sots-re/campaign/research/research-live-record-addresses.json

509 lines
36 KiB
JSON

{
"schema": "sots-live-record-addresses/1",
"status": "incomplete-planning-input",
"binary": {
"path": "dumps/sots.exe",
"sha256": "970b7de729956a53094c7eb98aba4270aee98e2fed5daf0d39e290013c90c841",
"image_base": "0x00400000"
},
"tool": {
"path": "/usr/bin/objdump",
"version": "GNU Binutils 2.38",
"sha256": "1eaaef2e7f57c4c7f69115c495e2466f5a8c8e5f3bc42221d092382f30f9d4cd"
},
"source_identity": {
"engine": {
"path": "/tmp/opencode/sots-final-research-engine",
"commit": "7741d42fc5e4e761e6449bdaf0e4a61d00036a23",
"git_common_dir": "/home/alex/sots-engine/.git"
},
"re": {
"path": "/tmp/opencode/sots-final-research-re",
"commit": "3bfde5a70d874a723e797a695bbd847fd82c0aa7",
"git_common_dir": "/home/alex/sots-re/.git"
}
},
"fresh_capture": {
"session": "run-eca0889c30beb7f00f4ac264",
"cwd": "/home/alex/sots-re",
"commands": [
{
"argv": [
"/usr/bin/objdump",
"-D",
"-Mintel",
"--start-address=0x0079a142",
"--stop-address=0x0079a1e0",
"dumps/sots.exe"
],
"returncode": 0,
"stdout_bytes": 3452,
"stdout_sha256": "f8f31b09ddb0a6d5b4016f84bfe86b994ed944be7372e264b90344fd560d4d05",
"stderr_bytes": 0,
"stderr_sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"
},
{
"argv": [
"/usr/bin/objdump",
"-D",
"-Mintel",
"dumps/sots.exe"
],
"returncode": 0,
"stdout_bytes": 148427275,
"stdout_sha256": "b748aef66fb4bb11be5223517a4c563eccd8c5117d86481c1459c20eded932c3",
"stderr_bytes": 0,
"stderr_sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"
},
{
"argv": [
"/usr/bin/objdump",
"-D",
"-Mintel",
"--start-address=0x007b7320",
"--stop-address=0x007b73a1",
"dumps/sots.exe"
],
"returncode": 0,
"stdout_bytes": 2794,
"stdout_sha256": "510efc3587feec6b34d52effccfd9afac6cec4ab3358de54ba7ad9aecfa73c67",
"stderr_bytes": 0,
"stderr_sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"
},
{
"argv": [
"/usr/bin/objdump",
"-D",
"-Mintel",
"--start-address=0x00425430",
"--stop-address=0x00425519",
"dumps/sots.exe"
],
"returncode": 0,
"stdout_bytes": 5205,
"stdout_sha256": "9f3ceb743ad7878d1d5900233d24acd2bd0bc86bc9f44acfcfccf0a6735e5c16",
"stderr_bytes": 0,
"stderr_sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"
}
]
},
"constructor_destructor_capture": {
"session": "run-a247a9d6650d9e0954596cc0",
"manifest": "verify/results/research-live-record-bridge/run-a247a9d6650d9e0954596cc0/manifest.json",
"scope": "Read-only constructor, scalar-deleting destructor, and vtable-slot capture; planning evidence only."
},
"reserve_recapture": {
"session": "run-a52f7d5ebec657d8923d8402",
"manifest": "verify/results/research-live-record-bridge/run-a52f7d5ebec657d8923d8402/manifest.json",
"stdout": "verify/results/research-live-record-bridge/run-a52f7d5ebec657d8923d8402/observed-reserve.stdout.txt",
"stdout_sha256": "2d011ed96329c4c4ff462cbfd65decac9dccf40558765244c769be1dedc92275",
"comparison": "verify/results/research-live-record-bridge/run-a52f7d5ebec657d8923d8402/comparison.json",
"scope": "Read-only byte-exact recapture of 0x007b5820..0x007b5898. Full comparison found the invalidated transcription omitted exactly eight presentation spaces; all 49 address/opcode/mnemonic/operand rows match. Planning evidence only."
},
"player_event_constructor_capture": {
"session": "run-c1238a40bfc3bfa7c2ff9ba6",
"manifest": "verify/results/research-live-record-bridge/run-c1238a40bfc3bfa7c2ff9ba6/manifest.json",
"constructor_stdout": "verify/results/research-live-record-bridge/run-c1238a40bfc3bfa7c2ff9ba6/player-event-ctor-exact.stdout.txt",
"eh_analysis": "verify/results/research-live-record-bridge/run-c1238a40bfc3bfa7c2ff9ba6/player-event-ctor-eh-analysis.json",
"scope": "Read-only callable constructor and MSVC unwind capture; static planning evidence only, not live allocator or exception execution."
