0
0
镜像自地址 https://github.com/THZoria/NX_Firmware.git 已同步 2026-04-09 10:41:13 +00:00

比较提交

...

11 次代码提交

作者 SHA1 备注 提交日期
Zoria
a9e20653cf Merge pull request #22 from JeremKOYTB/main
Massive Upgrade: Implement Strict NCA Crypto-Verification and Deterministic Archives
2026-04-08 21:07:07 +02:00
JérémKO
332d8f1f2f Update: Implement dynamic release body generation and streamline Python execution
-Removed the version argument from the Python script execution step.

-Removed the manual .nca file cleanup and ZIP creation steps.

-Added log extraction (tee and sed) to dynamically populate the GitHub Release body via $GITHUB_ENV.
2026-04-08 20:41:11 +02:00
JérémKO
5b7ae87b50 Massive Upgrade: Implement Detailed NCA Hash Verification and Deterministic Archive Generation
-Added SHA-256 hash verification for downloaded .nca files against .cnmt records.

-Implemented ZipInfo to hardcode ZIP metadata (timestamps, OS, permissions) for deterministic hashing.

-Changed compression method from ZIP_DEFLATED to ZIP_STORED.
2026-04-08 20:37:54 +02:00
Zoria
e642f574fd Merge pull request #21 from JeremKOYTB/main
Fix: Ignore case for exFAT file identification (Fixes 404 on 22.1.0)
2026-04-08 18:35:06 +02:00
JérémKO
fb77608da9 Fix: Ignore case for exFAT file identification (Fixes 404 on 22.1.0) 2026-04-08 18:04:07 +02:00
Zoria
cd09390cd5 Refactor firmware version check and download process 2026-03-17 07:11:08 +01:00
Zoria
df02467cdd Improve firmware download workflow and messages
Refactor firmware download workflow for clarity and accuracy.
2026-03-17 07:06:25 +01:00
Zoria
a3b5ff8eea Refactor firmware autodl workflow for improved checks 2026-03-17 07:04:25 +01:00
Zoria
bf849d454d Add lxml to Python module installation 2026-03-17 07:01:41 +01:00
Zoria
e5cac716b8 Refactor firmware autodl workflow for better handling
Updated the firmware autodl workflow to improve Python script and file handling.
2026-03-17 07:00:35 +01:00
Zoria
9f2d533eb2 Refactor firmware extraction and version handling 2026-03-17 06:52:05 +01:00
修改 2 个文件,包含 94 行新增87 行删除

