This commit is contained in:
@@ -0,0 +1,126 @@
|
||||
# Phase 1.0R: PS5 launch-context comparison
|
||||
|
||||
Status: `NO_SOURCE_PROVEN_LAUNCH_CONTEXT_FIX_TARGET_CHANGE_BLOCKED`
|
||||
|
||||
Date: 2026-07-22
|
||||
|
||||
This is an offline source, map, and provenance audit. It did not build target
|
||||
code, connect to the PS5, transfer an artifact, receive a device result, or
|
||||
execute anything on the PS5. Phase-1.0O authority remains consumed and every
|
||||
authorization remains false.
|
||||
|
||||
## Question and evidence boundary
|
||||
|
||||
Phase 1.0O proved that the exact M artifact opened VideoOut, registered its
|
||||
buffers, and received `-1` with saved errno `0` from the first
|
||||
`sceVideoOutSubmitFlip(handle, 0, 1, 0)`. Phase 1.0R asks whether the raw
|
||||
elfldr path differs, in a source-proven way relevant to that call, from the
|
||||
launch context used by existing PS5 SDL ports.
|
||||
|
||||
The comparison is bounded to these exact clean source identities:
|
||||
|
||||
| Component | Commit | Relevant evidence |
|
||||
|---|---|---|
|
||||
| Chimera RetroArch | artifact source `12cf1d783c41eb303987e49a5a920805a59ef7a4`; inspected HEAD `606909706f91d7213751c245081333f56c2cce89` | `Makefile.ps5`; exact M map and artifact identities |
|
||||
| PS5 Payload SDK | `d2e2e585740362976a39fdd5ccf390f199a7bc37` | `crt/crt.c`, `toolchain/prospero.mk` |
|
||||
| PS5 SDL | `0baf4ac49382b537ba449901b5b6d0d189bb1fbb` | `src/main/ps5/SDL_ps5_main.c`, `src/video/ps5/SDL_ps5video.c` |
|
||||
| hardened elfldr | `197623058f509eddde18868dafcb92fdcac66464` | `elfldr.c`, `socksrv.c` |
|
||||
| controlled Payload Manager | `e23d94ff91233aa770e2342800c1467875bdef44` | `src/ps5_launcher.c`, `src/main.c` |
|
||||
| PacBrew recipes | `c2abcfcb60f569128abd0e8e70ad03a67bee5ea7` | SDL2 and port recipes |
|
||||
| LakeSnes reference | `a2db690123649c7ffbc68a663af31efb3a41bf3f` | `Makefile.prospero`, `main.c`, `homebrew.js`, `README.prospero` |
|
||||
|
||||
The official port archives retained from Phase 1.0Q are source references,
|
||||
not deployed-artifact or on-device launch evidence.
|
||||
|
||||
## Exact compared paths
|
||||
|
||||
### Direct raw ELF and Payload Manager
|
||||
|
||||
The hardened elfldr listener sends every accepted raw ELF through
|
||||
`payload_spawn()` in `socksrv.c`, then through `elfldr_spawn()` in `elfldr.c`.
|
||||
That routine creates a process with `rfork_thread`, executes the system
|
||||
`SceSpZeroConf` image, replaces its executable mapping under ptrace, and
|
||||
detaches. The legacy route duplicates the accepted descriptor to standard
|
||||
input/output/error; the controlled route changes standard-I/O and watchdog
|
||||
policy. Neither route registers an application, title ID, flip owner, or
|
||||
display context.
|
||||
|
||||
Payload Manager's `ps5_launch_elf()` reads the selected ELF and sends it to
|
||||
loopback port 9021. It does not create a distinct payload process. Therefore
|
||||
both a direct host send and a Payload Manager launch reach the same
|
||||
`payload_spawn()`/`elfldr_spawn()` process constructor. Payload Manager does
|
||||
contain separate LNC-based disc-player management, but that path is not the
|
||||
ELF process constructor and is not evidence of payload display ownership.
|
||||
|
||||
### Exact RetroArch artifact
|
||||
|
||||
`Makefile.ps5` links `libSDL2.a`, but not `libSDL2main.a`. The exact M linker
|
||||
map proves `_start` comes from SDK `crt1.o` and includes
|
||||
`SDL_ps5video.c.o`. It contains no `SDL_ps5_main.c`, no `libSDL2main`, and no
|
||||
`sceSystemServiceLoadExec`; it does import
|
||||
`sceSystemServiceHideSplashScreen` through SDL video initialization.