},
"player_event_copy_capture": {
"session": "run-36c401e90eb0ec1db4d35865",
"manifest": "verify/results/research-live-record-bridge/run-36c401e90eb0ec1db4d35865/manifest.json",
"copy_stdout": "verify/results/research-live-record-bridge/run-36c401e90eb0ec1db4d35865/player-event-copy-exact.stdout.txt",
"eh_analysis": "verify/results/research-live-record-bridge/run-36c401e90eb0ec1db4d35865/player-event-copy-eh-analysis.json",
"scope": "Read-only callable copy-constructor and MSVC unwind capture; static planning evidence only, not live allocator or exception execution."
},
"player_event_destructor_capture": {
"session": "run-a4f6a9922bf5800747bfdfc6",
"manifest": "verify/results/research-live-record-bridge/run-a4f6a9922bf5800747bfdfc6/manifest.json",
"destructor_stdout": "verify/results/research-live-record-bridge/run-a4f6a9922bf5800747bfdfc6/player-event-dtor-exact.stdout.txt",
"context_stdout": "verify/results/research-live-record-bridge/run-a4f6a9922bf5800747bfdfc6/player-event-dtor-context.stdout.txt",
"scope": "Read-only complete callable destructor and boundary capture; static planning evidence only, not live allocator or destruction execution."
},
"player_event_append_capture": {
"session": "run-e21ce0d2909d8647e6a99a7b",
"manifest": "verify/results/research-live-record-bridge/run-e21ce0d2909d8647e6a99a7b/manifest.json",
"append_stdout": "verify/results/research-live-record-bridge/run-e21ce0d2909d8647e6a99a7b/player-event-append-exact.stdout.txt",
"growth_stdout": "verify/results/research-live-record-bridge/run-e21ce0d2909d8647e6a99a7b/player-event-growth-exact.stdout.txt",
"reallocator_stdout": "verify/results/research-live-record-bridge/run-e21ce0d2909d8647e6a99a7b/player-event-reallocate-exact.stdout.txt",
"eh_analysis": "verify/results/research-live-record-bridge/run-e21ce0d2909d8647e6a99a7b/player-event-append-eh-analysis.json",
"scope": "Read-only callable append, reserve/growth, reallocation and MSVC unwind capture; static planning evidence only, not live allocator, copy, destruction or exception execution."
},
"operations": {
"observed_tech_default_construct": {
"va": "0x008562a0",
"rva": "0x004562a0",
"callable_entry": true,
"prototype": "ObservedTech *__thiscall observed_tech_default_construct(ObservedTech *destination)",
"receiver": "ECX = writable uninitialized storage for one complete 0x2c-byte ObservedTech",
"arguments": [],
"stack_cleanup": "no stack arguments; helper ends in plain ret",
"return": "EAX = destination ObservedTech pointer on normal return",
"writes": [
"vptr 0x00a2439c at destination +0x00",
"zero dword at +0x04, covering both 16-bit turn fields",
"zero byte at +0x08",
"valid empty/SSO std::string rooted at +0x0c with size zero and capacity 0x0f",
"zero dword at +0x28"
],
"ownership": "Field-wise construction creates one valid embedded string; it does not adopt or copy an owning header. The constructor establishes an SEH frame around empty-string setup through VA 0x00425550. On normal return the destination owns exactly its initialized name string and must later be destroyed exactly once.",
"vtable_provenance": {
"vtable_va": "0x00a2439c",
"complete_object_locator_va": "0x00a81c78",
"slots": [
{"index": 0, "va": "0x00793610", "meaning": "scalar-deleting destructor"},
{"index": 1, "va": "0x00817c40", "meaning": "Read"},
{"index": 2, "va": "0x00817cf0", "meaning": "Write"}
]
},
"captures": [
"verify/results/research-live-record-bridge/run-a247a9d6650d9e0954596cc0/observed-ctor.stdout.txt",
"verify/results/research-live-record-bridge/run-a247a9d6650d9e0954596cc0/observed-vtable.stdout.txt",
"verify/results/research-live-record-bridge/run-a247a9d6650d9e0954596cc0/manifest.json"
]
},
"observed_tech_scalar_delete_destruct": {
"va": "0x00793610",
"rva": "0x00393610",
