Files
chimera-gfx-Public/docs/runtime/controlled-runtime-policy.md
Chimera GFX release export a6037502d7
phase0-ci / build-and-audit (push) Successful in 2m14s
Publish Chimera GFX source
2026-09-03 03:27:14 +02:00

3.7 KiB

Controlled PS5 runtime profile

manifests/controlled-runtime-profile.schema.json defines the mandatory machine boundary for hardened-runtime deployment preparation. Missing metadata is a denial, not an invitation to infer a value.

Required invariants

  • exact firmware 9.60, supported by Jens's explicit confirmation;
  • exact hardened Payload Manager, hardened elfldr, SDK, and artifact source commits, sizes, and SHA-256 values;
  • byte-identical double clean builds for every ELF;
  • lifecycle artifact filename, byte size, SHA-256, and clean source commit equal in artifact manifest, runtime profile, audit, and local bytes;
  • persistent writes limited to removable controlled application artifacts;
  • filesystem writes limited to the controlled artifact directory;
  • payload network access none;
  • maximum payload runtime 2000 ms;
  • automatic retry disabled;
  • no effect classified PERSISTENT_WRITE or UNBOUNDED_OR_UNKNOWN;
  • no hard blocker and decision READY_FOR_HARDENED_RUNTIME_DEPLOYMENT;
  • explicit execution_eligible=true;
  • profile name exactly controlled-ps5-runtime;
  • expected_volatile_effects exactly equal to the IDs classified EXPECTED_VOLATILE_RUNTIME_EFFECT;
  • explicit top-level execution_authorized=false;
  • deployment fields remain installed=false, ready_for_installation=true, and rollback_prepared=true.

The static pass means the exact bytes are eligible for a later, separate installation approval. It does not authorize a PS5 connection, transfer, installation, or execution.

rollback_prepared=true means only that the offline review and rollback packages exist. It does not claim that byte-exact stock backups are already present on the console. Phase 0.8 keeps installation hard-blocked until those current on-device rollback preconditions are proven through an admissible collector.

Current exact profile

manifests/runtime/controlled-ps5-runtime-profile.json binds:

  • lifecycle probe bfb4a5cc768e162fe4c2fddf41c3978e152722918a39085277fd172cb95a7182, 112680 bytes, source fe08300339a13f899fb78ea404ada381a5cba87c;
  • hardened elfldr 63e810982471eb40cae3a20aa9df9a0a02892f420e429874fae4e99aa400b561, 397000 bytes, source 197623058f509eddde18868dafcb92fdcac66464;
  • controlled Payload Manager 8fecf8241a46246eddbd21e8bb4d875f5d76f1f4f4c6a11384df1f131aa5e5b1, 99560 bytes, source e23d94ff91233aa770e2342800c1467875bdef44;
  • SDK v0.41 commit d2e2e585740362976a39fdd5ccf390f199a7bc37.

The profile records installed=false, execution_authorized=false, transferred=false, and executed=false. Firmware was not queried from the device because this phase was offline; the evidence string records Jens's exact 9.60 confirmation.

Static gate

tools/check_artifact_execution_policy.py verifies the profile, artifact manifest, local lifecycle bytes, firmware argument, and permanent denylist. It returns PASS_STATIC_DEPLOYMENT_ELIGIBILITY_GATE only for the exact reviewed set and still emits execution_authorized=false.

The gate rejects a blocked decision, altered bytes, wrong firmware, an uninstalled-identity claim, a widened budget, a hard effect, missing hardened runtime identity, any authorization/transfer/execution claim, or a permanent denylist match.

Historical boundary

Phase 0.5's freestanding startup and Phase 0.6's unmodified public loader chain remain blocked historical records. Phase 0.7 does not weaken or overwrite those findings; it builds new hardened binaries that close the Phase-0.6 implementation blockers.

Phase 0.8 is a separate operational preflight gate. Its current decision is READ_ONLY_PREFLIGHT_BLOCKED; it neither revokes the exact Phase-0.7 static build evidence nor promotes it into connection, installation, transfer, or execution authority.