0
0
镜像自地址 https://github.com/THZoria/NX_Firmware.git 已同步 2026-04-09 10:41:13 +00:00

比较提交

...

6 次代码提交
22.0.0 ... main

作者 SHA1 备注 提交日期
Zoria
a9e20653cf Merge pull request #22 from JeremKOYTB/main
Massive Upgrade: Implement Strict NCA Crypto-Verification and Deterministic Archives
2026-04-08 21:07:07 +02:00
JérémKO
332d8f1f2f Update: Implement dynamic release body generation and streamline Python execution
-Removed the version argument from the Python script execution step.

-Removed the manual .nca file cleanup and ZIP creation steps.

-Added log extraction (tee and sed) to dynamically populate the GitHub Release body via $GITHUB_ENV.
2026-04-08 20:41:11 +02:00
JérémKO
5b7ae87b50 Massive Upgrade: Implement Detailed NCA Hash Verification and Deterministic Archive Generation
-Added SHA-256 hash verification for downloaded .nca files against .cnmt records.

-Implemented ZipInfo to hardcode ZIP metadata (timestamps, OS, permissions) for deterministic hashing.

-Changed compression method from ZIP_DEFLATED to ZIP_STORED.
2026-04-08 20:37:54 +02:00
Zoria
e642f574fd Merge pull request #21 from JeremKOYTB/main
Fix: Ignore case for exFAT file identification (Fixes 404 on 22.1.0)
2026-04-08 18:35:06 +02:00
JérémKO
fb77608da9 Fix: Ignore case for exFAT file identification (Fixes 404 on 22.1.0) 2026-04-08 18:04:07 +02:00
Zoria
cd09390cd5 Refactor firmware version check and download process 2026-03-17 07:11:08 +01:00
修改 2 个文件,包含 81 行新增74 行删除

