39 Commits
Author SHA1 Message Date
Knutwurst cb7a86551b README: point links and badges at the renamed ps5-patchdl repo 2026-10-06 07:45:35 +02:00
Knutwurst ded0a4ddaa README: give all four screenshots the same 16:10 frame 2026-10-05 21:17:00 +02:00
Knutwurst 5cc430ec59 README: landing page with hero, screenshots, FAQ and disclaimer
New hero composite, desktop and phone screenshots rendered from demo
data, highlights, a get-started list, a short FAQ and a clear statement
that PatchDL only fetches official, unmodified updates for games already
on the console. Old photos showing debug output are replaced; the real
home-screen tile photo stays. docs/images/social-preview.png is ready
for the repository's social preview.
2026-10-05 21:15:26 +02:00
Knutwurst b727fd430f Net: drop the unused third-party lookup host
The allowlist carried a non-Sony host for a lookup that was never built;
the function was a stub that always returned -1. Removing both leaves
behaviour unchanged and keeps every request on the PlayStation CDN.
2026-10-05 21:15:26 +02:00
Knutwurst 74ec23aa7e UI: label queued downloads as Queued, plainer header and DNS wording
Jobs waiting for a free slot showed the green Downloading pill, same as
the one that was actually transferring. They now show a neutral Queued
pill. The header eyebrow reads "PS5 update manager" and the DNS tile
says the system DNS is left untouched.
2026-10-05 21:15:26 +02:00
Knutwurst 5dc5ee57b3 Add PS5 GitHub Actions build 2026-06-27 19:19:05 +02:00
Knutwurst 44ab1dd822 README: swap hero and home-screen tile images so each fits its section 2026-06-25 22:31:39 +02:00
Knutwurst 84f5051ba3 README: tighter prose, no em-dashes, fewer adverbs 2026-06-25 22:04:58 +02:00
Knutwurst 0510e3dc34 License: GPL-3.0-or-later
Full GPL-3.0 text in LICENSE, SPDX-License-Identifier header on every
source file, README license section updated. Copyright (C) 2026 Knutwurst.

Tidied a couple of stale comments in patchdl_tile.{c,h} while at it.
2026-06-25 17:01:49 +02:00
Knutwurst edb4c90978 README: rewrite as a tool description with screenshots
Reads like a project README now: what PatchDL is, what the UI looks
like, how to use the settings, how to install. The deeper notes
(target-id matching, source classification, partition layout, console
setup chain) are out — those belong in design docs, not the front door.

Five photos under docs/images/ render inline: home-screen tile, the
desktop browser UI, the mobile settings view, the on-console browser,
and the startup notification. Originals stay in photos/ for future
crops.
2026-06-25 09:00:00 +02:00
Knutwurst ec94f0578b Release 0.0.6 2026-06-25 06:35:01 +02:00
Knutwurst 88368e3df3 Plug response-OOM leak, cap RAM, free pool on shutdown
queue_buffer leaked the MUST_FREE payload (every queue_json_owned/
build_*_json/strdup(resp)) when MHD_create_response_from_buffer hit OOM.
The MUST_FREE contract hands ownership to MHD only on success — on the
NULL return path the caller still owns the buffer, so free it before
bailing. Critical under memory pressure where the first OOM turns into
a cascade.

patchdl_websrv_stop walked the verxml thread + workers but never freed
the remaining dl_job_t entries or g_debug_json. Today main never calls
the function, but the early-failure path inside patchdl_websrv_start
does, and any later graceful-shutdown work would hit the same leak.
Drain g_pool.jobs through free_job_locked under the pool lock; free
g_debug_json under g_mutex.

RAM caps:

- MHD: CONNECTION_LIMIT 64 -> 8 (single-user UI), and
  THREAD_STACK_SIZE = 512 KB. THREAD_PER_CONNECTION on libc's default
  pthread stack (multi-MB) was reserving hundreds of MB of VM per
  burst; the largest stack frame in any handler is the 8 KB sidecar
  buffer, so 512 KB is generous even with curl + openssl in the path.
- patchdl_buf_t caps: manifest 64 -> 16 MiB, version.xml 16 -> 4 MiB.
  Real PS5 manifests are 1-2 MiB; the old caps allowed 64 MiB per
  fetch with multiple fetches possible in flight.
- patchdl_install_status_json: ai_install_status_t (2 KB pad) moves
  from the MHD worker stack to a calloc/free pair so a polling browser
  doesn't keep committing pages on each /api/installstatus tick.
- seed_from_sidecar: 16 KB stack buf -> 8 KB. 4096-piece cap fits with
  the JSON wrapper inside 8 KB.

No functional changes; download/install/scan/tile paths unaffected.
2026-06-25 06:10:48 +02:00
Knutwurst c80be921c5 Release 0.0.5 2026-06-24 22:15:04 +02:00
Knutwurst a371a67521 Net: drop HTTPS pin on the streaming download paths
Real regression from c9d721f: pinning CURLOPT_PROTOCOLS_STR /
REDIR_PROTOCOLS_STR to "https" on the piece downloader (and the simple
file streamer) broke real-world Sony patch downloads. Banishers reliably
aborted after ~73 MB and Last of Us Part I after ~127 MB — the Sony CDN
appears to 302 the piece URL to an http:// signed edge inside its own
infrastructure, and refusing those redirects killed the transfer mid-piece.

The smaller patchdl_http_get path (version.xml + manifest JSON) keeps the
HTTPS pin since those payloads always come back from the public https
endpoints. The defence still holds elsewhere: host_allowed gates every
URL to the Sony CDN allowlist, TLS verifies against the pinned SCEI root
even on a 302, and NOSIGNAL stays so a connection RST can't smuggle a
SIGPIPE back into the worker thread.

For future regressions of this class /api/downloads now exposes the last
CURLcode + HTTP status per job (last_curl_rc, last_http_code) so we don't
have to instrument the binary again to find out what curl returned.
2026-06-24 22:13:16 +02:00
Knutwurst 2bc15cbaa2 UI: Updating now means only the queue; active downloads stay in Updatable
Previous behaviour moved a game out of Updatable the moment it entered
the pool, which made it disappear from the list you came to watch. The
queue chip now means literally that: jobs in state="queued" waiting
for a free pool slot. Active, paused and installing jobs stay under
Updatable so you don't have to switch tabs to see the thing you just
told to download.

Implementation: reconcileFromJobs stamps the raw j.state on the title
as g._jobState; gameCategory routes only "queued" to Updating, every
other live state falls through to the existing Updatable branch.
2026-06-24 22:00:42 +02:00
Knutwurst 81d6f0e332 UI: global download banner above the status strip
A sticky-feeling banner appears whenever any job is queued or active.
It shows the eyebrow (Downloading / Queued), the current title's name,
a "3 of 9" chip when more than one job is in this batch, plus
percent, speed, and ETA. A thin gradient bar runs edge-to-edge along
the bottom so the at-a-glance state matches the per-card progress.

Batch counting: jobs with state in {queued, active, done} make up the
batch; done count + 1 is the current position. When all queued jobs
finish and roll out of the pool list the banner hides on the next poll.

While the active job's manifest is still being fetched (no total_bytes
yet) the bar runs an indeterminate sweep so the user isn't staring at
a frozen 0%. Speed comes from the existing per-job smoothed estimate
in reconcileFromJobs so the banner shares one source of truth with
the per-game tiles.

Render hooks: renderGames() and applyDownloadProgress() both call
renderGlobalStatus(), so every refresh path keeps it in sync without
adding a separate timer.
2026-06-24 21:55:28 +02:00
Knutwurst fcd43b54ae Home-screen tile via sceAppInstUtilAppInstallTitleDir
Write param.json + icon0.png into /user/app/<TITLE_ID>/sce_sys/, then
call sceAppInstUtilAppInstallTitleDir to register the directory as an
app. No package, no code signing — the installer reads the metadata
files directly.

The tile uses TITLE_ID PTDL00001 and deeplinkUri
http://127.0.0.1:12880/, so tapping it opens PatchDL's own UI in the
on-console browser. Only useful while the ELF is running.

Asset pipeline: param.json + icon0.png live under assets/ and get
.incbin'd straight into .rodata. Makefile lists them as TILE_ASSETS so
a touch on either forces a relink.

Stat-guard: file_matches() diffs each asset against the on-disk copy
first; when nothing changed the install API isn't called at all. Keeps
repeated payload starts from re-registering the app. Repeated
/api/install_tile calls return "already installed and up to date".

Backend lazy-load: AppInstUtil isn't mapped until something pokes it,
so the helper polls patchdl_install_backend_check() for up to ~15 s
before resolving sceAppInstUtilAppInstallTitleDir.

Wiring: /api/install_tile POST triggers the install on demand;
patchdl_websrv_start() runs it at startup when home_shortcut is on;
and flipping the toggle from off to on in /api/config also fires it.
All three paths share the stat-guarded helper so they're safe to
repeat.
2026-06-24 21:50:59 +02:00
Knutwurst d0ca22d42d UI: pull version from /api/status instead of hardcoding it
The sidebar tag was a literal "v0.0.3" string in index.html, so a
release bump left the running UI lying about which build it was. Server
now publishes PATCHDL_VERSION via /api/status; renderStatus() drops it
into a #brandVersion span. No more chasing a hardcoded version on every
release.
2026-06-24 21:19:38 +02:00
Knutwurst fb47730d70 Docs: README for 0.0.4 (cross-region install works, UI updates, filename)
README catches up to where the code is:

- The "cross-region install is a known limitation" section is gone. We
  route through sceAppInstUtilAppInstallPkg now, verified end-to-end on
  Dead Island 2 (01.000.001 -> 01.000.011, including the shared-storage
  case where the patch lives under a master title id).
- A Web UI section documents the filter chips (Updatable default,
  Updating separate bucket, All on the right) and Update all.
- Deploy section notes the new filename shape (patchdl_<version>.elf)
  so Payload Manager can parse the version out of it.

deploy_ps5.sh follows: UP_NAME is now patchdl_${VERSION}.elf to match
the released asset naming.
2026-06-24 21:16:31 +02:00
Knutwurst a1d035313e Release 0.0.4
Update all skips shadowmount titles. They pass the download policy but
not the install policy (their app slot has no real source medium), so
sweeping them in would burn tens of GB on a download AppInstUtil would
refuse. Single shadowmount downloads via the per-title button still work
for the "pop the disc in later" workflow.
2026-06-24 20:59:47 +02:00
Knutwurst bffa9b2a3f UI: separate Updating filter for queued/active/paused downloads
Updating gets its own chip so Updatable shows only games the user could
still trigger. Anything mid-flight — queued, actively downloading,
paused with a partial on disk, or installing — moves to the new bucket.

Implemented in gameCategory(): downloading is true for both queued and
active jobs, so wartende Downloads (the user's words) show up in the
same list as the one actively transferring.
2026-06-24 20:57:17 +02:00
Knutwurst 3f4c4a15f5 UI: default to Updatable filter, add Update All, move All to the right
The Updatable chip is now the first segment and selected on load — the
common case (looking at what needs an update) doesn't need a click. All
moves to the right end of the strip.

Update All queues a download for every game whose status is "available"
and whose source/policy allow it (skips downloading/downloaded jobs).
With install_after_download on, the existing auto-install pipeline
picks each finished download up automatically.
2026-06-24 20:51:11 +02:00
Knutwurst c9d721fea6 Polish: NOSIGNAL + HTTPS pin on all transports, bounded kill loop
The three other curl_easy code paths (downloader, piece pool, net_diag)
now set CURLOPT_NOSIGNAL=1L plus PROTOCOLS_STR/REDIR_PROTOCOLS_STR =
"https" — matching what patchdl_http_get already does. SIGPIPE on a
broken connection in a worker thread previously could crash the process;
the protocol pin keeps a redirect from sliding off https.

patchdl_proc_kill_others is now bounded to 8 iterations. If kill returns
success but the process never exits (zombie / unusual proc-table state),
sleep(1) × N would otherwise stall startup indefinitely.

lookup_tsv rejects URLs that don't start with https://. The TSV file
lives under /data/patchdl and is writable by anyone with /data access;
patchdl_http_get's host_allowed gate still applies, but failing earlier
keeps a poisoned line from even reaching the network layer.
2026-06-24 20:41:26 +02:00
Knutwurst 73c75ddd83 Medium hardening: JSON escapes, policy whitelist, scan lock, EVP check
json_get_str now decodes the common JSON escapes (\" \\ \/ \n \r \t \b
\f) and collapses \uXXXX to '?'. Previously \" terminated the value
early and \\ was copied literal, so a body containing escapes turned
into garbage at the install backend.

default_policy is constrained to "allow" or "deny" before being stored,
so a malformed POST can't write an arbitrary string into config.json
and round-trip it back out of /api/config as broken JSON.

/api/manifest/<tid>, /api/pkgverify/<tid>, /api/pkgmeta/<tid> now run
path_segment_safe(tid) explicitly. The lookup gate they relied on
(get_title_action_info) is defense-by-coincidence — a future refactor
that populates g_titles via another path would lose the check.

patchdl_scan and patchdl_scan_debug_json perform a process-wide vnode
swap that is only safe single-threaded. patchdl_scan_lock() is now
called once right after MHD_start_daemon; subsequent calls return -1 /
NULL instead of racing the worker threads.

EVP_DigestFinal_ex return code is now checked. A failed final left dig
uninitialized; hex_encode would have produced empty hex and a silent
-2 with no diagnostic. patchdl_sha256_fd_region switches its inner
sprintf to snprintf — same effect, no -Wformat-security warning.
2026-06-24 20:39:43 +02:00
Knutwurst fcb0a5c3b0 Concurrency: atomic g_stage/g_err, snapshot pkg_diag, safe open, SQLite mutex
g_stage and g_err are now _Atomic. The backend init thread publishes
stage transitions and function-pointer assignments; HTTP request
handlers read g_stage to decide whether to call the Sony API. With the
old `volatile int` reads, nothing in the C memory model ordered the
function-pointer loads against the stage check — a stage==5 sighting
could (in theory) come before the pointer stores were visible. Default
seq_cst on _Atomic gives us the acquire/release pairing for free.

/api/pkgdiag returned g_pkg_diag_json directly with RESPMEM_PERSISTENT,
so MHD's writer thread could read the buffer while record_pkg_diag was
mid-snprintf — torn JSON or a missing NUL terminator. Snapshot under
g_mutex into a heap copy and queue with RESPMEM_MUST_FREE instead.

patchdl_net.c gets fopen_safe(): open() with O_NOFOLLOW|O_CLOEXEC and
mode 0600, then fdopen. The old fopen("wb") follows symlinks (a
malicious symlink at dest_path could redirect the write) and creates
mode 0666 (libc default). Both download paths now use it.

patchdl_appdb opens SQLite with SQLITE_OPEN_FULLMUTEX. Today the scan
runs on the startup thread only, but a future rescan triggered from the
HTTP thread would otherwise race the handle.
2026-06-24 20:35:31 +02:00
Knutwurst a6d9f939b5 OOM/stack protection: cap POST body, validate basename, heap playgo
POST handler: cap accumulated body at PATCHDL_POST_MAX_BYTES (64 KiB).
A LAN client streaming gigabytes into /api/config would otherwise grow
the per-connection buffer until OOM-kill. Past the cap, further chunks
are dropped and the final call returns 413.

title_pkg_path: the basename comes from the patch_url and ultimately
from version.xml via the Sony CDN. A poisoned manifest with a basename
like ".." or one containing delimiters would compose a dest path that
escapes /data/patchdl/<tid>/. Validate the basename through
path_segment_safe and fall back to "<title_id>.pkg" on rejection.
cleanup_installed_download now routes through the same helper instead
of doing its own basename extraction.

ai_install_by_package's playgo struct is 0x2700 bytes — comfortably
fine on its own, but on the MHD worker stack alongside meta/pkg/uris
buffers and Sony's own frame use it leaves little headroom. Move it to
the heap in both patchdl_install_local_pkg and patchdl_install_by_uri.
2026-06-24 20:32:45 +02:00
Knutwurst 5ba72b850c Net: scope JSON parser, cap manifest, harden DNS/CURL allowlist
Manifest JSON parser used substring scans with no per-piece scope; a key
defined in a later piece could be misattributed to the current one, and
the escape handling silently dropped the byte after a backslash even for
unknown escapes. json_string_after/json_u64_after now take an optional
limit pointer (NULL = legacy unbounded), and the manifest loops pass
obj_end so per-piece reads can't leak across pieces. JSON escapes are
decoded properly: \" \\ \/ \n \r \t \b \f; unknown \X drops the
backslash and keeps the payload byte.

Sanity caps on assembled manifests: PATCHDL_MAX_PIECES (4096),
PATCHDL_MAX_PIECE_BYTES (8 GiB), PATCHDL_MAX_TOTAL_BYTES (200 GiB).
A malformed manifest with a single multi-TB piece or millions of entries
is now rejected before any disk activity.

patchdl_buf_t gains an optional `max` field; write_cb fails the transfer
when growth would exceed it. patchdl_http_get preserves the caller-set
max across its internal memset(). verxml_query caps at 16 MiB,
fetch_manifest and download_manifest at 64 MiB.

host_allowed switches to strcasecmp (DNS is case-insensitive; an upstream
redirect could otherwise drop out of the list). CURLOPT_PROTOCOLS_STR /
REDIR_PROTOCOLS_STR pin all traffic and redirects to HTTPS.
CURLOPT_NOSIGNAL=1 prevents libcurl from raising SIGPIPE in a worker.

DNS label parser bounds-checks the length byte before incrementing pos,
so a malformed response with a 0xFF label near the end can no longer
read past the receive buffer.

extract_title_id used `p[8]` as the loop guard, which crossed the NUL
terminator on strings shorter than 9 chars (UB). Replaced with a
strlen-based bound.
2026-06-24 20:29:24 +02:00
Knutwurst 2f3490f21a Install: pad Sony output buffers, validate ids spliced into URIs
Sony's GetTitleIdFromPkg, GetContentIdFromPkg and GetInstallStatus take
output buffers with no length hint. We sized them to the visible id
length (0x30 / 0x40), but the firmware may NUL-pad more — that class of
bug already crashed the process once (commit 970c7d8). Switch all three
calls to padded AI_*_OUT_SIZE temporaries and copy_bounded() the safe
portion back into the right-sized destination.

patchdl_install_local_pkg extracts title_id and file_base from the
caller's local_path and splices them into http://127.0.0.1:.../api/pkg/
and the LAN equivalent that get fed to InstallByPackage. A path with
CRLF or '/' embedded in the basename would inject into Sony's HTTP
request line. install_id_safe() now gates both before they reach the
URI builders; on failure the loop / LAN URI is simply omitted (the
direct sdk_path and file:// URIs still run).

title_id_eq9() replaces strncmp(...,9): PS4/PS5 ids are exactly 9
chars (4 letters + 5 digits), and a prefix match would let PPSA12345
collide with PPSA12345EVIL when a future caller passes a longer string.
2026-06-24 20:24:20 +02:00
Knutwurst 80c47d6777 Validate install endpoints; cap MHD connections
/api/install_aip path must be PATCHDL_DL_DIR/<safe-title-id>/<safe-filename>,
rejecting attempts to point AppInstUtil at arbitrary on-disk PKGs (e.g.
/system/..., /user/uploads/...). local_install_path_safe enforces the
shape and reuses path_segment_safe for both segments.

/api/install_uri requires https:// to a Sony CDN host (subdomain match
against sgst/gst/gs2.*.playstation.net). file://, http://, and arbitrary
hosts are refused. The CDN list duplicates patchdl_net.c's ALLOWED_HOSTS
deliberately — both layers gate independently, both must stay in sync.

content_id / title_id from both endpoints now go through path_segment_safe
before reaching the install backend, so they cannot smuggle delimiters or
control chars into Sony's HTTP fetch.

MHD gets CONNECTION_LIMIT=64 (was unbounded with THREAD_PER_CONNECTION),
PER_IP_CONNECTION_LIMIT=8, CONNECTION_TIMEOUT=30s. A noisy LAN client
can no longer exhaust pthreads on the PS5.
2026-06-24 20:21:43 +02:00
Knutwurst 970c7d8f1d Install patches via sceAppInstUtilAppInstallPkg; fix GetInstallStatus ABI
sceAppInstUtilInstallByPackage returns 0x80B21163 from payload context
(process privilege rejection). sceAppInstUtilAppInstallPkg accepts the
same PKG with rc=0 and does install it. Switch all install paths to use
AppInstallPkg.

do_install (cross-region): require assembled PKG from the manifest
download; InstallByPackage and DP.pkg fallbacks are removed since both
are dead ends in this process context. do_install (same-region): also
switched to AppInstallPkg. do_download: removed the DP.pkg shortcut so
the manifest-assembled full PKG is downloaded as before.

sceAppInstUtilGetInstallStatus ABI: first arg is an output buffer for
the current install's content_id, not an input query. Passing our
tracking buffer there was overwriting it with zeros (disc game has no
explicit content_id). Fix: use a fresh output buffer; keep `cid` from
g_last_content_id untouched. Also add 2048-byte padding to
ai_install_status_t against firmware struct size variance.

New APIs: patchdl_install_by_uri, patchdl_install_app_pkg,
patchdl_install_debug_state. New endpoints: /api/install_uri,
/api/install_aip, /api/debug_install. delta_url propagated through
verxml → scan → websrv for future DP.pkg tracking.

Verified on device (FW 11.60, BD-JB+PPPwn): Dead Island 2 PPSA03099
updated from 01.000.001 to 01.000.011.
2026-06-24 20:04:11 +02:00
Knutwurst 983f39fa89 Harden AppInstUtil install path and status tracking 2026-06-24 17:19:34 +02:00
Knutwurst 79e1c377ed Update README for 0.0.3: parallel pool, resume, verify, honest install status
Document the connection-pool download (configurable 1–16, applied live), the
download queue, reboot-safe per-piece resume, Pause/Resume/Cancel, optional
SHA-256 verification, and on-device package verification. Add a Settings section.
Rewrite Status: download + verify is proven on 11.60 (a 61.6 GB update verified
byte-perfect across reboots); same-region install works; cross-region debug-magic
patches download and verify but cannot be installed via homebrew on 11.60.
2026-06-24 15:53:45 +02:00
Knutwurst fb9d06fb5b Install: pass the /user/data path Sony allowlists; report per-URI rc
Sony path-allowlists the URI given to sceAppInstUtilInstallByPackage —
/user/data/ and /mnt/usb are accepted, a bare /data/... path is rejected with
0x80B2116F (confirmed by the ps5upload project). PatchDL stored the pkg under
/data/patchdl and passed that /data path, so every install was rejected at the
path stage. Pass the /user/data view of the same file instead (the code already
computed it as sdk_path; it was only used for AppInstallPkg before).

Also report each URI's individual rc instead of only the last attempt's, which
revealed the real wall: via file:// the installer reaches header parsing and
rejects with 0x80B21106 — the assembled file is a valid but DEBUG-magic PKG
(\x7FFIH, not retail \x7FCNT), the format Sony's system updater consumes rather
than the retail-pkg format InstallByPackage expects.
2026-06-24 14:25:50 +02:00
Knutwurst 3d2ee430e1 Add read-only pkg diagnostics: manifest dump, integrity verify, embedded ids
Three read-only endpoints (no install, no writes) to inspect a downloaded
package on-device:

- GET /api/manifest/<title_id> — re-fetch the patch manifest (PatchDL bypasses
  the DNS block) and dump each piece's offset/size/SHA-256.
- GET /api/pkgverify/<title_id> — SHA-256 every piece of the assembled .pkg
  against the manifest hashes, on-device (SSD, no multi-GB transfer), and report
  per-piece pass/fail. Proves whether the file is byte-correct.
- GET /api/pkgmeta/<title_id> — read the pkg's embedded content id + title id
  (GetContentIdFromPkg) vs the target ids, to expose cross-region linkage.

Supporting code: patchdl_sha256_fd_region() (pread + OpenSSL EVP) in the net
layer, and bind sceAppInstUtilGetContentIdFromPkg in the install backend.

Used to diagnose the Dead Island 2 install: the 61.6 GB package verifies
byte-perfect (17/17 pieces) and its content id matches the target, so the
0x80B2116F install rejection is a Sony install-method limitation, not the data.
2026-06-24 14:10:39 +02:00
Knutwurst 986ff00c36 Persist resume state every piece; replace conn field with a stepper
Resume: write the sidecar after every completed piece instead of batching
every 8. Each piece's bytes are already fdatasync'd and the sidecar write is
a tiny atomic tmp+rename, so an unclean kill now re-downloads only the pieces
still in flight, not a batch of up-to-8 already-finished ones. Drops the now
-unused 'unpersisted' counter.

UI: the "parallel download connections" control is now a stepper — two large
54px -/+ buttons around a tabular value, in a row beside its label, instead of
a full-width number field for a 1-16 value. Big targets and a clear green focus
ring suit controller navigation (the UI is driven by the PS5 pad via the home
tile). Tapping -/+ updates and auto-saves that field alone (debounced), applying
live on the server.
2026-06-24 12:10:29 +02:00
Knutwurst 6024dbfc5d Apply the connection-count setting live, without a payload restart
The pool now spawns the full worker set at startup and gates each worker by
its slot against a live active_conns limit, instead of spawning exactly
max_connections threads once. Saving a new value in Settings updates the
limit and broadcasts: idle workers wake to pull pieces, and a lowered limit
parks the extra workers after they finish their current piece. No restart,
and no thread creation/teardown at runtime.

Verified on device: max_connections changed 4 -> 8 -> 16 -> 4 through the API
while a download stayed active throughout. (Throughput did not scale with
connections on this CDN, which caps aggregate bandwidth per source IP; 4 is a
sensible default.)
2026-06-24 11:36:48 +02:00
Knutwurst 21f6bd61ad Download patches over a connection pool with a queue and resume
Replace the single sequential transfer with a pool of N worker threads
that pull pieces of one manifest in parallel, lifting the per-connection
~7 MB/s ceiling. One job runs at a time; the rest queue. The connection
count is configurable (1-16, default 4) and applies on the next start.

Resume is tracked per piece in a sidecar bitmap that survives a reboot,
and a one-time migration recognises a partial written by the old
sequential build (a piece-aligned contiguous prefix on disk) and marks
those pieces done so an in-progress download is not restarted from zero.

Pause keeps the partial; Cancel deletes it. Both, plus Resume, are
available at any point in a download's life.

Concurrency review fixes folded in:
- a job is published as the active (claimable) job only after its
  manifest/state/fd are attached, so a half-built job can no longer be
  settled to "done" before any bytes are fetched
- cancel/pause during the admit I/O window only flag the job; admit_next
  is the sole finalizer, closing a use-after-free and a lost-pause race
- resuming a paused job frees the stale per-job buffers and zeroes the
  committed counters before re-seeding, fixing a leak and a double-count
- the background version.xml thread is joined on shutdown before the
  title list is freed
- verify_downloads is snapshotted under its own lock before the pool lock
- the web UI keeps Resume/Cancel after a failed transfer and bounds the
  local "downloading" bridge flag so a card cannot wedge
2026-06-24 11:12:25 +02:00
Knutwurst 01eaef79f2 Add pause/resume, within-part byte-range resume; bump to 0.0.3
Split the single morphing button into a green/amber play-pause (Update →
Pause → Resume) and a red stop (Cancel). Pause aborts the download but
keeps the partial (resumable); Cancel aborts and deletes. Backend gets a
separate pause flag distinct from cancel.

Resume now continues WITHIN a part: the partially-written piece is fetched
from its last byte via an HTTP byte range (with a safe fall back to
re-fetching the whole piece if the CDN ignores the range), instead of
re-downloading the whole part. A title is resumable as soon as any bytes
are on disk.

Version bumped to 0.0.3 (no release tagged).
2026-06-24 09:47:44 +02:00
Knutwurst 66e4912485 Resume interrupted downloads across a reboot
An interrupted download (cancel excepted) now keeps its partial package on
disk instead of deleting it, and records the manifest it belongs to in a
sidecar (state.json). On the next start the title is flagged resumable and
the UI shows a "Paused — X downloaded" note with a Resume button.

Resume refetches the manifest, skips every piece already fully on disk, and
re-fetches only the one partially-written piece (piece-granular, no HTTP
range needed), appending the rest. The fresh-download path is unchanged. A
partial belonging to a different/older manifest is dropped and the download
starts clean; a corrupt (failed SHA-256) download is not kept.

