It turns out that the offsets of the data in the return buffer matter: the offset 0x340 is hardcoded into the code that uses the result. With that fixed, get rid of the completely wrong 0x80000000 hack.