mirror of
https://github.com/Druthulu/BFM-decomp
synced 2026-09-27 05:56:00 -04:00
de02dc750c
Three static oracles failed to derive the parked payloads' load addresses this session. The runtime answer needed NO breakpoints, no Lua (no pcsx.lua wedge hazard) and no GDB stub: the loader mirrors its whole request in RAM (cdReq_curSector / cdReq_dest), and CdReadRequest's own MATCHED signature says cdlFile points INTO cdFileLocTable -- so (ptr-0x800AE830)/8 is the global file index and cdReq_dest is the destination. Both readable from the RAM-dump API we already had working. VALIDATED FIRST (R35): cdFileLocTable's live sizes reproduce our extractor's file sizes exactly for all five parked payloads. Then confirmed 7x against independently byte-proved addresses -- loadDestPtrTable slots [0]/[1]/[3], MAIN/10 (Phase-3 resident), MAIN/3 (S45-p2 md_MAIN_003), MAIN/12 (the resident's func_800CF94C row), and the LIST.CD bootstrap read from matched C. This is the R34 second oracle for the whole S44 routing table, which was static-only until now. FINDING: the script-module slot 0x801EF468 is live and GENERAL. SC03/76 AND SC03/34 both load there; 34 is outside the SC03/73-79 block, so S45's "chapter-2 period" label described one tenant, not the slot -- scripts swap PER SCENE. PRE-REGISTERED HYPOTHESIS (written before the test, kept honest): slot CONFIRMED (it lies inside SC03/54's independently-derived base window); "chapter-gated" WEAKENED (per-scene, not per-chapter); trio 0 sightings across 38 load events, 2 saves, multiple SC03 scenes. NEXT (static, no emulator): 0x801EF468 is now a concrete anchor. Register-track the code that loads into it and decode its scene->script-index SELECTOR -- answers all three at once instead of sweeping rooms. The correctly-scoped successor to the four refuted value-scans. Also lands the attract-cycle load map (.run/attract_loadmap.jsonl): MAIN/7 + MAIN/9 absent across a complete 304s cycle.