How to use these three pages

Reverse engineering a sealed game produces three kinds of knowledge: questions still being worked, questions answered, and readings that turned out to be wrong. Each has its own page, and the cheapest thing you can do before starting a hunt is check all three - if the question is not on this page, it is probably already answered or already disproved.

PageHoldsRead it when
This pageLive hunts: open, partial, mostly resolvedYou are picking up work, or want to know whether a question is still contested.
Settled threadsAnswered questions, each carrying an evidence gradeYou need the answer to something, or you are about to build on a claim and want to know how firmly it is pinned.
Do not re-walkFalsified hypotheses, reasoning intactA reading of the bytes looks obvious and you want to check nobody has already spent a week disproving it.
open partial mostly resolved settled threadsgraded by evidence do not re-walkreasoning kept reading disproved
A thread narrows left to right and leaves this page for one of two terminal registers.

A falsified row is kept forever with its reasoning, because the reasoning is the deliverable - "the world-map slot-4 bodies are coastline wireframes" is a very plausible reading of those bytes, and knowing why it is wrong is worth more than the row it occupies.

Nothing on any of the three pages counts ports, tests or coverage. Detailed captures and decompiler dumps live in the linked pages and under ghidra/scripts/funcs/.

Where the live hunts are

The live list is kept area by area below, one table per area, and each table holds every open question in that area. Nothing is summarised twice on this page: a digest table that restates the areas is a second place for a closed thread to keep looking open, which is exactly how this page once advertised a hunt that was already over.

Jump to an area: field / locomotion · battle / rendering · audio / BGM · title / boot / overlays · containers / data blobs · measurement + tooling.

One of the six carries no live hunt at all right now. That is a real state, not a gap - an area stays on the page with the note on what closed there last, because "this area has no open question" is itself worth knowing before you start one.

What an evidence grade means

When a thread closes it moves to settled threads carrying a grade: a label for what kind of evidence its answer actually rests on. Grades are explained here because they are the first thing to check when a settled fact is load-bearing for live work, and because a thread on this page is only closable by evidence of the strongest two kinds.

Where a row cites more than one kind, it is graded by the weakest load-bearing claim - the one that breaks the conclusion if it is wrong.

GradeThe row cites
disassemblyInstructions, addresses, opcode encodings, branch or store sequences. The strongest grade.
captureA runtime capture, save state, probe, firehose, or disc-derived oracle.
decompiled-CGhidra's C output, a FUN_x(...) call signature, a Ghidra label or plate comment, or a claim about store order / store count / a boolean operator with no instruction behind it.
inferenceReasoning from surrounding facts, corpus absence, or analogy, with no direct evidence cited.

decompiled-C is the re-audit bucket, not a wrong-answer bucket. It marks a claim nobody has confirmed against instructions. Most are probably right; the point is that none has been checked. The C is a rendering: dropped register arguments, || printed as nested ifs, reordered or omitted stores, and hand-written Ghidra annotations read as fact have each already put a wrong statement on these pages. The catalogue of rendering artifacts on the Ghidra tooling page is also the grading rubric. When a decompiled-C row is load-bearing for something you are about to build, re-derive it from the disassembly first.

Status conventions, and how a thread is laid out

StatusMeaning
openActive hunt. A concrete next step exists; the row names it.
partialThe main result is pinned; a residual sub-question remains.
mostly resolvedThe mechanism is pinned; one leg is unconfirmed.

Many rows qualify the status in parentheses - partial (transcode closed), open (narrowed) - naming how far it got. Read the parenthetical.

Each area below opens with a table of one-line rows. A thread whose write-up outgrows a table cell keeps its one-liner in the table and links to a subsection after it; the full analysis - every address, capture and falsification - lives in that subsection under its own Status line, with the long evidence folded into a disclosure so the page scans.

Corrected claims

Claims that stood on these pages and were overturned. They stay listed - a claim that was wrong once is the cheapest place to look for a claim that is still wrong - and each stands corrected on settled threads or do not re-walk.

