| 
									
										
										
										
											2018-08-16 17:08:13 -04:00
										 |  |  | // Copyright 2018 yuzu emulator team
 | 
					
						
							|  |  |  | // Licensed under GPLv2 or any later version
 | 
					
						
							|  |  |  | // Refer to the license.txt file included.
 | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-08-24 22:15:32 -04:00
										 |  |  | #include <algorithm>
 | 
					
						
							| 
									
										
										
										
											2018-08-16 17:08:13 -04:00
										 |  |  | #include <array>
 | 
					
						
							| 
									
										
										
										
											2018-08-24 22:15:32 -04:00
										 |  |  | #include <cstring>
 | 
					
						
							| 
									
										
										
										
											2018-08-16 17:08:13 -04:00
										 |  |  | #include <regex>
 | 
					
						
							|  |  |  | #include <string>
 | 
					
						
							| 
									
										
										
										
											2019-11-12 04:47:32 -05:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-08-16 17:08:13 -04:00
										 |  |  | #include <mbedtls/md.h>
 | 
					
						
							|  |  |  | #include <mbedtls/sha256.h>
 | 
					
						
							| 
									
										
										
										
											2019-11-12 04:47:32 -05:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-09-02 10:53:06 -04:00
										 |  |  | #include "common/file_util.h"
 | 
					
						
							| 
									
										
										
										
											2018-08-16 17:08:13 -04:00
										 |  |  | #include "common/hex_util.h"
 | 
					
						
							| 
									
										
										
										
											2019-11-12 04:47:32 -05:00
										 |  |  | #include "common/string_util.h"
 | 
					
						
							| 
									
										
										
										
											2018-08-16 17:08:13 -04:00
										 |  |  | #include "core/crypto/aes_util.h"
 | 
					
						
							|  |  |  | #include "core/crypto/xts_encryption_layer.h"
 | 
					
						
							|  |  |  | #include "core/file_sys/partition_filesystem.h"
 | 
					
						
							|  |  |  | #include "core/file_sys/vfs_offset.h"
 | 
					
						
							|  |  |  | #include "core/file_sys/xts_archive.h"
 | 
					
						
							|  |  |  | #include "core/loader/loader.h"
 | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | namespace FileSys { | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-08-18 21:14:57 -04:00
										 |  |  | constexpr u64 NAX_HEADER_PADDING_SIZE = 0x4000; | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-08-16 17:08:13 -04:00
										 |  |  | template <typename SourceData, typename SourceKey, typename Destination> | 
					
						
							| 
									
										
										
										
											2018-09-15 15:21:06 +02:00
										 |  |  | static bool CalculateHMAC256(Destination* out, const SourceKey* key, std::size_t key_length, | 
					
						
							|  |  |  |                              const SourceData* data, std::size_t data_length) { | 
					
						
							| 
									
										
										
										
											2018-08-16 17:08:13 -04:00
										 |  |  |     mbedtls_md_context_t context; | 
					
						
							|  |  |  |     mbedtls_md_init(&context); | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     if (mbedtls_md_setup(&context, mbedtls_md_info_from_type(MBEDTLS_MD_SHA256), 1) || | 
					
						
							|  |  |  |         mbedtls_md_hmac_starts(&context, reinterpret_cast<const u8*>(key), key_length) || | 
					
						
							|  |  |  |         mbedtls_md_hmac_update(&context, reinterpret_cast<const u8*>(data), data_length) || | 
					
						
							|  |  |  |         mbedtls_md_hmac_finish(&context, reinterpret_cast<u8*>(out))) { | 
					
						
							|  |  |  |         mbedtls_md_free(&context); | 
					
						
							|  |  |  |         return false; | 
					
						
							|  |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     mbedtls_md_free(&context); | 
					
						
							|  |  |  |     return true; | 
					
						
							|  |  |  | } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-09-19 13:45:29 -04:00
										 |  |  | NAX::NAX(VirtualFile file_) : header(std::make_unique<NAXHeader>()), file(std::move(file_)) { | 
					
						
							| 
									
										
										
										
											2018-08-16 17:08:13 -04:00
										 |  |  |     std::string path = FileUtil::SanitizePath(file->GetFullPath()); | 
					
						
							|  |  |  |     static const std::regex nax_path_regex("/registered/(000000[0-9A-F]{2})/([0-9A-F]{32})\\.nca", | 
					
						
							|  |  |  |                                            std::regex_constants::ECMAScript | | 
					
						
							|  |  |  |                                                std::regex_constants::icase); | 
					
						
							|  |  |  |     std::smatch match; | 
					
						
							|  |  |  |     if (!std::regex_search(path, match, nax_path_regex)) { | 
					
						
							|  |  |  |         status = Loader::ResultStatus::ErrorBadNAXFilePath; | 
					
						
							|  |  |  |         return; | 
					
						
							|  |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2019-11-12 04:47:32 -05:00
										 |  |  |     const std::string two_dir = Common::ToUpper(match[1]); | 
					
						
							|  |  |  |     const std::string nca_id = Common::ToLower(match[2]); | 
					
						
							| 
									
										
										
