19 KiB
Firmware compatibility
Firmware 9.60 remains the only exact firmware in scope. Separately approved
Phase-1.0D runs have proven SDK CRT/main/notification execution on that device,
but they do not prove the Phase-0 capability probe, GNM, general VideoOut,
rendering, cleanup or compatibility of any other artifact. On 2026-07-22 the
exact Phase-1.0E result artifact received and consumed one single-use
authorization; all authorization fields are again false.
| Firmware | Discovery build | Probe executed | Result | Evidence | Rendering |
|---|---|---|---|---|---|
| none | no | no | unknown | no hardware authorization | prohibited |
9.60 |
yes, offline only | no | unknown; SDK CRT execution blocker | docs/evidence/probe-9.60-offline-2026-07-17.md |
prohibited |
9.60 Phase 0.6 lifecycle |
no artifact built | no | blocked: exact loader has unbounded/unknown effects | docs/runtime/phase-0.6-loader-audit.md |
prohibited |
9.60 Phase 0.7 lifecycle |
yes, offline only | no | hardened runtime ready for a separately approved installation; hardware behavior unproven | docs/runtime/phase-0.7-hardening.md |
prohibited |
9.60 Phase 0.8 preflight |
no new artifact | no | read-only on-device preflight blocked: collector side-effect freedom and current rollback state unproven | docs/runtime/phase-0.8-read-only-preflight.md |
prohibited |
9.60 Phase 0.9A anti-brick |
no target artifact | no | offline design only; filesystem atomicity, durability and independent recovery unproven | docs/runtime/phase-0.9-installation-transaction-design.md |
prohibited |
9.60 Phase 0.9B observer |
no target artifact | no | blocked before build: startup/exit ABI and non-persistent output channel unproven | docs/runtime/phase-0.9b-bounded-observer-design.md |
prohibited |
9.60 Phase 0.9C feasibility |
no target artifact | no | blocked: startup/exit/cleanup, current bounded output, firmware source two, and observation effects remain unproven | docs/runtime/phase-0.9c-static-audit.md |
prohibited |
9.60 Phase 0.9D readback |
no target artifact | no | blocked: existing stack has no PS5-to-host file response; live paths and recovery remain unproven | docs/runtime/phase-0.9d-readback-feasibility.md |
prohibited |
9.60 Phase 0.9E-R provenance |
no target artifact | no | local outer Y2JB backup does not match any current official asset; official source has no 9020 listener implementation | docs/runtime/phase-0.9e-r-official-release-correlation.md |
prohibited |
9.60 Phase 0.9E-R2 inner provenance |
no target artifact | no | local inner differs from the mandatory official and selected community inners; MediaFire maker/source and deployment remain unbound | docs/runtime/phase-0.9e-r2-final-provenance-decision.md |
prohibited |
9.60 Phase 1.0D RUN A/B |
yes, exact one-shot artifacts | yes, two separately authorized runs | C1 proves SDK CRT/main/notification; RUN-B stage remains unclassified because its notification was unreadable | docs/retroarch/phase-1.0e-device-observations.md |
unproven |
9.60 Phase 1.0E result channel |
yes, exact one-shot artifact | yes, one authorized run | inherited stdout returned valid D00-D02 with platform result 0; remote EOF before D03; permission consumed |
docs/retroarch/phase-1.0e-inherited-result-channel.md |
unproven beyond D02 |
9.60 Phase 1.0F interval diagnostic |
yes, offline exact artifact | no | I00-I14 source interval prepared and statically audited; no device authorization | docs/retroarch/phase-1.0f-startup-interval.md |
unproven beyond D02 |
9.60 Phase 1.0G interval run |
exact one-shot artifact | yes, consumed | valid through I03; deterministic no-argument/no-menu help exit before I04 | docs/retroarch/phase-1.0g-device-result.md |
SDL/VideoOut unproven |
9.60 Phase 1.0H startup args |
yes, offline exact artifact | no | scoped argc-2 correction built and statically audited; no device authorization | docs/retroarch/phase-1.0h-startup-args.md |
unproven beyond I03 |
9.60 Phase 1.0H one-shot run |
exact one-shot artifact | yes, consumed | I04 and SDL/VideoOut reached; buffers registered; first flip submit and SDL init returned -1 |
docs/retroarch/phase-1.0h-device-result.md |
visible flip unproven |
9.60 Phase 1.0I postmortem |
no new artifact | no new run | offline source/map/disassembly binds submit (handle,0,1,0); exact E118 operation, submit errno and root cause remain unproven |
docs/retroarch/phase-1.0i-flip-and-write-analysis.md |
no new rendering evidence |
9.60 Phase 1.0J-1.0O diagnostics/results |
exact offline artifacts and consumed one-shot runs where recorded | only separately authorized J/K/O attempts | first blocked write was MKDIR; write-free M reached VideoOut but first flip still returned -1; all permissions consumed |
docs/retroarch/ Phase-1.0J through O records |
visible presentation and cleanup unproven |
9.60 Phase 1.0P-1.0S analysis |
no new target artifact | no new run | public VideoOut semantics and a source-proven launch-context fix remain unavailable; hbldr/shsrv is only a source candidate | docs/retroarch/ Phase-1.0P through S records |
parameter or launcher change blocked |
9.60 Phase 1.0T-1.0AY offline route design |
host-only models and source audits | no device request | deployed shsrv identity remains unknown; result-channel, launch-context, protocol and exact source-base work are offline only | docs/retroarch/ Phase-1.0T through AY records |
no firmware/rendering evidence |
Rules
- A firmware row is added only for an exact, reproducible identifier.
