Publish Chimera GFX source
phase0-ci / build-and-audit (push) Successful in 2m14s

This commit is contained in:
Chimera GFX release export
2026-09-03 03:27:14 +02:00
commit a6037502d7
828 changed files with 100454 additions and 0 deletions
@@ -0,0 +1,139 @@
# Phase 1.0I offline flip and write analysis
Status: **OFFLINE ANALYSIS COMPLETE; DEVICE RETEST BLOCKED**.
This is a static postmortem of the consumed Phase-1.0H run. It binds the
captured frames to the exact RetroArch source, SDL overlay, linker map and
artifact disassembly. No PS5 connection, request, transfer, execution or new
target build was performed.
## Conclusions first
- The first VideoOut submit failed at the exact call
`sceVideoOutSubmitFlip(handle, 0, 1, 0)`; the wait was not reached.
- The diagnostic helper uses buffer/frame zero while the same patch makes the
normal update path start at frame one. This is a strong code-level
inconsistency, not a proven firmware root cause.
- The original submit `errno` was not captured. D07 output occurs before
`errno` is read and can itself change it.
- E118 occurred between I03 and I04. The linked binary can classify the
rejected operation only as `OPEN` or `STREAM`; D12 does not carry the exact
stored operation.
- The E118 shutdown request did not gate later initialization: I04 through
D07 still ran.
The next safe action is another offline design/build phase that improves
observability and shutdown gating. It is not another device run.
## Evidence binding
| Object | Identity |
|---|---|
| RetroArch source | `c710f85816b5e456dd3a85a46f85eb28883522b3` |
| Phase-1.0H result commit | `5db76beddd56c0f82ecbcccfbe8ed12ea3bb4bda` |
| Artifact | 1,845,152 bytes, SHA-256 `822f2cf1f4d33a514d2bdd88fde40ad580dda5d85f537362ef6dff2eafcb56b6` |
| Linker map | 637,603 bytes, SHA-256 `638642b750b8d5b108cf6c73215a3f1759bc6da0b29ee0a0ade5c47e8b7b2d5` |
| SDL diagnostic patch | SHA-256 `c287cf0207192b06c2658c2ae6982a3c2fe3ee9179908de5911d074786dc889e` |
| Materialized SDL video source | SHA-256 `9a1c171711d2b5a1167b66a3c0e2ac926d7fd101b1f08b0a9240a3aa9c62211e` |
| Device trace | SHA-256 `858a205afcf682a498d8bc11947b67d2446098883a61f6871e31df4d950d0a61` |
| Public SDL source | commit `0baf4ac49382b537ba449901b5b6d0d189bb1fbb` |
| Public SDK v0.41 | commit `d2e2e585740362976a39fdd5ccf390f199a7bc37` |
The ignored artifact, map and trace remain local evidence; they are not added
to Git.
## E118 write-firewall interval
D12 has shutdown reason `6` (`WRITE_FIREWALL`) and first error `118`
(`E118_WRITE_BLOCKED`). Its sequence position proves the request occurred
after I03 and before I04. The in-memory status also stores
`first_blocked_write`, but D12 transmits only reason and error.
The exact linker map retains these blocking functions:
| Function | Address | Block category |
|---|---:|---|
| `__wrap_open` | `0x47580` | `OPEN` |
| `__wrap_fopen` | `0x475b0` | `OPEN` |
| `__wrap_fwrite` | `0x47600` | `STREAM` |
Configured wrappers for `openat`, `write`, create, truncate, directory and
rename/delete operations were garbage-collected from this artifact. Static
reachability within I03-to-I04 contains logging/configuration paths to
`__wrap_fopen`; it does not prove which runtime branch fired. The initial
`retro_main_log_file_init(NULL, false)` is specifically excluded because both
source and disassembly return before `fopen`. Remaining indirect/runtime
behavior prevents selecting `OPEN` over `STREAM` without inventing evidence.
Consequently the exact operation, path, mode/flags and intended file remain
`UNPROVEN`. This is an observability defect, not evidence that a device write
succeeded: the wrapper returned failure and set `EROFS`.
## Flip call and failure boundary
The SDL source fills its CPU surface, tiles it into `vbuf[0]`, then submits.
The artifact disassembly independently fixes the arguments:
```text
0xfe6ac esi = 0 buffer index
0xfe6ae edx = 1 flip mode
0xfe6b3 ecx = 0 64-bit flip argument
0xfe6bc call sceVideoOutSubmitFlip
```
D05 proves a positive handle for this run and D06 proves buffer registration
returned zero. D07 proves submit returned `-1`. The failure branch bypasses
`sceKernelWaitEqueue`; therefore no event wait, successful flip or visible
presentation is claimed.
The helper hard-codes `vbuf[0]` and `(0, 1, 0)`, while the patched normal
`PS5_UpdateWindowFramebuffer()` initializes `frame_id = 1` and derives the
buffer index from it. That mismatch is source-proven. However, the pinned SDL
upstream itself initializes the normal path at zero, so firmware semantics do
not establish that changing to one is correct.
SDK v0.41 exports the symbol but provides no public VideoOut prototype or
structure contract. The declaration and opaque layouts used here originate in
the public SDL fork. Buffer-index validity, flip argument monotonicity, buffer
attribute semantics and exact firmware-9.60 error codes remain unproven.
The helper calls the D07 diagnostic sender before `strerror(errno)`. Since the
sender performs an inherited-socket `send`, it can overwrite `errno`; the
original submit error must be copied immediately after the submit in any
future diagnostic. No reliable error text was present in captured stdout.
## Review matrix
| Question | Result |
|---|---|
| H startup-argument correction | PROVEN_ON_FIRMWARE_9_60 |
| E118 interval | PROVEN |
| E118 operation domain | PROVEN: `OPEN` OR `STREAM` |
| Exact E118 operation/path | UNPROVEN |
| Pattern write before submit | PROVEN_FROM_SOURCE_AND_STAGE |
| Submit argument tuple | PROVEN_FROM_SOURCE_AND_DISASSEMBLY |
| Submit return | PROVEN: `-1` FOR CONSUMED RUN |
| Original submit `errno` | UNPROVEN |
| Frame-zero mismatch | STRONG_SOURCE_CANDIDATE |
| Frame-zero mismatch is root cause | UNPROVEN |
| VideoOut argument/ABI semantics | UNPROVEN |
| Visible presentation | UNPROVEN |
| Complete cleanup/safe exit | UNPROVEN |
## Gate for a future offline artifact phase
A later phase may design and build, offline only, a newly hashed diagnostic
that:
1. captures submit return and `errno` before any reporting call;
2. emits the exact blocked write operation and count;
3. stops initialization before I04 once the firewall requests shutdown;
4. removes the divergent first-frame constants through one reviewed source of
truth;
5. preserves one submit, no submit retry, and waits only after submit success;
6. adds no target socket creation, address, filesystem write, install or
autoload path.
Choosing frame zero or one requires an evidence-backed decision. A new build
would remain ineligible until a separate review. No current PS5 connection,
transfer, execution, result reception or retry is authorized.