Worker C diagnosed the earlier drop: the source was correct; the row failed
only because g_80121BFA (gp) was not yet tracked, so it resolved absolutely
(+8 bytes). Adding the symbol row first made it 80 bytes MATCH. C's standing
rule adopted: claims referencing symbols not yet in the tracked registry are
reported as DEPENDENT (symbol merged before the claim), never as verified
against a superset. Process error #2 (gp arithmetic) recorded. Gate MATCH
whole-binary SHA-1 e173426c157384ebf1b6caf8c6fea18a85a14af9.
Worker B: 26 new this cycle, incl. the rare-epilogue three-way model
confirmed textually (sub-case b: 0x800F8928 mutual exclusion, before/after
68->64 then or-encoded moves), the discard-an-argument-outright pass-through
5th flavour, and D_80121ED8 corroboration. Worker C: 4 matched (0x80048E20,
0x8005784C, 0x800579A0, 0x80057AE0). GATE INCIDENT: C's 0x8002E3FC claimed
but its source is LENGTH-MISMATCH (88 vs expected) against the tracked
registry — dropped from the merge, reported back to C. Gate MATCH
whole-binary SHA-1 e173426c157384ebf1b6caf8c6fea18a85a14af9.
4 tier-2 frames (0x8002864C, 0x80049298 with gp=-D_80121BFC, 0x801032D4,
0x800893E8). C's process-error owning (hardcoded ends instead of the
worklist column) and the F24 finding (caller-saved reloaded pointer across
a call means the store belongs before the call) recorded. Rare-epilogue
census: 47 tier-2 rows carry the pattern at their final instructions —
definitive class, broadcast to the workers. Gate MATCH whole-binary
SHA-1 e173426c157384ebf1b6caf8c6fea18a85a14af9.
Worker C closed 0x80031F2C (a row the coordinator had recorded as a
negative) via the F23 struct-assignment lever (second confirmation) —
stale negative removed. Also 0x800129C8, 0x8009132C (F22: unsigned char
local re-masks an already-zero-extended lbu — width-of-DESTINATION tell).
C's link-error finding recorded: 'small-data section too large' on a
region that built fine = a duplicate gp symbol (name mismatch), not a -G
problem. New negative 0x80042E68 pairs with 0x80042DD4; named pointer
lever untried. Gate MATCH whole-binary SHA-1
e173426c157384ebf1b6caf8c6fea18a85a14af9.
3 tier-2 frames from C (0x800A6840, 0x8002C728, 0x8002E968). Gate DIFF
avoided: C's 0x8002C728 used the name g_80121B84 which resolves implicitly
WITHOUT the gp marker (F19) — its local superset carried a g_-marked row so
C's own run matched, but the tracked registry only has D_80121B84. Fixed the
source to the tracked name; re-verified MATCH. C's 0x80025070 'negative'
corrected: that row is the coordinator's registered claim (stale index
entry removed). C's address-arithmetic charter warning (lui + negative
displacement must be hand-derived; five occurrences) recorded. Gate MATCH
whole-binary SHA-1 e173426c157384ebf1b6caf8c6fea18a85a14af9.
Worker B: 3 more tier-2 frames (0x80036328, 0x800AA2B4, 0x80021FF4 — the
latter with the base+offset decode and the clearest finding-13 scratch
constant yet) + symbol D_80121978 (gp). 23 new bodies this cycle.
GATE INCIDENT: the first candidate gate DIFFed with 4 extra bytes because
src/func_80025070.c was DELETED from the working tree after my commit
( status) — the build used a stale/wrong object. Restored from git and
re-gated clean. Lesson recorded: every tracked src/ file is a claim; a
registry row whose source is missing breaks the whole-binary gate with a
cascade, so the pre-gate 'git status src/' check must catch deletions too.
Gate MATCH whole-binary SHA-1
e173426c157384ebf1b6caf8c6fea18a85a14af9.