"callable_entry": true,
"prototype": "ObservedTech *__thiscall observed_tech_scalar_delete_destruct(ObservedTech *value, uint32_t flags)",
"receiver": "ECX = one fully constructed live-layout ObservedTech",
"arguments": [
{
"index": 0,
"location": "[entry ESP+0x04] / [EBP+0x08]",
"meaning": "scalar-deleting flags; bit 0 requests freeing the object storage"
}
],
"stack_cleanup": "callee removes the one 4-byte flags argument with ret 4",
"return": "EAX = input ObservedTech pointer on normal return, including the flags-bit-0 path",
"writes": [
"when name capacity at +0x20 is at least 0x10, frees the owned buffer pointer at +0x0c through VA 0x00924faa",
"sets name capacity +0x20 to 0x0f, size +0x1c to zero, and first inline byte +0x0c to zero",
"writes base vptr 0x009e22bc at +0x00",
"when flags bit 0 is set, frees the ObservedTech storage through VA 0x00924faa"
],
"ownership": "Consumes the one name ownership exactly once. For stack temporaries, vector elements, and all other embedded values the bridge must pass flags=0 so only member lifetime ends and object storage is not freed. Reuse after return requires a fresh constructor; a second destructor call is forbidden.",
"embedded_invocation": {
"flags": 0,
"required_reason": "Original vector reallocation pushes zero before virtual slot-0 dispatch over each old 0x2c-byte element; flags=1 would incorrectly scalar-delete embedded storage."
},
"captures": [
"verify/results/research-live-record-bridge/run-a247a9d6650d9e0954596cc0/observed-dtor.stdout.txt",
"verify/results/research-live-record-bridge/run-a247a9d6650d9e0954596cc0/observed-vtable.stdout.txt",
"verify/results/research-completion-abi-independent/integration-lead-20260910/observed-realloc-wide.stdout.txt",
"verify/results/research-live-record-bridge/run-a247a9d6650d9e0954596cc0/manifest.json"
]
},
"observed_tech_copy_construct": {
"va": "0x0079a150",
"rva": "0x0039a150",
"callable_entry": true,
"prototype": "void __cdecl observed_tech_copy_construct(void *unused_allocator, ObservedTech *destination, const ObservedTech *source)",
"arguments": [
{
"index": 0,
"location": "[entry ESP+0x04] / [EBP+0x08]",
"meaning": "allocator-shaped argument passed as vector+0x0c by both callers; not read by this helper"
},
{
"index": 1,
"location": "[entry ESP+0x08] / [EBP+0x0c]",
"meaning": "destination ObservedTech pointer"
},
{
"index": 2,
"location": "[entry ESP+0x0c] / [EBP+0x10]",
"meaning": "source ObservedTech pointer"
}
],
"stack_cleanup": "caller removes 12 bytes; helper ends in plain ret",
"receiver": "none; incoming ECX is not consumed as a receiver",
"return": "no supported return-value contract; EAX is incidental/clobbered",
"writes": [
"destination vptr at +0x00",
"16-bit fields at +0x04 and +0x06",
"byte field at +0x08",
"deep-constructed string rooted at +0x0c through VA 0x00425430",
"32-bit field at +0x28"
],
"ownership": "Constructs destination field-wise. The destination string starts empty/SSO and is assigned from the source; no owning string header is copied. Entry SEH state covers the potentially allocating string operation.",
"callers": [
{
"call_va": "0x007b7366",
"containing_entry_va": "0x007b7320",
"path": "source originally inside vector; source pointer recomputed after possible growth"
},
{
"call_va": "0x007b738f",
"containing_entry_va": "0x007b7320",
"path": "source outside vector"
}
],
"all_direct_callers_probe": "Full-image linear objdump contained exactly the two direct call rows above for target 0x79a150.",
"interior_negative_control": {
"va": "0x0079a184",
"rva": "0x0039a184",
"callable_entry": false,
"reason": "Interior instruction depends on the 0x0079a150 prologue having established EBP, SEH state, ESI=destination and local construction state. No direct caller targets it."
