diff --git a/config/match_worklist.tsv b/config/match_worklist.tsv index 356de00..dbe1048 100644 --- a/config/match_worklist.tsv +++ b/config/match_worklist.tsv @@ -197,1160 +197,1144 @@ 190 0x8010AF50 0x8010B420 1232 exact 1 leaf 0 - 1 191 0x800259A0 0x800259DC 60 exact 2 frame 1 - 1 192 0x800F8A0C 0x800F8A48 60 exact 2 frame 2 - 1 -193 0x800429B0 0x800429F0 64 exact 2 frame 2 - 1 -194 0x80086DBC 0x80086DFC 64 exact 2 frame 1 - 1 -195 0x8001590C 0x80015950 68 exact 2 frame 1 - 1 -196 0x80048350 0x80048394 68 exact 2 frame 2 - 1 -197 0x80012918 0x80012960 72 exact 2 frame 1 - 1 -198 0x80017B50 0x80017B98 72 exact 2 frame 1 - 1 -199 0x80017DF0 0x80017E38 72 exact 2 frame 0 - 1 -200 0x8002E9AC 0x8002E9F4 72 exact 2 frame 2 - 1 -201 0x8002F0D0 0x8002F118 72 exact 2 frame 2 - 1 -202 0x8006B184 0x8006B1CC 72 exact 2 frame 1 - 1 -203 0x80070454 0x8007049C 72 exact 2 frame 1 - 1 -204 0x8007759C 0x800775E4 72 exact 2 frame 1 - 1 -205 0x800A6BEC 0x800A6C34 72 exact 2 frame 3 - 1 -206 0x800BBAC8 0x800BBB10 72 exact 2 frame 1 - 1 -207 0x800196B4 0x80019700 76 exact 2 frame 1 - 1 -208 0x8003D310 0x8003D35C 76 exact 2 frame 1 - 1 -209 0x800834B8 0x80083504 76 exact 2 frame 1 - 1 -210 0x800AC648 0x800AC694 76 exact 2 frame 2 - 1 -211 0x800AC98C 0x800AC9D8 76 exact 2 frame 1 - 1 -212 0x800B6CB4 0x800B6D00 76 exact 2 frame 1 - 1 -213 0x800FFFEC 0x80100038 76 exact 2 frame 1 - 1 -214 0x8010806C 0x801080B8 76 exact 2 frame 1 - 1 -215 0x80029E88 0x80029ED8 80 exact 2 frame 2 - 1 -216 0x80046198 0x800461E8 80 exact 2 frame 1 - 1 -217 0x8007D5AC 0x8007D5FC 80 exact 2 frame 1 - 1 -218 0x80090894 0x800908E4 80 exact 2 frame 2 - 1 -219 0x800AFACC 0x800AFB1C 80 exact 2 frame 1 - 1 -220 0x800FFBEC 0x800FFC3C 80 exact 2 frame 2 - 1 -221 0x80018210 0x80018264 84 exact 2 frame 2 - 1 -222 0x800419D0 0x80041A24 84 exact 2 frame 1 - 1 -223 0x8006ADB0 0x8006AE04 84 exact 2 frame 1 - 1 -224 0x8006B2D4 0x8006B328 84 exact 2 frame 1 - 1 -225 0x80090CAC 0x80090D00 84 exact 2 frame 2 - 1 -226 0x80091490 0x800914E4 84 exact 2 frame 1 - 1 -227 0x800AE66C 0x800AE6C0 84 exact 2 frame 1 - 1 -228 0x800B6C60 0x800B6CB4 84 exact 2 frame 3 - 1 -229 0x800FE970 0x800FE9C4 84 exact 2 frame 1 - 1 -230 0x80017AF8 0x80017B50 88 exact 2 frame 1 - 1 -231 0x80025E54 0x80025EAC 88 exact 2 frame 2 - 1 -232 0x80026650 0x800266A8 88 exact 2 frame 1 - 1 -233 0x8002C764 0x8002C7BC 88 exact 2 frame 4 - 1 -234 0x8003022C 0x80030284 88 exact 2 frame 1 - 1 -235 0x80030284 0x800302DC 88 exact 2 frame 1 - 1 -236 0x800319F0 0x80031A48 88 exact 2 frame 1 - 1 -237 0x80043404 0x8004345C 88 exact 2 frame 1 - 1 -238 0x8005E538 0x8005E590 88 exact 2 frame 2 - 1 -239 0x80069580 0x800695D8 88 exact 2 frame 2 - 1 -240 0x8008F2E0 0x8008F338 88 exact 2 frame 5 - 1 -241 0x80099D14 0x80099D6C 88 exact 2 frame 1 - 1 -242 0x800A6A18 0x800A6A70 88 exact 2 frame 2 - 1 -243 0x800A6C34 0x800A6C8C 88 exact 2 frame 2 - 1 -244 0x800F66B8 0x800F6710 88 exact 2 frame 1 - 1 -245 0x80012F24 0x80012F80 92 exact 2 frame 3 - 1 -246 0x80024838 0x80024894 92 exact 2 frame 2 - 1 -247 0x80027C44 0x80027CA0 92 exact 2 frame 1 - 1 -248 0x800307FC 0x80030858 92 exact 2 frame 3 - 1 -249 0x8006B214 0x8006B270 92 exact 2 frame 1 - 1 -250 0x8006B9E0 0x8006BA3C 92 exact 2 frame 2 - 1 -251 0x80093A08 0x80093A64 92 exact 2 frame 2 - 1 -252 0x800B255C 0x800B25B8 92 exact 2 frame 3 - 1 -253 0x800F44D0 0x800F452C 92 exact 2 frame 2 - 1 -254 0x8010A8D8 0x8010A934 92 exact 2 frame 0 - 1 -255 0x80027CA0 0x80027D00 96 exact 2 frame 1 - 1 -256 0x8004C000 0x8004C060 96 exact 2 frame 1 - 1 -257 0x80057564 0x800575C4 96 exact 2 frame 2 - 1 -258 0x8007E7FC 0x8007E85C 96 exact 2 frame 2 - 1 -259 0x8008D9AC 0x8008DA0C 96 exact 2 frame 2 - 1 -260 0x800F42AC 0x800F430C 96 exact 2 frame 2 - 1 -261 0x801029A0 0x80102A00 96 exact 2 frame 1 - 1 -262 0x80023080 0x800230E4 100 exact 2 frame 3 - 1 -263 0x80023A4C 0x80023AB0 100 exact 2 frame 3 - 1 -264 0x8004857C 0x800485E0 100 exact 2 frame 3 - 1 -265 0x8006B270 0x8006B2D4 100 exact 2 frame 1 - 1 -266 0x8008FFC4 0x80090028 100 exact 2 frame 3 - 1 -267 0x800A6934 0x800A6998 100 exact 2 frame 1 - 1 -268 0x800A8920 0x800A8984 100 exact 2 frame 2 - 1 -269 0x800B2488 0x800B24EC 100 exact 2 frame 0 - 1 -270 0x800B6754 0x800B67B8 100 exact 2 frame 0 - 1 -271 0x800BC960 0x800BC9C4 100 exact 2 frame 2 - 1 -272 0x800F2F08 0x800F2F6C 100 exact 2 frame 1 - 1 -273 0x80012960 0x800129C8 104 exact 2 frame 2 - 1 -274 0x800256F0 0x80025758 104 exact 2 frame 2 - 1 -275 0x8005E17C 0x8005E1E4 104 exact 2 frame 1 - 1 -276 0x8006F28C 0x8006F2F4 104 exact 2 frame 1 - 1 -277 0x8007432C 0x80074394 104 exact 2 frame 0 - 1 -278 0x8008A758 0x8008A7C0 104 exact 2 frame 2 - 1 -279 0x80091674 0x800916DC 104 exact 2 frame 3 - 1 -280 0x800A6B38 0x800A6BA0 104 exact 2 frame 1 - 1 -281 0x800B0E64 0x800B0ECC 104 exact 2 frame 4 - 1 -282 0x800B62C8 0x800B6330 104 exact 2 frame 2 - 1 -283 0x800F4098 0x800F4100 104 exact 2 frame 2 - 1 -284 0x800F6AD8 0x800F6B40 104 exact 2 frame 1 - 1 -285 0x800FAF84 0x800FAFEC 104 exact 2 frame 4 - 1 -286 0x800FB54C 0x800FB5B4 104 exact 2 frame 1 - 1 -287 0x80100038 0x801000A0 104 exact 2 frame 2 - 1 -288 0x801059E8 0x80105A50 104 exact 2 frame 1 - 1 -289 0x80015D50 0x80015DBC 108 exact 2 frame 2 - 1 -290 0x800183EC 0x80018458 108 exact 2 frame 0 - 1 -291 0x80026274 0x800262E0 108 exact 2 frame 1 - 1 -292 0x80030858 0x800308C4 108 exact 2 frame 1 - 1 -293 0x80055958 0x800559C4 108 exact 2 frame 1 - 1 -294 0x80072D0C 0x80072D78 108 exact 2 frame 0 - 1 -295 0x8007F9B0 0x8007FA1C 108 exact 2 frame 1 - 1 -296 0x800909D8 0x80090A44 108 exact 2 frame 1 - 1 -297 0x800AA0A0 0x800AA10C 108 exact 2 frame 1 - 1 -298 0x800ACAC8 0x800ACB34 108 exact 2 frame 4 - 1 -299 0x800AE4DC 0x800AE548 108 exact 2 frame 3 - 1 -300 0x80031EBC 0x80031F2C 112 exact 2 frame 1 - 1 -301 0x8005584C 0x800558BC 112 exact 2 frame 1 - 1 -302 0x8006B328 0x8006B398 112 exact 2 frame 1 - 1 -303 0x800784F4 0x80078564 112 exact 2 frame 0 - 1 -304 0x800922D0 0x80092340 112 exact 2 frame 2 - 1 -305 0x800B6AE0 0x800B6B50 112 exact 2 frame 1 - 1 -306 0x800F452C 0x800F459C 112 exact 2 frame 2 - 1 -307 0x800FB410 0x800FB480 112 exact 2 frame 1 - 1 -308 0x800FB758 0x800FB7C8 112 exact 2 frame 4 - 1 -309 0x8010AA28 0x8010AA98 112 exact 2 frame 5 - 1 -310 0x80013C90 0x80013D04 116 exact 2 frame 2 - 1 -311 0x80014258 0x800142CC 116 exact 2 frame 3 - 1 -312 0x800280DC 0x80028150 116 exact 2 frame 2 - 1 -313 0x8002FDC8 0x8002FE3C 116 exact 2 frame 1 - 1 -314 0x800475CC 0x80047640 116 exact 2 frame 0 - 1 -315 0x80074C00 0x80074C74 116 exact 2 frame 1 - 1 -316 0x800833CC 0x80083440 116 exact 2 frame 1 - 1 -317 0x8009141C 0x80091490 116 exact 2 frame 1 - 1 -318 0x8009214C 0x800921C0 116 exact 2 frame 1 - 1 -319 0x800A4CA8 0x800A4D1C 116 exact 2 frame 0 - 1 -320 0x800B1D5C 0x800B1DD0 116 exact 2 frame 1 - 1 -321 0x800F6948 0x800F69BC 116 exact 2 frame 5 - 1 -322 0x800F9014 0x800F9088 116 exact 2 frame 1 - 1 -323 0x80021C64 0x80021CDC 120 exact 2 frame 4 - 1 -324 0x800275CC 0x80027644 120 exact 2 frame 2 - 1 -325 0x800454C8 0x80045540 120 exact 2 frame 1 - 1 -326 0x80045FD8 0x80046050 120 exact 2 frame 3 - 1 -327 0x800472E8 0x80047360 120 exact 2 frame 2 - 1 -328 0x80048DA8 0x80048E20 120 exact 2 frame 1 - 1 -329 0x80050CA8 0x80050D20 120 exact 2 frame 1 - 1 -330 0x80057E04 0x80057E7C 120 exact 2 frame 0 - 1 -331 0x800801B4 0x8008022C 120 exact 2 frame 2 - 1 -332 0x8008E258 0x8008E2D0 120 exact 2 frame 1 - 1 -333 0x800AA4F4 0x800AA56C 120 exact 2 frame 2 - 1 -334 0x800C110C 0x800C1184 120 exact 2 frame 1 - 1 -335 0x80103144 0x801031BC 120 exact 2 frame 1 - 1 -336 0x8001896C 0x800189E8 124 exact 2 frame 2 - 1 -337 0x8001AAA8 0x8001AB24 124 exact 2 frame 1 - 1 -338 0x80029054 0x800290D0 124 exact 2 frame 1 - 1 -339 0x8002D17C 0x8002D1F8 124 exact 2 frame 2 - 1 -340 0x8002E44C 0x8002E4C8 124 exact 2 frame 2 - 1 -341 0x8002E870 0x8002E8EC 124 exact 2 frame 3 - 1 -342 0x8002E8EC 0x8002E968 124 exact 2 frame 0 - 1 -343 0x8002FCD0 0x8002FD4C 124 exact 2 frame 3 - 1 -344 0x8002FD4C 0x8002FDC8 124 exact 2 frame 3 - 1 -345 0x800302DC 0x80030358 124 exact 2 frame 1 - 1 -346 0x8003870C 0x80038788 124 exact 2 frame 4 - 1 -347 0x80057F08 0x80057F84 124 exact 2 frame 1 - 1 -348 0x8006B5F0 0x8006B66C 124 exact 2 frame 2 - 1 -349 0x8006B964 0x8006B9E0 124 exact 2 frame 3 - 1 -350 0x8006BB0C 0x8006BB88 124 exact 2 frame 1 - 1 -351 0x8006D148 0x8006D1C4 124 exact 2 frame 1 - 1 -352 0x80072D78 0x80072DF4 124 exact 2 frame 1 - 1 -353 0x8008A400 0x8008A47C 124 exact 2 frame 0 - 1 -354 0x80095CF8 0x80095D74 124 exact 2 frame 1 - 1 -355 0x800A4764 0x800A47E0 124 exact 2 frame 0 - 1 -356 0x800A84E8 0x800A8564 124 exact 2 frame 2 - 1 -357 0x800B8DE4 0x800B8E60 124 exact 2 frame 3 - 1 -358 0x800C5278 0x800C52F4 124 exact 2 frame 1 - 1 -359 0x800F6638 0x800F66B4 124 exact 2 frame 1 - 1 -360 0x80107E90 0x80107F0C 124 exact 2 frame 0 - 1 -361 0x80026E94 0x80026F14 128 exact 2 frame 1 - 1 -362 0x800A6998 0x800A6A18 128 exact 2 frame 4 - 1 -363 0x800A80B8 0x800A8138 128 exact 2 frame 0 - 1 -364 0x800A88A0 0x800A8920 128 exact 2 frame 1 - 1 -365 0x800B67B8 0x800B6838 128 exact 2 frame 1 - 1 -366 0x800F4B88 0x800F4C08 128 exact 2 frame 2 - 1 -367 0x800F521C 0x800F529C 128 exact 2 frame 0 - 1 -368 0x800F6DD0 0x800F6E50 128 exact 2 frame 2 - 1 -369 0x800F6E50 0x800F6ED0 128 exact 2 frame 2 - 1 -370 0x800FB6D8 0x800FB758 128 exact 2 frame 4 - 1 -371 0x800FBB20 0x800FBBA0 128 exact 2 frame 5 - 1 -372 0x801000A0 0x80100120 128 exact 2 frame 1 - 1 -373 0x80102A00 0x80102A80 128 exact 2 frame 6 - 1 -374 0x80107DE8 0x80107E68 128 exact 2 frame 1 - 1 -375 0x8001703C 0x800170C0 132 exact 2 frame 1 - 1 -376 0x80026E10 0x80026E94 132 exact 2 frame 2 - 1 -377 0x80042138 0x800421BC 132 exact 2 frame 4 - 1 -378 0x8005E79C 0x8005E820 132 exact 2 frame 3 - 1 -379 0x8007D5FC 0x8007D680 132 exact 2 frame 2 - 1 -380 0x800A8464 0x800A84E8 132 exact 2 frame 0 - 1 -381 0x800A9EF8 0x800A9F7C 132 exact 2 frame 1 - 1 -382 0x800AE458 0x800AE4DC 132 exact 2 frame 3 - 1 -383 0x800B1BB0 0x800B1C34 132 exact 2 frame 1 - 1 -384 0x800C3490 0x800C3514 132 exact 2 frame 0 - 1 -385 0x800FA5D8 0x800FA65C 132 exact 2 frame 4 - 1 -386 0x80102A80 0x80102B04 132 exact 2 frame 1 - 1 -387 0x80105148 0x801051CC 132 exact 2 frame 3 - 1 -388 0x8010A6C4 0x8010A748 132 exact 2 frame 4 - 1 -389 0x800239C4 0x80023A4C 136 exact 2 frame 2 - 1 -390 0x80025ADC 0x80025B64 136 exact 2 frame 1 - 1 -391 0x800268F4 0x8002697C 136 exact 2 frame 5 - 1 -392 0x8003FC78 0x8003FD00 136 exact 2 frame 2 - 1 -393 0x80073284 0x8007330C 136 exact 2 frame 1 - 1 -394 0x8007E0A4 0x8007E12C 136 exact 2 frame 2 - 1 -395 0x800A6294 0x800A631C 136 exact 2 frame 6 - 1 -396 0x800ADF18 0x800ADFA0 136 exact 2 frame 1 - 1 -397 0x80108740 0x801087C8 136 exact 2 frame 2 - 1 -398 0x80048180 0x8004820C 140 exact 2 frame 1 - 1 -399 0x80057E7C 0x80057F08 140 exact 2 frame 1 - 1 -400 0x8005BF44 0x8005BFD0 140 exact 2 frame 1 - 1 -401 0x8006D1C4 0x8006D250 140 exact 2 frame 1 - 1 -402 0x80089DE8 0x80089E74 140 exact 2 frame 1 - 1 -403 0x800B6B50 0x800B6BDC 140 exact 2 frame 1 - 1 -404 0x800C0BFC 0x800C0C88 140 exact 2 frame 1 - 1 -405 0x800FFF60 0x800FFFEC 140 exact 2 frame 3 - 1 -406 0x80107458 0x801074E4 140 exact 2 frame 1 - 1 -407 0x80013AF0 0x80013B80 144 exact 2 frame 3 - 1 -408 0x8001587C 0x8001590C 144 exact 2 frame 3 - 1 -409 0x80015CC0 0x80015D50 144 exact 2 frame 1 - 1 -410 0x8001758C 0x8001761C 144 exact 2 frame 1 - 1 -411 0x800182F4 0x80018384 144 exact 2 frame 1 - 1 -412 0x80025DC4 0x80025E54 144 exact 2 frame 2 - 1 -413 0x8002D364 0x8002D3F4 144 exact 2 frame 7 - 1 -414 0x80036278 0x80036308 144 exact 2 frame 2 - 1 -415 0x80038D48 0x80038DD8 144 exact 2 frame 0 - 1 -416 0x800461E8 0x80046278 144 exact 2 frame 1 - 1 -417 0x80047984 0x80047A14 144 exact 2 frame 1 - 1 -418 0x8005E340 0x8005E3D0 144 exact 2 frame 2 - 1 -419 0x80063060 0x800630F0 144 exact 2 frame 2 - 1 -420 0x80063870 0x80063900 144 exact 2 frame 3 - 1 -421 0x80065670 0x80065700 144 exact 2 frame 3 - 1 -422 0x800829D8 0x80082A68 144 exact 2 frame 0 - 1 -423 0x800AD1C8 0x800AD258 144 exact 2 frame 0 - 1 -424 0x800F421C 0x800F42AC 144 exact 2 frame 2 - 1 -425 0x800F897C 0x800F8A0C 144 exact 2 frame 2 - 1 -426 0x801001C4 0x80100254 144 exact 2 frame 1 - 1 -427 0x80100508 0x80100598 144 exact 2 frame 3 - 1 -428 0x80104BA8 0x80104C38 144 exact 2 frame 1 - 1 -429 0x800247A4 0x80024838 148 exact 2 frame 1 - 1 -430 0x8003AB20 0x8003ABB4 148 exact 2 frame 1 - 1 -431 0x8004331C 0x800433B0 148 exact 2 frame 0 - 1 -432 0x80051914 0x800519A8 148 exact 2 frame 1 - 1 -433 0x800637DC 0x80063870 148 exact 2 frame 2 - 1 -434 0x80079C90 0x80079D24 148 exact 2 frame 0 - 1 -435 0x8007A080 0x8007A114 148 exact 2 frame 1 - 1 -436 0x80089D54 0x80089DE8 148 exact 2 frame 1 - 1 -437 0x800A9CC4 0x800A9D58 148 exact 2 frame 4 - 1 -438 0x800AB504 0x800AB598 148 exact 2 frame 2 - 1 -439 0x800BC658 0x800BC6EC 148 exact 2 frame 4 - 1 -440 0x800FB480 0x800FB514 148 exact 2 frame 0 - 1 -441 0x801003A4 0x80100438 148 exact 2 frame 4 - 1 -442 0x80026A04 0x80026A9C 152 exact 2 frame 3 - 1 -443 0x8002BCE8 0x8002BD80 152 exact 2 frame 3 - 1 -444 0x8004A1E0 0x8004A278 152 exact 2 frame 1 - 1 -445 0x8005E820 0x8005E8B8 152 exact 2 frame 3 - 1 -446 0x800645CC 0x80064664 152 exact 2 frame 3 - 1 -447 0x8007D680 0x8007D718 152 exact 2 frame 1 - 1 -448 0x800B107C 0x800B1114 152 exact 2 frame 2 - 1 -449 0x800BBDF8 0x800BBE90 152 exact 2 frame 0 - 1 -450 0x800C1424 0x800C14BC 152 exact 2 frame 2 - 1 -451 0x800F4000 0x800F4098 152 exact 2 frame 3 - 1 -452 0x800F77D8 0x800F7870 152 exact 2 frame 3 - 1 -453 0x800F9094 0x800F912C 152 exact 2 frame 2 - 1 -454 0x80103094 0x8010312C 152 exact 2 frame 1 - 1 -455 0x80012DE8 0x80012E84 156 exact 2 frame 1 - 1 -456 0x80016F80 0x8001701C 156 exact 2 frame 1 - 1 -457 0x8002C7EC 0x8002C888 156 exact 2 frame 7 - 1 -458 0x8002FAB8 0x8002FB54 156 exact 2 frame 1 - 1 -459 0x80043AE4 0x80043B80 156 exact 2 frame 1 - 1 -460 0x80048B84 0x80048C20 156 exact 2 frame 2 - 1 -461 0x800491FC 0x80049298 156 exact 2 frame 3 - 1 -462 0x800558BC 0x80055958 156 exact 2 frame 1 - 1 -463 0x8006A654 0x8006A6F0 156 exact 2 frame 2 - 1 -464 0x80083018 0x800830B4 156 exact 2 frame 1 - 1 -465 0x800BC8C4 0x800BC960 156 exact 2 frame 4 - 1 -466 0x80012E84 0x80012F24 160 exact 2 frame 3 - 1 -467 0x8001644C 0x800164EC 160 exact 2 frame 3 - 1 -468 0x8001CDA0 0x8001CE40 160 exact 2 frame 1 - 1 -469 0x8002311C 0x800231BC 160 exact 2 frame 4 - 1 -470 0x800575C4 0x80057664 160 exact 2 frame 2 - 1 -471 0x80058190 0x80058230 160 exact 2 frame 1 - 1 -472 0x8007C408 0x8007C4A8 160 exact 2 frame 1 - 1 -473 0x80089C74 0x80089D14 160 exact 2 frame 1 - 1 -474 0x800A9C24 0x800A9CC4 160 exact 2 frame 4 - 1 -475 0x800B5FF0 0x800B6090 160 exact 2 frame 2 - 1 -476 0x800FF0E4 0x800FF184 160 exact 2 frame 2 - 1 -477 0x80012F80 0x80013024 164 exact 2 frame 1 - 1 -478 0x80016660 0x80016704 164 exact 2 frame 0 - 1 -479 0x80025D20 0x80025DC4 164 exact 2 frame 2 - 1 -480 0x800270D4 0x80027178 164 exact 2 frame 2 - 1 -481 0x8002DF84 0x8002E028 164 exact 2 frame 1 - 1 -482 0x80031B18 0x80031BBC 164 exact 2 frame 1 - 1 -483 0x80041FE4 0x80042088 164 exact 2 frame 4 - 1 -484 0x800516FC 0x800517A0 164 exact 2 frame 1 - 1 -485 0x8005E29C 0x8005E340 164 exact 2 frame 3 - 1 -486 0x80066738 0x800667DC 164 exact 2 frame 1 - 1 -487 0x8007D20C 0x8007D2B0 164 exact 2 frame 1 - 1 -488 0x800827C4 0x80082868 164 exact 2 frame 2 - 1 -489 0x800C2CE4 0x800C2D88 164 exact 2 frame 1 - 1 -490 0x800F6898 0x800F693C 164 exact 2 frame 4 - 1 -491 0x800FAC44 0x800FACE8 164 exact 2 frame 1 - 1 -492 0x80100120 0x801001C4 164 exact 2 frame 1 - 1 -493 0x80022E78 0x80022F20 168 exact 2 frame 1 - 1 -494 0x80032258 0x80032300 168 exact 2 frame 1 - 1 -495 0x800592A4 0x8005934C 168 exact 2 frame 2 - 1 -496 0x8007BC64 0x8007BD0C 168 exact 2 frame 1 - 1 -497 0x800A3358 0x800A3400 168 exact 2 frame 1 - 1 -498 0x800A4AC8 0x800A4B70 168 exact 2 frame 3 - 1 -499 0x800A5180 0x800A5228 168 exact 2 frame 1 - 1 -500 0x800A8B8C 0x800A8C34 168 exact 2 frame 1 - 1 -501 0x800BE6D8 0x800BE780 168 exact 2 frame 0 - 1 -502 0x800BE780 0x800BE828 168 exact 2 frame 0 - 1 -503 0x800FF758 0x800FF800 168 exact 2 frame 1 - 1 -504 0x80028C34 0x80028CE0 172 exact 2 frame 1 - 1 -505 0x8005E590 0x8005E63C 172 exact 2 frame 6 - 1 -506 0x8006D250 0x8006D2FC 172 exact 2 frame 1 - 1 -507 0x8007B00C 0x8007B0B8 172 exact 2 frame 1 - 1 -508 0x80082868 0x80082914 172 exact 2 frame 5 - 1 -509 0x800908E4 0x80090990 172 exact 2 frame 4 - 1 -510 0x80091370 0x8009141C 172 exact 2 frame 2 - 1 -511 0x800A5C1C 0x800A5CC8 172 exact 2 frame 0 - 1 -512 0x800A64C8 0x800A6574 172 exact 2 frame 1 - 1 -513 0x800A8224 0x800A82D0 172 exact 2 frame 3 - 1 -514 0x800F4424 0x800F44D0 172 exact 2 frame 2 - 1 -515 0x80016E68 0x80016F18 176 exact 2 frame 2 - 1 -516 0x80017C6C 0x80017D1C 176 exact 2 frame 2 - 1 -517 0x800250AC 0x8002515C 176 exact 2 frame 3 - 1 -518 0x80025A2C 0x80025ADC 176 exact 2 frame 1 - 1 -519 0x80027E1C 0x80027ECC 176 exact 2 frame 3 - 1 -520 0x80028344 0x800283F4 176 exact 2 frame 2 - 1 -521 0x80046348 0x800463F8 176 exact 2 frame 1 - 1 -522 0x80074734 0x800747E4 176 exact 2 frame 4 - 1 -523 0x80089338 0x800893E8 176 exact 2 frame 2 - 1 -524 0x800AD3D4 0x800AD484 176 exact 2 frame 0 - 1 -525 0x800B1DD0 0x800B1E80 176 exact 2 frame 2 - 1 -526 0x800C2D88 0x800C2E38 176 exact 2 frame 1 - 1 -527 0x801080B8 0x80108168 176 exact 2 frame 4 - 1 -528 0x801085E0 0x80108690 176 exact 2 frame 1 - 1 -529 0x80021CDC 0x80021D90 180 exact 2 frame 4 - 1 -530 0x8002E198 0x8002E24C 180 exact 2 frame 6 - 1 -531 0x80050BF4 0x80050CA8 180 exact 2 frame 2 - 1 -532 0x8006D2FC 0x8006D3B0 180 exact 2 frame 1 - 1 -533 0x800A631C 0x800A63D0 180 exact 2 frame 3 - 1 -534 0x800A6880 0x800A6934 180 exact 2 frame 3 - 1 -535 0x800B1F94 0x800B2048 180 exact 2 frame 4 - 1 -536 0x800C2C30 0x800C2CE4 180 exact 2 frame 2 - 1 -537 0x80014FE8 0x800150A0 184 exact 2 frame 9 - 1 -538 0x80019808 0x800198C0 184 exact 2 frame 1 - 1 -539 0x80021E6C 0x80021F24 184 exact 2 frame 3 - 1 -540 0x80023BF4 0x80023CAC 184 exact 2 frame 2 - 1 -541 0x80028698 0x80028750 184 exact 2 frame 4 - 1 -542 0x8005A6D4 0x8005A78C 184 exact 2 frame 7 - 1 -543 0x8005E1E4 0x8005E29C 184 exact 2 frame 2 - 1 -544 0x80079D24 0x80079DDC 184 exact 2 frame 0 - 1 -545 0x8007AB7C 0x8007AC34 184 exact 2 frame 1 - 1 -546 0x800ACA10 0x800ACAC8 184 exact 2 frame 4 - 1 -547 0x800F436C 0x800F4424 184 exact 2 frame 2 - 1 -548 0x800FED84 0x800FEE3C 184 exact 2 frame 5 - 1 -549 0x80108434 0x801084EC 184 exact 2 frame 1 - 1 -550 0x80021BA8 0x80021C64 188 exact 2 frame 2 - 1 -551 0x800236F8 0x800237B4 188 exact 2 frame 7 - 1 -552 0x80045F1C 0x80045FD8 188 exact 2 frame 3 - 1 -553 0x80050548 0x80050604 188 exact 2 frame 1 - 1 -554 0x800506E4 0x800507A0 188 exact 2 frame 1 - 1 -555 0x800507A0 0x8005085C 188 exact 2 frame 1 - 1 -556 0x8006B6BC 0x8006B778 188 exact 2 frame 3 - 1 -557 0x8008E19C 0x8008E258 188 exact 2 frame 2 - 1 -558 0x800A63D0 0x800A648C 188 exact 2 frame 3 - 1 -559 0x800A8984 0x800A8A40 188 exact 2 frame 4 - 1 -560 0x800AF260 0x800AF31C 188 exact 2 frame 1 - 1 -561 0x8002E0D8 0x8002E198 192 exact 2 frame 4 - 1 -562 0x800437CC 0x8004388C 192 exact 2 frame 2 - 1 -563 0x80046A18 0x80046AD8 192 exact 2 frame 0 - 1 -564 0x800589E8 0x80058AA8 192 exact 2 frame 4 - 1 -565 0x800682F0 0x800683B0 192 exact 2 frame 3 - 1 -566 0x8006D3B0 0x8006D470 192 exact 2 frame 1 - 1 -567 0x80086CFC 0x80086DBC 192 exact 2 frame 0 - 1 -568 0x8008CC00 0x8008CCC0 192 exact 2 frame 2 - 1 -569 0x8008DB44 0x8008DC04 192 exact 2 frame 2 - 1 -570 0x8008FE98 0x8008FF58 192 exact 2 frame 3 - 1 -571 0x800F459C 0x800F465C 192 exact 2 frame 4 - 1 -572 0x8002C30C 0x8002C3D0 196 exact 2 frame 2 - 1 -573 0x80030414 0x800304D8 196 exact 2 frame 5 - 1 -574 0x80044B90 0x80044C54 196 exact 2 frame 0 - 1 -575 0x80045D84 0x80045E48 196 exact 2 frame 1 - 1 -576 0x800460D4 0x80046198 196 exact 2 frame 1 - 1 -577 0x800654E4 0x800655A8 196 exact 2 frame 3 - 1 -578 0x8006F9B4 0x8006FA78 196 exact 2 frame 1 - 1 -579 0x80074268 0x8007432C 196 exact 2 frame 4 - 1 -580 0x80089B88 0x80089C4C 196 exact 2 frame 2 - 1 -581 0x800AD104 0x800AD1C8 196 exact 2 frame 0 - 1 -582 0x800C1048 0x800C110C 196 exact 2 frame 3 - 1 -583 0x80100254 0x80100318 196 exact 2 frame 1 - 1 -584 0x8002BC20 0x8002BCE8 200 exact 2 frame 6 - 1 -585 0x8003570C 0x800357D4 200 exact 2 frame 1 - 1 -586 0x800655A8 0x80065670 200 exact 2 frame 2 - 1 -587 0x800A6A70 0x800A6B38 200 exact 2 frame 2 - 1 -588 0x80100598 0x80100660 200 exact 2 frame 5 - 1 -589 0x800258D4 0x800259A0 204 exact 2 frame 2 - 1 -590 0x800297F4 0x800298C0 204 exact 2 frame 2 - 1 -591 0x8002CB84 0x8002CC50 204 exact 2 frame 10 - 1 -592 0x800323E4 0x800324B0 204 exact 2 frame 3 - 1 -593 0x80044C54 0x80044D20 204 exact 2 frame 4 - 1 -594 0x800508CC 0x80050998 204 exact 2 frame 6 - 1 -595 0x80054AF8 0x80054BC4 204 exact 2 frame 0 - 1 -596 0x8005A81C 0x8005A8E8 204 exact 2 frame 1 - 1 -597 0x800667DC 0x800668A8 204 exact 2 frame 1 - 1 -598 0x80083BAC 0x80083C78 204 exact 2 frame 3 - 1 -599 0x80099AE4 0x80099BB0 204 exact 2 frame 1 - 1 -600 0x8009B4A0 0x8009B56C 204 exact 2 frame 1 - 1 -601 0x800ACB34 0x800ACC00 204 exact 2 frame 1 - 1 -602 0x800BB9FC 0x800BBAC8 204 exact 2 frame 3 - 1 -603 0x800F8658 0x800F8724 204 exact 2 frame 1 - 1 -604 0x80104230 0x801042FC 204 exact 2 frame 7 - 1 -605 0x801094D8 0x801095A4 204 exact 2 frame 1 - 1 -606 0x80019738 0x80019808 208 exact 2 frame 2 - 1 -607 0x80031A48 0x80031B18 208 exact 2 frame 2 - 1 -608 0x800453F8 0x800454C8 208 exact 2 frame 1 - 1 -609 0x80046278 0x80046348 208 exact 2 frame 1 - 1 -610 0x80099C44 0x80099D14 208 exact 2 frame 0 - 1 -611 0x80100438 0x80100508 208 exact 2 frame 6 - 1 -612 0x8010080C 0x801008DC 208 exact 2 frame 2 - 1 -613 0x800111B0 0x80011284 212 exact 2 frame 1 - 1 -614 0x80025F10 0x80025FE4 212 exact 2 frame 3 - 1 -615 0x800279E4 0x80027AB8 212 exact 2 frame 0 - 1 -616 0x8002D0A8 0x8002D17C 212 exact 2 frame 2 - 1 -617 0x80043DC4 0x80043E98 212 exact 2 frame 3 - 1 -618 0x80045E48 0x80045F1C 212 exact 2 frame 0 - 1 -619 0x80057F84 0x80058058 212 exact 2 frame 0 - 1 -620 0x8006821C 0x800682F0 212 exact 2 frame 1 - 1 -621 0x8007A428 0x8007A4FC 212 exact 2 frame 1 - 1 -622 0x800ACCD8 0x800ACDAC 212 exact 2 frame 0 - 1 -623 0x800ACED4 0x800ACFA8 212 exact 2 frame 0 - 1 -624 0x80101764 0x80101838 212 exact 2 frame 4 - 1 -625 0x80105474 0x80105548 212 exact 2 frame 1 - 1 -626 0x8006B398 0x8006B470 216 exact 2 frame 3 - 1 -627 0x8006D470 0x8006D548 216 exact 2 frame 1 - 1 -628 0x80090BB4 0x80090C8C 216 exact 2 frame 5 - 1 -629 0x800A4E48 0x800A4F20 216 exact 2 frame 2 - 1 -630 0x800AD9A8 0x800ADA80 216 exact 2 frame 0 - 1 -631 0x800F3A30 0x800F3B08 216 exact 2 frame 1 - 1 -632 0x80107B84 0x80107C5C 216 exact 2 frame 2 - 1 -633 0x80015950 0x80015A2C 220 exact 2 frame 1 - 1 -634 0x800198F4 0x800199D0 220 exact 2 frame 0 - 1 -635 0x80021D90 0x80021E6C 220 exact 2 frame 3 - 1 -636 0x8004D7C8 0x8004D8A4 220 exact 2 frame 2 - 1 -637 0x8006B0A8 0x8006B184 220 exact 2 frame 2 - 1 -638 0x80074658 0x80074734 220 exact 2 frame 7 - 1 -639 0x8008F530 0x8008F60C 220 exact 2 frame 3 - 1 -640 0x8008FDBC 0x8008FE98 220 exact 2 frame 3 - 1 -641 0x80024F6C 0x8002504C 224 exact 2 frame 6 - 1 -642 0x80029ED8 0x80029FB8 224 exact 2 frame 5 - 1 -643 0x8002C22C 0x8002C30C 224 exact 2 frame 7 - 1 -644 0x800733C4 0x800734A4 224 exact 2 frame 3 - 1 -645 0x8007A324 0x8007A404 224 exact 2 frame 3 - 1 -646 0x800A75CC 0x800A76AC 224 exact 2 frame 2 - 1 -647 0x800AE6C0 0x800AE7A0 224 exact 2 frame 3 - 1 -648 0x80100660 0x80100740 224 exact 2 frame 4 - 1 -649 0x80105014 0x801050F4 224 exact 2 frame 1 - 1 -650 0x80045CA0 0x80045D84 228 exact 2 frame 1 - 1 -651 0x8005260C 0x800526F0 228 exact 2 frame 1 - 1 -652 0x80057664 0x80057748 228 exact 2 frame 2 - 1 -653 0x80073F78 0x8007405C 228 exact 2 frame 5 - 1 -654 0x8007405C 0x80074140 228 exact 2 frame 5 - 1 -655 0x8007FCCC 0x8007FDB0 228 exact 2 frame 4 - 1 -656 0x800800D0 0x800801B4 228 exact 2 frame 4 - 1 -657 0x8008FCD8 0x8008FDBC 228 exact 2 frame 2 - 1 -658 0x80092A48 0x80092B2C 228 exact 2 frame 1 - 1 -659 0x800A6574 0x800A6658 228 exact 2 frame 2 - 1 -660 0x800FCB4C 0x800FCC30 228 exact 2 frame 3 - 1 -661 0x80024894 0x8002497C 232 exact 2 frame 2 - 1 -662 0x80065C34 0x80065D1C 232 exact 2 frame 1 - 1 -663 0x80074570 0x80074658 232 exact 2 frame 1 - 1 -664 0x8008D5F8 0x8008D6E0 232 exact 2 frame 2 - 1 -665 0x800A3400 0x800A34E8 232 exact 2 frame 2 - 1 -666 0x800B6F64 0x800B704C 232 exact 2 frame 3 - 1 -667 0x800BB1C4 0x800BB2AC 232 exact 2 frame 3 - 1 -668 0x8010A940 0x8010AA28 232 exact 2 frame 4 - 1 -669 0x8001AB24 0x8001AC10 236 exact 2 frame 3 - 1 -670 0x80024E80 0x80024F6C 236 exact 2 frame 3 - 1 -671 0x800278F8 0x800279E4 236 exact 2 frame 1 - 1 -672 0x8002BD80 0x8002BE6C 236 exact 2 frame 7 - 1 -673 0x8006ED58 0x8006EE44 236 exact 2 frame 4 - 1 -674 0x8007B83C 0x8007B928 236 exact 2 frame 3 - 1 -675 0x8007C6E0 0x8007C7CC 236 exact 2 frame 1 - 1 -676 0x800A8138 0x800A8224 236 exact 2 frame 1 - 1 -677 0x800BC6EC 0x800BC7D8 236 exact 2 frame 6 - 1 -678 0x800BC7D8 0x800BC8C4 236 exact 2 frame 6 - 1 -679 0x800FF4BC 0x800FF5A8 236 exact 2 frame 4 - 1 -680 0x80101678 0x80101764 236 exact 2 frame 4 - 1 -681 0x8010713C 0x80107228 236 exact 2 frame 0 - 1 -682 0x80013024 0x80013114 240 exact 2 frame 1 - 1 -683 0x80026560 0x80026650 240 exact 2 frame 1 - 1 -684 0x8003A9C8 0x8003AAB8 240 exact 2 frame 3 - 1 -685 0x80046CCC 0x80046DBC 240 exact 2 frame 1 - 1 -686 0x800907A4 0x80090894 240 exact 2 frame 4 - 1 -687 0x800AE268 0x800AE358 240 exact 2 frame 5 - 1 -688 0x80104630 0x80104720 240 exact 2 frame 5 - 1 -689 0x80106C04 0x80106CF4 240 exact 2 frame 0 - 1 -690 0x80028750 0x80028844 244 exact 2 frame 6 - 1 -691 0x80028CE0 0x80028DD4 244 exact 2 frame 1 - 1 -692 0x80046AD8 0x80046BCC 244 exact 2 frame 0 - 1 -693 0x8006AA88 0x8006AB7C 244 exact 2 frame 7 - 1 -694 0x8006EBA0 0x8006EC94 244 exact 2 frame 3 - 1 -695 0x80090A70 0x80090B64 244 exact 2 frame 2 - 1 -696 0x80099078 0x8009916C 244 exact 2 frame 7 - 1 -697 0x8009F5AC 0x8009F6A0 244 exact 2 frame 0 - 1 -698 0x800267CC 0x800268C4 248 exact 2 frame 6 - 1 -699 0x8002DA48 0x8002DB40 248 exact 2 frame 3 - 1 -700 0x80036134 0x8003622C 248 exact 2 frame 8 - 1 -701 0x8004345C 0x80043554 248 exact 2 frame 2 - 1 -702 0x80058AA8 0x80058BA0 248 exact 2 frame 5 - 1 -703 0x80058DEC 0x80058EE4 248 exact 2 frame 4 - 1 -704 0x8007EF84 0x8007F07C 248 exact 2 frame 1 - 1 -705 0x8009F4B4 0x8009F5AC 248 exact 2 frame 0 - 1 -706 0x8009F6A0 0x8009F798 248 exact 2 frame 0 - 1 -707 0x8009F798 0x8009F890 248 exact 2 frame 0 - 1 -708 0x8009F890 0x8009F988 248 exact 2 frame 0 - 1 -709 0x800A466C 0x800A4764 248 exact 2 frame 2 - 1 -710 0x800AFDBC 0x800AFEB4 248 exact 2 frame 2 - 1 -711 0x800F8724 0x800F881C 248 exact 2 frame 1 - 1 -712 0x800FE878 0x800FE970 248 exact 2 frame 6 - 1 -713 0x800421BC 0x800422B8 252 exact 2 frame 10 - 1 -714 0x8005DF74 0x8005E070 252 exact 2 frame 4 - 1 -715 0x8007E12C 0x8007E228 252 exact 2 frame 4 - 1 -716 0x8009D69C 0x8009D798 252 exact 2 frame 2 - 1 -717 0x800A74D0 0x800A75CC 252 exact 2 frame 1 - 1 -718 0x800FF5A8 0x800FF6A4 252 exact 2 frame 2 - 1 -719 0x80046BCC 0x80046CCC 256 exact 2 frame 1 - 1 -720 0x800911D4 0x800912D4 256 exact 2 frame 3 - 1 -721 0x800A613C 0x800A623C 256 exact 2 frame 2 - 1 -722 0x800BCA14 0x800BCB14 256 exact 2 frame 3 - 1 -723 0x800FD120 0x800FD220 256 exact 2 frame 10 - 1 -724 0x800137C8 0x800138CC 260 exact 2 frame 1 - 1 -725 0x8002F300 0x8002F404 260 exact 2 frame 1 - 1 -726 0x80031BBC 0x80031CC0 260 exact 2 frame 8 - 1 -727 0x80049FE4 0x8004A0E8 260 exact 2 frame 2 - 1 -728 0x80058CE8 0x80058DEC 260 exact 2 frame 2 - 1 -729 0x80062D10 0x80062E14 260 exact 2 frame 1 - 1 -730 0x800AFEB4 0x800AFFB8 260 exact 2 frame 3 - 1 -731 0x800FA4D4 0x800FA5D8 260 exact 2 frame 4 - 1 -732 0x80013B80 0x80013C88 264 exact 2 frame 6 - 1 -733 0x80018458 0x80018560 264 exact 2 frame 2 - 1 -734 0x800237B4 0x800238BC 264 exact 2 frame 7 - 1 -735 0x800238BC 0x800239C4 264 exact 2 frame 7 - 1 -736 0x80027ECC 0x80027FD4 264 exact 2 frame 3 - 1 -737 0x80027FD4 0x800280DC 264 exact 2 frame 3 - 1 -738 0x800281E4 0x800282EC 264 exact 2 frame 4 - 1 -739 0x800308C4 0x800309CC 264 exact 2 frame 4 - 1 -740 0x80037770 0x80037878 264 exact 2 frame 2 - 1 -741 0x80058EE4 0x80058FEC 264 exact 2 frame 7 - 1 -742 0x8005BE3C 0x8005BF44 264 exact 2 frame 4 - 1 -743 0x8006CFB0 0x8006D0B8 264 exact 2 frame 6 - 1 -744 0x800747E4 0x800748EC 264 exact 2 frame 12 - 1 -745 0x8009D798 0x8009D8A0 264 exact 2 frame 2 - 1 -746 0x800AC884 0x800AC98C 264 exact 2 frame 4 - 1 -747 0x800B6E5C 0x800B6F64 264 exact 2 frame 3 - 1 -748 0x801031C4 0x801032CC 264 exact 2 frame 2 - 1 -749 0x800139E4 0x80013AF0 268 exact 2 frame 3 - 1 -750 0x80027430 0x8002753C 268 exact 2 frame 9 - 1 -751 0x80037878 0x80037984 268 exact 2 frame 2 - 1 -752 0x8003B178 0x8003B284 268 exact 2 frame 2 - 1 -753 0x800439D8 0x80043AE4 268 exact 2 frame 5 - 1 -754 0x80057418 0x80057524 268 exact 2 frame 2 - 1 -755 0x8005E070 0x8005E17C 268 exact 2 frame 2 - 1 -756 0x8009F3A8 0x8009F4B4 268 exact 2 frame 3 - 1 -757 0x8005AD44 0x8005AE54 272 exact 2 frame 0 - 1 -758 0x800734DC 0x800735EC 272 exact 2 frame 3 - 1 -759 0x80079DDC 0x80079EEC 272 exact 2 frame 1 - 1 -760 0x800921C0 0x800922D0 272 exact 2 frame 4 - 1 -761 0x800A6E9C 0x800A6FAC 272 exact 2 frame 3 - 1 -762 0x800AA59C 0x800AA6AC 272 exact 2 frame 2 - 1 -763 0x800C5168 0x800C5278 272 exact 2 frame 1 - 1 -764 0x8002DD14 0x8002DE28 276 exact 2 frame 2 - 1 -765 0x8002F1D8 0x8002F2EC 276 exact 2 frame 3 - 1 -766 0x80031FC4 0x800320D8 276 exact 2 frame 1 - 1 -767 0x800320D8 0x800321EC 276 exact 2 frame 1 - 1 -768 0x80064858 0x8006496C 276 exact 2 frame 2 - 1 -769 0x8006BF30 0x8006C044 276 exact 2 frame 2 - 1 -770 0x8007C524 0x8007C638 276 exact 2 frame 4 - 1 -771 0x8008E2D0 0x8008E3E4 276 exact 2 frame 2 - 1 -772 0x800B1E80 0x800B1F94 276 exact 2 frame 3 - 1 -773 0x800138CC 0x800139E4 280 exact 2 frame 3 - 1 -774 0x8003A6E0 0x8003A7F8 280 exact 2 frame 3 - 1 -775 0x800910BC 0x800911D4 280 exact 2 frame 5 - 1 -776 0x8002DB40 0x8002DC5C 284 exact 2 frame 4 - 1 -777 0x800529A0 0x80052ABC 284 exact 2 frame 2 - 1 -778 0x800A4D2C 0x800A4E48 284 exact 2 frame 5 - 1 -779 0x800F4100 0x800F421C 284 exact 2 frame 2 - 1 -780 0x800F69BC 0x800F6AD8 284 exact 2 frame 4 - 1 -781 0x800F95CC 0x800F96E8 284 exact 2 frame 5 - 1 -782 0x80108168 0x80108284 284 exact 2 frame 3 - 1 -783 0x80015FC8 0x800160E8 288 exact 2 frame 7 - 1 -784 0x800289B4 0x80028AD4 288 exact 2 frame 0 - 1 -785 0x80044FA4 0x800450C4 288 exact 2 frame 1 - 1 -786 0x80045110 0x80045230 288 exact 2 frame 1 - 1 -787 0x8007C108 0x8007C228 288 exact 2 frame 5 - 1 -788 0x8008B960 0x8008BA80 288 exact 2 frame 4 - 1 -789 0x800FC8D0 0x800FC9F0 288 exact 2 frame 1 - 1 -790 0x80089E7C 0x80089FA0 292 exact 2 frame 6 - 1 -791 0x800FB7C8 0x800FB8EC 292 exact 2 frame 3 - 1 -792 0x800372A0 0x800373C8 296 exact 2 frame 1 - 1 -793 0x8005DDD0 0x8005DEF8 296 exact 2 frame 5 - 1 -794 0x80074140 0x80074268 296 exact 2 frame 7 - 1 -795 0x800ACDAC 0x800ACED4 296 exact 2 frame 0 - 1 -796 0x800B1C34 0x800B1D5C 296 exact 2 frame 1 - 1 -797 0x801009E8 0x80100B10 296 exact 2 frame 5 - 1 -798 0x80017660 0x8001778C 300 exact 2 frame 1 - 1 -799 0x800257A8 0x800258D4 300 exact 2 frame 3 - 1 -800 0x8002B924 0x8002BA50 300 exact 2 frame 1 - 1 -801 0x80046DBC 0x80046EE8 300 exact 2 frame 0 - 1 -802 0x80057CD0 0x80057DFC 300 exact 2 frame 1 - 1 -803 0x8006B4C4 0x8006B5F0 300 exact 2 frame 1 - 1 -804 0x8007C2DC 0x8007C408 300 exact 2 frame 1 - 1 -805 0x800FEED0 0x800FEFFC 300 exact 2 frame 5 - 1 -806 0x80027AB8 0x80027BE8 304 exact 2 frame 1 - 1 -807 0x800373C8 0x800374F8 304 exact 2 frame 1 - 1 -808 0x80042A90 0x80042BC0 304 exact 2 frame 4 - 1 -809 0x8005A474 0x8005A5A4 304 exact 2 frame 7 - 1 -810 0x8005A5A4 0x8005A6D4 304 exact 2 frame 10 - 1 -811 0x80072BDC 0x80072D0C 304 exact 2 frame 4 - 1 -812 0x800ADDE8 0x800ADF18 304 exact 2 frame 3 - 1 -813 0x80022A98 0x80022BCC 308 exact 2 frame 1 - 1 -814 0x80039AE4 0x80039C18 308 exact 2 frame 7 - 1 -815 0x800630F0 0x80063224 308 exact 2 frame 2 - 1 -816 0x800A66B0 0x800A67E4 308 exact 2 frame 2 - 1 -817 0x800F8CBC 0x800F8DF0 308 exact 2 frame 3 - 1 -818 0x80015B88 0x80015CC0 312 exact 2 frame 5 - 1 -819 0x800180D8 0x80018210 312 exact 2 frame 1 - 1 -820 0x800235C0 0x800236F8 312 exact 2 frame 1 - 1 -821 0x80055108 0x80055240 312 exact 2 frame 3 - 1 -822 0x800582EC 0x80058424 312 exact 2 frame 1 - 1 -823 0x8005A33C 0x8005A474 312 exact 2 frame 1 - 1 -824 0x8007B928 0x8007BA60 312 exact 2 frame 3 - 1 -825 0x8008DA0C 0x8008DB44 312 exact 2 frame 3 - 1 -826 0x800A4B70 0x800A4CA8 312 exact 2 frame 4 - 1 -827 0x800AB3CC 0x800AB504 312 exact 2 frame 0 - 1 -828 0x80102E20 0x80102F58 312 exact 2 frame 13 - 1 -829 0x80024668 0x800247A4 316 exact 2 frame 2 - 1 -830 0x8002CD94 0x8002CED0 316 exact 2 frame 4 - 1 -831 0x8003B34C 0x8003B488 316 exact 2 frame 2 - 1 -832 0x80067D34 0x80067E70 316 exact 2 frame 1 - 1 -833 0x80078E94 0x80078FD0 316 exact 2 frame 3 - 1 -834 0x800F8B80 0x800F8CBC 316 exact 2 frame 3 - 1 -835 0x80028DD4 0x80028F14 320 exact 2 frame 1 - 1 -836 0x8007A16C 0x8007A2AC 320 exact 2 frame 4 - 1 -837 0x8008D86C 0x8008D9AC 320 exact 2 frame 2 - 1 -838 0x8008F338 0x8008F478 320 exact 2 frame 7 - 1 -839 0x800BC054 0x800BC194 320 exact 2 frame 0 - 1 -840 0x80023AB0 0x80023BF4 324 exact 2 frame 4 - 1 -841 0x80024494 0x800245D8 324 exact 2 frame 2 - 1 -842 0x8002CC50 0x8002CD94 324 exact 2 frame 8 - 1 -843 0x8002CED0 0x8002D014 324 exact 2 frame 12 - 1 -844 0x80046EE8 0x8004702C 324 exact 2 frame 1 - 1 -845 0x8005E3F4 0x8005E538 324 exact 2 frame 2 - 1 -846 0x80082A68 0x80082BAC 324 exact 2 frame 1 - 1 -847 0x80082BAC 0x80082CF0 324 exact 2 frame 3 - 1 -848 0x8009F264 0x8009F3A8 324 exact 2 frame 3 - 1 -849 0x800ADB30 0x800ADC74 324 exact 2 frame 2 - 1 -850 0x800F6364 0x800F64A8 324 exact 2 frame 4 - 1 -851 0x800FCFDC 0x800FD120 324 exact 2 frame 13 - 1 -852 0x80089FA0 0x8008A0E8 328 exact 2 frame 3 - 1 -853 0x80095BB0 0x80095CF8 328 exact 2 frame 2 - 1 -854 0x800BFBAC 0x800BFCF4 328 exact 2 frame 2 - 1 -855 0x800277AC 0x800278F8 332 exact 2 frame 1 - 1 -856 0x8004388C 0x800439D8 332 exact 2 frame 0 - 1 -857 0x80085B90 0x80085CDC 332 exact 2 frame 3 - 1 -858 0x800B1A64 0x800B1BB0 332 exact 2 frame 5 - 1 -859 0x800F8DF0 0x800F8F3C 332 exact 2 frame 4 - 1 -860 0x80027178 0x800272C8 336 exact 2 frame 5 - 1 -861 0x80076778 0x800768C8 336 exact 2 frame 2 - 1 -862 0x800A8564 0x800A86B4 336 exact 2 frame 2 - 1 -863 0x800AD698 0x800AD7E8 336 exact 2 frame 2 - 1 -864 0x800AE7A0 0x800AE8F0 336 exact 2 frame 7 - 1 -865 0x800AF3E8 0x800AF538 336 exact 2 frame 6 - 1 -866 0x800C1F04 0x800C2054 336 exact 2 frame 1 - 1 -867 0x800F60A4 0x800F61F4 336 exact 2 frame 5 - 1 -868 0x800393E0 0x80039534 340 exact 2 frame 11 - 1 -869 0x80077D7C 0x80077ED0 340 exact 2 frame 3 - 1 -870 0x800304D8 0x80030630 344 exact 2 frame 1 - 1 -871 0x80045230 0x80045388 344 exact 2 frame 2 - 1 -872 0x80047190 0x800472E8 344 exact 2 frame 1 - 1 -873 0x80015A2C 0x80015B88 348 exact 2 frame 2 - 1 -874 0x8002E24C 0x8002E3A8 348 exact 2 frame 9 - 1 -875 0x8005D4C4 0x8005D620 348 exact 2 frame 0 - 1 -876 0x80079B34 0x80079C90 348 exact 2 frame 2 - 1 -877 0x800AA6AC 0x800AA808 348 exact 2 frame 5 - 1 -878 0x800B6D00 0x800B6E5C 348 exact 2 frame 1 - 1 -879 0x800FC774 0x800FC8D0 348 exact 2 frame 6 - 1 -880 0x80028AD4 0x80028C34 352 exact 2 frame 9 - 1 -881 0x8005E63C 0x8005E79C 352 exact 2 frame 7 - 1 -882 0x800704BC 0x8007061C 352 exact 2 frame 1 - 1 -883 0x800735EC 0x8007374C 352 exact 2 frame 2 - 1 -884 0x8007EBEC 0x8007ED4C 352 exact 2 frame 1 - 1 -885 0x800ABA28 0x800ABB88 352 exact 2 frame 2 - 1 -886 0x800F6F70 0x800F70D0 352 exact 2 frame 4 - 1 -887 0x800F7FD8 0x800F8138 352 exact 2 frame 3 - 1 -888 0x8004702C 0x80047190 356 exact 2 frame 1 - 1 -889 0x800556E8 0x8005584C 356 exact 2 frame 1 - 1 -890 0x800A9768 0x800A98CC 356 exact 2 frame 5 - 1 -891 0x800B5AF8 0x800B5C5C 356 exact 2 frame 1 - 1 -892 0x800272C8 0x80027430 360 exact 2 frame 10 - 1 -893 0x80033DC8 0x80033F30 360 exact 2 frame 1 - 1 -894 0x80065794 0x800658FC 360 exact 2 frame 2 - 1 -895 0x80101CDC 0x80101E44 360 exact 2 frame 11 - 1 -896 0x80106ED4 0x8010703C 360 exact 2 frame 5 - 1 -897 0x8003126C 0x800313D8 364 exact 2 frame 0 - 1 -898 0x80047DE0 0x80047F4C 364 exact 2 frame 3 - 1 -899 0x8009B638 0x8009B7A4 364 exact 2 frame 4 - 1 -900 0x80028844 0x800289B4 368 exact 2 frame 11 - 1 -901 0x8007DF34 0x8007E0A4 368 exact 2 frame 6 - 1 -902 0x80083878 0x800839E8 368 exact 2 frame 2 - 1 -903 0x8009CE58 0x8009CFC8 368 exact 2 frame 2 - 1 -904 0x80012B88 0x80012CFC 372 exact 2 frame 1 - 1 -905 0x800164EC 0x80016660 372 exact 2 frame 2 - 1 -906 0x80038BD4 0x80038D48 372 exact 2 frame 1 - 1 -907 0x8003D594 0x8003D708 372 exact 2 frame 4 - 1 -908 0x800ADC74 0x800ADDE8 372 exact 2 frame 1 - 1 -909 0x800BA8D4 0x800BAA48 372 exact 2 frame 0 - 1 -910 0x800F3E8C 0x800F4000 372 exact 2 frame 9 - 1 -911 0x8004780C 0x80047984 376 exact 2 frame 3 - 1 -912 0x8006EE44 0x8006EFBC 376 exact 2 frame 5 - 1 -913 0x800F7660 0x800F77D8 376 exact 2 frame 2 - 1 -914 0x800FFC3C 0x800FFDB4 376 exact 2 frame 3 - 1 -915 0x8002EF54 0x8002F0D0 380 exact 2 frame 2 - 1 -916 0x80034E50 0x80034FCC 380 exact 2 frame 2 - 1 -917 0x800B5924 0x800B5AA0 380 exact 2 frame 2 - 1 -918 0x800BD5E8 0x800BD764 380 exact 2 frame 4 - 1 -919 0x80038DD8 0x80038F58 384 exact 2 frame 5 - 1 -920 0x8003F010 0x8003F190 384 exact 2 frame 6 - 1 -921 0x8005D620 0x8005D7A0 384 exact 2 frame 1 - 1 -922 0x800228D8 0x80022A60 392 exact 2 frame 5 - 1 -923 0x800B1114 0x800B129C 392 exact 2 frame 3 - 1 -924 0x800374F8 0x80037684 396 exact 2 frame 3 - 1 -925 0x8008D6E0 0x8008D86C 396 exact 2 frame 8 - 1 -926 0x800BF5A8 0x800BF734 396 exact 2 frame 1 - 1 -927 0x800BFCF4 0x800BFE80 396 exact 2 frame 1 - 1 -928 0x80026A9C 0x80026C2C 400 exact 2 frame 7 - 1 -929 0x800914E4 0x80091674 400 exact 2 frame 10 - 1 -930 0x80026C7C 0x80026E10 404 exact 2 frame 7 - 1 -931 0x80029118 0x800292AC 404 exact 2 frame 0 - 1 -932 0x80046884 0x80046A18 404 exact 2 frame 3 - 1 -933 0x80073B74 0x80073D08 404 exact 2 frame 10 - 1 -934 0x80079EEC 0x8007A080 404 exact 2 frame 2 - 1 -935 0x80096364 0x800964F8 404 exact 2 frame 8 - 1 -936 0x80109338 0x801094CC 404 exact 2 frame 5 - 1 -937 0x800162B4 0x8001644C 408 exact 2 frame 4 - 1 -938 0x800309CC 0x80030B64 408 exact 2 frame 3 - 1 -939 0x8004AAF0 0x8004AC88 408 exact 2 frame 3 - 1 -940 0x800A5D24 0x800A5EBC 408 exact 2 frame 2 - 1 -941 0x800C5AEC 0x800C5C84 408 exact 2 frame 1 - 1 -942 0x800199D0 0x80019B6C 412 exact 2 frame 4 - 1 -943 0x80025FE4 0x80026180 412 exact 2 frame 1 - 1 -944 0x8006606C 0x80066208 412 exact 2 frame 7 - 1 -945 0x800FA338 0x800FA4D4 412 exact 2 frame 10 - 1 -946 0x80109010 0x801091AC 412 exact 2 frame 3 - 1 -947 0x80039168 0x80039308 416 exact 2 frame 1 - 1 -948 0x80051F50 0x800520F0 416 exact 2 frame 0 - 1 -949 0x8007F774 0x8007F914 416 exact 2 frame 1 - 1 -950 0x800A8700 0x800A88A0 416 exact 2 frame 2 - 1 -951 0x800BE828 0x800BE9C8 416 exact 2 frame 4 - 1 -952 0x80044610 0x800447B4 420 exact 2 frame 3 - 1 -953 0x8006B7C0 0x8006B964 420 exact 2 frame 16 - 1 -954 0x80041A58 0x80041C00 424 exact 2 frame 8 - 1 -955 0x800AA10C 0x800AA2B4 424 exact 2 frame 1 - 1 -956 0x801027F8 0x801029A0 424 exact 2 frame 1 - 1 -957 0x8002497C 0x80024B28 428 exact 2 frame 5 - 1 -958 0x8002AAD8 0x8002AC84 428 exact 2 frame 9 - 1 -959 0x800489D8 0x80048B84 428 exact 2 frame 3 - 1 -960 0x800FFDB4 0x800FFF60 428 exact 2 frame 4 - 1 -961 0x8004E24C 0x8004E3FC 432 exact 2 frame 2 - 1 -962 0x800B0ECC 0x800B107C 432 exact 2 frame 0 - 1 -963 0x80108284 0x80108434 432 exact 2 frame 3 - 1 -964 0x8001AC10 0x8001ADC4 436 exact 2 frame 4 - 1 -965 0x8006F77C 0x8006F930 436 exact 2 frame 2 - 1 -966 0x8008DFE8 0x8008E19C 436 exact 2 frame 5 - 1 -967 0x800AA2F8 0x800AA4AC 436 exact 2 frame 2 - 1 -968 0x800231BC 0x80023374 440 exact 2 frame 6 - 1 -969 0x8002D828 0x8002D9E0 440 exact 2 frame 1 - 1 -970 0x80080800 0x800809B8 440 exact 2 frame 5 - 1 -971 0x80081174 0x8008132C 440 exact 2 frame 8 - 1 -972 0x8009D8E0 0x8009DA98 440 exact 2 frame 1 - 1 -973 0x80025B64 0x80025D20 444 exact 2 frame 7 - 1 -974 0x800559C4 0x80055B84 448 exact 2 frame 0 - 1 -975 0x800AD7E8 0x800AD9A8 448 exact 2 frame 3 - 1 -976 0x800AE9E0 0x800AEBA0 448 exact 2 frame 7 - 1 -977 0x8010A1C8 0x8010A388 448 exact 2 frame 6 - 1 -978 0x8002ACBC 0x8002AE80 452 exact 2 frame 12 - 1 -979 0x8002FE3C 0x80030000 452 exact 2 frame 3 - 1 -980 0x800839E8 0x80083BAC 452 exact 2 frame 2 - 1 -981 0x800BBE90 0x800BC054 452 exact 2 frame 0 - 1 -982 0x80018560 0x80018728 456 exact 2 frame 1 - 1 -983 0x80068D78 0x80068F40 456 exact 2 frame 10 - 1 -984 0x8006E1B0 0x8006E378 456 exact 2 frame 3 - 1 -985 0x80077088 0x80077250 456 exact 2 frame 7 - 1 -986 0x80030630 0x800307FC 460 exact 2 frame 2 - 1 -987 0x80036DA4 0x80036F70 460 exact 2 frame 3 - 1 -988 0x80036F70 0x8003713C 460 exact 2 frame 3 - 1 -989 0x800590D8 0x800592A4 460 exact 2 frame 6 - 1 -990 0x800695D8 0x800697A4 460 exact 2 frame 4 - 1 -991 0x8008F114 0x8008F2E0 460 exact 2 frame 6 - 1 -992 0x80099E84 0x8009A050 460 exact 2 frame 1 - 1 -993 0x801095A8 0x80109774 460 exact 2 frame 4 - 1 -994 0x8002BA50 0x8002BC20 464 exact 2 frame 14 - 1 -995 0x8002E9F4 0x8002EBC4 464 exact 2 frame 6 - 1 -996 0x8003A7F8 0x8003A9C8 464 exact 2 frame 10 - 1 -997 0x800BBC1C 0x800BBDEC 464 exact 2 frame 0 - 1 -998 0x800C022C 0x800C03FC 464 exact 2 frame 3 - 1 -999 0x800F7B84 0x800F7D54 464 exact 2 frame 5 - 1 -1000 0x8002D3F4 0x8002D5C8 468 exact 2 frame 11 - 1 -1001 0x80047F4C 0x80048128 476 exact 2 frame 3 - 1 -1002 0x80052ABC 0x80052C98 476 exact 2 frame 0 - 1 -1003 0x80074394 0x80074570 476 exact 2 frame 12 - 1 -1004 0x80078FD0 0x800791AC 476 exact 2 frame 7 - 1 -1005 0x80101878 0x80101A54 476 exact 2 frame 4 - 1 -1006 0x80044D78 0x80044F58 480 exact 2 frame 11 - 1 -1007 0x8006496C 0x80064B4C 480 exact 2 frame 6 - 1 -1008 0x80064B4C 0x80064D2C 480 exact 2 frame 4 - 1 -1009 0x8006AB7C 0x8006AD5C 480 exact 2 frame 12 - 1 -1010 0x800FBBA0 0x800FBD80 480 exact 2 frame 14 - 1 -1011 0x80106CF4 0x80106ED4 480 exact 2 frame 9 - 1 -1012 0x80059DF8 0x80059FDC 484 exact 2 frame 1 - 1 -1013 0x80070270 0x80070454 484 exact 2 frame 2 - 1 -1014 0x80052424 0x8005260C 488 exact 2 frame 7 - 1 -1015 0x80069398 0x80069580 488 exact 2 frame 3 - 1 -1016 0x800FA150 0x800FA338 488 exact 2 frame 21 - 1 -1017 0x8003F7CC 0x8003F9B8 492 exact 2 frame 2 - 1 -1018 0x80065980 0x80065B6C 492 exact 2 frame 1 - 1 -1019 0x801078A4 0x80107A94 496 exact 2 frame 11 - 1 -1020 0x80024C34 0x80024E28 500 exact 2 frame 3 - 1 -1021 0x80064664 0x80064858 500 exact 2 frame 3 - 1 -1022 0x800652A0 0x80065494 500 exact 2 frame 6 - 1 -1023 0x800A4F8C 0x800A5180 500 exact 2 frame 0 - 1 -1024 0x80016BD4 0x80016DCC 504 exact 2 frame 1 - 1 -1025 0x8007ED8C 0x8007EF84 504 exact 2 frame 6 - 1 -1026 0x800C52F4 0x800C54EC 504 exact 2 frame 3 - 1 -1027 0x80030000 0x800301FC 508 exact 2 frame 10 - 1 -1028 0x80031CC0 0x80031EBC 508 exact 2 frame 7 - 1 -1029 0x80014054 0x80014258 516 exact 2 frame 6 - 1 -1030 0x800254EC 0x800256F0 516 exact 2 frame 5 - 1 -1031 0x80029C84 0x80029E88 516 exact 2 frame 2 - 1 -1032 0x8007BA60 0x8007BC64 516 exact 2 frame 4 - 1 -1033 0x8009AC28 0x8009AE2C 516 exact 2 frame 3 - 1 -1034 0x800B0BE0 0x800B0DE4 516 exact 2 frame 8 - 1 -1035 0x80067E70 0x80068078 520 exact 2 frame 5 - 1 -1036 0x800150A0 0x800152AC 524 exact 2 frame 13 - 1 -1037 0x80015DBC 0x80015FC8 524 exact 2 frame 5 - 1 -1038 0x800194A8 0x800196B4 524 exact 2 frame 2 - 1 -1039 0x80043B80 0x80043D8C 524 exact 2 frame 5 - 1 -1040 0x80098E18 0x80099024 524 exact 2 frame 13 - 1 -1041 0x80038F58 0x80039168 528 exact 2 frame 3 - 1 -1042 0x8007CFFC 0x8007D20C 528 exact 2 frame 3 - 1 -1043 0x800A6C8C 0x800A6E9C 528 exact 2 frame 11 - 1 -1044 0x80104720 0x80104930 528 exact 2 frame 2 - 1 -1045 0x8004B438 0x8004B64C 532 exact 2 frame 3 - 1 -1046 0x800697FC 0x80069A10 532 exact 2 frame 3 - 1 -1047 0x800AD484 0x800AD698 532 exact 2 frame 5 - 1 -1048 0x800295D4 0x800297F4 544 exact 2 frame 6 - 1 -1049 0x8002D608 0x8002D828 544 exact 2 frame 2 - 1 -1050 0x8009D47C 0x8009D69C 544 exact 2 frame 0 - 1 -1051 0x8009C904 0x8009CB28 548 exact 2 frame 3 - 1 -1052 0x8001778C 0x800179B8 556 exact 2 frame 4 - 1 -1053 0x80059504 0x80059730 556 exact 2 frame 4 - 1 -1054 0x80063900 0x80063B2C 556 exact 2 frame 10 - 1 -1055 0x8003C590 0x8003C7C0 560 exact 2 frame 11 - 1 -1056 0x8008A1D0 0x8008A400 560 exact 2 frame 3 - 1 -1057 0x800BF734 0x800BF968 564 exact 2 frame 5 - 1 -1058 0x800FB8EC 0x800FBB20 564 exact 2 frame 11 - 1 -1059 0x8009D244 0x8009D47C 568 exact 2 frame 3 - 1 -1060 0x800B6090 0x800B62C8 568 exact 2 frame 13 - 1 -1061 0x80029A48 0x80029C84 572 exact 2 frame 2 - 1 -1062 0x8007F07C 0x8007F2B8 572 exact 2 frame 9 - 1 -1063 0x80018728 0x8001896C 580 exact 2 frame 3 - 1 -1064 0x80041DA0 0x80041FE4 580 exact 2 frame 6 - 1 -1065 0x800BF968 0x800BFBAC 580 exact 2 frame 5 - 1 -1066 0x8009AE2C 0x8009B074 584 exact 2 frame 0 - 1 -1067 0x800B0940 0x800B0B88 584 exact 2 frame 7 - 1 -1068 0x80023374 0x800235C0 588 exact 2 frame 0 - 1 -1069 0x80062E14 0x80063060 588 exact 2 frame 8 - 1 -1070 0x800B6894 0x800B6AE0 588 exact 2 frame 7 - 1 -1071 0x80016704 0x80016954 592 exact 2 frame 4 - 1 -1072 0x800A7E68 0x800A80B8 592 exact 2 frame 3 - 1 -1073 0x800AFB6C 0x800AFDBC 592 exact 2 frame 2 - 1 -1074 0x8002C930 0x8002CB84 596 exact 2 frame 23 - 1 -1075 0x8006AE54 0x8006B0A8 596 exact 2 frame 0 - 1 -1076 0x800283F4 0x8002864C 600 exact 2 frame 5 - 1 -1077 0x8009736C 0x800975C4 600 exact 2 frame 10 - 1 -1078 0x800C4F10 0x800C5168 600 exact 2 frame 2 - 1 -1079 0x80050998 0x80050BF4 604 exact 2 frame 2 - 1 -1080 0x80065E10 0x8006606C 604 exact 2 frame 4 - 1 -1081 0x800C29D4 0x800C2C30 604 exact 2 frame 6 - 1 -1082 0x800F5E44 0x800F60A4 608 exact 2 frame 5 - 1 -1083 0x800B5CF8 0x800B5F5C 612 exact 2 frame 2 - 1 -1084 0x800BCBBC 0x800BCE20 612 exact 2 frame 0 - 1 -1085 0x8002BE6C 0x8002C0D4 616 exact 2 frame 13 - 1 -1086 0x800571AC 0x80057418 620 exact 2 frame 2 - 1 -1087 0x800B7264 0x800B74D0 620 exact 2 frame 10 - 1 -1088 0x800FD834 0x800FDAA0 620 exact 2 frame 6 - 1 -1089 0x8003F9B8 0x8003FC28 624 exact 2 frame 3 - 1 -1090 0x80069128 0x80069398 624 exact 2 frame 2 - 1 -1091 0x80073D08 0x80073F78 624 exact 2 frame 9 - 1 -1092 0x800F4E40 0x800F50B0 624 exact 2 frame 5 - 1 -1093 0x801051CC 0x8010543C 624 exact 2 frame 3 - 1 -1094 0x80043554 0x800437CC 632 exact 2 frame 9 - 1 -1095 0x80104930 0x80104BA8 632 exact 2 frame 3 - 1 -1096 0x8009CFC8 0x8009D244 636 exact 2 frame 12 - 1 -1097 0x80016954 0x80016BD4 640 exact 2 frame 0 - 1 -1098 0x80069A10 0x80069C90 640 exact 2 frame 4 - 1 -1099 0x8008FA58 0x8008FCD8 640 exact 2 frame 5 - 1 -1100 0x800A5EBC 0x800A613C 640 exact 2 frame 4 - 1 -1101 0x80106154 0x801063D4 640 exact 2 frame 9 - 1 -1102 0x80109F48 0x8010A1C8 640 exact 2 frame 11 - 1 -1103 0x8010A444 0x8010A6C4 640 exact 2 frame 2 - 1 -1104 0x800A30D4 0x800A3358 644 exact 2 frame 5 - 1 -1105 0x8002AEAC 0x8002B138 652 exact 2 frame 30 - 1 -1106 0x800FF800 0x800FFA8C 652 exact 2 frame 13 - 1 -1107 0x80036B14 0x80036DA4 656 exact 2 frame 3 - 1 -1108 0x800943E0 0x80094670 656 exact 2 frame 1 - 1 -1109 0x80072680 0x80072914 660 exact 2 frame 0 - 1 -1110 0x80072914 0x80072BA8 660 exact 2 frame 16 - 1 -1111 0x8002E528 0x8002E7C4 668 exact 2 frame 9 - 1 -1112 0x8006A6F0 0x8006A98C 668 exact 2 frame 0 - 1 -1113 0x800FACE8 0x800FAF84 668 exact 2 frame 7 - 1 -1114 0x80093768 0x80093A08 672 exact 2 frame 7 - 1 -1115 0x800519A8 0x80051C4C 676 exact 2 frame 1 - 1 -1116 0x800313D8 0x80031684 684 exact 2 frame 10 - 1 -1117 0x800526F0 0x800529A0 688 exact 2 frame 0 - 1 -1118 0x800F5B94 0x800F5E44 688 exact 2 frame 9 - 1 -1119 0x8007DC4C 0x8007DF00 692 exact 2 frame 3 - 1 -1120 0x8009916C 0x80099420 692 exact 2 frame 4 - 1 -1121 0x800501DC 0x80050494 696 exact 2 frame 5 - 1 -1122 0x800844B8 0x80084770 696 exact 2 frame 8 - 1 -1123 0x800A3600 0x800A38B8 696 exact 2 frame 2 - 1 -1124 0x800FF184 0x800FF43C 696 exact 2 frame 3 - 1 -1125 0x80103544 0x801037FC 696 exact 2 frame 1 - 1 -1126 0x8006BC74 0x8006BF30 700 exact 2 frame 1 - 1 -1127 0x800FA980 0x800FAC44 708 exact 2 frame 10 - 1 -1128 0x801063D4 0x8010669C 712 exact 2 frame 9 - 1 -1129 0x80074F1C 0x800751E8 716 exact 2 frame 8 - 1 -1130 0x8006EFBC 0x8006F28C 720 exact 2 frame 2 - 1 -1131 0x80084770 0x80084A48 728 exact 2 frame 7 - 1 -1132 0x800FA688 0x800FA960 728 exact 2 frame 9 - 1 -1133 0x8008A47C 0x8008A758 732 exact 2 frame 7 - 1 -1134 0x8006C044 0x8006C324 736 exact 2 frame 1 - 1 -1135 0x800916DC 0x800919BC 736 exact 2 frame 9 - 1 -1136 0x80091D88 0x80092068 736 exact 2 frame 7 - 1 -1137 0x800AB0EC 0x800AB3CC 736 exact 2 frame 1 - 1 -1138 0x8007AD28 0x8007B00C 740 exact 2 frame 5 - 1 -1139 0x800A47E0 0x800A4AC8 744 exact 2 frame 2 - 1 -1140 0x80033ADC 0x80033DC8 748 exact 2 frame 5 - 1 -1141 0x800BAED4 0x800BB1C4 752 exact 2 frame 4 - 1 -1142 0x80093A84 0x80093D80 764 exact 2 frame 1 - 1 -1143 0x80078B94 0x80078E94 768 exact 2 frame 6 - 1 -1144 0x80051C4C 0x80051F50 772 exact 2 frame 2 - 1 -1145 0x8009A904 0x8009AC08 772 exact 2 frame 2 - 1 -1146 0x8004C400 0x8004C708 776 exact 2 frame 0 - 1 -1147 0x80059AF0 0x80059DF8 776 exact 2 frame 9 - 1 -1148 0x8009829C 0x800985A4 776 exact 2 frame 9 - 1 -1149 0x8006D884 0x8006DB90 780 exact 2 frame 1 - 1 -1150 0x80091A7C 0x80091D88 780 exact 2 frame 12 - 1 -1151 0x800BFF20 0x800C022C 780 exact 2 frame 1 - 1 -1152 0x80013D44 0x80014054 784 exact 2 frame 10 - 1 -1153 0x8005D1B0 0x8005D4C4 788 exact 2 frame 2 - 1 -1154 0x800748EC 0x80074C00 788 exact 2 frame 21 - 1 -1155 0x80025198 0x800254B0 792 exact 2 frame 5 - 1 -1156 0x80072048 0x80072360 792 exact 2 frame 12 - 1 -1157 0x800830B4 0x800833CC 792 exact 2 frame 2 - 1 -1158 0x80094670 0x80094988 792 exact 2 frame 8 - 1 -1159 0x800FCC48 0x800FCF60 792 exact 2 frame 12 - 1 -1160 0x8002B608 0x8002B924 796 exact 2 frame 3 - 1 -1161 0x8007061C 0x80070938 796 exact 2 frame 10 - 1 -1162 0x8008355C 0x80083878 796 exact 2 frame 7 - 1 -1163 0x80072360 0x80072680 800 exact 2 frame 5 - 1 -1164 0x8006DB90 0x8006DEB4 804 exact 2 frame 3 - 1 -1165 0x800292AC 0x800295D4 808 exact 2 frame 2 - 1 -1166 0x80082CF0 0x80083018 808 exact 2 frame 9 - 1 -1167 0x8009CB28 0x8009CE58 816 exact 2 frame 6 - 1 -1168 0x801042FC 0x80104630 820 exact 2 frame 18 - 1 -1169 0x80041688 0x800419D0 840 exact 2 frame 11 - 1 -1170 0x80052CAC 0x80052FF4 840 exact 2 frame 14 - 1 -1171 0x80077250 0x8007759C 844 exact 2 frame 5 - 1 -1172 0x800C54EC 0x800C583C 848 exact 2 frame 3 - 1 -1173 0x80048684 0x800489D8 852 exact 2 frame 6 - 1 -1174 0x800A98CC 0x800A9C24 856 exact 2 frame 14 - 1 -1175 0x8006CC54 0x8006CFB0 860 exact 2 frame 4 - 1 -1176 0x80059FDC 0x8005A33C 864 exact 2 frame 4 - 1 -1177 0x80031684 0x800319F0 876 exact 2 frame 14 - 1 -1178 0x8005CA30 0x8005CDA0 880 exact 2 frame 4 - 1 -1179 0x80090D00 0x80091070 880 exact 2 frame 4 - 1 -1180 0x80040884 0x80040BFC 888 exact 2 frame 4 - 1 -1181 0x800897B8 0x80089B30 888 exact 2 frame 17 - 1 -1182 0x8003C7C0 0x8003CB3C 892 exact 2 frame 9 - 1 -1183 0x80089434 0x800897B8 900 exact 2 frame 20 - 1 -1184 0x800AC2C4 0x800AC648 900 exact 2 frame 0 - 1 -1185 0x800ABB88 0x800ABF10 904 exact 2 frame 1 - 1 -1186 0x80017200 0x8001758C 908 exact 2 frame 6 - 1 -1187 0x80048E70 0x800491FC 908 exact 2 frame 10 - 1 -1188 0x8002EBC4 0x8002EF54 912 exact 2 frame 5 - 1 -1189 0x80095820 0x80095BB0 912 exact 2 frame 10 - 1 -1190 0x80034ABC 0x80034E50 916 exact 2 frame 11 - 1 -1191 0x80064230 0x800645CC 924 exact 2 frame 13 - 1 -1192 0x80072DF4 0x80073190 924 exact 2 frame 10 - 1 -1193 0x80090408 0x800907A4 924 exact 2 frame 12 - 1 -1194 0x8004FE38 0x800501DC 932 exact 2 frame 5 - 1 -1195 0x800564AC 0x80056854 936 exact 2 frame 11 - 1 -1196 0x800ABF10 0x800AC2C4 948 exact 2 frame 4 - 1 -1197 0x80059730 0x80059AF0 960 exact 2 frame 4 - 1 -1198 0x8006F2F4 0x8006F6BC 968 exact 2 frame 1 - 1 -1199 0x8008EBFC 0x8008EFC4 968 exact 2 frame 9 - 1 -1200 0x800B7524 0x800B78EC 968 exact 2 frame 4 - 1 -1201 0x80047A14 0x80047DE0 972 exact 2 frame 9 - 1 -1202 0x80033700 0x80033ADC 988 exact 2 frame 3 - 1 -1203 0x800447B4 0x80044B90 988 exact 2 frame 12 - 1 -1204 0x80073798 0x80073B74 988 exact 2 frame 4 - 1 -1205 0x80088F38 0x80089314 988 exact 2 frame 11 - 1 -1206 0x800AAC9C 0x800AB078 988 exact 2 frame 11 - 1 -1207 0x80058608 0x800589E8 992 exact 2 frame 2 - 1 -1208 0x80071C64 0x80072048 996 exact 2 frame 15 - 1 -1209 0x8010128C 0x80101678 1004 exact 2 frame 6 - 1 -1210 0x8009B074 0x8009B464 1008 exact 2 frame 0 - 1 -1211 0x800B0550 0x800B0940 1008 exact 2 frame 11 - 1 -1212 0x80037B98 0x80037F94 1020 exact 2 frame 9 - 1 -1213 0x8007BD0C 0x8007C108 1020 exact 2 frame 10 - 1 -1214 0x800C1A58 0x800C1E54 1020 exact 2 frame 8 - 1 -1215 0x800FD278 0x800FD674 1020 exact 2 frame 10 - 1 -1216 0x80039534 0x8003993C 1032 exact 2 frame 1 - 1 -1217 0x8010669C 0x80106AA8 1036 exact 2 frame 12 - 1 -1218 0x8005CDA0 0x8005D1B0 1040 exact 2 frame 17 - 1 -1219 0x80094F54 0x80095364 1040 exact 2 frame 9 - 1 -1220 0x800331D4 0x800335E8 1044 exact 2 frame 7 - 1 -1221 0x80055240 0x80055654 1044 exact 2 frame 6 - 1 -1222 0x800868E8 0x80086CFC 1044 exact 2 frame 3 - 1 -1223 0x800A2B04 0x800A2F20 1052 exact 2 frame 7 - 1 -1224 0x800B6330 0x800B6754 1060 exact 2 frame 13 - 1 -1225 0x8003F190 0x8003F5BC 1068 exact 2 frame 2 - 1 -1226 0x80056854 0x80056C88 1076 exact 2 frame 20 - 1 -1227 0x8003879C 0x80038BD4 1080 exact 2 frame 10 - 1 -1228 0x80092460 0x80092898 1080 exact 2 frame 13 - 1 -1229 0x800AA808 0x800AAC44 1084 exact 2 frame 9 - 1 -1230 0x800B2048 0x800B2488 1088 exact 2 frame 4 - 1 -1231 0x80034638 0x80034A80 1096 exact 2 frame 7 - 1 -1232 0x8008F60C 0x8008FA58 1100 exact 2 frame 4 - 1 -1233 0x8009A4AC 0x8009A904 1112 exact 2 frame 6 - 1 -1234 0x8005A8E8 0x8005AD44 1116 exact 2 frame 15 - 1 -1235 0x8003EBAC 0x8003F010 1124 exact 2 frame 10 - 1 -1236 0x800BCE20 0x800BD298 1144 exact 2 frame 13 - 1 -1237 0x800C03FC 0x800C0874 1144 exact 2 frame 3 - 1 -1238 0x800A38B8 0x800A3D34 1148 exact 2 frame 15 - 1 -1239 0x80041190 0x80041610 1152 exact 2 frame 18 - 1 -1240 0x80063358 0x800637DC 1156 exact 2 frame 11 - 1 -1241 0x800B8958 0x800B8DE4 1164 exact 2 frame 10 - 1 -1242 0x800BAA48 0x800BAED4 1164 exact 2 frame 1 - 1 -1243 0x800C5CD4 0x800C6168 1172 exact 2 frame 10 - 1 -1244 0x800668F0 0x80066DA0 1200 exact 2 frame 15 - 1 -1245 0x800A6FAC 0x800A745C 1200 exact 2 frame 20 - 1 -1246 0x800B9C64 0x800BA114 1200 exact 2 frame 0 - 1 -1247 0x8005E8B8 0x8005ED6C 1204 exact 2 frame 26 - 1 -1248 0x800F2A50 0x800F2F08 1208 exact 2 frame 3 - 1 -1249 0x80095364 0x80095820 1212 exact 2 frame 3 - 1 -1250 0x800BC194 0x800BC658 1220 exact 2 frame 6 - 1 -1251 0x8002B138 0x8002B608 1232 exact 2 frame 36 - 1 -1252 0x8004D8A4 0x8004DD74 1232 exact 2 frame 6 - 1 -1253 0x8004DD74 0x8004E24C 1240 exact 2 frame 7 - 1 -1254 0x800F465C 0x800F4B54 1272 exact 2 frame 8 - 1 -1255 0x800F70D0 0x800F75C8 1272 exact 2 frame 8 - 1 -1256 0x80093E54 0x80094370 1308 exact 2 frame 15 - 1 -1257 0x80056C88 0x800571AC 1316 exact 2 frame 4 - 1 -1258 0x8005C508 0x8005CA30 1320 exact 2 frame 1 - 1 -1259 0x8007D718 0x8007DC40 1320 exact 2 frame 5 - 1 -1260 0x800B78EC 0x800B7E14 1320 exact 2 frame 0 - 1 -1261 0x80034FCC 0x800354F8 1324 exact 2 frame 13 - 1 -1262 0x80066208 0x80066738 1328 exact 2 frame 7 - 1 -1263 0x800C3C4C 0x800C417C 1328 exact 2 frame 10 - 1 -1264 0x8005BFD0 0x8005C508 1336 exact 2 frame 1 - 1 -1265 0x80054BC4 0x80055108 1348 exact 2 frame 4 - 1 -1266 0x80086388 0x800868E8 1376 exact 2 frame 15 - 1 -1267 0x8004ED90 0x8004F2F8 1384 exact 2 frame 11 - 1 -1268 0x800855D4 0x80085B44 1392 exact 2 frame 2 - 1 -1269 0x80064D2C 0x800652A0 1396 exact 2 frame 4 - 1 -1270 0x8007E228 0x8007E7C0 1432 exact 2 frame 3 - 1 -1271 0x8007B2A0 0x8007B83C 1436 exact 2 frame 5 - 1 -1272 0x800C14BC 0x800C1A58 1436 exact 2 frame 12 - 1 -1273 0x80095D74 0x80096324 1456 exact 2 frame 11 - 1 -1274 0x800AEC48 0x800AF1FC 1460 exact 2 frame 14 - 1 -1275 0x80094988 0x80094F54 1484 exact 2 frame 22 - 1 -1276 0x800152AC 0x8001587C 1488 exact 2 frame 19 - 1 -1277 0x8003CBE4 0x8003D224 1600 exact 2 frame 15 - 1 -1278 0x8009B7A4 0x8009BDEC 1608 exact 2 frame 11 - 1 -1279 0x80075228 0x8007587C 1620 exact 2 frame 15 - 1 -1280 0x80076110 0x80076778 1640 exact 2 frame 27 - 1 -1281 0x80099420 0x80099A94 1652 exact 2 frame 11 - 1 -1282 0x80036390 0x80036A0C 1660 exact 2 frame 9 - 1 -1283 0x8007A4FC 0x8007AB7C 1664 exact 2 frame 9 - 1 -1284 0x80085CDC 0x80086388 1708 exact 2 frame 15 - 1 -1285 0x8004CF0C 0x8004D5CC 1728 exact 2 frame 11 - 1 -1286 0x800C356C 0x800C3C4C 1760 exact 2 frame 18 - 1 -1287 0x80023DA8 0x80024494 1772 exact 2 frame 3 - 1 -1288 0x80063B2C 0x80064230 1796 exact 2 frame 17 - 1 -1289 0x80030B64 0x8003126C 1800 exact 2 frame 7 - 1 -1290 0x80033F30 0x80034638 1800 exact 2 frame 0 - 1 -1291 0x80100B2C 0x80101244 1816 exact 2 frame 13 - 1 -1292 0x8006FB44 0x80070270 1836 exact 2 frame 24 - 1 -1293 0x800BB2AC 0x800BB9FC 1872 exact 2 frame 5 - 1 -1294 0x80037F94 0x8003870C 1912 exact 2 frame 25 - 1 -1295 0x80043E98 0x80044610 1912 exact 2 frame 12 - 1 -1296 0x8009E95C 0x8009F0E8 1932 exact 2 frame 10 - 1 -1297 0x800A3D34 0x800A44CC 1944 exact 2 frame 10 - 1 -1298 0x8004AC88 0x8004B438 1968 exact 2 frame 18 - 1 -1299 0x800A8F18 0x800A96CC 1972 exact 2 frame 8 - 1 -1300 0x800809B8 0x80081174 1980 exact 2 frame 17 - 1 -1301 0x800BA114 0x800BA8D4 1984 exact 2 frame 1 - 1 -1302 0x800B129C 0x800B1A64 1992 exact 2 frame 4 - 1 -1303 0x8005AE54 0x8005B638 2020 exact 2 frame 15 - 1 -1304 0x80092B2C 0x80093330 2052 exact 2 frame 16 - 1 -1305 0x8008E3E4 0x8008EBFC 2072 exact 2 frame 6 - 1 -1306 0x8007C7CC 0x8007CFFC 2096 exact 2 frame 10 - 1 -1307 0x80083C78 0x800844B8 2112 exact 2 frame 15 - 1 -1308 0x800C417C 0x800C49BC 2112 exact 2 frame 6 - 1 -1309 0x800985A4 0x80098E18 2164 exact 2 frame 49 - 1 -1310 0x8004A278 0x8004AAF0 2168 exact 2 frame 12 - 1 -1311 0x800713D0 0x80071C64 2196 exact 2 frame 12 - 1 -1312 0x8007587C 0x80076110 2196 exact 2 frame 33 - 1 -1313 0x8002203C 0x800228D8 2204 exact 2 frame 4 - 1 -1314 0x80050D48 0x80051628 2272 exact 2 frame 15 - 1 -1315 0x80053064 0x80053954 2288 exact 2 frame 12 - 1 -1316 0x80101EB0 0x801027CC 2332 exact 2 frame 12 - 1 -1317 0x80055B84 0x800564AC 2344 exact 2 frame 17 - 1 -1318 0x8001CE70 0x8001D7A0 2352 exact 2 frame 14 - 1 -1319 0x8006C324 0x8006CC54 2352 exact 2 frame 19 - 1 -1320 0x8008CCC0 0x8008D5F8 2360 exact 2 frame 11 - 1 -1321 0x800357D4 0x80036134 2400 exact 2 frame 21 - 1 -1322 0x800C2054 0x800C29D4 2432 exact 2 frame 17 - 1 -1323 0x80069C90 0x8006A654 2500 exact 2 frame 13 - 1 -1324 0x800A5228 0x800A5C1C 2548 exact 2 frame 23 - 1 -1325 0x8004F2F8 0x8004FE38 2880 exact 2 frame 21 - 1 -1326 0x800B7E14 0x800B8958 2884 exact 2 frame 5 - 1 -1327 0x800BEA28 0x800BF5A8 2944 exact 2 frame 16 - 1 -1328 0x8003FD00 0x80040884 2948 exact 2 frame 26 - 1 -1329 0x800975C4 0x8009829C 3288 exact 2 frame 71 - 1 -1330 0x800142F4 0x80014FE8 3316 exact 2 frame 38 - 1 -1331 0x800B8E60 0x800B9C64 3588 exact 2 frame 8 - 1 -1332 0x8009DA98 0x8009E8D0 3640 exact 2 frame 21 - 1 -1333 0x800964F8 0x8009736C 3700 exact 2 frame 32 - 1 -1334 0x80019C10 0x8001AA9C 3724 exact 2 frame 16 - 1 -1335 0x80066E58 0x80067D34 3804 exact 2 frame 39 - 1 -1336 0x800BD764 0x800BE6D8 3956 exact 2 frame 27 - 1 -1337 0x80053954 0x80054AF8 4516 exact 2 frame 32 - 1 -1338 0x80011508 0x80012780 4728 exact 2 frame 20 - 1 -1339 0x8008132C 0x80082750 5156 exact 2 frame 34 - 1 -1340 0x80086DFC 0x80088F38 8508 exact 2 frame 38 - 1 -1341 0x8009F988 0x800A2684 11516 exact 2 frame 102 - 1 -1342 0x80180808 0x8018080C 4 fallthrough 3 leaf 0 - 1 -1343 0x801007E0 0x80100808 40 fallthrough 3 frame 1 - 1 +193 0x80086DBC 0x80086DFC 64 exact 2 frame 1 - 1 +194 0x8001590C 0x80015950 68 exact 2 frame 1 - 1 +195 0x80048350 0x80048394 68 exact 2 frame 2 - 1 +196 0x80012918 0x80012960 72 exact 2 frame 1 - 1 +197 0x80017B50 0x80017B98 72 exact 2 frame 1 - 1 +198 0x80017DF0 0x80017E38 72 exact 2 frame 0 - 1 +199 0x8002E9AC 0x8002E9F4 72 exact 2 frame 2 - 1 +200 0x8006B184 0x8006B1CC 72 exact 2 frame 1 - 1 +201 0x80070454 0x8007049C 72 exact 2 frame 1 - 1 +202 0x8007759C 0x800775E4 72 exact 2 frame 1 - 1 +203 0x800BBAC8 0x800BBB10 72 exact 2 frame 1 - 1 +204 0x800196B4 0x80019700 76 exact 2 frame 1 - 1 +205 0x8003D310 0x8003D35C 76 exact 2 frame 1 - 1 +206 0x800AC648 0x800AC694 76 exact 2 frame 2 - 1 +207 0x800AC98C 0x800AC9D8 76 exact 2 frame 1 - 1 +208 0x800B6CB4 0x800B6D00 76 exact 2 frame 1 - 1 +209 0x800FFFEC 0x80100038 76 exact 2 frame 1 - 1 +210 0x8010806C 0x801080B8 76 exact 2 frame 1 - 1 +211 0x80029E88 0x80029ED8 80 exact 2 frame 2 - 1 +212 0x80046198 0x800461E8 80 exact 2 frame 1 - 1 +213 0x8007D5AC 0x8007D5FC 80 exact 2 frame 1 - 1 +214 0x800AFACC 0x800AFB1C 80 exact 2 frame 1 - 1 +215 0x800FFBEC 0x800FFC3C 80 exact 2 frame 2 - 1 +216 0x80018210 0x80018264 84 exact 2 frame 2 - 1 +217 0x8006ADB0 0x8006AE04 84 exact 2 frame 1 - 1 +218 0x8006B2D4 0x8006B328 84 exact 2 frame 1 - 1 +219 0x80091490 0x800914E4 84 exact 2 frame 1 - 1 +220 0x800AE66C 0x800AE6C0 84 exact 2 frame 1 - 1 +221 0x800FE970 0x800FE9C4 84 exact 2 frame 1 - 1 +222 0x80017AF8 0x80017B50 88 exact 2 frame 1 - 1 +223 0x80025E54 0x80025EAC 88 exact 2 frame 2 - 1 +224 0x80026650 0x800266A8 88 exact 2 frame 1 - 1 +225 0x8003022C 0x80030284 88 exact 2 frame 1 - 1 +226 0x80030284 0x800302DC 88 exact 2 frame 1 - 1 +227 0x800319F0 0x80031A48 88 exact 2 frame 1 - 1 +228 0x80043404 0x8004345C 88 exact 2 frame 1 - 1 +229 0x8005E538 0x8005E590 88 exact 2 frame 2 - 1 +230 0x80069580 0x800695D8 88 exact 2 frame 2 - 1 +231 0x80099D14 0x80099D6C 88 exact 2 frame 1 - 1 +232 0x800A6C34 0x800A6C8C 88 exact 2 frame 2 - 1 +233 0x800F66B8 0x800F6710 88 exact 2 frame 1 - 1 +234 0x80024838 0x80024894 92 exact 2 frame 2 - 1 +235 0x80027C44 0x80027CA0 92 exact 2 frame 1 - 1 +236 0x800307FC 0x80030858 92 exact 2 frame 3 - 1 +237 0x8006B214 0x8006B270 92 exact 2 frame 1 - 1 +238 0x8006B9E0 0x8006BA3C 92 exact 2 frame 2 - 1 +239 0x80093A08 0x80093A64 92 exact 2 frame 2 - 1 +240 0x800B255C 0x800B25B8 92 exact 2 frame 3 - 1 +241 0x800F44D0 0x800F452C 92 exact 2 frame 2 - 1 +242 0x8010A8D8 0x8010A934 92 exact 2 frame 0 - 1 +243 0x80027CA0 0x80027D00 96 exact 2 frame 1 - 1 +244 0x8004C000 0x8004C060 96 exact 2 frame 1 - 1 +245 0x80057564 0x800575C4 96 exact 2 frame 2 - 1 +246 0x8007E7FC 0x8007E85C 96 exact 2 frame 2 - 1 +247 0x8008D9AC 0x8008DA0C 96 exact 2 frame 2 - 1 +248 0x800F42AC 0x800F430C 96 exact 2 frame 2 - 1 +249 0x801029A0 0x80102A00 96 exact 2 frame 1 - 1 +250 0x80023080 0x800230E4 100 exact 2 frame 3 - 1 +251 0x80023A4C 0x80023AB0 100 exact 2 frame 3 - 1 +252 0x8004857C 0x800485E0 100 exact 2 frame 3 - 1 +253 0x8006B270 0x8006B2D4 100 exact 2 frame 1 - 1 +254 0x8008FFC4 0x80090028 100 exact 2 frame 3 - 1 +255 0x800A8920 0x800A8984 100 exact 2 frame 2 - 1 +256 0x800B2488 0x800B24EC 100 exact 2 frame 0 - 1 +257 0x800B6754 0x800B67B8 100 exact 2 frame 0 - 1 +258 0x800BC960 0x800BC9C4 100 exact 2 frame 2 - 1 +259 0x800F2F08 0x800F2F6C 100 exact 2 frame 1 - 1 +260 0x80012960 0x800129C8 104 exact 2 frame 2 - 1 +261 0x800256F0 0x80025758 104 exact 2 frame 2 - 1 +262 0x8005E17C 0x8005E1E4 104 exact 2 frame 1 - 1 +263 0x8006F28C 0x8006F2F4 104 exact 2 frame 1 - 1 +264 0x8007432C 0x80074394 104 exact 2 frame 0 - 1 +265 0x8008A758 0x8008A7C0 104 exact 2 frame 2 - 1 +266 0x80091674 0x800916DC 104 exact 2 frame 3 - 1 +267 0x800A6B38 0x800A6BA0 104 exact 2 frame 1 - 1 +268 0x800B0E64 0x800B0ECC 104 exact 2 frame 4 - 1 +269 0x800B62C8 0x800B6330 104 exact 2 frame 2 - 1 +270 0x800F4098 0x800F4100 104 exact 2 frame 2 - 1 +271 0x800F6AD8 0x800F6B40 104 exact 2 frame 1 - 1 +272 0x800FAF84 0x800FAFEC 104 exact 2 frame 4 - 1 +273 0x800FB54C 0x800FB5B4 104 exact 2 frame 1 - 1 +274 0x80100038 0x801000A0 104 exact 2 frame 2 - 1 +275 0x801059E8 0x80105A50 104 exact 2 frame 1 - 1 +276 0x80015D50 0x80015DBC 108 exact 2 frame 2 - 1 +277 0x800183EC 0x80018458 108 exact 2 frame 0 - 1 +278 0x80026274 0x800262E0 108 exact 2 frame 1 - 1 +279 0x80030858 0x800308C4 108 exact 2 frame 1 - 1 +280 0x80055958 0x800559C4 108 exact 2 frame 1 - 1 +281 0x80072D0C 0x80072D78 108 exact 2 frame 0 - 1 +282 0x8007F9B0 0x8007FA1C 108 exact 2 frame 1 - 1 +283 0x800909D8 0x80090A44 108 exact 2 frame 1 - 1 +284 0x800AA0A0 0x800AA10C 108 exact 2 frame 1 - 1 +285 0x800ACAC8 0x800ACB34 108 exact 2 frame 4 - 1 +286 0x800AE4DC 0x800AE548 108 exact 2 frame 3 - 1 +287 0x80031EBC 0x80031F2C 112 exact 2 frame 1 - 1 +288 0x8005584C 0x800558BC 112 exact 2 frame 1 - 1 +289 0x8006B328 0x8006B398 112 exact 2 frame 1 - 1 +290 0x800784F4 0x80078564 112 exact 2 frame 0 - 1 +291 0x800922D0 0x80092340 112 exact 2 frame 2 - 1 +292 0x800B6AE0 0x800B6B50 112 exact 2 frame 1 - 1 +293 0x800F452C 0x800F459C 112 exact 2 frame 2 - 1 +294 0x800FB410 0x800FB480 112 exact 2 frame 1 - 1 +295 0x800FB758 0x800FB7C8 112 exact 2 frame 4 - 1 +296 0x80013C90 0x80013D04 116 exact 2 frame 2 - 1 +297 0x80014258 0x800142CC 116 exact 2 frame 3 - 1 +298 0x800280DC 0x80028150 116 exact 2 frame 2 - 1 +299 0x8002FDC8 0x8002FE3C 116 exact 2 frame 1 - 1 +300 0x800475CC 0x80047640 116 exact 2 frame 0 - 1 +301 0x800833CC 0x80083440 116 exact 2 frame 1 - 1 +302 0x8009141C 0x80091490 116 exact 2 frame 1 - 1 +303 0x800A4CA8 0x800A4D1C 116 exact 2 frame 0 - 1 +304 0x800B1D5C 0x800B1DD0 116 exact 2 frame 1 - 1 +305 0x800F6948 0x800F69BC 116 exact 2 frame 5 - 1 +306 0x800F9014 0x800F9088 116 exact 2 frame 1 - 1 +307 0x80021C64 0x80021CDC 120 exact 2 frame 4 - 1 +308 0x800275CC 0x80027644 120 exact 2 frame 2 - 1 +309 0x800454C8 0x80045540 120 exact 2 frame 1 - 1 +310 0x80045FD8 0x80046050 120 exact 2 frame 3 - 1 +311 0x800472E8 0x80047360 120 exact 2 frame 2 - 1 +312 0x80048DA8 0x80048E20 120 exact 2 frame 1 - 1 +313 0x80050CA8 0x80050D20 120 exact 2 frame 1 - 1 +314 0x80057E04 0x80057E7C 120 exact 2 frame 0 - 1 +315 0x800801B4 0x8008022C 120 exact 2 frame 2 - 1 +316 0x8008E258 0x8008E2D0 120 exact 2 frame 1 - 1 +317 0x800AA4F4 0x800AA56C 120 exact 2 frame 2 - 1 +318 0x800C110C 0x800C1184 120 exact 2 frame 1 - 1 +319 0x80103144 0x801031BC 120 exact 2 frame 1 - 1 +320 0x8001896C 0x800189E8 124 exact 2 frame 2 - 1 +321 0x8001AAA8 0x8001AB24 124 exact 2 frame 1 - 1 +322 0x80029054 0x800290D0 124 exact 2 frame 1 - 1 +323 0x8002D17C 0x8002D1F8 124 exact 2 frame 2 - 1 +324 0x8002E44C 0x8002E4C8 124 exact 2 frame 2 - 1 +325 0x8002E870 0x8002E8EC 124 exact 2 frame 3 - 1 +326 0x8002E8EC 0x8002E968 124 exact 2 frame 0 - 1 +327 0x8002FCD0 0x8002FD4C 124 exact 2 frame 3 - 1 +328 0x8002FD4C 0x8002FDC8 124 exact 2 frame 3 - 1 +329 0x800302DC 0x80030358 124 exact 2 frame 1 - 1 +330 0x8003870C 0x80038788 124 exact 2 frame 4 - 1 +331 0x80057F08 0x80057F84 124 exact 2 frame 1 - 1 +332 0x8006B5F0 0x8006B66C 124 exact 2 frame 2 - 1 +333 0x8006B964 0x8006B9E0 124 exact 2 frame 3 - 1 +334 0x8006BB0C 0x8006BB88 124 exact 2 frame 1 - 1 +335 0x8006D148 0x8006D1C4 124 exact 2 frame 1 - 1 +336 0x80072D78 0x80072DF4 124 exact 2 frame 1 - 1 +337 0x8008A400 0x8008A47C 124 exact 2 frame 0 - 1 +338 0x80095CF8 0x80095D74 124 exact 2 frame 1 - 1 +339 0x800A4764 0x800A47E0 124 exact 2 frame 0 - 1 +340 0x800A84E8 0x800A8564 124 exact 2 frame 2 - 1 +341 0x800B8DE4 0x800B8E60 124 exact 2 frame 3 - 1 +342 0x800C5278 0x800C52F4 124 exact 2 frame 1 - 1 +343 0x800F6638 0x800F66B4 124 exact 2 frame 1 - 1 +344 0x80107E90 0x80107F0C 124 exact 2 frame 0 - 1 +345 0x80026E94 0x80026F14 128 exact 2 frame 1 - 1 +346 0x800A6998 0x800A6A18 128 exact 2 frame 4 - 1 +347 0x800A80B8 0x800A8138 128 exact 2 frame 0 - 1 +348 0x800A88A0 0x800A8920 128 exact 2 frame 1 - 1 +349 0x800B67B8 0x800B6838 128 exact 2 frame 1 - 1 +350 0x800F4B88 0x800F4C08 128 exact 2 frame 2 - 1 +351 0x800F521C 0x800F529C 128 exact 2 frame 0 - 1 +352 0x800F6DD0 0x800F6E50 128 exact 2 frame 2 - 1 +353 0x800F6E50 0x800F6ED0 128 exact 2 frame 2 - 1 +354 0x800FB6D8 0x800FB758 128 exact 2 frame 4 - 1 +355 0x800FBB20 0x800FBBA0 128 exact 2 frame 5 - 1 +356 0x801000A0 0x80100120 128 exact 2 frame 1 - 1 +357 0x80102A00 0x80102A80 128 exact 2 frame 6 - 1 +358 0x80107DE8 0x80107E68 128 exact 2 frame 1 - 1 +359 0x8001703C 0x800170C0 132 exact 2 frame 1 - 1 +360 0x80026E10 0x80026E94 132 exact 2 frame 2 - 1 +361 0x80042138 0x800421BC 132 exact 2 frame 4 - 1 +362 0x8005E79C 0x8005E820 132 exact 2 frame 3 - 1 +363 0x8007D5FC 0x8007D680 132 exact 2 frame 2 - 1 +364 0x800A8464 0x800A84E8 132 exact 2 frame 0 - 1 +365 0x800A9EF8 0x800A9F7C 132 exact 2 frame 1 - 1 +366 0x800AE458 0x800AE4DC 132 exact 2 frame 3 - 1 +367 0x800B1BB0 0x800B1C34 132 exact 2 frame 1 - 1 +368 0x800C3490 0x800C3514 132 exact 2 frame 0 - 1 +369 0x800FA5D8 0x800FA65C 132 exact 2 frame 4 - 1 +370 0x80102A80 0x80102B04 132 exact 2 frame 1 - 1 +371 0x80105148 0x801051CC 132 exact 2 frame 3 - 1 +372 0x8010A6C4 0x8010A748 132 exact 2 frame 4 - 1 +373 0x800239C4 0x80023A4C 136 exact 2 frame 2 - 1 +374 0x80025ADC 0x80025B64 136 exact 2 frame 1 - 1 +375 0x800268F4 0x8002697C 136 exact 2 frame 5 - 1 +376 0x8003FC78 0x8003FD00 136 exact 2 frame 2 - 1 +377 0x80073284 0x8007330C 136 exact 2 frame 1 - 1 +378 0x8007E0A4 0x8007E12C 136 exact 2 frame 2 - 1 +379 0x800A6294 0x800A631C 136 exact 2 frame 6 - 1 +380 0x800ADF18 0x800ADFA0 136 exact 2 frame 1 - 1 +381 0x80108740 0x801087C8 136 exact 2 frame 2 - 1 +382 0x80048180 0x8004820C 140 exact 2 frame 1 - 1 +383 0x80057E7C 0x80057F08 140 exact 2 frame 1 - 1 +384 0x8005BF44 0x8005BFD0 140 exact 2 frame 1 - 1 +385 0x8006D1C4 0x8006D250 140 exact 2 frame 1 - 1 +386 0x80089DE8 0x80089E74 140 exact 2 frame 1 - 1 +387 0x800B6B50 0x800B6BDC 140 exact 2 frame 1 - 1 +388 0x800C0BFC 0x800C0C88 140 exact 2 frame 1 - 1 +389 0x800FFF60 0x800FFFEC 140 exact 2 frame 3 - 1 +390 0x80107458 0x801074E4 140 exact 2 frame 1 - 1 +391 0x80013AF0 0x80013B80 144 exact 2 frame 3 - 1 +392 0x8001587C 0x8001590C 144 exact 2 frame 3 - 1 +393 0x80015CC0 0x80015D50 144 exact 2 frame 1 - 1 +394 0x8001758C 0x8001761C 144 exact 2 frame 1 - 1 +395 0x800182F4 0x80018384 144 exact 2 frame 1 - 1 +396 0x80025DC4 0x80025E54 144 exact 2 frame 2 - 1 +397 0x8002D364 0x8002D3F4 144 exact 2 frame 7 - 1 +398 0x80036278 0x80036308 144 exact 2 frame 2 - 1 +399 0x80038D48 0x80038DD8 144 exact 2 frame 0 - 1 +400 0x800461E8 0x80046278 144 exact 2 frame 1 - 1 +401 0x80047984 0x80047A14 144 exact 2 frame 1 - 1 +402 0x8005E340 0x8005E3D0 144 exact 2 frame 2 - 1 +403 0x80063060 0x800630F0 144 exact 2 frame 2 - 1 +404 0x80063870 0x80063900 144 exact 2 frame 3 - 1 +405 0x80065670 0x80065700 144 exact 2 frame 3 - 1 +406 0x800829D8 0x80082A68 144 exact 2 frame 0 - 1 +407 0x800AD1C8 0x800AD258 144 exact 2 frame 0 - 1 +408 0x800F421C 0x800F42AC 144 exact 2 frame 2 - 1 +409 0x800F897C 0x800F8A0C 144 exact 2 frame 2 - 1 +410 0x801001C4 0x80100254 144 exact 2 frame 1 - 1 +411 0x80100508 0x80100598 144 exact 2 frame 3 - 1 +412 0x80104BA8 0x80104C38 144 exact 2 frame 1 - 1 +413 0x800247A4 0x80024838 148 exact 2 frame 1 - 1 +414 0x8003AB20 0x8003ABB4 148 exact 2 frame 1 - 1 +415 0x8004331C 0x800433B0 148 exact 2 frame 0 - 1 +416 0x80051914 0x800519A8 148 exact 2 frame 1 - 1 +417 0x800637DC 0x80063870 148 exact 2 frame 2 - 1 +418 0x80079C90 0x80079D24 148 exact 2 frame 0 - 1 +419 0x8007A080 0x8007A114 148 exact 2 frame 1 - 1 +420 0x80089D54 0x80089DE8 148 exact 2 frame 1 - 1 +421 0x800A9CC4 0x800A9D58 148 exact 2 frame 4 - 1 +422 0x800AB504 0x800AB598 148 exact 2 frame 2 - 1 +423 0x800BC658 0x800BC6EC 148 exact 2 frame 4 - 1 +424 0x800FB480 0x800FB514 148 exact 2 frame 0 - 1 +425 0x801003A4 0x80100438 148 exact 2 frame 4 - 1 +426 0x80026A04 0x80026A9C 152 exact 2 frame 3 - 1 +427 0x8002BCE8 0x8002BD80 152 exact 2 frame 3 - 1 +428 0x8004A1E0 0x8004A278 152 exact 2 frame 1 - 1 +429 0x8005E820 0x8005E8B8 152 exact 2 frame 3 - 1 +430 0x800645CC 0x80064664 152 exact 2 frame 3 - 1 +431 0x8007D680 0x8007D718 152 exact 2 frame 1 - 1 +432 0x800B107C 0x800B1114 152 exact 2 frame 2 - 1 +433 0x800BBDF8 0x800BBE90 152 exact 2 frame 0 - 1 +434 0x800C1424 0x800C14BC 152 exact 2 frame 2 - 1 +435 0x800F4000 0x800F4098 152 exact 2 frame 3 - 1 +436 0x800F77D8 0x800F7870 152 exact 2 frame 3 - 1 +437 0x800F9094 0x800F912C 152 exact 2 frame 2 - 1 +438 0x80103094 0x8010312C 152 exact 2 frame 1 - 1 +439 0x80012DE8 0x80012E84 156 exact 2 frame 1 - 1 +440 0x80016F80 0x8001701C 156 exact 2 frame 1 - 1 +441 0x8002C7EC 0x8002C888 156 exact 2 frame 7 - 1 +442 0x8002FAB8 0x8002FB54 156 exact 2 frame 1 - 1 +443 0x80043AE4 0x80043B80 156 exact 2 frame 1 - 1 +444 0x80048B84 0x80048C20 156 exact 2 frame 2 - 1 +445 0x800491FC 0x80049298 156 exact 2 frame 3 - 1 +446 0x800558BC 0x80055958 156 exact 2 frame 1 - 1 +447 0x8006A654 0x8006A6F0 156 exact 2 frame 2 - 1 +448 0x80083018 0x800830B4 156 exact 2 frame 1 - 1 +449 0x800BC8C4 0x800BC960 156 exact 2 frame 4 - 1 +450 0x80012E84 0x80012F24 160 exact 2 frame 3 - 1 +451 0x8001644C 0x800164EC 160 exact 2 frame 3 - 1 +452 0x8001CDA0 0x8001CE40 160 exact 2 frame 1 - 1 +453 0x8002311C 0x800231BC 160 exact 2 frame 4 - 1 +454 0x800575C4 0x80057664 160 exact 2 frame 2 - 1 +455 0x80058190 0x80058230 160 exact 2 frame 1 - 1 +456 0x8007C408 0x8007C4A8 160 exact 2 frame 1 - 1 +457 0x80089C74 0x80089D14 160 exact 2 frame 1 - 1 +458 0x800A9C24 0x800A9CC4 160 exact 2 frame 4 - 1 +459 0x800B5FF0 0x800B6090 160 exact 2 frame 2 - 1 +460 0x800FF0E4 0x800FF184 160 exact 2 frame 2 - 1 +461 0x80012F80 0x80013024 164 exact 2 frame 1 - 1 +462 0x80016660 0x80016704 164 exact 2 frame 0 - 1 +463 0x80025D20 0x80025DC4 164 exact 2 frame 2 - 1 +464 0x800270D4 0x80027178 164 exact 2 frame 2 - 1 +465 0x8002DF84 0x8002E028 164 exact 2 frame 1 - 1 +466 0x80031B18 0x80031BBC 164 exact 2 frame 1 - 1 +467 0x80041FE4 0x80042088 164 exact 2 frame 4 - 1 +468 0x800516FC 0x800517A0 164 exact 2 frame 1 - 1 +469 0x8005E29C 0x8005E340 164 exact 2 frame 3 - 1 +470 0x80066738 0x800667DC 164 exact 2 frame 1 - 1 +471 0x8007D20C 0x8007D2B0 164 exact 2 frame 1 - 1 +472 0x800827C4 0x80082868 164 exact 2 frame 2 - 1 +473 0x800C2CE4 0x800C2D88 164 exact 2 frame 1 - 1 +474 0x800F6898 0x800F693C 164 exact 2 frame 4 - 1 +475 0x800FAC44 0x800FACE8 164 exact 2 frame 1 - 1 +476 0x80100120 0x801001C4 164 exact 2 frame 1 - 1 +477 0x80022E78 0x80022F20 168 exact 2 frame 1 - 1 +478 0x80032258 0x80032300 168 exact 2 frame 1 - 1 +479 0x800592A4 0x8005934C 168 exact 2 frame 2 - 1 +480 0x8007BC64 0x8007BD0C 168 exact 2 frame 1 - 1 +481 0x800A3358 0x800A3400 168 exact 2 frame 1 - 1 +482 0x800A4AC8 0x800A4B70 168 exact 2 frame 3 - 1 +483 0x800A5180 0x800A5228 168 exact 2 frame 1 - 1 +484 0x800A8B8C 0x800A8C34 168 exact 2 frame 1 - 1 +485 0x800BE6D8 0x800BE780 168 exact 2 frame 0 - 1 +486 0x800BE780 0x800BE828 168 exact 2 frame 0 - 1 +487 0x800FF758 0x800FF800 168 exact 2 frame 1 - 1 +488 0x80028C34 0x80028CE0 172 exact 2 frame 1 - 1 +489 0x8005E590 0x8005E63C 172 exact 2 frame 6 - 1 +490 0x8006D250 0x8006D2FC 172 exact 2 frame 1 - 1 +491 0x8007B00C 0x8007B0B8 172 exact 2 frame 1 - 1 +492 0x80082868 0x80082914 172 exact 2 frame 5 - 1 +493 0x800908E4 0x80090990 172 exact 2 frame 4 - 1 +494 0x80091370 0x8009141C 172 exact 2 frame 2 - 1 +495 0x800A5C1C 0x800A5CC8 172 exact 2 frame 0 - 1 +496 0x800A64C8 0x800A6574 172 exact 2 frame 1 - 1 +497 0x800A8224 0x800A82D0 172 exact 2 frame 3 - 1 +498 0x800F4424 0x800F44D0 172 exact 2 frame 2 - 1 +499 0x80016E68 0x80016F18 176 exact 2 frame 2 - 1 +500 0x80017C6C 0x80017D1C 176 exact 2 frame 2 - 1 +501 0x800250AC 0x8002515C 176 exact 2 frame 3 - 1 +502 0x80025A2C 0x80025ADC 176 exact 2 frame 1 - 1 +503 0x80027E1C 0x80027ECC 176 exact 2 frame 3 - 1 +504 0x80028344 0x800283F4 176 exact 2 frame 2 - 1 +505 0x80046348 0x800463F8 176 exact 2 frame 1 - 1 +506 0x80074734 0x800747E4 176 exact 2 frame 4 - 1 +507 0x80089338 0x800893E8 176 exact 2 frame 2 - 1 +508 0x800AD3D4 0x800AD484 176 exact 2 frame 0 - 1 +509 0x800B1DD0 0x800B1E80 176 exact 2 frame 2 - 1 +510 0x800C2D88 0x800C2E38 176 exact 2 frame 1 - 1 +511 0x801080B8 0x80108168 176 exact 2 frame 4 - 1 +512 0x801085E0 0x80108690 176 exact 2 frame 1 - 1 +513 0x80021CDC 0x80021D90 180 exact 2 frame 4 - 1 +514 0x8002E198 0x8002E24C 180 exact 2 frame 6 - 1 +515 0x80050BF4 0x80050CA8 180 exact 2 frame 2 - 1 +516 0x8006D2FC 0x8006D3B0 180 exact 2 frame 1 - 1 +517 0x800A631C 0x800A63D0 180 exact 2 frame 3 - 1 +518 0x800A6880 0x800A6934 180 exact 2 frame 3 - 1 +519 0x800B1F94 0x800B2048 180 exact 2 frame 4 - 1 +520 0x800C2C30 0x800C2CE4 180 exact 2 frame 2 - 1 +521 0x80014FE8 0x800150A0 184 exact 2 frame 9 - 1 +522 0x80019808 0x800198C0 184 exact 2 frame 1 - 1 +523 0x80021E6C 0x80021F24 184 exact 2 frame 3 - 1 +524 0x80023BF4 0x80023CAC 184 exact 2 frame 2 - 1 +525 0x80028698 0x80028750 184 exact 2 frame 4 - 1 +526 0x8005A6D4 0x8005A78C 184 exact 2 frame 7 - 1 +527 0x8005E1E4 0x8005E29C 184 exact 2 frame 2 - 1 +528 0x80079D24 0x80079DDC 184 exact 2 frame 0 - 1 +529 0x8007AB7C 0x8007AC34 184 exact 2 frame 1 - 1 +530 0x800ACA10 0x800ACAC8 184 exact 2 frame 4 - 1 +531 0x800F436C 0x800F4424 184 exact 2 frame 2 - 1 +532 0x800FED84 0x800FEE3C 184 exact 2 frame 5 - 1 +533 0x80108434 0x801084EC 184 exact 2 frame 1 - 1 +534 0x80021BA8 0x80021C64 188 exact 2 frame 2 - 1 +535 0x800236F8 0x800237B4 188 exact 2 frame 7 - 1 +536 0x80045F1C 0x80045FD8 188 exact 2 frame 3 - 1 +537 0x80050548 0x80050604 188 exact 2 frame 1 - 1 +538 0x800506E4 0x800507A0 188 exact 2 frame 1 - 1 +539 0x800507A0 0x8005085C 188 exact 2 frame 1 - 1 +540 0x8006B6BC 0x8006B778 188 exact 2 frame 3 - 1 +541 0x8008E19C 0x8008E258 188 exact 2 frame 2 - 1 +542 0x800A63D0 0x800A648C 188 exact 2 frame 3 - 1 +543 0x800A8984 0x800A8A40 188 exact 2 frame 4 - 1 +544 0x800AF260 0x800AF31C 188 exact 2 frame 1 - 1 +545 0x8002E0D8 0x8002E198 192 exact 2 frame 4 - 1 +546 0x800437CC 0x8004388C 192 exact 2 frame 2 - 1 +547 0x80046A18 0x80046AD8 192 exact 2 frame 0 - 1 +548 0x800589E8 0x80058AA8 192 exact 2 frame 4 - 1 +549 0x800682F0 0x800683B0 192 exact 2 frame 3 - 1 +550 0x8006D3B0 0x8006D470 192 exact 2 frame 1 - 1 +551 0x80086CFC 0x80086DBC 192 exact 2 frame 0 - 1 +552 0x8008CC00 0x8008CCC0 192 exact 2 frame 2 - 1 +553 0x8008DB44 0x8008DC04 192 exact 2 frame 2 - 1 +554 0x8008FE98 0x8008FF58 192 exact 2 frame 3 - 1 +555 0x800F459C 0x800F465C 192 exact 2 frame 4 - 1 +556 0x8002C30C 0x8002C3D0 196 exact 2 frame 2 - 1 +557 0x80030414 0x800304D8 196 exact 2 frame 5 - 1 +558 0x80044B90 0x80044C54 196 exact 2 frame 0 - 1 +559 0x80045D84 0x80045E48 196 exact 2 frame 1 - 1 +560 0x800460D4 0x80046198 196 exact 2 frame 1 - 1 +561 0x800654E4 0x800655A8 196 exact 2 frame 3 - 1 +562 0x8006F9B4 0x8006FA78 196 exact 2 frame 1 - 1 +563 0x80074268 0x8007432C 196 exact 2 frame 4 - 1 +564 0x80089B88 0x80089C4C 196 exact 2 frame 2 - 1 +565 0x800AD104 0x800AD1C8 196 exact 2 frame 0 - 1 +566 0x800C1048 0x800C110C 196 exact 2 frame 3 - 1 +567 0x80100254 0x80100318 196 exact 2 frame 1 - 1 +568 0x8002BC20 0x8002BCE8 200 exact 2 frame 6 - 1 +569 0x8003570C 0x800357D4 200 exact 2 frame 1 - 1 +570 0x800655A8 0x80065670 200 exact 2 frame 2 - 1 +571 0x800A6A70 0x800A6B38 200 exact 2 frame 2 - 1 +572 0x80100598 0x80100660 200 exact 2 frame 5 - 1 +573 0x800258D4 0x800259A0 204 exact 2 frame 2 - 1 +574 0x800297F4 0x800298C0 204 exact 2 frame 2 - 1 +575 0x8002CB84 0x8002CC50 204 exact 2 frame 10 - 1 +576 0x800323E4 0x800324B0 204 exact 2 frame 3 - 1 +577 0x80044C54 0x80044D20 204 exact 2 frame 4 - 1 +578 0x800508CC 0x80050998 204 exact 2 frame 6 - 1 +579 0x80054AF8 0x80054BC4 204 exact 2 frame 0 - 1 +580 0x8005A81C 0x8005A8E8 204 exact 2 frame 1 - 1 +581 0x800667DC 0x800668A8 204 exact 2 frame 1 - 1 +582 0x80083BAC 0x80083C78 204 exact 2 frame 3 - 1 +583 0x80099AE4 0x80099BB0 204 exact 2 frame 1 - 1 +584 0x8009B4A0 0x8009B56C 204 exact 2 frame 1 - 1 +585 0x800ACB34 0x800ACC00 204 exact 2 frame 1 - 1 +586 0x800BB9FC 0x800BBAC8 204 exact 2 frame 3 - 1 +587 0x800F8658 0x800F8724 204 exact 2 frame 1 - 1 +588 0x80104230 0x801042FC 204 exact 2 frame 7 - 1 +589 0x801094D8 0x801095A4 204 exact 2 frame 1 - 1 +590 0x80019738 0x80019808 208 exact 2 frame 2 - 1 +591 0x80031A48 0x80031B18 208 exact 2 frame 2 - 1 +592 0x800453F8 0x800454C8 208 exact 2 frame 1 - 1 +593 0x80046278 0x80046348 208 exact 2 frame 1 - 1 +594 0x80099C44 0x80099D14 208 exact 2 frame 0 - 1 +595 0x80100438 0x80100508 208 exact 2 frame 6 - 1 +596 0x8010080C 0x801008DC 208 exact 2 frame 2 - 1 +597 0x800111B0 0x80011284 212 exact 2 frame 1 - 1 +598 0x80025F10 0x80025FE4 212 exact 2 frame 3 - 1 +599 0x800279E4 0x80027AB8 212 exact 2 frame 0 - 1 +600 0x8002D0A8 0x8002D17C 212 exact 2 frame 2 - 1 +601 0x80043DC4 0x80043E98 212 exact 2 frame 3 - 1 +602 0x80045E48 0x80045F1C 212 exact 2 frame 0 - 1 +603 0x80057F84 0x80058058 212 exact 2 frame 0 - 1 +604 0x8006821C 0x800682F0 212 exact 2 frame 1 - 1 +605 0x8007A428 0x8007A4FC 212 exact 2 frame 1 - 1 +606 0x800ACCD8 0x800ACDAC 212 exact 2 frame 0 - 1 +607 0x800ACED4 0x800ACFA8 212 exact 2 frame 0 - 1 +608 0x80101764 0x80101838 212 exact 2 frame 4 - 1 +609 0x80105474 0x80105548 212 exact 2 frame 1 - 1 +610 0x8006B398 0x8006B470 216 exact 2 frame 3 - 1 +611 0x8006D470 0x8006D548 216 exact 2 frame 1 - 1 +612 0x80090BB4 0x80090C8C 216 exact 2 frame 5 - 1 +613 0x800A4E48 0x800A4F20 216 exact 2 frame 2 - 1 +614 0x800AD9A8 0x800ADA80 216 exact 2 frame 0 - 1 +615 0x800F3A30 0x800F3B08 216 exact 2 frame 1 - 1 +616 0x80107B84 0x80107C5C 216 exact 2 frame 2 - 1 +617 0x80015950 0x80015A2C 220 exact 2 frame 1 - 1 +618 0x800198F4 0x800199D0 220 exact 2 frame 0 - 1 +619 0x80021D90 0x80021E6C 220 exact 2 frame 3 - 1 +620 0x8004D7C8 0x8004D8A4 220 exact 2 frame 2 - 1 +621 0x8006B0A8 0x8006B184 220 exact 2 frame 2 - 1 +622 0x80074658 0x80074734 220 exact 2 frame 7 - 1 +623 0x8008F530 0x8008F60C 220 exact 2 frame 3 - 1 +624 0x8008FDBC 0x8008FE98 220 exact 2 frame 3 - 1 +625 0x80024F6C 0x8002504C 224 exact 2 frame 6 - 1 +626 0x80029ED8 0x80029FB8 224 exact 2 frame 5 - 1 +627 0x8002C22C 0x8002C30C 224 exact 2 frame 7 - 1 +628 0x800733C4 0x800734A4 224 exact 2 frame 3 - 1 +629 0x8007A324 0x8007A404 224 exact 2 frame 3 - 1 +630 0x800A75CC 0x800A76AC 224 exact 2 frame 2 - 1 +631 0x800AE6C0 0x800AE7A0 224 exact 2 frame 3 - 1 +632 0x80100660 0x80100740 224 exact 2 frame 4 - 1 +633 0x80105014 0x801050F4 224 exact 2 frame 1 - 1 +634 0x80045CA0 0x80045D84 228 exact 2 frame 1 - 1 +635 0x8005260C 0x800526F0 228 exact 2 frame 1 - 1 +636 0x80057664 0x80057748 228 exact 2 frame 2 - 1 +637 0x80073F78 0x8007405C 228 exact 2 frame 5 - 1 +638 0x8007405C 0x80074140 228 exact 2 frame 5 - 1 +639 0x8007FCCC 0x8007FDB0 228 exact 2 frame 4 - 1 +640 0x800800D0 0x800801B4 228 exact 2 frame 4 - 1 +641 0x8008FCD8 0x8008FDBC 228 exact 2 frame 2 - 1 +642 0x80092A48 0x80092B2C 228 exact 2 frame 1 - 1 +643 0x800A6574 0x800A6658 228 exact 2 frame 2 - 1 +644 0x800FCB4C 0x800FCC30 228 exact 2 frame 3 - 1 +645 0x80024894 0x8002497C 232 exact 2 frame 2 - 1 +646 0x80065C34 0x80065D1C 232 exact 2 frame 1 - 1 +647 0x80074570 0x80074658 232 exact 2 frame 1 - 1 +648 0x8008D5F8 0x8008D6E0 232 exact 2 frame 2 - 1 +649 0x800A3400 0x800A34E8 232 exact 2 frame 2 - 1 +650 0x800B6F64 0x800B704C 232 exact 2 frame 3 - 1 +651 0x800BB1C4 0x800BB2AC 232 exact 2 frame 3 - 1 +652 0x8010A940 0x8010AA28 232 exact 2 frame 4 - 1 +653 0x8001AB24 0x8001AC10 236 exact 2 frame 3 - 1 +654 0x80024E80 0x80024F6C 236 exact 2 frame 3 - 1 +655 0x800278F8 0x800279E4 236 exact 2 frame 1 - 1 +656 0x8002BD80 0x8002BE6C 236 exact 2 frame 7 - 1 +657 0x8006ED58 0x8006EE44 236 exact 2 frame 4 - 1 +658 0x8007B83C 0x8007B928 236 exact 2 frame 3 - 1 +659 0x8007C6E0 0x8007C7CC 236 exact 2 frame 1 - 1 +660 0x800A8138 0x800A8224 236 exact 2 frame 1 - 1 +661 0x800BC6EC 0x800BC7D8 236 exact 2 frame 6 - 1 +662 0x800BC7D8 0x800BC8C4 236 exact 2 frame 6 - 1 +663 0x800FF4BC 0x800FF5A8 236 exact 2 frame 4 - 1 +664 0x80101678 0x80101764 236 exact 2 frame 4 - 1 +665 0x8010713C 0x80107228 236 exact 2 frame 0 - 1 +666 0x80013024 0x80013114 240 exact 2 frame 1 - 1 +667 0x80026560 0x80026650 240 exact 2 frame 1 - 1 +668 0x8003A9C8 0x8003AAB8 240 exact 2 frame 3 - 1 +669 0x80046CCC 0x80046DBC 240 exact 2 frame 1 - 1 +670 0x800907A4 0x80090894 240 exact 2 frame 4 - 1 +671 0x800AE268 0x800AE358 240 exact 2 frame 5 - 1 +672 0x80104630 0x80104720 240 exact 2 frame 5 - 1 +673 0x80106C04 0x80106CF4 240 exact 2 frame 0 - 1 +674 0x80028750 0x80028844 244 exact 2 frame 6 - 1 +675 0x80028CE0 0x80028DD4 244 exact 2 frame 1 - 1 +676 0x80046AD8 0x80046BCC 244 exact 2 frame 0 - 1 +677 0x8006AA88 0x8006AB7C 244 exact 2 frame 7 - 1 +678 0x8006EBA0 0x8006EC94 244 exact 2 frame 3 - 1 +679 0x80090A70 0x80090B64 244 exact 2 frame 2 - 1 +680 0x80099078 0x8009916C 244 exact 2 frame 7 - 1 +681 0x8009F5AC 0x8009F6A0 244 exact 2 frame 0 - 1 +682 0x800267CC 0x800268C4 248 exact 2 frame 6 - 1 +683 0x8002DA48 0x8002DB40 248 exact 2 frame 3 - 1 +684 0x80036134 0x8003622C 248 exact 2 frame 8 - 1 +685 0x8004345C 0x80043554 248 exact 2 frame 2 - 1 +686 0x80058AA8 0x80058BA0 248 exact 2 frame 5 - 1 +687 0x80058DEC 0x80058EE4 248 exact 2 frame 4 - 1 +688 0x8007EF84 0x8007F07C 248 exact 2 frame 1 - 1 +689 0x8009F4B4 0x8009F5AC 248 exact 2 frame 0 - 1 +690 0x8009F6A0 0x8009F798 248 exact 2 frame 0 - 1 +691 0x8009F798 0x8009F890 248 exact 2 frame 0 - 1 +692 0x8009F890 0x8009F988 248 exact 2 frame 0 - 1 +693 0x800A466C 0x800A4764 248 exact 2 frame 2 - 1 +694 0x800AFDBC 0x800AFEB4 248 exact 2 frame 2 - 1 +695 0x800F8724 0x800F881C 248 exact 2 frame 1 - 1 +696 0x800FE878 0x800FE970 248 exact 2 frame 6 - 1 +697 0x800421BC 0x800422B8 252 exact 2 frame 10 - 1 +698 0x8005DF74 0x8005E070 252 exact 2 frame 4 - 1 +699 0x8007E12C 0x8007E228 252 exact 2 frame 4 - 1 +700 0x8009D69C 0x8009D798 252 exact 2 frame 2 - 1 +701 0x800A74D0 0x800A75CC 252 exact 2 frame 1 - 1 +702 0x800FF5A8 0x800FF6A4 252 exact 2 frame 2 - 1 +703 0x80046BCC 0x80046CCC 256 exact 2 frame 1 - 1 +704 0x800911D4 0x800912D4 256 exact 2 frame 3 - 1 +705 0x800A613C 0x800A623C 256 exact 2 frame 2 - 1 +706 0x800BCA14 0x800BCB14 256 exact 2 frame 3 - 1 +707 0x800FD120 0x800FD220 256 exact 2 frame 10 - 1 +708 0x800137C8 0x800138CC 260 exact 2 frame 1 - 1 +709 0x8002F300 0x8002F404 260 exact 2 frame 1 - 1 +710 0x80031BBC 0x80031CC0 260 exact 2 frame 8 - 1 +711 0x80049FE4 0x8004A0E8 260 exact 2 frame 2 - 1 +712 0x80058CE8 0x80058DEC 260 exact 2 frame 2 - 1 +713 0x80062D10 0x80062E14 260 exact 2 frame 1 - 1 +714 0x800AFEB4 0x800AFFB8 260 exact 2 frame 3 - 1 +715 0x800FA4D4 0x800FA5D8 260 exact 2 frame 4 - 1 +716 0x80013B80 0x80013C88 264 exact 2 frame 6 - 1 +717 0x80018458 0x80018560 264 exact 2 frame 2 - 1 +718 0x800237B4 0x800238BC 264 exact 2 frame 7 - 1 +719 0x800238BC 0x800239C4 264 exact 2 frame 7 - 1 +720 0x80027ECC 0x80027FD4 264 exact 2 frame 3 - 1 +721 0x80027FD4 0x800280DC 264 exact 2 frame 3 - 1 +722 0x800281E4 0x800282EC 264 exact 2 frame 4 - 1 +723 0x800308C4 0x800309CC 264 exact 2 frame 4 - 1 +724 0x80037770 0x80037878 264 exact 2 frame 2 - 1 +725 0x80058EE4 0x80058FEC 264 exact 2 frame 7 - 1 +726 0x8005BE3C 0x8005BF44 264 exact 2 frame 4 - 1 +727 0x8006CFB0 0x8006D0B8 264 exact 2 frame 6 - 1 +728 0x800747E4 0x800748EC 264 exact 2 frame 12 - 1 +729 0x8009D798 0x8009D8A0 264 exact 2 frame 2 - 1 +730 0x800AC884 0x800AC98C 264 exact 2 frame 4 - 1 +731 0x800B6E5C 0x800B6F64 264 exact 2 frame 3 - 1 +732 0x801031C4 0x801032CC 264 exact 2 frame 2 - 1 +733 0x800139E4 0x80013AF0 268 exact 2 frame 3 - 1 +734 0x80027430 0x8002753C 268 exact 2 frame 9 - 1 +735 0x80037878 0x80037984 268 exact 2 frame 2 - 1 +736 0x8003B178 0x8003B284 268 exact 2 frame 2 - 1 +737 0x800439D8 0x80043AE4 268 exact 2 frame 5 - 1 +738 0x80057418 0x80057524 268 exact 2 frame 2 - 1 +739 0x8005E070 0x8005E17C 268 exact 2 frame 2 - 1 +740 0x8009F3A8 0x8009F4B4 268 exact 2 frame 3 - 1 +741 0x8005AD44 0x8005AE54 272 exact 2 frame 0 - 1 +742 0x800734DC 0x800735EC 272 exact 2 frame 3 - 1 +743 0x80079DDC 0x80079EEC 272 exact 2 frame 1 - 1 +744 0x800921C0 0x800922D0 272 exact 2 frame 4 - 1 +745 0x800A6E9C 0x800A6FAC 272 exact 2 frame 3 - 1 +746 0x800AA59C 0x800AA6AC 272 exact 2 frame 2 - 1 +747 0x800C5168 0x800C5278 272 exact 2 frame 1 - 1 +748 0x8002DD14 0x8002DE28 276 exact 2 frame 2 - 1 +749 0x8002F1D8 0x8002F2EC 276 exact 2 frame 3 - 1 +750 0x80031FC4 0x800320D8 276 exact 2 frame 1 - 1 +751 0x800320D8 0x800321EC 276 exact 2 frame 1 - 1 +752 0x80064858 0x8006496C 276 exact 2 frame 2 - 1 +753 0x8006BF30 0x8006C044 276 exact 2 frame 2 - 1 +754 0x8007C524 0x8007C638 276 exact 2 frame 4 - 1 +755 0x8008E2D0 0x8008E3E4 276 exact 2 frame 2 - 1 +756 0x800B1E80 0x800B1F94 276 exact 2 frame 3 - 1 +757 0x800138CC 0x800139E4 280 exact 2 frame 3 - 1 +758 0x8003A6E0 0x8003A7F8 280 exact 2 frame 3 - 1 +759 0x800910BC 0x800911D4 280 exact 2 frame 5 - 1 +760 0x8002DB40 0x8002DC5C 284 exact 2 frame 4 - 1 +761 0x800529A0 0x80052ABC 284 exact 2 frame 2 - 1 +762 0x800A4D2C 0x800A4E48 284 exact 2 frame 5 - 1 +763 0x800F4100 0x800F421C 284 exact 2 frame 2 - 1 +764 0x800F69BC 0x800F6AD8 284 exact 2 frame 4 - 1 +765 0x800F95CC 0x800F96E8 284 exact 2 frame 5 - 1 +766 0x80108168 0x80108284 284 exact 2 frame 3 - 1 +767 0x80015FC8 0x800160E8 288 exact 2 frame 7 - 1 +768 0x800289B4 0x80028AD4 288 exact 2 frame 0 - 1 +769 0x80044FA4 0x800450C4 288 exact 2 frame 1 - 1 +770 0x80045110 0x80045230 288 exact 2 frame 1 - 1 +771 0x8007C108 0x8007C228 288 exact 2 frame 5 - 1 +772 0x8008B960 0x8008BA80 288 exact 2 frame 4 - 1 +773 0x800FC8D0 0x800FC9F0 288 exact 2 frame 1 - 1 +774 0x80089E7C 0x80089FA0 292 exact 2 frame 6 - 1 +775 0x800FB7C8 0x800FB8EC 292 exact 2 frame 3 - 1 +776 0x800372A0 0x800373C8 296 exact 2 frame 1 - 1 +777 0x8005DDD0 0x8005DEF8 296 exact 2 frame 5 - 1 +778 0x80074140 0x80074268 296 exact 2 frame 7 - 1 +779 0x800ACDAC 0x800ACED4 296 exact 2 frame 0 - 1 +780 0x800B1C34 0x800B1D5C 296 exact 2 frame 1 - 1 +781 0x801009E8 0x80100B10 296 exact 2 frame 5 - 1 +782 0x80017660 0x8001778C 300 exact 2 frame 1 - 1 +783 0x800257A8 0x800258D4 300 exact 2 frame 3 - 1 +784 0x8002B924 0x8002BA50 300 exact 2 frame 1 - 1 +785 0x80046DBC 0x80046EE8 300 exact 2 frame 0 - 1 +786 0x80057CD0 0x80057DFC 300 exact 2 frame 1 - 1 +787 0x8006B4C4 0x8006B5F0 300 exact 2 frame 1 - 1 +788 0x8007C2DC 0x8007C408 300 exact 2 frame 1 - 1 +789 0x800FEED0 0x800FEFFC 300 exact 2 frame 5 - 1 +790 0x80027AB8 0x80027BE8 304 exact 2 frame 1 - 1 +791 0x800373C8 0x800374F8 304 exact 2 frame 1 - 1 +792 0x80042A90 0x80042BC0 304 exact 2 frame 4 - 1 +793 0x8005A474 0x8005A5A4 304 exact 2 frame 7 - 1 +794 0x8005A5A4 0x8005A6D4 304 exact 2 frame 10 - 1 +795 0x80072BDC 0x80072D0C 304 exact 2 frame 4 - 1 +796 0x800ADDE8 0x800ADF18 304 exact 2 frame 3 - 1 +797 0x80022A98 0x80022BCC 308 exact 2 frame 1 - 1 +798 0x80039AE4 0x80039C18 308 exact 2 frame 7 - 1 +799 0x800630F0 0x80063224 308 exact 2 frame 2 - 1 +800 0x800A66B0 0x800A67E4 308 exact 2 frame 2 - 1 +801 0x800F8CBC 0x800F8DF0 308 exact 2 frame 3 - 1 +802 0x80015B88 0x80015CC0 312 exact 2 frame 5 - 1 +803 0x800180D8 0x80018210 312 exact 2 frame 1 - 1 +804 0x800235C0 0x800236F8 312 exact 2 frame 1 - 1 +805 0x80055108 0x80055240 312 exact 2 frame 3 - 1 +806 0x800582EC 0x80058424 312 exact 2 frame 1 - 1 +807 0x8005A33C 0x8005A474 312 exact 2 frame 1 - 1 +808 0x8007B928 0x8007BA60 312 exact 2 frame 3 - 1 +809 0x8008DA0C 0x8008DB44 312 exact 2 frame 3 - 1 +810 0x800A4B70 0x800A4CA8 312 exact 2 frame 4 - 1 +811 0x800AB3CC 0x800AB504 312 exact 2 frame 0 - 1 +812 0x80102E20 0x80102F58 312 exact 2 frame 13 - 1 +813 0x80024668 0x800247A4 316 exact 2 frame 2 - 1 +814 0x8002CD94 0x8002CED0 316 exact 2 frame 4 - 1 +815 0x8003B34C 0x8003B488 316 exact 2 frame 2 - 1 +816 0x80067D34 0x80067E70 316 exact 2 frame 1 - 1 +817 0x80078E94 0x80078FD0 316 exact 2 frame 3 - 1 +818 0x800F8B80 0x800F8CBC 316 exact 2 frame 3 - 1 +819 0x80028DD4 0x80028F14 320 exact 2 frame 1 - 1 +820 0x8007A16C 0x8007A2AC 320 exact 2 frame 4 - 1 +821 0x8008D86C 0x8008D9AC 320 exact 2 frame 2 - 1 +822 0x8008F338 0x8008F478 320 exact 2 frame 7 - 1 +823 0x800BC054 0x800BC194 320 exact 2 frame 0 - 1 +824 0x80023AB0 0x80023BF4 324 exact 2 frame 4 - 1 +825 0x80024494 0x800245D8 324 exact 2 frame 2 - 1 +826 0x8002CC50 0x8002CD94 324 exact 2 frame 8 - 1 +827 0x8002CED0 0x8002D014 324 exact 2 frame 12 - 1 +828 0x80046EE8 0x8004702C 324 exact 2 frame 1 - 1 +829 0x8005E3F4 0x8005E538 324 exact 2 frame 2 - 1 +830 0x80082A68 0x80082BAC 324 exact 2 frame 1 - 1 +831 0x80082BAC 0x80082CF0 324 exact 2 frame 3 - 1 +832 0x8009F264 0x8009F3A8 324 exact 2 frame 3 - 1 +833 0x800ADB30 0x800ADC74 324 exact 2 frame 2 - 1 +834 0x800F6364 0x800F64A8 324 exact 2 frame 4 - 1 +835 0x800FCFDC 0x800FD120 324 exact 2 frame 13 - 1 +836 0x80089FA0 0x8008A0E8 328 exact 2 frame 3 - 1 +837 0x80095BB0 0x80095CF8 328 exact 2 frame 2 - 1 +838 0x800BFBAC 0x800BFCF4 328 exact 2 frame 2 - 1 +839 0x800277AC 0x800278F8 332 exact 2 frame 1 - 1 +840 0x8004388C 0x800439D8 332 exact 2 frame 0 - 1 +841 0x80085B90 0x80085CDC 332 exact 2 frame 3 - 1 +842 0x800B1A64 0x800B1BB0 332 exact 2 frame 5 - 1 +843 0x800F8DF0 0x800F8F3C 332 exact 2 frame 4 - 1 +844 0x80027178 0x800272C8 336 exact 2 frame 5 - 1 +845 0x80076778 0x800768C8 336 exact 2 frame 2 - 1 +846 0x800A8564 0x800A86B4 336 exact 2 frame 2 - 1 +847 0x800AD698 0x800AD7E8 336 exact 2 frame 2 - 1 +848 0x800AE7A0 0x800AE8F0 336 exact 2 frame 7 - 1 +849 0x800AF3E8 0x800AF538 336 exact 2 frame 6 - 1 +850 0x800C1F04 0x800C2054 336 exact 2 frame 1 - 1 +851 0x800F60A4 0x800F61F4 336 exact 2 frame 5 - 1 +852 0x800393E0 0x80039534 340 exact 2 frame 11 - 1 +853 0x80077D7C 0x80077ED0 340 exact 2 frame 3 - 1 +854 0x800304D8 0x80030630 344 exact 2 frame 1 - 1 +855 0x80045230 0x80045388 344 exact 2 frame 2 - 1 +856 0x80047190 0x800472E8 344 exact 2 frame 1 - 1 +857 0x80015A2C 0x80015B88 348 exact 2 frame 2 - 1 +858 0x8002E24C 0x8002E3A8 348 exact 2 frame 9 - 1 +859 0x8005D4C4 0x8005D620 348 exact 2 frame 0 - 1 +860 0x80079B34 0x80079C90 348 exact 2 frame 2 - 1 +861 0x800AA6AC 0x800AA808 348 exact 2 frame 5 - 1 +862 0x800B6D00 0x800B6E5C 348 exact 2 frame 1 - 1 +863 0x800FC774 0x800FC8D0 348 exact 2 frame 6 - 1 +864 0x80028AD4 0x80028C34 352 exact 2 frame 9 - 1 +865 0x8005E63C 0x8005E79C 352 exact 2 frame 7 - 1 +866 0x800704BC 0x8007061C 352 exact 2 frame 1 - 1 +867 0x800735EC 0x8007374C 352 exact 2 frame 2 - 1 +868 0x8007EBEC 0x8007ED4C 352 exact 2 frame 1 - 1 +869 0x800ABA28 0x800ABB88 352 exact 2 frame 2 - 1 +870 0x800F6F70 0x800F70D0 352 exact 2 frame 4 - 1 +871 0x800F7FD8 0x800F8138 352 exact 2 frame 3 - 1 +872 0x8004702C 0x80047190 356 exact 2 frame 1 - 1 +873 0x800556E8 0x8005584C 356 exact 2 frame 1 - 1 +874 0x800A9768 0x800A98CC 356 exact 2 frame 5 - 1 +875 0x800B5AF8 0x800B5C5C 356 exact 2 frame 1 - 1 +876 0x800272C8 0x80027430 360 exact 2 frame 10 - 1 +877 0x80033DC8 0x80033F30 360 exact 2 frame 1 - 1 +878 0x80065794 0x800658FC 360 exact 2 frame 2 - 1 +879 0x80101CDC 0x80101E44 360 exact 2 frame 11 - 1 +880 0x80106ED4 0x8010703C 360 exact 2 frame 5 - 1 +881 0x8003126C 0x800313D8 364 exact 2 frame 0 - 1 +882 0x80047DE0 0x80047F4C 364 exact 2 frame 3 - 1 +883 0x8009B638 0x8009B7A4 364 exact 2 frame 4 - 1 +884 0x80028844 0x800289B4 368 exact 2 frame 11 - 1 +885 0x8007DF34 0x8007E0A4 368 exact 2 frame 6 - 1 +886 0x80083878 0x800839E8 368 exact 2 frame 2 - 1 +887 0x8009CE58 0x8009CFC8 368 exact 2 frame 2 - 1 +888 0x80012B88 0x80012CFC 372 exact 2 frame 1 - 1 +889 0x800164EC 0x80016660 372 exact 2 frame 2 - 1 +890 0x80038BD4 0x80038D48 372 exact 2 frame 1 - 1 +891 0x8003D594 0x8003D708 372 exact 2 frame 4 - 1 +892 0x800ADC74 0x800ADDE8 372 exact 2 frame 1 - 1 +893 0x800BA8D4 0x800BAA48 372 exact 2 frame 0 - 1 +894 0x800F3E8C 0x800F4000 372 exact 2 frame 9 - 1 +895 0x8004780C 0x80047984 376 exact 2 frame 3 - 1 +896 0x8006EE44 0x8006EFBC 376 exact 2 frame 5 - 1 +897 0x800F7660 0x800F77D8 376 exact 2 frame 2 - 1 +898 0x800FFC3C 0x800FFDB4 376 exact 2 frame 3 - 1 +899 0x8002EF54 0x8002F0D0 380 exact 2 frame 2 - 1 +900 0x80034E50 0x80034FCC 380 exact 2 frame 2 - 1 +901 0x800B5924 0x800B5AA0 380 exact 2 frame 2 - 1 +902 0x800BD5E8 0x800BD764 380 exact 2 frame 4 - 1 +903 0x80038DD8 0x80038F58 384 exact 2 frame 5 - 1 +904 0x8003F010 0x8003F190 384 exact 2 frame 6 - 1 +905 0x8005D620 0x8005D7A0 384 exact 2 frame 1 - 1 +906 0x800228D8 0x80022A60 392 exact 2 frame 5 - 1 +907 0x800B1114 0x800B129C 392 exact 2 frame 3 - 1 +908 0x800374F8 0x80037684 396 exact 2 frame 3 - 1 +909 0x8008D6E0 0x8008D86C 396 exact 2 frame 8 - 1 +910 0x800BF5A8 0x800BF734 396 exact 2 frame 1 - 1 +911 0x800BFCF4 0x800BFE80 396 exact 2 frame 1 - 1 +912 0x80026A9C 0x80026C2C 400 exact 2 frame 7 - 1 +913 0x800914E4 0x80091674 400 exact 2 frame 10 - 1 +914 0x80026C7C 0x80026E10 404 exact 2 frame 7 - 1 +915 0x80029118 0x800292AC 404 exact 2 frame 0 - 1 +916 0x80046884 0x80046A18 404 exact 2 frame 3 - 1 +917 0x80073B74 0x80073D08 404 exact 2 frame 10 - 1 +918 0x80079EEC 0x8007A080 404 exact 2 frame 2 - 1 +919 0x80096364 0x800964F8 404 exact 2 frame 8 - 1 +920 0x80109338 0x801094CC 404 exact 2 frame 5 - 1 +921 0x800162B4 0x8001644C 408 exact 2 frame 4 - 1 +922 0x800309CC 0x80030B64 408 exact 2 frame 3 - 1 +923 0x8004AAF0 0x8004AC88 408 exact 2 frame 3 - 1 +924 0x800A5D24 0x800A5EBC 408 exact 2 frame 2 - 1 +925 0x800C5AEC 0x800C5C84 408 exact 2 frame 1 - 1 +926 0x800199D0 0x80019B6C 412 exact 2 frame 4 - 1 +927 0x80025FE4 0x80026180 412 exact 2 frame 1 - 1 +928 0x8006606C 0x80066208 412 exact 2 frame 7 - 1 +929 0x800FA338 0x800FA4D4 412 exact 2 frame 10 - 1 +930 0x80109010 0x801091AC 412 exact 2 frame 3 - 1 +931 0x80039168 0x80039308 416 exact 2 frame 1 - 1 +932 0x80051F50 0x800520F0 416 exact 2 frame 0 - 1 +933 0x8007F774 0x8007F914 416 exact 2 frame 1 - 1 +934 0x800A8700 0x800A88A0 416 exact 2 frame 2 - 1 +935 0x800BE828 0x800BE9C8 416 exact 2 frame 4 - 1 +936 0x80044610 0x800447B4 420 exact 2 frame 3 - 1 +937 0x8006B7C0 0x8006B964 420 exact 2 frame 16 - 1 +938 0x80041A58 0x80041C00 424 exact 2 frame 8 - 1 +939 0x800AA10C 0x800AA2B4 424 exact 2 frame 1 - 1 +940 0x801027F8 0x801029A0 424 exact 2 frame 1 - 1 +941 0x8002497C 0x80024B28 428 exact 2 frame 5 - 1 +942 0x8002AAD8 0x8002AC84 428 exact 2 frame 9 - 1 +943 0x800489D8 0x80048B84 428 exact 2 frame 3 - 1 +944 0x800FFDB4 0x800FFF60 428 exact 2 frame 4 - 1 +945 0x8004E24C 0x8004E3FC 432 exact 2 frame 2 - 1 +946 0x800B0ECC 0x800B107C 432 exact 2 frame 0 - 1 +947 0x80108284 0x80108434 432 exact 2 frame 3 - 1 +948 0x8001AC10 0x8001ADC4 436 exact 2 frame 4 - 1 +949 0x8006F77C 0x8006F930 436 exact 2 frame 2 - 1 +950 0x8008DFE8 0x8008E19C 436 exact 2 frame 5 - 1 +951 0x800AA2F8 0x800AA4AC 436 exact 2 frame 2 - 1 +952 0x800231BC 0x80023374 440 exact 2 frame 6 - 1 +953 0x8002D828 0x8002D9E0 440 exact 2 frame 1 - 1 +954 0x80080800 0x800809B8 440 exact 2 frame 5 - 1 +955 0x80081174 0x8008132C 440 exact 2 frame 8 - 1 +956 0x8009D8E0 0x8009DA98 440 exact 2 frame 1 - 1 +957 0x80025B64 0x80025D20 444 exact 2 frame 7 - 1 +958 0x800559C4 0x80055B84 448 exact 2 frame 0 - 1 +959 0x800AD7E8 0x800AD9A8 448 exact 2 frame 3 - 1 +960 0x800AE9E0 0x800AEBA0 448 exact 2 frame 7 - 1 +961 0x8010A1C8 0x8010A388 448 exact 2 frame 6 - 1 +962 0x8002ACBC 0x8002AE80 452 exact 2 frame 12 - 1 +963 0x8002FE3C 0x80030000 452 exact 2 frame 3 - 1 +964 0x800839E8 0x80083BAC 452 exact 2 frame 2 - 1 +965 0x800BBE90 0x800BC054 452 exact 2 frame 0 - 1 +966 0x80018560 0x80018728 456 exact 2 frame 1 - 1 +967 0x80068D78 0x80068F40 456 exact 2 frame 10 - 1 +968 0x8006E1B0 0x8006E378 456 exact 2 frame 3 - 1 +969 0x80077088 0x80077250 456 exact 2 frame 7 - 1 +970 0x80030630 0x800307FC 460 exact 2 frame 2 - 1 +971 0x80036DA4 0x80036F70 460 exact 2 frame 3 - 1 +972 0x80036F70 0x8003713C 460 exact 2 frame 3 - 1 +973 0x800590D8 0x800592A4 460 exact 2 frame 6 - 1 +974 0x800695D8 0x800697A4 460 exact 2 frame 4 - 1 +975 0x8008F114 0x8008F2E0 460 exact 2 frame 6 - 1 +976 0x80099E84 0x8009A050 460 exact 2 frame 1 - 1 +977 0x801095A8 0x80109774 460 exact 2 frame 4 - 1 +978 0x8002BA50 0x8002BC20 464 exact 2 frame 14 - 1 +979 0x8002E9F4 0x8002EBC4 464 exact 2 frame 6 - 1 +980 0x8003A7F8 0x8003A9C8 464 exact 2 frame 10 - 1 +981 0x800BBC1C 0x800BBDEC 464 exact 2 frame 0 - 1 +982 0x800C022C 0x800C03FC 464 exact 2 frame 3 - 1 +983 0x800F7B84 0x800F7D54 464 exact 2 frame 5 - 1 +984 0x8002D3F4 0x8002D5C8 468 exact 2 frame 11 - 1 +985 0x80047F4C 0x80048128 476 exact 2 frame 3 - 1 +986 0x80052ABC 0x80052C98 476 exact 2 frame 0 - 1 +987 0x80074394 0x80074570 476 exact 2 frame 12 - 1 +988 0x80078FD0 0x800791AC 476 exact 2 frame 7 - 1 +989 0x80101878 0x80101A54 476 exact 2 frame 4 - 1 +990 0x80044D78 0x80044F58 480 exact 2 frame 11 - 1 +991 0x8006496C 0x80064B4C 480 exact 2 frame 6 - 1 +992 0x80064B4C 0x80064D2C 480 exact 2 frame 4 - 1 +993 0x8006AB7C 0x8006AD5C 480 exact 2 frame 12 - 1 +994 0x800FBBA0 0x800FBD80 480 exact 2 frame 14 - 1 +995 0x80106CF4 0x80106ED4 480 exact 2 frame 9 - 1 +996 0x80059DF8 0x80059FDC 484 exact 2 frame 1 - 1 +997 0x80070270 0x80070454 484 exact 2 frame 2 - 1 +998 0x80052424 0x8005260C 488 exact 2 frame 7 - 1 +999 0x80069398 0x80069580 488 exact 2 frame 3 - 1 +1000 0x800FA150 0x800FA338 488 exact 2 frame 21 - 1 +1001 0x8003F7CC 0x8003F9B8 492 exact 2 frame 2 - 1 +1002 0x80065980 0x80065B6C 492 exact 2 frame 1 - 1 +1003 0x801078A4 0x80107A94 496 exact 2 frame 11 - 1 +1004 0x80024C34 0x80024E28 500 exact 2 frame 3 - 1 +1005 0x80064664 0x80064858 500 exact 2 frame 3 - 1 +1006 0x800652A0 0x80065494 500 exact 2 frame 6 - 1 +1007 0x800A4F8C 0x800A5180 500 exact 2 frame 0 - 1 +1008 0x80016BD4 0x80016DCC 504 exact 2 frame 1 - 1 +1009 0x8007ED8C 0x8007EF84 504 exact 2 frame 6 - 1 +1010 0x800C52F4 0x800C54EC 504 exact 2 frame 3 - 1 +1011 0x80030000 0x800301FC 508 exact 2 frame 10 - 1 +1012 0x80031CC0 0x80031EBC 508 exact 2 frame 7 - 1 +1013 0x80014054 0x80014258 516 exact 2 frame 6 - 1 +1014 0x800254EC 0x800256F0 516 exact 2 frame 5 - 1 +1015 0x80029C84 0x80029E88 516 exact 2 frame 2 - 1 +1016 0x8007BA60 0x8007BC64 516 exact 2 frame 4 - 1 +1017 0x8009AC28 0x8009AE2C 516 exact 2 frame 3 - 1 +1018 0x800B0BE0 0x800B0DE4 516 exact 2 frame 8 - 1 +1019 0x80067E70 0x80068078 520 exact 2 frame 5 - 1 +1020 0x800150A0 0x800152AC 524 exact 2 frame 13 - 1 +1021 0x80015DBC 0x80015FC8 524 exact 2 frame 5 - 1 +1022 0x800194A8 0x800196B4 524 exact 2 frame 2 - 1 +1023 0x80043B80 0x80043D8C 524 exact 2 frame 5 - 1 +1024 0x80098E18 0x80099024 524 exact 2 frame 13 - 1 +1025 0x80038F58 0x80039168 528 exact 2 frame 3 - 1 +1026 0x8007CFFC 0x8007D20C 528 exact 2 frame 3 - 1 +1027 0x800A6C8C 0x800A6E9C 528 exact 2 frame 11 - 1 +1028 0x80104720 0x80104930 528 exact 2 frame 2 - 1 +1029 0x8004B438 0x8004B64C 532 exact 2 frame 3 - 1 +1030 0x800697FC 0x80069A10 532 exact 2 frame 3 - 1 +1031 0x800AD484 0x800AD698 532 exact 2 frame 5 - 1 +1032 0x800295D4 0x800297F4 544 exact 2 frame 6 - 1 +1033 0x8002D608 0x8002D828 544 exact 2 frame 2 - 1 +1034 0x8009D47C 0x8009D69C 544 exact 2 frame 0 - 1 +1035 0x8009C904 0x8009CB28 548 exact 2 frame 3 - 1 +1036 0x8001778C 0x800179B8 556 exact 2 frame 4 - 1 +1037 0x80059504 0x80059730 556 exact 2 frame 4 - 1 +1038 0x80063900 0x80063B2C 556 exact 2 frame 10 - 1 +1039 0x8003C590 0x8003C7C0 560 exact 2 frame 11 - 1 +1040 0x8008A1D0 0x8008A400 560 exact 2 frame 3 - 1 +1041 0x800BF734 0x800BF968 564 exact 2 frame 5 - 1 +1042 0x800FB8EC 0x800FBB20 564 exact 2 frame 11 - 1 +1043 0x8009D244 0x8009D47C 568 exact 2 frame 3 - 1 +1044 0x800B6090 0x800B62C8 568 exact 2 frame 13 - 1 +1045 0x80029A48 0x80029C84 572 exact 2 frame 2 - 1 +1046 0x8007F07C 0x8007F2B8 572 exact 2 frame 9 - 1 +1047 0x80018728 0x8001896C 580 exact 2 frame 3 - 1 +1048 0x80041DA0 0x80041FE4 580 exact 2 frame 6 - 1 +1049 0x800BF968 0x800BFBAC 580 exact 2 frame 5 - 1 +1050 0x8009AE2C 0x8009B074 584 exact 2 frame 0 - 1 +1051 0x800B0940 0x800B0B88 584 exact 2 frame 7 - 1 +1052 0x80023374 0x800235C0 588 exact 2 frame 0 - 1 +1053 0x80062E14 0x80063060 588 exact 2 frame 8 - 1 +1054 0x800B6894 0x800B6AE0 588 exact 2 frame 7 - 1 +1055 0x80016704 0x80016954 592 exact 2 frame 4 - 1 +1056 0x800A7E68 0x800A80B8 592 exact 2 frame 3 - 1 +1057 0x800AFB6C 0x800AFDBC 592 exact 2 frame 2 - 1 +1058 0x8002C930 0x8002CB84 596 exact 2 frame 23 - 1 +1059 0x8006AE54 0x8006B0A8 596 exact 2 frame 0 - 1 +1060 0x800283F4 0x8002864C 600 exact 2 frame 5 - 1 +1061 0x8009736C 0x800975C4 600 exact 2 frame 10 - 1 +1062 0x800C4F10 0x800C5168 600 exact 2 frame 2 - 1 +1063 0x80050998 0x80050BF4 604 exact 2 frame 2 - 1 +1064 0x80065E10 0x8006606C 604 exact 2 frame 4 - 1 +1065 0x800C29D4 0x800C2C30 604 exact 2 frame 6 - 1 +1066 0x800F5E44 0x800F60A4 608 exact 2 frame 5 - 1 +1067 0x800B5CF8 0x800B5F5C 612 exact 2 frame 2 - 1 +1068 0x800BCBBC 0x800BCE20 612 exact 2 frame 0 - 1 +1069 0x8002BE6C 0x8002C0D4 616 exact 2 frame 13 - 1 +1070 0x800571AC 0x80057418 620 exact 2 frame 2 - 1 +1071 0x800B7264 0x800B74D0 620 exact 2 frame 10 - 1 +1072 0x800FD834 0x800FDAA0 620 exact 2 frame 6 - 1 +1073 0x8003F9B8 0x8003FC28 624 exact 2 frame 3 - 1 +1074 0x80069128 0x80069398 624 exact 2 frame 2 - 1 +1075 0x80073D08 0x80073F78 624 exact 2 frame 9 - 1 +1076 0x800F4E40 0x800F50B0 624 exact 2 frame 5 - 1 +1077 0x801051CC 0x8010543C 624 exact 2 frame 3 - 1 +1078 0x80043554 0x800437CC 632 exact 2 frame 9 - 1 +1079 0x80104930 0x80104BA8 632 exact 2 frame 3 - 1 +1080 0x8009CFC8 0x8009D244 636 exact 2 frame 12 - 1 +1081 0x80016954 0x80016BD4 640 exact 2 frame 0 - 1 +1082 0x80069A10 0x80069C90 640 exact 2 frame 4 - 1 +1083 0x8008FA58 0x8008FCD8 640 exact 2 frame 5 - 1 +1084 0x800A5EBC 0x800A613C 640 exact 2 frame 4 - 1 +1085 0x80106154 0x801063D4 640 exact 2 frame 9 - 1 +1086 0x80109F48 0x8010A1C8 640 exact 2 frame 11 - 1 +1087 0x8010A444 0x8010A6C4 640 exact 2 frame 2 - 1 +1088 0x800A30D4 0x800A3358 644 exact 2 frame 5 - 1 +1089 0x8002AEAC 0x8002B138 652 exact 2 frame 30 - 1 +1090 0x800FF800 0x800FFA8C 652 exact 2 frame 13 - 1 +1091 0x80036B14 0x80036DA4 656 exact 2 frame 3 - 1 +1092 0x800943E0 0x80094670 656 exact 2 frame 1 - 1 +1093 0x80072680 0x80072914 660 exact 2 frame 0 - 1 +1094 0x80072914 0x80072BA8 660 exact 2 frame 16 - 1 +1095 0x8002E528 0x8002E7C4 668 exact 2 frame 9 - 1 +1096 0x8006A6F0 0x8006A98C 668 exact 2 frame 0 - 1 +1097 0x800FACE8 0x800FAF84 668 exact 2 frame 7 - 1 +1098 0x80093768 0x80093A08 672 exact 2 frame 7 - 1 +1099 0x800519A8 0x80051C4C 676 exact 2 frame 1 - 1 +1100 0x800313D8 0x80031684 684 exact 2 frame 10 - 1 +1101 0x800526F0 0x800529A0 688 exact 2 frame 0 - 1 +1102 0x800F5B94 0x800F5E44 688 exact 2 frame 9 - 1 +1103 0x8007DC4C 0x8007DF00 692 exact 2 frame 3 - 1 +1104 0x8009916C 0x80099420 692 exact 2 frame 4 - 1 +1105 0x800501DC 0x80050494 696 exact 2 frame 5 - 1 +1106 0x800844B8 0x80084770 696 exact 2 frame 8 - 1 +1107 0x800A3600 0x800A38B8 696 exact 2 frame 2 - 1 +1108 0x800FF184 0x800FF43C 696 exact 2 frame 3 - 1 +1109 0x80103544 0x801037FC 696 exact 2 frame 1 - 1 +1110 0x8006BC74 0x8006BF30 700 exact 2 frame 1 - 1 +1111 0x800FA980 0x800FAC44 708 exact 2 frame 10 - 1 +1112 0x801063D4 0x8010669C 712 exact 2 frame 9 - 1 +1113 0x80074F1C 0x800751E8 716 exact 2 frame 8 - 1 +1114 0x8006EFBC 0x8006F28C 720 exact 2 frame 2 - 1 +1115 0x80084770 0x80084A48 728 exact 2 frame 7 - 1 +1116 0x800FA688 0x800FA960 728 exact 2 frame 9 - 1 +1117 0x8008A47C 0x8008A758 732 exact 2 frame 7 - 1 +1118 0x8006C044 0x8006C324 736 exact 2 frame 1 - 1 +1119 0x800916DC 0x800919BC 736 exact 2 frame 9 - 1 +1120 0x80091D88 0x80092068 736 exact 2 frame 7 - 1 +1121 0x800AB0EC 0x800AB3CC 736 exact 2 frame 1 - 1 +1122 0x8007AD28 0x8007B00C 740 exact 2 frame 5 - 1 +1123 0x800A47E0 0x800A4AC8 744 exact 2 frame 2 - 1 +1124 0x80033ADC 0x80033DC8 748 exact 2 frame 5 - 1 +1125 0x800BAED4 0x800BB1C4 752 exact 2 frame 4 - 1 +1126 0x80093A84 0x80093D80 764 exact 2 frame 1 - 1 +1127 0x80078B94 0x80078E94 768 exact 2 frame 6 - 1 +1128 0x80051C4C 0x80051F50 772 exact 2 frame 2 - 1 +1129 0x8009A904 0x8009AC08 772 exact 2 frame 2 - 1 +1130 0x8004C400 0x8004C708 776 exact 2 frame 0 - 1 +1131 0x80059AF0 0x80059DF8 776 exact 2 frame 9 - 1 +1132 0x8009829C 0x800985A4 776 exact 2 frame 9 - 1 +1133 0x8006D884 0x8006DB90 780 exact 2 frame 1 - 1 +1134 0x80091A7C 0x80091D88 780 exact 2 frame 12 - 1 +1135 0x800BFF20 0x800C022C 780 exact 2 frame 1 - 1 +1136 0x80013D44 0x80014054 784 exact 2 frame 10 - 1 +1137 0x8005D1B0 0x8005D4C4 788 exact 2 frame 2 - 1 +1138 0x800748EC 0x80074C00 788 exact 2 frame 21 - 1 +1139 0x80025198 0x800254B0 792 exact 2 frame 5 - 1 +1140 0x80072048 0x80072360 792 exact 2 frame 12 - 1 +1141 0x800830B4 0x800833CC 792 exact 2 frame 2 - 1 +1142 0x80094670 0x80094988 792 exact 2 frame 8 - 1 +1143 0x800FCC48 0x800FCF60 792 exact 2 frame 12 - 1 +1144 0x8002B608 0x8002B924 796 exact 2 frame 3 - 1 +1145 0x8007061C 0x80070938 796 exact 2 frame 10 - 1 +1146 0x8008355C 0x80083878 796 exact 2 frame 7 - 1 +1147 0x80072360 0x80072680 800 exact 2 frame 5 - 1 +1148 0x8006DB90 0x8006DEB4 804 exact 2 frame 3 - 1 +1149 0x800292AC 0x800295D4 808 exact 2 frame 2 - 1 +1150 0x80082CF0 0x80083018 808 exact 2 frame 9 - 1 +1151 0x8009CB28 0x8009CE58 816 exact 2 frame 6 - 1 +1152 0x801042FC 0x80104630 820 exact 2 frame 18 - 1 +1153 0x80041688 0x800419D0 840 exact 2 frame 11 - 1 +1154 0x80052CAC 0x80052FF4 840 exact 2 frame 14 - 1 +1155 0x80077250 0x8007759C 844 exact 2 frame 5 - 1 +1156 0x800C54EC 0x800C583C 848 exact 2 frame 3 - 1 +1157 0x80048684 0x800489D8 852 exact 2 frame 6 - 1 +1158 0x800A98CC 0x800A9C24 856 exact 2 frame 14 - 1 +1159 0x8006CC54 0x8006CFB0 860 exact 2 frame 4 - 1 +1160 0x80059FDC 0x8005A33C 864 exact 2 frame 4 - 1 +1161 0x80031684 0x800319F0 876 exact 2 frame 14 - 1 +1162 0x8005CA30 0x8005CDA0 880 exact 2 frame 4 - 1 +1163 0x80090D00 0x80091070 880 exact 2 frame 4 - 1 +1164 0x80040884 0x80040BFC 888 exact 2 frame 4 - 1 +1165 0x800897B8 0x80089B30 888 exact 2 frame 17 - 1 +1166 0x8003C7C0 0x8003CB3C 892 exact 2 frame 9 - 1 +1167 0x80089434 0x800897B8 900 exact 2 frame 20 - 1 +1168 0x800AC2C4 0x800AC648 900 exact 2 frame 0 - 1 +1169 0x800ABB88 0x800ABF10 904 exact 2 frame 1 - 1 +1170 0x80017200 0x8001758C 908 exact 2 frame 6 - 1 +1171 0x80048E70 0x800491FC 908 exact 2 frame 10 - 1 +1172 0x8002EBC4 0x8002EF54 912 exact 2 frame 5 - 1 +1173 0x80095820 0x80095BB0 912 exact 2 frame 10 - 1 +1174 0x80034ABC 0x80034E50 916 exact 2 frame 11 - 1 +1175 0x80064230 0x800645CC 924 exact 2 frame 13 - 1 +1176 0x80072DF4 0x80073190 924 exact 2 frame 10 - 1 +1177 0x80090408 0x800907A4 924 exact 2 frame 12 - 1 +1178 0x8004FE38 0x800501DC 932 exact 2 frame 5 - 1 +1179 0x800564AC 0x80056854 936 exact 2 frame 11 - 1 +1180 0x800ABF10 0x800AC2C4 948 exact 2 frame 4 - 1 +1181 0x80059730 0x80059AF0 960 exact 2 frame 4 - 1 +1182 0x8006F2F4 0x8006F6BC 968 exact 2 frame 1 - 1 +1183 0x8008EBFC 0x8008EFC4 968 exact 2 frame 9 - 1 +1184 0x800B7524 0x800B78EC 968 exact 2 frame 4 - 1 +1185 0x80047A14 0x80047DE0 972 exact 2 frame 9 - 1 +1186 0x80033700 0x80033ADC 988 exact 2 frame 3 - 1 +1187 0x800447B4 0x80044B90 988 exact 2 frame 12 - 1 +1188 0x80073798 0x80073B74 988 exact 2 frame 4 - 1 +1189 0x80088F38 0x80089314 988 exact 2 frame 11 - 1 +1190 0x800AAC9C 0x800AB078 988 exact 2 frame 11 - 1 +1191 0x80058608 0x800589E8 992 exact 2 frame 2 - 1 +1192 0x80071C64 0x80072048 996 exact 2 frame 15 - 1 +1193 0x8010128C 0x80101678 1004 exact 2 frame 6 - 1 +1194 0x8009B074 0x8009B464 1008 exact 2 frame 0 - 1 +1195 0x800B0550 0x800B0940 1008 exact 2 frame 11 - 1 +1196 0x80037B98 0x80037F94 1020 exact 2 frame 9 - 1 +1197 0x8007BD0C 0x8007C108 1020 exact 2 frame 10 - 1 +1198 0x800C1A58 0x800C1E54 1020 exact 2 frame 8 - 1 +1199 0x800FD278 0x800FD674 1020 exact 2 frame 10 - 1 +1200 0x80039534 0x8003993C 1032 exact 2 frame 1 - 1 +1201 0x8010669C 0x80106AA8 1036 exact 2 frame 12 - 1 +1202 0x8005CDA0 0x8005D1B0 1040 exact 2 frame 17 - 1 +1203 0x80094F54 0x80095364 1040 exact 2 frame 9 - 1 +1204 0x800331D4 0x800335E8 1044 exact 2 frame 7 - 1 +1205 0x80055240 0x80055654 1044 exact 2 frame 6 - 1 +1206 0x800868E8 0x80086CFC 1044 exact 2 frame 3 - 1 +1207 0x800A2B04 0x800A2F20 1052 exact 2 frame 7 - 1 +1208 0x800B6330 0x800B6754 1060 exact 2 frame 13 - 1 +1209 0x8003F190 0x8003F5BC 1068 exact 2 frame 2 - 1 +1210 0x80056854 0x80056C88 1076 exact 2 frame 20 - 1 +1211 0x8003879C 0x80038BD4 1080 exact 2 frame 10 - 1 +1212 0x80092460 0x80092898 1080 exact 2 frame 13 - 1 +1213 0x800AA808 0x800AAC44 1084 exact 2 frame 9 - 1 +1214 0x800B2048 0x800B2488 1088 exact 2 frame 4 - 1 +1215 0x80034638 0x80034A80 1096 exact 2 frame 7 - 1 +1216 0x8008F60C 0x8008FA58 1100 exact 2 frame 4 - 1 +1217 0x8009A4AC 0x8009A904 1112 exact 2 frame 6 - 1 +1218 0x8005A8E8 0x8005AD44 1116 exact 2 frame 15 - 1 +1219 0x8003EBAC 0x8003F010 1124 exact 2 frame 10 - 1 +1220 0x800BCE20 0x800BD298 1144 exact 2 frame 13 - 1 +1221 0x800C03FC 0x800C0874 1144 exact 2 frame 3 - 1 +1222 0x800A38B8 0x800A3D34 1148 exact 2 frame 15 - 1 +1223 0x80041190 0x80041610 1152 exact 2 frame 18 - 1 +1224 0x80063358 0x800637DC 1156 exact 2 frame 11 - 1 +1225 0x800B8958 0x800B8DE4 1164 exact 2 frame 10 - 1 +1226 0x800BAA48 0x800BAED4 1164 exact 2 frame 1 - 1 +1227 0x800C5CD4 0x800C6168 1172 exact 2 frame 10 - 1 +1228 0x800668F0 0x80066DA0 1200 exact 2 frame 15 - 1 +1229 0x800A6FAC 0x800A745C 1200 exact 2 frame 20 - 1 +1230 0x800B9C64 0x800BA114 1200 exact 2 frame 0 - 1 +1231 0x8005E8B8 0x8005ED6C 1204 exact 2 frame 26 - 1 +1232 0x800F2A50 0x800F2F08 1208 exact 2 frame 3 - 1 +1233 0x80095364 0x80095820 1212 exact 2 frame 3 - 1 +1234 0x800BC194 0x800BC658 1220 exact 2 frame 6 - 1 +1235 0x8002B138 0x8002B608 1232 exact 2 frame 36 - 1 +1236 0x8004D8A4 0x8004DD74 1232 exact 2 frame 6 - 1 +1237 0x8004DD74 0x8004E24C 1240 exact 2 frame 7 - 1 +1238 0x800F465C 0x800F4B54 1272 exact 2 frame 8 - 1 +1239 0x800F70D0 0x800F75C8 1272 exact 2 frame 8 - 1 +1240 0x80093E54 0x80094370 1308 exact 2 frame 15 - 1 +1241 0x80056C88 0x800571AC 1316 exact 2 frame 4 - 1 +1242 0x8005C508 0x8005CA30 1320 exact 2 frame 1 - 1 +1243 0x8007D718 0x8007DC40 1320 exact 2 frame 5 - 1 +1244 0x800B78EC 0x800B7E14 1320 exact 2 frame 0 - 1 +1245 0x80034FCC 0x800354F8 1324 exact 2 frame 13 - 1 +1246 0x80066208 0x80066738 1328 exact 2 frame 7 - 1 +1247 0x800C3C4C 0x800C417C 1328 exact 2 frame 10 - 1 +1248 0x8005BFD0 0x8005C508 1336 exact 2 frame 1 - 1 +1249 0x80054BC4 0x80055108 1348 exact 2 frame 4 - 1 +1250 0x80086388 0x800868E8 1376 exact 2 frame 15 - 1 +1251 0x8004ED90 0x8004F2F8 1384 exact 2 frame 11 - 1 +1252 0x800855D4 0x80085B44 1392 exact 2 frame 2 - 1 +1253 0x80064D2C 0x800652A0 1396 exact 2 frame 4 - 1 +1254 0x8007E228 0x8007E7C0 1432 exact 2 frame 3 - 1 +1255 0x8007B2A0 0x8007B83C 1436 exact 2 frame 5 - 1 +1256 0x800C14BC 0x800C1A58 1436 exact 2 frame 12 - 1 +1257 0x80095D74 0x80096324 1456 exact 2 frame 11 - 1 +1258 0x800AEC48 0x800AF1FC 1460 exact 2 frame 14 - 1 +1259 0x80094988 0x80094F54 1484 exact 2 frame 22 - 1 +1260 0x800152AC 0x8001587C 1488 exact 2 frame 19 - 1 +1261 0x8003CBE4 0x8003D224 1600 exact 2 frame 15 - 1 +1262 0x8009B7A4 0x8009BDEC 1608 exact 2 frame 11 - 1 +1263 0x80075228 0x8007587C 1620 exact 2 frame 15 - 1 +1264 0x80076110 0x80076778 1640 exact 2 frame 27 - 1 +1265 0x80099420 0x80099A94 1652 exact 2 frame 11 - 1 +1266 0x80036390 0x80036A0C 1660 exact 2 frame 9 - 1 +1267 0x8007A4FC 0x8007AB7C 1664 exact 2 frame 9 - 1 +1268 0x80085CDC 0x80086388 1708 exact 2 frame 15 - 1 +1269 0x8004CF0C 0x8004D5CC 1728 exact 2 frame 11 - 1 +1270 0x800C356C 0x800C3C4C 1760 exact 2 frame 18 - 1 +1271 0x80023DA8 0x80024494 1772 exact 2 frame 3 - 1 +1272 0x80063B2C 0x80064230 1796 exact 2 frame 17 - 1 +1273 0x80030B64 0x8003126C 1800 exact 2 frame 7 - 1 +1274 0x80033F30 0x80034638 1800 exact 2 frame 0 - 1 +1275 0x80100B2C 0x80101244 1816 exact 2 frame 13 - 1 +1276 0x8006FB44 0x80070270 1836 exact 2 frame 24 - 1 +1277 0x800BB2AC 0x800BB9FC 1872 exact 2 frame 5 - 1 +1278 0x80037F94 0x8003870C 1912 exact 2 frame 25 - 1 +1279 0x80043E98 0x80044610 1912 exact 2 frame 12 - 1 +1280 0x8009E95C 0x8009F0E8 1932 exact 2 frame 10 - 1 +1281 0x800A3D34 0x800A44CC 1944 exact 2 frame 10 - 1 +1282 0x8004AC88 0x8004B438 1968 exact 2 frame 18 - 1 +1283 0x800A8F18 0x800A96CC 1972 exact 2 frame 8 - 1 +1284 0x800809B8 0x80081174 1980 exact 2 frame 17 - 1 +1285 0x800BA114 0x800BA8D4 1984 exact 2 frame 1 - 1 +1286 0x800B129C 0x800B1A64 1992 exact 2 frame 4 - 1 +1287 0x8005AE54 0x8005B638 2020 exact 2 frame 15 - 1 +1288 0x80092B2C 0x80093330 2052 exact 2 frame 16 - 1 +1289 0x8008E3E4 0x8008EBFC 2072 exact 2 frame 6 - 1 +1290 0x8007C7CC 0x8007CFFC 2096 exact 2 frame 10 - 1 +1291 0x80083C78 0x800844B8 2112 exact 2 frame 15 - 1 +1292 0x800C417C 0x800C49BC 2112 exact 2 frame 6 - 1 +1293 0x800985A4 0x80098E18 2164 exact 2 frame 49 - 1 +1294 0x8004A278 0x8004AAF0 2168 exact 2 frame 12 - 1 +1295 0x800713D0 0x80071C64 2196 exact 2 frame 12 - 1 +1296 0x8007587C 0x80076110 2196 exact 2 frame 33 - 1 +1297 0x8002203C 0x800228D8 2204 exact 2 frame 4 - 1 +1298 0x80050D48 0x80051628 2272 exact 2 frame 15 - 1 +1299 0x80053064 0x80053954 2288 exact 2 frame 12 - 1 +1300 0x80101EB0 0x801027CC 2332 exact 2 frame 12 - 1 +1301 0x80055B84 0x800564AC 2344 exact 2 frame 17 - 1 +1302 0x8001CE70 0x8001D7A0 2352 exact 2 frame 14 - 1 +1303 0x8006C324 0x8006CC54 2352 exact 2 frame 19 - 1 +1304 0x8008CCC0 0x8008D5F8 2360 exact 2 frame 11 - 1 +1305 0x800357D4 0x80036134 2400 exact 2 frame 21 - 1 +1306 0x800C2054 0x800C29D4 2432 exact 2 frame 17 - 1 +1307 0x80069C90 0x8006A654 2500 exact 2 frame 13 - 1 +1308 0x800A5228 0x800A5C1C 2548 exact 2 frame 23 - 1 +1309 0x8004F2F8 0x8004FE38 2880 exact 2 frame 21 - 1 +1310 0x800B7E14 0x800B8958 2884 exact 2 frame 5 - 1 +1311 0x800BEA28 0x800BF5A8 2944 exact 2 frame 16 - 1 +1312 0x8003FD00 0x80040884 2948 exact 2 frame 26 - 1 +1313 0x800975C4 0x8009829C 3288 exact 2 frame 71 - 1 +1314 0x800142F4 0x80014FE8 3316 exact 2 frame 38 - 1 +1315 0x800B8E60 0x800B9C64 3588 exact 2 frame 8 - 1 +1316 0x8009DA98 0x8009E8D0 3640 exact 2 frame 21 - 1 +1317 0x800964F8 0x8009736C 3700 exact 2 frame 32 - 1 +1318 0x80019C10 0x8001AA9C 3724 exact 2 frame 16 - 1 +1319 0x80066E58 0x80067D34 3804 exact 2 frame 39 - 1 +1320 0x800BD764 0x800BE6D8 3956 exact 2 frame 27 - 1 +1321 0x80053954 0x80054AF8 4516 exact 2 frame 32 - 1 +1322 0x80011508 0x80012780 4728 exact 2 frame 20 - 1 +1323 0x8008132C 0x80082750 5156 exact 2 frame 34 - 1 +1324 0x80086DFC 0x80088F38 8508 exact 2 frame 38 - 1 +1325 0x8009F988 0x800A2684 11516 exact 2 frame 102 - 1 +1326 0x80180808 0x8018080C 4 fallthrough 3 leaf 0 - 1 +1327 0x801007E0 0x80100808 40 fallthrough 3 frame 1 - 1 # -# listed=1343 -# excluded_already_registered=409 +# listed=1327 +# excluded_already_registered=424 # excluded_bad_extent_start=8 # excluded_degenerate_body=252 # excluded_delay_slot_start=5 @@ -1358,5 +1342,5 @@ # excluded_low_confidence_grade=90 # excluded_named_exclusion=8 # excluded_no_extent=0 -# excluded_recorded_negative=115 +# excluded_recorded_negative=116 # excluded_trapping_arith=54 diff --git a/config/near_match_negatives.tsv b/config/near_match_negatives.tsv index 4f7aca3..5c8ae16 100644 --- a/config/near_match_negatives.tsv +++ b/config/near_match_negatives.tsv @@ -8,26 +8,48 @@ 0x80010810 60 near-match register-tiebreak 0x8001084C 712 blocked trapping-arithmetic 0x80011084 - near-match - +0x8001278C - near-match - +0x80012834 - near-match - 0x80012A10 - near-match - +0x80012A48 80 near-match primitive-init scheduler-bound family 0x80012A98 68 near-match cc1-scheduler-bound (constant stores before stack-arg loads; 2 coordinator spellings incl. named locals, 72B both; same family as 0x80012A10/0x80012AE0) 0x80012AE0 - near-match - +0x80012CFC - near-match - 0x80012D54 56 near-match - 0x80013114 64 near-match - 0x800161E0 - near-match - 0x80016224 - near-match - 0x80016268 - near-match - +0x80016E24 - near-match - +0x800179E0 - near-match - +0x80017A38 - near-match - +0x80018284 80 near-match struct-copy jr-slot shape (8 loads/8 stores + v0-zero in slot) 0x80018CB0 120 blocked trapping-arithmetic 0x80019700 - near-match - 0x8001D98C 436 blocked,deferred trapping-arithmetic 0x8001DC20 - near-match - 0x8001EAFC 12 deferred shared-block-not-a-function +0x80022E44 52 near-match adjacent-zero-store merge +0x800245D8 - near-match - +0x80024630 56 near-match stack-routed min (temp elided by optimizer) 0x8002515C - near-match - +0x800254B0 - near-match - +0x80025758 - near-match - +0x800259DC - near-match - 0x80025C08 - near-match - +0x80025EAC - near-match - 0x8002622C - near-match - 0x800266A8 68 near-match byte-replication alloc (first sll register; fresh-context re-spelling 3B; named-locals regresses) +0x80027BE8 - near-match - 0x8002D014 - near-match - 0x8002D060 72 near-match - +0x80037984 - near-match - +0x800379E0 - near-match - 0x80039308 - near-match - +0x8003A5F4 80 near-match alloc+layout (j-to-done second guard; worker-C residual confirmed by coordinator) +0x8003EB18 - near-match - +0x80042CE0 80 near-match paired-array geometry (stride 1428, single walked at-register) +0x80042D88 76 near-match strength-reduce (sra5+sll2 vs cc1 folded shift) 0x80042DD4 - near-match - 0x80042E10 - near-match - 0x80042E68 - near-match - @@ -35,37 +57,61 @@ 0x80045F00 - near-match - 0x800460AC 40 near-match constant-materialisation-order 0x80047468 72 near-match alloc (move-zero-in-delay + *76 strength-reduce; 2 coordinator spellings 76B; the *76 and pointer-slot table-lever patterns confirmed) +0x8004820C - near-match - 0x800496CC - near-match - 0x800518BC 88 near-match return-merge/sltiu (3 spellings: goto-shared 80B, combined cond 80B, two-exit if 80B; original keeps move-zero at separate target + j-to-shared-return; sltiu needs unsigned val which alone fixes the compare byte but not the 8-byte layout) 0x800582AC 64 near-match - 0x8005DEF8 124 near-match register-tiebreak +0x80065494 80 near-match popcount scheduling (base in beqz delay slot) 0x800690E4 68 near-match loop-rotation+head-match-early-return (3 spellings: do/while arg-test-top 84B, while+conditional 76B, while-test 64B; the j/li early path and bnez-back-to-bne rotation are the residual) +0x8006AD5C - near-match - +0x8006AE04 - near-match - +0x8006B470 - near-match - +0x8006F95C - near-match - 0x8006FAA0 76 near-match cc1-scheduler (load/subu/store interleave + sra ordering; 1 coordinator attempt 72B) 0x8006FAEC 88 near-match - +0x8007374C - near-match - +0x800751E8 - near-match - +0x8007A114 - near-match - +0x8007E85C - near-match - 0x800807E0 - near-match - 0x80085B44 60 near-match - 0x8008A198 56 near-match - 0x8008F478 - near-match - 0x80090990 - near-match - 0x80092104 - near-match - +0x80094370 84 near-match triple-deref copy loop (dest = *(*(a0+0xc)+0x160)+0x160; 1 coordinator attempt 100B) +0x80099E34 40 near-match alloc-tiebreak (symbol-form address in a1) 0x8009B218 - near-match - 0x8009C69C 60 near-match register-tiebreak 0x8009C750 436 deferred trapping-arithmetic 0x8009F064 - near-match - 0x800A6658 88 near-match alloc+symbol-recompute (3 coordinator spellings; original recomputes lui/addu per iteration into two separate symbol arrays; cc1 pre-materializes base pointers — worker-A finding-8 CSE class) 0x800A82D0 64 near-match - +0x800A86B4 - near-match - +0x800A8AEC - near-match - +0x800AAC44 - near-match - 0x800AC9D8 56 near-match constant-materialisation-order +0x800B0B88 - near-match - 0x800B34A4 88 near-match alloc-tiebreak (bit-index/base register pair a0/a1 vs cc1 a0/v1; 2 spellings both 80B; original keeps base in a1 via direct +0x10 load) +0x800C1E54 - near-match - 0x800C3514 88 near-match alloc+layout (priority selector; original: all stack loads hoisted, beqz+nop+li groups, sltu first test; cc1 interleaves with bnez — 2 coordinator spellings 84B) 0x800F3BB4 164 near-match global-ra-save guard (ra through D_8012A57C is CRT/library asm, not usable C; GTE $0..