Files
chimera-gfx-Public/docs/retroarch/phase-1.0b-linker-and-wx-analysis.md
Chimera GFX release export a6037502d7
phase0-ci / build-and-audit (push) Successful in 2m14s
Publish Chimera GFX source
2026-09-03 03:27:14 +02:00

63 lines
2.6 KiB
Markdown

# Phase 1.0B linker and W^X analysis
## SDK baseline
PS5 Payload SDK v0.41 `ldscripts/elf_x86_64.x:20-25` emits three load
segments but deliberately marks text `0x7` (RWE), rodata `0x6` (RW) and data
`0x6` (RW). The Phase-1.0A software ELF consequently has a permanent RWE
text segment.
## Loader evidence
Both public elfldr `699e8bcff03e91e8d6ca6eba281af25c5a58d8c2`
and hardened elfldr `197623058f509eddde18868dafcb92fdcac66464`:
- enumerate every `PT_LOAD`;
- initially reserve one RW image mapping;
- copy all segments and apply `R_X86_64_RELATIVE` relocations in the host
mirror;
- copy the completed image to the child;
- translate every `p_flags` bit through `PFLAGS`;
- use `kernel_mprotect` for executable segments and `pt_mprotect` otherwise.
Relevant hardened source is `elfldr.c:54-56,144-263`. This supports multiple
load segments and a temporary relocation-write phase followed by final
per-segment protection.
## Smoke layout
The smoke-only `pkg/ps5/elf_x86_64_smoke_wx.x` preserves the SDK symbols and
0x4000 page alignment while arranging:
- `.text` and `.plt`: RX;
- unwind tables and constant `.rodata`: R;
- dynamic symbol/hash/string/relocation tables, `.data.rel.ro`, GOT,
init/fini arrays, `.dynamic`, `.data` and `.bss`: RW.
Runtime-relocated GOT and related metadata deliberately remain writable.
The final program-header audit must show no segment with both W and E. All
`R_X86_64_RELATIVE` destinations must lie in RW load ranges. The primary
candidate is accepted only if both checks pass twice byte-identically.
## RELRO and self-modification
The pinned SDK/loader contract does not implement a post-CRT RELRO transition.
Marking the GOT read-only before SDK runtime linking would be unsafe, so no
RELRO claim is made. No self-modifying RetroArch/smokecore code, JIT or
dynamic core loader is enabled or reachable. No production elfldr code was
changed.
## Residual risk
W^X is statically established, but the exact protected layout has not run on
firmware 9.60. Loader protection errors, an SDK runtime write to an
unexpected R-only section, or firmware-specific mapping behavior could end
the child/session. No persistent installation effect follows from the
artifact design, but that claim also remains unobserved.
The SDK CRT's statically linked runtime loader is present independently of
RetroArch's feature set and may conditionally load `libSceSysmodule`.
The final import list has no module-loader symbol, but absent imports alone
are not used as proof that startup has no module effects; the CRT source and
startup disassembly are the controlling evidence.