6.1 KiB
Phase 1.0T: inactive shsrv identity-collection gate
Status: INACTIVE_METADATA_GATE_DESIGNED_EXACT_IDENTITY_UNAVAILABLE
Date: 2026-07-22
This phase designs host-only controls. It does not contain a network client, target address, command sender, target code, artifact, active approval, or device authorization. No connection or PS5 request was performed.
Feasibility result
The existing shsrv protocol cannot attest the exact deployed binary:
- the greeting exposes a compile date/time but no source commit or binary SHA-256;
helpexposes a command-set fingerprint, which can identify a source family but not a byte-exact build;statexposes size and filesystem metadata only;sumopens the target read-only and computes a 16-bit rotating checksum, not a cryptographic digest;- no existing command returns a binary-safe full-file stream or SHA-256;
- a PacBrew path or official release identity is not a live-path identity.
The strongest permitted future result is WEAK_FILE_CORRELATION_ONLY. It must
never be labelled EXACT_DEPLOYED_IDENTITY, RUNTIME_VERIFIED, or recovery
proof.
Mandatory connection side effects
Even before the operator sends a command, a connection to port 2323 causes shsrv to:
- accept a socket and spawn an embedded
sh.elfthrough its ELF loader; - create a new session, pipes, a thread, telnet state, heap allocations and process-local environment;
- query model, serial number, firmware, SoC/CPU temperatures and CPU frequency;
- send those values plus the compile timestamp in the greeting.
The serial is sensitive and unrelated to launcher identity. A future approved
collector must discard it before persistence and must never print it to Codex,
logs, manifests, filenames, screenshots, or commits. Temperature/frequency
values must also be discarded because they add no provenance value. The
offline parser in tools/phase10t_shsrv_transcript.py enforces this for an
already-supplied transcript, but it is not a network client.
Command-effect matrix
| Command or event | Source behavior | Identity value | Future gate |
|---|---|---|---|
| connect/greeting | spawns shell; exposes serial and telemetry | compile metadata | separate explicit acceptance required |
help |
current source allocates/sorts command entries; v0.7 uses a static map | source-family fingerprint | first and only initial command candidate |
stat ABS_PATH |
metadata query; current implementation runs in a forked helper | size/times only | exact pre-attested path only |
sum ABS_PATH |
O_RDONLY, full read, 16-bit rotate checksum; forked helper |
weak correlation only | exact pre-attested path only |
ps/procstat |
exposes broad process/app information | unnecessary | excluded |
env/sysctl |
may expose unrelated or sensitive state | unnecessary | excluded |
ls/find |
directory discovery/path expansion | path guessing | excluded |
cat/hexdump |
unframed content over telnet | not binary-safe | excluded |
hbldr/exec/launch |
launches or replaces a process | none for identity | permanently forbidden here |
| every write/mount/signal command | mutation | none | permanently forbidden here |
For current source, stat and sum use fork=true: the command helper uses
rfork_thread, allocates a 4 MiB stack, changes its budget and duplicates
descriptors. In v0.7 these commands execute through an embedded core ELF. A
read-only filesystem operation therefore still has process and scheduler side
effects. sum may additionally affect atime, caches and I/O accounting.
Offline transcript model
The parser accepts text only through standard input and optionally retains
metadata for literal --expected-path values. It:
- retains no serial, model, temperature, frequency, raw transcript or unknown path;
- fingerprints sorted command names;
- recognizes the exact official v0.7 and v0.19 source-family fingerprints;
- labels the 16-bit checksum
BSD_ROTATE_16and non-cryptographic; - always emits
exact_identity=false; - imports no socket, HTTP or URL client and writes no file.
Official source fingerprints are:
| Source | Commands shown by help |
SHA-256 of sorted names |
|---|---|---|
| v0.7 | 44 | 40313637116b532f3c7f9bebe2c23c0018fe7d4093840cf463a22ba0314ca021 |
| v0.19 | 50 | f41168292e205590bda1d243cdf727044e0af280a89fb0c070f4c5d6c92f2fd7 |
A fingerprint match is still only a source-family candidate because builds can change while preserving the command set.
Future operational windows—not authorized
Window T1: manual host facts
Without touching the PS5, the operator may later identify the original local shsrv binary, source URL, download date, filename, size and host SHA-256. This creates a local candidate only. No binary was found during Phase 1.0T.
Window T2: greeting and help
Requires new exact authorization, an already-running listener attestation, one
connection, no scan, no reconnect and explicit acceptance of shell spawning
and automatic serial/telemetry reads. The collector must redact before any
persistence. Only help may be sent. Failure or mismatch ends the window.
Window T3: one exact path
Requires separate authorization and a path supplied from independent evidence.
One fresh connection may issue stat and optionally sum for that path only.
No wildcard, relative path, shell expansion, pipe, redirection, semicolon,
newline injection, directory listing or path guessing is allowed.
Window T4: fake-app metadata
Requires separate authorization. Only stat of the fixed source-bound
FAKE00000 paths may be considered. It must not call hbldr, create missing
paths, remount, repair, delete or inspect file contents.
Hard stops
- listener presence is not independently attested;
- address, exact path, command list or consent is absent;
- raw serial could reach persistent output;
- protocol framing or prompt is not recognized;
- any response is partial, malformed or exceeds its bound;
- any automatic retry, reconnect, resume or fallback is configured;
- any command outside the separately approved literal list is requested.
Phase 1.0T does not authorize any of these future windows.