feat(phase-22): FIRST free-local-model banks — 4 open stubs matched by the v2 LoRA

The fine-tuned 7B (bfm-match-7b-v2) drafted real OPEN ov_SC01_077 stubs; whole-binary gate banked 4
(func_80160B34 func_8015CC74 func_8016084C func_801705C0). Sample: 9/22 match_one proxy -> 4/22
whole-binary banked (18%; the proxy->gate gap is the TU-plumbing wall). Model is format-robust (raw .s
== normalized). api_draft: NORMALIZE_ASM bridge (unused — model handles raw .s) + ghidra_c-empty fix.
This commit is contained in:
Drew T
2026-06-29 21:58:09 -06:00
parent 6a45497a1e
commit b4c312a30c
4 changed files with 216 additions and 172 deletions
+159 -162
View File
@@ -2,7 +2,7 @@
> Generated by `tools/backlog.py render` from `.run/backlog.jsonl`. These are functions the Phase-21 automation got **close** on but did NOT byte-match. The whole-binary byte-gate is the sole arbiter (G3/P9): **byte-matches bank and are NOT listed here** — only genuine near-misses/blockers are. Ranked by hand-session priority: **reach** (×N propagation leverage) → **closeness** (match_one mismatch count, lower = closer) → **size**. Each row's `best_draft` is the closest C the machine reached — resume from there.
**Open near-misses:** 294 · by status {'near': 215, 'failed': 79} · by class {'WAVE': 20, 'plumbing': 43, 'other': 24, 'schedule': 61, 'loose-typing': 7, 'struct': 66, 'regalloc-order': 58, 'remat': 4, 'iv-combine': 3, 'GIANT': 8}
**Open near-misses:** 291 · by status {'near': 215, 'failed': 76} · by class {'WAVE': 19, 'plumbing': 42, 'other': 24, 'schedule': 61, 'loose-typing': 7, 'struct': 63, 'regalloc-order': 58, 'remat': 4, 'STUB': 2, 'iv-combine': 3, 'GIANT': 8}
| # | addr | reach | class | nins | status | closeness | where it stuck | best draft |
|--:|------|------:|-------|-----:|--------|----------:|----------------|------------|
@@ -84,47 +84,47 @@
| 76 | func_80136F3C | 134 | schedule | 61 | near | 10 | 10/61 — regalloc EXACT (param-copy + corner register-pins). residual = gcc list-scheduler permutation of the prologue window (idx 7-16): target saves $s0 before computing xp, sets $s4=0xFF before the D_800B9A02 lhu, and defers xm($s1=$s1-3) to AFTER the lhu; no C-level reorder/barrier reaches it; permuter can't run (pycparser rejects register __asm__). | `.run/backlog_drafts/func_80136F3C.c` |
| 77 | func_80149374 | 134 | remat | 23 | near | 11 | gcc -O2 CSEs &sp18 into freed callee-saved $s0 (1 addu + 2 move); target rematerializes addiu $sp,0x18 twice. Single-buffer straight-line address reused across 2 calls -> CSE wins; no clean C (cast/type/union/ptr-var/$8-pin) flips it; two-distinct-locals remats but grows frame +8 (gcc-2.7.2 won't coalesce slots back to 0x18). Frame/regs/params all match; only this 1 insn differs. | `.run/backlog_drafts/func_80149374.c` |
| 78 | func_8012EFB8 | 134 | other | 32 | near | 11 | none — MATCH (32 ins, byte-verified via objdump -dz; match_one's default objdump elides the 2 consecutive rtps-delay nops as "..." and miscounts 30, but raw bytes are identical) | `.run/backlog_drafts/func_8012EFB8.c` |
| 79 | func_80150528 | 134 | schedule | 53 | near | 12 | none — MATCH (53 ins). Modeled on banked sibling DEFINE_func_80163950 (same D_801202A0 stride-0x10C loop + func_80135A4C call); single-pointer for-loop reproduces gcc's two-IV (p, p+0x20) schedule exactly. NB: §20 had flagged this "unsteerable" pre-sibling-exemplar. | `.run/backlog_drafts/func_80150528.c` |
| 80 | func_80146AFC | 134 | schedule | 40 | near | 13 | none — MATCH | `.run/backlog_drafts/func_80146AFC.c` |
| 81 | func_80131CF4 | 134 | schedule | 29 | near | 15 | 15 mismatches cascade from a 2-instruction gap — target reloads *param_1 (lw v0,0(a0)) into v0 before the loop + a loop-label nop; gcc CSEs the guard-read with the loop-entry read so the pre-loop reload never emits. Top 9 instructions (bnez a0 + j epilogue + shared return-block-at-top) MATCH with this for-form. | `.run/backlog_drafts/func_80131CF4.c` |
| 82 | func_80137178 | 134 | schedule | 78 | near | 15 | reg values all correct; prologue independent-addiu order + lazy sw placement differ | `.run/backlog_drafts/func_80137178.c` |
| 83 | func_8015C030 | 134 | WAVE | 23 | near | 17 | WAVE: 17 mismatch | `.run/backlog_drafts/func_8015C030.c` |
| 84 | func_8014ADE0 | 134 | schedule | 139 | near | 19 | 16 ins off — all compiler-internal ties: (1) 0xAAA8 const lands $v0 vs target $v1; | `.run/backlog_drafts/func_8014ADE0.c` |
| 85 | func_8016191C | 134 | plumbing | 24 | near | 20 | none — MATCH (24 ins). early-return-per-arm: each arm sets $v0 directly + j-tail merges | `.run/backlog_drafts/func_8016191C.c` |
| 86 | func_8014FE60 | 134 | regalloc-order | 95 | near | 20 | none — MATCH (permuter closed the final bothzero-block regalloc/schedule residual: moving `a = in[2]` before the +0x7E read-modify-write flips the 0x7FFF constant into $v1 and computes return-0 in $v0) | `.run/backlog_drafts/func_8014FE60.c` |
| 87 | func_8017248C | 134 | WAVE | 24 | near | 23 | WAVE: 23 mismatch | `.run/backlog_drafts/func_8017248C.c` |
| 88 | func_8014E5B4 | 134 | regalloc-order | 59 | near | 23 | none — MATCH | `.run/backlog_drafts/func_8014E5B4.c` |
| 89 | func_80141B90 | 134 | struct | 29 | near | 24 | none — MATCH (29 ins); array-of-int %lo-fold + call + u16 if-block; volatile-double reserves the target's 8-byte frame slot | `.run/backlog_drafts/func_80141B90.c` |
| 90 | func_801571C4 | 134 | schedule | 198 | near | 24 | body byte-perfect + 9 callee-reg maps + frame 0x60; residual = prologue schedule order + local_40/38 slot swap. permuter fuel | `.run/backlog_drafts/func_801571C4.c` |
| 91 | func_801719A4 | 134 | struct | 24 | near | 25 | none — MATCH (24 ins, relocation-masked) | `.run/backlog_drafts/func_801719A4.c` |
| 92 | func_80144090 | 134 | regalloc-order | 154 | near | 25 | raw close=25: caller-saved temp-reg coalescing in final ring-vertex block (iVar4 mflo->$a3 vs $v0; subu reuses iVar4>>6 reg vs target dead $s0) + 2-ins giv-inc schedule swap — permuter fuel | `.run/drafts-giants/func_80144090.c` |
| 93 | func_8016706C | 134 | WAVE | 30 | near | 27 | WAVE: 27 mismatch | `.run/backlog_drafts/func_8016706C.c` |
| 94 | func_8014D2A0 | 134 | other | 80 | near | 27 | none — MATCH (80 ins, relocation-masked); loop-guard idiom per engine_core DEFINE_func_80164ACC | `.run/backlog_drafts/func_8014D2A0.c` |
| 95 | func_8012F49C | 134 | regalloc-order | 51 | near | 29 | gcc CSEs the two &D_800AF648 into one call-crossing pseudo and allocates it the | `.run/backlog_drafts/func_8012F49C.c` |
| 96 | func_801777BC | 134 | schedule | 59 | near | 29 | body byte-matches; residual ~3 ins = prologue instruction-scheduling (final `sll t8,16` / `lw param_7` / `addu t0,a0,0xC` ordering around the blez guard) + the loop-counter copy `addu t3,v0` — pure gcc sched/regalloc tie-break, permuter-blocked by the register __asm__ pins | `.run/backlog_drafts/func_801777BC.c` |
| 97 | func_80161888 | 134 | schedule | 37 | near | 30 | none — MATCH (proxy verified) | `.run/backlog_drafts/func_80161888.c` |
| 98 | func_80144B14 | 134 | schedule | 34 | near | 31 | none — MATCH (34 ins). Two stack structs (s16[3] each) passed by addr to | `.run/backlog_drafts/func_80144B14.c` |
| 99 | func_8012B77C | 134 | schedule | 58 | near | 33 | gcc instruction-scheduler load-ordering + 1st-ratan2 delay-slot fill differ (s2 subtraction lands early instead of in the delay slot; `lh s1,2(a2)` hoisted ahead of the iVar8 loads). All regs/ops correct (result pinned $s4 reads uninit then RMW-builds the u32; iVar8 unpinned so both halves load to temps -> `subu s5,v1,v0`). Residual is the §20 store-vs-load/delay-slot scheduler tie-break (source reorder/barrier/precompute all tried, do not move it); ~3-4 real slots, count inflated by offset cascade. move==addu rd,rs,zero byte-identical. | `.run/backlog_drafts/func_8012B77C.c` |
| 100 | func_801778A8 | 134 | iv-combine | 38 | near | 38 | gcc spawns 2 IVs (byte giv @+0xc, halfword RMW giv @+0xa); target combines both into ONE IV at +0xc reaching the halfword at -2($a3). A struct collapses to 1 IV but anchors at the struct base (+0xa) not +0xc; raw byte+halfword RMW never combines. Same combine_givs-refuses-halfword-RMW wall as sibling func_80177AD4 (§20, stubbed). Floor 33-off; not source-steerable (combine runs pre-regalloc, pins/order don't move it). | `.run/backlog_drafts/func_801778A8.c` |
| 101 | func_80132784 | 134 | regalloc-order | 400 | near | 40 | HARD-DEFER (R14, byte-evidenced): hoist-vs-remat (else-branch s1m&0xFEFFFFFF + index rematerialized in v0/v1 across the func_80049CAC call — irreducible §10) + register-LIFETIME-reuse: target reuses $s0/$s2 for the GTE pointers AFTER s0p/s2v die, but function-scoped register __asm__ pins reserve $s0/$s2 for the whole fn -> not C-expressible. Too big (400>220) + far (40>30) for the grinder. Needs a lifetime-aware permuter pass or accept as ceiling. | `.run/backlog_drafts/func_80132784.c` |
| 102 | func_8012A1BC | 134 | schedule | 78 | near | 42 | 42/78 — block-copy bytes correct (char[8] => lwl/lwr/swl/swr); residual is gcc's load-hoist split. Target hoists all 9 non-block scalar loads to the top then stores 4, blk, blk, then late-stores the rest; a "memory" barrier is needed to stop the block copy hoisting+spilling but it also pins the 5 late scalars' stores too early. No single source/barrier shape reproduces "loads cross the block copy but the copy itself does not" — permuter/schedule residual. | `.run/backlog_drafts/func_8012A1BC.c` |
| 103 | func_80176144 | 134 | regalloc-order | 53 | near | 50 | none — MATCH | `.run/backlog_drafts/func_80176144.c` |