$7 block verified as the rotation/translation macros — gte_ldTRX/TRY/TRZ added to gtemac.h from this row) 0x800F4B54 - near-match - +0x800F4C08 - near-match - 0x800F50B0 - near-match - 0x800F6ED0 44 near-match cc1-scheduling 0x800F6F20 - near-match - +0x800F7610 - near-match - 0x800F7930 96 near-match record-builder alloc (flag/0x100 branch shape + packed pair; 1 coordinator attempt 80B) 0x800F7E00 - near-match - +0x800F88F0 - near-match - +0x800F8928 - near-match - +0x800F9134 - near-match - 0x800FBD80 - near-match - +0x800FBDC0 - near-match - 0x800FBF5C 56 near-match - +0x800FC280 - near-match - 0x800FCC30 - near-match - 0x800FD220 88 near-match exit-duplication 0x800FDE54 - near-match - @@ -75,10 +121,12 @@ 0x800FFB74 72 near-match base-materialization (original: lui v0,0x8014 + addiu 0x5ac0 + addiu 0x678 in v0; cc1: lui v1 + one addiu or ori; gp stores need D_80122168/6C gp rows; 4 coordinator spellings) 0x800FFBBC 48 near-match reorg-thread-fill 0x80100334 - near-match - +0x8010036C 56 near-match rare-epilogue-order (F21) 0x80100998 80 near-match - 0x80101C5C 32 blocked - 0x80101C7C - near-match - 0x80101E50 76 near-match custom-compare loop shape (back-up-mismatch path; cc1 rewrites to 52B) +0x80102F58 - near-match - 0x80102FE4 - near-match - 0x80103AA4 - near-match - 0x8010400C 44 near-match constant-base-in-register @@ -90,56 +138,9 @@ 0x80108034 24 blocked gp-thunk 0x8010804C 16 blocked gp-thunk 0x80108578 56 near-match two-epilogue +0x801086B0 - near-match - 0x801092C0 52 near-match - 0x801097A0 - near-match - +0x8010AA28 112 near-match maspsx mutual exclusion (finding 17 in its purest form: maspsx=off -> 2 differing bytes at 0x8010AA6C; maspsx on -> 124 bytes, three unfilled delay slots; maspsx 2.56 has no flag suppressing only the jump-slot nop) 0x8010B420 - near-match - 0x801BB450 - near-match - -0x80042D88 76 near-match strength-reduce (sra5+sll2 vs cc1 folded shift) -0x80018284 80 near-match struct-copy jr-slot shape (8 loads/8 stores + v0-zero in slot) -0x80042CE0 80 near-match paired-array geometry (stride 1428, single walked at-register) -0x80065494 80 near-match popcount scheduling (base in beqz delay slot) -0x80012A48 80 near-match primitive-init scheduler-bound family -0x8003A5F4 80 near-match alloc+layout (j-to-done second guard; worker-C residual confirmed by coordinator) -0x800F9134 - near-match - -0x80094370 84 near-match triple-deref copy loop (dest = *(*(a0+0xc)+0x160)+0x160; 1 coordinator attempt 100B) -0x80099E34 40 near-match alloc-tiebreak (symbol-form address in a1) -0x80016E24 - near-match - -0x800F88F0 - near-match - -0x80024630 56 near-match stack-routed min (temp elided by optimizer) -0x80022E44 52 near-match adjacent-zero-store merge -0x8010036C 56 near-match rare-epilogue-order (F21) -0x800FBDC0 - near-match - -0x800F4C08 - near-match - -0x800254B0 - near-match - -0x800751E8 - near-match - -0x80017A38 - near-match - -0x8004820C - near-match - -0x80102F58 - near-match - -0x800F7610 - near-match - -0x800F8928 - near-match - -0x80025758 - near-match - -0x8006AE04 - near-match - -0x8006AD5C - near-match - -0x8006B470 - near-match - -0x800245D8 - near-match - -0x8007374C - near-match - -0x800A86B4 - near-match - -0x80027BE8 - near-match - -0x80037984 - near-match - -0x8007E85C - near-match - -0x801086B0 - near-match - -0x800379E0 - near-match - -0x8001278C - near-match - -0x80025EAC - near-match - -0x800B0B88 - near-match - -0x80012CFC - near-match - -0x8006F95C - near-match - -0x800FC280 - near-match - -0x800259DC - near-match - -0x800179E0 - near-match - -0x800C1E54 - near-match - -0x800AAC44 - near-match - -0x8003EB18 - near-match - -0x80012834 - near-match - -0x8007A114 - near-match - -0x800A8AEC - near-match - diff --git a/config/regions.tsv b/config/regions.tsv index 10bf42b..820000c 100644 --- a/config/regions.tsv +++ b/config/regions.tsv @@ -18,8 +18,11 @@ 0x800129C8 0x80012A10 src/func_800129C8.c 0x80012D8C 0x80012DBC src/func_80012D8C.c 0x80012DBC 0x80012DE8 src/func_80012DBC.c +0x80012F24 0x80012F80 src/func_80012F24.c 0x80013C88 0x80013C90 src/func_80013C88.c 0x80013D04 0x80013D44 src/func_80013D04.c +0x8001587C 0x8001590C src/func_8001587C.c +0x80015D50 0x80015DBC src/func_80015D50.c gp=-D_80121B88 0x800160E8 0x80016110 src/func_800160E8.c 0x80016110 0x80016120 src/func_80016110.c 0x80016120 0x80016158 src/func_80016120.c @@ -52,6 +55,7 @@ 0x8001AA9C 0x8001AAA8 src/func_8001AA9C.c 0x8001AE3C 0x8001AE50 src/func_8001AE3C.c 0x8001CE40 0x8001CE70 src/func_8001CE40.c +0x80021C64 0x80021CDC src/func_80021C64.c 0x80021F24 0x80021F50 src/func_80021F24.c 0x80021F50 0x80021F64 src/func_80021F50.c 0x80021F64 0x80021F88 src/func_80021F64.c @@ -61,6 +65,7 @@ 0x80022A60 0x80022A98 src/func_80022A60.c 0x80022FB8 0x80022FCC src/func_80022FB8.c 0x80022FCC 0x80022FFC src/func_80022FCC.c +0x80023080 0x800230E4 src/func_80023080.c 0x800230E4 0x8002311C src/func_800230E4.c 0x80024C14 0x80024C34 src/func_80024C14.c 0x80025070 0x800250AC src/func_80025070.c @@ -76,6 +81,7 @@ 0x80026C2C 0x80026C7C src/func_80026C2C.c 0x80026F14 0x80026F3C src/func_80026F14.c 0x800276B0 0x800276D4 src/func_800276B0.c +0x80027E1C 0x80027ECC src/func_80027E1C.c 0x80028150 0x800281A4 src/func_80028150.c 0x800281A4 0x800281E4 src/func_800281A4.c 0x800282EC 0x80028344 src/func_800282EC.c @@ -86,6 +92,7 @@ 0x8002AC84 0x8002ACBC src/func_8002AC84.c 0x8002C6EC 0x8002C728 src/func_8002C6EC.c 0x8002C728 0x8002C764 src/func_8002C728.c +0x8002C764 0x8002C7BC src/func_8002C764.c 0x8002C7BC 0x8002C7EC src/func_8002C7BC.c 0x8002C888 0x8002C894 src/func_8002C888.c 0x8002C894 0x8002C8A4 src/func_8002C894.c @@ -100,7 +107,9 @@ 0x8002E3FC 0x8002E44C src/func_8002E3FC.c 0x8002E4C8 0x8002E4F0 src/func_8002E4C8.c 0x8002E7C4 0x8002E7E4 src/func_8002E7C4.c +0x8002E870 0x8002E8EC src/func_8002E870.c 0x8002E968 0x8002E9AC src/func_8002E968.c +0x8002F0D0 0x8002F118 src/func_8002F0D0.c 0x8002F160 0x8002F1A4 src/func_8002F160.c 0x8002F1A4 0x8002F1D8 src/func_8002F1A4.c 0x8002F2F8 0x8002F300 src/func_8002F2F8.c @@ -129,9 +138,11 @@ 0x8003B2F0 0x8003B320 src/func_8003B2F0.c 0x8003B320 0x8003B34C src/func_8003B320.c 0x8003CB8C 0x8003CBE4 src/func_8003CB8C.c +0x800419D0 0x80041A24 src/func_800419D0.c 0x80041A24 0x80041A58 src/func_80041A24.c 0x80042088 0x80042090 src/func_80042088.c 0x80042964 0x800429B0 src/func_80042964.c +0x800429B0 0x800429F0 src/func_800429B0.c 0x80042D64 0x80042D88 src/func_80042D64.c 0x80043D8C 0x80043DC4 src/func_80043D8C.c 0x80044F58 0x80044FA4 src/func_80044F58.c gp=-D_80121BFC @@ -139,6 +150,7 @@ 0x80045388 0x800453C0 src/func_80045388.c 0x800453C0 0x800453F8 src/func_800453C0.c 0x800474B0 0x80047508 src/func_800474B0.c +0x80047984 0x80047A14 src/func_80047984.c 0x80048E20 0x80048E70 src/func_80048E20.c 0x80049298 0x800492E4 src/func_80049298.c gp=-D_80121BFC 0x8004C060 0x8004C090 src/func_8004C060.c @@ -151,6 +163,7 @@ 0x8005182C 0x80051864 src/func_8005182C.c 0x80052C98 0x80052CAC src/func_80052C98.c 0x80057524 0x80057564 src/func_80057524.c +0x80057564 0x800575C4 src/func_80057564.c 0x80057748 0x80057798 src/func_80057748.c 0x80057798 0x800577E8 src/func_80057798.c 0x800577E8 0x8005784C src/func_800577E8.c @@ -171,6 +184,7 @@ 0x80058230 0x80058288 src/func_80058230.c 0x80058288 0x800582AC src/func_80058288.c 0x8005E3D0 0x8005E3F4 src/func_8005E3D0.c +0x8005E79C 0x8005E820 src/func_8005E79C.c 0x8005ED6C 0x8005EDBC src/func_8005ED6C.c 0x800658FC 0x80065930 src/func_800658FC.c 0x80065930 0x80065980 src/func_80065930.c @@ -202,6 +216,7 @@ 0x80073250 0x80073284 src/func_80073250.c 0x80073364 0x800733C4 src/func_80073364.c 0x800734A4 0x800734DC src/func_800734A4.c +0x80074C00 0x80074C74 src/func_80074C00.c 0x8007A404 0x8007A428 src/func_8007A404.c 0x8007C4A8 0x8007C4EC src/func_8007C4A8.c 0x8007C4EC 0x8007C524 src/func_8007C4EC.c @@ -213,8 +228,10 @@ 0x80082750 0x800827A8 src/func_80082750.c 0x800827A8 0x800827C4 src/func_800827A8.c 0x80082914 0x80082944 src/func_80082914.c +0x800833CC 0x80083440 src/func_800833CC.c 0x80083440 0x80083470 src/func_80083440.c 0x80083470 0x800834B8 src/func_80083470.c +0x800834B8 0x80083504 src/func_800834B8.c 0x80083504 0x8008352C src/func_80083504.c 0x8008352C 0x8008355C src/func_8008352C.c 0x80085B80 0x80085B90 src/func_80085B80.c @@ -230,6 +247,8 @@ 0x8008B8E4 0x8008B8F4 src/func_8008B8E4.c 0x8008B8F4 0x8008B910 src/func_8008B8F4.c 0x8008B910 0x8008B960 src/func_8008B910.c +0x8008D9AC 0x8008DA0C src/func_8008D9AC.c +0x8008F2E0 0x8008F338 src/func_8008F2E0.c 0x8008F4A0 0x8008F4AC src/func_8008F4A0.c 0x8008F4AC 0x8008F4F4 src/func_8008F4AC.c 0x8008F4F4 0x8008F508 src/func_8008F4F4.c @@ -239,10 +258,12 @@ 0x80090028 0x80090048 src/func_80090028.c 0x80090048 0x80090058 src/func_80090048.c 0x800900A0 0x800900CC src/func_800900A0.c +0x80090894 0x800908E4 src/func_80090894.c 0x80090A44 0x80090A70 src/func_80090A44.c 0x80090B64 0x80090B7C src/func_80090B64.c 0x80090B7C 0x80090BB4 src/func_80090B7C.c 0x80090C8C 0x80090CAC src/func_80090C8C.c +0x80090CAC 0x80090D00 src/func_80090CAC.c 0x8009107C 0x800910B0 src/func_8009107C.c 0x800912D4 0x800912FC src/func_800912D4.c 0x800912FC 0x8009132C src/func_800912FC.c @@ -252,10 +273,13 @@ 0x800920BC 0x800920DC src/func_800920BC.c 0x800920DC 0x80092104 src/func_800920DC.c 0x80092130 0x8009214C src/func_80092130.c +0x8009214C 0x800921C0 src/func_8009214C.c +0x80093A08 0x80093A64 src/func_80093A08.c 0x80093A64 0x80093A84 src/func_80093A64.c 0x800943C4 0x800943E0 src/func_800943C4.c 0x80096324 0x80096364 src/func_80096324.c 0x80099024 0x80099078 src/func_80099024.c +0x80099078 0x8009916C src/func_80099078.c 0x80099A94 0x80099AE4 src/func_80099A94.c 0x80099DC4 0x80099E14 src/func_80099DC4.c 0x80099E14 0x80099E34 src/func_80099E14.c @@ -273,6 +297,9 @@ 0x800A6268 0x800A6294 src/func_800A6268.c 0x800A648C 0x800A64C8 src/func_800A648C.c 0x800A6840 0x800A6880 src/func_800A6840.c +0x800A6934 0x800A6998 src/func_800A6934.c +0x800A6A18 0x800A6A70 src/func_800A6A18.c +0x800A6BEC 0x800A6C34 src/func_800A6BEC.c cc1=-G8 0x800A745C 0x800A74BC src/func_800A745C.c 0x800A74BC 0x800A74D0 src/func_800A74BC.c 0x800A8B48 0x800A8B8C src/func_800A8B48.c @@ -284,14 +311,17 @@ 0x800AA56C 0x800AA59C src/func_800AA56C.c 0x800AC818 0x800AC85C src/func_800AC818.c 0x800AC85C 0x800AC884 src/func_800AC85C.c +0x800ACAC8 0x800ACB34 src/func_800ACAC8.c 0x800ACC00 0x800ACC20 src/func_800ACC00.c 0x800AE0F4 0x800AE10C src/func_800AE0F4.c +0x800AE4DC 0x800AE548 src/func_800AE4DC.c 0x800AE548 0x800AE574 src/func_800AE548.c 0x800AF1FC 0x800AF20C src/func_800AF1FC.c 0x800AF20C 0x800AF260 src/func_800AF20C.c 0x800AFB1C 0x800AFB6C src/func_800AFB1C.c 0x800AFFB8 0x800AFFE4 src/func_800AFFB8.c 0x800B0E30 0x800B0E64 src/func_800B0E30.c +0x800B1D5C 0x800B1DD0 src/func_800B1D5C.c 0x800B24EC 0x800B2534 src/func_800B24EC.c 0x800B2534 0x800B255C src/func_800B2534.c 0x800B3474 0x800B34A4 src/func_800B3474.c @@ -302,6 +332,7 @@ 0x800B6838 0x800B6894 src/func_800B6838.c 0x800B6BDC 0x800B6C14 src/func_800B6BDC.c 0x800B6C14 0x800B6C60 src/func_800B6C14.c +0x800B6C60 0x800B6CB4 src/func_800B6C60.c 0x800B7230 0x800B7264 src/func_800B7230.c 0x800B74D0 0x800B7524 src/func_800B74D0.c 0x800BBDEC 0x800BBDF8 src/func_800BBDEC.c @@ -388,6 +419,7 @@ 0x80104C38 0x80104C60 src/func_80104C38.c maspsx=off 0x80104C6C 0x80104CA0 src/func_80104C6C.c maspsx=off 0x8010513C 0x80105148 src/func_8010513C.c +0x80105148 0x801051CC src/func_80105148.c 0x8010543C 0x80105474 src/func_8010543C.c 0x80105B34 0x80105B54 src/func_80105B34.c 0x80105B54 0x80105B68 src/func_80105B54.c diff --git a/config/symbols.tsv b/config/symbols.tsv index dded457..f076b0d 100644 --- a/config/symbols.tsv +++ b/config/symbols.tsv @@ -46,6 +46,7 @@ D_80121A80 0x80121A80 gp D_80121A88 0x80121A88 gp D_80121AAC 0x80121AAC gp D_80121AD0 0x80121AD0 gp +D_80121AD4 0x80121AD4 gp D_80121B14 0x80121B14 gp D_80121B18 0x80121B18 gp D_80121B1C 0x80121B1C gp @@ -356,6 +357,8 @@ D_801226EC 0x801226EC gp D_801226F0 0x801226F0 gp D_801226F4 0x801226F4 gp D_801226F8 0x801226F8 gp +D_80122700 0x80122700 gp +D_80122704 0x80122704 gp D_80122708 0x80122708 gp D_80122714 0x80122714 gp D_80122716 0x80122716 gp diff --git a/docs/MATCHING_COOKBOOK.md b/docs/MATCHING_COOKBOOK.md index 9d3b2d1..4900266 100644 --- a/docs/MATCHING_COOKBOOK.md +++ b/docs/MATCHING_COOKBOOK.md @@ -639,3 +639,47 @@ Phase 10 takes the rare-epilogue classes on. Sony/SN toolchain story is the hypothesis for Phase 10's Goal B. - The exact `-G`, the CRT entry, and library-versus-game-code remain unresolved, with the class exclusions now precisely bounded. + +## Phase 10 — findings 40+ (coordinated tail squeeze, 2026-09-24) + +### 40. The rare epilogue's mechanism, and why the obvious maspsx fix does not work + +Finding 35's class is now mechanistically closed. GNU `as` in reorder mode fills a jump delay +slot with the immediately-preceding instruction, but **refuses when doing so would place `jr ra` +in the load-delay slot of `lw ra`**. So the class splits on whether any instruction intervenes +between `lw ra` and the frame release: + +| source before the `j $31` | `as` output | filled? | +|---|---|---| +| `lw ra,20(sp)` / `lw s0,16(sp)` / `addu sp,sp,24` | `lw ra` / `lw s0` / `jr ra` / `addiu sp,sp,24` | yes | +| `lw ra,16(sp)` / `addu sp,sp,24` | `lw ra` / `addiu sp,sp,24` / `jr ra` / `nop` | no | +| `addu sp,sp,24` alone | `jr ra` / `addiu sp,sp,24` | yes | +| `lw ra,16(sp)` / `nop` / `j $31` / `addiu` | `lw ra` / `nop` / `jr ra` / `nop` / `addiu` | no (does not remove an existing nop) | + +**Decision rule (costs one compile):** compile the row and read the CANDIDATE's `.s`, not the +original. If the epilogue sits inside cc1's own `.set noreorder` block (which happens when a +macro-using insn such as `move` is present), cc1 filled the slot itself and the row is ordinary. +If cc1 left the slot empty, check the hazard: an intervening instruction means `as` *can* fill it; +`lw ra` immediately before the release means it cannot, and the row is a harness row. + +**The obvious fix is closed, measured.** maspsx normally forces the whole function into +`.set noreorder` (it emits it after every `.ent`) and then supplies every delay slot itself, so +`as` never gets a chance to fill. Suppressing only maspsx's jump-slot `nop` therefore restores the +correct *length* but leaves the `jr ra` with an **empty** delay slot, because `as` will not insert +one under `.set noreorder`. Also suppressing the function-level `.set noreorder` lets `as` fill +the epilogue *correctly* (`lw ra` / `lw s2` / `lw s1` / `lw s0` / `jr ra` / `addiu sp,sp,32`, exactly +the original) — but then `as` over-fills *other* slots and the region comes out +4 bytes. Switching +to `.set reorder` at the jump alone does not re-enable the fill; reorder mode must be in effect from +the function start. + +*Basis:* coordinator measurements with the repo's binutils, plus worker A's per-guard classifier, +worker B's standalone `as` test and maspsx source citation (`maspsx/__init__.py`, the branch/jump +`nop` adjacent to the `move` expansion), and worker C's `0x800FFF60`/`0x800F6948` observations — +the three reports disagreed and the disagreement is what produced the rule above. +*Limit:* the only remaining route is a tracked post-pass that performs exactly one transform (move +the frame release into the jump slot, inserting the load-delay `nop` where required), i.e. modelling +ASPSX's fill for that site on maspsx's output. That is a developer-owned harness decision and was not +taken in Phase 10. The two opt-in maspsx modes shipped in Phase 10 (`maspsx=noreordernop`, +`maspsx=regread`) are implemented and default-off but **neither has been shown to close a region**: +on `0x800FFF60` R1 makes the length *worse* (140 → 128) because it also removes `nop`s the original +needs, and R2's predicate did not fire. diff --git a/docs/SETUP.md b/docs/SETUP.md index 59b3210..f28f58e 100644 --- a/docs/SETUP.md +++ b/docs/SETUP.md @@ -70,6 +70,29 @@ P3-T3 also added ignored local GNU Binutils and Maspsx candidates after explicit | GNU Binutils cross tools | 2.46.0, target `mipsel-none-elf` | AUR recipe `mipsel-none-elf-binutils 2.46.0-1`, fetched with `paru -G` into ignored `tools/mipsel-none-elf-binutils/`. Its GNU FTP source archive passed recipe SHA-256 `d75a94f4d73e7a4086f7513e67e439e8fcdcbb726ffe63f4661744e6256b2cf2` and PGP verification using imported recipe-declared Nick Clifton fingerprint `3A24BC1E8FB409FA9F14371813FCEF89DD9E3C4F`. Built locally with `makepkg --noconfirm --nocheck` and extracted to ignored `prefix/`; never installed system-wide. | | Maspsx | tagged `aspsx` commit `86ccd7d8c89682c0562d1425bbb15a09f42eb522` | Cloned from `https://github.com/mkst/maspsx.git` into ignored `tools/maspsx/`. It is a GNU-as compatibility transformer for GCC output, not the original ASPSX or a verified USA matching tool. It was inspected but not required for the P3-T3 payload-data build. | +### Maspsx local patch (Phase 10) + +`tools/maspsx/` is **ignored**, so a local edit there is invisible to a fresh clone and would silently +break reproducibility. Phase 10's two opt-in maspsx modes are therefore carried as a **tracked patch**: + +```bash +# from tools/ +patch -p1 < patches/maspsx-phase10-r1r2.patch +``` + +The patch applies to the pinned `86ccd7d8` checkout above and touches exactly two files +(`maspsx/__init__.py`, `maspsx.py`). It was verified by reconstructing the pristine files, applying the +patch, and diffing the result against the working tree (byte-identical). It adds: + +- `--no-jump-slot-nop` (region token `maspsx=noreordernop`) — suppress the unconditional reorder `nop` + after a branch/jump so GNU `as` can fill the slot. +- `--nop-on-reg-read` (region token `maspsx=regread`) — extend the load-delay predicate (cookbook + finding 27) so a following `jr`/`jalr` that *uses* the loaded register also gets the delay `nop`. + +Both default **off**, and `make check` is green at 439 regions with them off, so the matched corpus is +byte-identical. **Status: implemented, but neither mode has been shown to close a region.** See +`docs/MATCHING_COOKBOOK.md` finding 40 for the measured negative result before relying on them. + The local GNU assembler accepted self-authored COP2 and Splat GTE-macro synthetic sources, while LLVM's MIPS assembler did not. This is assembler-capability evidence only; it does not identify the original assembler or compiler. P3-T5 added tracked synthetic-only `tools/sf3_fingerprint_probe`. It writes a self-authored C fixture into a caller-selected new output directory, compiles twice with explicitly supplied paths, assembles both outputs, and requires byte-identical objects. Its validated invocation is: diff --git a/phase-ends/CURRENT_PHASE.md b/phase-ends/CURRENT_PHASE.md index 26e19be..5dfa3c6 100644 --- a/phase-ends/CURRENT_PHASE.md +++ b/phase-ends/CURRENT_PHASE.md @@ -107,6 +107,34 @@ candidate-gate-before-promote step is wired correctly for this phase. | Cycle | New bodies | Total bodies | New regions | Total regions | Result | |---|---|---|---|---|---| | (baseline) | — | 400 | — | 409 | green, head `25bf4a3` | +| 1 (in progress) | +32 | **432** | +32 | **441** | gate MATCH, `make check` green, full clean audit green | + +Worker yield at this point: A 7 claims, B 11 claims (1 negative, 1 deferred, 1 R1-pending), +C 14 claims. All 32 new bodies verified by the coordinator on the candidate whole-binary gate +before promotion; the registry has never been corrupted. + +## R1/R2 harness outcome (P10-T2) — measured negative result + +The developer authorised both maspsx modes. Both are implemented as **opt-in** modes +(`maspsx=noreordernop`, `maspsx=regread`), carried as a **tracked patch** +(`tools/patches/maspsx-phase10-r1r2.patch`, verified to reproduce the working tree byte-identically +from the pristine pinned checkout), and documented in `docs/SETUP.md`. + +**Neither mode has been shown to close a region, and this is recorded as a negative result.** + +- `make check` is green at 441 regions with both modes off, and the suite grew 229 → 232 tests, so the + default path is provably unchanged. +- **R1** (suppress the jump-slot `nop`) restores the correct LENGTH on worker B's acceptance row + `0x80102A80` (136 → 132) but leaves the `jr ra` with an **empty** delay slot, because maspsx forces + the function into `.set noreorder` and `as` will not insert one there. Also suppressing the + function-level `.set noreorder` makes `as` fill the epilogue *exactly* right — and then over-fill + other slots, for +4 bytes. +- On worker C's `0x800FFF60`, R1 makes the length **worse** (140 → 128) because it also removes `nop`s + the original needs — worker A's "second victim" warning, confirmed. +- **R2**'s extended predicate did not fire on the tested row. + +The mechanism and the remaining (developer-owned) route — a tracked post-pass modelling ASPSX's fill +for that one site — are recorded as cookbook finding 40. ## Open protocol notes diff --git a/phase-ends/logs/Phase10.md b/phase-ends/logs/Phase10.md index 2b67348..0e254ba 100644 --- a/phase-ends/logs/Phase10.md +++ b/phase-ends/logs/Phase10.md @@ -192,3 +192,51 @@ register numbering. | Cycle | New bodies | Total bodies | New regions | Total regions | Result | |---|---|---|---|---|---| | (baseline) | — | 400 | — | 409 | green, head `25bf4a3` | + +--- + +## Cycle 1 — merges 1-7 (2026-09-24) + +**432 distinct bodies / 441 regions**, from 400 / 409. All merges followed the hardened flow: +`sf3_merge apply` → candidate → **whole-binary gate** → promote → `make check`. The candidate gate was +run before every promotion and the tracked registry was never touched by a failing batch. + +| Merge | Worker | Added | Result | +|---|---|---|---| +| 1 | A(2) + B(5) | 7 regions, 2 symbols | gate MATCH | +| 2 | C(8) | 8 regions | gate MATCH | +| 3 | B(6-8) | 3 regions (5 skipped as registered) | gate MATCH | +| 4 | C(9-12) + A(3) | 5 regions | gate MATCH | +| 5 | B(9-11) | 3 regions, 1 symbol | gate MATCH | +| 6 | A(4-7) | 4 regions | gate MATCH | +| 7 | C(13-14) | 2 regions | gate MATCH | + +**Registry-row requests granted** (each byte-verified by the coordinator with a failing control): +`cc1=-G8` on `0x800A6BEC`; `gp=-D_80121B88` on `0x80015D50`; symbol rows `D_80122700`, `D_80122704`, +`D_80121AD4` (all `gp`). + +**Negatives reconciled:** `0x8010AA28` imported (maspsx mutual exclusion, finding 17's purest form). +The tracked index was also **sorted by address** and its 6 stale registered rows were dropped at +P10-T1, so it now carries a checkable ordering invariant: 140 rows, address-ordered, 0 duplicates, +0 registered. + +**Worklist/partition discipline.** The tracked worklist regenerates every merge +(`excluded_already_registered` always equals the registry size). Partitions were **filtered against the +new worklist** rather than re-interleaved mid-cycle, so an address cannot migrate between workers while +they are working down it; the union/disjointness proof was re-run after each filter. A full re-interleave +is reserved for the cycle boundary. + +**Full clean audit (due at the 3rd merge, run at merge 7):** +`make clean && make all` exit 0; `cmp` exit 0; both SHA-1 +`e173426c157384ebf1b6caf8c6fea18a85a14af9`; registry 441 rows / 0 overlaps / 0 unsorted / 0 bad extents / +0 missing sources / 432 distinct sources; 0 tracked paths under any prohibited root; 508 tracked files. + +**Deviations and decisions.** The developer approved the three-worker roster (plan said two); the +per-region `-G` override route (global `-G0` unchanged, so the 400-body corpus is untouched); and both +R1/R2 maspsx modes. R1/R2 are recorded as a **measured negative result** — implemented, default-off, +`make check` green at 441, but neither closes a region (cookbook finding 40, `CURRENT_PHASE.md`). + +**Coordinator-side dispatch aid (ignored, `.run/p10/`).** The family-set map, built up front instead of +reactively: 378 worklist rows call an already-registered function (the P1 pool). Two bugs were found and +fixed before dispatch (little-endian payload decode; call-site double-count). Per-partition lever files +rank each worker's rows P1 (known callee) → P2 (intra-worklist family) → P3 (small tier-1 leaf) → P4. diff --git a/src/func_80012F24.c b/src/func_80012F24.c new file mode 100644 index 0000000..92aaa6c --- /dev/null +++ b/src/func_80012F24.c @@ -0,0 +1,79 @@ +/* func_80012F24 — 0x80012F24..0x80012F80 (92 bytes). + * + * Original words (objdump of the validated payload, little-endian): + * addiu sp,sp,-40 + * addiu a0,sp,24 a0 = &e (sp+24) + * sw ra,32(sp) + * jal 0x80021F88 + * _addiu a1,sp,26 (delay slot) a1 = &f (sp+26) + * addiu a0,sp,16 a0 = &s (sp+16) + * move a1,zero + * move a2,zero + * lhu v1,24(sp) v1 = e (UNSIGNED halfword) + * lhu v0,26(sp) v0 = f (UNSIGNED halfword) + * move a3,zero + * sh zero,18(sp) s.b = 0 (b BEFORE a) + * sh zero,16(sp) s.a = 0 + * sll v0,v0,0x1 f * 2 + * sh v1,20(sp) s.c = e + * jal 0x800F421C + * _sh v0,22(sp) (delay slot) s.d = f * 2 + * jal 0x800F4098 + * _move a0,zero (delay slot) + * lw ra,32(sp) + * addiu sp,sp,40 + * jr ra + * _nop + * + * Builds a four-halfword record from two values filled in by an out-parameter + * callee and hands it to a four-argument callee, then runs a final call with a + * zero argument. The frame is 40 bytes = 16 (o32 outgoing args) + 12 of locals + * (the 8-byte record at sp+16 plus the two halfwords at sp+24/26) + the saved ra + * at sp+32. `func_80021F88` writes through its two `short *` out parameters, and + * the record is passed by address as argument 0 of `func_800F421C`. + * + * TWO LEVERS this body turns on, both found by dumping the word streams: + * + * 1. `lhu`, not `lh`: the two out-parameters are read as UNSIGNED halfwords, so + * `e` and `f` are `unsigned short`. Declared `short` the same source emits + * `lh v0,26(sp)` — 1 differing byte at 0x80012F48 — and (knock-on) also + * swaps the two `sh zero` stores. The callee's own registered prototype is + * `short *`, but only the caller-side declaration is visible here, so the + * out-parameters are declared `unsigned short *` to match the `lhu`. + * + * 2. CHAINED ASSIGNMENT REVERSES STORE ORDER: the two zeroing stores are + * `sh zero,18(sp)` THEN `sh zero,16(sp)` — field b before field a. Written + * as two statements in field order (`s.a = 0; s.b = 0;`) the stores come out + * 16 then 18 and differ by 2 bytes at 0x80012F50. Written `s.a = s.b = 0;` + * the inner assignment is evaluated first, so b is stored before a and the + * body is byte-identical. Same family as the commutative-operand lever: the + * bytes encode an ORDER that only the source spelling controls. + * + * LIMITS (unresolved, recorded rather than guessed): whether the two out-values + * are separate locals copied into the record (as written here: 8-byte record at + * sp+16, e at sp+24, f at sp+26) or the record's own fifth and sixth halfword + * fields (a 12-byte record) is NOT observable — both layouts put e/f at sp+24/26 + * and both compile byte-identically, so the frame is 40 either way. The + * separate-local reading is shipped as the more natural one. The purpose of the + * record, the meaning of `f * 2`, the two callees and the zero argument are not + * observable. Only the compiled bytes are evidence. + */ + +struct S { short a, b, c, d; }; + +extern int func_80021F88(unsigned short *first, unsigned short *second); +extern void func_800F421C(struct S *s, int a1, int a2, int a3); +extern void func_800F4098(int a0); + +void func_80012F24(void) +{ + struct S s; + unsigned short e, f; + + func_80021F88(&e, &f); + s.a = s.b = 0; + s.c = e; + s.d = f * 2; + func_800F421C(&s, 0, 0, 0); + func_800F4098(0); +} diff --git a/src/func_8001587C.c b/src/func_8001587C.c new file mode 100644 index 0000000..40ed999 --- /dev/null +++ b/src/func_8001587C.c @@ -0,0 +1,82 @@ +/* + * func_8001587C — 144 bytes at 0x8001587C..0x8001590C + * + * Byte-identical reconstruction of a framed range-checked converter: an index + * at or above 2048 is rejected with 1, otherwise two stack temporaries are + * filled, a halved index is looked up, and on success the halved temporary is + * converted and stored through the caller's pointer. + * + * The observed instructions are: + * addiu sp,sp,-40 + * sw s0,24(sp) + * move s0,a0 s0 = index + * sw s1,28(sp) + * move s1,a1 s1 = out + * slti v0,s0,2048 + * bnez v0,0x800158A4 + * sw ra,32(sp) (delay slot) + * j 0x800158F4 + * li v0,1 (delay slot) return 1 + * addiu a0,sp,16 + * jal 0x80021F88 + * addiu a1,sp,18 (delay slot) + * srl a0,s0,0x1f + * addu a0,s0,a0 + * sra a0,a0,0x1 index / 2 + * jal 0x80023080 + * addiu a1,sp,20 (delay slot) + * bnez v0,0x800158F4 if (r != 0) return r + * nop + * lhu v0,16(sp) the first temporary + * lw a1,20(sp) the looked-up word + * sll v0,v0,0x10 + * sra a0,v0,0x10 (short)tmp + * srl v0,v0,0x1f + * addu a0,a0,v0 + * jal 0x80010698 + * sra a0,a0,0x1 (delay slot) (short)tmp / 2 + * sw v0,0(s1) *out = converted + * move v0,zero return 0 + * lw ra,32(sp) + * lw s1,28(sp) + * lw s0,24(sp) + * addiu sp,sp,40 + * jr ra + * nop + * + * The frame is 40 bytes: the 16-byte o32 outgoing argument area, three locals + * at 16/18/20 (two 16-bit temporaries and a word), `s0` at 24(sp), `s1` at + * 28(sp) and `ra` at 32(sp). `lhu` followed by `sll`/`sra` is why the first + * temporary is declared `unsigned short` and then explicitly cast to `short` + * before the halving: a plain `short` would have loaded with `lh` and needed + * no extension. Both halvings are the signed `/ 2` idiom (`srl`+`addu`+`sra`), + * not a shift. + * + * LIMITS: the function names, the callees' arities and parameter types, the + * limit 2048 and the locals' meanings are hypotheses reconstructed from the + * disassembly. Only the compiled bytes are evidence. The `if (r != 0) return + * r;` shape follows from the `bnez` reaching the shared epilogue without + * materialising a constant. + */ + +void func_80021F88(short *, short *); +int func_80023080(int, int *); +int func_80010698(int, int); + +int func_8001587C(int index, int *out) { + unsigned short tmp; + unsigned short unused; + int word; + int r; + + if (index >= 2048) + return 1; + + func_80021F88((short *)&tmp, (short *)&unused); + r = func_80023080(index / 2, &word); + if (r != 0) + return r; + + *out = func_80010698((short)tmp / 2, word); + return 0; +} diff --git a/src/func_80015D50.c b/src/func_80015D50.c new file mode 100644 index 0000000..caadb12 --- /dev/null +++ b/src/func_80015D50.c @@ -0,0 +1,76 @@ +/* + * func_80015D50 — 108 bytes at 0x80015D50..0x80015DBC + * + * Accumulator flush: adds a pending delta into three counters, clears the delta, + * then re-arms only when a mode global equals 4. + * + * Original words: + * 8F860074 lw a2,116(gp) ; a2 = D_801219AC (hoisted above the frame) + * 27BDFFE8 addiu sp,sp,-24 + * 10C00014 beq a2,zero,0x80015DAC ; nothing pending -> return + * AFBF0010 sw ra,16(sp) ; (delay) + * 8F85006C lw a1,108(gp) ; a1 = D_801219A4 + * 8F820070 lw v0,112(gp) ; v0 = D_801219A8 + * 8F8308B4 lw v1,2228(gp) ; v1 = D_801221EC (a DIFFERENT address) + * AF800074 sw zero,116(gp) ; D_801219AC = 0 + * 00A62821 addu a1,a1,a2 ; a1 += delta + * 00461021 addu v0,v0,a2 ; v0 += delta + * 00651821 addu v1,v1,a1 ; v1 += the NEW D_801219A4 + * AF85006C sw a1,108(gp) ; D_801219A4 = a1 + * AF820070 sw v0,112(gp) ; D_801219A8 = v0 + * AF8308B8 sw v1,2232(gp) ; D_801221F0 = v1 + * 0C03D026 jal 0x800F4098 + * 00002021 addu a0,zero,zero ; (delay) func_800F4098(0) + * 3C038012 lui v1,0x8012 + * 8C631B88 lw v1,7048(v1) ; v1 = D_80121B88 (ABSOLUTE, not gp-relative) + * 24020004 addiu v0,zero,4 + * 14620003 bne v1,v0,0x80015DAC ; mode != 4 -> return + * 00000000 nop + * 0C00B1BB jal 0x8002C6EC + * 24040006 addiu a0,zero,6 ; (delay) func_8002C6EC(6) + * 8FBF0010 lw ra,16(sp) + * 27BD0018 addiu sp,sp,24 + * 03E00008 jr ra + * 00000000 nop + * + * The read at `2228(gp)` and the write at `2232(gp)` are 4 bytes apart and are + * DIFFERENT globals: D_801221F0 is assigned `D_801221EC + `, + * not an increment of one address. The three loads are hoisted above the + * `sw zero,116(gp)` and above the additions by the scheduler. + * + * PER-SITE gp OVERRIDE: D_80121B88 carries a registry `gp` marker but the original + * reads it ABSOLUTELY (`lui v1,0x8012` / `lw v1,7048(v1)`), so this region needs + * `gp=-D_80121B88` — the same per-site form difference as cookbook finding 16. + * The other five globals are genuinely gp-relative. + * + * LIMITS: the function name, both callees, all six globals and the meaning of the + * constants 0, 4 and 6 are hypotheses read from the instruction shape; only the + * bytes are evidence. The delta is a local in a2 and the accumulator in a1; the + * third counter's addend is a distinct global load. + */ + +extern int D_801219AC; +extern int D_801219A4; +extern int D_801219A8; +extern int D_801221EC; +extern int D_801221F0; +extern int D_80121B88; +extern void func_800F4098(int a0); +extern void func_8002C6EC(int a0); + +void func_80015D50(void) +{ + int delta = D_801219AC; + + if (delta == 0) + return; + + D_801219AC = 0; + D_801219A4 += delta; + D_801219A8 += delta; + D_801221F0 = D_801221EC + D_801219A4; + func_800F4098(0); + + if (D_80121B88 == 4) + func_8002C6EC(6); +} diff --git a/src/func_80021C64.c b/src/func_80021C64.c new file mode 100644 index 0000000..93592aa --- /dev/null +++ b/src/func_80021C64.c @@ -0,0 +1,86 @@ +/* func_80021C64 — 0x80021C64..0x80021CDC (120 bytes). + * + * Original words (objdump of the validated payload, little-endian): + * addiu sp,sp,-32 + * sw s0,24(sp) + * move s0,a0 s0 = the parameter (kept across all four calls) + * sw ra,28(sp) + * addiu a1,gp,412 a1 = &D_80121AD4 (gp + 412 = 0x80121AD4) + * lwl v0,3(a1) \ 8-byte UNALIGNED block copy + * lwr v0,0(a1) | (lwl/lwr + swl/swr, not lw/sw) + * lwl v1,7(a1) | + * lwr v1,4(a1) | + * swl v0,19(sp) | + * swr v0,16(sp) | + * swl v1,23(sp) | + * swr v1,20(sp) / + * jal 0x800F3E8C + * _move a0,zero (delay slot) + * addiu a0,sp,16 a0 = &s (sp+16) + * move a1,zero + * move a2,zero + * jal 0x800F421C + * _move a3,zero (delay slot) + * jal 0x800F4098 + * _move a0,zero (delay slot) + * sll s0,s0,0x10 \ narrow the parameter to 16 bits + * jal 0x800F8FE4 | + * _sra a0,s0,0x10 (delay slot) a0 = (short)parameter + * lw ra,28(sp) + * lw s0,24(sp) + * addiu sp,sp,32 + * jr ra + * _nop + * + * Copies an 8-byte object out of the small-data block, hands it to a + * four-argument callee, brackets it with two zero-argument calls, and finally + * forwards the parameter narrowed to 16 bits. The frame is 32 bytes = 16 (o32 + * outgoing args) + the 8-byte local at sp+16 + the saved s0/ra pair. + * + * WHY THE COPY IS `lwl/lwr` AND NOT `lw`: the eight-byte move uses the unaligned + * halfword/word forms on BOTH sides — including the destination, which is a + * frame slot at sp+16 that is in fact 4-byte aligned. cc1 only does that when the + * move's alignment is 1, so both the local and the source global are + * byte-aligned objects: `struct S { char c[8]; }` on both sides reproduces it. + * The global is addressed by `addiu a1,gp,412`, i.e. its ADDRESS is taken + * gp-relative, which is the address-taking form of the registry `gp` marker. + * + * The final `sll 16` / `sra 16` pair is the caller-side narrowing of an argument + * to a 16-bit parameter, so the last callee takes a `short` (or the source casts + * to `short`). `func_800F8FE4` is registered taking `int`, and passing a narrowed + * value to it is what the bytes show. + * + * SYMBOL DEPENDENCY: `D_80121AD4` is NOT yet in config/symbols.tsv. It must be + * added with the `gp` marker (see .run/p10/w-b/symbols-request.tsv) or the + * address is materialised absolutely (`lui`+`addiu`) instead of `addiu a1,gp,412`. + * This claim was verified against a local overlay of the tracked registry plus + * that row. + * + * LIMITS (unresolved, recorded rather than guessed): the parameter's declared + * type is NOT observable — `int a0` with `func_800F8FE4((short)a0)` and + * `short a0` with `func_800F8FE4(a0)` both compile byte-identically, because the + * sign-extension happens lazily at the call site rather than on entry; the + * `short` form is shipped as the cleaner reading. The object's real type (char + * array vs a packed structure) is not observable beyond its 8-byte size and + * alignment 1, and the three callees' names and semantics are hypotheses. Only + * the compiled bytes are evidence. + */ + +struct S { char c[8]; }; + +extern struct S D_80121AD4; +extern void func_800F3E8C(int a0); +extern void func_800F421C(struct S *s, int a1, int a2, int a3); +extern void func_800F4098(int a0); +extern int func_800F8FE4(int value); + +void func_80021C64(short a0) +{ + struct S s; + + s = D_80121AD4; + func_800F3E8C(0); + func_800F421C(&s, 0, 0, 0); + func_800F4098(0); + func_800F8FE4(a0); +} diff --git a/src/func_80023080.c b/src/func_80023080.c new file mode 100644 index 0000000..a97f704 --- /dev/null +++ b/src/func_80023080.c @@ -0,0 +1,78 @@ +/* + * func_80023080 — 100 bytes at 0x80023080..0x800230E4 + * + * Two-step lookup whose second result decides between storing a value and + * returning 0, or storing zero and returning 7. + * + * Original words: + * 27BDFFE0 addiu sp,sp,-32 + * AFB00010 sw s0,16(sp) + * 00808021 addu s0,a0,zero ; s0 = a0 + * AFB10014 sw s1,20(sp) + * AFBF0018 sw ra,24(sp) + * 0C03E4D1 jal 0x800F9344 + * 00A08821 addu s1,a1,zero ; (delay) s1 = a1 + * 02002021 addu a0,s0,zero ; a0 = the ORIGINAL a0 + * 0C03E4A9 jal 0x800F92A4 + * 00408021 addu s0,v0,zero ; (delay) s0 = first result + * 10400006 beq v0,zero,0x800230C4 ; second result zero -> the 7 path + * 02002021 addu a0,s0,zero ; (delay) a0 = first result + * 0C0041A6 jal 0x80010698 + * 00402821 addu a1,v0,zero ; (delay) a1 = second result + * AE220000 sw v0,0(s1) ; *a1 = third result + * 08008C33 j 0x800230CC + * 00001021 addu v0,zero,zero ; (delay) return 0 + * AE200000 sw zero,0(s1) ; *a1 = 0 + * 24020007 addiu v0,zero,7 ; return 7 + * 8FBF0018 lw ra,24(sp) + * 8FB10014 lw s1,20(sp) + * 8FB00010 lw s0,16(sp) + * 27BD0020 addiu sp,sp,32 + * 03E00008 jr ra + * 00000000 nop + * + * `s0` carries two different values with disjoint live ranges: the incoming `a0` + * across the first call, then that call's result across the second — which is why + * the second call is made with `a0,s0` and its delay slot overwrites `s0` with + * `v0`. `s1` holds the pointer argument across all three calls. + * + * The two arms are `*a1 = ; r = 0;` and `*a1 = 0; r = 7;` followed by a + * single `return r;`, with the `v0 == 0` test jumping to the second arm, so the + * non-zero arm is the fall-through. The shared epilogue is the normal order + * (`lw ra` / release / `jr ra` / `nop`). + * + * THE SHARED-RESULT LEVER (measured, both spellings compiled against this range). + * Writing the two arms as `return 0;` / `return 7;` makes cc1 REVERSE the layout: + * it emits `bne v0,zero,` and puts the `r = 7` arm in the fall-through + * position, 23 differing bytes with every instruction present. Writing the arms as + * assignments to a shared local with one `return r;` after the `if`/`else` + * produces the original exactly. So when both arms of an `if`/`else` end in a + * `return`, cc1's jump optimisation is free to reverse the arms; a single shared + * result local pins the original order. `v1.c` (both arms return) and `v4.c` + * (shared local) were both compiled; only v4 matches. + * + * LIMITS: the function name, the three callees, the pointer argument and the + * meaning of the constants 0 and 7 are hypotheses read from the instruction + * shape; only the bytes are evidence. func_800F92A4 and func_80010698 are not + * registered and are referenced by their address-named spellings. + */ + +extern int func_800F9344(int a0); +extern int func_800F92A4(int a0); +extern int func_80010698(int a0, int a1); + +int func_80023080(int a0, int *a1) +{ + int first = func_800F9344(a0); + int second = func_800F92A4(a0); + int r; + + if (second != 0) { + *a1 = func_80010698(first, second); + r = 0; + } else { + *a1 = 0; + r = 7; + } + return r; +} diff --git a/src/func_80027E1C.c b/src/func_80027E1C.c new file mode 100644 index 0000000..de97c5a --- /dev/null +++ b/src/func_80027E1C.c @@ -0,0 +1,87 @@ +/* + * func_80027E1C — 176 bytes at 0x80027E1C..0x80027ECC + * + * Byte-identical reconstruction of a framed three-component transform: it + * subtracts one vector from another, passes each component through a shared + * two-argument helper with the corresponding component of the second vector, + * sums the three results, and stores the sum through an out pointer. + * + * The observed instructions are: + * addiu sp,sp,-48 + * move a3,a0 p + * sw s1,36(sp) + * move s1,a1 q + * sw ra,44(sp) + * sw s2,40(sp) + * sw s0,32(sp) + * lw a0,0(a3) + * lw v0,0(s1) + * nop (load delay) + * subu a0,a0,v0 d[0] = p[0] - q[0] + * sw a0,16(sp) + * lw v0,4(a3) + * lw v1,4(s1) + * nop + * subu v0,v0,v1 d[1] + * sw v0,20(sp) + * lw v0,8(a3) + * lw v1,8(s1) + * nop + * subu v0,v0,v1 d[2] + * sw v0,24(sp) + * lw a1,16(s1) q[4] + * jal 0x80010654 + * move s2,a2 (delay slot) out + * lw a0,20(sp) d[1] + * lw a1,20(s1) q[5] + * jal 0x80010654 + * move s0,v0 (delay slot) r0 + * lw a0,24(sp) d[2] + * lw a1,24(s1) q[6] + * jal 0x80010654 + * move s1,v0 (delay slot) r1 (q is dead here) + * addu s0,s0,s1 r0 + r1 + * addu s0,s0,v0 + r2 + * move v0,zero + * sw s0,0(s2) *out = sum + * lw ra,44(sp) + * lw s2,40(sp) + * lw s1,36(sp) + * lw s0,32(sp) + * addiu sp,sp,48 + * jr ra + * nop + * + * The frame is 48 bytes: the 16-byte o32 outgoing argument area, three + * spilled component words at 16/20/24, `s0` at 32(sp), `s1` at 36(sp), `s2` at + * 40(sp) and `ra` at 44(sp). **The three components must be an ARRAY, not + * three scalars.** Written as scalars, cc1 keeps them in registers and the + * frame collapses to 40 bytes with four saved registers (160 bytes total); + * written as `int d[3]`, cc1 cannot keep an array in registers, so it spills + * and reloads exactly as the original does. `move s1,v0` in the third call's + * delay slot reuses the dead `q` register for the second result. + * + * LIMITS: the function name, the helper's arity and semantics, the vector + * strides and the out pointer's meaning are hypotheses reconstructed from the + * disassembly. Only the compiled bytes are evidence. The helper's two + * arguments are `(component, q[i + 4])`; whether the second is a scale, a + * basis element or a bias is not observable from this body. + */ + +int func_80010654(int, int); + +int func_80027E1C(int *p, int *q, int *out) { + int d[3]; + int r0; + int r1; + + d[0] = p[0] - q[0]; + d[1] = p[1] - q[1]; + d[2] = p[2] - q[2]; + + r0 = func_80010654(d[0], q[4]); + r1 = func_80010654(d[1], q[5]); + *out = r0 + r1 + func_80010654(d[2], q[6]); + + return 0; +} diff --git a/src/func_8002C764.c b/src/func_8002C764.c new file mode 100644 index 0000000..834e018 --- /dev/null +++ b/src/func_8002C764.c @@ -0,0 +1,61 @@ +/* func_8002C764 — 0x8002C764..0x8002C7BC (88 bytes). + * + * Original words (objdump of the validated payload, little-endian): + * addiu sp,sp,-24 + * sw s0,16(sp) + * sw ra,20(sp) + * jal 0x800A745C + * _move s0,a0 (delay slot; parameter kept across the call) + * jal 0x8002C6EC + * _li a0,4 (delay slot; literal argument 4) + * lbu v0,576(gp) v0 = D_80121B78 (gp-relative, 0x80121938+576) + * _nop load-delay slot + * beqz v0,0x8002C7A0 zero -> else branch + * _nop + * jal 0x80159FD0 + * _move a0,s0 (delay slot) + * j 0x8002C7A8 skip the else block + * _nop + * 0x8002C7A0: + * jal 0x80156D78 + * _move a0,s0 (delay slot) + * 0x8002C7A8: + * lw ra,20(sp) + * lw s0,16(sp) + * addiu sp,sp,24 + * jr ra + * _nop + * + * Two setup calls, then a two-way dispatch on a gp-relative byte global, both + * arms forwarding the incoming parameter. The parameter is copied to s0 in the + * first `jal` delay slot because it is live across both setup calls and is the + * argument to whichever arm runs. `func_8002C6EC` is called with the literal 4 + * materialised in its `jal` delay slot. + * + * The `lbu` is gp-relative, so `D_80121B78` is already carried in the tracked + * symbol registry with its `gp` marker (0x80121938 + 576 = 0x80121B78) — the + * harness rewrites the access to `%gp_rel`. The byte is tested with `beqz` on + * the zero-extended `lbu` result, so the global is an unsigned char. + * + * LIMITS: the purpose of the flag, the meaning of the literal 4, and the names + * of the two dispatch targets are not observable. `func_800A745C` is registered + * as taking no arguments, so it is called with none here; the call site leaves + * a0 holding the incoming parameter either way, so a source that passed it would + * compile identically. Only the compiled bytes are evidence. + */ + +extern unsigned char D_80121B78; +extern void func_800A745C(void); +extern void func_8002C6EC(int a0); +extern void func_80159FD0(int a0); +extern void func_80156D78(int a0); + +void func_8002C764(int a0) +{ + func_800A745C(); + func_8002C6EC(4); + if (D_80121B78) + func_80159FD0(a0); + else + func_80156D78(a0); +} diff --git a/src/func_8002E870.c b/src/func_8002E870.c new file mode 100644 index 0000000..6d2bb9f --- /dev/null +++ b/src/func_8002E870.c @@ -0,0 +1,95 @@ +/* func_8002E870 — 0x8002E870..0x8002E8EC (124 bytes). + * + * Original words (objdump of the validated payload, little-endian): + * lui v1,0x8012 \ + * lw v1,9044(v1) / v1 = g_80122354 (absolute, hoisted above the frame) + * lw v0,2444(gp) v0 = D_801222C4 (gp-relative, 0x801222C4) + * addiu sp,sp,-32 + * sw s1,20(sp) + * move s1,a0 s1 = the parameter + * sw ra,24(sp) + * sltu v0,v0,v1 v0 = (D_801222C4 < g_80122354) UNSIGNED + * beqz v0,0x8002E8D4 not below -> epilogue + * _sw s0,16(sp) (delay slot) + * jal 0x800FB5B4 + * _nop + * sll s0,v0,0x1 size = returned * 2 ... + * lui a0,0x8012 \ + * lw a0,9044(a0) / a0 = g_80122354 (RELOADED after the call) + * addiu s0,s0,24 ... + 24 + * addu a0,a0,s0 a0 = g_80122354 + size + * addiu a0,a0,16 a0 += 16 + * sw a0,2444(gp) D_801222C4 = a0 + * jal 0x800ACC00 call with that same value + * _nop + * move a0,zero + * move a1,s1 + * jal 0x80063870 + * _move a2,s0 (delay slot) a2 = size + * lw ra,24(sp) (epilogue) + * lw s1,20(sp) + * lw s0,16(sp) + * addiu sp,sp,32 + * jr ra + * _nop + * + * A guarded allocator step: while the cursor `D_801222C4` is still below the + * limit `g_80122354`, ask for a count, compute `count * 2 + 24`, advance the + * cursor past that many bytes plus 16, and hand both the new cursor value and + * the size to two callees. The frame is 32 bytes = 16 (o32 outgoing args) + the + * s0/s1 pair at sp+16/20 + ra at sp+24. `s1` holds the parameter across the + * first call; `s0` holds the computed size across the last one. + * + * THREE THINGS THE BYTES PIN DOWN: + * + * 1. THE COMPARISON IS WRITTEN MIRRORED — `g_80122354 > D_801222C4`, not + * `D_801222C4 < g_80122354`. Both give the same `sltu v0,v0,v1` (cc1 + * canonicalises `>` by swapping the operands), but the SOURCE order decides + * which global is loaded first: the mirrored spelling loads `g_80122354` into + * v1 first and then `D_801222C4` into v0, exactly as the original does. The + * natural spelling swaps those two instructions and leaves 18 differing bytes + * from 0x8002E870. This is the same operand-order family as claims 1 and 2, + * now on a comparison's operand evaluation order. + * + * 2. THE COMPUTED VALUE IS ALSO AN ARGUMENT. The sum is built in **a0** — the + * first argument register — not in v0: `lui a0` / `lw a0` / `addu a0,a0,s0` / + * `addiu a0,a0,16` / `sw a0,2444(gp)` / `jal 0x800ACC00`. That only happens + * when the same value is passed to the next call, so the source names it and + * passes it: `func_800ACC00(v)`. This is CONFIRMED by the registry — + * `src/func_800ACC00.c` is `void func_800ACC00(unsigned int value)`, i.e. the + * callee does take that argument. Building the sum into a temporary and + * storing only (no call argument) leaves the value in v0 and 6 differing + * bytes at 0x8002E8A4. + * + * 3. THE COMPARISON IS UNSIGNED: `sltu`, not `slt`. The cursor is + * `unsigned int` while the limit is `int`, so the usual arithmetic conversions + * make the comparison unsigned. + * + * The limit global is loaded TWICE (once for the guard, once for the update) and + * is deliberately NOT kept in a register across the middle call — the source + * re-reads it. `g_80122354` is read absolutely (`lui`+`lw`) because its registry + * row has no `gp` marker; `D_801222C4` is gp-relative (+2444 = 0x98C) and is + * already carried with its `gp` marker. + * + * LIMITS: the purpose of the +16 (an object header or alignment pad), the `* 2` + * scaling, the meaning of the limit and cursor, and the three callees' semantics + * are not observable. Only the compiled bytes are evidence. + */ + +extern int g_80122354; +extern unsigned int D_801222C4; +extern int func_800FB5B4(void); +extern void func_800ACC00(unsigned int value); +extern void func_80063870(int a0, int a1, int a2); + +void func_8002E870(int a0) +{ + if (g_80122354 > D_801222C4) { + int size = func_800FB5B4() * 2 + 24; + unsigned int v = g_80122354 + size + 16; + + D_801222C4 = v; + func_800ACC00(v); + func_80063870(0, a0, size); + } +} diff --git a/src/func_8002F0D0.c b/src/func_8002F0D0.c new file mode 100644 index 0000000..611a1f9 --- /dev/null +++ b/src/func_8002F0D0.c @@ -0,0 +1,53 @@ +/* + * func_8002F0D0 — 72 bytes at 0x8002F0D0..0x8002F118 + * + * Byte-identical reconstruction of a framed routine that calls a lookup with + * three arguments, conditionally calls a second routine with the lookup's + * result, and finally clears a gp-relative byte. + * + * The observed instructions are: + * addiu sp,sp,-24 + * move a0,zero + * lui a1,0x8014 + * lw a1,-15564(a1) a1 = *(int *)0x8013C334 + * sw ra,16(sp) + * jal 0x80063870 + * move a2,zero (delay slot) + * move a0,v0 r = lookup(...) + * li v0,-1 + * beq a0,v0,0x8002F104 + * nop + * jal 0x800A9F7C + * li a1,1 (delay slot) + * sb zero,2524(gp) D_80122314 = 0 + * lw ra,16(sp) + * addiu sp,sp,24 + * jr ra + * nop + * + * The frame is 24 bytes: the 16-byte o32 outgoing argument area plus `ra` at + * 16(sp). The global read is a **literal** constant address, which folds into + * the load's displacement (cookbook finding 18) — no symbol registry row is + * needed and none would change the encoding. The final store is gp-relative + * (gp = 0x80121938, so 2524(gp) is 0x80122314) and needs the registry's `gp` + * marker on that symbol's name (finding 30). + * + * LIMITS: the function names, the global's type, and the argument meanings are + * hypotheses reconstructed from the disassembly. Only the compiled bytes are + * evidence. The -1 sentinel is written as a comparison against -1 because that + * is the only value the original materialises into `v0`. + */ + +extern char D_80122314; + +int func_80063870(int, int, int); +void func_800A9F7C(int, int); + +void func_8002F0D0(void) { + int r = func_80063870(0, *(int *)0x8013C334, 0); + + if (r != -1) + func_800A9F7C(r, 1); + + D_80122314 = 0; +} diff --git a/src/func_800419D0.c b/src/func_800419D0.c new file mode 100644 index 0000000..991ebc6 --- /dev/null +++ b/src/func_800419D0.c @@ -0,0 +1,53 @@ +/* + * func_800419D0 — 84 bytes at 0x800419D0..0x80041A24 + * + * Byte-identical reconstruction of a framed accessor: it accepts a pointer + * that is either of two registered globals, in which case it walks two fields + * of the pointed-to structure, and otherwise delegates to a helper. + * + * The observed instructions are: + * lui v0,0x8013 + * lw v0,-10340(v0) v0 = *(int *)0x8012D79C + * addiu sp,sp,-24 + * beq a0,v0,0x800419F8 if (p == g1) goto body + * sw ra,16(sp) (delay slot) + * lui v0,0x8013 + * lw v0,-8912(v0) v0 = *(int *)0x8012DD30 + * nop (load-delay, finding 27) + * bne a0,v0,0x80041A0C if (p != g2) goto call + * nop + * lw v0,32(a0) body: v0 = *(int *)(p + 32) + * nop (load-delay) + * lw v0,24(v0) v0 = *(int *)(v0 + 24) + * j 0x80041A14 goto return + * nop + * jal 0x8007EB8C call: v0 = helper(p) + * nop + * lw ra,16(sp) return: + * addiu sp,sp,24 + * jr ra + * nop + * + * The two `if` arms share one return, so the original lays the body block out + * first, jumps over the call block, and lets the call block fall through into + * the epilogue — the shape `if (a || b) { ... } return helper(p);` produces. + * Both global reads are **literal** constant addresses folding into the load + * displacement (cookbook finding 18); the first one is scheduled above the + * prologue by cc1's reorganisation pass, which is why the `addiu sp,sp,-24` + * appears between the two loads. + * + * LIMITS: the function name, the helper's name, the global names and the + * structure field offsets are hypotheses reconstructed from the disassembly. + * Only the compiled bytes are evidence. Whether the two globals are pointers + * or ints is not observable here — only that each is loaded whole and compared + * against the incoming pointer. + */ + +int func_8007EB8C(char *); + +int func_800419D0(char *p) { + if (p == (char *)*(int *)0x8012D79C || p == (char *)*(int *)0x8012DD30) + return *(int *)(*(int *)(p + 32) + 24); + + return func_8007EB8C(p); +} diff --git a/src/func_800429B0.c b/src/func_800429B0.c new file mode 100644 index 0000000..57e7d3f --- /dev/null +++ b/src/func_800429B0.c @@ -0,0 +1,51 @@ +/* + * func_800429B0 — 64 bytes at 0x800429B0..0x800429F0 + * + * Framed routine that calls the same two setters as its sibling func_80042964 + * (0x80042964..0x800429B0), but passes the raw signed halfwords with no scaling. + * + * The observed instructions are: + * lui v0,0x8012 3c028012 \ + * lw v0,0x2430(v0) 8c422430 / v0 = *(int *)0x80122430 (D_80122430) + * addiu sp,sp,-0x18 27bdffe8 frame, 24 bytes + * sw ra,0x10(sp) afbf0010 save ra + * lh a0,0x4e(v0) 8444004e a0 = *(short *)(v0 + 0x4e) + * lh a1,0x50(v0) 84450050 a1 = *(short *)(v0 + 0x50) + * jal 0x80017c50 0c005f14 call func_80017C50 + * nop 00000000 (delay slot) + * lui a0,0x8012 3c048012 \ + * lh a0,0x242c(a0) 8484242c / a0 = *(short *)0x8012242C (D_8012242C) + * jal 0x80017c60 0c005f18 call func_80017C60 + * nop 00000000 (delay slot) + * lw ra,0x10(sp) 8fbf0010 restore ra + * addiu sp,sp,0x18 27bd0018 frame release + * jr ra 03e00008 + * nop 00000000 (delay slot) + * + * The sibling func_80042964 shares this prologue and the same two global loads + * byte-for-byte; the only difference is that the sibling scales its three + * operands (`sll` by 1, plus the `sll 17`/`sra 16` narrowing of the `short` + * argument) and this body does not. The pointer load is hoisted above the frame + * setup here too, and both `jal`s carry an unfilled `nop` delay slot. + * + * Both callees take 16-bit parameters and all three values come from signed + * halfword loads, so no narrowing instruction is required at either call site. + * + * LIMITS: the function name, both callees, the two globals and the meaning of + * the stores are hypotheses; only the bytes are evidence. `int v0` is a local + * used only to keep the pointer global loaded once — the disassembly fixes the + * load count, not the declaration. + */ + +extern int D_80122430; +extern short D_8012242C; +extern void func_80017C50(int a0, int a1); +extern void func_80017C60(short a0); + +void func_800429B0(void) +{ + int v0 = D_80122430; + + func_80017C50(*(short *)(v0 + 0x4e), *(short *)(v0 + 0x50)); + func_80017C60(D_8012242C); +} diff --git a/src/func_80047984.c b/src/func_80047984.c new file mode 100644 index 0000000..a9581c7 --- /dev/null +++ b/src/func_80047984.c @@ -0,0 +1,69 @@ +/* + * func_80047984 — 144 bytes at 0x80047984..0x80047A14 + * + * Byte-identical reconstruction of a framed two-arm dispatch on a mode + * argument: each arm walks a 76-byte record table with the object's index, + * reads the pointer at record offset 36, dereferences it, and calls one + * routine with a different pair of constants. + * + * The observed instructions are: + * addiu sp,sp,-24 + * li v0,1 + * bne a1,v0,0x800479C8 if (mode != 1) goto arm 2 + * sw ra,16(sp) (delay slot) + * lh v1,2(a0) idx = *(short *)(p + 2) + * li a1,220 + * sll v0,v1,0x2 + * addu v0,v0,v1 + * sll v0,v0,0x2 + * subu v0,v0,v1 idx * 19 + * lui v1,0x8012 + * lw v1,7164(v1) *(int *)0x80121BFC + * sll v0,v0,0x2 idx * 76 + * addu v0,v0,v1 (char *)(idx * 76) + base + * lw v0,36(v0) the record's pointer + * j 0x800479F8 + * li a2,13 (delay slot) + * ... the whole sequence again with 200 / 14 ... + * lw a0,0(v0) *record + * jal 0x80017AE8 + * li a3,3 (delay slot) + * lw ra,16(sp) + * addiu sp,sp,24 + * jr ra + * nop + * + * The frame is 24 bytes: the 16-byte o32 outgoing argument area plus `ra` at + * 16(sp). Three source-shape facts are load-bearing. (1) The index scaling + * `((idx*4 + idx)*4 - idx)*4` is cc1's strength reduction of `idx * 76`. + * (2) `addu v0,v0,v1` is the stride-first spelling of cookbook finding 22 — + * `(char *)(idx * 76) + base` — not the base-first one. (3) The address + * computation must be written **inline in both arms**: binding it to a local + * before the `if` lets cc1's CSE hoist it (108 bytes) and hoisting the two + * loads into locals shrinks the body differently (124 bytes). Written inline, + * the arms stay duplicated and cc1's **cross-jumping** merges only their + * identical tails — the `lw a0,0(v0)` / `jal` / `li a3,3` sequence — which is + * exactly the shared 0x800479F8 block. 0x80121BFC is read as a **literal** + * constant address because its registry symbol carries a `gp` marker and the + * original uses the absolute form (cookbook finding 30). + * + * LIMITS: the function name, the callee's arities and parameter types, the + * record stride 76, the field offset 36, the mode/constant pairs and the index + * field's width are hypotheses reconstructed from the disassembly. Only the + * compiled bytes are evidence. Whether the record's offset-36 field is a + * pointer or the first word of an embedded struct is not observable; only the + * double `lw` is. + */ + +void func_80017AE8(int, int, int, int); + +void func_80047984(char *a0, int a1) { + if (a1 == 1) + func_80017AE8( + **(int **)((char *)(*(short *)(a0 + 2) * 76) + *(int *)0x80121BFC + 36), + 220, 13, 3); + else + func_80017AE8( + **(int **)((char *)(*(short *)(a0 + 2) * 76) + *(int *)0x80121BFC + 36), + 200, 14, 3); +} diff --git a/src/func_80057564.c b/src/func_80057564.c new file mode 100644 index 0000000..0c955ac --- /dev/null +++ b/src/func_80057564.c @@ -0,0 +1,66 @@ +/* func_80057564 — 0x80057564..0x800575C4 (96 bytes). + * + * Original words (objdump of the validated payload, little-endian): + * lui v0,0x8013 + * lw v0,-10340(v0) v0 = *(int *)0x8012D79C (hoisted above the frame) + * addiu sp,sp,-24 + * sw s0,16(sp) + * move s0,a0 s0 = the argument + * beq s0,v0,0x80057594 argument == first sentinel -> body + * _sw ra,20(sp) (delay slot) + * lui v0,0x8013 + * lw v0,-8912(v0) v0 = *(int *)0x8012DD30 + * _nop load-delay slot + * bne s0,v0,0x800575B0 argument != second sentinel -> epilogue + * _nop + * 0x80057594: + * jal 0x80057524 + * _move a0,s0 (delay slot) + * lw v0,32(s0) v0 = *(int *)(s0 + 0x20) + * _nop load-delay slot + * lw a0,244(v0) a0 = *(int *)(v0 + 0xf4) + * jal 0x80050CA8 + * _nop + * 0x800575B0: + * lw ra,20(sp) + * lw s0,16(sp) + * addiu sp,sp,24 + * jr ra + * _nop + * + * A sentinel-guarded two-call body: when the argument equals either of two + * global sentinel pointers, forward it to one callee and then call a second + * callee with a word reached through two indirections from it. The argument is + * kept in s0 across the first call because it is both the second call's base and + * the guard's operand. The `||` short-circuit is visible as the layout: the + * first comparison's taken edge jumps *forward* to the shared body, the second + * comparison's not-taken edge falls into it, and the not-taken edge of the + * second jumps over the body to the epilogue. + * + * The two sentinels are the SAME globals as in the registered + * `func_800419D0.c` — `*(int *)0x8012D79C` (0x80130000 - 10340) and + * `*(int *)0x8012DD30` (0x80130000 - 8912) — which also compares its argument + * against both and then does the same `*(int *)(*(int *)(p + 0x20) + off)` + * double indirection (offset 24 there, 0xf4 here). That cross-reference is what + * fixes these as literal constant addresses rather than registry symbols. + * + * LIMITS (unresolved, recorded rather than guessed): the parameter's declared + * type is NOT observable — `int p` compared against `*(int *)0x8012D79C` and + * `char *p` compared against `(char *)*(int *)0x8012D79C` compile + * byte-identically. `int` with hex offsets is shipped to match the house style of + * the directly-called `func_80057524.c`, which uses the same double-indirection + * spelling. The sentinels' meanings, the field at +0xf4, and the callees' names + * are hypotheses read from the instruction shapes. Only the compiled bytes are + * evidence. + */ + +extern void func_80057524(int a0); +extern void func_80050CA8(int a0); + +void func_80057564(int p) +{ + if (p == *(int *)0x8012D79C || p == *(int *)0x8012DD30) { + func_80057524(p); + func_80050CA8(*(int *)(*(int *)(p + 0x20) + 0xf4)); + } +} diff --git a/src/func_8005E79C.c b/src/func_8005E79C.c new file mode 100644 index 0000000..0e83f26 --- /dev/null +++ b/src/func_8005E79C.c @@ -0,0 +1,17 @@ +void func_80057F08(int, char *); +void func_80058424(int); +void func_80057DFC(char *); +void func_8005E79C(char *a0) { + char *table = a0 + 2604; + int i = 0; + int offset = 252; + + for (; i < 7; i++) { + char *p = table + offset; + + offset += 12; + func_80057F08(*(int *)(a0 + 28), p); + func_80058424(*(int *)(p + 8)); + func_80057DFC(p); + } +} diff --git a/src/func_80074C00.c b/src/func_80074C00.c new file mode 100644 index 0000000..b9c6ce2 --- /dev/null +++ b/src/func_80074C00.c @@ -0,0 +1,77 @@ +/* + * func_80074C00 — 116 bytes at 0x80074C00..0x80074C74 + * + * Byte-identical reconstruction of a framed setter that records four incoming + * 16-bit values into a small-data block, calls a four-argument routine, stores + * the result, and finally packs two of its stack arguments into a 16-bit word. + * + * The observed instructions are: + * addiu sp,sp,-32 + * move v0,a0 + * sw s0,16(sp) + * lw s0,48(sp) s0 = arg5 + * move v1,a1 + * sw s1,20(sp) + * lw s1,52(sp) s1 = arg6 + * li a0,1 + * sh a2,3014(gp) D_801224FE = a2 + * move a2,v0 a2 = original a0 + * sh v0,3010(gp) D_801224FA = a0 + * sh v1,3012(gp) D_801224FC = a1 + * sh a3,3016(gp) D_80122500 = a3 + * lw a1,56(sp) a1 = arg7 + * sw ra,24(sp) + * jal 0x800F75D0 + * move a3,v1 (delay slot) a3 = original a1 + * sll s1,s1,0x6 arg6 << 6 + * sra s0,s0,0x4 arg5 >> 4 + * andi s0,s0,0x3f + * or s1,s1,s0 + * sh v0,3006(gp) D_801224F6 = result + * sh s1,3008(gp) D_801224F8 = packed + * lw ra,24(sp) + * lw s1,20(sp) + * lw s0,16(sp) + * addiu sp,sp,32 + * jr ra + * nop + * + * The frame is 32 bytes: the 16-byte o32 outgoing argument area, `s0` at + * 