re: the poke control PASSES -- writes reach the guest, hull is authoritative
Hammering settles what a single write could not: hull 0x44BB8000 (1500.0f), 944,387 writes of 1 over 15s, and afterwards the value HELD at 1 -- the game stopped rewriting it. The screen left 'flight', the HUD is gone, the ship is burning, and Natalie radios 'I've lost contact with Rhino 3!', the player's own callsign. The game read the poked value and killed the player. Established: writes to /dev/shm reach the running guest; hull at pos+0x154 is authoritative, not a readout; and a single write loses a race against the game's own continuous writes. This upgrades two earlier results from inconclusive to genuine negatives. The unit-record pokes were downgraded because I could not tell 'ignored' from 'never arrived'. The write arrives -- and those pokes persisted untouched for 60s, so the game genuinely saw state=4 and handle=0 on all three objective squadrons and did nothing. That is real evidence the phase-1 condition coroutine is not polling and its checks run only when a trigger starts them. Withdrawn: last iteration's claim that the pilot's hull= is a different field or scale. I read 1000.0f at pos+0x154 and inferred a mismatch with the logged 1500; this run reads 1500.0f at the same offset. Same field, different value per run.
This commit is contained in:
BIN
docs/re/captures/poke-control-kill.png
Normal file
BIN
docs/re/captures/poke-control-kill.png
Normal file
Binary file not shown.
|
After Width: | Height: | Size: 634 KiB |
Reference in New Issue
Block a user