docs(cookbook): S66 harvest — 4 NEW sections, 15 addenda, 1 refutation

Distilled from 35 wave transcripts (12 byte-proven, 23 drafted-but-ungated and marked UNPROVEN),
each extracted then adversarially novelty-verified against the book. 57/57 agents, 0 errors.
Verdicts: 4 NEW, 15 ADDENDUM, 6 COVERED (rediscoveries — the signal to fix RETRIEVAL, not to write
more prose), 1 REFUTED.

The NEW laws:
  §315  all-constant aggregate fill emits in SHARED-LITERAL GROUPS x destination order
  §316  IMM-OFFSET-only residual: early "return 0" guards skip the flag test
  §317  a narrow struct-field store distributes the truncation (convert.c convert_to_integer
        trunc1), minting a HImode copy whose source cse rewrites to the equivalent constant --
        so a LIVE variable becomes an immediate load. Fix: route the arithmetic through a FRESH
        s32 temp. Byte-proven func_8017EF94 (293->292 ins, closeness 73 -> MATCH); the control
        that reused an EXISTING scratch var regressed to 63, so freshness is the lever.
  §318  a unary minus stored back into the same halfword is computed in HImode (lhu)

Notable addendum: §167-12's own scope note asked for a byte-proven instance of the single-operand
volatile keepalive; func_8017F498 supplies it (closeness 2 -> MATCH, 99 ins), and extends the tell
from unary ops to a three-operand non-commutative subu whose dest ties its PINNED source.

This is the step I skipped for eight waves. Drew: harvesting is the project thesis, not hygiene --
new idioms make the next exemplars cheaper and mint free banks.
This commit is contained in:
Drew T
2026-08-30 14:41:30 -06:00
parent 45cf37ee02
commit a1024ab76d
2 changed files with 371 additions and 12 deletions
+81 -12
View File
@@ -2,7 +2,7 @@
> **Generated by `tools/cookbook_index.py` — do not hand-edit** (R33). Regenerate after adding a cookbook section.
>
> `docs/matching-cookbook.md` is ~716 KB / 922 sections. Grepping it blind is how three P30 wave-1 agents each "discovered" an idiom that was already written down. **Start here, then read the section.** A section appears under every symptom it addresses.
> `docs/matching-cookbook.md` is ~716 KB / 942 sections. Grepping it blind is how three P30 wave-1 agents each "discovered" an idiom that was already written down. **Start here, then read the section.** A section appears under every symptom it addresses.
**How to use:** name what you SEE in the diff (a stolen delay slot, an extra `la`, a swapped register pair, a `conflicting types` error), find that symptom below, read those sections first. If nothing fits, THEN grind — and add a section when you win.
@@ -34,7 +34,7 @@
## By symptom
### delay slots & branches (53)
### delay slots & branches (54)
- **§3-T4** — Branch polarity: invert the source condition to flip gcc's chosen branch <sub>L90</sub>
- **§5a** — Cross-jump tail-merge — gcc collapses two byte-identical blocks the original kept separate (FIX FOUND) <sub>L211</sub>
@@ -89,8 +89,9 @@
- **§309** — A FRAME-ADDRESS EQUIVALENCE RIDES *THROUGH* A SKIPPABLE CONDITIONAL: POST-`if` STORES FOLD ONTO `$sp` UNLESS THE `if` SURVIVES jump1 AS A BARRIER-PRECEDED DIAMOND (P31 S63 t5e-t5i; byte-proven func_801812AC) <sub>L30046</sub>
- **§311** — A JOIN-BLOCK STORE CAN SWALLOW AN ARM'S LOAD-DELAY `nop`: WHEN ONE ARM'S VALUE COMES FROM A LOAD, DUPLICATE THE STORE INTO BOTH ARMS (P31 S64 t5j-t5m; byte-proven func_8017D7E0) <sub>L30117</sub>
- **§314** — AN IF/ELSE-IF ABS-RANGE CHECK'S C SPELLING IS INERT: FOUR STRUCTURALLY DIFFERENT REWRITES ALL COMPILE BYTE-IDENTICAL, AND NONE REACHES A TARGET THAT SINKS THE NEGATIVE ARM INTO AN OUT-OF-LINE BLOCK (P31 S65; UNPROVEN, gate-refused draft func_80181720) <sub>L30241</sub>
- **Addendum** — A §5a BARRIER SITS IN REORG'S FILL WINDOW TOO, SO ITS SIDE OF THE INNER `goto` IS CHOSEN P (func_80181D08) <sub>L30489</sub>
### instruction scheduling (60)
### instruction scheduling (65)
- **§3-T2** — Source statement order drives instruction scheduling <sub>L78</sub>
- **§3** — When a diff is pure scheduling → decomp-permuter (harness built, Phase 6) <sub>L107</sub>
@@ -152,8 +153,13 @@
- **§307** — THE BRUTE-FORCE-THE-STATEMENT-ORDERS LEVER HAS A BOUND: A FAN-OUT COPY'S PRIORITY IS SCHEDULER-INTERNAL, AND NO SOURCE ORDER REACHES IT (P31 S63; byte-evidenced NEGATIVE result, main wave) <sub>L29939</sub>
- **§309** — A FRAME-ADDRESS EQUIVALENCE RIDES *THROUGH* A SKIPPABLE CONDITIONAL: POST-`if` STORES FOLD ONTO `$sp` UNLESS THE `if` SURVIVES jump1 AS A BARRIER-PRECEDED DIAMOND (P31 S63 t5e-t5i; byte-proven func_801812AC) <sub>L30046</sub>
- **§314** — AN IF/ELSE-IF ABS-RANGE CHECK'S C SPELLING IS INERT: FOUR STRUCTURALLY DIFFERENT REWRITES ALL COMPILE BYTE-IDENTICAL, AND NONE REACHES A TARGET THAT SINKS THE NEGATIVE ARM INTO AN OUT-OF-LINE BLOCK (P31 S65; UNPROVEN, gate-refused draft func_80181720) <sub>L30241</sub>
- **Addendum** — A §5a BARRIER SITS IN REORG'S FILL WINDOW TOO, SO ITS SIDE OF THE INNER `goto` IS CHOSEN P (func_80181D08) <sub>L30489</sub>
- **Addendum** — Loop sentinel wrongly hoisted out of a call-containing loop (func_801835B0) <sub>L30493</sub>
- **Addendum** — REGALLOC-PERM: one memory-clobber barrier insufficient — stack two (func_80182D1C) <sub>L30523</sub>
- **Addendum** — A plain global-RMW triplet is a fillable scheduling window too — zero drift, and the fille (func_800CB058) <sub>L30533</sub>
- **Addendum** — Shared arithmetic that CONSUMES the selected value cannot be hoisted above the `if` — narr (func_80183DA0) <sub>L30537</sub>
### register allocation & pins (104)
### register allocation & pins (109)
- **§10** — Closing the regalloc/scheduling hard tail by hand (LZSS, Phase 7 session F — the full close) <sub>L854</sub>
- **Residual** — A — commutative `|`/`&`/`+` result lands in the wrong source-operand register <sub>L875</sub>
@@ -259,8 +265,13 @@
- **ADDENDUM** — to §282 — the ADDRESS-GIV face: write the walked address INLINE so strength reduction births the induction register at loop.c's own insertion point <sub>L29313</sub>
- **§310** — A TWO-OPERAND `subu`'s DESTINATION TIES ONLY TO THE OPERAND THAT IS BLOCK-LOCAL: SHARE *ONE* SIDE ACROSS BLOCKS TO CHOOSE WHICH OPERAND'S REGISTER IT LANDS IN (P31 S64 t5j-t5m; byte-proven func_8017F578) <sub>L30086</sub>
- **§312** — A BARE RELATIONAL IN AN `if` GIVES THE `slt` NO TARGET: ASSIGN THE COMPARISON INTO THE ALREADY-ALLOCATED VARIABLE TO CHOOSE ITS DESTINATION REGISTER, AT ZERO INSTRUCTION COST (P31 S64 t5o-t5r; byte-proven func_80180DCC) <sub>L30159</sub>
- **Addendum** — §312 addendum — naming the compare's dest is the vehicle, the hard-reg pin on that name is (func_80184A68) <sub>L30461</sub>
- **Addendum** — subu/sh dest reuses a pinned operand's dying register (func_8017F498) <sub>L30465</sub>
- **Addendum** — Addendum to §312 — the compare's named destination must itself carry a hard register: nami (func_80184A68) <sub>L30481</sub>
- **Addendum** — REGALLOC-PERM: one memory-clobber barrier insufficient — stack two (func_80182D1C) <sub>L30523</sub>
- **REFUTED** — claim — Dead call-arg register address-fold: no C-level lever found (func_8017ECAC) <sub>L30541</sub>
### CSE / redundancy / rematerialization (28)
### CSE / redundancy / rematerialization (30)
- **§46** — The `func_80178D40` crack (890 ins ×134, the heaviest core in the game): four LOOP-STRUCTURE levers cheap-Opus found by reading loop.c/jump.c/cse.c (Phase 26 session 8, 2026-07-13) <sub>L3347</sub>
- **§83d** — CSE's quantity budget is WHOLE-FUNCTION, so a local rewrite cannot fix a local symptom <sub>L6486</sub>
@@ -290,8 +301,10 @@
- **ADDENDUM** — to §22 (`volatile`-qualified-global reload lever, cookbook ~L1922) — for a NON-constant, same-address double RMW, a plain memory clobber beats `volatile`, and `volatile` actively breaks a delay-slot fill <sub>L27226</sub>
- **§302** — A RED BINARY IS A DRIFTED SPEC, NOT A MYSTERY: THE THREE CARVE-STATE INVARIANTS AND HOW TO DERIVE EACH FROM THE BYTES (P31 S62 T2; five reds healed in one session, 5/5, +39 held banks) <sub>L29719</sub>
- **§308** — A NAIVE FINAL `goto` DELETES THE TARGET'S `j`+`nop`: SPELL THAT EDGE AS A TAUTOLOGICAL `if` SO cse FOLDS IT TO AN UNCONDITIONAL JUMP *AFTER* jump1's WINDOW HAS CLOSED (P31 S63 t5e-t5i; byte-proven func_80180808) <sub>L29983</sub>
- **§317** — A NARROW STRUCT-FIELD STORE TURNS A *LIVE SImode VARIABLE* INTO A `li`: convert.c's TRUNCATION-DISTRIBUTION MINTS A HImode COPY, AND cse REWRITES THAT COPY'S SOURCE TO THE EQUIVALENT CONSTANT (P31 S66; byte-proven func_8017EF94) <sub>L30344</sub>
- **Addendum** — Addendum to §167-12 — the single-operand volatile keepalive, re-confirmed at a gated MATCH (func_8017F498) <sub>L30485</sub>
### loops & induction variables (32)
### loops & induction variables (33)
- **§3-T1** — Loop pointer: top-of-body for `addu` induction, not constant-folded `addiu` <sub>L71</sub>
- **§34** — The `func_80138ED0` giant crack: gcc-2.7.2's **3-qty sort bug** + the **zero-byte asm allocation toolkit** + the **giv-init fence** (Phase 24 T5; Opus→close=21, Fable5→MATCH ×134) <sub>L2473</sub>
@@ -325,8 +338,9 @@
- **ADDENDUM** — to the L1800 anchor-steer bullet — a DERIVED-POINTER local silently flips the merged giv's anchor END <sub>L29357</sub>
- **§297** — ONE GIV SERVING MIXED-WIDTH LOADS *AND* A STORE NEEDS STRUCT-MEMBER SPELLING; CAST/INDEX SPELLINGS RE-SPLIT THE PSEUDO (P31 S61; wave m0a, `func_800347C8`, main, byte-proven 31/31) <sub>L29499</sub>
- **§312** — A BARE RELATIONAL IN AN `if` GIVES THE `slt` NO TARGET: ASSIGN THE COMPARISON INTO THE ALREADY-ALLOCATED VARIABLE TO CHOOSE ITS DESTINATION REGISTER, AT ZERO INSTRUCTION COST (P31 S64 t5o-t5r; byte-proven func_80180DCC) <sub>L30159</sub>
- **Addendum** — Loop sentinel wrongly hoisted out of a call-containing loop (func_801835B0) <sub>L30493</sub>
### structs, block moves & memcpy (72)
### structs, block moves & memcpy (75)
- **§3-T2** — Source statement order drives instruction scheduling <sub>L78</sub>
- **§5** — Known hard-residual classes (instruction-identical, one byte-exact blocker) <sub>L199</sub>
@@ -400,8 +414,11 @@
- **§308a** — A TWO-INSTRUCTION ARM STUB LAID *BEFORE* THE OTHER ARM AND REACHED ONLY BY A TRAILING `j` SURVIVES ONLY BEHIND A SHORT-CIRCUIT `&&` GUARD PLUS A SEPARATE RE-TEST; EVERY PLAIN if/else-if, GOTO-LADDER, NESTED-INVERTED-if AND 1-/2-NODE switch LETS jump1 INLINE IT (−2 ins) (P31 S63 t5e-t5i; byte-proven func_80180808) <sub>L30012</sub>
