Roster (fresh, spawned by the orchestrator; tab w1:t5, 2x2 grid):
A w1:pC 01a0d529 A1 lever-a.tsv 334 rows
B w1:pE 01a0d52a-2c40 A1 lever-b.tsv 334 rows
C w1:pD 01a0d52a-55d3 A2 negatives-c.tsv the 101 NAMED negatives
D w1:pF 01a0d52a-6198 A1+B lever-d.tsv 333 + negatives-d.tsv the 92 UNCLASSIFIED
Four agent_pane_not_found errors on first start, all cleared on retry after a few seconds --
the documented transient, not a bad id.
PARTITIONS ARE PROVEN, NOT ASSERTED (.run/p12/partition-proof.txt):
worklist rows 1001; a=334 b=334 d=333; sum 1001; distinct union 1001; overlaps 0;
union == worklist True; negatives 193 (c=101 d=92); negatives overlap worklist 0;
negatives c/d overlap 0.
The phase's structural premise was verified by set comparison: 0 of the 193 negatives rows
appear in the 1001-row worklist, because sf3_triage plan --negatives excludes them. The
negatives are an INDEX, not a queue, and worker C is the first worker in this project whose
partition is that index.
THE MEASURED RANKING, and it produced a real number. Band first, density second, with the
density statistic IMPORTED from the tracked tools/sf3_rank (which declares itself the reference
implementation and warns scores are not comparable across implementations -- reimplementing it
would silently break that guarantee):
band rows median density max size range
0 (<=244 B) 410 0.359 0.912 4-244 B
1 (245-400 B) 225 0.491 0.920 248-400 B
2 (401-800 B) 221 0.604 0.896 404-796 B
3 (>800 B) 145 0.720 0.940 804-11516 B
Median density rises MONOTONICALLY with band. That is worker D's warning ("density is
correlated with size, which biases the top of the list") measured on this corpus, and it is
exactly why a pure density ranking is wrong when the milestone counts BODIES rather than bytes:
one body at 80 B and one at 8000 B are worth the same. Band-first suppresses the bias; density
then orders within the band, where it is the measured cost signal.
MEASURED NEGATIVE, recorded so three workers do not each rediscover it: tools/sf3_family
--top 25 returns candidates=0 against the fresh band at ratio 1.000. The family lever is
EXHAUSTED for the worklist (Phase 11's 7 rows were all of it). It has NEVER been run against
the 193 negatives -- sf3_family reads the worklist, which excludes them -- so that is a named,
UNTRIED lever handed to workers C and D, who were both told to report who runs it.
Baseline revalidated from clean before dispatch: make clean/all exit 0; cmp exit 0; SHA-1
e173426c157384ebf1b6caf8c6fea18a85a14af9 unchanged; make test 290 OK (253 -> 281 -> 290);
extents-verify regions=611 disagreements=0 AGREE; gate c_regions=611 differing_bytes=0 MATCH.
CURRENT_PHASE.md rewritten for the phase, with the milestone warning stated plainly (+148 is
larger than any phase so far) and the cycle-1 requirement that at least 8 bodies must come from
the negatives pool -- so a low overturn rate is measured in cycle 1, not discovered at the close.
Syphon Filter 3 (USA) — matching decompilation
A matching decompilation of Syphon Filter 3 (PlayStation, USA release, SCUS-94640): C source
that, compiled with the game's own late-1990s toolchain, rebuilds the shipped executable byte for
byte.
"Matching" here has a narrow, machine-checkable meaning: the compiled output must be instruction-identical to the original and the whole rebuilt executable must be SHA-1 identical. Nothing "functionally equivalent" counts, and unmatched C never enters the default build.
Status: matching at scale. Phase 9 is closed — milestone partially met. The executable rebuilds byte-identically, the original toolchain is identified from byte evidence, and 400 distinct functions / 409 regions are matched to C — every one instruction-identical and covered by the clean full-binary gate. Function starts, ends and duplicate bodies are all derived from evidence rather than by hand, match targets come from a ranked worklist, and the phase was executed by three pi sessions in parallel under written coordination protocols. The 100-body shortfall below the 500 milestone is recorded with its evidence (measured pool exhaustion), and a Phase 10 plan is drafted pending developer approval.
