SPL services: Difference between revisions
No edit summary |
→(S2) spl:ldn: Moved to the ldn page. |
||
| (5 intermediate revisions by 2 users not shown) | |||
| Line 4: | Line 4: | ||
In [2.0.0+] where previously only one AES keyslot was used, there is now support for 4 of them and when the session closes, all allocated AES keyslots are automatically freed. | In [2.0.0+] where previously only one AES keyslot was used, there is now support for 4 of them and when the session closes, all allocated AES keyslots are automatically freed. | ||
[S2] The spl services were overhauled. New services were added, this appears to replace spl:mig where required for the relevant sysmodules. GenerateAesKek is no longer directly exposed, thus the Kek AccessKey and KeySource are no longer exposed. | |||
= csrng = | = csrng = | ||
| Line 38: | Line 40: | ||
|- | |- | ||
| 25 || [3.0.0+] [[#GetBootReason]] | | 25 || [3.0.0+] [[#GetBootReason]] | ||
|} | |||
Going by spl:ldn, this likely has a new interface on [S2]: | |||
{| class="wikitable" border="1" | |||
|- | |||
! Cmd || Name | |||
|- | |||
| 0 || [[#GenerateRandomBytes|GenerateRandomBytes]] | |||
|- | |||
| 1 || [[#GetConfig|GetConfig]] | |||
|- | |||
| 2 || | |||
|- | |||
| 3 || | |||
|- | |||
| 4 || | |||
|- | |||
| 5 || [[#GetConfigWithBuffer|GetConfigWithBuffer]] | |||
|} | |} | ||
| Line 51: | Line 72: | ||
Performs asymmetric crypto with user supplied modulus and exponent. | Performs asymmetric crypto with user supplied modulus and exponent. | ||
== Cmd2 == | |||
This is for the [S2] interface. | |||
Takes no input, returns 0x10-bytes of output. | |||
This returns the first 0xD-bytes from [[#GetConfigWithBuffer|GetConfigWithBuffer]] ConfigItem 8, byteswapped. | |||
== Cmd3 == | |||
This is for the [S2] interface. | |||
Takes no input. Returns unknown output, usually zeros? | |||
== Cmd4 == | |||
This is for the [S2] interface. | |||
Takes no input. Returns unknown output, usually zeros? | |||
== GetConfigWithBuffer == | |||
Unofficial name. | |||
Some config is incomplete when accessed with [[#GetConfig|GetConfig]], this allows returning the full config. | |||
Takes an input u32 '''ConfigItem''' and an output type-0xA buffer. | |||
== GenerateAesKek == | == GenerateAesKek == | ||
| Line 428: | Line 473: | ||
| 30 || [5.0.0+] ReencryptDeviceUniqueData | | 30 || [5.0.0+] ReencryptDeviceUniqueData | ||
|} | |} | ||
= (S2) spl:da = | |||
= (S2) spl:gc = | |||
= (S2) spl:nv = | |||
= (S2) spl:hid = | |||
= (S2) spl:ldn = | |||
This is "nn::spl::detail::ILdnInterface". | |||
This has IPC max_sessions 1? | |||
{| class="wikitable" border="1" | |||
|- | |||
! Cmd || Name | |||
|- | |||
| 0 || [[#GenerateRandomBytes|GenerateRandomBytes]] | |||
|- | |||
| 1 || [[#GetConfig|GetConfig]] | |||
|- | |||
| 2 || | |||
|- | |||
| 3 || | |||
|- | |||
| 4 || | |||
|- | |||
| 5 || [[#GetConfigWithBuffer|GetConfigWithBuffer]] | |||
|- | |||
| 7000 || [[#GenerateNxAdvertiseKey|GenerateNxAdvertiseKey]] | |||
|- | |||
| 7001 || [[#GenerateNxSessionKey|GenerateNxSessionKey]] | |||
|- | |||
| 7002 || [[#GenerateNxLp2pKeyIndex1|GenerateNxLp2pKeyIndex1]] | |||
|- | |||
| 7003 || [[#GenerateNxLp2pKeyIndex2|GenerateNxLp2pKeyIndex2]] | |||
|- | |||
| 7004 || [[#GenerateOunceAdvertiseKey|GenerateOunceAdvertiseKey]] | |||
|- | |||
| 7005 || [[#GenerateOunceSessionKey|GenerateOunceSessionKey]] | |||
|} | |||
The below 7000+ cmds take a KeySource (equivalent to NX-GenerateAesKey) and an u32. Bitmask 0x1F of the u32 is the Generation, 0x20 is valid but doesn't seem to do anything. Values >=0x21 throw error. A 0x10-byte outbuf is used for the output key. Cmd7004/Cmd7005 use a 0x20-byte outbuf. These are equivalent to GenerateAesKek+GenerateAesKey combined. | |||
With Nx commands, valid key generations match what's expected for S1. With Ounce commands, the valid key generations on 20.x are 0/1. | |||
All of these use AES-ECB with the input KeySource, with the buffer as the output. | |||
== GenerateNxAdvertiseKey == | |||
Unofficial name. | |||
Takes an input 16-byte '''KeySource''', an input u32, and an output type-0xA buffer '''AesKey'''. | |||
Generates a key using the NX-equivalent of the ldn Kek-action_keysource. | |||
== GenerateNxSessionKey == | |||
Unofficial name. | |||
Takes an input 16-byte '''KeySource''', an input u32, and an output type-0xA buffer '''AesKey'''. | |||
Generates a key using the NX-equivalent of the ldn Kek-data_keysource. | |||
== GenerateNxLp2pKeyIndex1 == | |||
Unofficial name. | |||
Takes an input 16-byte '''KeySource''', an input u32, and an output type-0xA buffer '''AesKey'''. | |||
Generates a key using the NX-equivalent of the lp2p Kek-Index1. | |||
== GenerateNxLp2pKeyIndex2 == | |||
Unofficial name. | |||
Takes an input 16-byte '''KeySource''', an input u32, and an output type-0xA buffer '''AesKey'''. | |||
Generates a key using the NX-equivalent of the lp2p Kek-Index2. | |||
== GenerateOunceAdvertiseKey == | |||
Unofficial name. | |||
Takes an input 32-byte '''KeySource''', an input u32, and an output type-0xA buffer '''AesKey'''. | |||
Ounce version of [[#GenerateNxAdvertiseKey|GenerateNxAdvertiseKey]]. | |||
== GenerateOunceSessionKey == | |||
Unofficial name. | |||
Takes an input 32-byte '''KeySource''', an input u32, and an output type-0xA buffer '''AesKey'''. | |||
Ounce version of [[#GenerateNxSessionKey|GenerateNxSessionKey]]. | |||
[[Category:Services]] | [[Category:Services]] | ||