# Phase 1.0R: PS5 launch-context comparison Status: `NO_SOURCE_PROVEN_LAUNCH_CONTEXT_FIX_TARGET_CHANGE_BLOCKED` Date: 2026-07-22 This is an offline source, map, and provenance audit. It did not build target code, connect to the PS5, transfer an artifact, receive a device result, or execute anything on the PS5. Phase-1.0O authority remains consumed and every authorization remains false. ## Question and evidence boundary Phase 1.0O proved that the exact M artifact opened VideoOut, registered its buffers, and received `-1` with saved errno `0` from the first `sceVideoOutSubmitFlip(handle, 0, 1, 0)`. Phase 1.0R asks whether the raw elfldr path differs, in a source-proven way relevant to that call, from the launch context used by existing PS5 SDL ports. The comparison is bounded to these exact clean source identities: | Component | Commit | Relevant evidence | |---|---|---| | Chimera RetroArch | artifact source `12cf1d783c41eb303987e49a5a920805a59ef7a4`; inspected HEAD `606909706f91d7213751c245081333f56c2cce89` | `Makefile.ps5`; exact M map and artifact identities | | PS5 Payload SDK | `d2e2e585740362976a39fdd5ccf390f199a7bc37` | `crt/crt.c`, `toolchain/prospero.mk` | | PS5 SDL | `0baf4ac49382b537ba449901b5b6d0d189bb1fbb` | `src/main/ps5/SDL_ps5_main.c`, `src/video/ps5/SDL_ps5video.c` | | hardened elfldr | `197623058f509eddde18868dafcb92fdcac66464` | `elfldr.c`, `socksrv.c` | | controlled Payload Manager | `e23d94ff91233aa770e2342800c1467875bdef44` | `src/ps5_launcher.c`, `src/main.c` | | PacBrew recipes | `c2abcfcb60f569128abd0e8e70ad03a67bee5ea7` | SDL2 and port recipes | | LakeSnes reference | `a2db690123649c7ffbc68a663af31efb3a41bf3f` | `Makefile.prospero`, `main.c`, `homebrew.js`, `README.prospero` | The official port archives retained from Phase 1.0Q are source references, not deployed-artifact or on-device launch evidence. ## Exact compared paths ### Direct raw ELF and Payload Manager The hardened elfldr listener sends every accepted raw ELF through `payload_spawn()` in `socksrv.c`, then through `elfldr_spawn()` in `elfldr.c`. That routine creates a process with `rfork_thread`, executes the system `SceSpZeroConf` image, replaces its executable mapping under ptrace, and detaches. The legacy route duplicates the accepted descriptor to standard input/output/error; the controlled route changes standard-I/O and watchdog policy. Neither route registers an application, title ID, flip owner, or display context. Payload Manager's `ps5_launch_elf()` reads the selected ELF and sends it to loopback port 9021. It does not create a distinct payload process. Therefore both a direct host send and a Payload Manager launch reach the same `payload_spawn()`/`elfldr_spawn()` process constructor. Payload Manager does contain separate LNC-based disc-player management, but that path is not the ELF process constructor and is not evidence of payload display ownership. ### Exact RetroArch artifact `Makefile.ps5` links `libSDL2.a`, but not `libSDL2main.a`. The exact M linker map proves `_start` comes from SDK `crt1.o` and includes `SDL_ps5video.c.o`. It contains no `SDL_ps5_main.c`, no `libSDL2main`, and no `sceSystemServiceLoadExec`; it does import `sceSystemServiceHideSplashScreen` through SDL video initialization. SDK `_start(payload_args_t *)` initializes its runtime, invokes the ordinary `main(argc, argv, environ)`, finalizes, and terminates according to the SDK payload contract. The inspected CRT contains no application/title registration and no LNC or VideoOut ownership setup. ### SDL2main ports At the pinned SDL commit, PS5 SDL2main is only this lifecycle wrapper: 1. `sceSystemServiceHideSplashScreen()`; 2. `SDL_main(argc, argv)`; 3. after `SDL_main` returns, `sceSystemServiceLoadExec("exit", 0)`. It contains no app registration, title-ID selection, LNC call, process creation, VideoOut call, or flip-owner acquisition. The `LoadExec` operation is post-return and cannot affect the first VideoOut submit. The exact SDL PS5 `PS5_VideoInit()` independently calls `sceSystemServiceHideSplashScreen()` immediately before `sceVideoOutOpen(0xff, 0, 0, NULL)`. Consequently the tested RetroArch path already performs the only SDL2main pre-entry action relevant by name before opening VideoOut. Linking SDL2main would merely perform that call earlier and again; no public source proves that this changes display ownership. LakeSnes does link `-lSDL2main -lSceSystemService` and defines `SDL_main`. Its `homebrew.js` returns an executable path and arguments, while its README describes `hbldr` through `ps5-payload-shsrv`. These are launcher references, not source for application registration. The exact `hbldr`/`shsrv` process constructor and its active-app state were not present in this bounded source set, so the launch-context relationship is `PARTIAL_UNBOUND`. ## Comparison matrix | Property before first submit | Direct host to elfldr | Payload Manager to elfldr | SDL2main-linked port | Evidence result | |---|---|---|---|---| | process constructor | hardened `elfldr_spawn` | same hardened `elfldr_spawn` | launcher-dependent | first two proven same; port launcher unbound | | SDK CRT | `crt1.o` | `crt1.o` | ordinarily `crt1.o` through `prospero.mk` | same SDK model in inspected builds | | splash hide | SDL `VideoInit` | SDL `VideoInit` | wrapper plus SDL `VideoInit` | only proven pre-submit difference is earlier duplicate call | | SDL application entry | ordinary RetroArch `main` | ordinary RetroArch `main` | wrapper calls `SDL_main` | symbol/lifecycle difference only | | post-return exit | SDK termination | SDK termination | `LoadExec("exit")` before wrapper returns | post-submit lifecycle only | | title/app registration | absent in inspected path | absent in ELF launch path | absent in SDL2main | no source-proven registration | | flip/display ownership | absent in inspected path | absent in ELF launch path | absent in SDL2main | unproven everywhere | | autoload or persistent setup | none in launch route | none required by ELF launch route | launcher-dependent | no evidence of a required fix | ## LNC log classification Phase 1.0O ordinary stdout repeatedly included `getAppStatus: LNC_ISOK::0x80940004`. It is `OBSERVED_NONUNIQUE_CORRELATION`: the trace does not identify its caller, multiple system-service/video activities can interleave, and public source does not define that value as the cause of the flip failure. It is not a root-cause verdict and does not justify adding LNC calls. ## Decision `SDL2main` is not a source-proven launch-context correction. PacBrew is a build/package repository, not a launcher. The official port metadata points to launchers whose exact process/app/display setup remains unbound. The possibility that active-app or launcher state matters therefore remains plausible but unproven. The root cause is unresolved. Do not link SDL2main as an experiment, add LNC or SystemService calls, change submit parameters, call another VideoOut export, build a target, or perform a device action under Phase 1.0R.