Skip to content

Commit 604f301

Browse files
authored
use MbedTLS (#263)
* Update exec_cmd.c * mbedtls * param.sfo psid * clean up * fixes * Update psv_resign.c * Update psv_ps2.c * Update owner_xml.c * Update sfo.c
1 parent d89856c commit 604f301

10 files changed

Lines changed: 63 additions & 75 deletions

File tree

‎Makefile‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ CONTENT_ID := IV0000-APOL00004_00-APOLLO0000000PS4
88
LIBS := -lc -lkernel -lc++ -lSceAudioOut -lSceUserService -lScePigletv2VSH -lSceSysmodule -lSceFreeType -lSQLite \
99
-lScePad -lSceSystemService -lSceSaveData -lSceCommonDialog -lSceMsgDialog -lSceNet -lSceNetCtl -lcurl \
1010
-lmbedtls -lmbedx509 -lmbedcrypto -lmini18n \
11-
-lSceRegMgr -lSceImeDialog -lSDL2 -lapollo -ldbglogger -lpolarssl -lz -lzip -ljbc -lmxml -lunrar -lun7zip -ls3m
11+
-lSceRegMgr -lSceImeDialog -lSDL2 -lapollo -ldbglogger -lz -lzip -ljbc -lmxml -lunrar -lun7zip -ls3m
1212

1313
# Additional compile flags.
1414
EXTRAFLAGS := -fcolor-diagnostics -Wall -D__PS4__

‎source/exec_cmd.c‎

Lines changed: 8 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@
77
#include <orbis/SystemService.h>
88
#include <orbis/UserService.h>
99
#include <orbis/SystemService.h>
10-
#include <polarssl/md5.h>
10+
#include <mbedtls/md5.h>
1111
#include <mini18n.h>
1212

1313
#include "saves.h"
@@ -291,6 +291,7 @@ static int _copy_save_hdd(const save_entry_t* save)
291291
sfo_patch_t patch = {
292292
.user_id = apollo_config.user_id,
293293
.account_id = apollo_config.account_id,
294+
.psid = (uint8_t*) apollo_config.psid,
294295
};
295296

296297
if (!orbis_SaveMount(save, ORBIS_SAVE_DATA_MOUNT_MODE_RDWR | ORBIS_SAVE_DATA_MOUNT_MODE_CREATE2 | ORBIS_SAVE_DATA_MOUNT_MODE_COPY_ICON, mount))
@@ -319,6 +320,7 @@ static int _copy_save_pfs(const save_entry_t* save)
319320
sfo_patch_t patch = {
320321
.user_id = apollo_config.user_id,
321322
.account_id = apollo_config.account_id,
323+
.psid = (uint8_t*) apollo_config.psid,
322324
};
323325

324326
snprintf(src_path, sizeof(src_path), "%s%s.bin", save->path, save->dir_name);
@@ -695,13 +697,14 @@ static int webReqHandler(dWebRequest_t* req, dWebResponse_t* res, void* list)
695697
if (strcmp(req->resource, "/") == 0)
696698
{
697699
uint64_t hash[2];
698-
md5_context ctx;
700+
mbedtls_md5_context ctx;
699701

700-
md5_starts(&ctx);
702+
mbedtls_md5_init(&ctx);
703+
mbedtls_md5_starts(&ctx);
701704
for (node = list_head(list); (item = list_get(node)); node = list_next(node))
702-
md5_update(&ctx, (uint8_t*) item->name, strlen(item->name));
705+
mbedtls_md5_update(&ctx, (uint8_t*) item->name, strlen(item->name));
703706

704-
md5_finish(&ctx, (uint8_t*) hash);
707+
mbedtls_md5_finish(&ctx, (uint8_t*) hash);
705708
asprintf(&res->data, APOLLO_LOCAL_CACHE "web%016lx%016lx.html", hash[0], hash[1]);
706709

707710
if (file_exists(res->data) == SUCCESS)
@@ -1344,7 +1347,6 @@ static void uploadAllSavesFTP(const save_entry_t* save, int all)
13441347
char *tmp = NULL;
13451348
char mount[ORBIS_SAVE_DATA_DIRNAME_DATA_MAXSIZE];
13461349
int done = 0, err_count = 0;
1347-
uint64_t progress = 0;
13481350
list_node_t *node;
13491351
save_entry_t *item;
13501352
list_t *list = ((void**)save->dir_name)[0];