查看文件

@@ -28,105 +28,70 @@ jobs:
- name: ⬇️ Setup hactool-linux - name: ⬇️ Setup hactool-linux
run: | run: |
cp hactool-linux hactool if [ -f "hactool-linux" ]; then
chmod +x hactool cp hactool-linux hactool
chmod +x hactool
else
echo "Warning: hactool-linux non trouvé."
fi
- name: 🔍 Check firmware version (Switch 1 only, >=21.0.0 strict) - name: 🔍 Check firmware version (Switch 1 only, >=21.0.0)
id: version_check id: version_check
shell: bash shell: bash
run: | run: |
set +e set +e
RSS=$(curl -sL --fail https://yls8.mtheall.com/ninupdates/feed.php) RSS=$(curl -sL --fail https://yls8.mtheall.com/ninupdates/feed.php)
CURL_STATUS=$? if [ $? -ne 0 ] || [ -z "$RSS" ]; then
if [ $CURL_STATUS -ne 0 ] || [ -z "$RSS" ]; then
echo "INFO: Impossible de récupérer le RSS."
echo "new_version=false" >> $GITHUB_OUTPUT echo "new_version=false" >> $GITHUB_OUTPUT
exit 0 exit 0
fi fi
# Extraire description Switch (ignore Switch 2) # Extraction stricte Switch 1 (hac) + Tri version
DESCRIPTION=$(echo "$RSS" | grep -oE '<description>Switch [0-9]+\.[0-9]+\.[0-9]+' | \ LATEST_VERSION=$(echo "$RSS" | tr -d '\n' | sed 's/<item>/\n<item>/g' | \
grep -v 'Switch 2' | \ grep 'sys=hac' | grep -oE '[0-9]+\.[0-9]+\.[0-9]+' | sort -V | tail -n 1)
head -n 1)
if [ -z "$DESCRIPTION" ]; then if [ -z "$LATEST_VERSION" ]; then
echo "INFO: Aucun firmware Switch valide trouvé."
echo "new_version=false" >> $GITHUB_OUTPUT echo "new_version=false" >> $GITHUB_OUTPUT
exit 0 exit 0
fi fi
echo "Description détectée : $DESCRIPTION" MAJOR=$(echo "$LATEST_VERSION" | cut -d. -f1)
VERSION=$(echo "$DESCRIPTION" | grep -oE '[0-9]+\.[0-9]+\.[0-9]+')
if [ -z "$VERSION" ]; then
echo "INFO: Impossible d'extraire la version."
echo "new_version=false" >> $GITHUB_OUTPUT
exit 0
fi
MAJOR=$(echo "$VERSION" | cut -d. -f1)
# Autorise uniquement 21+
if [ "$MAJOR" -lt 21 ]; then if [ "$MAJOR" -lt 21 ]; then
echo "INFO: Firmware $VERSION ignoré (<21.x)."
echo "new_version=false" >> $GITHUB_OUTPUT echo "new_version=false" >> $GITHUB_OUTPUT
exit 0 exit 0
fi fi
echo "Version valide détectée : $VERSION" # Check si la Release existe
HTTP_STATUS=$(curl -s -o /dev/null -w "%{http_code}" \ HTTP_STATUS=$(curl -s -o /dev/null -w "%{http_code}" \
-H "Authorization: token ${{ secrets.GITHUB_TOKEN }}" \ -H "Authorization: token ${{ secrets.GITHUB_TOKEN }}" \
"https://api.github.com/repos/${{ github.repository }}/releases/tags/$VERSION") "https://api.github.com/repos/${{ github.repository }}/releases/tags/$LATEST_VERSION")
if [ "$HTTP_STATUS" = "200" ]; then if [ "$HTTP_STATUS" = "200" ]; then
echo "INFO: La release $VERSION existe déjà."
echo "new_version=false" >> $GITHUB_OUTPUT echo "new_version=false" >> $GITHUB_OUTPUT
else else
echo "INFO: Nouvelle version $VERSION détectée !"
echo "new_version=true" >> $GITHUB_OUTPUT echo "new_version=true" >> $GITHUB_OUTPUT
echo "firmware_version=$VERSION" >> $GITHUB_OUTPUT echo "firmware_version=$LATEST_VERSION" >> $GITHUB_OUTPUT