										
											2018-08-16 17:08:13 -04:00
										 |  |  |     status = Parse(fmt::format("/registered/{}/{}.nca", two_dir, nca_id)); | 
					
						
							|  |  |  | } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | NAX::NAX(VirtualFile file_, std::array<u8, 0x10> nca_id) | 
					
						
							| 
									
										
										
										
											2018-09-19 13:45:29 -04:00
										 |  |  |     : header(std::make_unique<NAXHeader>()), file(std::move(file_)) { | 
					
						
							| 
									
										
										
										
											2018-08-16 17:08:13 -04:00
										 |  |  |     Core::Crypto::SHA256Hash hash{}; | 
					
						
							| 
									
										
										
										
											2019-11-12 08:37:58 -05:00
										 |  |  |     mbedtls_sha256_ret(nca_id.data(), nca_id.size(), hash.data(), 0); | 
					
						
							| 
									
										
										
										
											2018-08-16 17:08:13 -04:00
										 |  |  |     status = Parse(fmt::format("/registered/000000{:02X}/{}.nca", hash[0], | 
					
						
							| 
									
										
										
										
											2019-06-12 17:27:06 -04:00
										 |  |  |                                Common::HexToString(nca_id, false))); | 
					
						
							| 
									
										
										
										
											2018-08-16 17:08:13 -04:00
										 |  |  | } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-09-19 19:19:05 -04:00
										 |  |  | NAX::~NAX() = default; | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-08-18 21:14:57 -04:00
										 |  |  | Loader::ResultStatus NAX::Parse(std::string_view path) { | 
					
						
							| 
									
										
										
										
											2020-07-20 10:30:25 -04:00
										 |  |  |     if (file == nullptr) { | 
					
						
							|  |  |  |         return Loader::ResultStatus::ErrorNullFile; | 
					
						
							|  |  |  |     } | 
					
						
							|  |  |  |     if (file->ReadObject(header.get()) != sizeof(NAXHeader)) { | 
					
						
							| 
									
										
										
										
											2018-08-16 17:08:13 -04:00
										 |  |  |         return Loader::ResultStatus::ErrorBadNAXHeader; | 
					
						
							| 
									
										
										
										
											2020-07-20 10:30:25 -04:00
										 |  |  |     } | 
					
						
							|  |  |  |     if (header->magic != Common::MakeMagic('N', 'A', 'X', '0')) { | 
					
						
							| 
									
										
										
										
											2018-08-16 17:08:13 -04:00
										 |  |  |         return Loader::ResultStatus::ErrorBadNAXHeader; | 
					
						
							| 
									
										
										
										
											2020-07-20 10:30:25 -04:00
										 |  |  |     } | 
					
						
							|  |  |  |     if (file->GetSize() < NAX_HEADER_PADDING_SIZE + header->file_size) { | 
					
						
							| 
									
										
										
										
											2018-08-16 17:08:13 -04:00
										 |  |  |         return Loader::ResultStatus::ErrorIncorrectNAXFileSize; | 
					
						
							| 
									
										
										
										
											2020-07-20 10:30:25 -04:00
										 |  |  |     } | 
					
						
							| 
									
										
										
										
											2018-08-16 17:08:13 -04:00
										 |  |  | 
 | 
					
						
							|  |  |  |     keys.DeriveSDSeedLazy(); | 
					
						
							|  |  |  |     std::array<Core::Crypto::Key256, 2> sd_keys{}; | 
					
						
							|  |  |  |     const auto sd_keys_res = Core::Crypto::DeriveSDKeys(sd_keys, keys); | 
					
						
							|  |  |  |     if (sd_keys_res != Loader::ResultStatus::Success) { | 
					
						
							|  |  |  |         return sd_keys_res; | 
					
						
							|  |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     const auto enc_keys = header->key_area; | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-09-15 15:21:06 +02:00
										 |  |  |     std::size_t i = 0; | 
					
						
							| 
									
										
										
										
											2018-08-18 21:14:57 -04:00
										 |  |  |     for (; i < sd_keys.size(); ++i) { | 
					
						
							| 
									
										
										
										
											2018-08-16 17:08:13 -04:00
										 |  |  |         std::array<Core::Crypto::Key128, 2> nax_keys{}; | 
					
						
							| 
									
										
										
										
											2019-11-13 10:02:08 -05:00
										 |  |  |         if (!CalculateHMAC256(nax_keys.data(), sd_keys[i].data(), 0x10, path.data(), path.size())) { | 
					
						
							| 
									
										
										
