Skip to main content
Print

DMAC Overlap Behavior: Bounded sceDmacMemcpy Results and Open Edges


Wave 4 structured record

Stable ID: FIND-DMAC-OVERLAP-001

Evidence class: MEASURED / CROSS-MODEL NEEDED. This record separates public prior art from a bounded source-owned PSP-3001 / 6.61 ARK measurement of sceDmacMemcpy behavior.

Scope: Same-pointer success/no-corruption and forward/backward overlap were observed for measured RAM ranges; sizes through 0xC000 completed in the full tested set. A high-size tail-loss observation remains preliminary, and its exact boundary is deliberately withheld pending corrected v6 instrumentation. TryMemcpy semantics are not fully resolved.

Reproduction confidence: REPEATED SAME DEVICE for the bounded cases; replication on PSP-1000/2000/Go/Street and a corrected boundary probe are requested. Do not infer a universal maximum from this page.

Novelty/support: N2 bounded hardware evidence and N3 useful overlap discriminators. It supports EXP-DMAC-OVERLAP-20260806-A.

Status: HARDWARE MEASURED / PRIOR ART · Scope: PSP-3001 controlled campaign · Novelty posture: N3 candidate for the checked overlap cases · Last reviewed: 2026-08-11

Why overlap needs its own claim

sceDmacMemcpy and sceDmacTryMemcpy have a sparse public contract. A result that looks like memmove for a few offsets is not permission to promise memmove semantics for every alignment, cache state, size, or firmware. This page records only the checked cases and keeps the open edges visible.

Public prior art and measured cases

The pinned PSPSDK DMAC header exposes the APIs. PSPAutotests’ pinned DMAC source and expected output provide prior-art edge cases including normal copy success, NULL + nonzero returning 0x80000103, zero size returning 0x80000104, and a busy-like concurrent 1 MiB case returning 0x80000021. PPSSPP’s public sceDmac implementation warns on overlapping reads but leaves the overlap semantics as an open TODO.

Checked PSP-3001 case Observed result Claim class
same-pointer self-copy returned 0 with no observed corruption HARDWARE MEASURED, bounded
forward overlap correct for the checked offsets/sizes HARDWARE MEASURED, bounded
backward overlap correct for the checked offsets/sizes HARDWARE MEASURED, bounded
sizes through 0xc000 copied in the checked campaign HARDWARE MEASURED, bounded

The same-pointer observation should not be described as a direct contradiction of an older PSPAutotests comment that a self-copy “crashes.” Pointer alignment, exact size, cache state, and firmware conditions must be reproduced before those records can be compared.

Prior-art survey (2026-08-11)

Checked the PSPSDK DMAC header, PSPAutotests source/expected output, the PPSSPP DMAC implementation, PSP Developer Wiki material, YAPSPD and archived PSP documentation, and PSP RE HQ. Found: API signatures, public invalid-input/size/concurrency results, an older self-copy test comment, and an emulator warning that overlap behavior remains unresolved. No checked source publishes the same-pointer, forward-overlap, backward-overlap, and bounded-size PSP-3001 result matrix reported here. That matrix is the narrow addition claimed. Absence from this survey does not prove that no prior art exists elsewhere; N3 remains a candidate for these checked cases, not a discovery claim.

Hardware traceability

Directly observed: returned statuses and byte checks for the named same-pointer, forward/backward-overlap, and bounded-size cases on PSP-3001. Interpretation: those checked cases behaved correctly without an asserted universal memmove contract. Source/probe provenance: the source-owned case table and reproduction checklist are public; private raw captures are not published. Firmware/CFW: not specified in this public-safe summary; reproduce with a named firmware/CFW before comparison. Repeatability/untested: cross-device, cross-firmware, cache-state, alignment, and larger-size repeatability remain untested.

Do not publish a maximum

Preliminary high-size probes at 63488, 64512, 65535, and 65536 bytes lost final bytes. The interval between the successful and failing observations is too large and too sparsely measured to support a maximum-transfer claim. Treat those probes as an open boundary, not a limit.

Reproduction checklist

  • Record source/destination alignment and exact overlap direction.
  • Separate returned status from copied-byte verification.
  • Control cache state and concurrent transfers.
  • Repeat each size on a named PSP model and firmware.
  • Keep private captures and game inputs out of the public artifact.

Use the Hardware Oracle Methodology and Evidence Standard when extending the matrix. Related context: PSP Executable Model and Open Research Questions.

Contradiction/next experiment: The same-pointer disagreement is tracked as CONFLICT-DMAC-SAMEPTR-001; the smallest resolving follow-up is EXP-DMAC-BOUNDARY-V6-001, kept planned until corrected instrumentation is available. See REG-HARDWARE-FINDINGS-001 and do not publish private captures, addresses, or retail buffers.

Current source anchor — Wave 4

The runtime comparison was refreshed against src/rt/hle.c at main 04daf156. This link anchors the current public implementation; the measured ceiling remains intentionally unclaimed.

Table of Contents