mirror of
https://github.com/knutwurst/patchdl.git
synced 2026-10-06 09:00:23 +02:00
Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
a1d035313e | ||
|
|
bffa9b2a3f | ||
|
|
3f4c4a15f5 | ||
|
|
c9d721fea6 | ||
|
|
73c75ddd83 | ||
|
|
fcb0a5c3b0 | ||
|
|
a6d9f939b5 | ||
|
|
5ba72b850c | ||
|
|
2f3490f21a | ||
|
|
80c47d6777 | ||
|
|
970c7d8f1d | ||
|
|
983f39fa89 | ||
|
|
79e1c377ed | ||
|
|
fb9d06fb5b | ||
|
|
3d2ee430e1 | ||
|
|
986ff00c36 | ||
|
|
6024dbfc5d | ||
|
|
21f6bd61ad | ||
|
|
01eaef79f2 | ||
|
|
66e4912485 |
No files matched your search
@@ -1,31 +1,54 @@
|
||||
# PatchDL
|
||||
|
||||
A standalone PlayStation 5 ELF payload that downloads and installs official game
|
||||
patches on your terms. It serves its own web UI and runs without etaHEN.
|
||||
patches on your terms. It serves its own dark-mode web UI and runs without
|
||||
etaHEN.
|
||||
|
||||
PatchDL is built for setups where nanoDNS blocks Sony's servers for the whole
|
||||
console. It resolves the Sony patch CDN on its own path, so the rest of the
|
||||
console. It resolves the Sony patch CDN on its own DNS path, so the rest of the
|
||||
system stays offline and only the patches you pick get fetched.
|
||||
|
||||
by Knutwurst
|
||||
|
||||
## What it does
|
||||
|
||||
- Scans installed titles and classifies each one: genuine install,
|
||||
ShadowMountPlus mount, preinstall, or unknown.
|
||||
- Reads the title name, installed version, and the Sony `version.xml` URL from
|
||||
the PS5 app database.
|
||||
- Fetches each title's `version.xml` from Sony's CDN past nanoDNS (a raw DNS
|
||||
query to 1.1.1.1) and verifies TLS against the pinned SCEI DNAS root.
|
||||
- Scans installed titles and classifies each: genuine install, ShadowMountPlus
|
||||
mount, preinstall, or unknown.
|
||||
- Reads the title name, installed version, and Sony `version.xml` URL from the
|
||||
PS5 app database.
|
||||
- Fetches each title's `version.xml` past nanoDNS (a raw DNS query to 1.1.1.1)
|
||||
and verifies TLS against the pinned SCEI DNAS root.
|
||||
- Picks the newest patch compatible with the current firmware
|
||||
(`system_ver <= firmware`), so an update never forces a firmware upgrade.
|
||||
- Downloads the installable package from Sony's manifest pieces and installs it
|
||||
through Sony's AppInstUtil service.
|
||||
- Downloads the patch from Sony's manifest pieces into one local `.pkg`, then
|
||||
installs it through Sony's AppInstUtil service.
|
||||
|
||||
## Downloading
|
||||
|
||||
PatchDL pulls each patch over a pool of connections instead of one stream, which
|
||||
lifts the ~7 MB/s per-connection ceiling on the Sony CDN. Set the connection
|
||||
count (1 to 16) in Settings with the stepper; the change applies live, with no
|
||||
payload restart. One patch downloads at a time and further requests queue.
|
||||
|
||||
Downloads survive interruptions:
|
||||
|
||||
- **Resume across a reboot.** PatchDL records progress per manifest piece in a
|
||||
sidecar beside the `.pkg`, written after every completed piece, so a reboot or
|
||||
relaunch continues where it stopped.
|
||||
- **Pause, Resume, Cancel.** Pause keeps the partial file, Resume continues it,
|
||||
Cancel deletes it. All three work at any point in a download.
|
||||
- **Verification.** Turn on "Verify downloaded pieces (SHA-256)" to check each
|
||||
piece against its manifest hash while downloading. After a download you can
|
||||
also verify the assembled package on-device against Sony's per-piece hashes
|
||||
(`GET /api/pkgverify/<title_id>`).
|
||||
|
||||
Patches download to `/data/patchdl` on the internal SSD. Large retail updates
|
||||
run tens of GB.
|
||||
|
||||
## Safety model
|
||||
|
||||
Deny-by-default. A patch is installed only for a genuine install, and only when
|
||||
the patch metadata targets the installed game:
|
||||
Deny-by-default. A patch installs only for a genuine install, and only when the
|
||||
patch metadata targets the installed game:
|
||||
|
||||
| Source | Check | Download | Install |
|
||||
|-----------------------|-------|----------|---------|
|
||||
@@ -33,29 +56,30 @@ the patch metadata targets the installed game:
|
||||
| shadowmount | yes | yes | no |
|
||||
| preinstall / unknown | yes | no | no |
|
||||
|
||||
Two independent guards stop the wrong target being installed: the patch target
|
||||
id (read from `version.xml` / `manifest_url`) must match the installed game, and
|
||||
the install call receives the installed game's content id from app.db. Sony may
|
||||
store the actual patch bytes under a regional/master title id that differs from
|
||||
the target; that storage id is accepted only when `version.xml` targets the
|
||||
installed title. A true target-title mismatch is refused instead of installed as
|
||||
a phantom title.
|
||||
Two guards stop the wrong target being installed: the patch target id (from
|
||||
`version.xml` / `manifest_url`) must match the installed game, and the install
|
||||
call receives the installed game's content id from app.db. PatchDL refuses a
|
||||
true target-title mismatch rather than installing a phantom title.
|
||||
|
||||
For PS5 titles, `delta_url` often points to a small `*-DP.pkg` helper package.
|
||||
That bootstrap can make the system fetch the full patch, but it follows the
|
||||
package's storage/master title id and can create a duplicate/ghost title for
|
||||
cross-region updates. PatchDL therefore prefers the Sony `manifest_url`,
|
||||
downloads every listed `pieces[]` entry in order, and concatenates them into one
|
||||
local `.pkg` before handing it to AppInstUtil. The `delta_url` title id is kept
|
||||
only as the storage/master-id diagnostic.
|
||||
All writes stay under `/data/patchdl`. PatchDL never writes to the system
|
||||
partition and never touches firmware.
|
||||
|
||||
## Settings
|
||||
|
||||
Settings persist to `/data/patchdl/config.json` and survive a restart:
|
||||
|
||||
- Default policy (allow or deny) and a per-game enable toggle.
|
||||
- Install after download, as a global default with a per-game override.
|
||||
- Delete the PKG after a successful install.
|
||||
- Verify downloaded pieces (SHA-256).
|
||||
- Parallel download connections (1 to 16), applied live.
|
||||
|
||||
## Build
|
||||
|
||||
Requires `ps5-payload-dev/sdk`. The network and install features also need the
|
||||
prebuilt libcurl + OpenSSL from `ps5-payload-dev/pacbrew-repo` placed in the SDK
|
||||
sysroot (`target/user/homebrew`); `scripts/build_ps5.sh` enables them
|
||||
automatically when present. libmicrohttpd is vendored under `vendor/etahen`, and
|
||||
SQLite is vendored under `vendor/sqlite`.
|
||||
Requires `ps5-payload-dev/sdk`. The network and install features need the
|
||||
prebuilt libcurl + OpenSSL from `ps5-payload-dev/pacbrew-repo` in the SDK sysroot
|
||||
(`target/user/homebrew`); `scripts/build_ps5.sh` enables them when present.
|
||||
libmicrohttpd is vendored under `vendor/etahen`, SQLite under `vendor/sqlite`.
|
||||
|
||||
```sh
|
||||
scripts/build_ps5.sh # produces patchdl-ps5.elf
|
||||
@@ -63,9 +87,9 @@ scripts/build_ps5.sh # produces patchdl-ps5.elf
|
||||
|
||||
## Deploy
|
||||
|
||||
This console uses the BD-JB autoloader with itsPLK's Payload Manager on port
|
||||
8084 (not a 9021 elfldr). `scripts/deploy_ps5.sh` uploads the ELF named with its
|
||||
version and launches it; the payload replaces any running instance itself.
|
||||
This console uses the BD-JB autoloader with itsPLK's Payload Manager on port 8084
|
||||
(not a 9021 elfldr). `scripts/deploy_ps5.sh` uploads the version-named ELF and
|
||||
launches it; the payload replaces any running instance.
|
||||
|
||||
```sh
|
||||
PS5_HOST=<console-ip> scripts/deploy_ps5.sh
|
||||
@@ -79,17 +103,25 @@ http://<console-ip>:12880/
|
||||
|
||||
## Status
|
||||
|
||||
0.0.2, early. Title scan, source classification, version resolution,
|
||||
firmware-compatibility filtering, target/storage-id handling, and the local
|
||||
AppInstUtil HTTP stream have been verified on firmware 11.60. PatchDL now
|
||||
downloads PS5 update manifests as merged piece packages under `/data/patchdl`;
|
||||
large retail updates can be tens of GB. The download queue shows live progress,
|
||||
and each download can be cancelled (the partial file is deleted) or a finished
|
||||
package deleted again, from the queue or the title card. Manifest pieces are
|
||||
verified in offset order and against their declared size while merging. Open
|
||||
items: a full large-title manifest download/install still needs an end-to-end
|
||||
run, the web UI marks a title "Installing…" but reads progress from the PS5's
|
||||
own notifications rather than a percentage, and disc-based games need the disc
|
||||
inserted for their patch to apply (a normal Sony requirement).
|
||||
Settings (global policy and the per-game toggle) persist to
|
||||
`/data/patchdl/config.json` and survive a restart.
|
||||
Verified on firmware 11.60: title scan, source classification, version
|
||||
resolution past the nanoDNS block, firmware-compatibility filtering, the parallel
|
||||
download pool, reboot-safe resume, and on-device SHA-256 verification. A full
|
||||
Dead Island 2 update (61.6 GB) downloaded and verified byte-perfect across
|
||||
several reboots.
|
||||
|
||||
Install works for same-region patches, where Sony stores the patch bytes under
|
||||
the installed game's own title id. PatchDL now mirrors etaHEN's native
|
||||
DirectPKGInstaller call shape for that path: it passes an empty
|
||||
`MetaInfo.content_id`, lets AppInstUtil bind the signed package metadata, keeps
|
||||
the returned content id, and exposes `/api/installstatus` for installer progress
|
||||
when `sceAppInstUtilGetInstallStatus` is exported.
|
||||
|
||||
Cross-region patches are a known limitation. Sony sometimes packages a regional
|
||||
patch under a different (master) storage title and ships it as a debug-magic
|
||||
container. PatchDL downloads such a patch and verifies it against Sony's hashes,
|
||||
but refuses to install it from the standalone ELF because `InstallByPackage`
|
||||
does not retarget signed package metadata on 11.60, and the homebrew alternative
|
||||
(BGFT register) returns "not supported" outside the system process. Installing
|
||||
that class of patch needs Sony's authenticated updater, which nanoDNS blocks.
|
||||
Disc games need the disc inserted for their patch to apply, which is a normal
|
||||
Sony requirement.
|
||||
+5
-1
@@ -61,8 +61,12 @@ patchdl_appdb_load(patchdl_appinfo_t **out, size_t *count) {
|
||||
*out = NULL;
|
||||
*count = 0;
|
||||
|
||||
/* FULLMUTEX: today only the startup thread calls this, but future code
|
||||
paths (a manual rescan triggered from the HTTP thread) would otherwise
|
||||
race the SQLite handle. Cost is one mutex per call. */
|
||||
if (sqlite3_open_v2(APP_DB_URI, &db,
|
||||
SQLITE_OPEN_READONLY | SQLITE_OPEN_URI, NULL) != SQLITE_OK) {
|
||||
SQLITE_OPEN_READONLY | SQLITE_OPEN_URI |
|
||||
SQLITE_OPEN_FULLMUTEX, NULL) != SQLITE_OK) {
|
||||
if (db) sqlite3_close(db);
|
||||
return -1;
|
||||
}
|
||||
|
||||
+465
-70
@@ -7,8 +7,11 @@
|
||||
|
||||
#include <pthread.h>
|
||||
#include <stddef.h>
|
||||
#include <stdbool.h>
|
||||
#include <stdint.h>
|
||||
#include <stdatomic.h>
|
||||
#include <stdio.h>
|
||||
#include <stdlib.h>
|
||||
#include <string.h>
|
||||
#include <sys/socket.h>
|
||||
#include <sys/stat.h>
|
||||
@@ -45,6 +48,42 @@ typedef struct {
|
||||
long unknown[810];
|
||||
} ai_playgo_info_t;
|
||||
|
||||
typedef struct {
|
||||
int32_t error_code;
|
||||
int32_t version;
|
||||
char description[512];
|
||||
char type[9];
|
||||
} ai_install_error_t;
|
||||
|
||||
typedef struct {
|
||||
char status[16];
|
||||
char src_type[8];
|
||||
uint32_t remain_time;
|
||||
uint64_t downloaded_size;
|
||||
uint64_t initial_chunk_size;
|
||||
uint64_t total_size;
|
||||
uint32_t promote_progress;
|
||||
ai_install_error_t error_info;
|
||||
int32_t local_copy_percent;
|
||||
bool is_copy_only;
|
||||
char _pad[2048]; /* safety margin — actual Sony struct may be larger */
|
||||
} ai_install_status_t;
|
||||
|
||||
/* Padded buffers for Sony output writes whose actual size is reverse-engineered.
|
||||
The visible content fits in 0x30 (content_id) / 16 (title_id) bytes, but the
|
||||
firmware may NUL-pad or write more. Used as caller-side temporaries that are
|
||||
then copy_bounded()-d into the right-sized destination. */
|
||||
#define AI_CONTENTID_OUT_SIZE 256
|
||||
#define AI_TITLEID_OUT_SIZE 128
|
||||
|
||||
#define STATIC_ASSERT(c, n) typedef char static_assert_##n[(c) ? 1 : -1]
|
||||
STATIC_ASSERT(sizeof(ai_pkg_info_t) == 0x38, pkg_info_size);
|
||||
STATIC_ASSERT(sizeof(ai_meta_info_t) == (6 * sizeof(void *)), meta_info_size);
|
||||
STATIC_ASSERT(sizeof(ai_playgo_info_t) == 0x2700, playgo_info_size);
|
||||
STATIC_ASSERT(offsetof(ai_meta_info_t, uri) == 0, meta_uri_offset);
|
||||
STATIC_ASSERT(offsetof(ai_meta_info_t, icon_url) == (5 * sizeof(void *)),
|
||||
meta_icon_offset);
|
||||
|
||||
/* Sysmodule IDs (from ps5-payload-dev/sdk crt/rtld_sprx.c). */
|
||||
#define SYSMOD_IPMI 0x8000001d
|
||||
#define SYSMOD_USERSERVICE 0x80000011
|
||||
@@ -57,11 +96,15 @@ typedef int (*ai_install_pkg_fn)(const char *path, ai_pkg_info_t *info);
|
||||
typedef int (*ai_install_by_pkg_fn)(ai_meta_info_t *meta, ai_pkg_info_t *info,
|
||||
ai_playgo_info_t *playgo);
|
||||
typedef int (*ai_title_from_pkg_fn)(const char *path, char *title_id, int *is_app);
|
||||
typedef int (*ai_content_from_pkg_fn)(const char *path, char *content_id, int *is_app);
|
||||
typedef int (*ai_get_status_fn)(char *content_id_out, ai_install_status_t *status);
|
||||
|
||||
static ai_init_fn ai_initialize;
|
||||
static ai_install_pkg_fn ai_install_pkg;
|
||||
static ai_install_by_pkg_fn ai_install_by_package;
|
||||
static ai_title_from_pkg_fn ai_title_from_pkg;
|
||||
static ai_init_fn ai_initialize;
|
||||
static ai_install_pkg_fn ai_install_pkg;
|
||||
static ai_install_by_pkg_fn ai_install_by_package;
|
||||
static ai_title_from_pkg_fn ai_title_from_pkg;
|
||||
static ai_content_from_pkg_fn ai_content_from_pkg;
|
||||
static ai_get_status_fn ai_get_status;
|
||||
|
||||
/* Resolve + initialize the AppInstUtil backend WITHOUT linking the sce libs
|
||||
(that makes the ELF unloadable by the elfldr) and WITHOUT raw
|
||||
@@ -70,11 +113,18 @@ static ai_title_from_pkg_fn ai_title_from_pkg;
|
||||
symbols via the kernel dynlib helpers. Runs in a detached thread; the HTTP
|
||||
handler reports the stage and never blocks.
|
||||
stage: 0 idle, 1 resolve loader, 2 load modules, 3 resolve symbols,
|
||||
4 initialize, 5 ready, negative = failure at that step. */
|
||||
static volatile int g_stage;
|
||||
static int g_err;
|
||||
4 initialize, 5 ready, negative = failure at that step.
|
||||
Stored as _Atomic so the worker's release-store and the request handlers'
|
||||
acquire-loads pair properly — the function pointers they read after
|
||||
stage==5 must not be reordered ahead of the stage check. */
|
||||
static _Atomic int g_stage;
|
||||
static _Atomic int g_err;
|
||||
static pthread_mutex_t g_mtx = PTHREAD_MUTEX_INITIALIZER;
|
||||
static char g_probe_json[2048]; /* filled by the backend thread */
|
||||
static char g_last_content_id[AI_CONTENTID_SIZE];
|
||||
static char g_last_target_title_id[32];
|
||||
static char g_last_method[32];
|
||||
static int g_last_start_rc;
|
||||
|
||||
static intptr_t
|
||||
dynsym(const char *module, const char *sym) {
|
||||
@@ -110,6 +160,63 @@ local_ip(char *out, size_t n) {
|
||||
freeifaddrs(ifa);
|
||||
}
|
||||
|
||||
static void
|
||||
copy_bounded(char *dst, size_t dst_sz, const char *src, size_t src_sz) {
|
||||
size_t n;
|
||||
if (!dst || !dst_sz) return;
|
||||
dst[0] = '\0';
|
||||
if (!src || !src_sz) return;
|
||||
for (n = 0; n + 1 < dst_sz && n < src_sz && src[n]; n++)
|
||||
dst[n] = src[n];
|
||||
dst[n] = '\0';
|
||||
}
|
||||
|
||||
/* Conservative whitelist for ids/filenames that we extract from a local path
|
||||
and inject into URIs/log lines passed to AppInstUtil. Rejects CRLF, '/',
|
||||
'\\', NUL, control chars, anything that could change URI semantics. */
|
||||
static int
|
||||
install_id_safe(const char *s) {
|
||||
if (!s || !s[0]) return 0;
|
||||
for (const char *p = s; *p; p++) {
|
||||
if (!((*p >= 'A' && *p <= 'Z') ||
|
||||
(*p >= 'a' && *p <= 'z') ||
|
||||
(*p >= '0' && *p <= '9') ||
|
||||
*p == '_' || *p == '-' || *p == '.'))
