Compare commits

...
3 Commits
12 changed files with 217 additions and 110 deletions

No files matched your search

+23 -5
View File
@@ -554,11 +554,29 @@ passes stance selection (NewtonVR grip/trigger) but its motion warning waits for
which Lepton never delivers (no focused Android window) → ovrpshim registers its own
`UnityEngine.Input::GetMouseButtonDown(System.Int32)` icall (il2cpp_add_internal_call, after Unity's: resolve first)
that adds a click in the frame a Touch trigger or A/B/X/Y is newly pressed (`unity_oculus_check` revision 3).
BattleSisters (Unity 2019 InputSystem/XR InputDevices; libunity polls only Go masks 0x8000000/0x1000000/0x2000000;
device model "Oculus Quest" vs Lepton's "Valve Lepton", ovrp_GetSystemProductName (already "Oculus Quest"),
ovrp_GetNodePresent (hands present after ~2 s, logged by the shim) and missing ovrp_GetControllerState exports were
all ruled out in the headset): buttons still dead; next = find what makes libunity's Oculus input poll only Go
controllers. Accounting+ works (owner, 2026-10-06).
BattleSisters (Unity 2019 InputSystem/XR InputDevices via `VrHandInput`): libunity's Oculus module (OVRPlugin
function table: a global pointer at 0x16b57c0 in this build, slots filled by name, e.g. +0x160 GetControllerState,
+0x168 State2, +0xe8 GetNodePresent) only reports controllers when `strncmp(deviceModel, "Oculus", 6) == 0` (next to
the Go check `deviceModel == "Oculus Pacific"`); Lepton's model is "Valve Lepton" → Go/unknown → only Go masks polled,
buttons dead. `unity_oculus_check` revision 4 (`oculus_model_checks`, Unity 2019 only) turns the 17 compares' length
into 0 (`orr w2, wzr, #6` → `mov w2, #0` after the adrp/add of the "Oculus" literal; the string stays: it is also
Unity's VR device name). Device result: libunity now polls `ovrp_GetControllerState(0x3)` (Touch); buttons in the
headset not yet confirmed. Ruled out before: ProductName, GetNodePresent, the device-model string itself, exports.
Accounting+ works (owner, 2026-10-06).
**Vader Immortal (UE4, GitHub #49, 2026-10-06, headless):** stuck after the intro on an in-game image (the splash
quad ends ~6 s in; then the game's own projection frames, 72 fps, balanced xrBeginFrame/xrEndFrame). Not the Platform
SDK (`frame.ovr_trace`: only user + entitlement, both answered) and not the repack's Frida gadget (OVRPort's
`patch_clean_up_frida` removes its loadLibrary). It **leaks ~430 GPU mappings (/dev/dri/renderD128) and ~20 MB a
second** (6.5 GB + swap after 5 min, then 26 fps): page-fault stacks (perf -e page-faults, offsets resolved with the
process maps + vrclient.so's own symbols; its text segment is at file offset + 0x4000) end in SteamVR's runtime:
`xrBeginFrame → CSxrCompositorOpenVR::BeginFrame → SubmitExplicitTimingData → CVRCompositorSharedTextures::
BeginGPUTimingCommandBuffer` and `xrEndFrame → CVRCompositorClient::SubmitWithArrayIndexAndTime`. Ruled out: the
layer color scale/bias + image layout structs (FrameBridge `strip_color_bias` 1/2, diagnostic), Valve's Vulkan
layers (VK_INSTANCE_LAYERS=""), array swapchains in general (Lucky's Tale/I Am Cat flat). Kernel tracepoints aren't
allowed for steamos. FrameBridge: `layer_debug` logs xrDestroySwapchain and per-5 s xrBeginFrame/xrEndFrame counts;
`frame_balance` (ends an open frame before the next begin) exists but Vader never leaves one open. Next (built,
not yet run: the Frame slept): `layer_debug` also counts xrAcquire/Wait/ReleaseSwapchainImage per 5 s (hooked only
with layer_debug, after the other conditional hooks) to see whether Vader skips a wait or release.
**Lepton storage (2026-09-30):** each app's /sdcard (= /storage/emulated/0 → `<base>/lepton-data/external`) has `Movies`/`Download`/`Documents` symlinked to the Frame's `~/Videos`/`~/Downloads`/`~/Documents` (liblepton/mounting.sh, only if they exist at start); agent v24 `storage_targets` reads that mapping. Android's MediaProvider canonicalises paths to /home/steamos/... and rejects every file ("doesn't appear under [/system/media...]"), `sm list-volumes` is empty: the media index never works, apps must browse folders. Lepton installs with `adb install -g` (runtime permissions granted, MANAGE_EXTERNAL_STORAGE too). Files: `install/files.py`, `frameport frame send|storage`, GUI Files tab (formerly Frame → Send files).
