# Phase 1.0A build and artifact results ## Result `RETROARCH_PS5_SOFTWARE_PORT_BUILT` Both outputs are real RetroArch v1.22.2 frontends built from fork commit `ca1b45680577befc743e1c92fa40687e1b1745e7`. They link the upstream frontend/runloop and the static `chimera_smokecore`; the software target also links RGUI and the reviewed PS5 SDL2 software backends. They were not run. | Profile | Local output | Size | SHA-256 | Map SHA-256 | | --- | --- | ---: | --- | --- | | headless | `build/phase10a/final/retroarch_ps5_headless.elf` | 722392 | `fd595a826f64d18598be0b55e539bb524b33bd469b98f62c958ee50acb544628` | `fb935f7a768c91408a87290f03bad8ed59f5061de75232d5660957eff8ec017f` | | software/RGUI | `build/phase10a/final/retroarch_ps5_software.elf` | 3318432 | `7beb09592404b5c1fb4161c632171d2901f3715db26e59458998690e8c49f3fc` | `1573a9951fa53bfa1bf304e0038e6f049f859fbfbe92f6a895196dc283c27597` | The paths are relative to the separate `chimera-retroarch` repository. The ELFs and maps are ignored local build outputs, not files in `chimera-gfx` and not transfer, execution or installation packages. ## Builds and reproducibility Every target comparison used fork commit `ca1b45680577befc743e1c92fa40687e1b1745e7`, SDK commit `d2e2e585740362976a39fdd5ccf390f199a7bc37`, `SOURCE_DATE_EPOCH=1763597828`, `TZ=UTC` and `LC_ALL=C`. Each repetition invoked `make ... clean` to completion before a separate `make ... -j4 all`. An earlier concurrent `make clean all` experiment was rejected as a race and is not evidence. | Comparison | ELF | Linker map | | --- | --- | --- | | headless A versus B | byte-identical | byte-identical | | software A versus B | byte-identical | byte-identical | Compiler flags include warnings-as-errors, `-O2`, no debug data, source-prefix maps, section garbage collection, `--as-needed` and `--build-id=none`. The cross compiler reports Clang 18.1.8 for `x86_64-sie-ps5`; GNU Make 4.4.1 was used under WSL2. The static SDL2 archive is 3120572 bytes with SHA-256 `353065505f54e71fa8f7fff41e090dce52f39fe2aaafab85c4653648fc5f1b56`. It was built from commit `0baf4ac49382b537ba449901b5b6d0d189bb1fbb` plus the 5195-byte reviewed overlay whose SHA-256 is `b547260d8af40ce2360575ab7831c009036c1f35f8b525cad6fd376dc5ca9d6b`. ## Host integration result The host harness compiled with GCC 15.2.0, `-Werror`, AddressSanitizer and UndefinedBehaviorSanitizer, with leak detection enabled. It completed: - 600 frames; - video FNV-1a-64 `43f920496eb5f435`; - audio FNV-1a-64 `a48f47dc08c56625`; - digital and analog input mapping: pass; - Start-driven libretro shutdown callback: pass; - init/deinit and ASan/UBSan/leak checks: pass; - PS5 port structural validator: pass. This is host evidence for the core and source contracts, not PS5 runtime evidence. ## ELF audit Both files are ELF64 little-endian x86-64 System V PIE/DYN binaries, dynamically linked and not stripped. Neither has an interpreter, build ID, GNU-stack program header, ELF TLS segment, `.tdata` or `.tbss`. Both have 20 section headers; `.init_array` and `.fini_array` exist with zero size. The full section set is `.text`, unwind tables, dynamic symbol/hash/string/relocation tables, `.data.rel.ro`, `.got`, `.rodata`, empty init/fini arrays, `.dynamic`, `.data`, `.bss`, `.comment` and static symbol/string tables. | Field | Headless | Software/RGUI | | --- | ---: | ---: | | Entry point | `0x47d10` | `0x1c29c0` | | Program headers | 4 | 4 | | First LOAD | offset `0x4000`, size `0x4e570`, RWE | offset `0x4000`, size `0x1c93e0`, RWE | | Other LOADs | two RW | two RW | | `.rela.dyn` entries | 610 | 3373 | | Dynamic symbols | 79 | 220 | | Full symbols | 1387 | 7256 | | Defined global symbols | 719 | 2403 | | Undefined symbols/imports | 73 | 210 | The executable first LOAD segment is also writable because the pinned SDK linker script co-locates text that way. This is a material W^X weakness and a future execution risk; offline build success does not waive it. The linker maps prove inclusion of `frontend/drivers/platform_ps5.o` and `cores/chimera_smokecore/chimera_smokecore.o` in both targets. The software map additionally proves inclusion of `SDL_ps5video.c.o`, `SDL_ps5audio.c.o` and `SDL_ps5joystick.c.o`, while PS5 keyboard and IME objects are absent from the final link. ## Dynamic dependencies and imports Headless `DT_NEEDED`: - `libkernel_web.sprx`; - `libSceLibcInternal.sprx`. Software/RGUI additionally needs: - `libSceVideoOut.sprx`; - `libScePad.sprx`; - `libSceUserService.sprx`; - `libSceSystemService.sprx`; - `libSceAudioOut.sprx`. `--as-needed` removes the SDK's otherwise unconditional SceNet dependency. There are no undefined socket/network, `dlopen`/`dlsym`, module-loader, GNM, mount, reboot or console-shutdown symbols. The software target's complete Sce API import set is AudioOut init/open/output/close; direct-memory and equeue allocation/wait/release; Pad init/open/read/close plus linked-but-not-required lightbar/vibration calls; UserService initialization/user queries; `sceSystemServiceHideSplashScreen`; and VideoOut open/register/flip/event/ close operations. Full ordered import lists are in `manifests/retroarch/phase-1.0a-artifacts.json`. Generic RetroArch code keeps write-capable libc imports. Headless includes `fopen`, `ftruncate`, `fwrite`, `mkdir`, `open`, `remove`, `rename` and `write`; software also includes `setenv`. The fixed PS5 startup path blocks configuration reads, supplies no content/config/SRAM/state/core/data path and compiles the normal shutdown-save paths out. The claim is therefore control-flow-specific, not global absence of write-capable code. ## Entry, shutdown and static reachability Source and disassembly agree on this entry sequence: `_start` clears BSS, performs the inlined SDK `payload_init` sequence (`__crt_syscall_init`, `__kernel_init`, `__klog_init`, `__isthreaded`, `__patch_init`, `__rtld_init`), constructs the SDK payload runtime, calls `main`, which tail-jumps to `rarch_main`, then runs SDK fini/close/destroy and termination handling. RetroArch selects `frontend_ctx_ps5`, performs a contentless static-core launch, enters `runloop_iterate`, and reaches the linked `retro_run`. Start requests the normal RetroArch/core shutdown path; `retro_deinit` and the PS5 frontend deinit/shutdown callbacks are linked. The SDK source and linked disassembly also prove that startup is not kernelwrite-free: `__patch_init` reaches credential-capability/attribute changes and syscall-bound writes through `kernel_copyin/out`. Those effects are accepted for this authorized offline link milestone under the existing ADR boundary, but remain unexecuted and hardware-unproven. ## String and policy audit No personal absolute host path, credential, PS5/device address, install route, Payload Manager modification, elfldr modification, lifecycle probe, deploy client or execution helper was found. The generic RetroArch string pool keeps `udp://127.0.0.1:`, an RTMP template, overlay “autoload” labels and downloader localization even though networking, updater, dynamic cores and autoload routes are compiled out. The software pool also yields byte-pattern false positives `0.1.2.3` and `4.5.6.7`. SDK RTLD name tables contain module/dlsym strings, but none is an undefined application import. Full local audit output for each target contains the file classification, ELF/readobj dump, complete symbols and undefined symbols, relocations, disassembly, startup/shutdown slices and strings under `build/phase10a/audit/{headless,software}` in `chimera-retroarch`. The Chimera GFX secretscan passed across 658 text files and a clean archive of all 21 fork-delta files passed separately. A whole-upstream RetroArch scan also identified the pre-existing BearSSL sample private-key fixtures and mbedTLS parser/writer source literals; these are official baseline dependency test/source material, not additions or credentials introduced by this port. No PS5 connection, request, transfer, execution, installation, autoload or device write occurred.