Skip to content

证据方法 ​

Evidence ladder ​

BTLX 结论按证据类型分层,而不是把所有“看起来像”混在一起:

  1. Wire evidence:字节流能否严格按 protobuf wire 规则解析;
  2. Corpus evidence:字段出现频率、wire type、重复形态、版本分布;
  3. Native descriptor evidence:exact binary 内恢复出的 Game.proto 字段名、类型和 message graph;
  4. Native consumer evidence:游戏代码如何加载、读取或解释字段;
  5. Runtime evidence:真机/模拟器行为与动态 trace;
  6. Writer evidence:修改后能否 lossless/deterministic 写回并被目标版本接受。

低层证据不能替代高层证据。

当前状态 ​

领域EW7 3.5.0WS 3.2.2
Strict wire parsePassedPassed
Byte-preserving round-tripPassedPassed
Native Game.proto descriptorRecoveredRecovered
BattleArgs root identityConfirmedStronglySupported
Recursive descriptor validationPassedPassed
Exact BattleArgs consumerUnknownUnknown
Exact BattleArgs serializerUnknownUnknown
Device/runtime acceptanceNotRunNotRun

Unknown 处理 ​

Unknown 是正式状态,不是临时空白。尤其是:

  • 不因字段形状类似就给 semantic name;
  • 不因两个标题使用同号字段就共享语义;
  • 不因 parser 能递归下降就把 bytes 标成 message;
  • 不因静态 descriptor 匹配就声称游戏行为已经验证。

后续证据若推翻已有解释,应保留 superseded 记录,而不是静默覆盖研究历史。