Approved by the developer 2026-09-24: milestone 750, stretch 800; both harness repairs
authorised; Goal B (the 92-unclassified negatives) in scope and bounded; 4 workers —
two on the fresh band, one on the 101 named negatives, one on the third fresh slice plus
the 92 unclassified as the Goal B worker; compaction-first.
THE ONE STRUCTURAL FACT THIS PLAN IS BUILT ON, measured at the open:
0 of the 193 near_match_negatives rows appear in the 1001-row worklist.
The negatives index is held OUT of the worklist (sf3_triage plan --negatives) and is not a
queue — it is an index, and a worker dispatched only from the worklist can never reach it.
So the negatives pool becomes a first-class partition with its own worker, and the phase's
structural change is that it stops being an appendix.
Two pools, measured: 1001 fresh rows (410 of them <=244 B) plus 193 attempted-but-unresolved
negatives, of which 101 carry a NAMED mechanism and are overturnable by cookbook 182's rule,
and 92 carry no class at all and cannot be attempted until someone re-reads them. That is
what Goal B is for.
The plan states plainly that +148 is LARGER THAN ANY PHASE SO FAR (Phase 11 closed +118) and
that it cannot be reached from the fresh worklist alone — it depends on the negatives-overturn
programme working at scale, which is a measured route but only a ONE-ROW demonstration so far
(worker F's 0x8002622C). Two safeguards are built in rather than discovered late: the cycle-1
checkpoint must include at least 8 bodies from the negatives pool, so a low overturn rate is
measured in cycle 1 and not at the close; and the leading-indicator rule stands unchanged —
report the projection and ask, never redefine or self-certify the milestone.
Also recorded: the fresh-band size distribution, the negatives class distribution, and the
baseline revalidation table including the failed precondition that T0 repaired.
The firewall line in all four close records said 720 tracked files. That figure was measured BEFORE the
two close records themselves were added, so the true post-close count is 722
(phase-ends/PhaseEnd_Phase11.md and docs/PHASE11_VERIFICATION.md). Corrected in the PhaseEnd, the digest
entry, the verification record and the ledger.
Same class of error as the two the close already records: a number measured at one moment, then quoted
in a document that itself changes the thing being measured. The firewall RESULT is unaffected --
0 tracked paths under any prohibited root either way.
Developer confirmation of the 600-body milestone was requested and given before this record was
written, per the plan. The phase closes at 602 distinct matched bodies / 611 registered regions, from
the Phase 10 close state of 484 / 493 (+118 / +118).
Closing gate set, all green from a clean tree:
make clean && make all exit 0
cmp exit 0
SHA-1 (both files) e173426c157384ebf1b6caf8c6fea18a85a14af9 (UNCHANGED from Phase 10)
make test 253 tests, OK (from 237)
make extents-verify regions=611 disagreements=0 result=AGREE
make gate c_regions=611 differing_bytes=0 result=MATCH
The SHA-1 being identical to the Phase 10 close is the point: all +118 bodies are additions to a
binary that still reproduces exactly.
Records written:
phase-ends/PhaseEnd_Phase11.md the close record
docs/PHASE11_VERIFICATION.md the verification record
phase-ends/DIGEST.md Phase 11 section
phase-ends/CURRENT_PHASE.md rewritten: NO PHASE ACTIVE, roster-restart warning
phase-ends/logs/Phase11.md Cycle 3 close, corrections, ledger reconciliation
docs/MATCHING_COOKBOOK.md 187
docs/ORCHESTRATOR_WORKFLOW.md section 4.0 roster rule, section 10 close steps, section 11
Three corrections made during the close, each to something already reported:
1. The negatives index was reported as "200 rows, 82 with a mechanism". Measured: 194 data rows
(200 LINES, 6 of them header), 101 with a named class, 86 with a substantive note, 92 with no
class at all. The 700-body route is LARGER than reported. wc -l on a file with header comments is
not a row count -- and the same error was then made again with the symbol count (413 lines, 400
rows) inside this very record.
