2.3 KiB
Phase 1.0B persistent-write audit
Conclusion: persistent device writes are fail-closed in the selected smoke paths; device execution remains unauthorized.
Layers
- The PS5 frontend blocks config reads, supplies no content/config/SRAM/state path and selects a static no-content core.
- RetroArch VFS accepts only
RETRO_VFS_FILE_ACCESS_READ. Write, truncate, remove, rename and mkdir return failure and tripE118. - Link-time wrappers reject write-capable
open/openat, non-read-onlyfopen, non-stdiowrite/fwrite, and all create, temp, rename, unlink, remove, mkdir, rmdir, chmod, chown and truncate calls. - A rejected operation returns
EROFS, stores the first operation in memory, requests shutdown once and never retries.
stdout and stderr writes remain allowed because the SDK CRT/RetroArch can
already use those process streams. They are not file-output authorization.
The ELF imports read-only filesystem primitives (open, fopen, read,
fread, stat, directory iteration); the frontend has no content/config
path, but normal runtime/module implementation can still use read primitives.
Static reachability result
Final link garbage collection removes wrapper bodies for operations with no
remaining caller. Reachable application calls to open, fopen and fwrite
resolve to __wrap_open, __wrap_fopen and __wrap_fwrite; their only
forward edges are read-only opens or stdout/stderr. The underlying libc
imports remain because accepted paths forward to them.
No final import is present for rename, unlink, remove, mkdir, chmod,
chown, ftruncate, mkstemp, tmpfile or freopen. Static absence alone
is not the safety claim: the VFS guards, wrappers, linker map and disassembly
together provide the offline evidence.
Explicit exclusions
The profile disables or provides no route for config save, playlist/history, SRAM, savestate, screenshot, recording, shader cache, autoconfig, remap, database, temporary file, installation and autoload. It contains no device path, IP address, sender, transfer or installation package.
Limit: libc internals invoked inside an imported function are not intercepted by linker wrapping. No application path can supply a writable file stream because writable open modes are blocked, but this remains static reasoning, not observed firmware behavior.