},
"accepted_dependency_captures": [
"verify/results/research-completion-abi-independent/integration-lead-20260910/observed-copy-control.stdout.txt",
"verify/results/research-completion-abi-independent/integration-lead-20260910/observed-push-wide.stdout.txt",
"verify/results/research-completion-abi-independent/integration-lead-20260910/manifest.json"
]
},
"observed_tech_vector_append": {
"va": "0x007b7320",
"rva": "0x003b7320",
"callable_entry": true,
"prototype": "void __thiscall observed_tech_vector_append(ObservedTechVector *vector, const ObservedTech *source)",
"receiver": "ECX = live three-pointer vector header: first at +0x00, last at +0x04, end at +0x08; allocator-shaped storage begins at +0x0c",
"arguments": [
{
"index": 0,
"location": "[entry ESP+0x04] / [EBP+0x08]",
"meaning": "source live-layout ObservedTech to deep-copy"
}
],
"stack_cleanup": "callee removes the one 4-byte source argument with ret 4",
"return": "no supported return-value contract; EAX is incidental after the copy helper",
"source_location_branches": [
"When source is in [first,last), computes its 0x2c-element index before any growth and recomputes source from the possibly replaced first pointer afterward.",
"When source is outside [first,last), retains the caller pointer across possible growth. A pointer into unused capacity or exactly at last is not treated as a live in-vector source and is forbidden by the bridge precondition."
],
"no_growth": "Calls 0x0079a150 with vector+0x0c, destination=old last, and selected source; advances last by exactly 0x2c only after normal copy return. Existing elements and end are unchanged.",
"growth": {
"reserve_va": "0x007b5820",
"reserve_prototype": "void __thiscall observed_tech_vector_reserve_additional(ObservedTechVector *vector, uint32_t additional_count)",
"reserve_abi": "ECX=vector, one stack count, ret 4, no supported return; append passes additional_count=1 only when last==end.",
"capacity_rule": "Rejects size+additional above 0x05d1745d elements; if required exceeds capacity, chooses at least required and otherwise approximately capacity+floor(capacity/2), capped through the same maximum check, then calls 0x007b34e0 with the chosen element capacity.",
"reallocate_effects": "0x007b34e0 obtains count*0x2c storage through 0x0057e590 -> MSVCR100 scalar new thunk 0x00924fb6, deep-copy-constructs [old first,old last) into the new block through 0x0085e650, destroys each old element through virtual slot zero with flags=0, frees the old block through 0x00924faa, then writes end, last and first in that order. Append subsequently deep-copies the requested source at the new last and advances last by 0x2c.",
"normal_postcondition": "All prior element values survive as independently owned deep copies; every old element is destroyed exactly once and old array storage is freed once through the matching runtime family."
},
"exceptional_ownership": "The append helper has no local handler and advances last only after copy construction returns. Reserve/reallocate install MSVC SEH state around allocation/range copy; 0x0085e650 tracks the current destination and has a partial-range destruction funclet. Static control flow therefore supports cleanup before propagation and leaves the published vector header update until after successful relocation, but no live throw has been exercised. The bridge must contain any propagated C++ exception at its MSVC DLL boundary, must treat the operation as failed with no accepted new element, and must validate zero outstanding allocation/partial element before this row can support live-safety acceptance.",
"captures": [
"verify/results/research-completion-abi-independent/integration-lead-20260910/observed-push-wide.stdout.txt",
"verify/results/research-live-record-bridge/run-a52f7d5ebec657d8923d8402/observed-reserve.stdout.txt",
"verify/results/research-live-record-bridge/run-a52f7d5ebec657d8923d8402/manifest.json",
"verify/results/research-live-record-bridge/run-a52f7d5ebec657d8923d8402/comparison.json",
"verify/results/research-completion-abi-independent/integration-lead-20260910/observed-realloc-wide.stdout.txt",
"verify/results/research-completion-abi-independent/integration-lead-20260910/observed-alloc-wide.stdout.txt"
]
},
"player_event_default_construct": {
"va": "0x0084ee30",
"rva": "0x0044ee30",
"callable_entry": true,
"prototype": "PlayerEvent *__thiscall player_event_default_construct(PlayerEvent *destination)",
"receiver": "ECX = writable uninitialized storage for one complete 0x74-byte PlayerEvent",
