Commit Graph

79 Commits

Author SHA1 Message Date
Christopher Williams f8cdae42fd phase9: absorption batch 2 — 310 regions / 301 distinct bodies
Both worker-A-flagged high-value GTE rows closed by the coordinator:
0x80101C2C (nCLIP 0x480012 via lwc2/swc2/cfc2 asm, IR1-3 store + LZCR)
and 0x80102FA4 (mfc2 IR1/IR2 halfword stores + IR3 swc2 + LZCR). Added
gte_ldTRX/gte_ldTRY/gte_ldTRZ ($5-$7, translation block) to gtemac.h.
Gate MATCH whole-binary SHA-1 e173426c157384ebf1b6caf8c6fea18a85a14af9.

Bounded negatives recorded: 0x800F3BB4 (global-ra-save guard — CRT/library
asm pattern not reachable from C), 0x800B34A4/0x800A6658 (alloc-tiebreak),
0x800C3514 (alloc+layout), 0x800518BC (return-merge), 0x800F7930
(record-builder alloc), 0x800690E4 (loop-rotation), 0x80012A98
(scheduler-bound family).
2026-09-24 00:57:11 -04:00
Christopher Williams 345f5ecce6 phase9: coordinator absorption — 2 more regions (308 regions / 299 distinct bodies)
Coordinator absorbed partition B directly: 0x800F5AF8 (four pointer-slots
stored from constants — the globals at 0x8011A9E4 are POINTER VALUES read by
lw rt,sym then stored through, not direct symbol stores) and 0x80021FA8
(six 16-byte records, four fields zeroed via symbol+index, store-order fix).
0x800518BC recorded as a bounded return-merge negative. Gate MATCH
whole-binary SHA-1 e173426c157384ebf1b6caf8c6fea18a85a14af9.
2026-09-24 00:50:56 -04:00
Christopher Williams 85ae47d4a1 phase9: P9-T5 bounded investigation — route (a) closed, gap census + library-code evidence recorded 2026-09-24 00:46:59 -04:00
Christopher Williams 43201fa603 phase9: ledger — cycle-2 close, P9-T4 checkpoint crossed, all workers rotated 2026-09-24 00:44:15 -04:00
Christopher Williams 6d3a6ba434 phase9: bad-extent classification in sf3_triage (worker A's class, coordinator-verified)
Worker A reported nine worklist rows graded exact that are not function
starts. The coordinator verified the tell independently: a candidate whose
first instruction reads a register the range never defines (non-parameter),
or whose range has no jr/jalr return, is a wrong extent. Measured disjoint
from the matched corpus (7 worklist rows flagged incl. the runaway
0x801800C4 and the fallthrough 4-byte rows 0x80100808/0x80180808; 0 of 288
registered flagged). Implemented as excluded_bad_extent_start in sf3_triage
with 4 synthetic tests; worklist regenerated to 1,570 eligible rows.
2026-09-24 00:44:07 -04:00
Christopher Williams e523890b5f phase9: tracked worklist exclusions for the 0x80012A10 family and the maspsx-blocker row (0x8008A198) 2026-09-24 00:43:03 -04:00
Christopher Williams a106afe5ab phase9: merge worker A handoff — 306 regions / 297 distinct bodies
Worker A rotated out at 108 claims (+79 from its session) with a clean
handoff; final 4 rows verified MATCH by the coordinator. 18 new regions
gated MATCH whole-binary (c_regions=306, SHA-1
e173426c157384ebf1b6caf8c6fea18a85a14af9), make check green.

P9-T4 checkpoint (>=290 total) CROSSED at 297 bodies.
All three workers have now rotated out; the coordinator absorbs the
remaining partitions. Negatives census now 34 report rows from A alone
(25 match-class + 9 bad-extent triage), with the bad-extent class verified
independently by the coordinator (disjoint from 288 registered regions;
7 worklist rows flagged incl. the runaway 0x801800C4/0x80180808 that were
never excluded because they are fallthrough-graded).

