sceKernelWaitThreadEnd: Signed-Negative Intermediate Exit Status
Wave 4 record: FIND-THREAD-NEGEXIT-001 · Type: FINDING · Status: MEASURED / REPLICATION WANTED · Evidence: source-owned real PSP hardware · Reproduction confidence: ONE-RUN PRELIMINARY · Novelty: N3 candidate pending prior-art audit.
Scope boundary: PSP-3001 / 6.61-ARK, shared non-delete ThreadMan exit seam. Positive propagation, signed-negative observation, intermediate/outer wait behavior, and the non-delete limit are separate facts.
Status: HARDWARE MEASURED / DIFFERENTIAL · Scope: PSP-3001, firmware 6.61 with ARK · Last reviewed: 2026-08-11
Finding in one sentence
At a shared non-delete ThreadMan exit boundary, a signed-negative 32-bit intermediate status was observed through the outer sceKernelWaitThreadEnd call as SCE_KERNEL_ERROR_ILLEGAL_ARGUMENT (0x800200d2), while positive statuses were preserved. This is a bounded measured predicate, not a universal rule for every PSP termination path.
What was measured
The source-owned campaign used a PSP-3001 running firmware 6.61 with ARK. The harness exercised an ordinary thread exit and then waited on that thread from the outside. The raw capture and exact PRX are restricted; this article publishes the result classes and the controls, not private inputs or derived bytes.
| Exit-boundary value | Outer wait result | Interpretation |
|---|---|---|
0x800201ac (negative) |
0x800200d2 |
negative value normalized at this boundary |
ordinary signed -17 |
0x800200d2 |
same measured predicate |
0x800201a8 (wait-timeout-shaped negative) |
0x800200d2 |
same measured predicate in this control |
0x77 or 0x78 |
same positive value | positive control preserved |
Controls and evidence classes
- HARDWARE MEASURED: the PSP-3001/6.61-ARK record above, with a pre-wait status inspection. The inspection showed raw
status=0x10,waitType=0, andwaitId=0; those fields are reported as controls, not as a universal interpretation of status bits. - IMPLEMENTATION FACT: the public Nakagawa runtime documents the measured non-delete rule in sched.c and applies it at the thread-body exit and explicit exit paths. The wait implementation and join wake-up path are in hle.c.
- PRIOR ART: the PSPSDK ThreadMan declarations and the pinned PSPAutotests thread-end cases plus exit-status cases provide public kernel-test context. This page does not claim that either project already contains this exact case.
- DIFFERENTIAL: an older emulator/runtime comparison agreed on the unnormalized negative value, while the bounded hardware record above produced
0x800200d2. That comparison is a lead for reproduction, not a verdict that a particular emulator or firmware is “wrong.”
Hardware traceability
Directly observed: the outer return values and pre-wait status fields in the table above. Interpretation: signed-negative normalization at this shared non-delete boundary. Source/probe provenance: the source-owned probe and aggregate record are available for review; private raw captures are not published. Repeatability: this page records one accepted source-owned PSP-3001/6.61-ARK run; cross-device and cross-firmware repeatability is untested. Untested: delete paths, other models/firmware, and status values outside the listed controls.
Scope limits
The predicate is limited to the shared non-delete ThreadMan exit boundary tested above. It does not cover ExitDeleteThread, module self-unload, every negative integer or error code, other firmware or PSP models, or stock firmware without the tested CFW environment. The exact status-bit meaning and any behavior outside this boundary remain open.
Reproduction request
A useful public follow-up is a small, source-owned test that records the exit value, the pre-wait status fields, and the outer return value separately on a named firmware/model. Compare each input value independently and publish only aggregate results. Start with the Hardware Oracle Methodology, then apply the Evidence Standard; open variants belong in Open Research Questions.
Related reading: Static Recompilation Architecture and the Nakagawa Recomp Case Study.
Wave 4 record links
Experiment: EXP-THREAD-WAITEND-20260805-A · Conflict: CONFLICT-THREAD-WAITEND-001 · Registry: Hardware Findings · Experiments · Contradictions.
Source independence warning: Nakagawa/PPSSPP agreement is common-mode differential evidence, not independent PSP replication. Last reviewed: 2026-08-11.
Current source anchor — Wave 4
The current public implementation reference was refreshed against src/rt/sched.c at main 04daf156 and src/rt/hle.c at the same exact main revision. Any older commit link on this page is retained as historical lineage, not current-head evidence.