2. One in-flight ledger row was STALE-TAKEN and invisible. 0x800298C0 (392 B) traced
C wip -> C released -> A wip -> C wip, so last-row-wins read it TAKEN while NEITHER holder was
working it -- both were out of context and would never append a release. It is a live worklist
row and is NOT in the negatives index, so nothing else would have surfaced it. Released with
coordinator as the worker field; tools/sf3_free now reports FREE. This is cookbook 179's failure
mode in its OTHER half: the copied script blocked rows that HAD been released, while this row
shows the ledger cannot express "the holder no longer exists" at all. Now a standing close step
(cookbook 187).
3. Worker A's "32 first-attempt" claims are not reconcilable from its artefact -- only 27 of its 46
report rows carry an explicit first-attempt note. 27 is recorded as the verifiable figure and 32
is flagged unverified, because a first-attempt rate is a COST claim and cost claims drive
dispatch.
Ledger reconciliation at close: 275 rows over 135 addresses; last row released for 113, claimed for
21, wip for 1. The 21 claimed rows are all already registered, so they need no action -- claimed is a
legitimate resting state.
The roster does NOT survive this close. All six worker sessions are retired and their herdr panes
closed, so Phase 12 MUST spawn a fresh roster; there is nothing to reconnect to. This is a change
from Phase 10, which left three retired sessions listed in `intercom list` -- and a roster that is
retired but still listed is indistinguishable from one that is live. Both halves are now standing
rules in ORCHESTRATOR_WORKFLOW section 4.0.
No changes to AGENTS.md.
b29963e promoted worker F's staging tools, and in the same commit I copied F's
staging `diff.py` over `tools/sf3_diff` WITHOUT READING IT FIRST -- a direct
violation of AGENTS.md rule 3, 'Never overwrite blind.'
`tools/sf3_diff` was a 364-line Phase 9 tool: two subcommands (diff, resolve), a
PS-X-EXE header parser that reads the text address rather than hardcoding it, a
symbol-registry loader, and a lui/addiu + gp-relative address resolver. It had
17 tests of its own. Replacing it with a 97-line staging script dropped
`make check` from 253 tests to 237 and failed it with exit 2.
Restored from b29963e^ and verified byte-identical to it (cmp exit 0).
make check exit 0, 253 tests OK
extents-verify regions=611 disagreements=0 result=AGREE
gate rebuilt 1886208 B, differing_bytes=0, result=MATCH
sha1 e173426c157384ebf1b6caf8c6fea18a85a14af9
Documentation corrected, because the overwrite also left the record wrong:
* cookbook 185 documented the interface of F's STAGING script
(`sf3_diff 0xSTART 0xEND <workdir>`), which is NOT the interface of the
tracked tool and never was. Replaced with the real one, and the reason the
Phase 9 tool is worth more is now stated: its `notes` column resolves
lui/addiu pairs against the symbol registry and gp offsets against the gp
base, so a residual row can name WHICH GLOBAL an address is.
* cookbook 186 records the defect. The question to ask before promoting into
tools/ is not 'is the new one better?' but 'what does the old one already do
that the new one does not?'
* ORCHESTRATOR_WORKFLOW.md section 11 gains both as standing prohibitions, with
the diagnostic: a SHRINKING TEST COUNT means a tool that had tests no longer
satisfies them, and it fires before the failure itself is explained.
* phase-ends/logs/Phase11.md: 'seven defects' -> nine, recording the free-check
defect (cookbook 179) and this one.
Records worker output (104 claims total), the GTE class moving from BLOCKED to OPEN (worker D's
0x800F3E18 is the first GTE row matched in the project), the epilogue post-pass and its two
corrections, seven defects in coordinator-written rules, the central finding restated with worker
D's seven-finder breakdown, and the ranker's known blind spot with both failed proxies.
Records the cycle: five defects in coordinator-written rules (all found by workers following
them), the merge-flow defect the coordinator inflicted on itself, four new tools, the central
finding confirmed from both directions, the ranker's known blind spot with two failed proxies,
adjacency at 9-for-9, and the open items (GTE token, the post-pass, the solved 0x82082083).
Records the full cycle: the 244 B ceiling was a dispatch artefact, ASPSX does not fill delay
slots (so the post-pass shrank from a modelling project to five lines), and the central finding
that cost is tie-break density rather than size -- measured independently by two workers from
opposite directions and now shared tooling.