16(sp), `s1` at 20(sp), `ra` at 24(sp), and 4 bytes of alignment pad. The + * incoming stack arguments sit at 48/52/56(sp) — the caller's outgoing area + * offset by this frame — so the routine takes seven arguments: four in + * registers and three on the stack. Both stack words are loaded as full words + * (`lw`), so they are `int`, while the four register arguments are stored with + * `sh` (their globals are 16-bit). All six stores are `gp`-relative + * (gp = 0x80121938) and need the registry's `gp` markers. + * + * LIMITS: the function name, the callee's parameter meanings, the globals' + * types and the packing expression's purpose are hypotheses reconstructed from + * the disassembly. Only the compiled bytes are evidence. Whether the four + * register arguments are declared `int` or `short` is not observable: the + * `sh` stores follow from the globals' width either way. + */ + +extern short D_801224F6; +extern short D_801224F8; +extern short D_801224FA; +extern short D_801224FC; +extern short D_801224FE; +extern short D_80122500; + +int func_800F75D0(int, int, int, int); + +void func_80074C00(int a0, int a1, int a2, int a3, + int arg5, int arg6, int arg7) { + int r; + + D_801224FA = a0; + D_801224FC = a1; + D_801224FE = a2; + D_80122500 = a3; + + r = func_800F75D0(1, arg7, a0, a1); + + D_801224F6 = r; + D_801224F8 = (arg6 << 6) | ((arg5 >> 4) & 0x3f); +} diff --git a/src/func_800833CC.c b/src/func_800833CC.c new file mode 100644 index 0000000..c1980ed --- /dev/null +++ b/src/func_800833CC.c @@ -0,0 +1,77 @@ +/* + * func_800833CC — 116 bytes at 0x800833CC..0x80083440 + * + * Guarded call returning a flag. Original words: + * 27BDFFE8 addiu sp,sp,-24 + * AFBF0010 sw ra,16(sp) + * 8C820008 lw v0,8(a0) + * 00000000 nop + * 8C420000 lw v0,0(v0) + * 00000000 nop + * 10400012 beq v0,zero,0x80083430 ; first == 0 -> return 0 + * 00002821 addu a1,zero,zero ; (delay) result = 0 + * 3C028013 lui v0,0x8013 + * 8442E2C4 lh v0,-7484(v0) ; v0 = D_8012E2C4 (SIGNED halfword) + * 00000000 nop + * 1440000A bne v0,zero,0x80083424 ; D != 0 -> call + * 3C030040 lui v1,0x40 ; (delay) v1 = 0x400000 + * 8C82001C lw v0,28(a0) + * 00000000 nop + * 8C420008 lw v0,8(v0) + * 00000000 nop + * 8C420024 lw v0,36(v0) + * 00000000 nop + * 00431024 and v0,v0,v1 ; v0 &= 0x400000 + * 14400004 bne v0,zero,0x80083430 ; mask set -> return 0 + * 00000000 nop + * 0C02973B jal 0x800A5CEC ; (L2) + * 00000000 nop + * 24050001 addiu a1,zero,1 ; result = 1 + * 8FBF0010 lw ra,16(sp) ; (END) + * 00A01021 addu v0,a1,zero ; return result + * 03E00008 jr ra + * 27BD0018 addiu sp,sp,24 ; (delay slot) + * + * The two guards are one short-circuit `||` in source order: the `D != 0` test + * comes first and jumps straight to the call, and the three-load mask chain is + * evaluated only on the `D == 0` path, so the source is + * `if (D_8012E2C4 != 0 || (mask chain) == 0)`. The result is a local in `a1` + * (`a0` holds the pointer, so `a1` is the free argument register), initialised in + * the first `beq` delay slot and set to 1 after the call; the epilogue returns it + * with `addu v0,a1,zero`, which is `return result;` and not `return 0;`. + * + * THE EPILOGUE IS THE `rare-real` SHAPE of cookbook findings 11/35: + * `lw ra,16(sp)` / `addu v0,a1,zero` / `jr ra` / `addiu sp,sp,24` — the frame + * release is in the jump delay slot, and the instruction between the `ra` load + * and the jump is a REAL instruction that does not read `ra`. That is what makes + * this shape reachable: GNU `as` in reorder mode can move the frame release into + * the jump slot without putting `jr ra` in the `lw ra` load-delay slot, so the + * default toolchain reproduces the original with no override. The blocked variant + * of the same class is the one where the original has a `nop` there (0x800FE970 + * in this partition), which needs insert-nop-then-fill and is a harness limit. + * + * LIMITS: the function name, the callee, the global, the three struct offsets + * (8, 0x1c, 0x24), the inner offset 8 and the mask 0x400000 are hypotheses read + * from the instruction shape; only the bytes are evidence. D_8012E2C4 is loaded + * ABSOLUTELY (`lui`/`lh`, not gp-relative), so it needs no registry gp marker and + * the implicit address-named resolution is correct here. The `and` encodes + * `and v0,v0,v1` (rs = the loaded value, rt = the mask), so the source operand + * order is `value & 0x400000`. + */ + +extern short D_8012E2C4; +extern void func_800A5CEC(char *arg); + +int func_800833CC(char *a0) +{ + int result = 0; + + if (*(int *)(*(int *)(a0 + 8)) != 0) { + if (D_8012E2C4 != 0 + || (*(int *)(*(int *)(*(int *)(a0 + 0x1c) + 8) + 0x24) & 0x400000) == 0) { + func_800A5CEC(a0); + result = 1; + } + } + return result; +} diff --git a/src/func_800834B8.c b/src/func_800834B8.c new file mode 100644 index 0000000..ed7b17a --- /dev/null +++ b/src/func_800834B8.c @@ -0,0 +1,76 @@ +/* func_800834B8 — 0x800834B8..0x80083504 (76 bytes). + * + * Original words (objdump of the validated payload, little-endian): + * addiu sp,sp,-24 + * sw s0,16(sp) + * sw ra,20(sp) + * jal 0x80083440 + * _move s0,a0 (delay slot; index kept across the call) + * lui v1,0xffff + * lui v0,0x8012 + * lw v0,8968(v0) v0 = D_80122308 + * sll s0,s0,0x4 index *= 16 + * addu s0,s0,v0 element = index16 + base (INDEX16 FIRST) + * lw v0,0x0(s0) + * ori v1,v1,0x7fff v1 = 0xFFFF7FFF = ~0x8000 + * and v0,v0,v1 + * sw v0,0x0(s0) + * lw ra,20(sp) + * lw s0,16(sp) + * addiu sp,sp,24 + * jr ra + * _nop (delay slot) + * + * A sibling of the registered `func_80083440` (0x80083440..0x80083470) and the + * second half of the same table operation: it calls that function for its side + * effect only (the `jal` result is dead — v0 is immediately reloaded with the + * table base), then clears bit 15 of the same 16-byte-strided element. Both + * functions index `D_80122308`, the same global *value* (the `lui`+`lw` pair is + * a symbol load, so 0x80122308 holds a pointer, not the table), with the same + * `index << 4` stride. + * + * The mask is written as `~0x8000`, which is what makes the two-piece constant + * fall out as `lui v1,0xffff` + `ori v1,v1,0x7fff` (0xFFFF7FFF does not fit a + * sign-extended `addiu`); cc1 splits it into a high-part load and an `ori`, and + * the scheduler separates them around the table load. The store is a plain + * `sw`, not a delay-slot store (unlike the sibling, which is a single basic + * block and puts its store in the `jr ra` slot). + * + * OPERAND-ORDER LEVER (the byte-difference that this body turns on): the + * address addition is written `(index << 4) + D_80122308`, i.e. index16 first. + * cc1 does not canonicalize the operand order of a commutative `+`, and + * local-alloc hands the `addu` output the register of its *first* dying source + * operand. Written base-first (the sibling's spelling) the element pointer + * takes v1, the loaded value takes v0 and the mask is pushed to a0 — 12 + * differing bytes of pure register numbering with an otherwise identical + * instruction sequence. Written index16-first the element pointer stays in the + * s0 already holding the index, the base coalesces into v0 with the loaded + * value, and the mask lands in v1 — byte-identical. Six spellings of the same + * expression (`*element & ~0x8000`, a compound `&=`, a pointer-typed base, a + * duplicated address, `0xFFFF7FFF`, a named mask local) all produce the + * base-first allocation and DIFF, so the operand order is the whole lever. + * + * LIMITS: the stride 16, the displaced base and the cleared bit are read from + * the bytes; what the field means, and why the sibling sets bits 11/13 while + * this clears bit 15 of the same word, is not observable. The call's return + * value is provably discarded (v0 is overwritten before any use), so the callee + * is declared `int` but its result is ignored. `D_80122308` is typed `int` for + * the same reason as in func_80083440.c: the only proven use is as an integer + * base added to a scaled index. + */ + +extern int D_80122308; +extern int func_80083440(int index); + +int func_800834B8(int index) +{ + int *element; + int value; + + func_80083440(index); + element = (int *)((index << 4) + D_80122308); + value = *element; + value &= ~0x8000; + *element = value; + return value; +} diff --git a/src/func_8008D9AC.c b/src/func_8008D9AC.c new file mode 100644 index 0000000..6504287 --- /dev/null +++ b/src/func_8008D9AC.c @@ -0,0 +1,60 @@ +/* + * func_8008D9AC — 96 bytes at 0x8008D9AC..0x8008DA0C + * + * Guarded five-argument call: the first call's result decides whether the second + * runs, and the second call's result becomes the return value. + * + * Original words: + * 27BDFFD8 addiu sp,sp,-40 + * AFB00018 sw s0,24(sp) + * 00808021 addu s0,a0,zero ; s0 = a0 + * AFB1001C sw s1,28(sp) + * 00A08821 addu s1,a1,zero ; s1 = a1 + * AFB20020 sw s2,32(sp) + * 00C09021 addu s2,a2,zero ; s2 = a2 + * AFBF0024 sw ra,36(sp) + * 0C01608C jal 0x80058230 + * 00E02021 addu a0,a3,zero ; (delay) func_80058230(a3) + * 10400006 beq v0,zero,0x8008D9F0 ; zero -> return it untouched + * 02002021 addu a0,s0,zero ; (delay) a0 = a0 + * AFA00010 sw zero,16(sp) ; 5th outgoing argument = 0 + * 02202821 addu a1,s1,zero ; a1 = a1 + * 02403021 addu a2,s2,zero ; a2 = a2 + * 0C005C80 jal 0x80017200 + * 00403821 addu a3,v0,zero ; (delay) a3 = first result + * 8FBF0024 lw ra,36(sp) + * 8FB20020 lw s2,32(sp) + * 8FB1001C lw s1,28(sp) + * 8FB00018 lw s0,24(sp) + * 27BD0028 addiu sp,sp,40 + * 03E00008 jr ra + * 00000000 nop + * + * The three callee-saved registers hold the three leading arguments across the + * first call; the fourth argument is consumed by that call in its delay slot, so + * it needs no save. `sw zero,16(sp)` is the OUTGOING ARGUMENT AREA (the callee's + * fifth argument at sp+0x10), not a dead local store — the call therefore takes + * five arguments, and the frame arithmetic agrees: 0x10 for the register + * arguments, 0x14 for the fifth, then s0/s1/s2/ra at 0x18..0x28. + * + * The result of the first call is tested and, when non-zero, is both the fourth + * argument of the second call and the value the second call's result replaces, so + * the source is the `if (v0 != 0) v0 = call(...); return v0;` shape. + * + * LIMITS: the function name, both callees, the five-argument shape and the + * argument/return roles are hypotheses read from the instruction shape; only the + * bytes are evidence. func_80017200 is not registered and is referenced by its + * address-named spelling, which resolves implicitly. + */ + +extern int func_80058230(int a3); +extern int func_80017200(int a0, int a1, int a2, int a3, int a4); + +int func_8008D9AC(int a0, int a1, int a2, int a3) +{ + int v0 = func_80058230(a3); + + if (v0 != 0) + v0 = func_80017200(a0, a1, a2, v0, 0); + return v0; +} diff --git a/src/func_8008F2E0.c b/src/func_8008F2E0.c new file mode 100644 index 0000000..56388f0 --- /dev/null +++ b/src/func_8008F2E0.c @@ -0,0 +1,68 @@ +/* + * func_8008F2E0 — 88 bytes at 0x8008F2E0..0x8008F338 + * + * Byte-identical reconstruction of a framed teardown: five void calls in a + * fixed order (the first with a zero argument, the last with four) followed by + * a block of small-data state resets. + * + * The observed instructions are: + * addiu sp,sp,-24 + * sw ra,16(sp) + * jal 0x800FCFDC + * move a0,zero (delay slot) + * jal 0x80100740 + * nop + * jal 0x800FDE54 + * nop + * jal 0x800FB5E4 + * nop + * jal 0x800FC2CC + * li a0,4 (delay slot) + * li v0,-1 + * sw v0,3352(gp) D_80122650 = -1 + * sw v0,3344(gp) D_80122648 = -1 + * sw zero,3340(gp) D_80122644 = 0 + * sw zero,3376(gp) D_80122668 = 0 + * sb zero,3364(gp) D_8012265C = 0 + * lw ra,16(sp) + * addiu sp,sp,24 + * jr ra + * nop + * + * The frame is 24 bytes: the 16-byte o32 outgoing argument area plus `ra` at + * 16(sp). The `-1` is materialised once into `v0` and stored twice, so the two + * globals are written from a single constant; the three zero stores use the + * zero register directly. All five stores are `gp`-relative (gp = 0x80121938), + * so every target needs the registry's `gp` marker on its name. + * + * LIMITS: the function names, the callees' arities and parameter types, the + * global types and the state block's meaning are hypotheses reconstructed from + * the disassembly. Only the compiled bytes are evidence. The order of the five + * stores is the original's; it is not derivable from the addresses. + */ + +extern int D_80122650; +extern int D_80122648; +extern int D_80122644; +extern int D_80122668; +extern char D_8012265C; + +void func_800FCFDC(int); +void func_80100740(void); +void func_800FDE54(void); +void func_800FB5E4(void); +void func_800FC2CC(int); + +void func_8008F2E0(void) { + func_800FCFDC(0); + func_80100740(); + func_800FDE54(); + func_800FB5E4(); + func_800FC2CC(4); + + D_80122650 = -1; + D_80122648 = -1; + D_80122644 = 0; + D_80122668 = 0; + D_8012265C = 0; +} diff --git a/src/func_80090894.c b/src/func_80090894.c new file mode 100644 index 0000000..6fb642e --- /dev/null +++ b/src/func_80090894.c @@ -0,0 +1,60 @@ +/* func_80090894 — 0x80090894..0x800908E4 (80 bytes). + * + * Original words (objdump of the validated payload, little-endian): + * addiu sp,sp,-24 + * sw s0,16(sp) + * sw ra,20(sp) + * jal 0x80090028 + * _move s0,a0 (delay slot; parameter kept across the call) + * andi v0,v0,0xff narrow the call result to 8 bits + * beqz v0,0x800908d0 result == 0 -> epilogue + * _nop + * lui v0,0x8014 + * lh v0,-30554(v0) v0 = *(short *)0x801388A6 (D_801388A6) + * _nop load-delay slot + * bne v0,s0,0x800908d0 global != parameter -> epilogue + * _nop + * jal 0x800907a4 + * _nop + * 0x800908d0: (both early exits land here) + * lw ra,20(sp) + * lw s0,16(sp) + * addiu sp,sp,24 + * jr ra + * _nop + * + * A guarded forwarding call: the body runs `func_800907a4` only when the + * 8-bit-narrowed result of `func_80090028()` is nonzero AND the signed halfword + * global `D_801388A6` equals the incoming parameter. The parameter must survive + * the first call, which is why it is copied to s0 in the `jal` delay slot; the + * `lh` is sign-extended and compared against the full 32-bit parameter, so the + * global is a `short` promoted to `int` and the parameter is an `int`. + * + * The `& 0xFF` is real code, not a redundant mask: `func_80090028` is registered + * returning `unsigned char`, but cc1 still emits the `andi`, so the source masks + * explicitly (a bare `if (func_80090028())` would test the full register). + * + * OPERAND-ORDER LEVER, second instance (see func_800834B8.c for the first): the + * comparison must be written `D_801388A6 == a0`. Written `a0 != D_801388A6` in + * the inverted-branch spelling the body is otherwise byte-identical and leaves + * exactly 2 differing bytes at 0x800908C2 — `bne v0,s0` becomes `bne s0,v0`. + * cc1 does not canonicalize the operand order of a comparison, and the MIPS + * branch encoding is operand-ordered, so the two spellings are different bytes. + * + * LIMITS: the guard's purpose, the meaning of the halfword global, and whether + * the callee `func_80090028` is really called with no arguments are not + * observable. The call site leaves a0 holding the incoming parameter, so a + * source that passed it as an argument would compile identically — the no-arg + * call is chosen only to match the callee's own registered prototype. The name + * `D_801388A6` encodes its address, per the registry convention. + */ + +extern short D_801388A6; +extern unsigned char func_80090028(void); +extern void func_800907a4(void); + +void func_80090894(int a0) +{ + if ((func_80090028() & 0xFF) != 0 && D_801388A6 == a0) + func_800907a4(); +} diff --git a/src/func_80090CAC.c b/src/func_80090CAC.c new file mode 100644 index 0000000..09751d8 --- /dev/null +++ b/src/func_80090CAC.c @@ -0,0 +1,54 @@ +/* + * func_80090CAC — 84 bytes at 0x80090CAC..0x80090D00 + * + * Byte-identical reconstruction of a framed routine that clamps its argument + * against a value obtained from a helper minus a five-unit margin. + * + * The observed instructions are: + * addiu sp,sp,-24 + * sw s0,16(sp) + * sw ra,20(sp) + * jal 0x800FE86C + * move s0,a0 (delay slot) s = argument + * move a0,v0 t = helper() + * slt v0,s0,a0 (s < t) + * beqz v0,0x80090CD8 + * slt v0,a0,s0 (delay slot) (t < s) + * addiu a0,a0,-5 t - 5 + * slt v0,a0,s0 (t - 5 < s) + * beqz v0,0x80090CE4 + * nop + * move a0,s0 s + * andi a0,a0,0xff + * lw ra,20(sp) + * lw s0,16(sp) + * addiu sp,sp,24 + * jr ra + * nop + * + * The frame is 24 bytes: the 16-byte o32 outgoing argument area plus `s0` at + * 16(sp) and `ra` at 20(sp). The body is two straight-line guards on the same + * value, which is why cc1 merges the second guard's test into the first + * branch's delay slot and re-tests only on the path that changed the value. + * + * LIMITS: the helper's and the callee's names, the argument types and the + * `- 5` margin's meaning are hypotheses reconstructed from the disassembly. + * Only the compiled bytes are evidence. The final mask is written as an + * explicit `& 0xff` because the original emits `andi`; whether the callee + * declares an `unsigned char` parameter or the source masks by hand is not + * observable from this body alone. + */ + +int func_800FE86C(void); +void func_800FE844(int); + +void func_80090CAC(int s) { + int t = func_800FE86C(); + + if (s < t) + t = t - 5; + if (t < s) + t = s; + + func_800FE844(t & 0xff); +} diff --git a/src/func_8009214C.c b/src/func_8009214C.c new file mode 100644 index 0000000..da79cb8 --- /dev/null +++ b/src/func_8009214C.c @@ -0,0 +1,74 @@ +/* + * func_8009214C — 116 bytes at 0x8009214C..0x800921C0 + * + * Byte-identical reconstruction of a framed clamp: a status bit on a nested + * structure disables it, otherwise a helper's result is offset by a third + * argument, rejected when non-positive, and finally clamped to the second + * argument. + * + * The observed instructions are: + * addiu sp,sp,-32 + * sw s0,16(sp) + * move s0,a1 s0 = limit + * sw ra,24(sp) + * sw s1,20(sp) + * lw v0,8(a0) v0 = *(int *)(p + 8) + * nop (load delay) + * lw v0,20(v0) v0 = *(int *)(v0 + 20) + * lui v1,0x100 + * and v0,v0,v1 + * bnez v0,0x800921A4 if (status & 0x01000000) return limit + * move s1,a2 (delay slot) s1 = offset + * jal 0x80092130 + * nop + * move v1,v0 r = helper() + * blez v1,0x800921A4 if (r <= 0) return limit + * addu v1,v1,s1 (delay slot) r += offset + * blez v1,0x800921A4 if (r <= 0) return limit + * slt v0,v1,s0 (delay slot) (r < limit) + * beqz v0,0x800921A8 + * move v0,s0 (delay slot) limit + * move s0,v1 limit = r + * move v0,s0 return limit + * lw ra,24(sp) + * lw s1,20(sp) + * lw s0,16(sp) + * addiu sp,sp,32 + * jr ra + * nop + * + * The frame is 32 bytes: the 16-byte o32 outgoing argument area, `s0` at + * 16(sp), `s1` at 20(sp), `ra` at 24(sp), and 4 bytes of alignment pad. Both + * `s0` and `s1` hold live values across the call, which is why they are saved. + * The status mask is `0x01000000`, not `0x100`: `lui v1,0x100` loads the high + * half (cookbook finding 30), and the register form (rather than `andi`) + * follows from the mask being wider than 16 bits. The function has exactly one + * `return limit;`, which is why all three refusal paths branch to one shared + * `move v0,s0` block instead of each carrying its own copy in a delay slot. + * + * LIMITS: the function name, the helper's arity, the structure offsets, the + * status mask and the arguments' meanings are hypotheses reconstructed from + * the disassembly. Only the compiled bytes are evidence. Whether the guard + * reads a bitfield or a masked word is not observable; only `lui 0x100` + + * `and` is. + */ + +int func_80092130(void); + +int func_8009214C(int *p, int limit, int offset) { + int status = *(int *)(*(int *)((char *)p + 8) + 20); + int r; + + if ((status & 0x01000000) == 0) { + r = func_80092130(); + if (r > 0) { + r += offset; + if (r > 0) { + if (r < limit) + limit = r; + } + } + } + + return limit; +} diff --git a/src/func_80093A08.c b/src/func_80093A08.c new file mode 100644 index 0000000..19cdb8d --- /dev/null +++ b/src/func_80093A08.c @@ -0,0 +1,59 @@ +/* func_80093A08 — 0x80093A08..0x80093A64 (92 bytes). + * + * Original words (objdump of the validated payload, little-endian): + * addiu sp,sp,-24 + * sll a0,a0,0x10 sign-extend the halfword parameter ... + * lui v0,0x8012 + * lw v0,7168(v0) ... v0 = *(int *)0x80121C00 (the table base) + * sra a0,a0,0xe ... and scale it by 4 ((short)p * 4) + * sw ra,20(sp) + * sw s0,16(sp) + * addu a0,a0,v0 a0 = base + (short)p * 4 + * lw s0,0(a0) s0 = table[(short)p] + * jal 0x800697A4 + * _move a0,s0 (delay slot) + * lw v1,12(s0) v1 = *(int *)(s0 + 12) + * move a0,s0 + * lw v0,260(v1) v0 = *(int *)(v1 + 260) + * move a1,zero + * ori v0,v0,0x200 + * jal 0x80092A48 + * _sw v0,260(v1) (delay slot) read-modify-write + * lw ra,20(sp) + * lw s0,16(sp) + * addiu sp,sp,24 + * jr ra + * _nop + * + * Indexes a pointer table with a **halfword** index, forwards the selected + * element to one callee, sets bit 9 of a word reached through two indirections, + * then forwards the element again with a zero second argument. The `sll 16` / + * `sra 14` pair is this compiler's combined narrow-and-scale: sign-extend the + * low 16 bits of the argument and multiply by 4, so the parameter is a `short` + * and the table holds 4-byte elements. The element pointer is kept in s0 because + * it is live across both calls. The `lui`+`lw` pair is a symbol load, so + * 0x80121C00 holds a *pointer* (the table base), not the table. + * + * LIMITS (unresolved, recorded rather than guessed): the global's declared type + * is NOT observable. Three spellings all compile byte-identically — the literal + * `*(int *)(*(int *)0x80121C00 + index * 4)`, a pointer-typed + * `extern int *D_80121C00` indexed directly, and the symbolic + * `extern int D_80121C00` used as an integer base (shipped here, matching the + * `int`-holding-a-pointer style documented in func_80083440.c and + * func_800419D0.c). The table's element type, the two structure offsets (12 and + * 260), the meaning of bit 9 and the callees' names are all hypotheses read from + * the instruction shapes. Only the compiled bytes are evidence. + */ + +extern int D_80121C00; +extern void func_800697A4(int x); +extern void func_80092A48(int a0, int a1); + +void func_80093A08(short index) +{ + int p = *(int *)(D_80121C00 + index * 4); + + func_800697A4(p); + *(int *)(*(int *)(p + 12) + 260) |= 0x200; + func_80092A48(p, 0); +} diff --git a/src/func_80099078.c b/src/func_80099078.c new file mode 100644 index 0000000..f9a771d --- /dev/null +++ b/src/func_80099078.c @@ -0,0 +1,89 @@ +/* + * func_80099078 — 244 bytes at 0x80099078..0x8009916C + * + * Byte-identical reconstruction of a framed signed three-component scale: a + * helper fills a local, and depending on how a second argument compares with + * it the routine either scales each component of a vector by the negated + * argument and then re-scales by the local, or simply negates each component. + * + * The observed instructions are: + * addiu sp,sp,-40 + * sw s1,28(sp) + * move s1,a0 p + * sw s0,24(sp) + * move s0,a1 arg + * sw s2,32(sp) + * move s2,a2 out + * sw ra,36(sp) + * jal 0x800231BC + * addiu a1,sp,16 (delay slot) &tmp (a0 still holds p) + * lw v0,16(sp) + * nop (load delay) + * slt v0,s0,v0 arg < tmp + * beqz v0,0x8009911C else: negate-only arm + * negu s0,s0 (delay slot) -arg, kept for all three calls + * lw a0,0(s1) + * jal 0x80010654 + * move a1,s0 (delay slot) + * sw v0,0(s2) out[0] = f(p[0], -arg) + * ... the same for p[1] and p[2] ... + * lw a0,0(s2) + * lw a1,16(sp) tmp + * jal 0x80010698 + * sw v0,8(s2) (delay slot) out[2] = f(p[2], -arg) + * lw a0,4(s2) + * sw v0,0(s2) out[0] = g(out[0], tmp) + * ... the same for out[1] and out[2] ... + * j 0x8009914C + * sw v0,8(s2) (delay slot) out[2] = g(out[2], tmp) + * lw v0,0(s1) negate-only arm + * nop + * negu v0,v0 + * sw v0,0(s2) + * ... the same for p[1] and p[2] ... + * li v0,1 + * lw ra,36(sp) + * lw s2,32(sp) + * lw s1,28(sp) + * lw s0,24(sp) + * addiu sp,sp,40 + * jr ra + * nop + * + * The frame is 40 bytes: the 16-byte o32 outgoing argument area, the local + * `tmp` at 16(sp), `s0` at 24(sp), `s1` at 28(sp), `s2` at 32(sp) and `ra` at + * 36(sp). The first call receives `p` in `a0` unchanged (the `move s1,a0` does + * not disturb it), so it takes the object AND the out-parameter. The three + * `out[i]` values are written and then read back through the pointer rather + * than kept in registers, because each store is followed by a call. + * + * LIMITS: the function names, the helpers' arities and semantics, the vector + * stride and the meaning of the comparison and the negation are hypotheses + * reconstructed from the disassembly. Only the compiled bytes are evidence. + */ + +int func_800231BC(int *, int *); +int func_80010654(int, int); +int func_80010698(int, int); + +int func_80099078(int *p, int arg, int *out) { + int tmp; + + func_800231BC(p, &tmp); + + if (arg < tmp) { + out[0] = func_80010654(p[0], -arg); + out[1] = func_80010654(p[1], -arg); + out[2] = func_80010654(p[2], -arg); + + out[0] = func_80010698(out[0], tmp); + out[1] = func_80010698(out[1], tmp); + out[2] = func_80010698(out[2], tmp); + } else { + out[0] = -p[0]; + out[1] = -p[1]; + out[2] = -p[2]; + } + + return 1; +} diff --git a/src/func_800A6934.c b/src/func_800A6934.c new file mode 100644 index 0000000..4e61d1c --- /dev/null +++ b/src/func_800A6934.c @@ -0,0 +1,74 @@ +/* + * func_800A6934 — 100 bytes at 0x800A6934..0x800A6998 + * + * Byte-identical reconstruction of a framed predicate: it refuses when a + * small-data flag is set, otherwise selects one of two small-data words by a + * second state value, refuses again when that word is non-zero, and finally + * runs one call and reports success. + * + * The observed instructions are: + * lbu v0,1544(gp) D_80121F40 + * addiu sp,sp,-24 + * bnez v0,0x800A6984 if (flag) return 0 + * sw ra,16(sp) (delay slot) + * lui v0,0x8012 + * lw v0,7048(v0) *(int *)0x80121B88 + * nop (load delay) + * bnez v0,0x800A6964 + * nop + * lw v0,3516(gp) D_801226F4 + * j 0x800A6968 + * nop + * lw v0,3536(gp) D_80122708 + * nop + * bnez v0,0x800A6988 if (v) return 0 + * move v0,zero (delay slot) + * jal 0x800A745C + * nop + * j 0x800A6988 + * li v0,1 (delay slot) + * move v0,zero + * lw ra,16(sp) + * addiu sp,sp,24 + * jr ra + * nop + * + * The frame is 24 bytes: the 16-byte o32 outgoing argument area plus `ra` at + * 16(sp). The `nop` at 0x800A6968 is both the load-delay filler for the + * `lw v0,3536(gp)` above it and the target of the `j` at 0x800A695C — the + * two paths share one merge point, which is why one `nop` serves both. Both + * selected words are `gp`-relative (gp = 0x80121938), and 0x80121B88 is read + * as a **literal** constant address so it keeps the absolute encoding rather + * than the `gp`-relative form its registry symbol would force. + * + * LIMITS: the function name, the callee's arity, the flag's and words' + * meanings and the literal 13-family constants are hypotheses reconstructed + * from the disassembly. Only the compiled bytes are evidence. The two-arm + * selection is written with the **inverted** `== 0` condition because the + * original's `bnez` jumps over the first arm to the second — the mirrored + * block layout of cookbook finding 28, not the natural spelling. + */ + +extern char D_80121F40; +extern int D_801226F4; +extern int D_80122708; + +void func_800A745C(void); + +int func_800A6934(void) { + int v; + + if (D_80121F40 != 0) + return 0; + + if (*(int *)0x80121B88 == 0) + v = D_801226F4; + else + v = D_80122708; + + if (v != 0) + return 0; + + func_800A745C(); + return 1; +} diff --git a/src/func_800A6A18.c b/src/func_800A6A18.c new file mode 100644 index 0000000..50b499d --- /dev/null +++ b/src/func_800A6A18.c @@ -0,0 +1,76 @@ +/* func_800A6A18 — 0x800A6A18..0x800A6A70 (88 bytes). + * + * Original words (objdump of the validated payload, little-endian): + * addiu sp,sp,-48 + * move v0,a0 v0 = parameter 0 + * sw s0,40(sp) + * move s0,a1 s0 = parameter 1 + * addiu a0,sp,16 a0 = &local (sp+16) + * sw ra,44(sp) + * jal 0x800267CC + * _move a1,v0 (delay slot; parameter 0 as the second argument) + * beqz v0,0x800A6A58 result == 0 -> return 5 + * _nop + * sw s0,3532(gp) D_80122704 = parameter 1 + * jal 0x800FB13C + * _addiu a0,sp,16 (delay slot; &local again) + * sw v0,3528(gp) D_80122700 = result + * j 0x800A6A5C + * _move v0,zero (delay slot; return 0) + * 0x800A6A58: + * li v0,5 return 5 + * 0x800A6A5C: + * lw ra,44(sp) + * lw s0,40(sp) + * addiu sp,sp,48 + * jr ra + * _nop + * + * A framed guard that fills a 24-byte local through an unregistered callee and, + * on success, publishes the second parameter and a value derived from the local + * into the small-data block. Both globals are gp-relative full-word stores + * (gp = 0x80121938; 0x80121938 + 3528 = 0x80122700, + 3532 = 0x80122704), so + * both are `int` — the same small-data run as the registered `func_800A6934` + * (D_801226F4 at +3516, D_80122708 at +3536), which types them `int` too. Both + * `sw`s store full words: parameter 1 is an `int` and the callee returns `int`. + * + * The local is passed by address to both callees. `func_800FB13C` reads it as + * `unsigned char *p` and consumes p[0..2] as packed BCD; `func_800267CC` writes + * at least a word at offset 4 of it (`sw v0,4(s3)` inside that body), so the + * object is at least 8 bytes and is byte-addressable at the front. + * + * FRAME SIZE / LIMITS (unresolved, recorded rather than guessed): the frame is + * 48 bytes = the 16-byte o32 outgoing argument area + the local at sp+16 + the + * 8-byte saved area at sp+40/44. That constrains the local to **17..24 bytes**, + * and it does not narrow further: declared sizes 17, 20 and 24 all compile to + * byte-identical output (16 and 12 differ only in the frame size, 6 bytes at + * 0x800A6A18), because cc1 rounds the local area up when placing the saved + * registers. 