docs(phase-32): T4 DONE — the walls' FINAL ledger: 7 pinned rows re-probed in TU context (3 CC1 FAILs were plumbing, re-probed in a sandbox TU), 1 PROVED + 6 CANDIDATE, no verdict changed; pins annotated, backlog rows for all 7 (R62 paths fixed), cookbook §500-I, decision-log

- every wall's best draft re-run with rtu_match in its CURRENT real TU: func_80011380 DIFF 6 (--o0, §474 PROVED),
  func_80020DA4 DIFF 2, func_8017DF28 DIFF 2, func_801834A4 DIFF 6 ×3 variants; leaf match_one re-measured the CC1 rows
  (func_80032A74 1, func_80039DEC 2 permuter / 9 sonnet, func_800391D4 3)
- the three CC1-FAIL rows: func_80032A74 = 7 typedefs the TU provides via 800_shared.h + 4 decl spellings → synced copy
  (.run/P32/t4/drafts/func_80032A74_tuclean.c) DIFF 1 in the real TU (idx 244 lh vs lhu); func_80039DEC = the TU's narrow
  prototype (800_c.c:3496) vs the K&R def → sandbox TU (.run/P32/t4/tu/, no-proto decl) DIFF 2; func_800391D4 = the
  load-bearing `D_80073140[][1]` vs the TU's `[]` → sandbox TU DIFF 3 (TU-compatible spellings regress to 65 @ 76)
- config/wave_exclude.txt: each of the 7 lines carries its S83 re-probe verdict; exclude_audit --assert-fresh 7/7
- backlog: rows for all 7 walls (the path-less func_80011380/func_801834A4 given existing drafts, R62; two rows re-logged
  after a shell-quoting mangle); docs/backlog.md 16 open
- CURRENT_PHASE.md: T4 row DONE, the wall ledger table (row · ins · class · leaf/real-TU closeness · mechanism+citation ·
  attempt record · verdict · best draft; func_800CF3E8 listed as an unpinned candidate), the T4 log entry, 🛑 block → T5
  (R27 Max prompt + the gate-2 procedure)
- cookbook §500-I (the sandbox-TU re-probe method + the verdict table); accelerators (8); decision-log P32 S83 (R31)
This commit is contained in:
Drew T
2026-09-05 12:11:10 -06:00
parent a373a000d1
commit 90acd6902f
13 changed files with 1367 additions and 47 deletions
+10
View File
@@ -280,3 +280,13 @@ unsloth_compiled_cache/
/.run/P32/t3s3/gate/*
!/.run/P32/t3s3/gate/*.json
!/.run/P32/t3s3/gate/*.log
# P32 T4 (S83): the walls' re-probe artefacts — synced/variant drafts only (the sandbox TU copies and rtu compile dirs are regenerable)
!/.run/P32/t4/
/.run/P32/t4/*
!/.run/P32/t4/drafts/
!/.run/P32/t4/v32A74/
/.run/P32/t4/v32A74/*
!/.run/P32/t4/v32A74/*.c
!/.run/P32/t4/v391D4/
/.run/P32/t4/v391D4/*
!/.run/P32/t4/v391D4/*.c
+538
View File
@@ -0,0 +1,538 @@
#include "common.h"
/* =====================================================================================
* S79 (this session) — RESULT UNCHANGED AT closeness 1/422; the residual is now EXPLAINED
* AND THE ORPHAN SEARCH IS CLOSED. ~200 byte-probes, all with the pinned cc1
* (cpp -Iinclude | cc1 -quiet -O2 -G0 -mips1 -mcpu=3000 -mgas -msoft-float -fgnu-linker),
* oracle = `vars=` off the .frame line (NOT the `(use (reg))` count — see INSTRUMENT below).
*
* THE FRAME ARITHMETIC IS EXACT AND LEAVES EXACTLY ONE ORPHAN TO BUY (§165-03):
* target .frame $sp,0x78 regs=10/0 args=16 => vars = 0x40 = 64
* 64 = 0x20 (the ONE declared local, sp10) + 8*3 (the a0/a1/a2 reload spills at
* 0x30/0x38/0x40, all referenced) + 8*1 (ONE never-referenced slot at 0x48).
* sp10 must be 0x1C..0x20 bytes: 0x18 puts the first spill at 0x28, 0x24 puts it at 0x38;
* only [0x1C,0x20] CEIL_ROUNDs frame_offset to the target's 0x30. A declared pad can
* therefore NEVER buy the 8 bytes here — any pad lands before the spills and moves
* `sw $a0,0x30($sp)`. (§162i1/§226/§333 are all inapplicable to this function.)
*
* WHY THE ORPHAN AND THE `lhu` ARE MUTUALLY EXCLUSIVE (the new, general result):
* `extendhisi2` in mips.md is an EXPAND that does force_not_mem at -O2, so EVERY
* `int x = <s16 mem>` is movhi + ashl16 + ashr16 and combine 3-way-merges it to `lh`.
* In a SINGLE-USE merge, newi2pat==0 so elim_i2/elim_i1 DROP both intermediates' death
* notes -> no orphan. An orphan needs the HImode load's reg to carry a SECOND use, which
* forces the i3_subst_into_i2 path (newi2pat != 0 -> elim_i2 == 0) and strands the ashift
* intermediate. `zero_extendhisi2` is a define_INSN that takes memory, so every unsigned
* promotion is one insn and can never orphan (14 u16/u32/s32/QI respellings measured: 0).
* => an orphan in this function REQUIRES an `lh`, and the target's idx-244 load is `lhu`.
*
* THE SITE CENSUS (why no other site can pay for it). The target has 8 `lh`s
* (D_800C5328, D_800C532A, D_800A4646, D_800A46A2 x2, sp10.unk16, D_800A4EFA,
* ch->unk48, D_800A4EF6) and every one is SINGLE-USE, so each is a note-dropping
* 3->1 merge. The only two values in the whole body with a free narrow second use are
* - `vo->unk18` (mask + a QImode `(s8)` use) -> orphan only in the `lh` spelling, and
* - `n` (int uses + the `sh $s2,0x10($s0)` HImode store) -> `s16 n` costs +4 ins and
* TWO orphans (426 ins, near 395); an s16 shadow of n (nh/n pair, both directions)
* is 2 orphans / near 387. Measured, not assumed.
*
* MEASURED-INERT THIS SESSION (do not re-try):
* * 100-variant local-retyping sweep (20 locals x 6 widths): only `n`->s16/s8 (2 orphans,
* near 395/397) and `b`->s8 (1 orphan, near 273) move `vars`; nothing is free.
* * splitting `(s8)u18` into its own s32 temp DOES buy the orphan and the exact 0x78 frame
* (vars=64, near 5) — but combine then re-derives the byte straight from memory as a
* second load `lb $v0,0x18($s1)`; 8 spellings (u32/s32/s16 base, <<1 vs *2, compound,
* `(u8)`/`&0xFFFF` launders) all keep the `lb`. Best of that family: near 5.
* * `__asm__ __volatile__("" ::: "memory")` between the load and the use DOES block the
* 3-way merge and restores `lhu` at zero instruction cost — near 22, frame 0x70, and
* the orphan dies with the merge. Same for §148-C's zero-emission ref slider
* `__asm__ ("" :: "r"(u18))` placed BEFORE the expression (near 22, vars 56).
* Placed AFTER, the slider keeps the orphan but costs a `move` (423 ins, near 184).
* This is the tension in its sharpest form: the extra HImode use that BLOCKS the merge
* (giving `lhu`) is the same use that must SURVIVE the merge to strand the intermediate.
* * `?:`-accumulator respellings of the four selects (ch->unk48, ch->unk24, ch->unk4D,
* vv), s16 temps at every single-use `lh` site, un-hoisting the clear loop (index /
* pointer / 4 forms), and 6 zero-emission ref sliders at other sites: all vars=56.
* * volatile s16 local: vars=64 but near 192 (it is a DECLARED local, wrong stratum).
*
* INSTRUMENT CORRECTION (worth banking): §172's "count standalone `(use (reg))` in the
* .combine dump" UNDER-COUNTS. A minimal §167-10 reproducer
* (`s16 c = A; if (c != 0) A = c - 1;`) emits `vars= 8` with ZERO `(use (reg))` insns —
* the stranded pseudo is simply absent from every post-combine dump while flow's stale
* `reg_n_refs` keeps it an allocno (`; ST_REGS or none` in -dl, §165-03). Also: the
* naive grep counts hard-reg return USEs (`(use (reg/i:SI 2 v0))`) — 54 hits across
* src/800_b_2.c collapse to 11 real pseudo orphans. USE `vars=` AS THE ORACLE.
*
* WHAT IS LEFT (for whoever picks this up): the 8 bytes are almost certainly NOT a combine
* orphan. §172's producer 3 — a caller-save area, `assign_stack_local(SImode,4,0)`,
* allocated inside reload's loop (reload1.c:1445) and therefore AFTER the alter_reg slots
* (reload1.c:658) — lands exactly at 0x48 and MIPS_STACK_ALIGN rounds vars 0x3C -> 0x40,
* reproducing 64 with no instruction anywhere. That is a register-allocation event, not a
* spelling one; the C axis for it (one more call-crossing value competing for the 9
* callee-saved regs this function already uses in full) was not found. Next probe worth
* running: an A/B that adds one genuine call-crossing value and reads `vars` + the
* `.greg` "Spilling reg" lines, rather than any further respelling of the 0x18 read.
* ===================================================================================== */
/* func_80032A74 - NEAR, closeness 1 / 422 ins (frame 0x78 exact, every immediate, every stack
* offset, every branch target and 421 of 422 registers exact). Residual: idx 244 `lh` vs `lhu`.
*
* ===================================================================================
* THE LEVER THAT TOOK THIS FROM 12 -> 1 (new; not in the cookbook as of S77):
* HOIST A GLOBAL ARRAY'S BASE INTO A FILE-SCOPE-TYPED POINTER LOCAL ASSIGNED *BEFORE*
* THE LOOP. That single move reproduces the target's `lui $t0/addiu $t0/addu` shape
* for three different symbols AND puts them all in $t0, with no asm launder and no
* register pin. Mechanism, read out of the gcc-2.7.2 source (tools/reference/gcc-2.7.2):
*
* 1. local-alloc.c:472 - a pseudo is a LOCAL-ALLOC CANDIDATE only if
* `reg_basic_block[i] >= 0 && reg_n_deaths[i] == 1`
* i.e. it lives in ONE basic block and dies ONCE. `&D_800A4C28[idx]` written inline
* makes a 2-ref, one-block pseudo -> local-alloc hands it the LOWEST free hard reg
* (find_free_reg scans regno 0..31; MIPS defines no REG_ALLOC_ORDER) -> $v1.
* 2. Assigning the base to a local BEFORE the `for(;;)` makes it multi-block, so
* local-alloc skips it; global-alloc cannot place it either (all ten callee-saved
* registers are already taken and update_equiv_regs doubled its live length), so
* `reg_renumber < 0`.
* 3. update_equiv_regs (local-alloc.c:1030) has already attached REG_EQUIV (symbol_ref)
* because the pseudo is set once from a constant -> reload1.c DELETES the initialising
* insn (zero cost, so the hoist is FREE) and reload.c substitutes the symbol at every
* use, reloading it into a SPILL register. $t0 is this function's first spill reg
* (it is also what carries `lw $t0,0x30($sp)`, `addiu $t0,$zero,1`, `mflo $t0`) - which
* is exactly why the target shows the symbols and the parm reloads sharing $t0, and why
* `register s32 x __asm__("$8")` can NEVER reproduce it: a hard-reg user variable makes
* reload move every spill to $t1 (measured: +30 rows).
* 4. `addu $s1,$v0,$t0` operand order comes from writing `idx * 0x48 + (s32)vB`, not
* `vB + idx * 0x48`.
* 5. `const` on the two tables is LOAD-BEARING (dropping it costs 14 rows of scheduling
* around the mult/mflo pair) - the original declared them const.
*
* OTHER LEVERS RETAINED FROM THE PREVIOUS 408->12 RUN:
* - `vol` and `m` are ONE variable (both live in $a0 over disjoint ranges).
* - `register s32 base __asm__("$2")` on the 0x18-lerp base: without it the addu/addiu/subu
* chain lands in $v1 (+3 rows).
* - a zero-byte `__asm__ __volatile__("")` after `vo->unk04 = 0x6009F` stops sched1 hoisting
* the D_800A4EF6 `lh` above the three stores (-7 rows), and one after `ch->unk14 = t32`.
* - use the PARAMETERS directly (no `e = arg0` copies) so the reload spill slots stay
* 0x30/0x38/0x40; the 8-byte clear loop is a POINTER loop with `i = 7;` FIRST (S211).
*
* ===================================================================================
* THE ONE REMAINING ROW, and why it is a genuine wall for this spelling
* idx 244 mine `lh $v0,0x18($s1)` target `lhu $v0,0x18($s1)`
*
* The target frame is 0x78: sp10 at 0x10-0x2F, the three parm spills at 0x30/0x38/0x40, and a
* NEVER-REFERENCED 8-byte slot at 0x48. The only producer of that slot reachable from C here
* is a S172 combine USE-orphan, and the only site in this function that orphans is
* `s16 u18 = vo->unk18` with BOTH an int (sign) promotion and a QImode use - which forces the
* load to be `extendhisi2_internal` = `lh`. Spelling the int use as `(u16)u18 & 0xFF00` gives
* the target's `lhu` and is byte-identical in all 422 instructions - but the orphan vanishes,
* the frame drops to 0x70 and 22 stack-offset rows break (that draft is kept at
* .run/S77w/opus/scratch_func_80032A74/v2.c). Measured dead ends for a substitute orphan
* (each checked by counting standalone `(insn N P X (use (reg ...)))` in the cc1 `-dc` dump):
* - every u16/s16/s8/QImode respelling of the vo->unk18 site (14 forms) -> 0 orphans;
* - `s16 n` (D_800C5328/D_800C532A) -> 2 orphans but a `lhu`+`lh` DOUBLE LOAD, +4 ins;
* - an s16 temp at that site whose only uses are promotions -> folds, 0 orphans;
* - an s16 local for the func_8003F144 return -> 0 orphans.
* Every other `lh` in the target (D_800A4646, D_800A46A2 x2, sp10.unk16, D_800A4EFA,
* ch->unk48, D_800A4EF6) has a SINGLE consumer, and S172's rule is that a single-use load
* 3-way-merges and orphans nothing. A declared 8-byte dead local cannot substitute: expand-time
* locals precede the reload spills and push $a0 from 0x30 to 0x38.
*/
/* func_80032A74 - NEAR, closeness 12 / 422 ins (length exact, frame exact).
*
* LEVERS PROVEN THIS SESSION (each byte-measured with tools/match_one.py; start 408 -> 12):
* 1. FRAME +8 (vars 56 -> 64) = ONE combine USE-orphan (cookbook S172 producer 2). The target's
* frame is 0x10..0x2F C24 local | 0x30/0x38/0x40 parm spills | 0x48 NEVER-REFERENCED. A
* declared dead local CANNOT do it (expand-time locals precede reload spills - measured: it
* pushes a0 from 0x30 to 0x38), and neither can `asm("":: "m"(pad))` (mark_addressable puts it
* in the locals region too). What does: an `s16` LOCAL read from memory and promoted to int
* TWICE, sited after a CODE_LABEL -> expand emits movhi + ashift/ashiftrt, combine merges them
* into one `lh` and orphans the HImode pseudo as `(insn (use (reg:SI N)))`, which alter_reg
* still gives an 8-byte slot. Instrument: count standalone `(use (reg` insns in the .combine
* dump (tools/cc1_dumps.sh). ZERO-extending (u16) temps merge cleanly and orphan NOTHING -
* the ashift/ashiftrt PAIR is the whole mechanism. Single-use s16 temps also orphan nothing.
* COST: the only site available here is `vo->unk18`, where the target loads `lhu` - so idx 244
* is `lh` vs `lhu`, the one structural row left. A 2-use `lh` site would be free; the only
* other one is `n` (D_800C5328) and typing it s16 costs +4 ins.
* 2. `vol` AND `m` ARE ONE VARIABLE. The target holds both in $a0 across disjoint ranges; two
* separate C variables give two allocnos ($v1 and $a1). Merging them is what puts the whole
* volume chain in $a0.