- Build allowlisting is not runtime compatibility evidence or execution permission.
symbol presentmeans only that lookup returned non-null on that observation.- Presence does not establish signature, semantics, or rendering compatibility.
- Failure on an unlisted firmware is the expected fail-closed behavior.
- Compatibility does not transfer between firmware revisions.
- Every observation must reference the source commit, manifest hash, SDK lock, approval, and redacted crash/probe log.
The build cache variable CHIMERA_GFX_PS5_ALLOWED_FIRMWARE defaults to NONE.
Changing it is a deliberate build action, not a repository compatibility claim
and not permission to execute the artifact.
The default capability-probe and every VideoOut review artifact embed NONE.
The 9.60 capability artifact has its own digest, manifest, and offline review.
It remains execution-blocked because the pinned SDK payload CRT writes kernel
process state before main. VideoOut is not allowlisted for 9.60 and also
remains blocked by the unproven bounded-wait requirement in
docs/phase1/HARDWARE_TEST_PLAN.md.
Phase 0.5 did not create a firmware-9.60 startup artifact: the exact loader
caller, return, cleanup, crash, and pre-entry contract is unproven. The older
9.60 probe hash 4be1c17b4964f2b68c39b5145bc4af4619c32512d60269ecf5c39728b390fa63
is permanently denylisted independent of future firmware or approval records.
Phase 0.6 exactly matched the installed Payload Manager v0.3.1 and elfldr
v0.23, but the firmware identifier is still user-attested rather than
device-attested. The lifecycle remains blocked by unbounded ptrace/payload
runtime, unproven return and cleanup, incomplete restoration, absent
launch-time hash enforcement, and the manager's persistent upload path.
__patch_init is now a documented payload-process-local effect and is not by
itself the blocker.
Phase 0.7 uses new private hardened elfldr and controlled Payload Manager
artifacts rather than reclassifying the old binaries. Exact firmware 9.60 is
explicitly confirmed by Jens but has not been queried from the device in this
task. Offline compiler, linker, test, disassembly, callgraph, and
reproducibility evidence supports
READY_FOR_HARDENED_RUNTIME_DEPLOYMENT. This is not an installed, transferred,
executed, or compatibility-tested state, and it authorizes no console action.
Phase 0.8 preserves that static Phase-0.7 decision but blocks the operational read-only preflight before any connection. The stock Payload Manager HTTP interface mutates in-process state, and no alternative collector currently proves freedom from atime, audit, cache, metadata, service, or logging side effects. Firmware 9.60 remains user-attested rather than confirmed by two current device sources.
Phase 0.9A does not add firmware evidence. Its virtual host model cannot prove
PS5 filesystem identity, atomic switch, file or directory durability,
power-loss behavior, quiescence or independent recovery. Every such property
remains UNPROVEN, all device authorizations remain false, and no target
artifact is built.
Phase 0.9B also adds no firmware evidence. The normal SDK startup path violates the phase's kernelwrite-free rule, a freestanding return/exit cleanup contract is unproven, and the hash-bound controlled loader route does not return payload output. The observer build stops before source or artifact creation. Firmware 9.60 remains user-attested and runtime-unproven.
Phase 0.9C identifies SDK kernel_get_fw_version() as source 1, but that
function reads a libSceLibcInternal process-parameter SDK field and has no
runtime observation in this phase. The SDK stub name
sceKernelGetProsperoSystemSwVersion has no accepted public signature,
semantics, side-effect contract, or firmware-9.60 evidence and is not source
2. The host result record can bind two exact values to a nonce, request ID and
artifact hash, but no target output implementation exists. Firmware agreement
therefore remains BLOCKED_FIRMWARE_SOURCE_INCOMPLETE.
