Syscon Firmware
Description
The Syscon firmware (also known as system controller firmware) is the software stored inside syscon. Composed by the base firmware (not updateable in retail syscon models) and a optional patch that is applyed virtually on runtime on top of the base firmware
The syscon patches (also known as system controller update packages) for retail PS3 models are distributed in PKG format inside the Update_files.tar of the PS3UPDAT.PUPs. Syscon patches appear to always be 5KB (5376 bytes) in size.
Update procedure
The PS3 firmware installer PUP's contains a collection of syscon patches for all the different syscon's chips used in the different motherboard models. The ps3swu.self (system updater) checks the syscon SoftID and installs the compatible patch accordingly (via updater manager ss service).
The non-retail PS3 models with syscon CXR713F120A don't have patches, this special syscon model with the "F" product code (that seems to indicate that is fully flasheable) allows to overwrite the base syscon firmware through the Communication Processor
Syscon firmwares
SoftID | Firmware version | Build target | Build date | Adds support for Platform IDs | Corresponding SDK / CP versions | Notes |
---|---|---|---|---|---|---|
- | v0.4.5_b4 | BACKUP | 2005 | (Cyt1.0), (Cyt1.1), (Cyt2.1), (Cok01) | 0.40 | Only used on the backup bank of flash models |
06DA | v0.6.1_c8 | CYTOLOGY | 2006/01/31 | Cyt1.2, Cyt2.0, Cyt2.2, (Cok02), (Cok03) | 0.80 / 0.3.2 | |
073E | v0.6.10_c4 | CYTOLOGY | 2006/03/01 | (Cok05) | 0.81 / 0.4.3/0.4.7 | |
07FF | v0.6.11_c4 | CYTOLOGY | 2006/03/27 | Cyt3.0, Cyt3.1, Cyt3.2, (Cok08) | 0.82 / 0.5.3 | |
086C | v0.6.12_c5 | CYTOLOGY | 2006/04/11 | - | 0.83 / 0.6.4/0.6.5/0.6.7 | |
08F1 | v0.6.12_c7 | CYTOLOGY | 2006/04/22 | - | 0.83 | |
0955 | v0.6.14_c4 | CYTOLOGY | 2006/05/01 | - | 0.84 / 0.7.1 | |
0AF4 | v0.8.4_c8 | CYTOLOGY | 2006/06/23 | (Cok11) | 0.85 / 0.8.4/0.8.8 | |
0B48 | v0.9.9_c1 | CYTOLOGY | 2006/07/07 | Cyt3.3, Cyt3.4, (Cok12), (Cok13), (Cok14) | 0.90 / 0.9.1 | |
0B67 | v0.9.13_k1 | COOKIE | 2006 | - | - | COOKIE-13, COK-001(Proto), etc... with a CXR713F120A |
0B74 | v0.9.14_c1 | CYTOLOGY | 2006/08/03 | - | 0.91 / 0.9.2 | |
0B8E | v1.0.0_k1 | COOKIE (201) | 2006 | - | - | |
0B9D | v1.0.1_c1 | CYTOLOGY | 2006/08/31 | - | 0.93 / 0.9.4 | |
0C16 | v1.1.3_k1 | COOKIE (202) | 2006 | CokB10 | - | |
0C23 | v1.0.3_c1 | CYTOLOGY | 2006/12/04 | - | 1.50 / 1.1.1 | |
0D52 | v1.2.3_k1 | COOKIE (203) | 2007 | CokC10, CokC11, CokC12, CokD10 | - | |
0D79 | v1.0.4_c1 | CYTOLOGY | 2007/06/21 | - | 1.90 / 1.2.0 | |
0DBF | v1.3.3_k1 | COOKIE (301) | 2007 | - | - | |
0E4E | v1.0.4_c2 | CYTOLOGY | 2007/11/08 | - | 2.40 / 1.3.1 | |
0E69 | v1.4.4_k2 | COOKIE (302) | 2007 | CokE10, Deb01 | - | |
0F29 | v1.5.0_k2 | COOKIE (303) | 2009 | - | - | Removes hardcoding from previous firmware, adds support for 65nm RSX - not dumped yet |
0F38 | v1.5.1_k2 | COOKIE (304) | 2010 | - | - | Adds support for 40nm RSX |
0F3B | v1.0.5_c1 | CYTOLOGY | 2010/05/12 | - | 3.60 / 1.3.3 |
SoftID | Firmware version | Build target | Build date | Adds support for Platform IDs | Notes |
---|---|---|---|---|---|
0658 | ?.??.? | - | 2008 | CokF10 | not dumped yet VERTIGO-02 |
065D | 0.17.0 | SW-301 | 2008 | - | |
???? | ?.??.? | SW-302 | 2008 | - | not dumped yet VER-001 |
0832 | 1.11.0 | SW2-301 | 2009 | CokG10, CokG11 | |
08A0 | 1.16.0 | SW2-302 | 2009 | CokH10, CokH11, CokJ12 | |
08C2 | 1.21.0 | SW2-303 | 2010 | CokJ13, CokJ20 | |
0918 | 2.3.0 | SW3-301 | 2011 | CokK10 | |
098F | 2.12.0 | SW3-302 | 2012 | CokM20, CokM40, CokN10, CokN30 | |
???? | ?.??.? | SW3-303 | 2013 | - | not dumped yet (unknown PS3 model/motherboard) |
09A4 | 2.21.0 | SW3-304 | 2013 | - |
Syscon patches
These patches are in full Retail/CEX and Debug/DEX firmwares. Are intended to fix some problem in the syscon firmware
- Fix 1) System firmware 1.30 (December 6, 2006). Disables UART access to the Syscon EEPROM patch region (not for 0832)
- Fix 2) System firmware 1.81 (June 15, 2007). Patch for the HDMI display data channel read function (only for 0B8E and 0C16)
- Fix 3) System firmware 3.00 (September 1, 2009). Unknown patch (only for 0832)
- Fix 4) System firmware 3.40 (June 29, 2010) and 3.41 (July 26, 2010). Patch for the rtc read function (not for 0832)
SoftID | sys_con_firmware package | 1.00~1.11 | 1.30~1.80 | 1.81~2.80 | 3.00~3.30 | 3.40 | 3.41~4.88 | Notes |
---|---|---|---|---|---|---|---|---|
0B8E | SYS_CON_FIRMWARE_01000004.pkg | No | Yes (fix 1) | No | No | No | No | Superseded by SYS_CON_FIRMWARE_01000005.pkg |
