Skip to main content
Glama
AstralVoidZ
by AstralVoidZ

ppsspp_query

Read-onlyIdempotent

Query PPSSPP debug state—game status, CPU registers, backtrace, threads, modules, and HLE functions—to inspect execution or manage function tracking during emulator debugging.

Instructions

PURPOSE: Aggregate game-state queries — game_state, registers (all or one), backtrace, threads, modules, and function-list management (funcs/func_scan/func_add/func_remove).

USAGE: action + session_id; 'register' needs name; func_scan/func_remove need address; top_n defaults to 100 (pass 0 for the full list — hle.func.list can reach 700+KB).

ROUTING: one-shot PC read -> query(action='register', name='pc') (safe=true pauses for consistency; safe=false for hot-path polling); pause+capture -> ppsspp_frame_snapshot; recurring named probes -> ppsspp_state_observer; game_state / backtrace / threads / modules / HLE func management also here. BEHAVIOR: READ-ONLY. Lookups only — func_add/func_remove mutate the debugger function list. Verified on a live game: threads / modules / funcs / func_scan respond while the CPU is RUNNING (no pause needed); running-state PC/isCurrent reads are LOW trust unless safe=true (which pauses briefly for a consistent, high-trust read).

RETURNS: {action, data, trust_level} — data shape depends on the action.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
nameNoRequired for action='register' (the register name to read) and for action='func_add'. Ignored by func_remove because PPSSPP's hle.func.remove protocol does not accept a name parameter.
safeNoaction=register/registers only: pause the CPU for a consistent read (trust_level='high', same as the retired ppsspp_get_pc) — or read without pausing (trust_level='low', zero cost, racy while running; for hot-path polling).
sizeNoFunction size in bytes, 'func_add' only. When omitted the server sends no size — on PPSSPP builds where the omit path underflows (v1.20.4-1845 and earlier) this produces an unusable zero-size function, so this tool defaults to sending 4. Pass an explicit size to override.
top_nNoLimit the number of entries returned for 'funcs' / 'func_scan' actions (default 100). 0 = no limit — hle.func.list can reach 700+KB, pass 0 only when the full list is genuinely needed.
actionYesQuery action. Valid values: - 'game_state': PPSSPP game status (paused / game title). - 'registers': all CPU registers (GPR + FPU + VFPU). - 'register': single register by name (MIPS ABI name like 'a0'/'v0'/'t9', or 'pc'/'hi'/'lo'). - 'backtrace': HLE call stack (thread optional). - 'threads': PSP thread list (safe: stepping → query → resume). - 'modules': list all loaded HLE modules. - 'funcs': list registered HLE function tracking entries. - 'func_scan': scan HLE functions in a 64KB range starting at address (requires address; CPU must be stepping). - 'func_add': add HLE function tracking (name? and/or address?). - 'func_remove': remove HLE function tracking (address required; PPSSPP protocol only accepts address, no name).
threadNoThread ID (backtrace action only; None = current).
addressNoRequired for func_remove and func_scan. Function address as a hex string (e.g. '0x08804000'). Not used by the other actions. The schema default of '0x0' exists for legacy callers -- do NOT rely on it when the action is one of the above.0x0
session_idYesActive session ID.

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
dataYesRaw result payload.
textYesUnified text representation. Populated for action='registers' with grouped '── GPR ──' / '── FPU ──' / '── VFPU ──' headers and ' name = 0xVAL' lines, and for action='register' with a single 'name = 0xVAL' line (the requested register name echoed with its hex value). Empty for other actions (use the structured `data` field).
actionYes'game_state' / 'registers' / 'backtrace' / 'threads' / 'modules' / 'funcs' / 'func_scan' / 'func_add' / 'func_remove'.
trust_levelYesTrust annotation (threads + pc only). Lowercase enum value: 'high' (stepping-verified) / 'medium' / 'low'.

