From 13efa438ce01b158a51cd16900d1f298f3e82e02 Mon Sep 17 00:00:00 2001 From: Christopher Williams Date: Thu, 24 Sep 2026 01:37:17 -0400 Subject: [PATCH] =?UTF-8?q?phase9:=20absorption=20=E2=80=94=200x800A623C?= =?UTF-8?q?=20+=200x800A5CEC=20(348=20regions=20/=20339=20bodies)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Two more coordinator tier-2 wrappers, both first-try: 0x800A623C (symbol-form constant + pass-through swap), 0x800A5CEC (guarded call with zero in the jal slot). Gate MATCH whole-binary SHA-1 e173426c157384ebf1b6caf8c6fea18a85a14af9. --- config/regions.tsv | 2 ++ src/func_800A5CEC.c | 37 +++++++++++++++++++++++++++++++++++++ src/func_800A623C.c | 33 +++++++++++++++++++++++++++++++++ 3 files changed, 72 insertions(+) create mode 100644 src/func_800A5CEC.c create mode 100644 src/func_800A623C.c diff --git a/config/regions.tsv b/config/regions.tsv index e93f0e3..40784d2 100644 --- a/config/regions.tsv +++ b/config/regions.tsv @@ -221,6 +221,8 @@ 0x800A2F20 0x800A2F44 src/func_800A2F20.c 0x800A45E0 0x800A466C src/func_8009E8D0.c 0x800A5CC8 0x800A5CEC src/func_800A5CC8.c +0x800A5CEC 0x800A5D24 src/func_800A5CEC.c +0x800A623C 0x800A6268 src/func_800A623C.c 0x800A6268 0x800A6294 src/func_800A6268.c 0x800A648C 0x800A64C8 src/func_800A648C.c 0x800A74BC 0x800A74D0 src/func_800A74BC.c diff --git a/src/func_800A5CEC.c b/src/func_800A5CEC.c new file mode 100644 index 0000000..72e0a3a --- /dev/null +++ b/src/func_800A5CEC.c @@ -0,0 +1,37 @@ +/* func_800A5CEC — 0x800A5CEC..0x800A5D24 (56 bytes). + * + * When bit 0 of arg->byte_27 is clear, calls func_800A5C1C with a signed + * halfword from arg+2 and zero. + * + * Original words: + * 0x27BDFFE8 addiu sp,sp,-24 + * 0xAFBF0010 sw ra,16(sp) + * 0x90820027 lbu v0,39(a0) ; v0 = arg->byte_27 + * 0x00000000 nop + * 0x30420001 andi v0,v0,0x1 + * 0x14400004 bnez v0,done ; if (bit0 != 0) -> skip + * 0x00000000 nop + * 0x84840002 lh a0,2(a0) ; a0 = *(short *)(arg + 2) + * 0x0C029707 jal func_800A5C1C + * 0x00002821 move a1,zero ; (delay) a1 = 0 + * done: + * 0x8FBF0010 lw ra,16(sp) + * 0x27BD0018 addiu sp,sp,24 + * 0x03E00008 jr ra + * 0x00000000 nop + * + * The guard inverts: the call happens when the AND result is zero + * (bit0 clear). The second argument is the zero constant in the jal + * delay slot. + * + * LIMITS: the +39 byte flag and +2 halfword offsets are hypotheses; the + * bytes are the evidence. Only the compiled bytes are evidence. + */ + +void func_800A5C1C(int, int); + +void func_800A5CEC(char *arg) +{ + if ((arg[39] & 1) == 0) + func_800A5C1C(*(short *)(arg + 2), 0); +} \ No newline at end of file diff --git a/src/func_800A623C.c b/src/func_800A623C.c new file mode 100644 index 0000000..b5c8c76 --- /dev/null +++ b/src/func_800A623C.c @@ -0,0 +1,33 @@ +/* func_800A623C — 0x800A623C..0x800A6268 (44 bytes). + * + * Calls func_80012DE8 with a fixed address and the forwarded argument. + * + * Original words: + * 0x27BDFFE8 addiu sp,sp,-24 + * 0xAFBF0010 sw ra,16(sp) + * 0x00802821 move a1,a0 ; a1 = arg (forwarded) + * 0x3C048012 lui a0,0x8012 + * 0x24843660 addiu a0,a0,13920 ; a0 = 0x80123660 (symbol form) + * 0x0C004B7A jal func_80012DE8 + * 0x00000000 nop + * 0x8FBF0010 lw ra,16(sp) + * 0x27BD0018 addiu sp,sp,24 + * 0x03E00008 jr ra + * 0x00000000 nop + * + * The fixed address uses the symbol materialisation (lui+addiu), so it is + * written as a symbol constant (finding 5). a0/a1 are swapped: the constant + * takes the first slot, the argument the second (pass-through idiom). + * + * LIMITS: the fixed address's meaning is a hypothesis. Only the compiled + * bytes are evidence. + */ + +void func_80012DE8(int, int); + +extern int D_80123660; + +void func_800A623C(int arg) +{ + func_80012DE8((int)&D_80123660, arg); +} \ No newline at end of file