Reverse-engineering notes
One file per guest binary we have dug into, holding the facts that are expensive to re-derive and cheap to write down: module load bases, container/asset layout, which Win32 or COM paths the app actually uses, the function addresses we have already disassembled, and the hypotheses that have been ruled out.
These notes exist because the same disassembly keeps getting redone. Before starting an investigation on an app that has a file here, read it. When you finish one, add what you learned.
Paint dock-collapse geometry and remaining repaint artifacts: mspaint.md.
Blobby Volley's settings.dat format, the per-player CONTROL field, why player
two must not be preset to the computer, and why two emulator processes in one
room have to share a wall clock: blobby-volley.md.
What belongs here
- Load bases and address arithmetic. Runtime VA ↔ original VA per module.
- Asset/container layout — archive formats, offsets, how the app reads them.
- Traced API profile — which APIs the app calls and how often, especially
when the answer is surprising (Diablo never calls
BltorFlip). - Named addresses. Every function entry we have identified, with what it does.
- Reproduction commands that reach a given screen headlessly.
- Dead ends, explicitly. A hypothesis someone spent an hour disproving is worth as much as a positive finding, and it only stays worth that if it is written down. Mark withdrawn conclusions rather than deleting them, so nobody re-derives them from an old transcript.
What does not belong here
- Emulator-side design (that is
docs/*.mdproper) or the memory map of our own linear memory (docs/memory-map.md). - Anything a tool prints on demand. Record the command, not a stale dump.
Ground rules
- Say how each number was obtained. A VA with no provenance is a rumor. Prefer a one-line command the reader can re-run.
- Runtime bases shift. They depend on load order and on every preceding
module's
sizeOfImage, so they change when the app's DLL set changes. Use themodule+0xORIG_VAsyntax in--trace-at/--count/--breakinstead of hand-computing a delta, and treat any base written here as a fact to re-check rather than one to trust. - Disassembly addresses in these files are original VAs (what
tools/disasm_fn.jsprints for the file on disk) unless a line says otherwise.
Index
| App | File |
|---|---|
| Abe's Oddysee demo | abes-oddysee-demo.md |
| Age of Empires (1997 shareware demo) | age-of-empires.md |
| Arcanum demo | arcanum-demo.md |
| Bricks I | bricks.md |
| Civilization II: Multiplayer Gold Edition (Indeo 4 movies, headless Indeo install) | civilization-2-mge.md |
| DX-Ball | dxball.md |
| Diablo II Shareware demo | diablo2-demo.md |
| Diablo Shareware | diablo-shareware.md |
| Diablo retail CD | diablo-retail.md |
| Grand Theft Auto 2 Wild Demo | gta2-demo.md |
| Half-Life: Uplink | half-life-uplink.md |
| Heroes of Might and Magic III (demo) | heroes3-demo.md |
| Heroes of Might and Magic II (demo) | heroes2-demo.md |
| Hitman: Codename 47 demo | hitman-demo.md |
| Hype: The Time Quest demo | hype.md |
| Icy Tower v1.3.1 | icy-tower.md |
| Jardinains! v1.2 | jardinains.md |
| JigSawedME 1.3 (VB6; version-resource byte counts) | jigsawedme.md |
| Moorhuhn 1, 2, Winter-Edition, 3, Tennis and CD extras | moorhuhn.md |
| NetHack 3.4.3 for Windows | nethack-win32.md |
| Liquid War 5.6.2 | liquid-war.md |
| Little Fighter 2 v1.9 | little-fighter-2.md |
| War Wind (USA) and War Wind II (Europe) CD installs | war-wind.md |
| Over 1000 Games for Windows (Nodtronics CD) | over1000games-shareware.md |
| Pawn 3 | pawn.md |
| Pocket Tanks shareware | pocket-tanks.md |
| Total Annihilation demo | total-annihilation.md |
| The Elder Scrolls: Arena (GOG) | elder-scrolls-arena-gog.md |
| Ultima IV: Quest of the Avatar (GOG) | ultima4-gog.md |
| Quake II (demo) | quake2-demo.md |
| Rodent's Revenge (Win16) | wep16-rodent.md |
| ScummVM 0.8 — Flight of the Amazon Queen | scummvm-fotaq.md |
| SimCity 2000 Win95 Demo | simcity-2000-demo.md |
| SkiFree (Entertainment Pack) | skifree.md |
| Snood 2.2W | snood.md |
| Worms 2 October demo | worms2-demo.md |
| Warcraft III: Reign of Chaos demo | warcraft3-demo.md |