Table of contents

Direct FastRPC native-open probe

Kokoro-Hexagon 0a03be39Updated 2026-09-25

Date: 2026-09-25

FastRpcDirectIoctlProbe.ps1 was refactored to bind libc open, ioctl, and close through Native.Binding.psm1. It no longer uses Android.Systems.Os, reflects a managed file-descriptor object, or imports a QNN-named delegate factory.

The refactored probe was staged with source-hash verification and run under the installed diagnostic app package on physical SM8550 and SM8635 devices. Both returned -1 when opening /dev/adsprpc-smd; neither reached the read-only capability ioctl. Startup scripts were restored after each run.

The 2026-09-25 follow-up added SetLastError capture to the generic delegate factory. Its clean-process Windows test confirmed that a failed native call preserves the last-error value. On both Android devices, the same read-only probe returned OpenErrno=13 (EACCES). The probe and binding files matched their staged source hashes; each startup script was restored from a backup. No speech path was run.

The pinned Qualcomm FastRPC userspace source at d247519 selects domain-specific device nodes; its device-name definitions distinguish ADSP and CDSP. The upstream Android FastRPC driver likewise names separate adsprpc-smd and cdsprpc-smd channels. A targeted read-only device-node check found only adsprpc-smd and its secure variant on each current phone; neither exposes cdsprpc-smd or fastrpc-cdsp at that path. Thus even a successful open of adsprpc-smd would not prove a CDSP session. This upstream source is not asserted to be the phones' exact vendor driver or policy build.

This is a failed ADSP-node open probe, not a completed CDSP transport gate. The result does not distinguish app SELinux policy from other access controls or establish a permitted CDSP session API. No private vendor ABI is inferred from binaries. The existing libcdsprpc.so diagnostic path is separate evidence for the emitted kernel, not a product transport. Direct, source-defined FastRPC ioctls and memory mapping remained a candidate after this probe, not an established product requirement. A source-matched CDSP descriptor route has not yet been established on these phones. No claim is made about the vendor library's internal implementation or about an undocumented HAL fallback. The later transport evidence ledger separates this failed probe from the owner's reported Razr+ bypass test.