BLOODBORNE ARCHIPELAGO — RELEASE REMEDIATION REPORT Release: 0.2.0-remediation.1, Windows x64 Date: 10 October 2026 SCOPE AND STATUS This report describes the replacement Python-based Bloodborne AP launcher bundle. It is a new unsigned remediation build, not the withdrawn Qt BBLauncher binary. It includes the matching bloodborne.apworld, AP client, native tools, and source and notice materials described below. The old Qt, standalone, and Linux downloads are not restored by this publication. This is a technical report based on source inspection, package inspection, and local automated tests. It is not a legal certification, a claim of permission from the game's rights holders, or a claim that earlier distributions have been retroactively repaired. It was prepared with automated build and audit tooling. 1. GAME-DERIVED EVENT SCRIPTS AND INPUTS The replacement build no longer packages the identified decompiled event-script research tree or the legacy event catalog containing original event bodies. Enemy and boss preparation uses native readers/writers and authored patch plans to read the player's installed game data locally. It does not require a separate DarkScript installation for this path. Patched game files are local outputs for the player's installation, not inputs shipped inside this launcher download. The packaging audit rejects known game archive extensions, extracted event scripts, the legacy native-event catalog, complete serialized instruction records, and identified extracted table/database payloads. It recursively checks ZIP-like containers. A reviewed .NET source archive is accepted only at its exact recorded SHA-256; its upstream test data is not Bloodborne game data. This check is a regression aid, not a proof that every possible copyrighted byte can be recognized. Authored integration data, identifiers, offsets, short hook signatures, and patch descriptions remain where needed for interoperability. Nothing in the project's MIT license purports to license the underlying game. Public repository history and older releases are separate remediation matters; this report does not claim that history has been erased. 2. GPL-LINKED NATIVE TOOLS The C# tools link SoulsFormatsNEXT. The replacement explicitly distributes those combined executables under GPLv3, retains the original code's MIT grant, and includes the GPL text, notices, source, build recipes, and output receipts. The root MIT license is not presented as relicensing third-party components. The active SoulsFormats dependency was migrated to the GPL-bearing upstream soulsmods/SoulsFormatsNEXT revision: f2192ec0de9ec81b975cc5e622481daad0945d67 The build profile removes unused BouncyCastle and the unreviewed texture-converter dependencies, limits texture operations to the PC profile, and repairs zero-row PARAM handling. Compression API changes were propagated to the consumers; an interface/boxed-value comparison in the item writer was also corrected. The profile records the source changes. This does not establish a license grant for additional code in the previously used fork. The five source-bound executables are: - BBEnemizerWriter.exe - BBSuppressionWriter.exe - BBEventWriter.exe - BBToastWriter.exe - MSBBMiner.exe Their source snapshot is at tools/source-native. It includes 590 source/material files, original dependency licenses, the modified upstream profile, the build recipes, and source-manifest.json with executable hashes and publish commands. The .NET runtime source ZIP inside that snapshot contains the original upstream source/build scripts and is separately pinned by its full content hash. 3. COMPRESSION, .NET, AND WINDOWS RUNTIME MATERIALS ZstdNet 1.4.5 and zstd 1.4.5 are built from pinned source, instead of relying on an unexplained precompiled native DLL from the dependency package. The native and managed source trees, notices, build recipes, and acceptance records accompany the native snapshot. This includes zstd's separate libdivsufsort-lite MIT notice. The .NET 9.0.20 runtime package is bound to its original package hash and source revision 3879076d9a06ce098d37c3882fb1845a6627335b. Its source ZIP preserves the verified upstream Git tree; the preparation recipe records necessary line-ending normalization. The 187 extracted runtime package inputs were checked against the pinned package archive. Including exact runtime source is not a claim that this release rebuilt Microsoft's complete runtime from source. App-local VC runtime DLLs are copied from the Visual Studio 2022 x64 release redistributable after validating Microsoft's signature. Product, versions, file hashes, and redistribution terms are included. The AP client now receives its own adjacent VCRUNTIME140.dll; the Python application's internal copy was not a sufficient packaging arrangement for that separate executable. Eight runtime copies are recorded in this package. CPython, PyInstaller and its distribution exception, Tcl/Tk, OpenSSL, and zlib notices are retained under licenses. The collection checks the selected runtime versions and the recorded notice hashes. 