Survives a reboot: a killed payload runs no cleanup, so the partial and its
sidecar persist under /data/patchdl until resumed, completed, or deleted.
2026-06-24 08:58:32 +02:00
47 changed files with 4462 additions and 469 deletions

No files matched your search

+6
View File
@@ -0,0 +1,6 @@
# Files included in the release archive.
# One path per line, relative to the repository root.
patchdl-ps5.elf
README.md
LICENSE
+148
View File
@@ -0,0 +1,148 @@
name: PS5 Build and Release
on:
push:
paths-ignore:
- "**/*.md"
- "docs/**"
- "photos/**"
pull_request:
paths-ignore:
- "**/*.md"
- "docs/**"
- "photos/**"
workflow_dispatch:
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}-${{ github.event_name }}
cancel-in-progress: false
permissions:
contents: read
jobs:
build:
outputs:
archive_name: ${{ steps.package.outputs.archive_name }}
runs-on: ubuntu-latest
steps:
- name: Checkout PatchDL
uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Checkout pacbrew-repo
uses: actions/checkout@v4
with:
repository: ps5-payload-dev/pacbrew-repo
path: pacbrew-repo
- name: Checkout SDK stubs
uses: actions/checkout@v4
with:
repository: ps5-payload-dev/sdk
path: ps5-sdk
- name: Setup build environment
run: |
sudo apt update
sudo apt install -y \
autoconf \
automake \
build-essential \
clang-18 \
cmake \
curl \
git \
libarchive-tools \
libtool \
lld-18 \
makepkg \
meson \
ninja-build \
pacman-package-manager \
pkg-config \
python3 \
zip
- name: Build and install pacbrew packages
shell: bash
run: |
set -euo pipefail
build_and_install() {
local package_dir="$1"
pushd "pacbrew-repo/${package_dir}"
makepkg -c -f
sudo pacman --noconfirm -U ./ps5-payload-*.pkg.tar.gz
popd
}
build_and_install sdk
build_and_install libcxx
build_and_install zlib
build_and_install zstd
build_and_install openssl
build_and_install libpsl
build_and_install curl
- name: Build payload
env:
PS5_PAYLOAD_SDK: /opt/ps5-payload-sdk
PS5_SCE_STUBS_DIR: ${{ github.workspace }}/ps5-sdk/sce_stubs
run: |
scripts/build_ps5.sh clean all
- name: Create release archive
id: package
shell: bash
run: |
set -euo pipefail
version_tag="$(git describe --abbrev=6 --dirty --always --tags 2>/dev/null || echo "${GITHUB_SHA::7}")"
archive_name="PatchDL_${version_tag}.zip"
manifest_file=".github/release-files.txt"
mapfile -t release_files < <(grep -Ev '^[[:space:]]*(#|$)' "${manifest_file}")
if [ "${#release_files[@]}" -eq 0 ]; then
echo "Release manifest is empty: ${manifest_file}" >&2
exit 1
fi
for release_file in "${release_files[@]}"; do
if [ ! -f "${release_file}" ]; then
echo "Missing release file: ${release_file}" >&2
exit 1
fi
done
zip -9 "${archive_name}" "${release_files[@]}"
echo "archive_name=${archive_name}" >> "$GITHUB_OUTPUT"
- name: Upload build artifacts
uses: actions/upload-artifact@v4
with:
name: ${{ steps.package.outputs.archive_name }}
path: ${{ steps.package.outputs.archive_name }}
if-no-files-found: error
release:
needs: build
permissions:
contents: write
if: startsWith(github.ref, 'refs/tags/')
runs-on: ubuntu-latest
steps:
- name: Download build artifacts
uses: actions/download-artifact@v4
with:
name: ${{ needs.build.outputs.archive_name }}
path: dist
- name: Create GitHub Release
uses: softprops/action-gh-release@v2
with:
tag_name: ${{ github.ref_name }}
generate_release_notes: true
files: dist/${{ needs.build.outputs.archive_name }}
+674
View File
@@ -0,0 +1,674 @@
GNU GENERAL PUBLIC LICENSE
Version 3, 29 June 2007
Copyright (C) 2007 Free Software Foundation, Inc. <https://fsf.org/>
Everyone is permitted to copy and distribute verbatim copies
of this license document, but changing it is not allowed.
Preamble
The GNU General Public License is a free, copyleft license for
software and other kinds of works.
The licenses for most software and other practical works are designed
to take away your freedom to share and change the works. By contrast,
the GNU General Public License is intended to guarantee your freedom to
share and change all versions of a program--to make sure it remains free
software for all its users. We, the Free Software Foundation, use the
GNU General Public License for most of our software; it applies also to
any other work released this way by its authors. You can apply it to
your programs, too.
When we speak of free software, we are referring to freedom, not
price. Our General Public Licenses are designed to make sure that you
have the freedom to distribute copies of free software (and charge for
them if you wish), that you receive source code or can get it if you
want it, that you can change the software or use pieces of it in new
free programs, and that you know you can do these things.
To protect your rights, we need to prevent others from denying you
these rights or asking you to surrender the rights. Therefore, you have
certain responsibilities if you distribute copies of the software, or if
you modify it: responsibilities to respect the freedom of others.
For example, if you distribute copies of such a program, whether
gratis or for a fee, you must pass on to the recipients the same
freedoms that you received. You must make sure that they, too, receive
or can get the source code. And you must show them these terms so they
know their rights.
Developers that use the GNU GPL protect your rights with two steps:
(1) assert copyright on the software, and (2) offer you this License
giving you legal permission to copy, distribute and/or modify it.
For the developers' and authors' protection, the GPL clearly explains
that there is no warranty for this free software. For both users' and
authors' sake, the GPL requires that modified versions be marked as
changed, so that their problems will not be attributed erroneously to
authors of previous versions.
Some devices are designed to deny users access to install or run
modified versions of the software inside them, although the manufacturer
can do so. This is fundamentally incompatible with the aim of
protecting users' freedom to change the software. The systematic
pattern of such abuse occurs in the area of products for individuals to
use, which is precisely where it is most unacceptable. Therefore, we
have designed this version of the GPL to prohibit the practice for those
products. If such problems arise substantially in other domains, we
stand ready to extend this provision to those domains in future versions
of the GPL, as needed to protect the freedom of users.
Finally, every program is threatened constantly by software patents.
States should not allow patents to restrict development and use of
software on general-purpose computers, but in those that do, we wish to
avoid the special danger that patents applied to a free program could
make it effectively proprietary. To prevent this, the GPL assures that
patents cannot be used to render the program non-free.
The precise terms and conditions for copying, distribution and
modification follow.
TERMS AND CONDITIONS
0. Definitions.
"This License" refers to version 3 of the GNU General Public License.
"Copyright" also means copyright-like laws that apply to other kinds of
works, such as semiconductor masks.
"The Program" refers to any copyrightable work licensed under this
License. Each licensee is addressed as "you". "Licensees" and
"recipients" may be individuals or organizations.
To "modify" a work means to copy from or adapt all or part of the work
in a fashion requiring copyright permission, other than the making of an
exact copy. The resulting work is called a "modified version" of the
earlier work or a work "based on" the earlier work.
A "covered work" means either the unmodified Program or a work based
on the Program.
To "propagate" a work means to do anything with it that, without
permission, would make you directly or secondarily liable for
infringement under applicable copyright law, except executing it on a
computer or modifying a private copy. Propagation includes copying,
distribution (with or without modification), making available to the
public, and in some countries other activities as well.
To "convey" a work means any kind of propagation that enables other
parties to make or receive copies. Mere interaction with a user through
a computer network, with no transfer of a copy, is not conveying.
An interactive user interface displays "Appropriate Legal Notices"
to the extent that it includes a convenient and prominently visible
feature that (1) displays an appropriate copyright notice, and (2)
tells the user that there is no warranty for the work (except to the
extent that warranties are provided), that licensees may convey the
work under this License, and how to view a copy of this License. If
the interface presents a list of user commands or options, such as a
menu, a prominent item in the list meets this criterion.
1. Source Code.
The "source code" for a work means the preferred form of the work
for making modifications to it. "Object code" means any non-source
form of a work.
A "Standard Interface" means an interface that either is an official
standard defined by a recognized standards body, or, in the case of
interfaces specified for a particular programming language, one that
is widely used among developers working in that language.
The "System Libraries" of an executable work include anything, other
than the work as a whole, that (a) is included in the normal form of
packaging a Major Component, but which is not part of that Major
Component, and (b) serves only to enable use of the work with that
Major Component, or to implement a Standard Interface for which an
implementation is available to the public in source code form. A
"Major Component", in this context, means a major essential component
(kernel, window system, and so on) of the specific operating system
(if any) on which the executable work runs, or a compiler used to
produce the work, or an object code interpreter used to run it.
The "Corresponding Source" for a work in object code form means all
the source code needed to generate, install, and (for an executable
work) run the object code and to modify the work, including scripts to
control those activities. However, it does not include the work's
System Libraries, or general-purpose tools or generally available free
programs which are used unmodified in performing those activities but
which are not part of the work. For example, Corresponding Source
includes interface definition files associated with source files for
the work, and the source code for shared libraries and dynamically
linked subprograms that the work is specifically designed to require,
such as by intimate data communication or control flow between those
subprograms and other parts of the work.
The Corresponding Source need not include anything that users
can regenerate automatically from other parts of the Corresponding
Source.
The Corresponding Source for a work in source code form is that
same work.
2. Basic Permissions.
All rights granted under this License are granted for the term of
copyright on the Program, and are irrevocable provided the stated
conditions are met. This License explicitly affirms your unlimited
permission to run the unmodified Program. The output from running a
covered work is covered by this License only if the output, given its
content, constitutes a covered work. This License acknowledges your
rights of fair use or other equivalent, as provided by copyright law.
You may make, run and propagate covered works that you do not
convey, without conditions so long as your license otherwise remains
in force. You may convey covered works to others for the sole purpose
of having them make modifications exclusively for you, or provide you
with facilities for running those works, provided that you comply with
the terms of this License in conveying all material for which you do
not control copyright. Those thus making or running the covered works
for you must do so exclusively on your behalf, under your direction
and control, on terms that prohibit them from making any copies of
your copyrighted material outside their relationship with you.
Conveying under any other circumstances is permitted solely under
the conditions stated below. Sublicensing is not allowed; section 10
makes it unnecessary.
3. Protecting Users' Legal Rights From Anti-Circumvention Law.
No covered work shall be deemed part of an effective technological
measure under any applicable law fulfilling obligations under article
11 of the WIPO copyright treaty adopted on 20 December 1996, or
similar laws prohibiting or restricting circumvention of such
measures.
When you convey a covered work, you waive any legal power to forbid
circumvention of technological measures to the extent such circumvention
is effected by exercising rights under this License with respect to
the covered work, and you disclaim any intention to limit operation or
modification of the work as a means of enforcing, against the work's
users, your or third parties' legal rights to forbid circumvention of
technological measures.
4. Conveying Verbatim Copies.
You may convey verbatim copies of the Program's source code as you
receive it, in any medium, provided that you conspicuously and
appropriately publish on each copy an appropriate copyright notice;
keep intact all notices stating that this License and any
non-permissive terms added in accord with section 7 apply to the code;
keep intact all notices of the absence of any warranty; and give all
recipients a copy of this License along with the Program.
You may charge any price or no price for each copy that you convey,
and you may offer support or warranty protection for a fee.
5. Conveying Modified Source Versions.
You may convey a work based on the Program, or the modifications to
produce it from the Program, in the form of source code under the
terms of section 4, provided that you also meet all of these conditions:
a) The work must carry prominent notices stating that you modified
it, and giving a relevant date.
b) The work must carry prominent notices stating that it is
released under this License and any conditions added under section
7. This requirement modifies the requirement in section 4 to
"keep intact all notices".
c) You must license the entire work, as a whole, under this
License to anyone who comes into possession of a copy. This
License will therefore apply, along with any applicable section 7
additional terms, to the whole of the work, and all its parts,
regardless of how they are packaged. This License gives no
permission to license the work in any other way, but it does not
invalidate such permission if you have separately received it.
d) If the work has interactive user interfaces, each must display
Appropriate Legal Notices; however, if the Program has interactive
interfaces that do not display Appropriate Legal Notices, your
work need not make them do so.
A compilation of a covered work with other separate and independent
works, which are not by their nature extensions of the covered work,
and which are not combined with it such as to form a larger program,
in or on a volume of a storage or distribution medium, is called an
"aggregate" if the compilation and its resulting copyright are not
used to limit the access or legal rights of the compilation's users
beyond what the individual works permit. Inclusion of a covered work
in an aggregate does not cause this License to apply to the other
parts of the aggregate.
6. Conveying Non-Source Forms.
You may convey a covered work in object code form under the terms
of sections 4 and 5, provided that you also convey the
machine-readable Corresponding Source under the terms of this License,
in one of these ways:
a) Convey the object code in, or embodied in, a physical product
(including a physical distribution medium), accompanied by the
Corresponding Source fixed on a durable physical medium
customarily used for software interchange.
b) Convey the object code in, or embodied in, a physical product
(including a physical distribution medium), accompanied by a
written offer, valid for at least three years and valid for as
long as you offer spare parts or customer support for that product
model, to give anyone who possesses the object code either (1) a
copy of the Corresponding Source for all the software in the
product that is covered by this License, on a durable physical
medium customarily used for software interchange, for a price no
more than your reasonable cost of physically performing this
conveying of source, or (2) access to copy the
Corresponding Source from a network server at no charge.
c) Convey individual copies of the object code with a copy of the
written offer to provide the Corresponding Source. This
alternative is allowed only occasionally and noncommercially, and
only if you received the object code with such an offer, in accord
with subsection 6b.
d) Convey the object code by offering access from a designated
place (gratis or for a charge), and offer equivalent access to the
Corresponding Source in the same way through the same place at no
further charge. You need not require recipients to copy the
Corresponding Source along with the object code. If the place to
copy the object code is a network server, the Corresponding Source
may be on a different server (operated by you or a third party)
that supports equivalent copying facilities, provided you maintain
clear directions next to the object code saying where to find the
Corresponding Source. Regardless of what server hosts the
Corresponding Source, you remain obligated to ensure that it is
available for as long as needed to satisfy these requirements.
e) Convey the object code using peer-to-peer transmission, provided
you inform other peers where the object code and Corresponding
Source of the work are being offered to the general public at no
charge under subsection 6d.
A separable portion of the object code, whose source code is excluded
from the Corresponding Source as a System Library, need not be
included in conveying the object code work.
A "User Product" is either (1) a "consumer product", which means any
tangible personal property which is normally used for personal, family,
or household purposes, or (2) anything designed or sold for incorporation
into a dwelling. In determining whether a product is a consumer product,
doubtful cases shall be resolved in favor of coverage. For a particular
product received by a particular user, "normally used" refers to a
typical or common use of that class of product, regardless of the status
of the particular user or of the way in which the particular user
actually uses, or expects or is expected to use, the product. A product
is a consumer product regardless of whether the product has substantial
commercial, industrial or non-consumer uses, unless such uses represent
the only significant mode of use of the product.
"Installation Information" for a User Product means any methods,
procedures, authorization keys, or other information required to install
and execute modified versions of a covered work in that User Product from
a modified version of its Corresponding Source. The information must
suffice to ensure that the continued functioning of the modified object
code is in no case prevented or interfered with solely because
modification has been made.
If you convey an object code work under this section in, or with, or
specifically for use in, a User Product, and the conveying occurs as
part of a transaction in which the right of possession and use of the
User Product is transferred to the recipient in perpetuity or for a
fixed term (regardless of how the transaction is characterized), the
Corresponding Source conveyed under this section must be accompanied
by the Installation Information. But this requirement does not apply
if neither you nor any third party retains the ability to install
modified object code on the User Product (for example, the work has
been installed in ROM).
The requirement to provide Installation Information does not include a
requirement to continue to provide support service, warranty, or updates
for a work that has been modified or installed by the recipient, or for
the User Product in which it has been modified or installed. Access to a
network may be denied when the modification itself materially and
adversely affects the operation of the network or violates the rules and
protocols for communication across the network.
Corresponding Source conveyed, and Installation Information provided,
in accord with this section must be in a format that is publicly
documented (and with an implementation available to the public in
source code form), and must require no special password or key for
unpacking, reading or copying.
7. Additional Terms.
"Additional permissions" are terms that supplement the terms of this
License by making exceptions from one or more of its conditions.
Additional permissions that are applicable to the entire Program shall
be treated as though they were included in this License, to the extent
that they are valid under applicable law. If additional permissions
apply only to part of the Program, that part may be used separately
under those permissions, but the entire Program remains governed by
this License without regard to the additional permissions.
When you convey a copy of a covered work, you may at your option
remove any additional permissions from that copy, or from any part of
it. (Additional permissions may be written to require their own
removal in certain cases when you modify the work.) You may place
additional permissions on material, added by you to a covered work,
for which you have or can give appropriate copyright permission.
Notwithstanding any other provision of this License, for material you
add to a covered work, you may (if authorized by the copyright holders of
that material) supplement the terms of this License with terms:
a) Disclaiming warranty or limiting liability differently from the
terms of sections 15 and 16 of this License; or
b) Requiring preservation of specified reasonable legal notices or
author attributions in that material or in the Appropriate Legal
Notices displayed by works containing it; or
c) Prohibiting misrepresentation of the origin of that material, or
requiring that modified versions of such material be marked in
reasonable ways as different from the original version; or
d) Limiting the use for publicity purposes of names of licensors or
authors of the material; or
e) Declining to grant rights under trademark law for use of some
trade names, trademarks, or service marks; or
f) Requiring indemnification of licensors and authors of that
material by anyone who conveys the material (or modified versions of
it) with contractual assumptions of liability to the recipient, for
any liability that these contractual assumptions directly impose on
those licensors and authors.
All other non-permissive additional terms are considered "further
restrictions" within the meaning of section 10. If the Program as you
received it, or any part of it, contains a notice stating that it is
governed by this License along with a term that is a further
restriction, you may remove that term. If a license document contains
a further restriction but permits relicensing or conveying under this
License, you may add to a covered work material governed by the terms
of that license document, provided that the further restriction does
not survive such relicensing or conveying.
If you add terms to a covered work in accord with this section, you
must place, in the relevant source files, a statement of the
additional terms that apply to those files, or a notice indicating
where to find the applicable terms.
Additional terms, permissive or non-permissive, may be stated in the
form of a separately written license, or stated as exceptions;
the above requirements apply either way.
8. Termination.
You may not propagate or modify a covered work except as expressly
provided under this License. Any attempt otherwise to propagate or
modify it is void, and will automatically terminate your rights under
this License (including any patent licenses granted under the third
paragraph of section 11).
However, if you cease all violation of this License, then your
license from a particular copyright holder is reinstated (a)
provisionally, unless and until the copyright holder explicitly and
finally terminates your license, and (b) permanently, if the copyright
holder fails to notify you of the violation by some reasonable means
prior to 60 days after the cessation.
Moreover, your license from a particular copyright holder is
reinstated permanently if the copyright holder notifies you of the
violation by some reasonable means, this is the first time you have
received notice of violation of this License (for any work) from that
copyright holder, and you cure the violation prior to 30 days after
your receipt of the notice.
Termination of your rights under this section does not terminate the
licenses of parties who have received copies or rights from you under
this License. If your rights have been terminated and not permanently
reinstated, you do not qualify to receive new licenses for the same
material under section 10.
9. Acceptance Not Required for Having Copies.
You are not required to accept this License in order to receive or
run a copy of the Program. Ancillary propagation of a covered work
occurring solely as a consequence of using peer-to-peer transmission
to receive a copy likewise does not require acceptance. However,
nothing other than this License grants you permission to propagate or
modify any covered work. These actions infringe copyright if you do
not accept this License. Therefore, by modifying or propagating a
covered work, you indicate your acceptance of this License to do so.
10. Automatic Licensing of Downstream Recipients.
Each time you convey a covered work, the recipient automatically
receives a license from the original licensors, to run, modify and
propagate that work, subject to this License. You are not responsible
for enforcing compliance by third parties with this License.
An "entity transaction" is a transaction transferring control of an
organization, or substantially all assets of one, or subdividing an
organization, or merging organizations. If propagation of a covered
work results from an entity transaction, each party to that
transaction who receives a copy of the work also receives whatever
licenses to the work the party's predecessor in interest had or could
give under the previous paragraph, plus a right to possession of the
Corresponding Source of the work from the predecessor in interest, if
the predecessor has it or can get it with reasonable efforts.
You may not impose any further restrictions on the exercise of the
rights granted or affirmed under this License. For example, you may
not impose a license fee, royalty, or other charge for exercise of
rights granted under this License, and you may not initiate litigation
(including a cross-claim or counterclaim in a lawsuit) alleging that
any patent claim is infringed by making, using, selling, offering for
sale, or importing the Program or any portion of it.
11. Patents.
A "contributor" is a copyright holder who authorizes use under this
License of the Program or a work on which the Program is based. The
work thus licensed is called the contributor's "contributor version".
A contributor's "essential patent claims" are all patent claims
owned or controlled by the contributor, whether already acquired or
hereafter acquired, that would be infringed by some manner, permitted
by this License, of making, using, or selling its contributor version,
but do not include claims that would be infringed only as a
consequence of further modification of the contributor version. For
purposes of this definition, "control" includes the right to grant
patent sublicenses in a manner consistent with the requirements of
this License.
Each contributor grants you a non-exclusive, worldwide, royalty-free
patent license under the contributor's essential patent claims, to
make, use, sell, offer for sale, import and otherwise run, modify and
propagate the contents of its contributor version.
In the following three paragraphs, a "patent license" is any express
agreement or commitment, however denominated, not to enforce a patent
(such as an express permission to practice a patent or covenant not to
sue for patent infringement). To "grant" such a patent license to a
party means to make such an agreement or commitment not to enforce a
patent against the party.
If you convey a covered work, knowingly relying on a patent license,
and the Corresponding Source of the work is not available for anyone
to copy, free of charge and under the terms of this License, through a
publicly available network server or other readily accessible means,
then you must either (1) cause the Corresponding Source to be so
available, or (2) arrange to deprive yourself of the benefit of the
patent license for this particular work, or (3) arrange, in a manner
consistent with the requirements of this License, to extend the patent
license to downstream recipients. "Knowingly relying" means you have
actual knowledge that, but for the patent license, your conveying the
covered work in a country, or your recipient's use of the covered work
in a country, would infringe one or more identifiable patents in that
country that you have reason to believe are valid.
If, pursuant to or in connection with a single transaction or
arrangement, you convey, or propagate by procuring conveyance of, a
covered work, and grant a patent license to some of the parties
receiving the covered work authorizing them to use, propagate, modify
or convey a specific copy of the covered work, then the patent license
you grant is automatically extended to all recipients of the covered
work and works based on it.
A patent license is "discriminatory" if it does not include within
the scope of its coverage, prohibits the exercise of, or is
conditioned on the non-exercise of one or more of the rights that are
specifically granted under this License. You may not convey a covered
work if you are a party to an arrangement with a third party that is
in the business of distributing software, under which you make payment
to the third party based on the extent of your activity of conveying
the work, and under which the third party grants, to any of the
parties who would receive the covered work from you, a discriminatory
patent license (a) in connection with copies of the covered work
conveyed by you (or copies made from those copies), or (b) primarily
for and in connection with specific products or compilations that
contain the covered work, unless you entered into that arrangement,
or that patent license was granted, prior to 28 March 2007.
Nothing in this License shall be construed as excluding or limiting
any implied license or other defenses to infringement that may
otherwise be available to you under applicable patent law.
12. No Surrender of Others' Freedom.
If conditions are imposed on you (whether by court order, agreement or
otherwise) that contradict the conditions of this License, they do not
excuse you from the conditions of this License. If you cannot convey a
covered work so as to satisfy simultaneously your obligations under this
License and any other pertinent obligations, then as a consequence you may
not convey it at all. For example, if you agree to terms that obligate you
to collect a royalty for further conveying from those to whom you convey
the Program, the only way you could satisfy both those terms and this
License would be to refrain entirely from conveying the Program.
13. Use with the GNU Affero General Public License.
Notwithstanding any other provision of this License, you have
permission to link or combine any covered work with a work licensed
under version 3 of the GNU Affero General Public License into a single
combined work, and to convey the resulting work. The terms of this
License will continue to apply to the part which is the covered work,
but the special requirements of the GNU Affero General Public License,
section 13, concerning interaction through a network will apply to the
combination as such.
14. Revised Versions of this License.
The Free Software Foundation may publish revised and/or new versions of
the GNU General Public License from time to time. Such new versions will
be similar in spirit to the present version, but may differ in detail to
address new problems or concerns.
Each version is given a distinguishing version number. If the
Program specifies that a certain numbered version of the GNU General
Public License "or any later version" applies to it, you have the
option of following the terms and conditions either of that numbered
version or of any later version published by the Free Software
Foundation. If the Program does not specify a version number of the
GNU General Public License, you may choose any version ever published
by the Free Software Foundation.
If the Program specifies that a proxy can decide which future
versions of the GNU General Public License can be used, that proxy's
public statement of acceptance of a version permanently authorizes you
to choose that version for the Program.
Later license versions may give you additional or different
permissions. However, no additional obligations are imposed on any
author or copyright holder as a result of your choosing to follow a
later version.
15. Disclaimer of Warranty.
THERE IS NO WARRANTY FOR THE PROGRAM, TO THE EXTENT PERMITTED BY
APPLICABLE LAW. EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT
HOLDERS AND/OR OTHER PARTIES PROVIDE THE PROGRAM "AS IS" WITHOUT WARRANTY
OF ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO,
THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE OF THE PROGRAM
IS WITH YOU. SHOULD THE PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF
ALL NECESSARY SERVICING, REPAIR OR CORRECTION.
16. Limitation of Liability.
IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING
WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MODIFIES AND/OR CONVEYS
THE PROGRAM AS PERMITTED ABOVE, BE LIABLE TO YOU FOR DAMAGES, INCLUDING ANY
GENERAL, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES ARISING OUT OF THE
USE OR INABILITY TO USE THE PROGRAM (INCLUDING BUT NOT LIMITED TO LOSS OF
DATA OR DATA BEING RENDERED INACCURATE OR LOSSES SUSTAINED BY YOU OR THIRD
PARTIES OR A FAILURE OF THE PROGRAM TO OPERATE WITH ANY OTHER PROGRAMS),
EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF
SUCH DAMAGES.
17. Interpretation of Sections 15 and 16.
If the disclaimer of warranty and limitation of liability provided
above cannot be given local legal effect according to their terms,
reviewing courts shall apply local law that most closely approximates
an absolute waiver of all civil liability in connection with the
Program, unless a warranty or assumption of liability accompanies a
copy of the Program in return for a fee.
END OF TERMS AND CONDITIONS
How to Apply These Terms to Your New Programs
If you develop a new program, and you want it to be of the greatest
possible use to the public, the best way to achieve this is to make it
free software which everyone can redistribute and change under these terms.
To do so, attach the following notices to the program. It is safest
to attach them to the start of each source file to most effectively
state the exclusion of warranty; and each file should have at least
the "copyright" line and a pointer to where the full notice is found.
<one line to give the program's name and a brief idea of what it does.>
Copyright (C) <year> <name of author>
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation, either version 3 of the License, or
(at your option) any later version.
This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU General Public License for more details.
You should have received a copy of the GNU General Public License
along with this program. If not, see <https://www.gnu.org/licenses/>.
Also add information on how to contact you by electronic and paper mail.
If the program does terminal interaction, make it output a short
notice like this when it starts in an interactive mode:
<program> Copyright (C) <year> <name of author>
This program comes with ABSOLUTELY NO WARRANTY; for details type `show w'.
This is free software, and you are welcome to redistribute it
under certain conditions; type `show c' for details.
The hypothetical commands `show w' and `show c' should show the appropriate
parts of the General Public License. Of course, your program's commands
might be different; for a GUI interface, you would use an "about box".
You should also get your employer (if you work as a programmer) or school,
if any, to sign a "copyright disclaimer" for the program, if necessary.
For more information on this, and how to apply and follow the GNU GPL, see
<https://www.gnu.org/licenses/>.
The GNU General Public License does not permit incorporating your program
into proprietary programs. If your program is a subroutine library, you
may consider it more useful to permit linking proprietary applications with
the library. If this is what you want to do, use the GNU Lesser General
Public License instead of this License. But first, please read
<https://www.gnu.org/licenses/why-not-lgpl.html>.
+8 -3
View File
@@ -23,7 +23,12 @@ SRCS := src/main.c \
src/patchdl_resolve.c \ src/patchdl_resolve.c \
src/patchdl_verxml.c \ src/patchdl_verxml.c \
src/patchdl_install.c \ src/patchdl_install.c \
src/patchdl_notify.c src/patchdl_notify.c \
src/patchdl_tile.c
# patchdl_tile.c uses .incbin to embed param.json + icon0.png; touching the
# assets must trigger a rebuild.
TILE_ASSETS := assets/param.json assets/icon0.png
WEB_ASSETS := web/index.html web/styles.css web/app.js WEB_ASSETS := web/index.html web/styles.css web/app.js
GEN_SRCS := $(patsubst web/%,gen/web/%.c,$(WEB_ASSETS)) GEN_SRCS := $(patsubst web/%,gen/web/%.c,$(WEB_ASSETS))
@@ -56,8 +61,8 @@ gen/web/%.c: web/% scripts/gen_asset_module.py | gen/web
$(SQLITE_OBJ): $(SQLITE_DIR)/sqlite3.c $(SQLITE_OBJ): $(SQLITE_DIR)/sqlite3.c
$(CC) $(SQLITE_CFLAGS) -c -o $@ $< $(CC) $(SQLITE_CFLAGS) -c -o $@ $<
$(BIN): $(SRCS) $(GEN_SRCS) $(SQLITE_OBJ) $(BIN): $(SRCS) $(GEN_SRCS) $(SQLITE_OBJ) $(TILE_ASSETS)
$(CC) $(CFLAGS) -o $@ $^ $(LDADD) $(CC) $(CFLAGS) -o $@ $(SRCS) $(GEN_SRCS) $(SQLITE_OBJ) $(LDADD)
test: $(BIN) test: $(BIN)
$(PS5_DEPLOY) -h $(PS5_HOST) -p $(PS5_PORT) $^ $(PS5_DEPLOY) -h $(PS5_HOST) -p $(PS5_PORT) $^
+97 -69
View File
@@ -1,95 +1,123 @@
# PatchDL <h1 align="center">PatchDL</h1>
A standalone PlayStation 5 ELF payload that downloads and installs official game <p align="center">
patches on your terms. It serves its own web UI and runs without etaHEN. <img src="docs/images/hero.jpg" alt="PatchDL in a desktop browser and on a phone, downloading a game update" width="900">
</p>
PatchDL is built for setups where nanoDNS blocks Sony's servers for the whole <p align="center">
console. It resolves the Sony patch CDN on its own path, so the rest of the <b>Official game updates for your PS5, from any browser.</b><br>
system stays offline and only the patches you pick get fetched. PatchDL finds the newest update for every game on your console, downloads it at full speed and installs it.<br>
Run it from your phone, your laptop or the PS5 itself.
</p>
by Knutwurst <p align="center">
<img src="https://img.shields.io/github/v/release/knutwurst/ps5-patchdl?style=for-the-badge&label=release&color=22c55e" alt="Latest release">
<img src="https://img.shields.io/github/downloads/knutwurst/ps5-patchdl/total?style=for-the-badge&color=22c55e" alt="Downloads">
<img src="https://img.shields.io/badge/FW%2011.60-tested-22c55e?style=for-the-badge" alt="Tested on firmware 11.60">
<img src="https://img.shields.io/badge/UI-any%20browser-22c55e?style=for-the-badge" alt="Web UI in any browser">
<img src="https://img.shields.io/github/license/knutwurst/ps5-patchdl?style=for-the-badge&color=3a3a3a" alt="License">
</p>
## What it does <p align="center">
<a href="https://github.com/knutwurst/ps5-patchdl/releases/latest">
<img src="https://img.shields.io/badge/Download-latest%20release-22c55e?style=for-the-badge&logo=github&logoColor=white" alt="Download the latest release" height="42">
</a>
</p>
- Scans installed titles and classifies each one: genuine install, ---
ShadowMountPlus mount, preinstall, or unknown.
- Reads the title name, installed version, and the Sony `version.xml` URL from
the PS5 app database.
- Fetches each title's `version.xml` from Sony's CDN past nanoDNS (a raw DNS
query to 1.1.1.1) and verifies TLS against the pinned SCEI DNAS root.
- Picks the newest patch compatible with the current firmware
(`system_ver <= firmware`), so an update never forces a firmware upgrade.
- Downloads the installable package from Sony's manifest pieces and installs it
through Sony's AppInstUtil service.
## Safety model ## Highlights
Deny-by-default. A patch is installed only for a genuine install, and only when - **Your whole library at a glance.** Every installed game shows up with its version and the newest update Sony offers for it.
the patch metadata targets the installed game: - **Update all.** One click queues every game that has an update. PatchDL works through the queue and installs each update as soon as it lands.
- **Fast downloads.** Up to 16 parallel connections per update. Change the number in Settings while a download runs.
- **Survives reboots.** Pause, resume, or lose power: PatchDL saves progress after every finished piece and continues where it stopped.
- **Made for your firmware.** You only see updates your console can run, so no game ends up asking for newer system software.
- **Checked against Sony's checksums.** Turn on verification and PatchDL compares every piece with the SHA-256 Sony publishes for it.
- **A tile on your home screen.** One toggle adds PatchDL to the PS5 home screen. Tap it and the UI opens in the console's browser.
- **Live progress.** A banner at the top shows the current game, speed, time left and where you are in the queue.
| Source | Check | Download | Install | ## Screenshots
|-----------------------|-------|----------|---------|
| official | yes | yes | yes |
| shadowmount | yes | yes | no |
| preinstall / unknown | yes | no | no |
Two independent guards stop the wrong target being installed: the patch target <table>
id (read from `version.xml` / `manifest_url`) must match the installed game, and <tr>
the install call receives the installed game's content id from app.db. Sony may <td align="center" width="50%"><img src="docs/images/games.jpg" width="420" alt="Games view with a running download"><br><sub><b>Games</b> &nbsp;·&nbsp; every game, its version and the update waiting for it</sub></td>
store the actual patch bytes under a regional/master title id that differs from <td align="center" width="50%"><img src="docs/images/queue.jpg" width="420" alt="Updating view with two queued updates"><br><sub><b>Updating</b> &nbsp;·&nbsp; the queue, next to the download that's running</sub></td>
the target; that storage id is accepted only when `version.xml` targets the </tr>
installed title. A true target-title mismatch is refused instead of installed as <tr>
a phantom title. <td align="center" width="50%"><img src="docs/images/settings.jpg" width="420" alt="Settings view"><br><sub><b>Settings</b> &nbsp;·&nbsp; changes apply right away, no restart</sub></td>
<td align="center" width="50%"><img src="docs/images/tile-homescreen.jpg" width="420" alt="PatchDL tile on the PS5 home screen"><br><sub><b>Home screen</b> &nbsp;·&nbsp; the PatchDL tile on a real PS5</sub></td>
</tr>
</table>
For PS5 titles, `delta_url` often points to a small `*-DP.pkg` helper package. ## Fits any screen
That bootstrap can make the system fetch the full patch, but it follows the
package's storage/master title id and can create a duplicate/ghost title for
cross-region updates. PatchDL therefore prefers the Sony `manifest_url`,
downloads every listed `pieces[]` entry in order, and concatenates them into one
local `.pkg` before handing it to AppInstUtil. The `delta_url` title id is kept
only as the storage/master-id diagnostic.
## Build Start an update from the couch with your phone, check on it from your laptop, or open it on the TV. The UI adapts to whatever screen it's on.
Requires `ps5-payload-dev/sdk`. The network and install features also need the <p align="center">
prebuilt libcurl + OpenSSL from `ps5-payload-dev/pacbrew-repo` placed in the SDK <img src="docs/images/phones.jpg" alt="PatchDL on a phone: game list with a download, and Settings" width="560">
sysroot (`target/user/homebrew`); `scripts/build_ps5.sh` enables them </p>
automatically when present. libmicrohttpd is vendored under `vendor/etahen`, and
SQLite is vendored under `vendor/sqlite`. ## Get started
1. Download `patchdl_<version>.elf` from the [latest release](https://github.com/knutwurst/ps5-patchdl/releases/latest).
2. Send it to your PS5 with the ELF loader you already use.
3. A notification on the TV shows the address, for example `http://192.168.0.42:12880/`. Open it in any browser on your network.
4. Optional: switch on **Home-screen shortcut** in Settings to get the PatchDL tile.
**You need** a PS5 that can load ELF payloads. PatchDL is tested on firmware 11.60.
## Good to know
**Does PatchDL download games?**
No. It fetches updates for games that are already installed on your console. Nothing else.
**Where do the updates come from?**
From Sony's official update servers, the same files your console downloads on its own. PatchDL only talks to a short list of PlayStation CDN hosts.
**Does it change the updates?**
No. Each package stays exactly as Sony published it, and the console's own installer applies it.
**Will it touch my system software?**
No. PatchDL never downloads system software, and it only offers game updates that run on the firmware you have.
**What about disc games?**
Put the disc in, same as with any update.
**What happens if the power goes out?**
Start PatchDL again and press Resume. Finished pieces stay on disk.
## Disclaimer
PatchDL is an independent project. It is not affiliated with, endorsed by or sponsored by Sony Interactive Entertainment. "PlayStation" and "PS5" are trademarks of Sony Interactive Entertainment Inc. and appear here only to name the console PatchDL works with.
PatchDL downloads official, unmodified game updates that Sony publishes for games already installed on your console. It does not download games, does not contain or distribute Sony software, keys or game content, and does not install unsigned or modified packages. Use it with games you own, and follow the laws of your country and the terms that apply to you. This project does not support piracy, and issues about pirated content will be closed.
<details>
<summary><b>Build from source</b></summary>
<br>
```sh ```sh
scripts/build_ps5.sh # produces patchdl-ps5.elf scripts/build_ps5.sh # produces patchdl-ps5.elf
``` ```
## Deploy You need the [ps5-payload-dev SDK](https://github.com/ps5-payload-dev/sdk) with `libcurl` and `OpenSSL` from its [pacbrew-repo](https://github.com/ps5-payload-dev/pacbrew-repo). `libmicrohttpd` and SQLite are vendored. GitHub Actions builds every push; tagged builds become releases.
This console uses the BD-JB autoloader with itsPLK's Payload Manager on port To try a build on your own console:
8084 (not a 9021 elfldr). `scripts/deploy_ps5.sh` uploads the ELF named with its
version and launches it; the payload replaces any running instance itself.
```sh ```sh
PS5_HOST=<console-ip> scripts/deploy_ps5.sh PS5_HOST=<console-ip> scripts/deploy_ps5.sh
``` ```
On start it shows an on-screen notification with the URL. Open the web UI at: </details>
```text ## Credits
http://<console-ip>:12880/
```
## Status PatchDL is written in C and builds on [libmicrohttpd](https://www.gnu.org/software/libmicrohttpd/), [libcurl](https://curl.se/), [OpenSSL](https://www.openssl.org/), [SQLite](https://sqlite.org/) and the [ps5-payload-dev SDK](https://github.com/ps5-payload-dev/sdk). Thanks to everyone behind them.
0.0.2, early. Title scan, source classification, version resolution, ## License
firmware-compatibility filtering, target/storage-id handling, and the local
AppInstUtil HTTP stream have been verified on firmware 11.60. PatchDL now PatchDL is free software under the **GNU General Public License v3.0 or later**. See [LICENSE](LICENSE). Use it, study it, change it, share it. Forks stay under the same license.
downloads PS5 update manifests as merged piece packages under `/data/patchdl`;
large retail updates can be tens of GB. The download queue shows live progress, Copyright © 2026 Knutwurst.
and each download can be cancelled (the partial file is deleted) or a finished
package deleted again, from the queue or the title card. Manifest pieces are
verified in offset order and against their declared size while merging. Open
items: a full large-title manifest download/install still needs an end-to-end
run, the web UI marks a title "Installing…" but reads progress from the PS5's
own notifications rather than a percentage, and disc-based games need the disc
inserted for their patch to apply (a normal Sony requirement).
Settings (global policy and the per-game toggle) persist to
`/data/patchdl/config.json` and survive a restart.
BIN
View File
Binary file not shown.