Phase 0.9D adds no firmware evidence and performs no device request. Its local
source audit finds only host-to-PS5 upload/launch and internal read paths, not a
binary-safe PS5-to-host component download. Configured, packaged, and
historical reference paths are not current live-path evidence. Firmware 9.60
therefore remains user-attested and runtime behavior remains UNPROVEN.
Phase 0.9E also adds no firmware evidence. The local Y2JB-named backup
candidate covers firmware 4.03 through 12.40 only by filename claim; its opaque
SIECAF content cannot be tied to the exact firmware-9.60 deployment or to an
auditable port-9020 listener. No bootstrap, restart, host-to-memory, output,
filesystem, autoload, crash, or reboot property was tested on hardware.
Firmware 9.60 remains user-attested and runtime behavior remains UNPROVEN.
Phase 0.9E-R confirms only that official release 1.6 source permits Lapse's version-selection path through firmware 10.01. Because the local outer backup matches no current official asset, that source logic is not bound to the deployed bytes and is not runtime compatibility evidence for firmware 9.60.
Phase 0.9E-R2 adds no firmware evidence. Full host-side inner and SIECAF
comparisons are negative, and the MediaFire page exposes no source binding.
Even a positive structural or byte match would not prove current deployment.
Firmware 9.60 remains user-attested and runtime behavior remains UNPROVEN.
Phase-1.0D RUN A changes one narrow firmware statement: the operator visibly
observed the exact C1 marker, proving that hardened elfldr reached the normal
SDK CRT, main and the notification ABI on the firmware-9.60 console for that
exact canary hash. RUN B produced one unreadable notification and therefore
does not identify a D-stage. Phase-1.0E RUN C adds exact artifact-bound evidence
for D00-D02 and the inherited result channel. D02 reported platform result 0;
remote EOF occurred before D03. It proves neither SDL/VideoOut nor rendering,
terminal status, cleanup or safe exit. Every authorization is false.
Phase 1.0F adds no firmware evidence: its I00-I14 artifact exists only as an
offline build and has never been transferred, received from or executed on a
device.
Phase 1.0G adds exact artifact-bound firmware evidence through I03. Captured
ordinary stdout proves the build took RetroArch's no-argument/no-menu help path
and exited before I04. It adds no SDL, VideoOut, rendering, terminal cleanup or
safe-exit evidence. Its one-shot permission is consumed.
Phase 1.0H adds no firmware evidence. It is an offline, reproducible correction
for that source-bound argument defect and remains transfer- and
execution-ineligible. Its modeled I04 boundary and all later stages are
unproven on firmware 9.60.
The later exact H permission was consumed once. It proves I04, I13/I14, D03,
a positive D05 VideoOut handle and D06 buffer-registration result 0. D07 and
D04 both returned -1; no successful visible flip, runloop, full cleanup or
safe exit is proven. No retry occurred.
Phase 1.0M adds no firmware evidence. It removes the source-bound playlist
directory probe/mkdir from write-free builds and produces a reproducible,
statically audited artifact, but that new hash has never been transferred or
executed. I04, SDL, VideoOut, flip behavior, visible output and cleanup remain
unproven on firmware 9.60.
Phase 1.0N adds no firmware evidence. It prepares only an inactive, manifest-selected host runner for the unchanged Phase-1.0M hash. Fake-socket tests and static hash binding do not prove runtime behavior on firmware 9.60; all target, transfer, execution and reception authorizations remain false.
The separately authorized Phase-1.0O attempt adds exact firmware-9.60 evidence
for the M hash: I04 and SDL video entry were reached, VideoOut opened, buffer
registration returned 0, and the first flip submit returned -1 with saved
errno 0. No D13/write-firewall frame occurred. D12 reported runtime
failure/E104 and D04 reported SDL init -1. Visible presentation, successful
termination and cleanup remain unproven; the permission is consumed.
Phase 1.0P adds no firmware evidence. Its offline source/map/disassembly audit proves the exact first-submit tuple and failure site, but the local public sources do not prove the argument semantics, opaque attributes, flip-master or active-app requirements, return-code meaning, visible output or cleanup. The VideoOut root cause remains unresolved and no new device action is authorized.
Phase 1.0Q adds no firmware evidence. Its public-source search establishes that the current PS5 VideoOut declarations have one SDL lineage and no independent public PS5 corroboration. PS4 analogues and host source scans do not establish firmware-9.60 argument, layout, ownership or error semantics.