History: the overturned claims
  • A scene-local music id never loads the scene's own block. The loader computes that index only to test for a change, then loads a fixed fallback track from the shared bank; retail never stages a scene bank.
  • The shop's last three rows are Platinum Card stock. The probe looks for item 0xFF, the card - not an empty slot - and without it those rows are dropped; a capture shows 13 rows with the card and 10 without.
  • Rula and Riremito are the Door of Wind and Door of Light. The handler table is indexed by value, so the missing address references proved nothing; the arts scan the CDNAME define table, and the routine read as a fade is the pause-menu session.
  • The routine read as a glyph or draw helper is the NPC visibility cull, and the "motion-pause kick" holds nothing. Both dumps filed under the cull's address held other code.
  • The battle "target-highlight dim" is a near-camera ghost pass, and party animation entry 8 is the downed kneel, not a recover clip with a backstep.
  • The USA dialog font already carries accented letters - 32 high cells, most with zero width.
  • No Muscle Dome hub texture subtracts. The GPU blends only texels with the STP bit, so the "subtractive" packets draw opaque.
  • A battle drops at most one item. Retail rolls every enemy's drop chance but keeps only the last winner's item, then throws the drop away three times in four unless an enemy's chance is 100% or a party member has Items Up. The docs and the port had granted a drop per defeated enemy.
  • Two battle routines named for Miracle Arts and the capture cinematic belong to the Seru absorb. One checks whether the killer already knows the Seru, the other holds the Seru the killing blow absorbed - and the absorb itself had never run in the engine.
  • Incense stops random encounters outright for a window of walking steps; the word it fills had been read as a brightness ramp and as a frame cooldown.
  • A scene-stream chunk read as a texture upload is the music score's install, carried by every scene stream that has a score, and the installer decodes no compressed data at all.
  • Baka Fighter's "sprite" passes drive 3D models. The two "sprite archives" are the scene's animation-clip banks, the "mirrored sprite pass" is the special attack's afterimage, and the round-start cameo is the ring girl, not a party member.
  • The prologue jungle's black plants were a native-only mistake - a staging step gave the dim prologue ambient to every vertex of one colour, authored billboards included - not the sepia grade and not retail's own colour rewrite.
  • The field drop shadow is four textured quads over a projected grid, not a lighting helper and a gouraud grid; the port had filed the pair as handled by its rasteriser while neither host drew a shadow.
  • A field-script opcode read as "talk to this NPC" starts a fight. Op 0x3E with a first operand below 100 installs a scripted battle from the scene's formation table, exactly as the 0xFF form does; the engine had opened dialogue at all ten such sites on the disc, and eleven doc sentences described it as the talk trigger. Talking is a button press, not an opcode.
  • Three fog readings fell together. The fog sheets sample VRAM (448, 0), not (448, 256); the larger fog cap is every overworld's, set from a scene-header bit, not a debug value; and the port's excess fog came from feeding the spawner raw random-number state where retail's BIOS rand returns the high half, not from the stale live count.
  • kor5's tail flag needed no poke. The record that sets it does so a few thousand frames into the chain; the 17,500-frame estimate was the probe re-triggering an earlier beat over the running chain.
  • The title menu has two rows. No title route reaches Options, and the "boot Options screen draws twice" drift reading was wrong on both counts.
  • A battle routine's "captured-monster payout" is the refund of an item a fallen fighter had committed, read at an address that belongs to no routine - a mis-based print of the turn-order picker.
  • A routine named for zeroing the GTE light block zeroes the translation vector instead. The three control-register writes in the routine the docs cited are the far-colour trio, written from registers rather than zeroed; the routine that zeroes anything targets the translation vector. The battle-intro swirl rolls about two axes with it, not one. Both readings had been graded from Ghidra's C output, where a control-register write prints as a helper call with the register number buried in an argument.
  • The cast-voice bank was named from the wrong end. Each slot-B module hardcodes its own literal cue id near its head - 62 of the 64 images, the other two forming it at run time - so the bank is a property of the module, not of the caster, and it is seventeen streamed-audio files rather than the three the drift page listed. With it: the cue table its reader indexes is four times longer than the port's constant, and the reader bounds nothing above the threshold, so every cast cue fell off the end of a table that looked complete.
  • The port's shop screen was read back as retail's. Retail's quantity control is a pair of pad steppers (+1 / -1 / +10 / -10, clamped) whose bound is the smallest of what the purse affords, 99, and 99 minus what is held. The "nine-row list whose cursor is the quantity" describes the port's own screen, and while that stood the port capped every purchase at 9.
  • A 72-slot item bag was a cheat page's display bound. The bag is one 256-slot array reached only through an active window that a single setup routine writes; a real three-member memory card holds items up to index 159, so 88 of them were dropped on every lift. Enemy Steal has a third acceptance test nothing modelled - the item's shop price being non-zero - and its consume helper scans only the active window and returns a sentinel, so a steal outside the window banners a success and removes nothing.
  • An actor's heading is the middle of a triple. The field actor updater hands the whole +0x24 vector to the rotation setter, so pitch and roll ride beside the yaw a reader taking the halfword alone sees - which is why per-actor tilt was missing on both hosts and looked like a renderer gap.
  • The field-VM word the port called an input lock is the ambient-particle master gate. One opcode's sub-0 raises it and sub-1 clears it, both stores in a jump delay slot, and the word has six references disc-wide of which none is pad state. A field script decides per scene whether ambience emits at all.
  • The staged background loader is two dispatchers, not one walk. One word picks between a 19-arm field-restore table and a 12-arm panel-still table, and both run from phase 2 because the SCUS sequencer owns states 0 and 1. That is why a teardown census recorded four field-restore uploads and zero panel stills - the branch working, not a missing consumer.
  • The cast-arm countdown drain is per arm. It is a per-arm multiplier of a scratchpad frame byte - the product, twice it, or once it - so the single product shape held for one family only, and two arms measured as constants 4 and 8 were 1x and 2x a byte that read 4.
  • Two in-world minigames started the wrong track, because the extraction map from a loader index to a global BGM id is piecewise and a flat base had been assumed. Nearby: only one of the three overlays a doc listed as dance variants is the dance overlay.
  • The dance count-in banner is a sprite record, not text, seated from the dance overlay's own table with per-arm blend, and its animator samples once per three vsyncs. And the field follow camera's three "constants" were one save state's values - over the walkable state population they hold in 12, 8 and 1 of 19; retail derives all three per scene and per player tile.
  • The failing rebuilt character-pack container is not constructible. The decode is length-driven by the descriptor and the loader sizes its buffers from the container header, so a header-byte-exact rebuild with a different decoded size simply gets a truncated pack - and no shipped patcher path changes that size. The test turns out to need no patched disc at all: retail's own pack pointer is garbage in every catalogued battle state, and the registrar that reads it is unclamped.
  • Every scene-bundle descriptor offset is inside its entry - all 668 over 102 tables. The "offsets fall outside the file" reading was the over-reading entry-size expression, not the bundles. The type-0x14 descriptor of every count-4/5 bundle is the placeholder fill file, and the dispatcher answers it without reading the payload, so a descriptor resolving to filler is the format working.
  • Six readings of the cast band fell at once, and one measurement blind spot explains most of them. A phase-store census keyed on the literal 0x279 displacement misses every module that stores through a formed pointer - one module reads as zero stores and has six. A "no damage wrapper, no HP write" verdict taken inside one tick's own frame missed the applier one call deeper. The band has three clamp shapes, not two, and one module picks its cap per hit from its own slash counter. Only two of the eleven player-Seru bodies heal, and the published (power << 5) + 0xE0 formula belongs to neither - each has its own closed form over the caster's magic level. Actor +0x1DC is a bitfield at the reaction sites, not a counter. And a body's head table is not the body: one image's MP writer was named by the VA of the table that points at it.
  • Monster record +0x20 is a texture-page width flag, not a per-monster instant-death immunity byte. Three summon ticks read it before an instant-death roll and force the resist when it is set, and the 37 records carrying it are bosses plus one insect family - exactly what an immunity list looks like. Its primary reader is the model upload, which widens the VRAM rect. A field's meaning is its primary reader's, not its most interesting reader's.
  • Actor +0x8A bit 0 suppresses the scripted motion VM; it does not enable it. A zero byte runs the bytecode, and the bit gates the player-engaged / actor-busy / off-map early returns. Two op readings fell with it: op 0x06 is a home-relative one-tile wander rather than a pad echo, and op 0x0C fades a packed RGB tint and a draw mode rather than gliding a position - the speed halfword is one field away.
  • The field entry seat belonged to the ambient emitter. The quoted spawn coordinates are the one plain template's; the player is seated on both arms of the field MAIN INIT from the door operand. "Cold entry happens only at New Game" is false too - the same function's epilogue clears the gating word, so every ordinary scene change takes the cold arm.