‎source/menu_about.c‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -67,7 +67,7 @@ static void draw_sinetext(int y, const char* string)
6767
static void _setIdValues()
6868
{
6969
// set to display the PSID on the About menu
70-
snprintf(psid_str, sizeof(psid_str), "%016lX %016lX", apollo_config.psid[0], apollo_config.psid[1]);
70+
snprintf(psid_str, sizeof(psid_str), "%016lX %016lX", ES64(apollo_config.psid[0]), ES64(apollo_config.psid[1]));
7171
snprintf(user_id_str, sizeof(user_id_str), "%08x", apollo_config.user_id);
7272
snprintf(account_id_str, sizeof(account_id_str), "%016lx", apollo_config.account_id);
7373
}

‎source/owner_xml.c‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -103,7 +103,7 @@ int save_xml_owner(const char *xmlfile)
103103

104104
node = mxmlNewElement(group, "console");
105105
mxmlElementSetAttr(node, "idps", "");
106-
snprintf(tmp, sizeof(tmp), "%016lX %016lX", apollo_config.psid[0], apollo_config.psid[1]);
106+
snprintf(tmp, sizeof(tmp), "%016lX %016lX", ES64(apollo_config.psid[0]), ES64(apollo_config.psid[1]));
107107
mxmlElementSetAttr(node, "psid", tmp);
108108

109109
node = mxmlNewElement(group, "user");

‎source/ps1card.c‎

Lines changed: 13 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -8,8 +8,8 @@
88
#include <string.h>
99
#include <stdbool.h>
1010
#include <ctype.h>
11-
#include <polarssl/aes.h>
12-
#include <polarssl/sha256.h>
11+
#include <mbedtls/aes.h>
12+
#include <mbedtls/sha256.h>
1313

1414
#include "ps1card.h"
1515
#include "util.h"
@@ -38,28 +38,28 @@ static const uint8_t mcxIv[] = { 0x13, 0xC2, 0xE7, 0x69, 0x4B, 0xEC, 0x69, 0x6D
3838
static void AesCbcEncrypt(uint8_t* toEncrypt, size_t len, const uint8_t* key, const uint8_t* aes_iv)
3939
{
4040
uint8_t iv[16];
41-
aes_context ctx;
41+
mbedtls_aes_context ctx;
4242

4343
memcpy(iv, aes_iv, 16);
4444

45-
aes_init(&ctx);
46-
aes_setkey_enc(&ctx, key, 128);
47-
aes_crypt_cbc(&ctx, AES_ENCRYPT, len, iv, toEncrypt, toEncrypt);
48-
aes_free(&ctx);
45+
mbedtls_aes_init(&ctx);
46+
mbedtls_aes_setkey_enc(&ctx, key, 128);
47+
mbedtls_aes_crypt_cbc(&ctx, MBEDTLS_AES_ENCRYPT, len, iv, toEncrypt, toEncrypt);
48+
mbedtls_aes_free(&ctx);
4949
}
5050

5151
//Decrypts a buffer using AES CBC 128
5252
static void AesCbcDecrypt(uint8_t* toDecrypt, size_t len, const uint8_t* key, const uint8_t* aes_iv)
5353
{
5454
uint8_t iv[16];
55-
aes_context ctx;
55+
mbedtls_aes_context ctx;
5656

5757
memcpy(iv, aes_iv, 16);
5858

59-
aes_init(&ctx);
60-
aes_setkey_dec(&ctx, key, 128);
61-
aes_crypt_cbc(&ctx, AES_DECRYPT, len, iv, toDecrypt, toDecrypt);
62-
aes_free(&ctx);
59+
mbedtls_aes_init(&ctx);
60+
mbedtls_aes_setkey_dec(&ctx, key, 128);
61+
mbedtls_aes_crypt_cbc(&ctx, MBEDTLS_AES_DECRYPT, len, iv, toDecrypt, toDecrypt);
62+
mbedtls_aes_free(&ctx);
6363
}
6464

6565
//Load Data from raw Memory Card
@@ -181,7 +181,7 @@ static void MakeMcxCard(const uint8_t* rawCard, FILE* fp)
181181

