Skip to main content
Print

Experiment: WaitThreadEnd Signed-Negative Boundary

Experiment ID: EXP-THREAD-WAITEND-20260805-A · State: ACCEPTANCE ELIGIBLE · Classification: source-owned real-hardware measurement

Question

How does the outer sceKernelWaitThreadEnd report a joiner whose intermediate thread exit status is signed-negative?

Competing explanations

  • Negative PSP error-shaped values might propagate unchanged.
  • Only a particular PSP error-code prefix might normalize.
  • The boundary might depend on synchronization or on explicit versus implicit exit.

Fixture and environment

Source-owned, non-destructive ThreadMan probe; exact PRX and raw capture are private. Hardware: PSP-3001, firmware 6.61 with ARK. Transport: PSPLink/HostFS, accepted only after the session passed its transport health gate. Exact private source path, binary hash, and raw capture are intentionally withheld.

Procedure and controls

  1. Synchronize the joiner with a semaphore before the outer wait.
  2. Record the pre-wait status fields separately.
  3. Compare an error-shaped implicit return with positive controls.
  4. Repeat with explicit sceKernelExitThread, 0x800201a8, and ordinary signed -17.

Public-safe observation

Intermediate value Outer/latched result Control interpretation
0x800201ac 0x800200d2 negative value normalized
0x800201a8 0x800200d2 same predicate in this control
-17 0x800200d2 prefix-only explanation falsified
0x77 / 0x78 same positive value positive propagation control

Pre-wait inspection reported raw status=0x10, waitType=0, and waitId=0. The rejected unsynchronized iteration is not counted as acceptance evidence; its raw signal was retained in private provenance rather than rewritten.

Interpretation and supported claims

For the measured shared non-delete ThreadMan exit boundary, signed-negative exit status is observed/latch-normalized to 0x800200d2, while positive status is preserved. This supports FIND-THREAD-NEGEXIT-001 and the bounded WaitThreadEnd synthesis.

Claims not supported

  • No claim about ExitDeleteThread, module self-unload, every wait path, other models, other firmware, or stock firmware without the tested CFW mediation.
  • No claim that a generic HLE error-normalization helper should rewrite ordinary API errors.

Public implementation comparison

The current public runtime records the same measured boundary in sched.c and routes the wait/join path through hle.c. That is an implementation comparison, not independent hardware evidence.

Replication

Use a source-owned probe that reports the exit value, pre-wait status fields, and outer result as separate scalars. Repeat on another PSP-3000 and on PSP-1000/2000 if safe. Report model family, firmware/CFW, fixture identity, repeat count, and scalar results only. Do not upload retail data, keys, saves, device identifiers, or private captures.

Related: FIND-THREAD-NEGEXIT-001 · CONFLICT-THREAD-WAITEND-001 · Hardware Oracle Methodology.

Publication safety: PRIVATE ACCEPTANCE / PRIVATE EVIDENCE EXISTS; public aggregate only. Last reviewed: 2026-08-11.

Table of Contents