remaster: any-firmware hardening + installer remake

- detection: probe-first (ShellCoreUtil dlopen, msgbuf AppFocusChanged,
  sysctl kinfo via verified-only fw table, sandbox/save fallbacks)
- new orbisrpc/focus.c + fw.c/fw.h (bounded scans, fail-closed unknowns)
- daemon: no-exit everywhere (token wait-loop, 4004 retry), status.json
  heartbeat, daemon.gen supersede protocol
- installer: progress UI, token IME retry + FTP fallback, install.log,
  drop evict.elf (delete tools/evict.c, build_evict.sh)
- packaging: Apollo parity CATEGORY=gde ATTRIBUTE=32 --authinfo
- security: chmod 0600 on token-bearing files
- docs: firmware-independent injecting guide, SUPPORT.md, release.sh
This commit is contained in:
SirHumza committed 2026-09-27 14:47:09 +02:00
1 parent 68a34993da
commit d0972b68e9
25 files changed
+587 -181

No files matched your search

+2 -2
View File
@@ -41,13 +41,13 @@ CFLAGS="--target=$TARGET -fPIC -std=gnu11 -Wall -Wno-unused \
-Wno-int-conversion -Wno-incompatible-pointer-types \
-DMBEDTLS_NO_PLATFORM_ENTROPY \
-isystem $SDK/include -Ithird_party/mbedtls/include"
LIBS="-lc -lkernel -lSceNet -lSceNetCtl -lSceSysmodule \
LIBS="-lc -lkernel -lSceNet -lSceSysmodule \
-lSceUserService"
LDFLAGS="-m elf_x86_64 -pie --eh-frame-hdr -L$SDK/lib $LIBS $SDK/lib/crt1.o --script $SDK/link.x"
export OO_PS4_TOOLCHAIN="$SDK"
OUT="$ROOT/build"; mkdir -p "$OUT"
echo "=== compiling (CC=$CC LD=$LD SDK=$SDK) ==="
for f in log cfg jsonlite b64 sfo tmdb_crypto tmdb updater updater_http updater_util tls ws detect discord daemon compat lock timesync art health manifest main; do
for f in log cfg jsonlite b64 sfo tmdb_crypto tmdb updater updater_http updater_util tls ws detect focus fw discord daemon compat lock timesync art health manifest main; do
"$CC" $CFLAGS -c -o "$OUT/$f.o" "orbisrpc/$f.c" || fail "compile $f"
done
echo "=== mbedtls (skip net_sockets/timing: POSIX-only) ==="
-13
View File
@@ -1,13 +0,0 @@
#!/bin/sh
# build_evict.sh - evict.elf via ps4-payload-sdk (daemon-world linkage only).
# Usage: PS4_PAYLOAD_SDK=/path ./scripts/build_evict.sh
set -e
SDK="${PS4_PAYLOAD_SDK:-$HOME/ps4-payload-sdk/ps4-payload-sdk}"
CC="$SDK/bin/orbis-clang"
export PS4_PAYLOAD_SDK="$SDK"
export PATH="$HOME/llvmshim:$PATH"
OUT="build-sdk"
mkdir -p "$OUT"
echo "=== evict (SDK) ==="
"$CC" -O2 -Wall -DORBISRPC_SDK_PAYLOAD -o "$OUT/evict.elf" tools/evict.c || { echo "FAIL: evict"; exit 1; }
ls -la "$OUT/evict.elf"
+1 -1
View File
@@ -16,7 +16,7 @@ mkdir -p "$OUT"
CFLAGS="-O2 -Wall -DORBISRPC_SDK_PAYLOAD -Iorbisrpc -Ithird_party/mbedtls/include -Ithird_party/sqlite/sqlite-amalgamation-3510100"
SQLITE_DIR="third_party/sqlite/sqlite-amalgamation-3510100"
echo "=== daemon sources (SDK) ==="
for f in log cfg jsonlite b64 sfo tmdb_crypto tmdb updater updater_http updater_util tls ws detect discord daemon compat lock timesync art health manifest appdb main; do
for f in log cfg jsonlite b64 sfo tmdb_crypto tmdb updater updater_http updater_util tls ws detect focus fw discord daemon compat lock timesync art health manifest appdb main; do
# clock has no .c (header-only helper lives in compat.c); skip if missing
[ -f "orbisrpc/$f.c" ] || continue
"$CC" $CFLAGS -c -o "$OUT/$f.o" "orbisrpc/$f.c" || { echo "FAIL: $f"; exit 1; }
+17
View File
@@ -0,0 +1,17 @@
#!/bin/sh
# release.sh - one-command release: SDK payload -> staged assets -> Setup PKG.
# Usage: ./scripts/release.sh (needs OO_PS4_TOOLCHAIN + PS4_PAYLOAD_SDK)
# Output: OrbisRPC-Setup-<version>.pkg at repo root.
set -eu
cd "$(dirname "$0")/.."
VER="$(sed -n 's/^#define ORBISRPC_VERSION "\(.*\)"/\1/p' orbisrpc/version.h)"
[ -n "$VER" ] || { echo "FAIL: version.h unreadable"; exit 1; }
echo "=== release $VER ==="
./scripts/build_sdk.sh || { echo "FAIL: sdk payload"; exit 1; }
make -f installer/Makefile || { echo "FAIL: pkg"; exit 1; }
PKG="IV0000-ORPC00001_00-ORBISRPCSETUP000.pkg"
[ -f "$PKG" ] || { echo "FAIL: $PKG missing"; exit 1; }
OUT="OrbisRPC-Setup-$VER.pkg"
mv "$PKG" "$OUT"
ls -la "$OUT"
echo "done: $OUT"