4. AP CLIENT SOURCES AND THIRD-PARTY NOTICES The client is built from reviewed revision: 6d537f2141567607625b69ececac3d2d5feb9f9b The source and materials bundle at tools/source-client is bound to the exact client executable hash. It contains 771 files, including: - The five compiled workspace crates, their original licenses, a reduced workspace manifest, the original manifest/lockfile, and a source preparation recipe. - All 226 original registry source archives matched to Cargo.lock checksums. - Discovered original notices, plus recovered exact-upstream-revision notices for 13 registry crates whose published archives omitted their license files. - MPL-2.0 license text and original source archives for dynasm and dynasmrt. - Font-specific notices, including OFL and Ubuntu font-license material. - The pinned tungstenite Git source archive and original notices. - AWS-LC's aggregate notices, including vendored components, and the complete original crate sources retaining their file-level notices. - The build receipt and original Rust standard-library copyright inventory. The registry review compared 11,271 archived source files with the extracted build inputs. The workspace source profile was independently rebuilt earlier with the same dependency identities and compile-feature signatures; that rebuild was not byte-identical, and is not represented as a reproducible-binary proof. Rust is fixed to nightly-2026-09-30, compiler commit 5c543b0b8c73c7b72bc8284ced4fb22ead15734d. The compiler and standard-library archives matched the installed toolchain manifest's SHA-256 values. Ninety-three installed files were compared with those archives, including all 13 preserved notice files. The collector refuses a different compiler receipt or changed notice bytes. 5. REPEATABLE BUILD AND PACKAGING CHECKS The release, test, and local package paths now use a shared client build/material step. The client build uses a locked dependency graph and stamps its source revision. Launcher packaging requires a matching client revision and material bundle; the copied package is checked again after inclusion. Native source and binary receipts are verified independently. Client materials have a complete hashed inventory. Packaging retains runtime provenance, emits a whole-package file manifest, and rejects the identified extracted-game payloads. These checks supplement human review; they do not replace responsibility for the contents of a release. The related workflow edits have been tested locally; hosted GitHub Actions has not been run for this replacement. 6. VALIDATION AND LIMITS Local checks on the preceding complete candidate passed: - All 2,451 package file hashes matched its package manifest. - All five native executable receipts and 590 source/material files verified. - All 771 client source/material files verified against the client executable. - Frozen launcher self-check passed, including construction of the real Tk GUI. - The packaged client accepted the generated 341-item, 657-location contract. - Forty-four relevant collector/launcher/workflow tests passed. - A deliberately wrong client revision was refused by the material verifier. - Known extracted-game-payload checks passed. Earlier native integration testing passed 452 enemy assertions and the native event round-trip plus seven refusal cases. Source-built compression passed its native round-trips and 17 managed cases, including executable-only publishing. These are engineering checks, not gameplay observations. The separately attached RELEASE-VERIFICATION.json records verification of the final release-labeled package. SHA256SUMS.txt identifies the published archive, matching AP world, report, and verification data. Live Bloodborne/shadPS4 gameplay and a complete multiworld session have not been rerun on this release. The new build is unsigned. The Qt fork, other platforms, standalone randomizer publication, other repositories, and historical distribution questions are outside this release's completion claim. 7. REVIEWING THE DOWNLOAD The ZIP includes this report, the client notice-coverage inventory, LICENSING.md, licenses/, tools/source-client/, and tools/source-native/. Review those materials alongside package-manifest.json rather than relying on a GitHub link alone. The source remains available inside the download even while the GitHub account is unavailable. No claim is made that merely linking an inaccessible repository satisfied source availability for a past release.