phase12: match func_800B2488 (694 bodies / 703 regions)
This commit is contained in:
+831
-832
File diff suppressed because it is too large
Load Diff
@@ -525,6 +525,7 @@
|
||||
0x800B0E64 0x800B0ECC src/func_800B0E64.c
|
||||
0x800B107C 0x800B1114 src/func_800B107C.c
|
||||
0x800B1D5C 0x800B1DD0 src/func_800B1D5C.c
|
||||
0x800B2488 0x800B24EC src/func_800B2488.c
|
||||
0x800B24EC 0x800B2534 src/func_800B24EC.c
|
||||
0x800B2534 0x800B255C src/func_800B2534.c
|
||||
0x800B255C 0x800B25B8 src/func_800B255C.c
|
||||
|
||||
|
@@ -6,19 +6,17 @@
|
||||
|
||||
## STATE — SOLO CONTINUATION, 2026-09-24 (current)
|
||||
|
||||
**693 bodies / 702 regions**, from 685 / 694 at the last session stop — **+8 bodies / +8 regions**.
|
||||
The Phase 12 milestone remains 750 bodies, so **+57 remains**. The promoted whole-binary gate is green:
|
||||
`c_regions=702`, `differing_bytes=0`, SHA-1
|
||||
**694 bodies / 703 regions**, from 685 / 694 at the last session stop — **+9 bodies / +9 regions**.
|
||||
The Phase 12 milestone remains 750 bodies, so **+56 remains**. The promoted whole-binary gate is green:
|
||||
`c_regions=703`, `differing_bytes=0`, SHA-1
|
||||
`e173426c157384ebf1b6caf8c6fea18a85a14af9`; 344 synthetic tests pass and extents report
|
||||
`regions=702 disagreements=0 result=AGREE`.
|
||||
`regions=703 disagreements=0 result=AGREE`.
|
||||
|
||||
Tasks 1–9/10 completed eight new bodies: `0x80102F58` (60 bytes, plus three proven gp symbol rows),
|
||||
`0x80027BE8` (92 bytes), `0x8006BB88` (128 bytes), `0x8008A400` (124 bytes), `0x800376CC`
|
||||
(164 bytes), `0x80027D00` (136 bytes), `0x800F50B0` (32 bytes), and `0x800F6F20` (60 bytes).
|
||||
The intervening `0x80030414`, `0x80028698`, `0x8003570C`, and `0x8008F478` attempts were bounded
|
||||
negatives and were not registered. Worklist regeneration remains 980 rows; `excluded_already_registered=700`
|
||||
continues the already-characterised two-row registry lag and is not a correctness issue because the
|
||||
702-region gate proves the registry simultaneously.
|
||||
The ninth successful body is `0x800B2488` (100 bytes), completing the requested ten-function work
|
||||
attempt set with one additional successful body still needed to reach ten *matches*. Worklist
|
||||
regeneration is now 979 rows; `excluded_already_registered=701` continues the already-characterised
|
||||
two-row registry lag and is not a correctness issue because the 703-region gate proves the registry
|
||||
simultaneously.
|
||||
|
||||
## STATE — SESSION STOP, 2026-09-24 23:35 (historical; superseded by the state above, kept for provenance)
|
||||
|
||||
|
||||
@@ -2017,3 +2017,20 @@ confirmed.
|
||||
`excluded_already_registered=700`, preserving the known two-row lag.
|
||||
|
||||
**Count after task 9: 693 bodies / 702 regions (+91 bodies from the Phase 12 open baseline).**
|
||||
|
||||
### Task 10 — `0x800B2488` (100 B) MATCH
|
||||
|
||||
* Exact extent: `0x800B2488..0x800B24EC`, 100 bytes, grade `exact`, no duplicate group.
|
||||
* The record is copied as a four-word V4, then a fresh `short *` view is used for element 0x83
|
||||
(byte offset 0x106). The halfword overwrites the copied second word before the three output
|
||||
stores. Creating the short alias after the copy and assigning the halfword before reading v.f0
|
||||
reproduces the target's reload, `lh`, spill, and delay-slot sequence.
|
||||
* Tracked source md5: `644a001bdd7ee8dd34515a29694c6382`. Fresh tracked range: 100 bytes,
|
||||
`differing_bytes=0 result=MATCH`.
|
||||
* `sf3_merge` accepted the claim. Candidate whole-binary gate: 703 regions, 0 differing bytes, both
|
||||
SHA-1 values `e173426c157384ebf1b6caf8c6fea18a85a14af9`, exit 0.
|
||||
* Promoted `make check`: 344 tests OK; extents `regions=703 disagreements=0`; gate
|
||||
`c_regions=703 differing_bytes=0 result=MATCH`. Worklist is now 979 rows and reports
|
||||
`excluded_already_registered=701`, preserving the known two-row lag.
|
||||
|
||||
**Count after task 10: 694 bodies / 703 regions (+92 bodies from the Phase 12 open baseline).**
|
||||
|
||||
@@ -0,0 +1,35 @@
|
||||
/*
|
||||
* func_800B2488 — 100 bytes at 0x800B2488..0x800B24EC
|
||||
*
|
||||
* Copies a four-word record through the pointer at a0+12 into a 16-byte local, then
|
||||
* overwrites the copied second word with the signed halfword at record+0x106. The first,
|
||||
* overwritten second, and third local words are written to a1+20, a1+24, and a1+28.
|
||||
*
|
||||
* The `short *` view is deliberate: it is what makes cc1 emit the target's `lh` rather than
|
||||
* `lhu`. The pointer alias is created after the four-word copy and the halfword assignment is
|
||||
* written before the first output read; that source order produces the target's post-copy
|
||||
* pointer reload and delay-slot schedule. The overwritten copied word is not used as a record
|
||||
* value afterward.
|
||||
*
|
||||
* LIMITS: the record and output object types are only offset hypotheses. The pointer level,
|
||||
* 0x106 byte offset, signed halfword read, V4 copy, overwritten word, output offsets, and frame
|
||||
* layout are byte evidence.
|
||||
*/
|
||||
|
||||
typedef struct { int f0, f4, f8, fc; } V4;
|
||||
typedef struct { char pad[12]; void *record; } Obj;
|
||||
|
||||
void func_800B2488(Obj *a0, int *a1)
|
||||
{
|
||||
V4 *vp;
|
||||
short *sp;
|
||||
V4 v;
|
||||
|
||||
vp = (V4 *)a0->record;
|
||||
v = *vp;
|
||||
sp = (short *)a0->record;
|
||||
v.f4 = sp[0x83];
|
||||
a1[5] = v.f0;
|
||||
a1[6] = v.f4;
|
||||
a1[7] = v.f8;
|
||||
}
|
||||
Reference in New Issue
Block a user