== ldn ==&lt;br /&gt;
A beacon and Action frame are broadcasted. The SSID in the beacon is hidden (32-bytes with value 0). For [[#Scan]]/[[#ScanPrivate]] it doesn&#039;t matter if no beacon is available ([[#NetworkInfo]] is the same), as long as the Action frame is broadcasted. However, the Station will not send a probe-request during connection if no beacon is available (and therefore not attempt any communication with the AccessPoint). The beacon doesn&#039;t have any custom Nintendo data, that data is in the Action frame.&lt;br /&gt;
&lt;br /&gt;
During connection, the Station first sends a probe-request using the [[#NetworkInfo|generated]] SSID from the Action frame. If the probe-response contains the expected data for the [[#SecurityConfig]] type, the Station then proceeds to connect to the AccessPoint.&lt;br /&gt;
&lt;br /&gt;
Keys are derived with: &amp;lt;code&amp;gt;GenerateAesKek(AccessKey, KeySource, Generation, Option=0); GenerateAesKey(out_key, AccessKey, {output from SHA256(data_to_hash)});&amp;lt;/code&amp;gt; The key for data-frames, if [[#SecurityConfig|enabled]], is derived from a buffer containing: {[[#SecurityParameter]]+0x0} followed by {[[#SecurityConfig]] Passphrase with the specified PassphraseSize}. The [[#ActionFrame]]/data-frame keys are derived roughly the same, the only difference is the data for hashing + the [[SPL_services|KeySource]]. The key derived by ldn is used directly as the static CCMP key for all data-frames (CCMP / MIC is standard). When [[#Protocol|Protocol]] is 3 the [[SPL_services|Generation]] is [[19.0.0|0x13]] instead of 0x0, for all of the previously mentioned keys derivation.&lt;br /&gt;
&lt;br /&gt;
Then the Station scans for an [[#ActionFrame]] for loading the [[#NetworkInfo]].&lt;br /&gt;
&lt;br /&gt;
Once connected, the AccessPoint sends Epigram-vendor Action frame(s) (same data) to the Station, the Station doesn&#039;t require these frames: &amp;lt;code&amp;gt;dd1afeedfacedeadbeef010000000a00000000000000000000000000&amp;lt;/code&amp;gt;. Then the Station must Authenticate with the AccessPoint, this is custom. The Station sends a frame (a maximum of 3 times in some cases if errors occur, with the same data), and the AccessPoint sends a response. Once Authenticated, the node is added to the [[#NodeInfo|NodeInfo]] array in [[#NetworkInfo]]. If the Station does not successfully Authenticate X-seconds after connecting, the AccessPoint disconnects the Station. If the Station fails to Authenticate, the Station itself will disconnect as well.&lt;br /&gt;
&lt;br /&gt;
After Authentication the Station will scan for another [[#ActionFrame]], with frame-comparision enabled with the above frame (frame must have been updated since the previous scan). The Station locates the index for a [[#MacAddress|MacAddress]] matching itself in the [[#NetworkInfo]] [[#NodeInfo|NodeInfo]] array (the entry for the AccessPoint is skipped), throwing an error if not found. After validating the LocalCommunicationVersion, it proceeds to handle ARP setup below.&lt;br /&gt;
&lt;br /&gt;
This does not use DHCP, each node on the network has to manually setup IP-config with the [[#NodeInfo|NodeInfo]] array in [[#NetworkInfo]]. [?+] After the client is [[#EthFrame|authenticated]] ARP may be used in some cases however.&lt;br /&gt;
&lt;br /&gt;
At this point standard sockets can be used over Data frames.&lt;br /&gt;
&lt;br /&gt;
=== EthFrame ===&lt;br /&gt;
The custom Ethernet frames have the following structure:&lt;br /&gt;
* &amp;quot;Type: IEEE 802a OUI Extended Ethertype (0x88b7)&amp;quot;&lt;br /&gt;
* &amp;quot;IEEE802a OUI Extended Ethertype&amp;quot;:&lt;br /&gt;
** &amp;quot;Organization Code: 00:22:aa (Nintendo Co., Ltd.)&amp;quot;&lt;br /&gt;
** &amp;quot;Protocol ID: {...}&amp;quot;&lt;br /&gt;
*** Depends on the frame:&lt;br /&gt;
*** 0x0102: [[#Authentication]]&lt;br /&gt;
*** 0x0103: ?&lt;br /&gt;
* The first byte of Data is value 0, then the ProtocolID-specific data follows, see below.&lt;br /&gt;
** ProtocolID 0x0103 frames are sent by the AccessPoint to the Station. This is 0x20-bytes of zeros, except for the first byte which is 0x3. This is sent by the AccessPoint prior to destroying the network.&lt;br /&gt;
&lt;br /&gt;
==== Authentication ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x1 || [[#AuthVersion]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x1 || 0x1 || Low u8 for the size.&lt;br /&gt;
|-&lt;br /&gt;
| 0x2 || 0x1 || Status. 0 = success, non-zero = error.&lt;br /&gt;
|-&lt;br /&gt;
| 0x3 || 0x1 || [2.0.0+] bool flag. The AccessPoint verifies that this is not set. Always set to 1 by the AccessPoint in the response. [2.0.0-?] The Station only uses this when the [[#AuthVersion]] is &amp;gt;=2.&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || 0x1 || [6.0.0+] High u8 for the size.&lt;br /&gt;
|-&lt;br /&gt;
| 0x5 || 0x1 || [20.0.0+] AuthEncryptionType, must match the type being used by the [[#Protocol|Protocol]]. 0 = plaintext ([[#Protocol|Protocol]] NX), 1 = AES-128-GCM ([[#Protocol|Protocol]] non-NX).&lt;br /&gt;
|-&lt;br /&gt;
| 0x6 || 0x2 || Unused, zeros.&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x20 || [[#NetworkInfo]]+0, must match the corresponding data in [[#NetworkInfo]] when the receiving node verifies this. With the &lt;br /&gt;
AccessPoint-&amp;gt;Station frame, the Station verifies that this matches the data previously sent to the AccessPoint.&lt;br /&gt;
|-&lt;br /&gt;
| 0x28 || 0x10 || [[#NetworkInfo]]+0x50, must match the corresponding data in [[#NetworkInfo]] when the receiving node verifies this. With the &lt;br /&gt;
AccessPoint-&amp;gt;Station frame, the Station verifies that this matches the data previously sent to the AccessPoint.&lt;br /&gt;
|-&lt;br /&gt;
| 0x38 || 0x10 || AuthEncryptionType1: Used for key derivation.&lt;br /&gt;
Station-&amp;gt;AccessPoint: The Station sets this to random data. Unused by the AccessPoint (besides the above), except for copying into the response.&lt;br /&gt;
&lt;br /&gt;
AccessPoint-&amp;gt;Station: +0x38 from the data originally sent by the Station. The Station verifies that this matches the previously sent data.&lt;br /&gt;
|-&lt;br /&gt;
| 0x48 || 0x10 || Only present with AuthEncryptionType1: AES-128-GCM MAC tag.&lt;br /&gt;
|-&lt;br /&gt;
| 0x48 (0x58 with AuthEncryptionType1) || || Frame-specific payload data, with the above size. The total frame size - {offset of the start of this data in the frame} must match the above size.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
The Station sets the above size to 0x40 ([6.0.0+] if [[#NetworkInfo]]+0x13 is &amp;lt;3) ([?+] 0x64 regardless of [[#AuthVersion]]). [6.0.0+] The Authentication challenge is only used/enabled if that value is &amp;gt;=3, and [[#IUserLocalCommunicationService]] is being used.&lt;br /&gt;
&lt;br /&gt;
The AccessPoint sets the above size to 0x40 ([6.0.0+] 0x0 if the +0x0 [[#AuthVersion]] is &amp;lt;3) ([?+] 0x84 regardless of [[#AuthVersion]]). [6.0.0+] The AccessPoint will only use/enable the Authentication challenge when the +0x0 [[#AuthVersion]] is &amp;gt;=3, and [[#IUserLocalCommunicationService]] is being used. This data will not be included in the frame if the status field indicates error.&lt;br /&gt;
&lt;br /&gt;
[6.0.0+] Support for the Authentication challenge with [[ETicket_services|es]] cmds 1501-1504 was added.&lt;br /&gt;
&lt;br /&gt;
AuthEncryptionType1: The key is derived essentially the same as the data-frame CCMP key, except the input data for hashing is the 0x10-bytes at +0x38 (this also only supports using [[SPL_services|Generation]] 0x13, returning immediately if the input param indicates otherwise due to the [[#Protocol|Protocol]]). The encrypted AES-128-GCM data starts at +0x58 with the above size. The 0xC-bytes IV is at +0x0, the AAD is at +0x0 size 0x48-bytes.&lt;br /&gt;
&lt;br /&gt;
The AccessPoint will not respond to frames where the source mac-address is unrecognized.&lt;br /&gt;
&lt;br /&gt;
Station-&amp;gt;AccessPoint payload data, relative to frame_end above (frame size depends on whether the challenge is enabled):&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x20 || [[#UserConfig]]+0. Copied into state by the AccessPoint.&lt;br /&gt;
|-&lt;br /&gt;
| 0x20 || 0x2 || Big-endian LocalCommunicationVersion. Byte-swapped by the AccessPoint then copied into state. [?+] This is now ignored.&lt;br /&gt;
|-&lt;br /&gt;
| 0x22 || 0x1 || [19.0.0+] [[#NodeInfo|NodeInfo]] +0x2D. Copied into state by the AccessPoint. On NX the Station always sets this to 0 in the sent payload-data.&lt;br /&gt;
|-&lt;br /&gt;
| 0x23 || 0x1D || Zeros, unused by the AccessPoint.&lt;br /&gt;
|-&lt;br /&gt;
| 0x40 || 0x24 || [6.0.0+] Zeros, unused by the AccessPoint.&lt;br /&gt;
|-&lt;br /&gt;
| 0x64 || 0x300 || [6.0.0+] Authentication challenge data. If enabled, the total frame size must be &amp;gt;= {end offset of this data in the frame}. The frame data does not include this if it&#039;s not enabled.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
AccessPoint-&amp;gt;Station response payload data, relative to frame_end above (frame size depends on whether the challenge is enabled):&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x1 || Unused, always set to 0. [S2] This is usually set to value 1?&lt;br /&gt;
|-&lt;br /&gt;
| 0x1 || 0x3F || Zeros. [6.0.0-?] Only included in the frame if it&#039;s enabled (+0x0 [[#AuthVersion]] &amp;gt;= 3). Unused by the Station.&lt;br /&gt;
|-&lt;br /&gt;
| 0x40 || 0x44 || [6.0.0-?] Only included in the frame if it&#039;s enabled (+0x0 [[#AuthVersion]] &amp;gt;= 3). Unused by the Station.&lt;br /&gt;
|-&lt;br /&gt;
| 0x84 || 0x100 || [6.0.0+] If enabled, Authentication challenge response data. Not included in the frame if it&#039;s not enabled.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
===== AuthVersion =====&lt;br /&gt;
Must be 0x1-0xF (&amp;lt;0x10 with newer versions).&lt;br /&gt;
&lt;br /&gt;
[?+] When the AccessPoint is handling the [[#Authentication|Authentication]] EthFrame, the AuthVersion must be &amp;gt;=1 for [[#Protocol|Protocol]] NX, and &amp;gt;=4 for [[#Protocol|Protocol]] 3.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value || SystemVersion&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [1.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [2.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [6.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [19.0.0+]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== ActionFrame ===&lt;br /&gt;
The Action frames have the following structure:&lt;br /&gt;
* &amp;quot;Fixed parameters&amp;quot;:&lt;br /&gt;
** &amp;quot;Category code: Vendor Specific (127)&amp;quot;&lt;br /&gt;
** &amp;quot;OUI: 00:22:aa (Nintendo Co., Ltd.)&amp;quot;&lt;br /&gt;
* The Data starts with the following header:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x2 || 04 00 in sent frames.&lt;br /&gt;
|-&lt;br /&gt;
| 0x2 || 0x2 || Protocol ID, must be 0x0101.&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || 0x2 || Must be 0.&lt;br /&gt;
|-&lt;br /&gt;
| 0x6 || 0x2 || Zeros, unused.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Then the actual data follows:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x20 || [[#NetworkInfo]]+0x0. The u64/u16 are big-endian. Outside of [[#Scan]]/[[#ScanPrivate]], this must match the previously loaded data for this.&lt;br /&gt;
|-&lt;br /&gt;
| 0x20 || 0x1 || [[#AuthVersion]]. Copied to [[#NetworkInfo]]+0x63. When comparing with a previous frame is enabled, this must match the value from the previous frame.&lt;br /&gt;
|-&lt;br /&gt;
| 0x21 || 0x1 || Encryption type: 1 = plaintext, 2 = AES-128-CTR, [20.0.0+] 3 = AES-128-GCM, {frames with other values are ignored by [[#Scan]]/[[#ScanPrivate]]}. Must match the type which is currently being used: with [[#Scan]]/[[#ScanPrivate]] this is determined via this field, otherwise [[#SecurityConfig]] is used to determine this.&lt;br /&gt;
|-&lt;br /&gt;
| 0x22 || 0x2 || Big-endian u16 size for the data starting at +0x48 (+0x38 with EncryptionType3), and must match {total frame size relative to +0x0 above} - {header_size}.&lt;br /&gt;
|-&lt;br /&gt;
| 0x24 || 0x4 || Big-endian u32 Counter. The initial value is randomly-generated. This is incremented each time the below content is updated (including initial creation). Also used by the Station to determine whether the frame changed compared to a previous one. When comparing against a previous frame, new_counter-prev_counter must be &amp;lt;= 0xFF, and the counters must not match.&lt;br /&gt;
|-&lt;br /&gt;
| 0x28 || 0x20 || EncryptionType1-2: SHA256 hash over the entire frame starting at +0x0, with the above size + 0x48. During hashing, this hash is cleared, with the new hash overwriting the original in memory (the original is copied to stack for comparing).&lt;br /&gt;
|-&lt;br /&gt;
| 0x28 || 0x10 || EncryptionType3: AES-128-GCM MAC tag (replaces the SHA256 hash).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Using EncryptionType3 outside of [[#Scan]]/[[#ScanPrivate]] is enabled with [[#Protocol|Protocol]] non-NX.&lt;br /&gt;
&lt;br /&gt;
When encryption is enabled, the encrypted data is at +0x28 (+0x38 with EncryptionType3) with size {remaining frame size}. The key is derived from the raw 0x20-bytes at +0x0. The CTR/IV is {raw Counter above without byte-swap}, with the rest cleared to zeros. The AAD for AES-128-GCM is at +0x0 size 0x28-bytes.&lt;br /&gt;
&lt;br /&gt;
Originally [[#Scan]]/[[#ScanPrivate]] used the EncryptionType field to determine encryption handling. With [18.0.0+] these now set an internal SecurityMode field to 0 (Any) initially, then later uses the same SecurityMode override as [[#CreateNetwork|CreateNetwork]]. The internal SecurityMode field is used to determine encryption handling: Any uses the EncryptionType field like before. With non-zero the encryption handling is determined as required by the SecurityMode.&lt;br /&gt;
&lt;br /&gt;
The content data at +{above_header_size} follows, which has the size specified above (which must be &amp;gt;=0x500 with EncryptionType1-2), where all fields are big-endian. For EncryptionType1-2:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x10 || [[#NetworkInfo]]+0x50&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x2 || [[#NetworkInfo]]+0x60&lt;br /&gt;
|-&lt;br /&gt;
| 0x12 || 0x1 || [[#NetworkInfo]]+0x62&lt;br /&gt;
|-&lt;br /&gt;
| 0x13 || 0x1 || Unused&lt;br /&gt;
|-&lt;br /&gt;
| 0x14 || 0x2 || &lt;br /&gt;
|-&lt;br /&gt;
| 0x16 || 0x1 || s8 [[#NetworkInfo]]+0x66, clamped to range 1-8.&lt;br /&gt;
|-&lt;br /&gt;
| 0x17 || 0x1 || s8 [[#NetworkInfo]]+0x67, clamped to range 1-8.&lt;br /&gt;
|-&lt;br /&gt;
| 0x18 || 0x1C0(0x38*8) || Array of the below node struct.&lt;br /&gt;
|-&lt;br /&gt;
| 0x1D8 || 0x2 || Unused&lt;br /&gt;
|-&lt;br /&gt;
| 0x1DA || 0x2 || [[#NetworkInfo]]+0x26A&lt;br /&gt;
|-&lt;br /&gt;
| 0x1DC || 0x180 || [[#NetworkInfo]]+0x26C&lt;br /&gt;
|-&lt;br /&gt;
| 0x35C || 0x19C || Unused&lt;br /&gt;
|-&lt;br /&gt;
| 0x4F8 || 0x8 || [6.0.0+] [[#NetworkInfo]]+0x478&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
For EncryptionType3:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x10 || [[#NetworkInfo]]+0x50&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x8 || [[#NetworkInfo]]+0x478 [S2] The Station seems to verify that this is 0 when the Challenge is unused (ldn:s)? Throws an error if set before connecting to an [[#Protocol|Ounce]] network.&lt;br /&gt;
|-&lt;br /&gt;
| 0x18 || 0x1 || [[#NetworkInfo]]+0x60&lt;br /&gt;
|-&lt;br /&gt;
| 0x19 || 0x1 || [[#NetworkInfo]]+0x62&lt;br /&gt;
|-&lt;br /&gt;
| 0x1A || 0x2 || s16 LocalCommunicationVersion. Must not be negative.&lt;br /&gt;
|-&lt;br /&gt;
| 0x1C || 0x8 || Unused?&lt;br /&gt;
|-&lt;br /&gt;
| 0x24 || 0x2 || Same as +0x14 in the above struct for EncryptionType1-2.&lt;br /&gt;
|-&lt;br /&gt;
| 0x26 || 0x1 || s8 [[#NetworkInfo]]+0x66 (NodeCountMax)&lt;br /&gt;
|-&lt;br /&gt;
| 0x27 || 0x1 || s8 [[#NetworkInfo]]+0x67 (NodeCount)&lt;br /&gt;
|-&lt;br /&gt;
| 0x28 || NodeCount*0x30 || Array of the below node struct.&lt;br /&gt;
|-&lt;br /&gt;
| 0x28 + (NodeCount*0x30) || 0x2 || [[#NetworkInfo]]+0x26A (AdvertiseDataSize)&lt;br /&gt;
|-&lt;br /&gt;
| 0x2A + (NodeCount*0x30) || AdvertiseDataSize || [[#NetworkInfo]]+0x26C (AdvertiseData)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
The data here is copied into [[#NetworkInfo]].&lt;br /&gt;
&lt;br /&gt;
Node data used in the above array (all fields big-endian), which are copied into the [[#NetworkInfo]] [[#NodeInfo|NodeInfo]] array. For EncryptionType1-2:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x4 || [[#Ipv4Address]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || 0x6 || [[#MacAddress|MacAddress]]&lt;br /&gt;
|-&lt;br /&gt;
| 0xA || 0x1 || bool IsConnected&lt;br /&gt;
|-&lt;br /&gt;
| 0xB || 0x1 || [19.0.0+] [[#NodeInfo|NodeInfo]] +0x2D&lt;br /&gt;
|-&lt;br /&gt;
| 0xC || 0x20 || First 0x20-bytes of [[#UserConfig]].&lt;br /&gt;
|-&lt;br /&gt;
| 0x2C || 0x2 || s16 LocalCommunicationVersion &lt;br /&gt;
|-&lt;br /&gt;
| 0x2E || 0xA || Unused&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
For EncryptionType3:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x4 || [[#Ipv4Address]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || 0x6 || [[#MacAddress|MacAddress]]&lt;br /&gt;
|-&lt;br /&gt;
| 0xA || 0x1 || NodeId&lt;br /&gt;
|-&lt;br /&gt;
| 0xB || 0x1 || [[#NodeInfo|NodeInfo]] +0x2D&lt;br /&gt;
|-&lt;br /&gt;
| 0xC || 0x20 || First 0x20-bytes of [[#UserConfig]].&lt;br /&gt;
|-&lt;br /&gt;
| 0x2C || 0x4 || Unused&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== ActionFrame2 ===&lt;br /&gt;
The Action frames used by [[#SendActionFrame|SendActionFrame]]/[[#RecvActionFrame|RecvActionFrame]] have the following structure:&lt;br /&gt;
* &amp;quot;Fixed parameters&amp;quot;:&lt;br /&gt;
** &amp;quot;Category code: Vendor Specific (127)&amp;quot;&lt;br /&gt;
** &amp;quot;OUI: 00:22:aa (Nintendo Co., Ltd.)&amp;quot;&lt;br /&gt;
* The Data starts with the following header:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x2 || 04 00&lt;br /&gt;
|-&lt;br /&gt;
| 0x2 || 0x2 || Protocol ID, must match big-endian 0x0102.&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || 0x2 || 00 00&lt;br /&gt;
|-&lt;br /&gt;
| 0x6 || 0x2 || 00 00&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Then the actual data follows (all fields big-endian):&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x1 || [[#AuthVersion]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x1 || 0x1 || EncryptionType, must match the expected type for the current SecurityMode. 1 = plaintext, 2 = AES-128-GCM.&lt;br /&gt;
|-&lt;br /&gt;
| 0x2 || 0x2 || Padding&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || 0x4 || Counter&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x8 || LocalCommunicationId&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x10 || Used with key derivation.&lt;br /&gt;
|-&lt;br /&gt;
| 0x20 || 0x10 || EncryptionType2: AES-128-GCM MAC tag.&lt;br /&gt;
|-&lt;br /&gt;
| 0x30 || Remaining frame size || Data payload&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
The 0xC-byte IV for AES-128-GCM is the raw 4-bytes from the above Counter, with the rest cleared to zeroes. The encrypted data is at +0x30, with the remaining frame size. The AAD is the 0x20-bytes at +0x0.&lt;br /&gt;
&lt;br /&gt;
The key is derived similar to the regular action-frame key (same KeySource), except: the Generation is always [[17.0.0|0x11]], with the following data for hashing: {big-endian LocalCommunicationId} {+0x10 size 0x10-bytes} {[[#ActionFrameSettings]] Passphrase with the specified PassphraseSize}.&lt;br /&gt;
&lt;br /&gt;
The data payload is the data buffer for [[#SendActionFrame|SendActionFrame]]/[[#RecvActionFrame|RecvActionFrame]].&lt;br /&gt;
&lt;br /&gt;
== lp2p ==&lt;br /&gt;
This is used for communicating with accessories (external devices on [11.0.0+]) over local wifi. [[Mario Kart Live: Home Circuit]] uses this. [11.0.0+] [[Album_Applet|LibraryAppletPhotoViewer]] uses this.&lt;br /&gt;
&lt;br /&gt;
A beacon is broadcasted.&lt;br /&gt;
&lt;br /&gt;
Action frames are only sent when done so by [[#SendToOtherGroup]] (other than the Epigram one mentioned below).&lt;br /&gt;
&lt;br /&gt;
Communication uses sockets with standard Data frames and the above Action frames. Switch consoles presumably only use the Action frames to communicate with each other?&lt;br /&gt;
&lt;br /&gt;
Key A derived by ldn-sysmodule is used directly as the static CCMP key for all data-frames (CCMP / MIC is standard). However, with [[#GroupInfo]]+0x8A value 3, standard WPA2-PSK is used instead.&lt;br /&gt;
&lt;br /&gt;
This uses infrastructure-mode (AccessPoint), and DHCP is used. The group-owner is the AccessPoint. Note that the probe response includes the same Nintendo tags included with the beacon. Once connected, the group-owner sends the same Epigram-vendor Action frame(s) described in [[#ldn]]. At this point socket communication can begin, including DHCP usage.&lt;br /&gt;
&lt;br /&gt;
The DHCP server thread is started by the &amp;quot;nn.lp2p.StateMachine&amp;quot; thread eventually during group [[#CreateGroup|creation]]. The DHCP Offer option values are the following:&lt;br /&gt;
* &amp;quot;Subnet Mask: 255.255.255.0&amp;quot;&lt;br /&gt;
* &amp;quot;DHCP Server Identifier: {...}&amp;quot;&lt;br /&gt;
* &amp;quot;Broadcast Address: {...}&amp;quot;&lt;br /&gt;
* &amp;quot;IP Address Lease Time: (5s) 5 seconds&amp;quot;&lt;br /&gt;
* &amp;quot;Renewal Time Value: (0s) 0 seconds&amp;quot;&lt;br /&gt;
* &amp;quot;Rebinding Time Value: (0s) 0 seconds&amp;quot;&lt;br /&gt;
* &amp;quot;Interface MTU: 1500&amp;quot;&lt;br /&gt;
&lt;br /&gt;
Note that the above options doesn&#039;t include &amp;quot;Domain Name Server&amp;quot; or &amp;quot;Router&amp;quot;, the client device may fail to connect if it doesn&#039;t allow those DHCP options to be missing.&lt;br /&gt;
&lt;br /&gt;
=== Beacon ===&lt;br /&gt;
The SSID in the beacon can optionally be [[#GroupInfo|hidden]] (all-zero with the same length as the original SSID). The beacon contains two vendor-specific Nintendo information elements with OUI &amp;lt;code&amp;gt;00:22:aa&amp;lt;/code&amp;gt;; each IE has a 2-byte ID following the OUI. These Nintendo IEs are not used when standard WPA2-PSK is being used.&lt;br /&gt;
&lt;br /&gt;
The beacon is identical to ldn, except for the following (besides SSID length difference and the lp2p-only Nintendo tags): &lt;br /&gt;
* &amp;quot;Tag: HT Capabilities (802.11n D1.10)&amp;quot;: &amp;quot;HT Short GI for 20MHz&amp;quot; is set to &amp;quot;Not supported&amp;quot;, for ldn it&#039;s &amp;quot;Supported&amp;quot;.&lt;br /&gt;
* &amp;quot;Tag: Vendor Specific: Microsoft Corp.: WMM/WME: Parameter Element&amp;quot; &amp;quot;Ac Parameters ACI 0&amp;quot;: &amp;quot;CW Min: 15&amp;quot; for lp2p, &amp;quot;CW Min: 63&amp;quot; for ldn.&lt;br /&gt;
&lt;br /&gt;
Note that during group creation the beacon may be missing the Nintendo IEs in some cases, since group creation didn&#039;t finish yet.&lt;br /&gt;
&lt;br /&gt;
==== Nintendo IE 0 ====&lt;br /&gt;
&lt;br /&gt;
The first Nintendo IE (ID 0x0600) contains the following fixed parameters:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x1 || Fixed 0x20; perhaps a version or other magic number.&lt;br /&gt;
|-&lt;br /&gt;
| 0x1 || 0x1 || [[#GroupInfo|SecurityType]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x2 || 0x1 || [[#GroupInfo|StaticAesKeyIndex]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x3 || 0x1 || Fixed zero; padding byte.&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || 0x8 || Big-endian (i.e. byte-reversed) version of [[#GroupInfo|LocalCommunicationId]]. This is the only context where LocalCommunicationId is reversed.&lt;br /&gt;
|-&lt;br /&gt;
| 0xC || 0x10 || Wrapped master key. Same as [[#GroupInfo]]+0x0.&lt;br /&gt;
|-&lt;br /&gt;
| 0x1C || 0x4 || If encryption is enabled, a randomly-generated nonce, else nothing. Appending 8 zero bytes to this yields the AES-GCM IV.&lt;br /&gt;
|-&lt;br /&gt;
| 0x20 || 0x10 || If encryption is enabled, the AES-GCM MAC tag, else nothing. All bytes prior to this (fixed 0x20 through nonce) are the additional authenticated data. All bytes after this are encrypted with key B.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
After this, TLV tagged parameters occur. Each TLV tag is formatted as:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x1 || Tag type&lt;br /&gt;
|-&lt;br /&gt;
| 0x1 || 0x1 || Length&lt;br /&gt;
|-&lt;br /&gt;
| 0x2 || {above size} || Data for the tag&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Known TLV tags:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Type&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x1 || 0x2 || Additional network parameters: 0xAB 0xCD. A=[[#GroupInfo]]+0x82, B=[[#GroupInfo|MemberCountMax]], C=[[#GroupInfo|NetworkMode]], D=[[#GroupInfo|PerformanceRequirement]].&lt;br /&gt;
|-&lt;br /&gt;
| 0x2 || 0x8 || Flags: Bitwise-or of (1&amp;lt;&amp;lt;f) for each entry in [[#GroupInfo]]+0x40&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Nintendo IE 1 ====&lt;br /&gt;
&lt;br /&gt;
The second Nintendo IE (ID 0x0601) contains only TLVs. If encryption is enabled, a 0x4-byte nonce and 0x10-byte AES-GCM tag are written first, as above, and the TLVs are encrypted. Key C is used.&lt;br /&gt;
&lt;br /&gt;
Known TLV tags:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Type&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x21 || Varies || AdvertiseData&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== ActionFrame ===&lt;br /&gt;
The Action frames have the following structure:&lt;br /&gt;
* &amp;quot;Fixed parameters&amp;quot;:&lt;br /&gt;
** &amp;quot;Category code: Vendor Specific (127)&amp;quot;&lt;br /&gt;
** &amp;quot;OUI: 00:22:aa (Nintendo Co., Ltd.)&amp;quot;&lt;br /&gt;
* The Data starts with the following:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x2 || Usually 06 00?&lt;br /&gt;
|-&lt;br /&gt;
| 0x2 || 0x2 || Usually 20 02?(Second byte depends on whether encryption is used?)&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || 0x2 || Usually 02 00?(varies)&lt;br /&gt;
|-&lt;br /&gt;
| 0x6 || 0x8 || Big-endian version of [[#GroupInfo]]+0x10.&lt;br /&gt;
|-&lt;br /&gt;
| 0xE || 0x10 || Same as [[#GroupInfo]]+0x0.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
When encryption is used, the remaining data is:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x4 || Big-endian u32 Counter. The initial value is randomly-generated (?). This is incremented with each sent Action frame.&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || {remaining size} || Encrypted user-data. Also includes 0x10-bytes of unknown data.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
When plaintext is used, the remaining data is:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || {remaining size} || Plaintext user-data.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Notes =&lt;br /&gt;
The following services are accessible to ldn:&lt;br /&gt;
* arp:r, bsd:s, btm, es, fatal:u, ifcfg, lm, nifm:s, pl:s, set:sys, spl:mig, wlan&lt;br /&gt;
&lt;br /&gt;
[S2] Access to btm and spl:mig were replaced with bt:sys and spl:ldn.&lt;br /&gt;
&lt;br /&gt;
[S2] Various objects/state have the same size/layout as S1, generally?(Other than IPC-related differences) There&#039;s also stack differences.&lt;br /&gt;
&lt;br /&gt;
== Code-region Memory Layout ==&lt;br /&gt;
=== S2 20.2.0 ===&lt;br /&gt;
This is the codebin-region layout for S2 ldn 20.2.0-20.5.0. BuildId is &amp;quot;DC456FA4...&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
The on-NX note is for the equivalent memregion location/size, memregion-size/contents compared to NX may vary.&lt;br /&gt;
&lt;br /&gt;
Total size is 0x24F000-bytes.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Permissions&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0xE1000 || --X || .text&lt;br /&gt;
|-&lt;br /&gt;
| 0xE1000 || 0x3D000 || R-- || RO-region&lt;br /&gt;
|-&lt;br /&gt;
| 0x11E000 || 0x3A000 || RW || On NX this is at 0xEF000. The main ExpHeap is at +0x2000, on NX it&#039;s at +0x1000.&lt;br /&gt;
|-&lt;br /&gt;
| 0x158000 || 0x8000 || non-RW || On NX this is at 0x123000.&lt;br /&gt;
|-&lt;br /&gt;
| 0x160000 || 0x8000 || RW || On NX this is at 0x12B000.&lt;br /&gt;
|-&lt;br /&gt;
| 0x168000 || 0xF000 || non-RW || On NX this is at 0x139000.&lt;br /&gt;
|-&lt;br /&gt;
| 0x177000 || 0x3000 || RW || On NX this is at 0x13F000.&lt;br /&gt;
|-&lt;br /&gt;
| 0x17A000 || 0x24000 || non-RW || On NX this is at 0x14B000.&lt;br /&gt;
|-&lt;br /&gt;
| 0x19E000 || 0x4E000 || RW || On NX this is at 0x16F000.&lt;br /&gt;
|-&lt;br /&gt;
| 0x1EC000 || 0x2000 || -- || On NX this is at 0x1BD000.&lt;br /&gt;
|-&lt;br /&gt;
| 0x1EE000 || 0x2000 || {accessible} || On NX this is at 0x1BF000.&lt;br /&gt;
|-&lt;br /&gt;
| 0x1EF000 || 0x5000 || -- || On NX this is at 0x1E2000.&lt;br /&gt;
|-&lt;br /&gt;
| 0x1F4000 || 0x21000 || {accessible} || On NX this is at 0x1EA000.&lt;br /&gt;
|-&lt;br /&gt;
| 0x218000 || 0x8000 || -- ||&lt;br /&gt;
|-&lt;br /&gt;
| 0x220000 || 0x2F000 || {accessible}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[[Category:Services]]&lt;/div&gt;</summary>
		<author><name>Yellows8</name></author>
	</entry>
	<entry>
		<id>https://switchbrew.org/w/index.php?title=LDN_services&amp;diff=14823</id>
		<title>LDN services</title>
		<link rel="alternate" type="text/html" href="https://switchbrew.org/w/index.php?title=LDN_services&amp;diff=14823"/>
		<updated>2026-07-26T03:25:05Z</updated>

		<summary type="html">&lt;p&gt;Yellows8: /* Protocol */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;LDN handles all local network communication.&lt;br /&gt;
&lt;br /&gt;
There&#039;s 2 IPC handler threads for all ldn:* services.&lt;br /&gt;
&lt;br /&gt;
= ldn:m =&lt;br /&gt;
This is &amp;quot;nn::ldn::detail::IMonitorServiceCreator&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This has IPC max_sessions 5.&lt;br /&gt;
&lt;br /&gt;
[20.2.0+] This has max_sessions 6. &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#CreateMonitorService|CreateMonitorService]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== CreateMonitorService ==&lt;br /&gt;
Returns an [[#IMonitorService]].&lt;br /&gt;
&lt;br /&gt;
The user-process closes the IMonitorServiceCreator object immediately after using this cmd.&lt;br /&gt;
&lt;br /&gt;
== IMonitorService ==&lt;br /&gt;
This is &amp;quot;nn::ldn::detail::IMonitorService&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#GetState|GetState]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#GetNetworkInfo|GetNetworkInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [[#GetIpv4Address|GetIpv4Address]]&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [[#GetDisconnectReason|GetDisconnectReason]]&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [[#GetSecurityParameter|GetSecurityParameter]]&lt;br /&gt;
|-&lt;br /&gt;
| 5 || [[#GetNetworkConfig|GetNetworkConfig]]&lt;br /&gt;
|-&lt;br /&gt;
| 100 || [[#Initialize]]&lt;br /&gt;
|-&lt;br /&gt;
| 101 || [[#Finalize]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== GetState ===&lt;br /&gt;
No input, returns an output [[#State|u32]].&lt;br /&gt;
&lt;br /&gt;
sdknso implements this by &amp;lt;code&amp;gt;return&amp;lt;/code&amp;gt;ing the u32, with 0 being returned on error.&lt;br /&gt;
&lt;br /&gt;
=== GetNetworkInfo ===&lt;br /&gt;
Takes a type-0x1A output buffer containing a [[#NetworkInfo]].&lt;br /&gt;
&lt;br /&gt;
=== GetIpv4Address ===&lt;br /&gt;
No input, returns an output [[#Ipv4Address]] and a [[#SubnetMask]].&lt;br /&gt;
&lt;br /&gt;
=== GetDisconnectReason ===&lt;br /&gt;
No input, returns an output s16.&lt;br /&gt;
&lt;br /&gt;
This is not exposed by sdknso.&lt;br /&gt;
&lt;br /&gt;
This just returns 0.&lt;br /&gt;
&lt;br /&gt;
=== GetSecurityParameter ===&lt;br /&gt;
No input, returns an output [[#SecurityParameter]].&lt;br /&gt;
&lt;br /&gt;
This is not exposed by sdknso.&lt;br /&gt;
&lt;br /&gt;
=== GetNetworkConfig ===&lt;br /&gt;
No input, returns an output [[#NetworkConfig]].&lt;br /&gt;
&lt;br /&gt;
This is not exposed by sdknso.&lt;br /&gt;
&lt;br /&gt;
=== Initialize ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
This is used immediately after object creation. Official sw will Abort if this fails.&lt;br /&gt;
&lt;br /&gt;
This just returns 0.&lt;br /&gt;
&lt;br /&gt;
=== Finalize ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
This is used during service exit, prior to closing the object. Official sw will Abort if this fails.&lt;br /&gt;
&lt;br /&gt;
This just returns 0.&lt;br /&gt;
&lt;br /&gt;
= ldn:s =&lt;br /&gt;
This is &amp;quot;nn::ldn::detail::ISystemServiceCreator&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This has IPC max_sessions 5.&lt;br /&gt;
&lt;br /&gt;
[18.0.0+] The sdknso uses SessionManager with this, where the additional session-count is 0x3.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#CreateSystemLocalCommunicationService|CreateSystemLocalCommunicationService]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [18.0.0+] [[#CreateClientProcessMonitor|CreateClientProcessMonitor]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== CreateSystemLocalCommunicationService ==&lt;br /&gt;
No input. Returns an [[#ISystemLocalCommunicationService]].&lt;br /&gt;
&lt;br /&gt;
The user-process closes the ISystemServiceCreator object once finished with it during initialization. Official sw ignores errors from this cmd.&lt;br /&gt;
&lt;br /&gt;
== CreateClientProcessMonitor ==&lt;br /&gt;
No input. Returns an [[#IClientProcessMonitor]].&lt;br /&gt;
&lt;br /&gt;
== ISystemLocalCommunicationService ==&lt;br /&gt;
This is &amp;quot;nn::ldn::detail::ISystemLocalCommunicationService&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#GetState_2|GetState]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#GetNetworkInfo_2|GetNetworkInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [[#GetIpv4Address_2|GetIpv4Address]]&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [[#GetDisconnectReason_2|GetDisconnectReason]]&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [[#GetSecurityParameter_2|GetSecurityParameter]]&lt;br /&gt;
|-&lt;br /&gt;
| 5 || [[#GetNetworkConfig_2|GetNetworkConfig]]&lt;br /&gt;
|-&lt;br /&gt;
| 100 || [[#GetStateChangeEvent|GetStateChangeEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 101 || [[#GetNetworkInfoAndHistory|GetNetworkInfoAndHistory]]&lt;br /&gt;
|-&lt;br /&gt;
| 102 || [[#Scan|Scan]]&lt;br /&gt;
|-&lt;br /&gt;
| 103 || [[#ScanPrivate|ScanPrivate]]&lt;br /&gt;
|-&lt;br /&gt;
| 104 || [5.0.0+] [[#SetWirelessControllerPolicy|SetWirelessControllerPolicy]]&lt;br /&gt;
|-&lt;br /&gt;
| 105 || [13.1.0+] [[#SetWirelessAudioPolicy|SetWirelessAudioPolicy]]&lt;br /&gt;
|-&lt;br /&gt;
| 106 || [18.0.0+] [[#SetProtocol|SetProtocol]]&lt;br /&gt;
|-&lt;br /&gt;
| 200 || [[#OpenAccessPoint|OpenAccessPoint]]&lt;br /&gt;
|-&lt;br /&gt;
| 201 || [[#CloseAccessPoint|CloseAccessPoint]]&lt;br /&gt;
|-&lt;br /&gt;
| 202 || [[#CreateNetwork|CreateNetwork]]&lt;br /&gt;
|-&lt;br /&gt;
| 203 || [[#CreateNetworkPrivate|CreateNetworkPrivate]]&lt;br /&gt;
|-&lt;br /&gt;
| 204 || [[#DestroyNetwork|DestroyNetwork]]&lt;br /&gt;
|-&lt;br /&gt;
| 205 || [[#Reject|Reject]]&lt;br /&gt;
|-&lt;br /&gt;
| 206 || [[#SetAdvertiseData|SetAdvertiseData]]&lt;br /&gt;
|-&lt;br /&gt;
| 207 || [[#SetStationAcceptPolicy|SetStationAcceptPolicy]]&lt;br /&gt;
|-&lt;br /&gt;
| 208 || [[#AddAcceptFilterEntry|AddAcceptFilterEntry]]&lt;br /&gt;
|-&lt;br /&gt;
| 209 || [[#ClearAcceptFilter|ClearAcceptFilter]]&lt;br /&gt;
|-&lt;br /&gt;
| 300 || [[#OpenStation|OpenStation]]&lt;br /&gt;
|-&lt;br /&gt;
| 301 || [[#CloseStation|CloseStation]]&lt;br /&gt;
|-&lt;br /&gt;
| 302 || [[#Connect|Connect]]&lt;br /&gt;
|-&lt;br /&gt;
| 303 || [[#ConnectPrivate|ConnectPrivate]]&lt;br /&gt;
|-&lt;br /&gt;
| 304 || [[#Disconnect|Disconnect]]&lt;br /&gt;
|-&lt;br /&gt;
| 400 || [[#Initialize_2|Initialize]]&lt;br /&gt;
|-&lt;br /&gt;
| 401 || [[#Finalize_2|Finalize]]&lt;br /&gt;
|-&lt;br /&gt;
| 402 || [4.0.0+] [[#SetOperationMode|SetOperationMode]]&lt;br /&gt;
|-&lt;br /&gt;
| 403 || [7.0.0+] [[#InitializeWithVersion|InitializeWithVersion]]&lt;br /&gt;
|-&lt;br /&gt;
| 404 || [19.0.0+] [[#InitializeWithPriority|InitializeWithPriority]]&lt;br /&gt;
|-&lt;br /&gt;
| 500 || [18.0.0+] [[#EnableActionFrame|EnableActionFrame]]&lt;br /&gt;
|-&lt;br /&gt;
| 501 || [18.0.0+] [[#DisableActionFrame|DisableActionFrame]]&lt;br /&gt;
|-&lt;br /&gt;
| 502 || [18.0.0+] [[#SendActionFrame|SendActionFrame]]&lt;br /&gt;
|-&lt;br /&gt;
| 503 || [18.0.0+] [[#RecvActionFrame|RecvActionFrame]]&lt;br /&gt;
|-&lt;br /&gt;
| 505 || [18.0.0+] [[#SetHomeChannel|SetHomeChannel]]&lt;br /&gt;
|-&lt;br /&gt;
| 600 || [18.0.0+] [[#SetTxPower|SetTxPower]]&lt;br /&gt;
|-&lt;br /&gt;
| 601 || [18.0.0+] [[#ResetTxPower|ResetTxPower]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== GetState ===&lt;br /&gt;
No input, returns an output [[#State]].&lt;br /&gt;
&lt;br /&gt;
sdknso implements this by &amp;lt;code&amp;gt;return&amp;lt;/code&amp;gt;ing the u32, with 0 being returned on error / when service isn&#039;t initialized.&lt;br /&gt;
&lt;br /&gt;
=== GetNetworkInfo ===&lt;br /&gt;
Takes a type-0x1A output buffer containing a [[#NetworkInfo]].&lt;br /&gt;
&lt;br /&gt;
[[#GetState|State]] must be 3 or 5.&lt;br /&gt;
&lt;br /&gt;
=== GetIpv4Address ===&lt;br /&gt;
No input, returns an output [[#Ipv4Address]] and a [[#SubnetMask]].&lt;br /&gt;
&lt;br /&gt;
=== GetDisconnectReason ===&lt;br /&gt;
No input, returns an output [[#DisconnectReason]].&lt;br /&gt;
&lt;br /&gt;
sdknso implements this by &amp;lt;code&amp;gt;return&amp;lt;/code&amp;gt;ing the s16 as a s32, with -1 being returned on error.&lt;br /&gt;
&lt;br /&gt;
=== GetSecurityParameter ===&lt;br /&gt;
No input, returns an output [[#SecurityParameter]].&lt;br /&gt;
&lt;br /&gt;
=== GetNetworkConfig ===&lt;br /&gt;
No input, returns an output [[#NetworkConfig]].&lt;br /&gt;
&lt;br /&gt;
=== GetStateChangeEvent ===&lt;br /&gt;
No input, returns an output Event handle.&lt;br /&gt;
&lt;br /&gt;
sdknso uses EventClearMode=1 with this. sdknso will Abort if this cmd fails.&lt;br /&gt;
&lt;br /&gt;
This is signaled when the data returned by [[#GetNetworkInfo]]/[[#GetNetworkInfoAndHistory]] is updated.&lt;br /&gt;
&lt;br /&gt;
=== GetNetworkInfoAndHistory ===&lt;br /&gt;
Takes a type-0x1A output buffer containing a [[#NetworkInfo]] and a type-0xA output buffer containing an array of [[#NodeLatestUpdate]].&lt;br /&gt;
&lt;br /&gt;
The array count must be 8.&lt;br /&gt;
&lt;br /&gt;
=== Scan ===&lt;br /&gt;
Takes a type-0x22 output buffer containing an array of [[#NetworkInfo]], a s16 channel, a [[#ScanFilter]], returns an output s16 total_out.&lt;br /&gt;
&lt;br /&gt;
sdknso copies the output s16 to a s32, the value passed for the input s16 is from an user-specified s32 (user-apps generally use value 0 for this).&lt;br /&gt;
&lt;br /&gt;
This is the same as [[#ScanPrivate]], except this also has the same channel-override functionality as [[#CreateNetwork]].&lt;br /&gt;
&lt;br /&gt;
[[#GetState|State]] must be 3-5.&lt;br /&gt;
&lt;br /&gt;
The array count must be at least 1. This is clamped to a maximum of 0x18.&lt;br /&gt;
&lt;br /&gt;
=== ScanPrivate ===&lt;br /&gt;
Takes a type-0x22 output buffer containing an array of [[#NetworkInfo]], a s16 channel, a [[#ScanFilter]], returns an output s16 total_out.&lt;br /&gt;
&lt;br /&gt;
sdknso copies the output s16 to a s32, the value passed for the input s16 is from an user-specified s32.&lt;br /&gt;
&lt;br /&gt;
See [[#Scan]].&lt;br /&gt;
&lt;br /&gt;
=== SetWirelessControllerPolicy ===&lt;br /&gt;
Takes an input [[#WirelessControllerRestriction]], no output.&lt;br /&gt;
&lt;br /&gt;
[[#GetState|State]] must be 1.&lt;br /&gt;
&lt;br /&gt;
The input value is written into state.&lt;br /&gt;
&lt;br /&gt;
=== SetWirelessAudioPolicy ===&lt;br /&gt;
Takes an input [[#BluetoothAudioDeviceConnectableMode]], no output.&lt;br /&gt;
&lt;br /&gt;
=== SetProtocol ===&lt;br /&gt;
Takes an input [[#Protocol|u32]], no output.&lt;br /&gt;
&lt;br /&gt;
This cmd was implemented with [20.0.0+], prior to that this just returned an error.&lt;br /&gt;
&lt;br /&gt;
The sdk user-process func will pass value 1 (2 on Ounce) to the cmd when the input [[#Protocol|Protocol]] is 0, valid values passed directly when recognized, otherwise Abort. User-processes use SetProtocol immediately after initializing ldn.&lt;br /&gt;
&lt;br /&gt;
[20.0.0+] The ldn initialization functionality in sdknso also uses this with value 1 (NX) eventually after the init cmd was used successfully.&lt;br /&gt;
&lt;br /&gt;
The input is validated, then a vfunc is called.&lt;br /&gt;
&lt;br /&gt;
The cmd_input must be non-zero. BIT(cmd_input) must be set in a state-field, otherwise a separate Result is returned. This is a permission [[#Protocol|bitmask]] which originates from the ldn:* service object being used.&lt;br /&gt;
&lt;br /&gt;
The vfunc sends a message to another thread with the input u32 as the param, and returns the response from that.&lt;br /&gt;
&lt;br /&gt;
The thread msg-queue-handler (besides other validation) uses the input param to select what values to write to state fields. On NX only input value 1 or 3 is allowed, with an error being thrown otherwise. The previously mentioned validation includes verifying that [[#GetState|State]] is Initialized.&lt;br /&gt;
&lt;br /&gt;
=== OpenAccessPoint ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
[[#GetState|State]] must be 1, this cmd eventually sets the State to value 2.&lt;br /&gt;
&lt;br /&gt;
=== CloseAccessPoint ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
[[#GetState|State]] must be 2-3, this cmd eventually sets the State to value 1.&lt;br /&gt;
&lt;br /&gt;
=== CreateNetwork ===&lt;br /&gt;
Takes an input [[#SecurityConfig]], an [[#UserConfig]], a [[#NetworkConfig]], no output.&lt;br /&gt;
&lt;br /&gt;
This is the same as [[#CreateNetworkPrivate]], except the [[#AddressEntry]] params are 0, and the [[#SecurityParameter]] is generated from &amp;quot;nn::util::TinyMt::GenerateRandomBytes&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
Unlike CreateNetworkPrivate, this overwrites the channel field in the [[#NetworkConfig]]. When the cached [[SPL_services#IsDevelopment|IsDevelopment]] value is true, the output from [[Settings_services|GetLdnChannel]] will overwrite that field if the s32 setting value is &amp;gt;=0, otherwise the original value is used. Otherwise when the IsDevelopment field is false (retail), the channel is overwritten with value 0.&lt;br /&gt;
&lt;br /&gt;
This overwrites the u16 field at [[#SecurityConfig]]+0. When the cached [[SPL_services#IsDevelopment|IsDevelopment]] value is false (retail) ([18.0.0+] [[System_Settings|system-setting]] &amp;lt;code&amp;gt;ldn!enable_static_security_mode_configuration&amp;lt;/code&amp;gt; is checked for being true instead), value 1 is used ([18.0.0+] value from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;ldn!static_security_mode&amp;lt;/code&amp;gt; is used, with fallback to value 1 if the setting is &amp;gt;=0x4), otherwise the original value is used.&lt;br /&gt;
&lt;br /&gt;
[[#GetState|State]] must be 2, this cmd eventually sets the State to value 3.&lt;br /&gt;
&lt;br /&gt;
=== CreateNetworkPrivate ===&lt;br /&gt;
Takes an input [[#SecurityConfig]], a [[#SecurityParameter]], an [[#UserConfig]], a [[#NetworkConfig]], a type-0x9 input buffer containing an array of [[#AddressEntry]], no output.&lt;br /&gt;
&lt;br /&gt;
The buffer/count for [[#AddressEntry]] can be 0, in which case the network will be non-Private like [[#CreateNetwork]]. The count must be &amp;lt;=8.&lt;br /&gt;
&lt;br /&gt;
See [[#CreateNetwork]].&lt;br /&gt;
&lt;br /&gt;
=== DestroyNetwork ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
[[#GetState|State]] must be 3, this cmd eventually sets the State to value 2.&lt;br /&gt;
&lt;br /&gt;
=== Reject ===&lt;br /&gt;
Takes an input [[#Ipv4Address]], no output.&lt;br /&gt;
&lt;br /&gt;
[[#GetState|State]] must be 3.&lt;br /&gt;
&lt;br /&gt;
=== SetAdvertiseData ===&lt;br /&gt;
Takes a type-0x21 input buffer, no output.&lt;br /&gt;
&lt;br /&gt;
The input buffer contains arbitrary user data.&lt;br /&gt;
&lt;br /&gt;
The buffer size must be &amp;lt;=0x180. An empty buffer (addr=NULL/size=0) can be used to reset the AdvertiseData size in state to zero.&lt;br /&gt;
&lt;br /&gt;
[[#GetState|State]] must be 2-3.&lt;br /&gt;
&lt;br /&gt;
=== SetStationAcceptPolicy ===&lt;br /&gt;
Takes an input [[#AcceptPolicy]], no output.&lt;br /&gt;
&lt;br /&gt;
[[#GetState|State]] must be 2-3.&lt;br /&gt;
&lt;br /&gt;
=== AddAcceptFilterEntry ===&lt;br /&gt;
Takes an input [[#MacAddress|MacAddress]], no output.&lt;br /&gt;
&lt;br /&gt;
There are two sdknso funcs implementing this: one which takes a [[#MacAddress|MacAddress]] directly, the other loads the [[#MacAddress|MacAddress]] from the input [[#NodeInfo|NodeInfo]].&lt;br /&gt;
&lt;br /&gt;
[[#GetState|State]] must be 2-3.&lt;br /&gt;
&lt;br /&gt;
=== ClearAcceptFilter ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
[[#GetState|State]] must be 2-3.&lt;br /&gt;
&lt;br /&gt;
=== OpenStation ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
[[#GetState|State]] must be 1, this cmd eventually sets the State to value 4.&lt;br /&gt;
&lt;br /&gt;
=== CloseStation ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
[[#GetState|State]] must be 4-5, this cmd eventually sets the State to value 1.&lt;br /&gt;
&lt;br /&gt;
=== Connect ===&lt;br /&gt;
Takes a type-0x19 input buffer containing a [[#NetworkInfo]], a [[#SecurityConfig]], an [[#UserConfig]], a s32 LocalCommunicationVersion, a [[#ConnectOption]], no output.&lt;br /&gt;
&lt;br /&gt;
[[#GetState|State]] must be 4, this cmd eventually sets the State to value 5.&lt;br /&gt;
&lt;br /&gt;
This is identical to [[#ConnectPrivate]] (besides the below), except the data internally passed for [[#SecurityParameter]]/[[#NetworkConfig]] are loaded from the input [[#NetworkInfo]].&lt;br /&gt;
&lt;br /&gt;
[1.0.0-?] This overwrites the u16 field at [[#SecurityConfig]]+0. When the cached [[SPL_services#IsDevelopment|IsDevelopment]] value is false (retail), value 1 is used, otherwise the used value is: original_field == 0 ? {u16 [[#NetworkInfo]]+0x60} : original_field. [18.0.0+] This now uses the same SecurityMode override as [[#CreateNetwork|CreateNetwork]].&lt;br /&gt;
&lt;br /&gt;
u32 LocalCommunicationVersion&amp;gt;&amp;gt;15 must be 0.&lt;br /&gt;
&lt;br /&gt;
=== ConnectPrivate ===&lt;br /&gt;
Takes a [[#SecurityConfig]], [[#SecurityParameter]], an [[#UserConfig]], a s32 LocalCommunicationVersion, a [[#ConnectOption]], a [[#NetworkConfig]], no output.&lt;br /&gt;
&lt;br /&gt;
See [[#Connect]].&lt;br /&gt;
&lt;br /&gt;
[1.0.0-?] This overwrites the u16 field at [[#SecurityConfig]]+0. When the cached [[SPL_services#IsDevelopment|IsDevelopment]] value is false (retail), value 1 is used, otherwise the original value is used. [18.0.0+] This now uses the same SecurityMode override as [[#Connect|Connect]].&lt;br /&gt;
&lt;br /&gt;
=== Disconnect ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
[[#GetState|State]] must be 5, this cmd eventually sets the State to value 4.&lt;br /&gt;
&lt;br /&gt;
=== Initialize ===&lt;br /&gt;
Takes an input PID and an u64 pid_placeholder.&lt;br /&gt;
&lt;br /&gt;
This is used immediately after object creation.&lt;br /&gt;
&lt;br /&gt;
On old sysvers the cmd impl for User/System are identical, except different params are used for the funcs called internally.&lt;br /&gt;
&lt;br /&gt;
With [7.0.0+] [[#InitializeWithVersion|InitializeWithVersion]] is used instead. The cmd impl for Initialize uses [[#InitializeWithVersion|InitializeWithVersion]] with version=0.&lt;br /&gt;
&lt;br /&gt;
=== Finalize ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
This is used during service exit, prior to closing the object. Official sw will Abort if this fails.&lt;br /&gt;
&lt;br /&gt;
If State is set for it, this will run the equivalent of [[#CloseAccessPoint]]/[[#CloseStation]] when needed.&lt;br /&gt;
&lt;br /&gt;
[[#GetState|State]] must be non-zero, this cmd eventually sets the State to value 0.&lt;br /&gt;
&lt;br /&gt;
=== SetOperationMode ===&lt;br /&gt;
Takes an input [[#OperationMode]], no output.&lt;br /&gt;
&lt;br /&gt;
[[#GetState|State]] must be 1.&lt;br /&gt;
&lt;br /&gt;
The input value is written into state.&lt;br /&gt;
&lt;br /&gt;
=== InitializeWithVersion ===&lt;br /&gt;
Takes an input PID, a s32 version, and an u64 pid_placeholder.&lt;br /&gt;
&lt;br /&gt;
The priority is determined by whether the interface is User/System: System = 0x38, User = 0x5A.&lt;br /&gt;
&lt;br /&gt;
It then calls the init func, with the cmd input params and the above priority, returning the Result on failure.&lt;br /&gt;
&lt;br /&gt;
On newer sysvers this then adds an entry for the state array used by [[#RegisterClient|RegisterClient]].&lt;br /&gt;
&lt;br /&gt;
Lastly the input PID and version are written into state, then this returns.&lt;br /&gt;
&lt;br /&gt;
The init func does the following:&lt;br /&gt;
* The PID must be non-zero, and the version must not be negative. The priority must be 0x5A or 0x38.&lt;br /&gt;
* An error is returned if state fields are invalid.&lt;br /&gt;
* The input PID and version are written into state (a state field is also set to interface == User).&lt;br /&gt;
* Lastly, a vfunc is called with the input priority, returning the Result from that.&lt;br /&gt;
&lt;br /&gt;
The vfunc does the following:&lt;br /&gt;
* On newer sysvers, this uses [[Shared_Database_services|pl:s]] RequestApplicationFunctionAuthorizationByProcessId with the input PID and [[Shared_Database_services|ApplicationFunctionAuthorizationId]] = 2 (SecureLdnLocalCommunication), returning the Result on failure.&lt;br /&gt;
* Then a message is sent to a msg-queue with the input priority.&lt;br /&gt;
&lt;br /&gt;
The handler for the above message does the following:&lt;br /&gt;
* When state is already initialized, runs handling for that. An error is also thrown if the input priority is larger than a state field.&lt;br /&gt;
* Initializes state, etc.&lt;br /&gt;
* Various [[Network_Interface_services|nifm]] funcs are eventually used. The input priority is used to determine the value for [[Network_Interface_services#CreateRequest|nn::nifm::RequestParameters]]: value 0x4 or value 0x8 is used, depending on priority &amp;gt; 0x59.&lt;br /&gt;
** Newer versions also handle ldn lan_emulation [[System_Settings|sys-settings]] here. For the above value, when lan_emulation is enabled it uses value 0x17, with 0x18 additionally used for priority &amp;lt;= 0x59.&lt;br /&gt;
* The rest is state init, including setting [[#State|State]] to value 1. Then 0 is returned.&lt;br /&gt;
&lt;br /&gt;
On old sysvers the cmd impl for User/System are identical, except different params are used for the funcs called internally. With newer sysvers the cmd impl is now identical.&lt;br /&gt;
&lt;br /&gt;
Version values passed by official sw:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value || SystemVersion&lt;br /&gt;
|-&lt;br /&gt;
| 0x1 || [7.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 0x2 || [18.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 0x3 || [19.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || [20.0.0+]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== InitializeWithPriority ===&lt;br /&gt;
Takes an input PID, a s32 version, a s32 priority, and an u64 pid_placeholder.&lt;br /&gt;
&lt;br /&gt;
This is similar to [[#InitializeWithVersion|InitializeWithVersion]]. The input priority is passed directly to the init func which is called here, instead of determining it from whether the interface is User/System.&lt;br /&gt;
&lt;br /&gt;
Official sw passes input value 0x38 for the priority as the default, when the user doesn&#039;t specify the priority.&lt;br /&gt;
&lt;br /&gt;
=== EnableActionFrame ===&lt;br /&gt;
Takes an input [[#ActionFrameSettings]]. No output.&lt;br /&gt;
&lt;br /&gt;
[[#State|State]] must be Initialized.&lt;br /&gt;
&lt;br /&gt;
=== DisableActionFrame ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
[[#State|State]] must be Initialized.&lt;br /&gt;
&lt;br /&gt;
=== SendActionFrame ===&lt;br /&gt;
Takes a type-0x21 input buffer, two input [[#MacAddress]], two input s16s (&#039;&#039;&#039;Band&#039;&#039;&#039; and &#039;&#039;&#039;ChannelNumber&#039;&#039;&#039;) and an input [[#MessageFlagSet]]. No output.&lt;br /&gt;
&lt;br /&gt;
[20.0.0+] The input s16s were replaced with a single u16, which has the same format as [[#SetHomeChannel|SetHomeChannel]].&lt;br /&gt;
&lt;br /&gt;
The first [[#MacAddress]] is the destination, the second [[#MacAddress]] is the Bssid.&lt;br /&gt;
&lt;br /&gt;
The ChannelNumber must be non-zero.&lt;br /&gt;
&lt;br /&gt;
[[#State|State]] must be 3-5 (AccessPointCreated/Station/StationConnected).&lt;br /&gt;
&lt;br /&gt;
=== RecvActionFrame ===&lt;br /&gt;
Takes a type-0x22 output buffer and an input [[#MessageFlagSet]]. Returns two output [[#MacAddress]], two output s16s (&#039;&#039;&#039;Band&#039;&#039;&#039; and &#039;&#039;&#039;ChannelNumber&#039;&#039;&#039;), an output u32 &#039;&#039;&#039;Size&#039;&#039;&#039;, and an output s32 &#039;&#039;&#039;LinkLevel&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
[20.0.0+] The output s16s were replaced with a single u16, which has the same format as [[#SetHomeChannel|SetHomeChannel]].&lt;br /&gt;
&lt;br /&gt;
[[#EnableActionFrame|EnableActionFrame]] must be used prior to this.&lt;br /&gt;
&lt;br /&gt;
=== SetHomeChannel ===&lt;br /&gt;
Takes two input s16s &#039;&#039;&#039;Band&#039;&#039;&#039; and &#039;&#039;&#039;ChannelNumber&#039;&#039;&#039;. No output.&lt;br /&gt;
&lt;br /&gt;
[20.0.0+] Now takes an input u16 instead of two s16s, merging the two params. Bitmask 0x3FF (low 10-bits) is the ChannelNumber, while the remaining upper 6-bits is the Band. The Band is used as an array index to load the actual Band for passing to a func. Only the following Band input is valid, others return 0x0/0xFFFF: 2 - &amp;gt; 2400, 5 -&amp;gt; 5000, 6 -&amp;gt; 6000.&lt;br /&gt;
&lt;br /&gt;
On NX Band must be ([20.0.0+] converted Band from the above array) 50 ([20.0.0+] 5000) or 24 ([20.0.0+] 2400).&lt;br /&gt;
&lt;br /&gt;
The ChannelNumber must be non-zero.&lt;br /&gt;
&lt;br /&gt;
The [[#State|State]] must be Station.&lt;br /&gt;
&lt;br /&gt;
sdknso uses the input channel to convert to the input needed by the cmd.&lt;br /&gt;
&lt;br /&gt;
=== SetTxPower ===&lt;br /&gt;
Takes an input s16 &#039;&#039;&#039;Power&#039;&#039;&#039;. No output.&lt;br /&gt;
&lt;br /&gt;
The input must be 0x0..0xFF.&lt;br /&gt;
&lt;br /&gt;
A state field must be non-zero.&lt;br /&gt;
&lt;br /&gt;
The [[#State|State]] must be 2-5 (AccessPoint*/Station*).&lt;br /&gt;
&lt;br /&gt;
=== ResetTxPower ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
The same state field checked by [[#SetTxPower|SetTxPower]] must be non-zero. The [[#State|State]] check is also the same as [[#SetTxPower|SetTxPower]].&lt;br /&gt;
&lt;br /&gt;
== IClientProcessMonitor ==&lt;br /&gt;
This is &amp;quot;nn::ldn::detail::IClientProcessMonitor&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [18.0.0+]. &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || RegisterClient&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== RegisterClient ===&lt;br /&gt;
Takes an input PID and an u64 pid_placeholder.&lt;br /&gt;
&lt;br /&gt;
[18.0.0+] [[#CreateClientProcessMonitor|CreateClientProcessMonitor]] and RegisterClient are used by sdknso at the end of the ldn initialization functionality.&lt;br /&gt;
&lt;br /&gt;
If the objptr in IClientProcessMonitor state is already set from using this cmd previously, this just returns 0.&lt;br /&gt;
&lt;br /&gt;
This goes through global state to locate an entry with a matching PID, if none found 0 is returned. The objptr from the state entry is loaded, if NULL this returns 0. This obj is then incref&#039;d and written into the IClientProcessMonitor state. When PID is 0, 0 is returned. It then locates the above state entry again with a matching PID, clearing the entry which matches. Lastly 0 is returned.&lt;br /&gt;
&lt;br /&gt;
The initialization [[#InitializeWithPriority|cmds]] adds an entry to the above global state.&lt;br /&gt;
&lt;br /&gt;
= ldn:u =&lt;br /&gt;
This is &amp;quot;nn::ldn::detail::IUserServiceCreator&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This has IPC max_sessions 3.&lt;br /&gt;
&lt;br /&gt;
[18.0.0+] The sdknso uses SessionManager with this, where the additional session-count is 0x3.&lt;br /&gt;
&lt;br /&gt;
[S2] There appears to be 2 ldn:u services, this appears to be for having separate [[#Protocol|Protocol]] permissions for NX and Ounce games. The Creator object has the same vtable for both of these. However the vtable for IUserLocalCommunicationService appears to be larger even with NX, which likely indicates there&#039;s new commands? There also appears to be 4 additional max-sessions allocated to ldn*, this is probably for one of these ldn:u services?&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#CreateUserLocalCommunicationService|CreateUserLocalCommunicationService]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [18.0.0+] [[#CreateClientProcessMonitor|CreateClientProcessMonitor]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== CreateUserLocalCommunicationService==&lt;br /&gt;
Returns an [[#IUserLocalCommunicationService]].&lt;br /&gt;
&lt;br /&gt;
The user-process closes the IUserServiceCreator object once finished with it during initialization. Official sw ignores errors from this cmd.&lt;br /&gt;
&lt;br /&gt;
== IUserLocalCommunicationService ==&lt;br /&gt;
This is &amp;quot;nn::ldn::detail::IUserLocalCommunicationService&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#GetState_2|GetState]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#GetNetworkInfo_2|GetNetworkInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [[#GetIpv4Address_2|GetIpv4Address]]&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [[#GetDisconnectReason_2|GetDisconnectReason]]&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [[#GetSecurityParameter_2|GetSecurityParameter]]&lt;br /&gt;
|-&lt;br /&gt;
| 5 || [[#GetNetworkConfig_2|GetNetworkConfig]]&lt;br /&gt;
|-&lt;br /&gt;
| 100 || [[#GetStateChangeEvent|GetStateChangeEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 101 || [[#GetNetworkInfoAndHistory|GetNetworkInfoAndHistory]]&lt;br /&gt;
|-&lt;br /&gt;
| 102 || [[#Scan|Scan]]&lt;br /&gt;
|-&lt;br /&gt;
| 103 || [[#ScanPrivate|ScanPrivate]]&lt;br /&gt;
|-&lt;br /&gt;
| 104 || [5.0.0+] [[#SetWirelessControllerPolicy|SetWirelessControllerPolicy]]&lt;br /&gt;
|-&lt;br /&gt;
| 105 || [13.1.0+] [[#SetWirelessAudioPolicy|SetWirelessAudioPolicy]]&lt;br /&gt;
|-&lt;br /&gt;
| 106 || [18.0.0+] [[#SetProtocol|SetProtocol]]&lt;br /&gt;
|-&lt;br /&gt;
| 200 || [[#OpenAccessPoint|OpenAccessPoint]]&lt;br /&gt;
|-&lt;br /&gt;
| 201 || [[#CloseAccessPoint|CloseAccessPoint]]&lt;br /&gt;
|-&lt;br /&gt;
| 202 || [[#CreateNetwork|CreateNetwork]]&lt;br /&gt;
|-&lt;br /&gt;
| 203 || [[#CreateNetworkPrivate|CreateNetworkPrivate]]&lt;br /&gt;
|-&lt;br /&gt;
| 204 || [[#DestroyNetwork|DestroyNetwork]]&lt;br /&gt;
|-&lt;br /&gt;
| 205 || [[#Reject|Reject]]&lt;br /&gt;
|-&lt;br /&gt;
| 206 || [[#SetAdvertiseData|SetAdvertiseData]]&lt;br /&gt;
|-&lt;br /&gt;
| 207 || [[#SetStationAcceptPolicy|SetStationAcceptPolicy]]&lt;br /&gt;
|-&lt;br /&gt;
| 208 || [[#AddAcceptFilterEntry|AddAcceptFilterEntry]]&lt;br /&gt;
|-&lt;br /&gt;
| 209 || [[#ClearAcceptFilter|ClearAcceptFilter]]&lt;br /&gt;
|-&lt;br /&gt;
| 300 || [[#OpenStation|OpenStation]]&lt;br /&gt;
|-&lt;br /&gt;
| 301 || [[#CloseStation|CloseStation]]&lt;br /&gt;
|-&lt;br /&gt;
| 302 || [[#Connect|Connect]]&lt;br /&gt;
|-&lt;br /&gt;
| 303 || [[#ConnectPrivate|ConnectPrivate]]&lt;br /&gt;
|-&lt;br /&gt;
| 304 || [[#Disconnect|Disconnect]]&lt;br /&gt;
|-&lt;br /&gt;
| 400 || [[#Initialize_2|Initialize]]&lt;br /&gt;
|-&lt;br /&gt;
| 401 || [[#Finalize_2|Finalize]]&lt;br /&gt;
|-&lt;br /&gt;
| 402 || [7.0.0+] [[#InitializeWithVersion|InitializeWithVersion]]&lt;br /&gt;
|-&lt;br /&gt;
| 403 || [19.0.0+] [[#SetOperationMode|SetOperationMode]]&lt;br /&gt;
|-&lt;br /&gt;
| 500 || [18.0.0+] [[#EnableActionFrame|EnableActionFrame]]&lt;br /&gt;
|-&lt;br /&gt;
| 501 || [18.0.0+] [[#DisableActionFrame|DisableActionFrame]]&lt;br /&gt;
|-&lt;br /&gt;
| 502 || [18.0.0+] [[#SendActionFrame|SendActionFrame]]&lt;br /&gt;
|-&lt;br /&gt;
| 503 || [18.0.0+] [[#RecvActionFrame|RecvActionFrame]]&lt;br /&gt;
|-&lt;br /&gt;
| 505 || [18.0.0+] [[#SetHomeChannel|SetHomeChannel]]&lt;br /&gt;
|-&lt;br /&gt;
| 600 || [18.0.0+] [[#SetTxPower|SetTxPower]]&lt;br /&gt;
|-&lt;br /&gt;
| 601 || [18.0.0+] [[#ResetTxPower|ResetTxPower]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ndd =&lt;br /&gt;
This is &amp;quot;nn::ndd::IService&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [5.0.0] and removed with [6.0.0].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || EnableAutoCommunication&lt;br /&gt;
|-&lt;br /&gt;
| 1 || DisableAutoCommunication&lt;br /&gt;
|-&lt;br /&gt;
| 2 || IsAutoCommunicationEnabled&lt;br /&gt;
|-&lt;br /&gt;
| 3 || EnablePowerSave&lt;br /&gt;
|-&lt;br /&gt;
| 4 || DisablePowerSave&lt;br /&gt;
|-&lt;br /&gt;
| 5 || IsPowerSaveEnabled&lt;br /&gt;
|-&lt;br /&gt;
| 6 || IsNetworkActive&lt;br /&gt;
|-&lt;br /&gt;
| 7 || AcquireSendDataUpdateEvent&lt;br /&gt;
|-&lt;br /&gt;
| 8 || AddSendData&lt;br /&gt;
|-&lt;br /&gt;
| 9 || ClearSendData&lt;br /&gt;
|-&lt;br /&gt;
| 10 || GetSendData&lt;br /&gt;
|-&lt;br /&gt;
| 11 || AcquireReceiveDataEvent&lt;br /&gt;
|-&lt;br /&gt;
| 12 || GetCurrentReceiveDataCounter&lt;br /&gt;
|-&lt;br /&gt;
| 13 || GetOldestReceiveDataCounter&lt;br /&gt;
|-&lt;br /&gt;
| 14 || GetNextReceiveDataCounter&lt;br /&gt;
|-&lt;br /&gt;
| 15 || GetAvailableReceiveDataCount&lt;br /&gt;
|-&lt;br /&gt;
| 16 || GetRecentReceiveDataCounter&lt;br /&gt;
|-&lt;br /&gt;
| 17 || GetReceiveData&lt;br /&gt;
|-&lt;br /&gt;
| 18 || AddReceiveData&lt;br /&gt;
|-&lt;br /&gt;
| 19 || ClearReceiveData&lt;br /&gt;
|-&lt;br /&gt;
| 20 || ClearDataIdFilter&lt;br /&gt;
|-&lt;br /&gt;
| 21 || AcquireDeviceScanEvent&lt;br /&gt;
|-&lt;br /&gt;
| 22 || StartDeviceScan&lt;br /&gt;
|-&lt;br /&gt;
| 23 || CancelDeviceScan&lt;br /&gt;
|-&lt;br /&gt;
| 24 || GetDeviceScanResult&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= lp2p:app, lp2p:sys =&lt;br /&gt;
These are &amp;quot;nn::lp2p::detail::ISfServiceCreator&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
These were added with [9.0.0+].&lt;br /&gt;
&lt;br /&gt;
lp2p:app is used by [[Mario Kart Live: Home Circuit]]. lp2p:sys is used by [[Album_Applet|LibraryAppletPhotoViewer]] with [11.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#CreateNetworkService|CreateNetworkService]]&lt;br /&gt;
|-&lt;br /&gt;
| 8 || [[#CreateNetworkServiceMonitor|CreateNetworkServiceMonitor]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== CreateNetworkService ==&lt;br /&gt;
Takes a PID-descriptor, a reserved input u64 and an input u32. Returns an output [[#ISfService]].&lt;br /&gt;
&lt;br /&gt;
The input u32 must be value 0x1.&lt;br /&gt;
&lt;br /&gt;
== CreateNetworkServiceMonitor ==&lt;br /&gt;
Takes a PID-descriptor and a reserved input u64. Returns an output [[#ISfServiceMonitor]].&lt;br /&gt;
&lt;br /&gt;
== ISfService ==&lt;br /&gt;
This is &amp;quot;nn::lp2p::detail::ISfService&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#Initialize_4|Initialize]]&lt;br /&gt;
|-&lt;br /&gt;
| 256 || [9.0.0-9.0.1] [[#AttachNetworkInterfaceStateChangeEvent|AttachNetworkInterfaceStateChangeEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 264 || [9.0.0-9.0.1] [[#GetNetworkInterfaceLastError|GetNetworkInterfaceLastError]]&lt;br /&gt;
|-&lt;br /&gt;
| 272 || [9.0.0-9.0.1] [[#GetRole|GetRole]]&lt;br /&gt;
|-&lt;br /&gt;
| 280 || [9.0.0-9.0.1] [[#GetAdvertiseData|GetAdvertiseData]]&lt;br /&gt;
|-&lt;br /&gt;
| 288 || [9.0.0-9.0.1] [[#GetGroupInfo|GetGroupInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 296 || [9.0.0-9.0.1] [[#GetGroupInfo2|GetGroupInfo2]]&lt;br /&gt;
|-&lt;br /&gt;
| 304 || [9.0.0-9.0.1] [[#GetGroupOwner|GetGroupOwner]]&lt;br /&gt;
|-&lt;br /&gt;
| 312 || [9.0.0-9.0.1] [[#GetIpConfig|GetIpConfig]]&lt;br /&gt;
|-&lt;br /&gt;
| 320 || [9.0.0-9.0.1] [[#GetLinkLevel|GetLinkLevel]]&lt;br /&gt;
|-&lt;br /&gt;
| 512 || [[#Scan_2|Scan]]&lt;br /&gt;
|-&lt;br /&gt;
| 768 || [[#CreateGroup|CreateGroup]]&lt;br /&gt;
|-&lt;br /&gt;
| 776 || [[#DestroyGroup|DestroyGroup]]&lt;br /&gt;
|-&lt;br /&gt;
| 784 || [[#SetAdvertiseData|SetAdvertiseData]]&lt;br /&gt;
|-&lt;br /&gt;
| 1536 || [[#SendToOtherGroup|SendToOtherGroup]]&lt;br /&gt;
|-&lt;br /&gt;
| 1544 || [[#RecvFromOtherGroup|RecvFromOtherGroup]]&lt;br /&gt;
|-&lt;br /&gt;
| 1552 || [[#AddAcceptableGroupId|AddAcceptableGroupId]]&lt;br /&gt;
|-&lt;br /&gt;
| 1560 || [9.1.0+] [[#ClearAcceptableGroupId|ClearAcceptableGroupId]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Initialize ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Returns 0.&lt;br /&gt;
&lt;br /&gt;
Unused by official sw.&lt;br /&gt;
&lt;br /&gt;
=== Scan ===&lt;br /&gt;
Takes a type-0x19 input buffer containing a [[#GroupInfo]] and a type-0x22 output buffer containing an array of [[#ScanResult]]. Returns an output s32 &#039;&#039;&#039;TotalOut&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
=== CreateGroup ===&lt;br /&gt;
Takes a type-0x31 input buffer containing a [[#GroupInfo]]. No output.&lt;br /&gt;
&lt;br /&gt;
[[Mario Kart Live: Home Circuit|mklive]] uses the following string with this: &amp;quot;Failed to create a group: %08X&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
The [[#GetRole|role]] must be 0. This eventually sets the [[#GetRole|role]] to value 1.&lt;br /&gt;
&lt;br /&gt;
=== DestroyGroup ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
This destroys the previously [[#CreateGroup|created]] group. If no group was previously created ([[#GetRole|role]] is not 1), this just returns 0.&lt;br /&gt;
&lt;br /&gt;
=== SetAdvertiseData ===&lt;br /&gt;
Takes a type-0x21 input buffer. No output.&lt;br /&gt;
&lt;br /&gt;
The buffer size must be &amp;lt;=0x80. The [[#GetRole|role]] must be &amp;lt;=1.&lt;br /&gt;
&lt;br /&gt;
A string in [[Mario Kart Live: Home Circuit|mklive]] refers to the buffer data as &amp;quot;scan advertise data&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
=== SendToOtherGroup ===&lt;br /&gt;
Takes an input [[#MacAddress_2|MacAddress]], a [[#GroupId]], a s16 &#039;&#039;&#039;Frequency&#039;&#039;&#039;, a s16 &#039;&#039;&#039;Channel&#039;&#039;&#039;, an u32 &#039;&#039;&#039;MessageFlag&#039;&#039;&#039; and a type-0x21 input buffer. No output.&lt;br /&gt;
&lt;br /&gt;
The buffer size must be &amp;lt;=0x400.&lt;br /&gt;
&lt;br /&gt;
The MacAddress must be non-zero. The s16s must be &amp;gt;=1.&lt;br /&gt;
&lt;br /&gt;
Only bit0 is used from flags: clear = block until the data can be sent, set = return error when the data can&#039;t be sent.&lt;br /&gt;
&lt;br /&gt;
A string in [[Mario Kart Live: Home Circuit|mklive]] refers to the buffer data as &amp;quot;Action frame&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
The [[#GetRole|role]] must be non-zero. The error from [[#GetNetworkInterfaceLastError]] will be returned if it&#039;s set.&lt;br /&gt;
&lt;br /&gt;
[11.0.0+] [[#GroupInfo]]+0x8A must be value 2, otherwise an error is returned.&lt;br /&gt;
&lt;br /&gt;
This sends an Action frame to the specified [[#GroupId]], with the specified destination [[#MacAddress_2|MacAddress]] (can be a broadcast address).&lt;br /&gt;
&lt;br /&gt;
The frequency param is the same as the [[#GroupInfo]]+0x84 field.&lt;br /&gt;
&lt;br /&gt;
=== RecvFromOtherGroup ===&lt;br /&gt;
Takes an input u32 &#039;&#039;&#039;MessageFlag&#039;&#039;&#039; and a type-0x22 output buffer. Returns a [[#MacAddress_2|MacAddress]], an u16 &#039;&#039;&#039;Frequency&#039;&#039;&#039;, a s16 &#039;&#039;&#039;Channel&#039;&#039;&#039;, an u32 &#039;&#039;&#039;OutSize&#039;&#039;&#039; and a s32.&lt;br /&gt;
&lt;br /&gt;
The OutSize is the original size used for copying to the output buffer, before it&#039;s clamped to the output-buffer size.&lt;br /&gt;
&lt;br /&gt;
Only bit0 is used from MessageFlag: clear = block until data is available, set = return error when data is not available.&lt;br /&gt;
&lt;br /&gt;
When data is not available, the error from [[#GetNetworkInterfaceLastError]] will be returned if it&#039;s set.&lt;br /&gt;
&lt;br /&gt;
The [[#GetRole|role]] must be non-zero.&lt;br /&gt;
&lt;br /&gt;
This receives an Action frame.&lt;br /&gt;
&lt;br /&gt;
=== AddAcceptableGroupId ===&lt;br /&gt;
Takes an input [[#GroupId]]. No output.&lt;br /&gt;
&lt;br /&gt;
=== ClearAcceptableGroupId ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
== ISfServiceMonitor ==&lt;br /&gt;
This is &amp;quot;nn::lp2p::detail::ISfServiceMonitor&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This interface has no commands, until [9.1.0+] which added actual commands.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#Initialize_5|Initialize]]&lt;br /&gt;
|-&lt;br /&gt;
| 256 || [[#AttachNetworkInterfaceStateChangeEvent|AttachNetworkInterfaceStateChangeEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 264 || [[#GetNetworkInterfaceLastError|GetNetworkInterfaceLastError]]&lt;br /&gt;
|-&lt;br /&gt;
| 272 || [[#GetRole|GetRole]]&lt;br /&gt;
|-&lt;br /&gt;
| 280 || [[#GetAdvertiseData|GetAdvertiseData]]&lt;br /&gt;
|-&lt;br /&gt;
| 281 || [[#GetAdvertiseData2|GetAdvertiseData2]]&lt;br /&gt;
|-&lt;br /&gt;
| 288 || [[#GetGroupInfo|GetGroupInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 296 || [[#GetGroupInfo2|GetGroupInfo2]]&lt;br /&gt;
|-&lt;br /&gt;
| 304 || [[#GetGroupOwner|GetGroupOwner]]&lt;br /&gt;
|-&lt;br /&gt;
| 312 || [[#GetIpConfig|GetIpConfig]]&lt;br /&gt;
|-&lt;br /&gt;
| 320 || [[#GetLinkLevel|GetLinkLevel]]&lt;br /&gt;
|-&lt;br /&gt;
| 328 || [[#AttachJoinEvent|AttachJoinEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 336 || [[#GetMembers|GetMembers]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Initialize ===&lt;br /&gt;
Returns 0.&lt;br /&gt;
&lt;br /&gt;
Unused by official sw.&lt;br /&gt;
&lt;br /&gt;
=== AttachNetworkInterfaceStateChangeEvent ===&lt;br /&gt;
No input. Returns an output Event handle with EventClearMode=0.&lt;br /&gt;
&lt;br /&gt;
=== GetNetworkInterfaceLastError ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
=== GetRole ===&lt;br /&gt;
No input. Returns an output u8.&lt;br /&gt;
&lt;br /&gt;
=== GetAdvertiseData ===&lt;br /&gt;
Takes a type-0x22 output buffer. Returns two output u16s.&lt;br /&gt;
&lt;br /&gt;
Validates that the [[#GetRole|role]] is value 2, then copies data from state into the output buffer. The first output u16 is the size used for the memcpy, the second u16 is the original size from state.&lt;br /&gt;
&lt;br /&gt;
=== GetAdvertiseData2 ===&lt;br /&gt;
Takes a type-0x22 output buffer. Returns two output u16s.&lt;br /&gt;
&lt;br /&gt;
This is identical to [[#GetAdvertiseData]] except this doesn&#039;t run the role validation.&lt;br /&gt;
&lt;br /&gt;
=== GetGroupInfo ===&lt;br /&gt;
Takes a type-0x32 output buffer containing a [[#GroupInfo]].&lt;br /&gt;
&lt;br /&gt;
Validates that the [[#GetRole|role]] is non-zero, then copies the struct from state into the output buffer.&lt;br /&gt;
&lt;br /&gt;
=== GetGroupInfo2 ===&lt;br /&gt;
Takes a type-0x32 output buffer containing a [[#GroupInfo]] and a type-0x31 input buffer containing a [[#GroupInfo]].&lt;br /&gt;
&lt;br /&gt;
This runs the same code as [[#CreateGroup]] to generate the [[#GroupInfo]] for the input struct (which with [[#CreateGroup]] would be available with [[#GetGroupInfo]]). The input struct is the same as [[#CreateGroup]].&lt;br /&gt;
&lt;br /&gt;
=== GetGroupOwner ===&lt;br /&gt;
No input. Returns an output [[#NodeInfo_2|NodeInfo]].&lt;br /&gt;
&lt;br /&gt;
Validates that the [[#GetRole|role]] is non-zero, then copies the data from state to output.&lt;br /&gt;
&lt;br /&gt;
=== GetIpConfig ===&lt;br /&gt;
Takes a type-0x1A output buffer containing a 0x100-byte struct.&lt;br /&gt;
&lt;br /&gt;
Validates that the [[#GetRole|role]] is non-zero, then copies the struct from state into the output buffer.&lt;br /&gt;
&lt;br /&gt;
+0x20 is the &amp;lt;code&amp;gt;struct sockaddr&amp;lt;/code&amp;gt; IP address, +0x40 is the &amp;lt;code&amp;gt;struct sockaddr&amp;lt;/code&amp;gt; subnet-mask, +0x60 is the &amp;lt;code&amp;gt;struct sockaddr&amp;lt;/code&amp;gt; gateway(?). The address for the last one is set to localhost.&lt;br /&gt;
&lt;br /&gt;
=== GetLinkLevel ===&lt;br /&gt;
No input. Returns an output u32.&lt;br /&gt;
&lt;br /&gt;
=== AttachJoinEvent ===&lt;br /&gt;
No input. Returns an output Event handle with EventClearMode=0.&lt;br /&gt;
&lt;br /&gt;
=== GetMembers ===&lt;br /&gt;
Takes a type-0x22 output buffer containing an array of [[#NodeInfo_2|NodeInfo]]. Returns an output s32 &#039;&#039;&#039;TotalOut&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
Validates that the [[#GetRole|role]] is value 1. Then any entries from state which are available are copied into the output array buffer, if there&#039;s space available. A maximum of 8 entries can be returned.&lt;br /&gt;
&lt;br /&gt;
A string in [[Mario Kart Live: Home Circuit|mklive]] refers to the array data as &amp;quot;connected members&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
= lp2p:m =&lt;br /&gt;
This is &amp;quot;nn::lp2p::monitor::detail::ISfMonitorServiceCreator&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [9.1.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#CreateMonitorService|CreateMonitorService]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== CreateMonitorService ==&lt;br /&gt;
Takes a PID-descriptor, a reserved input u64 and an input u64. Returns an [[#ISfMonitorService]].&lt;br /&gt;
&lt;br /&gt;
== ISfMonitorService ==&lt;br /&gt;
This is &amp;quot;nn::lp2p::monitor::detail::ISfMonitorService&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#Initialize_6|Initialize]]&lt;br /&gt;
|-&lt;br /&gt;
| 288 || [[#GetGroupInfo|GetGroupInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 320 || [[#GetLinkLevel|GetLinkLevel]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Initialize ===&lt;br /&gt;
Returns 0.&lt;br /&gt;
&lt;br /&gt;
= State =&lt;br /&gt;
This is &amp;quot;nn::ldn::State&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Value&lt;br /&gt;
!  Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || None&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Initialized&lt;br /&gt;
|-&lt;br /&gt;
| 2 || AccessPoint&lt;br /&gt;
|-&lt;br /&gt;
| 3 || AccessPointCreated&lt;br /&gt;
|-&lt;br /&gt;
| 4 || Station&lt;br /&gt;
|-&lt;br /&gt;
| 5 || StationConnected&lt;br /&gt;
|-&lt;br /&gt;
| 6 || Error&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Ipv4Address =&lt;br /&gt;
This is &amp;quot;nn::ldn::Ipv4Address&amp;quot;. This is a 0x4-byte struct with 4-byte alignment.&lt;br /&gt;
&lt;br /&gt;
This is essentially the same as &amp;lt;code&amp;gt;struct in_addr&amp;lt;/code&amp;gt;, except this is little-endian.&lt;br /&gt;
&lt;br /&gt;
This is generally &amp;quot;169.254.XXX.{...}&amp;quot;, where XXX is random per created network.&lt;br /&gt;
&lt;br /&gt;
= SubnetMask =&lt;br /&gt;
This is &amp;quot;nn::ldn::SubnetMask&amp;quot;. This is a 0x4-byte struct with 4-byte alignment.&lt;br /&gt;
&lt;br /&gt;
This is essentially the same as &amp;lt;code&amp;gt;struct in_addr&amp;lt;/code&amp;gt;, except this is little-endian.&lt;br /&gt;
&lt;br /&gt;
= Ssid =&lt;br /&gt;
This is &amp;quot;nn::ldn::Ssid&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
When converting a Ssid to a string, the loaded chars from the string must be in the range of 0x20-0x7F, otherwise the byte written to the string will be 0.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x1 || Length (excluding NUL-terminator, must be 0x1-0x20)&lt;br /&gt;
|-&lt;br /&gt;
| 0x1 || 0x21 || Raw (SSID string including NUL-terminator, str[{above length}] must be 0)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= MacAddress =&lt;br /&gt;
This is &amp;quot;nn::ldn::MacAddress&amp;quot;. This is a 6-byte struct with 1-byte alignment.&lt;br /&gt;
&lt;br /&gt;
= NodeInfo =&lt;br /&gt;
This is &amp;quot;nn::ldn::NodeInfo&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
The first node in the nodes array is always the AccessPoint (NodeId 0x0). NodeId is the index of the node in the nodes array.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x4 || [[#Ipv4Address|Ipv4Address]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || 0x6 || [[#MacAddress|MacAddress]]&lt;br /&gt;
|-&lt;br /&gt;
| 0xA || 0x1 || NodeId&lt;br /&gt;
|-&lt;br /&gt;
| 0xB || 0x1 || IsConnected&lt;br /&gt;
|-&lt;br /&gt;
| 0xC || 0x21 || UserName&lt;br /&gt;
|-&lt;br /&gt;
| 0x2D || 0x1 || [19.0.0+] Platform? (0 = NX, 1 = Ounce)&lt;br /&gt;
|-&lt;br /&gt;
| 0x2E || 0x2 || LocalCommunicationVersion&lt;br /&gt;
|-&lt;br /&gt;
| 0x30 || 0x10 || Reserved&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= NodeLatestUpdate =&lt;br /&gt;
This is &amp;quot;nn::ldn::NodeLatestUpdate&amp;quot;. This is a 0x8-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x1 || StateChange&lt;br /&gt;
|-&lt;br /&gt;
| 0x1 || 0x7 || Reserved&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= IntentId =&lt;br /&gt;
This is &amp;quot;nn::ldn::IntentId&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x8 || LocalCommunicationId&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x2 || Reserved&lt;br /&gt;
|-&lt;br /&gt;
| 0xA || 0x2 || SceneId&lt;br /&gt;
|-&lt;br /&gt;
| 0xC || 0x4 || Reserved&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* LocalCommunicationId: [[#CreateNetwork|CreateNetwork]], [[#CreateNetworkPrivate|CreateNetworkPrivate]], [[#Connect|Connect]], [[#ConnectPrivate|ConnectPrivate]] (also [[#ScanFilter|ScanFilter]] when enabled with the flag): When -1, this is overwritten with the first LocalCommunicationId from the user-process [[NACP]], if loading fails value 0 is written instead. Otherwise when not -1, if [[NACP]] loading is successful, this field must match one of the LocalCommunicationIds from there.&lt;br /&gt;
* SceneId: Arbitrary user data, this can be used for filtering with [[#ScanFilter|ScanFilter]] for example.&lt;br /&gt;
&lt;br /&gt;
= SessionId =&lt;br /&gt;
This is &amp;quot;nn::ldn::SessionId&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This is used to generate/overwrite the Ssid when needed.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x10 || Random&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= NetworkId =&lt;br /&gt;
This is &amp;quot;nn::ldn::NetworkId&amp;quot;. This is a 0x20-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x10 || [[#IntentId|IntentId]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x10 || [[#SessionId|SessionId]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= CommonNetworkInfo =&lt;br /&gt;
This is &amp;quot;nn::ldn::CommonNetworkInfo&amp;quot;. This is a 0x30-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x6 || [[#MacAddress|Bssid]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x6 || 0x22 || [[#Ssid|Ssid]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x28 || 0x2 || Channel&lt;br /&gt;
|-&lt;br /&gt;
| 0x2A || 0x1 || LinkLevel&lt;br /&gt;
|-&lt;br /&gt;
| 0x2B || 0x1 || NetworkType&lt;br /&gt;
|-&lt;br /&gt;
| 0x2C || 0x4 || Reserved&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= LdnNetworkInfo =&lt;br /&gt;
This is &amp;quot;nn::ldn::LdnNetworkInfo&amp;quot;. This is a 0x430-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x10 || ServerRandom&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x2 || SecurityMode&lt;br /&gt;
|-&lt;br /&gt;
| 0x12 || 0x1 || StationAcceptPolicy&lt;br /&gt;
|-&lt;br /&gt;
| 0x13 || 0x1 || Version&lt;br /&gt;
|-&lt;br /&gt;
| 0x14 || 0x2 || Reserved&lt;br /&gt;
|-&lt;br /&gt;
| 0x16 || 0x1 || NodeCountMax&lt;br /&gt;
|-&lt;br /&gt;
| 0x17 || 0x1 || NodeCount&lt;br /&gt;
|-&lt;br /&gt;
| 0x18 || 0x200 (0x40 * 8) || [[#NodeInfo|Nodes]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x218 || 0x2 || Reserved&lt;br /&gt;
|-&lt;br /&gt;
| 0x21A || 0x2 || AdvertiseDataSize&lt;br /&gt;
|-&lt;br /&gt;
| 0x21C || 0x180 || AdvertiseData&lt;br /&gt;
|-&lt;br /&gt;
| 0x39C || 0x8C || Reserved&lt;br /&gt;
|-&lt;br /&gt;
| 0x428 || 0x8 || [6.0.0-?] Challenge (set to the output from [[ETicket_services|es]] cmd1501 during network creation) ([?+] only used internally, not exposed in LdnNetworkInfo anymore)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= NetworkInfo =&lt;br /&gt;
This is &amp;quot;nn::ldn::NetworkInfo&amp;quot;. This is a 0x480-byte struct.&lt;br /&gt;
&lt;br /&gt;
The fields listed as Reserved (besides the fields before +0x10) are cleared during the memset and are not written to again afterwards, with cmds which return NetworkInfo.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x20 || [[#NetworkId|NetworkId]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x20 || 0x30 || [[#CommonNetworkInfo|Common]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x50 || 0x430 || [[#LdnNetworkInfo|Ldn]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ScanFilter =&lt;br /&gt;
This is &amp;quot;nn::ldn::ScanFilter&amp;quot;. This is a 0x60-byte struct with 8-byte alignment.&lt;br /&gt;
&lt;br /&gt;
sdknso copies the input ScanFilter to a tmp struct on stack (with [[#ScanFilterFlag|Flag]] masking), which is then used with the cmd. sdknso only copies Bssid with [[#ScanPrivate|ScanPrivate]], with [[#Scan|Scan]] it also masks out the [[#ScanFilterFlag|Flag]] for Bssid.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x20 || [[#NetworkId|NetworkId]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x20 || 0x4 || NetworkType&lt;br /&gt;
|-&lt;br /&gt;
| 0x24 || 0x6 || [[#MacAddress|Bssid]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x2A || 0x22 || [[#Ssid|Ssid]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x4C || 0x10 || Reserved&lt;br /&gt;
|-&lt;br /&gt;
| 0x5C || 0x4 || [[#ScanFilterFlag|Flag]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Each [[#ScanFilterFlag|Flag]] bit when set enables using the corresponding ScanFilter data. This is usually a compare with the ScanFilter data and the internal [[#NetworkInfo|NetworkInfo]] data.&lt;br /&gt;
&lt;br /&gt;
* NetworkType: (ScanFilter_NetworkType &amp;amp; NetworkInfo_NetworkType) must be non-zero.&lt;br /&gt;
* Ssid: The length fields must match, then memcmp is used.&lt;br /&gt;
&lt;br /&gt;
The filtering func also handles validating the Band/Channel, however these fields are internal only and are not exposed in the user ScanFilter.&lt;br /&gt;
&lt;br /&gt;
= ScanFilterFlag =&lt;br /&gt;
This is &amp;quot;nn::ldn::ScanFilterFlag&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Value&lt;br /&gt;
!  Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || None&lt;br /&gt;
|-&lt;br /&gt;
| 0x1 || LocalCommunicationId&lt;br /&gt;
|-&lt;br /&gt;
| 0x2 || SessionId&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || NetworkType&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || Bssid&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || Ssid&lt;br /&gt;
|-&lt;br /&gt;
| 0x20 || SceneId&lt;br /&gt;
|-&lt;br /&gt;
| 0x21 || IntentId&lt;br /&gt;
|-&lt;br /&gt;
| 0x23 || NetworkId&lt;br /&gt;
|-&lt;br /&gt;
| 0x3F || All&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= NetworkConfig =&lt;br /&gt;
This is &amp;quot;nn::ldn::NetworkConfig&amp;quot;. This is a 0x20-byte struct with 8-byte alignment.&lt;br /&gt;
&lt;br /&gt;
sdknso copies the input NetworkConfig to a tmp struct on stack, which is then used with the cmd ([[#CreateNetwork]], [[#CreateNetworkPrivate]], [[#ConnectPrivate]]).&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x10 || [[#IntentId|IntentId]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x2 || Channel&lt;br /&gt;
|-&lt;br /&gt;
| 0x12 || 0x1 || NodeCountMax&lt;br /&gt;
|-&lt;br /&gt;
| 0x13 || 0x1 || Reserved&lt;br /&gt;
|-&lt;br /&gt;
| 0x14 || 0x2 || LocalCommunicationVersion&lt;br /&gt;
|-&lt;br /&gt;
| 0x16 || 0xA || Reserved&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= WirelessControllerRestriction =&lt;br /&gt;
This is &amp;quot;nn::ldn::WirelessControllerRestriction&amp;quot;. This is an u32 enum.&lt;br /&gt;
&lt;br /&gt;
This is used to determine the value passed to [[BTM_services|btm]] SetWlanMode.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Value&lt;br /&gt;
!  Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || Disabled&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Enabled&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= WirelessAudioRestriction =&lt;br /&gt;
This is &amp;quot;nn::ldn::WirelessAudioRestriction&amp;quot;. This is an u32 enum.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Value&lt;br /&gt;
!  Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || Disabled&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Enabled&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= SecurityMode =&lt;br /&gt;
This is &amp;quot;nn::ldn::SecurityMode&amp;quot;. This is an u32 enum.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Value&lt;br /&gt;
!  Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || Any&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Product&lt;br /&gt;
|-&lt;br /&gt;
| 2 || Debug&lt;br /&gt;
|-&lt;br /&gt;
| 3 || SystemDebug&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Value:&lt;br /&gt;
* 1-2: Broadcast Action frame data is encrypted.&lt;br /&gt;
* 3: Broadcast Action frame data is plaintext.&lt;br /&gt;
&lt;br /&gt;
* 1: Data frames are encrypted.&lt;br /&gt;
* 2-3: Data frames for normal data-transfer are plaintext - the network is Open.&lt;br /&gt;
&lt;br /&gt;
= SecurityConfig =&lt;br /&gt;
This is &amp;quot;nn::ldn::SecurityConfig&amp;quot;. This is a 0x44-byte struct with 2-byte alignment.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x2 || [[#SecurityMode|SecurityMode]] (overwritten by [[#CreateNetwork]]/[[#CreateNetworkPrivate]] and [[#Connect]]/[[#ConnectPrivate]], the value used internally by these cmds must be 1-3)&lt;br /&gt;
|-&lt;br /&gt;
| 0x2 || 0x2 || PassphraseSize (must be 0x10-0x40)&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || 0x40 || Passphrase (used with key derivation)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= SecurityParameter =&lt;br /&gt;
This is &amp;quot;nn::ldn::SecurityParameter&amp;quot;. This is a 0x20-byte struct with 1-byte alignment.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x10 || ServerRandom (used with the same key derivation as [[#SecurityConfig]])&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x10 || [[#SessionId|SessionId]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= UserConfig =&lt;br /&gt;
This is &amp;quot;nn::ldn::UserConfig&amp;quot;. This is a 0x30-byte struct with 1-byte alignment.&lt;br /&gt;
&lt;br /&gt;
An error is thrown if UserName+0x20 is non-zero.&lt;br /&gt;
&lt;br /&gt;
sdknso copies the input UserConfig to a tmp struct on stack, which is then used with the cmd. Only the first 0x20-bytes are copied, with the rest cleared.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x21 || UserName (NUL-terminated string for the user name)&lt;br /&gt;
|-&lt;br /&gt;
| 0x21 || 0xF || Reserved&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= AddressEntry =&lt;br /&gt;
This is &amp;quot;nn::ldn::AddressEntry&amp;quot;. This is a 0xC-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x4 || [[#Ipv4Address]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || 0x6 || [[#MacAddress|MacAddress]]&lt;br /&gt;
|-&lt;br /&gt;
| 0xA || 0x2 || Reserved&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= AcceptPolicy =&lt;br /&gt;
This is &amp;quot;nn::ldn::AcceptPolicy&amp;quot;. This is an u8.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Value&lt;br /&gt;
!  Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || AlwaysAccept&lt;br /&gt;
|-&lt;br /&gt;
| 1 || AlwaysReject&lt;br /&gt;
|-&lt;br /&gt;
| 2 || BlackList (addresses in the [[#AddAcceptFilterEntry|list]] are not allowed)&lt;br /&gt;
|-&lt;br /&gt;
| 3 || WhiteList (only addresses in the [[#AddAcceptFilterEntry|list]] are allowed)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ConnectOption =&lt;br /&gt;
This is &amp;quot;nn::ldn::ConnectOption&amp;quot;. This is an u32 bitmask.&lt;br /&gt;
&lt;br /&gt;
There&#039;s two versions of the sdknso funcs for [[#Connect]]/[[#ConnectPrivate]]: the version where the ConnectOption isn&#039;t user-specified uses a default value of 0x1 for it, with the same ShowError code without the bit0 check.&lt;br /&gt;
&lt;br /&gt;
When bit0 here is set after using the above cmds, the sdknso funcs will use [[Error_Applet|ShowError]] with the returned Result if: (rc &amp;amp; 0x3FE1FF) == 0xE0CB.&lt;br /&gt;
&lt;br /&gt;
This must be &amp;lt;=0x1, besides this validation ConnectOption is ignored by [[#Connect]]/[[#ConnectPrivate]].&lt;br /&gt;
&lt;br /&gt;
= DisconnectReason =&lt;br /&gt;
This is &amp;quot;nn::ldn::DisconnectReason&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Value&lt;br /&gt;
!  Description&lt;br /&gt;
|-&lt;br /&gt;
| -1 || Unknown&lt;br /&gt;
|-&lt;br /&gt;
| 0 || None&lt;br /&gt;
|-&lt;br /&gt;
| 1 || DisconnectedByUser&lt;br /&gt;
|-&lt;br /&gt;
| 2 || DisconnectedBySystem&lt;br /&gt;
|-&lt;br /&gt;
| 3 || DestroyedByUser&lt;br /&gt;
|-&lt;br /&gt;
| 4 || DestroyedBySystem&lt;br /&gt;
|-&lt;br /&gt;
| 5 || Rejected&lt;br /&gt;
|-&lt;br /&gt;
| 6 || SignalLost&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= OperationMode =&lt;br /&gt;
This is &amp;quot;nn::ldn::OperationMode&amp;quot;. This is an u32 enum.&lt;br /&gt;
&lt;br /&gt;
This controls bit1 in the value passed to [[WLAN_services|wlan:lcl]] cmd0/cmd1: bit1 = OperationMode==1.&lt;br /&gt;
&lt;br /&gt;
Value 1 seems to affect power (?) related fields in the beacon tags?&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Value&lt;br /&gt;
!  Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || Stable&lt;br /&gt;
|-&lt;br /&gt;
| 1 || HighSpeed&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Protocol =&lt;br /&gt;
This is &amp;quot;nn::ldn::Protocol&amp;quot;. This is an u32 enum.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Value&lt;br /&gt;
!  Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || Default&lt;br /&gt;
|-&lt;br /&gt;
| 1 || NX&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [20.0.0+] (NXAndOunce?)&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [S2] [20.0.0+]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
The Initialize* cmds configure state the same as using [[#SetProtocol|SetProtocol]] with Protocol NX.&lt;br /&gt;
&lt;br /&gt;
There&#039;s S2-only values which enables using Ounce-only keys. The following uses new Ounce-only keys (with S2 hosting):&lt;br /&gt;
* In-game ldn-usage for a S2-only Application.&lt;br /&gt;
* Local-game-update with a S2-only Application.&lt;br /&gt;
* Local-game-update for a S1-game which has a Nintendo Switch 2 Edition available, even without the S2-Edition being installed.&lt;br /&gt;
&lt;br /&gt;
There&#039;s system-titles which [[20.0.0|use]] SetProtocol. While there&#039;s game(s) which use SetProtocol, there&#039;s no known (?) games using Protocol3 (excluding GameShare which is system).&lt;br /&gt;
&lt;br /&gt;
[S2] Protocol2 and Protocol4 appear to be identical to Protocol3 except for using [[SPL_services|Ounce]] keys (?). It&#039;s unknown exactly which Protocol uses which [[SPL_services|Generation]], though presumably 2/4 is Generation 0/1? The following uses each Generation:&lt;br /&gt;
* Generation 0: Mario Kart World&lt;br /&gt;
* Generation 1: lcs (local-content-share), Splatoon Raiders (this might be just due to the value used for [[LDN_services#SetProtocol|Default]] being bumped?)&lt;br /&gt;
&lt;br /&gt;
[S2] Keys are generated by passing the SHA256 hash as the KeySource to the relevant [[SPL_services|spl:ldn]] command with the above Generation, with the full hash being passed to the Ounce cmds. Only the first 0x10-bytes of the output key is used, since AES-128 is used even with Ounce.&lt;br /&gt;
&lt;br /&gt;
On NX, the Protocol [[#SetProtocol|permission-bitmask]] is always set to 0xA (1 and 3). On Ounce, all services have this set to 0x1E, except for one which has it set to 0xA (which is likely the one for S1-compat). 0x1E allows additional protocol values 2 and 4.&lt;br /&gt;
&lt;br /&gt;
= ActionFrameSettings =&lt;br /&gt;
This is &amp;quot;nn::ldn::ActionFrameSettings&amp;quot;. This is a 0x80-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x8 || LocalCommunicationId&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x34 || Reserved&lt;br /&gt;
|-&lt;br /&gt;
| 0x3C || 0x2 || SecurityMode&lt;br /&gt;
|-&lt;br /&gt;
| 0x3E || 0x2 || PassphraseSize (Must be 0x10-0x40)&lt;br /&gt;
|-&lt;br /&gt;
| 0x40 || 0x40 || Passphrase&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
SecurityMode must be 1-2. The same SecurityMode override functionality from elsewhere is used later with this.&lt;br /&gt;
&lt;br /&gt;
The same LocalCommunicationId override/validation from elsewhere is used with the input as well.&lt;br /&gt;
&lt;br /&gt;
= MessageFlagSet =&lt;br /&gt;
This is &amp;quot;nn::ldn::MessageFlagSet&amp;quot;. This is a BitFlagSet object for [[#MessageFlag]].&lt;br /&gt;
&lt;br /&gt;
= MessageFlag =&lt;br /&gt;
This is &amp;quot;nn::ldn::MessageFlag&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Value&lt;br /&gt;
!  Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[[#SendActionFrame|SendActionFrame]]/[[#RecvActionFrame|RecvActionFrame]] handles bit0 the same way as the MessageFlag with lp2p [[#SendToOtherGroup|SendToOtherGroup]]/[[#RecvFromOtherGroup|RecvFromOtherGroup]].&lt;br /&gt;
&lt;br /&gt;
= MacAddress =&lt;br /&gt;
This is &amp;quot;nn::lp2p::MacAddress&amp;quot;. Same as [[#MacAddress|MacAddress]].&lt;br /&gt;
&lt;br /&gt;
= GroupId =&lt;br /&gt;
This is &amp;quot;nn::lp2p::GroupId&amp;quot;. This is a 6-byte struct with 1-byte alignment.&lt;br /&gt;
&lt;br /&gt;
This is a WiFi BSSID.&lt;br /&gt;
&lt;br /&gt;
= NodeInfo =&lt;br /&gt;
This is &amp;quot;nn::lp2p::NodeInfo&amp;quot;. This is a 0x80-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || || &amp;lt;code&amp;gt;struct sockaddr&amp;lt;/code&amp;gt; for the IP address.&lt;br /&gt;
|-&lt;br /&gt;
| 0x24 || 0x6 || [[#MacAddress_2|MacAddress]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= GroupInfo =&lt;br /&gt;
This is &amp;quot;nn::lp2p::GroupInfo&amp;quot;. This is a 0x200-byte struct.&lt;br /&gt;
&lt;br /&gt;
[[Mario Kart Live: Home Circuit|mklive]] sets the SSID to a string generated from random data.&lt;br /&gt;
&lt;br /&gt;
[[#Scan_2|Scan]] only uses the following fields for the cmd input struct: SupportedPlatform/Priority, Frequency/Channel, and PresharedKeyBinarySize/PresharedKey.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x10 || Wrapped master key. When zero, set to randomly-generated data. This is decrypted with a &amp;quot;static AES key&amp;quot; and used to derive the 4 encryption keys for the session.&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x8 || LocalCommunicationId. When zero, the value from control.nacp is loaded. This is later validated by [[#Join]]/[[#CreateGroup]] the same way as the [[#NetworkConfig]] field. Used during key derivation to derive keys B and D.&lt;br /&gt;
|-&lt;br /&gt;
| 0x18 || 0x6 || [[#GroupId]] (&amp;quot;GROUP ID  (BSSID)&amp;quot;). When zero, the default is used. The default should be used here: an error is thrown if the data here doesn&#039;t match the output from [[WLAN_services|wlan:lcl]] cmd2.&lt;br /&gt;
|-&lt;br /&gt;
| 0x1E || 0x21 || ServiceName (&amp;quot;GROUP NAME (SSID)&amp;quot;). NUL-terminated string. See below.&lt;br /&gt;
|-&lt;br /&gt;
| 0x3F || 0x1 || s8 Flags count. Must be &amp;lt;=0x3F.&lt;br /&gt;
|-&lt;br /&gt;
| 0x40 || 0x40 || Array of s8 with the above count. Each entry value must be &amp;lt;=0x3F. Each entry is an array index used to load a set of flags from a global array with the specified index. global_flags are also masked with flags loaded from here. User-processes use entryval=1 as the default, with [11.0.0+] entryval=0 can be used for standard WPA2-PSK (see +0x8A).&lt;br /&gt;
|-&lt;br /&gt;
| 0x80 || 0x1 || SupportedPlatform. Must match value 1. 0 is PlatformIdNX, 1 is PlatformIdRcd.&lt;br /&gt;
