# map1_01a Edge Trigger Gap

Route: `map1_01a -> map2_02d`

This audit checks whether the geometry-only edge candidates can be promoted as a generic original edge/boundary transition. It keeps promotion blocked.

## Gate

- promotionAllowed: `False`
- promotionStatus: `blocked-generic-edge-trigger-unproven`
- proofFound: `False`
- failed edge trigger gates: `edge-to-transition-control-flow, runtime-edge-selected-root-proof, strict-source-hotspot`
- missingEvidenceCount: `3`
- evidenceRefs: `3`
- source boundary candidates: `2`
- auto boundary candidates: `2`
- transition-like direct rel hits in helper/controller: `0`
- route direct immediates in helper/controller: `0`
- direction latch direct .text refs: `79`
- direction latch route-window hits: `0` rel / `0` immediates
- actor-controller caller-window hits: `0` rel / `0` immediates
- collision-helper caller-window hits: `0` rel / `0` immediates
- script-runner call windows: `4` calls / `0` route immediates / `0` map-loader rel / `0` selector-table rel
- selected-pointer immediate windows: `6` refs / `0` route-specific hits
- edge handler encoded route-target scalars: `0` / `0` / `0` / `0` / `0` (`no-encoded-route-target-scalars-in-edge-windows`)
- edge local-window encoded route-target scalars: `0` / `0` / `0` / `0` / `0` (`no-encoded-route-target-scalars-in-edge-windows`)
- edge call-graph encoded route-target scalars: `0` / `0` / `0` / `0` / `0` (`no-encoded-route-target-scalars-in-edge-windows`)
- global contrast-window encoded route-target scalars: `4` / `4` / `0` / `0` / `0` (`edge-encoded-route-target-scalars-nonpromoting`)
- direct call graph: `bounded-direct-callgraph-no-transition-path` / proof `False` / functions `7` / edges `24` / transition targets `0` / transition hits `0` / route immediates `0` / indirect-like bytes `6`
- direct call graph depth sensitivity: max depth `6` / no proof `True` / stable beyond default `True`
- indirect call graph rejection: `bounded-indirect-callgraph-no-static-transition-target` / proof `False` / absolute `0` / jump tables `6`/`58` entries / targets `58`/`54` unique / local `True` / outside `0` / resolved `0` / unresolved `0` / transition hits `0` / route hits `0`
- global .text transition refs: `0` map-loader / `4` script-runner / `0` selector-table rel hits

## Candidate Rows

| side | tile | direction | edge | auto | source boundary | in-bounds move | original standable | helper rule | helper check |
| --- | --- | --- | ---: | ---: | ---: | ---: | ---: | --- | --- |
| top | 18,0 | up | 0 | True | True | False | True | tileY == 0 | `0x00431ae6` |
| bottom | 16,47 | down | 0 | True | True | False | False | mapHeight - footprintHeight == tileY | `0x00431a48` |
| left | 3,14 | left | 2 | False | False | True | True | tileX == 0 | `0x00431b84` |
| right | 34,19 | right | 2 | False | False | True | True | mapWidth - footprintWidth == tileX | `0x00431c0c` |

## Boundary Helper Evidence

| direction | rule | check | fallback latch | exit target | snippet |
| --- | --- | --- | --- | --- | ---: |
| down | mapHeight - footprintHeight == tileY | `0x00431a48` | `0x01` | `0x00431ca6` | True |
| up | tileY == 0 | `0x00431ae6` | `0x02` | `0x00431ca6` | True |
| left | tileX == 0 | `0x00431b84` | `0x03` | `0x00431ca6` | True |
| right | mapWidth - footprintWidth == tileX | `0x00431c0c` | `0x04` | `0x00431ca6` | True |

## Direct Reference Checks

| range | map loader rel | script runner rel | selector table rel | selected ptr imm | current root imm | source string imm | target string imm |
| --- | ---: | ---: | ---: | ---: | ---: | ---: | ---: |
| collision helper `0x004319f8..0x00431fe8` | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| actor controller `0x0043022d..0x00431350` | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| global .text `0x00401000..0x0043a7ff` | 0 | 4 | 0 | 6 | 0 | 0 | 0 |

