Syscon Firmware: Difference between revisions

From PS3 Developer wiki
Jump to navigation Jump to search
m (→‎Syscon patches: Hmmm, or is this way ?)
Line 86: Line 86:
= Syscon patches =
= Syscon patches =
These patches are in full Retail/CEX and Debug/DEX firmwares. Are intended to fix some problem in the syscon firmware
These patches are in full Retail/CEX and Debug/DEX firmwares. Are intended to fix some problem in the syscon firmware
*Bugfix 1) Firmware 1.30 (December 6, 2006) Disables UART access to the Syscon EEPROM patch region (not for 0832)
*Bugfix 1) System firmware 1.30 (December 6, 2006). Disables UART access to the Syscon EEPROM patch region (not for 0832)
*Bugfix 2) Firmware 1.81 (June 15, 2007) Patch for the HDMI display data channel read function (only for 0B8E and 0C16)
*Bugfix 2) System firmware 1.81 (June 15, 2007). Patch for the HDMI display data channel read function (only for 0B8E and 0C16)
*Bugfix 3) Firmware 3.00 (September 1, 2009) Unknown patch (only for 0832)
*Bugfix 3) System firmware 3.00 (September 1, 2009). Unknown patch (only for 0832)
*Bugfix 4) Firmware 3.40 (June 29, 2010) Patch for the rtc read function (not for 0832)
*Bugfix 4) System firmware 3.40 (June 29, 2010) and  3.41 (July 26, 2010). Patch for the rtc read function (not for 0832)
*Bugfix 5) Firmware 3.41 (July 26, 2010) No patch added


{| class="wikitable"
{| class="wikitable"
Line 121: Line 120:
|-
|-
! 0F38
! 0F38
| SYS_CON_FIRMWARE_01050101.pkg || {{No}} || {{No}} || {{No}} || {{No}} || {{No}} || {{Yes}} (bugfix 5) ||  
| SYS_CON_FIRMWARE_01050101.pkg || {{No}} || {{No}} || {{No}} || {{No}} || {{No}} || {{Yes}} (bugfix 4) ||  
|-
|-
! 0832
! 0832

Revision as of 08:58, 10 June 2021

Description

The system controller firmware (also known as the syscon firmware) is the software stored inside syscon. Is composed by the base firmware (not updateable in retail syscon models) and a optional patch that is applyed virtually on runtime on top of the base firmware
The syscon update packages (also known as syscon patches) for retail PS3 models are distributed in PKG format inside the Update_files.tar of the PS3UPDAT.PUPs. Syscon patches appear to always be 5KB (5376 bytes) in size.

Update procedure

The PS3 firmware installer PUP's contains a collection of syscon patches for all the different syscon's chips used in the different motherboard models. The ps3swu.self (system updater) checks the syscon SoftID and installs the compatible patch accordingly (via updater manager ss service).
The non-retail PS3 models with syscon CXR713F120A don't have patches, this special syscon model with the "F" product code (that seems to indicate that is fully flasheable) allows to overwrite the base syscon firmware through the Communication Processor

Syscon firmwares

Mullion
SoftID Firmware version Build target Build date Adds support for Platform IDs Corresponding SDK version Notes
- v0.4.5_b4 BACKUP 2005 (Cyt1.0), (Cyt1.1), (Cyt2.1), (Cok01) 0.40 Only used on the backup bank of flash models
06DA v0.6.1_c8 CYTOLOGY 2006/01/31 Cyt1.2, Cyt2.0, Cyt2.2, (Cok02), (Cok03) 0.80
073E v0.6.10_c4 CYTOLOGY 2006/03/01 (Cok05) 0.81
07FF v0.6.11_c4 CYTOLOGY 2006/03/27 Cyt3.0, Cyt3.1, Cyt3.2, (Cok08) 0.82
086C v0.6.12_c5 CYTOLOGY 2006/04/11 - 0.83
08F1 v0.6.12_c7 CYTOLOGY 2006/04/22 - 0.83
0955 v0.6.14_c4 CYTOLOGY 2006/05/01 - 0.84
0AF4 v0.8.4_c8 CYTOLOGY 2006/06/23 (Cok11) 0.85
0B48 v0.9.9_c1 CYTOLOGY 2006/07/07 Cyt3.3, Cyt3.4, (Cok12), (Cok13), (Cok14) 0.90
0B67 v0.9.13_k1 COOKIE 2006 - - COOKIE-13, COK-001(Proto), etc... with a CXR713F120A
0B74 v0.9.14_c1 CYTOLOGY 2006/08/03 - 0.91
0B8E v1.0.0_k1 COOKIE (201) 2006 - -
0B9D v1.0.1_c1 CYTOLOGY 2006/08/31 - 0.93
0C16 v1.1.3_k1 COOKIE (202) 2006 CokB10 - not dumped yet
0C23 v1.0.3_c1 CYTOLOGY 2006/12/04 - 1.50
0D52 v1.2.3_k1 COOKIE (203) 2007 CokC10, CokC11, CokC12 - not dumped yet
0D79 v1.0.4_c1 CYTOLOGY 2007/06/21 - 1.90
0DBF v1.3.3_k1 COOKIE (301) 2007 CokD10 -
0E4E v1.0.4_c2 CYTOLOGY 2007/11/08 - 2.40
0E69 v1.4.4_k2 COOKIE (302) 2007 CokE10, Deb01 -
0F29 v1.5.0_k2 COOKIE (303) 2009 - - Removes hardcoding from previous firmware, adds support for 65nm RSX - not dumped yet
0F38 v1.5.1_k2 COOKIE (304) 2010 - - Adds support for 40nm RSX
0F3B v1.0.5_c1 CYTOLOGY 2010/05/12 - 3.60
Sherwood
SoftID Firmware version Build target Build date Adds support for Platform IDs Notes
0658 ?.??.? - 2008 CokF10 VERTIGO-02 not dumped yet
065D 0.17.0 SW-301 2008 -
???? ?.??.? SW-302 2008 - not dumped yet
0832 1.11.0 SW2-301 2009 CokG10, CokG11
08A0 1.16.0 SW2-302 2009 CokH10, CokH11 not dumped yet
08C2 1.21.0 SW2-303 2010 CokJ13, CokJ20 not dumped yet
0918 2.3.0 SW3-301 2011 CokK10 not dumped yet
098F 2.12.0 SW3-302 2012 CokM20, CokM40, CokN10, CokN30 not dumped yet
???? ?.??.? SW3-303 2013 - not dumped yet
09A4 2.21.0 SW3-304 2013 - partially dumped