After

Width:  |  Height:  |  Size: 21 KiB

+20
View File
@@ -0,0 +1,20 @@
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 512 512">
<defs>
<linearGradient id="bg" x1="0" y1="0" x2="0" y2="1">
<stop offset="0" stop-color="#0f2a1e"/>
<stop offset="1" stop-color="#0a1612"/>
</linearGradient>
<linearGradient id="badge" x1="0" y1="0" x2="0" y2="1">
<stop offset="0" stop-color="#21d07a"/>
<stop offset="1" stop-color="#179a59"/>
</linearGradient>
</defs>
<rect width="512" height="512" rx="72" fill="url(#bg)"/>
<rect x="56" y="56" width="160" height="160" rx="36" fill="url(#badge)"/>
<text x="136" y="178" font-family="Helvetica,Arial,sans-serif" font-size="116"
font-weight="800" fill="#0a1612" text-anchor="middle">PD</text>
<text x="256" y="346" font-family="Helvetica,Arial,sans-serif" font-size="80"
font-weight="700" fill="#e7ecea" text-anchor="middle">PatchDL</text>
<text x="256" y="404" font-family="Helvetica,Arial,sans-serif" font-size="32"
font-weight="500" fill="#7a8f86" text-anchor="middle">PS5 Patch Tool</text>
</svg>

After

Width:  |  Height:  |  Size: 1.0 KiB

+10
View File
@@ -0,0 +1,10 @@
{
"titleId": "PTDL00001",
"deeplinkUri": "http://127.0.0.1:12880/",
"localizedParameters": {
"defaultLanguage": "en-US",
"en-US": {
"titleName": "PatchDL"
}
}
}
Binary file not shown.

After

Width:  |  Height:  |  Size: 157 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 207 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 145 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 132 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 115 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 184 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 171 KiB

