leftover-wait99-o32-nk-e32 text-1010 dump-true EntryPoint - #30
leftover-wait99-o32-nk-e32 text-1010 dump-true EntryPoint#30julerobb1 wants to merge 497 commits into
Conversation
|
HEAD ExtraROM is no longer a single Dump B000FFs this host will load (Julian's dump headers; this VM still has only
nk chain table Firmware inherit publish still does not peek ExtraROM VAs. After a real |
|
HEAD
Peek-and-skip of an unmapped chain VA: no site in nk.bin. Overlay is only So after a real
On the Windows host next to the real |
|
HEAD No peek-and-skip site. Overlay only matches NK. Inherit walker skips only
|
|
HEAD Stub probe (no real etc.bin):
No |
|
HEAD Julian’s extracted After Next miss: ExtraROM XIP No SetEvent. No invented |
|
Dump is a real WinForms OpenFileDialog now ( Workflows on this PR:
Dump bins ( |
|
Dump is a folder again on this PR only ( Dump uses No work on PR #28. No |
|
Host chrome on this PR is a MIPS guest console (
No work on PR #28. No |
|
No host/chrome change this turn. Evidence only. (a) No step cap
(b) Who starts the next CE process — not in nk After inherit skip, The client/gwes launch path is filesys RunApps
NK inventory (this
Conclusion: HKLM\init Launch for gwes / tv2clientce is not a dropped NK/hive/Hard Disk path. It is not in this nk. The next CreateProcess after device.exe is supposed to come from RunApps Launch values that this image does not contain. Those names / that hive belong with Julian’s 13,749,339-byte ExtraROM No restore. Stop. |
|
Julian pointed at https://github.com/julerobb1/Uverse. That tree is the real Hard Disk / ExtraROM dump. Inventoried in /tmp only. Not copied into this repo. No dump assets on this PR. etc.bin 13,749,339 bytes, ExtraROM XIP TOC includes ExtraROM FILESentry (28-byte) does have the client file:
Repo extract HKLM\init Launch is still not in ExtraROM. Zero UTF-16 NK So: ExtraROM is what makes Host still hunts a folder. Point Folder at a local clone of that Uverse tree ( |
|
Fetched https://github.com/julerobb1/Uverse for analysis only ( Who starts the client filesys RunApps
Prior boot: helper loaded dump/ drivers vs ExtraROM
No |
Live overlay sb $v1,-5496($0) dest 0xFFFFEA88 — dest-miss / never-wire skip. Never invent E000/F000/SUD. Continue dump-true. No jr hop 0x8003F78C. No MULT 0x8003F748. Do not hop PC to 0x8003F888. No MUL. Co-authored-by: Julian R <julerobb1@users.noreply.github.com>
…addiu sw Dump-true sw $ra,40($sp) at 0x8003F858 — dest-miss skip dest 0x9A023EA0. Leave $ra/$sp. NEVER write / invent 0x9A page. PC:=0x8003F85C. Never invent *0xFFFFDB58 / SUD / E000 / F000. No jr hop 0x8003F78C. No MULT 0x8003F748. After skip, cap leaves >=0x8003F85C. No MUL. Co-authored-by: Julian R <julerobb1@users.noreply.github.com>
Dump-true continue-skip sw $fp/$s7/$s6/$s5/$s4/$s3 at 0x8003F85C-0x8003F870 (dest $sp+16..36 0x9A02 miss). NEVER write / invent 0x9A page. Exec jal 0x80014F30 at 0x8003F874: $ra:=0x8003F87C; delay or $fp,$a0. PC:=0x80014F30 (I-fetch dump-true at callee; no invent dest pages). Keep EA88 / 9A / E000 dest-miss skip. No jr hop 0x8003F78C. No MULT 0x8003F748. After jal, cap leaves >=0x80014F30. No MUL. Co-authored-by: Julian R <julerobb1@users.noreply.github.com>