| 104 | func_8016163C | 134 | plumbing | 78 | near | 50 | none — MATCH (78 ins). First arm calls func_801599A4 with NO arg (asm nop delay slot) via fn-ptr cast ((void(*)(void))func_801599A4)(). | `.run/backlog_drafts/func_8016163C.c` |
| 105 | func_801387B8 | 134 | regalloc-order | 100 | near | 50 | the two scanned bytes land in $a0/$a1 not $a1/$a2 (gcc-2.7.2 grabs the freed incoming-arg $a0 for the first load; a $5 register-asm pin is NOT honored on a load-defined arg-class reg, a $6 pin IS — kept pin-free so the permuter can grind it, costing +1) + gcc basic-block layout of the case-7/case-10/default handlers differs; control-flow semantics correct, 50 mismatch | `.run/backlog_drafts/func_801387B8.c` |
| 106 | func_8014F2E0 | 134 | schedule | 66 | near | 51 | §10 IV-init placement (piVar3 setup not sunk past loop guard) + store-vs-load (D_801150D8=0 schedules between the two arg-loads) — both CONFIRMED-unsteerable per cookbook §20; 11-off | `.run/backlog_drafts/func_8014F2E0.c` |
| 107 | func_80161774 | 134 | plumbing | 69 | near | 53 | none — MATCH (69 ins, match_one verified; clean nested-if; param_1 -> $s0 call-crossing) | `.run/backlog_drafts/func_80161774.c` |
| 108 | func_801770E0 | 134 | schedule | 152 | near | 53 | callee-saved regalloc EXACT (param_2->$s2, iVar6->$s1, uVar5/spill->$s0, consts 3/0xB8/0xFF->$s5/$s4/$s3). | `.run/backlog_drafts/func_801770E0.c` |
| 109 | func_80176D94 | 134 | schedule | 152 | near | 63 | 63/152 — frame+prologue+4 calls+2x(801783D0/801777BC) MATCH (pins $s0=uVar2/$s2=param_2 + CSE-break barrier); residual is GIANT store-block caller-saved temp COLORING ($a2/$a3/$a0/$v1 vs target $t0/$t1/$t2/$a2) + micro-schedule (~70-ins straight line) + 4 delay-slot fills (li a1,4 vs s0-capture). structurally complete, count-exact → permuter/grinder territory. | `.run/backlog_drafts/func_80176D94.c` |
| 110 | func_80177940 | 134 | iv-combine | 101 | near | 65 | prologue+setup (35 ins) byte-match exactly; loop body diverges on gcc loop-invariant hoist ORDERING (scheduler tie-break), the conditional 0x74808080 recompute-vs-hoist, and the tail IV final-value double-move (addu s3,a0,zero; addu v0,s3,zero) + pd+=5 increment placement -- same loop-IV-combine class S20 flags as stub for sibling func_80177AD4. | `.run/backlog_drafts/func_80177940.c` |
| 111 | func_801330E0 | 134 | other | 110 | near | 79 | none — MATCH (110/110 words byte-identical via objcopy raw .text, reloc-masked on jal+%hi/%lo(D_800AF648)). match_one shows "79 mismatched" but that is the objdump zero-run-elision artifact (it collapses the 6 GTE/mult latency nops in display); precedent func_8013E2C4. | `.run/backlog_drafts/func_801330E0.c` |
| 112 | func_8014DD8C | 134 | WAVE | 108 | near | 83 | WAVE: 83 mismatch | `.run/backlog_drafts/func_8014DD8C.c` |
| 113 | func_80137DD4 | 134 | schedule | 129 | near | 107 | regalloc fully matches (frame -0x30; s4/s3/s5=params, s2=mask, s1=ptr w/ in-place +0x24 reuse, s0=acc+reused as 0xff000000); residual is gcc -O2 in-block scheduling not steerable from C: (1) first block emits one-register diff (a3) vs target two-register a0=diff/a1=result + p3 in load-delay slot; (2) signed-char field 0x1f emits `lb` but target `lbu;sll24;sra24` (gcc folds every (s8)/(<<24>>24) form back to lb); (3) ~3 chain-block temp/schedule micro-diffs (lw into a2 vs v1, in-place addu vs t1). | `.run/backlog_drafts/func_80137DD4.c` |
| 114 | func_80148094 | 134 | regalloc-order | 213 | near | 107 | ~39/213 residual (LCS), all in the sVar1>=0x201 clamp blocks: $v0/$v1 mflo regalloc swap + coupled branch-polarity/join-placement (bnez<->beqz) + 2 delay-slot fills (addiu s1,v0,0x400 into 80013F3C slot; sll s1,16 in-place into 2nd ratan2 slot) + early_ret a2-vs-s5 -> permuter/grinder territory | `.run/backlog_drafts/func_80148094.c` |
| 115 | func_801412A8 | 134 | regalloc-order | 198 | near | 154 | 154-mismatch near-miss (198/198 ins, structure+branches exact). Two irreducible gcc residuals: (1) HEAD: held &D_800B9A02 ptr must be init-at-decl to stay in a reg across all 4 prims (correct 198-ins), but that forces gcc to materialize the address at fn entry (2 ins before the branches) vs target's in-body materialization -> shifts the head regalloc cascade; in-body assign re-materializes per-use (172 ins, wrong count) even with the $9 pin. (2) BODY: gcc OFFSET-FOLDS the 4x-unrolled prim stores (p[0..3], p+=4 -> sw at 16/20/24/28 from a fixed base) instead of ADVANCING $t6 (addiu $t6,0x10; sw at 0/4/8/12) like the target; no C form (post-inc, char* advance, =r/0 barrier, r-only barrier) triggers the register-advance. Pins landed p1->$t6/uVar4->$t0/iVar1->$a0/pidx->$t1 (head 0-1,8,14,16-19 exact). | `.run/backlog_drafts/func_801412A8.c` |
| 116 | func_801372B0 | 134 | schedule | 207 | near | 173 | STRUCTURALLY CRACKED from raw Ghidra-C (xHigh, Phase 22): 3D-gizmo/compass HUD drawer — SVEC in@0x10/out@0x18 + GsLINE prim@0x20; 4 axis unit-vectors -> ApplyMatrixSV(D_800AF630+0x18) -> GsSortLine(D_800A6518[D_800B9A02*0x14]) + func_80137030/178. Logic 100% (206/207 ins). Residual = giant scheduler/regalloc last-mile (10 held callee-saved regs; §17 pins place them but gcc list-scheduler orders prologue-saves+materializations differently -> pervasive positional diff). NOT C-steerable to byte-exact; too far for grinder (173>30). Future: focused permuter or accept as ceiling. Draft has the right types/decls/logic + pins as a head-start. | `.run/backlog_drafts/func_801372B0.c` |
| 117 | func_80132784 | 134 | regalloc-order | 400 | near | 240 | 240/400 — prologue+frame+Blk16+both GTE pipelines match through idx114; residual is else-branch pu pointer ($s0) regalloc + GTE-section stack-ptr ($s0-$s5 sp+0x60/0x80/0xA0/0x82/0x84/0x94) allocation (pins hoist them; unpinned picks wrong regs) cascading the tail | `.run/backlog_drafts/func_80132784.c` |
| 118 | func_801745AC | 134 | plumbing | 12 | failed | | none — MATCH (stub: param saved in $s0 across first call, passed to second) | `.run/backlog_drafts/func_801745AC.c` |
| 119 | func_801705C0 | 134 | WAVE | 14 | failed | | won't compile standalone (loose-typing / missing decl) | `.run/backlog_drafts/func_801705C0.c` |
| 79 | func_801745AC | 134 | STUB | 12 | near | 12 | STUB: 12 mismatch | `.run/backlog_drafts/func_801745AC.c` |
| 80 | func_80150528 | 134 | schedule | 53 | near | 12 | none — MATCH (53 ins). Modeled on banked sibling DEFINE_func_80163950 (same D_801202A0 stride-0x10C loop + func_80135A4C call); single-pointer for-loop reproduces gcc's two-IV (p, p+0x20) schedule exactly. NB: §20 had flagged this "unsteerable" pre-sibling-exemplar. | `.run/backlog_drafts/func_80150528.c` |
| 81 | func_80146AFC | 134 | schedule | 40 | near | 13 | none — MATCH | `.run/backlog_drafts/func_80146AFC.c` |
| 82 | func_80131CF4 | 134 | schedule | 29 | near | 15 | 15 mismatches cascade from a 2-instruction gap — target reloads *param_1 (lw v0,0(a0)) into v0 before the loop + a loop-label nop; gcc CSEs the guard-read with the loop-entry read so the pre-loop reload never emits. Top 9 instructions (bnez a0 + j epilogue + shared return-block-at-top) MATCH with this for-form. | `.run/backlog_drafts/func_80131CF4.c` |
| 83 | func_80137178 | 134 | schedule | 78 | near | 15 | reg values all correct; prologue independent-addiu order + lazy sw placement differ | `.run/backlog_drafts/func_80137178.c` |
| 84 | func_8015C030 | 134 | WAVE | 23 | near | 17 | WAVE: 17 mismatch | `.run/backlog_drafts/func_8015C030.c` |
| 85 | func_8014ADE0 | 134 | schedule | 139 | near | 19 | 16 ins off — all compiler-internal ties: (1) 0xAAA8 const lands $v0 vs target $v1; | `.run/backlog_drafts/func_8014ADE0.c` |
| 86 | func_8016191C | 134 | plumbing | 24 | near | 20 | none — MATCH (24 ins). early-return-per-arm: each arm sets $v0 directly + j-tail merges | `.run/backlog_drafts/func_8016191C.c` |
| 87 | func_8014FE60 | 134 | regalloc-order | 95 | near | 20 | none — MATCH (permuter closed the final bothzero-block regalloc/schedule residual: moving `a = in[2]` before the +0x7E read-modify-write flips the 0x7FFF constant into $v1 and computes return-0 in $v0) | `.run/backlog_drafts/func_8014FE60.c` |
| 88 | func_8017248C | 134 | WAVE | 24 | near | 23 | WAVE: 23 mismatch | `.run/backlog_drafts/func_8017248C.c` |
| 89 | func_8014E5B4 | 134 | regalloc-order | 59 | near | 23 | none — MATCH | `.run/backlog_drafts/func_8014E5B4.c` |
| 90 | func_80141B90 | 134 | struct | 29 | near | 24 | none — MATCH (29 ins); array-of-int %lo-fold + call + u16 if-block; volatile-double reserves the target's 8-byte frame slot | `.run/backlog_drafts/func_80141B90.c` |
| 91 | func_801571C4 | 134 | schedule | 198 | near | 24 | body byte-perfect + 9 callee-reg maps + frame 0x60; residual = prologue schedule order + local_40/38 slot swap. permuter fuel | `.run/backlog_drafts/func_801571C4.c` |
| 92 | func_801719A4 | 134 | struct | 24 | near | 25 | none — MATCH (24 ins, relocation-masked) | `.run/backlog_drafts/func_801719A4.c` |
| 93 | func_80144090 | 134 | regalloc-order | 154 | near | 25 | raw close=25: caller-saved temp-reg coalescing in final ring-vertex block (iVar4 mflo->$a3 vs $v0; subu reuses iVar4>>6 reg vs target dead $s0) + 2-ins giv-inc schedule swap — permuter fuel | `.run/drafts-giants/func_80144090.c` |
| 94 | func_8016706C | 134 | WAVE | 30 | near | 27 | WAVE: 27 mismatch | `.run/backlog_drafts/func_8016706C.c` |
| 95 | func_8014D2A0 | 134 | other | 80 | near | 27 | none — MATCH (80 ins, relocation-masked); loop-guard idiom per engine_core DEFINE_func_80164ACC | `.run/backlog_drafts/func_8014D2A0.c` |
| 96 | func_8012F49C | 134 | regalloc-order | 51 | near | 29 | gcc CSEs the two &D_800AF648 into one call-crossing pseudo and allocates it the | `.run/backlog_drafts/func_8012F49C.c` |
