Save Selector Opcode 0x20 Context+0xf2 Sources
route map1_01a -> map2_02d; context+0xf2 refs 204; reads/writes 141/63; runtime object-table readers 65; direct f2 initializers 2; constant f2 writes: 0; context+0xf2 object selectors: 16; fixed stream+2 object selectors: 0; proofFound False; promotion status blocked.
The opcode 0x20 object-base candidates all rely on context+0xf2, but the f2 byte is a runtime object-slot selector. Static code evidence finds only runtime initializers/copies and object-table readers, with no constant f2 assignment or fixed stream+2 object index for the current route. The patched public-base diagnostic poll now captures a stable active order and 0x0059db30 object-table snapshot, but that capture is constructed diagnostic evidence rather than a normal-route proof. Because the current selector sample is still uncovered and active order alone does not promote the route, context+0xf2 cannot identify a specific map1_01a->map2_02d gate object without non-diagnostic runtime object-table state or an equivalent trace.
Failed Gates
normal-route-runtime-object-table-statecontext-f2-current-frontier-valueopcode42-object-pointer-tracestrict-source-hotspot
Missing Evidence
- non-diagnostic/normal-route selector 2:0 active order/count with live 0x0059db30 object-table contents
- current frontier context+0xf2 byte or equivalent runtime object selector
- runtime trace of opcode 0x42 reader 0x00406470 resolving the current route object pointer
- strict map1_01a source hotspot or equivalent route trigger
Evidence Refs
Hwanse2.exe: static context+0xf2 read/write and object-table reader scanout/save_selector_opcode20_object_base_candidates.json: opcode 0x20 object-base candidates that depend on context+0xf2out/save_selector_opcode20_order_space.json: current selector sample coverage and active-order insufficiencyout/runtime_selected_pointer_patched_public_selector_2_0_active_order_poll.json: diagnostic-only active order and object-table snapshot
Diagnostic Runtime Object Table
| source poll | runtime_selected_pointer_patched_public_selector_2_0_active_order_poll.json |
| available | True |
| diagnostic only | True |
| route samples | 210 across 1 route-reaching sequence(s) |
| total samples | 374 across 2 sequence(s) |
| route sequence names | input-path-slot1-down-enter-enter |
| observed selectors | 50:0, 2:0, 10:0 |
| loaded base | 0x00120000 |
| active order count | 0x01 |
| active order bytes | 0x00, 0x02, 0x02 |
| active order used bytes | 0x00 |
| active slot first dwords static | 0x004f867c |
| runtime slot-base table static | 0x00457750 |
| runtime object table static | 0x0055be00, 0x0055d2f8, 0x0055d5d4 |
| all watched values stable | True |
| normal route proof | False |
| promotion status | diagnostic-only |
Known Evidence
| va | access | instruction | role | source | effect | nearby evidence |
0x00406470 | read | mov cl, byte [eax+0xf2] | opcode 0x42 context+0xf2 object-base reader | context+0xf2 | loads dword[0x0059db30 + context[0xf2]*4] for context+0xa8 | 0x00406480 |
0x0040c00e | write | mov byte [ecx+0xf2], al | active object initializer | loop/local object index | sets context+0xf2 to the table slot and stores the context in 0x0059db30[index] | 0x0040c048 |
0x0040c24f | write | mov byte [ecx+0xf2], al | secondary object initializer | loop/local object index + 3 | sets context+0xf2 to an offset slot and stores the context in 0x0059db3c[index] | 0x0040c28b |
0x0041d90f | read | mov cl, byte [eax+0xf2] | alternate context+0xf2 object-base reader | context+0xf2 | loads dword[0x0059db30 + context[0xf2]*4] for context+0xa8 | 0x0041d91f |
0x00433430 | read | mov al, byte [eax+0xf2] | object field materializer | linked context+0xf2 | copies linked context+0xf2 into object+0x61 | 0x00433439 |
Direct Initializers
| va | source | effect |
0x0040c00e | loop/local object index | sets context+0xf2 to the table slot and stores the context in 0x0059db30[index] |
0x0040c24f | loop/local object index + 3 | sets context+0xf2 to an offset slot and stores the context in 0x0059db3c[index] |
Remaining Proofs
- capture non-diagnostic/normal-route selector 2:0 active order/count with live 0x0059db30 object-table contents
- trace the opcode 0x42 read at 0x00406470 to a concrete context+0xf2 slot and object pointer
- find a strict map1_01a source hotspot if object-table state cannot be proven statically