Field report (night 3): "two ammo bay fires and no death" (Cyd + RajelAran; one
purged, one left burning). Root cause = THREE independent kill-switches stacked
on the same path, all in ammobin.cpp:
1. `GameClock::Now() { return 0; }` -- `cookOffTime < Now()` was `0 < 0`, so
an ARMED bay fire never detonated.
2. `InjectHeat(void*) {}` -- the detonation body was a no-op.
3. The bin's Damage record was never stamped -- 0 damage of type 0 (which the
mech TakeDamage handler drops) even if 1+2 had fired.
THE FUSE (raw disasm, scratchpad/disammo.py): the old "RandomDelay" was a Ghidra
carve artifact -- FUN_004dcd94 is __ftol and the export DROPPED the caller's x87
expression. The real bytes @004bd450: fld 10.0 / fmul [ticksPerSecond] /
fadd 0.5 / __ftol -- a FIXED 10.0-SECOND fuse in clock ticks. New gotcha #19
(reconstruction-gotchas.md) documents the __ftol export blind spot.
THE DAMAGE RECORD: bin+0x1F0..0x21C is a real engine `Damage` (FUN_0041db7c IS
Damage::Damage(), byte-matched to T0 DAMAGE.cpp). The linked ProjectileWeapon's
ctor @004bc3fc stamps it from weapon->damageData @0x3A8 via
owner->roster[0x128][res+0x1C0] -- projweap.cpp's old comment called this "the
bin's HUD display block ... wired in the AmmoBin family"; both halves were wrong
and it was wired nowhere. Now stamped (before MissileLauncher's ctor divides by
missileCount -- a missile bin authentically holds the per-SALVO amount).
THE DETONATION (@004ac274 = MechSubsystem::DistributeCriticalHit -- the old
"HeatableSubsystem::InjectHeat" label was wrong, and the old reconstruction
iterated a stand-in CriticalChain whose First()/Next() returned 0):
statusAlarm pulse Exploding(2)->Destroyed(1) (slot 13 = the printSimulationState
state PRINT @004ac8c0, not an "explosion notify"), own private zone pinned
destroyed, then collect the mech DamageZones whose crit entries plug the bin
(the binary filters plug classID 0x4E = DamageZoneClassID -- VDATA.h idx 78,
cross-checked via idx 28 = AudioStateTrigger), split the amount evenly, and send
the OWNER one full Entity::TakeDamageMessage per zone: inflictingEntity = SELF,
damageZone = the zone index, inflictingSubsystemID = the bin (the message-
manager explosion-bundling key, ENTITY3.h's own NOTE), printing the binary's
exact "ammo explosion damaging <zoneName>" @0050df61.
Port shape: Mech::AmmoExplosionFanOut (mechdmg.cpp) behind a databinding bridge;
guarded deviation: zoneCount==0 warns instead of the binary's unguarded divide.
CriticalChain/CriticalEntry stand-ins DELETED from mechrecon.hpp.
VERIFIED LIVE (BT_BAYTEST hook = message 1, the crit-induced arm channel):
scratchpad/baytest.py : arm -> 10s -> "20 rounds x 35 = 700 (type 2)" ->
"ammo explosion damaging dz_ltorso" -> zone cascade -> mech DESTROYED
(authentic death list).
scratchpad/baypurge.py: arm -> eject-hold purge -> "bay fire EXTINGUISHED
(bin empty)", no detonation.
scratchpad/sim3.py : the HEAT route arms organically in combat (overheated
AFC100), detonates "11 x 25 = 275 (type 1)" split across dz_larm + dz_lgun.
BAYBOOM matchlog record added for MP field forensics.
