7.1 KiB
Phase 0.9B bounded observer design
Status: BLOCKED — OFFLINE AUDIT ONLY.
No observer source, PS5 target, ELF, installation package, lifecycle package or execution package was created. No PS5 connection, scan, transfer or execution occurred. This document describes the rejected design boundary and the exact evidence needed before implementation may start.
Canonical boundary
- Historical Phase 0.8 remains
READ_ONLY_PREFLIGHT_BLOCKED. - Phase 0.9A remains
DESIGN_ONLY. - Firmware 9.60 runtime behavior remains
UNPROVEN. - Stock sizes and hashes remain
reference_only. - The byte-exact on-device Payload Manager backup remains a
HARD_BLOCKER. - Every authorization field remains
false; automatic retry remainsfalse. - SHA-256
4be1c17b4964f2b68c39b5145bc4af4619c32512d60269ecf5c39728b390fa63remains permanently denied and execution-ineligible.
Source identities
| Source | Commit | Tree |
|---|---|---|
| hardened elfldr | 197623058f509eddde18868dafcb92fdcac66464 |
clean |
| controlled Payload Manager | e23d94ff91233aa770e2342800c1467875bdef44 |
clean |
| public elfldr v0.23 base | 699e8bcff03e91e8d6ca6eba281af25c5a58d8c2 |
clean |
| public Payload Manager v0.3.1 base | cfbc70f30f419b09bf2b52283f7409e2d3117ee1 |
clean |
| PS5 Payload SDK v0.41 | d2e2e585740362976a39fdd5ccf390f199a7bc37 |
clean |
| lifecycle-probe source | fe08300339a13f899fb78ea404ada381a5cba87c |
byte identity checked |
The public bases establish provenance and the pre-hardening behavior. The hardened source commits establish the only controlled route considered here. No external source was contacted during this audit.
Mandatory gates
| Gate | Required | Evidence | Result |
|---|---|---|---|
| kernelwrite-free startup | complete reachable startup path excludes kernel/process patch writes | SDK crt/crt.c:48-80,193-220, crt/patch.c:25-101, crt/Makefile:19-26 |
FAIL for normal CRT |
| custom entry ABI | entry register, BSS, stack, return, exit and cleanup are all proven | elfldr elfldr.c:273-415; prior Phase-0.5 audit |
UNPROVEN |
| non-persistent output | payload bytes return over the hash-bound route without a device file, listener or global-state mutation | elfldr socksrv.c:129-145,361-365, elfldr.c:499-520; manager verified_launcher.c:119-185, ps5_launcher.c:18-70 |
FAIL |
| bounded exit | successful and failing observer paths terminate without relying on an unproven ABI | SDK crt/crt.c:150-220; hardened loader watchdog |
UNPROVEN |
Both implementation gates fail independently. The build gate therefore stops before observer source or target creation.
Capability matrix
“Source present” does not mean firmware-9.60 behavior is proven. “Implement”
is no for every row because startup/exit and output fail first.
| Needed fact | Available local API | Source | Evidence | Implement |
|---|---|---|---|---|
| firmware source 1 | kernel_get_fw_version() reads sdk_ps5_ver |
SDK crt/kernel.c:148-171 |
source present; runtime unproven | no |
| firmware source 2 | none established | — | unproven | no |
| file metadata | open(O_RDONLY|O_NOFOLLOW|O_CLOEXEC), fstat, lstat, close |
manager verified_launcher.c:76-115,174-184 |
source/host evidence only | no |
| object identity | pre/post st_dev, st_ino, st_size |
manager verified_launcher.c:26-29,87-101 |
source/host evidence only | no |
| SHA-256 | bounded descriptor read plus local SHA-256 | manager verified_launcher.c:31-55, src/sha256.c |
source/host evidence only | no |
| mount information | getmntinfo() / getfsstat() sample |
SDK samples/mntinfo/main.c, libc/getmntinfo.c |
sample present; runtime unproven | no |
| processes/services | sysctl(KERN_PROC) sample; no complete service map |
SDK samples/ps/main.c |
partial and runtime unproven | no |
| listeners | none established | — | unproven | no |
| autoload configuration | stock file readers and mutating HTTP handlers | manager config.c, autoload.c, http_server.c |
unsafe or unproven | no |
| output channel | controlled route suppresses payload stdio and manager has no receive operation | elfldr socksrv.c, manager ps5_launcher.c |
proven absent on controlled route | no |
| monotonic deadline | clock_gettime(CLOCK_MONOTONIC) in loader watchdog |
elfldr ps5_controlled.c:26-59 |
source/host evidence only | no |
| process exit | normal CRT terminate path or custom return | SDK crt/crt.c:150-220, elfldr elfldr.c:380-415 |
observer ABI unproven | no |
Unknown capabilities remain unknown. There is no FreeBSD, PS4 or other firmware fallback.
Rejected runtime designs
Normal SDK CRT
The installed compiler wrapper adds crt1.o unless -nostartfiles is used.
That object transitively contains patch.o. _start() calls
payload_init(), which calls __patch_init() before main.
__patch_init() changes credential capabilities/attributes and syscall
permission bounds. This violates the Phase-0.9B kernelwrite-free requirement.
Freestanding custom _start
The loader places its payload_args_t * in RDI, stores the old instruction
pointer at RSP-8, and enters the ELF. Those operations show how control is
transferred; they do not prove that a bare ret, a direct process-exit import,
or another custom termination path performs every required cleanup safely.
The prior minimal-startup gate remains blocked. It was not bypassed.
Controlled stdout/stderr
The controlled route passes -1 as stdio. The elfldr duplicates the request
socket into standard descriptors only when stdio > 0. The manager transport
exposes connect, send and close callbacks but no receive callback. The fixed
Controlled payload exited response carries no observer data. The legacy
stdio route is not the hash-bound controlled route and is inadmissible.
Notifications, klog and manager HTTP
A system notification is not a complete deterministic machine-readable return
channel. Klog is not proven to be a bounded host-return channel. The Payload
Manager HTTP service is a persistent listener, and ordinary routes change
process-global state; /autoload_status also changes autoload state. None is
admissible.
Intended observer shape if gates are later proven
This is a non-implemented contract:
- enter once through a source-bound, kernelwrite-free ABI;
- emit a fixed offline-bound artifact identity;
- initialize bounded in-memory results;
- execute each explicitly authorized read at most once;
- emit raw value or explicit error;
- emit a final status;
- terminate through a proven exit/cleanup path.
It would have no event loop, server, thread, callback, retry, sleep, process signal, subprocess, module load, file mutation, lifecycle action, graphics, SDL, RetroArch, GNM or VideoOut behavior.
Decision
BLOCKED — OBSERVER STARTUP OR EXIT ABI UNPROVEN; NO PROVEN NON-PERSISTENT OUTPUT CHANNEL.
The minimum missing evidence is:
- a commit-bound, kernelwrite-free entry and termination contract that covers BSS, stack, return/exit, crash paths and loader cleanup; and
- a commit-bound controlled response route that carries bounded observer bytes without a device file, new listener, persistent state or Payload Manager global-state mutation.