SYS_CON_FIRMWARE_01000005.pkg | No | No | Yes (fix 1+2) | No | No | Superseded by SYS_CON_FIRMWARE_01000006.pkg | ||
SYS_CON_FIRMWARE_01000006.pkg | No | No | No | No | Yes (fix 1+2+4) | CXR713120-201GB ...4706 | ||
0C16 | SYS_CON_FIRMWARE_01010302.pkg | No | No | Yes (fix 1+2) | No | No | Superseded by SYS_CON_FIRMWARE_01010303.pkg | |
SYS_CON_FIRMWARE_01010303.pkg | No | No | No | No | Yes (fix 1+2+4) | CXR713120-202GB ...7214 | ||
0D52 | SYS_CON_FIRMWARE_01020302.pkg | No | No | No | No | Yes (fix 1+4) | CXR713120-203GB ...F427 | |
0DBF | SYS_CON_FIRMWARE_01030302.pkg | No | No | No | No | Yes (fix 1+4) | CXR714120-301GB ...F321 | |
0E69 | SYS_CON_FIRMWARE_01040402.pkg | No | No | No | No | Yes (fix 1+4) | CXR714120-302GB ...5096 | |
0F29 | SYS_CON_FIRMWARE_01050002.pkg | No | No | No | No | Yes (fix 1+4) | CXR714120-303GB | |
0F38 | SYS_CON_FIRMWARE_01050101.pkg | No | No | No | No | No | Yes (fix 1+4) | CXR714120-304GB ...16FA |
0832 | SYS_CON_FIRMWARE_S1_00010002083E0832.pkg | No | No | No | Yes (fix 3) | SW2-301 |
The screen More System Information allows to see some details related with syscon. The syscon firmware version can be derived from the SoftID, and additionally if there is a patch installed the PatchID displayed in the screen contains both, the syscon firmware version and the patch version. Note also that there is a direct relationship in between the PatchID displayed in the screen and the patch filename. The syscon UART commands also displays some info related with the base syscon firmware and the patch
Some examples from syscon UART:
>$ revision 0C16 >$ version v1.1.3_k1 >$ patchvereep major:0x0001 minor:0x0001 patch:0x0003 revision:0x0003 >$ patchcsum r1 csum: [00030266] [018DB626] [90662679] r2 csum: [000069C5] [0046B830] [5E535A06]
>$ revision # Revision = 2098(0832) >$ version # Sherwood Version = 1.11.0 >$ patchinfo # # MAJOR :0000 # MINOR :0000 # REV :0000 # SYS_REV :0000 # TABLE :00FFFFFF # DATSIZ :FFFF # DATSUM :FFFF # SUM :FFFF # not applyed
>$ revision # Revision = 2098(0832) >$ version # Sherwood Version = 1.11.0 >$ patchinfo # # MAJOR :0001 # MINOR :0002 # REV :083E # SYS_REV :0832 # TABLE :0000201A # DATSIZ :0FAA # DATSUM :02AB # SUM :035D # applyed
- Mullion PatchID names format (major, minor, patch, revision)
- 0B8E.0000000000000000@SC = syscon firmware v1.0.0_k1, not patched
- 0B8E.0001000000000005@SC = syscon firmware v1.0.0_k1, patch 5 (filename SYS_CON_FIRMWARE_01000005.pkg)
- 0F38.0000000000000000@SC = syscon firmware v1.5.1_k2, not patched
- 0F38.0001000500010001@SC = syscon firmware v1.5.1_k2, patch 1 (filename SYS_CON_FIRMWARE_01050101.pkg)
- Sherwood PatchID names format (major, minor, rev, sys_rev)
- 0832.0000000000000000@SC = syscon firmware 1.11.0, not patched
- 0832.00010002083E0832@SC = syscon firmware 1.11.0, patch 1.2.83E.832 (filename SYS_CON_FIRMWARE_S1_00010002083E0832.pkg)
Package structure
Sys_con_firmware Packages can be unpacked with unpkg. See PKG files and Certified File
Header
Address | Length | Value | Description |
---|---|---|---|
0x00 | 0x4 | ASCI:"SCE" | SCE magic header |
0x04 | 0x4 | 0x2 | Version |
0x08 | 0x2 | 0x0 | Attribute |
0x0A | 0x2 | 0x3 | Category (0x3 = Update Package) |
0x0C | 0x4 | 0x0 | Extended Header Size (no ext header) |
0x10 | 0x8 | 0x280 | File Offset (hdr_len) |
0x18 | 0x8 | 0x1080 | File Size (dec_size) |
0x20 | 0x260 | - | Encrypted part of header |
0x280 | 0x40 | - | update_package_header section (see below) |
0x2C0 | 0x40 | - | update_package_contents_header section (see below) |
0x300 | 0x1000 | - | content section |
Update Package Header
Address | Length | Value | Description |
---|---|---|---|
0x00 | 0x4 | 0x3 | Header Version? 3 (fixed value for all PS3 update packages) |
0x04 | 0x4 | 0x8 | SoftType? 8 = SC firmware |
0x08 | 0x8 | - | SC firmware revision (the high word of it is the SC type) |
0x0C | 0x4 | 0x0B8E(1.30-4.84) 0x0C16(1.81-4.84) 0x0D52(3.40-4.84) 0x0DBF(3.40-4.84) 0x0E69(3.40-4.84) 0x0F29(3.40-4.84) 0x0F38(3.41-4.84) 0x0832(3.00-4.84) |
'SoftID' |
0x10 | 0x8 | 0x0001000000000004 0x0001000000000005 0x0001000000000006 0x0001000100030002 0x0001000100030003 0x0001000200030002 0x0001000300030002 0x0001000400040002 0x0001000500000002 0x0001000500010001 0x00010002083E0832 |
'PatchID' (official name is "version") |
0x18 | 0x8 | 0x1000 | Content Data Size |
0x20 | 0x8 | 0x1000 | Content Compressed Data Size |
0x28 | 0x4 | 0x0 | Attribute |
0x2C | 0x4 | 0x0 | Region |
0x30 | 0x8 | 0x0 | Image Offset |
0x38 | 0x8 | 0x0 | Reserved_0 |
Note: PS3 firmwares cannot deal with compressed syscon firmwares, so they will abort the update process in that case.