|-&lt;br /&gt;
| 0x81 || 0x1 || MemberCountMax. s8, Must be &amp;lt;=0x8. During group creation this is passed to [[WLAN_services|wlan:lcl]] cmd40, when this is value 0 a default of value 1 is passed. During group-creation when the below +0x88 field is not value 0x2, the passed [[BTM_services#SetWlanMode|WlanMode]] is &amp;lt;code&amp;gt;x81_field_val &amp;gt; 3&amp;lt;/code&amp;gt;.&lt;br /&gt;
|-&lt;br /&gt;
| 0x82 || 0x1 || &lt;br /&gt;
|-&lt;br /&gt;
| 0x84 || 0x2 || Frequency. Wifi frequency: 24 = 2.4GHz, 50 = 5GHz.&lt;br /&gt;
|-&lt;br /&gt;
| 0x86 || 0x2 || s16 Channel (&amp;quot;CHANNEL&amp;quot;). Wifi channel number. 0 = use default, otherwise this must be one of the following depending on the frequency field:&lt;br /&gt;
* 24: 1, 6, 11.&lt;br /&gt;
* 50: 36, 40, 44, 48.&lt;br /&gt;
|-&lt;br /&gt;
| 0x88 || 0x1 || NetworkMode. Used during group-creation to determine the [[BTM_services#SetWlanMode|WlanMode]] to use. When this is value 0x2, mode=3 is used, otherwise it&#039;s determined via the +0x81 field.&lt;br /&gt;
|-&lt;br /&gt;
| 0x89 || 0x1 || PerformanceRequirement.&lt;br /&gt;
|-&lt;br /&gt;
| 0x8A || 0x1 || Security type, used during key derivation. 0 = use defaults, 1 = plaintext, 2 = encrypted. [11.0.0+] 3: Standard WPA2-PSK.&lt;br /&gt;
|-&lt;br /&gt;
| 0x8B || 0x1 || StaticAesKeyIndex. s8, used as the array-index for selecting the KeySource used with [[SPL_services#GenerateAesKek|GenerateAesKek]] during key derivation. Should be 1-2, otherwise GenerateAesKek is skipped and zeros are used for the AccessKey instead.&lt;br /&gt;
|-&lt;br /&gt;
| 0x8D || 0x1 || Priority. Must match one of the following, depending on the used service (doesn&#039;t apply to [[#Join]]): 55 = SystemPriority (lp2p:sys), 90 = ApplicationPriority (lp2p:app and lp2p:sys).&lt;br /&gt;
|-&lt;br /&gt;
| 0x8E || 0x1 || StealthEnabled. Bool flag, controls whether the SSID is hidden.&lt;br /&gt;
|-&lt;br /&gt;
| 0x8F || 0x1 || If zero, a default value of 0x20 is used.&lt;br /&gt;
|-&lt;br /&gt;
| 0x1C0 || 0x1 || PresharedKeyBinarySize. Must be 0x20 for PresharedKeyBinary. [11.0.0+] With WPA2-PSK, this must be value 1.&lt;br /&gt;
|-&lt;br /&gt;
| 0x1C1 || 0x3F ([9.0.0-10.2.0] 0x20) || PresharedKey. Used to derive encryption keys A and C. [11.0.0+] With WPA2-PSK, this is the passphrase string (length must be at least 8).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
In order for the ServiceName to be valid without a new one being generated, the following checks must pass:&lt;br /&gt;
* It loops through the characters in the string, looking for the first &#039;_&#039; character:&lt;br /&gt;
** The loop will exit once a &#039;_&#039; character is found.&lt;br /&gt;
** The character must be &#039;-&#039;, or alphanumeric (lowercase/uppercase), otherwise the function will immediately return failure.&lt;br /&gt;
** The loop will also exit once string_pos is &amp;gt;19, in which case the function will also immediately return failure.&lt;br /&gt;
* Then it checks the 11 characters which follow the above:&lt;br /&gt;
** The character must be hex: &#039;0&#039;-&#039;9&#039;, or &#039;A-F&#039; / &#039;a-&#039;f.&lt;br /&gt;
* The following character must be a NUL-terminator.&lt;br /&gt;
* The last hex character above, then the characters for the whole string prior to the last hex character are summed. return sum % 0x2B == 0. u32 is used for these calculations. (Return success when sum is a multiple of 0x2B, otherwise return failure)&lt;br /&gt;
&lt;br /&gt;
If the above fails, then the following runs, otherwise it just returns 0:&lt;br /&gt;
* It loops through the characters in the string.&lt;br /&gt;
** The character must be &#039;-&#039;, or alphanumeric (lowercase/uppercase), otherwise the function will immediately return failure.&lt;br /&gt;
** The loop will exit once string_pos&amp;gt;20 is reached, or when a NUL-terminator is reached.&lt;br /&gt;
* Once finished, success is returned if string_pos-1 is &amp;lt;20, otherwise failure is returned (which also immediately occurs if the first character is a NUL-terminator).&lt;br /&gt;
&lt;br /&gt;
If the above fails, an error is returned, otherwise a new ServiceName is generated:&lt;br /&gt;
* Up to 20 characters are copied from the original ServiceName to the output ServiceName, stopping once the limit is reached or when a NUL-terminator is reached.&lt;br /&gt;
* &#039;_&#039; is appended to the string.&lt;br /&gt;
* &amp;lt;code&amp;gt;nn::util::TSNPrintf({strptr following the above character}, {remaining size}, &amp;quot;%02X%02X%02X%02X%02X&amp;quot;, [[#GroupId|GroupId_byte3]], [[#GroupId|GroupId_byte4]], [[#GroupId|GroupId_byte5]], ([[SPL_services#IsDevelopment|IsDevelopment]] ? 0x80 : 0) | 0x1, 0);&amp;lt;/code&amp;gt;&lt;br /&gt;
* Then the last character is set to the output from a calling a function:&lt;br /&gt;
** All string characters which were already written are summed same way as above. Then: &amp;lt;code&amp;gt;return character_lookup_table[sum % 0x2B];&amp;lt;/code&amp;gt; (If the length passed to this function is 0, this will instead just return character_lookup_table[0])&lt;br /&gt;
*** character_lookup_table contains 0x2B entries: [V-A][k-a][5-0][Z-W].&lt;br /&gt;
&lt;br /&gt;
loaded_flags are first loaded from elsewhere, then masked with the above flags when available. loaded_flags are used when +0x8A is 0. global_flags are loaded from global data. These flags are only used with [[#CreateGroup]]/[[#Join]]. Flags (note that the following was updated with [11.0.0+], and differs from below):&lt;br /&gt;
* Bit2 clear:&lt;br /&gt;
** global_flags must be non-zero, and loaded_flags bit1 must be set.&lt;br /&gt;
** u8 +0x8A is set to value 1.&lt;br /&gt;
** When the cached [[SPL_services#IsDevelopment|IsDevelopment]] value is false (retail), an error is thrown.&lt;br /&gt;
** u8 +0x8B is set to value 0.&lt;br /&gt;
* Otherwise, if bit2 is set:&lt;br /&gt;
** u8 +0x8A is set to value 2.&lt;br /&gt;
** global_flags bit1 set:&lt;br /&gt;
*** u8 +0x8B is set to value 1.&lt;br /&gt;
** Otherwise, if global_flags bit2 is set:&lt;br /&gt;
*** u8 +0x8B is set to value 2.&lt;br /&gt;
&lt;br /&gt;
= ScanResult =&lt;br /&gt;
This is &amp;quot;nn::lp2p::ScanResult&amp;quot;. This is a 0x300-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x200 || [[#GroupInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x200 || 0x1 || &lt;br /&gt;
|-&lt;br /&gt;
| 0x206 || 0x2 || AdvertiseData size.&lt;br /&gt;
|-&lt;br /&gt;
| 0x208 || 0x80 || AdvertiseData&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Network protocol =&lt;br /&gt;
== ldn ==&lt;br /&gt;
A beacon and Action frame are broadcasted. The SSID in the beacon is hidden (32-bytes with value 0). For [[#Scan]]/[[#ScanPrivate]] it doesn&#039;t matter if no beacon is available ([[#NetworkInfo]] is the same), as long as the Action frame is broadcasted. However, the Station will not send a probe-request during connection if no beacon is available (and therefore not attempt any communication with the AccessPoint). The beacon doesn&#039;t have any custom Nintendo data, that data is in the Action frame.&lt;br /&gt;
&lt;br /&gt;
During connection, the Station first sends a probe-request using the [[#NetworkInfo|generated]] SSID from the Action frame. If the probe-response contains the expected data for the [[#SecurityConfig]] type, the Station then proceeds to connect to the AccessPoint.&lt;br /&gt;
&lt;br /&gt;
Keys are derived with: &amp;lt;code&amp;gt;GenerateAesKek(AccessKey, KeySource, Generation, Option=0); GenerateAesKey(out_key, AccessKey, {output from SHA256(data_to_hash)});&amp;lt;/code&amp;gt; The key for data-frames, if [[#SecurityConfig|enabled]], is derived from a buffer containing: {[[#SecurityParameter]]+0x0} followed by {[[#SecurityConfig]] Passphrase with the specified PassphraseSize}. The [[#ActionFrame]]/data-frame keys are derived roughly the same, the only difference is the data for hashing + the [[SPL_services|KeySource]]. The key derived by ldn is used directly as the static CCMP key for all data-frames (CCMP / MIC is standard). When [[#Protocol|Protocol]] is 3 the [[SPL_services|Generation]] is [[19.0.0|0x13]] instead of 0x0, for all of the previously mentioned keys derivation.&lt;br /&gt;
&lt;br /&gt;
Then the Station scans for an [[#ActionFrame]] for loading the [[#NetworkInfo]].&lt;br /&gt;
&lt;br /&gt;
Once connected, the AccessPoint sends Epigram-vendor Action frame(s) (same data) to the Station, the Station doesn&#039;t require these frames: &amp;lt;code&amp;gt;dd1afeedfacedeadbeef010000000a00000000000000000000000000&amp;lt;/code&amp;gt;. Then the Station must Authenticate with the AccessPoint, this is custom. The Station sends a frame (a maximum of 3 times in some cases if errors occur, with the same data), and the AccessPoint sends a response. Once Authenticated, the node is added to the [[#NodeInfo|NodeInfo]] array in [[#NetworkInfo]]. If the Station does not successfully Authenticate X-seconds after connecting, the AccessPoint disconnects the Station. If the Station fails to Authenticate, the Station itself will disconnect as well.&lt;br /&gt;
&lt;br /&gt;
After Authentication the Station will scan for another [[#ActionFrame]], with frame-comparision enabled with the above frame (frame must have been updated since the previous scan). The Station locates the index for a [[#MacAddress|MacAddress]] matching itself in the [[#NetworkInfo]] [[#NodeInfo|NodeInfo]] array (the entry for the AccessPoint is skipped), throwing an error if not found. After validating the LocalCommunicationVersion, it proceeds to handle ARP setup below.&lt;br /&gt;
&lt;br /&gt;
This does not use DHCP, each node on the network has to manually setup IP-config with the [[#NodeInfo|NodeInfo]] array in [[#NetworkInfo]]. [?+] After the client is [[#EthFrame|authenticated]] ARP may be used in some cases however.&lt;br /&gt;
&lt;br /&gt;
At this point standard sockets can be used over Data frames.&lt;br /&gt;
&lt;br /&gt;
=== EthFrame ===&lt;br /&gt;
The custom Ethernet frames have the following structure:&lt;br /&gt;
* &amp;quot;Type: IEEE 802a OUI Extended Ethertype (0x88b7)&amp;quot;&lt;br /&gt;
* &amp;quot;IEEE802a OUI Extended Ethertype&amp;quot;:&lt;br /&gt;
** &amp;quot;Organization Code: 00:22:aa (Nintendo Co., Ltd.)&amp;quot;&lt;br /&gt;
** &amp;quot;Protocol ID: {...}&amp;quot;&lt;br /&gt;
*** Depends on the frame:&lt;br /&gt;
*** 0x0102: [[#Authentication]]&lt;br /&gt;
*** 0x0103: ?&lt;br /&gt;
* The first byte of Data is value 0, then the ProtocolID-specific data follows, see below.&lt;br /&gt;
** ProtocolID 0x0103 frames are sent by the AccessPoint to the Station. This is 0x20-bytes of zeros, except for the first byte which is 0x3. This is sent by the AccessPoint prior to destroying the network.&lt;br /&gt;
&lt;br /&gt;
==== Authentication ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x1 || [[#AuthVersion]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x1 || 0x1 || Low u8 for the size.&lt;br /&gt;
|-&lt;br /&gt;
| 0x2 || 0x1 || Status. 0 = success, non-zero = error.&lt;br /&gt;
|-&lt;br /&gt;
| 0x3 || 0x1 || [2.0.0+] bool flag. The AccessPoint verifies that this is not set. Always set to 1 by the AccessPoint in the response. [2.0.0-?] The Station only uses this when the [[#AuthVersion]] is &amp;gt;=2.&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || 0x1 || [6.0.0+] High u8 for the size.&lt;br /&gt;
|-&lt;br /&gt;
| 0x5 || 0x1 || [20.0.0+] AuthEncryptionType, must match the type being used by the [[#Protocol|Protocol]]. 0 = plaintext ([[#Protocol|Protocol]] NX), 1 = AES-128-GCM ([[#Protocol|Protocol]] non-NX).&lt;br /&gt;
|-&lt;br /&gt;
| 0x6 || 0x2 || Unused, zeros.&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x20 || [[#NetworkInfo]]+0, must match the corresponding data in [[#NetworkInfo]] when the receiving node verifies this. With the &lt;br /&gt;
AccessPoint-&amp;gt;Station frame, the Station verifies that this matches the data previously sent to the AccessPoint.&lt;br /&gt;
|-&lt;br /&gt;
| 0x28 || 0x10 || [[#NetworkInfo]]+0x50, must match the corresponding data in [[#NetworkInfo]] when the receiving node verifies this. With the &lt;br /&gt;
AccessPoint-&amp;gt;Station frame, the Station verifies that this matches the data previously sent to the AccessPoint.&lt;br /&gt;
|-&lt;br /&gt;
| 0x38 || 0x10 || AuthEncryptionType1: Used for key derivation.&lt;br /&gt;
Station-&amp;gt;AccessPoint: The Station sets this to random data. Unused by the AccessPoint (besides the above), except for copying into the response.&lt;br /&gt;
&lt;br /&gt;
AccessPoint-&amp;gt;Station: +0x38 from the data originally sent by the Station. The Station verifies that this matches the previously sent data.&lt;br /&gt;
|-&lt;br /&gt;
| 0x48 || 0x10 || Only present with AuthEncryptionType1: AES-128-GCM MAC tag.&lt;br /&gt;
|-&lt;br /&gt;
| 0x48 (0x58 with AuthEncryptionType1) || || Frame-specific payload data, with the above size. The total frame size - {offset of the start of this data in the frame} must match the above size.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
The Station sets the above size to 0x40 ([6.0.0+] if [[#NetworkInfo]]+0x13 is &amp;lt;3) ([?+] 0x64 regardless of [[#AuthVersion]]). [6.0.0+] The Authentication challenge is only used/enabled if that value is &amp;gt;=3, and [[#IUserLocalCommunicationService]] is being used.&lt;br /&gt;
&lt;br /&gt;
The AccessPoint sets the above size to 0x40 ([6.0.0+] 0x0 if the +0x0 [[#AuthVersion]] is &amp;lt;3) ([?+] 0x84 regardless of [[#AuthVersion]]). [6.0.0+] The AccessPoint will only use/enable the Authentication challenge when the +0x0 [[#AuthVersion]] is &amp;gt;=3, and [[#IUserLocalCommunicationService]] is being used. This data will not be included in the frame if the status field indicates error.&lt;br /&gt;
&lt;br /&gt;
[6.0.0+] Support for the Authentication challenge with [[ETicket_services|es]] cmds 1501-1504 was added.&lt;br /&gt;
&lt;br /&gt;
AuthEncryptionType1: The key is derived essentially the same as the data-frame CCMP key, except the input data for hashing is the 0x10-bytes at +0x38 (this also only supports using [[SPL_services|Generation]] 0x13, returning immediately if the input param indicates otherwise due to the [[#Protocol|Protocol]]). The encrypted AES-128-GCM data starts at +0x58 with the above size. The 0xC-bytes IV is at +0x0, the AAD is at +0x0 size 0x48-bytes.&lt;br /&gt;
&lt;br /&gt;
The AccessPoint will not respond to frames where the source mac-address is unrecognized.&lt;br /&gt;
&lt;br /&gt;
Station-&amp;gt;AccessPoint payload data, relative to frame_end above (frame size depends on whether the challenge is enabled):&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x20 || [[#UserConfig]]+0. Copied into state by the AccessPoint.&lt;br /&gt;
|-&lt;br /&gt;
| 0x20 || 0x2 || Big-endian LocalCommunicationVersion. Byte-swapped by the AccessPoint then copied into state. [?+] This is now ignored.&lt;br /&gt;
|-&lt;br /&gt;
| 0x22 || 0x1 || [19.0.0+] [[#NodeInfo|NodeInfo]] +0x2D. Copied into state by the AccessPoint. On NX the Station always sets this to 0 in the sent payload-data.&lt;br /&gt;
|-&lt;br /&gt;
| 0x23 || 0x1D || Zeros, unused by the AccessPoint.&lt;br /&gt;
|-&lt;br /&gt;
| 0x40 || 0x24 || [6.0.0+] Zeros, unused by the AccessPoint.&lt;br /&gt;
|-&lt;br /&gt;
| 0x64 || 0x300 || [6.0.0+] Authentication challenge data. If enabled, the total frame size must be &amp;gt;= {end offset of this data in the frame}. The frame data does not include this if it&#039;s not enabled.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
AccessPoint-&amp;gt;Station response payload data, relative to frame_end above (frame size depends on whether the challenge is enabled):&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x1 || Unused, always set to 0. [S2] This is usually set to value 1?&lt;br /&gt;
|-&lt;br /&gt;
| 0x1 || 0x3F || Zeros. [6.0.0-?] Only included in the frame if it&#039;s enabled (+0x0 [[#AuthVersion]] &amp;gt;= 3). Unused by the Station.&lt;br /&gt;
|-&lt;br /&gt;
| 0x40 || 0x44 || [6.0.0-?] Only included in the frame if it&#039;s enabled (+0x0 [[#AuthVersion]] &amp;gt;= 3). Unused by the Station.&lt;br /&gt;
|-&lt;br /&gt;
| 0x84 || 0x100 || [6.0.0+] If enabled, Authentication challenge response data. Not included in the frame if it&#039;s not enabled.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
===== AuthVersion =====&lt;br /&gt;
Must be 0x1-0xF (&amp;lt;0x10 with newer versions).&lt;br /&gt;
&lt;br /&gt;
[?+] When the AccessPoint is handling the [[#Authentication|Authentication]] EthFrame, the AuthVersion must be &amp;gt;=1 for [[#Protocol|Protocol]] NX, and &amp;gt;=4 for [[#Protocol|Protocol]] 3.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value || SystemVersion&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [1.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [2.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [6.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [19.0.0+]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== ActionFrame ===&lt;br /&gt;
The Action frames have the following structure:&lt;br /&gt;
* &amp;quot;Fixed parameters&amp;quot;:&lt;br /&gt;
** &amp;quot;Category code: Vendor Specific (127)&amp;quot;&lt;br /&gt;
** &amp;quot;OUI: 00:22:aa (Nintendo Co., Ltd.)&amp;quot;&lt;br /&gt;
* The Data starts with the following header:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x2 || 04 00 in sent frames.&lt;br /&gt;
|-&lt;br /&gt;
| 0x2 || 0x2 || Protocol ID, must be 0x0101.&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || 0x2 || Must be 0.&lt;br /&gt;
|-&lt;br /&gt;
| 0x6 || 0x2 || Zeros, unused.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Then the actual data follows:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x20 || [[#NetworkInfo]]+0x0. The u64/u16 are big-endian. Outside of [[#Scan]]/[[#ScanPrivate]], this must match the previously loaded data for this.&lt;br /&gt;
|-&lt;br /&gt;
| 0x20 || 0x1 || [[#AuthVersion]]. Copied to [[#NetworkInfo]]+0x63. When comparing with a previous frame is enabled, this must match the value from the previous frame.&lt;br /&gt;
|-&lt;br /&gt;
| 0x21 || 0x1 || Encryption type: 1 = plaintext, 2 = AES-128-CTR, [20.0.0+] 3 = AES-128-GCM, {frames with other values are ignored by [[#Scan]]/[[#ScanPrivate]]}. Must match the type which is currently being used: with [[#Scan]]/[[#ScanPrivate]] this is determined via this field, otherwise [[#SecurityConfig]] is used to determine this.&lt;br /&gt;
|-&lt;br /&gt;
| 0x22 || 0x2 || Big-endian u16 size for the data starting at +0x48 (+0x38 with EncryptionType3), and must match {total frame size relative to +0x0 above} - {header_size}.&lt;br /&gt;
|-&lt;br /&gt;
| 0x24 || 0x4 || Big-endian u32 Counter. The initial value is randomly-generated. This is incremented each time the below content is updated (including initial creation). Also used by the Station to determine whether the frame changed compared to a previous one. When comparing against a previous frame, new_counter-prev_counter must be &amp;lt;= 0xFF, and the counters must not match.&lt;br /&gt;
|-&lt;br /&gt;
| 0x28 || 0x20 || EncryptionType1-2: SHA256 hash over the entire frame starting at +0x0, with the above size + 0x48. During hashing, this hash is cleared, with the new hash overwriting the original in memory (the original is copied to stack for comparing).&lt;br /&gt;
|-&lt;br /&gt;
| 0x28 || 0x10 || EncryptionType3: AES-128-GCM MAC tag (replaces the SHA256 hash).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Using EncryptionType3 outside of [[#Scan]]/[[#ScanPrivate]] is enabled with [[#Protocol|Protocol]] non-NX.&lt;br /&gt;
&lt;br /&gt;
When encryption is enabled, the encrypted data is at +0x28 (+0x38 with EncryptionType3) with size {remaining frame size}. The key is derived from the raw 0x20-bytes at +0x0. The CTR/IV is {raw Counter above without byte-swap}, with the rest cleared to zeros. The AAD for AES-128-GCM is at +0x0 size 0x28-bytes.&lt;br /&gt;
&lt;br /&gt;
Originally [[#Scan]]/[[#ScanPrivate]] used the EncryptionType field to determine encryption handling. With [18.0.0+] these now set an internal SecurityMode field to 0 (Any) initially, then later uses the same SecurityMode override as [[#CreateNetwork|CreateNetwork]]. The internal SecurityMode field is used to determine encryption handling: Any uses the EncryptionType field like before. With non-zero the encryption handling is determined as required by the SecurityMode.&lt;br /&gt;
&lt;br /&gt;
The content data at +{above_header_size} follows, which has the size specified above (which must be &amp;gt;=0x500 with EncryptionType1-2), where all fields are big-endian. For EncryptionType1-2:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x10 || [[#NetworkInfo]]+0x50&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x2 || [[#NetworkInfo]]+0x60&lt;br /&gt;
|-&lt;br /&gt;
| 0x12 || 0x1 || [[#NetworkInfo]]+0x62&lt;br /&gt;
|-&lt;br /&gt;
| 0x13 || 0x1 || Unused&lt;br /&gt;
|-&lt;br /&gt;
| 0x14 || 0x2 || &lt;br /&gt;
|-&lt;br /&gt;
| 0x16 || 0x1 || s8 [[#NetworkInfo]]+0x66, clamped to range 1-8.&lt;br /&gt;
|-&lt;br /&gt;
| 0x17 || 0x1 || s8 [[#NetworkInfo]]+0x67, clamped to range 1-8.&lt;br /&gt;
|-&lt;br /&gt;
| 0x18 || 0x1C0(0x38*8) || Array of the below node struct.&lt;br /&gt;
|-&lt;br /&gt;
| 0x1D8 || 0x2 || Unused&lt;br /&gt;
|-&lt;br /&gt;
| 0x1DA || 0x2 || [[#NetworkInfo]]+0x26A&lt;br /&gt;
|-&lt;br /&gt;
| 0x1DC || 0x180 || [[#NetworkInfo]]+0x26C&lt;br /&gt;
|-&lt;br /&gt;
| 0x35C || 0x19C || Unused&lt;br /&gt;
|-&lt;br /&gt;
| 0x4F8 || 0x8 || [6.0.0+] [[#NetworkInfo]]+0x478&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
For EncryptionType3:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x10 || [[#NetworkInfo]]+0x50&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x8 || [[#NetworkInfo]]+0x478 [S2] The Station seems to verify that this is 0 when the Challenge is unused (ldn:s)? Throws an error if set before connecting to an [[#Protocol|Ounce]] network.&lt;br /&gt;
|-&lt;br /&gt;
| 0x18 || 0x1 || [[#NetworkInfo]]+0x60&lt;br /&gt;
|-&lt;br /&gt;
| 0x19 || 0x1 || [[#NetworkInfo]]+0x62&lt;br /&gt;
|-&lt;br /&gt;
| 0x1A || 0x2 || s16 LocalCommunicationVersion. Must not be negative.&lt;br /&gt;
|-&lt;br /&gt;
| 0x1C || 0x8 || Unused?&lt;br /&gt;
|-&lt;br /&gt;
| 0x24 || 0x2 || Same as +0x14 in the above struct for EncryptionType1-2.&lt;br /&gt;
|-&lt;br /&gt;
| 0x26 || 0x1 || s8 [[#NetworkInfo]]+0x66 (NodeCountMax)&lt;br /&gt;
|-&lt;br /&gt;
| 0x27 || 0x1 || s8 [[#NetworkInfo]]+0x67 (NodeCount)&lt;br /&gt;
|-&lt;br /&gt;
| 0x28 || NodeCount*0x30 || Array of the below node struct.&lt;br /&gt;
|-&lt;br /&gt;
| 0x28 + (NodeCount*0x30) || 0x2 || [[#NetworkInfo]]+0x26A (AdvertiseDataSize)&lt;br /&gt;
|-&lt;br /&gt;
| 0x2A + (NodeCount*0x30) || AdvertiseDataSize || [[#NetworkInfo]]+0x26C (AdvertiseData)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
The data here is copied into [[#NetworkInfo]].&lt;br /&gt;
&lt;br /&gt;
Node data used in the above array (all fields big-endian), which are copied into the [[#NetworkInfo]] [[#NodeInfo|NodeInfo]] array. For EncryptionType1-2:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x4 || [[#Ipv4Address]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || 0x6 || [[#MacAddress|MacAddress]]&lt;br /&gt;
|-&lt;br /&gt;
| 0xA || 0x1 || bool IsConnected&lt;br /&gt;
|-&lt;br /&gt;
| 0xB || 0x1 || [19.0.0+] [[#NodeInfo|NodeInfo]] +0x2D&lt;br /&gt;
|-&lt;br /&gt;
| 0xC || 0x20 || First 0x20-bytes of [[#UserConfig]].&lt;br /&gt;
|-&lt;br /&gt;
| 0x2C || 0x2 || s16 LocalCommunicationVersion &lt;br /&gt;
|-&lt;br /&gt;
| 0x2E || 0xA || Unused&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
For EncryptionType3:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x4 || [[#Ipv4Address]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || 0x6 || [[#MacAddress|MacAddress]]&lt;br /&gt;
|-&lt;br /&gt;
| 0xA || 0x1 || NodeId&lt;br /&gt;
|-&lt;br /&gt;
| 0xB || 0x1 || [[#NodeInfo|NodeInfo]] +0x2D&lt;br /&gt;
|-&lt;br /&gt;
| 0xC || 0x20 || First 0x20-bytes of [[#UserConfig]].&lt;br /&gt;
|-&lt;br /&gt;
| 0x2C || 0x4 || Unused&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== ActionFrame2 ===&lt;br /&gt;
The Action frames used by [[#SendActionFrame|SendActionFrame]]/[[#RecvActionFrame|RecvActionFrame]] have the following structure:&lt;br /&gt;
* &amp;quot;Fixed parameters&amp;quot;:&lt;br /&gt;
** &amp;quot;Category code: Vendor Specific (127)&amp;quot;&lt;br /&gt;
** &amp;quot;OUI: 00:22:aa (Nintendo Co., Ltd.)&amp;quot;&lt;br /&gt;
* The Data starts with the following header:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x2 || 04 00&lt;br /&gt;
|-&lt;br /&gt;
| 0x2 || 0x2 || Protocol ID, must match big-endian 0x0102.&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || 0x2 || 00 00&lt;br /&gt;
|-&lt;br /&gt;
| 0x6 || 0x2 || 00 00&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Then the actual data follows (all fields big-endian):&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x1 || [[#AuthVersion]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x1 || 0x1 || EncryptionType, must match the expected type for the current SecurityMode. 1 = plaintext, 2 = AES-128-GCM.&lt;br /&gt;
|-&lt;br /&gt;
| 0x2 || 0x2 || Padding&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || 0x4 || Counter&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x8 || LocalCommunicationId&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x10 || Used with key derivation.&lt;br /&gt;
|-&lt;br /&gt;
| 0x20 || 0x10 || EncryptionType2: AES-128-GCM MAC tag.&lt;br /&gt;
|-&lt;br /&gt;
| 0x30 || Remaining frame size || Data payload&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
The 0xC-byte IV for AES-128-GCM is the raw 4-bytes from the above Counter, with the rest cleared to zeroes. The encrypted data is at +0x30, with the remaining frame size. The AAD is the 0x20-bytes at +0x0.&lt;br /&gt;
&lt;br /&gt;
The key is derived similar to the regular action-frame key (same KeySource), except: the Generation is always [[17.0.0|0x11]], with the following data for hashing: {big-endian LocalCommunicationId} {+0x10 size 0x10-bytes} {[[#ActionFrameSettings]] Passphrase with the specified PassphraseSize}.&lt;br /&gt;
&lt;br /&gt;
The data payload is the data buffer for [[#SendActionFrame|SendActionFrame]]/[[#RecvActionFrame|RecvActionFrame]].&lt;br /&gt;
&lt;br /&gt;
== lp2p ==&lt;br /&gt;
This is used for communicating with accessories (external devices on [11.0.0+]) over local wifi. [[Mario Kart Live: Home Circuit]] uses this. [11.0.0+] [[Album_Applet|LibraryAppletPhotoViewer]] uses this.&lt;br /&gt;
&lt;br /&gt;
A beacon is broadcasted.&lt;br /&gt;
&lt;br /&gt;
Action frames are only sent when done so by [[#SendToOtherGroup]] (other than the Epigram one mentioned below).&lt;br /&gt;
&lt;br /&gt;
Communication uses sockets with standard Data frames and the above Action frames. Switch consoles presumably only use the Action frames to communicate with each other?&lt;br /&gt;
&lt;br /&gt;
Key A derived by ldn-sysmodule is used directly as the static CCMP key for all data-frames (CCMP / MIC is standard). However, with [[#GroupInfo]]+0x8A value 3, standard WPA2-PSK is used instead.&lt;br /&gt;
&lt;br /&gt;
This uses infrastructure-mode (AccessPoint), and DHCP is used. The group-owner is the AccessPoint. Note that the probe response includes the same Nintendo tags included with the beacon. Once connected, the group-owner sends the same Epigram-vendor Action frame(s) described in [[#ldn]]. At this point socket communication can begin, including DHCP usage.&lt;br /&gt;
&lt;br /&gt;
The DHCP server thread is started by the &amp;quot;nn.lp2p.StateMachine&amp;quot; thread eventually during group [[#CreateGroup|creation]]. The DHCP Offer option values are the following:&lt;br /&gt;
* &amp;quot;Subnet Mask: 255.255.255.0&amp;quot;&lt;br /&gt;
* &amp;quot;DHCP Server Identifier: {...}&amp;quot;&lt;br /&gt;
* &amp;quot;Broadcast Address: {...}&amp;quot;&lt;br /&gt;
* &amp;quot;IP Address Lease Time: (5s) 5 seconds&amp;quot;&lt;br /&gt;
* &amp;quot;Renewal Time Value: (0s) 0 seconds&amp;quot;&lt;br /&gt;
* &amp;quot;Rebinding Time Value: (0s) 0 seconds&amp;quot;&lt;br /&gt;
* &amp;quot;Interface MTU: 1500&amp;quot;&lt;br /&gt;
&lt;br /&gt;
Note that the above options doesn&#039;t include &amp;quot;Domain Name Server&amp;quot; or &amp;quot;Router&amp;quot;, the client device may fail to connect if it doesn&#039;t allow those DHCP options to be missing.&lt;br /&gt;
&lt;br /&gt;
=== Beacon ===&lt;br /&gt;
The SSID in the beacon can optionally be [[#GroupInfo|hidden]] (all-zero with the same length as the original SSID). The beacon contains two vendor-specific Nintendo information elements with OUI &amp;lt;code&amp;gt;00:22:aa&amp;lt;/code&amp;gt;; each IE has a 2-byte ID following the OUI. These Nintendo IEs are not used when standard WPA2-PSK is being used.&lt;br /&gt;
&lt;br /&gt;
The beacon is identical to ldn, except for the following (besides SSID length difference and the lp2p-only Nintendo tags): &lt;br /&gt;
* &amp;quot;Tag: HT Capabilities (802.11n D1.10)&amp;quot;: &amp;quot;HT Short GI for 20MHz&amp;quot; is set to &amp;quot;Not supported&amp;quot;, for ldn it&#039;s &amp;quot;Supported&amp;quot;.&lt;br /&gt;
* &amp;quot;Tag: Vendor Specific: Microsoft Corp.: WMM/WME: Parameter Element&amp;quot; &amp;quot;Ac Parameters ACI 0&amp;quot;: &amp;quot;CW Min: 15&amp;quot; for lp2p, &amp;quot;CW Min: 63&amp;quot; for ldn.&lt;br /&gt;
&lt;br /&gt;
Note that during group creation the beacon may be missing the Nintendo IEs in some cases, since group creation didn&#039;t finish yet.&lt;br /&gt;
&lt;br /&gt;
==== Nintendo IE 0 ====&lt;br /&gt;
&lt;br /&gt;
The first Nintendo IE (ID 0x0600) contains the following fixed parameters:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x1 || Fixed 0x20; perhaps a version or other magic number.&lt;br /&gt;
|-&lt;br /&gt;
| 0x1 || 0x1 || [[#GroupInfo|SecurityType]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x2 || 0x1 || [[#GroupInfo|StaticAesKeyIndex]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x3 || 0x1 || Fixed zero; padding byte.&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || 0x8 || Big-endian (i.e. byte-reversed) version of [[#GroupInfo|LocalCommunicationId]]. This is the only context where LocalCommunicationId is reversed.&lt;br /&gt;
|-&lt;br /&gt;
| 0xC || 0x10 || Wrapped master key. Same as [[#GroupInfo]]+0x0.&lt;br /&gt;
|-&lt;br /&gt;
| 0x1C || 0x4 || If encryption is enabled, a randomly-generated nonce, else nothing. Appending 8 zero bytes to this yields the AES-GCM IV.&lt;br /&gt;
|-&lt;br /&gt;
| 0x20 || 0x10 || If encryption is enabled, the AES-GCM MAC tag, else nothing. All bytes prior to this (fixed 0x20 through nonce) are the additional authenticated data. All bytes after this are encrypted with key B.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
After this, TLV tagged parameters occur. Each TLV tag is formatted as:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x1 || Tag type&lt;br /&gt;
|-&lt;br /&gt;
| 0x1 || 0x1 || Length&lt;br /&gt;
|-&lt;br /&gt;
| 0x2 || {above size} || Data for the tag&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Known TLV tags:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Type&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x1 || 0x2 || Additional network parameters: 0xAB 0xCD. A=[[#GroupInfo]]+0x82, B=[[#GroupInfo|MemberCountMax]], C=[[#GroupInfo|NetworkMode]], D=[[#GroupInfo|PerformanceRequirement]].&lt;br /&gt;
|-&lt;br /&gt;
| 0x2 || 0x8 || Flags: Bitwise-or of (1&amp;lt;&amp;lt;f) for each entry in [[#GroupInfo]]+0x40&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Nintendo IE 1 ====&lt;br /&gt;
&lt;br /&gt;
The second Nintendo IE (ID 0x0601) contains only TLVs. If encryption is enabled, a 0x4-byte nonce and 0x10-byte AES-GCM tag are written first, as above, and the TLVs are encrypted. Key C is used.&lt;br /&gt;
&lt;br /&gt;
Known TLV tags:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Type&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x21 || Varies || AdvertiseData&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== ActionFrame ===&lt;br /&gt;
The Action frames have the following structure:&lt;br /&gt;
* &amp;quot;Fixed parameters&amp;quot;:&lt;br /&gt;
** &amp;quot;Category code: Vendor Specific (127)&amp;quot;&lt;br /&gt;
** &amp;quot;OUI: 00:22:aa (Nintendo Co., Ltd.)&amp;quot;&lt;br /&gt;
* The Data starts with the following:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x2 || Usually 06 00?&lt;br /&gt;
|-&lt;br /&gt;
| 0x2 || 0x2 || Usually 20 02?(Second byte depends on whether encryption is used?)&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || 0x2 || Usually 02 00?(varies)&lt;br /&gt;
|-&lt;br /&gt;
| 0x6 || 0x8 || Big-endian version of [[#GroupInfo]]+0x10.&lt;br /&gt;
|-&lt;br /&gt;
| 0xE || 0x10 || Same as [[#GroupInfo]]+0x0.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
When encryption is used, the remaining data is:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x4 || Big-endian u32 Counter. The initial value is randomly-generated (?). This is incremented with each sent Action frame.&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || {remaining size} || Encrypted user-data. Also includes 0x10-bytes of unknown data.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
When plaintext is used, the remaining data is:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || {remaining size} || Plaintext user-data.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Notes =&lt;br /&gt;
The following services are accessible to ldn:&lt;br /&gt;
* arp:r, bsd:s, btm, es, fatal:u, ifcfg, lm, nifm:s, pl:s, set:sys, spl:mig, wlan&lt;br /&gt;
&lt;br /&gt;
[S2] Access to btm and spl:mig were replaced with bt:sys and spl:ldn.&lt;br /&gt;
&lt;br /&gt;
[S2] Various objects/state have the same size/layout as S1, generally?(Other than IPC-related differences) There&#039;s also stack differences.&lt;br /&gt;
&lt;br /&gt;
== Code-region Memory Layout ==&lt;br /&gt;
=== S2 20.2.0 ===&lt;br /&gt;
This is the codebin-region layout for S2 ldn 20.2.0-20.5.0. BuildId is &amp;quot;DC456FA4...&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
The on-NX note is for the equivalent memregion location/size, memregion-size/contents compared to NX may vary.&lt;br /&gt;
&lt;br /&gt;
Total size is 0x24F000-bytes.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Permissions&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0xE1000 || --X || .text&lt;br /&gt;
|-&lt;br /&gt;
| 0xE1000 || 0x3D000 || R-- || RO-region&lt;br /&gt;
|-&lt;br /&gt;
| 0x11E000 || 0x3A000 || RW || On NX this is at 0xEF000. The main ExpHeap is at +0x2000, on NX it&#039;s at +0x1000.&lt;br /&gt;
|-&lt;br /&gt;
| 0x158000 || 0x8000 || non-RW || On NX this is at 0x123000.&lt;br /&gt;
|-&lt;br /&gt;
| 0x160000 || 0x8000 || RW || On NX this is at 0x12B000.&lt;br /&gt;
|-&lt;br /&gt;
| 0x168000 || 0xF000 || non-RW || On NX this is at 0x139000.&lt;br /&gt;
|-&lt;br /&gt;
| 0x177000 || 0x3000 || RW || On NX this is at 0x13F000.&lt;br /&gt;
|-&lt;br /&gt;
| 0x17A000 || 0x24000 || non-RW || On NX this is at 0x14B000.&lt;br /&gt;
|-&lt;br /&gt;
| 0x19E000 || 0x4E000 || RW || On NX this is at 0x16F000.&lt;br /&gt;
|-&lt;br /&gt;
| 0x1EC000 || 0x2000 || -- || On NX this is at 0x1BD000.&lt;br /&gt;
|-&lt;br /&gt;
| 0x1EE000 || 0x2000 || {accessible} || On NX this is at 0x1BF000.&lt;br /&gt;
|-&lt;br /&gt;
| 0x1EF000 || 0x5000 || -- || On NX this is at 0x1E2000.&lt;br /&gt;
|-&lt;br /&gt;
| 0x1F4000 || 0x21000 || {accessible} || On NX this is at 0x1EA000.&lt;br /&gt;
|-&lt;br /&gt;
| 0x218000 || 0x8000 || -- ||&lt;br /&gt;
|-&lt;br /&gt;
| 0x220000 || 0x2F000 || {accessible}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[[Category:Services]]&lt;/div&gt;</summary>
		<author><name>Yellows8</name></author>
	</entry>
	<entry>
		<id>https://switchbrew.org/w/index.php?title=Internet_Browser&amp;diff=14822</id>
		<title>Internet Browser</title>
		<link rel="alternate" type="text/html" href="https://switchbrew.org/w/index.php?title=Internet_Browser&amp;diff=14822"/>
		<updated>2026-07-25T19:39:10Z</updated>

		<summary type="html">&lt;p&gt;Yellows8: /* WebApplet launch with Tetris */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Nintendo Switch does not have a normal Internet Browser for user usage. However, there is multiple browser applets. It is the [https://web.archive.org/web/20170304075230/https://gl.access-company.com/news_event/archives/2017/170303/ NetFront NX] browser, which is based on Webkit.&lt;br /&gt;
&lt;br /&gt;
When linking the Nintendo Account with Facebook, the Facebook Auth website will open, offering a search box that can be used to browse the Internet (&amp;quot;LoginApplet&amp;quot;). Alternatively, it can be accessed with custom DNS settings which simulate a Wi-Fi login page ([[#WifiWebAuthApplet|WifiWebAuthApplet]] for captive-portal).&lt;br /&gt;
&lt;br /&gt;
At some point WebApplet started sending header &amp;quot;Upgrade-Insecure-Requests: 1&amp;quot; with all plain-HTTP requests (unknown whether other applets affected). This is only for server-use: plain-HTTP content and redirects to plain-HTTP URLs are still allowed (at least on S1).&lt;br /&gt;
&lt;br /&gt;
== Known User Agent Strings ==&lt;br /&gt;
{| class=&#039;wikitable&#039;&lt;br /&gt;
! System Version&lt;br /&gt;
! UA String&lt;br /&gt;
|-&lt;br /&gt;
| [[1.0.0]]&lt;br /&gt;
| Mozilla/5.0 (Nintendo Switch; &amp;lt;appletname&amp;gt;) AppleWebKit/601.6 (KHTML, like Gecko) NF/4.0.0.4.25 NintendoBrowser/5.1.0.11682&lt;br /&gt;
|-&lt;br /&gt;
| [[2.0.0]]&lt;br /&gt;
| Mozilla/5.0 (Nintendo Switch; &amp;lt;appletname&amp;gt;) AppleWebKit/601.6 (KHTML, like Gecko) NF/4.0.0.5.9 NintendoBrowser/5.1.0.13341&lt;br /&gt;
|-&lt;br /&gt;
| [[2.1.0]]-[[2.3.0]]&lt;br /&gt;
| Mozilla/5.0 (Nintendo Switch; &amp;lt;appletname&amp;gt;) AppleWebKit/601.6 (KHTML, like Gecko) NF/4.0.0.5.10 NintendoBrowser/5.1.0.13343&lt;br /&gt;
|-&lt;br /&gt;
| [[3.0.0]]&lt;br /&gt;
| Mozilla/5.0 (Nintendo Switch; &amp;lt;appletname&amp;gt;) AppleWebKit/601.6 (KHTML, like Gecko) NF/4.0.0.6.9 NintendoBrowser/5.1.0.14936&lt;br /&gt;
|-&lt;br /&gt;
| [[4.0.0]]&lt;br /&gt;
| Mozilla/5.0 (Nintendo Switch; &amp;lt;appletname&amp;gt;) AppleWebKit/601.6 (KHTML, like Gecko) NF/4.0.0.7.9 NintendoBrowser/5.1.0.15785&lt;br /&gt;
|-&lt;br /&gt;
| [[5.0.0]]&lt;br /&gt;
| Mozilla/5.0 (Nintendo Switch; &amp;lt;appletname&amp;gt;) AppleWebKit/601.6 (KHTML, like Gecko) NF/4.0.0.8.9 NintendoBrowser/5.1.0.16739&lt;br /&gt;
|-&lt;br /&gt;
| [[5.1.0]]&lt;br /&gt;
| Mozilla/5.0 (Nintendo Switch; &amp;lt;appletname&amp;gt;) AppleWebKit/601.6 (KHTML, like Gecko) NF/4.0.0.9.3 NintendoBrowser/5.1.0.16958&lt;br /&gt;
|-&lt;br /&gt;
| [[6.0.0]]&lt;br /&gt;
| Mozilla/5.0 (Nintendo Switch; &amp;lt;appletname&amp;gt;) AppleWebKit/601.6 (KHTML, like Gecko) NF/4.0.0.10.13 NintendoBrowser/5.1.0.17805&lt;br /&gt;
|-&lt;br /&gt;
| [[6.1.0]]&lt;br /&gt;
| Mozilla/5.0 (Nintendo Switch; &amp;lt;appletname&amp;gt;) AppleWebKit/601.6 (KHTML, like Gecko) NF/4.0.0.10.14 NintendoBrowser/5.1.0.17806&lt;br /&gt;
|-&lt;br /&gt;
| [[10.0.0]]&lt;br /&gt;
| Mozilla/5.0 (Nintendo Switch; &amp;lt;appletname&amp;gt;) AppleWebKit/606.4 (KHTML, like Gecko) NF/6.0.1.15.4 NintendoBrowser/5.1.0.20389&lt;br /&gt;
|-&lt;br /&gt;
| [[20.1.0]]-[[20.1.1]]&lt;br /&gt;
| Mozilla/5.0 (Nintendo Switch; &amp;lt;appletname&amp;gt;) AppleWebKit/613.0 (KHTML, like Gecko) NF/6.0.3.27.11 NintendoBrowser/5.1.0.35219&lt;br /&gt;
[S2] Mozilla/5.0 (Nintendo Switch; &amp;lt;appletname&amp;gt;) AppleWebKit/613.0 (KHTML, like Gecko) NF/7.0.3.8.11 NintendoBrowser/5.2.0.35483&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
The UA is generated with: &amp;quot;Mozilla/5.0 (Nintendo Switch; &amp;lt;appletname&amp;gt;) AppleWebKit/&amp;lt;webkitver&amp;gt; (KHTML, like Gecko) NF/&amp;lt;nfver0&amp;gt;.&amp;lt;nfver1&amp;gt;.&amp;lt;nfver2&amp;gt; NintendoBrowser/5.&amp;lt;ninver0&amp;gt;.&amp;lt;ninver1&amp;gt;.&amp;lt;ninver2&amp;gt;&amp;quot;&lt;br /&gt;
&lt;br /&gt;
The full UA for Switch and Switch 2 are similar, on matching system-versions. The NF and NintendoBrowser versions are newer for S2 however.&lt;br /&gt;
&lt;br /&gt;
== Browser Applets ==&lt;br /&gt;
{| class=&#039;wikitable&#039;&lt;br /&gt;
! appletname (From UA)&lt;br /&gt;
! Usage&lt;br /&gt;
! Invalid TLS cert handling&lt;br /&gt;
! Uses whitelist&lt;br /&gt;
! [[Applet_Manager_services#AppletId|AppletId]]&lt;br /&gt;
! Notes&lt;br /&gt;
|-&lt;br /&gt;
| WebApplet&lt;br /&gt;
| General web-applet for use by applications(online manuals, ...).&lt;br /&gt;
| Displays an error dialog without an option to ignore it.&lt;br /&gt;
| Yes&lt;br /&gt;
| 0x13&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| ShopN&lt;br /&gt;
| Actual eShop client&lt;br /&gt;
| Just displays an error-code.&lt;br /&gt;
| Yes&lt;br /&gt;
| 0x14&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| WebApplet&lt;br /&gt;
| Offline HTML display&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| 0x17&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| LoginApplet&lt;br /&gt;
| Nintendo Account linking, and for linking Facebook and Twitter to suggest friends&lt;br /&gt;
| Just displays an error-code.&lt;br /&gt;
| Yes&lt;br /&gt;
| 0x18&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| ShareApplet&lt;br /&gt;
| Posting screenshots to social media, and (optionally) linking social media accounts&lt;br /&gt;
| Just displays an error-code.&lt;br /&gt;
| Yes&lt;br /&gt;
| 0x18&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| LobbyApplet&lt;br /&gt;
| &amp;quot;Nintendo Switch Online Lounge&amp;quot;&lt;br /&gt;
| Just displays an error-code.&lt;br /&gt;
| Yes&lt;br /&gt;
| 0x18&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| NsoApplet&lt;br /&gt;
| Nintendo Switch Online menu&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| 0x18&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| WifiWebAuthApplet&lt;br /&gt;
| Captive-portal&lt;br /&gt;
| Displays an error dialog with an option to ignore it.&lt;br /&gt;
| No&lt;br /&gt;
| 0x19&lt;br /&gt;
| &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
When whitelisting is enabled, you can only load page domains included in the whitelist, otherwise an error is displayed. This only applies to page navigation. Videos via the &amp;lt;video&amp;gt; tag are not affected, likewise with network requests with JS.&lt;br /&gt;
&lt;br /&gt;
No known applets can directly access the SD card via mounting it. This includes ShareApplet (which posts screenshots from SD to social media).&lt;br /&gt;
&lt;br /&gt;
== BrowserDll ==&lt;br /&gt;
The NROs for the OSS are stored under the BrowserDll [[Title_list|SystemData]]. All of the web-applets use the same OSS NROs via this SystemData.&lt;br /&gt;
&lt;br /&gt;
String from v2.0 in oss_wkc.nro: &amp;quot;libcurl/7.50.1&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
Almost all RomFs data for the web-applets is stored here.&lt;br /&gt;
&lt;br /&gt;
S2 has the following changes for BrowserDll, compared to S1:&lt;br /&gt;
* Various data under &amp;quot;/browser/&amp;quot; was updated.&lt;br /&gt;
** Also, the following was added under &amp;quot;/browser/&amp;quot;: &amp;quot;icudt62l.dat.lz4&amp;quot;, &amp;quot;UserCssNxCompatibleLineHeight.dat&amp;quot;.&lt;br /&gt;
** [21.0.0-21.2.0] Updated &amp;quot;/browser/ErrorPageTemplate.html&amp;quot;.&lt;br /&gt;
** [21.0.0-21.2.0] Updated &amp;quot;icudt62l.dat.lz4&amp;quot;.&lt;br /&gt;
* &amp;quot;/buildinfo/buildinfo.dat&amp;quot; differ.&lt;br /&gt;
* Added &amp;quot;/font/nintendo_private_ext.bfttf&amp;quot;. [21.0.0-21.2.0] updated&lt;br /&gt;
* Updated &amp;quot;/gfxShader/BrowserOffscreenDrawer.bnsh&amp;quot;, added &amp;quot;/gfxShader/MediaPlayerCcDrawer.bnsh&amp;quot;, updated &amp;quot;/gfxShader/MediaPlayerDrawer.bnsh&amp;quot;.&lt;br /&gt;
* The contents of UrlBlackList were moved here to &amp;quot;/&amp;quot;. These are the following:&lt;br /&gt;
** &amp;quot;listCommon.txt&amp;quot;, &amp;quot;listEcChina.txt&amp;quot;, &amp;quot;listEcGlobal.txt&amp;quot;, &amp;quot;listIframe.txt&amp;quot;, &amp;quot;listLnsChina.txt&amp;quot;, &amp;quot;listLnsGlobal.txt&amp;quot;, &amp;quot;listWebYouTubePlayerCommon.txt&amp;quot;&lt;br /&gt;
** These are identical except for &amp;quot;listLnsGlobal.txt&amp;quot;, which adds a newline at end-of-file.&lt;br /&gt;
** [21.0.0-21.2.0] These were moved into the SystemData UrlBlackList.&lt;br /&gt;
* Removed &amp;quot;/lyt/&amp;quot;.&lt;br /&gt;
* The various localization data under &amp;quot;/message/&amp;quot; was updated, etc.&lt;br /&gt;
** [21.0.0-21.2.0] updated&lt;br /&gt;
* &amp;quot;/nro/netfront/core_0/default&amp;quot;:&lt;br /&gt;
** &amp;quot;cfi_disabled/&amp;quot; is now &amp;quot;cfi_enabled/&amp;quot;.&lt;br /&gt;
** [21.0.0-21.2.0] &amp;quot;cfi_enabled/&amp;quot; is now &amp;quot;cfi_nncfi/&amp;quot;.&lt;br /&gt;
* &amp;quot;/nro/netfront/core_3/&amp;quot;:&lt;br /&gt;
** &amp;quot;default/&amp;quot; is now &amp;quot;mse/&amp;quot;.&lt;br /&gt;
** [21.0.0-21.2.0] Removed &amp;quot;/nro/netfront/core_3/&amp;quot;.&lt;br /&gt;
* Removed &amp;quot;/shader/&amp;quot;.&lt;br /&gt;
* Moved &amp;quot;/sound/&amp;quot; from SystemData into the applet RomFs, with filename/content being updated.&lt;br /&gt;
* Added &amp;quot;/ui/&amp;quot;.&lt;br /&gt;
** [21.0.0-21.2.0] updated&lt;br /&gt;
&lt;br /&gt;
== UrlBlackList ==&lt;br /&gt;
With [S2] [21.0.0-21.2.0] the list* files from BrowserDll were moved here, with the following changes:&lt;br /&gt;
* &amp;quot;listCommon.txt&amp;quot;, &amp;quot;listIframe.txt&amp;quot;, &amp;quot;listWebYouTubePlayerCommon.txt&amp;quot; are identical.&lt;br /&gt;
* The files for China/Global were removed.&lt;br /&gt;
* Added &amp;quot;listOpenWebJump.txt&amp;quot;, same as &amp;quot;listLnsGlobal.txt&amp;quot; which was removed, except the &amp;quot;nintendo*&amp;quot; entries were removed.&lt;br /&gt;
* Added &amp;quot;listSystemWeb.txt&amp;quot;, identical to &amp;quot;listEcGlobal.txt&amp;quot; which was removed.&lt;br /&gt;
&lt;br /&gt;
== Video Playback ==&lt;br /&gt;
WifiWebAuthApplet does not fully support playing videos. It will [[Error_codes|assert]] with normal videos. The assert triggers before it even starts MP4 parsing?(For example, selecting a video from a video-tag will assert even though it doesn&#039;t send any network request for it) However, in some cases with certain MP4s using vulns it will display an error dialog instead.&lt;br /&gt;
&lt;br /&gt;
With v3.0 WifiWebAuthApplet video-playback was disabled, it now throws the following error when attempting to play a video: &amp;quot;Support Code: 2809-1212&amp;quot; &amp;quot;This feature is not available.&amp;quot; On past system-versions it would just trigger a fatal-error(see above). Video playback still works on the whitelisted applets following v3.0.0, which allows video playback through Facebook and embedded into Google Sites.&lt;br /&gt;
&lt;br /&gt;
== Trusted RootCAs ==&lt;br /&gt;
While the rootCA(s) for Let&#039;s Encrypt isn&#039;t included, Let&#039;s Encrypt is indirectly trusted via &amp;quot;Digital Signature Trust Co.&amp;quot;. This seems to be only(?) the case for WifiWebAuthApplet, hence non-WifiWebAuthApplet seems to have a different set of trusted rootCAs.&lt;br /&gt;
&lt;br /&gt;
== WifiWebAuthApplet ==&lt;br /&gt;
When doing a connection-test in system-settings, it will detect that the captive-portal is required and display an error for it when the response for &amp;quot;http://conntest.nintendowifi.net/&amp;quot; doesn&#039;t include the &amp;quot;X-Organization: Nintendo&amp;quot; HTTP header. The web-applet will not load until something else attempts a conntest, for example when launching eShop and prior to LoginApplet launching. The initial page loaded by this applet is the above conntest URL.&lt;br /&gt;
&lt;br /&gt;
This is only available starting with [[2.0.0]].&lt;br /&gt;
&lt;br /&gt;
Prior to version [[3.0.0]], this applet was launched when attempting a system update from recovery mode if needed. This was changed to display a &amp;quot;This feature is not available.&amp;quot; popup instead.&lt;br /&gt;
&lt;br /&gt;
The conntest URL from [[#WebWifiPageArg]] is used to poll whether the connection is usable, with the SDK [[libcurl]].&lt;br /&gt;
&lt;br /&gt;
In later versions the above domain was replaced with [[Network|ctest.{...}]].&lt;br /&gt;
&lt;br /&gt;
==Whitelisted Applets==&lt;br /&gt;
The v2.1 main-codebin page-aligned .text size is 0x1000-bytes larger than ShopN.&lt;br /&gt;
&lt;br /&gt;
The file at &amp;quot;data:/whitelist/WhitelistLns.txt&amp;quot; for LoginApplet/ShareApplet/LobbyApplet, which doesn&#039;t exist in WifiWebAuthApplet, contains the following:&lt;br /&gt;
&lt;br /&gt;
  &amp;lt;nowiki&amp;gt;^https://([0-9A-Za-z\-]+\.)*nintendo\.net(/|$)&lt;br /&gt;
 ^https?://([0-9A-Za-z\-]+\.)*nintendo\.(co\.jp|com|eu|co\.uk|es|pt|ch|at|de|nl|be|ch|ru|fr|it|co\.za|co\.kr|tw|com\.hk|com\.au|ca|co\.nz)(/|$)&lt;br /&gt;
 ^https?://([0-9A-Za-z\-]+\.)*nintendo-europe\.com(/|$)&lt;br /&gt;
 ^https?://([0-9A-Za-z\-]+\.)*nintendoservicecentre\.co\.uk(/|$)&lt;br /&gt;
 ^https?://([0-9A-Za-z\-]+\.)*google\.(com|ad|ae|com\.af|com\.ag|com\.ai|al|am|co\.ao|com\.ar|as|at|com\.au|az|ba|com\.bd|be|bf|bg|com\.bh|bi|bj|com\.bn|com\.bo|com\.br|bs|bt|co\.bw|by|com\.bz|ca|cd|cf|cg|ch|ci|co\.ck|cl|cm|cn|com\.co|co\.cr|com\.cu|cv|com\.cy|cz|de|dj|dk|dm|com\.do|dz|com\.ec|ee|com\.eg|es|com\.et|fi|com\.fj|fm|fr|ga|ge|gg|com\.gh|com\.gi|gl|gm|gp|gr|com\.gt|gy|com\.hk|hn|hr|ht|hu|co\.id|ie|co\.il|im|co\.in|iq|is|it|je|com\.jm|jo|co\.jp|co\.ke|com\.kh|ki|kg|co\.kr|com\.kw|kz|la|com\.lb|li|lk|co\.ls|lt|lu|lv|com\.ly|co\.ma|md|me|mg|mk|ml|com\.mm|mn|ms|com\.mt|mu|mv|mw|com\.mx|com\.my|co\.mz|com\.na|com\.nf|com\.ng|com\.ni|ne|nl|no|com\.np|nr|nu|co\.nz|com\.om|com\.pa|com\.pe|com\.pg|com\.ph|com\.pk|pl|pn|com\.pr|ps|pt|com\.py|com\.qa|ro|ru|rw|com\.sa|com\.sb|sc|se|com\.sg|sh|si|sk|com\.sl|sn|so|sm|sr|st|com\.sv|td|tg|co\.th|com\.tj|tk|tl|tm|tn|to|com\.tr|tt|com\.tw|co\.tz|com\.ua|co\.ug|co\.uk|com\.uy|co\.uz|com\.vc|co\.ve|vg|co\.vi|com\.vn|vu|ws|rs|co\.za|co\.zm|co\.zw|cat)(/|$)&lt;br /&gt;
 ^https://([0-9A-Za-z\-]+\.)*facebook\.com(/|$)&lt;br /&gt;
 ^https://([0-9A-Za-z\-]+\.)*twitter\.com(/|$)&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[3.0.0+]: The &amp;quot;google\.(com&amp;quot; line now starts with &amp;quot;^https://&amp;quot; instead of &amp;quot;https?://&amp;quot;, hence plain HTTP is no longer allowed. The following line was added right after the original google line: &amp;quot;---- ^https?://([0-9A-Za-z\-]+\.)*google(\.[A-Za-z]+)*/(search|translate)\?&amp;quot;&lt;br /&gt;
&lt;br /&gt;
[4.0.0+]: Lines 2-4 (&amp;quot;...nintendo\.(co...&amp;quot;, &amp;quot;nintendo-europe&amp;quot;, and &amp;quot;nintendoservicecentre&amp;quot;) now starts with &amp;quot;^https://&amp;quot; instead of &amp;quot;https?://&amp;quot;. Hence, plain HTTP for these are no longer allowed.&lt;br /&gt;
&lt;br /&gt;
===ShareApplet===&lt;br /&gt;
The initial page loaded by this applet is controlled by the [[#ShareStartPage]] TLV.&lt;br /&gt;
&lt;br /&gt;
The &amp;quot;web-lp1.share.srv.nintendo.net&amp;quot; site will return a HTTP 302 redirect to &amp;lt;nowiki&amp;gt;&amp;quot;https://nintendo.com/&amp;quot;&amp;lt;/nowiki&amp;gt; when the specified User-Agent isn&#039;t the one for ShareApplet.&lt;br /&gt;
&lt;br /&gt;
===LobbyApplet===&lt;br /&gt;
Support for Lobby was added with [2.0.0+]. This applet is for &amp;quot;Nintendo Switch Online Lounge&amp;quot;&lt;br /&gt;
&lt;br /&gt;
The initial page loaded by this applet is: &amp;lt;nowiki&amp;gt;&amp;quot;https://web-lp1.znc.srv.nintendo.net/lobby/&amp;quot;&amp;lt;/nowiki&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
The content of the above URL refers to &amp;quot;rooms&amp;quot;, &amp;quot;NxView_Img_Google_Play_Icon&amp;quot;, etc.&lt;br /&gt;
&lt;br /&gt;
And also:&lt;br /&gt;
  Your room has been created.&lt;br /&gt;
  &lt;br /&gt;
  You can invite friends to the room via&lt;br /&gt;
  the Nintendo Switch Online Lounge app.&lt;br /&gt;
&lt;br /&gt;
=== NsoApplet ===&lt;br /&gt;
[11.0.0+] This applet handles the new Nintendo Switch Online menu, which is launched from qlaunch.&lt;br /&gt;
&lt;br /&gt;
The initial page loaded by this applet is: &amp;lt;nowiki&amp;gt;&amp;quot;https://%.nso.nintendo.net/&amp;lt;/nowiki&amp;gt;{string from [[#TLVs|TLV]] 0x2}&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== ShopN ==&lt;br /&gt;
The initial page loaded by ShopN is: &amp;lt;nowiki&amp;gt;&amp;quot;https://bugyo.hac.lp1.eshop.nintendo.net/ashigaru/&amp;quot;&amp;lt;/nowiki&amp;gt;.&lt;br /&gt;
This can be accessed via computer possesed the certificate ShopN.&lt;br /&gt;
&lt;br /&gt;
The file at &amp;quot;data:/whitelist/WhitelistEc.txt&amp;quot;, which doesn&#039;t exist in WifiWebAuthApplet, contains the following:&lt;br /&gt;
&lt;br /&gt;
  &amp;lt;nowiki&amp;gt;^https://([0-9A-Za-z\-]+\.)*eshop\.nintendo\.net($|/)&lt;br /&gt;
 ^https?://([0-9A-Za-z\-]+\.)*nintendo\.(co\.jp|com|de)($|/)&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== WebApplet ==&lt;br /&gt;
===010000000000100A===&lt;br /&gt;
The initial page loaded by this applet is specified by the title which launched this applet. Plain HTTP is allowed.&lt;br /&gt;
&lt;br /&gt;
The files under &amp;quot;data:/&amp;quot; are identical to WifiWebAuthApplet except that the content of each file differs.&lt;br /&gt;
&lt;br /&gt;
This applet uses a whitelist, but it doesn&#039;t come from &amp;quot;data:/&amp;quot; like whitelisted-applet.&lt;br /&gt;
&lt;br /&gt;
==== WebApplet launch with Tetris ====&lt;br /&gt;
See [[Switch_System_Flaws#Whitelist|here]].&lt;br /&gt;
&lt;br /&gt;
=== Offline Applet ===&lt;br /&gt;
Minus TIDs, the [[NPDM]] is the same as 010000000000100A except 010000000000100A has access to more/other services.&lt;br /&gt;
&lt;br /&gt;
== [[NPDM]] ==&lt;br /&gt;
All web-applets have access to the following services: acc:u1, appletAE, audin:u, audout:u, audren:u, [7.0.0+] banana, bsd:u, bsdcfg, [12.1.0+] csrng, erpt:c, fatal:u, fsp-srv, hid, hid:sys, htc, htc:tenv, htcs, hwopus, irs, ldn:m, ldr:ro, lm, [9.1.0+] lp2p:m, mm:u, nifm:s, [3.0.0+] ns:vm, ns:am, nsd:u, nvdrv:a, pl:u, prepo:s, set, set:sys, sfdnsres, ssl, time:u, [1.0.0] tspm, vi:s&lt;br /&gt;
&lt;br /&gt;
[3.0.0+] ns:am was replaced with ns:web.&lt;br /&gt;
&lt;br /&gt;
[17.0.0+] htcs:sys access was added. [18.1.0+] htcs access was removed.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] bsd:u was replaced with bsd:a.&lt;br /&gt;
&lt;br /&gt;
WebApplet also has access to ntc. [3.0.0+] Added ntc access for Shop and LibAppletLns.&lt;br /&gt;
&lt;br /&gt;
LibAppletLns has access to the above + caps:a. Also [13.1.0+] caps:ss, [13.1.0+] mnpp:web, [3.0.0+] pctl. [20.0.0+] ns:sweb is accessible instead of ns:web.&lt;br /&gt;
&lt;br /&gt;
Shop also has access to [2.0.0+] nim:shp, [?+] &amp;lt;nowiki&amp;gt;news:c&amp;lt;/nowiki&amp;gt;. Shop has access to ns:ec instead of ns:web.&lt;br /&gt;
&lt;br /&gt;
Offline has access to nifm:u instead of nifm:s. Unlike the other applets, Offline doesn&#039;t have access to the following: ldn:m, lp2p:m, ssl.&lt;br /&gt;
&lt;br /&gt;
Unlike the other applets, LibAppletAuth doesn&#039;t have access to following: [3.0.0+] mm:u, [3.0.0+] ns:web.&lt;br /&gt;
&lt;br /&gt;
All web-applets have fs-permission [[NPDM|SystemSaveData]].&lt;br /&gt;
&lt;br /&gt;
Unlike the applets listed above, WebApplet/Offline also have access to fs-permission [[NPDM|ApplicationInfo]]. This is so it can open the specified Manual content. With WebApplet this is used for loading the whitelist from &amp;quot;/accessible-urls/accessible-urls.txt&amp;quot; in the mounted content.&lt;br /&gt;
&lt;br /&gt;
[S2] OpenWeb has access to the following services: acc:u1, adraw:a, appletAE, aud:u, auddmg:u, audsmx:u, banana, bsd:a, csrng, erpt:c, fatal:u, fsp-srv, hid, hid:sys, htc, htc:tenv, htcs:sys, imf, ldn:m, ldr:ro, lm, lp2p:m, nifm:s, ns:vm, ns:web, nsd:u, ntc, pl:u, prepo:s, set, set:sys, sfdnsres, ssl, time:u&lt;br /&gt;
* [S2] OpenWeb: [20.1.0+] pctl access was added.&lt;br /&gt;
&lt;br /&gt;
== Heap ==&lt;br /&gt;
The size used for [[SVC|svcSetHeapSize]] by the web-applets is 0x15600000. Under ShopN, the largest size that can be passed to this without an error being returned, is 0x1B400000.&lt;br /&gt;
&lt;br /&gt;
The size used by title 010000000000100A (on 10.0.0 at least) is 0x14200000.&lt;br /&gt;
&lt;br /&gt;
The heap for the main-codebin (&amp;lt;code&amp;gt;malloc&amp;lt;/code&amp;gt;/&amp;lt;code&amp;gt;operator new&amp;lt;/code&amp;gt;) uses nn::lmem::*ExpHeap. [8.0.0+] &amp;lt;code&amp;gt;malloc&amp;lt;/code&amp;gt;/&amp;lt;code&amp;gt;operator new&amp;lt;/code&amp;gt; now checks the return-addr (addr located in a relevant NRO), with wkc_malloc_crashonfailure being called for the allocation if the check passes, otherwise a normal allocation is done (the code which runs for this will Abort if allocation fails).&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;malloc&amp;lt;/code&amp;gt; passes the input size directly to the called func. &amp;lt;code&amp;gt;operator new&amp;lt;/code&amp;gt; when handling normal non-wkc allocations passes the following to the called func: &amp;lt;code&amp;gt;sxtw x1, {inw0}&amp;lt;/code&amp;gt; (for wkc allocations the size is passed directly). [12.1.0+] The size is now passed directly (64bit) without using sxtw.&lt;br /&gt;
&lt;br /&gt;
[11.0.0+] There&#039;s now optional code for using [[SVC|svcMapPhysicalMemoryUnsafe]] etc, however it&#039;s unknown what sets the flag for this. An Abort string used this is: &amp;quot;{path}/TransferredMemoryManager.cpp&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Applet Launching ==&lt;br /&gt;
The web-applets are launched using a storage containing the input arg data, on exit the output storage contains the &amp;quot;*ReturnValue&amp;quot; reply data.&lt;br /&gt;
&lt;br /&gt;
Input/output storage size for TLV data is 0x2000-bytes.&lt;br /&gt;
&lt;br /&gt;
=== Library Applet Versions ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! System Version || Value&lt;br /&gt;
|-&lt;br /&gt;
| [1.0.0+] || 0x20000&lt;br /&gt;
|-&lt;br /&gt;
| [3.0.0+] || 0x30000&lt;br /&gt;
|-&lt;br /&gt;
| [5.0.0+] || 0x50000&lt;br /&gt;
|-&lt;br /&gt;
| [6.0.0+] || 0x60000&lt;br /&gt;
|-&lt;br /&gt;
| [8.0.0+] || 0x80000&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
The above only (?) applies to non-WebWifi. WebWifi uses version 0x0.&lt;br /&gt;
&lt;br /&gt;
=== ShimKind ===&lt;br /&gt;
This enum is &amp;quot;nn::web::common::ShimKind&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This indicates the type of web-applet.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Value&lt;br /&gt;
!  Name&lt;br /&gt;
|-&lt;br /&gt;
| 1&lt;br /&gt;
| Shop&lt;br /&gt;
|-&lt;br /&gt;
| 2&lt;br /&gt;
| Login&lt;br /&gt;
|-&lt;br /&gt;
| 3&lt;br /&gt;
| Offline&lt;br /&gt;
|-&lt;br /&gt;
| 4&lt;br /&gt;
| Share&lt;br /&gt;
|-&lt;br /&gt;
| 5&lt;br /&gt;
| Web&lt;br /&gt;
|-&lt;br /&gt;
| 6&lt;br /&gt;
| Wifi&lt;br /&gt;
|-&lt;br /&gt;
| 7&lt;br /&gt;
| Lobby&lt;br /&gt;
|-&lt;br /&gt;
| 8&lt;br /&gt;
| [[#NsoApplet|Lhub]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== WebSession ===&lt;br /&gt;
With [5.0.0+] sdk-nso added &amp;lt;code&amp;gt;nn::web::Session::&amp;lt;/code&amp;gt;. With [6.0.0+] this was removed, however it was reintroduced with [7.0.0+] as &amp;lt;code&amp;gt;nn::web::*WebSession&amp;lt;/code&amp;gt; (for ShimKind Offline and Web).&lt;br /&gt;
&lt;br /&gt;
This is for sending/receiving [[#SessionMessage]]s via applet Interactive storage.&lt;br /&gt;
&lt;br /&gt;
During state init, max_messages is set to 0xA ([7.0.0+] 0x10), with message_count=0 and cur_size=0. [5.0.0-5.1.0] max_size is set to 0x5000. [7.0.0+] Two queues are used for message_count/cur_size: first one is for BrowserEngineContent (max_size 0x8000 is used), the second one is for non-BrowserEngineContent (max_size 0x1000 is used).&lt;br /&gt;
&lt;br /&gt;
When sending messages, there has to be an available message slot available (&amp;lt;code&amp;gt;max_messages!=message_count&amp;lt;/code&amp;gt;), and there has to be enough space available (&amp;lt;code&amp;gt;msghdr_contentsize+0x10 + cur_size &amp;lt;= max_size&amp;lt;/code&amp;gt;). After pushing the storage, message_count is incremented and cur_size is increased by &amp;lt;code&amp;gt;msghdr_contentsize+0x10&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
When receiving messages, it will repeatedly pop Interactive output storage until no more are available. Non-Ack messages are Acked.&lt;br /&gt;
* Ack: Verifies that message_count is not already 0, then decrements it. Then cur_size is decreased by the u32 loaded from msgcontent+0.&lt;br /&gt;
* 0x0: Does some validation. Reads the message content into the user buffer, when contentsize is non-zero. The original contentsize is written to an user output param. The last byte in the user buffer (contentsize clamped to the user max-buf-size, -1) is set to 0 for NUL-termination.&lt;br /&gt;
&lt;br /&gt;
Next info was tested in 9.0.0&lt;br /&gt;
&lt;br /&gt;
In the js side (which is only available when enabled via the JsExtensionEnabled TLV), there is a method called &amp;lt;code&amp;gt;window.nx.sendMessage(arg)&amp;lt;/code&amp;gt; that sends data to the native side, this method returns a boolean indicating if sending was successful and accepts a string as an argument. The string is encoded like a C null terminated string in the message content. For receive messages from native part, there is a dom event called &amp;lt;code&amp;gt;message&amp;lt;/code&amp;gt; which is dispatched when a message arrives. The event can be listened using &amp;lt;code&amp;gt;window.nx.addEventListener(&amp;quot;message&amp;quot;, callback)&amp;lt;/code&amp;gt; being callback a function which first parameter is like a dom event arg and contains a member called &amp;lt;code&amp;gt;data&amp;lt;/code&amp;gt; which contains the string decoded from the arrived message.&lt;br /&gt;
&lt;br /&gt;
If messages aren&#039;t acked by the native part, js side will not longer receive messages. Ack to web applet &#039;&#039;&#039;must&#039;&#039;&#039; have 4 bytes after the message content or the applet will Abort.&lt;br /&gt;
&lt;br /&gt;
==== SessionMessage ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Offset&lt;br /&gt;
!  Size&lt;br /&gt;
!  Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0&lt;br /&gt;
| 0x10&lt;br /&gt;
| [[#SessionMessageHeader]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x10&lt;br /&gt;
| Size from header&lt;br /&gt;
| Message content&lt;br /&gt;
|-&lt;br /&gt;
| After message content&lt;br /&gt;
| 0x4 if message is ack, 0x0 otherwise&lt;br /&gt;
| Padding&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== SessionMessageHeader ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Offset&lt;br /&gt;
!  Size&lt;br /&gt;
!  Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0&lt;br /&gt;
| 0x4&lt;br /&gt;
| Message Kind ([[#WebSessionSendMessageKind]] / [[#WebSessionReceiveMessageKind]])&lt;br /&gt;
|-&lt;br /&gt;
| 0x4&lt;br /&gt;
| 0x4&lt;br /&gt;
| Data size following the header.&lt;br /&gt;
|-&lt;br /&gt;
| 0x8&lt;br /&gt;
| 0x8&lt;br /&gt;
| Unused&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== WebSessionSendMessageKind ====&lt;br /&gt;
This is &amp;quot;nn::web::detail::WebSessionSendMessageKind&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  ID&lt;br /&gt;
!  Content size&lt;br /&gt;
!  Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0&lt;br /&gt;
| Arbitrary&lt;br /&gt;
| BrowserEngine Content, NUL-terminated string. Used to communicate with the applet via JsExtensions used by the Js being run by the applet on the current page.&lt;br /&gt;
|-&lt;br /&gt;
| 0x100&lt;br /&gt;
| 0x0&lt;br /&gt;
| SystemMessage Appear. Requests the applet to Appear, this is only needed with [[#WebSessionBootMode]] AllForegroundInitiallyHidden.&lt;br /&gt;
|-&lt;br /&gt;
| 0x1000&lt;br /&gt;
| 0xC&lt;br /&gt;
| Ack. Content: first u32 is the entire storage size of the message being acked, the rest is not used.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== WebSessionReceiveMessageKind ====&lt;br /&gt;
This is &amp;quot;nn::web::detail::WebSessionReceiveMessageKind&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  ID&lt;br /&gt;
!  Content size&lt;br /&gt;
!  Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0&lt;br /&gt;
| Arbitrary&lt;br /&gt;
| BrowserEngine Content, see [[#WebSessionSendMessageKind]].&lt;br /&gt;
|-&lt;br /&gt;
| 0x1000&lt;br /&gt;
| 0xC&lt;br /&gt;
| Ack BrowserEngine&lt;br /&gt;
|-&lt;br /&gt;
| 0x1001&lt;br /&gt;
| 0xC&lt;br /&gt;
| Ack SystemMessage&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== WebWifiPageArg ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Offset&lt;br /&gt;
!  Size&lt;br /&gt;
!  Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x4 || Official sw sets this to 0 with appletStorageWrite, separately from the rest of the config struct.&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || 0x100 || URL used for the connection-test requests.&lt;br /&gt;
|-&lt;br /&gt;
| 0x104 || 0x400 || Initial URL navigated to by the applet.&lt;br /&gt;
|-&lt;br /&gt;
| 0x504 || 0x10 || NIFM Network UUID. Can be value zero. Only used by the applet when conntest_url is set.&lt;br /&gt;
|-&lt;br /&gt;
| 0x514 || 0x4 || Input value for nifm cmd SetRequirementByRevision. Can be value zero. Only used by the applet when conntest_url is set.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
This is the input struct for WifiWebAuthApplet. This is a total of 0x518-bytes.&lt;br /&gt;
&lt;br /&gt;
When the conntest_url is empty, the applet will test the connection with nifm and throw an error on failure.&lt;br /&gt;
&lt;br /&gt;
=== WebWifiReturnValue ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Offset&lt;br /&gt;
!  Size&lt;br /&gt;
!  Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x4 || ?&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || 0x8 || Result&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
This is the output struct for WifiWebAuthApplet. This is a total of 0x8-bytes.&lt;br /&gt;
&lt;br /&gt;
=== WebCommonReturnValue ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Offset&lt;br /&gt;
!  Size&lt;br /&gt;
!  Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x4 || u32 exitReason&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || 0x4 || Padding&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x1000 || lastUrl string&lt;br /&gt;
|-&lt;br /&gt;
| 0x1008 || 0x8 || lastUrlSize&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
This is the 0x1010-byte output storage used by all non-WebWifi applets - except for Share which returns a TLV storage on [3.0.0+], and Web on [8.0.0+].&lt;br /&gt;
&lt;br /&gt;
=== WebArgHeader ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Offset&lt;br /&gt;
!  Size&lt;br /&gt;
!  Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x2 || Total [[#WebArgTLV]] entries following this struct.&lt;br /&gt;
|-&lt;br /&gt;
| 0x2 || 0x2 || Padding&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || 0x4 || [[#ShimKind]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
This is the header struct at offset 0 in the input web Arg storage for non-WebWifi. This is a total of 0x8-bytes. The total storage size used for input/output TLVs is 0x2000.&lt;br /&gt;
&lt;br /&gt;
=== WebArgTLV ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Offset&lt;br /&gt;
!  Size&lt;br /&gt;
!  Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x2 || Type of this arg.&lt;br /&gt;
|-&lt;br /&gt;
| 0x2 || 0x2 || Size of the arg data following this struct.&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || 0x4 || Padding&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Web TLV used in the input web Arg storage, after [[#WebArgHeader]]. This is a total of 0x8-bytes.&lt;br /&gt;
&lt;br /&gt;
=== WebBootFooterButtonEntry ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Offset&lt;br /&gt;
!  Size&lt;br /&gt;
!  Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x4 || [[#FooterButtonId]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || 0x1 || u8 bool visible flag&lt;br /&gt;
|-&lt;br /&gt;
| 0x5 || 0x2 || ?&lt;br /&gt;
|-&lt;br /&gt;
| 0x7 || 0x1 || ?&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== TLVs ===&lt;br /&gt;
All strings are NUL-terminated.&lt;br /&gt;
&lt;br /&gt;
==== Input TLVs ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  System Version&lt;br /&gt;
!  Applets&lt;br /&gt;
!  Type&lt;br /&gt;
!  Size&lt;br /&gt;
!  Value&lt;br /&gt;
!  Description&lt;br /&gt;
|-&lt;br /&gt;
| [1.0.0+]&lt;br /&gt;
| &lt;br /&gt;
| 0x1&lt;br /&gt;
| 0xC00&lt;br /&gt;
| string&lt;br /&gt;
| Initial URL&lt;br /&gt;
|-&lt;br /&gt;
| [1.0.0+]&lt;br /&gt;
| &lt;br /&gt;
| 0x3&lt;br /&gt;
| 0x400&lt;br /&gt;
| string&lt;br /&gt;
| CallbackUrl&lt;br /&gt;
|-&lt;br /&gt;
| [1.0.0+]&lt;br /&gt;
| &lt;br /&gt;
| 0x4&lt;br /&gt;
| 0x400&lt;br /&gt;
| string&lt;br /&gt;
| CallbackableUrl&lt;br /&gt;
|-&lt;br /&gt;
| [1.0.0+]&lt;br /&gt;
| Offline&lt;br /&gt;
| 0x5&lt;br /&gt;
| 0x8&lt;br /&gt;
| u64 titleID&lt;br /&gt;
| ApplicationId, for DocumentKind_OfflineHtmlPage/DocumentKind_ApplicationLegalInformation. Should be zero for DocumentKind_OfflineHtmlPage since it&#039;s ignored.&lt;br /&gt;
|-&lt;br /&gt;
| [1.0.0+]&lt;br /&gt;
| Offline&lt;br /&gt;
| 0x6&lt;br /&gt;
| 0xC00&lt;br /&gt;
| string&lt;br /&gt;
| DocumentPath&lt;br /&gt;
|-&lt;br /&gt;
| [1.0.0+]&lt;br /&gt;
| Offline&lt;br /&gt;
| 0x7&lt;br /&gt;
| 0x4&lt;br /&gt;
| u32 enum OfflineDocumentKind&lt;br /&gt;
| [[#DocumentKind]]&lt;br /&gt;
|-&lt;br /&gt;
| [1.0.0+]&lt;br /&gt;
| Offline&lt;br /&gt;
| 0x8&lt;br /&gt;
| 0x8&lt;br /&gt;
| u64 titleID&lt;br /&gt;
| SystemDataId, for DocumentKind_SystemDataPage.&lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
| Share&lt;br /&gt;
| 0x9&lt;br /&gt;
| 0x4&lt;br /&gt;
| u32 enum [[#ShareStartPage]]&lt;br /&gt;
| ShareStartPage&lt;br /&gt;
|-&lt;br /&gt;
| [1.0.0+]&lt;br /&gt;
| &lt;br /&gt;
| 0xA&lt;br /&gt;
| 0x1000&lt;br /&gt;
| string&lt;br /&gt;
| Whitelist. If not formatted properly, the applet will exit briefly after the applet is launched. Each line is a regex for each whitelisted URL.&lt;br /&gt;
|-&lt;br /&gt;
| [1.0.0+]&lt;br /&gt;
| &lt;br /&gt;
| 0xB&lt;br /&gt;
| 0x1&lt;br /&gt;
| u8 bool&lt;br /&gt;
| News flag. When set the domain from the input URL is automatically whitelisted, in addition to any already loaded whitelist.&lt;br /&gt;
|-&lt;br /&gt;
| [1.0.0+]&lt;br /&gt;
| &lt;br /&gt;
| 0xE&lt;br /&gt;
| 0x10&lt;br /&gt;
| userID&lt;br /&gt;
| userID, controls which user-specific savedata to mount.&lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
| Share&lt;br /&gt;
| 0xF&lt;br /&gt;
| 0x20&lt;br /&gt;
| [[Capture_services|AlbumEntry]]&lt;br /&gt;
| AlbumEntry0&lt;br /&gt;
|-&lt;br /&gt;
| [1.0.0+]&lt;br /&gt;
| &lt;br /&gt;
| 0x10&lt;br /&gt;
| 0x1&lt;br /&gt;
| u8 bool&lt;br /&gt;
| ScreenShotEnabled. Controls whether screen-shot capture is allowed.&lt;br /&gt;
|-&lt;br /&gt;
| [1.0.0+]&lt;br /&gt;
| &lt;br /&gt;
| 0x11&lt;br /&gt;
| 0x1&lt;br /&gt;
| u8 bool&lt;br /&gt;
| EcClientCertEnabled&lt;br /&gt;
|-&lt;br /&gt;
| [1.0.0+]&lt;br /&gt;
| &lt;br /&gt;
| 0x12&lt;br /&gt;
| 0x1&lt;br /&gt;
| u8&lt;br /&gt;
| ?&lt;br /&gt;
|-&lt;br /&gt;
| [1.0.0+]&lt;br /&gt;
| Offline&lt;br /&gt;
| 0x13&lt;br /&gt;
| 0x1&lt;br /&gt;
| u8 bool&lt;br /&gt;
| PlayReportEnabled&lt;br /&gt;
|-&lt;br /&gt;
| [1.0.0+]&lt;br /&gt;
| &lt;br /&gt;
| 0x14&lt;br /&gt;
| 0x1&lt;br /&gt;
| u8&lt;br /&gt;
| ?&lt;br /&gt;
|-&lt;br /&gt;
| [1.0.0+]&lt;br /&gt;
| &lt;br /&gt;
| 0x15&lt;br /&gt;
| 0x1&lt;br /&gt;
| u8&lt;br /&gt;
| ?&lt;br /&gt;
|-&lt;br /&gt;
| [1.0.0+]&lt;br /&gt;
| &lt;br /&gt;
| 0x17&lt;br /&gt;
| 0x4&lt;br /&gt;
| u32 enum [[#BootDisplayKind]]&lt;br /&gt;
| BootDisplayKind&lt;br /&gt;
|-&lt;br /&gt;
| [1.0.0+]&lt;br /&gt;
| &lt;br /&gt;
| 0x18&lt;br /&gt;
| 0x4&lt;br /&gt;
| u32 enum [[#BackgroundKind]]&lt;br /&gt;
| BackgroundKind&lt;br /&gt;
|-&lt;br /&gt;
| [1.0.0+]&lt;br /&gt;
| &lt;br /&gt;
| 0x19&lt;br /&gt;
| 0x1&lt;br /&gt;
| u8 bool&lt;br /&gt;
| FooterEnabled. Controls whether the UI footer is enabled.&lt;br /&gt;
|-&lt;br /&gt;
| [1.0.0+]&lt;br /&gt;
| &lt;br /&gt;
| 0x1A&lt;br /&gt;
| 0x1&lt;br /&gt;
| u8 bool&lt;br /&gt;
| PointerEnabled&lt;br /&gt;
|-&lt;br /&gt;
| [1.0.0+]&lt;br /&gt;
| &lt;br /&gt;
| 0x1B&lt;br /&gt;
| 0x4&lt;br /&gt;
| u32 enum [[#LeftStickMode]]&lt;br /&gt;
| LeftStickMode&lt;br /&gt;
|-&lt;br /&gt;
| [1.0.0+]&lt;br /&gt;
| &lt;br /&gt;
| 0x1C&lt;br /&gt;
| 0x4&lt;br /&gt;
| s32&lt;br /&gt;
| KeyRepeatFrame, first param&lt;br /&gt;
|-&lt;br /&gt;
| [1.0.0+]&lt;br /&gt;
| &lt;br /&gt;
| 0x1D&lt;br /&gt;
| 0x4&lt;br /&gt;
| s32&lt;br /&gt;
| KeyRepeatFrame, second param&lt;br /&gt;
|-&lt;br /&gt;
| [1.0.0+]&lt;br /&gt;
| &lt;br /&gt;
| 0x1E&lt;br /&gt;
| 0x1&lt;br /&gt;
| u8 bool&lt;br /&gt;
| Set after BootAsMediaPlayer with the value inverted.&lt;br /&gt;
|-&lt;br /&gt;
| [1.0.0+]&lt;br /&gt;
| &lt;br /&gt;
| 0x1F&lt;br /&gt;
| 0x1&lt;br /&gt;
| u8 bool&lt;br /&gt;
| DisplayUrlKind (&amp;lt;code&amp;gt;value = (input_enumval==0x1)&amp;lt;/code&amp;gt;)&lt;br /&gt;
|-&lt;br /&gt;
| [2.0.0+]&lt;br /&gt;
| &lt;br /&gt;
| 0x21&lt;br /&gt;
| 0x1&lt;br /&gt;
| u8 bool&lt;br /&gt;
| BootAsMediaPlayer&lt;br /&gt;
|-&lt;br /&gt;
| [2.0.0+]&lt;br /&gt;
| &lt;br /&gt;
| 0x22&lt;br /&gt;
| 0x1&lt;br /&gt;
| u8 bool&lt;br /&gt;
| ShopJumpEnabled&lt;br /&gt;
|-&lt;br /&gt;
| [2.0.0+]&lt;br /&gt;
| &lt;br /&gt;
| 0x23&lt;br /&gt;
| 0x1&lt;br /&gt;
| u8 bool&lt;br /&gt;
| [6.0.0+] MediaAutoPlayEnabled ([2.0.0-5.1.0] MediaPlayerUserGestureRestrictionEnabled)&lt;br /&gt;
|-&lt;br /&gt;
| [2.0.0+]&lt;br /&gt;
| &lt;br /&gt;
| 0x24&lt;br /&gt;
| 0x100&lt;br /&gt;
| string&lt;br /&gt;
| LobbyParameter&lt;br /&gt;
|-&lt;br /&gt;
| [3.0.0+]&lt;br /&gt;
| Share&lt;br /&gt;
| 0x26&lt;br /&gt;
| 0x20&lt;br /&gt;
| [[Capture_services|ApplicationAlbumEntry]]&lt;br /&gt;
| ApplicationAlbumEntry&lt;br /&gt;
|-&lt;br /&gt;
| [3.0.0+]&lt;br /&gt;
| &lt;br /&gt;
| 0x27&lt;br /&gt;
| 0x1&lt;br /&gt;
| u8 bool&lt;br /&gt;
| JsExtensionEnabled&lt;br /&gt;
|-&lt;br /&gt;
| [4.0.0+]&lt;br /&gt;
| Share&lt;br /&gt;
| 0x28&lt;br /&gt;
| 0x100&lt;br /&gt;
| string&lt;br /&gt;
| AdditionalCommentText&lt;br /&gt;
|-&lt;br /&gt;
| [4.0.0+]&lt;br /&gt;
| &lt;br /&gt;
| 0x29&lt;br /&gt;
| 0x1&lt;br /&gt;
| u8 bool&lt;br /&gt;
| TouchEnabledOnContents&lt;br /&gt;
|-&lt;br /&gt;
| [4.0.0+]&lt;br /&gt;
| &lt;br /&gt;
| 0x2A&lt;br /&gt;
| 0x80&lt;br /&gt;
| string&lt;br /&gt;
| UserAgentAdditionalString. &amp;quot; &amp;quot; followed by this string are appended to the normal User-Agent string.&lt;br /&gt;
|-&lt;br /&gt;
| [4.0.0+]&lt;br /&gt;
| Share&lt;br /&gt;
| 0x2B&lt;br /&gt;
| 0x10&lt;br /&gt;
| u8 array&lt;br /&gt;
| AdditionalMediaData0 (If the user-input size is less than 0x10, the remaining tmp data used for the TLV is cleared)&lt;br /&gt;
|-&lt;br /&gt;
| [4.0.0+]&lt;br /&gt;
| &lt;br /&gt;
| 0x2C&lt;br /&gt;
| 0x1&lt;br /&gt;
| u8 bool&lt;br /&gt;
| MediaPlayerAutoCloseEnabled&lt;br /&gt;
|-&lt;br /&gt;
| [4.0.0+]&lt;br /&gt;
| &lt;br /&gt;
| 0x2D&lt;br /&gt;
| 0x1&lt;br /&gt;
| u8 bool&lt;br /&gt;
| PageCacheEnabled&lt;br /&gt;
|-&lt;br /&gt;
| [4.0.0+]&lt;br /&gt;
| &lt;br /&gt;
| 0x2E&lt;br /&gt;
| 0x1&lt;br /&gt;
| u8 bool&lt;br /&gt;
| WebAudioEnabled&lt;br /&gt;
|-&lt;br /&gt;
| [5.0.0+]&lt;br /&gt;
| &lt;br /&gt;
| 0x2F&lt;br /&gt;
| 0x1&lt;br /&gt;
| u8&lt;br /&gt;
| ?&lt;br /&gt;
|-&lt;br /&gt;
| [5.0.0+]&lt;br /&gt;
| &lt;br /&gt;
| 0x31&lt;br /&gt;
| 0x1&lt;br /&gt;
| u8 bool&lt;br /&gt;
| When set, indicates the whitelist for YouTubeVideo should be used (loaded from web-applet RomFS).&lt;br /&gt;
|-&lt;br /&gt;
| [5.0.0+]&lt;br /&gt;
| &lt;br /&gt;
| 0x32&lt;br /&gt;
| 0x4&lt;br /&gt;
| u32 enum *WebFooterFixedKind&lt;br /&gt;
| FooterFixedKind&lt;br /&gt;
|-&lt;br /&gt;
| [5.0.0+]&lt;br /&gt;
| &lt;br /&gt;
| 0x33&lt;br /&gt;
| 0x1&lt;br /&gt;
| u8 bool&lt;br /&gt;
| PageFadeEnabled&lt;br /&gt;
|-&lt;br /&gt;
| [5.0.0+]&lt;br /&gt;
| Share&lt;br /&gt;
| 0x34&lt;br /&gt;
| 0x20&lt;br /&gt;
| s8 data[32]&lt;br /&gt;
| MediaCreatorApplicationRatingAge&lt;br /&gt;
|-&lt;br /&gt;
| [5.0.0+]&lt;br /&gt;
| &lt;br /&gt;
| 0x35&lt;br /&gt;
| 0x1&lt;br /&gt;
| u8 bool&lt;br /&gt;
| BootLoadingIconEnabled&lt;br /&gt;
|-&lt;br /&gt;
| [5.0.0+]&lt;br /&gt;
| &lt;br /&gt;
| 0x36&lt;br /&gt;
| 0x1&lt;br /&gt;
| u8 bool&lt;br /&gt;
| PageScrollIndicatorEnabled&lt;br /&gt;
|-&lt;br /&gt;
| [6.0.0+]&lt;br /&gt;
| &lt;br /&gt;
| 0x37&lt;br /&gt;
| 0x1&lt;br /&gt;
| u8 bool&lt;br /&gt;
| MediaPlayerSpeedControlEnabled&lt;br /&gt;
|-&lt;br /&gt;
| [6.0.0+]&lt;br /&gt;
| Share&lt;br /&gt;
| 0x38&lt;br /&gt;
| 0x20&lt;br /&gt;
| [[Capture_services|AlbumEntry]]&lt;br /&gt;
| AlbumEntry1&lt;br /&gt;
|-&lt;br /&gt;
| [6.0.0+]&lt;br /&gt;
| Share&lt;br /&gt;
| 0x39&lt;br /&gt;
| 0x20&lt;br /&gt;
| [[Capture_services|AlbumEntry]]&lt;br /&gt;
| AlbumEntry2&lt;br /&gt;
|-&lt;br /&gt;
| [6.0.0+]&lt;br /&gt;
| Share&lt;br /&gt;
| 0x3A&lt;br /&gt;
| 0x20&lt;br /&gt;
| [[Capture_services|AlbumEntry]]&lt;br /&gt;
| AlbumEntry3&lt;br /&gt;
|-&lt;br /&gt;
| [6.0.0+]&lt;br /&gt;
| Share&lt;br /&gt;
| 0x3B&lt;br /&gt;
| 0x10&lt;br /&gt;
| u8 array&lt;br /&gt;
| AdditionalMediaData1&lt;br /&gt;
|-&lt;br /&gt;
| [6.0.0+]&lt;br /&gt;
| Share&lt;br /&gt;
| 0x3C&lt;br /&gt;
| 0x10&lt;br /&gt;
| u8 array&lt;br /&gt;
| AdditionalMediaData2&lt;br /&gt;
|-&lt;br /&gt;
| [6.0.0+]&lt;br /&gt;
| Share&lt;br /&gt;
| 0x3D&lt;br /&gt;
| 0x10&lt;br /&gt;
| u8 array&lt;br /&gt;
| AdditionalMediaData3&lt;br /&gt;
|-&lt;br /&gt;
| [6.0.0+]&lt;br /&gt;
| BootFooterButton&lt;br /&gt;
| 0x3E&lt;br /&gt;
| 0x80&lt;br /&gt;
| Array of [[#WebBootFooterButtonEntry]] with 0x10 entries.&lt;br /&gt;
| BootFooterButton&lt;br /&gt;
|-&lt;br /&gt;
| [6.0.0+]&lt;br /&gt;
| &lt;br /&gt;
| 0x3F&lt;br /&gt;
| 0x4&lt;br /&gt;
| float&lt;br /&gt;
| OverrideWebAudioVolume&lt;br /&gt;
|-&lt;br /&gt;
| [6.0.0+]&lt;br /&gt;
| &lt;br /&gt;
| 0x40&lt;br /&gt;
| 0x4&lt;br /&gt;
| float&lt;br /&gt;
| OverrideMediaAudioVolume&lt;br /&gt;
|-&lt;br /&gt;
| [7.0.0+]&lt;br /&gt;
| &lt;br /&gt;
| 0x41&lt;br /&gt;
| 0x4&lt;br /&gt;
| u32 enum [[#WebSessionBootMode]]&lt;br /&gt;
| BootMode&lt;br /&gt;
|-&lt;br /&gt;
| [7.0.0+]&lt;br /&gt;
| &lt;br /&gt;
| 0x42&lt;br /&gt;
| 0x1&lt;br /&gt;
| u8 bool&lt;br /&gt;
| Enables using [[#WebSession]] when set.&lt;br /&gt;
|-&lt;br /&gt;
| [8.0.0+]&lt;br /&gt;
| Offline&lt;br /&gt;
| 0x43&lt;br /&gt;
| 0x1&lt;br /&gt;
| u8 bool&lt;br /&gt;
| MediaPlayerUiEnabled&lt;br /&gt;
|-&lt;br /&gt;
| [11.0.0+]&lt;br /&gt;
| &lt;br /&gt;
| 0x44&lt;br /&gt;
| 0x1&lt;br /&gt;
| bool&lt;br /&gt;
| TransferMemoryEnabled&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Offline: title to load the content from is controlled by ApplicationId/SystemDataId. With DocumentKind_OfflineHtmlPage, it will ignore this and only load from the user-process title.&lt;br /&gt;
&lt;br /&gt;
Offline DocumentPath: Initial document path in RomFS, without the leading &#039;/&#039;. For DocumentKind_OfflineHtmlPage, this is relative to &amp;quot;html-document/&amp;quot; in RomFS. For the other DocumentKind values, this is relative to &amp;quot;/&amp;quot; in RomFS. This path must contain &amp;quot;.htdocs/&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
Share/Lobby: if a non-zero userID isn&#039;t set, the applet will launch the profile-selector applet to select an account.&lt;br /&gt;
&lt;br /&gt;
Share: An error will be displayed if neither AlbumEntry or ApplicationAlbumEntry are set, with [[#ShareStartPage|ShareStartPage_Default]].&lt;br /&gt;
&lt;br /&gt;
[6.0.0+] &amp;lt;code&amp;gt;AddAlbumEntryAndMediaData&amp;lt;/code&amp;gt; was added:&lt;br /&gt;
* Looks for AlbumEntry{N} TLVs, when a TLV is not found it is written, then the associated AdditionalMediaData{N} TLV is written the same way as AdditionalMediaData0. If all AlbumEntry{N} TLVs already exist, this returns without writing anything.&lt;br /&gt;
&lt;br /&gt;
TransferMemoryEnabled: sdknso only exposes this for the Web applet. The sdknso func uses &amp;lt;code&amp;gt;nn::os::QueryMemoryInfo&amp;lt;/code&amp;gt; at the start of the func, however the output is unused. The applet doesn&#039;t seem to parse this TLV.&lt;br /&gt;
&lt;br /&gt;
==== Output TLVs ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  System Version&lt;br /&gt;
!  Applets&lt;br /&gt;
!  Type&lt;br /&gt;
!  Size&lt;br /&gt;
!  Value&lt;br /&gt;
!  Description&lt;br /&gt;
|-&lt;br /&gt;
| [3.0.0+]&lt;br /&gt;
| Share, Web&lt;br /&gt;
| 0x1&lt;br /&gt;
| 0x4&lt;br /&gt;
| u32&lt;br /&gt;
| ShareExitReason&lt;br /&gt;
|-&lt;br /&gt;
| [3.0.0+]&lt;br /&gt;
| Share, Web&lt;br /&gt;
| 0x2&lt;br /&gt;
| &lt;br /&gt;
| string&lt;br /&gt;
| LastUrl&lt;br /&gt;
|-&lt;br /&gt;
| [3.0.0+]&lt;br /&gt;
| Share, Web&lt;br /&gt;
| 0x3&lt;br /&gt;
| 0x8&lt;br /&gt;
| u64&lt;br /&gt;
| LastUrlSize&lt;br /&gt;
|-&lt;br /&gt;
| [3.0.0+]&lt;br /&gt;
| Share&lt;br /&gt;
| 0x4&lt;br /&gt;
| 0x4&lt;br /&gt;
| u32&lt;br /&gt;
| SharePostResult&lt;br /&gt;
|-&lt;br /&gt;
| [3.0.0+]&lt;br /&gt;
| Share&lt;br /&gt;
| 0x5&lt;br /&gt;
| &lt;br /&gt;
| string&lt;br /&gt;
| PostServiceName&lt;br /&gt;
|-&lt;br /&gt;
| [3.0.0+]&lt;br /&gt;
| Share&lt;br /&gt;
| 0x6&lt;br /&gt;
| 0x8&lt;br /&gt;
| u64&lt;br /&gt;
| PostServiceNameSize&lt;br /&gt;
|-&lt;br /&gt;
| [3.0.0+]&lt;br /&gt;
| Share&lt;br /&gt;
| 0x7&lt;br /&gt;
| &lt;br /&gt;
| string&lt;br /&gt;
| PostId&lt;br /&gt;
|-&lt;br /&gt;
| [3.0.0+]&lt;br /&gt;
| Share&lt;br /&gt;
| 0x8&lt;br /&gt;
| 0x8&lt;br /&gt;
| u64&lt;br /&gt;
| PostIdSize&lt;br /&gt;
|-&lt;br /&gt;
| [8.0.0+]&lt;br /&gt;
| Web&lt;br /&gt;
| 0x9&lt;br /&gt;
| 0x1&lt;br /&gt;
| u8 bool&lt;br /&gt;
| MediaPlayerAutoClosedByCompletion&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
These are used for Share-applet on [3.0.0+], and with Web on [8.0.0+]. Official user-processes doesn&#039;t check the TLV size for any of these.&lt;br /&gt;
&lt;br /&gt;
==== DocumentKind ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Value&lt;br /&gt;
!  Name&lt;br /&gt;
!  Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x1&lt;br /&gt;
| DocumentKind_OfflineHtmlPage&lt;br /&gt;
| Use the HtmlDocument NCA content from the application.&lt;br /&gt;
|-&lt;br /&gt;
| 0x2&lt;br /&gt;
| DocumentKind_ApplicationLegalInformation&lt;br /&gt;
| Use the LegalInformation NCA content from the application.&lt;br /&gt;
|-&lt;br /&gt;
| 0x3&lt;br /&gt;
| DocumentKind_SystemDataPage&lt;br /&gt;
| Use the Data NCA content from the specified title, see also: [[Title_list#System_Data_Archives]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
This controls the kind of content to mount with Offline-applet.&lt;br /&gt;
&lt;br /&gt;
==== ShareStartPage ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Value&lt;br /&gt;
!  Name&lt;br /&gt;
!  URL&lt;br /&gt;
|-&lt;br /&gt;
| 0&lt;br /&gt;
| ShareStartPage_Default&lt;br /&gt;
| [[Network|&amp;quot;https://web-%.share.srv.nintendo.net/&amp;quot;]]&lt;br /&gt;
|-&lt;br /&gt;
| 1&lt;br /&gt;
| ShareStartPage_Settings&lt;br /&gt;
| [[Network|&amp;quot;https://web-%.share.srv.nintendo.net/settings/&amp;quot;]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
This enum controls the initial page for ShareApplet.&lt;br /&gt;
&lt;br /&gt;
==== BootDisplayKind ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Value&lt;br /&gt;
!  Name&lt;br /&gt;
!  Description&lt;br /&gt;
|-&lt;br /&gt;
| 0&lt;br /&gt;
| BootDisplayKind_White&lt;br /&gt;
| Default white background.&lt;br /&gt;
|-&lt;br /&gt;
| 1&lt;br /&gt;
| &lt;br /&gt;
| Unknown. Used by Offline default Arg initialization for DocumentKind_ApplicationLegalInformation/DocumentKind_SystemDataPage.&lt;br /&gt;
|-&lt;br /&gt;
| 2&lt;br /&gt;
| BootDisplayKind_Black&lt;br /&gt;
| Black background.&lt;br /&gt;
|-&lt;br /&gt;
| 3&lt;br /&gt;
| &lt;br /&gt;
| Unknown. Used by Share default Arg initialization.&lt;br /&gt;
|-&lt;br /&gt;
| 4&lt;br /&gt;
| &lt;br /&gt;
| Unknown. Used by Lobby default default Arg initialization.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Kind values for BootDisplayKind. Controls the background color while displaying the loading screen during applet boot. Also controls the BackgroundKind when value is non-zero.&lt;br /&gt;
&lt;br /&gt;
The applet converts this to internal values.&lt;br /&gt;
* BootDisplayKind 0: &lt;br /&gt;
** If launched by an Application:&lt;br /&gt;
*** If [[#BackgroundKind]] is 2..1, return 3..2. When 0, run the below, otherwise assert.&lt;br /&gt;
** return TLV value from BootAsMediaPlayer&lt;br /&gt;
* BootDisplayKind 1..4: return 0..3.&lt;br /&gt;
&lt;br /&gt;
==== BackgroundKind ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Value&lt;br /&gt;
!  Name&lt;br /&gt;
!  Description&lt;br /&gt;
|-&lt;br /&gt;
| 0&lt;br /&gt;
| &lt;br /&gt;
| Unknown. Used by Offline default Arg initialization for DocumentKind_ApplicationLegalInformation/DocumentKind_SystemDataPage.&lt;br /&gt;
|-&lt;br /&gt;
| 1&lt;br /&gt;
| &lt;br /&gt;
| Same as [[#BootDisplayKind]] value 3.&lt;br /&gt;
|-&lt;br /&gt;
| 2&lt;br /&gt;
| &lt;br /&gt;
| Same as [[#BootDisplayKind]] value 4. Used by Lobby default Arg initialization.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Kind values for BackgroundKind. Only used when [[#BootDisplayKind]] is 0.&lt;br /&gt;
&lt;br /&gt;
==== LeftStickMode ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Value&lt;br /&gt;
!  Name&lt;br /&gt;
!  Description&lt;br /&gt;
|-&lt;br /&gt;
| 0&lt;br /&gt;
| LeftStickMode_Pointer&lt;br /&gt;
| The user can directly control the pointer via the left-stick.&lt;br /&gt;
|-&lt;br /&gt;
| 1&lt;br /&gt;
| LeftStickMode_Cursor&lt;br /&gt;
| The user can only select elements on the page via the left-stick.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Controls the initial mode, this can be toggled by the user via the pressing the left-stick button. If the Pointer flag is set to false, only LeftStickMode_Cursor will be used and mode toggle by the user is disabled (input value ignored).&lt;br /&gt;
&lt;br /&gt;
==== FooterButtonId ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Value&lt;br /&gt;
!  Name&lt;br /&gt;
!  Description&lt;br /&gt;
|-&lt;br /&gt;
| 0&lt;br /&gt;
| None&lt;br /&gt;
| None, for empty [[#WebBootFooterButtonEntry]]. Invalid for use as an input Id.&lt;br /&gt;
|-&lt;br /&gt;
| 1&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 2&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 3&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 4&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 5&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 6&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 7&lt;br /&gt;
| &lt;br /&gt;
| Values starting with this are invalid.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== WebSessionBootMode ====&lt;br /&gt;
This is &amp;quot;nn::web::WebSessionBootMode&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Value&lt;br /&gt;
!  Name&lt;br /&gt;
!  Description&lt;br /&gt;
|-&lt;br /&gt;
| 0&lt;br /&gt;
| &lt;br /&gt;
| Normal/default (AllForeground)&lt;br /&gt;
|-&lt;br /&gt;
| 1&lt;br /&gt;
| &lt;br /&gt;
| AllForegroundInitiallyHidden&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
This controls which [[Applet_Manager_services|LibraryAppletMode]] the applet will be launched with, by the user-process. The TLV for this seems to be ignored by the applet.&lt;br /&gt;
&lt;br /&gt;
==== LastUrl ====&lt;br /&gt;
When the applet loads a page where the beginning of the URL matches the URL from CallbackUrl, the applet will exit and set LastUrl to that URL (exit doesn&#039;t occur when CallbackableUrl is set). With Offline-applet for CallbackUrl handling, it compares the domain with &amp;quot;localhost&amp;quot; instead of using the CallbackUrl TLV.&lt;br /&gt;
&lt;br /&gt;
== Versions ==&lt;br /&gt;
&lt;br /&gt;
=== [[1.0.0]] ===&lt;br /&gt;
&amp;quot;shareddata:/buildinfo/buildinfo.dat&amp;quot; content:&lt;br /&gt;
  r:11682&lt;br /&gt;
  p:NX64&lt;br /&gt;
  v:Pilot&lt;br /&gt;
  d:2016-11-25 23:30&lt;br /&gt;
  n:0.4.25&lt;br /&gt;
&lt;br /&gt;
=== [[2.0.0]] ===&lt;br /&gt;
&lt;br /&gt;
&amp;quot;shareddata:/buildinfo/buildinfo.dat&amp;quot; content:&lt;br /&gt;
  r:13341&lt;br /&gt;
  p:NX64&lt;br /&gt;
  v:Release&lt;br /&gt;
  d:2017-02-13 22:57&lt;br /&gt;
  n:0.5.9&lt;br /&gt;
  &lt;br /&gt;
&lt;br /&gt;
=== [[2.1.0]] ===&lt;br /&gt;
See [[Switch_Userland_Flaws|here]] for vuln-related changes.&lt;br /&gt;
&lt;br /&gt;
The WebKit NRO was updated. For the WebKit NRO, the page-aligned size for the R-X, R--, and RW- pages are the same as v2.0.&lt;br /&gt;
* The actual code in the NRO starts differing starting at offset 0xE780. In v2.0 the offset following the last code instruction is text_lastpage+0x3F8(text_end-0xC08), while for v2.1 it&#039;s text_lastpage+0xE60(text_end-0x1A0). Compared to the previous version, there&#039;s a val0 u32(padding) inserted where the code for the import stubs begin, near the end of .text. Relative to that end offset going backwards, .text differs starting at v2.0 textbase+0xD56530 / v2.1 textbase+0xD56F94.&lt;br /&gt;
* The R-- section was updated. Besides the large table(?) which was updated(nothing was added/removed there), the strings containing &amp;quot;D:/for_cruiser/release_182/nx/webkit/&amp;quot; were updated: &amp;quot;182&amp;quot; was changed to &amp;quot;189&amp;quot;. 0x10-bytes at offset 0x57292C were removed. 0x8-bytes were inserted at offset 0x14B2B5C in the v2.1 section. 0x8-bytes were inserted at offset 0x14B5C10 in the v2.1 section. ...&lt;br /&gt;
* The RW- section was updated, mainly for different addrs. Nothing was added/removed. Most(?)/all(?) main-codebin func import-addrs relative to main-codebin-base are the same as v2.0.&lt;br /&gt;
&lt;br /&gt;
Main-codebin region(titleID 010000000000100B):&lt;br /&gt;
* rtld is same as before basically, minus addrs. Likewise for the &amp;quot;nnSdkEmpty&amp;quot; binary following the main-codebin.&lt;br /&gt;
* Various byte values were changed in the main .text.&lt;br /&gt;
* In the main R-- section:&lt;br /&gt;
** The length of a string used with the user-agent changed, due to being changed from &amp;quot;{...}.9&amp;quot; to &amp;quot;{...}.10&amp;quot;.&lt;br /&gt;
** The version in the following string was changed from &amp;quot;1.2.2&amp;quot; to &amp;quot;1.2.3&amp;quot;: &amp;quot;FS_ACCESS: { sdk_versio n: 1.2.3, spec:  NX }&amp;quot;&lt;br /&gt;
** The datetime strings following &amp;quot;b/23876444&amp;quot; was changed from &amp;quot;Feb 10 2017&amp;quot; &amp;quot;02:24:47&amp;quot; to &amp;quot;Mar  9 201 7&amp;quot; &amp;quot;21:41:27&amp;quot;.&lt;br /&gt;
** A 0x10-byte block prior to SDK library tag strings was updated. The version in those strings was changed from &amp;quot;1_2_2&amp;quot; to &amp;quot;1_2_3&amp;quot;.&lt;br /&gt;
* The main RW- section appears to be basically the same minus addrs.&lt;br /&gt;
&lt;br /&gt;
All of the other NROs were updated in FS with only the following changes:&lt;br /&gt;
* The R-X section is identical to the previous version except for the 0x10-byte block in the NRO header. &lt;br /&gt;
* The R-- section only had version values in &amp;quot;/release_{ver}/&amp;quot; strings updated, see the for_cruiser path mentioned for WebKit NRO above. The only other change was that a 0x10-byte block following a &amp;quot;GNU&amp;quot; string was updated.&lt;br /&gt;
&lt;br /&gt;
==== FS ====&lt;br /&gt;
The content of &amp;quot;blacklist:/&amp;quot; and &amp;quot;oceanShared:/&amp;quot; haven&#039;t changed. Only the content of &amp;quot;shareddata:/&amp;quot; and &amp;quot;data:/&amp;quot; changed.&lt;br /&gt;
&lt;br /&gt;
===== &amp;quot;shareddata:/&amp;quot; =====&lt;br /&gt;
The following files were updated here(nothing added/removed):&lt;br /&gt;
&lt;br /&gt;
* /buildinfo/buildinfo.dat&lt;br /&gt;
* /dll/cairo_wkc.nro&lt;br /&gt;
* /dll/libfont.nro&lt;br /&gt;
* /dll/oss_wkc.nro&lt;br /&gt;
* /dll/peer_wkc.nro&lt;br /&gt;
* /dll/webkit_wkc.nro&lt;br /&gt;
&lt;br /&gt;
That is, every .nro under the above directory was updated.&lt;br /&gt;
&lt;br /&gt;
&amp;quot;shareddata:/buildinfo/buildinfo.dat&amp;quot; content:&lt;br /&gt;
  r:13343&lt;br /&gt;
  p::NX64&lt;br /&gt;
  v:Release&lt;br /&gt;
  d:2017-03-14 21:08&lt;br /&gt;
  n:0.5.10&lt;br /&gt;
&lt;br /&gt;
===== &amp;quot;data:/&amp;quot; =====&lt;br /&gt;
The following files were updated here(nothing added/removed):&lt;br /&gt;
&lt;br /&gt;
* /.nrr/netfront.nrr&lt;br /&gt;
* /buildinfo/buildinfo.dat&lt;br /&gt;
&lt;br /&gt;
=== [[3.0.1]] ===&lt;br /&gt;
While main-codebin .text was updated, no actual code was changed.&lt;br /&gt;
&lt;br /&gt;
The .nss path string in main-codebin was changed from &amp;quot;Q:\work\LibraryApplet\...&amp;quot; to &amp;quot;Q:\work\nup\LibraryApplet\...&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
See [[3.0.1|here]] regarding &amp;quot;shareddata:/&amp;quot; buildinfo.&lt;br /&gt;
&lt;br /&gt;
=== [[5.0.0]] ===&lt;br /&gt;
Support for YouTubeVideo was added, and new [[#TLVs]] etc.&lt;br /&gt;
&lt;br /&gt;
In RomFS &amp;quot;/whitelist/WhitelistYouTubePlayer.txt&amp;quot; was added for the YouTubeVideo whitelist, which contains the following: &amp;lt;nowiki&amp;gt;&amp;quot;^https://www\.youtube\.com/embed/&amp;quot;&amp;lt;/nowiki&amp;gt;. This file has the same content on 7.0.x.&lt;br /&gt;
&lt;br /&gt;
[[Category:Library Applets]]&lt;/div&gt;</summary>
		<author><name>Yellows8</name></author>
	</entry>
	<entry>
		<id>https://switchbrew.org/w/index.php?title=Switch_System_Flaws&amp;diff=14821</id>
		<title>Switch System Flaws</title>
		<link rel="alternate" type="text/html" href="https://switchbrew.org/w/index.php?title=Switch_System_Flaws&amp;diff=14821"/>
		<updated>2026-07-25T19:39:01Z</updated>

		<summary type="html">&lt;p&gt;Yellows8: /* Whitelist */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This page is a list of publicly known Switch / Switch 2 (S2) flaws.&lt;br /&gt;
&lt;br /&gt;
= Hardware =&lt;br /&gt;
Flaws in this category pertain to the underlying hardware that powers the Switch.&lt;br /&gt;
&lt;br /&gt;
This includes components shared across Tegra based devices such as the [[TSEC]], the [[Security_Engine|Security Engine]], the [[GPU]] and so on.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
!  Summary&lt;br /&gt;
!  Description&lt;br /&gt;
!  Fixed with hardware model/revision&lt;br /&gt;
!  Newest hardware model/revision this flaw was checked for&lt;br /&gt;
!  Timeframe this was discovered&lt;br /&gt;
!  Public disclosure timeframe&lt;br /&gt;
!  Discovered by&lt;br /&gt;
|-&lt;br /&gt;
| GMMU DMA attack&lt;br /&gt;
| The Switch&#039;s GPU includes a separate MMU (GMMU) that is allowed to bypass the system&#039;s IOMMU (SMMU). By accessing the GPU&#039;s MMIO region and manipulating the page table entries in the GMMU, an attacker can read/write any portion of the DRAM (except memory carveouts).&lt;br /&gt;
&lt;br /&gt;
[5.0.0+] Works around this hardware flaw by using memory pool partitioning. You can no longer escalate into sysmodules with GPU DMA because all their memory is allocated using heap that&#039;s carved out.&lt;br /&gt;
&lt;br /&gt;
HAC-001-01 (Mariko/Tegra214/Tegra210b01): Fixes this by adding a new register which restricts what memory untranslated DMA requests may access. Untranslated GPU DMA may now only access the GPU carveout (physmem 0x80002000-0x80006000), which the GPU already has legitimate and exclusive access to.&lt;br /&gt;
| HAC-001-01 (Mariko/Tegra214/Tegra210b01)&lt;br /&gt;
| HAC-001 (Tegra210)&lt;br /&gt;
| Summer 2017&lt;br /&gt;
| December 28, 2017&lt;br /&gt;
| [[User:hexkyz|hexkyz]], [[User:SciresM|SciresM]] and [[User:qlutoo|qlutoo]]&lt;br /&gt;
|-&lt;br /&gt;
| Weak Security Engine context validation&lt;br /&gt;
| The Tegra X1 supports a &amp;quot;deep sleep&amp;quot; feature, where everything but DRAM and the PMC registers lose their content (and the SoC loses power). Upon awaking, the bootrom re-executes, restoring system state. Among these stored states is the Security Engine&#039;s saved state, which uses AES-128-CBC with a random key and all-zeroes IV. However, the bootrom doesn&#039;t perform a MAC on this data, and only validates the last block. This allows one to control most of security engine&#039;s state upon wakeup, if one has a way to modify the encrypted state buffer.&lt;br /&gt;
