sots-re/verify/results/research-completion-abi/run-79357a65226f61d6a86c042d/report.md

64 lines
3.8 KiB
Markdown

# Ownership-window provenance repair
Static local capture only. This run implements the six-capture probe and remaining ownership-window
boundary audit required by Astra decision `d-d4c494ba02ada278030ef473`. It does not execute the game,
an allocator, a constructor, a copy, a destructor, or an exception path.
## Bound identities
* Input: `dumps/sots.exe`, 7,898,624 bytes, SHA-256
`970b7de729956a53094c7eb98aba4270aee98e2fed5daf0d39e290013c90c841`, MD5
`9969481c39f4b33a8a21c48b62abee4c`.
* Tool: `/usr/bin/objdump`, SHA-256
`1eaaef2e7f57c4c7f69115c495e2466f5a8c8e5f3bc42221d092382f30f9d4cd`, GNU Binutils 2.38.
* CWD: `/home/alex/sots-re`; exact argv, return codes, stream paths/sizes/hashes and paired source
binding are in `manifest.json`.
* Source binding before and after capture: engine
`ccd8e02083e8d2e2b3e97976ace2273c8f924dfc02a39e919004eaf3544c50fd`, RE
`6696fd5201e144843617cbf6d78b41b5287ad5dcc9fa1e8aaa861d52b64e72e8`.
## Measured observations
All 22 objdump commands exited zero and every stderr stream is empty. For each paired row below,
`comparison.json` reports that every line before the terminal line is identical.
| function/window | historical stop | widened stop | narrow terminal bytes | widened/raw bytes |
|---|---:|---:|---|---|
| allocator `0x0057e590` | `0x0057e5e4` | `0x0057e5e6` | `c2` | `c2 04 00` |
| PlayerEvent append `0x0086c580` | `0x0086c62e` | `0x0086c630` | `c2` | `c2 04 00` |
| PlayerEvent copy `0x007693f0` | `0x007694c0` | `0x007694c2` | `c2` | `c2 04 00` |
| ObservedTech append `0x007b7320` | `0x007b739f` | `0x007b73a1` | `c2` | `c2 04 00` |
| ObservedTech reallocator `0x007b34e0` | `0x007b35ef` | `0x007b35f1` | `c2` | `c2 04 00` |
| string allocator/replace `0x004249a0` | `0x00424ada` | `0x00424adc` | `c2` | `c2 08 00` |
The audit also freshly retained complete historical-stop streams for the ObservedTech constructor
(`c3`), ObservedTech copy helper (`c3`), PlayerEvent destructor (`c3`), and import-thunk window
(complete six-byte jump at `0x00924fb6`). Thus six of ten audited ownership windows ended on a
three-byte `ret imm16`; all six historical stops admitted only its first byte. The selected 2026-09-09
archive happened to print complete terminal rows, but these fresh captures do not establish how that
archive was produced.
## Bounded interpretation and unresolved inputs
Complete image bytes establish encoded `ret 4` for the allocator, both append operations, the
PlayerEvent copy operation and the ObservedTech reallocator, and `ret 8` for string allocation/
replacement. This repairs command-to-byte provenance. It does not by itself prove receiver meaning,
field semantics, live allocator-family compatibility, successful long-string/full-capacity behavior,
or exceptional cleanup.
The callable original-helper dependencies remain the original MSVCR100 allocation/deallocation
thunks `0x00924fb6`/`0x00924faa`, string assignment/allocation boundary
`0x00425430`/`0x004249a0`, ObservedTech copy helper `0x0079a150`, PlayerEvent copy helper
`0x007693f0`, and the virtual element destructors reached during growth. A standalone implementation
must supply one coherent allocation/copy/destruction family rather than mix raw headers with these
original-owned allocations.
Missing runtime inputs remain: safe short/long-string fixtures, spare/full-capacity vectors,
pre/post element and pointer ownership observations, allocation-failure/throw outcomes, and
same-bucket equal versus description-only-different events. No RNG boundary is present in these
helpers and no RNG draw occurred because nothing was executed live.
Independent verification must reproduce complete windows from the pinned input/tool, challenge at
least one historical stop and one complete stop, and retain the distinct empty/full, short/long,
duplicate/nonduplicate and unwind limitations. This analyst does not promote either acceptance
criterion.