* 3. THE S153 LAUNDER'S REAL COST IS AN ALLOCNO, AND THE FIX IS A PIN ON A DEAD TEMP. Removing
* the launder (plain `D_8007319E[pan]`) fixes m/$a0, the `li 0x100` delay-slot schedule and the
* D_800A4EF6 hoist all at once - but folds the address back to the 3-insn $at macro form (-2
* ins). Keeping the launder, the symbol pseudo has priority log2(refs)*refs/live_length ~ 0.67
* and OUTRANKS the long-lived `vol` (~0.19), so it steals $a0 and pushes the whole chain to $a1
* (+17 rows). `register s32 bp __asm__("$10")` parks it on a register nothing else wants:
* $a0 goes back to vol/m and reload keeps $t0. Do NOT pin it to $8: reload then picks $t1 for
* every parm reload (measured +14 rows, net worse). $9 costs 2 rows (the mflo temp at idx 272
* moves $t1 -> $t2); $10 costs none.
* 4. A zero-byte `__asm__ __volatile__("")` after `vo->unk04 = 0x6009F;` stops sched1 hoisting the
* D_800A4EF6 `lh` above the three stores (-7 rows).
* 5. S219: `vol *= 0x70; vol >>= 7;` (compound) vs `vol = (vol*0x70)>>7;` decides whether the
* `<<4` intermediate lands in $a0 or $v0 (-2 rows).
*
* REMAINING RESIDUAL (12), all REGISTER-NAMING, nothing structural:
* - 3 rows: the D_800A4C28 base is $v1, target $t0.
* - 8 rows: the laundered table base is $t1/$t2, target $t0 - and $t0 is unreachable because the
* same $t0 is reload's spill register for the three parm reloads; a hard-reg var there evicts
* reload. In the target BOTH uses coexist, which means those symbol pseudos are NOT allocnos -
* they are reload rematerialisations of a reg_equiv_constant. Every C spelling tried
* (array[i], &array[i], scalar `extern u16 D;` + `&D + off`, S195-H's struct-cast force_reg,
* const u16* local, S239 integer-space, one-table-two-index) folds to the $at macro form; only
* the launder produces the 4-insn shape, and the launder always creates an allocno.
* - 1 row: idx 244 `lh` vs `lhu` (see lever 1).
*/
/* 0x0C */
/* 0x0C */
/* 0x20 */
/* 0x14 */
/* ---- views this function needs (new names, no TU collision) ---- */
/* the caller's 0x54 request slot (Slot54, seen past its declared tail) */
typedef struct {
/* 0x00 */ u16 unk00;
/* 0x02 */ u16 unk02;
/* 0x04 */ u8 pad04[6];
/* 0x0A */ u8 unk0A;
/* 0x0B */ u8 pad0B[1];
/* 0x0C */ u16 unk0C;
/* 0x0E */ u8 unk0E[8];
} Req32A74;
/* the 0x14 record walked by this loop (Rec14, byte-resolved) */
typedef struct {
/* 0x00 */ u16 unk00;
/* 0x02 */ u16 unk02;
/* 0x04 */ u16 unk04;
/* 0x06 */ u8 unk06;
/* 0x07 */ u8 unk07;
/* 0x08 */ u8 unk08;
/* 0x09 */ u8 unk09;
/* 0x0A */ u8 unk0A;
/* 0x0B */ u8 unk0B;
/* 0x0C */ u8 pad0C[4];
/* 0x10 */ s32 unk10;
} Rec32A74; /* 0x14 */
/* the 0x54 mixer channel at D_800A4988 (cf. Chan336A8) */
typedef struct {
/* 0x00 */ s32 unk00;
/* 0x04 */ s32 unk04;
/* 0x08 */ u16 unk08;
/* 0x0A */ u16 unk0A;
/* 0x0C */ u16 unk0C;
/* 0x0E */ u16 unk0E;
/* 0x10 */ s16 unk10;
/* 0x12 */ s16 unk12;
/* 0x14 */ s32 unk14;
/* 0x18 */ u8 pad18[0xC];
/* 0x24 */ s32 unk24;
/* 0x28 */ u8 pad28[0xC];
/* 0x34 */ u8 unk34;
/* 0x35 */ u8 unk35;
/* 0x36 */ u8 unk36;
/* 0x37 */ u8 pad37[9];
/* 0x40 */ s32 unk40;
/* 0x44 */ s32 unk44;
/* 0x48 */ s16 unk48;
/* 0x4A */ s16 unk4A;
/* 0x4C */ u8 unk4C;
/* 0x4D */ u8 unk4D;
/* 0x4E */ u8 unk4E;
/* 0x4F */ u8 unk4F;
/* 0x50 */ u8 pad50[2];
/* 0x52 */ u8 unk52;
/* 0x53 */ u8 unk53;
} Chan32A74; /* 0x54 */
/* the 0x48 voice at D_800A4C28 (Slot, byte-resolved) */
typedef struct {
/* 0x00 */ s32 unk00;
/* 0x04 */ s32 unk04;
/* 0x08 */ u16 unk08;
/* 0x0A */ u16 unk0A;
/* 0x0C */ u16 unk0C;
/* 0x0E */ u16 unk0E;
/* 0x10 */ u8 pad10[4];
/* 0x14 */ u16 unk14;
/* 0x16 */ u8 pad16[2];
/* 0x18 */ u16 unk18;
/* 0x1A */ u8 pad1A[2];
/* 0x1C */ s32 unk1C;
/* 0x20 */ u8 pad20[0x1A];
/* 0x3A */ u16 unk3A;
/* 0x3C */ u16 unk3C;
/* 0x3E */ u8 pad3E[2];
/* 0x40 */ s32 unk40;
/* 0x44 */ u8 unk44;
/* 0x45 */ u8 unk45;
/* 0x46 */ u8 pad46[2];
} Voice32A74; /* 0x48 */
extern s16 D_800C5328[];
extern s16 D_800C532A[];
extern s16 D_800A4646[];
extern A12 D_80064D44[];
extern B12 *D_8006A970[];
extern Slot D_800A4C28[];
extern u8 D_800A4988[];
extern s32 D_80073140[];
extern s16 D_800A46A2;
extern s16 D_800A4EF6;
extern s16 D_800A4EFA;
extern u8 D_800A4F19;
extern u8 D_800A4F1E;
extern u16 D_8006AA30[];
extern u16 D_8006AB30[];
extern u16 D_8006AB32[];
extern const u16 D_8007319E[];
extern const u16 D_800731A0[];
extern u16 D_8007321E;
extern u8 D_8006AED8[];
extern s16 func_8003F144(s32, s32, s32, C24 *);
extern s32 func_8003F380(s32, s32);
extern s32 func_80030CA4(u16);
extern void func_8002EFF8(s32, s32);
extern void func_8002F064(s32, s32);
extern void func_800316F8(s32);
extern void func_80033324(s32, s32);
void func_80032A74(Slot54 *arg0, s32 arg1, Rec14 *arg2, s32 flags) {
#define REQ ((Req32A74 *)arg0)
#define REC ((Rec32A74 *)arg2)
C24 sp10;
Chan32A74 *ch;
Voice32A74 *vo;
A12 *dd;
B12 *q;
u8 *cp;
const u16 *tA;
const u16 *tB;
u8 *vB;
s32 i2;
u16 v;
u32 vv;
s32 idx;
s32 w;
s32 n;
s32 flag;
s32 h;
s32 i;
s32 b;
s32 sub;
u8 pan;
u32 vol;
u32 mp;
u32 qq;
s32 tb;
u32 d;
register s32 base __asm__("$2");
u16 t16;
s32 t8;
s32 t32;
tA = D_8007319E;
tB = D_800731A0;
vB = (u8 *)D_800A4C28;
v = REQ->unk02;
i = 7;
cp = (u8 *)arg0 + 7;
do {
cp[0xE] = 0;
i--;
cp--;
} while (i >= 0);
REQ->unk0C = 0;
for (;;) {
b = REC->unk08;
flag = 0;
if ((b & 0x80) == 0) {
dd = &D_80064D44[b];
sub = REC->unk09;
if (dd->unk06 != 0) {
flag = (u32)sub < (u32)dd->unk07;
}
n = D_800C5328[b * 2];
if (n < 0) {
if (flag == 0) {
break;
}
n = D_800C532A[b * 2];
if (n < 0) {
break;
}
if (sub >= D_800A4646[n * 12]) {
break;
}
}
} else {
n = 4;
}
if ((flags & 0x1000) && (flags & 0x7F) < 0x30U) {
v >>= 1;
flags = (flags & 0xFF80) | (0x2F - ((0x2F - (flags & 0x7F)) >> 1));
}
idx = func_80030CA4(v);
if (idx != 0) {
idx--;
vo = (Voice32A74 *)(idx * 0x48 + (s32)vB);
if ((b & 0x80) == 0) {
q = &D_8006A970[n][REC->unk09];
vo->unk1C = q->unk00;
vo->unk18 = q->unk04;
vo->unk3A = q->unk06;
vo->unk3C = q->unk08;
} else {
if (func_8003F144(D_800A46A2, b & 0x7F, REC->unk09, &sp10) != 0) {
goto next;
}
h = func_8003F380(D_800A46A2, sp10.unk16);
if (h < 0) {
goto next;
}
tb = sp10.unk04;
vo->unk1C = h;
vo->unk18 = tb << 8;
vo->unk3A = sp10.unk10;
vo->unk3C = sp10.unk12;
}
w = idx + 0x10;
vo->unk00 = D_80073140[w];
ch = (Chan32A74 *)(D_800A4988 + idx * 0x54);
ch->unk4C = 0;
ch->unk4A = 0x7FFF;
if (REQ->unk00 & 0x80) {
ch->unk4D = 0;
} else {
ch->unk4D = 1;
}
t16 = REC->unk02;
ch->unk04 = 0;
ch->unk08 = v;
ch->unk0A = w;
ch->unk00 = t16;
t8 = REC->unk09;
ch->unk0E = b;
ch->unk36 = flag;
ch->unk10 = n;
ch->unk12 = 0;
ch->unk0C = t8;
t32 = REC->unk10;
ch->unk4F = 0;
ch->unk4E = 0x85;
ch->unk14 = t32;
__asm__ __volatile__("");
vol = REC->unk06;
if (D_800A4F1E != 0) {
vol *= 0x70;
vol >>= 7;
}
if (flags & 0x1000) {
ch->unk48 = flags & 0x7F;
} else {
ch->unk48 = 0x7F;
}
ch->unk34 = vol & 0x7F;
pan = REC->unk07;
ch->unk35 = pan;
if (flags & 0x8000) {
ch->unk24 = REC->unk04 - 0x80;
} else {
ch->unk24 = REC->unk04;
}
ch->unk40 = (s32)func_80033324;
ch->unk44 = arg1;
if ((flags & 0x2000) && pan != 0) {
if ((flags & 0x3000) == 0x3000) {
ch->unk53 = D_8006AED8[(u32)(flags & 0xF00) >> 8];
} else {
ch->unk53 = flags & 0x7F;
}
} else {
ch->unk53 = 0;
}
if (REC->unk02 == 0) {
func_800316F8(ch);
}
{
s16 u18 = vo->unk18;
base = (u18 & 0xFF00) + (s8)u18 * 2;
}
base -= 0x3C00;
d = ch->unk24;
d -= base;
if (d >= 0x5300) {
vo->unk14 = 0x3FFF;
} else {
qq = D_8006AB30[d >> 8];
qq = qq * (0x100 - (d & 0xFF));
vo->unk14 = (qq + D_8006AB32[d >> 8] * (d & 0xFF)) >> 8;
}
vol = D_8006AA30[ch->unk34];
mp = vol * D_800A4EFA;
vol = mp >> 7;
mp = vol * ch->unk48;
vol = mp >> 7;
if (pan != 0) {
if (ch->unk53 != 0) {
pan += ch->unk53;
if (pan >= 0x42) {
pan -= 0x40;
if (pan >= 0x80) {
pan = 0x7F;
}
} else {
pan = 1;
}
}
if (D_800A4F19 != 0) {
vv = (vol * tA[pan]) >> 14;
vo->unk0A = vv;
vv = (vol * tB[0x7F - pan]) >> 14;
vo->unk08 = vv;
} else {
vv = (vol * D_8007321E) >> 14;
vo->unk0A = vv;
vo->unk08 = vv;
}
} else {
vv = vol;
vo->unk08 = vv;
vo->unk0A = vv;
}
ch->unk52 = pan;
vo->unk0C = 0;
vo->unk0E = 0;
vo->unk04 = 0x6009F;
__asm__ __volatile__("");
if (D_800A4EF6 > REC->unk0A) {
func_8002F064(1, vo->unk00);
} else {
func_8002F064(0, vo->unk00);
}
t16 = ch->unk0A;
vo->unk45 = 0;
vo->unk44 = 1;
vo->unk40 = t16;
if (REC->unk02 == 0) {
func_8002EFF8(1, vo->unk00);
}
REQ->unk0C++;
REQ->unk0E[idx] = 1;
}
next:
if (REC->unk0B == 0) {
break;
}
arg2++;
v = REC->unk00;
}
if (REQ->unk0C == 0) {
REQ->unk00 = 0;
} else {
REQ->unk0A = 4;
}
}
#undef REQ
#undef REC
+538
View File
@@ -0,0 +1,538 @@
#include "common.h"
/* =====================================================================================
* S79 (this session) — RESULT UNCHANGED AT closeness 1/422; the residual is now EXPLAINED
* AND THE ORPHAN SEARCH IS CLOSED. ~200 byte-probes, all with the pinned cc1
* (cpp -Iinclude | cc1 -quiet -O2 -G0 -mips1 -mcpu=3000 -mgas -msoft-float -fgnu-linker),
* oracle = `vars=` off the .frame line (NOT the `(use (reg))` count — see INSTRUMENT below).
*
* THE FRAME ARITHMETIC IS EXACT AND LEAVES EXACTLY ONE ORPHAN TO BUY (§165-03):
* target .frame $sp,0x78 regs=10/0 args=16 => vars = 0x40 = 64
* 64 = 0x20 (the ONE declared local, sp10) + 8*3 (the a0/a1/a2 reload spills at
* 0x30/0x38/0x40, all referenced) + 8*1 (ONE never-referenced slot at 0x48).
* sp10 must be 0x1C..0x20 bytes: 0x18 puts the first spill at 0x28, 0x24 puts it at 0x38;
* only [0x1C,0x20] CEIL_ROUNDs frame_offset to the target's 0x30. A declared pad can
* therefore NEVER buy the 8 bytes here — any pad lands before the spills and moves
* `sw $a0,0x30($sp)`. (§162i1/§226/§333 are all inapplicable to this function.)
*
* WHY THE ORPHAN AND THE `lhu` ARE MUTUALLY EXCLUSIVE (the new, general result):
* `extendhisi2` in mips.md is an EXPAND that does force_not_mem at -O2, so EVERY
* `int x = <s16 mem>` is movhi + ashl16 + ashr16 and combine 3-way-merges it to `lh`.
* In a SINGLE-USE merge, newi2pat==0 so elim_i2/elim_i1 DROP both intermediates' death
* notes -> no orphan. An orphan needs the HImode load's reg to carry a SECOND use, which
* forces the i3_subst_into_i2 path (newi2pat != 0 -> elim_i2 == 0) and strands the ashift
* intermediate. `zero_extendhisi2` is a define_INSN that takes memory, so every unsigned
* promotion is one insn and can never orphan (14 u16/u32/s32/QI respellings measured: 0).
* => an orphan in this function REQUIRES an `lh`, and the target's idx-244 load is `lhu`.
*
* THE SITE CENSUS (why no other site can pay for it). The target has 8 `lh`s
* (D_800C5328, D_800C532A, D_800A4646, D_800A46A2 x2, sp10.unk16, D_800A4EFA,
* ch->unk48, D_800A4EF6) and every one is SINGLE-USE, so each is a note-dropping
* 3->1 merge. The only two values in the whole body with a free narrow second use are
* - `vo->unk18` (mask + a QImode `(s8)` use) -> orphan only in the `lh` spelling, and
* - `n` (int uses + the `sh $s2,0x10($s0)` HImode store) -> `s16 n` costs +4 ins and
* TWO orphans (426 ins, near 395); an s16 shadow of n (nh/n pair, both directions)
* is 2 orphans / near 387. Measured, not assumed.
*
* MEASURED-INERT THIS SESSION (do not re-try):
* * 100-variant local-retyping sweep (20 locals x 6 widths): only `n`->s16/s8 (2 orphans,
* near 395/397) and `b`->s8 (1 orphan, near 273) move `vars`; nothing is free.
* * splitting `(s8)u18` into its own s32 temp DOES buy the orphan and the exact 0x78 frame
* (vars=64, near 5) — but combine then re-derives the byte straight from memory as a
* second load `lb $v0,0x18($s1)`; 8 spellings (u32/s32/s16 base, <<1 vs *2, compound,
* `(u8)`/`&0xFFFF` launders) all keep the `lb`. Best of that family: near 5.
* * `__asm__ __volatile__("" ::: "memory")` between the load and the use DOES block the
* 3-way merge and restores `lhu` at zero instruction cost — near 22, frame 0x70, and
* the orphan dies with the merge. Same for §148-C's zero-emission ref slider
* `__asm__ ("" :: "r"(u18))` placed BEFORE the expression (near 22, vars 56).
* Placed AFTER, the slider keeps the orphan but costs a `move` (423 ins, near 184).
* This is the tension in its sharpest form: the extra HImode use that BLOCKS the merge
* (giving `lhu`) is the same use that must SURVIVE the merge to strand the intermediate.
* * `?:`-accumulator respellings of the four selects (ch->unk48, ch->unk24, ch->unk4D,
* vv), s16 temps at every single-use `lh` site, un-hoisting the clear loop (index /
* pointer / 4 forms), and 6 zero-emission ref sliders at other sites: all vars=56.
* * volatile s16 local: vars=64 but near 192 (it is a DECLARED local, wrong stratum).
*
* INSTRUMENT CORRECTION (worth banking): §172's "count standalone `(use (reg))` in the
* .combine dump" UNDER-COUNTS. A minimal §167-10 reproducer
* (`s16 c = A; if (c != 0) A = c - 1;`) emits `vars= 8` with ZERO `(use (reg))` insns —
* the stranded pseudo is simply absent from every post-combine dump while flow's stale
* `reg_n_refs` keeps it an allocno (`; ST_REGS or none` in -dl, §165-03). Also: the
* naive grep counts hard-reg return USEs (`(use (reg/i:SI 2 v0))`) — 54 hits across
* src/800_b_2.c collapse to 11 real pseudo orphans. USE `vars=` AS THE ORACLE.
*
* WHAT IS LEFT (for whoever picks this up): the 8 bytes are almost certainly NOT a combine
* orphan. §172's producer 3 — a caller-save area, `assign_stack_local(SImode,4,0)`,
* allocated inside reload's loop (reload1.c:1445) and therefore AFTER the alter_reg slots
* (reload1.c:658) — lands exactly at 0x48 and MIPS_STACK_ALIGN rounds vars 0x3C -> 0x40,
* reproducing 64 with no instruction anywhere. That is a register-allocation event, not a
* spelling one; the C axis for it (one more call-crossing value competing for the 9
* callee-saved regs this function already uses in full) was not found. Next probe worth
* running: an A/B that adds one genuine call-crossing value and reads `vars` + the
* `.greg` "Spilling reg" lines, rather than any further respelling of the 0x18 read.
* ===================================================================================== */
/* func_80032A74 - NEAR, closeness 1 / 422 ins (frame 0x78 exact, every immediate, every stack
* offset, every branch target and 421 of 422 registers exact). Residual: idx 244 `lh` vs `lhu`.
*
* ===================================================================================
* THE LEVER THAT TOOK THIS FROM 12 -> 1 (new; not in the cookbook as of S77):
* HOIST A GLOBAL ARRAY'S BASE INTO A FILE-SCOPE-TYPED POINTER LOCAL ASSIGNED *BEFORE*
* THE LOOP. That single move reproduces the target's `lui $t0/addiu $t0/addu` shape
* for three different symbols AND puts them all in $t0, with no asm launder and no
* register pin. Mechanism, read out of the gcc-2.7.2 source (tools/reference/gcc-2.7.2):
*
* 1. local-alloc.c:472 - a pseudo is a LOCAL-ALLOC CANDIDATE only if
* `reg_basic_block[i] >= 0 && reg_n_deaths[i] == 1`
* i.e. it lives in ONE basic block and dies ONCE. `&D_800A4C28[idx]` written inline
* makes a 2-ref, one-block pseudo -> local-alloc hands it the LOWEST free hard reg
* (find_free_reg scans regno 0..31; MIPS defines no REG_ALLOC_ORDER) -> $v1.
* 2. Assigning the base to a local BEFORE the `for(;;)` makes it multi-block, so
* local-alloc skips it; global-alloc cannot place it either (all ten callee-saved
* registers are already taken and update_equiv_regs doubled its live length), so
* `reg_renumber < 0`.
* 3. update_equiv_regs (local-alloc.c:1030) has already attached REG_EQUIV (symbol_ref)
* because the pseudo is set once from a constant -> reload1.c DELETES the initialising
* insn (zero cost, so the hoist is FREE) and reload.c substitutes the symbol at every
* use, reloading it into a SPILL register. $t0 is this function's first spill reg
* (it is also what carries `lw $t0,0x30($sp)`, `addiu $t0,$zero,1`, `mflo $t0`) - which
* is exactly why the target shows the symbols and the parm reloads sharing $t0, and why
* `register s32 x __asm__("$8")` can NEVER reproduce it: a hard-reg user variable makes
* reload move every spill to $t1 (measured: +30 rows).
* 4. `addu $s1,$v0,$t0` operand order comes from writing `idx * 0x48 + (s32)vB`, not
* `vB + idx * 0x48`.
* 5. `const` on the two tables is LOAD-BEARING (dropping it costs 14 rows of scheduling
* around the mult/mflo pair) - the original declared them const.
*
* OTHER LEVERS RETAINED FROM THE PREVIOUS 408->12 RUN:
* - `vol` and `m` are ONE variable (both live in $a0 over disjoint ranges).
* - `register s32 base __asm__("$2")` on the 0x18-lerp base: without it the addu/addiu/subu
* chain lands in $v1 (+3 rows).
* - a zero-byte `__asm__ __volatile__("")` after `vo->unk04 = 0x6009F` stops sched1 hoisting
* the D_800A4EF6 `lh` above the three stores (-7 rows), and one after `ch->unk14 = t32`.
* - use the PARAMETERS directly (no `e = arg0` copies) so the reload spill slots stay
* 0x30/0x38/0x40; the 8-byte clear loop is a POINTER loop with `i = 7;` FIRST (S211).
*
* ===================================================================================
* THE ONE REMAINING ROW, and why it is a genuine wall for this spelling
* idx 244 mine `lh $v0,0x18($s1)` target `lhu $v0,0x18($s1)`
*
* The target frame is 0x78: sp10 at 0x10-0x2F, the three parm spills at 0x30/0x38/0x40, and a
* NEVER-REFERENCED 8-byte slot at 0x48. The only producer of that slot reachable from C here
* is a S172 combine USE-orphan, and the only site in this function that orphans is
* `s16 u18 = vo->unk18` with BOTH an int (sign) promotion and a QImode use - which forces the
* load to be `extendhisi2_internal` = `lh`. Spelling the int use as `(u16)u18 & 0xFF00` gives
* the target's `lhu` and is byte-identical in all 422 instructions - but the orphan vanishes,
* the frame drops to 0x70 and 22 stack-offset rows break (that draft is kept at
* .run/S77w/opus/scratch_func_80032A74/v2.c). Measured dead ends for a substitute orphan
* (each checked by counting standalone `(insn N P X (use (reg ...)))` in the cc1 `-dc` dump):
* - every u16/s16/s8/QImode respelling of the vo->unk18 site (14 forms) -> 0 orphans;
* - `s16 n` (D_800C5328/D_800C532A) -> 2 orphans but a `lhu`+`lh` DOUBLE LOAD, +4 ins;
* - an s16 temp at that site whose only uses are promotions -> folds, 0 orphans;
* - an s16 local for the func_8003F144 return -> 0 orphans.
* Every other `lh` in the target (D_800A4646, D_800A46A2 x2, sp10.unk16, D_800A4EFA,
* ch->unk48, D_800A4EF6) has a SINGLE consumer, and S172's rule is that a single-use load
* 3-way-merges and orphans nothing. A declared 8-byte dead local cannot substitute: expand-time
* locals precede the reload spills and push $a0 from 0x30 to 0x38.
*/
/* func_80032A74 - NEAR, closeness 12 / 422 ins (length exact, frame exact).
*
* LEVERS PROVEN THIS SESSION (each byte-measured with tools/match_one.py; start 408 -> 12):
* 1. FRAME +8 (vars 56 -> 64) = ONE combine USE-orphan (cookbook S172 producer 2). The target's
* frame is 0x10..0x2F C24 local | 0x30/0x38/0x40 parm spills | 0x48 NEVER-REFERENCED. A
* declared dead local CANNOT do it (expand-time locals precede reload spills - measured: it
* pushes a0 from 0x30 to 0x38), and neither can `asm("":: "m"(pad))` (mark_addressable puts it
* in the locals region too). What does: an `s16` LOCAL read from memory and promoted to int
* TWICE, sited after a CODE_LABEL -> expand emits movhi + ashift/ashiftrt, combine merges them
* into one `lh` and orphans the HImode pseudo as `(insn (use (reg:SI N)))`, which alter_reg
* still gives an 8-byte slot. Instrument: count standalone `(use (reg` insns in the .combine
* dump (tools/cc1_dumps.sh). ZERO-extending (u16) temps merge cleanly and orphan NOTHING -
* the ashift/ashiftrt PAIR is the whole mechanism. Single-use s16 temps also orphan nothing.
* COST: the only site available here is `vo->unk18`, where the target loads `lhu` - so idx 244
* is `lh` vs `lhu`, the one structural row left. A 2-use `lh` site would be free; the only
* other one is `n` (D_800C5328) and typing it s16 costs +4 ins.
* 2. `vol` AND `m` ARE ONE VARIABLE. The target holds both in $a0 across disjoint ranges; two
* separate C variables give two allocnos ($v1 and $a1). Merging them is what puts the whole
* volume chain in $a0.
* 3. THE S153 LAUNDER'S REAL COST IS AN ALLOCNO, AND THE FIX IS A PIN ON A DEAD TEMP. Removing
* the launder (plain `D_8007319E[pan]`) fixes m/$a0, the `li 0x100` delay-slot schedule and the
* D_800A4EF6 hoist all at once - but folds the address back to the 3-insn $at macro form (-2
* ins). Keeping the launder, the symbol pseudo has priority log2(refs)*refs/live_length ~ 0.67
* and OUTRANKS the long-lived `vol` (~0.19), so it steals $a0 and pushes the whole chain to $a1
* (+17 rows). `register s32 bp __asm__("$10")` parks it on a register nothing else wants:
* $a0 goes back to vol/m and reload keeps $t0. Do NOT pin it to $8: reload then picks $t1 for
* every parm reload (measured +14 rows, net worse). $9 costs 2 rows (the mflo temp at idx 272
* moves $t1 -> $t2); $10 costs none.
* 4. A zero-byte `__asm__ __volatile__("")` after `vo->unk04 = 0x6009F;` stops sched1 hoisting the
* D_800A4EF6 `lh` above the three stores (-7 rows).
* 5. S219: `vol *= 0x70; vol >>= 7;` (compound) vs `vol = (vol*0x70)>>7;` decides whether the
* `<<4` intermediate lands in $a0 or $v0 (-2 rows).
*
* REMAINING RESIDUAL (12), all REGISTER-NAMING, nothing structural:
* - 3 rows: the D_800A4C28 base is $v1, target $t0.
* - 8 rows: the laundered table base is $t1/$t2, target $t0 - and $t0 is unreachable because the
* same $t0 is reload's spill register for the three parm reloads; a hard-reg var there evicts
* reload. In the target BOTH uses coexist, which means those symbol pseudos are NOT allocnos -
* they are reload rematerialisations of a reg_equiv_constant. Every C spelling tried
* (array[i], &array[i], scalar `extern u16 D;` + `&D + off`, S195-H's struct-cast force_reg,
* const u16* local, S239 integer-space, one-table-two-index) folds to the $at macro form; only
* the launder produces the 4-insn shape, and the launder always creates an allocno.
* - 1 row: idx 244 `lh` vs `lhu` (see lever 1).
*/
/* 0x0C */
/* 0x0C */
/* 0x20 */
/* 0x14 */
/* ---- views this function needs (new names, no TU collision) ---- */
/* the caller's 0x54 request slot (Slot54, seen past its declared tail) */
typedef struct {
/* 0x00 */ u16 unk00;
/* 0x02 */ u16 unk02;
/* 0x04 */ u8 pad04[6];
/* 0x0A */ u8 unk0A;
/* 0x0B */ u8 pad0B[1];
/* 0x0C */ u16 unk0C;
/* 0x0E */ u8 unk0E[8];
} Req32A74;
/* the 0x14 record walked by this loop (Rec14, byte-resolved) */
typedef struct {
/* 0x00 */ u16 unk00;
/* 0x02 */ u16 unk02;
/* 0x04 */ u16 unk04;
/* 0x06 */ u8 unk06;
/* 0x07 */ u8 unk07;
/* 0x08 */ u8 unk08;
/* 0x09 */ u8 unk09;
/* 0x0A */ u8 unk0A;
/* 0x0B */ u8 unk0B;
/* 0x0C */ u8 pad0C[4];
/* 0x10 */ s32 unk10;
} Rec32A74; /* 0x14 */
/* the 0x54 mixer channel at D_800A4988 (cf. Chan336A8) */
typedef struct {
/* 0x00 */ s32 unk00;
/* 0x04 */ s32 unk04;
/* 0x08 */ u16 unk08;
/* 0x0A */ u16 unk0A;
/* 0x0C */ u16 unk0C;
/* 0x0E */ u16 unk0E;
/* 0x10 */ s16 unk10;
/* 0x12 */ s16 unk12;
/* 0x14 */ s32 unk14;
/* 0x18 */ u8 pad18[0xC];
/* 0x24 */ s32 unk24;
/* 0x28 */ u8 pad28[0xC];
/* 0x34 */ u8 unk34;
/* 0x35 */ u8 unk35;
/* 0x36 */ u8 unk36;
/* 0x37 */ u8 pad37[9];
/* 0x40 */ s32 unk40;
/* 0x44 */ s32 unk44;
/* 0x48 */ s16 unk48;
/* 0x4A */ s16 unk4A;
/* 0x4C */ u8 unk4C;
/* 0x4D */ u8 unk4D;
/* 0x4E */ u8 unk4E;
/* 0x4F */ u8 unk4F;
/* 0x50 */ u8 pad50[2];
/* 0x52 */ u8 unk52;
/* 0x53 */ u8 unk53;
} Chan32A74; /* 0x54 */
/* the 0x48 voice at D_800A4C28 (Slot, byte-resolved) */
typedef struct {
/* 0x00 */ s32 unk00;
/* 0x04 */ s32 unk04;
/* 0x08 */ u16 unk08;
/* 0x0A */ u16 unk0A;
/* 0x0C */ u16 unk0C;
/* 0x0E */ u16 unk0E;
/* 0x10 */ u8 pad10[4];
/* 0x14 */ u16 unk14;
/* 0x16 */ u8 pad16[2];
/* 0x18 */ u16 unk18;
/* 0x1A */ u8 pad1A[2];
/* 0x1C */ s32 unk1C;
/* 0x20 */ u8 pad20[0x1A];
/* 0x3A */ u16 unk3A;
/* 0x3C */ u16 unk3C;
/* 0x3E */ u8 pad3E[2];
/* 0x40 */ s32 unk40;
/* 0x44 */ u8 unk44;
/* 0x45 */ u8 unk45;
/* 0x46 */ u8 pad46[2];
} Voice32A74; /* 0x48 */
extern s16 D_800C5328[];
extern s16 D_800C532A[];
extern s16 D_800A4646[];
extern A12 D_80064D44[];
extern B12 *D_8006A970[];
extern Slot D_800A4C28[];
extern u8 D_800A4988[];
extern s32 D_80073140[];
extern s16 D_800A46A2;
extern s16 D_800A4EF6;
extern s16 D_800A4EFA;
extern u8 D_800A4F19;
extern u8 D_800A4F1E;
extern u16 D_8006AA30[];
extern u16 D_8006AB30[];
extern u16 D_8006AB32[];
extern const u16 D_8007319E[];
extern const u16 D_800731A0[];
extern u16 D_8007321E;
extern u8 D_8006AED8[];
extern s16 func_8003F144(s32, s32, s32, C24 *);
extern s32 func_8003F380(s32, s32);
extern s32 func_80030CA4(u16);
extern void func_8002EFF8(s32, s32);
extern void func_8002F064(s32, s32);
extern void func_800316F8(s32);
extern void func_80033324(s32, s32);
void func_80032A74(Slot54 *arg0, s32 arg1, Rec14 *arg2, s32 flags) {
#define REQ ((Req32A74 *)arg0)
#define REC ((Rec32A74 *)arg2)
C24 sp10;
Chan32A74 *ch;
Voice32A74 *vo;
A12 *dd;
B12 *q;
u8 *cp;
const u16 *tA;
const u16 *tB;
u8 *vB;
s32 i2;
u16 v;
u32 vv;
s32 idx;
s32 w;
s32 n;
s32 flag;
s32 h;
s32 i;
s32 b;
s32 sub;
u8 pan;
u32 vol;
u32 mp;
u32 qq;
s32 tb;
u32 d;
register s32 base __asm__("$2");
u16 t16;
s32 t8;
s32 t32;
tA = D_8007319E;
tB = D_800731A0;
vB = (u8 *)D_800A4C28;
v = REQ->unk02;
i = 7;
cp = (u8 *)arg0 + 7;
do {
cp[0xE] = 0;
i--;
cp--;
} while (i >= 0);
REQ->unk0C = 0;
for (;;) {
b = REC->unk08;
flag = 0;
if ((b & 0x80) == 0) {
dd = &D_80064D44[b];
sub = REC->unk09;
if (dd->unk06 != 0) {
flag = (u32)sub < (u32)dd->unk07;
}
n = D_800C5328[b * 2];
if (n < 0) {
if (flag == 0) {
break;
}
n = D_800C532A[b * 2];
if (n < 0) {
break;
}
if (sub >= D_800A4646[n * 12]) {
break;
}
}
} else {
n = 4;
}
if ((flags & 0x1000) && (flags & 0x7F) < 0x30U) {
v >>= 1;
flags = (flags & 0xFF80) | (0x2F - ((0x2F - (flags & 0x7F)) >> 1));
}
idx = func_80030CA4(v);
if (idx != 0) {
idx--;
vo = (Voice32A74 *)(idx * 0x48 + (s32)vB);
if ((b & 0x80) == 0) {
q = &D_8006A970[n][REC->unk09];
vo->unk1C = q->unk00;
vo->unk18 = q->unk04;
vo->unk3A = q->unk06;
vo->unk3C = q->unk08;
} else {
if (func_8003F144(D_800A46A2, b & 0x7F, REC->unk09, &sp10) != 0) {
goto next;
}
h = func_8003F380(D_800A46A2, sp10.unk16);
if (h < 0) {
goto next;
}
tb = sp10.unk04;
vo->unk1C = h;
vo->unk18 = tb << 8;
vo->unk3A = sp10.unk10;
vo->unk3C = sp10.unk12;
}
w = idx + 0x10;
vo->unk00 = D_80073140[w];
ch = (Chan32A74 *)(D_800A4988 + idx * 0x54);
ch->unk4C = 0;
ch->unk4A = 0x7FFF;
if (REQ->unk00 & 0x80) {
ch->unk4D = 0;
} else {
ch->unk4D = 1;
}
t16 = REC->unk02;
ch->unk04 = 0;
ch->unk08 = v;
ch->unk0A = w;
ch->unk00 = t16;
t8 = REC->unk09;
ch->unk0E = b;
ch->unk36 = flag;
ch->unk10 = n;
ch->unk12 = 0;
ch->unk0C = t8;
t32 = REC->unk10;
ch->unk4F = 0;
ch->unk4E = 0x85;
ch->unk14 = t32;
__asm__ __volatile__("");
vol = REC->unk06;
if (D_800A4F1E != 0) {
vol *= 0x70;
vol >>= 7;
}
if (flags & 0x1000) {
ch->unk48 = flags & 0x7F;
} else {
ch->unk48 = 0x7F;
}
ch->unk34 = vol & 0x7F;
pan = REC->unk07;
ch->unk35 = pan;
if (flags & 0x8000) {
ch->unk24 = REC->unk04 - 0x80;
} else {
ch->unk24 = REC->unk04;
}
ch->unk40 = (s32)func_80033324;
ch->unk44 = arg1;
if ((flags & 0x2000) && pan != 0) {
if ((flags & 0x3000) == 0x3000) {
ch->unk53 = D_8006AED8[(u32)(flags & 0xF00) >> 8];
} else {
ch->unk53 = flags & 0x7F;
}
} else {
ch->unk53 = 0;
}
if (REC->unk02 == 0) {
func_800316F8(ch);
}
{
s16 u18 = vo->unk18;
base = (u18 & 0xFF00) + (s8)u18 * 2;
}
base -= 0x3C00;
d = ch->unk24;
d -= base;
if (d >= 0x5300) {
vo->unk14 = 0x3FFF;
} else {
qq = D_8006AB30[d >> 8];
qq = qq * (0x100 - (d & 0xFF));
vo->unk14 = (qq + D_8006AB32[d >> 8] * (d & 0xFF)) >> 8;
}
vol = D_8006AA30[ch->unk34];
mp = vol * D_800A4EFA;
vol = mp >> 7;
mp = vol * ch->unk48;
vol = mp >> 7;
if (pan != 0) {
if (ch->unk53 != 0) {
pan += ch->unk53;
if (pan >= 0x42) {
pan -= 0x40;
if (pan >= 0x80) {
pan = 0x7F;
}
} else {
pan = 1;
}
}
if (D_800A4F19 != 0) {
vv = (vol * tA[pan]) >> 14;
vo->unk0A = vv;
vv = (vol * tB[0x7F - pan]) >> 14;
vo->unk08 = vv;
} else {
vv = (vol * D_8007321E) >> 14;
vo->unk0A = vv;
vo->unk08 = vv;
}
} else {
vv = vol;
vo->unk08 = vv;
vo->unk0A = vv;
}
ch->unk52 = pan;
vo->unk0C = 0;
vo->unk0E = 0;
vo->unk04 = 0x6009F;
__asm__ __volatile__("");
if (D_800A4EF6 > REC->unk0A) {
func_8002F064(1, vo->unk00);
} else {
func_8002F064(0, vo->unk00);
}
t16 = ch->unk0A;
vo->unk45 = 0;
vo->unk44 = 1;
vo->unk40 = t16;
if (REC->unk02 == 0) {
func_8002EFF8(1, vo->unk00);
}
REQ->unk0C++;
REQ->unk0E[idx] = 1;
}
next:
if (REC->unk0B == 0) {
break;
}
arg2++;
v = REC->unk00;
}
if (REQ->unk0C == 0) {
REQ->unk00 = 0;
} else {
REQ->unk0A = 4;
}
}
#undef REQ
#undef REC
+45
View File
@@ -0,0 +1,45 @@
void func_800391D4(s32 arg0, s16 arg1, s16 arg2) {
extern u8 D_800C6DD0[];
extern u8 D_800C6DD4[];
extern s32 D_800C7D20;
extern s32 D_800A2B98;
extern u8 *D_800762B0;
extern u8 D_800762B4[];
u8 *base;
u8 *entry;
register s32 i __asm__("$7");
s32 off;
s32 mask;
i = 0;
base = arg0 + arg2 * 0x1A;
off = 0;
do {
__asm__("");
__asm__("");
__asm__("");
__asm__("");
__asm__("");
__asm__("");
__asm__("");
if (*(base + i + 0x23) != 0 && *(s16 *)&D_800C6DD4[off] == arg1) {
entry = &D_800C6DD0[(s16)i * 0x60];
if (entry[0x5A] != 0) {
s32 off2;
u8 *base2;
off2 = *(s16 *)(entry + 6) * 0x1A;
base2 = *(s32 *)(entry + 0x50);
*(base2 + off2 + (s16)i + 0x23) = 0;
entry[0x5A] = 0;
}
mask = D_80073140[i];
D_800C7D20 &= ~mask;
D_800A2B98 |= mask;
D_800762B0[i] = 2;
D_800762B4[i] = 0;
}
i++;
off += 0x60;
} while (i < 0x10);
}
+45
View File
@@ -0,0 +1,45 @@
void func_800391D4(s32 arg0, s16 arg1, s16 arg2) {
extern u8 D_800C6DD0[];
extern u8 D_800C6DD4[];
extern s32 D_800C7D20;
extern s32 D_800A2B98;
extern u8 *D_800762B0;
extern u8 D_800762B4[];
u8 *base;
u8 *entry;
register s32 i __asm__("$7");
s32 off;
s32 mask;
i = 0;
base = arg0 + arg2 * 0x1A;
off = 0;
do {
__asm__("");
__asm__("");
__asm__("");
__asm__("");
__asm__("");
__asm__("");
__asm__("");
if (*(base + i + 0x23) != 0 && *(s16 *)&D_800C6DD4[off] == arg1) {
entry = &D_800C6DD0[(s16)i * 0x60];
if (entry[0x5A] != 0) {
s32 off2;
u8 *base2;
off2 = *(s16 *)(entry + 6) * 0x1A;
base2 = *(s32 *)(entry + 0x50);
*(base2 + off2 + (s16)i + 0x23) = 0;
entry[0x5A] = 0;
}
mask = ((s32 (*)[1])D_80073140)[i][0];
D_800C7D20 &= ~mask;
D_800A2B98 |= mask;
D_800762B0[i] = 2;
D_800762B4[i] = 0;
}
i++;
off += 0x60;
} while (i < 0x10);
}
+46
View File
@@ -0,0 +1,46 @@
void func_800391D4(s32 arg0, s16 arg1, s16 arg2) {
extern u8 D_800C6DD0[];
extern u8 D_800C6DD4[];
extern s32 D_80073140[];
extern s32 D_800C7D20;
extern s32 D_800A2B98;
extern u8 *D_800762B0;
extern u8 D_800762B4[];
u8 *base;
u8 *entry;
register s32 i __asm__("$7");
s32 off;
s32 mask;
i = 0;
base = arg0 + arg2 * 0x1A;
off = 0;
do {
__asm__("");
__asm__("");
__asm__("");
__asm__("");
__asm__("");
__asm__("");
__asm__("");
if (*(base + i + 0x23) != 0 && *(s16 *)&D_800C6DD4[off] == arg1) {
entry = &D_800C6DD0[(s16)i * 0x60];
if (entry[0x5A] != 0) {
s32 off2;
u8 *base2;
off2 = *(s16 *)(entry + 6) * 0x1A;
base2 = *(s32 *)(entry + 0x50);
*(base2 + off2 + (s16)i + 0x23) = 0;
entry[0x5A] = 0;
}
mask = *(s32 *)((u8 *)D_80073140 + i * 4);
D_800C7D20 &= ~mask;
D_800A2B98 |= mask;
D_800762B0[i] = 2;
D_800762B4[i] = 0;
}
i++;
off += 0x60;
} while (i < 0x10);
}
+9
View File
@@ -12,3 +12,12 @@
{"ts": "2026-09-05 10:57:05", "addr": "0x8017dc80", "name": "func_8017DC80", "reach": null, "klass": "FRAME", "nins": 346, "status": "near", "closeness": 46, "where_stuck": "the historic -33 LENGTH wall CLOSED (GTE macros must be REAL macros \u2014 the TU house block; the splat Handwritten tag is wrong): 346/346, exact 0x70 frame + 9 callee-saved. Residual: reload-slot frame + the la $a0 slot; cse1 unifies OT index and n<4 across func_80010A08(8) (\u00a7500-D2 zero-byte asm retire)", "best_draft": ".run/P32/t3/opus/func_8017DC80.c", "binary": "ov_SC07_002", "source": "P32-T3 one Opus agent 30-70min; \u00a7500-C; report .run/P32/t3/reports/", "residual": null, "passes_tried": null}
{"ts": "2026-09-05 10:57:05", "addr": "0x800cf408", "name": "func_800CF408", "reach": null, "klass": "SCHED", "nins": 178, "status": "near", "closeness": 49, "where_stuck": "[permuter] 3 hunks: two prologue sched2 slots, an mlo/mhi allocno tie, a 3-insn block-2 head hoist. Two LENGTH-bearing pins found (tp $17 shared by 0xE1000087/97 = the 6th callee-saved; ob $10 fixes the $t1/$t2/$t3 rotation, 56->49). \u00a7351 family (func_8001212C -O0 / func_8017DD04 -O2 exemplars)", "best_draft": ".run/P32/t3/opus/func_800CF408.c", "binary": "md_MAIN_007", "source": "P32-T3 one Opus agent 30-70min; \u00a7500-C; report .run/P32/t3/reports/", "residual": null, "passes_tried": null}
{"ts": "2026-09-05 10:57:06", "addr": "0x800cf6d0", "name": "func_800CF6D0", "reach": null, "klass": "SCHED", "nins": 249, "status": "near", "closeness": 137, "where_stuck": "sched1 rank_for_schedule last-insn-CLASS tie (every store priority 2, equal refs; QImode stores grouped, loads floated, HImode after \u2014 5 of 6 blocks) + $t1<->$t3 local-alloc swap of the two masks. 249/249 exact length only with tpage-before-len field order (19 swept). Inert at 137: pins on tpage constants/masks, asm re-ties, volatile/memory fences, /s-denial on any store subset, *0x4000 vs <<14, p++ vs p+0x18, | swap. decomp-permuter 122 was semantically wrong (R63)", "best_draft": ".run/P32/t3/opus/func_800CF6D0.c", "binary": "md_MAIN_007", "source": "P32-T3 one Opus agent 30-70min; \u00a7500-C; report .run/P32/t3/reports/", "residual": null, "passes_tried": null}
{"ts": "2026-09-05 12:05:51", "addr": "0x80011380", "name": "func_80011380", "reach": null, "klass": "WALL-PROVED", "nins": 192, "status": "near", "closeness": 6, "where_stuck": "\u00a7474 PROVED C-level floor (boot -O0): fold-const.c:882 split_tree merges MULT(MULT(i,2),2); the two escapes each cost one instruction (stupid.c:497 adjacency / expand_decl use-brackets); \u00a7388 -O0 colouring oracle. Pinned S79 #8; re-probed S83 in the real TU: DIFF 6 (unchanged)", "best_draft": ".run/m3/opus/func_80011380.c", "binary": "main", "source": "P32-T4 S83 ledger path fix (R62): the ledger's .run/backlog_drafts/func_80011380.c was missing; this draft re-run DIFF 6 in src/boot.c (rtu_match --o0, S83)", "residual": null, "passes_tried": null}
{"ts": "2026-09-05 12:05:51", "addr": "0x801834a4", "name": "func_801834A4", "reach": null, "klass": "WALL-CANDIDATE", "nins": 106, "status": "near", "closeness": 6, "where_stuck": "WALL candidate: loop.c movable ordering, closeness 6 (S71); re-probed S83 in the real TU: DIFF 6 for all three stored variants (unchanged)", "best_draft": ".run/S71_gate14/ov_SC03_105-cn-cast-rc-sd/func_801834A4.c", "binary": "ov_SC03_105", "source": "P32-T4 S83 ledger path fix (R62): the ledger's .run/backlog_drafts/func_801834A4.c was missing; the three S71_gate14 variants (cn-cast, cn-cast-rc, cn-cast-rc-sd) all re-run DIFF 6 in src/ov_SC03_105/ov_SC03_105_jr_80181C84.c (S83)", "residual": null, "passes_tried": null}
{"ts": "2026-09-05 12:06:54", "addr": "0x80032a74", "name": "func_80032A74", "reach": null, "klass": "WALL-CANDIDATE", "nins": 422, "status": "near", "closeness": 1, "where_stuck": "WALL candidate CONFIRMED in the real TU (S83): 422/422, sole residual idx 244 `lh v0,0x18(s1)` vs target `lhu` \u2014 extendhisi2 is a force_not_mem EXPAND (the orphan frame slot is minted only at an lh; \u00a7172 producer 3 caller-save area, reload1.c:1445), so lhu loses the 8 frame bytes; ~200 byte-probes + 100-variant retyping sweep (S79) + permuter_ils 8x150s null (S80). Citation current (\u00a7172, reload1.c:1445). Draft synced to the TU (typedefs stripped via cdecl.strip_provided_typedefs; D_80064D44/D_8006A970/func_8003F144/func_800316F8 spelled as the TU)", "best_draft": ".run/P32/t4/drafts/func_80032A74_tuclean.c", "binary": "main", "source": "P32-T4 S83 re-probe (R40): the S79w Opus draft was a CC1 FAIL in src/800_b_2.c only for PLUMBING (7 typedefs the TU provides via 800_shared.h + 4 decl spellings); stripped/synced copy re-run in the REAL TU: DIFF 1 (idx 244 lh vs lhu) \u2014 the recorded residual, confirmed in TU context", "residual": null, "passes_tried": null}
{"ts": "2026-09-05 12:06:55", "addr": "0x80020da4", "name": "func_80020DA4", "reach": null, "klass": "WALL-CANDIDATE", "nins": 100, "status": "near", "closeness": 2, "where_stuck": "WALL candidate CONFIRMED (S83 rtu DIFF 2): 100/100, phantom 16-byte frame reproduced (address-taken frame_pad[3]); residual = mflo destination $t0 vs $a2 (REGALLOC-PERM), pinning regresses to 79; 5 attempts 51->20->14->8->2 + permuter_ils null (S80)", "best_draft": ".run/S79w/sonnet/func_80020DA4.c", "binary": "main", "source": "P32-T4 S83 re-probe in the REAL TU (src/800.c, after the S83 banks of func_80015B6C/func_8001BC6C): DIFF 2 \u2014 unchanged", "residual": null, "passes_tried": null}
{"ts": "2026-09-05 12:06:55", "addr": "0x8017df28", "name": "func_8017DF28", "reach": null, "klass": "WALL-CANDIDATE", "nins": 119, "status": "near", "closeness": 2, "where_stuck": "WALL candidate CONFIRMED (S83 rtu DIFF 2): expand_block_move copy_addr_to_reg pseudo cse-reused for both later &mtx args (gcc-2.7.2-map cse_expr.md [A23-2]/\u00a7H); 119/119; the addiu $s2,sp,0x10 sits in the jal delay slot vs the target bnez slot; five RTL-verified attempts (S71/S79); permuter_ils (S80) \"1\" was a divergent rewrite (R63). Citation current ([A23-2] present in cse_expr.md)", "best_draft": ".run/S79w/sonnet/func_8017DF28.c", "binary": "ov_SC06_022", "source": "P32-T4 S83 re-probe in the REAL TU (src/ov_SC06_022/ov_SC06_022_jr_8017BEBC.c): DIFF 2 \u2014 idx 25/28 addiu s2,sp,0x10 vs nop swapped (the jal delay slot vs the target's bnez slot) \u2014 unchanged", "residual": null, "passes_tried": null}
{"ts": "2026-09-05 12:07:57", "addr": "0x80039dec", "name": "func_80039DEC", "reach": null, "klass": "WALL-CANDIDATE", "nins": 74, "status": "near", "closeness": 2, "where_stuck": "WALL candidate CONFIRMED (S83 sandbox-TU rtu DIFF 2: idx 0 `move t1,a2` vs `addu a3,a2,zero`; idx 56 `sb t1` vs `sb a3`): 74/74 exact length; the $a3<->$t0/$t1 swap of the two K&R raw-preserve parameter copies is fixed by ARGUMENT POSITION in gcc-2.7.2 narrow-parameter promotion (2nd param -> $a3, 3rd -> $t0) before the global allocator runs \u2014 every pin regresses to 60-75; 3 attempts + permuter_ils 9 -> 2 (S80). Banking would need the TU decl -> no-proto (byte-neutral commit) \u2014 only worth it at closeness 0", "best_draft": ".run/S79w/permuter/func_80039DEC.c", "binary": "main", "source": "P32-T4 S83 re-probe (R40): the drafts were CC1 FAIL in src/800_c.c only because the TU's prototype (line 3496) rejects the K&R definition; in a sandbox TU copy with the no-proto spelling the permuter draft re-runs DIFF 2 \u2014 the recorded residual, confirmed in TU context (leaf 2; the Sonnet draft leaf 9)", "residual": null, "passes_tried": null}
{"ts": "2026-09-05 12:07:58", "addr": "0x800391d4", "name": "func_800391D4", "reach": null, "klass": "WALL-CANDIDATE", "nins": 75, "status": "near", "closeness": 3, "where_stuck": "WALL candidate CONFIRMED (S83 sandbox-TU rtu DIFF 3: idx 9-11 `move t0,zero` before vs after arg1 sll/sra): 75/75, a 3-insn SCHEDULE-REORDER \u2014 move_movables splices hoisted invariants after any pre-existing preheader flow code (loop.c 2.7.2:1529, map loop.md L4), so off init cannot follow arg1 hoisted sign-extend from C; 4 prior attempts + S79 Sonnet 64->3 + permuter_ils null (S80). Banking would need the TU externs -> [][1] (whole-EXE sha decides) \u2014 only worth it at closeness 0", "best_draft": ".run/S79w/sonnet/func_800391D4.c", "binary": "main", "source": "P32-T4 S83 re-probe (R40): CC1 FAIL in src/800_c.c only because the draft's lever spelling conflicts with the TU's three ; in a sandbox TU copy with the externs spelled [][1] (+ (s32*) casts at the 3 uses) the Sonnet draft re-runs DIFF 3 \u2014 the recorded residual; the [][1] spelling is LOAD-BEARING: the TU's [] spelling, a (s32 (*)[1]) cast and a byte-offset form all regress to 65 @ 76 ins", "residual": null, "passes_tried": null}
{"ts": "2026-09-05 12:09:39", "addr": "0x80039dec", "name": "func_80039DEC", "reach": null, "klass": "WALL-CANDIDATE", "nins": 74, "status": "near", "closeness": 2, "where_stuck": "WALL candidate CONFIRMED (S83 sandbox-TU rtu DIFF 2: idx 0 'move t1,a2' vs 'addu a3,a2,zero'; idx 56 'sb t1' vs 'sb a3'): 74/74 exact length; the $a3<->$t0/$t1 swap of the two K&R raw-preserve parameter copies is fixed by ARGUMENT POSITION in gcc-2.7.2 narrow-parameter promotion (2nd param -> $a3, 3rd -> $t0) before the global allocator runs - every pin regresses to 60-75; 3 attempts + permuter_ils 9 -> 2 (S80). Banking would need the TU decl -> no-proto (byte-neutral commit) - only worth it at closeness 0", "best_draft": ".run/S79w/permuter/func_80039DEC.c", "binary": "main", "source": "P32-T4 S83 re-probe (R40): the drafts were CC1 FAIL in src/800_c.c only because the TU's prototype 'extern void func_80039DEC(void *, s16, u8)' (line 3496) rejects the K&R definition; in a sandbox TU copy with the no-proto spelling the permuter draft re-runs DIFF 2 - the recorded residual, confirmed in TU context (leaf 2; the Sonnet draft leaf 9)", "residual": null, "passes_tried": null}
{"ts": "2026-09-05 12:09:40", "addr": "0x800391d4", "name": "func_800391D4", "reach": null, "klass": "WALL-CANDIDATE", "nins": 75, "status": "near", "closeness": 3, "where_stuck": "WALL candidate CONFIRMED (S83 sandbox-TU rtu DIFF 3: idx 9-11 'move t0,zero' before vs after arg1 sll/sra): 75/75, a 3-insn SCHEDULE-REORDER - move_movables splices hoisted invariants after any pre-existing preheader flow code (loop.c 2.7.2:1529, map loop.md L4), so off init cannot follow arg1 hoisted sign-extend from C; 4 prior attempts + S79 Sonnet 64->3 + permuter_ils null (S80). Banking would need the TU externs -> [][1] (whole-EXE sha decides) - only worth it at closeness 0", "best_draft": ".run/S79w/sonnet/func_800391D4.c", "binary": "main", "source": "P32-T4 S83 re-probe (R40): CC1 FAIL in src/800_c.c only because the draft's lever spelling 'extern s32 D_80073140[][1]' conflicts with the TU's three 'extern s32 D_80073140[]'; in a sandbox TU copy with the externs spelled [][1] (+ (s32*) casts at the 3 uses) the Sonnet draft re-runs DIFF 3 - the recorded residual; the [][1] spelling is LOAD-BEARING: the TU's [] spelling, a (s32 (*)[1]) cast and a byte-offset form all regress to 65 @ 76 ins", "residual": null, "passes_tried": null}
+7 -7
View File
@@ -2,10 +2,10 @@
# 7 still-valid of 8; 1 dropped as stale (banked / linked / blocker-since-fixed).
# An exclude list records what the TOOLING could not do — regenerate it as
# part of every tool fix, or it becomes a list of work you decided not to do.
ov_SC03_105:func_801834A4 # WALL: loop.c movable ordering, closeness 6 (S71)
ov_SC06_022:func_8017DF28 # WALL: expand_block_move copy_addr_to_reg pseudo cse-reused for both later &mtx args (cse_expr.md [A23-2]/§H) — the addiu $s2,sp,0x10 sits in the jal's delay slot vs the target's bnez slot; closeness 2 on five RTL-verified attempts (S71/S79); permuter_ils 8x150s (S80) reported 1 but its waypoint REPLACED the addiu with `sw zero,48(sp)` — a divergent rewrite, not a closer body: closeness stays 2
main:func_80032A74 # WALL: candidate: 422/422, frame/offsets/27 symbols exact, sole residual idx 244 `lh` vs `lhu` — extendhisi2 is a force_not_mem EXPAND (an orphan frame slot is minted only at an lh), the target's 8 extra frame bytes are §172 producer 3 (caller-save area, reload1.c:1445); ~200 byte-probes incl. a 100-variant retyping sweep (S79 Opus) + permuter_ils 8x150s null (S80); closeness 1
main:func_80020DA4 # WALL: candidate: 100/100, phantom 16-byte frame reproduced (address-taken frame_pad[3]); residual = mflo destination $t0 vs $a2 (REGALLOC-PERM), pinning regresses to 79; 5 attempts 51→20→14→8→2 (S7x/S79) + permuter_ils 8x150s null (S80); closeness 2
main:func_800391D4 # WALL: candidate: 75/75, residual = a 3-insn SCHEDULE-REORDER (off=0 vs arg1's sll/sra pair) — move_movables splices hoisted invariants after any pre-existing preheader flow code (loop.c), so off's init cannot follow arg1's hoisted sign-extend from C; 4 prior attempts + S79 Sonnet (64→3: i=$7 pin kills combine_givs, D_80073140[][1] decl, 7 asm("") insn_count pads) + permuter_ils 8x150s null (S80); closeness 3
main:func_80011380 # WALL: §474 PROVED C-level floor (closeness 6) — fold-const.c:882 split_tree merges MULT(MULT(i,2),2); the two escapes each cost one instruction (stupid.c:497 adjacency / expand_decl use-brackets); §388 -O0 colouring oracle. Pinned S79 #8.
main:func_80039DEC # WALL: candidate: 74/74 exact length; the $a3<->$t0 swap of the two K&R raw-preserve parameter copies is fixed by ARGUMENT POSITION in gcc-2.7.2's narrow-parameter promotion (2nd param -> $a3, 3rd -> $t0) before the global allocator runs — every pin on the raw-preserve values regresses to 60-75; 3 attempts corroborate (S7x/S79 Sonnet 9) + permuter_ils 8x150s 9 -> 2 (S80); closeness 2
ov_SC03_105:func_801834A4 # WALL: loop.c movable ordering, closeness 6 (S71) | T4 S83: re-probed in the real TU (3 stored variants) DIFF 6 — CANDIDATE, unchanged
ov_SC06_022:func_8017DF28 # WALL: expand_block_move copy_addr_to_reg pseudo cse-reused for both later &mtx args (cse_expr.md [A23-2]/§H) — the addiu $s2,sp,0x10 sits in the jal's delay slot vs the target's bnez slot; closeness 2 on five RTL-verified attempts (S71/S79); permuter_ils 8x150s (S80) reported 1 but its waypoint REPLACED the addiu with `sw zero,48(sp)` — a divergent rewrite, not a closer body: closeness stays 2 | T4 S83: re-probed in the real TU DIFF 2 (addiu/nop slot swap idx 25/28) — CANDIDATE, unchanged; citation [A23-2] current
main:func_80032A74 # WALL: candidate: 422/422, frame/offsets/27 symbols exact, sole residual idx 244 `lh` vs `lhu` — extendhisi2 is a force_not_mem EXPAND (an orphan frame slot is minted only at an lh), the target's 8 extra frame bytes are §172 producer 3 (caller-save area, reload1.c:1445); ~200 byte-probes incl. a 100-variant retyping sweep (S79 Opus) + permuter_ils 8x150s null (S80); closeness 1 | T4 S83: the S79w draft was a CC1 FAIL only for PLUMBING (7 header typedefs + 4 decl spellings); synced copy .run/P32/t4/drafts/func_80032A74_tuclean.c re-run in the real TU DIFF 1 (idx 244 lh vs lhu) — CANDIDATE, unchanged
main:func_80020DA4 # WALL: candidate: 100/100, phantom 16-byte frame reproduced (address-taken frame_pad[3]); residual = mflo destination $t0 vs $a2 (REGALLOC-PERM), pinning regresses to 79; 5 attempts 51→20→14→8→2 (S7x/S79) + permuter_ils 8x150s null (S80); closeness 2 | T4 S83: re-probed in the real TU DIFF 2 — CANDIDATE, unchanged
main:func_800391D4 # WALL: candidate: 75/75, residual = a 3-insn SCHEDULE-REORDER (off=0 vs arg1's sll/sra pair) — move_movables splices hoisted invariants after any pre-existing preheader flow code (loop.c), so off's init cannot follow arg1's hoisted sign-extend from C; 4 prior attempts + S79 Sonnet (64→3: i=$7 pin kills combine_givs, D_80073140[][1] decl, 7 asm("") insn_count pads) + permuter_ils 8x150s null (S80); closeness 3 | T4 S83: CC1 FAIL was the draft's load-bearing `D_80073140[][1]` vs the TU's `[]`; sandbox TU with [][1] externs: DIFF 3 (idx 9-11) — CANDIDATE, unchanged; the TU-compatible spellings all regress to 65
main:func_80011380 # WALL: §474 PROVED C-level floor (closeness 6) — fold-const.c:882 split_tree merges MULT(MULT(i,2),2); the two escapes each cost one instruction (stupid.c:497 adjacency / expand_decl use-brackets); §388 -O0 colouring oracle. Pinned S79 #8. | T4 S83: re-probed in the real TU (rtu --o0) DIFF 6 — PROVED (§474), unchanged
main:func_80039DEC # WALL: candidate: 74/74 exact length; the $a3<->$t0 swap of the two K&R raw-preserve parameter copies is fixed by ARGUMENT POSITION in gcc-2.7.2's narrow-parameter promotion (2nd param -> $a3, 3rd -> $t0) before the global allocator runs — every pin on the raw-preserve values regresses to 60-75; 3 attempts corroborate (S7x/S79 Sonnet 9) + permuter_ils 8x150s 9 -> 2 (S80); closeness 2 | T4 S83: CC1 FAIL was the TU's prototype (800_c.c:3496) vs the K&R definition; sandbox TU with the no-proto decl: permuter draft DIFF 2 (idx 0/56 t1 vs a3) — CANDIDATE, unchanged
+7
View File
@@ -764,3 +764,10 @@ bytes; five "cleaner" spellings did not — the lever was the pseudo's BIRTH poi
agent's `src/.masked_diff_probe.<pid>.c` existed and compiled after it was deleted — gate_main reported a false batch
FAIL and spent a rebuild. Accelerator: guard at the consumer (`-not -name '.*'` in the Makefile's find) so every probing
tool is covered at once; a probe tool that must live in `src/` should also be listed in the cookbook §500-E3.
**(8) Re-probe a CC1-FAIL wall in a SANDBOX TU, not by editing `src/` (P32 T4 S83).** Three of seven pinned walls failed to
compile in their TU for declaration reasons only (header typedefs a draft duplicated; a narrow-typed prototype vs a K&R
definition; a load-bearing `[][1]` extern vs the TU's `[]`). Copying the TU under `.run/`, symlinking `src/*.h` +
`src/shared` beside it, editing the declaration THERE and passing `--tu <copy>` to `rtu_match` reproduced every residual
(1/2/3) with zero commits to `src/` — the byte-neutral TU edit is deferred to the day a row reaches closeness 0.
Accelerator: `rtu_match --tu` accepts any path; a sandbox costs one `mkdir` + two symlinks.
+17 -15
View File
@@ -2,21 +2,23 @@
> Generated by `tools/backlog.py render` from `.run/backlog.jsonl`. These are functions the Phase-21 automation got **close** on but did NOT byte-match. The whole-binary byte-gate is the sole arbiter (G3/P9): **byte-matches bank and are NOT listed here** — only genuine near-misses/blockers are. Ranked by hand-session priority: **reach** (×N propagation leverage) → **closeness** (match_one mismatch count, lower = closer) → **size**. Each row's `best_draft` is the closest C the machine reached — resume from there.
**Open near-misses:** 14 · by status {'near': 13, 'failed': 1} · by class {None: 6, 'REGALLOC-PERM': 1, 'SCHED': 4, 'REGALLOC': 1, 'ALIAS': 1, 'FRAME': 1}
**Open near-misses:** 16 · by status {'near': 15, 'failed': 1} · by class {'WALL-CANDIDATE': 6, 'REGALLOC-PERM': 1, 'WALL-PROVED': 1, 'SCHED': 4, 'REGALLOC': 1, 'ALIAS': 1, 'FRAME': 1, None: 1}
| # | addr | reach | class | nins | status | closeness | where it stuck | best draft |
|--:|------|------:|-------|-----:|--------|----------:|----------------|------------|
| 1 | func_80032A74 | None | | None | near | 1 | 422/422 instructions, frame 0x78 exact, every immediate/stack offset/branch target exact, all 27 symbols audited against the target's own relocation lines (law 1c). Sole residual is idx 244 `lh` vs `lhu`. I proved WHY it is a wall rather than re-grinding it: `extendhisi2` is a force_not_mem EXPAND, so an orphan (the 8 bytes the 0x78 frame needs at sp+0x48) can only be minted by a 3-way movhi+ashl+ | `/home/musashi/bfm-decomp/.run/S79w/opus/func_80032A74.c` |
| 2 | func_800CD674 | None | REGALLOC-PERM | 174 | near | 2 | $a3<->$t1 across two masked prim pointers (one shared local can be only one; splitting = +1 pseudo displacing two hoisted constants, 31); SPRT-with-tpage family, §364 mirror (non-struct field stores). Inert: pin order (8 perms), assignment placement (6), volatile index, p+=0x18 spellings, u8* cursor, every pin subset. NEXT: permuter_ils on the pinned seed (§494 recipe) | `.run/P32/t3/opus/func_800CD674.c` |
| 3 | func_80020DA4 | None | | None | near | 2 | Q12 3x3 rotation-matrix build (twin shape of ov_SC02_011:func_8018B76C). Prior 51->20->14->8; NEW lever: an address-taken s32 frame_pad[3] local induces the target's phantom 16-byte frame -> 2. Residual: mflo destination $t0 vs target $a2 (REGALLOC-PERM); pinning regresses to 79. Handed to permuter_ils. | `.run/S79w/sonnet/func_80020DA4.c` |
| 4 | func_80039DEC | None | | None | near | 2 | S80 permuter_ils best 2 (seed 9); 74/74 exact length match, OPCODE-MIXED. Key levers that moved the residual from the seed's 74-vs-72-length structural failure down to 9: (1) K&R old-style definition for a2 (s16 a2 in the identifier-declaration form) reproduces the target's in-place sll/sra-16 arg-register cast + its addu $a3,$a2,zero raw-preserve, which no ANSI (s16)-cast or s32-typed spelling ever produced; (2) forward-goto bloc | `/home/musashi/bfm-decomp/.run/S79w/sonnet/func_80039DEC.c` |
| 5 | func_8017DF28 | None | | None | near | 2 | S80 permuter_ils 8x150s: waypoint '1' replaced the addiu $s2,$sp,0x10 with sw zero,48(sp) (semantically divergent, R14) -> closeness stays 2; 119/119; single SCHEDULE residual: addiu $s2,sp,0x10 sits in the jal's delay slot vs the target's bnez slot — expand_block_move's copy_addr_to_reg pseudo for mtx=D_800AE620 is cse-reused for both later &mtx args (gcc-2.7.2-map cse_expr.md [A23-2]/§H). Field-wise copy regresses to 117 (a real loop); the §H diamond cse-reset is a byte-identical no-op (no 2-predecessor merge to exploit). Fifth RTL-ve | `.run/S79w/sonnet/func_8017DF28.c` |
| 6 | func_800391D4 | None | | None | near | 3 | 75/75 instructions (exact length), only residual is a 3-insn SCHEDULE-REORDER (off=0 vs arg1's sll/sra pair rotated) classified bucket=permuter. Cracked the 4-prior-attempt wall (best prior closeness 64, LENGTH-DRIFT+1) via register-pin i=$7 to kill combine_givs on D_80073140[i], a 2D-array decl D_80073140[][1] (cookbook SS164-26) to stop move_movables hoisting the address instead of folding it in | `/home/musashi/bfm-decomp/.run/S79w/sonnet/func_800391D4.c` |
| 7 | func_800CD92C | None | SCHED | 247 | near | 15 | map §S7 prologue WEAVE: the {sw,lui,ori} groups for 0xE100008D/8F land after the 9-insn li block instead of before — the §17 pins reproduce the ALLOCATION but the hoist happens in sched2. Same SPRT family as func_800CD674 (§364 mirror levers applied) | `.run/P32/t3/opus/func_800CD92C.c` |
| 8 | func_80039308 | None | REGALLOC | 518 | near | 17 | sched2 + cross-block regalloc: preheader 49/50 swap, un-spellable addu $a2,$a0,$zero (every p=r form cse-propagated), a temp on $t0 vs $s7, and 11 insns of one alias fact (2nd D_80073140[j] load cannot schedule above the D_800C7D20 store from C; /s unlock costs the address allocation, net 20-24). 34->17 via s16 b4 widening copy + dead-local identity sweep (.run/P32/t3/restored/sweep_func_80039308.py) + $2 pin. permuter_ils --klass REGALLOC 2x150s: no gain | `.run/P32/t3/opus/func_80039308.c` |
| 9 | func_800CF3E8 | None | ALIAS | 469 | near | 27 | ONE cause: the pinned-base alias basin (§500-D1) in the p5/p6 tail; blocks 1-2 byte-exact (idx 0-361). 54->27 via blk2 constant birth order + birthing-boost local w60 + §194-A fence relocation. Inert: all 9 pins load-bearing (+5..+1409), asm position x7, h6 hoist 32x2, tag reshape, P_TAG ADDPRIM, array p6 stores, ~92k annealed variants. Untested: an unpinned alias of p6 for the tag load alone (ONE Opus second look allowed) | `.run/P32/t3/opus/func_800CF3E8.c` |
| 10 | func_80185810 | None | SCHED | 489 | near | 35 | [permuter] 4 emission windows (see report .run/P32/t3/reports/func_80185810__opus__*.md); exact length, rtu-clean | `.run/P32/t3/opus/func_80185810.c` |
| 11 | func_8017DC80 | None | FRAME | 346 | near | 46 | the historic -33 LENGTH wall CLOSED (GTE macros must be REAL macros — the TU house block; the splat Handwritten tag is wrong): 346/346, exact 0x70 frame + 9 callee-saved. Residual: reload-slot frame + the la $a0 slot; cse1 unifies OT index and n<4 across func_80010A08(8) (§500-D2 zero-byte asm retire) | `.run/P32/t3/opus/func_8017DC80.c` |
| 12 | func_800CF408 | None | SCHED | 178 | near | 49 | [permuter] 3 hunks: two prologue sched2 slots, an mlo/mhi allocno tie, a 3-insn block-2 head hoist. Two LENGTH-bearing pins found (tp $17 shared by 0xE1000087/97 = the 6th callee-saved; ob $10 fixes the $t1/$t2/$t3 rotation, 56->49). §351 family (func_8001212C -O0 / func_8017DD04 -O2 exemplars) | `.run/P32/t3/opus/func_800CF408.c` |
| 13 | func_800CF6D0 | None | SCHED | 249 | near | 137 | sched1 rank_for_schedule last-insn-CLASS tie (every store priority 2, equal refs; QImode stores grouped, loads floated, HImode after — 5 of 6 blocks) + $t1<->$t3 local-alloc swap of the two masks. 249/249 exact length only with tpage-before-len field order (19 swept). Inert at 137: pins on tpage constants/masks, asm re-ties, volatile/memory fences, /s-denial on any store subset, *0x4000 vs <<14, p++ vs p+0x18, / swap. decomp-permuter 122 was semantically wrong (R63) | `.run/P32/t3/opus/func_800CF6D0.c` |
| 14 | func_80062144 | None | | None | failed | | won't compile standalone (loose-typing / missing decl) | |
| 1 | func_80032A74 | None | WALL-CANDIDATE | 422 | near | 1 | WALL candidate CONFIRMED in the real TU (S83): 422/422, sole residual idx 244 `lh v0,0x18(s1)` vs target `lhu` — extendhisi2 is a force_not_mem EXPAND (the orphan frame slot is minted only at an lh; §172 producer 3 caller-save area, reload1.c:1445), so lhu loses the 8 frame bytes; ~200 byte-probes + 100-variant retyping sweep (S79) + permuter_ils 8x150s null (S80). Citation current (§172, reload1.c:1445). Draft synced to the TU (typedefs stripped via cdecl.strip_provided_typedefs; D_80064D44/D_8006A970/func_8003F144/func_800316F8 spelled as the TU) | `.run/P32/t4/drafts/func_80032A74_tuclean.c` |
| 2 | func_80039DEC | None | WALL-CANDIDATE | 74 | near | 2 | WALL candidate CONFIRMED (S83 sandbox-TU rtu DIFF 2: idx 0 `move t1,a2` vs `addu a3,a2,zero`; idx 56 `sb t1` vs `sb a3`): 74/74 exact length; the $a3<->$t0/$t1 swap of the two K&R raw-preserve parameter copies is fixed by ARGUMENT POSITION in gcc-2.7.2 narrow-parameter promotion (2nd param -> $a3, 3rd -> $t0) before the global allocator runs — every pin regresses to 60-75; 3 attempts + permuter_ils 9 -> 2 (S80). Banking would need the TU decl -> no-proto (byte-neutral commit) — only worth it at closeness 0 | `.run/S79w/permuter/func_80039DEC.c` |
| 3 | func_80020DA4 | None | WALL-CANDIDATE | 100 | near | 2 | WALL candidate CONFIRMED (S83 rtu DIFF 2): 100/100, phantom 16-byte frame reproduced (address-taken frame_pad[3]); residual = mflo destination $t0 vs $a2 (REGALLOC-PERM), pinning regresses to 79; 5 attempts 51->20->14->8->2 + permuter_ils null (S80) | `.run/S79w/sonnet/func_80020DA4.c` |
| 4 | func_8017DF28 | None | WALL-CANDIDATE | 119 | near | 2 | WALL candidate CONFIRMED (S83 rtu DIFF 2): expand_block_move copy_addr_to_reg pseudo cse-reused for both later &mtx args (gcc-2.7.2-map cse_expr.md [A23-2]/§H); 119/119; the addiu $s2,sp,0x10 sits in the jal delay slot vs the target bnez slot; five RTL-verified attempts (S71/S79); permuter_ils (S80) "1" was a divergent rewrite (R63). Citation current ([A23-2] present in cse_expr.md) | `.run/S79w/sonnet/func_8017DF28.c` |
| 5 | func_800CD674 | None | REGALLOC-PERM | 174 | near | 2 | $a3<->$t1 across two masked prim pointers (one shared local can be only one; splitting = +1 pseudo displacing two hoisted constants, 31); SPRT-with-tpage family, §364 mirror (non-struct field stores). Inert: pin order (8 perms), assignment placement (6), volatile index, p+=0x18 spellings, u8* cursor, every pin subset. NEXT: permuter_ils on the pinned seed (§494 recipe) | `.run/P32/t3/opus/func_800CD674.c` |
| 6 | func_800391D4 | None | WALL-CANDIDATE | 75 | near | 3 | WALL candidate CONFIRMED (S83 sandbox-TU rtu DIFF 3: idx 9-11 `move t0,zero` before vs after arg1 sll/sra): 75/75, a 3-insn SCHEDULE-REORDER — move_movables splices hoisted invariants after any pre-existing preheader flow code (loop.c 2.7.2:1529, map loop.md L4), so off init cannot follow arg1 hoisted sign-extend from C; 4 prior attempts + S79 Sonnet 64->3 + permuter_ils null (S80). Banking would need the TU externs -> [][1] (whole-EXE sha decides) — only worth it at closeness 0 | `.run/S79w/sonnet/func_800391D4.c` |
| 7 | func_801834A4 | None | WALL-CANDIDATE | 106 | near | 6 | WALL candidate: loop.c movable ordering, closeness 6 (S71); re-probed S83 in the real TU: DIFF 6 for all three stored variants (unchanged) | `.run/S71_gate14/ov_SC03_105-cn-cast-rc-sd/func_801834A4.c` |
| 8 | func_80011380 | None | WALL-PROVED | 192 | near | 6 | §474 PROVED C-level floor (boot -O0): fold-const.c:882 split_tree merges MULT(MULT(i,2),2); the two escapes each cost one instruction (stupid.c:497 adjacency / expand_decl use-brackets); §388 -O0 colouring oracle. Pinned S79 #8; re-probed S83 in the real TU: DIFF 6 (unchanged) | `.run/m3/opus/func_80011380.c` |
| 9 | func_800CD92C | None | SCHED | 247 | near | 15 | map §S7 prologue WEAVE: the {sw,lui,ori} groups for 0xE100008D/8F land after the 9-insn li block instead of before — the §17 pins reproduce the ALLOCATION but the hoist happens in sched2. Same SPRT family as func_800CD674 (§364 mirror levers applied) | `.run/P32/t3/opus/func_800CD92C.c` |
| 10 | func_80039308 | None | REGALLOC | 518 | near | 17 | sched2 + cross-block regalloc: preheader 49/50 swap, un-spellable addu $a2,$a0,$zero (every p=r form cse-propagated), a temp on $t0 vs $s7, and 11 insns of one alias fact (2nd D_80073140[j] load cannot schedule above the D_800C7D20 store from C; /s unlock costs the address allocation, net 20-24). 34->17 via s16 b4 widening copy + dead-local identity sweep (.run/P32/t3/restored/sweep_func_80039308.py) + $2 pin. permuter_ils --klass REGALLOC 2x150s: no gain | `.run/P32/t3/opus/func_80039308.c` |
| 11 | func_800CF3E8 | None | ALIAS | 469 | near | 27 | ONE cause: the pinned-base alias basin (§500-D1) in the p5/p6 tail; blocks 1-2 byte-exact (idx 0-361). 54->27 via blk2 constant birth order + birthing-boost local w60 + §194-A fence relocation. Inert: all 9 pins load-bearing (+5..+1409), asm position x7, h6 hoist 32x2, tag reshape, P_TAG ADDPRIM, array p6 stores, ~92k annealed variants. Untested: an unpinned alias of p6 for the tag load alone (ONE Opus second look allowed) | `.run/P32/t3/opus/func_800CF3E8.c` |
| 12 | func_80185810 | None | SCHED | 489 | near | 35 | [permuter] 4 emission windows (see report .run/P32/t3/reports/func_80185810__opus__*.md); exact length, rtu-clean | `.run/P32/t3/opus/func_80185810.c` |
| 13 | func_8017DC80 | None | FRAME | 346 | near | 46 | the historic -33 LENGTH wall CLOSED (GTE macros must be REAL macros — the TU house block; the splat Handwritten tag is wrong): 346/346, exact 0x70 frame + 9 callee-saved. Residual: reload-slot frame + the la $a0 slot; cse1 unifies OT index and n<4 across func_80010A08(8) (§500-D2 zero-byte asm retire) | `.run/P32/t3/opus/func_8017DC80.c` |
| 14 | func_800CF408 | None | SCHED | 178 | near | 49 | [permuter] 3 hunks: two prologue sched2 slots, an mlo/mhi allocno tie, a 3-insn block-2 head hoist. Two LENGTH-bearing pins found (tp $17 shared by 0xE1000087/97 = the 6th callee-saved; ob $10 fixes the $t1/$t2/$t3 rotation, 56->49). §351 family (func_8001212C -O0 / func_8017DD04 -O2 exemplars) | `.run/P32/t3/opus/func_800CF408.c` |
| 15 | func_800CF6D0 | None | SCHED | 249 | near | 137 | sched1 rank_for_schedule last-insn-CLASS tie (every store priority 2, equal refs; QImode stores grouped, loads floated, HImode after — 5 of 6 blocks) + $t1<->$t3 local-alloc swap of the two masks. 249/249 exact length only with tpage-before-len field order (19 swept). Inert at 137: pins on tpage constants/masks, asm re-ties, volatile/memory fences, /s-denial on any store subset, *0x4000 vs <<14, p++ vs p+0x18, / swap. decomp-permuter 122 was semantically wrong (R63) | `.run/P32/t3/opus/func_800CF6D0.c` |
| 16 | func_80062144 | None | | None | failed | | won't compile standalone (loose-typing / missing decl) | |
+33
View File
@@ -3295,3 +3295,36 @@ message and per-function work dirs should have been in the S80 shape from its fi
a FRESH session, not at the end of a T0–T2c day; (3) packs should carry the same-TU neighbours' DECLARATIONS of the
shared globals (the func_8002FDE8 fix was two functions away); (4) a "converged plateau" in the journal is a reason to
re-read the body against a neighbour, not a reason to route to the permuter.
## P32 S83 (2026-09-05) — the crack pass closed on 39 banks, the walls got their final ledger, and every remaining "wall" was re-probed in TU context without touching src/
### Context and belief
The 10:01 checkpoint handed S83 a census of 44 stubs: 10 verified-MATCH rows awaiting the gate, 17 Haiku rows never launched
(the 20-agent cap), 9 NEAR seeds and 7 pinned walls. The belief going in: the MATCH rows were free banks, the Haiku rows were
~50% yield on the ≤25-ins band, the walls were settled.
### What happened, measured
- **The MATCH rows were free only per draft.** Eleven of twelve same-TU drafts were `rtu_match` MATCH alone and the batch
failed twice: a `s16`/`u16` spelling of one global across two drafts, a §304 rodata block only the stub `.s` owned
(invisible to a compile-only oracle — it fails at LINK), and a prototype a sibling bank introduced between an agent's
verification and the splice. The BUILD is the batch verdict; a per-TU bank chain (`bank.sh`) made it deterministic.