Handoff notes recorded: two high-value unattempted GTE rows (0x80101C2C,
0x80102FA4 — need raw lwc2/swc2 asm with memory operands), 8 lever findings
for the next charter (srl=sra-unsigned, slti-sltiu 16-bit tell, single-exit
result shape, struct-assignment for a0/a1 loads, maspsx=off scope x2, side-
effect statement order, lui/lw address arithmetic, CSE-preventing symbols).
The bad-extent detector is implemented in sf3_triage with synthetic tests;
the regenerated worklist will exclude the class.
2026-09-24 00:42:33 -04:00
Christopher Williams 80a4e9e5ed phase9: merge 5 more — 288 regions / 279 distinct bodies
Worker A batch 10 incl. the finding-13 store-only callee caller, pointer-table
walk, byte-dispatch 2-arm (not switch). Three negatives recorded: epilogue-
order-variant THIRD data point 0x800FBD80 (class now 3 members outside CRT +
new arg-copy tell), alloc+storeform 0x800582AC (explicit lui/at form tied to
allocation), alloc-tiebreak 0x800161E0. Gate MATCH whole-binary SHA-1
e173426c157384ebf1b6caf8c6fea18a85a14af9.
2026-09-24 00:34:32 -04:00
Christopher Williams c286bc4355 phase9: merge worker C handoff close — 283 regions / 274 distinct bodies
Worker C rotated out on budget with a clean handoff (28 claims total, all
verified; 18 negatives with hypotheses). Its final 2 rows verified MATCH
(0x80101838 reopening closed via do/while + sentinel: this closes B's cycle-2
negative on the same address!; 0x8007C4A8). Handoff inheritance: orig.py
disassembly helper, F1-F14 findings confirmed, 2-byte free claim 0x800266A8
left with its exact hypothesis. Gate MATCH whole-binary SHA-1
e173426c157384ebf1b6caf8c6fea18a85a14af9.
2026-09-24 00:33:42 -04:00
Christopher Williams c160fa9326 phase9: merge 6 more — 281 regions / 272 distinct bodies
Worker A batch 9: if-conversion demo, pre-increment append, negate-magnitude,
guarded call pairs, epilogue-order-variant NEGATIVE 0x80100334 (finding 11's
'13 CRT sites' scoping corrected — this site is outside the CRT; recorded as
a third epilogue class data point), sched-tiebreak 0x8002515C. New symbol
D_80122160 (gp). Gate MATCH whole-binary SHA-1
e173426c157384ebf1b6caf8c6fea18a85a14af9.
2026-09-24 00:32:22 -04:00
Christopher Williams af9630b617 phase9: merge 7 more — 275 regions / 266 distinct bodies (worker A batch 8)
A's maspsx=off extension to CALL delay slots verified (0x80102B30: symbol-store
macro split around jal, 44B MATCH); third/fourth indirect-call wrappers through
D_8011FB4C; record-build shape; wrong-extent triage row 0x801BB450 recorded.
Gate MATCH whole-binary SHA-1 e173426c157384ebf1b6caf8c6fea18a85a14af9.
2026-09-24 00:29:40 -04:00
Christopher Williams b27ba1bac1 phase9: merge cycle 2 final — 268 regions / 259 distinct bodies
8 regions (A 7 + C handoff 0x8010A748), gate MATCH whole-binary SHA-1
e173426c157384ebf1b6caf8c6fea18a85a14af9; make check green. New symbols:
D_80121B4C (gp, worker A request for the jalr-through-gp-pointer row). New
negative: 0x8008F478 sched-tiebreak (register-position only, 3 spellings
identical). Triage note: 0x80180808 fallthrough row is data (cookbook's
runaway-walk record) — worker-skipped.

Worker A is now at 71 claims / 12 negatives; worker C at 25 / 13. The
coordinator continues absorbing partition B.
2026-09-24 00:27:50 -04:00
Christopher Williams 08a261d29e phase9: ledger — cycle 2 closed, full audit green, collision policy recorded 2026-09-24 00:26:58 -04:00
Christopher Williams e317c8ed5a phase9: merge cycle 2 close — 260 regions / 251 distinct bodies
14 more regions merged and gated MATCH (c_regions=260, whole-binary SHA-1
e173426c157384ebf1b6caf8c6fea18a85a14af9); make check green (AGREE + MATCH).
Full audit passed from clean state (CMP_OK, SHA-1, 223 tests, gate, extents).

Worker A: 12 more (tier-2 wrappers incl. 7-arg o32 forwarder, GTE-forwarder
adjacent to the registered maspsx=off 0x800F3160, and 0x80036380 — a
byte-proven 48-byte empty-frame registered under an honest limits header).
New: maspsx-conflict scope limit (finding 17 corrected: maspsx=off unsafe
for bodies with move pseudo-instructions — addu-vs-or expansion), alloc-
tiebreak negative 0x80019700.
Worker C: 2 boundary-crossing matches accepted under the decided policy
(verified work is claimable across regenerated partition edges); handoff
0x8010A748 accepted. F10 named-pointer base-first for register bases (closes
the F5 gap), F11 duplicate stores need volatile, F12 if-conversion is a
compiler class (0x80010418 exclusion recommended and accepted).

Collision policy decided: verified work is claimable regardless of the
regenerated partition boundary; overlapping staging is deduped by the merge.
All boundary crossings reported by the workers.
2026-09-24 00:26:45 -04:00
Christopher Williams 6e8c3df7a7 phase9: ledger — cycle 2 totals, P9-T5 gap-measurement verification, partition-B absorption 2026-09-24 00:24:06 -04:00
Christopher Williams e51ec91514 phase9: tracked worklist after the 0x80012A10-family exclusion (1,666 rows) 2026-09-24 00:23:56 -04:00
Christopher Williams e7603dc531 phase9: merge cycle 2 progress — 246 regions / 237 distinct bodies
31 new regions merged and gated MATCH (whole-binary, SHA-1
e173426c157384ebf1b6caf8c6fea18a85a14af9), make check green
(regions=246 disagreements=0 AGREE, c_regions=246 MATCH).

Worker A took the tier-2 lead the rotation pointed at: 29 new framed
wrapper/call bodies incl. jalr-indirect rows, argument-swap wrappers, and a
statement-order-around-side-effect fix (0x800198C0). New levers recorded:
lui/lw symbol address arithmetic check (carry-adjusted %hi), named-local
ordering around a side-effect store.

Worker C closed two retry rows from the negatives index: 0x80036AD8
(commutative-operand-order, the 0x8002DEB4-class) and 0x800B5CB4 (deferred
--g_80122068 family hypothesis, using the gp symbols staged in cycle 1).

Worklist regenerated with the 0x80012A10-family exclusion (worker C
recommendation): --exclude 0x80012A10 --exclude 0x80012AE0, pool 1,666,
named exclusions 5; partitions re-proved disjoint (556/555/555).