&lt;br /&gt;
With a way to modify the encrypted state buffer, one can thus dump keys from &amp;quot;write-only&amp;quot; keyslots, etc.&lt;br /&gt;
&lt;br /&gt;
This also bypasses the SBK protection of the bootROM: indeed, at warmboot, bootROM will always clear keyslot 0xE to prevent malicious code from saving the SBK. Moving the SBK to another keyslot in the saved context renders this protection moot.&lt;br /&gt;
&lt;br /&gt;
HAC-001-01 (Mariko/Tegra214/Tegra210b01): Fixes this by streamlining the context save process; security engine contexts are now saved to protected memory which the CPU cannot access or modify.&lt;br /&gt;
| HAC-001-01 (Mariko/Tegra214/Tegra210b01)&lt;br /&gt;
| HAC-001 (Tegra210)&lt;br /&gt;
| December 2017&lt;br /&gt;
| January 20, 2018&lt;br /&gt;
| [[User:SciresM|SciresM]] and [[User:motezazer|motezazer]]&lt;br /&gt;
|-&lt;br /&gt;
| Security Engine keyslots vulnerable to partial overwrite attack&lt;br /&gt;
| &lt;br /&gt;
The Tegra X1 security engine supports writing keyslot data to the engine with syntax as follows: &lt;br /&gt;
&lt;br /&gt;
SECURITY_ENGINE-&amp;gt;AES_KEYTABLE_ADDR = (keyslot &amp;lt;&amp;lt; 4) | (dword_index_in_keyslot); &lt;br /&gt;
&lt;br /&gt;
SECURITY_ENGINE-&amp;gt;AES_KEYTABLE_DATA = readle32(key, dword_index_in_keyslot * 4); &lt;br /&gt;
&lt;br /&gt;
However, the Security Engine flushes writes to the internal key tables immediately when AES_KEYTABLE_DATA is written -- this allows one to overwrite a single dword of a key at a time, and thus brute force the contents of keyslots in time (2^32 * 8) = 2^35 instead of 2^256.&lt;br /&gt;
| None&lt;br /&gt;
| HAC-001 (Tegra210)&lt;br /&gt;
| Theorized Summer 2017 due to suggestive syntax, confirmed April 9, 2018&lt;br /&gt;
| April 9, 2018&lt;br /&gt;
| [[User:SciresM|SciresM]], almost surely others (independently).&lt;br /&gt;
|-&lt;br /&gt;
| CVE-2018-6242 (leveraged by the ShofEL2 and Fusée Gelée exploits)&lt;br /&gt;
| The USB software stack provided inside the boot instruction rom (IROM/bootROM) contains a copy operation whose length can be controlled by an attacker. By carefully constructing a USB control request, an attacker can leverage this vulnerability to copy the contents of an attacker-controlled buffer over the active execution stack, gaining control of the Boot and Power Management processor (BPMP) before any lock-outs or privilege reductions occur. This execution can then be used to exfiltrate secrets and to load arbitrary code onto the main CPU Complex (CCPLEX) &amp;quot;application processors&amp;quot; at the highest possible level of privilege (typically as the TrustZone Secure Monitor at PL3/EL3).&lt;br /&gt;
| HAC-001-01 (Mariko/Tegra214/Tegra210b01) (also fixed independently on Tegra186).&lt;br /&gt;
| HAC-001 (Tegra210)&lt;br /&gt;
| January 2018&lt;br /&gt;
| April 23, 2018&lt;br /&gt;
| [[User:Shuffle2|shuffle2]] and fail0verflow (originally),&amp;lt;br&amp;gt; [[User:Ktemkin|ktemkin]] and ReSwitched Team (independently),&amp;lt;br&amp;gt; [[User:Naehrwert|naehrwert]] (independently),&amp;lt;br&amp;gt; [[User:Hexkyz|hexkyz]] (independently),&amp;lt;br&amp;gt; st4rk with [[User:Shinyquagsire23|Shiny Quagsire]] and Dazzozo (independently),&amp;lt;br&amp;gt; and many others (independently).&lt;br /&gt;
|-&lt;br /&gt;
| Poor validation of bootrom SDRAM configuration parameters leads to arbitrary writes in bootrom&lt;br /&gt;
| &lt;br /&gt;
The Tegra X1 bootrom supports saving SDRAM parameters to scratch registers, and using the saved configuration to enable DRAM during warmboot.&lt;br /&gt;
&lt;br /&gt;
The code that parses these parameters does if (params-&amp;gt;EmcBctSpareN) *params-&amp;gt;EmcBctSpareN = params-&amp;gt;EmcBctSpareNPlusOne for most N, without validating either the address or value written to it.&lt;br /&gt;
There are other arbitrary writes in this code, as well (e.g. BootromPatch parameters intended for patching MISC registers do not check a relative offset to 0x7000000, etc).&lt;br /&gt;
&lt;br /&gt;
This allows a user with access to the PMC registers (via pre-sleep bpmp execution, or otherwise) to gain arbitrary bootrom code execution.&lt;br /&gt;
&lt;br /&gt;
HAC-001-01 (Mariko/Tegra214/Tegra210b01): Fixes this by validating that the spare writes/bootrom patch before performing them.&lt;br /&gt;
| HAC-001-01 (Mariko/Tegra214/Tegra210b01)&lt;br /&gt;
| HAC-001 (Tegra210)&lt;br /&gt;
| 2017&lt;br /&gt;
| December 16, 2018&lt;br /&gt;
| Everyone (independently).&lt;br /&gt;
|-&lt;br /&gt;
| TSEC ROM does not clear crypto registers after signature verification&lt;br /&gt;
|&lt;br /&gt;
TSEC supports executing signed-microcode at a greater privilege level than normal payloads.&lt;br /&gt;
&lt;br /&gt;
When jumping to signed microcode, the caller is expected to load hardware crypto register $c6 = &amp;lt;signature&amp;gt;, $c7 = &amp;lt;seed (zero for all officially-signed microcode)&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
TSEC ROM then calculates the expected signature and compares it to the user-supplied one in $c6. On match, the secure payload is executed, and on failure an exception is raised.&lt;br /&gt;
&lt;br /&gt;
However, TSEC ROM fails to clear the crypto registers used to calculate the expected signature in either of the success/failure cases.&lt;br /&gt;
&lt;br /&gt;
Thus, with some way of obtaining the contents of crypto registers (e.g. ROP under some secure payload), an attacker can dump intermediary values from signature calculation.&lt;br /&gt;
&lt;br /&gt;
With enough data/trial/error, this is enough to reconstruct the signature algorithm:&lt;br /&gt;
* mac = &amp;lt;davies meyer hash of (page || address of page) for each 0x100 page in the payload&amp;gt;&lt;br /&gt;
* key = AES-ENCRYPT(hardware csecret 0x1, seed)&lt;br /&gt;
* signature = AES-ENCRYPT(key, mac)&lt;br /&gt;
&lt;br /&gt;
| None&lt;br /&gt;
| HAC-001 (Tegra210)&lt;br /&gt;
| Late 2018/Early 2019&lt;br /&gt;
| August 2020&lt;br /&gt;
| [[User:qlutoo|qlutoo]]/[[User:Hexkyz|hexkyz]]/[[User:Shuffle2|shuffle2]], [[User:SciresM|SciresM]]/[[User:motezazer|motezazer]] (independently).&lt;br /&gt;
|-&lt;br /&gt;
| TSEC signature validation design flaw leads to fake-signing&lt;br /&gt;
|&lt;br /&gt;
As mentioned above, when jumping to signed microcode the caller is expected to load hardware crypto register $c6 = &amp;lt;signature&amp;gt;, $c7 = &amp;lt;seed (zero for all officially-signed microcode)&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
However, TSEC ROM performs no validation on the input seed used to generate the signing key.&lt;br /&gt;
&lt;br /&gt;
This leads to the following attack:&lt;br /&gt;
* Attacker gains rop under any secure microcode payload with signature = S.&lt;br /&gt;
* Attacker uses the &amp;quot;csigenc&amp;quot; instruction to obtain K = AES-ENCRYPT(hardware csecret 0x1, S).&lt;br /&gt;
* Attacker jumps to their own microcode with $c6 = &amp;lt;signature calculated on pc using K&amp;gt;, $c7 = S&lt;br /&gt;
* TSEC ROM calculates key = AES-ENCRYPT(hardware csecret 0x1, S) = K, and the signature check passes.&lt;br /&gt;
* Attackers microcode is executed in secure mode as though it were signed by NVidia.&lt;br /&gt;
&lt;br /&gt;
Thus an attacker who has exploited *any* secure payload may use this to obtain a &amp;quot;fake signature key&amp;quot;, which can be used to sign and execute arbitrary microcode in secure mode.&lt;br /&gt;
&lt;br /&gt;
Note: this does not break the TSEC cryptosystem, as the csigenc mechanism relies on the signature of the executing microcode, and fakesigning produces different signatures from NVidia that cannot be controlled.&lt;br /&gt;
| None&lt;br /&gt;
| HAC-001 (Tegra210)&lt;br /&gt;
| Late 2018/Early 2019&lt;br /&gt;
| August 2020&lt;br /&gt;
| [[User:qlutoo|qlutoo]]/[[User:Hexkyz|hexkyz]]/[[User:Shuffle2|shuffle2]], [[User:SciresM|SciresM]]/[[User:motezazer|motezazer]] (independently).&lt;br /&gt;
|-&lt;br /&gt;
| ROP under TSEC secure bootrom via DMA engine stack overwrite (--xploit)&lt;br /&gt;
| TSEC DMA engine does not stop when entering TSEC secure bootrom. By pointing TSEC DMA to current stack before secure bootrom entry, stack can be controlled. &lt;br /&gt;
&lt;br /&gt;
One can then use blind ROP against the TSEC secure bootrom (which is execute only, and cannot be dumped).&lt;br /&gt;
&lt;br /&gt;
With sufficient effort, an attacker can construct a ROP chain that leads to csigcmp being executed with fully controlled arguments.&lt;br /&gt;
&lt;br /&gt;
This allows for arbitrary heavy secure mode code execution with the current signature set to an arbitrary value.&lt;br /&gt;
&lt;br /&gt;
This completely breaks the TSEC cryptosystem, by allowing one to obtain the result of csigenc with signature = &amp;lt;any desired value&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
This has many uses/results, notably including dumping the &amp;quot;true&amp;quot; signature key (set signature = zeroes, perform csigenc using csecret 0x1).&lt;br /&gt;
| None&lt;br /&gt;
| TSEC for all Tegra devices&lt;br /&gt;
| Late 2018&lt;br /&gt;
| January 2021&lt;br /&gt;
| [[User:Hexkyz|hexkyz]]/[[User:SciresM|SciresM]], [[User:Vale|Vale]]/[[User:Thog|Thog]] (independently), [[User:Tatsuko|Tatsuko]] (independently), possibly others (independently).&lt;br /&gt;
|-&lt;br /&gt;
| Boot straps are not relatched on watchdog resets (strapwn)&lt;br /&gt;
| On boot, the BOOTSELECT, RCM and RAM_CODE straps are latched from external GPIO to determine which boot medium to use and verify from in bootrom. However, APB_MISC_PP_STRAPPING_OPT_A can be overwritten with arbitrary values following bootrom. Write access to PP_STRAPPING_OPT_A would otherwise be mundane, however these straps are not relatched during a watchdog reset (despite being latched during other software resets), allowing for arbitrary straps to be selected and executed in bootrom.&lt;br /&gt;
&lt;br /&gt;
This allows setting NVPROD_UART on some hardware configurations where it would normally be unavailable (ie on Jetson Nano boards), but is otherwise mostly useless and/or useful for testing unintended boot options (such as USB Mass Storage boot) without having to move boot strap resistors.&lt;br /&gt;
| Unknown&lt;br /&gt;
| HAC-001 (Tegra210)&lt;br /&gt;
| May 2020&lt;br /&gt;
| April 30, 2021&lt;br /&gt;
| [[User:Shinyquagsire23|Shiny Quagsire]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Firmware =&lt;br /&gt;
Flaws in this category pertain to the firmware running on hardware devices, such as wifi/bluetooth, etc. Firmware is generally uploaded by sysmodules.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Summary&lt;br /&gt;
!  Description&lt;br /&gt;
!  Successful exploitation result&lt;br /&gt;
!  Fixed in system version&lt;br /&gt;
!  Last system version this flaw was checked for&lt;br /&gt;
!  Timeframe this was discovered&lt;br /&gt;
!  Public disclosure timeframe&lt;br /&gt;
!  Discovered by&lt;br /&gt;
|-&lt;br /&gt;
| Broadpwn (CVE-2017-9417)&lt;br /&gt;
| See [https://blog.exodusintel.com/2017/07/26/broadpwn/ here] and [https://www.blackhat.com/docs/us-17/thursday/us-17-Artenstein-Broadpwn-Remotely-Compromising-Android-And-iOS-Via-A-Bug-In-Broadcoms-Wifi-Chipsets.pdf here].&lt;br /&gt;
| Code execution on the wifi controller (untested on Switch).&lt;br /&gt;
| [[4.0.0]]&lt;br /&gt;
| [[4.0.0]]&lt;br /&gt;
| Switch: July 2022&lt;br /&gt;
| Switch: July 30, 2022&lt;br /&gt;
| Switch: [[User:Yellows8|yellows8]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Software =&lt;br /&gt;
== Bootloader ==&lt;br /&gt;
Flaws in this category pertain to any bootloader component such as the [[Package1#Package1ldr|package1ldr]], the [[Package1#Section_1|NX bootloader]] or the [[Package1#Section_0|warmboot binary]].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Summary&lt;br /&gt;
!  Description&lt;br /&gt;
!  Successful exploitation result&lt;br /&gt;
!  Fixed in system version&lt;br /&gt;
!  Last system version this flaw was checked for&lt;br /&gt;
!  Timeframe this was discovered&lt;br /&gt;
!  Public disclosure timeframe&lt;br /&gt;
!  Discovered by&lt;br /&gt;
|-&lt;br /&gt;
| Null-dereference in panic()&lt;br /&gt;
| The Switch&#039;s stage 1 bootloader, on panic(), clears the stack and then attempts to clear the Security Engine. However, it does so by dereferencing a pointer to the SE in .bss (initially NULL), and this pointer doesn&#039;t get initialized until partway into the bootloader&#039;s main() after several functions that might panic() are called. Thus, a panic() caused prior to SE initialization would result in the SE pointer still being NULL when dereferenced. &lt;br /&gt;
The BPMP doesn&#039;t have an active MPU and the bus won&#039;t data abort on an invalid address, so no exception will be entered: it&#039;ll end up overwriting some exception vectors with NULL before halting.&lt;br /&gt;
&lt;br /&gt;
In 3.0.0, this was fixed by moving the security engine initialization earlier in main(), before the first function that could potentially panic().&lt;br /&gt;
| Some exception vectors overwritten with NULL, before SBK/other keyslots are cleared. Probably useless for anything more interesting.&lt;br /&gt;
| [[3.0.0]]&lt;br /&gt;
| [[3.0.0]]&lt;br /&gt;
| Early July, 2017&lt;br /&gt;
| July 30, 2017&lt;br /&gt;
| Everyone who diff&#039;d 2.3.0 and 3.0.0 Package1&lt;br /&gt;
|-&lt;br /&gt;
| FUSE_DIS_PGM not written by package1 &lt;br /&gt;
| The switch&#039;s hardware fuse driver contains a write-once bit in a register called &amp;quot;FUSE_DIS_PGM&amp;quot;, which disables burning fuses until the next reboot. While Nintendo&#039;s bootloader code for waking up from sleep writes this on all firmware, the actual package1 initial bootloader forgets to write to it on cold reboot. &lt;br /&gt;
&lt;br /&gt;
This isn&#039;t too big of a problem because another fuse is burnt on retail devices (production mode), which prevents burning *all* fuses other than ODM_RESERVED ones in hardware.&lt;br /&gt;
&lt;br /&gt;
This was fixed in 3.0.0 by writing to the register on cold boot (although the write happens in TZ instead of package1 where it should take place, possibly to obfuscate the fact that they made this mistake).&lt;br /&gt;
| Burning arbitrary ODM reserved fuses with TZ code execution, which should never be possible for non-bootloader code.&lt;br /&gt;
&lt;br /&gt;
Warning: one could irreparably brick one&#039;s console by playing with this.&lt;br /&gt;
| [[3.0.0]]&lt;br /&gt;
| [[3.0.0]]&lt;br /&gt;
| Late summer/early fall 2017&lt;br /&gt;
| December 31, 2017&lt;br /&gt;
| [[User:SciresM|SciresM]], [[User:motezazer|motezazer]]&lt;br /&gt;
|-&lt;br /&gt;
| maconstack (TSEC firmware leaves MAC on the stack)&lt;br /&gt;
| Package1ldr loads a firmware blob into TSEC early on boot. This piece of code runs on the TSEC in Authenticated Mode and has the sole purpose of generating the per-console TSEC key (see [[Cryptosystem]]).&lt;br /&gt;
&lt;br /&gt;
As a way to mitigate attacks, the TSEC firmware blob is split into 3 stages: [[TSEC_Firmware#Boot|Boot]] which is unencrypted and unsigned, [[TSEC_Firmware#KeygenLdr|KeygenLdr]] which is unencrypted but signed and [[TSEC_Firmware#Keygen|Keygen]] which is encrypted and signed.&lt;br /&gt;
Boot loads a static pre-generated signature into the Falcon&#039;s CPU crypto registers, loads KeygenLdr into the Falcon&#039;s CODE region and jumps to it. Execution will proceed into KeygenLdr in Heavy Secure Mode if, and only if, the loaded signature matches the one Falcon calculates internally for KeygenLdr.&lt;br /&gt;
&lt;br /&gt;
Among various things, KeygenLdr will attempt to do a &amp;quot;backwards&amp;quot; security check by calculating a CMAC over Boot and comparing it with a known hash stored in the TSEC firmware&#039;s key data (a small buffer stored after Boot&#039;s code). If the hashes don&#039;t match, execution aborts.&lt;br /&gt;
&lt;br /&gt;
KeygenLdr stores the calculated Boot&#039;s CMAC in the stack, but forgets to clear it. Since the stack is located in Falcon&#039;s DATA region, loading the TSEC firmware blob and dumping the DATA region afterwards (via MMIO) will reveal the calculated hash.&lt;br /&gt;
This allows using KeygenLdr as an oracle to generate a valid CMAC for arbitrary Boot code. Replacing the CMAC in the TSEC firmware&#039;s key data region results in KeygenLdr accepting any Boot code, thus rendering this security measure useless.&lt;br /&gt;
&lt;br /&gt;
Additionally, since signed Falcon code can&#039;t be revoked without an hardware revision, an attacker can always reuse the flawed KeygenLdr code even if a fix is issued.&lt;br /&gt;
| Running TSEC firmware&#039;s KeygenLdr in a user controlled environment.&lt;br /&gt;
| None&lt;br /&gt;
| [[5.0.2]]&lt;br /&gt;
| January 2018&lt;br /&gt;
| April 29, 2018&lt;br /&gt;
| [[User:Hexkyz|hexkyz]], [[User:Rei|Reisyukaku]] (independently), probably others (independently).&lt;br /&gt;
|-&lt;br /&gt;
| pk1ldrhax&lt;br /&gt;
| Package1ldr decrypts and verifies the keyblob inside of the current BCT in order to get the package1 key, and then uses the package1 key to decrypt package1. It then validates package1 before jumping to it by checking the PK11 magic number, and that the section sizes sum to the expected size (and are individually less than the expected size). &lt;br /&gt;
&lt;br /&gt;
However, package1ldr does not actually validate the package1 key against a fixed vector (much like kernel9loader forgot to do so on the 3ds). This would normally not matter, as keyblobs are validated -- however, with bootrom code execution one can dump SBK and forge keyblobs, and thus control the package1 key. &lt;br /&gt;
&lt;br /&gt;
Thus (&#039;&#039;&#039;in theory, but not in practice due to the size of the brute force required&#039;&#039;&#039;) one can replace the package1 key with garbage, causing package1 to decrypt into garbage, and hope that this garbage passes validation checks and that package1ldr jumping into the garbage will do something useful.&lt;br /&gt;
&lt;br /&gt;
This was fixed incidentally in [[6.2.0]], as pk1ldr does not use keyblob data to decrypt package1 any more.&lt;br /&gt;
&lt;br /&gt;
| With a large enough brute force: arbitrary package1 code execution from coldboot.&lt;br /&gt;
&lt;br /&gt;
However, a usable brute force is on the order of &amp;gt;= ~2^80, so &#039;&#039;&#039;this is almost certainly not actually usable in any meaningful context&#039;&#039;&#039;.&lt;br /&gt;
| [[6.2.0]]&lt;br /&gt;
| [[6.2.0]]&lt;br /&gt;
| Early 2017 (as soon as plaintext package1ldr was first dumped)&lt;br /&gt;
| November 20, 2018&lt;br /&gt;
| Everyone&lt;br /&gt;
|-&lt;br /&gt;
| Stack smash in TSEC firmware&#039;s KeygenLdr&lt;br /&gt;
| Given that we can control the [[TSEC_Firmware#Key_data|key data]] (which is not authenticated) and the [[TSEC_Firmware#Boot|Boot]] blob (see &amp;quot;maconstack&amp;quot;), as well as the fact Non-secure and Heavy Secure code share the same stack, we can use this to attack KeygenLdr. KeygenLdr uses memcpy to copy over a payload to DMEM to verify it, which can be abused to smash the stack (in DMEM) and write over the return address of said function.&lt;br /&gt;
| ROP under KeygenLdr in Heavy Secure mode.&lt;br /&gt;
| None&lt;br /&gt;
| [[8.0.1]]&lt;br /&gt;
| Early 2018&lt;br /&gt;
| May 21, 2019&lt;br /&gt;
| Everyone (independently).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== TrustZone ==&lt;br /&gt;
Flaws in this category pertain exclusively to the [[Package1#Section_2|Secure Monitor]].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Summary&lt;br /&gt;
!  Description&lt;br /&gt;
!  Successful exploitation result&lt;br /&gt;
!  Fixed in system version&lt;br /&gt;
!  Last system version this flaw was checked for&lt;br /&gt;
!  Timeframe this was discovered&lt;br /&gt;
!  Public disclosure timeframe&lt;br /&gt;
!  Discovered by&lt;br /&gt;
|-&lt;br /&gt;
| Non-atomic mutexes&lt;br /&gt;
| When an [[SMC]] is called, TrustZone sets a global variable to mark that an SMC is in progress, so that two SMCs using shared resources (like the security engine) do not trample on one another. On 1.0.0, this global variable was written using non-atomic writes, and thus a race condition is possible.&lt;br /&gt;
&lt;br /&gt;
However, the SMC handler enforces that all SMCs must be called from core #3, unless the top-level handler ID is 1 (SMCs internal to the kernel). Thus, the only SMCs that can be run side-by-side are [any userland smc] and smcGetRandomBytesForKernel, and this turns out to not really be abusable.&lt;br /&gt;
| Mostly useless. Maybe some oob-write into unused (and thus useless) memory if running smcGetRandomBytesForKernel and smcGetRandomBytesForUser at the same time.&lt;br /&gt;
| [[2.0.0]]&lt;br /&gt;
| [[2.0.0]]&lt;br /&gt;
| December 2017 (Probably earlier by others)&lt;br /&gt;
| January 18, 2018&lt;br /&gt;
| [[User:SciresM|SciresM]], probably others (independently).&lt;br /&gt;
|-&lt;br /&gt;
| jamais vu (non-secure world access to PMC MMIO and pre-deep sleep firmware)&lt;br /&gt;
| On [[1.0.0]], one could map in the PMC registers in userland. In addition, [[AM_services|am]] ran a little-kernel based firmware on the BPMP at runtime. With code execution under am, one could modify the BPMP&#039;s little-kernel firmware to hook deep sleep entry, and modify TrustZone/Security engine state. &lt;br /&gt;
&lt;br /&gt;
This was fixed in [[2.0.0]] by making the PMC secure-world only, blacklisting the BPMP&#039;s exception vectors from being mapped, and thoroughly checking for malicious behavior on deep sleep entry.&lt;br /&gt;
| Arbitrary TrustZone code execution.&lt;br /&gt;
| [[2.0.0]]&lt;br /&gt;
| [[2.0.0]]&lt;br /&gt;
| December, 2017&lt;br /&gt;
| January 20, 2018&lt;br /&gt;
| [[User:SciresM|SciresM]] and [[User:motezazer|motezazer]]&lt;br /&gt;
|-&lt;br /&gt;
| Missed BPMP Exception Vector Writes&lt;br /&gt;
| Starting in [[2.0.0]], the BPMP is asleep at runtime, and is turned on by TrustZone during [[SMC|smcCpuSuspend]] in order to initiate the deep sleep process. When it does so, it is held in RESET, and TrustZone attempts to write to the BPMP exception vectors at 0x6000F200 to register EVP_RESET = lp0_entry_fw_crt0, and all other EVPs to a function that simply reboots. However, while they successfully write EVP_RESET, they miss all the other vectors, accidentally writing to the 0x6000F004-0x6000F020 region instead of the 0x6000F204-0x6000F220 region they want to write to. This results in all the exception vectors for the BPMP other than RESET being &amp;quot;undefined&amp;quot; (attacker controlled).&lt;br /&gt;
&lt;br /&gt;
With some way of causing an exception vector to be taken at the right time, this would give pre-sleep code execution (and thus arbitrary TrustZone code execution, via the security engine flaw). However, none of the abort vectors are really triggerable, and interrupts are disabled for the BPMP when it is taken out of reset. Thus, this is useless in practice.&lt;br /&gt;
&lt;br /&gt;
This was fixed in [[4.0.0]] by writing to the correct registers.&lt;br /&gt;
| Theoretically: Arbitrary TrustZone code execution. In practice: Useless.&lt;br /&gt;
| [[4.0.0]]&lt;br /&gt;
| [[4.0.0]]&lt;br /&gt;
| January, 2018&lt;br /&gt;
| February 23, 2018&lt;br /&gt;
| [[User:SciresM|SciresM]] and [[User:motezazer|motezazer]], [[User:Naehrwert|naehrwert]], [[User:Hexkyz|hexkyz]], probably others (independently).&lt;br /&gt;
|-&lt;br /&gt;
| TSEC has access to the secure kernel carveout &lt;br /&gt;
| TrustZone is responsible for managing security carveouts to prevent DMA controllers from accessing the carveout which contains the kernel, sysmodules, and other critical operating system data.&lt;br /&gt;
&lt;br /&gt;
Until [[8.0.0]], the list of devices that could access the carveout included the TSEC. However, the TSEC can bypass the SMMU when in authenticated mode by writing to a certain register. Thus, pwning nvservices would allow one to take over the TSEC, and use it to write to normally protected mmio/memory.&lt;br /&gt;
&lt;br /&gt;
In [[8.0.0]], this was fixed by removing TSEC access, and adding TSECB access (TSECB cannot bypass the SMMU).&lt;br /&gt;
| With access to the TSEC mmio (nvservices ROP) and code execution in TSEC Heavy Secure mode, kernel code execution, probably.&lt;br /&gt;
| [[8.0.0]]&lt;br /&gt;
| [[8.0.0]]&lt;br /&gt;
| 2017 (when TrustZone code plaintext was first obtained).&lt;br /&gt;
| April 15, 2019&lt;br /&gt;
| Everyone&lt;br /&gt;
|-&lt;br /&gt;
| deja vu (insufficient system state validation on suspend leads to pre-sleep BPMP code execution)&lt;br /&gt;
| Jamais Vu was fixed in [[2.0.0]] by making the PMC secure-world only, blacklisting the BPMP&#039;s exception vectors from being mapped, and thoroughly checking for malicious behavior on deep sleep entry, since gaining pre-sleep code execution on the BPMP compromises the system.&lt;br /&gt;
&lt;br /&gt;
However, the state validation performed by Nintendo&#039;s Secure Monitor was insufficient to prevent pre-sleep execution from being obtained.&lt;br /&gt;
&lt;br /&gt;
Prior to [[6.0.0]], one could use a DMA controller that had access to IRAM and was not held in reset (there were multiple) to race TrustZone&#039;s writes to the BPMP firmware in IRAM, and thus overwrite Nintendo&#039;s firmware with an attacker&#039;s to gain pre-sleep code execution.&lt;br /&gt;
&lt;br /&gt;
[[6.0.0]] addressed this by performing TrustZone state MAC writes and locking PMC scratch *before* turning on the BPMP, fixing the original Jamais Vu exploit entirely. In addition, the BPMP firmware in TrustZone&#039;s .rodata is now memcmp&#039;d to the actual data after it is written to IRAM. This mitigates race attacks that modify the firmware.&lt;br /&gt;
&lt;br /&gt;
However, Nintendo both forgot to validate the BPMP exception vectors after writing them, and forgot to hold in reset a DMA controller that can write to the BPMP&#039;s exception vectors.&lt;br /&gt;
&lt;br /&gt;
AHB-DMA is not blacklisted by kernel mapping whitelist (Nintendo probably forgot it, because the TX1 TRM does not really document that it&#039;s present, although the MMIO works as documented in older (Tegra 3 and before) TRMs).&lt;br /&gt;
&lt;br /&gt;
Thus, with kernel code execution (or some other way of accessing AHB-DMA, e.g. nspwn on &amp;lt;= 4.1.0, TSEC hax, or other arbitrary mmio access flaws), one can DMA to the BPMP&#039;s exception vectors as they are written, causing TrustZone to start the BPMP executing an attacker&#039;s firmware at a different location than TrustZone intends/validates.&lt;br /&gt;
&lt;br /&gt;
This was fixed in [[8.0.0]] by blocking AHB-DMA arbitration and verifying it is held in reset during suspend, and thus there are no more devices that can write to the relevant MMIO at the right time.&lt;br /&gt;
&lt;br /&gt;
| Arbitrary TrustZone/BootROM code execution, by using either the original Jamais Vu flaw (prior to [[6.0.0]] or a warmboot bootrom exploit (any firmware where pre-sleep execution can be gained).&lt;br /&gt;
| [[8.0.0]]&lt;br /&gt;
| [[8.0.0]]&lt;br /&gt;
| December 2017&lt;br /&gt;
| April 15, 2019&lt;br /&gt;
| [[User:SciresM|SciresM]], [[User:motezazer|motezazer]] and ktemkin,  [[User:Naehrwert|naehrwert]] (independently), almost certainly others (independently)&lt;br /&gt;
|-&lt;br /&gt;
| TrustZone allows using imported RSA exponents with arbitrary modulus&lt;br /&gt;
| TrustZone supports &amp;quot;importing&amp;quot; RSA private exponents for use by userland -- these are stored encrypted with TrustZone only keydata in NAND, and decrypted only to TZRAM. This prevents a console that has compromised userland from learning the private exponents of these keys and doing calculations with them offline. In practice, this is used for FS (gamecard communications), ES (drm), and SSL (console client cert communications).&lt;br /&gt;
&lt;br /&gt;
However, the actual SMC API only imports the RSA exponent, and not the modulus, which is passed separately by userland in each call. There is no validation done on the modulus passed in -- this means that userland can pass in any message and modulus it chooses, and obtain the result of (message ^ private exponent) % modulus back from the secure monitor.&lt;br /&gt;
&lt;br /&gt;
By choosing a prime number modulus P such that P has &amp;quot;smooth&amp;quot; order (totient(P) == P-1 is divisible only by &amp;quot;small&amp;quot; primes), one can efficiently use the [[wikipedia:Pohlig-Hellman algorithm|Pohlig-Hellman algorithm]] to calculate the discrete logarithm of such a result directly, and thus obtain the private exponent.&lt;br /&gt;
&lt;br /&gt;
This is mostly useless in practice, given the general availability of other exploits to obtain these decrypted exponents.&lt;br /&gt;
&lt;br /&gt;
This was fixed in 10.0.0 by importing the modulus in addition to the exponent for the ES device key and ES client cert key. For backwards compatibility reasons the SSL key and Lotus key still only import the exponent.&lt;br /&gt;
&lt;br /&gt;
StorageExpMod also now validates that the exponentiation of &amp;quot;DDDDD...&amp;quot; about the provided modulus by the imported exponent and then the fixed public exponent returns &amp;quot;DDDDD...&amp;quot;, and returns invalid argument if validation fails.&lt;br /&gt;
| With userland privileges sufficient to use an imported RSA key: obtaining that RSA key&#039;s private exponent.&lt;br /&gt;
| [[10.0.0]]&lt;br /&gt;
| [[10.0.0]]&lt;br /&gt;
| August 14, 2019&lt;br /&gt;
| August 14, 2019&lt;br /&gt;
| [[User:SciresM|SciresM]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Kernel ==&lt;br /&gt;
Flaws in this category pertain exclusively to the [[Package2#Section_0|HorizonOS Kernel]].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Summary&lt;br /&gt;
!  Description&lt;br /&gt;
!  Successful exploitation result&lt;br /&gt;
!  Fixed in system version&lt;br /&gt;
!  Last system version this flaw was checked for&lt;br /&gt;
!  Timeframe this was discovered&lt;br /&gt;
!  Public disclosure timeframe&lt;br /&gt;
!  Discovered by&lt;br /&gt;
|-&lt;br /&gt;
| Syscall Infoleaks&lt;br /&gt;
| Many syscalls leaked kernel pointers on sad paths (for example svcSetHeapSize and svcQueryMemory), until they landed a bunch of fixes in 2.0.0.&lt;br /&gt;
| Nothing really.&lt;br /&gt;
| [[2.0.0]]&lt;br /&gt;
| [[2.0.0]]&lt;br /&gt;
| &lt;br /&gt;
| 2017&lt;br /&gt;
| Everyone&lt;br /&gt;
|-&lt;br /&gt;
| svcWaitSynchronization/svcReplyAndReceive bad cleanup on error&lt;br /&gt;
| If there is a page fault when fetching handles from the userspace array, it cleans up by dereferencing all objects despite having only loaded first N. Allows the attacker to make arbitrary decrefs on any kernel synchronization object, and thus can be used to get UAF. Haven&#039;t actually been tried on real HW though, but should work (tm).&lt;br /&gt;
| Kernel code execution&lt;br /&gt;
| [[2.0.0]]&lt;br /&gt;
| [[2.0.0]]&lt;br /&gt;
| &lt;br /&gt;
| April 24, 2017&lt;br /&gt;
| [[User:qlutoo|qlutoo]]&lt;br /&gt;
|-&lt;br /&gt;
| Bad irq_id check in CreateInterruptEvent&lt;br /&gt;
| CreateInterruptEvent syscall is designed to work only for irq_id &amp;gt;= 32. All irq_ids &amp;lt; 32 are &amp;quot;per-core&amp;quot; and reserved for kernel use (watchdog/scheduling/core communications).&lt;br /&gt;
On 1.0.0 you could supply irq_id &amp;lt; 32 and it would write outside the SharedIrqs table.&lt;br /&gt;
| You can register irq&#039;s in the Core3Irqs table, and thus register per-core irqs for core3, that are normally reserved for kernel. Useless.&lt;br /&gt;
| [[2.0.0]]&lt;br /&gt;
| [[2.0.0]]&lt;br /&gt;
| October 2017&lt;br /&gt;
| October 17, 2017&lt;br /&gt;
| [[User:qlutoo|qlutoo]]&lt;br /&gt;
|-&lt;br /&gt;
| Kernel .text mapped executable in usermode&lt;br /&gt;
| Prior to [[3.0.2]] the kernel .text was [[Memory_layout|mapped]] in usermode as executable. This can be used for usermode ROP for bypassing ASLR, but SVCs/IPC are not usable by running kernel .text in usermode.&lt;br /&gt;
| Executing kernel .text in usermode&lt;br /&gt;
| [[3.0.2]]&lt;br /&gt;
| [[3.0.2]]&lt;br /&gt;
| &lt;br /&gt;
| December 28, 2017 (34c3)&lt;br /&gt;
| [[User:qlutoo|qlutoo]]&lt;br /&gt;
|-&lt;br /&gt;
| Memory Controller not properly secured&lt;br /&gt;
| The Switch OS originally had the memory controller not set to be accessible only by the secure-world, which was problematic because insecure access can compromise the kernel.&lt;br /&gt;
&lt;br /&gt;
This was fixed partially in [[2.0.0]] by blacklisting the memory controller from being mapped by user-processes, and was fixed entirely in [[4.0.0]] by making the memory controller TZ-only and making all kernel accesses go through [[SMC|smcReadWriteRegister]].&lt;br /&gt;
| With some way to access the memory controller MMIO, arbitrary kernel code execution.&lt;br /&gt;
| [[4.0.0]]&lt;br /&gt;
| [[4.0.0]]&lt;br /&gt;
| January 2018&lt;br /&gt;
| January 2018&lt;br /&gt;
| [[User:SciresM|SciresM]], [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| Potential [[SVC|svcWaitForAddress]] thread use-after-free&lt;br /&gt;
| Between [[4.0.0]], where svcWaitForAddress was introduced, and [[7.0.0]], there was a second intrusive rbtree node in KThread for the WaitForAddress tree (the key being (address, priority), sorted lexicographically). Unlike the WaitProcessWideKeyAtomic tree, the kernel forgot to reinsert the WaitForAddress node when the thread&#039;s priority changed (priority inheritance and/or SetPriority), breaking the rbtree invariants; and since the kernel walks through the entire tree to remove intrusive nodes, you could cause threads to stay in the tree even after their deletion.&lt;br /&gt;
&lt;br /&gt;
[[7.0.0]] fixed the issue by using the same intrusive node for both trees. The thread/node knows which tree it is in, and the latter is correctly updated when thread priority changes.&lt;br /&gt;
| It unluckily didn&#039;t look exploitable&lt;br /&gt;
| [[7.0.0]]&lt;br /&gt;
| [[7.0.0]]&lt;br /&gt;
| July 2018&lt;br /&gt;
| February 2019&lt;br /&gt;
| [[User:TuxSH|TuxSH]]&lt;br /&gt;
|-&lt;br /&gt;
| Kernel RWX identity mapping never unmapped&lt;br /&gt;
| During init, the kernel binary is identity-mapped as RWX at 0x80060000; this is necessary to facilitate the transitionary period while the MMU is being enabled but mappings for e.g. KASLR are not yet determined, and also to enable smooth MMU enable transition during wake-from-sleep.&lt;br /&gt;
&lt;br /&gt;
However, the identity mapping was never unmapped, and thus the whole kernel code bin remained permanently mapped as RWX for all kernel threads (any thread which does not have an owner process and thus uses the KSupervisorPageTable TTBR0).&lt;br /&gt;
&lt;br /&gt;
Thus, any theoretical exploit which would give kernel memory corruption or ROP under a kernel thread would allow making use of this mapping to modify kernel text + bypass KASLR.&lt;br /&gt;
&lt;br /&gt;
This was fixed in [[16.0.0]] by unmapping the identity-mapping during init, and re identity-mapping only the very first page of kernel .text as R-X (for use by wake-from-sleep), which fixes the shellcode problem and mostly fixes the ROP problem, since this page mostly lacks interesting gadgets.&lt;br /&gt;
| In theory, with another exploitable kernel memory corruption (or ROP under kernel thread) bug: bypassing KASLR + modifying kernel .text. &lt;br /&gt;
&lt;br /&gt;
However, no such bugs are known.&lt;br /&gt;
| [[16.0.0]]&lt;br /&gt;
| [[16.0.0]]&lt;br /&gt;
| Summer 2018&lt;br /&gt;
| February 2023&lt;br /&gt;
| Everyone&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== BootImagePackage System Modules ==&lt;br /&gt;
Flaws in this category pertain to any of the [[Package2#Section_1|built-in system modules]].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Summary&lt;br /&gt;
!  Description&lt;br /&gt;
!  Successful exploitation result&lt;br /&gt;
!  Fixed in system version&lt;br /&gt;
!  Last system version this flaw was checked for&lt;br /&gt;
!  Timeframe this was discovered&lt;br /&gt;
!  Public disclosure timeframe&lt;br /&gt;
!  Discovered by&lt;br /&gt;
|-&lt;br /&gt;
| Service access control bypass (sm:h, smhax, probably other names)&lt;br /&gt;
| Prior to [[3.0.1]], the &#039;&#039;service manager&#039;&#039; (sm) built-in system module treats a user as though it has full permissions if the user creates a new &amp;quot;sm:&amp;quot; port session but bypasses [[Services_API#Initialize|initialization]]. This is due to the other sm commands skipping the service ACL check for Pids &amp;lt;= 7 (i.e. all kernel bundled modules) and that skipping the initialization command leaves the Pid field uninitialized.&lt;br /&gt;
In [[3.0.1]], sm returns error code 0x415 if [[Services_API#Initialize|Initialize]] has not been called yet.&lt;br /&gt;
| Acquiring, registering, and unregistering arbitrary services&lt;br /&gt;
| [[3.0.1]]&lt;br /&gt;
| [[3.0.1]]&lt;br /&gt;
| May 2017&lt;br /&gt;
| August 17, 2017&lt;br /&gt;
| Everyone&lt;br /&gt;
|-&lt;br /&gt;
| Overly permissive SPL service&lt;br /&gt;
| The concept behind the switch&#039;s [[SMC|Secure Monitor]] is that all cryptographic keydata is located in userspace, but stored as &amp;quot;access keys&amp;quot; encrypted with &amp;quot;keks&amp;quot; that never leave TrustZone. The [[SPL services|spl]] (&amp;quot;security processor liaison&amp;quot;?) service serves as an interface between the rest of the system and the secure monitor. Prior to [[4.0.0]], spl exposed only a single service &amp;quot;spl:&amp;quot;, which provided all TrustZone wrapper functions to all sysmodules with access to it. Thus anyone with access to the spl: service (via smhax or by pwning a sysmodule with access) could do crypto with any access keys they knew. &lt;br /&gt;
&lt;br /&gt;
This was fixed in [[4.0.0]] by splitting spl: into spl:, spl:mig, spl:ssl, spl:es, and spl:fs.&lt;br /&gt;
| Arbitrary spl: crypto with any access keys one knows. For example, one could use the SSL module&#039;s access keys to decrypt their console&#039;s SSL certificate private key without having to pwn the SSL sysmodule.&lt;br /&gt;
| [[4.0.0]]&lt;br /&gt;
| [[4.0.0]]&lt;br /&gt;
| Summer 2017 (after smhax was discovered).&lt;br /&gt;
| December 23, 2017&lt;br /&gt;
| Everyone&lt;br /&gt;
|-&lt;br /&gt;
| Single session services not really single session&lt;br /&gt;
| Several &amp;quot;critical&amp;quot; services (like fsp-ldr, fsp-pr, sm:m, etc) are meant to only ever hold a single session with a specific sysmodule. However, when a sysmodule dies, all its service session handles are released -- and thus killing the holder of a single session handle would allow one (via sm:hax etc) to get access to that service. &lt;br /&gt;
&lt;br /&gt;
This was fixed in [[4.0.0]] by adding a semaphore to these critical single-session services, so that even if one gets access to them an error code will be returned when attempting to use any of their commands.&lt;br /&gt;
| With some way to access these services and kill their session holders (like expLDR): dumping sysmodule code, arbitrary service access, elevated filesystem permissions, etc.&lt;br /&gt;
| [[4.0.0]]&lt;br /&gt;
| [[4.0.0]]&lt;br /&gt;
| May/June 2017 (basically immediately after smhax was discovered)&lt;br /&gt;
| December 30, 2017&lt;br /&gt;
| Everyone&lt;br /&gt;
|-&lt;br /&gt;
| nspwn&lt;br /&gt;
| fsp-ldr command 0 &amp;quot;MountCode&amp;quot; takes in a Content Path (retrieved from NCM by Loader), and returns an IFileSystem for the resulting ExeFS. These content paths, are normally NCAs, but MountCode also supports a number of other formats, including &amp;quot;.nsp&amp;quot; -- which is just a PFS0.&lt;br /&gt;
&lt;br /&gt;
When a path ending in &amp;quot;.nsp&amp;quot; is parsed by MountCode, the PFS0 is treated as a raw ExeFS. Because there is no NCA header, the ACID signatures are not validated -- and because there are no other signatures in a PFS0, this results in no signature checking happening at all.&lt;br /&gt;
&lt;br /&gt;
The actual .nsp handling is eventually done by {content mounting function} called by MountCode and other FS commands.&lt;br /&gt;
&lt;br /&gt;
Thus, by placing an ExeFS (NSOs + &amp;quot;main.npdm&amp;quot;) and setting one&#039;s desired title ID to &amp;quot;@Sdcard:/some_title.nsp&amp;quot; or &amp;quot;@User:/some_title.nsp&amp;quot; etc one can launch arbitrary unsigned code, with arbitrary unsigned NPDMs.&lt;br /&gt;
&lt;br /&gt;
This appears to have been fixed by only allowing .nsp when the input fstype==7 for the internal content-mounting function, returning 0x2EE202 otherwise.&lt;br /&gt;
| With access to &amp;quot;lr&amp;quot;: Arbitrary code execution with full system privileges.&lt;br /&gt;
| [[5.0.0]]&lt;br /&gt;
| [[5.0.0]]&lt;br /&gt;
| Late 2017&lt;br /&gt;
| April 23, 2018&lt;br /&gt;
| Everyone&lt;br /&gt;
|-&lt;br /&gt;
| Single null-byte stack overflow in Loader ContentPath parsing&lt;br /&gt;
| Previously, loader content path parsing looked like this, where path_from_lr was up to 0x300 bytes and not necessarily null-terminated:&lt;br /&gt;
&lt;br /&gt;
  char nca_path[0x300] = {0};&lt;br /&gt;
  strcat(nca_path, path_from_lr);&lt;br /&gt;
  for (int i = 0; nca_path[i]; i++) {&lt;br /&gt;
      if (nca_path[i] == &#039;\\&#039;) { nca_path[i] = &#039;/&#039;); }&lt;br /&gt;
  }&lt;br /&gt;
&lt;br /&gt;
Thus, a content path of the maximum length (0x300 bytes) would result in strcat writing a NULL terminator past the end of the nca_path buffer.&lt;br /&gt;
&lt;br /&gt;
This was fixed in [[6.0.0]], the new code looks like this:&lt;br /&gt;
&lt;br /&gt;
  char nca_path[0x300];&lt;br /&gt;
  strncpy(nca_path, path_from_lr, sizeof(nca_path));&lt;br /&gt;
  for (int i = 0; i  &amp;lt; sizeof(nca_path) &amp;amp;&amp;amp; nca_path[i]; i++) {&lt;br /&gt;
      if (nca_path[i] == &#039;\\&#039;) { nca_path[i] = &#039;/&#039;); }&lt;br /&gt;
  }&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| With access to &amp;quot;lr&amp;quot;: single null-byte stack overflow in Loader. Maybe (but probably not) loader code execution.&lt;br /&gt;
| [[6.0.0]]&lt;br /&gt;
| [[6.0.0]]&lt;br /&gt;
| September 2, 2018&lt;br /&gt;
| September 19, 2018&lt;br /&gt;
| [[User:SciresM|SciresM]]&lt;br /&gt;
|-&lt;br /&gt;
| System modules vulnerable to selective downgrade attacks&lt;br /&gt;
| Horizon has no mechanism for specifying the specific title version to Loader on process creation.&lt;br /&gt;
&lt;br /&gt;
Observing this, one can note that after a system update one could install a downgraded version of a specific system module (e.g. nvservices) while leaving the rest of the OS at the same version.&lt;br /&gt;
&lt;br /&gt;
Unless there was some breaking API change, this allows one to make a console vulnerable once more to an exploit in a sysmodule by downgrading it and nothing else.&lt;br /&gt;
&lt;br /&gt;
This was fixed in [[8.1.0]] by incrementing a version field in NPDM, and checking it against a hardcoded list for certain titles in Loader&#039;s process creation func.&lt;br /&gt;
| With access to content installation commands (or a vulnerable lower version to selectively install newer titles), reintroducing bugs in vulnerable system modules on newer firmware versions.&lt;br /&gt;
| [[8.1.0]]&lt;br /&gt;
| [[8.1.0]]&lt;br /&gt;
| When FIRM was first dumped in 2017.&lt;br /&gt;
| June 17, 2019&lt;br /&gt;
| Everyone&lt;br /&gt;
|-&lt;br /&gt;
| Broken RNG for [[Loader_services|Loader]] ASLR&lt;br /&gt;
| The RNG used for generating the ASLR slide is only seeded with 32bits, with the data from [[SVC|svcGetInfo]]. Hence, one could bruteforce the seed if one has infoleaks from any programs. This can be successfully bruteforced with at least 2 sample codebin addrs from different programs (with only 1 sample a lot of invalid seeds are found), however in some cases more than 1 seed might be found.&lt;br /&gt;
&lt;br /&gt;
With [15.0.0+] Loader now uses csrng_GenerateRandomBytes for determining the ASLR slide.&lt;br /&gt;
&lt;br /&gt;
See also [https://github.com/switchbrew/loader-aslr-solver loader-aslr-solver].&lt;br /&gt;
| Breaking ASLR for all non-KIP processes, allowing predicting the main-codebin base addr for all non-KIP processes until the next reboot.&lt;br /&gt;
| [[15.0.0]]&lt;br /&gt;
| [[15.0.0]]&lt;br /&gt;
| January 30, 2022 (presumably found much earlier?)&lt;br /&gt;
| October 11, 2022&lt;br /&gt;
| Everyone&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== System Modules ==&lt;br /&gt;
Flaws in this category pertain to any non-built-in system module.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Summary&lt;br /&gt;
!  Description&lt;br /&gt;
!  Successful exploitation result&lt;br /&gt;
!  Fixed in system version&lt;br /&gt;
!  Last system version this flaw was checked for&lt;br /&gt;
!  Timeframe this was discovered&lt;br /&gt;
!  Public disclosure timeframe&lt;br /&gt;
!  Discovered by&lt;br /&gt;
|-&lt;br /&gt;
| OOB Read in NS system module (pl:utoohax, pl:utonium, maybe other names)&lt;br /&gt;
| Prior to [[3.0.0]], pl:u (Shared Font services implemented in the NS sysmodule) service commands 1,2,3 took in a signed 32-bit index and returned that index of an array but did not check that index at all. This allowed for an arbitrary read within a 34-bit range (33-bit signed) from NS .bss. In [[3.0.0]], sending out of range indexes causes error code 0x60A to be returned.&lt;br /&gt;
| Dumping full NS .text, .rodata and .data, infoleak, etc&lt;br /&gt;
| [[3.0.0]]&lt;br /&gt;
| [[3.0.0]]&lt;br /&gt;
| April 2017&lt;br /&gt;
| June 19, 2017&lt;br /&gt;
| [[User:qlutoo|qlutoo]], ReSwitched Team (independently)&lt;br /&gt;
|-&lt;br /&gt;
| Unchecked domain ID in common IPC code&lt;br /&gt;
| Prior to [[2.0.0]], object IDs in [[IPC_Marshalling#Domain_message|domain messages]] are not bounds checked. This out-of-bounds read could be exploited to brute-force ASLR and get PC control in some services that support domain messages.&lt;br /&gt;
|&lt;br /&gt;
| [[2.0.0]]&lt;br /&gt;
| [[2.0.0]]&lt;br /&gt;
| July 2017&lt;br /&gt;
| July 20, 2017‎&lt;br /&gt;
| [[User:hthh|hthh]]&lt;br /&gt;
|-&lt;br /&gt;
| Out-of-bounds array read for [[BCAT_Content_Container]] secret-data index&lt;br /&gt;
| The [[BCAT_Content_Container]] secret-data index is not validated at all. This is handled before the RSA-signature(?) is ever used. Since the field is an u8, a total of 0x800-bytes relative to the array start can be accessed.&lt;br /&gt;
This is not useful since the string loaded from this array is only involved with key-generation.&lt;br /&gt;
| &lt;br /&gt;
| Unknown&lt;br /&gt;
| [[2.0.0]]&lt;br /&gt;
| August 4, 2017&lt;br /&gt;
| August 6, 2017&lt;br /&gt;
| [[User: shinyquagsire23|Shiny Quagsire]], [[User:Yellows8|yellows8]] (independently)&lt;br /&gt;
|-&lt;br /&gt;
| expLDR (sysmodule handle table exhaustion)&lt;br /&gt;
| Most sysmodules share common template code to handle IPC control messages. The command DuplicateSession (type 5 command 2)&#039;s template code will abort() if it fails to duplicate a session&#039;s handle for the requester. Because many sysmodules have limited handle table size (smaller than the browser/other entrypoints), repeatedly requesting to duplicate one&#039;s session will cause the sysmodule to run out of handle table space and abort, causing the service to release all its handles cleanly.&lt;br /&gt;
| Sysmodule crashes.  Most usefully, crashing ldr allows access to fsp-ldr and crashing pm allows access to fsp-pr. Useless after [[4.0.0]], which mitigated a number of single-session service access issues.&lt;br /&gt;
| Unfixed&lt;br /&gt;
| [[4.1.0]]&lt;br /&gt;
| June 24, 2017&lt;br /&gt;
| March 8, 2018&lt;br /&gt;
| [[User:daeken|daeken]]&lt;br /&gt;
|-&lt;br /&gt;
| Transfer Memory leak in nvservices system module&lt;br /&gt;
| The nvservices sysmodule does not clear most of its transfer memory prior to release.&lt;br /&gt;
| The calling process can read key bits of memory, including breaking ASLR (by revealing the image base) and exposing the address of other transfer memory to set up attacks. More details here: [https://daeken.svbtle.com/nintendo-switch-nvservices-info-leak transfermeme (nvservices info leak)] by [[User:daeken|daeken]]&lt;br /&gt;
| [[6.0.0]]&lt;br /&gt;
| [[6.0.0]]&lt;br /&gt;
| June 2017&lt;br /&gt;
| October 16, 2018&lt;br /&gt;
| [[User:qlutoo|qlutoo]] and [[User:hexkyz|hexkyz]],&lt;br /&gt;
[[User:daeken|daeken]] (independently)&lt;br /&gt;
|-&lt;br /&gt;
| OOB write in audio system module&lt;br /&gt;
| Prior to [[2.0.0]], the [[Audio_services#audout:u|AppendAudioOutBuffer]] and [[Audio_services#audin:u|AppendAudioInBuffer]] IPC commands would blindly increment the appended buffers&#039; count while using said count value as an index to where the user data should be copied into. This resulted in an 0x28 bytes, user controlled, out-of-bounds memory write into the [[Audio_services|audio]] sysmodule&#039;s memory space.&lt;br /&gt;
Combined with the [[Audio_services#audout:u|GetReleasedAudioOutBuffer]] or [[Audio_services#audin:u|GetReleasedAudioInBuffer]] commands, this could also be used as an 8 byte infoleak.&lt;br /&gt;
&lt;br /&gt;
In [[2.0.0]], the commands now return error code 0x1099 if the number of unreleased buffers exceeds 0x1F.&lt;br /&gt;
| Code execution under audio sysmodule&lt;br /&gt;
| [[2.0.0]]&lt;br /&gt;
| [[2.0.0]]&lt;br /&gt;
| &lt;br /&gt;
| November 2, 2018&lt;br /&gt;
| [[User:hexkyz|hexkyz]], probably others (independently).&lt;br /&gt;
|-&lt;br /&gt;
| Infoleak in nvservices system module&lt;br /&gt;
| The [[NV_services|nvservices]] ioctl [[NV_services#NVMAP_IOC_ALLOC|NVMAP_IOC_ALLOC]] takes an optional argument &amp;quot;addr&amp;quot; which allows the calling process to pass a pointer to user allocated memory for backing a nvmap object. If &amp;quot;addr&amp;quot; is left as 0, nvservices uses the transfer memory region (donated by the user during initialization) instead, when allocating memory for the nvmap object.&lt;br /&gt;
By design, freeing the nvmap object by calling the ioctl [[NV_services#NVMAP_IOC_FREE|NVMAP_IOC_FREE]] returns, in its &amp;quot;refcount&amp;quot; argument, the user address previously supplied if the reference count reaches 0.&lt;br /&gt;
However, prior to [[6.2.0]], the case where the transfer memory region is used to allocate the nvmap object was not taken into account, thus resulting in [[NV_services#NVMAP_IOC_FREE|NVMAP_IOC_FREE]] leaking back an address from within the transfer memory region mapped in nvservices&#039; memory space.&lt;br /&gt;
&lt;br /&gt;
In [[6.2.0]], [[NV_services#NVMAP_IOC_FREE|NVMAP_IOC_FREE]] no longer returns the address when the transfer memory region is used instead of user supplied memory.&lt;br /&gt;
| Combined with other vulnerabilities: Defeating ASLR in nvservices sysmodule.&lt;br /&gt;
| [[6.2.0]]&lt;br /&gt;
| [[6.2.0]]&lt;br /&gt;
| April 2017&lt;br /&gt;
| November 24, 2018&lt;br /&gt;
| Everyone&lt;br /&gt;
|-&lt;br /&gt;
| nvhax (memory corruption in nvservices system module)&lt;br /&gt;
| Prior to [[6.2.0]], the [[NV_services|nvservices]] ioctl [[NV_services#.2Fdev.2Fnvhost-ctrl-gpu|NVGPU_GPU_IOCTL_WAIT_FOR_PAUSE]] would take a single &amp;quot;pwarpstate&amp;quot; argument which would be interpreted by nvservices as a memory pointer for writing 2 &amp;quot;warpstate&amp;quot; structs (one for each Streaming Multiprocessor).&lt;br /&gt;
This resulted in nvservices attempting to blindly memcpy into this user supplied address and trigger a crash. However, if paired with an infoleak, this could be used to arbitrarily write 0x30 bytes anywhere in nvservices&#039; memory space.&lt;br /&gt;
Additionally, the &amp;quot;warpstate&amp;quot; struct itself was never initialized, which means nvservices would leak the 0x30 bytes from the stack. By invoking other ioctls it was also possible to partially control the stack contents and achieve a usable arbitrary memory write primitive.&lt;br /&gt;
&lt;br /&gt;
In [[6.2.0]], [[NV_services#.2Fdev.2Fnvhost-ctrl-gpu|NVGPU_GPU_IOCTL_WAIT_FOR_PAUSE]] now takes 2 inline &amp;quot;warpstate&amp;quot; structs instead of a &amp;quot;pwarpstate&amp;quot; pointer, thus effectively avoiding the bad memcpy.&lt;br /&gt;
| Code execution under nvservices sysmodule&lt;br /&gt;
| [[6.2.0]]&lt;br /&gt;
| [[6.2.0]]&lt;br /&gt;
| April 5, 2017&lt;br /&gt;
| November 24, 2018&lt;br /&gt;
| [[User:hexkyz|hexkyz]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Applet_Manager_services#IStorage|AM IStorage]] infoleak&lt;br /&gt;
| Originally the buffer allocated by [[Applet_Manager_services#CreateStorage|CreateStorage]] using the specified input size was not cleared. With [8.0.0+] this was fixed by adding a memset() for the buffer after successful allocation.&lt;br /&gt;
&lt;br /&gt;
Hence, IStorage-&amp;gt;IStorageAccessor-&amp;gt;Read will return uninitialized memory when the Write cmd was not previously used with the specified region.&lt;br /&gt;
| Infoleak from the main [[Applet_Manager_services#IStorage|AM]] heap, allowing defeating ASLR by reading addresses from previously allocated objects.&lt;br /&gt;
| [[8.0.0]]&lt;br /&gt;
| [[8.1.0]]&lt;br /&gt;
| December 2018&lt;br /&gt;
| August 9, 2019&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[HID_services#hid:sys|hid:sys]] ButtonConfig s32 array-index not validated&lt;br /&gt;
| The input s32 array-index for [[HID_services#hid:sys|hid:sys]] ButtonConfig cmds 1255-1270 was originally not validated. Using a negative or &amp;gt;=5 index results in accessing out-of-bounds data, with an array stored on stack.&lt;br /&gt;
[10.1.0-10.2.0] Each of these cmds will now Abort if the s32 is negative or &amp;gt;=5. [11.0.0+] Now an unsigned compare is used, with 0 or an error being immediately returned when the value is invalid.&lt;br /&gt;
| hid infoleak, out-of-bounds mem-write anywhere in hid address-space relative to the stack array (with constraints on the data).&lt;br /&gt;
| [[10.1.0]]&lt;br /&gt;
| [[11.0.1]]&lt;br /&gt;
| April 18, 2020&lt;br /&gt;
| July 14, 2020&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Bluetooth_Driver_services|Bluetooth]] sdp_server.cc process_service_search() continuation request p_req validation&lt;br /&gt;
| With [5.0.0+], the following was added to the if-block prior to loading cont_offset from p_req: &amp;lt;code&amp;gt;(p_req + sizeof(cont_offset) &amp;gt; p_req_end)&amp;lt;/code&amp;gt; (which verifies that cont_offset is within message bounds).&lt;br /&gt;
| Bluetooth-sysmodule out-of-bounds read from heap, probably not useful since the read value must match a state field, etc.&lt;br /&gt;
| [[5.0.0]]&lt;br /&gt;
| [[11.0.0]]&lt;br /&gt;
| Switch: December 2020&lt;br /&gt;
| Switch: December 25, 2020&lt;br /&gt;
| Switch: [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Bluetooth_Driver_services|Bluetooth]] A-63146698&lt;br /&gt;
| [https://android.googlesource.com/platform/system/bt/+/226ea26684d4cd609a5b456d3d2cc762453c2d75 A-63146698] / CVE-2017-0785. See also [https://info.armis.com/rs/645-PDC-047/images/BlueBorne%20Technical%20White%20Paper_20171130.pdf here].&lt;br /&gt;
| Bluetooth-sysmodule stack infoleak, which allows defeating ASLR (note: not tested on hw).&lt;br /&gt;
| [[5.0.0]]&lt;br /&gt;
| [[11.0.0]]&lt;br /&gt;
| Switch: December 2020&lt;br /&gt;
| Switch: December 25, 2020&lt;br /&gt;
| Switch: [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Bluetooth_Driver_services|bluetooth]] GetAdapterProperty/SetAdapterProperty unchecked memcpy size&lt;br /&gt;
| GetAdapterProperty copies data from stack to the output buffer using the buffer size, without checking the size (when not handling the Name type). SetAdapterProperty copies data to stack from the input buffer using the buffer size, without checking the size.&lt;br /&gt;
This requires access to the btdrv service, only hid and btm have access.&lt;br /&gt;
&lt;br /&gt;
This was fixed with [[12.0.0]] by replacing the buffer data with a fixed-size-struct.&lt;br /&gt;
| Stack infoleak with GetAdapterProperty, stack buffer overflow (and hence ROP) with SetAdapterProperty.&lt;br /&gt;
| [[12.0.0]]&lt;br /&gt;
| [[12.0.0]]&lt;br /&gt;
| July 17, 2020&lt;br /&gt;
| April 7, 2021&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Bluetooth_Driver_services|bluetooth]] stack buffer overflow with HID DATA packets&lt;br /&gt;
| The BSA (bt-stack) func bta_hh_co_data copies data from a HID DATA packet to stack without checking the size, then sends it over Uipc. [7.0.0+] The user Uipc callback also copies the input data to stack without checking the size, then sends it to the sharedmem CircularBuffer.&lt;br /&gt;
With [12.0.2+] this was fixed in bta_hh_co_data by clamping the size to a maximum of 0x2BB. The aforementioned buffer overflow in the Uipc callback can&#039;t be triggered since at that point the size was already clamped.&lt;br /&gt;
&lt;br /&gt;
Before this bta_hh_co_data func is reached, there is no validation of the size (such as comparing against the L2CAP MTU) when Basic Mode is being used.&lt;br /&gt;
&lt;br /&gt;
Actually triggering this requires using a data-size larger than the normal L2CAP MTU. This can be done by for example, using raw HCI to send the packet from the remote bluetooth device.&lt;br /&gt;
&lt;br /&gt;
Note that when the remote device is configured as an audio device for [12.0.0+] where [[Settings_services#BluetoothDevicesSettings|BluetoothDevicesSettings]].TrustedServices was only ever set for audio since system-boot, it is not possible for the remote device to connect to the Switch for HID.&lt;br /&gt;
| ROP under [[Bluetooth_Driver_services|bluetooth]] via HID DATA packet sent by a paired HID bluetooth device. This can be triggered at any time while not in sleep-mode, when not in airplane-mode. The earliest is while the Nintendo Switch logo screen is displayed during system boot.&lt;br /&gt;
| [[12.0.2]]&lt;br /&gt;
| [[12.0.2]]&lt;br /&gt;
| July-August 2020&lt;br /&gt;
| May 11, 2021&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Bluetooth_Driver_services|bluetooth]] WriteHidData/WriteHidData2/SetHidReport unchecked memcpy size&lt;br /&gt;
| WriteHidData/SetHidReport copies the input struct to stack, then passes it to the funcptr/vfunc call. WriteHidData2 passes the input buffer addr directly to the funcptr/vfunc call. The called func eventually copies the input data to the stack struct using the specified size without validating it.&lt;br /&gt;
This requires access to the btdrv service, only hid and btm have access.&lt;br /&gt;
&lt;br /&gt;
This was fixed with [[12.1.0]] in WriteHidData/SetHidReport by doing a fixed-size copy into another tmp struct, with the size field being clamped to a maximum of 0x2BB afterwards. This struct is then used when calling the vfunc. The vfuncs called by WriteHidData/WriteHidData2/SetHidReport were also updated to clamp the size to the required maximum value.&lt;br /&gt;
| Stack buffer overflow&lt;br /&gt;
| [[12.1.0]]&lt;br /&gt;
| [[12.1.0]]&lt;br /&gt;
| July 16, 2020&lt;br /&gt;
| July 6, 2021&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| Infoleak with [[HID_services|hid:sys]] SetButtonConfigStorage{name}Deprecated&lt;br /&gt;
| These cmds pass a stack ptr for the StorageName when calling the internal func. Nothing is written to this StorageName. Hence, stack infoleak (data is copied as a NUL-terminated string), which can be later read by the GetButtonConfigStorage{name} cmds.&lt;br /&gt;
&lt;br /&gt;
This was fixed by removing the Deprecated cmds in [[13.0.0]].&lt;br /&gt;
| Infoleak of hid stack from a StorageName readable via GetButtonConfigStorage{name}, up to the NUL-terminator.&lt;br /&gt;
| [[13.0.0]]&lt;br /&gt;
| [[13.0.0]]&lt;br /&gt;
| December 11, 2020&lt;br /&gt;
| September 27, 2021&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Bluetooth_Driver_services|bluetooth]] EventInfo infoleak&lt;br /&gt;
| The various funcs which send messages to the thread which handles writing to EventInfo, didn&#039;t clear the stack msgbuf. Hence, the various get-EventInfo cmds could return leaked stack data. This likely affected most (?) get-EventInfo cmds, besides CircularBuffer-GetHidReportEventInfo.&lt;br /&gt;
&lt;br /&gt;
This only matters for events where there&#039;s uninitialized regions of the EventInfo, such as events with variable-size data without a memset.&lt;br /&gt;
&lt;br /&gt;
This was fixed by clearing the msgbuf in a number of funcs.&lt;br /&gt;
| Bluetooth-sysmodule stack infoleak, which allows defeating ASLR&lt;br /&gt;
| [[13.0.0]]&lt;br /&gt;
| [[13.1.0]]&lt;br /&gt;
| &lt;br /&gt;
| During initial [[13.0.0|diff]]. Added to this page on: December 12, 2021&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[SSL_services|ssl]] CVE-2021-43527&lt;br /&gt;
| CVE-2021-43527, see also [https://bugs.chromium.org/p/project-zero/issues/detail?id=2237 here] and [https://googleprojectzero.blogspot.com/2021/12/this-shouldnt-have-happened.html here].&lt;br /&gt;
Using BigSig where the server cert sig is RSA-PSS results in the remote server throwing {no shared cipher} error when Switch connects. If however one creates a rootCA using BigSig (RSA-PSS), which then signs a server cert where the server key is RSA (not PSS), the vuln can be triggered (if the rootCA is trusted, via using the import service-cmd). It&#039;s unknown whether there&#039;s other ways to trigger the vuln.&lt;br /&gt;
&lt;br /&gt;
The crash occurs in VFY_Begin when using the previously overwritten data. A bitsize of &amp;lt;code&amp;gt;$((16384 + 32 + 64 + 64 + 64))&amp;lt;/code&amp;gt; is only enough to overwrite cx-&amp;gt;hashcx, to fully overwrite cx-&amp;gt;hashobj an additional 0xC-bytes (additional 96 bits) is needed.&lt;br /&gt;
Note that partial overwrite isn&#039;t an option: this is the func that initializes those fields to begin with, it just does deinit first before initializing hashcx/hashobj (prior to that these fields would be all-zero when not overwritten by the buf-overflow).&lt;br /&gt;
| Heap buffer overflow in [[SSL_services|ssl]], overwriting data including a ptr to an object which is later used to load a funcptr.&lt;br /&gt;
| [[13.2.1]]&lt;br /&gt;
| [[13.2.1]]&lt;br /&gt;
| Switch: December 1-2, 2021&lt;br /&gt;
| Switch: January 19, 2022&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| [[Bluetooth_Driver_services|bluetooth]] BSA gatt_process_notification stack buffer overflow&lt;br /&gt;
| gatt_process_notification is the GATT handler for processing notification/indication messages. gatt_process_notification does memcpy to stack from the input bt msg data, without size validation. The input len param isn&#039;t validated in this func either - if the remaining len following op_code is less than 2, a negative value will be used for the data copy to stack.&lt;br /&gt;
These were fixed by adding a bounds check for the size, size==0 is also checked for now.&lt;br /&gt;
| Bluetooth-sysmodule stack buffer overflow, with data received from a bluetooth message&lt;br /&gt;
| [[13.2.1]]&lt;br /&gt;
| [[13.2.1]]&lt;br /&gt;
| November 2021&lt;br /&gt;
| January 19, 2022&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Applet_Manager_services#IDisplayController|AM IDisplayController]] TakeScreenShotOfOwnLayer OOB&lt;br /&gt;
| The captureBuf is used as an array index without validation. Data used from this array includes calling a funcptr from the array entry, if set. Eventually this is also used to write bools into this array, one of which is from the command input.&lt;br /&gt;
With [5.0.0+] a func is eventually called to get a ptr determined by the input captureBuf, with nullptr being returned for captureBuf&amp;gt;=0x10. The caller will Abort if nullptr was returned.&lt;br /&gt;
| OOB array access&lt;br /&gt;
| [[5.0.0]]&lt;br /&gt;
| [[13.1.0]]&lt;br /&gt;
| ~July 31, 2019&lt;br /&gt;
| January 26, 2022&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Applet_Manager_services#IDisplayController|AM IDisplayController]] ClearCaptureBuffer OOB&lt;br /&gt;
| The captureBuf is used as an array index without proper validation. There is code validating it, but on failure it just skips over a code-block, with code using captureBuf still being used afterwards. Then this is used to write bools into a global array, one of which is from the command input.&lt;br /&gt;
This was fixed with [9.1.0+] by requiring captureBuf = 0-1.&lt;br /&gt;
| OOB bool writes into an array&lt;br /&gt;
| [[9.1.0]]&lt;br /&gt;
| [[13.1.0]]&lt;br /&gt;
| ~July 31, 2019&lt;br /&gt;
| January 26, 2022&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Sockets_services|bsdsockets]] ioctl SIOCGIFCONF infoleak&lt;br /&gt;
| Originally bsd ioctl SIOCGIFCONF was handled by setting the data in IPC outbuf0 to the size/addr of IPC outbuf1. These buffers are HipcAutoSelect, so if buf1 is small enough for HipcPointer (otherwise it would be HipcMapAlias) the IPC-buf-ptr leaked into outbuf0 would be located in the codebin-region. Since this is done before the actual ioctl-handling, it doesn&#039;t matter whether the fd is valid.&lt;br /&gt;
This was fixed in [5.0.0+] by using a tmp struct on stack instead of buf0.&lt;br /&gt;
| bsdsockets-sysmodule codebin-region addr infoleak, which allows defeating ASLR.&lt;br /&gt;
| [[5.0.0]]&lt;br /&gt;
| [[13.1.0]]&lt;br /&gt;
| February 14, 2022 (probably earlier)&lt;br /&gt;
| February 14, 2022&lt;br /&gt;
| [[User:Yellows8|yellows8]], probably others&lt;br /&gt;
|-&lt;br /&gt;
| [[Sockets_services|bsdsockets]] ioctl SIOCGIFMEDIA input can contain ptr&lt;br /&gt;
| Originally bsd ioctl SIOCGIFMEDIA used the user-specified ifmediareq structure directly from the input buffer. This includes a ptr. This ptr probably isn&#039;t actually used?&lt;br /&gt;
With [5.0.0+] the structure used as input for the ioctl was changed to using &amp;lt;code&amp;gt;int ifm_ulist[1]&amp;lt;/code&amp;gt; instead of &amp;lt;code&amp;gt;int *ifm_ulist&amp;lt;/code&amp;gt; (which is unused). The input structure is copied to a tmp struct which is used as the original ifmediareq structure, with ifm_ulist always NULL. The user can still specify a non-zero ifm_count value, however that&#039;s not useful with ifm_ulist being always NULL.&lt;br /&gt;
| Useless?&lt;br /&gt;
| [[5.0.0]]&lt;br /&gt;
| [[13.1.0]]&lt;br /&gt;
| February 14, 2022&lt;br /&gt;
| February 14, 2022&lt;br /&gt;
| [[User:Yellows8|yellows8]], probably others&lt;br /&gt;
|-&lt;br /&gt;
| Infoleak with [[Joy-Con]] HidCommand PairingIn&lt;br /&gt;
| The joycon protocol handler for PairingIn copies data from stack to the response cmd-buf for sending PairingOut. Only the first byte is set to a type value, the rest is uninitialized stack data.&lt;br /&gt;
&lt;br /&gt;
This was fixed with [15.0.0+] by directly writing to the response data without using stack data.&lt;br /&gt;
| Infoleak of hid stack via a bluetooth/uart message+response with a connected hid controller. This returns addrs for the main-codebin/stack, which allows defeating ASLR.&lt;br /&gt;
| [[15.0.0]]&lt;br /&gt;
| [[15.0.0]]&lt;br /&gt;
| September 4, 2020&lt;br /&gt;
| October 10, 2022&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| Broken RNG for [[RO_services|ro]] ASLR&lt;br /&gt;
| The RNG used to determine where to randomly map NROs in the target process was TinyMT (nn::os::detail::RngManager output, seeded by 128 bits of entropy). However, TinyMT is not cryptographically secure (and can in fact be analytically solved). &lt;br /&gt;
&lt;br /&gt;
Thus, with a few NRO mapping addresses, one could learn the TinyMT state and derive all previous/future RNG outputs, breaking NRO aslr for all processes. &lt;br /&gt;
&lt;br /&gt;
With [15.0.0+] ro now uses csrng_GenerateRandomBytes to determine the random map address for NROs.&lt;br /&gt;
| Breaking ASLR for all NROs loaded in all processes, allowing predicting all NRO mappings for all processes until the next reboot.&lt;br /&gt;
| [[15.0.0]]&lt;br /&gt;
| [[15.0.0]]&lt;br /&gt;
| Late 2021/Early 2022&lt;br /&gt;
| October 11, 2022&lt;br /&gt;
| Everyone&lt;br /&gt;
|-&lt;br /&gt;
| Broken RNG used by [[NS_Services|ns]]&lt;br /&gt;
| The code generating the sd seed and the data for the [[SD_Filesystem|sd]] private/private1 file, all use nn::os::GenerateRandomBytes, not csrng. The sd-seed is generated first, then private, then private1. This allows deriving sd-seed from private since this uses TinyMT, as long as the system shipped from factory on [2.0.0+]. private1 is only useful if the system shipped with [4.0.0+].&lt;br /&gt;
&lt;br /&gt;
There&#039;s various other code in ns using nn::os::GenerateRandomBytes as well. This includes the code generating ns_systemseed when it doesn&#039;t exist. ns_systemseed is generated at some point after the various sd-seed-related code (both are called from the same func). Hence, ns_systemseed can be recovered with the above method as well, if it wasn&#039;t recreated at some point without regenerating the above nand-save used with the above.&lt;br /&gt;
&lt;br /&gt;
With [15.0.0+] ns now uses csrng_GenerateRandomBytes for sd-seed/private and ns_systemseed, etc. This only matters when the file is newly generated, which is usually only for factory-fresh systems which ship with this version. This would also apply after being deleted during {System Settings -&amp;gt; Formatting Options -&amp;gt; Initialize Console}, and also with a refurbished console.&lt;br /&gt;
| Generation of a system&#039;s sd-seed allowing decryption of the NAX0 layer of data on [[SD_Filesystem|SD]], derived using the private file from SD. Applies to systems which factory-shipped with a system-version prior to [[15.0.0]] (that is, [2.0.0-14.1.2]).&lt;br /&gt;
| [[15.0.0]], for newly generated files&lt;br /&gt;
| [[15.0.0]]&lt;br /&gt;
| December ~12, 2021&lt;br /&gt;
| October 11, 2022&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Bluetooth_Driver_services|bluetooth]] BSA bsa_sv_av_cback stack buffer overflow&lt;br /&gt;
| bsa_sv_av_cback checks for two input type values (0xC/0xD), on match it copies the input data to stack without size validation. Then it sends an internal request with this data (likewise when the type values don&#039;t match, except the input data is passed directly with a small size), then it returns.&lt;br /&gt;
This requires the AV functionality added with [13.0.0+], however this func is only reachable with [14.0.0+] where the required functionality was enabled.&lt;br /&gt;
&lt;br /&gt;
This requires message data that&#039;s larger than the MTU, so fragmentation must be used, or manually send the ACL data to bypass the MTU.&lt;br /&gt;
&lt;br /&gt;
This can be triggered via an AVRC message with opcode=0x0 (vendor). The above type 0xC is reached via AVRC ctype 0..4, while 0xD is reached with ctype&amp;gt;=0x9.&lt;br /&gt;
&lt;br /&gt;
With [15.0.0+] the size value for the memcpy (which is also written to the request struct) is clamped to a max value.&lt;br /&gt;
| Bluetooth-sysmodule stack buffer overflow on [14.0.0-14.1.2], with data received from an AVRC bluetooth message with a bluetooth-audio device.&lt;br /&gt;
| [[15.0.0]]&lt;br /&gt;
| [[15.0.0]]&lt;br /&gt;
| November 2021&lt;br /&gt;
| October 11, 2022&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[WLAN_services|wlan]] SetMulticastList heap buffer overflow&lt;br /&gt;
| The [[WLAN_services#SetMulticastList|SetMulticastList]] command allocates a 0x31-bytes sized buffer and copies to it as much [[WLAN_services#MacAddress|MacAddress]] values from the input [[WLAN_services#MulticastList|MulticastList]] as specified by the &amp;quot;Count&amp;quot; field, but this field is never validated. &lt;br /&gt;
&lt;br /&gt;
With [15.0.0+] error code 0x1906B is now returned if &amp;quot;Count&amp;quot; is larger than 8.&lt;br /&gt;
| wlan-sysmodule heap buffer overflow.&lt;br /&gt;
| [[15.0.0]]&lt;br /&gt;
| [[15.0.0]]&lt;br /&gt;
| June 6, 2022&lt;br /&gt;
| November 9, 2022&lt;br /&gt;
| [[User:Hexkyz|hexkyz]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Bluetooth_Driver_services|bluetooth]] WriteGattCharacteristic/WriteGattDescriptor stack buffer overflow regression&lt;br /&gt;
| Originally btdrv WriteGattCharacteristic/WriteGattDescriptor (bt service LeClientWriteCharacteristic/LeClientWriteDescriptor are the same) validated the input buffer size. However the size check was removed with [12.0.0+] (which was also when bluetooth was refactored), hence stack buffer overflow. Anything with btdrv/bt services access can trigger it. While this is intended to require a BLE connection, it seems to be possible to trigger the buffer overflow without any BLE connection by passing ConnectionHandle=0xFFFFFFFF (handle not tested on hardware).&lt;br /&gt;
| Bluetooth-sysmodule stack buffer overflow on [12.0.0-15.0.1], with data from BLE IPC cmds.&lt;br /&gt;
| [[16.0.0]]&lt;br /&gt;
| [[16.0.0]]&lt;br /&gt;
| December 10, 2021&lt;br /&gt;
| February 23, 2023&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[JIT_services|JIT]] usability issues&lt;br /&gt;
| CreateJitEnvironment will enter infinite-loops using nn::jitsrv::detail::AslrAllocator::GetAslrRegion when either of the input CodeMemory sizes are zero. Also the second CodeMemory is useless for the user-process since the second addr returned by GetCodeAddress is a dup of the first one, set during state init by CreateJitEnvironment.&lt;br /&gt;
With [14.0.0+] size=0 is now properly handled, and also the state for the second addr from GetCodeAddress is now properly initialized.&lt;br /&gt;
| Minor usability issues, not useful for exploitation (size=0 will cause jit-sysmodule to hang in a loop).&lt;br /&gt;
| [[14.0.0]]&lt;br /&gt;
| [[14.0.0]]&lt;br /&gt;
| October 1, 2020&lt;br /&gt;
| February 26, 2023&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[USB_services|usbhs]] uninitialized IClientEpSession&lt;br /&gt;
| usbhs IClientIfSession OpenUsbEp creates an IClientEpSession object. The allocated object from ExpHeap is not memset, only select fields are cleared. The rest of initialization is done by PopulateRing - however the user-process could skip using that if wanted (official sw always uses it).&lt;br /&gt;
&lt;br /&gt;
ShareReportRing maps tmem and writes the ring buffer/count field into object state. PopulateRing also eventually initializes these fields, with the buffer being allocated from ExpHeap instead of tmem. These fields are not cleared during object creation from OpenUsbEp.&lt;br /&gt;
&lt;br /&gt;
GetXferReport after validating the cmd input, just uses object state assuming it was initialized. This runs code which is the same as the user-process code handling the tmem ringbuf.&lt;br /&gt;
&lt;br /&gt;
Therefore, by skipping using PopulateRing and then using GetXferReport the sysmodule will use an uninitialized ringbuf ptr, and an uninitialized count field. If one could control these fields by doing ExpHeap allocations prior to OpenUsbEp so that {target fields} would be located at {IClientEpSession ring fields}, then one could read usb-sysmodule memory at the target buffer address.&lt;br /&gt;
&lt;br /&gt;
See [[USB_services#ShareReportRing|here]] for ringbuf format. The sysmodule will Abort if read_index is &amp;gt;= {ring count field from object state}. Otherwise it copies an entry from that index to output, and updates read_index.&lt;br /&gt;
&lt;br /&gt;
This is probably tricky to abuse as the ringbuf ptr has to be valid, and {see above} (likewise for write_index when the report-ringbuf-writing func runs).&lt;br /&gt;
&lt;br /&gt;
PostBufferAsync/BatchBufferAsync also use seperate object ring fields which are left uninitialized from OpenUsbEp. Targeting this would be tricky with the ring restrictions - this would allow writing data to a ring addr however.&lt;br /&gt;
&lt;br /&gt;
Pre-4.0.0 (only 2.0.0 checked) is not affected by these. The ring fields in the object are cleared during object creation (no memset of the entire object however). GetXferReport would null-deref if PopulateRing was skipped. PostBufferAsync/BatchBufferAsync will throw an error if PopulateRing was skipped. Pre-4.0.0 also has different ring handling as well.&lt;br /&gt;
&lt;br /&gt;
[16.0.0+] The IClientEpSession init func now clears the remaining previously uninitialized fields. The cmds using the ring fields still don&#039;t check for NULL, so using GetXferReport/PostBufferAsync/BatchBufferAsync without PopulateRing will just trigger null-deref. Even if the ptr were somehow valid but ring-count field was left at 0, this would then Abort due to: &amp;lt;code&amp;gt;if (ring_count &amp;lt;= index_loaded_from_ringptr) &amp;lt;Abort&amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
| [4.0.0-15.0.1] If one can trigger using {target values} as the unintialized fields: memory reads from the target addr with GetXferReport, and memory R/W with PostBufferAsync/BatchBufferAsync. This requires access to usb:hs, and an usb device must be connected which is not being used by {other sessions}. If successful, this might (?) result in usb-sysmodule compromise.&lt;br /&gt;
| [[16.0.0]]&lt;br /&gt;
| [[16.0.0]]&lt;br /&gt;
| January 30, 2023&lt;br /&gt;
| February 26, 2023&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[NS_services|ns]] RequestMoveApplicationEntity/EstimateSizeToMove buffer overflow&lt;br /&gt;
| ns RequestMoveApplicationEntity eventually calls a func which: Loops through the input buffer. If any entry has value 6, it will call another func to copy data from state to output safely (uses the max_count param). Otherwise, it copies the input buffer to an outbuf (located on caller&#039;s stack) without any size validation (inlined memcpy), even though there is a max_count param.&lt;br /&gt;
&lt;br /&gt;
Additional memwrites are also done to the above outbuf following the initial memcopy. This can be avoided if the buffer doesn&#039;t contain bytes with values 3-6 (if using values in that range is really needed, the cmd input StorageId param can be set to the required value so that the specified value doesn&#039;t trigger the memwrite). Value 6 shouldn&#039;t be used anyway (see above).&lt;br /&gt;
&lt;br /&gt;
ns EstimateSizeToMove first calls the same func which does the copy above (outbuf is also located on stack), then it calls another func. Hence, same vuln here.&lt;br /&gt;
&lt;br /&gt;
By corrupting just the first byte of x29 with EstimateSizeToMove, one can obtain infoleaks. This method with x29 essentially only works with [15.0.0+]. Pre-15.0.0 would require a different method with partial overwrite of retaddr, however it&#039;s unknown whether this would actually work for infoleak (would require [12.0.0+] for the stack layout change).&lt;br /&gt;
With EstimateSizeToMove where x29 is overwritten, the output u64 is the leaked ptr (can be codebin-region). Note that the cmd has to return Result=0 for this to work. x29 is used to load the value which is copied to the cmdreply rawdata.&lt;br /&gt;
&lt;br /&gt;
As of [17.0.0+] an error is thrown if the input array count is larger than 8 (size of the stack dst-array).&lt;br /&gt;
| ns-sysmodule stack buffer overflow, allowing ns infoleak+ROP.&lt;br /&gt;
| [[17.0.0]]&lt;br /&gt;
| [[17.0.0]]&lt;br /&gt;
| January 2, 2023&lt;br /&gt;
| October 17, 2023&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[PSC_services|ovln:snd]] OpenSender unvalidated count&lt;br /&gt;
| ovln:snd OpenSender has a count param. This count is used to allocate the specified number of objects in a linked-list for storing the data from Send. If count is 0, the linked-list is left empty, with ptrs to itself within the ISender object.&lt;br /&gt;
&lt;br /&gt;
ISender Send when the above linked-list is empty, runs a switch-statement with &amp;lt;code&amp;gt;(inval&amp;gt;&amp;gt;8)&amp;amp;0xFF&amp;lt;/code&amp;gt;. This uses another linked-list where the ptrs are initially {within ISender obj}.&lt;br /&gt;
No space is allocated in the ISender obj for the linked-list object-data. Therefore using Send with val 1&amp;lt;&amp;lt;8 or 2&amp;lt;&amp;lt;8 (other values throw error) results in the specified input struct being copied into the ISender obj, which then overwrites heap data OOB.&lt;br /&gt;
If for example one used OpenSender again right after the first OpenSender usage, then used Send as described above, this would corrupt the second ISender which includes overwriting the vtable.&lt;br /&gt;
If one would use Send twice in a row like this, the second one would use a corrupted linked-list (written from the first Send). If the linked-list ptrs would be valid (no crash triggered) this would allow one to copy the input data to a controlled addr, though it&#039;s restricted with the linked-list usage.&lt;br /&gt;
&lt;br /&gt;
Using GetUnreceivedMessageCount afterwards is of no interest.&lt;br /&gt;
&lt;br /&gt;
Besides ovln, the only other allocs on this heap is from IPmModule Initialize. This heap is also used for psc:* services (object allocs).&lt;br /&gt;
&lt;br /&gt;
In theory (untested) it may be possible to also use this to obtain infoleaks, however it would only return the high-u32 of ptrs not the low u32. Essentially, one would trigger object allocations so that ExpHeap has layout: {ISender} -&amp;gt; {RF chunk from freeing an object} -&amp;gt; {module object from IPmModule Initialize}. Then one would use the Send vuln to corrupt the RF chunk, changing the size to a larger value. Then one would trigger an object allocation (probably same object which was previously freed), then another object for overwriting the module object (ISender would work) with ptrs at the target offsets in the module object. Then once IPmModule GetRequest is used, the returned u32s would be the high-u32 from ptrs. Due to alignment requirements with each allocation, it isn&#039;t possible to shift the allocations in order to leak ptr low-u32.&lt;br /&gt;
&lt;br /&gt;
[17.0.0+] Now throws an error if the input count for OpenSender is 0.&lt;br /&gt;
| [[PSC_services|psc]]-sysmodule heap memory corruption ([[NS_services|ns]]-sysmodule on pre-8.0.0).&lt;br /&gt;
| [[17.0.0]]&lt;br /&gt;
| [[17.0.0]]&lt;br /&gt;
| January 13, 2023&lt;br /&gt;
| October 20, 2023&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[NV_services|nv]] NVGPU_GPU_IOCTL_GET_CHARACTERISTICS Ioctl3 infoleak&lt;br /&gt;
| The handler code for NVGPU_GPU_IOCTL_GET_CHARACTERISTICS for Ioctl/Ioctl3 are essentially the same, except for the value used for the max-size clamp: Ioctl uses constant 0xA0, while Ioctl3 uses the outbuf1_size. So if one uses this with Ioctl3 and a large outbuf1, this will memcpy data OOB from the source buffer, hence infoleak.&lt;br /&gt;
With [17.0.0+] the second block of csel code which previouly essentially used the clamped size from above, was replaced with code which properly clamps to the max-size constant.&lt;br /&gt;
| nvservices-sysmodule infoleak, which allows defeating ASLR.&lt;br /&gt;
| [[17.0.0]]&lt;br /&gt;
| [[17.0.0]]&lt;br /&gt;
| February 25, 2022&lt;br /&gt;
| October 24, 2023&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Audio_services|audctl]] GetTargetDeviceInfo infoleak&lt;br /&gt;
| audctl GetTargetDeviceInfo calls an impl func with a ptr to a stackbuf, then if successful memcpys the 0x100-bytes from that buffer to output. This stackbuf is not memset. This func (after doing various state checks) copies a string to output, other than always writing a NUL-terminator there&#039;s no clearing of the buffer.&lt;br /&gt;
&lt;br /&gt;
This will leak audio-sysmodule stack into the output buffer as long as the state/input checks pass (for the remainder of the buffer following the string NUL-terminator).&lt;br /&gt;
&lt;br /&gt;
With [18.0.0+] data is written directly to the outbuf instead of the stack tmpbuf.&lt;br /&gt;
| audio-sysmodule infoleak, which allows defeating ASLR.&lt;br /&gt;
| [[18.0.0]]&lt;br /&gt;
| [[18.0.0]]&lt;br /&gt;
| December 24, 2022&lt;br /&gt;
| March 26, 2024&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Audio_services|audctl]] GetSystemInformationForDebug infoleak / buffer overflow&lt;br /&gt;
| audctl GetSystemInformationForDebug calls a func with a 0x1000-byte stack tmpbuf, then afterwards that buffer is memcpy&#039;d into the cmd outbuf. This called func doesn&#039;t clear the buffer. This func eventually uses [[BTM_services|btm]] cmd75 with outarray={global ptr} and count=10. Then if the outcount is s32 &amp;gt;=1, it loops through the output using the outcount, without validating it besides the &amp;lt;1 check. Data from that outarray is copied into the array in the func output buffer (tmpbuf above).&lt;br /&gt;
&lt;br /&gt;
With btm comprimised, one could return a large output count and trigger a stack buffer overflow with data following that global array, however exploiting this would be difficult since that data would be uncontrolled (can&#039;t directly control it from this cmd at least).&lt;br /&gt;
&lt;br /&gt;
A stack infoleak can be obtained with this as well (assuming the above output array isn&#039;t full).&lt;br /&gt;
&lt;br /&gt;
Even though the name has &amp;quot;ForDebug&amp;quot;, there&#039;s no checks which would trigger an error / return early (this also always returns 0).&lt;br /&gt;
&lt;br /&gt;
[18.0.0+] now clears the output buffer, and also now prints strings into the buffer instead of writing binary data (overflow no longer possible).&lt;br /&gt;
| audio-sysmodule infoleak, which allows defeating ASLR. Also audio-sysmodule memory corruption, likely not useful unless there&#039;s a way to control the data.&lt;br /&gt;
| [[18.0.0]]&lt;br /&gt;
| [[18.0.0]]&lt;br /&gt;
| December 7, 2022&lt;br /&gt;
| March 27, 2024&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Migration_services|migration]] nn::migration::savedata::IServer cmd1 buffer overflow&lt;br /&gt;
| nn::migration::savedata::IServer cmd1 with [18.0.0-18.0.1] copies data from an array to the output ptr. As the output is an u64 field for the IPC cmd output, this is a field on stack. Hence, if more than 1 entry (8-bytes) are copied a stack buffer overflow will occur. Note that cmd3 loads the same data, except this has a proper output array.&lt;br /&gt;
It&#039;s unknown whether there&#039;s a way to actually control this data with a large enough enough size.&lt;br /&gt;
&lt;br /&gt;
See [[18.1.0]] for the diff/fix.&lt;br /&gt;
| [[Migration_services|migration]] stack buffer overflow, only on [18.0.0-18.0.1].&lt;br /&gt;
| [[18.1.0]]&lt;br /&gt;
| [[18.1.0]]&lt;br /&gt;
| June 11, 2024&lt;br /&gt;
| June 11, 2024&lt;br /&gt;
| [[User:Yellows8|yellows8]] (sysupdate diff)&lt;br /&gt;
|-&lt;br /&gt;
| [[SSL_services|ssl]] broken RNG&lt;br /&gt;
| [[SSL_services|ssl]] uses nn::os::GenerateRandomBytes, but not [[SPL_services|spl]] GenerateRandomBytes. See the RNG entries elsewhere. This is used to seed the NSS global RNG (drbg.c, RNG_GenerateGlobalRandomBytes etc).&lt;br /&gt;
&lt;br /&gt;
If one could somehow determine the data which was returned by nn::os::GenerateRandomBytes during seeding (which is likely difficult), the global RNG would be broken.&lt;br /&gt;
&lt;br /&gt;
With [19.0.0+] nn::os::GenerateRandomBytes usage was replaced with [[SPL_services|spl]] GenerateRandomBytes.&lt;br /&gt;
| Breaking [[SSL_services|ssl]] global RNG -&amp;gt; potentially predict RNG data (keys(?)) during TLS comms.&lt;br /&gt;
| [[19.0.0]]&lt;br /&gt;
| [[19.0.0]]&lt;br /&gt;
| December 14, 2021&lt;br /&gt;
| October 8, 2024&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Audio_services|audren]] uncleared TransferMemory&lt;br /&gt;
| audren OpenAudioRenderer uses the input tmem as workmem. The IAudioRenderer dtor doesn&#039;t clear the workmem properly. Depending on input params, certain objects stored here have vtables - hence infoleak.&lt;br /&gt;
The exact location in the workmem will vary depending on the input params - these objects are dynamically allocated in the workmem.&lt;br /&gt;
The following will leak vtables: Sink, Effect.&lt;br /&gt;
&lt;br /&gt;
If the initialization func fails, the tmem is unmapped without clearing it first. It&#039;s unknown whether there&#039;s a way to actually trigger an infoleak with this however. With [19.0.0+] it&#039;s now cleared on failure.&lt;br /&gt;
&lt;br /&gt;
With [19.0.0+] the dtor now clears the workmem when needed.&lt;br /&gt;
| Reading leaked data/ptrs from TransferMemory -&amp;gt; defeating ASLR in [[Audio_services|audio]]-sysmodule.&lt;br /&gt;
| [[19.0.0]]&lt;br /&gt;
| [[19.0.0]]&lt;br /&gt;
| December 17, 2022&lt;br /&gt;
| October 13, 2024&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Audio_services|audren]] UpdateMixes OOB mem-copy&lt;br /&gt;
| With nn::audio::server::InfoUpdater::UpdateMixes when nn::audio::server::BehaviorInfo::IsMixInParameterDirtyOnlyUpdateSupported() returns true (requires REV7, which is [7.0.0+]), the mix_id from user input is used without validation as input to &amp;lt;code&amp;gt;&amp;lt;nn::audio::server::MixContext::GetInfo(int) const&amp;gt;&amp;lt;/code&amp;gt;, instead of the counter from the for-loop. This allows one to control the destination MixInfo index which the user-input data is written into. If too large, this will trigger OOB data-copy. Note that the u8 at dest_MixInfo+12 must be non-zero.&lt;br /&gt;
Also note that a field is loaded from dest_MixInfo which is used as a splitter_id, so splitters need to be initialized where count is large enough for that id.&lt;br /&gt;
&lt;br /&gt;
With [19.0.0+] after getting the mix_id (loop-index/input) it now does: &amp;lt;code&amp;gt;if (mix_id &amp;lt; 0 || mix_id &amp;gt;= nn::audio::server::MixContext::GetCount()) continue;&amp;lt;/code&amp;gt;&lt;br /&gt;
| OOB mem-copy in [[Audio_services|audio]]-sysmodule, which for example can be used to overwrite a vtable used immediately after UpdateMixes.&lt;br /&gt;
| [[19.0.0]]&lt;br /&gt;
| [[19.0.0]]&lt;br /&gt;
| December 19, 2022&lt;br /&gt;
| October 13, 2024&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Bus_services|sasbus]] StartPeriodicReceiveMode infoleak&lt;br /&gt;
| StartPeriodicReceiveMode writes a vtable ptr into the mapped tmem at +0. The tmem is mapped RW in the user-process. There is no clearing of tmem during tmem cleanup. Hence, the user-process can read the tmem to obtain a Bus-sysmodule codebin-region infoleak. This vtable-ptr seems to be unused - it&#039;s also empty after the first two entries (stubbed incref/decref).&lt;br /&gt;
[20.0.0+] Removed the vtable ptr, with data intended for the user-process being moved from tmem+0x8 to +0x0. Also, instead of calling memset, funcs are called for manually clearing tmem.&lt;br /&gt;
| Bus-sysmodule infoleak, which allows defeating ASLR.&lt;br /&gt;
| [[20.0.0]]&lt;br /&gt;
| [[20.0.0]]&lt;br /&gt;
| February 22, 2022&lt;br /&gt;
| May 3, 2025&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[NFC_services|nfc]] SendCommandByPassThrough buffer overflow&lt;br /&gt;
| SendCommandByPassThrough eventually copies the input buffer into a fixed-size heap buffer, without size validation.&lt;br /&gt;
This was fixed with [20.0.0+] by clamping the size.&lt;br /&gt;
| nfc-sysmodule heap buffer overflow.&lt;br /&gt;
| [[20.0.0]]&lt;br /&gt;
| [[20.0.0]]&lt;br /&gt;
| Late November 2021&lt;br /&gt;
| May 3, 2025&lt;br /&gt;
| [[User:Yellows8|yellows8]] (maybe others?)&lt;br /&gt;
|-&lt;br /&gt;
| [[HID_services|hidbus]] EnableJoyPollingReceiveMode infoleak&lt;br /&gt;
| The tmem initialized by hidbus EnableJoyPollingReceiveMode contains a vtable ptr (tmem+0x10), hence infoleak. With [20.0.0+] the vtable ptr write was removed, and tmem is now memset starting at tmem+0x10 instead of +0x20.&lt;br /&gt;
| hid-sysmodule infoleak, which allows defeating ASLR.&lt;br /&gt;
| [[20.0.0]]&lt;br /&gt;
| [[20.0.0]]&lt;br /&gt;
| March 2020&lt;br /&gt;
| May 4, 2025&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[SSL_services|ssl]] Certificate verification bypass&lt;br /&gt;
| The ssl sysmodule keeps a list of trusted certificates, that are imported by an app with ImportServerPki. During certificate verification, if the certificate that is provided by the server has the same subject key id as a trusted certificate, the certificate is accepted, even if self-signed. A blog post about this vulnerability can be found [https://reversing.live/sslbypass.html here].&lt;br /&gt;
| Man-in-the-middle for any connection that uses ImportServerPki.&lt;br /&gt;
| [[20.2.0]]&lt;br /&gt;
| [[20.2.0]]&lt;br /&gt;
| June 6, 2025&lt;br /&gt;
| August 8, 2025&lt;br /&gt;
| [https://github.com/kinnay Yannik]&lt;br /&gt;
|-&lt;br /&gt;
| [[LDN_services|ldn]] AdvertiseData OOB-memcpy with EncryptionType3 (AES-128-GCM) actionframes (ldnhax)&lt;br /&gt;
| The ldn action-frame parser object for AES-128-GCM (used with [[LDN_services|EncryptionType3]]), when it does validation once finished, only verifies that the sizes are within bounds of the input buffer. There&#039;s no validation against constants, which the other EncryptionType objects have. The caller code doesn&#039;t validate the size either.&lt;br /&gt;
&lt;br /&gt;
[21.0.0+] Now validates the advert-size with sizeof(NetworkInfo.AdvertiseData).&lt;br /&gt;
&lt;br /&gt;
For more details see [https://gist.github.com/yellows8/16bb56343d085d2db2ab0adc5d4cef99 here].&lt;br /&gt;
| Compromise of ldn starting from OOB-memcpy, even on S2: stack infoleak (ASLR defeat), arbitrary memory read/write (which also allows handle-leak), vfunc-calls with arbitrary [[Security_Mitigations|vtable]].&lt;br /&gt;
| [[21.0.0]]&lt;br /&gt;
| [[21.0.0]]&lt;br /&gt;
| June ~13, 2025&lt;br /&gt;
| November 11, 2025&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[HID_services|hid:dbg]] AttachHdlsVirtualDevice unvalidated DeviceTypeInternal&lt;br /&gt;
| hid:dbg AttachHdlsVirtualDevice eventually passes the input from HdlsDeviceInfo into a func without any validation. The DeviceTypeInternal field is used as the index for loading a ptr from a global array. The only validation occurs when the loaded ptr is NULL - this is just for initializing the ptr in the array when it&#039;s not already set.&lt;br /&gt;
&lt;br /&gt;
Since the highest DeviceTypeInternal is value 30, using &amp;gt;=31 will load an OOB ptr. This ptr is written to state, and also immediately passed to a called func. As long as ptr is valid it should be fine with this func.&lt;br /&gt;
&lt;br /&gt;
This functionality is also used eventually by ApplyHdlsNpadAssignmentState and ApplyHdlsStateList.&lt;br /&gt;
&lt;br /&gt;
It&#039;s unknown whether there&#039;s a way to exploit this. Also note that hid:dbg is not normally accessible to retail titles.&lt;br /&gt;
&lt;br /&gt;
[21.0.0+] Arrayindex=0 is now used when the input is invalid.&lt;br /&gt;
| Likely useless, even if reachable?&lt;br /&gt;
| [[21.0.0]]&lt;br /&gt;
| [[21.0.0]]&lt;br /&gt;
| June 3, 2024 (possibly eariler(?))&lt;br /&gt;
| November 14, 2025&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Bluetooth_Driver_services|bluetooth]] BSA allowed ATT MTU is too large&lt;br /&gt;
| GATT-handler stack buffer overflows with a large input size are only possible if the payload_size (MTU) field in state is large enough. gatt_client_handle_server_rsp/gatt_server_handle_client_req will drop messages where the size is &amp;gt;= payload_size (though unless the request opcode matches certain values it will also send an error-response for invalid-PDU). Both of these handle updating this field when needed, however that&#039;s handled properly.&lt;br /&gt;
&lt;br /&gt;
With bluetooth-classic via L2CAP, a hard-coded MTU of 0x205 is sent in the configure request. However the code handling received configure requests will set payload_size to 0x2A0 if no MTU is specified, or the input MTU if it&#039;s within range 0x30..0x2A0. Hence, sending data large enough for buffer overflows requires bluetooth-classic via L2CAP + manually sending large ACL data.&lt;br /&gt;
&lt;br /&gt;
[15.0.0+] gatt_l2cif_config_ind_cback which handles the received configure-requests with bluetooth-classic mentioned above, now uses MTU range 0x30..0x205 with the default MTU being 0x205. It is therefore no longer possible to trigger the previously mentioned buffer-overflows with bluetooth-classic.&lt;br /&gt;
| Stack buffer overflows in bluetooth-sysmodule due to the allowed MTU for ATT being larger than the stack data.&lt;br /&gt;
| [[15.0.0]]&lt;br /&gt;
| [[20.0.0]]&lt;br /&gt;
| November 2021?&lt;br /&gt;
| November 26, 2025&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Bluetooth_Driver_services|bluetooth]] BSA gatt_process_prep_write_rsp stack buffer overflow&lt;br /&gt;
| BSA gatt_process_prep_write_rsp memcpys to stack without size validation (the input len param which is subtracted to determine the copy-size is also unvalidated). Triggering this is only possible if the system sent ATT_PREPARE_WRITE_REQ, and then received ATT_PREPARE_WRITE_RSP with a large size.&lt;br /&gt;