  • The battle context byte the port called "counter-attack" is the scripted-fight flag, derived at battle init from a bit of the per-battle flags; the counter-attack byte is the next one along. All three action-SM reads gate on it, so two audio-duck arms and the attack-return arm were unreachable while the port seeded zero. In the same area: the dome arena's pre-test seed of the special-battle word is 1, not 0 - course 0 with no bans, which is a different thing from no seed.
  • The dome tally screen's rows were wrong on both hosts. Retail puts the HP accumulator between lanes 2 and 3 and uses four brightness steps, not six. The lane base is re-formed into a different register between the product and the store, which is what mis-attributed the lanes.
  • The koin4 coplanar sliver was manufactured by the port's own lift. The offending strip is exactly one nudge wide, because the lift applied to that family lies inside the second plane; zeroing the offset takes the measured overlap to zero. A repair pass is part of the instrument measuring the defect, so its own artifacts read as findings.
  • Nothing on the disc can materialise the rebuilt-container wild read's address. No overlay image holds the upper half it would need, and the delta from the container base is an order of magnitude off what the earlier arithmetic assumed - so the pointer is computed at run time, with two pack walks as candidates, and the byte-exactness rule the modding path follows stays conservative rather than explained.
  • Two measurement headlines were the instruments' own. A feature view's Port % counted ignored rows in the numerator and the denominator, so five views read far below their real figure and the headline moved whenever an ignore row was added; and every dump of one 588-byte function stops at 276, because the decompiler stops at an interior jump table the preceding branch skips past. Seven dumps agreeing is agreement about the decompiler.
  • An open-ended CDNAME block's range is not a length. The last block runs to the end of the map, so an unclamped block range reserved 64 GiB on a scene load - and Linux overcommit granted it silently until a test run met the memory watchdog. Reproduce this class under a ulimit -v cap: an overcommitted reservation only aborts under one.
  • "No dome round bans magic" was wrong, and this page published it. The claim rested on the magic bit's known writers keying on the first enemy monster id, which the dome ladder never reaches - true, and beside the point: the arena seeds the whole restriction word itself, on three story flags, last match winning. Every seed bars the Item chip and the top seed bars magic, so retail really does cross out the Ra-Seru chip on the highest course. Enumerating one bit's writers is not enumerating the word's.
  • A correction on this very list was itself wrong. "A slot-B module's regions interleave - records sit between bodies" was published here after the bodies above two images' record bands were read as those images' own code. They are the donor's: one image is byte-identical to its neighbour from a file offset partway up, so its own content ends there and everything above belongs to the other. A dump that prints at an address under two images' names is not evidence of which one owns it.
  • Sixteen of twenty "un-dumped code runs" were never code - the count was published as seventeen, and the twentieth run really is code: an eight-arm leaf table whose seven 20-byte leaves and one 12-byte leaf have no frame for frame matching to see. The other sixteen are an image's own data tail or a neighbouring image's bytes at the same file offset - a build-buffer leftover every extracted overlay ends in, and the rule that recognises it carried two wrong restrictions of its own: the buffer is indexed by file offset, so the donor need not share a load base, and the length field is a sector extent, so it need not be longer. 79 of 83 images and 88,150 bytes, not 66 and 61,597.
  • A slot-B module's data tail is a spawn-record band. The uncovered span is [i16 model_sel][u16 reserved][move-VM bytecode] records addressed by the consumer's own lui/addiu; 62 of 64 images carry one. The +0x02 halfword is zero in every one of the band's records with no reader, so it is reserved rather than flags.
  • FUN_801DA390 eases a camera height, not a yaw. 0x801DA3B4 reads ctrl[+0x4A], 0x801DA3B8 reads the actor's +0x16 - the Y of the position triple, not an angle. The same halfword had three incompatible readings across the docs, and nothing on the disc masks it as an angle.
  • Retail's title screen does not run under mode 0x10. The front end is six mode stores and the title's own mode is the card mode 0x17; 0x10 is one frame of logo INIT. Each hand-off is the handler's own store, not a field of the mode table.
  • A dome round is an ordinary battle; the dome hub is the OTHER mode. A cast also costs MP, not AP, so every "the pennant pays for a cast" argument was about the wrong currency. (The magic-ban half of this bullet was itself overturned - see the top of the list.)
  • FUN_80058490 is MoveImage, not a sound-driver lane. It moves a VRAM rect to (0xE0, 0x1DC) - CLUT row y = 476 - so the table behind it holds VRAM x coordinates, and anything reading those bytes as sound-effect ids is reading a palette column.
  • FUN_8003E8A8 returns a sector count. 0x8003E90C is subu s0,v0,s2 over the two TOC words and 0x8003E948 returns it; the LBA is a side effect. Two loader rows and one argument order were reversed against it, and the libcd directory cache is at 0x801CB408. How 0x801C4BEC arose is not settled: the "offset half of an instruction pair" story does not survive, because that halfword occurs at no word in the executable.
  • A live port wore another routine's address. engine-core::dialog carried PORT: FUN_8001FD44 and implements nothing of it. Nothing gates this class: a // PORT: tag naming the wrong routine passes every check that exists.
  • Twelve feature views were measuring one blob. A breadth-first walk from a feature root spills through the title tick into the save UI, the effect spawner and the move VM, so one view's anchor set was a strict subset of another's. Localized, the same feature measures 72 anchors instead of 781.
  • FUN_801DD35C is the title tick, not a menu dispatcher, and _DAT_8007BAB4 is its pre-attract hold rather than an "active submenu index" - read at 0x801DDA9C, tested bgtz at 0x801DDAB4, drained by frame_scalar << 3. Three more title readings fell with it: the sub-mode word is 0x801F0204 and 0x801DD920 is only the instruction that writes it; a cold boot never shows sub-mode 0x02; and the slider state[-0xEB4] has no [0, 0x2C] range - both arms converge on 0x2C, and the graph seeds it 0x100 and -0x16.
  • The summon draw does not run 35-64 times a frame. Re-measured on the same catalogued state, FUN_80048A08 is called once per live actor per rendered frame - at most 2 in the solo fight the original figure came from.
  • The world-map overlay's per-prim handler table is based at 0x801F8968, not at its first non-zero word. FUN_80043390 materialises the base with lui s4,0x8020 / addiu s4,s4,-0x7698 and indexes it with the same (flags >> 1) * 4 it uses on the SCUS table 0x8007657C - which has the identical shape, words 0..7 zero. Re-basing by the zero prefix shifts every prim kind by eight.
  • Two dumps were reading the wrong image. 0x801D2784 is PROT 0976 (Baka Fighter), not 0979 - the two are byte-identical from file 0x3C68, so only the operands separate them. And every overlay_dance_* print above 0x801D6818 is PROT 0972's fishing overlay: 0x801D73B8 is that image's file 0x8BA0, byte for byte.
  • Not every alias is a phantom. 0x801DDA90 is a real entry in both slot-A images - the field overlay's screen-frame corner writer and the title tick's AttractDelay arm - and the "two slices of one loop, neither an entry" reading was right about 0x801DDB44 only.
  • Four field-overlay routines were named for the wrong effect. FUN_801DD784 is the scene shutter blackout, not a letterbox; 0x801F27EC oscillates one rung of the floor-height ladder at 0x1F80035C, not a fade; FUN_801CFF3C is FUN_801DE754 printed 0xE818 low; and 0x801D44CC flips the dance step-marker's mesh rather than facing a dancer.
  • A jal sweep scoped to one image answered the wrong question. PROT 0898 really does not call FUN_8002C69C; SCUS FUN_80031D00 drives it off the retained widget list every frame a battle is up, so the post-battle report chrome is the ordinary nine-slice.
  • FUN_80019D50 uploads a palette, it does not emit primitives - one LoadImage at 0x8001A030 per call, the CLUT-cell HSV cycler. And FUN_801D362C has exactly one reference on the disc, the move VM's own op-0x2F arm, so the world-map controller does not call it directly.
  • Two measurement reflexes were wrong. A disc-coverage --check floor regression is attribution lag - a new unattributed dump raises the denominator first - not lost coverage; and a // PORT: tag's live/inert bucket is a property of the tagged item, not of a neighbouring symbol that happens to be called.
  • The title screen was never "ahead of the mode table". It runs under the CARD mode pair 22/23; main()'s one pre-loop overlay load is the boot init.pak 0895, and FUN_801DD35C is inside PROT 0899 at +0xEB44. Four more inference-graded rows were re-derived from instructions in the same pass; _DAT_8007BD84 is an effect handle, not a mode word, and the item table carries 250 names, not "far below 128".
  • The five "sealed" chapter-1 scenes were never sealed. uru, urudre1..3 and jouine carry walk-on exits in their .PCH sidecar; the ladder's own caps produced the verdict. Live-confirmed for uru.
  • The battle-intro enemy-name banner is raised by no placement record; the composer FUN_801D9D3C spawns its labels with immediate geometry. bse.dat loads at battle init, not boot, and its columns are pinned.
  • Debug flag _DAT_8007B8C2 had its branch sense backwards, and one arm was named for the wrong loader. Every site reads the flag with lh and takes the zero arm to the debug-station host trap, the non-zero arm to the index resolver. Settled on that polarity, writer and all.
  • The VA-aliasing corollary was too narrow. It read as an 0x801Fxxxx problem; 801e23ec is a settled casualty in the 0x801E band, and its aliased reading had silently dropped all three initiative modifier terms.
  • The op-0x2F "seven byte-identical dumps" shorthand was compressing. The capture-derived dumps agree with each other; the static 0897 dump is a strict subset of them, not a twin.
