32 new bodies from 400, all verified on the candidate whole-binary gate before
promotion. SHA-1 e173426c157384ebf1b6caf8c6fea18a85a14af9 stable.
Registry requests granted (each byte-verified with a failing control):
cc1=-G8 on 0x800A6BEC; gp=-D_80121B88 on 0x80015D50
symbols D_80122700, D_80122704, D_80121AD4 (gp)
Harness: per-region maspsx modes wired through sf3_match (maspsx=noreordernop,
maspsx=regread) plus --no-jump-slot-nop/--nop-on-reg-read for range. Both are
opt-in and default-off; make check green at 441 with them off, suite 229 -> 232
tests. Carried as a TRACKED patch (tools/patches/maspsx-phase10-r1r2.patch)
because tools/maspsx/ is git-ignored, so an in-place edit would not survive a
fresh clone; patch verified to reproduce the working tree byte-identically.
R1/R2 are recorded as a MEASURED NEGATIVE: neither closes a region (cookbook
finding 40 has the mechanism and the remaining developer-owned route).
Docs: cookbook finding 40 (rare-epilogue mechanism + why the obvious maspsx fix
fails); SETUP.md maspsx patch provenance and apply step.
Negatives: 0x8010AA28 imported; index sorted by address (140 rows, 0 registered).
Full clean audit green: make clean && make all exit 0, cmp exit 0, both SHA-1
match, registry 441/0 overlaps/0 bad extents/0 missing sources, 0 firewall.
- Phase10_PLAN.md status DRAFT -> APPROVED (Goal A, 475 bodies, 70-80% ctx cap)
- phase-ends/CURRENT_PHASE.md: Phase 10 control record
- config/near_match_negatives.tsv: drop 6 rows that were already registered
(index header says every row is UNREGISTERED); index 145 -> 139 rows, 0 registered.
Worklist regenerates byte-identically after the fix.
- Baseline revalidated at 25bf4a3: make check exit 0, regions=409 disagreements=0
AGREE, c_regions=409 differing_bytes=0 MATCH, 229 tests OK, SHA-1 stable.
- Worklist regen: listed=1343, excluded_already_registered=409 (= registry size).
- 3-way partitions in .run/p10 (448/448/447, pairwise intersection 0, union == worklist).
- Roster deviation recorded and developer-approved: 3 workers, not the plan's 2.
Phase 9 closed at 400 distinct bodies / 409 regions (from 149/158), all
gates green from clean: CMP_OK, SHA-1
e173426c157384ebf1b6caf8c6fea18a85a14af9, 229 tests, make gate
c_regions=409 MATCH, extents-verify AGREE, worklist listed=1343 with
excluded_already_registered=409, firewall 0, src/ 0 untracked.
Milestone partially met (400 of 500): the blocker is recorded with per-class
evidence (tier-1 tie-break domination, class disjointness, measured rate
decay) per the plan's Or branch. PhaseEnd_Phase9.md, digest entry, and the
ledger archive (logs/Phase9.md) written. docs/PHASE9_PROTOCOL.md (scale-run
retrospective: queue fix, tier-2 pivot, family-set lever, rotation
discipline, leading-indicator rule, measured budget), docs/PHASE9_VERIFICATION.md
(all gates, incidents, class exclusions), cookbook findings 29-39,
conventions additions, README updated to 400/409.
Phase10_PLAN.md drafted (Goals A/B/C: tail squeeze vs library-boundary
investigation, developer decisions enumerated) — requires explicit approval
before any Phase 10 task; no Phase 10 work begins in this session.
The 400-body target (P9-T6 checkpoint, 251 new bodies from 149) is crossed
on the coordinator's own whole-binary gate: c_regions=409, differing_bytes=0,
SHA-1 e173426c157384ebf1b6caf8c6fea18a85a14af9.
Final batch: B's last 2 family members (0x800578EC, 0x800577E8, both 100B),
11 consecutive first-attempt family matches closing the run. Cycle-4 total:
47 new bodies from worker B following the milestone-close directive
(reliable-rows over exploration). The family-as-a-set lever (scan for rows
calling a matched target; stable positions selector->arg2 sentinel->arg3
a1->arg9, per-row elsewhere) drove 11 first-attempt closes.