Where it stands
| Milestone | State |
|---|---|
| Deterministic disc extraction and manifest | done (Phase 1) — two fresh runs, byte-identical manifests |
| First Ghidra import and static oracle | done (Phase 1) |
| All-assembly byte-identical rebuild of the executable | done (Phase 3–4) |
| Address-ordered code-recovery path (entry as real MIPS) | done (Phase 4) |
| Original compiler identified from byte evidence | done (Phase 5) |
| Matching harness and full-binary gate | done (Phase 5) |
| Code/function segmentation | 2,875 candidates graded; extents derived for all of them |
| Duplicate-body census | 65 groups, 10 containing code — 6 of the 10 now fully matched |
| Ranked match worklist | 1,744 eligible candidates, every exclusion counted |
| Multi-session coordination | 3 sessions in one worktree under written protocols (Phase 8 and 9), all claims independently re-verified by the coordinator's own whole-binary gate |
| Functions matched to C | 400 distinct bodies / 409 regions — byte-identical and gated (Ghidra's analyzer reports ~1,721 function candidates) |
The validated target is the USA executable SCUS_946.40;1:
| Property | Value |
|---|---|
| Size | 1,886,208 bytes |
| SHA-1 | e173426c157384ebf1b6caf8c6fea18a85a14af9 |
| Declared payload | [0x80010000, 0x801DC000) |
| Entry PC | 0x800FB368 |
The current tracked build is an all-payload assembly representation: it reproduces the executable byte for byte but asserts no code, function, section, or object model. It is a build/comparison baseline, not a recovery of the original program structure.
Toolchain (pinned by byte evidence)
The original compiler was re-identified in Phase 6 by comparing candidate compilers against the SDK's own binaries and the executable:
| Role | Component | Evidence |
|---|---|---|
| Compiler | GNU C 2.7.2.SN32.3.7.0002 — the CC1PSX.EXE of PsyQ SDK 4.0 |
the real binary executed and compared; the open gcc-2.7.2-psx build is instruction-identical to it across all 21 probe files |
| Assembler | ASPSX 2.56 (Sony) |
SDK 4.0 banner; maspsx is the open emulator |
| Linker / binary tools | GNU mipsel-none-elf binutils |
Phase 3 local build, recorded in docs/SETUP.md |
| Splitter | splat (+ spimdisasm, rabbitizer) |
Phase 3 |
Working compiler invocation (input must be preprocessed; cc1 rejects comments and directives):
gcc-2.7.2-psx/cc1 -quiet -O2 -G0 # then maspsx, then GNU as
The macro address form is this compiler's default. Phase 5 had selected egcs-2.91.66 (PsyQ 4.5),
which matches simple functions but emits a different framed epilogue; the executable's framed code
identifies PsyQ 4.0. The compiler is open: decompals/old-gcc release 0.17 publishes
gcc-2.7.2-psx, and no proprietary SDK is needed for the matching build. The full derivation is in
docs/PHASE6_TOOLCHAIN_CORRECTION.md.
Build it from your own disc
The repository contains no game data: no disc image, no executable, no disassembly, no assets, no
memory dumps — only source, configuration, tooling, hashes and documentation. You need your own
MODE2/2352 dump of the USA disc (SCUS94640; the local input is 691,530,336 bytes over 294,018
sectors, SHA-1 4abe30077c2b449ea68239083df7932d47ae0b69; a CUE is not required for filesystem
extraction).
# 1. extract the disc deterministically and record a manifest
./tools/sf3_extract extract 'disks/Syphon Filter 3 (USA).bin' extracted
# 2. rebuild the executable from assembly and compare
make clean && make all
cmp -s build/scus_946_40.rebuilt 'extracted/SCUS_946.40;1' && echo byte-identical
sha1sum build/scus_946_40.rebuilt 'extracted/SCUS_946.40;1'
The rebuild must print byte-identical and both files must hash to
e173426c157384ebf1b6caf8c6fea18a85a14af9.
Run the project's synthetic test suite with:
PYTHONDONTWRITEBYTECODE=1 python3 -m unittest discover -s tools/tests -v
The build needs the ignored local tooling recorded in docs/SETUP.md: pinned
splat, a GNU MIPS binutils cross toolchain, the vintage cc1 candidates, and — only if you want to
verify against the original SDK compiler — the proprietary PsyQ SDK plus the wibo Win32 loader.
What is in the repository
| Path | What |
|---|---|
tools/ |
The project's own tooling: sf3_extract (disc/extraction), sf3_probe (structural probe), sf3_fingerprint_probe, sf3_boundaries (function starts), sf3_extents (function ends), sf3_dupes (duplicate bodies), sf3_triage (match worklist), sf3_merge (validated claim merge), sf3_match (the matching harness), and the synthetic test suite in tools/tests/ |
config/ |
The tracked registries and evidence tables: regions.tsv (matches), symbols.tsv (symbols), function_inventory.tsv (graded starts), function_extents.tsv (graded extents), duplicate_bodies.tsv (duplicate census), match_worklist.tsv (ranked queue), near_match_negatives.tsv (open negatives index) |
src/ |
One C file per matched function body, named by address until a name is earned. Every tracked file here is a registered match; unmatched drafts live in ignored staging |
include/ |
gtemac.h — the project's own re-derived COP2 macros and control-register map, with per-macro provenance |
docs/ |
The format/address records, per-phase investigation and verification records, setup and toolchain provenance, the Phase 7 extents/dupes/triage records, the Phase 8 and Phase 9 coordination protocols, and the matching cookbook and matching conventions |
phase-ends/ |
The project's governance record: the phase digest, one PhaseEnd per closed phase, each phase plan, and the active CURRENT_PHASE.md |
Makefile |
The all-assembly rebuild (validate → split → assemble → link → binary) plus the ordered C build, the byte gate, and the extents/extents-verify/dupes/worklist regeneration targets |
AGENTS.md, PROJECT_CONTEXT.md |
The standing rules and the permanent project constitution |
Everything under disks/, extracted/, asm/, build/, ghidra/, dumps/, assets/, and the
local tool directories (tools/splat/, tools/maspsx/, tools/old-gcc/, tools/mipsel-none-elf-binutils/,
tools/psyq/, tools/wibo/) is ignored and never committed.
How it was made
The project runs under a written constitution (PROJECT_CONTEXT.md) and standing
agent rules (AGENTS.md): one task at a time, evidence before assumptions, a byte-level
match or nothing, an explicit ROM firewall, and a hard stop at every phase boundary. Each phase has an
approved plan, a verification gate, a PhaseEnd record, and a digest entry under
phase-ends/.
The static oracle is Ghidra with the locally built PSX loader; the runtime oracle is PCSX-Redux; the
match oracle is a clean rebuild plus cmp and SHA-1 over the whole binary. Compiler conclusions are
reached by differential fingerprinting against the real executable, never from a version label — the
Phase 5 record documents one such conclusion that was found wrong and corrected.
What has been learned about the compiler is written down where it can be reused:
docs/MATCHING_COOKBOOK.md (byte-proven findings, each with its basis
and limit) and docs/MATCHING_CONVENTIONS.md (what counts as a match
and how one is registered).
Coordinated parallel work
Phase 8 onwards is executed by several agent sessions in one worktree under a written contract,
docs/PHASE8_PROTOCOL.md: one coordinator that hands out partitions, merges
what comes back and verifies it, and several workers that match concurrently. The rules that make it
safe are that workers may only create new src/*.c files inside their own partition while the tracked
registries, build/ and every writing git command belong to the coordinator; that a worker's claim is
never trusted, because it is merged into a candidate registry which must pass the whole-binary gate
before it is promoted; and that a tracked src/ file is a claim, so unmatched drafts live in ignored
staging. That model closed 115 bodies in Phase 8 — including a scheduling anomaly that had stood
unresolved for three phases — and it caught its own first bad merge before the tracked registry was
touched. The protocol document also carries the reusable charter and report templates, the failure modes
seen, and the closing checklist.
Standards, and the no-ROM policy
Accuracy. A function is matched only when its compiled instructions are identical to the
original's and the full executable passes cmp and the SHA-1 check. Every match claim must be
reproducible from a clean state, and unmatched content stays behind an explicit fallback.
No game data. Nothing derived from the game may be committed: no disc image, no extracted files,
no disassembly, no assets, no memory dumps, no Ghidra database, and no proprietary SDK files. Review
git status before every commit; git clean -x/-fdx are forbidden because they can destroy ignored
reverse-engineering data.
Third-party components
This project uses, but does not redistribute, other people's work. Third-party components keep their own licenses:
splat,spimdisasm,rabbitizer— the split and the disassemblymaspsx(Mark Street) — Sony ASPSX's assembler quirks, reproducedold-gcc(decompals) — the vintagecc1builds (GPL-licensed builds of GCC)wibo(decompals) — the minimal Win32 loader used to run the SDK compiler- Ghidra and
ghidra_psx_ldr(lab313ru) — the static oracle and its PSX loader - PCSX-Redux — the runtime oracle
- GNU binutils — the MIPS assembler, linker and
objcopy - The Sony PsyQ SDK — proprietary; never distributed, only referenced by checksum. The PsyQ 4.0/4.1/4.4/4.5/4.6
compiler binaries were obtained from
mkst/esa'spsyq-binariesrelease and are used only as a verification reference
The reimplementation of game code that this project will produce carries no license. No license has yet been chosen for the project's own tooling and documentation.
Syphon Filter 3 is © its respective rights holders (Sony Computer Entertainment / 989 Studios). This project is not affiliated with or endorsed by them.