  • FUN_8001EBEC's second pose-copy arm loads seven words, so its range ends at +0x15C, not +0x158.
  • A committed claim can quote a dump statistic the dump no longer reports. Re-extraction makes dumps longer, and a caveat written against the old one keeps suppressing work - 0x8005BA38 was recorded "not a function, do not open a port row" and is a complete RotTransPers. Checker: scripts/ghidra-analysis/check-dump-stat-drift.py; the class is on do not re-walk § measurement readings.
  • A battle 0xB5 was read in the wrong id space. Spell 0xB5 is Lapis Wave; formation 0xB5 is Cort. The branch at 0x801E6D04 reads the formation-id byte, and the wrong reading survived because Cort casts Lapis Wave - the two spaces agreeing on the answer is what hid the error.
  • Op-0x35 sub-op 9 was recorded as "Queue". It is a start behind an asset-load barrier - the arm at 0x801E0224 waits on _DAT_8007BAB8 == _DAT_8007BA9C and then makes sub-op 1's own _DAT_8007BAC8 store. It is what a cutscene changes music with, so a scene-corpus BGM sweep (which only runs prescripts, and those emit sub-op 1) could not see the difference. Falsification: do not re-walk.
  • FUN_801D27E0 was handed off as "the talk controller that restores party count/leader and drops lock 0xD". The disassembly says otherwise. The function is the three-actor talk's leader-cycle state machine (six states off +0x54): state 0 polls system flag 0xD and the per-participant flags base+0..2, and a switch trigger fades out, hands control to the next un-talked participant (rewriting 0x80084597/98 + flags 0x10..0x12, parking the old leader's record at 0x3F80), and fades back in. It never writes the party count 0x80084594 and never clears flag 0xD - when the script clears the flag, state 5 merely despawns the controller (s4+0x10 &= ~8). Retail's post-talk party membership comes from the scene script's own party ops (the field VM's 0x454-offset writers). The engine's restore (World::end_three_actor_talk) therefore keys on the flag-drop trigger and restores an arm-time snapshot, disclosed as such.
  • The quick-travel placement scene_id "unresolvable id space" is resolved. The u16 at record +2 of DAT_80073A98 is the destination scene's raw CDNAME TOC index - disc values 0x55/0xF4/0x187 are the map01/02/03 kingdom bases and 0x162/0x215 are son/korout - and the staged copy at 0x80084628 is the same word the world-map arrival kernel FUN_801EE328 matches (record +0xC of the visited-map table) before seating the party at (tile << 7) + 0x40. Resolver: World::tables.scene_toc_names; drain World::drain_staged_menu_warp.
  • "Retail shots rarely roll the camera" was false, and so was the row that replaced it. Retail authors a non-zero op-0x45 slot-2 roll in eight scenes. The renderer's dropped RotMatrixZ factor was a real divergence, and the two linear censuses that had measured it - one strict, one byte-resuming, plus a raw byte scan quoting a "2 %" figure as fact - were each measuring their own decode gate. Settled by execution on settled threads.
  • The field view matrix is built per field frame, not three times a vsync, and two of its five call sites are not a camera at all. Over a world-map-to-town entry only 749 of 1800 captured vsyncs carried any build, split 389 / 313 between the full order and a short one. The two sites a sweep of the executable and the first-slot overlays cannot see are one bracket in the world-map render module, which zeroes the camera yaw to draw a screen-fixed band and then puts it back.
  • The last build before the draw does not win - it frames no geometry at all. A link count already put 16810 of 31046 under the first build and fourteen under the last; splitting by graphics command code gives the real figure, because that count was mixing attribute packets and flat rectangles in with polygons. Of 4289 polygons over three runs, 3861 are under the first build, 428 under the second and none under the last.
  • The slot-B stage selector does have a writer. The field entity tick clears the byte and raises it off a system story flag, and battle latches its other value directly. Every access is of the register-relative form the project's address sweep is blind to, which is the same blind spot that hid a camera-focus destination earlier.
  • The cast-cue band's door is an item, not a spell. Its one caller is the Spirit / Item wait state, entered from a pre-arm state that the item command sets unconditionally and the magic command sets only for ids below a threshold the player's own Seru block sits above - so fifteen injected casts finding it cold was a bound, not a sampling accident.
  • An archive entry labelled monster_test is the world-map top-view debug image. Names inherit forward from the block that opens above it, so the label says which block a slot is in and nothing about its content; the image's own operands are the world-map location table, the kingdom filter and the camera pair. The "324-byte routine" the corpus printed inside it is one arm of its own dispatcher.
  • The developer menu's BGM row plays a track; it does not cycle the index. Cycling is the input half, a different routine. The row's action installs a sound-test entry's global track id, which makes it the fourth writer of the music-request word on the whole disc - and the reason it had been filed as a world-map region change.
  • The equip compare panel's no-passive sentinel is not a free substitution. Every equipment row carries it, so it reproduces that arm exactly and nothing else; 80 of the 151 non-equipment ids carry a real passive index on the other arm, and a host feeding the sentinel unconditionally loses two of the three row sets. The screen that opens the panel was wrong too - it is the equip candidate step, not the shop's recipient flow, and no screen opens both compare windows.
  • A captured sound voice is audible by its envelope level, not its phase word. The phase has no idle member - a key-off parks a voice in release - so a phase test counts every voice a state has ever keyed, which is why retail snapshots read 20 to 24 of 24 voices live and why an oracle rule looked unsatisfiable. Against the level, retail holds 4 to 9 audible voices and the engine 4 to 8, and 1624 of 2352 slots across the retail corpus are at level zero. The engine really was missing three cold scene-entry steps underneath; that was a second, independent defect.
  • The browser play page's frame path does short-circuit - in the page's own JavaScript rather than in the Rust runtime, so a guarded frame runs none of the per-frame work and still paints. A check that reads only the Rust cannot see it.
  • Two minigame citations were off by bytes rather than by reading. The Baka Fighter editor's actor record and its sibling start four bytes lower than cited - the cited words are each record's filler field, not its head - and the fishing bite tick's two per-frame map reads are unrelated (one is the water gate, the other drifts the lure sideways over an obstructed cell), and the halfword read as the lure's z is its height.
  • The Muscle Dome's "match state machine" is the round state machine every battle runs. It has exactly one call site disc-wide, unconditional, inside the SCUS battle frame driver, and three non-dome battle states enter it hundreds of times over 700 frames each. Reading it as a dome controller was reading one caller's context for the routine.
  • The audio oracle's "reverb" channel was the SPU control register. The emulator's register blob is the hardware window verbatim, so the offset being compared was the control register, and the value that read as "retail routes four voices" is enable | unmute | reverb-master | CD. The real per-voice enable mask reads all 24 voices on every captured frame - and the engine's own zero came from an oracle building a bare SPU where the shipped audio host builds one with retail's reverb installed.
  • "The engine runs half retail's voices" compared two pieces of music. An engine trace plays the track the scene's own entry script selects; the retail capture it was paired against still held the overworld track, because that save walked into town from the world map. On one track over a comparable stretch the two sides land in the same place, and the sequencer drops no notes at all.
  • An overlay with "no load base that fits" had one all along. The measurement was a resolution ratio over the image's address-forming pairs, which is one-sided: a base that catches few pairs scores perfectly on all of them, and on this image it ranked a refuted base first. The call-graph recovery lands, every internal jump resolves inside the file at that base, and the image turns out to be linked against an executable this disc does not carry.
  • The dome panel still has a draw site; it never materialises the number that was searched for. A textured primitive addresses video memory through a packed page index, so the emitter's constants are page numbers rather than the pixel column. It is in the contest hub - a mode later than the upload, in an image that is not resident when the load runs.
  • A frame kernel paired by name can be an empty body. The host-drift gate paired a native step with a browser one and asserted both advanced the scene's posed actors; the native body was {}, and an empty body pairs with anything. The window does that work inline, which is a different claim.
  • The port's camera visible-tile window was seeded once at construction, not at scene entry. A scene that scripted a wide window handed it to the next scene's clamp. Retail's window is per region: a town walk alternates between two windows as the player crosses regions, and neither is the port's default.
  • A wall-slide oracle was not asserting the defect it was blamed for. Both pinned wall-press legs are slide-neutral - the resolver hands back the held direction at each - so the test measured points where the two models agree, while retail's slide fires in ordinary free-roam.
  • A reserved value on the music request word is a park sentinel, not a track. The resolver compares against it, copies the pending index onto the loaded-index barrier and skips the load; the second streaming slot carries the same test. The states that read it are the ending ones.
  • A spawn opcode's two operands are envelope rates, not a kind/variant pair. The opcode spawns from the morph-weight descriptor, whose handler reads the two fields as the rise and fall steps of the morph weight. The port's field names were the generic allocator's, not this spawner's.

