3.8 KiB
Ownership-window provenance repair
Static local capture only. This run implements the six-capture probe and remaining ownership-window
boundary audit required by Astra decision d-d4c494ba02ada278030ef473. It does not execute the game,
an allocator, a constructor, a copy, a destructor, or an exception path.
Bound identities
- Input:
dumps/sots.exe, 7,898,624 bytes, SHA-256970b7de729956a53094c7eb98aba4270aee98e2fed5daf0d39e290013c90c841, MD59969481c39f4b33a8a21c48b62abee4c. - Tool:
/usr/bin/objdump, SHA-2561eaaef2e7f57c4c7f69115c495e2466f5a8c8e5f3bc42221d092382f30f9d4cd, GNU Binutils 2.38. - CWD:
/home/alex/sots-re; exact argv, return codes, stream paths/sizes/hashes and paired source binding are inmanifest.json. - Source binding before and after capture: engine
ccd8e02083e8d2e2b3e97976ace2273c8f924dfc02a39e919004eaf3544c50fd, RE6696fd5201e144843617cbf6d78b41b5287ad5dcc9fa1e8aaa861d52b64e72e8.
Measured observations
All 22 objdump commands exited zero and every stderr stream is empty. For each paired row below,
comparison.json reports that every line before the terminal line is identical.
| function/window | historical stop | widened stop | narrow terminal bytes | widened/raw bytes |
|---|---|---|---|---|
allocator 0x0057e590 |
0x0057e5e4 |
0x0057e5e6 |
c2 |
c2 04 00 |
PlayerEvent append 0x0086c580 |
0x0086c62e |
0x0086c630 |
c2 |
c2 04 00 |
PlayerEvent copy 0x007693f0 |
0x007694c0 |
0x007694c2 |
c2 |
c2 04 00 |
ObservedTech append 0x007b7320 |
0x007b739f |
0x007b73a1 |
c2 |
c2 04 00 |
ObservedTech reallocator 0x007b34e0 |
0x007b35ef |
0x007b35f1 |
c2 |
c2 04 00 |
string allocator/replace 0x004249a0 |
0x00424ada |
0x00424adc |
c2 |
c2 08 00 |
The audit also freshly retained complete historical-stop streams for the ObservedTech constructor
(c3), ObservedTech copy helper (c3), PlayerEvent destructor (c3), and import-thunk window
(complete six-byte jump at 0x00924fb6). Thus six of ten audited ownership windows ended on a
three-byte ret imm16; all six historical stops admitted only its first byte. The selected 2026-09-09
archive happened to print complete terminal rows, but these fresh captures do not establish how that
archive was produced.
Bounded interpretation and unresolved inputs
Complete image bytes establish encoded ret 4 for the allocator, both append operations, the
PlayerEvent copy operation and the ObservedTech reallocator, and ret 8 for string allocation/
replacement. This repairs command-to-byte provenance. It does not by itself prove receiver meaning,
field semantics, live allocator-family compatibility, successful long-string/full-capacity behavior,
or exceptional cleanup.
The callable original-helper dependencies remain the original MSVCR100 allocation/deallocation
thunks 0x00924fb6/0x00924faa, string assignment/allocation boundary
0x00425430/0x004249a0, ObservedTech copy helper 0x0079a150, PlayerEvent copy helper
0x007693f0, and the virtual element destructors reached during growth. A standalone implementation
must supply one coherent allocation/copy/destruction family rather than mix raw headers with these
original-owned allocations.
Missing runtime inputs remain: safe short/long-string fixtures, spare/full-capacity vectors, pre/post element and pointer ownership observations, allocation-failure/throw outcomes, and same-bucket equal versus description-only-different events. No RNG boundary is present in these helpers and no RNG draw occurred because nothing was executed live.
Independent verification must reproduce complete windows from the pinned input/tool, challenge at least one historical stop and one complete stop, and retain the distinct empty/full, short/long, duplicate/nonduplicate and unwind limitations. This analyst does not promote either acceptance criterion.