Dump-true lui/addiu/jr $t0 at 0x80014F30-0x80014F3C → 0x80014F40. Exec mtc0 $0,$12; nop; jr $ra ($ra=0x8003F87C) + nop. PC:=0x8003F87C. Dump-true trampoline hop, not stale-ra 0x8003F78C. Keep EA88 / 9A / E000 dest-miss skip. No invent KSEG / SUD / 0x9A. No MULT 0x8003F748. After trampoline, cap leaves >=0x8003F87C. No MUL. Co-authored-by: Julian R <julerobb1@users.noreply.github.com>
Dump-true lui/addiu at 0x8003F87C-0x8003F880 → $v0:=0x80340000 $s7:=0x8033FC78. lw $v1,0($s7) peek-or-zero (NO invent 0x8033 page). sltu $v0,$v1,$fp; bne + nop take/fall from ALU. PC:=0x8003F894 fall or 0x8003F8BC taken. Break 0x9FFFF/0x9A after-stk-sw recurse — cap leaves >= bne dest. Keep EA88 / E000 dest-miss skip. No invent SUD / 0x9A / 0x9F. No MULT 0x8003F748. No jr hop 0x8003F78C. No MUL. Co-authored-by: Julian R <julerobb1@users.noreply.github.com>
Dump-true first I-fetch after ret bne. Fall 0x8003F894 lui $v0,0x8034 — ALU $v0:=0x80340000; PC:=0x8003F898 observe. Taken 0x8003F8BC jal 0x80014F1C — delay peek 0/nop only (do not invent delay); $ra:=0x8003F8C4; PC:=0x80014F1C observe (do not invent callee word). Keep EA88 / 9A / E000 dest-miss skip. No hop 0x8003F888. No invent 0x8033 / SUD / 0x9A / 0x9F. No MULT 0x8003F748. No jr hop 0x8003F78C. After take, cap leaves >= 0x8003F898 or 0x80014F1C. No MUL. Co-authored-by: Julian R <julerobb1@users.noreply.github.com>
Dump-true whole-path FALL of fn 0x8003F854–0x8003F960 (VA 0x8003F800==file 0x2E85F). Live 17ec945: FIRST-WIN ret bne=0 to 0x8003F894 then after-stk-sw spam next=0x8003F894 ~2h. Map (what the fn does): INT-OFF via 14F30 hop+mtc0 Status:=0; compare avail *0x8033FC78 vs $fp; FALL ($fp=$a0=0) shrinks avail / bumps base *0x8033FC70; INT-ON via 14F1C (NOT a 14F30 lui/jr stub — lw *0xFFFFD890 / ori 1 / jr / mtc0 Status); b 0x8003F93C epi $v0:=$s5; restore; jr $ra. Taken alloc path 3F8BC–3F938 is dead this Boot. PC table remaining FALL: 3F894 lui $v0,0x8034 EXEC 3F898 addiu $v0,-912 → 0x8033FC70 EXEC 3F89C lw $s5,0($v0) peek-or-zero (NO invent 0x8033) 3F8A0 subu $v1,$v1,$fp EXEC 3F8A4 sw $v1,0($s7) dest-miss skip *8033FC78 3F8A8 addu $v1,$s5,$fp EXEC 3F8AC jal 0x80014F1C $ra:=3F8B4 3F8B0 sw $v1,0($v0) delay dest-miss skip 14F1C lw $t0,0xFFFFD890 zero (NO invent KData) 14F24 ori $t0,1; 14F28 jr $ra; 14F2C mtc0 $t0,$12 EXEC 3F8B4 b 0x8003F93C; 3F93C or $v0,$s5 3F940–958 lw 9A dest-miss skip; 3F95C jr $ra SKIP (no hop 3F8B4/3F78C) 3F960 addiu $sp,48 EXEC; leave 0x8003F964 Phantom: 9A/9FFFF/FFFFEA88/E000/FFFFDB58/SUD skip. Unbacked 8033/FFFFD890 zero/skip. Cap leave 3F964 breaks after-stk-sw 3F894 loop. Keep EA88/E000/9A skips. No MUL. No FILE[26]. No invent SUD/9A/9F/8033. Co-authored-by: Julian R <julerobb1@users.noreply.github.com>