- **§312** — A BARE RELATIONAL IN AN `if` GIVES THE `slt` NO TARGET: ASSIGN THE COMPARISON INTO THE ALREADY-ALLOCATED VARIABLE TO CHOOSE ITS DESTINATION REGISTER, AT ZERO INSTRUCTION COST (P31 S64 t5o-t5r; byte-proven func_80180DCC) <sub>L30159</sub>
- **§314** — AN IF/ELSE-IF ABS-RANGE CHECK'S C SPELLING IS INERT: FOUR STRUCTURALLY DIFFERENT REWRITES ALL COMPILE BYTE-IDENTICAL, AND NONE REACHES A TARGET THAT SINKS THE NEGATIVE ARM INTO AN OUT-OF-LINE BLOCK (P31 S65; UNPROVEN, gate-refused draft func_80181720) <sub>L30241</sub>
- **§315** — ALL-CONSTANT AGGREGATE FILL: THE EMISSION ORDER IS SHARED-LITERAL GROUPS × DESCENDING INDEX, WITH PAIRED SUB-FIELDS INTERLEAVED (P31 S66; ⚠ **UNPROVEN** — `func_80185214`, gate-REFUSED draft, closeness 32→5, never MATCHed) <sub>L30273</sub>
- **§316** — A GUARD CHAIN THAT GATES A SUCCESS BLOCK ROUTES ITS FAILING GUARDS TO A LABEL **BEFORE** THE FLAG TEST, NOT TO THE EPILOGUE: THE RESIDUAL IS IMM-OFFSET-ONLY AT AN EXACTLY EQUAL INSTRUCTION COUNT (P31 S66; byte-proven func_80180284) <sub>L30310</sub>
- **§317** — A NARROW STRUCT-FIELD STORE TURNS A *LIVE SImode VARIABLE* INTO A `li`: convert.c's TRUNCATION-DISTRIBUTION MINTS A HImode COPY, AND cse REWRITES THAT COPY'S SOURCE TO THE EQUIVALENT CONSTANT (P31 S66; byte-proven func_8017EF94) <sub>L30344</sub>
### types, signedness & load/store width (77)
### types, signedness & load/store width (79)
- **§3-I1** — Unsigned range check: `(x - lo) < (hi-lo)` → `addiu`+`sltiu` <sub>L41</sub>
- **§3-I2** — Byte mask forces `andi` even after `lbu` <sub>L47</sub>
@@ -480,6 +497,8 @@
- **ADDENDUM** — to §172b-1 (counter-type dial) — the sll's SOURCE REGISTER is the placement discriminator <sub>L29268</sub>
- **ADDENDUM** — to §31's asm→layout inference — TWO WIDTH-PAIR DISCRIMINATORS (same offset, different widths) <sub>L29380</sub>
- **§297** — ONE GIV SERVING MIXED-WIDTH LOADS *AND* A STORE NEEDS STRUCT-MEMBER SPELLING; CAST/INDEX SPELLINGS RE-SPLIT THE PSEUDO (P31 S61; wave m0a, `func_800347C8`, main, byte-proven 31/31) <sub>L29499</sub>
- **§318** — A UNARY MINUS STORED BACK INTO THE SAME HALFWORD IS COMPUTED IN HImode, SO ITS LOAD IS `lhu`; AN INLINE `(s32)` CAST IS PROVABLY INERT AND ONLY A NAMED SImode LOCAL BUYS `lh` (P31 S66; `func_8018568C`, ov_SC03_028 — **`match_one`-only, NOT byte-gated**) <sub>L30378</sub>
- **Addendum** — Reversed-operand sltu then xori 1 means unsigned less-or-equal (func_8017D948) <sub>L30505</sub>
### declarations, prototypes & K&R (99)
@@ -632,7 +651,7 @@
- **§305** — "CARVE-REFUSED" AT GATE TIME IS THREE NAMED, DETERMINISTIC CLASSES — NONE OF THEM A CARVE (P31 S62 T3; 28 resolver drafts autopsied 28/28) <sub>L29822</sub>
- **§308a** — A TWO-INSTRUCTION ARM STUB LAID *BEFORE* THE OTHER ARM AND REACHED ONLY BY A TRAILING `j` SURVIVES ONLY BEHIND A SHORT-CIRCUIT `&&` GUARD PLUS A SEPARATE RE-TEST; EVERY PLAIN if/else-if, GOTO-LADDER, NESTED-INVERTED-if AND 1-/2-NODE switch LETS jump1 INLINE IT (−2 ins) (P31 S63 t5e-t5i; byte-proven func_80180808) <sub>L30012</sub>
### optimisation level (-O0/-O2) (18)
### optimisation level (-O0/-O2) (20)
- **§6** — Per-module optimization mixing — the -O0 boot module (Phase 7) <sub>L265</sub>
- **Detecting** — the opt level (do this first) <sub>L273</sub>
@@ -652,6 +671,8 @@
- **§265** — THE VERBATIM-ASM BANK LANE: A FUNCTION NO -O2 C CAN EVER MATCH BANKS AS A RAW `__asm__` BODY (P31 S59b; two banked cards, two in-tree precedents) <sub>L25018</sub>
- **ADDENDUM** — to §127 — the -O0 constant-offset fold keys on the MEMBER-ACCESS tree shape, not on the index being constant <sub>L29170</sub>
- **ADDENDUM** — to §261a — FOUR MORE -O0 DIALS BEYOND THE RELOAD COUNT (boot.c + md_MAIN_011/003, wave m0a/g0a/g0f, byte-proven) <sub>L29198</sub>
- **Addendum** — Addendum to §261a — the -O0 increment-operator copy also fires on the POINTER LOCAL itself (func_8001212C) <sub>L30473</sub>
- **Addendum** — Addendum to §164-XX/§165-06 — at -O0 a bare local IS a memory lvalue, so the increment ope (func_8001212C) <sub>L30477</sub>
### family propagation & sweeps (110)
@@ -766,7 +787,7 @@
- **§308a** — A TWO-INSTRUCTION ARM STUB LAID *BEFORE* THE OTHER ARM AND REACHED ONLY BY A TRAILING `j` SURVIVES ONLY BEHIND A SHORT-CIRCUIT `&&` GUARD PLUS A SEPARATE RE-TEST; EVERY PLAIN if/else-if, GOTO-LADDER, NESTED-INVERTED-if AND 1-/2-NODE switch LETS jump1 INLINE IT (−2 ins) (P31 S63 t5e-t5i; byte-proven func_80180808) <sub>L30012</sub>
- **§314** — AN IF/ELSE-IF ABS-RANGE CHECK'S C SPELLING IS INERT: FOUR STRUCTURALLY DIFFERENT REWRITES ALL COMPILE BYTE-IDENTICAL, AND NONE REACHES A TARGET THAT SINKS THE NEGATIVE ARM INTO AN OUT-OF-LINE BLOCK (P31 S65; UNPROVEN, gate-refused draft func_80181720) <sub>L30241</sub>
### integration / TU plumbing (60)
### integration / TU plumbing (61)
- **§8c** — Splitting a TU means rebuilding its DECLARATION ENVIRONMENT, not moving text (Phase 26 session 6) <sub>L456</sub>
- **§8d** — Templating a body INTO a TU must not CHANGE its declaration environment — demote the carried data externs (Phase 26 session 8, byte-proven on `func_8015AE2C` ×133) <sub>L502</sub>
@@ -828,8 +849,9 @@
- **§NNN** — A LOOP CURSOR'S C TYPE (POINTER vs PLAIN INTEGER) SELECTS `sltu` vs `slt` FOR ITS BOUND TEST, INDEPENDENT OF THE VALUES INVOLVED (P31 S60; `func_800CAE74`, md_MAIN_031, byte-proven; cross-confirmed same wave by `func_8017F2A4`, ov_SC03_096) <sub>L26957</sub>
- **ADDENDUM** — to §199-G — A `default:` LABEL GROUPED ONTO THE LAST CASE REMOVES THE `j default` TAIL, EVEN THOUGH THE 2-NODE HEADER STAYS ALL-POSITIVE <sub>L27411</sub>
- **§301** — AN INTERNAL `j` CARRIES `R_MIPS_26 .text`: rtu/match_one "MATCH" COULD NOT SEE WHICH LABEL A `j` TAKES — FIXED (`jrel`), AND THE TWO DRAFT SHAPES IT HID (P31 S62 T1; byte-proven 2/2, negative-controlled over 3,297 stubs) <sub>L29671</sub>
- **Addendum** — Reversed-operand sltu then xori 1 means unsigned less-or-equal (func_8017D948) <sub>L30505</sub>
### build graph, splat & the harness (169)
### build graph, splat & the harness (173)
- **§4** — Flag/toolchain gotchas <sub>L190</sub>
- **Build** — mechanism — per-file opt override (splat resegmentation) <sub>L307</sub>
@@ -1000,6 +1022,10 @@
- **§305** — "CARVE-REFUSED" AT GATE TIME IS THREE NAMED, DETERMINISTIC CLASSES — NONE OF THEM A CARVE (P31 S62 T3; 28 resolver drafts autopsied 28/28) <sub>L29822</sub>
- **§313** — A RECOVERY STAGE THAT REWRITES THE DRAFT IS PART OF THE MEASUREMENT: GATE THE RAW DRAFT FIRST, THE REWRITE ONLY AS A FALLBACK (P31 S65 t5r-recovery; byte-proven func_8017BEBC, 246 ins) <sub>L30185</sub>
- **§314** — AN IF/ELSE-IF ABS-RANGE CHECK'S C SPELLING IS INERT: FOUR STRUCTURALLY DIFFERENT REWRITES ALL COMPILE BYTE-IDENTICAL, AND NONE REACHES A TARGET THAT SINKS THE NEGATIVE ARM INTO AN OUT-OF-LINE BLOCK (P31 S65; UNPROVEN, gate-refused draft func_80181720) <sub>L30241</sub>
- **§315** — ALL-CONSTANT AGGREGATE FILL: THE EMISSION ORDER IS SHARED-LITERAL GROUPS × DESCENDING INDEX, WITH PAIRED SUB-FIELDS INTERLEAVED (P31 S66; ⚠ **UNPROVEN** — `func_80185214`, gate-REFUSED draft, closeness 32→5, never MATCHed) <sub>L30273</sub>
- **§316** — A GUARD CHAIN THAT GATES A SUCCESS BLOCK ROUTES ITS FAILING GUARDS TO A LABEL **BEFORE** THE FLAG TEST, NOT TO THE EPILOGUE: THE RESIDUAL IS IMM-OFFSET-ONLY AT AN EXACTLY EQUAL INSTRUCTION COUNT (P31 S66; byte-proven func_80180284) <sub>L30310</sub>
- **§318** — A UNARY MINUS STORED BACK INTO THE SAME HALFWORD IS COMPUTED IN HImode, SO ITS LOAD IS `lhu`; AN INLINE `(s32)` CAST IS PROVABLY INERT AND ONLY A NAMED SImode LOCAL BUYS `lh` (P31 S66; `func_8018568C`, ov_SC03_028 — **`match_one`-only, NOT byte-gated**) <sub>L30378</sub>
- **Addendum** — Addendum to §167-12 — the single-operand volatile keepalive, re-confirmed at a gated MATCH (func_8017F498) <sub>L30485</sub>
### process, measurement & doctrine (108)
@@ -1112,7 +1138,7 @@
- **§294** — ADDENDA HARVESTED FROM THE S61 GEN0/MAXTOK/MAIN/DEEPSEEK BATCH (waves ab8/ab16/ab24/ab32 · g0a–g0f · m0a · ds1/ds2): 99 candidates, 52 covered, 15 notes → 10 addenda, 29 notes → 5 new laws (§295–§299), 3 refuted <sub>L29159</sub>
- **§313** — A RECOVERY STAGE THAT REWRITES THE DRAFT IS PART OF THE MEASUREMENT: GATE THE RAW DRAFT FIRST, THE REWRITE ONLY AS A FALLBACK (P31 S65 t5r-recovery; byte-proven func_8017BEBC, 246 ins) <sub>L30185</sub>
### (unbucketed — title matched no symptom vocabulary) (288)
### (unbucketed — title matched no symptom vocabulary) (291)
- **§3-How** — to use this <sub>L30</sub>
- **§1** — Idiom catalog (asm pattern → C that produces it) <sub>L39</sub>
@@ -1402,6 +1428,9 @@
- **ADDENDUM** — to §31's density-dummy dial (L2460/L2497) — the dose is TWO refs, and the dummy must sit where the loser is live-through <sub>L29296</sub>
- **§300** — S61 DISTILL BATCH NOTES (waves ab8/ab16/ab24/ab32 · g0a–g0f · m0a · ds1/ds2 · m0b) <sub>L29602</sub>
- **§306a** — T4 DISTILL ADDENDA (P31 S62; four byte-proven refinements to existing laws, verified against the book by an independent verifier; each names its parent §) <sub>L29901</sub>
- **Addendum** — §148-A2 addendum — the empty-asm insn_count dial (N bare `__asm__("")` = exactly +N real i (func_801835B0) <sub>L30453</sub>
- **Addendum** — Chained *2*2 array index folds to one copy;sll, not two (func_80011380) <sub>L30509</sub>
- **Addendum** — Last if-arm's nested if un-fuses the whole preceding chain (func_8017FE88) <sub>L30529</sub>
## All sections, in order
@@ -2328,6 +2357,26 @@
- **§312** — A BARE RELATIONAL IN AN `if` GIVES THE `slt` NO TARGET: ASSIGN THE COMPARISON INTO THE ALREADY-ALLOCATED VARIABLE TO CHOOSE ITS DESTINATION REGISTER, AT ZERO INSTRUCTION COST (P31 S64 t5o-t5r; byte-proven func_80180DCC) <sub>L30159</sub>
- **§313** — A RECOVERY STAGE THAT REWRITES THE DRAFT IS PART OF THE MEASUREMENT: GATE THE RAW DRAFT FIRST, THE REWRITE ONLY AS A FALLBACK (P31 S65 t5r-recovery; byte-proven func_8017BEBC, 246 ins) <sub>L30185</sub>
- **§314** — AN IF/ELSE-IF ABS-RANGE CHECK'S C SPELLING IS INERT: FOUR STRUCTURALLY DIFFERENT REWRITES ALL COMPILE BYTE-IDENTICAL, AND NONE REACHES A TARGET THAT SINKS THE NEGATIVE ARM INTO AN OUT-OF-LINE BLOCK (P31 S65; UNPROVEN, gate-refused draft func_80181720) <sub>L30241</sub>
- **§315** — ALL-CONSTANT AGGREGATE FILL: THE EMISSION ORDER IS SHARED-LITERAL GROUPS × DESCENDING INDEX, WITH PAIRED SUB-FIELDS INTERLEAVED (P31 S66; ⚠ **UNPROVEN** — `func_80185214`, gate-REFUSED draft, closeness 32→5, never MATCHed) <sub>L30273</sub>
