6.3 KiB
Phase 1.0I offline flip and write analysis
Status: OFFLINE ANALYSIS COMPLETE; DEVICE RETEST BLOCKED.
This is a static postmortem of the consumed Phase-1.0H run. It binds the captured frames to the exact RetroArch source, SDL overlay, linker map and artifact disassembly. No PS5 connection, request, transfer, execution or new target build was performed.
Conclusions first
- The first VideoOut submit failed at the exact call
sceVideoOutSubmitFlip(handle, 0, 1, 0); the wait was not reached. - The diagnostic helper uses buffer/frame zero while the same patch makes the normal update path start at frame one. This is a strong code-level inconsistency, not a proven firmware root cause.
- The original submit
errnowas not captured. D07 output occurs beforeerrnois read and can itself change it. - E118 occurred between I03 and I04. The linked binary can classify the
rejected operation only as
OPENorSTREAM; D12 does not carry the exact stored operation. - The E118 shutdown request did not gate later initialization: I04 through D07 still ran.
The next safe action is another offline design/build phase that improves observability and shutdown gating. It is not another device run.
Evidence binding
| Object | Identity |
|---|---|
| RetroArch source | c710f85816b5e456dd3a85a46f85eb28883522b3 |
| Phase-1.0H result commit | 5db76beddd56c0f82ecbcccfbe8ed12ea3bb4bda |
| Artifact | 1,845,152 bytes, SHA-256 822f2cf1f4d33a514d2bdd88fde40ad580dda5d85f537362ef6dff2eafcb56b6 |
| Linker map | 637,603 bytes, SHA-256 638642b750b8d5b108cf6c73215a3f1759bc6da0b29ee0a0ade5c47e8b7b2d5 |
| SDL diagnostic patch | SHA-256 c287cf0207192b06c2658c2ae6982a3c2fe3ee9179908de5911d074786dc889e |
| Materialized SDL video source | SHA-256 9a1c171711d2b5a1167b66a3c0e2ac926d7fd101b1f08b0a9240a3aa9c62211e |
| Device trace | SHA-256 858a205afcf682a498d8bc11947b67d2446098883a61f6871e31df4d950d0a61 |
| Public SDL source | commit 0baf4ac49382b537ba449901b5b6d0d189bb1fbb |
| Public SDK v0.41 | commit d2e2e585740362976a39fdd5ccf390f199a7bc37 |
The ignored artifact, map and trace remain local evidence; they are not added to Git.
E118 write-firewall interval
D12 has shutdown reason 6 (WRITE_FIREWALL) and first error 118
(E118_WRITE_BLOCKED). Its sequence position proves the request occurred
after I03 and before I04. The in-memory status also stores
first_blocked_write, but D12 transmits only reason and error.
The exact linker map retains these blocking functions:
| Function | Address | Block category |
|---|---|---|
__wrap_open |
0x47580 |
OPEN |
__wrap_fopen |
0x475b0 |
OPEN |
__wrap_fwrite |
0x47600 |
STREAM |
Configured wrappers for openat, write, create, truncate, directory and
rename/delete operations were garbage-collected from this artifact. Static
reachability within I03-to-I04 contains logging/configuration paths to
__wrap_fopen; it does not prove which runtime branch fired. The initial
retro_main_log_file_init(NULL, false) is specifically excluded because both
source and disassembly return before fopen. Remaining indirect/runtime
behavior prevents selecting OPEN over STREAM without inventing evidence.
Consequently the exact operation, path, mode/flags and intended file remain
UNPROVEN. This is an observability defect, not evidence that a device write
succeeded: the wrapper returned failure and set EROFS.
Flip call and failure boundary
The SDL source fills its CPU surface, tiles it into vbuf[0], then submits.
The artifact disassembly independently fixes the arguments:
0xfe6ac esi = 0 buffer index
0xfe6ae edx = 1 flip mode
0xfe6b3 ecx = 0 64-bit flip argument
0xfe6bc call sceVideoOutSubmitFlip
D05 proves a positive handle for this run and D06 proves buffer registration
returned zero. D07 proves submit returned -1. The failure branch bypasses
sceKernelWaitEqueue; therefore no event wait, successful flip or visible
presentation is claimed.
The helper hard-codes vbuf[0] and (0, 1, 0), while the patched normal
PS5_UpdateWindowFramebuffer() initializes frame_id = 1 and derives the
buffer index from it. That mismatch is source-proven. However, the pinned SDL
upstream itself initializes the normal path at zero, so firmware semantics do
not establish that changing to one is correct.
SDK v0.41 exports the symbol but provides no public VideoOut prototype or structure contract. The declaration and opaque layouts used here originate in the public SDL fork. Buffer-index validity, flip argument monotonicity, buffer attribute semantics and exact firmware-9.60 error codes remain unproven.
The helper calls the D07 diagnostic sender before strerror(errno). Since the
sender performs an inherited-socket send, it can overwrite errno; the
original submit error must be copied immediately after the submit in any
future diagnostic. No reliable error text was present in captured stdout.
Review matrix
| Question | Result |
|---|---|
| H startup-argument correction | PROVEN_ON_FIRMWARE_9_60 |
| E118 interval | PROVEN |
| E118 operation domain | PROVEN: OPEN OR STREAM |
| Exact E118 operation/path | UNPROVEN |
| Pattern write before submit | PROVEN_FROM_SOURCE_AND_STAGE |
| Submit argument tuple | PROVEN_FROM_SOURCE_AND_DISASSEMBLY |
| Submit return | PROVEN: -1 FOR CONSUMED RUN |
Original submit errno |
UNPROVEN |
| Frame-zero mismatch | STRONG_SOURCE_CANDIDATE |
| Frame-zero mismatch is root cause | UNPROVEN |
| VideoOut argument/ABI semantics | UNPROVEN |
| Visible presentation | UNPROVEN |
| Complete cleanup/safe exit | UNPROVEN |
Gate for a future offline artifact phase
A later phase may design and build, offline only, a newly hashed diagnostic that:
- captures submit return and
errnobefore any reporting call; - emits the exact blocked write operation and count;
- stops initialization before I04 once the firewall requests shutdown;
- removes the divergent first-frame constants through one reviewed source of truth;
- preserves one submit, no submit retry, and waits only after submit success;
- adds no target socket creation, address, filesystem write, install or autoload path.
Choosing frame zero or one requires an evidence-backed decision. A new build would remain ineligible until a separate review. No current PS5 connection, transfer, execution, result reception or retry is authorized.