Editing Non Volatile Storage
Jump to navigation
Jump to search
The edit can be undone. Please check the comparison below to verify that this is what you want to do, and then publish the changes below to finish undoing the edit.
Latest revision | Your text | ||
Line 25: | Line 25: | ||
! Bank # !! Block # !! Start Offset in /dev/sflash0s0x34 !! Start Offset in Sflash !! Size !! Notes | ! Bank # !! Block # !! Start Offset in /dev/sflash0s0x34 !! Start Offset in Sflash !! Size !! Notes | ||
|- | |- | ||
| 0 || 0 || 0 || 0x1C4000 || 0x3000 || | | 0 || 0 || 0 || 0x1C4000 || 0x3000 || does not match, probably one (sflash or nvs, likely sflash) updates data | ||
|- | |- | ||
| 0 || 1 || 0x3000 || 0x1C7000 || 0x1000 || | | 0 || 1 || 0x3000 || 0x1C7000 || 0x1000 || match | ||
|- | |- | ||
| 0 || 2 || 0x4000 || 0x1C8000 || 0x800 || | | 0 || 2 || 0x4000 || 0x1C8000 || 0x800 || match, console data region aka NvsFactoryArea | ||
|- | |- | ||
| 0 || 3 || 0x4800 || 0x1C8800 || 0x800 || | | 0 || 3 || 0x4800 || 0x1C8800 || 0x800 || match, all ffs? | ||
|- | |- | ||
| 0 || 4 || 0x5000 || 0x1C9000 || 0x3000 || | | 0 || 4 || 0x5000 || 0x1C9000 || 0x3000 || match, tokens and flags region (backuped at bank 1 block 0) | ||
|- | |- | ||
| 1 || 0 || 0x8000 || 0x1CC000 || 0x3000 || | | 1 || 0 || 0x8000 || 0x1CC000 || 0x3000 || match, tokens and flags region (backup of bank 0 block 4) | ||
|- | |- | ||
| 1 || 1 || 0xB000 || 0x1CF000 || 0x1000 || | | 1 || 1 || 0xB000 || 0x1CF000 || 0x1000 || match | ||
|} | |} | ||
Line 44: | Line 44: | ||
{| class="wikitable sortable" | {| class="wikitable sortable" | ||
|- | |- | ||
! Bank # !! Block # !! Start Offset in /dev/ | ! Bank # !! Block # !! Start Offset in /dev/sflash0s0x34 !! Start Offset in Sflash !! Size !! Notes | ||
|- | |- | ||
| 0 || 0 || 0 || 0x1C4000 || 0x8 || | | 0 || 0 || 0 || 0x1C4000 || 0x8 || Board ID (e.g 04 01 01 01 01 01 04 01) | ||
|- | |- | ||
| 0 || 0 || | | 0 || 0 || 0x20 || 0x1C4020 || 0x6 || Unknown (e.g 02 BC 60 A7 28 83 66) | ||
|- | |- | ||
| 0 || 0 || 0x4E || 0x1C404E || 0x2 || Unknown (e.g 25 16) | | 0 || 0 || 0x4E || 0x1C404E || 0x2 || Unknown (e.g 25 16) | ||
Line 192: | Line 190: | ||
| 0 || 0 || 0x2000 || 0x1C6000 || 0x8 || | | 0 || 0 || 0x2000 || 0x1C6000 || 0x8 || | ||
|- | |- | ||
| 0 || 1 || | | 0 || 1 || 0x3000 || 0x1C7000 || 0x40 || | ||
|- | |- | ||
| 0 || | | 0 || 1 || 0x3040 || 0x1C7040 || 0x10 || trsw_attach (e.g 1F FF 00 00 07 FF FF 07 FF FF 00 00 00 00 00 00) | ||
|- | |- | ||
| 0 || | | 0 || 1 || 0x30A0 || 0x1C70A0 || 0x2 || get_icc_max (e.g 20 9A) | ||
|- | |- | ||
| 0 || | | 0 || 1 || 0x30B0 || 0x1C70B0 || 0x1 || ???? | ||
|- | |- | ||
| 0 || | | 0 || 1 || 0x30B1 || 0x1C70B1 || 0x1 || ???? | ||
|- | |- | ||
| 0 || | | 0 || 1 || 0x30B2 || 0x1C70B2 || 0x1 || ???? | ||