## Selected Pointer Immediate Context

| ref | window | selected ptr imm | current root imm | source string imm | target string imm | map-loader rel | script-runner rel | selector-table rel |
| --- | --- | ---: | ---: | ---: | ---: | ---: | ---: | ---: |
| `0x0040adb9` | `0x0040acf9..0x0040ae79` | 5 | 0 | 0 | 0 | 0 | 0 | 0 |
| `0x0040add8` | `0x0040ad18..0x0040ae98` | 5 | 0 | 0 | 0 | 0 | 0 | 0 |
| `0x0040adff` | `0x0040ad3f..0x0040aebf` | 5 | 0 | 0 | 0 | 0 | 0 | 0 |
| `0x0040ae38` | `0x0040ad78..0x0040aef8` | 5 | 0 | 0 | 0 | 0 | 0 | 0 |
| `0x0040ae4b` | `0x0040ad8b..0x0040af0b` | 5 | 0 | 0 | 0 | 0 | 0 | 0 |
| `0x004234bb` | `0x004233fb..0x0042357b` | 1 | 0 | 0 | 0 | 0 | 0 | 0 |

All direct selected-pointer global immediates in .text were scanned with local windows. Those windows do not contain current-root, source-map, target-map, map-loader, script-runner, or selector-table evidence that would tie the global selected-pointer access to this edge path.

## Script Runner Call Context

| call | window | selected ptr imm | current root imm | source string imm | target string imm | map-loader rel | selector-table rel |
| --- | --- | ---: | ---: | ---: | ---: | ---: | ---: |
| `0x0040237f` | `0x004022bf..0x0040243f` | 0 | 0 | 0 | 0 | 0 | 0 |
| `0x004058af` | `0x004057ef..0x0040596f` | 0 | 0 | 0 | 0 | 0 | 0 |
| `0x004058d8` | `0x00405818..0x00405998` | 0 | 0 | 0 | 0 | 0 | 0 |
| `0x004330a9` | `0x00432fe9..0x00433169` | 0 | 0 | 0 | 0 | 0 | 0 |

All direct script-runner calls were scanned with local windows. They are outside the actor-controller/collision-helper ranges and their windows contain no map-loader or selector-table rel branches and no selected-pointer, current-root, source-map, or target-map immediates.

## Direct Call Graph

- classification: `bounded-direct-callgraph-no-transition-path`
- proof found: `False`
- reachable functions / direct call edges: `7` / `24`
- transition targets reachable / transition hits / route immediates: `0` / `0` / `0`
- indirect call-like bytes: `6`
- depth sensitivity max / no proof / stable beyond default: `6` / `True` / `True`
- indirect rejection: `bounded-indirect-callgraph-no-static-transition-target` / proof `False` / absolute `0` / jump tables `6`/`58` entries / targets `58`/`54` unique / local `True` / outside `0` / resolved `0` / unresolved `0` / transition hits `0` / route hits `0`

| function | depth | range | calls | transition hits | route immediates |
| --- | ---: | --- | ---: | ---: | ---: |
| actor-controller | 0 | `0x0043022d..0x00431350` | 22 | 0 | 0 |
| collision-helper | 0 | `0x004319f8..0x00431fe8` | 0 | 0 | 0 |
| sub_00424cd6 | 1 | `0x00424cd6..0x00424d28` | 1 | 0 | 0 |
| sub_004319f8 | 1 | `0x004319f8..0x00431a3e` | 0 | 0 | 0 |
| sub_004330e0 | 1 | `0x004330e0..0x00433112` | 1 | 0 | 0 |
| sub_00416ce2 | 2 | `0x00416ce2..0x00416d22` | 0 | 0 | 0 |
| sub_00427730 | 2 | `0x00427730..0x00427774` | 0 | 0 | 0 |

### Direct Call Graph Depth Sensitivity

| max depth | observed depth | functions | edges | transition targets | transition hits | route immediates | indirect-like bytes | proof | stable class |
| ---: | ---: | ---: | ---: | ---: | ---: | ---: | ---: | ---: | --- |
| 1 | 1 | 5 | 22 | 0 | 0 | 0 | 6 | False | bounded-direct-callgraph-no-transition-path |
| 2 | 2 | 7 | 24 | 0 | 0 | 0 | 6 | False | bounded-direct-callgraph-no-transition-path |
| 3 | 2 | 7 | 24 | 0 | 0 | 0 | 6 | False | bounded-direct-callgraph-no-transition-path |
| 4 | 2 | 7 | 24 | 0 | 0 | 0 | 6 | False | bounded-direct-callgraph-no-transition-path |
| 5 | 2 | 7 | 24 | 0 | 0 | 0 | 6 | False | bounded-direct-callgraph-no-transition-path |
| 6 | 2 | 7 | 24 | 0 | 0 | 0 | 6 | False | bounded-direct-callgraph-no-transition-path |

Depth sensitivity over max depths 1,2,3,4,5,6 found no transition target, route immediate, or indirect route target. Counts are stable at and beyond the default depth, so increasing the bounded call-graph depth does not make the edge candidates promotable.


