re: sub_822737C8 is the coroutine spawner; the record's third word is the MAIN ENTRY
Asking who calls the function the timeline calls enumerates every way an ISL routine
can begin. sub_822737C8(phase, base, offset) computes base + offset early on, and has
seven real call sites: the phase initialiser sub_82270DF8, the built-in stub region
(start_coroutine), the timeline walker sub_822748D0, TWICE inside sub_8226D740 -- the
per-frame engine->script drain -- and two unread, sub_82273910 and sub_82264058.
CORRECTION to my own write-up: the 0x1883 record's third word is the phase's MAIN
ENTRY, not a "size". The initialiser hands it straight to the spawner:
8227101C or r5, r22, r22 ; the record's third word
82271020 or r4, r26, r26 ; the code base
82271030 bl 0x822737C8
44 of 44 records land on the instruction stream (100%) against a 25.0% control, and
all three Stage-02 targets open with the identical prologue
`special[0]=0 ; local[0]=0 ; call builtin116(0)` -- a routine entry, not a length.
So the record is 0x1883, base, MAIN_ENTRY, 0, code_end, force_end_handler.
Seeding the main entries moves no coverage number: every one was already among the
CFG's entry points by another route. This corrects a field's meaning, not the graph.
Lead recorded rather than claimed: both of the drain's spawns take their offset from
[node+112], the first field of a drained node to be located, and the best remaining
angle on the ~15% of code nothing appears to start. It is NOT shown that those nodes
come from the trigger queue at phase+272 -- that is precisely the over-reach
isl-builtins.md already made and withdrew, so it is not asserted here.
All artefacts regenerate byte-identical; this is documentation only.
This commit is contained in:
@@ -99,8 +99,25 @@ tag `0x19` = int, tag `0x1A` = IEEE float — and `entry_a` is where it starts.
|
||||
exceeds 0x18 is exactly that phase's `entry_a`. Zero exceptions.** Only two tags
|
||||
ever appear: 1 394 × `0x19` and 675 × `0x1A`.
|
||||
|
||||
So the record is `0x1883, base, size, 0, code_end, force_end_handler` — one
|
||||
boundary and one entry.
|
||||
So the record is
|
||||
|
||||
```
|
||||
0x1883, base, MAIN_ENTRY, 0, code_end, force_end_handler
|
||||
```
|
||||
|
||||
🔴 **The third word is NOT a size** — that was my label and it was wrong. The
|
||||
phase initialiser `sub_82270DF8` passes it straight to the coroutine spawner:
|
||||
|
||||
```
|
||||
8227101C or r5, r22, r22 ; r22 = the record's third word
|
||||
82271020 or r4, r26, r26 ; r26 = the code base
|
||||
82271030 bl 0x822737C8 ; spawn(phase, base, word3)
|
||||
```
|
||||
|
||||
Measured: **44 of 44 records land on the instruction stream (100 %) against a
|
||||
25.0 % control**, and all three of Stage 02's targets open with the identical
|
||||
prologue `special[0]=0 ; local[0]=0 ; call builtin116(0)` — a routine entry, not
|
||||
a length.
|
||||
|
||||
🟡 The table's contents are **not decoded**. Its int values do land on the
|
||||
instruction stream more often than chance (46/51 vs 29.5 %), but **0 of them are
|
||||
|
||||
Reference in New Issue
Block a user