&lt;br /&gt;
The size used with memcpy is (u16)(insize-4), so when insize is less than 4 the copy size will be {negative value masked to u16}. This will therefore eventually crash when the stacktop is reached during memcpy.&lt;br /&gt;
&lt;br /&gt;
[15.0.0+] Paritially fixed due to corrected MTU handling (doesn&#039;t apply to negative-copysize). [21.0.0+] Fully fixed with proper size validation.&lt;br /&gt;
| Stack buffer overflow in bluetooth-sysmodule when the required ATT messages are sent/received.&lt;br /&gt;
| [[21.0.0]]&lt;br /&gt;
| [[21.0.0]]&lt;br /&gt;
| November 2021?&lt;br /&gt;
| January 19, 2026&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[NFC_services|nfc]] Initialize buffer overflow&lt;br /&gt;
| All Initialize* cmds for nn::nfc::detail::IUser (nfc:user), nn::nfc::detail::ISystem (nfc:sys), nn::nfp::detail::IUser (nfp:user), nn::nfp::detail::ISystem (nfp:sys), nn::nfp::detail::IDebug (nfp:dbg), nn::nfc::mifare::detail::IUser (nfc:mf:u): these copy the input array into _this, without validating the array count.&lt;br /&gt;
The data is copied to obj_impl+0x8+0x28, with each entry being 0x20-bytes. The event handle returned by AttachAvailabilityChangeEvent is at obj_impl+0x8+0xB8+0x14 (Same with nfc/nfp interfaces). This therefore means +0xA4 in the input buffer will overwrite the handle returned by that cmd, allowing one to leak any handle with the specified value. This can be done with count=0x6. The object is large enough that this count will only overwrite data within the current object. However during the dtor it will use ptrs which were corrupted with this (located before the event), so one must avoid closing the session unless the input data included valid ptrs.&lt;br /&gt;
&lt;br /&gt;
This can be exploited by just using a 0xC0-byte (array_count=0x6) input buffer with Initialize where each u32 is the target nfc handle value, then using cmd GetAvailabilityChangeEventHandle to leak the handle.&lt;br /&gt;
&lt;br /&gt;
[22.0.0+] This was fixed by clamping the count to a maximum of 0x4.&lt;br /&gt;
| OOB datacopy into object state. Allows leaking arbitary [[NFC_services|handles]], including on [S2] (such as process-handle, sm, fsp-srv (remaining services can also be used via sm)).&lt;br /&gt;
| [[22.0.0]]&lt;br /&gt;
| [[22.0.0]]&lt;br /&gt;
| November 2021&lt;br /&gt;
| March 17, 2026&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Internet Browser == &lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
!  Summary&lt;br /&gt;
!  Description&lt;br /&gt;
!  Successful exploitation result&lt;br /&gt;
!  Fixed in system version&lt;br /&gt;
!  Last system version this flaw was checked for&lt;br /&gt;
!  Timeframe this was discovered&lt;br /&gt;
!  Public disclosure timeframe&lt;br /&gt;
!  Discovered by&lt;br /&gt;
|-&lt;br /&gt;
| CVE-2016-4657&lt;br /&gt;
| WebKit vuln discovered around August 2016. Most notably used in the iOS 9.3.X exploit. A simple PoC can be found [https://github.com/LiveOverflow/lo_nintendoswitch/blob/master/poc1.html here]. This was later exploited by [https://twitter.com/qwertyoruiopz Qwertyoruiop] using an adjusted version of his iOS 9.3 webkit exploit (others exploited this prior to then).&lt;br /&gt;
|&lt;br /&gt;
| [[2.1.0]]&lt;br /&gt;
| [[2.0.0]]&lt;br /&gt;
| Original: August 2016&lt;br /&gt;
Switch: March 3rd-4th 2017&lt;br /&gt;
|&lt;br /&gt;
| Everyone&lt;br /&gt;
|-&lt;br /&gt;
| CVE-2017-7005&lt;br /&gt;
| WebKit type confusion.&lt;br /&gt;
|&lt;br /&gt;
| [[3.0.1]]&lt;br /&gt;
| [[3.0.1]]&lt;br /&gt;
|&lt;br /&gt;
| &lt;br /&gt;
| Everyone&lt;br /&gt;
|-&lt;br /&gt;
| CVE-2016-4622&lt;br /&gt;
| WebKit memory corruption bug. This bug was incorrectly re-introduced in [[4.0.0]]. See [http://www.phrack.org/papers/attacking_javascript_engines.html here] for a detailed write-up from the author.&lt;br /&gt;
|&lt;br /&gt;
| [[6.1.0]]&lt;br /&gt;
| [[6.1.0]]&lt;br /&gt;
|&lt;br /&gt;
| &lt;br /&gt;
| Everyone&lt;br /&gt;
|-&lt;br /&gt;
| CVE-2018-4441&lt;br /&gt;
| WebKit memory corruption bug. See [https://bugs.chromium.org/p/project-zero/issues/detail?id=1685&amp;amp;desc=2 here].&lt;br /&gt;
|&lt;br /&gt;
| [[7.0.0]]&lt;br /&gt;
| [[7.0.0]]&lt;br /&gt;
| &lt;br /&gt;
|&lt;br /&gt;
| Everyone&lt;br /&gt;
|-&lt;br /&gt;
| Web-applets OpenSSL broken RNG&lt;br /&gt;
| [[SPL_services|csrng]] access was added to web-applets with [12.1.0+]. Prior to that, csrng and nn::os::GenerateRandomBytes were not used (besides sdk heap code).&lt;br /&gt;
nn::os::GetSystemTick is used to seed the OpenSSL RNG, among other data. Hence, it&#039;s probably (?) possible to bruteforce the RNG initial state, allowing predicting RNG output.&lt;br /&gt;
&lt;br /&gt;
The RNG code is wkcRandomNumbersPeer (peer_wkc nro), with the initialization code using GetSystemTick located in the func immediately before wkcGetTickCountPeer. The former is called from wkcOsslRandFilefReadPeer. wkcOsslRandFilefReadPeer is called for seeding the OpenSSL RNG.&lt;br /&gt;
&lt;br /&gt;
With [12.1.0+], wkcRandomNumberPeer/wkcRandomNumbersPeer wrap nn::os::GenerateRandomBytes. wkcCryptographicallyRandomValuesPeer was added which wraps nn::crypto::GenerateCryptographicallyRandomBytes. wkcOsslRandFilefReadPeer now calls nn::crypto::GenerateCryptographicallyRandomBytes instead of wkcRandomNumbersPeer.&lt;br /&gt;
| Breaking web-applets OpenSSL RNG -&amp;gt; potentially predict RNG data (keys(?)) during TLS comms.&lt;br /&gt;
| [[12.1.0]]&lt;br /&gt;
| [[12.1.0]]&lt;br /&gt;
| January 28, 2022&lt;br /&gt;
| October 8, 2024&lt;br /&gt;
| [[User:Yellows8|yellows8]], likely (?) others&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Whitelist ===&lt;br /&gt;
This section documents [[Internet_Browser|WebApplet]] whitelist issues in applications. These can be used to load your own browser content over plain HTTP, which then for example could be used for web-applet exploitation.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
!  Application&lt;br /&gt;
!  Description&lt;br /&gt;
!  Fixed with app version&lt;br /&gt;
!  Newest app version this flaw was checked for&lt;br /&gt;
!  Timeframe this was discovered&lt;br /&gt;
!  Public disclosure timeframe&lt;br /&gt;
!  Discovered by&lt;br /&gt;
|-&lt;br /&gt;
| Sonic Mania&lt;br /&gt;
| Originally this game launched web-applet with a plain-http URL for displaying the manual, this was later changed to https. Originally the whitelist only had 1 entry for a http URL, this was later replaced with various https-only URLs.&lt;br /&gt;
| 1.04, unknown if fixed with an earlier update&lt;br /&gt;
| 1.04&lt;br /&gt;
| January (?) 2022&lt;br /&gt;
| February 23, 2022&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| ぷよぷよ™テトリス®Ｓ (JPN Puyo Puyo Tetris)&lt;br /&gt;
| The JPN Tetris game/demo can be used to launch the online-WebApplet.&lt;br /&gt;
&lt;br /&gt;
First, launch the offline-WebApplet for the manual:&lt;br /&gt;
* Game: Main-menu -&amp;gt; press A with the already selected top menu button -&amp;gt; press the R button.&lt;br /&gt;
* Demo: Main-menu -&amp;gt; select menu button on the right side -&amp;gt; press A.&lt;br /&gt;
&lt;br /&gt;
Then in the manual:&lt;br /&gt;
* Press A -&amp;gt; select the bottom menu entry in the list.&lt;br /&gt;
* Select the SEGA icon -&amp;gt; press A.&lt;br /&gt;
&lt;br /&gt;
This will then trigger launching the online-WebApplet with the plain-http &amp;lt;nowiki&amp;gt;&amp;quot;http://sega.jp/&amp;quot;&amp;lt;/nowiki&amp;gt; URL.&lt;br /&gt;
&lt;br /&gt;
With game-update v1.1.3 the whitelist no longer allows plain-http. The plain-http links appear to have been changed to https.&lt;br /&gt;
| 1.1.3&lt;br /&gt;
| 1.1.3&lt;br /&gt;
| 2017&lt;br /&gt;
| 2017&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== NintendoSDK ==&lt;br /&gt;
This section documents vulnerabilities for NSOs in NintendoSDK.&lt;br /&gt;
&lt;br /&gt;
=== nnSdk ===&lt;br /&gt;
This section documents vulnerabilities for nnSdk (sdknso).&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Summary&lt;br /&gt;
!  Description&lt;br /&gt;
!  Successful exploitation result&lt;br /&gt;
!  Fixed in SDK [[System_Versions|version]]&lt;br /&gt;
!  Last SDK version this flaw was checked for&lt;br /&gt;
!  Timeframe this was discovered&lt;br /&gt;
!  Public disclosure timeframe&lt;br /&gt;
!  Discovered by&lt;br /&gt;
|-&lt;br /&gt;
| [[HID_services|hidbus]] GetJoyPollingReceivedData buffer overflow&lt;br /&gt;
| hidbus GetJoyPollingReceivedData doesn&#039;t validate the u8 size used for memcpy, when copying the data to the output JoyPollingReceivedData. With 11.x, the size is now clamped to a maximum of 0x2C (regardless of polling-mode). Note that 0x2C is the data-size for JoyButtonOnlyPollingDataAccessor, the other polling-modes have a smaller size.&lt;br /&gt;
&lt;br /&gt;
The hid-sysmodule code which writes data here does handle it properly: size is clamped to a max size, and the data-read uses a fixed-size anyway (hence there&#039;s no way to trigger this sdknso vuln with the hid-sysmodule tmem writing code).&lt;br /&gt;
&lt;br /&gt;
This could only be exploited if one directly writes to the tmem when one has previously compromised hid-sysmodule, without using the normal tmem-writing func for this.&lt;br /&gt;
&lt;br /&gt;
There are only a few [[HID_services#ExternalDevices|apps]] which use hidbus.&lt;br /&gt;
| Triggering a buffer overflow in an application which uses hidbus GetJoyPollingReceivedData, from a previously compromised hid-sysmodule.&lt;br /&gt;
| 11.x.0&lt;br /&gt;
| 11.4.0&lt;br /&gt;
| March 2020&lt;br /&gt;
| December 3, 2020&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| [[Profile_Selector|Profile Selector]] uninitialized input data&lt;br /&gt;
| Originally unused regions of [[Profile_Selector]] UiSettings/UserSelectionSettings were not cleared prior to being sent to the applet. With 1.x.x these are now properly memset().&lt;br /&gt;
| Stack infoleak from user-process, sent to the applet.&lt;br /&gt;
| 1.x.x&lt;br /&gt;
| 11.4.0&lt;br /&gt;
| November-December 2019&lt;br /&gt;
| December 31, 2020&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== NEX ===&lt;br /&gt;
This section documents client-side vulnerabilities for [https://github.com/Kinnay/NintendoClients/wiki/NEX-Overview-(Game-Servers) NEX].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Summary&lt;br /&gt;
!  Description&lt;br /&gt;
!  Successful exploitation result&lt;br /&gt;
!  Fixed in version&lt;br /&gt;
!  Timeframe this was discovered&lt;br /&gt;
!  Public disclosure timeframe&lt;br /&gt;
!  Discovered by&lt;br /&gt;
|-&lt;br /&gt;
| Buffer overflow in StringConversion::T2Char8&lt;br /&gt;
| StringConversion::T2Char8 is used to convert IP addresses from a platform-specific encoding to UTF-8. On the 3DS and Switch, the implementation is simply a strcpy. By sending a long IP address string, a buffer overflow can be triggered on the stack. The vulnerability can be triggered through the NAT traversal protocol. A blog post about this vulnerable can be found [https://reversing.live/hacking-hundreds-of-wii-us-at-once.html here].&lt;br /&gt;
| Stack overflow in any game that uses NEX for matchmaking&lt;br /&gt;
| Fixed server-side&lt;br /&gt;
| December, 2022&lt;br /&gt;
| May, 2024&lt;br /&gt;
| [https://github.com/kinnay Yannik]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Pia ===&lt;br /&gt;
This section documents vulnerabilities for [https://github.com/Kinnay/NintendoClients/wiki/Pia-Overview Pia].&lt;br /&gt;
&lt;br /&gt;
In v5.11.3 (exact starting version unknown) the fixes aren&#039;t present for the below vulns which were fixed in v5.9.3, while in v5.18.98 these are present (exact starting version unknown). This probably indicates that the vuln fixes were backported from a newer Pia version to v5.9.3.&lt;br /&gt;
&lt;br /&gt;
The Pia packet handlers are only active when the game is using multiplayer. LanProtocol is only active in the games which are actively using the LAN-mode option (not Ldn) - only certain games support LAN-mode. The LanProtocol Pia packet handler can be reached while in a lobby or searching for one.&lt;br /&gt;
&lt;br /&gt;
Most Pia packets require an active StationProtocol connection to be active with {InetAddr which the packet was received from}, otherwise the packet is filtered out. The only protocols which don&#039;t use filtering are the following: NatTraversalProtocol, LanProtocol, StationProtocol, LocalProtocol.&lt;br /&gt;
&lt;br /&gt;
Note that broadcast IP-dest Pia packets are accepted - this can be used to target every device on the network which is using Pia (which is really only useful with {above protocols} due to the filtering mentioned above, unless one also handles StationProtocol).&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Summary&lt;br /&gt;
!  Description&lt;br /&gt;
!  Successful exploitation result&lt;br /&gt;
!  Fixed in Pia version&lt;br /&gt;
!  Last Pia version this flaw was checked for&lt;br /&gt;
!  Timeframe this was discovered&lt;br /&gt;
!  Public disclosure timeframe&lt;br /&gt;
!  Discovered by&lt;br /&gt;
|-&lt;br /&gt;
| nn::pia::session::RelayRouteManageJob::UpdateConnectionReport buffer overflow&lt;br /&gt;
| nn::pia::session::RelayRouteManageJob::UpdateConnectionReport() checks that the input size is at least {value}, but there&#039;s no max size check. This is used to memcpy from the input to elsewhere - hence buf-overflow if size is too large. The dst buffer is allocated on the pead heap - this buffer is probably small.&lt;br /&gt;
Note that there&#039;s various requirements before it would actually reach the memcpy, such as &amp;lt;code&amp;gt;&amp;lt;nn::pia::session::Mesh::IsHost() const&amp;gt;&amp;lt;/code&amp;gt; must return true.&lt;br /&gt;
&lt;br /&gt;
This is called from nn::pia::session::MeshProtocol::ParseConnectionReport().&lt;br /&gt;
&lt;br /&gt;
ParseConnectionReport uses a state ptr for object nn::pia::session::RelayRouteManageJob, it will return if not set. nn::pia::session::Mesh::Initialize handles setup for this, depending on an input field from nn::pia::session::Mesh::Setting. These settings originate from &amp;lt;code&amp;gt;&amp;lt;nn::pia::session::Session::CreateInstance(nn::pia::session::Session::Setting const&amp;amp;)&amp;gt;&amp;lt;/code&amp;gt;, which is called by user-code with the needed settings.&lt;br /&gt;
ParseConnectionReport is therefore only usable if the game explicitly enables the Relay functionality.&lt;br /&gt;
&lt;br /&gt;
In fixed versions immediately after the StationIndex validation it now does: &amp;lt;code&amp;gt;if(statefield+0x10&amp;lt;input_size) return;&amp;lt;/code&amp;gt;&lt;br /&gt;
| Heap buffer overflow triggered by a Pia MeshProtocol message sent to a host device.&lt;br /&gt;
| v5.9.3, see above.&lt;br /&gt;
| v5.9.1/v5.9.2/v5.9.3&lt;br /&gt;
| November 11, 2022&lt;br /&gt;
| November 15, 2022&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| nn::pia::lan::LanProtocol::ParseSessionMessage buffer overflow&lt;br /&gt;
| nn::pia::lan::LanProtocol::ParseSessionMessage() calls nn::pia::lan::LanSessionMessage::Deserialize() to deserialize the message payload data buffer into the LanSessionMessage object on stack. LanSessionMessage::Deserialize (among other things) memcpys data from the input buffer to the object, using an u32 from the input buffer - there is no size validation in Deserialize itself.&lt;br /&gt;
There is a size check immediately after calling Deserialize() to verify &amp;lt;code&amp;gt;payloadsize=={u32val}+{constant}&amp;lt;/code&amp;gt;, returning on fail - but this doesn&#039;t matter for too-large-size.&lt;br /&gt;
&lt;br /&gt;
In fixed versions Deserialize now does bounds checking, both for the minimum message size and clamping the memcpy size to a constant. An error is thrown if the clamped memcpy size is larger than the message size. The caller now checks the ret properly, previously it was ignored.&lt;br /&gt;
&lt;br /&gt;
Following the size check in ParseSessionMessage() it calls &amp;lt;code&amp;gt;&amp;lt;nn::pia::session::Mesh::IsProcessingLeaveMesh() const&amp;gt;&amp;lt;/code&amp;gt;, returning if ret is false.&lt;br /&gt;
&lt;br /&gt;
Then it calls nn::pia::lan::LanProtocol::ReceivedFragmentData::Receive(), with the memcpy&#039;d buffer/size from the above LanSessionMessage, and other fields from LanSessionMessage. This eventually memcpys the input buffer to object+{offset}+{chunksize_field}*inputu8, there is no validation for size or inputu8 (except for the above size check). Hence, if the u8 is large enough, this would result in a heap buffer overflow.&lt;br /&gt;
&lt;br /&gt;
In fixed versions ReceivedFragmentData::Receive added a bunch of validation before the memcpy.&lt;br /&gt;
| Stack/heap buffer overflow triggered by a Pia LanProtocol message.&lt;br /&gt;
| v5.9.3, see above.&lt;br /&gt;
| v5.9.1/v5.9.2/v5.9.3&lt;br /&gt;
| November 14, 2022&lt;br /&gt;
| November 15, 2022&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| nn::pia::session::SessionProtocol::ParseLeaveMeshInvitation buffer overflow&lt;br /&gt;
| &amp;lt;code&amp;gt;&amp;lt;nn::pia::session::SessionProtocol::ParseLeaveMeshInvitation(nn::pia::transport::ReceivedMessageAccessor const&amp;amp;)&amp;gt;&amp;lt;/code&amp;gt; This immediately returns if *(ReceivedMessageAccessor+16) is 0. Then the input data is deserialized. The input u64 array is deserialized to stack, the u8 arraycount field from input is not validated.&lt;br /&gt;
&lt;br /&gt;
Hence, stack buffer overflow. Note that there&#039;s similar loop code in nearby funcs, which do validate the count properly.&lt;br /&gt;
&lt;br /&gt;
In fixed versions the arraycount field is now validated.&lt;br /&gt;
&lt;br /&gt;
SessionProtocol uses ReliableSlidingWindow MessageHeader, with a maximum message size of 0x100. The allocated size used for the above u64 array is also 0x100-bytes. Hence, when triggering a buf overflow the data after the buffer is uncontrolled data from the SessionProtocol object.&lt;br /&gt;
| Stack buffer overflow triggered by a Pia SessionProtocol message.&lt;br /&gt;
| v5.9.3, see above.&lt;br /&gt;
| v5.9.1/v5.9.2/v5.9.3&lt;br /&gt;
| November 14, 2022&lt;br /&gt;
| November 15, 2022&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| Optional Pia packet encryption&lt;br /&gt;
| Pia packet encryption is optional. If the encryption flag is disabled, the packet handler will accept it and skip crypto.&lt;br /&gt;
In fixed versions immediately after grabbing a packet, it now checks the crypto flag. If it&#039;s plaintext the packet is dropped.&lt;br /&gt;
&lt;br /&gt;
This can be used to send a plaintext Pia packet without needing to handle encryption, especially useful if the session-key can&#039;t be obtained (online-play matchmaking). This could be combined with other vulns if wanted.&lt;br /&gt;
| Sending a plaintext Pia packet without needing to handle encryption.&lt;br /&gt;
| v5.9.3, see above.&lt;br /&gt;
| v5.9.3 (and later versions)&lt;br /&gt;
| &lt;br /&gt;
| November 19, 2022&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| nn::pia::session::{JoinMeshJob/ProcessUpdateMeshJob}::SetStationDataList OOB read/write/vfunc-call&lt;br /&gt;
| &amp;lt;code&amp;gt;nn::pia::session::JoinMeshJob::SetStationDataList&amp;lt;/code&amp;gt;is called by &amp;lt;code&amp;gt;nn::pia::session::MeshProtocol::ParseJoinResponse(nn::pia::transport::ReceivedMessageAccessor const&amp;amp;)&amp;gt;&amp;lt;/code&amp;gt; with the ReceivedMessageAccessor buffer.&lt;br /&gt;
SetStationDataList will update state and immediately return if the join was denied. It will also validate the num_mesh_stations field against state. ParseJoinResponse also essentially verifies that the message was received from the host device.&lt;br /&gt;
&lt;br /&gt;
The input buffer size is ignored.&lt;br /&gt;
&lt;br /&gt;
The num_fragments field must be value 1 or &amp;lt;=3 otherwise it will return, there&#039;s two seperate code blocks handling these.&lt;br /&gt;
&lt;br /&gt;
Other than the checks at the start, there&#039;s no validation for the index fields. So large enough values could result in OOB-reads.&lt;br /&gt;
&lt;br /&gt;
When handling multiple fragments, it will loop through the stationinfo list. There is no validation for the u8 count field or the baseindex field. It calls a vfunc from obj baseptr+index*{entrysize} with data from the buffer, where index starts with the above baseindex field. Afterwards, an u8 is copied into an u32 array (with certain versions an u16 is deserialized into an u16 array).&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;nn::pia::session::ProcessUpdateMeshJob::UpdateStationDataList&amp;lt;/code&amp;gt; is (eventually) called from &amp;lt;code&amp;gt;nn::pia::session::MeshProtocol::ParseUpdateMesh&amp;lt;/code&amp;gt;, which has similar issues to the above.&lt;br /&gt;
&lt;br /&gt;
Note that ParseJoinResponse/ParseUpdateMesh essentially require the message to be received from the host device.&lt;br /&gt;
&lt;br /&gt;
With fixed versions (v5.18.98, exact version unknown) various validation was added. Additional/updated validation was added in a later version (v5.31.0, exact version unknown).&lt;br /&gt;
| OOB read/write / vfunc call where the object is selected by an OOB index, triggered by a Pia MeshProtocol message.&lt;br /&gt;
| v5.18.98 and v5.31.0 (exact versions unknown).&lt;br /&gt;
| v5.31.0&lt;br /&gt;
| November 18, 2022&lt;br /&gt;
| November 21, 2022&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| Insecure encryption&lt;br /&gt;
| Originally Pia packets used AES-ECB encryption. As documented [https://github.com/Kinnay/NintendoClients/wiki/Pia-Overview here] it was later changed with v5.7.0 to AES-GCM. Each 0x10-byte block would have the same encrypted block output where the plaintext 0x10-byte data is the same.&lt;br /&gt;
The mechanism for generating the Pia SessionKey for LAN has also changed over time.&lt;br /&gt;
&lt;br /&gt;
The [https://github.com/Kinnay/NintendoClients/wiki/LAN-Protocol LAN] non-Pia-encapsulated packets were also originally sent in plaintext, however at some point it was changed to mostly encrypted.&lt;br /&gt;
| &lt;br /&gt;
| AES-GCM fix: v5.7.0&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| nn::pia::transport::UnreliableProtocol::Dispatch buffer overflow&lt;br /&gt;
| &amp;lt;code&amp;gt;nn::pia::transport::UnreliableProtocol::Dispatch&amp;lt;/code&amp;gt; memcpys data from the message into a list entry, without size validation. If the pia packet is the max size, it will only overwrite the 0xC-bytes which were written to immediately before the memcpy: the u32 size and the 8-byte StationAddress (depending on the version there can also be 4-byte padding after the size for alignment).&lt;br /&gt;
However, nn::pia::transport::UnreliableProtocol::Receive will clamp the size from the list entry to the outbuf size when doing the memcpy. So this is probably useless.&lt;br /&gt;
&lt;br /&gt;
It&#039;s unknown whether there&#039;s a version where more data could be overwritten, and whether that would be useful.&lt;br /&gt;
&lt;br /&gt;
This is fixed in v5.31.0, exact version unknown. The message is dropped if too large in Dispatch.&lt;br /&gt;
| Small buffer overflow triggered by a Pia UnreliableProtocol message.&lt;br /&gt;
| v5.31.0, exact version unknown.&lt;br /&gt;
| v5.18.98/v5.31.0&lt;br /&gt;
| November 2022&lt;br /&gt;
| November 29, 2022&lt;br /&gt;
| [[User:Yellows8|yellows8]]&lt;br /&gt;
|-&lt;br /&gt;
| Uncleared input structs for [[LDN_services|LDN]]&lt;br /&gt;
| The Pia code using ldn CreateNetwork*/ConnectNetwork*/Scan doesn&#039;t properly memset the input data for SecurityConfig/ScanFilter (when keysize is less than 0x40 for the former). Hence, infoleak from games is sent to ldn (structs are located on stack, so stack data is leaked). This requires ldn compromise/mitm to obtain the leaked data - these are not sent over the network.&lt;br /&gt;
With v6.20.1 (exact version unknown - fix isn&#039;t present in v5.32.0), the code using Scan* now clears the input ScanFilter properly. With v6.25.1 (exact version unknown - fix isn&#039;t present in v6.23.3), the code using CreateNetwork*/ConnectNetwork* now clears the input SecurityConfig properly.&lt;br /&gt;
| Infoleak from games with LDN cmds, requires compromised sysmodule/mitm.&lt;br /&gt;
| v6.20.1 and v6.25.1, exact versions unknown.&lt;br /&gt;
| v5.32.0/v6.20.1/v6.23.3/v6.25.1&lt;br /&gt;
| &lt;br /&gt;
| December 7, 2022&lt;br /&gt;
| &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== ENL ===&lt;br /&gt;
This section documents vulnerabilities for [https://github.com/kinnay/NintendoClients/wiki/ENL-Protocol ENL].&lt;br /&gt;
A framework used by Nintendo games including Mario Kart 8 Deluxe, Splatoon 2 / 3, Mario Maker 2, and more.&lt;br /&gt;
&lt;br /&gt;
Fun fact, this library appears to re-use network code and concepts from older Nintendo titles such as Mario Kart 7 and some Wii multiplayer games.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!  Summary&lt;br /&gt;
!  Description&lt;br /&gt;
!  Successful exploitation result&lt;br /&gt;
!  Fixed in Enl version&lt;br /&gt;
!  Last Enl version this flaw was checked for&lt;br /&gt;
!  Timeframe this was discovered&lt;br /&gt;
!  Public disclosure timeframe&lt;br /&gt;
!  Discovered by&lt;br /&gt;
|-&lt;br /&gt;
| enl::TransportManager::updateReceiveBuffer_() nullptr deref&lt;br /&gt;
| enl::TransportManager::updateReceiveBuffer_() is called when the ENL framework receives a PIA packet from a client, it will fully trust the ENL header which includes a &amp;quot;ContentTransporter&amp;quot; type (ID) and a length.&lt;br /&gt;
The function will try to fetch the content transporter by ID using &amp;lt;code&amp;gt;enl::TransportManager::getContentTransporter(unsigned char const &amp;amp;)&amp;lt;/code&amp;gt;, it returns NULL if there&#039;s no content transporter with the same ID&lt;br /&gt;
&lt;br /&gt;
*NOTE: The function may be inlined&lt;br /&gt;
&lt;br /&gt;
Then it will try to call a virtual method: &amp;lt;code&amp;gt;virtual size_t readyReceiveStream(enl::RamReadStream&amp;amp;, enl::Buffer*, size_t)&amp;lt;/code&amp;gt;, dereferencing the pointer to fetch the vtable ptr&lt;br /&gt;
&lt;br /&gt;
[https://gist.github.com/Rambo6Glaz/c088e2ed7a12db08f6322e9f7a3c4911 Pseudocode of the function before it was fixed]&lt;br /&gt;
&lt;br /&gt;
| nullptr dereference triggered by an invalid content transporter type in the ENL header (it will crash the game/process)&lt;br /&gt;
| Unknown&lt;br /&gt;
| Depends on the game&lt;br /&gt;
| Early April 2022&lt;br /&gt;
| November 16, 2022&lt;br /&gt;
| [[User:Rambo6Glaz|Rambo6Glaz]], [https://github.com/kinnay Yannik] (massive RE help)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
There&#039;s another one more interesting but it will have to wait a bit :)&lt;br /&gt;
&lt;br /&gt;
== Games ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Game&lt;br /&gt;
!  Summary&lt;br /&gt;
!  Description&lt;br /&gt;
!  Impact&lt;br /&gt;
!  Fixed in version&lt;br /&gt;
!  Timeframe this was discovered&lt;br /&gt;
!  Public disclosure timeframe&lt;br /&gt;
!  Discovered by&lt;br /&gt;
|-&lt;br /&gt;
| Mario Kart World&lt;br /&gt;
| ASLR leak in application data&lt;br /&gt;
| A memory address can be leaked by changing your username to something short, and hosting a network session in LAN mode (press L + R + Left Stick on the main menu to enable this). The memory address can be found in bytes 12 - 19 of the application data that is transmitted in response to a browse request.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note:&#039;&#039;&#039; there is more uninitialized data in the packet, but the memory address is probably the most interesting part. The vulnerability was fixed by clearing the application data with zeros, before filling in the information.&lt;br /&gt;
&lt;br /&gt;
[https://hackerone.com/reports/3463719 HackerOne report]&lt;br /&gt;
&lt;br /&gt;
This stack infoleak was also present in the [[LDN_services|ldn]] AdvertiseData.&lt;br /&gt;
| A memory address can leaked (this is a requirement for many types of attacks).&lt;br /&gt;
| 1.5.0&lt;br /&gt;
| December 12, 2025&lt;br /&gt;
| February 19, 2026&lt;br /&gt;
| [https://github.com/kinnay Yannik], yellows8 (ldn)&lt;br /&gt;
|-&lt;br /&gt;
| Splatoon 3&lt;br /&gt;
| Anticheat Seed Randomization Weakness&lt;br /&gt;
| This oversight of seed generation would allow an attacker to quickly compute all code hashes, and modify game code, while still producing a valid ch1 hash.&lt;br /&gt;
&lt;br /&gt;
[https://hackerone.com/reports/3042475 HackerOne report]&lt;br /&gt;
| Allows an attacker to bypass the ch1 anti-cheat hashing mechanism.&lt;br /&gt;
| 10.0.0&lt;br /&gt;
| March 17, 2025&lt;br /&gt;
| February 19, 2026&lt;br /&gt;
| hana2736&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Yellows8</name></author>
	</entry>
	<entry>
		<id>https://switchbrew.org/w/index.php?title=Switch_2:_Title_list/Games&amp;diff=14820</id>
		<title>Switch 2: Title list/Games</title>
		<link rel="alternate" type="text/html" href="https://switchbrew.org/w/index.php?title=Switch_2:_Title_list/Games&amp;diff=14820"/>
		<updated>2026-07-24T22:41:35Z</updated>

		<summary type="html">&lt;p&gt;Yellows8: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The Id listed by eShop-data for Upgrade Packs for Nintendo Switch 2 Edition is DLC for the base NX Application: the Id is [[NACP|AddOnContentBaseId]] + index, like other DLC.&lt;br /&gt;
&lt;br /&gt;
= Applications / Games =&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot;&lt;br /&gt;
! ApplicationId || Description || Region || Minimum Required OS || Distribution Method || Versions || Notes || Type&lt;br /&gt;
|-&lt;br /&gt;
| 040003901FBC2000 || Survival Kids || CHN EUR JPN KOR USA || || Digital || || [[Shared_Database_services#FunctionBlackList|ApplicationUpdateRequired]] = v0. || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04000470212CE000 || Kunitsu-Gami: Path of the Goddess || CHN EUR JPN KOR USA || || Digital || || [[Shared_Database_services#FunctionBlackList|ApplicationUpdateRequired]] = v0. || Game&lt;br /&gt;
|-&lt;br /&gt;
| 040029A01D3E0000 || Nintendo GameCube™ – Nintendo Classics || EUR KOR USA || || Digital || || || Application&lt;br /&gt;
|-&lt;br /&gt;
| 0400303021AAC000 || DELTARUNE || EUR JPN USA || || Digital || || || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04003DC020784000 || シャインポスト Be Your アイドル！ || JPN || || Digital || || [[Shared_Database_services#FunctionBlackList|ApplicationUpdateRequired]] = v0. || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04003FB022F4E000 || RAIDOU Remastered: The Mystery of the Soulless Army || EUR USA || || Digital || || [[Shared_Database_services#FunctionBlackList|ApplicationUpdateRequired]] = v0. || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400CE7022F4A000 || RAIDOU Remastered: The Mystery of the Soulless Army || JPN || || Digital || || [[Shared_Database_services#FunctionBlackList|ApplicationUpdateRequired]] = v0. || Game&lt;br /&gt;
|-&lt;br /&gt;
| 040041601D83A000 || Drag x Drive™ || CHN EUR JPN KOR USA || || Digital || || || Game&lt;br /&gt;
|-&lt;br /&gt;
| 040041E0212AE000 || Fast Fusion || EUR JPN USA || || Digital || || || Game&lt;br /&gt;
|-&lt;br /&gt;
| 040047D020DB2000 || Puyo Puyo Tetris 2S || CHN EUR JPN KOR USA || || Digital || || [[Shared_Database_services#FunctionBlackList|ApplicationUpdateRequired]] = v0. || Game&lt;br /&gt;
|-&lt;br /&gt;
| 040052E01D3DA000 || Nintendo GameCube™ – Nintendo Classics || CHN JPN || || Digital || || || Application&lt;br /&gt;
|-&lt;br /&gt;
| 040057C02159A000 || Nintendo Switch 2 Welcome Tour || CHN EUR JPN KOR USA || || Digital || || || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04005C902322C000 || No Sleep For Kaname Date - From AI: THE SOMNIUM FILES || EUR USA || || Digital || || [[Shared_Database_services#FunctionBlackList|ApplicationUpdateRequired]] = v0. || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04008980227DC000 || DRAGON QUEST XI S: Echoes of an Elusive Age - Definitive Edition || EUR KOR USA || || Digital || || || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400DCC0223F8000 || No Sleep For Kaname Date - From AI: THE SOMNIUM FILES || JPN || || Digital || || [[Shared_Database_services#FunctionBlackList|ApplicationUpdateRequired]] = v0. || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400E32022656000 || ドラゴンクエストXI　過ぎ去りし時を求めて S || JPN || || Digital || || [[Shared_Database_services#FunctionBlackList|ApplicationUpdateRequired]] = v0. || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04006CC0223D2000 || HITMAN World of Assassination – Signature Edition || CHN EUR JPN KOR USA || || Digital || || [[Shared_Database_services#FunctionBlackList|ApplicationUpdateRequired]] = v0. || Game&lt;br /&gt;
|-&lt;br /&gt;
| 040074A01BF12000 || Donkey Kong Bananza || CHN EUR JPN KOR USA || 19.1.0 (update-partition) || Digital || || || Game&lt;br /&gt;
|-&lt;br /&gt;
| 040077201BE50000 || Kirby™ Air Riders || CHN EUR JPN KOR USA || || Digital || || || Game&lt;br /&gt;
|-&lt;br /&gt;
| 040078001CCF6000 || Street Fighter 6 || CHN EUR JPN KOR USA || || Digital || || [[Shared_Database_services#FunctionBlackList|ApplicationUpdateRequired]] = v0. || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04007EF01F8AE000 || Fire Emblem™: Fortune’s Weave || EUR JPN KOR USA || || Digital / Cartridge || || || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400813022B32000 || Fortnite || CHN EUR JPN KOR USA || || Digital || || || Game&lt;br /&gt;
|-&lt;br /&gt;
| 040082902313C000 || Arcade Archives 2 RIDGE RACER || CHN EUR JPN KOR USA || || Digital || || || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04009570209F8000 || Hogwarts Legacy || CHN EUR JPN KOR USA || || Digital || || [[Shared_Database_services#FunctionBlackList|ApplicationUpdateRequired]] = v0. || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400959022CA2000 || || || || || || [[Shared_Database_services#FunctionBlackList|ApplicationUpdateRequired]] = v0. || &lt;br /&gt;
|-&lt;br /&gt;
| 0400A4802437E000 || Drag x Drive™: Global Jam || CHN EUR JPN KOR USA || || Digital || || || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400A940233E0000 || Daemon X Machina: Titanic Scion || USA || || Digital || || || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400408021236000 || Daemon X Machina: Titanic Scion || JPN KOR || || Digital || || [[Shared_Database_services#FunctionBlackList|ApplicationUpdateRequired]] = v0. || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400BA202340A000 || Daemon X Machina: Titanic Scion || EUR || || Digital || || || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400BBB020FF0000 || Yakuza 0 Director’s Cut || CHN EUR JPN KOR USA || || Digital || || [[Shared_Database_services#FunctionBlackList|ApplicationUpdateRequired]] = v0. || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400BE601F38A000 || EA SPORTS Madden NFL 26 || CHN EUR JPN KOR USA || || Digital || || || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400C3F00006E000 || Mario Kart World || CHN EUR JPN KOR USA || 19.1.0 (update-partition) || Digital / Cartridge || || || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400CA40208C8000 || Split Fiction || CHN EUR JPN KOR USA || || Digital || || [[Shared_Database_services#FunctionBlackList|ApplicationUpdateRequired]] = v0. || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400CBA0221EA000 || BRAVELY DEFAULT FLYING FAIRY HD Remaster || EUR USA || || Digital || || [[Shared_Database_services#FunctionBlackList|ApplicationUpdateRequired]] = v0. || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400DC401FCE6000 || BRAVELY DEFAULT FLYING FAIRY HD Remaster || JPN KOR || || Digital || || [[Shared_Database_services#FunctionBlackList|ApplicationUpdateRequired]] = v0. || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400D9E02053C000 || NOBUNAGA&#039;S AMBITION: Awakening Complete Edition || EUR USA || || Digital || || || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04009DE020850000 || NOBUNAGA&#039;S AMBITION: Awakening Complete Edition || JPN || || Digital || || [[Shared_Database_services#FunctionBlackList|ApplicationUpdateRequired]] = v0. || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400DDB020648000 || Cyberpunk 2077: Ultimate Edition || CHN EUR KOR USA || || Digital || || || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04000FC022CC8000 || Cyberpunk 2077: Ultimate Edition || JPN || || Digital || || || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400E140216D4000 || SONIC X SHADOW GENERATIONS || CHN EUR JPN KOR USA || || Digital / Game Key Card || || [[Shared_Database_services#FunctionBlackList|ApplicationUpdateRequired]] = v0. || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400E23021102000 || WILD HEARTS S || CHN EUR JPN KOR USA || || Digital || || [[Shared_Database_services#FunctionBlackList|ApplicationUpdateRequired]] = v0. || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400E88025B1A000 || Star Fox™ || EUR JPN KOR USA || 21.2.0 (update-partition) || Digital / Cartridge || || || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400EBD0236AE000 || Tony Hawk&#039;s™ Pro Skater 3 + 4 || CHN EUR JPN USA || || Digital || || [[Shared_Database_services#FunctionBlackList|ApplicationUpdateRequired]] = v0. || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400F4E022F4C000 || || || || || || [[Shared_Database_services#FunctionBlackList|ApplicationUpdateRequired]] = v0. || &lt;br /&gt;
|-&lt;br /&gt;
| 0400F6D020A02000 || Suikoden I&amp;amp;II HD Remaster for Nintendo Switch 2: Gate Rune and Dunan Unification Wars || CHN EUR JPN KOR USA || || Digital || || [[Shared_Database_services#FunctionBlackList|ApplicationUpdateRequired]] = v0. || Game&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 04001BD027712000 || Vampire Crawlers: The Turbo Wildcard from Vampire Survivors || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400A95026AB2000 || Alien: Rogue Incursion Evolved Edition || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400E5502720C000 || Truxton Extreme || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400F9E025342000 || Bubsy 4D || CHN EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 040091C0232EE000 || Persona 3 Reload || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400380020056000 || Splatoon Raiders || CHN EUR JPN KOR USA || 22.1.0 (update-partition) || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 040045F02661E000 || Mixtape || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04002FC02493E000 || Outbound || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400AC8025344000 || Total Chaos || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04006020233D4000 || MARVEL Cosmic Invasion || EUR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400C76024710000 || PRAGMATA || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400912023308000 || Goat Simulator 3 || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04007CF02469A000 || Console Archives Ishin no Arashi || EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400E98025DE4000 || OPUS: Prism Peak || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04007FD027916000 || Police Simulator: Patrol Officers  || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400160026F40000 || Arcade Archives 2 KONAMI GT || EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400E070279B6000 || Amnesia: Rebirth || CHN EUR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400C460219B2000 || EA SPORTS FC™ 26 || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04000E1023AB4000 || Bandit Trap || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400172024E7A000 || Overwatch® || EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400D28024076000 || Call of the Elder Gods || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400B3402468C000 || Console Archives SEICROSS || EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04000D0027188000 || Arcade Archives 2 POLARIS || EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400C11023B5A000 || Indiana Jones and the Great Circle™ || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400BE70262DA000 || System Shock || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04004890268C0000 || THE NEW DENPA MEN || JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04002550248C4000 || Content Warning || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04000A3024F22000 || Darwin&#039;s Paradox! || EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400E570261A2000 || South of Midnight Weaver&#039;s Edition || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400A86024AF6000 || MotoGP™26 || EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400304025212000 || WWE 2K26 Standard Edition || EUR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400CF702589C000 || Warframe || JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400817025C2C000 || The Midnight Walk || EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 040048C027456000 || Dread Delusion || EUR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400FF902081C000 || Apex Legends™ || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 040080D0277C6000 || Haste || CHN EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400D09026580000 || AFL 26 || EUR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400245021D2C000 || Yoshi and the Mysterious Book || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400322024480000 || Virtua Fighter 5 R.E.V.O. World Stage || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400D9E01D3E6000 || Pokémon Winds || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 040046201D3E8000 || Pokémon Waves || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 040062C02722A000 || Super Meat Boy 3D || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400D8D02466E000 || Console Archives TERRA CRESTA || EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400A62026C7E000 || Arcade Archives 2 FINAL LAP || EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 040094B02455C000 || MOUSE: P.I. For Hire || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400A79026B36000 || Kena: Bridge of Spirits || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 040069E024F5A000 || Deadzone: Rogue || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400984020BE8000 || eFootball™ Kick-Off! || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 040092E026C70000 || Bluey&#039;s Quest For The Gold Pen || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400557024B3E000 || Under Par Golf Architect || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04000D9025B16000 || Minecraft Dungeons II || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400EE2024E98000 || Denshattack! || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400135024684000 || Console Archives Ninja-Kid II || EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400F16026F62000 || Arcade Archives 2 DEVASTATORS || EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 040042E02684C000 || Dosa Divas || EUR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400EF4026274000 || Snoopy &amp;amp; The Great Mystery Club || EUR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400B20025A70000 || Tomb Raider I-III Remastered || CHN EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400B1E02610C000 || People of Note || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04006F70246E2000 || Console Archives SONIC WINGS Special || EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400327026C56000 || Arcade Archives 2 PLUMP POP || EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400A02022D2A000 || Two Point Museum || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400D1E0237CC000 || Monster Hunter Stories 3: Twisted Reflection || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400A3A0269E6000 || Citadelum || CHN EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400F12025CCC000 || Shadow Tactics: Blades of the Shogun - Aiko&#039;s Choice || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400A2B02653E000 || Starship Troopers: Ultimate Bug War! || EUR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04005CB027440000 || Royal Revolt Survivors || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400054025D02000 || Rushing Beat X: Return of Brawl Brothers || EUR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04000EE026672000 || Arcade Archives 2 Rave Racer || EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400C470236D6000 || FULL METAL SCHOOLGIRL || JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04005550254B8000 || FATAL FRAME II: Crimson Butterfly REMAKE　  || EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400125024470000 || Console Archives NOBUNAGA&#039;S AMBITION || EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 040055202608A000 || Back to the Dawn || CHN JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400A3A01EE4C000 || Pokémon Pokopia || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04006D1023DB6000 || Rotwood || CHN EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400C18025BBA000 || Blue Prince || EUR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04005290268BE000 || SUSHI BAR MOEBIUS for Nintendo Switch™ 2 || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04003A4026868000 || City Hunter || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 040029202747A000 || Balatro || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400207026A48000 || Arcade Archives 2 ADVENTURE CANOE || EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04005870238DA000 || The Duskbloods || EUR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04005E2024678000 || Console Archives Dezaemon || EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 040078D025266000 || Exit Lab ~15 Rooms~ || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400410024C4E000 || High On Life 2 || CHN EUR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 040051B0269D8000 || Arcade Archives 2 MEGA ZONE || EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 040073D025D98000 || Scott Pilgrim EX || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04008BE0262BC000 || FINAL FANTASY VII REBIRTH || EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400D4201C6EA000 || Mario Tennis Fever || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400617024E42000 || DYNASTY WARRIORS: ORIGINS || EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 040076E025B46000 || Star Trek: Voyager - Across the Unknown || CHN EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 040037C025346000 || PGA TOUR 2K25 || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400B6302227E000 || The Adventures of Elliot: The Millennium Tales || EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400472025966000 || Arcade Archives 2 TOP SPEED || EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 040032B023CA4000 || Orbitals || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 040093D0233B0000 || FINAL FANTASY VII REMAKE INTERGRADE || EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400F1C021178000 || Granblue Fantasy: Relink - Endless Ragnarok || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400B7A02454A000 || Fallout 4: Anniversary Edition || CHN EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04006C5025F8A000 || Digimon Story Time Stranger || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400528024B30000 || Console Archives NINJA GAIDEN II: THE DARK SWORD OF CHAOS || EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400360024B26000 || Console Archives Cool Boarders || EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04003170238F0000 || Valheim || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400A15024D62000 || Turok: Origins || CHN EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 040096D024506000 || TOKYO SCRAMBLE || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400114025CCA000 || Shadow Tactics: Blades of the Shogun || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400A58024718000 || Resident Evil Requiem || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 040021E02594A000 || The Disney Afternoon Collection || EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04004F70262B2000 || Draw King || JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400E380261E2000 || Arcade Archives 2 QUESTER || EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04000B0024B12000 || UNDERWARD: LASTBOSS, Genius Gyaru Doctor || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 040036E024882000 || Yakuza Kiwami 3 &amp;amp; Dark Ties || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04002D602483C000 || &amp;quot;Run for Money&amp;quot;: Hunter VS Runner! Which Side Will You Win With!? || JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04004A00263D6000 || Arcade Archives 2 LABYRINTH RUNNER || EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04000E9024DDA000 || Ys X: Proud Nordics || EUR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400AEE0246B0000 || POOL ROOM BILLIARD || CHN JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400994022308000 || Little Nightmares Enhanced Edition - Complete Edition || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400F23024BDE000 || Carmageddon: Rogue Shift || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04008A9025E38000 || Arcade Archives 2 BOMB JACK TWIN || EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04000A8024AEE000 || GRID™ Legends: Deluxe Edition || CHN EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400B4B021792000 || REANIMAL || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04000DE025BF6000 || Arcade Archives 2 SPACE INVADERS PART II || EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400FF8023CF0000 || They are Billions || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400CB3024EF8000 || Suika Game Planet || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400D1C026514000 || Tombi! Special Edition || EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04005CC022C9E000 || DRAGON QUEST VII Reimagined || EUR JPN USA ||  || Digital ||  || [[Shared_Database_services#FunctionBlackList|ApplicationUpdateRequired]] = v0. || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04004A1024BD6000 || MIO: Memories in Orbit || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400473025B00000 || Arcade Archives 2 SPACE INVADERS || EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 040045B025E5A000 || Layers of Fear: The Final Masterpiece Edition || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04001040243D4000 || The Legend of Heroes: Trails beyond the Horizon || EUR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400152025A96000 || Arcade Archives 2 THE OUTFOXIES || EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400018025B92000 || Arcade Archives 2 ROC&#039;N ROPE || EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 040003C023FC4000 || LEGO® Batman™: Legacy of the Dark Knight || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400256024344000 || Gear.Club Unlimited 3 || CHN EUR KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 040026802427E000 || The Rogue Prince of Persia™ || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400255025990000 || Ultimate Sheep Raccoon || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04008C6024BB4000 || The Elder Scrolls V: Skyrim Anniversary Edition || CHN EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04007E00249C2000 || Skate Story || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04009B9023ABC000 || Yooka-Replaylee || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400FED0215A4000 || Star Wars Outlaws Gold Edition || CHN EUR JPN KOR USA ||  || Digital ||  || [[Shared_Database_services#FunctionBlackList|ApplicationUpdateRequired]] = v0. || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04007A7024024000 || Warhammer 40,000: Rogue Trader || CHN EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400C45026074000 || Tombi! 2: The Evil Swine Return Special Edition || EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400AE40256CE000 || RippleIsland Kyle and Cal’s Restaurant || EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04002310235C2000 || Handy Hockey || JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400D30025242000 || Arcade Archives 2 BOMB BEE || EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04004800254A6000 || PUNYAN for Nintendo Switch 2 || CHN JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 040065A023ABA000 || ChromaGun 2: Dye Hard || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400668024E94000 || Squirrel with a Gun || EUR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04008150213A2000 || Assassin&#039;s Creed Shadows || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400FDB022B7C000 || Tomb Raider: Definitive Edition || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04008430258C6000 || Arcade Archives 2 GALACTIC WARRIORS || EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400890023806000 || OCTOPATH TRAVELER 0 || JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400DA10226BE000 || NBA 2K26 || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400412024EB4000 || Nicktoons &amp;amp; The Dice of Destiny || EUR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400255024C1C000 || Arcade Archives 2 TOKYO WARS || EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04003F40232DE000 || Hyrule Warriors: Age of Imprisonment || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400DB8025084000 || Arcade Archives 2 SCION || EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04000220234BA000 || DRAGON QUEST I &amp;amp; II HD-2D Remake || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400B78024F7E000 || Resident Evil Village Gold Edition || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400101024F7A000 || Resident Evil 7 biohazard Gold Edition || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400C800247DE000 || SpongeBob SquarePants: Titans of the Tide || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400F7D0239A6000 || PowerWash Simulator 2 || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04001B102590C000 || Arcade Archives 2 MIDNIGHT LANDING || EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400B21022266000 || WWE 2K25 Standard Edition || EUR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400F7F02353E000 || Goodnight Universe || CHN EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 040013C024128000 || Atelier Ryza: Ever Darkness &amp;amp; the Secret Hideout DX || JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04008E302412C000 || Atelier Ryza 3: Alchemist of the End &amp;amp; the Secret Key DX || JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 040097D02412A000 || Atelier Ryza 2: Lost Legends &amp;amp; the Secret Fairy DX || EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04004CD022304000 || Little Nightmares III || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400E54024C2E000 || Arcade Archives 2 BATTLANTIS || EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04003940236DC000 || PAC-MAN WORLD 2 Re-PAC || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400B5E02408A000 || Farming Simulator: Signature Edition || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 040036B0237FA000 || Majogami || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 040016E025052000 || Arcade Archives 2 GEE BEE || EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400E7D0239DC000 || Mortal Kombat: Legacy Kollection || EUR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400224023CF8000 || Relayer Advanced Definitive Edition || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04007D1024268000 || Yakuza Kiwami 2 || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400F65024266000 || Yakuza Kiwami || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400483024390000 || Arcade Archives 2 STEEL WORKER || EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400C420250EC000 || The Touryst Deluxe || EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400BDE024DF4000 || ShapeHero Factory || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400DAE0251C8000 || LEGO® Voyagers || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 040004B024908000 || Arcade Archives 2 VIDEO HUSTLER || EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400EDD023C64000 || Arcade Archives 2 MACH BREAKERS || EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 040023502410A000 || Cronos: The New Dawn || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400A69024378000 || Arcade Archives 2 SCRAMBLED EGG || EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400F97023C72000 || Disgaea 7 Complete || EUR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400F98023D16000 || Arcade Archives 2 AQUA JET || EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 040046A0248C0000 || BOKURA: planet || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400F9A021142000 || DRAGON BALL: Sparking! ZERO || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 040071401FF84000 || Chillin&#039; by the Fire || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04005860239F4000 || Plants vs. Zombies™: Replanted || CHN EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 0400E440238BC000 || Dear me, I was ... || CHN EUR JPN KOR USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|-&lt;br /&gt;
| 04000510239A8000 || Arcade Archives2 AIR COMBAT 22 || EUR JPN USA ||  || Digital ||  ||  || Game&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Yellows8</name></author>
	</entry>
	<entry>
		<id>https://switchbrew.org/w/index.php?title=NS_services&amp;diff=14819</id>
		<title>NS services</title>
		<link rel="alternate" type="text/html" href="https://switchbrew.org/w/index.php?title=NS_services&amp;diff=14819"/>
		<updated>2026-07-24T17:42:52Z</updated>

		<summary type="html">&lt;p&gt;Yellows8: /* GetGameCardUpdateDetectionEvent */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= aoc:u =&lt;br /&gt;
This is &amp;quot;nn::aocsrv::detail::IAddOnContentManager&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This is only available when [[Process_Manager_services|pm:bm]] GetBootMode returns output 0 (Normal).&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [1.0.0-6.2.0] CountAddOnContentByApplicationId&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [1.0.0-6.2.0] ListAddOnContentByApplicationId&lt;br /&gt;
|-&lt;br /&gt;
| 2 || CountAddOnContent&lt;br /&gt;
|-&lt;br /&gt;
| 3 || ListAddOnContent&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [1.0.0-6.2.0] GetAddOnContentBaseIdByApplicationId&lt;br /&gt;
|-&lt;br /&gt;
| 5 || GetAddOnContentBaseId&lt;br /&gt;
|-&lt;br /&gt;
| 6 || [1.0.0-6.2.0] PrepareAddOnContentByApplicationId&lt;br /&gt;
|-&lt;br /&gt;
| 7 || PrepareAddOnContent&lt;br /&gt;
|-&lt;br /&gt;
| 8 || [4.0.0+] GetAddOnContentListChangedEvent&lt;br /&gt;
|-&lt;br /&gt;
| 9 || [10.0.0+] GetAddOnContentLostErrorCode&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [11.0.0+] GetAddOnContentListChangedEventWithProcessId&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [13.0.0+] NotifyMountAddOnContent&lt;br /&gt;
|-&lt;br /&gt;
| 12 || [13.0.0+] NotifyUnmountAddOnContent&lt;br /&gt;
|-&lt;br /&gt;
| 13 || [13.0.0+] IsAddOnContentMountedForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 50 || [13.0.0+] CheckAddOnContentMountStatus&lt;br /&gt;
|-&lt;br /&gt;
| 100 || [7.0.0+] [[#IPurchaseEventManager|CreateEcPurchasedEventManager]]&lt;br /&gt;
|-&lt;br /&gt;
| 101 || [9.0.0+] [[#IPurchaseEventManager|CreatePermanentEcPurchasedEventManager]]&lt;br /&gt;
|-&lt;br /&gt;
| 110 || [12.0.0+] [[#IContentsServiceManager|CreateContentsServiceManager]]&lt;br /&gt;
|-&lt;br /&gt;
| 200 || [13.1.0+] SetRequiredAddOnContentsOnContentsAvailabilityTransition&lt;br /&gt;
|-&lt;br /&gt;
| 300 || [16.0.0+] SetupHostAddOnContent&lt;br /&gt;
|-&lt;br /&gt;
| 301 || [16.0.0+] GetRegisteredAddOnContentPath&lt;br /&gt;
|-&lt;br /&gt;
| 302 || [16.0.0+] UpdateCachedList&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IPurchaseEventManager ==&lt;br /&gt;
This is &amp;quot;nn::ec::IPurchaseEventManager&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || SetDefaultDeliveryTarget&lt;br /&gt;
|-&lt;br /&gt;
| 1 || SetDeliveryTarget&lt;br /&gt;
|-&lt;br /&gt;
| 2 || GetPurchasedEventReadableHandle&lt;br /&gt;
|-&lt;br /&gt;
| 3 || PopPurchasedProductInfo&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [9.0.0+] PopPurchasedProductInfoWithUid&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IContentsServiceManager ==&lt;br /&gt;
This is &amp;quot;nn::ec::IContentsServiceManager&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [12.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [16.0.0+] RequestContentsAuthorizationTokenDeprecated ([12.0.0-15.0.1] [[#RequestContentsAuthorizationToken]])&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [16.0.0+] RequestContentsAuthorizationToken&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== RequestContentsAuthorizationToken ===&lt;br /&gt;
Takes a total of 0x50-bytes of input, a PID, a type-0x5 input buffer. Returns an [[#IAsyncData|IAsyncData]] and an output handle.&lt;br /&gt;
&lt;br /&gt;
== IAsyncData ==&lt;br /&gt;
This is &amp;quot;nn::ec::detail::IAsyncData&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [12.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetSize&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Get&lt;br /&gt;
|-&lt;br /&gt;
| 2 || Cancel&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ns:am =&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IApplicationManagerInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
[3.0.0+] This service was replaced by [[#ns:am2, ns:ec, ns:rid, ns:rt, ns:web, ns:ro, ns:sweb|ns:am2]].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#ListApplicationRecord]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GenerateApplicationRecordCount&lt;br /&gt;
|-&lt;br /&gt;
| 2 || GetApplicationRecordUpdateSystemEvent&lt;br /&gt;
|-&lt;br /&gt;
| 3 || GetApplicationView&lt;br /&gt;
|-&lt;br /&gt;
| 4 || DeleteApplicationEntity&lt;br /&gt;
|-&lt;br /&gt;
| 5 || DeleteApplicationCompletely&lt;br /&gt;
|-&lt;br /&gt;
| 6 || IsAnyApplicationEntityRedundant&lt;br /&gt;
|-&lt;br /&gt;
| 7 || DeleteRedundantApplicationEntity&lt;br /&gt;
|-&lt;br /&gt;
| 8 || IsApplicationEntityMovable&lt;br /&gt;
|-&lt;br /&gt;
| 9 || MoveApplicationEntity&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [[#CalculateApplicationOccupiedSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 16 || PushApplicationRecord&lt;br /&gt;
|-&lt;br /&gt;
| 17 || ListApplicationRecordContentMeta&lt;br /&gt;
|-&lt;br /&gt;
| 18 || CheckLaunchRights&lt;br /&gt;
|-&lt;br /&gt;
| 19 || [[#LaunchApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 21 || [[#GetApplicationContentPath]]&lt;br /&gt;
|-&lt;br /&gt;
| 22 || TerminateApplication&lt;br /&gt;
|-&lt;br /&gt;
| 23 || [2.0.0+] ResolveApplicationContentPath&lt;br /&gt;
|-&lt;br /&gt;
| 26 || BeginInstallApplication&lt;br /&gt;
|-&lt;br /&gt;
| 27 || DeleteApplicationRecord&lt;br /&gt;
|-&lt;br /&gt;
| 30 || RequestApplicationUpdateInfo&lt;br /&gt;
|-&lt;br /&gt;
| 31 || RequestUpdateApplication&lt;br /&gt;
|-&lt;br /&gt;
| 32 || CancelApplicationDownload&lt;br /&gt;
|-&lt;br /&gt;
| 33 || ResumeApplicationDownload&lt;br /&gt;
|-&lt;br /&gt;
| 34 || ClearTaskStatusList&lt;br /&gt;
|-&lt;br /&gt;
| 35 || UpdateVersionList&lt;br /&gt;
|-&lt;br /&gt;
| 36 || PushLaunchVersion&lt;br /&gt;
|-&lt;br /&gt;
| 37 || ListRequiredVersion&lt;br /&gt;
|-&lt;br /&gt;
| 38 || CheckApplicationLaunchVersion&lt;br /&gt;
|-&lt;br /&gt;
| 39 || CheckApplicationLaunchRights&lt;br /&gt;
|-&lt;br /&gt;
| 40 || GetApplicationLogoData&lt;br /&gt;
|-&lt;br /&gt;
| 41 || CalculateApplicationDownloadRequiredSize&lt;br /&gt;
|-&lt;br /&gt;
| 42 || CleanupSdCard&lt;br /&gt;
|-&lt;br /&gt;
| 43 || [[#CheckSdCardMountStatus]]&lt;br /&gt;
|-&lt;br /&gt;
| 44 || GetSdCardMountStatusChangedEvent&lt;br /&gt;
|-&lt;br /&gt;
| 45 || GetGameCardAttachmentEvent&lt;br /&gt;
|-&lt;br /&gt;
| 46 || GetGameCardAttachmentInfo&lt;br /&gt;
|-&lt;br /&gt;
| 47 || [[#GetTotalSpaceSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 48 || [[#GetFreeSpaceSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 49 || GetSdCardRemovedEvent&lt;br /&gt;
|-&lt;br /&gt;
| 52 || GetGameCardUpdateDetectionEvent&lt;br /&gt;
|-&lt;br /&gt;
| 53 || DisableApplicationAutoDelete&lt;br /&gt;
|-&lt;br /&gt;
| 54 || EnableApplicationAutoDelete&lt;br /&gt;
|-&lt;br /&gt;
| 55 || [[#GetApplicationDesiredLanguage]]&lt;br /&gt;
|-&lt;br /&gt;
| 56 || SetApplicationTerminateResult&lt;br /&gt;
|-&lt;br /&gt;
| 57 || ClearApplicationTerminateResult&lt;br /&gt;
|-&lt;br /&gt;
| 58 || GetLastSdCardMountUnexpectedResult&lt;br /&gt;
|-&lt;br /&gt;
| 59 || ConvertApplicationLanguageToLanguageCode&lt;br /&gt;
|-&lt;br /&gt;
| 60 || [[#ConvertLanguageCodeToApplicationLanguage]]&lt;br /&gt;
|-&lt;br /&gt;
| 61 || GetBackgroundDownloadStressTaskInfo&lt;br /&gt;
|-&lt;br /&gt;
| 62 || GetGameCardStopper&lt;br /&gt;
|-&lt;br /&gt;
| 63 || IsSystemProgramInstalled&lt;br /&gt;
|-&lt;br /&gt;
| 64 || [2.0.0+] StartApplyDeltaTask&lt;br /&gt;
|-&lt;br /&gt;
| 65 || [2.0.0+] GetRequestServerStopper&lt;br /&gt;
|-&lt;br /&gt;
| 100 || ResetToFactorySettings&lt;br /&gt;
|-&lt;br /&gt;
| 101 || ResetToFactorySettingsWithoutUserSaveData&lt;br /&gt;
|-&lt;br /&gt;
| 102 || [2.0.0+] ResetToFactorySettingsForRefurbishment&lt;br /&gt;
|-&lt;br /&gt;
| 200 || CalculateUserSaveDataStatistics&lt;br /&gt;
|-&lt;br /&gt;
| 201 || DeleteUserSaveDataAll&lt;br /&gt;
|-&lt;br /&gt;
| 210 || DeleteUserSystemSaveData&lt;br /&gt;
|-&lt;br /&gt;
| 220 || UnregisterNetworkServiceAccount&lt;br /&gt;
|-&lt;br /&gt;
| 300 || GetApplicationShellEvent&lt;br /&gt;
|-&lt;br /&gt;
| 301 || PopApplicationShellEventInfo&lt;br /&gt;
|-&lt;br /&gt;
| 302 || LaunchLibraryApplet&lt;br /&gt;
|-&lt;br /&gt;
| 303 || TerminateLibraryApplet&lt;br /&gt;
|-&lt;br /&gt;
| 304 || LaunchSystemApplet&lt;br /&gt;
|-&lt;br /&gt;
| 305 || TerminateSystemApplet&lt;br /&gt;
|-&lt;br /&gt;
| 306 || LaunchOverlayApplet&lt;br /&gt;
|-&lt;br /&gt;
| 307 || TerminateOverlayApplet&lt;br /&gt;
|-&lt;br /&gt;
| 400 || [[#GetApplicationControlData]]&lt;br /&gt;
|-&lt;br /&gt;
| 401 || InvalidateAllApplicationControlCache&lt;br /&gt;
|-&lt;br /&gt;
| 402 || RequestDownloadApplicationControlData&lt;br /&gt;
|-&lt;br /&gt;
| 403 || GetMaxApplicationControlCacheCount&lt;br /&gt;
|-&lt;br /&gt;
| 404 || [2.0.0+] InvalidateApplicationControlCache&lt;br /&gt;
|-&lt;br /&gt;
| 405 || [2.0.0+] ListApplicationControlCacheEntryInfo&lt;br /&gt;
|-&lt;br /&gt;
| 502 || [2.0.0+] RequestCheckGameCardRegistration&lt;br /&gt;
|-&lt;br /&gt;
| 503 || [2.0.0+] RequestGameCardRegistrationGoldPoint&lt;br /&gt;
|-&lt;br /&gt;
| 504 || [2.0.0+] RequestRegisterGameCard&lt;br /&gt;
|-&lt;br /&gt;
| 600 || [2.0.0+] [[#CountApplicationContentMeta]]&lt;br /&gt;
|-&lt;br /&gt;
| 601 || [2.0.0+] [[#ListApplicationContentMetaStatus]]&lt;br /&gt;
|-&lt;br /&gt;
| 602 || [2.0.0+] ListOwnedAndInstalledAddOnContent&lt;br /&gt;
|-&lt;br /&gt;
| 603 || [2.0.0+] GetOwnedApplicationContentMetaStatus&lt;br /&gt;
|-&lt;br /&gt;
| 604 || [2.0.0+] RegisterContentsExternalKey&lt;br /&gt;
|-&lt;br /&gt;
| 605 || [2.0.0+] ListApplicationContentMetaStatusWithRightsCheck&lt;br /&gt;
|-&lt;br /&gt;
| 700 || [2.0.0+] PushDownloadTaskList&lt;br /&gt;
|-&lt;br /&gt;
| 701 || [2.0.0+] [[#ClearTaskStatusList]]&lt;br /&gt;
|-&lt;br /&gt;
| 702 || [2.0.0+] [[#RequestDownloadTaskList]]&lt;br /&gt;
|-&lt;br /&gt;
| 703 || [2.0.0+] [[#RequestEnsureDownloadTask]]&lt;br /&gt;
|-&lt;br /&gt;
| 704 || [2.0.0+] [[#ListDownloadTaskStatus]]&lt;br /&gt;
|-&lt;br /&gt;
| 705 || [2.0.0+] RequestDownloadTaskListData&lt;br /&gt;
|-&lt;br /&gt;
| 800 || [2.0.0+] RequestVersionList&lt;br /&gt;
|-&lt;br /&gt;
| 801 || [2.0.0+] ListVersionList&lt;br /&gt;
|-&lt;br /&gt;
| 900 || [2.0.0+] GetApplicationRecord&lt;br /&gt;
|-&lt;br /&gt;
| 901 || [2.0.0+] GetApplicationRecordProperty&lt;br /&gt;
|-&lt;br /&gt;
| 902 || [2.0.0+] EnableApplicationAutoUpdate&lt;br /&gt;
|-&lt;br /&gt;
| 903 || [2.0.0+] DisableApplicationAutoUpdate&lt;br /&gt;
|-&lt;br /&gt;
| 904 || [2.0.0+] TouchApplication&lt;br /&gt;
|-&lt;br /&gt;
| 905 || [2.0.0+] RequestApplicationUpdate&lt;br /&gt;
|-&lt;br /&gt;
| 906 || [2.0.0+] IsApplicationUpdateRequested&lt;br /&gt;
|-&lt;br /&gt;
| 907 || [2.0.0+] WithdrawApplicationUpdateRequest&lt;br /&gt;
|-&lt;br /&gt;
| 908 || [2.0.0+] ListApplicationRecordInstalledContentMeta&lt;br /&gt;
|-&lt;br /&gt;
| 1000 || [2.0.0+] RequestVerifyApplication&lt;br /&gt;
|-&lt;br /&gt;
| 1001 || [2.0.0+] CorruptApplicationForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 1200 || [2.0.0+] [[#NeedsUpdateVulnerability]]&lt;br /&gt;
|-&lt;br /&gt;
| 1300 || [2.0.0+] IsAnyApplicationEntityInstalled&lt;br /&gt;
|-&lt;br /&gt;
| 1301 || [2.0.0+] DeleteApplicationContentEntities&lt;br /&gt;
|-&lt;br /&gt;
| 1302 || [2.0.0+] CleanupUnrecordedApplicationEntity&lt;br /&gt;
|-&lt;br /&gt;
| 1400 || [2.0.0+] PrepareShutdown&lt;br /&gt;
|-&lt;br /&gt;
| 1500 || [2.0.0+] FormatSdCard&lt;br /&gt;
|-&lt;br /&gt;
| 1501 || [2.0.0+] NeedsSystemUpdateToFormatSdCard&lt;br /&gt;
|-&lt;br /&gt;
| 1502 || [2.0.0+] GetLastSdCardFormatUnexpectedResult&lt;br /&gt;
|-&lt;br /&gt;
| 1503 || [2.0.0+] DetachSdCard&lt;br /&gt;
|-&lt;br /&gt;
| 1600 || [2.0.0+] GetSystemSeedForPseudoDeviceId&lt;br /&gt;
|-&lt;br /&gt;
| 1700 || [2.0.0+] ListApplicationDownloadingContentMeta&lt;br /&gt;
|-&lt;br /&gt;
| 1800 || [2.0.0+] IsNotificationSetupCompleted&lt;br /&gt;
|-&lt;br /&gt;
| 1801 || [2.0.0+] GetLastNotificationInfoCount&lt;br /&gt;
|-&lt;br /&gt;
| 1802 || [2.0.0+] ListLastNotificationInfo&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== ListApplicationRecord ==&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of [[#ApplicationRecord]] and an s32 entry_offset, returns an output s32 out_entrycount.&lt;br /&gt;
&lt;br /&gt;
Returns an array of entries with the below format using the specified offset and count.&lt;br /&gt;
&lt;br /&gt;
== LaunchApplication ==&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output u64 PID.&lt;br /&gt;
&lt;br /&gt;
Launches an application title which is registered with NS.&lt;br /&gt;
&lt;br /&gt;
== GetApplicationContentPath ==&lt;br /&gt;
Takes a 0x16-type output buffer, an u8 [[NCM_services#ContentType|ContentType]], and an [[NCM_services#ApplicationId|ApplicationId]].&lt;br /&gt;
&lt;br /&gt;
The input [[NCM_services#ApplicationId|ApplicationId]] is used with the application-title table like various other cmds, anything not in that table can&#039;t be used with this.&lt;br /&gt;
&lt;br /&gt;
Returns a string path for the specified type of patch content with this [[NCM_services#ApplicationId|ApplicationId]], otherwise returns regular-application paths when update-title not installed. Returns an error when the specified type of content doesn&#039;t exist for this title. Starts with &amp;quot;@{SdCardContent,UserContent}://&amp;quot; and ends in &amp;quot;.nca&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
For gamecard content, the output path is: &amp;quot;@GcSXXXXXXXX:/&amp;lt;NcaId&amp;gt;.nca&amp;quot;. NCA-type0 with gamecard returns 0 with an empty output string.&lt;br /&gt;
&lt;br /&gt;
The output string is then used by the user-process with [[Filesystem_services|FS]] to mount the content.&lt;br /&gt;
&lt;br /&gt;
== GetTotalSpaceSize ==&lt;br /&gt;
Takes an input u8 [[NCM_services#StorageId|StorageId]], no output.&lt;br /&gt;
&lt;br /&gt;
The StorageId must be SdCard.&lt;br /&gt;
&lt;br /&gt;
Returns the s64 from [[NCM_services#IContentStorage]] GetFreeSpaceSize.&lt;br /&gt;
&lt;br /&gt;
== GetFreeSpaceSize ==&lt;br /&gt;
Takes an input u8 [[NCM_services#StorageId|StorageId]], no output.&lt;br /&gt;
&lt;br /&gt;
The StorageId must be SdCard.&lt;br /&gt;
&lt;br /&gt;
Returns the s64 from [[NCM_services#IContentStorage]] GetTotalSpaceSize.&lt;br /&gt;
&lt;br /&gt;
== GetApplicationDesiredLanguage ==&lt;br /&gt;
Takes an input u8 language-bitmask, returns an output u8 [[control.nacp]] langentry index.&lt;br /&gt;
&lt;br /&gt;
User-processes generate the language-bitmask with the following for all 16 lang-entries: &amp;lt;code&amp;gt;if(&amp;lt;either string in langentry[i] is non-empty&amp;gt;)bitmask |= 1&amp;lt;&amp;lt;i&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== ConvertLanguageCodeToApplicationLanguage ==&lt;br /&gt;
Takes an input u8 pointer for the resulting Id to be written to and a string represented as a u64 (i.e 0x53552D6E65 for &#039;en-US&#039;).&lt;br /&gt;
&lt;br /&gt;
Returns 0 if an ID was successfully found, otherwise returns 0x25810.&lt;br /&gt;
&lt;br /&gt;
== GetApplicationControlData ==&lt;br /&gt;
Takes an input u8 [[#ApplicationControlSource]], an [[NCM_services#ApplicationId|ApplicationId]], and a type-0x6 output buffer. Returns an output u32 for actual_size. Official user-processes use buffer size 0x24000. [[qlaunch]] only uses source value 0x1 (Storage if not in cache).&lt;br /&gt;
&lt;br /&gt;
Loads cached [[control.nacp]] to buf+0 and the cached icon to buf+0x4000. Returns an error if the buffer is too small.&lt;br /&gt;
&lt;br /&gt;
== ListApplicationContentMetaStatus ==&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of [[#ApplicationContentMetaStatus]], an input s32 index and [[NCM_services#ApplicationId|ApplicationId]], returns an output s32 out_entrycount.&lt;br /&gt;
&lt;br /&gt;
Returns 0x10-byte entries using the specified [[NCM_services#ApplicationId|ApplicationId]] starting at the specified index. Can only return game titles. The second entry if any is the update-title usually. When the input entryindex is &amp;gt;= totalentries, this will return 0 with out_entrycount=0.&lt;br /&gt;
&lt;br /&gt;
= ns:am2, ns:ec, ns:rid, ns:rt, ns:web, ns:ro, ns:sweb =&lt;br /&gt;
These are &amp;quot;nn::ns::detail::IServiceGetterInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
These commands check a state field for a command-specific bit and returns an error if not set, this is a permissions check for service+command.&lt;br /&gt;
&lt;br /&gt;
[11.0.0+] ns:ro was added.&lt;br /&gt;
&lt;br /&gt;
[15.0.0+] ns:sweb was added.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Permission bit&lt;br /&gt;
|-&lt;br /&gt;
| 7988 || [6.0.0+] [[#IDynamicRightsInterface|GetDynamicRightsInterface]] || 10&lt;br /&gt;
|-&lt;br /&gt;
| 7989 || [5.1.0+] [[#IReadOnlyApplicationControlDataInterface|GetReadOnlyApplicationControlDataInterface]] || 9&lt;br /&gt;
|-&lt;br /&gt;
| 7991 || [5.0.0+] [[#IReadOnlyApplicationRecordInterface|GetReadOnlyApplicationRecordInterface]] || 8&lt;br /&gt;
|-&lt;br /&gt;
| 7992 || [4.0.0+] [[#IECommerceInterface|GetECommerceInterface]] || 7&lt;br /&gt;
|-&lt;br /&gt;
| 7993 || [4.0.0+] [[#IApplicationVersionInterface|GetApplicationVersionInterface]] || 6&lt;br /&gt;
|-&lt;br /&gt;
| 7994 || [[#IFactoryResetInterface|GetFactoryResetInterface]] || 5&lt;br /&gt;
|-&lt;br /&gt;
| 7995 || [[#IAccountProxyInterface|GetAccountProxyInterface]] || 4&lt;br /&gt;
|-&lt;br /&gt;
| 7996 || [[#IApplicationManagerInterface|GetApplicationManagerInterface]] || 3&lt;br /&gt;
|-&lt;br /&gt;
| 7997 || [[#IDownloadTaskInterface|GetDownloadTaskInterface]] || 1&lt;br /&gt;
|-&lt;br /&gt;
| 7998 || [[#IContentManagementInterface|GetContentManagementInterface]] || 0&lt;br /&gt;
|-&lt;br /&gt;
| 7999 || [[#IDocumentInterface|GetDocumentInterface]] || 2&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Permissions state field with each service:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Service || Permissions&lt;br /&gt;
|-&lt;br /&gt;
| ns:web || 0x304&lt;br /&gt;
|-&lt;br /&gt;
| ns:ec || 0x83&lt;br /&gt;
|-&lt;br /&gt;
| ns:sweb || 0x387&lt;br /&gt;
|-&lt;br /&gt;
| ns:rid || 0x10&lt;br /&gt;
|-&lt;br /&gt;
| ns:rt || 0x20&lt;br /&gt;
|-&lt;br /&gt;
| ns:ro || 0x301&lt;br /&gt;
|-&lt;br /&gt;
| ns:am2 || 0x7FF&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IAccountProxyInterface ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IAccountProxyInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || CreateUserAccount&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IApplicationManagerInterface ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IApplicationManagerInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#ListApplicationRecord]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GenerateApplicationRecordCount&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [[#GetApplicationRecordUpdateSystemEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [[#GetApplicationViewDeprecated]]&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [[#DeleteApplicationEntity]]&lt;br /&gt;
|-&lt;br /&gt;
| 5 || [[#DeleteApplicationCompletely]]&lt;br /&gt;
|-&lt;br /&gt;
| 6 || IsAnyApplicationEntityRedundant&lt;br /&gt;
|-&lt;br /&gt;
| 7 || [[#DeleteRedundantApplicationEntity]]&lt;br /&gt;
|-&lt;br /&gt;
| 8 || [[#IsApplicationEntityMovable]]&lt;br /&gt;
|-&lt;br /&gt;
| 9 || [1.0.0-9.2.0] [[#MoveApplicationEntity]]&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [[#CalculateApplicationOccupiedSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 16 || PushApplicationRecord&lt;br /&gt;
|-&lt;br /&gt;
| 17 || ListApplicationRecordContentMeta&lt;br /&gt;
|-&lt;br /&gt;
| 19 || [1.0.0-5.1.0] LaunchApplicationOld&lt;br /&gt;
|-&lt;br /&gt;
| 21 || [[#GetApplicationContentPath]]&lt;br /&gt;
|-&lt;br /&gt;
| 22 || TerminateApplication&lt;br /&gt;
|-&lt;br /&gt;
| 23 || ResolveApplicationContentPath&lt;br /&gt;
|-&lt;br /&gt;
| 26 || BeginInstallApplication&lt;br /&gt;
|-&lt;br /&gt;
| 27 || DeleteApplicationRecord&lt;br /&gt;
|-&lt;br /&gt;
| 30 || [[#RequestApplicationUpdateInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 31 || [1.0.0-3.0.2] RequestUpdateApplication&lt;br /&gt;
|-&lt;br /&gt;
| 32 || [[#CancelApplicationDownload]]&lt;br /&gt;
|-&lt;br /&gt;
| 33 || [[#ResumeApplicationDownload]]&lt;br /&gt;
|-&lt;br /&gt;
| 35 || UpdateVersionList&lt;br /&gt;
|-&lt;br /&gt;
| 36 || PushLaunchVersion&lt;br /&gt;
|-&lt;br /&gt;
| 37 || ListRequiredVersion&lt;br /&gt;
|-&lt;br /&gt;
| 38 || [[#CheckApplicationLaunchVersion]]&lt;br /&gt;
|-&lt;br /&gt;
| 39 || [1.0.0-6.2.0] CheckApplicationLaunchRights&lt;br /&gt;
|-&lt;br /&gt;
| 40 || GetApplicationLogoData&lt;br /&gt;
|-&lt;br /&gt;
| 41 || CalculateApplicationDownloadRequiredSize&lt;br /&gt;
|-&lt;br /&gt;
| 42 || [[#CleanupSdCard]]&lt;br /&gt;
|-&lt;br /&gt;
| 43 || [[#CheckSdCardMountStatus]]&lt;br /&gt;
|-&lt;br /&gt;
| 44 || [[#GetSdCardMountStatusChangedEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 45 || GetGameCardAttachmentEvent&lt;br /&gt;
|-&lt;br /&gt;
| 46 || GetGameCardAttachmentInfo&lt;br /&gt;
|-&lt;br /&gt;
| 47 || [[#GetTotalSpaceSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 48 || [[#GetFreeSpaceSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 49 || GetSdCardRemovedEvent&lt;br /&gt;
|-&lt;br /&gt;
| 52 || [[#GetGameCardUpdateDetectionEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 53 || [[#DisableApplicationAutoDelete]]&lt;br /&gt;
|-&lt;br /&gt;
| 54 || [[#EnableApplicationAutoDelete]]&lt;br /&gt;
|-&lt;br /&gt;
| 55 || GetApplicationDesiredLanguage&lt;br /&gt;
|-&lt;br /&gt;
| 56 || [[#SetApplicationTerminateResult]]&lt;br /&gt;
|-&lt;br /&gt;
| 57 || [[#ClearApplicationTerminateResult]]&lt;br /&gt;
|-&lt;br /&gt;
| 58 || [[#GetLastSdCardMountUnexpectedResult]]&lt;br /&gt;
|-&lt;br /&gt;
| 59 || ConvertApplicationLanguageToLanguageCode&lt;br /&gt;
|-&lt;br /&gt;
| 60 || [[#ConvertLanguageCodeToApplicationLanguage]]&lt;br /&gt;
|-&lt;br /&gt;
| 61 || GetBackgroundDownloadStressTaskInfo&lt;br /&gt;
|-&lt;br /&gt;
| 62 || GetGameCardStopper&lt;br /&gt;
|-&lt;br /&gt;
| 63 || IsSystemProgramInstalled&lt;br /&gt;
|-&lt;br /&gt;
| 64 || StartApplyDeltaTask&lt;br /&gt;
|-&lt;br /&gt;
| 65 || [[#GetRequestServerStopper]]&lt;br /&gt;
|-&lt;br /&gt;
| 66 || [3.0.0+] GetBackgroundApplyDeltaStressTaskInfo&lt;br /&gt;
|-&lt;br /&gt;
| 67 || [3.0.0+] [[#CancelApplicationApplyDelta]]&lt;br /&gt;
|-&lt;br /&gt;
| 68 || [3.0.0+] [[#ResumeApplicationApplyDelta]]&lt;br /&gt;
|-&lt;br /&gt;
| 69 || [3.0.0+] [[#CalculateApplicationApplyDeltaRequiredSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 70 || [3.0.0+] [[#ResumeAll]]&lt;br /&gt;
|-&lt;br /&gt;
| 71 || [3.0.0+] [[#GetStorageSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 80 || [3.0.0+] RequestDownloadApplication&lt;br /&gt;
|-&lt;br /&gt;
| 81 || [3.0.0+] RequestDownloadAddOnContent&lt;br /&gt;
|-&lt;br /&gt;
| 82 || [3.0.0+] DownloadApplication&lt;br /&gt;
|-&lt;br /&gt;
| 83 || [4.0.0-6.2.0] CheckApplicationResumeRights&lt;br /&gt;
|-&lt;br /&gt;
| 84 || [4.0.0-16.1.0] GetDynamicCommitEvent&lt;br /&gt;
|-&lt;br /&gt;
| 85 || [4.0.0+] [[#RequestUpdateApplication2]]&lt;br /&gt;
|-&lt;br /&gt;
| 86 || [4.0.0+] EnableApplicationCrashReport&lt;br /&gt;
|-&lt;br /&gt;
| 87 || [4.0.0+] IsApplicationCrashReportEnabled&lt;br /&gt;
|-&lt;br /&gt;
| 90 || [15.0.0+] BoostSystemMemoryResourceLimit ([4.0.0-8.1.0] BoostSystemMemoryResourceLimit)&lt;br /&gt;
|-&lt;br /&gt;
| 91 || [5.0.0+] DeprecatedLaunchApplication&lt;br /&gt;
|-&lt;br /&gt;
| 92 || [5.0.0+] GetRunningApplicationProgramId&lt;br /&gt;
|-&lt;br /&gt;
| 93 || [5.0.0+] GetMainApplicationProgramIndex&lt;br /&gt;
|-&lt;br /&gt;
| 94 || [6.0.0+] [[#LaunchApplication_2|LaunchApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 95 || [6.0.0+] [[#GetApplicationLaunchInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 96 || [6.0.0+] [[#AcquireApplicationLaunchInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 97 || [6.0.0+] [[#GetMainApplicationProgramIndexByApplicationLaunchInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 98 || [6.0.0+] EnableApplicationAllThreadDumpOnCrash&lt;br /&gt;
|-&lt;br /&gt;
| 99 || [8.0.0+] [[#LaunchDevMenu]]&lt;br /&gt;
|-&lt;br /&gt;
| 100 || [[#ResetToFactorySettings]]&lt;br /&gt;
|-&lt;br /&gt;
| 101 || [[#ResetToFactorySettingsWithoutUserSaveData]]&lt;br /&gt;
|-&lt;br /&gt;
| 102 || [[#ResetToFactorySettingsForRefurbishment]]&lt;br /&gt;
|-&lt;br /&gt;
| 103 || [9.1.0+] [[#ResetToFactorySettingsWithPlatformRegion]]&lt;br /&gt;
|-&lt;br /&gt;
| 104 || [9.1.0+] [[#ResetToFactorySettingsWithPlatformRegionAuthentication]]&lt;br /&gt;
|-&lt;br /&gt;
| 105 || [10.0.0+] [[#RequestResetToFactorySettingsSecurely]]&lt;br /&gt;
|-&lt;br /&gt;
| 106 || [10.0.0+] [[#RequestResetToFactorySettingsWithPlatformRegionAuthenticationSecurely]]&lt;br /&gt;
|-&lt;br /&gt;
| 200 || CalculateUserSaveDataStatistics&lt;br /&gt;
|-&lt;br /&gt;
| 201 || [[#DeleteUserSaveDataAll]]&lt;br /&gt;
|-&lt;br /&gt;
| 210 || [[#DeleteUserSystemSaveData]]&lt;br /&gt;
|-&lt;br /&gt;
| 211 || [6.0.0+] [[#DeleteSaveData]]&lt;br /&gt;
|-&lt;br /&gt;
| 220 || [[#UnregisterNetworkServiceAccount]]&lt;br /&gt;
|-&lt;br /&gt;
| 221 || [6.0.0+] [[#UnregisterNetworkServiceAccountWithUserSaveDataDeletion]]&lt;br /&gt;
|-&lt;br /&gt;
| 300 || GetApplicationShellEvent&lt;br /&gt;
|-&lt;br /&gt;
| 301 || PopApplicationShellEventInfo&lt;br /&gt;
|-&lt;br /&gt;
| 302 || [[#LaunchLibraryApplet]]&lt;br /&gt;
|-&lt;br /&gt;
| 303 || TerminateLibraryApplet&lt;br /&gt;
|-&lt;br /&gt;
| 304 || [[#LaunchSystemApplet]]&lt;br /&gt;
|-&lt;br /&gt;
| 305 || TerminateSystemApplet&lt;br /&gt;
|-&lt;br /&gt;
| 306 || [[#LaunchOverlayApplet]]&lt;br /&gt;
|-&lt;br /&gt;
| 307 || TerminateOverlayApplet&lt;br /&gt;
|-&lt;br /&gt;
| 308 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 309 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 400 || [[#GetApplicationControlData]]&lt;br /&gt;
|-&lt;br /&gt;
| 401 || InvalidateAllApplicationControlCache&lt;br /&gt;
|-&lt;br /&gt;
| 402 || [[#RequestDownloadApplicationControlData]]&lt;br /&gt;
|-&lt;br /&gt;
| 403 || GetMaxApplicationControlCacheCount&lt;br /&gt;
|-&lt;br /&gt;
| 404 || InvalidateApplicationControlCache&lt;br /&gt;
|-&lt;br /&gt;
| 405 || ListApplicationControlCacheEntryInfo&lt;br /&gt;
|-&lt;br /&gt;
| 406 || [6.0.0-18.1.0] [[#GetApplicationControlProperty]]&lt;br /&gt;
|-&lt;br /&gt;
| 407 || [8.0.0+] [[#ListApplicationTitle]]&lt;br /&gt;
|-&lt;br /&gt;
| 408 || [8.0.0+] [[#ListApplicationIcon]]&lt;br /&gt;
|-&lt;br /&gt;
| 409 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 410 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 411 || [19.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 412 || [19.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 413 || [19.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 414 || [19.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 415 || [19.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 416 || [19.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 417 || [19.0.0+] InvalidateAllApplicationControlCacheOfTheStage&lt;br /&gt;
|-&lt;br /&gt;
| 418 || [19.0.0+] InvalidateApplicationControlCacheOfTheStage&lt;br /&gt;
|-&lt;br /&gt;
| 419 || [19.0.0+] RequestDownloadApplicationControlDataInBackground&lt;br /&gt;
|-&lt;br /&gt;
| 420 || [19.0.0+] CloneApplicationControlDataCacheForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 421 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 422 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 423 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 424 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 425 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 426 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 427 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 428 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 429 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 430 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 502 || [[#RequestCheckGameCardRegistration]]&lt;br /&gt;
|-&lt;br /&gt;
| 503 || [[#RequestGameCardRegistrationGoldPoint]]&lt;br /&gt;
|-&lt;br /&gt;
| 504 || [[#RequestRegisterGameCard]]&lt;br /&gt;
|-&lt;br /&gt;
| 505 || [3.0.0+] [[#GetGameCardMountFailureEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 506 || [3.0.0+] [[#IsGameCardInserted]]&lt;br /&gt;
|-&lt;br /&gt;
| 507 || [3.0.0+] [[#EnsureGameCardAccess]]&lt;br /&gt;
|-&lt;br /&gt;
| 508 || [3.0.0+] [[#GetLastGameCardMountFailureResult]]&lt;br /&gt;
|-&lt;br /&gt;
| 509 || [5.0.0+] [[#ListApplicationIdOnGameCard]]&lt;br /&gt;
|-&lt;br /&gt;
| 510 || [9.0.0+] [[#GetGameCardPlatformRegion]]&lt;br /&gt;
|-&lt;br /&gt;
| 511 || [19.0.0+] GetGameCardWakenReadyEvent&lt;br /&gt;
|-&lt;br /&gt;
| 512 || [19.0.0+] IsGameCardApplicationRunning&lt;br /&gt;
|-&lt;br /&gt;
| 513 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 514 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 515 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 516 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 517 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 518 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 519 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 600 || [[#CountApplicationContentMeta]]&lt;br /&gt;
|-&lt;br /&gt;
| 601 || [[#ListApplicationContentMetaStatus]]&lt;br /&gt;
|-&lt;br /&gt;
| 602 || [2.0.0-5.1.0] ListAvailableAddOnContent&lt;br /&gt;
|-&lt;br /&gt;
| 603 || GetOwnedApplicationContentMetaStatus&lt;br /&gt;
|-&lt;br /&gt;
| 604 || [1.0.0-15.0.1] RegisterContentsExternalKey&lt;br /&gt;
|-&lt;br /&gt;
| 605 || ListApplicationContentMetaStatusWithRightsCheck&lt;br /&gt;
|-&lt;br /&gt;
| 606 || [3.0.0+] GetContentMetaStorage&lt;br /&gt;
|-&lt;br /&gt;
| 607 || [6.0.0+] [[#ListAvailableAddOnContent]]&lt;br /&gt;
|-&lt;br /&gt;
| 609 || [13.0.0+] ListAvailabilityAssuredAddOnContent&lt;br /&gt;
|-&lt;br /&gt;
| 610 || [14.0.0+] GetInstalledContentMetaStorage&lt;br /&gt;
|-&lt;br /&gt;
| 611 || [16.0.0+] PrepareAddOnContent&lt;br /&gt;
|-&lt;br /&gt;
| 700 || PushDownloadTaskList&lt;br /&gt;
|-&lt;br /&gt;
| 701 || [[#ClearTaskStatusList]]&lt;br /&gt;
|-&lt;br /&gt;
| 702 || [[#RequestDownloadTaskList]]&lt;br /&gt;
|-&lt;br /&gt;
| 703 || [[#RequestEnsureDownloadTask]]&lt;br /&gt;
|-&lt;br /&gt;
| 704 || [[#ListDownloadTaskStatus]]&lt;br /&gt;
|-&lt;br /&gt;
| 705 || [[#RequestDownloadTaskListData]]&lt;br /&gt;
|-&lt;br /&gt;
| 800 || RequestVersionList&lt;br /&gt;
|-&lt;br /&gt;
| 801 || ListVersionList&lt;br /&gt;
|-&lt;br /&gt;
| 802 || [3.0.0+] [[#RequestVersionListData]]&lt;br /&gt;
|-&lt;br /&gt;
| 900 || GetApplicationRecord&lt;br /&gt;
|-&lt;br /&gt;
| 901 || GetApplicationRecordProperty&lt;br /&gt;
|-&lt;br /&gt;
| 902 || EnableApplicationAutoUpdate&lt;br /&gt;
|-&lt;br /&gt;
| 903 || DisableApplicationAutoUpdate&lt;br /&gt;
|-&lt;br /&gt;
| 904 || [[#TouchApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 905 || RequestApplicationUpdate&lt;br /&gt;
|-&lt;br /&gt;
| 906 || [[#IsApplicationUpdateRequested]]&lt;br /&gt;
|-&lt;br /&gt;
| 907 || [[#WithdrawApplicationUpdateRequest]]&lt;br /&gt;
|-&lt;br /&gt;
| 908 || ListApplicationRecordInstalledContentMeta&lt;br /&gt;
|-&lt;br /&gt;
| 909 || [3.0.0-14.1.2] WithdrawCleanupAddOnContentsWithNoRightsRecommendation&lt;br /&gt;
|-&lt;br /&gt;
| 910 || [5.0.0+] HasApplicationRecord&lt;br /&gt;
|-&lt;br /&gt;
| 911 || [5.1.0+] SetPreInstalledApplication&lt;br /&gt;
|-&lt;br /&gt;
| 912 || [5.1.0+] ClearPreInstalledApplicationFlag&lt;br /&gt;
|-&lt;br /&gt;
| 913 || [9.0.0+] ListAllApplicationRecord&lt;br /&gt;
|-&lt;br /&gt;
| 914 || [9.0.0+] HideApplicationRecord&lt;br /&gt;
|-&lt;br /&gt;
| 915 || [9.0.0+] ShowApplicationRecord&lt;br /&gt;
|-&lt;br /&gt;
| 916 || [11.0.0+] IsApplicationAutoDeleteDisabled&lt;br /&gt;
|-&lt;br /&gt;
| 917 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 918 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 919 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 920 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 921 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 922 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 923 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 924 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 925 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 926 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 927 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 928 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 929 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 930 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 931 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 933 || [20.1.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 934 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 935 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 936 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 1000 || [[#RequestVerifyApplicationDeprecated]]&lt;br /&gt;
|-&lt;br /&gt;
| 1001 || CorruptApplicationForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 1002 || [3.0.0-9.2.0] [[#RequestVerifyAddOnContentsRights]]&lt;br /&gt;
|-&lt;br /&gt;
| 1003 || [5.0.0+] [[#RequestVerifyApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 1004 || [5.0.0+] CorruptContentForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 1200 || [[#NeedsUpdateVulnerability]]&lt;br /&gt;
|-&lt;br /&gt;
| 1300 || [[#IsAnyApplicationEntityInstalled]]&lt;br /&gt;
|-&lt;br /&gt;
| 1301 || DeleteApplicationContentEntities&lt;br /&gt;
|-&lt;br /&gt;
| 1302 || CleanupUnrecordedApplicationEntity&lt;br /&gt;
|-&lt;br /&gt;
| 1303 || [3.0.0-9.2.0] CleanupAddOnContentsWithNoRights&lt;br /&gt;
|-&lt;br /&gt;
| 1304 || [3.0.0+] DeleteApplicationContentEntity&lt;br /&gt;
|-&lt;br /&gt;
| 1308 || [5.0.0+] DeleteApplicationCompletelyForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 1309 || [6.0.0+] [[#CleanupUnavailableAddOnContents]]&lt;br /&gt;
|-&lt;br /&gt;
| 1310 || [10.0.0+] [[#RequestMoveApplicationEntity]]&lt;br /&gt;
|-&lt;br /&gt;
| 1311 || [10.0.0+] [[#EstimateSizeToMove]]&lt;br /&gt;
|-&lt;br /&gt;
| 1312 || [10.0.0+] HasMovableEntity&lt;br /&gt;
|-&lt;br /&gt;
| 1313 || [11.0.0+] CleanupOrphanContents&lt;br /&gt;
|-&lt;br /&gt;
| 1314 || [11.0.0+] CheckPreconditionSatisfiedToMove&lt;br /&gt;
|-&lt;br /&gt;
| 1400 || PrepareShutdown&lt;br /&gt;
|-&lt;br /&gt;
| 1500 || [[#FormatSdCard]]&lt;br /&gt;
|-&lt;br /&gt;
| 1501 || [[#NeedsSystemUpdateToFormatSdCard]]&lt;br /&gt;
|-&lt;br /&gt;
| 1502 || [[#GetLastSdCardFormatUnexpectedResult]]&lt;br /&gt;
|-&lt;br /&gt;
| 1504 || [3.0.0+] InsertSdCard&lt;br /&gt;
|-&lt;br /&gt;
| 1505 || [3.0.0+] RemoveSdCard&lt;br /&gt;
|-&lt;br /&gt;
| 1506 || [9.0.0+] GetSdCardStartupStatus&lt;br /&gt;
|-&lt;br /&gt;
| 1508 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 1509 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 1510 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 1511 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 1512 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 1600 || GetSystemSeedForPseudoDeviceId&lt;br /&gt;
|-&lt;br /&gt;
| 1601 || [3.0.0+] ResetSystemSeedForPseudoDeviceId&lt;br /&gt;
|-&lt;br /&gt;
| 1700 || ListApplicationDownloadingContentMeta&lt;br /&gt;
|-&lt;br /&gt;
| 1701 || [3.0.0+] [[#GetApplicationView]]&lt;br /&gt;
|-&lt;br /&gt;
| 1702 || [3.0.0+] GetApplicationDownloadTaskStatus&lt;br /&gt;
|-&lt;br /&gt;
| 1703 || [4.0.0+] [[#GetApplicationViewDownloadErrorContext]]&lt;br /&gt;
|-&lt;br /&gt;
| 1704 || [8.0.0+] [[#GetApplicationViewWithPromotionInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 1705 || [11.0.0+] [[#IsPatchAutoDeletableApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 1706 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 1800 || IsNotificationSetupCompleted&lt;br /&gt;
|-&lt;br /&gt;
| 1801 || GetLastNotificationInfoCount&lt;br /&gt;
|-&lt;br /&gt;
| 1802 || [[#ListLastNotificationInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 1803 || [3.0.0+] [[#ListNotificationTask]]&lt;br /&gt;
|-&lt;br /&gt;
| 1900 || [3.0.0-12.1.0] IsActiveAccount&lt;br /&gt;
|-&lt;br /&gt;
| 1901 || [4.0.0+] [[#RequestDownloadApplicationPrepurchasedRights]]&lt;br /&gt;
|-&lt;br /&gt;
| 1902 || [5.0.0+] GetApplicationTicketInfo&lt;br /&gt;
|-&lt;br /&gt;
| 1903 || [13.1.0+] RequestDownloadApplicationPrepurchasedRightsForAccount&lt;br /&gt;
|-&lt;br /&gt;
| 2000 || [4.0.0+] [[#GetSystemDeliveryInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 2001 || [4.0.0+] [[#SelectLatestSystemDeliveryInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 2002 || [4.0.0+] [[#VerifyDeliveryProtocolVersion]]&lt;br /&gt;
|-&lt;br /&gt;
| 2003 || [4.0.0+] [[#GetApplicationDeliveryInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 2004 || [4.0.0+] [[#HasAllContentsToDeliver]]&lt;br /&gt;
|-&lt;br /&gt;
| 2005 || [4.0.0+] [[#CompareApplicationDeliveryInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 2006 || [4.0.0+] [[#CanDeliverApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 2007 || [4.0.0+] [[#ListContentMetaKeyToDeliverApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 2008 || [4.0.0+] [[#NeedsSystemUpdateToDeliverApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 2009 || [4.0.0+] [[#EstimateRequiredSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 2010 || [4.0.0+] [[#RequestReceiveApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 2011 || [4.0.0+] [[#CommitReceiveApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 2012 || [4.0.0+] [[#GetReceiveApplicationProgress]]&lt;br /&gt;
|-&lt;br /&gt;
| 2013 || [4.0.0+] [[#RequestSendApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 2014 || [4.0.0+] [[#GetSendApplicationProgress]]&lt;br /&gt;
|-&lt;br /&gt;
| 2015 || [4.0.0+] [[#CompareSystemDeliveryInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 2016 || [4.0.0+] [[#ListNotCommittedContentMeta]]&lt;br /&gt;
|-&lt;br /&gt;
| 2017 || [4.0.0+] [[#RecoverDownloadTask]]&lt;br /&gt;
|-&lt;br /&gt;
| 2018 || [5.0.0+] [[#GetApplicationDeliveryInfoHash]]&lt;br /&gt;
|-&lt;br /&gt;
| 2019 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2050 || [6.0.0+] [[#GetApplicationRightsOnClient]]&lt;br /&gt;
|-&lt;br /&gt;
| 2051 || [9.0.0+] InvalidateRightsIdCache&lt;br /&gt;
|-&lt;br /&gt;
| 2052 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2053 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2100 || [6.0.0+] [[#GetApplicationTerminateResult]]&lt;br /&gt;
|-&lt;br /&gt;
| 2101 || [6.0.0+] GetRawApplicationTerminateResult&lt;br /&gt;
|-&lt;br /&gt;
| 2150 || [6.0.0+] CreateRightsEnvironment&lt;br /&gt;
|-&lt;br /&gt;
| 2151 || [6.0.0+] DestroyRightsEnvironment&lt;br /&gt;
|-&lt;br /&gt;