Worker B rotated out (budget) with a clean handoff: 13 promoted claims, 18
negative entries in report.tsv, four named cheap closes for fresh context,
and a P9-T5 lead (trapping arithmetic in un-extented gaps, verified by the
coordinator: 275 gap words vs 661 in-extent words). No replacement session
available; the coordinator absorbs partition B per the plan's fallback.
2026-09-24 00:23:51 -04:00
Christopher Williams ce75bee419 phase9: record worker B budget rotation; coordinator absorbs partition B 2026-09-24 00:21:33 -04:00
Christopher Williams 318e73ab75 phase9: record cycle 1 detail, GTE map correction, and negative census in the ledger 2026-09-24 00:16:17 -04:00
Christopher Williams 2bb883c871 phase9: merge cycle 1 — 57 claims verified, 39 new regions (206 distinct bodies)
Coordinator-verified every staged claim with its own range runs (57/57 MATCH,
one required the staged gp symbol g_80122158). Merged to a candidate, whole-
binary gate MATCH at c_regions=215, differing_bytes=0, SHA-1
e173426c157384ebf1b6caf8c6fea18a85a14af9; promoted; make check green
(regions=215 disagreements=0 result=AGREE, c_regions=215 MATCH, 223 tests).

Workers: A 23, B 13, C 21 claims. New symbols: g_80122158/g_80122068/
g_8012277C/g_80122738 (gp-marked, worker C request). Override additions:
0x80104C38 maspsx=off (verified 1-byte DIFF with maspsx on at the loop
back-edge, finding 17 family).

gtemac.h GTE control map corrected after two workers' independent decodes
and coordinator raw-word verification: the executable's control registers
are the standard map UNshifted for 0..5 (rotation matrix, 0x80101CAC) and
standard+7 from RBK onward (3 RBK .. 8 DQB); light matrix is 6..0,
far colour 1..3, H 6, DQA 7, DQB 8. Cookbook finding 24's label
for 3..5 was wrong; the numbers were always right. Added gte_ldH,
gte_ldRT1RT2..gte_ldRT33; func_8001AE3C.c updated to the corrected
RBK/GBK/BBK macros (re-verified MATCH); 0x80102FD4 and 0x80101CAC rewritten
to macro form (re-verified MATCH).

Recorded negatives: A 4 (cond-value-ifconv, alloc-scheduling, cc1-fold,
strength-reduce+loop-rotate), B 7 (incl. exit-duplication, load-use-nop
GTE alloc class, finding-4 sign-adjust trap), C 6 (incl. delay-slot-fill
class, cc1-scheduler-bound). All deployed from src/.
2026-09-24 00:16:00 -04:00
Christopher Williams 706c5455cd phase9: record cycle-1 dispatch numbers in the ledger 2026-09-23 23:54:31 -04:00
Christopher Williams 54af82aa95 phase9: ledger, delay-slot exclusion, and the promoted instruction-diff tool
P9-T1: create CURRENT_PHASE.md as the phase ledger; baseline revalidated
clean (cmp + SHA-1 e173426c157384ebf1b6caf8c6fea18a85a14af9, make check
regions=158 disagreements=0 c_regions=158 MATCH); three workers probed and
recruited (01a0d180-ea72/-efdd/-f513); 3-way partitions generated and proved
disjoint (3x575 rows, pairwise intersections 0, union == worklist).

P9-T2 (tooling half): promote worker B's scratch instruction diff into
tools/sf3_diff, hardened per the plan: PS-X LOAD read from the header,
objdump path derived from the repo, temp files under the caller's work dir,
resolver printing ready-to-paste symbol names. 17 synthetic tests.

sf3_triage: new counted exclusion excluded_delay_slot_start=5, implemented
after independent verification of worker B's finding (a branch/jump always
executes its delay slot, so no function starts at X+4; 0 of 158 registered
regions does). Worklist regenerated: 1725 eligible rows, tiers 355/1365/5.
3 new synthetic tests; existing triage fixture extended.
2026-09-23 23:52:58 -04:00
Christopher Williams 48dca3e271 phase9: add the worker-identification procedure to the plan
With four fresh sessions in one repository the coordinator must be able to tell
which peers are its workers without assuming: list the sessions in this cwd
excluding itself, probe each, recruit the responders up to three, never charter a
session that has not answered, and record the recruited ids in the ledger so a
later cycle or a replacement coordinator can tell who is who. This also covers the
case where an extra session (a planning session left open) is live in the repo.
2026-09-23 23:40:30 -04:00
Christopher Williams d9a43975d4 phase9: draft the scaled coordinated plan with a 500-body target
Developer goal: 500 distinct matched bodies (from 149, so >=351 new), run
unattended overnight by one coordinator and three workers.

The plan reuses the Phase 8 protocol verbatim - it is the contract that just
closed a successful phase - and adds only what scale requires: 3-way disjoint
partitions regenerated every cycle, an explicit autonomy loop the coordinator
repeats without developer input, planned worker rotation (a fresh session is a
fixed resource and one phase can consume one, with an absorb-it-yourself
fallback), and a verification ladder that gates every cycle and audits every
third.

The pool is measured and the risk is stated rather than assumed: 1730 eligible
candidates remain, but the easy tier-1 leaves are largely already matched, so the
phase works mostly tier-2 bodies where Phase 8 measured 5/12 in the 56-64 byte
band. 200-300 new bodies is the realistic band and 351 is the stretch, so the
target is staged at 180/230/290/400/500 with explicit stop conditions - including
"three consecutive cycles add fewer than 5 bodies" - so an unattended run cannot
spin without producing evidence. On any stop the registry must be green first.

One structural task: the trapping-arithmetic class, 50 bodies that no available
compiler emits and the best current lead on the unresolved library-versus-game
question. Its route (b) - a documented per-region transform - is flagged as a
developer convention decision, not the coordinator's to take.

Also records the coordinated workflow in the README's methodology section, which
is what the developer asked for.
2026-09-23 23:39:37 -04:00
Christopher Williams 2e7daf5329 phase8: close the phase with the verification milestone
Developer-confirmed milestone: 149 distinct byte-identical bodies across 158
registered regions, up from 34 / 39 at Phase 7 close - 115 new bodies against a
target of 70, produced by three sessions working one worktree under a written
protocol.