|- | |- | ||
| 0 || 2 || | | 0 || 2 || 0x4000 || 0x1C8000 || 0xE || KibanID (e.g 33001D00836391) | ||
|- | |- | ||
| 0 || 2 || | | 0 || 2 || 0x4010 || 0x1C8010 || 0x10 || SOCUID (e.g DA 24 7A 4C FB AB D3 CA D0 95 53 7C 7B F1 45 A9) | ||
|- | |- | ||
| 0 || 2 || | | 0 || 2 || 0x4020 || 0x1C8020 || 0x10 || ViopData | ||
|- | |- | ||
| 0 || 2 || | | 0 || 2 || 0x4030 || 0x1C8030 || 0x11 || Used in FW 5.05. Unique identifier of console, hw_info (e.g 00TS4DB00K2180050) | ||
|- | |- | ||
| 0 || 2 || | | 0 || 2 || 0x4041 || 0x1C8041 || 0x1F || Used in later firmwares. Unique identifier of console, hw_model (e.g DUT-DBW00JK-S0ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ) aka Product Name | ||
|- | |- | ||
| 0 || | | 0 || 2 || 0x4060 || 0x1C8060 || 0x38 || Unknown | ||
|- | |- | ||
| 0 || | | 0 || 2 || 0x4098 || 0x1C8098 || 0x14 || Unknown, some hash maybe (0x14 bytes size) | ||
|- | |- | ||
| 0 || | | 0 || 2 || 0x40AC || 0x1C80AC || 0x4 || Unknown (e.g 00 00 00 C2) | ||
|- | |- | ||
| 0 || | | 0 || 2 || 0x40B0 || 0x1C80B0 || 0x6 || Unknown (e.g 01 01 01 01 06 06 06 06) | ||
|- | |- | ||
| 0 || | | 0 || 2 || 0x40C0 || 0x1C80C0 || 0xD || (e.g 0000027452252) Product Code (first 5 zeroes are Product Code Branch Number) | ||
|- | |- | ||
| 0 || | | 0 || 2 || 0x4100 || 0x1C8100 || 0x20 || (e.g 00 02 F4 C1 64 E6 83 41 0C D0 8D 91 38 56 50 AE 15 3E 60 9E 70 16 17 1A 1C 18 26 25 1B 1B F5 F7) | ||
|- | |- | ||
| 0 || | | 0 || 2 || 0x47D0 || 0x1C87D0 || 0x10 || Manufacturing Process Flags (01 enabled, 00 disabled) (e.g 01 01 01 01 01 01 01 01 01 00 00 00 00 00 00 00) | ||
|- | |- | ||
| 0 || | | 0 || 2 || 0x47F0 || 0x1C87F0 || 0x1 || (e.g 01) | ||
|- | |- | ||
| 0 || 4 || | | 0 || 4 || 0x5000 || 0x1C9000 || 0x20 || dipswitch flags, see below | ||
|- | |- | ||
| 0 || 4 || | | 0 || 4 || 0x5000 || 0x1C9000 || 0x1 || SCE_REGMGR_ENT_KEY_DEVENV_TOOL_boot_param (FE Development Mode) (FB Assist Mode) (FF Release Mode) | ||
|- | |- | ||
| 0 || 4 || | | 0 || 4 || 0x5003 || 0x1C9003 || 0x1 || Memory Budget (0xFF Normal, 0xFE Large) | ||
|- | |- | ||
| 0 || 4 || | | 0 || 4 || 0x5005 || 0x1C9005 || 0x1 || Slow HDD Mode (0xFE ON) (0xFF OFF) | ||
|- | |- | ||
| 0 || 4 || | | 0 || 4 || 0x500B || 0x1C900B || 0x1 || Unknown (0x87 on prototype DevKit) | ||
|- | |- | ||
| 0 || 4 || | | 0 || 4 || 0x5010 || 0x1C9010 || 0x1 || vsh_4K Mode (0xFE ON) (0xFF OFF) | ||
|- | |- | ||
| 0 || 4 || | | 0 || 4 || 0x501F || 0x1C901F || 0x1 || ??? (e.g 7F) | ||
|- | |- | ||
| 0 || 4 || | | 0 || 4 || 0x5020 || 0x1C9020 || 0x1 || init_safe_mode flag (e.g F1) | ||
|- | |- | ||
| 0 || 4 || | | 0 || 4 || 0x5021 || 0x1C9021 || 0x1 || sysctl_machdep_cavern_dvt1_init_update | ||
|- | |- | ||
