0
0
镜像自地址 https://github.com/THZoria/NX_Firmware.git 已同步 2026-04-09 10:41:13 +00:00

比较提交

...

11 次代码提交

作者 SHA1 备注 提交日期
Zoria
a9e20653cf Merge pull request #22 from JeremKOYTB/main
Massive Upgrade: Implement Strict NCA Crypto-Verification and Deterministic Archives
2026-04-08 21:07:07 +02:00
JérémKO
332d8f1f2f Update: Implement dynamic release body generation and streamline Python execution
-Removed the version argument from the Python script execution step.

-Removed the manual .nca file cleanup and ZIP creation steps.

-Added log extraction (tee and sed) to dynamically populate the GitHub Release body via $GITHUB_ENV.
2026-04-08 20:41:11 +02:00
JérémKO
5b7ae87b50 Massive Upgrade: Implement Detailed NCA Hash Verification and Deterministic Archive Generation
-Added SHA-256 hash verification for downloaded .nca files against .cnmt records.

-Implemented ZipInfo to hardcode ZIP metadata (timestamps, OS, permissions) for deterministic hashing.

-Changed compression method from ZIP_DEFLATED to ZIP_STORED.
2026-04-08 20:37:54 +02:00
Zoria
e642f574fd Merge pull request #21 from JeremKOYTB/main
Fix: Ignore case for exFAT file identification (Fixes 404 on 22.1.0)
2026-04-08 18:35:06 +02:00
JérémKO
fb77608da9 Fix: Ignore case for exFAT file identification (Fixes 404 on 22.1.0) 2026-04-08 18:04:07 +02:00
Zoria
cd09390cd5 Refactor firmware version check and download process 2026-03-17 07:11:08 +01:00
Zoria
df02467cdd Improve firmware download workflow and messages
Refactor firmware download workflow for clarity and accuracy.
2026-03-17 07:06:25 +01:00
Zoria
a3b5ff8eea Refactor firmware autodl workflow for improved checks 2026-03-17 07:04:25 +01:00
Zoria
bf849d454d Add lxml to Python module installation 2026-03-17 07:01:41 +01:00
Zoria
e5cac716b8 Refactor firmware autodl workflow for better handling
Updated the firmware autodl workflow to improve Python script and file handling.
2026-03-17 07:00:35 +01:00
Zoria
9f2d533eb2 Refactor firmware extraction and version handling 2026-03-17 06:52:05 +01:00
修改 2 个文件,包含 94 行新增87 行删除