Workers: B 60 claims (rotated cleanly, handoff block written with 104
report entries and the corrected cookbook items), C 70 claims (earlier
rotation). Coordinator holds merge/gate/ledger at 86% protecting the
essential role.
B 9-for-9 across the family batches. 0x80057B30 has TWO incoming stack
params; the family-set lever's scope limit sharpened: stable positions
(selector->arg2, sentinel->arg3, a1->arg9, extra->arg10) + per-row
positions elsewhere — the map proves once for the STANDARD form only, and
B corrected its own earlier 'map proves once' framing (belongs in the
cookbook with the lever). Two more 100-byte callers (0x800578EC,
0x800577E8) in flight for margin. Gate MATCH whole-binary SHA-1
e173426c157384ebf1b6caf8c6fea18a85a14af9.
B: 42 new this cycle. Family rows restored the rate 3-for-3 first attempt
(selectors 6/17/15). Boundary note: 0x80057BE8 is in partition C (retired,
no race) — accepted under the standing verified-work-claimable policy. Key
finding: the family's argument map is NOT constant — stable positions
(narrowed a1 -> arg 9, 5th param -> arg 10) + per-row positions elsewhere
(no negu when there is no conditional selection — the discriminator
predicts it). Third selector-proving pair. Gate MATCH whole-binary SHA-1
e173426c157384ebf1b6caf8c6fea18a85a14af9.
B: 39 new this cycle. Finding 5 at its sharpest: ONE byte (ori vs addiu)
was the whole difference — a literal vs symbol with identical address.
Three-way family now: lui-high-half, name-keyed-gp, literal-vs-symbol —
all encoding-only source constructs. 0x8003EB18 duplicated-arms mechanism
(cc1 shares something even with explicit duplication — 100 vs 108) and
0x80012834 tie-break recorded. Gate MATCH whole-binary SHA-1
e173426c157384ebf1b6caf8c6fea18a85a14af9.
B: 38 new this cycle. 0x800AA01C three-way mode switch (if/else-if/else
chain — arms are exact complements: set bit 3/clear 6 vs set 6/clear 3 vs
clear both). Contrast finding: the move a0,v0 after the lookup decides
whether the flush gets the looked-up object or the original a0 — one
instruction, re-verified per family row (0x800AAC44 negative recorded).
Gate MATCH whole-binary SHA-1
e173426c157384ebf1b6caf8c6fea18a85a14af9.
B's family-target scan paid off a 3rd time: 0x80057B84 = the family's 4th
member, matched on the 2nd attempt with two levers — (1) branch-vs-
branchless discriminator (how many distinct values are selected decides
the spelling), (2) the mask must be INLINED not held in a local (here the
repeated expression is correct and the local is the mistake — mirror
image of the usual named-locals lever). Two negatives recorded
(0x800179E0 guard polarity, 0x800C1E54 dead local). Gate MATCH whole-
binary SHA-1 e173426c157384ebf1b6caf8c6fea18a85a14af9.
B 4-for-4 first attempt via the family-as-a-set lever (scan for rows
calling the same target after a match; the argument map is paid once).
Three siblings of 0x80057748 (selectors 11/4/16, some with the 5th
incoming arg as outgoing arg 10) plus 0x8006B66C (0x8006B1CC sibling with
a per-node flag test). Byte-identical-pair-teaching-constant-as-selector
(0x8005789C vs 0x80057C30 differ only in li a1,4 vs li a1,16). Gate MATCH
whole-binary SHA-1 e173426c157384ebf1b6caf8c6fea18a85a14af9.
B: 32 new this cycle. Load-bearing insight: frame slots never read back are
the callee's 9th/10th stack arguments (0x80057748 was 68-vs-80 until the
10-arg call). Branchless conditional lever (ternary-zero differs from
if/else — sltu+negu+and). negu evidence set grows (3rd row) for finding
26's toolchain direction. Sibling 0x8005789C (11th stack arg) recorded
with the start-from-10-args note. Gate MATCH whole-binary SHA-1
e173426c157384ebf1b6caf8c6fea18a85a14af9.