Phase 1.0R adds no firmware evidence. Source proves only that SDL2main is a lifecycle wrapper and that the tested artifact already hides the splash before VideoOut open. It does not prove the firmware-9.60 active-app, flip-owner, launcher, process, visibility or cleanup contract. The observed LNC log remains a non-unique correlation, not a firmware interpretation or root cause.
Phase 1.0S adds no firmware evidence. Official shsrv source proves that hbldr creates a BigApp-based process context, but source cannot prove that the route works on this firmware-9.60 device, grants flip ownership, or fixes the exact submit failure. The deployed shsrv version, target fake-app state, visibility, crash and cleanup behavior remain unobserved.
Phase 1.0T adds no firmware evidence. It statically proves that the audited shsrv source emits firmware, serial and telemetry on connection and that its existing identity-related commands cannot return an exact deployed SHA-256. No port-2323 connection occurred, so the deployed shsrv family, compile metadata, device paths and all firmware-9.60 runtime effects remain unobserved.
Phase 1.0U adds no firmware evidence. Its bounded host inventory found no original shsrv target binary or receipt to hash. Official source and packaging metadata do not establish what runs on firmware 9.60, and no device identity, path, version, greeting or behavior was observed.
Phase 1.0V adds no firmware evidence. Its Telnet and sanitization behavior is a synthetic host model fed from stdin. It neither connects to nor observes the firmware-9.60 device, and it does not prove the live greeting, prompt, negotiation, timeout, disconnect, shell cleanup or deployed shsrv identity.
Phase 1.0W adds no firmware evidence. Its remediated collector, session policy
and fake transport use synthetic host input and an explicit synthetic clock.
Source-bound port 2323 and exact firmware text 9.60 are policy constraints,
not proof of a listener, negotiation, device identity, deployed bytes or
runtime behavior.
Phase 1.0X also adds no firmware evidence. Its receipt/output operations and
deadline/cleanup state are exercised only against injected fake adapters. The
official shsrv source describes a dynamic PWD prompt and automatic greeting,
but does not bind the deployed bytes or live Telnet stream on firmware 9.60.
Phase 1.0Y adds source-history evidence only. Official tags v0.7-v0.8 use raw
framing and v0.9-v0.19 use libtelnet/NVT, but no evidence selects which
family, revision or modified binary runs on firmware 9.60. Synthetic framing
tests therefore do not establish live line endings, prompt completion, echo,
short-write behavior or disconnect cleanup.
Phase 1.0Z adds no firmware evidence. Its one-batch formatter and deadline-only accumulator run exclusively on synthetic host inputs. The tests show that the contract tolerates modeled LF/CRLF output and rejects incomplete data; they do not prove a listener, exact deployed shsrv bytes, live deadline behavior, filesystem effects, cleanup or restart on firmware 9.60.
Phase 1.0AA adds no firmware evidence. Its exact fake adapter, synthetic clock, exclusive temporary host files and scripted events exercise only local model composition. Passing receipt/send/deadline/close tests cannot establish a live listener, OS timeout behavior, target identity, shell cleanup or any behavior on firmware 9.60.
Phase 1.0AB adds no firmware evidence. Local Windows Python runtime identities and synthetic nonblocking traces describe only a possible host implementation. They do not observe port state, packet delivery, shsrv cleanup or any behavior on firmware 9.60.
Phase 1.0AC adds no firmware evidence. Its dormant adapter accepts only exact built-in fake syscall steps and a synthetic clock. Passing its lifecycle and cleanup cases does not establish a listener, deployed shsrv identity, network timing, remote cleanup, launch context or any firmware-9.60 behavior.
Phase 1.0AU adds no firmware evidence. Exact official headers establish source signatures for pipe, descriptor inheritance, nonblocking reads, monotonic time, termination and reap. They do not establish their runtime behavior on firmware 9.60, and current official shsrv does not contain the bounded composition.
Phase 1.0AV adds no firmware evidence. Its two synthetic arms define how a future exact-payload comparison would isolate launcher identity, but neither arm has target source, an artifact, approval or device result. A modeled return difference cannot prove a visible flip or firmware behavior.
Phase 1.0AW adds no firmware evidence. It proves only that official v0.7 source passes raw stdout into the replaced BigApp and identifies the source changes a future canary would need. No deployed identity, bounded launcher, target bytes or firmware-9.60 result exists.
Phase 1.0AX adds no firmware evidence. Its valid D07/D04/D14 traces are synthetic bytes and its cleanup predicate is a host reference. No target source, artifact, device result or visible output implements that reference.
Phase 1.0AY adds no firmware evidence. Selecting an exact private Git commit establishes only source lineage; it creates no target source delta, artifact or firmware-9.60 observation.