trigger_watch.sh + host_addr.py translate the guest VA to a host address (0xBE14DEA4 -> host 0x1BE14DEA4) and watch it. It fires: Thread 50 'Main XThread', old 0, new 16777216 -- which is big-endian 1 read little-endian, so the count going 0 -> 1, independently confirming the field. The write happens on the guest's own main thread, not an emulator worker. But the writer cannot be named from the host stack: the faulting PC is 0xa0c65f23 with no symbol, executing 'mov 0x110(%rsi),%rbx', i.e. Xenia's JIT-compiled guest code, and the frames above it are not host-unwindable. So the watchpoint answers when and which thread, not which guest function. Recorded as a ceiling of the method rather than retried blindly. The way past it is that the JIT holds the guest context in a register (%rsi here), so the guest PC is recoverable from the context block -- which needs Xenia's context layout from the xenia-rs sources on this box, a separate tractable piece of work.