### Indirect Call/Jump Candidates

| function | depth | instruction | kind | operand | table | entries | absolute | resolved | target hit | route hit |
| --- | ---: | --- | --- | --- | --- | ---: | --- | --- | --- | --- |
| actor-controller | 0 | `0x0043032c` | jmp | indexed-jump-table | `0x00430333` | 4 | `-` | `-` | - | - |
| actor-controller | 0 | `0x00430af9` | jmp | indexed-jump-table | `0x00430b00` | 4 | `-` | `-` | - | - |
| actor-controller | 0 | `0x00430d5a` | jmp | indexed-jump-table | `0x00430d61` | 34 | `-` | `-` | - | - |
| actor-controller | 0 | `0x00430fca` | jmp | indexed-jump-table | `0x00430fd1` | 4 | `-` | `-` | - | - |
| collision-helper | 0 | `0x00431c8f` | jmp | indexed-jump-table | `0x00431c96` | 4 | `-` | `-` | - | - |
| collision-helper | 0 | `0x00431f94` | jmp | indexed-jump-table | `0x00431f9b` | 8 | `-` | `-` | - | - |

### Indirect Jump Table Audit

| function | instruction | table | entries | target classes | local-only | outside | transition labels | route labels |
| --- | --- | --- | ---: | --- | --- | ---: | --- | --- |
| actor-controller | `0x0043032c` | `0x00430333` | 4 | `actor-controller-local:4` | True | 0 | `-` | `-` |
| actor-controller | `0x00430af9` | `0x00430b00` | 4 | `actor-controller-local:4` | True | 0 | `-` | `-` |
| actor-controller | `0x00430d5a` | `0x00430d61` | 34 | `actor-controller-local:34` | True | 0 | `-` | `-` |
| actor-controller | `0x00430fca` | `0x00430fd1` | 4 | `actor-controller-local:4` | True | 0 | `-` | `-` |
| collision-helper | `0x00431c8f` | `0x00431c96` | 4 | `collision-helper-local:4` | True | 0 | `-` | `-` |
| collision-helper | `0x00431f94` | `0x00431f9b` | 8 | `collision-helper-local:8` | True | 0 | `-` | `-` |

A bounded direct-call graph from the actor-controller and collision-helper ranges did not reach the map loader, script runner, selector table, selected-pointer global, current root, or route map strings. The indirect call/jump-like candidates in the same reachable graph also have no static route or transition target; computed operands still require runtime proof.

The indirect call/jump-like opcodes reachable from the actor movement/collision ranges have no static absolute or resolved target matching the map loader, script runner, selector table, selected pointer, current root, or route map strings. Their indexed jump-table entries stay inside the actor-controller/collision-helper edge handlers, so they are local movement branches rather than map-transition proof.

## Direction Latch Global Scan

- latch: `0x00574533`
- text refs: `79` (`48` reads / `31` writes / `9` outside helper/controller range)
- local route-window hits: `0` transition rel / `0` route immediates
- outside helper/controller refs: reset `1`, actor-state continuation reads `8`, transition consumers `0`, unclassified `0`
- outside helper/controller route-window hits: `0` transition rel / `0` route immediates
- outside refs classified non-transition: `True`
- by kind: `read-al=47, read-movzx-u8=1, write-al=1, write-immediate-u8=30`

| ref | range | kind | value |
| --- | --- | --- | --- |
| `0x00430157` | other-text | write-immediate-u8 | `0x00` |
| `0x0043024c` | actor-controller | write-immediate-u8 | `0x00` |
| `0x004302c8` | actor-controller | write-al | `-` |
| `0x004302e8` | actor-controller | write-immediate-u8 | `0x01` |
| `0x004302f4` | actor-controller | write-immediate-u8 | `0x02` |
| `0x00430300` | actor-controller | write-immediate-u8 | `0x03` |
| `0x0043030c` | actor-controller | write-immediate-u8 | `0x04` |
| `0x00430420` | actor-controller | write-immediate-u8 | `0x05` |
| `0x00430437` | actor-controller | write-immediate-u8 | `0x06` |
| `0x0043044e` | actor-controller | write-immediate-u8 | `0x07` |
| `0x00430465` | actor-controller | write-immediate-u8 | `0x08` |
| `0x0043046d` | actor-controller | read-al | `-` |
| `0x00430486` | actor-controller | read-al | `-` |
| `0x0043058e` | actor-controller | read-al | `-` |
| `0x004305b7` | actor-controller | read-al | `-` |
| `0x004305d1` | actor-controller | read-al | `-` |
| `0x004305e1` | actor-controller | read-al | `-` |
| `0x004305f0` | actor-controller | write-immediate-u8 | `0x01` |
| `0x00430607` | actor-controller | read-al | `-` |
| `0x0043070f` | actor-controller | read-al | `-` |

All direct .text references to the direction latch were scanned with local windows. None of those windows contains a direct map-loader/script-runner/selector-table branch or a selected-pointer, current-root, source-map, or target-map immediate. The refs outside the bounded helper/controller ranges are one movement-state reset and two nearby actor-state compare clusters that select actor +0x68 states, not a map transition consumer. Direction latch use therefore remains actor movement/collision state, not edge-transition proof.