- **§316** — A GUARD CHAIN THAT GATES A SUCCESS BLOCK ROUTES ITS FAILING GUARDS TO A LABEL **BEFORE** THE FLAG TEST, NOT TO THE EPILOGUE: THE RESIDUAL IS IMM-OFFSET-ONLY AT AN EXACTLY EQUAL INSTRUCTION COUNT (P31 S66; byte-proven func_80180284) <sub>L30310</sub>
- **§317** — A NARROW STRUCT-FIELD STORE TURNS A *LIVE SImode VARIABLE* INTO A `li`: convert.c's TRUNCATION-DISTRIBUTION MINTS A HImode COPY, AND cse REWRITES THAT COPY'S SOURCE TO THE EQUIVALENT CONSTANT (P31 S66; byte-proven func_8017EF94) <sub>L30344</sub>
- **§318** — A UNARY MINUS STORED BACK INTO THE SAME HALFWORD IS COMPUTED IN HImode, SO ITS LOAD IS `lhu`; AN INLINE `(s32)` CAST IS PROVABLY INERT AND ONLY A NAMED SImode LOCAL BUYS `lh` (P31 S66; `func_8018568C`, ov_SC03_028 — **`match_one`-only, NOT byte-gated**) <sub>L30378</sub>
- **Addendum** — §148-A2 addendum — the empty-asm insn_count dial (N bare `__asm__("")` = exactly +N real i (func_801835B0) <sub>L30453</sub>
- **Addendum** — §312 addendum — naming the compare's dest is the vehicle, the hard-reg pin on that name is (func_80184A68) <sub>L30461</sub>
- **Addendum** — subu/sh dest reuses a pinned operand's dying register (func_8017F498) <sub>L30465</sub>
- **Addendum** — Addendum to §261a — the -O0 increment-operator copy also fires on the POINTER LOCAL itself (func_8001212C) <sub>L30473</sub>
- **Addendum** — Addendum to §164-XX/§165-06 — at -O0 a bare local IS a memory lvalue, so the increment ope (func_8001212C) <sub>L30477</sub>
- **Addendum** — Addendum to §312 — the compare's named destination must itself carry a hard register: nami (func_80184A68) <sub>L30481</sub>
- **Addendum** — Addendum to §167-12 — the single-operand volatile keepalive, re-confirmed at a gated MATCH (func_8017F498) <sub>L30485</sub>
- **Addendum** — A §5a BARRIER SITS IN REORG'S FILL WINDOW TOO, SO ITS SIDE OF THE INNER `goto` IS CHOSEN P (func_80181D08) <sub>L30489</sub>
- **Addendum** — Loop sentinel wrongly hoisted out of a call-containing loop (func_801835B0) <sub>L30493</sub>
- **Addendum** — Reversed-operand sltu then xori 1 means unsigned less-or-equal (func_8017D948) <sub>L30505</sub>
- **Addendum** — Chained *2*2 array index folds to one copy;sll, not two (func_80011380) <sub>L30509</sub>
- **Addendum** — REGALLOC-PERM: one memory-clobber barrier insufficient — stack two (func_80182D1C) <sub>L30523</sub>
- **Addendum** — Last if-arm's nested if un-fuses the whole preceding chain (func_8017FE88) <sub>L30529</sub>
- **Addendum** — A plain global-RMW triplet is a fillable scheduling window too — zero drift, and the fille (func_800CB058) <sub>L30533</sub>
- **Addendum** — Shared arithmetic that CONSUMES the selected value cannot be hoisted above the `if` — narr (func_80183DA0) <sub>L30537</sub>
- **REFUTED** — claim — Dead call-arg register address-fold: no C-level lever found (func_8017ECAC) <sub>L30541</sub>
---
@@ -3262,3 +3311,23 @@ Notes routinely quote that as a section id. This table resolves it. Grep bait: `
| L30159 | §312 | A BARE RELATIONAL IN AN `if` GIVES THE `slt` NO TARGET: ASSIGN THE COMPARISON INTO THE ALR |
| L30185 | §313 | A RECOVERY STAGE THAT REWRITES THE DRAFT IS PART OF THE MEASUREMENT: GATE THE RAW DRAFT FI |
| L30241 | §314 | AN IF/ELSE-IF ABS-RANGE CHECK'S C SPELLING IS INERT: FOUR STRUCTURALLY DIFFERENT REWRITES |
| L30273 | §315 | ALL-CONSTANT AGGREGATE FILL: THE EMISSION ORDER IS SHARED-LITERAL GROUPS × DESCENDING INDE |
| L30310 | §316 | A GUARD CHAIN THAT GATES A SUCCESS BLOCK ROUTES ITS FAILING GUARDS TO A LABEL **BEFORE** T |
| L30344 | §317 | A NARROW STRUCT-FIELD STORE TURNS A *LIVE SImode VARIABLE* INTO A `li`: convert.c's TRUNCA |
| L30378 | §318 | A UNARY MINUS STORED BACK INTO THE SAME HALFWORD IS COMPUTED IN HImode, SO ITS LOAD IS `lh |
| L30453 | Addendum | §148-A2 addendum — the empty-asm insn_count dial (N bare `__asm__("")` = exactly +N real i |
| L30461 | Addendum | §312 addendum — naming the compare's dest is the vehicle, the hard-reg pin on that name is |
| L30465 | Addendum | subu/sh dest reuses a pinned operand's dying register (func_8017F498) |
| L30473 | Addendum | Addendum to §261a — the -O0 increment-operator copy also fires on the POINTER LOCAL itself |
| L30477 | Addendum | Addendum to §164-XX/§165-06 — at -O0 a bare local IS a memory lvalue, so the increment ope |
| L30481 | Addendum | Addendum to §312 — the compare's named destination must itself carry a hard register: nami |
| L30485 | Addendum | Addendum to §167-12 — the single-operand volatile keepalive, re-confirmed at a gated MATCH |
| L30489 | Addendum | A §5a BARRIER SITS IN REORG'S FILL WINDOW TOO, SO ITS SIDE OF THE INNER `goto` IS CHOSEN P |
| L30493 | Addendum | Loop sentinel wrongly hoisted out of a call-containing loop (func_801835B0) |
| L30505 | Addendum | Reversed-operand sltu then xori 1 means unsigned less-or-equal (func_8017D948) |
| L30509 | Addendum | Chained *2*2 array index folds to one copy;sll, not two (func_80011380) |
| L30523 | Addendum | REGALLOC-PERM: one memory-clobber barrier insufficient — stack two (func_80182D1C) |
| L30529 | Addendum | Last if-arm's nested if un-fuses the whole preceding chain (func_8017FE88) |
| L30533 | Addendum | A plain global-RMW triplet is a fillable scheduling window too — zero drift, and the fille |
| L30537 | Addendum | Shared arithmetic that CONSUMES the selected value cannot be hoisted above the `if` — narr |
| L30541 | REFUTED | claim — Dead call-arg register address-fold: no C-level lever found (func_8017ECAC) |
+290
View File
@@ -30260,3 +30260,293 @@ So the agent's own closing summary ("merges provably-equivalent arms into one sh
**THE MECHANISM — unknown/inferred, NOT verified against gcc-2.7.2 source this session.** No `-dj`/`-dS` dump or `jump.c`/`stmt.c` read was done to identify the deciding pass. Candidate, unconfirmed: some `expand_expr`/`do_jump` block-layout heuristic for a nested `if` whose OUTER condition's false arm is itself a full `if` (as opposed to `jump.c:1806`'s documented "every arm returns" swap at §167-27/§136g-1, whose stated precondition does not hold here — the fall-through path continues into `VectorNormal(...)`, not a `return`). Do not cite either pass as the cause without re-deriving it from source.
**BOUND.** n=1 (one function, and the whole-binary byte-gate REFUSED this draft, so even the 51-diff intermediate state is not proven correct elsewhere in the function — only the `match_one`/`masked_diff` closeness comparisons between drafts, which are a reliable local tool, are asserted here). Only four C spellings were tried, all closely related (all keep the guard as two nested nullary-side-effect `if`s feeding early returns); untested and left open: whether a spelling with a REAL intervening side effect between the two tests (a `§164-52`-style label with ≥2 jump references, which resets cse's path-local tables and is documented elsewhere to disarm similar folds) reaches the target's out-of-line shape. Says nothing about functions where the "rare arm" contains a `return` from every path (that's §167-27's territory, already covered) or about any range check that is a single `||`/`&&` expression (that's §164-56's `range_test`, a different, statement-boundary-sensitive fold, explicitly checked and ruled out as the mechanism here since a statement boundary already existed in every spelling tried and did not change the outcome).
---
# S66 HARVEST (P31, 2026-08-30) — 4 NEW, 15 ADDENDUM, 1 REFUTED
*Distilled from 35 wave transcripts (12 byte-proven banked, 23 drafted-but-ungated). Rows marked
UNPROVEN came from drafts the whole-binary gate had not accepted — the lever may still be real
(cookbook §52: a frontier model that FAILS a wall still distils the idiom that cracks its
siblings), but no byte-equality is asserted for them.*
## §315 — ALL-CONSTANT AGGREGATE FILL: THE EMISSION ORDER IS SHARED-LITERAL GROUPS × DESCENDING INDEX, WITH PAIRED SUB-FIELDS INTERLEAVED (P31 S66; ⚠ **UNPROVEN** — `func_80185214`, gate-REFUSED draft, closeness 32→5, never MATCHed)
**⚠ STATUS FIRST.** This section is filed on a **differential** measurement, not on bytes. `func_80185214` never reached MATCH; its best draft bottoms at `{"status":"near","closeness":5,...,"klass":"SCHEDULE-REORDER","bucket":"permuter"}`. Treat the ordering rule below as a **probe worth two minutes**, not a law. No gcc-2.7.2 source cite ties it to a pass — the agent grepped `sched.c` for `birthing_insn_p` (§3-C) and tried §3-G block reordering, and *both named mechanisms were flat*.
**THE TELL.** A run of `li`/`addiu` constant loads into one or two scratch regs (`$v0`/`$v1`), each immediately followed by several `sh`/`sw` stores into a **local** struct/array (PS1 `POLY_FT4`-style vertex/uv prim is the archetype), where the store OFFSETS run counter to naive left-to-right source order — e.g. one constant group hitting `0x28, 0x18, 0x2A, 0x22` = array indices **3, 1, 3, 2** — and where two sub-fields of the *same* element (`uv[i].u` then `uv[i].v`) land as **adjacent** stores rather than being split apart by field.
**THE PROBE (what the sweep selected).** When a local aggregate is filled **entirely with compile-time constants** and several sibling fields share literals, write the source as: **(1)** one group per distinct literal (all the `0x40`s, then all the `-0x40`s, …); **(2)** inside each group, walk the array index **DOWN** — `[3], [2], [1], [0]`; **(3)** for paired sub-fields, interleave per index instead of writing whole fields.
```c
prim.v[3].vx = 0x40; prim.v[2].vx = -0x40; prim.v[1].vx = 0x40; prim.v[0].vx = -0x40;
prim.v[3].vy = 0x40; prim.v[2].vy = 0x40; prim.v[1].vy = -0x40; prim.v[0].vy = -0x40;
prim.clut = 0x79;
prim.v[3].vz = 0; prim.v[2].vz = 0; prim.v[1].vz = 0; prim.v[0].vz = 0;
prim.uv[0].u = 0xC00; prim.uv[0].v = 0x180; prim.uv[1].u = 0xC7F; prim.uv[1].v = 0x180;
prim.uv[2].u = 0xC00; prim.uv[2].v = 0x1FF; prim.uv[3].u = 0xC7F; prim.uv[3].v = 0x1FF;
```
**EVIDENCE — a 40-variant combinatorial sweep, differential only.** `.run/.../sweep2.py`, 5 v-shapes × 4 u-shapes × 2 tails, masked-diff against the real target `.s` via `match_one`. Baseline backlog draft (source order + single-expression tail) = **32** (`sig":"WIDTH/sw!=lw"`). A load-hoist variant = **34** (worse). Splitting the colour expression alone with unchanged write order = **38** (worse still). Then: `grp+nat+B` = **16**, `vdsc+nat+B` = **10**, **`fdsc+nat+B` = 5** (best), against `fdsc+base+A` = 28, `fdsc+natd+A` = 28, `vasc+nat+A` = 28. The three levers are **jointly required** — swap any one out and it reverts to double digits.