+1 -1
View File
@@ -19,7 +19,7 @@ VERSION=$(sed -n 's/.*PATCHDL_VERSION[^"]*"\([^"]*\)".*/\1/p' "$ROOT_DIR/src/pat
SRC_ELF="$ROOT_DIR/patchdl-ps5.elf" SRC_ELF="$ROOT_DIR/patchdl-ps5.elf"
[ -f "$SRC_ELF" ] || { echo "build first: $SRC_ELF missing" >&2; exit 1; } [ -f "$SRC_ELF" ] || { echo "build first: $SRC_ELF missing" >&2; exit 1; }
UP_NAME="patchdl-ps5-v${VERSION}.elf" UP_NAME="patchdl_${VERSION}.elf"
TMP_ELF="$ROOT_DIR/$UP_NAME" TMP_ELF="$ROOT_DIR/$UP_NAME"
cp "$SRC_ELF" "$TMP_ELF" cp "$SRC_ELF" "$TMP_ELF"
+9
View File
@@ -1,3 +1,12 @@
/* SPDX-License-Identifier: GPL-3.0-or-later
* Copyright (C) 2026 Knutwurst
*
* PatchDL is free software: you can redistribute it and/or modify it under
* the terms of the GNU General Public License as published by the Free
* Software Foundation, either version 3 of the License, or (at your option)
* any later version. See the LICENSE file in the project root for details.
*/
#include <signal.h> #include <signal.h>
#include <stdio.h> #include <stdio.h>
#include <stdlib.h> #include <stdlib.h>
+14 -1
View File
@@ -1,3 +1,12 @@
/* SPDX-License-Identifier: GPL-3.0-or-later
* Copyright (C) 2026 Knutwurst
*
* PatchDL is free software: you can redistribute it and/or modify it under
* the terms of the GNU General Public License as published by the Free
* Software Foundation, either version 3 of the License, or (at your option)
* any later version. See the LICENSE file in the project root for details.
*/
#include "patchdl_appdb.h" #include "patchdl_appdb.h"
#include <sqlite3.h> #include <sqlite3.h>
@@ -61,8 +70,12 @@ patchdl_appdb_load(patchdl_appinfo_t **out, size_t *count) {
*out = NULL; *out = NULL;
*count = 0; *count = 0;
/* FULLMUTEX: today only the startup thread calls this, but future code
paths (a manual rescan triggered from the HTTP thread) would otherwise
race the SQLite handle. Cost is one mutex per call. */
if (sqlite3_open_v2(APP_DB_URI, &db, if (sqlite3_open_v2(APP_DB_URI, &db,
SQLITE_OPEN_READONLY | SQLITE_OPEN_URI, NULL) != SQLITE_OK) { SQLITE_OPEN_READONLY | SQLITE_OPEN_URI |
SQLITE_OPEN_FULLMUTEX, NULL) != SQLITE_OK) {
if (db) sqlite3_close(db); if (db) sqlite3_close(db);
return -1; return -1;
} }
+9
View File
@@ -1,3 +1,12 @@
/* SPDX-License-Identifier: GPL-3.0-or-later
* Copyright (C) 2026 Knutwurst
*
* PatchDL is free software: you can redistribute it and/or modify it under
* the terms of the GNU General Public License as published by the Free
* Software Foundation, either version 3 of the License, or (at your option)
* any later version. See the LICENSE file in the project root for details.
*/
#pragma once #pragma once
#include <stddef.h> #include <stddef.h>
+9
View File
@@ -1,3 +1,12 @@
/* SPDX-License-Identifier: GPL-3.0-or-later
* Copyright (C) 2026 Knutwurst
*
* PatchDL is free software: you can redistribute it and/or modify it under
* the terms of the GNU General Public License as published by the Free
* Software Foundation, either version 3 of the License, or (at your option)
* any later version. See the LICENSE file in the project root for details.
*/
#include "patchdl_assets.h" #include "patchdl_assets.h"
#include <stdlib.h> #include <stdlib.h>
+9
View File
@@ -1,3 +1,12 @@
/* SPDX-License-Identifier: GPL-3.0-or-later
* Copyright (C) 2026 Knutwurst
*
* PatchDL is free software: you can redistribute it and/or modify it under
* the terms of the GNU General Public License as published by the Free
* Software Foundation, either version 3 of the License, or (at your option)
* any later version. See the LICENSE file in the project root for details.
*/
#pragma once #pragma once
#include <stddef.h> #include <stddef.h>
+9
View File
@@ -1,3 +1,12 @@
/* SPDX-License-Identifier: GPL-3.0-or-later
* Copyright (C) 2026 Knutwurst
*
* PatchDL is free software: you can redistribute it and/or modify it under
* the terms of the GNU General Public License as published by the Free
* Software Foundation, either version 3 of the License, or (at your option)
* any later version. See the LICENSE file in the project root for details.
*/
#pragma once #pragma once
/* /*
+9
View File
@@ -1,3 +1,12 @@
/* SPDX-License-Identifier: GPL-3.0-or-later
* Copyright (C) 2026 Knutwurst
*
* PatchDL is free software: you can redistribute it and/or modify it under
* the terms of the GNU General Public License as published by the Free
* Software Foundation, either version 3 of the License, or (at your option)
* any later version. See the LICENSE file in the project root for details.
*/
#include "patchdl_fw.h" #include "patchdl_fw.h"
#include <ps5/kernel.h> #include <ps5/kernel.h>
+9
View File
@@ -1,3 +1,12 @@
/* SPDX-License-Identifier: GPL-3.0-or-later
* Copyright (C) 2026 Knutwurst
*
* PatchDL is free software: you can redistribute it and/or modify it under
* the terms of the GNU General Public License as published by the Free
* Software Foundation, either version 3 of the License, or (at your option)
* any later version. See the LICENSE file in the project root for details.
*/
#pragma once #pragma once
#include <stdint.h> #include <stdint.h>
+450 -37
View File
@@ -1,3 +1,12 @@
/* SPDX-License-Identifier: GPL-3.0-or-later
* Copyright (C) 2026 Knutwurst
*
* PatchDL is free software: you can redistribute it and/or modify it under
* the terms of the GNU General Public License as published by the Free
* Software Foundation, either version 3 of the License, or (at your option)
* any later version. See the LICENSE file in the project root for details.
*/
#include "patchdl_install.h" #include "patchdl_install.h"
#include <arpa/inet.h> #include <arpa/inet.h>
@@ -7,8 +16,11 @@
#include <pthread.h> #include <pthread.h>
#include <stddef.h> #include <stddef.h>
#include <stdbool.h>
#include <stdint.h> #include <stdint.h>
#include <stdatomic.h>
#include <stdio.h> #include <stdio.h>
#include <stdlib.h>
#include <string.h> #include <string.h>
#include <sys/socket.h> #include <sys/socket.h>
#include <sys/stat.h> #include <sys/stat.h>
@@ -45,6 +57,42 @@ typedef struct {
long unknown[810]; long unknown[810];
} ai_playgo_info_t; } ai_playgo_info_t;
typedef struct {
int32_t error_code;
int32_t version;
char description[512];
char type[9];
} ai_install_error_t;
typedef struct {
char status[16];
char src_type[8];
uint32_t remain_time;
uint64_t downloaded_size;
uint64_t initial_chunk_size;
uint64_t total_size;
uint32_t promote_progress;
ai_install_error_t error_info;
int32_t local_copy_percent;
bool is_copy_only;
char _pad[2048]; /* safety margin — actual Sony struct may be larger */
} ai_install_status_t;
/* Padded buffers for Sony output writes whose actual size is reverse-engineered.
The visible content fits in 0x30 (content_id) / 16 (title_id) bytes, but the
firmware may NUL-pad or write more. Used as caller-side temporaries that are
then copy_bounded()-d into the right-sized destination. */
#define AI_CONTENTID_OUT_SIZE 256
#define AI_TITLEID_OUT_SIZE 128
#define STATIC_ASSERT(c, n) typedef char static_assert_##n[(c) ? 1 : -1]
STATIC_ASSERT(sizeof(ai_pkg_info_t) == 0x38, pkg_info_size);
STATIC_ASSERT(sizeof(ai_meta_info_t) == (6 * sizeof(void *)), meta_info_size);
STATIC_ASSERT(sizeof(ai_playgo_info_t) == 0x2700, playgo_info_size);
STATIC_ASSERT(offsetof(ai_meta_info_t, uri) == 0, meta_uri_offset);
STATIC_ASSERT(offsetof(ai_meta_info_t, icon_url) == (5 * sizeof(void *)),
meta_icon_offset);
/* Sysmodule IDs (from ps5-payload-dev/sdk crt/rtld_sprx.c). */ /* Sysmodule IDs (from ps5-payload-dev/sdk crt/rtld_sprx.c). */
#define SYSMOD_IPMI 0x8000001d #define SYSMOD_IPMI 0x8000001d
#define SYSMOD_USERSERVICE 0x80000011 #define SYSMOD_USERSERVICE 0x80000011
@@ -57,11 +105,15 @@ typedef int (*ai_install_pkg_fn)(const char *path, ai_pkg_info_t *info);
typedef int (*ai_install_by_pkg_fn)(ai_meta_info_t *meta, ai_pkg_info_t *info, typedef int (*ai_install_by_pkg_fn)(ai_meta_info_t *meta, ai_pkg_info_t *info,
ai_playgo_info_t *playgo); ai_playgo_info_t *playgo);
typedef int (*ai_title_from_pkg_fn)(const char *path, char *title_id, int *is_app); typedef int (*ai_title_from_pkg_fn)(const char *path, char *title_id, int *is_app);
typedef int (*ai_content_from_pkg_fn)(const char *path, char *content_id, int *is_app);
typedef int (*ai_get_status_fn)(char *content_id_out, ai_install_status_t *status);
static ai_init_fn ai_initialize; static ai_init_fn ai_initialize;
static ai_install_pkg_fn ai_install_pkg; static ai_install_pkg_fn ai_install_pkg;
static ai_install_by_pkg_fn ai_install_by_package; static ai_install_by_pkg_fn ai_install_by_package;
static ai_title_from_pkg_fn ai_title_from_pkg; static ai_title_from_pkg_fn ai_title_from_pkg;
static ai_content_from_pkg_fn ai_content_from_pkg;
static ai_get_status_fn ai_get_status;
/* Resolve + initialize the AppInstUtil backend WITHOUT linking the sce libs /* Resolve + initialize the AppInstUtil backend WITHOUT linking the sce libs
(that makes the ELF unloadable by the elfldr) and WITHOUT raw (that makes the ELF unloadable by the elfldr) and WITHOUT raw
@@ -70,11 +122,18 @@ static ai_title_from_pkg_fn ai_title_from_pkg;
symbols via the kernel dynlib helpers. Runs in a detached thread; the HTTP symbols via the kernel dynlib helpers. Runs in a detached thread; the HTTP
handler reports the stage and never blocks. handler reports the stage and never blocks.
stage: 0 idle, 1 resolve loader, 2 load modules, 3 resolve symbols, stage: 0 idle, 1 resolve loader, 2 load modules, 3 resolve symbols,
4 initialize, 5 ready, negative = failure at that step. */ 4 initialize, 5 ready, negative = failure at that step.
static volatile int g_stage; Stored as _Atomic so the worker's release-store and the request handlers'
static int g_err; acquire-loads pair properly — the function pointers they read after
stage==5 must not be reordered ahead of the stage check. */
static _Atomic int g_stage;
static _Atomic int g_err;
static pthread_mutex_t g_mtx = PTHREAD_MUTEX_INITIALIZER; static pthread_mutex_t g_mtx = PTHREAD_MUTEX_INITIALIZER;
static char g_probe_json[2048]; /* filled by the backend thread */ static char g_probe_json[2048]; /* filled by the backend thread */
static char g_last_content_id[AI_CONTENTID_SIZE];
static char g_last_target_title_id[32];
static char g_last_method[32];
static int g_last_start_rc;
static intptr_t static intptr_t
dynsym(const char *module, const char *sym) { dynsym(const char *module, const char *sym) {
@@ -110,6 +169,63 @@ local_ip(char *out, size_t n) {
freeifaddrs(ifa); freeifaddrs(ifa);
} }
static void
copy_bounded(char *dst, size_t dst_sz, const char *src, size_t src_sz) {
size_t n;
if (!dst || !dst_sz) return;
dst[0] = '\0';
if (!src || !src_sz) return;
for (n = 0; n + 1 < dst_sz && n < src_sz && src[n]; n++)
dst[n] = src[n];
dst[n] = '\0';
}
/* Conservative whitelist for ids/filenames that we extract from a local path
and inject into URIs/log lines passed to AppInstUtil. Rejects CRLF, '/',
'\\', NUL, control chars, anything that could change URI semantics. */
static int
install_id_safe(const char *s) {
if (!s || !s[0]) return 0;
for (const char *p = s; *p; p++) {
if (!((*p >= 'A' && *p <= 'Z') ||
(*p >= 'a' && *p <= 'z') ||
(*p >= '0' && *p <= '9') ||
*p == '_' || *p == '-' || *p == '.'))
return 0;
}
return 1;
}
/* Exact match for PS4/PS5 title ids (9 chars: 4 letters + 5 digits). A bare
strncmp(...,9) would also match longer ids that share a 9-char prefix and
could collide PPSA12345 with PPSA12345EVIL. */
static int
title_id_eq9(const char *a, const char *b) {
if (!a || !b) return 0;
if (strnlen(a, 16) != 9 || strnlen(b, 16) != 9) return 0;
return strncmp(a, b, 9) == 0;
}
static void
remember_install(const char *target_title_id, const char *method,
const ai_pkg_info_t *pkg, const char *fallback_content_id,
int rc) {
char cid[AI_CONTENTID_SIZE] = {0};
if (pkg)
copy_bounded(cid, sizeof(cid), pkg->content_id, sizeof(pkg->content_id));
if (!cid[0] && fallback_content_id)
copy_bounded(cid, sizeof(cid), fallback_content_id, strlen(fallback_content_id));
pthread_mutex_lock(&g_mtx);
snprintf(g_last_content_id, sizeof(g_last_content_id), "%s", cid);
snprintf(g_last_target_title_id, sizeof(g_last_target_title_id), "%s",
target_title_id ? target_title_id : "");
snprintf(g_last_method, sizeof(g_last_method), "%s", method ? method : "");
g_last_start_rc = rc;
pthread_mutex_unlock(&g_mtx);
}
/* Resolve (dlsym, never call) a list of candidate patch-install symbols and /* Resolve (dlsym, never call) a list of candidate patch-install symbols and
record which exist. Runs inside the backend thread, where the AppInstUtil record which exist. Runs inside the backend thread, where the AppInstUtil
module is already loaded — the same proven-safe context as the normal symbol module is already loaded — the same proven-safe context as the normal symbol
@@ -124,6 +240,7 @@ fill_probe(void) {
"sceAppInstUtilInstallByPackageEx", "sceAppInstUtilInstallByPackageEx",
"sceAppInstUtilGetTitleIdFromPkg", "sceAppInstUtilGetTitleIdFromPkg",
"sceAppInstUtilGetContentIdFromPkg", "sceAppInstUtilGetContentIdFromPkg",
"sceAppInstUtilGetInstallStatus",
"sceAppInstUtilAppExist", "sceAppInstUtilAppExist",
"sceAppInstUtilAppGetInstallStatus", "sceAppInstUtilAppGetInstallStatus",
"sceAppInstUtilAppInstallStatus", "sceAppInstUtilAppInstallStatus",
@@ -205,6 +322,10 @@ backend_init_thread(void *arg) {
"sceAppInstUtilInstallByPackage"); "sceAppInstUtilInstallByPackage");
ai_title_from_pkg = (ai_title_from_pkg_fn)dynsym("libSceAppInstUtil.sprx", ai_title_from_pkg = (ai_title_from_pkg_fn)dynsym("libSceAppInstUtil.sprx",
"sceAppInstUtilGetTitleIdFromPkg"); "sceAppInstUtilGetTitleIdFromPkg");
ai_content_from_pkg = (ai_content_from_pkg_fn)dynsym("libSceAppInstUtil.sprx",
"sceAppInstUtilGetContentIdFromPkg");
ai_get_status = (ai_get_status_fn)dynsym("libSceAppInstUtil.sprx",
"sceAppInstUtilGetInstallStatus");
/* Read-only feasibility probe — module is loaded, safe context. */ /* Read-only feasibility probe — module is loaded, safe context. */
fill_probe(); fill_probe();
@@ -284,6 +405,168 @@ patchdl_install_api_probe(char *out, size_t out_sz) {
return -1; return -1;
} }
/* Read-only: report the .pkg's embedded content id + title id (and whether it
is a full app vs a patch). No install, no side effects. 0 if anything read. */
int
patchdl_install_pkg_meta(const char *local_path, char *content_id, size_t cid_sz,
char *title_id, size_t tid_sz, int *is_app,
char *msg, size_t msg_sz) {
char sdk_path[1024];
/* Padded output buffers — Sony's GetContentIdFromPkg / GetTitleIdFromPkg
take no length hint; firmware may NUL-pad more than the visible id. */
char cid[AI_CONTENTID_OUT_SIZE] = {0};
char tid[AI_TITLEID_OUT_SIZE] = {0};
int app_c = 0, app_t = 0, ok = 0;
struct stat st;
if (content_id && cid_sz) content_id[0] = '\0';
if (title_id && tid_sz) title_id[0] = '\0';
if (is_app) *is_app = 0;
if (!local_path || !local_path[0] || stat(local_path, &st) != 0) {
snprintf(msg, msg_sz, "package not on disk");
return -1;
}
backend_start();
if (g_stage != 5) {
snprintf(msg, msg_sz, "install backend not ready: %s", stage_str(g_stage));
return -1;
}
if (!strncmp(local_path, "/data/", 6))
snprintf(sdk_path, sizeof sdk_path, "/user%s", local_path);
else
snprintf(sdk_path, sizeof sdk_path, "%s", local_path);
if (ai_content_from_pkg &&
ai_content_from_pkg(sdk_path, cid, &app_c) == 0 && cid[0]) {
copy_bounded(content_id, cid_sz, cid, sizeof(cid));
if (is_app) *is_app = app_c;
ok = 1;
}
if (ai_title_from_pkg &&
ai_title_from_pkg(sdk_path, tid, &app_t) == 0 && tid[0]) {
copy_bounded(title_id, tid_sz, tid, sizeof(tid));
ok = 1;
}
snprintf(msg, msg_sz, ok ? "ok" : "could not read pkg metadata");
return ok ? 0 : -1;
}
void
patchdl_install_debug_state(char *out, size_t out_sz) {
char cid[AI_CONTENTID_SIZE];
char tid[32], method[32];
int start_rc;
int stage;
pthread_mutex_lock(&g_mtx);
memcpy(cid, g_last_content_id, sizeof(cid));
snprintf(tid, sizeof(tid), "%s", g_last_target_title_id);
snprintf(method, sizeof(method), "%s", g_last_method);
start_rc = g_last_start_rc;
stage = g_stage;
pthread_mutex_unlock(&g_mtx);
snprintf(out, out_sz,
"{\"stage\":%d,\"cid_len\":%d,\"cid_hex\":\"%02x%02x%02x%02x\","
"\"content_id\":\"%s\",\"target_title_id\":\"%s\","
"\"method\":\"%s\",\"start_rc\":%d}",
stage,
(int)strnlen(cid, sizeof(cid)),
(unsigned char)cid[0], (unsigned char)cid[1],
(unsigned char)cid[2], (unsigned char)cid[3],
cid, tid, method, start_rc);
}
int
patchdl_install_status_json(char *out, size_t out_sz) {
char cid[AI_CONTENTID_SIZE];
char tid[32];
char method[32];
int start_rc;
/* ai_install_status_t carries a 2 KB safety pad; live on the heap so
a frequently-polled /api/installstatus doesn't keep committing pages
on every MHD worker's stack. */
ai_install_status_t *st = NULL;
char status[17], src_type[9];
int rc;
int progress = 0;
int terminal = 0;
if (!out || !out_sz)
return -1;
backend_start();
pthread_mutex_lock(&g_mtx);
snprintf(cid, sizeof(cid), "%s", g_last_content_id);
snprintf(tid, sizeof(tid), "%s", g_last_target_title_id);
snprintf(method, sizeof(method), "%s", g_last_method);
start_rc = g_last_start_rc;
pthread_mutex_unlock(&g_mtx);
if (!cid[0]) {
snprintf(out, out_sz, "{\"active\":false}");
return -1;
}
if (g_stage != 5) {
snprintf(out, out_sz,
"{\"active\":true,\"content_id\":\"%s\",\"target_title_id\":\"%s\","
"\"method\":\"%s\",\"start_rc\":%d,\"status\":\"backend_not_ready\","
"\"stage\":\"%s\"}",
cid, tid, method, start_rc, stage_str(g_stage));
return -1;
}
if (!ai_get_status) {
snprintf(out, out_sz,
"{\"active\":true,\"content_id\":\"%s\",\"target_title_id\":\"%s\","
"\"method\":\"%s\",\"start_rc\":%d,\"status\":\"unavailable\","
"\"message\":\"sceAppInstUtilGetInstallStatus not exported\"}",
cid, tid, method, start_rc);
return -1;
}
st = calloc(1, sizeof(*st));
if (!st) {
snprintf(out, out_sz, "{\"error\":\"oom\"}");
return -1;
}
/* sceAppInstUtilGetInstallStatus(char *content_id_out, status_t *status):
first arg is an OUTPUT buffer that receives the current install's content_id.
Do NOT pass `cid` there — it would be overwritten. The visible id fits in
0x30 bytes but Sony's NUL-pad length is unknown; use a padded buffer. */
{
char ai_cid_out[AI_CONTENTID_OUT_SIZE] = {0};
rc = ai_get_status(ai_cid_out, st);
(void)ai_cid_out; /* returned content_id for future use */
}
copy_bounded(status, sizeof(status), st->status, sizeof(st->status));
copy_bounded(src_type, sizeof(src_type), st->src_type, sizeof(st->src_type));
if (st->total_size > 0)
progress = (int)((st->downloaded_size * 100) / st->total_size);
if (progress < 0) progress = 0;
if (progress > 100) progress = 100;
terminal = (!strcmp(status, "playable") ||
!strcmp(status, "error") ||
!strcmp(status, "none"));
snprintf(out, out_sz,
"{\"active\":true,\"terminal\":%s,\"content_id\":\"%s\","
"\"target_title_id\":\"%s\",\"method\":\"%s\",\"start_rc\":%d,"
"\"rc\":%d,\"status\":\"%s\",\"src_type\":\"%s\","
"\"progress\":%d,\"downloaded_size\":%llu,\"total_size\":%llu,"
"\"promote_progress\":%u,\"error_code\":%d}",
terminal ? "true" : "false", cid, tid, method, start_rc, rc,
status, src_type, progress,
(unsigned long long)st->downloaded_size,
(unsigned long long)st->total_size,
(unsigned)st->promote_progress,
(int)st->error_info.error_code);
free(st);
return rc;
}
int int
patchdl_install_local_pkg(const char *local_path, const char *expected_title_id, patchdl_install_local_pkg(const char *local_path, const char *expected_title_id,
const char *storage_title_id, const char *storage_title_id,
@@ -294,7 +577,6 @@ patchdl_install_local_pkg(const char *local_path, const char *expected_title_id,
struct stat st; struct stat st;
int rc; int rc;
int pkg_tid_mismatch = 0; int pkg_tid_mismatch = 0;
const char *last_uri = "";
if (!local_path || !local_path[0]) { if (!local_path || !local_path[0]) {
snprintf(msg, msg_sz, "no package path"); snprintf(msg, msg_sz, "no package path");
@@ -311,10 +593,11 @@ patchdl_install_local_pkg(const char *local_path, const char *expected_title_id,
return -1; return -1;
} }
/* AppInstallPkg runs in a sandbox that sees the user partition as /* Sony's installer sees the user partition as /user/data, not /data, and
/user/data, not /data. InstallByPackage is different: the shell/debug PATH-ALLOWLISTS the URI passed to InstallByPackage: /user/data/ and
installer path takes the normal /data/... URI, so keep `local_path` for /mnt/usb are accepted, but a bare /data/... path is REJECTED with
that API and use `sdk_path` only for AppInstallPkg / metadata probes. */ 0x80B2116F (empirically confirmed by the ps5upload project). So feed the
/user/data view of the file to both InstallByPackage and AppInstallPkg. */
if (!strncmp(local_path, "/data/", 6)) if (!strncmp(local_path, "/data/", 6))
snprintf(sdk_path, sizeof(sdk_path), "/user%s", local_path); snprintf(sdk_path, sizeof(sdk_path), "/user%s", local_path);
else else
@@ -326,15 +609,20 @@ patchdl_install_local_pkg(const char *local_path, const char *expected_title_id,
such packages to the raw AppInstallPkg path. */ such packages to the raw AppInstallPkg path. */
if (storage_title_id && storage_title_id[0] && if (storage_title_id && storage_title_id[0] &&
expected_title_id && expected_title_id[0] && expected_title_id && expected_title_id[0] &&
strncmp(storage_title_id, expected_title_id, 9) != 0) { !title_id_eq9(storage_title_id, expected_title_id)) {
pkg_tid_mismatch = 1; pkg_tid_mismatch = 1;
strncpy(pkg_tid, storage_title_id, sizeof(pkg_tid) - 1); strncpy(pkg_tid, storage_title_id, sizeof(pkg_tid) - 1);
pkg_tid[sizeof(pkg_tid) - 1] = '\0';
} }
if (ai_title_from_pkg && expected_title_id && expected_title_id[0]) { if (ai_title_from_pkg && expected_title_id && expected_title_id[0]) {
/* Sony's GetTitleIdFromPkg writes into the output buffer with no length
hint — pad generously and copy the safe portion into pkg_tid. */
char tid_out[AI_TITLEID_OUT_SIZE] = {0};
int is_app = 0; int is_app = 0;
if (ai_title_from_pkg(sdk_path, pkg_tid, &is_app) == 0 && pkg_tid[0] && if (ai_title_from_pkg(sdk_path, tid_out, &is_app) == 0 && tid_out[0]) {
strncmp(pkg_tid, expected_title_id, 9) != 0) { if (!title_id_eq9(tid_out, expected_title_id))
pkg_tid_mismatch = 1; pkg_tid_mismatch = 1;
copy_bounded(pkg_tid, sizeof(pkg_tid), tid_out, sizeof(tid_out));
} }
} }
if (pkg_tid_mismatch && (!target_content_id || !target_content_id[0])) { if (pkg_tid_mismatch && (!target_content_id || !target_content_id[0])) {
@@ -343,10 +631,11 @@ patchdl_install_local_pkg(const char *local_path, const char *expected_title_id,
pkg_tid, expected_title_id); pkg_tid, expected_title_id);
return -1; return -1;
} }
/* Preferred path: etaHEN's DPI uses InstallByPackage with the installed
/* Preferred path: InstallByPackage accepts target metadata. Use it first, game's content_id in MetaInfo so AppInstUtil binds the install to the
and use it exclusively when the downloaded bytes report a master/storage right title slot. For shared-master cross-region packages the pkg bytes
title id that differs from the target regional title id. */ carry a different title id than the installed game; passing content_id
is what etaHEN does to route the install correctly. */
{ {
char file_uri[1100]; char file_uri[1100];
char http_loop_uri[1200] = {0}; char http_loop_uri[1200] = {0};
@@ -354,12 +643,19 @@ patchdl_install_local_pkg(const char *local_path, const char *expected_title_id,
const char *uris[4]; const char *uris[4];
ai_meta_info_t meta = {0}; ai_meta_info_t meta = {0};
ai_pkg_info_t pkg = {0}; ai_pkg_info_t pkg = {0};
ai_playgo_info_t playgo = {0}; /* playgo is 0x2700 bytes — too big for the MHD worker stack alongside
uris, meta, pkg, resp buffers, and Sony's own frame use. */
ai_playgo_info_t *playgo = calloc(1, sizeof(*playgo));
int rc2 = -1; int rc2 = -1;
const char *title_dir; const char *title_dir;
const char *file_base; const char *file_base;
snprintf(file_uri, sizeof(file_uri), "file://%s", local_path); if (!playgo) {
snprintf(msg, msg_sz, "out of memory");
return -1;
}
snprintf(file_uri, sizeof(file_uri), "file://%s", sdk_path);
title_dir = strstr(local_path, "/data/patchdl/"); title_dir = strstr(local_path, "/data/patchdl/");
file_base = strrchr(local_path, '/'); file_base = strrchr(local_path, '/');
if (title_dir && file_base && file_base > title_dir + strlen("/data/patchdl/")) { if (title_dir && file_base && file_base > title_dir + strlen("/data/patchdl/")) {
@@ -369,6 +665,10 @@ patchdl_install_local_pkg(const char *local_path, const char *expected_title_id,
if (tlen > 0 && tlen < sizeof(title_id)) { if (tlen > 0 && tlen < sizeof(title_id)) {
char ip[INET_ADDRSTRLEN] = {0}; char ip[INET_ADDRSTRLEN] = {0};
memcpy(title_id, t, tlen); memcpy(title_id, t, tlen);
/* CRLF/path-injection guard: anything we splice into the loop /
LAN URI lands inside Sony's HTTP request line. Reject ids
or filenames carrying delimiters or control chars. */
if (install_id_safe(title_id) && install_id_safe(file_base + 1)) {
snprintf(http_loop_uri, sizeof(http_loop_uri), snprintf(http_loop_uri, sizeof(http_loop_uri),
"http://127.0.0.1:%d/api/pkg/%s/%s", "http://127.0.0.1:%d/api/pkg/%s/%s",
PATCHDL_HTTP_PORT, title_id, file_base + 1); PATCHDL_HTTP_PORT, title_id, file_base + 1);
@@ -379,53 +679,166 @@ patchdl_install_local_pkg(const char *local_path, const char *expected_title_id,
ip, PATCHDL_HTTP_PORT, title_id, file_base + 1); ip, PATCHDL_HTTP_PORT, title_id, file_base + 1);
} }
} }
uris[0] = local_path; }
uris[1] = file_uri; uris[0] = sdk_path; /* /user/data/... — the allowlisted path */
uris[1] = file_uri; /* file:///user/data/... */
uris[2] = http_loop_uri[0] ? http_loop_uri : NULL; uris[2] = http_loop_uri[0] ? http_loop_uri : NULL;
uris[3] = http_lan_uri[0] ? http_lan_uri : NULL; uris[3] = http_lan_uri[0] ? http_lan_uri : NULL;
meta.ex_uri = ""; meta.ex_uri = "";
meta.playgo_scenario_id = ""; meta.playgo_scenario_id = "";
meta.content_id = target_content_id ? target_content_id : ""; /* For cross-region shared-master packages pass the installed game's
content_id so AppInstUtil binds the download to the right title. */
meta.content_id = (pkg_tid_mismatch &&
target_content_id && target_content_id[0])
? target_content_id : "";
meta.content_name = "PatchDL"; meta.content_name = "PatchDL";
meta.icon_url = ""; meta.icon_url = "";
{
char tries[260] = {0};
const char *labels[4] = { "userdata", "file", "loop", "lan" };
for (int i = 0; i < 4; i++) { for (int i = 0; i < 4; i++) {
if (!uris[i]) continue; if (!uris[i]) continue;
memset(&pkg, 0, sizeof(pkg)); memset(&pkg, 0, sizeof(pkg));
memset(&playgo, 0, sizeof(playgo)); memset(playgo, 0, sizeof(*playgo));
meta.uri = uris[i]; meta.uri = uris[i];
last_uri = uris[i]; rc2 = ai_install_by_package(&meta, &pkg, playgo);
rc2 = ai_install_by_package(&meta, &pkg, &playgo); {
size_t l = strlen(tries);
snprintf(tries + l, sizeof(tries) - l, "%s%s=0x%08x",
l ? "," : "", labels[i], (unsigned)rc2);
}
if (rc2 == 0) { if (rc2 == 0) {
snprintf(msg, msg_sz, "install started (InstallByPackage%s)", remember_install(expected_title_id, "InstallByPackage",
pkg_tid_mismatch ? ", shared master bytes" : ""); &pkg, target_content_id, rc2);
snprintf(msg, msg_sz, "install started (InstallByPackage, content %.47s)",
pkg.content_id[0] ? pkg.content_id :
(target_content_id ? target_content_id : ""));
free(playgo);
return 0; return 0;
} }
} }
rc = rc2; rc = rc2;
} }
free(playgo);
if (pkg_tid_mismatch) {
snprintf(msg, msg_sz,
"install rejected (InstallByPackage=0x%08x, pkg %.12s, target %.12s, uri %.96s)",
(unsigned)rc, pkg_tid, expected_title_id ? expected_title_id : "",
last_uri);
return rc ? rc : -1;
} }
/* Last resort for normal same-title packages only. This path has no target /* AppInstallPkg: simpler API, no MetaInfo content_id override. Tried for
metadata parameter, so it is intentionally skipped for shared-master all packages including cross-region, since it may have different
region bytes. */ privilege requirements than InstallByPackage. For shared-master packages
it will bind to the pkg's own embedded title, not the expected_title_id,
so treat success with caution; also report the complete error set. */
{ {
char ibp_tries[260] = {0};
ai_pkg_info_t pkg = {0}; ai_pkg_info_t pkg = {0};
int rc2 = ai_install_pkg(sdk_path, &pkg); int rc2;
/* stash the InstallByPackage diagnostic if available */
if (pkg_tid_mismatch)
snprintf(ibp_tries, sizeof(ibp_tries),
"ibp=0x%08x(pkg %.12s->%.12s)",
(unsigned)rc, pkg_tid,
expected_title_id ? expected_title_id : "");
rc2 = ai_install_pkg(sdk_path, &pkg);
if (rc2 == 0) { if (rc2 == 0) {
snprintf(msg, msg_sz, "install started (AppInstallPkg)"); remember_install(expected_title_id, "AppInstallPkg",
&pkg, target_content_id, rc2);
snprintf(msg, msg_sz, "install started (AppInstallPkg, content %.47s%s%s)",
pkg.content_id[0] ? pkg.content_id :
(target_content_id ? target_content_id : ""),
ibp_tries[0] ? " " : "", ibp_tries);
return 0; return 0;
} }
if (pkg_tid_mismatch)
snprintf(msg, msg_sz,
"install rejected (pkg %.12s->%.12s ibp=0x%08x aip=0x%08x)",
pkg_tid, expected_title_id ? expected_title_id : "",
(unsigned)rc, (unsigned)rc2);
else
snprintf(msg, msg_sz, snprintf(msg, msg_sz,
"install rejected (InstallByPackage=0x%08x, AppInstallPkg=0x%08x)", "install rejected (InstallByPackage=0x%08x, AppInstallPkg=0x%08x)",
(unsigned)rc, (unsigned)rc2); (unsigned)rc, (unsigned)rc2);
return rc2 ? rc2 : (rc ? rc : -1); return rc2 ? rc2 : (rc ? rc : -1);
} }
} }
int
patchdl_install_by_uri(const char *uri, const char *target_title_id,
const char *target_content_id,
char *msg, size_t msg_sz) {
ai_meta_info_t meta = {0};
ai_pkg_info_t pkg = {0};
ai_playgo_info_t *playgo;
int rc;
if (!uri || !uri[0]) {
snprintf(msg, msg_sz, "no uri");
return -1;
}
backend_start();
if (g_stage != 5) {
snprintf(msg, msg_sz, "install backend not ready: %s", stage_str(g_stage));
return -1;
}
playgo = calloc(1, sizeof(*playgo));
if (!playgo) { snprintf(msg, msg_sz, "out of memory"); return -1; }
meta.uri = uri;
meta.ex_uri = "";
meta.playgo_scenario_id = "";
meta.content_id = target_content_id ? target_content_id : "";
meta.content_name = "PatchDL";
meta.icon_url = "";
rc = ai_install_by_package(&meta, &pkg, playgo);
remember_install(target_title_id, "InstallByURI", &pkg, target_content_id, rc);
free(playgo);
if (rc == 0) {
snprintf(msg, msg_sz, "install started (InstallByPackage/uri, content %.47s)",
