Every conclusion that named EulerAngles::operator=(const LinearMatrix&) as the
fault site was wrong, including the disassembly built on top of it. Three
independent proofs:
1. ROTATION.CPP is ours, so the function was instrumented directly -- print
this, &matrix and a local's address on the first twelve calls plus any wild
pointer. The run faulted with ZERO [euler] lines: never called.
2. After the probe was added, 0x66D9 disassembles to a two-byte conditional
jump (jnl) that touches no memory. The dump reports ErrCode 0004, a data
READ.
3. EIP 0x66D9 and cr2 0x7000FA64 are identical to the byte across every build
this session, including builds where the code at that offset changed
completely. A fault in our CODE segment moves when the code moves. This
one does not -- it lives in the DPMI host, which loads low and never gets
relinked.
The map lookup was a coincidence: our _TEXT is section-relative from 0, so its
offsets overlap the host's low addresses, and the map will name a function for
any small number. Before resolving a fault address against the map, confirm it
belongs to our segment -- cheapest check is whether it moves on relink.
What is actually true, by same-binary A/B:
vRIO DOWN, serial1 still a namedpipe -> mission LAUNCHES
vRIO UP, same conf, same binary -> FAULT
The trigger is a LIVE RIO stream, not an unplugged cable. The emulator reports
continuous serial1 RX overruns, the fault lands wherever the app happened to be
(terrain one run, the mech's inside view another), and the shipped binary
survives the identical conditions. A fault at a fixed host address, at
arbitrary points in the app, requiring an interrupt-driven stream, is an
interrupt re-entrancy signature rather than a wild pointer.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
75 lines
2.4 KiB
Plaintext
75 lines
2.4 KiB
Plaintext
[sdl]
|
|
output=opengl
|
|
# higher,higher not highest: HIGH_PRIORITY_CLASS starved the host desktop;
|
|
# with the retry patches a rare dropout self-recovers (see gauge_rio.conf).
|
|
priority=higher,higher
|
|
[dosbox]
|
|
memsize=32
|
|
machine=svga_s3
|
|
[cpu]
|
|
core=dynamic
|
|
cputype=pentium
|
|
cycles=max
|
|
[sblaster]
|
|
sbtype=sb16
|
|
sbbase=220
|
|
irq=5
|
|
dma=1
|
|
hdma=5
|
|
[mixer]
|
|
# match the EMU8000s' native rate (no resample) and buffer ~60ms so brief
|
|
# emulation-thread stalls (RIO retry recovery) don't audibly chop
|
|
rate=44100
|
|
blocksize=1024
|
|
prebuffer=60
|
|
[serial]
|
|
# RIO on COM1 with the low-latency options (rxpollus/rxburst) so the board's
|
|
# few-ms ACK deadline is met; plasma display on COM2 (real pod has both).
|
|
# VWE fork namedpipe backend (com0com/realport retired -- COM1/COM2 gone):
|
|
# DOSBox = pipe client (retry), vRIO/vPLASMA apps = servers; an unconnected
|
|
# pipe behaves as an unplugged cable so the mission still runs. serialnamedpipe.h
|
|
serial1=namedpipe pipe:vrio rxpollus:100 rxburst:16
|
|
serial2=namedpipe pipe:vplasma
|
|
# live UNBUFFERED game output: DOS char devices are not buffered, so
|
|
# redirecting stdout to COM3 lands every line immediately. A normal
|
|
# '> file' redirect stays 0 bytes until the process exits, which hides
|
|
# all progress on a run that does NOT crash.
|
|
serial3=file file:C:\VWE\TeslaRel410\emulator\render-bridge\podlog.txt
|
|
[autoexec]
|
|
mount c "C:\VWE\TeslaRel410\ALPHA_1"
|
|
c:
|
|
cd \REL410\BT
|
|
set VIDEOFORMAT=svga
|
|
rem production pod card init (PARAMETR.BAT:181-186): DIAGNOSE + AWEUTIL per
|
|
rem card -- AWEUTIL /S does the EMU8000 bring-up and DRAM detect the HMI SOS
|
|
rem driver relies on; skipping it left the cards uninitialized (silent).
|
|
rem aweutil /s SKIPPED for now: it verifies the AWE32 GM ROM, which the
|
|
rem emulated cards lack (hangs in a retry loop) -- restore once the ROM is
|
|
rem dumped from a real card. diagnose /s kept (passes, sets mixer config).
|
|
set BLASTER=A220 I5 D1 H5 P330 T6
|
|
c:\sb16\diagnose /s
|
|
set BLASTER=A240 I7 D3 H6 P300 T6
|
|
c:\sb16\diagnose /s
|
|
set BLASTER=A220 I5 D1 H5 P330 T6
|
|
set TEMP=c:\
|
|
rem arena1 city mission (TESTARN.EGG: map=arena1, time=day) with the RIO
|
|
rem attached; stdout redirected so mission-load progress survives kills.
|
|
set BT_MECH_LOG=1
|
|
set BT_LAUNCH_LOG=1
|
|
set BT_STACK_LOG=1
|
|
set BT_MER_LOG=1
|
|
set BT_EULER_LOG=1
|
|
set BT_FORCE_THROTTLE=0.6
|
|
set BT_FORCE_TURN=0.25
|
|
set HEAPSIZE=15000000
|
|
set L4GAUGE=640x480x16
|
|
call setenv.bat r s n p
|
|
32rtm.exe -x
|
|
BTL4REC.EXE -egg testarn.egg > COM3
|
|
|
|
echo GAME-RC=%errorlevel% >> RC.TXT
|
|
32rtm.exe -u
|
|
echo ALPHA1-RUN-DONE
|
|
pause
|
|
|