|
||||
return 0;
|
||||
}
|
||||
return 1;
|
||||
}
|
||||
|
||||
/* Exact match for PS4/PS5 title ids (9 chars: 4 letters + 5 digits). A bare
|
||||
strncmp(...,9) would also match longer ids that share a 9-char prefix and
|
||||
could collide PPSA12345 with PPSA12345EVIL. */
|
||||
static int
|
||||
title_id_eq9(const char *a, const char *b) {
|
||||
if (!a || !b) return 0;
|
||||
if (strnlen(a, 16) != 9 || strnlen(b, 16) != 9) return 0;
|
||||
return strncmp(a, b, 9) == 0;
|
||||
}
|
||||
|
||||
static void
|
||||
remember_install(const char *target_title_id, const char *method,
|
||||
const ai_pkg_info_t *pkg, const char *fallback_content_id,
|
||||
int rc) {
|
||||
char cid[AI_CONTENTID_SIZE] = {0};
|
||||
|
||||
if (pkg)
|
||||
copy_bounded(cid, sizeof(cid), pkg->content_id, sizeof(pkg->content_id));
|
||||
if (!cid[0] && fallback_content_id)
|
||||
copy_bounded(cid, sizeof(cid), fallback_content_id, strlen(fallback_content_id));
|
||||
|
||||
pthread_mutex_lock(&g_mtx);
|
||||
snprintf(g_last_content_id, sizeof(g_last_content_id), "%s", cid);
|
||||
snprintf(g_last_target_title_id, sizeof(g_last_target_title_id), "%s",
|
||||
target_title_id ? target_title_id : "");
|
||||
snprintf(g_last_method, sizeof(g_last_method), "%s", method ? method : "");
|
||||
g_last_start_rc = rc;
|
||||
pthread_mutex_unlock(&g_mtx);
|
||||
}
|
||||
|
||||
/* Resolve (dlsym, never call) a list of candidate patch-install symbols and
|
||||
record which exist. Runs inside the backend thread, where the AppInstUtil
|
||||
module is already loaded — the same proven-safe context as the normal symbol
|
||||
@@ -124,6 +231,7 @@ fill_probe(void) {
|
||||
"sceAppInstUtilInstallByPackageEx",
|
||||
"sceAppInstUtilGetTitleIdFromPkg",
|
||||
"sceAppInstUtilGetContentIdFromPkg",
|
||||
"sceAppInstUtilGetInstallStatus",
|
||||
"sceAppInstUtilAppExist",
|
||||
"sceAppInstUtilAppGetInstallStatus",
|
||||
"sceAppInstUtilAppInstallStatus",
|
||||
@@ -205,6 +313,10 @@ backend_init_thread(void *arg) {
|
||||
"sceAppInstUtilInstallByPackage");
|
||||
ai_title_from_pkg = (ai_title_from_pkg_fn)dynsym("libSceAppInstUtil.sprx",
|
||||
"sceAppInstUtilGetTitleIdFromPkg");
|
||||
ai_content_from_pkg = (ai_content_from_pkg_fn)dynsym("libSceAppInstUtil.sprx",
|
||||
"sceAppInstUtilGetContentIdFromPkg");
|
||||
ai_get_status = (ai_get_status_fn)dynsym("libSceAppInstUtil.sprx",
|
||||
"sceAppInstUtilGetInstallStatus");
|
||||
|
||||
/* Read-only feasibility probe — module is loaded, safe context. */
|
||||
fill_probe();
|
||||
@@ -284,6 +396,159 @@ patchdl_install_api_probe(char *out, size_t out_sz) {
|
||||
return -1;
|
||||
}
|
||||
|
||||
/* Read-only: report the .pkg's embedded content id + title id (and whether it
|
||||
is a full app vs a patch). No install, no side effects. 0 if anything read. */
|
||||
int
|
||||
patchdl_install_pkg_meta(const char *local_path, char *content_id, size_t cid_sz,
|
||||
char *title_id, size_t tid_sz, int *is_app,
|
||||
char *msg, size_t msg_sz) {
|
||||
char sdk_path[1024];
|
||||
/* Padded output buffers — Sony's GetContentIdFromPkg / GetTitleIdFromPkg
|
||||
take no length hint; firmware may NUL-pad more than the visible id. */
|
||||
char cid[AI_CONTENTID_OUT_SIZE] = {0};
|
||||
char tid[AI_TITLEID_OUT_SIZE] = {0};
|
||||
int app_c = 0, app_t = 0, ok = 0;
|
||||
struct stat st;
|
||||
|
||||
if (content_id && cid_sz) content_id[0] = '\0';
|
||||
if (title_id && tid_sz) title_id[0] = '\0';
|
||||
if (is_app) *is_app = 0;
|
||||
|
||||
if (!local_path || !local_path[0] || stat(local_path, &st) != 0) {
|
||||
snprintf(msg, msg_sz, "package not on disk");
|
||||
return -1;
|
||||
}
|
||||
backend_start();
|
||||
if (g_stage != 5) {
|
||||
snprintf(msg, msg_sz, "install backend not ready: %s", stage_str(g_stage));
|
||||
return -1;
|
||||
}
|
||||
if (!strncmp(local_path, "/data/", 6))
|
||||
snprintf(sdk_path, sizeof sdk_path, "/user%s", local_path);
|
||||
else
|
||||
snprintf(sdk_path, sizeof sdk_path, "%s", local_path);
|
||||
|
||||
if (ai_content_from_pkg &&
|
||||
ai_content_from_pkg(sdk_path, cid, &app_c) == 0 && cid[0]) {
|
||||
copy_bounded(content_id, cid_sz, cid, sizeof(cid));
|
||||
if (is_app) *is_app = app_c;
|
||||
ok = 1;
|
||||
}
|
||||
if (ai_title_from_pkg &&
|
||||
ai_title_from_pkg(sdk_path, tid, &app_t) == 0 && tid[0]) {
|
||||
copy_bounded(title_id, tid_sz, tid, sizeof(tid));
|
||||
ok = 1;
|
||||
}
|
||||
snprintf(msg, msg_sz, ok ? "ok" : "could not read pkg metadata");
|
||||
return ok ? 0 : -1;
|
||||
}
|
||||
|
||||
void
|
||||
patchdl_install_debug_state(char *out, size_t out_sz) {
|
||||
char cid[AI_CONTENTID_SIZE];
|
||||
char tid[32], method[32];
|
||||
int start_rc;
|
||||
int stage;
|
||||
|
||||
pthread_mutex_lock(&g_mtx);
|
||||
memcpy(cid, g_last_content_id, sizeof(cid));
|
||||
snprintf(tid, sizeof(tid), "%s", g_last_target_title_id);
|
||||
snprintf(method, sizeof(method), "%s", g_last_method);
|
||||
start_rc = g_last_start_rc;
|
||||
stage = g_stage;
|
||||
pthread_mutex_unlock(&g_mtx);
|
||||
|
||||
snprintf(out, out_sz,
|
||||
"{\"stage\":%d,\"cid_len\":%d,\"cid_hex\":\"%02x%02x%02x%02x\","
|
||||
"\"content_id\":\"%s\",\"target_title_id\":\"%s\","
|
||||
"\"method\":\"%s\",\"start_rc\":%d}",
|
||||
stage,
|
||||
(int)strnlen(cid, sizeof(cid)),
|
||||
(unsigned char)cid[0], (unsigned char)cid[1],
|
||||
(unsigned char)cid[2], (unsigned char)cid[3],
|
||||
cid, tid, method, start_rc);
|
||||
}
|
||||
|
||||
int
|
||||
patchdl_install_status_json(char *out, size_t out_sz) {
|
||||
char cid[AI_CONTENTID_SIZE];
|
||||
char tid[32];
|
||||
char method[32];
|
||||
int start_rc;
|
||||
ai_install_status_t st;
|
||||
char status[17], src_type[9];
|
||||
int rc;
|
||||
int progress = 0;
|
||||
int terminal = 0;
|
||||
|
||||
if (!out || !out_sz)
|
||||
return -1;
|
||||
|
||||
backend_start();
|
||||
|
||||
pthread_mutex_lock(&g_mtx);
|
||||
snprintf(cid, sizeof(cid), "%s", g_last_content_id);
|
||||
snprintf(tid, sizeof(tid), "%s", g_last_target_title_id);
|
||||
snprintf(method, sizeof(method), "%s", g_last_method);
|
||||
start_rc = g_last_start_rc;
|
||||
pthread_mutex_unlock(&g_mtx);
|
||||
|
||||
if (!cid[0]) {
|
||||
snprintf(out, out_sz, "{\"active\":false}");
|
||||
return -1;
|
||||
}
|
||||
if (g_stage != 5) {
|
||||
snprintf(out, out_sz,
|
||||
"{\"active\":true,\"content_id\":\"%s\",\"target_title_id\":\"%s\","
|
||||
"\"method\":\"%s\",\"start_rc\":%d,\"status\":\"backend_not_ready\","
|
||||
"\"stage\":\"%s\"}",
|
||||
cid, tid, method, start_rc, stage_str(g_stage));
|
||||
return -1;
|
||||
}
|
||||
if (!ai_get_status) {
|
||||
snprintf(out, out_sz,
|
||||
"{\"active\":true,\"content_id\":\"%s\",\"target_title_id\":\"%s\","
|
||||
"\"method\":\"%s\",\"start_rc\":%d,\"status\":\"unavailable\","
|
||||
"\"message\":\"sceAppInstUtilGetInstallStatus not exported\"}",
|
||||
cid, tid, method, start_rc);
|
||||
return -1;
|
||||
}
|
||||
|
||||
/* sceAppInstUtilGetInstallStatus(char *content_id_out, status_t *status):
|
||||
first arg is an OUTPUT buffer that receives the current install's content_id.
|
||||
Do NOT pass `cid` there — it would be overwritten. The visible id fits in
|
||||
0x30 bytes but Sony's NUL-pad length is unknown; use a padded buffer. */
|
||||
{
|
||||
char ai_cid_out[AI_CONTENTID_OUT_SIZE] = {0};
|
||||
memset(&st, 0, sizeof(st));
|
||||
rc = ai_get_status(ai_cid_out, &st);
|
||||
(void)ai_cid_out; /* returned content_id for future use */
|
||||
}
|
||||
copy_bounded(status, sizeof(status), st.status, sizeof(st.status));
|
||||
copy_bounded(src_type, sizeof(src_type), st.src_type, sizeof(st.src_type));
|
||||
if (st.total_size > 0)
|
||||
progress = (int)((st.downloaded_size * 100) / st.total_size);
|
||||
if (progress < 0) progress = 0;
|
||||
if (progress > 100) progress = 100;
|
||||
terminal = (!strcmp(status, "playable") ||
|
||||
!strcmp(status, "error") ||
|
||||
!strcmp(status, "none"));
|
||||
|
||||
snprintf(out, out_sz,
|
||||
"{\"active\":true,\"terminal\":%s,\"content_id\":\"%s\","
|
||||
"\"target_title_id\":\"%s\",\"method\":\"%s\",\"start_rc\":%d,"
|
||||
"\"rc\":%d,\"status\":\"%s\",\"src_type\":\"%s\","
|
||||
"\"progress\":%d,\"downloaded_size\":%llu,\"total_size\":%llu,"
|
||||
"\"promote_progress\":%u,\"error_code\":%d}",
|
||||
terminal ? "true" : "false", cid, tid, method, start_rc, rc,
|
||||
status, src_type, progress,
|
||||
(unsigned long long)st.downloaded_size,
|
||||
(unsigned long long)st.total_size,
|
||||
(unsigned)st.promote_progress,
|
||||
(int)st.error_info.error_code);
|
||||
return rc;
|
||||
}
|
||||
|
||||
int
|
||||
patchdl_install_local_pkg(const char *local_path, const char *expected_title_id,
|
||||
const char *storage_title_id,
|
||||
@@ -294,7 +559,6 @@ patchdl_install_local_pkg(const char *local_path, const char *expected_title_id,
|
||||
struct stat st;
|
||||
int rc;
|
||||
int pkg_tid_mismatch = 0;
|
||||
const char *last_uri = "";
|
||||
|
||||
if (!local_path || !local_path[0]) {
|
||||
snprintf(msg, msg_sz, "no package path");
|
||||
@@ -311,10 +575,11 @@ patchdl_install_local_pkg(const char *local_path, const char *expected_title_id,
|
||||
return -1;
|
||||
}
|
||||
|
||||
/* AppInstallPkg runs in a sandbox that sees the user partition as
|
||||
/user/data, not /data. InstallByPackage is different: the shell/debug
|
||||
installer path takes the normal /data/... URI, so keep `local_path` for
|
||||
that API and use `sdk_path` only for AppInstallPkg / metadata probes. */
|
||||
/* Sony's installer sees the user partition as /user/data, not /data, and
|
||||
PATH-ALLOWLISTS the URI passed to InstallByPackage: /user/data/ and
|
||||
/mnt/usb are accepted, but a bare /data/... path is REJECTED with
|
||||
0x80B2116F (empirically confirmed by the ps5upload project). So feed the
|
||||
/user/data view of the file to both InstallByPackage and AppInstallPkg. */
|
||||
if (!strncmp(local_path, "/data/", 6))
|
||||
snprintf(sdk_path, sizeof(sdk_path), "/user%s", local_path);
|
||||
else
|
||||
@@ -326,15 +591,20 @@ patchdl_install_local_pkg(const char *local_path, const char *expected_title_id,
|
||||
such packages to the raw AppInstallPkg path. */
|
||||
if (storage_title_id && storage_title_id[0] &&
|
||||
expected_title_id && expected_title_id[0] &&
|
||||
strncmp(storage_title_id, expected_title_id, 9) != 0) {
|
||||
!title_id_eq9(storage_title_id, expected_title_id)) {
|
||||
pkg_tid_mismatch = 1;
|
||||
strncpy(pkg_tid, storage_title_id, sizeof(pkg_tid) - 1);
|
||||
pkg_tid[sizeof(pkg_tid) - 1] = '\0';
|
||||
}
|
||||
if (ai_title_from_pkg && expected_title_id && expected_title_id[0]) {
|
||||
/* Sony's GetTitleIdFromPkg writes into the output buffer with no length
|
||||
hint — pad generously and copy the safe portion into pkg_tid. */
|
||||
char tid_out[AI_TITLEID_OUT_SIZE] = {0};
|
||||
int is_app = 0;
|
||||
if (ai_title_from_pkg(sdk_path, pkg_tid, &is_app) == 0 && pkg_tid[0] &&
|
||||
strncmp(pkg_tid, expected_title_id, 9) != 0) {
|
||||
pkg_tid_mismatch = 1;
|
||||
if (ai_title_from_pkg(sdk_path, tid_out, &is_app) == 0 && tid_out[0]) {
|
||||
if (!title_id_eq9(tid_out, expected_title_id))
|
||||
pkg_tid_mismatch = 1;
|
||||
copy_bounded(pkg_tid, sizeof(pkg_tid), tid_out, sizeof(tid_out));
|
||||
}
|
||||
}
|
||||
if (pkg_tid_mismatch && (!target_content_id || !target_content_id[0])) {
|
||||
@@ -343,23 +613,31 @@ patchdl_install_local_pkg(const char *local_path, const char *expected_title_id,
|
||||
pkg_tid, expected_title_id);
|
||||
return -1;
|
||||
}
|
||||
|
||||
/* Preferred path: InstallByPackage accepts target metadata. Use it first,
|
||||
and use it exclusively when the downloaded bytes report a master/storage
|
||||
title id that differs from the target regional title id. */
|
||||
/* Preferred path: etaHEN's DPI uses InstallByPackage with the installed
|
||||
game's content_id in MetaInfo so AppInstUtil binds the install to the
|
||||
right title slot. For shared-master cross-region packages the pkg bytes
|
||||
carry a different title id than the installed game; passing content_id
|
||||
is what etaHEN does to route the install correctly. */
|
||||
{
|
||||
char file_uri[1100];
|
||||
char http_loop_uri[1200] = {0};
|
||||
char http_lan_uri[1200] = {0};
|
||||
const char *uris[4];
|
||||
ai_meta_info_t meta = {0};
|
||||
ai_pkg_info_t pkg = {0};
|
||||
ai_playgo_info_t playgo = {0};
|
||||
int rc2 = -1;
|
||||
const char *title_dir;
|
||||
const char *file_base;
|
||||
char file_uri[1100];
|
||||
char http_loop_uri[1200] = {0};
|
||||
char http_lan_uri[1200] = {0};
|
||||
const char *uris[4];
|
||||
ai_meta_info_t meta = {0};
|
||||
ai_pkg_info_t pkg = {0};
|
||||
/* playgo is 0x2700 bytes — too big for the MHD worker stack alongside
|
||||
uris, meta, pkg, resp buffers, and Sony's own frame use. */
|
||||
ai_playgo_info_t *playgo = calloc(1, sizeof(*playgo));
|
||||
int rc2 = -1;
|
||||
const char *title_dir;
|
||||
const char *file_base;
|
||||
|
||||
snprintf(file_uri, sizeof(file_uri), "file://%s", local_path);
|
||||
if (!playgo) {
|
||||
snprintf(msg, msg_sz, "out of memory");
|
||||
return -1;
|
||||
}
|
||||
|
||||
snprintf(file_uri, sizeof(file_uri), "file://%s", sdk_path);
|
||||
title_dir = strstr(local_path, "/data/patchdl/");
|
||||
file_base = strrchr(local_path, '/');
|
||||
if (title_dir && file_base && file_base > title_dir + strlen("/data/patchdl/")) {
|
||||
@@ -369,63 +647,180 @@ patchdl_install_local_pkg(const char *local_path, const char *expected_title_id,
|
||||
if (tlen > 0 && tlen < sizeof(title_id)) {
|
||||
char ip[INET_ADDRSTRLEN] = {0};
|
||||
memcpy(title_id, t, tlen);
|
||||
snprintf(http_loop_uri, sizeof(http_loop_uri),
|
||||
"http://127.0.0.1:%d/api/pkg/%s/%s",
|
||||
PATCHDL_HTTP_PORT, title_id, file_base + 1);
|
||||
local_ip(ip, sizeof(ip));
|
||||
if (ip[0])
|
||||
snprintf(http_lan_uri, sizeof(http_lan_uri),
|
||||
"http://%s:%d/api/pkg/%s/%s",
|
||||
ip, PATCHDL_HTTP_PORT, title_id, file_base + 1);
|
||||
/* CRLF/path-injection guard: anything we splice into the loop /
|
||||
LAN URI lands inside Sony's HTTP request line. Reject ids
|
||||
or filenames carrying delimiters or control chars. */
|
||||
if (install_id_safe(title_id) && install_id_safe(file_base + 1)) {
|
||||
snprintf(http_loop_uri, sizeof(http_loop_uri),
|
||||
"http://127.0.0.1:%d/api/pkg/%s/%s",
|
||||
PATCHDL_HTTP_PORT, title_id, file_base + 1);
|
||||
local_ip(ip, sizeof(ip));
|
||||
if (ip[0])
|
||||
snprintf(http_lan_uri, sizeof(http_lan_uri),
|
||||