Adds PhaseEnd_Phase8.md and the digest entry, archives CURRENT_PHASE.md as
logs/Phase8.md, and completes docs/PHASE8_PROTOCOL.md with the retrospective the
developer asked for: which rules were load-bearing (worker/coordinator file
ownership, candidate-first merging, worklist regeneration, self-contained
charters), where the protocol needed a decision, the four failure modes seen with
their mitigations, and reusable CHARTER and worker-report templates so the next
coordinated phase does not pay the cost of writing them again.

Final gates: 203 tests; make clean, make all, cmp and SHA-1 e173426c...; make
check green at c_regions=158 with 0 differing bytes and regions=158
disagreements=0; registry audit 0 violations; no untracked file in src/; 244
tracked files, none under a prohibited root.
2026-09-23 23:36:58 -04:00
Christopher Williams ea6841d307 phase8: consolidate at 158 regions / 149 bodies and record the verification gate
All gates exit 0 from a clean state: make clean, make all, cmp, both files SHA-1
e173426c..., and make check (203 tests, regions=158 disagreements=0, c_regions=158,
0 differing bytes). The registry audit reports 0 violations across 158 ordered,
non-overlapping regions whose every extent is graded exact and whose every source
exists. The worklist regenerates with excluded_already_registered=158, equal to
the registry. 244 tracked files, none under a prohibited root, and no unmatched
draft survives in src/.

Phase 8 went from 34 distinct bodies / 39 regions to 149 / 158 against a target of
70, with three pi sessions working one worktree under a written protocol. Adds the
verification record, the open-negatives index (addresses, sizes, statuses and class
labels only - no bytes, no instruction text), and the README status.

Worker B's last act is recorded as a result rather than a footnote: it tested
worker A's mirrored-layout lever against its own two bounded negatives and
produced a decision rule instead of a match - the lever applies when the
instruction count is already correct and the block order is wrong, so where the
count is wrong and the order right it only trades one defect for another.
2026-09-23 23:32:20 -04:00
Christopher Williams 6ef29e45e9 phase8: merge cycle 6 and record the conventions the phase produced
5 new matches from worker A (func_800F75D0, func_80026180, func_8003768C,
func_80089D14, func_800681A4) -> 158 regions / 149 distinct bodies, candidate gate
0 differing bytes, make check green.

MATCHING_CONVENTIONS.md now records the four per-region override keys with the
byte-level measurement behind each (cc1=, as=, gp=-NAME, maspsx=off), the
inline-assembly convention as the developer decided it (accepted for coprocessor
and kernel instructions, documented per file, integer logic in C, no .word lumps,
and a register-name binding is not inline assembly), the rule that an unmatched
draft does not stay in src/, and the worklist classes that are excluded outright
with counted reasons.
2026-09-23 23:26:49 -04:00
Christopher Williams db8afed4bf phase8: merge worker C's 0x80019B6C
0x80019B6C is the one-byte commutative-operand row that workers A and B both left
open; worker C closed it by counting the loop down from 272 with `i >= 0` and
using a byte offset into a char array, rather than the scaling form.

Registry: 153 regions. make check green at 203 tests, regions=153
disagreements=0, c_regions=153.

Worker C also removed its own unmatched g0013 draft from src/ citing the
"unmatched code stays fallback" convention, preserving it in the ignored staging
path with its evidence. Nothing referenced it.
2026-09-23 23:25:16 -04:00
Christopher Williams 591923a32f phase8: exclude the trapping-arithmetic class and record the shape tells
Worker C found the strongest structural signal of the phase and asked me to act
on it rather than merely record it. I re-derived the census independently before
acting: 50 of the 1,937 exact extents contain trapping add/sub (funct 0x20/0x22,
410 instructions) and 0 of the 144 then-registered regions does. All four
unmatched duplicate groups are inside the class. Ten cc1 builds plus the real
CC1PSX 4.0-4.6 over ~30 C shapes and 15 flags never emit the trapping forms, and
-ftrapv is rejected by all of them.

tools/sf3_triage now detects the class and excludes it by default
(excluded_trapping_arith=50, --allow-trapping to list it), with three synthetic
tests, so no worker can spend budget on it by accident. Recorded as cookbook
finding 26 with the neg-macro clue that points at a macro-print-style difference
rather than a source difference. The class is now the best candidate for part of
the unresolved library-versus-game-code boundary - a hypothesis, not a claim.

Also recorded: worker A's maspsx load-delay defect (its predicate tests whether
the next instruction loads FROM the register, not whether it reads it at all, so
a load followed by a store of that register gets no delay nop), four mechanical
layout tells, and the struct-assignment lever for the base-in-register class.
Finding 22 is refined with worker C's third spelling: the written order of the +
operands decides the emitted addu order.

Cycle 5 merge: 65 claims, 8 accepted, 57 skipped, 0 rejected. Candidate gate
c_regions=152, 0 differing bytes; promoted; make check green at 203 tests.
Distinct matched bodies: 143.
2026-09-23 23:23:33 -04:00
Christopher Williams dafdd6998e phase8: register the COP2 and BIOS-stub regions under the accepted convention
Developer decision: inline assembly is accepted for coprocessor and kernel
instructions, documented per file. The boundary already applied: the stack
accessor (register int sp __asm__("$29"), a register-name binding rather than an
instruction) was treated as pure C and merged earlier; these 7 regions each carry
one __asm__ volatile statement in the re-derived SDK-macro form, with the integer
logic in C and the epilogue and scheduling produced by cc1 and maspsx. No .word
lumps and no whole-function assembly.