24 is chosen as the largest consistent size and the round number; + * the true declared size is not observable from these bytes. + * + * SYMBOL DEPENDENCY: D_80122700 and D_80122704 are NOT yet in + * config/symbols.tsv. They must be added with the `gp` marker (see + * .run/p10/w-b/symbols-request.tsv) or the two stores encode absolutely instead + * of gp-relative. This claim was verified against a local overlay of the + * tracked registry plus those two rows. + * + * LIMITS (semantics): the purpose of the guard, the local's layout, the meaning + * of the two published words, and the 5/0 return codes are not observable. + * Only the compiled bytes are evidence. + */ + +extern int D_80122700; +extern int D_80122704; +extern int func_800267CC(void *a0, int a1); +extern int func_800FB13C(unsigned char *p); + +int func_800A6A18(int a0, int a1) +{ + unsigned char buf[24]; + + if (func_800267CC(buf, a0) == 0) + return 5; + D_80122704 = a1; + D_80122700 = func_800FB13C(buf); + return 0; +} diff --git a/src/func_800A6BEC.c b/src/func_800A6BEC.c new file mode 100644 index 0000000..2e635ec --- /dev/null +++ b/src/func_800A6BEC.c @@ -0,0 +1,77 @@ +/* + * func_800A6BEC — 72 bytes at 0x800A6BEC..0x800A6C34 + * + * Framed routine that clears one byte of an 8-byte stack buffer and makes three + * calls, the first two with a shared gp-relative pointer and the buffer address. + * + * The observed instructions are: + * addiu sp,sp,-0x20 27bdffe0 frame, 32 bytes + * li a0,0xe 2404000e a0 = 14 + * addiu a1,sp,0x10 27a50010 a1 = &buf + * addiu a2,gp,0xdc0 27860dc0 a2 = D_801226F8 (gp+0xdc0) + * sw ra,0x18(sp) afbf0018 save ra + * jal 0x800f8df0 0c03e37c call func_800F8DF0 + * sb zero,0x10(sp) a3a00010 buf[0] = 0 (delay slot) + * li a0,8 24040008 a0 = 8 + * addiu a2,gp,0xdc0 27860dc0 a2 = D_801226F8 + * jal 0x800f8df0 0c03e37c call func_800F8DF0 + * addiu a1,sp,0x10 27a50010 a1 = &buf (delay slot) + * addiu a1,gp,0xdc0 27850dc0 a1 = D_801226F8 + * jal 0x800f8b18 0c03e2c6 call func_800F8B18 + * addu a0,zero,zero 00002021 a0 = 0 (delay slot) + * lw ra,0x18(sp) 8fbf0018 restore ra + * addiu sp,sp,0x20 27bd0020 frame release + * jr ra 03e00008 + * nop 00000000 (delay slot) + * + * Frame arithmetic: `sw ra,0x18(sp)` bounds the save area at 0x18, so the local + * area is sp+0x10..sp+0x18 — 8 bytes — and the frame rounds to 0x20. + * + * Two encoding notes that were checked against the payload bytes rather than the + * Ghidra mnemonics: the constant loads are `addiu rd,zero,imm` (so `li`), and the + * third call's zero argument is `addu a0,zero,zero` (Ghidra's `clear`), not + * `addiu a0,zero,0`. + * + * THE `-G` REQUIREMENT (the reason this region carries a `cc1=` override). The + * three `addiu rt,gp,0xdc0` are the address of D_801226F8 materialised once per + * call site, straight into the argument register. Under the harness default + * `-G0` the symbol is not small data, so cc1 emits `la` as a two-instruction + * large-data address, CSE hoists it into a callee-saved register, and the body + * comes out 84 bytes (`sw s0`/`lw s0` added, ra moved 0x18 -> 0x1c). With a + * nonzero `-G` that admits the symbol, cc1 treats the address as small data and + * emits one `la` per use with no hoist. Measured matrix (all against this range): + * + * G=0 size=4 -> 84 bytes LENGTH-MISMATCH + * G=4 size=1 -> 72 bytes MATCH G=8 size=1 -> 72 bytes MATCH + * G=4 size=4 -> 72 bytes MATCH G=8 size=4 -> 72 bytes MATCH + * G=4 size=8 -> 84 bytes LENGTH-MISMATCH + * G=8 size=8 -> 72 bytes MATCH G=8 size=16 -> 84 bytes LENGTH-MISMATCH + * + * The rule is exactly `declared size <= G`. A `__attribute__((section(".sdata")))` + * on the declaration does not substitute for it (tested at -G0: still 84 bytes). + * This is the first byte-visible evidence that the original build ran cc1 with a + * nonzero `-G`: with `-G0` no symbol is small data and the gp-relative form + * cannot be produced by cc1 at all. The symbol's true size is unknown; the next + * symbol above it is at 0x80122708, so it is at most 16 bytes. + * + * LIMITS: the callees, the global and the meaning of the two small integer + * arguments are hypotheses; only the bytes are evidence. `buf`'s size is fixed + * by the frame arithmetic; only `buf[0]` is ever written, so its type is a + * hypothesis and the buffer is declared `char` because the single observed store + * is a byte store. The declared size 8 is the largest the `-G8` override admits + * and is not an independent measurement. + */ + +extern char D_801226F8[8]; +extern void func_800F8DF0(int a0, char *a1, char *a2); +extern void func_800F8B18(int a0, char *a1); + +void func_800A6BEC(void) +{ + char buf[8]; + + buf[0] = 0; + func_800F8DF0(0xe, buf, D_801226F8); + func_800F8DF0(8, buf, D_801226F8); + func_800F8B18(0, D_801226F8); +} diff --git a/src/func_800ACAC8.c b/src/func_800ACAC8.c new file mode 100644 index 0000000..d028291 --- /dev/null +++ b/src/func_800ACAC8.c @@ -0,0 +1,65 @@ +/* + * func_800ACAC8 — 108 bytes at 0x800ACAC8..0x800ACB34 + * + * Teardown: conditionally closes a handle, then for a non-null argument resolves a + * value and passes it on with a flag, and finally poisons the handle global. + * + * Original words: + * 27BDFFE8 addiu sp,sp,-24 + * AFB00010 sw s0,16(sp) + * 00808021 addu s0,a0,zero ; s0 = a0 (survives two calls) + * 8F8406D8 lw a0,1752(gp) ; a0 = D_80122010 + * AFBF0014 sw ra,20(sp) + * 0C02A791 jal 0x800A9E44 + * 00000000 nop ; (delay) func_800A9E44(handle) + * 10400004 beq v0,zero,0x800ACAF8 ; zero -> skip the close + * 00000000 nop + * 8F8406D8 lw a0,1752(gp) ; a0 = D_80122010 (RELOADED) + * 0C02A756 jal 0x800A9D58 + * 00000000 nop ; (delay) func_800A9D58(handle) + * 12000007 beq s0,zero,0x800ACB18 ; null argument -> skip + * 00002021 addu a0,zero,zero ; (delay) a0 = 0 + * 02002821 addu a1,s0,zero ; a1 = a0 (the argument) + * 0C018E1C jal 0x80063870 + * 00003021 addu a2,zero,zero ; (delay) a2 = 0 + * 00402021 addu a0,v0,zero ; a0 = the resolved value + * 0C02A7DF jal 0x800A9F7C + * 24050001 addiu a1,zero,1 ; (delay) func_800A9F7C(value, 1) + * 2402FFFF addiu v0,zero,-1 ; D_80122010 = -1 + * AF8206D8 sw v0,1752(gp) + * 8FBF0014 lw ra,20(sp) + * 8FB00010 lw s0,16(sp) + * 27BD0018 addiu sp,sp,24 + * 03E00008 jr ra + * 00000000 nop + * + * The handle global is loaded TWICE (once per call) rather than held in a + * register, so it is read at each use. The three-argument call takes the zero + * constant in `a0` and the incoming argument in `a1`, and its result is the first + * argument of the two-argument call whose second argument is the constant 1. + * `D_80122010` is set to -1 through `v0` at the single exit, which is shared by + * both early paths (the frame is entered before either test). + * + * LIMITS: the function name, the four callees, the handle global and the meaning + * of the constants 0 and 1 are hypotheses read from the instruction shape; only + * the bytes are evidence. func_800A9E44, func_80063870 and func_800A9F7C are not + * registered and are referenced by their address-named spellings. The frame's + * `s0` slot holds the argument because it must survive two calls. + */ + +extern int D_80122010; +extern int func_800A9E44(int a0); +extern void func_800A9D58(int a0); +extern int func_80063870(int a0, int a1, int a2); +extern void func_800A9F7C(int a0, int a1); + +void func_800ACAC8(int a0) +{ + if (func_800A9E44(D_80122010) != 0) + func_800A9D58(D_80122010); + + if (a0 != 0) + func_800A9F7C(func_80063870(0, a0, 0), 1); + + D_80122010 = -1; +} diff --git a/src/func_800AE4DC.c b/src/func_800AE4DC.c new file mode 100644 index 0000000..52b90fc --- /dev/null +++ b/src/func_800AE4DC.c @@ -0,0 +1,84 @@ +/* func_800AE4DC — 0x800AE4DC..0x800AE548 (108 bytes). + * + * Original words (objdump of the validated payload, little-endian): + * addiu sp,sp,-32 + * sw s0,24(sp) + * move s0,a0 s0 = the argument + * sw ra,28(sp) + * lbu v0,0(s0) v0 = p[0] (UNSIGNED byte) + * _nop + * ori v0,v0,0x20 v0 |= 0x20 + * jal 0x800AE458 + * _sb v0,0(s0) (delay slot) p[0] = v0 + * addiu a1,sp,16 a1 = &a (sp+16) + * lbu a0,1(s0) a0 = p[1] + * jal 0x800AE0F4 + * _addiu a2,sp,18 (delay slot) a2 = &b (sp+18) + * lui v0,0x8012 + * lbu v0,9076(v0) v0 = *(unsigned char *)0x80122374 + * _nop load-delay slot + * beqz v0,0x800AE534 flag == 0 -> epilogue + * _li a1,600 (delay slot) + * lui a0,0x800b + * addiu a0,a0,-8288 a0 = &D_800ADFA0 (%hi/%lo form) + * jal 0x8002D0A8 + * _move a2,s0 (delay slot) a2 = p + * 0x800AE534: + * lw ra,28(sp) + * lw s0,24(sp) + * addiu sp,sp,32 + * jr ra + * _nop + * + * Sets bit 5 of the first byte, runs a no-argument call, splits the second byte + * into two halfword out-parameters, and — only when a byte flag is set — reports + * through a three-argument callee. The argument is kept in s0 across the first + * two calls because it is still the third argument of the last one. The frame is + * 32 bytes = 16 (o32 outgoing args) + 8 (the two `short` out-parameters at + * sp+16/18) + the saved s0/ra pair at sp+24/28. The `lbu`/`sb` pair fixes an + * unsigned byte, and `func_800AE0F4`'s registered prototype + * (`unsigned int value, short *p1, short *p2`) fixes the argument order + * (value in a0, then p1, then p2). + * + * ENCODING LEVER (the byte-difference this body turns on): the third argument's + * first pointer must be a SYMBOL reference, not a folded literal constant. The + * original materialises it as `lui a0,0x800b` + `addiu a0,a0,-8288` — the + * `%hi`/`%lo` form, whose high half is incremented because the low half has bit + * 15 set. Writing the literal `(char *)0x800ADFA0` makes cc1 fold the constant + * and emit `lui a0,0x800a` + `ori a0,a0,0xdfa0` instead, which also knocks the + * scheduler off: the two instructions land in the `beqz` delay slot and push + * `li a1,600` after the branch, for 11 differing bytes. Declaring + * `extern char D_800ADFA0;` and passing `&D_800ADFA0` restores the symbol form + * and matches byte-for-byte. Diagnostic: `lui hi, ori lo` = folded literal; + * `lui hi+1, addiu -lo` = symbol. + * + * SYMBOL NOTE: `D_800ADFA0` is not in config/symbols.tsv; the harness resolved + * it implicitly from the name-encoded address, exactly as it resolves + * `func_XXXXXXXX` callees. No registry change was needed for this claim. If the + * merged whole-binary build needs an explicit row, add `D_800ADFA0 0x800ADFA0`. + * + * LIMITS: the object at 0x800ADFA0 is only proven to be an address; whether it + * is a string, a table or a structure is not observable, and the `char` type is + * the minimal declaration that yields the right pointer. The meaning of the + * literal 600, the byte flag at 0x80122374, bit 5, and the callees' names are + * hypotheses read from the instruction shapes. `func_800AE458` is called with no + * arguments; the call site leaves a0 holding the parameter either way, so a + * source that passed it would compile identically. Only the compiled bytes are + * evidence. + */ + +extern char D_800ADFA0; +extern void func_800AE458(void); +extern void func_800AE0F4(unsigned int value, short *p1, short *p2); +extern void func_8002D0A8(char *a0, int a1, int a2); + +void func_800AE4DC(unsigned char *p) +{ + short a, b; + + p[0] |= 0x20; + func_800AE458(); + func_800AE0F4(p[1], &a, &b); + if (*(unsigned char *)0x80122374) + func_8002D0A8(&D_800ADFA0, 600, (char *)p); +} diff --git a/src/func_800B1D5C.c b/src/func_800B1D5C.c new file mode 100644 index 0000000..37d567f --- /dev/null +++ b/src/func_800B1D5C.c @@ -0,0 +1,90 @@ +/* func_800B1D5C — 0x800B1D5C..0x800B1DD0 (116 bytes). + * + * Original words (objdump of the validated payload, little-endian): + * addiu sp,sp,-72 + * sw ra,64(sp) + * lw v0,12(a1) v0 = *(int *)(a1 + 12) + * _nop load-delay slot + * lw v1,0(v0) \ 16-byte block copy + * lw a0,4(v0) | (all four loads, then all four stores — + * lw a1,8(v0) | cc1's block_move, i.e. a STRUCT ASSIGNMENT) + * lw a2,12(v0) | + * sw v1,16(sp) | + * sw a0,20(sp) | + * sw a1,24(sp) | + * sw a2,28(sp) / + * addiu a1,sp,32 a1 = &t (sp+32) + * addiu a2,sp,56 a2 = &v (sp+56) + * lw v0,20(sp) v0 = s.f1 (word) + * lw v1,16(sp) v1 = s.f0 (word) + * lhu a0,24(sp) a0 = s.f2 (UNSIGNED halfword) + * negu v0,v0 -s.f1 + * sh a0,52(sp) u.h2 = s.f2 + * addiu a0,sp,48 a0 = &u (sp+48) + * sw v0,20(sp) s.f1 = -s.f1 (the negation is stored BACK) + * sh v1,48(sp) u.h0 = s.f0 + * jal 0x80101C2C + * _sh v0,50(sp) (delay slot) u.h1 = -s.f1 + * lw v0,40(sp) v0 = t.g2 (sp+40 = t+8) + * lw ra,64(sp) + * addiu sp,sp,72 + * jr ra + * _nop + * + * Copies a 16-byte structure out of a doubly-indirected pointer, negates its + * second word **in place**, projects three of its fields into a halfword record, + * passes that record plus two output records to a callee, and returns a word + * from one of the outputs. The frame is 72 bytes = 16 (o32 outgoing args) + 48 of + * locals + the saved ra at sp+64. The locals are the copied structure at sp+16 + * (16 bytes), t at sp+32 (16), u at sp+48 (8) and v at sp+56 (8) — the + * declaration order s, t, u, v. + * + * FOUR THINGS THE BYTES PIN DOWN: + * 1. `s = *(struct S *)p` is a real STRUCT ASSIGNMENT, not four int assignments: + * cc1's block_move emits all four loads before all four stores (using + * v1/a0/a1/a2), which the four-separate-assignments spelling does not produce. + * 2. Offset 8 of the copied structure is read with `lhu`, so that field is an + * `unsigned short` while offsets 0 and 4 are full words. Declared as four ints + * the same source emits `lw` there. + * 3. The negation is stored BACK to the structure (`sw v0,20(sp)`), so the source + * modifies the copy in place — and `u.h1 = s.f1` then reuses the negated value + * (one `lw` feeds both the `negu` and the two stores), so the source reads the + * field back rather than negating twice. + * 4. STATEMENT ORDER IS THE LEVER: the three record stores and the negation must + * be written `s.f1 = -s.f1; u.h0 = s.f0; u.h1 = s.f1; u.h2 = s.f2;`. All ten + * permutations of these four statements were compiled; only that one is + * byte-identical (the others leave 4-31 differing bytes), because cc1's + * scheduler keeps this store order. The "natural" order is also the correct + * one here — worth checking first on similar record-building bodies. + * + * LIMITS: the field names, `t`'s layout (only t+8 is proven, by the returned + * `lw`), `u`'s fourth halfword (padding, never read), and `v`'s size (8 bytes, + * inferred from the frame rather than read) are hypotheses. The callee is + * declared with its REGISTERED prototype `(const int *, int *, int *)` and the + * struct pointers are cast at the call site; a struct-typed prototype compiles + * identically, so the pointer types are not observable. What the structures mean + * is unknown and not guessed. Only the compiled bytes are evidence. + */ + +struct S { int f0; int f1; unsigned short f2; unsigned short f3; int f4; }; +struct T { int g0, g1, g2, g3; }; +struct U { short h0; short h1; unsigned short h2; short h3; }; +struct V { int i0, i1; }; + +extern void func_80101C2C(const int *a0, int *a1, int *a2); + +int func_800B1D5C(int a0, int a1) +{ + struct S s; + struct T t; + struct U u; + struct V v; + + s = *(struct S *)(*(int *)(a1 + 12)); + s.f1 = -s.f1; + u.h0 = s.f0; + u.h1 = s.f1; + u.h2 = s.f2; + func_80101C2C((const int *)&u, (int *)&t, (int *)&v); + return t.g2; +} diff --git a/src/func_800B6C60.c b/src/func_800B6C60.c new file mode 100644 index 0000000..045b4b9 --- /dev/null +++ b/src/func_800B6C60.c @@ -0,0 +1,59 @@ +/* + * func_800B6C60 — 84 bytes at 0x800B6C60..0x800B6CB4 + * + * Byte-identical reconstruction of a framed routine that queries a lookup, + * and on a non-null answer announces it to a small-data buffer, flags the + * event, and dispatches a three-argument call with the original argument. + * + * The observed instructions are: + * addiu sp,sp,-24 + * sw s0,16(sp) + * sw ra,20(sp) + * jal 0x800B6BDC + * move s0,a0 (delay slot) s = argument + * beqz v0,0x800B6CA0 if (r == 0) return + * nop + * addiu a0,gp,1788 a0 = &D_80122034 (small-data address) + * jal 0x80026560 + * move a1,v0 (delay slot) a1 = r + * li v0,1 + * sb v0,1794(gp) D_8012203A = 1 + * move a0,s0 a0 = s + * li a1,2 + * jal 0x800B6894 + * move a2,zero (delay slot) + * lw ra,20(sp) + * lw s0,16(sp) + * addiu sp,sp,24 + * jr ra + * nop + * + * The frame is 24 bytes: the 16-byte o32 outgoing argument area plus `s0` at + * 16(sp) and `ra` at 20(sp). `addiu a0,gp,1788` is the small-data *address* + * form (`la` of a `gp`-relative symbol, 1788 + 0x80121938 = 0x80122034), not a + * load: taking the address of a `gp` symbol keeps the `gp` base and an + * immediate, so it needs the registry's `gp` marker on the name. + * + * LIMITS: the function names, the callee's parameter count and types, the + * global types and the flag's meaning are hypotheses reconstructed from the + * disassembly. Only the compiled bytes are evidence. Whether the first call's + * argument is `&D_80122034` or a byte offset from a base is not observable; + * only the `addiu a0,gp,1788` encoding is. + */ + +extern char D_80122034; +extern char D_8012203A; + +char *func_800B6BDC(int); +void func_80026560(char *, char *); +void func_800B6894(int, int, int); + +void func_800B6C60(int key) { + char *r = func_800B6BDC(key); + + if (r != 0) { + func_80026560(&D_80122034, r); + D_8012203A = 1; + func_800B6894(key, 2, 0); + } +} diff --git a/src/func_80105148.c b/src/func_80105148.c new file mode 100644 index 0000000..de3117c --- /dev/null +++ b/src/func_80105148.c @@ -0,0 +1,78 @@ +/* + * func_80105148 — 132 bytes at 0x80105148..0x801051CC + * + * Byte-identical reconstruction of a framed three-way dispatch on a byte field + * of the object passed in: each arm calls a different routine with a different + * argument drawn from the same object, and all three fall to one return. + * + * The observed instructions are: + * addiu sp,sp,-24 + * sw ra,16(sp) + * lbu v1,70(a0) v1 = p[70] + * li v0,3 + * beq v1,v0,0x8010519C case 3 + * slti v0,v1,4 (delay slot) + * beqz v0,0x80105178 + * li v0,2 (delay slot) + * beq v1,v0,0x8010518C case 2 + * nop + * j 0x801051BC default + * nop + * li v0,4 + * beq v1,v0,0x801051B0 case 4 + * nop + * j 0x801051BC default + * nop + * jal 0x80105B54 case 2 + * nop + * j 0x801051BC + * nop + * lbu a1,228(a0) case 3 + * jal 0x80105B68 + * nop + * j 0x801051BC + * nop + * lbu a1,71(a0) case 4 + * jal 0x80105BA8 + * nop + * lw ra,16(sp) + * addiu sp,sp,24 + * jr ra + * nop + * + * The frame is 24 bytes: the 16-byte o32 outgoing argument area plus `ra` at + * 16(sp). The decision tree is the balanced form cc1 emits for the three case + * values 2/3/4 — test the middle value first, then split on `< 4` — and the + * default arm is a jump to the shared epilogue rather than a fall-through, + * because every arm ends at the same return. The `lbu` loads (rather than + * `lb`) are why the field is `unsigned char`: plain `char` is unsigned on this + * target (cookbook finding 7). + * + * LIMITS: the function name, the callees' arities and parameter types, the + * field offsets and the case meanings are hypotheses reconstructed from the + * disassembly. Only the compiled bytes are evidence. Whether the switch + * selector is a struct field or an array element is not observable; only + * `lbu v1,70(a0)` is. The two `lbu`s target `a1`, not `a0`, and `a0` still + * holds the incoming object pointer at both call sites — so each arm passes + * the object as the FIRST argument and the loaded byte as the second, and the + * case-2 call passes the object too (which costs no instruction, since `a0` + * is already loaded). + */ + +void func_80105B54(unsigned char *); +void func_80105B68(unsigned char *, unsigned char); +void func_80105BA8(unsigned char *, unsigned char); + +void func_80105148(unsigned char *p) { + switch (p[70]) { + case 2: + func_80105B54(p); + break; + case 3: + func_80105B68(p, p[228]); + break; + case 4: + func_80105BA8(p, p[71]); + break; + } +} diff --git a/tools/patches/maspsx-phase10-r1r2.patch b/tools/patches/maspsx-phase10-r1r2.patch new file mode 100644 index 0000000..5301b56 --- /dev/null +++ b/tools/patches/maspsx-phase10-r1r2.patch @@ -0,0 +1,113 @@ +--- a/maspsx/__init__.py ++++ b/maspsx/__init__.py +@@ -78,6 +78,38 @@ + return line.strip() + + ++def line_jumps_via_reg(line: str, r_source: str) -> bool: ++ """True if `line` is a register jump whose target is `r_source`. ++ ++ Cookbook finding 27's gap: the delay-nop predicate (`line_loads_from_reg`) ++ recognises loads and branches but not `jr`/`jalr`, and `jr`/`jalr` are not in ++ `jump_mnemonics` either, so a load feeding a register jump got no delay nop. ++ ++ This is OPT-IN (`--nop-on-reg-read`): the default must stay byte-identical for ++ the corpus already matched against it. Local patch to a pinned vendored tool; ++ see docs/SETUP.md for provenance. ++ """ ++ line = strip_comments(line) ++ ++ # escape dollar ++ r_source = r_source.replace("$", r"\$") ++ ++ if match := re.match(r"^([A-z][A-z0-9]*)\s+(.*)$", line): ++ op, rest = match.group(1, 2) ++ else: ++ return False ++ ++ if op in ("jr", "jalr"): ++ # jr $31 ++ if re.match(rf"^{r_source}$", rest): ++ return True ++ # jalr $2,$31 (destination first, target last) ++ if re.match(rf"^.*,\s*{r_source}\s*$", rest): ++ return True ++ ++ return False ++ ++ + def line_loads_from_reg(line: str, r_source: str, loads_to_reg=False) -> bool: + """ + NOTE: Returns True even if line might use $at expansion +@@ -448,6 +480,8 @@ + gp_allow_la=False, + use_comm_section=False, + use_comm_for_lcomm=False, ++ no_jump_slot_nop=False, ++ nop_on_reg_read=False, + ): + self.lines = [x.strip() for x in lines] + +@@ -460,6 +494,15 @@ + self.nop_mflo_mfhi = nop_mflo_mfhi + self.nop_lw_lw = nop_lw_lw + ++ # Local opt-in modes (Phase 10, developer-authorised). Both default off so ++ # the matched corpus reproduces byte-identically. ++ # no_jump_slot_nop: suppress the unconditional reorder nop after a ++ # branch/jump, so GNU `as` can fill the slot itself (worker C's R1). ++ # nop_on_reg_read: additionally treat a following `jr`/`jalr` that uses ++ # the loaded register as needing the delay nop (worker C's R2). ++ self.no_jump_slot_nop = no_jump_slot_nop ++ self.nop_on_reg_read = nop_on_reg_read ++ + self.sltu_at = sltu_at + self.addiu_at = addiu_at + self.div_uses_tge = div_uses_tge +@@ -696,7 +739,14 @@ + ) -> List[str]: + res: List[str] = [] + +- if line_loads_from_reg(next_instruction, r_dest, loads_to_reg=self.nop_lw_lw): ++ reuse = line_loads_from_reg(next_instruction, r_dest, loads_to_reg=self.nop_lw_lw) ++ if not reuse and self.nop_on_reg_read: ++ # Cookbook finding 27's gap: the predicate above recognises loads and ++ # branches but not `jr`/`jalr`, so a load feeding a register jump got ++ # no delay nop. Opt-in, so the default path is unchanged. ++ reuse = line_jumps_via_reg(next_instruction, r_dest) ++ ++ if reuse: + nop_required = False + + if not uses_at(next_instruction): +@@ -1102,7 +1152,7 @@ + + elif op in branch_mnemonics or op in jump_mnemonics: + res.append(line) +- if self.is_reorder: ++ if self.is_reorder and not self.no_jump_slot_nop: + res.append("nop # DEBUG: branch/jump") + + elif op == "move": +--- a/maspsx.py ++++ b/maspsx.py +@@ -62,6 +62,10 @@ + parser.add_argument("--passthrough", action="store_true") + parser.add_argument("--use-comm-section", action="store_true") + parser.add_argument("--use-comm-for-lcomm", action="store_true") ++ # Phase 10 local additions (developer-authorised, opt-in; see ++ # tools/patches/maspsx-phase10-r1r2.patch and docs/SETUP.md). ++ parser.add_argument("--no-jump-slot-nop", action="store_true") ++ parser.add_argument("--nop-on-reg-read", action="store_true") + # decomp.me debugging + parser.add_argument("--print-output", action="store_true") + parser.add_argument("--print-input", action="store_true") +@@ -152,6 +156,8 @@ + gp_allow_la=version_config.gp_allow_la, + use_comm_section=args.use_comm_section, + use_comm_for_lcomm=args.use_comm_for_lcomm, ++ no_jump_slot_nop=args.no_jump_slot_nop, ++ nop_on_reg_read=args.nop_on_reg_read, + ) + + try: diff --git a/tools/sf3_match b/tools/sf3_match index f37b4cb..72d446b 100755 --- a/tools/sf3_match +++ b/tools/sf3_match @@ -186,6 +186,7 @@ class Region: as_flags: tuple[str, ...] = () no_gp: tuple[str, ...] = () no_maspsx: bool = False + maspsx_flags: tuple[str, ...] = () # A region's optional fourth field: space-separated `key=value` overrides. @@ -198,13 +199,22 @@ class Region: # maspsx's unconditional `nop` for a jump destroys the delay-slot fill that GNU # `as` reorder mode performs on an expanded symbol store (0x80102B10, 0x800F8B6C, # 0x800F3160), while the ASPSX `la`/`addiu` form needs maspsx (func_8002D2BC). +# The same key also takes Phase 10's opt-in maspsx modes, which are local additions +# to the pinned vendored tool (tools/patches/maspsx-phase10-r1r2.patch): +# `maspsx=noreordernop` suppresses maspsx's unconditional reorder `nop` after a +# branch/jump so GNU `as` can fill the slot itself (worker C's R1). +# `maspsx=regread` additionally treats a following `jr`/`jalr` that uses the +# loaded register as needing the load-delay `nop` (worker C's R2). +# Both default off, so every region without them compiles exactly as before. _REGION_OPTION_KEYS = ("cc1", "as", "gp", "maspsx") +_MASPSX_MODES = {"off": "--off", "noreordernop": "--no-jump-slot-nop", + "regread": "--nop-on-reg-read"} -def parse_region_options(text: str, line_number: int) -> tuple[tuple[str, ...], tuple[str, ...], tuple[str, ...], bool]: +def parse_region_options(text: str, line_number: int) -> tuple[tuple[str, ...], tuple[str, ...], tuple[str, ...], bool, tuple[str, ...]]: """Parse the optional per-region override field. - Returns `(cc1_flags, as_flags, no_gp, no_maspsx)`. `gp=-NAME` names a symbol + Returns `(cc1_flags, as_flags, no_gp, no_maspsx, maspsx_flags)`. `gp=-NAME` names a symbol the registry marks `gp` that this region accesses absolutely instead, and `maspsx=off` drops the ASPSX emulation stage for this region. """ @@ -239,13 +249,19 @@ def parse_region_options(text: str, line_number: int) -> tuple[tuple[str, ...], ) no_gp.append(name[1:]) no_maspsx = False + maspsx_flags: list[str] = [] for value in overrides.get("maspsx", ()): - if value not in ("on", "off"): + if value not in _MASPSX_MODES: raise ToolError( - f"regions line {line_number}: expected 'maspsx=on' or 'maspsx=off', got {value!r}" + f"regions line {line_number}: expected one of " + f"{', '.join(sorted(_MASPSX_MODES))} for 'maspsx', got {value!r}" ) - no_maspsx = value == "off" - return (overrides.get("cc1", ()), overrides.get("as", ()), tuple(no_gp), no_maspsx) + if value == "off": + no_maspsx = True + else: + maspsx_flags.append(_MASPSX_MODES[value]) + return (overrides.get("cc1", ()), overrides.get("as", ()), tuple(no_gp), no_maspsx, + tuple(maspsx_flags)) def parse_regions(text: str) -> list[Region]: @@ -263,10 +279,10 @@ def parse_regions(text: str) -> list[Region]: end = parse_address(fields[1]) if not 0 <= start < end: raise ToolError(f"regions line {number}: invalid range") - cc1_flags, as_flags, no_gp, no_maspsx = ((), (), (), False) + cc1_flags, as_flags, no_gp, no_maspsx, maspsx_flags = ((), (), (), False, ()) if len(fields) == 4: - cc1_flags, as_flags, no_gp, no_maspsx = parse_region_options(fields[3], number) - regions.append(Region(start, end, fields[2], cc1_flags, as_flags, no_gp, no_maspsx)) + cc1_flags, as_flags, no_gp, no_maspsx, maspsx_flags = parse_region_options(fields[3], number) + regions.append(Region(start, end, fields[2], cc1_flags, as_flags, no_gp, no_maspsx, maspsx_flags)) regions.sort(key=lambda region: region.start) for left, right in zip(regions, regions[1:]): if right.start < left.end: @@ -453,6 +469,7 @@ class Toolchain: defsyms: Sequence[str] gp_symbols: frozenset[str] = frozenset() maspsx: Path | None = None + maspsx_flags: tuple[str, ...] = () aspsx_version: str = DEFAULT_ASPSX_VERSION nm: Path | None = None @@ -512,7 +529,8 @@ def compile_c(source: Path, out_object: Path, work: Path, tools: Toolchain) -> N transformed = work / (out_object.stem + ".maspsx.s") run_filter( [sys.executable, str(tools.maspsx), - f"--aspsx-version={tools.aspsx_version}"], + f"--aspsx-version={tools.aspsx_version}", + *tools.maspsx_flags], assembly, transformed, ) assembly = transformed @@ -696,6 +714,7 @@ def _build(args: argparse.Namespace) -> tuple[Path, Path]: as_flags=[*tools.as_flags, *region.as_flags], gp_symbols=tools.gp_symbols - frozenset(region.no_gp), maspsx=None if region.no_maspsx else tools.maspsx, + maspsx_flags=region.maspsx_flags, ) compile_c(item.source, object_path, work, region_tools) localize_symbols(object_path, tools) @@ -778,6 +797,12 @@ def add_toolchain_arguments(parser: argparse.ArgumentParser) -> None: help="ASPSX emulator run between cc1 and the assembler") parser.add_argument("--no-maspsx", action="store_true", help="assemble cc1 output directly, without maspsx") + parser.add_argument("--no-jump-slot-nop", action="store_true", + help="maspsx mode: suppress the unconditional reorder nop after a " + "branch/jump so GNU as can fill the slot (region: maspsx=noreordernop)") + parser.add_argument("--nop-on-reg-read", action="store_true", + help="maspsx mode: also treat a following jr/jalr that uses the loaded " + "register as needing the load-delay nop (region: maspsx=regread)") parser.add_argument("--aspsx-version", default=DEFAULT_ASPSX_VERSION, help="ASPSX version for maspsx (default: the SDK's 2.81)") parser.add_argument("--cpp-flag", action="append", default=[], @@ -879,6 +904,10 @@ def resolve_toolchain(args: argparse.Namespace) -> Toolchain: defsyms=defsyms, gp_symbols=frozenset(gp_names - set(getattr(args, "no_gp", ()))), maspsx=maspsx, + maspsx_flags=tuple( + flag for flag, enabled in ( + ("--no-jump-slot-nop", getattr(args, "no_jump_slot_nop", False)), + ("--nop-on-reg-read", getattr(args, "nop_on_reg_read", False))) if enabled), aspsx_version=args.aspsx_version, ) diff --git a/tools/tests/test_sf3_match.py b/tools/tests/test_sf3_match.py index 0a9e489..b6e45ae 100644 --- a/tools/tests/test_sf3_match.py +++ b/tools/tests/test_sf3_match.py @@ -203,20 +203,42 @@ class RegionOverrideTests(unittest.TestCase): """The per-region override field: cc1/as flags, gp exclusions, maspsx stage.""" def test_cc1_and_as_flags(self) -> None: - cc1, as_flags, no_gp, no_maspsx = sf3_match.parse_region_options("cc1=-O0 as=-G8", 1) + cc1, as_flags, no_gp, no_maspsx, maspsx_flags = sf3_match.parse_region_options( + "cc1=-O0 as=-G8", 1) self.assertEqual(cc1, ("-O0",)) self.assertEqual(as_flags, ("-G8",)) self.assertEqual(no_gp, ()) self.assertFalse(no_maspsx) + self.assertEqual(maspsx_flags, ()) def test_gp_exclusion_names(self) -> None: - _cc1, _as_flags, no_gp, _no_maspsx = sf3_match.parse_region_options( + _cc1, _as_flags, no_gp, _no_maspsx, _flags = sf3_match.parse_region_options( "gp=-D_80121F84,-D_80121F40", 1) self.assertEqual(no_gp, ("D_80121F84", "D_80121F40")) def test_maspsx_off(self) -> None: - _cc1, _as_flags, _no_gp, no_maspsx = sf3_match.parse_region_options("maspsx=off", 1) + _cc1, _as_flags, _no_gp, no_maspsx, maspsx_flags = sf3_match.parse_region_options( + "maspsx=off", 1) self.assertTrue(no_maspsx) + self.assertEqual(maspsx_flags, ()) + + def test_maspsx_phase10_modes(self) -> None: + """The Phase 10 opt-in maspsx modes map to their CLI flags, and the + legacy `on`/`off` spelling is gone.""" + _c, _a, _g, no_maspsx, flags = sf3_match.parse_region_options( + "maspsx=noreordernop,regread", 1) + self.assertFalse(no_maspsx) + self.assertEqual(flags, ("--no-jump-slot-nop", "--nop-on-reg-read")) + + def test_maspsx_modes_compose_with_off(self) -> None: + _c, _a, _g, no_maspsx, flags = sf3_match.parse_region_options( + "maspsx=off,noreordernop", 1) + self.assertTrue(no_maspsx) + self.assertEqual(flags, ("--no-jump-slot-nop",)) + + def test_default_region_has_no_maspsx_flags(self) -> None: + regions = sf3_match.parse_regions("0x80010000 0x80010010 src/a.c\n") + self.assertEqual(regions[0].maspsx_flags, ()) def test_rejects_a_gp_token_without_a_minus(self) -> None: with self.assertRaises(sf3_match.ToolError):