fi fi
set -e set -e
- name: 💻 Execute download script and capture changelog - name: 💻 Execute download script & Extract Release Notes
id: download id: download
if: steps.version_check.outputs.new_version == 'true' if: steps.version_check.outputs.new_version == 'true'
run: | run: |
python3 firmware_downloader.py | tee firmware_output.txt VERSION="${{ steps.version_check.outputs.firmware_version }}"
FIRMWARE_VERSION=$(grep 'Folder: Firmware ' firmware_output.txt | awk '{print $NF}')
echo "firmware_version=$FIRMWARE_VERSION" >> $GITHUB_OUTPUT # Exécution SANS paramètre pour que le script interroge lui-même l'API Nintendo
tail -n 4 firmware_output.txt > changelog_body.txt python3 firmware_downloader.py | tee script_output.log
echo "firmware_version=$VERSION" >> $GITHUB_OUTPUT
- name: 🧹 Clean and zip firmware
if: steps.version_check.outputs.new_version == 'true' # Extraction stricte des dernières lignes générées par le script Python
run: | sed -n '/Archive created:/,$p' script_output.log > changelog_body.txt
VERSION="${{ steps.download.outputs.firmware_version }}"
# Stockage sécurisé et multi-lignes du texte pour GitHub Actions
find . -type f -name "*.nca.*" -delete EOF=$(dd if=/dev/urandom bs=15 count=1 status=none | base64)
echo "CHANGELOG_CONTENT<<$EOF" >> $GITHUB_ENV
if [ -d "Firmware $VERSION" ]; then cat changelog_body.txt >> $GITHUB_ENV
rm -f "Firmware $VERSION.zip" echo "$EOF" >> $GITHUB_ENV
zip -rj "Firmware $VERSION.zip" "Firmware $VERSION/" -i "*.nca"
fi
- name: 📝 Prepare Release Body
id: prepare_body
if: steps.version_check.outputs.new_version == 'true'
uses: actions/github-script@v7
with:
script: |
const fs = require('fs');
if (fs.existsSync('changelog_body.txt')) {
const changelogBody = fs.readFileSync('changelog_body.txt', 'utf8');
core.setOutput('release_body', changelogBody);
} else {
core.setOutput('release_body', 'No changelog available.');
}
- name: 📦 Create Tag and Release - name: 📦 Create Tag and Release
if: steps.version_check.outputs.new_version == 'true' if: steps.version_check.outputs.new_version == 'true'
@@ -135,13 +100,10 @@ jobs:
tag_name: ${{ steps.download.outputs.firmware_version }} tag_name: ${{ steps.download.outputs.firmware_version }}
name: Firmware ${{ steps.download.outputs.firmware_version }} name: Firmware ${{ steps.download.outputs.firmware_version }}
body: | body: |
Automatic download of the official Nintendo Switch firmware version **${{ steps.download.outputs.firmware_version }}**. Automatic download of the official Nintendo Switch firmware version ${{ steps.download.outputs.firmware_version }}.
--- Downloaded file details:
${{ env.CHANGELOG_CONTENT }}
**Downloaded file details:**
${{ steps.prepare_body.outputs.release_body }}
files: | files: |
Firmware ${{ steps.download.outputs.firmware_version }}.zip Firmware ${{ steps.download.outputs.firmware_version }}.zip
env: env:

查看文件

@@ -13,7 +13,7 @@ from os import makedirs, remove
from os.path import basename, exists, join from os.path import basename, exists, join
from configparser import ConfigParser from configparser import ConfigParser
from sys import argv from sys import argv
from zipfile import ZipFile, ZIP_DEFLATED from zipfile import ZipFile, ZIP_STORED, ZipInfo
from requests import request from requests import request
from requests.exceptions import HTTPError from requests.exceptions import HTTPError
@@ -121,15 +121,15 @@ def nin_request(method, url, headers=None):
def parse_cnmt(nca): def parse_cnmt(nca):
ncaf = basename(nca) ncaf = basename(nca)
# --- MODIFICATION CLÉ --- # --- KEY MODIFICATION ---
# Force l'utilisation de l'exécutable hactool dans le répertoire courant. # Force the use of the hactool executable in the current directory.
# Dans le workflow, hactool-linux a été renommé en hactool et rendu exécutable. # In the workflow, hactool-linux was renamed to hactool and made executable.
hactool_bin = "hactool.exe" if os.name == "nt" else "./hactool" hactool_bin = "hactool.exe" if os.name == "nt" else "./hactool"
# ----------------------- # -----------------------
cnmt_temp_dir = f"cnmt_tmp_{ncaf}" cnmt_temp_dir = f"cnmt_tmp_{ncaf}"
# Le script tente de lancer './hactool' # The script attempts to run './hactool'
run( run(
[hactool_bin, "-k", "prod.keys", nca, "--section0dir", cnmt_temp_dir], [hactool_bin, "-k", "prod.keys", nca, "--section0dir", cnmt_temp_dir],
stdout=PIPE, stderr=PIPE stdout=PIPE, stderr=PIPE
@@ -181,7 +181,7 @@ def dltitle(title_id, version, is_su=False):
except HTTPError as e: except HTTPError as e:
if e.response is not None and e.response.status_code == 404: if e.response is not None and e.response.status_code == 404:
print(f"INFO: Title {title_id} version {version} not found (404).") print(f"INFO: Title {title_id} version {version} not found (404).")
if title_id == "010000000000081B": if title_id.lower() == "010000000000081b":
sv_nca_exfat = "" sv_nca_exfat = ""
return return
raise raise
@@ -201,9 +201,9 @@ def dltitle(title_id, version, is_su=False):
dltitle(t_id, ver) dltitle(t_id, ver)
else: else:
for nca_id, nca_hash in parse_cnmt(cnmt_nca): for nca_id, nca_hash in parse_cnmt(cnmt_nca):
if title_id == "0100000000000809": if title_id.lower() == "0100000000000809":
sv_nca_fat = f"{nca_id}.nca" sv_nca_fat = f"{nca_id}.nca"
elif title_id == "010000000000081B": elif title_id.lower() == "010000000000081b":
sv_nca_exfat = f"{nca_id}.nca" sv_nca_exfat = f"{nca_id}.nca"
if nca_id not in queued_ncas: if nca_id not in queued_ncas:
@@ -217,12 +217,22 @@ def dltitle(title_id, version, is_su=False):
)) ))
def zipdir(src_dir, out_zip): def zipdir(src_dir, out_zip):
with ZipFile(out_zip, "w", compression=ZIP_DEFLATED) as zf: with ZipFile(out_zip, "w", compression=ZIP_STORED) as zf:
for root, _, files in os.walk(src_dir): for root, dirs, files in os.walk(src_dir):
for name in files: dirs.sort()
for name in sorted(files):
full = os.path.join(root, name) full = os.path.join(root, name)
rel = os.path.relpath(full, start=src_dir) rel = os.path.relpath(full, start=src_dir)
zf.write(full, arcname=rel) os.utime(full, (1780315200, 1780315200))
zinfo = ZipInfo.from_file(full, arcname=rel)
zinfo.date_time = (2026, 1, 1, 0, 0, 0)
zinfo.create_system = 0
zinfo.external_attr = 0
zinfo.compress_type = ZIP_STORED
with open(full, 'rb') as f:
zf.writestr(zinfo, f.read())
if __name__ == "__main__": if __name__ == "__main__":
if not exists("certificat.pem"): if not exists("certificat.pem"):
@@ -296,8 +306,8 @@ if __name__ == "__main__":
dlfiles(update_dls) dlfiles(update_dls)
if not sv_nca_exfat: if not sv_nca_exfat:
print("INFO: exFAT not found via meta — direct attempt 010000000000081B") print("INFO: exFAT not found via meta — direct attempt 010000000000081b")
dltitle("010000000000081B", ver_raw, is_su=False) dltitle("010000000000081b", ver_raw, is_su=False)
if sv_nca_exfat: if sv_nca_exfat:
dlfiles(update_dls) dlfiles(update_dls)
else: else:
@@ -311,13 +321,48 @@ if __name__ == "__main__":
if failed: if failed:
exit(1) exit(1)
print("\nINFO: Starting detailed verification of NCA hashes...")
hash_failed = False
for url, dirc, fname, expected_hash in update_dls:
fpath = join(dirc, fname)
if exists(fpath):
h = hashlib.sha256()
with open(fpath, "rb") as f:
for chunk in iter(lambda: f.read(1048576), b""):
h.update(chunk)
actual_hash = h.hexdigest()
if actual_hash == expected_hash:
print(f"[OK] {fname}")
print(f" -> Verified Hash: {actual_hash}")
else:
print(f"[ERROR] {fname}")
print(f" Expected : {expected_hash}")
print(f" Actual : {actual_hash}")
hash_failed = True
else:
print(f"[MISSING] {fname}")
hash_failed = True
if hash_failed:
print("\nCRITICAL: Hash verification failed for one or more files. Archive will not be created.")
exit(1)
else:
print("\nINFO: All files successfully verified against CNMT records.")
out_zip = f"{ver_dir}.zip" out_zip = f"{ver_dir}.zip"
if exists(out_zip): if exists(out_zip):
remove(out_zip) remove(out_zip)
zipdir(ver_dir, out_zip) zipdir(ver_dir, out_zip)
h = hashlib.sha256()
with open(out_zip, "rb") as f:
for chunk in iter(lambda: f.read(1048576), b""):
h.update(chunk)
zip_sha256 = h.hexdigest()
print("\nDOWNLOAD COMPLETE!") print("\nDOWNLOAD COMPLETE!")
print(f"Archive created: {out_zip}") print(f"Archive created: {out_zip}")
print(f"SystemVersion NCA FAT: {sv_nca_fat or 'Not Found'}") print(f"SystemVersion NCA FAT: {sv_nca_fat or 'Not Found'}")
print(f"SystemVersion NCA exFAT: {sv_nca_exfat or 'Not Found'}") print(f"SystemVersion NCA exFAT: {sv_nca_exfat or 'Not Found'}")
print("Verify hashes before installation!") print(f"Archive SHA256: {zip_sha256}")
print("Verify hashes before installation!")