- **The Haiku band went 17/17 first pass** (13–25 ins, ~50k tokens each, 46–126 s) — the S82 9/11 was an under-estimate
because the two S82 FAILs were plumbing, not model failures. 28 banks in one session, then a 29th from the permuter.
- **The permuter's "1" was two sound levers plus one wrong-width mutation.** Subtracting the unsound hunk left a leaf MATCH;
the lever was the §47 live-length slider (an early BIRTH of a pseudo), re-spelled well-defined. A waypoint carrying a
semantic mutation is a seed, not a rejection (R63 both ways).
- **The `func_800CF3E8` second look corrected a mechanism and refuted a lever** (cse.c `find_best_addr`, not `canon_reg`;
the alias lever 5/5 inert; a new pinned-pointer launder frees the load but lands it 4 slots late) — 245k tokens for a
closeness that did not move, and a citation that is now right.
- **T4: all seven pinned walls reproduce their residual in TU context** — and the three that were CC1 FAILs were
declaration plumbing, re-probed in a SANDBOX TU copy (`.run/P32/t4/tu/`) rather than by byte-neutral commits to `src/`.
1 PROVED (§474) + 6 CANDIDATE, citations current. Nothing changed; everything is now measured where it will be judged.
### The shape, and the hindsight path
Three sessions running (S81, S82, S83) the finding is the same: the last stubs fall to PLUMBING, not codegen — declaration
environments, rodata ownership, TU spellings — and the instruments that judge them (a per-draft compile-only oracle; a
`find src -name '*.c'` that admits a live probe) are the walls' co-authors. Sooner: (1) `rtu_match --batch` from the first
multi-draft TU; (2) the §304 sentence in every drafter brief from the first module wave; (3) a sandbox TU for any CC1-FAIL
re-probe — it costs a `mkdir` and two symlinks and spends no commit; (4) treat a permuter waypoint's diff as a lever list.
What P32 leaves for P33: 15 functions (7 walls with citations, 8 near-misses with cost), every module at 100% C except the
ones those rows sit in, the fleet byte-identical 218/218 on every sweep of the day.
+24
View File
@@ -37119,3 +37119,27 @@ and a build-instrument collision fixed at the consumer.**
* **Map corollary:** for a pinned struct pointer at −O2, "the load through the pinned base is scheduled late while every
store is in place" = `find_best_addr` took the offset-0 address to a pseudo. The zero-byte pointer launder is the
release; where the released load must land is then a scheduling question the launder does not answer.
**I. T4 — the seven pinned walls' FINAL verdicts, every one re-probed IN TU CONTEXT without touching `src/` (S83, 12:05–12:35 MDT).**
* **Method.** Each row's best draft was re-run with `rtu_match` in its CURRENT real TU (S83 had changed `src/800.c` and
`src/800_b_2.c`). Four rows reproduced their recorded closeness directly (`func_80011380` 6 with `--o0`, `func_80020DA4`
2, `func_8017DF28` 2, `func_801834A4` 6 ×3 variants). **Three were CC1 FAILs — and all three were plumbing, none a verdict
(R40):** (1) `func_80032A74`'s draft redefined seven structs the TU provides via `800_shared.h` and spelled four
declarations its own way → `cdecl.strip_provided_typedefs(draft, cdecl.typedef_names(tu))` + adopt the TU's four lines →
DIFF 1 in the real TU, the recorded `lh`/`lhu` residual; (2) `func_80039DEC`'s TU carries a narrow-typed PROTOTYPE
(`extern void f(void *, s16, u8)`) that C forbids against a K&R definition; (3) `func_800391D4`'s lever spelling
`extern s32 D_80073140[][1]` conflicts with the TU's three `[]` externs — and the `[][1]` TYPE is load-bearing (the TU's
spelling, a `(s32 (*)[1])` cast and a byte-offset form all regress 3 → 65 @ 76 ins). **For (2) and (3) the re-probe used a
SANDBOX TU: copy the TU under `.run/P32/t4/tu/`, symlink `src/*.h` + `src/shared` beside it, edit the declaration there,
and pass `--tu <copy>`** — the residual reproduces (2 and 3) with zero edits to `src/`, and no byte-neutral commit is
spent on a row that will not bank. The TU-side edits are recorded in the backlog rows for the day closeness reaches 0.
* **Verdicts.** `main:func_80011380` **PROVED** (§474, fold-const.c:882 `split_tree` + stupid.c:497, `--o0`; DIFF 6). Six
**CANDIDATE** with current citations and bounded attempt records: `func_80032A74` 1 (extendhisi2 force_not_mem / §172
producer 3, reload1.c:1445) · `func_80020DA4` 2 (mflo destination REGALLOC-PERM; pins regress to 79) · `func_80039DEC` 2
(K&R narrow-parameter argument-position promotion → `$a3`/`$t0` before global-alloc) · `func_800391D4` 3 (`move_movables`
splices hoisted invariants after preheader flow code, loop.c 2.7.2:1529 / map loop.md L4) · `ov_SC06_022:func_8017DF28`
2 (`expand_block_move` `copy_addr_to_reg` pseudo cse-reused, cse_expr.md [A23-2]) · `ov_SC03_105:func_801834A4` 6
(loop.c movable ordering). No verdict changed; the pin file (`config/wave_exclude.txt`) carries each row's S83 re-probe
line; `exclude_audit --assert-fresh` 7/7. Unpinned candidate with a cited mechanism: `md_MAIN_003:func_800CF3E8` 27 (§500-H).
* **Law.** A wall's CC1 FAIL in its TU is evidence about the TU's declaration environment, never about the body; re-probe
before any verdict, and prefer a sandbox TU over a src/ edit when the row is not going to bank.
+48 -25
View File
@@ -94,7 +94,7 @@ Scale estimate: 3–5 sessions.
(`parallel_gate --r22` / main: `gate_main <slate> --apply`, read the BODY/TABLE/PLUMBING/MIXED line) →
commit per bank (R42) → `twin_rescan`; plateaus → `backlog.py log` with attempt + cost (R41).
Expected 1–4 banks (S79: 3/11 on the Opus F/G tier), ~0.6–1.4M tokens. **Progress report after T3.**
- [ ] **T4 — the walls' FINAL verdicts** (xHigh; no drafting): the 8 pinned rows — confirm each citation current
- [x] **T4 — the walls' FINAL verdicts** — DONE 2026-09-05 (S83, xHigh, no drafting): all 7 pinned rows re-probed IN TU CONTEXT (`rtu_match` in the real TU; the three CC1-FAIL rows via a sandbox TU copy under `.run/P32/t4/tu/` — every CC1 FAIL was plumbing, R40) and every one reproduced its recorded residual: **1 PROVED** (`main:func_80011380` §474, DIFF 6) · **6 CANDIDATE** with current citations (`func_80032A74` 1 · `func_80020DA4` 2 · `func_80039DEC` 2 · `func_800391D4` 3 · `ov_SC06_022:func_8017DF28` 2 · `ov_SC03_105:func_801834A4` 6). No verdict changed. Deliverables: the wall table below; `config/wave_exclude.txt` annotated per row, `exclude_audit --assert-fresh` 7/7; backlog rows for all 7 (the two path-less rows given existing drafts, R62; `func_80032A74` got a TU-clean synced draft `.run/P32/t4/drafts/func_80032A74_tuclean.c`); cookbook **§500-I**; `docs/accelerators.md` (8); decision-log (the final wall doctrine, R31). Original brief: the 8 pinned rows — confirm each citation current
+ instrument exonerated (R40), PROVED vs CANDIDATE, ledger best-draft → an existing real-TU-clean C file (R62:
`func_80011380` → `.run/m3/opus/func_80011380.c`; `func_801834A4` → `.run/S71_gate14/ov_SC03_105*/`),
`exclude_audit --write`, `backlog.py render`; a T3 idiom naming a wall's mechanism re-opens that row
@@ -105,6 +105,20 @@ Scale estimate: 3–5 sessions.
for gate 2**; `PhaseEnd_Phase32.md` (+ Roadmap delta + Plain-English Recap); `git mv` this file →
`phase-ends/logs/Phase32.md` (R19); R23 MCP stop if it ran; leave both uncommitted for Drew (R6); 🛑 (P8).
## T4 — the walls' FINAL ledger (S83, 2026-09-05; every row re-probed in TU context; `config/wave_exclude.txt` carries the same lines)
| row | ins | class | closeness leaf / real-TU (S83) | mechanism · citation | bounded attempt record | verdict | best draft |
|---|---|---|---|---|---|---|---|
| main:func_80011380 (boot, −O0) | 192 | C-level floor | 6 / 6 (`rtu --o0`) | fold-const.c:882 `split_tree` merges MULT(MULT(i,2),2); the two escapes each cost one insn (stupid.c:497 adjacency / expand_decl use-brackets) — cookbook §474, §388 −O0 colouring oracle | 20 spellings + statement-expression + `(t=i*2)*2` register form (S76 proof); pinned S79 #8 | **PROVED** | `.run/m3/opus/func_80011380.c` |
| main:func_80032A74 (800_b_2) | 422 | FRAME/WIDTH | 1 / 1 (synced draft) | sole residual idx 244 `lh` vs `lhu`: extendhisi2 is a force_not_mem EXPAND (an orphan frame slot is minted only at an `lh`); the target's +8 frame bytes = §172 producer 3 (caller-save area, reload1.c:1445) | ~200 byte-probes + 100-variant retyping sweep (S79 Opus) + permuter_ils 8×150 s null (S80); S83: CC1 FAIL was 7 header typedefs + 4 decl spellings → synced copy DIFF 1 | CANDIDATE | `.run/P32/t4/drafts/func_80032A74_tuclean.c` |
| main:func_80020DA4 (800) | 100 | REGALLOC-PERM | 2 / 2 | phantom 16-byte frame reproduced (address-taken `frame_pad[3]`); residual = `mflo` destination `$t0` vs `$a2`; pinning regresses to 79 | 5 attempts 51→20→14→8→2 (S7x/S79) + permuter_ils null (S80); S83 rtu DIFF 2 | CANDIDATE | `.run/S79w/sonnet/func_80020DA4.c` |
| main:func_80039DEC (800_c) | 74 | REGALLOC (K&R) | 2 / 2 (sandbox TU, no-proto decl) | the `$a3↔$t0` swap of the two K&R raw-preserve parameter copies is fixed by ARGUMENT POSITION in gcc-2.7.2 narrow-parameter promotion (2nd → `$a3`, 3rd → `$t0`) before global-alloc; every pin regresses to 60–75 (cookbook §376/§495 K&R laws, lines ~1320/1508) | 3 attempts (S7x/S79 Sonnet 9) + permuter_ils 9→2 (S80); S83: CC1 FAIL = the TU's narrow prototype at 800_c.c:3496 vs the K&R def | CANDIDATE | `.run/S79w/permuter/func_80039DEC.c` |
| main:func_800391D4 (800_c) | 75 | SCHED (loop) | 3 / 3 (sandbox TU, `[][1]` externs) | 3-insn SCHEDULE-REORDER (`off` init vs arg1's `sll/sra`): `move_movables` splices hoisted invariants after any pre-existing preheader flow code (loop.c 2.7.2:1529; map loop.md L4) | 4 prior + S79 Sonnet 64→3 (`i=$7` pin kills combine_givs, `D_80073140[][1]` decl, 7 `asm("")` pads) + permuter_ils null (S80); S83: the `[][1]` spelling is load-bearing (TU-compatible forms → 65 @ 76) | CANDIDATE | `.run/S79w/sonnet/func_800391D4.c` |
| ov_SC06_022:func_8017DF28 (jr_8017BEBC) | 119 | SCHED (slot) | 2 / 2 | `expand_block_move` `copy_addr_to_reg` pseudo cse-reused for both later `&mtx` args (map cse_expr.md [A23-2]/§H); `addiu $s2,sp,0x10` in the jal delay slot vs the target's bnez slot | five RTL-verified attempts (S71/S79); permuter_ils "1" was a divergent rewrite (S80, R63); S83 rtu DIFF 2 | CANDIDATE | `.run/S79w/sonnet/func_8017DF28.c` |
| ov_SC03_105:func_801834A4 (jr_80181C84) | 106 | SCHED (loop) | 6 / 6 (×3 variants) | loop.c movable ordering (S71) | S71 gate14 resolver variants cn-cast / -rc / -rc-sd all DIFF 6; S83 rtu DIFF 6 ×3 | CANDIDATE | `.run/S71_gate14/ov_SC03_105-cn-cast-rc-sd/func_801834A4.c` |
| *(unpinned)* md_MAIN_003:func_800CF3E8 | 469 | ALIAS-BASIN | 27 / 27 | cse.c `find_best_addr` (fold_rtx MEM; COST pseudo 0 vs hard reg 1) swaps the bare-REG tag-load address to a pseudo; the alias lever refuted 5/5; the pinned-pointer launder frees the load but lands it 4 slots late (79 @ 470) — §500-H | S79/S82 Opus + S83 Opus second look (245k tokens, ~16k compiles) | CANDIDATE (backlog, not pinned) | `.run/P32/t3/opus/func_800CF3E8.c` |
The other 7 NEAR rows (`func_80039308` 17, `func_800CD674` 2, `func_800CD92C` 15, `func_800CF408` 49, `func_800CF6D0` 137, `func_80185810` 35, `func_8017DC80` 46) are DEFERRED WITH COST in `docs/backlog.md` (class · closeness · best draft · agent/permuter cost), per the milestone's third disposition.
## Standing procedure (every task)
Fix the TU by a byte-neutral plumbing commit BEFORE any gate (S77 law) · commit banked work before the next
command that can touch `src/` (R42) · after any bank: `twin_rescan`, `verbatim_check --strict` (R62) · after a
@@ -120,6 +134,7 @@ cookbook before the next drafting step (R16/R30) · no `Co-Authored-By` trailer
needed for T0–T2b; if T2d needs it: `tools/ghidra_mcp_start.sh` → pause → Drew runs `/mcp` (R29) → G2 ping.
## Log
- 2026-09-05 12:05–12:40 MDT (S83, continued) — **T4 DONE.** Preflight: tree clean, verbatim 5==5, R22 218/218 (12:00), `exclude_audit --assert-fresh` 7/7. Every pinned wall's best draft re-run with `rtu_match` in its CURRENT real TU: `func_80011380` DIFF 6 (`--o0`), `func_80020DA4` DIFF 2, `func_8017DF28` DIFF 2, `func_801834A4` DIFF 6 ×3 variants; the three CC1-FAIL rows re-probed after their plumbing was understood — `func_80032A74` (7 TU-provided typedefs + 4 decl spellings → `cdecl.strip_provided_typedefs` + the TU's lines → DIFF 1 in the real TU), `func_80039DEC` and `func_800391D4` (a sandbox TU copy under `.run/P32/t4/tu/` with the declaration edited THERE → DIFF 2 / DIFF 3) — no `src/` edit, no byte-neutral commit spent on rows that will not bank. Leaf `match_one` re-measured all three (1 / 2 (permuter) / 3). **No verdict changed: 1 PROVED (§474) + 6 CANDIDATE**, citations current (§474, §172 reload1.c:1445, loop.md L4 2.7.2:1529, cse_expr.md [A23-2], the K&R promotion laws). Deliverables: the wall table (above), `config/wave_exclude.txt` per-row S83 lines, backlog rows for all 7 (+ the two path-less rows fixed, R62; `docs/backlog.md` 16 open), cookbook §500-I, accelerators (8), decision-log. NEXT = **T5 (Max, Tier 1 — prompt R27, WAIT for gate 2)**.
- 2026-09-05 11:30–12:30 MDT (S83, continued) — **T3 steps 8–9 DONE → T3 CLOSED.** Step 8: `permuter_ils` 8×150 s -j3 on the two REGALLOC-PERM seeds — `func_800CD674` plateau (best waypoint = the same 2-row `$a3↔$t1` pair; ledgered with cost), `func_8001BC6C` reached masked 1; the R63 read showed three mutations, one of them a WRONG-WIDTH `& 0xFF` (lhu→lbu); the two sound ones (idx after color; an early `tag`/`k` birth) = leaf MATCH, re-spelled well-defined as `k = 0; tag = (a1 << 8) | k;` (11 spellings measured), rtu MATCH in src/800.c, **gate_main BANKED 143dbb89** (`commit:3948`) — main 7 → 6 open. gate_main's first rebuild died on a concurrent agent's `src/.masked_diff_probe.<pid>.c` (present at parse, gone at compile) → **Makefile `C_SRCS` find now `-not -name '.*'`** (`commit:3949`, byte-neutral, control on `make -pn`). One bounded Opus second look at `func_800CF3E8` (245k tokens, 29 min): 27 holds; §500-D1's mechanism corrected to `cse.c find_best_addr` (fold_rtx MEM; COST pseudo 0 vs hard reg 1), the alias lever refuted 5/5, a new zero-byte pinned-pointer launder found (79 @ 470, structurally closer) — cookbook **§500-H**, backlog row updated. Step 9: `make report` (fleet instr 100.0% · distinct 99.9% · fn 100.00% · 15 stubs), `make report BINARY=main`, census `.run/P32/frontier_t3_close.json` (15 / 3,758), twin_rescan 0 free, cookbook §500-G/H + index, this file; R22 → see the 🛑 block. **Kill gate:** the session banked 29 and produced 3 new verdicts; the tail's three bounded attempts are spent — T3 closes on the evidence. NEXT = T4.