"http://%s:%d/api/pkg/%s/%s",
|
||||
ip, PATCHDL_HTTP_PORT, title_id, file_base + 1);
|
||||
}
|
||||
}
|
||||
}
|
||||
uris[0] = local_path;
|
||||
uris[1] = file_uri;
|
||||
uris[0] = sdk_path; /* /user/data/... — the allowlisted path */
|
||||
uris[1] = file_uri; /* file:///user/data/... */
|
||||
uris[2] = http_loop_uri[0] ? http_loop_uri : NULL;
|
||||
uris[3] = http_lan_uri[0] ? http_lan_uri : NULL;
|
||||
meta.ex_uri = "";
|
||||
meta.playgo_scenario_id = "";
|
||||
meta.content_id = target_content_id ? target_content_id : "";
|
||||
/* For cross-region shared-master packages pass the installed game's
|
||||
content_id so AppInstUtil binds the download to the right title. */
|
||||
meta.content_id = (pkg_tid_mismatch &&
|
||||
target_content_id && target_content_id[0])
|
||||
? target_content_id : "";
|
||||
meta.content_name = "PatchDL";
|
||||
meta.icon_url = "";
|
||||
|
||||
for (int i = 0; i < 4; i++) {
|
||||
if (!uris[i]) continue;
|
||||
memset(&pkg, 0, sizeof(pkg));
|
||||
memset(&playgo, 0, sizeof(playgo));
|
||||
meta.uri = uris[i];
|
||||
last_uri = uris[i];
|
||||
rc2 = ai_install_by_package(&meta, &pkg, &playgo);
|
||||
if (rc2 == 0) {
|
||||
snprintf(msg, msg_sz, "install started (InstallByPackage%s)",
|
||||
pkg_tid_mismatch ? ", shared master bytes" : "");
|
||||
return 0;
|
||||
{
|
||||
char tries[260] = {0};
|
||||
const char *labels[4] = { "userdata", "file", "loop", "lan" };
|
||||
for (int i = 0; i < 4; i++) {
|
||||
if (!uris[i]) continue;
|
||||
memset(&pkg, 0, sizeof(pkg));
|
||||
memset(playgo, 0, sizeof(*playgo));
|
||||
meta.uri = uris[i];
|
||||
rc2 = ai_install_by_package(&meta, &pkg, playgo);
|
||||
{
|
||||
size_t l = strlen(tries);
|
||||
snprintf(tries + l, sizeof(tries) - l, "%s%s=0x%08x",
|
||||
l ? "," : "", labels[i], (unsigned)rc2);
|
||||
}
|
||||
if (rc2 == 0) {
|
||||
remember_install(expected_title_id, "InstallByPackage",
|
||||
&pkg, target_content_id, rc2);
|
||||
snprintf(msg, msg_sz, "install started (InstallByPackage, content %.47s)",
|
||||
pkg.content_id[0] ? pkg.content_id :
|
||||
(target_content_id ? target_content_id : ""));
|
||||
free(playgo);
|
||||
return 0;
|
||||
}
|
||||
}
|
||||
rc = rc2;
|
||||
}
|
||||
rc = rc2;
|
||||
free(playgo);
|
||||
}
|
||||
|
||||
if (pkg_tid_mismatch) {
|
||||
snprintf(msg, msg_sz,
|
||||
"install rejected (InstallByPackage=0x%08x, pkg %.12s, target %.12s, uri %.96s)",
|
||||
(unsigned)rc, pkg_tid, expected_title_id ? expected_title_id : "",
|
||||
last_uri);
|
||||
return rc ? rc : -1;
|
||||
}
|
||||
|
||||
/* Last resort for normal same-title packages only. This path has no target
|
||||
metadata parameter, so it is intentionally skipped for shared-master
|
||||
region bytes. */
|
||||
/* AppInstallPkg: simpler API, no MetaInfo content_id override. Tried for
|
||||
all packages including cross-region, since it may have different
|
||||
privilege requirements than InstallByPackage. For shared-master packages
|
||||
it will bind to the pkg's own embedded title, not the expected_title_id,
|
||||
so treat success with caution; also report the complete error set. */
|
||||
{
|
||||
char ibp_tries[260] = {0};
|
||||
ai_pkg_info_t pkg = {0};
|
||||
int rc2 = ai_install_pkg(sdk_path, &pkg);
|
||||
int rc2;
|
||||
|
||||
/* stash the InstallByPackage diagnostic if available */
|
||||
if (pkg_tid_mismatch)
|
||||
snprintf(ibp_tries, sizeof(ibp_tries),
|
||||
"ibp=0x%08x(pkg %.12s->%.12s)",
|
||||
(unsigned)rc, pkg_tid,
|
||||
expected_title_id ? expected_title_id : "");
|
||||
|
||||
rc2 = ai_install_pkg(sdk_path, &pkg);
|
||||
if (rc2 == 0) {
|
||||
snprintf(msg, msg_sz, "install started (AppInstallPkg)");
|
||||
remember_install(expected_title_id, "AppInstallPkg",
|
||||
&pkg, target_content_id, rc2);
|
||||
snprintf(msg, msg_sz, "install started (AppInstallPkg, content %.47s%s%s)",
|
||||
pkg.content_id[0] ? pkg.content_id :
|
||||
(target_content_id ? target_content_id : ""),
|
||||
ibp_tries[0] ? " " : "", ibp_tries);
|
||||
return 0;
|
||||
}
|
||||
snprintf(msg, msg_sz,
|
||||
"install rejected (InstallByPackage=0x%08x, AppInstallPkg=0x%08x)",
|
||||
(unsigned)rc, (unsigned)rc2);
|
||||
if (pkg_tid_mismatch)
|
||||
snprintf(msg, msg_sz,
|
||||
"install rejected (pkg %.12s->%.12s ibp=0x%08x aip=0x%08x)",
|
||||
pkg_tid, expected_title_id ? expected_title_id : "",
|
||||
(unsigned)rc, (unsigned)rc2);
|
||||
else
|
||||
snprintf(msg, msg_sz,
|
||||
"install rejected (InstallByPackage=0x%08x, AppInstallPkg=0x%08x)",
|
||||
(unsigned)rc, (unsigned)rc2);
|
||||
return rc2 ? rc2 : (rc ? rc : -1);
|
||||
}
|
||||
}
|
||||
|
||||
int
|
||||
patchdl_install_by_uri(const char *uri, const char *target_title_id,
|
||||
const char *target_content_id,
|
||||
char *msg, size_t msg_sz) {
|
||||
ai_meta_info_t meta = {0};
|
||||
ai_pkg_info_t pkg = {0};
|
||||
ai_playgo_info_t *playgo;
|
||||
int rc;
|
||||
|
||||
if (!uri || !uri[0]) {
|
||||
snprintf(msg, msg_sz, "no uri");
|
||||
return -1;
|
||||
}
|
||||
backend_start();
|
||||
if (g_stage != 5) {
|
||||
snprintf(msg, msg_sz, "install backend not ready: %s", stage_str(g_stage));
|
||||
return -1;
|
||||
}
|
||||
playgo = calloc(1, sizeof(*playgo));
|
||||
if (!playgo) { snprintf(msg, msg_sz, "out of memory"); return -1; }
|
||||
|
||||
meta.uri = uri;
|
||||
meta.ex_uri = "";
|
||||
meta.playgo_scenario_id = "";
|
||||
meta.content_id = target_content_id ? target_content_id : "";
|
||||
meta.content_name = "PatchDL";
|
||||
meta.icon_url = "";
|
||||
|
||||
rc = ai_install_by_package(&meta, &pkg, playgo);
|
||||
remember_install(target_title_id, "InstallByURI", &pkg, target_content_id, rc);
|
||||
free(playgo);
|
||||
|
||||
if (rc == 0) {
|
||||
snprintf(msg, msg_sz, "install started (InstallByPackage/uri, content %.47s)",
|
||||
pkg.content_id[0] ? pkg.content_id :
|
||||
(target_content_id ? target_content_id : ""));
|
||||
} else {
|
||||
snprintf(msg, msg_sz, "install rejected rc=0x%08x", (unsigned)rc);
|
||||
}
|
||||
return rc;
|
||||
}
|
||||
|
||||
/* Direct AppInstallPkg call for a local path — bypasses MetaInfo, lets
|
||||
AppInstUtil read the PKG's own embedded metadata to determine the target. */
|
||||
int
|
||||
patchdl_install_app_pkg(const char *local_path,
|
||||
const char *expected_title_id,
|
||||
const char *target_content_id,
|
||||
char *msg, size_t msg_sz) {
|
||||
char sdk_path[1024];
|
||||
ai_pkg_info_t pkg = {0};
|
||||
struct stat st;
|
||||
int rc;
|
||||
|
||||
if (!local_path || !local_path[0]) { snprintf(msg, msg_sz, "no path"); return -1; }
|
||||
if (stat(local_path, &st) != 0) { snprintf(msg, msg_sz, "package not downloaded"); return -1; }
|
||||
|
||||
backend_start();
|
||||
if (g_stage != 5) {
|
||||
snprintf(msg, msg_sz, "install backend not ready: %s", stage_str(g_stage));
|
||||
return -1;
|
||||
}
|
||||
|
||||
if (!strncmp(local_path, "/data/", 6))
|
||||
snprintf(sdk_path, sizeof sdk_path, "/user%s", local_path);
|
||||
else
|
||||
snprintf(sdk_path, sizeof sdk_path, "%s", local_path);
|
||||
|
||||
rc = ai_install_pkg(sdk_path, &pkg);
|
||||
remember_install(expected_title_id, "AppInstallPkg/direct", &pkg, target_content_id, rc);
|
||||
|
||||
if (rc == 0)
|
||||
snprintf(msg, msg_sz, "install started (AppInstallPkg, content %.47s)",
|
||||
pkg.content_id[0] ? pkg.content_id :
|
||||
(target_content_id ? target_content_id : ""));
|
||||
else
|
||||
snprintf(msg, msg_sz, "install rejected rc=0x%08x", (unsigned)rc);
|
||||
return rc;
|
||||
}
|
||||
+36
-3
@@ -14,9 +14,10 @@
|
||||
*/
|
||||
/* `expected_title_id` is the title id of the installed game the patch is for.
|
||||
`storage_title_id` is the title id embedded in the delta_url storage path.
|
||||
`target_content_id` is the installed game's content id from app.db; when
|
||||
present it is passed to InstallByPackage so Sony's installer has the target
|
||||
metadata even for region-shared/master-storage patch bytes. */
|
||||
`target_content_id` is the installed game's content id from app.db; it is
|
||||
retained for diagnostics and status fallback. Normal same-title installs
|
||||
deliberately pass an empty MetaInfo.content_id, matching etaHEN's native DPI
|
||||
path and letting AppInstUtil bind the package to its signed metadata. */
|
||||
int patchdl_install_local_pkg(const char *local_path,
|
||||
const char *expected_title_id,
|
||||
const char *storage_title_id,
|
||||
@@ -31,3 +32,35 @@ int patchdl_install_backend_check(char *msg, size_t msg_sz);
|
||||
AppInstUtil/Bgft patch-install symbols and report which exist on this
|
||||
firmware. Writes a JSON object into `out`. No install, no side effects. */
|
||||
int patchdl_install_api_probe(char *out, size_t out_sz);
|
||||
|
||||
/* Read-only: report the .pkg's embedded content id + title id (and whether it
|
||||
is a full app vs a patch, via *is_app). No install. 0 if anything was read. */
|
||||
int patchdl_install_pkg_meta(const char *local_path, char *content_id, size_t cid_sz,
|
||||
char *title_id, size_t tid_sz, int *is_app,
|
||||
char *msg, size_t msg_sz);
|
||||
|
||||
/* Read-only: report the last AppInstUtil install task PatchDL started, using
|
||||
sceAppInstUtilGetInstallStatus when present. No install, no mutation. */
|
||||
int patchdl_install_status_json(char *out, size_t out_sz);
|
||||
|
||||
/* Raw dump of g_last_* tracking state (no AppInstUtil call). For diagnosis. */
|
||||
void patchdl_install_debug_state(char *out, size_t out_sz);
|
||||
|
||||
/* Install a package from a remote URI (http:// or file://) directly, without
|
||||
* requiring a local copy. Used for shared-master delta packages where the
|
||||
* version.xml targets a different title id than the CDN storage path.
|
||||
* `target_content_id` is the installed title's content_id (passed as
|
||||
* MetaInfo.content_id so AppInstUtil binds the install to the right title).
|
||||
*/
|
||||
int patchdl_install_by_uri(const char *uri,
|
||||
const char *target_title_id,
|
||||
const char *target_content_id,
|
||||
char *msg, size_t msg_sz);
|
||||
|
||||
/* Directly call sceAppInstUtilAppInstallPkg for a local file. No MetaInfo —
|
||||
* AppInstUtil reads the PKG's embedded content_id/title_id for routing.
|
||||
* Use when InstallByPackage is unavailable (privilege). */
|
||||
int patchdl_install_app_pkg(const char *local_path,
|
||||
const char *expected_title_id,
|
||||
const char *target_content_id,
|
||||
char *msg, size_t msg_sz);
|
||||
+497
-65
@@ -2,6 +2,7 @@
|
||||
|
||||
#include <arpa/inet.h>
|
||||
#include <errno.h>
|
||||
#include <fcntl.h>
|
||||
#include <netinet/in.h>
|
||||
#include <pthread.h>
|
||||
#include <stdio.h>
|
||||
@@ -9,6 +10,7 @@
|
||||
#include <string.h>
|
||||
#include <strings.h>
|
||||
#include <sys/socket.h>
|
||||
#include <sys/stat.h>
|
||||
#include <sys/time.h>
|
||||
#include <unistd.h>
|
||||
|
||||
@@ -22,6 +24,32 @@
|
||||
#define DNS_PORT 53
|
||||
#define DNS_TIMEOUT_MS 3000
|
||||
|
||||
/* Manifest sanity caps — reject anything bigger than a real PS5 patch. The
|
||||
largest title we've seen tops out around 70 GB / 18 pieces. */
|
||||
#define PATCHDL_MAX_PIECES 4096
|
||||
#define PATCHDL_MAX_PIECE_BYTES (8ULL * 1024 * 1024 * 1024) /* 8 GiB */
|
||||
#define PATCHDL_MAX_TOTAL_BYTES (200ULL * 1024 * 1024 * 1024) /* 200 GiB */
|
||||
|
||||
/* In-RAM buffer caps for full HTTP body fetches. version.xml is a few KB,
|
||||
manifest JSON is a few MB at most — fail-closed beyond that. */
|
||||
#define PATCHDL_BUF_MAX_VERXML (16 * 1024 * 1024)
|
||||
#define PATCHDL_BUF_MAX_MANIFEST (64 * 1024 * 1024)
|
||||
|
||||
#ifdef PATCHDL_HAVE_CURL
|
||||
/* Replacement for fopen("wb"/"r+b") that refuses to follow a symlink at the
|
||||
destination (would let a malicious symlink redirect the download) and pins
|
||||
the new file's mode to 0600. Returns NULL on any open error. */
|
||||
static FILE *
|
||||
fopen_safe(const char *path, int rw_existing) {
|
||||
int flags = O_CLOEXEC | O_NOFOLLOW;
|
||||
int fd;
|
||||
flags |= rw_existing ? O_RDWR : (O_WRONLY | O_CREAT | O_TRUNC);
|
||||
fd = open(path, flags, 0600);
|
||||
if (fd < 0) return NULL;
|
||||
return fdopen(fd, rw_existing ? "r+b" : "wb");
|
||||
}
|
||||
#endif
|
||||
|
||||
#ifdef PATCHDL_HAVE_CURL
|
||||
|
||||
static const char *ALLOWED_HOSTS[] = {
|
||||
@@ -35,13 +63,15 @@ static const char *ALLOWED_HOSTS[] = {
|
||||
static int
|
||||
host_allowed(const char *host) {
|
||||
size_t hlen = strlen(host);
|
||||
/* DNS is case-insensitive; an upstream redirect to "SGST.prod..." would
|
||||
otherwise drop out of the allowlist. */
|
||||
for (int i = 0; ALLOWED_HOSTS[i]; i++) {
|
||||
if (!strcmp(host, ALLOWED_HOSTS[i]))
|
||||
if (!strcasecmp(host, ALLOWED_HOSTS[i]))
|
||||
return 1;
|
||||
size_t alen = strlen(ALLOWED_HOSTS[i]);
|
||||
if (hlen > alen + 1 &&
|
||||
host[hlen - alen - 1] == '.' &&
|
||||
!strcmp(host + hlen - alen, ALLOWED_HOSTS[i]))
|
||||
!strcasecmp(host + hlen - alen, ALLOWED_HOSTS[i]))
|
||||
return 1;
|
||||
}
|
||||
return 0;
|
||||
@@ -145,6 +175,10 @@ dns_resolve(const char *host, char *ip_out, size_t ip_sz) {
|
||||
while (pos < (size_t)n) {
|
||||
if (!resp[pos]) { pos++; break; }
|
||||
if ((resp[pos] & 0xC0) == 0xC0) { pos += 2; break; }
|
||||
/* Bounds-check the label length BEFORE the increment — a malformed
|
||||
response with a 0xFF label byte near the end would otherwise walk
|
||||
past `n`. */
|
||||
if (pos + 1 + (size_t)resp[pos] >= (size_t)n) { g_dns_step = 5; return -1; }
|
||||
pos += 1 + resp[pos];
|
||||
}
|
||||
if (pos + 4 > (size_t)n) { g_dns_step = 5; return -1; }
|
||||
@@ -156,8 +190,10 @@ dns_resolve(const char *host, char *ip_out, size_t ip_sz) {
|
||||
if ((resp[pos] & 0xC0) == 0xC0) {
|
||||
pos += 2;
|
||||
} else {
|
||||
while (pos < (size_t)n && resp[pos])
|
||||
while (pos < (size_t)n && resp[pos]) {
|
||||
if (pos + 1 + (size_t)resp[pos] >= (size_t)n) break;
|
||||
pos += 1 + resp[pos];
|
||||
}
|
||||
pos++;
|
||||
}
|
||||
if (pos + 10 > (size_t)n) break;
|
||||
@@ -198,14 +234,14 @@ dns_lookup(const char *host, char *ip_out, size_t ip_sz) {
|
||||
return 0;
|
||||
}
|
||||
}
|
||||
pthread_mutex_unlock(&dns_cache_mtx);
|
||||
|
||||
/* Cold miss: resolve while HOLDING the cache lock (single-flight). N pool
|
||||
workers needing the same CDN host would otherwise each blast Sony's
|
||||
rate-limited resolver; this way one resolves and the rest get the cache.
|
||||
It also serializes dns_resolve so its diagnostic globals can't be raced.
