Update 2.61
6/9/2026
Native menu STEP 3: native-list row source reverse-engineered + `list-read` (probe) + live selection read. Continuing the native in-game menu lane (Yojimbo→Jarvis-BAHAMUT), step-3 gap #1 ("where do the native list's rows come from?") is closed via IDA: the list INPUT (`FFX_Menu_List_UpdateInput 0x8B4460`) is 100% generic — pure field math over the 152-byte object (`+40` state, `+48` count, `+50` top, `+52` target, `+58` page, `+66` slots, `+69` result, `+70` scroll, `+72` selected, `+28` validator), touches no global, and is reused by 10 distinct builders — but every native draw is item-shaped: the scene3 list (`FFX_Menu_CreateScene3ScrollableList 0x8B4FB0` → draw `0x8B4A00` → row `0x8B4B20`) reads rows from `unk_159EC30[64i]` (64-byte structs) + `byte_1866250[]` (type), with the item name resolved by `0x86C3C0(id→table)` and an optional direct label at `rowPtr+32` (type 1); it loads scene3/33/34 and depends on Customize globals. There is no "free-text list" draw in the binary — so a native list with OUR text (the arena / Aurora Photo-Mode shell) requires a DLL draw callback (step 5, the path foreseen in tick-bible §4), with the hand-rolled recipe documented (generic input `0x8B4460` + a DLL draw using `sub_8F5F70` window / `sub_9016B0` string / `sub_8C0640` cursor, reading `+69`/`+72`). Shipped via probe TODAY: new verb `ffxprobectl list-read [handleHex]` (READ-only) that scans the menu-object POOL (`g_FFX_MenuObjPool 0x18408C0`, 32 slots × 152B) — finds ANY active native list/popup and identifies it by its callbacks — plus the shortcut "current list" globals (`dword_1866214`/`186A5DC`/`23CC120`). ✅ RT2 PASS (live, 2026-06-09): with the game in the Customize equipment menu, the pool scan caught the navigated list (slot[3] `@0x017A0A88`, `input=0x8D57E0`, a thin wrapper of the generic `0x8B4460`) and `+72`/`SELECTED` tracked the cursor in real time (35→42) as the operator moved it → step-3 "read the selection of a native navigable list" PROVEN without writing anything. (Bonus: the reset object's `+62 = group 0x101` matches `FFX_MenuObj_Reset` (IDA) — offsets confirmed against memory.) No camera RAM / Aurora / `dllmain.cpp` / save touched; IDA read-only (`_claude_ida` copy, rename-queue in the doc). `ffxprobectl` build 0 errors. Step 5 (blueprint): paste-ready skeleton of the native shell at `RuntimeTools/NativeMenuShell/NativeMenuShell.h` (+README) — object hand-roll + draw callback (window+rows+cursor) + FFX font encoder + decoupled bridge to Aurora's Photo Mode actions; ABIs/offsets confirmed (IDA verify workflow) and adversarially reviewed (2 lenses FFX-vs-IDA + C++ → no crash/compile blocker); x86 guard + anti-OOB clamp + load-bearing invariants annotated; not wired, does not touch `dllmain.cpp`. Step 5.1 (wire blueprint, NOT applied): plan + patch draft (`docs/ai/HANDOFF_BAHAMUT_NATIVE_MENU_WIRE_BLUEPRINT_2026-06-09.md` + `docs/patches/BAHAMUT_NATIVE_MENU_WIRE_DRAFT_2026-06-09.patch`) wiring the shell into `ffx-hooks.dll` via a detour on the menu pump `FFX_Menu_PerFramePump 0x8A9C50` (`int __cdecl(uint)`, IDA-verified, main-thread) — OFF by default (`FFXHOOKS_ENABLE_NATIVE_MENU` + F7 hotkey), bridge only calls `PhotoMode::`; adversarially reviewed (2 lenses) no blocker (compile reviewer applied it to a scratch tree, `git apply --recount --check` exit 0); `dllmain.cpp` NOT touched/committed. Doc: `docs/reverse/FFX_NATIVE_MENU_LIST_ROW_SOURCE_2026-06-09.md`.
Read notes