Syscon patches

These patches are in full Retail/CEX and Debug/DEX firmwares. Are intended to fix some problem in the syscon firmware

  • Bugfix 1) System firmware 1.30 (December 6, 2006). Disables UART access to the Syscon EEPROM patch region (not for 0832)
  • Bugfix 2) System firmware 1.81 (June 15, 2007). Patch for the HDMI display data channel read function (only for 0B8E and 0C16)
  • Bugfix 3) System firmware 3.00 (September 1, 2009). Unknown patch (only for 0832)
  • Bugfix 4) System firmware 3.40 (June 29, 2010) and 3.41 (July 26, 2010). Patch for the rtc read function (not for 0832)
SoftID sys_con_firmware package 1.00~1.11 1.30~1.80 1.81~2.80 3.00~3.30 3.40 3.41~4.88 Notes
0B8E SYS_CON_FIRMWARE_01000004.pkg No Yes (bugfix 1) No No No No Superseded by SYS_CON_FIRMWARE_01000005.pkg
SYS_CON_FIRMWARE_01000005.pkg No No Yes (bugfix 1+2) No No Superseded by SYS_CON_FIRMWARE_01000006.pkg
SYS_CON_FIRMWARE_01000006.pkg No No No No Yes (bugfix 1+2+4)
0C16 SYS_CON_FIRMWARE_01010302.pkg No No Yes (bugfix 1+2) No No Superseded by SYS_CON_FIRMWARE_01010303.pkg
SYS_CON_FIRMWARE_01010303.pkg No No No No Yes (bugfix 1+2+4)
0D52 SYS_CON_FIRMWARE_01020302.pkg No No No No Yes (bugfix 4)
0DBF SYS_CON_FIRMWARE_01030302.pkg No No No No Yes (bugfix 4)
0E69 SYS_CON_FIRMWARE_01040402.pkg No No No No Yes (bugfix 4)
0F29 SYS_CON_FIRMWARE_01050002.pkg No No No No Yes (bugfix 4)
0F38 SYS_CON_FIRMWARE_01050101.pkg No No No No No Yes (bugfix 4)
0832 SYS_CON_FIRMWARE_S1_00010002083E0832.pkg No No No Yes (bugfix 3)
CECHAxx Refurbished 40nm RSX / COK-001 / CXR714120-304GB
Syscon firmware v1.5.1_k2 patch 1

CECH-20xx / DYN-001 / SW2-301
Syscon firmware 1.11.0 patch 1.2.83E.832

The screen More System Information allows to see some details related with syscon. The syscon firmware version can be derived from the SoftID, and additionally if there is a patch installed the PatchID displayed in the screen contains both, the syscon firmware version and the patch version. Note also that there is a direct relationship in between the PatchID displayed in the screen and the patch filename. The syscon UART commands also displays some info related with the base syscon firmware and the patch

Some examples from syscon UART:

CECHC, CECHE / COK-002 / CXR713120-202GB
>$ revision
0C16

>$ version
v1.1.3_k1

>$ patchvereep
major:0x0001
minor:0x0001
patch:0x0003
revision:0x0003

>$ patchcsum
r1 csum: [00030266] [018DB626] [90662679]
r2 csum: [000069C5] [0046B830] [5E535A06]
CECH-20xx / DYN-001 / SW2-301
>$ revision
# Revision = 2098(0832)

>$ version
# Sherwood Version = 1.11.0

>$ patchinfo
#
# MAJOR   :0000
# MINOR   :0000
# REV     :0000
# SYS_REV :0000
# TABLE   :00FFFFFF
# DATSIZ  :FFFF
# DATSUM  :FFFF
# SUM     :FFFF
# not applyed
CECH-20xx / DYN-001 / SW2-301
>$ revision
# Revision = 2098(0832)

>$ version
# Sherwood Version = 1.11.0

>$ patchinfo
#
# MAJOR   :0001
# MINOR   :0002
# REV     :083E
# SYS_REV :0832
# TABLE   :0000201A
# DATSIZ  :0FAA
# DATSUM  :02AB
# SUM     :035D
# applyed


  • Mullion PatchID names format (major, minor, patch, revision)
    • 0B8E.0000000000000000@SC = syscon firmware v1.0.0_k1, not patched
    • 0B8E.0001000000000005@SC = syscon firmware v1.0.0_k1, patch 5 (filename SYS_CON_FIRMWARE_01000005.pkg)
    • 0F38.0000000000000000@SC = syscon firmware v1.5.1_k2, not patched
    • 0F38.0001000500010001@SC = syscon firmware v1.5.1_k2, patch 1 (filename SYS_CON_FIRMWARE_01050101.pkg)
  • Sherwood PatchID names format (major, minor, rev, sys_rev)
    • 0832.0000000000000000@SC = syscon firmware 1.11.0, not patched
    • 0832.00010002083E0832@SC = syscon firmware 1.11.0, patch 1.2.83E.832 (filename SYS_CON_FIRMWARE_S1_00010002083E0832.pkg)