|
||||
(This is the DNS lock, independent of the pool lock.) */
|
||||
for (int attempt = 0; attempt < 4 && rc; attempt++)
|
||||
rc = dns_resolve(host, ip_out, ip_sz);
|
||||
if (rc) return -1;
|
||||
|
||||
pthread_mutex_lock(&dns_cache_mtx);
|
||||
if (dns_cache_n < (int)(sizeof(dns_cache) / sizeof(dns_cache[0]))) {
|
||||
if (!rc && dns_cache_n < (int)(sizeof(dns_cache) / sizeof(dns_cache[0]))) {
|
||||
strncpy(dns_cache[dns_cache_n].host, host,
|
||||
sizeof(dns_cache[0].host) - 1);
|
||||
strncpy(dns_cache[dns_cache_n].ip, ip_out,
|
||||
@@ -213,7 +249,7 @@ dns_lookup(const char *host, char *ip_out, size_t ip_sz) {
|
||||
dns_cache_n++;
|
||||
}
|
||||
pthread_mutex_unlock(&dns_cache_mtx);
|
||||
return 0;
|
||||
return rc;
|
||||
}
|
||||
|
||||
/* ---------- HTTP GET via curl ------------------------------------------- */
|
||||
@@ -222,7 +258,12 @@ static size_t
|
||||
write_cb(void *ptr, size_t size, size_t nmemb, void *userdata) {
|
||||
patchdl_buf_t *b = userdata;
|
||||
size_t total = size * nmemb;
|
||||
char *newp = realloc(b->data, b->size + total + 1);
|
||||
char *newp;
|
||||
/* Overflow guard before the cap check (b->size+total may wrap on 32-bit). */
|
||||
if (total > (size_t)-1 - b->size - 1) return 0;
|
||||
/* Cap accumulation so a hostile CDN can't drive unbounded RAM growth. */
|
||||
if (b->max && b->size + total > b->max) return 0;
|
||||
newp = realloc(b->data, b->size + total + 1);
|
||||
if (!newp) return 0;
|
||||
b->data = newp;
|
||||
memcpy(b->data + b->size, ptr, total);
|
||||
@@ -252,7 +293,11 @@ patchdl_http_get(const char *url, patchdl_buf_t *out) {
|
||||
snprintf(resolve_80, sizeof(resolve_80), "%s:80:%s", host, ip);
|
||||
resolve_list = curl_slist_append(resolve_list, resolve_80);
|
||||
|
||||
memset(out, 0, sizeof(*out));
|
||||
{
|
||||
size_t caller_max = out->max;
|
||||
memset(out, 0, sizeof(*out));
|
||||
out->max = caller_max;
|
||||
}
|
||||
|
||||
curl = curl_easy_init();
|
||||
if (!curl) { curl_slist_free_all(resolve_list); return -1; }
|
||||
@@ -277,6 +322,12 @@ patchdl_http_get(const char *url, patchdl_buf_t *out) {
|
||||
curl_easy_setopt(curl, CURLOPT_TIMEOUT, 15L);
|
||||
curl_easy_setopt(curl, CURLOPT_FOLLOWLOCATION, 1L);
|
||||
curl_easy_setopt(curl, CURLOPT_MAXREDIRS, 3L);
|
||||
/* Redirects must stay on HTTPS — host_allowed gates the initial URL, but
|
||||
once libcurl follows a 302 we want the protocol pinned too. The _STR
|
||||
variants replaced the bitfield options in libcurl 7.85. */
|
||||
curl_easy_setopt(curl, CURLOPT_PROTOCOLS_STR, "https");
|
||||
curl_easy_setopt(curl, CURLOPT_REDIR_PROTOCOLS_STR, "https");
|
||||
curl_easy_setopt(curl, CURLOPT_NOSIGNAL, 1L);
|
||||
curl_easy_setopt(curl, CURLOPT_USERAGENT, "patchdl/1.0");
|
||||
|
||||
res = curl_easy_perform(curl);
|
||||
@@ -344,14 +395,20 @@ curl_progress_cb(void *clientp, curl_off_t dltotal, curl_off_t dlnow,
|
||||
}
|
||||
|
||||
/* Returns 0 on success, -1 on download/network failure, -2 when an expected
|
||||
SHA-256 was given and the downloaded bytes did not match it. */
|
||||
SHA-256 was given and the downloaded bytes did not match it, -3 when a byte
|
||||
range was requested (range_start>0) but the server ignored it (no HTTP 206).
|
||||
When range_start>0 the body is appended at the file's current position, so
|
||||
the caller must have it positioned at range_start and must not verify. */
|
||||
static int
|
||||
http_download_to_file_progress(const char *url, FILE *fp, long long *bytes_out,
|
||||
progress_state_t *progress,
|
||||
const char *expected_sha256_hex) {
|
||||
const char *expected_sha256_hex,
|
||||
long long range_start) {
|
||||
CURL *curl;
|
||||
CURLcode res;
|
||||
char host[256], ip[INET_ADDRSTRLEN], rs443[512], rs80[512];
|
||||
char range_hdr[48];
|
||||
long http_code = 0;
|
||||
struct curl_slist *rl = NULL;
|
||||
struct curl_blob ca_blob;
|
||||
curl_off_t dl = 0;
|
||||
@@ -395,11 +452,18 @@ http_download_to_file_progress(const char *url, FILE *fp, long long *bytes_out,
|
||||
curl_easy_setopt(curl, CURLOPT_SSL_CIPHER_LIST, "DEFAULT@SECLEVEL=0");
|
||||
curl_easy_setopt(curl, CURLOPT_FOLLOWLOCATION, 1L);
|
||||
curl_easy_setopt(curl, CURLOPT_MAXREDIRS, 5L);
|
||||
curl_easy_setopt(curl, CURLOPT_PROTOCOLS_STR, "https");
|
||||
curl_easy_setopt(curl, CURLOPT_REDIR_PROTOCOLS_STR, "https");
|
||||
curl_easy_setopt(curl, CURLOPT_NOSIGNAL, 1L);
|
||||
curl_easy_setopt(curl, CURLOPT_CONNECTTIMEOUT, 20L);
|
||||
/* No total timeout (patches can be large); abort only on a long stall. */
|
||||
curl_easy_setopt(curl, CURLOPT_LOW_SPEED_LIMIT, 1024L);
|
||||
curl_easy_setopt(curl, CURLOPT_LOW_SPEED_TIME, 30L);
|
||||
curl_easy_setopt(curl, CURLOPT_USERAGENT, "patchdl/1.0");
|
||||
if (range_start > 0) {
|
||||
snprintf(range_hdr, sizeof(range_hdr), "%lld-", range_start);
|
||||
curl_easy_setopt(curl, CURLOPT_RANGE, range_hdr);
|
||||
}
|
||||
if (progress && progress->cb) {
|
||||
curl_easy_setopt(curl, CURLOPT_NOPROGRESS, 0L);
|
||||
curl_easy_setopt(curl, CURLOPT_XFERINFOFUNCTION, curl_progress_cb);
|
||||
@@ -407,6 +471,7 @@ http_download_to_file_progress(const char *url, FILE *fp, long long *bytes_out,
|
||||
}
|
||||
|
||||
res = curl_easy_perform(curl);
|
||||
curl_easy_getinfo(curl, CURLINFO_RESPONSE_CODE, &http_code);
|
||||
curl_easy_getinfo(curl, CURLINFO_SIZE_DOWNLOAD_T, &dl);
|
||||
curl_easy_cleanup(curl);
|
||||
curl_slist_free_all(rl);
|
||||
@@ -415,13 +480,22 @@ http_download_to_file_progress(const char *url, FILE *fp, long long *bytes_out,
|
||||
if (sink.md) EVP_MD_CTX_free(sink.md);
|
||||
return -1;
|
||||
}
|
||||
/* Asked for a byte range but the server sent the whole file (no 206): the
|
||||
caller must drop the piece and re-fetch it whole. */
|
||||
if (range_start > 0 && http_code != 206) {
|
||||
if (sink.md) EVP_MD_CTX_free(sink.md);
|
||||
return -3;
|
||||
}
|
||||
|
||||
if (sink.md) {
|
||||
unsigned char dig[EVP_MAX_MD_SIZE];
|
||||
unsigned int dlen = 0;
|
||||
char hex[2 * EVP_MAX_MD_SIZE + 1];
|
||||
EVP_DigestFinal_ex(sink.md, dig, &dlen);
|
||||
int ok = EVP_DigestFinal_ex(sink.md, dig, &dlen);
|
||||
EVP_MD_CTX_free(sink.md);
|
||||
/* Fail-closed on a digest API failure — otherwise hex would be empty
|
||||
and we'd silently report -2 with no diagnostic. */
|
||||
if (ok != 1 || dlen == 0) return -2;
|
||||
hex_encode(dig, dlen, hex, sizeof(hex));
|
||||
if (strcasecmp(hex, expected_sha256_hex) != 0)
|
||||
return -2; /* integrity mismatch */
|
||||
@@ -435,12 +509,12 @@ int
|
||||
patchdl_http_download_progress(const char *url, const char *dest_path,
|
||||
long long *bytes_out,
|
||||
patchdl_download_progress_cb cb, void *ctx) {
|
||||
FILE *fp = fopen(dest_path, "wb");
|
||||
FILE *fp = fopen_safe(dest_path, 0);
|
||||
progress_state_t progress = { cb, ctx, 0, 0 };
|
||||
int rc;
|
||||
|
||||
if (!fp) return -1;
|
||||
rc = http_download_to_file_progress(url, fp, bytes_out, &progress, NULL);
|
||||
rc = http_download_to_file_progress(url, fp, bytes_out, &progress, NULL, 0);
|
||||
fclose(fp);
|
||||
|
||||
if (rc) {
|
||||
@@ -456,8 +530,24 @@ patchdl_http_download(const char *url, const char *dest_path,
|
||||
return patchdl_http_download_progress(url, dest_path, bytes_out, NULL, NULL);
|
||||
}
|
||||
|
||||
/* Substring scan bounded to [p, limit). NULL limit means search to NUL.
|
||||
Returns NULL if needle is not found before limit. */
|
||||
static const char *
|
||||
strstr_bounded(const char *p, const char *needle, const char *limit) {
|
||||
const char *hit = strstr(p, needle);
|
||||
if (!hit) return NULL;
|
||||
if (limit && hit >= limit) return NULL;
|
||||
return hit;
|
||||
}
|
||||
|
||||
/* Read "key": "value" starting from p. Search and read are bounded by `limit`
|
||||
(pass NULL to search to end of buffer). Decodes \\ \" \/ \n \r \t \b \f; any
|
||||
other \X is copied without the backslash. \uXXXX is left as the raw 6 bytes
|
||||
(we don't need Unicode for manifest fields). limit==NULL keeps legacy
|
||||
end-of-string scope for callers that don't need the cap. */
|
||||
static int
|
||||
json_string_after(const char *p, const char *key, char *out, size_t out_sz) {
|
||||
json_string_after(const char *p, const char *key, char *out, size_t out_sz,
|
||||
const char *limit) {
|
||||
char needle[48];
|
||||
const char *q;
|
||||
size_t n = 0;
|
||||
@@ -465,35 +555,59 @@ json_string_after(const char *p, const char *key, char *out, size_t out_sz) {
|
||||
if (!p || !out || out_sz == 0) return -1;
|
||||
out[0] = '\0';
|
||||
snprintf(needle, sizeof(needle), "\"%s\"", key);
|
||||
q = strstr(p, needle);
|
||||
q = strstr_bounded(p, needle, limit);
|
||||
if (!q) return -1;
|
||||
q += strlen(needle);
|
||||
while (*q == ' ' || *q == '\t' || *q == '\r' || *q == '\n') q++;
|
||||
while ((!limit || q < limit) &&
|
||||
(*q == ' ' || *q == '\t' || *q == '\r' || *q == '\n')) q++;
|
||||
if (limit && q >= limit) return -1;
|
||||
if (*q++ != ':') return -1;
|
||||
while (*q == ' ' || *q == '\t' || *q == '\r' || *q == '\n') q++;
|
||||
while ((!limit || q < limit) &&
|
||||
(*q == ' ' || *q == '\t' || *q == '\r' || *q == '\n')) q++;
|
||||
if (limit && q >= limit) return -1;
|
||||
if (*q++ != '"') return -1;
|
||||
|
||||
while (*q && *q != '"' && n + 1 < out_sz) {
|
||||
if (*q == '\\' && q[1]) q++;
|
||||
out[n++] = *q++;
|
||||
while ((!limit || q < limit) && *q && *q != '"' && n + 1 < out_sz) {
|
||||
if (*q == '\\' && q[1] && (!limit || q + 1 < limit)) {
|
||||
q++;
|
||||
switch (*q) {
|
||||
case '"': out[n++] = '"'; break;
|
||||
case '\\': out[n++] = '\\'; break;
|
||||
case '/': out[n++] = '/'; break;
|
||||
case 'n': out[n++] = '\n'; break;
|
||||
case 'r': out[n++] = '\r'; break;
|
||||
case 't': out[n++] = '\t'; break;
|
||||
case 'b': out[n++] = '\b'; break;
|
||||
case 'f': out[n++] = '\f'; break;
|
||||
default: out[n++] = *q; break; /* unknown escape: keep payload */
|
||||
}
|
||||
q++;
|
||||
} else {
|
||||
out[n++] = *q++;
|
||||
}
|
||||
}
|
||||
out[n] = '\0';
|
||||
return n ? 0 : -1;
|
||||
}
|
||||
|
||||
static int
|
||||
json_u64_after(const char *p, const char *key, unsigned long long *out) {
|
||||
json_u64_after(const char *p, const char *key, unsigned long long *out,
|
||||
const char *limit) {
|
||||
char needle[48];
|
||||
const char *q;
|
||||
|
||||
if (!p || !out) return -1;
|
||||
snprintf(needle, sizeof(needle), "\"%s\"", key);
|
||||
q = strstr(p, needle);
|
||||
q = strstr_bounded(p, needle, limit);
|
||||
if (!q) return -1;
|
||||
q += strlen(needle);
|
||||
while (*q == ' ' || *q == '\t' || *q == '\r' || *q == '\n') q++;
|
||||
while ((!limit || q < limit) &&
|
||||
(*q == ' ' || *q == '\t' || *q == '\r' || *q == '\n')) q++;
|
||||
if (limit && q >= limit) return -1;
|
||||
if (*q++ != ':') return -1;
|
||||
while (*q == ' ' || *q == '\t' || *q == '\r' || *q == '\n') q++;
|
||||
while ((!limit || q < limit) &&
|
||||
(*q == ' ' || *q == '\t' || *q == '\r' || *q == '\n')) q++;
|
||||
if (limit && q >= limit) return -1;
|
||||
if (*q < '0' || *q > '9') return -1;
|
||||
*out = strtoull(q, NULL, 10);
|
||||
return 0;
|
||||
@@ -504,17 +618,17 @@ patchdl_http_download_manifest_progress(const char *manifest_url,
|
||||
const char *dest_path,
|
||||
long long *bytes_out,
|
||||
patchdl_download_progress_cb cb,
|
||||
void *ctx, int verify) {
|
||||
void *ctx, int verify, int resume) {
|
||||
patchdl_buf_t manifest;
|
||||
const char *pieces;
|
||||
const char *p;
|
||||
FILE *fp;
|
||||
long long total = 0;
|
||||
const char *pieces, *pieces_end, *p;
|
||||
FILE *fp = NULL;
|
||||
long long total = 0, have = 0;
|
||||
unsigned long long manifest_total = 0;
|
||||
int count = 0;
|
||||
int rc = -1;
|
||||
int count = 0, started, rc = -1;
|
||||
|
||||
if (bytes_out) *bytes_out = 0;
|
||||
memset(&manifest, 0, sizeof(manifest));
|
||||
manifest.max = PATCHDL_BUF_MAX_MANIFEST;
|
||||
if (patchdl_http_get(manifest_url, &manifest))
|
||||
return -1;
|
||||
if (!manifest.data || !manifest.size) {
|
||||
@@ -529,52 +643,113 @@ patchdl_http_download_manifest_progress(const char *manifest_url,
|
||||
}
|
||||
/* Bound the scan to the pieces array; otherwise a later "url" key in the
|
||||
manifest (e.g. playgoChunkCrcUrl) could be appended as a bogus piece. */
|
||||
const char *pieces_end = strchr(pieces, ']');
|
||||
json_u64_after(manifest.data, "originalFileSize", &manifest_total);
|
||||
pieces_end = strchr(pieces, ']');
|
||||
json_u64_after(manifest.data, "originalFileSize", &manifest_total, NULL);
|
||||
|
||||
fp = fopen(dest_path, "wb");
|
||||
if (!fp) {
|
||||
free(manifest.data);
|
||||
return -1;
|
||||
/* Resume: reopen the existing partial and keep its bytes; else start clean.