Dump-true whole-path caller 0x8003F964–0x8003F9E4 (VA 0x8003F800==file 0x2E85F). Live 29a9913: FIRST-WIN FALL leave 0x8003F964 then 9A/99FF after-stk spam + TLBL at 0x800151A4 a0=0xBDFE5B4 ra=0x8003F998. Map: skip 9A phantom sw/lw; ALU v0:=20 + dump-true MULT 0x18 (NOT SPECIAL 0x16) + lui/addiu table 0x8032024C (NO invent 0x8032); delay a0:=s7+8 BEFORE list-pop 0x80015198; peek-or-zero empty v0=0; skip re-enter 0x8003F854 (FALL already logged); skip 9A epi restore; honor sane ra else leave 0x8003F9E8. Incr 0x80048174 only if fp!=0 (peek-or-zero / store-miss). Cap leave breaks after-stk-sw 3F964 loop. Keep EA88/E000/9A skips. No FILE[26]. No invent SUD/9A/99FF/8032. No hop 0x80048190 / 0x8003F78C / 0x8003F748. Co-authored-by: Julian R <julerobb1@users.noreply.github.com>
Dependabot alert #2 / GHSA-6c8g-7p36-r338. Patched floor is 0.48.0; pin 0.50.4 stable. archive/ArchiveExtractor.cs stays parked behind Compile Remove; Open → OpenArchive so WriteToDirectory / ExtractionOptions still compile on 0.50.x. No FILE[26]. ExtraROM fat caller take unchanged. Co-authored-by: Julian R <julerobb1@users.noreply.github.com>
Dump-true addiu $sp,$sp,-24 at 0x8003F9E8 (named 0x27BDFFE8). ALU $sp:=$sp-24. $sp may stay 0x9A (ALU only; do not invent 0x9A page). PC:=0x8003F9EC observe (do not invent next word). Keep EA88 / 9A / E000 dest-miss skip. No hop 0x8003F888. No invent 0x8032 / SUD / 0x9F. No MULT 0x8003F748. No jr hop 0x8003F78C. No hop 0x80048190. After addiu, cap leaves >=0x8003F9EC. No MUL. Co-authored-by: Julian R <julerobb1@users.noreply.github.com>
Guard null bus/regs before BeginDdiNopDecompStoreWatch, TryMeasureDdiNopDestAfterDecomp, and TryServeDdiNopAtDecompRet. Observe/measure/serve logic unchanged when arguments are live. No CS8604 in NoWarn. No FILE[26]. Co-authored-by: Julian R <julerobb1@users.noreply.github.com>
Boot 90d6470 FIRST-WIN fat caller left at twin 0x8003F9E8 instead of jr $ra. Live ra 0x8003F8B4 is dump-true FALL jal-link (b 0x8003F93C). Stop treating it as insane leave. After delay addiu $sp,+32, honor sane 0x800xxxxx ra; cap after-stk / NextFn yank to that ra. Do not fall through into twin jal 0x800151C0 (TLBS 0x800151D0 sw v0,0(a1) a1=0). Keep CS8604 / SharpCompress / caller-next. No invent 0x8032 / 0x9A / 0x99FF / SUD. No hop 0x80048190 / 0x8003F78C. No MUL 0x16. No FILE[26]. Co-authored-by: Julian R <julerobb1@users.noreply.github.com>
Dump-true honored jr $ra land 0x8003F8B4 (b 0x8003F93C / 0x10000021). Exec beq $0,$0; delay peek 0/nop only; or $v0,$s5 at 0x8003F93C. PC:=0x8003F940 observe (do not invent 9A epi lw). Keep EA88 / 9A / E000 dest-miss skip. No hop 0x8003F888. No invent 0x8032 / SUD / 0x9F. No MULT 0x8003F748. No jr hop 0x8003F78C. No hop 0x80048190. After b/or, cap leaves >=0x8003F940. No MUL. Co-authored-by: Julian R <julerobb1@users.noreply.github.com>
Boot 2412828 FIRST-WIN honored ra 0x8003F8B4 then STALL on beq. Fat dump-true: b 0x8003F93C + nop; or $v0,$s5; skip 9A epi lw 3F940-3F958; jr $ra + delay addiu $sp,+48. Honor saved outer link ~0x8003F78C (3F854 entry from 3F84C fall), not loop 3F8B4 / twin 3F9E8. Cap after-stk at outer. Keep CS8604 / jr-ra honor. No invent 0x9A / 0x99FF / SUD / 0x8032. No hop 0x80048190 / MULT 0x8003F748. No MUL 0x16. No FILE[26]. Co-authored-by: Julian R <julerobb1@users.noreply.github.com>
Dump-true lhu $v0,0($s7) at the honored-ra epi return 0x8003F78C. Peek *$s7 only; dest-miss skips the $v0 ALU. Leave at 0x8003F798. Co-authored-by: Julian R <julerobb1@users.noreply.github.com>
