A position becomes a sound
In DX-Ball, a brick hit supplies a horizontal screen position. The sound code turns it into a left/right panning value. We want to recover that calculation from the executable.
The starting function, 0x00406400, has a short
decompiler result: a call to __ftol(). REA also
returns its instructions and callers, which give the agent a way
to investigate the missing arithmetic.
Three pieces of evidence, one calculation
- 01 · InstructionsAn integer inputA stack read supplies the value used by the floating-point instructions.
-
02 · CallerA screen coordinateThe brick-hit caller passes
20 + 30 × tile_x. -
03 · Data bytesThe numeric constantsReferenced bytes decode to
1.5625,500.0and a scale value.
pan = (x × 1.5625 − 500.0) × scale
Ask about the behavior
After connecting REA to your agent, provide the local executable and a question:
Use REA to find how DX-Ball calculates sound panning. Explain the calculation and show the code.
Example prompt. Give your agent the path to your local DX-Ball 1.07 executable.
You can start with a feature name. Your agent uses REA to locate relevant functions, then follows the evidence with more focused queries.
Follow what REA returns
Read the input
MOV EAX, dword ptr [EBP + 0x8]
MOV dword ptr [EBP + -0xc], EAX
FILD dword ptr [EBP + -0xc]
The instructions load an integer argument and convert it for floating-point arithmetic. This is the input absent from the first pseudocode view.
Follow the caller
ADD EAX, 0x14
PUSH EAX
CALL 0x00406400
REA identifies the brick-hit caller. Its earlier instructions
multiply the tile coordinate by 30; adding 0x14 (20)
gives the brick's screen position.
Read the referenced constants
0x420068 000000000000f93f → 1.5625
0x420070 0000000000407f40 → 500.0
0x4210a0 000000000000f03f → 1.0
The arithmetic references these addresses. Reading the bytes supplies the actual values; the instruction order tells the agent how they are used.
Write and check the recovered function
pan = (double)x;
pan = pan * 1.5625;
pan = pan - 500.0;
pan = pan * dxball_pan_scale;
return (DxBallInt)pan;
With a scale of 1.0, screen positions 0, 320 and 640 map to −500, 0 and 500 before integer conversion. The calculation puts the center of the screen at the center of the stereo field.
The agent used REA's findings to write the C. Separate checks compared 3,205 inputs against the original x86 function and reproduced all 63 compiled bytes of the complete function.
Try it with your own binary
Connect a native analysis provider, then give your agent a local executable or library and a feature to investigate. Useful starting questions include “How is this file parsed?” or “Which function handles this menu action?”
If you already know a function name or address, you can query it from the terminal. For a configured Ghidra installation:
npx -y rea-agents@latest function /absolute/path/to/program main \
--provider ghidra --json
Replace the target path and main with your own
function name or address. Each CLI invocation imports and analyzes
the binary, then closes its session. Your agent's MCP queries
reuse the imported binary while that session is open.
Read the pseudocode alongside instructions and references. When a result leaves a call or value unresolved, use that location as the next question.