|
||||
Fully-downloaded pieces are skipped; the one piece that was only partially
|
||||
written continues mid-piece via an HTTP byte range (with a fall back to
|
||||
re-fetching it whole if the CDN ignores the range). */
|
||||
if (resume) {
|
||||
fp = fopen_safe(dest_path, 1);
|
||||
if (fp) { fseek(fp, 0, SEEK_END); have = ftell(fp); if (have < 0) have = 0; }
|
||||
}
|
||||
if (!fp) { fp = fopen_safe(dest_path, 0); have = 0; }
|
||||
if (!fp) { free(manifest.data); return -1; }
|
||||
started = (have <= 0);
|
||||
|
||||
p = pieces;
|
||||
while ((p = strstr(p, "\"url\"")) && (!pieces_end || p < pieces_end)) {
|
||||
char url[768];
|
||||
char hash[80] = {0};
|
||||
long long got = 0;
|
||||
long long got = 0, range_start = 0;
|
||||
unsigned long long expected = 0;
|
||||
unsigned long long offset = 0;
|
||||
int have_offset, drc;
|
||||
const char *want_hash;
|
||||
const char *obj_end = strchr(p, '}');
|
||||
progress_state_t progress = {
|
||||
cb,
|
||||
ctx,
|
||||
total,
|
||||
manifest_total ? (long long)manifest_total : 0
|
||||
};
|
||||
const char *piece_limit = (obj_end && (!pieces_end || obj_end < pieces_end))
|
||||
? obj_end : pieces_end;
|
||||
|
||||
if (json_string_after(p, "url", url, sizeof(url)))
|
||||
if (json_string_after(p, "url", url, sizeof(url), piece_limit))
|
||||
break;
|
||||
json_u64_after(p, "fileSize", &expected);
|
||||
have_offset = (json_u64_after(p, "fileOffset", &offset) == 0);
|
||||
if (verify)
|
||||
json_string_after(p, "hashValue", hash, sizeof(hash));
|
||||
json_u64_after(p, "fileSize", &expected, piece_limit);
|
||||
have_offset = (json_u64_after(p, "fileOffset", &offset, piece_limit) == 0);
|
||||
|
||||
/* Pieces are concatenated in array order; each one's fileOffset must
|
||||
equal the bytes written so far. A manifest that lists them out of
|
||||
order would otherwise silently produce a corrupt package. */
|
||||
if (have_offset && offset != (unsigned long long)total)
|
||||
/* Piece already fully present from a previous run: skip the download. */
|
||||
if (!started && have_offset && expected &&
|
||||
have >= (long long)(offset + expected)) {
|
||||
total = (long long)(offset + expected);
|
||||
count++;
|
||||
if (cb && cb(ctx, total, manifest_total ? (long long)manifest_total : total))
|
||||
goto done;
|
||||
p = obj_end ? obj_end + 1 : p + 5;
|
||||
continue;
|
||||
}
|
||||
|
||||
/* First piece to (re)download while resuming. If part of it is already
|
||||
on disk, resume WITHIN it with a byte range; otherwise drop any stray
|
||||
bytes and fetch it whole. After this, every piece is fetched whole. */
|
||||
if (!started) {
|
||||
if (have_offset && expected && have > (long long)offset &&
|
||||
have < (long long)(offset + expected)) {
|
||||
range_start = have - (long long)offset; /* this piece's bytes on disk */
|
||||
fseek(fp, 0, SEEK_END); /* append at `have` */
|
||||
total = have;
|
||||
} else {
|
||||
long long start_at = have_offset ? (long long)offset : 0;
|
||||
fflush(fp);
|
||||
if (ftruncate(fileno(fp), (off_t)start_at) != 0)
|
||||
goto done; /* can't resume cleanly; keep partial */
|
||||
fseek(fp, 0, SEEK_END);
|
||||
total = start_at;
|
||||
}
|
||||
started = 1;
|
||||
}
|
||||
|
||||
/* Whole pieces are concatenated in array order; a ranged (partial) piece
|
||||
starts mid-piece, so the contiguity guard applies only to whole ones. */
|
||||
if (have_offset && range_start == 0 && offset != (unsigned long long)total)
|
||||
goto done;
|
||||
|
||||
/* drc: 0 ok, -1 network/cancel, -2 SHA-256 mismatch (propagated out). */
|
||||
drc = http_download_to_file_progress(url, fp, &got, &progress,
|
||||
hash[0] ? hash : NULL);
|
||||
/* A ranged piece can't be hashed (only its tail is fetched). */
|
||||
want_hash = NULL;
|
||||
if (range_start == 0 && verify) {
|
||||
json_string_after(p, "hashValue", hash, sizeof(hash), piece_limit);
|
||||
want_hash = hash[0] ? hash : NULL;
|
||||
}
|
||||
|
||||
{
|
||||
progress_state_t progress = {
|
||||
cb, ctx, total, manifest_total ? (long long)manifest_total : 0
|
||||
};
|
||||
/* drc: 0 ok, -1 network/cancel, -2 SHA-256, -3 range ignored. */
|
||||
drc = http_download_to_file_progress(url, fp, &got, &progress,
|
||||
want_hash, range_start);
|
||||
if (drc == -3) {
|
||||
/* Server ignored the range: drop the piece and fetch it whole. */
|
||||
fflush(fp);
|
||||
if (ftruncate(fileno(fp), (off_t)offset) != 0)
|
||||
goto done;
|
||||
fseek(fp, 0, SEEK_END);
|
||||
total = (long long)offset;
|
||||
range_start = 0;
|
||||
if (verify) {
|
||||
json_string_after(p, "hashValue", hash, sizeof(hash),
|
||||
piece_limit);
|
||||
want_hash = hash[0] ? hash : NULL;
|
||||
}
|
||||
progress.base = total;
|
||||
drc = http_download_to_file_progress(url, fp, &got, &progress,
|
||||
want_hash, 0);
|
||||
}
|
||||
}
|
||||
if (drc) {
|
||||
if (drc == -2) rc = -2;
|
||||
goto done;
|
||||
}
|
||||
if (expected && (unsigned long long)got != expected)
|
||||
/* range_start + got = this piece's bytes now on disk. */
|
||||
if (expected && (unsigned long long)(range_start + got) != expected)
|
||||
goto done;
|
||||
|
||||
total += got;
|
||||
@@ -593,7 +768,8 @@ patchdl_http_download_manifest_progress(const char *manifest_url,
|
||||
done:
|
||||
fclose(fp);
|
||||
free(manifest.data);
|
||||
if (rc) unlink(dest_path);
|
||||
/* Keep the partial on failure so it can be resumed; the caller deletes it
|
||||
on cancel or on a corrupt-verify (-2). */
|
||||
return rc;
|
||||
}
|
||||
|
||||
@@ -601,7 +777,260 @@ int
|
||||
patchdl_http_download_manifest(const char *manifest_url, const char *dest_path,
|
||||
long long *bytes_out) {
|
||||
return patchdl_http_download_manifest_progress(manifest_url, dest_path,
|
||||
bytes_out, NULL, NULL, 0);
|
||||
bytes_out, NULL, NULL, 0, 0);
|
||||
}
|
||||
|
||||
/* ---- global init + parallel piece download (connection pool) ----------- */
|
||||
|
||||
void patchdl_net_global_init(void) { curl_global_init(CURL_GLOBAL_ALL); }
|
||||
void patchdl_net_global_cleanup(void) { curl_global_cleanup(); }
|
||||
|
||||
/* Write sink for one piece: pwrite at a fixed base offset (concurrent
|
||||
non-overlapping pieces of the same fd are safe), tee into SHA-256 if asked,
|
||||
and publish bytes-so-far for live progress. */
|
||||
typedef struct {
|
||||
int fd;
|
||||
long long base;
|
||||
long long written;
|
||||
EVP_MD_CTX *md;
|
||||
volatile long long *bytes_slot;
|
||||
} piece_sink_t;
|
||||
|
||||
static size_t
|
||||
piece_write_cb(void *ptr, size_t size, size_t nmemb, void *ud) {
|
||||
piece_sink_t *s = (piece_sink_t *)ud;
|
||||
size_t n = size * nmemb;
|
||||
ssize_t w;
|
||||
if (n == 0) return 0;
|
||||
w = pwrite(s->fd, ptr, n, (off_t)(s->base + s->written));
|
||||
if (w < 0 || (size_t)w != n) return 0; /* short write -> curl errors out */
|
||||
if (s->md) EVP_DigestUpdate(s->md, ptr, n);
|
||||
s->written += (long long)n;
|
||||
if (s->bytes_slot) *s->bytes_slot = s->written;
|
||||
return n;
|
||||
}
|
||||
|
||||
static int
|
||||
piece_xfer_cb(void *clientp, curl_off_t dltotal, curl_off_t dlnow,
|
||||
curl_off_t ultotal, curl_off_t ulnow) {
|
||||
volatile int *abort_flag = (volatile int *)clientp;
|
||||
(void)dltotal; (void)dlnow; (void)ultotal; (void)ulnow;
|
||||
return (abort_flag && *abort_flag) ? 1 : 0; /* non-zero aborts the transfer */
|
||||
}
|
||||
|
||||
int
|
||||
patchdl_http_download_piece(const char *url, int fd,
|
||||
long long file_offset, long long file_size,
|
||||
const char *expected_sha256_or_null,
|
||||
patchdl_piece_ctx_t *ctx) {
|
||||
CURL *curl;
|
||||
CURLcode res;
|
||||
long http_code = 0;
|
||||
char host[256], ip[INET_ADDRSTRLEN], rs443[512], rs80[512];
|
||||
struct curl_slist *rl = NULL;
|
||||
struct curl_blob ca_blob;
|
||||
piece_sink_t sink;
|
||||
int verify = (expected_sha256_or_null && expected_sha256_or_null[0]);
|
||||
|
||||
if (url_host(url, host, sizeof(host))) return -1;
|
||||
if (!host_allowed(host)) return -1;
|
||||
if (dns_lookup(host, ip, sizeof(ip))) return -1;
|
||||
|
||||
memset(&sink, 0, sizeof(sink));
|
||||
sink.fd = fd;
|
||||
sink.base = file_offset;
|
||||
sink.bytes_slot = ctx ? ctx->bytes_slot : NULL;
|
||||
if (verify) {
|
||||
sink.md = EVP_MD_CTX_new();
|
||||
if (sink.md) EVP_DigestInit_ex(sink.md, EVP_sha256(), NULL);
|
||||
}
|
||||
|
||||
snprintf(rs443, sizeof(rs443), "%s:443:%s", host, ip);
|
||||
rl = curl_slist_append(NULL, rs443);
|
||||
snprintf(rs80, sizeof(rs80), "%s:80:%s", host, ip);
|
||||
rl = curl_slist_append(rl, rs80);
|
||||
|
||||
ca_blob.data = (void *)PATCHDL_SCEI_DNAS_ROOT_PEM;
|
||||
ca_blob.len = strlen(PATCHDL_SCEI_DNAS_ROOT_PEM);
|
||||
ca_blob.flags = CURL_BLOB_COPY;
|
||||
|
||||
curl = curl_easy_init();
|
||||
if (!curl) {
|
||||
curl_slist_free_all(rl);
|
||||
if (sink.md) EVP_MD_CTX_free(sink.md);
|
||||
return -1;
|
||||
}
|
||||
|
||||
curl_easy_setopt(curl, CURLOPT_URL, url);
|
||||
curl_easy_setopt(curl, CURLOPT_RESOLVE, rl);
|
||||
curl_easy_setopt(curl, CURLOPT_WRITEFUNCTION, piece_write_cb);
|
||||
curl_easy_setopt(curl, CURLOPT_WRITEDATA, &sink);
|
||||
curl_easy_setopt(curl, CURLOPT_CAINFO_BLOB, &ca_blob);
|
||||
curl_easy_setopt(curl, CURLOPT_SSL_VERIFYPEER, 1L);
|
||||
curl_easy_setopt(curl, CURLOPT_SSL_VERIFYHOST, 2L);
|
||||
curl_easy_setopt(curl, CURLOPT_SSL_CIPHER_LIST, "DEFAULT@SECLEVEL=0");
|
||||
curl_easy_setopt(curl, CURLOPT_FOLLOWLOCATION, 1L);
|
||||
curl_easy_setopt(curl, CURLOPT_MAXREDIRS, 5L);
|
||||
curl_easy_setopt(curl, CURLOPT_PROTOCOLS_STR, "https");
|
||||
curl_easy_setopt(curl, CURLOPT_REDIR_PROTOCOLS_STR, "https");
|
||||
curl_easy_setopt(curl, CURLOPT_NOSIGNAL, 1L);
|
||||
curl_easy_setopt(curl, CURLOPT_FAILONERROR, 1L); /* 4xx/5xx -> error, no body written */
|
||||
curl_easy_setopt(curl, CURLOPT_CONNECTTIMEOUT, 20L);
|
||||
curl_easy_setopt(curl, CURLOPT_LOW_SPEED_LIMIT, 1024L);
|
||||
curl_easy_setopt(curl, CURLOPT_LOW_SPEED_TIME, 30L);
|
||||
curl_easy_setopt(curl, CURLOPT_USERAGENT, "patchdl/1.0");
|
||||
if (ctx && ctx->abort) {
|
||||
curl_easy_setopt(curl, CURLOPT_NOPROGRESS, 0L);
|
||||
curl_easy_setopt(curl, CURLOPT_XFERINFOFUNCTION, piece_xfer_cb);
|
||||
curl_easy_setopt(curl, CURLOPT_XFERINFODATA, (void *)ctx->abort);
|
||||
}
|
||||
|
||||
res = curl_easy_perform(curl);
|
||||
curl_easy_getinfo(curl, CURLINFO_RESPONSE_CODE, &http_code);
|
||||
curl_easy_cleanup(curl);
|
||||
curl_slist_free_all(rl);
|
||||
|
||||
if (res != CURLE_OK) {
|
||||
if (sink.md) EVP_MD_CTX_free(sink.md);
|
||||
return -1; /* network error / abort */
|
||||
}
|
||||
if (file_size > 0 && sink.written != file_size) {
|
||||
if (sink.md) EVP_MD_CTX_free(sink.md);
|
||||
return -1; /* short or over-long -> failed */
|
||||
}
|
||||
if (sink.md) {
|
||||
unsigned char dig[EVP_MAX_MD_SIZE];
|
||||
unsigned int dl = 0;
|
||||
char hex[2 * EVP_MAX_MD_SIZE + 1];
|
||||
int ok = EVP_DigestFinal_ex(sink.md, dig, &dl);
|
||||
EVP_MD_CTX_free(sink.md);
|
||||
if (ok != 1 || dl == 0) return -2;
|
||||
hex_encode(dig, dl, hex, sizeof(hex));
|
||||
if (strcasecmp(hex, expected_sha256_or_null) != 0)
|
||||
return -2; /* integrity mismatch */
|
||||
}
|
||||
fdatasync(fd); /* durable before the caller sets the done bit */
|
||||
return 0;
|
||||
}
|
||||
|
||||
/* Read-only: SHA-256 a [offset, offset+size) region of fd into out_hex (>=65
|
||||
bytes). Uses pread so it doesn't disturb the fd offset. 0 on success. */
|
||||
int
|
||||
patchdl_sha256_fd_region(int fd, long long offset, long long size, char *out_hex) {
|
||||
EVP_MD_CTX *md;
|
||||
unsigned char *buf;
|
||||
long long pos = offset, remaining = size;
|
||||
const size_t CHUNK = 1u << 20;
|
||||
|
||||
out_hex[0] = '\0';
|
||||
if (fd < 0 || size < 0) return -1;
|
||||
md = EVP_MD_CTX_new();
|
||||
if (!md) return -1;
|
||||
buf = malloc(CHUNK);
|
||||
if (!buf) { EVP_MD_CTX_free(md); return -1; }
|
||||
EVP_DigestInit_ex(md, EVP_sha256(), NULL);
|
||||
while (remaining > 0) {
|
||||
size_t want = remaining > (long long)CHUNK ? CHUNK : (size_t)remaining;
|
||||
ssize_t got = pread(fd, buf, want, (off_t)pos);
|
||||
if (got <= 0) { free(buf); EVP_MD_CTX_free(md); return -1; }
|
||||
EVP_DigestUpdate(md, buf, (size_t)got);
|
||||
pos += got; remaining -= got;
|
||||
}
|
||||
{
|
||||
unsigned char dig[EVP_MAX_MD_SIZE];
|
||||
unsigned int dl = 0, i;
|
||||
int ok = EVP_DigestFinal_ex(md, dig, &dl);
|
||||
if (ok != 1 || dl == 0) { free(buf); EVP_MD_CTX_free(md); return -1; }
|
||||
for (i = 0; i < dl; i++) snprintf(out_hex + 2 * i, 3, "%02x", dig[i]);
|
||||
out_hex[2 * dl] = '\0';
|
||||
}
|
||||
free(buf);
|
||||
EVP_MD_CTX_free(md);
|
||||
return 0;
|
||||
}
|
||||
|
||||
void
|
||||
patchdl_manifest_free(patchdl_manifest_t *m) {
|
||||
if (!m || !m->pieces) return;
|
||||
for (int i = 0; i < m->count; i++) free(m->pieces[i].url);
|
||||
free(m->pieces);
|
||||
m->pieces = NULL;
|
||||
m->count = 0;
|
||||
}
|
||||
|
||||
int
|
||||
patchdl_fetch_manifest(const char *manifest_url, patchdl_manifest_t *out) {
|
||||
patchdl_buf_t buf;
|
||||
const char *pieces, *pieces_end, *p;
|
||||
int cap = 0, n = 0;
|
||||
long long running = 0;
|
||||
|
||||
memset(out, 0, sizeof(*out));
|
||||
memset(&buf, 0, sizeof(buf));
|
||||
buf.max = PATCHDL_BUF_MAX_MANIFEST;
|
||||
if (patchdl_http_get(manifest_url, &buf)) return -1;
|
||||
if (!buf.data || !buf.size) { free(buf.data); return -1; }
|
||||
|
||||
pieces = strstr(buf.data, "\"pieces\"");
|
||||
if (!pieces || !(pieces = strchr(pieces, '['))) { free(buf.data); return -1; }
|
||||
pieces_end = strchr(pieces, ']');
|
||||
|
||||
for (p = pieces; (p = strstr(p, "\"url\"")) && (!pieces_end || p < pieces_end); p += 5)
|
||||
cap++;
|
||||
if (cap <= 0) { free(buf.data); return -1; }
|
||||
out->pieces = calloc((size_t)cap, sizeof(patchdl_piece_t));
|
||||
if (!out->pieces) { free(buf.data); return -1; }
|
||||
|
||||
/* Sanity caps: refuse a manifest that would let a CDN drive multi-TB
|
||||
allocations or millions of pieces. The biggest real PS5 patch we've
|
||||
seen is ~70 GB / 18 pieces; these limits leave room to spare. */
|
||||
if (cap > PATCHDL_MAX_PIECES) { free(buf.data); return -1; }
|
||||
|
||||
p = pieces;
|
||||
while ((p = strstr(p, "\"url\"")) && (!pieces_end || p < pieces_end) && n < cap) {
|
||||
char url[768] = {0};
|
||||
unsigned long long sz = 0, off = 0;
|
||||
const char *obj_end = strchr(p, '}');
|
||||
const char *piece_limit = (obj_end && (!pieces_end || obj_end < pieces_end))
|
||||
? obj_end : pieces_end;
|
||||
|
||||
if (json_string_after(p, "url", url, sizeof(url), piece_limit))
|
||||
break;
|
||||
json_u64_after(p, "fileSize", &sz, piece_limit);
|
||||
if (json_u64_after(p, "fileOffset", &off, piece_limit) != 0)
|
||||
off = (unsigned long long)running; /* no offset -> assume contiguous */
|
||||
|
||||
/* Validate tiling: pieces must be in order, contiguous, non-empty,
|
||||
and each individually under the per-piece cap. */
|
||||
if ((long long)off != running || sz == 0 || sz > PATCHDL_MAX_PIECE_BYTES) {
|
||||
patchdl_manifest_free(out);
|
||||
free(buf.data);
|
||||
return -1;
|
||||
}
|
||||
if ((unsigned long long)running + sz > PATCHDL_MAX_TOTAL_BYTES) {
|
||||
patchdl_manifest_free(out);
|
||||
free(buf.data);
|
||||
return -1;
|
||||
}
|
||||
out->pieces[n].url = strdup(url);
|
||||
out->pieces[n].offset = (long long)off;
|
||||
out->pieces[n].size = (long long)sz;
|
||||
json_string_after(p, "hashValue", out->pieces[n].hash,
|
||||
sizeof(out->pieces[n].hash), piece_limit);
|
||||
if (!out->pieces[n].url) {
|
||||
patchdl_manifest_free(out);
|
||||
free(buf.data);
|
||||
return -1;
|
||||
}
|
||||
running += (long long)sz;
|
||||
n++;
|
||||
out->count = n; /* keep current so manifest_free frees exactly n */
|
||||
p = obj_end ? obj_end + 1 : p + 5;
|
||||
}
|
||||
free(buf.data);
|
||||
if (n == 0) { patchdl_manifest_free(out); return -1; }
|
||||
out->total = running; /* authoritative assembled size */
|
||||
return 0;
|
||||
}
|
||||
|
||||
void
|
||||
@@ -637,6 +1066,9 @@ patchdl_net_diag(const char *url, char *out_json, size_t sz) {
|
||||
curl_easy_setopt(curl, CURLOPT_SSL_VERIFYPEER, 1L);
|
||||
curl_easy_setopt(curl, CURLOPT_SSL_VERIFYHOST, 2L);
|
||||
curl_easy_setopt(curl, CURLOPT_SSL_CIPHER_LIST, "DEFAULT@SECLEVEL=0");
|
||||
curl_easy_setopt(curl, CURLOPT_PROTOCOLS_STR, "https");
|
||||
curl_easy_setopt(curl, CURLOPT_REDIR_PROTOCOLS_STR, "https");
|
||||
