# Read-only capture / provenance index Initial ReVa session: `run-1b88df9d169e9517a5e1b0f0`. ReVa selected program: `/Sword of the Stars.exe`; reported MD5: `9969481c39f4b33a8a21c48b62abee4c`. The initial ReVa service did not expose a local path or SHA-256. This limitation is now resolved for the static analysis input only: local `dumps/sots.exe` has the same MD5 and SHA-256 `970b7de729956a53094c7eb98aba4270aee98e2fed5daf0d39e290013c90c841`, as independently recorded in `campaign/research/record-observation-crosscheck.md`. This binds the local objdump captures to the ReVa-selected binary fingerprint; it does not bind any live runtime, allocator, asset, or shim. | Anchor | Fresh static observation | |---|---| | `0x007ba1a0` | `read-memory` returned 256 bytes; decompilation reports 395 bytes, four callers including `OnTechResearched` at `0x008917dc`. | | `0x008862b0` | `read-memory` returned 435 bytes; decompilation reports 435 bytes and 161 incoming references. | | `0x0084ee30` | `read-memory` returned 196 bytes; decompilation reports a 196-byte `__fastcall` constructor and six incoming references. | Requests used the live schema: `programPath=/Sword of the Stars.exe`, `addressOrSymbol` for memory, and `functionNameOrAddress` for decompilation. All calls were read-only; no Ghidra, VM, or source mutation occurred. ## Local instruction capture added in this quantum `objdump-2026-09-09-ownership.txt` contains selected raw instruction windows plus exact GNU objdump 2.38 commands. It covers the ObservedTech constructor, append/copy/reallocation/allocation and destruction path, plus PlayerEvent vector copy and three-string destruction path. The interpretation is in `recovered-static.md`; raw instructions are the authority where the old decompiler's false non-return annotation could truncate cleanup. `objdump-2026-09-09-turnevents.txt` adds exact local commands and selected raw instructions for `0x00885380`, `0x00825d40`, `0x00879eb0`, outer TurnEvents append/growth/copy/destruction, nested PlayerEvent vector construction/copy/destruction, both allocation strides, and static unwind edges. Its selected excerpt omitted the test/branch at `0x00825e1e`--`0x00825e2d`, so Astra decision `d-2ff30c9f5355116bea822924` overturned that excerpt's sufficiency for branch polarity. `objdump-2026-09-09-dedup-helper.txt` was intended to repair that gap with exit-zero GNU objdump 2.38 output for `0x00825d40`--`0x00825e64`, helper `0x0046f8c0` through its return, and direct comparison callees `0x004236a0` and `0x00422720` through every return. After `EvImg`, FindDuplicate passes both `EvDsc` strings to `0x0046f8c0`; that helper returns one for unequal strings and zero for equal strings. `0x00825e23` jumps to the matched-element return only on zero. Therefore description equality is required for dedup. Candidate and stored strings each independently select inline versus heap bytes at capacity `0x10`; byte equality plus length equality is required, including empty and mixed short/long cases. This is static instruction evidence, not a live same-bucket fixture. The historical archive SHA-256 is `3bc3c368f30f2ef2b0d291acad9c0f898b74f4436393d47bf8c942571793dd06`; its first-window unfiltered provenance claim is superseded below. ### 2026-09-10 stop-boundary provenance repair Independent review found that the archive above could not be literal unfiltered stdout of its declared first command: stop `0x00825e65` truncates the terminal three-byte instruction after `c2`, but the archive displayed `c2 08 00`. Astra decision `d-d2a9b8be6399a6abaa0e05a5` overturned that provenance claim and required paired captures. The repaired raw streams are: * `objdump-2026-09-10-dedup-narrow.stdout.txt` / `.stderr.txt`, exact stop `0x00825e65`, exit zero, stdout SHA-256 `1c2408cd49cc10383bad9fe06d3287476b103205f4155adf64c8a50ccd5205e8`; * `objdump-2026-09-10-dedup-wide.stdout.txt` / `.stderr.txt`, exact stop `0x00825e67`, exit zero, stdout SHA-256 `3c9f83d3a98d95ffa68e0595e47f6c3beab3016aa97cd44bf39ac72ed3ec0a84`. `objdump-2026-09-10-boundary-repair.md` records executable/tool/source identities, stream sizes and the bounded comparison. Both contain 120 decoded instructions and identical preceding instruction lines; narrow prints terminal `c2`, wide prints `c2 08 00`. The wide content matches the old first window after line-end normalization apart from one final blank line. This supersedes only the old first-window production claim; independent semantic review is still required. ### 2026-09-10 ownership-window provenance repair Astra decision `d-d4c494ba02ada278030ef473` required the same narrow/wide check for the three ownership rows independently found to have truncated stops, followed by an audit of every remaining terminal boundary in `objdump-2026-09-09-ownership.txt`. The complete fresh package is `run-79357a65226f61d6a86c042d/manifest.json`; measured comparison and bounded interpretation are in `comparison.json` and `report.md`. The decision's three predictions held exactly: the allocator, PlayerEvent append and PlayerEvent copy narrow streams end in `c2`, while widened streams and independent section-byte dumps contain `c2 04 00`; all preceding lines agree. The audit found three additional historical stops with the same boundary effect: ObservedTech append and reallocator widen from `c2` to `c2 04 00`, and the string allocation/replacement helper widens from `c2` to `c2 08 00`. The constructor, ObservedTech copy helper, PlayerEvent destructor and import-thunk windows were already complete at their declared stops. All 22 commands exited zero with empty stderr. This supersedes command-to-terminal-byte provenance only; it does not establish archive production history, live execution, allocator safety, field semantics or acceptance. Fresh independent reproduction remains required. ## Independent-review falsifiers The independent verifier should reproduce the local commands against the recorded SHA-256 input and challenge these distinct-state claims: 1. Empty ObservedTech vector and full vector: verify that `0x007b7320` reaches growth only on `_Mylast == _Myend`, and that its `0x0079a150` path copy-constructs rather than header-copies. 2. Long versus short strings: verify `>= 0x10` cleanup and that the temporary cleanup after `RecordObservedTech` cannot be interpreted as ownership transfer. 3. New versus existing observed-tech name and duplicate versus no-duplicate event: verify branch ordering before inferring any allocation or ID effect. 4. Event vector full capacity: verify the `0x74` copy/growth path independently from the `0x2c` ObservedTech path; a matching vector header alone is not a falsifier-resistant semantic test. 5. Duplicate comparator: hold action/location/finite position/message/image fixed; compare equal versus description-only-different EvDsc for empty/short and long strings. Raw instructions predict dedup only for equal descriptions. Require positive comparator entry/return evidence and full pre/post records/IDs in any later live test; static parsing alone does not prove runtime safety. 6. Prune boundaries: distinguish zero, one, and two leading stale buckets, plus stale-after-fresh; only the two-leading-stale case should shorten the outer vector, by one bucket. 7. Turn buckets: with duplicate `EvTurn` buckets, get-or-create should return the last match; on a miss compare spare versus full outer capacity and empty versus nonempty nested vectors. No live allocator-safety or replacement claim is offered for independent approval.