Also records the four defects in coordinator work that workers found, the coordination defect
the best heuristic created, the new classes and levers (58-106), and two orchestrator notes:
the milestone counts BODIES not bytes, and a diagnostic should be routed to the row shape it
matches rather than broadcast.
Records worker B's oracle result overturning the post-pass framing (ASPSX does not
fill delay slots; maspsx is faithful to it; the fills come from GNU as reorder mode and
the only gap is one mnemonic), the new `maspsx=moves` mode, worker C's correction of a
too-broad Phase 10 coordinator fix (now opt-in `maspsx=nopmarker`), the per-worker cost
tables that show SHAPE not band is the variable, and the new findings 63-66 plus the
named-locals family's fourth mechanism and the char[4] block-move recipe.
Committed at the orchestrator's 70% context cap; compaction follows, safe because the
ledger and CURRENT_PHASE are current.
494 bodies / 503 regions. Three bodies above the old 244 B ceiling from two workers
(248/248/264 B). Cookbook 59 extended with the unreferenced-array-local mechanism
(cc1 gives unreferenced scalars no home but does allocate for unreferenced arrays),
the amended three-direction rule, the per-band cost table, the sf3_merge fail-fast
fixes, and the rank-instability broadcast.
Records: the "244-byte ceiling" is a DISPATCH ARTEFACT not a measured wall (5 of 427
rows ever attempted, 1.2%; three in an excluded class; both non-excluded attempts
near-matched; 84% unclassified ordinary code), so worker C is re-assigned above the
ceiling onto a 619-row dispatch file with 258 known-callee rows.
The new division_check exclusion class (break and div always co-occur; 0 of 493
registered regions contains either; worklist 1193 -> 1118).
Worker B's localisation of the maspsx/GNU-as mutual exclusion (ASPSX does both the
move->addu conversion and the fill; maspsx the first only, as the second only, and they
cannot be combined) with a 42-row/14% census in its partition, and the developer's
authorization of a tracked post-pass modelled on ASPSX's behaviour via oracle
characterisation -- ASPSX itself is a diagnostic oracle only, never a build stage,
because it is proprietary and git-ignored and a build depending on it could not be
reproduced.
Baseline revalidated at the Phase 10 close state: tracked maspsx patch applied,
make check exit 0, extents regions=493 AGREEE, gate differing_bytes=0 MATCH, 237
tests OK, 484 bodies / 493 regions, worklist 1193 with excluded_already_registered=493.
Roster spawned by the orchestrator via herdr (tab w1:t4, 2x2 at ~115x31); all four
probed clean and all four confirmed context_info + compact_context, which is the
basis for the compaction-first policy. Worker D is assigned GOAL B (the 244-byte
ceiling) with a bounded four-step investigation and a running GOALB.md deliverable;
A, B and C are on Goal A with 12-claim cycle targets.
Partitions: 4-way rank-interleaved, 299/298/298/298, disjoint, union == worklist,
near-identical tier/size mixes. Lever files rank size-band-first (cookbook 41):
P2 (<=200B, no lever) at 359 rows is the main target across the four partitions.
Charters carry the Phase 10 process rules as hard requirements: md5 per claim,
verify the staged path, cleanup audit before reporting, read ranges from the worklist
row, one attempt on a named lever then classify, fold region options into the claim row.
Plan approved by the developer with all four recommended decisions: milestone 600
(stretch 700), Goal B (the bounded 244-byte-ceiling investigation) in scope, a
4-worker roster spawned by the orchestrator with discretion to scale or retire, and
a compaction-first context policy.
Roster spawned by the orchestrator via herdr in a verified 2x2 grid (tab w1:t4,
~115x31 per pane):
w1:p5 worker-a 01a0d36a-be1f
w1:p6 worker-b 01a0d36b-1dc6
w1:p7 worker-c 01a0d36b-f346
w1:p8 worker-d 01a0d36c-02f4
All four probed; worker A confirmed context_info works (1.4% at spawn) and that
compact_context is available, which is the mechanical basis for the compaction-first
policy.
phase-ends/CURRENT_PHASE.md rewritten for Phase 11 with the planning finding (the
matched corpus median is 52 B, p90 108 B, max 244 B, and nothing larger has ever
matched), the roster table with herdr pane and intercom ids, the context policy, and
the carried machinery.
