Files
chimera-gfx-Public/docs/runtime/phase-0.9c-side-effect-model.md
T
Chimera GFX release export a6037502d7
phase0-ci / build-and-audit (push) Successful in 2m14s
Publish Chimera GFX source
2026-09-03 03:27:14 +02:00

6.9 KiB

Phase 0.9C observation side-effect model

Status: OBSERVATION SIDE EFFECTS UNBOUNDED.

This is an offline classification. No observation ran on a PS5. A source-level read, O_RDONLY, metadata query, syscall, or manager request is never promoted to side-effect-free merely because project code does not write file content.

Distinct effect dimensions

Dimension Meaning in this review Required proof for absence
content bytes of the observed object do not change exact operation and all callees contain no content mutation
metadata timestamps, flags, ownership, allocation or namespace state do not change target filesystem and syscall semantics for the exact mount
atime access time is not updated immediately or lazily exact mount policy plus operation semantics
audit platform audit/security/logging does not record the access complete platform policy and service path
cache page, name, attribute, service or network caches do not change complete kernel/service implementation or an accepted bounded effect
counters syscall, network, service, kernel or security counters do not change complete implementation and counter inventory
service state flags, wakeups, queues, worker state or functional service state do not change exact service source and all invoked dependencies
security monitoring access does not trigger security/accounting observation exact policy and monitor implementation
open bookkeeping descriptor tables, vnode references, locks, access records and reference counts remain unchanged exact open/query semantics and close cleanup
process accounting CPU time, scheduler data, resource usage and process records remain unchanged platform accounting contract
object lifetime an open/reference cannot delay deletion, replacement, unmount or cleanup exact reference and namespace semantics
races the observed identity cannot change between validation and read stable-handle and concurrent-mutation contract

Absence of a persistent content write proves none of the other rows.

Classification vocabulary

Every proposed observation is labelled with one or more of:

  • SEMANTICALLY_READONLY;
  • METADATA_EFFECT_POSSIBLE;
  • ATIME_EFFECT_POSSIBLE;
  • AUDIT_EFFECT_POSSIBLE;
  • CACHE_EFFECT_POSSIBLE;
  • COUNTER_EFFECT_POSSIBLE;
  • SERVICE_STATE_EFFECT_POSSIBLE;
  • SECURITY_MONITORING_EFFECT_POSSIBLE;
  • OPEN_BOOKKEEPING_EFFECT_POSSIBLE;
  • PROCESS_ACCOUNTING_EFFECT_POSSIBLE;
  • OBJECT_LIFETIME_EFFECT_POSSIBLE;
  • OBJECT_RACE_POSSIBLE;
  • NOT_PROVABLY_SIDE_EFFECT_FREE.

SEMANTICALLY_READONLY means only that the requested information flow does not intentionally alter the observed value. Every row below remains NOT_PROVABLY_SIDE_EFFECT_FREE.

Observation matrix

Observation Application intent Possible effects Source boundary Result
runtime self-identity compare in-memory fixed identity cache, audit, process accounting, loader mapping already exists no target implementation NOT_PROVABLY_SIDE_EFFECT_FREE
firmware source 1 read sdk_ps5_ver process parameter syscall/dynamic-member lookup, cache, audit, counters, process accounting SDK crt/kernel.c:148-170; requires prohibited normal runtime dependencies NOT_PROVABLY_SIDE_EFFECT_FREE
firmware source 2 independently query current system firmware all query ABI and effects unknown only an export name exists; no accepted ABI UNPROVEN
mount query enumerate mount state cache, audit, counters, locks, reference lifetime, snapshot races SDK sample only; runtime semantics unproven NOT_PROVABLY_SIDE_EFFECT_FREE
file metadata no-follow stable-object metadata metadata/access bookkeeping, cache, audit, reference lifetime, races manager host/source pattern only NOT_PROVABLY_SIDE_EFFECT_FREE
object ID and size compare pre/post identity same as metadata plus concurrent replacement race manager verified_launcher.c:26-29,83-115,174-176 NOT_PROVABLY_SIDE_EFFECT_FREE
file SHA-256 bounded descriptor read atime, metadata, page cache, audit, counters, open bookkeeping, lifetime, races manager verified_launcher.c:31-55; PS5 semantics unproven NOT_PROVABLY_SIDE_EFFECT_FREE
process snapshot enumerate process records kernel allocation/cache/counters, scheduler/accounting, snapshot races SDK process sample is partial NOT_PROVABLY_SIDE_EFFECT_FREE
service snapshot map services and supervisors service queries, queues/counters/cache/audit and races no complete API or mapping UNPROVEN
listener snapshot enumerate sockets and owners network counters/cache/locks, service state, owner mapping races no accepted API UNPROVEN
autoload/startup/retry read all authoritative sources atime/metadata/cache/audit/open state; stock HTTP also changes global/autoload state Phase 0.8R source audit NOT_PROVABLY_SIDE_EFFECT_FREE; stock route is side-effecting
rollback objects metadata and hash existing backups same filesystem effects plus object lifetime and target/backup race no current paths or objects UNPROVEN
monotonic time enforce deadline clock/syscall counters, vDSO/runtime dependencies, accounting only loader-owned clock use is source-proven NOT_PROVABLY_SIDE_EFFECT_FREE for a future observer
result publication write caller-owned transient buffer caller memory mutation, cache, accounting, synchronization and lifetime host-only concept; no target owner UNPROVEN

Stock Payload Manager remains inadmissible

Phase 0.8R already proves that non-OPTIONS requests set server_active_flag, /autoload_status sets autoload_triggered, and several routes read configuration or mutate logging state. OPTIONS does not provide the needed data and still has unproven network, allocation, audit, cache, scheduler and counter effects.

Phase 0.9C does not reinterpret those endpoints as a collector. A persistent listener or HTTP response is also forbidden as observer output.

Filesystem-specific conclusion

The controlled manager demonstrates a useful source pattern:

open(O_RDONLY | O_NOFOLLOW | O_CLOEXEC)
-> fstat
-> bounded read
-> fstat
-> lstat path
-> compare identity/size
-> close

That pattern can detect several races in the reviewed source. It does not prove no atime update, no audit record, no page-cache fill, no vnode/reference bookkeeping, no process accounting, or no platform-specific service effect. It also cannot make a hash atomic with respect to every target namespace race without proven filesystem and stable-object semantics.

Decision

No planned observation is proven side-effect-free on firmware 9.60. A later phase would need an explicit bounded-effect budget rather than an absolute zero-effect claim, plus exact public ABI/source evidence and separately authorized runtime observation. Phase 0.9C grants neither.

Current blocker: BLOCKED_OBSERVATION_SIDE_EFFECTS_UNBOUNDED.