B: 30 new this cycle. 0x80103D0C matched; two source fixes recorded
(mask at use site; D_801220F4 is a short not int — sh vs sw tell).
Pre-screen correction: 50/55 (91%) of rare-epilogue rows in A are in the
mutual-exclusion blocked subset (move-pseudo detector fixed: rt==0 not
rs==0) — the class is not unmatchable but operationally mostly blocked;
coordinator's original skip instinct was partly right. New name-keyed-gp
finding: the gp marker hangs off the NAME not the address, so a
differently-named symbol with the right address silently loses gp-relative
form. Gate MATCH whole-binary SHA-1
e173426c157384ebf1b6caf8c6fea18a85a14af9.
Fourth failure (0x80012CFC, 54 bytes — worst residual of the cycle) against
two successes in one family confirms C's scheduler-bound diagnosis. Family
is a toolchain limit, not a source problem: 0x80012A10/0x80012AE0 (earlier
excluded) plus now 0x80012CFC/0x80012B20. Extensive arithmetic checks
(5 stack args fix a 9-parameter signature; lui immediates 0x08000000 and
0x38000000 are high halves) confirm the model without the bytes.
B solved one of C's parked picks with a better vehicle: the result-first
hypothesis needs RETURN-inside-loop, not a result local (a local allocates
to a0 and costs a move). 0x800263A8 matched 64B first try. Its twin
0x80016224 is now 8 differing bytes, a pure node-v1/payload-a0 register
swap — identical residual to B's own 0x800161E0 (one allocation family,
chartered together). Gate MATCH whole-binary SHA-1
e173426c157384ebf1b6caf8c6fea18a85a14af9.
C's last claim 0x800A745C (flag-as-literal lever: named variable cost 4
bytes of s1 save/restore). Handoff accepted after a MEASURED stall signal:
1/4 batch, plus breaking two of its own recorded rules (gp+2300 arithmetic
and the g_/D_ name) in one batch — the criterion C committed to. Handoff
content: 71 claims all tracked-verified, 48 report rows, 38 parked
negatives by class, rareepi.py classifier (validated on 6 cases), orig.py,
lever list with scope limits, ~26 fresh rows in the 100-120 band.
Symbol note: D_80122234 already tracked (C's g_ request redundant — ignore);
g_801219D4 genuinely new for the open 0x80016E24. Gate MATCH whole-binary
SHA-1 e173426c157384ebf1b6caf8c6fea18a85a14af9.
2 tier-2 rows (0x800B58C8, 0x80073364). C's weaker-batch honest report:
2/6 then +1 on a fix; new arithmetic instance (0x00FFFF00 from lui 0xff +
ori 0xff00 — the standing compute-don't-eyeball rule applied to two-piece
constant builds). Three genuine compiler residuals with untried levers
named. Gate MATCH whole-binary SHA-1
e173426c157384ebf1b6caf8c6fea18a85a14af9.
4 tier-2 rows (0x80089B30, 0x800A9F7C, 0x800A34E8, 0x80103B8C). C tested
the register-binding lever on 0x800245D8 (FAILED, record corrected from
untried to tried-and-failed; family nuance kept for the pointer-based
0x8006AE04). New address-vs-value tell (same-looking global: lw rt,off(rt)
= VALUE, lui+addiu = ADDRESS). F10 re-confirmed (5th row). Gate MATCH
whole-binary SHA-1 e173426c157384ebf1b6caf8c6fea18a85a14af9.
Worker B: 28 new this cycle. 0x800B6C14's inverted-polarity guard
(if (test() == 0) — nonzero skips the work) recorded as the 3rd
same-count-wrong-reading this cycle. Two pure-allocation negatives
(0x8007374C 7B reg swap, 0x800A86B4 pointer roles). Gate MATCH
whole-binary SHA-1 e173426c157384ebf1b6caf8c6fea18a85a14af9.