Prepared immediately after Phase 10 closure (484 bodies / 493 regions).
THE PLANNING FINDING THAT DEFINES THE PHASE: the matched corpus is n=493 with a
median of 52 bytes, p90 108 bytes and MAX 244 bytes -- NOT ONE BODY LARGER THAN 244
BYTES HAS EVER MATCHED. Against a remaining worklist of 1193 rows:
<=120 B 115 rows proven-matchable band
121-200 B 284 rows proven-matchable band
201-400 B 367 rows partially proven (up to 244 B)
401-800 B 245 rows UNPROVEN -- nothing has ever matched here
>800 B 182 rows UNPROVEN
So the ~400-450 rows at <=244 B are the finite proven band, and +116 bodies means
matching a quarter to a third of it. The 244-byte ceiling is therefore the real
subject, and the plan states TWO goals: A consume the proven band (the milestone
path), B break the 244-byte ceiling (a bounded investigation with a measured
deliverable, where a result that adds zero bodies is still a met goal).
Structural change: the orchestrator spawns and retires its own workers via herdr
(4 agent panes per tab, 2x2 verified at 115x31 each); the developer spawns only the
orchestrator. Context management changes too: pi-context-tools is installed
globally, so every session has context_info and compact_context -- measurement is
exact and self-service, and COMPACTION replaces rotation as the first response to a
full context, with rotation second. That is only safe because the state lives in
files, so keeping the ledger current becomes a hard requirement.
Four decisions requested: the milestone number; whether Goal B is in scope this
phase; the 4-worker default with orchestrator discretion to add a fifth; and
confirmation of the compaction-first policy.
MILESTONE MET AND EXCEEDED: 484 distinct matched bodies / 493 registered regions
(target 475, from the 400 baseline) — +84 bodies. Developer confirmation of the
milestone was requested and given before any close record was written.
Closing checklist all green from clean:
make clean && make all exit 0
cmp exit 0
SHA-1 both files e173426c157384ebf1b6caf8c6fea18a85a14af9
make test 237 tests, OK
make extents-verify regions=493 disagreements=0 AGREE
make gate c_regions=493 differing_bytes=0 MATCH
registry audit 493 rows, 0 overlaps, 0 unsorted, 0 bad extents,
0 missing sources, 484 distinct sources
worklist listed=1193, excluded_already_registered=493
negatives index 194 rows, address-ordered, 0 registered
git status --short src/ empty (0 untracked files)
firewall 0 prohibited-root paths (591 tracked files)
New records:
phase-ends/PhaseEnd_Phase10.md the phase record
docs/PHASE10_VERIFICATION.md the verification record
docs/MATCHING_COOKBOOK.md findings 41-57 (57 total)
phase-ends/CURRENT_PHASE.md CLOSED, with the checklist itemised
phase-ends/DIGEST.md the Phase 10 digest entry
The headline finding is methodological (finding 41, THE SIZE-BAND LAW): the matched
corpus median is 48 bytes with 454/459 at <=200 B while the remaining levered rows
had a median of 456 B, and two independent measurements — one controlled — put the
small band at 1-2 attempts per row against 1-in-12 for 200-800 B.
The phase's character: five of the coordinator's own generalisations were bounded by
workers (rare-epilogue class, register-field diagnostic, polarity lever, goto
trigger, load-delay consumer form). The rules that survived are the ones that were
bounded.
Five incidents recorded rather than smoothed over; the candidate gate rejected three
batches and the tracked registry was never corrupted. Scope held: the blocked classes
stay excluded, no scheduler-changing flag was granted, and inline asm was extended
only to shapes C provably cannot express.
STOPPING HERE. Phase 11 does not begin in this session.
Records the 0x800A9C24 collision (coordinator double-assignment: the row was
redistributed to B2 and then chartered to C2), B2's diagnosis that "verify the file
at the path you claim" is necessary but not sufficient because the gap is between
verify and merge, the adopted md5-in-claim-row guard, and worker A's 4 first-attempt
bodies including the second byte-exact stack-switch row that isolates the variable
to an argument move at the call site.
