Skip to content

Source recovery references

Function and data recovery is recorded by native address. The old aggregate naming notebook duplicated format, struct and behavior pages and retained superseded hypotheses. Its unique observations are preserved in the historical notebook; it is not a maintained reference or a backlog.

Resolve current evidence

just analysis-function creature_handle_death
uv run crimson match status
  • analysis/ghidra/maps/name_map.json and analysis/ghidra/maps/data_map.json record canonical names, signatures and data labels.
  • analysis/annotations/functions.json retains address-keyed recovery notes.
  • tools/match/STATUS.md reports matching results; each scratch's configuration identifies its source, including bodies moved into tools/native/recovered/.
  • Binary analysis describes current source/view lookup.
  • Native linking distinguishes recovered code, library providers, linkability and byte-match evidence.

Behavior and layout references

Keep new findings in the owning reference page after verification. A recovered name is not by itself proof of behavior; retain instruction addresses, capture provenance and remaining uncertainty where they affect the conclusion.