Two rows a prior audit flagged as the highest-risk decompiled-C claims on the register - the narration-roller op's operand decode and the item-add OOB store-order claim - have both now been re-derived from the disassembly and confirmed (grade disassembly). Both live on the settled register with the instruction evidence cited.

Field / locomotion

The field is the game you spend most of your time in - walking towns and dungeons, triggering scripted events, crossing scene boundaries. Its logic lives in the field overlay (PROT 0897) and the 43-opcode script VM, and the open questions left here are a residue of gate families no save state reaches and one menu refusal seen once after a Door use.

ThreadStatusWhat would close it
Region story-flag gate families (record-header C1/C2 gates)partial - structure settled; play order capture-confirmed for most spokes; the residual is a card-block question with the instrument readydetails ↓

Three rows closed here. Does a later keikoku MAN replace the Ravine pushback closed as no: the Ravine has one MAN, and every arm of its pushback walks the player back out. Does retail step helper contexts while a timeline sits on an open text box closed as yes: every context off text keeps its slice, and a second context that reaches text waits for the one shared box - the port now keeps a single box owner. The Tetsu fight seats and flags as retail does: a scripted row, so Run is refused, with the Ra-Seru bit raised by battle init and the lone monster at its fixed seat.

Who sets a field NPC's moving-class bit closed: the placement seater sets it on every placed NPC and one opcode sets it at 26 spawn prologues; nothing clears it. Wiring what it gates showed the "motion-pause kick" is a standing-clip request, not a hold, and brought the per-actor visibility cull onto both hosts. The Door items' route closed with it - a capture of a Door of Light and a Door of Wind use matches the port phase for phase.

Five rows closed here. What clears the two halt bits an inn conversation sets is the conversation's own opening op, read a second time by the per-actor walk kernel as a twenty-frame "turn to face" order: its last frame clears both bits, 18 frames after they went up, with the text box already open - so the halt is a window in which the player turns toward the speaker, not a stall. Whom that turn faces is whatever actor the op names, not always the speaker: 40 of the 146 such ops in placement scripts name another actor. The field's attached light was already fixed when its row was written; the dark rim matches retail on both captured scenes. A script jump read as a screen-mode test tests the held d-pad against a compass table, and a scratchpad bit turns out to be the "stand on this tile and press Down" re-poll Rim Elm's beats use (settled).

Four rows closed here. The region battle-setup half is ported on both hosts: a region's byte picks the battle backdrop, re-opens the Door of Light / Wind items and keeps or drops one backdrop object; only the world-map return point it also stores has no consumer in the port. Scripted arcs and attached sprites are drawn on both hosts, and the arc now waits for its target instead of skipping the op. kor5's 0x619 was never a chain beat: the write sits in a record's spawn section, which retail runs once per scene load, and the engine had re-run it on every talk. The frame-step floor is the scene's: field init writes 2 and the opening scene's own script raises it to 3. And a capture settled where an inn conversation ends: at its last page, not at a failing halt on the next pass.

Does the kor5 chain write its tail flag without help closed as yes: with only the two trigger tiles poked and the chain's boss fight held at 1 HP, the record that writes 0x436 does so 3,336 frames after the previous beat clears, and the tail record fires on its first crossing. The 17,500-frame estimate was the probe's own - it re-triggered an earlier beat over the running chain and stalled it (settled).

Does retail's cold entry into conc clear flag 0x6DE closed as yes - twice - and the flag turned out not to be progress at all. A single-flag write watch across retail's own card-boot entry sees the scene load clear it from two entry scripts (not the two walk-on records the engine had blamed, which a cold entry never reaches), and from the first field frame the entry script's per-frame body sets it again every other frame, for as long as the party stands outside a box of tiles around the plaza. Teleporting the player into the box stops it dead. So 0x6DE means "the party is not in the plaza", and the card-boot save held it set because that is where the save stands. The engine half was a real defect: the system script's position anchor sat at the origin in every scene but three, so every per-frame box test on the disc answered "outside"; it now follows the player each frame (settled, do not re-walk).

Does a scripted camera tile window survive into the next scene closed here: it does, by 78 frames. A per-frame poll across a real world-map-to-town door finds the scene word flipping at frame 37 while the window keeps the previous scene's values, re-stamped only at frame 115 and per region from there. The port's re-stamp-per-entry is not falsified; the value it stamps is - the engine's field default is a later region's window, not the one retail writes on entry. The same run retired the walk meant to produce it: a house door inside a town is an intra-scene warp, so it crosses no scene at all (settled).

Three field-VM opcodes closed here, none of them doing what its label said. 4C 14 clones an actor - it is the one eight-byte instruction in its nibble, and the extra byte names the source actor whose transform is copied onto a fading pool node; the seven-byte reading desynced 94 sites in six scenes from their first occurrence. 4C 86 spawns a reflection controller: the executing script makes itself the mirror image of the actor its last operand byte names, and the six signed halfwords are that controller's mirror line and tracking rect. 4C 87 retires every live one - and neither it nor its sibling 4C 9F parks the script, because the advance sits in the retire call's own delay slot (settled, do not re-walk).

Does retail's equip screen offer a Goods-slot candidate closed here: yes, out of the item class-2 id space, through three builder cases the browse step selects by writing a content id per row. Their filter carries no character mask - the masked rule belongs to the armament half only - and 80 of 151 class-2 ids pass it (settled).

What consumes the fishing bite tick's per-cell fish weight closed here: it is the modulus of the caught fish's size roll, and the same value plus a constant becomes the render scale of the object the catch spawns. It touches neither the species roll nor the bite credit, so a deeper cell makes a bigger fish rather than a different one (settled).

Which view build the frame draws under closed here, and the answer is the first. Splitting each ordering-table link by its graphics command code over three runs - including the real world-map-to-town entry the question was asked about - gives 4289 polygons: 3861 under the first site, 428 under the second, and none under the third or either of the world-map module's pair, whose whole share is attribute packets and flat rectangles. The earlier link-count ranking was mixing those in with polygons (settled).

What a field submode returns to closed here: nothing reads the parked word. The submode enter stores it twice, neither the executable nor any of the 86 extracted overlay images loads it at any width, and a live read watch across an enter records none either - so the return rides the driver's own handler slot, and the port's collapsed chain drops a store retail never consumes (settled).

Three rows closed here at once, two of them camera. What composes the field camera's translation - the live eye trio is the eye-space translation and the focus is transformed through the scaled rotation into it, so there is no eye-back depth constant to calibrate; four readings fell with it, including a sibling routine that turned out to build another mode's view. What edbylon selects when the tile query misses - nothing does: no site re-queries the camera zone on a bare tile crossing, so the block is held from wherever the player last crossed a queried tile. And the Throw Out cursor, which is a bag slot; the displayed list hides empty slots while the cursor's payload does not, so the two disagree on exactly the bags a fixture never builds. Before them: what arms _DAT_8007B8B8 - it is a one-shot entry-mode argument rather than a latch, with ten writers and 25 readers across the 84 overlay images and six sites that write zero, so the field overlay's one ambient template is spawned per scene and not once at boot. And the coplanar residual tail: the curved-shell half was answered by reading retail's own display list (it never draws both copies), and the sliver half turned out to be the port's own repair pass - the leftover strip is exactly one nudge wide because the lift applied to that family lies inside the second plane. Both on settled threads, the sliver reading on do not re-walk.

History: teien's hedge fill and Rim Elm's south gate (both closed)

teien's hedge-base ground fill had a false premise. Retail ships no kind-2-cell draw channel at all: a live teien field pass visits 1536 window cells and emits 370 - exactly the cells carrying 0x1000 - and none of the 42 that are 0x0800-only. Only 8 of 84 images touch the object grid at all, only PROT 0900 / 0901 hold a per-cell pass, and each one's andi 0x800 reads an object record's +0x12 rather than a cell bit. The cell bit 0x8000 turns out to be a per-tile depth-sort flag. Answer on settled threads; the falsified reading on do not re-walk.

Neither of the gate's two walk-on bands holds the player in - the exit record is ungated and the other is five inert bytes; a collision row painted by the gate object's own script does. Answer on settled threads; the falsified force-walk reading is on do not re-walk.

Region story-flag gate families

Status: structure resolved and settled; residual = play-order confirmation for the dungeons the capture corpus never walked.

Every scene's spawn records carry a list of story flags that must be set (or clear) for the record to fire - which is how the game makes a door open only after a boss, or a villager say something new after an event. The per-region families of those lists are decoded and pinned; what is still owed is watching the flags fire in play order in the regions nobody has walked under a probe.

Evidence, residual and the runbook

The per-region C1/C2 gate families - the partition-2 record-header flag lists the spawn evaluator FUN_8003BDE0 checks - are decoded across the chapter-2/3 regions and the Rim Elm variants, with every family's exact lists pinned by census-file anchor tests. The full structure (Sebucus spokes, Rim Elm opening/revisit/final bands, Uru Mais, Nivora Ravine, Karisto castle depth, Conkram, and the 0x7/0xF variant-discriminator pattern) lives on settled threads § Region story-flag gate families.