Records: worker A's 8 first-attempt bodies and two general levers (two-arm polarity
byte-required; named boolean local forces the branchless compare); worker B2's
limitation of the coordinator's polarity broadcast (both ordinary spellings give the
mirrored branch, so the guard must be a goto); the staging slip the candidate gate
caught (verified finding, wrong file staged) and the standing rule it produces
(verify the file you stage, not a scratch variant); and the dead-store-elimination
class from 0x80016F80.
Third coordinator over-generalisation a worker has caught this phase.
32 new bodies from 400, all verified on the candidate whole-binary gate before
promotion. SHA-1 e173426c157384ebf1b6caf8c6fea18a85a14af9 stable.
Registry requests granted (each byte-verified with a failing control):
cc1=-G8 on 0x800A6BEC; gp=-D_80121B88 on 0x80015D50
symbols D_80122700, D_80122704, D_80121AD4 (gp)
Harness: per-region maspsx modes wired through sf3_match (maspsx=noreordernop,
maspsx=regread) plus --no-jump-slot-nop/--nop-on-reg-read for range. Both are
opt-in and default-off; make check green at 441 with them off, suite 229 -> 232
tests. Carried as a TRACKED patch (tools/patches/maspsx-phase10-r1r2.patch)
because tools/maspsx/ is git-ignored, so an in-place edit would not survive a
fresh clone; patch verified to reproduce the working tree byte-identically.
R1/R2 are recorded as a MEASURED NEGATIVE: neither closes a region (cookbook
finding 40 has the mechanism and the remaining developer-owned route).
Docs: cookbook finding 40 (rare-epilogue mechanism + why the obvious maspsx fix
fails); SETUP.md maspsx patch provenance and apply step.
Negatives: 0x8010AA28 imported; index sorted by address (140 rows, 0 registered).
Full clean audit green: make clean && make all exit 0, cmp exit 0, both SHA-1
match, registry 441/0 overlaps/0 bad extents/0 missing sources, 0 firewall.
- Phase10_PLAN.md status DRAFT -> APPROVED (Goal A, 475 bodies, 70-80% ctx cap)
- phase-ends/CURRENT_PHASE.md: Phase 10 control record
- config/near_match_negatives.tsv: drop 6 rows that were already registered
(index header says every row is UNREGISTERED); index 145 -> 139 rows, 0 registered.
Worklist regenerates byte-identically after the fix.
- Baseline revalidated at 25bf4a3: make check exit 0, regions=409 disagreements=0
AGREE, c_regions=409 differing_bytes=0 MATCH, 229 tests OK, SHA-1 stable.
- Worklist regen: listed=1343, excluded_already_registered=409 (= registry size).
- 3-way partitions in .run/p10 (448/448/447, pairwise intersection 0, union == worklist).
- Roster deviation recorded and developer-approved: 3 workers, not the plan's 2.
Phase 9 closed at 400 distinct bodies / 409 regions (from 149/158), all
gates green from clean: CMP_OK, SHA-1
e173426c157384ebf1b6caf8c6fea18a85a14af9, 229 tests, make gate
c_regions=409 MATCH, extents-verify AGREE, worklist listed=1343 with
excluded_already_registered=409, firewall 0, src/ 0 untracked.
Milestone partially met (400 of 500): the blocker is recorded with per-class
evidence (tier-1 tie-break domination, class disjointness, measured rate
decay) per the plan's Or branch. PhaseEnd_Phase9.md, digest entry, and the
ledger archive (logs/Phase9.md) written. docs/PHASE9_PROTOCOL.md (scale-run
retrospective: queue fix, tier-2 pivot, family-set lever, rotation
discipline, leading-indicator rule, measured budget), docs/PHASE9_VERIFICATION.md
(all gates, incidents, class exclusions), cookbook findings 29-39,
conventions additions, README updated to 400/409.
Phase10_PLAN.md drafted (Goals A/B/C: tail squeeze vs library-boundary
investigation, developer decisions enumerated) — requires explicit approval
before any Phase 10 task; no Phase 10 work begins in this session.