**SteamVR per-app settings (2026-09-30):** editing steamvr.vrsettings while SteamVR runs is lost; the web API (127.0.0.1:27062 /app/setsettings) needs `x-steamvr-secret`. `native/vrsettings` = `fp_vrsettings.exe` (freestanding, OpenVR `FnTable:IVRSettings_003` as a Utility app, loads SteamVR's bin/win64/openvr_api.dll) sets them live and SteamVR persists them: section `steam.app.<shortcut appid>`, keys `preferredRefreshRate` (float) and `motionSmoothingOverride` (0 global, 1 on, 2 off, 3 always). Steam Link (vrlink) lists the Frame's rates 72/80/90/96/108/120/144 in vrserver.txt and follows the per-app preference ("host preferred N Hz"; whether the key is honoured is unverified in-headset yet). Judder metric: vrcompositor.txt session summary dropped + "Timed out. N total" (Stormland: 0 dropped but 313 timeouts in 2 min); fpsVR (`%LOCALAPPDATA%\fpsVR\*.json`, 0.1 ms histograms) gives p99 CPU/GPU ms. `pcvr.steamvr_tuning` (default on, PC only) applies on Play: highest rate whose budget ≥ p99×1.05, at least one step down, smoothing on.
+2 -2
View File
@@ -5,10 +5,10 @@ b5949e9e90e4c51e2733b9f6cd3c857a447552ac7291aec340407c27b034b600 ./arm64-v8a/li
383054f8b3b41dde76d062c71856cd3163655e50009c08454bc1793f393ead65 ./arm64-v8a/libfpg.so
424d8e5cb15608ad627f9415df4c4665efd9358fed3447a5d3765279dc652f6b ./arm64-v8a/libframe_xrshim.so
3bfd1261688ed766c0adb9172f44dd7d41cc6459f26205ce3069f536a52e4ab9 ./arm64-v8a/libglshim.so
899b76382e6d10fe2b594b40fed369d03808a1f3ec7a18ccc05f420c11056aeb ./arm64-v8a/libopenxr_loader_generic.so
abf3533b9d02dc2e10d4849e99d850c2f232b039cc5c8761050bf7e129227c69 ./arm64-v8a/libopenxr_loader_generic.so
1feaeafad467c4cafdf2b018a4d84b0bee200c3f711697b4ce97e66a3ba256ca ./arm64-v8a/libovrplatformcompat.so
32525cd0a9ee3d9993d8871cd6905bdcf22cde4f4ba28f5db6434ce7d6554758 ./arm64-v8a/libvrapi.so
79955f386b4e8d43b36b052f9f838e85310c4234403c31e1b2b3f2e914aa4627 ./armeabi-v7a/libopenxr_loader_generic.so
bdfa906442edd83fc272efe6481e7c99260a0304578788bdcdb739afebb7efcf ./armeabi-v7a/libopenxr_loader_generic.so
1871eae093432d277da4bc751bf5f3269dfcf11f9168260b0c3caadb0dedb19d ./dex/oculusos-stubs.dex
1aa733117cf57ccff7cf23f0425dbfd73b0332a3ef1c905ceeca0ccd0449c4e0 ./linux-arm64/XR_APILAYER_FRAMEPORT_timefix.json
28c2430a02bbd8902c5bfb9562c6fd0e318654f9e05c095bfeb94b0450ab1b07 ./linux-arm64/libxr_frameport_timefix.so
Binary file not shown.
Binary file not shown.
