6.6 KiB
Phase 0.9C capability closure
Status: NO TARGET CAPABILITY CLOSED.
“Host evidence” below means a deterministic model or source validator. It is
not PS5 evidence. implementation allowed and execution allowed are false
for every capability because the startup/exit, output, firmware-source, and
side-effect gates fail before target implementation.
Closure matrix
| Capability | Source evidence | Host evidence | Target evidence | Implement allowed | Execute allowed | Remaining blocker |
|---|---|---|---|---|---|---|
| runtime self-identity | future protocol binds observer version and artifact SHA-256 | framing validates both | absent | false | false | no target artifact or runtime self-binding |
| firmware source 1 | SDK kernel_get_fw_version, crt/kernel.c:148-170 |
protocol binds raw value | absent | false | false | depends on prohibited runtime and is not independent system identity |
| firmware source 2 | export-stub name only, no accepted signature/semantics | missing/conflict tests fail closed | absent | false | false | independent accepted source absent |
| mount query | SDK samples/mntinfo and libc wrapper |
unsupported can be represented | absent | false | false | ABI, completeness, runtime behavior and effects unproven |
| metadata | controlled manager no-follow pattern | result framing can represent error | absent | false | false | target metadata/no-follow semantics and effects unproven |
| object ID | manager compares st_dev/st_ino |
completeness rules modeled | absent | false | false | stable target identity and race contract unproven |
| size | manager compares exact st_size |
checked result length modeled | absent | false | false | current object and stable-read evidence absent |
| SHA-256 | bounded same-FD manager implementation | checksum corruption is rejected | absent | false | false | target read effects, current paths and stable object absent |
| processes | SDK samples/ps partial snapshot |
unsupported result modeled | absent | false | false | complete ABI, bounds and semantics absent |
| services | no complete source/API mapping | unsupported result modeled | absent | false | false | service inventory and ownership semantics absent |
| listeners | no accepted snapshot/owner API | unsupported result modeled | absent | false | false | listener API, ownership and side effects absent |
| autoload/startup/retry | stock manager readers/HTTP are incomplete or side-effecting | missing source remains blocked | absent | false | false | complete authoritative sources and safe collector absent |
| rollback objects | Phase 0.8R/0.9A evidence contract only | no false promotion in validators | absent | false | false | current exact backups absent; manager backup is hard blocker |
| monotonic time | hardened loader uses CLOCK_MONOTONIC |
deadline expiry is rejected | absent in observer ABI | false | false | loader exposes no clock callback; freestanding callable ABI absent |
| startup | SDK and hardened loader callgraphs | startup classifications validated | absent | false | false | normal CRT writes; freestanding dependency closure incomplete |
| output | current route proven send-only; D1 host contract defined | 4096-byte framing and negative tests | absent | false | false | no caller-owned target buffer/copy-out/manager delivery |
| normal exit | loader has wait/reap; status discarded | no safe exit terminal modeled | absent | false | false | return/exit semantics and teardown unproven |
| error exit | CRT error/longjmp/trap and loader reap reviewed | observer error cannot equal empty success | absent | false | false | partial unwind, status and cleanup unproven |
| timeout | loader SIGTERM/SIGKILL watchdog reviewed | timeout record is rejected | absent | false | false | kill/timeout is not an admissible safe exit |
| cleanup | pre-detach cleanup state exists; post-detach relies on process lifetime | failed/incomplete cleanup rejected | absent | false | false | mappings, FDs, buffers, loader and manager cleanup not jointly proven |
| recovery independence | Phase 0.9A contract | blocker preserved | absent | false | false | recovery executor and exact rollback objects unproven |
Firmware-source closure
Current source 1 reads a process-parameter field associated with
libSceLibcInternal; its own comment says it is chosen because some payloads
modify the kernel-reported value. That makes it useful source evidence, but
not an independent second current device identity.
The SDK stubs contain
sceKernelGetProsperoSystemSwVersion, but a stub exports only a name/NID
surface. The repository has no reviewed public prototype, result layout,
return semantics, side-effect contract, or firmware-9.60 observation. It is
not callable evidence and is not source 2.
A future source 2 must:
- be official/reproducible public platform evidence or a separately reviewed locally obtained runtime value;
- have exact function/data ABI and side-effect evidence;
- identify the current system, not the observer's compiled SDK requirement;
- produce an exact raw value under the same deadline;
- be independent of source 1's data origin;
- bind source identity, raw result, nonce, request ID, observer artifact hash and deadline into the result record; and
- fail closed if absent, ambiguous, stale, or conflicting.
The host protocol returns
BLOCKED_FIRMWARE_SOURCE_2_ABSENT for absence and
BLOCKED_FIRMWARE_CONFLICT for disagreement. It never normalizes a conflict
away or prefers one source.
Cross-gate closure
The following dependencies form one conjunctive gate:
kernelwrite-free usable startup
+ proven stack/relocation/BSS/TLS closure
+ callable bounded observation primitives
+ two bound firmware sources
+ bounded transient output
+ normal/error/deadline exit without kill
+ complete cleanup and unambiguous status
+ bounded accepted observation effects
= target implementation may be reconsidered
Every term is required. A passing host protocol cannot compensate for a missing exit ABI. A proven read algorithm cannot compensate for an absent output channel. Two firmware strings cannot compensate for an unreviewed ABI or stale execution binding.
Decision
Closed for host design:
- startup graph classifications are explicit;
- the freestanding missing dependencies are explicit;
- D1 framing is fixed at 4096 bytes and fails closed;
- stale, duplicate, incomplete, corrupt, timed-out and conflicting records are rejected; and
- every capability has an explicit blocker.
Not closed for target implementation:
- all 21 capabilities in the matrix.
The capability result contributes to
BLOCKED_MULTIPLE_FOUNDATIONAL_CONTRACTS.