LegacyJB is a PS5 payload that provides a jailbreak service for supported applications. This repository includes the payload source and the libraries required to build it with CMake.
.
|-- CMakeLists.txt
|-- include/
|-- legacyjb/
|-- libhijacker/
|-- libNidResolver/
`-- libSelfDecryptor/
The build produces:
bin/LegacyJB.elf
bin/LegacyJB.bin
- Linux or WSL on Windows
- CMake 3.20 or newer
- Ninja or GNU Make
- PS5 Payload SDK configured through
PS5_PAYLOAD_SDK - The SDK CMake toolchain, normally located at
$PS5_PAYLOAD_SDK/toolchain/prospero.cmake
The project is configured and tested with PS5 Payload SDK v0.43.
Set the SDK path:
export PS5_PAYLOAD_SDK=/opt/ps5-payload-sdkConfigure the project with Ninja:
cmake -S . -B build -G Ninja \
-DCMAKE_BUILD_TYPE=Debug \
-DCMAKE_TOOLCHAIN_FILE="$PS5_PAYLOAD_SDK/toolchain/prospero.cmake" \
-DV_FW=0x320To use GNU Make instead:
cmake -S . -B build -G "Unix Makefiles" \
-DCMAKE_BUILD_TYPE=Debug \
-DCMAKE_TOOLCHAIN_FILE="$PS5_PAYLOAD_SDK/toolchain/prospero.cmake" \
-DV_FW=0x320Build LegacyJB:
cmake --build build --target legacyjb -j"$(nproc)"The output files are written to bin/.
Configure with Ninja:
wsl -e bash -lc "cd '/mnt/c/Projects/LegacyJB' && export PS5_PAYLOAD_SDK=/opt/ps5-payload-sdk && cmake -S . -B build -G Ninja -DCMAKE_BUILD_TYPE=Debug -DCMAKE_TOOLCHAIN_FILE=`$PS5_PAYLOAD_SDK/toolchain/prospero.cmake -DV_FW=0x320"If Ninja is not installed in WSL, use GNU Make:
wsl -e bash -lc "cd '/mnt/c/Projects/LegacyJB' && export PS5_PAYLOAD_SDK=/opt/ps5-payload-sdk && cmake -S . -B build -G 'Unix Makefiles' -DCMAKE_BUILD_TYPE=Debug -DCMAKE_TOOLCHAIN_FILE=`$PS5_PAYLOAD_SDK/toolchain/prospero.cmake -DV_FW=0x320"Then build the payload:
wsl -e bash -lc "cd '/mnt/c/Projects/LegacyJB' && cmake --build build --target legacyjb -j`$(nproc)"V_FW defines the PS5_FW_VERSION compatibility macro during compilation. The default value is 0x1360.
Kernel addresses are resolved at runtime by PS5 Payload SDK v0.43. SELF decryption includes pager-table mappings through firmware 13.60, so one build can run across the firmware versions recognized by the SDK.
Examples:
-DV_FW=0x320
-DV_FW=0x900
-DV_FW=0x1360Use a value supported by the SDK and by the offsets available for your environment.
Send bin/LegacyJB.elf or bin/LegacyJB.bin using your preferred PS5 payload loader.
When started, the payload:
- opens a TCP jailbreak service on port
9028; - monitors file-based requests from supported applications;
- writes logs to
/user/data/legacy_jb.log; - rotates the previous log to
/user/data/legacy_jb.prev.log; - enables Homebrew Store and Itemzflow compatibility.
The workflow at .github/workflows/build.yml builds the legacyjb target on GitHub.
By default, it downloads PS5 Payload SDK v0.43 from:
https://github.com/ps5-payload-dev/sdk/releases/download/v0.43/ps5-payload-sdk.zip
To use another release, create a repository variable named PS5_PAYLOAD_SDK_URL containing the desired SDK ZIP URL.
You can select the firmware in either of these ways:
- enter
firmwarewhen manually running the workflow; - create a repository variable named
PS5_FW_VERSION.
After a successful build, the workflow publishes an artifact named LegacyJB containing LegacyJB.elf and LegacyJB.bin.
Set the variable before configuring CMake:
export PS5_PAYLOAD_SDK=/opt/ps5-payload-sdkVerify that the SDK was extracted to the expected directory:
ls "$PS5_PAYLOAD_SDK/toolchain/prospero.cmake"Force a clean rebuild:
cmake --build build --target legacyjb --clean-first -j"$(nproc)"