Replace the bottom WinForms Label with a read-only single-line TextBox so Julian can select Hive lines and Ctrl+C. Display up to 400 chars; double-click and context-menu Copy put the full status string on the clipboard. Keep Dock=Bottom, Height 24, BeginInvoke ShowStatus. Thin Win7 host only. ExtraROM fat path unchanged. Co-authored-by: Julian R <julerobb1@users.noreply.github.com>
Dump-true lw $v0,0($s3) at 0x8003F798 after epi-ret lhu. Peek *$s3 only; dest-miss leaves $v0. Leave at 0x8003F79C. No invent 0x8033 / MULT hop. Co-authored-by: Julian R <julerobb1@users.noreply.github.com>
Dump-true addiu $t1,$0,4 at 0x8003F79C after epi-ret lw. Exec ALU rs=$0. Leave at 0x8003F7A0. Do not take the bne or hop MULT 0x8003F748. Co-authored-by: Julian R <julerobb1@users.noreply.github.com>
Dump-true bne $s4,$t1 at 0x8003F7A0 after addiu $t1,$0,4. Live compare; delay nop skip. Leave fall 0x8003F7A8 or taken 0x8003F7AC. No MULT hop. Co-authored-by: Julian R <julerobb1@users.noreply.github.com>
Boot 8cae3af: RetCallerRa required peek == invented 8FBE0010..8FBF0028 and aborted before Hive. Skip dump-true epi loads; leave ~0x8003F78C. One-shot refuse log. Keep RaLhu / status-bar copy. Co-authored-by: Julian R <julerobb1@users.noreply.github.com>
nk B000FF rec 0x80011000 peeks at 3F8B4/3F93C/3F940..3F960 match. Boot 8cae3af silent false was first-take inDelay / HonoredRaLeave, not the encode map. Take honored 3F8B4 even in a delay slot; force leave ~0x8003F78C. Keep RaLhu. No further hops. Co-authored-by: Julian R <julerobb1@users.noreply.github.com>
Boot 07cb2b3 froze on the bad-a Hive line; 8cae3af continued to e000-0288 at 0x800151D0. ProgressLeave yank to 3F78C+ and e000 kseg/busy silent false aborted that next. Dump-true jal 0x80042920 continue; dest-miss e000 skip after restore; keep RetCallerRa inDelay once e000 logs. Co-authored-by: Julian R <julerobb1@users.noreply.github.com>
Boot 8f64660 hopped jal-continue into 0x80042920 then froze (e000=0). Dump-true walk that WCHAR callee (skip dest-miss 9A/8032; skip helper jal / 0x800423F0) and resume leftover list-insert sw at 0x800151D0 so Hive logs e000-0288 like 8cae3af. Keep ProgressLeave refuse until e000; keep RetCallerRa inDelay once e000 logs. No invent E000/F000/SUD/9A. Co-authored-by: Julian R <julerobb1@users.noreply.github.com>
…inue Delete after-stk ProgressLeave yank to 0x8003F8B4 (Julian/Gemini reject that fake leave). ProgressLeave never returns 3F8B4; Na02 recurse cap no longer ORs fat FALL; PastJalRa refuses 3F8B4 / 3F78C on toxic SP. Keep unbacked load skips. Dump-true outer epi jr $ra JUMP sane caller (not 3F7FC / 3F8B4). Restore ROMHDR enter 0x8001728C: exec addiu, skip unbacked prologue sw, honor empty *0x803429C8 beq → 0x8001732C. No invent ROMChain / 9A / 9F / E000 / F000 / SUD. Co-authored-by: Julian R <julerobb1@users.noreply.github.com>
RamDevice stays 2 GiB from phys 0. 0x80000000+RamSize-0x1000 overflows uint at 2 GiB and exceeds the 512 MiB KSEG0 window, so SP uses min(RamSize, 0x20000000) and stays 0x9FFFF000. Long alloc + very-large objects so the 2 GiB byte[] is not a negative int. No new maps. Co-authored-by: Julian R <julerobb1@users.noreply.github.com>