"arguments": [],
"stack_cleanup": "no stack arguments; helper ends in plain ret",
"return": "EAX = destination PlayerEvent pointer on normal return",
"writes": [
"vptr 0x00a21958 at destination +0x00",
"EvEID zero at +0x04",
"valid empty/SSO EvDsc std::string rooted at +0x08 with size zero, capacity 0x0f and first inline byte zero",
"valid empty/SSO EvMsg std::string rooted at +0x24 with size zero, capacity 0x0f and first inline byte zero",
"EvLoc zero at +0x40",
"EvPos dwords at +0x44, +0x48 and +0x4c copied from 0x00af0dc8, 0x00af0dcc and 0x00af0dd0; each source word is 0x7f7fffff (FLT_MAX)",
"valid empty/SSO EvImg std::string rooted at +0x50 with size zero, capacity 0x0f and first inline byte zero",
"EvAct zero at +0x6c",
"EvCID zero at +0x70"
],
"complete_layout": "The listed writes establish every logical field of the 0x74-byte object: 4-byte vptr, 4-byte EvEID, three independent 0x1c-byte strings, EvLoc, three position dwords, EvAct and EvCID. They do not overwrite inactive SSO union bytes or the allocator-shaped trailing dword in each 0x1c-byte string object; those bytes are not observable string value or ownership state. No owning header is imported from caller storage.",
"string_initialization": "Each string is manually established as empty/SSO and then passed as ECX to 0x00425550 with stack arguments empty literal 0x009e100c and count zero. The bound zero-count path writes size zero and the inline terminator, performs no allocation or free, and returns the destination with ret 8. On normal return all three are distinct valid owned subobjects even though inactive storage bytes may retain their prior contents.",
"exceptional_partial_construction": {
"handler_thunk_va": "0x0099613e",
"func_info_va": "0x00ac98a4",
"func_info": "MSVC magic 0x19930522, maxState 3, unwind map 0x00ac988c, no try-block or IP maps, flags 1",
"unwind_states": [
"state 0 -> -1 through 0x00996120: restore base vptr 0x009e22bc through 0x00763a00",
"state 1 -> 0 through 0x00996128: destroy completed EvDsc at destination+0x08 through 0x008e0610, then continue state 0 cleanup",
"state 2 -> 1 through 0x00996133: destroy completed EvMsg at destination+0x24 through 0x008e0610, then continue states 1 and 0 cleanup"
],
"qualification": "The state is advanced immediately before the next empty-string helper call, so a hypothetical exception during construction of a string cleans only predecessor string subobjects plus the base; a failing current subobject is not treated as completed. For the constructor's fixed valid empty-literal/count-zero inputs, the bound 0x00425550 path does not allocate, free or call a failure helper. The third successful call is followed only by scalar stores on the observed path. This is static unwind topology; no throw or allocator behavior was executed."
},
"ownership": "On normal return the destination owns three independently destructible valid strings and must be destroyed exactly once. A failed construction must not be passed to the complete PlayerEvent destructor; only the compiler unwind actions for completed states may run.",
"captures": [
"verify/results/research-live-record-bridge/run-c1238a40bfc3bfa7c2ff9ba6/player-event-ctor-exact.stdout.txt",
"verify/results/research-live-record-bridge/run-c1238a40bfc3bfa7c2ff9ba6/player-event-ctor.stdout.txt",
"verify/results/research-live-record-bridge/run-c1238a40bfc3bfa7c2ff9ba6/player-event-ctor-ehdata.stdout.txt",
"verify/results/research-live-record-bridge/run-c1238a40bfc3bfa7c2ff9ba6/player-event-ctor-funcinfo.stdout.txt",
"verify/results/research-live-record-bridge/run-c1238a40bfc3bfa7c2ff9ba6/player-event-ctor-cleanup-base.stdout.txt",
"verify/results/research-live-record-bridge/run-c1238a40bfc3bfa7c2ff9ba6/player-event-ctor-cleanup-string.stdout.txt",
"verify/results/research-live-record-bridge/run-c1238a40bfc3bfa7c2ff9ba6/string-empty-init.stdout.txt",
"verify/results/research-live-record-bridge/run-c1238a40bfc3bfa7c2ff9ba6/player-event-ctor-eh-record.bin",
"verify/results/research-live-record-bridge/run-c1238a40bfc3bfa7c2ff9ba6/player-event-ctor-eh-analysis.json",
"verify/results/research-live-record-bridge/run-c1238a40bfc3bfa7c2ff9ba6/manifest.json"
]
},
"player_event_copy_construct": {
"va": "0x007693f0",
"rva": "0x003693f0",
"callable_entry": true,
"prototype": "PlayerEvent *__thiscall player_event_copy_construct(PlayerEvent *destination, const PlayerEvent *source)",
"receiver": "ECX = writable uninitialized storage for one complete 0x74-byte PlayerEvent",
"arguments": [
