091a9020f7
+2 bodies (worker C claims 19-20) and 3 gp symbol rows (D_80121F90, D_8012196E, D_80121964). Candidate gate MATCH before promotion. NEW EXCLUSION CLASS `restores_unsaved` (worker A, coordinator-verified). A body that restores a callee-saved register it never saves cannot be a whole function: the register it restores was established by an enclosing prologue that the derived extent cut off. These are jal targets INSIDE a real function, so the walk began mid-body — distinct from bad_extent_start, which flags starts that are not function entries at all. Verified disjoint from the matched corpus before acting, as the project requires: 0 of 462 registered regions trip the rule; 11 worklist rows do. excluded_restores_unsaved=11; worklist 1265 -> 1253 rows. 5 new tests; suite 229 -> 237, OK. make check green: regions=462 AGREE, differing_bytes=0 MATCH. Independent corroboration worth recording: the new rule re-derives 0x8010080C, the false extent start worker C reported earlier via a completely different signal (the first instruction reads a register the range never defines). Two independent detections of one defect class. bad_extent_start is False for that row, confirming C's observation that the older rule missed it. Its Makefile --exclude entry is retained only as the provenance record for that defect.