Files
chimera-gfx-Public/docs/retroarch/phase-1.0al-offline-mdbg-copy-audit.md
Chimera GFX release export a6037502d7
phase0-ci / build-and-audit (push) Successful in 2m14s
Publish Chimera GFX source
2026-09-03 03:27:14 +02:00

1.3 KiB

Phase 1.0AL: offline mdbg copy and restoration audit

Status: SDK_MDBG_COPY_NOT_FAIL_CLOSED_DIRECT_REUSE_BLOCKED

Date: 2026-07-29

The exact pinned SDK v0.41 mdbg_copyin implementation is unsuitable for direct reuse in the hybrid loader. It changes the service process auth ID before changing capabilities, but a capability-set failure returns without restoring that auth ID. Its normal restoration also returns immediately after an auth-ID restore failure, so capability restoration is not attempted.

The copy loop neither bounds iterations nor uses a monotonic deadline. It does not reject a reported length larger than the remaining length, check pointer arithmetic, or expose partial progress. A nonzero remote status with zero progress can leave the syscall return value as zero, so return value zero does not prove that the requested copy completed. Any earlier iterations may already have mutated target memory.

A replacement contract must report exact progress and restoration failures, attempt every required restoration on every exit, and terminate/reap the child after any partial copy or restoration failure. This audit authorizes only a capability-free host model of that contract; it does not authorize target code, a build, connection, transfer or execution.