import ctypes, struct
from ctypes import wintypes

k32 = ctypes.WinDLL('kernel32', use_last_error=True)
psapi = ctypes.WinDLL('psapi', use_last_error=True)

class MODULEINFO(ctypes.Structure):
    _fields_ = [
        ("lpBaseOfDll", ctypes.c_void_p),
        ("SizeOfImage", wintypes.DWORD),
        ("EntryPoint", ctypes.c_void_p),
    ]

pid = 49116
h = k32.OpenProcess(0x410, False, pid)
if not h:
    print('OpenProcess failed')
    exit(1)

base = 0x7ff6afc20000
size = 0x4c9e000
print(f"Base: {base:#x}, Size: {size:#x}")

def rpm_chunked(addr, total_size, chunk_size=65536):
    res = bytearray()
    for off in range(0, total_size, chunk_size):
        curr_addr = addr + off
        to_read = min(chunk_size, total_size - off)
        buf = (ctypes.c_ubyte * to_read)()
        got = ctypes.c_size_t(0)
        if k32.ReadProcessMemory(h, ctypes.c_void_p(curr_addr), buf, to_read, ctypes.byref(got)):
            res.extend(buf[:got.value])
        else:
            res.extend(b"\x00" * to_read)
    return bytes(res)

text_size = 0x2E86000 # .text section size
print(f"Reading {text_size // 1024 // 1024}MB of .text starting at {base+0x1000:#x}...")
blob = rpm_chunked(base + 0x1000, text_size)
print(f"Read {len(blob)} bytes")

# Find all occurrences of movss xmm, [reg+0x2C] / movss xmm, [reg+0x34]
print("\n--- Scanning for Camera distance instructions ---")
for i in range(0, len(blob) - 16):
    if blob[i:i+3] == b"\xF3\x0F\x10" and blob[i+4] == 0x2C:
        va = base + 0x1000 + i
        window = blob[max(0, i-32):min(len(blob), i+32)]
        if 0x34 in window and (b"\x0F\x2F" in window or b"\x0F\x2E" in window):
            print(f"Hit @ {va:#x}: {blob[i:i+16].hex()}")
            print(f"   Context: {blob[max(0, i-16):min(len(blob), i+32)].hex()}")