Worker B's maspsx structural limitation recorded: a region needing
addu-encoded moves (maspsx expands move->addu, GNU as expands move->or)
AND an assembler-filled jr slot cannot be matched with any single
maspsx= setting — this explains a family of epilogue residuals. B
verified in .s files. Two negatives with mechanisms (0x800254B0 alloc,
0x800751E8 with negu — evidence FOR the toolchain, finding-26 route).
B self-corrected an invented-address method error. Gate MATCH whole-
binary SHA-1 e173426c157384ebf1b6caf8c6fea18a85a14af9.
Worker B matched 0x800F6330 (correcting my stale negative: destination is
0x8011AA18 via the signed-displacement finding-4 trap) and 0x80090B7C
(18th/19th first-attempt matches this cycle). Coordinator absorbed
0x80025070 (conditional dispatch wrapper). B's correction of its own
void-vs-valued epilogue tell accepted (0x800FBDC0 counterexample; the
shared-epilogue hypothesis stands untested — recorded as observation, not
rule). Gate MATCH whole-binary SHA-1
e173426c157384ebf1b6caf8c6fea18a85a14af9.
Two more coordinator tier-2 wrappers, both first-try: 0x800A623C
(symbol-form constant + pass-through swap), 0x800A5CEC (guarded call with
zero in the jal slot). Gate MATCH whole-binary SHA-1
e173426c157384ebf1b6caf8c6fea18a85a14af9.
Worker B: 0x8002E3A8 bare unused frame (16B of pure stack adjustment from a
removed local — reproduced by declaring char unused[16] and nothing else),
0x8010AAC0 pass-through with arg reorder, 0x8008FF58 six-arg rebuild,
0x800F79C0 virtual dispatch. Worker C: 0x800268C4 (D_ names), 0x800697C4,
0x800658FC (F20 displacement-fold lever), 0x800A5CC8 (overlap with the
coordinator's claim — C's registration stood). Gate MATCH whole-binary
SHA-1 e173426c157384ebf1b6caf8c6fea18a85a14af9.
B's alignment-1 find closed 0x80013D04 first-attempt (lwl/lwr on provably
aligned addresses = declared-type alignment, not real alignment; Quad4
struct model). New symbol D_801219F4 (gp-relative address taken without
lui). Coordinator wrappers 0x800F8FC0/0x800A5CC8 (pass-through + constant-arg
delay-slot). Report negatives reconciled into the tracked index (0x800F9134,
0x80094370 now excluded by regenerated worklist). Gate MATCH whole-binary
SHA-1 e173426c157384ebf1b6caf8c6fea18a85a14af9.
Worker B observed that gating each batch without regenerating the worklist
re-grows partition drift every cycle (their file was 10 rows stale). The
regeneration is now done alongside each merge; partitions re-proved disjoint
(486/486/486, total 1458).
4 new (0x80082750, 0x8007EB8C, 0x800B34FC, 0x800C1EA8), 2 new gp symbols
(g_80122610, g_80122618) for the gp-relative table-address rows. Recorded
findings F17 (sra-vs-srl = signedness of the shifted value), F18
(inline mask strength-reduce -> bind to a local), F19 (address-shaped name
resolves implicitly but loses its gp marker -> use the registry's exact
name). Gate MATCH whole-binary SHA-1
e173426c157384ebf1b6caf8c6fea18a85a14af9.
Per-guard inline reload of obj->p (finding-8 CSE prevention) + stack byte
argument (a1 was a 5th param at sp+16). Gate MATCH whole-binary SHA-1
e173426c157384ebf1b6caf8c6fea18a85a14af9.
Worker C re-engaged on partition C closed 4 more (incl. 0x800450C4 which the
coordinator had recorded as a negative — C's source spelling beat the
coordinator's; the row is removed from the tracked index, the per-site
gp=-D_80121BFC override applied as recorded finding 16). 0x80065930 was
claimed by both C and the coordinator independently; skip-registered handled
the duplicate (coordinator's registration stood). Gate MATCH whole-binary
SHA-1 e173426c157384ebf1b6caf8c6fea18a85a14af9. C's F15 (do/while
counter-init-first for bottom-tested search loops) and F16 (mirrored-layout
lever is per-GUARD, tested guard by guard) recorded for the cookbook.