-45
View File
@@ -28,21 +28,6 @@ xrAttachSessionActionSets:
.globl fwd_xrAttachSessionActionSets
.hidden fwd_xrAttachSessionActionSets
fwd_xrAttachSessionActionSets:
.quad frame_unsupported
.text
.p2align 2
.globl xrBeginFrame
.type xrBeginFrame, %function
xrBeginFrame:
adrp x16, fwd_xrBeginFrame
ldr x16, [x16, :lo12:fwd_xrBeginFrame]
br x16
.size xrBeginFrame, .-xrBeginFrame
.data
.p2align 3
.globl fwd_xrBeginFrame
.hidden fwd_xrBeginFrame
fwd_xrBeginFrame:
.quad frame_unsupported
.text
.p2align 2
@@ -403,21 +388,6 @@ xrPathToString:
.globl fwd_xrPathToString
.hidden fwd_xrPathToString
fwd_xrPathToString:
.quad frame_unsupported
.text
.p2align 2
.globl xrReleaseSwapchainImage
.type xrReleaseSwapchainImage, %function
xrReleaseSwapchainImage:
adrp x16, fwd_xrReleaseSwapchainImage
ldr x16, [x16, :lo12:fwd_xrReleaseSwapchainImage]
br x16
.size xrReleaseSwapchainImage, .-xrReleaseSwapchainImage
.data
.p2align 3
.globl fwd_xrReleaseSwapchainImage
.hidden fwd_xrReleaseSwapchainImage
fwd_xrReleaseSwapchainImage:
.quad frame_unsupported
.text
.p2align 2
@@ -523,20 +493,5 @@ xrSyncActions:
.globl fwd_xrSyncActions
.hidden fwd_xrSyncActions
fwd_xrSyncActions:
.quad frame_unsupported
.text
.p2align 2
.globl xrWaitSwapchainImage
.type xrWaitSwapchainImage, %function
xrWaitSwapchainImage:
adrp x16, fwd_xrWaitSwapchainImage
ldr x16, [x16, :lo12:fwd_xrWaitSwapchainImage]
br x16
.size xrWaitSwapchainImage, .-xrWaitSwapchainImage
.data
.p2align 3
.globl fwd_xrWaitSwapchainImage
.hidden fwd_xrWaitSwapchainImage
fwd_xrWaitSwapchainImage:
.quad frame_unsupported
.section .note.GNU-stack,"",%progbits
-3
View File
@@ -1,7 +1,6 @@
// Generated from overport 3.4.3 libopenxr_loader_generic.so exports minus hooked functions.
FORWARD(xrApplyHapticFeedback)
FORWARD(xrAttachSessionActionSets)
FORWARD(xrBeginFrame)
FORWARD(xrBeginSession)
FORWARD(xrCreateAction)
FORWARD(xrCreateActionSet)
@@ -26,7 +25,6 @@ FORWARD(xrGetReferenceSpaceBoundsRect)
FORWARD(xrGetSystem)
FORWARD(xrGetViewConfigurationProperties)
FORWARD(xrPathToString)
FORWARD(xrReleaseSwapchainImage)
FORWARD(xrRequestExitSession)
FORWARD(xrResultToString)
FORWARD(xrStopHapticFeedback)
@@ -34,4 +32,3 @@ FORWARD(xrStringToPath)
FORWARD(xrStructureTypeToString)
FORWARD(xrSuggestInteractionProfileBindings)
FORWARD(xrSyncActions)
FORWARD(xrWaitSwapchainImage)
-51
View File
@@ -34,23 +34,6 @@ xrAttachSessionActionSets:
.globl fwd_xrAttachSessionActionSets
.hidden fwd_xrAttachSessionActionSets
fwd_xrAttachSessionActionSets:
.word frame_unsupported
.text
.p2align 2
.globl xrBeginFrame
.type xrBeginFrame, %function
xrBeginFrame:
ldr ip, 1f
2: add ip, pc, ip
ldr ip, [ip]
bx ip
1: .word fwd_xrBeginFrame - (2b + 8)
.size xrBeginFrame, .-xrBeginFrame
.data
.p2align 2
.globl fwd_xrBeginFrame
.hidden fwd_xrBeginFrame
fwd_xrBeginFrame:
.word frame_unsupported
.text
.p2align 2
@@ -459,23 +442,6 @@ xrPathToString:
.globl fwd_xrPathToString
.hidden fwd_xrPathToString
fwd_xrPathToString:
.word frame_unsupported
.text
.p2align 2
.globl xrReleaseSwapchainImage
.type xrReleaseSwapchainImage, %function
xrReleaseSwapchainImage:
ldr ip, 1f
2: add ip, pc, ip
ldr ip, [ip]
bx ip
1: .word fwd_xrReleaseSwapchainImage - (2b + 8)
.size xrReleaseSwapchainImage, .-xrReleaseSwapchainImage
.data
.p2align 2
.globl fwd_xrReleaseSwapchainImage
.hidden fwd_xrReleaseSwapchainImage
fwd_xrReleaseSwapchainImage:
.word frame_unsupported
.text
.p2align 2
@@ -595,22 +561,5 @@ xrSyncActions:
.globl fwd_xrSyncActions
.hidden fwd_xrSyncActions
fwd_xrSyncActions:
.word frame_unsupported
.text
.p2align 2
.globl xrWaitSwapchainImage
.type xrWaitSwapchainImage, %function
xrWaitSwapchainImage:
ldr ip, 1f
2: add ip, pc, ip
ldr ip, [ip]
bx ip
1: .word fwd_xrWaitSwapchainImage - (2b + 8)
.size xrWaitSwapchainImage, .-xrWaitSwapchainImage
.data
.p2align 2
.globl fwd_xrWaitSwapchainImage
.hidden fwd_xrWaitSwapchainImage
fwd_xrWaitSwapchainImage:
.word frame_unsupported
.section .note.GNU-stack,"",%progbits
+120
View File
@@ -86,6 +86,11 @@ static int foveation_fix = 1;
// hide XR_FB_space_warp: games then render every frame themselves (UE5 Application SpaceWarp flickered on the Frame,
// e.g. Into The Radius 2; OVRPort's patch_disable_space_warp doesn't reach UE5's OpenXR plugin)
static int hide_space_warp = 0;
static int strip_color_bias = 0;
static int frame_balance = 0; // end a still-open frame before the next xrBeginFrame
static int frame_begins, frame_discarded, frame_ends, frame_balanced; // per pacing period (layer_debug)
static int frame_open;
static int sc_acquires, sc_waits, sc_releases, sc_wait_fails; // per pacing period (layer_debug) // drop XrCompositionLayerColorScaleBiasKHR (the runtime's color pass)
static int controller_fix = 1;
static int swapchain_fix = 1;
static int rect_clamp = 1;
@@ -136,6 +141,8 @@ static void read_settings(const char *path) {
if (sscanf(line, "scale=%f", &value) == 1 && value >= 0.5f && value <= 2.0f) scale = value;
if (sscanf(line, "foveation_fix=%f", &value) == 1) foveation_fix = value != 0;
if (sscanf(line, "hide_space_warp=%f", &value) == 1) hide_space_warp = value != 0;
if (sscanf(line, "strip_color_bias=%f", &value) == 1) strip_color_bias = (int)value;
if (sscanf(line, "frame_balance=%f", &value) == 1) frame_balance = value != 0;
if (sscanf(line, "controller_fix=%f", &value) == 1) controller_fix = value != 0;
if (sscanf(line, "swapchain_fix=%f", &value) == 1) swapchain_fix = value != 0;
if (sscanf(line, "rect_clamp=%f", &value) == 1) rect_clamp = value != 0;
@@ -214,6 +221,8 @@ static void initialize(void) {
log_file = fopen(path, "a");
}
if (hide_space_warp) LOG("per-game: hide_space_warp=1 (XR_FB_space_warp hidden, space warp info removed)");
if (strip_color_bias) LOG("per-game: strip_color_bias=%d (layer color scale/bias removed)", strip_color_bias);
if (frame_balance) LOG("per-game: frame_balance=1 (an open frame is ended before the next one begins)");
if (eye_debug || release_wait) LOG("per-game: eye_debug=%d release_wait=%d log_file=%s", eye_debug, release_wait,
log_file ? path : "none");
if (controller_models && *process && !strchr(process, '/')) render_model_init(process);
@@ -515,6 +524,10 @@ XRAPI_ATTR XrResult XRAPI_CALL xrCreateSwapchain(XrSession session, const XrSwap
XRAPI_ATTR XrResult XRAPI_CALL xrDestroySwapchain(XrSwapchain swapchain) {
PFN_xrDestroySwapchain fn = (PFN_xrDestroySwapchain)lookup(active_instance, "xrDestroySwapchain");
if (!fn) return XR_ERROR_FUNCTION_UNSUPPORTED;
if (layer_debug) {
static int logged;
if (logged++ < 200) LOG("layer_debug: xrDestroySwapchain %p", (void *)swapchain);
}
forget_swapchain(swapchain);
surf_on_destroy(swapchain);
flip_on_destroy(swapchain);
@@ -800,6 +813,23 @@ XRAPI_ATTR XrResult XRAPI_CALL xrEnumerateSwapchainImages(XrSwapchain swapchain,
return result;
}
// counted for layer_debug (an app that skips the wait or release keeps runtime resources alive)
XRAPI_ATTR XrResult XRAPI_CALL xrWaitSwapchainImage(XrSwapchain swapchain, const XrSwapchainImageWaitInfo *info) {
PFN_xrWaitSwapchainImage fn = (PFN_xrWaitSwapchainImage)lookup(active_instance, "xrWaitSwapchainImage");
if (!fn) return XR_ERROR_FUNCTION_UNSUPPORTED;
XrResult result = fn(swapchain, info);
__atomic_add_fetch(&sc_waits, 1, __ATOMIC_RELAXED);
if (result != XR_SUCCESS) __atomic_add_fetch(&sc_wait_fails, 1, __ATOMIC_RELAXED);
return result;
}
