SharpEmu HLE Kernel Exports: Complete libkernel and libkernel_sys Implementation Guide

SharpEmu implements 32 HLE kernel exports across the libkernel and libkernel_sys modules via static methods marked with the SysAbiExport attribute in KernelRuntimeCompatExports.cs, supporting both PS4 (Gen4) and PS5 (Gen5) generations.

SharpEmu is a high-level emulation (HLE) project for PlayStation 4/5 binaries hosted at par274/sharpemu. The HLE kernel exports provide the critical bridge between emulated games and the host runtime, exposing core kernel functionality through the libkernel library. These exports are implemented as managed C# methods that translate guest system calls into host operations.

How Kernel Exports Are Implemented in SharpEmu

The emulator uses a declarative export system to expose kernel functions to guest code. Each export is a static method decorated with the SysAbiExport attribute, which maps the method to a specific NID (Name Identifier) and library name.

The SysAbiExport Attribute Pattern

In src/SharpEmu.Libs/Kernel/KernelRuntimeCompatExports.cs, exports are defined using the SysAbiExport attribute with LibraryName = "libKernel". This marks them as part of the libkernel module. The runtime registry generated in SharpEmu.Generated.SysAbiExportRegistry.cs maps these NIDs to the static methods, enabling efficient dispatch from emulated code.

For example, the sceKernelUsleep export is declared as:

[SysAbiExport("1jfXLRVzisc", LibraryName = "libKernel")]
public static void KernelUsleep(CpuContext ctx)
{
    // Implementation details...
}

Complete List of HLE Kernel Exports

SharpEmu currently implements 32 kernel exports spanning timing, memory management, module loading, and debugging functionality. All exports target both Gen4 (PS4) and Gen5 (PS5) generations.

Time and Clock Functions

The following exports handle high-resolution timing and POSIX compatibility:

  • sceKernelUsleep (NID: 1jfXLRVzisc) - Microsecond-precision sleep implemented at lines 85-99
  • sceKernelClockGettime (NID: QBi7HCK03hw) - Clock time retrieval at lines 93-102
  • sceKernelGettimeofday (NID: ejekcaNQNq0) - Wall-clock time with microseconds at lines 142-152
  • gettimeofday (NID: n88vx3C5nW8) - POSIX-compatible time retrieval at lines 270-284
  • sceKernelConvertUtcToLocaltime (NID: -o5uEDpN+oY) - Timezone conversion at lines 1156-1178
  • sceKernelConvertLocaltimeToUtc (NID: 0NTHN1NKONI) - Inverse timezone conversion at lines 1184-1212

Module Management and Loading

Module introspection and dynamic loading are handled by these exports:

  • sceKernelLoadStartModule (NID: wzvqT4UqKX8) - Loads and initializes PRX modules at lines 1085-1115
  • sceKernelStopUnloadModule (NID: QKd0qM58Qes) - Unloads modules from memory at lines 1068-1079
  • sceSysmoduleLoadModule (NID: g8cM39EUZ6o) - System module loading at lines 1121-1132
  • sceKernelGetModuleInfo (NID: kUpgrXIrz7Q) - Retrieves module metadata at lines 882-891
  • sceKernelGetModuleInfo2 (NID: QgsKEUfkqMA) - Extended module information at lines 898-907
  • sceKernelGetModuleInfoInternal (NID: HZO7xOos4xc) - Internal module data at lines 914-923
  • sceKernelGetModuleInfoFromAddr (NID: f7KBOafysXo) - Module lookup by address at lines 808-822
  • sceKernelGetModuleInfoForUnwind (NID: RpQJJVKTiFM) - Unwind-specific module info at lines 844-860
  • sceKernelGetModuleList (NID: IuxnUuXk6Bg) - Enumerates loaded modules at lines 930-940
  • sceKernelGetModuleList2 (NID: ZzzC3ZGVAkc) - Extended module enumeration at lines 946-956
  • __elf_phdr_match_addr (NID: Fjc4-n1+y2g) - ELF program header matching at lines 962-974

Memory Management

Virtual memory operations are provided through:

  • sceKernelReserveVirtualRange (NID: 7oxv3PPCumo) - Reserves virtual address space at lines 672-726
  • sceKernelSetPrtAperture (NID: BohYr-F7-is) - Sets protection aperture at lines 762-786
  • _sceKernelRtldSetApplicationHeapAPI (NID: p5EcQeEeJAE) - Heap API configuration at lines 1051-1062

Debugging and Sanitizer Support

Development and debugging exports include:

