Files
chimera-gfx-Public/docs/retroarch/phase-1.0d-startup-import-closure.md
Chimera GFX release export a6037502d7
phase0-ci / build-and-audit (push) Successful in 2m14s
Publish Chimera GFX source
2026-09-03 03:27:14 +02:00

3.3 KiB

Phase 1.0D startup and import closure

Pre-main closure

The SDK _start order is BSS clear; syscall bridge; kernel argument bridge; klog; __isthreaded; __patch_init; runtime linker; dependent library opening/relocation; init array; then main. Both Phase-1.0D artifacts have zero-byte init and fini arrays and no TLS sections or PT_TLS. Heap, signal, and pthread behavior is not an application constructor here, but the runtime and linked libraries remain able to resolve their normal facilities.

__patch_init is not side-effect-free: it reads then changes current-process capability/attribute bytes (including source comments for JIT shared memory and ptrace) and writes lower/upper syscall-address bounds through kernel copyin. The loader also prepares mappings and SDK resources before entry. These are pre-main failure points with no C1/D00 marker.

The SDK runtime linker can resolve and conditionally load /system/common/lib/libSceSysmodule.sprx; exact runtime module availability and whether that conditional path executes on firmware 9.60 are unproven. Hardened elfldr does not resolve the artifact's dynamic symbols; the SDK runtime path does.

Canary imports

Import Class Rationale
memset CRT_PRE_MAIN / helper request clearing may be compiler-lowered; SDK startup precedes it
sceKernelSendNotificationRequest CANARY_MAIN only C1 output
nanosleep CANARY_MAIN one two-second relative wait
_Exit SHUTDOWN selected terminal call

Required modules are libkernel_web.sprx and libSceLibcInternal.sprx.

Early-diagnostic groups

The complete 141-symbol set is machine-readable in manifests/retroarch/phase-1.0d-early-diag-artifact.json. Its meaningful boundary grouping is:

  • CRT_PRE_MAIN: SDK-owned syscall/kernel/klog/patch/runtime-linker operations are statically linked and may resolve libc/kernel facilities before D00. No target marker precedes them.
  • RETROARCH_PRE_VIDEO: libc/POSIX support, user service, system-service splash, notification, clock and bounded platform status.
  • VIDEO: direct memory, equeue, and every sceVideoOut* import.
  • INPUT: scePadInit, scePadOpen, scePadReadState, scePadClose.
  • AUDIO: sceAudioOutInit, sceAudioOutOpen, sceAudioOutOutput, sceAudioOutClose.
  • SHUTDOWN: _Exit, close/release/delete operations and bounded teardown.
  • UNREACHABLE_IN_PROFILE: generic RetroArch file-write strings and code may remain linked, but the profile routes mutating entrypoints through the write firewall and disables content/configuration; no socket/SceNet import is present.

The import list alone cannot prove reachability. Conversely, absent imports do not disprove statically linked behavior. The source profile, linker map, disassembly, undefined-symbol inventory, and host fault model are considered together. Generic localization strings such as netplay text and udp://127.0.0.1: remain in the binary; there is no target network callgraph or network import. SDK patch symbols also remain because normal CRT startup was an explicit requirement.

The earliest new marker that does not modify SDK CRT or loader architecture is therefore C1/D00 at application main. A notification earlier than that would require a separately reviewed CRT/loader change and is out of scope.