Skip to content

Repository files navigation

Ratchet: Deadlocked Decompilation

Progress report Code Functions

A work-in-progress matching decompilation of Ratchet: Deadlocked (Ratchet: Gladiator in PAL regions; Insomniac Games, 2005) for the PlayStation 2, NTSC-U version. The goal is C/C++ source that, built with the original toolchain, produces a byte-identical copy of the retail executable.

The project runs in two phases:

  1. Match. Write source that compiles to exactly the retail machine code. This is what proves a function has been understood: the compiler judges the result, not a read-through.
  2. Make it readable. Refactor matched code toward idiomatic C++ with real names, types and structure. The matching build acts as the regression test for every cleanup.

Status: early. The whole build pipeline works (unpacking the retail image, disassembly, compiler and flags identified, library code rebuilt from its open-source originals) and functions are matching. There is no linked image yet, so matching is checked function by function.

Progress

Progress is tracked on decomp.dev.

Version Region Game ID Code Functions
v1.00 NTSC-U (VER = 1.00) SCUS_974.65

Only NTSC-U is targeted. PAL (Ratchet: Gladiator) may follow as a second version if someone with a PAL disc joins.

Category Progress Contents
Game All game code
Core Engine and SDK code that stays resident (core.text)
Network Network code (net.text)
Resident level code The level text kept in the executable (.text); the menus' code
libgcc GCC runtime library rebuilt from GCC's own source (src/libgcc/)
libm Math library rebuilt from newlib's source (src/libm/)
Level overlays All level overlay code (docs/OVERLAYS.md)
Common Overlay code shared by two or more levels
Level-specific Overlay code found in one level only (the multiplayer menu)

Level overlays

Each level carries its own build of the level code, loaded over the resident image when the level starts (docs/OVERLAYS.md). There are 47 overlays (24 campaign and 23 multiplayer levels) that share 85 to 97 percent of their code at different addresses. Their functions are split and counted once each: code shared by two or more levels under Common (4,714 functions), code found in one level only under Level-specific (2,315 functions, all of them the multiplayer menu's), and in the row of every level that contains it. Functions identical to one in the resident level text are counted there, not twice. The overlays come from your own disc: unpack it with the wrench build tool and run tools/split_overlays.py (see docs/OVERLAYS.md). Nothing is decompiled in them yet.

Per level

Each row counts the overlay code of that level, including the common code it contains (code identical to the resident level text is counted under Resident level code instead).

Level Name Kind Code Functions
00 Multiplayer Menu multiplayer
01 Dreadzone Station campaign
02 Catacrom Graveyard campaign
04 Sarathos Swamp campaign
05 Dark Cathedral campaign
06 Temple Of Shaar campaign
07 Valix Lighthouse campaign
08 Mining Facility campaign
10 Torval Ruins campaign
11 Tempus Station campaign
13 Maraxus Prison campaign
14 Ghost Station campaign
15 Control Level campaign
21 Dreadzone Station Splitscreen campaign
22 Catacrom Graveyard Splitscreen campaign
24 Sarathos Swamp Splitscreen campaign
25 Dark Cathedral Splitscreen campaign
26 Temple Of Shaar Splitscreen campaign
27 Valix Lighthouse Splitscreen campaign
28 Mining Facility Splitscreen campaign
30 Torval Ruins Splitscreen campaign
31 Tempus Station Splitscreen campaign
33 Maraxus Prison Splitscreen campaign
34 Ghost Station Splitscreen campaign
35 Control Level Splitscreen campaign
41 Battledome Tower multiplayer
42 Catacrom Graveyard multiplayer
44 Sarathos Swamp multiplayer
45 Dark Cathedral multiplayer
46 Temple Of Shaar multiplayer
47 Valix Lighthouse multiplayer
48 Mining Facility multiplayer
50 Torval Ruins multiplayer
51 Tempus Station multiplayer
53 Maraxus Prison multiplayer
54 Ghost Station multiplayer
61 Battledome Tower Splitscreen multiplayer
62 Catacrom Graveyard Splitscreen multiplayer
64 Sarathos Swamp Splitscreen multiplayer
65 Dark Cathedral Splitscreen multiplayer
66 Temple Of Shaar Splitscreen multiplayer
67 Valix Lighthouse Splitscreen multiplayer
68 Mining Facility Splitscreen multiplayer
70 Torval Ruins Splitscreen multiplayer
71 Tempus Station Splitscreen multiplayer
73 Maraxus Prison Splitscreen multiplayer
74 Ghost Station Splitscreen multiplayer

A function counts as matched when its compiled code equals retail with relocatable fields masked (tools/audit_matches.py). This is not a link-time comparison yet, so a function that calls or reads the wrong symbol can still count.