curl_easy_setopt(curl, CURLOPT_NOSIGNAL, 1L);
|
||||
curl_easy_setopt(curl, CURLOPT_TIMEOUT, 15L);
|
||||
res = curl_easy_perform(curl);
|
||||
curl_easy_getinfo(curl, CURLINFO_RESPONSE_CODE, &http_code);
|
||||
@@ -696,8 +1128,8 @@ patchdl_http_download_manifest_progress(const char *manifest_url,
|
||||
const char *dest_path,
|
||||
long long *bytes_out,
|
||||
patchdl_download_progress_cb cb,
|
||||
void *ctx, int verify) {
|
||||
(void)cb; (void)ctx; (void)verify;
|
||||
void *ctx, int verify, int resume) {
|
||||
(void)cb; (void)ctx; (void)verify; (void)resume;
|
||||
return patchdl_http_download_manifest(manifest_url, dest_path, bytes_out);
|
||||
}
|
||||
|
||||
|
||||
+55
-2
@@ -6,13 +6,63 @@ typedef struct {
|
||||
char *data;
|
||||
size_t size;
|
||||
size_t cap;
|
||||
size_t max; /* 0 = unbounded (legacy). Otherwise write_cb fails past this. */
|
||||
} patchdl_buf_t;
|
||||
|
||||
patchdl_buf_t *patchdl_buf_new(void);
|
||||
void patchdl_buf_free(patchdl_buf_t *b);
|
||||
|
||||
/* Call once, single-threaded, before any concurrent download worker starts /
|
||||
after they have all joined. curl's global/OpenSSL init is otherwise lazy and
|
||||
races across threads. */
|
||||
void patchdl_net_global_init(void);
|
||||
void patchdl_net_global_cleanup(void);
|
||||
|
||||
int patchdl_http_get(const char *url, patchdl_buf_t *out);
|
||||
|
||||
/* ---- parallel piece download (used by the connection pool) ------------- */
|
||||
|
||||
/* One piece of a split manifest package. `url` is heap-allocated. */
|
||||
typedef struct {
|
||||
char *url;
|
||||
long long offset; /* byte offset of this piece in the assembled file */
|
||||
long long size; /* exact length of this piece */
|
||||
char hash[80]; /* manifest SHA-256 hex, or "" */
|
||||
} patchdl_piece_t;
|
||||
|
||||
typedef struct {
|
||||
patchdl_piece_t *pieces;
|
||||
int count;
|
||||
long long total; /* assembled file size = sum of piece sizes */
|
||||
} patchdl_manifest_t;
|
||||
|
||||
/* Fetch + parse a Sony JSON manifest into a validated, contiguously-tiled
|
||||
piece list. Returns 0 on success (caller frees with patchdl_manifest_free),
|
||||
-1 on fetch/parse/tiling failure. */
|
||||
int patchdl_fetch_manifest(const char *manifest_url, patchdl_manifest_t *out);
|
||||
void patchdl_manifest_free(patchdl_manifest_t *m);
|
||||
|
||||
/* Live state shared with one in-flight piece download. The worker owns these;
|
||||
the curl callbacks read `abort` (set elsewhere) and publish progress into
|
||||
`bytes_slot` (single-writer per worker slot). */
|
||||
typedef struct {
|
||||
volatile long long *bytes_slot; /* bytes written so far for this piece */
|
||||
volatile int *abort; /* non-zero -> stop this transfer */
|
||||
} patchdl_piece_ctx_t;
|
||||
|
||||
/* Download one whole piece and pwrite it into `fd` at `file_offset`. Concurrent
|
||||
non-overlapping pieces of the same fd are safe. Returns 0 on success (and
|
||||
fdatasyncs fd), -1 on network/IO/abort, -2 on a SHA-256 mismatch. */
|
||||
int patchdl_http_download_piece(const char *url, int fd,
|
||||
long long file_offset, long long file_size,
|
||||
const char *expected_sha256_or_null,
|
||||
patchdl_piece_ctx_t *ctx);
|
||||
|
||||
/* Read-only: SHA-256 a [offset, offset+size) region of fd into out_hex
|
||||
(caller provides >= 65 bytes). Returns 0 on success. */
|
||||
int patchdl_sha256_fd_region(int fd, long long offset, long long size,
|
||||
char *out_hex);
|
||||
|
||||
/* Progress callback. Return non-zero to ABORT the in-flight download (used to
|
||||
cancel large patch downloads); return 0 to continue. */
|
||||
typedef int (*patchdl_download_progress_cb)(void *ctx,
|
||||
@@ -29,14 +79,17 @@ int patchdl_http_download_progress(const char *url, const char *dest_path,
|
||||
|
||||
/* Download a Sony JSON package manifest by concatenating every entry in
|
||||
"pieces" into one installable PKG. When `verify` is non-zero each piece is
|
||||
checked against its manifest SHA-256 (a mismatch returns -2). */
|
||||
checked against its manifest SHA-256 (a mismatch returns -2). When `resume`
|
||||
is non-zero an existing partial at dest_path is kept: fully-downloaded pieces
|
||||
are skipped and only the remainder is fetched (survives a reboot). On any
|
||||
failure the partial is left in place for a later resume. */
|
||||
int patchdl_http_download_manifest(const char *manifest_url, const char *dest_path,
|
||||
long long *bytes_out);
|
||||
int patchdl_http_download_manifest_progress(const char *manifest_url,
|
||||
const char *dest_path,
|
||||
long long *bytes_out,
|
||||
patchdl_download_progress_cb cb,
|
||||
void *ctx, int verify);
|
||||
void *ctx, int verify, int resume);
|
||||
|
||||
/* Diagnostic: run the GET pipeline for `url` and write a JSON report
|
||||
(dns result/ip, curl code, http status, bytes) into `out_json`. */
|
||||
|
||||
+4
-1
@@ -65,7 +65,10 @@ patchdl_proc_kill_others(const char *name) {
|
||||
int killed = 0;
|
||||
pid_t pid;
|
||||
|
||||
while ((pid = find_pid(name)) > 0) {
|
||||
/* Bound the loop: at startup we expect 0-1 stale instance. A pathological
|
||||
proc table (or kill returning success but the process not exiting) would
|
||||
otherwise stall startup for sleep(1) × N. */
|
||||
while (killed < 8 && (pid = find_pid(name)) > 0) {
|
||||
if (kill(pid, SIGKILL))
|
||||
break;
|
||||
killed++;
|
||||
|
||||
@@ -27,6 +27,14 @@ lookup_tsv(const char *title_id, char *url_out, size_t url_sz) {
|
||||
fclose(fp);
|
||||
return -1;
|
||||
}
|
||||
/* Defense in depth: the TSV file lives under /data/patchdl, writable
|
||||
by anyone with /data access. patchdl_http_get also enforces
|
||||
host_allowed, but rejecting non-https / non-Sony schemes here means
|
||||
a poisoned line can't even reach the network layer. */
|
||||
if (strncmp(url, "https://", 8) != 0) {
|
||||
fclose(fp);
|
||||
return -1;
|
||||
}
|
||||
memcpy(url_out, url, len + 1);
|
||||
fclose(fp);
|
||||
return 0;
|
||||
|
||||
@@ -5,6 +5,7 @@
|
||||
|
||||
#include <dirent.h>
|
||||
#include <limits.h>
|
||||
#include <stdatomic.h>
|
||||
#include <stdint.h>
|
||||
#include <stdio.h>
|
||||
#include <stdlib.h>
|
||||
@@ -389,6 +390,15 @@ merge_appdb(patchdl_title_t *arr, size_t cnt) {
|
||||
patchdl_appdb_free(info);
|
||||
}
|
||||
|
||||
/* See patchdl_scan_lock — both vnode-swap entry points return -1 / NULL once
|
||||
this is set so a late rescan call can't race the running MHD threads. */
|
||||
static _Atomic int g_scan_locked = 0;
|
||||
|
||||
void
|
||||
patchdl_scan_lock(void) {
|
||||
atomic_store(&g_scan_locked, 1);
|
||||
}
|
||||
|
||||
int
|
||||
patchdl_scan(patchdl_title_t **titles_out, size_t *count_out) {
|
||||
patchdl_title_t *arr;
|
||||
@@ -400,6 +410,8 @@ patchdl_scan(patchdl_title_t **titles_out, size_t *count_out) {
|
||||
struct statfs *mounts = NULL;
|
||||
int nmounts;
|
||||
|
||||
if (atomic_load(&g_scan_locked)) return -1;
|
||||
|
||||
arr = calloc(MAX_TITLES, sizeof(*arr));
|
||||
if (!arr) return -1;
|
||||
|
||||
@@ -467,6 +479,8 @@ patchdl_scan_debug_json(void) {
|
||||
char tmp[2048];
|
||||
pid_t pid = getpid();
|
||||
intptr_t saved_root = 0, root_vnode;
|
||||
|
||||
if (atomic_load(&g_scan_locked)) return NULL;
|
||||
int using_vswap = 0;
|
||||
struct statfs *mounts = NULL;
|
||||
int nmounts;
|
||||
|
||||
@@ -24,10 +24,13 @@ typedef struct {
|
||||
char latest_version[16];
|
||||
char latest_required_fw[16];
|
||||
char patch_url[512]; /* manifest_url if present, otherwise pkg URL */
|
||||
char delta_url[512]; /* DP.pkg bootstrap URL (always a PKG) */
|
||||
char patch_title_id[16]; /* target title id from version.xml */
|
||||
char patch_storage_title_id[16]; /* title id embedded in delta_url */
|
||||
int verxml_done;
|
||||
int enabled; /* user policy, persisted in config.json */
|
||||
int resumable; /* a partial download is on disk */
|
||||
long long partial_bytes; /* size of that partial, for the UI */
|
||||
} patchdl_title_t;
|
||||
|
||||
int patchdl_scan(patchdl_title_t **titles_out, size_t *count_out);
|
||||
@@ -37,3 +40,9 @@ const char *patchdl_source_str(patchdl_source_t src);
|
||||
/* Diagnostic: malloc'd JSON dump of the mount table + scan-base directory
|
||||
listings. Caller frees. */
|
||||
char *patchdl_scan_debug_json(void);
|
||||
|
||||
/* Mark scan/debug as no longer safe to call (must be set after MHD worker
|
||||
threads come up — patchdl_scan performs a process-wide vnode swap that
|
||||
would race any concurrent thread). After this is set, both entry points
|
||||
return immediately. Call once during startup, after MHD_start_daemon. */
|
||||
void patchdl_scan_lock(void);
|
||||
@@ -1,3 +1,3 @@
|
||||
#pragma once
|
||||
|
||||
#define PATCHDL_VERSION "0.0.2"
|
||||
#define PATCHDL_VERSION "0.0.4"
|
||||
+17
-5
@@ -66,14 +66,20 @@ ver_gt(const char *a, const char *b) {
|
||||
from a string such as nptitleid, manifest_url, or delta_url. */
|
||||
static void
|
||||
extract_title_id(const char *s, char *out, size_t sz) {
|
||||
size_t len;
|
||||
out[0] = '\0';
|
||||
if (sz < 10 || !s) return;
|
||||
for (const char *p = s; p[0] && p[8]; p++) {
|
||||
len = strlen(s);
|
||||
if (len < 9) return;
|
||||
/* `len - 9` is the last position where a 9-char id can still fit; this
|
||||
avoids reading p[8] past the NUL terminator. */
|
||||
for (size_t i = 0; i <= len - 9; i++) {
|
||||
const char *p = s + i;
|
||||
int ok = 1;
|
||||
for (int i = 0; i < 4 && ok; i++)
|
||||
if (p[i] < 'A' || p[i] > 'Z') ok = 0;
|
||||
for (int i = 4; i < 9 && ok; i++)
|
||||
if (p[i] < '0' || p[i] > '9') ok = 0;
|
||||
for (int k = 0; k < 4 && ok; k++)
|
||||
if (p[k] < 'A' || p[k] > 'Z') ok = 0;
|
||||
for (int k = 4; k < 9 && ok; k++)
|
||||
if (p[k] < '0' || p[k] > '9') ok = 0;
|
||||
if (ok) {
|
||||
memcpy(out, p, 9);
|
||||
out[9] = '\0';
|
||||
@@ -148,6 +154,8 @@ parse_packages(const char *xml, uint32_t fw_bin, patchdl_verinfo_t *out) {
|
||||
sizeof(out->compatible_version) - 1);
|
||||
strncpy(out->compatible_url, murl[0] ? murl : durl,
|
||||
sizeof(out->compatible_url) - 1);
|
||||
if (durl[0])
|
||||
strncpy(out->delta_url, durl, sizeof(out->delta_url) - 1);
|
||||
extract_title_id(durl, out->compatible_storage_title,
|
||||
sizeof(out->compatible_storage_title));
|
||||
if (root_title[0]) {
|
||||
@@ -175,6 +183,10 @@ patchdl_verxml_query(const char *url, uint32_t fw_bin, patchdl_verinfo_t *out) {
|
||||
if (!url || !out) return -1;
|
||||
memset(out, 0, sizeof(*out));
|
||||
|
||||
/* version.xml is a few KB in practice; cap to 16 MiB so a misbehaving CDN
|
||||
can't slurp unbounded RAM into the buffer. */
|
||||
memset(&buf, 0, sizeof(buf));
|
||||
buf.max = 16 * 1024 * 1024;
|
||||
if (patchdl_http_get(url, &buf)) return -1;
|
||||
if (!buf.data || !buf.size) { free(buf.data); return -1; }
|
||||
|
||||
|
||||
@@ -7,6 +7,7 @@ typedef struct {
|
||||
char latest_version[16]; /* highest pkg overall, or "" */
|
||||
char latest_required_fw[16]; /* fw str for latest pkg, e.g. "11.60", or "" */
|
||||
char compatible_url[512]; /* manifest_url if present, otherwise pkg URL */
|
||||
char delta_url[512]; /* DP.pkg bootstrap URL (always a PKG, never JSON) */
|
||||
char compatible_title[16]; /* target title id from version.xml/manifest_url */
|
||||
char compatible_storage_title[16]; /* title id embedded in delta_url storage path */
|
||||
} patchdl_verinfo_t;
|
||||
|
||||
+1272
-178
File diff suppressed because it is too large.
Load diff
@@ -16,6 +16,9 @@ GET /api/config
|
||||
POST /api/config
|
||||
GET /api/titles
|
||||
GET /api/downloads
|
||||
GET /api/installstatus
|
||||
GET /api/pkgmeta/:title_id
|
||||
GET /api/pkgverify/:title_id
|
||||
POST /api/titles/:title_id/check
|
||||
POST /api/titles/:title_id/download
|
||||
POST /api/titles/:title_id/install
|
||||
@@ -88,3 +91,8 @@ For PS5 game updates, the backend may turn a Sony `manifest_url` into a merged
|
||||
local `.pkg` by downloading all manifest pieces. The `delta_url` `*-DP.pkg` is
|
||||
not shown as a separate user action because it can bootstrap the storage/master
|
||||
title instead of the installed regional target.
|
||||
|
||||
If `patch_storage_match` is false, the UI keeps download/verify available but
|
||||
does not offer install or auto-install. Those shared-master packages are signed
|
||||
for a different storage title id and cannot be retargeted by standalone
|
||||
AppInstUtil on firmware 11.60.
|
||||
+334
-89
@@ -3,6 +3,7 @@ const API = {
|
||||
titles: "/api/titles",
|
||||
config: "/api/config",
|
||||
downloads: "/api/downloads",
|
||||
installStatus: "/api/installstatus",
|
||||
action: (titleId, action) => `/api/titles/${encodeURIComponent(titleId)}/${action}`,
|
||||
};
|
||||
|
||||
@@ -29,6 +30,7 @@ const fallback = {
|
||||
delete_pkg_after_install: true,
|
||||
verify_downloads: false,
|
||||
home_shortcut: true,
|
||||
max_connections: 4,
|
||||
source_policy: {
|
||||
official: { allow_check: true, allow_download: true, allow_install: true },
|
||||
external: { allow_check: true, allow_download: true, allow_install: true },
|
||||
@@ -48,6 +50,7 @@ const fallback = {
|
||||
installed_version: "01.032.000", compatible_version: "01.041.000",
|
||||
latest_version: "01.041.000", latest_required_fw: "11.60",
|
||||
source_type: "official", source_path: "/system_ex/app/PPSA01628_00",
|
||||
patch_storage_match: true,
|
||||
mount_from: "/dev/ssd0.system_ex", enabled: true, status: "available",
|
||||
},
|
||||
{
|
||||
@@ -56,6 +59,7 @@ const fallback = {
|
||||
installed_version: "01.004.000", compatible_version: "01.004.000",
|
||||
latest_version: "01.004.000", latest_required_fw: "10.01",
|
||||
source_type: "external", source_path: "/system_data/priv/appmeta/external/PPSA01284_00",
|
||||
patch_storage_match: true,
|
||||
mount_from: "/mnt/ext0/user/app/PPSA01284_00", enabled: true, status: "up_to_date",
|
||||
},
|
||||
{
|
||||
@@ -64,6 +68,7 @@ const fallback = {
|
||||
installed_version: "01.000.000", compatible_version: "01.006.000",
|
||||
latest_version: "01.009.000", latest_required_fw: "12.00",
|
||||
source_type: "shadowmount", source_path: "/system_ex/app/PPSA90001_00",
|
||||
patch_storage_match: true,
|
||||
mount_from: "/mnt/usb0/itemzflow/Shadowmounted Test Title", enabled: true, status: "available",
|
||||
},
|
||||
],
|
||||
@@ -78,12 +83,13 @@ let state = {
|
||||
downloads: fallback.downloads,
|
||||
logs: fallback.logs,
|
||||
view: "games",
|
||||
filter: "all",
|
||||
filter: "updatable",
|
||||
query: "",
|
||||
usingFallback: false,
|
||||
};
|
||||
|
||||
let downloadPollTimer = null;
|
||||
let installPollTimer = null;
|
||||
let emptyPolls = 0;
|
||||
const dlMeta = {}; // per-title speed tracking: { bytes, t, speed }
|
||||
|
||||
@@ -116,7 +122,11 @@ function bindElements() {
|
||||
deleteAfterInstall: document.getElementById("deleteAfterInstall"),
|
||||
verifyDownloads: document.getElementById("verifyDownloads"),
|
||||
homeShortcut: document.getElementById("homeShortcut"),
|
||||
connValue: document.getElementById("connValue"),
|
||||
connMinus: document.getElementById("connMinus"),
|
||||
connPlus: document.getElementById("connPlus"),
|
||||
refreshBtn: document.getElementById("refreshBtn"),
|
||||
updateAllBtn: document.getElementById("updateAllBtn"),
|
||||
saveBtn: document.getElementById("saveBtn"),
|
||||
clearLogBtn: document.getElementById("clearLogBtn"),
|
||||
toast: document.getElementById("toast"),
|
||||
@@ -146,8 +156,13 @@ function bindEvents() {
|
||||
});
|
||||
|
||||
els.refreshBtn.addEventListener("click", loadInitialData);
|
||||
if (els.updateAllBtn) els.updateAllBtn.addEventListener("click", updateAll);
|
||||
els.saveBtn.addEventListener("click", saveConfig);
|
||||
els.clearLogBtn.addEventListener("click", () => { state.logs = []; renderLogs(); });
|
||||
if (els.connMinus)
|
||||
els.connMinus.addEventListener("click", () => setConnections(clampConn(state.config.max_connections) - 1));
|
||||
if (els.connPlus)
|
||||
els.connPlus.addEventListener("click", () => setConnections(clampConn(state.config.max_connections) + 1));
|
||||
}
|
||||
|
||||
function setView(view) {
|
||||
@@ -173,27 +188,27 @@ async function loadInitialData() {
|
||||
// /api/titles carries no client-only progress flags, so preserve them across a
|
||||
// refresh — otherwise an in-flight download/install flips back to a clickable
|
||||
// button mid-operation.
