Files
TeslaRel410/restoration
CydandClaude Fable 5 e97862507c BT410 5.3.74: the faulting instruction decoded -- a handler-chain walk with a bad node
The SegPhys-corrected dump read real code at last (the earlier zeros were the
probe reading EIP as a bare linear address; CS=00FF has a base):

    66D4  push 0 / push edi / push ebx / push esi
    66D9  call dword near [ebx+4]     <- faults
    66DC  cmp eax,0 / jz done
    66E5  mov ebx,[ebx] / jmp loop

A linked-list walk with a per-node callback -- node = {next@+0, handler@+4},
four args, "handled" on nonzero.  A DPMI exception/interrupt handler chain.

The arithmetic closes exactly: the read is DS_base + ebx + 4, and
7000FA64 - F000CA64 = 80003000, so DS base is 0x80003000 and the famous cr2
is that wrap.  My earlier '[EBX+0x3004]' reading was fabricated from the cr2
alone -- there is no 0x3004 displacement, which is why the constant appeared
in no binary.

So: a chain node's NEXT pointer holds F000CA60, the value parked in unhooked
IVT slots -- the walk expected a terminator and got an interrupt vector, then
read its +4 as a function pointer.  Identical registers on every catch, so
one deterministic path, entered often enough that our 60s load window catches
it 25-40% of the time while shipped's 15s window mostly does not.

Open: which routine owns the chain, and where the bogus next came from.  The
probe now walks the EBP frame chain to name the caller.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-29 18:34:22 -05:00
..

Scene Restorations

Modern re-renderings of the Division dVS scenes recovered from the Glaze developer drive (see HISTORY.md) and this repo's CONTENT tree. The originals ran on Division Ltd.'s pixel-pipeline hardware in 19941997; these tools parse the original data files and re-render them in WebGL, in the browser.

Viewers (open in any browser, fully self-contained)

  • vwe-archive.html — the Scene Archive: 26 curated scenes across all projects — Star Trek (Enterprise-D, Klingon flyby), Hull Pressure (sea demos, fish schools, sunken temple), BattleTech (polar map with mech lineup, Ravine and desert maps, stadium), Red Planet (Blade arena, the Mars canal milestone demo), and the Canyon/Maya-temple Division demos. Fly camera: drag to look, WASD to fly, R resets.
  • trek-scn.html — the original standalone Star Trek restoration (TREK.SCN and KLNGVID.SCN).

Toolkit

  • divformats.py — parsers for every Division format found on the drive: text VGF/VMF (DIV-VIZ2 geometry/materials, both the 1995 VERSION 2:07 and 1996 02:05 dialects, with header SCALE support), binary BGF/BMF (DIV-BIZ2) — the binary block-stream layout was recovered from Division's own reader source (DPL3/BIZREAD.C, 1994), including all 14 vertex layouts, pmesh/tristrip/polygon connectivity, LOD blocks (newer writers nest patches inside LODs; the largest LOD is taken), and embedded materials/textures/ramps — plus TGA and raw SVT textures, SPL splines, and SCN scene scripts.
  • audit.py — scans every .SCN on the drive and reports what fraction of its geometry survives, and in which format.
  • extract_all.py — extracts every scene with ≥60 % of its geometry recoverable (108 of 241 on the drive; the rest reference lost models) into allscenes.json, resolving models/materials/textures across the drive and this repo's CONTENT dirs.
  • gallery_build.py — curates scenes from allscenes.json into the self-contained vwe-archive.html (via gallery_template.html).
  • convert.py / viewer_template.html — the original single-scene Star Trek pipeline.

Rebuild

python extract_all.py     # requires the sda4/ drive dump beside this repo
python gallery_build.py

Fidelity notes

Faithful: vertices, triangles, material colors and shading ramps, textures, fog and light parameters, spline motion, camera start positions. Approximated: Division's rasterizer behavior, point sizes, timing (originals ran at 30 Hz). Not simulated: event-driven SPECIALFX particles. A few dev scenes had camera start positions inside geometry; those get overridden or auto-framed cameras (see START_OVERRIDE in gallery_build.py). Scenes missing one or more models from the drive say so in their header.