7 regions: 0x80103A94 (cfc2), 0x80103B60 (ctc2), 0x800F3E70 (mtc2/mfc2),
0x80109778 (two ctc2), 0x8001AE3C (three ctc2), 0x80103FCC and 0x80103FEC (BIOS
stubs, whose 16-byte extents come from the syscall-terminator fix).

include/gtemac.h is tracked as the provenance record for the re-derived
encodings and the control-register map. It is worker C's own derivation from the
observed bytes, with no SDK text; the staged sources are self-contained and do
not depend on it yet.

Candidate gate: c_regions=144, 0 differing bytes, SHA-1 e173426c. Promoted, then
make check green. Distinct matched bodies: 135.
2026-09-23 23:18:25 -04:00
Christopher Williams 18e784df39 phase8: record cycle 3, the SDK-shape verdict, and the worker negative results
Cycle 3 merged 22 claims (worker A's 8 new plus 9 gp rows, worker C's 6 pure-C
rows) at 137 regions / 128 distinct bodies, and closed every near-miss that
Phases 5-7 recorded in the reachable set: 0x800F3160, 0x800F8AEC, 0x800F8B58/6C,
0x800F8FE4, 0x80102B10 (maspsx=off), 0x800F7FB4 x3 (a cc1 loop-shape artifact),
0x8009E8D0 x2 (ordinary matching).

Worker C's SDK-shape investigation refuted its own premise: the COP2 shapes are
reachable, the blocker was never the missing SDK headers, and the stack accessor
needs no asm at all. The 8 COP2/syscall regions are parked pending the
developer's inline-asm convention decision.

Recorded as results, not footnotes: three rules that were tested and bounded. The
commutative-operand rule's direction is right but its trigger fails for a literal
base in a counted loop; the do/while loop rewrite does not transfer to
0x800FBF5C; and the reorg class is a cc1 reorder thread-fill decision that no
assembler can perform for a conditional branch, so it is a bounded negative
rather than a harness gap.
2026-09-23 23:16:08 -04:00
Christopher Williams 2775d2e077 phase8: merge cycle 3 — g0007 and g0030 closed, 137 regions / 128 bodies
22 claims accepted (worker A's 8 new + 9 gp rows, worker C's 6 pure-C rows),
28 skipped as already registered, 0 rejected. Candidate gate c_regions=137, 0
differing bytes, SHA-1 e173426c; promoted, then make check green (200 tests,
regions=137 disagreements=0).

Worker C closed two duplicate groups that other sessions had left as near-matches:

- g0007 (0x800F7FB4 x3 addresses): the unexplained 8-byte frame was cc1 loop
  restructuring, not a calling-convention need. `for (i = n-1; i != -1; i--) *p++ = 0;`
  makes cc1 emit an unused subu/addu sp pair; an explicit guard plus a do/while
  gives the exact 36 bytes.
- g0030 (0x8009E8D0 x2 addresses): the abs-of-3-component-difference function
  that workers A and B both recorded as near-matches.

The two BIOS stubs are still policy-gated (they need an inline-asm statement) and
are not in this merge. Distinct matched bodies: 128.
2026-09-23 23:13:17 -04:00
Christopher Williams 62983c9a8a phase8: syscall returns, so it is not a walk terminator
Worker C found that config/function_extents.tsv mis-split the two BIOS stubs:
it recorded 0x80103FCC..0x80103FD4 (8 bytes) and 0x80103FEC..0x80103FF4, but the
real bodies are 16 bytes (li a0,N / syscall / jr ra / nop). Its evidence: the
first address has four jal callers and the following address has none, syscall
returns to EPC+4 so the body must continue to a jr ra, every neighbouring stub is
16 bytes with the same shape, and an 8-byte body is unreachable from C because
cc1 always appends an epilogue.

Root cause: the walk treated `syscall` as a terminal alongside `break`. On this
target syscall is the BIOS call instruction and it returns to the next word.
`break` still terminates. After the fix both stubs are 16 bytes ending at their
jr ra, and all 115 registered regions still agree with their derived extents.

The fix also exposed three walks in the 0x8017xxxx region that the accidental
syscall stop had been bounding: 0x8017D5C0 now runs out of the payload
(grade=outside), 0x801800C4 becomes a 1860-byte fallthrough, and 0x8018080C a
240708-byte indirect. All three are jal-graded starts whose bodies are almost
certainly data; none is registered and none is matchable. 200 tests pass.
2026-09-23 23:11:38 -04:00
Christopher Williams e98aa102e4 phase8: rules check after P8-T4 2026-09-23 23:07:30 -04:00
Christopher Williams 270cb6201a phase8: record cycles 1-2 and the two harness mechanisms
Control record updated with both verified cycles, the two per-region overrides
that came out of worker findings (maspsx=off and gp=-NAME, with the byte evidence
for each of the six anomaly-class regions), and the coordinator findings: the
stale worklist caught before dispatch, the candidate-first merge that contained a
bad cycle, Ghidra's COP2 pseudo-op collapsing, and the two $gp thunk halves.

Also excludes 0x80108034 and 0x8010804C from the worklist: they are the two halves
of a $gp-switch thunk and are not matchable as C regions.

Milestone met at 109 distinct bodies (target 70).
2026-09-23 23:06:54 -04:00
Christopher Williams 9a49ee62f7 phase8: close the assembler-anomaly and gp-site classes, reaching 109 bodies
Two harness gaps were closed as per-region overrides, both found by the workers
and implemented by the coordinator:

1. maspsx=off. Worker A isolated the $at-macro-store-in-the-jr-delay-slot shape
   with a decisive experiment: cc1 emits an empty delay slot, maspsx fills it with
   a nop, and GNU as in reorder mode fills it properly by moving the last half of
   the expanded store. Six regions need this, including 0x800F3160 -- Phase 5's
   first recorded bounded negative, unreachable for three phases -- and 0x800F8AEC,
   0x800F8B58, 0x800F8B6C, 0x800F8FE4, 0x80102B10. Worker B reverse-engineered the
   same mechanism independently from the cc1 output.