|
||||
// Carry client-only flags across a refresh; the pool's job list is the source
|
||||
// of truth for download state and is reconciled right after.
|
||||
const prev = new Map(state.titles.map((g) => [g.title_id, g]));
|
||||
titles.forEach((g) => {
|
||||
const old = prev.get(g.title_id);
|
||||
// Carry client-only progress flags across a refresh — unless the server now
|
||||
// reports the title up to date (the patch applied), in which case drop them.
|
||||
if (old && g.status !== "up_to_date") {
|
||||
if (old.downloading) g.downloading = true;
|
||||
if (old.downloaded) g.downloaded = true;
|
||||
if (old.installing) g.installing = true;
|
||||
if (old._autoInstalled) g._autoInstalled = true;
|
||||
if (old._localDownloading) g._localDownloading = true;
|
||||
}
|
||||
});
|
||||
// Reconcile active downloads the server reports, so progress + Cancel show even
|
||||
// after a hard reload or a download started from another session/device.
|
||||
const activeDl = new Set(downloads.map((d) => d.title_id));
|
||||
titles.forEach((g) => { if (activeDl.has(g.title_id)) g.downloading = true; });
|
||||
|
||||
state = { ...state, status, config, titles, downloads };
|
||||
reconcileFromJobs(downloads);
|
||||
|
||||
render();
|
||||
if (state.downloads.length) startDownloadPolling();
|
||||
if (downloads.some((j) => j.state === "active" || j.state === "queued") ||
|
||||
state.titles.some((g) => g._localDownloading))
|
||||
startDownloadPolling();
|
||||
if (state.titles.some((g) => g.installing)) startInstallPolling();
|
||||
showToast(state.usingFallback ? "Demo data loaded. API is not reachable yet." : "Data refreshed.");
|
||||
}
|
||||
|
||||
@@ -227,6 +242,40 @@ function renderStatus() {
|
||||
if (els.railSpace) els.railSpace.textContent = `${space} free`;
|
||||
}
|
||||
|
||||
const CONN_MIN = 1, CONN_MAX = 16;
|
||||
function clampConn(n) {
|
||||
n = parseInt(n, 10);
|
||||
if (!Number.isFinite(n)) n = 4;
|
||||
return Math.max(CONN_MIN, Math.min(CONN_MAX, n));
|
||||
}
|
||||
|
||||
function renderConnStepper() {
|
||||
const n = clampConn(state.config.max_connections);
|
||||
if (els.connValue) els.connValue.textContent = String(n);
|
||||
if (els.connMinus) els.connMinus.disabled = n <= CONN_MIN;
|
||||
if (els.connPlus) els.connPlus.disabled = n >= CONN_MAX;
|
||||
}
|
||||
|
||||
let connSaveTimer = null;
|
||||
// Stepper +/-: update + re-render immediately, then persist just this field
|
||||
// (debounced) so rapid taps collapse into one POST and other unsaved form
|
||||
// fields stay untouched. The server applies the new count live (no restart).
|
||||
function setConnections(n) {
|
||||
const v = clampConn(n);
|
||||
if (v === clampConn(state.config.max_connections)) { renderConnStepper(); return; }
|
||||
state.config.max_connections = v;
|
||||
renderConnStepper();
|
||||
clearTimeout(connSaveTimer);
|
||||
connSaveTimer = setTimeout(async () => {
|
||||
try {
|
||||
await postJson(API.config, { max_connections: v });
|
||||
showToast(`Parallel connections: ${v}`);
|
||||
} catch (e) {
|
||||
showToast("Could not save connections — API not reachable.");
|
||||
}
|
||||
}, 450);
|
||||
}
|
||||
|
||||
function renderSettings() {
|
||||
els.defaultPolicy.value = state.config.default_policy || "deny";
|
||||
els.downloadDir.value = state.config.download_dir || "";
|
||||
@@ -234,6 +283,7 @@ function renderSettings() {
|
||||
els.deleteAfterInstall.checked = Boolean(state.config.delete_pkg_after_install);
|
||||
if (els.verifyDownloads) els.verifyDownloads.checked = Boolean(state.config.verify_downloads);
|
||||
if (els.homeShortcut) els.homeShortcut.checked = state.config.home_shortcut !== false;
|
||||
renderConnStepper();
|
||||
els.allowlistHosts.replaceChildren(...(state.config.cdn_allowlist || []).map((host) => {
|
||||
const chip = document.createElement("span");
|
||||
chip.className = "host-chip";
|
||||
@@ -261,12 +311,15 @@ function renderGames() {
|
||||
|
||||
// Mutually-exclusive bucket per game for the filter chips.
|
||||
function gameCategory(game) {
|
||||
// In-flight work (queued, active, paused, installing) lives in its own
|
||||
// bucket so Updatable shows only what the user could still trigger.
|
||||
if (game.installing || game.downloading || game.resumable) return "updating";
|
||||
// checking is transient (version lookup still running); keep it visible under
|
||||
// Updatable rather than letting it fall out of every specific filter.
|
||||
if (game.installing || game.downloading || game.status === "checking") return "updatable";
|
||||
if (game.status === "checking") return "updatable";
|
||||
if (game.patch_title_match === false) return "blocked";
|
||||
if (!sourcePolicy(game).allow_install) return "blocked";
|
||||
if (game.status === "available") return "updatable";
|
||||
if (game.status === "available" && isDownloadAllowed(game)) return "updatable";
|
||||
if (!sourcePolicy(game).allow_install && !sourcePolicy(game).allow_download) return "blocked";
|
||||
if (game.status === "incompatible_fw") return "needsfw";
|
||||
return "uptodate";
|
||||
}
|
||||
@@ -312,7 +365,9 @@ function createGameCard(game) {
|
||||
</div>
|
||||
<div class="pills">
|
||||
${game.downloading ? `<span class="pill live">Downloading</span>` : ""}
|
||||
${game.resumable && !game.downloading ? `<span class="pill warn">Paused</span>` : ""}
|
||||
${statusPill(game)}
|
||||
${storagePill(game)}
|
||||
${sourcePill(game)}
|
||||
</div>
|
||||
<div class="versions">
|
||||
@@ -324,8 +379,8 @@ function createGameCard(game) {
|
||||
|
||||
const actions = document.createElement("div");
|
||||
actions.className = "card-actions";
|
||||
const act = tileButton(game);
|
||||
if (act) {
|
||||
[primaryButton(game), stopButton(game)].forEach((act) => {
|
||||
if (!act) return;
|
||||
const btn = document.createElement("button");
|
||||
btn.className = `row-button is-${act.variant}`;
|
||||
btn.textContent = act.label;
|
||||
@@ -333,16 +388,7 @@ function createGameCard(game) {
|
||||
if (act.disabled) btn.disabled = true;
|
||||
else btn.addEventListener("click", () => runTitleAction(game.title_id, act.action));
|
||||
actions.appendChild(btn);
|
||||
}
|
||||
// Delete a finished (not-yet-installed) download.
|
||||
if (game.downloaded && !game.installing && !game.downloading) {
|
||||
const del = document.createElement("button");
|
||||
del.className = "row-button is-ghost";
|
||||
del.textContent = "Delete";
|
||||
del.title = "Delete the downloaded package";
|
||||
del.addEventListener("click", () => cancelDownload(game.title_id));
|
||||
actions.appendChild(del);
|
||||
}
|
||||
});
|
||||
|
||||
row.append(lead, body, actions);
|
||||
card.appendChild(row);
|
||||
@@ -357,6 +403,26 @@ function createGameCard(game) {
|
||||
<div class="progress-meta">${progressMetaHtml(d)}</div>
|
||||
`;
|
||||
card.appendChild(prog);
|
||||
} else if (game.installing) {
|
||||
const pct = Math.max(0, Math.min(100, Number(game.installProgress) || 0));
|
||||
const note = document.createElement("div");
|
||||
note.className = "card-progress";
|
||||
note.innerHTML = `
|
||||
<div class="progress"><i style="width:${pct}%"></i></div>
|
||||
<div class="progress-meta">${installProgressHtml(game)}</div>
|
||||
`;
|
||||
card.appendChild(note);
|
||||
} else if (game.resumable && game.partial_bytes > 0) {
|
||||
// ---- paused partial (survived a reboot) ----
|
||||
const note = document.createElement("div");
|
||||
note.className = "card-progress";
|
||||
note.innerHTML = `
|
||||
<div class="progress-meta">
|
||||
<span>Paused — <b>${formatBytes(game.partial_bytes)}</b> downloaded</span>
|
||||
<span>Resume to continue</span>
|
||||
</div>
|
||||
`;
|
||||
card.appendChild(note);
|
||||
}
|
||||
|
||||
return card;
|
||||
@@ -382,21 +448,33 @@ function buildToggle(game) {
|
||||
return toggle;
|
||||
}
|
||||
|
||||
// The single morphing action button: blue Update/Download/Install, or amber
|
||||
// Cancel while a download runs. Fixed width (CSS) so the label never reflows.
|
||||
function tileButton(game) {
|
||||
// Primary play/pause button (green to go, amber while downloading). Fixed width
|
||||
// (CSS) so the label never reflows. Returns null when there is nothing to do.
|
||||
function primaryButton(game) {
|
||||
if (game.installing) return { label: "Installing…", variant: "ghost", disabled: true };
|
||||
if (game.downloading) return { label: "Cancel", action: "cancel", variant: "cancel", hint: "Stop the download and delete the partial file" };
|
||||
if (game.downloading) return { label: "Pause", action: "pause", variant: "pause", hint: "Pause the download (keeps what was downloaded)." };
|
||||
if (game.patch_title_match === false) return null;
|
||||
if (!isInstallAllowed(game)) return null;
|
||||
if (game.downloaded && game.status === "available")
|
||||
if (game.resumable && isDownloadAllowed(game))
|
||||
return { label: "Resume", action: "download", variant: "update", hint: "Continue the paused download where it stopped." };
|
||||
if (game.downloaded && game.status === "available" && isInstallAllowed(game))
|
||||
return { label: "Install", action: "install", variant: "update", hint: "Install the downloaded patch (modifies the game)." };
|
||||
if (game.downloaded && game.status === "available") return null;
|
||||
if (game.status !== "available") return null;
|
||||
return state.config.install_after_download
|
||||
if (!isDownloadAllowed(game)) return null;
|
||||
return state.config.install_after_download && isInstallAllowed(game)
|
||||
? { label: "Update", action: "update", variant: "update", hint: "Download and install the update." }
|
||||
: { label: "Download", action: "download", variant: "update", hint: "Download the patch internally." };
|
||||
}
|
||||
|
||||
// Red stop button: present whenever there is a download to stop or discard.
|
||||
// Cancel stops AND deletes (unlike Pause, which keeps the partial).
|
||||
function stopButton(game) {
|
||||
if (game.installing) return null;
|
||||
if (game.downloading || game.resumable || game.downloaded)
|
||||
return { label: "Cancel", action: "cancel", variant: "cancel", hint: "Stop and delete the download." };
|
||||
return null;
|
||||
}
|
||||
|
||||
function statusPill(game) {
|
||||
if (game.installing) return `<span class="pill warn">Installing…</span>`;
|
||||
if (game.status === "checking") return `<span class="pill">Checking…</span>`;
|
||||
@@ -407,6 +485,10 @@ function statusPill(game) {
|
||||
return `<span class="pill">No patch info</span>`;
|
||||
}
|
||||
|
||||
function storagePill(game) {
|
||||
return hasSharedStorage(game) ? `<span class="pill warn">Shared master</span>` : "";
|
||||
}
|
||||
|
||||
function sourcePill(game) {
|
||||
const info = sourceInfo(game);
|
||||
return `<span class="pill ${info.className}">${escapeHtml(info.label)}</span>`;
|
||||
@@ -427,6 +509,7 @@ function progressMetaHtml(d) {
|
||||
const done = Number(d.bytes) || 0;
|
||||
const total = Number(d.total_bytes) || 0;
|
||||
const speed = Number(d._speed) || 0;
|
||||
if (d.state === "queued") return `<span>Queued — waiting for a free slot</span>`;
|
||||
const parts = [];
|
||||
parts.push(`<span><b>${formatBytes(done)}</b>${total > 0 ? ` / ${formatBytes(total)}` : ""}</span>`);
|
||||
if (speed > 0) parts.push(`<span><b>${formatBytes(speed)}/s</b></span>`);
|
||||
@@ -436,6 +519,16 @@ function progressMetaHtml(d) {
|
||||
return parts.join("");
|
||||
}
|
||||
|
||||
function installProgressHtml(game) {
|
||||
const status = game.installStatus || "waiting";
|
||||
const done = Number(game.installDone) || 0;
|
||||
const total = Number(game.installTotal) || 0;
|
||||
const parts = [`<span>Status <b>${escapeHtml(status)}</b></span>`];
|
||||
if (total > 0) parts.push(`<span><b>${formatBytes(done)}</b> / ${formatBytes(total)}</span>`);
|
||||
parts.push(`<span><b>${Math.max(0, Math.min(100, Number(game.installProgress) || 0))}%</b></span>`);
|
||||
return parts.join("");
|
||||
}
|
||||
|
||||
function startDownloadPolling() {
|
||||
emptyPolls = 0;
|
||||
if (downloadPollTimer) return;
|
||||
@@ -449,55 +542,147 @@ function stopDownloadPolling() {
|
||||
downloadPollTimer = null;
|
||||
}
|
||||
|
||||
// Map the pool's job list onto per-title flags, and auto-install once a job
|
||||
// finishes if "install after download" is on.
|
||||
function reconcileFromJobs(jobs) {
|
||||
const byId = new Map((jobs || []).map((j) => [j.title_id, j]));
|
||||
state.titles.forEach((g) => {
|
||||
const j = byId.get(g.title_id);
|
||||
if (!j) {
|
||||
// The pool never produced a job for our local intent: time it out so the
|
||||
// card can't wedge in "Downloading" forever (server restart between POST
|
||||
// and poll, or an unexpected response shape).
|
||||
if (g._localDownloading && g._localSince &&
|
||||
Date.now() - g._localSince > 12000) {
|
||||
g._localDownloading = false;
|
||||
}
|
||||
if (g.downloading && !g._localDownloading) g.downloading = false;
|
||||
return;
|
||||
}
|
||||
g._localDownloading = false; // the pool now tracks it
|
||||
if (j.state === "active" || j.state === "queued") {
|
||||
g.downloading = true;
|
||||
g.resumable = false;
|
||||
g._wasActive = true;
|
||||
} else if (j.state === "paused") {
|
||||
g.downloading = false;
|
||||
g.resumable = true;
|
||||
g.partial_bytes = Number(j.bytes) || g.partial_bytes || 0;
|
||||
g._wasActive = false;
|
||||
} else if (j.state === "done") {
|
||||
g.downloading = false;
|
||||
g.resumable = false;
|
||||
g.downloaded = true;
|
||||
g._wasActive = false;
|
||||
if (state.config.install_after_download && isInstallAllowed(g) &&
|
||||
!g.installing && !g._autoInstalled) {
|
||||
g._autoInstalled = true;
|
||||
doInstall(g);
|
||||
}
|
||||
} else if (j.state === "error") {
|
||||
// The server keeps the partial + sidecar (resumable) on a post-retry
|
||||
// network failure. Reflect that so primaryButton shows "Resume" and the
|
||||
// red Cancel stays available to delete the kept partial.
|
||||
const bytes = Number(j.bytes) || 0;
|
||||
if (g._wasActive) {
|
||||
showToast(`${g.name}: download failed${bytes > 0 ? " — partial kept, press Resume to continue" : "."}`);
|
||||
}
|
||||
g._wasActive = false;
|
||||
g.downloading = false;
|
||||
g.resumable = bytes > 0;
|
||||
g.partial_bytes = bytes || g.partial_bytes || 0;
|
||||
}
|
||||
});
|
||||
}
|
||||
|
||||
function startInstallPolling() {
|
||||
if (installPollTimer) return;
|
||||
installPollTimer = setInterval(refreshInstallStatus, 2000);
|
||||
refreshInstallStatus();
|
||||
}
|
||||
|
||||
function stopInstallPolling() {
|
||||
if (!installPollTimer) return;
|
||||
clearInterval(installPollTimer);
|
||||
installPollTimer = null;
|
||||
}
|
||||
|
||||
async function refreshInstallStatus() {
|
||||
let s;
|
||||
try {
|
||||
const response = await fetch(API.installStatus, { cache: "no-store" });
|
||||
if (!response.ok) throw new Error(`HTTP ${response.status}`);
|
||||
s = await response.json();
|
||||
} catch (error) {
|
||||
return;
|
||||
}
|
||||
|
||||
if (!s || !s.active) {
|
||||
if (!state.titles.some((g) => g.installing)) stopInstallPolling();
|
||||
return;
|
||||
}
|
||||
|
||||
const titleId = s.target_title_id || "";
|
||||
const game = state.titles.find((g) => g.title_id === titleId || g.title_id.slice(0, 9) === titleId.slice(0, 9));
|
||||
if (!game) return;
|
||||
|
||||
game.installing = !s.terminal;
|
||||
game.installStatus = s.status || "running";
|
||||
game.installProgress = Number(s.progress) || 0;
|
||||
game.installDone = Number(s.downloaded_size) || 0;
|
||||
game.installTotal = Number(s.total_size) || 0;
|
||||
renderGames();
|
||||
|
||||
if (s.terminal) {
|
||||
const ok = s.status === "playable";
|
||||
state.logs.push(`[${timeNow()}] Install ${ok ? "completed" : "stopped"} for ${game.title_id}: ${s.status || "unknown"}${s.error_code ? ` (0x${Number(s.error_code >>> 0).toString(16)})` : ""}`);
|
||||
renderLogs();
|
||||
stopInstallPolling();
|
||||
if (ok) loadInitialData();
|
||||
}
|
||||
}
|
||||
|
||||
async function refreshDownloads() {
|
||||
let downloads;
|
||||
let jobs;
|
||||
try {
|
||||
const response = await fetch(API.downloads, { cache: "no-store" });
|
||||
if (!response.ok) throw new Error(`HTTP ${response.status}`);
|
||||
downloads = await response.json();
|
||||
jobs = await response.json();
|
||||
} catch (error) {
|
||||
return; // keep last state on a transient failure
|
||||
}
|
||||
|
||||
const now = Date.now();
|
||||
const activeIds = new Set();
|
||||
downloads.forEach((d) => {
|
||||
activeIds.add(d.title_id);
|
||||
const done = Number(d.bytes) || 0;
|
||||
const prev = dlMeta[d.title_id];
|
||||
const ids = new Set();
|
||||
jobs.forEach((j) => {
|
||||
ids.add(j.title_id);
|
||||
const done = Number(j.bytes) || 0;
|
||||
const prev = dlMeta[j.title_id];
|
||||
if (prev && now > prev.t) {
|
||||
if (done >= prev.bytes) {
|
||||
const inst = ((done - prev.bytes) * 1000) / (now - prev.t); // bytes/s
|
||||
prev.speed = prev.speed ? prev.speed * 0.5 + inst * 0.5 : inst; // smoothed
|
||||
} else {
|
||||
prev.speed = 0; // counter went backwards -> re-baseline, no stale speed
|
||||
prev.speed = 0; // counter went backwards -> re-baseline
|
||||
}
|
||||
}
|
||||
const meta = prev || (dlMeta[d.title_id] = { speed: 0 });
|
||||
const meta = prev || (dlMeta[j.title_id] = { speed: 0 });
|
||||
meta.bytes = done;
|
||||
meta.t = now;
|
||||
d._speed = meta.speed || 0;
|
||||
j._speed = meta.speed || 0;
|
||||
});
|
||||
Object.keys(dlMeta).forEach((id) => { if (!activeIds.has(id)) delete dlMeta[id]; });
|
||||
Object.keys(dlMeta).forEach((id) => { if (!ids.has(id)) delete dlMeta[id]; });
|
||||
|
||||
state.downloads = downloads;
|
||||
|
||||
// Reconcile downloading flags with the server. A structural change (a download
|
||||
// appeared or finished) needs a full re-render to add/remove the progress block
|
||||
// and morph the button; otherwise update the bar in place.