Coordinator matched the 30-entry key/value pair-table lookup on the first
attempt (array spelling reproduced the two walked pointers). Gate MATCH
whole-binary SHA-1 e173426c157384ebf1b6caf8c6fea18a85a14af9.
Worker B measured that recorded negatives cluster at the head of every
partition: 39 of the first 40 worklist rows and 57 of 271 tier-1 rows (21%)
were addresses an earlier session had already attempted and recorded. The
triage tool never read the negatives index, so every closed negative
returned to the queue head and workers rediscovered them.
Fix: sf3_triage reads the tracked config/near_match_negatives.tsv (a new
--negatives input) and excludes those rows as recorded_negative=69. The
tracked index was grown from 38 Phase-8 rows to 94 by importing 56 Phase-9
negatives from the workers' reports and the coordinator's absorption record
(filtered to unregistered; tracked rows win on conflict). Worklist
regenerated: the head is now genuinely fresh (0x800F9134, 0x80042D88,
0x800450C4, ...). 3 new synthetic tests; plan-level tests wired for the new
argument. The phase plan said extract negatives only at close; B's
measurement showed the harm is per-cycle, so the index is now a living
tracked input. Note for P9-T8: keep importing worker negatives each cycle.
Worker B found the exclusion detector's blind spot: opcode 0x08 (addi, traps
on overflow) appears in 7 of 1,666 worklist rows (frame adjustments
addi sp,sp,-28, loop counters) while 0 of 310 registered regions contains
one — the same disjointness signal as finding 26's R-type class. addiu (0x09)
is ubiquitous, so the 0x08 occurrences are the anomaly. Verified by the
coordinator from raw words: 7 rows, incl. 3 of partition A's 5 call-shape
rows (0x80011084, 0x800F3B10, 0x80010F30) and 0x800F3BB4 (previously
recorded as a separate coordinator negative — now explained by this class).
sf3_triage.trapping_arithmetic now counts opcode 0x08; worklist regenerated
(1,563 rows, excluded_trapping_arith=54). Synthetic test added.
P9-T5 route (a) widened: the immediate form is part of the class; the 7
ADDI rows are a ready-made minimal probe set for any cc1 candidate.
Also confirmed this cycle: the no-frame global-ra ISR family (ra saved to a
global, no stack frame — 0x801097A0 proved, 0x8010B420 pattern-transferred)
is a second library-asm class identical in kind to the CRT entry.
Coordinator absorbed partition B directly: 0x800F5AF8 (four pointer-slots
stored from constants — the globals at 0x8011A9E4 are POINTER VALUES read by
lw rt,sym then stored through, not direct symbol stores) and 0x80021FA8
(six 16-byte records, four fields zeroed via symbol+index, store-order fix).
0x800518BC recorded as a bounded return-merge negative. Gate MATCH
whole-binary SHA-1 e173426c157384ebf1b6caf8c6fea18a85a14af9.
Worker A reported nine worklist rows graded exact that are not function
starts. The coordinator verified the tell independently: a candidate whose
first instruction reads a register the range never defines (non-parameter),
or whose range has no jr/jalr return, is a wrong extent. Measured disjoint
from the matched corpus (7 worklist rows flagged incl. the runaway
0x801800C4 and the fallthrough 4-byte rows 0x80100808/0x80180808; 0 of 288
registered flagged). Implemented as excluded_bad_extent_start in sf3_triage
with 4 synthetic tests; worklist regenerated to 1,570 eligible rows.
Worker A rotated out at 108 claims (+79 from its session) with a clean
handoff; final 4 rows verified MATCH by the coordinator. 18 new regions
gated MATCH whole-binary (c_regions=306, SHA-1
e173426c157384ebf1b6caf8c6fea18a85a14af9), make check green.
P9-T4 checkpoint (>=290 total) CROSSED at 297 bodies.
All three workers have now rotated out; the coordinator absorbs the
remaining partitions. Negatives census now 34 report rows from A alone
(25 match-class + 9 bad-extent triage), with the bad-extent class verified
independently by the coordinator (disjoint from 288 registered regions;
7 worklist rows flagged incl. the runaway 0x801800C4/0x80180808 that were
never excluded because they are fallthrough-graded).
