5.0 KiB
Phase 1.0J offline write-firewall diagnostic
Status: OFFLINE ARTIFACT AUDITED; DEVICE ACTION BLOCKED.
Phase 1.0J implements the bounded offline follow-up required by Phase 1.0I. It does not connect to a PS5, transfer an ELF, receive a device result or run target code. The built ELF and map stay in ignored local build storage and are not committed.
Exact source and artifact binding
| Object | Identity |
|---|---|
| RetroArch source | 2e385265ab893dbba5898178dde5e108d3dbfa19 |
| Chimera GFX baseline | 2bee49e5e8f1ee6faa0589d2d74de5ba0d809293 |
| Public PS5 SDL source | 0baf4ac49382b537ba449901b5b6d0d189bb1fbb |
| Public PS5 Payload SDK v0.41 | d2e2e585740362976a39fdd5ccf390f199a7bc37 |
| SDL diagnostic patch | SHA-256 aa1d3ebc6043d6051938cee1dbffecb80729b3b6595eef964915e93f1570c193 |
| Materialized SDL video source | SHA-256 9949a280fed40241746788a8c001280455bc629e0566a88f82f16a8634d43025 |
| J ELF | 1,845,208 bytes; SHA-256 6ff0f7ea391da5f15ea43512a871078133e896a6900ae9f8f3fa75711abb8009 |
| Linker map | 637,728 bytes; SHA-256 19f1cf851ad8f99d31d5de3a14591f81faa83589c18e93cd60be96ebef5d7719 |
| Normalized disassembly | SHA-256 45dc4e0233b3770add430aaa6bb23a60210b50744effb76b515fca4b9e6e310f |
Two clean PS5_PROFILE=write-diag builds produced byte-identical ELFs and
maps. The raw audit disassembly hashes differ because objdump includes each
input pathname; replacing only the write-diag-a/write-diag-b path component
produces the identical normalized hash above.
Bounded diagnostic behavior
The protocol uses distinct magic CHD10J01. Existing stage numbers and wire
values are preserved; D13 is appended and carries exactly:
value_a = first_blocked_write
value_b = write_block_count
The first write-firewall rejection emits one inherited-stdout, nonblocking,
signal-suppressed D13 frame immediately before terminal D12. No target socket
is created and the existing live runner has no J selector. Immediately after
argument/config parsing, retroarch_main_init() observes
shutdown_requested and returns false before I04 and all SDL/VideoOut driver
lookup. Thus the first unresolved E118 operation can be identified without
continuing into graphics initialization.
The SDL helper separately copies errno immediately after its single
sceVideoOutSubmitFlip() call and before notification or stream output. Under
J, D07 would carry (submit_result, saved_errno). That branch is deliberately
unreachable after an earlier firewall shutdown; it is retained for a later,
separately reviewed phase only.
ADR-0012 fixes one CHIMERA_PS5_FIRST_FRAME_INDEX value of zero for the early
copy, early submit and normal initial counter. This removes an internal source
inconsistency. It is not firmware proof or a root-cause claim.
Static and transitive audit
The ELF is a PIE with entry point 0xff210, 20 sections and four program
headers. Three LOAD segments are R E, R and RW; no segment is RWX.
.init_array and .fini_array both have size zero, and there is no TLS
section. .bss is 0xaa520 bytes. The dynamic closure has 142 undefined
symbols and 1,055 relocations: 142 R_X86_64_GLOB_DAT and 913
R_X86_64_RELATIVE.
The exact DT_NEEDED set is:
libSceAudioOut.sprxlibSceLibcInternal.sprxlibScePad.sprxlibSceSystemService.sprxlibSceUserService.sprxlibSceVideoOut.sprxlibkernel_web.sprx
The import set contains send for the already-audited inherited stdout
descriptor. It contains no socket, connect, bind, listen, accept or
recv, and no GNM symbol. The linker map binds the firewall entry at
0x466d0, its surviving wrappers at 0x475a0, 0x47610 and 0x476a0,
retroarch_main_init at 0x3dc0, and the dormant early VideoOut helper at
0xfe550.
String scanning still finds dormant generic RetroArch text mentioning networking, installation, credentials, autoload and writes. Absence of a string is not used as safety proof. Safety rests on the source profile, write-wrapper closure, linker map and disassembly; the scan findings remain recorded as dormant linked data rather than declared reachable behavior.
Review matrix
| Property | Result |
|---|---|
| Exact E118 operation reporting | PROVEN_OFFLINE_FROM_SOURCE_AND_TESTS |
| Stop before I04 after E118 | PROVEN_OFFLINE_FROM_SOURCE_AND_DISASSEMBLY |
| Submit errno capture ordering | PROVEN_OFFLINE_FROM_SOURCE |
| Unified first-frame value | PROVEN_OFFLINE_FROM_SOURCE |
| Byte-reproducible ELF and map | PROVEN_OFFLINE |
| Firmware-9.60 runtime behavior | UNPROVEN |
| Exact blocked operation for the consumed H run | UNPROVEN |
| Submit errno on firmware 9.60 | UNPROVEN |
| Visible presentation | UNPROVEN |
| Complete target cleanup and safe exit | UNPROVEN |
The normal SDK CRT and its documented runtime effects remain inherited. The early fail-closed return occurs before driver initialization, but the complete loader/process cleanup path is still not firmware-proven. Every artifact and authorization gate remains false. No device action is authorized.