| 97 | func_801777BC | 134 | schedule | 59 | near | 29 | body byte-matches; residual ~3 ins = prologue instruction-scheduling (final `sll t8,16` / `lw param_7` / `addu t0,a0,0xC` ordering around the blez guard) + the loop-counter copy `addu t3,v0` — pure gcc sched/regalloc tie-break, permuter-blocked by the register __asm__ pins | `.run/backlog_drafts/func_801777BC.c` |
| 98 | func_80161888 | 134 | schedule | 37 | near | 30 | none — MATCH (proxy verified) | `.run/backlog_drafts/func_80161888.c` |
| 99 | func_80144B14 | 134 | schedule | 34 | near | 31 | none — MATCH (34 ins). Two stack structs (s16[3] each) passed by addr to | `.run/backlog_drafts/func_80144B14.c` |
| 100 | func_8012B77C | 134 | schedule | 58 | near | 33 | gcc instruction-scheduler load-ordering + 1st-ratan2 delay-slot fill differ (s2 subtraction lands early instead of in the delay slot; `lh s1,2(a2)` hoisted ahead of the iVar8 loads). All regs/ops correct (result pinned $s4 reads uninit then RMW-builds the u32; iVar8 unpinned so both halves load to temps -> `subu s5,v1,v0`). Residual is the §20 store-vs-load/delay-slot scheduler tie-break (source reorder/barrier/precompute all tried, do not move it); ~3-4 real slots, count inflated by offset cascade. move==addu rd,rs,zero byte-identical. | `.run/backlog_drafts/func_8012B77C.c` |
| 101 | func_801778A8 | 134 | iv-combine | 38 | near | 38 | gcc spawns 2 IVs (byte giv @+0xc, halfword RMW giv @+0xa); target combines both into ONE IV at +0xc reaching the halfword at -2($a3). A struct collapses to 1 IV but anchors at the struct base (+0xa) not +0xc; raw byte+halfword RMW never combines. Same combine_givs-refuses-halfword-RMW wall as sibling func_80177AD4 (§20, stubbed). Floor 33-off; not source-steerable (combine runs pre-regalloc, pins/order don't move it). | `.run/backlog_drafts/func_801778A8.c` |
| 102 | func_80132784 | 134 | regalloc-order | 400 | near | 40 | HARD-DEFER (R14, byte-evidenced): hoist-vs-remat (else-branch s1m&0xFEFFFFFF + index rematerialized in v0/v1 across the func_80049CAC call — irreducible §10) + register-LIFETIME-reuse: target reuses $s0/$s2 for the GTE pointers AFTER s0p/s2v die, but function-scoped register __asm__ pins reserve $s0/$s2 for the whole fn -> not C-expressible. Too big (400>220) + far (40>30) for the grinder. Needs a lifetime-aware permuter pass or accept as ceiling. | `.run/backlog_drafts/func_80132784.c` |
| 103 | func_8012A1BC | 134 | schedule | 78 | near | 42 | 42/78 — block-copy bytes correct (char[8] => lwl/lwr/swl/swr); residual is gcc's load-hoist split. Target hoists all 9 non-block scalar loads to the top then stores 4, blk, blk, then late-stores the rest; a "memory" barrier is needed to stop the block copy hoisting+spilling but it also pins the 5 late scalars' stores too early. No single source/barrier shape reproduces "loads cross the block copy but the copy itself does not" — permuter/schedule residual. | `.run/backlog_drafts/func_8012A1BC.c` |
| 104 | func_80176144 | 134 | regalloc-order | 53 | near | 50 | none — MATCH | `.run/backlog_drafts/func_80176144.c` |
| 105 | func_8016163C | 134 | plumbing | 78 | near | 50 | none — MATCH (78 ins). First arm calls func_801599A4 with NO arg (asm nop delay slot) via fn-ptr cast ((void(*)(void))func_801599A4)(). | `.run/backlog_drafts/func_8016163C.c` |
| 106 | func_801387B8 | 134 | regalloc-order | 100 | near | 50 | the two scanned bytes land in $a0/$a1 not $a1/$a2 (gcc-2.7.2 grabs the freed incoming-arg $a0 for the first load; a $5 register-asm pin is NOT honored on a load-defined arg-class reg, a $6 pin IS — kept pin-free so the permuter can grind it, costing +1) + gcc basic-block layout of the case-7/case-10/default handlers differs; control-flow semantics correct, 50 mismatch | `.run/backlog_drafts/func_801387B8.c` |
| 107 | func_8014F2E0 | 134 | schedule | 66 | near | 51 | §10 IV-init placement (piVar3 setup not sunk past loop guard) + store-vs-load (D_801150D8=0 schedules between the two arg-loads) — both CONFIRMED-unsteerable per cookbook §20; 11-off | `.run/backlog_drafts/func_8014F2E0.c` |
| 108 | func_80161774 | 134 | plumbing | 69 | near | 53 | none — MATCH (69 ins, match_one verified; clean nested-if; param_1 -> $s0 call-crossing) | `.run/backlog_drafts/func_80161774.c` |
| 109 | func_801770E0 | 134 | schedule | 152 | near | 53 | callee-saved regalloc EXACT (param_2->$s2, iVar6->$s1, uVar5/spill->$s0, consts 3/0xB8/0xFF->$s5/$s4/$s3). | `.run/backlog_drafts/func_801770E0.c` |
| 110 | func_80176D94 | 134 | schedule | 152 | near | 63 | 63/152 — frame+prologue+4 calls+2x(801783D0/801777BC) MATCH (pins $s0=uVar2/$s2=param_2 + CSE-break barrier); residual is GIANT store-block caller-saved temp COLORING ($a2/$a3/$a0/$v1 vs target $t0/$t1/$t2/$a2) + micro-schedule (~70-ins straight line) + 4 delay-slot fills (li a1,4 vs s0-capture). structurally complete, count-exact → permuter/grinder territory. | `.run/backlog_drafts/func_80176D94.c` |
| 111 | func_80177940 | 134 | iv-combine | 101 | near | 65 | prologue+setup (35 ins) byte-match exactly; loop body diverges on gcc loop-invariant hoist ORDERING (scheduler tie-break), the conditional 0x74808080 recompute-vs-hoist, and the tail IV final-value double-move (addu s3,a0,zero; addu v0,s3,zero) + pd+=5 increment placement -- same loop-IV-combine class S20 flags as stub for sibling func_80177AD4. | `.run/backlog_drafts/func_80177940.c` |
| 112 | func_801330E0 | 134 | other | 110 | near | 79 | none — MATCH (110/110 words byte-identical via objcopy raw .text, reloc-masked on jal+%hi/%lo(D_800AF648)). match_one shows "79 mismatched" but that is the objdump zero-run-elision artifact (it collapses the 6 GTE/mult latency nops in display); precedent func_8013E2C4. | `.run/backlog_drafts/func_801330E0.c` |
| 113 | func_8014DD8C | 134 | WAVE | 108 | near | 83 | WAVE: 83 mismatch | `.run/backlog_drafts/func_8014DD8C.c` |
| 114 | func_80137DD4 | 134 | schedule | 129 | near | 107 | regalloc fully matches (frame -0x30; s4/s3/s5=params, s2=mask, s1=ptr w/ in-place +0x24 reuse, s0=acc+reused as 0xff000000); residual is gcc -O2 in-block scheduling not steerable from C: (1) first block emits one-register diff (a3) vs target two-register a0=diff/a1=result + p3 in load-delay slot; (2) signed-char field 0x1f emits `lb` but target `lbu;sll24;sra24` (gcc folds every (s8)/(<<24>>24) form back to lb); (3) ~3 chain-block temp/schedule micro-diffs (lw into a2 vs v1, in-place addu vs t1). | `.run/backlog_drafts/func_80137DD4.c` |
| 115 | func_80148094 | 134 | regalloc-order | 213 | near | 107 | ~39/213 residual (LCS), all in the sVar1>=0x201 clamp blocks: $v0/$v1 mflo regalloc swap + coupled branch-polarity/join-placement (bnez<->beqz) + 2 delay-slot fills (addiu s1,v0,0x400 into 80013F3C slot; sll s1,16 in-place into 2nd ratan2 slot) + early_ret a2-vs-s5 -> permuter/grinder territory | `.run/backlog_drafts/func_80148094.c` |
| 116 | func_801412A8 | 134 | regalloc-order | 198 | near | 154 | 154-mismatch near-miss (198/198 ins, structure+branches exact). Two irreducible gcc residuals: (1) HEAD: held &D_800B9A02 ptr must be init-at-decl to stay in a reg across all 4 prims (correct 198-ins), but that forces gcc to materialize the address at fn entry (2 ins before the branches) vs target's in-body materialization -> shifts the head regalloc cascade; in-body assign re-materializes per-use (172 ins, wrong count) even with the $9 pin. (2) BODY: gcc OFFSET-FOLDS the 4x-unrolled prim stores (p[0..3], p+=4 -> sw at 16/20/24/28 from a fixed base) instead of ADVANCING $t6 (addiu $t6,0x10; sw at 0/4/8/12) like the target; no C form (post-inc, char* advance, =r/0 barrier, r-only barrier) triggers the register-advance. Pins landed p1->$t6/uVar4->$t0/iVar1->$a0/pidx->$t1 (head 0-1,8,14,16-19 exact). | `.run/backlog_drafts/func_801412A8.c` |
| 117 | func_801372B0 | 134 | schedule | 207 | near | 173 | STRUCTURALLY CRACKED from raw Ghidra-C (xHigh, Phase 22): 3D-gizmo/compass HUD drawer — SVEC in@0x10/out@0x18 + GsLINE prim@0x20; 4 axis unit-vectors -> ApplyMatrixSV(D_800AF630+0x18) -> GsSortLine(D_800A6518[D_800B9A02*0x14]) + func_80137030/178. Logic 100% (206/207 ins). Residual = giant scheduler/regalloc last-mile (10 held callee-saved regs; §17 pins place them but gcc list-scheduler orders prologue-saves+materializations differently -> pervasive positional diff). NOT C-steerable to byte-exact; too far for grinder (173>30). Future: focused permuter or accept as ceiling. Draft has the right types/decls/logic + pins as a head-start. | `.run/backlog_drafts/func_801372B0.c` |
| 118 | func_80132784 | 134 | regalloc-order | 400 | near | 240 | 240/400 — prologue+frame+Blk16+both GTE pipelines match through idx114; residual is else-branch pu pointer ($s0) regalloc + GTE-section stack-ptr ($s0-$s5 sp+0x60/0x80/0xA0/0x82/0x84/0x94) allocation (pins hoist them; unpinned picks wrong regs) cascading the tail | `.run/backlog_drafts/func_80132784.c` |
| 119 | func_80174650 | 134 | STUB | 9 | failed | | won't compile standalone (loose-typing / missing decl) | `.run/backlog_drafts/func_80174650.c` |
| 120 | func_8016B91C | 134 | WAVE | 18 | failed | | won't compile standalone (loose-typing / missing decl) | `.run/backlog_drafts/func_8016B91C.c` |
| 121 | func_80156600 | 134 | other | 18 | failed | | none — MATCH (simple counted scan, do-while form per Ghidra-C) | `.run/backlog_drafts/func_80156600.c` |
| 122 | func_801718AC | 134 | WAVE | 22 | failed | | won't compile standalone (loose-typing / missing decl) | `.run/backlog_drafts/func_801718AC.c` |
@@ -180,123 +180,120 @@