182182
memset(mcxCard, 0, 0x80);
183183
memcpy(mcxCard + 0x80, rawCard, PS1CARD_SIZE);
184-
sha256(mcxCard, 0x20080, mcxCard + 0x20080, 0);
184+
mbedtls_sha256(mcxCard, 0x20080, mcxCard + 0x20080, 0);
185185

186186
AesCbcEncrypt(mcxCard, 0x200A0, mcxKey, mcxIv);
187187
fwrite(mcxCard, 1, 0x200A0, fp);

‎source/psv_ps2.c‎

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@
55

66
#include <stdio.h>
77
#include <zlib.h>
8-
#include <polarssl/arc4.h>
8+
#include <mbedtls/arc4.h>
99

1010
#include "util.h"
1111
#include "lzari.h"
@@ -296,11 +296,11 @@ int ps2_max2psv(const char *save, const char* psv_path)
296296

297297
static void cbsCrypt(uint8_t *buf, size_t bufLen)
298298
{
299-
arc4_context ctx;
299+
mbedtls_arc4_context ctx;
300300

301-
memset(&ctx, 0, sizeof(arc4_context));
301+
mbedtls_arc4_init(&ctx);
302302
memcpy(ctx.m, cbsKey, sizeof(cbsKey));
303-
arc4_crypt(&ctx, bufLen, buf, buf);
303+
mbedtls_arc4_crypt(&ctx, bufLen, buf, buf);
304304
}
305305

306306
static int isCBSFile(const char *path)

‎source/psv_resign.c‎

Lines changed: 21 additions & 21 deletions
Original file line numberDiff line numberDiff line change
@@ -8,8 +8,8 @@
88
#include <string.h>
99
#include <stdio.h>
1010
#include <stdlib.h>
11-
#include <polarssl/aes.h>
12-
#include <polarssl/sha1.h>
11+
#include <mbedtls/aes.h>
12+
#include <mbedtls/sha1.h>
1313

1414
#include "types.h"
1515
#include "util.h"
@@ -67,14 +67,14 @@ static void XorWithIv(uint8_t* buf, const uint8_t* Iv)
6767

6868
static void generateHash(const uint8_t *input, const uint8_t *salt_seed, uint8_t *dest, size_t sz, uint8_t type)
6969
{
70-
aes_context aes_ctx;
71-
sha1_context sha1_ctx;
70+
mbedtls_aes_context aes_ctx;
71+
mbedtls_sha1_context sha1_ctx;
7272
uint8_t iv[0x10];
7373
uint8_t salt[0x40];
7474
uint8_t work_buf[0x14];
7575

7676
memset(salt , 0, sizeof(salt));
77-
memset(&aes_ctx, 0, sizeof(aes_context));
77+
mbedtls_aes_init(&aes_ctx);
7878

7979
LOG("Type detected: %d", type);
8080
if(type == PSV_TYPE_PS1)
@@ -83,10 +83,10 @@ static void generateHash(const uint8_t *input, const uint8_t *salt_seed, uint8_t
8383
//idk why the normal cbc doesn't work.
8484
memcpy(work_buf, salt_seed, 0x10);
8585

86-
aes_setkey_dec(&aes_ctx, psv_ps1key, 128);
87-
aes_crypt_ecb(&aes_ctx, AES_DECRYPT, work_buf, salt);
88-
aes_setkey_enc(&aes_ctx, psv_ps1key, 128);
89-
aes_crypt_ecb(&aes_ctx, AES_ENCRYPT, work_buf, salt + 0x10);
86+
mbedtls_aes_setkey_dec(&aes_ctx, psv_ps1key, 128);
87+
mbedtls_aes_crypt_ecb(&aes_ctx, MBEDTLS_AES_DECRYPT, work_buf, salt);
88+
mbedtls_aes_setkey_enc(&aes_ctx, psv_ps1key, 128);
89+
mbedtls_aes_crypt_ecb(&aes_ctx, MBEDTLS_AES_ENCRYPT, work_buf, salt + 0x10);
9090

9191
XorWithIv(salt, psv_iv);
9292

@@ -101,8 +101,8 @@ static void generateHash(const uint8_t *input, const uint8_t *salt_seed, uint8_t
101101
memcpy(salt, salt_seed, 0x14);
102102
memcpy(iv, psv_iv, sizeof(iv));
103103