										
											2018-08-16 17:08:13 -04:00
										 |  |  |             return Loader::ResultStatus::ErrorNAXKeyHMACFailed; | 
					
						
							|  |  |  |         } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-09-15 15:21:06 +02:00
										 |  |  |         for (std::size_t j = 0; j < nax_keys.size(); ++j) { | 
					
						
							| 
									
										
										
										
											2018-08-16 17:08:13 -04:00
										 |  |  |             Core::Crypto::AESCipher<Core::Crypto::Key128> cipher(nax_keys[j], | 
					
						
							|  |  |  |                                                                  Core::Crypto::Mode::ECB); | 
					
						
							|  |  |  |             cipher.Transcode(enc_keys[j].data(), 0x10, header->key_area[j].data(), | 
					
						
							|  |  |  |                              Core::Crypto::Op::Decrypt); | 
					
						
							|  |  |  |         } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |         Core::Crypto::SHA256Hash validation{}; | 
					
						
							|  |  |  |         if (!CalculateHMAC256(validation.data(), &header->magic, 0x60, sd_keys[i].data() + 0x10, | 
					
						
							|  |  |  |                               0x10)) { | 
					
						
							|  |  |  |             return Loader::ResultStatus::ErrorNAXValidationHMACFailed; | 
					
						
							|  |  |  |         } | 
					
						
							|  |  |  |         if (header->hmac == validation) | 
					
						
							|  |  |  |             break; | 
					
						
							|  |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     if (i == 2) { | 
					
						
							|  |  |  |         return Loader::ResultStatus::ErrorNAXKeyDerivationFailed; | 
					
						
							|  |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     type = static_cast<NAXContentType>(i); | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     Core::Crypto::Key256 final_key{}; | 
					
						
							| 
									
										
										
										
											2018-08-18 21:14:57 -04:00
										 |  |  |     std::memcpy(final_key.data(), &header->key_area, final_key.size()); | 
					
						
							|  |  |  |     const auto enc_file = | 
					
						
							|  |  |  |         std::make_shared<OffsetVfsFile>(file, header->file_size, NAX_HEADER_PADDING_SIZE); | 
					
						
							| 
									
										
										
										
											2018-08-16 17:08:13 -04:00
										 |  |  |     dec_file = std::make_shared<Core::Crypto::XTSEncryptionLayer>(enc_file, final_key); | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     return Loader::ResultStatus::Success; | 
					
						
							|  |  |  | } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-08-18 21:14:57 -04:00
										 |  |  | Loader::ResultStatus NAX::GetStatus() const { | 
					
						
							| 
									
										
										
										
											2018-08-16 17:08:13 -04:00
										 |  |  |     return status; | 
					
						
							|  |  |  | } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-08-18 21:14:57 -04:00
										 |  |  | VirtualFile NAX::GetDecrypted() const { | 
					
						
							| 
									
										
										
										
											2018-08-16 17:08:13 -04:00
										 |  |  |     return dec_file; | 
					
						
							|  |  |  | } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-09-19 14:16:22 -04:00
										 |  |  | std::unique_ptr<NCA> NAX::AsNCA() const { | 
					
						
							| 
									
										
										
										
											2018-08-16 17:08:13 -04:00
										 |  |  |     if (type == NAXContentType::NCA) | 
					
						
							| 
									
										
										
										
											2018-09-19 14:16:22 -04:00
										 |  |  |         return std::make_unique<NCA>(GetDecrypted()); | 
					
						
							| 
									
										
										
										
											2018-08-16 17:08:13 -04:00
										 |  |  |     return nullptr; | 
					
						
							|  |  |  | } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-08-18 21:14:57 -04:00
										 |  |  | NAXContentType NAX::GetContentType() const { | 
					
						
							| 
									
										
										
										
											2018-08-16 17:08:13 -04:00
										 |  |  |     return type; | 
					
						
							|  |  |  | } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | std::vector<std::shared_ptr<VfsFile>> NAX::GetFiles() const { | 
					
						
							|  |  |  |     return {dec_file}; | 
					
						
							|  |  |  | } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | std::vector<std::shared_ptr<VfsDirectory>> NAX::GetSubdirectories() const { | 
					
						
							|  |  |  |     return {}; | 
					
						
							|  |  |  | } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | std::string NAX::GetName() const { | 
					
						
							|  |  |  |     return file->GetName(); | 
					
						
							|  |  |  | } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | std::shared_ptr<VfsDirectory> NAX::GetParentDirectory() const { | 
					
						
							|  |  |  |     return file->GetContainingDirectory(); | 
					
						
							|  |  |  | } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | } // namespace FileSys
 |