pkg.content_id[0] ? pkg.content_id :
(target_content_id ? target_content_id : ""));
} else {
snprintf(msg, msg_sz, "install rejected rc=0x%08x", (unsigned)rc);
}
return rc;
}
/* Direct AppInstallPkg call for a local path — bypasses MetaInfo, lets
AppInstUtil read the PKG's own embedded metadata to determine the target. */
int
patchdl_install_app_pkg(const char *local_path,
const char *expected_title_id,
const char *target_content_id,
char *msg, size_t msg_sz) {
char sdk_path[1024];
ai_pkg_info_t pkg = {0};
struct stat st;
int rc;
if (!local_path || !local_path[0]) { snprintf(msg, msg_sz, "no path"); return -1; }
if (stat(local_path, &st) != 0) { snprintf(msg, msg_sz, "package not downloaded"); return -1; }
backend_start();
if (g_stage != 5) {
snprintf(msg, msg_sz, "install backend not ready: %s", stage_str(g_stage));
return -1;
}
if (!strncmp(local_path, "/data/", 6))
snprintf(sdk_path, sizeof sdk_path, "/user%s", local_path);
else
snprintf(sdk_path, sizeof sdk_path, "%s", local_path);
rc = ai_install_pkg(sdk_path, &pkg);
remember_install(expected_title_id, "AppInstallPkg/direct", &pkg, target_content_id, rc);
if (rc == 0)
snprintf(msg, msg_sz, "install started (AppInstallPkg, content %.47s)",
pkg.content_id[0] ? pkg.content_id :
(target_content_id ? target_content_id : ""));
else
snprintf(msg, msg_sz, "install rejected rc=0x%08x", (unsigned)rc);
return rc;
}
+45 -3
View File
@@ -1,3 +1,12 @@
/* SPDX-License-Identifier: GPL-3.0-or-later
* Copyright (C) 2026 Knutwurst
*
* PatchDL is free software: you can redistribute it and/or modify it under
* the terms of the GNU General Public License as published by the Free
* Software Foundation, either version 3 of the License, or (at your option)
* any later version. See the LICENSE file in the project root for details.
*/
#pragma once #pragma once
#include <stddef.h> #include <stddef.h>
@@ -14,9 +23,10 @@
*/ */
/* `expected_title_id` is the title id of the installed game the patch is for. /* `expected_title_id` is the title id of the installed game the patch is for.
`storage_title_id` is the title id embedded in the delta_url storage path. `storage_title_id` is the title id embedded in the delta_url storage path.
`target_content_id` is the installed game's content id from app.db; when `target_content_id` is the installed game's content id from app.db; it is
present it is passed to InstallByPackage so Sony's installer has the target retained for diagnostics and status fallback. Normal same-title installs
metadata even for region-shared/master-storage patch bytes. */ deliberately pass an empty MetaInfo.content_id, matching etaHEN's native DPI
path and letting AppInstUtil bind the package to its signed metadata. */
int patchdl_install_local_pkg(const char *local_path, int patchdl_install_local_pkg(const char *local_path,
const char *expected_title_id, const char *expected_title_id,
const char *storage_title_id, const char *storage_title_id,
@@ -31,3 +41,35 @@ int patchdl_install_backend_check(char *msg, size_t msg_sz);
AppInstUtil/Bgft patch-install symbols and report which exist on this AppInstUtil/Bgft patch-install symbols and report which exist on this
firmware. Writes a JSON object into `out`. No install, no side effects. */ firmware. Writes a JSON object into `out`. No install, no side effects. */
int patchdl_install_api_probe(char *out, size_t out_sz); int patchdl_install_api_probe(char *out, size_t out_sz);
/* Read-only: report the .pkg's embedded content id + title id (and whether it
is a full app vs a patch, via *is_app). No install. 0 if anything was read. */
int patchdl_install_pkg_meta(const char *local_path, char *content_id, size_t cid_sz,
char *title_id, size_t tid_sz, int *is_app,
char *msg, size_t msg_sz);
/* Read-only: report the last AppInstUtil install task PatchDL started, using
sceAppInstUtilGetInstallStatus when present. No install, no mutation. */
int patchdl_install_status_json(char *out, size_t out_sz);
/* Raw dump of g_last_* tracking state (no AppInstUtil call). For diagnosis. */
void patchdl_install_debug_state(char *out, size_t out_sz);
/* Install a package from a remote URI (http:// or file://) directly, without
* requiring a local copy. Used for shared-master delta packages where the
* version.xml targets a different title id than the CDN storage path.
* `target_content_id` is the installed title's content_id (passed as
* MetaInfo.content_id so AppInstUtil binds the install to the right title).
*/
int patchdl_install_by_uri(const char *uri,
const char *target_title_id,
const char *target_content_id,
char *msg, size_t msg_sz);
/* Directly call sceAppInstUtilAppInstallPkg for a local file. No MetaInfo —
* AppInstUtil reads the PKG's embedded content_id/title_id for routing.
* Use when InstallByPackage is unavailable (privilege). */
int patchdl_install_app_pkg(const char *local_path,
const char *expected_title_id,
const char *target_content_id,
char *msg, size_t msg_sz);
+516 -63
View File
@@ -1,7 +1,17 @@
/* SPDX-License-Identifier: GPL-3.0-or-later
* Copyright (C) 2026 Knutwurst
*
* PatchDL is free software: you can redistribute it and/or modify it under
* the terms of the GNU General Public License as published by the Free
* Software Foundation, either version 3 of the License, or (at your option)
* any later version. See the LICENSE file in the project root for details.
*/
#include "patchdl_net.h" #include "patchdl_net.h"
#include <arpa/inet.h> #include <arpa/inet.h>
#include <errno.h> #include <errno.h>
#include <fcntl.h>
#include <netinet/in.h> #include <netinet/in.h>
#include <pthread.h> #include <pthread.h>
#include <stdio.h> #include <stdio.h>
@@ -9,6 +19,7 @@
#include <string.h> #include <string.h>
#include <strings.h> #include <strings.h>
#include <sys/socket.h> #include <sys/socket.h>
#include <sys/stat.h>
#include <sys/time.h> #include <sys/time.h>
#include <unistd.h> #include <unistd.h>
@@ -22,26 +33,55 @@
#define DNS_PORT 53 #define DNS_PORT 53
#define DNS_TIMEOUT_MS 3000 #define DNS_TIMEOUT_MS 3000
/* Manifest sanity caps — reject anything bigger than a real PS5 patch. The
largest title we've seen tops out around 70 GB / 18 pieces. */
#define PATCHDL_MAX_PIECES 4096
#define PATCHDL_MAX_PIECE_BYTES (8ULL * 1024 * 1024 * 1024) /* 8 GiB */
#define PATCHDL_MAX_TOTAL_BYTES (200ULL * 1024 * 1024 * 1024) /* 200 GiB */
/* In-RAM buffer caps for full HTTP body fetches. version.xml is a few KB,
manifest JSON is a few MB at most — fail-closed beyond that. The
manifest cap is sized for ~4096 pieces × ~3 KB JSON each with plenty of
headroom; real PS5 manifests are 1-2 MB. */
#define PATCHDL_BUF_MAX_VERXML (4 * 1024 * 1024)
#define PATCHDL_BUF_MAX_MANIFEST (16 * 1024 * 1024)
#ifdef PATCHDL_HAVE_CURL
/* Replacement for fopen("wb"/"r+b") that refuses to follow a symlink at the
destination (would let a malicious symlink redirect the download) and pins
the new file's mode to 0600. Returns NULL on any open error. */
static FILE *
fopen_safe(const char *path, int rw_existing) {
int flags = O_CLOEXEC | O_NOFOLLOW;
int fd;
flags |= rw_existing ? O_RDWR : (O_WRONLY | O_CREAT | O_TRUNC);
fd = open(path, flags, 0600);
if (fd < 0) return NULL;
return fdopen(fd, rw_existing ? "r+b" : "wb");
}
#endif
#ifdef PATCHDL_HAVE_CURL #ifdef PATCHDL_HAVE_CURL
static const char *ALLOWED_HOSTS[] = { static const char *ALLOWED_HOSTS[] = {
"sgst.prod.dl.playstation.net", "sgst.prod.dl.playstation.net",
"gst.prod.dl.playstation.net", "gst.prod.dl.playstation.net",
"gs2.ww.prod.dl.playstation.net", "gs2.ww.prod.dl.playstation.net",
"prosperopatches.com",
NULL, NULL,
}; };
static int static int
host_allowed(const char *host) { host_allowed(const char *host) {
size_t hlen = strlen(host); size_t hlen = strlen(host);
/* DNS is case-insensitive; an upstream redirect to "SGST.prod..." would
otherwise drop out of the allowlist. */
for (int i = 0; ALLOWED_HOSTS[i]; i++) { for (int i = 0; ALLOWED_HOSTS[i]; i++) {
if (!strcmp(host, ALLOWED_HOSTS[i])) if (!strcasecmp(host, ALLOWED_HOSTS[i]))
return 1; return 1;
size_t alen = strlen(ALLOWED_HOSTS[i]); size_t alen = strlen(ALLOWED_HOSTS[i]);
if (hlen > alen + 1 && if (hlen > alen + 1 &&
host[hlen - alen - 1] == '.' && host[hlen - alen - 1] == '.' &&
!strcmp(host + hlen - alen, ALLOWED_HOSTS[i])) !strcasecmp(host + hlen - alen, ALLOWED_HOSTS[i]))
return 1; return 1;
} }
return 0; return 0;
@@ -145,6 +185,10 @@ dns_resolve(const char *host, char *ip_out, size_t ip_sz) {
while (pos < (size_t)n) { while (pos < (size_t)n) {
if (!resp[pos]) { pos++; break; } if (!resp[pos]) { pos++; break; }
if ((resp[pos] & 0xC0) == 0xC0) { pos += 2; break; } if ((resp[pos] & 0xC0) == 0xC0) { pos += 2; break; }
/* Bounds-check the label length BEFORE the increment — a malformed
response with a 0xFF label byte near the end would otherwise walk
past `n`. */
if (pos + 1 + (size_t)resp[pos] >= (size_t)n) { g_dns_step = 5; return -1; }
pos += 1 + resp[pos]; pos += 1 + resp[pos];
} }
if (pos + 4 > (size_t)n) { g_dns_step = 5; return -1; } if (pos + 4 > (size_t)n) { g_dns_step = 5; return -1; }
@@ -156,8 +200,10 @@ dns_resolve(const char *host, char *ip_out, size_t ip_sz) {
if ((resp[pos] & 0xC0) == 0xC0) { if ((resp[pos] & 0xC0) == 0xC0) {
pos += 2; pos += 2;
} else { } else {
while (pos < (size_t)n && resp[pos]) while (pos < (size_t)n && resp[pos]) {
if (pos + 1 + (size_t)resp[pos] >= (size_t)n) break;
pos += 1 + resp[pos]; pos += 1 + resp[pos];
}
pos++; pos++;
} }
if (pos + 10 > (size_t)n) break; if (pos + 10 > (size_t)n) break;
@@ -198,14 +244,14 @@ dns_lookup(const char *host, char *ip_out, size_t ip_sz) {
return 0; return 0;
} }
} }
pthread_mutex_unlock(&dns_cache_mtx); /* Cold miss: resolve while HOLDING the cache lock (single-flight). N pool
workers needing the same CDN host would otherwise each blast Sony's
rate-limited resolver; this way one resolves and the rest get the cache.
It also serializes dns_resolve so its diagnostic globals can't be raced.
(This is the DNS lock, independent of the pool lock.) */
for (int attempt = 0; attempt < 4 && rc; attempt++) for (int attempt = 0; attempt < 4 && rc; attempt++)
rc = dns_resolve(host, ip_out, ip_sz); rc = dns_resolve(host, ip_out, ip_sz);
if (rc) return -1; if (!rc && dns_cache_n < (int)(sizeof(dns_cache) / sizeof(dns_cache[0]))) {
pthread_mutex_lock(&dns_cache_mtx);
if (dns_cache_n < (int)(sizeof(dns_cache) / sizeof(dns_cache[0]))) {
strncpy(dns_cache[dns_cache_n].host, host, strncpy(dns_cache[dns_cache_n].host, host,
sizeof(dns_cache[0].host) - 1); sizeof(dns_cache[0].host) - 1);
strncpy(dns_cache[dns_cache_n].ip, ip_out, strncpy(dns_cache[dns_cache_n].ip, ip_out,
@@ -213,7 +259,7 @@ dns_lookup(const char *host, char *ip_out, size_t ip_sz) {
dns_cache_n++; dns_cache_n++;
} }
pthread_mutex_unlock(&dns_cache_mtx); pthread_mutex_unlock(&dns_cache_mtx);
return 0; return rc;
} }
/* ---------- HTTP GET via curl ------------------------------------------- */ /* ---------- HTTP GET via curl ------------------------------------------- */
@@ -222,7 +268,12 @@ static size_t
write_cb(void *ptr, size_t size, size_t nmemb, void *userdata) { write_cb(void *ptr, size_t size, size_t nmemb, void *userdata) {
patchdl_buf_t *b = userdata; patchdl_buf_t *b = userdata;
size_t total = size * nmemb; size_t total = size * nmemb;
char *newp = realloc(b->data, b->size + total + 1); char *newp;
/* Overflow guard before the cap check (b->size+total may wrap on 32-bit). */
if (total > (size_t)-1 - b->size - 1) return 0;
/* Cap accumulation so a hostile CDN can't drive unbounded RAM growth. */
if (b->max && b->size + total > b->max) return 0;
newp = realloc(b->data, b->size + total + 1);
if (!newp) return 0; if (!newp) return 0;
b->data = newp; b->data = newp;
memcpy(b->data + b->size, ptr, total); memcpy(b->data + b->size, ptr, total);
@@ -252,7 +303,11 @@ patchdl_http_get(const char *url, patchdl_buf_t *out) {
snprintf(resolve_80, sizeof(resolve_80), "%s:80:%s", host, ip); snprintf(resolve_80, sizeof(resolve_80), "%s:80:%s", host, ip);
resolve_list = curl_slist_append(resolve_list, resolve_80); resolve_list = curl_slist_append(resolve_list, resolve_80);
{
size_t caller_max = out->max;
memset(out, 0, sizeof(*out)); memset(out, 0, sizeof(*out));
out->max = caller_max;
}
curl = curl_easy_init(); curl = curl_easy_init();
if (!curl) { curl_slist_free_all(resolve_list); return -1; } if (!curl) { curl_slist_free_all(resolve_list); return -1; }
@@ -277,6 +332,12 @@ patchdl_http_get(const char *url, patchdl_buf_t *out) {
curl_easy_setopt(curl, CURLOPT_TIMEOUT, 15L); curl_easy_setopt(curl, CURLOPT_TIMEOUT, 15L);
curl_easy_setopt(curl, CURLOPT_FOLLOWLOCATION, 1L); curl_easy_setopt(curl, CURLOPT_FOLLOWLOCATION, 1L);
curl_easy_setopt(curl, CURLOPT_MAXREDIRS, 3L); curl_easy_setopt(curl, CURLOPT_MAXREDIRS, 3L);
/* Redirects must stay on HTTPS — host_allowed gates the initial URL, but
once libcurl follows a 302 we want the protocol pinned too. The _STR
variants replaced the bitfield options in libcurl 7.85. */
curl_easy_setopt(curl, CURLOPT_PROTOCOLS_STR, "https");
curl_easy_setopt(curl, CURLOPT_REDIR_PROTOCOLS_STR, "https");
curl_easy_setopt(curl, CURLOPT_NOSIGNAL, 1L);
curl_easy_setopt(curl, CURLOPT_USERAGENT, "patchdl/1.0"); curl_easy_setopt(curl, CURLOPT_USERAGENT, "patchdl/1.0");
res = curl_easy_perform(curl); res = curl_easy_perform(curl);
@@ -344,14 +405,20 @@ curl_progress_cb(void *clientp, curl_off_t dltotal, curl_off_t dlnow,
} }
/* Returns 0 on success, -1 on download/network failure, -2 when an expected /* Returns 0 on success, -1 on download/network failure, -2 when an expected
SHA-256 was given and the downloaded bytes did not match it. */ SHA-256 was given and the downloaded bytes did not match it, -3 when a byte
range was requested (range_start>0) but the server ignored it (no HTTP 206).
When range_start>0 the body is appended at the file's current position, so
the caller must have it positioned at range_start and must not verify. */
static int static int
http_download_to_file_progress(const char *url, FILE *fp, long long *bytes_out, http_download_to_file_progress(const char *url, FILE *fp, long long *bytes_out,
progress_state_t *progress, progress_state_t *progress,
const char *expected_sha256_hex) { const char *expected_sha256_hex,
long long range_start) {
CURL *curl; CURL *curl;
CURLcode res; CURLcode res;
char host[256], ip[INET_ADDRSTRLEN], rs443[512], rs80[512]; char host[256], ip[INET_ADDRSTRLEN], rs443[512], rs80[512];
char range_hdr[48];
long http_code = 0;
struct curl_slist *rl = NULL; struct curl_slist *rl = NULL;
struct curl_blob ca_blob; struct curl_blob ca_blob;
curl_off_t dl = 0; curl_off_t dl = 0;
@@ -395,11 +462,22 @@ http_download_to_file_progress(const char *url, FILE *fp, long long *bytes_out,
curl_easy_setopt(curl, CURLOPT_SSL_CIPHER_LIST, "DEFAULT@SECLEVEL=0"); curl_easy_setopt(curl, CURLOPT_SSL_CIPHER_LIST, "DEFAULT@SECLEVEL=0");
curl_easy_setopt(curl, CURLOPT_FOLLOWLOCATION, 1L); curl_easy_setopt(curl, CURLOPT_FOLLOWLOCATION, 1L);
curl_easy_setopt(curl, CURLOPT_MAXREDIRS, 5L); curl_easy_setopt(curl, CURLOPT_MAXREDIRS, 5L);
/* HTTPS pin removed on the streaming download path: the Sony CDN sometimes
302s a piece URL to a signed http:// edge inside its own infrastructure,
and refusing those redirects was breaking real-world downloads.
host_allowed + TLS-against-pinned-root on every leg already gate the
hosts we'll talk to. NOSIGNAL stays — it protects the worker from a
SIGPIPE on connection RST. */
curl_easy_setopt(curl, CURLOPT_NOSIGNAL, 1L);
curl_easy_setopt(curl, CURLOPT_CONNECTTIMEOUT, 20L); curl_easy_setopt(curl, CURLOPT_CONNECTTIMEOUT, 20L);
/* No total timeout (patches can be large); abort only on a long stall. */ /* No total timeout (patches can be large); abort only on a long stall. */
curl_easy_setopt(curl, CURLOPT_LOW_SPEED_LIMIT, 1024L); curl_easy_setopt(curl, CURLOPT_LOW_SPEED_LIMIT, 1024L);
curl_easy_setopt(curl, CURLOPT_LOW_SPEED_TIME, 30L); curl_easy_setopt(curl, CURLOPT_LOW_SPEED_TIME, 30L);
curl_easy_setopt(curl, CURLOPT_USERAGENT, "patchdl/1.0"); curl_easy_setopt(curl, CURLOPT_USERAGENT, "patchdl/1.0");
if (range_start > 0) {
snprintf(range_hdr, sizeof(range_hdr), "%lld-", range_start);
curl_easy_setopt(curl, CURLOPT_RANGE, range_hdr);
}
if (progress && progress->cb) { if (progress && progress->cb) {
curl_easy_setopt(curl, CURLOPT_NOPROGRESS, 0L); curl_easy_setopt(curl, CURLOPT_NOPROGRESS, 0L);
curl_easy_setopt(curl, CURLOPT_XFERINFOFUNCTION, curl_progress_cb); curl_easy_setopt(curl, CURLOPT_XFERINFOFUNCTION, curl_progress_cb);
@@ -407,6 +485,7 @@ http_download_to_file_progress(const char *url, FILE *fp, long long *bytes_out,
} }
res = curl_easy_perform(curl); res = curl_easy_perform(curl);
curl_easy_getinfo(curl, CURLINFO_RESPONSE_CODE, &http_code);
curl_easy_getinfo(curl, CURLINFO_SIZE_DOWNLOAD_T, &dl); curl_easy_getinfo(curl, CURLINFO_SIZE_DOWNLOAD_T, &dl);
curl_easy_cleanup(curl); curl_easy_cleanup(curl);
curl_slist_free_all(rl); curl_slist_free_all(rl);
@@ -415,13 +494,22 @@ http_download_to_file_progress(const char *url, FILE *fp, long long *bytes_out,
if (sink.md) EVP_MD_CTX_free(sink.md); if (sink.md) EVP_MD_CTX_free(sink.md);
return -1; return -1;
} }
/* Asked for a byte range but the server sent the whole file (no 206): the
caller must drop the piece and re-fetch it whole. */
if (range_start > 0 && http_code != 206) {
if (sink.md) EVP_MD_CTX_free(sink.md);
return -3;
}
if (sink.md) { if (sink.md) {
unsigned char dig[EVP_MAX_MD_SIZE]; unsigned char dig[EVP_MAX_MD_SIZE];
unsigned int dlen = 0; unsigned int dlen = 0;
char hex[2 * EVP_MAX_MD_SIZE + 1]; char hex[2 * EVP_MAX_MD_SIZE + 1];
EVP_DigestFinal_ex(sink.md, dig, &dlen); int ok = EVP_DigestFinal_ex(sink.md, dig, &dlen);
EVP_MD_CTX_free(sink.md); EVP_MD_CTX_free(sink.md);
/* Fail-closed on a digest API failure — otherwise hex would be empty
and we'd silently report -2 with no diagnostic. */
if (ok != 1 || dlen == 0) return -2;
hex_encode(dig, dlen, hex, sizeof(hex)); hex_encode(dig, dlen, hex, sizeof(hex));
if (strcasecmp(hex, expected_sha256_hex) != 0) if (strcasecmp(hex, expected_sha256_hex) != 0)
return -2; /* integrity mismatch */ return -2; /* integrity mismatch */
@@ -435,12 +523,12 @@ int
patchdl_http_download_progress(const char *url, const char *dest_path, patchdl_http_download_progress(const char *url, const char *dest_path,
long long *bytes_out, long long *bytes_out,
patchdl_download_progress_cb cb, void *ctx) { patchdl_download_progress_cb cb, void *ctx) {
FILE *fp = fopen(dest_path, "wb"); FILE *fp = fopen_safe(dest_path, 0);
progress_state_t progress = { cb, ctx, 0, 0 }; progress_state_t progress = { cb, ctx, 0, 0 };
int rc; int rc;
if (!fp) return -1; if (!fp) return -1;
rc = http_download_to_file_progress(url, fp, bytes_out, &progress, NULL); rc = http_download_to_file_progress(url, fp, bytes_out, &progress, NULL, 0);
fclose(fp); fclose(fp);
if (rc) { if (rc) {
@@ -456,8 +544,24 @@ patchdl_http_download(const char *url, const char *dest_path,
return patchdl_http_download_progress(url, dest_path, bytes_out, NULL, NULL); return patchdl_http_download_progress(url, dest_path, bytes_out, NULL, NULL);
} }
/* Substring scan bounded to [p, limit). NULL limit means search to NUL.
Returns NULL if needle is not found before limit. */
static const char *
strstr_bounded(const char *p, const char *needle, const char *limit) {
const char *hit = strstr(p, needle);
if (!hit) return NULL;
if (limit && hit >= limit) return NULL;
return hit;
}
/* Read "key": "value" starting from p. Search and read are bounded by `limit`
(pass NULL to search to end of buffer). Decodes \\ \" \/ \n \r \t \b \f; any
other \X is copied without the backslash. \uXXXX is left as the raw 6 bytes
(we don't need Unicode for manifest fields). limit==NULL keeps legacy
end-of-string scope for callers that don't need the cap. */
static int static int
json_string_after(const char *p, const char *key, char *out, size_t out_sz) { json_string_after(const char *p, const char *key, char *out, size_t out_sz,
const char *limit) {
char needle[48]; char needle[48];
const char *q; const char *q;
size_t n = 0; size_t n = 0;
@@ -465,35 +569,59 @@ json_string_after(const char *p, const char *key, char *out, size_t out_sz) {
if (!p || !out || out_sz == 0) return -1; if (!p || !out || out_sz == 0) return -1;
out[0] = '\0'; out[0] = '\0';
snprintf(needle, sizeof(needle), "\"%s\"", key); snprintf(needle, sizeof(needle), "\"%s\"", key);
q = strstr(p, needle); q = strstr_bounded(p, needle, limit);
if (!q) return -1; if (!q) return -1;
q += strlen(needle); q += strlen(needle);
while (*q == ' ' || *q == '\t' || *q == '\r' || *q == '\n') q++; while ((!limit || q < limit) &&
(*q == ' ' || *q == '\t' || *q == '\r' || *q == '\n')) q++;
if (limit && q >= limit) return -1;
if (*q++ != ':') return -1; if (*q++ != ':') return -1;
while (*q == ' ' || *q == '\t' || *q == '\r' || *q == '\n') q++; while ((!limit || q < limit) &&
(*q == ' ' || *q == '\t' || *q == '\r' || *q == '\n')) q++;
if (limit && q >= limit) return -1;
if (*q++ != '"') return -1; if (*q++ != '"') return -1;
while (*q && *q != '"' && n + 1 < out_sz) { while ((!limit || q < limit) && *q && *q != '"' && n + 1 < out_sz) {
if (*q == '\\' && q[1]) q++; if (*q == '\\' && q[1] && (!limit || q + 1 < limit)) {
q++;
switch (*q) {
case '"': out[n++] = '"'; break;
case '\\': out[n++] = '\\'; break;
case '/': out[n++] = '/'; break;
case 'n': out[n++] = '\n'; break;
case 'r': out[n++] = '\r'; break;
case 't': out[n++] = '\t'; break;
case 'b': out[n++] = '\b'; break;
case 'f': out[n++] = '\f'; break;
default: out[n++] = *q; break; /* unknown escape: keep payload */
}
q++;
} else {
out[n++] = *q++; out[n++] = *q++;
} }
}
out[n] = '\0'; out[n] = '\0';
return n ? 0 : -1; return n ? 0 : -1;
} }
static int static int
json_u64_after(const char *p, const char *key, unsigned long long *out) { json_u64_after(const char *p, const char *key, unsigned long long *out,
const char *limit) {
char needle[48]; char needle[48];
const char *q; const char *q;
if (!p || !out) return -1; if (!p || !out) return -1;
snprintf(needle, sizeof(needle), "\"%s\"", key); snprintf(needle, sizeof(needle), "\"%s\"", key);
q = strstr(p, needle); q = strstr_bounded(p, needle, limit);
if (!q) return -1; if (!q) return -1;
q += strlen(needle); q += strlen(needle);
while (*q == ' ' || *q == '\t' || *q == '\r' || *q == '\n') q++; while ((!limit || q < limit) &&
(*q == ' ' || *q == '\t' || *q == '\r' || *q == '\n')) q++;
if (limit && q >= limit) return -1;
if (*q++ != ':') return -1; if (*q++ != ':') return -1;
while (*q == ' ' || *q == '\t' || *q == '\r' || *q == '\n') q++; while ((!limit || q < limit) &&
(*q == ' ' || *q == '\t' || *q == '\r' || *q == '\n')) q++;
if (limit && q >= limit) return -1;
if (*q < '0' || *q > '9') return -1; if (*q < '0' || *q > '9') return -1;
*out = strtoull(q, NULL, 10); *out = strtoull(q, NULL, 10);
return 0; return 0;
@@ -504,17 +632,17 @@ patchdl_http_download_manifest_progress(const char *manifest_url,
const char *dest_path, const char *dest_path,
long long *bytes_out, long long *bytes_out,
patchdl_download_progress_cb cb, patchdl_download_progress_cb cb,
void *ctx, int verify) { void *ctx, int verify, int resume) {
patchdl_buf_t manifest; patchdl_buf_t manifest;
const char *pieces; const char *pieces, *pieces_end, *p;
const char *p; FILE *fp = NULL;
FILE *fp; long long total = 0, have = 0;
long long total = 0;
unsigned long long manifest_total = 0; unsigned long long manifest_total = 0;
int count = 0; int count = 0, started, rc = -1;
int rc = -1;
if (bytes_out) *bytes_out = 0; if (bytes_out) *bytes_out = 0;
memset(&manifest, 0, sizeof(manifest));
manifest.max = PATCHDL_BUF_MAX_MANIFEST;
if (patchdl_http_get(manifest_url, &manifest)) if (patchdl_http_get(manifest_url, &manifest))
return -1; return -1;
if (!manifest.data || !manifest.size) { if (!manifest.data || !manifest.size) {
@@ -529,52 +657,113 @@ patchdl_http_download_manifest_progress(const char *manifest_url,
} }
/* Bound the scan to the pieces array; otherwise a later "url" key in the /* Bound the scan to the pieces array; otherwise a later "url" key in the
manifest (e.g. playgoChunkCrcUrl) could be appended as a bogus piece. */ manifest (e.g. playgoChunkCrcUrl) could be appended as a bogus piece. */
const char *pieces_end = strchr(pieces, ']'); pieces_end = strchr(pieces, ']');
json_u64_after(manifest.data, "originalFileSize", &manifest_total); json_u64_after(manifest.data, "originalFileSize", &manifest_total, NULL);
fp = fopen(dest_path, "wb"); /* Resume: reopen the existing partial and keep its bytes; else start clean.
if (!fp) { Fully-downloaded pieces are skipped; the one piece that was only partially
free(manifest.data); written continues mid-piece via an HTTP byte range (with a fall back to
return -1; re-fetching it whole if the CDN ignores the range). */
if (resume) {
fp = fopen_safe(dest_path, 1);
if (fp) { fseek(fp, 0, SEEK_END); have = ftell(fp); if (have < 0) have = 0; }
} }
if (!fp) { fp = fopen_safe(dest_path, 0); have = 0; }
if (!fp) { free(manifest.data); return -1; }
started = (have <= 0);
p = pieces; p = pieces;
while ((p = strstr(p, "\"url\"")) && (!pieces_end || p < pieces_end)) { while ((p = strstr(p, "\"url\"")) && (!pieces_end || p < pieces_end)) {
char url[768]; char url[768];
char hash[80] = {0}; char hash[80] = {0};
long long got = 0; long long got = 0, range_start = 0;
unsigned long long expected = 0; unsigned long long expected = 0;
unsigned long long offset = 0; unsigned long long offset = 0;
int have_offset, drc; int have_offset, drc;
const char *want_hash;
const char *obj_end = strchr(p, '}'); const char *obj_end = strchr(p, '}');
progress_state_t progress = { const char *piece_limit = (obj_end && (!pieces_end || obj_end < pieces_end))
cb, ? obj_end : pieces_end;
ctx,
total,
manifest_total ? (long long)manifest_total : 0
};
if (json_string_after(p, "url", url, sizeof(url))) if (json_string_after(p, "url", url, sizeof(url), piece_limit))
break; break;
json_u64_after(p, "fileSize", &expected); json_u64_after(p, "fileSize", &expected, piece_limit);
have_offset = (json_u64_after(p, "fileOffset", &offset) == 0); have_offset = (json_u64_after(p, "fileOffset", &offset, piece_limit) == 0);
if (verify)
json_string_after(p, "hashValue", hash, sizeof(hash));
/* Pieces are concatenated in array order; each one's fileOffset must /* Piece already fully present from a previous run: skip the download. */
equal the bytes written so far. A manifest that lists them out of if (!started && have_offset && expected &&
order would otherwise silently produce a corrupt package. */ have >= (long long)(offset + expected)) {
if (have_offset && offset != (unsigned long long)total) total = (long long)(offset + expected);
count++;
if (cb && cb(ctx, total, manifest_total ? (long long)manifest_total : total))
goto done;
p = obj_end ? obj_end + 1 : p + 5;
continue;
}
/* First piece to (re)download while resuming. If part of it is already
on disk, resume WITHIN it with a byte range; otherwise drop any stray
bytes and fetch it whole. After this, every piece is fetched whole. */
if (!started) {
if (have_offset && expected && have > (long long)offset &&
have < (long long)(offset + expected)) {
range_start = have - (long long)offset; /* this piece's bytes on disk */
fseek(fp, 0, SEEK_END); /* append at `have` */
total = have;
} else {
long long start_at = have_offset ? (long long)offset : 0;
fflush(fp);
if (ftruncate(fileno(fp), (off_t)start_at) != 0)
goto done; /* can't resume cleanly; keep partial */
fseek(fp, 0, SEEK_END);
total = start_at;
}
started = 1;
}
/* Whole pieces are concatenated in array order; a ranged (partial) piece
starts mid-piece, so the contiguity guard applies only to whole ones. */
if (have_offset && range_start == 0 && offset != (unsigned long long)total)
goto done; goto done;
/* drc: 0 ok, -1 network/cancel, -2 SHA-256 mismatch (propagated out). */ /* A ranged piece can't be hashed (only its tail is fetched). */
want_hash = NULL;
if (range_start == 0 && verify) {
json_string_after(p, "hashValue", hash, sizeof(hash), piece_limit);
want_hash = hash[0] ? hash : NULL;
}
{
progress_state_t progress = {
cb, ctx, total, manifest_total ? (long long)manifest_total : 0
};
/* drc: 0 ok, -1 network/cancel, -2 SHA-256, -3 range ignored. */
drc = http_download_to_file_progress(url, fp, &got, &progress, drc = http_download_to_file_progress(url, fp, &got, &progress,
hash[0] ? hash : NULL); want_hash, range_start);
if (drc == -3) {
/* Server ignored the range: drop the piece and fetch it whole. */
fflush(fp);
if (ftruncate(fileno(fp), (off_t)offset) != 0)
goto done;
fseek(fp, 0, SEEK_END);
total = (long long)offset;
range_start = 0;
if (verify) {
json_string_after(p, "hashValue", hash, sizeof(hash),
piece_limit);
want_hash = hash[0] ? hash : NULL;
}
progress.base = total;
drc = http_download_to_file_progress(url, fp, &got, &progress,
want_hash, 0);
}
}
if (drc) { if (drc) {
if (drc == -2) rc = -2; if (drc == -2) rc = -2;
goto done; goto done;
} }
if (expected && (unsigned long long)got != expected) /* range_start + got = this piece's bytes now on disk. */
if (expected && (unsigned long long)(range_start + got) != expected)
goto done; goto done;
total += got; total += got;
@@ -593,7 +782,8 @@ patchdl_http_download_manifest_progress(const char *manifest_url,
done: done:
fclose(fp); fclose(fp);
free(manifest.data); free(manifest.data);
if (rc) unlink(dest_path); /* Keep the partial on failure so it can be resumed; the caller deletes it
on cancel or on a corrupt-verify (-2). */
return rc; return rc;
} }
@@ -601,7 +791,267 @@ int
patchdl_http_download_manifest(const char *manifest_url, const char *dest_path, patchdl_http_download_manifest(const char *manifest_url, const char *dest_path,
long long *bytes_out) { long long *bytes_out) {
return patchdl_http_download_manifest_progress(manifest_url, dest_path, return patchdl_http_download_manifest_progress(manifest_url, dest_path,
bytes_out, NULL, NULL, 0); bytes_out, NULL, NULL, 0, 0);
}
/* ---- global init + parallel piece download (connection pool) ----------- */
void patchdl_net_global_init(void) { curl_global_init(CURL_GLOBAL_ALL); }
void patchdl_net_global_cleanup(void) { curl_global_cleanup(); }