104-
aes_setkey_dec(&aes_ctx, psv_ps2key, 128);
105-
aes_crypt_cbc(&aes_ctx, AES_DECRYPT, sizeof(salt), iv, salt, salt);
104+
mbedtls_aes_setkey_dec(&aes_ctx, psv_ps2key, 128);
105+
mbedtls_aes_crypt_cbc(&aes_ctx, MBEDTLS_AES_DECRYPT, sizeof(salt), iv, salt, salt);
106106
}
107107
else
108108
{
@@ -115,19 +115,19 @@ static void generateHash(const uint8_t *input, const uint8_t *salt_seed, uint8_t
115115

116116
XorWithByte(salt, 0x36, sizeof(salt));
117117

118-
memset(&sha1_ctx, 0, sizeof(sha1_context));
119-
sha1_starts(&sha1_ctx);
120-
sha1_update(&sha1_ctx, salt, sizeof(salt));
121-
sha1_update(&sha1_ctx, input, sz);
122-
sha1_finish(&sha1_ctx, work_buf);
118+
mbedtls_sha1_init(&sha1_ctx);
119+
mbedtls_sha1_starts(&sha1_ctx);
120+
mbedtls_sha1_update(&sha1_ctx, salt, sizeof(salt));
121+
mbedtls_sha1_update(&sha1_ctx, input, sz);
122+
mbedtls_sha1_finish(&sha1_ctx, work_buf);
123123

124124
XorWithByte(salt, 0x6A, sizeof(salt));
125125

126-
memset(&sha1_ctx, 0, sizeof(sha1_context));
127-
sha1_starts(&sha1_ctx);
128-
sha1_update(&sha1_ctx, salt, sizeof(salt));
129-
sha1_update(&sha1_ctx, work_buf, 0x14);
130-
sha1_finish(&sha1_ctx, dest);
126+
mbedtls_sha1_init(&sha1_ctx);
127+
mbedtls_sha1_starts(&sha1_ctx);
128+
mbedtls_sha1_update(&sha1_ctx, salt, sizeof(salt));
129+
mbedtls_sha1_update(&sha1_ctx, work_buf, 0x14);
130+
mbedtls_sha1_finish(&sha1_ctx, dest);
131131
}
132132

133133
int psv_resign(const char *src_psv)

‎source/settings.c‎

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -372,8 +372,6 @@ int load_app_settings(app_config_t* config)
372372

373373
sceUserServiceGetNpAccountId(config->user_id, &config->account_id);
374374
sceKernelGetOpenPsIdForSystem(config->psid);
375-
config->psid[0] = ES64(config->psid[0]);
376-
config->psid[1] = ES64(config->psid[1]);
377375

378376
if (sceSaveDataInitialize3(0) != SUCCESS)
379377
{

‎source/sfo.c‎

Lines changed: 12 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -1,11 +1,15 @@
11
#include <apollo.h>
2+
#include <mbedtls/md.h>
23
#include "sfo.h"
34
#include "util.h"
45

56
#define PKG_MAGIC 0x544E437Fu
67
#define SFO_MAGIC 0x46535000u
78
#define SFO_VERSION 0x0101u /* 1.1 */
89

10+
// https://www.psdevwiki.com/ps4/Keys#param.sfo_OpenPSID_HMAC-SHA256_Key
11+
static const u8 PSID_HMAC_KEY[] = { 0x13, 0xD1, 0xDF, 0x06, 0x75, 0xC9, 0xFD, 0x95, 0x0A, 0x17, 0xE5, 0x64, 0xC2, 0x77, 0x7F, 0x2C };
12+
913
typedef struct sfo_header_s {
1014
u32 magic;
1115
u32 version;
@@ -25,7 +29,7 @@ typedef struct sfo_index_table_s {
2529
typedef struct sfo_param_params_s {
2630
u32 unk1;
2731
u32 user_id;
28-
u8 unk2[32];
32+
u8 psid_hmac[32];
2933
u32 unk3;
3034
char title_id_1[0x10];
3135
char title_id_2[0x10];
@@ -354,7 +358,7 @@ static void sfo_patch_titleid(sfo_context_t *inout) {
354358
sfo_context_param_t *p;
355359