Note2: The PatchID is also present in the first 8 bytes of decrypted content but 16bit swapped for ARM BGAs
Update Package Contents Header
Address | Length | Value | Description |
---|---|---|---|
0x00 | 0x8 | 0x3 | Header Version? |
0x08 | 0x8 | 0x40 | Header Size? |
0x10 | 0x8 | 0x0 | Chunk Offset |
0x18 | 0x8 | 0x1000 | Chunk Size |
0x20 | 0x8 | 0x1 | Current Chunk |
0x28 | 0x8 | 0x1 | Chunks Total |
0x30 | 0x8 | 0x0 | Reserved_0? |
0x38 | 0x8 | 0x0 | Reserved_1? |
Content
Address | Length | Value | Description |
---|---|---|---|
0x0 | 0x1000 | - | Content Data |
Content Data Header
The header format is partially unknown at this stage. All the Firmwares patches are written in little endian.
Offset | Length | Notes | Related DECR Error | Notes |
---|---|---|---|---|
0x0 | 0x4 | Magic | FFFFFED2 (Magic Error) | 0x1B2D700F in mullions, sys1 in cytology ? |
0x4 | 0x10 | Header CMAC1 | FFFFFED1 (Header Check Error) | CMAC of Partial Header (0x10,0x30 size) with header first 4 bytes instead of random 4 bytes and where Header CMAC2 is zeroed Concatenated with Encrypted Body |
0x14 | 0x10 | Header CMAC2 | CMAC of Header (where this cmac has been zeroed) | |
0x24 | 0x4 | Padding | ||
0x28 | 0x4 | Total size | Always 0x1000 in mullions, 0x60040 in cytology ? | |
0x2C | 0x4 | Size of binary | Always 0xFC0 in mullions, 0x60000 in cytology ? | |
0x30 | 0x10 | IV for AES-128 CBC | ||
0x40 | 0xFC0 | Encrypted binary | FFFFFED0 (Data Check Error) FFFFFECF (Data Size Check Error) |
- Note: For the weird bogus update ONLY: FFFFFF37 (Alignment Error?) (Trying any data size between 0x41 and 0x4C bytes)
- Note2: v0.6.14c4 is the bogus update (only update with a weird header)
- Note3: setting data between 0x40 to 0x4C to zero in bogus update yields error FFFFFED0
Samples
00000000 1B 2D 70 0F AB 5E B3 99 68 20 FE 3D E1 80 6A 1D .-p.«^³™h þ=á€j. 00000010 B8 FD 37 CF CD 45 85 AB 51 F7 05 E3 EA 32 A5 EA ¸ý7ÏÍE…«Q÷.ãê2¥ê 00000020 67 45 F9 48 00 00 00 00 00 10 00 00 C0 0F 00 00 gEùH........À... 00000030 8B 04 07 F9 9B A2 90 3A 75 89 F1 42 12 59 DA 0D ‹..ù›¢.:u‰ñB.YÚ. 00000040 21 7C A2 C3 5A E4 78 00 10 8D 4B F7 A2 73 9C 63 !|¢ÃZäx...K÷¢sœc 00000050 5D 8D 5D 49 16 C7 6F 2C AD 33 FE 1F D3 6C A1 CA ].]I.Ço,.3þ.Ól¡Ê 00000060 BA AD 2B FE 8F 33 71 D7 C5 E6 5C FF BF 77 6C 80 º.+þ.3q×Åæ\ÿ¿wl€ 00000070 F2 BE 11 BB 3C 52 52 DC A9 68 E5 24 AD 4F F3 48 ò¾.»<RRÜ©hå$.OóH
-From v1.0.4c2_TMU510_u-
00000000 73 79 73 31 73 47 59 5D FB 85 3B 7B 4A 28 10 5D sys1sGY]û…;{J( ] 00000010 46 EE 8C 01 3C B4 F1 82 1E 18 4F B7 4A 56 FC C7 FîŒ <´ñ‚ O·JVüÇ 00000020 FF 83 0B E0 00 00 00 00 40 00 06 00 00 00 06 00 ÿƒ à @ 00000030 69 B6 02 69 3A 97 8B 1C 4E 18 D4 E0 63 7D CA 94 i¶ i:—‹ N Ôàc}Ê” 00000040 4B A0 79 34 79 41 BD 09 BB 68 D4 0A A0 B7 05 78 K y4yA½ »hÔ · x 00000050 D9 8F 8F 28 6C 9A 1B 61 CF A1 E7 49 7D CA C4 A3 Ù (lš aÏ¡çI}ÊÄ£ 00000060 A4 4D 4B E0 AE 48 86 03 B1 43 F2 47 C0 C4 1D 4F ¤MKà®H† ±CòGÀÄ O 00000070 FA E8 43 A7 1E 6E 79 8C E5 FF 04 20 E9 44 09 B5 úèC§ nyŒåÿ éD µ
Content Data Patch (encrypted)
Packages can be extracted with the unpkg tool. Extracted content of the updates appears to always be 0x1000 bytes (4KB).
The following is all theoretical and is intended to discard possibilities about modes of operation used by aes when decrypting body of firmware/patch
We know that:
- Two key expansions are used before applying crypto on body (one probably for hashing. the other for decrypting with cbc)
- Encrypt is used when applying crypto on body TopHalf (forward ttables) and Decrypt is used when applying on body Bottomhalf (inverse ttables)
- Authenticated regions uses a form of what seems to be some ECB with tweak xoring (as graf once said about XTS)
- XTS was introduced in 2007 and SysCon from ps3 exists for far more time than that (2003)
- XEX is a close relative of XTS that was introduced in 1984
- PS4 uses XTS for Authenticated Regions or SNVS (with sector size of 0x20 being used. is this even considered safe?)