| 172 | func_80144B9C | 134 | other | 770 | failed | | -O0 cluster fn (prologue 21F0A003, fp-frame, all locals spilled+reloaded, load-delay nops). match_one compiles -O2 so it CANNOT match this; needs its own per-file -O0 split (Makefile CC1FLAGS:=-O0), like ov_SC01_077_o0.c. Body below is the faithful -O0 source; gate via whole-binary -O0 build only. | `.run/backlog_drafts/func_80144B9C.c` |
| 173 | func_80151944 | 4 | struct | 15 | near | 0 | none — MATCH (fn-pointer table dispatch; array-of-ptr indexing folds %lo) | `.run/backlog_drafts/func_80151944.c` |
| 174 | func_8016039C | 2 | struct | 15 | near | 1 | none — MATCH (function-pointer table dispatch indexed by unsigned-halfword field) | `.run/backlog_drafts/func_8016039C.c` |
| 175 | func_8015CC74 | 2 | struct | 15 | failed | | none — MATCH (analog func_8015BE38 idiom: D_80189354[a0->idx]() with Obj.idx at off 2) | `.run/backlog_drafts/func_8015CC74.c` |
| 176 | func_8015DAF8 | 1 | struct | 15 | near | 0 | none — MATCH (proxy); identical idiom to matched func_8016901C in same overlay | `.run/backlog_drafts/func_8015DAF8.c` |
| 177 | func_801577C8 | 1 | plumbing | 16 | near | 0 | none — MATCH expected (scalar global store + two sequential calls, param preserved across first call) | `.run/backlog_drafts/func_801577C8.c` |
| 178 | func_80178B70 | 1 | struct | 18 | near | 0 | none — MATCH; local ptr p=&D_8018A458 used for store AND (int)p-0xC arg forces $s0-base reuse across call1, param_1 into $s1 | `.run/backlog_drafts/func_80178B70.c` |
| 179 | func_8013373C | 1 | regalloc-order | 18 | near | 0 | none — MATCH (indexed-global int-array %lo-fold + (short)param*4 fuses sll16/sra14; loaded value pinned to $a0/$4 to reuse the param reg instead of $v0) | `.run/backlog_drafts/func_8013373C.c` |
| 180 | func_8017F240 | 1 | regalloc-order | 20 | near | 0 | none — MATCH (base &D_801270D0 pinned to $s0 holds across call; one lui/addiu reused for load+store) | `.run/backlog_drafts/func_8017F240.c` |
| 181 | func_80157D20 | 1 | plumbing | 21 | near | 0 | none — MATCH expected (call, indexed u16-global load as 2nd arg, then call; param_1 saved across all three calls) | `.run/backlog_drafts/func_80157D20.c` |
| 182 | func_80163408 | 1 | struct | 21 | near | 0 | local 8-byte struct copied from D_801D8BB0, &copy passed as 5th arg (s32) | `.run/backlog_drafts/func_80163408.c` |
| 183 | func_80175184 | 1 | struct | 21 | near | 0 | none — MATCH (fnptr-array %lo-fold dispatch; idx = *(u16*)(a0+2) < 2 ? D_8018A1A4[idx]() : func_80175268()) | `.run/backlog_drafts/func_80175184.c` |
| 184 | func_8012F8C8 | 1 | plumbing | 21 | near | 0 | none — MATCH (pending verify) | `.run/backlog_drafts/func_8012F8C8.c` |
| 185 | func_8014FBC0 | 1 | schedule | 22 | near | 0 | none — MATCH (22 ins). Stack-switch primitive: register $sp var, manual save/switch/restore around the call. | `.run/backlog_drafts/func_8014FBC0.c` |
| 186 | func_80178B18 | 1 | other | 22 | near | 0 | none — MATCH | `.run/backlog_drafts/func_80178B18.c` |
| 187 | func_8017B8E8 | 1 | plumbing | 22 | near | 0 | none — MATCH (two inlined unaligned 8-byte memcpy blocks: src[0..7]->D_801DA794, src[8..15]->D_801DA78C) | `.run/backlog_drafts/func_8017B8E8.c` |
| 188 | func_80182988 | 1 | plumbing | 22 | near | 0 | none — MATCH (u16 store of 0xAA10 forces ori, not sign-extended addiu) | `.run/backlog_drafts/func_80182988.c` |
| 189 | func_801320D8 | 1 | schedule | 27 | near | 0 | none — MATCH (27 ins, relocation-masked) | `.run/backlog_drafts/func_801320D8.c` |
| 190 | func_80132144 | 1 | other | 27 | near | 0 | none — MATCH | `.run/backlog_drafts/func_80132144.c` |
| 191 | func_801321B0 | 1 | other | 27 | near | 0 | none — MATCH (match_one 27/27, relocation-masked) | `.run/backlog_drafts/func_801321B0.c` |
| 192 | func_8013221C | 1 | other | 27 | near | 0 | none — MATCH (expected); straight scheduling, one call-crossing local -> $s0 naturally | `.run/backlog_drafts/func_8013221C.c` |
| 193 | func_801609B8 | 1 | struct | 28 | near | 0 | none — MATCH (pending byte-gate); function-pointer table %lo-fold via extern array | `.run/backlog_drafts/func_801609B8.c` |
| 194 | func_801312D0 | 1 | struct | 28 | near | 0 | none — MATCH (unaligned 8-byte memcpy from global; if/else branch layout) | `.run/backlog_drafts/func_801312D0.c` |
| 195 | func_80136C90 | 1 | other | 28 | near | 0 | local char[10] string-literal init -> rodata-template block move (lwl/lwr + swl/swr + lb/sb), 9+1 split | `.run/backlog_drafts/func_80136C90.c` |
| 196 | func_8017E224 | 1 | struct | 29 | near | 0 | none — MATCH (unaligned 8-byte memcpy of global onto stack + cond byte incr) | `.run/backlog_drafts/func_8017E224.c` |
| 197 | func_80165140 | 1 | regalloc-order | 30 | near | 0 | none — MATCH (pin i=$v1/eight=$a0/p=$a2; DON'T pin param — let it self-copy to $a3 first; memcpy 8/4 unaligned) | `.run/backlog_drafts/func_80165140.c` |
| 198 | func_801549F8 | 1 | iv-combine | 31 | near | 0 | none — MATCH (31 ins). Re-tie barrier on the index defeats gcc's pointer-giv | `.run/backlog_drafts/func_801549F8.c` |
| 199 | func_8015E698 | 1 | struct | 31 | near | 0 | none — MATCH (clean -O2 reconstruction; table-of-fnptr indexed by param_1[0]) | `.run/backlog_drafts/func_8015E698.c` |
| 200 | func_8017D98C | 1 | plumbing | 31 | near | 0 | none — MATCH (expected): straight global stores + tail call; const 0x140 reused for two halves | `.run/backlog_drafts/func_8017D98C.c` |
| 201 | func_80182268 | 1 | struct | 31 | near | 0 | none — MATCH (jump-table switch over sign-extended high byte of *(u16*)(a0+0x70); case4 decrements D_801270CC then falls into case3/7's func_8012C218; no default) | `.run/backlog_drafts/func_80182268.c` |
| 202 | func_801602A4 | 1 | struct | 34 | near | 0 | none — MATCH (template = matched twin func_801601E4; lhu+0x8000 == compare, fnptr-table dispatch D_801891B8[*(u16*)a0]() no-arg, then 3-call setup in target order; func_80161208 in else) | `.run/backlog_drafts/func_801602A4.c` |
| 203 | func_801734BC | 1 | struct | 34 | near | 0 | none — MATCH (pending byte-gate); switch-jtbl with no default, 3 short stores + fnptr call | `.run/backlog_drafts/func_801734BC.c` |
| 204 | func_8017D900 | 1 | plumbing | 35 | near | 0 | none — expect MATCH (STUB: ordered global stores + single tail call, sibling of func_8017D840) | `.run/backlog_drafts/func_8017D900.c` |
| 205 | func_8016BEA0 | 1 | other | 37 | near | 0 | none — MATCH (expected) | `.run/backlog_drafts/func_8016BEA0.c` |
| 206 | func_801754A8 | 1 | regalloc-order | 37 | near | 0 | none — MATCH (37 ins, relocation-masked proxy) | `.run/backlog_drafts/func_801754A8.c` |
| 207 | func_80160920 | 1 | struct | 38 | near | 0 | none — MATCH (function-pointer table folds %lo via extern array indexed by halfword) | `.run/backlog_drafts/func_80160920.c` |
| 208 | func_80183BAC | 1 | struct | 41 | near | 0 | switch jump-table dispatch (jtbl_801D9420); verifying case grouping 0,1,2,5,6/3,7/4 emits the target table + tail | `.run/backlog_drafts/func_80183BAC.c` |
| 209 | func_80183C50 | 1 | struct | 41 | near | 0 | none — MATCH (cross-jump exploit §cookbook L1543: dup func_8012C218 into case3/7 + case4 → merged jal;nop) | `.run/backlog_drafts/func_80183C50.c` |
| 210 | func_8015DF34 | 1 | struct | 44 | near | 0 | none — MATCH (clean structural; fn-ptr table via array index folds %lo) | `.run/backlog_drafts/func_8015DF34.c` |
| 211 | func_8015FE70 | 1 | struct | 44 | near | 0 | none — MATCH expected (fn-ptr-table dispatch + ushort struct fields) | `.run/backlog_drafts/func_8015FE70.c` |
| 212 | func_8014358C | 1 | regalloc-order | 45 | near | 0 | none — MATCH (relocation-masked match_one) | `.run/backlog_drafts/func_8014358C.c` |
| 213 | func_80183AF0 | 1 | regalloc-order | 47 | near | 0 | none — MATCH (mask pinned $a1/$5 + p pinned $v0/$2; switch w/ distributed func_8012C218 tail via dup calls + cross-jump merge) | `.run/backlog_drafts/func_80183AF0.c` |
| 214 | func_80178BF8 | 1 | plumbing | 49 | near | 0 | none — MATCH (pure scalar-store + two pointer-decrement do-while loops) | `.run/backlog_drafts/func_80178BF8.c` |
| 215 | func_8015E344 | 1 | struct | 50 | near | 0 | none — MATCH (pending whole-binary gate); fn-ptr table folds %lo via extern array, 0x234 single word store | `.run/backlog_drafts/func_8015E344.c` |
| 216 | func_8017EC7C | 1 | struct | 52 | near | 0 | none — MATCH (52 ins, relocation-masked) | `.run/backlog_drafts/func_8017EC7C.c` |
| 217 | func_80183CF4 | 1 | struct | 57 | near | 0 | none — MATCH (clean switch + jtbl; orchestrator owns jtbl/rodata migration) | `.run/backlog_drafts/func_80183CF4.c` |
| 218 | func_8015D01C | 1 | regalloc-order | 58 | near | 0 | none — MATCH | `.run/backlog_drafts/func_8015D01C.c` |
| 219 | func_8016D688 | 1 | struct | 60 | near | 0 | none — MATCH (byte array D_801D9C20[] folds the &D_801D9C21 base/-1 offsets; emit p+0xE store BEFORE the param+2 increment so the lhu fills the load-delay slot in $v1) | `.run/backlog_drafts/func_8016D688.c` |
| 220 | func_801842C8 | 1 | plumbing | 62 | near | 0 | none — MATCH | `.run/backlog_drafts/func_801842C8.c` |
| 221 | func_80165240 | 1 | regalloc-order | 63 | near | 0 | none — MATCH (63 ins). buf pinned to $s2 (register __asm__("$18")) so it stays in a callee-saved reg; param_3 then naturally lands in $s3. memcpy(buf+0x30,param_3,4) -> lwl/lwr+swl/swr unaligned 4B copy (cookbook §1 mem->mem). array-of-u8 buf with explicit *(T*)(buf+off) stores; mtx[0x20] declared 2nd so it lands at sp+0x50, buf_ at sp+0x10. | `.run/backlog_drafts/func_80165240.c` |
| 222 | func_8017BB34 | 1 | struct | 65 | near | 0 | none — MATCH (65 ins). Keys: (1) align-1 {s8 b[8]} struct so the two 8-byte copies emit lwl/lwr; (2) stack-local declaration order = target frame order (svin@0x10, buf@0x18, out@0x38, local8@0x40, rt_in@0x48, rt_out@0x50) — reordering the locals to ascending offset fixed all 23 offset-only diffs. | `.run/backlog_drafts/func_8017BB34.c` |