c768b57 used RamSize=2GiB (2147483648). .NET array length is int; int.MaxValue is 2147483647, so new byte[] threw and Start's empty catch wrote Stopped with WS still ~66MB. 2047 MiB fits. Keep KSEG0 SP cap at 0x9FFFF000. Log Start exceptions so OOM is not silent. Co-authored-by: Julian R <julerobb1@users.noreply.github.com>
Julian: 2 GiB / 2047 MiB alloc still blocked Start. Restore the original 256 MiB RamDevice and SP 0x8FFFF000. Drop the kseg0Ram workaround and very-large-objects plumbing. Keep Start: <type>: <message> so the next failure is not silent. Leave/ROMHDR dump-true from 07f8a9a stays. Co-authored-by: Julian R <julerobb1@users.noreply.github.com>
Boot 0e9d76d reached dump sw $v0,0($a1) at 0x800151D0 with a1=0xC0002BC8 before nest-1670 armed the C000 dest-miss skip. Arm skip from leftover entry or that EPC; I-fetch Take skips the unbacked store and continues 0x800151D4. Log e000-0288 when dest is E000, else c000-store-skip. No invent C000/E000/ F000/SUD/9A. No hop 0x8003F8B4. RamSize stays 256 MiB. Co-authored-by: Julian R <julerobb1@users.noreply.github.com>
Boot c3e1614 skipped C000 dest-miss (unique dests C000→C005; climb, not a same-VA spin) then stalled at dump sw $v0,0($a1) epc=0x800151D0 bad=0x14E88. Extend low-useg dest-miss skip from 0xFFFF to 0x1FFFF so 0x14E88 continues at 0x800151D4. No invent useg/E000/F000/SUD/9A. No hop 0x8003F8B4. RamSize stays 256 MiB. Co-authored-by: Julian R <julerobb1@users.noreply.github.com>
Boot a654026 skipped 0x14E88 then stalled at the same dump sw $v0,0($a1) with a1=0x25068. Stop range bumps. At 0x800151D0, dest-miss skip any unbacked $a1 (refuse leftover/GetProc/fp50), PC:=0x800151D4, log once per dest class. E000 dest still logs e000-0288. Cap C000 Hive to one class line; skip stays. No invent pages. No hop 0x8003F8B4. RamSize stays 256 MiB. Co-authored-by: Julian R <julerobb1@users.noreply.github.com>
Status
CI green. Parked on
037e309. Windows 34409387523, Dev Build 34409387531, NuGet 34409391197. Display staysddi_nop.dll. FILE[26] unchanged. Do not leftover hop. Do not invent dest. Do not Boot4a2c700(CS0103). QA on DESKTOP-PGN06F7 / Uverse Drive E. Windows zip from CI:ProcessorEmulator-windows/ProcessorEmulator-pr.zip.Boot
a654026(partial win)Past
0x14E88(lowuseg-14e88 store-skip×7, also 14ED8…15BE0). Start OK, WS~533MB, Hive=115. Still no e000-0288 / abs-15c28 / leave. Then:coredll.dll … epc=0x800151D0 bad=0x25068 via=exn-tlbsSame list-insert
sw $v0,0($a1). Range bumps (1000→FFFF→1FFFF→25068) are the wrong shape.Fix (
037e309) — one dest-miss rule at0x800151D0Dump-true: dump-match
sw $v0,0($a1); if$a1cannot peek, skip store;PC := 0x800151D4. Log once per dest class (kuseg/c000/e000/ …). Refuse leftover hop dest / GetProc /0x80086E5C/ fp50. Class helpers still loge000-0288when dest is E000. Did not poke$a1toFFFFE288(that invents the 8cae3af dest). C000 Hive storm capped to one class line; skip still runs. No invent pages. No hop0x8003F8B4. RamSize stays 256 MiB.Boot
c3e1614(partial win)Start OK, WS~508MB, Hive=108.
