The NS (Nintendo User Interface Shell) system module is the first module launched from a CTR-NAND title after the FIRM processes are loaded (also see Bootloader). This module is launched by the pm process, with the titleID loaded from NS state(hard-coded TID initialized during applet TID-array initialization). NS first launches ErrDisp, then the menu. On retail the menu TID is loaded from NS state, while on dev/debug the menu TID is loaded from config. On dev-units if the menu TID block doesn’t exist in config, NS will attempt to launch the alternate menu instead. The TID of the launched menu is then written to ACTIVEMENUTID. NS uses pm:app to launch titles.
NS will not trigger the fatal-error screen when launching the regular/alternate menu fails.
Like home menu NS is constantly running while the system is in 3DS-mode. When attempting to return to home-menu when the home-menu process isn’t running(like when the process terminated/crashed), NS will trigger a fatal error.
When launching the regular menu fails, NS will then attempt to launch the alternate menu. This title could be used as a recovery process, however it’s normally not used after the factory.
At the factory for all 3DS systems, Test Menu is installed with this TID. On retail this title is eventually deleted during Factory Setup.
Auto-boot #
After loading FIRM params and prior to launching ErrDisp/Home Menu, NS handles auto-booting titles. The same code called by APT:Reboot is used for launching FIRM here. When the UPDATEFLAG is set, NS will launch SAFE_MODE_FIRM with the application titleID set to the System Updater titleID for this region. When the UPDATEFLAG is not set, NS can auto-boot the following titles as well if 0x1FF80016 bit0 is set.
When bit1 and bit2 are value zero in 0x1FF80016, NS will launch the title specified by the FIRM parameters if the title-info is set. This FIRM launch is done after launching ErrDisp and Home Menu. Otherwise when 0x1FF80016 is value 2 and the output u8 from PTMSYSM command 0x08140000 is value 0, NS will boot the title specified from the TWL TLNC block from FIRMparams+0x300. This is the same TLNC block which DSi titles wrote to RAM+0x300 for launching other titles via the launcher title. When handling the TLNC block, NS will boot the 3DS System Settings title when the TLNC titleID is the DSi System Settings titleID(the region field in the TLNC TID is not checked/used). When the TLNC titleID is not System Settings, NS will convert the input DSi titleID-high to the 3DS TWL titleID-high(tidhigh = (TLNCtidhigh & 0x7FFF) | 0x48000), then launch TWL_FIRM to run the title. NS does not support launching from gamecard via TLNC.
NS Workaround #
A “ns_workaround” was added in NS to workaround the flaw added with 5.0.0-11. When NS is loading before launching any ARM11 processes and certain Configuration Memory fields are set, NS will launch AM then use command AM:InstallNATIVEFIRM. NS will then execute the code called by APT:StartNewestHomeMenu, the code related to APT:PrepareToStartNewestHomeMenu is not executed here.
NS will only execute this code-path when 0x1FF80016 is value zero, when KERNEL_VERSIONMAJOR is value 2, and when KERNEL_VERSIONMINOR is less than 35. Therefore, this code-path is only executed when the running NATIVE_FIRM version is prior to 5.0.0-11.
NS Service “ns:s” #
The maximum sessions that can be used with this service is two, therefore only two processes can use this service at the same time.
NS Power Service “ns:p” #
Command Header | Description |
---|---|
0x00010040 | RebootSystem |
0x00020000 | ShutdownAsync |
This was added with 3.0.0-5. The PTM sysmodule connects to this service, and syncs whenever ptm:s GetShellState() changes.
NS Service “ns:c” #
Command Header | Description |
---|---|
0x00010100 | LockSpecialContent |
0x00020100 | UnlockSpecialContent |
This was added with 5.0.0-11. It is used by the Instruction Manual applet, and is likely related to triggering SD/Game Card removal errors when ejecting the media the manual is stored on.
APT Services #
These “APT:U” and “APT:S” NS services can handle launching titles/“applets”, these services handle signaling for home/power button as well. Only one session for either APT service can be open at a time, normally processes close the service handle immediately once finished using the service. The commands for APT:U and APT:S are exactly the same, however certain commands are only accessible with APT:S(NS module will call svcBreak when the command isn’t accessible).
Applets returning to home-menu first use commands APT:PrepareToJumpToHomeMenu and APT:JumpToHomeMenu, followed by these commands to launch home-menu: APT:PrepareToStartSystemApplet and APT:StartSystemApplet. APT:PrepareToStartSystemApplet and APT:StartSystemApplet are also used for launching the Internet Browser, the camera applet, etc.
Processes launch applications via home-menu, not directly with APT:PrepareToStartApplication and APT:StartApplication. Regular applications can’t directly launch applications since APT:StartApplication launches the process without terminating the currently running application.
APT:PrepareToDoApplicationJump and APT:DoApplicationJump are used by applications, for launching native/<non-NATIVE_FIRM> applications. These commands notify Home Menu that title launching needs done, Home Menu does the actual title launching via NS commands.
AppletAttr #
Bits | Description |
---|---|
0-2 | AppletPos |
3 | Manually Acquire/Release GPU Rights |
4 | Manually Acquire/Release DSP Rights |
5 | ? |
DisplayBufferMode #
Value | Description |
---|---|
0 | FORMAT_R8G8B8A8 |
1 | FORMAT_R8G8B8 |
2 | FORMAT_R5G6B5 |
3 | FORMAT_R5G5B5A1 |
4 | FORMAT_R4G4B4A4 |
0xFFFFFFFF | FORMAT_UNIMPORTABLE |
This is the same mapping as used for the GPU framebuffer color formats.
AppletPos #
Value | Description |
---|---|
-1 | POS_NONE |
0 | POS_APP |
1 | POS_APPLIB |
2 | POS_SYS |
3 | POS_SYSLIB |
4 | POS_RESIDENT |
QueryReply #
Value | Description |
---|---|
0 | REPLY_REJECT |
1 | REPLY_ACCEPT |
2 | REPLY_LATER |
Notification #
Value | Description |
---|---|
0 | NOTIFICATION_NONE |
1 | NOTIFICATION_HOME_BUTTON_1 |
2 | NOTIFICATION_HOME_BUTTON_2 |
3 | NOTIFICATION_SLEEP_QUERY |
4 | NOTIFICATION_SLEEP_CANCELED_BY_OPEN |
5 | NOTIFICATION_SLEEP_ACCEPTED |
6 | NOTIFICATION_SLEEP_AWAKE |
7 | NOTIFICATION_SHUTDOWN |
8 | NOTIFICATION_POWER_BUTTON_CLICK |
9 | NOTIFICATION_POWER_BUTTON_CLEAR |
10 | NOTIFICATION_TRY_SLEEP |
11 | NOTIFICATION_ORDER_TO_CLOSE |
Command #
Value | Description |
---|---|
0 | COMMAND_NONE |
1 | COMMAND_WAKEUP |
2 | COMMAND_REQUEST |
3 | COMMAND_RESPONSE |
4 | COMMAND_EXIT |
5 | COMMAND_MESSAGE |
6 | COMMAND_HOME_BUTTON_SINGLE |
7 | COMMAND_HOME_BUTTON_DOUBLE |
8 | COMMAND_DSP_SLEEP |
9 | COMMAND_DSP_WAKEUP |
10 | COMMAND_WAKEUP_BY_EXIT |
11 | COMMAND_WAKEUP_BY_PAUSE |
12 | COMMAND_WAKEUP_BY_CANCEL |
13 | COMMAND_WAKEUP_BY_CANCELALL |
14 | COMMAND_WAKEUP_BY_POWER_BUTTON_CLICK |
15 | COMMAND_WAKEUP_TO_JUMP_HOME |
16 | COMMAND_REQUEST_FOR_SYS_APPLET |
17 | COMMAND_WAKEUP_TO_LAUNCH_APPLICATION |
0x41 | Unknown. Received by Home Menu during boot when the Home Menu process doesn’t terminate properly(svcExitProcess/crash). |
AppletPreparationState #
Value | Description |
---|---|
0 | NO_PREPARATION |
1 | PREPARED_TO_LAUNCH_APP |
2 | PREPARED_TO_CLOSE_APP |
3 | PREPARED_TO_FORCE_TO_CLOSE_APP |
4 | PREPARED_TO_PRELOAD_APPLIB |
5 | PREPARED_TO_LAUNCH_APPLIB |
6 | PREPARED_TO_CLOSE_APPLIB |
7 | PREPARED_TO_LAUNCH_SYS |
8 | PREPARED_TO_CLOSE_SYS |
9 | PREPARED_TO_PRELOAD_SYSLIB |
10 | PREPARED_TO_LAUNCH_SYSLIB |
11 | PREPARED_TO_CLOSE_SYSLIB |
12 | PREPARED_TO_LAUNCH_RESIDENT |
13 | PREPARED_TO_LEAVE_RESIDENT |
14 | PREPARED_TO_DO_HOMEMENU |
15 | PREPARED_TO_LEAVE_HOMEMENU |
16 | PREPARED_TO_START_RESIDENT |
17 | PREPARED_TO_DO_APP_JUMP |
18 | PREPARED_TO_FORCE_TO_CLOSE_SYS |
19 | PREPARED_TO_LAUNCH_OTHER_SYS |
20 | PREPARED_TO_JUMP_TO_APP |
StartupArgumentType #
Value | Description |
---|---|
0 | STARTUP_ARGUMENT_TYPE_OTHER_APP |
1 | STARTUP_ARGUMENT_TYPE_RESTART |
2 | STARTUP_ARGUMENT_TYPE_OTHER_MEDIA |
CaptureBufferInfo #
Offset | Size | Description |
---|---|---|
0x0 | 0x4 | u32, Size |
0x4 | 0x1 | u8, 3D (0 = not 3D, 1 = 3D) |
0x5 | 0x3 | Reserved |
0x8 | 0x4 | Main Screen Left Offset |
0xC | 0x4 | Main Screen Right Offset |
0x10 | 0x4 | Main Screen DisplayBufferMode |
0x14 | 0x4 | Sub Screen Left Offset |
0x18 | 0x4 | Sub Screen Right Offset |
0x1C | 0x4 | Sub Screen DisplayBufferMode |
WirelessRebootInfo #
Offset | Size | Description |
---|---|---|
0x0 | 0x6 | Host MAC address. |
0x6 | 0x9 | WirelessRebootPassphrase |
0xF | 0x1 | Uninitialized |
This is setup by the dlplay system-application, before launching the DLP-child which can then use APT:GetWirelessRebootInfo. The MAC address and passphrase is used for connecting to the host by the DLP-child. See also here.
“APT:A” Service #
This was added with 7.0.0-X. Official apps built with the CTRSDK for system-version >= 7.0.0-X normally use the “APT:A” service instead of “APT:U”. Those processes also have “APT:A” instead of “APT:U” in the service-access-control. Unlike APT:U, APT:A can call APT:GetAppletInfo with applet ID 0x300.
Applets #
NS module does not verify that the input appID for the APT service cmds are correct for that type of command. For example, a process-launch of a SystemApplet via LibraryApplet commands works fine(minus the launched-process side of APT probably).
System Applets #
On Old3DS there could only be one applet here(Home Menu, Internet Browser, Friend-List, etc) with programID-high 00040030 running at a time. On Old3DS when directly launching one of these 00040030 applets with Home Menu, the Home Menu process will terminate once the process is launched. On Old3DS when returning to Home Menu from that launched process, the Home Menu process is launched again.
On New3DS the Home Menu process is still running/in-memory, while another system-applet is running. On New3DS it appears that the Home Menu process is terminated+relaunched, when another system-applet terminated without exiting with APT properly.
Library Applets #
Library applets can be launched by applications and regular applets. These library applets render to the screen(s) when running, etc. For example, this includes swkbd for text input. See the below appIDs in the 0x2XX range, the actual appID used is 0x4XX however.
Input data can be sent to the library applet via the NS parameter buffer, and/or with shared-memory with a shared-mem handle sent to the library applet. Output data from the library applet can be received by APT:ReceiveParameter, the library applet can also use the specified shared-mem for output too.
AppIDs #
AppID | Description |
---|---|
0x101 | Home Menu (menu) |
0x103 | Alternate Menu |
0x110 | Camera applet ( CtrApp) |
0x112 | Friends List applet ( friend) |
0x113 | Game Notes applet (Cherry) |
0x114 | Internet Browser (spider/SKATER) |
0x115 | Instruction Manual applet |
0x116 | Notifications applet (newslist) |
0x117 | Miiverse applet (olv) |
0x118 | Miiverse posting applet (solv3) |
0x119 | Amiibo settings (cabinet) |
0x201 | Software Keyboard (swkbd) (?) |
0x202 | Mii Selector (appletEd) (?) |
0x204 | Photo Selector (PNOTE_AP) (?) |
0x205 | Sound Selector (SNOTE_AP) (?) |
0x206 | Error Display ( error) (?) |
0x207 | eShop applet ( mint) (?) |
0x208 | Circle Pad Pro Calibrator ( extrapad) (?) |
0x209 | Notepad (memolib) (?) |
0x300 | Application |
0x301 | eShop (tiger) |
0x401 | Software Keyboard (swkbd) |
0x402 | Mii Selector (appletEd) |
0x404 | Photo Selector (PNOTE_AP) |
0x405 | Sound Selector (SNOTE_AP) |
0x406 | Error Display (error) |
0x407 | eShop applet (mint) |
0x408 | Circle Pad Pro Calibrator ( extrapad) |
0x409 | Notepad (memolib) |
0xF10 | ProgramID: 0004003000008900. |
0xF11 | ProgramID: 000400000FFFFD00. |
0xF12 | ProgramID: 000400000FFFFC00. |
0xF13 | ProgramID: 000400000FFFFB00. |
0xF14 | ProgramID: 000400000FFFF900. |
0xF15 | ProgramID: 000400000FFFF800. |
0xF16 | ProgramID: 000400000FFFF700. |
0xF17 | ProgramID: 000400000FFFF600. |
0xF18 | ProgramID: 000400000FFFF500. |
These AppIDs are all for NAND titles, except for 0x300. AppIDs in the 0x1XX range are applets(programID-high 00040030), and the AppIDs in the 0x2XX range are “system libraries”(programID-high 00040030). The 0xFXX AppID range is for development NAND applications, these are not available for retail.
Note that at some point the total AppID entry count was changed from 28 to 27.