Repository navigation
Expand file tree
/
Copy pathnocturnerecomp_config.toml
More file actions
79 lines (72 loc) · 2.84 KB
/
Copy pathnocturnerecomp_config.toml
File metadata and controls
79 lines (72 loc) · 2.84 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
# nocturnerecomp - ReXGlue codegen config
#
# Add named functions (indirect-call targets), midasm hooks, and CRT
# addresses here once they are located in assets/default.xex.
#
# Example:
# [functions]
# 0x8XXXXXXX = {name = "MyFunction"}
#
# [[midasm_hook]]
# address = 0x8XXXXXXX
# name = "MyHook"
# registers = ["r3"]
# return = true
#
# [rexcrt]
# memcpy = 0x8XXXXXXX
# memset = 0x8XXXXXXX
# memmove = 0x8XXXXXXX
[functions]
0x8282AEF0 = {}
0x82286638 = {}
[rexcrt]
memcpy = 0x825E3300
memmove = 0x825E37D0
memset = 0x825E2740
# sub_825252C8 is the guest's generic "wait for the GPU to catch up" ring/pool
# primitive. It polls a GPU-driven counter that only a real GraphicsSystem
# ever advances. When headless there's no GPU to wait for, so bypass the wait
# entirely instead of trying to emulate every counter it might poll.
[[midasm_hook]]
address = 0x825252C8
name = "HeadlessRingWaitBypass"
return_on_true = true
[[midasm_hook]]
address = 0x82524330
name = "HeadlessRingWaitBypass"
return_on_true = true
# Main Menu -> Leaderboards routes through FE page 8 (the Xbox Live logon
# interstitial, ctor sub_825B69A0 / vtable 0x82013ec0). With no real Live
# signin the logon fails and page 8's Update (sub_825B6AB0) posts a
# page-switch event back to the main menu (page 1) at loc_825B6E48. When the
# logon was started with mode 1 (the Leaderboards intent, obj+544 == 1),
# reroute that exit to page 3 (the actual Leaderboards screen) so the menu
# opens with local/empty data instead of bouncing back to the main menu.
# r5 = destination page index, r31 = page-8 object pointer.
# See LEADERBOARD_HANG_INVESTIGATION.md session 8.
[[midasm_hook]]
address = 0x825B6E48
name = "LeaderboardLogonRouteToScreen"
registers = ["r5", "r31"]
# The Leaderboards screen's page-activate (sub_825C1AB8) busy-spins on the
# async leaderboard-read status (sub_82584C18 == 1/2) with no timeout. The
# SDK never reports a Live signin, so the read can never reach a terminal
# state -- skip the spin entirely (mirrors the pause menu, which never enters
# this path when Live is unavailable). Spin body 0x825C1B24..0x825C1B40;
# first instruction after it is 0x825C1B44.
[[midasm_hook]]
address = 0x825C1B24
name = "LeaderboardActivateSpinSkip"
jump_address_on_true = 0x825C1B44
# The Leaderboards screen's per-frame event handler (sub_825C2CB0) gates on
# XamUserGetSigninState(user) == SignedInToLive at its very top; when not
# signed in it immediately re-posts a page-switch event back to the logon
# interstitial (sub_825CE8E8(8, ...)) instead of handling the event, so the
# screen flashes its error state for a frame and bounces back to the main
# menu. Skip the signin check and always take the "signed in" path
# (loc_825C2D0C) -- same rationale as the spin-skip above.
[[midasm_hook]]
address = 0x825C2CD0
name = "LeaderboardEventSigninBypass"
jump_address_on_true = 0x825C2D0C