Residual. Poll-tier playthrough captures (mined with save-state-load frames screened out by their mode-churn + inventory-rewrite signature) confirm live play order for retona, dohaty, taiku, the Sebucus teien-tower-geremi spine, korb3, the kor5 chain head (0x43A to 0x436) and the map03 hub latch, alongside the earlier organic ropeway/ropeway2/jiji walks and Nivora's 0x370 SET. Still owed:

  • never walked, and the corpus cannot help: rayman/rayman2, station/station3, and the Karisto spokes bubu2 + deroa/chitei2. A sweep of both emulators' state populations finds no state in station, station3, bubu2, deroa or chitei2 at all, and the one rayman state answers a different question - an idle firehose over it logs 0 SETs and 2 CLEARs, because a family SET fires on the beat, not on standing still. These need a human play-forward, not another probe;
  • walked without an organic family SET (the beats were already latched in the loaded state, or the region was entered mid-arc): retock/retockin (0x502 never fired; 0x357 pre-latched), doman (0x3FB did not fire), nilboa's entry family, son, and the kor5 tail 0x6C4.

The generic C1/C2 seeder already drives every family. One more session from an early-enough save (before the retock/doman/nilboa beats) closes the walked-but-latched set; the never-walked set needs the walks themselves.

A door no longer needs a walk. A walk-on door is an exact tile match in the scene map's trigger table, so writing the player's position onto a door tile crosses it in about ninety frames (scripts/pcsx-redux/autorun_w5a_poke_walk.lua), plus one confirm press where the door asks a question first. Paired with a single-flag write watch, that turns each residual spoke into one run from a card save that reaches its region. It measures arrival, never the walk - and read what it logs with the conc lesson in hand: a flag written every other frame from an entry script's per-frame body is a position test, not a story beat.

What this needs is capture time, not a new instrument. scripts/pcsx-redux/autorun_flag_firehose.lua is already the right probe: an exec breakpoint on the flag SET / CLEAR entry points with the writer's ra, plus a per-VSync scene-name and game-mode poll, so a single play-forward through a region emits the region's own SET order with the scene each write happened in. It is designed for whole-playthrough runs, so the four unwalked regions can be covered in one session.

Two operating notes, both already bitten: PCSX-Redux probes do not exit on their own - kill on a timeout or the process hangs (PCSX-Redux automation) - and pgrep -f matches the caller's own command line, which is why the process-matching helpers in scripts/lib/proc.sh exist.

Battle / rendering

Battles run in their own overlay with their own screen chrome - the enemy-name banner at the top, the party panels, the arts announcements. Most of that chrome is now pinned sprite by sprite, and every tick body of the cast-module band is decoded and ported; what is left here is the order the overworld fog draws in, and one ambush fight no save state holds.

ThreadStatusWhat would close it
Are camera-relative move-VM parts drawn camera-relative?open - capture; neither host does334 of 3956 nodes in the save-state library carry a billboard, axis-skip or camera-lock flag; no draw record carries that flag, so both hosts draw them under the full camera.

Three rows closed here. The Rot and Curse marks over refused arms are drawn on both hosts: a Rot stamp on the Attack chip, the Curse plate on the Magic chip, and a Rot stamp on each rotted direction during arts entry. The overworld decoration cells are depth-cued per object toward far colour 0xD0, on both hosts. The overworld fog sheets read too bright because the GPU writes a texture-blended pixel at 5-bit depth; both hosts now blend the screen primitives the same way.

Does a monster's one-shot clip tween into its queued clip closed as yes, and ported: on its last frame the decoder blends into the first frame of the clip that plays next, carrying the entry's end-of-clip step on the Z axis, and at the clip's natural end the actor moves by that step - so a lunge ends forward without snapping back.

Does the monster animation decoder share the field blender's re-blend retry closed as yes: it rewrites the next frame's angles in a scratch journal past the same threshold, and the port now poses monsters through a battle kernel that does the same.

Is the overworld ground depth-cued closed as yes: the far colour is a literal 0x100 per channel set just before the terrain emitter runs, and both hosts now draw the cue (566 of 584 keikoku cells exact).

Does Koru's timed-fight strip draw over or under the name tab closed as over, by disassembly: both are text actors on one list kept sorted by key, the tab's key is larger, and the list is drawn front to back onto the same ordering-table entry, so the strip covers the tab. Both hosts now hide the tab while the strip is up.

Three rows closed here, all on the overworld. The camera's vertical offset is written by the first overworld's own entry script, once, two frames after the scene starts; the port never reached that line because its system script sat anchored at the map origin outside field mode, so a whole-map "is the player here" test always failed. A routine read as a depth ramp builds the overworld's screen-curvature table, and retail bends every overworld vertex by it; both hosts now do, though the port also bends four rows of landmarks retail leaves flat. The field drop shadow - four textured quads over a projected grid at the actor's feet - is drawn on both hosts and matches retail's packets on every captured frame (settled).

Three more rows closed here. The overworld camera is the field zone camera: the overworld is a field-run scene, and on every resident overworld state the live camera equals the zone composer's staged pose, so both hosts now run the zone camera there. The world-map fog runs on both hosts: the kingdom's system script is stepped on the overworld, widens the view window and raises the fog gate, and the spawner's overworld arm is modelled; what is left of its density is the fog row above. The enemy-target label is retail's target-select plaque on both hosts, centred on column 232 at row 162; the slide-in is not modelled (settled).

Three more rows closed here. The commit log is drawn on both hosts - one row of name, command and target per committed member, scrolling up as the round fills; the slide-in and the round-start launch are not modelled. The native world map's white sheets were the field fog: a debug launch flag left the overworld in field mode. The spoils and shop ink is retail's default light-grey pen on every screen that had drawn full white.

Three rows closed here with a wire on both hosts. The party-wide commit-confirm screen is staged once, after the last member able to act, for every party size; its Reselect steps back one member - onto the last able member, not the first - and refunds that member's item. The Mist forest's missing native fog was the native scene VRAM lacking the effect-texture pool the fog page samples; retail keeps it resident under every field scene. Which host draws Koru's turn strip is both, and only its order against the tab stays open (settled).

Two threads closed here at once, both of them questions about whether a routine no capture had caught is reachable at all. Does any shipped actor raise the mesh-renderer gate closed with a yes that splits in two: the actor allocator stamps the halfword when a world-map dev counter has a bit up - booted clear, raised only by the debug menu and a pad ring - while the content-driven raiser is a move-VM opcode that writes its own operand into the field, and shipped move programs do issue it non-zero. What the 5089-zero census establishes is narrower than "nothing raises it": across the sampled modes no drawn actor had the bit up. And is the Muscle Dome match state machine entered by an ordinary battle closed on the bytes as well as on a capture - the routine has exactly one call site disc-wide, unconditional, inside the SCUS battle frame driver, and three non-dome battle states enter it hundreds of times over 700 frames each. It is the round state machine every battle runs; the dome is one of its callers' contexts.

No open threads here. The last one - what stages the dance widgets' second texture page - closed on the disc rather than on a capture: the page is boot-resident interface art out of the archive's unindexed head gap, so no archive entry stages it and no per-entry sweep could have found it (settled).

Closed here: who reads the GTE light matrix the per-actor render dispatcher writes inline - five sites, every one of them a normal-colour GTE command in the world-map handlers, with no overlay image containing one and nothing on the disc selecting the light matrix through the general matrix-vector command's matrix field. The question needed a census of GTE opcodes rather than a cross-reference query, because the matrix is consumed implicitly by the commands that read it. It corroborates the renderer page rather than changing it: the field path applies no light source. Before it: which frames gate each capture-class tick body's arms. Every arm of the band is decoded and ported, and the dwell turns out to be a module-resident countdown whose drain is a per-arm multiplier of a scratchpad frame byte - so the product shape holds for one family, not for the band. The last two arms needed a different caster rather than a different state: both stage the same clip, and the animation commit resolves a staged clip by indexing the caster's own spell-entry array with it, so a ten-entry monster reads its record's name text as a pointer. No monster record names either action, so retail never performs either cast. With it, where a slot-B module image's highest spawn record ends. Its own move-VM program bounds it, under four rules - round the end up to 4 because the records are word-aligned, let HALT outrank an armed idle loop, chain [header][program] rather than assume one record per pointer, and fall back to the last maximal WAIT the walk stepped over. The "within 4 bytes for about three quarters" figure that read as evidence of no static rule was the missing alignment step. Every image that has a highest record now bounds it, and the residue has a direction: no miss ever terminates above a measured end, so the rule never claims bytes the band does not bound.