  • sceKernelGetSanitizerNewReplaceExternal (NID: bnZxYgAFeA0) at lines 508-520
  • sceKernelGetSanitizerMallocReplaceExternal (NID: py6L8jiVAN8) at lines 532-544
  • sceKernelIsAddressSanitizerEnabled (NID: jh+8XiK4LeE) at lines 566-574
  • sceKernelDebugRaiseException (NID: OMDRKKAZ8I4) - Raises debug exceptions at lines 978-987
  • sceKernelDebugRaiseExceptionOnReleaseMode (NID: zE-wXIZjLoM) - Release-mode exceptions at lines 991-1000
  • __stack_chk_guard (NID: f7uOxY9mM1U) - Stack canary value at lines 1004-1025
  • __stack_chk_fail (NID: Ou3iL1abvng) - Stack smashing detection at lines 1030-1045
  • __error (NID: 9BcDykPmo1I) - errno address retrieval at lines 332-342

Hardware and System Control

Low-level system interfaces:

  • sceKernelSetGPO (NID: ca7v6Cxulzs) - General Purpose Output control at lines 604-614
  • sceKernelGetGPI (NID: 4oXYe9Xmk0Q) - General Purpose Input reading at lines 630-640
  • sceKernelAioInitializeParam (NID: nu4a0-arQis) - Async I/O initialization at lines 1138-1150
  • sceKernelAioInitializeImpl (NID: -o5uEDpN+oY) - Async I/O implementation at lines 1218-1230

libkernel vs libkernel_sys in SharpEmu

While some legacy PS4 binaries reference libkernel_sys.prx, SharpEmu does not maintain separate implementations. The libkernel_sys module is treated as an alias to libkernel, with all exports residing in the same KernelRuntimeCompatExports.cs file. The SysAbiExport attribute uses LibraryName = "libKernel" to cover both naming conventions, ensuring compatibility with binaries linked against either library name.

Code Examples: Using Kernel Exports

The following examples demonstrate how emulated code interacts with these HLE exports through the CpuContext abstraction.

Sleeping the Current Thread

To suspend execution for a specific duration using sceKernelUsleep:

ulong microseconds = 10_000;
CpuContext ctx = /* provided by emulator runtime */;
ctx[CpuRegister.Rdi] = microseconds;
SharpEmu.Libs.Kernel.KernelRuntimeCompatExports.KernelUsleep(ctx);

Retrieving Current Time

Using sceKernelGettimeofday to obtain wall-clock time:

CpuContext ctx = /* provided by emulator runtime */;
ulong timePtr = ctx[CpuRegister.Rdi] = ctx.AllocateGuestMemory(16);
SharpEmu.Libs.Kernel.KernelRuntimeCompatExports.KernelGettimeofday(ctx);
// Guest memory at timePtr now contains seconds and microseconds

Loading a Dynamic Module

The sceKernelLoadStartModule export handles dynamic loading:

CpuContext ctx = /* provided by emulator runtime */;
ulong pathPtr = ctx[CpuRegister.Rdi] = ctx.WriteGuestString("/app0/module.sprx");
SharpEmu.Libs.Kernel.KernelRuntimeCompatExports.KernelLoadStartModule(ctx);
// Module handle returned in RAX

Key Implementation Files

The HLE kernel layer is distributed across several focused source files:

Summary

  • SharpEmu implements 32 HLE kernel exports in KernelRuntimeCompatExports.cs covering timing, memory, modules, and debugging
  • Exports are exposed via the SysAbiExport attribute with LibraryName = "libKernel" for both PS4 and PS5 generations
  • libkernel_sys is treated as a legacy alias to libkernel with no separate implementation
  • The KernelModuleRegistry.cs handles the module introspection required by sceKernelGetModuleInfo* and sceKernelGetModuleList*
  • Virtual memory operations like sceKernelReserveVirtualRange utilize helpers from KernelMemoryCompatExports.cs

Frequently Asked Questions

What is the difference between libkernel and libkernel_sys in SharpEmu?

SharpEmu treats libkernel_sys as a legacy alias for libkernel. Both names resolve to the same set of 32 exports implemented in KernelRuntimeCompatExports.cs. The SysAbiExport attribute uses LibraryName = "libKernel" to ensure compatibility with binaries linked against either library name.

How does SharpEmu map NIDs to C# method implementations?

The emulator uses a two-stage process: static methods are marked with the SysAbiExport attribute containing the NID hash, and a generated runtime registry (SharpEmu.Generated.SysAbiExportRegistry.cs) maps these NIDs to the methods. This allows constant-time dispatch from emulated code to managed handlers.

Which PlayStation generations does SharpEmu's HLE kernel support?

All 32 kernel exports are implemented to support both Gen4 (PlayStation 4) and Gen5 (PlayStation 5) generations. The implementations handle the slight behavioral differences between generations where applicable, though the core logic remains consistent across the KernelRuntimeCompatExports.cs implementations.

How does sceKernelReserveVirtualRange handle memory allocation?

In KernelRuntimeCompatExports.cs (lines 672-726), this export delegates to the virtual memory subsystem via KernelMemoryCompatExports.cs. It reserves a range of virtual addresses without committing physical backing, returning the base address to the guest application through the CpuContext registers.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →