From 5f07d099e6ec161d37e66dd77c61f8ad7437330c Mon Sep 17 00:00:00 2001 From: Drew T <50529377+Druthulu@users.noreply.github.com> Date: Sat, 11 Jul 2026 23:12:53 -0600 Subject: [PATCH] docs(phase-26): finalize Task-6 triage (119 agents) + banking caveat; pause before Task 8 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit - full triage complete: cheap 29 (23 closeness-0 isolation-MATCH) / permuter 29 / fable5 61 (1.71M ins). - attempted to bank the 23 cracked wins into ov077 -> 0/23: the match_one isolation-MATCHes are genuine function matches but carry standalone struct/scalar typedefs + Ghidra-typed sigs that conflict with the real ov077 TU (redefinition of struct Obj / conflicting types) = the §41 def-side wall. Banking needs the Task-8 --reconcile / canon_sig_reconcile pass (not run — paused before Task 8 per Drew). - docs/phase26-triage.md carries the crack curriculum + the caveat; seeds in .run/phase26-seeds/. - src pristine, ov077 byte-identical. --- docs/phase26-triage.md | 173 +++++++++++++++++++----------------- phase-ends/CURRENT_PHASE.md | 6 +- 2 files changed, 95 insertions(+), 84 deletions(-) diff --git a/docs/phase26-triage.md b/docs/phase26-triage.md index 91bbcc676..e4de1d402 100644 --- a/docs/phase26-triage.md +++ b/docs/phase26-triage.md @@ -1,97 +1,108 @@ # Phase 26 — substantial-family crack triage (Task 6) -> Generated by the `.run/wf_triage*.js` Ultracode Workflow (per-family m2c draft + §8 jtbl handling → `match_one` reloc-masked closeness → class + §31/§45 lever + seed to `.run/phase26-seeds/`). The whole-binary byte-gate stays the sole arbiter (G3/P9): closeness/MATCH here are match_one isolation indicators; Task 8 confirms each through `harvest_verify`. +> Generated by the `.run/wf_triage_full.js` Ultracode Workflow (119 agents, 0 errors, 5.3M tok): per-family m2c draft (+§8 jtbl) → `match_one` reloc-masked closeness → class + §31/§45 lever + seed to `.run/phase26-seeds/`. **`match_one` is an ISOLATION indicator** (prepends common.h); the whole-binary byte-gate is the sole arbiter (G3/P9). -**119 draftable substantial uncracked families triaged** (2.38M templatable ins). Classes: +**119 draftable substantial uncracked families triaged** (2.38M templatable ins): -- **cheap: 22 families / 323,751 ins** — small §31/§42/§43 fixes; **20 already isolation-MATCH (closeness 0)** → Task-8 gate+template ×members now. -- **permuter: 23 families / 339,556 ins** — 26–100 regalloc/schedule band (permuter-ILS / cheap-Opus). -- **fable5: 74 families / 1,717,944 ins** — giants / >100-diff / hard §31 classes; the Fable5 crack curriculum (below), seeds in `.run/phase26-seeds/`. +- **cheap: 29 families / 324,878 ins** — small §31/§42/§43 fixes; 23 reached closeness-0 isolation-MATCH. +- **permuter: 29 families / 341,416 ins** — 26–100 regalloc/schedule band. +- **fable5: 61 families / 1,714,957 ins** — giants / >100-diff / hard §31 classes; the Fable5 curriculum (below); seeds in `.run/phase26-seeds/`. -## Already-cracked seeds (cheap, closeness 0 — Task-8 bank+template candidates) +> **⚠ Banking caveat (verified 2026-07-11): the closeness-0 seeds do NOT bank as-is.** Gating all 23 into ov077 → **0/23** — each is a genuine function-level match but carries standalone type defs (`struct Obj`, scalar typedefs) + a Ghidra-typed signature that conflict with ov077's real TU (`redefinition of struct Obj`, `conflicting types for func_…`) = the §41 def-side wall. **Banking them needs the Task-8 reconcile pass** (`family_sweep --reconcile` / `canon_sig_reconcile` v3.2 — strip the ambient types, rewrite to the canonical sig, cast at uses). The isolation-MATCH is the crack; the reconcile is the plumbing. Paused before Task 8 per Drew. -| func | nins | ×members | tw ins | lever / note | +## Closeness-0 cracked seeds (isolation-MATCH — Task-8 reconcile+gate+template ×members) + +| func | nins | ×members | tw ins | note | |--|--:|--:|--:|--| -| func_80160534 | 161 | 134 | 21,574 | MATCH(161 ins) on first try; state-dispatcher calling fn-ptr table D_801891B8[arg0->unk0] | -| func_8013C0F8 | 154 | 134 | 20,636 | MATCH 154/154 (reloc-masked) at -O0; O0 stack-machine pointer-relocation loop with a switc | -| func_80155800 | 145 | 134 | 19,430 | m2c draft matched byte-for-byte after two tweaks: widen the sp+0x10 local buffer to force | -| func_8014F4C0 | 141 | 134 | 18,894 | MATCH (141/141 ins, closeness 0): CSE-held temps + union u16/u8 flags field + char[8] blob | -| func_8015C128 | 129 | 134 | 17,286 | MATCH (129 ins) — m2c draft in project int-cast idiom; only fix was making the two 3-int s | -| func_8015CD20 | 129 | 134 | 17,286 | MATCH(0) — clean m2c draft; only levers were inverting the unk234 branch to ==0, sharing t | -| func_80140608 | 123 | 134 | 16,482 | Full MATCH (123 ins, 0 mismatch): 5-case jump-table dispatch; m2c-drafted then fixed idx=( | -| func_8016C998 | 123 | 134 | 16,482 | Full MATCH (123/123 ins). Fixed via struct-copy grouping (§42a, 0x38-0x54 as two 16-byte n | -| func_80167540 | 117 | 134 | 15,678 | Full MATCH (117 ins) confirmed by match_one; cheap crack via shared-store goto + operand-o | -| func_8014CD80 | 97 | 134 | 12,998 | MATCH (97 ins, masked). m2c-clean structure; needed 2 block-layout reorders (return block | -| func_801506A4 | 95 | 134 | 12,730 | m2c one-shot; MATCH(95 ins) after typing the switch variable `int` instead of unsigned sho | -| func_8014D12C | 93 | 134 | 12,462 | MATCH (93/93 ins, reloc-masked). m2c semantics correct; crack was pure early-return block- | -| func_8015CA28 | 91 | 134 | 12,194 | MATCH (91/91 ins). m2c draft cleaned up; only lever was placing func_80161240 as a cold ta | -| func_8015C7E4 | 88 | 134 | 11,792 | Clean control-flow dispatcher; m2c draft with typed struct + fn-ptr table D_801891B8[unk0] | -| func_80158638 | 87 | 134 | 11,658 | m2c one-shot; restructured the short-circuit else-tail (three &&-chained checks fall throu | -| func_8016A73C | 85 | 134 | 11,390 | MATCH(0) byte-exact: m2c draft + §42a struct-assign for D_800AE620 block-copy + signed `sh | -| func_80156670 | 83 | 134 | 11,122 | Full byte MATCH (83/83 ins). m2c seed refined by: rewriting the D_80126AF6 guard as (char* | -| func_8014CF04 | 82 | 134 | 10,988 | MATCH(0): straight for-loop scan over 96 elem[0x10C] array; only levers were exact array c | -| func_8012E138 | 81 | 134 | 10,854 | Clean m2c draft; full MATCH (81/81) after making the 3 global-snapshot shorts a u16[3] sta | -| func_801824D0 | 181 | 3 | 543 | MATCH(0) in isolation — 3-case compare-chain switch (no jtbl); two levers: hold a0->unkC2 | +| func_80160534 | 161 | 134 | 21,574 | MATCH(161 ins) on first try; state-dispatcher calling fn-ptr table D_801891B8[arg0->unk0] acros | +| func_8013C0F8 | 154 | 134 | 20,636 | MATCH 154/154 (reloc-masked) at -O0; O0 stack-machine pointer-relocation loop with a switch/jtb | +| func_80155800 | 145 | 134 | 19,430 | m2c draft matched byte-for-byte after two tweaks: widen the sp+0x10 local buffer to force frame | +| func_8014F4C0 | 141 | 134 | 18,894 | MATCH (141/141 ins, closeness 0): CSE-held temps + union u16/u8 flags field + char[8] blob for | +| func_8015C128 | 129 | 134 | 17,286 | MATCH (129 ins) — m2c draft in project int-cast idiom; only fix was making the two 3-int stack | +| func_8015CD20 | 129 | 134 | 17,286 | MATCH(0) — clean m2c draft; only levers were inverting the unk234 branch to ==0, sharing the un | +| func_80140608 | 123 | 134 | 16,482 | Full MATCH (123 ins, 0 mismatch): 5-case jump-table dispatch; m2c-drafted then fixed idx=(arg0& | +| func_8016C998 | 123 | 134 | 16,482 | Full MATCH (123/123 ins). Fixed via struct-copy grouping (§42a, 0x38-0x54 as two 16-byte nested | +| func_80167540 | 117 | 134 | 15,678 | Full MATCH (117 ins) confirmed by match_one; cheap crack via shared-store goto + operand-order | +| func_8014CD80 | 97 | 134 | 12,998 | MATCH (97 ins, masked). m2c-clean structure; needed 2 block-layout reorders (return block hoist | +| func_801506A4 | 95 | 134 | 12,730 | m2c one-shot; MATCH(95 ins) after typing the switch variable `int` instead of unsigned short so | +| func_8014D12C | 93 | 134 | 12,462 | MATCH (93/93 ins, reloc-masked). m2c semantics correct; crack was pure early-return block-place | +| func_8015CA28 | 91 | 134 | 12,194 | MATCH (91/91 ins). m2c draft cleaned up; only lever was placing func_80161240 as a cold tail bl | +| func_8015C7E4 | 88 | 134 | 11,792 | Clean control-flow dispatcher; m2c draft with typed struct + fn-ptr table D_801891B8[unk0] MATC | +| func_80158638 | 87 | 134 | 11,658 | m2c one-shot; restructured the short-circuit else-tail (three &&-chained checks fall through to | +| func_8016A73C | 85 | 134 | 11,390 | MATCH(0) byte-exact: m2c draft + §42a struct-assign for D_800AE620 block-copy + signed `short` | +| func_80156670 | 83 | 134 | 11,122 | Full byte MATCH (83/83 ins). m2c seed refined by: rewriting the D_80126AF6 guard as (char*)&D_8 | +| func_8014CF04 | 82 | 134 | 10,988 | MATCH(0): straight for-loop scan over 96 elem[0x10C] array; only levers were exact array count | +| func_8012E138 | 81 | 134 | 10,854 | Clean m2c draft; full MATCH (81/81) after making the 3 global-snapshot shorts a u16[3] stack ar | +| func_801824D0 | 181 | 3 | 543 | MATCH(0) in isolation — 3-case compare-chain switch (no jtbl); two levers: hold a0->unkC2 in on | +| func_8017FAAC | 154 | 1 | 154 | MATCH (154 ins, reloc-masked). Cracked via 6 cheap C levers: unk70 byte/halfword union, CSE-def | +| func_80184D50 | 98 | 1 | 98 | MATCH 98/98 ins. m2c draft + cast-based offsets; two unaligned 8-byte copies modeled via packed | +| func_8017F290 | 86 | 1 | 86 | MATCH (86 ins): m2c switch draft + pointer-local (int *p=&D_801270CC) to force $s0 saved-reg ad | ## Fable5 crack curriculum (top 30 by templatable byte-weight — Task 7 window) -| # | func | nins | jr | tag | tw ins | lever hypothesis | -|--:|--|--:|:-:|--|--:|--| -| 1 | func_80178D40 | 890 | Y | per-location | 119,260 | giant jtbl switch dispatch (§8) + overlay struct typing | -| 2 | func_8015AE2C | 562 | Y | per-location | 75,308 | giant + struct-typing (needs overlay Actor* struct + ty | -| 3 | func_8017A4AC | 536 | Y | per-location | 71,824 | switch-prologue scheduling + branch-vs-ternary structur | -| 4 | func_8015A3C8 | 493 | Y | per-location | 66,062 | giant §45 struct-typed fn-ptr-table dispatch (*(&D_8018 | -| 5 | func_8013F350 | 490 | Y | per-location | 65,660 | giant §45 + struct-field typing §42a + s16/u8 narrow-pa | -| 6 | func_801380E0 | 438 | Y | per-location | 58,692 | regalloc ($sN saved-reg alloc of var_s3/var_s0/var_s4 a | -| 7 | func_80131340 | 424 | Y | per-location | 56,816 | struct-typing + giant; §42a unaligned lwl/lwr struct-co | -| 8 | func_80176734 | 371 | . | per-location | 49,714 | regalloc ($s0-$s6 seven saved-reg pins) + §43 s16-param | -| 9 | func_8015444C | 363 | Y | per-location | 48,642 | regalloc: saved-reg $sN swap ($s2=arg1/$s3=arg2/$s1=arg | -| 10 | func_80159C84 | 337 | Y | per-location | 45,158 | block/case-order layout (schedule) + repeated fn-ptr di | -| 11 | func_8013C414 | 329 | Y | per-location | 44,086 | O0 stack-slot layout + byte-offset pointer-cast access | -| 12 | func_80176218 | 327 | . | per-location | 43,818 | §45-A merged-accumulator (repeated (arg0<<16)>>14 base | -| 13 | func_8013FAF8 | 312 | . | per-location | 41,808 | §43 s16-param sll/sra + §45-A merged-accumulator mask ( | -| 14 | func_8014D820 | 304 | . | per-location | 40,736 | §42a struct-assign (lwl/lwr/swl/swr 4-byte unaligned co | -| 15 | func_80135EB0 | 289 | Y | per-location | 38,726 | regalloc/CSE — original reloads global pointer D_801870 | -| 16 | func_801670E4 | 279 | . | per-location | 37,386 | giant(279): 3 templatable byte-table loops (s8->s16 sll | -| 17 | func_8013B83C | 272 | Y | per-location | 36,448 | O0 struct-field address materialization (§42a) — +0/+4/ | -| 18 | func_8015B950 | 271 | Y | per-location | 36,314 | regalloc: callee-saved promotion — 0xFFF50000 hoisted t | -| 19 | func_80140958 | 260 | . | per-location | 34,840 | §43 s16 narrow-param (sll/sra) + §45-A merged-accumulat | -| 20 | func_8013CB84 | 249 | . | per-location | 33,366 | overlay-table absolute-indexed access + §42a packed-str | -| 21 | func_8013D53C | 240 | . | per-location | 32,160 | regalloc: un-merge accumulator to force 3rd saved-reg $ | -| 22 | func_80175DA8 | 231 | . | per-location | 30,954 | giant §45 + §43 narrow-param sll/sra (arg0<<16>>16, >>1 | -| 23 | func_8012956C | 226 | . | per-location | 30,284 | regalloc: saved-reg-pinned scratchpad ptrs ($s5=0x1F800 | -| 24 | func_8015C32C | 222 | Y | per-location | 29,748 | regalloc saved-register swap (§31): arg0 must land in $ | -| 25 | func_8013FFD8 | 213 | Y | per-location | 28,542 | merged-accumulator return (a2, §45-A) + branch-polarity | -| 26 | func_8016CBC0 | 209 | . | per-location | 28,006 | §42a struct-assign (D_800AE620 ptr struct-copy) + packe | -| 27 | func_8015EA3C | 204 | . | per-location | 27,336 | §31 regalloc saved-reg swap ($s0↔$s1: entity must live | -| 28 | func_8015D738 | 201 | . | per-location | 26,934 | s8 narrow-param sign-extend (sll24/sra24, §43) + fn-poi | -| 29 | func_8013BD74 | 198 | Y | per-location | 26,532 | o0-stack-slot-layout + field-address-materialization (d | -| 30 | func_801412A8 | 198 | . | per-location | 26,532 | saved-reg $s0 spill/frame-elimination (regalloc) — targ | +| # | func | nins | jr | tag | ×m | tw ins | lever hypothesis | +|--:|--|--:|:-:|--|--:|--:|--| +| 1 | func_80178D40 | 890 | Y | per-location | 134 | 119,260 | giant jtbl switch dispatch (§8) + overlay struct t | +| 2 | func_8015AE2C | 562 | Y | per-location | 134 | 75,308 | giant + struct-typing (needs overlay Actor* struct | +| 3 | func_8017A4AC | 536 | Y | per-location | 134 | 71,824 | switch-prologue scheduling + branch-vs-ternary str | +| 4 | func_8015A3C8 | 493 | Y | per-location | 134 | 66,062 | giant §45 struct-typed fn-ptr-table dispatch (*(&D | +| 5 | func_8013F350 | 490 | Y | per-location | 134 | 65,660 | giant §45 + struct-field typing §42a + s16/u8 narr | +| 6 | func_801380E0 | 438 | Y | per-location | 134 | 58,692 | regalloc ($sN saved-reg alloc of var_s3/var_s0/var | +| 7 | func_80131340 | 424 | Y | per-location | 134 | 56,816 | struct-typing + giant; §42a unaligned lwl/lwr stru | +| 8 | func_80176734 | 371 | . | per-location | 134 | 49,714 | regalloc ($s0-$s6 seven saved-reg pins) + §43 s16- | +| 9 | func_8015444C | 363 | Y | per-location | 134 | 48,642 | regalloc: saved-reg $sN swap ($s2=arg1/$s3=arg2/$s | +| 10 | func_80159C84 | 337 | Y | per-location | 134 | 45,158 | block/case-order layout (schedule) + repeated fn-p | +| 11 | func_8013C414 | 329 | Y | per-location | 134 | 44,086 | O0 stack-slot layout + byte-offset pointer-cast ac | +| 12 | func_80176218 | 327 | . | per-location | 134 | 43,818 | §45-A merged-accumulator (repeated (arg0<<16)>>14 | +| 13 | func_8013FAF8 | 312 | . | per-location | 134 | 41,808 | §43 s16-param sll/sra + §45-A merged-accumulator m | +| 14 | func_8014D820 | 304 | . | per-location | 134 | 40,736 | §42a struct-assign (lwl/lwr/swl/swr 4-byte unalign | +| 15 | func_80135EB0 | 289 | Y | per-location | 134 | 38,726 | regalloc/CSE — original reloads global pointer D_8 | +| 16 | func_801670E4 | 279 | . | per-location | 134 | 37,386 | giant(279): 3 templatable byte-table loops (s8->s1 | +| 17 | func_8013B83C | 272 | Y | per-location | 134 | 36,448 | O0 struct-field address materialization (§42a) — + | +| 18 | func_8015B950 | 271 | Y | per-location | 134 | 36,314 | regalloc: callee-saved promotion — 0xFFF50000 hois | +| 19 | func_80140958 | 260 | . | per-location | 134 | 34,840 | §43 s16 narrow-param (sll/sra) + §45-A merged-accu | +| 20 | func_8013CB84 | 249 | . | per-location | 134 | 33,366 | overlay-table absolute-indexed access + §42a packe | +| 21 | func_8013D53C | 240 | . | per-location | 134 | 32,160 | regalloc: un-merge accumulator to force 3rd saved- | +| 22 | func_80175DA8 | 231 | . | per-location | 134 | 30,954 | giant §45 + §43 narrow-param sll/sra (arg0<<16>>16 | +| 23 | func_8012956C | 226 | . | per-location | 134 | 30,284 | regalloc: saved-reg-pinned scratchpad ptrs ($s5=0x | +| 24 | func_8015C32C | 222 | Y | per-location | 134 | 29,748 | regalloc saved-register swap (§31): arg0 must land | +| 25 | func_8013FFD8 | 213 | Y | per-location | 134 | 28,542 | merged-accumulator return (a2, §45-A) + branch-pol | +| 26 | func_8016CBC0 | 209 | . | per-location | 134 | 28,006 | §42a struct-assign (D_800AE620 ptr struct-copy) + | +| 27 | func_8015EA3C | 204 | . | per-location | 134 | 27,336 | §31 regalloc saved-reg swap ($s0↔$s1: entity must | +| 28 | func_8015D738 | 201 | . | per-location | 134 | 26,934 | s8 narrow-param sign-extend (sll24/sra24, §43) + f | +| 29 | func_8013BD74 | 198 | Y | per-location | 134 | 26,532 | o0-stack-slot-layout + field-address-materializati | +| 30 | func_801412A8 | 198 | . | per-location | 134 | 26,532 | saved-reg $s0 spill/frame-elimination (regalloc) — | ## Permuter/cheap-Opus band (26–100 diff) | func | nins | close | tw ins | lever | |--|--:|--:|--:|--| -| func_8015F448 | 188 | 47 | 25,192 | regalloc (arg-reg assignment of CSE'd unkE + load | -| func_80169BBC | 162 | 84 | 21,708 | schedule (reorder) — structural body matches; resi | -| func_801299C8 | 158 | 135 | 21,172 | schedule+frame-elim: suppress spurious 8-byte fram | -| func_8014ADE0 | 139 | 60 | 18,626 | regalloc: register __asm__ pins ($17=p base, $18=t | -| func_801555F4 | 131 | 98 | 17,554 | regalloc: merged var_v0 (the 5-or-7 flag written b | -| func_8012AAAC | 125 | 77 | 16,750 | regalloc $v0/$v1 swap + schedule (store reorder / | -| func_8015D1B8 | 114 | 63 | 15,276 | regalloc ($s0 holds unmasked sum, andi reads $v1) | -| func_801594E8 | 108 | 34 | 14,472 | schedule/delay-slot (dbr) — target packs %hi addr- | -| func_8012CC88 | 105 | 64 | 14,070 | regalloc (pervasive $sN/temp-reg rename cascade v0 | -| func_80169228 | 105 | 35 | 14,070 | regalloc: $v0<->$v1 saved-swap on n=-0x40-(unk1C<< | -| func_80167714 | 104 | 76 | 13,936 | regalloc/copy-prop: target stores const to u1C the | -| func_801463A0 | 101 | 65 | 13,534 | schedule (load-delay-slot hoisting in the sequenti | -| func_80177940 | 101 | 98 | 13,534 | regalloc ($sN alloc-order swap) + cse (defeat (x&m | -| func_801387B8 | 100 | 55 | 13,400 | regalloc: $v0/$v1 value-reg swap on var_v1 + $a0/$ | -| func_801379FC | 97 | 75 | 12,998 | schedule/delay-slot (dbr) — increment-order swap i | +| func_8015F448 | 188 | 47 | 25,192 | regalloc (arg-reg assignment of CSE'd unkE + loa | +| func_80169BBC | 162 | 84 | 21,708 | schedule (reorder) — structural body matches; re | +| func_801299C8 | 158 | 135 | 21,172 | schedule+frame-elim: suppress spurious 8-byte fr | +| func_8014ADE0 | 139 | 60 | 18,626 | regalloc: register __asm__ pins ($17=p base, $18 | +| func_801555F4 | 131 | 98 | 17,554 | regalloc: merged var_v0 (the 5-or-7 flag written | +| func_8012AAAC | 125 | 77 | 16,750 | regalloc $v0/$v1 swap + schedule (store reorder | +| func_8015D1B8 | 114 | 63 | 15,276 | regalloc ($s0 holds unmasked sum, andi reads $v1 | +| func_801594E8 | 108 | 34 | 14,472 | schedule/delay-slot (dbr) — target packs %hi add | +| func_8012CC88 | 105 | 64 | 14,070 | regalloc (pervasive $sN/temp-reg rename cascade | +| func_80169228 | 105 | 35 | 14,070 | regalloc: $v0<->$v1 saved-swap on n=-0x40-(unk1C | +| func_80167714 | 104 | 76 | 13,936 | regalloc/copy-prop: target stores const to u1C t | +| func_801463A0 | 101 | 65 | 13,534 | schedule (load-delay-slot hoisting in the sequen | +| func_80177940 | 101 | 98 | 13,534 | regalloc ($sN alloc-order swap) + cse (defeat (x | +| func_801387B8 | 100 | 55 | 13,400 | regalloc: $v0/$v1 value-reg swap on var_v1 + $a0 | +| func_801379FC | 97 | 75 | 12,998 | schedule/delay-slot (dbr) — increment-order swap | | func_8016B6BC | 94 | 77 | 12,596 | regalloc+schedule | -| func_8014C6F4 | 91 | 56 | 12,194 | regalloc: search-loop walker $a0-vs-$a1 (perm_reg/ | -| func_80173CB4 | 90 | 70 | 12,060 | schedule+regalloc: save-order ($ra before $s0) + c | -| func_8016EC0C | 88 | 74 | 11,792 | regalloc (saved-reg $sN swap: target $s1=const8,$s | -| func_8016AE5C | 85 | 33 | 11,390 | schedule/block-reorder + §5a cross-jump tail-merge | -| func_8012B4B8 | 84 | 82 | 11,256 | regalloc: saved-reg $sN swap + gcc CSE of &stack_l | -| func_8014D4C0 | 84 | 44 | 11,256 | reorder=schedule (block_6 tail arrangement + extra | -| func_8014D2A0 | 80 | 73 | 10,720 | regalloc — saved-reg $sN swap (arg0 vs loop-ptr ge | +| func_8014C6F4 | 91 | 56 | 12,194 | regalloc: search-loop walker $a0-vs-$a1 (perm_re | +| func_80173CB4 | 90 | 70 | 12,060 | schedule+regalloc: save-order ($ra before $s0) + | +| func_8016EC0C | 88 | 74 | 11,792 | regalloc (saved-reg $sN swap: target $s1=const8, | +| func_8016AE5C | 85 | 33 | 11,390 | schedule/block-reorder + §5a cross-jump tail-mer | +| func_8012B4B8 | 84 | 82 | 11,256 | regalloc: saved-reg $sN swap + gcc CSE of &stack | +| func_8014D4C0 | 84 | 44 | 11,256 | reorder=schedule (block_6 tail arrangement + ext | +| func_8014D2A0 | 80 | 73 | 10,720 | regalloc — saved-reg $sN swap (arg0 vs loop-ptr | +| func_8018308C | 166 | 40 | 498 | regalloc ($s1 null-path merge — resists, moves D | +| func_80183834 | 135 | 35 | 405 | schedule (first-block const-load hoist) + regall | +| func_80181F08 | 117 | 87 | 351 | struct/variadic arg-homing at top (§42a struct-a | +| func_80182E7C | 85 | 27 | 255 | schedule/block-layout (§31 reorder): gcc places | +| func_801865EC | 125 | 65 | 250 | regalloc ($a1-vs-$a2 for nx=-unkE cascades whole | +| func_80183FB8 | 101 | 82 | 101 | schedule + regalloc: top-of-fn %hi/%lo global lo | diff --git a/phase-ends/CURRENT_PHASE.md b/phase-ends/CURRENT_PHASE.md index 1fc4d6a03..059602164 100644 --- a/phase-ends/CURRENT_PHASE.md +++ b/phase-ends/CURRENT_PHASE.md @@ -16,7 +16,7 @@ The Phase-25 h_seq reframe: the "unique tail" is really per-location families - [x] **Task 3 — Imm engine (T2a Tier 1) + cross-address delta (T2b)** `[xHigh]` — `family_remap.imm_value`/`imm_map_tier1`/`remap_hseq`: diff-driven Tier-1 value-replace (asm-side ambiguity guard defers ambiguous values; C-literal swap preserving sign/hex-case) + T2b self-rename via the Task-1 `to_addr`. **Tier 2 (probe) DEFERRED** — build-if-needed per Task-5 measurement (byte-gate arbitrates; only ~8 low-weight IMM families). **VERIFIED** (`.run/v3_imm.py`, match_one reloc-masked): **0 DIFF** on every compilable pair — 3 IMM + 2 cross-address MATCH; 4 remap-fails were correctly-deferred asm-ambiguous values; 45 compile-fail(isolation) → whole-TU gate in Task 5. *(committed)* - [x] **Task 4 — `family_sweep --hseq` mode** `[xHigh]` — additive `hseq_sweep()` (h_norm path byte-untouched): consumes `family_hseq.json`, templates matched-exemplar members via `remap_hseq` (cross-address + imm), stages `.run/sweep//func_.c` grouped by (overlay,split), gates via `harvest_verify` (unique per-group verified-out — fixes a latent multi-split overwrite). Member pre-filter = `remap_hseq` refusal (STRUCT/unresolved). **Static pin guard** (`__asm__("$N"` → skip family; §42e — the ×1-only pinned cracks that cc1-crash sibling TUs). `--band`/`--min-members`/`--stage-only`/`--only`. **VERIFIED:** substantial → 29 families, 1507 clean members staged / 267 groups, 1643 correctly skipped as pinned (16/29 families pinned incl. the decision-log-named `func_8016DF5C`/`8013D9B0`/`80133AB0`); h_norm path intact; drafts byte-correct by construction (V3), type-using → whole-TU gate (Task 5). *(committed)* - [x] **Task 5 — Zero-crack validation harvest (substantial band) — GO/NO-GO = GO** `[xHigh]` — ran the real byte-gate on the 29 substantial matched-exemplar families. **Tooling fix discovered + applied (Task-5's "measure then fix"):** `remap_hseq.gather_externs` carries file-scope externs for body-referenced symbols (`extract_unit` only grabbed adjacent ones) — the decl class that depressed the first run. **Result: 532 members banked** (byte-gated); per-family: **3 tracker-miss PURE families (`0x8015d5e8`/`0x8015f118`/`0x801407f4`) bank 100% ×133 = 399 byte-perfect** (the free win), 1 cross-addr family 50%; **9 zero-bank families are type-using (`Work8016`/`Prim`/…) → §41 reconcile follow-on (Task 8)**, 16 families pinned → Task 7. **VERDICT: the h_seq machinery is 100% correct on clean families — GO.** decision-log 2026-07-11 (R31). **R22 clean-fleet 136/136 GREEN**; metrics 30.3→**30.9% distinct** (+375 fns) / 58.2→**58.5% instr**. *(committed)* -- [x] **Task 6 — Step-A triage of the 119 draftable substantial exemplars** `[Ultracode]` — Workflow (`.run/wf_triage*.js`): per-family m2c draft (+§8 jtbl) → `match_one` closeness → class + §31/§45 lever + seed (`.run/phase26-seeds/`). **119 triaged → cheap 22 (323k ins, 20 already isolation-MATCH) / permuter 23 (340k) / fable5 74 (1.72M).** Curriculum + cracked-seed list → `docs/phase26-triage.md` + `.run/phase26_triage.json`. The 20 closeness-0 seeds → Task-8 gate+template ×134. *(committed)* +- [x] **Task 6 — Step-A triage of the 119 draftable substantial exemplars** `[Ultracode]` — Workflow (`.run/wf_triage_full.js`, 119 agents / 0 err / 5.3M tok): per-family m2c draft (+§8 jtbl) → `match_one` closeness → class + §31/§45 lever + seed (`.run/phase26-seeds/`). **119 triaged → cheap 29 (325k ins, 23 closeness-0 isolation-MATCH) / permuter 29 (341k) / fable5 61 (1.71M).** Curriculum → `docs/phase26-triage.md`. **⚠ Banking caveat (verified): the 23 closeness-0 seeds gate 0/23 into ov077** — genuine function matches but carry standalone types + Ghidra sigs conflicting with the TU (§41 def-side wall: `redefinition of struct Obj` / `conflicting types`); banking needs the Task-8 `--reconcile`/`canon_sig_reconcile` pass. *(committed)* - [ ] **Task 7 — Family-core crack waves (the Fable5 window)** `[launch at Max — R27; agents model:fable, parallel-isolated, distill-between]` — biggest byte-weight first (890/562/536/493…); §45-templated prompts (read `.greg`/`.lreg` first; Lever-A merged-accumulator audit; 1-death in-out-asm; /s; gdb-on-cc1, `tools/reference/gcc-2.7.2/`); PIN-FREE (×134); `harvest_verify` arbitrates; distill each crack → cookbook §46+ (R30); cheap-Opus applies banked idioms between waves; cheap/permuter lists run in parallel `[UC]`. ~375k tok/crack guide; documented wall + levers = valid outcome (P9). - [ ] **Task 8 — Mechanical harvest waves** `[Ultracode; continues post-window]` — cracked exemplars → template ×members → gate → bank; h_norm draftable/matched-free retries with the new tracker (5.9 MB bucket); F-jumptable 4 (§8); M-linkwall 1; link-undef second pass. Batched commits; **R22 clean-fleet before each commit batch** (never while agents need `asm/`). - [ ] **Task 9 — Mid-band + residue measurement** `[xHigh]` — <80-ins families (0.68M ins) through the engine; measure h_seq-miss → GO/NO-GO fuzzy pass (build only if ROI; else Phase 27). @@ -24,7 +24,7 @@ The Phase-25 h_seq reframe: the "unique tail" is really per-location families - [ ] **Task 11 — Step-D residue map** `[xHigh]` — true singletons (~0.27M ins) + 5 behemoths → Phase-27 input doc. NO execution. - [ ] **Task 12 — PhaseEnd** `[Max — Tier 1; R27 prompt]` — P7 walk, milestone demo, gate 2, `PhaseEnd_Phase26.md`, worklog → `logs/Phase26.md` (R19), in-file recap (R25), decision-log current (R31). -## ▶ CURRENT TASK: Task 8 (first wave) — gate+template the 20 triage-cracked seeds [Ultracode]; then Task 7 Fable5 window (needs Max+Fable5 toggle — R27). Cracked seeds live in `.run/phase26-seeds/` (protect per R20 → bank to src). +## ▶ CURRENT TASK: **PAUSED before Task 8** (Drew, 2026-07-11). Triage done + all 119 seeds in `.run/phase26-seeds/`. Next: Task 8 = reconcile+gate+template the 23 cracked seeds (needs `--reconcile`/`canon_sig_reconcile`) + the type-family reconcile from Task 5 + mid/tiny harvest; Task 7 = Fable5 window on the 61 cores (needs Max+Fable5 toggle — R27). The 23 isolation-MATCH seeds are the crack; the reconcile is the plumbing. ## Milestone (gate 2 — structural completion, per Drew) @@ -47,7 +47,7 @@ On approval → `/model opus` + `/effort xHigh` (Tasks 0–4; ALL Fable5 via `Ag ## Log -- **2026-07-11 (session 1, Task 6 — triage, in progress):** Ultracode enabled (Drew). Built the triage Workflow (`.run/wf_triage*.js`): per-family m2c draft (+§8 jtbl handling) → `match_one` closeness → classify cheap/permuter/Fable5 + save seed to `.run/phase26-seeds/`. Pilot (4 families) validated: agents handled the 890-giant's jump table, measured real closeness, classified correctly, named levers. **Found `func_8014FFDC` = closeness-2 CHEAP (templates ×268).** Full 119-family run launched (`wf_triage_full.js`, families embedded to dodge args-serialization). Awaiting completion → crack curriculum for Task 7 + cheap list for Task 8. +- **2026-07-11 (session 1, Task 6 — DONE + paused):** Ultracode triage Workflow (119 agents, 0 err, 5.3M tok): m2c draft (+§8 jtbl) → `match_one` closeness → class + lever + seed. **cheap 29 (23 closeness-0) / permuter 29 / fable5 61.** Curriculum → `docs/phase26-triage.md`. Attempted to bank the 23 cracked "wins" into ov077 (Drew: "bank the wins but pause before task8") → **0/23 gate** — the isolation-MATCHes carry standalone types/Ghidra-sigs that hit the §41 def-side wall in the real TU (`redefinition of struct Obj` / `conflicting types`); banking needs the Task-8 `--reconcile` pass. Seeds preserved in `.run/phase26-seeds/` + `.run/ov077_bank/`. **PAUSED before Task 8 per Drew.** src pristine, ov077 green. - **2026-07-11 (session 1, Task 5 — GO/NO-GO = GO):** Ran the real byte-gate on the substantial matched-exemplar band. Discovered + fixed the decl class (`remap_hseq.gather_externs` carries file-scope externs). **532 members banked**, R22 136/136 green, distinct 30.3→30.9% / instr 58.2→58.5%. Per-family: 3 tracker-miss PURE families bank 100% ×133 (399 byte-perfect free win); 9 type-using families → §41 reconcile (Task 8); 16 pinned → Task 7. Machinery byte-proven 100% correct on clean families → GO to scale. decision-log 2026-07-11 (R31). Committed. - **2026-07-11 (session 1, Task 4):** Added `family_sweep --hseq` (additive `hseq_sweep()`, h_norm path byte-untouched): manifest-driven templating via `remap_hseq`, unique per-group verified-out, static `__asm__("$N"` pin guard (skips the ×1-only pinned cracks → Task 7). Dry-run (`--stage-only`): substantial band stages 1507 clean / 267 groups, 1643 correctly skipped as pinned (16/29 families pinned, incl. the decision-log-named ones). Drafts byte-correct by construction; whole-TU gate = Task 5. Committed. - **2026-07-11 (session 1, Task 3):** Built the T2a imm engine (`imm_value`/`imm_map_tier1`/`remap_hseq`) — diff-driven Tier-1 literal swap with an asm-side ambiguity guard — + wired T2b cross-address self-rename. Tier-2 probe deferred (build-if-needed; byte-gate arbitrates). V3 (`.run/v3_imm.py`): 0 DIFF on all compilable pairs (5 MATCH), ambiguity guard + cross-address self-rename confirmed; comprehensive whole-TU gate validation is Task 5. Committed.