- 4 regions can be controlled for DPA and they are: 0x2790 (size 0x20) (FFs), patch header (most notably at offset 0x4 of header size 0x10 and 0x30 size 0x10), patch body tophalf(+0x40) and patch body bottomhalf(+0x50)
- here are the DPA bytes for each of the controlable sections:
- 21 06 23 DC A2 98 99 4D XX 87 F8 40 FC 48 1C BF (section 2/FF's from 0x2790 on DIA-001) -> 210623DCA298994DFE87F840FC481CBF
- 21 06 23 DC A2 98 99 4D XX 87 F8 40 FC 48 1C BF (section 2/FF's from 0x2790 on DEB-001) -> 210623DCA298994DFE87F840FC481CBF
- 16 32 47 79 C3 2C 47 D3 2B 39 CA B5 83 41 0E D5 (section 3/header from DIA-001 patch content)
- XX XX XX XX 7B FC 27 CD D5 9A 05 09 3A DF E4 75 (section 3/header AA from DEB-001 patch content) -> 6E9CE7C57BFC27CDD59A05093ADFE475
- 92 4A 87 88 20 59 6C 49 9F 0E 7D 77 2F 38 4C FC (section 3/header DD from DEB-001 patch content)
- 7D C6 3B 3B 69 DF 67 4C 94 D7 D4 A8 E0 F8 5B B2 (section 4/body from DIA-001 patch content/tophalf/forward)
- 73 XX F0 3D XX 9A F0 92 4D XX 62 DA XX 48 3C DB (section 4/body from DIA-001 patch content/bottomhalf/inverse)
- 49 1F 7B 0A 48 BD 79 33 4E 16 89 F6 B0 25 86 48 (section 4/body from DEB-001 patch content/tophalf/forward)
- 14 4D F1 D3 21 B6 17 46 60 81 42 E5 02 C9 07 66 (section 4/body from DEB-001 patch content/bottomhalf/inverse/PROPER) -> 6B3583DA1AA6B49106E1641178EE68C8 (inverse ttables)
- some bytes are considered "weak" bytes and should be bruteforced in the eventuality these keys fail
- another possibility is that both the header and the body are hashed and then decrypted, using for example, cmac and cbc
- since key expansions take 10 "hills" in the analysis, it should be safe to assume that AES-128 is used(because it uses 10 rounds).
- 6554cff202c3bfdd9740901070b705bf : correct md5 for patch content we are trying keys on (DIA-001)
- 4875ad06a1499cc516a0d4d92e595794 : correct md5 for patch content we are trying keys on (DEB-001/DIA-002)
- trying a different header/body patch content from another similar board will result into failure of decrypting body, which means that the header is checked for authenticity and that the header hash is NOT in the header
- altering the patch header doesn't cause the patch header dpa bytes to change (a test was done with 4 bytes and the result was 16 32 47 79, which matches the other patch dpa recovered bytes)
- there are in fact not 4 but 5 aes sections. the last one seems to be body related, as changing the body even one bit makes the last aes section disappear.
- section 2 is divided into two sections, corresponding to TopHalf and BottomHalf of patch area.
- TopHalf uses forward ttables/sbox. BottomHalf uses inverse ttables/sbox
- TopHalf is ONLY the very first 0x10 bytes AFTER the header and into the body (corresponding to 0x40 in header size 0x10)
- BottomHalf is the rest of the body itself.
- DYN-001 processes one entire chunk of 0x1000 bytes, 0x40 for header and 0xFC0 for body, and not two of 0x400 and 0xC00 like the Sony models
- 504 aes operations are done for the body (252/0xFC for cmac and 252/0xFC for cbc). it is unknown if cmac comes first or it is cbc.
- All attacks show weak bytes in comparisson with CXR(F), likely due to CXR being optimized for the attack (removed resistors/capacitors, etc)
Patch structure (decrypted)
Mullion Patch structure
Offset | Size | Name | Number | Example | Notes |
---|---|---|---|---|---|
0x00 | 0x2 | Major Version | 1 | ||
0x02 | 0x2 | Minor Version | 1 | ||
0x04 | 0x2 | Major Revision | 1 | ||
0x06 | 0x2 | Minor Revision | 1 | ||
0x08 | 0x10 | Patch Addresses | 4*4 | ||
0x18 | 0x10 | Patch Instruction / Data | 4*4 | ||
0x28 | 0x10 | Patch Jump Instruction Addresses | 4*4 | ||
0x38 | 0x388 | Additional Patch Instructions | 1 | ||
0x3C0 | 0xC00 | HDMI Patch | 1 |
Sherwood Patch structure
Offset | Size | Name | Number | Example | Notes |
---|---|---|---|---|---|
0x00 | 0x4 | Magic | 1 | 0x5D4E246B | |
0x04 | 0x2 | Major Version | 1 | 0x0001 | In the output of the UART command patchinfo is named MAJOR |
0x06 | 0x2 | Minor Version | 1 | 0x0002 | In the output of the UART command patchinfo is named MINOR |
0x08 | 0x2 | Major Revision | 1 | 0x083E | In the output of the UART command patchinfo is named REV (patch revision) |
0x0A | 0x2 | Minor Revision | 1 | 0x0832 | In the output of the UART command patchinfo is named SYS_REV (syscon revision) |
0x0C | 0x4 | Absolute Table Address | 1 | 0x0000201A | In the output of the UART command patchinfo is named TABLE |
0x10 | 0x2 | Data Size | 1 | 0x0FAA | In the output of the UART command patchinfo is named DATSIZE |
0x12 | 0x2 | Data Checksum | 1 | 0x02AB | In the output of the UART command patchinfo is named DATSUM |
0x14 | 0x2 | Patch Checksum | 1 | 0x035D | In the output of the UART command patchinfo is named SUM (patch checksum) |
0x16 | 0x2 | Relative Data Address | 1 | 0x0000 | Not parsed/ignored on SW (only used on SW2/SW3). Relative to the patch start address (0x2000) |
