Publish Chimera GFX source
phase0-ci / build-and-audit (push) Successful in 2m14s

This commit is contained in:
Chimera GFX release export
2026-09-03 03:27:14 +02:00
commit a6037502d7
828 changed files with 100454 additions and 0 deletions
+122
View File
@@ -0,0 +1,122 @@
# Phase 0.6 exact loader audit
Historical record: superseded for current deployment preparation by the new
Phase-0.7 hardened binaries. This blocked decision remains authoritative for
the unmodified public-release chain.
Audit date: 2026-07-17. Decision:
**BLOCKED_VERSION_OR_UNBOUNDED_EFFECT**.
No ELF was built, transferred, or executed. The PS5 was not contacted through
raw port 9021. Read-only Payload Manager status endpoints were used only to
identify the installed public components. A strict existing read-only status
client on port 744 could not connect, so firmware 9.60 remains user-attested,
not device-attested.
## Identity evidence
| Component | Observed identity | Public source/release match | Result |
|---|---|---|---|
| firmware | exact `9.60`, stated by Jens | no independent device response | `UNPROVEN` attestation |
| Payload Manager | `/version` = `0.3.1`; inventory SHA-256 `518740ad...3c0b` | v0.3.1, commit `cfbc70f30...` | exact |
| elfldr | inventory v0.23; SHA-256 `092d16ee...03e8` | `ps5-payload-dev/elfldr` v0.23, commit `699e8bcff0...` | exact |
| itsPLK elfldr candidate | SHA-256 `2c28f847...8f933` | differs from installed hash | excluded |
| SDK | v0.41 | commit `d2e2e58574...` | exact |
| exploit/autoloader | local backup candidate only | no installed identity proof | `UNPROVEN` |
The exact source and release pins are in `manifests/upstreams.lock.json`. The
machine audit normalizes source text to LF, hashes every reviewed file, hashes
the complete release-binary disassembly and readelf report, and asserts the
critical source tokens before generating its result.
## Exact release binary
The installed elfldr release asset is a stripped ELF64 PIE with entry `0x4700`.
Its complete import surface is:
```text
DT_NEEDED:
libSceLibcInternal.sprx
libSceNet.sprx
libkernel_web.sprx
Undefined dynamic symbols:
__error
close
execve
free
getpid
kevent
kill
kqueue
malloc
memcpy
memset
open
printf
puts
realloc
recv
rfork_thread
sceKernelSendNotificationRequest
strcmp
strerror
strlen
sysctl
vsnprintf
waitpid
```
It has 164 dynamic relocations, 140 of them `R_X86_64_RELATIVE`; zero-byte
preinit/init/fini arrays; and no TLS segment or TLS sections. The first load
segment is RWE. This import list does not prove absence of statically linked
kernel helpers, so the source and disassembly audits remain primary.
## Loader lifecycle
The loader uses a dedicated SceSpZeroConf child. It establishes a synthetic
call frame by placing the observed trap RIP at `RSP-8`, setting `RIP` to the
payload entry and `RDI` to a loader-created `payload_args_t`. It restores the
INT3 byte, jail/root/caps/authid on the child success path, and its own authid
after each ptrace syscall on the normal path.
It does not prove or enforce:
- the continuation reached when the payload returns;
- a finite step count in `pt_call()` or `pt_syscall()`;
- a two-second payload runtime;
- restoration after an authid-restore failure;
- child UID restoration;
- child mapping/socket/pipe cleanup after detach;
- child termination and reaping after normal return, crash, or hang.
The installed service's existing QA flag and bootstrap credential effects are
separate from new artifact effects. They are still documented because the
full lifecycle depends on them.
## Payload Manager lifecycle
The exact `/loadpayload:` handler resolves a filename/path and streams that
file to elfldr on loopback port 9021. It does not calculate or compare the file
SHA-256 at launch. The `/manage:upload` path creates
`/data/pldmgr/payloads/<filename>.tmp` and commits the upload into storage.
Consequently the current manager cannot simultaneously provide exact-hash
launch binding and the required zero-filesystem-write transfer budget.
No manager route was invoked to upload, load, kill, configure, retry, or
contact port 9021 during this audit.
## Minimum evidence needed to reopen Phase D
1. Exact exploit/autoloader identity and public-source lifecycle evidence.
2. Read-only, exact device attestation of firmware 9.60.
3. A bounded loader path whose ptrace and payload phases enforce a maximum of
2000 ms without automatic retry.
4. Proven payload return/exit/crash continuation and child cleanup/reaping.
5. Proven restoration or bounded termination on every credential-change
failure path, including UID.
6. A Payload Manager path that verifies the exact SHA-256 immediately before
launch and performs no filesystem write.
No workaround is authorized. The two safe development tracks remain the
mock/software backend and a separately scoped Linux-on-PS5 backend.