3.3 KiB
Phase 0.6 independent review
Historical record: superseded for current deployment preparation by the new Phase-0.7 hardened binaries. This blocked decision remains authoritative for the unmodified public-release chain.
Date: 2026-07-17. Final decision: BLOCKED_VERSION_OR_UNBOUNDED_EFFECT.
SAFE below means proven only for the stated offline/source scope. UNSAFE
means incompatible with the mandatory controlled profile. UNPROVEN means
required primary evidence is absent.
| Component | Status | Finding |
|---|---|---|
| private project isolation | SAFE |
only chimera-gfx changed |
| firmware claim | UNPROVEN |
exact 9.60 supplied by Jens; no device attestation |
| Payload Manager identity | SAFE |
v0.3.1 asset hash matches commit/release |
| elfldr identity | SAFE |
installed v0.23 asset hash matches exact public release |
| proposed itsPLK elfldr | SAFE exclusion |
release hash differs; not audited as installed |
| exploit/autoloader identity | UNPROVEN |
local backup is not installed-chain proof |
| separate payload process | SAFE source fact |
rfork/exec creates SceSpZeroConf child |
RSP/RIP/RDI setup |
SAFE source fact |
exact assignments identified |
| return continuation | UNPROVEN |
trap RIP semantics and SDK terminate branch unresolved |
| ptrace completion | UNSAFE |
single-step loops have no finite bound |
| maximum runtime | UNSAFE |
detached child has no two-second watchdog |
| retry behavior | SAFE project policy |
no project retry or execution path exists |
| normal authid restore | SAFE success path |
loader backs up and restores |
| authid restore failure | UNSAFE |
no recovery after failed restore |
| child credential restore | UNPROVEN partial |
jail/root/caps/authid restored; UID not restored |
| breakpoint byte | SAFE |
restored before payload detach |
| breakpoint permissions | UNPROVEN cleanup |
page remains RWX until unproven child exit |
| payload args/resources | UNPROVEN cleanup |
mappings, sockets and pipe rely on child exit |
__patch_init |
SAFE classification |
known payload-process-local effect; not an automatic blocker |
| child exit/reaping | UNPROVEN |
post-detach semantics not documented |
| manager launch hash | UNSAFE |
path-bound stream; no launch-time SHA-256 verification |
| manager upload | UNSAFE |
persistent /data/pldmgr/payloads write |
| GNM/VideoOut/SDL/MMIO | SAFE nonexistence |
no lifecycle source or artifact was created |
| lifecycle artifact | SAFE nonexistence |
Phase D stopped before source/build |
| legacy blocked artifact | SAFE policy |
permanent denylist unchanged |
| transfer/execution | SAFE nonoccurrence |
neither happened; no approval requested |
Artifact disposition
There is no artifact path, artifact size, artifact SHA-256, or source commit
because no lifecycle probe was built. The machine profile contains null for
each of those fields and execution_eligible=false. No ELF is committed.
The permanent blocked SHA-256 remains:
4be1c17b4964f2b68c39b5145bc4af4619c32512d60269ecf5c39728b390fa63
This review is not an approval package. Reopening Phase D requires resolving
every minimum-evidence item in phase-0.6-loader-audit.md, followed by a new
offline audit and a new decision. It does not require or request execution
permission now.