0x18 | 0x2 | Relative Table Address | 1 | 0x0000 | Not parsed/ignored on SW (only used on SW2/SW3). Relative to the patch start address (0x2000) |
0x1A | 0x80 | Table | 4*0x20 | ||
0x9A | 0x6 | Padding | - | Not parsed/ignored on SW (only used on SW2/SW3) |
Command list
Mullion
External commands
Address | Command | Subcommand | Permission |
---|---|---|---|
0x32959 | BOOT | MODE | 0x000080D6 |
0x329D5 | BOOT | CONT | 0x000080D5 |
0x342D7 | SHUTDOWN | - | 0x0000C0D5 |
0x32A51 | HALT | - | 0x0000C0D5 |
0x32A85 | BOOTENABLE | - | 0x0000809A |
0x33491 | AUTH1 | - | 0x0000C0EF |
0x33525 | AUTH2 | - | 0x0000C0EF |
0x33619 | AUTHVER | SET | 0x0000C0DF |
0x335BF | AUTHVER | GET | 0x0000C0FF |
0x32AC3 | EEP | INIT | 0x000080DA |
0x32C51 | EEP | SET | 0x0000C0DF |
0x32D3D | EEP | GET | 0x0000C0DF |
0x32EA7 | PDAREA | SET | 0x0000C0DF |
0x32E3B | PDAREA | GET | 0x0000C0DF |
0x330C5 | CSAREA | SET | 0x0000C0DF |
0x33057 | CSAREA | GET | 0x0000C0DF |
0x33169 | VID | GET | 0x0000C0D5 |
0x331D7 | CID | GET | 0x0000C0D5 |
0x3321D | ECID | GET | 0x0000C0D5 |
0x3325D | REV | SB | 0x0000C0D5 |
0x3328D | SPU | INFO | 0x0000C0D5 |
0x332E1 | KSV | - | 0x0000C0D5 |
0x33685 | FAN | SETPOLICY | 0x0000C0D7 |
0x33717 | FAN | GETPOLICY | 0x0000C0D7 |
0x33781 | FAN | START | 0x0000C0D7 |
0x33781 | FAN | STOP | 0x0000C0D7 |
0x33951 | FAN | SETDUTY | 0x0000C0D7 |
0x339C3 | FAN | GETDUTY | 0x0000C0D7 |
0x33A27 | R8 | - | 0x0000C0DF |
0x33AD1 | W8 | - | 0x0000C0DF |
0x33B71 | R16 | - | 0x0000C0DF |
0x33C19 | W16 | - | 0x0000C0DF |
0x33CBB | R32 | - | 0x0000C0DF |
0x33E49 | W32 | - | 0x0000C0DF |
0x33EE9 | RBE | - | 0x0000C0D5 |
0x33F91 | WBE | - | 0x0000C0D5 |
0x34049 | PORTSTAT | - | 0x0000C0DF |
0x332BF | VER | - | 0x0000C0FF |
0x341C5 | BUZ | - | 0x00008096 |
0x342D7 | SERVFAN | - | 0x0000C0D7 |
0x341F9 | ERRLOG | START | 0x0000C0DF |
0x34221 | ERRLOG | STOP | 0x0000C0DF |
0x34249 | ERRLOG | GET | 0x0000C0FF |
0x342B3 | ERRLOG | CLEAR | 0x0000C0DF |
Internal commands
Command | Address | Perms | SubCommands | Description |
---|---|---|---|---|
becount | 0xCA7D | 0xDD0C0000 | - | Display bringup/shutdown count + Power-on time |
bepgoff | 0xA4E7 | 0xD00C0000 | - | BE power grid off |
bepkt | 0x2435D | 0xDC0C0000 | show/set/unset/mode/debug/help | Packet permissions |
bestat | 0xD413 | 0xFD0F0000 | - | Get status of BE |
boardconfig | 0x99C7 | 0xDC0C0000 | - | Displays board configuration (NOT WORKING?) |
bootbeep | 0x1EA67 | 0xF0000000 | stat/on/off | Boot beep |
bringup | 0xD597 | 0xFD0F0000 | - | Turn PS3 on |
bsn | 0xD805 | 0xF00F0000 | - | Get board serial number |
bstatus | 0x24269 | 0xDD0C0000 | - | HDMI related status |
buzz | 0xA4FF | 0xDC0C0000 | [freq] | Activate buzzer |
buzzpattern | 0xA8B7 | 0xDC0C0000 | [freq] [pattern] [count] | Buzzer pattern |
clear_err | 0x2595B | 0xDD0C0000 | last/eeprom/all | Clear errors |
clearerrlog | 0xB8CB | 0xDD0C0000 | - | Clears error log |
comm | 0x9919 | 0xDC0C0000 | - | Communication mode |
commt | 0x24907 | 0xDC0C0000 | help/start/stop/send | Manual BE communication |
cp | 0x1E077 | 0xF0000000 | ready/busy/reset/beepremote/beep2kn1n3/beep2kn2n3 | CP control commands |
csum | 0xD687 | 0xFF0F0000 | - | Firmware checksum |
devpm | 0xD053 | 0xDD0C0000 | ata/pci/pciex/rsx | Device power management |
diag | 0x9AAD | 0xD00C0000 | ... | Diag (execute without param to show help) (NOT WORKING?) |
disp_err | 0x25911 | 0xDD0C0000 | - | Displays errors |
duty | 0x9B23 | 0xDD0C0000 | get/getmin/getmax/getinimin/getinimax set/setmin/setmax/setinimin/setinimax |
Fan speed
Usage: duty get fanconNo ex. duty get 1 |
dve | 0x2995D | 0xDC0C0000 | help/set/save/show | DVE chip parameters |
eepcsum | 0xAA65 | 0xDD0C0000 | - | Displays checksums of some eeprom areas |
eepromcheck | 0x9A1D | 0x000C0000 | [id] | Check eeprom |
eeprominit | 0x9A65 | 0x000C0000 | [id] | Init eeprom |
ejectsw | 0xD611 | 0xFD0F0000 | - | Eject switch |
errlog | 0xB7ED | 0xFF0C0000 | - | Gets the error log |
fancon | 0xD26D | 0x0D000000 | - | Does nothing |
fanconautotype | 0xC075 | 0xDD0C0000 | - | Does nothing |
fanconmode | 0xBF35 | 0xDD0C0000 | get | Fan control mode (0=Full, 1=VaryTable & VaryServo, 2=Manual, 3=Minimun)
Usage: fanconmode get fanconNo ex. fanconmode get 1 |
fanconpolicy | 0xBBC9 | 0xDD0C0000 | get/set/getini/setini | Fan control policy (0=Full, 1=Auto, 2=Manual)
Usage: fanconpolicy get fanconNo ex. fanconpolicy get 1 |
fandiag | 0x1E91B | 0xF0000000 | - | Fan Diagnostic (test) |
faninictrl | 0xD3D9 | 0x0D000000 | - | Does nothing |
fanpol | 0xCA31 | 0xDD0C0000 | - | Does nothing |
fanservo | 0xBF29 | 0xDD0C0000 | - | Does nothing |
fantbl | 0xC087 | 0xDD0C0000 | get/set/getini/setini/gettable/settable/getselect/setselect | Fan table: get/set - currently in RAM/in use ; getini/setini - stored in EEPROM (!! in COK the chksum does not updated automatically !!)