**WHAT THE FLOOR ACTUALLY IS, AND WHY IT MATTERS.** The surviving 5-instruction window is **not** the fill body — it is the prologue schedule:
```
mine: sw $v0,0x50($sp) ; li $v0,0x40 ; sw $ra,0x58($sp) ; lw $a3,0x1C($a0) ; li $v1,-0x40
target: sw $ra,0x58($sp) ; lw $a3,0x1C($a0) ; addiu $v1,$zero,-0x40 ; sw $v0,0x50($sp) ; addiu $v0,$zero,0x40
```
Per **§234** the `li 0x40` / `addiu $zero,0x40` pair is the *same* encoding (bit-15-clear ⇒ the signedness dial is inert), so the residual is pure **position**: the target sinks the first frame store below the `$ra` save and the `$a3` load, and births `$v1` before `$v0`. So the fill-order lever appears to have done its job and the remainder is a separate prologue-window defect — which is the honest reading, and also why the section cannot be promoted: nothing byte-confirms it. From that floor, **484** statement placements of the flags store/load, **57** block permutations, §205 chained forms, §55a/§3-C re-tie fences, §220 param typings and empty-asm barriers all left the number at 5.
**BOUNDS AND RELATIONS (read these before reaching for it).**
1. **This is §213's declared blind spot, which is why it is its own section.** §213's BOUNDARY says verbatim: *"This is about independent stores — no aliasing, **no shared value**, no call between them."* It then routes shared-value runs to §30/§193-D/§194-M — none of which cover an all-constant aggregate fill. §213's own three-step procedure (asm order verbatim → ascending offset → rotate-one-left) was **not** among the winners here, and its S58b addendum's "a non-monotonic offset sequence in the target is order-faithful" reading is exactly the trap this card fell into at closeness 32.
2. **Not §145(c).** §145(c) is descending emission from *one chained* statement `a = b = c = 0;`. This is descending across *separate* statements, grouped by literal.
3. **Not §281.** §281 groups by OPERATION KIND (copies then RMWs) in a copy-then-adjust block; here every store is a constant and there is no dependent RMW to group.
4. **The tail-split half of this card is a REDISCOVERY — do not file it.** `t = t | (t<<8) | (t<<16); col = 0x808080 - t;` beating the single combined expression is **§164-80 Law 1** (L13628: an inner op evaluates into an anonymous temp that takes a scratch; make each statement's destination the variable itself) as extended by **§167-46** (L16204). Cite those, not this section.
5. **n=1, one shape.** One function, one PS1 prim layout, `sh`-width stores, no call inside the run. Re-measure before generalising to word stores, to non-aggregate locals, or to any fill with a non-constant term.
**Grep bait:** `all-constant struct fill`, `prim vertex store order`, `descending array index stores`, `constant group store order`, `uv interleave`, `POLY_FT4 fill order`.
## §316 — A GUARD CHAIN THAT GATES A SUCCESS BLOCK ROUTES ITS FAILING GUARDS TO A LABEL **BEFORE** THE FLAG TEST, NOT TO THE EPILOGUE: THE RESIDUAL IS IMM-OFFSET-ONLY AT AN EXACTLY EQUAL INSTRUCTION COUNT (P31 S66; byte-proven func_80180284)
*(BOUNDS §225-3, whose early-return ladder is the winning spelling only when the chain ends in a bare `return C == D;` with no success block — with a success block the same ladder is what fails here. Instantiates §225-1's "failure edges need explicit gotos landing mid-flow" for a flag test rather than a shared call. Generalises §176-F row 3 / its S62 T4 addendum from one branch to N. NOT §195-E: the named-flag-across-a-join axis is already satisfied in both the failing and the matching draft. NOT §195-N: that law's chain has no success block and its own BOUND 2 kills it when the returned constant is not 1, which is this function's case.)*
**THE DIAGNOSTIC TELL.** `match_one` reports `klass == "IMM-OFFSET"`, `bucket == "structural"`, **`nins_mine == nins_tgt` exactly**, and **every** residual word is one of the early-guard branches carrying the **same** constant displacement delta — sig `IMM-OFFSET/-9`, `n=3`, `kinds:{"imm":3}`. The instruction sequence and count are already 100% right; only the `beqz`/`bne` guard-fail targets are off, by a fixed word count equal to the size of the flag-test-plus-success block your branches are jumping over. **A shared delta across N branches is not a scheduling nuance and not a dropped edge — it is one wrong destination shared by N edges.** Count the words between the target's guard-branch label and your own before touching polarity, pins or statement order.
**THE MECHANISM (as far as it is demonstrated).** Written as N independent `if (guard_fail) return 0;` statements, cross-jump/tail-merge collapses the N `return 0` tails to one, so the count comes out right — but every guard branch lands on the function's **outer epilogue**, past the whole flag-test/success block. The real source instead converges all N failing guards on a label sitting **immediately before the last chain term's flag test**, with `$v0` already zeroed from the failed comparison, so the flag-test and branch machinery is *reused* rather than bypassed. The last chain term must stay its own one-line statement (`r = last_cmp;`); folding it back into the `&&`/`if` condition re-triggers the §195-N-family value-form tax (see the caveat below). Each guard edge must also explicitly re-zero `r` — leaving it uninitialised on one path is a semantic bug, not a dial, and regressed this function from closeness 3 to 50.
**THE C SHAPE.**
```c
/* closeness=3, IMM-OFFSET/-9, nins 50 == 50 — WRONG: every guard branch
lands past the flag test, at the outer epilogue */
if (guard1_fail) return 0;
if (guard2_fail) return 0;
if (guard3_fail) return 0;
r = last_cmp;
if (r) { success_stuff(); return x; }
return 0;
/* closeness=0, MATCH, nins 50 — guards converge on a label BEFORE the flag
test, each re-zeroing r first (this is func_80180284 verbatim) */
if (guard1_fail) { r = 0; goto chain_fail; }
if (guard2_fail) { r = 0; goto chain_fail; }
if (guard3_fail) { r = 0; goto chain_fail; }
r = last_cmp; /* last chain term: its OWN statement, never folded into && */
chain_fail:
if (r) { success_stuff(); return x; }
return 0;
```
**BYTE EVIDENCE.** `func_80180284` (ov_SC04_019, 50 ins, **MATCH**, banked at `src/ov_SC04_019/ov_SC04_019_jr_8017AE2C.c:6064-6094` — three `r = 0; goto chain_fail;` guards with `chain_fail:` immediately above `if (r)`). `match_one --json` trajectory across fifteen drafts: 53→29→44→19→53→19→19→19→53→19→18→**3** (draft11, the early-`return 0` ladder: `{"klass":"IMM-OFFSET","closeness":3,"nins_mine":50,"nins_tgt":50,"sig":"IMM-OFFSET/-9","detail":{"delta":-9,"n":3,"kinds":{"imm":3}}}`) →18 (draft12, last term folded back into `&&`, LENGTH-DRIFT/+1) →50 (draft13, goto shape but `r` uninitialised on one path) →22 (draft14, nested if/else with `r = 0` in each else) →**0** (draft15, `{"status":"match","closeness":0,"nins":50,"residual":[]}`). *Note: the same vram in ov_SC03_102 is an unrelated one-line body — cite the ov_SC04_019 definition.*
**SCOPE, stated honestly.** One function, five spellings, one overlay. The *prescription* is byte-proven; the *gcc internals* are not — no `jump.c`/`cse.c`/`reorg.c` line was traced for which pass fixes the displacement or why the shared label must precede the flag test, and that half is inferred from the residual shape alone. The draft12 `+1 j` observation is **weaker than the rest**: draft12 moved from the goto shape back to `&&` *and* re-inlined `r` (closeness 3 → 18), so it is not a single-axis A/B, and it sits outside §195-N's stated preconditions (no success block; returned constant must be 1) — it is evidence that §195-N's BOUND 2 may be over-broad, not a confirmed instance of §195-N. Re-measure both on the first out-of-TU instance before treating either as settled.
## §317 — A NARROW STRUCT-FIELD STORE TURNS A *LIVE SImode VARIABLE* INTO A `li`: convert.c's TRUNCATION-DISTRIBUTION MINTS A HImode COPY, AND cse REWRITES THAT COPY'S SOURCE TO THE EQUIVALENT CONSTANT (P31 S66; byte-proven func_8017EF94)
*(EXTENDS §201-B (L21231) — the SAME `convert.c` `trunc1` distribution, a DIFFERENT consequence: §201-B decides the SIGN (`ori` vs `addiu`) of a constant the source spelled as a bare literal, and its BOUND 2 explicitly scopes itself to "the constant must actually need materialisation"; this law is about a constant the source NEVER SPELLED — it is manufactured out of a variable, and it costs an instruction. BOUNDS §178-D (L17332), whose "a narrow type blocks copy elision, so the copy SURVIVES at its source position" is the BENIGN half of this same SI→HI copy: when the copy's source pseudo carries a constant equivalence the copy does not survive as a copy at all, it becomes a `li`. BOUNDS §167-14's asm→source read (L15435) — "`li K` followed by `subu` ⇒ it wrote `K - x`" — false here: the source wrote `h - n`, two variables. Same cse constant-equivalence family as §164-02 (L11934) / §164-52, run through the SET_SRC of a copy instead of a commutative swap.)*
**THE TELL.** `li $vN,K` immediately followed by the arithmetic op that consumes it (`li $v0,0x28 ; subu $v0,$v0,$s0`) where the TARGET computes straight off a callee-saved register that has carried that value since much earlier in the function (`subu $v0,$s5,$s0`). Two extra reads: the consumer of the result is a **narrow store** (`sh` into an `s16` field), and the literal is usually one you can find *in your own source* as a named local assigned statements above (`h = 0x28;`). A constant standing where a register should be, on a narrowing store, is this — not §167-14's `K - x` spelling and not a scheduling residual.
**THE LAW.** The `s16` destination makes the assignment a SI→HI truncation of a MINUS, so `convert_to_integer`'s `trunc1` (`tools/reference/gcc-2.7.2/convert.c:269-317`, the PLUS/MINUS/BIT_AND/BIT_IOR/BIT_XOR/BIT_ANDTC label) redoes the arithmetic in `typex`, converting **each operand** (`:311-313`) instead of the result — `narrow(a - b)` becomes `narrow(narrow(a) - narrow(b))`. Each operand therefore reaches RTL as its own HImode **copy** pseudo of the SImode variable rather than as the variable itself. `fold_rtx`'s cheapest-operand replacement loop (`cse.c:5222-5250`) then picks between the folded operand and its equivalent constant by `COST` (`cse.c:481`): `COST(const_int) = rtx_cost*2 = 0` against `COST(pseudo) = 1`, so `validate_change` swaps the pseudo for the constant and the copy's source **is** the literal. A `li` is not a register-register copy, so nothing downstream can coalesce it back onto the register that still holds the value — you pay a whole instruction and lose the target's register reuse. Routing the subtraction through a **fresh `s32` temp** keeps the MINUS in SImode, where `subsi3`'s `reg_or_0_operand` predicate makes the same `validate_change` **reject** the fold, and the variable survives in its callee-saved register; the temp's extra reference also lifts that variable's allocno rank back over its neighbour's, restoring the target's `$s4`/`$s5` order.
**THE C SHAPE.**
```c
/* fails: closeness 73, LENGTH-DRIFT/1 — the store narrows, and h folds to `li 0x28` */
s32 n, h, w;
h = 0x28;
D_STRUCT.h = h - n; /* s16 field: SI->HI truncation distributes into the MINUS operands */
/* fix: closeness 0, MATCH — a FRESH s32 temp keeps the MINUS SImode */
s32 n, h, w, hh;
h = 0x28;
hh = h - n;
D_STRUCT.h = hh;
```
**BYTE EVIDENCE — `func_8017EF94` (ov_SC06_025, 292 ins, MATCH; banked `src/ov_SC06_025/ov_SC06_025_jr_8017EEC4.c:2905`, note at :2864-2877).** With the `h`-placement residual already fixed and `D_801B1B58.h = h - n;` stored direct (`v2.c`): `near closeness 73 nins 293 LENGTH-DRIFT/1`. The same file with **only that one statement** respelled `hh = h - n; D_801B1B58.h = hh;` (`v6.c`): `match 0 292 MATCH`.
**THE CONTROL — the temp must be FRESH, and this inverts §164-24's imperative.** `v7.c` reused an existing scratch local `t` for the identical purpose: `near 63 292 OPCODE-MIXED/addressing,width`. It gets the mode right (the length drift is gone) and loses on allocation. So §164-24's closing "when you use the variable-K form, SPEND AN EXISTING VARIABLE" does not transfer here; this agrees with §165-18's fresh-pair result (L14181) and gives it a second, differently-caused instance — there the discriminator was store-target-vs-load-target, here it is that the reused variable already has a live range the narrow value must not join.
**BOUNDS.** (1) Only `trunc1`'s opcodes — PLUS, MINUS, BIT_AND, BIT_IOR, BIT_XOR, BIT_ANDTC (`convert.c:269-276`); MULT takes the `:253-264` path and division/shifts never reach `trunc1` (§201-B bound 4). (2) The destination must actually narrow — a wide store keeps the MINUS SImode and there is nothing to fold (§201-B bound 3). (3) The operand must have a **constant** equivalence in cse's table at that point; a variable whose value cse cannot prove constant is not at risk. (4) Untested: QImode fields (`s8`), the PLUS direction, and whether an already-narrow (`s16`) source variable behaves the same.
*Honest scope: n=1 function, one site; the lever, the failing spelling and the reused-variable control are all byte-measured against the target. The RTL narrative (HImode copy pseudo → `li`) is read out of the pinned `convert.c`/`cse.c` and is NOT dump-confirmed — no `-dr` was taken. Ship the precondition and the lever; if this recurs, dump it.*
*(NEW; evidence: byte-probed, 3 spellings incl. a negative control; from `func_8017EF94`)*
**Symptom lines for the index:** **"a `li K` where the target has a `subu` off a callee-saved register"** · **"the constant I assigned to a local reappears as a literal at the narrow store"** · **"LENGTH-DRIFT +1 on an `sh` of a subtraction"** · **"routing a narrow store through an s32 temp changed the register allocation"**
## §318 — A UNARY MINUS STORED BACK INTO THE SAME HALFWORD IS COMPUTED IN HImode, SO ITS LOAD IS `lhu`; AN INLINE `(s32)` CAST IS PROVABLY INERT AND ONLY A NAMED SImode LOCAL BUYS `lh` (P31 S66; `func_8018568C`, ov_SC03_028 — **`match_one`-only, NOT byte-gated**)
**⚠ STATUS — UNPROVEN LEVER.** The whole-binary byte-gate refused this draft; the three states below
were measured with `match_one`'s isolated per-function compile+mask check only. The C→asm delta is
tool-measured and reproducible, and the *mechanism* below I re-read out of the pinned gcc-2.7.2
source myself — but nothing here is a byte-match. Re-gate before quoting it as law.
**THE TELL.** A single opcode-only residual, **count-neutral** (72/72 both sides, `closeness 1`, class
`WIDTH`, `sig=WIDTH/lhu!=lh`): your `lhu $v0,N($rB)` where the target has `lh $v0,N($rB)`,
**immediately feeding a `negu` whose result goes straight back to `sh` at the same address**. No
length drift ever warns you. Target, verbatim
(`asm/ov_SC03_028/nonmatchings/ov_SC03_028_jr_80184914/func_8018568C.s`, `80185764`–`80185778`):
```
80185764 lw $v1, 0x20($a0)
8018576C lh $v0, 0x18($v1) <- SIGNED load: the source did NOT negate in HImode
80185774 negu $v0, $v0
80185778 sh $v0, 0x18($v1)
```
**THE MECHANISM (source-cited; this is the front end, not an optimizer pass).** `*(s16*)p = -*(s16*)p;`
is `convert_to_integer (short, NEGATE_EXPR<int>(…))`, and `convert.c:320-346` is a **separate arm** from
the `trunc1` arm §201-B owns: it distributes the truncation down through the negate *unconditionally*
(no `get_unwidened` operand guard, no operand-precision test), rebuilding it as
`NEGATE_EXPR<short>(convert (short, operand))`. So the negate is done in HImode, the load is a plain
HImode copy, and `LOAD_EXTEND_OP == ZERO_EXTEND` (`mips.h:1163`) emits **`lhu`** (§172a's copy-vs-promotion
tell, seen from the authoring side). **Why the inline cast cannot help:** `-(s32)*(s16*)p` builds the
*same tree* the implicit promotion already built, and the recursive `convert (typex, operand)` above
lands on `case NOP_EXPR` at **`convert.c:352-353`**, which is literally
`return convert (type, get_unwidened (…))` — the cast is stripped on the way back down. A cast written
inside an expression the assignment narrows is not a lever; it is a no-op. **The only escape is to take
the load out of the narrowed expression**, into a genuine SImode local, where it is a real promotion
(`extendhisi2_internal`) and emits `lh`.
**THE C SHAPE.**
```c
/* FAILS — both spellings identical, closeness 1, sig=WIDTH/lhu!=lh */
*(s16 *)p = -*(s16 *)p;
*(s16 *)p = -(s32)*(s16 *)p; /* the cast changes NOTHING — convert.c:352 strips it */
/* WORKS — closeness 0 in match_one */
s32 val;
val = *(s16 *)p; /* a real SImode local: this is the promotion -> lh */
val = -val;
*(s16 *)p = val;
```
**THE EVIDENCE.** `match_one --json`, three states, one edit apart: attempt A
`{"status":"near","closeness":1,"nins":72,"residual":[[56,"94620018 lhu v0,24(v1)","84620018 lh $v0, 0x18($v1)"]],"verdict":{"klass":"WIDTH","sig":"WIDTH/lhu!=lh"}}`;
attempt B (inline `(s32)`) — **byte-for-byte the same JSON**, the cleanest possible negative control;
attempt C (named `s32` local) — `{"status":"match","closeness":0,"nins":72,"residual":[]}`.
**WHERE IT SITS vs THE NEIGHBOURS (all four checked; none states this).**
* **§201-B** owns the same `convert_to_integer` narrowing family but is bounded to `trunc1`'s *binary*
opcodes (its BOUND 4: "ONLY `trunc1`'s OPCODES: PLUS, MINUS, BIT_AND, BIT_IOR, BIT_XOR, BIT_ANDTC")
and to the *constant's* `ori`/`addiu` opcode. **Do not carry its truth table over:** the NEGATE arm's
`typex` signedness is `TREE_UNSIGNED (TREE_TYPE (expr))` alone (`:340-341`) — there is no OR over the
unwidened operands, so the operand's `*(s16*)`⇄`*(u16*)` cast has no vote here. This entry also
answers §201-B's own BOUND 6 on the `lh`/`lhu` axis: in the *unary* arm the load width **is** visible.
* **§242 #1** is the same residual class from the other side (`*4` keeps `lh`, `<<2` gives `lhu`, sink is
a narrow `sh`) and is the nearest prior art — but its dial is a *spelling of the scale*. Here there is
no spelling escape at all; the statement must be split.
* **§261a** states the observation (`s16` fields: "`lh` at a plain read, but `lhu` inside a
read-modify-write") but scoped to **-O0**, with no mechanism and no cure. That it holds at both -O0
and -O2 is expected — `convert.c` is the C front end — and it corroborates §201-B's untested -O0 bound.
* **§172a is NOT contradicted.** Its corollary (`s32 x = shortmem` ≡ `s16 t = shortmem; s32 x = t;`) is
scoped to a value that really is *promoted*, i.e. an SImode destination. In a store-narrowed
expression nothing is promoted, so the corollary never applies and the cast never had a chance.
**BOUNDS / UNTESTED.** n=1, and not byte-gated. Untested: `~x` (`BIT_NOT_EXPR` shares the identical arm —
predicted the same, unmeasured); QImode (`*(s8*)p = -*(s8*)p`); whether a `volatile` or a second SImode
consumer of the same load changes the answer; whether the cure survives when the named local is `s16`
(predicted no — HImode local, still a copy). `ABS_EXPR` is explicitly excluded by the comment at
`convert.c:322-323` ("we must test the sign before truncation") and is a different section (§267-ADD-5).
### Addendum — §148-A2 addendum — the empty-asm insn_count dial (N bare `__asm__("")` = exactly +N real i (func_801835B0)
**Addendum (P31 S66, func_801835B0):** a **third insn_count dial, and the cheapest one — `N` bare `__asm__("");` statements at the top of the loop body buy exactly `+N` to `insn_count` and restructure nothing.** A colon-less empty asm is `ASM_INPUT` (`stmt.c:1340`, per §194-A's predicate table at L19008), so it is a real insn to loop.c's count, no pass before `loop` can fold it (satisfying this section's BOUND 6), and it emits zero bytes. §148-A2's two dials each buy a fixed `+2` and each demand a semantic rewrite (duplicate the back-edge; route a constant through a multiply-set variable); this one is arbitrary-granularity and semantics-free, so **compute `N` from the dump and spend exactly that**: `N = threshold·savings·lifetime + 1 − insn_count`.
**The savings-1 / lifetime-1 band, which is the common one and worth memorising:** a plain literal sentinel (`-1`) in a call-containing loop has savings 1 and lifetime 1, so the whole test collapses to **`29 ≥ insn_count`** — it hoists iff the loop is ≤29 real insns, all-or-nothing, no staircase (only one movable). Here `insn_count` was 23, so `N = 29+1−23 = 7`; six barriers would have landed on the `>=` edge and still hoisted, exactly as this section's 104-both / 105-split boundary did twice.
**THE `+3` TELL (the mirror of §164-35's `−3`).** Draft carries **one extra callee-saved register**, `nins = nins_tgt + 3` (the extra `sw`/`lw` pair plus the preheader materialisation), frame `-40` vs target `-0x20`, one extra `.mask` bit, and a `li $sN,-1` sitting **before** the loop label while the target computes `addiu $vN,$zero,-1` **inside** the body just ahead of the terminating branch. match_one files this as `klass: LENGTH-DRIFT`, `sig: LENGTH-DRIFT/3?`. §164-35's identical-looking `−3` cascade is the opposite fault (an invariant that should hoist and did not) — read the sign before routing.
**BYTE EVIDENCE.** `func_801835B0`: two intermediate drafts both `{"status":"near","closeness":28,"nins":37,"verdict":{"klass":"LENGTH-DRIFT","sig":"LENGTH-DRIFT/3?","detail":{"delta":3}}}`; with the 7 barriers at the loop top, `{"status":"match","closeness":0,"nins":34,"residual":[]}`. Confirmed independently by standalone `cc1 -dL` runs (`v5.c`/`v6.c`): with the barriers the emitted `.s` loses the pre-loop `li $19,-1` and the `sw $19,28($sp)`, and the frame drops 40 → 32, matching the target's `.frame $sp,32,$31` / `.mask 0x80070000,-4`.
**BOUND.** `N=7` is arithmetic, not a constant — never transplant it; re-read `Loop from A to B: N real insns` for the new loop. The minimum was derived from the formula, not bisected by ablation (§266): 7 is proven sufficient, and 6 is predicted-insufficient by the `>=` edge but was not compiled. Seven barriers is also seven §194-A scheduling fences stacked at the block head; here they sat above an otherwise empty region so nothing competed, but on a loop whose top statements matter that side effect is real and must be attributed separately.
### Addendum — §312 addendum — naming the compare's dest is the vehicle, the hard-reg pin on that name is (func_80184A68)
**Addendum (P31 S66, func_80184A68):** §312's bound (2) — *"an unpinned local would only move the dest to whatever that local got"* — is now **measured, not reconstructed**, and it splits §312's one-step recipe into two when there is no already-coloured variable to assign into. Same tell exactly: both of the compare's INPUTS already pinned correctly (`register s32 iVar __asm__("$2")` on the call result), zero length drift, residual exactly 2 — `[[17,"0062102a slt v0,v1,v0","0062182a slt $v1, $v1, $v0"],[18,"14400003 bnez v0","14600003 bnez $v1"]]`, `REGALLOC-PERM/$v0>$v1`, `map {"$v0":"$v1"}` (closeness 23 → 2 on the input pin alone, nins 33 = target). **draft7 applied §312's statement verbatim with a FRESH, UNPINNED name** (`cond = threshold < iVar; if (!cond)`) → **closeness unchanged at 2, byte-identical residual — naming alone buys nothing here.** **draft8, the only change being `register s32 cond __asm__("$3")` on that same name → `match`, closeness 0, nins 33, residual `[]`.** So the assignment is the *vehicle* (it gives the `slt`'s `SET_DEST` an addressable C name where a bare relational has none); the pin on that name is the *payload* — §312 got the payload for free because its `v0` was already pinned, and its "already-allocated" title clause is load-bearing, not incidental. Also ablated inert: draft6 pinned the OTHER operand (`threshold` → `$3`, not the compare's LHS) and left closeness 2 — a second confirmation that no INPUT pin reaches the dest, which is §165-47's composition law ("pinning only the operands leaves the dest on `$v1`"; a register *relationship* needs every member named) showing up on the relational operator instead of a three-address `subu`. **BOUNDS.** (1) n = 1; mechanism still un-dumped, so §312's `do_jump`/`store_expr` inference gains no evidence — what is proven is name+pin → MATCH. (2) This **narrows** §306a's T4 bound (4) (*"on a 2-instruction REGALLOC-PERM reach for the naming/scope lever first and the pin never"*): that holds when the wrong register is an INPUT; when it is the compare's own DEST and no coloured variable is at hand, name **and** pin. Pay §37/§162p rung-3's family cost knowingly. (3) Polarity is free — `if (!cond)`/`beqz` behaves exactly as §312's `if (v0 != 0)`/`bnez`. (4) ⚠ The `func_80184A68` at L23136/L23959 (ov_SC06_000, 16 ins, the `update_equiv_regs` anti-remat card) is a **different body at the same address** (§313/R48's per-address-name collision); this one is 33 ins and the transcript did not name its overlay.
### Addendum — subu/sh dest reuses a pinned operand's dying register (func_8017F498)
**Addendum (P31 S66, func_8017F498):** This is the **banked exemplar §167-12's own scope note asks for** — its eight A/B pairs were mismatch counts on a still-5-off `func_8017F3C8`, and it closes with *"Re-confirm on a banked exemplar before treating the position rule as exact."* Here the identical construct — a single-operand `__asm__ __volatile__("" :: "r"(mid));` on a `register s16 mid __asm__("$5")` pin — drives a **gated MATCH** (`match_one --json`: `status match, closeness 0, nins 99, residual []`), so the volatile-anchor form now has a byte-proven instance and not only a directional one.