- 2026-09-05 10:10–11:25 MDT (S83, session 491895ad, xHigh, Fable 5.1) — **T3 steps 0–7 DONE: 28 banks, fleet R22 218/218 twice.** Preflight R22 218/218 rc 0 (`.run/P32/t3s3/r22_check.log`) → the 11 S82 MATCH rows banked: md_SC03_053 ×2 (`commit:3935` `commit:3936`, 100% C) · main ×2 via gate_main (`commit:3937`: "slate 2 -> 2 compatible … BANKED 2 … 143dbb89 BYTE-IDENTICAL") · md_SC03_054 func_801EF6D8 604+7 jtbls (`commit:3938`; `jtbl_carve --probe` refused the tail carve → §303 derive stage reproduced the island pads `0,0t1,0t1,0t1,0t1,0t1,0` with NO carve state change) · md_MAIN_007 ×6 after the byte-neutral func_800CF3B0 no-proto decl commit (`commit:3939`, `commit:3940`) — two integration classes on the way (same-TU s16/u16 spelling of D_800B99E8; §304 self-defining rodata D_800CEDFC). twin_rescan 33 open / 0 free; verbatim 5==5; **R22 `make clean && make extract-all && make check-all` → 217+main extracted, 218 passed / 0 failed, exits 0/0/0** (`.run/P32/t3s3/r22_full.log`, 10:41–10:46); tools-health OK. The 9 NEAR rows ledgered (`backlog_near.sh`; docs/backlog.md 15 open). **17 Haiku agents launched 10:57 from staged prompts (`.run/P32/t3s3/prompts/`), 17/17 MATCH by 11:15**, each re-verified with rtu_match in the CURRENT TU and banked by `bank.sh` (verbatim grep → rtu → splice → one build → sha → commit-on-green): md_MAIN_007 ×6 (`commit:3941` `commit:3942`), md_MAIN_009 ×8 (`commit:3943` `commit:3946` — func_800CD520 needed a §376 re-spell after a sibling bank added the file-scope prototype), md_SC03_054 ×2 (`commit:3944`, 100% C), md_SC03_056 ×1 (`commit:3945`, 100% C). twin_rescan 16 open / 0 free. Harvest: cookbook **§500-F** (the four integration classes), BRIEF.md §304 sentence, `jtbl_carve --probe` text, harvest_notes. Post-batch R22 (after all 28 banks): 217+main extracted, **218 passed / 0 failed, exits 0/0/0** (`.run/P32/t3s3/r22b_full.log`, 11:04–11:09).
- 2026-09-05 (successor session, later) — **Session-start protocol rewritten at Drew's direction (R64 candidate):** `phase-ends/DIGEST.md` created (every phase synopsis + every rule in full + the PROJECT_CONTEXT corrections + the doc map); CLAUDE.md load order = PROJECT_CONTEXT → DIGEST → the three most recent PhaseEnds → CURRENT_PHASE, ≈100k tokens, the 🛑 block replayed VERBATIM; Phase Boundary step 3b maintains the digest (P7); `phase-ends/README.md` + SETUP §7 updated; the two memories (`checkpoint-current-phase-before-pause`, `session-start-list-rules-in-full`) + MEMORY.md updated; `.run/P32/t3/PROMPT_TEMPLATE.md` saved (verbatim agent prompts). The 🛑 block below was REFRESHED to the verbatim-replay standard and SUPERSEDES the 09:30 block. Ratify R64 at PhaseEnd_Phase32.
@@ -132,15 +147,15 @@ cookbook before the next drafting step (R16/R30) · no `Co-Authored-By` trailer
- 2026-09-05 — **T1a DONE — `resident:func_800D128C` BANKED (243 ins, byte-identical 8e17e02f, R22 213/213).** The stored S71 closeness-0 draft was byte-correct all along; the whole task was three instrument defects the resident (the fleet's one `common.h`-only, `--pre`-sandwich binary) exposed in overlay-only assumptions: (1) `jr_isolate_all` dropped a file-local typedef whose name engine_types.h also defines (§496 — fixed: provided types derived from the TU's own includes); (2) `jtbl_carve` regenerated `JTBL_INTERLEAVE` without the `--pre hdr.rodata.o` clause → extract refused → the gate linked a stale script and booked the byte-correct draft as DIFF; `harvest_verify` ignored that extract's rc (§498 — both fixed, R49/R61); (3) `interleave_check` read a `--pre` line as n=0 (false DRIFT; fixed). R38 then found two more stored MATCH bodies for T1b/T1c (see their rows). Effort stayed Max.
- 2026-09-05 — **T0 DONE.** Baseline reads all green (`.run/P32/t0_baseline.log`): `verbatim_check --strict` 5 bodies == 5 rows; `exclude_audit --assert-fresh` 8 entries, 8 WALL, 0 stale; `frontier_classify` → 21 rows = the S80 census exactly; `make tools-health` OK (sigs fresh, corpus(+resident), cdecl, audit-binaries 213/213, report lint+dedup, cookbook-index, split_indicator 213 OK); `make check-all` 213 passed / 0 failed, rc 0. Harness task list #1–#11 built (R28). NEXT = T1a.
## 🛑 SESSION CHECKPOINT — T3 CLOSED, T4 NEXT (2026-09-05 12:40 MDT; written by session 491895ad "S83"; SUPERSEDES the 11:30 block)
## 🛑 SESSION CHECKPOINT — T3 + T4 DONE, T5 (PhaseEnd) NEXT (2026-09-05 12:45 MDT; written by session 491895ad "S83"; SUPERSEDES the 12:40 block)
### 0. How to use this block
You are a FRESH SESSION that has read `PROJECT_CONTEXT.md`, `phase-ends/DIGEST.md`, `PhaseEnd_Phase29/30/31.md` and this
file, and nothing else (CLAUDE.md protocol, R64 candidate). Replay this block verbatim into your chat, state phase / done /
NEXT / effort, list the rules from the digest, then WAIT for Drew. When he confirms, follow §4 in order. **Effort: xHigh for
T4** (R27 — Drew sets it; if the status line does not say xHigh, prompt before the first command); **Max only for T5**
(prompt R27 at the T4→T5 hand-off). T4 is NO-DRAFTING work: verdicts, citations, ledger hygiene. Fable only if a wall class
the codegen map lacks appears — STOP and prompt Drew first. No Workflow / Ultracode.
NEXT / effort, list the rules from the digest, then WAIT for Drew. **NEXT is T5 — the PhaseEnd — a Tier 1 task: state
"🟡 PhaseEnd creation is a Tier 1 task. Confirm effort: Max is set" (R27) and WAIT for the actual `/effort` before the
first command.** Then follow §4. T5 has TWO stops: the milestone demo → **WAIT for gate 2** (Drew confirms) → the
PhaseEnd file → 🛑 (P8). No drafting, no agents, no Workflow.
### 1. Where we are
**Phase 32 — the last 21 + the parked 5 (short, kill-gated).** Gate 1 approved 2026-09-05 (Drew, plan mode, Max, Fable 5.1);
@@ -149,8 +164,8 @@ R44–R63 ratified then; R64 is a candidate (DIGEST §3). Tasks: **T0 ✓** `com
`commit:3912` `commit:3913` `commit:3914` (fleet 213 → 218) · **T2c ✓** `commit:3917` `commit:3918` `commit:3919` `commit:3920`, close
`commit:3921` · **T2d not needed** · **T3 ✓ CLOSED 2026-09-05 12:40 MDT** (launch `commit:3922`; banks 1–9 `commit:3923`..`commit:3931`;
S82 checkpoints `commit:3932` `commit:3933` `commit:3934`; S83 banks 10–38 `commit:3935`..`commit:3946` + `commit:3948`; S83 checkpoint
`commit:3947`; Makefile guard `commit:3949`; §500-G `commit:3950`; the T3-close commit = HEAD) · **T4 NEXT · T5 pending.** Harness
task list #1–#12 (#10 done at the close commit; #11 = T4 next). Fleet **218 binaries** (main + resident + 138 `ov_*` + 78
`commit:3947`; Makefile guard `commit:3949`; §500-G `commit:3950`; the T3-close commit = HEAD) · **T4 ✓ DONE 12:45 MDT** (the walls' final ledger — 1 PROVED + 6 CANDIDATE, all re-probed in TU context, no verdict
changed; the T4 commit = HEAD) · **T5 NEXT.** Harness task list #1–#12 (#11 done; #12 = T5 next). Fleet **218 binaries** (main + resident + 138 `ov_*` + 78
`md_*`). **Fleet R22 at the T3 close (after ALL S83 banks + the Makefile guard): **217+main extracted, 218 passed / 0 failed, exits 0/0/0 at 12:00 MDT**** (`.run/P32/t3s3/r22c_full.log`);
earlier S83 R22s 218/218 at 10:46 and 11:09. `make report` at the close: **instr 13,484,739 / 13,488,497 = 100.0% · distinct
5,812,831 / 5,816,589 = 99.9% (90,975 / 90,984 unique fns) · fn-count 363,199 / 363,214 = 100.00% · INCLUDE_ASM 15**; main:
@@ -194,22 +209,30 @@ Modules at 100% C after S83: resident (145/145), md_SC03_053, md_SC03_054, md_SC
launching session (§500-A) + S83's 29 (`git log --oneline commit:3934..HEAD`). Backlog: `docs/backlog.md` 14 open near-misses
(every NEAR row carries class · closeness · best draft · cost, R41). `verdicts.jsonl`: 50 rows.
### 4. NEXT — T4 then T5 (R42 still binds: any bank that lands commits before the next command that can touch src/)
0. **Preflight:** `git status --short | grep -v ghidra/` (empty) · `.venv/bin/python tools/verbatim_check.py --strict` (5 == 5)
· `make check-all` → **218 passed, 0 failed of 218, exit 0** (R56 baseline) · `exclude_audit --assert-fresh` (7 entries, 7 WALL).
1. **T4 — the walls' FINAL verdicts (xHigh, NO drafting; one bounded permuter-first attempt only where a T3 idiom names a
wall's mechanism):** for each of the 7 pinned rows (`config/wave_exclude.txt`): (a) re-run its best draft in the REAL TU
with `rtu_match` (main: `--tu src/<sub>.c`) and record the verdict line; (b) for the THREE CC1-FAIL rows (`func_80032A74`,
`func_80039DEC`, `func_800391D4`) fix the §376/§495 plumbing FIRST by a byte-neutral commit (the TU's own declaration;
`fix_arity_callers` / `cast_self_callers` / `--sync-decls` chain) and re-probe — a CC1 FAIL is not a wall verdict (R40);
(c) classify PROVED (a gcc-mechanism citation the codegen map carries + an instrument-exonerated bounded attempt) vs
CANDIDATE (citation present, attempt record bounded) — cite `docs/gcc-2.7.2-map/` + the cookbook §; (d) fix the two dangling
ledger best-draft paths (R62: `func_80011380` → `.run/m3/opus/func_80011380.c`; `func_801834A4` → the S71_gate14 variant) via
`tools/backlog.py log … --draft <existing path>`; (e) `exclude_audit --write`, `backlog.py render`; (f) the wall table into
this file (row · ins · class · closeness · citation · attempt record · PROVED/CANDIDATE), cookbook §501 if any verdict
changed, `docs/decision-log.md` (R31: the final wall doctrine), `docs/accelerators.md`; commit per row-batch; refresh this
block. Also consider `func_800CF3E8` (§500-H) for the CANDIDATE-wall ledger with its mechanism — it is NOT pinned; T4 decides.
2. **T5 (Max, Tier 1 — prompt R27; WAIT for gate 2)** — §6 below.
### 4. NEXT — T5, the PhaseEnd (Max, Tier 1 — prompt R27 FIRST; WAIT for gate 2)
0. **Preflight (read-only):** `git status --short | grep -v ghidra/` (empty) · `.venv/bin/python tools/verbatim_check.py --strict`
(5 == 5) · `exclude_audit --assert-fresh config/wave_exclude.txt` (7 entries, 7 WALL).
1. **P7 checkbox walk** over T0–T4 in this file (every `[x]` row has its commits/logs cited; T2d is NOT NEEDED, say so).
2. **Milestone demo — run and QUOTE (P9/R58):** `make clean && make extract-all && make check-all` → 218 passed / 0 failed,
exits 0/0/0 · `make tools-health` → OK · `verbatim_check --strict` 5 == 5 · `.venv/bin/python tools/frontier_classify.py --json
.run/P32/frontier_p32_final.json` → the final census (15 rows: 7 pinned walls + 8 NEAR; every row with class · closeness ·
best draft · mechanism/cost) · the wall ledger table (this file, "T4 — the walls' FINAL ledger") · parked-5 dispositions:
`make audit-disc` → UNCLAIMED 0 of 220 (all five onboarded at T2b; `docs/disc-completeness.md` P32 section) · `make report`
→ the three fleet metrics (T3-close values: instr 13,484,739 / 13,488,497 = 100.0% · distinct 5,812,831 / 5,816,589 = 99.9%
· fn-count 363,199 / 363,214 = 100.00% · 15 stubs) · `make report BINARY=main` → REAL 783 · LINKED 1,256 · VERBATIM 3 · stubs 6
· 2,085 / 2,091 = 99.71% · `143dbb89…` **WITH and WITHOUT the SDK object dirs** (`.run/obj40`, `.run/obj42` — the
fresh-extract fallback: move them aside, `make extract BINARY=main && make build BINARY=main`, sha, move back) · corrected
denominators (main game-code 41,556 — the 22-ins Ghidra-boundary gap; the fleet denominator grew by the five modules'
~2,600 ins at T2b). Present all of it to Drew and **WAIT for gate 2.**
3. **On confirmation:** `phase-ends/PhaseEnd_Phase32.md` in the constitution's format (Build Log · Deviations · Commit
Message · Rules Added — R64 to RATIFY, plus any candidates from S82/S83: the sandbox-TU re-probe law, "the build is the
batch verdict" · PhaseEnd Changelog v1.30.0 → v1.31.0 · Roadmap delta: P33 = verify + public flip, the 15-row remainder
stated, not redefined · Plain-English Recap · What we believed / what failed / what we would do sooner · 🛑 Stop Here)
→ **append the P32 synopsis + rules to `phase-ends/DIGEST.md` §2/§3 (step 3b, P7)** → `git mv phase-ends/CURRENT_PHASE.md
phase-ends/logs/Phase32.md` (R19) → R23: the headless Ghidra MCP the SessionStart hook launched (`.run/ghidra-mcp.log`) is
stopped (`tools/ghidra_mcp_stop.sh` or the SessionEnd hook; no RE writes this phase — never stage `ghidra/`) → leave the
PhaseEnd + the archived log UNCOMMITTED for Drew (R6) → final message "PhaseEnd file created. Commit the file and start a
new Claude Code session for the next phase." → HARD STOP (P8).
### 5. Files, tools, exact invocations, gotchas
- **`.run/P32/t3s3/` (S83; tracked: `*.sh *.py *.log *.txt prompts/ gate/*.json gate/*.log`; untracked: `verify*/` compile
@@ -240,7 +263,7 @@ launching session (§500-A) + S83's 29 (`git log --oneline commit:3934..HEAD`).
make extract-all` is in flight · the harness cap is 20 concurrent subagents · never `cd` inside a compound command ·
`set -o pipefail` + `grep -c` exits 1 on zero matches.
### 6. Carried context for T4 and T5
### 6. Carried context for T5 (T4 is DONE — its ledger is the table above this block)
**T4 (xHigh, no drafting) — the dead session's read-only pre-check (07:00Z) still stands (re-run each in the CURRENT TU first — S83 changed src/800.c and src/800_b_2.c):** `exclude_audit --assert-fresh`: 7
entries, 7 WALL, 0 stale. Best drafts in their REAL TU: `main:func_80011380` `.run/m3/opus/func_80011380.c` DIFF 6 (the
ledger's `.run/backlog_drafts/func_80011380.c` is MISSING — R62 path fix) · `main:func_80032A74` `.run/S79w/opus/