sots-re/verify/results/research-completion-abi/run-79357a65226f61d6a86c042d/report.md

3.8 KiB

Ownership-window provenance repair

Static local capture only. This run implements the six-capture probe and remaining ownership-window boundary audit required by Astra decision d-d4c494ba02ada278030ef473. It does not execute the game, an allocator, a constructor, a copy, a destructor, or an exception path.

Bound identities

  • Input: dumps/sots.exe, 7,898,624 bytes, SHA-256 970b7de729956a53094c7eb98aba4270aee98e2fed5daf0d39e290013c90c841, MD5 9969481c39f4b33a8a21c48b62abee4c.
  • Tool: /usr/bin/objdump, SHA-256 1eaaef2e7f57c4c7f69115c495e2466f5a8c8e5f3bc42221d092382f30f9d4cd, GNU Binutils 2.38.
  • CWD: /home/alex/sots-re; exact argv, return codes, stream paths/sizes/hashes and paired source binding are in manifest.json.
  • Source binding before and after capture: engine ccd8e02083e8d2e2b3e97976ace2273c8f924dfc02a39e919004eaf3544c50fd, RE 6696fd5201e144843617cbf6d78b41b5287ad5dcc9fa1e8aaa861d52b64e72e8.

Measured observations

All 22 objdump commands exited zero and every stderr stream is empty. For each paired row below, comparison.json reports that every line before the terminal line is identical.

function/window historical stop widened stop narrow terminal bytes widened/raw bytes
allocator 0x0057e590 0x0057e5e4 0x0057e5e6 c2 c2 04 00
PlayerEvent append 0x0086c580 0x0086c62e 0x0086c630 c2 c2 04 00
PlayerEvent copy 0x007693f0 0x007694c0 0x007694c2 c2 c2 04 00
ObservedTech append 0x007b7320 0x007b739f 0x007b73a1 c2 c2 04 00
ObservedTech reallocator 0x007b34e0 0x007b35ef 0x007b35f1 c2 c2 04 00
string allocator/replace 0x004249a0 0x00424ada 0x00424adc c2 c2 08 00

The audit also freshly retained complete historical-stop streams for the ObservedTech constructor (c3), ObservedTech copy helper (c3), PlayerEvent destructor (c3), and import-thunk window (complete six-byte jump at 0x00924fb6). Thus six of ten audited ownership windows ended on a three-byte ret imm16; all six historical stops admitted only its first byte. The selected 2026-09-09 archive happened to print complete terminal rows, but these fresh captures do not establish how that archive was produced.

Bounded interpretation and unresolved inputs

Complete image bytes establish encoded ret 4 for the allocator, both append operations, the PlayerEvent copy operation and the ObservedTech reallocator, and ret 8 for string allocation/ replacement. This repairs command-to-byte provenance. It does not by itself prove receiver meaning, field semantics, live allocator-family compatibility, successful long-string/full-capacity behavior, or exceptional cleanup.

The callable original-helper dependencies remain the original MSVCR100 allocation/deallocation thunks 0x00924fb6/0x00924faa, string assignment/allocation boundary 0x00425430/0x004249a0, ObservedTech copy helper 0x0079a150, PlayerEvent copy helper 0x007693f0, and the virtual element destructors reached during growth. A standalone implementation must supply one coherent allocation/copy/destruction family rather than mix raw headers with these original-owned allocations.

Missing runtime inputs remain: safe short/long-string fixtures, spare/full-capacity vectors, pre/post element and pointer ownership observations, allocation-failure/throw outcomes, and same-bucket equal versus description-only-different events. No RNG boundary is present in these helpers and no RNG draw occurred because nothing was executed live.

Independent verification must reproduce complete windows from the pinned input/tool, challenge at least one historical stop and one complete stop, and retain the distinct empty/full, short/long, duplicate/nonduplicate and unwind limitations. This analyst does not promote either acceptance criterion.