|
|
|
@@ -8,6 +8,7 @@
|
|
|
|
|
0x80010810 60 near-match register-tiebreak
|
|
|
|
|
0x8001084C 712 blocked trapping-arithmetic
|
|
|
|
|
0x80011084 - near-match -
|
|
|
|
|
0X80011484 132 near-match candidate_bytes=108 vs 132 (24 SHORT). My reconstruction is wrong and I am recording it as unresolved rather than guessing further. What the bytes DO show: a fr
|
|
|
|
|
0x8001278C - near-match -
|
|
|
|
|
0x80012834 - near-match -
|
|
|
|
|
0x80012A10 - near-match -
|
|
|
|
@@ -16,11 +17,13 @@
|
|
|
|
|
0x80012AE0 - near-match -
|
|
|
|
|
0x80012CFC - near-match -
|
|
|
|
|
0x80012D54 56 near-match -
|
|
|
|
|
0X80012E84 160 near-match LENGTH-MISMATCH 168 vs 160 (42 vs 40 words). Same family as 0x800A6B38. cc1 placed the shared `return 0` block in the MIDDLE of the function (branch target 0x80
|
|
|
|
|
0x80013114 64 near-match -
|
|
|
|
|
0x800161E0 - near-match -
|
|
|
|
|
0x80016224 - near-match -
|
|
|
|
|
0x80016268 - near-match -
|
|
|
|
|
0x80016E24 - near-match -
|
|
|
|
|
0X80016F80 156 near-match candidate_bytes=156 = CORRECT LENGTH, 45 differing bytes, first_difference=0x80016F90. Instruction MULTISET is identical to the original; the residual is purely
|
|
|
|
|
0x800179E0 - near-match -
|
|
|
|
|
0x80017A38 - near-match -
|
|
|
|
|
0x80018284 80 near-match struct-copy jr-slot shape (8 loads/8 stores + v0-zero in slot)
|
|
|
|
@@ -31,10 +34,12 @@
|
|
|
|
|
0x8001EAFC 12 deferred shared-block-not-a-function
|
|
|
|
|
0x80022E44 52 near-match adjacent-zero-store merge
|
|
|
|
|
0X800238BC 264 near-match candidate_bytes=264 (correct length) differing_bytes=5 first_difference=0x80023900. Structure solved: `if (arg == 0) { out->x=out->y=out->z=0; } else
|
|
|
|
|
0X80023D40 104 near-match candidate_bytes=104 = CORRECT length, 5 differing bytes, and the diff is ONLY the first two instructions: original `bgez a0,<after the negu>` + `nop`, candidate
|
|
|
|
|
0x800245D8 - near-match -
|
|
|
|
|
0x80024630 56 near-match stack-routed min (temp elided by optimizer)
|
|
|
|
|
0x8002515C - near-match -
|
|
|
|
|
0x800254B0 - near-match -
|
|
|
|
|
0X800256F0 104 near-match LENGTH-MISMATCH 108 vs 104 (27 vs 26 words). Right structure, one extra instruction: the original RELOADS the sub-object field after the call (`lw v1,32(s0)` th
|
|
|
|
|
0x80025758 - near-match -
|
|
|
|
|
0x800259DC - near-match -
|
|
|
|
|
0x80025C08 - near-match -
|
|
|
|
@@ -43,11 +48,17 @@
|
|
|
|
|
0x800266A8 68 near-match byte-replication alloc (first sll register; fresh-context re-spelling 3B; named-locals regresses)
|
|
|
|
|
0X800268F4 136 near-match differing_bytes=9 result=DIFF at 136 bytes with the shared-result spelling (r-268f4-shared): branch target 0x80026968 vs 0x80026964 and the delay slot
|
|
|
|
|
0X80026A04 152 near-match LENGTH-MISMATCH: `for (i=0;i<10;i++)` gives 136 bytes (34 words) vs 152; cc1 ROTATED the loop into a do-while with the test at the bottom, and dropped
|
|
|
|
|
0X80027744 104 near-match candidate_bytes=104 = CORRECT length, differing_bytes=4, first_difference=0x8002778D. Residual is ONE instruction's DESTINATION register: original emits `addu v
|
|
|
|
|
0x80027BE8 - near-match -
|
|
|
|
|
0X80028750 244 near-match candidate_bytes=236 vs 244 (8 short) with `int r[4]; int s;` and with `int r[3]; int s;`. Structure understood: s = f(p0,q0)+f(p1,q1)+f(p2,q2); r[i] =
|
|
|
|
|
