The final unmapped a part of the fats PS2 has been dumped.
Greater than 25 years after the fat PlayStation 2 launched, a dev generally known as DiscoStarslayer has managed to tug firmware out of the cussed SPC970 MechaCon chip accountable for authorizing discs and dealing with many of the console’s safety.
In a Bluesky post, the dev credited Libby, the collaborator who discovered an exploit that made the extraction potential. In line with the dump tool’s docs, that exploit instructed the chip that an incoming batch of settings knowledge could be empty, and despatched extra knowledge than it had room for. Earlier than this, in an effort masking some 4 years, there had been struggles with a slower methodology of stripping the chip’s packaging and studying its contents, which produced solely tough dumps.
All the things has been pushed to GitHub alongside 22 firmware pictures masking fats PS2s from the Japan-only SCPH-15000 of 2000 to the 39000-series fashions of 2002. In addition they cowl the Namco System 246 and 256 arcade boards that used the identical chip. These early machines have been among the last unread elements of the PS2 after the 2003 “Dragon” MechaCon was dumped in 2021.
Pulling the chip’s firmware
The SPC970 chip retains its code in masks ROM, which might’t be written or patched, and shops solely calibration and config knowledge in a separate 1KB EEPROM. To get round this, the “spc970-dumper-union” enthusiast group abused how the chip writes to that EEPROM.
The group discovered that by opening a config write session with a block rely of zero, the chip’s inner counter would underflow. Pushing extra knowledge than the seven-block buffer can maintain overflows into RAM that holds the EEPROM write activity. Overwriting that activity’s supply tackle factors it on the chip’s ROM as a substitute, which means that the MechaCon copies 256 bytes of its firmware into the EEPROM. As soon as there, the PS2 can learn it again with a regular command. As soon as repeated round 1,000 occasions, the total 256KB picture sits on a USB stick.
Every of these 1,000 passes rewrites the EEPROM, however each dump shortens its life as a result of it has no put on leveling and a smaller write price range than flash reminiscence. To safeguard in opposition to this, the device backs up the EEPROM earlier than it begins, restoring it phrase by phrase after and checking the end result in opposition to the chip’s power-on checksum routine. There’s nonetheless a danger, although, and Libby’s original dumper warns that it could go away a PS2 “unable to function usually, or require hardware-level restore. Use it totally at your individual danger.”
Constructing on MechaPwn’s work
Dragon MechaCon firmware pictures have been launched again in 2021. MechaPwn, the exploit that makes later PS2s region-free and lets them learn backup discs, was launched a month later. That exploit’s README says that older consoles do not use a Dragon-based MechaCon and subsequently aren’t supported, and that no help is deliberate. That impacts roughly 20 mannequin numbers from the PS2’s first three years between 2000 and 2003. These machines can nonetheless run backups by way of reminiscence card and arduous drive exploits, however could not be unlocked on the chip degree till now as a result of no one may see its code. These dumps make that search potential for the primary time.
The photographs alone do not maintain sufficient info to construct an optical drive emulator, however they might help a modchip that replaces the MechaCon, whereas conserving the drive’s DSP to learn discs. Since PS2 video games weren’t encrypted, nothing new is unlocked right here. However the firmware does expose the code behind Sony’s “MagicGate” encryption for reminiscence playing cards and KELF executables the console boots from disc and reminiscence playing cards. That’ll ultimately feed “full-system low-level emulation,” says contributor uyjulian. PCSX2 and other emulators, which might additionally emulate the weaker GameCube, do not run the chip’s code in any respect: PCSX2 reimplements MechaCon’s instructions in C++ and reads a 1KB NVRAM file and a four-byte model quantity from disk to face in for the actual half. DiscoStarslayer maintains a PCSX2 fork known as Reliquary, aimed on the PS2’s authed paths. They acknowledge in its README that generated stand-in knowledge is not an alternative to {hardware} values when a safety verify inspects console id.
As for the SPC970, the primary job of its dump is to discover a bug that opens up the early consoles. With MechaPwn, folks may learn the Dragon chip’s code and discover a weak spot in how Sony let that chip replace itself. uyjulian says a MechaPwn or TonyHax-style unlock for the SPC970 is among the objectives right here, but it surely will not come as quick. It took researchers solely a month to crack Dragon as a result of Sony constructed that chip to simply accept patches. That gave researchers one thing to interrupt. The SPC970 cannot be up to date in any respect; its code was baked into the chip in 2000 and has by no means modified.