Usage: fantbl set fanconNo pNo tempD tempU duty ex. fantbl set 0 p1 0x1400 0x1E40 0xC0 ex. fantbl set 0 p1 20.0 30.25 75 Usage: fantbl get fanconNo ex. fantbl get 1 |
firmud | 0xD61D | 0xFDFF0000 | - | Firmware update |
geterrlog | 0xB84F | 0xDD0C0000 | [id] | Gets error log |
getrtc | 0xA6F3 | 0xDD0C0000 | - | Gets rtc |
halt | 0x1E107 | 0xF0000000 | - | Halts syscon |
hdmi | 0x29F39 | 0xDD0C0000 | ... | HDMI (various commands, use help)
[HDMI Help] HDMI System Start :$ hdmi setup ([ChannelNo]) [HDMI Help] Show IC Type :$ hdmi ictype [ChannelNo] [HDMI Help] Display EDID :$ hdmi redid [ChannelNo] (p) [HDMI Help] Display KSV :$ hdmi rksv [ChannelNo] [HDMI Help] SiI Register Read :$ hdmi r [ChannelNo] [TargetDevID(0/1)] [OffsetAddr(hex)] [ReadSize(hex)] [HDMI Help] SiI Register Write :$ hdmi w [ChannelNo] [TargetDevID(0/1)] [OffsetAddr(hex)] [WriteData(hex)] [HDMI Help] Set 12bit Param :$ hdmi 12bit [ChannelNo] (d1:0 - d5:4) [HDMI Help] Set 10bit Param :$ hdmi 10bit [ChannelNo] (d1:0 - d5:4) [HDMI Help] DDC Bus Read :$ hdmi dr [ChannelNo] [TargetDevID(0/1)] [OffsetAddr(hex)] [ReadSize(hex)] [HDMI Help] DDC Bus Write :$ hdmi dw [OffsetAddr(hex)] [WriteData(hex)] [HDMI Help] Show Channel Status :$ hdmi chstat [ChannelNo] [HDMI Help] Debug Log Verbose :$ hdmi vbs ([Verbose Setting(hex)]) [HDMI Help] HDMI System Shutdown :$ hdmi letup ([ChannelNo]) [HDMI Help] HDMI Eleguler Test :$ hdmi hwreset ([ChannelNo]) [HDMI Help] HDMI Eleguler Test KPL :$ hdmi hwreset2 ([ChannelNo]) [HDMI Help] HDMI Manage Struct Dump :$ hdmi dumpst ([ChannelNo]) [HDMI Help] Show HDMI and DVE Port Num:$ hdmi ports [HDMI Help] Show Timer Value :$ hdmi timer [HDMI Help] Show I2C Resource :$ hdmi i2c [HDMI Help] Show Patch Information :$ hdmi patch [HDMI Help] Resolution Reset :$ hdmi resrst [ChannelNo] [HDMI Help] Show this Message :$ hdmi help |
hdmiid | 0x29D1D | 0xDC0F0000 | - | Get HDMI id's |
hdmiid2 | 0x29D81 | 0xDC0F0000 | - | Get HDMI id's |
hversion | 0x2422F | 0xDD0C0000 | - | Displays Platform ID |
hyst | 0xAEF5 | 0xDD0C0000 | get/set/getini/setini | This value is stored inside the Thermal Config area, every thermal sensor has their own. See: Hysteresis
Usage: hyst set TZoneNo temp ex. hyst set 1 0x0200 ex. hyst set 1 2.0 Usage: hyst get TZoneNo ex. hyst get 14 |
lasterrlog | 0xB7FF | 0xDD0C0000 | - | Last error from log |
ledmode | 0xA80B | 0xDC0C0000 | [id] [id] | Get led mode |
LS | 0x2421B | 0xDD0C0000 | - | LabStation Mode |
ltstest | 0xCB97 | 0xDD0C0000 | get/set be/rsx | ?Temp related? values |
osbo | 0x1EA3F | 0xF0000000 | - | Sets 0x2000F60 |
patchcsum | 0xD9F7 | 0xDD0C0000 | - | Patch checksum |
patchvereep | 0xD9B1 | 0xDD0C0000 | - | Patch version eeprom |
patchverram | 0xD965 | 0xDD0C0000 | - | Patch version ram |
poll | 0x240E3 | 0xDD0C0000 | - | Poll log |
portscan | 0xDA0D | 0xDD0C0000 | [port] | Scan port (NOT WORKING?) |
powbtnmode | 0xB911 | 0xDC0C0000 | [mode (0/1)] | Power button mode |
powerstate | 0xCE6F | 0xDD0C0000 | - | Get power state |
powersw | 0xD5F9 | 0xFD0F0000 | - | Power switch |
powupcause | 0xB621 | 0xDD0C0000 | - | Power up cause |
printmode | 0x99D9 | 0xDC0C0000 | [mode (0/1/2/3)] | Set printmode |
printpatch | 0xD94F | 0xDD0C0000 | - | Prints patch |
r | 0x8CA5 | 0xDD0C0000 | [offset] [length] | Read byte from SC |
r16 | 0x8ED5 | 0xDD0C0000 | [offset] [length] | Read word from SC |
r32 | 0x9191 | 0xDD0C0000 | [offset] [length] | Read dword from SC |
r64 | 0x935D | 0xDD0C0000 | [offset] [length] | Read qword from SC |
r64d | 0x948F | 0xDD0C0000 | [offset] [length] | Read ?qword data? from SC |
rbe | 0x96F9 | 0xDD0C0000 | [offset] | Read from BE |
recv | 0x24135 | 0xDD0C0000 | - | Receive something |
resetsw | 0xD605 | 0xFC0F0000 | - | Reset switch |
restartlogerrtoeep | 0xB903 | 0xDD0C0000 | - | Reenable error logging to eeprom |
revision | 0xD7E1 | 0xFFFF0000 | - | Get SoftID |
rrsxc | 0xD313 | 0xDD0C0000 | [offset] [length] | Read from RSX |