{
"index": 0,
"location": "[entry ESP+0x04] / [EBP+0x08]",
"meaning": "source fully constructed live-layout PlayerEvent"
}
],
"stack_cleanup": "callee removes the one 4-byte source argument with ret 4",
"return": "EAX = destination PlayerEvent pointer on normal return",
"ordered_writes": [
"writes vptr 0x00a21958 at destination +0x00, then copies source EvEID +0x04",
"establishes destination EvDsc +0x08 as empty/SSO, then deep-assigns source EvDsc through 0x00425430 with offset zero and count 0xffffffff",
"establishes destination EvMsg +0x24 as empty/SSO, then deep-assigns source EvMsg through 0x00425430 with offset zero and count 0xffffffff",
"copies source EvLoc +0x40 and all three EvPos dwords +0x44, +0x48 and +0x4c",
"establishes destination EvImg +0x50 as empty/SSO, then deep-assigns source EvImg through 0x00425430 with offset zero and count 0xffffffff",
"copies source EvAct +0x6c and EvCID +0x70"
],
"complete_layout": "The ordered writes establish every logical field of the 0x74-byte destination. Each destination string receives its own valid SSO or heap ownership; no source string header, pointer, size/capacity tuple, or other owning header is transferred.",
"exceptional_partial_construction": {
"handler_thunk_va": "0x009862de",
"func_info_va": "0x00ab9f0c",
"func_info": "MSVC magic 0x19930522, maxState 3, unwind map 0x00ab9ef4, no try-block or IP maps, flags 1",
"unwind_states": [
"state 0 -> -1 through 0x009862c0: restore base vptr 0x009e22bc through 0x00763a00",
"state 1 -> 0 through 0x009862c8: destroy completed destination EvDsc at +0x08 through 0x008e0610, then continue state 0 cleanup",
"state 2 -> 1 through 0x009862d3: destroy completed destination EvMsg at +0x24 through 0x008e0610, then continue states 1 and 0 cleanup"
],
"qualification": "Construction state is set to 0 before the EvDsc assignment, 1 before the EvMsg assignment, and 2 before the EvImg assignment. Therefore a throwing current deep assignment is not treated as completed; only predecessor destination strings plus the base are unwound. After successful EvImg assignment, only scalar copies remain. This is static unwind topology; no allocation failure or throw was executed."
},
"ownership": "On normal return destination owns three independent deep copies and must later be destroyed exactly once. Source remains unchanged and retains all three original ownerships. A failed copy must not be passed to the complete PlayerEvent destructor; compiler unwind handles only completed destination subobjects.",
"captures": [
"verify/results/research-live-record-bridge/run-36c401e90eb0ec1db4d35865/player-event-copy-exact.stdout.txt",
"verify/results/research-live-record-bridge/run-36c401e90eb0ec1db4d35865/player-event-copy-ehdata.stdout.txt",
"verify/results/research-live-record-bridge/run-36c401e90eb0ec1db4d35865/player-event-copy-funcinfo.stdout.txt",
"verify/results/research-live-record-bridge/run-36c401e90eb0ec1db4d35865/player-event-copy-cleanup-base.stdout.txt",
"verify/results/research-live-record-bridge/run-36c401e90eb0ec1db4d35865/player-event-copy-cleanup-string.stdout.txt",
"verify/results/research-live-record-bridge/run-36c401e90eb0ec1db4d35865/player-event-copy-eh-record.bin",
"verify/results/research-live-record-bridge/run-36c401e90eb0ec1db4d35865/player-event-copy-eh-analysis.json",
"verify/results/research-live-record-bridge/run-36c401e90eb0ec1db4d35865/manifest.json"
]
},
"player_event_vector_append": {
"va": "0x0086c580",
"rva": "0x0046c580",
"callable_entry": true,
"prototype": "void __thiscall player_event_vector_append(PlayerEventVector *vector, const PlayerEvent *source)",
"receiver": "ECX = live three-pointer vector header: first at +0x00, last at +0x04 and end at +0x08; allocator-shaped storage begins at +0x0c",
"arguments": [{"index": 0, "location": "[entry ESP+0x04] / [EBP+0x08]", "meaning": "source fully constructed live-layout PlayerEvent to deep-copy"}],
"stack_cleanup": "callee removes the one 4-byte source argument with ret 4",
"return": "no supported return-value contract; EAX is incidental after copy construction",
"source_location_branches": [
"For an element-aligned source in [first,last), computes its 0x74-byte element index before possible growth and recomputes the source from the possibly replaced first pointer afterward.",
"For source below first or at/above last, retains the external caller pointer across possible growth. A source inside unused capacity, at last, or unaligned inside the live byte range violates the bridge precondition."
