# Ownership-window provenance repair Static local capture only. This run implements the six-capture probe and remaining ownership-window boundary audit required by Astra decision `d-d4c494ba02ada278030ef473`. It does not execute the game, an allocator, a constructor, a copy, a destructor, or an exception path. ## Bound identities * Input: `dumps/sots.exe`, 7,898,624 bytes, SHA-256 `970b7de729956a53094c7eb98aba4270aee98e2fed5daf0d39e290013c90c841`, MD5 `9969481c39f4b33a8a21c48b62abee4c`. * Tool: `/usr/bin/objdump`, SHA-256 `1eaaef2e7f57c4c7f69115c495e2466f5a8c8e5f3bc42221d092382f30f9d4cd`, GNU Binutils 2.38. * CWD: `/home/alex/sots-re`; exact argv, return codes, stream paths/sizes/hashes and paired source binding are in `manifest.json`. * Source binding before and after capture: engine `ccd8e02083e8d2e2b3e97976ace2273c8f924dfc02a39e919004eaf3544c50fd`, RE `6696fd5201e144843617cbf6d78b41b5287ad5dcc9fa1e8aaa861d52b64e72e8`. ## Measured observations All 22 objdump commands exited zero and every stderr stream is empty. For each paired row below, `comparison.json` reports that every line before the terminal line is identical. | function/window | historical stop | widened stop | narrow terminal bytes | widened/raw bytes | |---|---:|---:|---|---| | allocator `0x0057e590` | `0x0057e5e4` | `0x0057e5e6` | `c2` | `c2 04 00` | | PlayerEvent append `0x0086c580` | `0x0086c62e` | `0x0086c630` | `c2` | `c2 04 00` | | PlayerEvent copy `0x007693f0` | `0x007694c0` | `0x007694c2` | `c2` | `c2 04 00` | | ObservedTech append `0x007b7320` | `0x007b739f` | `0x007b73a1` | `c2` | `c2 04 00` | | ObservedTech reallocator `0x007b34e0` | `0x007b35ef` | `0x007b35f1` | `c2` | `c2 04 00` | | string allocator/replace `0x004249a0` | `0x00424ada` | `0x00424adc` | `c2` | `c2 08 00` | The audit also freshly retained complete historical-stop streams for the ObservedTech constructor (`c3`), ObservedTech copy helper (`c3`), PlayerEvent destructor (`c3`), and import-thunk window (complete six-byte jump at `0x00924fb6`). Thus six of ten audited ownership windows ended on a three-byte `ret imm16`; all six historical stops admitted only its first byte. The selected 2026-09-09 archive happened to print complete terminal rows, but these fresh captures do not establish how that archive was produced. ## Bounded interpretation and unresolved inputs Complete image bytes establish encoded `ret 4` for the allocator, both append operations, the PlayerEvent copy operation and the ObservedTech reallocator, and `ret 8` for string allocation/ replacement. This repairs command-to-byte provenance. It does not by itself prove receiver meaning, field semantics, live allocator-family compatibility, successful long-string/full-capacity behavior, or exceptional cleanup. The callable original-helper dependencies remain the original MSVCR100 allocation/deallocation thunks `0x00924fb6`/`0x00924faa`, string assignment/allocation boundary `0x00425430`/`0x004249a0`, ObservedTech copy helper `0x0079a150`, PlayerEvent copy helper `0x007693f0`, and the virtual element destructors reached during growth. A standalone implementation must supply one coherent allocation/copy/destruction family rather than mix raw headers with these original-owned allocations. Missing runtime inputs remain: safe short/long-string fixtures, spare/full-capacity vectors, pre/post element and pointer ownership observations, allocation-failure/throw outcomes, and same-bucket equal versus description-only-different events. No RNG boundary is present in these helpers and no RNG draw occurred because nothing was executed live. Independent verification must reproduce complete windows from the pinned input/tool, challenge at least one historical stop and one complete stop, and retain the distinct empty/full, short/long, duplicate/nonduplicate and unwind limitations. This analyst does not promote either acceptance criterion.