Files
chimera-gfx-Public/docs/retroarch/phase-1.0s-hbldr-shsrv-provenance.md
T
Chimera GFX release export a6037502d7
phase0-ci / build-and-audit (push) Successful in 2m14s
Publish Chimera GFX source
2026-09-03 03:27:14 +02:00

5.0 KiB

Phase 1.0S: official shsrv/hbldr provenance

Status: BIGAPP_CONTEXT_SOURCE_PROVEN_DEPLOYED_IDENTITY_UNPROVEN_DEVICE_PATH_BLOCKED

Date: 2026-07-22

This phase acquired and inspected only the official public ps5-payload-dev/shsrv Git source. No downloaded code was built or executed. No PS5 address was used, no connection or request was made, and no target source, target artifact, transfer package, installation package, or device client was created.

Provenance boundary

The official repository is https://github.com/ps5-payload-dev/shsrv. During the audit its master, latest release tag v0.19, and commit all resolved to 6f320637d56d344a0e7797753099e33238bbf146; the tree object is c26ce02b6c3ca4202993e039b3db7c28c353dee4. The clean, detached historical v0.7 worktree resolves to commit 74287f5db6b20320efd7892d7b29cf438fe7cb98 and tree 7184968c702afe038551bf3228cc25f455388bb6.

These source identities prove official implementations, not which shsrv binary—if any—is installed or running on the target PS5. No locally supplied shsrv/hbldr binary, package receipt, deployment log, or byte-exact device identity was found. The deployed identity remains UNPROVEN.

Why v0.7 and v0.19 are both relevant

The Phase-1.0Q LakeSnes source at commit a2db690123649c7ffbc68a663af31efb3a41bf3f states that shsrv v0.7 or later is required and launches the emulator with hbldr. Therefore v0.7 is the oldest source-bound implementation relevant to that port documentation. Version v0.19 is the latest official release inspected during Phase 1.0S.

The hbldr family began at commit 4a70b50eecab853408f0a93a579b90428369fa09 as an experimental loader that injects an ELF into a web application. The significant lineage is:

Point Commit/tag Source-proven behavior
introduction 4a70b50eecab853408f0a93a579b90428369fa09 inject an ELF into a webapp process
LakeSnes minimum v0.7, 74287f5... launch VideoPlayer BigApp PPSA01659, replace its process image
fake-game transition 18e9a62aea801b5a1be4a692dba76bf5381e9fcb attach homebrew to a created fake game
first release containing transition v0.8 fake-app/system-ex path present
current official release v0.19, 6f32063... launch FAKE00000, replace its process image

An official tag or source lineage is not deployed-use proof. The current device may use no shsrv, a historical build, a current build, or a modified binary.

Exact source identities

v0.19

File Size SHA-256
README.md 3,546 4855fa2adbe1fc0c7aa0174aa3275742d9b9aba3d818ae09cf2722a89b06cd34
shsrv.c 5,293 6ec71b4eb6c2bc1159f21568c1c9834f8aecac8d8881113bf09cf8981be19ee3
sh.c 13,278 3c4b7f76efdd157436ed4b353ee1b550bf3ff9df17c147b4762b767982fc8253
elfldr.c 17,911 4aa31f5a942681f8d88281b9713f087ced8963de842438cacad1088933f8e785
bundles/hbldr/main.c 1,520 6fa519888f79fe0458a983a517073c1eccc61239edfbe40d607f69b6b38a8af4
bundles/hbldr/hbldr.c 13,438 0096f86a00fdedcbc7509db47eb0f54dbc3e487d37e699f3de79048bac001be9

v0.7

File Size SHA-256
README.md 3,248 3d16e46416dd07940fcde1190a6ab558348bc80263da615331dda0f3eb6183ed
shsrv.c 4,716 66197d08308180fe923aa8aedc91bd5025f08938156ae3092ea2c69d0ad0be57
sh.c 8,449 bf97bc6dd3f49345ad8da9a29b28a5d6bcde5e53a6f32c60a538d6e187c7e05a
elfldr.c 17,920 1ff6cfa1300a95e8be48e5f7adc1413e3384ba04ea266c167fcd441ef20197d1
bundles/hbldr/main.c 7,134 2081ece2f7d0a7e9b392660696c2a44802f64680365607e742b37dcf3223a55a

PacBrew relationship

PacBrew commit c2abcfcb60f569128abd0e8e70ad03a67bee5ea7 contains an shsrv recipe that clones the official repository, uses pkgver=git, and declares sha256sums=('SKIP'). It installs shsrv.elf, but does not pin the fetched shsrv commit or prove which package was installed on the target. It is SOURCE_REPOSITORY_ASSOCIATION, not byte-exact deployment provenance.

Proven and unproven conclusions

SOURCE_PROVEN:

  • the official hbldr family creates or launches a BigApp and replaces that process with the requested ELF;
  • v0.7 and v0.19 differ materially from raw elfldr's SceSpZeroConf process;
  • both variants read the target ELF from a device path;
  • both may terminate the currently running BigApp and perform kernel/ptrace process mutations;
  • v0.19 may remount and persistently populate /system_ex/app/FAKE00000.

UNPROVEN:

  • which shsrv/hbldr binary is deployed;
  • whether FAKE00000 already exists on the target;
  • whether the launcher works on the specific firmware-9.60 runtime;
  • whether BigApp substitution provides the missing VideoOut permission;
  • whether it would make the exact RetroArch first submit succeed;
  • crash, cleanup, reboot, and visibility behavior on the target.

The source difference is a STRONG_SOURCE_CANDIDATE_NOT_PROVEN_ROOT_CAUSE. It does not authorize using hbldr, staging an ELF, connecting to shsrv, or creating a replacement launcher.