### Direction Latch Outside Helper/Controller Audit

| instruction | ref | class | effect | transition rel | route imm | bytes |
| --- | --- | --- | --- | ---: | ---: | --- |
| `0x00430155` | `0x00430157` | movement-state-initializer-reset | writes direction latch 0x00 while resetting actor/list display state | 0 | 0 | `c6 05 33 45 57 00 00 c7 45 fc 00 00` |
| `0x0043135d` | `0x0043135e` | actor-state-continuation-read | compares latch against 0x05..0x08 and selects actor +0x68 state 0x07 or 0x03 | 0 | 0 | `a0 33 45 57 00 83 f8 05 0f 84 30 00` |
| `0x0043136d` | `0x0043136e` | actor-state-continuation-read | compares latch against 0x05..0x08 and selects actor +0x68 state 0x07 or 0x03 | 0 | 0 | `a0 33 45 57 00 83 f8 06 0f 84 20 00` |
| `0x0043137d` | `0x0043137e` | actor-state-continuation-read | compares latch against 0x05..0x08 and selects actor +0x68 state 0x07 or 0x03 | 0 | 0 | `a0 33 45 57 00 83 f8 07 0f 84 10 00` |
| `0x0043138d` | `0x0043138e` | actor-state-continuation-read | compares latch against 0x05..0x08 and selects actor +0x68 state 0x07 or 0x03 | 0 | 0 | `a0 33 45 57 00 83 f8 08 0f 85 0f 00` |
| `0x004313bb` | `0x004313bc` | actor-state-continuation-read | compares latch against 0x05..0x08 and selects actor +0x68 state 0x08 or 0x04 | 0 | 0 | `a0 33 45 57 00 83 f8 05 0f 84 30 00` |
| `0x004313cb` | `0x004313cc` | actor-state-continuation-read | compares latch against 0x05..0x08 and selects actor +0x68 state 0x08 or 0x04 | 0 | 0 | `a0 33 45 57 00 83 f8 06 0f 84 20 00` |
| `0x004313db` | `0x004313dc` | actor-state-continuation-read | compares latch against 0x05..0x08 and selects actor +0x68 state 0x08 or 0x04 | 0 | 0 | `a0 33 45 57 00 83 f8 07 0f 84 10 00` |
| `0x004313eb` | `0x004313ec` | actor-state-continuation-read | compares latch against 0x05..0x08 and selects actor +0x68 state 0x08 or 0x04 | 0 | 0 | `a0 33 45 57 00 83 f8 08 0f 85 0f 00` |

## Caller Window Scans

| target | callers | local transition rel hits | local route immediates | hit windows |
| --- | ---: | ---: | ---: | ---: |
| actor-controller `0x0043022d` | 1 | 0 | 0 | 0 |
| collision-helper `0x004319f8` | 20 | 0 | 0 | 0 |

All direct callers of actor-controller were scanned with local windows. Any transition-like branch or source/target/current-root immediate near those calls must still be tied to the edge path before it can prove a generic boundary transition.

All direct callers of collision-helper were scanned with local windows. Any transition-like branch or source/target/current-root immediate near those calls must still be tied to the edge path before it can prove a generic boundary transition.

## Conclusion

The top and bottom map1_01a routeAssist candidates are real map-edge boundary candidates, but the original collision helper evidence only shows boundary fallback writes to the direction latch before returning to the actor collision/overlap path. No direct map-loader, selected-pointer, current-root, or map1_01a/map2_02d string reference is present in the helper/controller ranges or near any direct direction-latch reference in .text, and the bounded direct-call graph from the actor movement/collision ranges remains stable through the deeper sensitivity pass without reaching a transition target or route-specific immediate. This keeps the manual movement trigger consumer unidentified; it does not support a scene-auto-transition interpretation, and a generic edge-trigger transition remains unproven.

## Missing Evidence

- a branch/call from the boundary collision path to the map loader or scene selector
- a runtime watchpoint showing an edge candidate changes the selected map/root
- a strict map1_01a source hotspot/event record for map2_02d