| 0 || 4 || | | 0 || 4 || 0x5030 || 0x1C9030 || 0x1 || trsw_probe (01 for [ WLAN mode : FT ], else [ WLAN mode : OFF ]) also bt_sdio_probe and trs_probe | ||
|- | |- | ||
| 0 || 4 || | | 0 || 4 || 0x5038 || 0x1C9038 || 0x1 || gigabyte ethernet related (gbe) | ||
|- | |- | ||
| 0 || 4 || | | 0 || 4 || 0x5050 || 0x1C9050 || 0x1 || is_extra_clock_available_rtc_status | ||
|- | |- | ||
| 0 || 4 || | | 0 || 4 || 0x5060 || 0x1C9060 || 0x4 || SMI SDK version (e.g 00 00 50 02 (2.50)) (minimal version) | ||
|- | |- | ||
| 0 || 4 || | | 0 || 4 || 0x5068 || 0x1C9068 || 0x4 || Current SDK version 2 (e.g 00 00 05 05 (5.05)) | ||
|- | |- | ||
| 0 || 4 || | | 0 || 4 || 0x5070 || 0x1C9070 || 0x4 || manu_mode related (sdk version?) | ||
|- | |- | ||
| 0 || 4 || | | 0 || 4 || 0x5074 || 0x1C9074 || 0x4 || Unknown (e.g. 84 72 4E 57) | ||
|- | |- | ||
| 0 || 4 || | | 0 || 4 || 0x507C || 0x1C907C || 0x4 || manu_mode related (sdk version?) | ||
|- | |- | ||
| 0 || 4 || | | 0 || 4 || 0x5080 || 0x1C9080 || varies (0x68-0x6C) || acf token <- checked by sceSblDevActVerifyCheckExpire | ||
|- | |- | ||
| 0 || 4 || | | 0 || 4 || 0x5100 || 0x1C9100 || 0x100 || sce_cam_error_put | ||
|- | |- | ||
| 0 || 4 || | | 0 || 4 || 0x5200 || 0x1C9200 || varies (0x40-0x60) || scrambled/obfuscated eap hdd key <- checked by g_crypt_deferred_init, also checked by read_idstorage | ||
|- | |- | ||
| 0 || 4 || | | 0 || 4 || 0x5300 || 0x1C9300 || 0x30 || sam/liverpool flags (fun stuff here) (SEE BELOW) | ||
|- | |- | ||
| 0 || 4 || | | 0 || 4 || 0x5301 || 0x1C9301 || 1 || unknown (01 = enabled) (only available for prototype) | ||
|- | |- | ||
| 0 || 4 || | | 0 || 4 || 0x5310 || 0x1C9310 || 1 || sam_memtest (01 = enabled) | ||
|- | |- | ||
| 0 || 4 || | | 0 || 4 || 0x5311 || 0x1C9311 || 1 || unknown (01 = enabled) (only available for prototype) | ||
|- | |- | ||
| 0 || 4 || | | 0 || 4 || 0x5312 || 0x1C9312 || 1 || sam_rngtest (01 = enabled) | ||
|- | |- | ||
| 0 || 4 || | | 0 || 4 || 0x531F || 0x1C931F || 1 || extra UART. 0xFF - extra UART disabled, 0x00 - extra UART enabled when ???, 0x01 - extra UART enabled | ||
|- | |- | ||
| 0 || 4 || | | 0 || 4 || 0x5320 || 0x1C9320 || 1 || lvp_configure_get_gddr5clk (0x14 = 500Mhz) (whatever value is here is multiplied by 0x19 to get final value) (0xED max value, 5925Mhz) (500Mhz will semi-brick the console with DCT errors, however for some stupid reason BwE's lets you pick ranges from 400 to 2250MHz) | ||
|- | |- | ||
| 0 || 4 || | | 0 || 4 || 0x5322 || 0x1C9322 || 1 || lvp_configure_tccds | ||
|- | |- | ||
| 0 || 4 || | | 0 || 4 || 0x5323 || 0x1C9323 || 1 || sam_boot_flags (anything other than FF for enabled) | ||
|- | |- | ||
| 0 || 4 || | | 0 || 4 || 0x5329 || 0x1C9329 || 1 || related to lvp_config (likely gddr5DebugFlag, 1->Read DBI disabled, 2->Write DBI disabled, 4->ABI disabled, 8->Force auto precharge enabled, 0x10 -> Bank swap disabled, 0x20-> Bank swizzle mode disabled, 0x3F -> Everything set) | ||