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed3 schema fields changedv0.1.7
    • changedInput schema / properties / address / description
      Previous value: -"Function address as a hex string (e.g. '0x08804000'). Required for func_remove and func_scan."New value: +"Required for func_remove and func_scan. Function address as a hex string (e.g. '0x08804000'). Not used by the other actions. The schema default of '0x0' exists for legacy callers -- do NOT rely on it when the action is one of the above."
    • changedInput schema / properties / name / description
      Previous value: -"Function name (func_add only; ignored by func_remove because PPSSPP's hle.func.remove protocol does not accept a name parameter)."New value: +"Required for action='register' (the register name to read) and for action='func_add'. Ignored by func_remove because PPSSPP's hle.func.remove protocol does not accept a name parameter."
    • changedOutput schema / properties / text / description
      Previous value: -"Unified text representation. Populated for action='registers' with grouped '── GPR ──' / '── FPU ──' / '── VFPU ──' headers and '  name = 0xVAL' lines. Empty for other actions (use the structured `data` field)."New value: +"Unified text representation. Populated for action='registers' with grouped '── GPR ──' / '── FPU ──' / '── VFPU ──' headers and '  name = 0xVAL' lines, and for action='register' with a single 'name = 0xVAL' line (the requested register name echoed with its hex value). Empty for other actions (use the structured `data` field)."
  2. Changed2 schema fields changedv0.1.6
    • addedInput schema / properties / safe
      Added value: +{
      +  "default": true,
      +  "description": "action=register/registers only: pause the CPU for a consistent read (trust_level='high', same as the retired ppsspp_get_pc) — or read without pausing (trust_level='low', zero cost, racy while running; for hot-path polling).",
      +  "title": "Safe",
      +  "type": "boolean"
      +}
    • addedInput schema / properties / size
      Added value: +{
      +  "anyOf": [
      +    {
      +      "type": "integer"
      +    },
      +    {
      +      "type": "null"
      +    }
      +  ],
      +  "default": null,
      +  "description": "Function size in bytes, 'func_add' only. When omitted the server sends no size — on PPSSPP builds where the omit path underflows (v1.20.4-1845 and earlier) this produces an unusable zero-size function, so this tool defaults to sending 4. Pass an explicit size to override.",
      +  "title": "Size"
      +}
  3. First observedv0.1.0

TDQS

A4.8/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Goes well beyond the annotations: it discloses that threads/modules/funcs/func_scan respond while the CPU is RUNNING without a pause, that running-state PC reads are LOW trust unless safe=true, and that func_add/func_remove mutate the debugger-side function list (a nuance annotations alone would not convey). It also notes top_n=0 can produce a 700+KB payload, which is real behavioral context for an agent.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with PURPOSE/USAGE/ROUTING/BEHAVIOR/RETURNS headers, so an agent can skim. It is dense but largely earns its length; a few clauses (e.g. the 'same as the retired ppsspp_get_pc' aside) restate what the annotation or schema already implies.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With an output schema present, the description need not document return fields, and it correctly just lists {action, data, trust_level}. Given 10 actions, 8 parameters, and an enum, the routing, prerequisites, trust-level semantics, and mutation caveats together make this complete enough to call correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is already 100%, so the baseline is 3, but the description adds genuine value: top_n's default and the rationale for pass-0 (700+KB hle.func.list), the safe flag's effect on trust_level, and which actions require name/address. It stops short of explaining the output data shape per action.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The PURPOSE line names a specific verb (aggregate queries) and enumerates the concrete resources covered — game_state, registers, backtrace, threads, modules, and HLE function-list management. Combined with the ROUTING section, an agent can distinguish this multi-action query tool from ppsspp_frame_snapshot and ppsspp_state_observer without opening any schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The ROUTING block gives explicit when-to-use-this vs when-to-use-a-sibling guidance: one-shot PC read -> query(action='register', name='pc'), pause+capture -> ppsspp_frame_snapshot, recurring probes -> ppsspp_state_observer. It also states the per-action parameter prerequisites (name for 'register', address for func_scan/func_remove) and the safe=true/false tradeoff for PC reads.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.