XRAPI_ATTR XrResult XRAPI_CALL xrReleaseSwapchainImage(XrSwapchain swapchain, const XrSwapchainImageReleaseInfo *info) {
PFN_xrReleaseSwapchainImage fn = (PFN_xrReleaseSwapchainImage)lookup(active_instance, "xrReleaseSwapchainImage");
if (!fn) return XR_ERROR_FUNCTION_UNSUPPORTED;
__atomic_add_fetch(&sc_releases, 1, __ATOMIC_RELAXED);
return fn(swapchain, info);
}
XRAPI_ATTR XrResult XRAPI_CALL xrAcquireSwapchainImage(XrSwapchain swapchain, const XrSwapchainImageAcquireInfo *info,
uint32_t *index) {
PFN_xrAcquireSwapchainImage fn = (PFN_xrAcquireSwapchainImage)lookup(active_instance, "xrAcquireSwapchainImage");
@@ -811,6 +841,7 @@ XRAPI_ATTR XrResult XRAPI_CALL xrAcquireSwapchainImage(XrSwapchain swapchain, co
return XR_SUCCESS;
}
XrResult result = fn(swapchain, info, index);
__atomic_add_fetch(&sc_acquires, 1, __ATOMIC_RELAXED);
if (XR_SUCCEEDED(result) && index) { flip_on_acquire(swapchain, *index); emul_on_acquire(swapchain, *index); }
return result;
}
@@ -1019,9 +1050,39 @@ XRAPI_ATTR XrResult XRAPI_CALL xrLocateViews(XrSession session, const XrViewLoca
return result;
}
// xrBeginFrame: counted for layer_debug. A game that begins a new frame while the previous one is still open
// (never ended) makes the runtime discard it; the Frame's runtime then never recycles that frame's GPU timing
// command buffer (Vader Immortal: ~430 GPU mappings / 20 MB a second). frame_balance ends the open frame first,
// with no layers, as the runtime expects.
static XrTime last_begin_display_time;
XRAPI_ATTR XrResult XRAPI_CALL xrBeginFrame(XrSession session, const XrFrameBeginInfo *info) {
PFN_xrBeginFrame fn = (PFN_xrBeginFrame)lookup(active_instance, "xrBeginFrame");
if (!fn) return XR_ERROR_FUNCTION_UNSUPPORTED;
if (frame_open && frame_balance) {
PFN_xrEndFrame end = (PFN_xrEndFrame)lookup(active_instance, "xrEndFrame");
XrFrameEndInfo empty = {XR_TYPE_FRAME_END_INFO, NULL, last_begin_display_time ? last_begin_display_time
: last_predicted_time,
XR_ENVIRONMENT_BLEND_MODE_OPAQUE, 0, NULL};
XrResult r = end ? end(session, &empty) : XR_ERROR_FUNCTION_UNSUPPORTED;
static int logged;
if (logged++ < 3) LOG("frame_balance: ended an open frame before xrBeginFrame (result %d)", r);
__atomic_add_fetch(&frame_balanced, 1, __ATOMIC_RELAXED);
}
XrResult result = fn(session, info);
__atomic_add_fetch(&frame_begins, 1, __ATOMIC_RELAXED);
if (result == XR_FRAME_DISCARDED) __atomic_add_fetch(&frame_discarded, 1, __ATOMIC_RELAXED);
if (XR_SUCCEEDED(result)) {
frame_open = 1;
last_begin_display_time = last_predicted_time;
}
return result;
}
XRAPI_ATTR XrResult XRAPI_CALL xrEndFrame(XrSession session, const XrFrameEndInfo *info) {
PFN_xrEndFrame fn = (PFN_xrEndFrame)lookup(active_instance, "xrEndFrame");
if (!fn) return XR_ERROR_FUNCTION_UNSUPPORTED;
frame_open = 0;
__atomic_add_fetch(&frame_ends, 1, __ATOMIC_RELAXED);
if (eye_debug) eye_debug_end_frame(session, info);
{ // frame pacing statistics every ~5 s: fps and submitted-vs-predicted display time
static struct timespec start;
@@ -1038,6 +1099,18 @@ XRAPI_ATTR XrResult XRAPI_CALL xrEndFrame(XrSession session, const XrFrameEndInf
if (elapsed >= 5.0) {
LOG("pacing: %.1f fps, displayTime vs predicted: avg %.2f ms, max %.2f ms", frames / elapsed,
drift_sum / (double)frames / 1e6, drift_max / 1e6);
if (layer_debug)
LOG("layer_debug: swapchain images: %d acquired, %d waited (%d not ok), %d released",
__atomic_exchange_n(&sc_acquires, 0, __ATOMIC_RELAXED),
__atomic_exchange_n(&sc_waits, 0, __ATOMIC_RELAXED),
__atomic_exchange_n(&sc_wait_fails, 0, __ATOMIC_RELAXED),
__atomic_exchange_n(&sc_releases, 0, __ATOMIC_RELAXED));
if (layer_debug)
LOG("layer_debug: frames: %d xrBeginFrame (%d discarded), %d xrEndFrame, %d balanced",
