Replace the single sequential transfer with a pool of N worker threads that pull pieces of one manifest in parallel, lifting the per-connection ~7 MB/s ceiling. One job runs at a time; the rest queue. The connection count is configurable (1-16, default 4) and applies on the next start. Resume is tracked per piece in a sidecar bitmap that survives a reboot, and a one-time migration recognises a partial written by the old sequential build (a piece-aligned contiguous prefix on disk) and marks those pieces done so an in-progress download is not restarted from zero. Pause keeps the partial; Cancel deletes it. Both, plus Resume, are available at any point in a download's life. Concurrency review fixes folded in: - a job is published as the active (claimable) job only after its manifest/state/fd are attached, so a half-built job can no longer be settled to "done" before any bytes are fetched - cancel/pause during the admit I/O window only flag the job; admit_next is the sole finalizer, closing a use-after-free and a lost-pause race - resuming a paused job frees the stale per-job buffers and zeroes the committed counters before re-seeding, fixing a leak and a double-count - the background version.xml thread is joined on shutdown before the title list is freed - verify_downloads is snapshotted under its own lock before the pool lock - the web UI keeps Resume/Cancel after a failed transfer and bounds the local "downloading" bridge flag so a card cannot wedge
PatchDL Web UI
Standalone static UI for the planned PS5 patchdl.elf web server.
Open index.html directly for the mock UI, or serve this directory from the
ELF web server. The JavaScript first tries the real API and falls back to demo
data when the API is not available.
The embedded ELF server serves this UI on port 12880 by default.
Expected API
GET /api/status
GET /api/config
POST /api/config
GET /api/titles
GET /api/downloads
POST /api/titles/:title_id/check
POST /api/titles/:title_id/download
POST /api/titles/:title_id/install
POST /api/titles/:title_id/enable
POST /api/titles/:title_id/disable
Policy Model
The UI assumes deny-by-default behavior:
{
"default_policy": "deny",
"download_dir": "/data/patchdl (internal)",
"install_after_download": false,
"delete_pkg_after_install": true,
"source_policy": {
"official": { "allow_check": true, "allow_download": true, "allow_install": true },
"external": { "allow_check": true, "allow_download": true, "allow_install": true },
"shadowmount": { "allow_check": true, "allow_download": true, "allow_install": false },
"unknown": { "allow_check": true, "allow_download": false, "allow_install": false }
},
"cdn_allowlist": [
"sgst.prod.dl.playstation.net",
"gst.prod.dl.playstation.net",
"gs2.ww.prod.dl.playstation.net"
]
}
Per-title modes:
disabled
download_only
latest_compatible
pin
check_only
Per-title source fields:
{
"title_id": "PPSA90001_00",
"name": "Shadowmounted Test Title",
"source_type": "shadowmount",
"source_path": "/system_ex/app/PPSA90001_00",
"mount_from": "/mnt/usb0/itemzflow/Shadowmounted Test Title",
"enabled": true,
"mode": "download_only"
}
Supported source_type values:
official
external
shadowmount
unknown
The frontend treats shadowmount as download-only and unknown as blocked for
downloads and installs. Backend code should enforce the same policy even if a
client sends a forged request.
For PS5 game updates, the backend may turn a Sony manifest_url into a merged
local .pkg by downloading all manifest pieces. The delta_url *-DP.pkg is
not shown as a separate user action because it can bootstrap the storage/master
title instead of the installed regional target.