Package structure

Sys_con_firmware Packages can be unpacked with unpkg. See PKG files and Certified File

Header

Address Length Value Description
0x00 0x4 ASCI:"SCE" SCE magic header
0x04 0x4 0x2 Version
0x08 0x2 0x0 Attribute
0x0A 0x2 0x3 Category (0x3 = Update Package)
0x0C 0x4 0x0 Extended Header Size (no ext header)
0x10 0x8 0x280 File Offset (hdr_len)
0x18 0x8 0x1080 File Size (dec_size)
0x20 0x260 - Encrypted part of header
0x280 0x40 - update_package_header section (see below)
0x2C0 0x40 - update_package_contents_header section (see below)
0x300 0x1000 - content section

Update Package Header

Address Length Value Description
0x00 0x4 0x3 Header Version? 3 (fixed value for all PS3 update packages)
0x04 0x4 0x8 SoftType? 8 = SC firmware
0x08 0x8 - SC firmware revision (the high word of it is the SC type)
0x0C 0x4 0x0B8E(1.30-4.84)
0x0C16(1.81-4.84)
0x0D52(3.40-4.84)
0x0DBF(3.40-4.84)
0x0E69(3.40-4.84)
0x0F29(3.40-4.84)
0x0F38(3.41-4.84)
0x065D
0x0832(3.00-4.84)
0x08A0
0x08C2
0x0918
'SoftID'
0x10 0x8 0x0001000000000004
0x0001000000000005
0x0001000000000006
0x0001000100030002
0x0001000100030003
0x0001000200030002
0x0001000300030002
0x0001000400040002
0x0001000500000002
0x0001000500010001
0x00010002083E0832
'PatchID' (official name is "version")
0x18 0x8 0x1000 Content Data Size
0x20 0x8 0x1000 Content Compressed Data Size
0x28 0x4 0x0 Attribute
0x2C 0x4 0x0 Region
0x30 0x8 0x0 Image Offset
0x38 0x8 0x0 Reserved_0

Note: PS3 firmwares cannot deal with compressed syscon firmwares, so they will abort the update process in that case.

Note2: The PatchID is also present in the first 8 bytes of decrypted content but 16bit swapped for ARM BGAs

Update Package Contents Header

Address Length Value Description
0x00 0x8 0x3 Header Version?
0x08 0x8 0x40 Header Size?
0x10 0x8 0x0 Chunk Offset
0x18 0x8 0x1000 Chunk Size
0x20 0x8 0x1 Current Chunk
0x28 0x8 0x1 Chunks Total
0x30 0x8 0x0 Reserved_0?
0x38 0x8 0x0 Reserved_1?

Content

Address Length Value Description
0x0 0x1000 - Content Data

Content Data Header

The header format is partially unknown at this stage. All the Firmwares patches are written in little endian.

Offset Length Notes Related DECR Error Notes
0x0 0x4 Magic FFFFFED2 (Magic Error) 0x1B2D700F in mullions, sys1 in cytology ?
0x4 0x10 Header CMAC1 FFFFFED1 (Header Check Error) CMAC of Partial Header (0x10,0x30 size) with header first 4 bytes instead of random 4 bytes
and where Header CMAC2 is zeroed Concatenated with Encrypted Body
0x14 0x10 Header CMAC2 CMAC of Header (where this cmac has been zeroed)
0x24 0x4 Padding
0x28 0x4 Total size Always 0x1000 in mullions, 0x60040 in cytology ?
0x2C 0x4 Size of binary Always 0xFC0 in mullions, 0x60000 in cytology ?
0x30 0x10 IV for AES-128 CBC
0x40 0xFC0 Encrypted binary FFFFFED0 (Data Check Error)
FFFFFECF (Data Size Check Error)
  • Note: For the weird bogus update ONLY: FFFFFF37 (Alignment Error?) (Trying any data size between 0x41 and 0x4C bytes)
  • Note2: v0.6.14c4 is the bogus update (only update with a weird header)
  • Note3: setting data between 0x40 to 0x4C to zero in bogus update yields error FFFFFED0

Samples

00000000  1B 2D 70 0F AB 5E B3 99 68 20 FE 3D E1 80 6A 1D  .-p.«^³™h þ=á€j.
00000010  B8 FD 37 CF CD 45 85 AB 51 F7 05 E3 EA 32 A5 EA  ¸ý7ÏÍE…«Q÷.ãê2¥ê
00000020  67 45 F9 48 00 00 00 00 00 10 00 00 C0 0F 00 00  gEùH........À...
00000030  8B 04 07 F9 9B A2 90 3A 75 89 F1 42 12 59 DA 0D  ‹..ù›¢.:u‰ñB.YÚ.
00000040  21 7C A2 C3 5A E4 78 00 10 8D 4B F7 A2 73 9C 63  !|¢ÃZäx...K÷¢sœc
00000050  5D 8D 5D 49 16 C7 6F 2C AD 33 FE 1F D3 6C A1 CA  ].]I.Ço,.3þ.Ól¡Ê
00000060  BA AD 2B FE 8F 33 71 D7 C5 E6 5C FF BF 77 6C 80  º.+þ.3q×Åæ\ÿ¿wl€
00000070  F2 BE 11 BB 3C 52 52 DC A9 68 E5 24 AD 4F F3 48  ò¾.»<RRÜ©hå$.OóH