2. gp=-NAME. The gp marker is per symbol, but the original's access form is per
   SITE: 0x80121F84 is read gp-relative at 0x800A80BC and written absolutely at
   0x8002D288, in the same function. A byte search confirmed 6 gp-relative
   accesses at d=0x64c, so worker B's census row was right and worker A's source
   was right; only a per-region exclusion can express both. This makes cookbook
   finding 10 incomplete.

Both overrides are validated (199 tests, 10 added), and sf3_merge gained
--skip-registered because a worker's claims file is naturally cumulative.

Cycle-2 merge: 66 claims, 58 accepted, 8 skipped, 0 rejected. Candidate gate:
c_regions=115, 0 differing bytes, SHA-1 e173426c. Promoted, then make check green:
199 tests, regions=115 disagreements=0, c_regions=115 MATCH.

Distinct matched bodies: 51 -> 109, past the phase milestone of 70.
2026-09-23 23:05:35 -04:00
Christopher Williams 7c299aca26 phase8: merge worker B's first eight claims and 335 gp rows
P8-T2's protocol record plus worker B's cycle-1 merge.

Worker B verified 8 claims (7 bodies: g0029 is a two-address duplicate group).
It also classified its whole 946-row partition off one objdump and found that 226
rows (24%) access gp-relative globals, staging 335 distinct addresses. Those were
checked before use: every row is arithmetically exact under the list's decimal d
column (335 rows, 0 errors), and four sampled globals were confirmed against my
own Ghidra disassembly (0x564(gp) -> 0x80121E9C and three others). A risk check
for whether a new gp marker could change an already-matched region found only
worker A's unclaimed in-progress files, so no registered region is affected.

323 rows were new (12 already present), taking config/symbols.tsv to 354 rows and
unblocking a quarter of worker B's partition.

Candidate gate: c_regions=57, 0 differing bytes, SHA-1 e173426c. Promoted, then
make check green: 189 tests, regions=57 disagreements=0, c_regions=57 MATCH.
Distinct matched bodies: 34 -> 51.

Worker B also deferred 0x8001D98C (g0053, 436B, GTE 3x3 transform) into the
bounded GTE class, and recorded two byte-proven cookbook findings: BCD nibble
pairs must be their own parenthesised subexpression (a pure association tell, 9
shifted bytes), and a constant absolute address in a load folds the
carry-adjusted low half into the load displacement rather than using lui+ori.
2026-09-23 22:55:42 -04:00
Christopher Williams d7047e08c7 phase8: add the claim-merge tooling and merge worker A's first ten claims
P8-T2 plus the first verified cycle-1 merge.

tools/sf3_merge validates worker claims before anything tracked changes: a claim
is accepted only if its extent exists in the derived extents table and is graded
exact with exactly the claimed end, its source is a repo-relative
src/func_XXXXXXXX.c that exists, and it overlaps neither the registry nor another
worker's claim. Rejections are reported with reasons and nothing is written.

The workflow it enables is stronger than the plan's wording: merge to a CANDIDATE
registry, gate the candidate, and promote only on MATCH, so the tracked registry
never contains an unverified claim.

Worker A reported 10 claims (target 8) and correctly refused to edit the shared
symbol registry itself, instead requesting 9 gp-marked rows; each was checked
arithmetically as gp + d. Candidate gate: c_regions=49, 0 differing bytes, SHA-1
e173426c. Promoted, then make check green: 189 tests, regions=49
disagreements=0, c_regions=49 MATCH.

Worker A also reported a significant blocker: two of the remaining duplicate
groups are GTE (COP2) bodies -- 0x80018CB0 (3 addresses) and 0x8001084C (2
addresses, the 712-byte shared body) -- plus 0x80103A94 and 0x80103B60. That is
four GTE functions, which raises the value of the bounded SDK-shape
investigation in P8-T5.
2026-09-23 22:52:08 -04:00
Christopher Williams 5f07614247 phase8: open the control record, revalidate the baseline, and hand off to two workers
P8-T1 of the coordinated multi-session phase. Baseline re-run green: make clean,
make all, cmp, SHA-1 e173426c..., 168 synthetic tests, extents agreement 39/39,
and the ordered gate at c_regions=39 with 0 differing bytes. No tracked path
under a prohibited root.

Both peers were probed rather than assumed: 01a0d143 and 01a0d145 are live in
this repository at HEAD 42c9b1d with shell and a full tool set, but neither had
read the project docs, so both charters are self-contained. Hard rules were
restated with the probe: the tracked registries, build/ and all writing git
commands are coordinator-only, and only new src/*.c files inside a worker's own
partition may be created.

Before dispatching, the partitions were checked against config/regions.tsv and
the tracked worklist was found STALE -- it was generated in P7-T4 with only 12
regions registered, so it still listed 23 candidates Phase 7 later matched.
Regenerating it gives 1893 listed with 39 excluded as already registered, which
is exactly the 39 regions. Partitions are now 947/946 rows, disjoint
(intersection 0), union equal to the worklist. Worker B's charter was corrected
immediately because it quoted the old bounds.

The charters carry a standing safety net: a worker that finds a row already in
config/regions.tsv must skip it and report, because that means the file went
stale again.
2026-09-23 22:48:25 -04:00
Christopher Williams 42c9b1d9bc phase8: draft the coordinated multi-session plan
Phase 7 made matching possible at scale; Phase 8 makes it parallel. Three pi
sessions in one worktree, coordinated over pi-intercom: one coordinator that
dispatches charters, merges claims and independently verifies them, and two
workers that match concurrently.