| 223 | func_8016BD78 | 1 | regalloc-order | 74 | near | 0 | none — MATCH (lazy pointer locals pa=&BC4, pb=&BC8 assigned at first use → $a1/$a2 held thru middle code as final call args; middle bytes BC5/BC6/BC9/BCA direct global) | `.run/backlog_drafts/func_8016BD78.c` |
| 224 | func_8016E7C8 | 1 | regalloc-order | 74 | near | 0 | none — MATCH (match_one 74/74; pins $18=&prim, $19=param_3 fixed s2/s3 alloc order; Work struct sized to 0x20) | `.run/backlog_drafts/func_8016E7C8.c` |
| 225 | func_8018281C | 1 | struct | 76 | near | 0 | none — MATCH (76 ins). jtbl forced via explicit case 4/6 (count>=5 over MIPS tablejump threshold); case-5 block placed between if-block and default via goto so the if-block emits j default w/ e2=0 in the delay slot | `.run/backlog_drafts/func_8018281C.c` |
| 226 | func_8016AE5C | 1 | regalloc-order | 85 | near | 0 | none — MATCH (85 ins, match_one). switch/jtbl STRUCT fn. The tail's | `.run/backlog_drafts/func_8016AE5C.c` |
| 227 | func_80182E7C | 1 | struct | 85 | near | 0 | none — MATCH (85 ins, relocation-masked). Two switch-codegen levers: | `.run/backlog_drafts/func_80182E7C.c` |
| 228 | func_8015C7E4 | 1 | struct | 88 | near | 0 | none — MATCH (match_one 88/88); fn-ptr-array dispatch, top-level if/else needed branch-polarity invert (small block falls through, big block at L854) | `.run/backlog_drafts/func_8015C7E4.c` |
| 229 | func_8015CA28 | 1 | schedule | 91 | near | 0 | none — MATCH (goto forces the func_80161240 block to the function tail; bnez-to-end layout vs early-return fall-through) | `.run/backlog_drafts/func_8015CA28.c` |
| 230 | func_801820DC | 1 | struct | 94 | near | 0 | none — MATCH (switch on entity state at 0x34, inner jtbl on (s8)(u70>>8)) | `.run/backlog_drafts/func_801820DC.c` |
| 231 | func_80184D50 | 1 | schedule | 98 | near | 0 | none — MATCH (98 ins, relocation-masked) | `.run/backlog_drafts/func_80184D50.c` |
| 232 | func_80161D20 | 1 | struct | 14 | near | 1 | none — MATCH (array-of-u16 %lo-fold, §18) | `.run/backlog_drafts/func_80161D20.c` |
| 233 | func_8015FAAC | 1 | struct | 15 | near | 1 | none — MATCH expected; fn-ptr table indexed by u16 field at +2, *4 scaled load then jalr | `.run/backlog_drafts/func_8015FAAC.c` |
| 234 | func_8016084C | 1 | struct | 15 | near | 1 | none — MATCH (jump-table dispatch via array-of-fn-ptr %lo-fold) | `.run/backlog_drafts/func_8016084C.c` |
| 235 | func_8017F714 | 1 | plumbing | 27 | near | 1 | none — MATCH (27/27 ins, match_one verified) | `.run/backlog_drafts/func_8017F714.c` |
| 236 | func_80142A10 | 1 | struct | 28 | near | 1 | none — MATCH (pending byte-gate) | `.run/backlog_drafts/func_80142A10.c` |
| 237 | func_80161C24 | 1 | struct | 29 | near | 1 | none — MATCH (array-of-struct %lo-fold; even/odd u16 fields at off 0/2, stride 4) | `.run/backlog_drafts/func_80161C24.c` |
| 238 | func_80184C0C | 1 | struct | 48 | near | 1 | none — MATCH (array-of-struct %lo-fold for &D_8018AEB8[idx], stride 0x34) | `.run/backlog_drafts/func_80184C0C.c` |
| 239 | func_8016B4F8 | 1 | regalloc-order | 50 | near | 1 | none — MATCH | `.run/backlog_drafts/func_8016B4F8.c` |
| 240 | func_801803B0 | 1 | other | 51 | near | 1 | none — MATCH expected; simple if/else, no call-crossing locals beyond param in $s0 | `.run/backlog_drafts/func_801803B0.c` |
| 241 | func_8015FBE0 | 1 | schedule | 58 | near | 1 | none — MATCH | `.run/backlog_drafts/func_8015FBE0.c` |
| 242 | func_8017F114 | 1 | regalloc-order | 75 | near | 1 | none — MATCH | `.run/backlog_drafts/func_8017F114.c` |
| 243 | func_8017F290 | 1 | regalloc-order | 86 | near | 2 | none — MATCH. Two levers: (1) hold &D_801270CC in a `int *state` local so its | `.run/backlog_drafts/func_8017F290.c` |
| 244 | func_8016EC0C | 1 | schedule | 88 | near | 2 | none — MATCH (88 ins). Sparse switch(uVar2) = gcc's beq-pivot+slti comparison | `.run/backlog_drafts/func_8016EC0C.c` |
| 245 | func_80171B4C | 1 | schedule | 70 | near | 3 | 3-off in the tail only (body+prologue MATCH via $s1 pin on arg1). gcc fills the | `.run/backlog_drafts/func_80171B4C.c` |
| 246 | func_80140E6C | 1 | schedule | 37 | near | 4 | 4 ins — each save-across-call copy (move s1,v0 / move s0,v0) should fill the NEXT jal's delay slot (target) but gcc-2.7.2 sched ties the copy with the next call's arg-setup at priority 2 and the LUID tie-break (rank_for_schedule) keeps the copy first, so reorg fills the slot with the arg-setup instead; no C reshape found that flips the LUID/priority order without breaking the OR-chain regalloc. | `.run/backlog_drafts/func_80140E6C.c` |
| 247 | func_8017EF50 | 1 | schedule | 53 | near | 5 | 5 ins — gcc-2.7.2 instr-scheduler load-order tie-breaks. Branch region + cross-jump-break (t14 pin to $3) + 0x34/0x30 hoist (c34 pin $5, c2c pin $3) all MATCH. Residual: (a) header 0x10-load vs 0x2c-load order swap; (b) compare loads 0x36-before-0xA and puts 0xA in $a1 not $a2 (slt operand reg differs). Both clusters resist source steering — every fix to one perturbs the pinned header schedule. | `.run/backlog_drafts/func_8017EF50.c` |
| 248 | func_8014D3E0 | 1 | other | 22 | near | 6 | none — MATCH | `.run/backlog_drafts/func_8014D3E0.c` |
| 249 | func_8013CF68 | 1 | schedule | 63 | near | 6 | blocks 2&3 delay-slot fill — gcc picks dead-reg $v1(b0,0x10/0x20) store for the jal delay slot; target picks arg-reg $a3(0x12/0x22). 6 ins (2 rotations); not flippable by source store-order/interleave/barrier (all tested); permuter/scheduler-internal lever needed. Prologue, $s0 fold, regalloc, block-1 all exact. | `.run/backlog_drafts/func_8013CF68.c` |
| 250 | func_8017B940 | 1 | struct | 63 | near | 6 | none — MATCH | `.run/backlog_drafts/func_8017B940.c` |
| 251 | func_8017B238 | 1 | regalloc-order | 76 | near | 6 | 6 ins — gcc coalesces param_2 into callee-saved $s0 and hoists `move $s0,$a1` | `.run/backlog_drafts/func_8017B238.c` |
| 252 | func_8017B614 | 1 | regalloc-order | 101 | near | 6 | 6 ins — param_2 lands in callee-saved $s0 (entry `move s0,a1`, sltiu/sll read s0) vs target's $a1; gcc prefers s0 (saved anyway for the late p794/p78C copies) over caller-saved $a1. Body+schedule otherwise byte-exact (101/101 ins); the late-part `__asm__("")` barrier is load-bearing (fixes the const-store schedule, 21->6). | `.run/backlog_drafts/func_8017B614.c` |
| 253 | func_801345F8 | 1 | schedule | 106 | near | 7 | 7 ins, all pure scheduling order — maskedp copy not sunk into bnez delay slot | `.run/backlog_drafts/func_801345F8.c` |
| 254 | func_80164E40 | 1 | struct | 25 | near | 8 | none — MATCH expected; byte 0 keeps base $v1 (reused by final lw word), bytes 1/2 standalone | `.run/backlog_drafts/func_80164E40.c` |
| 255 | func_8016E9EC | 1 | schedule | 53 | near | 11 | 11 left — all GNU scheduler/canon tie-breaks (regs all match via pins): (a) prologue hoists `addiu a1,0x1C` into the save block; (b) first lbu reads $a0 not $s1 (incoming-arg still live); (c) iCopy copy `addu s4,s0` lands early (scheduler) vs target's func_800D2CA8 delay-slot; (d) `addu a2,s2,s3` vs target `s3,s2` commutative-canon (unflippable w/o breaking load order). Permuter can't run (register __asm__ pins rejected, cookbook §5a). | `.run/backlog_drafts/func_8016E9EC.c` |
| 256 | func_80156044 | 1 | struct | 74 | near | 12 | none — MATCH (74 ins, relocation-masked); $s2-pin for u16-return + def-mask + 3-arg cast on func_80156848 | `.run/backlog_drafts/func_80156044.c` |
| 257 | func_80161CD0 | 1 | regalloc-order | 20 | near | 14 | param_2 must survive the call in $s0; try plain C first then pin to $16 | `.run/backlog_drafts/func_80161CD0.c` |
| 258 | func_80158FA4 | 1 | schedule | 51 | near | 17 | target keeps a DEAD `sra $a1,$v0,16` before `beqz $a1` (sign-extend of func_80159464's | `.run/backlog_drafts/func_80158FA4.c` |
| 259 | func_8018301C | 1 | plumbing | 28 | near | 24 | none — MATCH (straight-line, statement-order; verify with match_one) | `.run/backlog_drafts/func_8018301C.c` |
| 260 | func_8016BBE0 | 1 | other | 56 | near | 24 | none — straightforward; expect MATCH (mirror Ghidra-C order, synth_mult ×0x555) | `.run/backlog_drafts/func_8016BBE0.c` |
| 261 | func_8016E95C | 1 | regalloc-order | 36 | near | 25 | none — MATCH (pending byte-gate) | `.run/backlog_drafts/func_8016E95C.c` |
| 262 | func_80139BE0 | 1 | loose-typing | 39 | near | 32 | target has redundant andi a1,v0,0xff (uchar zero-extend) gcc proves away; else identical | `.run/backlog_drafts/func_80139BE0.c` |
| 263 | func_80148E54 | 1 | regalloc-order | 67 | near | 40 | 67/67 ins, structure+branches+block-order+body-reload all match; residual is pure register-allocation order (permuter-eligible, no register-pins). (1) masked first-angle folds andi->$s1; target keeps it in $a0 then copies addu $s1,$a0 lazily into the beq delay-slot (the s1-copy schedules 1 slot later). (2) the 0x80 const is CSE-held in $a2 across both test+body; target re-materializes 0x80 in $v0 per block (it gets clobbered by `srl v0,v1,8`), which both renames the compare regs ($v0 not $a2) AND fills the body's reload load-delay slot (mine emits a nop there). (3) single-exit ret funnels $v1->$v0 (move v0,v1) where target writes $v0 directly. All three are gcc regalloc/value-prop tie-breaks no C reshape steered (tried: $v0 pin, temp-split, low-mask-reuse compare, memory-clobber-vs-volatile reload) — leave for the permuter. | `.run/backlog_drafts/func_80148E54.c` |
| 264 | func_8017B0E4 | 1 | other | 61 | near | 51 | none — MATCH (expected; clean six-call sign-extend-store pattern) | `.run/backlog_drafts/func_8017B0E4.c` |