-From v1.0.4c2_TMU510_u-

00000000   73 79 73 31 73 47 59 5D  FB 85 3B 7B 4A 28 10 5D   sys1sGY]û…;{J( ]
00000010   46 EE 8C 01 3C B4 F1 82  1E 18 4F B7 4A 56 FC C7   FîŒ <´ñ‚  O·JVüÇ
00000020   FF 83 0B E0 00 00 00 00  40 00 06 00 00 00 06 00   ÿƒ à    @       
00000030   69 B6 02 69 3A 97 8B 1C  4E 18 D4 E0 63 7D CA 94   i¶ i:—‹ N Ôàc}Ê”
00000040   4B A0 79 34 79 41 BD 09  BB 68 D4 0A A0 B7 05 78   K y4yA½ »hÔ  · x
00000050   D9 8F 8F 28 6C 9A 1B 61  CF A1 E7 49 7D CA C4 A3   Ù  (lš aÏ¡çI}ÊÄ£
00000060   A4 4D 4B E0 AE 48 86 03  B1 43 F2 47 C0 C4 1D 4F   ¤MKà®H† ±CòGÀÄ O
00000070   FA E8 43 A7 1E 6E 79 8C  E5 FF 04 20 E9 44 09 B5   úèC§ nyŒåÿ  éD µ

Content Data Patch (encrypted)

Packages can be extracted with the unpkg tool. Extracted content of the updates appears to always be 0x1000 bytes (4KB).

The following is all theoretical and is intended to discard possibilities about modes of operation used by aes when decrypting body of firmware/patch
We know that:

  • Two key expansions are used before applying crypto on body (one probably for hashing. the other for decrypting with cbc)
  • Encrypt is used when applying crypto on body TopHalf (forward ttables) and Decrypt is used when applying on body Bottomhalf (inverse ttables)
  • Authenticated regions uses a form of what seems to be some ECB with tweak xoring (as graf once said about XTS)
  • XTS was introduced in 2007 and SysCon from ps3 exists for far more time than that (2003)
  • XEX is a close relative of XTS that was introduced in 1984
  • PS4 uses XTS for Authenticated Regions or SNVS (with sector size of 0x20 being used. is this even considered safe?)
  • 4 regions can be controlled for DPA and they are: 0x2790 (size 0x20) (FFs), patch header (most notably at offset 0x4 of header size 0x10 and 0x30 size 0x10), patch body tophalf(+0x40) and patch body bottomhalf(+0x50)
  • here are the DPA bytes for each of the controlable sections:
  • 21 06 23 DC A2 98 99 4D XX 87 F8 40 FC 48 1C BF (section 2/FF's from 0x2790 on DIA-001) -> 210623DCA298994DFE87F840FC481CBF
  • 21 06 23 DC A2 98 99 4D XX 87 F8 40 FC 48 1C BF (section 2/FF's from 0x2790 on DEB-001) -> 210623DCA298994DFE87F840FC481CBF
  • 16 32 47 79 C3 2C 47 D3 2B 39 CA B5 83 41 0E D5 (section 3/header from DIA-001 patch content)
  • XX XX XX XX 7B FC 27 CD D5 9A 05 09 3A DF E4 75 (section 3/header AA from DEB-001 patch content) -> 6E9CE7C57BFC27CDD59A05093ADFE475
  • 92 4A 87 88 20 59 6C 49 9F 0E 7D 77 2F 38 4C FC (section 3/header DD from DEB-001 patch content)
  • 7D C6 3B 3B 69 DF 67 4C 94 D7 D4 A8 E0 F8 5B B2 (section 4/body from DIA-001 patch content/tophalf/forward)
  • 73 XX F0 3D XX 9A F0 92 4D XX 62 DA XX 48 3C DB (section 4/body from DIA-001 patch content/bottomhalf/inverse)
  • 49 1F 7B 0A 48 BD 79 33 4E 16 89 F6 B0 25 86 48 (section 4/body from DEB-001 patch content/tophalf/forward)
  • 14 4D F1 D3 21 B6 17 46 60 81 42 E5 02 C9 07 66 (section 4/body from DEB-001 patch content/bottomhalf/inverse/PROPER) -> 6B3583DA1AA6B49106E1641178EE68C8 (inverse ttables)
  • some bytes are considered "weak" bytes and should be bruteforced in the eventuality these keys fail
  • another possibility is that both the header and the body are hashed and then decrypted, using for example, cmac and cbc
  • since key expansions take 10 "hills" in the analysis, it should be safe to assume that AES-128 is used(because it uses 10 rounds).
  • 6554cff202c3bfdd9740901070b705bf : correct md5 for patch content we are trying keys on (DIA-001)
  • 4875ad06a1499cc516a0d4d92e595794 : correct md5 for patch content we are trying keys on (DEB-001/DIA-002)
  • trying a different header/body patch content from another similar board will result into failure of decrypting body, which means that the header is checked for authenticity and that the header hash is NOT in the header
  • altering the patch header doesn't cause the patch header dpa bytes to change (a test was done with 4 bytes and the result was 16 32 47 79, which matches the other patch dpa recovered bytes)
  • there are in fact not 4 but 5 aes sections. the last one seems to be body related, as changing the body even one bit makes the last aes section disappear.
  • section 2 is divided into two sections, corresponding to TopHalf and BottomHalf of patch area.
  • TopHalf uses forward ttables/sbox. BottomHalf uses inverse ttables/sbox
  • TopHalf is ONLY the very first 0x10 bytes AFTER the header and into the body (corresponding to 0x40 in header size 0x10)
  • BottomHalf is the rest of the body itself.
  • DYN-001 processes one entire chunk of 0x1000 bytes, 0x40 for header and 0xFC0 for body, and not two of 0x400 and 0xC00 like the Sony models
  • 504 aes operations are done for the body (252/0xFC for cmac and 252/0xFC for cbc). it is unknown if cmac comes first or it is cbc.
  • All attacks show weak bytes in comparisson with CXR(F), likely due to CXR being optimized for the attack (removed resistors/capacitors, etc)