],
"no_growth": "Deep-copy-constructs at old last through 0x007693f0 and advances last by exactly 0x74 only after normal return. First, end and all prior elements remain unchanged.",
"growth": {
"reserve_va": "0x00869500",
"reserve_prototype": "void __thiscall player_event_vector_reserve_additional(PlayerEventVector *vector, uint32_t additional_count)",
"reserve_abi": "ECX=vector, one stack count, ret 4, no supported return; append passes additional_count=1 only when last==end.",
"capacity_rule": "Rejects size+additional above 0x0234f72c elements. If required exceeds capacity, chooses at least required and otherwise capacity+floor(capacity/2), subject to the same maximum, then calls 0x00865ee0.",
"reallocator_va": "0x00865ee0",
"reallocator_abi": "ECX=vector, one requested-capacity stack word, ret 4, no supported return.",
"reallocate_effects": "Allocates requested_count*0x74 through 0x0078af40 -> MSVCR100 scalar new thunk 0x00924fb6; deep-copy-constructs [old first,old last) through 0x00772430 -> 0x007693f0; destroys each old PlayerEvent by virtual slot zero with flags=0; frees old storage through 0x00924faa; then publishes end, last and first in that order. Append subsequently copies the requested source at new last and publishes last+0x74.",
"normal_postcondition": "Every prior event survives as a complete independent deep copy; each old event is destroyed exactly once, old array storage is freed once through the matching runtime family, and the appended event owns three independent strings."
},
"exceptional_ownership": "Append FuncInfo 0x00aa0428 has two branch-specific states whose actions call no-op 0x0080c5a0; partial destination cleanup remains inside 0x007693f0. Reallocator FuncInfo 0x00acb5d4 routes a failed range copy to 0x00865ff1, which frees the unpublished new block after the range helper destroys its completed prefix, then continues propagation through 0x00924fbc. Header publication and append last advancement occur only after successful relocation/copy. This is static unwind topology; no live throw was exercised, so the fixture must contain propagation and prove balanced identities before live-safety acceptance.",
"captures": [
"verify/results/research-live-record-bridge/run-e21ce0d2909d8647e6a99a7b/player-event-append-exact.stdout.txt",
"verify/results/research-live-record-bridge/run-e21ce0d2909d8647e6a99a7b/player-event-growth-exact.stdout.txt",
"verify/results/research-live-record-bridge/run-e21ce0d2909d8647e6a99a7b/player-event-reallocate-exact.stdout.txt",
"verify/results/research-live-record-bridge/run-e21ce0d2909d8647e6a99a7b/player-event-reallocate-cleanup.stdout.txt",
"verify/results/research-live-record-bridge/run-e21ce0d2909d8647e6a99a7b/player-event-append-eh-analysis.json",
"verify/results/research-live-record-bridge/run-e21ce0d2909d8647e6a99a7b/manifest.json",
"verify/results/research-completion-abi-independent/integration-lead-20260910/player-append-wide.stdout.txt"
]
},
"player_event_destruct": {
"va": "0x0061ae90",
"rva": "0x0021ae90",
"callable_entry": true,
"prototype": "void __thiscall player_event_destruct(PlayerEvent *value)",
"receiver": "ECX = one fully constructed live-layout 0x74-byte PlayerEvent",
"arguments": [],
"stack_cleanup": "no stack arguments; helper ends in plain ret",
"return": "no supported return-value contract; EAX is untouched on the all-SSO path and otherwise may retain an incidental scalar-delete result",
"ordered_writes": [
"destroys EvImg first: when capacity +0x64 is at least 0x10, frees the owned buffer pointer at +0x50 through scalar-delete thunk 0x00924faa; then sets capacity +0x64 to 0x0f, size +0x60 to zero and first inline byte +0x50 to zero",
"destroys EvMsg second: when capacity +0x38 is at least 0x10, frees the owned buffer pointer at +0x24 through scalar-delete thunk 0x00924faa; then sets capacity +0x38 to 0x0f, size +0x34 to zero and first inline byte +0x24 to zero",
"destroys EvDsc last: when capacity +0x1c is at least 0x10, frees the owned buffer pointer at +0x08 through scalar-delete thunk 0x00924faa; then sets size +0x18 to zero, capacity +0x1c to 0x0f and first inline byte +0x08 to zero",
"after all three strings are empty, replaces PlayerEvent vptr 0x00a21958 with base vptr 0x009e22bc at +0x00"
],