查看文件

@@ -35,105 +35,63 @@ jobs:
echo "Warning: hactool-linux non trouvé." echo "Warning: hactool-linux non trouvé."
fi fi
- name: 🔍 Check firmware version (Switch 1 only, >=21.0.0 strict) - name: 🔍 Check firmware version (Switch 1 only, >=21.0.0)
id: version_check id: version_check
shell: bash shell: bash
run: | run: |
set +e set +e
# Récupération du flux RSS
RSS=$(curl -sL --fail https://yls8.mtheall.com/ninupdates/feed.php) RSS=$(curl -sL --fail https://yls8.mtheall.com/ninupdates/feed.php)
if [ $? -ne 0 ] || [ -z "$RSS" ]; then if [ $? -ne 0 ] || [ -z "$RSS" ]; then
echo "ERROR: Impossible de récupérer le flux RSS."
echo "new_version=false" >> $GITHUB_OUTPUT echo "new_version=false" >> $GITHUB_OUTPUT
exit 0 exit 0
fi fi
# LOGIQUE DE DÉTECTION ROBUSTE : # Extraction stricte Switch 1 (hac) + Tri version
# 1. On extrait les blocs <item> pour ne pas mélanger les données
# 2. On filtre uniquement ceux qui contiennent 'sys=hac' (Switch 1)
# 3. On extrait le numéro de version X.X.X
# 4. On trie par version (sort -V) et on prend la plus haute
LATEST_VERSION=$(echo "$RSS" | tr -d '\n' | sed 's/<item>/\n<item>/g' | \ LATEST_VERSION=$(echo "$RSS" | tr -d '\n' | sed 's/<item>/\n<item>/g' | \
grep 'sys=hac' | \ grep 'sys=hac' | grep -oE '[0-9]+\.[0-9]+\.[0-9]+' | sort -V | tail -n 1)
grep -oE '[0-9]+\.[0-9]+\.[0-9]+' | \
sort -V | tail -n 1)
if [ -z "$LATEST_VERSION" ]; then if [ -z "$LATEST_VERSION" ]; then
echo "INFO: Aucun firmware Switch 1 trouvé."
echo "new_version=false" >> $GITHUB_OUTPUT echo "new_version=false" >> $GITHUB_OUTPUT
exit 0 exit 0
fi fi
echo "Dernière version Switch 1 détectée : $LATEST_VERSION"
# Vérification du seuil (>= 21)
MAJOR=$(echo "$LATEST_VERSION" | cut -d. -f1) MAJOR=$(echo "$LATEST_VERSION" | cut -d. -f1)
if [ "$MAJOR" -lt 21 ]; then if [ "$MAJOR" -lt 21 ]; then
echo "INFO: Version $LATEST_VERSION ignorée (seuil < 21)."
echo "new_version=false" >> $GITHUB_OUTPUT echo "new_version=false" >> $GITHUB_OUTPUT
exit 0 exit 0
fi fi
# Vérification si la release existe déjà # Check si la Release existe
HTTP_STATUS=$(curl -s -o /dev/null -w "%{http_code}" \ HTTP_STATUS=$(curl -s -o /dev/null -w "%{http_code}" \
-H "Authorization: token ${{ secrets.GITHUB_TOKEN }}" \ -H "Authorization: token ${{ secrets.GITHUB_TOKEN }}" \
"https://api.github.com/repos/${{ github.repository }}/releases/tags/$LATEST_VERSION") "https://api.github.com/repos/${{ github.repository }}/releases/tags/$LATEST_VERSION")
if [ "$HTTP_STATUS" = "200" ]; then if [ "$HTTP_STATUS" = "200" ]; then
echo "INFO: La release $LATEST_VERSION existe déjà."
echo "new_version=false" >> $GITHUB_OUTPUT echo "new_version=false" >> $GITHUB_OUTPUT
else else
echo "ACTION: Nouvelle version $LATEST_VERSION détectée !"
echo "new_version=true" >> $GITHUB_OUTPUT echo "new_version=true" >> $GITHUB_OUTPUT
echo "firmware_version=$LATEST_VERSION" >> $GITHUB_OUTPUT echo "firmware_version=$LATEST_VERSION" >> $GITHUB_OUTPUT
fi fi
set -e set -e