| 2152 || [6.0.0+] ActivateRightsEnvironment&lt;br /&gt;
|-&lt;br /&gt;
| 2153 || [6.0.0+] DeactivateRightsEnvironment&lt;br /&gt;
|-&lt;br /&gt;
| 2154 || [6.0.0+] ForceActivateRightsContextForExit&lt;br /&gt;
|-&lt;br /&gt;
| 2155 || [7.0.0+] UpdateRightsEnvironmentStatus&lt;br /&gt;
|-&lt;br /&gt;
| 2156 || [10.0.0-12.1.0] CreateRightsEnvironmentForMicroApplication ([9.0.0-9.2.0] CreateRightsEnvironmentForPreomia)&lt;br /&gt;
|-&lt;br /&gt;
| 2160 || [6.0.0+] AddTargetApplicationToRightsEnvironment&lt;br /&gt;
|-&lt;br /&gt;
| 2161 || [6.0.0+] SetUsersToRightsEnvironment&lt;br /&gt;
|-&lt;br /&gt;
| 2170 || [6.0.0+] GetRightsEnvironmentStatus&lt;br /&gt;
|-&lt;br /&gt;
| 2171 || [6.0.0+] GetRightsEnvironmentStatusChangedEvent&lt;br /&gt;
|-&lt;br /&gt;
| 2180 || [6.0.0+] RequestExtendExpirationInRightsEnvironment&lt;br /&gt;
|-&lt;br /&gt;
| 2181 || [6.0.0+] GetResultOfExtendExpirationInRightsEnvironment&lt;br /&gt;
|-&lt;br /&gt;
| 2182 || [6.0.0+] SetActiveRightsContextUsingStateToRightsEnvironment&lt;br /&gt;
|-&lt;br /&gt;
| 2183 || [20.1.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2190 || [6.0.0+] [[#GetRightsEnvironmentHandleForApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 2199 || [6.0.0+] GetRightsEnvironmentCountForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 2200 || [6.0.0-9.2.0] GetGameCardApplicationCopyIdentifier&lt;br /&gt;
|-&lt;br /&gt;
| 2201 || [6.0.0-9.2.0] GetInstalledApplicationCopyIdentifier&lt;br /&gt;
|-&lt;br /&gt;
| 2250 || [6.0.0-6.2.0] RequestReportActiveELicence&lt;br /&gt;
|-&lt;br /&gt;
| 2300 || [6.0.0-8.1.0] ListEventLog&lt;br /&gt;
|-&lt;br /&gt;
| 2350 || [7.0.0+] PerformAutoUpdateByApplicationId&lt;br /&gt;
|-&lt;br /&gt;
| 2351 || [9.0.0+] [[#RequestNoDownloadRightsErrorResolution]]&lt;br /&gt;
|-&lt;br /&gt;
| 2352 || [9.0.0+] [[#RequestResolveNoDownloadRightsError]]&lt;br /&gt;
|-&lt;br /&gt;
| 2353 || [10.0.0+] GetApplicationDownloadTaskInfo&lt;br /&gt;
|-&lt;br /&gt;
| 2354 || [11.0.0+] PrioritizeApplicationBackgroundTask&lt;br /&gt;
|-&lt;br /&gt;
| 2355 || [12.0.0+] PreferStorageEfficientUpdate&lt;br /&gt;
|-&lt;br /&gt;
| 2356 || [12.0.0+] RequestStorageEfficientUpdatePreferable&lt;br /&gt;
|-&lt;br /&gt;
| 2357 || [15.0.0+] EnableMultiCoreDownload&lt;br /&gt;
|-&lt;br /&gt;
| 2358 || [15.0.0+] DisableMultiCoreDownload&lt;br /&gt;
|-&lt;br /&gt;
| 2359 || [15.0.0+] IsMultiCoreDownloadEnabled&lt;br /&gt;
|-&lt;br /&gt;
| 2360 || [19.0.0+] GetApplicationDownloadTaskCount&lt;br /&gt;
|-&lt;br /&gt;
| 2361 || [19.0.0+] GetMaxApplicationDownloadTaskCount&lt;br /&gt;
|-&lt;br /&gt;
| 2362 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2363 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2364 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2365 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2366 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2367 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2368 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2369 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2400 || [8.0.0+] [[#GetPromotionInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 2401 || [8.0.0+] CountPromotionInfo&lt;br /&gt;
|-&lt;br /&gt;
| 2402 || [8.0.0+] [[#ListPromotionInfo|ListPromotionInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 2403 || [8.0.0+] [[#ImportPromotionJsonForDebug]]&lt;br /&gt;
|-&lt;br /&gt;
| 2404 || [8.0.0+] [[#ClearPromotionInfoForDebug]]&lt;br /&gt;
|-&lt;br /&gt;
| 2500 || [8.0.0+] ConfirmAvailableTime&lt;br /&gt;
|-&lt;br /&gt;
| 2510 || [9.0.0+] [[#CreateApplicationResource]]&lt;br /&gt;
|-&lt;br /&gt;
| 2511 || [9.0.0+] [[#GetApplicationResource]]&lt;br /&gt;
|-&lt;br /&gt;
| 2513 || [10.0.0+] [[#LaunchMicroApplication]] ([9.0.0-9.2.0] LaunchPreomia)&lt;br /&gt;
|-&lt;br /&gt;
| 2514 || [9.0.0+] ClearTaskOfAsyncTaskManager&lt;br /&gt;
|-&lt;br /&gt;
| 2515 || [10.0.0+] CleanupAllPlaceHolderAndFragmentsIfNoTask&lt;br /&gt;
|-&lt;br /&gt;
| 2516 || [10.0.0-14.1.2] EnsureApplicationCertificate&lt;br /&gt;
|-&lt;br /&gt;
| 2517 || [13.0.0+] [[#CreateApplicationInstance]]&lt;br /&gt;
|-&lt;br /&gt;
| 2518 || [13.0.0+] UpdateQualificationForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 2519 || [13.0.0+] IsQualificationTransitionSupported&lt;br /&gt;
|-&lt;br /&gt;
| 2520 || [13.0.0+] IsQualificationTransitionSupportedByProcessId&lt;br /&gt;
|-&lt;br /&gt;
| 2521 || [13.0.0-16.1.0] GetRightsUserChangedEvent&lt;br /&gt;
|-&lt;br /&gt;
| 2522 || [14.0.0+] IsRomRedirectionAvailable&lt;br /&gt;
|-&lt;br /&gt;
| 2523 || [17.0.0+] GetProgramId&lt;br /&gt;
|-&lt;br /&gt;
| 2524 || [19.0.0+] &lt;br /&gt;
|-&lt;br /&gt;
| 2525 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2800 || [9.0.0+] GetApplicationIdOfPreomia&lt;br /&gt;
|-&lt;br /&gt;
| 3000 || [11.0.0+] [[#RegisterDeviceLockKey]]&lt;br /&gt;
|-&lt;br /&gt;
| 3001 || [11.0.0+] [[#UnregisterDeviceLockKey]]&lt;br /&gt;
|-&lt;br /&gt;
| 3002 || [11.0.0+] [[#VerifyDeviceLockKey]]&lt;br /&gt;
|-&lt;br /&gt;
| 3003 || [11.0.0+] [[#HideApplicationIcon]]&lt;br /&gt;
|-&lt;br /&gt;
| 3004 || [11.0.0+] [[#ShowApplicationIcon]]&lt;br /&gt;
|-&lt;br /&gt;
| 3005 || [11.0.0+] [[#HideApplicationTitle]]&lt;br /&gt;
|-&lt;br /&gt;
| 3006 || [11.0.0+] [[#ShowApplicationTitle]]&lt;br /&gt;
|-&lt;br /&gt;
| 3007 || [11.0.0+] [[#EnableGameCard]]&lt;br /&gt;
|-&lt;br /&gt;
| 3008 || [11.0.0+] [[#DisableGameCard]]&lt;br /&gt;
|-&lt;br /&gt;
| 3009 || [11.0.0+] [[#EnableLocalContentShare]]&lt;br /&gt;
|-&lt;br /&gt;
| 3010 || [11.0.0+] [[#DisableLocalContentShare]]&lt;br /&gt;
|-&lt;br /&gt;
| 3011 || [11.0.0+] [[#IsApplicationIconHidden]]&lt;br /&gt;
|-&lt;br /&gt;
| 3012 || [11.0.0+] [[#IsApplicationTitleHidden]]&lt;br /&gt;
|-&lt;br /&gt;
| 3013 || [11.0.0+] [[#IsGameCardEnabled]]&lt;br /&gt;
|-&lt;br /&gt;
| 3014 || [11.0.0+] [[#IsLocalContentShareEnabled]]&lt;br /&gt;
|-&lt;br /&gt;
| 3015 || [18.0.0+] GetNetworkUpdateRequiredByGameCardDetectionEvent&lt;br /&gt;
|-&lt;br /&gt;
| 3050 || [14.0.0+] ListAssignELicenseTaskResult&lt;br /&gt;
|-&lt;br /&gt;
| 3100 || [17.0.0+] [[#GetSafeSystemVersionCheckInfo|GetSafeSystemVersionCheckInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 3101 || [17.0.0+] [[#RequestUpdateSafeSystemVersionCheckInfo|RequestUpdateSafeSystemVersionCheckInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 3102 || [17.0.0+] [[#ResetSafeSystemVersionCheckInfo|ResetSafeSystemVersionCheckInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 3104 || [18.0.0+] GetApplicationNintendoLogo&lt;br /&gt;
|-&lt;br /&gt;
| 3105 || [18.0.0+] GetApplicationStartupMovie&lt;br /&gt;
|-&lt;br /&gt;
| 3150 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 4000 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4004 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4006 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4007 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4008 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4009 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4010 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4011 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4012 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4013 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4015 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4017 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4019 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4020 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4021 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4022 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4023 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4024 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4025 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4026 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4027 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4028 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4029 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4030 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4031 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4032 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4033 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4034 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4035 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4037 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4038 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4039 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4040 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4041 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4042 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4043 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4044 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4045 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4046 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4049 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4050 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4051 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4052 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4053 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4054 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4055 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4056 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4057 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4058 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4059 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4060 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4061 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4062 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4063 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4064 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4065 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4066 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4067 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4068 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4069 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4070 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4071 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4072 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4073 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4074 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4075 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4076 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4077 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4078 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4079 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4080 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4081 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4083 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4084 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4085 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4086 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4087 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4088 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4089 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4090 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4091 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4092 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4093 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4094 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4095 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4096 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4097 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 4099 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 5000 || [18.0.0+] &lt;br /&gt;
|-&lt;br /&gt;
| 5001 || [18.0.0+] &lt;br /&gt;
|-&lt;br /&gt;
| 9999 || [10.0.0-10.2.0] GetApplicationCertificate&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[4.0.0+] RequestDownloadAddOnContent now takes an additional 8-bytes of input.&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationRecordUpdateSystemEvent ====&lt;br /&gt;
No input, returns an output Event handle with EventClearMode=1.&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationViewDeprecated ====&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of [[#ApplicationViewDeprecated]], a type-0x5 input buffer containing an array of u64 [[NCM_services#ApplicationId|ApplicationIds]], no output.&lt;br /&gt;
&lt;br /&gt;
On newer system-versions this is the same as [[#GetApplicationView]], except this converts the output from the func called in the loop from [[#ApplicationView]] to [[#ApplicationViewDeprecated]].&lt;br /&gt;
&lt;br /&gt;
==== DeleteApplicationEntity ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== DeleteApplicationCompletely ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== DeleteRedundantApplicationEntity ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== IsApplicationEntityMovable ====&lt;br /&gt;
Takes an input u8 [[NCM_services#StorageId|StorageId]], an [[NCM_services#ApplicationId|ApplicationId]], returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
==== MoveApplicationEntity ====&lt;br /&gt;
Takes an input u8 [[NCM_services#StorageId|StorageId]], an [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== RequestApplicationUpdateInfo ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
The data that can be read from the [[#IAsyncValue]] is [[#ApplicationUpdateInfo]].&lt;br /&gt;
&lt;br /&gt;
Before using the cmd, official sw uses [[Network_Interface_services#IsAnyInternetRequestAccepted|IsAnyInternetRequestAccepted]] with the output from [[Network_Interface_services#GetClientId|GetClientId]], throwing an error when the returned bool is false.&lt;br /&gt;
&lt;br /&gt;
==== CancelApplicationDownload ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== ResumeApplicationDownload ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== CheckApplicationLaunchVersion ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== CalculateApplicationDownloadRequiredSize ====&lt;br /&gt;
Takes an input u8 [[NCM_services#StorageId|StorageId]], an [[NCM_services#ApplicationId|ApplicationId]], returns an output s64.&lt;br /&gt;
&lt;br /&gt;
==== CleanupSdCard ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== GetSdCardMountStatusChangedEvent ====&lt;br /&gt;
No input, returns an output Event handle with EventClearMode=0.&lt;br /&gt;
&lt;br /&gt;
==== GetGameCardUpdateDetectionEvent ====&lt;br /&gt;
No input, returns an output Event handle with EventClearMode=0.&lt;br /&gt;
&lt;br /&gt;
This Event is used by [[qlaunch]] to check whether a card-sysupdate is required.&lt;br /&gt;
&lt;br /&gt;
==== DisableApplicationAutoDelete ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== EnableApplicationAutoDelete ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== SetApplicationTerminateResult ====&lt;br /&gt;
Takes an input u32 Result, an [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== ClearApplicationTerminateResult ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== GetLastSdCardMountUnexpectedResult ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== GetRequestServerStopper ====&lt;br /&gt;
No input, returns an output [[#IRequestServerStopper]].&lt;br /&gt;
&lt;br /&gt;
This increfs a state ref-count, with decref being handled when the object is closed. This ref-count is checked by [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]] and related cmds.&lt;br /&gt;
&lt;br /&gt;
==== CancelApplicationApplyDelta ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== ResumeApplicationApplyDelta ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== CalculateApplicationApplyDeltaRequiredSize ====&lt;br /&gt;
Takes an input u8 [[NCM_services#StorageId|StorageId]], an [[NCM_services#ApplicationId|ApplicationId]], returns an output s64.&lt;br /&gt;
&lt;br /&gt;
==== ResumeAll ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== GetStorageSize ====&lt;br /&gt;
Takes an input u8 [[NCM_services#StorageId|StorageId]], returns two output s64s.&lt;br /&gt;
&lt;br /&gt;
This temporarily mounts the [[Filesystem_services#OpenContentStorageFileSystem|ContentStorage]] specified by the StorageId (must be BuiltInUser or SdCard). The two output s64s are the output from [[Filesystem_services#GetTotalSpaceSize|GetTotalSpaceSize]] and [[Filesystem_services#GetFreeSpaceSize|GetFreeSpaceSize]] with this ContentStorage, with it this being unmounted afterwards.&lt;br /&gt;
&lt;br /&gt;
==== RequestUpdateApplication2 ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
See [[#RequestApplicationUpdateInfo]] regarding nifm.&lt;br /&gt;
&lt;br /&gt;
==== LaunchApplication ====&lt;br /&gt;
Takes an input u8 ProgramIndex, an input [[#ApplicationLaunchInfo]], returns an output u64.&lt;br /&gt;
&lt;br /&gt;
[18.0.0+] Now takes a total of 0x58 bytes of input.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] Now takes a total of 0x88 bytes of input.&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationLaunchInfo ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output [[#ApplicationLaunchInfo]].&lt;br /&gt;
&lt;br /&gt;
[18.0.0+] Now returns a total of 0x50 bytes of output.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] Now returns a total of 0x80 bytes of output.&lt;br /&gt;
&lt;br /&gt;
==== AcquireApplicationLaunchInfo ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output [[#ApplicationLaunchInfo]].&lt;br /&gt;
&lt;br /&gt;
This verifies that a state flag is set and that a state field matches the input ApplicationId, throwing an error otherwise. The [[#ApplicationLaunchInfo]] from state is copied to output, then the state flag is cleared.&lt;br /&gt;
&lt;br /&gt;
[18.0.0+] Now returns a total of 0x50 bytes of output.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] Now returns a total of 0x80 bytes of output.&lt;br /&gt;
&lt;br /&gt;
==== GetMainApplicationProgramIndexByApplicationLaunchInfo ====&lt;br /&gt;
[18.0.0+] Now takes a total of 0x50 bytes of input.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] Now returns a total of 0x80 bytes of output.&lt;br /&gt;
&lt;br /&gt;
==== LaunchDevMenu ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
This is used by AM cmd [[Applet_Manager_services#LaunchDevMenu|LaunchDevMenu]].&lt;br /&gt;
&lt;br /&gt;
This loads ProgramIds from [[System_Settings|system-settings]] &amp;lt;code&amp;gt;ns.applet!devmenu_id&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;ns.applet!devoverlaydisp_id&amp;lt;/code&amp;gt;, which only exists on devunits. An error is thrown if loading these fail.&lt;br /&gt;
&lt;br /&gt;
[[NCM_services#ncm|OpenContentMetaDatabase]] is used with StorageId = NandSystem, then IContentMetaDatabase GetLatestContentMetaKey is used with both of the above ProgramIds to verify that the cmd is successful.&lt;br /&gt;
&lt;br /&gt;
Then if the above succeeds, the above titles are launched with the above StorageId via [[Process_Manager_services|pmshell]] LaunchProgram ([10.0.0+] [[PGL_services#LaunchProgram|pgl]] with pgl_launch_flags=0), with a 0.5s sleep-thread afterwards on success. [[Process_Manager_services#LaunchFlags|LaunchFlags]] value 0xB is used here.&lt;br /&gt;
&lt;br /&gt;
==== DeleteUserSaveDataAll ====&lt;br /&gt;
Takes an input [[Account_services#Uid|Uid]], returns an output [[#IProgressMonitorForDeleteUserSaveDataAll]].&lt;br /&gt;
&lt;br /&gt;
On success, [[#IProgressMonitorForDeleteUserSaveDataAll]] GetProgress is used with the output being copied into object state.&lt;br /&gt;
&lt;br /&gt;
==== DeleteUserSystemSaveData ====&lt;br /&gt;
Takes an input [[Account_services#Uid|Uid]], an u64 SystemSaveDataId, no output.&lt;br /&gt;
&lt;br /&gt;
==== DeleteSaveData ====&lt;br /&gt;
Takes an input u8 [[Filesystem_services#SaveDataSpaceId|SaveDataSpaceId]], an u64 SaveDataId, no output.&lt;br /&gt;
&lt;br /&gt;
==== UnregisterNetworkServiceAccount ====&lt;br /&gt;
Takes an input [[Account_services#Uid|Uid]], no output.&lt;br /&gt;
&lt;br /&gt;
==== UnregisterNetworkServiceAccountWithUserSaveDataDeletion ====&lt;br /&gt;
Takes an input [[Account_services#Uid|Uid]], no output.&lt;br /&gt;
&lt;br /&gt;
==== LaunchLibraryApplet ====&lt;br /&gt;
Takes an input u64 [[NCM_services#ProgramId|ProgramId]], returns an output u64.&lt;br /&gt;
&lt;br /&gt;
The specified program is launched with StorageId=BuiltInSystem via [[Process_Manager_services|pmshell]] LaunchProgram ([10.0.0+] [[PGL_services#LaunchProgram|pgl]] with pgl_launch_flags=0). [[Process_Manager_services#LaunchFlags|LaunchFlags]] value 0x9 is used here. The output u64 from here is written to the output for this cmd, on success.&lt;br /&gt;
&lt;br /&gt;
This is used by [[Applet_Manager_services|AM]].&lt;br /&gt;
&lt;br /&gt;
==== LaunchSystemApplet ====&lt;br /&gt;
No input, returns an output u64.&lt;br /&gt;
&lt;br /&gt;
A state flag must be non-zero, otherwise an error is thrown. When a state field is value 1, a hard-coded ProgramId for MaintenanceMenu is used. Otherwise, the ProgramId is loaded from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;ns.applet!system_applet_id&amp;lt;/code&amp;gt; ([20.0.0+] &amp;lt;code&amp;gt;ns.applet!system_applet_id_gen2&amp;lt;/code&amp;gt;).&lt;br /&gt;
&lt;br /&gt;
The SystemApplet is launched with StorageId=BuiltInSystem via [[Process_Manager_services|pmshell]] LaunchProgram ([10.0.0+] [[PGL_services#LaunchProgram|pgl]] with pgl_launch_flags=0). [[Process_Manager_services#LaunchFlags|LaunchFlags]] value 0x9 is used here. The output u64 from here is written to the output for this cmd, on success.&lt;br /&gt;
&lt;br /&gt;
This is used by [[Applet_Manager_services|AM]].&lt;br /&gt;
&lt;br /&gt;
==== LaunchOverlayApplet ====&lt;br /&gt;
No input, returns an output u64.&lt;br /&gt;
&lt;br /&gt;
A state flag must be non-zero, otherwise an error is thrown. The ProgramId is loaded from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;ns.applet!overlay_applet_id&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
The OverlayApplet is launched with StorageId=BuiltInSystem via [[Process_Manager_services|pmshell]] LaunchProgram ([10.0.0+] [[PGL_services#LaunchProgram|pgl]] with pgl_launch_flags=0). [[Process_Manager_services#LaunchFlags|LaunchFlags]] value 0x9 is used here. The output u64 from here is written to the output for this cmd, on success.&lt;br /&gt;
&lt;br /&gt;
This is used by [[Applet_Manager_services|AM]].&lt;br /&gt;
&lt;br /&gt;
==== RequestDownloadApplicationControlData ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
See [[#RequestApplicationUpdateInfo]] regarding nifm.&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationControlProperty ====&lt;br /&gt;
[18.0.0+] Now takes a total of 0x58 bytes of input.&lt;br /&gt;
&lt;br /&gt;
==== ListApplicationTitle ====&lt;br /&gt;
Takes an input TransferMemory handle, a type-0x5 input buffer containing an array of u64 [[NCM_services#ApplicationId|ApplicationIds]], an u8 [[#ApplicationControlSource]], an u64 size, returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
[[qlaunch]] uses value 0x1 for the u8.&lt;br /&gt;
&lt;br /&gt;
The user-process creates the TransferMemory with permissions=R--.&lt;br /&gt;
&lt;br /&gt;
The data available with [[#IAsyncValue]] Get is a s32 for the offset within the TransferMemory where the output data is located, GetSize returns the total byte-size of the data located here. The data located here is the [[NACP_Format|NACP]] title-entry for each specified ApplicationId.&lt;br /&gt;
&lt;br /&gt;
The TransferMemory size must be at least: count*sizeof([[NACP_Format|title-entry]]) + count*sizeof(u64) + count*[[#GetApplicationControlData|0x24000]].&lt;br /&gt;
&lt;br /&gt;
This is essentially an async wrapper for [[#GetApplicationControlData]], with support for multiple ApplicationIds.&lt;br /&gt;
&lt;br /&gt;
==== ListApplicationIcon ====&lt;br /&gt;
Takes an input TransferMemory handle, a type-0x5 input buffer containing an array of u64 [[NCM_services#ApplicationId|ApplicationIds]], an u8 [[#ApplicationControlSource]], an u64 size, returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
The user-process creates the TransferMemory with permissions=R--.&lt;br /&gt;
&lt;br /&gt;
The data available with [[#IAsyncValue]] Get is a s32 for the offset within the TransferMemory where the output data is located, GetSize returns the total byte-size of the data located here. This data is: an u64 for total entries, an array of u64s for each icon size, then the icon JPEGs for the specified ApplicationIds.&lt;br /&gt;
&lt;br /&gt;
The TransferMemory size must be at least: 0x4 + count*sizeof(u64) + count*[[#GetApplicationControlData|0x20000]] + count*sizeof(u64) + [[#GetApplicationControlData|0x24000]].&lt;br /&gt;
&lt;br /&gt;
This is essentially an async wrapper for [[#GetApplicationControlData]], with support for multiple ApplicationIds.&lt;br /&gt;
&lt;br /&gt;
==== Cmd421 ====&lt;br /&gt;
Takes an input TransferMemory handle, a type-0x5 input buffer containing an array of u64 [[NCM_services#ApplicationId|ApplicationIds]], an u8 [[#ApplicationControlSource]], an u64 size, returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
This is essentially the same as [[#ListApplicationTitle|ListApplicationTitle]] except the ApplicationControlSource is used here (ListApplicationTitle ignores it and uses 0xF0 instead).&lt;br /&gt;
&lt;br /&gt;
The TransferMemory size must be at least: count*sizeof(u64) + count*[[NACP#ApplicationTitle|0x300]] + [[#GetApplicationControlData|0x1d000]].&lt;br /&gt;
&lt;br /&gt;
The async task impl code eventually compares ApplicationControlSource with 0xF0, with a separate code-path being used when it doesn&#039;t match (which also handles [[NACP|compression]] when needed).&lt;br /&gt;
&lt;br /&gt;
==== RequestCheckGameCardRegistration ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
See [[#RequestApplicationUpdateInfo]] regarding nifm.&lt;br /&gt;
&lt;br /&gt;
==== RequestGameCardRegistrationGoldPoint ====&lt;br /&gt;
Takes an input [[Account_services#Uid|Uid]], an [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
The data that can be read from the [[#IAsyncValue]] is 4-bytes.&lt;br /&gt;
&lt;br /&gt;
See [[#RequestApplicationUpdateInfo]] regarding nifm.&lt;br /&gt;
&lt;br /&gt;
==== RequestRegisterGameCard ====&lt;br /&gt;
Takes an input s32, an [[Account_services#Uid|Uid]], an [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
See [[#RequestApplicationUpdateInfo]] regarding nifm.&lt;br /&gt;
&lt;br /&gt;
==== GetGameCardMountFailureEvent ====&lt;br /&gt;
No input, returns an output Event handle with EventClearMode=0.&lt;br /&gt;
&lt;br /&gt;
==== IsGameCardInserted ====&lt;br /&gt;
No input, returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
==== EnsureGameCardAccess ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== GetLastGameCardMountFailureResult ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== ListApplicationIdOnGameCard ====&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of u64 [[NCM_services#ApplicationId|ApplicationIds]], returns an output s32 for total output entries.&lt;br /&gt;
&lt;br /&gt;
==== GetGameCardPlatformRegion ====&lt;br /&gt;
No input, returns an u8 &#039;&#039;&#039;GameCardPlatformRegion&#039;&#039;&#039; (0x00 = Global, 0x01 = China).&lt;br /&gt;
&lt;br /&gt;
This calls [[Filesystem_services#IDeviceOperator|fsp-srv IDeviceOperator]] GetGameCardCompatibilityType and returns the result.&lt;br /&gt;
&lt;br /&gt;
==== ListAvailableAddOnContent ====&lt;br /&gt;
[10.0.0+] This now takes a total of 0x10-bytes of input instead of a total of 0x18-bytes of input.&lt;br /&gt;
&lt;br /&gt;
[15.0.0+] This now takes a total of 0x8-bytes of input instead of a total of 0x10-bytes of input.&lt;br /&gt;
&lt;br /&gt;
==== RequestDownloadTaskListData ====&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
==== TouchApplication ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== IsApplicationUpdateRequested ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output u8 bool and an u32.&lt;br /&gt;
&lt;br /&gt;
The output u32 is only valid when the output bool is set.&lt;br /&gt;
&lt;br /&gt;
==== WithdrawApplicationUpdateRequest ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== RequestVerifyApplicationDeprecated ====&lt;br /&gt;
Takes an input TransferMemory handle, an [[NCM_services#ApplicationId|ApplicationId]], an u64 size, returns an output Event handle and an [[#IProgressAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
On newer system-versions this calls the same func as [[#RequestVerifyApplication]], with the u32 value set to 0x7.&lt;br /&gt;
&lt;br /&gt;
==== RequestVerifyAddOnContentsRights ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IProgressAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
==== RequestVerifyApplication ====&lt;br /&gt;
Takes an input TransferMemory handle, an u32, an [[NCM_services#ApplicationId|ApplicationId]], an u64 size, returns an output Event handle and an [[#IProgressAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
Official sw creates the TransferMemory with an user-specified buffer with permissions=0. [[qlaunch]] uses buffer size 0x100000.&lt;br /&gt;
&lt;br /&gt;
Official sw has an additional wrapper func which calls the original wrapper func, this uses value 0x7 for the u32. This is the same func used by [[qlaunch]].&lt;br /&gt;
&lt;br /&gt;
==== IsAnyApplicationEntityInstalled ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
==== CleanupUnavailableAddOnContents ====&lt;br /&gt;
Takes an input u64 [[NCM_services#ApplicationId|ApplicationId]], an [[Account_services#Uid|Uid]], no output.&lt;br /&gt;
&lt;br /&gt;
==== RequestMoveApplicationEntity ====&lt;br /&gt;
Takes an input TransferMemory handle, a type-0x5 input buffer containing an array of [[NCM_services#StorageId|StorageId]], a [[NCM_services#StorageId|StorageId]], an u32 bitfield of &amp;quot;nn::ns::KeepApplicationEntityFlagTag&amp;quot;, an [[NCM_services#ApplicationId|ApplicationId]], an u64 tmem_size, returns an output Event handle and an [[#IProgressAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
The TransferMemory uses permissions=0.&lt;br /&gt;
&lt;br /&gt;
==== EstimateSizeToMove ====&lt;br /&gt;
Takes a type-0x5 input buffer containing an array of [[NCM_services#StorageId|StorageId]], a [[NCM_services#StorageId|StorageId]], an u32 bitfield of &amp;quot;nn::ns::KeepApplicationEntityFlagTag&amp;quot;, an [[NCM_services#ApplicationId|ApplicationId]], returns an output s64.&lt;br /&gt;
&lt;br /&gt;
This calls a func also used by [[#RequestMoveApplicationEntity]], then calls another func.&lt;br /&gt;
&lt;br /&gt;
==== FormatSdCard ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== NeedsSystemUpdateToFormatSdCard ====&lt;br /&gt;
No input, returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
==== GetLastSdCardFormatUnexpectedResult ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationView ====&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of [[#ApplicationView]], a type-0x5 input buffer containing an array of u64 [[NCM_services#ApplicationId|ApplicationIds]], no output.&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationViewDownloadErrorContext ====&lt;br /&gt;
Takes a type-0x16 output buffer containg an [[Error_Applet#ErrorContext|ErrorContext]], an u64 [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationViewWithPromotionInfo ====&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of [[#ApplicationViewWithPromotionInfo]], a type-0x5 input buffer containing an array of u64 [[NCM_services#ApplicationId|ApplicationIds]], no output.&lt;br /&gt;
&lt;br /&gt;
==== IsPatchAutoDeletableApplication ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output bool.&lt;br /&gt;
&lt;br /&gt;
Compares the input ApplicationId with the value of [[System_Settings|system-setting]] &amp;lt;code&amp;gt;ns.application!auto_deletable_application_id_on_not_enough_space&amp;lt;/code&amp;gt;, with the bool being set to the comparsion result.&lt;br /&gt;
&lt;br /&gt;
==== ListLastNotificationInfo ====&lt;br /&gt;
Takes a type-0x6 buffer containing an array with struct entry size 0x90-bytes. Returns 4-bytes of output.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] The struct size is now 0x98-bytes.&lt;br /&gt;
&lt;br /&gt;
==== ListNotificationTask ====&lt;br /&gt;
Takes a type-0x6 buffer containing an array with struct entry size 0xB0-bytes. Returns 4-bytes of output.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] The struct size is now 0xB8-bytes.&lt;br /&gt;
&lt;br /&gt;
==== RequestDownloadApplicationPrepurchasedRights ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
See [[#RequestApplicationUpdateInfo]] regarding nifm.&lt;br /&gt;
&lt;br /&gt;
==== GetSystemDeliveryInfo ====&lt;br /&gt;
Takes a type-0x16 output buffer containing a [[#SystemDeliveryInfo]], no output.&lt;br /&gt;
&lt;br /&gt;
This generates a [[#SystemDeliveryInfo]] using the currently installed SystemUpdate meta title.&lt;br /&gt;
&lt;br /&gt;
==== SelectLatestSystemDeliveryInfo ====&lt;br /&gt;
Takes a type-0x15 input buffer containing a [[#SystemDeliveryInfo]], a type-0x5 input buffer containing an array of [[#SystemDeliveryInfo]], a type-0x5 input buffer containing an array of [[#ApplicationDeliveryInfo]], and returns an output s32.&lt;br /&gt;
&lt;br /&gt;
This determines the latest version (RequiredSystemVersion) from the input [[#ApplicationDeliveryInfo]] array (ApplicationDeliveryProtocolVersion and the HMAC are also validated), using value 0 if the array is empty.&lt;br /&gt;
&lt;br /&gt;
* [20.0.0+] The following code block now only runs when the SystemDeliveryInfoPlatform from the type-0x15 [[#SystemDeliveryInfo]] buffer matches the [[System_Settings|sys-setting]].&lt;br /&gt;
** It then loops through the [[#ApplicationDeliveryInfo]] array again:&lt;br /&gt;
** This uses functionality which essentially uses [[Shared_Database_services|pl:s]] GetFunctionBlackListSystemVersionToAuthorize with the [[#ApplicationDeliveryInfo]] ApplicationId and ApplicationFunctionAuthorizationId=0x5 then parses the output, using cached data if available. The error is returned on failure.&lt;br /&gt;
** tmp_version = out_u8 == 0 ? 0 : out_u32 + 0x10000;&lt;br /&gt;
** Then the current latest-version value is updated with tmp_version, if tmp_version is higher.&lt;br /&gt;
&lt;br /&gt;
If this version value is less than a state field, the state field value is used instead (state field originates from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;contents_delivery!required_system_version_to_deliver_application&amp;lt;/code&amp;gt;).&lt;br /&gt;
&lt;br /&gt;
Then this selects the [[#SystemDeliveryInfo]] with the latest version from the input array. The output s32 is an index in that array for the selected entry, -1 if none found.&lt;br /&gt;
&lt;br /&gt;
During the above loop it first calls the [[#SystemDeliveryInfo]] validation func, returning the Result on failure. Then it runs additional validation, with the [[#SystemDeliveryInfo]] entry being ignored on failure:&lt;br /&gt;
* The above latest-version value must be at least the version value from the type-0x15 [[#SystemDeliveryInfo]] buffer and the [[#SystemDeliveryInfo]] array entry.&lt;br /&gt;
* When HasExFat is set in the type-0x15 [[#SystemDeliveryInfo]] buffer, it must be set in the [[#SystemDeliveryInfo]] array entry.&lt;br /&gt;
* FirmwareVariationId in the type-0x15 [[#SystemDeliveryInfo]] buffer must not be 0xFF.&lt;br /&gt;
* UpdatableFirmwareGroupId in the [[#SystemDeliveryInfo]] array entry must not be 0xFF. The value must be within bounds of the settings array ([[System_Settings|sys-settings]] &amp;lt;code&amp;gt;contents_delivery!updatable_firmware_group_string&amp;lt;/code&amp;gt;).&lt;br /&gt;
* PlatformRegion in the [[#SystemDeliveryInfo]] array entry and the type-0x15 [[#SystemDeliveryInfo]] buffer must match.&lt;br /&gt;
* Lastly when the following is true, this indicates success: (settings_array[UpdatableFirmwareGroupId] &amp;gt;&amp;gt; {above FirmwareVariationId}) &amp;amp; 1.&lt;br /&gt;
&lt;br /&gt;
==== VerifyDeliveryProtocolVersion ====&lt;br /&gt;
Takes a type-0x15 input buffer containing a [[#SystemDeliveryInfo]], no output.&lt;br /&gt;
&lt;br /&gt;
This validates the [[#SystemDeliveryInfo]] HMAC and the protocol-version fields. Then an error is returned when SystemUpdateVersion is less than a state field, otherwise 0 is returned (state field originates from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;contents_delivery!required_system_version_to_deliver_application&amp;lt;/code&amp;gt;).&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationDeliveryInfo ====&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of [[#ApplicationDeliveryInfo|ApplicationDeliveryInfo]], an input u32 bitmask &amp;lt;code&amp;gt;nn::ns::ApplicationDeliveryAttributeTag&amp;lt;/code&amp;gt;, an [[NCM_services#ApplicationId|ApplicationId]], and returns an output s32 total_out.&lt;br /&gt;
&lt;br /&gt;
[11.0.0+] An error is thrown if LocalContentShare is not [[#IsLocalContentShareEnabled|enabled]].&lt;br /&gt;
&lt;br /&gt;
An error is thrown if any bit is set in ApplicationDeliveryAttributeTag besides bit1, this must also be &amp;lt;=0x3. The output array-count must be at least 1: only 1 entry will be written to this array (hence on success total_out will also only be 1 on success).&lt;br /&gt;
&lt;br /&gt;
[7.0.0+] An error is thrown if the state ref-count for [[#GetRequestServerStopper|RequestServerStopper]] is zero. [7.0.0-7.0.1] The func which checks this would also return success when a field prior to the previously mentioned field is 0 (checked before the ref-count).&lt;br /&gt;
&lt;br /&gt;
An error is thrown if [[NIM_services|nim]] ListApplicationApplyDeltaTask returns a task.&lt;br /&gt;
&lt;br /&gt;
HasApplicationRecord is called with the input [[NCM_services#ApplicationId|ApplicationId]], an error is returned if the record isn&#039;t found.&lt;br /&gt;
&lt;br /&gt;
[[#ApplicationDeliveryInfo|RequiredApplicationVersion]] is initially set to the output version from [[Shared_Database_services|avm]] GetLaunchRequiredVersion. Later when ContentMetaType == Application etc, it calls a func. This func uses [[NCM_services|ncm]] IContentMetaDatabase GetRequiredApplicationVersion. If the output version is higher than the [[#ApplicationDeliveryInfo|RequiredApplicationVersion]] field then the output version is written here. Immediately aferwards, it also checks whether the bit for Compacted is set from [[NCM_services|ncm]] IContentMetaDatabase GetAttributes, clearing [[#ApplicationDeliveryInfo|ApplicationVersion]] if the attribute is set.&lt;br /&gt;
&lt;br /&gt;
[20.0.0+] [[#ApplicationDeliveryInfo|ApplicationDeliveryInfo]] ContentMetaPlatform and ProperProgramExists are now set using data from [[NCM_services|ncm]].&lt;br /&gt;
&lt;br /&gt;
[20.0.0+] [[Shared_Database_services|pl:s]] GetFunctionBlackListSystemVersionToAuthorize with ApplicationFunctionAuthorizationId=0x5 is now used, the output version is written to [[#ApplicationDeliveryInfo|RequiredSystemVersion]] when it&#039;s higher than the value previously written here.&lt;br /&gt;
&lt;br /&gt;
[20.0.0+] [[Shared_Database_services|pl:s]] GetRequiredApplicationVersion with ApplicationFunctionAuthorizationId=0x5 is now used, the output version is written to [[#ApplicationDeliveryInfo|RequiredApplicationVersion]] when it&#039;s higher than the value previously written here.&lt;br /&gt;
&lt;br /&gt;
==== HasAllContentsToDeliver ====&lt;br /&gt;
Takes a type-0x5 input buffer containing an array of [[#ApplicationDeliveryInfo]], returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
The array-count must match 1.&lt;br /&gt;
&lt;br /&gt;
This uses the same LocalContentShare check as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
After validating the [[#ApplicationDeliveryInfo]], the output bool is set to [[#ApplicationDeliveryInfo|ApplicationDeliveryAttributeTag]] &amp;amp; 0x10000002 != 0x2, then this returns 0.&lt;br /&gt;
&lt;br /&gt;
==== CompareApplicationDeliveryInfo ====&lt;br /&gt;
Takes two type-0x5 input buffers containing an array of [[#ApplicationDeliveryInfo]], returns an output s32.&lt;br /&gt;
&lt;br /&gt;
This uses the same LocalContentShare check as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
The array-count for both buffers must be 1, otherwise an error is returned.&lt;br /&gt;
&lt;br /&gt;
Both [[#ApplicationDeliveryInfo]] are validated, then the application-version in the first/second buffer are compared. The output s32 is set to the comparison result: -1 for less than, 0 for equal, and 1 for higher than.&lt;br /&gt;
&lt;br /&gt;
==== CanDeliverApplication ====&lt;br /&gt;
Takes two type-0x5 input buffers containing an array of [[#ApplicationDeliveryInfo]], returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
The array-count for the second buffer must be 1, otherwise an error is returned.&lt;br /&gt;
&lt;br /&gt;
This uses the same LocalContentShare check as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
The second [[#ApplicationDeliveryInfo]] buffer is validated. An error is thrown when [[#ApplicationDeliveryInfo|ApplicationDeliveryAttributeTag]] (second buffer) &amp;amp; 0x3 != 0x2, likewise when bit28 is clear in this field (bitmask 0x10000000).&lt;br /&gt;
&lt;br /&gt;
The array-count for the first buffer must be &amp;lt;=1, otherwise an error is returned. If the array-count for the first buffer is 0, this will return 0 with the output bool set to 0. The first [[#ApplicationDeliveryInfo]] buffer is validated. An error is thrown when [[#ApplicationDeliveryInfo|ApplicationDeliveryAttributeTag]] (first buffer) bit1 is clear or bit0 set. An error is thrown when [[#ApplicationDeliveryInfo|ApplicationDeliveryAttributeTag]] (second buffer) bit1 is clear.&lt;br /&gt;
&lt;br /&gt;
When [[#ApplicationDeliveryInfo|RequiredApplicationVersion]] (first or second buffer) is higher than [[#ApplicationDeliveryInfo|ApplicationVersion]] (second buffer), this will return 0 with the output bool set to 0.&lt;br /&gt;
&lt;br /&gt;
When [[#ApplicationDeliveryInfo|ApplicationDeliveryAttributeTag]] (first buffer) bit28 is set (bitmask 0x10000000):&lt;br /&gt;
* When [[#ApplicationDeliveryInfo|ApplicationVersion]] (first buffer) &amp;gt;= [[#ApplicationDeliveryInfo|ApplicationVersion]] (second buffer), write 0 to the output bool, otherwise write 1. Then return 0.&lt;br /&gt;
Otherwise when the above bit28 is clear:&lt;br /&gt;
* When [[#ApplicationDeliveryInfo|ApplicationVersion]] (first buffer) &amp;gt; [[#ApplicationDeliveryInfo|ApplicationVersion]] (second buffer), write 0 to the output bool, otherwise write 1. Then return 0.&lt;br /&gt;
&lt;br /&gt;
==== ListContentMetaKeyToDeliverApplication ====&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of [[NCM_services#ContentMetaKey|ContentMetaKey]], a type-0x5 input buffer containing an array of [[#ApplicationDeliveryInfo]], a s32, and returns an output s32 total_out.&lt;br /&gt;
&lt;br /&gt;
This uses the same LocalContentShare check as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
The array-count for ContentMetaKey must be at least 1, and for ApplicationDeliveryInfo it must match 1.&lt;br /&gt;
&lt;br /&gt;
The [[#ApplicationDeliveryInfo|ApplicationDeliveryInfo]] is validated (ApplicationDeliveryProtocolVersion/HMAC). An error is thrown when [[#ApplicationDeliveryInfo|ApplicationDeliveryAttributeTag]] bit0 is set.&lt;br /&gt;
&lt;br /&gt;
This uses the same ref-count check as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
An error is thrown if [[NIM_services|nim]] ListApplicationApplyDeltaTask returns a task.&lt;br /&gt;
&lt;br /&gt;
This will only return 1 ContentMetaKey entry. This will not output the entry when the input s32 is larger than 0, or when [[#ApplicationDeliveryInfo|ApplicationDeliveryAttributeTag]] bit1 is clear.&lt;br /&gt;
&lt;br /&gt;
==== NeedsSystemUpdateToDeliverApplication ====&lt;br /&gt;
Takes a type-0x15 input buffer containing a [[#SystemDeliveryInfo]], a type-0x5 input buffer containing an array of [[#ApplicationDeliveryInfo]], and returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
This uses the same LocalContentShare check as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
The [[#SystemDeliveryInfo]] is validated (validation for ApplicationDeliveryProtocolVersion is enabled).&lt;br /&gt;
&lt;br /&gt;
The array-count must match 1.&lt;br /&gt;
&lt;br /&gt;
The [[#ApplicationDeliveryInfo]] is validated (ApplicationDeliveryProtocolVersion/HMAC).&lt;br /&gt;
&lt;br /&gt;
This then runs functionality similar to [[#SelectLatestSystemDeliveryInfo]]:&lt;br /&gt;
* [20.0.0+] The following code block now only runs when the SystemDeliveryInfoPlatform from the input [[#SystemDeliveryInfo]] matches the [[System_Settings|sys-setting]].&lt;br /&gt;
* Uses the same functionality as [[#SelectLatestSystemDeliveryInfo]] for GetFunctionBlackListSystemVersionToAuthorize, returning the Result on failure.&lt;br /&gt;
* The output bool is set to: out_u8!=0 &amp;amp;&amp;amp; out_u32 &amp;gt;= [[#SystemDeliveryInfo]] SystemUpdateVersion (only the upper 16bits are used from the SystemUpdateVersion).&lt;br /&gt;
&lt;br /&gt;
Otherwise when the output bool is still false, this sets the output bool by comparing system-version fields in the [[#SystemDeliveryInfo]]/[[#ApplicationDeliveryInfo]] and with a state field (state field originates from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;contents_delivery!required_system_version_to_deliver_application&amp;lt;/code&amp;gt;).&lt;br /&gt;
&lt;br /&gt;
==== EstimateRequiredSize ====&lt;br /&gt;
Takes a type-0x5 input buffer containing an array of [[NCM_services#ContentMetaKey|ContentMetaKey]], returns an output s64.&lt;br /&gt;
&lt;br /&gt;
When the array-count is less than 1, this will return 0 with the s64 set to 0.&lt;br /&gt;
&lt;br /&gt;
==== RequestReceiveApplication ====&lt;br /&gt;
Takes a type-0x5 input buffer containing an array of [[NCM_services#ContentMetaKey|ContentMetaKey]], a [[NCM_services#StorageId|StorageId]], an u16 port, an u32 Ipv4Address, an [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
[[qlaunch]] uses value Any for the StorageId, and value 55556 for the port.&lt;br /&gt;
&lt;br /&gt;
This uses the same LocalContentShare and ref-count checks as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
An error is thrown if [[NIM_services|nim]] ListApplicationApplyDeltaTask returns a task.&lt;br /&gt;
&lt;br /&gt;
HasApplicationRecord is called with the input [[NCM_services#ApplicationId|ApplicationId]], an error is returned if the record isn&#039;t found.&lt;br /&gt;
&lt;br /&gt;
This loops through the input [[NCM_services#ContentMetaKey|ContentMetaKey]] array, throwing an error if the [[NCM_services#ContentMetaType|ContentMetaType]] doesn&#039;t match Patch. The input array is copied into state which is used later by the thread for [[NIM_services|nim]] CreateLocalCommunicationReceiveApplicationTask, max entries is 0x12.&lt;br /&gt;
&lt;br /&gt;
This does various setup then creates the [[#IAsyncResult]] + the async thread which handles the [[#IAsyncResult]] operation. Then the thread does:&lt;br /&gt;
&lt;br /&gt;
* Calls a func which does:&lt;br /&gt;
** Throws an error if a state flag is set.&lt;br /&gt;
** Uses [[NIM_services|nim]] CreateLocalCommunicationReceiveApplicationTask, returning the Result on failure.&lt;br /&gt;
** Uses [[NIM_services|nim]] RequestLocalCommunicationReceiveApplicationTaskRun, returning the Result on failure. Waits for the IAsyncResult operation from this to finish, then uses the Get cmd to get the output Result.&lt;br /&gt;
*** When the Result from Get is an error, a func is called for filling in the [[#IAsyncResult|IAsyncResult]] ErrorContext with Type4.&lt;br /&gt;
** Handles cleanup and returns.&lt;br /&gt;
* On success, this loads various data which is then used for saving a SystemPlayReport when the cached [[System_Settings|system-setting]] &amp;quot;systemreport!enabled&amp;quot; is set.&lt;br /&gt;
** The EventId is &amp;quot;receive_app_contents&amp;quot; with ApplicationId &amp;lt;NS ProgramId&amp;gt;.&lt;br /&gt;
** This report has the following fields:&lt;br /&gt;
*** &amp;quot;ApplicationId&amp;quot;&lt;br /&gt;
*** &amp;quot;DestinationVersion&amp;quot;&lt;br /&gt;
*** &amp;quot;SourceVersion&amp;quot;&lt;br /&gt;
*** &amp;quot;HasApplicationEntity&amp;quot;&lt;br /&gt;
*** &amp;quot;HasPatchEntity&amp;quot;&lt;br /&gt;
*** &amp;quot;ApplicationStorageId&amp;quot;&lt;br /&gt;
*** &amp;quot;PatchStorageId&amp;quot;&lt;br /&gt;
*** &amp;quot;Size&amp;quot;&lt;br /&gt;
*** &amp;quot;ThroughputKBps&amp;quot;&lt;br /&gt;
&lt;br /&gt;
==== CommitReceiveApplication ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
This uses the same LocalContentShare and ref-count checks as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
An error is thrown if [[NIM_services|nim]] ListApplicationApplyDeltaTask returns a task.&lt;br /&gt;
&lt;br /&gt;
==== GetReceiveApplicationProgress ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output [[#ReceiveApplicationProgress]].&lt;br /&gt;
&lt;br /&gt;
This uses the same ref-count check as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
An error is thrown if [[NIM_services|nim]] ListApplicationApplyDeltaTask returns a task.&lt;br /&gt;
&lt;br /&gt;
Uses [[NIM_services|nim]] ListApplicationLocalCommunicationReceiveApplicationTask, throwing an error if no task is returned. Then [[NIM_services|nim]] GetLocalCommunicationReceiveApplicationTaskInfo is used, returning the error from there on failure. Lastly, this writes the 0x10-bytes from output+8 from the latter cmd to the output [[#ReceiveApplicationProgress]], and returns 0.&lt;br /&gt;
&lt;br /&gt;
==== RequestSendApplication ====&lt;br /&gt;
Takes a type-0x5 input buffer containing an array of [[NCM_services#ContentMetaKey|ContentMetaKey]], an u16 port, an u32 Ipv4Address, an [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
[[qlaunch]] uses value 55556 for the port.&lt;br /&gt;
&lt;br /&gt;
This uses the same LocalContentShare and ref-count checks as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
An error is thrown if [[NIM_services|nim]] ListApplicationApplyDeltaTask returns a task.&lt;br /&gt;
&lt;br /&gt;
This does various setup and loops through the input ContentMetaKey array for initializing the array passed to the nim cmd during the async task. This loop does the following:&lt;br /&gt;
* Throws an error if the [[NCM_services#ContentMetaType|ContentMetaType]] in the ContentMetaKey doesn&#039;t match Patch.&lt;br /&gt;
* Calls a func with the ContentMetaKey and the ApplicationId, throwing an error if the output value is 0.&lt;br /&gt;
* Calls a func with the ContentMetaKey for getting the StorageId. This essentially loops through each valid ncm [[NCM_services|IContentMetaDatabase]] using cmd [[NCM_services|Has]] with the input ContentMetaKey, returning the relevant StorageId when found.&lt;br /&gt;
* The ContentMetaKey and the StorageId are copied into a tmp struct.&lt;br /&gt;
* if (ContentMetaType==Patch &amp;amp;&amp;amp; StorageId==GameCard) { &amp;lt;call a func etc&amp;gt; }&lt;br /&gt;
* Copies the above tmp struct into the async task state array.&lt;br /&gt;
&lt;br /&gt;
This then creates the [[#IAsyncResult]] + the async thread which handles the [[#IAsyncResult]] operation. Then the thread does:&lt;br /&gt;
&lt;br /&gt;
* Calls a func which does:&lt;br /&gt;
** Throws an error if a state flag is set.&lt;br /&gt;
** Uses [[NIM_services|nim]] CreateLocalCommunicationSendApplicationTask, returning the Result on failure.&lt;br /&gt;
** Uses [[NIM_services|nim]] RequestLocalCommunicationSendApplicationTaskRun, returning the Result on failure. Waits for the IAsyncResult operation from this to finish, then uses the Get cmd to get the output Result.&lt;br /&gt;
*** When the Result from Get is an error, a func is called for filling in the [[#IAsyncResult|IAsyncResult]] ErrorContext with Type4.&lt;br /&gt;
** Handles cleanup and returns.&lt;br /&gt;
* On success, this loads various data which is then used for saving a SystemPlayReport when the cached [[System_Settings|system-setting]] &amp;quot;systemreport!enabled&amp;quot; is set.&lt;br /&gt;
** The EventId is &amp;quot;send_app_contents&amp;quot; with ApplicationId &amp;lt;NS ProgramId&amp;gt;.&lt;br /&gt;
** This report has the following fields:&lt;br /&gt;
*** &amp;quot;ApplicationId&amp;quot;&lt;br /&gt;
*** &amp;quot;Version&amp;quot;&lt;br /&gt;
*** &amp;quot;ApplicationStorageId&amp;quot;&lt;br /&gt;
*** &amp;quot;PatchStorageId&amp;quot;&lt;br /&gt;
&lt;br /&gt;
==== GetSendApplicationProgress ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output [[#SendApplicationProgress]].&lt;br /&gt;
&lt;br /&gt;
Same as [[#GetReceiveApplicationProgress]] except this is the Send version, and uses [[NIM_services|nim]] ListApplicationLocalCommunicationSendApplicationTask/GetLocalCommunicationSendApplicationTaskInfo instead. The data copied to output is also swapped: u64 nim_out+0x8 is copied to out+0x8, and u64 nim_out+0x10 is copied to out+0x0.&lt;br /&gt;
&lt;br /&gt;
==== CompareSystemDeliveryInfo ====&lt;br /&gt;
Takes two type-0x15 input buffers containing a [[#SystemDeliveryInfo]], returns an output s32.&lt;br /&gt;
&lt;br /&gt;
This is essentially the same as [[#CompareApplicationDeliveryInfo]], except this compares the [[#SystemDeliveryInfo]] SystemUpdate version.&lt;br /&gt;
&lt;br /&gt;
==== ListNotCommittedContentMeta ====&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of [[NCM_services#ContentMetaKey|ContentMetaKey]], a s32, an [[NCM_services#ApplicationId|ApplicationId]], returns an output s32 total_out.&lt;br /&gt;
&lt;br /&gt;
This uses the same ref-count check as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
An error is thrown if [[NIM_services|nim]] ListApplicationApplyDeltaTask returns a task.&lt;br /&gt;
&lt;br /&gt;
==== RecoverDownloadTask ====&lt;br /&gt;
Takes a type-0x5 input buffer containing an array of {unknown} and an input u64, no output.&lt;br /&gt;
&lt;br /&gt;
This uses the same LocalContentShare and ref-count checks as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationDeliveryInfoHash ====&lt;br /&gt;
Takes a type-0x5 input buffer containing an array of [[#ApplicationDeliveryInfo]], returns an output 0x20-byte SHA256 hash.&lt;br /&gt;
&lt;br /&gt;
This uses the same LocalContentShare check as [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]].&lt;br /&gt;
&lt;br /&gt;
This extracts data from the input array for hashing with SHA256, with validation being done when handling each entry (ApplicationDeliveryProtocolVersion/HMAC).&lt;br /&gt;
&lt;br /&gt;
The 0x14-bytes from [[#ApplicationDeliveryInfo|ApplicationDeliveryInfo]]+0x8 are copied into a 0x18-byte struct entry in an array buffer, with the last 4-bytes being cleared. Then each 0x18-byte struct entry is hashed.&lt;br /&gt;
&lt;br /&gt;
==== Cmd2019 ====&lt;br /&gt;
Takes a type-0x15 input buffer containing a [[#SystemDeliveryInfo]], a type-0x5 input buffer containing an array of [[#ApplicationDeliveryInfo]], a type-0x5 input buffer containing an array of [[#ApplicationDeliveryInfo]], returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
This is essentially an extended version of [[#CanDeliverApplication|CanDeliverApplication]], with additional functionality for determining platform compatibility.&lt;br /&gt;
&lt;br /&gt;
This calls a func for validating the [[#SystemDeliveryInfo]] from the type-0x15 buffer, returning the Result on failure.&lt;br /&gt;
&lt;br /&gt;
Then [[#CanDeliverApplication|CanDeliverApplication]] is called with the output bool and the input arrays, returning the Result on failure.&lt;br /&gt;
&lt;br /&gt;
If the output bool is set after calling the above, it then calls a func with the output bool, the second [[#ApplicationDeliveryInfo]] buffer, and the [[#SystemDeliveryInfo]] from the type-0x15 buffer. This func does the following:&lt;br /&gt;
* When the SystemDeliveryInfoPlatform from the input [[#SystemDeliveryInfo]] matches the [[System_Settings|sys-setting]], it does the following:&lt;br /&gt;
** Uses [[Shared_Database_services|pl:s]] RequestApplicationFunctionAuthorizationByApplicationId with the [[#ApplicationDeliveryInfo]] ApplicationId/ApplicationVersion and ApplicationFunctionAuthorizationId=0x5, handling the Result on failure.&lt;br /&gt;
* When the platform fields from the input [[#SystemDeliveryInfo]]/[[#ApplicationDeliveryInfo]] match, write 1 to the output bool and return 0. Otherwise:&lt;br /&gt;
** When the [[#SystemDeliveryInfo]] SystemDeliveryInfoPlatform is 0x1 (Ounce): *output = [[#ApplicationDeliveryInfo|ContentMetaPlatform]] == 0 &amp;amp;&amp;amp; [[#ApplicationDeliveryInfo|ProperProgramExists]] == 0;&lt;br /&gt;
** When the [[#SystemDeliveryInfo]] SystemDeliveryInfoPlatform is 0x0 (NX): write 0 to the output bool and return 0.&lt;br /&gt;
** Otherwise, Abort.&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationRightsOnClient ====&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of [[#ApplicationRightsOnClient]], an input u32 flags, an [[NCM_services#ApplicationId|ApplicationId]], an [[Account_services#Uid|Uid]], returns 4-bytes of output for total output entries.&lt;br /&gt;
&lt;br /&gt;
Official sw has at least two wrappers which use this cmd: one with an all-zero Uid, one with an user-specified Uid. With both of these, the passed flags are hard-coded to value 0x3.&lt;br /&gt;
&lt;br /&gt;
For the output array count, [[qlaunch]] uses value 3.&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationTerminateResult ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output u32 Result.&lt;br /&gt;
&lt;br /&gt;
==== GetRightsEnvironmentHandleForApplication ====&lt;br /&gt;
No input, returns a total of 8-bytes of output.&lt;br /&gt;
&lt;br /&gt;
[9.0.0+] Now takes a total of 8-bytes of input, returns a total of 8-bytes of output.&lt;br /&gt;
&lt;br /&gt;
==== RequestNoDownloadRightsErrorResolution ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
The data that can be read from the [[#IAsyncValue]] is [[#NoDownloadRightsErrorResolution]].&lt;br /&gt;
&lt;br /&gt;
See [[#RequestApplicationUpdateInfo]] regarding nifm.&lt;br /&gt;
&lt;br /&gt;
==== RequestResolveNoDownloadRightsError ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
The data that can be read from the [[#IAsyncValue]] is [[#NoDownloadRightsErrorResolution]].&lt;br /&gt;
&lt;br /&gt;
See [[#RequestApplicationUpdateInfo]] regarding nifm.&lt;br /&gt;
&lt;br /&gt;
==== GetPromotionInfo ====&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of [[#PromotionInfo]], a type-0x5 input buffer containing an array of u64 [[NCM_services#ApplicationId|ApplicationIds]], a type-0x5 input buffer containing an array of [[Account_services#Uid|Uids]], no output.&lt;br /&gt;
&lt;br /&gt;
Official sw uses hard-coded value 1 for the count with each of these arrays.&lt;br /&gt;
&lt;br /&gt;
==== ListPromotionInfo ====&lt;br /&gt;
[20.0.0+] The struct size for the output buffer array is now 0x28-bytes instead of 0x20-bytes.&lt;br /&gt;
&lt;br /&gt;
==== ImportPromotionJsonForDebug ====&lt;br /&gt;
Takes a type-0x5 input buffer, no output.&lt;br /&gt;
&lt;br /&gt;
The output from [[Settings_services#GetDebugModeFlag]] must be 1, otherwise an error is returned.&lt;br /&gt;
&lt;br /&gt;
==== ClearPromotionInfoForDebug ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
The output from [[Settings_services#GetDebugModeFlag]] must be 1, otherwise an error is returned.&lt;br /&gt;
&lt;br /&gt;
This just clears 0xC-bytes in state.&lt;br /&gt;
&lt;br /&gt;
==== CreateApplicationResource ====&lt;br /&gt;
Takes an input [[#ApplicationResourceType]]. Returns an [[#IApplicationResource]].&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationResource ====&lt;br /&gt;
Takes an input u64 ProcessId and an input [[#ApplicationResourceType]]. Returns an [[#IApplicationResource]].&lt;br /&gt;
&lt;br /&gt;
==== LaunchMicroApplication ====&lt;br /&gt;
[18.0.0+] Now takes a total of 0x50 bytes of input.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] Now takes a total of 0x80 bytes of input.&lt;br /&gt;
&lt;br /&gt;
==== CreateApplicationInstance ====&lt;br /&gt;
[18.0.0+] Now takes a total of 0x50 bytes of input.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] Now takes a total of 0x80 bytes of input.&lt;br /&gt;
&lt;br /&gt;
==== RegisterDeviceLockKey ====&lt;br /&gt;
Takes a type-0x5 input buffer containing an InArray of u8, no output.&lt;br /&gt;
&lt;br /&gt;
User-processes expose this with two funcs: one which uses an user-specified u8 array directly, while the other uses [[HID_services#NpadButtonSet|NpadButton]].&lt;br /&gt;
&lt;br /&gt;
This does SHA256 hashing, etc.&lt;br /&gt;
&lt;br /&gt;
==== UnregisterDeviceLockKey ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Runs code identical to [[#RegisterDeviceLockKey]], except the passed buffer/size are 0.&lt;br /&gt;
&lt;br /&gt;
==== VerifyDeviceLockKey ====&lt;br /&gt;
Takes a type-0x5 input buffer containing an InArray of u8, no output.&lt;br /&gt;
&lt;br /&gt;
User-processes expose this with two funcs: one which uses an user-specified u8 array directly, while the other uses [[HID_services#NpadButtonSet|NpadButton]].&lt;br /&gt;
&lt;br /&gt;
This runs hashing similar to [[#RegisterDeviceLockKey]], with the calculated hash being verified with the one from state.&lt;br /&gt;
&lt;br /&gt;
==== HideApplicationIcon ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== ShowApplicationIcon ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== HideApplicationTitle ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== ShowApplicationTitle ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== EnableGameCard ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== DisableGameCard ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== EnableLocalContentShare ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== DisableLocalContentShare ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== IsApplicationIconHidden ====&lt;br /&gt;
No input, returns an output bool.&lt;br /&gt;
&lt;br /&gt;
==== IsApplicationTitleHidden ====&lt;br /&gt;
No input, returns an output bool.&lt;br /&gt;
&lt;br /&gt;
==== IsGameCardEnabled ====&lt;br /&gt;
No input, returns an output bool.&lt;br /&gt;
&lt;br /&gt;
==== IsLocalContentShareEnabled ====&lt;br /&gt;
No input, returns an output bool.&lt;br /&gt;
&lt;br /&gt;
Various Deliver cmds now run essentially the same code as IsLocalContentShareEnabled, with an error being returned when it&#039;s not enabled.&lt;br /&gt;
&lt;br /&gt;
==== Cmd4026 ====&lt;br /&gt;
Takes an input u64, returns an [[#IHostSession|IHostSession]].&lt;br /&gt;
&lt;br /&gt;
The input u64 must match a state field.&lt;br /&gt;
&lt;br /&gt;
This initializes [[LDN_services|ldn]] etc, and creates a network.&lt;br /&gt;
&lt;br /&gt;
==== Cmd4027 ====&lt;br /&gt;
Takes an input u64, returns an [[#IClientSession|IClientSession]].&lt;br /&gt;
&lt;br /&gt;
The input u64 must match a state field.&lt;br /&gt;
&lt;br /&gt;
This initializes [[LDN_services|ldn]] etc.&lt;br /&gt;
&lt;br /&gt;
=== IGameCardStopper ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IGameCardStopper&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This interface has no commands.&lt;br /&gt;
&lt;br /&gt;
=== IRequestServerStopper ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IRequestServerStopper&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This interface has no commands.&lt;br /&gt;
&lt;br /&gt;
=== IProgressMonitorForDeleteUserSaveDataAll ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IProgressMonitorForDeleteUserSaveDataAll&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetSystemEvent&lt;br /&gt;
|-&lt;br /&gt;
| 1 || IsFinished&lt;br /&gt;
|-&lt;br /&gt;
| 2 || GetResult&lt;br /&gt;
|-&lt;br /&gt;
| 10 || GetProgress&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
When closing the object, official sw uses IsFinished first, asserting when the output bool is false.&lt;br /&gt;
&lt;br /&gt;
* GetSystemEvent: No input, returns an output Event handle. [[qlaunch]] doesn&#039;t use this.&lt;br /&gt;
&lt;br /&gt;
* IsFinished: No input, returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
* GetResult: No input/output.&lt;br /&gt;
&lt;br /&gt;
* GetProgress: No input, returns an output [[#ProgressForDeleteUserSaveDataAll]]. Official sw writes this struct directly to object state.&lt;br /&gt;
&lt;br /&gt;
=== IProgressAsyncResult ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IProgressAsyncResult&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || Get&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Cancel&lt;br /&gt;
|-&lt;br /&gt;
| 2 || GetProgress&lt;br /&gt;
|-&lt;br /&gt;
| 3 || GetDetailResult&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [4.0.0+] GetErrorContext&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IHostSession ===&lt;br /&gt;
This is &amp;quot;nn::ns::vphym::detail::IHostSession&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [20.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || &lt;br /&gt;
|-&lt;br /&gt;
| 1 || &lt;br /&gt;
|-&lt;br /&gt;
| 2 || &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Cmd0 ====&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
The async task does the following:&lt;br /&gt;
* This waits for a client to connect.&lt;br /&gt;
* The [[LDN_services|NodeInfo]] UserName is converted into two u64s, which are used to locate a state entry with matching values.&lt;br /&gt;
* The client [[LDN_services|NodeInfo]] Ipv4Address is copied into state.&lt;br /&gt;
* Then a ptr to the above located state entry is also written into state.&lt;br /&gt;
&lt;br /&gt;
==== Cmd1 ====&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
The async task uses [[NIM_services|nim]] cmd2018 or cmd2027, depending on a state field. Once finished when a state flag is set, [[LDN_services|ldn]] is finalized and that state flag is cleared.&lt;br /&gt;
&lt;br /&gt;
==== Cmd2 ====&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
The async task uses [[NIM_sevices|nim]] cmd2024.&lt;br /&gt;
&lt;br /&gt;
=== IClientSession ===&lt;br /&gt;
This is &amp;quot;nn::ns::vphym::detail::IClientSession&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [20.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || &lt;br /&gt;
|-&lt;br /&gt;
| 1 || &lt;br /&gt;
|-&lt;br /&gt;
| 2 || &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Cmd0 ====&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
The async task does the following:&lt;br /&gt;
* Uses [[LDN_services|ldn]] Scan.&lt;br /&gt;
* After a [[LDN_services|NodeInfo]] is found with a matching UserName, the Ipv4Address for it is copied into state.&lt;br /&gt;
* If a timeout didn&#039;t occur and a valid NodeInfo was found, it proceeds with connecting to the network.&lt;br /&gt;
&lt;br /&gt;
==== Cmd1 ====&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
The async task uses [[NIM_services|nim]] cmd2019 or cmd2028, depending on a state field. Once finished when a state flag is set, [[LDN_services|ldn]] is finalized and that state flag is cleared.&lt;br /&gt;
&lt;br /&gt;
==== Cmd2 ====&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
This is identical to [[#IHostSession|IHostSession]] Cmd2.&lt;br /&gt;
&lt;br /&gt;
=== IApplicationVersionInterface ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IApplicationVersionInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [4.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetLaunchRequiredVersion&lt;br /&gt;
|-&lt;br /&gt;
| 1 || UpgradeLaunchRequiredVersion&lt;br /&gt;
|-&lt;br /&gt;
| 35 || UpdateVersionList&lt;br /&gt;
|-&lt;br /&gt;
| 36 || PushLaunchVersion&lt;br /&gt;
|-&lt;br /&gt;
| 37 || ListRequiredVersion&lt;br /&gt;
|-&lt;br /&gt;
| 800 || RequestVersionList&lt;br /&gt;
|-&lt;br /&gt;
| 801 || ListVersionList&lt;br /&gt;
|-&lt;br /&gt;
| 802 || [[#RequestVersionListData]]&lt;br /&gt;
|-&lt;br /&gt;
| 900 || [12.0.0+] ImportAutoUpdatePolicyJsonForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 901 || [12.0.0+] ListDefaultAutoUpdatePolicy&lt;br /&gt;
|-&lt;br /&gt;
| 902 || [12.0.0+] ListAutoUpdatePolicyForSpecificApplication&lt;br /&gt;
|-&lt;br /&gt;
| 1000 || PerformAutoUpdate&lt;br /&gt;
|-&lt;br /&gt;
| 1001 || [11.0.0+] ListAutoUpdateSchedule&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== RequestVersionListData ====&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
The data that can be read from the [[#IAsyncValue]] is [[#VersionListData]].&lt;br /&gt;
&lt;br /&gt;
=== IContentManagementInterface ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IContentManagementInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [[#CalculateApplicationOccupiedSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 43 || [[#CheckSdCardMountStatus]]&lt;br /&gt;
|-&lt;br /&gt;
| 47 || [[#GetTotalSpaceSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 48 || [[#GetFreeSpaceSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 58 || [20.1.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 71 || [20.1.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 600 || [[#CountApplicationContentMeta]]&lt;br /&gt;
|-&lt;br /&gt;
| 601 || [[#ListApplicationContentMetaStatus]]&lt;br /&gt;
|-&lt;br /&gt;
| 605 || [[#ListApplicationContentMetaStatusWithRightsCheck]]&lt;br /&gt;
|-&lt;br /&gt;
| 607 || [[#IsAnyApplicationRunning]]&lt;br /&gt;
|-&lt;br /&gt;
| 608 || [21.0.0+]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== CalculateApplicationOccupiedSize ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output [[#ApplicationOccupiedSize]].&lt;br /&gt;
&lt;br /&gt;
==== CheckSdCardMountStatus ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== CountApplicationContentMeta ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output s32.&lt;br /&gt;
&lt;br /&gt;
==== ListApplicationContentMetaStatusWithRightsCheck ====&lt;br /&gt;
Same input/output as [[#ListApplicationContentMetaStatus]].&lt;br /&gt;
&lt;br /&gt;
==== IsAnyApplicationRunning ====&lt;br /&gt;
No input, returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
=== IDocumentInterface ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IDocumentInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 21 || GetApplicationContentPath&lt;br /&gt;
|-&lt;br /&gt;
| 23 || ResolveApplicationContentPath&lt;br /&gt;
|-&lt;br /&gt;
| 92 || [5.0.0+] GetRunningApplicationProgramId&lt;br /&gt;
|-&lt;br /&gt;
| 100 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 101 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 2524 || [19.0.0+] &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Cmd100 ====&lt;br /&gt;
Takes a type-0x16 output buffer containing a 0x300-byte struct, an input u8, an u64. Returns two output u8s.&lt;br /&gt;
&lt;br /&gt;
==== Cmd101 ====&lt;br /&gt;
Takes a type-0x16 output buffer containing a 0x300-byte struct, an input u8, an u64. Returns an output u8, an u8 [[Filesystem_services|ContentAttributes]], and a [[NCM_services#ProgramId|ProgramId]].&lt;br /&gt;
&lt;br /&gt;
This is similar to Cmd2524. On [S2] this is used instead of Cmd2524.&lt;br /&gt;
&lt;br /&gt;
==== Cmd2524 ====&lt;br /&gt;
Takes a type-0x16 output buffer containing a 0x300-byte struct, an input u8, an u64. Returns an output u8 [[Filesystem_services|ContentAttributes]] and a [[NCM_services#ProgramId|ProgramId]].&lt;br /&gt;
&lt;br /&gt;
The user-process uses the output from this as the input for [[Filesystem_services|OpenFileSystemWithId]] (out-buffer is used as the [[Filesystem_services|FspPath]]).&lt;br /&gt;
&lt;br /&gt;
=== IDownloadTaskInterface ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IDownloadTaskInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 701 || [[#ClearTaskStatusList]]&lt;br /&gt;
|-&lt;br /&gt;
| 702 || [[#RequestDownloadTaskList]]&lt;br /&gt;
|-&lt;br /&gt;
| 703 || [[#RequestEnsureDownloadTask]]&lt;br /&gt;
|-&lt;br /&gt;
| 704 || [[#ListDownloadTaskStatus]]&lt;br /&gt;
|-&lt;br /&gt;
| 705 || [[#RequestDownloadTaskListData]]&lt;br /&gt;
|-&lt;br /&gt;
| 706 || [4.0.0+] [[#TryCommitCurrentApplicationDownloadTask]]&lt;br /&gt;
|-&lt;br /&gt;
| 707 || [4.0.0+] [[#EnableAutoCommit]]&lt;br /&gt;
|-&lt;br /&gt;
| 708 || [4.0.0+] [[#DisableAutoCommit]]&lt;br /&gt;
|-&lt;br /&gt;
| 709 || [4.0.0+] [[#TriggerDynamicCommitEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 710 || [20.0.0+]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== ClearTaskStatusList ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== RequestDownloadTaskList ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== RequestEnsureDownloadTask ====&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
==== ListDownloadTaskStatus ====&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of [[#DownloadTaskStatus]], returns an output s32 total_out.&lt;br /&gt;
&lt;br /&gt;
A maximum of 0x100 tasks can be stored in state.&lt;br /&gt;
&lt;br /&gt;
==== TryCommitCurrentApplicationDownloadTask ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== EnableAutoCommit ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== DisableAutoCommit ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== TriggerDynamicCommitEvent ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
=== IReadOnlyApplicationRecordInterface ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IReadOnlyApplicationRecordInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [5.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || HasApplicationRecord || Same as [[#IApplicationManagerInterface]] cmd 910&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [10.0.0+] NotifyApplicationFailure ||&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [10.0.0+] IsDataCorruptedResult ||&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [20.0.0+] [[#ListApplicationRecord|ListApplicationRecord]] ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IReadOnlyApplicationControlDataInterface ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IReadOnlyApplicationControlDataInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [5.1.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#GetApplicationControlData]] || Same as [[#IApplicationManagerInterface]] cmd 400&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#GetApplicationDesiredLanguage]] || Same as [[#IApplicationManagerInterface]] cmd 55&lt;br /&gt;
|-&lt;br /&gt;
| 2 || ConvertApplicationLanguageToLanguageCode || Same as [[#IApplicationManagerInterface]] cmd 59&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [[#ConvertLanguageCodeToApplicationLanguage]] || Same as [[#IApplicationManagerInterface]] cmd 60&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [9.0.0+] SelectApplicationDesiredLanguage ||&lt;br /&gt;
|-&lt;br /&gt;
| 5 || [19.0.0+] || Same as [[#IApplicationManagerInterface]] cmd 411&lt;br /&gt;
|-&lt;br /&gt;
| 6 || [19.0.0+] || Same as [[#IApplicationManagerInterface]] cmd 416&lt;br /&gt;
|-&lt;br /&gt;
| 7 || [20.0.0+] || Same as [[#IApplicationManagerInterface]] cmd 921&lt;br /&gt;
|-&lt;br /&gt;
| 8 || [20.0.0+] || Same as [[#IApplicationManagerInterface]] cmd 922&lt;br /&gt;
|-&lt;br /&gt;
| 9 || [20.0.0+] || Same as [[#IApplicationManagerInterface]] cmd 923&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [20.0.0+] || Same as [[#IApplicationManagerInterface]] cmd 421&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [20.0.0+] || Same as [[#IApplicationManagerInterface]] cmd 422&lt;br /&gt;
|-&lt;br /&gt;
| 12 || [20.0.0+] || Same as [[#IApplicationManagerInterface]] cmd 423&lt;br /&gt;
|-&lt;br /&gt;
| 13 || [20.0.0+] || Same as [[#IApplicationManagerInterface]] cmd 407&lt;br /&gt;
|-&lt;br /&gt;
| 14 || [20.0.0+] || Same as [[#IApplicationManagerInterface]] cmd 408&lt;br /&gt;
|-&lt;br /&gt;
| 15 || [20.0.0+] || Same as [[#IApplicationManagerInterface]] cmd 415&lt;br /&gt;
|-&lt;br /&gt;
| 16 || [20.0.0+] ||&lt;br /&gt;
|-&lt;br /&gt;
| 17 || [20.1.0+] || Same as [[#IApplicationManagerInterface]] cmd 933&lt;br /&gt;
|-&lt;br /&gt;
| 18 || [21.0.0+] ||&lt;br /&gt;
|-&lt;br /&gt;
| 19 || [21.0.0+] ||&lt;br /&gt;
|-&lt;br /&gt;
| 20 || [21.0.0+] ||&lt;br /&gt;
|-&lt;br /&gt;
| 21 || [21.0.0+] ||&lt;br /&gt;
|-&lt;br /&gt;
| 22 || [21.0.0+] ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IDynamicRightsInterface ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IDynamicRightsInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [6.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#RequestApplicationRightsOnServer]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#RequestAssignRights]]&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [[#DeprecatedRequestAssignRightsToResume]]&lt;br /&gt;
|-&lt;br /&gt;
| 5 || [[#VerifyActivatedRightsOwners]]&lt;br /&gt;
|-&lt;br /&gt;
| 6 || [[#DeprecatedGetApplicationRightsStatus]]&lt;br /&gt;
|-&lt;br /&gt;
| 7 || [[#RequestPrefetchForDynamicRights]]&lt;br /&gt;
|-&lt;br /&gt;
| 8 || [[#GetDynamicRightsState]]&lt;br /&gt;
|-&lt;br /&gt;
| 9 || [7.0.0+] [[#RequestApplicationRightsOnServerToResume]]&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [7.0.0+] [[#RequestAssignRightsToResume]]&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [7.0.0+] [[#GetActivatedRightsUsers]]&lt;br /&gt;
|-&lt;br /&gt;
| 12 || [8.0.0+] [[#GetApplicationRightsStatus]]&lt;br /&gt;
|-&lt;br /&gt;
| 13 || [8.0.0+] [[#GetRunningApplicationStatus]]&lt;br /&gt;
|-&lt;br /&gt;
| 14 || [10.0.0-15.0.1] SelectApplicationLicense&lt;br /&gt;
|-&lt;br /&gt;
| 15 || [12.0.0+] [[#RequestContentsAuthorizationToken]]&lt;br /&gt;
|-&lt;br /&gt;
| 16 || [13.0.0+] QualifyUser&lt;br /&gt;
|-&lt;br /&gt;
| 17 || [13.0.0+] QualifyUserWithProcessId&lt;br /&gt;
|-&lt;br /&gt;
| 18 || [13.0.0+] NotifyApplicationRightsCheckStart&lt;br /&gt;
|-&lt;br /&gt;
| 19 || [13.0.0+] UpdateUserList&lt;br /&gt;
|-&lt;br /&gt;
| 20 || [13.0.0+] IsRightsLostUser&lt;br /&gt;
|-&lt;br /&gt;
| 21 || [13.1.0+] SetRequiredAddOnContentsOnContentsAvailabilityTransition&lt;br /&gt;
|-&lt;br /&gt;
| 22 || [14.0.0+] GetLimitedApplicationLicense&lt;br /&gt;
|-&lt;br /&gt;
| 23 || [14.0.0+] GetLimitedApplicationLicenseUpgradableEvent&lt;br /&gt;
|-&lt;br /&gt;
| 24 || [14.0.0+] NotifyLimitedApplicationLicenseUpgradableEventForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 25 || [14.0.0+] RequestProceedDynamicRightsState&lt;br /&gt;
|-&lt;br /&gt;
| 26 || [18.0.0+] HasAccountRestrictedRightsInRunningApplications&lt;br /&gt;
|-&lt;br /&gt;
| 27 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 28 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 29 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 30 || [21.0.0+]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== RequestApplicationRightsOnServer ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], an [[Account_services#Uid|Uid]] and an u32. Returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
==== RequestAssignRights ====&lt;br /&gt;
Takes a type-0x5 input buffer containing an array of &amp;quot;nn::ns::ApplicationRightsOnServer&amp;quot;. Returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
==== DeprecatedRequestAssignRightsToResume ====&lt;br /&gt;
Takes an input u64 &amp;quot;nn::ns::RightsEnvironmentHandle&amp;quot; and an [[Account_services#Uid|Uid]]. Returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
==== VerifyActivatedRightsOwners ====&lt;br /&gt;
Takes an input u64 &amp;quot;nn::ns::RightsEnvironmentHandle&amp;quot;. No output.&lt;br /&gt;
&lt;br /&gt;
==== DeprecatedGetApplicationRightsStatus ====&lt;br /&gt;
Takes an input u64 &amp;quot;nn::ns::RightsEnvironmentHandle&amp;quot;. Returns a bool &amp;quot;nn::ns::ApplicationRightsStatus&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==== RequestPrefetchForDynamicRights ====&lt;br /&gt;
Takes an input [[Account_services#Uid|Uid]]. Returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
==== GetDynamicRightsState ====&lt;br /&gt;
No input. Returns a bool &amp;quot;nn::ns::DynamicRightsState&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==== RequestApplicationRightsOnServerToResume ====&lt;br /&gt;
Takes an input u64 &amp;quot;nn::ns::RightsEnvironmentHandle&amp;quot;. Returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
==== RequestAssignRightsToResume ====&lt;br /&gt;
Takes an input u64 &amp;quot;nn::ns::RightsEnvironmentHandle&amp;quot;. Returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
==== GetActivatedRightsUsers ====&lt;br /&gt;
Takes an input u64 &amp;quot;nn::ns::RightsEnvironmentHandle&amp;quot;. Returns a bool, an u32 and a type-0x6 output buffer containing an array of [[Account_services#Uid|Uid]].&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationRightsStatus ====&lt;br /&gt;
Takes an input &amp;quot;nn::ns::RightsEnvironmentHandle&amp;quot;. Returns 2 bools &amp;quot;nn::ns::ApplicationRightsStatus&amp;quot; and &amp;quot;nn::ns::ApplicationLicenseType&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==== GetRunningApplicationStatus ====&lt;br /&gt;
Takes an input u64 &amp;quot;nn::ns::RightsEnvironmentHandle&amp;quot;. Returns an u32 &amp;quot;nn::ns::RunningApplicationStatus&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==== RequestContentsAuthorizationToken ====&lt;br /&gt;
Takes a total of 0x50-bytes of input, a type-0x5 input buffer. Returns an [[#IAsyncData_2|IAsyncData]] and an output handle.&lt;br /&gt;
&lt;br /&gt;
==== IAsyncData ====&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IAsyncData&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [12.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetSize&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Get&lt;br /&gt;
|-&lt;br /&gt;
| 2 || Cancel&lt;br /&gt;
|-&lt;br /&gt;
| 3 || GetErrorContext&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IECommerceInterface===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IECommerceInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [4.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#RequestLinkDevice]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [6.0.0+] [[#RequestCleanupAllPreInstalledApplications]]&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [6.0.0+] [[#RequestCleanupPreInstalledApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [6.0.0+] [[#RequestSyncRights]]&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [6.0.0+] [[#RequestUnlinkDevice]]&lt;br /&gt;
|-&lt;br /&gt;
| 5 || [6.1.0+] [[#RequestRevokeAllELicense]]&lt;br /&gt;
|-&lt;br /&gt;
| 6 || [9.0.0+] [[#RequestSyncRightsBasedOnAssignedELicenses]]&lt;br /&gt;
|-&lt;br /&gt;
| 7 || [14.0.0+] RequestOnlineSubscriptionFreeTrialAvailability&lt;br /&gt;
|-&lt;br /&gt;
| 8 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 9 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 12 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 13 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 14 || [21.0.0+]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== RequestLinkDevice ====&lt;br /&gt;
Takes an input [[Account_services#Uid|Uid]], returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
See [[#RequestApplicationUpdateInfo]] regarding nifm.&lt;br /&gt;
&lt;br /&gt;
==== RequestCleanupAllPreInstalledApplications ====&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
==== RequestCleanupPreInstalledApplication ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
==== RequestSyncRights ====&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
==== RequestUnlinkDevice ====&lt;br /&gt;
Takes an input [[Account_services#Uid|Uid]], returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
See [[#RequestApplicationUpdateInfo]] regarding nifm.&lt;br /&gt;
&lt;br /&gt;
==== RequestRevokeAllELicense ====&lt;br /&gt;
Takes an input [[Account_services#Uid|Uid]], returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
==== RequestSyncRightsBasedOnAssignedELicenses ====&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
=== IFactoryResetInterface ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IFactoryResetInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 100 || [[#ResetToFactorySettings]]&lt;br /&gt;
|-&lt;br /&gt;
| 101 || [[#ResetToFactorySettingsWithoutUserSaveData]]&lt;br /&gt;
|-&lt;br /&gt;
| 102 || [[#ResetToFactorySettingsForRefurbishment]]&lt;br /&gt;
|-&lt;br /&gt;
| 103 || [9.1.0+] [[#ResetToFactorySettingsWithPlatformRegion]]&lt;br /&gt;
|-&lt;br /&gt;
| 104 || [9.1.0+] [[#ResetToFactorySettingsWithPlatformRegionAuthentication]]&lt;br /&gt;
|-&lt;br /&gt;
| 105 || [10.0.0+] [[#RequestResetToFactorySettingsSecurely]]&lt;br /&gt;
|-&lt;br /&gt;
| 106 || [10.0.0+] [[#RequestResetToFactorySettingsWithPlatformRegionAuthenticationSecurely]]&lt;br /&gt;
|-&lt;br /&gt;
| 107 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 108 || [20.0.0+]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== ResetToFactorySettings ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
As of [9.1.0] this is the only [[#IFactoryResetInterface]] cmd used by [[qlaunch]].&lt;br /&gt;
&lt;br /&gt;
==== ResetToFactorySettingsWithoutUserSaveData ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== ResetToFactorySettingsForRefurbishment ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== ResetToFactorySettingsWithPlatformRegion ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== ResetToFactorySettingsWithPlatformRegionAuthentication ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== RequestResetToFactorySettingsSecurely ====&lt;br /&gt;
Takes an input u64 tmem_size, a TransferMemory handle, returns an output [[#IAsyncValueAndProgress]] and an Event handle.&lt;br /&gt;
&lt;br /&gt;
The TransferMemory uses permissions=0.&lt;br /&gt;
&lt;br /&gt;
==== RequestResetToFactorySettingsWithPlatformRegionAuthenticationSecurely ====&lt;br /&gt;
Takes an input u32 &amp;quot;nn::ae::PlatformRegion&amp;quot;, an u64 tmem_size, a TransferMemory handle, returns an output [[#IAsyncValueAndProgress]] and an Event handle.&lt;br /&gt;
&lt;br /&gt;
The TransferMemory uses permissions=0.&lt;br /&gt;
&lt;br /&gt;
===== IAsyncValueAndProgress =====&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IAsyncValueAndProgress&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [10.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetSize&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Get&lt;br /&gt;
|-&lt;br /&gt;
| 2 || Cancel&lt;br /&gt;
|-&lt;br /&gt;
| 3 || GetErrorContext&lt;br /&gt;
|-&lt;br /&gt;
| 4 || GetProgress&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IApplicationResource ===&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IApplicationResource&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [9.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || Attach&lt;br /&gt;
|-&lt;br /&gt;
| 1 || BoostSystemMemoryResourceLimit&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ns:vm =&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IVulnerabilityManagerInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 1200 || [3.0.0+] [[#NeedsUpdateVulnerability]]&lt;br /&gt;
|-&lt;br /&gt;
| 1201 || [4.0.0+] [[#UpdateSafeSystemVersionForDebug]]&lt;br /&gt;
|-&lt;br /&gt;
| 1202 || [4.0.0+] [[#GetSafeSystemVersion]]&lt;br /&gt;
|-&lt;br /&gt;
| 3100 || [18.0.0+] [[#GetSafeSystemVersionCheckInfo|GetSafeSystemVersionCheckInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 3101 || [18.0.0+] [[#RequestUpdateSafeSystemVersionCheckInfo|RequestUpdateSafeSystemVersionCheckInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 3102 || [18.0.0+] [[#ResetSafeSystemVersionCheckInfo|ResetSafeSystemVersionCheckInfo]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== NeedsUpdateVulnerability ==&lt;br /&gt;
No input, returns an output u8 bool flag.&lt;br /&gt;
&lt;br /&gt;
[S1] Web-applets use this command to check if the system needs an update.&lt;br /&gt;
&lt;br /&gt;
== UpdateSafeSystemVersionForDebug ==&lt;br /&gt;
Takes an input u32 &#039;&#039;&#039;version&#039;&#039;&#039; and an [[NCM_services#ApplicationId|ApplicationId]].&lt;br /&gt;
&lt;br /&gt;
This command is not available for retail units. On a debug unit, if the [[System_Settings|system setting]] &amp;lt;code&amp;gt;vulnerability!enable_debug&amp;lt;/code&amp;gt; is set, this mounts the system savegame [[Flash_Filesystem#System_Savegames|0x8000000000000049]] as &amp;quot;ns_ssversion:/&amp;quot;, opens the file &amp;quot;ns_ssversion:/entry&amp;quot; and writes the supplied [[NCM_services#ApplicationId|ApplicationId]] and &#039;&#039;&#039;version&#039;&#039;&#039; in it.&lt;br /&gt;
&lt;br /&gt;
Finally, it calls [[NCM_services#ncm|OpenContentMetaDatabase]] with [[NCM_services#StorageId|StorageId]] 3, then calls [[NCM_services#IContentMetaDatabase|GetLatestContentMetaKey]] with the supplied [[NCM_services#ApplicationId|ApplicationId]] and compares the version field from the returned [[CNMT#Content_Meta_Records|Content Meta Record]] with the supplied &#039;&#039;&#039;version&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
If the supplied &#039;&#039;&#039;version&#039;&#039;&#039; is higher than the one in NCM&#039;s database, the value returned by [[NS_Services#NeedsUpdateVulnerability|NeedsUpdateVulnerability]] is set to &amp;quot;true&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== GetSafeSystemVersion ==&lt;br /&gt;
No input, returns an output [[NCM_services#ContentMetaKey|ContentMetaKey]] with the cached contents of &amp;quot;ns_ssversion:/entry&amp;quot; ([[NCM_services#ApplicationId|ApplicationId]], u32 &#039;&#039;&#039;version&#039;&#039;&#039; and u32 &#039;&#039;&#039;policy&#039;&#039;&#039; from &amp;lt;code&amp;gt;vulnerability!needs_update_vulnerability_policy&amp;lt;/code&amp;gt;).&lt;br /&gt;
&lt;br /&gt;
== GetSafeSystemVersionCheckInfo ==&lt;br /&gt;
No input, returns 0x10-bytes of output.&lt;br /&gt;
&lt;br /&gt;
[S2] Used by web-applets via ns:vm.&lt;br /&gt;
&lt;br /&gt;
== RequestUpdateSafeSystemVersionCheckInfo ==&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncResult|IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
[S2] Used by web-applets via ns:vm.&lt;br /&gt;
&lt;br /&gt;
The async task thread uses [[NIM_services|nim]] RequestCheckSafeSystemVersion, etc.&lt;br /&gt;
&lt;br /&gt;
== ResetSafeSystemVersionCheckInfo ==&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
This throws an error if [[Settings_services|GetDebugModeFlag]] returns false.&lt;br /&gt;
&lt;br /&gt;
= ns:su =&lt;br /&gt;
This is &amp;quot;nn::ns::detail::ISystemUpdateInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#GetBackgroundNetworkUpdateState]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#OpenSystemUpdateControl]]&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [[#NotifyExFatDriverRequired]]&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [[#ClearExFatDriverStatusForDebug]]&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [[#RequestBackgroundNetworkUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 5 || [[#NotifyBackgroundNetworkUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 6 || [[#NotifyExFatDriverDownloadedForDebug]]&lt;br /&gt;
|-&lt;br /&gt;
| 9 || [[#GetSystemUpdateNotificationEventForContentDelivery]]&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [[#NotifySystemUpdateForContentDelivery]]&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [3.0.0+] [[#PrepareShutdown]]&lt;br /&gt;
|-&lt;br /&gt;
| 12 || [3.0.0-3.0.2]&lt;br /&gt;
|-&lt;br /&gt;
| 13 || [3.0.0-3.0.2]&lt;br /&gt;
|-&lt;br /&gt;
| 14 || [3.0.0-3.0.2]&lt;br /&gt;
|-&lt;br /&gt;
| 15 || [3.0.0-3.0.2]&lt;br /&gt;
|-&lt;br /&gt;
| 16 || [4.0.0+] [[#DestroySystemUpdateTask]]&lt;br /&gt;
|-&lt;br /&gt;
| 17 || [4.0.0+] [[#RequestSendSystemUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 18 || [4.0.0+] [[#GetSendSystemUpdateProgress]]&lt;br /&gt;
|-&lt;br /&gt;
| 19 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 20 || [S2]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== GetBackgroundNetworkUpdateState ==&lt;br /&gt;
No input, returns an output [[#BackgroundNetworkUpdateState]].&lt;br /&gt;
&lt;br /&gt;
This is similar to [[#HasDownloaded]], see [[#BackgroundNetworkUpdateState]].&lt;br /&gt;
&lt;br /&gt;
== OpenSystemUpdateControl ==&lt;br /&gt;
No input, returns an [[#ISystemUpdateControl]].&lt;br /&gt;
&lt;br /&gt;
Only 1 ISystemUpdateControl can be open at a time.&lt;br /&gt;
&lt;br /&gt;
== NotifyExFatDriverRequired ==&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Only usable when an [[#ISystemUpdateControl]] isn&#039;t open.&lt;br /&gt;
&lt;br /&gt;
This uses [[NIM_services|nim]] ListSystemUpdateTask, then when a task is returned uses it with DestroySystemUpdateTask.&lt;br /&gt;
&lt;br /&gt;
Then this runs ExFat handling, updates state, and sets the same state flag as [[#RequestBackgroundNetworkUpdate]].&lt;br /&gt;
&lt;br /&gt;
== ClearExFatDriverStatusForDebug ==&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
== RequestBackgroundNetworkUpdate ==&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Only usable when an [[#ISystemUpdateControl]] isn&#039;t open.&lt;br /&gt;
&lt;br /&gt;
This sets a state flag to value 1.&lt;br /&gt;
&lt;br /&gt;
== NotifyBackgroundNetworkUpdate ==&lt;br /&gt;
Takes an input [[NCM_services#ContentMetaKey|ContentMetaKey]], no output.&lt;br /&gt;
&lt;br /&gt;
This checks whether a sysupdate is needed with the input ContentMetaKey using [[NCM_services|NCM]] commands, if not this will just return 0. Otherwise, this will then run code which is identical to [[#RequestBackgroundNetworkUpdate]].&lt;br /&gt;
&lt;br /&gt;
== NotifyExFatDriverDownloadedForDebug ==&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
== GetSystemUpdateNotificationEventForContentDelivery ==&lt;br /&gt;
No input, returns an output Event handle with EventClearMode=0.&lt;br /&gt;
&lt;br /&gt;
== NotifySystemUpdateForContentDelivery ==&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Signals the Event returned by [[#GetSystemUpdateNotificationEventForContentDelivery]].&lt;br /&gt;
&lt;br /&gt;
== PrepareShutdown ==&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
This is used by [[AM_services|AM]].&lt;br /&gt;
&lt;br /&gt;
Just returns 0 when an [[#ISystemUpdateControl]] is open. &lt;br /&gt;
&lt;br /&gt;
This does various cleanup / uses various service-cmds etc for shutdown preparation.&lt;br /&gt;
&lt;br /&gt;
== DestroySystemUpdateTask ==&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Only usable when an [[#ISystemUpdateControl]] isn&#039;t open.&lt;br /&gt;
&lt;br /&gt;
This uses [[NIM_services|nim]] ListSystemUpdateTask, then when a task is returned uses it with DestroySystemUpdateTask.&lt;br /&gt;
&lt;br /&gt;
== RequestSendSystemUpdate ==&lt;br /&gt;
Takes a type-0x15 input buffer containing a [[#SystemDeliveryInfo]], an u16 port, an u32 Ipv4Address, returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
[[qlaunch]] uses value 55556 for the port. IP is normally a local-WLAN address, however this can be any address. port/addr are little-endian.&lt;br /&gt;
&lt;br /&gt;
See [[NIM_services|nim]] regarding the input addr/port usage, etc.&lt;br /&gt;
&lt;br /&gt;
[11.0.0+] An error is thrown if LocalContentShare is not [[#IsLocalContentShareEnabled|enabled]].&lt;br /&gt;
&lt;br /&gt;
This validates the [[#SystemDeliveryInfo]] and generates a [[NCM_services#ContentMetaKey|ContentMetaKey]] from that, and creates the [[#IAsyncResult]] + the async thread which handles the [[#IAsyncResult]] operation.&lt;br /&gt;
&lt;br /&gt;
The above validation verifies that the HMAC and SystemDeliveryProtocolVersion are valid. The OldSystemUpdateId ([20.0.0+] SystemUpdateId, SystemUpdateIdFlag ignored) must match the Id for the installed SystemUpdate as returned by [[NCM_services|ncm]].&lt;br /&gt;
&lt;br /&gt;
Then the thread does:&lt;br /&gt;
* Calls a func which does:&lt;br /&gt;
** Uses [[NIM_services|nim]] CreateLocalCommunicationSendSystemUpdateTask, returning the Result on failure.&lt;br /&gt;
*** The input firmware_variation is from the [[#SystemDeliveryInfo|FirmwareVariationId]].&lt;br /&gt;
** Uses [[NIM_services|nim]] RequestLocalCommunicationSendSystemUpdateTaskRun, returning the Result on failure. Waits for the IAsyncResult operation from this to finish, then uses the Get cmd to get the output Result.&lt;br /&gt;
*** When the Result from Get is an error, a func is called for filling in the [[#IAsyncResult|IAsyncResult]] ErrorContext with Type4.&lt;br /&gt;
** Handles cleanup and returns.&lt;br /&gt;
* Unlike [[#RequestReceiveSystemUpdate]], this doesn&#039;t save a SystemPlayReport.&lt;br /&gt;
&lt;br /&gt;