Patch structure (decrypted)

Mullion Patch structure

Offset Size Notes Number
0x00 0x2 Major Version 1
0x02 0x2 Minor Version 1
0x04 0x2 Major Revision 1
0x06 0x2 Minor Revision 1
0x08 0x10 Patch Addresses 4*4
0x18 0x10 Patch Instruction / Data 4*4
0x28 0x10 Patch Jump Instruction Addresses 4*4
0x38 0x388 Additional Patch Instructions 1
0x3C0 0xC00 HDMI Patch 1

Sherwood Patch structure

Offset Size Notes Number
0x00 0x4 Magic 1
0x04 0x2 Major Version 1
0x06 0x2 Minor Version 1
0x08 0x2 Major Revision 1
0x0A 0x2 Minor Revision 1
0x0C 0x4 Absolute Table Address 1
0x10 0x2 Data Size 1
0x12 0x2 Data Checksum 1
0x14 0x2 Patch Checksum 1
0x16 0x2 Relative (0x2000) Data Address 1
0x18 0x2 Relative (0x2000) Table Address 1
------ 0x80 Table with Addresses 32*4
------ ------ Data (not parsed on SW) -

Command list

Mullion

External commands

Address Command Subcommand Permission
0x32959 BOOT MODE 0x000080D6
0x329D5 BOOT CONT 0x000080D5
0x342D7 SHUTDOWN - 0x0000C0D5
0x32A51 HALT - 0x0000C0D5
0x32A85 BOOTENABLE - 0x0000809A
0x33491 AUTH1 - 0x0000C0EF
0x33525 AUTH2 - 0x0000C0EF
0x33619 AUTHVER SET 0x0000C0DF
0x335BF AUTHVER GET 0x0000C0FF
0x32AC3 EEP INIT 0x000080DA
0x32C51 EEP SET 0x0000C0DF
0x32D3D EEP GET 0x0000C0DF
0x32EA7 PDAREA SET 0x0000C0DF
0x32E3B PDAREA GET 0x0000C0DF
0x330C5 CSAREA SET 0x0000C0DF
0x33057 CSAREA GET 0x0000C0DF
0x33169 VID GET 0x0000C0D5
0x331D7 CID GET 0x0000C0D5
0x3321D ECID GET 0x0000C0D5
0x3325D REV SB 0x0000C0D5
0x3328D SPU INFO 0x0000C0D5
0x332E1 KSV - 0x0000C0D5
0x33685 FAN SETPOLICY 0x0000C0D7
0x33717 FAN GETPOLICY 0x0000C0D7
0x33781 FAN START 0x0000C0D7
0x33781 FAN STOP 0x0000C0D7
0x33951 FAN SETDUTY 0x0000C0D7
0x339C3 FAN GETDUTY 0x0000C0D7
0x33A27 R8 - 0x0000C0DF
0x33AD1 W8 - 0x0000C0DF
0x33B71 R16 - 0x0000C0DF
0x33C19 W16 - 0x0000C0DF
0x33CBB R32 - 0x0000C0DF
0x33E49 W32 - 0x0000C0DF
0x33EE9 RBE - 0x0000C0D5
0x33F91 WBE - 0x0000C0D5
0x34049 PORTSTAT - 0x0000C0DF
0x332BF VER - 0x0000C0FF
0x341C5 BUZ - 0x00008096
0x342D7 SERVFAN - 0x0000C0D7
0x341F9 ERRLOG START 0x0000C0DF
0x34221 ERRLOG STOP 0x0000C0DF
0x34249 ERRLOG GET 0x0000C0FF
0x342B3 ERRLOG CLEAR 0x0000C0DF