Disclaimer

This repository contains no game assets, executable, or disassembly. To build it you need your own legally obtained copy of the game. Read LEGAL.md before contributing.

How it works

  • The executable is a loader plus a packed image. tools/unpack_wad.py decodes the compressed game image and tools/split_image.py splits it into its 17 sections and rebuilds an ELF for splat (docs/RESEARCH.md).
  • The compiler is SN GCC 2.95.3 v1.36 with -O2 -G8 -fopt-stack -mno-check-zero-division, run as 32-bit Windows programs (through Wine in a container on Linux and macOS). Retail was assembled by SN's own assembler, whose nops and constant sequences tools/cc.sh reproduces.
  • Level code is overlays. Each level has its own copy of the level code, 47 in all, split by tools/split_overlays.py into common and level-specific functions, as in rac1-decomp (docs/OVERLAYS.md).
  • Library code is rebuilt from source. libgcc comes from GCC and libm from newlib, both built unchanged with Sony's 2.9-ee driver and matched against the retail bytes; only files that match are kept.

Quick start

git clone git@github.com:Lynder063/rac-deadlocked-decomp.git
cd rac-deadlocked-decomp
cp /path/to/SCUS_974.65 baserom/                 # SHA-1 aa91b1c3b9b1a244320c47580b77342ef9856e95
bash tools/setup_asm.sh                           # unpack, split, splat -> asm/
git clone https://github.com/AngheloAlf/SN-Systems-ProDG_for_PS2_3.01 toolchain/sn-prodg-3.01
git clone https://github.com/AngheloAlf/sce_ps2_sdk_24 toolchain/sn-prodg-24
bash tools/docker/run.sh bash tools/build.sh      # compile src/
venv/bin/python tools/audit_matches.py            # compare every function with retail
python3 tools/gen_progress_report.py              # progress/report.json for decomp.dev

The compilers are third-party mirrors of commercial software and are not part of this repository. CONTRIBUTING.md has the full setup, how code is compiled, how to add a function and what tends to make functions match.

Project structure

Path Contents
src/core/, src/net/, src/game/ Decompiled game code, one file per start address until the real source file is known
src/libgcc/, src/libm/ GCC's runtime library and newlib's math library, sources that match retail (see their READMEs and THIRD_PARTY_NOTICES.md)
include/ Shared headers (common.h) and assembly macros
config/ splat configuration, section table, function list (functions.tsv), library tables (libgcc.tsv, libm.tsv) and the level overlays (overlays.tsv, overlay_functions.tsv)
tools/ Unpacker, section splitter, compile pipeline (cc.sh), audit, diff and report tools
tools/docker/ The build container runner
nonmatching/ Drafts that do not match yet (not built)
docs/ RESEARCH.md (how the executable is built and rebuilt), OVERLAYS.md (the level overlays), CREDITS.md
baserom/ Your own executable, not tracked
asm/ Locally generated disassembly, not tracked
progress/report.json objdiff-format progress report read by decomp.dev

decomp.dev

.github/workflows/progress.yml validates progress/report.json and uploads it as the artifact SCUS_974.65_report. The report is generated locally by python3 tools/gen_progress_report.py and committed with each change, because CI cannot build the game (the compiler and the executable cannot be redistributed). CI fails if the report disagrees with src/.

Contributing

Contributions are welcome: see CONTRIBUTING.md. A good first step is a small function from asm/nonmatchings/, a draft from m2c, and tools/diff_func.py to compare it with retail.

Resources

Credits

Full list with what each was used for: docs/CREDITS.md.

  • GFI (Game Fuckery Inc.): Special thanks to the GFI Discord server for the years of time spent researching and exploring these games, which helped make this decompilation possible.
  • rac1-decomp: project layout, workflow, toolchain research, and the assembler passes.
  • ratchet-uya-decomp: compiler flags (-fopt-stack, -G8) and global-declaration findings.
  • OpenRAC: sibling decompilations of the same engine family.
  • wrench: documentation of the packed image format and the executable's layout.
  • GCC and newlib: the library sources in src/libgcc/ and src/libm/.
  • AngheloAlf: PS2 toolchain mirrors.
  • splat, spimdisasm, m2c, asm-differ, objdiff and decomp.dev.

License

The original work in this repository is MIT licensed (LICENSE). Files under src/libgcc/ and src/libm/ keep their own licenses, stated in their headers (GPL with the libgcc exception, and the Sun/fdlibm notice).

About

Matching decompilation of Ratchet: Deadlocked (2005, PS2)

Resources

Contributing

Stars

3 stars

Watchers

1 watching

Forks

Contributors

Languages