import ctypes
import struct

PROCESS_ALL_ACCESS = 0x1F0FFF
kernel32 = ctypes.windll.kernel32
hProc = kernel32.OpenProcess(PROCESS_ALL_ACCESS, False, 43084)

def rpm(addr, size):
    buf = (ctypes.c_char * size)()
    read = ctypes.c_size_t()
    if kernel32.ReadProcessMemory(hProc, ctypes.c_uint64(addr), buf, size, ctypes.byref(read)):
        return bytes(buf[:read.value])
    return b""

def rpm_u64(addr):
    b = rpm(addr, 8)
    return struct.unpack("<Q", b)[0] if len(b) == 8 else 0

def rpm_u32(addr):
    b = rpm(addr, 4)
    return struct.unpack("<I", b)[0] if len(b) == 4 else 0

def rpm_f32(addr):
    b = rpm(addr, 4)
    return struct.unpack("<f", b)[0] if len(b) == 4 else 0.0

area_instance = 0x2AFF1831800
ptrs = [
    (0x288, 0x2AFF082C9D0),
    (0x2A0, 0x2AFF0820D10),
    (0x2B8, 0x2AFF082DF10),
    (0x2D0, 0x2AEF1E25990),
    (0x2E8, 0x2AEF1E2A0D0),
    (0x300, 0x2AFF0824190),
    (0x318, 0x2AEF1E27C90),
    (0x330, 0x2AEF1E22A10),
    (0x348, 0x2AEF1E2D550),
    (0x360, 0x2AEF1E273D0),
    (0x390, 0x2AEF1E2C010),
    (0x3A8, 0x2AEF1E20FD0),
    (0x3D8, 0x2AEF1E23A50),
    (0x3F0, 0x2AEF1E22010),
    (0x408, 0x2AEF1E23910),
    (0x420, 0x2AEF1E28050),
    (0x438, 0x2AEF1E23050),
    (0x450, 0x2AEF1E241D0),
    (0x468, 0x2AEF1E20AD0),
    (0x480, 0x2AEF1E2E310),
    (0x498, 0x2AEF1E26610),
]

for off_ai, ptr in ptrs:
    vt = rpm_u64(ptr)
    # Check fields in ptr
    buf = rpm(ptr, 0x100)
    # Find any float or dimension or buffer
    info = []
    for o in range(0, 0x100, 4):
        u = struct.unpack("<I", buf[o:o+4])[0]
        f = struct.unpack("<f", buf[o:o+4])[0]
        if u in (804, 759) or (50 <= u <= 3000 and o % 8 == 0):
            u_next = struct.unpack("<I", buf[o+4:o+8])[0]
            if 50 <= u_next <= 3000:
                info.append(f"dims@{o:X}: {u}x{u_next}")
        if 0.2 <= f <= 5.0 and f not in (1.0, 2.0):
            info.append(f"float@{o:X}: {f:.3f}")
    print(f"AI+0x{off_ai:03X} -> 0x{ptr:X} (vt=0x{vt:X}) {info}")

kernel32.CloseHandle(hProc)
