Replace the partial mechanics transcriptions with a separate, readable C11 reconstruction of the complete Win16 image while preserving the original raw Ghidra export as immutable evidence. Cover all ordinary and overlapping entry points, Borland runtime behavior, Win16 imports, segmented data, callbacks, resources, indirect control flow, physics, rendering, persistence, and startup/shutdown lifecycles. Add deterministic extraction and audit tooling plus address-linked ledgers for functions, imports, DGROUP ranges and objects, relocations, resources, and callbacks. The final gate records zero raw, partial, restored, unknown, blocked, or unclassified required units. Keep the semantic-fidelity boundary explicit: the portable C is not claimed to reproduce a byte-identical Borland NE build. Add strict focused harnesses for every reconstructed C unit, exact resource round-trip checks, and a 16-bit Borland Real48 reference probe. No Rust source or Cargo metadata is changed in this phase. Test Plan: - `bash original/tools/test_reconstructed_c.sh` -- passed - `bash original/tools/probe_real48_reference.sh` -- passed bit-for-bit - `python3 original/tools/audit_reconstruction.py --require-complete` -- passed - `git diff --cached --check` -- passed - `git diff HEAD -- '*.rs' Cargo.toml Cargo.lock` -- empty
4.0 KiB
TDKPIN.EXE decompilation
Target
- File:
TDKPIN.EXE - SHA-256:
a9022f1894e3e6e21fc42e8f6c932f7c549ca77f63aaa0c488bb9d55d9d0174c - Format: Windows 3.x New Executable (NE), 16-bit protected-mode x86
- NE entry point: segment 1, offset
fd85(Ghidra address1000:fd85) - Image: five executable segments, one data segment, and 63 resource blocks
- Companion import:
MMTIMER.DLL
The executable contains a Borland runtime copyright string, but it does not retain
useful original function or variable names. The FUN_... and DAT_... names in
the output are therefore analysis-generated identifiers.
Outputs
TDKPIN_GHIDRA_RAW.c: preserved initial Ghidra export; immutable evidence.TDKPIN_GHIDRA_COMPLETE_RAW.c: separate regenerated C-like Ghidra output for every currently recovered in-image function, with Win16 import signatures applied.TDKPIN_PHYSICS_RESTORED.candTDKPIN_MECHANICS_RESTORED.c: preserved historical partial transcriptions, explicitly superseded by the complete address-linked modules underreconstructed/.FUNCTIONS.tsvandCOVERAGE.tsv: preserved inventories paired with the initial raw export.COMPLETE_FUNCTIONS.tsvandCOMPLETE_COVERAGE.tsv: regenerated inventories paired withTDKPIN_GHIDRA_COMPLETE_RAW.c.BINARY_FUNCTIONS.tsv: function extents, segments, provisional conventions, and signatures.REFERENCES.tsv,DEFINED_DATA.tsv, andSYMBOLS.tsv: reproducible call/data evidence.UNEXPLAINED.tsv: exact classification of bytes not representable by a normal non-overlapping Ghidra code/data unit.FUNCTION_RECONSTRUCTION.tsv: semantic reconstruction status for every in-image function.OBJECTS.tsv: all 175 initialized collision/rule records, including geometry, Real48 response values, flags, layers, scores, and render bounds.tools/ExportDecompilation.java: deterministic decompiler exporter.tools/SeedMissingEntrypoints.java: classifies compiler data and seeds missed NE/runtime entries.tools/ExportProgramEvidence.java: regenerates function metadata, references, data, symbols, and exceptional executable-byte evidence.tools/AuditCoverage.java: regenerates the byte-coverage audit.tools/decompile.sh: runs the import, repair, export, and audit from scratch.tools/dump_original_objects.py: regenerates the initialized object ledger from a traceable Wine process without patching the executable.
Accounting
- 301/301 NE exported entry points have corresponding in-image functions.
- 90 additional internal/startup/runtime functions were recovered.
- 391 in-image functions were submitted to the decompiler.
- 391 produced C-like output; none returned a decompiler failure.
- 292 imported Win16 APIs are recorded separately and are not represented as fake bodies.
- 92,780 bytes are disassembled instructions and 282 bytes are embedded compiler data.
- 93,062/93,064 executable-segment bytes have non-overlapping Ghidra code/data units.
- The remaining two bytes are fully classified in
UNEXPLAINED.tsv: one is the first opcode byte of an overlapping Borland alternate entry at1020:0666, and one is an alignment NOP at1020:0dea.
Ghidra's initial NE analysis missed export ordinal 10 at 1000:eab1 and the program entry at
1000:fd85, plus 28 entries in the Borland runtime segment. Each added entry was
verified from prologue/control-flow/return bytes or a direct recovered call target
before being submitted to the decompiler.
Fidelity boundary
TDKPIN_GHIDRA_RAW.c remains an immutable decompilation artifact rather than the
readable deliverable. Its guessed types and names are intentionally preserved as evidence.
The separate modules under reconstructed/ now provide the address-linked C reconstruction;
their completeness, typed data/import/resource ledgers, strict host harnesses, and focused live
Wine comparisons are tracked in RECONSTRUCTION_PROGRESS.md. No claim is made that rebuilding
those portable semantic modules reproduces a byte-identical Borland NE image.