FIX-OF-THE-FIX (caught by the sim3 regression, would have shipped a crash):
MechSubsystem's ReconDamageZone proxy puts structureLevel at OFFSET 0 -- which
ALIASES THE REAL DamageZone's VTABLE POINTER (the private zone is `new
DamageZone`, mechsub.cpp:154; mechsub.hpp:260 documents the alias). My first
DistributeCriticalHit kept the old body's `damageZone->structureLevel = 1.0f`
and OVERWROTE THE ZONE'S VPTR with 0x3F800000; the respawn sweep's virtual
SetGraphicState (vtable+0xC) then called through it -> AV at 0x3f80000c in
RespawnRepair, one frame after a bay-fire death. ALL EIGHT proxy-view sites in
mechsub.cpp swept to the engine view (((DamageZone*)damageZone)->damageLevel
@0x158) -- including two silently-wrong LIVE readers: GetStatusFlags (vptr as
float -> always "intact") and ApplyDamageAndMeasure (the crit cascade's
measure). Ruled out first by evidence: the weapon->bin stamps were all clean
(six stamps, all classID 0xbcb, logged).
#47 (half 1 -- the FIRE ICON): BallisticWeaponCluster::Execute @004c9a38 reads
bin+0x18C = cookOffArmed into the btefire.pcc TwoState, and while armed computes
(Now - cookOffTime)/ticksPerSecond -- the COOK-OFF COUNTDOWN -- into the numeric
beside it. The old reconstruction misread 0x18C as "the reload state" and
bridged the icon to BTAmmoBinFeeding, so it blinked on every feed and never lit
on a bay fire (RajelAran: "it doesn't"). Now driven by the
BTAmmoBinCookOffArmed/CookOffTime complete-type bridges. [T2 -- the data path
is rig-verified; the pixels await the next live session.]
#47 (half 2 -- the ENG-BUTTON FLASH): fully mapped, deliberately NOT built this
session. The authored data SHIPS (BTL4.RES carries exactly one type-31
GaugeAlarmStream); the chain is alarm SetLevel -> gauge-watcher socket ->
Renderer msg 7 -> GaugeAlarmManager::Activate @00448d00 (T0) -> the BTL4
override @004cc148..@004cc2fc (btl4galm.cpp's provenance note claiming "no
override body exists" is WRONG -- corrected in-file) -> LampManager::FindLamp
@00444c80 -> Lamp::SetAlertState @00444e64 (flash counter) -> the L4 flush
@00474e94 emitting flashFast states 0x37/0x13 (== T0 L4LAMP.cpp:234-239).
Missing: the override bodies, the gauge-watcher sender, the aux-button lamps.
3-piece plan in context/open-questions.md.
Also logged: HandleMessage is vtable slot 8/9 in the binary but NON-virtual
across 10 reconstruction classes (bit the BT_BAYTEST hook; typed call used, gap
documented in open-questions).
KB: combat-damage.md (the full cook-off section), decomp-reference.md (the
cluster addresses + the GaugeAlarm/lamp map + BT_BAYTEST env), gauges-hud.md
(the fire-icon correction), reconstruction-gotchas.md #19 (__ftol),
open-questions.md (2 entries), btl4galm.cpp provenance correction.
checkctx CLEAN. 40 LNK2019 unchanged (the two pre-existing families).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
99 lines
3.5 KiB
Python
99 lines
3.5 KiB
Python
"""Gitea #46 -- verify the ammo bay fire detonates and applies real damage.
|
|
|
|
Before this fix, three stacked defects made an armed bay fire permanently inert:
|
|
the clock stub (`0 < 0` never fired), the InjectHeat no-op (nothing applied),
|
|
and the never-stamped Damage record (0 damage of type 0 even if it had).
|
|
|
|
Rig: BT_BAYTEST=<frame> sends message 1 (the crit-induced "begin cook-off
|
|
countdown", @004bdb94) to the first AmmoBin. The authentic fuse is a FIXED
|
|
10.0 seconds (raw disasm @004bd450: 10.0 x ticksPerSecond + 0.5, __ftol --
|
|
the old "RandomDelay" was a Ghidra artifact).
|
|
|
|
PASS =
|
|
[ammo] ... BAY FIRE (message): cook-off armed, N rounds, detonation in 10s
|
|
...~10 wall seconds later...
