Direct FastRPC native-open probe
Date: 2026-09-25
FastRpcDirectIoctlProbe.ps1 was refactored to bind libc open, ioctl, and
close through Native.Binding.psm1. It no longer uses
Android.Systems.Os, reflects a managed file-descriptor object, or imports a
QNN-named delegate factory.
The refactored probe was staged with source-hash verification and run under
the installed diagnostic app package on physical SM8550 and SM8635 devices.
Both returned -1 when opening /dev/adsprpc-smd; neither reached the
read-only capability ioctl. Startup scripts were restored after each run.
The 2026-09-25 follow-up added SetLastError capture to the generic delegate
factory. Its clean-process Windows test confirmed that a failed native call
preserves the last-error value. On both Android devices, the same read-only
probe returned OpenErrno=13 (EACCES). The probe and binding files matched
their staged source hashes; each startup script was restored from a backup.
No speech path was run.
The pinned Qualcomm FastRPC userspace source at d247519
selects domain-specific device nodes; its
device-name definitions
distinguish ADSP and CDSP. The upstream
Android FastRPC driver
likewise names separate adsprpc-smd and cdsprpc-smd channels. A targeted
read-only device-node check found only adsprpc-smd and its secure variant on
each current phone; neither exposes cdsprpc-smd or fastrpc-cdsp at that
path. Thus even a successful open of adsprpc-smd would not prove a CDSP
session. This upstream source is not asserted to be the phones' exact vendor
driver or policy build.
This is a failed ADSP-node open probe, not a completed CDSP transport gate.
The result does not distinguish app SELinux policy from other access controls
or establish a permitted CDSP session API.
No private vendor ABI is inferred from binaries. The existing libcdsprpc.so
diagnostic path is separate evidence for the emitted kernel, not a product
transport. Direct, source-defined FastRPC ioctls and memory mapping remained
a candidate after this probe, not an established product requirement. A
source-matched CDSP descriptor route has not yet been established on these
phones. No claim is made about the vendor library's internal implementation
or about an undocumented HAL fallback. The later transport evidence ledger
separates this failed probe from the owner's reported Razr+ bypass test.