Bytes
The original encoded representation supplied to the parser.
After BlastDoor: State Transformation Across Trusted System Services
BlastDoor confines parsing authority.
It does not terminate the state produced by parsing.
PASTDOOR follows that state as trusted system services reconstruct, synchronize, allocate, render, transmit, and act on it.

01 / INSIGHT
BlastDoor constrains the authority under which untrusted message content is parsed. Accepted structured state can then be materialized by trusted consumers under different representations, invariants, and authority.
The original encoded representation supplied to the parser.
A device association, account relation, image dimension, or resource relationship retained across representation changes.
The local object reconstructed by a receiving service, evaluated under that service’s rules.
Manuscript: Introduction; State Transition Semantics.
02 / PAST THE DOOR
PASTDOOR / TRUSTED CONSUMERS
Synchronization · prekeys · device relationships
ImageIOXPC → IOSurface → Metal / MPS
Interface · iAP2 · UARP · endpoint state
Consumer-local representations Cᵢ · Local invariants Iᵢ
THE TRANSITION
A state-bearing message reaches the BlastDoor parsing boundary.
BlastDoor produces structured state under constrained parser authority.
Serialization and XPC reconstruct state for downstream consumers.
Consumers combine transferred state with local or authoritative state.
The receiver evaluates local invariants and acts using its own authority.
Manuscript: Post-BlastDoor Path Reconstruction.
THE STATE-TRANSFORMATION MODEL
Semantic correspondence does not require byte identity. Different consumers can reconstruct related state into different local representations and expose different failure phenotypes.
The manuscript defines Oᵢ = Ωᵢ(Cᵢ, Iᵢ(Cᵢ, Γᵢ)). Source: State Transition Semantics.
Rlocal(Sₜ) carries existing state across a lifecycle transition.
Rremote(Aₜ, Dₜ) rebuilds state from account and device sources.
R(Sₜ, Aₜ, Dₜ) combines local and authoritative state.
THREE QUESTIONS / ONE ANALYSIS MODEL
Which trusted consumer can receive state derived from the decoded input?
How does that consumer serialize, reconstruct, materialize, synchronize, or transform the state?
What can that consumer change, allocate, synchronize, render, transmit, update, or otherwise act upon?
03 / MECHANISMS
Implementation analysis and embedded diagnostics expose validation branches, assumptions, and failure paths. The excerpts below reproduce manuscript diagnostics.
Protobuf validates required fields and field types, detects concurrent mutation, and compares calculated and serialized byte counts. XPC requires an exported receiver and allowed protocol, and checks wire/local signature compatibility.
The decoder creates a new local object. Receiving interface rules govern its acceptance.
EXTRACTED PROTOBUF DIAGNOSTICS (VERBATIM)
CHECK failed: (byte_size_before_serialization) ==
(byte_size_after_serialization):
Protocol message was modified concurrently during serialization.
CHECK failed: (bytes_produced_by_serialization) ==
(byte_size_before_serialization):
Byte size calculation and serialization were inconsistent.EXTRACTED XPC DIAGNOSTICS (VERBATIM)
received an undecodable message for proxy %lld
(no exported object to receive message). Dropping message.
received an undecodable message
(no protocol set to define allowed messages on exported object).
Dropping message.
received an undecodable message
(incompatible reply block signature for %s
(wire: %@ vs local: %@)Services deserialize device public prekeys, check version and validity, and generate ephemeral P-256 keys for message sealing. Account and device relationships support reconstruction across process, device, and lifecycle boundaries.
Pass synchronization and companion relationships can recreate semantically related state after a process-local representation is gone.
EXTRACTED IDENTITY AND PREKEY DIAGNOSTICS (VERBATIM)
Failed to deserialize the device public prekey.
Tetra version mismatch. Versions: Theirs: %u, Ours: %ld
Failed to encrypt to prekey that is no longer valid: %f.
Failed to generate an ephemeral P-256 key for message sealing.