|- | |- | ||
| 0 || 4 || | | 0 || 4 || 0x5400 || 0x1C9400 || 0x800 || dev/qaf/utkn region (tokens, signatures here) (SEE BELOW) | ||
|- | |- | ||
| 0 || 4 || | | 0 || 4 || 0x5400 || 0x1C9400 || 0x210 || token??? | ||
|- | |- | ||
| 0 || 4 || | | 0 || 4 || 0x5650 || 0x1C9650 || 0x290 || qafutkn_ioctl? | ||
|- | |- | ||
| 0 || 4 || | | 0 || 4 || 0x5900 || 0x1C9900 || 0x100 || acf RSA signature | ||
|- | |- | ||
| 0 || 4 || | | 0 || 4 || 0x5A00 || 0x1C9A00 || 0x190 || token??? | ||
|- | |- | ||
| 0 || 4 || | | 0 || 4 || 0x5C00 || 0x1C9C00 || 0x3C || HDD Info (e.g "GHTSH ST4501019A6E08 613081DJ0124FZD129SN" for an HGST) | ||
|- | |- | ||
| 0 || 4 || | | 0 || 4 || 0x5C3C || 0x1C9C3C || 0x04 || Unknown (e.g 05 C6 0A 00) | ||
|- | |- | ||
| 0 || 4 || | | 0 || 4 || 0x5C40 || 0x1C9C40 || 0x130 || setPupExpirationStatus | ||
|- | |- | ||
| 0 || 4 || | | 0 || 4 || 0x6000 || 0x1CA000 || 0x300 || wrappNvsRead, or regMgrNvsRead | ||
|- | |- | ||
| 0 || 4 || | | 0 || 4 || 0x600E || 0x1CA00E || 0x1 || Unknown (Not Regions) | ||
|- | |- | ||
| 0 || 4 || | | 0 || 4 || 0x6040 || 0x1CA040 || 0x1 || Circle Button Behaviour (0x01 is Circle Go Back) (0x00 is Circle Accept) | ||
|- | |- | ||
| 0 || 4 || | | 0 || 4 || 0x6300 || 0x1CA300 || 0x300 || wrappNvsRead, or regMgrNvsRead | ||
|- | |- | ||
| 0 || 4 || | | 0 || 4 || 0x6600 || 0x1CA600 || 0x20 || Modes (See Below) | ||
|- | |- | ||
| 0 || 4 || | | 0 || 4 || 0x6600 || 0x1CA600 || 0x1 || SCE_REGMGR_ENT_KEY_SYSTEM_SPECIFIC_idu_mode (0x01 Enabled 0x00 or 0xFF Disabled) | ||
|- | |- | ||
| 0 || 4 || | | 0 || 4 || 0x6601 || 0x1CA601 || 0X1 || SCE_REGMGR_ENT_KEY_SYSTEM_update_mode (0xFF or 0x00 disabled) (0x10, 0x20, 0x30, 0x31, 0x32, 0x50 enabled) | ||
|- | |- | ||
| 0 || 4 || | | 0 || 4 || 0x6602 || 0x1CA602 || 0x1 || SCE_REGMGR_ENT_KEY_SYSTEM_SPECIFIC_show_mode (0x01 Enabled 0x00 Disabled) (Testkit Only!) | ||
|- | |- | ||
| 0 || 4 || | | 0 || 4 || 0x6603 || 0x1CA603 || 0x1 || SCE_REGMGR_ENT_KEY_REGISTRY_recover | ||
|- | |- | ||
| 0 || 4 || | | 0 || 4 || 0x6604 || 0x1CA604 || 0x4 || SCE_REGMGR_ENT_KEY_SYSTEM_soft_version (deprecated) (devkit only?) | ||
|- | |- | ||
| 0 || 4 || | | 0 || 4 || 0x6609 || 0x1CA609 || 0x1 || SCE_REGMGR_ENT_KEY_SYSTEM_SPECIFIC_arcade_mode | ||
|- | |- | ||
| | | 0 || 4 || 0x7C00 || 0x1CBC00 || 0x20 || manufacturing mode (all zeroes for enabled, all FFs for disabled) | ||
|- | |- | ||
| | | 0 || 4 || 0x7C40 || 0x1CBC40 || 0x20 || | ||
|- | |- | ||
| | | 0 || 4 || 0x7CC0 || 0x1CBCC0 || 0x20 || srtc_modevent | ||
|- | |- | ||
| ? || ? || ??? || 0x1CF000 || 1 || ?? FF disabled | | ? || ? || ??? || 0x1CF000 || 1 || ?? FF disabled 00 enabled | ||
|} | |} |