7.4 KiB
Read-only capture / provenance index
Initial ReVa session: run-1b88df9d169e9517a5e1b0f0.
ReVa selected program: /Sword of the Stars.exe; reported MD5:
9969481c39f4b33a8a21c48b62abee4c. The initial ReVa service did not expose a local path or
SHA-256. This limitation is now resolved for the static analysis input only: local
dumps/sots.exe has the same MD5 and SHA-256
970b7de729956a53094c7eb98aba4270aee98e2fed5daf0d39e290013c90c841, as independently recorded
in campaign/research/record-observation-crosscheck.md. This binds the local objdump captures to
the ReVa-selected binary fingerprint; it does not bind any live runtime, allocator, asset, or shim.
| Anchor | Fresh static observation |
|---|---|
0x007ba1a0 |
read-memory returned 256 bytes; decompilation reports 395 bytes, four callers including OnTechResearched at 0x008917dc. |
0x008862b0 |
read-memory returned 435 bytes; decompilation reports 435 bytes and 161 incoming references. |
0x0084ee30 |
read-memory returned 196 bytes; decompilation reports a 196-byte __fastcall constructor and six incoming references. |
Requests used the live schema: programPath=/Sword of the Stars.exe,
addressOrSymbol for memory, and functionNameOrAddress for decompilation. All calls were
read-only; no Ghidra, VM, or source mutation occurred.
Local instruction capture added in this quantum
objdump-2026-09-09-ownership.txt contains selected raw instruction windows plus exact GNU
objdump 2.38 commands. It covers the ObservedTech constructor, append/copy/reallocation/allocation
and destruction path, plus PlayerEvent vector copy and three-string destruction path. The
interpretation is in recovered-static.md; raw instructions are the authority where the old
decompiler's false non-return annotation could truncate cleanup.
objdump-2026-09-09-turnevents.txt adds exact local commands and selected raw instructions for
0x00885380, 0x00825d40, 0x00879eb0, outer TurnEvents append/growth/copy/destruction, nested
PlayerEvent vector construction/copy/destruction, both allocation strides, and static unwind edges.
Its selected excerpt omitted the test/branch at 0x00825e1e--0x00825e2d, so Astra decision
d-2ff30c9f5355116bea822924 overturned that excerpt's sufficiency for branch polarity.
objdump-2026-09-09-dedup-helper.txt was intended to repair that gap with exit-zero GNU objdump 2.38
output for 0x00825d40--0x00825e64, helper 0x0046f8c0 through its return, and direct
comparison callees 0x004236a0 and 0x00422720 through every return. After EvImg, FindDuplicate
passes both EvDsc strings to 0x0046f8c0; that helper returns one for unequal strings and zero for
equal strings. 0x00825e23 jumps to the matched-element return only on zero. Therefore description
equality is required for dedup. Candidate and stored strings each independently select inline versus
heap bytes at capacity 0x10; byte equality plus length equality is required, including empty and
mixed short/long cases. This is static instruction evidence, not a live same-bucket fixture.
The historical archive SHA-256 is 3bc3c368f30f2ef2b0d291acad9c0f898b74f4436393d47bf8c942571793dd06;
its first-window unfiltered provenance claim is superseded below.
2026-09-10 stop-boundary provenance repair
Independent review found that the archive above could not be literal unfiltered stdout of its
declared first command: stop 0x00825e65 truncates the terminal three-byte instruction after c2,
but the archive displayed c2 08 00. Astra decision d-d2a9b8be6399a6abaa0e05a5 overturned that
provenance claim and required paired captures. The repaired raw streams are:
objdump-2026-09-10-dedup-narrow.stdout.txt/.stderr.txt, exact stop0x00825e65, exit zero, stdout SHA-2561c2408cd49cc10383bad9fe06d3287476b103205f4155adf64c8a50ccd5205e8;objdump-2026-09-10-dedup-wide.stdout.txt/.stderr.txt, exact stop0x00825e67, exit zero, stdout SHA-2563c9f83d3a98d95ffa68e0595e47f6c3beab3016aa97cd44bf39ac72ed3ec0a84.
objdump-2026-09-10-boundary-repair.md records executable/tool/source identities, stream sizes and
the bounded comparison. Both contain 120 decoded instructions and identical preceding instruction
lines; narrow prints terminal c2, wide prints c2 08 00. The wide content matches the old first
window after line-end normalization apart from one final blank line. This supersedes only the old
first-window production claim; independent semantic review is still required.
2026-09-10 ownership-window provenance repair
Astra decision d-d4c494ba02ada278030ef473 required the same narrow/wide check for the three
ownership rows independently found to have truncated stops, followed by an audit of every remaining
terminal boundary in objdump-2026-09-09-ownership.txt. The complete fresh package is
run-79357a65226f61d6a86c042d/manifest.json; measured comparison and bounded interpretation are in
comparison.json and report.md.
The decision's three predictions held exactly: the allocator, PlayerEvent append and PlayerEvent copy
narrow streams end in c2, while widened streams and independent section-byte dumps contain
c2 04 00; all preceding lines agree. The audit found three additional historical stops with the
same boundary effect: ObservedTech append and reallocator widen from c2 to c2 04 00, and the
string allocation/replacement helper widens from c2 to c2 08 00. The constructor, ObservedTech
copy helper, PlayerEvent destructor and import-thunk windows were already complete at their declared
stops. All 22 commands exited zero with empty stderr. This supersedes command-to-terminal-byte
provenance only; it does not establish archive production history, live execution, allocator safety,
field semantics or acceptance. Fresh independent reproduction remains required.
Independent-review falsifiers
The independent verifier should reproduce the local commands against the recorded SHA-256 input and challenge these distinct-state claims:
- Empty ObservedTech vector and full vector: verify that
0x007b7320reaches growth only on_Mylast == _Myend, and that its0x0079a150path copy-constructs rather than header-copies. - Long versus short strings: verify
>= 0x10cleanup and that the temporary cleanup afterRecordObservedTechcannot be interpreted as ownership transfer. - New versus existing observed-tech name and duplicate versus no-duplicate event: verify branch ordering before inferring any allocation or ID effect.
- Event vector full capacity: verify the
0x74copy/growth path independently from the0x2cObservedTech path; a matching vector header alone is not a falsifier-resistant semantic test. - Duplicate comparator: hold action/location/finite position/message/image fixed; compare equal versus description-only-different EvDsc for empty/short and long strings. Raw instructions predict dedup only for equal descriptions. Require positive comparator entry/return evidence and full pre/post records/IDs in any later live test; static parsing alone does not prove runtime safety.
- Prune boundaries: distinguish zero, one, and two leading stale buckets, plus stale-after-fresh; only the two-leading-stale case should shorten the outer vector, by one bucket.
- Turn buckets: with duplicate
EvTurnbuckets, get-or-create should return the last match; on a miss compare spare versus full outer capacity and empty versus nonempty nested vectors.
No live allocator-safety or replacement claim is offered for independent approval.