| 265 | func_80166F58 | 1 | schedule | 69 | near | 55 | regs/loop/logic/%lo-fold all match (pinned $s0-$s6); residual is reorg.c delay-slot fill — target replicates `addiu $v0,$s2,1` into the 3 skip-branch delay slots + commits `addu $s2,$v0,0` at merge (my codegen emits in-place `addiu $s2,$s2,1` w/ nop slots, -1 ins); plus prologue short-arg promote-then-move not fusing (`sra $a1;addu $s4,$a1,0` vs my fused `sra $s4,$a1`). Not source-steerable (pins block permuter). | `.run/backlog_drafts/func_80166F58.c` |
| 266 | func_80177DA8 | 1 | remat | 63 | near | 58 | gcc narrows `&0xfffffeff` on a 16-bit (lhu) value to `andi 0xfeff` (inline), but target hoisted -0x101 into $t4 (and-reg) in the loop preheader — a gcc-2.7.2 LICM-before-combine pass-ordering quirk unsteerable from C; that 1-ins gap cascades the constant-reg numbering + tail reassoc. Secondary: single-IV loop ptr anchors at +0xA (short, 2 accesses) not +0xC (byte) like target. | `.run/backlog_drafts/func_80177DA8.c` |
| 267 | func_80141A60 | 1 | other | 76 | near | 63 | none — MATCH (76 ins, relocation-masked). Body byte-identical; target reserves an 8-byte | `.run/backlog_drafts/func_80141A60.c` |
| 268 | func_801457A4 | 1 | other | 79 | near | 74 | MATCH at -O0 (79 ins, reloc-masked, real -O0 flags). BANKING BLOCKER: this -O0 fn lives in the -O2 main ov_SC01_077.c; needs its own §18 -O0 split at 0x801457A4 (existing _o0.c covers 0x8013B568..0x8013C98C only). match_one is -O2 -> WRONG here. | `.run/backlog_drafts/func_801457A4.c` |
| 269 | func_8016B6BC | 1 | schedule | 94 | near | 80 | 12-off, all in the last 12 ins (tail). First 82 ins byte-match. Target materializes | `.run/backlog_drafts/func_8016B6BC.c` |
| 270 | func_80134A74 | 1 | regalloc-order | 107 | near | 84 | structure + all 8 callee-saved regs (s0..s7) + block layout MATCH; residual is caller-saved-temp | `.run/backlog_drafts/func_80134A74.c` |
| 271 | func_8013EE10 | 1 | struct | 94 | near | 86 | none — MATCH (94 ins). array-of-struct %lo-fold (E[]) for the 5-elt loops; | `.run/backlog_drafts/func_8013EE10.c` |
| 272 | func_80160B34 | 1 | struct | 15 | failed | | none — MATCH | `.run/backlog_drafts/func_80160B34.c` |
| 273 | func_80182338 | 1 | other | 26 | failed | | none — straight-line init; rely on gcc scheduler to hoist $a1/$v0=6 into prologue/delay-slot | `.run/backlog_drafts/func_80182338.c` |
| 274 | func_80184A68 | 1 | regalloc-order | 33 | failed | | none — MATCH | `.run/backlog_drafts/func_80184A68.c` |
| 275 | func_8015E018 | 1 | loose-typing | 47 | failed | | none — MATCH (signed char forces lbu+sll24/sra24 sign-extend; default char is unsigned in this toolchain) | `.run/backlog_drafts/func_8015E018.c` |
| 276 | func_80159A20 | 1 | struct | 58 | failed | | none — MATCH. Key lever: block tail-MERGE (gcc shared `bne ...,$L1` cross-jump) by making the two return-tests STRUCTURALLY DIFFERENT — positive `if(==){goto mask;} return;` per branch (not `if(!=) return;`), so neither tail can merge. Then fix block ORDER by inverting the outer test (`if(d!=1)` makes the ==4/return path the inline fall-through, the d==1/p[2] path the forward `beq`-target block — matching the target layout). | `.run/backlog_drafts/func_80159A20.c` |
| 277 | func_8013E958 | 1 | schedule | 63 | failed | | 2 ins swapped — cc1 emits `andi 0x7f; andi 0xff; beqz`(tests doubly-masked) but target wants `andi 0x7f; beqz; andi 0xff`(andi 0xff in the first beqz delay slot). Loop fully byte-matches; struct/ptr fold idioms nailed (D_80115110.q[0x16] hoists base+0x58 disp, Cell D_80115188[i].v folds %lo). func_800D0488 takes (m&0xFF) arg. s16 m -> 2 mism (right ins count); s32 m fixes order but merges andi+arg-move (62 ins, 1 short). | `.run/backlog_drafts/func_8013E958.c` |
| 278 | func_8013E83C | 1 | plumbing | 71 | failed | | none — MATCH (scalar global stores + 2 conditional calls; §3-T4 branch-polarity invert on the &0xFF test) | `.run/backlog_drafts/func_8013E83C.c` |
| 279 | func_8017B368 | 1 | schedule | 74 | failed | | dead table-path off by 1 ins — target keeps src*16 live in $s0 & computes 2nd arg src16+(base+8) in call1 delay slot; every C form either folds to e+8 (73 ins) or CSEs base into an extra saved reg $s2 (75 ins). All live code (prologue, sltiu dispatch, copy path, 4 struct-copy stores, tail) matches; only the unreachable func_8012F214 path scheduling diverges. | `.run/backlog_drafts/func_8017B368.c` |
| 280 | func_80180B64 | 1 | struct | 75 | failed | | none — MATCH (75 ins, relocation-masked) | `.run/backlog_drafts/func_80180B64.c` |
| 281 | func_80180F10 | 1 | schedule | 75 | failed | | none — MATCH (aggregate-initializer form schedules const setup after the prologue saves) | `.run/backlog_drafts/func_80180F10.c` |
| 282 | func_8016C188 | 1 | schedule | 79 | failed | | none — MATCH (79 ins, match_one). Levers: invert if to if(iVar1!=0){big}else{small} | `.run/backlog_drafts/func_8016C188.c` |
| 283 | func_80164930 | 1 | regalloc-order | 81 | failed | | none — MATCH (81 ins, relocation-masked) | `.run/backlog_drafts/func_80164930.c` |
| 284 | func_801418F8 | 1 | loose-typing | 90 | failed | | none — MATCH (90 ins). Keys: D_8011511A is `volatile u16` (store-2-then-read must NOT const-fold), read ONCE into a `u16` local t (an `unsigned int` local adds a stray andi 0xffff; reusing t feeds the single lhu to both sltiu and t-3), and the lone D_80115158 store after the if yields the delay-slot-fill-from-target dup of `addiu 0x106`. | `.run/backlog_drafts/func_801418F8.c` |
| 285 | func_801789AC | 1 | struct | 91 | failed | | none — MATCH (91 ins, relocation-masked) | `.run/backlog_drafts/func_801789AC.c` |
| 286 | func_80183DE0 | 1 | regalloc-order | 91 | failed | | testing if(!=1) layout + counter-before-pointer init order | `.run/backlog_drafts/func_80183DE0.c` |
| 287 | func_80185428 | 1 | struct | 94 | failed | | none — MATCH (94 ins, relocation-masked) | `.run/backlog_drafts/func_80185428.c` |
| 288 | func_801506A4 | 1 | loose-typing | 95 | failed | | none — MATCH (95 ins). switch var must be int not u16 (u16 adds andi 0xffff promotion mask) | `.run/backlog_drafts/func_801506A4.c` |
| 289 | func_8016BFD0 | 1 | struct | 95 | failed | | none — MATCH (95 ins). memcpy(d,s,4) -> lwl/lwr/swl/swr; MATRIX work buf as s32[16] (0x40, fills 0x10-0x4f, t[] = buf[5..7]); two SVECTOR locals at 0x50/0x58; natural saved-reg order s0=param_5/s1=param_4/s2=iVar5 | `.run/backlog_drafts/func_8016BFD0.c` |
| 290 | func_801596F0 | 1 | struct | 97 | failed | | none — MATCH (97 ins). Loop 1 = struct-ptr for-loop (E38, flag@+4) -> -4 guard / +4 test via gcc biv-elim. Loop 2 needed an EXPLICIT if-guard + do-while with the FIELD pointer as the loop var (so the giv init emits FIRST in the preheader, before the &D invariant block), a non-volatile re-tie barrier on d=&D_800AFAE8 (keeps &D BARE so +4/+0x88 add off it = +1 ins vs the folded %lo, matching target), an explicit u32 mask hoisted first (fills the guard's delay slot), and a separate range check fp<d+4 // fp>=d+0x88. | `.run/backlog_drafts/func_801596F0.c` |
| 291 | func_8017B490 | 1 | schedule | 97 | failed | | none — MATCH (97 ins). Keys: (1) inverted if so the SV4 block-copy else is fallthrough and block A is bnez-far (cond = (u32)&D_801DA73C >= 0xB, a relocated-symbol compare gcc can't fold); (2) SV4{s16 a,b,c,d} align-2 8-byte copy -> lwl/lwr/swl/swr, locals at sp+0x10/0x18; (3) the DEAD block-A index = (s32)&D_801DA73C into D_8018A45C[] (WAVE16=two SV4) needs BOTH source addrs (&[idx].v0,&[idx].v1) in EXPLICIT TEMPS before call1 so base (&D_8018A45C) dies pre-call -> temp $v0 (not callee-saved), forcing the natural 2-reg alloc idx=$s0/param_1=$s1 + src2 into call1's delay slot; (4) tail: D_801DA794/D_801DA78C are SV4, re-read .a/.b/.c via lh sign-extended to s32 stores. | `.run/backlog_drafts/func_8017B490.c` |
| 292 | func_80182C9C | 1 | schedule | 101 | failed | | none — MATCH (101 ins). Inner-switch break-to-shared-tail must be written as | `.run/backlog_drafts/func_80182C9C.c` |
| 293 | func_80183FB8 | 1 | loose-typing | 101 | failed | | none — MATCH (relocation-masked match_one, 101/101 ins) | `.run/backlog_drafts/func_80183FB8.c` |
| 294 | func_8013EF88 | 1 | struct | 108 | failed | | none — MATCH (108 ins). Keys: (1) §18 array-of-struct E4{s32 v} for | `.run/backlog_drafts/func_8013EF88.c` |
| 175 | func_8015DAF8 | 1 | struct | 15 | near | 0 | none — MATCH (proxy); identical idiom to matched func_8016901C in same overlay | `.run/backlog_drafts/func_8015DAF8.c` |
| 176 | func_801577C8 | 1 | plumbing | 16 | near | 0 | none — MATCH expected (scalar global store + two sequential calls, param preserved across first call) | `.run/backlog_drafts/func_801577C8.c` |
| 177 | func_80178B70 | 1 | struct | 18 | near | 0 | none — MATCH; local ptr p=&D_8018A458 used for store AND (int)p-0xC arg forces $s0-base reuse across call1, param_1 into $s1 | `.run/backlog_drafts/func_80178B70.c` |
| 178 | func_8013373C | 1 | regalloc-order | 18 | near | 0 | none — MATCH (indexed-global int-array %lo-fold + (short)param*4 fuses sll16/sra14; loaded value pinned to $a0/$4 to reuse the param reg instead of $v0) | `.run/backlog_drafts/func_8013373C.c` |
| 179 | func_8017F240 | 1 | regalloc-order | 20 | near | 0 | none — MATCH (base &D_801270D0 pinned to $s0 holds across call; one lui/addiu reused for load+store) | `.run/backlog_drafts/func_8017F240.c` |
| 180 | func_80157D20 | 1 | plumbing | 21 | near | 0 | none — MATCH expected (call, indexed u16-global load as 2nd arg, then call; param_1 saved across all three calls) | `.run/backlog_drafts/func_80157D20.c` |
| 181 | func_80163408 | 1 | struct | 21 | near | 0 | local 8-byte struct copied from D_801D8BB0, &copy passed as 5th arg (s32) | `.run/backlog_drafts/func_80163408.c` |
