Recover a calculation.
Follow the evidence.

Use DX-Ball’s sound panning to see how an agent moves from a binary to an explanation and a checked C function.

A position becomes a sound

In DX-Ball, a brick hit supplies a horizontal screen position. The sound code turns it into a left/right panning value. We want to recover that calculation from the executable.

The starting function, 0x00406400, has a short decompiler result: a call to __ftol(). REA also returns its instructions and callers, which give the agent a way to investigate the missing arithmetic.

Three pieces of evidence, one calculation

  1. 01 · InstructionsAn integer inputA stack read supplies the value used by the floating-point instructions.
  2. 02 · CallerA screen coordinateThe brick-hit caller passes 20 + 30 × tile_x.
  3. 03 · Data bytesThe numeric constantsReferenced bytes decode to 1.5625, 500.0 and a scale value.

pan = (x × 1.5625 − 500.0) × scale

REA supplies the instructions, call relationship and bytes. The agent interprets them together.

Ask about the behavior

After connecting REA to your agent, provide the local executable and a question:

Your coding agent

Use REA to find how DX-Ball calculates sound panning. Explain the calculation and show the code.

Example prompt. Give your agent the path to your local DX-Ball 1.07 executable.

You can start with a feature name. Your agent uses REA to locate relevant functions, then follows the evidence with more focused queries.

Follow what REA returns

Read the input

REA instruction excerpt · 0x406409
MOV EAX, dword ptr [EBP + 0x8]
MOV dword ptr [EBP + -0xc], EAX
FILD dword ptr [EBP + -0xc]

The instructions load an integer argument and convert it for floating-point arithmetic. This is the input absent from the first pseudocode view.

Follow the caller

REA caller excerpt · 0x411f5b
ADD EAX, 0x14
PUSH EAX
CALL 0x00406400

REA identifies the brick-hit caller. Its earlier instructions multiply the tile coordinate by 30; adding 0x14 (20) gives the brick's screen position.

Read the referenced constants

REA byte results · interpreted as little-endian doubles
0x420068  000000000000f93f  → 1.5625
0x420070  0000000000407f40  → 500.0
0x4210a0  000000000000f03f  → 1.0

The arithmetic references these addresses. Reading the bytes supplies the actual values; the instruction order tells the agent how they are used.

Write and check the recovered function

Recovered C · excerpt
pan = (double)x;
pan = pan * 1.5625;
pan = pan - 500.0;
pan = pan * dxball_pan_scale;
return (DxBallInt)pan;

With a scale of 1.0, screen positions 0, 320 and 640 map to −500, 0 and 500 before integer conversion. The calculation puts the center of the screen at the center of the stereo field.

The agent used REA's findings to write the C. Separate checks compared 3,205 inputs against the original x86 function and reproduced all 63 compiled bytes of the complete function.

See the full investigation and assembly-to-C comparison

Try it with your own binary

Connect a native analysis provider, then give your agent a local executable or library and a feature to investigate. Useful starting questions include “How is this file parsed?” or “Which function handles this menu action?”

If you already know a function name or address, you can query it from the terminal. For a configured Ghidra installation:

Function analysis
npx -y rea-agents@latest function /absolute/path/to/program main \
  --provider ghidra --json

Replace the target path and main with your own function name or address. Each CLI invocation imports and analyzes the binary, then closes its session. Your agent's MCP queries reuse the imported binary while that session is open.

Read the pseudocode alongside instructions and references. When a result leaves a call or value unresolved, use that location as the next question.