# Phase 1.0J offline write-firewall diagnostic Status: **OFFLINE ARTIFACT AUDITED; DEVICE ACTION BLOCKED**. Phase 1.0J implements the bounded offline follow-up required by Phase 1.0I. It does not connect to a PS5, transfer an ELF, receive a device result or run target code. The built ELF and map stay in ignored local build storage and are not committed. ## Exact source and artifact binding | Object | Identity | |---|---| | RetroArch source | `2e385265ab893dbba5898178dde5e108d3dbfa19` | | Chimera GFX baseline | `2bee49e5e8f1ee6faa0589d2d74de5ba0d809293` | | Public PS5 SDL source | `0baf4ac49382b537ba449901b5b6d0d189bb1fbb` | | Public PS5 Payload SDK v0.41 | `d2e2e585740362976a39fdd5ccf390f199a7bc37` | | SDL diagnostic patch | SHA-256 `aa1d3ebc6043d6051938cee1dbffecb80729b3b6595eef964915e93f1570c193` | | Materialized SDL video source | SHA-256 `9949a280fed40241746788a8c001280455bc629e0566a88f82f16a8634d43025` | | J ELF | 1,845,208 bytes; SHA-256 `6ff0f7ea391da5f15ea43512a871078133e896a6900ae9f8f3fa75711abb8009` | | Linker map | 637,728 bytes; SHA-256 `19f1cf851ad8f99d31d5de3a14591f81faa83589c18e93cd60be96ebef5d7719` | | Normalized disassembly | SHA-256 `45dc4e0233b3770add430aaa6bb23a60210b50744effb76b515fca4b9e6e310f` | Two clean `PS5_PROFILE=write-diag` builds produced byte-identical ELFs and maps. The raw audit disassembly hashes differ because `objdump` includes each input pathname; replacing only the `write-diag-a`/`write-diag-b` path component produces the identical normalized hash above. ## Bounded diagnostic behavior The protocol uses distinct magic `CHD10J01`. Existing stage numbers and wire values are preserved; D13 is appended and carries exactly: ```text value_a = first_blocked_write value_b = write_block_count ``` The first write-firewall rejection emits one inherited-stdout, nonblocking, signal-suppressed D13 frame immediately before terminal D12. No target socket is created and the existing live runner has no J selector. Immediately after argument/config parsing, `retroarch_main_init()` observes `shutdown_requested` and returns false before I04 and all SDL/VideoOut driver lookup. Thus the first unresolved E118 operation can be identified without continuing into graphics initialization. The SDL helper separately copies `errno` immediately after its single `sceVideoOutSubmitFlip()` call and before notification or stream output. Under J, D07 would carry `(submit_result, saved_errno)`. That branch is deliberately unreachable after an earlier firewall shutdown; it is retained for a later, separately reviewed phase only. ADR-0012 fixes one `CHIMERA_PS5_FIRST_FRAME_INDEX` value of zero for the early copy, early submit and normal initial counter. This removes an internal source inconsistency. It is not firmware proof or a root-cause claim. ## Static and transitive audit The ELF is a PIE with entry point `0xff210`, 20 sections and four program headers. Three LOAD segments are `R E`, `R` and `RW`; no segment is RWX. `.init_array` and `.fini_array` both have size zero, and there is no TLS section. `.bss` is `0xaa520` bytes. The dynamic closure has 142 undefined symbols and 1,055 relocations: 142 `R_X86_64_GLOB_DAT` and 913 `R_X86_64_RELATIVE`. The exact DT_NEEDED set is: - `libSceAudioOut.sprx` - `libSceLibcInternal.sprx` - `libScePad.sprx` - `libSceSystemService.sprx` - `libSceUserService.sprx` - `libSceVideoOut.sprx` - `libkernel_web.sprx` The import set contains `send` for the already-audited inherited stdout descriptor. It contains no `socket`, `connect`, `bind`, `listen`, `accept` or `recv`, and no GNM symbol. The linker map binds the firewall entry at `0x466d0`, its surviving wrappers at `0x475a0`, `0x47610` and `0x476a0`, `retroarch_main_init` at `0x3dc0`, and the dormant early VideoOut helper at `0xfe550`. String scanning still finds dormant generic RetroArch text mentioning networking, installation, credentials, autoload and writes. Absence of a string is not used as safety proof. Safety rests on the source profile, write-wrapper closure, linker map and disassembly; the scan findings remain recorded as dormant linked data rather than declared reachable behavior. ## Review matrix | Property | Result | |---|---| | Exact E118 operation reporting | PROVEN_OFFLINE_FROM_SOURCE_AND_TESTS | | Stop before I04 after E118 | PROVEN_OFFLINE_FROM_SOURCE_AND_DISASSEMBLY | | Submit errno capture ordering | PROVEN_OFFLINE_FROM_SOURCE | | Unified first-frame value | PROVEN_OFFLINE_FROM_SOURCE | | Byte-reproducible ELF and map | PROVEN_OFFLINE | | Firmware-9.60 runtime behavior | UNPROVEN | | Exact blocked operation for the consumed H run | UNPROVEN | | Submit errno on firmware 9.60 | UNPROVEN | | Visible presentation | UNPROVEN | | Complete target cleanup and safe exit | UNPROVEN | The normal SDK CRT and its documented runtime effects remain inherited. The early fail-closed return occurs before driver initialization, but the complete loader/process cleanup path is still not firmware-proven. Every artifact and authorization gate remains false. No device action is authorized.