# TDKPIN.EXE decompilation ## Target - File: `TDKPIN.EXE` - SHA-256: `a9022f1894e3e6e21fc42e8f6c932f7c549ca77f63aaa0c488bb9d55d9d0174c` - Format: Windows 3.x New Executable (NE), 16-bit protected-mode x86 - NE entry point: segment 1, offset `fd85` (Ghidra address `1000:fd85`) - Image: five executable segments, one data segment, and 63 resource blocks - Companion import: `MMTIMER.DLL` The executable contains a Borland runtime copyright string, but it does not retain useful original function or variable names. The `FUN_...` and `DAT_...` names in the output are therefore analysis-generated identifiers. ## Outputs - `TDKPIN_GHIDRA_RAW.c`: preserved initial Ghidra export; immutable evidence. - `TDKPIN_GHIDRA_COMPLETE_RAW.c`: separate regenerated C-like Ghidra output for every currently recovered in-image function, with Win16 import signatures applied. - `TDKPIN_PHYSICS_RESTORED.c` and `TDKPIN_MECHANICS_RESTORED.c`: preserved historical partial transcriptions, explicitly superseded by the complete address-linked modules under `reconstructed/`. - `FUNCTIONS.tsv` and `COVERAGE.tsv`: preserved inventories paired with the initial raw export. - `COMPLETE_FUNCTIONS.tsv` and `COMPLETE_COVERAGE.tsv`: regenerated inventories paired with `TDKPIN_GHIDRA_COMPLETE_RAW.c`. - `BINARY_FUNCTIONS.tsv`: function extents, segments, provisional conventions, and signatures. - `REFERENCES.tsv`, `DEFINED_DATA.tsv`, and `SYMBOLS.tsv`: reproducible call/data evidence. - `UNEXPLAINED.tsv`: exact classification of bytes not representable by a normal non-overlapping Ghidra code/data unit. - `FUNCTION_RECONSTRUCTION.tsv`: semantic reconstruction status for every in-image function. - `OBJECTS.tsv`: all 175 initialized collision/rule records, including geometry, Real48 response values, flags, layers, scores, and render bounds. - `tools/ExportDecompilation.java`: deterministic decompiler exporter. - `tools/SeedMissingEntrypoints.java`: classifies compiler data and seeds missed NE/runtime entries. - `tools/ExportProgramEvidence.java`: regenerates function metadata, references, data, symbols, and exceptional executable-byte evidence. - `tools/AuditCoverage.java`: regenerates the byte-coverage audit. - `tools/decompile.sh`: runs the import, repair, export, and audit from scratch. - `tools/dump_original_objects.py`: regenerates the initialized object ledger from a traceable Wine process without patching the executable. ## Accounting - 301/301 NE exported entry points have corresponding in-image functions. - 90 additional internal/startup/runtime functions were recovered. - 391 in-image functions were submitted to the decompiler. - 391 produced C-like output; none returned a decompiler failure. - 292 imported Win16 APIs are recorded separately and are not represented as fake bodies. - 92,780 bytes are disassembled instructions and 282 bytes are embedded compiler data. - 93,062/93,064 executable-segment bytes have non-overlapping Ghidra code/data units. - The remaining two bytes are fully classified in `UNEXPLAINED.tsv`: one is the first opcode byte of an overlapping Borland alternate entry at `1020:0666`, and one is an alignment NOP at `1020:0dea`. Ghidra's initial NE analysis missed export ordinal 10 at `1000:eab1` and the program entry at `1000:fd85`, plus 28 entries in the Borland runtime segment. Each added entry was verified from prologue/control-flow/return bytes or a direct recovered call target before being submitted to the decompiler. ## Fidelity boundary `TDKPIN_GHIDRA_RAW.c` remains an immutable decompilation artifact rather than the readable deliverable. Its guessed types and names are intentionally preserved as evidence. The separate modules under `reconstructed/` now provide the address-linked C reconstruction; their completeness, typed data/import/resource ledgers, strict host harnesses, and focused live Wine comparisons are tracked in `RECONSTRUCTION_PROGRESS.md`. No claim is made that rebuilding those portable semantic modules reproduces a byte-identical Borland NE image.