- name: 💻 Execute download script and capture changelog - name: 💻 Execute download script & Extract Release Notes
id: download id: download
if: steps.version_check.outputs.new_version == 'true' if: steps.version_check.outputs.new_version == 'true'
run: | run: |
python3 firmware_downloader.py | tee firmware_output.txt VERSION="${{ steps.version_check.outputs.firmware_version }}"
# Extraction de la version confirmée par le script (nettoyage des retours chariot) # Exécution SANS paramètre pour que le script interroge lui-même l'API Nintendo
F_VER=$(grep 'Folder: Firmware ' firmware_output.txt | awk '{print $NF}' | tr -d '\r') python3 firmware_downloader.py | tee script_output.log
echo "firmware_version=$VERSION" >> $GITHUB_OUTPUT
if [ -z "$F_VER" ]; then # Extraction stricte des dernières lignes générées par le script Python
F_VER="${{ steps.version_check.outputs.firmware_version }}" sed -n '/Archive created:/,$p' script_output.log > changelog_body.txt
fi
echo "firmware_version=$F_VER" >> $GITHUB_OUTPUT # Stockage sécurisé et multi-lignes du texte pour GitHub Actions
tail -n 10 firmware_output.txt > changelog_body.txt EOF=$(dd if=/dev/urandom bs=15 count=1 status=none | base64)
echo "CHANGELOG_CONTENT<<$EOF" >> $GITHUB_ENV
- name: 🧹 Clean and zip firmware cat changelog_body.txt >> $GITHUB_ENV
if: steps.version_check.outputs.new_version == 'true' echo "$EOF" >> $GITHUB_ENV
run: |
VERSION="${{ steps.download.outputs.firmware_version }}"
find . -type f -name "*.nca.*" -delete
if [ -d "Firmware $VERSION" ]; then
rm -f "Firmware $VERSION.zip"
zip -rj "Firmware $VERSION.zip" "Firmware $VERSION/" -i "*.nca"
else
echo "ERROR: Dossier Firmware $VERSION introuvable."
exit 1
fi
- name: 📝 Prepare Release Body
id: prepare_body
if: steps.version_check.outputs.new_version == 'true'
uses: actions/github-script@v7
with:
script: |
const fs = require('fs');
let body = "Automatic download of official Nintendo Switch firmware.";
if (fs.existsSync('changelog_body.txt')) {
const changelog = fs.readFileSync('changelog_body.txt', 'utf8');
body += "\n\n**Changelog / Output:**\n```\n" + changelog + "\n```";
}
core.setOutput('release_body', body);
- name: 📦 Create Tag and Release - name: 📦 Create Tag and Release
if: steps.version_check.outputs.new_version == 'true' if: steps.version_check.outputs.new_version == 'true'
@@ -141,7 +99,11 @@ jobs:
with: with:
tag_name: ${{ steps.download.outputs.firmware_version }} tag_name: ${{ steps.download.outputs.firmware_version }}
name: Firmware ${{ steps.download.outputs.firmware_version }} name: Firmware ${{ steps.download.outputs.firmware_version }}
body: ${{ steps.prepare_body.outputs.release_body }} body: |
Automatic download of the official Nintendo Switch firmware version ${{ steps.download.outputs.firmware_version }}.
Downloaded file details:
${{ env.CHANGELOG_CONTENT }}
files: | files: |
Firmware ${{ steps.download.outputs.firmware_version }}.zip Firmware ${{ steps.download.outputs.firmware_version }}.zip
env: env:

查看文件

@@ -13,7 +13,7 @@ from os import makedirs, remove
from os.path import basename, exists, join from os.path import basename, exists, join
from configparser import ConfigParser from configparser import ConfigParser
from sys import argv from sys import argv
from zipfile import ZipFile, ZIP_DEFLATED from zipfile import ZipFile, ZIP_STORED, ZipInfo
from requests import request from requests import request
from requests.exceptions import HTTPError from requests.exceptions import HTTPError
@@ -121,15 +121,15 @@ def nin_request(method, url, headers=None):
def parse_cnmt(nca): def parse_cnmt(nca):
ncaf = basename(nca) ncaf = basename(nca)
# --- MODIFICATION CLÉ --- # --- KEY MODIFICATION ---
# Force l'utilisation de l'exécutable hactool dans le répertoire courant. # Force the use of the hactool executable in the current directory.
# Dans le workflow, hactool-linux a été renommé en hactool et rendu exécutable. # In the workflow, hactool-linux was renamed to hactool and made executable.
hactool_bin = "hactool.exe" if os.name == "nt" else "./hactool" hactool_bin = "hactool.exe" if os.name == "nt" else "./hactool"
# ----------------------- # -----------------------
cnmt_temp_dir = f"cnmt_tmp_{ncaf}" cnmt_temp_dir = f"cnmt_tmp_{ncaf}"
# Le script tente de lancer './hactool' # The script attempts to run './hactool'
run( run(
[hactool_bin, "-k", "prod.keys", nca, "--section0dir", cnmt_temp_dir], [hactool_bin, "-k", "prod.keys", nca, "--section0dir", cnmt_temp_dir],
stdout=PIPE, stderr=PIPE stdout=PIPE, stderr=PIPE
@@ -181,7 +181,7 @@ def dltitle(title_id, version, is_su=False):
except HTTPError as e: except HTTPError as e:
if e.response is not None and e.response.status_code == 404: if e.response is not None and e.response.status_code == 404:
print(f"INFO: Title {title_id} version {version} not found (404).") print(f"INFO: Title {title_id} version {version} not found (404).")
if title_id == "010000000000081B": if title_id.lower() == "010000000000081b":
sv_nca_exfat = "" sv_nca_exfat = ""
return return
raise raise
@@ -201,9 +201,9 @@ def dltitle(title_id, version, is_su=False):
dltitle(t_id, ver) dltitle(t_id, ver)
else: else:
for nca_id, nca_hash in parse_cnmt(cnmt_nca): for nca_id, nca_hash in parse_cnmt(cnmt_nca):
if title_id == "0100000000000809": if title_id.lower() == "0100000000000809":
sv_nca_fat = f"{nca_id}.nca" sv_nca_fat = f"{nca_id}.nca"
elif title_id == "010000000000081B": elif title_id.lower() == "010000000000081b":
sv_nca_exfat = f"{nca_id}.nca" sv_nca_exfat = f"{nca_id}.nca"
if nca_id not in queued_ncas: if nca_id not in queued_ncas:
@@ -217,12 +217,22 @@ def dltitle(title_id, version, is_su=False):
)) ))
def zipdir(src_dir, out_zip): def zipdir(src_dir, out_zip):
with ZipFile(out_zip, "w", compression=ZIP_DEFLATED) as zf: with ZipFile(out_zip, "w", compression=ZIP_STORED) as zf:
for root, _, files in os.walk(src_dir): for root, dirs, files in os.walk(src_dir):
for name in files: dirs.sort()
for name in sorted(files):
full = os.path.join(root, name) full = os.path.join(root, name)
rel = os.path.relpath(full, start=src_dir) rel = os.path.relpath(full, start=src_dir)
zf.write(full, arcname=rel) os.utime(full, (1780315200, 1780315200))
zinfo = ZipInfo.from_file(full, arcname=rel)
zinfo.date_time = (2026, 1, 1, 0, 0, 0)
zinfo.create_system = 0
zinfo.external_attr = 0
zinfo.compress_type = ZIP_STORED
with open(full, 'rb') as f:
zf.writestr(zinfo, f.read())
if __name__ == "__main__": if __name__ == "__main__":
if not exists("certificat.pem"): if not exists("certificat.pem"):
@@ -296,8 +306,8 @@ if __name__ == "__main__":
dlfiles(update_dls) dlfiles(update_dls)
if not sv_nca_exfat: if not sv_nca_exfat:
print("INFO: exFAT not found via meta — direct attempt 010000000000081B") print("INFO: exFAT not found via meta — direct attempt 010000000000081b")
dltitle("010000000000081B", ver_raw, is_su=False) dltitle("010000000000081b", ver_raw, is_su=False)
if sv_nca_exfat: if sv_nca_exfat:
dlfiles(update_dls) dlfiles(update_dls)
else: else:
@@ -311,13 +321,48 @@ if __name__ == "__main__":
if failed: if failed:
exit(1) exit(1)
print("\nINFO: Starting detailed verification of NCA hashes...")
hash_failed = False
for url, dirc, fname, expected_hash in update_dls:
fpath = join(dirc, fname)
if exists(fpath):
h = hashlib.sha256()
with open(fpath, "rb") as f:
for chunk in iter(lambda: f.read(1048576), b""):
h.update(chunk)
actual_hash = h.hexdigest()
if actual_hash == expected_hash:
print(f"[OK] {fname}")
print(f" -> Verified Hash: {actual_hash}")
else:
print(f"[ERROR] {fname}")
print(f" Expected : {expected_hash}")
print(f" Actual : {actual_hash}")
hash_failed = True
else:
print(f"[MISSING] {fname}")
hash_failed = True
if hash_failed:
print("\nCRITICAL: Hash verification failed for one or more files. Archive will not be created.")
exit(1)
else:
print("\nINFO: All files successfully verified against CNMT records.")
out_zip = f"{ver_dir}.zip" out_zip = f"{ver_dir}.zip"
if exists(out_zip): if exists(out_zip):
remove(out_zip) remove(out_zip)
zipdir(ver_dir, out_zip) zipdir(ver_dir, out_zip)
h = hashlib.sha256()
with open(out_zip, "rb") as f:
for chunk in iter(lambda: f.read(1048576), b""):
h.update(chunk)
zip_sha256 = h.hexdigest()
print("\nDOWNLOAD COMPLETE!") print("\nDOWNLOAD COMPLETE!")
print(f"Archive created: {out_zip}") print(f"Archive created: {out_zip}")
print(f"SystemVersion NCA FAT: {sv_nca_fat or 'Not Found'}") print(f"SystemVersion NCA FAT: {sv_nca_fat or 'Not Found'}")
print(f"SystemVersion NCA exFAT: {sv_nca_exfat or 'Not Found'}") print(f"SystemVersion NCA exFAT: {sv_nca_exfat or 'Not Found'}")
print(f"Archive SHA256: {zip_sha256}")
print("Verify hashes before installation!") print("Verify hashes before installation!")