This commit is contained in:
@@ -0,0 +1,107 @@
|
||||
# Phase 1.0S: official shsrv/hbldr provenance
|
||||
|
||||
Status:
|
||||
`BIGAPP_CONTEXT_SOURCE_PROVEN_DEPLOYED_IDENTITY_UNPROVEN_DEVICE_PATH_BLOCKED`
|
||||
|
||||
Date: 2026-07-22
|
||||
|
||||
This phase acquired and inspected only the official public
|
||||
`ps5-payload-dev/shsrv` Git source. No downloaded code was built or executed.
|
||||
No PS5 address was used, no connection or request was made, and no target
|
||||
source, target artifact, transfer package, installation package, or device
|
||||
client was created.
|
||||
|
||||
## Provenance boundary
|
||||
|
||||
The official repository is `https://github.com/ps5-payload-dev/shsrv`. During
|
||||
the audit its `master`, latest release tag `v0.19`, and commit all resolved to
|
||||
`6f320637d56d344a0e7797753099e33238bbf146`; the tree object is
|
||||
`c26ce02b6c3ca4202993e039b3db7c28c353dee4`. The clean, detached historical
|
||||
`v0.7` worktree resolves to commit
|
||||
`74287f5db6b20320efd7892d7b29cf438fe7cb98` and tree
|
||||
`7184968c702afe038551bf3228cc25f455388bb6`.
|
||||
|
||||
These source identities prove official implementations, not which shsrv
|
||||
binary—if any—is installed or running on the target PS5. No locally supplied
|
||||
shsrv/hbldr binary, package receipt, deployment log, or byte-exact device
|
||||
identity was found. The deployed identity remains `UNPROVEN`.
|
||||
|
||||
## Why v0.7 and v0.19 are both relevant
|
||||
|
||||
The Phase-1.0Q LakeSnes source at commit
|
||||
`a2db690123649c7ffbc68a663af31efb3a41bf3f` states that shsrv v0.7 or later is
|
||||
required and launches the emulator with `hbldr`. Therefore v0.7 is the oldest
|
||||
source-bound implementation relevant to that port documentation. Version
|
||||
v0.19 is the latest official release inspected during Phase 1.0S.
|
||||
|
||||
The `hbldr` family began at commit
|
||||
`4a70b50eecab853408f0a93a579b90428369fa09` as an experimental loader that
|
||||
injects an ELF into a web application. The significant lineage is:
|
||||
|
||||
| Point | Commit/tag | Source-proven behavior |
|
||||
|---|---|---|
|
||||
| introduction | `4a70b50eecab853408f0a93a579b90428369fa09` | inject an ELF into a webapp process |
|
||||
| LakeSnes minimum | `v0.7`, `74287f5...` | launch VideoPlayer BigApp `PPSA01659`, replace its process image |
|
||||
| fake-game transition | `18e9a62aea801b5a1be4a692dba76bf5381e9fcb` | attach homebrew to a created fake game |
|
||||
| first release containing transition | `v0.8` | fake-app/system-ex path present |
|
||||
| current official release | `v0.19`, `6f32063...` | launch `FAKE00000`, replace its process image |
|
||||
|
||||
An official tag or source lineage is not deployed-use proof. The current
|
||||
device may use no shsrv, a historical build, a current build, or a modified
|
||||
binary.
|
||||
|
||||
## Exact source identities
|
||||
|
||||
### v0.19
|
||||
|
||||
| File | Size | SHA-256 |
|
||||
|---|---:|---|
|
||||
| `README.md` | 3,546 | `4855fa2adbe1fc0c7aa0174aa3275742d9b9aba3d818ae09cf2722a89b06cd34` |
|
||||
| `shsrv.c` | 5,293 | `6ec71b4eb6c2bc1159f21568c1c9834f8aecac8d8881113bf09cf8981be19ee3` |
|
||||
| `sh.c` | 13,278 | `3c4b7f76efdd157436ed4b353ee1b550bf3ff9df17c147b4762b767982fc8253` |
|
||||
| `elfldr.c` | 17,911 | `4aa31f5a942681f8d88281b9713f087ced8963de842438cacad1088933f8e785` |
|
||||
| `bundles/hbldr/main.c` | 1,520 | `6fa519888f79fe0458a983a517073c1eccc61239edfbe40d607f69b6b38a8af4` |
|
||||
| `bundles/hbldr/hbldr.c` | 13,438 | `0096f86a00fdedcbc7509db47eb0f54dbc3e487d37e699f3de79048bac001be9` |
|
||||
|
||||
### v0.7
|
||||
|
||||
| File | Size | SHA-256 |
|
||||
|---|---:|---|
|
||||
| `README.md` | 3,248 | `3d16e46416dd07940fcde1190a6ab558348bc80263da615331dda0f3eb6183ed` |
|
||||
| `shsrv.c` | 4,716 | `66197d08308180fe923aa8aedc91bd5025f08938156ae3092ea2c69d0ad0be57` |
|
||||
| `sh.c` | 8,449 | `bf97bc6dd3f49345ad8da9a29b28a5d6bcde5e53a6f32c60a538d6e187c7e05a` |
|
||||
| `elfldr.c` | 17,920 | `1ff6cfa1300a95e8be48e5f7adc1413e3384ba04ea266c167fcd441ef20197d1` |
|
||||
| `bundles/hbldr/main.c` | 7,134 | `2081ece2f7d0a7e9b392660696c2a44802f64680365607e742b37dcf3223a55a` |
|
||||
|
||||
## PacBrew relationship
|
||||
|
||||
PacBrew commit `c2abcfcb60f569128abd0e8e70ad03a67bee5ea7` contains an shsrv recipe that
|
||||
clones the official repository, uses `pkgver=git`, and declares
|
||||
`sha256sums=('SKIP')`. It installs `shsrv.elf`, but does not pin the fetched
|
||||
shsrv commit or prove which package was installed on the target. It is
|
||||
`SOURCE_REPOSITORY_ASSOCIATION`, not byte-exact deployment provenance.
|
||||
|
||||
## Proven and unproven conclusions
|
||||
|
||||
`SOURCE_PROVEN`:
|
||||
|
||||
- the official hbldr family creates or launches a BigApp and replaces that
|
||||
process with the requested ELF;
|
||||
- v0.7 and v0.19 differ materially from raw elfldr's SceSpZeroConf process;
|
||||
- both variants read the target ELF from a device path;
|
||||
- both may terminate the currently running BigApp and perform kernel/ptrace
|
||||
process mutations;
|
||||
- v0.19 may remount and persistently populate `/system_ex/app/FAKE00000`.
|
||||
|
||||
`UNPROVEN`:
|
||||
|
||||
- which shsrv/hbldr binary is deployed;
|
||||
- whether `FAKE00000` already exists on the target;
|
||||
- whether the launcher works on the specific firmware-9.60 runtime;
|
||||
- whether BigApp substitution provides the missing VideoOut permission;
|
||||
- whether it would make the exact RetroArch first submit succeed;
|
||||
- crash, cleanup, reboot, and visibility behavior on the target.
|
||||
|
||||
The source difference is a
|
||||
`STRONG_SOURCE_CANDIDATE_NOT_PROVEN_ROOT_CAUSE`. It does not authorize using
|
||||
hbldr, staging an ELF, connecting to shsrv, or creating a replacement launcher.
|
||||
Reference in New Issue
Block a user