This commit is contained in:
@@ -0,0 +1,78 @@
|
||||
# Phase 1.0U: bounded local shsrv artifact inventory
|
||||
|
||||
Status: `BOUNDED_LOCAL_INVENTORY_COMPLETE_NO_DEPLOYED_CANDIDATE_FOUND`
|
||||
|
||||
Date: 2026-07-22
|
||||
|
||||
This phase is host-only. It performed no internet request, PS5 connection,
|
||||
port operation, target build, payload execution, transfer or file mutation.
|
||||
It did not execute any discovered script or binary.
|
||||
|
||||
## Question and result
|
||||
|
||||
Phase 1.0T established that the deployed shsrv binary cannot be identified
|
||||
exactly through its existing shell metadata. Phase 1.0U therefore searched for
|
||||
the original host-side `shsrv.elf`, package, receipt or deployment record that
|
||||
could instead be hashed directly.
|
||||
|
||||
No deployed candidate was found in the bounded scope. This means only
|
||||
`NO_CANDIDATE_IN_SCANNED_SCOPE`; it does not prove that no copy exists
|
||||
elsewhere on the host or device.
|
||||
|
||||
## Bounded scope
|
||||
|
||||
The inventory was restricted to:
|
||||
|
||||
- the Chimera GFX repository, including existing work and outputs;
|
||||
- the known Chimera elfldr, Payload Manager and RetroArch sibling trees;
|
||||
- already supplied Codex attachment storage;
|
||||
- candidate filenames in the previously evidenced user download directory;
|
||||
- entry names, but not extraction or execution, for ZIP files in those roots.
|
||||
|
||||
The scan matched case-insensitive `shsrv`/`hbldr` names and known target/host
|
||||
artifact extensions. It did not scan the whole computer, browser databases,
|
||||
unrelated archives, network shares or the PS5. Non-ZIP archives with unrelated
|
||||
names were not inspected.
|
||||
|
||||
## Findings
|
||||
|
||||
| Object | Size | SHA-256 | Classification |
|
||||
|---|---:|---|---|
|
||||
| `work/upstream/shsrv` | n/a | commit `6f320637d56d344a0e7797753099e33238bbf146` | official source reference only |
|
||||
| `work/upstream/shsrv-v0.7` | n/a | commit `74287f5db6b20320efd7892d7b29cf438fe7cb98` | historical source reference only |
|
||||
| `work/upstream/shsrv/host/prospero-shsrv-shell` | 1,026 | `34283c1d27a8b723ba529dfd5ed79ff9a1f967ab2ad2b97ed2b8889351f0973a` | official host wrapper, not target binary |
|
||||
| `work/upstream/pacbrew-repo/shsrv/PKGBUILD` | 1,051 | `3f134e9986fb8352136150216006d68fb92052ec55d5698d36825a97c37c3b30` | unpinned package recipe only |
|
||||
|
||||
The official host wrapper selects `rlwrap telnet` or `telnet`. It was read and
|
||||
hashed but never executed. It contains no target shsrv bytes and cannot prove
|
||||
what is installed. The PacBrew recipe would build `shsrv-ps5.elf` and package
|
||||
it as `shsrv.elf`, but uses an unpinned Git source with `sha256sums=('SKIP')`.
|
||||
It is not a package receipt or installed-file identity.
|
||||
|
||||
The existing Y2JB and Chimera ZIP entry-name inventory yielded no shsrv/hbldr
|
||||
entry. Existing elfldr, Payload Manager, Chimera GFX and RetroArch ELFs are
|
||||
distinct artifacts and were not relabelled as shsrv candidates.
|
||||
|
||||
## Evidence boundary
|
||||
|
||||
None of the following was found:
|
||||
|
||||
- a local `shsrv.elf` or `shsrv-ps5.elf` deployment candidate;
|
||||
- a package archive containing a shsrv/hbldr-named target;
|
||||
- a package-manager receipt with installed hash and path;
|
||||
- a host transfer log binding exact bytes to the device;
|
||||
- an operator-provided original binary;
|
||||
- an independently verified current device path or hash.
|
||||
|
||||
An official source checkout, host helper or package recipe is not deployed
|
||||
identity. A future operator-supplied file must first be treated as
|
||||
`LOCAL_CANDIDATE_ONLY`, hashed without execution, and provenance-reviewed.
|
||||
|
||||
## Decision
|
||||
|
||||
Exact deployed shsrv identity remains `UNPROVEN`. No Phase-1 launch-context
|
||||
experiment is enabled. The next permitted engineering activity is an offline,
|
||||
inactive design for a one-shot sanitizing collector. That design must still
|
||||
begin with all addresses, commands and authorizations absent and may not open a
|
||||
socket. Live collection would require separate exact authorization and
|
||||
acceptance of shsrv's unavoidable shell, serial and telemetry effects.
|
||||
Reference in New Issue
Block a user