|
||||
state.downloads = jobs;
|
||||
const before = downloadingIds();
|
||||
state.titles.forEach((g) => {
|
||||
if (activeIds.has(g.title_id)) g.downloading = true;
|
||||
else if (g.downloading && !g._localDownloading) g.downloading = false;
|
||||
});
|
||||
reconcileFromJobs(jobs);
|
||||
if (downloadingIds() !== before) renderGames();
|
||||
else applyDownloadProgress();
|
||||
|
||||
if (!downloads.length && !state.titles.some((g) => g.downloading)) {
|
||||
if (++emptyPolls >= 3) stopDownloadPolling();
|
||||
} else {
|
||||
emptyPolls = 0;
|
||||
}
|
||||
const busy = jobs.some((j) => j.state === "active" || j.state === "queued") ||
|
||||
state.titles.some((g) => g._localDownloading);
|
||||
if (!busy) { if (++emptyPolls >= 3) stopDownloadPolling(); }
|
||||
else emptyPolls = 0;
|
||||
}
|
||||
|
||||
function downloadingIds() {
|
||||
@@ -508,6 +693,11 @@ function downloadingIds() {
|
||||
function applyDownloadProgress() {
|
||||
let needRender = false;
|
||||
state.downloads.forEach((d) => {
|
||||
// Only titles currently downloading render a progress tile; paused/done/error
|
||||
// jobs linger in the pool list but have no .progress bar — skip them so a
|
||||
// missing tile for a non-downloading title doesn't force a full rebuild.
|
||||
const g = state.titles.find((t) => t.title_id === d.title_id);
|
||||
if (!g || !g.downloading) return;
|
||||
const card = els.gameGrid.querySelector(`[data-title-id="${d.title_id}"]`);
|
||||
const bar = card && card.querySelector(".card-progress .progress > i");
|
||||
const meta = card && card.querySelector(".card-progress .progress-meta");
|
||||
@@ -549,6 +739,7 @@ async function saveConfig() {
|
||||
delete_pkg_after_install: els.deleteAfterInstall.checked,
|
||||
verify_downloads: els.verifyDownloads ? els.verifyDownloads.checked : Boolean(state.config.verify_downloads),
|
||||
home_shortcut: els.homeShortcut ? els.homeShortcut.checked : state.config.home_shortcut !== false,
|
||||
max_connections: clampConn(state.config.max_connections),
|
||||
};
|
||||
try {
|
||||
await postJson(API.config, config);
|
||||
@@ -564,19 +755,55 @@ async function saveConfig() {
|
||||
|
||||
/* ---------------- actions (data layer) ---------------- */
|
||||
|
||||
// Queue a download for every game that has an available update AND could
|
||||
// actually be installed afterwards. Shadowmounts pass isDownloadAllowed but
|
||||
// fail isInstallAllowed (their app slot has no real source medium), so a
|
||||
// sweep would otherwise pull tens of GB that AppInstUtil will refuse — the
|
||||
// user picks those up by hand when the disc is ready. The server tolerates
|
||||
// duplicate requests, so a second click is harmless. If install_after_download
|
||||
// is on, the per-job auto-install pipeline kicks in once each download
|
||||
// finishes — no further client action needed.
|
||||
async function updateAll() {
|
||||
const targets = state.games.filter((g) =>
|
||||
g.status === "available" && isInstallAllowed(g) &&
|
||||
!g.downloading && !g.downloaded);
|
||||
if (!targets.length) {
|
||||
showToast("No installable updates to queue.");
|
||||
return;
|
||||
}
|
||||
showToast(`Queueing ${targets.length} update${targets.length === 1 ? "" : "s"}…`);
|
||||
for (const g of targets) {
|
||||
// Sequential await: the pool returns quickly (202 Accepted) and we want
|
||||
// a stable order in the queue, not a thundering-herd of concurrent POSTs.
|
||||
try { await doDownload(g); } catch (_) { /* per-job errors already toast */ }
|
||||
}
|
||||
}
|
||||
|
||||
// Enqueue a download. The pool returns immediately (202); progress, completion
|
||||
// and (if configured) auto-install are driven by reconcileFromJobs() on poll.
|
||||
async function doDownload(game) {
|
||||
game.downloading = true;
|
||||
game._localDownloading = true; // this client owns it; don't let a poll clear it
|
||||
game._localDownloading = true; // until the pool reports a job for this title
|
||||
game._localSince = Date.now(); // bounded in reconcileFromJobs if no job appears
|
||||
game._autoInstalled = false;
|
||||
state.downloads = state.downloads.filter((i) => i.title_id !== game.title_id);
|
||||
state.downloads.push({ title_id: game.title_id, name: game.name, version: game.compatible_version || "", progress: 0, bytes: 0, total_bytes: 0 });
|
||||
state.logs.push(`[${timeNow()}] Download started: ${game.title_id} ${game.compatible_version}`);
|
||||
state.downloads.push({ title_id: game.title_id, name: game.name,
|
||||
version: game.compatible_version || "",
|
||||
state: "queued", progress: 0, bytes: 0, total_bytes: 0 });
|
||||
renderGames();
|
||||
renderLogs();
|
||||
startDownloadPolling();
|
||||
|
||||
let r;
|
||||
try {
|
||||
r = await postJson(API.action(game.title_id, "download"), {});
|
||||
const r = await postJson(API.action(game.title_id, "download"), {});
|
||||
if (r && r.downloaded && r.already) {
|
||||
game.downloading = false;
|
||||
game._localDownloading = false;
|
||||
game.downloaded = true;
|
||||
renderGames();
|
||||
} else {
|
||||
state.logs.push(`[${timeNow()}] Download queued: ${game.title_id} ${game.compatible_version || ""}`);
|
||||
renderLogs();
|
||||
}
|
||||
} catch (error) {
|
||||
game.downloading = false;
|
||||
game._localDownloading = false;
|
||||
@@ -584,34 +811,14 @@ async function doDownload(game) {
|
||||
const why = reasonText(error);
|
||||
state.logs.push(`[${timeNow()}] download ${game.title_id} blocked: ${why}`);
|
||||
showToast(`${game.name}: ${why}`);
|
||||
renderGames(); renderLogs(); stopDownloadPolling();
|
||||
return false;
|
||||
renderGames(); renderLogs();
|
||||
}
|
||||
|
||||
game.downloading = false;
|
||||
game._localDownloading = false;
|
||||
state.downloads = state.downloads.filter((i) => i.title_id !== game.title_id);
|
||||
|
||||
// Cancel / soft failure returns HTTP 200 with ok:false (not thrown).
|
||||
if (!r || r.ok === false) {
|
||||
game.downloaded = false;
|
||||
const what = r && r.cancelled ? "cancelled" : "failed";
|
||||
state.logs.push(`[${timeNow()}] Download ${what}: ${game.title_id}`);
|
||||
showToast(`${game.name}: download ${what}.`);
|
||||
renderGames(); renderLogs(); stopDownloadPolling();
|
||||
return false;
|
||||
}
|
||||
|
||||
game.downloaded = true;
|
||||
const sz = r && r.bytes ? formatBytes(r.bytes) : "?";
|
||||
state.logs.push(`[${timeNow()}] Downloaded ${game.title_id} ${game.compatible_version} (${sz}, internal)`);
|
||||
showToast(`${game.name}: downloaded ${sz}.`);
|
||||
renderGames(); renderLogs(); stopDownloadPolling();
|
||||
return true;
|
||||
}
|
||||
|
||||
async function doInstall(game) {
|
||||
game.installing = true;
|
||||
game.installStatus = "starting";
|
||||
game.installProgress = 0;
|
||||
game.downloaded = false; // the package is being consumed by the install
|
||||
renderGames();
|
||||
try {
|
||||
@@ -625,7 +832,8 @@ async function doInstall(game) {
|
||||
return false;
|
||||
}
|
||||
state.logs.push(`[${timeNow()}] Install started for ${game.title_id} ${game.compatible_version} — running in PS5 background`);
|
||||
showToast(`${game.name}: installing update — progress shows in your PS5 notifications.`);
|
||||
showToast(`${game.name}: installing update.`);
|
||||
startInstallPolling();
|
||||
renderGames(); renderLogs();
|
||||
return true;
|
||||
}
|
||||
@@ -640,7 +848,13 @@ async function cancelDownload(titleId) {
|
||||
} catch (error) {
|
||||
showToast(`${game ? game.name : titleId}: ${reasonText(error)}`);
|
||||
}
|
||||
if (game) { game.downloading = false; game._localDownloading = false; game.downloaded = false; }
|
||||
if (game) {
|
||||
game.downloading = false;
|
||||
game._localDownloading = false;
|
||||
game.downloaded = false;
|
||||
game.resumable = false;
|
||||
game.partial_bytes = 0;
|
||||
}
|
||||
state.downloads = state.downloads.filter((i) => i.title_id !== titleId);
|
||||
state.logs.push(`[${timeNow()}] Download cancelled / deleted: ${titleId}`);
|
||||
renderGames(); renderLogs();
|
||||
@@ -650,10 +864,23 @@ async function cancelDownload(titleId) {
|
||||
async function runTitleAction(titleId, action) {
|
||||
const game = state.titles.find((i) => i.title_id === titleId);
|
||||
if (!game) return;
|
||||
if (action === "download") await doDownload(game);
|
||||
// "update" and "download" both just enqueue; for "update" (install-after-
|
||||
// download on) the reconciler auto-installs once the pool reports it done.
|
||||
if (action === "download" || action === "update") await doDownload(game);
|
||||
else if (action === "install") await doInstall(game);
|
||||
else if (action === "pause") await doPause(game);
|
||||
else if (action === "cancel") await cancelDownload(titleId);
|
||||
else if (action === "update") { if (await doDownload(game)) await doInstall(game); }
|
||||
}
|
||||
|
||||
// Pause only sends the signal; the in-flight doDownload() request returns its
|
||||
// "paused" result and updates the card (resumable + partial bytes).
|
||||
async function doPause(game) {
|
||||
try {
|
||||
await postJson(API.action(game.title_id, "pause"), {});
|
||||
showToast(`${game.name}: pausing…`);
|
||||
} catch (error) {
|
||||
showToast(`${game.name}: ${reasonText(error)}`);
|
||||
}
|
||||
}
|
||||
|
||||
function updateGame(titleId, patch) {
|
||||
@@ -671,11 +898,26 @@ function updateGame(titleId, patch) {
|
||||
/* ---------------- policy helpers ---------------- */
|
||||
|
||||
function isInstallBlocked(game) { return !sourcePolicy(game).allow_install; }
|
||||
function hasSharedStorage(game) {
|
||||
if (game.patch_storage_match === false) return true;
|
||||
const storage = (game.patch_storage_title_id || "").slice(0, 9);
|
||||
const target = (game.title_id || "").slice(0, 9);
|
||||
return Boolean(storage && target && storage !== target);
|
||||
}
|
||||
function isDownloadAllowed(game) {
|
||||
return Boolean(
|
||||
game.enabled !== false &&
|
||||
game.compatible_version &&
|
||||
game.patch_title_match !== false &&
|
||||
sourcePolicy(game).allow_download
|
||||
);
|
||||
}
|
||||
function isInstallAllowed(game) {
|
||||
return Boolean(
|
||||
game.enabled !== false &&
|
||||
game.compatible_version &&
|
||||
game.patch_title_match !== false &&
|
||||
!hasSharedStorage(game) &&
|
||||
sourcePolicy(game).allow_install
|
||||
);
|
||||
}
|
||||
@@ -704,6 +946,7 @@ async function postJson(url, body) {
|
||||
|
||||
const REASON_TEXT = {
|
||||
patch_title_mismatch: "Patch metadata targets a different title - install blocked.",
|
||||
cross_region_storage_unsupported: "Patch bytes are signed for a shared master title; this standalone installer cannot retarget them.",
|
||||
install_not_allowed_for_source: "Install blocked for this source.",
|
||||
source_unknown: "Source unknown — blocked.",
|
||||
no_compatible_patch: "No compatible patch available.",
|
||||
@@ -711,6 +954,8 @@ const REASON_TEXT = {
|
||||
download_in_progress: "Another download is already running.",
|
||||
piece_verify_failed: "A downloaded piece failed its SHA-256 check.",
|
||||
title_disabled: "This title is disabled.",
|
||||
download_paused: "Download paused.",
|
||||
not_downloading: "Nothing is downloading for this title.",
|
||||
};
|
||||
function reasonText(error) {
|
||||
const r = error && error.body && error.body.reason;
|
||||
|
||||
+19
-3
@@ -39,7 +39,7 @@
|
||||
<div class="brand-mark">PD</div>
|
||||
<div>
|
||||
<strong>PatchDL</strong>
|
||||
<span>by Knutwurst · v0.0.2</span>
|
||||
<span>by Knutwurst · v0.0.3</span>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
@@ -70,6 +70,10 @@
|
||||
<h1>Games</h1>
|
||||
</div>
|
||||
<div class="topbar-actions">
|
||||
<button class="primary-button" id="updateAllBtn" title="Download (and optionally install) every game that has an available, allowed update">
|
||||
<svg><use href="#icon-download"></use></svg>
|
||||
Update all
|
||||
</button>
|
||||
<button class="icon-button" id="refreshBtn" title="Refresh status and games" aria-label="Refresh">
|
||||
<svg><use href="#icon-refresh"></use></svg>
|
||||
</button>
|
||||
@@ -105,11 +109,12 @@
|
||||
<input id="searchInput" type="search" placeholder="Search title, Title ID, or Content ID" />
|
||||
</div>
|
||||
<div class="segmented" role="group" aria-label="Filter">
|
||||
<button class="is-selected" data-filter="all" aria-pressed="true">All</button>
|
||||
<button data-filter="updatable" aria-pressed="false">Updatable</button>
|
||||
<button class="is-selected" data-filter="updatable" aria-pressed="true">Updatable</button>
|
||||
<button data-filter="updating" aria-pressed="false">Updating</button>
|
||||
<button data-filter="uptodate" aria-pressed="false">Up to date</button>
|
||||
<button data-filter="needsfw" aria-pressed="false">Needs FW</button>
|
||||
<button data-filter="blocked" aria-pressed="false">Can't update</button>
|
||||
<button data-filter="all" aria-pressed="false">All</button>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
@@ -186,6 +191,17 @@
|
||||
<span class="track"></span>
|
||||
</span>
|
||||
</label>
|
||||
<div class="switch-row">
|
||||
<span>
|
||||
<strong>Parallel download connections</strong>
|
||||
<em>1–16 · applies live, no payload restart</em>
|
||||
</span>
|
||||
<div class="stepper" role="group" aria-label="Parallel download connections">
|
||||
<button type="button" class="stepper-btn" id="connMinus" aria-label="Fewer connections">−</button>
|
||||
<output class="stepper-value" id="connValue" aria-live="polite">4</output>
|
||||
<button type="button" class="stepper-btn" id="connPlus" aria-label="More connections">+</button>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="allowlist">
|
||||
|
||||
+35
-4
@@ -331,10 +331,13 @@ h2 { font-size: 18px; line-height: 1.2; }
|
||||
width: 100%; /* fills the fixed-width actions column -> never reflows */
|
||||
padding: 0 12px;
|
||||
}
|
||||
.row-button.is-update { border-color: var(--blue); color: #04111f; background: var(--blue); }
|
||||
.row-button.is-update:hover { background: var(--blue-dark); }
|
||||
.row-button.is-cancel { border-color: var(--amber); color: #1c1402; background: var(--amber); }
|
||||
.row-button.is-cancel:hover { background: var(--amber-dark); }
|
||||
/* go = green (Update / Resume / Install), pause = amber, cancel/stop = red */
|
||||
.row-button.is-update { border-color: var(--green); color: #04150c; background: var(--green); }
|
||||
.row-button.is-update:hover { background: var(--green-dark); }
|
||||
.row-button.is-pause { border-color: var(--amber); color: #1c1402; background: var(--amber); }
|
||||
.row-button.is-pause:hover { background: var(--amber-dark); }
|
||||
.row-button.is-cancel { border-color: var(--red); color: #1a0606; background: var(--red); }
|
||||
.row-button.is-cancel:hover { background: #ff8a8a; }
|
||||
.row-button.is-ghost { background: transparent; color: var(--muted); }
|
||||
.row-button.is-ghost:hover { color: var(--ink); border-color: var(--muted); }
|
||||
.row-button:disabled { opacity: 0.6; cursor: default; }
|
||||
@@ -392,6 +395,34 @@ h2 { font-size: 18px; line-height: 1.2; }
|
||||
background: var(--surface-2);
|
||||
border-radius: 8px;
|
||||
}
|
||||
|
||||
/* number stepper — big, controller-friendly targets with a clear focus ring
|
||||
(the UI is operated by the PS5 controller via the home tile). */
|
||||
.stepper { display: inline-flex; align-items: center; gap: 12px; flex: none; }
|
||||
.stepper-btn {
|
||||
width: 54px; height: 54px;
|
||||
display: inline-flex; align-items: center; justify-content: center;
|
||||
font-size: 30px; line-height: 1; font-weight: 600;
|
||||
color: var(--ink);
|
||||
background: var(--surface);
|
||||
border: 1px solid var(--border);
|
||||
border-radius: 14px;
|
||||
cursor: pointer;
|
||||
-webkit-tap-highlight-color: transparent;
|
||||
transition: background .12s ease, border-color .12s ease, transform .07s ease;
|
||||
}
|
||||
.stepper-btn:hover { background: var(--surface); border-color: var(--muted); }
|
||||
.stepper-btn:active { transform: scale(0.93); background: var(--green-soft); border-color: var(--green); }
|
||||
/* :focus (not only :focus-visible) so the controller's focus is always obvious */
|
||||
.stepper-btn:focus { outline: none; border-color: var(--green); box-shadow: 0 0 0 3px var(--green-soft); }
|
||||
.stepper-btn:disabled { opacity: 0.32; cursor: default; transform: none; }
|
||||
.stepper-value {
|
||||
min-width: 52px;
|
||||
text-align: center;
|
||||
font-size: 26px; font-weight: 700;
|
||||
font-variant-numeric: tabular-nums;
|
||||
color: var(--ink);
|
||||
}
|
||||
.switch-row > span:first-child strong { display: block; font-size: 14px; }
|
||||
.switch-row > span:first-child em { display: block; margin-top: 3px; color: var(--muted); font-size: 12px; font-style: normal; }
|
||||
|
||||
|
||||
Reference in new issue
Block a user