0X80029ED8 224 near-match candidate_bytes=236 vs 224 (12 over). Two levers applied and kept: (a) declare the address local unassigned and assign it AFTER the first call (244 -> 240) -- c
|
|
|
|
|
0x8002D014 - near-match -
|
|
|
|
|
0x8002D060 72 near-match -
|
|
|
|
|
0X8002DE28 140 near-match candidate_bytes=136 vs 140 (4 short), 2 spellings tried, both 136. Structure solved and it is the SIBLING of 0x8002DF1C (same 76-byte record at D_80121BFC index
|
|
|
|
|
0X8002DF1C 104 near-match candidate_bytes=104 = CORRECT length, 58 differing bytes. Structure: if (a0 < D_801222B4 && a0 >= 0) { *a2 = *(int *)(D_80121BFC + a0*76 + 44); *a1 = *(short *)
|
|
|
|
|
0X8002E198 180 deferred 4 prologue callee-saved assignment: ORIGINAL copies a0->s2, a1->s3, a2->s1 and the func_800A8700 result->s0 (save order s2,s3,s1, then s0 in the jal d
|
|
|
|
|
0X8002FB54 108 near-match candidate_bytes=112 vs 108 (4 over). Structure: int r = 1; if (a2 == 0) a3[2] = a0[0]; else if ((unsigned)a2 < 3) { a3[2]=a0[0]; a3[3]=a0[1]; a3[4]=a0[2]; a3[5]
|
|
|
|
|
0X8002FD4C 124 deferred LENGTH-EXACT (124 B, 31 insns) with 9 differing bytes in 5 instructions, all in the s0-first-use group: 0x8002FD50/54 prologue save order (orig sw s0,16 then sw
|
|
|
|
|
0x80037984 - near-match -
|
|
|
|
|
0x800379E0 - near-match -
|
|
|
|
|
0x80039308 - near-match -
|
|
|
|
@@ -59,6 +70,7 @@
|
|
|
|
|
0x80042DD4 - near-match -
|
|
|
|
|
0x80042E10 - near-match -
|
|
|
|
|
0x80042E68 - near-match -
|
|
|
|
|
0X80043DC4 212 deferred 2 2 attempts. Body understood: table lookup via 0x80121C00, x = *(int *)(*(int *)(s0+16)+16) loaded at the TOP into a0 and used as func_80043D8C's only argument
|
|
|
|
|
0x80045540 56 near-match constant-materialisation-order
|
|
|
|
|
0x80045F00 - near-match -
|
|
|
|
|
0X80045FD8 120 deferred 4 register shift: original reloads a3->a0, a4->v0, and in the L1 block a4->a1; candidate gets a3->v0, a4->v0, a4->v1 (i.e. the allocator's choice star
|
|
|
|
@@ -67,12 +79,15 @@
|
|
|
|
|
0x8004820C - near-match -
|
|
|
|
|
0x800496CC - near-match -
|
|
|
|
|
0X8004D7C8 220 near-match candidate_bytes=220 = CORRECT length, differing_bytes=7 first_difference=0x8004D7F4. Structure: `v = *(char**)(p+32); s1 = *(int*)(*(char**)(v+244)+8)
|
|
|
|
|
0X80050604 112 near-match candidate_bytes=116 vs 112 (4 over). Structure solved: two 24-byte-stride array bases 384 bytes apart (D_8012FDD4 and D_8012FF54, both address-named, both takin
|
|
|
|
|
0X80050674 112 near-match candidate_bytes=112 = CORRECT length, differing_bytes=1, first_difference=0x80050696 -- the register FIELDS of the second `addu`, nothing else. Original: `addu
|
|
|
|
|
0x800518BC 88 near-match return-merge/sltiu (3 spellings: goto-shared 80B, combined cond 80B, two-exit if 80B; original keeps move-zero at separate target + j-to-shared-return; sltiu needs unsigned val which alone fixes the compare byte but not the 8-byte layout)
|
|
|
|
|
0x800582AC 64 near-match -
|
|
|
|
|
0X800589E8 192 near-match candidate_bytes=196 vs 192 with `V4 d; V4 r;` and with `int d[3]; int r[3];` (the array form gives the original's 64-byte... no: frame 64 with s1 also
|
|
|
|
|
0X80058AA8 248 near-match candidate_bytes=252 vs 248 (4 over, 121 differing bytes from one shifted instruction). Structure: `V4 d; V4 v; v = *(V4*)D_8010D138; func_80027ECC(&v,
|
|
|
|
|
0x8005DEF8 124 near-match register-tiebreak