/* Write sink for one piece: pwrite at a fixed base offset (concurrent
non-overlapping pieces of the same fd are safe), tee into SHA-256 if asked,
and publish bytes-so-far for live progress. */
typedef struct {
int fd;
long long base;
long long written;
EVP_MD_CTX *md;
volatile long long *bytes_slot;
} piece_sink_t;
static size_t
piece_write_cb(void *ptr, size_t size, size_t nmemb, void *ud) {
piece_sink_t *s = (piece_sink_t *)ud;
size_t n = size * nmemb;
ssize_t w;
if (n == 0) return 0;
w = pwrite(s->fd, ptr, n, (off_t)(s->base + s->written));
if (w < 0 || (size_t)w != n) return 0; /* short write -> curl errors out */
if (s->md) EVP_DigestUpdate(s->md, ptr, n);
s->written += (long long)n;
if (s->bytes_slot) *s->bytes_slot = s->written;
return n;
}
static int
piece_xfer_cb(void *clientp, curl_off_t dltotal, curl_off_t dlnow,
curl_off_t ultotal, curl_off_t ulnow) {
volatile int *abort_flag = (volatile int *)clientp;
(void)dltotal; (void)dlnow; (void)ultotal; (void)ulnow;
return (abort_flag && *abort_flag) ? 1 : 0; /* non-zero aborts the transfer */
}
int
patchdl_http_download_piece(const char *url, int fd,
long long file_offset, long long file_size,
const char *expected_sha256_or_null,
patchdl_piece_ctx_t *ctx,
int *curl_rc_out, long *http_code_out) {
CURL *curl;
CURLcode res;
long http_code = 0;
char host[256], ip[INET_ADDRSTRLEN], rs443[512], rs80[512];
struct curl_slist *rl = NULL;
struct curl_blob ca_blob;
piece_sink_t sink;
int verify = (expected_sha256_or_null && expected_sha256_or_null[0]);
if (curl_rc_out) *curl_rc_out = 0;
if (http_code_out) *http_code_out = 0;
if (url_host(url, host, sizeof(host))) return -1;
if (!host_allowed(host)) return -1;
if (dns_lookup(host, ip, sizeof(ip))) return -1;
memset(&sink, 0, sizeof(sink));
sink.fd = fd;
sink.base = file_offset;
sink.bytes_slot = ctx ? ctx->bytes_slot : NULL;
if (verify) {
sink.md = EVP_MD_CTX_new();
if (sink.md) EVP_DigestInit_ex(sink.md, EVP_sha256(), NULL);
}
snprintf(rs443, sizeof(rs443), "%s:443:%s", host, ip);
rl = curl_slist_append(NULL, rs443);
snprintf(rs80, sizeof(rs80), "%s:80:%s", host, ip);
rl = curl_slist_append(rl, rs80);
ca_blob.data = (void *)PATCHDL_SCEI_DNAS_ROOT_PEM;
ca_blob.len = strlen(PATCHDL_SCEI_DNAS_ROOT_PEM);
ca_blob.flags = CURL_BLOB_COPY;
curl = curl_easy_init();
if (!curl) {
curl_slist_free_all(rl);
if (sink.md) EVP_MD_CTX_free(sink.md);
return -1;
}
curl_easy_setopt(curl, CURLOPT_URL, url);
curl_easy_setopt(curl, CURLOPT_RESOLVE, rl);
curl_easy_setopt(curl, CURLOPT_WRITEFUNCTION, piece_write_cb);
curl_easy_setopt(curl, CURLOPT_WRITEDATA, &sink);
curl_easy_setopt(curl, CURLOPT_CAINFO_BLOB, &ca_blob);
curl_easy_setopt(curl, CURLOPT_SSL_VERIFYPEER, 1L);
curl_easy_setopt(curl, CURLOPT_SSL_VERIFYHOST, 2L);
curl_easy_setopt(curl, CURLOPT_SSL_CIPHER_LIST, "DEFAULT@SECLEVEL=0");
curl_easy_setopt(curl, CURLOPT_FOLLOWLOCATION, 1L);
curl_easy_setopt(curl, CURLOPT_MAXREDIRS, 5L);
/* HTTPS pin removed on the streaming piece path — see the same change in
http_download_to_file_progress for the why. */
curl_easy_setopt(curl, CURLOPT_NOSIGNAL, 1L);
curl_easy_setopt(curl, CURLOPT_FAILONERROR, 1L); /* 4xx/5xx -> error, no body written */
curl_easy_setopt(curl, CURLOPT_CONNECTTIMEOUT, 20L);
curl_easy_setopt(curl, CURLOPT_LOW_SPEED_LIMIT, 1024L);
curl_easy_setopt(curl, CURLOPT_LOW_SPEED_TIME, 30L);
curl_easy_setopt(curl, CURLOPT_USERAGENT, "patchdl/1.0");
if (ctx && ctx->abort) {
curl_easy_setopt(curl, CURLOPT_NOPROGRESS, 0L);
curl_easy_setopt(curl, CURLOPT_XFERINFOFUNCTION, piece_xfer_cb);
curl_easy_setopt(curl, CURLOPT_XFERINFODATA, (void *)ctx->abort);
}
res = curl_easy_perform(curl);
curl_easy_getinfo(curl, CURLINFO_RESPONSE_CODE, &http_code);
curl_easy_cleanup(curl);
curl_slist_free_all(rl);
if (curl_rc_out) *curl_rc_out = (int)res;
if (http_code_out) *http_code_out = http_code;
if (res != CURLE_OK) {
if (sink.md) EVP_MD_CTX_free(sink.md);
return -1; /* network error / abort */
}
if (file_size > 0 && sink.written != file_size) {
if (sink.md) EVP_MD_CTX_free(sink.md);
return -1; /* short or over-long -> failed */
}
if (sink.md) {
unsigned char dig[EVP_MAX_MD_SIZE];
unsigned int dl = 0;
char hex[2 * EVP_MAX_MD_SIZE + 1];
int ok = EVP_DigestFinal_ex(sink.md, dig, &dl);
EVP_MD_CTX_free(sink.md);
if (ok != 1 || dl == 0) return -2;
hex_encode(dig, dl, hex, sizeof(hex));
if (strcasecmp(hex, expected_sha256_or_null) != 0)
return -2; /* integrity mismatch */
}
fdatasync(fd); /* durable before the caller sets the done bit */
return 0;
}
/* Read-only: SHA-256 a [offset, offset+size) region of fd into out_hex (>=65
bytes). Uses pread so it doesn't disturb the fd offset. 0 on success. */
int
patchdl_sha256_fd_region(int fd, long long offset, long long size, char *out_hex) {
EVP_MD_CTX *md;
unsigned char *buf;
long long pos = offset, remaining = size;
const size_t CHUNK = 1u << 20;
out_hex[0] = '\0';
if (fd < 0 || size < 0) return -1;
md = EVP_MD_CTX_new();
if (!md) return -1;
buf = malloc(CHUNK);
if (!buf) { EVP_MD_CTX_free(md); return -1; }
EVP_DigestInit_ex(md, EVP_sha256(), NULL);
while (remaining > 0) {
size_t want = remaining > (long long)CHUNK ? CHUNK : (size_t)remaining;
ssize_t got = pread(fd, buf, want, (off_t)pos);
if (got <= 0) { free(buf); EVP_MD_CTX_free(md); return -1; }
EVP_DigestUpdate(md, buf, (size_t)got);
pos += got; remaining -= got;
}
{
unsigned char dig[EVP_MAX_MD_SIZE];
unsigned int dl = 0, i;
int ok = EVP_DigestFinal_ex(md, dig, &dl);
if (ok != 1 || dl == 0) { free(buf); EVP_MD_CTX_free(md); return -1; }
for (i = 0; i < dl; i++) snprintf(out_hex + 2 * i, 3, "%02x", dig[i]);
out_hex[2 * dl] = '\0';
}
free(buf);
EVP_MD_CTX_free(md);
return 0;
}
void
patchdl_manifest_free(patchdl_manifest_t *m) {
if (!m || !m->pieces) return;
for (int i = 0; i < m->count; i++) free(m->pieces[i].url);
free(m->pieces);
m->pieces = NULL;
m->count = 0;
}
int
patchdl_fetch_manifest(const char *manifest_url, patchdl_manifest_t *out) {
patchdl_buf_t buf;
const char *pieces, *pieces_end, *p;
int cap = 0, n = 0;
long long running = 0;
memset(out, 0, sizeof(*out));
memset(&buf, 0, sizeof(buf));
buf.max = PATCHDL_BUF_MAX_MANIFEST;
if (patchdl_http_get(manifest_url, &buf)) return -1;
if (!buf.data || !buf.size) { free(buf.data); return -1; }
pieces = strstr(buf.data, "\"pieces\"");
if (!pieces || !(pieces = strchr(pieces, '['))) { free(buf.data); return -1; }
pieces_end = strchr(pieces, ']');
for (p = pieces; (p = strstr(p, "\"url\"")) && (!pieces_end || p < pieces_end); p += 5)
cap++;
if (cap <= 0) { free(buf.data); return -1; }
out->pieces = calloc((size_t)cap, sizeof(patchdl_piece_t));
if (!out->pieces) { free(buf.data); return -1; }
/* Sanity caps: refuse a manifest that would let a CDN drive multi-TB
allocations or millions of pieces. The biggest real PS5 patch we've
seen is ~70 GB / 18 pieces; these limits leave room to spare. */
if (cap > PATCHDL_MAX_PIECES) { free(buf.data); return -1; }
p = pieces;
while ((p = strstr(p, "\"url\"")) && (!pieces_end || p < pieces_end) && n < cap) {
char url[768] = {0};
unsigned long long sz = 0, off = 0;
const char *obj_end = strchr(p, '}');
const char *piece_limit = (obj_end && (!pieces_end || obj_end < pieces_end))
? obj_end : pieces_end;
if (json_string_after(p, "url", url, sizeof(url), piece_limit))
break;
json_u64_after(p, "fileSize", &sz, piece_limit);
if (json_u64_after(p, "fileOffset", &off, piece_limit) != 0)
off = (unsigned long long)running; /* no offset -> assume contiguous */
/* Validate tiling: pieces must be in order, contiguous, non-empty,
and each individually under the per-piece cap. */
if ((long long)off != running || sz == 0 || sz > PATCHDL_MAX_PIECE_BYTES) {
patchdl_manifest_free(out);
free(buf.data);
return -1;
}
if ((unsigned long long)running + sz > PATCHDL_MAX_TOTAL_BYTES) {
patchdl_manifest_free(out);
free(buf.data);
return -1;
}
out->pieces[n].url = strdup(url);
out->pieces[n].offset = (long long)off;
out->pieces[n].size = (long long)sz;
json_string_after(p, "hashValue", out->pieces[n].hash,
sizeof(out->pieces[n].hash), piece_limit);
if (!out->pieces[n].url) {
patchdl_manifest_free(out);
free(buf.data);
return -1;
}
running += (long long)sz;
n++;
out->count = n; /* keep current so manifest_free frees exactly n */
p = obj_end ? obj_end + 1 : p + 5;
}
free(buf.data);
if (n == 0) { patchdl_manifest_free(out); return -1; }
out->total = running; /* authoritative assembled size */
return 0;
} }
void void
@@ -637,6 +1087,9 @@ patchdl_net_diag(const char *url, char *out_json, size_t sz) {
curl_easy_setopt(curl, CURLOPT_SSL_VERIFYPEER, 1L); curl_easy_setopt(curl, CURLOPT_SSL_VERIFYPEER, 1L);
curl_easy_setopt(curl, CURLOPT_SSL_VERIFYHOST, 2L); curl_easy_setopt(curl, CURLOPT_SSL_VERIFYHOST, 2L);
curl_easy_setopt(curl, CURLOPT_SSL_CIPHER_LIST, "DEFAULT@SECLEVEL=0"); curl_easy_setopt(curl, CURLOPT_SSL_CIPHER_LIST, "DEFAULT@SECLEVEL=0");
curl_easy_setopt(curl, CURLOPT_PROTOCOLS_STR, "https");
curl_easy_setopt(curl, CURLOPT_REDIR_PROTOCOLS_STR, "https");
curl_easy_setopt(curl, CURLOPT_NOSIGNAL, 1L);
curl_easy_setopt(curl, CURLOPT_TIMEOUT, 15L); curl_easy_setopt(curl, CURLOPT_TIMEOUT, 15L);
res = curl_easy_perform(curl); res = curl_easy_perform(curl);
curl_easy_getinfo(curl, CURLINFO_RESPONSE_CODE, &http_code); curl_easy_getinfo(curl, CURLINFO_RESPONSE_CODE, &http_code);
@@ -696,8 +1149,8 @@ patchdl_http_download_manifest_progress(const char *manifest_url,
const char *dest_path, const char *dest_path,
long long *bytes_out, long long *bytes_out,
patchdl_download_progress_cb cb, patchdl_download_progress_cb cb,
void *ctx, int verify) { void *ctx, int verify, int resume) {
(void)cb; (void)ctx; (void)verify; (void)cb; (void)ctx; (void)verify; (void)resume;
return patchdl_http_download_manifest(manifest_url, dest_path, bytes_out); return patchdl_http_download_manifest(manifest_url, dest_path, bytes_out);
} }
+67 -2
View File
@@ -1,3 +1,12 @@
/* SPDX-License-Identifier: GPL-3.0-or-later
* Copyright (C) 2026 Knutwurst
*
* PatchDL is free software: you can redistribute it and/or modify it under
* the terms of the GNU General Public License as published by the Free
* Software Foundation, either version 3 of the License, or (at your option)
* any later version. See the LICENSE file in the project root for details.
*/
#pragma once #pragma once
#include <stddef.h> #include <stddef.h>
@@ -6,13 +15,66 @@ typedef struct {
char *data; char *data;
size_t size; size_t size;
size_t cap; size_t cap;
size_t max; /* 0 = unbounded (legacy). Otherwise write_cb fails past this. */
} patchdl_buf_t; } patchdl_buf_t;
patchdl_buf_t *patchdl_buf_new(void); patchdl_buf_t *patchdl_buf_new(void);
void patchdl_buf_free(patchdl_buf_t *b); void patchdl_buf_free(patchdl_buf_t *b);
/* Call once, single-threaded, before any concurrent download worker starts /
after they have all joined. curl's global/OpenSSL init is otherwise lazy and
races across threads. */
void patchdl_net_global_init(void);
void patchdl_net_global_cleanup(void);
int patchdl_http_get(const char *url, patchdl_buf_t *out); int patchdl_http_get(const char *url, patchdl_buf_t *out);
/* ---- parallel piece download (used by the connection pool) ------------- */
/* One piece of a split manifest package. `url` is heap-allocated. */
typedef struct {
char *url;
long long offset; /* byte offset of this piece in the assembled file */
long long size; /* exact length of this piece */
char hash[80]; /* manifest SHA-256 hex, or "" */
} patchdl_piece_t;
typedef struct {
patchdl_piece_t *pieces;
int count;
long long total; /* assembled file size = sum of piece sizes */
} patchdl_manifest_t;
/* Fetch + parse a Sony JSON manifest into a validated, contiguously-tiled
piece list. Returns 0 on success (caller frees with patchdl_manifest_free),
-1 on fetch/parse/tiling failure. */
int patchdl_fetch_manifest(const char *manifest_url, patchdl_manifest_t *out);
void patchdl_manifest_free(patchdl_manifest_t *m);
/* Live state shared with one in-flight piece download. The worker owns these;
the curl callbacks read `abort` (set elsewhere) and publish progress into
`bytes_slot` (single-writer per worker slot). */
typedef struct {
volatile long long *bytes_slot; /* bytes written so far for this piece */
volatile int *abort; /* non-zero -> stop this transfer */
} patchdl_piece_ctx_t;
/* Download one whole piece and pwrite it into `fd` at `file_offset`. Concurrent
non-overlapping pieces of the same fd are safe. Returns 0 on success (and
fdatasyncs fd), -1 on network/IO/abort, -2 on a SHA-256 mismatch.
`curl_rc_out`/`http_code_out` (either may be NULL) receive the last libcurl
CURLcode + HTTP status for failure diagnosis. */
int patchdl_http_download_piece(const char *url, int fd,
long long file_offset, long long file_size,
const char *expected_sha256_or_null,
patchdl_piece_ctx_t *ctx,
int *curl_rc_out, long *http_code_out);
/* Read-only: SHA-256 a [offset, offset+size) region of fd into out_hex
(caller provides >= 65 bytes). Returns 0 on success. */
int patchdl_sha256_fd_region(int fd, long long offset, long long size,
char *out_hex);
/* Progress callback. Return non-zero to ABORT the in-flight download (used to /* Progress callback. Return non-zero to ABORT the in-flight download (used to
cancel large patch downloads); return 0 to continue. */ cancel large patch downloads); return 0 to continue. */
typedef int (*patchdl_download_progress_cb)(void *ctx, typedef int (*patchdl_download_progress_cb)(void *ctx,
@@ -29,14 +91,17 @@ int patchdl_http_download_progress(const char *url, const char *dest_path,
/* Download a Sony JSON package manifest by concatenating every entry in /* Download a Sony JSON package manifest by concatenating every entry in
"pieces" into one installable PKG. When `verify` is non-zero each piece is "pieces" into one installable PKG. When `verify` is non-zero each piece is
checked against its manifest SHA-256 (a mismatch returns -2). */ checked against its manifest SHA-256 (a mismatch returns -2). When `resume`
is non-zero an existing partial at dest_path is kept: fully-downloaded pieces
are skipped and only the remainder is fetched (survives a reboot). On any
failure the partial is left in place for a later resume. */
int patchdl_http_download_manifest(const char *manifest_url, const char *dest_path, int patchdl_http_download_manifest(const char *manifest_url, const char *dest_path,
long long *bytes_out); long long *bytes_out);
int patchdl_http_download_manifest_progress(const char *manifest_url, int patchdl_http_download_manifest_progress(const char *manifest_url,
const char *dest_path, const char *dest_path,
long long *bytes_out, long long *bytes_out,
patchdl_download_progress_cb cb, patchdl_download_progress_cb cb,
void *ctx, int verify); void *ctx, int verify, int resume);
/* Diagnostic: run the GET pipeline for `url` and write a JSON report /* Diagnostic: run the GET pipeline for `url` and write a JSON report
(dns result/ip, curl code, http status, bytes) into `out_json`. */ (dns result/ip, curl code, http status, bytes) into `out_json`. */
+9
View File
@@ -1,3 +1,12 @@
/* SPDX-License-Identifier: GPL-3.0-or-later
* Copyright (C) 2026 Knutwurst
*
* PatchDL is free software: you can redistribute it and/or modify it under
* the terms of the GNU General Public License as published by the Free
* Software Foundation, either version 3 of the License, or (at your option)
* any later version. See the LICENSE file in the project root for details.
*/
#include "patchdl_notify.h" #include "patchdl_notify.h"
#include "patchdl_version.h" #include "patchdl_version.h"
+9
View File
@@ -1,3 +1,12 @@
/* SPDX-License-Identifier: GPL-3.0-or-later
* Copyright (C) 2026 Knutwurst
*
* PatchDL is free software: you can redistribute it and/or modify it under
* the terms of the GNU General Public License as published by the Free
* Software Foundation, either version 3 of the License, or (at your option)
* any later version. See the LICENSE file in the project root for details.
*/
#pragma once #pragma once
/* Send an on-screen PS5 notification at startup showing the web UI URL /* Send an on-screen PS5 notification at startup showing the web UI URL
+13 -1
View File
@@ -1,3 +1,12 @@
/* SPDX-License-Identifier: GPL-3.0-or-later
* Copyright (C) 2026 Knutwurst
*
* PatchDL is free software: you can redistribute it and/or modify it under
* the terms of the GNU General Public License as published by the Free
* Software Foundation, either version 3 of the License, or (at your option)
* any later version. See the LICENSE file in the project root for details.
*/
#include "patchdl_proc.h" #include "patchdl_proc.h"
#include <signal.h> #include <signal.h>
@@ -65,7 +74,10 @@ patchdl_proc_kill_others(const char *name) {
int killed = 0; int killed = 0;
pid_t pid; pid_t pid;
while ((pid = find_pid(name)) > 0) { /* Bound the loop: at startup we expect 0-1 stale instance. A pathological
proc table (or kill returning success but the process not exiting) would
otherwise stall startup for sleep(1) × N. */
while (killed < 8 && (pid = find_pid(name)) > 0) {
if (kill(pid, SIGKILL)) if (kill(pid, SIGKILL))
break; break;
killed++; killed++;
+9
View File
@@ -1,3 +1,12 @@
/* SPDX-License-Identifier: GPL-3.0-or-later
* Copyright (C) 2026 Knutwurst
*
* PatchDL is free software: you can redistribute it and/or modify it under
* the terms of the GNU General Public License as published by the Free
* Software Foundation, either version 3 of the License, or (at your option)
* any later version. See the LICENSE file in the project root for details.
*/
#pragma once #pragma once
/* Set this process's (main thread) name as shown in the PS5 process list. */ /* Set this process's (main thread) name as shown in the PS5 process list. */
+18 -14
View File
@@ -1,3 +1,12 @@
/* SPDX-License-Identifier: GPL-3.0-or-later
* Copyright (C) 2026 Knutwurst
*
* PatchDL is free software: you can redistribute it and/or modify it under
* the terms of the GNU General Public License as published by the Free
* Software Foundation, either version 3 of the License, or (at your option)
* any later version. See the LICENSE file in the project root for details.
*/
#include "patchdl_resolve.h" #include "patchdl_resolve.h"
#include <stdio.h> #include <stdio.h>
@@ -27,6 +36,14 @@ lookup_tsv(const char *title_id, char *url_out, size_t url_sz) {
fclose(fp); fclose(fp);
return -1; return -1;
} }
/* Defense in depth: the TSV file lives under /data/patchdl, writable
by anyone with /data access. patchdl_http_get also enforces
host_allowed, but rejecting non-https / non-Sony schemes here means
a poisoned line can't even reach the network layer. */
if (strncmp(url, "https://", 8) != 0) {
fclose(fp);
return -1;
}
memcpy(url_out, url, len + 1); memcpy(url_out, url, len + 1);
fclose(fp); fclose(fp);
return 0; return 0;
@@ -35,16 +52,6 @@ lookup_tsv(const char *title_id, char *url_out, size_t url_sz) {
return -1; return -1;
} }
static int
lookup_prosperopatches(const char *title_id, char *url_out, size_t url_sz) {
/* TODO: implement live lookup once API endpoint is confirmed on-device.
prosperopatches.com serves Sony CDN index links for PS5 titles. */
(void)title_id;
(void)url_out;
(void)url_sz;
return -1;
}
int int
patchdl_resolve_url(const char *title_id, char *url_out, size_t url_sz) { patchdl_resolve_url(const char *title_id, char *url_out, size_t url_sz) {
if (!title_id) return -1; if (!title_id) return -1;
@@ -57,8 +64,5 @@ patchdl_resolve_url(const char *title_id, char *url_out, size_t url_sz) {
strncmp(title_id, "PPSC", 4)) strncmp(title_id, "PPSC", 4))
return -1; return -1;
if (!lookup_tsv(title_id, url_out, url_sz)) return lookup_tsv(title_id, url_out, url_sz);
return 0;
return lookup_prosperopatches(title_id, url_out, url_sz);
} }
+9
View File
@@ -1,3 +1,12 @@
/* SPDX-License-Identifier: GPL-3.0-or-later
* Copyright (C) 2026 Knutwurst
*
* PatchDL is free software: you can redistribute it and/or modify it under
* the terms of the GNU General Public License as published by the Free
* Software Foundation, either version 3 of the License, or (at your option)
* any later version. See the LICENSE file in the project root for details.
*/
#pragma once #pragma once
#include <stddef.h> #include <stddef.h>
+23
View File
@@ -1,3 +1,12 @@
/* SPDX-License-Identifier: GPL-3.0-or-later
* Copyright (C) 2026 Knutwurst
*
* PatchDL is free software: you can redistribute it and/or modify it under
* the terms of the GNU General Public License as published by the Free
* Software Foundation, either version 3 of the License, or (at your option)
* any later version. See the LICENSE file in the project root for details.
*/
#include "patchdl_scan.h" #include "patchdl_scan.h"
#include "patchdl_appdb.h" #include "patchdl_appdb.h"
@@ -5,6 +14,7 @@
#include <dirent.h> #include <dirent.h>
#include <limits.h> #include <limits.h>
#include <stdatomic.h>
#include <stdint.h> #include <stdint.h>
#include <stdio.h> #include <stdio.h>
#include <stdlib.h> #include <stdlib.h>
@@ -389,6 +399,15 @@ merge_appdb(patchdl_title_t *arr, size_t cnt) {
patchdl_appdb_free(info); patchdl_appdb_free(info);
} }
/* See patchdl_scan_lock — both vnode-swap entry points return -1 / NULL once
this is set so a late rescan call can't race the running MHD threads. */
static _Atomic int g_scan_locked = 0;
void
patchdl_scan_lock(void) {
atomic_store(&g_scan_locked, 1);
}
int int
patchdl_scan(patchdl_title_t **titles_out, size_t *count_out) { patchdl_scan(patchdl_title_t **titles_out, size_t *count_out) {
patchdl_title_t *arr; patchdl_title_t *arr;
@@ -400,6 +419,8 @@ patchdl_scan(patchdl_title_t **titles_out, size_t *count_out) {
struct statfs *mounts = NULL; struct statfs *mounts = NULL;
int nmounts; int nmounts;
if (atomic_load(&g_scan_locked)) return -1;
arr = calloc(MAX_TITLES, sizeof(*arr)); arr = calloc(MAX_TITLES, sizeof(*arr));
if (!arr) return -1; if (!arr) return -1;
@@ -467,6 +488,8 @@ patchdl_scan_debug_json(void) {
char tmp[2048]; char tmp[2048];
pid_t pid = getpid(); pid_t pid = getpid();
intptr_t saved_root = 0, root_vnode; intptr_t saved_root = 0, root_vnode;
if (atomic_load(&g_scan_locked)) return NULL;
int using_vswap = 0; int using_vswap = 0;
struct statfs *mounts = NULL; struct statfs *mounts = NULL;
int nmounts; int nmounts;
+18
View File
@@ -1,3 +1,12 @@
/* SPDX-License-Identifier: GPL-3.0-or-later
* Copyright (C) 2026 Knutwurst
*
* PatchDL is free software: you can redistribute it and/or modify it under
* the terms of the GNU General Public License as published by the Free
* Software Foundation, either version 3 of the License, or (at your option)
* any later version. See the LICENSE file in the project root for details.
*/
#pragma once #pragma once
#include <stddef.h> #include <stddef.h>
@@ -24,10 +33,13 @@ typedef struct {
char latest_version[16]; char latest_version[16];
char latest_required_fw[16]; char latest_required_fw[16];
char patch_url[512]; /* manifest_url if present, otherwise pkg URL */ char patch_url[512]; /* manifest_url if present, otherwise pkg URL */
char delta_url[512]; /* DP.pkg bootstrap URL (always a PKG) */
char patch_title_id[16]; /* target title id from version.xml */ char patch_title_id[16]; /* target title id from version.xml */
char patch_storage_title_id[16]; /* title id embedded in delta_url */ char patch_storage_title_id[16]; /* title id embedded in delta_url */
int verxml_done; int verxml_done;
int enabled; /* user policy, persisted in config.json */ int enabled; /* user policy, persisted in config.json */
int resumable; /* a partial download is on disk */
long long partial_bytes; /* size of that partial, for the UI */
} patchdl_title_t; } patchdl_title_t;
int patchdl_scan(patchdl_title_t **titles_out, size_t *count_out); int patchdl_scan(patchdl_title_t **titles_out, size_t *count_out);
@@ -37,3 +49,9 @@ const char *patchdl_source_str(patchdl_source_t src);
/* Diagnostic: malloc'd JSON dump of the mount table + scan-base directory /* Diagnostic: malloc'd JSON dump of the mount table + scan-base directory
listings. Caller frees. */ listings. Caller frees. */
char *patchdl_scan_debug_json(void); char *patchdl_scan_debug_json(void);
/* Mark scan/debug as no longer safe to call (must be set after MHD worker
threads come up — patchdl_scan performs a process-wide vnode swap that
would race any concurrent thread). After this is set, both entry points
return immediately. Call once during startup, after MHD_start_daemon. */
void patchdl_scan_lock(void);
+214
View File
@@ -0,0 +1,214 @@
/* SPDX-License-Identifier: GPL-3.0-or-later
* Copyright (C) 2026 Knutwurst
*
* PatchDL is free software: you can redistribute it and/or modify it under
* the terms of the GNU General Public License as published by the Free
* Software Foundation, either version 3 of the License, or (at your option)
* any later version. See the LICENSE file in the project root for details.
*/
#include "patchdl_tile.h"
#include "patchdl_install.h"
#include <errno.h>
#include <fcntl.h>
#include <stddef.h>
#include <stdint.h>
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
#include <sys/stat.h>
#include <unistd.h>
#include <ps5/kernel.h>
/* Embed the tile assets into .rodata directly via .incbin — no codegen step,
no Python helper, no second translation unit. */
#define INCASSET(name, file) \
__asm__(".section .rodata\n" \
".global " #name "\n" \
".global " #name "_end\n" \
".global " #name "_size\n" \
".align 16\n" #name ":\n" \
".incbin \"" file "\"\n" #name "_end:\n" #name "_size:\n" \
".quad " #name "_end - " #name "\n" \
".previous\n"); \
extern const uint8_t name[]; \
extern const size_t name##_size;
INCASSET(tile_param_json, "assets/param.json");
INCASSET(tile_icon0_png, "assets/icon0.png");
#define TILE_TITLE_ID "PTDL00001"
/* Forward decls — we resolve sceAppInstUtilInitialize/AppInstallTitleDir at
runtime via the kernel dynlib helpers so the ELF stays loader-friendly. */
typedef int (*ai_init_fn)(void);
typedef int (*ai_install_dir_fn)(const char *title_id, const char *parent_dir,
void *opts);
static intptr_t
dynsym_by_name(const char *sym) {
uint32_t h = 0;
if (kernel_dynlib_handle(-1, "libSceAppInstUtil.sprx", &h) < 0) return 0;
return kernel_dynlib_dlsym(-1, h, sym);
}
static intptr_t
dynsym_by_nid(const char *nid) {
uint32_t h = 0;
if (kernel_dynlib_handle(-1, "libSceAppInstUtil.sprx", &h) < 0) return 0;
return kernel_dynlib_resolve(-1, h, nid);
}
static int
write_all(const char *path, const uint8_t *data, size_t size) {
int fd;
ssize_t w;
size_t off = 0;
/* O_NOFOLLOW + 0600: don't follow a symlink at the destination, and don't
create the file with the libc default 0666 mode. Same pattern as the
net layer's fopen_safe. */
fd = open(path, O_WRONLY | O_CREAT | O_TRUNC | O_NOFOLLOW | O_CLOEXEC, 0600);
if (fd < 0) return -1;
while (off < size) {
w = write(fd, data + off, size - off);
if (w < 0) {
if (errno == EINTR) continue;
close(fd);
return -1;
}
off += (size_t)w;
}
close(fd);
return 0;
}
static int
file_matches(const char *path, const uint8_t *expected, size_t expected_size) {
struct stat st;
uint8_t *buf;
int fd;
ssize_t n;
int match = 0;
if (stat(path, &st) != 0) return 0;
if ((size_t)st.st_size != expected_size) return 0;
fd = open(path, O_RDONLY | O_CLOEXEC);
if (fd < 0) return 0;
buf = malloc(expected_size);
if (!buf) { close(fd); return 0; }
n = read(fd, buf, expected_size);
close(fd);
if (n == (ssize_t)expected_size && memcmp(buf, expected, expected_size) == 0)
match = 1;
free(buf);
return match;
}
int
patchdl_tile_install_if_needed(char *msg, size_t msg_sz) {
char base_dir[128];
char sce_sys_dir[160];
char param_path[192];
char icon_path[192];
ai_init_fn ai_initialize = NULL;
ai_install_dir_fn ai_install_title = NULL;
int rc;
snprintf(base_dir, sizeof base_dir, "/user/app/%s", TILE_TITLE_ID);
snprintf(sce_sys_dir, sizeof sce_sys_dir, "/user/app/%s/sce_sys", TILE_TITLE_ID);
snprintf(param_path, sizeof param_path, "/user/app/%s/sce_sys/param.json", TILE_TITLE_ID);
snprintf(icon_path, sizeof icon_path, "/user/app/%s/sce_sys/icon0.png", TILE_TITLE_ID);
/* stat-guard: if everything on disk already matches, do nothing. Re-running
the install API every payload start would be wasted work and burns the
only safe path through Sony's installer state machine. */
{
struct stat st;
if (stat(base_dir, &st) == 0 &&
file_matches(param_path, tile_param_json, tile_param_json_size) &&
file_matches(icon_path, tile_icon0_png, tile_icon0_png_size)) {
snprintf(msg, msg_sz, "tile already installed and up to date");
return 0;
}
}
/* AppInstUtil is loaded lazily by the install backend thread. Poke it +
poll briefly so libSceAppInstUtil.sprx is mapped before we try to
resolve symbols out of it. Bounded to a few seconds so a stuck init
doesn't wedge an MHD worker forever. */
{
char ready_msg[128];
int ready = -1;
for (int i = 0; i < 60 && ready != 0; i++) {
ready = patchdl_install_backend_check(ready_msg, sizeof ready_msg);
if (ready != 0) usleep(250 * 1000);
}
if (ready != 0) {
snprintf(msg, msg_sz,
"install backend not ready: %s", ready_msg);
return -1;
}
}
/* Resolve the install API now so we can fail fast before touching disk.
The symbol export is Sony-private, so the NID resolver is the more
reliable lookup — try NID first, fall back to the by-name dlsym. */
ai_install_title = (ai_install_dir_fn)dynsym_by_nid("Wudg3Xe3heE");
if (!ai_install_title)
ai_install_title = (ai_install_dir_fn)dynsym_by_name(
"sceAppInstUtilAppInstallTitleDir");
if (!ai_install_title) {
snprintf(msg, msg_sz, "sceAppInstUtilAppInstallTitleDir not resolved");
return -1;
}
ai_initialize = (ai_init_fn)dynsym_by_name("sceAppInstUtilInitialize");
if (ai_initialize) {
rc = ai_initialize();
/* SCE_OK == 0; a non-zero rc here usually means "already initialised"
in this process, which is fine. We only bail on a clearly fatal
code (anything that isn't already the success case). */
if (rc != 0 && rc != 0x80B21161 /* ALREADY_INITIALIZED */) {
snprintf(msg, msg_sz,
"sceAppInstUtilInitialize failed 0x%08x", (unsigned)rc);
return -1;
}
}
if (mkdir(base_dir, 0755) && errno != EEXIST) {
snprintf(msg, msg_sz, "mkdir %s failed errno=%d", base_dir, errno);
return -1;
}
if (mkdir(sce_sys_dir, 0755) && errno != EEXIST) {
snprintf(msg, msg_sz, "mkdir %s failed errno=%d", sce_sys_dir, errno);
return -1;
}