Internal commands

Command Address Perms SubCommands Description
becount 0xCA7D 0xDD0C0000 - Display bringup/shutdown count + Power-on time
bepgoff 0xA4E7 0xD00C0000 - BE power grid off
bepkt 0x2435D 0xDC0C0000 show/set/unset/mode/debug/help Packet permissions
bestat 0xD413 0xFD0F0000 - Get status of BE
boardconfig 0x99C7 0xDC0C0000 - Displays board configuration (NOT WORKING?)
bootbeep 0x1EA67 0xF0000000 stat/on/off Boot beep
bringup 0xD597 0xFD0F0000 - Turn PS3 on
bsn 0xD805 0xF00F0000 - Get board serial number
bstatus 0x24269 0xDD0C0000 - HDMI related status
buzz 0xA4FF 0xDC0C0000 [freq] Activate buzzer
buzzpattern 0xA8B7 0xDC0C0000 [freq] [pattern] [count] Buzzer pattern
clear_err 0x2595B 0xDD0C0000 last/eeprom/all Clear errors
clearerrlog 0xB8CB 0xDD0C0000 - Clears error log
comm 0x9919 0xDC0C0000 - Communication mode
commt 0x24907 0xDC0C0000 help/start/stop/send Manual BE communication
cp 0x1E077 0xF0000000 ready/busy/reset/beepremote/beep2kn1n3/beep2kn2n3 CP control commands
csum 0xD687 0xFF0F0000 - Firmware checksum
devpm 0xD053 0xDD0C0000 ata/pci/pciex/rsx Device power management
diag 0x9AAD 0xD00C0000 ... Diag (execute without param to show help) (NOT WORKING?)
disp_err 0x25911 0xDD0C0000 - Displays errors
duty 0x9B23 0xDD0C0000 get/getmin/getmax/getinimin/getinimax
set/setmin/setmax/setinimin/setinimax
Fan speed
dve 0x2995D 0xDC0C0000 help/set/save/show DVE chip parameters
eepcsum 0xAA65 0xDD0C0000 - Displays checksums of some eeprom areas
eepromcheck 0x9A1D 0x000C0000 [id] Check eeprom
eeprominit 0x9A65 0x000C0000 [id] Init eeprom
ejectsw 0xD611 0xFD0F0000 - Eject switch
errlog 0xB7ED 0xFF0C0000 - Gets the error log
fancon 0xD26D 0x0D000000 - Does nothing
fanconautotype 0xC075 0xDD0C0000 - Does nothing
fanconmode 0xBF35 0xDD0C0000 get Fan control mode
fanconpolicy 0xBBC9 0xDD0C0000 get/set/getini/setini Fan control policy
fandiag 0x1E91B 0xF0000000 - Fan Diagnostic (test)
faninictrl 0xD3D9 0x0D000000 - Does nothing
fanpol 0xCA31 0xDD0C0000 - Does nothing
fanservo 0xBF29 0xDD0C0000 - Does nothing
fantbl 0xC087 0xDD0C0000 get/set/getini/setini/gettable/settable Fan table: get/set - currently in RAM/in use ; getini/setini - stored in EEPROM (!! in COK the chksum does not updated automatically !!)
 fantbl - Fan Table set/get command
 Usage: fantbl set fanconNo pNo tempD tempU duty
    ex. fantbl set 0 p1 0x1400 0x1E40 0xC0
    ex. fantbl set 0 p1 20.0 30.25 75
 Usage: fantbl get fanconNo
    ex. fantbl get 1
firmud 0xD61D 0xFDFF0000 - Firmware update
geterrlog 0xB84F 0xDD0C0000 [id] Gets error log
getrtc 0xA6F3 0xDD0C0000 - Gets rtc
halt 0x1E107 0xF0000000 - Halts syscon
hdmi 0x29F39 0xDD0C0000 ... HDMI (various commands, use help)
[HDMI Help] HDMI System Start         :$ hdmi setup ([ChannelNo])
[HDMI Help] Show IC Type              :$ hdmi ictype [ChannelNo]
[HDMI Help] Display EDID              :$ hdmi redid  [ChannelNo] (p)
[HDMI Help] Display KSV               :$ hdmi rksv   [ChannelNo]
[HDMI Help] SiI Register Read         :$ hdmi r  [ChannelNo] [TargetDevID(0/1)] [OffsetAddr(hex)] [ReadSize(hex)]
[HDMI Help] SiI Register Write        :$ hdmi w  [ChannelNo] [TargetDevID(0/1)] [OffsetAddr(hex)] [WriteData(hex)]
[HDMI Help] Set 12bit Param           :$ hdmi 12bit  [ChannelNo] (d1:0 - d5:4)
[HDMI Help] Set 10bit Param           :$ hdmi 10bit  [ChannelNo] (d1:0 - d5:4)
[HDMI Help] DDC Bus Read              :$ hdmi dr [ChannelNo] [TargetDevID(0/1)] [OffsetAddr(hex)] [ReadSize(hex)]
[HDMI Help] DDC Bus Write             :$ hdmi dw [OffsetAddr(hex)] [WriteData(hex)]
[HDMI Help] Show Channel Status       :$ hdmi chstat  [ChannelNo]
[HDMI Help] Debug Log Verbose         :$ hdmi vbs ([Verbose Setting(hex)])
[HDMI Help] HDMI System Shutdown      :$ hdmi letup ([ChannelNo])
[HDMI Help] HDMI Eleguler Test        :$ hdmi hwreset ([ChannelNo])
[HDMI Help] HDMI Eleguler Test KPL    :$ hdmi hwreset2 ([ChannelNo])
[HDMI Help] HDMI Manage Struct Dump   :$ hdmi dumpst ([ChannelNo])
[HDMI Help] Show HDMI and DVE Port Num:$ hdmi ports
[HDMI Help] Show Timer Value          :$ hdmi timer
