Experiment: WaitThreadEnd Signed-Negative Boundary
Experiment ID: EXP-THREAD-WAITEND-20260805-A · State: ACCEPTANCE ELIGIBLE · Classification: source-owned real-hardware measurement
Question
How does the outer sceKernelWaitThreadEnd report a joiner whose intermediate thread exit status is signed-negative?
Competing explanations
- Negative PSP error-shaped values might propagate unchanged.
- Only a particular PSP error-code prefix might normalize.
- The boundary might depend on synchronization or on explicit versus implicit exit.
Fixture and environment
Source-owned, non-destructive ThreadMan probe; exact PRX and raw capture are private. Hardware: PSP-3001, firmware 6.61 with ARK. Transport: PSPLink/HostFS, accepted only after the session passed its transport health gate. Exact private source path, binary hash, and raw capture are intentionally withheld.
Procedure and controls
- Synchronize the joiner with a semaphore before the outer wait.
- Record the pre-wait status fields separately.
- Compare an error-shaped implicit return with positive controls.
- Repeat with explicit
sceKernelExitThread,0x800201a8, and ordinary signed-17.
Public-safe observation
| Intermediate value | Outer/latched result | Control interpretation |
|---|---|---|
0x800201ac |
0x800200d2 |
negative value normalized |
0x800201a8 |
0x800200d2 |
same predicate in this control |
-17 |
0x800200d2 |
prefix-only explanation falsified |
0x77 / 0x78 |
same positive value | positive propagation control |
Pre-wait inspection reported raw status=0x10, waitType=0, and waitId=0. The rejected unsynchronized iteration is not counted as acceptance evidence; its raw signal was retained in private provenance rather than rewritten.
Interpretation and supported claims
For the measured shared non-delete ThreadMan exit boundary, signed-negative exit status is observed/latch-normalized to 0x800200d2, while positive status is preserved. This supports FIND-THREAD-NEGEXIT-001 and the bounded WaitThreadEnd synthesis.
Claims not supported
- No claim about
ExitDeleteThread, module self-unload, every wait path, other models, other firmware, or stock firmware without the tested CFW mediation. - No claim that a generic HLE error-normalization helper should rewrite ordinary API errors.
Public implementation comparison
The current public runtime records the same measured boundary in sched.c and routes the wait/join path through hle.c. That is an implementation comparison, not independent hardware evidence.
Replication
Use a source-owned probe that reports the exit value, pre-wait status fields, and outer result as separate scalars. Repeat on another PSP-3000 and on PSP-1000/2000 if safe. Report model family, firmware/CFW, fixture identity, repeat count, and scalar results only. Do not upload retail data, keys, saves, device identifiers, or private captures.
Related: FIND-THREAD-NEGEXIT-001 · CONFLICT-THREAD-WAITEND-001 · Hardware Oracle Methodology.
Publication safety: PRIVATE ACCEPTANCE / PRIVATE EVIDENCE EXISTS; public aggregate only. Last reviewed: 2026-08-11.