Worker B's maspsx structural limitation recorded: a region needing
addu-encoded moves (maspsx expands move->addu, GNU as expands move->or)
AND an assembler-filled jr slot cannot be matched with any single
maspsx= setting — this explains a family of epilogue residuals. B
verified in .s files. Two negatives with mechanisms (0x800254B0 alloc,
0x800751E8 with negu — evidence FOR the toolchain, finding-26 route).
B self-corrected an invented-address method error. Gate MATCH whole-
binary SHA-1 e173426c157384ebf1b6caf8c6fea18a85a14af9.
Worker B matched 0x800F6330 (correcting my stale negative: destination is
0x8011AA18 via the signed-displacement finding-4 trap) and 0x80090B7C
(18th/19th first-attempt matches this cycle). Coordinator absorbed
0x80025070 (conditional dispatch wrapper). B's correction of its own
void-vs-valued epilogue tell accepted (0x800FBDC0 counterexample; the
shared-epilogue hypothesis stands untested — recorded as observation, not
rule). Gate MATCH whole-binary SHA-1
e173426c157384ebf1b6caf8c6fea18a85a14af9.
Two more coordinator tier-2 wrappers, both first-try: 0x800A623C
(symbol-form constant + pass-through swap), 0x800A5CEC (guarded call with
zero in the jal slot). Gate MATCH whole-binary SHA-1
e173426c157384ebf1b6caf8c6fea18a85a14af9.
Worker B: 0x8002E3A8 bare unused frame (16B of pure stack adjustment from a
removed local — reproduced by declaring char unused[16] and nothing else),
0x8010AAC0 pass-through with arg reorder, 0x8008FF58 six-arg rebuild,
0x800F79C0 virtual dispatch. Worker C: 0x800268C4 (D_ names), 0x800697C4,
0x800658FC (F20 displacement-fold lever), 0x800A5CC8 (overlap with the
coordinator's claim — C's registration stood). Gate MATCH whole-binary
SHA-1 e173426c157384ebf1b6caf8c6fea18a85a14af9.
B's alignment-1 find closed 0x80013D04 first-attempt (lwl/lwr on provably
aligned addresses = declared-type alignment, not real alignment; Quad4
struct model). New symbol D_801219F4 (gp-relative address taken without
lui). Coordinator wrappers 0x800F8FC0/0x800A5CC8 (pass-through + constant-arg
delay-slot). Report negatives reconciled into the tracked index (0x800F9134,
0x80094370 now excluded by regenerated worklist). Gate MATCH whole-binary
SHA-1 e173426c157384ebf1b6caf8c6fea18a85a14af9.
Worker B observed that gating each batch without regenerating the worklist
re-grows partition drift every cycle (their file was 10 rows stale). The
regeneration is now done alongside each merge; partitions re-proved disjoint
(486/486/486, total 1458).
4 new (0x80082750, 0x8007EB8C, 0x800B34FC, 0x800C1EA8), 2 new gp symbols
(g_80122610, g_80122618) for the gp-relative table-address rows. Recorded
findings F17 (sra-vs-srl = signedness of the shifted value), F18
(inline mask strength-reduce -> bind to a local), F19 (address-shaped name
resolves implicitly but loses its gp marker -> use the registry's exact
name). Gate MATCH whole-binary SHA-1
e173426c157384ebf1b6caf8c6fea18a85a14af9.
Per-guard inline reload of obj->p (finding-8 CSE prevention) + stack byte
argument (a1 was a 5th param at sp+16). Gate MATCH whole-binary SHA-1
e173426c157384ebf1b6caf8c6fea18a85a14af9.
Worker C re-engaged on partition C closed 4 more (incl. 0x800450C4 which the
coordinator had recorded as a negative — C's source spelling beat the
coordinator's; the row is removed from the tracked index, the per-site
gp=-D_80121BFC override applied as recorded finding 16). 0x80065930 was
claimed by both C and the coordinator independently; skip-registered handled
the duplicate (coordinator's registration stood). Gate MATCH whole-binary
SHA-1 e173426c157384ebf1b6caf8c6fea18a85a14af9. C's F15 (do/while
counter-init-first for bottom-tested search loops) and F16 (mirrored-layout
lever is per-GUARD, tested guard by guard) recorded for the cookbook.
Coordinator matched the 30-entry key/value pair-table lookup on the first
attempt (array spelling reproduced the two walked pointers). Gate MATCH
whole-binary SHA-1 e173426c157384ebf1b6caf8c6fea18a85a14af9.
Worker B measured that recorded negatives cluster at the head of every
partition: 39 of the first 40 worklist rows and 57 of 271 tier-1 rows (21%)
were addresses an earlier session had already attempted and recorded. The
triage tool never read the negatives index, so every closed negative
returned to the queue head and workers rediscovered them.
Fix: sf3_triage reads the tracked config/near_match_negatives.tsv (a new
--negatives input) and excludes those rows as recorded_negative=69. The
tracked index was grown from 38 Phase-8 rows to 94 by importing 56 Phase-9
negatives from the workers' reports and the coordinator's absorption record
(filtered to unregistered; tracked rows win on conflict). Worklist
regenerated: the head is now genuinely fresh (0x800F9134, 0x80042D88,
0x800450C4, ...). 3 new synthetic tests; plan-level tests wired for the new
argument. The phase plan said extract negatives only at close; B's
measurement showed the harm is per-cycle, so the index is now a living
tracked input. Note for P9-T8: keep importing worker negatives each cycle.