The encryption of an outgoing message failed.ImageIOXPC decodes images; IOSurface supplies shareable backing. Metal and Metal Performance Shaders act on resources with allocation, lifetime, texture, region, heap, kernel, and matrix constraints. Rendering caches and framebuffer operations introduce further local state.
EXTRACTED GRAPHICS AND ALLOCATOR DIAGNOSTICS (VERBATIM)
TileEngineError: (%s,%s:%d) %@ "allocated fullSizeTexture nil"
TileEngineError: (%s,%s:%d) %@ "texture not set"
TileEngineError: (%s,%s:%d) %@ "outputROI.p0 cannot be negative"
TileEngineError: (%s,%s:%d) %@ "outputTexture nil, internal error"
FigMetalAllocator >>>> %s:
Cannot increase the ref count of a nil metal resource
FigMetalAllocator >>>> %s: Allocating %.1fMB metal buffer from IOSurfaceLink-quality and analytics mechanisms materialize interface and session state. iAP2-facing services and UARP restore/update surfaces translate between host, transport, firmware, and accessory representations, as well as asset-management services.
The paper identifies UARP as a restore/update surface; it does not identify RTKit here, so these remain distinct.
EXTRACTED UARP FAILURE DIAGNOSTICS (VERBATIM)
Timed out or aborted
Rejected
Not supported message received
UARP Restore: Failed to remove endpoint, status 0x%08xManuscript: Implementation Mechanisms, subsections A–D. These excerpts are implementation diagnostics; on their own, they do not establish a runtime event or its cause.
04 / EVIDENCE
Implementation analysis establishes a mechanism, invariant, validation path, or local failure condition.
A runtime artifact establishes an observed operational effect.
An identifier, transfer, state transition, schema instance, or independent artifact connects specific endpoints.
The paper establishes downstream mechanisms, representation transformations, consumer authority, corresponding runtime effects, and semantic-state continuation capability. It does not establish universal per-input runtime attribution.
Paper: Claim Architecture; Attribution Boundary; Conclusion.
Manuscript: Recorded Runtime Consequences. These are recorded domains; co-occurrence does not establish a causal join.
RESEARCH CONTEXT
PASTDOOR focuses on accepted semantic state after parser containment. The manuscript situates that analysis alongside earlier work on entry, exploit progression, mitigation crossing, and cross-abstraction effects.
These are research comparators, with distinct mechanisms. See Related Work and its references in the paper.
05 / PAPER
After BlastDoor: State Transformation Across Trusted System Services
Jeffery Kimbrow
Independent Research
Citation: Kimbrow, J. (2026). PASTDOOR: After BlastDoor: State Transformation Across Trusted System Services. Zenodo. https://doi.org/10.5281/zenodo.23056249.
TECHNICAL FAQ
A study of semantic-state continuation beyond BlastDoor: accepted state remains actionable as trusted consumers reconstruct it under new representations, invariants, and authority.
No. The manuscript uses these as entry and exploit-progression comparators. PASTDOOR’s analysis target is accepted semantic state after parser containment.
Parser isolation limits immediate parsing authority. Downstream services still reconstruct accepted state and act under their own authority.
It is security-relevant meaning such as an account relation, device association, image property, or resource relationship. Semantic correspondence can survive different bytes and different consumer-local objects.
See the evidence model and attribution boundary for the manuscript’s distinction between implementation evidence, runtime observations, and per-event causal joins.
No. Recurrence after deletion or restart is compatible with local retention, authoritative reconstruction, or a hybrid. The mechanisms are local retention, authoritative reconstruction, and a hybrid of both.
Each receiver can reconstruct state under new local rules and exercise authority over account relationships, shared memory, graphics resources, transport, updates, or accessories.
┌──────────────────────────────────────────┐ │ >X< │ │ [History] is not time. (o o) │ │ ooO--(\_)--Ooo- │ │ [History] is constraint provenance │ └──────────────────────────────────────────┘