64 lines
2.9 KiB
Markdown
64 lines
2.9 KiB
Markdown
# Phase 0.9E-R remaining provenance gaps
|
|
|
|
Date: 2026-07-18
|
|
|
|
Overall decision: `LOCAL_BACKUP_NOT_CORRELATED`
|
|
|
|
## Closed questions
|
|
|
|
- The local outer ZIP retains its Phase-0.9E size and SHA-256.
|
|
- The official current inventory consists of releases 1.3, 1.5, and 1.6 and
|
|
tags `Y2JB-1.2.1`, 1.3, 1.4, 1.5, and 1.6.
|
|
- All seven current official release assets have official SHA-256 digests,
|
|
names, and sizes different from the local outer ZIP.
|
|
- Official tag commits, trees, source archives, and host sender are bound.
|
|
- Official Y2JB does not implement a port-9020 listener in the inspected tags.
|
|
- Its Remote JS Loader is a dynamic port listener normally seeking 50000.
|
|
- Port 9021 belongs to an embedded elfldr path reached after Lapse/kexp.
|
|
|
|
## Remaining gaps
|
|
|
|
1. The source, author, version, and construction procedure for
|
|
`Y2JB-Autoloader-403-1240.zip` are unknown.
|
|
2. The MediaFire download marker does not identify an official release asset.
|
|
3. The local opaque `SIECAF` content cannot be matched to official source.
|
|
4. No evidence binds the local outer ZIP to what was restored on the PS5.
|
|
5. No evidence shows whether `download0.dat` or app data was later replaced.
|
|
6. No evidence identifies the operator's actual host sender.
|
|
7. No evidence explains the previously assumed port-9020 listener.
|
|
8. The source/generator identity of the 1.6 embedded elfldr and kexp blobs is
|
|
not present in Y2JB.
|
|
9. Runtime behavior on firmware 9.60 remains unobserved.
|
|
10. Independent recovery and the current Payload Manager backup remain
|
|
unresolved installation blockers.
|
|
11. The exact requested official source-archive URLs are recorded, but the
|
|
transient GitHub redirect URLs were not retained.
|
|
|
|
The official sender is one-way. The JavaScript server can write log bytes on
|
|
its accepted socket, but `payload_sender.py` never receives them. Therefore no
|
|
existing end-to-end duplex result channel is established. Reusing that
|
|
connection would require a different host contract; an outbound connection or
|
|
temporary listener would require new target design. No output architecture is
|
|
selected while the exact-used bootstrap remains unbound.
|
|
|
|
## Phase 0.9F gate
|
|
|
|
`phase09f_offline_design_allowed=false`.
|
|
|
|
The mandatory official outer-asset byte match is absent and the inspected
|
|
official source has only a 9020 reference, not a found or partial 9020
|
|
implementation. Device observation cannot be used to repair these facts in
|
|
this phase.
|
|
|
|
Minimum safe next evidence:
|
|
|
|
- a verifiable publisher/provenance record for the exact MediaFire-marked
|
|
outer ZIP, or a different operator-provided exact outer ZIP that matches an
|
|
official asset;
|
|
- a completed non-runtime operator attestation;
|
|
- exact identification of any external autoloader or 9020 implementation and
|
|
sender used in the real workflow.
|
|
|
|
Supplying evidence grants no connection, transfer, installation, execution,
|
|
autoload, device-write, or retry authority.
|