Region ranking

The ranking rule is visible.

r2b sorts evidence regions with fixed rules. The score controls order only. It is not probability, confidence, severity, or a vulnerability verdict.

CURRENT BEHAVIOR

The same input and tool output produce the same order.

r2b builds regions from analyzer output, sorts them by score and stable ID, removes duplicates, and returns the first six by default.

candidates.sort(key=lambda region: (-region.score, region.id))
regions = dedupe(candidates)[:max_regions]

Entry gets 89 points. Named service symbols, analyzed child files, extracted artifact maps, process launch, and network boundaries can rank above it.

Prompts and next commands are added after selection. A model does not participate in this step.

THE POINT TABLE

The points choose what fits in the brief.

97Named protocol or service symbols
95 / 94Analyzed child / extracted artifact map
93Process launch / child-control imports
90Network ingress / egress imports
89Entry disassembly
87Runtime loading / memory-mapping imports
84Memory and path imports
81Kernel and identity-control imports
40Fallback inventory

Function size and name hints add another fixed rule. Firmware uses a separate table. Targets with at least 32 MiB of code, 1,000 imports, or 5,000 functions are marked broad, and r2b withholds automatic next commands.

What r2b adds

The point table is simple. r2b keeps the source evidence, skipped tools, hashes, a small region capsule, and the exact follow-up command. The score only decides what appears first.

REVIEW WIDTH

Ask more than one question of the same brief.

--width asks several review questions of the same region and evidence IDs, then combines their top regions. Rules mode calls no model. Model and both modes use the configured provider. No mode changes the brief.

r2b review brief.json --mode rules --width 3 --top 2 --json
r2b bundle create ./sample.bin --review-width 3 -o sample.r2br

SEPARATE PASSES

Keep each pass separate until the results are combined.

01

Freeze the evidence

Each pass receives the same region and evidence IDs. Model passes do not receive the point scores.

02

Ask each question

Rules use fixed tag weights. A model must return every known region exactly once and cite registered evidence IDs.

03

Merge the top rows

The overlay records agreement, added regions, rank spread, and the first width that included each region.

04

Choose a follow-up

Review executes no tools. A harness may run a separate verify or one-function decompile command.

r2b review brief.json \
  --mode both --width 3 --top 2 \
  --lens "trace request data to process launch" --json

Unknown, duplicate, or missing region IDs fail closed. ID checks keep the model tied to the record; they do not prove its explanation.

THE LIMIT

More width cannot repair thin evidence.

If another pass adds no region, stop increasing width. Run the verifier, decompile one function, or collect the missing runtime fact.

Harness contract ↗Back to r2brief