Recently closed in this area: the eleven player-Seru tick bodies, now ported off their own disassembly rather than off the per-entry stager verdicts that stood in for them; and the two ready-work rows that asked the port to catch up with retail. The live loop stages the Seru-magic side-effect debuffs and installs the random-encounter boost profile, having first derived the scripted-fight gate the stager reads, and the dome seeds the special-battle word from its three story flags at entry, so a seeded course crosses out the Item chip and the top seed the Ra-Seru chip.

Before them: what makes a Ra-Seru chip render. The question had a false premise - the native window drew no dome command cluster at all - and the three gates are now in order: ctx[+0x25F+member], then +0x16E & 0x1000, then the special-battle word 0x8007BAC0 & 0x200, of which only the third selects a mark. The three emitters FUN_801DBC30 (the red cross-out X), FUN_801DBD04 (Attack) and FUN_801DBEC4 (Ra-Seru sealed) are pinned cell by cell (settled threads).

Before it: the battle-intro enemy-name banner - the question had a false premise. No placement record raises it; the flow-0x0A composer FUN_801D9D3C places its labels with immediate geometry at y = 48, nothing slides, and the intro timer tears them down (settled, falsified reading). Before it, the +0x0E kind-pair mapping and the element-badge palette selector both fell out of the widget-class table, and the status-element badge sheet 0x18..=0x20 is pinned cell by cell.

Recently closed in this area: pack-member growth (nothing outside a scene TMD pack holds a byte offset into it, so a rebuild is the only cost) and the signature-cast choreography question (the spawn layer is data in the art path's own record format; the lift and camera are module code) - both on the settled page.

Audio / BGM

ThreadStatusWhat would close it
Is a field track the script left running audible under a mid-game movie's XA?mostly resolved - yes, where the script left it soundingCaptures in four scenes agree: a score the script left playing keeps playing under the movie, and one it stopped stays silent. The port now layers the score under movies the same way. Two scenes (town0d and jouine) are still unmeasured, because no save state reaches them.

What the field init's slot-10 load serves closed as the credits theme, by disassembly and capture. It is not a bank of sound effects: the field init stages the credits score and its instrument bank into sound slot 10, starts the score itself, and raises a latch that makes the ordinary music loader stand aside. The ending save states hold that score in slot 10's buffer byte for byte, and the engine now plays it from the same two disc entries (settled).

Does a Muscle Dome round load the battle sound bank closed as yes, by capture: entering a round closes the field bank's slots and the battle loader stages the class-2 bank, exactly as an ordinary field battle does - which is what the port already did (settled).

Do the hosts play the field's scripted SFX cues closed as yes, on both. The two script opcodes hand their cue ids to the same four-slot ring retail keeps; both hosts replay it, the field's own sound bank is resident and swapped per mode with the battle bank it shares memory with, and a cue whose bank is closed is silent rather than played from the wrong bank.

The last three threads before it closed the same way: by fixing the instrument rather than the engine.

Why the port sustains more sounding voices than retail on the same track closed as two instrument defects stacked, with no engine change owed. The "matched window" was never matched - pairing frame 0 of each side compares two different bars of one piece, and the retail window actually aligns 3111 frames into the engine trace, where both a symmetric and an intersection-only pitch score peak. Aligned, the two sides carry the same ten envelope-config words, the same key-on count on nine of ten tones, and 71 engine key-ons against 67 retail ones. What is left is in the envelope channel, and that channel is not on emulated time at all: the emulator steps its envelope on an audio-paced thread, so a per-frame save-state capture carries an uncontrolled amount of envelope motion - two captures of one state with no input agree on the voice pitch register for 5285 of 6000 voice-frames and on the envelope level for 404 of 1000. The comparand that survives is the key-on rate, which the score performs from the game's own frame handler, and on the aligned window the two sides agree (settled, do not re-walk).

Two threads closed here at once, and both closed by fixing the instrument rather than the engine. Which voices the score allocates is now an ordinary comparison - the trace record carries envelope level, per-side volume, the envelope-config word and the reverb send for every voice from all three emitters. Why the engine's mix is quieter closed on that oracle's own criterion: the two channels it named as divergences were an instrument reading the wrong register, and a pairing of two different pieces of music. What survives is a window difference - the engine renders a track from its first tick where a retail save is frozen somewhere inside one - and that is the residual the row above carries.

Closed here: which battle state owns the only arm that reaches the high cue band. It is the Spirit / Item wait state, and the door into it is an ordinary item use - a spell cannot reach it, because the magic arm only routes ids below a threshold the player's own Seru block sits above. Fifteen injected casts finding the arm cold was the bound, not a sampling accident (settled).

The last thread here - a supposed second record family inside the battle sound bank - resolved as a neighbouring file's tone rows left in the sector (do not re-walk). The one before it - field-VM op-0x35 sub-op 0xA - closed as the track-swap commit; see settled threads.

Containers / data blobs

No open threads here. The last one - whether the PAL text renderer remaps two accented bytes - closed as no: all four PAL executables draw a glyph straight from its byte, so the French and Italian discs really do show placeholder boxes where their script uses those two codes.

The last three threads here closed on one mechanism - the packer's buffer.

Should byte accounting cut an inherited tail the way disc coverage does closed as yes, with one rule under both instruments. The disc was mastered through one buffer indexed by file offset and never cleared, so the bytes past an entry's own content are the bytes of the nearest earlier entry that reached that offset - an overlay, or not (the battle overlay and the boot image both end in a battle-effect file's bytes). Searching for that suffix over the whole entry reproduces the old cut on 82 of 83 images, and the same rule explains every scene bundle's last-sector residue and the compressed-container, pack and battle-sound-bank tails that had read as bytes a walker left behind. PROT 0901 was the last disagreement, and its own code settles it: its last routine returns well below the run, which opens mid-routine on its neighbour's epilogue (settled, do not re-walk).

Is the tutorial module part of the slot-B module band closed on the layout question rather than the band one. The layout walk is selected by the shared link base, which admits the image at 96.6%; its prompt pool is consumed - twenty-eight strings its own code forms - and its one frameless leaf is reached by a call from inside the image, which also retires "a slot-B image never calls itself". Which images the cast dispatcher reaches is a separate question, and its range stays where it was.

What actually breaks a rebuilt character-pack container at battle load closed here: nothing a rebuild can do reaches the registrar, and the symptom is the truncated pack the third reading already named. A sixth reading corrects the fourth rather than the fifth. The loader does check integrity in its own frame - on one of its three entry arms it reads the raw container back out of VRAM, re-sums every word and compares against the sum taken at boot, reloading from the disc on a mismatch. But that guard sits on the decompress source, not on the pack the registrar walks, and the register-only arm jumps straight past it. And the leg the row kept open is not constructible: its "header size word" and its "decoded length" are one field - the descriptor's own size word, which both sizes the buffer and drives the length-driven decode - so a hand-built container can only truncate, never disagree. The probe the row left over has run too, and a RAM clobber cannot trip the guard: a genuine mismatch reloads and heals in about 45 frames, but corrupting the resident container leaves the sum identical, because the sum is taken over a read-back from VRAM (settled, do not re-walk).

Closed here: which image holds the dev-menu row strings - the field overlay, at a file offset its own renderer forms the address of, with a live window byte-identical to that image's head. The other slot-A occupant aliases the same address and the two are never resident together, which is the whole of why it read as unattributable (settled).

Closed here: what writes the slot-B stage selector - the field entity tick does, off a system story flag, and battle latches its other value directly. Every access to the byte is of a form the project's address sweep cannot see, which is why it read as writerless for so long (settled).

Recently closed here: the card-screen kanji page is sampled by nothing - the GPU-FIFO watch at card-screen entry draws no primitive from it, so the USA build ships the Japanese glyph page and never reads it (settled threads).

Measurement + tooling

ThreadStatusWhat would close it
Which save-state library entries still hold a patched executable?open - narrowed: audited and tagged; the rest need human playA save state made on a patched disc keeps that build's executable in memory forever. Every library state is now tagged with the patch family it carries, the playthrough anchors are re-shot on an unpatched disc, and every capture-graded claim re-checked against its family stands. Re-shooting the remaining boss, story and minigame states on an unpatched disc closes it.
Which engine draws hand a raw LCG state where retail calls BIOS rand?mostly resolved - every battle draw is shapedRetail's rand returns the high half of one kernel generator that nothing reseeds, and every battle routine the port covers calls it - no battle code carries a generator of its own. Every battle-side port now draws from the one shaped world stream. Left: one field-script extension still draws the raw state, and the battle camera script, the camera shake and the Muscle Dome session keep private seeds. Moving those onto the world stream closes it.

Which live ports cover only part of their routine closed: every residue the audit named as still changing behaviour is ported. The last three were Baka Fighter's display clip (all three hosts pose the fighters from it), the victory load hold's stream request (a capture now sets its span) and the battle draw tick, whose crate barrier went when the pass moved into the VM crate.

Three threads closed here together. Which slot-B record walk bounds PROT 0944's top record closed on the walker, not the image: nothing in any consumer bounds the record band, and one walker had chained zero padding as a record. Both now stop at eight zero bytes, which moves twelve images and leaves the two instruments agreeing everywhere. Does any shipped beat take the screen-effect arm's second fork closed as no: a census of every writer of the gating bit over every image and scene script finds none the disc executes, and a motion-VM opcode pair fell with it - no scene authors either. Does the morph-weight spawner ever seat its handler closed by taking the seat, and a premise fell on the way: the spawner's model operand is an index into the scene's model bank, not the global pool, which is why two scenes looked unseatable - all five carrier scenes now seat, and all seventeen morph blocks fit their mesh vertex for vertex (settled, do not re-walk).

Which model owns the field screen-effect fade closed here, and the answer is the push. Retail's beat, logged frame by frame, is one spawner call per step from an effect actor the script arm creates - a (kind, blend, packed colour) triple, which is the push's shape exactly - while the global multiply tint holds neutral for all 900 frames of the capture, so the beat is not a global-tint fade at all. The row's premise was half wrong in the port's favour and half wrong against it: the float ramp it said both renderers read had no reader either, so both representations were dead, and the arm the port did implement was a third of one - retail's is a walk-out / walk-in pair whose blend and push kind come out of the sub-op byte, and whose all-zero operand clears the live actor rather than ramping to black (settled, do not re-walk).

Four threads closed here before them, three of them the Equip screen's. What retail's equip item-info panel looks like closed by driving one: every library state parked on the screen sits at slot-pick with the panel blank, so the oracle was absent rather than disagreeing, and a pad ladder into the candidate list gives one populated frame per row - three stacked panels, the lowest of which only an item with a passive fills. Whether the port asks the compare-category question of the wrong row closed as yes and is fixed: retail's guard silences the four gear rows, so only the three accessory rows resolve a category, and the category follows the hovered item rather than the row. Where retail enters the list-reorder screen closed on one address - the pause menu's Status row is the only site that raises that sub-screen, and the port's Magic-screen shortcut was its own invention. Which per-frame kernels the hosts share closed by building the instrument the row asked for: a tier comparing, per paired kernel, the engine functions each host's body reaches. The first thing it found was the pairing's own failure mode - a native body that was empty, aliased to a browser kernel that does real work.

Closed here: which shipped scenes carry the two rarest field-VM script arms - one scene and three scenes respectively. The row asked for an instrument rather than an answer, and the instrument is the general one it predicted: a disc-wide opcode census over every scene's script stream, whose zeros separate "no fixture drives this arm" from "the disc contains nothing to drive it". Before it - eleven cast-band tick addresses statically live and never entered by any ladder - closed the way its own row predicted, by seating a cast per PROT 0903..0966 id. Two of the eleven turned out not to be cast bodies at all but AoE sweep stagers reached only through the AoE entry, so a ladder over the ordinary cast path could never have converted them; the rest were second arms of modules a ladder already entered once. Read a reach cell as a claim and not a measurement: the page audit checks addresses, not the prose beside them.

Recently closed here: when SCUS's one call into slot B runs - a probe driving a Slippery cast catches it firing 212 times in that single cast, across six module phases, always with the battle-running signal set; its gate has five writers inside PROT 0920 and never reaches zero on its own, so the three-site table the docs carried was incomplete. With it, the dashboard's Port %, which was dividing and multiplying by rows the ignore list removes, and the donor call sites the slot-B call-site filter admitted - cutting every call site and record target at the image's own content end drops the credited pointer in five of the six images. Before them, cast_earthquake's floor. The 2480-byte tail neither shape rule recognised is the module's spawn-record band - [i16 model_sel][u16 reserved][move-VM bytecode] records addressed by the consumer's own pointer-forming instruction, present in 62 of the 64 images. No earlier shape rule reached it because a record's bytecode contains a lui word by accident, which the data-segment test rejects. Before it, PROT 0901's middle band splits into nine routines - eight frameless tail-call leaves plus a framed ninth at 0x801F89B8 - and the boundary rule is the j that leaves the band, not every j in it (twenty sit there and only eight leave).

Title / boot / overlays

No open threads. The last one - which entry uploads the card-message page - closed on a capture: the strips are the title screen's own art (PROT 0890), redrawn behind the Load window when it is opened from the title, and the port draws them on both hosts.

The last thread closed here - the browser play page holding no mode seat - closed by being taken: the browser runtime now owns the same mode seat the native host does and enters MAIN INIT and CARD INIT through it. The thread had assumed a residency model was the blocker; what it needed was the seat, because an INIT mode lasts one frame inside the seat's own enter call and hands off to RUN before returning. That is also why no post-call sampler can witness one on either host, and why the parity witness is the edge count rather than a mode word.

The two threads before it both closed by capture. Nothing draws the init.pak WARNING screen - the TIM is uploaded to VRAM (704, 0) and given descriptor 1 of the table at 0x801F369C, and no call site ever passes that id. And a cold boot always shows title sub-mode 0x10: the boot image raises _DAT_8007BB00 unconditionally at 0x801CEB84, so the 0x02 two-row menu is unreachable. Two readings fell with the second - the sub-mode word is 0x801F0204 and 0x801DD920 is only the instruction that writes it, and the slider state[-0xEB4] has no [0, 0x2C] range (both arms converge on 0x2C).

The thread before those - the identity of PROT 0968 - closed by capture.

History: how PROT 0968 closed

The cort_evolved_battle_first_menu PCSX-Redux state (first command menu of the evolved-Cort fight, before any cast) shows the loader-B tracker 0x8007BC4C reading 0x49 and entry 968 100% byte-resident at 0x801F69D8 over its own 0xA28 extent, with the field-side ladder states bracketing the page-in to the battle load. See settled threads § PROT 0968; the instrument is scripts/mednafen/check-0968-residency.py, which reads either emulator's states (dispatched on file extension).

When to add a row

A thread belongs here when:

  1. There is something specific that would close it - a probe to run, a dump to read, a function to port. "Generally understand X better" is not closable; skip.
  2. The next step is non-obvious from the code or git log. If grep would surface it, no row needed.
  3. The detail lives elsewhere (a docs page, a Ghidra dump). The row is the pointer, not the analysis.

When a thread closes, rewrite the row to a resolved / falsified line if the path was instructive enough to warrant a do-not-re-walk marker; otherwise delete the row. Rotating the page is part of using it.

See also