3.3 KiB
Phase 1.0D startup and import closure
Pre-main closure
The SDK _start order is BSS clear; syscall bridge; kernel argument bridge;
klog; __isthreaded; __patch_init; runtime linker; dependent library
opening/relocation; init array; then main. Both Phase-1.0D artifacts have
zero-byte init and fini arrays and no TLS sections or PT_TLS. Heap, signal, and
pthread behavior is not an application constructor here, but the runtime and
linked libraries remain able to resolve their normal facilities.
__patch_init is not side-effect-free: it reads then changes current-process
capability/attribute bytes (including source comments for JIT shared memory
and ptrace) and writes lower/upper syscall-address bounds through kernel
copyin. The loader also prepares mappings and SDK resources before entry.
These are pre-main failure points with no C1/D00 marker.
The SDK runtime linker can resolve and conditionally load
/system/common/lib/libSceSysmodule.sprx; exact runtime module availability
and whether that conditional path executes on firmware 9.60 are unproven.
Hardened elfldr does not resolve the artifact's dynamic symbols; the SDK
runtime path does.
Canary imports
| Import | Class | Rationale |
|---|---|---|
memset |
CRT_PRE_MAIN / helper | request clearing may be compiler-lowered; SDK startup precedes it |
sceKernelSendNotificationRequest |
CANARY_MAIN | only C1 output |
nanosleep |
CANARY_MAIN | one two-second relative wait |
_Exit |
SHUTDOWN | selected terminal call |
Required modules are libkernel_web.sprx and libSceLibcInternal.sprx.
Early-diagnostic groups
The complete 141-symbol set is machine-readable in
manifests/retroarch/phase-1.0d-early-diag-artifact.json. Its meaningful
boundary grouping is:
- CRT_PRE_MAIN: SDK-owned syscall/kernel/klog/patch/runtime-linker operations are statically linked and may resolve libc/kernel facilities before D00. No target marker precedes them.
- RETROARCH_PRE_VIDEO: libc/POSIX support, user service, system-service splash, notification, clock and bounded platform status.
- VIDEO: direct memory, equeue, and every
sceVideoOut*import. - INPUT:
scePadInit,scePadOpen,scePadReadState,scePadClose. - AUDIO:
sceAudioOutInit,sceAudioOutOpen,sceAudioOutOutput,sceAudioOutClose. - SHUTDOWN:
_Exit, close/release/delete operations and bounded teardown. - UNREACHABLE_IN_PROFILE: generic RetroArch file-write strings and code may remain linked, but the profile routes mutating entrypoints through the write firewall and disables content/configuration; no socket/SceNet import is present.
The import list alone cannot prove reachability. Conversely, absent imports do
not disprove statically linked behavior. The source profile, linker map,
disassembly, undefined-symbol inventory, and host fault model are considered
together. Generic localization strings such as netplay text and
udp://127.0.0.1: remain in the binary; there is no target network callgraph
or network import. SDK patch symbols also remain because normal CRT startup
was an explicit requirement.
The earliest new marker that does not modify SDK CRT or loader architecture is
therefore C1/D00 at application main. A notification earlier than that would
require a separately reviewed CRT/loader change and is out of scope.