if (write_all(param_path, tile_param_json, tile_param_json_size)) {
snprintf(msg, msg_sz, "write param.json failed errno=%d", errno);
return -1;
}
if (write_all(icon_path, tile_icon0_png, tile_icon0_png_size)) {
snprintf(msg, msg_sz, "write icon0.png failed errno=%d", errno);
return -1;
}
rc = ai_install_title(TILE_TITLE_ID, "/user/app/", NULL);
if (rc != 0) {
snprintf(msg, msg_sz,
"AppInstallTitleDir(%s) returned 0x%08x",
TILE_TITLE_ID, (unsigned)rc);
return -1;
}
snprintf(msg, msg_sz, "tile installed (%s)", TILE_TITLE_ID);
return 0;
}
+29
View File
@@ -0,0 +1,29 @@
/* SPDX-License-Identifier: GPL-3.0-or-later
* Copyright (C) 2026 Knutwurst
*
* PatchDL is free software: you can redistribute it and/or modify it under
* the terms of the GNU General Public License as published by the Free
* Software Foundation, either version 3 of the License, or (at your option)
* any later version. See the LICENSE file in the project root for details.
*/
#pragma once
#include <stddef.h>
/* Install / refresh the PatchDL home-screen tile.
*
* Writes param.json + icon0.png into /user/app/<TITLE_ID>/sce_sys/ and asks
* the on-console installer to register the directory as an app. The tile's
* deeplinkUri opens the on-console browser at http://127.0.0.1:12880/, i.e.
* PatchDL's own UI — only useful while the ELF is running.
*
* No package, no code signing — files only; the installer reads the
* directory directly.
*
* stat-guard: the asset bytes are diffed against the on-disk copy first;
* if nothing changed the install call isn't made at all (avoids a costly
* re-register every payload start). Returns 0 on success or when nothing
* needed doing.
*/
int patchdl_tile_install_if_needed(char *msg, size_t msg_sz);
+10 -1
View File
@@ -1,3 +1,12 @@
/* SPDX-License-Identifier: GPL-3.0-or-later
* Copyright (C) 2026 Knutwurst
*
* PatchDL is free software: you can redistribute it and/or modify it under
* the terms of the GNU General Public License as published by the Free
* Software Foundation, either version 3 of the License, or (at your option)
* any later version. See the LICENSE file in the project root for details.
*/
#pragma once #pragma once
#define PATCHDL_VERSION "0.0.2" #define PATCHDL_VERSION "0.0.6"
+26 -5
View File
@@ -1,3 +1,12 @@
/* SPDX-License-Identifier: GPL-3.0-or-later
* Copyright (C) 2026 Knutwurst
*
* PatchDL is free software: you can redistribute it and/or modify it under
* the terms of the GNU General Public License as published by the Free
* Software Foundation, either version 3 of the License, or (at your option)
* any later version. See the LICENSE file in the project root for details.
*/
#include "patchdl_verxml.h" #include "patchdl_verxml.h"
#include "patchdl_net.h" #include "patchdl_net.h"
@@ -66,14 +75,20 @@ ver_gt(const char *a, const char *b) {
from a string such as nptitleid, manifest_url, or delta_url. */ from a string such as nptitleid, manifest_url, or delta_url. */
static void static void
extract_title_id(const char *s, char *out, size_t sz) { extract_title_id(const char *s, char *out, size_t sz) {
size_t len;
out[0] = '\0'; out[0] = '\0';
if (sz < 10 || !s) return; if (sz < 10 || !s) return;
for (const char *p = s; p[0] && p[8]; p++) { len = strlen(s);
if (len < 9) return;
/* `len - 9` is the last position where a 9-char id can still fit; this
avoids reading p[8] past the NUL terminator. */
for (size_t i = 0; i <= len - 9; i++) {
const char *p = s + i;
int ok = 1; int ok = 1;
for (int i = 0; i < 4 && ok; i++) for (int k = 0; k < 4 && ok; k++)
if (p[i] < 'A' || p[i] > 'Z') ok = 0; if (p[k] < 'A' || p[k] > 'Z') ok = 0;
for (int i = 4; i < 9 && ok; i++) for (int k = 4; k < 9 && ok; k++)
if (p[i] < '0' || p[i] > '9') ok = 0; if (p[k] < '0' || p[k] > '9') ok = 0;
if (ok) { if (ok) {
memcpy(out, p, 9); memcpy(out, p, 9);
out[9] = '\0'; out[9] = '\0';
@@ -148,6 +163,8 @@ parse_packages(const char *xml, uint32_t fw_bin, patchdl_verinfo_t *out) {
sizeof(out->compatible_version) - 1); sizeof(out->compatible_version) - 1);
strncpy(out->compatible_url, murl[0] ? murl : durl, strncpy(out->compatible_url, murl[0] ? murl : durl,
sizeof(out->compatible_url) - 1); sizeof(out->compatible_url) - 1);
if (durl[0])
strncpy(out->delta_url, durl, sizeof(out->delta_url) - 1);
extract_title_id(durl, out->compatible_storage_title, extract_title_id(durl, out->compatible_storage_title,
sizeof(out->compatible_storage_title)); sizeof(out->compatible_storage_title));
if (root_title[0]) { if (root_title[0]) {
@@ -175,6 +192,10 @@ patchdl_verxml_query(const char *url, uint32_t fw_bin, patchdl_verinfo_t *out) {
if (!url || !out) return -1; if (!url || !out) return -1;
memset(out, 0, sizeof(*out)); memset(out, 0, sizeof(*out));
/* version.xml is a few KB in practice; cap so a misbehaving CDN can't
slurp unbounded RAM into the buffer. */
memset(&buf, 0, sizeof(buf));
buf.max = 4 * 1024 * 1024;
if (patchdl_http_get(url, &buf)) return -1; if (patchdl_http_get(url, &buf)) return -1;
if (!buf.data || !buf.size) { free(buf.data); return -1; } if (!buf.data || !buf.size) { free(buf.data); return -1; }
+10
View File
@@ -1,3 +1,12 @@
/* SPDX-License-Identifier: GPL-3.0-or-later
* Copyright (C) 2026 Knutwurst
*
* PatchDL is free software: you can redistribute it and/or modify it under
* the terms of the GNU General Public License as published by the Free
* Software Foundation, either version 3 of the License, or (at your option)
* any later version. See the LICENSE file in the project root for details.
*/
#pragma once #pragma once
#include <stdint.h> #include <stdint.h>
@@ -7,6 +16,7 @@ typedef struct {
char latest_version[16]; /* highest pkg overall, or "" */ char latest_version[16]; /* highest pkg overall, or "" */
char latest_required_fw[16]; /* fw str for latest pkg, e.g. "11.60", or "" */ char latest_required_fw[16]; /* fw str for latest pkg, e.g. "11.60", or "" */
char compatible_url[512]; /* manifest_url if present, otherwise pkg URL */ char compatible_url[512]; /* manifest_url if present, otherwise pkg URL */
char delta_url[512]; /* DP.pkg bootstrap URL (always a PKG, never JSON) */
char compatible_title[16]; /* target title id from version.xml/manifest_url */ char compatible_title[16]; /* target title id from version.xml/manifest_url */
char compatible_storage_title[16]; /* title id embedded in delta_url storage path */ char compatible_storage_title[16]; /* title id embedded in delta_url storage path */
} patchdl_verinfo_t; } patchdl_verinfo_t;
+1345 -170
View File
File diff suppressed because it is too large. Load diff
+9
View File
@@ -1,3 +1,12 @@
/* SPDX-License-Identifier: GPL-3.0-or-later
* Copyright (C) 2026 Knutwurst
*
* PatchDL is free software: you can redistribute it and/or modify it under
* the terms of the GNU General Public License as published by the Free
* Software Foundation, either version 3 of the License, or (at your option)
* any later version. See the LICENSE file in the project root for details.
*/
#pragma once #pragma once
int patchdl_websrv_start(unsigned short port); int patchdl_websrv_start(unsigned short port);
+8
View File
@@ -16,6 +16,9 @@ GET /api/config
POST /api/config POST /api/config
GET /api/titles GET /api/titles
GET /api/downloads GET /api/downloads
GET /api/installstatus
GET /api/pkgmeta/:title_id
GET /api/pkgverify/:title_id
POST /api/titles/:title_id/check POST /api/titles/:title_id/check
POST /api/titles/:title_id/download POST /api/titles/:title_id/download
POST /api/titles/:title_id/install POST /api/titles/:title_id/install
@@ -88,3 +91,8 @@ For PS5 game updates, the backend may turn a Sony `manifest_url` into a merged
local `.pkg` by downloading all manifest pieces. The `delta_url` `*-DP.pkg` is local `.pkg` by downloading all manifest pieces. The `delta_url` `*-DP.pkg` is
not shown as a separate user action because it can bootstrap the storage/master not shown as a separate user action because it can bootstrap the storage/master
title instead of the installed regional target. title instead of the installed regional target.
If `patch_storage_match` is false, the UI keeps download/verify available but
does not offer install or auto-install. Those shared-master packages are signed
for a different storage title id and cannot be retargeted by standalone
AppInstUtil on firmware 11.60.
+406 -90
View File
@@ -3,6 +3,7 @@ const API = {
titles: "/api/titles", titles: "/api/titles",
config: "/api/config", config: "/api/config",
downloads: "/api/downloads", downloads: "/api/downloads",
installStatus: "/api/installstatus",
action: (titleId, action) => `/api/titles/${encodeURIComponent(titleId)}/${action}`, action: (titleId, action) => `/api/titles/${encodeURIComponent(titleId)}/${action}`,
}; };
@@ -29,6 +30,7 @@ const fallback = {
delete_pkg_after_install: true, delete_pkg_after_install: true,
verify_downloads: false, verify_downloads: false,
home_shortcut: true, home_shortcut: true,
max_connections: 4,
source_policy: { source_policy: {
official: { allow_check: true, allow_download: true, allow_install: true }, official: { allow_check: true, allow_download: true, allow_install: true },
external: { allow_check: true, allow_download: true, allow_install: true }, external: { allow_check: true, allow_download: true, allow_install: true },
@@ -48,6 +50,7 @@ const fallback = {
installed_version: "01.032.000", compatible_version: "01.041.000", installed_version: "01.032.000", compatible_version: "01.041.000",
latest_version: "01.041.000", latest_required_fw: "11.60", latest_version: "01.041.000", latest_required_fw: "11.60",
source_type: "official", source_path: "/system_ex/app/PPSA01628_00", source_type: "official", source_path: "/system_ex/app/PPSA01628_00",
patch_storage_match: true,
mount_from: "/dev/ssd0.system_ex", enabled: true, status: "available", mount_from: "/dev/ssd0.system_ex", enabled: true, status: "available",
}, },
{ {
@@ -56,6 +59,7 @@ const fallback = {
installed_version: "01.004.000", compatible_version: "01.004.000", installed_version: "01.004.000", compatible_version: "01.004.000",
latest_version: "01.004.000", latest_required_fw: "10.01", latest_version: "01.004.000", latest_required_fw: "10.01",
source_type: "external", source_path: "/system_data/priv/appmeta/external/PPSA01284_00", source_type: "external", source_path: "/system_data/priv/appmeta/external/PPSA01284_00",
patch_storage_match: true,
mount_from: "/mnt/ext0/user/app/PPSA01284_00", enabled: true, status: "up_to_date", mount_from: "/mnt/ext0/user/app/PPSA01284_00", enabled: true, status: "up_to_date",
}, },
{ {
@@ -64,6 +68,7 @@ const fallback = {
installed_version: "01.000.000", compatible_version: "01.006.000", installed_version: "01.000.000", compatible_version: "01.006.000",
latest_version: "01.009.000", latest_required_fw: "12.00", latest_version: "01.009.000", latest_required_fw: "12.00",
source_type: "shadowmount", source_path: "/system_ex/app/PPSA90001_00", source_type: "shadowmount", source_path: "/system_ex/app/PPSA90001_00",
patch_storage_match: true,
mount_from: "/mnt/usb0/itemzflow/Shadowmounted Test Title", enabled: true, status: "available", mount_from: "/mnt/usb0/itemzflow/Shadowmounted Test Title", enabled: true, status: "available",
}, },
], ],
@@ -78,12 +83,13 @@ let state = {
downloads: fallback.downloads, downloads: fallback.downloads,
logs: fallback.logs, logs: fallback.logs,
view: "games", view: "games",
filter: "all", filter: "updatable",
query: "", query: "",
usingFallback: false, usingFallback: false,
}; };
let downloadPollTimer = null; let downloadPollTimer = null;
let installPollTimer = null;
let emptyPolls = 0; let emptyPolls = 0;
const dlMeta = {}; // per-title speed tracking: { bytes, t, speed } const dlMeta = {}; // per-title speed tracking: { bytes, t, speed }
@@ -116,7 +122,20 @@ function bindElements() {
deleteAfterInstall: document.getElementById("deleteAfterInstall"), deleteAfterInstall: document.getElementById("deleteAfterInstall"),
verifyDownloads: document.getElementById("verifyDownloads"), verifyDownloads: document.getElementById("verifyDownloads"),
homeShortcut: document.getElementById("homeShortcut"), homeShortcut: document.getElementById("homeShortcut"),
connValue: document.getElementById("connValue"),
connMinus: document.getElementById("connMinus"),
connPlus: document.getElementById("connPlus"),
refreshBtn: document.getElementById("refreshBtn"), refreshBtn: document.getElementById("refreshBtn"),
updateAllBtn: document.getElementById("updateAllBtn"),
brandVersion: document.getElementById("brandVersion"),
globalDl: document.getElementById("globalDl"),
globalDlState: document.getElementById("globalDlState"),
globalDlName: document.getElementById("globalDlName"),
globalDlPosition: document.getElementById("globalDlPosition"),
globalDlPct: document.getElementById("globalDlPct"),
globalDlSpeed: document.getElementById("globalDlSpeed"),
globalDlEta: document.getElementById("globalDlEta"),
globalDlBar: document.getElementById("globalDlBar"),
saveBtn: document.getElementById("saveBtn"), saveBtn: document.getElementById("saveBtn"),
clearLogBtn: document.getElementById("clearLogBtn"), clearLogBtn: document.getElementById("clearLogBtn"),
toast: document.getElementById("toast"), toast: document.getElementById("toast"),
@@ -146,8 +165,13 @@ function bindEvents() {
}); });
els.refreshBtn.addEventListener("click", loadInitialData); els.refreshBtn.addEventListener("click", loadInitialData);
if (els.updateAllBtn) els.updateAllBtn.addEventListener("click", updateAll);
els.saveBtn.addEventListener("click", saveConfig); els.saveBtn.addEventListener("click", saveConfig);
els.clearLogBtn.addEventListener("click", () => { state.logs = []; renderLogs(); }); els.clearLogBtn.addEventListener("click", () => { state.logs = []; renderLogs(); });
if (els.connMinus)
els.connMinus.addEventListener("click", () => setConnections(clampConn(state.config.max_connections) - 1));
if (els.connPlus)
els.connPlus.addEventListener("click", () => setConnections(clampConn(state.config.max_connections) + 1));
} }
function setView(view) { function setView(view) {
@@ -173,27 +197,27 @@ async function loadInitialData() {
// /api/titles carries no client-only progress flags, so preserve them across a // /api/titles carries no client-only progress flags, so preserve them across a
// refresh — otherwise an in-flight download/install flips back to a clickable // refresh — otherwise an in-flight download/install flips back to a clickable
// button mid-operation. // button mid-operation.
// Carry client-only flags across a refresh; the pool's job list is the source
// of truth for download state and is reconciled right after.
const prev = new Map(state.titles.map((g) => [g.title_id, g])); const prev = new Map(state.titles.map((g) => [g.title_id, g]));
titles.forEach((g) => { titles.forEach((g) => {
const old = prev.get(g.title_id); const old = prev.get(g.title_id);
// Carry client-only progress flags across a refresh — unless the server now
// reports the title up to date (the patch applied), in which case drop them.
if (old && g.status !== "up_to_date") { if (old && g.status !== "up_to_date") {
if (old.downloading) g.downloading = true;
if (old.downloaded) g.downloaded = true; if (old.downloaded) g.downloaded = true;
if (old.installing) g.installing = true; if (old.installing) g.installing = true;
if (old._autoInstalled) g._autoInstalled = true;
if (old._localDownloading) g._localDownloading = true; if (old._localDownloading) g._localDownloading = true;
} }
}); });
// Reconcile active downloads the server reports, so progress + Cancel show even
// after a hard reload or a download started from another session/device.
const activeDl = new Set(downloads.map((d) => d.title_id));
titles.forEach((g) => { if (activeDl.has(g.title_id)) g.downloading = true; });
state = { ...state, status, config, titles, downloads }; state = { ...state, status, config, titles, downloads };
reconcileFromJobs(downloads);
render(); render();
if (state.downloads.length) startDownloadPolling(); if (downloads.some((j) => j.state === "active" || j.state === "queued") ||
state.titles.some((g) => g._localDownloading))
startDownloadPolling();
if (state.titles.some((g) => g.installing)) startInstallPolling();
showToast(state.usingFallback ? "Demo data loaded. API is not reachable yet." : "Data refreshed."); showToast(state.usingFallback ? "Demo data loaded. API is not reachable yet." : "Data refreshed.");
} }
@@ -225,6 +249,42 @@ function renderStatus() {
els.downloadDirValue.textContent = state.status.download_dir || state.config.download_dir || "Download target"; els.downloadDirValue.textContent = state.status.download_dir || state.config.download_dir || "Download target";
if (els.railFw) els.railFw.textContent = `FW ${state.status.firmware || "--"}`; if (els.railFw) els.railFw.textContent = `FW ${state.status.firmware || "--"}`;
if (els.railSpace) els.railSpace.textContent = `${space} free`; if (els.railSpace) els.railSpace.textContent = `${space} free`;
if (els.brandVersion)
els.brandVersion.textContent = state.status.version ? `v${state.status.version}` : "v--";
}
const CONN_MIN = 1, CONN_MAX = 16;
function clampConn(n) {
n = parseInt(n, 10);
if (!Number.isFinite(n)) n = 4;
return Math.max(CONN_MIN, Math.min(CONN_MAX, n));
}
function renderConnStepper() {
const n = clampConn(state.config.max_connections);
if (els.connValue) els.connValue.textContent = String(n);
if (els.connMinus) els.connMinus.disabled = n <= CONN_MIN;
if (els.connPlus) els.connPlus.disabled = n >= CONN_MAX;
}
let connSaveTimer = null;
// Stepper +/-: update + re-render immediately, then persist just this field
// (debounced) so rapid taps collapse into one POST and other unsaved form
// fields stay untouched. The server applies the new count live (no restart).
function setConnections(n) {
const v = clampConn(n);
if (v === clampConn(state.config.max_connections)) { renderConnStepper(); return; }
state.config.max_connections = v;
renderConnStepper();
clearTimeout(connSaveTimer);
connSaveTimer = setTimeout(async () => {
try {
await postJson(API.config, { max_connections: v });
showToast(`Parallel connections: ${v}`);
} catch (e) {
showToast("Could not save connections — API not reachable.");
}
}, 450);
} }
function renderSettings() { function renderSettings() {
@@ -234,6 +294,7 @@ function renderSettings() {
els.deleteAfterInstall.checked = Boolean(state.config.delete_pkg_after_install); els.deleteAfterInstall.checked = Boolean(state.config.delete_pkg_after_install);
if (els.verifyDownloads) els.verifyDownloads.checked = Boolean(state.config.verify_downloads); if (els.verifyDownloads) els.verifyDownloads.checked = Boolean(state.config.verify_downloads);
if (els.homeShortcut) els.homeShortcut.checked = state.config.home_shortcut !== false; if (els.homeShortcut) els.homeShortcut.checked = state.config.home_shortcut !== false;
renderConnStepper();
els.allowlistHosts.replaceChildren(...(state.config.cdn_allowlist || []).map((host) => { els.allowlistHosts.replaceChildren(...(state.config.cdn_allowlist || []).map((host) => {
const chip = document.createElement("span"); const chip = document.createElement("span");
chip.className = "host-chip"; chip.className = "host-chip";
@@ -246,6 +307,7 @@ function renderSettings() {
/* ---------------- games ---------------- */ /* ---------------- games ---------------- */
function renderGames() { function renderGames() {
renderGlobalStatus();
const visible = state.titles.filter(matchesFilter).filter(matchesQuery); const visible = state.titles.filter(matchesFilter).filter(matchesQuery);
els.gameGrid.replaceChildren(); els.gameGrid.replaceChildren();
@@ -261,12 +323,17 @@ function renderGames() {
// Mutually-exclusive bucket per game for the filter chips. // Mutually-exclusive bucket per game for the filter chips.
function gameCategory(game) { function gameCategory(game) {
// Updating is the queue — jobs waiting for a pool slot. An actively
// downloading game stays under Updatable so you don't lose sight of it
// while drilling into the queue; same for paused (the user knows where
// it is and can resume from the card) and installing.
if (game._jobState === "queued") return "updating";
// checking is transient (version lookup still running); keep it visible under // checking is transient (version lookup still running); keep it visible under
// Updatable rather than letting it fall out of every specific filter. // Updatable rather than letting it fall out of every specific filter.
if (game.installing || game.downloading || game.status === "checking") return "updatable"; if (game.status === "checking") return "updatable";
if (game.patch_title_match === false) return "blocked"; if (game.patch_title_match === false) return "blocked";
if (!sourcePolicy(game).allow_install) return "blocked"; if (game.status === "available" && isDownloadAllowed(game)) return "updatable";
if (game.status === "available") return "updatable"; if (!sourcePolicy(game).allow_install && !sourcePolicy(game).allow_download) return "blocked";
if (game.status === "incompatible_fw") return "needsfw"; if (game.status === "incompatible_fw") return "needsfw";
return "uptodate"; return "uptodate";
} }
@@ -311,8 +378,11 @@ function createGameCard(game) {
<span>${escapeHtml(game.content_id || "")}</span> <span>${escapeHtml(game.content_id || "")}</span>
</div> </div>
<div class="pills"> <div class="pills">
${game.downloading ? `<span class="pill live">Downloading</span>` : ""} ${game.downloading && game._jobState === "queued" ? `<span class="pill">Queued</span>` : ""}
${game.downloading && game._jobState !== "queued" ? `<span class="pill live">Downloading</span>` : ""}
${game.resumable && !game.downloading ? `<span class="pill warn">Paused</span>` : ""}
${statusPill(game)} ${statusPill(game)}
${storagePill(game)}
${sourcePill(game)} ${sourcePill(game)}
</div> </div>
<div class="versions"> <div class="versions">
@@ -324,8 +394,8 @@ function createGameCard(game) {
const actions = document.createElement("div"); const actions = document.createElement("div");
actions.className = "card-actions"; actions.className = "card-actions";
const act = tileButton(game); [primaryButton(game), stopButton(game)].forEach((act) => {
if (act) { if (!act) return;
const btn = document.createElement("button"); const btn = document.createElement("button");
btn.className = `row-button is-${act.variant}`; btn.className = `row-button is-${act.variant}`;
btn.textContent = act.label; btn.textContent = act.label;
@@ -333,16 +403,7 @@ function createGameCard(game) {
if (act.disabled) btn.disabled = true; if (act.disabled) btn.disabled = true;
else btn.addEventListener("click", () => runTitleAction(game.title_id, act.action)); else btn.addEventListener("click", () => runTitleAction(game.title_id, act.action));
actions.appendChild(btn); actions.appendChild(btn);
} });
// Delete a finished (not-yet-installed) download.
if (game.downloaded && !game.installing && !game.downloading) {
const del = document.createElement("button");
del.className = "row-button is-ghost";
del.textContent = "Delete";
del.title = "Delete the downloaded package";
del.addEventListener("click", () => cancelDownload(game.title_id));
actions.appendChild(del);
}
row.append(lead, body, actions); row.append(lead, body, actions);
card.appendChild(row); card.appendChild(row);
@@ -357,6 +418,26 @@ function createGameCard(game) {
<div class="progress-meta">${progressMetaHtml(d)}</div> <div class="progress-meta">${progressMetaHtml(d)}</div>
`; `;
card.appendChild(prog); card.appendChild(prog);
} else if (game.installing) {
const pct = Math.max(0, Math.min(100, Number(game.installProgress) || 0));
const note = document.createElement("div");
note.className = "card-progress";
note.innerHTML = `
<div class="progress"><i style="width:${pct}%"></i></div>
<div class="progress-meta">${installProgressHtml(game)}</div>
`;
card.appendChild(note);
} else if (game.resumable && game.partial_bytes > 0) {
// ---- paused partial (survived a reboot) ----
const note = document.createElement("div");
note.className = "card-progress";
note.innerHTML = `
<div class="progress-meta">
<span>Paused — <b>${formatBytes(game.partial_bytes)}</b> downloaded</span>
<span>Resume to continue</span>
</div>
`;
card.appendChild(note);
} }
return card; return card;
@@ -382,21 +463,33 @@ function buildToggle(game) {
return toggle; return toggle;
} }
// The single morphing action button: blue Update/Download/Install, or amber // Primary play/pause button (green to go, amber while downloading). Fixed width
// Cancel while a download runs. Fixed width (CSS) so the label never reflows. // (CSS) so the label never reflows. Returns null when there is nothing to do.
function tileButton(game) { function primaryButton(game) {
if (game.installing) return { label: "Installing…", variant: "ghost", disabled: true }; if (game.installing) return { label: "Installing…", variant: "ghost", disabled: true };
if (game.downloading) return { label: "Cancel", action: "cancel", variant: "cancel", hint: "Stop the download and delete the partial file" }; if (game.downloading) return { label: "Pause", action: "pause", variant: "pause", hint: "Pause the download (keeps what was downloaded)." };
if (game.patch_title_match === false) return null; if (game.patch_title_match === false) return null;
if (!isInstallAllowed(game)) return null; if (game.resumable && isDownloadAllowed(game))
if (game.downloaded && game.status === "available") return { label: "Resume", action: "download", variant: "update", hint: "Continue the paused download where it stopped." };
if (game.downloaded && game.status === "available" && isInstallAllowed(game))
return { label: "Install", action: "install", variant: "update", hint: "Install the downloaded patch (modifies the game)." }; return { label: "Install", action: "install", variant: "update", hint: "Install the downloaded patch (modifies the game)." };
if (game.downloaded && game.status === "available") return null;
if (game.status !== "available") return null; if (game.status !== "available") return null;
return state.config.install_after_download if (!isDownloadAllowed(game)) return null;
return state.config.install_after_download && isInstallAllowed(game)
? { label: "Update", action: "update", variant: "update", hint: "Download and install the update." } ? { label: "Update", action: "update", variant: "update", hint: "Download and install the update." }
: { label: "Download", action: "download", variant: "update", hint: "Download the patch internally." }; : { label: "Download", action: "download", variant: "update", hint: "Download the patch internally." };
} }
// Red stop button: present whenever there is a download to stop or discard.
// Cancel stops AND deletes (unlike Pause, which keeps the partial).
function stopButton(game) {
if (game.installing) return null;
if (game.downloading || game.resumable || game.downloaded)
return { label: "Cancel", action: "cancel", variant: "cancel", hint: "Stop and delete the download." };
return null;
}
function statusPill(game) { function statusPill(game) {
if (game.installing) return `<span class="pill warn">Installing…</span>`; if (game.installing) return `<span class="pill warn">Installing…</span>`;
if (game.status === "checking") return `<span class="pill">Checking…</span>`; if (game.status === "checking") return `<span class="pill">Checking…</span>`;
@@ -407,6 +500,10 @@ function statusPill(game) {
return `<span class="pill">No patch info</span>`; return `<span class="pill">No patch info</span>`;
} }
function storagePill(game) {
return hasSharedStorage(game) ? `<span class="pill warn">Shared master</span>` : "";
}
function sourcePill(game) { function sourcePill(game) {
const info = sourceInfo(game); const info = sourceInfo(game);
return `<span class="pill ${info.className}">${escapeHtml(info.label)}</span>`; return `<span class="pill ${info.className}">${escapeHtml(info.label)}</span>`;
@@ -427,6 +524,7 @@ function progressMetaHtml(d) {
const done = Number(d.bytes) || 0; const done = Number(d.bytes) || 0;
const total = Number(d.total_bytes) || 0; const total = Number(d.total_bytes) || 0;
const speed = Number(d._speed) || 0; const speed = Number(d._speed) || 0;
if (d.state === "queued") return `<span>Queued — waiting for a free slot</span>`;
const parts = []; const parts = [];
parts.push(`<span><b>${formatBytes(done)}</b>${total > 0 ? ` / ${formatBytes(total)}` : ""}</span>`); parts.push(`<span><b>${formatBytes(done)}</b>${total > 0 ? ` / ${formatBytes(total)}` : ""}</span>`);
if (speed > 0) parts.push(`<span><b>${formatBytes(speed)}/s</b></span>`); if (speed > 0) parts.push(`<span><b>${formatBytes(speed)}/s</b></span>`);
@@ -436,6 +534,16 @@ function progressMetaHtml(d) {
return parts.join(""); return parts.join("");
} }
function installProgressHtml(game) {
const status = game.installStatus || "waiting";
const done = Number(game.installDone) || 0;
const total = Number(game.installTotal) || 0;
const parts = [`<span>Status <b>${escapeHtml(status)}</b></span>`];
if (total > 0) parts.push(`<span><b>${formatBytes(done)}</b> / ${formatBytes(total)}</span>`);
parts.push(`<span><b>${Math.max(0, Math.min(100, Number(game.installProgress) || 0))}%</b></span>`);
return parts.join("");
}
function startDownloadPolling() { function startDownloadPolling() {
emptyPolls = 0; emptyPolls = 0;
if (downloadPollTimer) return; if (downloadPollTimer) return;
@@ -449,65 +557,218 @@ function stopDownloadPolling() {
downloadPollTimer = null; downloadPollTimer = null;
} }
// Map the pool's job list onto per-title flags, and auto-install once a job
// finishes if "install after download" is on.
function reconcileFromJobs(jobs) {
const byId = new Map((jobs || []).map((j) => [j.title_id, j]));
state.titles.forEach((g) => {
const j = byId.get(g.title_id);
if (!j) {
// The pool never produced a job for our local intent: time it out so the
// card can't wedge in "Downloading" forever (server restart between POST
// and poll, or an unexpected response shape).
if (g._localDownloading && g._localSince &&
Date.now() - g._localSince > 12000) {
g._localDownloading = false;
}
if (g.downloading && !g._localDownloading) g.downloading = false;
g._jobState = null;
return;
}