Three refinements the parent sections do not carry. (1) **The tell generalises off unary ops.** §167-12's shape is a destructive one-operand `sll $s1,$s1,16` and §164-62's an `andi $a0,$a0,0x1`; here it is a **three-operand non-commutative `subu` plus its consumer** — draft `subu $a1,$a1,$a0` / `sh $a1,0x2E($s0)` against target `subu $v0,$a1,$a0` / `sh $v0,0x2E($s0)`, i.e. the dest ties the *pinned* source while the other operand is untouched, and the residual is a 2-line REGALLOC-PERM/closeness-2 tail, not a whole triad (contrast §310 (L30086), whose subu tie is between two *unpinned* operands and whose dial is share-exactly-one — its BOUND 5 explicitly leaves the pinned case untested; this is that case, and the lever is the keepalive, not the share).
(2) **A new legal position: after an if/else join, before the next `if`.** §167-12 prescribes materialising the compare into a named boolean so the asm has a statement boundary to sit on; here the boundary is the **join after the arm that consumes `mid`** (`if (x < mid) result = mid - x; else result = 0;` → keepalive → the next `if`), which is enough to hold the death and hand `result` a fresh `$v0`.
(3) **Two fresh negatives, one A/B apart, at the same closeness-2 plateau:** pinning the result instead (`register s32 d __asm__("$2")` block-scoped, h5) and a plain unpinned `s32 d` temp (h6) **both regressed 2 → 72**. So the lever is the keep-alive *use*, not "give the result its own variable" and not a second pin — §176-B's "right class, wrong pin" reproduced on a 99-ins leaf.
**⚠ Bound (unchanged from the parents, plus one).** No `-dl`/`-da` dump was taken on this function: the `qty_phys_sugg`/`find_free_reg` death-guard story is inherited from §80/§164-62/§167-12, not re-derived here, and the agent's own reload narrative across g1→g5→h1 is a reading of the emitted registers. The free confirmations nobody ran are §164-62's two greps (`';; Register N in H.'` in `.lreg`, `REG_DEAD` on the consuming insn) and `grep -n '#APP' t.s` to prove the block sits *below* the `subu`. Also untested here: §164-62's competing two-operand anchor (`asm("" :: "r"(mid), "r"(result))`), which on this shape has a value defined at the consuming insn and should work — the volatile form was taken first and never ablated against it.
### Addendum — Addendum to §261a — the -O0 increment-operator copy also fires on the POINTER LOCAL itself (func_8001212C)
**Addendum (P31 S66, func_8001212C):** §261a's second bullet gives this law for a struct FIELD through a pointer (`++p->f` ⇒ 3 reloads, the first dead, plus an `addu rd,rs,$zero` copy after the add; `p->f += k` ⇒ 2 reloads, no copy). It also fires on the **auto POINTER LOCAL itself** — at -O0 a non-`register` local IS the memory lvalue, so `q++` on a `$fp`-slot pointer emits the four-instruction window `lw $a0,0($fp)` / `addiu $v1,$a0,0x18` / `addu $a0,$v1,$zero` / `sw $a0,0($fp)`. Tell: a draft 2 instructions short at a pointer advance with no copy before the store-back — the same dead-reload + copy pair §261a counts. An A/B sweep of one `ADVANCE` line in boot.c reports `q++` and `++q` at `match_one` closeness 0 / 177 ins, while **all four** non-increment spellings (`q += 1`, `q = q + 1`, `q = (T*)((u8*)q+0x18)`, `q = (T*)((s32)q+0x18)`) fold the copy away at 87 / 175 — consistent with §164-XX's proven axis (INCREMENT-OPERATOR vs everything else, not post-vs-pre) and with its note that at -O2 the copy coalesces away by `final`, which is why this is count-visible only at -O0. **Do not read this as flipping ADDENDUM (a):** (a) is a `register` (pseudo-resident) local where `x = x + 1` copies and `+=` folds; residency picks the dial — memory local ⇒ only the increment operator copies. ⚠ **UNPROVEN — not byte-proven.** The whole-binary byte-gate refused this draft (or never ran on it); closeness 0 is `match_one`'s isolated masked-diff verdict only. One function, one offset (0x18), mechanism inferred from §164-XX rather than re-read from RTL here. Try the lever, re-gate, and promote this to byte-proven on the next confirming target.
### Addendum — Addendum to §164-XX/§165-06 — at -O0 a bare local IS a memory lvalue, so the increment ope (func_8001212C)
**Addendum (P31 S66, func_8001212C):** §164-XX's law reaches a **bare local at -O0**, and there the extra copy is **emitted, not coalesced**. At -O0 every local lives in a frame slot, so a pointer local *is* a memory lvalue: `q++` / `++q` route through `expand_increment` (`expr.c:8482` → `copy_to_reg` :8648 → `expand_binop` :8657 → `emit_move_insn` :8660) and, with no regalloc/cse pass to coalesce it, that copy survives into the `.s` as a real instruction; `q += 1`, `q = q + 1` and the cast-add forms go through `build_modify_expr`'s plain `MODIFY_EXPR` and store the add's result straight back. **Tell:** a 4-instruction advance triad against a `$fp` slot — `lw $a0,0x0($fp)` / `addiu $v1,$a0,0x18` / `addu $a0,$v1,$zero` / `sw $a0,0x0($fp)` — twice in `func_8001212C` (boot, -O0 prologue `21F0A003`, 177 ins) at `0x80012290` and `0x800123C0`; a draft emitting only load/add/store is 1 insn short **per advance site**. **Evidence:** a six-spelling A/B on the single advance line against `match_one` — `q++` → 0/177 and `++q` → 0/177; `q += 1`, `q = (T *)((u8 *)q + 0x18)`, `q = (T *)((s32)q + 0x18)` → near 87/175 (exactly the two copies short); `q = &q[1]` → cc1 fail. So §164-XX's "the copy coalesces away by `final`, so the emitted COUNT is identical" is an **-O2-only** statement: at -O0 the same dial is a *countable* length tell, which makes the increment-operator spelling the first thing to check on an -O0 LENGTH-DRIFT that is an exact multiple of the advance-site count. It also **bounds ADDENDUM to §261a (a)**: that card's register-local polarity (`x = x + 1` copies, `+=` folds) is a *different axis*, not a mirror — for a **frame-slot** local both `+=` and `q = q + 1` fold and only the `++`/`--` operator copies. Read the lvalue's class (REG vs MEM) before picking between the two dials. **⚠ UNPROVEN — not byte-gated.** The whole-binary byte-gate refused this draft (or never ran on it); the 0/177 is `match_one`'s isolated masked-diff verdict only. The target's 4-insn triad is ground truth from `asm/nonmatchings/boot/func_8001212C.s`, but the C→asm attribution is one function at one offset (0x18) and awaits a gated confirmation or a second target before it is treated as law.
### Addendum — Addendum to §312 — the compare's named destination must itself carry a hard register: nami (func_80184A68)
**Addendum (P31 S66, func_80184A68):** §312's tell and lever reproduce exactly on a second function — same 2-instruction zero-drift `slt`+branch REGALLOC-PERM with both operands already correct (`[[17,"0062102a slt v0,v1,v0","0062182a slt $v1, $v1, $v0"],[18,"14400003 bnez v0","14600003 bnez $v1"]]`, `sig REGALLOC-PERM/$v0>$v1`, `map {"$v0":"$v1"}`, nins 33 = target) — and it **splits §312's lever into two clauses, only the second of which is load-bearing**. §312's BOUND (2) guessed that "an unpinned local would only move the dest to whatever that local got"; that is now measured, not guessed. Ablation on the pinned triple, one axis per draft: draft5 (`register s32 iVar __asm__("$2")` on the call-result input alone) → 23 → **2**; draft6, additionally pinning the *other* operand `threshold` to `$3` → **inert, still 2, byte-identical residual**; draft7, §312's assignment shape into a **fresh unpinned** name (`cond = threshold < iVar; if (!cond)`) → **also inert, still 2** — naming alone does nothing; draft8, the only change being `register s32 cond __asm__("$3")` on that same name → **`{"status":"match","closeness":0,"nins":33,"residual":[]}`**. So restate the recipe as: (i) give the comparison a named destination so `expand_expr` has a target at all, **and** (ii) make that name carry a hard register. §312 got (ii) for free because it assigned back into an operand that was *already* pinned; when neither operand's variable is pinned to the register you need, declare a fresh `register s32 cond __asm__("$N")` and pick `$N` by reading the target's own `slt` dest (here `$v1`, the LHS's register — still §312's in-place-compare tell). **Routing (a bounded counter-example to §176-B and to the S62-T4 addendum's bound (4), which say reach for naming/scope on a 2-insn REGALLOC-PERM and for the pin never):** on the compare's **DEST** the pin is required — but only on the assigned boolean; pinning an *input* was inert here, and §268 is why it is honored at all (the boolean's live range crosses no `jal`). **BOUND.** n = 2 for the law, n = 1 for this clause. §312's own self-assign form (`threshold = (threshold < iVar)`) was never tried on this body, so "fresh pinned bool" vs "reuse an already-pinned operand" is unablated — treat them as one lever with two spellings. No `-dS`/`-dl`/`-dg` dump was taken; the drafter cites no gcc-2.7.2 source line, so §312's `do_jump`-has-no-target story remains the inferred mechanism (§164z / §137's bar) and this entry adds only that the synthesised dest is *also* free of any preference from its pinned operands.
### Addendum — Addendum to §167-12 — the single-operand volatile keepalive, re-confirmed at a gated MATCH (func_8017F498)
**Addendum (P31 S66, func_8017F498):** §167-12's closing ask — *"re-confirm on a banked exemplar before treating the position rule as exact"* — is answered. The same single-operand `__asm__ __volatile__("" :: "r"(mid));` drove a **gated MATCH** here (`match_one --json` → `{"status":"match","closeness":0,"nins":99,"residual":[]}`), not §167-12's 5-off plateau, and it widens the entry on three axes. (1) **Insn class:** the consuming insn is a `subu` *and the `sh` that stores its result* — draft `55 subu $a1,$a1,$a0` / `57 sh $a1,0x2E($s0)` vs target `subu $v0,$a1,$a0` / `sh $v0,0x2E($s0)` — so read the tell as *any* 3-operand ALU op whose destination equals one of its own live sources, with its dependent store dragged along, not just §167-12's `sll`. (2) **Pin class:** the dying value is a **caller-saved** pin, `register s16 mid __asm__("$5")` whose range crosses no call (so §268's honour condition holds), not §167-12's callee-saved `$s1`. (3) **Position:** the keepalive that worked sits **after the whole `if/else` whose arm contains the consuming insn, ahead of the next `if`** (`if (x < mid) result = mid - x; else result = 0;` … `__asm__ __volatile__("" :: "r"(mid));` … `if (sp10.v[2] >= 0x1241)`). §167-12 measured "inside either arm" as a regression on *its* shape, so state the position rule as **"below the consuming insn, at the nearest statement boundary the value still reaches"** — the if/else join qualifies. **Routing, byte-measured at the same closeness-2 plateau:** pinning the *destination* instead (`register s32 d __asm__("$2")` around the result) and a plain unpinned `s32 d` temp **both regressed to 72** — so on this residual do not reach for §312/§197-C's "name/assign the destination" lever, and do not read it as §310's block-local-operand dial (which picks *which* operand the dest ties to, not whether it ties at all). **Bound (§266 / R14):** this run ablated only the lever *choice*; `__volatile__`-vs-plain and the exact placement were **not** solo-removed here — that axis still rests entirely on §167-12's eight controlled pairs — and no `-dl`/`.lreg` dump was taken, so `qty_phys_sugg` stays the cited hypothesis for this function, not a traced fact.