|
|
[ammo] ... BAY FIRE DETONATION: N rounds x D = total (type T)
|
|
ammo explosion damaging <zoneName> (the binary's exact @0050df61 print)
|
|
...and the mech takes real zone damage (BT_MP_NET handler line / DAMAGE state).
|
|
|
|
Kills only the PID it spawns.
|
|
"""
|
|
import os
|
|
import re
|
|
import subprocess
|
|
import sys
|
|
import time
|
|
|
|
REPO = r"C:\git\bt411"
|
|
LOG = os.path.join(REPO, "scratchpad_baypurge.log")
|
|
if os.path.exists(LOG):
|
|
os.remove(LOG)
|
|
|
|
env = dict(os.environ)
|
|
env.update({
|
|
"BT_START_INSIDE": "1",
|
|
"BT_DEV_GAUGES": "1",
|
|
"BT_BAYTEST": "400",
|
|
"BT_EJECTTEST": "hold", # dump the bay ~13s in -- inside the 10s fuse window if arming is late,
|
|
# after it if early; PASS here = EXTINGUISHED, no detonation # arm at sim frame 400
|
|
"BT_AMMO_LOG": "1",
|
|
"BT_MP_NET": "1", # [mp-hdlr] TakeDamageHandler lines (zone + amount)
|
|
"BT_DEATH_LOG": "1", # crit cascade / zone destruction
|
|
"BT_LOG": LOG,
|
|
})
|
|
proc = subprocess.Popen(
|
|
[os.path.join(REPO, "build", "Release", "btl4.exe"), "-egg", "LAST.EGG"],
|
|
cwd=os.path.join(REPO, "content"), env=env,
|
|
stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL)
|
|
print("pid", proc.pid)
|
|
|
|
try:
|
|
deadline = time.time() + 240
|
|
armed = False
|
|
while time.time() < deadline:
|
|
if os.path.exists(LOG):
|
|
t = open(LOG, errors="replace").read()
|
|
if "BAY FIRE (message)" in t:
|
|
armed = True
|
|
break
|
|
time.sleep(2)
|
|
if not armed:
|
|
print("FAIL: never armed")
|
|
# wait through the 10s fuse + margin for the fan-out and damage
|
|
time.sleep(25)
|
|
finally:
|
|
proc.terminate()
|
|
time.sleep(1)
|
|
|
|
t = open(LOG, errors="replace").read() if os.path.exists(LOG) else ""
|
|
arm = re.findall(r"^\[ammo\].*BAY FIRE.*armed.*$", t, re.M)
|
|
boom = re.findall(r"^\[ammo\].*DETONATION.*$", t, re.M)
|
|
zones = re.findall(r"^ammo explosion damaging.*$", t, re.M)
|
|
hdlr = re.findall(r"^\[mp-hdlr\] TakeDamageHandler.*$", t, re.M)
|
|
dfx = re.findall(r"^\[deathfx\].*$", t, re.M)
|
|
ext = re.findall(r"^\[ammo\].*EXTINGUISHED.*$", t, re.M)
|
|
|
|
print("\n=============== RESULT ===============")
|
|
print("armed:", len(arm))
|
|
for l in arm[:2]:
|
|
print(" ", l[:120])
|
|
print("\ndetonation:", len(boom))
|
|
for l in boom[:2]:
|
|
print(" ", l[:130])
|
|
print("\n'ammo explosion damaging' zone prints:", len(zones))
|
|
for l in zones[:6]:
|
|
print(" ", l[:100])
|
|
print("\nTakeDamage handler runs:", len(hdlr))
|
|
for l in hdlr[:4]:
|
|
print(" ", l[:150])
|
|
print("\n[deathfx] zone/crit lines:", len(dfx))
|
|
for l in dfx[:8]:
|
|
print(" ", l[:120])
|
|
if ext:
|
|
print("\nextinguished (unexpected in this rig):", ext[:2])
|
|
|
|
ok = arm and ext and not boom
|
|
print("\nVERDICT:", "PASS -- bay fire armed, PURGE extinguished it, no detonation"
|
|
if ok else "FAIL -- see which stage is missing above")
|
|
sys.exit(0 if ok else 2)
|