|
|
|
|
|
0x80065494 80 near-match popcount scheduling (base in beqz delay slot)
|
|
|
|
|
0X800667DC 204 near-match candidate_bytes=188 vs 204 (16 short). cc1 merged the two call sites by selecting `a1` (`j 0x80066880` + `li a1,23`) where the original has a shared call reache
|
|
|
|
|
0x800690E4 68 near-match loop-rotation+head-match-early-return (3 spellings: do/while arg-test-top 84B, while+conditional 76B, while-test 64B; the j/li early path and bnez-back-to-bne rotation are the residual)
|
|
|
|
|
0x8006AD5C - near-match -
|
|
|
|
|
0x8006AE04 - near-match -
|
|
|
|
@@ -83,14 +98,17 @@
|
|
|
|
|
0x8007374C - near-match -
|
|
|
|
|
0x800751E8 - near-match -
|
|
|
|
|
0x8007A114 - near-match -
|
|
|
|
|
0X8007C408 160 near-match LENGTH-MISMATCH 164 vs 160 (41 vs 40 words), first difference 0x8007C418. SECOND INSTANCE of the same unexplained tie-break as 0x800A6B38: the original holds th
|
|
|
|
|
0x8007E85C - near-match -
|
|
|
|
|
0x800807E0 - near-match -
|
|
|
|
|
0x80085B44 60 near-match -
|
|
|
|
|
0x8008A198 56 near-match -
|
|
|
|
|
0x8008F478 - near-match -
|
|
|
|
|
0x80090990 - near-match -
|
|
|
|
|
0X80091490 84 near-match candidate_bytes=84 differing_bytes=2 result=DIFF at 0x800914B8 (or at 0x800914C8 with the statements swapped). The original emits load 20(s0), load 4(s0), subu,
|
|
|
|
|
0x80092104 - near-match -
|
|
|
|
|
0x80094370 84 near-match triple-deref copy loop (dest = *(*(a0+0xc)+0x160)+0x160; 1 coordinator attempt 100B)
|
|
|
|
|
0X80099D14 88 near-match candidate_bytes=88 differing_bytes=12 result=DIFF, one instruction POSITION. Everything matches except that the original emits `addiu v0,zero,2` (the constant f
|
|
|
|
|
0x80099E34 40 near-match alloc-tiebreak (symbol-form address in a1)
|
|
|
|
|
0x8009B218 - near-match -
|
|
|
|
|
0x8009C69C 60 near-match register-tiebreak
|
|
|
|
@@ -101,13 +119,18 @@
|
|
|
|
|
0x800A6C34 88 near-match hoist: cc1 lifts `li v0,-1; sw v0,0(s0)` above the load of 0x80121B88; the original loads first then stores, so the hoist is the WHOLE residual. The draft already uses a LITERAL address (`*(int *)0x80121B88`) deliberately, to avoid the name-keyed gp trap, and that literal correctly produces the original's absolute encoding (`lui v1,0x8012` / `lw v1,7048(v1)`). Note: the coordinator's `--no-gp D_80121B88` test on this draft is INERT by construction -- the harness gp rewrite only acts on SYMBOL accesses, so a literal gives identical output and that is not evidence about the encoding. The untried lever is a source order that stops the hoist. Recovered by worker C's cleanup audit after the row fell out of its staging.
|
|
|
|
|
0x800A82D0 64 near-match -
|
|
|
|
|
0x800A86B4 - near-match -
|
|
|
|
|
0X800A8920 100 near-match LENGTH-MISMATCH 104 vs 100 (26 vs 25 words). Everything matches except the `return 0` path: the original puts `addu v0,zero,zero` in the `beq s0,zero` DELAY SLO
|
|
|
|
|
0x800A8AEC - near-match -
|
|
|
|
|
0x800AAC44 - near-match -
|
|
|
|
|
0X800AB504 148 near-match candidate_bytes=172 vs 148 (24 over). Structure solved: recursive free of a linked record (`if (n) func_800AB504(n);`), then a counted loop of `count
|
|
|
|
|
0X800AC7A0 120 near-match candidate_bytes=120 = CORRECT length (with the 2D-array spelling), 70 differing; the 1D spelling `D_8013C078[a3 * 4 + a4]` gives 116 (4 short) and 28 differing.