The plan's centre of gravity is concurrency safety, because three sessions share
one worktree: src/*.c is partitioned disjointly so no two sessions can write the
same file, the tracked registries and build/ and git are coordinator-only, and
worker deliverables stage in ignored paths. The safety property is that a
worker's claim is never trusted -- the coordinator's own clean make gate over the
whole 1,886,208-byte executable is the only authority, so a fabricated match
breaks the SHA-1, and make extents-verify stops a hand-chosen end address.

Target: at least 70 distinct bodies (from 34), staged across three cycles so a
stall shows up early, plus one bounded investigation into the SDK-header shapes
Phase 7 deferred.

Draft, awaiting approval. Decisions flagged for the developer: this session
coordinates, workers match while the coordinator verifies, the two already-live
peers (01a0d143, 01a0d145) are probed rather than assumed, and the target size.
2026-09-23 22:42:52 -04:00
Christopher Williams 2f05e821fc phase7: close the phase with the verification milestone
Developer-confirmed milestone: 34 distinct byte-identical function bodies across
39 registered regions, up from 11 / 12 at Phase 6 close. Every region end is now
derived from control flow and enforced by make check, duplicate bodies are
censused, match targets come from a ranked worklist, and cross-references no
longer need hand-written symbol rows.

Adds PhaseEnd_Phase7.md and the digest entry, and archives CURRENT_PHASE.md as
logs/Phase7.md.

Final gates: 168 synthetic tests; make clean, make all, cmp and SHA-1
e173426c...; make check green at c_regions=39 with 0 differing bytes and
regions=39 disagreements=0. 121 tracked files, none under a prohibited root.
2026-09-23 22:40:26 -04:00
Christopher Williams 0e3ff39ea9 phase7: record the verification gate and the new conventions
Phase 7 closes the milestone: 34 distinct byte-identical bodies across 39
registered regions, up from 11 bodies / 12 regions at Phase 6 close, with every
region end derived from control flow instead of by hand.

New cookbook findings, each byte-proven:

- 13: a store-only function leaves its constant in v0 as scratch. Writing
  `return 1` costs an instruction in the delay slot (0x8003636C: 12 vs 16 bytes).
- 14: the gp-relative offsets proved so far, with the global each one names.
- 15: shapes plain C cannot reach without SDK headers (GTE/COP2 code, BIOS
  syscall wrappers, stack-pointer accessors).

Conventions updated: a region end comes from config/function_extents.tsv and is
enforced by make check; the duplicate check is the tracked census rather than a
manual search; the worklist is the ranked queue; and address-named symbols
resolve implicitly while anything else fails loudly.

Clean-state gates all exit 0: make clean, make all, cmp, both files SHA-1
e173426c..., and make check (168 tests, regions=39 disagreements=0,
c_regions=39, 0 differing bytes). 121 tracked files, none under a prohibited
root. Milestone confirmation requested before any PhaseEnd.
2026-09-23 22:37:16 -04:00
Christopher Williams dd807ffb8c phase7: match 22 more function bodies from the worklist
Both batch targets are met in one pass: 22 new bodies (23 including the P7-T5
match), taking the project from 11 distinct bodies to 34 -- past the phase
milestone of 30 -- across 39 registered regions.

The batch is dominated by the small leaf shapes the worklist ranks first:
empty function (4 duplicate addresses), byte/halfword/word setters, field
getters, a word-buffer clearer, and eight gp-relative getters/setters. Every one
was byte-identical on the first or second attempt, and every extent came from
tools/sf3_extents rather than a hand-derived end.

Three shapes needed diagnosis, and two were solved:

- 0x8003636C was 16 bytes instead of 12 because `return 1` forced a second
  `li v0,1` into the delay slot; the original leaves 1 in v0 as scratch, so the
  function is `void`.
- 0x800F7FB4 needed the parameter reused as the loop counter.

Four candidates are recorded as bounded negatives or deferrals rather than
guesses:

- 0x800F7FB4: the loop body reproduces exactly, but the original has no frame
  and every tested formulation allocates 8 bytes (five C forms, and an
  -O1/-O2/-O3/-fomit-frame-pointer matrix). Stopped after two distinct attempts.
- 0x800F8AEC: the original schedules `lui` / `jr ra` / `addiu` with the low half
  in the delay slot; the reconstruction emits `lui` / `addiu` / `jr ra` / `nop`.
- 0x80010810: GTE (COP2) code needing the SDK's GTE macros, which the build has
  no headers for.
- 0x800FB5D4 (`move v0,sp`) and 0x80103FCC/0x80103FEC (BIOS `syscall` wrappers)
  and 0x8001EAFC (a shared jump block, not a standalone function).

make gate: c_regions=39, 0 differing bytes, SHA-1 e173426c. Extents verify agrees
on all 39 regions. 168 synthetic tests.
2026-09-23 22:34:02 -04:00
Christopher Williams 399da98a83 phase7: resolve address-named symbols implicitly and fail loudly otherwise
Every cross-reference used to need a hand-written config/symbols.tsv row, which
does not scale to a batch. A symbol whose name is an address now resolves to that
address with no row: func_XXXXXXXX, D_XXXXXXXX, g_XXXXXXXX, lbl_XXXXXXXX. This is
the convention the registry already used, applied without the row.

The names come from the object's own undefined-symbol list (nm -u), not from a
guess about the source, so a name the source defines but never references is
never mistaken for one needing resolution. A registry row still wins, which is
how a gp marker or a real name is attached. Anything neither registered nor
address-shaped now fails before the link with a message naming the symbol and the
fix, instead of a bare ld diagnostic.