__atomic_exchange_n(&frame_begins, 0, __ATOMIC_RELAXED),
__atomic_exchange_n(&frame_discarded, 0, __ATOMIC_RELAXED),
__atomic_exchange_n(&frame_ends, 0, __ATOMIC_RELAXED),
__atomic_exchange_n(&frame_balanced, 0, __ATOMIC_RELAXED));
if (layer_debug)
LOG("layer_debug: input: %d xrSyncActions (%d ok, last %d), %d bool reads, %d pressed",
__atomic_exchange_n(&input_syncs, 0, __ATOMIC_RELAXED),
@@ -1171,6 +1244,48 @@ XRAPI_ATTR XrResult XRAPI_CALL xrEndFrame(XrSession session, const XrFrameEndInf
if (!logged++) LOG("strip_depth: removed depth info from projection layer");
++swapped;
}
{
// XR_KHR_composition_layer_color_scale_bias (1000034000) on the layer itself: logged when its values
// change (layer_debug); with strip_color_bias the runtime never gets it (Vader Immortal: the Frame's
// runtime allocates GPU memory for it every frame and never frees it)
const XrBaseInStructure *head = (const XrBaseInStructure *)layer->next;
const XrCompositionLayerColorScaleBiasKHR *cb = NULL;
for (const XrBaseInStructure *n = head; n; n = n->next)
if (n->type == XR_TYPE_COMPOSITION_LAYER_COLOR_SCALE_BIAS_KHR) cb = (const XrCompositionLayerColorScaleBiasKHR *)n;
if (cb && layer_debug) {
static float last[8] = {-1};
float now[8] = {cb->colorScale.r, cb->colorScale.g, cb->colorScale.b, cb->colorScale.a,
cb->colorBias.r, cb->colorBias.g, cb->colorBias.b, cb->colorBias.a};
static int logged;
if (memcmp(now, last, sizeof(now)) && logged++ < 100) {
LOG("layer_debug: layer type=%d color scale %.2f %.2f %.2f %.2f bias %.2f %.2f %.2f %.2f", layer->type,
now[0], now[1], now[2], now[3], now[4], now[5], now[6], now[7]);
memcpy(last, now, sizeof(now));
}
}
if (cb && strip_color_bias && (layer->type == XR_TYPE_COMPOSITION_LAYER_PROJECTION ||
layer->type == XR_TYPE_COMPOSITION_LAYER_QUAD)) {
const XrBaseInStructure *rest = head; // skip leading color structs; one further down drops the chain
while (rest && rest->type == XR_TYPE_COMPOSITION_LAYER_COLOR_SCALE_BIAS_KHR) rest = rest->next;
for (const XrBaseInStructure *n = rest; n; n = n->next)
if (n->type == XR_TYPE_COMPOSITION_LAYER_COLOR_SCALE_BIAS_KHR) rest = NULL;
if (strip_color_bias > 1) rest = NULL; // 2: the layer's whole extension chain (diagnostics)
if (layer->type == XR_TYPE_COMPOSITION_LAYER_PROJECTION) {
if (layer != (const XrCompositionLayerBaseHeader *)&projections[count])
projections[count] = *(const XrCompositionLayerProjection *)layer;
projections[count].next = rest;
layer = (const XrCompositionLayerBaseHeader *)&projections[count];
} else {
if (layer != (const XrCompositionLayerBaseHeader *)&quads[count])
quads[count] = *(const XrCompositionLayerQuad *)layer;
quads[count].next = rest;
layer = (const XrCompositionLayerBaseHeader *)&quads[count];
}
static int logged;
if (!logged++) LOG("strip_color_bias: removed the color scale/bias from a layer");
++swapped;
}
}
if (hide_space_warp && layer->type == XR_TYPE_COMPOSITION_LAYER_PROJECTION &&
((const XrCompositionLayerProjection *)layer)->viewCount == 2) {
// The game may still attach XrCompositionLayerSpaceWarpInfoFB (1000171000) to its views: OVRPort's
@@ -1464,6 +1579,7 @@ XRAPI_ATTR XrResult XRAPI_CALL xrGetInstanceProcAddr(XrInstance instance, const
HOOK(xrCreateSwapchain)
HOOK(xrDestroySwapchain)
HOOK(xrEndFrame)
HOOK(xrBeginFrame)
HOOK(xrLocateHandJointsEXT)
HOOK(xrGetCurrentInteractionProfile)
HOOK(xrEnumerateInstanceExtensionProperties)
@@ -1480,6 +1596,10 @@ XRAPI_ATTR XrResult XRAPI_CALL xrGetInstanceProcAddr(XrInstance instance, const
}
if (surface_emul) HOOK_AS(xrCreateSwapchainAndroidSurfaceKHR, hook_xrCreateSwapchainAndroidSurfaceKHR)
if (eye_debug || release_wait) HOOK_AS(xrReleaseSwapchainImage, eye_hook_xrReleaseSwapchainImage)