356360
p = sfo_context_get_param(inout, "PARAMS");
357-
if (p != NULL) {
361+
if (p != NULL && p->actual_length > 0x50) {
358362
sfo_param_params_t *params = (sfo_param_params_t *)p->value;
359363
memcpy(params->title_id_2, params->title_id_1, sizeof(params->title_id_1));
360364
}
@@ -370,13 +374,6 @@ static void sfo_patch_account(sfo_context_t *inout, u64 account) {
370374
if (p != NULL && p->actual_length == SFO_ACCOUNT_ID_SIZE) {
371375
memcpy(p->value, &account, SFO_ACCOUNT_ID_SIZE);
372376
}
373-
/*
374-
p = sfo_context_get_param(inout, "PARAMS");
375-
if (p != NULL) {
376-
sfo_param_params_t *params = (sfo_param_params_t *)p->value;
377-
memcpy(params->account_id, account, SFO_ACCOUNT_ID_SIZE);
378-
}
379-
*/
380377
}
381378

382379
static void sfo_patch_user_id(sfo_context_t *inout, u32 userid) {
@@ -386,26 +383,27 @@ static void sfo_patch_user_id(sfo_context_t *inout, u32 userid) {
386383
return;
387384

388385
p = sfo_context_get_param(inout, "PARAMS");
389-
if (p != NULL) {
386+
if (p != NULL && p->actual_length > 0x50) {
390387
sfo_param_params_t *params = (sfo_param_params_t *)p->value;
391388
params->user_id = userid;
392389
}
393390
}
394391

395-
/*
396392
void sfo_patch_psid(sfo_context_t *inout, u8* psid) {
397393
sfo_context_param_t *p;
398394

399395
if (!psid)
400396
return;
401397

402398
p = sfo_context_get_param(inout, "PARAMS");
403-
if (p != NULL) {
399+
if (p != NULL && p->actual_length > 0x50) {
404400
sfo_param_params_t *params = (sfo_param_params_t *)p->value;
405-
memcpy(params->psid, psid, SFO_PSID_SIZE);
401+
if (mbedtls_md_hmac(mbedtls_md_info_from_type(MBEDTLS_MD_SHA256), PSID_HMAC_KEY, sizeof(PSID_HMAC_KEY), psid, SFO_PSID_SIZE, params->psid_hmac) != 0)
402+
LOG("Failed to calculate PSID HMAC");
406403
}
407404
}
408405

406+
/*
409407
void sfo_patch_directory(sfo_context_t *inout, const char* save_dir) {
410408
sfo_context_param_t *p;
411409
@@ -444,7 +442,7 @@ int patch_sfo(const char *in_file_path, sfo_patch_t* patches) {
444442
sfo_patch_titleid(sfo);
445443
sfo_patch_account(sfo, patches->account_id);
446444
sfo_patch_user_id(sfo, patches->user_id);
447-
// sfo_patch_psid(sfo, patches->psid);
445+
sfo_patch_psid(sfo, patches->psid);
448446
// sfo_patch_directory(sfo, patches->directory);
449447

450448
if (sfo_write(sfo, in_file_path) < 0) {

‎source/util.c‎

Lines changed: 2 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
#include "util.h"
22
#include "types.h"
33

4-
#include <polarssl/sha1.h>
4+
#include <mbedtls/md.h>
55

66
void dump_data(const u8 *data, u64 size) {
77
u64 i;
@@ -67,20 +67,10 @@ int write_file(const char *file_path, u8 *data, u64 size) {
6767
}
6868

6969
int calculate_hmac_hash(const u8 *data, u64 size, const u8 *key, u32 key_length, u8 output[20]) {
70-
sha1_context sha1;
71-
7270
if (!key_length || !output)
7371
return -1;
7472

75-
memset(&sha1, 0, sizeof(sha1_context));
76-
77-
sha1_hmac_starts(&sha1, key, key_length);
78-
sha1_hmac_update(&sha1, data, size);
79-
sha1_hmac_finish(&sha1, output);
80-
81-
memset(&sha1, 0, sizeof(sha1_context));
82-
83-
return 0;
73+
return mbedtls_md_hmac(mbedtls_md_info_from_type(MBEDTLS_MD_SHA1), key, key_length, data, size, output);
8474
}
8575

8676
u64 align_to_pow2(u64 offset, u64 alignment) {

0 commit comments

Comments
 (0)