[HDMI Help] Show I2C Resource         :$ hdmi i2c
[HDMI Help] Show Patch Information    :$ hdmi patch
[HDMI Help] Resolution Reset          :$ hdmi resrst [ChannelNo]
[HDMI Help] Show this Message         :$ hdmi help
hdmiid 0x29D1D 0xDC0F0000 - Get HDMI id's
hdmiid2 0x29D81 0xDC0F0000 - Get HDMI id's
hversion 0x2422F 0xDD0C0000 - Displays Platform ID
hyst 0xAEF5 0xDD0C0000 get/set/getini/setini This value is stored inside the Thermal Config area, every thermal sensor have his own
lasterrlog 0xB7FF 0xDD0C0000 - Last error from log
ledmode 0xA80B 0xDC0C0000 [id] [id] Get led mode
LS 0x2421B 0xDD0C0000 - LabStation Mode
ltstest 0xCB97 0xDD0C0000 get/set be/rsx ?Temp related? values
osbo 0x1EA3F 0xF0000000 - Sets 0x2000F60
patchcsum 0xD9F7 0xDD0C0000 - Patch checksum
patchvereep 0xD9B1 0xDD0C0000 - Patch version eeprom
patchverram 0xD965 0xDD0C0000 - Patch version ram
poll 0x240E3 0xDD0C0000 - Poll log
portscan 0xDA0D 0xDD0C0000 [port] Scan port (NOT WORKING?)
powbtnmode 0xB911 0xDC0C0000 [mode (0/1)] Power button mode
powerstate 0xCE6F 0xDD0C0000 - Get power state
powersw 0xD5F9 0xFD0F0000 - Power switch
powupcause 0xB621 0xDD0C0000 - Power up cause
printmode 0x99D9 0xDC0C0000 [mode (0/1/2/3)] Set printmode
printpatch 0xD94F 0xDD0C0000 - Prints patch
r 0x8CA5 0xDD0C0000 [offset] [length] Read byte from SC
r16 0x8ED5 0xDD0C0000 [offset] [length] Read word from SC
r32 0x9191 0xDD0C0000 [offset] [length] Read dword from SC
r64 0x935D 0xDD0C0000 [offset] [length] Read qword from SC
r64d 0x948F 0xDD0C0000 [offset] [length] Read ?qword data? from SC
rbe 0x96F9 0xDD0C0000 [offset] Read from BE
recv 0x24135 0xDD0C0000 - Receive something
resetsw 0xD605 0xFC0F0000 - Reset switch
restartlogerrtoeep 0xB903 0xDD0C0000 - Reenable error logging to eeprom
revision 0xD7E1 0xFFFF0000 - Get SoftID
rrsxc 0xD313 0xDD0C0000 [offset] [length] Read from RSX
rtcreset 0xA7BB 0x000C0000 - Reset RTC
scagv2 0xE24F 0xFF000000 - Auth related?
scasv2 0xE207 0xDD000000 - Auth related?
scclose 0xE1EF 0xFF000000 - Auth related?
scopen 0xE121 0xFF000000 - Auth related?
send 0x2416F 0xDD0C0000 [variable] Send something
shutdown 0xD5C5 0xFD0F0000 - PS3 shutdown
startlogerrtsk 0xB8E7 0xDD0C0000 - Start error log task
stoplogerrtoeep 0xB8F5 0xDD0C0000 - Stop error logging to eeprom
stoplogerrtsk 0xB8D9 0xDD0C0000 - Stop error log task
syspowdown 0xB6E9 0xDD0C0000 3 params System power down
task 0x15005 0xDD0C0000 - Print tasks
thalttest 0xD813 0x000F0000 - Does nothing
thermfatalmode 0xCA3B 0xDD0C0000 canboot/cannotboot Set thermal boot mode
therrclr 0xD3E5 0xDD0C0000 - Thermal register clear
thrm 0xBF1D 0xDD0C0000 - Does nothing
tmp 0xAA69 0xDD0C0000 [zone] Get temperature
trace 0xB951 0xDD0C0000 ... Trace tasks (use help)
Usage: trace command param
    command:
      [status/start/stop/dump/print/id]
    param (with `id' command):
      available characters: [0-9][,][-]
      ex. trace id 1-12,16
trp 0xAB2F 0xDD0C0000 get/set/getini/setini This value is stored inside the Thermal Config area, every thermal sensor have his own
tsensor 0xA279 0xDD0C0000 [sensor] Get raw temperature
tshutdown 0xB2A1 0xDD0C0000 get/set/getini/setini Thermal shutdown. This value is stored inside the Thermal Config area, every thermal sensor have his own
tshutdowntime 0xC95D 0xDD0C0000 [time] Thermal shutdown time. This value is stored inside the Thermal Config area, is a single value shared by all thermal sensors
tzone 0xB5E1 0xDD0C0000 - Show thermal zones
version 0xD65F 0xFFFF0000 - Syscon firmware version
w 0x8BF9 0xDD0C0000 [offset] [value] Write byte to SC
w16 0x8E2D 0xDD0C0000 [offset] [value] Write word to SC
w32 0x8FED 0xDD0C0000 [offset] [value] Write dword to SC
w64 0x92A9 0xDD0C0000 [offset] [value] Write qword to SC
wbe 0x9665 0xDD0C0000 [offset] [value] Write to BE
wmmto 0xCB3B 0xDC0C0000 get Get watch dog timeout
wrsxc 0xD279 0xDD0C0000 [offset] [value] Write to RSX
xdrdiag 0x1E711 0xF0000000 start/info/result XDR diagnostics
xiodiag 0x1E875 0xF0000000 - XIO diagnostic
xrcv 0x25313 0xDC0C0000 - Xmodem receive

