# Phase 1.0T: inactive shsrv identity-collection gate Status: `INACTIVE_METADATA_GATE_DESIGNED_EXACT_IDENTITY_UNAVAILABLE` Date: 2026-07-22 This phase designs host-only controls. It does not contain a network client, target address, command sender, target code, artifact, active approval, or device authorization. No connection or PS5 request was performed. ## Feasibility result The existing shsrv protocol cannot attest the exact deployed binary: - the greeting exposes a compile date/time but no source commit or binary SHA-256; - `help` exposes a command-set fingerprint, which can identify a source family but not a byte-exact build; - `stat` exposes size and filesystem metadata only; - `sum` opens the target read-only and computes a 16-bit rotating checksum, not a cryptographic digest; - no existing command returns a binary-safe full-file stream or SHA-256; - a PacBrew path or official release identity is not a live-path identity. The strongest permitted future result is `WEAK_FILE_CORRELATION_ONLY`. It must never be labelled `EXACT_DEPLOYED_IDENTITY`, `RUNTIME_VERIFIED`, or recovery proof. ## Mandatory connection side effects Even before the operator sends a command, a connection to port 2323 causes shsrv to: 1. accept a socket and spawn an embedded `sh.elf` through its ELF loader; 2. create a new session, pipes, a thread, telnet state, heap allocations and process-local environment; 3. query model, serial number, firmware, SoC/CPU temperatures and CPU frequency; 4. send those values plus the compile timestamp in the greeting. The serial is sensitive and unrelated to launcher identity. A future approved collector must discard it before persistence and must never print it to Codex, logs, manifests, filenames, screenshots, or commits. Temperature/frequency values must also be discarded because they add no provenance value. The offline parser in `tools/phase10t_shsrv_transcript.py` enforces this for an already-supplied transcript, but it is not a network client. ## Command-effect matrix | Command or event | Source behavior | Identity value | Future gate | |---|---|---|---| | connect/greeting | spawns shell; exposes serial and telemetry | compile metadata | separate explicit acceptance required | | `help` | current source allocates/sorts command entries; v0.7 uses a static map | source-family fingerprint | first and only initial command candidate | | `stat ABS_PATH` | metadata query; current implementation runs in a forked helper | size/times only | exact pre-attested path only | | `sum ABS_PATH` | `O_RDONLY`, full read, 16-bit rotate checksum; forked helper | weak correlation only | exact pre-attested path only | | `ps`/`procstat` | exposes broad process/app information | unnecessary | excluded | | `env`/`sysctl` | may expose unrelated or sensitive state | unnecessary | excluded | | `ls`/`find` | directory discovery/path expansion | path guessing | excluded | | `cat`/`hexdump` | unframed content over telnet | not binary-safe | excluded | | `hbldr`/`exec`/`launch` | launches or replaces a process | none for identity | permanently forbidden here | | every write/mount/signal command | mutation | none | permanently forbidden here | For current source, `stat` and `sum` use `fork=true`: the command helper uses `rfork_thread`, allocates a 4 MiB stack, changes its budget and duplicates descriptors. In v0.7 these commands execute through an embedded core ELF. A read-only filesystem operation therefore still has process and scheduler side effects. `sum` may additionally affect atime, caches and I/O accounting. ## Offline transcript model The parser accepts text only through standard input and optionally retains metadata for literal `--expected-path` values. It: - retains no serial, model, temperature, frequency, raw transcript or unknown path; - fingerprints sorted command names; - recognizes the exact official v0.7 and v0.19 source-family fingerprints; - labels the 16-bit checksum `BSD_ROTATE_16` and non-cryptographic; - always emits `exact_identity=false`; - imports no socket, HTTP or URL client and writes no file. Official source fingerprints are: | Source | Commands shown by `help` | SHA-256 of sorted names | |---|---:|---| | v0.7 | 44 | `40313637116b532f3c7f9bebe2c23c0018fe7d4093840cf463a22ba0314ca021` | | v0.19 | 50 | `f41168292e205590bda1d243cdf727044e0af280a89fb0c070f4c5d6c92f2fd7` | A fingerprint match is still only a source-family candidate because builds can change while preserving the command set. ## Future operational windows—not authorized ### Window T1: manual host facts Without touching the PS5, the operator may later identify the original local shsrv binary, source URL, download date, filename, size and host SHA-256. This creates a local candidate only. No binary was found during Phase 1.0T. ### Window T2: greeting and `help` Requires new exact authorization, an already-running listener attestation, one connection, no scan, no reconnect and explicit acceptance of shell spawning and automatic serial/telemetry reads. The collector must redact before any persistence. Only `help` may be sent. Failure or mismatch ends the window. ### Window T3: one exact path Requires separate authorization and a path supplied from independent evidence. One fresh connection may issue `stat` and optionally `sum` for that path only. No wildcard, relative path, shell expansion, pipe, redirection, semicolon, newline injection, directory listing or path guessing is allowed. ### Window T4: fake-app metadata Requires separate authorization. Only `stat` of the fixed source-bound `FAKE00000` paths may be considered. It must not call hbldr, create missing paths, remount, repair, delete or inspect file contents. ## Hard stops - listener presence is not independently attested; - address, exact path, command list or consent is absent; - raw serial could reach persistent output; - protocol framing or prompt is not recognized; - any response is partial, malformed or exceeds its bound; - any automatic retry, reconnect, resume or fallback is configured; - any command outside the separately approved literal list is requested. Phase 1.0T does not authorize any of these future windows.