| 182 | func_80175184 | 1 | struct | 21 | near | 0 | none — MATCH (fnptr-array %lo-fold dispatch; idx = *(u16*)(a0+2) < 2 ? D_8018A1A4[idx]() : func_80175268()) | `.run/backlog_drafts/func_80175184.c` |
| 183 | func_8012F8C8 | 1 | plumbing | 21 | near | 0 | none — MATCH (pending verify) | `.run/backlog_drafts/func_8012F8C8.c` |
| 184 | func_8014FBC0 | 1 | schedule | 22 | near | 0 | none — MATCH (22 ins). Stack-switch primitive: register $sp var, manual save/switch/restore around the call. | `.run/backlog_drafts/func_8014FBC0.c` |
| 185 | func_80178B18 | 1 | other | 22 | near | 0 | none — MATCH | `.run/backlog_drafts/func_80178B18.c` |
| 186 | func_8017B8E8 | 1 | plumbing | 22 | near | 0 | none — MATCH (two inlined unaligned 8-byte memcpy blocks: src[0..7]->D_801DA794, src[8..15]->D_801DA78C) | `.run/backlog_drafts/func_8017B8E8.c` |
| 187 | func_80182988 | 1 | plumbing | 22 | near | 0 | none — MATCH (u16 store of 0xAA10 forces ori, not sign-extended addiu) | `.run/backlog_drafts/func_80182988.c` |
| 188 | func_801320D8 | 1 | schedule | 27 | near | 0 | none — MATCH (27 ins, relocation-masked) | `.run/backlog_drafts/func_801320D8.c` |
| 189 | func_80132144 | 1 | other | 27 | near | 0 | none — MATCH | `.run/backlog_drafts/func_80132144.c` |
| 190 | func_801321B0 | 1 | other | 27 | near | 0 | none — MATCH (match_one 27/27, relocation-masked) | `.run/backlog_drafts/func_801321B0.c` |
| 191 | func_8013221C | 1 | other | 27 | near | 0 | none — MATCH (expected); straight scheduling, one call-crossing local -> $s0 naturally | `.run/backlog_drafts/func_8013221C.c` |
| 192 | func_801609B8 | 1 | struct | 28 | near | 0 | none — MATCH (pending byte-gate); function-pointer table %lo-fold via extern array | `.run/backlog_drafts/func_801609B8.c` |
| 193 | func_801312D0 | 1 | struct | 28 | near | 0 | none — MATCH (unaligned 8-byte memcpy from global; if/else branch layout) | `.run/backlog_drafts/func_801312D0.c` |
| 194 | func_80136C90 | 1 | other | 28 | near | 0 | local char[10] string-literal init -> rodata-template block move (lwl/lwr + swl/swr + lb/sb), 9+1 split | `.run/backlog_drafts/func_80136C90.c` |
| 195 | func_8017E224 | 1 | struct | 29 | near | 0 | none — MATCH (unaligned 8-byte memcpy of global onto stack + cond byte incr) | `.run/backlog_drafts/func_8017E224.c` |
| 196 | func_80165140 | 1 | regalloc-order | 30 | near | 0 | none — MATCH (pin i=$v1/eight=$a0/p=$a2; DON'T pin param — let it self-copy to $a3 first; memcpy 8/4 unaligned) | `.run/backlog_drafts/func_80165140.c` |
| 197 | func_801549F8 | 1 | iv-combine | 31 | near | 0 | none — MATCH (31 ins). Re-tie barrier on the index defeats gcc's pointer-giv | `.run/backlog_drafts/func_801549F8.c` |
| 198 | func_8015E698 | 1 | struct | 31 | near | 0 | none — MATCH (clean -O2 reconstruction; table-of-fnptr indexed by param_1[0]) | `.run/backlog_drafts/func_8015E698.c` |
| 199 | func_8017D98C | 1 | plumbing | 31 | near | 0 | none — MATCH (expected): straight global stores + tail call; const 0x140 reused for two halves | `.run/backlog_drafts/func_8017D98C.c` |
| 200 | func_80182268 | 1 | struct | 31 | near | 0 | none — MATCH (jump-table switch over sign-extended high byte of *(u16*)(a0+0x70); case4 decrements D_801270CC then falls into case3/7's func_8012C218; no default) | `.run/backlog_drafts/func_80182268.c` |
| 201 | func_801602A4 | 1 | struct | 34 | near | 0 | none — MATCH (template = matched twin func_801601E4; lhu+0x8000 == compare, fnptr-table dispatch D_801891B8[*(u16*)a0]() no-arg, then 3-call setup in target order; func_80161208 in else) | `.run/backlog_drafts/func_801602A4.c` |
| 202 | func_801734BC | 1 | struct | 34 | near | 0 | none — MATCH (pending byte-gate); switch-jtbl with no default, 3 short stores + fnptr call | `.run/backlog_drafts/func_801734BC.c` |
| 203 | func_8017D900 | 1 | plumbing | 35 | near | 0 | none — expect MATCH (STUB: ordered global stores + single tail call, sibling of func_8017D840) | `.run/backlog_drafts/func_8017D900.c` |
| 204 | func_8016BEA0 | 1 | other | 37 | near | 0 | none — MATCH (expected) | `.run/backlog_drafts/func_8016BEA0.c` |
| 205 | func_801754A8 | 1 | regalloc-order | 37 | near | 0 | none — MATCH (37 ins, relocation-masked proxy) | `.run/backlog_drafts/func_801754A8.c` |
| 206 | func_80160920 | 1 | struct | 38 | near | 0 | none — MATCH (function-pointer table folds %lo via extern array indexed by halfword) | `.run/backlog_drafts/func_80160920.c` |
| 207 | func_80183BAC | 1 | struct | 41 | near | 0 | switch jump-table dispatch (jtbl_801D9420); verifying case grouping 0,1,2,5,6/3,7/4 emits the target table + tail | `.run/backlog_drafts/func_80183BAC.c` |
| 208 | func_80183C50 | 1 | struct | 41 | near | 0 | none — MATCH (cross-jump exploit §cookbook L1543: dup func_8012C218 into case3/7 + case4 → merged jal;nop) | `.run/backlog_drafts/func_80183C50.c` |
| 209 | func_8015DF34 | 1 | struct | 44 | near | 0 | none — MATCH (clean structural; fn-ptr table via array index folds %lo) | `.run/backlog_drafts/func_8015DF34.c` |
| 210 | func_8015FE70 | 1 | struct | 44 | near | 0 | none — MATCH expected (fn-ptr-table dispatch + ushort struct fields) | `.run/backlog_drafts/func_8015FE70.c` |
| 211 | func_8014358C | 1 | regalloc-order | 45 | near | 0 | none — MATCH (relocation-masked match_one) | `.run/backlog_drafts/func_8014358C.c` |
| 212 | func_80183AF0 | 1 | regalloc-order | 47 | near | 0 | none — MATCH (mask pinned $a1/$5 + p pinned $v0/$2; switch w/ distributed func_8012C218 tail via dup calls + cross-jump merge) | `.run/backlog_drafts/func_80183AF0.c` |
| 213 | func_80178BF8 | 1 | plumbing | 49 | near | 0 | none — MATCH (pure scalar-store + two pointer-decrement do-while loops) | `.run/backlog_drafts/func_80178BF8.c` |
| 214 | func_8015E344 | 1 | struct | 50 | near | 0 | none — MATCH (pending whole-binary gate); fn-ptr table folds %lo via extern array, 0x234 single word store | `.run/backlog_drafts/func_8015E344.c` |
| 215 | func_8017EC7C | 1 | struct | 52 | near | 0 | none — MATCH (52 ins, relocation-masked) | `.run/backlog_drafts/func_8017EC7C.c` |
| 216 | func_80183CF4 | 1 | struct | 57 | near | 0 | none — MATCH (clean switch + jtbl; orchestrator owns jtbl/rodata migration) | `.run/backlog_drafts/func_80183CF4.c` |
| 217 | func_8015D01C | 1 | regalloc-order | 58 | near | 0 | none — MATCH | `.run/backlog_drafts/func_8015D01C.c` |
| 218 | func_8016D688 | 1 | struct | 60 | near | 0 | none — MATCH (byte array D_801D9C20[] folds the &D_801D9C21 base/-1 offsets; emit p+0xE store BEFORE the param+2 increment so the lhu fills the load-delay slot in $v1) | `.run/backlog_drafts/func_8016D688.c` |
| 219 | func_801842C8 | 1 | plumbing | 62 | near | 0 | none — MATCH | `.run/backlog_drafts/func_801842C8.c` |
| 220 | func_80165240 | 1 | regalloc-order | 63 | near | 0 | none — MATCH (63 ins). buf pinned to $s2 (register __asm__("$18")) so it stays in a callee-saved reg; param_3 then naturally lands in $s3. memcpy(buf+0x30,param_3,4) -> lwl/lwr+swl/swr unaligned 4B copy (cookbook §1 mem->mem). array-of-u8 buf with explicit *(T*)(buf+off) stores; mtx[0x20] declared 2nd so it lands at sp+0x50, buf_ at sp+0x10. | `.run/backlog_drafts/func_80165240.c` |
| 221 | func_8017BB34 | 1 | struct | 65 | near | 0 | none — MATCH (65 ins). Keys: (1) align-1 {s8 b[8]} struct so the two 8-byte copies emit lwl/lwr; (2) stack-local declaration order = target frame order (svin@0x10, buf@0x18, out@0x38, local8@0x40, rt_in@0x48, rt_out@0x50) — reordering the locals to ascending offset fixed all 23 offset-only diffs. | `.run/backlog_drafts/func_8017BB34.c` |
| 222 | func_8016BD78 | 1 | regalloc-order | 74 | near | 0 | none — MATCH (lazy pointer locals pa=&BC4, pb=&BC8 assigned at first use → $a1/$a2 held thru middle code as final call args; middle bytes BC5/BC6/BC9/BCA direct global) | `.run/backlog_drafts/func_8016BD78.c` |
| 223 | func_8016E7C8 | 1 | regalloc-order | 74 | near | 0 | none — MATCH (match_one 74/74; pins $18=&prim, $19=param_3 fixed s2/s3 alloc order; Work struct sized to 0x20) | `.run/backlog_drafts/func_8016E7C8.c` |
| 224 | func_8018281C | 1 | struct | 76 | near | 0 | none — MATCH (76 ins). jtbl forced via explicit case 4/6 (count>=5 over MIPS tablejump threshold); case-5 block placed between if-block and default via goto so the if-block emits j default w/ e2=0 in the delay slot | `.run/backlog_drafts/func_8018281C.c` |
| 225 | func_8016AE5C | 1 | regalloc-order | 85 | near | 0 | none — MATCH (85 ins, match_one). switch/jtbl STRUCT fn. The tail's | `.run/backlog_drafts/func_8016AE5C.c` |
| 226 | func_80182E7C | 1 | struct | 85 | near | 0 | none — MATCH (85 ins, relocation-masked). Two switch-codegen levers: | `.run/backlog_drafts/func_80182E7C.c` |
| 227 | func_8015C7E4 | 1 | struct | 88 | near | 0 | none — MATCH (match_one 88/88); fn-ptr-array dispatch, top-level if/else needed branch-polarity invert (small block falls through, big block at L854) | `.run/backlog_drafts/func_8015C7E4.c` |
| 228 | func_8015CA28 | 1 | schedule | 91 | near | 0 | none — MATCH (goto forces the func_80161240 block to the function tail; bnez-to-end layout vs early-return fall-through) | `.run/backlog_drafts/func_8015CA28.c` |
| 229 | func_801820DC | 1 | struct | 94 | near | 0 | none — MATCH (switch on entity state at 0x34, inner jtbl on (s8)(u70>>8)) | `.run/backlog_drafts/func_801820DC.c` |
| 230 | func_80184D50 | 1 | schedule | 98 | near | 0 | none — MATCH (98 ins, relocation-masked) | `.run/backlog_drafts/func_80184D50.c` |
| 231 | func_80161D20 | 1 | struct | 14 | near | 1 | none — MATCH (array-of-u16 %lo-fold, §18) | `.run/backlog_drafts/func_80161D20.c` |
