With certain 3DS nandimages, the following NCCH can be recovered from NAND(in some cases these are somewhat corrupted). In some cases, only 000400000F980000 is left, in other cases the NCCH headers for all of these are overwritten. All of these use the retail NCCH secure-crypto mode, the NCCH accessdesc uses the retail pubk too.
Note that Nandrw/sys/updater.log, Twln/sys/log/inspect.log, and Twln/sys/log/product.log gets written during Factory Setup. CTRAging probably does the product.log writing.
TID-high | TID-low | Description |
---|---|---|
00040000 | 0F980000 | CTRAging ("Test Program") |
00040001 | 00000002 | NATIVE_FIRM |
00040001 | 00000102 | TWL_FIRM |
00040001 | 00000202 | AGB_FIRM |
00040001 | 00001902 | dmnt (Debugger sysmodule, see here) |
00040001 | 00001B02 | gpio sysmodule |
00040001 | 00001D02 | hid sysmodule |
00040001 | 00001E02 | i2c sysmodule |
00040001 | 00001F02 | mcu sysmodule |
00040001 | 00002102 | pdn sysmodule |
00040001 | 00002302 | |
00040001 | 00002702 | csnd sysmodule |
00040001 | 00002802 | dlp sysmodule |
00040001 | 00002A02 | mp sysmodule |
00040001 | 00002B02 | ndm sysmodule |
00040001 | 00002C02 | nim sysmodule |
00040001 | 00002D02 | |
00040001 | 00003102 | ps module |
00040001 | 00003202 | friends sysmodule |
00040001 | 00003302 | ir sysmodule |
00040001 | 00003402 | boss sysmodule |
00040001 | 00008002 | NS |
00040030 | 00008102 | TestMenu |
00040001 | 00008A02 | DevErrDi |