Skip to content

feat(nx-object): read an NCA and the PFS0 archives it carries - #13

Merged
LNSD merged 1 commit into
mainfrom
lnsd/read-nca-and-pfs0
Aug 18, 2026
Merged

LNSD merged 1 commit into
mainfrom
lnsd/read-nca-and-pfs0

Conversation

@LNSD

@LNSD LNSD commented Aug 17, 2026

Copy link
Copy Markdown
Contributor

The crate could build both formats but not read either, so a consumer verifying what it packed had to re-derive the layouts itself. These readers close that gap while keeping the crate's no-crypto contract: an NCA arrives already decrypted, and the magic check is what catches a caller who skipped that step.

  • Add read::pfs0, proving the entry table, the string table, and every file's bounds at construction, so a file's bytes come back as a plain slice rather than a Result
  • Add read::nca, validating section extents, hash and encryption types, and each superblock's data region, and exposing a section's byte range and AES-CTR counter so a caller can decrypt in place
  • Model a section's verification structure as a Superblock enum rather than two optional fields, since the hash type is what decides which of the two the same 0x138 bytes are
  • Recover the single key generation the header splits across crypto_type and crypto_type2, inverting how the builder writes it

The crate could build both formats but not read either, so a consumer verifying what it packed had to re-derive the layouts itself. These readers close that gap while keeping the crate's no-crypto contract: an NCA arrives already decrypted, and the magic check is what catches a caller who skipped that step.

- Add `read::pfs0`, proving the entry table, the string table, and every file's bounds at construction, so a file's bytes come back as a plain slice rather than a `Result`
- Add `read::nca`, validating section extents, hash and encryption types, and each superblock's data region, and exposing a section's byte range and AES-CTR counter so a caller can decrypt in place
- Model a section's verification structure as a `Superblock` enum rather than two optional fields, since the hash type is what decides which of the two the same `0x138` bytes are
- Recover the single key generation the header splits across `crypto_type` and `crypto_type2`, inverting how the builder writes it

Signed-off-by: Lorenzo Delgado <lnsdev@proton.me>
@LNSD
LNSD added this pull request to the merge queue Aug 18, 2026
Merged via the queue into main with commit 3283a55 Aug 18, 2026
5 checks passed
@LNSD
LNSD deleted the lnsd/read-nca-and-pfs0 branch August 18, 2026 07:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant