Related to this, every ROM needs a "boot loader" that has to be signed and is verified by the lockout chip.

Nintendo's boot code is under copyright and thus cannot be used. So the boot code distributed with Libdragon is signed by finding a hash collision with a brute force tool running on the GPU[1]. Fun stuff!

[1] https://github.com/DragonMinded/libdragon/tree/trunk/boot#bu...

They might be able to get around it with an affirmative defense in court, but they obviously don't want to, lest they lose.

But it's legal to use the Sony and Nintendo trademarks in a similar way. The court ruled that since they are checked by the console, there was no way not to use them, and Nintendo lost their protection by doing so.

The “development” version of that is even crazier: it's a very tiny signed bootloader that does nothing but copies the “real” bootloader into memory, then trampolines into it, such that even developing your own IPL3 doesn't require having to re-brute-force the signature for every build.

And on top of that, libdragon's IPL3 doesn't just blindly copy the first megabyte of ROM code into RDRAM like the official Nintendo one does, but actually expects the ROM data after it to be a full-blown ELF executable, which it parses out and copies pieces of to the specified places.

Pretty slick stuff.