|
|
|
|
|
0x800AC9D8 56 near-match constant-materialisation-order
|
|
|
|
|
0X800ACA10 184 near-match candidate_bytes=188 vs 184 (one extra instruction). Structure solved: `v = 0; for (i=0;i<9;i++) if (D_80116E3C[i] == 1) { v = D_80116E84[i]; break; }`
|
|
|
|
|
0x800B0B88 - near-match -
|
|
|
|
|
0x800B34A4 88 near-match alloc-tiebreak (bit-index/base register pair a0/a1 vs cc1 a0/v1; 2 spellings both 80B; original keeps base in a1 via direct +0x10 load)
|
|
|
|
|
0X800B5C5C 88 near-match candidate_bytes=88 = CORRECT length, 61 differing bytes, first_difference=0x800B5C5C. Structure solved: int idx = g_80122068; int prev = g_8012277C; unsigned sh
|
|
|
|
|
0X800B6F64 232 near-match four variants, all named. (1) `int n = D_80122774;` as an INITIALISER before the call: 240 bytes -- cc1 hoists the global load ABOVE the call. (2) assigning `n
|
|
|
|
|
0X800BC658 148 near-match LENGTH-MISMATCH 140 vs 148 (35 vs 37 words). THE INLINE-ASM IDIOM IS PROVEN CORRECT: all eight stack-switch instructions (4 in the slow path, 4 in the join bloc
|
|
|
|
|
0X800BC6EC 236 deferred 0 NOT attempted beyond disassembly. The body switches the STACK POINTER to the PSX scratchpad and back: `lui at,0x1f80` + `sw sp,1020(at)` (saves sp t
|
|
|
|
|
0x800C1E54 - near-match -
|
|
|
|
|
0x800C3514 88 near-match alloc+layout (priority selector; original: all stack loads hoisted, beqz+nop+li groups, sltu first test; cc1 interleaves with bnez — 2 coordinator spellings 84B)
|
|
|
|
@@ -126,6 +149,7 @@
|
|
|
|
|
0x800F9134 - near-match -
|
|
|
|
|
0X800FB6D8 128 near-match differing_bytes=56 result=DIFF, 128 bytes both sides. Instruction MULTISET and register allocation are IDENTICAL (handler in s0, previous in v0, buffe
|
|
|
|
|
0X800FB758 112 near-match rare-epilogue-order-35b; residual 6B at 0x800FB7BC; tried default;--no-maspsx;--cc1 gcc-2.91.66-psx;--cc1 gcc-2.8.1-ps
|
|
|
|
|
0X800FBB20 128 near-match HARNESS ROW (finding-40 class). Structure fully solved; candidate_bytes=132 vs 128, only 3 differing instructions, and one of them is a HARNESS limitation. Sour
|
|
|
|
|
0x800FBD80 - near-match -
|
|
|
|
|
0x800FBDC0 - near-match -
|
|
|
|
|
0x800FBF5C 56 near-match -
|
|
|
|
@@ -144,6 +168,8 @@
|
|
|
|
|
0x80100334 - near-match -
|
|
|
|
|
0x8010036C 56 near-match rare-epilogue-order (F21)
|
|
|
|
|
0X801003A4 148 near-match candidate_bytes=180 vs 148 (32 over). Structure read off the original: two calls, then a 24-iteration loop over 72-byte records at 0x80145AC0 where th
|
|
|
|
|
0X80100438 208 deferred 2 2 attempts. Body fully understood: `func_800FFBBC(0)`, then a 24-iteration loop over 72-byte records at 0x80145AC0 with fields +12/+14 (short), +16 (short), +
|
|
|
|
|
0X801008DC 88 near-match candidate_bytes=88 = CORRECT length, 58 differing bytes, first_difference=0x801008E4. Structure solved: int *p = *(int **)(a0 + 28); if (p == 0) return 0; if (*
|
|
|
|
|
0x80100998 80 near-match -
|
|
|
|
|
0X80101764 212 near-match correct LENGTH (212) with `int one = 1;` used for `one << mask` and both loop comparisons, but 139 differing bytes. WITHOUT the `one` local: 216 bytes
|
|
|
|
|
0x80101C5C 32 blocked -
|
|
|
|
@@ -159,7 +185,9 @@
|
|
|
|
|
0x80107338 48 near-match no-frame-call (t0-t2 temps across call, ra via a3 — library asm family; cc1 builds a frame 88B)
|
|
|
|
|
0x80107874 40 near-match constant-base-in-register
|
|
|
|
|
0x80107B40 68 near-match -
|
|
|
|
|
0X80107C5C 112 near-match HARNESS ROW, ROOT CAUSE PINNED TO A SINGLE MASPSX PREDICATE - and this one looks like a one-line fix worth taking to the developer. candidate_bytes=108 vs 112,
|
|
|
|
|
0x80107CCC 76 near-match -
|
|
|
|
|
0X80107D7C 108 near-match candidate_bytes=112 vs 108 (4 over). Structure solved: int *p = (int *)D_801221C4; while (p != 0) { if (p[2] == a0 && p[3] == a1 && *(short *)(p + 5) == a2) { D
|
|
|
|
|
0x80108034 24 blocked gp-thunk
|
|
|
|
|
0x8010804C 16 blocked gp-thunk
|
|
|
|
|
0x80108578 56 near-match two-epilogue
|
|
|
|
|