Byrgenwerth
Bloodborne
Paleblood is a decompilation of Bloodborne with its own runtime, one verified function at a time
We are born of the blood, made men by the blood, undone by the blood. Our eyes are yet to open… Fear the old blood.Master Willem / The Blood Minister
Paleblood is a decompilation of Bloodborne (PS4, CUSA03173, version 1.09) with its own runtime: a functional decompilation, the game's code rewritten function by function as readable C++ that does exactly what the original did, and a runtime of our own for that code to run on.
The game doesn't run on Paleblood yet: 21 of 157,757 functions are verified (0.01%). On our own runtime the executable's boot gets as far as scePthreadAttrGetaffinity (libkernel, called by libc.elf), with 238 of 686 system imports provided.
Transition in progress
Paleblood is becoming a decompilation with its own runtime: the borrowed runtime (bbport, with the shadPS4 graphics code it carries) is being removed, and the game won't run on Paleblood until our own runtime is far enough along. Some pages still describe the old setup while they are updated. See the announcement and the Runtime page.
This project is not affiliated with or endorsed by Sony Interactive Entertainment or FromSoftware in any way.
Why we do this
Because we love this game. Yharnam deserves to outlive the hardware it was made for, and to be understood as well as it is loved: every function of the original, read, named, rewritten and proved to behave exactly as it did, so that one day it runs natively, at any frame rate, for as long as there are hunters to play it.
The goal
A complete source port of Bloodborne for the PC. When the hunt is over, every function of the game's 1.09 executable will have been rewritten as readable C++ and proved to behave exactly like the original, and the game will run natively on Paleblood's own runtime: no PS4, no emulator, no original executable, only the game's data from your own copy. Because it will be source, the game can be read, understood, preserved, fixed and modded like any other program, at any frame rate and resolution.
Two tracks get there, side by side:
- Decompilation: functions rewritten as readable C++ and proved against the original in the verification harness, on inputs recorded earlier and on generated edge cases.
- Runtime: our own loader (done), then generic input capture, kernel, threads and memory, files, input, audio, video out, and the graphics, rebuilt at the engine's own level rather than by emulating the PS4's GPU (Runtime).
The game does not run on Paleblood until the runtime is far enough along that road.
A place to learn
This wiki is also an educational resource, and that is one of its most important jobs. Every page is written so that someone who has never taken a game apart can follow how it is done, and see why each step is taken, not only what was found. You do not need a console, a dump or any game files to read and learn from it; the project only ever shows how the game's code works, in our own words and our own code.
What you can learn here:
- How a console game is put together: the PS4 executable and its libraries, how the game's frame loop paces itself, how its systems (timing, input, rendering, AI, characters) talk to each other. Start with Architecture and How the Frame Limiter Works.
- Reverse engineering in practice: reading disassembly, telling what a function does from its callers, callees and the memory it touches, and the traps in the tools (Ghidra & PS4 Quirks, the system pages).
- Proving code correct: how a rewritten function is checked against the original on real and hand-made inputs, and why deliberately wrong versions must fail (Architecture: Verification).
- The words: every term of the trade, explained in the Glossary; hover a dotted term anywhere for its meaning.
The devlog tells the same story as it happened, mistakes included.
Start here
Reference
Where the work is
| Functions | Bytes | |
|---|---|---|
| Target (Ghidra export) | 157,757 | 42,487,347 |
| Replaced | 30 (0.02%) | 15,176 (0.04%) |
| Edge-verified | 21 (0.01%) | 14,010 (0.03%) |
| Verified | 21 (0.01%) | 14,010 (0.03%) |
Each row includes the next: verified functions are also edge-verified and replaced.
| System | Tracked | Replaced | Edge-verified | Verified | Replaced bytes |
|---|---|---|---|---|---|
| ai | 1 | 1 | 1 | 1 | 2,693 |
| audio | 0 | 0 | 0 | 0 | 0 |
| camera | 0 | 0 | 0 | 0 | 0 |
| character | 1 | 1 | 1 | 1 | 979 |
| event | 1 | 1 | 1 | 1 | 368 |
| frame_timing | 22 | 21 | 12 | 12 | 5,447 |
| input | 1 | 1 | 1 | 1 | 426 |
| kernel | 1 | 1 | 1 | 1 | 204 |
| loading | 0 | 0 | 0 | 0 | 0 |
| physics | 1 | 1 | 1 | 1 | 3,222 |
| render | 3 | 3 | 3 | 3 | 1,837 |
Generated by tools/sync_progress.py from the code repo. Do not edit.
The executable's code, slice by slice, is on the Address Map; every tracked function with its status is on its system page.
Key documents
| Document | What it covers |
|---|---|
| Architecture | The two tracks, the verification harness, the frame pipeline |
| Runtime | Our own runtime: the roadmap and how far the game's executable boots on it |
| How the Frame Limiter Works | The first system replaced, step by step |
| Glossary | PS4 and project terms explained |
| Ghidra & PS4 Quirks | Traps in the tools and the ABI |
| Contributing | Joining, the first pull request, the rules |
Methodology
Each function goes through five steps before it is marked verified:
- Analyze — Ghidra with the GhidraOrbis loader finds the function in your own dump; its callers, callees and the memory it touches are read from the disassembly, not only the decompiler.
- Name — it gets a name and a system in the shared function table, so every contributor's Ghidra shows the same names.
- Rewrite — a readable C++ version: named structures instead of raw offsets, named calls instead of addresses, named constants, faithful to what the original does.
- Verify — the harness runs the original and the replacement on the same inputs, recorded in earlier game runs and generated for the corners, and compares return values, registers, every byte written and every library call. Deliberately wrong versions must fail.
- Review — an independent reviewer checks the verification and the readability. A function whose code no recording reaches yet is edge-verified until one does.
Legal
Tools and source only — no game files, no extracted assets, no decompiler dumps. Everything starts from your own console and your own copy: to contribute or verify you need Bloodborne (CUSA03173, EU) with the 1.09 update, dumped from your own PS4. The project does not provide or point to game files, pkgs, firmware, keys or decryption tools.
Loaded image SHA-256 of the target executable: