Commit Graph

24 Commits

Author SHA1 Message Date
Christopher Williams 2000cc4101 phase7: census duplicate bodies and expose a zero band of false positives
Matching conventions require a duplicate check before registering, because a
shared body is matched once and registered once per address. Phase 6 did that
check by hand and found one 12-byte pair. tools/sf3_dupes now hashes every
derived extent body and groups exact duplicates.

Results: 2284 extents, 65 multi-address groups, 2104 singletons. Only 10 groups
contain code (24 addresses, all exact-graded); 55 are all-zero bodies. The
hand-found pair 0x800262E0/0x800262EC is reproduced as g0002, which is the check
that the census measures what it claims. The largest real groups are 712 bytes
(0x8001084C/0x800189E8) and 436 bytes.

The zero groups are a real finding: 252 extents have all-zero bodies, 245 inside
the zero band 0x80147000..0x80170000. The cause is the inventory's jal grade,
which decodes every word as an instruction -- in a data region a word with
opcode 3 is graded as a call whose target lands in the zero band. The census
flags those groups rather than hiding them, and the worklist must exclude
degenerate bodies.

The census is tracked rather than ignored as the plan said, because it holds
addresses, sizes and grades only (the same class as the tracked inventory and
extents tables) and the worklist must be reproducible from tracked inputs. The
content hash is computed and never written.
2026-09-23 22:15:51 -04:00
Christopher Williams 6988ca96b0 phase7: derive evidence-graded function extents from control flow
Phase 6 graded function starts and left every end to be derived by hand. This
adds tools/sf3_extents, which explores all reachable control flow from each hard
start (jal/entry) and reports an extent plus how far it can be trusted.

Measured decisions, not stylistic ones:

- Soft starts are not walk boundaries. A body's second instruction can satisfy
  the prologue grade exactly (0x800152AC is lw v1,8(gp) / addiu sp,sp,-176, so
  0x800152B0 looks like a start). Enforcing soft boundaries stopped 155 of 416
  walks inside a real body.
- The walk is a full reachability computation, not a first-terminal search: a
  function whose paths return at different addresses must report the whole body.

Grades: exact 1940 (1666 packed, gap=0), fallthrough 256, indirect 73,
escape 15, contained 153, standalone 438; 63.8% of the payload covered.

Verification: all 12 registered regions reproduce exactly (make extents-verify,
now part of make check), 29 new synthetic tests (115 total), byte-identical
across two runs, and Ghidra's independent body for FUN_80017ad4 agrees. Two
defects were caught by writing the tests first and are recorded: reach had to be
an exclusive end, and a terminal j's delay slot must not continue linearly.

The table holds addresses, sizes, grades and site addresses only -- no bytes.
2026-09-23 22:12:31 -04:00
Christopher Williams ce43b7b42b phase6: document the Ghidra-draft workflow and record the verification gate 2026-09-23 21:50:03 -04:00
Christopher Williams 2507994ac3 phase6: correct the compiler to PsyQ 4.0 (gcc-2.7.2-psx) and register the framed batch 2026-09-23 21:37:15 -04:00
Christopher Williams 8ece49c130 phase6: register the leaf/gp batch and record the framed-function blocker 2026-09-23 21:24:15 -04:00
Christopher Williams d951e49b1d phase6: add the evidence-graded function-boundary inventory 2026-09-23 21:12:54 -04:00
Christopher Williams d379b84ec3 phase6: reproduce a gp-relative function and record the small-data evidence 2026-09-23 21:09:07 -04:00
Christopher Williams 4688662cf4 phase6: wire maspsx and link-time symbols, resolving the ASPSX la form 2026-09-23 21:01:20 -04:00
Christopher Williams 673edb2ded phase6: add the symbol registry and per-region flag overrides, and register 0x8002D2A0 2026-09-23 20:54:10 -04:00
Christopher Williams defbf446eb phase5: cookbook, conventions, and verification record
P5-T6. Adds docs/MATCHING_COOKBOOK.md (nine byte-proven compiler/assembler
findings, each with basis and limit), docs/MATCHING_CONVENTIONS.md (what counts
as a match, registry format, source naming, duplicate sharing, symbols, the
verification procedure, the firewall) and docs/PHASE5_VERIFICATION.md (outcome,
clean gates, bounded negatives, milestone request).

Tooling: make test and make check targets; region objects are now
symbol-localized so the documented duplicate-sharing mechanism (N registry rows
-> 1 source) links, covered by a synthetic test (53 tests).

Clean gates: 53/53 tests; make clean/all/cmp/SHA-1 green; make gate with one C
region -> c_regions=1, 0 differing bytes, SHA-1 e173426c...; 57 tracked files, 0
under any prohibited root. Phase 5 is not closed until the milestone is
confirmed.
2026-09-23 20:43:33 -04:00
Christopher Williams ff35291d40 phase5: determine the entry is CRT startup and match the first C function
P5-T5. Part A: the entry [0x800FB368,0x800FB410) is not compiler output. The
return address is round-tripped through an absolute global around the first
call, the range ends in break, the stack pointer is built from linker globals,
and the clear loop falls through with no jr ra. Two bounded compile experiments
failed and were stopped; the entry stays fallback and no C is claimed.

Part B: first byte-identical C match -- func_80017AD4 at 0x80017AD4..0x80017AE8
(20 bytes), src/func_80017AD4.c, registered in config/regions.tsv. make gate
reports c_regions=1, 0 differing bytes, SHA-1 e173426c157384ebf1b6caf8c6fea18a85a14af9.
Body is unique with one caller at 0x80014C14; a shared-tail near-miss was
checked and rejected as a duplicate. The Phase 3 baseline is unaffected.

Records six codegen findings, notably that GNU as expands the la macro with ori
while the original assembler (ASPSX 2.81) uses addiu, so la-using functions will
need maspsx. No ROM-derived material is tracked.
2026-09-23 20:39:40 -04:00
Christopher Williams f0237f1549 phase5: add the tracked matching harness and ordered-layout gate
P5-T4: tools/sf3_match provides range/plan/build/gate. It compiles a C candidate
with the identified toolchain (egcs-2.91.66 psx, -O2 -G0 -mno-split-addresses),
compares the exact instruction range byte-for-byte against the original, and
builds the address-ordered executable from the tracked registry config/regions.tsv
(header 0x800 + data gaps + C regions, LMA 0x800, metadata discarded).

Promotes the Phase 4 ordered workflow from an ignored experiment to tracked
tooling. Verified: make gate with an empty registry and with one real C region
both reproduce SHA-1 e173426c...; the Phase 3 baseline is unchanged and green;
the synthetic suite is now 50 tests including deliberate-corruption failures and
safe refusal of an existing destination. No ROM-derived material is tracked.
2026-09-23 20:32:11 -04:00
Christopher Williams 147eb4abf8 phase5: identify the compiler as egcs-2.91.66 (PSX) / PsyQ 4.5 CC1PSX
P5-T3 revised: obtained the real PsyQ 4.4/4.5/4.6 SDK compilers (proprietary,
kept ignored) and ran CC1PSX 4.5 under the ignored wibo Win32 loader. The SDK's
own README and the binary agree: PsyQ 4.5 CC1PSX = egcs-2.91.66 (egcs-1.1.2),
target mips-sony-psx, assembler ASPSX 2.81.

The open decompals/old-gcc gcc-2.91.66-psx produces instruction-identical
output to the real CC1PSX across ~990 instructions in twelve probe files, so no
proprietary compiler is needed for the matching build. Five reconstructed
original functions are byte-identical with -O2 -G0 -mno-split-addresses.

Corrects the earlier gcc-2.7.2-psx selection, which was an artifact of the
invalid -mcpu=3000 spelling. Records the unresolved 0x8005DEF8 reconstruction.
2026-09-23 20:23:05 -04:00
Christopher Williams f80ada2e07 phase5: record 2.5.7-psx/2.6.0-psx provenance and old-gcc build origin
P5-T3 follow-up: tested the two remaining GPL psx candidates. Both match the
same signatures as 2.7.2-psx but also synthesize the constant multiply, so
neither resolves the recorded divergence. SETUP now also records that the
old-gcc '-psx' builds are community GCC+patch reconstructions, and that the
real Sony PsyQ compilers exist in the mkst/esa psyq-binaries release (not
downloaded).
2026-09-23 20:15:20 -04:00
Christopher Williams 073da76a8a phase5: select gcc-2.7.2-psx from the old-gcc ladder
P5-T3: fingerprinted all eight decompals/old-gcc 0.17 cc1 candidates with
self-authored probes. gcc-2.7.2-psx is the only candidate matching the
ASPSX-style $at symbolic store, the same-register symbolic load, the
unsigned-char default, and the mfhi <scratch> magic-division allocation.
Five reconstructed original functions are byte-identical; 2.6.3-psx, vanilla
2.7.2, 2.7.2-cdk and 2.8.0/2.8.1/2.91.66/2.95.2 are eliminated. One bounded
constant-multiply synthesis divergence is recorded. No ROM-derived material is
tracked.
2026-09-23 20:10:46 -04:00
Christopher Williams e0d994d49d phase5: acquire vintage cc1 candidate ladder with provenance
P5-T2: downloaded decompals/old-gcc 0.17 prebuilt cc1 binaries (GCC 2.6.3/2.7.2/
2.8.0/2.8.1/2.91.66/2.95.2 psx variants plus vanilla 2.7.2 and cygnus cdk) into
ignored tools/old-gcc/. All eight run on this host and self-identify; the two
sha256 values cross-checked against an independent project matched exactly.
Local GNU as accepts COP2/GTE with -march=r3000 -G0.
2026-09-23 19:58:31 -04:00
Christopher Williams ed2f249397 phase5: activate phase and record toolchain evidence inventory
P5-T1: revalidated the clean payload-data baseline (28 tests, make clean/all,
cmp, SHA-1 e173426c...), reviewed the firewall and Git state, and inventoried the
USA toolchain-relevant codegen signatures and SDK version-marker provenance.
No ROM-derived bytes, strings, or listings are tracked.
2026-09-23 19:51:47 -04:00
Christopher Williams b9543e5213 phase4: close code recovery evidence milestone 2026-09-23 19:46:17 -04:00
Christopher Williams 7b0879f8da phase3: add assembly baseline pipeline 2026-09-23 18:41:28 -04:00
Christopher Williams cb87942249 chore(phase-2): close archive loader investigation 2026-09-23 17:46:32 -04:00
Christopher Williams 1dd720d998 chore(phase-1): close extraction and import milestone 2026-09-23 15:03:12 -04:00
Christopher Williams 04331bd5b4 feat(phase-1): add disc extraction and EXE validation 2026-09-23 14:30:45 -04:00
Christopher Williams 14dc2b2620 docs(phase-0): characterize MODE2 ISO9660 disc image 2026-09-23 09:38:10 -04:00
Christopher Williams 23e9a8871c chore(phase-0): establish ROM-safe project baseline 2026-09-23 09:36:50 -04:00