rtcreset | 0xA7BB | 0x000C0000 | - | Reset RTC |
scagv2 | 0xE24F | 0xFF000000 | - | Auth related? |
scasv2 | 0xE207 | 0xDD000000 | - | Auth related? |
scclose | 0xE1EF | 0xFF000000 | - | Auth related? |
scopen | 0xE121 | 0xFF000000 | - | Auth related? |
send | 0x2416F | 0xDD0C0000 | [variable] | Send something |
shutdown | 0xD5C5 | 0xFD0F0000 | - | PS3 shutdown |
startlogerrtsk | 0xB8E7 | 0xDD0C0000 | - | Start error log task |
stoplogerrtoeep | 0xB8F5 | 0xDD0C0000 | - | Stop error logging to eeprom |
stoplogerrtsk | 0xB8D9 | 0xDD0C0000 | - | Stop error log task |
syspowdown | 0xB6E9 | 0xDD0C0000 | 3 params | System power down |
task | 0x15005 | 0xDD0C0000 | - | Print tasks |
thalttest | 0xD813 | 0x000F0000 | - | Thermal Alert Test ? (boes nothing), maybe is needed to do it while GameOS is working to trigger the XMB overheat warning message and the power off sequence |
thermfatalmode | 0xCA3B | 0xDD0C0000 | canboot/cannotboot | Set boot mode after a thermal alert ? |
therrclr | 0xD3E5 | 0xDD0C0000 | - | Clears the thermal alert register ? |
thrm | 0xBF1D | 0xDD0C0000 | - | Does nothing |
tmp | 0xAA69 | 0xDD0C0000 | [tzone] | Get temperature
Usage: tmp TZoneNo ex. tmp 1 |
trace | 0xB951 | 0xDD0C0000 | ... | Trace tasks (use help)
Usage: trace command param command: [status/start/stop/dump/print/id] param (with `id' command): available characters: [0-9][,][-] ex. trace id 1-12,16 |
trp | 0xAB2F | 0xDD0C0000 | get/set/getini/setini | This value is stored inside the Thermal Config area, every thermal sensor has their own
Usage: trp set TZoneNo temp ex. trp set 2 0x5980 ex. trp set 2 89.5 Usage: trp get TZoneNo ex. trp get 14 |
tsensor | 0xA279 | 0xDD0C0000 | [tzone] | Get raw temperature
Usage: tsensor TZoneNo ex. tsensor 2 |
tshutdown | 0xB2A1 | 0xDD0C0000 | get/set/getini/setini | Thermal shutdown. This value is stored inside the Thermal Config area, every thermal sensor has their own
Usage: tshutdown set TZoneNo temp ex. tshutdown set 2 0x5A80 ex. tshutdown set 2 90.5 Usage: tshutdown get TZoneNo ex. tshutdown get 14 |
tshutdowntime | 0xC95D | 0xDD0C0000 | get | Thermal shutdown time. This value is stored inside the Thermal Config area, is a single value shared by all thermal sensors |
tzone | 0xB5E1 | 0xDD0C0000 | - | Shows a list of the "TZone" identifyers associated with every thermal sensor, and a short text description of them
Example, on cytology PS3 models > tzone 00: 1st BE Primary 01: RSX Primary 02: XDR Primary 0A: Air Intake 0F: GbE 14: SB Example, on cookie old > tzone 00: 1st BE Primary 01: RSX Primary 03: BE VR 14: SB 15: EE+GS Example, on cookie new > tzone 00: 1st BE Primary 01: RSX Primary 14: SB Example, on sherwood > tzone # 00:1st BE Primary # 01:RSX Primary |
version | 0xD65F | 0xFFFF0000 | - | Syscon firmware version |
w | 0x8BF9 | 0xDD0C0000 | [offset] [value] | Write byte to SC |
w16 | 0x8E2D | 0xDD0C0000 | [offset] [value] | Write word to SC |
w32 | 0x8FED | 0xDD0C0000 | [offset] [value] | Write dword to SC |
w64 | 0x92A9 | 0xDD0C0000 | [offset] [value] | Write qword to SC |
wbe | 0x9665 | 0xDD0C0000 | [offset] [value] | Write to BE |
wmmto | 0xCB3B | 0xDC0C0000 | get | Get watch dog timeout |
wrsxc | 0xD279 | 0xDD0C0000 | [offset] [value] | Write to RSX |
xdrdiag | 0x1E711 | 0xF0000000 | start/info/result | XDR diagnostics |
xiodiag | 0x1E875 | 0xF0000000 | - | XIO diagnostic |
xrcv | 0x25313 | 0xDC0C0000 | - | Xmodem receive |
Sherwood
- Permission
- 0x0700 = A_AUTH
- 0x0B00 = B_AUTH
- 0x0300 = INT (Command not available from UART interface. Can be unlocked by patching syscon firmware)
- 0x0F00 = ANY
Command lowercase/UPPERCASE |
Perms | Address | Notes | ||
---|---|---|---|---|---|
SW-301 | SW2-301 | SW3-304 | |||
hdmi | A_AUTH | 0x32030 | 0x3D989 | 0x3E21D | |
tsensor | A_AUTH | 0x2FB30 | 0x3B1CF | 0x3B8F0 | |
tmp | A_AUTH | 0x2FE7F | 0x3B3D5 | 0x3BAF6 | |
trp | A_AUTH | 0x2FFA6 | 0x3B627 | 0x3BD48 | |
