Table of contents

PowerShell-emitted Hexagon ELF executes on the S23

Kokoro-Hexagon 0a03be39Updated 2026-09-23

Result

PowerShell emitted both the ELF container and all 53 Hexagon instructions in libkqnn_emit_skel.so. The S23's existing FastRPC loader opened the unsigned library, dispatched calls, returned correct arithmetic, rejected invalid calls, and closed the handle. No compiler, assembler, linker, or qaic output is used to produce the loaded library.

Reused implementation and target contract

tools/Emit-HexagonProbe.ps1 extracts an allowlist of ELF functions from the existing Pwsh writer at commit e215a96, after checking its complete SHA-256 and the provenance manifest. It parses the source before loading only those functions. It does not execute the Pwsh build or change the Pwsh repository. The adapter permits an empty dependency list and adds the ABI-mandatory DT_HEXAGON_VER=3 entry. ELF32 layout, program headers, symbols, SysV hash, dynamic table and section table come from the existing writer.

The Hexagon target supplies named instruction encoders in src/emit/Hexagon.ps1. Every instruction is a singleton packet and is decoded back before emission. The SDK assembler independently produces exactly the same 212 code bytes from the generated assembly listing. Its output is a verification artifact only.

Sources:

Device result

Galaxy S23, SM8550 / Hexagon V73, existing AndroidSMA preview host:

Job=hexagon-emitted-elf
LibrarySHA256=95743649561D263E1BC1CBF703D521619F0A79B0E0F64DD5248956B35BFFDBD1
UnsignedPdRc=0
OpenRc=0
Add a=19 b=23 expected=42 got=42 rc=0
Add a=-200 b=73 expected=-127 got=-127 rc=0
Add a=2147483647 b=1 expected=-2147483648 got=-2147483648 rc=0
Add a=0 b=0 expected=0 got=0 rc=0
Reject=short-input rc=14
Reject=short-output rc=14
UnsupportedMethodRc=20
WrongSignatureRc=20
CloseRc=0
Passed=True

The first host test incorrectly required preservation of an output-only buffer on a failed invocation. remote.h makes no such promise. The final test checks error codes and only reads results after success; the DSP library bytes were unchanged. This result does not claim buffer preservation on error.

Reproduction and scope

Host generation: tools/Emit-HexagonProbe.ps1. Independent instruction check: tools/Test-HexagonEmission.ps1 (WSL SDK 19.0.04). Device test: src/runspace/HexagonEmitProbe.ps1, using the existing AndroidSMA preview host and a separately staged, hash-checked delegate factory. Device selection stays in KOKORO_QNN_SERIAL.

All generated output lives under ..\Build\Kokoro-QNN\hexagon-emission. The phone's previous startup scripts were backed up and restored; their hashes matched before and after the test. Nothing was committed or pushed.

Controls: pinned source extraction and parse validation (SSDF/SI-7), exact signature and buffer-length checks, bounded host allocations, zeroing/freeing host buffers and handle closure (AC-6/SC-4). The existing host uses FullLanguage for .NET native interop; this is not a ConstrainedLanguage claim.

This proves our emitter-to-loader execution path and buffer ABI. It does not establish a minimal ELF, shared-memory zero-copy operation, HVX/HMX performance, or a completed Kokoro backend. No runtime executable mapping was used. The artifact is a native ABI probe, not a QNN graph or a Kokoro inference result.