phase12: match func_800B2488 (694 bodies / 703 regions)

This commit is contained in:
Christopher Williams
2026-09-24 20:56:06 -04:00
parent ca930cfc6e
commit df8963a779
5 changed files with 893 additions and 843 deletions
+831 -832
View File
File diff suppressed because it is too large Load Diff
+1
View File
@@ -525,6 +525,7 @@
0x800B0E64 0x800B0ECC src/func_800B0E64.c
0x800B107C 0x800B1114 src/func_800B107C.c
0x800B1D5C 0x800B1DD0 src/func_800B1D5C.c
0x800B2488 0x800B24EC src/func_800B2488.c
0x800B24EC 0x800B2534 src/func_800B24EC.c
0x800B2534 0x800B255C src/func_800B2534.c
0x800B255C 0x800B25B8 src/func_800B255C.c
1 # Code-region registry: one C region per matched function.
525 0x800B0E64
526 0x800B107C
527 0x800B1D5C
528 0x800B2488
529 0x800B24EC
530 0x800B2534
531 0x800B255C
+9 -11
View File
@@ -6,19 +6,17 @@
## STATE — SOLO CONTINUATION, 2026-09-24 (current)
**693 bodies / 702 regions**, from 685 / 694 at the last session stop — **+8 bodies / +8 regions**.
The Phase 12 milestone remains 750 bodies, so **+57 remains**. The promoted whole-binary gate is green:
`c_regions=702`, `differing_bytes=0`, SHA-1
**694 bodies / 703 regions**, from 685 / 694 at the last session stop — **+9 bodies / +9 regions**.
The Phase 12 milestone remains 750 bodies, so **+56 remains**. The promoted whole-binary gate is green:
`c_regions=703`, `differing_bytes=0`, SHA-1
`e173426c157384ebf1b6caf8c6fea18a85a14af9`; 344 synthetic tests pass and extents report
`regions=702 disagreements=0 result=AGREE`.
`regions=703 disagreements=0 result=AGREE`.
Tasks 1–9/10 completed eight new bodies: `0x80102F58` (60 bytes, plus three proven gp symbol rows),
`0x80027BE8` (92 bytes), `0x8006BB88` (128 bytes), `0x8008A400` (124 bytes), `0x800376CC`
(164 bytes), `0x80027D00` (136 bytes), `0x800F50B0` (32 bytes), and `0x800F6F20` (60 bytes).
The intervening `0x80030414`, `0x80028698`, `0x8003570C`, and `0x8008F478` attempts were bounded
negatives and were not registered. Worklist regeneration remains 980 rows; `excluded_already_registered=700`
continues the already-characterised two-row registry lag and is not a correctness issue because the
702-region gate proves the registry simultaneously.
The ninth successful body is `0x800B2488` (100 bytes), completing the requested ten-function work
attempt set with one additional successful body still needed to reach ten *matches*. Worklist
regeneration is now 979 rows; `excluded_already_registered=701` continues the already-characterised
two-row registry lag and is not a correctness issue because the 703-region gate proves the registry
simultaneously.
## STATE — SESSION STOP, 2026-09-24 23:35 (historical; superseded by the state above, kept for provenance)
+17
View File
@@ -2017,3 +2017,20 @@ confirmed.
`excluded_already_registered=700`, preserving the known two-row lag.
**Count after task 9: 693 bodies / 702 regions (+91 bodies from the Phase 12 open baseline).**
### Task 10 — `0x800B2488` (100 B) MATCH
* Exact extent: `0x800B2488..0x800B24EC`, 100 bytes, grade `exact`, no duplicate group.
* The record is copied as a four-word V4, then a fresh `short *` view is used for element 0x83
(byte offset 0x106). The halfword overwrites the copied second word before the three output
stores. Creating the short alias after the copy and assigning the halfword before reading v.f0
reproduces the target's reload, `lh`, spill, and delay-slot sequence.
* Tracked source md5: `644a001bdd7ee8dd34515a29694c6382`. Fresh tracked range: 100 bytes,
`differing_bytes=0 result=MATCH`.
* `sf3_merge` accepted the claim. Candidate whole-binary gate: 703 regions, 0 differing bytes, both
SHA-1 values `e173426c157384ebf1b6caf8c6fea18a85a14af9`, exit 0.
* Promoted `make check`: 344 tests OK; extents `regions=703 disagreements=0`; gate
`c_regions=703 differing_bytes=0 result=MATCH`. Worklist is now 979 rows and reports
`excluded_already_registered=701`, preserving the known two-row lag.
**Count after task 10: 694 bodies / 703 regions (+92 bodies from the Phase 12 open baseline).**
+35
View File
@@ -0,0 +1,35 @@
/*
* func_800B2488 — 100 bytes at 0x800B2488..0x800B24EC
*
* Copies a four-word record through the pointer at a0+12 into a 16-byte local, then
* overwrites the copied second word with the signed halfword at record+0x106. The first,
* overwritten second, and third local words are written to a1+20, a1+24, and a1+28.
*
* The `short *` view is deliberate: it is what makes cc1 emit the target's `lh` rather than
* `lhu`. The pointer alias is created after the four-word copy and the halfword assignment is
* written before the first output read; that source order produces the target's post-copy
* pointer reload and delay-slot schedule. The overwritten copied word is not used as a record
* value afterward.
*
* LIMITS: the record and output object types are only offset hypotheses. The pointer level,
* 0x106 byte offset, signed halfword read, V4 copy, overwritten word, output offsets, and frame
* layout are byte evidence.
*/
typedef struct { int f0, f4, f8, fc; } V4;
typedef struct { char pad[12]; void *record; } Obj;
void func_800B2488(Obj *a0, int *a1)
{
V4 *vp;
short *sp;
V4 v;
vp = (V4 *)a0->record;
v = *vp;
sp = (short *)a0->record;
v.f4 = sp[0x83];
a1[5] = v.f0;
a1[6] = v.f4;
a1[7] = v.f8;
}