### Addendum — A §5a BARRIER SITS IN REORG'S FILL WINDOW TOO, SO ITS SIDE OF THE INNER `goto` IS CHOSEN P (func_80181D08)
**Addendum (P31 S66, func_80181D08):** §283's ADDENDUM-to-§5a (L28359, `func_80181F74`, **same overlay** ov_SC03_112) prescribes the guarded-twin barrier "in the ELSE-continuation, … not inside the guard's taken-arm (it changes which arm is fall-through and flips branch polarity)". That prescription is **function-scoped, not general.** `func_80181D08` (ov_SC03_112, 96 ins, banked `src/ov_SC03_112/ov_SC03_112_jr_801817E0.c:3043-3062`) carries **both** placements in one body, one per sign-arm, and neither is optional. The discriminator is §164-09's ⚠ bound (L12085) turned into a rule: the barrier does double duty — it denies `find_cross_jump` (its job) **and** stands in reorg's fill window on whatever path you typed it on — so **read the target's two delay slots at the join and put the barrier on the side that does not deny the fill you need.** When the join block's head insn is stolen into the *conditional branch's own* slot (here `lui $v0,(0xB60B60B7>>16)`, the divide magic at the vy join), the barrier must go **BEFORE** the inner `goto`, inside the taken arm; left after the `goto` on the fall-through it halts the eager scan of that arm and you get `beqz TAIL / nop / j CONT / lui` against the target's `bnez CONT / lui / j TAIL / nop`. When the target leaves **both** slots `nop` (the sibling vx arm here; §164-09's and §283's own exemplars) the after-the-`goto` placement is free and correct. **THE TELL — `klass=DELAY-SLOT, sig=DELAY-SLOT/2`, a 4-row residual at a §5a barrier site,** not the usual single stolen-load row: the conditional branch's polarity is inverted **with its two labels swapped**, and one instruction has moved between that branch's slot and the following `j`'s slot. Do **not** reach for §3-T4's polarity invert, a register pin, or a second fence (§163f-2) — move the existing barrier across the `goto`, and expect to keep the sibling arm's placement unchanged. **Byte evidence** (single-axis A/Bs on the pinned triple; `nins` already pinned at 96 by an unrelated s16-clamp-temp fix): d3, both barriers after their `goto` → `near, closeness 4, nins 96`, residual `[54] beqz $v0,158 ↔ bnez $v0,.L80181E00`, `[55] nop ↔ lui $v0,0xb60b`, `[56] j f8 ↔ j .L80181E60`, `[57] lui $v0,0xb60b ↔ nop`; d5, identical except the vy barrier moved before its `goto` → `match, closeness 0, 96, residual []`; control d4 (placement moved, clamp fix withheld) held at closeness 40 / LENGTH-DRIFT, so the two fixes are independent and both required. *Honest scope: the "barrier halts the eager scan" half is §5a/§199-F's already-established `stop_search_p` mechanism (`reorg.c:674-704`, `fill_slots_from_thread`); this card did not dump `-dd`/re-derive which thread reorg would otherwise have picked, so treat the causal story as observed, and the prescription (read the slots, place per arm) as the byte-proven part.*
### Addendum — Loop sentinel wrongly hoisted out of a call-containing loop (func_801835B0)
**Addendum (P31 S66, func_801835B0):** *A third insn_count dial — `N × __asm__("");` at the loop-body top — and it is the only one that needs no later pass to delete it.* Both dials in "HOW TO STEER IT" above (the doubled back-edge, the multiply-set returned constant) are +2 each and are free only because jump2/cross-jumping removes them afterwards, which is what BOUND 6 states as a requirement ("any construct you add to raise the count must be deleted by a pass that runs AFTER loop"). **That bound is too strong.** A colon-less `__asm__("")` expands to an `ASM_INPUT` insn (`stmt.c:1340`, §194-A's predicate table), loop.c counts it in `Loop from A to B: N real insns` like any other real insn, and it is *never* deleted — it simply emits zero bytes at final. So the dial is **+1 insn_count per statement, arbitrarily many, zero bytes**, and the correct form of BOUND 6 is: *the construct must be invisible to cse1/jump1 (which run before loop) and must emit nothing — being deleted after loop is one way to satisfy that, not the only way.*
**The instance, and it runs the arithmetic in the refusing direction.** `func_801835B0`'s loop calls a function ⇒ `threshold = 29`; the movable was a plain `-1` sentinel literal (savings 1, lifetime 1), and the draft's real body was only 23 RTL insns, so `29·1·1 = 29 ≥ 23` hoisted it into an extra callee-saved register with a preheader `li $s3,-1`. Seven `__asm__("")` at the top of the loop body took the count 23 → 30, `29 ≥ 30` is false, the hoist is refused, and the sentinel re-computes in-loop exactly as the target has it. Confirmed by reading `move_movables`/`scan_loop` and by `cc1 -dL` on standalone v5.c/v6.c.
**THE DIAGNOSTIC TELL — the exact mirror of §164-35's.** §164-35 routes "one callee-saved register **short**, frame 4 smaller, **−3** ins" to a *missing* hoist. This is the same cascade with every sign flipped: **`nins_mine == nins_tgt + 3`** (the extra `sw $sN` / `lw $sN` / preheader `li`), **one callee-saved register too many**, frame **larger** (`addiu $sp,$sp,-40` vs the target's `-0x20`), an extra `.mask` bit, and a **`li $sN,-1` sitting before the loop label** where the target computes `addiu $vN,$zero,-1` *inside* the body ahead of the terminating branch. `match_one` calls this `klass: LENGTH-DRIFT`, `sig: LENGTH-DRIFT/3?` — do **not** read that sig as a scheduling or regalloc residual; it is an `insn_count` reading, and it is arithmetic.
**BYTE EVIDENCE.** `func_801835B0`: before, `{"status":"near","closeness":28,"nins":37,"verdict":{"klass":"LENGTH-DRIFT","sig":"LENGTH-DRIFT/3?","detail":{"delta":3}}}`, identical across two intermediate drafts; after inserting the seven barriers at the loop top, `{"status":"match","closeness":0,"nins":34,"residual":[]}`. Standalone `cc1 -dL` A/B: with the barriers the `.s` loses the pre-loop `li $19,-1` and its `sw $19,28($sp)`, and the frame shrinks 40 → 32, reaching the target's `.frame $sp,32,$31` / `.mask 0x80070000,-4`.
**BOUNDS (two, both already law elsewhere — check them before spending this dial).** (1) **§164-36 still governs the slot:** an asm at the head of a block whose first insn the target steals into a delay slot costs +1 ins. The loop-*body* top was safe here; a loop *head* that is also a branch target may not be. (2) **§47/§158/§194-A-6 collateral:** N extra static insns add +N `reg_live_length` to every pseudo spanning them, so any exact-tie allocno pair straddling the barriers can flip — re-verify the whole function, not just the loop. Note also that this dial is a *counting* instrument only when the barrier is colon-less/`volatile`; a non-volatile `__asm__("" ::: "memory")` is a different animal per §194-A's table.
### Addendum — Reversed-operand sltu then xori 1 means unsigned less-or-equal (func_8017D948)
**Addendum (P31 S66, func_8017D948):** the `GT, LE, GTU, LEU` row's reg-path cell reads "`reverse_regs` puts the constant on slt's **LEFT** … `li CST ; slt K,x` verbatim + **uninverted** branch at every `-O`". That "uninverted" clause is the **GT/GTU half only** — LE/LEU carry `invert_reg = 1`, and in **VALUE context** (a `return`, not a branch) that inversion is emitted as an explicit **`xori rD,rD,0x1`**. BOUND 1's value-context probe only ever showed the *const*-path xori (`slt $2,$2,31 ; xori 1`); this is the reg-path cell it never measured. **Byte evidence — `func_8017D948` (ov_SC02_026, 36 ins, MATCH on the first compile, banked at `src/ov_SC02_026/ov_SC02_026_jr_8017C180.c:3491`):** tail `ori $v0,$zero,0x8FFE ; sltu $v0,$v0,$v1 ; xori $v0,$v0,0x1` ⇐ `return (data[0] + data[1] + data[2]) - 0x10001U <= 0x8FFE;`. `CST+1 = 0x8FFF > 32766` ⇒ out of window ⇒ `force_reg` + `reverse_regs`, so here the constant-FIRST operand order proves a **bare literal**, not a named local — the reading rule's second bullet is guarded by `CST ≤ 32766` and must not be read as a naming signal above the window. **READING RULE (value context).** A register load of K (`ori rC,$zero,K`, or `lui`/`ori`) immediately followed by `sltu rD,rC,rX` — constant first, variable second — and then `xori rD,rD,0x1` before the return ⇒ `x <= K` **unsigned**, K bare. The same pair *without* the `xori` is `K < x` (GTU). **The C dial for the unsignedness is one `U` suffix inside the additive expression:** a single unsigned operand drags the whole usual-arithmetic-conversion result unsigned even when every base term is plain `int` — the third member of the "what makes a compare unsigned" family beside §280 (pointer vs integer cursor) and §199-D (narrow unsigned object). Not a one-off: the identical construct is already banked in six sibling overlays in its GTU/branch spelling `if (0x13FFE < s1 - 0x10001U)` (ov_SC06_018/020/022/024/032/033).
### Addendum — Chained *2*2 array index folds to one copy;sll, not two (func_80011380)
**Addendum (P31 S66, func_80011380): the -O0 ARRAY-INDEX face of (b) — COUNT the `copy;sll` pairs, each one is one multiply STEP in the source. ⚠ LEVER UNPROVEN (the byte-gate REFUSED this draft; best result 6/192 mismatched, never a MATCH).**
(b) says a power-of-2 scale spelled as a MULTIPLY routes through the mul-style expansion (a `move`) while the SHIFT spelling reads its operand straight. In an index that is the `addu $X,$Y,$zero ; sll $Y,$X,k` pair, and `func_80011380` (boot, -O0) carries **both counts on the same index global**, three instructions apart in the C:
80011420 lw D_80074784 ; addu $v1,$v0,$zero ; sll $v0,$v1,2 <- ONE pair -> lhu off D_800629D4
80011488 lw D_80074784 ; addu $a0,$v1,$zero ; sll $v1,$a0,1
addu $a0,$v1,$zero ; sll $v1,$a0,1 <- TWO pairs -> lbu off D_800629D6
So **two `copy;sll 1` pairs before an array's `lui/addiu/addu` base add mean the source did the ×4 as two separate multiply STATEMENTS, not one `*4` and not a chained `i*2*2` written inline.** ~15 inline respellings of the chain (parens, `({…})` statement-exprs, u32/s32/long casts, `<<1`, `+0`/`|0` no-ops, `__asm__`-pinned regs) all plateaued at closeness 9 or worse — that is **§164-16 (L12228)** working exactly as written: `MULT_EXPR` (fold-const.c:3897) reaches the `associate:` label, `split_tree` strips same-mode casts and takes the constant from either side, and **only a DECL leaf breaks it**. The reported lever — `D_800629D6[({ register s32 t = D_80074784; t *= 2; t; }) * 2]` — moved closeness 9 → 6 (residual idx 71-76), reproduced by five sibling spellings; `register` matters here per **§261a addendum (c)** (a plain -O0 local would live in the frame and add `lw`/`sw` traffic the target does not have).
**⚠ Do not re-buy the submitted mechanism.** The card attributes this to `expand_mult` special-casing a power-of-2 under `EXPAND_SUM` — **unsupported**; fold runs *before* expand, §164-16 already owns the chain-collapse and §164-13/§164-03 own the real EXPAND_SUM laws (which are about `(v+C)*K` and operand order, not this). The card's own "`t <<= 1` did NOT work, only `t *= 2`/`t = t*2`" is **(b) confirming itself** — the shift spelling drops the copy — not a separate mystery. Untested and left open: whether a **plain, non-`register`** local reaches the same shape (§164-16 predicts it does at the fold level), and whether anything closes the final 6-mismatch `$a0`/`$v1` coloring residual.
### Addendum — REGALLOC-PERM: one memory-clobber barrier insufficient — stack two (func_80182D1C)
**Addendum (P31 S66, func_80182D1C) — ⚠ UNPROVEN: gate-refused draft, `match_one` closeness only, no `-dl`/`-dg` on the winning variant.** §137 step 4 places **one** zero-byte barrier at the source point that lands `L` in the priority window, and its five-placement probe teaches placement as the only dial. On this card the placement sweep read as *inert*: draft4 (no barrier), draft11 (`__asm__ __volatile__("" :: "r"(r1))`) and draft12 (one `__asm__ __volatile__("" ::: "memory")`) all returned the **byte-identical** residual — `near`, closeness 9, `REGALLOC-PERM/$s0>$s1>$s0`, same residual list. A **second identical barrier stacked back-to-back** (draft13) took it to `match`, 0/66, residual `[]`. So the barrier **COUNT is itself a dial**, not just its position: per §47 and §194-A bound 6 each zero-byte asm is **+1 static insn at global-alloc time, +1 `reg_live_length` to every pseudo spanning it**, and a single +1 can leave the contenders on the same `int(numerator/L)` plateau §47's step 3 describes. **Sweep N = 1, 2, 3 at a fixed point before concluding the class is barrier-inert** — the same fixed-point compose §158 step 4 already does with two *different* zero-emission asms, here with two identical ones for one relation.
**The sub-tell that says the barrier reached global-alloc but did not cross the boundary:** draft12's `-dg` header reordered its allocnos (`5 regs to allocate: 78 75 77 74 73` → `75 78 77 74 73`) while the emitted bytes did not move. Ranking motion with zero byte motion = plateau, add another slot; no ranking motion = wrong placement, per §137 step 4.
**What is NOT established, and what to run first if this recurs.** (1) No `-dl`/`-dg` was taken on draft13, so *which* allocno's R/L crossed is unconfirmed — the §137/§158 dump bar is unmet and the plateau story is the leading hypothesis, not a re-derivation. (2) The `"memory"` clobber is almost certainly **not** the ingredient: §194-A's byte-discriminated predicate table (`sched.c:1953`) shows the bare `__asm__ __volatile__("")` is an equally good barrier and does not drag in §178-G2's address-chain sinking or §21's prologue pin — retest the stack in the bare form, and per §47's placement rule sit it next to an existing volatile asm so no new cse/sched perturbation rides along. (3) draft11's null is **predicted, not anomalous**: §158's placement rule puts the input-tied extender *after* the variable's natural last use, and here it sat above the compare that kills `r1`, extending nothing. (4) Per §266 the pair is only jointly citable — removing either barrier reproduces draft12 — so cite "two", never "a barrier".