tshutdown | A_AUTH | 0x301D8 | 0x3B645 | 0x3BD66 | |
tzone | A_AUTH | 0x3041B | 0x3B663 | 0x3BD84 | |
thrm | A_AUTH | 0x30482 | 0x3B6C9 | 0x3BDEA | |
duty | A_AUTH | 0x307EF | 0x3B95D | 0x3C07E | |
fanconpolicy | A_AUTH | 0x30C0D | 0x3BBB9 | 0x3C2DA | |
fanconmode | A_AUTH | 0x30DF9 | 0x3BD48 | 0x3C469 | |
fantbl | A_AUTH | 0x30F3B | 0x3BE58 | 0x3C579 | |
fanservo | A_AUTH | N/A ? | 0x3C07D | 0x3C79E | |
fanservostat | A_AUTH | N/A ? | 0x3C2E2 | 0x3CA03 | |
fanservosetval | A_AUTH | N/A ? | N/A ? | 0x3CB6B | |
hyst | A_AUTH | 0x305F2 | 0x3B7F0 | 0x3BF11 | |
powupcause | A_AUTH | 0x313EB | 0x3C695 | 0x3CE8E | |
syspowdown | A_AUTH | 0x31460 | 0x3C70A | 0x3CF03 | |
devpm | A_AUTH | 0x316C6 | 0x3C98A | 0x3D183 | |
powerstate | A_AUTH | 0x318CF | 0x3CB93 | 0x3D38C | |
nonfatalerror | A_AUTH | 0x31AC2 | 0x3CDF0 | 0x3D5E9 | |
getrtc | INT | 0x2F82A | 0x3AD68 | 0x3B489 | |
help | A_AUTH | 0x2ED2B | 0x3A280 | 0x3A9A1 | |
meminfo | INT | 0x2EED7 | 0x3A42C | 0x3AB4D | |
rbe | INT | 0x2EF63 | 0x3A4B8 | 0x3ABD9 | |
DISABLEALLERASE | A_AUTH | 0x2F1FC | 0x3A751 | 0x3AE72 | |
task | INT | 0x2F281 | 0x3A7D6 | 0x3AEF7 | |
cleareep | INT | 0x2F460 | 0x3A99E | 0x3B0BF | |
commt | INT | 0x2F499 | 0x3A9D7 | 0x3B0F8 | |
bestat | A_AUTH | 0x2F79B | 0x3ACD9 | 0x3B3FA | |
bringup / BOOT | A_AUTH | 0x2DAC3 | 0x39018 | 0x39739 | |
shutdown / HALT | A_AUTH | 0x2DC1C | 0x39171 | 0x39892 | |
r / R8 r16 / R16 r32 / R32 |
A_AUTH | 0x2DC9B | 0x391F0 | 0x39911 | |
r64 r64d |
A_AUTH | 0x2E7BC | 0x39D11 | 0x3A432 | |
w / W8 w16 / W16 w32 / W32 |
A_AUTH | 0x2E03B | 0x39590 | 0x39CB1 | |
w64 wbe |
A_AUTH | 0x2E6C1 | 0x39C16 | 0x3A337 | |
BOOTENABLE | A_AUTH | 0x2DC7B | 0x391D0 | 0x398F1 | |
EEP | A_AUTH | 0x2E8C2 | 0x39E17 | 0x3A538 | |
PDAREA CSAREA |
A_AUTH | 0x2E9B8 | 0x39F0D | 0x3A62E | |
portset | INT | 0x2EC36 | 0x3A18B | 0x3A8AC | |
extend | A_AUTH | 0x2ECF9 | 0x3A24E | 0x3A96F | |
version | ANY | 0x080D0 | 0x0A0F1 | 0x0A0FF | |
revision | ANY | 0x0812B | 0x0A14C | 0x0A15A | |
setcmdlong / SETCMDLONG | ANY | 0x08251 | 0x0A272 | 0x0A280 | |
VER | ANY | 0x081C3 | 0x0A1E4 | 0x0A1F2 | |
csum | A_AUTH | 0x08356 | 0x0A37B | 0x0A389 | |
AUTH1 AUTH2 |
B_AUTH | 0x08555 | 0x0A5AF | 0x0A5BD | |
AUTHVER | ANY | 0x086FB | 0x0A755 | 0x0A763 | |
errlog / ERRLOG | ANY | 0x311DA | 0x3C484 | 0x3CC7D | |
powersw | A_AUTH | 0x31C87 | 0x3D005 | 0x3D7FE | |
ejectsw | A_AUTH | 0x31CA5 | 0x3D023 | 0x3D81C | |
doorsw | A_AUTH | N/A ? | N/A ? | 0x3D83C | |
buzzduty | INT | 0x31CC5 | 0x3D043 | 0x3D8D7 | |
buzz | INT | 0x31D24 | 0x3D0A2 | 0x3D936 | |
VID | A_AUTH | 0x33F98 | 0x3FC43 | 0x404D8 | |
CID ECID |
A_AUTH | 0x340BF | 0x3FD6A | 0x405FF | |
SPU | A_AUTH | 0x34211 | 0x3FEBC | 0x40751 | |
REV | A_AUTH | 0x342BC | 0x3FF67 | 0x407FC | |
KSV | A_AUTH | 0x34363 | 0x4000E | 0x408A3 | |
MOUNTINFO | A_AUTH | N/A ? | N/A ? | 0x4095B | |
portscan | A_AUTH | 0x3441B | 0x400C6 | 0x40A2A | |
eepcsum | A_AUTH | 0x33F46 | 0x3FBF1 | 0x40486 | |
patchinfo | A_AUTH | 0x346DD | 0x40388 | 0x40CF2 | |
poll | INT | 0x346F3 | 0x4039E | 0x40D08 | |
recv | INT | 0x3470F | 0x403BA | 0x40D24 | |
send | INT | 0x3472B | 0x403D6 | 0x40D40 | |
LS | INT | 0x34747 | 0x403F2 | 0x40D5C | |
hversion | INT | 0x34763 | 0x4040E | 0x40D78 |
Access to Syscon from Linux
Access SysCon ROM without needing ps3dm-utils: http://wiki.gitbrew.org/wikibrew/PS3:HvReverseEngineering#SYSCON
Placeholder for bga patch key generation
34 3A 00 00 00 00 5F 5F 53 43 45 49 53 59 53 31
4:....__SCEISYS1
OR (slim DYN-001)
00 00 00 00 5F 5F 5F 5F 53 43 45 49 53 59 53 31
....____SCEISYS1
- replace 4 dots with soft id in decimal form, xor with 0x140 key and with cipher patcher key and encrypt with master patcher key to obtain cipher master key for that soft id
- replace 4 dots with soft id in decimal form, xor with 0x140 key and with hasher patcher key and encrypt with master patcher key to obtain hasher master key for that soft id
|