"ownership": "Consumes the three independent PlayerEvent string ownerships exactly once in reverse member-construction order EvImg, EvMsg, EvDsc. SSO strings cause no free; heap strings each use the matching original-runtime scalar-delete thunk. This complete-object destructor does not take scalar-deleting flags and does not free the enclosing PlayerEvent storage. Reuse requires complete reconstruction; a second call is forbidden.",
"exception_boundary": "The callable has no local SEH frame and performs only capacity tests, optional scalar-delete calls, empty-string state writes and the base-vptr transition. The original scalar-delete service is treated as nonthrowing by this static path, but no live destruction, allocator failure or exception behavior was executed; the bridge boundary must still prevent any exception from crossing its exported WINAPI entry.",
"boundary": "The exact callable is 0x0061ae90..0x0061aefb inclusive, followed by int3 padding at 0x0061aefc..0x0061aeff and the next prologue at 0x0061af00.",
"captures": [
"verify/results/research-live-record-bridge/run-a4f6a9922bf5800747bfdfc6/player-event-dtor-exact.stdout.txt",
"verify/results/research-live-record-bridge/run-a4f6a9922bf5800747bfdfc6/player-event-dtor-context.stdout.txt",
"verify/results/research-live-record-bridge/run-a4f6a9922bf5800747bfdfc6/manifest.json",
"verify/results/research-completion-abi-independent/integration-lead-20260910/player-dtor-control.stdout.txt"
]
},
"string_assign_substr": {
"va": "0x00425430",
"rva": "0x00025430",
"callable_entry": true,
"prototype": "std::string *__thiscall string_assign_substr(std::string *destination, const std::string *source, uint32_t source_offset, uint32_t count)",
"receiver": "ECX = destination std::string",
"arguments": [
{
"index": 0,
"location": "[entry ESP+0x04] / [EBP+0x08]",
"meaning": "source std::string pointer"
},
{
"index": 1,
"location": "[entry ESP+0x08] / [EBP+0x0c]",
"meaning": "zero-based source byte offset"
},
{
"index": 2,
"location": "[entry ESP+0x0c] / [EBP+0x10]",
"meaning": "maximum byte count; 0xffffffff means through source end"
}
],
"stack_cleanup": "callee removes all 12 stack-argument bytes with ret 0x0c",
"return": "EAX = destination std::string pointer on every normal return path",
"bridge_invocation": {
"source": "valid live-layout source string",
"source_offset": 0,
"count": "0xffffffff",
"destination_precondition": "already initialized empty or otherwise valid live-layout string"
},
"writes": [
"destination bytes or destination-owned heap buffer",
"destination size at +0x10",
"destination capacity at +0x14 when growth is required",
"terminating zero byte"
],
"ownership": "Self-assignment uses two in-place erase operations. Non-self assignment selects source inline bytes when capacity is below 0x10 or its heap pointer otherwise. If destination capacity is insufficient it calls VA 0x004249a0 before copying; that worker uses the bound MSVCR100 new/delete thunks. The bridge must initialize destination first and must never transfer the source header.",
"exception_boundary": "This helper has no local SEH frame. Invalid offset and excessive length call imported failure helpers; allocation can propagate from VA 0x004249a0. Bridge usage fixes offset=0/count=0xffffffff on a valid source, leaving allocation as the expected exceptional edge to be contained by the fixture DLL boundary.",
"bridge_call_sites": [
"0x0079a1bd copies ObservedTech name at +0x0c",
"0x00769445 copies PlayerEvent EvDsc at +0x08",
"0x00769464 copies PlayerEvent EvMsg at +0x24",
"0x0076949b copies PlayerEvent EvImg at +0x50"
],
"accepted_dependency_captures": [
"verify/results/research-completion-abi-independent/integration-lead-20260910/observed-copy-control.stdout.txt",
"verify/results/research-completion-abi-independent/integration-lead-20260910/player-copy-wide.stdout.txt",
"verify/results/research-completion-abi-independent/integration-lead-20260910/string-alloc-wide.stdout.txt",
"verify/results/research-completion-abi-independent/integration-lead-20260910/manifest.json"
]
}
},
"forbidden_entries": [
"0x0079a184"
],
"readiness": {
"complete": false,
"reason": "The ObservedTech default-construction, copy-construction, vector-append/growth and scalar-deleting destruction, PlayerEvent default-construction, copy-construction, vector-append/growth and destruction, and shared string-assignment rows are reconciled here. Every TurnEvents operation and remaining exposed allocation operations still require exact generated rows and bound captures before implementation."
}
}