|
||||
|
||||
SDK `_start(payload_args_t *)` initializes its runtime, invokes the ordinary
|
||||
`main(argc, argv, environ)`, finalizes, and terminates according to the SDK
|
||||
payload contract. The inspected CRT contains no application/title
|
||||
registration and no LNC or VideoOut ownership setup.
|
||||
|
||||
### SDL2main ports
|
||||
|
||||
At the pinned SDL commit, PS5 SDL2main is only this lifecycle wrapper:
|
||||
|
||||
1. `sceSystemServiceHideSplashScreen()`;
|
||||
2. `SDL_main(argc, argv)`;
|
||||
3. after `SDL_main` returns, `sceSystemServiceLoadExec("exit", 0)`.
|
||||
|
||||
It contains no app registration, title-ID selection, LNC call, process
|
||||
creation, VideoOut call, or flip-owner acquisition. The `LoadExec` operation
|
||||
is post-return and cannot affect the first VideoOut submit.
|
||||
|
||||
The exact SDL PS5 `PS5_VideoInit()` independently calls
|
||||
`sceSystemServiceHideSplashScreen()` immediately before
|
||||
`sceVideoOutOpen(0xff, 0, 0, NULL)`. Consequently the tested RetroArch path
|
||||
already performs the only SDL2main pre-entry action relevant by name before
|
||||
opening VideoOut. Linking SDL2main would merely perform that call earlier and
|
||||
again; no public source proves that this changes display ownership.
|
||||
|
||||
LakeSnes does link `-lSDL2main -lSceSystemService` and defines `SDL_main`.
|
||||
Its `homebrew.js` returns an executable path and arguments, while its README
|
||||
describes `hbldr` through `ps5-payload-shsrv`. These are launcher references,
|
||||
not source for application registration. The exact `hbldr`/`shsrv` process
|
||||
constructor and its active-app state were not present in this bounded source
|
||||
set, so the launch-context relationship is `PARTIAL_UNBOUND`.
|
||||
|
||||
## Comparison matrix
|
||||
|
||||
| Property before first submit | Direct host to elfldr | Payload Manager to elfldr | SDL2main-linked port | Evidence result |
|
||||
|---|---|---|---|---|
|
||||
| process constructor | hardened `elfldr_spawn` | same hardened `elfldr_spawn` | launcher-dependent | first two proven same; port launcher unbound |
|
||||
| SDK CRT | `crt1.o` | `crt1.o` | ordinarily `crt1.o` through `prospero.mk` | same SDK model in inspected builds |
|
||||
| splash hide | SDL `VideoInit` | SDL `VideoInit` | wrapper plus SDL `VideoInit` | only proven pre-submit difference is earlier duplicate call |
|
||||
| SDL application entry | ordinary RetroArch `main` | ordinary RetroArch `main` | wrapper calls `SDL_main` | symbol/lifecycle difference only |
|
||||
| post-return exit | SDK termination | SDK termination | `LoadExec("exit")` before wrapper returns | post-submit lifecycle only |
|
||||
| title/app registration | absent in inspected path | absent in ELF launch path | absent in SDL2main | no source-proven registration |
|
||||
| flip/display ownership | absent in inspected path | absent in ELF launch path | absent in SDL2main | unproven everywhere |
|
||||
| autoload or persistent setup | none in launch route | none required by ELF launch route | launcher-dependent | no evidence of a required fix |
|
||||
|
||||
## LNC log classification
|
||||
|
||||
Phase 1.0O ordinary stdout repeatedly included
|
||||
`getAppStatus: LNC_ISOK::0x80940004`. It is
|
||||
`OBSERVED_NONUNIQUE_CORRELATION`: the trace does not identify its caller,
|
||||
multiple system-service/video activities can interleave, and public source
|
||||
does not define that value as the cause of the flip failure. It is not a
|
||||
root-cause verdict and does not justify adding LNC calls.
|
||||
|
||||
## Decision
|
||||
|
||||
`SDL2main` is not a source-proven launch-context correction. PacBrew is a
|
||||
build/package repository, not a launcher. The official port metadata points
|
||||
to launchers whose exact process/app/display setup remains unbound. The
|
||||
possibility that active-app or launcher state matters therefore remains
|
||||
plausible but unproven.
|
||||
|
||||
The root cause is unresolved. Do not link SDL2main as an experiment, add LNC
|
||||
or SystemService calls, change submit parameters, call another VideoOut
|
||||
export, build a target, or perform a device action under Phase 1.0R.
|
||||
Reference in New Issue
Block a user