phase11: cookbook 172-174 — a missing sign bias, a second swapped-subtraction, and when to decline a row
172: a MISSING sign bias is evidence of a shift, not a division -- the values are non-negative in the source but cc1 cannot know that after a conditional, so the absence of the addiu is the diagnostic. Finding 97 read backwards. 173: the absolute value is a SWAPPED SUBTRACTION (subu with operands exchanged), not negu -- the natural -x is the trap. Second instance of finding 101. 174: the idiom-redundant-by-construction class, and the discipline of declining a row. Worker E decoded 0x800FECF8 -- one of the highest-scoring fresh small rows -- and RELEASED it without attempting it, because it is a magic-division row where every division has several equally plausible spellings. A high redundancy score is not sufficient if the row is in a class known to be spelling-ambiguous.
This commit is contained in:
@@ -2808,3 +2808,39 @@ the divisor is determined.**
|
||||
`0x800FBE84` matched on the **first spelling** with worker A's derivation: `n = a0 + 150; a = n/75;
|
||||
b = a/60; t = n % 75;` then three `sb` at offsets 2, 1, 0, each byte being `(x/10) << 4 + x % 10`
|
||||
(`sll` for the `<<4`, **`addu` not `or`**), with the `%10` sharing the `/10` quotient via CSE.
|
||||
|
||||
### 172. A missing sign bias is EVIDENCE of a shift, not a division (worker E)
|
||||
|
||||
Worker E's `0x80027D88`: the emitted rounding is the **BARE `sra v0,v0,2` with NO sign bias**, where
|
||||
`(y + z) / 4` makes cc1 emit `addiu ...,3` first (finding 97).
|
||||
|
||||
> **The values are non-negative in the source, but cc1 cannot know that after a conditional, so the
|
||||
> MISSING bias is the evidence that the source wrote a SHIFT, not a division.**
|
||||
|
||||
This is finding 97 read **backwards** — 97 says "a `/ 4096` emits the bias and a `>> 12` does not"; this
|
||||
says "**if you expect a division and there is no bias, you have the shift.**" New diagnostic.
|
||||
|
||||
### 173. The absolute value is a SWAPPED SUBTRACTION — second instance (worker E)
|
||||
|
||||
Worker E's `0x80027D88`: the emitted second op is **`subu v1,v0,a3`** — the operands **exchanged** —
|
||||
not `negu`. So the source is
|
||||
|
||||
if (x < 0) x = a1[0] - a0[0]; /* NOT x = -x; */
|
||||
|
||||
**Finding 101 has the lever; this is a clean second instance and the natural `-x` is the trap.** Same
|
||||
row, same family as worker A's `0x80027D00`.
|
||||
|
||||
### 174. The idiom-redundant-by-construction class, and when to DECLINE a row (worker E)
|
||||
|
||||
Worker E decoded `0x800FECF8` (140 B, redundancy 0.68 — one of the highest-scoring fresh small rows)
|
||||
and **released it without attempting it**:
|
||||
|
||||
> TWO magic divisions each with an **add-back** (`mfhi`/`addu`/`sra`, so `2^k−1` divisors by finding
|
||||
> 127), wrapped around `mult`/`mflo` and a `sign()` — with `(short)` narrowing at both ends. **By
|
||||
> worker C's finding 128 this is the idiom-redundant-by-construction class** (every division has
|
||||
> several equally plausible spellings), so it is a poor body-per-context bet.
|
||||
|
||||
**A high redundancy score is not sufficient if the row is in a class known to be spelling-ambiguous.**
|
||||
Worker E spent its budget on a row with a complete derivation instead. **That is the right trade, and
|
||||
it is the second time this phase a worker has declined a well-scoring row for a measured reason**
|
||||
(worker D declined `0x8006C044` and `0x80103544` the same way).
|
||||
|
||||
Reference in New Issue
Block a user