Skip to content

v0.3.12

Latest

Choose a tag to compare

@github-actions github-actions released this 23 Sep 17:25
· 9 commits to main since this release

What changed

See CHANGELOG.md for the curated entry for this version,
including which items were verified on hardware and which are still device-gated. The
auto-generated commit list follows below.

Installing

Download cinder-installer-windows-x64.exe, connect the Walkman in USB mass-storage
mode, and run it. Double-clicking opens a window; running it from a terminal gives the
same thing as text.

It does three things:

Install Choose the optional components, stage them, flash.
Update Reads the choices already on the player and keeps them, so a new build never silently resets a customised install.
Uninstall Restores Sony's launch config from the backup the install made and removes Cinder's binaries. Your music, playlists and settings are untouched.

It reads what is on the player out of the device's own install log before offering
anything — whether Cinder is there, which version put it there, and whether the last
attempt succeeded, was reverted by the device's sanity gate, or never finished.

Everything the installer needs is inside the one file: the device binaries, both .UPG
packages and the component catalogue. No separate download, no WSL, no usbipd, no driver
setup, and no network connection.
It sends the player's own upgrade command itself — SCSI
pass-through on Windows (so it asks for administrator), SG_IO on Linux (so it asks for
sudo). Sony's updater is no longer embedded in it.

Command line, if you prefer it:

cinder-installer --install | --update | --uninstall
cinder-installer --clean       # delete staged payload files left in the drive root
cinder-installer --check       # ask GitHub whether a newer release exists
cinder-installer -y            # no questions

Linux

cinder-installer-linux-x64 does the whole job — run it with sudo. It stages the
files and then sends the upgrade command itself: the same 12-byte vendor SCSI command
Sony's tool ends with. Root is needed because that is a raw SCSI passthrough. Without
it, the files are still staged correctly and the installer says what did not happen.

macOS

The installer stages the files but cannot finish. The upgrade command is a vendor SCSI
passthrough, and macOS only exposes those through an IOKit SCSITaskUserClient, which
the kernel refuses for an already-mounted disk. Finish from Linux or Windows; see
install.md.

The player has no update option in its own menus. This generation never had one —
the upgrade is always triggered by the host over USB.

cinder-home-install.upg and cinder-home-uninstall.upg are attached for that route
and for advanced recovery use. On Windows, the one-click executable is the recommended
path — it does the handoff for you.

Read RECOVERY.md first. This device has no public
DFU/EDL recovery path.

Verifying the download

GitHub shows its own sha256: digest beside each file in the assets list above. That is computed
by GitHub when the file is uploaded, and it proves your download matches what GitHub stores.

The sums below are a different link in the same chain: they are computed on the build runner,
before upload, so they say what was actually built. They should agree with GitHub's digests — if
they ever do not, something happened between the build and the release, and that is worth knowing.

917ef82645daffdaa8f8c54d1918e96dc063d62e83581dbee9762e0782ba3d16  cinder-home-install.upg
aeefcf053f1da6119469406987cbd22b6bf8cfd6e97ccf9f7632025f57cb7e0d  cinder-home-uninstall.upg
a62d5a3390b2cd75074896359ecba74ef705775192e783c60a7d671523813b46  cinder-installer-linux-x64
ad6e9e2387e5da78e285a6c6e92dfd22ec08d5b78040a508e8a65c8c7d9cd4cd  cinder-installer-windows-x64.exe

On Linux or macOS, save that block as SHA256SUMS next to the downloads and run:

sha256sum -c SHA256SUMS

On Windows:

Get-FileHash .\cinder-installer-windows-x64.exe -Algorithm SHA256

Every file above also has a GitHub build attestation. With the GitHub CLI
2.49 or later (older versions, including the 2.45 Ubuntu packages, do not have this command):

gh attestation verify cinder-installer-windows-x64.exe -R superwilso/Cinder

A pass means the file was built by this repository's release workflow from the tagged commit, and
is signed in a way an uploaded replacement cannot fake. The checksums say the file is intact; the
attestation says where it came from.

The installer is unsigned, so SmartScreen will warn about an unknown publisher — that
is expected for an unsigned binary and is not itself evidence of anything. Check the
hash if you want more than my word for it.

Full Changelog: v0.3.9...v0.3.12