Skip to content

Ask what a stub libprivileged-service-client.so must export (issue 105) - #112

Merged
PatrickSt1991 merged 1 commit into
mainfrom
engine-imports-105
Oct 2, 2026
Merged

PatrickSt1991 merged 1 commit into
mainfrom
engine-imports-105

Conversation

@PatrickSt1991

Copy link
Copy Markdown
Contributor

Issue 105. The AU7200's build-3996334 report is the first trail on which the ladder's verdict is yes: all five locations map libovprobe.so executable and dlopen loads it, on one launch, in 243 ms, with the engine wall otherwise the Q80's line for line (libchromium-impl.so refused on libprivileged-service-client.so: Operation not permitted). The gate that refuses the engine's helper library does not refuse a native library of ours on this firmware. That is the third gate of the stub route, the one the Q80 failed.

EngineImports (src/common) asks what the stub must export, since the real library is the file the firmware will not let us open:

  1. Reads the implementation's dynamic section: DT_NEEDED and every undefined dynamic symbol (ELF32 on the set, ELF64 for the harness).
  2. dlopens each DT_NEEDED library by soname, then by path in the engine's directory, recording each refusal with the loader's words.
  3. Looks every non-weak import up in the process and in each library that loaded. What is left unresolved is the stub's export list, by name and kind (FUNC/OBJECT).

Runs on the post-failure probe thread after NativeProbe.Run and ahead of SmackWall.Investigate (whose last step is the one the Q80 never came back from), every step under a Deadline. Report: engine imports: header line, a what a stub must provide block in the full page, trail lines with up to forty names.

  • tools/engineimports/run.sh: builds a library in this box's architecture needing libm, libc and a libblocked.so made unopenable by permission; the census must name exactly that library's two symbols (one function, one data object), the refusal with the loader's words, nothing another library provides, no weak import. ELF32 path on the committed ARM libovprobe.so; a FIFO holds it to a recorded miss; a second call changes nothing.
  • docs/INTERNALS.md: A set that passed the third gate: the AU7200 (issue App doesn't load on Samsung AU7200 (Tizen OS 6.0) #105), with how to read the next report before it exists. CLAUDE.md has the harness.

Built: all five packages and OverscanProbe. Harness passes.

The AU7200's build-3996334 report is the first trail on which the ladder's
verdict is yes: every one of the five locations maps libovprobe.so
executable and dlopen loads it, on one launch, in 243 ms, while the engine
wall is otherwise the Q80's line for line. So the stub route the Q80 closed
is open on this set, and what it needs next is the one thing the firmware
will not let us read: the symbols the engine imports from the library it
refuses.

EngineImports asks the loader instead. It reads libchromium-impl.so's own
dynamic section (DT_NEEDED and every undefined dynamic symbol, ELF32 on the
set and ELF64 for the harness), dlopens each DT_NEEDED library by soname and
then by path in the engine's directory, recording each refusal with the
loader's words, and looks every non-weak import up in the process and in
each library that loaded. What is left is what a stub must export, by name
and kind. It runs on the post-failure probe thread ahead of the permission
investigation, every step under a Deadline, and lands as an engine imports:
header line, a block in the full report and trail lines.

tools/engineimports/run.sh builds a library that needs a libblocked.so made
unopenable by permission and holds the census to naming exactly its two
symbols; the committed ARM libovprobe.so exercises the ELF32 path.
@PatrickSt1991
PatrickSt1991 merged commit 283f3e9 into main Oct 2, 2026
7 checks passed
@PatrickSt1991
PatrickSt1991 deleted the engine-imports-105 branch October 2, 2026 11:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant