Add optional SHA-256 verification of downloaded manifest pieces

Each Sony manifest piece carries a SHA-256 (hashValue). When the new
"Verify downloaded pieces" setting is on, every piece is hashed while it
streams to disk (OpenSSL EVP, already linked) and compared against the
manifest value; a mismatch aborts the download, deletes the partial, and
reports piece_verify_failed instead of handing a corrupt 60 GB package to
the installer.

Off by default: TLS already protects the bytes in transit and the PS5
installer verifies the whole packageDigest before applying, so this is a
fail-fast belt-and-suspenders check. It is also unverified on hardware
yet, so it stays opt-in (persisted in config.json) until confirmed
on-device; the hex compare is case-insensitive since Sony mixes cases.
This commit is contained in:
Knutwurst committed 2026-06-23 18:08:57 +02:00
1 parent 9006965a75
commit ea1328de79
5 files changed
+117 -27

No files matched your search

+7
View File
@@ -184,6 +184,13 @@
<em>Only after a successful install</em>
</span>
</label>
<label class="switch-row">
<input id="verifyDownloads" type="checkbox" />
<span>
<strong>Verify downloaded pieces (SHA-256)</strong>
<em>Checks each manifest piece; off by default, verify on-device first</em>
</span>
</label>
</div>
<div class="allowlist">