2.9 KiB
Phase 0.5 startup offline evidence — 2026-07-17
Outcome
Decision: BLOCKED. The stock SDK v0.41 startup is UNSAFE, and the exact
loader caller needed to prove safe return from a replacement is absent. No
custom _start source and no PS5 ELF were created.
No PS5 connection, transfer, execution, VideoOut open, module load, network initialization, GNM operation, framebuffer mutation, credential change, syscall-bound change, MMIO access, or firmware change occurred.
Offline startup audit
tools/audit_ps5_startup_feasibility.py was run twice independently against
the pinned SDK source and install. Both JSON outputs were byte-identical:
- startup audit SHA-256:
d0e8202c1a07e4104476cadf6c14a1dea2d724b1d97495dddcdf05858f6c8d4a; - 12 transitive stock CRT sources enumerated;
- six other CRT-named installed files confirmed as empty archives;
- 31 functions and 182 call/tail-call edges reachable from stock
_start; - reachable prohibited set:
__patch_init,kernel_copyin,kernel_copyout,kernel_set_ucred_caps, andkernel_set_ucred_attrs; - compiler
-###trace confirmed that-nostartfiles -nodefaultlibsadds no stock CRT or default library and produced no ELF; - non-SDK local loader-contract hits: zero.
Policy verification
The real legacy artifact, its updated manifest, and the permanent denylist were
evaluated together. The policy tool returned exit 2 with both
ARTIFACT_PERMANENTLY_DENYLISTED and
MANIFEST_EXECUTION_INELIGIBLE.
JSON Schema validation passed for all three tracked artifact manifests and the permanent denylist.
Host and static tests
- Windows MSVC warnings-as-errors build: passed.
- Windows CTest: 14/14 passed.
- WSL Clang 18 plus clang-tidy build: passed.
- WSL Clang CTest including formatting: 15/15 passed.
- WSL GCC 15 ASan+UBSan build: passed.
- WSL GCC ASan+UBSan CTest: 15/15 passed.
- Python syntax compilation for every changed tool/test: passed.
git diff --check: passed at review time.
An initial Clang ASan configure did not compile a project source because the
local Clang install lacks libclang_rt.asan*. GCC's available ASan/UBSan
runtime was used successfully instead. The failed configure is an environment
toolchain limitation and was not reported as a passed test.
Bound hashes
| Record | SHA-256 |
|---|---|
| permanent denylist | e9603b0e3792781ad5b511afb22ef61e3d4fd4c5a16bf928f8609193bcd97783 |
| denylist schema | 78d0d28da552550e4b7dabc5b9c25347fb2618c4664b7a554b87c6de69cd6c96 |
| startup audit JSON | d0e8202c1a07e4104476cadf6c14a1dea2d724b1d97495dddcdf05858f6c8d4a |
| non-build decision | b04dd224c00af0c7228c582f6ba3ca55ef03e9453287f233a0c4ff2e545092fc |
| machine proof matrix | aefd1d1e663be617ed1042c6a1d68b9f21dd0c137f0c601d15cdcbfdf03dadb7 |
| permanently blocked legacy ELF | 4be1c17b4964f2b68c39b5145bc4af4619c32512d60269ecf5c39728b390fa63 |
The last hash names pre-existing bytes only. It is not a Phase-0.5 artifact and must not be transferred or executed.