== GetSendSystemUpdateProgress ==&lt;br /&gt;
No input, returns an output [[#SystemUpdateProgress]].&lt;br /&gt;
&lt;br /&gt;
Same as [[#GetReceiveProgress]] except this uses nim ListLocalCommunicationSendSystemUpdateTask and GetLocalCommunicationSendSystemUpdateTaskInfo. The data copied to output is also swapped: u64 nim_out+0x8 is copied to out+0x8, and u64 nim_out+0x10 is copied to out+0x0.&lt;br /&gt;
&lt;br /&gt;
== Cmd19 ==&lt;br /&gt;
This is exclusive to S2.&lt;br /&gt;
&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
== Cmd20 ==&lt;br /&gt;
This is exclusive to S2.&lt;br /&gt;
&lt;br /&gt;
No input, returns an output u8.&lt;br /&gt;
&lt;br /&gt;
== ISystemUpdateControl ==&lt;br /&gt;
This is &amp;quot;nn::ns::detail::ISystemUpdateControl&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#HasDownloaded]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#RequestCheckLatestUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [[#RequestDownloadLatestUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [[#GetDownloadProgress]]&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [[#ApplyDownloadedUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 5 || [[#RequestPrepareCardUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 6 || [[#GetPrepareCardUpdateProgress]]&lt;br /&gt;
|-&lt;br /&gt;
| 7 || [[#HasPreparedCardUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 8 || [[#ApplyCardUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 9 || [[#GetDownloadedEulaDataSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [[#GetDownloadedEulaData]]&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [[#SetupCardUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 12 || [[#GetPreparedCardUpdateEulaDataSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 13 || [[#GetPreparedCardUpdateEulaData]]&lt;br /&gt;
|-&lt;br /&gt;
| 14 || [4.0.0+] [[#SetupCardUpdateViaSystemUpdater]]&lt;br /&gt;
|-&lt;br /&gt;
| 15 || [4.0.0+] [[#HasReceived]]&lt;br /&gt;
|-&lt;br /&gt;
| 16 || [4.0.0+] [[#RequestReceiveSystemUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 17 || [4.0.0+] [[#GetReceiveProgress]]&lt;br /&gt;
|-&lt;br /&gt;
| 18 || [4.0.0+] [[#ApplyReceivedUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 19 || [4.0.0+] [[#GetReceivedEulaDataSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 20 || [4.0.0+] [[#GetReceivedEulaData]]&lt;br /&gt;
|-&lt;br /&gt;
| 21 || [4.0.0+] [[#SetupToReceiveSystemUpdate]]&lt;br /&gt;
|-&lt;br /&gt;
| 22 || [6.0.0+] [[#RequestCheckLatestUpdateIncludesRebootlessUpdate]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
All Card cmds except SetupCardUpdate* require [[#SetupCardUpdate]]/[[#SetupCardUpdateViaSystemUpdater]] to be used previously. [[#GetPreparedCardUpdateEulaDataSize]]/[[#GetPreparedCardUpdateEulaData]] checks a different state flag.&lt;br /&gt;
&lt;br /&gt;
=== HasDownloaded ===&lt;br /&gt;
No input, returns an output u8 bool flag.&lt;br /&gt;
&lt;br /&gt;
Gets whether a network sysupdate was downloaded, with install pending.&lt;br /&gt;
&lt;br /&gt;
Uses [[NIM_services|nim]] ListSystemUpdateTask and [[NIM_services|nim]] GetSystemUpdateTaskInfo. When ListSystemUpdateTask successfully returns a task and GetSystemUpdateTaskInfo is successful, the output flag is set to: &amp;lt;code&amp;gt;*((u8*)(taskinfo+0) == 0x3&amp;lt;/code&amp;gt;. Otherwise, flag=0.&lt;br /&gt;
&lt;br /&gt;
This always returns 0, however this will assert if GetSystemUpdateTaskInfo fails with ret!=0x3C89.&lt;br /&gt;
&lt;br /&gt;
=== RequestCheckLatestUpdate ===&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
The data that can be read from the [[#IAsyncValue]] is [[#LatestSystemUpdate]].&lt;br /&gt;
&lt;br /&gt;
=== RequestDownloadLatestUpdate ===&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
=== GetDownloadProgress ===&lt;br /&gt;
No input, returns an output [[#SystemUpdateProgress]].&lt;br /&gt;
&lt;br /&gt;
Similar to [[#HasDownloaded]] except instead of a flag, this returns the 0x10-bytes from taskinfo+8. The output struct is cleared when the task(info) isn&#039;t available.&lt;br /&gt;
&lt;br /&gt;
=== ApplyDownloadedUpdate ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Runs code similar to [[#HasDownloaded]], throwing an error if a network sysupdate isn&#039;t ready for install. Then the sysupdate is installed:&lt;br /&gt;
&lt;br /&gt;
* Uses ListSystemUpdateTask again, then [[NIM_services|nim]] IsExFatDriverIncluded. Runs ExFat handling when the output flag is set.&lt;br /&gt;
* On newer system-versions, this uses [[NIM_services|nim]] GetSystemUpdateTaskInfo then on success uses data from there to save a SystemPlayReport when the cached [[System_Settings|system-setting]] &amp;quot;systemreport!enabled&amp;quot; is set.&lt;br /&gt;
** The EventId is &amp;quot;systemupdate_dl_throughput&amp;quot; with ApplicationId 0100000000001018.&lt;br /&gt;
** The following fields are added to the report, see [[NIM_services#SystemUpdateTaskInfo|nim SystemUpdateTaskInfo]]: &amp;quot;ContentMetaId&amp;quot;, &amp;quot;Version&amp;quot;, &amp;quot;DownloadSize&amp;quot;, and &amp;quot;ThroughputKBps&amp;quot;.&lt;br /&gt;
* On newer system-versions, this saves another SystemPlayReport when a state flag is set (same flag mentioned above).&lt;br /&gt;
** The EventId is &amp;quot;systemupdate_pass&amp;quot; with ApplicationId 0100000000001021.&lt;br /&gt;
** This report has the following fields:&lt;br /&gt;
*** &amp;quot;Type&amp;quot;&lt;br /&gt;
*** &amp;quot;SourceSystemUpdateMetaId&amp;quot;&lt;br /&gt;
*** &amp;quot;SourceSystemUpdateMetaVersion&amp;quot;&lt;br /&gt;
*** &amp;quot;SourceExFatStatus&amp;quot;&lt;br /&gt;
*** &amp;quot;DestinationSystemUpdateMetaId&amp;quot;&lt;br /&gt;
*** &amp;quot;DestinationSystemUpdateMetaVersion&amp;quot;&lt;br /&gt;
*** &amp;quot;DestinationExFatStatus&amp;quot;&lt;br /&gt;
*** &amp;quot;Rebootless&amp;quot;&lt;br /&gt;
* Since BootImagePackage will be installed later, the two flags in [[Flash_Filesystem#System_Update_Control]] are set to 1.&lt;br /&gt;
* Uses [[NIM_services|nim]] CommitSystemUpdateTask and [[NIM_services|nim]] DestroySystemUpdateTask.&lt;br /&gt;
* Installs BootImagePackage. After installing each BootImagePackage, the associated flag in [[Flash_Filesystem#System_Update_Control]] is set to 0.&lt;br /&gt;
* On newer system versions when an input flag is set, this uses [[Filesystem_services|NotifySystemDataUpdateEvent]], however this doesn&#039;t happen with ApplyDownloadedUpdate since that input flag is 0.&lt;br /&gt;
&lt;br /&gt;
=== RequestPrepareCardUpdate ===&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
=== GetPrepareCardUpdateProgress ===&lt;br /&gt;
No input, returns an output [[#SystemUpdateProgress]].&lt;br /&gt;
&lt;br /&gt;
=== HasPreparedCardUpdate ===&lt;br /&gt;
No input, returns an output u8 bool flag.&lt;br /&gt;
&lt;br /&gt;
=== ApplyCardUpdate ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
=== GetDownloadedEulaDataSize ===&lt;br /&gt;
Takes a type-0x15 input buffer [[#EulaDataPath]], returns an output u64 &#039;&#039;&#039;filesize&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
Runs code similar to [[#HasDownloaded]], throwing an error if a network sysupdate isn&#039;t ready for install.&lt;br /&gt;
&lt;br /&gt;
Uses ListSystemUpdateTask again. Then [[NIM_services|nim]] GetDownloadedSystemDataPath, with the output ContentPath being used to mount the EULA title with FS.&lt;br /&gt;
&lt;br /&gt;
Then &amp;quot;&amp;lt;mountname&amp;gt;:/&amp;lt;[[#EulaDataPath]]&amp;gt;&amp;quot; is opened, gets the &#039;&#039;&#039;filesize&#039;&#039;&#039;, then runs cleanup.&lt;br /&gt;
&lt;br /&gt;
=== GetDownloadedEulaData ===&lt;br /&gt;
Takes a type-0x15 input buffer [[#EulaDataPath]] and a type-0x6 output buffer, returns an output u64 &#039;&#039;&#039;filesize&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
Similar to [[#GetDownloadedEulaDataSize]] except this reads the file instead, using the specified output buffer with size=filesize. This will throw an error if the filesize is larger than the buffer size.&lt;br /&gt;
&lt;br /&gt;
=== SetupCardUpdate ===&lt;br /&gt;
Takes an input u64 size and a TransferMemory handle, no output.&lt;br /&gt;
&lt;br /&gt;
Official sw creates the TransferMemory with an user-specified buffer, with permissions=None.&lt;br /&gt;
&lt;br /&gt;
[[qlaunch]] uses size 0x100000 for the TransferMemory buffer.&lt;br /&gt;
&lt;br /&gt;
=== GetPreparedCardUpdateEulaDataSize ===&lt;br /&gt;
Takes a type-0x15 input buffer [[#EulaDataPath]], returns an output u64 &#039;&#039;&#039;filesize&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
This is similar to [[#GetDownloadedEulaDataSize]].&lt;br /&gt;
&lt;br /&gt;
=== GetPreparedCardUpdateEulaData ===&lt;br /&gt;
Takes a type-0x15 input buffer [[#EulaDataPath]] and a type-0x6 output buffer, returns an output u64 &#039;&#039;&#039;filesize&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
This is similar to [[#GetDownloadedEulaData]].&lt;br /&gt;
&lt;br /&gt;
=== SetupCardUpdateViaSystemUpdater ===&lt;br /&gt;
Takes an input u64 size and a TransferMemory handle, no output.&lt;br /&gt;
&lt;br /&gt;
The permissions for the TransferMemory is None.&lt;br /&gt;
&lt;br /&gt;
Same as [[#SetupCardUpdate]], except this doesn&#039;t have the code for [[Filesystem_services|GetGameCardHandle/GetGameCardUpdatePartitionInfo]], and uses [[Filesystem_services|OpenRegisteredUpdatePartition]] instead of [[Filesystem_services|OpenGameCardFileSystem]]. This uses the same is_initialized bool state flag.&lt;br /&gt;
&lt;br /&gt;
=== HasReceived ===&lt;br /&gt;
No input, returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
Same as [[#HasDownloaded]] except this uses [[NIM_services|nim]] ListLocalCommunicationReceiveSystemUpdateTask and GetLocalCommunicationReceiveSystemUpdateTaskInfo.&lt;br /&gt;
&lt;br /&gt;
=== RequestReceiveSystemUpdate ===&lt;br /&gt;
Takes a type-0x15 input buffer containing a [[#SystemDeliveryInfo]], an u16 port, an u32 Ipv4Address, returns an output Event handle and an [[#IAsyncResult]].&lt;br /&gt;
&lt;br /&gt;
[[qlaunch]] uses the same value for the port as [[#RequestSendSystemUpdate]] (see [[#RequestSendSystemUpdate]] for addr as well).&lt;br /&gt;
&lt;br /&gt;
See [[NIM_services|nim]] regarding the input addr/port usage, etc.&lt;br /&gt;
&lt;br /&gt;
This uses the same LocalContentShare check as [[#RequestSendSystemUpdate|RequestSendSystemUpdate]].&lt;br /&gt;
&lt;br /&gt;
An error is thrown if a state flag is clear.&lt;br /&gt;
&lt;br /&gt;
This validates the [[#SystemDeliveryInfo]] (same as [[#RequestSendSystemUpdate|RequestSendSystemUpdate]]) and generates a [[NCM_services#ContentMetaKey|ContentMetaKey]] from that, and creates the [[#IAsyncResult]] + the async thread which handles the [[#IAsyncResult]] operation.&lt;br /&gt;
&lt;br /&gt;
Then the thread does:&lt;br /&gt;
&lt;br /&gt;
* Calls a func which does:&lt;br /&gt;
** Throws an error if [[NIM_services#ListSystemUpdateTask|ListSystemUpdateTask]] returns any task.&lt;br /&gt;
** Checks whether a sysupdate is actually required using the previously generated [[NCM_services#ContentMetaKey|ContentMetaKey]] (this func is also passed the below statefield as the last param), throwing an error if not.&lt;br /&gt;
*** [20.0.0+] The above check-sysupdate func was updated (which is also used elsewhere), flag handling during the loop was updated (which uses the last input param).&lt;br /&gt;
** Uses [[NIM_services|nim]] CreateLocalCommunicationReceiveSystemUpdateTask, returning the Result on failure.&lt;br /&gt;
*** The input firmware_variation is from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;ns.systemupdate!firmware_variation&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;ns.systemupdate!t_firmware_variation&amp;lt;/code&amp;gt;, depending on the [[Settings_services|PlatformRegion]] (value 0xFF is used when the output setting-size is invalid).&lt;br /&gt;
*** The input &#039;&#039;&#039;unk&#039;&#039;&#039; is set to: &amp;lt;code&amp;gt;unk = statefield == 0 ? 0x4 : 0xC&amp;lt;/code&amp;gt; ([20.0.0+] uses statefield &amp;amp; 1 == 0). [20.0.0+] Additional data is now ORRed with unk afterwards: &amp;lt;code&amp;gt;unk |= ((statefield&amp;gt;&amp;gt;1) &amp;amp; 0x3) &amp;lt;&amp;lt; 8;&amp;lt;/code&amp;gt; (same statefield as before)&lt;br /&gt;
** Uses [[NIM_services|nim]] RequestLocalCommunicationReceiveSystemUpdateTaskRun, returning the Result on failure. Waits for the IAsyncResult operation from this to finish, then uses the Get cmd to get the output Result.&lt;br /&gt;
*** When the Result from Get is an error, a func is called for filling in the [[#IAsyncResult|IAsyncResult]] ErrorContext with Type4.&lt;br /&gt;
** Handles cleanup and returns.&lt;br /&gt;
* On success, this loads various data which is then used for saving a SystemPlayReport when the cached [[System_Settings|system-setting]] &amp;quot;systemreport!enabled&amp;quot; is set.&lt;br /&gt;
** The EventId is &amp;quot;receive_system_update&amp;quot; with ApplicationId &amp;lt;NS ProgramId&amp;gt;.&lt;br /&gt;
** This report has the following fields: &lt;br /&gt;
*** &amp;quot;SourceSystemUpdateId&amp;quot;&lt;br /&gt;
*** &amp;quot;DestinationSystemUpdateId&amp;quot;&lt;br /&gt;
*** &amp;quot;SourceSystemUpdateVersion&amp;quot;&lt;br /&gt;
*** &amp;quot;DestinationSystemUpdateVersion&amp;quot;&lt;br /&gt;
*** &amp;quot;SenderFirmwareVariationId&amp;quot;&lt;br /&gt;
*** &amp;quot;ReceiverFirmwareVariationId&amp;quot;&lt;br /&gt;
*** &amp;quot;SenderPlatformRegion&amp;quot;&lt;br /&gt;
*** &amp;quot;ReceiverPlatformRegion&amp;quot;&lt;br /&gt;
*** &amp;quot;SenderHasExFat&amp;quot;&lt;br /&gt;
*** &amp;quot;ReceiverHasExFat&amp;quot;&lt;br /&gt;
*** &amp;quot;Size&amp;quot;&lt;br /&gt;
*** &amp;quot;ThroughputKBps&amp;quot;&lt;br /&gt;
&lt;br /&gt;
=== GetReceiveProgress ===&lt;br /&gt;
No input, returns an output [[#SystemUpdateProgress]].&lt;br /&gt;
&lt;br /&gt;
Same as [[#GetDownloadProgress]] except this uses [[NIM_services|nim]] ListLocalCommunicationReceiveSystemUpdateTask and GetLocalCommunicationReceiveSystemUpdateTaskInfo.&lt;br /&gt;
&lt;br /&gt;
=== ApplyReceivedUpdate ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
This uses the same LocalContentShare check as [[#RequestSendSystemUpdate|RequestSendSystemUpdate]].&lt;br /&gt;
&lt;br /&gt;
=== GetReceivedEulaDataSize ===&lt;br /&gt;
Takes a type-0x15 input buffer [[#EulaDataPath]], returns an output u64 &#039;&#039;&#039;filesize&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
This is similar to [[#GetDownloadedEulaDataSize]].&lt;br /&gt;
&lt;br /&gt;
=== GetReceivedEulaData ===&lt;br /&gt;
Takes a type-0x15 input buffer [[#EulaDataPath]] and a type-0x6 output buffer, returns an output u64 &#039;&#039;&#039;filesize&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
This is similar to [[#GetDownloadedEulaData]].&lt;br /&gt;
&lt;br /&gt;
=== SetupToReceiveSystemUpdate ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
This just uses [[NIM_services|nim]] ListSystemUpdateTask, then when a task is returned uses it with DestroySystemUpdateTask.&lt;br /&gt;
&lt;br /&gt;
[[qlaunch]] uses this before [[#RequestReceiveSystemUpdate]].&lt;br /&gt;
&lt;br /&gt;
=== RequestCheckLatestUpdateIncludesRebootlessUpdate ===&lt;br /&gt;
No input, returns an output Event handle and an [[#IAsyncValue]].&lt;br /&gt;
&lt;br /&gt;
= IAsyncValue =&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IAsyncValue&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetSize&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Get&lt;br /&gt;
|-&lt;br /&gt;
| 2 || Cancel&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [4.0.0+] GetErrorContext&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Official sw creates a container object for this using the output from the service commands, which contains the IAsyncValue object, and the Event with EventClearMode=0.&lt;br /&gt;
&lt;br /&gt;
* GetSize: No input, returns an output u64.&lt;br /&gt;
* Get: Takes a type-0x6 output buffer, no output. Official sw waits on the Event prior to using this cmd.&lt;br /&gt;
* Cancel: No input/output. Used by official sw when closing the object, when the serv-obj is initialized (after using the cmd, official sw will also wait on the Event). This cmd is also used in other official sw funcs.&lt;br /&gt;
* GetErrorContext: No input/output, takes a type-0x16 output buffer containing an [[Error_Applet#ErrorContext|ErrorContext]].&lt;br /&gt;
&lt;br /&gt;
= IAsyncResult =&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IAsyncResult&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || Get&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Cancel&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [4.0.0+] GetErrorContext&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Official sw creates a container object for this using the output from the service commands, which contains the IAsyncResult object, and the Event with EventClearMode=0.&lt;br /&gt;
&lt;br /&gt;
* Get: No input/output. Official sw waits on the Event prior to using this cmd.&lt;br /&gt;
* Cancel: No input/output. Used by official sw when closing the object, when the serv-obj is initialized (after using the cmd, official sw will also wait on the Event). This cmd is also used in other official sw funcs.&lt;br /&gt;
* GetErrorContext: No input/output, takes a type-0x16 output buffer containing an [[Error_Applet#ErrorContext|ErrorContext]].&lt;br /&gt;
&lt;br /&gt;
= ns:dev =&lt;br /&gt;
This is &amp;quot;nn::ns::detail::IDevelopInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
[10.0.0+] Some of these cmds were replaced by the [[PGL_services|pgl]] system module.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [1.0.0-9.2.0] [[#LaunchProgram]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#TerminateProcess]]&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [1.0.0-9.2.0] [[#TerminateProgram]]&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [1.0.0-9.2.0] [[#GetShellEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 5 || [1.0.0-9.2.0] [[#GetShellEventInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 6 || [[#TerminateApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 7 || [1.0.0-9.2.0] [[#PrepareLaunchProgramFromHost]]&lt;br /&gt;
|-&lt;br /&gt;
| 8 || [10.0.0-17.0.1] [[#LaunchApplicationFromHost]] ([1.0.0-9.2.0] LaunchApplication)&lt;br /&gt;
|-&lt;br /&gt;
| 9 || [1.0.0-17.0.1] [[#LaunchApplicationWithStorageId]]&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [6.0.0-8.1.0] [[#IsSystemMemoryResourceLimitBoosted]]&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [6.0.0+] [[#GetRunningApplicationProcessId]]&lt;br /&gt;
|-&lt;br /&gt;
| 12 || [6.0.0+] [[#SetCurrentApplicationRightsEnvironmentCanBeActive]]&lt;br /&gt;
|-&lt;br /&gt;
| 13 || [9.0.0+] [[#CreateApplicationResource]]&lt;br /&gt;
|-&lt;br /&gt;
| 14 || [9.0.0+] [[#IsPreomia]]&lt;br /&gt;
|-&lt;br /&gt;
| 15 || [10.0.0-17.0.1] [[#GetApplicationProgramIdFromHost]]&lt;br /&gt;
|-&lt;br /&gt;
| 16 || [12.0.0+] RefreshCachedDebugValues&lt;br /&gt;
|-&lt;br /&gt;
| 17 || [12.0.0+] [[#PrepareLaunchApplicationFromHost]]&lt;br /&gt;
|-&lt;br /&gt;
| 18 || [12.0.0+] [[#GetLaunchEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 19 || [12.0.0+] [[#GetLaunchResult]]&lt;br /&gt;
|-&lt;br /&gt;
| 20 || [14.0.0+] GetProgramId&lt;br /&gt;
|-&lt;br /&gt;
| 21 || [18.0.0+] [[#PrepareLaunchApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 22 || [18.0.0+] [[#LaunchApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 23 || [18.0.0+] [[#GetProgramIdByApplicationLaunchInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 24 || [18.0.0+] DestroyApplicationLaunchPreparation&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== LaunchProgram ==&lt;br /&gt;
Wrapper for &amp;quot;pm:shell&amp;quot; [[Process_Manager_services#pm:shell|LaunchProcess]].&lt;br /&gt;
&lt;br /&gt;
== TerminateProcess ==&lt;br /&gt;
Wrapper for &amp;quot;pm:shell&amp;quot; [[Process_Manager_services#pm:shell|TerminateProcess]].&lt;br /&gt;
&lt;br /&gt;
== TerminateProgram ==&lt;br /&gt;
Wrapper for &amp;quot;pm:shell&amp;quot; [[Process_Manager_services#pm:shell|TerminateProgram]].&lt;br /&gt;
&lt;br /&gt;
== GetShellEvent ==&lt;br /&gt;
Wrapper for &amp;quot;pm:shell&amp;quot; [[Process_Manager_services#pm:shell|GetProcessEventHandle]].&lt;br /&gt;
&lt;br /&gt;
== GetShellEventInfo ==&lt;br /&gt;
Wrapper for &amp;quot;pm:shell&amp;quot; [[Process_Manager_services#pm:shell|GetProcessEventInfo]].&lt;br /&gt;
&lt;br /&gt;
== TerminateApplication ==&lt;br /&gt;
Calls &amp;quot;pm:shell&amp;quot; [[Process_Manager_services#pm:shell|GetApplicationProcessIdForShell]] and sends the ProcessId to [[Process_Manager_services#pm:shell|TerminateProcess]].&lt;br /&gt;
&lt;br /&gt;
== PrepareLaunchProgramFromHost ==&lt;br /&gt;
Takes a type-0x5 input buffer containing the [[Filesystem_services#FspPath|FspPath]], returns an output 0x10-byte struct.&lt;br /&gt;
&lt;br /&gt;
Calls [[NCM_services#IPathResolverForStorage|IPathResolverForStorage]] Set...NcaPath functions.&lt;br /&gt;
&lt;br /&gt;
== LaunchApplicationFromHost ==&lt;br /&gt;
Takes an input u32 [[Process_Manager_services#LaunchFlags|LaunchFlags]] and a type-0x5 input buffer containing the [[Filesystem_services#FspPath|FspPath]]. Returns an output u64 ProcessId.&lt;br /&gt;
&lt;br /&gt;
== LaunchApplicationWithStorageId ==&lt;br /&gt;
Takes 2 input u8 [[NCM_services#StorageId|StorageIds]], an u32 [[Process_Manager_services#LaunchFlags|LaunchFlags]], and an [[NCM_services#ApplicationId|ApplicationId]]. Returns an output u64 ProcessId.&lt;br /&gt;
&lt;br /&gt;
Launches an application title which is registered with NS.&lt;br /&gt;
&lt;br /&gt;
== IsSystemMemoryResourceLimitBoosted ==&lt;br /&gt;
No input. Returns a bool.&lt;br /&gt;
&lt;br /&gt;
== GetRunningApplicationProcessId ==&lt;br /&gt;
Returns an output u64 ProcessId.&lt;br /&gt;
&lt;br /&gt;
== SetCurrentApplicationRightsEnvironmentCanBeActive ==&lt;br /&gt;
Takes an input bool. No output.&lt;br /&gt;
&lt;br /&gt;
== CreateApplicationResource ==&lt;br /&gt;
Takes an input u32 (1 = Preomia/MicroApplication). Returns an [[#IApplicationResource]].&lt;br /&gt;
&lt;br /&gt;
== IsPreomia ==&lt;br /&gt;
Takes an input u64 [[NCM_services#ProgramId|ProgramId]]. Returns a bool.&lt;br /&gt;
&lt;br /&gt;
== GetApplicationProgramIdFromHost ==&lt;br /&gt;
Takes a type-0x5 input buffer containing the [[Filesystem_services#FspPath|FspPath]]. Returns an u64 [[NCM_services#ProgramId|ProgramId]].&lt;br /&gt;
&lt;br /&gt;
== PrepareLaunchApplicationFromHost ==&lt;br /&gt;
[18.0.0+] Now returns a total of 0x50 bytes of output.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] Now returns a total of 0x80 bytes of output.&lt;br /&gt;
&lt;br /&gt;
== GetLaunchEvent ==&lt;br /&gt;
[18.0.0+] Now takes a total of 0x50 bytes of input.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] Now takes a total of 0x80 bytes of input.&lt;br /&gt;
&lt;br /&gt;
== GetLaunchResult ==&lt;br /&gt;
[18.0.0+] Now takes a total of 0x50 bytes of input.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] Now takes a total of 0x80 bytes of input.&lt;br /&gt;
&lt;br /&gt;
== PrepareLaunchApplication ==&lt;br /&gt;
Takes a total of 0x10-bytes of input. Returns a total of 0x50-bytes of output.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] Now returns a total of 0x80-bytes of output.&lt;br /&gt;
&lt;br /&gt;
== LaunchApplication ==&lt;br /&gt;
Takes a total of 0x50-bytes of input. Returns a total of 8-bytes of output.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] Now takes a total of 0x80 bytes of input.&lt;br /&gt;
&lt;br /&gt;
== GetProgramIdByApplicationLaunchInfo ==&lt;br /&gt;
Takes a total of 0x50-bytes of input. Returns a total of 8-bytes of output.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] Now takes a total of 0x80 bytes of input.&lt;br /&gt;
&lt;br /&gt;
= acc:su =&lt;br /&gt;
This is &amp;quot;nn::account::IAccountServiceForAdministrator&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
[13.0.0+] This was moved from [[Account_services|account]].&lt;br /&gt;
&lt;br /&gt;
This is only available when the output from [[Process_Manager_services|pm:bm]] GetBootMode is Normal/Maintenance.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetUserCount ||&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GetUserExistence ||&lt;br /&gt;
|-&lt;br /&gt;
| 2 || ListAllUsers ||&lt;br /&gt;
|-&lt;br /&gt;
| 3 || ListOpenUsers ||&lt;br /&gt;
|-&lt;br /&gt;
| 4 || GetLastOpenedUser ||&lt;br /&gt;
|-&lt;br /&gt;
| 5 || GetProfile || Returns an [[#IProfile]].&lt;br /&gt;
|-&lt;br /&gt;
| 6 || [3.0.0+] GetProfileDigest ||&lt;br /&gt;
|-&lt;br /&gt;
| 50 || [[#IsUserRegistrationRequestPermitted]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 51 || TrySelectUserWithoutInteractionDeprecated ([1.0.0-18.1.0] [[#TrySelectUserWithoutInteraction]]) ||&lt;br /&gt;
|-&lt;br /&gt;
| 52 || [19.0.0+] TrySelectUserWithoutInteraction ||&lt;br /&gt;
|-&lt;br /&gt;
| 60 || [5.0.0-5.1.0] ListOpenContextStoredUsers ||&lt;br /&gt;
|-&lt;br /&gt;
| 99 || [6.0.0+] DebugActivateOpenContextRetention || No input, returns an [[#ISessionObject]].&lt;br /&gt;
|-&lt;br /&gt;
| 100 || GetUserRegistrationNotifier || Returns an [[#INotifier]].&lt;br /&gt;
|-&lt;br /&gt;
| 101 || GetUserStateChangeNotifier || Returns an [[#INotifier]].&lt;br /&gt;
|-&lt;br /&gt;
| 102 || GetBaasAccountManagerForSystemService || Returns an [[#IManagerForSystemService]].&lt;br /&gt;
|-&lt;br /&gt;
| 103 || GetBaasUserAvailabilityChangeNotifier || Returns an [[#INotifier]].&lt;br /&gt;
|-&lt;br /&gt;
| 104 || GetProfileUpdateNotifier || Returns an [[#INotifier]].&lt;br /&gt;
|-&lt;br /&gt;
| 105 || [4.0.0+] CheckNetworkServiceAvailabilityAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 106 || [9.0.0+] GetProfileSyncNotifier ||&lt;br /&gt;
|-&lt;br /&gt;
| 110 || StoreSaveDataThumbnail ||&lt;br /&gt;
|-&lt;br /&gt;
| 111 || ClearSaveDataThumbnail ||&lt;br /&gt;
|-&lt;br /&gt;
| 112 || LoadSaveDataThumbnail ||&lt;br /&gt;
|-&lt;br /&gt;
| 113 || [5.0.0+] GetSaveDataThumbnailExistence ||&lt;br /&gt;
|-&lt;br /&gt;
| 120 || [10.0.0+] ListOpenUsersInApplication ||&lt;br /&gt;
|-&lt;br /&gt;
| 130 || [6.0.0+] ActivateOpenContextRetention || Takes a total of 0x8-bytes of input, returns an [[#ISessionObject]].&lt;br /&gt;
|-&lt;br /&gt;
| 140 || [6.0.0+] ListQualifiedUsers || &lt;br /&gt;
|-&lt;br /&gt;
| 150 || [10.0.0-10.2.0] AuthenticateApplicationAsync || &lt;br /&gt;
|-&lt;br /&gt;
| 151 || [12.0.0+] EnsureSignedDeviceIdentifierCacheForNintendoAccountAsync || &lt;br /&gt;
|-&lt;br /&gt;
| 152 || [12.0.0+] LoadSignedDeviceIdentifierCacheForNintendoAccount ||&lt;br /&gt;
|-&lt;br /&gt;
| 170 || [13.0.0+] GetNasOp2MembershipStateChangeNotifier ||&lt;br /&gt;
|-&lt;br /&gt;
| 190 || [1.0.0-9.2.0] GetUserLastOpenedApplication ||&lt;br /&gt;
|-&lt;br /&gt;
| 191 || [7.0.0-19.0.1] UpdateNotificationReceiverInfo ([5.0.0-5.1.0] ActivateOpenContextHolder) ||&lt;br /&gt;
|-&lt;br /&gt;
| 200 || BeginUserRegistration ||&lt;br /&gt;
|-&lt;br /&gt;
| 201 || CompleteUserRegistration ||&lt;br /&gt;
|-&lt;br /&gt;
| 202 || CancelUserRegistration ||&lt;br /&gt;
|-&lt;br /&gt;
| 203 || DeleteUser ||&lt;br /&gt;
|-&lt;br /&gt;
| 204 || SetUserPosition ||&lt;br /&gt;
|-&lt;br /&gt;
| 205 || GetProfileEditor || Takes an input userID and returns an [[#IProfileEditor]].&lt;br /&gt;
|-&lt;br /&gt;
| 206 || CompleteUserRegistrationForcibly ||&lt;br /&gt;
|-&lt;br /&gt;
| 210 || [3.0.0+] CreateFloatingRegistrationRequest || Returns an [[#IFloatingRegistrationRequest]].&lt;br /&gt;
|-&lt;br /&gt;
| 211 || [8.0.0+] CreateProcedureToRegisterUserWithNintendoAccount || Takes a total of 0x4-bytes of input and a handle, returns an [[#IOAuthProcedureForUserRegistration]].&lt;br /&gt;
|-&lt;br /&gt;
| 212 || [8.0.0+] ResumeProcedureToRegisterUserWithNintendoAccount || Takes a total of 0x14-bytes of input and a handle, returns an [[#IOAuthProcedureForUserRegistration]].&lt;br /&gt;
|-&lt;br /&gt;
| 213 || [17.0.0+] CreateProcedureToCreateUserWithNintendoAccount ||&lt;br /&gt;
|-&lt;br /&gt;
| 214 || [17.0.0+] ResumeProcedureToCreateUserWithNintendoAccount ||&lt;br /&gt;
|-&lt;br /&gt;
| 215 || [17.0.0+] ResumeProcedureToCreateUserWithNintendoAccountAfterApplyResponse ||&lt;br /&gt;
|-&lt;br /&gt;
| 230 || AuthenticateServiceAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 250 || GetBaasAccountAdministrator || Returns an [[#IAdministrator]].&lt;br /&gt;
|-&lt;br /&gt;
| 251 || [20.0.0+] SynchronizeNetworkServiceAccountsSnapshotAsync ||&lt;br /&gt;
|-&lt;br /&gt;
| 290 || ProxyProcedureForGuestLoginWithNintendoAccount || Returns an [[#IOAuthProcedureForExternalNsa]] (formerly [[#IOAuthProcedureForGuestLogin]] with [1.0.0-2.3.0]).&lt;br /&gt;
|-&lt;br /&gt;
| 291 || [3.0.0+] ProxyProcedureForFloatingRegistrationWithNintendoAccount || Returns an [[#IOAuthProcedureForExternalNsa]].&lt;br /&gt;
|-&lt;br /&gt;
| 292 || [20.0.0+] ProxyProcedureForDeviceMigrationAuthenticatingOperatingUser ||&lt;br /&gt;
|-&lt;br /&gt;
| 293 || [20.0.0+] ProxyProcedureForDeviceMigrationDownload ||&lt;br /&gt;
|-&lt;br /&gt;
| 299 || SuspendBackgroundDaemon || Returns an [[#ISessionObject]].&lt;br /&gt;
|-&lt;br /&gt;
| 350 || [20.0.0+] CreateDeviceMigrationUserExportRequest ||&lt;br /&gt;
|-&lt;br /&gt;
| 351 || [20.0.0+] UploadNasCredential ||&lt;br /&gt;
|-&lt;br /&gt;
| 352 || [20.0.0+] CreateDeviceMigrationUserImportRequest ||&lt;br /&gt;
|-&lt;br /&gt;
| 353 || [20.0.0+] DeleteUserMigrationSaveData ||&lt;br /&gt;
|-&lt;br /&gt;
| 400 || [18.0.0+] SetPinCode ||&lt;br /&gt;
|-&lt;br /&gt;
| 401 || [18.0.0+] GetPinCodeLength ||&lt;br /&gt;
|-&lt;br /&gt;
| 402 || [18.0.0-19.0.1] GetPinCode ||&lt;br /&gt;
|-&lt;br /&gt;
| 403 || [20.0.0+] GetPinCodeParity ||&lt;br /&gt;
|-&lt;br /&gt;
| 404 || [20.0.0+] VerifyPinCode ||&lt;br /&gt;
|-&lt;br /&gt;
| 405 || [20.0.0+] IsPinCodeVerificationForbidden ||&lt;br /&gt;
|-&lt;br /&gt;
| 410 || [18.0.0+] GetPinCodeErrorCount ||&lt;br /&gt;
|-&lt;br /&gt;
| 411 || [18.0.0-19.0.1] ResetPinCodeErrorCount ||&lt;br /&gt;
|-&lt;br /&gt;
| 412 || [18.0.0-19.0.1] IncrementPinCodeErrorCount ||&lt;br /&gt;
|-&lt;br /&gt;
| 413 || [20.0.0+] SetPinCodeErrorCount ||&lt;br /&gt;
|-&lt;br /&gt;
| 420 || [19.0.0+] SetStartPenaltyTime || &lt;br /&gt;
|-&lt;br /&gt;
| 421 || [19.0.0+] GetStartPenaltyTime || &lt;br /&gt;
|-&lt;br /&gt;
| 900 || [13.0.0+] SetUserUnqualifiedForDebug ||&lt;br /&gt;
|-&lt;br /&gt;
| 901 || [13.0.0+] UnsetUserUnqualifiedForDebug ||&lt;br /&gt;
|-&lt;br /&gt;
| 902 || [13.0.0+] ListUsersUnqualifiedForDebug ||&lt;br /&gt;
|-&lt;br /&gt;
| 910 || [16.0.0+] RefreshFirmwareSettingsForDebug ||&lt;br /&gt;
|-&lt;br /&gt;
| 997 || [3.0.0+] DebugInvalidateTokenCacheForUser ||&lt;br /&gt;
|-&lt;br /&gt;
| 998 || DebugSetUserStateClose ||&lt;br /&gt;
|-&lt;br /&gt;
| 999 || DebugSetUserStateOpen ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[10.0.0+] DebugSetUserStateClose/DebugSetUserStateOpen now takes an additional 8-bytes of input.&lt;br /&gt;
&lt;br /&gt;
== IsUserRegistrationRequestPermitted ==&lt;br /&gt;
Takes a PID, an input u64 pid_reserved, and returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
== TrySelectUserWithoutInteraction ==&lt;br /&gt;
Takes an input u8 bool isNetworkServiceAccountRequired, returns an output Uid.&lt;br /&gt;
&lt;br /&gt;
== IManagerForSystemService ==&lt;br /&gt;
This is &amp;quot;nn::account::baas::IManagerForSystemService&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || CheckAvailability ||&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GetAccountId ||&lt;br /&gt;
|-&lt;br /&gt;
| 2 || EnsureIdTokenCacheAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [19.0.0+] LoadIdTokenCacheDeprecated ([1.0.0-18.1.0] LoadIdTokenCache) ||&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [19.0.0+] LoadIdTokenCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 100 || SetSystemProgramIdentification ||&lt;br /&gt;
|-&lt;br /&gt;
| 101 || RefreshNotificationTokenAsync || &lt;br /&gt;
|-&lt;br /&gt;
| 110 || GetServiceEntryRequirementCacheForLogin ||&lt;br /&gt;
|-&lt;br /&gt;
| 111 || InvalidateServiceEntryRequirementCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 113 || GetServiceEntryRequirementCacheForOnlinePlay || Takes a total of 0x8-bytes of input, returns a total of 0x4-bytes of output.&lt;br /&gt;
|-&lt;br /&gt;
| 120 || GetNintendoAccountId ||&lt;br /&gt;
|-&lt;br /&gt;
| 121 || CalculateNintendoAccountAuthenticationFingerprint ||&lt;br /&gt;
|-&lt;br /&gt;
| 130 || GetNintendoAccountUserResourceCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 131 || RefreshNintendoAccountUserResourceCacheAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 132 || RefreshNintendoAccountUserResourceCacheAsyncIfSecondsElapsed || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 133 || GetNintendoAccountVerificationUrlCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 134 || RefreshNintendoAccountVerificationUrlCacheAsync ||&lt;br /&gt;
|-&lt;br /&gt;
| 135 || RefreshNintendoAccountVerificationUrlCacheAsyncIfSecondsElapsed ||&lt;br /&gt;
|-&lt;br /&gt;
| 136 || [19.0.0+] GetNintendoAccountUserResourceCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 140 || GetNetworkServiceLicenseCache || &lt;br /&gt;
|-&lt;br /&gt;
| 141 || RefreshNetworkServiceLicenseCacheAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 142 || RefreshNetworkServiceLicenseCacheAsyncIfSecondsElapsed || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 143 || [15.0.0+] GetNetworkServiceLicenseCacheEx ||&lt;br /&gt;
|-&lt;br /&gt;
| 150 || CreateAuthorizationRequest || Returns an [[#IAuthorizationRequest]].&lt;br /&gt;
|-&lt;br /&gt;
| 160 || [15.0.0+] RequiresUpdateNetworkServiceAccountIdTokenCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 161 || [16.0.0+] RequireReauthenticationOfNetworkServiceAccount ||&lt;br /&gt;
|-&lt;br /&gt;
| 180 || [18.0.0-19.0.1] GetRequestForNintendoAccountReauthentication ||&lt;br /&gt;
|-&lt;br /&gt;
| 181 || [20.0.0+] CreateProcedureToReauthenticateNintendoAccount ||&lt;br /&gt;
|-&lt;br /&gt;
| 182 || [20.0.0+] ResumeProcedureToReauthenticateNintendoAccount ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IFloatingRegistrationRequest ==&lt;br /&gt;
This is &amp;quot;nn::account::baas::IFloatingRegistrationRequest&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
Added with [3.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetSessionId ||&lt;br /&gt;
|-&lt;br /&gt;
| 12 || GetAccountId ||&lt;br /&gt;
|-&lt;br /&gt;
| 13 || GetLinkedNintendoAccountId ||&lt;br /&gt;
|-&lt;br /&gt;
| 14 || GetNickname ||&lt;br /&gt;
|-&lt;br /&gt;
| 15 || GetProfileImage ||&lt;br /&gt;
|-&lt;br /&gt;
| 16 || [18.0.0+] GetProfileLargeImage ||&lt;br /&gt;
|-&lt;br /&gt;
| 21 || LoadIdTokenCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 100 || RegisterUser ([1.0.0-3.0.2] RegisterAsync) || [1.0.0-3.0.2] Used to return an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 101 || RegisterUserWithUid ([1.0.0-3.0.2] RegisterWithUidAsync) || [1.0.0-3.0.2] Used to return an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 102 || [4.0.0+] RegisterNetworkServiceAccountAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 103 || [4.0.0+] RegisterNetworkServiceAccountWithUidAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 110 || SetSystemProgramIdentification ||&lt;br /&gt;
|-&lt;br /&gt;
| 111 || EnsureIdTokenCacheAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IAdministrator ==&lt;br /&gt;
This is &amp;quot;nn::account::baas::IAdministrator&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || CheckAvailability ||&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GetAccountId ||&lt;br /&gt;
|-&lt;br /&gt;
| 2 || EnsureIdTokenCacheAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [19.0.0+] LoadIdTokenCacheDeprecated ([1.0.0-18.1.0] LoadIdTokenCache) ||&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [19.0.0+] LoadIdTokenCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 100 || SetSystemProgramIdentification ||&lt;br /&gt;
|-&lt;br /&gt;
| 101 || [7.0.0+] RefreshNotificationTokenAsync&lt;br /&gt;
|-&lt;br /&gt;
| 110 || [4.0.0+] GetServiceEntryRequirementCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 111 || [4.0.0+] InvalidateServiceEntryRequirementCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 112 || [4.0.0-6.2.0] InvalidateTokenCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 113 || [6.1.0+] GetServiceEntryRequirementCacheForOnlinePlay || Takes a total of 0x8-bytes of input, returns a total of 0x4-bytes of output.&lt;br /&gt;
|-&lt;br /&gt;
| 120 || GetNintendoAccountId ||&lt;br /&gt;
|-&lt;br /&gt;
| 121 || [9.0.0+] CalculateNintendoAccountAuthenticationFingerprint ||&lt;br /&gt;
|-&lt;br /&gt;
| 130 || GetNintendoAccountUserResourceCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 131 || RefreshNintendoAccountUserResourceCacheAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 132 || RefreshNintendoAccountUserResourceCacheAsyncIfSecondsElapsed || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 133 || [9.0.0+] GetNintendoAccountVerificationUrlCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 134 || [9.0.0+] RefreshNintendoAccountVerificationUrlCacheAsync ||&lt;br /&gt;
|-&lt;br /&gt;
| 135 || [9.0.0+] RefreshNintendoAccountVerificationUrlCacheAsyncIfSecondsElapsed ||&lt;br /&gt;
|-&lt;br /&gt;
| 136 || [19.0.0+] GetNintendoAccountUserResourceCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 140 || [5.0.0+] GetNetworkServiceLicenseCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 141 || [5.0.0+] RefreshNetworkServiceLicenseCacheAsync ||&lt;br /&gt;
|-&lt;br /&gt;
| 142 || [5.0.0+] RefreshNetworkServiceLicenseCacheAsyncIfSecondsElapsed ||&lt;br /&gt;
|-&lt;br /&gt;
| 143 || [15.0.0+] GetNetworkServiceLicenseCacheEx ||&lt;br /&gt;
|-&lt;br /&gt;
| 150 || CreateAuthorizationRequest || Returns an [[#IAuthorizationRequest]].&lt;br /&gt;
|-&lt;br /&gt;
| 160 || [15.0.0+] RequiresUpdateNetworkServiceAccountIdTokenCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 161 || [16.0.0+] RequireReauthenticationOfNetworkServiceAccount ||&lt;br /&gt;
|-&lt;br /&gt;
| 180 || [18.0.0-19.0.1] GetRequestForNintendoAccountReauthentication ||&lt;br /&gt;
|-&lt;br /&gt;
| 181 || [20.0.0+] CreateProcedureToReauthenticateNintendoAccount ||&lt;br /&gt;
|-&lt;br /&gt;
| 182 || [20.0.0+] ResumeProcedureToReauthenticateNintendoAccount ||&lt;br /&gt;
|-&lt;br /&gt;
| 200 || IsRegistered ||&lt;br /&gt;
|-&lt;br /&gt;
| 201 || RegisterAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 202 || UnregisterAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 203 || DeleteRegistrationInfoLocally ||&lt;br /&gt;
|-&lt;br /&gt;
| 204 || [19.0.0-19.0.1] UnregisterDeviceAsync ||&lt;br /&gt;
|-&lt;br /&gt;
| 220 || SynchronizeProfileAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 221 || UploadProfileAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 222 || SynchronizeProfileAsyncIfSecondsElapsed || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 223 || [19.0.0+] DownloadProfileAsync ||&lt;br /&gt;
|-&lt;br /&gt;
| 250 || IsLinkedWithNintendoAccount ||&lt;br /&gt;
|-&lt;br /&gt;
| 251 || CreateProcedureToLinkWithNintendoAccount || Returns an [[#IOAuthProcedureForNintendoAccountLinkage]].&lt;br /&gt;
|-&lt;br /&gt;
| 252 || ResumeProcedureToLinkWithNintendoAccount || Returns an [[#IOAuthProcedureForNintendoAccountLinkage]].&lt;br /&gt;
|-&lt;br /&gt;
| 255 || CreateProcedureToUpdateLinkageStateOfNintendoAccount || Returns an [[#IOAuthProcedure]].&lt;br /&gt;
|-&lt;br /&gt;
| 256 || ResumeProcedureToUpdateLinkageStateOfNintendoAccount || Returns an [[#IOAuthProcedure]].&lt;br /&gt;
|-&lt;br /&gt;
| 260 || [3.0.0+] CreateProcedureToLinkNnidWithNintendoAccount || Returns an [[#IOAuthProcedure]].&lt;br /&gt;
|-&lt;br /&gt;
| 261 || [3.0.0+] ResumeProcedureToLinkNnidWithNintendoAccount || Returns an [[#IOAuthProcedure]].&lt;br /&gt;
|-&lt;br /&gt;
| 280 || ProxyProcedureToAcquireApplicationAuthorizationForNintendoAccount || Returns an [[#IOAuthProcedure]].&lt;br /&gt;
|-&lt;br /&gt;
| 290 || [8.0.0+] GetRequestForNintendoAccountUserResourceView || &lt;br /&gt;
|-&lt;br /&gt;
| 300 || [6.0.0+] TryRecoverNintendoAccountUserStateAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 400 || [6.1.0+] IsServiceEntryRequirementCacheRefreshRequiredForOnlinePlay || Takes a total of 0x8-bytes of input, returns an output u8.&lt;br /&gt;
|-&lt;br /&gt;
| 401 || [6.1.0+] RefreshServiceEntryRequirementCacheForOnlinePlayAsync || Takes a total of 0x8-bytes of input, returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 900 || [9.0.0+] GetAuthenticationInfoForWin ||&lt;br /&gt;
|-&lt;br /&gt;
| 901 || [9.0.0+] ImportAsyncForWin ||&lt;br /&gt;
|-&lt;br /&gt;
| 997 || DebugUnlinkNintendoAccountAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 998 || DebugSetAvailabilityErrorDetail ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IAuthorizationRequest ==&lt;br /&gt;
This is &amp;quot;nn::account::nas::IAuthorizationRequest&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetSessionId ||&lt;br /&gt;
|-&lt;br /&gt;
| 10 || InvokeWithoutInteractionAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 19 || IsAuthorized ||&lt;br /&gt;
|-&lt;br /&gt;
| 20 || GetAuthorizationCode ||&lt;br /&gt;
|-&lt;br /&gt;
| 21 || GetIdToken ||&lt;br /&gt;
|-&lt;br /&gt;
| 22 || GetState ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IOAuthProcedure ==&lt;br /&gt;
This is &amp;quot;nn::account::http::IOAuthProcedure&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || PrepareAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GetRequest ||&lt;br /&gt;
|-&lt;br /&gt;
| 2 || ApplyResponse ||&lt;br /&gt;
|-&lt;br /&gt;
| 3 || ApplyResponseAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 10 || Suspend ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IOAuthProcedureForExternalNsa ==&lt;br /&gt;
This is &amp;quot;nn::account::nas::IOAuthProcedureForExternalNsa&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
Added with [3.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || PrepareAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GetRequest ||&lt;br /&gt;
|-&lt;br /&gt;
| 2 || ApplyResponse ||&lt;br /&gt;
|-&lt;br /&gt;
| 3 || ApplyResponseAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 10 || Suspend ||&lt;br /&gt;
|-&lt;br /&gt;
| 100 || GetAccountId ||&lt;br /&gt;
|-&lt;br /&gt;
| 101 || GetLinkedNintendoAccountId ||&lt;br /&gt;
|-&lt;br /&gt;
| 102 || GetNickname ||&lt;br /&gt;
|-&lt;br /&gt;
| 103 || GetProfileImage ||&lt;br /&gt;
|-&lt;br /&gt;
| 104 || [18.0.0+] GetProfileLargeImage ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IOAuthProcedureForNintendoAccountLinkage ==&lt;br /&gt;
This is &amp;quot;nn::account::nas::IOAuthProcedureForNintendoAccountLinkage&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || PrepareAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GetRequest ||&lt;br /&gt;
|-&lt;br /&gt;
| 2 || ApplyResponse ||&lt;br /&gt;
|-&lt;br /&gt;
| 3 || ApplyResponseAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 10 || Suspend ||&lt;br /&gt;
|-&lt;br /&gt;
| 100 || GetRequestWithTheme ||&lt;br /&gt;
|-&lt;br /&gt;
| 101 || IsNetworkServiceAccountReplaced ||&lt;br /&gt;
|-&lt;br /&gt;
| 199 || [2.0.0-5.1.0] GetUrlForIntroductionOfExtraMembership ||&lt;br /&gt;
|-&lt;br /&gt;
| 200 || [16.0.0+] ApplyAsyncWithAuthorizedToken ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== INotifier ==&lt;br /&gt;
This is &amp;quot;nn::account::detail::INotifier&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetSystemEvent&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IProfile ==&lt;br /&gt;
This is &amp;quot;nn::account::profile::IProfile&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#Get]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#GetBase]]&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [[#GetImageSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [[#LoadImage]]&lt;br /&gt;
|-&lt;br /&gt;
| 20 || [18.0.0+] GetLargeImageSize&lt;br /&gt;
|-&lt;br /&gt;
| 21 || [18.0.0+] LoadLargeImage&lt;br /&gt;
|-&lt;br /&gt;
| 30 || [18.0.0+] GetImageId&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Get ===&lt;br /&gt;
Takes an output type-0x1A buffer for [[#UserData]], returns an output [[#ProfileBase]].&lt;br /&gt;
&lt;br /&gt;
=== GetBase ===&lt;br /&gt;
No input, returns an output [[#ProfileBase]].&lt;br /&gt;
&lt;br /&gt;
=== GetImageSize ===&lt;br /&gt;
No input, returns an output u32 for the size of the image buffer.&lt;br /&gt;
&lt;br /&gt;
=== LoadImage === &lt;br /&gt;
Takes an output type-0x6 buffer, returns the same output u32 as [[#GetImageSize]].&lt;br /&gt;
&lt;br /&gt;
The output buffer contains the JPEG profile image icon. This is valid for both Miis and character icons.&lt;br /&gt;
&lt;br /&gt;
== IProfileEditor ==&lt;br /&gt;
This is &amp;quot;nn::account::profile::IProfileEditor&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#Get]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#GetBase]]&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [[#GetImageSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [[#LoadImage]]&lt;br /&gt;
|-&lt;br /&gt;
| 20 || [18.0.0+] GetLargeImageSize&lt;br /&gt;
|-&lt;br /&gt;
| 21 || [18.0.0+] LoadLargeImage&lt;br /&gt;
|-&lt;br /&gt;
| 30 || [18.0.0+] GetImageId&lt;br /&gt;
|-&lt;br /&gt;
| 100 || [[#Store]]&lt;br /&gt;
|-&lt;br /&gt;
| 101 || [[#StoreWithImage]]&lt;br /&gt;
|-&lt;br /&gt;
| 110 || [18.0.0+] StoreWithLargeImage&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Store ===&lt;br /&gt;
Takes a [[#ProfileBase]] and an input type-0x19 buffer for [[#UserData]].&lt;br /&gt;
&lt;br /&gt;
=== StoreWithImage ===&lt;br /&gt;
Takes a [[#ProfileBase]], an input type-0x19 buffer for [[#UserData]], and an input type-0x5 buffer.&lt;br /&gt;
&lt;br /&gt;
== IAsyncContext ==&lt;br /&gt;
This is &amp;quot;nn::account::detail::IAsyncContext&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetSystemEvent&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Cancel&lt;br /&gt;
|-&lt;br /&gt;
| 2 || HasDone&lt;br /&gt;
|-&lt;br /&gt;
| 3 || GetResult&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== ISessionObject ==&lt;br /&gt;
This is &amp;quot;nn::account::detail::ISessionObject&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 999 || Dummy&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= acc:u0 =&lt;br /&gt;
This is &amp;quot;nn::account::IAccountServiceForApplication&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
[13.0.0+] This was moved from [[Account_services|account]].&lt;br /&gt;
&lt;br /&gt;
This is only available when the output from [[Process_Manager_services|pm:bm]] GetBootMode is Normal/Maintenance.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetUserCount ||&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GetUserExistence ||&lt;br /&gt;
|-&lt;br /&gt;
| 2 || ListAllUsers ||&lt;br /&gt;
|-&lt;br /&gt;
| 3 || ListOpenUsers ||&lt;br /&gt;
|-&lt;br /&gt;
| 4 || GetLastOpenedUser ||&lt;br /&gt;
|-&lt;br /&gt;
| 5 || GetProfile || Takes an input userID, returns an [[#IProfile]].&lt;br /&gt;
|-&lt;br /&gt;
| 6 || [3.0.0+] GetProfileDigest ||&lt;br /&gt;
|-&lt;br /&gt;
| 50 || [[#IsUserRegistrationRequestPermitted]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 51 || TrySelectUserWithoutInteractionDeprecated ([1.0.0-18.1.0] [[#TrySelectUserWithoutInteraction]]) ||&lt;br /&gt;
|-&lt;br /&gt;
| 52 || [19.0.0+] TrySelectUserWithoutInteraction ||&lt;br /&gt;
|-&lt;br /&gt;
| 60 || [5.0.0-5.1.0] ListOpenContextStoredUsers ||&lt;br /&gt;
|-&lt;br /&gt;
| 99 || [6.0.0+] DebugActivateOpenContextRetention || No input, returns an [[#ISessionObject]].&lt;br /&gt;
|-&lt;br /&gt;
| 100 || [[#InitializeApplicationInfoV0]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 101 || GetBaasAccountManagerForApplication || Takes an input userID, returns an [[#IManagerForApplication]].&lt;br /&gt;
|-&lt;br /&gt;
| 102 || AuthenticateApplicationAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 103 || [4.0.0+] CheckNetworkServiceAvailabilityAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 110 || StoreSaveDataThumbnail ||&lt;br /&gt;
|-&lt;br /&gt;
| 111 || ClearSaveDataThumbnail ||&lt;br /&gt;
|-&lt;br /&gt;
| 120 || CreateGuestLoginRequest || Returns an [[#IGuestLoginRequest]].&lt;br /&gt;
|-&lt;br /&gt;
| 130 || [5.0.0+] LoadOpenContext ||&lt;br /&gt;
|-&lt;br /&gt;
| 131 || [6.0.0+] ListOpenContextStoredUsers || &lt;br /&gt;
|-&lt;br /&gt;
| 140 || [6.0.0+] [[#InitializeApplicationInfoV1]] || &lt;br /&gt;
|-&lt;br /&gt;
| 141 || [6.0.0+] ListQualifiedUsers || &lt;br /&gt;
|-&lt;br /&gt;
| 150 || [6.0.0+] IsUserAccountSwitchLocked || &lt;br /&gt;
|-&lt;br /&gt;
| 160 || [13.0.0+] InitializeApplicationInfoV2 || &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
InitializeApplicationInfo* is used by the user-process during service init.&lt;br /&gt;
&lt;br /&gt;
== InitializeApplicationInfoV0 ==&lt;br /&gt;
Takes a PID and an input u64 pid_placeholder, no output.&lt;br /&gt;
&lt;br /&gt;
== InitializeApplicationInfoV1 ==&lt;br /&gt;
Takes a PID and an input u64 pid_placeholder, no output.&lt;br /&gt;
&lt;br /&gt;
== IGuestLoginRequest ==&lt;br /&gt;
This is &amp;quot;nn::account::baas::IGuestLoginRequest&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetSessionId&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [1.0.0-2.3.0] &lt;br /&gt;
|-&lt;br /&gt;
| 12 || GetAccountId&lt;br /&gt;
|-&lt;br /&gt;
| 13 || GetLinkedNintendoAccountId&lt;br /&gt;
|-&lt;br /&gt;
| 14 || GetNickname&lt;br /&gt;
|-&lt;br /&gt;
| 15 || GetProfileImage&lt;br /&gt;
|-&lt;br /&gt;
| 16 || [18.0.0+] GetProfileLargeImage&lt;br /&gt;
|-&lt;br /&gt;
| 21 || [3.0.0+] LoadIdTokenCache&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IManagerForApplication ==&lt;br /&gt;
This is &amp;quot;nn::account::baas::IManagerForApplication&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || CheckAvailability ||&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GetAccountId ||&lt;br /&gt;
|-&lt;br /&gt;
| 2 || EnsureIdTokenCacheAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 3 || LoadIdTokenCache ||&lt;br /&gt;
|-&lt;br /&gt;
| 130 || GetNintendoAccountUserResourceCacheForApplication ||&lt;br /&gt;
|-&lt;br /&gt;
| 150 || CreateAuthorizationRequest || Returns an [[#IAuthorizationRequest]].&lt;br /&gt;
|-&lt;br /&gt;
| 160 || [5.0.0+] StoreOpenContext ||&lt;br /&gt;
|-&lt;br /&gt;
| 170 || [13.0.0+] EnsureIdTokenCacheForOnlinePlayAsync ([6.0.0-12.1.0] LoadNetworkServiceLicenseKindAsync) || No input, returns an [[#IAsyncContextForLoginForOnlinePlay]] ([6.0.0-12.1.0] [[#IAsyncNetworkServiceLicenseKindContext]]).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IAsyncNetworkServiceLicenseKindContext ==&lt;br /&gt;
This is &amp;quot;nn::account::detail::IAsyncNetworkServiceLicenseKindContext&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [6.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetSystemEvent || &lt;br /&gt;
|-&lt;br /&gt;
| 1 || Cancel || &lt;br /&gt;
|-&lt;br /&gt;
| 2 || HasDone || &lt;br /&gt;
|-&lt;br /&gt;
| 3 || GetResult || &lt;br /&gt;
|-&lt;br /&gt;
| 100 || GetNetworkServiceLicenseKind || &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IAsyncContextForLoginForOnlinePlay ==&lt;br /&gt;
This is &amp;quot;nn::account::baas::IAsyncContextForLoginForOnlinePlay&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [13.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetSystemEvent || &lt;br /&gt;
|-&lt;br /&gt;
| 1 || Cancel || &lt;br /&gt;
|-&lt;br /&gt;
| 2 || HasDone || &lt;br /&gt;
|-&lt;br /&gt;
| 3 || GetResult || &lt;br /&gt;
|-&lt;br /&gt;
| 100 || GetNetworkServiceLicenseInfoForOnlinePlay || &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= acc:u1 =&lt;br /&gt;
This is &amp;quot;nn::account::IAccountServiceForSystemService&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
[13.0.0+] This was moved from [[Account_services|account]].&lt;br /&gt;
&lt;br /&gt;
This is only available when the output from [[Process_Manager_services|pm:bm]] GetBootMode is Normal/Maintenance.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetUserCount ||&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GetUserExistence ||&lt;br /&gt;
|-&lt;br /&gt;
| 2 || ListAllUsers ||&lt;br /&gt;
|-&lt;br /&gt;
| 3 || ListOpenUsers ||&lt;br /&gt;
|-&lt;br /&gt;
| 4 || GetLastOpenedUser ||&lt;br /&gt;
|-&lt;br /&gt;
| 5 || GetProfile || Returns an [[#IProfile]].&lt;br /&gt;
|-&lt;br /&gt;
| 6 || [3.0.0+] GetProfileDigest ||&lt;br /&gt;
|-&lt;br /&gt;
| 50 || [[#IsUserRegistrationRequestPermitted]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 51 || TrySelectUserWithoutInteractionDeprecated ([1.0.0-18.1.0] [[#TrySelectUserWithoutInteraction]]) ||&lt;br /&gt;
|-&lt;br /&gt;
| 52 || [19.0.0+] TrySelectUserWithoutInteraction ||&lt;br /&gt;
|-&lt;br /&gt;
| 60 || [5.0.0-5.1.0] ListOpenContextStoredUsers ||&lt;br /&gt;
|-&lt;br /&gt;
| 99 || [6.0.0+] DebugActivateOpenContextRetention || No input, returns an [[#ISessionObject]].&lt;br /&gt;
|-&lt;br /&gt;
| 100 || GetUserRegistrationNotifier || Returns an [[#INotifier]].&lt;br /&gt;
|-&lt;br /&gt;
| 101 || GetUserStateChangeNotifier || Returns an [[#INotifier]].&lt;br /&gt;
|-&lt;br /&gt;
| 102 || GetBaasAccountManagerForSystemService || Returns an [[#IManagerForSystemService]].&lt;br /&gt;
|-&lt;br /&gt;
| 103 || GetBaasUserAvailabilityChangeNotifier || Returns an [[#INotifier]].&lt;br /&gt;
|-&lt;br /&gt;
| 104 || GetProfileUpdateNotifier || Returns an [[#INotifier]].&lt;br /&gt;
|-&lt;br /&gt;
| 105 || [4.0.0+] CheckNetworkServiceAvailabilityAsync || Returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 106 || [9.0.0+] GetProfileSyncNotifier ||&lt;br /&gt;
|-&lt;br /&gt;
| 110 || StoreSaveDataThumbnail ||&lt;br /&gt;
|-&lt;br /&gt;
| 111 || ClearSaveDataThumbnail ||&lt;br /&gt;
|-&lt;br /&gt;
| 112 || LoadSaveDataThumbnail ||&lt;br /&gt;
|-&lt;br /&gt;
| 113 || [5.0.0+] GetSaveDataThumbnailExistence ||&lt;br /&gt;
|-&lt;br /&gt;
| 120 || [10.0.0+] ListOpenUsersInApplication ||&lt;br /&gt;
|-&lt;br /&gt;
| 130 || [6.0.0+] ActivateOpenContextRetention || Takes a total of 0x8-bytes of input, returns an [[#ISessionObject]].&lt;br /&gt;
|-&lt;br /&gt;
| 140 || [6.0.0+] ListQualifiedUsers || &lt;br /&gt;
|-&lt;br /&gt;
| 150 || [10.0.0-10.2.0] AuthenticateApplicationAsync ||&lt;br /&gt;
|-&lt;br /&gt;
| 151 || [12.0.0+] EnsureSignedDeviceIdentifierCacheForNintendoAccountAsync || &lt;br /&gt;
|-&lt;br /&gt;
| 152 || [12.0.0+] LoadSignedDeviceIdentifierCacheForNintendoAccount ||&lt;br /&gt;
|-&lt;br /&gt;
| 170 || [13.0.0+] GetNasOp2MembershipStateChangeNotifier ||&lt;br /&gt;
|-&lt;br /&gt;
| 190 || [1.0.0-9.2.0] GetUserLastOpenedApplication ||&lt;br /&gt;
|-&lt;br /&gt;
| 191 || [7.0.0-19.0.1] UpdateNotificationReceiverInfo ([5.0.0-5.1.0] ActivateOpenContextHolder) ||&lt;br /&gt;
|-&lt;br /&gt;
| 401 || [18.0.0+] GetPinCodeLength ||&lt;br /&gt;
|-&lt;br /&gt;
| 402 || [18.0.0-19.0.1] GetPinCode ||&lt;br /&gt;
|-&lt;br /&gt;
| 403 || [20.0.0+] GetPinCodeParity ||&lt;br /&gt;
|-&lt;br /&gt;
| 404 || [20.0.0+] VerifyPinCode ||&lt;br /&gt;
|-&lt;br /&gt;
| 405 || [20.0.0+] IsPinCodeVerificationForbidden ||&lt;br /&gt;
|-&lt;br /&gt;
| 997 || [3.0.0+] DebugInvalidateTokenCacheForUser ||&lt;br /&gt;
|-&lt;br /&gt;
| 998 || DebugSetUserStateClose ||&lt;br /&gt;
|-&lt;br /&gt;
| 999 || DebugSetUserStateOpen ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[10.0.0+] DebugSetUserStateClose/DebugSetUserStateOpen now takes an additional 8-bytes of input. &lt;br /&gt;
&lt;br /&gt;
== IOAuthProcedureForUserRegistration ==&lt;br /&gt;
This is &amp;quot;nn::account::nas::IOAuthProcedureForUserRegistration&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [8.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || PrepareAsync || No input, returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GetRequest || &lt;br /&gt;
|-&lt;br /&gt;
| 2 || ApplyResponse || &lt;br /&gt;
|-&lt;br /&gt;
| 3 || ApplyResponseAsync || Takes a type-0x9 input buffer, returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 10 || Suspend || &lt;br /&gt;
|-&lt;br /&gt;
| 100 || GetAccountId || &lt;br /&gt;
|-&lt;br /&gt;
| 101 || GetLinkedNintendoAccountId || &lt;br /&gt;
|-&lt;br /&gt;
| 102 || GetNickname || &lt;br /&gt;
|-&lt;br /&gt;
| 103 || GetProfileImage || &lt;br /&gt;
|-&lt;br /&gt;
| 104 || [18.0.0+] GetProfileLargeImage || &lt;br /&gt;
|-&lt;br /&gt;
| 110 || RegisterUserAsync || No input, returns an [[#IAsyncContext]].&lt;br /&gt;
|-&lt;br /&gt;
| 111 || GetUid || &lt;br /&gt;
|-&lt;br /&gt;
| 200 || [17.0.0+] ApplyResponseForUserCreationAsync || &lt;br /&gt;
|-&lt;br /&gt;
| 205 || [17.0.0+] SuspendAfterApplyResponse || &lt;br /&gt;
|-&lt;br /&gt;
| 210 || [17.0.0+] IsProfileAvailable || &lt;br /&gt;
|-&lt;br /&gt;
| 220 || [17.0.0+] RegisterUserAsyncWithoutProfile || &lt;br /&gt;
|-&lt;br /&gt;
| 221 || [17.0.0+] RegisterUserWithProfileAsync || &lt;br /&gt;
|-&lt;br /&gt;
| 230 || [18.0.0+] RegisterUserWithLargeImageProfileAsync || &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationRecord =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationRecord&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0&lt;br /&gt;
| 0x8&lt;br /&gt;
| [[NCM_services#ApplicationId|Id]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x8&lt;br /&gt;
| 0x1&lt;br /&gt;
| [[#ApplicationEvent|LastEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x9&lt;br /&gt;
| 0x1&lt;br /&gt;
| Attributes&lt;br /&gt;
|-&lt;br /&gt;
| 0xA&lt;br /&gt;
| 0x6&lt;br /&gt;
| Reserved&lt;br /&gt;
|-&lt;br /&gt;
| 0x10&lt;br /&gt;
| 0x8&lt;br /&gt;
| LastUpdated&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationEvent =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationEvent&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || Launched&lt;br /&gt;
|-&lt;br /&gt;
| 1 || LocalInstalled&lt;br /&gt;
|-&lt;br /&gt;
| 2 || DownloadStarted&lt;br /&gt;
|-&lt;br /&gt;
| 3 || GameCardInserted&lt;br /&gt;
|-&lt;br /&gt;
| 4 || Touched&lt;br /&gt;
|-&lt;br /&gt;
| 5 || &lt;br /&gt;
|-&lt;br /&gt;
| 6 || &lt;br /&gt;
|-&lt;br /&gt;
| 7 || &lt;br /&gt;
|-&lt;br /&gt;
| 8 || &lt;br /&gt;
|-&lt;br /&gt;
| 9 || &lt;br /&gt;
|-&lt;br /&gt;
| 10 || &lt;br /&gt;
|-&lt;br /&gt;
| 11 || &lt;br /&gt;
|-&lt;br /&gt;
| 12 || &lt;br /&gt;
|-&lt;br /&gt;
| 13 || &lt;br /&gt;
|-&lt;br /&gt;
| 14 || &lt;br /&gt;
|-&lt;br /&gt;
| 15 || &lt;br /&gt;
|-&lt;br /&gt;
| 16 || &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationControlSource =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationControlSource&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0&lt;br /&gt;
| CacheOnly&lt;br /&gt;
|-&lt;br /&gt;
| 1&lt;br /&gt;
| Storage&lt;br /&gt;
|-&lt;br /&gt;
| 2&lt;br /&gt;
| StorageOnly&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationContentMetaStatus =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationContentMetaStatus&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0&lt;br /&gt;
| 0x1&lt;br /&gt;
| [[NCM_services#ContentMetaType|Type]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x1&lt;br /&gt;
| 0x1&lt;br /&gt;
| [[NCM_services#StorageId|InstalledStorage]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x2&lt;br /&gt;
| 0x1&lt;br /&gt;
| [[#ContentMetaRightsCheck|RightsCheck]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x3&lt;br /&gt;
| 0x1&lt;br /&gt;
| Reserved&lt;br /&gt;
|-&lt;br /&gt;
| 0x4&lt;br /&gt;
| 0x4&lt;br /&gt;
| Version&lt;br /&gt;
|-&lt;br /&gt;
| 0x8&lt;br /&gt;
| 0x8&lt;br /&gt;
| [[NCM_services#ApplicationId|Id]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ContentMetaRightsCheck =&lt;br /&gt;
This is &amp;quot;nn::ns::ContentMetaRightsCheck&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0&lt;br /&gt;
| NotChecked&lt;br /&gt;
|-&lt;br /&gt;
| 1&lt;br /&gt;
| NotNeeded&lt;br /&gt;
|-&lt;br /&gt;
| 2&lt;br /&gt;
| CommonRights&lt;br /&gt;
|-&lt;br /&gt;
| 3&lt;br /&gt;
| PersonalizedRights&lt;br /&gt;
|-&lt;br /&gt;
| 4&lt;br /&gt;
| NoRights&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= VersionListData =&lt;br /&gt;
This is &amp;quot;nn::ns::VersionListData&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
= ApplicationUpdateInfo =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationUpdateInfo&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || UpToDate&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Updatable&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationOccupiedSize =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationOccupiedSize&amp;quot;. This is a 0x80-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x20 * 4 || Array of [[#ApplicationOccupiedSizeEntity]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationOccupiedSizeEntity =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationOccupiedSizeEntity&amp;quot;. This is a 0x20-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x1 || [[NCM_services#StorageId|StorageId]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x1 || 0x7 || Reserved&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x8 || AppSize&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x8 || PatchSize&lt;br /&gt;
|-&lt;br /&gt;
| 0x18 || 0x8 || AocSize&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ProgressForDeleteUserSaveDataAll =&lt;br /&gt;
This is &amp;quot;nn::ns::detail::ProgressForDeleteUserSaveDataAll&amp;quot;. This is a 0x28-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x8 || StartedAt&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x4 || Count&lt;br /&gt;
|-&lt;br /&gt;
| 0xC || 0x4 || Reserved&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x8 || SizeInBytes&lt;br /&gt;
|-&lt;br /&gt;
| 0x18 || 0x1 || IsSystem&lt;br /&gt;
|-&lt;br /&gt;
| 0x19 || 0x7 || Reserved&lt;br /&gt;
|-&lt;br /&gt;
| 0x20 || 0x8 || ApplicationId&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationViewDeprecated =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationViewDeprecated&amp;quot;. This is a 0x40-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x8 || [[NCM_services#ApplicationId|ApplicationId]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x4 || Version&lt;br /&gt;
|-&lt;br /&gt;
| 0xC || 0x4 || [[#ApplicationViewFlag|Flag]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x18 || [[#ApplicationDownloadProgress|Progress]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x28 || 0x18 || [[#ApplicationApplyDeltaProgress|ApplyProgress]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
This is converted from [[#ApplicationView]] by [[#GetApplicationViewDeprecated]] on newer system-versions as follows:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x20 || Same as [[#ApplicationView]] +0x0.&lt;br /&gt;
|-&lt;br /&gt;
| 0x20 || 0x4 || Same as [[#ApplicationView]] +0x20.&lt;br /&gt;
|-&lt;br /&gt;
| 0x24 || 0x2 || Same as [[#ApplicationView]] +0x24.&lt;br /&gt;
|-&lt;br /&gt;
| 0x26 || 0x2 || Cleared to 0.&lt;br /&gt;
|-&lt;br /&gt;
| 0x28 || 0x10 || Same as [[#ApplicationView]] +0x30.&lt;br /&gt;
|-&lt;br /&gt;
| 0x38 || 0x4 || Same as [[#ApplicationView]] +0x40.&lt;br /&gt;
|-&lt;br /&gt;
| 0x3C || 0x1 || Same as [[#ApplicationView]] +0x44.&lt;br /&gt;
|-&lt;br /&gt;
| 0x3D || 0x2 || Cleared to 0.&lt;br /&gt;
|-&lt;br /&gt;
| 0x3F || 0x1 || Cleared to 0.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationViewFlag =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationViewFlag&amp;quot;. This is a 32-bit flag.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Bit&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 1&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 2&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 3&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 4&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 5&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 6&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 7&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 8&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 9&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 10&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 11&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 12&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 13&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 14&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 15&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 16&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 17&lt;br /&gt;
| &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationDownloadProgress =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationDownloadProgress&amp;quot;. This is a 0x18-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x8 || Downloaded&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x8 || Total&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x4 || LastResult&lt;br /&gt;
|-&lt;br /&gt;
| 0x14 || 0x1 || [[#ApplicationDownloadState|State]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x15 || 0x3 || Reserved&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationApplyDeltaProgress =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationApplyDeltaProgress&amp;quot;. This is a 0x18-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x8 || Applied&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x8 || Total&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x4 || LastResult&lt;br /&gt;
|-&lt;br /&gt;
| 0x14 || 0x1 || [[#ApplicationApplyDeltaState|State]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x15 || 0x3 || Reserved&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationDownloadState =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationDownloadState&amp;quot;. This is an u8.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || Runnable&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Suspended&lt;br /&gt;
|-&lt;br /&gt;
| 2 || NotEnoughSpace&lt;br /&gt;
|-&lt;br /&gt;
| 3 || Fatal&lt;br /&gt;
|-&lt;br /&gt;
| 4 || Finished&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationApplyDeltaState =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationApplyDeltaState&amp;quot;. This is an u8.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || Applying&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Suspended&lt;br /&gt;
|-&lt;br /&gt;
| 2 || NotEnoughSpace&lt;br /&gt;
|-&lt;br /&gt;
| 3 || Fatal&lt;br /&gt;
|-&lt;br /&gt;
| 4 || NoTask&lt;br /&gt;
|-&lt;br /&gt;
| 5 || WaitApply&lt;br /&gt;
|-&lt;br /&gt;
| 6 || Applied&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationView =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationView&amp;quot;. This is a 0x50-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x8 || [[NCM_services#ApplicationId|ApplicationId]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x4 || ?&lt;br /&gt;
|-&lt;br /&gt;
| 0xC || 0x4 || Flags&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x40 || ?&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationViewWithPromotionInfo =&lt;br /&gt;
This is a 0x70-byte struct.&lt;br /&gt;
&lt;br /&gt;
[20.0.0+] This is a 0x78-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x50 || [[#ApplicationView]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x50 || 0x20 || [[#PromotionInfo]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= PromotionInfo =&lt;br /&gt;
This is a 0x20-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x8 || PosixTime start_timestamp.&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x8 || PosixTime end_timestamp.&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x8 || Remaining time until the promotion ends, in nanoseconds ({end_timestamp - current_time} converted to nanoseconds).&lt;br /&gt;
|-&lt;br /&gt;
| 0x18 || 0x4 || Not set, left at zero.&lt;br /&gt;
|-&lt;br /&gt;
| 0x1C || 0x1 || Flags. Bit0: whether the PromotionInfo is valid (including bit1). Bit1 clear: u64 +0x10 is set.&lt;br /&gt;
|-&lt;br /&gt;
| 0x1D || 0x3 || Padding&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationResourceType =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationResourceType&amp;quot;. This is an u8.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || ApplicationResource&lt;br /&gt;
|-&lt;br /&gt;
| 1 || MicroApplicationResource&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationErrorCodeCategory =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationErrorCodeCategory&amp;quot;. This is an u64.&lt;br /&gt;
&lt;br /&gt;
= NoDownloadRightsErrorResolution =&lt;br /&gt;
This is &amp;quot;nn::ns::NoDownloadRightsErrorResolution&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
= BackgroundNetworkUpdateState =&lt;br /&gt;
This is &amp;quot;nn::ns::BackgroundNetworkUpdateState&amp;quot;. This is an u8.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || None&lt;br /&gt;
|-&lt;br /&gt;
| 1 || InProgress&lt;br /&gt;
|-&lt;br /&gt;
| 2 || Ready&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Similar to [[#HasDownloaded]], [[#GetBackgroundNetworkUpdateState]] uses [[NIM_services|nim]] ListSystemUpdateTask and [[NIM_services|nim]] GetSystemUpdateTaskInfo. When ListSystemUpdateTask successfully returns a task and GetSystemUpdateTaskInfo is successful, the output value is set to: &amp;lt;code&amp;gt;1 + *((u8*)(taskinfo+0) == 0x3&amp;lt;/code&amp;gt;. Otherwise, value=0.&lt;br /&gt;
&lt;br /&gt;
[[#GetBackgroundNetworkUpdateState]] always returns Result 0, however this will assert if GetSystemUpdateTaskInfo fails with ret!=0x3C89.&lt;br /&gt;
&lt;br /&gt;
= SystemUpdateProgress =&lt;br /&gt;
This is &amp;quot;nn::ns::SystemUpdateProgress&amp;quot;. This is a 0x10-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x8 || Loaded (this value can be larger than total_size when the async operation is finishing and when total_size is &amp;lt;=0, this current_size field may contain a progress value for when the total_size is not yet determined)&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x8 || Total (this field is only valid when &amp;gt;0)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Commands which have this as output will return 0 with the output cleared, when no task is available.&lt;br /&gt;
&lt;br /&gt;
= EulaDataPath =&lt;br /&gt;
This is &amp;quot;nn::ns::detail::EulaDataPath&amp;quot;. This is a 0x100-byte struct.&lt;br /&gt;
&lt;br /&gt;
This contains a file path.&lt;br /&gt;
&lt;br /&gt;
= SystemDeliveryInfo =&lt;br /&gt;
This is &amp;quot;nn::ns::SystemDeliveryInfo&amp;quot;. This is a 0x100-byte struct.&lt;br /&gt;
&lt;br /&gt;
Originally the SystemDeliveryInfo validation func verified that OldSystemUpdateId matched the installed SystemUpdate Id. [20.0.0+] The used (Old)SystemUpdateId as selected by SystemUpdateIdFlag must now match one of the Ids in [[System_Settings|system-setting]] &amp;lt;code&amp;gt;contents_delivery!acceptable_system_update_ids_string&amp;lt;/code&amp;gt; (replaces the previously mentioned installed-SystemUpdate check).&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x4 || SystemDeliveryProtocolVersion. Must be &amp;lt;= to and match [[System_Settings|system-setting]] &amp;lt;code&amp;gt;contents_delivery!system_delivery_protocol_version&amp;lt;/code&amp;gt;.&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || 0x4 || ApplicationDeliveryProtocolVersion. Loaded from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;contents_delivery!application_delivery_protocol_version&amp;lt;/code&amp;gt;. Unused by [[#RequestSendSystemUpdate]]/[[#RequestReceiveSystemUpdate]], besides HMAC validation.&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x1 || HasExFat. Unused by [[#RequestSendSystemUpdate]]/[[#RequestReceiveSystemUpdate]], besides HMAC validation.&lt;br /&gt;
|-&lt;br /&gt;
| 0x9 || 0x3 || Reserved.&lt;br /&gt;
|-&lt;br /&gt;
| 0xC || 0x4 || SystemUpdateVersion.&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x8 || OldSystemUpdateId. [20.0.0+] Always the NX Id: this is loaded from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;contents_delivery!old_system_update_id&amp;lt;/code&amp;gt;.&lt;br /&gt;
|-&lt;br /&gt;
| 0x18 || 0x1 || FirmwareVariationId. Used by [[#RequestSendSystemUpdate]]. Loaded from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;ns.systemupdate!firmware_variation&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;ns.systemupdate!t_firmware_variation&amp;lt;/code&amp;gt;, depending on the [[Settings_services|PlatformRegion]].&lt;br /&gt;
|-&lt;br /&gt;
| 0x19 || 0x1 || UpdatableFirmwareGroupId. Unused by [[#RequestSendSystemUpdate]]/[[#RequestReceiveSystemUpdate]], besides HMAC validation. Loaded from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;ns.systemupdate!updatable_firmware_group_id&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;ns.systemupdate!t_updatable_firmware_group_id&amp;lt;/code&amp;gt;, depending on the [[Settings_services|PlatformRegion]].&lt;br /&gt;
|-&lt;br /&gt;
| 0x1A || 0x1 || PlatformRegion (0x00 = Unknown/Global, 0x01 = China).&lt;br /&gt;
|-&lt;br /&gt;
| 0x1B || 0x1 || [20.0.0+] SystemDeliveryInfoPlatform. Loaded from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;ns.systemupdate!system_delivery_info_platform&amp;lt;/code&amp;gt;. Elsewhere this is compared against the sys-setting, etc.&lt;br /&gt;
|-&lt;br /&gt;
| 0x1C || 0x1 || [20.0.0+] SystemUpdateIdFlag. When non-zero, SystemUpdateId is used instead of OldSystemUpdateId. Always set to 0x1 by [[#GetSystemDeliveryInfo]] with [20.0.0+].&lt;br /&gt;
|-&lt;br /&gt;
| 0x1D || 0x3 || Padding&lt;br /&gt;
|-&lt;br /&gt;
| 0x20 || 0x8 || [20.0.0+] SystemUpdateId. See above. With [20.0.0+] [[#GetSystemDeliveryInfo]] now writes the Id here instead of OldSystemUpdateId (for the installed SystemUpdate). On S2 this is set to the Ounce Id.&lt;br /&gt;
|-&lt;br /&gt;
| 0x28 || 0xB8 || Reserved&lt;br /&gt;
|-&lt;br /&gt;
| 0xE0 || 0x20 || HMAC-SHA256 over the previous 0xE0-bytes.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationDeliveryInfo =&lt;br /&gt;
This is &amp;quot;nn::ns::ApplicationDeliveryInfo&amp;quot;. This is a 0x100-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x4 || ApplicationDeliveryProtocolVersion. Loaded from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;contents_delivery!application_delivery_protocol_version&amp;lt;/code&amp;gt;. An error is thrown when [[System_Settings|system-setting]] &amp;lt;code&amp;gt;contents_delivery!application_delivery_protocol_version&amp;lt;/code&amp;gt; &amp;lt; version, or when [[System_Settings|system-setting]] &amp;lt;code&amp;gt;contents_delivery!acceptable_application_delivery_protocol_version&amp;lt;/code&amp;gt; &amp;gt; version.&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || 0x4 || Padding&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x8 || ApplicationId.&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x4 || ApplicationVersion.&lt;br /&gt;
|-&lt;br /&gt;
| 0x14 || 0x4 || RequiredApplicationVersion.&lt;br /&gt;
|-&lt;br /&gt;
| 0x18 || 0x4 || RequiredSystemVersion.&lt;br /&gt;
|-&lt;br /&gt;
| 0x1C || 0x4 || u32 bitmask &amp;lt;code&amp;gt;nn::ns::ApplicationDeliveryAttributeTag&amp;lt;/code&amp;gt;. [[#GetApplicationDeliveryInfo|GetApplicationDeliveryInfo]] sets this to the input u32. Bit30 and bit28 are additionally set, depending on [[NCM_services|ContentMetaType]] == Patch, etc.&lt;br /&gt;
|-&lt;br /&gt;
| 0x20 || 0x1 || [20.0.0+] [[NCM_services|ContentMetaPlatform]]. Loaded from [[NCM_services|ncm]] IContentMetaDatabase GetPlatform.&lt;br /&gt;
|-&lt;br /&gt;
| 0x21 || 0x1 || [20.0.0+] ProperProgramExists. Set to whether the bit for ProperProgramExists is set from [[NCM_services|ncm]] IContentMetaDatabase GetAttributes.&lt;br /&gt;
|-&lt;br /&gt;
| 0x22 || 0x1 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 0x23 || 0xBD || Reserved&lt;br /&gt;
|-&lt;br /&gt;
| 0xE0 || 0x20 || HMAC-SHA256 over the previous 0xE0-bytes. Uses a different key than [[#SystemDeliveryInfo]].&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= LatestSystemUpdate =&lt;br /&gt;
This is &amp;quot;nn::ns::LatestSystemUpdate&amp;quot;. This is an u8.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || UpToDate&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Downloaded&lt;br /&gt;
|-&lt;br /&gt;
| 2 || NeedsDownload&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ReceiveApplicationProgress =&lt;br /&gt;
This is &amp;quot;nn::ns::ReceiveApplicationProgress&amp;quot;. This is a 0x10-byte struct.&lt;br /&gt;
&lt;br /&gt;
= SendApplicationProgress =&lt;br /&gt;
This is &amp;quot;nn::ns::SendApplicationProgress&amp;quot;. This is a 0x10-byte struct.&lt;br /&gt;
&lt;br /&gt;
= ApplicationRightsOnClient =&lt;br /&gt;
This is a 0x20-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x8 || [[NCM_services#ApplicationId|ApplicationId]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x10 || [[Account_services#Uid|Uid]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x18 || 0x1 || Flags, [[qlaunch]] only uses bit0-bit4 and bit7.&lt;br /&gt;
|-&lt;br /&gt;
| 0x19 || 0x1 || Flags, [[qlaunch]] only uses bit0.&lt;br /&gt;
|-&lt;br /&gt;
| 0x1A || 0x6 || Unknown&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[[qlaunch]] only uses +0x18/+0x19 in this struct.&lt;br /&gt;
&lt;br /&gt;
= DownloadTaskStatus =&lt;br /&gt;
This is &amp;quot;nn::ns::DownloadTaskStatus&amp;quot;. This is a 0x20-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x10 || Uuid&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x8 || [[NCM_services#ApplicationId|ApplicationId]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x18 || 0x1 || [[#DownloadTaskStatusDetail|Detail]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x19 || 0x1 || NeedsCleanup&lt;br /&gt;
|-&lt;br /&gt;
| 0x1A || 0x2 || Reserved&lt;br /&gt;
|-&lt;br /&gt;
| 0x1C || 0x4 || Result&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= DownloadTaskStatusDetail =&lt;br /&gt;
This is &amp;quot;nn::ns::DownloadTaskStatusDetail&amp;quot;. This is an u8.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || Created&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Added&lt;br /&gt;
|-&lt;br /&gt;
| 2 || AlreadyExists&lt;br /&gt;
|-&lt;br /&gt;
| 3 || Failed&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationLaunchInfo =&lt;br /&gt;
This is a 0x40-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset&lt;br /&gt;
! Size&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x8 || [[NCM_services#ApplicationId|ApplicationId]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x4 || Application version&lt;br /&gt;
|-&lt;br /&gt;
| 0xC || 0x4 || [[Process_Manager_services#LaunchFlags|LaunchFlags]], set to hard-coded value 0xB by [[#GetApplicationLaunchInfo]].&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x1 || Application [[NCM_services#StorageId|StorageId]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x11 || 0x1 || Update [[NCM_services#StorageId|StorageId]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x12 || 0x2E || &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= UserData =&lt;br /&gt;
This is a 0x80-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset || Size || Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x4? || ?&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || 0x4? || Icon ID. 0 = Mii, the rest are character icon IDs.&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x1? || Profile icon background color ID&lt;br /&gt;
|-&lt;br /&gt;
| 0x9 || 0x7 || ?&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x10 || Some ID related to the Mii? All zeros when a character icon is used.&lt;br /&gt;
|-&lt;br /&gt;
| 0x20 || 0x60 || Usually zeros?&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ProfileBase =&lt;br /&gt;
This is a 0x38-byte struct.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset || Size || Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x10 || userID&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x8 || POSIX UTC timestamp, for last account edit.&lt;br /&gt;
|-&lt;br /&gt;
| 0x18 || 0x20 || UTF-8 Nickname. Official sw uses strncpy to copy this into another struct (&amp;lt;code&amp;gt;nn::account::Nickname&amp;lt;/code&amp;gt;), with a NUL-byte written after the copied data.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Uid =&lt;br /&gt;
This is &amp;quot;nn::account::Uid&amp;quot;. This is a 0x10-byte struct. This contains 2 u64s for the UserId.&lt;br /&gt;
&lt;br /&gt;
= Notes =&lt;br /&gt;
[[Process_Manager_services|pm:bm]] GetBootMode is used to determine whether aoc:u is available (see above). This value is also passed to thread &amp;quot;nn.ns.DelayedInitialization&amp;quot;, which calls various funcs depending on the BootMode in various cases.&lt;br /&gt;
&lt;br /&gt;
The &amp;quot;nn.ns.DelayedInitialization&amp;quot; thread uses BootMode as follows (this also handles various other initialization):&lt;br /&gt;
* Initializes [[NPNS_services|npns:s]] only for BootMode Normal/Maintenance.&lt;br /&gt;
* Initializes the hosted acc:* services and service [[Account_services|acc:su]] only for BootMode Normal/Maintenance.&lt;br /&gt;
* Calls a func only for BootMode Normal.&lt;br /&gt;
* Initializes [[ETicket_services|es]] and [[Shared_Database_services|avm]] only for BootMode Normal/Maintenance.&lt;br /&gt;
&lt;br /&gt;
The output of GetBootMode is also written into state. This same func later enters a code block when BootMode is Maintenance/SafeMode: various [[NCM_services|ncm]] cmds are used with input StorageId=BuiltInUser (VerifyContentMetaDatabase, VerifyContentStorage, ActivateContentMetaDatabase, ActivateContentStorage, InactivateContentMetaDatabase, InactivateContentStorage) and state fields are written. Then if the BootMode is Maintenance the savedata for [[Flash_Filesystem|ns_rightsid]] (0x800000000000004A) is deleted. Then 0 is returned. Otherwise for BootMode Normal it continues with various initialization, including gamecard handling which handles launching the gamecard title in certain conditions (this is the only time ns launches anything with pgl outside of service cmds).&lt;br /&gt;
&lt;br /&gt;
In the above block, InactivateContentMetaDatabase/InactivateContentStorage are only used if using ActivateContentMetaDatabase/ActivateContentStorage failed (error is only checked after using both cmds). If any of the ncm cmds prior to this fail, it will skip using the rest of the ncm cmds.&lt;br /&gt;
&lt;br /&gt;
[[Category:Services]]&lt;/div&gt;</summary>
		<author><name>Yellows8</name></author>
	</entry>
	<entry>
		<id>https://switchbrew.org/w/index.php?title=Applet_Manager_services&amp;diff=14818</id>
		<title>Applet Manager services</title>
		<link rel="alternate" type="text/html" href="https://switchbrew.org/w/index.php?title=Applet_Manager_services&amp;diff=14818"/>
		<updated>2026-07-23T18:01:58Z</updated>

		<summary type="html">&lt;p&gt;Yellows8: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;AM (Applet Manager) provides services for interacting with system applets while abstracting several aspects of power and operation management.&lt;br /&gt;
&lt;br /&gt;
Contains multiple raw images, with at least the following: &amp;quot;NN_OMM_CHARGING_BIN_{begin|end}&amp;quot;(charging icon), low-battery icon, and the Nintendo Switch logo displayed during system boot.&lt;br /&gt;
&lt;br /&gt;
= appletAE =&lt;br /&gt;
This is &amp;quot;nn::am::service::IAllSystemAppletProxiesService&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 100 || OpenSystemAppletProxyOld ([1.0.0-19.0.1] OpenSystemAppletProxy) || Returns an [[#ISystemAppletProxy]].&lt;br /&gt;
|-&lt;br /&gt;
| 110 || [20.0.0+] OpenSystemAppletProxy || Same as OpenSystemAppletProxyOld except this now takes a type-0x15 buffer containing an [[#AppletAttribute|AppletAttribute]].&lt;br /&gt;
|-&lt;br /&gt;
| 200 || OpenLibraryAppletProxyOld ([1.0.0-2.3.0] OpenLibraryAppletProxy) || Returns an [[#ILibraryAppletProxy]].&lt;br /&gt;
|-&lt;br /&gt;
| 201 || [3.0.0+] [[#OpenLibraryAppletProxy]] || Returns an [[#ILibraryAppletProxy]].&lt;br /&gt;
|-&lt;br /&gt;
| 300 || OpenOverlayAppletProxy || Returns an [[#IOverlayAppletProxy]].&lt;br /&gt;
|-&lt;br /&gt;
| 310 || [S2] || Returns an [[#ICMenuProxy|ICMenuProxy]].&lt;br /&gt;
|-&lt;br /&gt;
| 350 || OpenSystemApplicationProxy || Returns an [[#IApplicationProxy]].&lt;br /&gt;
|-&lt;br /&gt;
| 400 || [[#CreateSelfLibraryAppletCreatorForDevelop]] || &lt;br /&gt;
|-&lt;br /&gt;
| 410 || [6.0.0+] [[#GetSystemAppletControllerForDebug]] || &lt;br /&gt;
|-&lt;br /&gt;
| 450 || [19.0.0+] [[#GetSystemProcessCommonFunctions]] || &lt;br /&gt;
|-&lt;br /&gt;
| 460 || [20.0.0+] || Returns an [[#IAppletAlternativeFunctions]].&lt;br /&gt;
|-&lt;br /&gt;
| 500 || [S2] || Returns an [[#IChatProxy|IChatProxy]].&lt;br /&gt;
|-&lt;br /&gt;
| 1000 || [6.0.0+] [[#GetDebugFunctions]] || &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
All of these Open*Proxy commands except [[#OpenLibraryAppletProxy]] take the same input as [[#OpenApplicationProxy]], with the same user-process retry-loop as [[#OpenApplicationProxy]]. These Open*Proxy commands (including appletOE) doesn&#039;t seem to usable from processes which aren&#039;t actual applets (such as sysmodules), at least for applet-types which aren&#039;t already in use.&lt;br /&gt;
&lt;br /&gt;
OpenLibraryAppletProxyOld eventually calls the same func as [[#OpenLibraryAppletProxy]], except that the [[#AppletAttribute]] is all-zero.&lt;br /&gt;
&lt;br /&gt;
This service is used by all system non-regular-applications.&lt;br /&gt;
&lt;br /&gt;
The 01000000000010XX system [[Title_list|titles]] use the following applet types(above Open{type}Proxy commands):&lt;br /&gt;
* &amp;quot;qlaunch&amp;quot;: SystemApplet&lt;br /&gt;
* &amp;quot;overlay&amp;quot;: OverlayApplet&lt;br /&gt;
* &amp;quot;starter&amp;quot;: SystemApplication&lt;br /&gt;
* &amp;quot;maintenance&amp;quot;: SystemApplet&lt;br /&gt;
* All others: LibraryApplet&lt;br /&gt;
&lt;br /&gt;
== OpenLibraryAppletProxy ==&lt;br /&gt;
Returns an [[#ILibraryAppletProxy]].&lt;br /&gt;
&lt;br /&gt;
Takes a [[IPC_Marshalling|reserved]] input u64(official user-processes use hard-coded value 0), a PID,a process copy-handle(cur-proc handle alias), and a type-0x15 input buffer containing an [[#AppletAttribute]].&lt;br /&gt;
&lt;br /&gt;
Official user-processes use the same retry loop with this as the other Open*Proxy commands.&lt;br /&gt;
&lt;br /&gt;
== CreateSelfLibraryAppletCreatorForDevelop ==&lt;br /&gt;
Takes a PID and an input u64 pid_placeholder, returns an [[#ILibraryAppletCreator]].&lt;br /&gt;
&lt;br /&gt;
The cached value loaded from [[Settings_services#GetDebugModeFlag]] must be 1, otherwise an error is returned.&lt;br /&gt;
&lt;br /&gt;
The cached value loaded from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;am.debug!dev_function&amp;lt;/code&amp;gt; must be set to 0x1 with size 0x1, otherwise an error is returned.&lt;br /&gt;
&lt;br /&gt;
== GetSystemAppletControllerForDebug ==&lt;br /&gt;
No input, returns an [[#ISystemAppletControllerForDebug]].&lt;br /&gt;
&lt;br /&gt;
The cached value loaded from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;am.debug!dev_function&amp;lt;/code&amp;gt; must be set to 0x1 with size 0x1, and various state checks must pass, otherwise 0 is returned with no output interface.&lt;br /&gt;
&lt;br /&gt;
== GetSystemProcessCommonFunctions ==&lt;br /&gt;
No input. Returns an [[#ISystemProcessCommonFunctions]].&lt;br /&gt;
&lt;br /&gt;
== GetDebugFunctions ==&lt;br /&gt;
No input, returns an [[#IDebugFunctions]].&lt;br /&gt;
&lt;br /&gt;
The cached value loaded from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;am.debug!dev_function&amp;lt;/code&amp;gt; must be set to 0x1 with size 0x1, otherwise 0 is returned with no output interface.&lt;br /&gt;
&lt;br /&gt;
== ISystemAppletProxy ==&lt;br /&gt;
This is &amp;quot;nn::am::service::ISystemAppletProxy&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetCommonStateGetter || Returns an [[#ICommonStateGetter]].&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GetSelfController || Returns an [[#ISelfController]].&lt;br /&gt;
|-&lt;br /&gt;
| 2 || GetWindowController || Returns an [[#IWindowController]].&lt;br /&gt;
|-&lt;br /&gt;
| 3 || GetAudioController || Returns an [[#IAudioController]].&lt;br /&gt;
|-&lt;br /&gt;
| 4 || GetDisplayController || Returns an [[#IDisplayController]].&lt;br /&gt;
|-&lt;br /&gt;
| 10 || GetProcessWindingController || Returns an [[#IProcessWindingController]].&lt;br /&gt;
|-&lt;br /&gt;
| 11 || GetLibraryAppletCreator || Returns an [[#ILibraryAppletCreator]].&lt;br /&gt;
|-&lt;br /&gt;
| 20 || GetHomeMenuFunctions || Returns an [[#IHomeMenuFunctions]].&lt;br /&gt;
|-&lt;br /&gt;
| 21 || GetGlobalStateController || Returns an [[#IGlobalStateController]].&lt;br /&gt;
|-&lt;br /&gt;
| 22 || GetApplicationCreator || Returns an [[#IApplicationCreator]].&lt;br /&gt;
|-&lt;br /&gt;
| 23 || [7.0.0+] GetAppletCommonFunctions || Returns an [[#IAppletCommonFunctions]].&lt;br /&gt;
|-&lt;br /&gt;
| 1000 || GetDebugFunctions || Returns an [[#IDebugFunctions]].&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IHomeMenuFunctions ===&lt;br /&gt;
This is &amp;quot;nn::am::service::IHomeMenuFunctions&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [[#RequestToGetForeground]]&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [[#LockForeground]]&lt;br /&gt;
|-&lt;br /&gt;
| 12 || [[#UnlockForeground]]&lt;br /&gt;
|-&lt;br /&gt;
| 20 || [[#PopFromGeneralChannel]]&lt;br /&gt;
|-&lt;br /&gt;
| 21 || [[#GetPopFromGeneralChannelEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 30 || [[#GetHomeButtonWriterLockAccessor]]&lt;br /&gt;
|-&lt;br /&gt;
| 31 || [2.0.0+] [[#GetWriterLockAccessorEx]]&lt;br /&gt;
|-&lt;br /&gt;
| 40 || [11.0.0+] [[#IsSleepEnabled]]&lt;br /&gt;
|-&lt;br /&gt;
| 41 || [12.0.0+] [[#IsRebootEnabled]]&lt;br /&gt;
|-&lt;br /&gt;
| 50 || [16.0.0+] [[#LaunchSystemApplet]]&lt;br /&gt;
|-&lt;br /&gt;
| 51 || [16.0.0+] [[#LaunchStarter]]&lt;br /&gt;
|-&lt;br /&gt;
| 60 || [19.0.0+] &lt;br /&gt;
|-&lt;br /&gt;
| 61 || [19.0.0+] &lt;br /&gt;
|-&lt;br /&gt;
| 100 || [6.0.0+] [[#PopRequestLaunchApplicationForDebug]]&lt;br /&gt;
|-&lt;br /&gt;
| 110 || [9.0.0+] [[#IsForceTerminateApplicationDisabledForDebug]]&lt;br /&gt;
|-&lt;br /&gt;
| 200 || [8.0.0+] [[#LaunchDevMenu]]&lt;br /&gt;
|-&lt;br /&gt;
| 1000 || [11.0.0+] [[#SetLastApplicationExitReason]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== RequestToGetForeground ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== LockForeground ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== UnlockForeground ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== PopFromGeneralChannel ====&lt;br /&gt;
No input, returns an output [[#IStorage]].&lt;br /&gt;
&lt;br /&gt;
==== GetPopFromGeneralChannelEvent ====&lt;br /&gt;
No input, returns an output Event handle with autoclear=false.&lt;br /&gt;
&lt;br /&gt;
==== GetHomeButtonWriterLockAccessor ====&lt;br /&gt;
No input, returns an output [[#ILockAccessor]].&lt;br /&gt;
&lt;br /&gt;
Similar to using [[#GetWriterLockAccessorEx]] with inval=0.&lt;br /&gt;
&lt;br /&gt;
==== GetWriterLockAccessorEx ====&lt;br /&gt;
Takes an input u32, returns an output [[#ILockAccessor]].&lt;br /&gt;
&lt;br /&gt;
The input value must be 0-3. 0 = HomeButton.&lt;br /&gt;
&lt;br /&gt;
==== IsSleepEnabled ====&lt;br /&gt;
No input, returns an output bool.&lt;br /&gt;
&lt;br /&gt;
==== IsRebootEnabled ====&lt;br /&gt;
No input, returns an output bool.&lt;br /&gt;
&lt;br /&gt;
==== LaunchSystemApplet ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
This wraps [[NS_Services|ns]] LaunchSystemApplet, ignoring the u64 returned by that cmd (and other functionality).&lt;br /&gt;
&lt;br /&gt;
==== LaunchStarter ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
This is similar to [[#LaunchSystemApplet]], except this uses [[NS_Services|ns]] LaunchLibraryApplet with a ProgramId from global state.&lt;br /&gt;
&lt;br /&gt;
The global state field is initialized elsewhere with the value of [[System_Settings|system-setting]] &amp;lt;code&amp;gt;am.debug!starter_id&amp;lt;/code&amp;gt;, defaulting to ProgramId 0100000000001012 ([[Title_list|starter]]) if not available.&lt;br /&gt;
&lt;br /&gt;
==== PopRequestLaunchApplicationForDebug ====&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of u128 userIDs, returns an output [[NCM_services#ApplicationId|ApplicationId]] and an output s32 &#039;&#039;&#039;total_userIDs&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
The total entries in the userID buffer must be &amp;gt;= {total userIDs in state}.&lt;br /&gt;
&lt;br /&gt;
==== IsForceTerminateApplicationDisabledForDebug ====&lt;br /&gt;
No input, returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
When the cached value loaded from [[Settings_services#GetDebugModeFlag]] is 0 this will just set the bool to 0. Otherwise, the bool is loaded using data from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;am.debug!disable_force_terminate_application&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
==== LaunchDevMenu ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
The cached value loaded from [[Settings_services#GetDebugModeFlag]] must be 1, otherwise an error is returned.&lt;br /&gt;
&lt;br /&gt;
Uses [[NS_Services|ns]] LaunchDevMenu.&lt;br /&gt;
&lt;br /&gt;
This is used by [[qlaunch]]. On success, official sw will enter an infinite loop with sleep-thread value 86400000000000.&lt;br /&gt;
&lt;br /&gt;
==== SetLastApplicationExitReason ====&lt;br /&gt;
Takes an input s32, no output.&lt;br /&gt;
&lt;br /&gt;
==== ILockAccessor ====&lt;br /&gt;
This is &amp;quot;nn::am::service::ILockAccessor&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#TryLock]]&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [[#Unlock]]&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [[#GetEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [10.0.0+] [[#IsLocked]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
===== TryLock =====&lt;br /&gt;
Takes an input u8 bool flag, returns an output u8 bool flag and a handle.&lt;br /&gt;
&lt;br /&gt;
Official sw waits on the previously loaded event from [[#GetEvent]]. The output flag indicates whether locking was successful, the user-process can try using this cmd again when flag=false.&lt;br /&gt;
&lt;br /&gt;
Official sw only uses inflag=false. Official sw just closes the output handle. The input flag controls whether this returns the output handle.&lt;br /&gt;
&lt;br /&gt;
===== Unlock =====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
===== GetEvent =====&lt;br /&gt;
No input, returns an output Event handle with autoclear=false.&lt;br /&gt;
&lt;br /&gt;
==== IsLocked ====&lt;br /&gt;
No input, returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
=== IGlobalStateController ===&lt;br /&gt;
This is &amp;quot;nn::am::service::IGlobalStateController&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#RequestToEnterSleep]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#EnterSleep]]&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [[#StartSleepSequence]]&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [[#StartShutdownSequence]]&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [[#StartRebootSequence]]&lt;br /&gt;
|-&lt;br /&gt;
| 9 || [7.0.0+] [[#IsAutoPowerDownRequested]]&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [[#LoadAndApplyIdlePolicySettings]]&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [2.0.0+] [[#NotifyCecSettingsChanged]]&lt;br /&gt;
|-&lt;br /&gt;
| 12 || [3.0.0+] [[#SetDefaultHomeButtonLongPressTime]]&lt;br /&gt;
|-&lt;br /&gt;
| 13 || [3.0.0+] [[#UpdateDefaultDisplayResolution]]&lt;br /&gt;
|-&lt;br /&gt;
| 14 || [3.0.0+] [[#ShouldSleepOnBoot]]&lt;br /&gt;
|-&lt;br /&gt;
| 15 || [4.0.0+] [[#GetHdcpAuthenticationFailedEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 30 || [12.0.0+] [[#OpenCradleFirmwareUpdater]]&lt;br /&gt;
|-&lt;br /&gt;
| 100 || [S2]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== RequestToEnterSleep ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Stubbed, just returns an error.&lt;br /&gt;
&lt;br /&gt;
==== EnterSleep ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Stubbed, just returns an error.&lt;br /&gt;
&lt;br /&gt;
==== StartSleepSequence ====&lt;br /&gt;
Takes an input u8 bool, no output.&lt;br /&gt;
&lt;br /&gt;
Official sw uses hard-coded input value = 1.&lt;br /&gt;
&lt;br /&gt;
==== StartShutdownSequence ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== StartRebootSequence ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== IsAutoPowerDownRequested ====&lt;br /&gt;
No input, returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
Uses [[#idle:sys]] cmd1.&lt;br /&gt;
&lt;br /&gt;
==== LoadAndApplyIdlePolicySettings ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Uses [[#idle:sys]] cmd LoadAndApplySettings.&lt;br /&gt;
&lt;br /&gt;
==== NotifyCecSettingsChanged ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Uses [[#omm]] cmd NotifyCecSettingsChanged.&lt;br /&gt;
&lt;br /&gt;
==== SetDefaultHomeButtonLongPressTime ====&lt;br /&gt;
Takes an input s64, no output.&lt;br /&gt;
&lt;br /&gt;
==== UpdateDefaultDisplayResolution ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Uses [[#omm]] cmd UpdateDefaultDisplayResolution.&lt;br /&gt;
&lt;br /&gt;
==== ShouldSleepOnBoot ====&lt;br /&gt;
No input, returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
Uses [[#omm]] cmd ShouldSleepOnBoot.&lt;br /&gt;
&lt;br /&gt;
==== GetHdcpAuthenticationFailedEvent ====&lt;br /&gt;
No input, returns an output Event handle with autoclear=false.&lt;br /&gt;
&lt;br /&gt;
Uses [[#omm]] cmd GetHdcpAuthenticationFailedEvent.&lt;br /&gt;
&lt;br /&gt;
==== OpenCradleFirmwareUpdater ====&lt;br /&gt;
No input, returns an [[#ICradleFirmwareUpdater]].&lt;br /&gt;
&lt;br /&gt;
==== Cmd100 ====&lt;br /&gt;
No input, returns an output handle.&lt;br /&gt;
&lt;br /&gt;
=== ICradleFirmwareUpdater ===&lt;br /&gt;
This is &amp;quot;nn::am::service::ICradleFirmwareUpdater&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [12.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || StartUpdate&lt;br /&gt;
|-&lt;br /&gt;
| 1 || FinishUpdate&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [[#GetCradleDeviceInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 3 || GetCradleDeviceInfoChangeEvent&lt;br /&gt;
|-&lt;br /&gt;
| 4 || GetUpdateProgressInfo&lt;br /&gt;
|-&lt;br /&gt;
| 5 || GetLastInternalResult&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== GetCradleDeviceInfo ====&lt;br /&gt;
No input, returns a 8-byte CradleDeviceInfo.&lt;br /&gt;
&lt;br /&gt;
[13.0.0+] Now returns a total of 0xC-bytes.&lt;br /&gt;
&lt;br /&gt;
=== IApplicationCreator ===&lt;br /&gt;
This is &amp;quot;nn::am::service::IApplicationCreator&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#CreateApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#PopLaunchRequestedApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [[#CreateSystemApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 100 || [[#PopFloatingApplicationForDevelopment]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[[#CreateApplication]]/[[#CreateSystemApplication]] eventually call the same internal func. With [[#CreateApplication]], two ptrs passed to the internal func are NULL, while with [[#CreateSystemApplication]] these are loaded from state. The initial content of [[#ApplicationLaunchRequestInfo]] is all-zero with [[#CreateSystemApplication]], while with [[#CreateApplication]] the first two u32s are value 0x3 with the rest all-zero. The [[#AppletId]] is set to 0x01 with [[#CreateApplication]], while with [[#CreateSystemApplication]] it&#039;s 0x04.&lt;br /&gt;
&lt;br /&gt;
==== CreateApplication ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an [[#IApplicationAccessor]].&lt;br /&gt;
&lt;br /&gt;
==== PopLaunchRequestedApplication ====&lt;br /&gt;
No input, returns an [[#IApplicationAccessor]].&lt;br /&gt;
&lt;br /&gt;
==== CreateSystemApplication ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|SystemApplicationId]], returns an [[#IApplicationAccessor]].&lt;br /&gt;
&lt;br /&gt;
[[qlaunch]] only uses this with a hard-coded id for the &amp;quot;starter&amp;quot; title.&lt;br /&gt;
&lt;br /&gt;
==== PopFloatingApplicationForDevelopment ====&lt;br /&gt;
No input, returns an [[#IApplicationAccessor]].&lt;br /&gt;
&lt;br /&gt;
Should not be used if no FloatingApplication is available (svcBreak).&lt;br /&gt;
&lt;br /&gt;
==== IApplicationAccessor ====&lt;br /&gt;
This is &amp;quot;nn::am::service::IApplicationAccessor&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#GetAppletStateChangedEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#IsCompleted]]&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [[#Start]]&lt;br /&gt;
|-&lt;br /&gt;
| 20 || [[#RequestExit]]&lt;br /&gt;
|-&lt;br /&gt;
| 25 || [[#Terminate]]&lt;br /&gt;
|-&lt;br /&gt;
| 30 || [[#GetResult]]&lt;br /&gt;
|-&lt;br /&gt;
| 101 || [[#RequestForApplicationToGetForeground]] &lt;br /&gt;
|-&lt;br /&gt;
| 110 || [[#TerminateAllLibraryApplets]]&lt;br /&gt;
|-&lt;br /&gt;
| 111 || [[#AreAnyLibraryAppletsLeft]] &lt;br /&gt;
|-&lt;br /&gt;
| 112 || [[#GetCurrentLibraryApplet]] &lt;br /&gt;
|-&lt;br /&gt;
| 120 || [[#GetApplicationId]]&lt;br /&gt;
|-&lt;br /&gt;
| 121 || [[#PushLaunchParameter]] &lt;br /&gt;
|-&lt;br /&gt;
| 122 || [[#GetApplicationControlProperty]] &lt;br /&gt;
|-&lt;br /&gt;
| 123 || [2.0.0+] [[#GetApplicationLaunchProperty]] &lt;br /&gt;
|-&lt;br /&gt;
| 124 || [6.0.0+] [[#GetApplicationLaunchRequestInfo]] &lt;br /&gt;
|-&lt;br /&gt;
| 130 || [6.0.0+] [[#SetUsers]]&lt;br /&gt;
|-&lt;br /&gt;
| 131 || [6.0.0+] [[#CheckRightsEnvironmentAvailable]]&lt;br /&gt;
|-&lt;br /&gt;
| 132 || [6.0.0+] [[#GetNsRightsEnvironmentHandle]] &lt;br /&gt;
|-&lt;br /&gt;
| 140 || [6.0.0+] [[#GetDesirableUids]]&lt;br /&gt;
|-&lt;br /&gt;
| 150 || [6.0.0+] [[#ReportApplicationExitTimeout]] &lt;br /&gt;
|-&lt;br /&gt;
| 160 || [8.0.0+] [[#SetApplicationAttribute]]&lt;br /&gt;
|-&lt;br /&gt;
| 170 || [8.0.0+] [[#HasSaveDataAccessPermission]]&lt;br /&gt;
|-&lt;br /&gt;
| 180 || [9.0.0+] [[#PushToFriendInvitationStorageChannel]]&lt;br /&gt;
|-&lt;br /&gt;
| 190 || [9.0.0+] [[#PushToNotificationStorageChannel]]&lt;br /&gt;
|-&lt;br /&gt;
| 200 || [10.0.0+] [[#RequestApplicationSoftReset]]&lt;br /&gt;
|-&lt;br /&gt;
| 201 || [10.0.0+] [[#RestartApplicationTimer]]&lt;br /&gt;
|-&lt;br /&gt;
| 300 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 301 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 310 || [21.0.0+]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Commands &amp;lt;=30 are inherited from [[#IAppletAccessor]].&lt;br /&gt;
&lt;br /&gt;
===== RequestForApplicationToGetForeground =====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
===== GetCurrentLibraryApplet =====&lt;br /&gt;
No input, returns an output [[#IAppletAccessor]].&lt;br /&gt;
&lt;br /&gt;
===== GetApplicationId =====&lt;br /&gt;
No input, returns an output [[NCM_services#ApplicationId|ApplicationId]].&lt;br /&gt;
&lt;br /&gt;
===== PushLaunchParameter =====&lt;br /&gt;
Takes an input u32 [[#LaunchParameterKind]] and an input [[#IStorage]], no output.&lt;br /&gt;
&lt;br /&gt;
===== GetApplicationControlProperty =====&lt;br /&gt;
No input, takes a type-0x6 output buffer.&lt;br /&gt;
&lt;br /&gt;
The output buffer must be at least 0x4000-bytes. Returns an error when the [[#AppletId]] is 0x04, aka when the IApplicationAccessor is for a SystemApplication. &lt;br /&gt;
&lt;br /&gt;
This gets the application [[NACP_Format|control.nacp]].&lt;br /&gt;
&lt;br /&gt;
===== GetApplicationLaunchProperty =====&lt;br /&gt;
Takes a type-0x6 output buffer.&lt;br /&gt;
&lt;br /&gt;
The output buffer size must be at least 0x10-bytes. Returns an error when the [[#AppletId]] is 0x04, aka when the IApplicationAccessor is for a SystemApplication.&lt;br /&gt;
&lt;br /&gt;
This gets the [[#ApplicationLaunchProperty]].&lt;br /&gt;
&lt;br /&gt;
===== GetApplicationLaunchRequestInfo =====&lt;br /&gt;
No input, returns an output 0x10-byte struct.&lt;br /&gt;
&lt;br /&gt;
This gets the [[#ApplicationLaunchRequestInfo]] from state. The output struct is &amp;quot;nn::applet::ApplicationLaunchRequestInfo&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
===== SetUsers =====&lt;br /&gt;
Takes an input u8 bool flag and a type-0x5 input buffer containing an array of u128 userIDs.&lt;br /&gt;
&lt;br /&gt;
The total entries for the userIDs must be &amp;lt;=8.&lt;br /&gt;
&lt;br /&gt;
When the input flag is true, this just clears the &#039;&#039;&#039;users_available&#039;&#039;&#039; state flag to 0 and returns.&lt;br /&gt;
&lt;br /&gt;
===== CheckRightsEnvironmentAvailable =====&lt;br /&gt;
No input, returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
===== GetNsRightsEnvironmentHandle =====&lt;br /&gt;
No input, returns an output u64.&lt;br /&gt;
&lt;br /&gt;
===== GetDesirableUids =====&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of u128 userIDs, returns an output s32 &#039;&#039;&#039;total_entries&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
Gets a userID listing, this is unrelated to [[#SetUsers]]. [[qlaunch]] only uses 1 userID with this.&lt;br /&gt;
&lt;br /&gt;
The stored entry-count in state must be &amp;lt;= &amp;lt;size of output buffer in entries&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
===== ReportApplicationExitTimeout =====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
===== SetApplicationAttribute =====&lt;br /&gt;
Takes a type-0x15 input buffer containing an [[#ApplicationAttribute]], no output.&lt;br /&gt;
&lt;br /&gt;
===== HasSaveDataAccessPermission =====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], returns an output u8 bool flag.&lt;br /&gt;
&lt;br /&gt;
Gets whether the savedata specified by the input ApplicationId is accessible. The output flag indicates whether it&#039;s accessible.&lt;br /&gt;
&lt;br /&gt;
If the ApplicationId matches the current application, this immediately returns success with flag=1.&lt;br /&gt;
&lt;br /&gt;
===== PushToFriendInvitationStorageChannel =====&lt;br /&gt;
Takes an input [[#IStorage]], no output.&lt;br /&gt;
&lt;br /&gt;
Clears the FriendInvitation StorageChannel, then pushes the input storage there.&lt;br /&gt;
&lt;br /&gt;
===== PushToNotificationStorageChannel =====&lt;br /&gt;
Takes an input [[#IStorage]], no output.&lt;br /&gt;
&lt;br /&gt;
Clears the Notification StorageChannel, then pushes the input storage there.&lt;br /&gt;
&lt;br /&gt;
[[qlaunch]] will only push data for this when launching the Application when the Alarm was triggered, where the system was previously in sleep-mode. This data is the [[Glue_services|Notification]] ApplicationParameter.&lt;br /&gt;
&lt;br /&gt;
===== RequestApplicationSoftReset =====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
===== RestartApplicationTimer =====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
===== IAppletAccessor =====&lt;br /&gt;
This is &amp;quot;nn::am::service::IAppletAccessor&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#GetAppletStateChangedEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#IsCompleted]]&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [[#Start]]&lt;br /&gt;
|-&lt;br /&gt;
| 20 || [[#RequestExit]]&lt;br /&gt;
|-&lt;br /&gt;
| 25 || [[#Terminate]]&lt;br /&gt;
|-&lt;br /&gt;
| 30 || [[#GetResult]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== GetAppletStateChangedEvent ====&lt;br /&gt;
No input, returns an output event handle with autoclear=false.&lt;br /&gt;
&lt;br /&gt;
==== IsCompleted ====&lt;br /&gt;
No input, returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
==== Start ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== RequestExit ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== Terminate ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== GetResult====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
== IAppletCommonFunctions ==&lt;br /&gt;
This is &amp;quot;nn::am::service::IAppletCommonFunctions&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [7.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [9.0.0+] [[#SetTerminateResult]]&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [[#ReadThemeStorage]]&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [[#WriteThemeStorage]]&lt;br /&gt;
|-&lt;br /&gt;
| 20 || [9.0.0+] [[#PushToAppletBoundChannel]]&lt;br /&gt;
|-&lt;br /&gt;
| 21 || [9.0.0+] [[#TryPopFromAppletBoundChannel]]&lt;br /&gt;
|-&lt;br /&gt;
| 40 || [8.0.0+] [[#GetDisplayLogicalResolution]]&lt;br /&gt;
|-&lt;br /&gt;
| 42 || [8.0.0+] [[#SetDisplayMagnification]]&lt;br /&gt;
|-&lt;br /&gt;
| 50 || [8.0.0+] [[#SetHomeButtonDoubleClickEnabled]]&lt;br /&gt;
|-&lt;br /&gt;
| 51 || [8.0.0+] [[#GetHomeButtonDoubleClickEnabled]]&lt;br /&gt;
|-&lt;br /&gt;
| 52 || [10.0.0+] [[#IsHomeButtonShortPressedBlocked]]&lt;br /&gt;
|-&lt;br /&gt;
| 60 || [11.0.0+] [[#IsVrModeCurtainRequired]]&lt;br /&gt;
|-&lt;br /&gt;
| 61 || [12.0.0+] IsSleepRequiredByHighTemperature&lt;br /&gt;
|-&lt;br /&gt;
| 62 || [12.0.0+] IsSleepRequiredByLowBattery&lt;br /&gt;
|-&lt;br /&gt;
| 70 || [11.0.0+] [[#SetCpuBoostRequestPriority]]&lt;br /&gt;
|-&lt;br /&gt;
| 80 || [14.0.0+] SetHandlingCaptureButtonShortPressedMessageEnabledForApplet&lt;br /&gt;
|-&lt;br /&gt;
| 81 || [14.0.0+] SetHandlingCaptureButtonLongPressedMessageEnabledForApplet&lt;br /&gt;
|-&lt;br /&gt;
| 82 || [18.0.0+] SetBlockingCaptureButtonInEntireSystem&lt;br /&gt;
|-&lt;br /&gt;
| 90 || [15.0.0+] OpenNamedChannelAsParent&lt;br /&gt;
|-&lt;br /&gt;
| 91 || [15.0.0+] OpenNamedChannelAsChild&lt;br /&gt;
|-&lt;br /&gt;
| 100 || [15.0.0+] SetApplicationCoreUsageMode&lt;br /&gt;
|-&lt;br /&gt;
| 110 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 111 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 112 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 113 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 114 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 115 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 116 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 117 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 118 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 119 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 120 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 121 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 122 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 123 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 124 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 130 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 131 || [S2] [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 135 || [S2] [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 140 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 150 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 160 || [18.0.0+] [[#GetNotificationReceiverService|GetNotificationReceiverService]]&lt;br /&gt;
|-&lt;br /&gt;
| 161 || [18.0.0+] [[#GetNotificationSenderService|GetNotificationSenderService]]&lt;br /&gt;
|-&lt;br /&gt;
| 170 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 171 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 200 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 210 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 211 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 220 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 221 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 230 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 231 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 250 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 251 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 252 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 253 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 260 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 271 || [S2] [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 280 || [S2] [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 290 || [S2] [20.0.0+] RequestChatProhibition&lt;br /&gt;
|-&lt;br /&gt;
| 291 || [S2] [20.0.0+] RequestChatExpirationCheckSkip&lt;br /&gt;
|-&lt;br /&gt;
| 300 || [17.0.0+] GetCurrentApplicationId&lt;br /&gt;
|-&lt;br /&gt;
| 310 || [19.0.0+] IsSystemAppletHomeMenu&lt;br /&gt;
|-&lt;br /&gt;
| 311 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 320 || [19.0.0+] SetGpuTimeSliceBoost&lt;br /&gt;
|-&lt;br /&gt;
| 321 || [19.0.0+] SetGpuTimeSliceBoostDueToApplication&lt;br /&gt;
|-&lt;br /&gt;
| 322 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 330 || [19.0.0+] &lt;br /&gt;
|-&lt;br /&gt;
| 340 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 341 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 342 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 350 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 360 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 370 || [22.0.0+] GetGpuErrorEventForApplet&lt;br /&gt;
|-&lt;br /&gt;
| 2000 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 2010 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 3000 || [S2] [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 3010 || [S2] [20.0.0+]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
ReadThemeStorage/WriteThemeStorage: these commands copy data from/to a state buffer and the user specified buffer. The size of the state buffer is 0x400-bytes. The default content of the ThemeStorage prior to using the WriteThemeStorage cmd, is: &amp;lt;code&amp;gt;memset(statebuf, 0xAA, 0x400);&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== ReadThemeStorage ===&lt;br /&gt;
Takes an input u64 &#039;&#039;&#039;offset&#039;&#039;&#039; and a type-0x22 output buffer, returns an output u64 &#039;&#039;&#039;actual_transfer_size&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
=== WriteThemeStorage ===&lt;br /&gt;
Takes an input u64 &#039;&#039;&#039;offset&#039;&#039;&#039; and a type-0x21 input buffer, no output.&lt;br /&gt;
&lt;br /&gt;
=== PushToAppletBoundChannel ===&lt;br /&gt;
Takes an input [[#IStorage]], no output.&lt;br /&gt;
&lt;br /&gt;
This is similar to [[#PushToAppletBoundChannelForDebug]] (no DebugMode check), except the used s32 is loaded from elsewhere and must be in the range 31-32.&lt;br /&gt;
&lt;br /&gt;
=== TryPopFromAppletBoundChannel ===&lt;br /&gt;
No input, returns an output [[#IStorage]].&lt;br /&gt;
&lt;br /&gt;
This is similar to [[#TryPopFromAppletBoundChannelForDebug]] (no DebugMode check), except the used s32 is loaded from elsewhere and must be in the range 31-32.&lt;br /&gt;
&lt;br /&gt;
=== GetDisplayLogicalResolution ===&lt;br /&gt;
No input, returns an output s32 &#039;&#039;&#039;width&#039;&#039;&#039; and s32 &#039;&#039;&#039;height&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
=== SetDisplayMagnification ===&lt;br /&gt;
Takes an input float &#039;&#039;&#039;x&#039;&#039;&#039;, float &#039;&#039;&#039;y&#039;&#039;&#039;, float &#039;&#039;&#039;width&#039;&#039;&#039;, and float &#039;&#039;&#039;height&#039;&#039;&#039;, no output.&lt;br /&gt;
&lt;br /&gt;
Sets the DisplayMagnification. This is essentially layer image crop, for everything non-Overlay.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;x&#039;&#039;&#039; and &#039;&#039;&#039;width&#039;&#039;&#039; are multiplied with the same width value returned by [[#GetDisplayLogicalResolution]], so these should be in the range 0.0f-1.0f. Likewise for y and height, except these are multipled with the height value.&lt;br /&gt;
&lt;br /&gt;
=== SetHomeButtonDoubleClickEnabled ===&lt;br /&gt;
Takes an input u8 bool, no output.&lt;br /&gt;
&lt;br /&gt;
=== GetHomeButtonDoubleClickEnabled ===&lt;br /&gt;
No input, returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
=== IsHomeButtonShortPressedBlocked ===&lt;br /&gt;
No input, returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
=== IsVrModeCurtainRequired ===&lt;br /&gt;
No input, returns an output bool.&lt;br /&gt;
&lt;br /&gt;
=== SetCpuBoostRequestPriority ===&lt;br /&gt;
Takes an input s32, no output.&lt;br /&gt;
&lt;br /&gt;
=== GetNotificationReceiverService ===&lt;br /&gt;
No input, returns an [[#IReceiverService|IReceiverService]].&lt;br /&gt;
&lt;br /&gt;
=== GetNotificationSenderService ===&lt;br /&gt;
No input, returns an [[#ISenderService|ISenderService]].&lt;br /&gt;
&lt;br /&gt;
=== IReceiverService ===&lt;br /&gt;
This is &amp;quot;nn::am::service::IReceiverService&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [18.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Cmd0 ====&lt;br /&gt;
No input, returns an [[#INotificationReceiver|INotificationReceiver]].&lt;br /&gt;
&lt;br /&gt;
==== INotificationReceiver ====&lt;br /&gt;
This is &amp;quot;nn::am::service::INotificationReceiver&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [18.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || AddSource&lt;br /&gt;
|-&lt;br /&gt;
| 1 || RemoveSource&lt;br /&gt;
|-&lt;br /&gt;
| 2 || GetEvent&lt;br /&gt;
|-&lt;br /&gt;
| 3 || Receive&lt;br /&gt;
|-&lt;br /&gt;
| 4 || ReceiveWithTick&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
===== GetEvent =====&lt;br /&gt;
Unofficial name.&lt;br /&gt;
&lt;br /&gt;
No input, returns an Event handle.&lt;br /&gt;
&lt;br /&gt;
===== ReceiveWithTick =====&lt;br /&gt;
Unofficial name.&lt;br /&gt;
&lt;br /&gt;
=== ISenderService ===&lt;br /&gt;
This is &amp;quot;nn::am::service::ISenderService&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [18.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Cmd0 ====&lt;br /&gt;
Takes a total of 0x18-bytes of input, returns an [[#INotificationSender|INotificationSender]].&lt;br /&gt;
&lt;br /&gt;
=== INotificationSender ===&lt;br /&gt;
This is &amp;quot;nn::am::service::INotificationSender&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [18.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || Send&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GetUnreceivedMessageCount&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== ILibraryAppletProxy ==&lt;br /&gt;
This is &amp;quot;nn::am::service::ILibraryAppletProxy&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetCommonStateGetter || Returns an [[#ICommonStateGetter]].&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GetSelfController || Returns an [[#ISelfController]].&lt;br /&gt;
|-&lt;br /&gt;
| 2 || GetWindowController || Returns an [[#IWindowController]].&lt;br /&gt;
|-&lt;br /&gt;
| 3 || GetAudioController || Returns an [[#IAudioController]].&lt;br /&gt;
|-&lt;br /&gt;
| 4 || GetDisplayController || Returns an [[#IDisplayController]].&lt;br /&gt;
|-&lt;br /&gt;
| 10 || GetProcessWindingController || Returns an [[#IProcessWindingController]].&lt;br /&gt;
|-&lt;br /&gt;
| 11 || GetLibraryAppletCreator || Returns an [[#ILibraryAppletCreator]].&lt;br /&gt;
|-&lt;br /&gt;
| 20 || OpenLibraryAppletSelfAccessor || Returns an [[#ILibraryAppletSelfAccessor]].&lt;br /&gt;
|-&lt;br /&gt;
| 21 || [7.0.0+] GetAppletCommonFunctions || No input, returns an [[#IAppletCommonFunctions]].&lt;br /&gt;
|-&lt;br /&gt;
| 22 || [15.0.0+] GetHomeMenuFunctions || No input, returns an [[#IHomeMenuFunctions]].&lt;br /&gt;
|-&lt;br /&gt;
| 23 || [15.0.0+] GetGlobalStateController || No input, returns an [[#IGlobalStateController]].&lt;br /&gt;
|-&lt;br /&gt;
| 1000 || GetDebugFunctions || Returns an [[#IDebugFunctions]].&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== ILibraryAppletSelfAccessor ===&lt;br /&gt;
This is &amp;quot;nn::am::service::ILibraryAppletSelfAccessor&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#PopInData]] || &lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#PushOutData]] || &lt;br /&gt;
|-&lt;br /&gt;
| 2 || [[#PopInteractiveInData]] || &lt;br /&gt;
|-&lt;br /&gt;
| 3 || [[#PushInteractiveOutData]] || &lt;br /&gt;
|-&lt;br /&gt;
| 5 || [[#GetPopInDataEvent]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 6 || [[#GetPopInteractiveInDataEvent]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [[#ExitProcessAndReturn]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [[#GetLibraryAppletInfo]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 12 || [[#GetMainAppletIdentityInfo]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 13 || [[#CanUseApplicationCore]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 14 || [[#GetCallerAppletIdentityInfo]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 15 || [2.0.0+] [[#GetMainAppletApplicationControlProperty]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 16 || [2.0.0+] [[#GetMainAppletStorageId]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 17 || [3.0.0+] [[#GetCallerAppletIdentityInfoStack]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 18 || [4.0.0+] [[#GetNextReturnDestinationAppletIdentityInfo]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 19 || [4.0.0+] [[#GetDesirableKeyboardLayout]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 20 || [[#PopExtraStorage]] || &lt;br /&gt;
|-&lt;br /&gt;
| 25 || [[#GetPopExtraStorageEvent]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 30 || [[#UnpopInData]] || &lt;br /&gt;
|-&lt;br /&gt;
| 31 || [[#UnpopExtraStorage]] || &lt;br /&gt;
|-&lt;br /&gt;
| 40 || [2.0.0+] [[#GetIndirectLayerProducerHandle]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 50 || [3.0.0+] [[#ReportVisibleError]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 51 || [4.0.0+] [[#ReportVisibleErrorWithErrorContext]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 60 || [4.0.0+] [[#GetMainAppletApplicationDesiredLanguage]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 70 || [8.0.0+] [[#GetCurrentApplicationId]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 80 || [6.0.0+] [[#RequestExitToSelf]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 90 || [5.0.0+] [[#CreateApplicationAndPushAndRequestToLaunch]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 100 || [4.0.0+] [[#CreateGameMovieTrimmer]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 101 || [5.0.0+] [[#ReserveResourceForMovieOperation]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 102 || [5.0.0+] [[#UnreserveResourceForMovieOperation]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 110 || [6.0.0+] [[#GetMainAppletAvailableUsers]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 120 || [9.0.0+] [[#GetLaunchStorageInfoForDebug]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 130 || [9.0.0+] [[#GetGpuErrorDetectedSystemEvent]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 140 || [10.0.0+] [[#SetApplicationMemoryReservation]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 150 || [10.0.0+] [[#ShouldSetGpuTimeSliceManually]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 160 || [17.0.0+] [[#GetLibraryAppletInfoEx]] || &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== PopInData ====&lt;br /&gt;
No input, returns an output [[#IStorage]].&lt;br /&gt;
&lt;br /&gt;
==== PushOutData ====&lt;br /&gt;
Takes an input [[#IStorage]], no output.&lt;br /&gt;
&lt;br /&gt;
==== PopInteractiveInData ====&lt;br /&gt;
No input, returns an output [[#IStorage]].&lt;br /&gt;
&lt;br /&gt;
==== PushInteractiveOutData ====&lt;br /&gt;
Takes an input [[#IStorage]], no output.&lt;br /&gt;
&lt;br /&gt;
==== GetPopInDataEvent ====&lt;br /&gt;
No input, returns an output Event handle with autoclear=false.&lt;br /&gt;
&lt;br /&gt;
==== GetPopInteractiveInDataEvent ====&lt;br /&gt;
No input, returns an output Event handle with autoclear=false.&lt;br /&gt;
&lt;br /&gt;
==== ExitProcessAndReturn ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Exits the LibraryApplet and returns to running the title which launched this LibraryApplet ([[qlaunch]] for example).&lt;br /&gt;
&lt;br /&gt;
On success, official sw will enter an infinite loop with sleep-thread value 86400000000000.&lt;br /&gt;
&lt;br /&gt;
==== GetLibraryAppletInfo ====&lt;br /&gt;
No input, returns an output [[#LibraryAppletInfo]].&lt;br /&gt;
&lt;br /&gt;
==== GetMainAppletIdentityInfo ====&lt;br /&gt;
No input, returns an output [[#AppletIdentityInfo]].&lt;br /&gt;
&lt;br /&gt;
==== CanUseApplicationCore ====&lt;br /&gt;
No input, returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
==== GetCallerAppletIdentityInfo ====&lt;br /&gt;
No input, returns an output [[#AppletIdentityInfo]].&lt;br /&gt;
&lt;br /&gt;
==== GetMainAppletApplicationControlProperty ====&lt;br /&gt;
No input, takes a type-0x16 output buffer.&lt;br /&gt;
&lt;br /&gt;
This gets the [[NACP_Format|control.nacp]].&lt;br /&gt;
&lt;br /&gt;
==== GetMainAppletStorageId ====&lt;br /&gt;
No input, returns an output u8 storageId.&lt;br /&gt;
&lt;br /&gt;
==== GetCallerAppletIdentityInfoStack ====&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of [[#AppletIdentityInfo]], and returns an output s32 total_entries.&lt;br /&gt;
&lt;br /&gt;
==== GetNextReturnDestinationAppletIdentityInfo ====&lt;br /&gt;
No input, returns an output [[#AppletIdentityInfo]].&lt;br /&gt;
&lt;br /&gt;
==== GetDesirableKeyboardLayout ====&lt;br /&gt;
No input, returns an output u32.&lt;br /&gt;
&lt;br /&gt;
The output u32 is &amp;quot;nn::settings::KeyboardLayout&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This gets the value previously set by [[#SetDesirableKeyboardLayout]]. An error is returned if it&#039;s not set.&lt;br /&gt;
&lt;br /&gt;
==== PopExtraStorage ====&lt;br /&gt;
No input, returns an output [[#IStorage]].&lt;br /&gt;
&lt;br /&gt;
==== GetPopExtraStorageEvent ====&lt;br /&gt;
No input, returns an output Event handle with autoclear=false.&lt;br /&gt;
&lt;br /&gt;
==== UnpopInData ====&lt;br /&gt;
Takes an input [[#IStorage]], no output.&lt;br /&gt;
&lt;br /&gt;
==== UnpopExtraStorage ====&lt;br /&gt;
Takes an input [[#IStorage]], no output.&lt;br /&gt;
&lt;br /&gt;
==== GetIndirectLayerProducerHandle ====&lt;br /&gt;
No input, returns an output u64.&lt;br /&gt;
&lt;br /&gt;
==== ReportVisibleError ====&lt;br /&gt;
Takes an input [[Error_Applet#ErrorCode|ErrorCode]], no output.&lt;br /&gt;
&lt;br /&gt;
==== ReportVisibleErrorWithErrorContext ====&lt;br /&gt;
Takes an input [[Error_Applet#ErrorCode|ErrorCode]] and a type-0x15 input buffer containing an [[Error_Applet#ErrorContext|ErrorContext]], no output.&lt;br /&gt;
&lt;br /&gt;
==== GetMainAppletApplicationDesiredLanguage ====&lt;br /&gt;
No input, returns an output [[Settings_services#LanguageCode|LanguageCode]].&lt;br /&gt;
&lt;br /&gt;
==== GetCurrentApplicationId ====&lt;br /&gt;
No input, returns an output [[NCM_services#ApplicationId|ApplicationId]].&lt;br /&gt;
&lt;br /&gt;
Gets the [[NCM_services#ApplicationId|ApplicationId]] for the currently running Application. ApplicationId=0 when no Application is running.&lt;br /&gt;
&lt;br /&gt;
==== RequestExitToSelf ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Same as [[#RequestExit]] except this is for the current applet.&lt;br /&gt;
&lt;br /&gt;
==== CreateApplicationAndPushAndRequestToLaunch ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]] and an input #IStorage, no output.&lt;br /&gt;
&lt;br /&gt;
This is is similar to [[#CreateApplicationAndPushAndRequestToStart]].&lt;br /&gt;
&lt;br /&gt;
==== CreateGameMovieTrimmer ====&lt;br /&gt;
Takes an input u64 size and a TransferMemory handle, returns a GRC [[GRC_services#IGameMovieTrimmer|IGameMovieTrimmer]].&lt;br /&gt;
&lt;br /&gt;
This is a wrapper for GRC [[GRC_services#OpenGameMovieTrimmer|OpenGameMovieTrimmer]].&lt;br /&gt;
&lt;br /&gt;
Official sw uses an user-buffer for the tmem, with permissions=0.&lt;br /&gt;
&lt;br /&gt;
==== ReserveResourceForMovieOperation ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Updates state fields. This must be used before [[#CreateGameMovieTrimmer]].&lt;br /&gt;
&lt;br /&gt;
==== UnreserveResourceForMovieOperation ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Updates state fields. This must be used once finished with [[GRC_services#IGameMovieTrimmer|IGameMovieTrimmer]].&lt;br /&gt;
&lt;br /&gt;
==== GetMainAppletAvailableUsers ====&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of u128 userIDs, returns an output u8 bool and a s32 &#039;&#039;&#039;total_entries&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
This gets the userIDs previously set by [[#SetUsers]].&lt;br /&gt;
&lt;br /&gt;
The size of the output buffer in entries must be at least 8.&lt;br /&gt;
&lt;br /&gt;
Normally the output bool is set to 0, however when no users are available it&#039;s set to 1 with &#039;&#039;&#039;total_entries&#039;&#039;&#039; = -1.&lt;br /&gt;
&lt;br /&gt;
==== SetApplicationMemoryReservation ====&lt;br /&gt;
Takes an input u64, no output.&lt;br /&gt;
&lt;br /&gt;
An Application must be currently running. The input u64 must be 0x1000-byte aligned.&lt;br /&gt;
&lt;br /&gt;
==== ShouldSetGpuTimeSliceManually ====&lt;br /&gt;
No input, returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
==== GetLibraryAppletInfoEx ====&lt;br /&gt;
No input, returns an output u64. Currently always returns 0.&lt;br /&gt;
&lt;br /&gt;
== IOverlayAppletProxy ==&lt;br /&gt;
This is &amp;quot;nn::am::service::IOverlayAppletProxy&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetCommonStateGetter || Returns an [[#ICommonStateGetter]].&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GetSelfController || Returns an [[#ISelfController]].&lt;br /&gt;
|-&lt;br /&gt;
| 2 || GetWindowController || Returns an [[#IWindowController]].&lt;br /&gt;
|-&lt;br /&gt;
| 3 || GetAudioController || Returns an [[#IAudioController]].&lt;br /&gt;
|-&lt;br /&gt;
| 4 || GetDisplayController || Returns an [[#IDisplayController]].&lt;br /&gt;
|-&lt;br /&gt;
| 10 || GetProcessWindingController || Returns an [[#IProcessWindingController]].&lt;br /&gt;
|-&lt;br /&gt;
| 11 || GetLibraryAppletCreator || Returns an [[#ILibraryAppletCreator]].&lt;br /&gt;
|-&lt;br /&gt;
| 20 || GetOverlayFunctions || Returns an [[#IOverlayFunctions]].&lt;br /&gt;
|-&lt;br /&gt;
| 21 || [7.0.0+] GetAppletCommonFunctions || No input, returns an [[#IAppletCommonFunctions]].&lt;br /&gt;
|-&lt;br /&gt;
| 23 || [15.0.0+] GetGlobalStateController || No input, returns an [[#IGlobalStateController]].&lt;br /&gt;
|-&lt;br /&gt;
| 1000 || GetDebugFunctions || Returns an [[#IDebugFunctions]].&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IOverlayFunctions ===&lt;br /&gt;
This is &amp;quot;nn::am::service::IOverlayFunctions&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#BeginToWatchShortHomeButtonMessage]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#EndToWatchShortHomeButtonMessage]]&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [[#GetApplicationIdForLogo]]&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [[#SetGpuTimeSliceBoost]]&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [2.0.0+] [[#SetAutoSleepTimeAndDimmingTimeEnabled]]&lt;br /&gt;
|-&lt;br /&gt;
| 5 || [2.0.0+] [[#TerminateApplicationAndSetReason]]&lt;br /&gt;
|-&lt;br /&gt;
| 6 || [3.0.0+] [[#SetScreenShotPermissionGlobally]]&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [6.0.0+] [[#StartShutdownSequenceForOverlay]]&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [6.0.0+] [[#StartRebootSequenceForOverlay]]&lt;br /&gt;
|-&lt;br /&gt;
| 20 || [8.0.0+] [[#SetHandlingHomeButtonShortPressedEnabled]]&lt;br /&gt;
|-&lt;br /&gt;
| 21 || [14.0.0+] SetHandlingTouchScreenInputEnabled&lt;br /&gt;
|-&lt;br /&gt;
| 30 || [9.0.0+] [[#SetHealthWarningShowingState]]&lt;br /&gt;
|-&lt;br /&gt;
| 31 || [10.0.0+] [[#IsHealthWarningRequired]]&lt;br /&gt;
|-&lt;br /&gt;
| 40 || [18.0.0+] GetApplicationNintendoLogo&lt;br /&gt;
|-&lt;br /&gt;
| 41 || [18.0.0+] GetApplicationStartupMovie&lt;br /&gt;
|-&lt;br /&gt;
| 50 || [19.0.0+] SetGpuTimeSliceBoostForApplication&lt;br /&gt;
|-&lt;br /&gt;
| 60 || [19.0.0+] &lt;br /&gt;
|-&lt;br /&gt;
| 61 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 70 || [21.0.0+] &lt;br /&gt;
|-&lt;br /&gt;
| 71 || [21.0.0+] &lt;br /&gt;
|-&lt;br /&gt;
| 75 || [21.0.0+] &lt;br /&gt;
|-&lt;br /&gt;
| 90 || [7.0.0+] [[#SetRequiresGpuResourceUse]]&lt;br /&gt;
|-&lt;br /&gt;
| 101 || [5.0.0+] [[#BeginToObserveHidInputForDevelop]]&lt;br /&gt;
|-&lt;br /&gt;
| 110 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 1000 || [S2]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== BeginToWatchShortHomeButtonMessage ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== EndToWatchShortHomeButtonMessage ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== GetApplicationIdForLogo ====&lt;br /&gt;
No input, returns an output [[NCM_services#ApplicationId|ApplicationId]].&lt;br /&gt;
&lt;br /&gt;
Gets the ApplicationId for displaying the logo screen during application launch.&lt;br /&gt;
&lt;br /&gt;
When no application is running, this returns success with ApplicationId=0.&lt;br /&gt;
&lt;br /&gt;
==== SetGpuTimeSliceBoost ====&lt;br /&gt;
Takes an input u64, no output.&lt;br /&gt;
&lt;br /&gt;
==== SetAutoSleepTimeAndDimmingTimeEnabled ====&lt;br /&gt;
Takes an input u8 bool, no output.&lt;br /&gt;
&lt;br /&gt;
==== TerminateApplicationAndSetReason ====&lt;br /&gt;
Takes an input u32 Result, no output.&lt;br /&gt;
&lt;br /&gt;
==== SetScreenShotPermissionGlobally ====&lt;br /&gt;
Takes an input u8 bool, no output.&lt;br /&gt;
&lt;br /&gt;
==== StartShutdownSequenceForOverlay ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
On success, official sw will enter an infinite loop with sleep-thread value 86400000000000.&lt;br /&gt;
&lt;br /&gt;
==== StartRebootSequenceForOverlay ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
On success, official sw will enter an infinite loop with sleep-thread value 86400000000000.&lt;br /&gt;
&lt;br /&gt;
==== SetHandlingHomeButtonShortPressedEnabled ====&lt;br /&gt;
Takes an input u8 bool, no output.&lt;br /&gt;
&lt;br /&gt;
==== SetHealthWarningShowingState ====&lt;br /&gt;
Takes an input u8 bool, no output.&lt;br /&gt;
&lt;br /&gt;
This writes the input bool into state, signals an Event, and returns 0.&lt;br /&gt;
&lt;br /&gt;
==== IsHealthWarningRequired ====&lt;br /&gt;
No input, returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
==== SetRequiresGpuResourceUse ====&lt;br /&gt;
Takes an input u8 bool, no output.&lt;br /&gt;
&lt;br /&gt;
Just returns 0.&lt;br /&gt;
&lt;br /&gt;
==== BeginToObserveHidInputForDevelop ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Sets various state fields and signals an userspace-event.&lt;br /&gt;
&lt;br /&gt;
Enables HID input for the OverlayApplet, without disabling input for the foreground applet.&lt;br /&gt;
&lt;br /&gt;
== ICMenuProxy ==&lt;br /&gt;
This is &amp;quot;nn::am::service::ICMenuProxy&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This is exclusive to Switch 2.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetCommonStateGetter || Returns an [[#ICommonStateGetter]].&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GetSelfController || Returns an [[#ISelfController]].&lt;br /&gt;
|-&lt;br /&gt;
| 2 || GetWindowController || Returns an [[#IWindowController]].&lt;br /&gt;
|-&lt;br /&gt;
| 3 || GetAudioController || Returns an [[#IAudioController]].&lt;br /&gt;
|-&lt;br /&gt;
| 4 || GetDisplayController || Returns an [[#IDisplayController]].&lt;br /&gt;
|-&lt;br /&gt;
| 1000 || GetDebugFunctions || Returns an [[#IDebugFunctions]].&lt;br /&gt;
|-&lt;br /&gt;
| 10 || GetProcessWindingController || Returns an [[#IProcessWindingController]].&lt;br /&gt;
|-&lt;br /&gt;
| 11 || GetLibraryAppletCreator || Returns an [[#ILibraryAppletCreator]].&lt;br /&gt;
|-&lt;br /&gt;
| 20 || GetOverlayFunctions || Returns an [[#IOverlayFunctions]].&lt;br /&gt;
|-&lt;br /&gt;
| 21 || GetAppletCommonFunctions || No input, returns an [[#IAppletCommonFunctions]].&lt;br /&gt;
|-&lt;br /&gt;
| 23 || GetGlobalStateController || No input, returns an [[#IGlobalStateController]].&lt;br /&gt;
|-&lt;br /&gt;
| 24 || || No input, returns an [[#ICMenuFunctions|ICMenuFunctions]].&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== ICMenuFunctions ===&lt;br /&gt;
This is &amp;quot;nn::am::service::ICMenuFunctions&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This is exclusive to Switch 2.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || &lt;br /&gt;
|-&lt;br /&gt;
| 1 || &lt;br /&gt;
|-&lt;br /&gt;
| 2 || &lt;br /&gt;
|-&lt;br /&gt;
| 3 || &lt;br /&gt;
|-&lt;br /&gt;
| 4 || &lt;br /&gt;
|-&lt;br /&gt;
| 5 || &lt;br /&gt;
|-&lt;br /&gt;
| 6 || &lt;br /&gt;
|-&lt;br /&gt;
| 10 || &lt;br /&gt;
|-&lt;br /&gt;
| 11 || &lt;br /&gt;
|-&lt;br /&gt;
| 20 || &lt;br /&gt;
|-&lt;br /&gt;
| 21 || &lt;br /&gt;
|-&lt;br /&gt;
| 30 || &lt;br /&gt;
|-&lt;br /&gt;
| 31 || &lt;br /&gt;
|-&lt;br /&gt;
| 40 || &lt;br /&gt;
|-&lt;br /&gt;
| 41 || &lt;br /&gt;
|-&lt;br /&gt;
| 50 || &lt;br /&gt;
|-&lt;br /&gt;
| 60 || &lt;br /&gt;
|-&lt;br /&gt;
| 61 || &lt;br /&gt;
|-&lt;br /&gt;
| 90 || &lt;br /&gt;
|-&lt;br /&gt;
| 101 || &lt;br /&gt;
|-&lt;br /&gt;
| 110 || &lt;br /&gt;
|-&lt;br /&gt;
| 1000 || &lt;br /&gt;
|-&lt;br /&gt;
| 200 || &lt;br /&gt;
|-&lt;br /&gt;
| 202 || &lt;br /&gt;
|-&lt;br /&gt;
| 210 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 220 || [20.0.0+]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Cmd200 ====&lt;br /&gt;
No input, returns an [[#ILibraryAppletAgent|ILibraryAppletAgent]].&lt;br /&gt;
&lt;br /&gt;
==== Cmd202 ====&lt;br /&gt;
Takes {...}, returns an [[#IFocusableLayer|IFocusableLayer]].&lt;br /&gt;
&lt;br /&gt;
==== ILibraryAppletAgent ====&lt;br /&gt;
This is &amp;quot;nn::am::service::ILibraryAppletAgent&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This is exclusive to Switch 2.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || &lt;br /&gt;
|-&lt;br /&gt;
| 1 || &lt;br /&gt;
|-&lt;br /&gt;
| 2 || &lt;br /&gt;
|-&lt;br /&gt;
| 3 || &lt;br /&gt;
|-&lt;br /&gt;
| 4 || &lt;br /&gt;
|-&lt;br /&gt;
| 5 || &lt;br /&gt;
|-&lt;br /&gt;
| 10 || &lt;br /&gt;
|-&lt;br /&gt;
| 20 || &lt;br /&gt;
|-&lt;br /&gt;
| 21 || &lt;br /&gt;
|-&lt;br /&gt;
| 31 || &lt;br /&gt;
|-&lt;br /&gt;
| 32 || &lt;br /&gt;
|-&lt;br /&gt;
| 33 || &lt;br /&gt;
|-&lt;br /&gt;
| 34 || &lt;br /&gt;
|-&lt;br /&gt;
| 35 || &lt;br /&gt;
|-&lt;br /&gt;
| 40 || &lt;br /&gt;
|-&lt;br /&gt;
| 41 || &lt;br /&gt;
|-&lt;br /&gt;
| 42 || &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
===== Cmd0 =====&lt;br /&gt;
No input, returns an [[#IStorage|IStorage]].&lt;br /&gt;
&lt;br /&gt;
===== Cmd1 =====&lt;br /&gt;
Takes an unknown input interface, no output.&lt;br /&gt;
&lt;br /&gt;
===== Cmd2 =====&lt;br /&gt;
No input, returns an [[#IStorage|IStorage]].&lt;br /&gt;
&lt;br /&gt;
===== Cmd3 =====&lt;br /&gt;
Takes an unknown input interface, no output.&lt;br /&gt;
&lt;br /&gt;
===== Cmd10 =====&lt;br /&gt;
No input, returns an [[#IStorage|IStorage]].&lt;br /&gt;
&lt;br /&gt;
===== Cmd20 =====&lt;br /&gt;
Takes an unknown input interface, no output.&lt;br /&gt;
&lt;br /&gt;
===== Cmd21 =====&lt;br /&gt;
Takes an unknown input interface, no output.&lt;br /&gt;
&lt;br /&gt;
==== IFocusableLayer ====&lt;br /&gt;
This is &amp;quot;nn::am::service::IFocusableLayer&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This is exclusive to Switch 2.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || &lt;br /&gt;
|-&lt;br /&gt;
| 1 || &lt;br /&gt;
|-&lt;br /&gt;
| 2 || &lt;br /&gt;
|-&lt;br /&gt;
| 3 || &lt;br /&gt;
|-&lt;br /&gt;
| 4 || &lt;br /&gt;
|-&lt;br /&gt;
| 10 || &lt;br /&gt;
|-&lt;br /&gt;
| 11 || &lt;br /&gt;
|-&lt;br /&gt;
| 20 || &lt;br /&gt;
|-&lt;br /&gt;
| 21 || &lt;br /&gt;
|-&lt;br /&gt;
| 32 || &lt;br /&gt;
|-&lt;br /&gt;
| 33 || &lt;br /&gt;
|-&lt;br /&gt;
| 40 || &lt;br /&gt;
|-&lt;br /&gt;
| 41 || &lt;br /&gt;
|-&lt;br /&gt;
| 42 || &lt;br /&gt;
|-&lt;br /&gt;
| 50 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 51 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 60 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 70 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 71 || [20.0.0+]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IApplicationProxy ==&lt;br /&gt;
This is &amp;quot;nn::am::service::IApplicationProxy&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetCommonStateGetter || Returns an [[#ICommonStateGetter]].&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GetSelfController || Returns an [[#ISelfController]].&lt;br /&gt;
|-&lt;br /&gt;
| 2 || GetWindowController || Returns an [[#IWindowController]].&lt;br /&gt;
|-&lt;br /&gt;
| 3 || GetAudioController || Returns an [[#IAudioController]].&lt;br /&gt;
|-&lt;br /&gt;
| 4 || GetDisplayController || Returns an [[#IDisplayController]].&lt;br /&gt;
|-&lt;br /&gt;
| 10 || GetProcessWindingController || Returns an [[#IProcessWindingController]].&lt;br /&gt;
|-&lt;br /&gt;
| 11 || GetLibraryAppletCreator || Returns an [[#ILibraryAppletCreator]].&lt;br /&gt;
|-&lt;br /&gt;
| 20 || GetApplicationFunctions || Returns an [[#IApplicationFunctions]].&lt;br /&gt;
|-&lt;br /&gt;
| 40 || [S2] || Returns an [[#IPerformanceFunctions|IPerformanceFunctions]].&lt;br /&gt;
|-&lt;br /&gt;
| 60 || [S2] || Returns an [[#IGraphicsScalingParametersFunctions|IGraphicsScalingParametersFunctions]].&lt;br /&gt;
|-&lt;br /&gt;
| 1000 || GetDebugFunctions || Returns an [[#IDebugFunctions]].&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IApplicationFunctions ===&lt;br /&gt;
This is &amp;quot;nn::am::service::IApplicationFunctions&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#PopLaunchParameter]]&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [[#CreateApplicationAndPushAndRequestToStart]]&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [3.0.0+] [[#CreateApplicationAndPushAndRequestToStartForQuest]]&lt;br /&gt;
|-&lt;br /&gt;
| 12 || [4.0.0+] [[#CreateApplicationAndRequestToStart]]&lt;br /&gt;
|-&lt;br /&gt;
| 13 || [4.0.0+] [[#CreateApplicationAndRequestToStartForQuest]]&lt;br /&gt;
|-&lt;br /&gt;
| 14 || [7.0.0+] [[#CreateApplicationWithAttributeAndPushAndRequestToStartForQuest]]&lt;br /&gt;
|-&lt;br /&gt;
| 15 || [7.0.0+] [[#CreateApplicationWithAttributeAndRequestToStartForQuest]]&lt;br /&gt;
|-&lt;br /&gt;
| 20 || [[#EnsureSaveData]]&lt;br /&gt;
|-&lt;br /&gt;
| 21 || [[#GetDesiredLanguage]]&lt;br /&gt;
|-&lt;br /&gt;
| 22 || [[#SetTerminateResult]]&lt;br /&gt;
|-&lt;br /&gt;
| 23 || [[#GetDisplayVersion]]&lt;br /&gt;
|-&lt;br /&gt;
| 24 || [2.0.0+] [[#GetLaunchStorageInfoForDebug]]&lt;br /&gt;
|-&lt;br /&gt;
| 25 || [3.0.0+] ExtendSaveData&lt;br /&gt;
|-&lt;br /&gt;
| 26 || [3.0.0+] GetSaveDataSize&lt;br /&gt;
|-&lt;br /&gt;
| 27 || [5.0.0+] CreateCacheStorage&lt;br /&gt;
|-&lt;br /&gt;
| 28 || [11.0.0+] [[#GetSaveDataSizeMax]]&lt;br /&gt;
|-&lt;br /&gt;
| 29 || [11.0.0+] [[#GetCacheStorageMax]]&lt;br /&gt;
|-&lt;br /&gt;
| 30 || [[#BeginBlockingHomeButtonShortAndLongPressed]]&lt;br /&gt;
|-&lt;br /&gt;
| 31 || [[#EndBlockingHomeButtonShortAndLongPressed]]&lt;br /&gt;
|-&lt;br /&gt;
| 32 || [[#BeginBlockingHomeButton]]&lt;br /&gt;
|-&lt;br /&gt;
| 33 || [[#EndBlockingHomeButton]]&lt;br /&gt;
|-&lt;br /&gt;
| 34 || [10.0.0-15.0.1] [[#SelectApplicationLicense]]&lt;br /&gt;
|-&lt;br /&gt;
| 35 || [11.0.0+] [[#GetDeviceSaveDataSizeMax]]&lt;br /&gt;
|-&lt;br /&gt;
| 36 || [14.0.0+] GetLimitedApplicationLicense&lt;br /&gt;
|-&lt;br /&gt;
| 37 || [14.0.0+] GetLimitedApplicationLicenseUpgradableEvent&lt;br /&gt;
|-&lt;br /&gt;
| 40 || [[#NotifyRunning]]&lt;br /&gt;
|-&lt;br /&gt;
| 50 || [2.0.0+] [[#GetPseudoDeviceId]]&lt;br /&gt;
|-&lt;br /&gt;
| 60 || [2.0.0+] [[#SetMediaPlaybackStateForApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 65 || [3.0.0+] [[#IsGamePlayRecordingSupported]]&lt;br /&gt;
|-&lt;br /&gt;
| 66 || [3.0.0+] [[#InitializeGamePlayRecording]]&lt;br /&gt;
|-&lt;br /&gt;
| 67 || [3.0.0+] [[#SetGamePlayRecordingState]]&lt;br /&gt;
|-&lt;br /&gt;
| 68 || [4.0.0+] [[#RequestFlushGamePlayingMovieForDebug]]&lt;br /&gt;
|-&lt;br /&gt;
| 70 || [3.0.0+] [[#RequestToShutdown]]&lt;br /&gt;
|-&lt;br /&gt;
| 71 || [3.0.0+] [[#RequestToReboot]]&lt;br /&gt;
|-&lt;br /&gt;
| 72 || [10.0.0+] [[#RequestToSleep]]&lt;br /&gt;
|-&lt;br /&gt;
| 80 || [4.0.0+] [[#ExitAndRequestToShowThanksMessage]]&lt;br /&gt;
|-&lt;br /&gt;
| 90 || [4.0.0+] [[#EnableApplicationCrashReport]]&lt;br /&gt;
|-&lt;br /&gt;
| 100 || [5.0.0+] [[#InitializeApplicationCopyrightFrameBuffer]] &lt;br /&gt;
|-&lt;br /&gt;
| 101 || [5.0.0+] [[#SetApplicationCopyrightImage]]&lt;br /&gt;
|-&lt;br /&gt;
| 102 || [5.0.0+] [[#SetApplicationCopyrightVisibility]]&lt;br /&gt;
|-&lt;br /&gt;
| 110 || [5.0.0+] [[#QueryApplicationPlayStatistics]]&lt;br /&gt;
|-&lt;br /&gt;
| 111 || [6.0.0+] [[#QueryApplicationPlayStatisticsByUid]]&lt;br /&gt;
|-&lt;br /&gt;
| 112 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 113 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 120 || [5.0.0+] [[#ExecuteProgram]]&lt;br /&gt;
|-&lt;br /&gt;
| 121 || [5.0.0+] [[#ClearUserChannel]]&lt;br /&gt;
|-&lt;br /&gt;
| 122 || [5.0.0+] [[#UnpopToUserChannel]]&lt;br /&gt;
|-&lt;br /&gt;
| 123 || [5.0.0+] [[#GetPreviousProgramIndex]]&lt;br /&gt;
|-&lt;br /&gt;
| 124 || [6.0.0+] [[#EnableApplicationAllThreadDumpOnCrash]]&lt;br /&gt;
|-&lt;br /&gt;
| 130 || [8.0.0+] [[#GetGpuErrorDetectedSystemEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 131 || [11.0.0+] [[#SetDelayTimeToAbortOnGpuError]]&lt;br /&gt;
|-&lt;br /&gt;
| 140 || [9.0.0+] [[#GetFriendInvitationStorageChannelEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 141 || [9.0.0+] [[#TryPopFromFriendInvitationStorageChannel]] &lt;br /&gt;
|-&lt;br /&gt;
| 150 || [9.0.0+] [[#GetNotificationStorageChannelEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 151 || [9.0.0+] [[#TryPopFromNotificationStorageChannel]]&lt;br /&gt;
|-&lt;br /&gt;
| 160 || [9.0.0+] [[#GetHealthWarningDisappearedSystemEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 170 || [9.0.0+] [[#SetHdcpAuthenticationActivated]]&lt;br /&gt;
|-&lt;br /&gt;
| 180 || [10.1.0+] [[#GetLaunchRequiredVersion]]&lt;br /&gt;
|-&lt;br /&gt;
| 181 || [10.1.0+] [[#UpgradeLaunchRequiredVersion]]&lt;br /&gt;
|-&lt;br /&gt;
| 190 || [11.0.0+] [[#SendServerMaintenanceOverlayNotification]]&lt;br /&gt;
|-&lt;br /&gt;
| 200 || [11.0.0+] [[#GetLastApplicationExitReason]]&lt;br /&gt;
|-&lt;br /&gt;
| 210 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 220 || [20.0.0+] [[#SetAudioOutputPolicy|SetAudioOutputPolicy]]&lt;br /&gt;
|-&lt;br /&gt;
| 230 || [S2] [20.0.0+] IsTensorRtSupported&lt;br /&gt;
|-&lt;br /&gt;
| 300 || [19.0.0+] [[#CreateMovieWriter]]&lt;br /&gt;
|-&lt;br /&gt;
| 310 || [20.0.0+] [[#RequestExitApplicationAndTryPopMessage|RequestExitApplicationAndTryPopMessage]]&lt;br /&gt;
|-&lt;br /&gt;
| 320 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 321 || [S2] [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 330 || [20.2.0+] IsLanguageSelectionLimited&lt;br /&gt;
|-&lt;br /&gt;
| 500 || [5.0.0+] [[#StartContinuousRecordingFlushForDebug]]&lt;br /&gt;
|-&lt;br /&gt;
| 1000 || [5.0.0+] [[#CreateMovieMaker]]&lt;br /&gt;
|-&lt;br /&gt;
| 1001 || [5.0.0+] [[#PrepareForJit]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
The BOTW game uses this GamePlayRecording functionality from the main-nso &amp;quot;nninitStartup&amp;quot; function, with size 0x6000000(96MiB). The official GamePlayRecording-enable code does the following(this will panic on any failure):&lt;br /&gt;
* [[SVC|Creates]] TransferMemory using the input buffer and size, with permissions=0.&lt;br /&gt;
* Uses [[#InitializeGamePlayRecording]] with the TransferMemory.&lt;br /&gt;
* Closes the TransferMemory handle, + TransferMemory cleanup.&lt;br /&gt;
* Uses [[#SetGamePlayRecordingState]] with value 0x1.&lt;br /&gt;
This GamePlayRecording functionality presumably enables the video-recording usable starting with [[4.0.0]].&lt;br /&gt;
&lt;br /&gt;
==== PopLaunchParameter ====&lt;br /&gt;
Takes an input u32 [[#LaunchParameterKind]], returns an output [[#IStorage]].&lt;br /&gt;
&lt;br /&gt;
Pops a LaunchParameter [[#IStorage]], the storage will be removed from sysmodule state during this.&lt;br /&gt;
&lt;br /&gt;
==== CreateApplicationAndPushAndRequestToStart ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]] and an input [[#IStorage]], no output. ApplicationId=0 can be used to relaunch the current application.&lt;br /&gt;
&lt;br /&gt;
==== CreateApplicationAndPushAndRequestToStartForQuest ====&lt;br /&gt;
Takes 2 input u32s (loaded from struct [[#ApplicationAttributeForQuest]]), an input [[NCM_services#ApplicationId|ApplicationId]], and an input [[#IStorage]], no output.&lt;br /&gt;
&lt;br /&gt;
==== CreateApplicationAndRequestToStart ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
Same as [[#CreateApplicationAndPushAndRequestToStart]] except without the input storage, official sw uses this when no input storage is specified.&lt;br /&gt;
&lt;br /&gt;
==== CreateApplicationAndRequestToStartForQuest ====&lt;br /&gt;
Takes 2 input u32s (loaded from struct [[#ApplicationAttributeForQuest]]) and an input [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
Same as [[#CreateApplicationAndPushAndRequestToStartForQuest]] except without the input storage, official sw uses this when no input storage is specified.&lt;br /&gt;
&lt;br /&gt;
==== CreateApplicationWithAttributeAndPushAndRequestToStartForQuest ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], a type-0x15 input buffer containing an [[#ApplicationAttribute]], an input [[#IStorage]], no output.&lt;br /&gt;
&lt;br /&gt;
[21.0.0+] Now returns an output [[#IStorage]].&lt;br /&gt;
&lt;br /&gt;
Same as [[#CreateApplicationAndPushAndRequestToStartForQuest]] except the entire attributes structure is directly specified via the input buffer. This command replaces [[#CreateApplicationAndPushAndRequestToStartForQuest]], official user-processes no longer use [[#CreateApplicationAndPushAndRequestToStartForQuest]].&lt;br /&gt;
&lt;br /&gt;
==== CreateApplicationWithAttributeAndRequestToStartForQuest ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]] and a type-0x15 input buffer containing an [[#ApplicationAttribute]], no output.&lt;br /&gt;
&lt;br /&gt;
Same as [[#CreateApplicationAndRequestToStartForQuest]] except the entire attributes structure is directly specified via the input buffer. This command replaces [[#CreateApplicationAndRequestToStartForQuest]], official user-processes no longer use [[#CreateApplicationAndPushAndRequestToStartForQuest]].&lt;br /&gt;
&lt;br /&gt;
==== EnsureSaveData ====&lt;br /&gt;
Takes an input u128 userID, returns an output u64 size.&lt;br /&gt;
&lt;br /&gt;
Calls sdk func &amp;lt;code&amp;gt;nn::fs::EnsureApplicationSaveData&amp;lt;/code&amp;gt;. [[qlaunch]] also calls this same sdk func directly.&lt;br /&gt;
&lt;br /&gt;
Creates the various savedata as specified by the application [[NACP_Format|control.nacp]] when the savedata doesn&#039;t exist.&lt;br /&gt;
&lt;br /&gt;
Official user-processes launch the dataErase LibraryApplet depending on the Result, the above output size is used with this.&lt;br /&gt;
&lt;br /&gt;
==== GetDesiredLanguage ====&lt;br /&gt;
No input, returns an output [[Settings_services#LanguageCode|LanguageCode]].&lt;br /&gt;
&lt;br /&gt;
==== SetTerminateResult ====&lt;br /&gt;
Takes an input u32 &#039;&#039;&#039;Result&#039;&#039;&#039;, no output.&lt;br /&gt;
&lt;br /&gt;
For example, in some cases official apps use this with [[Error_codes|error]] 0x2A2 then uses svcBreak.&lt;br /&gt;
&lt;br /&gt;
==== GetDisplayVersion ====&lt;br /&gt;
No input, returns an output 0x10-byte struct.&lt;br /&gt;
&lt;br /&gt;
The output struct is &amp;quot;nn::oe::DisplayVersion&amp;quot;. This the DisplayVersion string copied from the application [[NACP_Format|control.nacp]], this is always NUL-terminated.&lt;br /&gt;
&lt;br /&gt;
==== GetLaunchStorageInfoForDebug ====&lt;br /&gt;
No input, returns an output u8 [[Filesystem_services#StorageId|StorageId]] and u8 [[Filesystem_services#StorageId|StorageId]].&lt;br /&gt;
&lt;br /&gt;
This returns two u8s loaded from state, these are the same StorageIds from [[#ApplicationLaunchProperty]].&lt;br /&gt;
&lt;br /&gt;
==== GetSaveDataSizeMax ====&lt;br /&gt;
No input, returns two ouput s64s.&lt;br /&gt;
&lt;br /&gt;
==== GetCacheStorageMax ====&lt;br /&gt;
No input, returns an output s32 and s64.&lt;br /&gt;
&lt;br /&gt;
==== BeginBlockingHomeButtonShortAndLongPressed ====&lt;br /&gt;
Takes an input s64, no output.&lt;br /&gt;
&lt;br /&gt;
Official user-processes use hard-coded value 0 for the s64.&lt;br /&gt;
&lt;br /&gt;
Starts blocking the Home button.&lt;br /&gt;
&lt;br /&gt;
==== EndBlockingHomeButtonShortAndLongPressed ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Ends the blocking started by [[#BeginBlockingHomeButtonShortAndLongPressed]].&lt;br /&gt;
&lt;br /&gt;
==== BeginBlockingHomeButton ====&lt;br /&gt;
Takes an input s64 nanoseconds, no output. The input nanoseconds can be zero.&lt;br /&gt;
&lt;br /&gt;
==== EndBlockingHomeButton ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== SelectApplicationLicense ====&lt;br /&gt;
Takes an input array of [[#ApplicationLicenseType]], returns an output [[#ApplicationLicenseType]].&lt;br /&gt;
&lt;br /&gt;
==== GetDeviceSaveDataSizeMax ====&lt;br /&gt;
No input, returns two output s64s.&lt;br /&gt;
&lt;br /&gt;
==== NotifyRunning ====&lt;br /&gt;
Takes no input. Returns an output u8 bool, which is ignored by official user-processes.&lt;br /&gt;
&lt;br /&gt;
==== GetPseudoDeviceId ====&lt;br /&gt;
No input, returns an output 0x10-byte &amp;quot;nn::util::Uuid&amp;quot; struct.&lt;br /&gt;
&lt;br /&gt;
The 0x20-byte output data from [[NS_Services|GetSystemSeedForPseudoDeviceId]] followed by the 8-byte [[NACP_Format|SeedForPseudoDeviceId]] from the current control.nacp, is hashed with SHA1. Then &amp;quot;nn::util::GenerateUuidVersion5&amp;quot; is called with the final hash, the output from this is then returned for the Uuid.&lt;br /&gt;
&lt;br /&gt;
==== SetMediaPlaybackStateForApplication ====&lt;br /&gt;
Takes an input u8 bool, no output.&lt;br /&gt;
&lt;br /&gt;
==== IsGamePlayRecordingSupported ====&lt;br /&gt;
No input, returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
==== InitializeGamePlayRecording ====&lt;br /&gt;
Takes a TransferMemory handle and an u64 for the size of the TransferMemory. The size must match 0x6000000 otherwise an error is returned.&lt;br /&gt;
&lt;br /&gt;
==== SetGamePlayRecordingState ====&lt;br /&gt;
Takes an input u32. 0 = disable/pause, 1 = enable/restart.&lt;br /&gt;
&lt;br /&gt;
==== RequestFlushGamePlayingMovieForDebug ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Requests to save the video recording, as if the Capture-button was held.&lt;br /&gt;
&lt;br /&gt;
==== RequestToShutdown ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
On success, official sw will enter an infinite loop with sleep-thread value 86400000000000.&lt;br /&gt;
&lt;br /&gt;
==== RequestToReboot ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
On success, official sw will enter an infinite loop with sleep-thread value 86400000000000.&lt;br /&gt;
&lt;br /&gt;
==== RequestToSleep ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
==== ExitAndRequestToShowThanksMessage ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Used to exit the application and return to the kiosk menu. Official sw uses [[#UnlockExit]] immediately before this if needed.&lt;br /&gt;
&lt;br /&gt;
On success, official sw will enter an infinite loop with sleep-thread value 86400000000000.&lt;br /&gt;
&lt;br /&gt;
This throws an error when the cached [[Settings_services#GetQuestFlag]] value is 0.&lt;br /&gt;
&lt;br /&gt;
==== EnableApplicationCrashReport ====&lt;br /&gt;
Takes an input u8 bool, no output.&lt;br /&gt;
&lt;br /&gt;
==== InitializeApplicationCopyrightFrameBuffer ====&lt;br /&gt;
Takes an input TransferMemory handle, an s32 &#039;&#039;&#039;width&#039;&#039;&#039;, an s32 &#039;&#039;&#039;height&#039;&#039;&#039;, an u64 tmem_size, and no output.&lt;br /&gt;
&lt;br /&gt;
tmem_size must be 0x40000-byte aligned. &#039;&#039;&#039;width&#039;&#039;&#039; must be 1-1280, and &#039;&#039;&#039;height&#039;&#039;&#039; must be 1-720.&lt;br /&gt;
&lt;br /&gt;
User-processes create the tmem with an user-specified buffer with permissions=0. &#039;&#039;&#039;width&#039;&#039;&#039; = 1280 and &#039;&#039;&#039;height&#039;&#039;&#039; = 720.&lt;br /&gt;
&lt;br /&gt;
After the validation checks pass the input is passed to [[OMM_services|ommdisp]] cmd500.&lt;br /&gt;
&lt;br /&gt;
This is used as an overlay for screenshots.&lt;br /&gt;
&lt;br /&gt;
==== SetApplicationCopyrightImage ====&lt;br /&gt;
Takes a type-0x45 input buffer, an s32 &#039;&#039;&#039;x&#039;&#039;&#039;, an s32 &#039;&#039;&#039;y&#039;&#039;&#039;, an s32 &#039;&#039;&#039;width&#039;&#039;&#039;, an s32 &#039;&#039;&#039;height&#039;&#039;&#039;, an s32 [[#WindowOriginMode]], and no output.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;x&#039;&#039;&#039; and &#039;&#039;&#039;y&#039;&#039;&#039; must not have the negative bit set. &#039;&#039;&#039;width&#039;&#039;&#039; and &#039;&#039;&#039;height&#039;&#039;&#039; must not be &amp;lt;1.&lt;br /&gt;
&lt;br /&gt;
Sets the RGBA8 image for use with [[#InitializeApplicationCopyrightFrameBuffer]]. Overrides the current image, if this was already used previously.&lt;br /&gt;
&lt;br /&gt;
==== SetApplicationCopyrightVisibility ====&lt;br /&gt;
Takes an input u8 bool, no output.&lt;br /&gt;
&lt;br /&gt;
Sets the visibility for the image set by [[#SetApplicationCopyrightImage]], in screenshots. By default it&#039;s visible.&lt;br /&gt;
&lt;br /&gt;
==== QueryApplicationPlayStatistics ====&lt;br /&gt;
Takes a type-0x6 output buffer containing an array of [[Shared_Database_services|ApplicationPlayStatistics]] and a type-0x5 input buffer containing an array of [[NCM_services#ApplicationId|ApplicationId]]. Returns an output s32 for actual total output entries.&lt;br /&gt;
&lt;br /&gt;
The number of entries in each array is the same.&lt;br /&gt;
&lt;br /&gt;
See also [[NACP_Format#PlayLogQueryCapability|PlayLogQueryCapability]].&lt;br /&gt;
&lt;br /&gt;
This uses [[Shared_Database_services|pdm:qry]] QueryApplicationPlayStatisticsForSystem.&lt;br /&gt;
&lt;br /&gt;
==== QueryApplicationPlayStatisticsByUid ====&lt;br /&gt;
Takes a u128 userID, a type-0x6 output buffer containing an array of [[Shared_Database_services|ApplicationPlayStatistics]] and a type-0x5 input buffer containing an array of [[NCM_services#ApplicationId|ApplicationId]]. Returns an output s32 for actual total output entries.&lt;br /&gt;
&lt;br /&gt;
Same as [[#QueryApplicationPlayStatistics]] except this uses [[Shared_Database_services|pdm:qry]] cmd16, to get playstats specific to userIDs. &lt;br /&gt;
&lt;br /&gt;
==== ExecuteProgram ====&lt;br /&gt;
Takes an input u32 [[#ProgramSpecifyKind]] and an input u64, no output.&lt;br /&gt;
&lt;br /&gt;
==== ClearUserChannel ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Clears the UserChannel used by [[#UnpopToUserChannel]].&lt;br /&gt;
&lt;br /&gt;
==== UnpopToUserChannel ====&lt;br /&gt;
Takes an input [[#IStorage]], no output.&lt;br /&gt;
&lt;br /&gt;
The input storage is pushed to the UserChannel. This is the same channel used by [[#LaunchParameterKind]] value 1.&lt;br /&gt;
&lt;br /&gt;
User-processes create a storage using data specified by the user (written to offset=0 size=inputsize), with max size 0x1000. This storage is then used with this cmd.&lt;br /&gt;
&lt;br /&gt;
==== GetPreviousProgramIndex ====&lt;br /&gt;
No input, returns an output s32.&lt;br /&gt;
&lt;br /&gt;
Gets the ProgramIndex of the Application which launched this title. The output ProgramIndex is -1 when there was no previous title.&lt;br /&gt;
&lt;br /&gt;
==== EnableApplicationAllThreadDumpOnCrash ====&lt;br /&gt;
Takes an input u8 bool, no output.&lt;br /&gt;
&lt;br /&gt;
==== GetGpuErrorDetectedSystemEvent ====&lt;br /&gt;
No input, returns an output Event handle with autoclear=false.&lt;br /&gt;
&lt;br /&gt;
This is used by sdknso during applet-application initialization. A separate thread is setup where event-waiting is handled. When the Event is signaled, official sw will Abort.&lt;br /&gt;
&lt;br /&gt;
==== SetDelayTimeToAbortOnGpuError ====&lt;br /&gt;
Takes an input s64 &amp;quot;nn::TimeSpan&amp;quot;, no output.&lt;br /&gt;
&lt;br /&gt;
==== GetFriendInvitationStorageChannelEvent ====&lt;br /&gt;
No input, returns an output Event handle with EventClearMode=0.&lt;br /&gt;
&lt;br /&gt;
This is exposed by sdknso under &amp;lt;code&amp;gt;nn::friends::&amp;lt;/code&amp;gt;. This returns a ptr to the cached Event in global state, with the Event being loaded if not previously initialized.&lt;br /&gt;
&lt;br /&gt;
==== TryPopFromFriendInvitationStorageChannel ====&lt;br /&gt;
No input, returns an output [[#IStorage]].&lt;br /&gt;
&lt;br /&gt;
This uses the same StorageChannel as [[#PushToFriendInvitationStorageChannel]].&lt;br /&gt;
&lt;br /&gt;
This is exposed by sdknso under &amp;lt;code&amp;gt;nn::friends::&amp;lt;/code&amp;gt;. When the storage_size is &amp;lt;0x10, this returns false. &amp;lt;code&amp;gt;data_size = storage_size-0x10;&amp;lt;/code&amp;gt; Then the first 0x10-bytes from storage are read to stack, which is later copied to the output Uid on success prior to returning. Then the storage is read into the specified output buffer with storage-offset 0x10, where the size is &amp;lt;code&amp;gt;size = data_size &amp;gt; buf_size ? buf_size : data_size&amp;lt;/code&amp;gt;. Reading is skipped if size is zero. Afterwards the used size is written to an output param. On success, true is returned.&lt;br /&gt;
&lt;br /&gt;
==== GetNotificationStorageChannelEvent ====&lt;br /&gt;
No input, returns an output Event handle with EventClearMode=0.&lt;br /&gt;
&lt;br /&gt;
This is exposed by sdknso under &amp;lt;code&amp;gt;nn::notification::&amp;lt;/code&amp;gt;. This returns a ptr to the cached Event in global state, with the Event being loaded if not previously initialized.&lt;br /&gt;
&lt;br /&gt;
==== TryPopFromNotificationStorageChannel ====&lt;br /&gt;
No input, returns an output [[#IStorage]].&lt;br /&gt;
&lt;br /&gt;
This uses the same StorageChannel as [[#PushToNotificationStorageChannel]].&lt;br /&gt;
&lt;br /&gt;
This is exposed by sdknso under &amp;lt;code&amp;gt;nn::notification::&amp;lt;/code&amp;gt;. The storage is read into the specified output buffer, where the size is &amp;lt;code&amp;gt;size = storage_size &amp;gt; buf_size ? buf_size : storage_size&amp;lt;/code&amp;gt;. Reading is skipped if size is zero. Afterwards the used size is written to an output param.&lt;br /&gt;
&lt;br /&gt;
==== GetHealthWarningDisappearedSystemEvent ====&lt;br /&gt;
No input, returns an output Event with EventClearMode=0.&lt;br /&gt;
&lt;br /&gt;
==== SetHdcpAuthenticationActivated ====&lt;br /&gt;
Takes an input u8 bool, no output.&lt;br /&gt;
&lt;br /&gt;
==== GetLaunchRequiredVersion ====&lt;br /&gt;
Takes an input [[NCM_services#ApplicationId|ApplicationId]], an u64, returns an output [[#LaunchRequiredVersion]].&lt;br /&gt;
&lt;br /&gt;
sdknso passes hard-coded value 0 for the u64.&lt;br /&gt;
&lt;br /&gt;
==== UpgradeLaunchRequiredVersion ====&lt;br /&gt;
Takes an input [[#LaunchRequiredVersion]], an [[NCM_services#ApplicationId|ApplicationId]], an u64, no output.&lt;br /&gt;
&lt;br /&gt;
sdknso passes hard-coded value 0 for the u64.&lt;br /&gt;
&lt;br /&gt;
==== SendServerMaintenanceOverlayNotification ====&lt;br /&gt;
Takes two input [[PCV_services#PosixTime|PosixTime]], no output.&lt;br /&gt;
&lt;br /&gt;
The second input value can optionally be 0.&lt;br /&gt;
&lt;br /&gt;
==== GetLastApplicationExitReason ====&lt;br /&gt;
No input, returns an output s32.&lt;br /&gt;
&lt;br /&gt;
==== Cmd210 ====&lt;br /&gt;
No input, returns an output Event handle.&lt;br /&gt;
&lt;br /&gt;
==== SetAudioOutputPolicy ====&lt;br /&gt;
Takes an input u8, no output.&lt;br /&gt;
&lt;br /&gt;
The input must be &amp;lt;=1.&lt;br /&gt;
&lt;br /&gt;
==== CreateMovieWriter ====&lt;br /&gt;
Takes 8-bytes of input and a handle. Returns an [[#IMovieWriter]].&lt;br /&gt;
&lt;br /&gt;
This internally uses the GRC cmd to open an [[GRC_services|IMovieWriter]]. This is therefore not usable on NX since that cmd is stubbed.&lt;br /&gt;
&lt;br /&gt;
==== RequestExitApplicationAndTryPopMessage ====&lt;br /&gt;
Takes an input [[#IStorage|IStorage]], no output.&lt;br /&gt;
&lt;br /&gt;
[21.0.0+] Now additionally takes a total of 0x18-bytes of input.&lt;br /&gt;
&lt;br /&gt;
==== IsLanguageSelectionLimited ====&lt;br /&gt;
No input, returns 1-byte of output.&lt;br /&gt;
&lt;br /&gt;
On NX this just writes 0 to output and returns 0.&lt;br /&gt;
&lt;br /&gt;
==== StartContinuousRecordingFlushForDebug ====&lt;br /&gt;
Takes an input s64 nanoseconds-value, returns an output Event handle with autoclear=false.&lt;br /&gt;
&lt;br /&gt;
The cached value loaded from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;am.debug!dev_function&amp;lt;/code&amp;gt; must be set to 0x1 with size 0x1, otherwise an error is returned.&lt;br /&gt;
&lt;br /&gt;
==== CreateMovieMaker ====&lt;br /&gt;
Takes an input u64 size and a TransferMemory handle, returns an [[#IMovieMaker]].&lt;br /&gt;
&lt;br /&gt;
Official sw retries using the cmd in a loop on error 0x8D4 with svcSleepThread(100000000) being used first.&lt;br /&gt;
&lt;br /&gt;
Official sw uses permissions=None for the TransferMemory, with an user-specified buffer. The size of the buffer used by official sw is 0x6000000.&lt;br /&gt;
&lt;br /&gt;
==== PrepareForJit ====&lt;br /&gt;
Takes no input. Launches the [[JIT_services|jit-sysmodule]] via [[NS_Services|ns]] LaunchLibraryApplet if it has not already been launched for the current application, storing a std::shared_ptr&amp;lt;&amp;gt; for jit-sysmodule process tracking object as an IApplicationFunctions member.&lt;br /&gt;
&lt;br /&gt;
~IApplicationFunctions() includes:&lt;br /&gt;
&lt;br /&gt;
    if (this-&amp;gt;jit_process) {&lt;br /&gt;
        Terminate(this-&amp;gt;jit_process);&lt;br /&gt;
        this-&amp;gt;jit_process = nullptr;&lt;br /&gt;
    }&lt;br /&gt;
&lt;br /&gt;
Thus the lifetime of the jit sysmodule is tied to the application which uses it, and each application gets its own fresh copy of the jit sysmodule.&lt;br /&gt;
&lt;br /&gt;
AM can also optionally launch jit-sysmodule automatically if the [[NACP]] enables it.&lt;br /&gt;
&lt;br /&gt;
[S2] This is no longer usable since this returns Result 0x408 (sysmodule doesn&#039;t exist).&lt;br /&gt;
&lt;br /&gt;
=== IMovieWriter ===&lt;br /&gt;
This is &amp;quot;nn::am::service::IMovieWriter&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [19.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Cmd0 ====&lt;br /&gt;
No input. Returns a GRC [[GRC_services|IMovieWriter]].&lt;br /&gt;
&lt;br /&gt;
=== IMovieMaker ===&lt;br /&gt;
This is &amp;quot;nn::am::service::IMovieMaker&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#GetGrcMovieMaker]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#GetLayerHandle]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== GetGrcMovieMaker ====&lt;br /&gt;
No input, returns a GRC [[GRC_services|IMovieMaker]].&lt;br /&gt;
&lt;br /&gt;
==== GetLayerHandle ====&lt;br /&gt;
No input, returns an output u64.&lt;br /&gt;
&lt;br /&gt;
=== IPerformanceFunctions ===&lt;br /&gt;
This is &amp;quot;nn::am::service::IPerformanceFunctions&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This is exclusive to Switch 2.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || IsCpuOverclockEnabled&lt;br /&gt;
|-&lt;br /&gt;
| 1 || SetCpuOverclockEnabled&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IGraphicsScalingParametersFunctions ===&lt;br /&gt;
This is &amp;quot;nn::am::service::IGraphicsScalingParametersFunctions&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This is exclusive to Switch 2.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 10 || GetGraphicsScalingParameters&lt;br /&gt;
|-&lt;br /&gt;
| 1000 || SetSupportingGraphicsScalingParametersForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 1010 || SetGpuQuotaForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 1020 || ClearGpuQuotaForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 1030 || SetScreenRatioForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 1040 || ClearScreenRatioForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 1050 || SetGraphicsScaleChangedNotificationEnabled&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== ILibraryAppletCreator ==&lt;br /&gt;
This is &amp;quot;nn::am::service::ILibraryAppletCreator&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#CreateLibraryAppletOld|CreateLibraryAppletOld]] ([1.0.0-19.0.1] CreateLibraryApplet) || &lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#TerminateAllLibraryApplets]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [[#AreAnyLibraryAppletsLeft]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [20.0.0+] [[#CreateLibraryApplet|CreateLibraryApplet]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [[#CreateStorage]] || &lt;br /&gt;
|-&lt;br /&gt;
| 11 || [[#CreateTransferMemoryStorage]] || &lt;br /&gt;
|-&lt;br /&gt;
| 12 || [2.0.0+] [[#CreateHandleStorage]] || &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CreateLibraryAppletOld ===&lt;br /&gt;
Unofficial name.&lt;br /&gt;
&lt;br /&gt;
Takes 2 input u32s [[#AppletId]] and [[#LibraryAppletMode]], returns an [[#ILibraryAppletAccessor]].&lt;br /&gt;
&lt;br /&gt;
=== TerminateAllLibraryApplets ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Stubbed with an ILibraryAppletCreator from [[#CreateSelfLibraryAppletCreatorForDevelop]], just returns an error.&lt;br /&gt;
&lt;br /&gt;
Terminates all LibraryApplets which were created by the current applet (or by the Application when used from the [[#IApplicationAccessor]] cmd).&lt;br /&gt;
&lt;br /&gt;
=== AreAnyLibraryAppletsLeft ===&lt;br /&gt;
No input, returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
Stubbed with an ILibraryAppletCreator from [[#CreateSelfLibraryAppletCreatorForDevelop]], just returns an error.&lt;br /&gt;
&lt;br /&gt;
Gets whether any LibraryApplets ([[#ILibraryAppletAccessor]]) which were created by the current applet are still open (or by the Application when used from the [[#IApplicationAccessor]] cmd).&lt;br /&gt;
&lt;br /&gt;
=== CreateLibraryApplet ===&lt;br /&gt;
Unofficial name.&lt;br /&gt;
&lt;br /&gt;
Takes 2 input u32s [[#AppletId]] and [[#LibraryAppletMode]], an u64 ThreadId, returns an [[#ILibraryAppletAccessor]].&lt;br /&gt;
&lt;br /&gt;
The ThreadId is from the current-thread of the user-process which is using the cmd.&lt;br /&gt;
&lt;br /&gt;
=== CreateStorage ===&lt;br /&gt;
Takes an input s64 for the storage size, returns an [[#IStorage]].&lt;br /&gt;
&lt;br /&gt;
This allocates a buffer with the specified size which can then be accessed via [[#IStorageAccessor]].&lt;br /&gt;
&lt;br /&gt;
=== CreateTransferMemoryStorage ===&lt;br /&gt;
Takes an input TransferMemory copy-handle, an input u8 bool, and an s64 size, returns an [[#IStorage]].&lt;br /&gt;
&lt;br /&gt;
The user-process creates the TransferMemory with permissions=0.&lt;br /&gt;
&lt;br /&gt;
The TransferMemory is mapped, which can then be accessed via [[#IStorageAccessor]]. The input bool controls whether writing to the storage is allowed: [[#Write]] will throw an error if this flag is not set.&lt;br /&gt;
&lt;br /&gt;
=== CreateHandleStorage ===&lt;br /&gt;
Takes an input copy-handle and an input s64, returns an [[#IStorage]]. In some cases the s64 must not have the negative bit set.&lt;br /&gt;
&lt;br /&gt;
The input can be arbitrary, however official sw is only (?) known to use this for TransferMemory (with s64=size).&lt;br /&gt;
&lt;br /&gt;
=== ILibraryAppletAccessor ===&lt;br /&gt;
This is &amp;quot;nn::am::service::ILibraryAppletAccessor&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#GetAppletStateChangedEvent]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#IsCompleted]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [[#Start]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 20 || [[#RequestExit]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 25 || [[#Terminate]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 30 || [[#GetResult]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 50 || [[#SetOutOfFocusApplicationSuspendingEnabled]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 60 || [10.0.0+] [[#PresetLibraryAppletGpuTimeSliceZero]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 70 || [S2] || &lt;br /&gt;
|-&lt;br /&gt;
| 80 || [19.0.0+] RequestForLibraryAppletToGetForeground ||&lt;br /&gt;
|-&lt;br /&gt;
| 81 || [19.0.0+] GetCurrentChildLibraryApplet ||&lt;br /&gt;
|-&lt;br /&gt;
| 90 || [20.0.0+] ||&lt;br /&gt;
|-&lt;br /&gt;
| 100 || [[#PushInData]] || &lt;br /&gt;
|-&lt;br /&gt;
| 101 || [[#PopOutData]] || &lt;br /&gt;
|-&lt;br /&gt;
| 102 || [[#PushExtraStorage]] || &lt;br /&gt;
|-&lt;br /&gt;
| 103 || [[#PushInteractiveInData]] || &lt;br /&gt;
|-&lt;br /&gt;
| 104 || [[#PopInteractiveOutData]] || &lt;br /&gt;
|-&lt;br /&gt;
| 105 || [[#GetPopOutDataEvent]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 106 || [[#GetPopInteractiveOutDataEvent]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 110 || [[#NeedsToExitProcess]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 120 || [[#GetLibraryAppletInfo]] || &lt;br /&gt;
|-&lt;br /&gt;
| 150 || [[#RequestForAppletToGetForeground]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 160 || [2.0.0+] [[#GetIndirectLayerConsumerHandle]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 170 || [22.0.0+]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Commands &amp;lt;=30 are inherited from [[#IAppletAccessor]]. GetLibraryAppletInfo is identical to the [[#ILibraryAppletSelfAccessor]] cmd.&lt;br /&gt;
&lt;br /&gt;
==== SetOutOfFocusApplicationSuspendingEnabled ====&lt;br /&gt;
Takes an input u8 bool, no output.&lt;br /&gt;
&lt;br /&gt;
Official sw will assert prior to using this if applet-service was not initialized as *Application.&lt;br /&gt;
&lt;br /&gt;
==== PresetLibraryAppletGpuTimeSliceZero ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
sdknso only uses with with [[Software_Keyboard|swkbd-inline]], immediately after creating the LibraryApplet.&lt;br /&gt;
&lt;br /&gt;
==== PushInData ====&lt;br /&gt;
Takes an input [[#IStorage]], no output.&lt;br /&gt;
&lt;br /&gt;
==== PopOutData ====&lt;br /&gt;
No input, returns an output [[#IStorage]].&lt;br /&gt;
&lt;br /&gt;
==== PushExtraStorage ====&lt;br /&gt;
Takes an input [[#IStorage]], no output.&lt;br /&gt;
&lt;br /&gt;
==== PushInteractiveInData ====&lt;br /&gt;
Takes an input [[#IStorage]], no output.&lt;br /&gt;
&lt;br /&gt;
==== PopInteractiveOutData ====&lt;br /&gt;
No input, returns an output [[#IStorage]].&lt;br /&gt;
&lt;br /&gt;
==== GetPopOutDataEvent ====&lt;br /&gt;
No input, returns an output handle with autoclear=false.&lt;br /&gt;
&lt;br /&gt;
==== GetPopInteractiveOutDataEvent ====&lt;br /&gt;
No input, returns an output event handle with autoclear=false.&lt;br /&gt;
&lt;br /&gt;
==== NeedsToExitProcess ====&lt;br /&gt;
No input, returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
Stubbed, just returns an error.&lt;br /&gt;
&lt;br /&gt;
==== RequestForAppletToGetForeground ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Stubbed, just returns an error.&lt;br /&gt;
&lt;br /&gt;
==== GetIndirectLayerConsumerHandle ====&lt;br /&gt;
Takes an input PID and an input u64 AppletResourceUserId, returns an output u64 IndirectLayerConsumerHandle.&lt;br /&gt;
&lt;br /&gt;
Official sw uses this during LibraryApplet creation when [[#LibraryAppletMode]] is 0x3.&lt;br /&gt;
&lt;br /&gt;
== ICommonStateGetter ==&lt;br /&gt;
This is &amp;quot;nn::am::service::ICommonStateGetter&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#GetEventHandle]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#ReceiveMessage]]&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [[#GetThisAppletKind]]&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [[#AllowToEnterSleep]]&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [[#DisallowToEnterSleep]]&lt;br /&gt;
|-&lt;br /&gt;
| 5 || [[#GetOperationMode]]&lt;br /&gt;
|-&lt;br /&gt;
| 6 || [[#GetPerformanceMode]]&lt;br /&gt;
|-&lt;br /&gt;
| 7 || [[#GetCradleStatus]]&lt;br /&gt;
|-&lt;br /&gt;
| 8 || [[#GetBootMode]]&lt;br /&gt;
|-&lt;br /&gt;
| 9 || [[#GetCurrentFocusState]]&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [[#RequestToAcquireSleepLock]]&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [[#ReleaseSleepLock]]&lt;br /&gt;
|-&lt;br /&gt;
| 12 || [[#ReleaseSleepLockTransiently]]&lt;br /&gt;
|-&lt;br /&gt;
| 13 || [[#GetAcquiredSleepLockEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 14 || [11.0.0+] [[#GetWakeupCount]]&lt;br /&gt;
|-&lt;br /&gt;
| 15 || [19.0.0+] &lt;br /&gt;
|-&lt;br /&gt;
| 20 || [[#PushToGeneralChannel]]&lt;br /&gt;
|-&lt;br /&gt;
| 30 || [[#GetHomeButtonReaderLockAccessor]]&lt;br /&gt;
|-&lt;br /&gt;
| 31 || [2.0.0+] [[#GetReaderLockAccessorEx]]&lt;br /&gt;
|-&lt;br /&gt;
| 32 || [7.0.0+] [[#GetWriterLockAccessorEx]]&lt;br /&gt;
|-&lt;br /&gt;
| 40 || [2.0.0+] [[#GetCradleFwVersion]]&lt;br /&gt;
|-&lt;br /&gt;
| 50 || [3.0.0+] [[#IsVrModeEnabled]]&lt;br /&gt;
|-&lt;br /&gt;
| 51 || [3.0.0+] [[#SetVrModeEnabled]]&lt;br /&gt;
|-&lt;br /&gt;
| 52 || [4.0.0+] [[#SetLcdBacklighOffEnabled]]&lt;br /&gt;
|-&lt;br /&gt;
| 53 || [7.0.0+] [[#BeginVrModeEx]]&lt;br /&gt;
|-&lt;br /&gt;
| 54 || [7.0.0+] [[#EndVrModeEx]]&lt;br /&gt;
|-&lt;br /&gt;
| 55 || [3.0.0+] [[#IsInControllerFirmwareUpdateSection]]&lt;br /&gt;
|-&lt;br /&gt;
| 59 || [11.0.0+] [[#SetVrPositionForDebug]]&lt;br /&gt;
|-&lt;br /&gt;
| 60 || [3.0.0+] [[#GetDefaultDisplayResolution]]&lt;br /&gt;
|-&lt;br /&gt;
| 61 || [3.0.0+] [[#GetDefaultDisplayResolutionChangeEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 62 || [4.0.0+] [[#GetHdcpAuthenticationState]]&lt;br /&gt;
|-&lt;br /&gt;
| 63 || [4.0.0+] [[#GetHdcpAuthenticationStateChangeEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 64 || [5.0.0+] [[#SetTvPowerStateMatchingMode]]&lt;br /&gt;
|-&lt;br /&gt;
| 65 || [5.1.0+] [[#GetApplicationIdByContentActionName]]&lt;br /&gt;
|-&lt;br /&gt;
| 66 || [6.0.0+] [[#SetCpuBoostMode]]&lt;br /&gt;
|-&lt;br /&gt;
| 67 || [10.0.0+] [[#CancelCpuBoostMode]]&lt;br /&gt;
|-&lt;br /&gt;
| 68 || [11.0.0+] [[#GetBuiltInDisplayType]]&lt;br /&gt;
|-&lt;br /&gt;
| 80 || [6.0.0+] [[#PerformSystemButtonPressingIfInFocus]]&lt;br /&gt;
|-&lt;br /&gt;
| 90 || [7.0.0+] [[#SetPerformanceConfigurationChangedNotification]]&lt;br /&gt;
|-&lt;br /&gt;
| 91 || [7.0.0+] [[#GetCurrentPerformanceConfiguration]]&lt;br /&gt;
|-&lt;br /&gt;
| 100 || [9.1.0+] [[#SetHandlingHomeButtonShortPressedEnabled]]&lt;br /&gt;
|-&lt;br /&gt;
| 110 || [11.0.0+] [[#OpenMyGpuErrorHandler]]&lt;br /&gt;
|-&lt;br /&gt;
| 120 || [13.0.0+] GetAppletLaunchedHistory&lt;br /&gt;
|-&lt;br /&gt;
| 130 || [21.0.0+] EnableStartupLogoDisappearedMessage&lt;br /&gt;
|-&lt;br /&gt;
| 200 || [7.0.0+] [[#GetOperationModeSystemInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 300 || [9.0.0+] [[#GetSettingsPlatformRegion]]&lt;br /&gt;
|-&lt;br /&gt;
| 400 || [10.0.0+] [[#ActivateMigrationService]]&lt;br /&gt;
|-&lt;br /&gt;
| 401 || [10.0.0+] [[#DeactivateMigrationService]]&lt;br /&gt;
|-&lt;br /&gt;
| 500 || [11.0.0+] [[#DisableSleepTillShutdown]]&lt;br /&gt;
|-&lt;br /&gt;
| 501 || [11.0.0+] [[#SuppressDisablingSleepTemporarily]]&lt;br /&gt;
|-&lt;br /&gt;
| 502 || [12.0.0+] IsSleepEnabled&lt;br /&gt;
|-&lt;br /&gt;
| 503 || [12.0.0+] IsDisablingSleepSuppressed&lt;br /&gt;
|-&lt;br /&gt;
| 600 || [20.0.0+] SetHidInputMagnificationForApplication ([17.0.0-18.1.0] OpenNamedChannelAsChild)&lt;br /&gt;
|-&lt;br /&gt;
| 610 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 611 || [22.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 650 || [S2] BeginUsingCameraResource&lt;br /&gt;
|-&lt;br /&gt;
| 651 || [S2] EndUsingCameraResource&lt;br /&gt;
|-&lt;br /&gt;
| 900 || [11.0.0+] [[#SetRequestExitToLibraryAppletAtExecuteNextProgramEnabled]]&lt;br /&gt;
|-&lt;br /&gt;
| 910 || [17.0.0+] GetLaunchRequiredTick&lt;br /&gt;
|-&lt;br /&gt;
| 1000 || [19.0.0+] BeginVrMode3d&lt;br /&gt;
|-&lt;br /&gt;
| 1001 || [19.0.0+] EndVrMode3d&lt;br /&gt;
|-&lt;br /&gt;
| 1002 || [19.0.0+] IsVrModeEnabled3d&lt;br /&gt;
|-&lt;br /&gt;
| 1003 || [21.0.0+] GetVrLaboGoggleViewport&lt;br /&gt;
|-&lt;br /&gt;
| 1004 || [21.0.0+] GetPanelPhysicalSizeForSpecificTitle&lt;br /&gt;
|-&lt;br /&gt;
| 1005 || [21.0.0+] GetPanelResolutionForSpecificTitle&lt;br /&gt;
|-&lt;br /&gt;
| 2000 || [S2] SetRtcModeChangedMessageEnabled&lt;br /&gt;
|-&lt;br /&gt;
| 2010 || [S2] GetCurrentDisplayLayoutRatio&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Officially notification messages are handled by the application itself, not sdk-nso in ExeFS. Official apps call code in sdk-nso which basically uses svcWaitSynchronization with the event from [[#GetEventHandle]] to check whether a message is available, then if so it uses [[#ReceiveMessage]]. The actual handling for message IDs is done in the app itself(see [[#AppletMessage]]).&lt;br /&gt;
&lt;br /&gt;
[7.0.0+] User-processes now use BeginVrModeEx/EndVrModeEx instead of [[#SetVrModeEnabled]]. Prior to using using BeginVrModeEx, [[Parental_Control_services|pctl]] IsStereoVisionPermitted is used and error 0xD08E is thrown if not allowed by pctl.&lt;br /&gt;
&lt;br /&gt;
=== GetEventHandle ===&lt;br /&gt;
No input. Returns an output event handle. This is signalled when a message is available with [[#ReceiveMessage]].&lt;br /&gt;
&lt;br /&gt;
=== ReceiveMessage ===&lt;br /&gt;
No input. Returns an output [[#AppletMessage]]. Error 0x680 indicates no message is available.&lt;br /&gt;
&lt;br /&gt;
=== GetThisAppletKind ===&lt;br /&gt;
No input, returns an output [[#AppletKind]].&lt;br /&gt;
&lt;br /&gt;
Stubbed, just returns an error.&lt;br /&gt;
&lt;br /&gt;
=== AllowToEnterSleep ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Stubbed, just returns an error.&lt;br /&gt;
&lt;br /&gt;
=== DisallowToEnterSleep ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Stubbed, just returns an error.&lt;br /&gt;
&lt;br /&gt;
=== GetOperationMode ===&lt;br /&gt;
No input. Returns an output u8 for the current [[#OperationMode]].&lt;br /&gt;
&lt;br /&gt;
=== GetPerformanceMode ===&lt;br /&gt;
No input. Returns an output u32 for the current [[#PerformanceMode]].&lt;br /&gt;
&lt;br /&gt;
=== GetCradleStatus ===&lt;br /&gt;
No input, returns an output u8.&lt;br /&gt;
&lt;br /&gt;
This uses [[#omm]] GetCradleStatus.&lt;br /&gt;
&lt;br /&gt;
=== GetBootMode ===&lt;br /&gt;
No input, returns an output u8.&lt;br /&gt;
&lt;br /&gt;
Returns the value from [[Process_Manager_services|pm:bm]] GetBootMode.&lt;br /&gt;
&lt;br /&gt;
=== GetCurrentFocusState ===&lt;br /&gt;
No input. Returns an output u8 [[#FocusState]].&lt;br /&gt;
&lt;br /&gt;
=== RequestToAcquireSleepLock ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
=== ReleaseSleepLock ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
=== ReleaseSleepLockTransiently ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
=== GetAcquiredSleepLockEvent ===&lt;br /&gt;
No input, returns an output Event handle with autoclear=false.&lt;br /&gt;
&lt;br /&gt;
=== GetWakeupCount ===&lt;br /&gt;
No input, returns an output u64.&lt;br /&gt;
&lt;br /&gt;
=== PushToGeneralChannel ===&lt;br /&gt;
Takes an input [[#IStorage]], no output.&lt;br /&gt;
&lt;br /&gt;
This is not usable under an Application, however it is usable under a LibraryApplet.&lt;br /&gt;
&lt;br /&gt;
Used for sending requests to [[qlaunch]]. sdk-nso creates a 0x10-byte storage which is sent to this. The following are the functions which use this, with the data written to the storage:&lt;br /&gt;
* &amp;lt;code&amp;gt;RequestHomeMenu&amp;lt;/code&amp;gt; &amp;lt;code&amp;gt;5341 4d53 0100 0000 0200 0000 0100 0000&amp;lt;/code&amp;gt; Returns to the main Home Menu, equivalent to pressing the HOME button.&lt;br /&gt;
* &amp;lt;code&amp;gt;RequestJumpToSystemUpdate&amp;lt;/code&amp;gt; &amp;lt;code&amp;gt;5341 4d53 0100 0000 0b00 0000 0100 0000&amp;lt;/code&amp;gt; Equivalent to entering &amp;quot;System Update&amp;quot; under System Settings. When leaving this, it returns to the main Home Menu.&lt;br /&gt;
&lt;br /&gt;
=== GetHomeButtonReaderLockAccessor ===&lt;br /&gt;
No input, returns an output [[#ILockAccessor]].&lt;br /&gt;
&lt;br /&gt;
Similar to using [[#GetReaderLockAccessorEx]] with inval=0.&lt;br /&gt;
&lt;br /&gt;
=== GetReaderLockAccessorEx ===&lt;br /&gt;
Takes an input u32, returns an output [[#ILockAccessor]].&lt;br /&gt;
&lt;br /&gt;
The input value must be 0-3. 0 = HomeButton.&lt;br /&gt;
&lt;br /&gt;
=== GetWriterLockAccessorEx ===&lt;br /&gt;
Takes an input u32, returns an output [[#ILockAccessor]].&lt;br /&gt;
&lt;br /&gt;
The input value must be 0-3. 0 = HomeButton.&lt;br /&gt;
&lt;br /&gt;
=== GetCradleFwVersion ===&lt;br /&gt;
No input, returns 4 output u32s.&lt;br /&gt;
&lt;br /&gt;
This uses [[#omm]] GetCradleFwVersion.&lt;br /&gt;
&lt;br /&gt;
=== IsVrModeEnabled ===&lt;br /&gt;
No input, returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
=== SetVrModeEnabled ===&lt;br /&gt;
Takes an input u8 bool flag. No output.&lt;br /&gt;
&lt;br /&gt;
Updates internal AM state fields. If the new state doesn&#039;t match the previous state, this uses the [[Backlight_services]] {Disable/Enable}VrMode command depending on whether flag={disable/enable}.&lt;br /&gt;
&lt;br /&gt;
When the VrMode is set to true, the console shows a screen rendered like vr asking the user to move his face away and hit the &#039;close&#039; button. When this button is pressed, the console resets the vrMode to false.&lt;br /&gt;
&lt;br /&gt;
=== SetLcdBacklighOffEnabled ===&lt;br /&gt;
Takes an input u8 bool, no output.&lt;br /&gt;
&lt;br /&gt;
Sets whether the LCD screen blacklight is turned off.&lt;br /&gt;
&lt;br /&gt;
=== BeginVrModeEx ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Identical to [[#SetVrModeEnabled]] except with hard-coded flag=1.&lt;br /&gt;
&lt;br /&gt;
=== EndVrModeEx ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Identical to [[#SetVrModeEnabled]] except with hard-coded flag=0.&lt;br /&gt;
&lt;br /&gt;
=== IsInControllerFirmwareUpdateSection ===&lt;br /&gt;
No input, returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
=== SetVrPositionForDebug ===&lt;br /&gt;
Takes 4 input s32s, no output.&lt;br /&gt;
&lt;br /&gt;
The s32s are: x, y, width, height.&lt;br /&gt;
&lt;br /&gt;
The cached value loaded from [[Settings_services#GetDebugModeFlag]] must be 1, otherwise an error is returned.&lt;br /&gt;
&lt;br /&gt;
width must be 1-1280, height must be 1-720.&lt;br /&gt;
&lt;br /&gt;
x and y must not be negative. x+width must be &amp;lt;=1280. y+height must be &amp;lt;=720.&lt;br /&gt;
&lt;br /&gt;
=== GetDefaultDisplayResolution ===&lt;br /&gt;
No input, returns two output s32s &#039;&#039;&#039;width&#039;&#039;&#039; and &#039;&#039;&#039;height&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
=== GetDefaultDisplayResolutionChangeEvent ===&lt;br /&gt;
No input, returns an output Event handle with autoclear=true.&lt;br /&gt;
&lt;br /&gt;
=== GetHdcpAuthenticationState ===&lt;br /&gt;
No input, returns an output s32.&lt;br /&gt;
&lt;br /&gt;
=== GetHdcpAuthenticationStateChangeEvent ===&lt;br /&gt;
No input, returns an output Event handle with autoclear=true.&lt;br /&gt;
&lt;br /&gt;
=== SetTvPowerStateMatchingMode ===&lt;br /&gt;
Takes an input s32 [[#TvPowerStateMatchingMode]], no output.&lt;br /&gt;
&lt;br /&gt;
=== GetApplicationIdByContentActionName ===&lt;br /&gt;
Takes a type-0x5 input buffer containing a string, returns an output [[NCM_services#ApplicationId|ApplicationId]].&lt;br /&gt;
&lt;br /&gt;
Gets the ApplicationId for the specified ContentActionName string. Returns an error when the current [[#AppletId]] isn&#039;t 0x04 (when the current applet isn&#039;t a SystemApplication).&lt;br /&gt;
&lt;br /&gt;
=== SetCpuBoostMode ===&lt;br /&gt;
Takes an input u32 [[#CpuBoostMode]] and passes it to [[PPC_services#apm:sys|SetCpuBoostMode]].&lt;br /&gt;
&lt;br /&gt;
=== CancelCpuBoostMode ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
=== GetBuiltInDisplayType ===&lt;br /&gt;
No input, returns an output s32.&lt;br /&gt;
&lt;br /&gt;
This is not exposed by sdknso.&lt;br /&gt;
&lt;br /&gt;
This loads a s32 index from global state (originates from [[SPL_services#GetConfig|GetConfig]] [[SMC#HardwareType|HardwareType]]), Aborts if it&#039;s out-of-bounds, then the following is returned for the output s32: global_array[loaded_index].&lt;br /&gt;
&lt;br /&gt;
=== PerformSystemButtonPressingIfInFocus ===&lt;br /&gt;
Takes an input [[#SystemButtonType]], no output.&lt;br /&gt;
&lt;br /&gt;
Just returns 0 when a state field is not value 1. Verifies that the input button is allowed, then calls the same func as [[#PerformSystemButtonPressing]] internally.&lt;br /&gt;
&lt;br /&gt;
=== SetPerformanceConfigurationChangedNotification ===&lt;br /&gt;
Takes an input u8 bool, no output.&lt;br /&gt;
&lt;br /&gt;
=== GetCurrentPerformanceConfiguration ===&lt;br /&gt;
No input, returns the result of calling [[PPC_services#apm:sys|GetCurrentPerformanceConfiguration]].&lt;br /&gt;
&lt;br /&gt;
=== OpenMyGpuErrorHandler ===&lt;br /&gt;
No input, returns an [[#IGpuErrorHandler]].&lt;br /&gt;
&lt;br /&gt;
The cached value loaded from [[Settings_services#GetDebugModeFlag]] must be 1, otherwise an error is returned.&lt;br /&gt;
&lt;br /&gt;
=== GetOperationModeSystemInfo ===&lt;br /&gt;
No input, returns an output u32.&lt;br /&gt;
&lt;br /&gt;
This returns the output from [[#GetOperationModeSystemInfo_2|omm GetOperationModeSystemInfo]].&lt;br /&gt;
&lt;br /&gt;
=== GetSettingsPlatformRegion ===&lt;br /&gt;
No input, returns an output u8.&lt;br /&gt;
&lt;br /&gt;
This just returns the output from [[Settings_services#GetPlatformRegion|setsys GetPlatformRegion]].&lt;br /&gt;
&lt;br /&gt;
=== ActivateMigrationService ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Besides various other functionality, if required this eventually uses [[NS_Services|ns]] LaunchLibraryApplet to launch [[Migration_services|migration]].&lt;br /&gt;
&lt;br /&gt;
=== DeactivateMigrationService ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
=== DisableSleepTillShutdown ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
=== SuppressDisablingSleepTemporarily ===&lt;br /&gt;
Takes an input u64 &amp;quot;nn::TimeSpanType&amp;quot;, no output.&lt;br /&gt;
&lt;br /&gt;
=== SetRequestExitToLibraryAppletAtExecuteNextProgramEnabled ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
=== IGpuErrorHandler ===&lt;br /&gt;
This is &amp;quot;nn::am::service::IGpuErrorHandler&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [11.0.0+].&lt;br /&gt;
&lt;br /&gt;
This uses various [[NV_services#nvgem:cd|nvgem:cd]] commands.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 100 || [[#GetManualGpuErrorInfoSize]]&lt;br /&gt;
|-&lt;br /&gt;
| 101 || [[#GetManualGpuErrorInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 102 || [[#GetManualGpuErrorDetectionSystemEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 103 || [[#FinishManualGpuErrorHandling]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== GetManualGpuErrorInfoSize ====&lt;br /&gt;
No input, returns an output u64.&lt;br /&gt;
&lt;br /&gt;
==== GetManualGpuErrorInfo ====&lt;br /&gt;
Takes a type-0x6 output buffer, returns an output u64.&lt;br /&gt;
&lt;br /&gt;
The OutBuffer_size must be &amp;gt;= the output size from [[#GetManualGpuErrorInfoSize]].&lt;br /&gt;
&lt;br /&gt;
sdknso exposes the buffer as &amp;lt;code&amp;gt;void*&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
==== GetManualGpuErrorDetectionSystemEvent ====&lt;br /&gt;
No input, returns an output Event handle with EventClearMode=0.&lt;br /&gt;
&lt;br /&gt;
==== FinishManualGpuErrorHandling ====&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
== ISelfController ==&lt;br /&gt;
This is &amp;quot;nn::am::service::ISelfController&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#Exit]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#LockExit]]&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [[#UnlockExit]]&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [2.0.0+] [[#EnterFatalSection]]&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [2.0.0+] [[#LeaveFatalSection]]&lt;br /&gt;
|-&lt;br /&gt;
| 9 || [[#GetLibraryAppletLaunchableEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [[#SetScreenShotPermission]]&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [[#SetOperationModeChangedNotification]]&lt;br /&gt;
|-&lt;br /&gt;
| 12 || [[#SetPerformanceModeChangedNotification]]&lt;br /&gt;
|-&lt;br /&gt;
| 13 || [[#SetFocusHandlingMode]]&lt;br /&gt;
|-&lt;br /&gt;
| 14 || [[#SetRestartMessageEnabled]]&lt;br /&gt;
|-&lt;br /&gt;
| 15 || [2.0.0+] [[#SetScreenShotAppletIdentityInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 16 || [2.0.0+] [[#SetOutOfFocusSuspendingEnabled]]&lt;br /&gt;
|-&lt;br /&gt;
| 17 || [3.0.0+] [[#SetControllerFirmwareUpdateSection]]&lt;br /&gt;
|-&lt;br /&gt;
| 18 || [3.0.0+] [[#SetRequiresCaptureButtonShortPressedMessage]]&lt;br /&gt;
|-&lt;br /&gt;
| 19 || [3.0.0+] [[#SetAlbumImageOrientation]]&lt;br /&gt;
|-&lt;br /&gt;
| 20 || [4.0.0+] [[#SetDesirableKeyboardLayout]]&lt;br /&gt;
|-&lt;br /&gt;
| 21 || [13.0.0+] GetScreenShotProgramId&lt;br /&gt;
|-&lt;br /&gt;
| 22 || [19.0.0+] GetScreenShotAcdIndex&lt;br /&gt;
|-&lt;br /&gt;
| 23 || [19.0.0+] GetScreenShotApparentPlatform&lt;br /&gt;
|-&lt;br /&gt;
| 24 || [19.0.0+] GetScreenShotApplicationProperty&lt;br /&gt;
|-&lt;br /&gt;
| 40 || [[#CreateManagedDisplayLayer]]&lt;br /&gt;
|-&lt;br /&gt;
| 41 || [4.0.0+] [[#IsSystemBufferSharingEnabled]]&lt;br /&gt;
|-&lt;br /&gt;
| 42 || [4.0.0+] [[#GetSystemSharedLayerHandle]]&lt;br /&gt;
|-&lt;br /&gt;
| 43 || [5.0.0+] [[#GetSystemSharedBufferHandle]]&lt;br /&gt;
|-&lt;br /&gt;
| 44 || [10.0.0+] [[#CreateManagedDisplaySeparableLayer]]&lt;br /&gt;
|-&lt;br /&gt;
| 45 || [10.0.0+] [[#SetManagedDisplayLayerSeparationMode]]&lt;br /&gt;
|-&lt;br /&gt;
| 46 || [13.0.0+] [[#SetRecordingLayerCompositionEnabled]]&lt;br /&gt;
|-&lt;br /&gt;
| 50 || [[#SetHandlesRequestToDisplay]]&lt;br /&gt;
|-&lt;br /&gt;
| 51 || [[#ApproveToDisplay]]&lt;br /&gt;
|-&lt;br /&gt;
| 60 || [[#OverrideAutoSleepTimeAndDimmingTime]]&lt;br /&gt;
|-&lt;br /&gt;
| 61 || [[#SetMediaPlaybackState]]&lt;br /&gt;
|-&lt;br /&gt;
| 62 || [[#SetIdleTimeDetectionExtension]]&lt;br /&gt;
|-&lt;br /&gt;
| 63 || [[#GetIdleTimeDetectionExtension]]&lt;br /&gt;
|-&lt;br /&gt;
| 64 || [[#SetInputDetectionSourceSet]]&lt;br /&gt;
|-&lt;br /&gt;
| 65 || [2.0.0+] [[#ReportUserIsActive]]&lt;br /&gt;
|-&lt;br /&gt;
| 66 || [3.0.0+] [[#GetCurrentIlluminance]]&lt;br /&gt;
|-&lt;br /&gt;
| 67 || [3.0.0+] [[#IsIlluminanceAvailable]]&lt;br /&gt;
|-&lt;br /&gt;
| 68 || [5.0.0+] [[#SetAutoSleepDisabled]]&lt;br /&gt;
|-&lt;br /&gt;
| 69 || [5.0.0+] [[#IsAutoSleepDisabled]]&lt;br /&gt;
|-&lt;br /&gt;
| 70 || [4.0.0+] [[#ReportMultimediaError]]&lt;br /&gt;
|-&lt;br /&gt;
| 71 || [5.0.0+] [[#GetCurrentIlluminanceEx]]&lt;br /&gt;
|-&lt;br /&gt;
| 72 || [9.0.0+] [[#SetInputDetectionPolicy]]&lt;br /&gt;
|-&lt;br /&gt;
| 73 || [21.0.0+] &lt;br /&gt;
|-&lt;br /&gt;
| 80 || [4.0.0+] [[#SetWirelessPriorityMode]]&lt;br /&gt;
|-&lt;br /&gt;
| 90 || [6.0.0+] [[#GetAccumulatedSuspendedTickValue]]&lt;br /&gt;
|-&lt;br /&gt;
| 91 || [6.0.0+] [[#GetAccumulatedSuspendedTickChangedEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 100 || [7.0.0+] [[#SetAlbumImageTakenNotificationEnabled]]&lt;br /&gt;
|-&lt;br /&gt;
| 110 || [8.0.0+] [[#SetApplicationAlbumUserData]]&lt;br /&gt;
|-&lt;br /&gt;
| 120 || [11.0.0+] [[#SaveCurrentScreenshot]]&lt;br /&gt;
|-&lt;br /&gt;
| 130 || [13.0.0+] [[#SetRecordVolumeMuted]]&lt;br /&gt;
|-&lt;br /&gt;
| 200 || [20.0.0+] &lt;br /&gt;
|-&lt;br /&gt;
| 210 || [20.0.0+] &lt;br /&gt;
|-&lt;br /&gt;
| 211 || [20.0.0+] &lt;br /&gt;
|-&lt;br /&gt;
| 220 || [20.0.0+] &lt;br /&gt;
|-&lt;br /&gt;
| 221 || [20.0.0+] &lt;br /&gt;
|-&lt;br /&gt;
| 230 || [20.0.0+] &lt;br /&gt;
|-&lt;br /&gt;
| 1000 || [7.0.0+] [[#GetDebugStorageChannel]]&lt;br /&gt;
|-&lt;br /&gt;
| 2000 || [S2] [[#GetGraphicsSupervisor]]&lt;br /&gt;
|-&lt;br /&gt;
| 2100 || [S2] SetRecordingLayerEnabled&lt;br /&gt;
|-&lt;br /&gt;
| 2200 || [S2] SetSharingLayerEnabled&lt;br /&gt;
|-&lt;br /&gt;
| 2300 || [S2] [20.0.0+] SetCopyrightLayerEnabled&lt;br /&gt;
|-&lt;br /&gt;
| 2400 || [S2] SetRtcScreenSharingAudioEnabled&lt;br /&gt;
|-&lt;br /&gt;
| 2401 || [S2] [20.0.0+] SetStreamPlayMirroringAudioEnabled&lt;br /&gt;
|-&lt;br /&gt;
| 2402 || [S2] [20.0.0+]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Exit ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Exits the current applet. On success, official sw will enter an infinite loop with sleep-thread value 86400000000000.&lt;br /&gt;
&lt;br /&gt;
=== LockExit ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Locks exit process of pressing X to close in HOME Menu for an application or HOME button for an applet. When locked, it will show the &amp;quot;waiting for software to be closed dialog&amp;quot; until UnlockExit is called or a 15 seconds timeout (when the latter occurs, the process is force-terminated).&lt;br /&gt;
&lt;br /&gt;
=== UnlockExit ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Unlocks exit process, if LockExit was previously used.&lt;br /&gt;
&lt;br /&gt;
=== EnterFatalSection ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
=== LeaveFatalSection ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
[[#EnterFatalSection]] must be executed at least once before executing this command, otherwise error code 0x40080 will be returned. EnterFatalSection and LeaveFatalSection work in pairs, that is, N calls to EnterFatalSection must be performed first in order to perform N executions of LeaveFatalSection. Essentially, these two functions operate like how one would lock and unlock a recursive mutex.&lt;br /&gt;
&lt;br /&gt;
=== GetLibraryAppletLaunchableEvent ===&lt;br /&gt;
No input, returns an output event handle with autoclear=false.&lt;br /&gt;
&lt;br /&gt;
=== SetScreenShotPermission ===&lt;br /&gt;
Takes an input s32. No output.&lt;br /&gt;
&lt;br /&gt;
Controls whether screenshot-capture is allowed.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value || Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || Inherit from parent applet&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Enable&lt;br /&gt;
|-&lt;br /&gt;
| 2 || Disable&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SetOperationModeChangedNotification ===&lt;br /&gt;
Takes an input u8 bool flag. No output.&lt;br /&gt;
&lt;br /&gt;
=== SetPerformanceModeChangedNotification ===&lt;br /&gt;
Takes an input u8 bool flag. No output.&lt;br /&gt;
&lt;br /&gt;
=== SetFocusHandlingMode ===&lt;br /&gt;
Takes 3 input u8s with each field located immediately after the previous u8, these are bool flags. No output.&lt;br /&gt;
&lt;br /&gt;
=== SetRestartMessageEnabled ===&lt;br /&gt;
Takes an input u8 bool flag, no output.&lt;br /&gt;
&lt;br /&gt;
See [[#AppletMessage]].&lt;br /&gt;
&lt;br /&gt;
=== SetScreenShotAppletIdentityInfo ===&lt;br /&gt;
Takes an input [[#AppletIdentityInfo]], no output.&lt;br /&gt;
&lt;br /&gt;
=== SetOutOfFocusSuspendingEnabled ===&lt;br /&gt;
Takes an input u8 bool flag. No output.&lt;br /&gt;
&lt;br /&gt;
=== SetControllerFirmwareUpdateSection ===&lt;br /&gt;
Takes an input u8 bool flag, no output.&lt;br /&gt;
&lt;br /&gt;
This throws error 0x40280 when the internal state flag already matches the input value.&lt;br /&gt;
&lt;br /&gt;
=== SetRequiresCaptureButtonShortPressedMessage ===&lt;br /&gt;
Takes an input u8 bool flag, no output.&lt;br /&gt;
&lt;br /&gt;
See [[#AppletMessage]].&lt;br /&gt;
&lt;br /&gt;
When enabled with a non-Overlay applet, Overlay applet will not be notified of capture button short-presses for screenshots.&lt;br /&gt;
&lt;br /&gt;
=== SetAlbumImageOrientation ===&lt;br /&gt;
Takes an input u32 &amp;quot;nn::album::ImageOrientation&amp;quot;. No output.&lt;br /&gt;
&lt;br /&gt;
The input value must not be &amp;gt;3.&lt;br /&gt;
&lt;br /&gt;
=== SetDesirableKeyboardLayout ===&lt;br /&gt;
Takes an input u32, no output.&lt;br /&gt;
&lt;br /&gt;
The input u32 is &amp;quot;nn::settings::KeyboardLayout&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
=== CreateManagedDisplayLayer ===&lt;br /&gt;
Returns an output u64 LayerId which is then used by the user-process with [[Display_services#OpenLayer]].&lt;br /&gt;
&lt;br /&gt;
=== IsSystemBufferSharingEnabled ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Not available when the current applet is an Application ([[#AppletId]] == 0x01).&lt;br /&gt;
&lt;br /&gt;
Checks whether SystemBufferSharing is enabled, throwing an error otherwise.&lt;br /&gt;
&lt;br /&gt;
=== GetSystemSharedLayerHandle ===&lt;br /&gt;
No input, returns two output u64s &amp;quot;nn::vi::fbshare::SharedBufferHandle&amp;quot; and &amp;quot;nn::vi::fbshare::SharedLayerHandle&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
Runs code similar to [[#IsSystemBufferSharingEnabled]] first.&lt;br /&gt;
&lt;br /&gt;
=== GetSystemSharedBufferHandle ===&lt;br /&gt;
No input, returns an output u64 &amp;quot;nn::vi::fbshare::SharedBufferHandle&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
Runs code similar to [[#IsSystemBufferSharingEnabled]] first.&lt;br /&gt;
&lt;br /&gt;
Same as [[#GetSystemSharedLayerHandle]] except this just gets the SharedBufferHandle.&lt;br /&gt;
&lt;br /&gt;
=== CreateManagedDisplaySeparableLayer ===&lt;br /&gt;
No input, returns two output u64 LayerIds.&lt;br /&gt;
&lt;br /&gt;
sdknso now uses this instead of [[#CreateManagedDisplayLayer]]. sdknso caches the output from the cmd so that it&#039;s only used once. The first u64 is used the same as the original LayerId from [[#CreateManagedDisplayLayer]]. &amp;lt;code&amp;gt;nn::vi::CreateRecordingLayer&amp;lt;/code&amp;gt; uses the second LayerId, the layer creation is identical besides which LayerId is used.&lt;br /&gt;
&lt;br /&gt;
=== SetManagedDisplayLayerSeparationMode ===&lt;br /&gt;
Takes an input u32, no output.&lt;br /&gt;
&lt;br /&gt;
sdknso exposes this as &amp;lt;code&amp;gt;nn::vi::SetRecordingLayerEnabled(bool)&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
The input u32 must be 0-1.&lt;br /&gt;
&lt;br /&gt;
=== SetRecordingLayerCompositionEnabled ===&lt;br /&gt;
Takes an input bool, no output.&lt;br /&gt;
&lt;br /&gt;
=== SetHandlesRequestToDisplay ===&lt;br /&gt;
Takes an input u8 bool, no output.&lt;br /&gt;
&lt;br /&gt;
Sets an internal state flag. When the input flag is 0, this will in additional run the same code as [[#ApproveToDisplay]].&lt;br /&gt;
&lt;br /&gt;
See [[#AppletMessage]].&lt;br /&gt;
&lt;br /&gt;
=== ApproveToDisplay ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Used to handle the notification enabled by [[#SetHandlesRequestToDisplay]].&lt;br /&gt;
&lt;br /&gt;
=== OverrideAutoSleepTimeAndDimmingTime ===&lt;br /&gt;
Takes 4 input s32s, no output.&lt;br /&gt;
&lt;br /&gt;
=== SetMediaPlaybackState ===&lt;br /&gt;
Takes an input u8 bool, no output.&lt;br /&gt;
&lt;br /&gt;
=== SetIdleTimeDetectionExtension ===&lt;br /&gt;
Takes an input u32, no output.&lt;br /&gt;
&lt;br /&gt;
The input value must be 0-2: 0 = disabled, 1 = Extended, and 2 = ExtendedUnsafe.&lt;br /&gt;
&lt;br /&gt;
=== GetIdleTimeDetectionExtension ===&lt;br /&gt;
No input, returns an output u32.&lt;br /&gt;
&lt;br /&gt;
Returns the value set by [[#SetIdleTimeDetectionExtension]].&lt;br /&gt;
&lt;br /&gt;
=== SetInputDetectionSourceSet ===&lt;br /&gt;
Takes an input u32, no output.&lt;br /&gt;
&lt;br /&gt;
=== ReportUserIsActive ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Uses idle:sys ReportUserIsActive.&lt;br /&gt;
&lt;br /&gt;
Reports that the user is active, for idle detection (screen dimming / auto-sleep). This is equivalent to when the user uses HID input.&lt;br /&gt;
&lt;br /&gt;
=== GetCurrentIlluminance ===&lt;br /&gt;
No input, returns an output float.&lt;br /&gt;
&lt;br /&gt;
Uses [[Backlight_services|lbl]] command GetAmbientLightSensorValue, where only the output float is used.&lt;br /&gt;
&lt;br /&gt;
=== IsIlluminanceAvailable ===&lt;br /&gt;
No input, returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
Uses [[Backlight_services|lbl]] command IsAmbientLightSensorAvailable.&lt;br /&gt;
&lt;br /&gt;
User-processes can use this to determine whether to continue with using GetCurrentIlluminance(Ex).&lt;br /&gt;
&lt;br /&gt;
=== SetAutoSleepDisabled ===&lt;br /&gt;
Takes an input u8 bool, no output.&lt;br /&gt;
&lt;br /&gt;
=== IsAutoSleepDisabled ===&lt;br /&gt;
No input, returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
=== ReportMultimediaError ===&lt;br /&gt;
Takes an input Result and a type-0x5 input buffer, no output.&lt;br /&gt;
&lt;br /&gt;
The buffer contains a 0x138-byte &amp;quot;movie::MultimediaTelemetryReport&amp;quot; struct.&lt;br /&gt;
&lt;br /&gt;
=== GetCurrentIlluminanceEx ===&lt;br /&gt;
No input, returns an output u8 bool and float.&lt;br /&gt;
&lt;br /&gt;
Uses [[Backlight_services|lbl]] command GetAmbientLightSensorValue.&lt;br /&gt;
&lt;br /&gt;
=== SetInputDetectionPolicy ===&lt;br /&gt;
Takes an input [[#InputDetectionPolicy]], no output.&lt;br /&gt;
&lt;br /&gt;
=== SetWirelessPriorityMode ===&lt;br /&gt;
Takes an input s32 [[#WirelessPriorityMode]], no output.&lt;br /&gt;
&lt;br /&gt;
=== GetAccumulatedSuspendedTickValue ===&lt;br /&gt;
No input, returns an output u64 tick value.&lt;br /&gt;
&lt;br /&gt;
Gets the total time in ticks that the process was suspended, relative to when the applet-service was last initialized.&lt;br /&gt;
&lt;br /&gt;
=== GetAccumulatedSuspendedTickChangedEvent ===&lt;br /&gt;
No input, returns an output Event handle with autoclear=true.&lt;br /&gt;
&lt;br /&gt;
This is signaled when the output from [[#GetAccumulatedSuspendedTickValue]] is updated.&lt;br /&gt;
&lt;br /&gt;
=== SetAlbumImageTakenNotificationEnabled ===&lt;br /&gt;
Takes an input u8 bool, no output.&lt;br /&gt;
&lt;br /&gt;
See [[#AppletMessage]].&lt;br /&gt;
&lt;br /&gt;
=== SetApplicationAlbumUserData ===&lt;br /&gt;
Takes a type-0x21 input buffer, no output.&lt;br /&gt;
&lt;br /&gt;
The buffer contains arbitrary UserData.&lt;br /&gt;
&lt;br /&gt;
The size must be &amp;lt;=0x400. The input buffer is copied to a buffer loaded from a state ptr (throwing an error when the state ptr is not set), with the u32 size being written to statebuf+0x400 afterwards.&lt;br /&gt;
&lt;br /&gt;
=== SaveCurrentScreenshot ===&lt;br /&gt;
Takes an input s32 [[Capture_services#AlbumReportOption|AlbumReportOption]], no output.&lt;br /&gt;
&lt;br /&gt;
sdknso exposes this under &amp;quot;nn::album::&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
=== SetRecordVolumeMuted ===&lt;br /&gt;
Takes an input bool, no output.&lt;br /&gt;
&lt;br /&gt;
=== GetDebugStorageChannel ===&lt;br /&gt;
No input, returns an output [[#IStorageChannel]].&lt;br /&gt;
&lt;br /&gt;
The cached value loaded from [[System_Settings|system-setting]] &amp;lt;code&amp;gt;am.debug!dev_function&amp;lt;/code&amp;gt; must be set to 0x1 with size 0x1, otherwise an error is returned.&lt;br /&gt;
&lt;br /&gt;
=== GetGraphicsSupervisor ===&lt;br /&gt;
This is exclusive to S2.&lt;br /&gt;
&lt;br /&gt;
No input. Returns an output TIPC handle to [[Switch_2:_GSV_services|GraphicsSupervisor]].&lt;br /&gt;
&lt;br /&gt;
== IStorageChannel ==&lt;br /&gt;
This is &amp;quot;nn::am::service::IStorageChannel&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [7.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || Push || No input, returns an output [[#IStorage]].&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Unpop || No input, returns an output [[#IStorage]].&lt;br /&gt;
|-&lt;br /&gt;
| 2 || Pop || No input, returns an output [[#IStorage]].&lt;br /&gt;
|-&lt;br /&gt;
| 3 || GetPopEventHandle || No input, returns an output handle.&lt;br /&gt;
|-&lt;br /&gt;
| 4 || Clear || No input/output.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IWindowController ==&lt;br /&gt;
This is &amp;quot;nn::am::service::IWindowController&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#CreateWindow]] || &lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#GetAppletResourceUserId]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [6.0.0+] [[#GetAppletResourceUserIdOfCallerApplet]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [[#AcquireForegroundRights]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [[#ReleaseForegroundRights]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 12 || [[#RejectToChangeIntoBackground]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 20 || [7.0.0+] [[#SetAppletWindowVisibility]] || &lt;br /&gt;
|-&lt;br /&gt;
| 21 || [7.0.0+] [[#SetAppletGpuTimeSlice]] || &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CreateWindow ===&lt;br /&gt;
Takes an input u32, returns an output [[#IWindow]].&lt;br /&gt;
&lt;br /&gt;
Stubbed, just returns an error.&lt;br /&gt;
&lt;br /&gt;
=== GetAppletResourceUserId ===&lt;br /&gt;
No input, returns an output u64 [[#AppletResourceUserId]].&lt;br /&gt;
&lt;br /&gt;
=== GetAppletResourceUserIdOfCallerApplet ===&lt;br /&gt;
No input, returns an output u64 [[#AppletResourceUserId]].&lt;br /&gt;
&lt;br /&gt;
=== AcquireForegroundRights ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Just returns 0.&lt;br /&gt;
&lt;br /&gt;
=== ReleaseForegroundRights ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Just returns 0.&lt;br /&gt;
&lt;br /&gt;
=== RejectToChangeIntoBackground ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Just returns 0.&lt;br /&gt;
&lt;br /&gt;
=== SetAppletWindowVisibility ===&lt;br /&gt;
Takes an input u8 bool, no output.&lt;br /&gt;
&lt;br /&gt;
=== SetAppletGpuTimeSlice ===&lt;br /&gt;
Takes an input s64, no output.&lt;br /&gt;
&lt;br /&gt;
The input s64 must not be negative.&lt;br /&gt;
&lt;br /&gt;
== IAudioController ==&lt;br /&gt;
This is &amp;quot;nn::am::service::IAudioController&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#SetExpectedMasterVolume]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#GetMainAppletExpectedMasterVolume]]&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [[#GetLibraryAppletExpectedMasterVolume]]&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [[#ChangeMainAppletMasterVolume]]&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [[#SetTransparentVolumeRate]]&lt;br /&gt;
|-&lt;br /&gt;
| 5 || [20.0.0+]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
GetMainAppletExpectedMasterVolume/SetExpectedMasterVolume are used for saving/restoring state for LibraryApplet launching, with SetExpectedMasterVolume being used with new state prior to launching a LibraryApplet. With official sw these applet funcs are used directly in the main-codebin.&lt;br /&gt;
&lt;br /&gt;
=== SetExpectedMasterVolume ===&lt;br /&gt;
Takes two input floats, no output.&lt;br /&gt;
&lt;br /&gt;
Writes the input floats to state: first one is used by [[#GetMainAppletExpectedMasterVolume]], second one is used by [[#GetLibraryAppletExpectedMasterVolume]].&lt;br /&gt;
&lt;br /&gt;
=== GetMainAppletExpectedMasterVolume ===&lt;br /&gt;
No input, returns an output float.&lt;br /&gt;
&lt;br /&gt;
=== GetLibraryAppletExpectedMasterVolume ===&lt;br /&gt;
No input, returns an output float.&lt;br /&gt;
&lt;br /&gt;
=== ChangeMainAppletMasterVolume ===&lt;br /&gt;
Takes an input float and an input u64, no output.&lt;br /&gt;
&lt;br /&gt;
=== SetTransparentVolumeRate ===&lt;br /&gt;
Takes an input float, no output.&lt;br /&gt;
&lt;br /&gt;
== IDisplayController ==&lt;br /&gt;
This is &amp;quot;nn::am::service::IDisplayController&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#GetLastForegroundCaptureImage]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#UpdateLastForegroundCaptureImage]]&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [[#GetLastApplicationCaptureImage]]&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [[#GetCallerAppletCaptureImage]]&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [[#UpdateCallerAppletCaptureImage]]&lt;br /&gt;
|-&lt;br /&gt;
| 5 || [[#GetLastForegroundCaptureImageEx]]&lt;br /&gt;
|-&lt;br /&gt;
| 6 || [[#GetLastApplicationCaptureImageEx]]&lt;br /&gt;
|-&lt;br /&gt;
| 7 || [[#GetCallerAppletCaptureImageEx]]&lt;br /&gt;
|-&lt;br /&gt;
| 8 || [2.0.0+] [[#TakeScreenShotOfOwnLayer]]&lt;br /&gt;
|-&lt;br /&gt;
| 9 || [5.0.0+] [[#CopyBetweenCaptureBuffers]]&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [[#AcquireLastApplicationCaptureBuffer]]&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [[#ReleaseLastApplicationCaptureBuffer]]&lt;br /&gt;
|-&lt;br /&gt;
| 12 || [[#AcquireLastForegroundCaptureBuffer]]&lt;br /&gt;
|-&lt;br /&gt;
| 13 || [[#ReleaseLastForegroundCaptureBuffer]]&lt;br /&gt;
|-&lt;br /&gt;
| 14 || [[#AcquireCallerAppletCaptureBuffer]]&lt;br /&gt;
|-&lt;br /&gt;
| 15 || [[#ReleaseCallerAppletCaptureBuffer]]&lt;br /&gt;
|-&lt;br /&gt;
| 16 || [[#AcquireLastApplicationCaptureBufferEx]]&lt;br /&gt;
|-&lt;br /&gt;
| 17 || [[#AcquireLastForegroundCaptureBufferEx]]&lt;br /&gt;
|-&lt;br /&gt;
| 18 || [[#AcquireCallerAppletCaptureBufferEx]]&lt;br /&gt;
|-&lt;br /&gt;
| 20 || [3.0.0+] [[#ClearCaptureBuffer]]&lt;br /&gt;
|-&lt;br /&gt;
| 21 || [3.0.0+] [[#ClearAppletTransitionBuffer]]&lt;br /&gt;
|-&lt;br /&gt;
| 22 || [4.0.0+] [[#AcquireLastApplicationCaptureSharedBuffer]]&lt;br /&gt;
|-&lt;br /&gt;
| 23 || [4.0.0+] [[#ReleaseLastApplicationCaptureSharedBuffer]]&lt;br /&gt;
|-&lt;br /&gt;
| 24 || [4.0.0+] [[#AcquireLastForegroundCaptureSharedBuffer]]&lt;br /&gt;
|-&lt;br /&gt;
| 25 || [4.0.0+] [[#ReleaseLastForegroundCaptureSharedBuffer]]&lt;br /&gt;
|-&lt;br /&gt;
| 26 || [4.0.0+] [[#AcquireCallerAppletCaptureSharedBuffer]]&lt;br /&gt;
|-&lt;br /&gt;
| 27 || [4.0.0+] [[#ReleaseCallerAppletCaptureSharedBuffer]]&lt;br /&gt;
|-&lt;br /&gt;
| 28 || [6.0.0+] [[#TakeScreenShotOfOwnLayerEx]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== GetLastForegroundCaptureImage ===&lt;br /&gt;
Takes a type-0x6 output buffer.&lt;br /&gt;
&lt;br /&gt;
Stubbed, just returns an error.&lt;br /&gt;
&lt;br /&gt;
=== UpdateLastForegroundCaptureImage ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
=== GetLastApplicationCaptureImage ===&lt;br /&gt;
Takes a type-0x6 output buffer.&lt;br /&gt;
&lt;br /&gt;
Stubbed, just returns an error.&lt;br /&gt;
&lt;br /&gt;
=== GetCallerAppletCaptureImage ===&lt;br /&gt;
Takes a type-0x6 output buffer.&lt;br /&gt;
&lt;br /&gt;
Stubbed, just returns an error.&lt;br /&gt;
&lt;br /&gt;
=== UpdateCallerAppletCaptureImage ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Calls the same func internally as [[#UpdateLastForegroundCaptureImage]], except this passes param value 2 instead of 1.&lt;br /&gt;
&lt;br /&gt;
=== GetLastForegroundCaptureImageEx ===&lt;br /&gt;
Takes a type-0x6 output buffer, returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
The buffer size must match 0x384000.&lt;br /&gt;
&lt;br /&gt;
=== GetLastApplicationCaptureImageEx ===&lt;br /&gt;
Takes a type-0x6 output buffer, returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
The buffer size must match 0x384000.&lt;br /&gt;
&lt;br /&gt;
Calls the same internal func as [[#GetLastForegroundCaptureImageEx]], except that the last param is set to value 0 instead of 1.&lt;br /&gt;
&lt;br /&gt;
=== GetCallerAppletCaptureImageEx ===&lt;br /&gt;
Takes a type-0x6 output buffer, returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
The buffer size must match 0x384000.&lt;br /&gt;
&lt;br /&gt;
Calls the same internal func as [[#GetLastForegroundCaptureImageEx]], except that the last param is set to value 2 instead of 1.&lt;br /&gt;
&lt;br /&gt;
=== TakeScreenShotOfOwnLayer ===&lt;br /&gt;
Takes an input u8 bool and a s32, no output.&lt;br /&gt;
&lt;br /&gt;
=== CopyBetweenCaptureBuffers ===&lt;br /&gt;
Takes two input s32s, no output.&lt;br /&gt;
&lt;br /&gt;
=== AcquireLastApplicationCaptureBuffer ===&lt;br /&gt;
No input, returns an output handle.&lt;br /&gt;
&lt;br /&gt;
Stubbed, just returns an error.&lt;br /&gt;
&lt;br /&gt;
=== ReleaseLastApplicationCaptureBuffer ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Clears a state field if it&#039;s not already 0, returning an error otherwise. On newer sysvers: then a func is called which just returns 0, then this cmd returns 0.&lt;br /&gt;
&lt;br /&gt;
=== AcquireLastForegroundCaptureBuffer ===&lt;br /&gt;
No input, returns an output handle.&lt;br /&gt;
&lt;br /&gt;
Stubbed, just returns an error.&lt;br /&gt;
&lt;br /&gt;
=== ReleaseLastForegroundCaptureBuffer ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Same as [[#ReleaseLastApplicationCaptureBuffer]] except with a different state field + different input param for the called func.&lt;br /&gt;
&lt;br /&gt;
=== AcquireCallerAppletCaptureBuffer ===&lt;br /&gt;
No input, returns an output handle.&lt;br /&gt;
&lt;br /&gt;
Stubbed, just returns an error.&lt;br /&gt;
&lt;br /&gt;
=== ReleaseCallerAppletCaptureBuffer ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Same as [[#ReleaseLastApplicationCaptureBuffer]] except with a different state field + different input param for the called func.&lt;br /&gt;
&lt;br /&gt;
=== AcquireLastApplicationCaptureBufferEx ===&lt;br /&gt;
No input, returns an output TransferMemory handle and an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
The state field used by [[#ReleaseLastApplicationCaptureBuffer]] must be 0. Calls a func which just returns an error (this is only the case on newer sysvers), hence this cmd will just return that error. If that func would have returned successfully, the state field would be set to 1 and the cmd would return 0.&lt;br /&gt;
&lt;br /&gt;
On old sysvers, the output TransferMemory is size 0x384000 with permissions=RW.&lt;br /&gt;
&lt;br /&gt;
=== AcquireLastForegroundCaptureBufferEx ===&lt;br /&gt;
No input, returns an output TransferMemory handle and an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
Same as [[#AcquireLastApplicationCaptureBufferEx]] except this uses the [[#ReleaseLastForegroundCaptureBuffer]] state field, and uses a different input param value for the called func.&lt;br /&gt;
&lt;br /&gt;
=== AcquireCallerAppletCaptureBufferEx ===&lt;br /&gt;
No input, returns an output TransferMemory handle and an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
Same as [[#AcquireLastApplicationCaptureBufferEx]] except this uses the [[#ReleaseCallerAppletCaptureBuffer]] state field, and uses a different input param value for the called func.&lt;br /&gt;
&lt;br /&gt;
=== ClearCaptureBuffer ===&lt;br /&gt;
Takes an input u8 bool, a s32 CaptureSharedBuffer, and an u32 color, returns no output.&lt;br /&gt;
&lt;br /&gt;
Clear the input CaptureSharedBuffer with the specified RGBA8 color.&lt;br /&gt;
&lt;br /&gt;
=== ClearAppletTransitionBuffer ===&lt;br /&gt;
Takes an input u32, no output.&lt;br /&gt;
&lt;br /&gt;
Clear the AppletTransitionBuffer with the specified RGBA8 color.&lt;br /&gt;
&lt;br /&gt;
=== AcquireLastApplicationCaptureSharedBuffer ===&lt;br /&gt;
No input, returns an output u8 bool and an s32.&lt;br /&gt;
&lt;br /&gt;
This loads data from state.&lt;br /&gt;
&lt;br /&gt;
=== ReleaseLastApplicationCaptureSharedBuffer ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Depending on whether a state field is 0, this just returns an error or returns 0.&lt;br /&gt;
&lt;br /&gt;
=== AcquireLastForegroundCaptureSharedBuffer ===&lt;br /&gt;
No input, returns an output u8 bool and an s32.&lt;br /&gt;
&lt;br /&gt;
Calls the same func internally as [[#AcquireLastApplicationCaptureSharedBuffer]], except this passes value 1 for the last param instead of 0.&lt;br /&gt;
&lt;br /&gt;
=== ReleaseLastForegroundCaptureSharedBuffer ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Calls the same func internally as [[#ReleaseLastApplicationCaptureSharedBuffer]], except this passes value 1 for the last param instead of 0.&lt;br /&gt;
&lt;br /&gt;
=== AcquireCallerAppletCaptureSharedBuffer ===&lt;br /&gt;
No input, returns an output u8 bool and an s32.&lt;br /&gt;
&lt;br /&gt;
Calls the same func internally as [[#AcquireLastApplicationCaptureSharedBuffer]], except this passes value 2 for the last param instead of 0.&lt;br /&gt;
&lt;br /&gt;
=== ReleaseCallerAppletCaptureSharedBuffer ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Calls the same func internally as [[#ReleaseLastApplicationCaptureSharedBuffer]], except this passes value 2 for the last param instead of 0.&lt;br /&gt;
&lt;br /&gt;
=== TakeScreenShotOfOwnLayerEx ===&lt;br /&gt;
Takes two input u8 bools and a s32, no output.&lt;br /&gt;
&lt;br /&gt;
Calls the same func internally as [[#TakeScreenShotOfOwnLayer]], except the last bool param is the last cmd param bool instead of hard-coded 0. This flag indicates whether the screenshot should be taken Immediately.&lt;br /&gt;
&lt;br /&gt;
== ISystemAppletControllerForDebug ==&lt;br /&gt;
This is &amp;quot;nn::am::service::ISystemAppletControllerForDebug&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 1 || RequestLaunchApplicationForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [7.0.0+] [[#GetDebugStorageChannel]]&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [7.0.0+] [[#CreateStorageForDebug]]&lt;br /&gt;
|-&lt;br /&gt;
| 4 || [12.0.0+] [[#CreateCradleFirmwareUpdaterForDebug]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== GetDebugStorageChannel ===&lt;br /&gt;
No input. Returns an output [[#IStorageChannel]].&lt;br /&gt;
&lt;br /&gt;
=== CreateStorageForDebug ===&lt;br /&gt;
Takes a total of 8-bytes of input. Returns an [[#IStorage]].&lt;br /&gt;
&lt;br /&gt;
=== CreateCradleFirmwareUpdaterForDebug ===&lt;br /&gt;
No input. Returns an [[#ICradleFirmwareUpdater]].&lt;br /&gt;
&lt;br /&gt;
== IProcessWindingController ==&lt;br /&gt;
This is &amp;quot;nn::am::service::IProcessWindingController&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
GetProcessWindingController throws an error when used from non-LibraryApplet (at least with Application).&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#GetLaunchReason]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [[#OpenCallingLibraryApplet]] || &lt;br /&gt;
|-&lt;br /&gt;
| 21 || [[#PushContext]] || &lt;br /&gt;
|-&lt;br /&gt;
| 22 || [[#PopContext]] || &lt;br /&gt;
|-&lt;br /&gt;
| 23 || [[#CancelWindingReservation]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 30 || [[#WindAndDoReserved]] ||&lt;br /&gt;
|-&lt;br /&gt;
| 40 || [[#ReserveToStartAndWaitAndUnwindThis]] || &lt;br /&gt;
|-&lt;br /&gt;
| 41 || [4.0.0+] [[#ReserveToStartAndWait]] ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== GetLaunchReason ===&lt;br /&gt;
No input, returns an output [[#AppletProcessLaunchReason]].&lt;br /&gt;
&lt;br /&gt;
Used by LibraryApplets.&lt;br /&gt;
&lt;br /&gt;
=== OpenCallingLibraryApplet ===&lt;br /&gt;
No input, returns an output [[#ILibraryAppletAccessor]].&lt;br /&gt;
&lt;br /&gt;
The objptr from state is cleared during this, an error is thrown if it&#039;s already 0.&lt;br /&gt;
&lt;br /&gt;
=== PushContext ===&lt;br /&gt;
Takes an input [[#IStorage]], no output.&lt;br /&gt;
&lt;br /&gt;
=== PopContext ===&lt;br /&gt;
No input, returns an output [[#IStorage]].&lt;br /&gt;
&lt;br /&gt;
=== CancelWindingReservation ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
=== WindAndDoReserved ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
=== ReserveToStartAndWaitAndUnwindThis ===&lt;br /&gt;
Takes an input [[#ILibraryAppletAccessor]], no output.&lt;br /&gt;
&lt;br /&gt;
=== ReserveToStartAndWait ===&lt;br /&gt;
Takes an input [[#ILibraryAppletAccessor]], no output.&lt;br /&gt;
&lt;br /&gt;
== ISystemProcessCommonFunctions ==&lt;br /&gt;
This is &amp;quot;nn::am::service::ISystemProcessCommonFunctions&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [19.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 1 || &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Cmd1 ===&lt;br /&gt;
No input. Returns an [[#IApplicationObserver]].&lt;br /&gt;
&lt;br /&gt;
=== IApplicationObserver ===&lt;br /&gt;
This is &amp;quot;nn::am::service::IApplicationObserver&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [19.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 1 || &lt;br /&gt;
|-&lt;br /&gt;
| 2 || &lt;br /&gt;
|-&lt;br /&gt;
| 10 || &lt;br /&gt;
|-&lt;br /&gt;
| 20 || &lt;br /&gt;
|-&lt;br /&gt;
| 30 || &lt;br /&gt;
|-&lt;br /&gt;
| 40 || [S2] [20.0.0+]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IAppletAlternativeFunctions ==&lt;br /&gt;
This is &amp;quot;nn::am::service::IAppletAlternativeFunctions&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [20.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || &lt;br /&gt;
|-&lt;br /&gt;
| 1 || &lt;br /&gt;
|-&lt;br /&gt;
| 2 || &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IChatProxy ==&lt;br /&gt;
This is &amp;quot;nn::am::service::IChatProxy&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This is exclusive to Switch 2.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetCommonStateGetter || Returns an [[#ICommonStateGetter]].&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GetSelfController || Returns an [[#ISelfController]].&lt;br /&gt;
|-&lt;br /&gt;
| 2 || GetWindowController || Returns an [[#IWindowController]].&lt;br /&gt;
|-&lt;br /&gt;
| 3 || GetAudioController || Returns an [[#IAudioController]].&lt;br /&gt;
|-&lt;br /&gt;
| 4 || GetDisplayController || Returns an [[#IDisplayController]].&lt;br /&gt;
|-&lt;br /&gt;
| 1000 || GetDebugFunctions || Returns an [[#IDebugFunctions]].&lt;br /&gt;
|-&lt;br /&gt;
| 10 || GetProcessWindingController || Returns an [[#IProcessWindingController]].&lt;br /&gt;
|-&lt;br /&gt;
| 11 || GetLibraryAppletCreator || Returns an [[#ILibraryAppletCreator]].&lt;br /&gt;
|-&lt;br /&gt;
| 20 || || Returns an [[#IChatFunctions]].&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IChatFunctions ===&lt;br /&gt;
This is &amp;quot;nn::am::service::IChatFunctions&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This is exclusive to Switch 2.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 1 || &lt;br /&gt;
|-&lt;br /&gt;
| 102 || &lt;br /&gt;
|-&lt;br /&gt;
| 103 || &lt;br /&gt;
|-&lt;br /&gt;
| 104 || &lt;br /&gt;
|-&lt;br /&gt;
| 110 || &lt;br /&gt;
|-&lt;br /&gt;
| 120 || &lt;br /&gt;
|-&lt;br /&gt;
| 121 || &lt;br /&gt;
|-&lt;br /&gt;
| 130 || &lt;br /&gt;
|-&lt;br /&gt;
| 140 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 141 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 200 || &lt;br /&gt;
|-&lt;br /&gt;
| 201 || &lt;br /&gt;
|-&lt;br /&gt;
| 210 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 220 || [20.0.0+]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== IDebugFunctions ==&lt;br /&gt;
This is &amp;quot;nn::am::service::IDebugFunctions&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#NotifyMessageToHomeMenuForDebug]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [1.0.0-9.2.0] [[#OpenMainApplication]]&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [[#PerformSystemButtonPressing]]&lt;br /&gt;
|-&lt;br /&gt;
| 20 || [[#InvalidateTransitionLayer]]&lt;br /&gt;
|-&lt;br /&gt;
| 30 || [6.0.0+] [[#RequestLaunchApplicationWithUserAndArgumentForDebug]]&lt;br /&gt;
|-&lt;br /&gt;
| 31 || [12.0.0+] [[#RequestLaunchApplicationByApplicationLaunchInfoForDebug]]&lt;br /&gt;
|-&lt;br /&gt;
| 40 || [6.0.0+] [[#GetAppletResourceUsageInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 50 || [15.0.0+] AddSystemProgramIdAndAppletIdForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 51 || [16.0.0+] AddOperationConfirmedLibraryAppletIdForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 52 || [17.0.0+] GetProgramIdFromAppletIdForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 53 || [18.0.0+] GetProgramIdFromAppletIdAndLibraryAppletModeForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 100 || [7.0.0+] [[#SetCpuBoostModeForApplet]]&lt;br /&gt;
|-&lt;br /&gt;
| 101 || [10.0.0+] [[#CancelCpuBoostModeForApplet]]&lt;br /&gt;
|-&lt;br /&gt;
| 110 || [9.0.0+] [[#PushToAppletBoundChannelForDebug]]&lt;br /&gt;
|-&lt;br /&gt;
| 111 || [9.0.0+] [[#TryPopFromAppletBoundChannelForDebug]]&lt;br /&gt;
|-&lt;br /&gt;
| 120 || [9.0.0+] [[#AlarmSettingNotificationEnableAppEventReserve]]&lt;br /&gt;
|-&lt;br /&gt;
| 121 || [9.0.0+] [[#AlarmSettingNotificationDisableAppEventReserve]]&lt;br /&gt;
|-&lt;br /&gt;
| 122 || [9.0.0+] [[#AlarmSettingNotificationPushAppEventNotify]]&lt;br /&gt;
|-&lt;br /&gt;
| 130 || [9.0.0+] [[#FriendInvitationSetApplicationParameter]]&lt;br /&gt;
|-&lt;br /&gt;
| 131 || [9.0.0+] [[#FriendInvitationClearApplicationParameter]]&lt;br /&gt;
|-&lt;br /&gt;
| 132 || [9.0.0+] [[#FriendInvitationPushApplicationParameter]]&lt;br /&gt;
|-&lt;br /&gt;
| 140 || [14.0.0+] [[#RestrictPowerOperationForSecureLaunchModeForDebug|RestrictPowerOperationForSecureLaunchModeForDebug]]&lt;br /&gt;
|-&lt;br /&gt;
| 150 || [21.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 200 || [15.0.0+] [[#CreateFloatingLibraryAppletAccepterForDebug|CreateFloatingLibraryAppletAccepterForDebug]]&lt;br /&gt;
|-&lt;br /&gt;
| 300 || [16.0.0+] TerminateAllRunningApplicationsForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 400 || [S2] LaunchDebugAppletForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 401 || [S2] TerminateDebugAppletForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 402 || [S2] IsDebugAppletLaunchedForDebug&lt;br /&gt;
|-&lt;br /&gt;
| 403 || [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 410 || [18.0.0+] [[#CreateGeneralStorageForDebug|CreateGeneralStorageForDebug]]&lt;br /&gt;
|-&lt;br /&gt;
| 411 || [18.0.0+] [[#ReadGeneralStorageForDebug|ReadGeneralStorageForDebug]]&lt;br /&gt;
|-&lt;br /&gt;
| 412 || [18.0.0+] [[#WriteGeneralStorageForDebug|WriteGeneralStorageForDebug]]&lt;br /&gt;
|-&lt;br /&gt;
| 430 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 431 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 900 || [12.0.0+] GetGrcProcessLaunchedSystemEvent&lt;br /&gt;
|-&lt;br /&gt;
| 910 || [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 2000 || [S2] [20.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 10000 || [S2]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== NotifyMessageToHomeMenuForDebug ===&lt;br /&gt;
Takes an input [[#AppletMessage]], no output.&lt;br /&gt;
&lt;br /&gt;
Stubbed, just returns an error.&lt;br /&gt;
&lt;br /&gt;
=== OpenMainApplication ===&lt;br /&gt;
No input, returns an output [[#IApplicationAccessor]].&lt;br /&gt;
&lt;br /&gt;
Should not be used when no Application is running (svcBreak).&lt;br /&gt;
&lt;br /&gt;
=== PerformSystemButtonPressing ===&lt;br /&gt;
Takes an input [[#SystemButtonType]], no output.&lt;br /&gt;
&lt;br /&gt;
=== InvalidateTransitionLayer ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
=== RequestLaunchApplicationWithUserAndArgumentForDebug ===&lt;br /&gt;
Takes an input u8 bool flag, an [[NCM_services#ApplicationId|ApplicationId]], a type-0x5 input buffer containing an array of u128 userIDs, and a type-0x5 input buffer, no output.&lt;br /&gt;
&lt;br /&gt;
Requests to launch the specified Application, with the specified users. When the bool flag is true, the content of the second input buffer is used to create a storage which is pushed to the UserChannel for this Application (see [[#LaunchParameterKind]]).&lt;br /&gt;
&lt;br /&gt;
=== RequestLaunchApplicationByApplicationLaunchInfoForDebug ===&lt;br /&gt;
Takes a total of 0x58-bytes of input, a type-0x5 input buffer containing an array of 0x10-byte entries, and a type-0x5 input buffer. No output.&lt;br /&gt;
&lt;br /&gt;
[19.0.0+] Takes a total of 0x88-bytes of input, a type-0x5 input buffer containing an array of 0x10-byte entries, and a type-0x5 input buffer. No output.&lt;br /&gt;
&lt;br /&gt;
=== GetAppletResourceUsageInfo ===&lt;br /&gt;
No input, returns an output [[#AppletResourceUsageInfo]].&lt;br /&gt;
&lt;br /&gt;
=== SetCpuBoostModeForApplet ===&lt;br /&gt;
Takes an input u32 [[#CpuBoostMode]] and passes it to [[PPC_services#apm:sys|SetCpuBoostMode]].&lt;br /&gt;
&lt;br /&gt;
The cached value loaded from [[Settings_services#GetDebugModeFlag]] must be 1, otherwise an error is returned.&lt;br /&gt;
&lt;br /&gt;
=== CancelCpuBoostModeForApplet ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
=== PushToAppletBoundChannelForDebug ===&lt;br /&gt;
Takes an input [[#IStorage]] and a s32, no output.&lt;br /&gt;
&lt;br /&gt;
The cached value loaded from [[Settings_services#GetDebugModeFlag]] must be 1, otherwise an error is returned.&lt;br /&gt;
&lt;br /&gt;
The s32 must match the value already stored in state when the state value is non-zero, otherwise an error is returned. When the state value is 0, the s32 is written into state. Then the input storage is pushed to the StorageChannel.&lt;br /&gt;
&lt;br /&gt;
=== TryPopFromAppletBoundChannelForDebug ===&lt;br /&gt;
Takes an input s32, returns an output [[#IStorage]].&lt;br /&gt;
&lt;br /&gt;
The cached value loaded from [[Settings_services#GetDebugModeFlag]] must be 1, otherwise an error is returned.&lt;br /&gt;
&lt;br /&gt;
The s32 must not be 0 and must match the value previously saved by [[#PushToAppletBoundChannelForDebug]], otherwise errors are returned. Then the output storage is popped from the StorageChannel.&lt;br /&gt;
&lt;br /&gt;
=== AlarmSettingNotificationEnableAppEventReserve ===&lt;br /&gt;
Takes an input [[#IStorage]] and an [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
Clears a StorageChannel, pushes the input storage there, and writes the ApplicationId into state.&lt;br /&gt;
&lt;br /&gt;
When launching an Application with a matching ApplicationId, this storage is popped, then pushed to [[#PushToNotificationStorageChannel|NotificationStorageChannel]].&lt;br /&gt;
&lt;br /&gt;
=== AlarmSettingNotificationDisableAppEventReserve ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Clears the StorageChannel/saved-ApplicationId used by [[#AlarmSettingNotificationEnableAppEventReserve]].&lt;br /&gt;
&lt;br /&gt;
=== AlarmSettingNotificationPushAppEventNotify ===&lt;br /&gt;
Takes an input [[#IStorage]], no output.&lt;br /&gt;
&lt;br /&gt;
Same as [[#PushToNotificationStorageChannel]] except this uses the MainApplication.&lt;br /&gt;
&lt;br /&gt;
=== FriendInvitationSetApplicationParameter ===&lt;br /&gt;
Takes an input [[#IStorage]] and an [[NCM_services#ApplicationId|ApplicationId]], no output.&lt;br /&gt;
&lt;br /&gt;
Clears a StorageChannel, pushes the input storage there, and writes the ApplicationId into state.&lt;br /&gt;
&lt;br /&gt;
When launching an Application with a matching ApplicationId, this storage is popped, then pushed to [[#PushToFriendInvitationStorageChannel|FriendInvitationStorageChannel]].&lt;br /&gt;
&lt;br /&gt;
=== FriendInvitationClearApplicationParameter ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Clears the StorageChannel/saved-ApplicationId used by [[#FriendInvitationSetApplicationParameter]].&lt;br /&gt;
&lt;br /&gt;
=== FriendInvitationPushApplicationParameter ===&lt;br /&gt;
Takes an input [[#IStorage]], no output.&lt;br /&gt;
&lt;br /&gt;
Same as [[#PushToFriendInvitationStorageChannel]] except this uses the MainApplication.&lt;br /&gt;
&lt;br /&gt;
=== RestrictPowerOperationForSecureLaunchModeForDebug ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
This runs the same functionality as [[#DisableSleepTillShutdown|DisableSleepTillShutdown]].&lt;br /&gt;
&lt;br /&gt;
=== CreateFloatingLibraryAppletAccepterForDebug ===&lt;br /&gt;
Takes a PID, an input u64 reserved_pid, a type-0x5 input buffer containing an array of u32s, returns an [[#IFloatingLibraryAppletAccepter|IFloatingLibraryAppletAccepter]].&lt;br /&gt;
&lt;br /&gt;
If a state field is already set it must match the PID, otherwise when state==0 the PID is written into state etc.&lt;br /&gt;
&lt;br /&gt;
=== CreateGeneralStorageForDebug ===&lt;br /&gt;
Takes two input u64s Id and size, no output.&lt;br /&gt;
&lt;br /&gt;
The high-byte of Id must be 0.&lt;br /&gt;
&lt;br /&gt;
Goes through a linked-list to check whether there&#039;s already an entry with a matching Id. If there&#039;s a matching Id, return 0 if the size matches, otherwise return error.&lt;br /&gt;
&lt;br /&gt;
When no entry is found, a new entry is added with a buffer allocated using the input size.&lt;br /&gt;
&lt;br /&gt;
=== ReadGeneralStorageForDebug ===&lt;br /&gt;
Takes a type-0x22 output buffer, two input u64s Id and offset, returns an output u64 out_size.&lt;br /&gt;
&lt;br /&gt;
The high-byte of Id must be 0.&lt;br /&gt;
&lt;br /&gt;
Reads data from the buffer previously allocated by [[#CreateGeneralStorageForDebug|CreateGeneralStorageForDebug]] with the specified Id.&lt;br /&gt;
&lt;br /&gt;
The out_size is always the buffer-size (an error is thrown when bounds-check fails).&lt;br /&gt;
&lt;br /&gt;
=== WriteGeneralStorageForDebug ===&lt;br /&gt;
Takes a type-0x21 input buffer, two input u64s Id and offset.&lt;br /&gt;
&lt;br /&gt;
Same as [[#ReadGeneralStorageForDebug|ReadGeneralStorageForDebug]] except this writes into the buffer, and no out_size.&lt;br /&gt;
&lt;br /&gt;
== IStorage ==&lt;br /&gt;
This is &amp;quot;nn::am::service::IStorage&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || Open || No input. Returns an [[#IStorageAccessor]].&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [2.0.0+] OpenTransferStorage || No input. Returns an [[#ITransferStorageAccessor]].&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Open can only be used when the IStorage was created by [[#CreateStorage]] or [[#CreateTransferMemoryStorage]]. OpenTransferStorage can only be used when the IStorage was created by [[#CreateHandleStorage]].&lt;br /&gt;
&lt;br /&gt;
Only 1 *Accessor session can be open for each IStorage at a time.&lt;br /&gt;
&lt;br /&gt;
== IStorageAccessor ==&lt;br /&gt;
This is &amp;quot;nn::am::service::IStorageAccessor&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetSize || No input. Returns an s64.&lt;br /&gt;
|-&lt;br /&gt;
| 10 || Write || Takes an input s64 and a type-0x21 input buffer.&lt;br /&gt;
|-&lt;br /&gt;
| 11 || Read || Takes an input s64 and a type-0x22 output buffer.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== ITransferStorageAccessor ==&lt;br /&gt;
This is &amp;quot;nn::am::service::ITransferStorageAccessor&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name || Notes&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetSize || No input. Returns an output s64.&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GetHandle || No input. Returns an output s64 and handle.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
These commands return the data originally from [[#CreateHandleStorage]] input, both return the same s64.&lt;br /&gt;
&lt;br /&gt;
== IFloatingLibraryAppletAccepter ==&lt;br /&gt;
This is &amp;quot;nn::am::service::IFloatingLibraryAppletAccepter&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This interface has no commands.&lt;br /&gt;
&lt;br /&gt;
= appletOE =&lt;br /&gt;
This is &amp;quot;nn::am::service::IApplicationProxyService&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 2000 || [S2] [[#OpenCompatApplicationFunctions|OpenCompatApplicationFunctions]]&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#OpenApplicationProxy]]&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [S2] [[#OpenApplicationProxy2|OpenApplicationProxy2]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
This is used by all regular-applications, including [[flog]] and &amp;quot;Retail Interactive Display Menu&amp;quot;. Only one session can be open for this service at a time.&lt;br /&gt;
&lt;br /&gt;
== OpenApplicationProxy ==&lt;br /&gt;
Takes a reserved input u64 (official user-processes use hard-coded value 0), a PID, and a process copy-handle (cur-proc handle alias). Returns an [[#IApplicationProxy]].&lt;br /&gt;
&lt;br /&gt;
On failure, official user-processes will retry using this command in a loop while the retval is 0x19280, with svcSleepThread(10000000) being called first.&lt;br /&gt;
&lt;br /&gt;
== OpenApplicationProxy2 ==&lt;br /&gt;
Unofficial name.&lt;br /&gt;
&lt;br /&gt;
Takes an input u32, an u64 pid_reserved, a PID, and a process copy-handle (cur-proc handle alias). Returns an [[#IApplicationProxy]].&lt;br /&gt;
&lt;br /&gt;
= idle:sys =&lt;br /&gt;
This is &amp;quot;nn::idle::detail::IPolicyManagerSystem&amp;quot;&lt;br /&gt;
&lt;br /&gt;
This was moved to [[OMM_services|omm]] with [14.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetAutoPowerDownEvent&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [7.0.0+] IsAutoPowerDownRequested ([1.0.0-3.0.2] )&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [1.0.0-3.0.2]&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [[#SetHandlingContext]]&lt;br /&gt;
|-&lt;br /&gt;
| 4 || LoadAndApplySettings&lt;br /&gt;
|-&lt;br /&gt;
| 5 || ReportUserIsActive&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== SetHandlingContext ==&lt;br /&gt;
[3.0.0+] Now takes an additional 0x10-bytes of input.&lt;br /&gt;
&lt;br /&gt;
[13.0.0+] Total input size is now 0x30 instead of 0x38.&lt;br /&gt;
&lt;br /&gt;
= omm =&lt;br /&gt;
This is &amp;quot;nn::omm::detail::IOperationModeManager&amp;quot;&lt;br /&gt;
&lt;br /&gt;
Operation Mode Manager (OMM) is a service responsible for arbitrating the operation changes between docked and handheld modes.&lt;br /&gt;
Besides [[PTM_services|PTM]], this is the only service that interacts with the [[Dock]] through [[USB_services|usb:pd*]].&lt;br /&gt;
&lt;br /&gt;
This was moved to [[OMM_services|omm]] with [14.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetOperationMode&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GetOperationModeChangeEvent&lt;br /&gt;
|-&lt;br /&gt;
| 2 || EnableAudioVisual&lt;br /&gt;
|-&lt;br /&gt;
| 3 || DisableAudioVisual&lt;br /&gt;
|-&lt;br /&gt;
| 4 || EnterSleepAndWait&lt;br /&gt;
|-&lt;br /&gt;
| 5 || GetCradleStatus&lt;br /&gt;
|-&lt;br /&gt;
| 6 || FadeInDisplay&lt;br /&gt;
|-&lt;br /&gt;
| 7 || FadeOutDisplay&lt;br /&gt;
|-&lt;br /&gt;
| 8 || [2.0.0+] GetCradleFwVersion&lt;br /&gt;
|-&lt;br /&gt;
| 9 || [2.0.0+] NotifyCecSettingsChanged&lt;br /&gt;
|-&lt;br /&gt;
| 10 || [3.0.0+] SetOperationModePolicy&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [3.0.0+] GetDefaultDisplayResolution&lt;br /&gt;
|-&lt;br /&gt;
| 12 || [3.0.0+] GetDefaultDisplayResolutionChangeEvent&lt;br /&gt;
|-&lt;br /&gt;
| 13 || [3.0.0+] UpdateDefaultDisplayResolution&lt;br /&gt;
|-&lt;br /&gt;
| 14 || [3.0.0+] ShouldSleepOnBoot&lt;br /&gt;
|-&lt;br /&gt;
| 15 || [4.0.0+] NotifyHdcpApplicationExecutionStarted&lt;br /&gt;
|-&lt;br /&gt;
| 16 || [4.0.0+] NotifyHdcpApplicationExecutionFinished&lt;br /&gt;
|-&lt;br /&gt;
| 17 || [4.0.0+] NotifyHdcpApplicationDrawingStarted&lt;br /&gt;
|-&lt;br /&gt;
| 18 || [4.0.0+] NotifyHdcpApplicationDrawingFinished&lt;br /&gt;
|-&lt;br /&gt;
| 19 || [4.0.0+] GetHdcpAuthenticationFailedEvent&lt;br /&gt;
|-&lt;br /&gt;
| 20 || [4.0.0+] GetHdcpAuthenticationFailedEmulationEnabled&lt;br /&gt;
|-&lt;br /&gt;
| 21 || [4.0.0+] SetHdcpAuthenticationFailedEmulation&lt;br /&gt;
|-&lt;br /&gt;
| 22 || [4.0.0+] GetHdcpStateChangeEvent&lt;br /&gt;
|-&lt;br /&gt;
| 23 || [4.0.0+] GetHdcpState&lt;br /&gt;
|-&lt;br /&gt;
| 24 || [5.0.0+] ShowCardUpdateProcessing&lt;br /&gt;
|-&lt;br /&gt;
| 25 || [5.0.0+] SetApplicationCecSettingsAndNotifyChanged&lt;br /&gt;
|-&lt;br /&gt;
| 26 || [7.0.0+] [[#GetOperationModeSystemInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 27 || [9.0.0+] GetAppletFullAwakingSystemEvent&lt;br /&gt;
|-&lt;br /&gt;
| 28 || [12.0.0+] [[#CreateCradleFirmwareUpdater]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== GetOperationModeSystemInfo ==&lt;br /&gt;
No input, returns an output u32.&lt;br /&gt;
&lt;br /&gt;
This is used by [[#GetOperationModeSystemInfo|ICommonStateGetter GetOperationModeSystemInfo]].&lt;br /&gt;
&lt;br /&gt;
== CreateCradleFirmwareUpdater ==&lt;br /&gt;
No input. Returns an [[#ICradleFirmwareUpdater]].&lt;br /&gt;
&lt;br /&gt;
== ICradleFirmwareUpdater ==&lt;br /&gt;
This is &amp;quot;nn::am::service::ICradleFirmwareUpdater&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [12.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || Start&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Finish&lt;br /&gt;
|-&lt;br /&gt;
| 2 || GetUpdateDeviceStatus&lt;br /&gt;
|-&lt;br /&gt;
| 3 || GetUpdateProgress&lt;br /&gt;
|-&lt;br /&gt;
| 4 || GetUpdateDeviceStatusChangeEvent&lt;br /&gt;
|-&lt;br /&gt;
| 5 || GetUpdateProgress2&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= spsm =&lt;br /&gt;
This is &amp;quot;nn::spsm::detail::IPowerStateInterface&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was moved to [[OMM_services|omm]] with [14.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetCurrentState&lt;br /&gt;
|-&lt;br /&gt;
| 1 || EnterSleep&lt;br /&gt;
|-&lt;br /&gt;
| 2 || GetLastWakeReason&lt;br /&gt;
|-&lt;br /&gt;
| 3 || Shutdown&lt;br /&gt;
|-&lt;br /&gt;
| 4 || GetNotificationMessageEventHandle&lt;br /&gt;
|-&lt;br /&gt;
| 5 || ReceiveNotificationMessage&lt;br /&gt;
|-&lt;br /&gt;
| 6 || AnalyzeLogForLastSleepWakeSequence&lt;br /&gt;
|-&lt;br /&gt;
| 7 || ResetEventLog&lt;br /&gt;
|-&lt;br /&gt;
| 8 || AnalyzePerformanceLogForLastSleepWakeSequence&lt;br /&gt;
|-&lt;br /&gt;
| 9 || ChangeHomeButtonLongPressingTime&lt;br /&gt;
|-&lt;br /&gt;
| 10 || PutErrorState&lt;br /&gt;
|-&lt;br /&gt;
| 11 || [1.0.0-3.0.2] InvalidateCurrentHomeButtonPressing&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[3.0.0+] Cmd11 now takes a total of 8-bytes of input.&lt;br /&gt;
&lt;br /&gt;
= tcap =&lt;br /&gt;
This is &amp;quot;nn::tcap::server::IManager&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was removed with [11.0.0+].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || GetContinuousHighSkinTemperatureEvent&lt;br /&gt;
|-&lt;br /&gt;
| 1 || SetOperationMode&lt;br /&gt;
|-&lt;br /&gt;
| 2 || LoadAndApplySettings&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= caps:su =&lt;br /&gt;
This is &amp;quot;nn::capsrv::sf::IScreenShotApplicationService&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [6.0.0+].&lt;br /&gt;
&lt;br /&gt;
This can be used by applications to save screenshots.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 32 || [7.0.0+] [[#SetShimLibraryVersion]]&lt;br /&gt;
|-&lt;br /&gt;
| 201 || [[#SaveScreenShot]]&lt;br /&gt;
|-&lt;br /&gt;
| 203 || [[#SaveScreenShotEx0]]&lt;br /&gt;
|-&lt;br /&gt;
| 205 || [8.0.0+] [[#SaveScreenShotEx1]]&lt;br /&gt;
|-&lt;br /&gt;
| 210 || [[#SaveScreenShotEx2]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== SetShimLibraryVersion ==&lt;br /&gt;
Takes a total of 0x10-bytes of input and a PID, no output.&lt;br /&gt;
&lt;br /&gt;
This is a wrapper for [[Capture_services|caps:c]] cmd33. Commands &#039;&#039;&#039;SaveScreenShot&#039;&#039;&#039;, &#039;&#039;&#039;SaveScreenShotEx0&#039;&#039;&#039;, &#039;&#039;&#039;SaveScreenShotEx1&#039;&#039;&#039; and &#039;&#039;&#039;SaveScreenShotEx2&#039;&#039;&#039; are wrappers for [[Display_services|caps:sc]] cmd210.&lt;br /&gt;
&lt;br /&gt;
== SaveScreenShot ==&lt;br /&gt;
Takes two input u32s, an u64 AppletResourceUserId, a PID, and a type-0x45 input buffer containing image data. Returns an [[Capture_services|ApplicationAlbumEntry]].&lt;br /&gt;
&lt;br /&gt;
Official user-processes doesn&#039;t use this, instead [[#SaveScreenShotEx0]] is used: ScreenShotAttributeEx0 is all-zero, except +4 is set to an input u32 and u32 +0xC = 0x1.&lt;br /&gt;
&lt;br /&gt;
This cmd internally uses an all-zero ScreenShotAttributeEx0, with u32 +0 = input u32 and u32 +0x8 = 0x3.&lt;br /&gt;
&lt;br /&gt;
== SaveScreenShotEx0 ==&lt;br /&gt;
Takes an input 0x40-byte struct &#039;&#039;&#039;ScreenShotAttributeEx0&#039;&#039;&#039;, an input u32, an input u64 AppletResourceUserId, a PID, and a type-0x45 input buffer containing image data. Returns an [[Capture_services|ApplicationAlbumEntry]].&lt;br /&gt;
&lt;br /&gt;
== SaveScreenShotEx1 ==&lt;br /&gt;
Takes an input 0x40-byte struct &#039;&#039;&#039;ScreenShotAttributeEx0&#039;&#039;&#039;, an input u32, an input u64 AppletResourceUserId, a PID, a type-0x15 input buffer containing an [[Capture_services|ApplicationData]], and a type-0x45 input buffer containing image data. Returns an [[Capture_services|ApplicationAlbumEntry]].&lt;br /&gt;
&lt;br /&gt;
== SaveScreenShotEx2 ==&lt;br /&gt;
Takes an input 0x40-byte struct &#039;&#039;&#039;ScreenShotAttributeEx0&#039;&#039;&#039;, an input u32, an input u64 AppletResourceUserId, a type-0x15 input buffer containing an [[Capture_services|UserIdList]], and a type-0x45 input buffer containing image data. Returns an [[Capture_services|ApplicationAlbumEntry]].&lt;br /&gt;
&lt;br /&gt;
= apm =&lt;br /&gt;
This is &amp;quot;nn::am::service::IApmManager&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was added with [8.0.0+].&lt;br /&gt;
&lt;br /&gt;
[S2] Official sw no longer uses this (stubbed out).&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#OpenSession]]&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GetPerformanceMode&lt;br /&gt;
|-&lt;br /&gt;
| 6 || [7.0.0+] [[#IsCpuOverclockEnabled]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== OpenSession ==&lt;br /&gt;
Returns an [[#ISession]].&lt;br /&gt;
&lt;br /&gt;
== IsCpuOverclockEnabled ==&lt;br /&gt;
No input, returns an output u8 bool.&lt;br /&gt;
&lt;br /&gt;
== ISession ==&lt;br /&gt;
This is &amp;quot;nn::am::service::IApmSession&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || SetPerformanceConfiguration&lt;br /&gt;
|-&lt;br /&gt;
| 1 || GetPerformanceConfiguration&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [8.0.0+] SetCpuOverclockEnabled&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= (S2) adraw:a =&lt;br /&gt;
This is &amp;quot;nn::appletdraw::sfif::IAppletRoot&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#OpenResourceSession]]&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [[#OpenAppletSession]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== OpenResourceSession ==&lt;br /&gt;
Unofficial name. &lt;br /&gt;
&lt;br /&gt;
Takes a PID and an input [[#AppletResourceUserId|AppletResourceUserId]]. Returns a [[#IResourceSession]].&lt;br /&gt;
&lt;br /&gt;
== OpenAppletSession ==&lt;br /&gt;
Unofficial name.&lt;br /&gt;
&lt;br /&gt;
Takes a PID and an input [[#AppletResourceUserId|AppletResourceUserId]]. Returns a [[#IAppletSession]].&lt;br /&gt;
&lt;br /&gt;
== IResourceSession ==&lt;br /&gt;
This is &amp;quot;nn::appletdraw::sfif::IResourceSession&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#Ping|Ping]]&lt;br /&gt;
|-&lt;br /&gt;
| 10 ||  &lt;br /&gt;
|-&lt;br /&gt;
| 11 ||  &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Ping ===&lt;br /&gt;
Unofficial name.&lt;br /&gt;
&lt;br /&gt;
Takes an input u64. Returns an output u64.&lt;br /&gt;
&lt;br /&gt;
The output u64 should match the input u64. Official software sends the current system tick value.&lt;br /&gt;
&lt;br /&gt;
=== Cmd10 ===&lt;br /&gt;
Takes a handle, a u64 and an int. Returns a handle.&lt;br /&gt;
&lt;br /&gt;
=== Cmd11 ===&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
== IAppletSession ==&lt;br /&gt;
This is &amp;quot;nn::appletdraw::sfif::IAppletSession&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[#Ping|Ping]]&lt;br /&gt;
|-&lt;br /&gt;
| 2 || [[#GetEvent|GetEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 3 || [20.1.1+] &lt;br /&gt;
|-&lt;br /&gt;
| 10 ||  &lt;br /&gt;
|-&lt;br /&gt;
| 11 ||  &lt;br /&gt;
|-&lt;br /&gt;
| 12 ||  &lt;br /&gt;
|-&lt;br /&gt;
| 13 ||  &lt;br /&gt;
|-&lt;br /&gt;
| 15 ||  &lt;br /&gt;
|-&lt;br /&gt;
| 16 || [20.1.1+]&lt;br /&gt;
|-&lt;br /&gt;
| 17 || [20.1.1+]&lt;br /&gt;
|-&lt;br /&gt;
| 18 || [20.1.1+]&lt;br /&gt;
|-&lt;br /&gt;
| 19 || [20.1.1+]&lt;br /&gt;
|-&lt;br /&gt;
| 21 ||  &lt;br /&gt;
|-&lt;br /&gt;
| 22 ||  &lt;br /&gt;
|-&lt;br /&gt;
| 23 || [20.1.1+]&lt;br /&gt;
|-&lt;br /&gt;
| 24 || [20.1.1+]&lt;br /&gt;
|-&lt;br /&gt;
| 31 || [[#GetFrameBufferInfo|GetFrameBufferInfo]]&lt;br /&gt;
|-&lt;br /&gt;
| 8001 || [[#GetFrameBufferInfoForDebug|GetFrameBufferInfoForDebug]]&lt;br /&gt;
|-&lt;br /&gt;
| 8003 || [19.0.0-19.1.0]&lt;br /&gt;
|-&lt;br /&gt;
| 8004 ||  &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== GetEvent ===&lt;br /&gt;
Unofficial name.&lt;br /&gt;
&lt;br /&gt;
No input. Returns an output Event handle.&lt;br /&gt;
&lt;br /&gt;
=== Cmd3 ===&lt;br /&gt;
Takes a handle. No output.&lt;br /&gt;
&lt;br /&gt;
=== Cmd10 ===&lt;br /&gt;
Takes an input u32. No output.&lt;br /&gt;
&lt;br /&gt;
=== Cmd11 ===&lt;br /&gt;
Takes an input u32. No output.&lt;br /&gt;
&lt;br /&gt;
=== Cmd12 ===&lt;br /&gt;
Takes an input u64. Returns an output u32.&lt;br /&gt;
&lt;br /&gt;
=== Cmd13 ===&lt;br /&gt;
Takes an input u32. Returns an output u32.&lt;br /&gt;
&lt;br /&gt;
=== Cmd15 ===&lt;br /&gt;
Takes an input u32. Returns three output u32s.&lt;br /&gt;
&lt;br /&gt;
=== Cmd16 ===&lt;br /&gt;
No input. Returns an output u32.&lt;br /&gt;
&lt;br /&gt;
=== Cmd17 ===&lt;br /&gt;
Takes an input u32. Returns an output u32 and an output u16.&lt;br /&gt;
&lt;br /&gt;
=== Cmd18 ===&lt;br /&gt;
Takes an input u32. Returns three output u32s and an output u16.&lt;br /&gt;
&lt;br /&gt;
=== Cmd19 ===&lt;br /&gt;
Takes an input u32. Returns an output u32 and an output u16.&lt;br /&gt;
&lt;br /&gt;
=== Cmd21 ===&lt;br /&gt;
Takes an input u32. Returns a struct of size 0x40.&lt;br /&gt;
&lt;br /&gt;
=== Cmd22 ===&lt;br /&gt;
Takes a struct of size 0x20. Returns a struct of size 0x40.&lt;br /&gt;
&lt;br /&gt;
=== Cmd23 ===&lt;br /&gt;
No input. Returns a struct of size 0xC8.&lt;br /&gt;
&lt;br /&gt;
=== Cmd24 ===&lt;br /&gt;
Takes an ipc-buf with size 0xD8. No output.&lt;br /&gt;
&lt;br /&gt;
=== GetFrameBufferInfo ===&lt;br /&gt;
Unofficial name.&lt;br /&gt;
&lt;br /&gt;
No input. Returns an [[#(S2)_AdrawFrameBufferInfo|AdrawFrameBufferInfo]].&lt;br /&gt;
&lt;br /&gt;
[[#(S2)_AdrawFrameBufferInfo|Id]] is &amp;quot;adrawfb&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
=== GetFrameBufferInfoForDebug ===&lt;br /&gt;
Unofficial name.&lt;br /&gt;
&lt;br /&gt;
No input. Returns an [[#(S2)_AdrawFrameBufferInfo|AdrawFrameBufferInfo]].&lt;br /&gt;
&lt;br /&gt;
=== Cmd8003 ===&lt;br /&gt;
Takes an input u64. Returns a struct with size 0x18.&lt;br /&gt;
&lt;br /&gt;
=== Cmd8004 ===&lt;br /&gt;
Takes an input u32. Returns an output u64.&lt;br /&gt;
&lt;br /&gt;
= (S2) appletOE =&lt;br /&gt;
This is &amp;quot;nn::am::service::IApplicationProxyServiceForNxCompat&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 0 || [[#OpenApplicationProxy]]&lt;br /&gt;
|-&lt;br /&gt;
| 2000 || [[#OpenCompatApplicationFunctions]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== OpenCompatApplicationFunctions ==&lt;br /&gt;
No input. Returns an [[#INxCompatApplicationFunctions]].&lt;br /&gt;
&lt;br /&gt;
== INxCompatApplicationFunctions ==&lt;br /&gt;
This is &amp;quot;nn::am::service::INxCompatApplicationFunctions&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Cmd || Name&lt;br /&gt;
|-&lt;br /&gt;
| 2000 || [[#GetGraphicsSupervisorForNxCompat]]&lt;br /&gt;
|-&lt;br /&gt;
| 2001 || &lt;br /&gt;
|-&lt;br /&gt;
| 2002 ||  &lt;br /&gt;
|-&lt;br /&gt;
| 2003 || [[#SetCopyright]]&lt;br /&gt;
|-&lt;br /&gt;
| 2004 ||  &lt;br /&gt;
|-&lt;br /&gt;
| 2010 ||  &lt;br /&gt;
|-&lt;br /&gt;
| 2020 || [[#Initialize]]&lt;br /&gt;
|-&lt;br /&gt;
| 2030 || [[#GetVsyncEvent]]&lt;br /&gt;
|-&lt;br /&gt;
| 2040 || [[#GetVsyncTimestamp]]&lt;br /&gt;
|-&lt;br /&gt;
| 2050 || &lt;br /&gt;
|-&lt;br /&gt;
| 2060 || &lt;br /&gt;
|-&lt;br /&gt;
| 2070 || [[#CreateMovieMaker]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== GetGraphicsSupervisorForNxCompat ===&lt;br /&gt;
Unofficial name.&lt;br /&gt;
&lt;br /&gt;
No input. Returns an output TIPC handle to [[Switch_2:_GSV_services|GraphicsSupervisor]].&lt;br /&gt;
&lt;br /&gt;
Same as [[#GetGraphicsSupervisor]] but for compat mode.&lt;br /&gt;
&lt;br /&gt;
=== SetCopyright ===&lt;br /&gt;
Unofficial name.&lt;br /&gt;
&lt;br /&gt;
Takes an input bool. No output.&lt;br /&gt;
&lt;br /&gt;
Called directly after &amp;quot;nn::vi::WriteToCopyrightFramebuffer&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
=== Initialize ===&lt;br /&gt;
Unofficial name.&lt;br /&gt;
&lt;br /&gt;
No input/output.&lt;br /&gt;
&lt;br /&gt;
Called during init.&lt;br /&gt;
&lt;br /&gt;
=== GetVsyncEvent ===&lt;br /&gt;
Unofficial name.&lt;br /&gt;
&lt;br /&gt;
No input. Returns an Event handle.&lt;br /&gt;
&lt;br /&gt;
=== GetVsyncTimestamp ===&lt;br /&gt;
Unofficial name.&lt;br /&gt;
&lt;br /&gt;
No input. Returns an output u64.&lt;br /&gt;
&lt;br /&gt;
When event from [[#GetVsyncEvent]] triggers, this returns a timestamp.&lt;br /&gt;
&lt;br /&gt;
= Library Applets =&lt;br /&gt;
This section documents library applet launching.&lt;br /&gt;
&lt;br /&gt;
Before starting the applet, [[#IStorage]]s are [[#ILibraryAppletCreator|created]] and written, then passed to [[#ILibraryAppletAccessor]] PushInData. The [[#IStorage]] session is closed afterwards. The first [[#IStorage]] is [[#CommonArguments]], followed by any applet-specific [[#IStorage]]s.&lt;br /&gt;
&lt;br /&gt;
Once the applet finishes running successfully, [[#ILibraryAppletAccessor]] PopOutData can be used to get the applet-specific [[#IStorage]] containing the applet output data.&lt;br /&gt;
&lt;br /&gt;
== CommonArguments ==&lt;br /&gt;
The first [[#CreateStorage|IStorage]] passed to applets should contain the common library applet arguments. This is populated by &amp;lt;code&amp;gt;nn::la::CommonArgumentsWriter&amp;lt;/code&amp;gt; and has the following format.&lt;br /&gt;
&lt;br /&gt;
This struct is 0x20-bytes.&lt;br /&gt;
&lt;br /&gt;
Official sw handles the first 8-bytes separately, which is a header. With CommonArguments version 0x0, the header is 4-bytes, while starting with version 0x1 it&#039;s 8-bytes.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset || Size || Typical Value || Notes &lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 4 || 1 || Common Arguments version&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || 4 || 0x20 || Common Arguments size&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 4 || || Library applet version (API version)&lt;br /&gt;
|-&lt;br /&gt;
| 0xC || 4 || 0 || Theme color&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 1 || 0 || Play startup sound&lt;br /&gt;
|-&lt;br /&gt;
| 0x18 || 8 || N/A || System tick (see [[SVC#svcGetSystemTick|svcGetSystemTick]])&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= AppletId =&lt;br /&gt;
This is &amp;quot;nn::applet::AppletId&amp;quot;. See also [[:Category:Library Applets]].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! ProgramId&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x00000000&lt;br /&gt;
| &lt;br /&gt;
| None&lt;br /&gt;
|-&lt;br /&gt;
| 0x00000001&lt;br /&gt;
| &lt;br /&gt;
| Application (not valid for use with LibraryApplets)&lt;br /&gt;
|-&lt;br /&gt;
| 0x00000002&lt;br /&gt;
| 0x010000000000100C&lt;br /&gt;
| OverlayApplet (overlayDisp)&lt;br /&gt;
|-&lt;br /&gt;
| 0x00000003&lt;br /&gt;
| 0x0100000000001000&lt;br /&gt;
| SystemAppletMenu (qlaunch)&lt;br /&gt;
|-&lt;br /&gt;
| 0x00000004&lt;br /&gt;
| 0x0100000000001012&lt;br /&gt;
| SystemApplication (starter)&lt;br /&gt;
|-&lt;br /&gt;
| 0x0000000A&lt;br /&gt;
| 0x0100000000001001&lt;br /&gt;
| [[Auth_Applet|LibraryAppletAuth (auth)]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x0000000B&lt;br /&gt;
| 0x0100000000001002&lt;br /&gt;
| [[Cabinet_Applet|LibraryAppletCabinet (cabinet)]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x0000000C&lt;br /&gt;
| 0x0100000000001003&lt;br /&gt;
| [[Controller_Applet|LibraryAppletController (controller)]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x0000000D&lt;br /&gt;
| 0x0100000000001004&lt;br /&gt;
| LibraryAppletDataErase (dataErase)&lt;br /&gt;
|-&lt;br /&gt;
| 0x0000000E&lt;br /&gt;
| 0x0100000000001005&lt;br /&gt;
| [[Error_Applet|LibraryAppletError (error)]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x0000000F&lt;br /&gt;
| 0x0100000000001006&lt;br /&gt;
| LibraryAppletNetConnect (netConnect)&lt;br /&gt;
|-&lt;br /&gt;
| 0x00000010&lt;br /&gt;
| 0x0100000000001007&lt;br /&gt;
| [[Profile_Selector|LibraryAppletPlayerSelect (playerSelect)]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x00000011&lt;br /&gt;
| 0x0100000000001008&lt;br /&gt;
| [[Software_Keyboard|LibraryAppletSwkbd (swkbd)]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x00000012&lt;br /&gt;
| 0x0100000000001009&lt;br /&gt;
| [[MiiEdit_Applet|LibraryAppletMiiEdit (miiEdit)]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x00000013&lt;br /&gt;
| [22.0.0+] 0x0100000000001043 ([1.0.0-21.2.0] 0x010000000000100A)&lt;br /&gt;
| [[Internet_Browser#010000000000100A|LibraryAppletWeb (web)]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x00000014&lt;br /&gt;
| 0x010000000000100B&lt;br /&gt;
| [[Internet_Browser#ShopN|LibraryAppletShop (shop)]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x00000015&lt;br /&gt;
| 0x010000000000100D&lt;br /&gt;
| [[Album_Applet|LibraryAppletPhotoViewer (photoViewer)]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x00000016&lt;br /&gt;
| 0x010000000000100E&lt;br /&gt;
| LibraryAppletSet (set)&lt;br /&gt;
|-&lt;br /&gt;
| 0x00000017&lt;br /&gt;
| 0x010000000000100F&lt;br /&gt;
| [[Internet_Browser#Offline_Applet|LibraryAppletOfflineWeb (offlineWeb)]] (LibraryAppletOfflineWebApp_0 in Ounce)&lt;br /&gt;
|-&lt;br /&gt;
| 0x00000018&lt;br /&gt;
| [22.0.0+] 0x0100000000001042 ([1.0.0-21.2.0] 0x0100000000001010)&lt;br /&gt;
| [[Internet_Browser#Whitelisted_Applets|LibraryAppletLoginShare (loginShare)]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x00000019&lt;br /&gt;
| [22.0.0+] 0x0100000000001043 ([1.0.0-21.2.0] 0x0100000000001011)&lt;br /&gt;
| [[Internet_Browser#WifiWebAuthApplet|LibraryAppletWifiWebAuth (wifiWebAuth)]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x0000001A&lt;br /&gt;
| 0x0100000000001013&lt;br /&gt;
| [[MyPage_Applet|LibraryAppletMyPage (myPage)]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x0000001B&lt;br /&gt;
| 0x010000000000101A&lt;br /&gt;
| LibraryAppletGift (gift)&lt;br /&gt;
|-&lt;br /&gt;
| 0x0000001C&lt;br /&gt;
| 0x010000000000101C&lt;br /&gt;
| LibraryAppletUserMigration (userMigration)&lt;br /&gt;
|-&lt;br /&gt;
| 0x0000001D&lt;br /&gt;
| 0x010000000000101D&lt;br /&gt;
| [9.0.0+] LibraryAppletPreomiaSys (EncounterSys)&lt;br /&gt;
|-&lt;br /&gt;
| 0x0000001E&lt;br /&gt;
| 0x0100000000001020&lt;br /&gt;
| [9.0.0+] LibraryAppletStory (story)&lt;br /&gt;
|-&lt;br /&gt;
| 0x0000001F&lt;br /&gt;
| 0x010070000E3C0000&lt;br /&gt;
| [9.0.0+] LibraryAppletPreomiaUsr (EncounterUsr)&lt;br /&gt;
|-&lt;br /&gt;
| 0x00000020&lt;br /&gt;
| 0x010086000E49C000&lt;br /&gt;
| [9.0.0+] LibraryAppletPreomiaUsrDummy (EncounterUsrDummy)&lt;br /&gt;
|-&lt;br /&gt;
| 0x00000021&lt;br /&gt;
| 0x0100000000001038&lt;br /&gt;
| [10.0.0+] LibraryAppletSample (sample)&lt;br /&gt;
|-&lt;br /&gt;
| 0x00000022&lt;br /&gt;
| 0x0100000000001007&lt;br /&gt;
| [13.0.0+] LibraryAppletPromoteQualification (playerSelect)&lt;br /&gt;
|-&lt;br /&gt;
| 0x00000032&lt;br /&gt;
| 0x010000000000100F&lt;br /&gt;
| [17.0.0+] LibraryAppletOfflineWebApp_3 ([[Internet_Browser#Offline_Applet|LibraryAppletOfflineWeb (offlineWeb)]] in NX)&lt;br /&gt;
|-&lt;br /&gt;
| 0x00000033&lt;br /&gt;
| 0x010000000000100F&lt;br /&gt;
| [17.0.0+] LibraryAppletOfflineWebSystem ([[Internet_Browser#Offline_Applet|LibraryAppletOfflineWeb (offlineWeb)]] in NX)&lt;br /&gt;
|-&lt;br /&gt;
| 0x00000035&lt;br /&gt;
| [22.0.0+] 0x0100000000001042 ([17.0.0-21.2.0] 0x0100000000001010, [16.0.0-16.1.0] 0x0100000000001042)&lt;br /&gt;
| [17.0.0+] LibraryAppletLhub ([16.0.0-16.1.0] ) ([[Internet_Browser#Whitelisted_Applets|LibraryAppletLoginShare (loginShare)]] in NX)&lt;br /&gt;
|-&lt;br /&gt;
| 0x00000036&lt;br /&gt;
| [22.0.0+] 0x0100000000001042 ([17.0.0-21.2.0] 0x0100000000001010, [16.0.0-16.1.0] 0x0100000000001042)&lt;br /&gt;
| [17.0.0+] LibraryAppletLogin ([16.0.0-16.1.0] ) ([[Internet_Browser#Whitelisted_Applets|LibraryAppletLoginShare (loginShare)]] in NX)&lt;br /&gt;
|-&lt;br /&gt;
| 0x00000037&lt;br /&gt;
| [22.0.0+] 0x0100000000001042 ([17.0.0-21.2.0] 0x0100000000001010, [16.0.0-16.1.0] 0x0100000000001042)&lt;br /&gt;
| [17.0.0+] LibraryAppletShare ([16.0.0-16.1.0] ) ([[Internet_Browser#Whitelisted_Applets|LibraryAppletLoginShare (loginShare)]] in NX)&lt;br /&gt;
|-&lt;br /&gt;
| 0x00000038&lt;br /&gt;
| 0x0100000000001043&lt;br /&gt;
| [16.0.0-16.1.0]&lt;br /&gt;
|-&lt;br /&gt;
| 0x00000050&lt;br /&gt;
| 0x0100000000001007&lt;br /&gt;
| [18.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 0x00000051&lt;br /&gt;
| 0x0100000000001007&lt;br /&gt;
| [18.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 0x00000052&lt;br /&gt;
| 0x0100000000001001&lt;br /&gt;
| [22.0.0+]&lt;br /&gt;
|-&lt;br /&gt;
| 0x00000064&lt;br /&gt;
| 0x0100000000001048&lt;br /&gt;
| [20.0.0+] [[Splay_Applet|splay]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x00000066&lt;br /&gt;
| 0x0100000000001054&lt;br /&gt;
| [21.0.0+] &lt;br /&gt;
|-&lt;br /&gt;
| 0x000003E8&lt;br /&gt;
| &lt;br /&gt;
| [10.0.0-16.1.0] DevlopmentTool&lt;br /&gt;
|-&lt;br /&gt;
| 0x000003F1&lt;br /&gt;
| 0x010000000000D619&lt;br /&gt;
| [10.0.0-16.1.0] CombinationLA&lt;br /&gt;
|-&lt;br /&gt;
| 0x000003F2&lt;br /&gt;
| 0x010000000000D610&lt;br /&gt;
| [10.0.0-16.1.0] AeSystemApplet&lt;br /&gt;
|-&lt;br /&gt;
| 0x000003F3&lt;br /&gt;
| 0x010000000000D611&lt;br /&gt;
| [10.0.0-16.1.0] AeOverlayApplet&lt;br /&gt;
|-&lt;br /&gt;
| 0x000003F4&lt;br /&gt;
| 0x010000000000D612&lt;br /&gt;
| [10.0.0-16.1.0] AeStarter&lt;br /&gt;
|-&lt;br /&gt;
| 0x000003F5&lt;br /&gt;
| 0x010000000000D613&lt;br /&gt;
| [10.0.0-16.1.0] AeLibraryAppletAlone&lt;br /&gt;
|-&lt;br /&gt;
| 0x000003F6&lt;br /&gt;
| 0x010000000000D614&lt;br /&gt;
| [10.0.0-16.1.0] AeLibraryApplet1&lt;br /&gt;
|-&lt;br /&gt;
| 0x000003F7&lt;br /&gt;
| 0x010000000000D615&lt;br /&gt;
| [10.0.0-16.1.0] AeLibraryApplet2&lt;br /&gt;
|-&lt;br /&gt;
| 0x000003F8&lt;br /&gt;
| 0x010000000000D616&lt;br /&gt;
| [10.0.0-16.1.0] AeLibraryApplet3&lt;br /&gt;
|-&lt;br /&gt;
| 0x000003F9&lt;br /&gt;
| 0x010000000000D617&lt;br /&gt;
| [10.0.0-16.1.0] AeLibraryApplet4&lt;br /&gt;
|-&lt;br /&gt;
| 0x000003FA&lt;br /&gt;
| 0x010000000000D60A&lt;br /&gt;
| [10.0.0-16.1.0] AppletISA&lt;br /&gt;
|-&lt;br /&gt;
| 0x000003FB&lt;br /&gt;
| 0x010000000000D60B&lt;br /&gt;
| [10.0.0-16.1.0] AppletIOA&lt;br /&gt;
|-&lt;br /&gt;
| 0x000003FC&lt;br /&gt;
| 0x010000000000D60C&lt;br /&gt;
| [10.0.0-16.1.0] AppletISTA&lt;br /&gt;
|-&lt;br /&gt;
| 0x000003FD&lt;br /&gt;
| 0x010000000000D60D&lt;br /&gt;
| [10.0.0-16.1.0] AppletILA1&lt;br /&gt;
|-&lt;br /&gt;
| 0x000003FE&lt;br /&gt;
| 0x010000000000D60E&lt;br /&gt;
| [10.0.0-16.1.0] AppletILA2&lt;br /&gt;
|-&lt;br /&gt;
| 0x0100000A&lt;br /&gt;
| &lt;br /&gt;
| [[Auth_Applet|LibraryAppletAuth]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x0100000B&lt;br /&gt;
| &lt;br /&gt;
| [[Cabinet_Applet|LibraryAppletCabinet]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x0100000C&lt;br /&gt;
| &lt;br /&gt;
| [[Controller_Applet|LibraryAppletController]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x0100000D&lt;br /&gt;
| &lt;br /&gt;
| [S2]&lt;br /&gt;
|-&lt;br /&gt;
| 0x0100000E&lt;br /&gt;
| &lt;br /&gt;
| [S2] LibraryAppletError&lt;br /&gt;
|-&lt;br /&gt;
| 0x01000010&lt;br /&gt;
| &lt;br /&gt;
| [S2] LibraryAppletPlayerSelect&lt;br /&gt;
|-&lt;br /&gt;
| 0x01010011&lt;br /&gt;
| &lt;br /&gt;
| [S2] SwkbdModeless&lt;br /&gt;
|-&lt;br /&gt;
| 0x01020011&lt;br /&gt;
| &lt;br /&gt;
| [S2] Swkbd&lt;br /&gt;
|-&lt;br /&gt;
| 0x01010012&lt;br /&gt;
| &lt;br /&gt;
| [S2] [[MiiEdit_Applet|LibraryAppletMiiEdit]] (for ShowMiiEdit)&lt;br /&gt;
|-&lt;br /&gt;
| 0x01020012&lt;br /&gt;
| &lt;br /&gt;
| [S2] [[MiiEdit_Applet|LibraryAppletMiiEdit]] (for AppendMii)&lt;br /&gt;
|-&lt;br /&gt;
| 0x01070012&lt;br /&gt;
| &lt;br /&gt;
| [S2] [[MiiEdit_Applet|LibraryAppletMiiEdit]] (for CreateMii)&lt;br /&gt;
|-&lt;br /&gt;
| 0x01080012&lt;br /&gt;
| &lt;br /&gt;
| [S2] [[MiiEdit_Applet|LibraryAppletMiiEdit]] (for EditMii)&lt;br /&gt;
|-&lt;br /&gt;
| 0x01000013&lt;br /&gt;
| &lt;br /&gt;
| [S2] OpenWeb&lt;br /&gt;
|-&lt;br /&gt;
| 0x01000014&lt;br /&gt;
| &lt;br /&gt;
| [S2] LibraryAppletShop&lt;br /&gt;
|-&lt;br /&gt;
| 0x01000015&lt;br /&gt;
| &lt;br /&gt;
| [S2] [[Album_Applet|Album]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x01000017&lt;br /&gt;
| &lt;br /&gt;
| [S2] LibraryAppletOffline (for Gen0)&lt;br /&gt;
|-&lt;br /&gt;
| 0x01000018&lt;br /&gt;
| &lt;br /&gt;
| [S2] [[Internet_Browser#Whitelisted_Applets|LibraryAppletLoginShare]] (for Lobby)&lt;br /&gt;
|-&lt;br /&gt;
| 0x0100001A&lt;br /&gt;
| &lt;br /&gt;
| [S2] [[MyPage_Applet|MyPageApplet]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x01000022&lt;br /&gt;
| &lt;br /&gt;
| [S2] LibraryAppletPromoteQualification&lt;br /&gt;
|-&lt;br /&gt;
| 0x01000024&lt;br /&gt;
| &lt;br /&gt;
| [S2] SplayApplet&lt;br /&gt;
|-&lt;br /&gt;
| 0x01030024&lt;br /&gt;
| &lt;br /&gt;
| [S2] SplayApplet&lt;br /&gt;
|-&lt;br /&gt;
| 0x01010025&lt;br /&gt;
| &lt;br /&gt;
| [S2] SaveDataBackup (System Settings menu for Save Data Cloud)&lt;br /&gt;
|-&lt;br /&gt;
| 0x01020025&lt;br /&gt;
| &lt;br /&gt;
| [S2] SaveDataBackup (Same as above except with ApplicationId specified)&lt;br /&gt;
|-&lt;br /&gt;
| 0x01000028&lt;br /&gt;
| &lt;br /&gt;
| [S2] Eula&lt;br /&gt;
|-&lt;br /&gt;
| 0x01000032&lt;br /&gt;
| &lt;br /&gt;
| [S2] LibraryAppletOfflineWebApp_3&lt;br /&gt;
|-&lt;br /&gt;
| 0x01000033&lt;br /&gt;
| &lt;br /&gt;
| [S2] LibraryAppletOfflineWebSystem&lt;br /&gt;
|-&lt;br /&gt;
| 0x01000035&lt;br /&gt;
| &lt;br /&gt;
| [S2] LibraryAppletLhub&lt;br /&gt;
|-&lt;br /&gt;
| 0x01000036&lt;br /&gt;
| &lt;br /&gt;
| [S2] LibraryAppletLogin&lt;br /&gt;
|-&lt;br /&gt;
| 0x01000037&lt;br /&gt;
| &lt;br /&gt;
| [S2] LibraryAppletShare&lt;br /&gt;
|-&lt;br /&gt;
| 0x01000050&lt;br /&gt;
| &lt;br /&gt;
| [S2] PlayerSelect&lt;br /&gt;
|-&lt;br /&gt;
| 0x01000051&lt;br /&gt;
| &lt;br /&gt;
| [S2] PlayerSelect&lt;br /&gt;
|-&lt;br /&gt;
| 0x01000052&lt;br /&gt;
| &lt;br /&gt;
| [S2] PlayerSelect&lt;br /&gt;
|-&lt;br /&gt;
| 0x01000065&lt;br /&gt;
| &lt;br /&gt;
| [S2] Chat (ForChatStart)&lt;br /&gt;
|-&lt;br /&gt;
| 0x01010065&lt;br /&gt;
| &lt;br /&gt;
| [S2] Chat (ForCameraConfiguration)&lt;br /&gt;
|-&lt;br /&gt;
| 0x01020065&lt;br /&gt;
| &lt;br /&gt;
| [S2] Chat (ForFullScreen)&lt;br /&gt;
|-&lt;br /&gt;
| 0x01030065&lt;br /&gt;
| &lt;br /&gt;
| [S2] Chat (ForCameraSharingGuide)&lt;br /&gt;
|-&lt;br /&gt;
| 0x700000C8&lt;br /&gt;
| 0x010000000000D65B&lt;br /&gt;
| [18.0.0+] &lt;br /&gt;
|-&lt;br /&gt;
| 0x700000C9&lt;br /&gt;
| 0x010000000000D65C&lt;br /&gt;
| [18.0.0+] &lt;br /&gt;
|-&lt;br /&gt;
| 0x700000DC&lt;br /&gt;
| 0x010000000000D619&lt;br /&gt;
| [17.0.0+] CombinationLA&lt;br /&gt;
|-&lt;br /&gt;
| 0x700000E6&lt;br /&gt;
| 0x010000000000D610&lt;br /&gt;
| [17.0.0+] AeSystemApplet&lt;br /&gt;
|-&lt;br /&gt;
| 0x700000E7&lt;br /&gt;
| 0x010000000000D611&lt;br /&gt;
| [17.0.0+] AeOverlayApplet&lt;br /&gt;
|-&lt;br /&gt;
| 0x700000E8&lt;br /&gt;
| 0x010000000000D612&lt;br /&gt;
| [17.0.0+] AeStarter&lt;br /&gt;
|-&lt;br /&gt;
| 0x700000E9&lt;br /&gt;
| 0x010000000000D613&lt;br /&gt;
| [17.0.0+] AeLibraryAppletAlone&lt;br /&gt;
|-&lt;br /&gt;
| 0x700000EA&lt;br /&gt;
| 0x010000000000D614&lt;br /&gt;
| [17.0.0+] AeLibraryApplet1&lt;br /&gt;
|-&lt;br /&gt;
| 0x700000EB&lt;br /&gt;
| 0x010000000000D615&lt;br /&gt;
| [17.0.0+] AeLibraryApplet2&lt;br /&gt;
|-&lt;br /&gt;
| 0x700000EC&lt;br /&gt;
| 0x010000000000D616&lt;br /&gt;
| [17.0.0+] AeLibraryApplet3&lt;br /&gt;
|-&lt;br /&gt;
| 0x700000ED&lt;br /&gt;
| 0x010000000000D617&lt;br /&gt;
| [17.0.0+] AeLibraryApplet4&lt;br /&gt;
|-&lt;br /&gt;
| 0x700000F0&lt;br /&gt;
| 0x010000000000D60A&lt;br /&gt;
| [17.0.0+] AppletISA&lt;br /&gt;
|-&lt;br /&gt;
| 0x700000F1&lt;br /&gt;
| 0x010000000000D60B&lt;br /&gt;
| [17.0.0+] AppletIOA&lt;br /&gt;
|-&lt;br /&gt;
| 0x700000F2&lt;br /&gt;
| 0x010000000000D60C&lt;br /&gt;
| [17.0.0+] AppletISTA&lt;br /&gt;
|-&lt;br /&gt;
| 0x700000F3&lt;br /&gt;
| 0x010000000000D60D&lt;br /&gt;
| [17.0.0+] AppletILA1&lt;br /&gt;
|-&lt;br /&gt;
| 0x700000F4&lt;br /&gt;
| 0x010000000000D60E&lt;br /&gt;
| [17.0.0+] AppletILA2&lt;br /&gt;
|-&lt;br /&gt;
| 0x700000FA&lt;br /&gt;
| 0x010000000000D677&lt;br /&gt;
| [20.1.0+] &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= LibraryAppletMode =&lt;br /&gt;
This is &amp;quot;nn::applet::LibraryAppletMode&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0&lt;br /&gt;
| AllForeground&lt;br /&gt;
|-&lt;br /&gt;
| 0x1&lt;br /&gt;
| PartialForeground&lt;br /&gt;
|-&lt;br /&gt;
| 0x2&lt;br /&gt;
| NoUi&lt;br /&gt;
|-&lt;br /&gt;
| 0x3&lt;br /&gt;
| PartialForegroundWithIndirectDisplay (see also [[#GetIndirectLayerConsumerHandle]], only used by swkbd [[Software_Keyboard|InlineKeyboard]])&lt;br /&gt;
|-&lt;br /&gt;
| 0x4&lt;br /&gt;
| AllForegroundInitiallyHidden (can be used by [7.0.0+] [[Internet_Browser|WebSession]])&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= AppletMessage =&lt;br /&gt;
This is &amp;quot;nn::am::AppletMessage&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || None&lt;br /&gt;
|-&lt;br /&gt;
| 1 || ChangeIntoForeground&lt;br /&gt;
|-&lt;br /&gt;
| 2 || ChangeIntoBackground&lt;br /&gt;
|-&lt;br /&gt;
| 4 || Exit&lt;br /&gt;
|-&lt;br /&gt;
| 6 || ApplicationExited&lt;br /&gt;
|-&lt;br /&gt;
| 7 || &lt;br /&gt;
|-&lt;br /&gt;
| 15 || [[#FocusState|FocusStateChanged]]&lt;br /&gt;
|-&lt;br /&gt;
| 16 || [[#SetRestartMessageEnabled|Resume]]&lt;br /&gt;
|-&lt;br /&gt;
| 20 || DetectShortPressingHomeButton&lt;br /&gt;
|-&lt;br /&gt;
| 21 || DetectLongPressingHomeButton&lt;br /&gt;
|-&lt;br /&gt;
| 22 || DetectShortPressingPowerButton&lt;br /&gt;
|-&lt;br /&gt;
| 23 || DetectMiddlePressingPowerButton&lt;br /&gt;
|-&lt;br /&gt;
| 24 || DetectLongPressingPowerButton&lt;br /&gt;
|-&lt;br /&gt;
| 25 || RequestToPrepareSleep&lt;br /&gt;
|-&lt;br /&gt;
| 26 || FinishedSleepSequence&lt;br /&gt;
|-&lt;br /&gt;
| 27 || SleepRequiredByHighTemperature&lt;br /&gt;
|-&lt;br /&gt;
| 28 || SleepRequiredByLowBattery&lt;br /&gt;
|-&lt;br /&gt;
| 29 || AutoPowerDown&lt;br /&gt;
|-&lt;br /&gt;
| 30 || [[#OperationMode|OperationModeChanged]]&lt;br /&gt;
|-&lt;br /&gt;
| 31 || [[#PerformanceMode|PerformanceModeChanged]]&lt;br /&gt;
|-&lt;br /&gt;
| 32 || DetectReceivingCecSystemStandby&lt;br /&gt;
|-&lt;br /&gt;
| 33 || SdCardRemoved&lt;br /&gt;
|-&lt;br /&gt;
| 34 || &lt;br /&gt;
|-&lt;br /&gt;
| 50 || LaunchApplicationRequested&lt;br /&gt;
|-&lt;br /&gt;
| 51 || [[#SetHandlesRequestToDisplay|RequestToDisplay]]&lt;br /&gt;
|-&lt;br /&gt;
| 55 || ShowApplicationLogo&lt;br /&gt;
|-&lt;br /&gt;
| 56 || HideApplicationLogo&lt;br /&gt;
|-&lt;br /&gt;
| 57 || ForceHideApplicationLogo&lt;br /&gt;
|-&lt;br /&gt;
| 58 || &lt;br /&gt;
|-&lt;br /&gt;
| 59 || &lt;br /&gt;
|-&lt;br /&gt;
| 60 || FloatingApplicationDetected&lt;br /&gt;
|-&lt;br /&gt;
| 61 || [7.0.0+] PerformanceConfigurationChanged&lt;br /&gt;
|-&lt;br /&gt;
| 70 || &lt;br /&gt;
|-&lt;br /&gt;
| 71 || &lt;br /&gt;
|-&lt;br /&gt;
| 72 || &lt;br /&gt;
|-&lt;br /&gt;
| 73 || &lt;br /&gt;
|-&lt;br /&gt;
| 75 || &lt;br /&gt;
|-&lt;br /&gt;
| 80 || &lt;br /&gt;
|-&lt;br /&gt;
| 81 || &lt;br /&gt;
|-&lt;br /&gt;
| 82 || &lt;br /&gt;
|-&lt;br /&gt;
| 83 || &lt;br /&gt;
|-&lt;br /&gt;
| 85 || &lt;br /&gt;
|-&lt;br /&gt;
| 86 || &lt;br /&gt;
|-&lt;br /&gt;
| 90 || [[#SetRequiresCaptureButtonShortPressedMessage|DetectShortPressingCaptureButton]]&lt;br /&gt;
|-&lt;br /&gt;
| 92 || [[#SetAlbumImageTakenNotificationEnabled|AlbumScreenShotTaken]]&lt;br /&gt;
|-&lt;br /&gt;
| 93 || AlbumRecordingSaved&lt;br /&gt;
|-&lt;br /&gt;
| 94 || &lt;br /&gt;
|-&lt;br /&gt;
| 100 || &lt;br /&gt;
|-&lt;br /&gt;
| 101 || &lt;br /&gt;
|-&lt;br /&gt;
| 110 || [14.0.0+] DetectShortPressingCaptureButtonForApplet&lt;br /&gt;
|-&lt;br /&gt;
| 111 || [14.0.0+] DetectLongPressingCaptureButtonForApplet&lt;br /&gt;
|-&lt;br /&gt;
| 1000 || &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= OperationMode =&lt;br /&gt;
This is &amp;quot;nn::oe::OperationMode&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || Handheld&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Console&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= PerformanceMode =&lt;br /&gt;
This is &amp;quot;nn::oe::PerformanceMode&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| -1 || Invalid&lt;br /&gt;
|-&lt;br /&gt;
| 0 || Normal&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Boost&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= FocusState =&lt;br /&gt;
This is &amp;quot;nn::oe::FocusState&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 1 || InFocus&lt;br /&gt;
|-&lt;br /&gt;
| 2 || OutOfFocus&lt;br /&gt;
|-&lt;br /&gt;
| 3 || Background&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= CpuBoostMode =&lt;br /&gt;
This is &amp;quot;nn::oe::CpuBoostMode&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || Normal&lt;br /&gt;
|-&lt;br /&gt;
| 1 || FastLoad&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= WindowOriginMode =&lt;br /&gt;
This is &amp;quot;nn::oe::WindowOriginMode&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || LowerLeft&lt;br /&gt;
|-&lt;br /&gt;
| 1 || UpperLeft&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= WirelessPriorityMode =&lt;br /&gt;
This is &amp;quot;nn::oe::WirelessPriorityMode&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || Default&lt;br /&gt;
|-&lt;br /&gt;
| 1 || OptimizedForWlan&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= TvPowerStateMatchingMode =&lt;br /&gt;
This is &amp;quot;nn::oe::TvPowerStateMatchingMode&amp;quot;. This is used with [[#SetTvPowerStateMatchingMode]].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || Unknown&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Unknown&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= SystemButtonType =&lt;br /&gt;
This is &amp;quot;nn::am::service::SystemButtonType&amp;quot;. This is used with [[#PerformSystemButtonPressingIfInFocus]]/[[#PerformSystemButtonPressing]].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 1 || PerformHomeButtonShortPressing&lt;br /&gt;
|-&lt;br /&gt;
| 2 || PerformHomeButtonLongPressing&lt;br /&gt;
|-&lt;br /&gt;
| 3 || Short-pressing with the Power-button. Only available with [[#PerformSystemButtonPressing]].&lt;br /&gt;
|-&lt;br /&gt;
| 4 || Long-pressing with the Power-button. Only available with [[#PerformSystemButtonPressing]].&lt;br /&gt;
|-&lt;br /&gt;
| 5 || Shutdown the system. Only available with [[#PerformSystemButtonPressing]].&lt;br /&gt;
|-&lt;br /&gt;
| 6 || PerformCaptureButtonShortPressing&lt;br /&gt;
|-&lt;br /&gt;
| 7 || PerformCaptureButtonLongPressing&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= LaunchParameterKind =&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 1 || UserChannel. Application-specific LaunchParameter.&lt;br /&gt;
|-&lt;br /&gt;
| 2 || account PreselectedUser&lt;br /&gt;
|-&lt;br /&gt;
| 3 || Unknown if used by anything?&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= LibraryAppletExitReason =&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || Normal&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Canceled&lt;br /&gt;
|-&lt;br /&gt;
| 2 || Abnormal&lt;br /&gt;
|-&lt;br /&gt;
| 10 || Unexpected&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ProgramSpecifyKind =&lt;br /&gt;
This is &amp;quot;nn::am::service::ProgramSpecifyKind&amp;quot;. This controls the type of the u64 passed to [[#ExecuteProgram]].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || u8 ProgramIndex. &amp;quot;ExecuteProgram&amp;quot;. [[NS_Services|NS]] handles ProgramIndex by launching ApplicationId+ProgramIndex. After using [[#ExecuteProgram]] with this successfully, official user-processes will enter an infinite loop with sleep-thread value 86400000000000.&lt;br /&gt;
|-&lt;br /&gt;
| 1 || [[NCM_services#ApplicationId|ApplicationId]]. &amp;quot;JumpToSubApplicationProgramForDevelopment&amp;quot;. Only available when [[Settings_services#GetDebugModeFlag|DebugMode]] is 1.&lt;br /&gt;
|-&lt;br /&gt;
| 2 || u64 = value 0. &amp;quot;RestartProgram&amp;quot;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
ProgramIndex values where the title is not installed should not be used: [[qlaunch]] will display an error message and the current title will become &amp;quot;corrupted&amp;quot;, however Home Menu will have an option to repair it.&lt;br /&gt;
&lt;br /&gt;
= InputDetectionPolicy =&lt;br /&gt;
This is u32 enum &amp;quot;nn::applet::InputDetectionPolicy&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || Unknown&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Unknown&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= AppletResourceUserId =&lt;br /&gt;
This is &amp;quot;nn::applet::AppletResourceUserId&amp;quot;. Used by a number of non-AM services.&lt;br /&gt;
&lt;br /&gt;
= AppletAttribute =&lt;br /&gt;
This is &amp;quot;nn::am::AppletAttribute&amp;quot;. This struct is 0x80 bytes.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset || Size || Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x1 || Flag. When non-zero, two state fields are set to 1.&lt;br /&gt;
|-&lt;br /&gt;
| 0x1 || 0x7F || Unused&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
This is used by [[#OpenLibraryAppletProxy]].&lt;br /&gt;
&lt;br /&gt;
= AppletProcessLaunchReason =&lt;br /&gt;
This is &amp;quot;nn::am::service::AppletProcessLaunchReason&amp;quot;. This struct is 0x4-bytes.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset || Size || Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x1 || Flag. When non-zero, LibraryApplets then use [[#OpenCallingLibraryApplet]].&lt;br /&gt;
|-&lt;br /&gt;
| 0x1 || 0x2 || Always 0.&lt;br /&gt;
|-&lt;br /&gt;
| 0x3 || 0x1 || Always 0.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= LibraryAppletInfo =&lt;br /&gt;
This is &amp;quot;nn::am::service::LibraryAppletInfo&amp;quot;. This struct is 0x8-bytes.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset || Size || Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x4 || [[#AppletId]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || 0x4 || [[#LibraryAppletMode]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= AppletKind =&lt;br /&gt;
This is &amp;quot;nn::am::service::AppletKind&amp;quot;. This is 8-bytes.&lt;br /&gt;
&lt;br /&gt;
= AppletIdentityInfo =&lt;br /&gt;
This struct is &amp;quot;nn::am::service::AppletIdentityInfo&amp;quot;. This struct is 0x10-bytes.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset || Size || Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x4 || [[#AppletId]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || 0x4 || Padding&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x8 || [[NCM_services#ApplicationId|ApplicationId]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationAttributeForQuest =&lt;br /&gt;
This struct is &amp;quot;nn::applet::ApplicationAttributeForQuest&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset || Size || Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x4 || See [[#ApplicationAttribute]].&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || 0x4 || See [[#ApplicationAttribute]].&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x4 || [7.0.0+] See [[#ApplicationAttribute]].&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
User-processes copy the first 0x8-bytes (0xC-bytes with [[#CreateApplicationWithAttributeAndPushAndRequestToStartForQuest]]/[[#CreateApplicationWithAttributeAndRequestToStartForQuest]]) to a [[#ApplicationAttribute]] with the rest of the struct being cleared, which is then passed to the actual cmd (CreateApplication*ToStartForQuest).&lt;br /&gt;
&lt;br /&gt;
= ApplicationAttribute =&lt;br /&gt;
This struct is &amp;quot;nn::am::ApplicationAttribute&amp;quot;. This struct is 0x20-bytes.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset || Size || Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x4 || Default is 0 for non-Quest. Only used when non-zero: unknown value in seconds.&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || 0x4 || Default is 0 for non-Quest. Only used when non-zero: unknown value in seconds.&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x4 || float audio volume. Must be in the range of 0.0f-1.0f. The default is 1.0f.&lt;br /&gt;
|-&lt;br /&gt;
| 0xC || 0x14 || Unused. Default is 0.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Internally AM only uses the first 0xC-bytes from ApplicationAttribute, regardless of the cmd.&lt;br /&gt;
&lt;br /&gt;
= ApplicationLaunchProperty =&lt;br /&gt;
This struct is 0x10-bytes.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset || Size || Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x8 || [[NCM_services#ApplicationId|ApplicationId]]&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x4 || Application title-version.&lt;br /&gt;
|-&lt;br /&gt;
| 0xC || 0x1 || [[Filesystem_services#StorageId|StorageId]] for the Application base title.&lt;br /&gt;
|-&lt;br /&gt;
| 0xD || 0x1 || [[Filesystem_services#StorageId|StorageId]] for the Application update title.&lt;br /&gt;
|-&lt;br /&gt;
| 0xE || 0x1 || Unknown.&lt;br /&gt;
|-&lt;br /&gt;
| 0xF || 0x1 || Padding.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationLaunchRequestInfo =&lt;br /&gt;
This is &amp;quot;nn::applet::ApplicationLaunchRequestInfo&amp;quot;. This struct is 0x10-bytes.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset || Size || Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x4 || Unknown. The default is 0x0 with [[#CreateSystemApplication]], 0x3 with [[#CreateApplication]].&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || 0x4 || Unknown. The default is 0x0 with [[#CreateSystemApplication]], 0x3 with [[#CreateApplication]].&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x8 || Unknown. The default is 0x0.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= AppletResourceUsageInfo =&lt;br /&gt;
This is &amp;quot;nn::am::service::AppletResourceUsageInfo&amp;quot;. This struct is 0x20-bytes.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset || Size || Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x4 || Unknown counter.&lt;br /&gt;
|-&lt;br /&gt;
| 0x4 || 0x4 || Unknown counter.&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x4 || Output from [[NS_Services|NS GetRightsEnvironmentCountForDebug]].&lt;br /&gt;
|-&lt;br /&gt;
| 0xC || 0x14 || Always zero.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= ApplicationLicenseType =&lt;br /&gt;
This is &amp;quot;nn::oe::ApplicationLicenseType&amp;quot;. This is 1-byte.&lt;br /&gt;
&lt;br /&gt;
= LaunchRequiredVersion =&lt;br /&gt;
This is &amp;quot;nn::oe::LaunchRequiredVersion&amp;quot;. This is a 0x40-byte struct with 1-byte alignment.&lt;br /&gt;
&lt;br /&gt;
= ServerEnvironmentType =&lt;br /&gt;
This is &amp;quot;nn::oe::ServerEnvironmentType&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Value&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
| 0 || dd&lt;br /&gt;
|-&lt;br /&gt;
| 1 || lp&lt;br /&gt;
|-&lt;br /&gt;
| 2 || sd&lt;br /&gt;
|-&lt;br /&gt;
| 3 || sp&lt;br /&gt;
|-&lt;br /&gt;
| 4 || dp&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= (S2) AdrawFrameBufferInfo =&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset || Size || Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x8 || Id&lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x2 || Width&lt;br /&gt;
|-&lt;br /&gt;
| 0xA || 0x2 || Height&lt;br /&gt;
|-&lt;br /&gt;
| 0xC || 0x4 || BlockCount&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x8 || &lt;br /&gt;
|-&lt;br /&gt;
| 0x18 || 0x8 || &lt;br /&gt;
|-&lt;br /&gt;
| 0x20 || 0x8 || &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= (S2) ImageInfo =&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Offset || Size || Description&lt;br /&gt;
|-&lt;br /&gt;
| 0x0 || 0x8 || &lt;br /&gt;
|-&lt;br /&gt;
| 0x8 || 0x8 || Address&lt;br /&gt;
|-&lt;br /&gt;
| 0x10 || 0x8 || &lt;br /&gt;
|-&lt;br /&gt;
| 0x18 || 0x8 || &lt;br /&gt;
|-&lt;br /&gt;
| 0x20 || 0x8 || &lt;br /&gt;
|-&lt;br /&gt;
| 0x28 || 0x8 || &lt;br /&gt;
|-&lt;br /&gt;
| 0x30 || 0x8 || &lt;br /&gt;
|-&lt;br /&gt;
| 0x38 || 0x4 || Offset&lt;br /&gt;
|-&lt;br /&gt;
| 0x3C || 0x4 || Size&lt;br /&gt;
|-&lt;br /&gt;
| 0x40 || 0x8 || &lt;br /&gt;
|-&lt;br /&gt;
| 0x48 || 0x8 || &lt;br /&gt;
|-&lt;br /&gt;
| 0x50 || 0x8 || &lt;br /&gt;
|-&lt;br /&gt;
| 0x58 || 0x8 || &lt;br /&gt;
|-&lt;br /&gt;
| 0x60 || 0x8 || &lt;br /&gt;
|-&lt;br /&gt;
| 0x68 || 0x8 || &lt;br /&gt;
|-&lt;br /&gt;
| 0x70 || 0x8 || &lt;br /&gt;
|-&lt;br /&gt;
| 0x78 || 0x8 || &lt;br /&gt;
|-&lt;br /&gt;
| 0x80 || 0x8 || &lt;br /&gt;
|-&lt;br /&gt;
| 0x88 || 0x8 || &lt;br /&gt;
|-&lt;br /&gt;
| 0x90 || 0x4 || Flags&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Notes =&lt;br /&gt;
AM-sysmodule will only initialize [[Shared_Database_services|pdm:ntfy]] / use pdm:ntfy service commands when the value from [[Process_Manager_services|pm:bm]] GetBootMode is not 0x1 (Maintenance).&lt;br /&gt;
&lt;br /&gt;
An object constructor also writes the output from [[Process_Manager_services|pm:bm]] GetBootMode into the created object. A vfunc for this object checks whether this field is Maintenance: if so, it calls a vfunc then a func and returns. Otherwise after calling various (v)funcs, if required this eventually uses [[OMM_services|ommdisp]] cmd600.&lt;br /&gt;
&lt;br /&gt;
[[Category:Services]]&lt;/div&gt;</summary>
		<author><name>Yellows8</name></author>
	</entry>
</feed>