3dd4b4537e
32 new bodies from 400, all verified on the candidate whole-binary gate before promotion. SHA-1 e173426c157384ebf1b6caf8c6fea18a85a14af9 stable. Registry requests granted (each byte-verified with a failing control): cc1=-G8 on 0x800A6BEC; gp=-D_80121B88 on 0x80015D50 symbols D_80122700, D_80122704, D_80121AD4 (gp) Harness: per-region maspsx modes wired through sf3_match (maspsx=noreordernop, maspsx=regread) plus --no-jump-slot-nop/--nop-on-reg-read for range. Both are opt-in and default-off; make check green at 441 with them off, suite 229 -> 232 tests. Carried as a TRACKED patch (tools/patches/maspsx-phase10-r1r2.patch) because tools/maspsx/ is git-ignored, so an in-place edit would not survive a fresh clone; patch verified to reproduce the working tree byte-identically. R1/R2 are recorded as a MEASURED NEGATIVE: neither closes a region (cookbook finding 40 has the mechanism and the remaining developer-owned route). Docs: cookbook finding 40 (rare-epilogue mechanism + why the obvious maspsx fix fails); SETUP.md maspsx patch provenance and apply step. Negatives: 0x8010AA28 imported; index sorted by address (140 rows, 0 registered). Full clean audit green: make clean && make all exit 0, cmp exit 0, both SHA-1 match, registry 441/0 overlaps/0 bad extents/0 missing sources, 0 firewall.