查看文件

@@ -28,105 +28,70 @@ jobs:
- name: ⬇️ Setup hactool-linux
run: |
cp hactool-linux hactool
chmod +x hactool
if [ -f "hactool-linux" ]; then
cp hactool-linux hactool
chmod +x hactool
else
echo "Warning: hactool-linux non trouvé."
fi
- name: 🔍 Check firmware version (Switch 1 only, >=21.0.0 strict)
- name: 🔍 Check firmware version (Switch 1 only, >=21.0.0)
id: version_check
shell: bash
run: |
set +e
RSS=$(curl -sL --fail https://yls8.mtheall.com/ninupdates/feed.php)
CURL_STATUS=$?
if [ $CURL_STATUS -ne 0 ] || [ -z "$RSS" ]; then
echo "INFO: Impossible de récupérer le RSS."
if [ $? -ne 0 ] || [ -z "$RSS" ]; then
echo "new_version=false" >> $GITHUB_OUTPUT
exit 0
fi
# Extraire description Switch (ignore Switch 2)
DESCRIPTION=$(echo "$RSS" | grep -oE '<description>Switch [0-9]+\.[0-9]+\.[0-9]+' | \
grep -v 'Switch 2' | \
head -n 1)
# Extraction stricte Switch 1 (hac) + Tri version
LATEST_VERSION=$(echo "$RSS" | tr -d '\n' | sed 's/<item>/\n<item>/g' | \
grep 'sys=hac' | grep -oE '[0-9]+\.[0-9]+\.[0-9]+' | sort -V | tail -n 1)
if [ -z "$DESCRIPTION" ]; then
echo "INFO: Aucun firmware Switch valide trouvé."
if [ -z "$LATEST_VERSION" ]; then
echo "new_version=false" >> $GITHUB_OUTPUT
exit 0
fi
echo "Description détectée : $DESCRIPTION"
VERSION=$(echo "$DESCRIPTION" | grep -oE '[0-9]+\.[0-9]+\.[0-9]+')
if [ -z "$VERSION" ]; then
echo "INFO: Impossible d'extraire la version."
echo "new_version=false" >> $GITHUB_OUTPUT
exit 0
fi
MAJOR=$(echo "$VERSION" | cut -d. -f1)
# Autorise uniquement 21+
MAJOR=$(echo "$LATEST_VERSION" | cut -d. -f1)
if [ "$MAJOR" -lt 21 ]; then
echo "INFO: Firmware $VERSION ignoré (<21.x)."
echo "new_version=false" >> $GITHUB_OUTPUT
exit 0
fi
echo "Version valide détectée : $VERSION"
# Check si la Release existe
HTTP_STATUS=$(curl -s -o /dev/null -w "%{http_code}" \
-H "Authorization: token ${{ secrets.GITHUB_TOKEN }}" \
"https://api.github.com/repos/${{ github.repository }}/releases/tags/$VERSION")
"https://api.github.com/repos/${{ github.repository }}/releases/tags/$LATEST_VERSION")
if [ "$HTTP_STATUS" = "200" ]; then
echo "INFO: La release $VERSION existe déjà."
echo "new_version=false" >> $GITHUB_OUTPUT
else
echo "INFO: Nouvelle version $VERSION détectée !"
echo "new_version=true" >> $GITHUB_OUTPUT
echo "firmware_version=$VERSION" >> $GITHUB_OUTPUT
echo "firmware_version=$LATEST_VERSION" >> $GITHUB_OUTPUT
fi
set -e
- name: 💻 Execute download script and capture changelog
- name: 💻 Execute download script & Extract Release Notes
id: download
if: steps.version_check.outputs.new_version == 'true'
run: |
python3 firmware_downloader.py | tee firmware_output.txt
FIRMWARE_VERSION=$(grep 'Folder: Firmware ' firmware_output.txt | awk '{print $NF}')
echo "firmware_version=$FIRMWARE_VERSION" >> $GITHUB_OUTPUT
tail -n 4 firmware_output.txt > changelog_body.txt
- name: 🧹 Clean and zip firmware
if: steps.version_check.outputs.new_version == 'true'
run: |
VERSION="${{ steps.download.outputs.firmware_version }}"
find . -type f -name "*.nca.*" -delete
if [ -d "Firmware $VERSION" ]; then
rm -f "Firmware $VERSION.zip"
zip -rj "Firmware $VERSION.zip" "Firmware $VERSION/" -i "*.nca"
fi
- name: 📝 Prepare Release Body
id: prepare_body
if: steps.version_check.outputs.new_version == 'true'
uses: actions/github-script@v7
with:
script: |
const fs = require('fs');
if (fs.existsSync('changelog_body.txt')) {
const changelogBody = fs.readFileSync('changelog_body.txt', 'utf8');
core.setOutput('release_body', changelogBody);
} else {
core.setOutput('release_body', 'No changelog available.');
}
VERSION="${{ steps.version_check.outputs.firmware_version }}"
# Exécution SANS paramètre pour que le script interroge lui-même l'API Nintendo
python3 firmware_downloader.py | tee script_output.log
echo "firmware_version=$VERSION" >> $GITHUB_OUTPUT
# Extraction stricte des dernières lignes générées par le script Python
sed -n '/Archive created:/,$p' script_output.log > changelog_body.txt
# Stockage sécurisé et multi-lignes du texte pour GitHub Actions
EOF=$(dd if=/dev/urandom bs=15 count=1 status=none | base64)
echo "CHANGELOG_CONTENT<<$EOF" >> $GITHUB_ENV
cat changelog_body.txt >> $GITHUB_ENV
echo "$EOF" >> $GITHUB_ENV
- name: 📦 Create Tag and Release
if: steps.version_check.outputs.new_version == 'true'
@@ -135,13 +100,10 @@ jobs:
tag_name: ${{ steps.download.outputs.firmware_version }}
name: Firmware ${{ steps.download.outputs.firmware_version }}
body: |
Automatic download of the official Nintendo Switch firmware version **${{ steps.download.outputs.firmware_version }}**.
Automatic download of the official Nintendo Switch firmware version ${{ steps.download.outputs.firmware_version }}.
---
**Downloaded file details:**
${{ steps.prepare_body.outputs.release_body }}
Downloaded file details:
${{ env.CHANGELOG_CONTENT }}
files: |
Firmware ${{ steps.download.outputs.firmware_version }}.zip
env:

查看文件

@@ -13,7 +13,7 @@ from os import makedirs, remove
from os.path import basename, exists, join
from configparser import ConfigParser
from sys import argv
from zipfile import ZipFile, ZIP_DEFLATED
from zipfile import ZipFile, ZIP_STORED, ZipInfo
from requests import request
from requests.exceptions import HTTPError
@@ -121,15 +121,15 @@ def nin_request(method, url, headers=None):
def parse_cnmt(nca):
ncaf = basename(nca)
# --- MODIFICATION CLÉ ---
# Force l'utilisation de l'exécutable hactool dans le répertoire courant.
# Dans le workflow, hactool-linux a été renommé en hactool et rendu exécutable.
# --- KEY MODIFICATION ---
# Force the use of the hactool executable in the current directory.
# In the workflow, hactool-linux was renamed to hactool and made executable.
hactool_bin = "hactool.exe" if os.name == "nt" else "./hactool"
# -----------------------
cnmt_temp_dir = f"cnmt_tmp_{ncaf}"
# Le script tente de lancer './hactool'
# The script attempts to run './hactool'
run(
[hactool_bin, "-k", "prod.keys", nca, "--section0dir", cnmt_temp_dir],
stdout=PIPE, stderr=PIPE
@@ -181,7 +181,7 @@ def dltitle(title_id, version, is_su=False):
except HTTPError as e:
if e.response is not None and e.response.status_code == 404:
print(f"INFO: Title {title_id} version {version} not found (404).")
if title_id == "010000000000081B":
if title_id.lower() == "010000000000081b":
sv_nca_exfat = ""
return
raise
@@ -201,9 +201,9 @@ def dltitle(title_id, version, is_su=False):
dltitle(t_id, ver)
else:
for nca_id, nca_hash in parse_cnmt(cnmt_nca):
if title_id == "0100000000000809":
if title_id.lower() == "0100000000000809":
sv_nca_fat = f"{nca_id}.nca"
elif title_id == "010000000000081B":
elif title_id.lower() == "010000000000081b":
sv_nca_exfat = f"{nca_id}.nca"
if nca_id not in queued_ncas:
@@ -217,12 +217,22 @@ def dltitle(title_id, version, is_su=False):
))
def zipdir(src_dir, out_zip):
with ZipFile(out_zip, "w", compression=ZIP_DEFLATED) as zf:
for root, _, files in os.walk(src_dir):
for name in files:
with ZipFile(out_zip, "w", compression=ZIP_STORED) as zf:
for root, dirs, files in os.walk(src_dir):
dirs.sort()
for name in sorted(files):
full = os.path.join(root, name)
rel = os.path.relpath(full, start=src_dir)
zf.write(full, arcname=rel)
os.utime(full, (1780315200, 1780315200))
zinfo = ZipInfo.from_file(full, arcname=rel)
zinfo.date_time = (2026, 1, 1, 0, 0, 0)
zinfo.create_system = 0
zinfo.external_attr = 0
zinfo.compress_type = ZIP_STORED
with open(full, 'rb') as f:
zf.writestr(zinfo, f.read())
if __name__ == "__main__":
if not exists("certificat.pem"):
@@ -296,8 +306,8 @@ if __name__ == "__main__":
dlfiles(update_dls)
if not sv_nca_exfat:
print("INFO: exFAT not found via meta — direct attempt 010000000000081B")
dltitle("010000000000081B", ver_raw, is_su=False)
print("INFO: exFAT not found via meta — direct attempt 010000000000081b")
dltitle("010000000000081b", ver_raw, is_su=False)
if sv_nca_exfat:
dlfiles(update_dls)
else:
@@ -311,13 +321,48 @@ if __name__ == "__main__":
if failed:
exit(1)
print("\nINFO: Starting detailed verification of NCA hashes...")
hash_failed = False
for url, dirc, fname, expected_hash in update_dls:
fpath = join(dirc, fname)
if exists(fpath):
h = hashlib.sha256()
with open(fpath, "rb") as f:
for chunk in iter(lambda: f.read(1048576), b""):
h.update(chunk)
actual_hash = h.hexdigest()
if actual_hash == expected_hash:
print(f"[OK] {fname}")
print(f" -> Verified Hash: {actual_hash}")
else:
print(f"[ERROR] {fname}")
print(f" Expected : {expected_hash}")
print(f" Actual : {actual_hash}")
hash_failed = True
else:
print(f"[MISSING] {fname}")
hash_failed = True
if hash_failed:
print("\nCRITICAL: Hash verification failed for one or more files. Archive will not be created.")
exit(1)
else:
print("\nINFO: All files successfully verified against CNMT records.")
out_zip = f"{ver_dir}.zip"
if exists(out_zip):
remove(out_zip)
zipdir(ver_dir, out_zip)
h = hashlib.sha256()
with open(out_zip, "rb") as f:
for chunk in iter(lambda: f.read(1048576), b""):
h.update(chunk)
zip_sha256 = h.hexdigest()
print("\nDOWNLOAD COMPLETE!")
print(f"Archive created: {out_zip}")
print(f"SystemVersion NCA FAT: {sv_nca_fat or 'Not Found'}")
print(f"SystemVersion NCA exFAT: {sv_nca_exfat or 'Not Found'}")
print("Verify hashes before installation!")
print(f"Archive SHA256: {zip_sha256}")
print("Verify hashes before installation!")