mirror of
https://github.com/Druthulu/BFM-decomp
synced 2026-09-27 22:45:39 -04:00
0bd334c30d
- MAIN/7 (id 0x3A) and MAIN/9 (id 0x2D) carry 'C:\TIMPACK\OPDEMO0.PAT' /
'OPDEMO1.PAT' path strings -> they are the OPENING/ATTRACT-DEMO modules. S45 p2
checked 'OPENING' negative, so the live target is attract-mode (idle at title),
a different state. Turns a blind search into a targeted capture.
- THREE payload-side base oracles built and ALL refuted by their own controls
(R32/R35 assertions did their job; none of their answers were used):
derive_base 0/4 -- 'code follows the table' is false (MAIN/34: 0x208 gap)
vote_base 4/12 -- calls are outward + MIPS leaf fns have no prologue
vote_base2 0/4 -- self-jals 0/N: there are NO internal jal calls at all
The third is structural: a module's bytes do NOT encode its base, because its
functions are reached indirectly via the header pointer table (jalr), not jal.
- The one real constraint: SC03/54's 19 header pointers (0x801EF718..0x801EFEE8)
confine its base to [0x801EDED0..0x801EF6C8]. That window lies INSIDE SC02/9's
span (0x801E4C60+70784=0x801F60E0) -> SC02/9 + the SC03 trio are mutually
exclusive event modules sharing a ~0x801Exxxx region at DIFFERENT bases.
- => event-module destinations are per-scene/runtime-allocated, not a static slot.
This explains the empty resourceIdMap branch and why the emulator resolved SC02/9.
The CD-read tracer stays the correct instrument (R11 + Drew).