if (layer_debug) { // counters only; every other wait/release hook above takes precedence
HOOK(xrWaitSwapchainImage)
HOOK(xrReleaseSwapchainImage)
}
if (sync_guard || layer_debug) HOOK_AS(xrSyncActions, hook_xrSyncActions)
if (layer_debug) HOOK_AS(xrGetActionStateBoolean, hook_xrGetActionStateBoolean)
if (layer_debug || aim_correction_on() || profile_remap)
+2
View File
@@ -306,6 +306,7 @@
"Download…": "",
"Draws each eye separately; try it when one eye shows a grey or broken picture.": "",
"Drop invalid layers": "",
"Drop layer color fades": "",
"Drop layers whose swapchain failed or whose extension isn't enabled.": "",
"Drop to upload": "",
"Drops Quest-only shared library requirements.": "",
@@ -808,6 +809,7 @@
"Removes Meta's old VR library when the game doesn't need it.": "",
"Removes OVRPort's controller pose offset if controllers look misplaced.": "",
"Removes requirements for Quest-only system parts.": "",
"Removes the color scale/bias (XR_KHR_composition_layer_color_scale_bias) from the game's layers, so the runtime doesn't apply it. The Frame's runtime allocates GPU memory for it every frame without freeing it, e.g. Vader Immortal leaked ~20 MB/s on its loading screen. Fades done this way no longer show.": "",
"Removes the game from the Frame. Saves are kept, so a reinstall picks up where you left off.": "",
"Removes the previous version kept after each reinstall and any leftover uploads. Games and saves aren't touched.": "",
"Removes {title} from this PC's Steam library (Steam restarts once). The game folder isn't touched.": "",
@@ -27,6 +27,46 @@ INPUT_CALLS = ("ovrp_GetConnectedControllers", "ovrp_GetControllerState4", "ovrp
UNITY_INPUT_CALLS = ("ovrp_GetControllerState", "ovrp_GetControllerState2")
ORR_W2_6 = 0x321F07E2 # orr w2, wzr, #6 (strncmp length 6)
MOV_W2_0 = 0x52800002 # mov w2, #0 (strncmp length 0: always equal)
def oculus_model_checks(data: bytes) -> tuple[bytes, int]:
"""Unity's built-in Oculus input only reports controllers on a device whose model starts with "Oculus"
(strncmp(SystemInfo.deviceModel, "Oculus", 6), next to its Oculus Go check "Oculus Pacific"). Lepton's Android is
"Valve Lepton", so BattleSisters got no controller buttons. Every such compare (the literal loaded with adrp/add
right before `orr w2, wzr, #6`) gets length 0, so any device but the Go counts as an Oculus one. The "Oculus"
string itself stays: Unity also uses it as its VR device name."""
import struct
literal = data.find(b"\0Oculus\0") + 1
if literal <= 0:
return data, 0
buf, count = bytearray(data), 0
end = len(data) - len(data) % 4
for at in range(0, end, 4):
if struct.unpack_from("<I", data, at)[0] != ORR_W2_6:
continue
# look back for `adrp xA, page` + `add x1, xA, #off` that computes the literal's address
for back in range(4, 16, 4):
add = struct.unpack_from("<I", data, at - back)[0] if at >= back else 0
if add & 0xFFC00000 != 0x91000000 or add & 0x1F != 1: # add x1, xN, #imm (no shift)
continue
rn, imm12 = (add >> 5) & 0x1F, (add >> 10) & 0xFFF
adrp_at = at - back - 4
adrp = struct.unpack_from("<I", data, adrp_at)[0] if adrp_at >= 0 else 0
if adrp & 0x9F000000 != 0x90000000 or adrp & 0x1F != rn:
continue
imm = ((adrp >> 5) & 0x7FFFF) << 2 | (adrp >> 29) & 3
if imm & (1 << 20):
imm -= 1 << 21
if (adrp_at & ~0xFFF) + (imm << 12) + imm12 == literal:
struct.pack_into("<I", buf, at, MOV_W2_0)
count += 1
break
return bytes(buf), count
class UnityOculusCheck(Patch):
id = "frame.unity_oculus_check"
title = "Unity: start VR without Meta's system apps"
@@ -40,8 +80,9 @@ class UnityOculusCheck(Patch):
"mouse click (Input.GetMouseButtonDown), which Go-era screens wait for (e.g. Accounting+'s motion "
"warning) and which Lepton never delivers.")