First match from the worklist: func_800F8F9C (36 bytes, worklist rank 3), a
duplicate-group representative with a frame and a call. It matched on the first
attempt and is registered twice (0x800F8F9C, 0x80109314) against one source, so
two functions were matched for one body. Its callee needed no registry row.
Ghidra's independent body agrees with the derived extent.

make gate: c_regions=14, 0 differing bytes, SHA-1 e173426c. 168 synthetic tests.
2026-09-23 22:26:08 -04:00
Christopher Williams a6af8b3cd2 phase7: replace hand-picked targets with a ranked, reproducible worklist
Phase 6 chose match targets by eye from the boundary inventory. tools/sf3_triage
now ranks every eligible candidate by (tier, size, address) from tracked inputs
alone and records why everything else was excluded.

Eligibility: an exact or fallthrough extent, a non-degenerate body, not already
registered, not the header entry, not named by --exclude. indirect, escape,
outside, runaway, contained and standalone are excluded and counted.

Tiers: 0 duplicate-group representative (one match, several addresses), 1 exact
leaf (no cross-references, so no symbol rows), 2 exact non-leaf, 3 fallthrough.

Result: 1916 listed (tier 0: 9, tier 1: 509, tier 2: 1394, tier 3: 4), with 252
degenerate bodies, 88 low-confidence grades, 12 registered, 1 header entry and
2 named near-misses excluded. The nine tier-0 entries are the real duplicate
groups: matching those nine bodies registers 22 function addresses.

The two deferred near-misses are excluded by name in the Makefile so the
exclusion stays visible rather than buried in the tool. 160 synthetic tests pass.
2026-09-23 22:19:39 -04:00
Christopher Williams 2000cc4101 phase7: census duplicate bodies and expose a zero band of false positives
Matching conventions require a duplicate check before registering, because a
shared body is matched once and registered once per address. Phase 6 did that
check by hand and found one 12-byte pair. tools/sf3_dupes now hashes every
derived extent body and groups exact duplicates.

Results: 2284 extents, 65 multi-address groups, 2104 singletons. Only 10 groups
contain code (24 addresses, all exact-graded); 55 are all-zero bodies. The
hand-found pair 0x800262E0/0x800262EC is reproduced as g0002, which is the check
that the census measures what it claims. The largest real groups are 712 bytes
(0x8001084C/0x800189E8) and 436 bytes.

The zero groups are a real finding: 252 extents have all-zero bodies, 245 inside
the zero band 0x80147000..0x80170000. The cause is the inventory's jal grade,
which decodes every word as an instruction -- in a data region a word with
opcode 3 is graded as a call whose target lands in the zero band. The census
flags those groups rather than hiding them, and the worklist must exclude
degenerate bodies.

The census is tracked rather than ignored as the plan said, because it holds
addresses, sizes and grades only (the same class as the tracked inventory and
extents tables) and the worklist must be reproducible from tracked inputs. The
content hash is computed and never written.
2026-09-23 22:15:51 -04:00
Christopher Williams 6988ca96b0 phase7: derive evidence-graded function extents from control flow
Phase 6 graded function starts and left every end to be derived by hand. This
adds tools/sf3_extents, which explores all reachable control flow from each hard
start (jal/entry) and reports an extent plus how far it can be trusted.

Measured decisions, not stylistic ones:

- Soft starts are not walk boundaries. A body's second instruction can satisfy
  the prologue grade exactly (0x800152AC is lw v1,8(gp) / addiu sp,sp,-176, so
  0x800152B0 looks like a start). Enforcing soft boundaries stopped 155 of 416
  walks inside a real body.
- The walk is a full reachability computation, not a first-terminal search: a
  function whose paths return at different addresses must report the whole body.

Grades: exact 1940 (1666 packed, gap=0), fallthrough 256, indirect 73,
escape 15, contained 153, standalone 438; 63.8% of the payload covered.

Verification: all 12 registered regions reproduce exactly (make extents-verify,
now part of make check), 29 new synthetic tests (115 total), byte-identical
across two runs, and Ghidra's independent body for FUN_80017ad4 agrees. Two
defects were caught by writing the tests first and are recorded: reach had to be
an exclusive end, and a terminal j's delay slot must not continue linearly.

The table holds addresses, sizes, grades and site addresses only -- no bytes.
2026-09-23 22:12:31 -04:00
Christopher Williams 97ee078142 phase7: open the phase control record, revalidate the baseline, and triage the open items
Approved plan: phase-ends/Phase7_PLAN.md. Goal is scale -- evidence-graded
function extents and a duplicate-body census first, then a batch that takes the
project past thirty distinct byte-identical functions.

P7-T1 re-ran every entry gate green: 86 synthetic tests, clean make all with
cmp exit 0 and both files SHA-1 e173426c..., make gate at c_regions=12 with 0
differing bytes. No tracked path under a prohibited root.

Triage splits the Phase 6 open items into four class blockers (missing function
ends, unknown duplicate bodies, no candidate ranking, per-function symbol-row
cost) and the deferred or unresolved single items (0x8005DEF8, 0x800F3160, the
numeric -G, the CRT entry, library versus game code).

Also ignore .pi/, the agent harness's local task-log state, which was untracked
but not ignored.
2026-09-23 21:59:37 -04:00
Christopher Williams 6ca8ac1a3c phase6: close the phase with the verification milestone 2026-09-23 21:51:44 -04:00
Christopher Williams ce43b7b42b phase6: document the Ghidra-draft workflow and record the verification gate 2026-09-23 21:50:03 -04:00