Save Selector Gate Base Candidates

route map1_01a -> map2_02d; gate offsets 0xe8, 0xea; expected selection index range 0..11; proofFound False; promotion status blocked

Mapping the gate offsets through known context+0xa8 base candidates weakens the party-slot-base path: for party slots, 0xe8/0xea land on later character MP/stat bytes such as Rinshan and Smashu MP fields, not on documented selector-index bytes. Since opcode 0x11 expects a branch-state slot index in the 0..11 range, those stat-byte mappings are not promotion evidence. Loader-aware save/runtime mapping also matters here: 0x004576d8+0xe8/0xea falls into the second loaded save block after the six-byte runtime gap, so those bytes map to save offsets 0x00e2/0x00e4 rather than linear offsets 0x00e8/0x00ea. The viable sources remain an unresolved global/save-runtime buffer or object pointer table mode, so control-flow proof is still blocked.

Failed Gates

Missing Evidence

Evidence Refs

baseslotgateruntime addresssave blocksave offsetknown save fielddirect refsclassification
global selection buffer-0xe80x0059e3f8---0unresolved-global-buffer
save/runtime block base-0xe80x004577c0partyAndStats0x00e2unknown within partyAndStats save block (unmapped-byte)0save-backed-unmapped-byte
party slot base00xe80x00457838partyAndStats0x015aRinshan MP recover (low-byte)0implausible-stat-byte-index
party slot base10xe80x00457910partyAndStats0x0232Smashu MP recover (low-byte)0implausible-stat-byte-index
party slot base20xe80x004579e8---0party-slot-byte-needs-runtime-proof
runtime object pointer table-0xe8----0unresolved-pointer-table-base
global selection buffer-0xea0x0059e3fa---0unresolved-global-buffer
save/runtime block base-0xea0x004577c2partyAndStats0x00e4unknown within partyAndStats save block (unmapped-byte)0save-backed-unmapped-byte
party slot base00xea0x0045783apartyAndStats0x015cRinshan MP maximum (low-byte)0implausible-stat-byte-index
party slot base10xea0x00457912partyAndStats0x0234Smashu MP maximum (low-byte)0implausible-stat-byte-index
party slot base20xea0x004579ea---0party-slot-byte-needs-runtime-proof
runtime object pointer table-0xea----0unresolved-pointer-table-base