### Addendum — Last if-arm's nested if un-fuses the whole preceding chain (func_8017FE88)
**Addendum (P31 S66, func_8017FE88; ⚠ UNPROVEN — `match_one` isolated masked diff only, the whole-binary byte-gate refused this draft):** §312's own scope sentence — *"a bare relational has no join and no constant arms, so §195-E's 'naming materialises a 0/1' does not fire and the naming is byte-free apart from the register it buys"* — has a measured counter-case, and the price is not a register but the whole block layout. Inside a **chain of constant-assigning arms** (`if (v1<0x140) idx=0; else if (…) idx=1; … else idx=4;`) the target form is one fused pair per arm: `slti` + `bnez <shared merge>` with the arm's constant sitting **in that branch's own delay slot** — no separate move, no trailing `j` — i.e. §136d-2/§164-57's `jump.c:728-760` collapse firing at every arm because every arm is a lone simple REG SET (the N-arm face of the two-arm family at §164-73/§164-74/§13114). Naming the LAST arm's condition and nesting it — `register s32 c __asm__("$2") = (v1 < 0x17C); if (c) { idx = 3; } else { idx = 4; }` — gave that one arm a non-simple-SET body and the chain **de-fused end to end**: every comparison reverted to `slti` + `beqz <next block>` with each arm ending in its own `j <merge>`. `near`, closeness **31**, `LENGTH-DRIFT/2?`, nins 45 vs 43, `detail {"delta":2,"at":12,"explains":"partial"}` — and residual[0] is at **index 12, the FIRST comparison (`v1<0x140`), which the edit never touched**: mine `10400003 beqz v0,40` vs target `1440000c bnez $v0,.L8017FEEC`. Flattening the last arm back to `} else if (v1 < 0x17C) { idx = 3; } else { idx = 4; }` → `match`, closeness 0, 43/43, residual `[]`. **ROUTING / TELL:** a `LENGTH-DRIFT +2` on a constant-select chain whose residual *starts at the chain's first comparison* means an arm downstream stopped being a flat assignment — keep every arm, including the terminal `else`, a single flat assignment, and treat §312's naming lever and any `register __asm__` pin on an arm's condition as contraindicated here (§72/§176-B's "the pin is the wrong tool", and §80's unconditional `qty_phys_sugg` cost, both apply). **⚠ BOUNDS — confounded, n=1, unproven.** (1) The pin, the naming and the nesting all moved in ONE edit; no single-axis ablation was run, so §266's solo-proof bar is not met and the cause is not separated between "a pinned/named condition" and "a nested block in the arm". (2) The mechanism is asserted from the before/after only: the cascade is *consistent with* each arm's collapse being the precondition for the next one outward (an inner arm that keeps its `j` denies the enclosing arm the simple-SET shape jump.c requires), but no `-dj`/`-dS` dump was taken. (3) closeness 0 is per-function masked diff, **not** a banked byte-match, so the RIGHT form is validated only at isolated-compile level.
### Addendum — A plain global-RMW triplet is a fillable scheduling window too — zero drift, and the fille (func_800CB058)
**Addendum (P31 S66, func_800CB058):** The fillable window needs **no long-latency instruction**. Here it is an ordinary global counter RMW — `cnt = D_800CB984++;` expanding to `lui/lw %lo` → `addiu $v1,$v0,1` → `lui/sw %lo` — whose interior sched1 fills with an unrelated `lw $a2,0x20($a0)` (r3000 load ready-delay 2, `mips.md:153-163`, quoted at L20967). So a statement's multi-insn expansion is not atomic to the scheduler even with no `mult`/`div` in the block, and §306's mechanism half (1) should be read as a property of *any* dependence gap, not of the `imuldiv` shadow. **Direction agrees with §306, not §16Xb:** the independent statement must be written **BEFORE** the RMW to sink into it — `fptr = *(s32 *)(p + 0x20);` then `cnt = D_800CB984++;` → MATCH (closeness 0, 78 ins); the reverse order, everything else identical → closeness 16. **New tell for this family — the drift is ZERO.** `nins` is equal both ways, so `match_one` classes it `ADDRESSING`/`li!=addu` over a ~15-19-instruction span rather than §306's `LENGTH-DRIFT +1` (no maspsx `nop`: that splicer is `--expand-div`-only), and ADDRESSING-class churn misroutes a drafter to §164-02's addressing laws instead of to statement order — route it here when the churn straddles a global's read and its store-back. **Two levers, both load-bearing (§266):** the §278/§74 co-pin of `fptr` onto `maska`'s `$6` was necessary but by itself left closeness 16; a zero-byte `__asm__ __volatile__("")` fence at the same spot (§194-A family) *regressed* it to 45 at +1 ins — one more row for §257/§268's barrier/pin dead-end ledger. **Provenance:** distilled from a wave whose byte-gate refused the draft (match_one-masked evidence only), but the identical body has **since banked byte-gate-green** at `src/md_MAIN_033/md_MAIN_033.c:93-131` (commit `commit:3304`, x1 wave, authoritative `make clean && make extract-all && make check-all` = 213/213) — read this addendum as byte-proven, not unproven.
### Addendum — Shared arithmetic that CONSUMES the selected value cannot be hoisted above the `if` — narr (func_80183DA0)
**Addendum (P31 S66, func_80183DA0): ⚠ UNPROVEN — this draft was REFUSED by the whole-binary byte-gate and never reached MATCH (best 27 mismatched, nins 83 vs target 82). Only the relative `match_one` closeness deltas below are asserted; the pass attribution is inference, with no `-dj`/`-dS` dump taken.** §193-C's cure — *"write a shared statement ONCE, above the `if`"* — is **unreachable whenever the duplicated work CONSUMES the value the arms disagree about**, which is the common face of this class in BFM's scaling arithmetic. On `func_80183DA0` the drafted arms were `if (out.vx < 0) val = base - (-out.vx * 0x7F / 0x140); else val = base - (out.vx * 0x7F / 0x140);` — nothing is hoistable above the `if`, because the multiply's operand is exactly what the `if` selects. The tell is §193-C's own, one level in: the **magic-divide head** (`lui $v1,0x6666 / ori $v1,$v1,0x6667 / sll $v0,$a0,7` — the `*0x7F` reciprocal-divide setup, §16N+2's ladder) appears **twice**, once inside each arm, while the target carries it **once** below a single `bltz` merge; the deeper `mult`/`sra`/`mfhi` tail had already merged, exactly as §164-09/§50-B predict — the backward walk breaks at the first `rtx_renumbered_equal_p` failure, here the `sll` whose source register differs per arm. **Nothing was "un-CSE'd": the two arms compute different values, so no common subexpression ever existed** — do not write this up as a CSE failure. **The cure is §165-21's, generalised from a shared trailing STORE to a shared trailing arithmetic CHAIN: narrow the arms to the differing value alone and write the shared computation once below the select** — `val = base - (out.vx < 0 ? -out.vx : out.vx) * 0x7F / 0x140;`. Evidence: `match_one` closeness **53 → 39 at an unchanged nins 81** on that single edit (`agent-ad9135a44913f81b5.jsonl` lines 103 → 109), the largest single-edit drop in the run (62→56→53→39→27). Per §193-C, the length did not move at all — read the duplicated micro-sequence, never the count. **Bounds:** n=1, gate-refused, and the `?:`-vs-`if/else` axis was not separately ablated against §195-F/§167-09's arm-order folds (§267-ADD-5 measured *every* select spelling byte-identical for a bare halfword abs, so the load-bearing edit here is plausibly the narrowing, not the ternary itself — untested).
### REFUTED claim — Dead call-arg register address-fold: no C-level lever found (func_8017ECAC)
**⚠ UNPROVEN — REFUTED AT VET TIME. File under §167z-style "do NOT re-derive"; nothing here is byte-proven (no MATCH, closeness floor 16/31, never sent to the whole-binary gate).**
* **`func_8017ECAC`** — "Dead call-arg register address-fold: gcc-2.7.2 picks the just-dead `$a1` to materialize the address of the FIRST of three sequential global stores; a genuine compiler-internal register-allocation artifact with no C-level lever."
*Why refuted:* **(1) The headline contradicts byte-proven law.** §48-C1 (L3519, 14 micro-probes) states the opposite as a positive rule — *"the C type literally selects the addressing mode … target shows `la` + offsets → declare a struct; target shows plain `lui/%lo` → declare a scalar"* — and §165-10 (L13990) byte-measures **both directions** of this exact two-form choice on one symbol (−9 / −10 ins A/Bs off a MATCH baseline), while §167-45's **PER-SITE, NOT PER-BLOCK** law (L16187) is banked on precisely this shape: *one* global routed through a materialized base while its neighbours keep the plain `%hi/%lo` fold. The class is steerable; L1396-1401's R14 caveat forbids the verdict on this evidence.
**(2) The prescribed lever was never run.** Every probe in the set attacks the *use site* (`*(Blk8*)&D_x`, `s16 *p=&D_x`, `u8 D_x[]`, `*(s16*)&D_x`, a `$5` pin, an `asm("")` barrier, store reordering) or converts **all three** symbols to one struct. §48-C1's construct — a struct-**TYPED** file-scope declaration for the FIRST symbol **only**, `D_801274EA`/`D_801274EC` left bare scalars — is §48-C1 crossed with §167-45's per-site discipline and is absent from the list. A struct **cast** at the use site is a different construct, and L3046-3049 already byte-proves the cast form is address-**neutral** for a write-only global (`lui $at,%hi ; sh $v,%lo($at)`), i.e. that probe was predicted dead before it ran.
**(3) The 8-way plateau is a rediscovery of documented negatives, not a wall.** §48-B (L3508-3510: *"`s16 *p = &G;` is constant-folded straight back by cse's `find_best_addr`"*), its offset-0 corollary (L3515), and §164-52 (L12990: init and uses on ONE cse path with no ≥2-jump-ref label ⇒ the `la` loses its last user and is deleted) predict that the pointer-local, `&`-cast, array-decay and plain-scalar spellings all collapse to the identical direct-macro form. Eight spellings landing on the **same** 16/31 is exactly that prediction, not evidence of an unsteerable residual.
**(4) The "dead call-arg register" framing is over-specific and unsupported.** A scan of all 11,681 stub `.s` for `addiu $rD,$rD,%lo(SYM)` immediately followed by a store at `0($rD)` returns **4** instances: `func_8017ECAC` ($a1), `ov_SC07_007/func_8017DFB8` ($s0), and `ov_MAIN_012` + `ov_SC03_107` `func_8016D1D8` ($v0). In `func_8016D1D8` the base is explained outright by §48-C1 — it serves **two** MEMs (`sb $v1,0x0($v0)` at 8016D2E0 and `sb $v1,-0x1($v0)` at 8016D2F0) while five neighbours (`D_80184892/94/95/96`) keep the `$at` fold, textbook §167-45. The register *identity* is an allocation outcome; it is not a tell, and the previous call's argument register is coincidence at n=1.
*What survives and is worth keeping:* the target reading itself (`asm/ov_SC02_005/nonmatchings/ov_SC02_005_jr_8017CF90/func_8017ECAC.s:19-27` — 3-insn base for `D_801274E8`, 2-insn `$at` folds for `D_801274EA`/`D_801274EC`, LENGTH-DRIFT −1 at idx 15) and the negative-control table (8 spellings, identical 16/31). Next agent: run §48-C1's struct-**typed** declaration on `D_801274E8` alone; there are three banked in-tree references to this record (`src/ov_SC07_009/ov_SC07_009_jr_8017AE2C.c:3933`, `:4038-4040`, `:4070`) to read the fleet-canonical typing off before touching the file-scope decls.
**Why refuted:** Checked §48-C1 (L3519), §48-B + its offset-0 corollary (L3505-3517), §48-C2/§48-C3, §164-52 (L12990), §20's scalar-global-RMW and volatile-reload bullets (L1907-1946), the `*(T*)&D_sym` write-only note (L3046-3049), §165-10 (L13990-14009), §167-45 LAW 1/1a/PER-SITE (L16163-16190), §167-18 (L15496), §167-08 (L15242), §153/§165-26 pointers, §176-A/§176j-2 and §177 (the refs the agent cited), plus §167z's refuted-list format and the R14 discipline line at L1396-1401. Verdict is REFUTED, not NEW/ADDENDUM, on four grounds. (a) Not byte-proven: no MATCH, floor 16/31, never gated — so ADDENDUM's "byte-proven refinement" bar is not met. (b) The submitted law contradicts byte-proven sections: §48-C1's 14 micro-probes make the base-vs-$at addressing mode a C-TYPE choice, §165-10 measures both directions of that same choice on one global, and §167-45 banks the exact per-site shape (one global through a base, neighbours on the plain fold). (c) The prescribed lever was never tried — a struct-TYPED file-scope declaration for D_801274E8 ALONE (§48-C1 × §167-45's per-site rule); the agent tried a struct CAST, which L3046 already byte-proves is address-neutral for a write-only global. (d) The 8-way 16/31 plateau is predicted by §48-B/§164-52 (an all-dereference pointer-to-global on a single cse path folds back to the direct macro), so it is a rediscovery of documented negatives rather than a new wall. I also verified the target myself (asm/ov_SC02_005/.../func_8017ECAC.s:19-27 — the tell is real) and scanned all 11,681 stub .s for the shape: 4 hits, bases $a1/$s0/$v0/$v0, and the ov_MAIN_012 hit (func_8016D1D8:71-75) is a clean §48-C1 counter-example (base serves two MEMs at 0x0 and -0x1 while five neighbours keep $at), which falsifies the "dead call-argument register" half of the tell at n=1. The entry_markdown is written as a §167z-style refutation note that preserves the honest target reading, the negative-control table, and the untried lever plus the three banked in-tree references to the same record.