6.9 KiB
Phase 0.9C observation side-effect model
Status: OBSERVATION SIDE EFFECTS UNBOUNDED.
This is an offline classification. No observation ran on a PS5. A source-level
read, O_RDONLY, metadata query, syscall, or manager request is never
promoted to side-effect-free merely because project code does not write file
content.
Distinct effect dimensions
| Dimension | Meaning in this review | Required proof for absence |
|---|---|---|
| content | bytes of the observed object do not change | exact operation and all callees contain no content mutation |
| metadata | timestamps, flags, ownership, allocation or namespace state do not change | target filesystem and syscall semantics for the exact mount |
| atime | access time is not updated immediately or lazily | exact mount policy plus operation semantics |
| audit | platform audit/security/logging does not record the access | complete platform policy and service path |
| cache | page, name, attribute, service or network caches do not change | complete kernel/service implementation or an accepted bounded effect |
| counters | syscall, network, service, kernel or security counters do not change | complete implementation and counter inventory |
| service state | flags, wakeups, queues, worker state or functional service state do not change | exact service source and all invoked dependencies |
| security monitoring | access does not trigger security/accounting observation | exact policy and monitor implementation |
| open bookkeeping | descriptor tables, vnode references, locks, access records and reference counts remain unchanged | exact open/query semantics and close cleanup |
| process accounting | CPU time, scheduler data, resource usage and process records remain unchanged | platform accounting contract |
| object lifetime | an open/reference cannot delay deletion, replacement, unmount or cleanup | exact reference and namespace semantics |
| races | the observed identity cannot change between validation and read | stable-handle and concurrent-mutation contract |
Absence of a persistent content write proves none of the other rows.
Classification vocabulary
Every proposed observation is labelled with one or more of:
SEMANTICALLY_READONLY;METADATA_EFFECT_POSSIBLE;ATIME_EFFECT_POSSIBLE;AUDIT_EFFECT_POSSIBLE;CACHE_EFFECT_POSSIBLE;COUNTER_EFFECT_POSSIBLE;SERVICE_STATE_EFFECT_POSSIBLE;SECURITY_MONITORING_EFFECT_POSSIBLE;OPEN_BOOKKEEPING_EFFECT_POSSIBLE;PROCESS_ACCOUNTING_EFFECT_POSSIBLE;OBJECT_LIFETIME_EFFECT_POSSIBLE;OBJECT_RACE_POSSIBLE;NOT_PROVABLY_SIDE_EFFECT_FREE.
SEMANTICALLY_READONLY means only that the requested information flow does
not intentionally alter the observed value. Every row below remains
NOT_PROVABLY_SIDE_EFFECT_FREE.
Observation matrix
| Observation | Application intent | Possible effects | Source boundary | Result |
|---|---|---|---|---|
| runtime self-identity | compare in-memory fixed identity | cache, audit, process accounting, loader mapping already exists | no target implementation | NOT_PROVABLY_SIDE_EFFECT_FREE |
| firmware source 1 | read sdk_ps5_ver process parameter |
syscall/dynamic-member lookup, cache, audit, counters, process accounting | SDK crt/kernel.c:148-170; requires prohibited normal runtime dependencies |
NOT_PROVABLY_SIDE_EFFECT_FREE |
| firmware source 2 | independently query current system firmware | all query ABI and effects unknown | only an export name exists; no accepted ABI | UNPROVEN |
| mount query | enumerate mount state | cache, audit, counters, locks, reference lifetime, snapshot races | SDK sample only; runtime semantics unproven | NOT_PROVABLY_SIDE_EFFECT_FREE |
| file metadata | no-follow stable-object metadata | metadata/access bookkeeping, cache, audit, reference lifetime, races | manager host/source pattern only | NOT_PROVABLY_SIDE_EFFECT_FREE |
| object ID and size | compare pre/post identity | same as metadata plus concurrent replacement race | manager verified_launcher.c:26-29,83-115,174-176 |
NOT_PROVABLY_SIDE_EFFECT_FREE |
| file SHA-256 | bounded descriptor read | atime, metadata, page cache, audit, counters, open bookkeeping, lifetime, races | manager verified_launcher.c:31-55; PS5 semantics unproven |
NOT_PROVABLY_SIDE_EFFECT_FREE |
| process snapshot | enumerate process records | kernel allocation/cache/counters, scheduler/accounting, snapshot races | SDK process sample is partial | NOT_PROVABLY_SIDE_EFFECT_FREE |
| service snapshot | map services and supervisors | service queries, queues/counters/cache/audit and races | no complete API or mapping | UNPROVEN |
| listener snapshot | enumerate sockets and owners | network counters/cache/locks, service state, owner mapping races | no accepted API | UNPROVEN |
| autoload/startup/retry | read all authoritative sources | atime/metadata/cache/audit/open state; stock HTTP also changes global/autoload state | Phase 0.8R source audit | NOT_PROVABLY_SIDE_EFFECT_FREE; stock route is side-effecting |
| rollback objects | metadata and hash existing backups | same filesystem effects plus object lifetime and target/backup race | no current paths or objects | UNPROVEN |
| monotonic time | enforce deadline | clock/syscall counters, vDSO/runtime dependencies, accounting | only loader-owned clock use is source-proven | NOT_PROVABLY_SIDE_EFFECT_FREE for a future observer |
| result publication | write caller-owned transient buffer | caller memory mutation, cache, accounting, synchronization and lifetime | host-only concept; no target owner | UNPROVEN |
Stock Payload Manager remains inadmissible
Phase 0.8R already proves that non-OPTIONS requests set
server_active_flag, /autoload_status sets autoload_triggered, and several
routes read configuration or mutate logging state. OPTIONS does not provide
the needed data and still has unproven network, allocation, audit, cache,
scheduler and counter effects.
Phase 0.9C does not reinterpret those endpoints as a collector. A persistent listener or HTTP response is also forbidden as observer output.
Filesystem-specific conclusion
The controlled manager demonstrates a useful source pattern:
open(O_RDONLY | O_NOFOLLOW | O_CLOEXEC)
-> fstat
-> bounded read
-> fstat
-> lstat path
-> compare identity/size
-> close
That pattern can detect several races in the reviewed source. It does not prove no atime update, no audit record, no page-cache fill, no vnode/reference bookkeeping, no process accounting, or no platform-specific service effect. It also cannot make a hash atomic with respect to every target namespace race without proven filesystem and stable-object semantics.
Decision
No planned observation is proven side-effect-free on firmware 9.60. A later phase would need an explicit bounded-effect budget rather than an absolute zero-effect claim, plus exact public ABI/source evidence and separately authorized runtime observation. Phase 0.9C grants neither.
Current blocker: BLOCKED_OBSERVATION_SIDE_EFFECTS_UNBOUNDED.