Publish Chimera GFX source
phase0-ci / build-and-audit (push) Successful in 2m14s

This commit is contained in:
Chimera GFX release export
2026-09-03 03:27:14 +02:00
commit a6037502d7
828 changed files with 100454 additions and 0 deletions
@@ -0,0 +1,104 @@
# Phase 1.0S: hbldr BigApp launch and safety contract
Status: `EXISTING_ROUTE_UNSAFE_FOR_CURRENT_DEVICE_GATE`
## v0.19 callgraph
```text
host telnet client
-> shsrv TCP listener on port 2323
-> accepted connection
-> elfldr_spawn(embedded sh.elf)
-> shell parses command
-> builtin hbldr
-> elfldr_spawn(embedded hbldr.elf)
-> read requested ELF from device filesystem
-> ensure /system_ex/app/FAKE00000 exists
-> optionally remount /system_ex
-> optionally mkdir/write param.json and eboot.bin
-> initialize foreground-user context
-> kill currently running BigApp, if present
-> attach to SceSysCore and follow fork
-> sceSystemServiceLaunchApp("FAKE00000", ...)
-> follow child exec
-> set child rootdir/jaildir through kernel helpers
-> replace BigApp process image with requested ELF
-> detach; target continues
```
The v0.7 path has the same essential distinction from raw elfldr but directly
launches VideoPlayer title `PPSA01659`. It does not contain the later
`FAKE00000` creation/remount path. It still kills a running BigApp, reads a
device-resident target ELF, changes target-process root/jail state, and injects
the ELF into a SystemService-launched BigApp.
## Raw elfldr versus hbldr
| Property | Hardened raw elfldr | Official hbldr |
|---|---|---|
| input | host-streamed raw ELF | path to ELF already on device |
| process basis | `SceSpZeroConf` child | SystemService-launched BigApp |
| foreground user | not established by inspected route | queried and passed to launch context |
| app/title launch | none | v0.7 `PPSA01659`; v0.19 `FAKE00000` |
| running BigApp | left untouched by constructor | may be killed before launch |
| persistent writes | none in raw launch route | possible v0.19 fake-app creation |
| kernel/ptrace process mutation | yes | yes, plus BigApp substitution |
| display permission | unproven | unproven; architecture is materially different |
The difference is source-proven. Its effect on VideoOut is not.
## Side-effect matrix
| Effect | v0.7 | v0.19 | Classification |
|---|---|---|---|
| read target ELF from device | yes | yes | requires staging; current hard blocker |
| terminate active BigApp | yes | yes | `HIGH_SESSION_DISRUPTION` |
| launch SystemService BigApp | VideoPlayer | fake game | `HIGH_FUNCTIONAL` |
| attach/follow SysCore child | event tracking | ptrace follow-fork/exec | `HIGH_RUNTIME_MUTATION` |
| kernel root/jail changes | yes | yes | outside current safety scope |
| executable mapping replacement | yes | yes | expected launcher mutation, not persistent file proof |
| remount `/system_ex` | no | possible | `BRICK_RELEVANT_HARD_BLOCKER` |
| create fake-app directories/files | no | possible | `PERSISTENT_SYSTEM_MUTATION_HARD_BLOCKER` |
| autoload change | not found | not found | source-negative only |
| bounded deadline | no | no | `SESSION_HANG_RISK` |
| automatic retry | not found | not found | source-negative only |
| rollback/power-loss protocol | absent | absent | v0.19 `POWER_LOSS_UNSAFE_OR_UNPROVEN` |
## Persistent-write audit for v0.19
`fakeapp_create_if_missing()` checks fixed paths, creates directories, writes a
fixed `param.json`, and copies the existing PSNow eboot into the fake app. If
the initial attempt fails, `remount_system_ex()` performs an `MNT_UPDATE` and
the creation is attempted again.
The writes have no temporary sibling, atomic rename, `fsync`, byte-exact
post-write verification, backup, rollback, or power-loss recovery. `open()`
uses `O_CREAT|O_WRONLY`, without `O_EXCL` or an atomic replacement protocol.
This is incompatible with Chimera GFX's current anti-brick gate regardless of
whether a particular target already has the fake app.
## Robustness findings
- `readfile()` has no maximum input size and allocates the whole ELF;
- process waits, child-await, and `pthread_join` have no hard deadline;
- the port-2323 listener binds all IPv4 interfaces and the inspected source
shows no authentication or transport protection;
- `splitstring()` initially allocates `bufsize * sizeof(char)` but stores
pointers, a source-visible memory-corruption risk;
- `which()` uses unbounded `strcpy`/`sprintf` into `PATH_MAX` storage;
- failure branches do not establish a complete restoration contract for every
traced process and modified breakpoint;
- target authenticity, size, and SHA-256 are not verified before launch.
These are `SESSION_CRASH_OR_INTEGRITY_RISK` unless a persistent write is
involved. A session crash is not automatically a brick, but it does not satisfy
the bounded one-shot Chimera test contract.
## Decision
The official hbldr route cannot be reused, imitated, or treated as an approved
launcher in the current phase. It requires device staging and contains
operations explicitly outside the active authorization and safety boundary.
No `hbldr` command, port-2323 connection, shsrv deployment, target build,
transfer, installation, app termination, system remount, file creation, or
execution is authorized.