bad=0xC0002BC8is nowvia=c000-store-skip×40 unique dests C000→C005 — dest progress, not a same-VA spin. Then list-insert TLBSbad=0x14E88.Fix (
a654026)Extended low-useg dest-miss skip to
0x1000–0x1FFFF(last range bump). Superseded by037e309.Boot
0e9d76d(Start FIXED — then C000 TLBS)Start works at 256 MiB. Log ~47KB, 68 Hive, ROMHDR=7. Path reached LoadO32-ret + leftover-wait99-o32-nk-chain / coredll-page maps, then list-insert TLBS
bad=0xC0002BC8.Fix (
c3e1614)Arm C000/E000/F000/page0/lowuseg store-skips from leftover entry or I-fetch/EPC
0x800151D0. Take dest-miss skip;PC := 0x800151D4.MapC0000088Vastill requires leftover+stk1670. RamSize stays 256 MiB.Boot
c768b57/e9ece3d(Start blocker)Start click did nothing: Hive
loadingthen immediatelyStopped. Exact 2 GiB overflowedint.MaxValue; 2047 MiB still did not Start for Julian. Removed the large alloc entirely.Fix (
0e9d76d)RamSize = 256u * 1024u * 1024uagain. SP is0x80000000u + RamSize - 0x1000u(0x8FFFF000). Start catch still logsStart: <type>: <message>. Leave/ROMHDR dump-true from07f8a9astays. Do not keep 2047 MiB.Boot
75fab53(regressed)Hung at ROMHDR enter with only 3 Hive lines. Compare
8cae3af: got past ROMHDR into e000 / abs-15c28.Julian also rejects the fake leave:
after-stk-sw next=0x8003F8B4 sp=0x9FFFFF08 cap=1 via=dump-mem-15c28-after-stk-swFix (
07f8a9a) — Gemini dump-true leaveGates removed
PC → 0x8003F8B4DumpMem15C28OuterJalProgressLeave()never returns0x8003F8B4jr $raat0x8003F7F4JUMP sane caller — not hop0x8003F7FC/0x8003F8B4Kept
0x8003F78C→0x8003F7EC0x80042920→ list-insert0x800151D0ROMHDR early path
Dump-true continue at enter
0x8001728C: execaddiu $sp,-248; skip unbacked prologuesw; peek*0x803429C8(0 → empty); honorbeq→0x8001732C.Success: Hive shows
ROMHDR continuethen later a clean outer epi JUMP to a sane caller — notafter-stk-sw next=0x8003F8B4 sp=0x9FFFFF08.Next Boot
%TEMP%\ProcessorEmulator-extrarom\boot-sha.ps1 -Sha 037e309Start must stay
running(256 MiB). Hive should loglist-insert dest-miss class=kuseg bad=0x25068once instead ofexn-tlbs. Then e000-0288 / abs-15c28 / leave ~0x8003F78C. Do not treatafter-stk-sw next=0x8003F8B4as the leave.Commits
8cae3afCI green fat FALL epi; did continue past ROMHDR and bad-a75fab53CI green dump-true callee continue; Boot hung at ROMHDR enter07f8a9aCI green Gemini dump-true leave (delete 3F8B4 yank) + ROMHDR continuec768b57CI green ~2 GiB guest RAM; Start threw — silent Stoppede9ece3dCI green 2047 MiB RAM; Start still failed for Julian0e9d76dCI green revert guest RAM to 256 MiB; Start FIXED; leftover-chain then list-insert TLBSbad=0xC0002BC8c3e1614CI green dest-miss skip at0xC0002BC8; Boot C000 climb then TLBSbad=0x14E88a654026CI green low-useg skip to0x1FFFF; Boot past 14E88 then TLBSbad=0x25068037e309CI green one dest-miss rule at0x800151D0(any unbacked$a1; once per class)Artifacts
/opt/cursor/artifacts/3f854_fall_path_map.txt/opt/cursor/artifacts/3f964_caller_path_map.txt/opt/cursor/artifacts/07f8a9a_dump_true_leave_gates.txt/opt/cursor/artifacts/e9ece3d_start_ram_int_max.txt/opt/cursor/artifacts/c3e1614_list_insert_tlbs.txt/opt/cursor/artifacts/c3e1614_14e88_lowuseg.txt/opt/cursor/artifacts/a654026_list_insert_any_dest_miss.txt