Worker B found the exclusion detector's blind spot: opcode 0x08 (addi, traps
on overflow) appears in 7 of 1,666 worklist rows (frame adjustments
addi sp,sp,-28, loop counters) while 0 of 310 registered regions contains
one — the same disjointness signal as finding 26's R-type class. addiu (0x09)
is ubiquitous, so the 0x08 occurrences are the anomaly. Verified by the
coordinator from raw words: 7 rows, incl. 3 of partition A's 5 call-shape
rows (0x80011084, 0x800F3B10, 0x80010F30) and 0x800F3BB4 (previously
recorded as a separate coordinator negative — now explained by this class).
sf3_triage.trapping_arithmetic now counts opcode 0x08; worklist regenerated
(1,563 rows, excluded_trapping_arith=54). Synthetic test added.
P9-T5 route (a) widened: the immediate form is part of the class; the 7
ADDI rows are a ready-made minimal probe set for any cc1 candidate.
Also confirmed this cycle: the no-frame global-ra ISR family (ra saved to a
global, no stack frame — 0x801097A0 proved, 0x8010B420 pattern-transferred)
is a second library-asm class identical in kind to the CRT entry.
Coordinator absorbed partition B directly: 0x800F5AF8 (four pointer-slots
stored from constants — the globals at 0x8011A9E4 are POINTER VALUES read by
lw rt,sym then stored through, not direct symbol stores) and 0x80021FA8
(six 16-byte records, four fields zeroed via symbol+index, store-order fix).
0x800518BC recorded as a bounded return-merge negative. Gate MATCH
whole-binary SHA-1 e173426c157384ebf1b6caf8c6fea18a85a14af9.
Worker A reported nine worklist rows graded exact that are not function
starts. The coordinator verified the tell independently: a candidate whose
first instruction reads a register the range never defines (non-parameter),
or whose range has no jr/jalr return, is a wrong extent. Measured disjoint
from the matched corpus (7 worklist rows flagged incl. the runaway
0x801800C4 and the fallthrough 4-byte rows 0x80100808/0x80180808; 0 of 288
registered flagged). Implemented as excluded_bad_extent_start in sf3_triage
with 4 synthetic tests; worklist regenerated to 1,570 eligible rows.
Worker A rotated out at 108 claims (+79 from its session) with a clean
handoff; final 4 rows verified MATCH by the coordinator. 18 new regions
gated MATCH whole-binary (c_regions=306, SHA-1
e173426c157384ebf1b6caf8c6fea18a85a14af9), make check green.
P9-T4 checkpoint (>=290 total) CROSSED at 297 bodies.
All three workers have now rotated out; the coordinator absorbs the
remaining partitions. Negatives census now 34 report rows from A alone
(25 match-class + 9 bad-extent triage), with the bad-extent class verified
independently by the coordinator (disjoint from 288 registered regions;
7 worklist rows flagged incl. the runaway 0x801800C4/0x80180808 that were
never excluded because they are fallthrough-graded).
Handoff notes recorded: two high-value unattempted GTE rows (0x80101C2C,
0x80102FA4 — need raw lwc2/swc2 asm with memory operands), 8 lever findings
for the next charter (srl=sra-unsigned, slti-sltiu 16-bit tell, single-exit
result shape, struct-assignment for a0/a1 loads, maspsx=off scope x2, side-
effect statement order, lui/lw address arithmetic, CSE-preventing symbols).
The bad-extent detector is implemented in sf3_triage with synthetic tests;
the regenerated worklist will exclude the class.
Worker A batch 10 incl. the finding-13 store-only callee caller, pointer-table
walk, byte-dispatch 2-arm (not switch). Three negatives recorded: epilogue-
order-variant THIRD data point 0x800FBD80 (class now 3 members outside CRT +
new arg-copy tell), alloc+storeform 0x800582AC (explicit lui/at form tied to
allocation), alloc-tiebreak 0x800161E0. Gate MATCH whole-binary SHA-1
e173426c157384ebf1b6caf8c6fea18a85a14af9.
Worker C rotated out on budget with a clean handoff (28 claims total, all
verified; 18 negatives with hypotheses). Its final 2 rows verified MATCH
(0x80101838 reopening closed via do/while + sentinel: this closes B's cycle-2
negative on the same address!; 0x8007C4A8). Handoff inheritance: orig.py
disassembly helper, F1-F14 findings confirmed, 2-byte free claim 0x800266A8
left with its exact hypothesis. Gate MATCH whole-binary SHA-1
e173426c157384ebf1b6caf8c6fea18a85a14af9.
Worker A batch 9: if-conversion demo, pre-increment append, negate-magnitude,
guarded call pairs, epilogue-order-variant NEGATIVE 0x80100334 (finding 11's
'13 CRT sites' scoping corrected — this site is outside the CRT; recorded as
a third epilogue class data point), sched-tiebreak 0x8002515C. New symbol
D_80122160 (gp). Gate MATCH whole-binary SHA-1
e173426c157384ebf1b6caf8c6fea18a85a14af9.