Handoff notes recorded: two high-value unattempted GTE rows (0x80101C2C,
0x80102FA4 — need raw lwc2/swc2 asm with memory operands), 8 lever findings
for the next charter (srl=sra-unsigned, slti-sltiu 16-bit tell, single-exit
result shape, struct-assignment for a0/a1 loads, maspsx=off scope x2, side-
effect statement order, lui/lw address arithmetic, CSE-preventing symbols).
The bad-extent detector is implemented in sf3_triage with synthetic tests;
the regenerated worklist will exclude the class.
Worker A batch 10 incl. the finding-13 store-only callee caller, pointer-table
walk, byte-dispatch 2-arm (not switch). Three negatives recorded: epilogue-
order-variant THIRD data point 0x800FBD80 (class now 3 members outside CRT +
new arg-copy tell), alloc+storeform 0x800582AC (explicit lui/at form tied to
allocation), alloc-tiebreak 0x800161E0. Gate MATCH whole-binary SHA-1
e173426c157384ebf1b6caf8c6fea18a85a14af9.
Worker C rotated out on budget with a clean handoff (28 claims total, all
verified; 18 negatives with hypotheses). Its final 2 rows verified MATCH
(0x80101838 reopening closed via do/while + sentinel: this closes B's cycle-2
negative on the same address!; 0x8007C4A8). Handoff inheritance: orig.py
disassembly helper, F1-F14 findings confirmed, 2-byte free claim 0x800266A8
left with its exact hypothesis. Gate MATCH whole-binary SHA-1
e173426c157384ebf1b6caf8c6fea18a85a14af9.
Worker A batch 9: if-conversion demo, pre-increment append, negate-magnitude,
guarded call pairs, epilogue-order-variant NEGATIVE 0x80100334 (finding 11's
'13 CRT sites' scoping corrected — this site is outside the CRT; recorded as
a third epilogue class data point), sched-tiebreak 0x8002515C. New symbol
D_80122160 (gp). Gate MATCH whole-binary SHA-1
e173426c157384ebf1b6caf8c6fea18a85a14af9.
8 regions (A 7 + C handoff 0x8010A748), gate MATCH whole-binary SHA-1
e173426c157384ebf1b6caf8c6fea18a85a14af9; make check green. New symbols:
D_80121B4C (gp, worker A request for the jalr-through-gp-pointer row). New
negative: 0x8008F478 sched-tiebreak (register-position only, 3 spellings
identical). Triage note: 0x80180808 fallthrough row is data (cookbook's
runaway-walk record) — worker-skipped.
Worker A is now at 71 claims / 12 negatives; worker C at 25 / 13. The
coordinator continues absorbing partition B.
14 more regions merged and gated MATCH (c_regions=260, whole-binary SHA-1
e173426c157384ebf1b6caf8c6fea18a85a14af9); make check green (AGREE + MATCH).
Full audit passed from clean state (CMP_OK, SHA-1, 223 tests, gate, extents).
Worker A: 12 more (tier-2 wrappers incl. 7-arg o32 forwarder, GTE-forwarder
adjacent to the registered maspsx=off 0x800F3160, and 0x80036380 — a
byte-proven 48-byte empty-frame registered under an honest limits header).
New: maspsx-conflict scope limit (finding 17 corrected: maspsx=off unsafe
for bodies with move pseudo-instructions — addu-vs-or expansion), alloc-
tiebreak negative 0x80019700.
Worker C: 2 boundary-crossing matches accepted under the decided policy
(verified work is claimable across regenerated partition edges); handoff
0x8010A748 accepted. F10 named-pointer base-first for register bases (closes
the F5 gap), F11 duplicate stores need volatile, F12 if-conversion is a
compiler class (0x80010418 exclusion recommended and accepted).
Collision policy decided: verified work is claimable regardless of the
regenerated partition boundary; overlapping staging is deduped by the merge.
All boundary crossings reported by the workers.