g._localDownloading = false; // the pool now tracks it
g._jobState = j.state;
if (j.state === "active" || j.state === "queued") {
g.downloading = true;
g.resumable = false;
g._wasActive = true;
} else if (j.state === "paused") {
g.downloading = false;
g.resumable = true;
g.partial_bytes = Number(j.bytes) || g.partial_bytes || 0;
g._wasActive = false;
} else if (j.state === "done") {
g.downloading = false;
g.resumable = false;
g.downloaded = true;
g._wasActive = false;
if (state.config.install_after_download && isInstallAllowed(g) &&
!g.installing && !g._autoInstalled) {
g._autoInstalled = true;
doInstall(g);
}
} else if (j.state === "error") {
// The server keeps the partial + sidecar (resumable) on a post-retry
// network failure. Reflect that so primaryButton shows "Resume" and the
// red Cancel stays available to delete the kept partial.
const bytes = Number(j.bytes) || 0;
if (g._wasActive) {
showToast(`${g.name}: download failed${bytes > 0 ? " — partial kept, press Resume to continue" : "."}`);
}
g._wasActive = false;
g.downloading = false;
g.resumable = bytes > 0;
g.partial_bytes = bytes || g.partial_bytes || 0;
}
});
}
function startInstallPolling() {
if (installPollTimer) return;
installPollTimer = setInterval(refreshInstallStatus, 2000);
refreshInstallStatus();
}
function stopInstallPolling() {
if (!installPollTimer) return;
clearInterval(installPollTimer);
installPollTimer = null;
}
async function refreshInstallStatus() {
let s;
try {
const response = await fetch(API.installStatus, { cache: "no-store" });
if (!response.ok) throw new Error(`HTTP ${response.status}`);
s = await response.json();
} catch (error) {
return;
}
if (!s || !s.active) {
if (!state.titles.some((g) => g.installing)) stopInstallPolling();
return;
}
const titleId = s.target_title_id || "";
const game = state.titles.find((g) => g.title_id === titleId || g.title_id.slice(0, 9) === titleId.slice(0, 9));
if (!game) return;
game.installing = !s.terminal;
game.installStatus = s.status || "running";
game.installProgress = Number(s.progress) || 0;
game.installDone = Number(s.downloaded_size) || 0;
game.installTotal = Number(s.total_size) || 0;
renderGames();
if (s.terminal) {
const ok = s.status === "playable";
state.logs.push(`[${timeNow()}] Install ${ok ? "completed" : "stopped"} for ${game.title_id}: ${s.status || "unknown"}${s.error_code ? ` (0x${Number(s.error_code >>> 0).toString(16)})` : ""}`);
renderLogs();
stopInstallPolling();
if (ok) loadInitialData();
}
}
async function refreshDownloads() { async function refreshDownloads() {
let downloads; let jobs;
try { try {
const response = await fetch(API.downloads, { cache: "no-store" }); const response = await fetch(API.downloads, { cache: "no-store" });
if (!response.ok) throw new Error(`HTTP ${response.status}`); if (!response.ok) throw new Error(`HTTP ${response.status}`);
downloads = await response.json(); jobs = await response.json();
} catch (error) { } catch (error) {
return; // keep last state on a transient failure return; // keep last state on a transient failure
} }
const now = Date.now(); const now = Date.now();
const activeIds = new Set(); const ids = new Set();
downloads.forEach((d) => { jobs.forEach((j) => {
activeIds.add(d.title_id); ids.add(j.title_id);
const done = Number(d.bytes) || 0; const done = Number(j.bytes) || 0;
const prev = dlMeta[d.title_id]; const prev = dlMeta[j.title_id];
if (prev && now > prev.t) { if (prev && now > prev.t) {
if (done >= prev.bytes) { if (done >= prev.bytes) {
const inst = ((done - prev.bytes) * 1000) / (now - prev.t); // bytes/s const inst = ((done - prev.bytes) * 1000) / (now - prev.t); // bytes/s
prev.speed = prev.speed ? prev.speed * 0.5 + inst * 0.5 : inst; // smoothed prev.speed = prev.speed ? prev.speed * 0.5 + inst * 0.5 : inst; // smoothed
} else { } else {
prev.speed = 0; // counter went backwards -> re-baseline, no stale speed prev.speed = 0; // counter went backwards -> re-baseline
} }
} }
const meta = prev || (dlMeta[d.title_id] = { speed: 0 }); const meta = prev || (dlMeta[j.title_id] = { speed: 0 });
meta.bytes = done; meta.bytes = done;
meta.t = now; meta.t = now;
d._speed = meta.speed || 0; j._speed = meta.speed || 0;
}); });
Object.keys(dlMeta).forEach((id) => { if (!activeIds.has(id)) delete dlMeta[id]; }); Object.keys(dlMeta).forEach((id) => { if (!ids.has(id)) delete dlMeta[id]; });
state.downloads = downloads; state.downloads = jobs;
// Reconcile downloading flags with the server. A structural change (a download
// appeared or finished) needs a full re-render to add/remove the progress block
// and morph the button; otherwise update the bar in place.
const before = downloadingIds(); const before = downloadingIds();
state.titles.forEach((g) => { reconcileFromJobs(jobs);
if (activeIds.has(g.title_id)) g.downloading = true;
else if (g.downloading && !g._localDownloading) g.downloading = false;
});
if (downloadingIds() !== before) renderGames(); if (downloadingIds() !== before) renderGames();
else applyDownloadProgress(); else applyDownloadProgress();
if (!downloads.length && !state.titles.some((g) => g.downloading)) { const busy = jobs.some((j) => j.state === "active" || j.state === "queued") ||
if (++emptyPolls >= 3) stopDownloadPolling(); state.titles.some((g) => g._localDownloading);
} else { if (!busy) { if (++emptyPolls >= 3) stopDownloadPolling(); }
emptyPolls = 0; else emptyPolls = 0;
}
} }
function downloadingIds() { function downloadingIds() {
return state.titles.filter((g) => g.downloading).map((g) => g.title_id).join(","); return state.titles.filter((g) => g.downloading).map((g) => g.title_id).join(",");
} }
// Top-of-page status banner. Visible while any job in this batch is queued,
// active, or has just finished (done jobs linger one or two polls before the
// pool reaps them, which is what gives us the "5 of 9" position).
function renderGlobalStatus() {
const el = els.globalDl;
if (!el) return;
const jobs = state.downloads || [];
const batch = jobs.filter((j) => ["queued", "active", "done"].includes(j.state));
const flying = batch.filter((j) => j.state === "queued" || j.state === "active");
if (flying.length === 0) { el.hidden = true; return; }
el.hidden = false;
const active = batch.find((j) => j.state === "active") || flying[0];
const total = batch.length;
const done = batch.filter((j) => j.state === "done").length;
const pos = Math.min(total, done + 1);
const isActive = active && active.state === "active";
// Eyebrow + name
els.globalDlState.textContent = isActive ? "Downloading" : "Queued";
els.globalDlName.textContent = active.name || active.title_id || "—";
// Position chip ("3 of 9") only when there's more than one game in this run
if (total > 1) {
els.globalDlPosition.hidden = false;
els.globalDlPosition.textContent = `${pos} of ${total}`;
} else {
els.globalDlPosition.hidden = true;
}
// Progress line
const pct = pctOf(active);
const speed = Number(active._speed) || 0;
const done_ = Number(active.bytes) || 0;
const total_ = Number(active.total_bytes) || 0;
els.globalDlPct.innerHTML = isActive ? `<b>${pct}%</b>` : `<b>—</b> waiting`;
els.globalDlSpeed.innerHTML = isActive && speed > 0
? `<b>${formatBytes(speed)}/s</b>`
: (isActive && !total_ ? "fetching manifest…" : "—");
els.globalDlEta.innerHTML = isActive && speed > 0 && total_ > done_
? `ETA <b>${formatEta((total_ - done_) / speed)}</b>`
: "";
// Bar: animated indeterminate while fetching manifest, otherwise width=pct
if (isActive && total_ > 0) {
els.globalDlBar.classList.remove("is-indeterminate");
els.globalDlBar.style.width = pct + "%";
} else {
els.globalDlBar.classList.add("is-indeterminate");
}
}
// Update the progress bar/meta in place to avoid rebuilding every card each tick. // Update the progress bar/meta in place to avoid rebuilding every card each tick.
function applyDownloadProgress() { function applyDownloadProgress() {
renderGlobalStatus();
let needRender = false; let needRender = false;
state.downloads.forEach((d) => { state.downloads.forEach((d) => {
// Only titles currently downloading render a progress tile; paused/done/error
// jobs linger in the pool list but have no .progress bar — skip them so a
// missing tile for a non-downloading title doesn't force a full rebuild.
const g = state.titles.find((t) => t.title_id === d.title_id);
if (!g || !g.downloading) return;
const card = els.gameGrid.querySelector(`[data-title-id="${d.title_id}"]`); const card = els.gameGrid.querySelector(`[data-title-id="${d.title_id}"]`);
const bar = card && card.querySelector(".card-progress .progress > i"); const bar = card && card.querySelector(".card-progress .progress > i");
const meta = card && card.querySelector(".card-progress .progress-meta"); const meta = card && card.querySelector(".card-progress .progress-meta");
@@ -549,6 +810,7 @@ async function saveConfig() {
delete_pkg_after_install: els.deleteAfterInstall.checked, delete_pkg_after_install: els.deleteAfterInstall.checked,
verify_downloads: els.verifyDownloads ? els.verifyDownloads.checked : Boolean(state.config.verify_downloads), verify_downloads: els.verifyDownloads ? els.verifyDownloads.checked : Boolean(state.config.verify_downloads),
home_shortcut: els.homeShortcut ? els.homeShortcut.checked : state.config.home_shortcut !== false, home_shortcut: els.homeShortcut ? els.homeShortcut.checked : state.config.home_shortcut !== false,
max_connections: clampConn(state.config.max_connections),
}; };
try { try {
await postJson(API.config, config); await postJson(API.config, config);
@@ -564,19 +826,55 @@ async function saveConfig() {
/* ---------------- actions (data layer) ---------------- */ /* ---------------- actions (data layer) ---------------- */
// Queue a download for every game that has an available update AND could
// actually be installed afterwards. Shadowmounts pass isDownloadAllowed but
// fail isInstallAllowed (their app slot has no real source medium), so a
// sweep would otherwise pull tens of GB that AppInstUtil will refuse — the
// user picks those up by hand when the disc is ready. The server tolerates
// duplicate requests, so a second click is harmless. If install_after_download
// is on, the per-job auto-install pipeline kicks in once each download
// finishes — no further client action needed.
async function updateAll() {
const targets = state.games.filter((g) =>
g.status === "available" && isInstallAllowed(g) &&
!g.downloading && !g.downloaded);
if (!targets.length) {
showToast("No installable updates to queue.");
return;
}
showToast(`Queueing ${targets.length} update${targets.length === 1 ? "" : "s"}…`);
for (const g of targets) {
// Sequential await: the pool returns quickly (202 Accepted) and we want
// a stable order in the queue, not a thundering-herd of concurrent POSTs.
try { await doDownload(g); } catch (_) { /* per-job errors already toast */ }
}
}
// Enqueue a download. The pool returns immediately (202); progress, completion
// and (if configured) auto-install are driven by reconcileFromJobs() on poll.
async function doDownload(game) { async function doDownload(game) {
game.downloading = true; game.downloading = true;
game._localDownloading = true; // this client owns it; don't let a poll clear it game._localDownloading = true; // until the pool reports a job for this title
game._localSince = Date.now(); // bounded in reconcileFromJobs if no job appears
game._autoInstalled = false;
state.downloads = state.downloads.filter((i) => i.title_id !== game.title_id); state.downloads = state.downloads.filter((i) => i.title_id !== game.title_id);
state.downloads.push({ title_id: game.title_id, name: game.name, version: game.compatible_version || "", progress: 0, bytes: 0, total_bytes: 0 }); state.downloads.push({ title_id: game.title_id, name: game.name,
state.logs.push(`[${timeNow()}] Download started: ${game.title_id} ${game.compatible_version}`); version: game.compatible_version || "",
state: "queued", progress: 0, bytes: 0, total_bytes: 0 });
renderGames(); renderGames();
renderLogs();
startDownloadPolling(); startDownloadPolling();
let r;
try { try {
r = await postJson(API.action(game.title_id, "download"), {}); const r = await postJson(API.action(game.title_id, "download"), {});
if (r && r.downloaded && r.already) {
game.downloading = false;
game._localDownloading = false;
game.downloaded = true;
renderGames();
} else {
state.logs.push(`[${timeNow()}] Download queued: ${game.title_id} ${game.compatible_version || ""}`);
renderLogs();
}
} catch (error) { } catch (error) {
game.downloading = false; game.downloading = false;
game._localDownloading = false; game._localDownloading = false;
@@ -584,34 +882,14 @@ async function doDownload(game) {
const why = reasonText(error); const why = reasonText(error);
state.logs.push(`[${timeNow()}] download ${game.title_id} blocked: ${why}`); state.logs.push(`[${timeNow()}] download ${game.title_id} blocked: ${why}`);
showToast(`${game.name}: ${why}`); showToast(`${game.name}: ${why}`);
renderGames(); renderLogs(); stopDownloadPolling(); renderGames(); renderLogs();
return false;
} }
game.downloading = false;
game._localDownloading = false;
state.downloads = state.downloads.filter((i) => i.title_id !== game.title_id);
// Cancel / soft failure returns HTTP 200 with ok:false (not thrown).
if (!r || r.ok === false) {
game.downloaded = false;
const what = r && r.cancelled ? "cancelled" : "failed";
state.logs.push(`[${timeNow()}] Download ${what}: ${game.title_id}`);
showToast(`${game.name}: download ${what}.`);
renderGames(); renderLogs(); stopDownloadPolling();
return false;
}
game.downloaded = true;
const sz = r && r.bytes ? formatBytes(r.bytes) : "?";
state.logs.push(`[${timeNow()}] Downloaded ${game.title_id} ${game.compatible_version} (${sz}, internal)`);
showToast(`${game.name}: downloaded ${sz}.`);
renderGames(); renderLogs(); stopDownloadPolling();
return true;
} }
async function doInstall(game) { async function doInstall(game) {
game.installing = true; game.installing = true;
game.installStatus = "starting";
game.installProgress = 0;
game.downloaded = false; // the package is being consumed by the install game.downloaded = false; // the package is being consumed by the install
renderGames(); renderGames();
try { try {
@@ -625,7 +903,8 @@ async function doInstall(game) {
return false; return false;
} }
state.logs.push(`[${timeNow()}] Install started for ${game.title_id} ${game.compatible_version} — running in PS5 background`); state.logs.push(`[${timeNow()}] Install started for ${game.title_id} ${game.compatible_version} — running in PS5 background`);
showToast(`${game.name}: installing update — progress shows in your PS5 notifications.`); showToast(`${game.name}: installing update.`);
startInstallPolling();
renderGames(); renderLogs(); renderGames(); renderLogs();
return true; return true;
} }
@@ -640,7 +919,13 @@ async function cancelDownload(titleId) {
} catch (error) { } catch (error) {
showToast(`${game ? game.name : titleId}: ${reasonText(error)}`); showToast(`${game ? game.name : titleId}: ${reasonText(error)}`);
} }
if (game) { game.downloading = false; game._localDownloading = false; game.downloaded = false; } if (game) {
game.downloading = false;
game._localDownloading = false;
game.downloaded = false;
game.resumable = false;
game.partial_bytes = 0;
}
state.downloads = state.downloads.filter((i) => i.title_id !== titleId); state.downloads = state.downloads.filter((i) => i.title_id !== titleId);
state.logs.push(`[${timeNow()}] Download cancelled / deleted: ${titleId}`); state.logs.push(`[${timeNow()}] Download cancelled / deleted: ${titleId}`);
renderGames(); renderLogs(); renderGames(); renderLogs();
@@ -650,10 +935,23 @@ async function cancelDownload(titleId) {
async function runTitleAction(titleId, action) { async function runTitleAction(titleId, action) {
const game = state.titles.find((i) => i.title_id === titleId); const game = state.titles.find((i) => i.title_id === titleId);
if (!game) return; if (!game) return;
if (action === "download") await doDownload(game); // "update" and "download" both just enqueue; for "update" (install-after-
// download on) the reconciler auto-installs once the pool reports it done.
if (action === "download" || action === "update") await doDownload(game);
else if (action === "install") await doInstall(game); else if (action === "install") await doInstall(game);
else if (action === "pause") await doPause(game);
else if (action === "cancel") await cancelDownload(titleId); else if (action === "cancel") await cancelDownload(titleId);
else if (action === "update") { if (await doDownload(game)) await doInstall(game); } }
// Pause only sends the signal; the in-flight doDownload() request returns its
// "paused" result and updates the card (resumable + partial bytes).
async function doPause(game) {
try {
await postJson(API.action(game.title_id, "pause"), {});
showToast(`${game.name}: pausing…`);
} catch (error) {
showToast(`${game.name}: ${reasonText(error)}`);
}
} }
function updateGame(titleId, patch) { function updateGame(titleId, patch) {
@@ -671,11 +969,26 @@ function updateGame(titleId, patch) {
/* ---------------- policy helpers ---------------- */ /* ---------------- policy helpers ---------------- */
function isInstallBlocked(game) { return !sourcePolicy(game).allow_install; } function isInstallBlocked(game) { return !sourcePolicy(game).allow_install; }
function hasSharedStorage(game) {
if (game.patch_storage_match === false) return true;
const storage = (game.patch_storage_title_id || "").slice(0, 9);
const target = (game.title_id || "").slice(0, 9);
return Boolean(storage && target && storage !== target);
}
function isDownloadAllowed(game) {
return Boolean(
game.enabled !== false &&
game.compatible_version &&
game.patch_title_match !== false &&
sourcePolicy(game).allow_download
);
}
function isInstallAllowed(game) { function isInstallAllowed(game) {
return Boolean( return Boolean(
game.enabled !== false && game.enabled !== false &&
game.compatible_version && game.compatible_version &&
game.patch_title_match !== false && game.patch_title_match !== false &&
!hasSharedStorage(game) &&
sourcePolicy(game).allow_install sourcePolicy(game).allow_install
); );
} }
@@ -704,6 +1017,7 @@ async function postJson(url, body) {
const REASON_TEXT = { const REASON_TEXT = {
patch_title_mismatch: "Patch metadata targets a different title - install blocked.", patch_title_mismatch: "Patch metadata targets a different title - install blocked.",
cross_region_storage_unsupported: "Patch bytes are signed for a shared master title; this standalone installer cannot retarget them.",
install_not_allowed_for_source: "Install blocked for this source.", install_not_allowed_for_source: "Install blocked for this source.",
source_unknown: "Source unknown — blocked.", source_unknown: "Source unknown — blocked.",
no_compatible_patch: "No compatible patch available.", no_compatible_patch: "No compatible patch available.",
@@ -711,6 +1025,8 @@ const REASON_TEXT = {
download_in_progress: "Another download is already running.", download_in_progress: "Another download is already running.",
piece_verify_failed: "A downloaded piece failed its SHA-256 check.", piece_verify_failed: "A downloaded piece failed its SHA-256 check.",
title_disabled: "This title is disabled.", title_disabled: "This title is disabled.",
download_paused: "Download paused.",
not_downloading: "Nothing is downloading for this title.",
}; };
function reasonText(error) { function reasonText(error) {
const r = error && error.body && error.body.reason; const r = error && error.body && error.body.reason;
+44 -5
View File
@@ -39,7 +39,7 @@
<div class="brand-mark">PD</div> <div class="brand-mark">PD</div>
<div> <div>
<strong>PatchDL</strong> <strong>PatchDL</strong>
<span>by Knutwurst · v0.0.2</span> <span>by Knutwurst · <span id="brandVersion">--</span></span>
</div> </div>
</div> </div>
@@ -66,16 +66,43 @@
<section class="view is-active" data-view="games"> <section class="view is-active" data-view="games">
<header class="topbar"> <header class="topbar">
<div> <div>
<p class="eyebrow">Standalone ELF Web UI</p> <p class="eyebrow">PS5 update manager</p>
<h1>Games</h1> <h1>Games</h1>
</div> </div>
<div class="topbar-actions"> <div class="topbar-actions">
<button class="primary-button" id="updateAllBtn" title="Download (and optionally install) every game that has an available, allowed update">
<svg><use href="#icon-download"></use></svg>
Update all
</button>
<button class="icon-button" id="refreshBtn" title="Refresh status and games" aria-label="Refresh"> <button class="icon-button" id="refreshBtn" title="Refresh status and games" aria-label="Refresh">
<svg><use href="#icon-refresh"></use></svg> <svg><use href="#icon-refresh"></use></svg>
</button> </button>
</div> </div>
</header> </header>
<aside id="globalDl" class="global-dl" hidden aria-live="polite">
<div class="global-dl-row">
<span class="global-dl-pulse" aria-hidden="true"></span>
<div class="global-dl-text">
<div class="global-dl-line1">
<span class="global-dl-eyebrow" id="globalDlState">Downloading</span>
<strong class="global-dl-name" id="globalDlName">—</strong>
<span class="global-dl-position" id="globalDlPosition" hidden></span>
</div>
<div class="global-dl-line2">
<span id="globalDlPct">0%</span>
<span class="global-dl-sep" aria-hidden="true">·</span>
<span id="globalDlSpeed">—</span>
<span class="global-dl-sep" aria-hidden="true">·</span>
<span id="globalDlEta">—</span>
</div>
</div>
</div>
<div class="global-dl-track">
<i class="global-dl-bar" id="globalDlBar" style="width:0%"></i>
</div>
</aside>
<section class="status-strip" aria-label="System status"> <section class="status-strip" aria-label="System status">
<article class="metric"> <article class="metric">
<span>Firmware</span> <span>Firmware</span>
@@ -85,7 +112,7 @@
<article class="metric"> <article class="metric">
<span>DNS Guard</span> <span>DNS Guard</span>
<strong id="dnsValue">--</strong> <strong id="dnsValue">--</strong>
<em>Sony blocked by nanoDNS</em> <em>System DNS left untouched</em>
</article> </article>
<article class="metric"> <article class="metric">
<span>CDN Access</span> <span>CDN Access</span>
@@ -105,11 +132,12 @@
<input id="searchInput" type="search" placeholder="Search title, Title ID, or Content ID" /> <input id="searchInput" type="search" placeholder="Search title, Title ID, or Content ID" />
</div> </div>
<div class="segmented" role="group" aria-label="Filter"> <div class="segmented" role="group" aria-label="Filter">
<button class="is-selected" data-filter="all" aria-pressed="true">All</button> <button class="is-selected" data-filter="updatable" aria-pressed="true">Updatable</button>
<button data-filter="updatable" aria-pressed="false">Updatable</button> <button data-filter="updating" aria-pressed="false">Updating</button>
<button data-filter="uptodate" aria-pressed="false">Up to date</button> <button data-filter="uptodate" aria-pressed="false">Up to date</button>
<button data-filter="needsfw" aria-pressed="false">Needs FW</button> <button data-filter="needsfw" aria-pressed="false">Needs FW</button>
<button data-filter="blocked" aria-pressed="false">Can't update</button> <button data-filter="blocked" aria-pressed="false">Can't update</button>
<button data-filter="all" aria-pressed="false">All</button>
</div> </div>
</div> </div>
@@ -186,6 +214,17 @@
<span class="track"></span> <span class="track"></span>
</span> </span>
</label> </label>
<div class="switch-row">
<span>
<strong>Parallel download connections</strong>
<em>1–16 · applies live, no payload restart</em>
</span>
<div class="stepper" role="group" aria-label="Parallel download connections">
<button type="button" class="stepper-btn" id="connMinus" aria-label="Fewer connections">−</button>
<output class="stepper-value" id="connValue" aria-live="polite">4</output>
<button type="button" class="stepper-btn" id="connPlus" aria-label="More connections">+</button>
</div>
</div>
</div> </div>
<div class="allowlist"> <div class="allowlist">
+134 -4
View File
@@ -173,6 +173,105 @@ h2 { font-size: 18px; line-height: 1.2; }
margin-bottom: 18px; margin-bottom: 18px;
} }
/* ---------------- global download banner ---------------- */
/* Sticky banner above the status strip, visible only while at least one
download is queued/active. The pulse dot and gradient bar at the bottom
echo the per-game card progress styling so the two read as one system. */
.global-dl {
position: relative;
display: flex;
flex-direction: column;
gap: 12px;
margin-bottom: 18px;
padding: 16px 18px 0;
border: 1px solid var(--border);
background:
radial-gradient(120% 80% at 0% 0%, var(--green-soft), transparent 60%),
linear-gradient(180deg, rgba(56, 193, 114, 0.06), transparent 60%),
var(--surface);
border-radius: var(--radius);
overflow: hidden;
}
.global-dl[hidden] { display: none; }
.global-dl-row {
display: flex;
align-items: center;
gap: 14px;
min-width: 0;
}
.global-dl-pulse {
flex: none;
width: 12px;
height: 12px;
border-radius: 50%;
background: var(--green);
box-shadow: 0 0 0 0 var(--green);
animation: globalDlPulse 1.6s ease-out infinite;
}
@keyframes globalDlPulse {
0% { box-shadow: 0 0 0 0 rgba(56, 193, 114, 0.55); }
70% { box-shadow: 0 0 0 14px rgba(56, 193, 114, 0); }
100% { box-shadow: 0 0 0 0 rgba(56, 193, 114, 0); }
}
.global-dl-text { display: flex; flex-direction: column; gap: 4px; min-width: 0; flex: 1; }
.global-dl-line1 {
display: flex; align-items: baseline; gap: 10px;
min-width: 0; flex-wrap: wrap;
}
.global-dl-eyebrow {
text-transform: uppercase; letter-spacing: 0.08em;
font-size: 11px; font-weight: 600; color: var(--green-dark);
}
.global-dl-name {
font-size: 16px; font-weight: 600; color: #fff;
overflow: hidden; text-overflow: ellipsis; white-space: nowrap;
min-width: 0; flex: 1;
}
.global-dl-position {
font-size: 12px; color: var(--muted);
padding: 2px 8px; border-radius: 999px;
background: rgba(255, 255, 255, 0.04); border: 1px solid var(--border);
}
.global-dl-position[hidden] { display: none; }
.global-dl-line2 {
display: flex; align-items: center; gap: 8px;
font-size: 12px; color: var(--muted);
font-variant-numeric: tabular-nums;
}
.global-dl-line2 b { color: #d6dde4; font-weight: 600; }
.global-dl-sep { opacity: 0.5; }
.global-dl-track {
position: relative;
height: 3px;
margin: 0 -18px; /* extend bar edge-to-edge */
background: rgba(56, 193, 114, 0.08);
overflow: hidden;
}
.global-dl-bar {
display: block;
height: 100%;
width: 0%;
background: linear-gradient(90deg, var(--green) 0%, var(--green-dark) 100%);
box-shadow: 0 0 12px rgba(56, 193, 114, 0.4);
transition: width 400ms ease-out;
}
.global-dl-bar.is-indeterminate {
width: 32% !important;
animation: globalDlIndet 1.6s ease-in-out infinite;
}
@keyframes globalDlIndet {
0% { transform: translateX(-100%); }
100% { transform: translateX(320%); }
}
.metric { .metric {
min-width: 0; min-width: 0;
padding: 14px 16px; padding: 14px 16px;
@@ -331,10 +430,13 @@ h2 { font-size: 18px; line-height: 1.2; }
width: 100%; /* fills the fixed-width actions column -> never reflows */ width: 100%; /* fills the fixed-width actions column -> never reflows */
padding: 0 12px; padding: 0 12px;
} }
.row-button.is-update { border-color: var(--blue); color: #04111f; background: var(--blue); } /* go = green (Update / Resume / Install), pause = amber, cancel/stop = red */
.row-button.is-update:hover { background: var(--blue-dark); } .row-button.is-update { border-color: var(--green); color: #04150c; background: var(--green); }
.row-button.is-cancel { border-color: var(--amber); color: #1c1402; background: var(--amber); } .row-button.is-update:hover { background: var(--green-dark); }
.row-button.is-cancel:hover { background: var(--amber-dark); } .row-button.is-pause { border-color: var(--amber); color: #1c1402; background: var(--amber); }
.row-button.is-pause:hover { background: var(--amber-dark); }
.row-button.is-cancel { border-color: var(--red); color: #1a0606; background: var(--red); }
.row-button.is-cancel:hover { background: #ff8a8a; }
.row-button.is-ghost { background: transparent; color: var(--muted); } .row-button.is-ghost { background: transparent; color: var(--muted); }
.row-button.is-ghost:hover { color: var(--ink); border-color: var(--muted); } .row-button.is-ghost:hover { color: var(--ink); border-color: var(--muted); }
.row-button:disabled { opacity: 0.6; cursor: default; } .row-button:disabled { opacity: 0.6; cursor: default; }
@@ -392,6 +494,34 @@ h2 { font-size: 18px; line-height: 1.2; }
background: var(--surface-2); background: var(--surface-2);
border-radius: 8px; border-radius: 8px;
} }
/* number stepper — big, controller-friendly targets with a clear focus ring
(the UI is operated by the PS5 controller via the home tile). */
.stepper { display: inline-flex; align-items: center; gap: 12px; flex: none; }
.stepper-btn {
width: 54px; height: 54px;
display: inline-flex; align-items: center; justify-content: center;
font-size: 30px; line-height: 1; font-weight: 600;
color: var(--ink);
background: var(--surface);
border: 1px solid var(--border);
border-radius: 14px;
cursor: pointer;
-webkit-tap-highlight-color: transparent;
transition: background .12s ease, border-color .12s ease, transform .07s ease;
}
.stepper-btn:hover { background: var(--surface); border-color: var(--muted); }
.stepper-btn:active { transform: scale(0.93); background: var(--green-soft); border-color: var(--green); }
/* :focus (not only :focus-visible) so the controller's focus is always obvious */
.stepper-btn:focus { outline: none; border-color: var(--green); box-shadow: 0 0 0 3px var(--green-soft); }
.stepper-btn:disabled { opacity: 0.32; cursor: default; transform: none; }
.stepper-value {
min-width: 52px;
text-align: center;
font-size: 26px; font-weight: 700;
font-variant-numeric: tabular-nums;
color: var(--ink);
}
.switch-row > span:first-child strong { display: block; font-size: 14px; } .switch-row > span:first-child strong { display: block; font-size: 14px; }
.switch-row > span:first-child em { display: block; margin-top: 3px; color: var(--muted); font-size: 12px; font-style: normal; } .switch-row > span:first-child em { display: block; margin-top: 3px; color: var(--muted); font-size: 12px; font-style: normal; }