order = 45
# 2: frame wait also for Unity 2019 without the Oculus XR Plugin; 3: controller presses as mouse clicks (ovrpshim)
revision = 3
# 2: frame wait also for Unity 2019 without the Oculus XR Plugin; 3: controller presses as mouse clicks
# (ovrpshim); 4: Unity 2019's Oculus device-model checks (Touch controllers on Lepton)
revision = 4
@staticmethod
def _major(a) -> int:
@@ -76,7 +117,10 @@ class UnityOculusCheck(Patch):
return False
data, loops = elf.replace_rodata_string(data, UPDATE, SHIM_UPDATE) if self.legacy_loop(ctx.analysis) \
else (data, 0)
if loops:
if loops and self._major(ctx.analysis) >= 2019: # Accounting+ (2017) reads OVRInput: works without
data, models = oculus_model_checks(data)
if models:
ctx.notes.append(f"libunity.so: {models} Oculus device-model checks accept Lepton's model")
data, nodes = elf.replace_rodata_string(data, NODE, SHIM_NODE)
if nodes:
ctx.notes.append(f"libunity.so: {NODE} -> {SHIM_NODE}")
+5 -1
View File
@@ -16,6 +16,10 @@ SETTINGS = [
("scale", "float", 1.0, "Resolution scale",
"Multiplies the recommended eye-buffer width and height (0.5–2.0). 1.5 ≈ 2.25× pixels."),
("foveation_fix", "int", 1, "Hide Quest foveation", "Hides Quest foveation extensions the Frame runtime lacks."),
("strip_color_bias", "int", 0, "Drop layer color fades",
"Removes the color scale/bias (XR_KHR_composition_layer_color_scale_bias) from the game's layers, so the runtime "
"doesn't apply it. The Frame's runtime allocates GPU memory for it every frame without freeing it, e.g. Vader "
"Immortal leaked ~20 MB/s on its loading screen. Fades done this way no longer show."),
("hide_space_warp", "int", 0, "Turn off space warp",
"Hides XR_FB_space_warp, so the game renders every frame itself instead of half of them plus motion vectors "
"(Application SpaceWarp). For games whose picture flickers or smears on the Frame (e.g. Unreal Engine 5 games "
@@ -255,7 +259,7 @@ UI: dict[str, dict] = {
control=("choice", [(0, "As the game sends it"), (2, "Flat")])),
**{key: dict(group="troubleshooting", level="advanced", control=("switch",)) for key in (
"foveation_fix", "hide_space_warp", "swapchain_fix", "layer_fix", "gl_hide_multiview", "mutable_fix",
"flip_quads", "swap_eyes", "vk_validation", "rect_clamp", "gl_hide_msrtt",
"flip_quads", "swap_eyes", "vk_validation", "rect_clamp", "gl_hide_msrtt", "strip_color_bias",
"strip_depth", "respace_kick", "layer_debug", "eye_debug", "release_wait")},
}
+18
View File
@@ -273,3 +273,21 @@ def test_user_recipes_get_a_catalog_update_offer(tmp_path, monkeypatch):
assert "catalog_update" not in g and g["recipe"]["patches"]["adapter.scale"] == {"value": 0.9}
assert g["recipe"].get("source") != "user" and "adapter.vk_shader_fix" in g["recipe"]["patches"]
def test_oculus_model_checks_accept_any_device_but_the_go():
import struct
from frameport.patches.frame import unity_oculus_check as C
# .text: adrp x1, page(0x1000); add x1, x1, #0x10; orr w2, wzr, #6; bl ... -> strncmp(model, "Oculus", 6)
code = struct.pack("<4I", 0xB0000001, 0x91004021, C.ORR_W2_6, 0x94000000)
other = struct.pack("<4I", 0xB0000001, 0x91008021, C.ORR_W2_6, 0x94000000) # a different string: untouched
data = bytearray(0x2000)
data[0:16], data[16:32] = code, other
data[0x100F:0x1017] = b"\0Oculus\0" # the literal at 0x1010
data[0x1020:0x1028] = b"OculusX\0"
out, n = C.oculus_model_checks(bytes(data))
assert n == 1
assert struct.unpack_from("<I", out, 8)[0] == C.MOV_W2_0 and struct.unpack_from("<I", out, 24)[0] == C.ORR_W2_6
assert out[0x1010:0x1016] == b"Oculus" # the string itself stays (Unity's VR device name)