Sherwood

Very similar to PS4 southbridge firmware. Only difference here is the string Playstation 3

  • A_AUTH = 0x0700
  • B_AUTH = 0x0B00
  • INT = 0x0300 (Command not available from UART interface. Can be unlocked by patching syscon firmware)
  • ANY = 0x0F00
Sherwood Commands
Command
lowercase/UPPERCASE
Perms Address Notes
SW-301 SW2-301 SW3-304
hdmi A_AUTH 0x32030 0x3D989 0x3E21D
tsensor A_AUTH 0x2FB30 0x3B1CF 0x3B8F0
tmp A_AUTH 0x2FE7F 0x3B3D5 0x3BAF6
trp A_AUTH 0x2FFA6 0x3B627 0x3BD48
tshutdown A_AUTH 0x301D8 0x3B645 0x3BD66
tzone A_AUTH 0x3041B 0x3B663 0x3BD84
thrm A_AUTH 0x30482 0x3B6C9 0x3BDEA
duty A_AUTH 0x307EF 0x3B95D 0x3C07E
fanconpolicy A_AUTH 0x30C0D 0x3BBB9 0x3C2DA
fanconmode A_AUTH 0x30DF9 0x3BD48 0x3C469
fantbl A_AUTH 0x30F3B 0x3BE58 0x3C579
fanservo A_AUTH N/A ? 0x3C07D 0x3C79E
fanservostat A_AUTH N/A ? 0x3C2E2 0x3CA03
fanservosetval A_AUTH N/A ? N/A ? 0x3CB6B
hyst A_AUTH 0x305F2 0x3B7F0 0x3BF11
powupcause A_AUTH 0x313EB 0x3C695 0x3CE8E
syspowdown A_AUTH 0x31460 0x3C70A 0x3CF03
devpm A_AUTH 0x316C6 0x3C98A 0x3D183
powerstate A_AUTH 0x318CF 0x3CB93 0x3D38C
nonfatalerror A_AUTH 0x31AC2 0x3CDF0 0x3D5E9
getrtc INT 0x2F82A 0x3AD68 0x3B489
help A_AUTH 0x2ED2B 0x3A280 0x3A9A1
meminfo INT 0x2EED7 0x3A42C 0x3AB4D
rbe INT 0x2EF63 0x3A4B8 0x3ABD9
DISABLEALLERASE A_AUTH 0x2F1FC 0x3A751 0x3AE72
task INT 0x2F281 0x3A7D6 0x3AEF7
cleareep INT 0x2F460 0x3A99E 0x3B0BF
commt INT 0x2F499 0x3A9D7 0x3B0F8
bestat A_AUTH 0x2F79B 0x3ACD9 0x3B3FA
bringup / BOOT A_AUTH 0x2DAC3 0x39018 0x39739
shutdown / HALT A_AUTH 0x2DC1C 0x39171 0x39892
r / R8 A_AUTH 0x2DC9B 0x391F0 0x39911
r16 / R16 A_AUTH 0x2DC9B 0x391F0 0x39911
r32 / R32 A_AUTH 0x2DC9B 0x391F0 0x39911
r64 A_AUTH 0x2E7BC 0x39D11 0x3A432
r64d A_AUTH 0x2E7BC 0x39D11 0x3A432
w / W8 A_AUTH 0x2E03B 0x39590 0x39CB1
w16 / W16 A_AUTH 0x2E03B 0x39590 0x39CB1
w32 / W32 A_AUTH 0x2E03B 0x39590 0x39CB1
w64 A_AUTH 0x2E6C1 0x39C16 0x3A337
wbe A_AUTH 0x2E6C1 0x39C16 0x3A337
BOOTENABLE A_AUTH 0x2DC7B 0x391D0 0x398F1
EEP A_AUTH 0x2E8C2 0x39E17 0x3A538
PDAREA A_AUTH 0x2E9B8 0x39F0D 0x3A62E
CSAREA A_AUTH 0x2E9B8 0x39F0D 0x3A62E
portset INT 0x2EC36 0x3A18B 0x3A8AC
extend A_AUTH 0x2ECF9 0x3A24E 0x3A96F
version ANY 0x80D0 0xA0F1 0xA0FF
revision ANY 0x812B 0xA14C 0xA15A
setcmdlong / SETCMDLONG ANY 0x8251 0xA272 0xA280
VER ANY 0x81C3 0xA1E4 0xA1F2
csum A_AUTH 0x8356 0xA37B 0xA389
AUTH1 B_AUTH 0x8555 0xA5AF 0xA5BD
AUTH2 B_AUTH 0x8555 0xA5AF 0xA5BD
AUTHVER ANY 0x86FB 0xA755 0xA763
errlog / ERRLOG ANY 0x311DA 0x3C484 0x3CC7D
powersw A_AUTH 0x31C87 0x3D005 0x3D7FE
ejectsw A_AUTH 0x31CA5 0x3D023 0x3D81C
doorsw A_AUTH N/A ? N/A ? 0x3D83C
buzzduty INT 0x31CC5 0x3D043 0x3D8D7
buzz INT 0x31D24 0x3D0A2 0x3D936
VID A_AUTH 0x33F98 0x3FC43 0x404D8
CID A_AUTH 0x340BF 0x3FD6A 0x405FF
ECID A_AUTH 0x340BF 0x3FD6A 0x405FF
SPU A_AUTH 0x34211 0x3FEBC 0x40751
REV A_AUTH 0x342BC 0x3FF67 0x407FC
KSV A_AUTH 0x34363 0x4000E 0x408A3
MOUNTINFO A_AUTH N/A ? N/A ? 0x4095B
portscan A_AUTH 0x3441B 0x400C6 0x40A2A
eepcsum A_AUTH 0x33F46 0x3FBF1 0x40486
patchinfo A_AUTH 0x346DD 0x40388 0x40CF2
poll INT 0x346F3 0x4039E 0x40D08
recv INT 0x3470F 0x403BA 0x40D24
send INT 0x3472B 0x403D6 0x40D40
LS INT 0x34747 0x403F2 0x40D5C
hversion INT 0x34763 0x4040E 0x40D78

Access to Syscon from Linux

Access SysCon ROM without needing ps3dm-utils: http://wiki.gitbrew.org/wikibrew/PS3:HvReverseEngineering#SYSCON

Placeholder for bga patch key generation

34 3A 00 00 00 00 5F 5F 53 43 45 49 53 59 53 31
4:....__SCEISYS1

OR (slim DYN-001)

00 00 00 00 5F 5F 5F 5F 53 43 45 49 53 59 53 31
....____SCEISYS1
  • replace 4 dots with soft id in decimal form, xor with 0x140 key and with cipher patcher key and encrypt with master patcher key to obtain cipher master key for that soft id
  • replace 4 dots with soft id in decimal form, xor with 0x140 key and with hasher patcher key and encrypt with master patcher key to obtain hasher master key for that soft id