d7047e08c7
P8-T2 plus the first verified cycle-1 merge. tools/sf3_merge validates worker claims before anything tracked changes: a claim is accepted only if its extent exists in the derived extents table and is graded exact with exactly the claimed end, its source is a repo-relative src/func_XXXXXXXX.c that exists, and it overlaps neither the registry nor another worker's claim. Rejections are reported with reasons and nothing is written. The workflow it enables is stronger than the plan's wording: merge to a CANDIDATE registry, gate the candidate, and promote only on MATCH, so the tracked registry never contains an unverified claim. Worker A reported 10 claims (target 8) and correctly refused to edit the shared symbol registry itself, instead requesting 9 gp-marked rows; each was checked arithmetically as gp + d. Candidate gate: c_regions=49, 0 differing bytes, SHA-1 e173426c. Promoted, then make check green: 189 tests, regions=49 disagreements=0, c_regions=49 MATCH. Worker A also reported a significant blocker: two of the remaining duplicate groups are GTE (COP2) bodies -- 0x80018CB0 (3 addresses) and 0x8001084C (2 addresses, the 712-byte shared body) -- plus 0x80103A94 and 0x80103B60. That is four GTE functions, which raises the value of the bounded SDK-shape investigation in P8-T5.