Canary backs the whole guest address space with one shared-memory file, so the game's RAM is readable from the host while it runs -- no debugger, no emulator patch. That turns the parked Route-B question (fields the IDXD omits because they sit at their default) from "unreachable" into a table lookup. gmem.py maps guest VAs into /dev/shm/xenia_memory_* via Xenia's fixed table and searches only the allocated extents, so a full-RAM scan is ~0.2 s. weapon_runtime.py finds the parsed objects by scanning for their vtable, then *solves* the struct layout instead of guessing it: every (field, offset, encoding) triple is scored against the disc records, and a binding is accepted only with zero contradictions -- and marked confirmed only when >=10 records agree on >=3 distinct values, because a field whose samples are all one number matches any offset holding that constant. Result: Weapon (0xc0) and Shell (0x200) mapped, 4393 values the disc does not carry, for all 126 weapons at 5 % save progress. Cross-checks hold -- the Arsenal DATA SHEET read 4 for wep_05/wep_60 Max. Lock Ons and the memory read agrees; the in-flight HUD's 06000/00300 match LoadingCount; all 252 objects are byte-identical across a screen change, so this is definition data, not state. Two findings fell out: `IsCharging = Yes` switches LoadingCount and TriggerShotCount to float32 (it partitions the 8 float-encoded records exactly), and two .tbl entries declare Shell_TCAF_Ship_AAGun with conflicting Power -- the runtime keeps the one that omits it. Where the defaulted values *come from* (the IDXD's undecoded binary node region vs code defaults) is not settled here; they vary per weapon, so they are not one constructor constant. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
4.3 KiB
4.3 KiB
RE knowledge index
Confidence: ✅ CONFIRMED · 🟡 PROBABLE · ❔ HYPOTHESIS. See README.
Formats we've already reversed are, for now, documented by their parser + disc round-trip
tests (the executable spec) rather than a prose file — the "Spec" column points there.
Promote to a prose structures/…md file when a format needs behavioural notes beyond layout.
Data structures / formats
| Format | Conf. | Spec (parser + tests) | Notes |
|---|---|---|---|
IPFB .pak archive |
✅ | sylpheed-formats/src/pak.rs + tests/pak_idxd_disc.rs |
header + 12-byte TOC, Z1/zlib payloads |
| name-hash (TOC keys) | ✅ | sylpheed-formats/src/hash.rs |
Barrett-reduction hash; recovers original paths |
| IDXD object/table | ✅ | sylpheed-formats/src/idxd.rs |
self-describing; ship/weapon stats verified vs known values |
| XPR2 texture + cubemap | 🟡 | sylpheed-formats/src/texture.rs |
de-tile + A8R8G8B8; colours unverified (dynamic item) |
| T8aD 2D texture | 🟡 | sylpheed-formats/src/t8ad.rs |
~85% decode; colours ✅ CONFIRMED (k8888); ~15% variants deferred |
| RATC bundle | 🟡 | sylpheed-formats/src/ratc.rs |
child listing confirmed; one level deep |
| LSTA sprite list | 🟡 | sylpheed-formats/src/lsta.rs |
inline T8aD frames |
| IXUD subtitle | 🟡 | sylpheed-formats/src/ixud.rs |
timed cues; movie↔track link unknown (dynamic item) |
| Fonts (ttf/otf/ttc) | ✅ | sylpheed-formats/src/font.rs |
standard OpenType, parsed via ttf-parser |
| XBG7 mesh | 🟡/❔ | sylpheed-formats/src/mesh.rs + tests/mesh_disc.rs (xbg7) |
weapons/props: declaration-driven variable stride (36 models), GPU-confirmed. Stage containers: 5662 sub-models across 22 stages via content-anchored grouped pools (stage_models). Quantized hero bodies (DeltaSaber f004) still declined |
| Capital-ship part placement | 🟡 | sylpheed-formats/src/ship.rs (static) + runtime capture |
hull placement static-exact; external parts approximate statically. Runtime capture (Canary F10 → VS-constant WorldView) gives ground truth — validated on e106 destroyer; not yet baked into the viewer |
| Weapon fields defaulted on disc | ✅ | runtime struct · DATA SHEET route | Solved. Canary maps guest RAM into /dev/shm, so the parsed Weapon/Shell objects are readable live; their layout is solved against disc ground truth (zero contradictions over 100+ records). All 126 weapons, exact numbers, no story progress needed — 4 393 values the disc does not carry. Supersedes the letter-bucket limit of the DATA SHEET route, which now serves as the independent cross-check |
UI screen layout (.rat) |
✅/🟡 | ui-rat-layout | One pak per UI screen; each RATC = one (context × language) build; every <name>.t32 sprite has a <name>.rat layout record (BE u32; 1280×720 design space; scale/tint/X/Y, keyframes for animated elements, opt link to the focused state). The tutorial PAUSE menu and the title main menu both rebuild pixel-accurately from the disc. loop1.rat (screen-level draw order) not yet decoded |
Runtime / dynamic-capture technique
| Technique | Conf. | Spec | Notes |
|---|---|---|---|
| Live guest-memory read | ✅ | tools/re-capture/gmem.py |
Canary backs the guest address space with /dev/shm/xenia_memory_*; guest VAs map in through Xenia's fixed table. Full-RAM search ~0.2 s (sparse, SEEK_DATA). No debugger, no emulator patch, game keeps running |
| IDXD object layout solver | ✅ | tools/re-capture/weapon_runtime.py |
Scan RAM for a class's vtable → enumerate its objects → brute-force (field, offset, encoding) against the disc records. Accepts a binding only on zero contradictions. Generalizes to any IDXD-backed definition |
Functions / code paths
None documented yet — populated during the dynamic-RE phase.
| Function | Conf. | Reimpl. | Summary |
|---|---|---|---|
| — | — | — | — |