{ "schema_version": 1, "phase": "0.8", "preflight_id": "phase08-offline-admissibility-2026-07-18", "scope": "offline_admissibility_audit_only", "date": "2026-07-18", "timezone": "Europe/Brussels", "operator": "Codex", "decision": "READ_ONLY_PREFLIGHT_BLOCKED", "dataset_complete": false, "open_stop_ro": true, "open_stop_gate": true, "on_device_session_started": false, "authorization": { "explicit_read_only_preflight_permission_recorded": false, "permission_reference": null, "permission_exact_text": null, "connection_authorized": false, "installation_authorized": false, "lifecycle_authorized": false, "execution_authorized": false, "automatic_retry": false }, "ps5_actions": { "connected": false, "file_created": false, "file_modified": false, "file_deleted_or_renamed": false, "configuration_changed": false, "service_started_stopped_or_restarted": false, "process_signaled": false, "artifact_transferred": false, "artifact_executed": false, "autoload_activated": false, "automatic_retry_performed": false }, "collector_assessment": { "selected_collector": null, "can_prove_no_atime_audit_cache_or_metadata_change": false, "writes_output_or_logs_on_ps5": "unknown_no_collector_selected", "candidates": [ { "id": "payload_manager_v0_3_1_http", "version": "0.3.1", "origin": "itsPLK/ps5-payload-manager", "source_commit": "cfbc70f30f419b09bf2b52283f7409e2d3117ee1", "usable": false, "result": "STOP-RO", "reasons": [ "Every handled non-OPTIONS request calls log_server_set_active(), which writes server_active_flag in process memory.", "The /autoload_status route calls pldmgr_autoload_get_status(), which writes autoload_triggered = 1 before returning status.", "The /autoload_status and /get_config routes open /data/pldmgr/autoload.txt for reading; no no-atime mount or open guarantee is proven.", "Non-noisy routes call pldmgr_log(), which writes stdout and the in-process log ring." ] }, { "id": "unspecified_filesystem_collector", "version": null, "origin": null, "source_commit": null, "usable": false, "result": "STOP-RO", "reasons": [ "No exact collector, version, transport, operation set, or source was supplied.", "No proof excludes atime, audit-log, cache, filesystem-metadata, process-state, or on-device log changes." ] } ] }, "firmware": { "expected_exact": "9.60", "source_1": { "kind": "user_attestation", "value": "9.60", "current_device_read": false }, "source_2": null, "two_current_sources_agree": "UNPROVEN", "result": "STOP-GATE" }, "current_live_state": { "stock_elfldr": { "expected_size": 397000, "expected_sha256": "092d16ee0ede0c494947efd38d1a17bbd7cc4b022d3858ea898833c188c703e8", "path": null, "object_identity": null, "metadata": null, "pre_post_stable": "UNPROVEN", "current_hash_match": "UNPROVEN", "result": "STOP-GATE" }, "stock_payload_manager": { "expected_size": 2050320, "expected_sha256": "518740adbacccb9094fadb07dd424c53ee290f38306449ccc9d6957fdf813c0b", "path": null, "object_identity": null, "metadata": null, "pre_post_stable": "UNPROVEN", "current_hash_match": "UNPROVEN", "result": "STOP-GATE" }, "processes_and_services": { "complete": false, "unknown_or_unmapped_relevant_processes": "UNPROVEN", "result": "STOP-GATE" }, "listeners": { "required_ports": [ 8084, 8085, 9021 ], "complete": false, "unambiguous_owners": "UNPROVEN", "no_conflict_or_unexpected_exposure": "UNPROVEN", "result": "STOP-GATE" }, "autoload_startup_retry": { "authoritative_sources_complete": false, "lifecycle_probe_absent_from_autoload": "UNPROVEN", "hardened_runtime_absent_from_autoload": "UNPROVEN", "automatic_retry_inactive": "UNPROVEN", "result": "STOP-GATE" } }, "rollback_preconditions": { "separate_destination": { "minimum_content_bytes": 2447320, "path": null, "separate_device": "UNPROVEN", "available_bytes": null, "filesystem_reserve_assessed": false, "result": "STOP-GATE" }, "stock_elfldr_backup": { "already_present": "UNPROVEN", "path": null, "expected_size": 397000, "expected_sha256": "092d16ee0ede0c494947efd38d1a17bbd7cc4b022d3858ea898833c188c703e8", "exact_separate_object": "UNPROVEN", "restore_mapping_unambiguous": "UNPROVEN", "result": "STOP-GATE" }, "stock_payload_manager_backup": { "already_present": "UNPROVEN", "path": null, "expected_size": 2050320, "expected_sha256": "518740adbacccb9094fadb07dd424c53ee290f38306449ccc9d6957fdf813c0b", "exact_separate_object": "UNPROVEN", "restore_mapping_unambiguous": "UNPROVEN", "result": "HARD_STOP-GATE" } }, "blockers": [ { "id": "explicit_permission_record_absent", "severity": "STOP-RO", "minimum_missing_evidence": "Artifact-independent exact permission text and a stable task reference authorizing only this read-only preflight." }, { "id": "collector_side_effect_freedom_unproven", "severity": "STOP-RO", "minimum_missing_evidence": "A pinned public collector and transport whose complete source and environment prove no file, metadata, audit-log, cache, process-state, network-service-state, or on-device log mutation." }, { "id": "payload_manager_http_mutates_runtime_state", "severity": "STOP-RO", "minimum_missing_evidence": "A different collector path; the reviewed stock Payload Manager HTTP path cannot satisfy this Phase-0.8 contract." }, { "id": "two_source_firmware_attestation_absent", "severity": "STOP-GATE", "minimum_missing_evidence": "Two authoritative current read-only firmware observations that agree exactly on 9.60." }, { "id": "current_live_identity_and_topology_absent", "severity": "STOP-GATE", "minimum_missing_evidence": "Stable pre/post paths, object IDs, metadata, sizes, hashes, processes, services, and listener ownership from an admissible collector." }, { "id": "autoload_startup_retry_state_absent", "severity": "STOP-GATE", "minimum_missing_evidence": "All authoritative current autoload, startup, and retry sources collected without side effects." }, { "id": "stock_elfldr_backup_unproven", "severity": "STOP-GATE", "minimum_missing_evidence": "An already-present, separate, byte-exact stock elfldr backup and unambiguous restore mapping." }, { "id": "stock_payload_manager_backup_unproven", "severity": "HARD_STOP-GATE", "minimum_missing_evidence": "An already-present, separate, byte-exact stock Payload Manager backup and unambiguous restore mapping." } ], "source_evidence": [ { "component": "Payload Manager HTTP dispatch", "path": "src/http_server.c", "sha256": "35cf5d8f0dd44cf64ceab5e4b0ecc09413c82d7e9946ba9de2ca4b1898631fdd", "source_commit": "cfbc70f30f419b09bf2b52283f7409e2d3117ee1", "relevant_lines": [ "131-152", "479-481", "835-930" ] }, { "component": "Payload Manager autoload state", "path": "src/autoload.c", "sha256": "7051cab3ee1a3e0b9f6498000565eb9e160b9c63efa1771f250e98ec3aa4ae67", "source_commit": "cfbc70f30f419b09bf2b52283f7409e2d3117ee1", "relevant_lines": [ "33-49", "51-93" ] }, { "component": "Payload Manager log state", "path": "src/log_server.c", "sha256": "659095f43df1bbe8eb24acb165f027edc277af1e60aabb26ba9e3920b233d6f1", "source_commit": "cfbc70f30f419b09bf2b52283f7409e2d3117ee1", "relevant_lines": [ "12-55" ] } ], "historical_evidence_is_not_current_preflight_evidence": true, "payload_manager_backup_exactly_present": "UNPROVEN", "installation_approval_after_preflight": "NOT AUTHORIZED", "lifecycle_approval_after_preflight": "NOT AUTHORIZED" }