| 232 | func_8015FAAC | 1 | struct | 15 | near | 1 | none — MATCH expected; fn-ptr table indexed by u16 field at +2, *4 scaled load then jalr | `.run/backlog_drafts/func_8015FAAC.c` |
| 233 | func_8017F714 | 1 | plumbing | 27 | near | 1 | none — MATCH (27/27 ins, match_one verified) | `.run/backlog_drafts/func_8017F714.c` |
| 234 | func_80142A10 | 1 | struct | 28 | near | 1 | none — MATCH (pending byte-gate) | `.run/backlog_drafts/func_80142A10.c` |
| 235 | func_80161C24 | 1 | struct | 29 | near | 1 | none — MATCH (array-of-struct %lo-fold; even/odd u16 fields at off 0/2, stride 4) | `.run/backlog_drafts/func_80161C24.c` |
| 236 | func_80184C0C | 1 | struct | 48 | near | 1 | none — MATCH (array-of-struct %lo-fold for &D_8018AEB8[idx], stride 0x34) | `.run/backlog_drafts/func_80184C0C.c` |
| 237 | func_8016B4F8 | 1 | regalloc-order | 50 | near | 1 | none — MATCH | `.run/backlog_drafts/func_8016B4F8.c` |
| 238 | func_801803B0 | 1 | other | 51 | near | 1 | none — MATCH expected; simple if/else, no call-crossing locals beyond param in $s0 | `.run/backlog_drafts/func_801803B0.c` |
| 239 | func_8015FBE0 | 1 | schedule | 58 | near | 1 | none — MATCH | `.run/backlog_drafts/func_8015FBE0.c` |
| 240 | func_8017F114 | 1 | regalloc-order | 75 | near | 1 | none — MATCH | `.run/backlog_drafts/func_8017F114.c` |
| 241 | func_8017F290 | 1 | regalloc-order | 86 | near | 2 | none — MATCH. Two levers: (1) hold &D_801270CC in a `int *state` local so its | `.run/backlog_drafts/func_8017F290.c` |
| 242 | func_8016EC0C | 1 | schedule | 88 | near | 2 | none — MATCH (88 ins). Sparse switch(uVar2) = gcc's beq-pivot+slti comparison | `.run/backlog_drafts/func_8016EC0C.c` |
| 243 | func_80171B4C | 1 | schedule | 70 | near | 3 | 3-off in the tail only (body+prologue MATCH via $s1 pin on arg1). gcc fills the | `.run/backlog_drafts/func_80171B4C.c` |
| 244 | func_80140E6C | 1 | schedule | 37 | near | 4 | 4 ins — each save-across-call copy (move s1,v0 / move s0,v0) should fill the NEXT jal's delay slot (target) but gcc-2.7.2 sched ties the copy with the next call's arg-setup at priority 2 and the LUID tie-break (rank_for_schedule) keeps the copy first, so reorg fills the slot with the arg-setup instead; no C reshape found that flips the LUID/priority order without breaking the OR-chain regalloc. | `.run/backlog_drafts/func_80140E6C.c` |
| 245 | func_8017EF50 | 1 | schedule | 53 | near | 5 | 5 ins — gcc-2.7.2 instr-scheduler load-order tie-breaks. Branch region + cross-jump-break (t14 pin to $3) + 0x34/0x30 hoist (c34 pin $5, c2c pin $3) all MATCH. Residual: (a) header 0x10-load vs 0x2c-load order swap; (b) compare loads 0x36-before-0xA and puts 0xA in $a1 not $a2 (slt operand reg differs). Both clusters resist source steering — every fix to one perturbs the pinned header schedule. | `.run/backlog_drafts/func_8017EF50.c` |
| 246 | func_8014D3E0 | 1 | other | 22 | near | 6 | none — MATCH | `.run/backlog_drafts/func_8014D3E0.c` |
| 247 | func_8013CF68 | 1 | schedule | 63 | near | 6 | blocks 2&3 delay-slot fill — gcc picks dead-reg $v1(b0,0x10/0x20) store for the jal delay slot; target picks arg-reg $a3(0x12/0x22). 6 ins (2 rotations); not flippable by source store-order/interleave/barrier (all tested); permuter/scheduler-internal lever needed. Prologue, $s0 fold, regalloc, block-1 all exact. | `.run/backlog_drafts/func_8013CF68.c` |
| 248 | func_8017B940 | 1 | struct | 63 | near | 6 | none — MATCH | `.run/backlog_drafts/func_8017B940.c` |
| 249 | func_8017B238 | 1 | regalloc-order | 76 | near | 6 | 6 ins — gcc coalesces param_2 into callee-saved $s0 and hoists `move $s0,$a1` | `.run/backlog_drafts/func_8017B238.c` |
| 250 | func_8017B614 | 1 | regalloc-order | 101 | near | 6 | 6 ins — param_2 lands in callee-saved $s0 (entry `move s0,a1`, sltiu/sll read s0) vs target's $a1; gcc prefers s0 (saved anyway for the late p794/p78C copies) over caller-saved $a1. Body+schedule otherwise byte-exact (101/101 ins); the late-part `__asm__("")` barrier is load-bearing (fixes the const-store schedule, 21->6). | `.run/backlog_drafts/func_8017B614.c` |
| 251 | func_801345F8 | 1 | schedule | 106 | near | 7 | 7 ins, all pure scheduling order — maskedp copy not sunk into bnez delay slot | `.run/backlog_drafts/func_801345F8.c` |
| 252 | func_80164E40 | 1 | struct | 25 | near | 8 | none — MATCH expected; byte 0 keeps base $v1 (reused by final lw word), bytes 1/2 standalone | `.run/backlog_drafts/func_80164E40.c` |
| 253 | func_8016E9EC | 1 | schedule | 53 | near | 11 | 11 left — all GNU scheduler/canon tie-breaks (regs all match via pins): (a) prologue hoists `addiu a1,0x1C` into the save block; (b) first lbu reads $a0 not $s1 (incoming-arg still live); (c) iCopy copy `addu s4,s0` lands early (scheduler) vs target's func_800D2CA8 delay-slot; (d) `addu a2,s2,s3` vs target `s3,s2` commutative-canon (unflippable w/o breaking load order). Permuter can't run (register __asm__ pins rejected, cookbook §5a). | `.run/backlog_drafts/func_8016E9EC.c` |
| 254 | func_80156044 | 1 | struct | 74 | near | 12 | none — MATCH (74 ins, relocation-masked); $s2-pin for u16-return + def-mask + 3-arg cast on func_80156848 | `.run/backlog_drafts/func_80156044.c` |
| 255 | func_80161CD0 | 1 | regalloc-order | 20 | near | 14 | param_2 must survive the call in $s0; try plain C first then pin to $16 | `.run/backlog_drafts/func_80161CD0.c` |
| 256 | func_80158FA4 | 1 | schedule | 51 | near | 17 | target keeps a DEAD `sra $a1,$v0,16` before `beqz $a1` (sign-extend of func_80159464's | `.run/backlog_drafts/func_80158FA4.c` |
| 257 | func_8018301C | 1 | plumbing | 28 | near | 24 | none — MATCH (straight-line, statement-order; verify with match_one) | `.run/backlog_drafts/func_8018301C.c` |
| 258 | func_8016BBE0 | 1 | other | 56 | near | 24 | none — straightforward; expect MATCH (mirror Ghidra-C order, synth_mult ×0x555) | `.run/backlog_drafts/func_8016BBE0.c` |
| 259 | func_8016E95C | 1 | regalloc-order | 36 | near | 25 | none — MATCH (pending byte-gate) | `.run/backlog_drafts/func_8016E95C.c` |
| 260 | func_80139BE0 | 1 | loose-typing | 39 | near | 32 | target has redundant andi a1,v0,0xff (uchar zero-extend) gcc proves away; else identical | `.run/backlog_drafts/func_80139BE0.c` |
| 261 | func_80148E54 | 1 | regalloc-order | 67 | near | 40 | 67/67 ins, structure+branches+block-order+body-reload all match; residual is pure register-allocation order (permuter-eligible, no register-pins). (1) masked first-angle folds andi->$s1; target keeps it in $a0 then copies addu $s1,$a0 lazily into the beq delay-slot (the s1-copy schedules 1 slot later). (2) the 0x80 const is CSE-held in $a2 across both test+body; target re-materializes 0x80 in $v0 per block (it gets clobbered by `srl v0,v1,8`), which both renames the compare regs ($v0 not $a2) AND fills the body's reload load-delay slot (mine emits a nop there). (3) single-exit ret funnels $v1->$v0 (move v0,v1) where target writes $v0 directly. All three are gcc regalloc/value-prop tie-breaks no C reshape steered (tried: $v0 pin, temp-split, low-mask-reuse compare, memory-clobber-vs-volatile reload) — leave for the permuter. | `.run/backlog_drafts/func_80148E54.c` |
| 262 | func_8017B0E4 | 1 | other | 61 | near | 51 | none — MATCH (expected; clean six-call sign-extend-store pattern) | `.run/backlog_drafts/func_8017B0E4.c` |
| 263 | func_80166F58 | 1 | schedule | 69 | near | 55 | regs/loop/logic/%lo-fold all match (pinned $s0-$s6); residual is reorg.c delay-slot fill — target replicates `addiu $v0,$s2,1` into the 3 skip-branch delay slots + commits `addu $s2,$v0,0` at merge (my codegen emits in-place `addiu $s2,$s2,1` w/ nop slots, -1 ins); plus prologue short-arg promote-then-move not fusing (`sra $a1;addu $s4,$a1,0` vs my fused `sra $s4,$a1`). Not source-steerable (pins block permuter). | `.run/backlog_drafts/func_80166F58.c` |
| 264 | func_80177DA8 | 1 | remat | 63 | near | 58 | gcc narrows `&0xfffffeff` on a 16-bit (lhu) value to `andi 0xfeff` (inline), but target hoisted -0x101 into $t4 (and-reg) in the loop preheader — a gcc-2.7.2 LICM-before-combine pass-ordering quirk unsteerable from C; that 1-ins gap cascades the constant-reg numbering + tail reassoc. Secondary: single-IV loop ptr anchors at +0xA (short, 2 accesses) not +0xC (byte) like target. | `.run/backlog_drafts/func_80177DA8.c` |
| 265 | func_80141A60 | 1 | other | 76 | near | 63 | none — MATCH (76 ins, relocation-masked). Body byte-identical; target reserves an 8-byte | `.run/backlog_drafts/func_80141A60.c` |
| 266 | func_801457A4 | 1 | other | 79 | near | 74 | MATCH at -O0 (79 ins, reloc-masked, real -O0 flags). BANKING BLOCKER: this -O0 fn lives in the -O2 main ov_SC01_077.c; needs its own §18 -O0 split at 0x801457A4 (existing _o0.c covers 0x8013B568..0x8013C98C only). match_one is -O2 -> WRONG here. | `.run/backlog_drafts/func_801457A4.c` |
| 267 | func_8016B6BC | 1 | schedule | 94 | near | 80 | 12-off, all in the last 12 ins (tail). First 82 ins byte-match. Target materializes | `.run/backlog_drafts/func_8016B6BC.c` |
| 268 | func_80134A74 | 1 | regalloc-order | 107 | near | 84 | structure + all 8 callee-saved regs (s0..s7) + block layout MATCH; residual is caller-saved-temp | `.run/backlog_drafts/func_80134A74.c` |
| 269 | func_8013EE10 | 1 | struct | 94 | near | 86 | none — MATCH (94 ins). array-of-struct %lo-fold (E[]) for the 5-elt loops; | `.run/backlog_drafts/func_8013EE10.c` |
| 270 | func_80182338 | 1 | other | 26 | failed | | none — straight-line init; rely on gcc scheduler to hoist $a1/$v0=6 into prologue/delay-slot | `.run/backlog_drafts/func_80182338.c` |
| 271 | func_80184A68 | 1 | regalloc-order | 33 | failed | | none — MATCH | `.run/backlog_drafts/func_80184A68.c` |
| 272 | func_8015E018 | 1 | loose-typing | 47 | failed | | none — MATCH (signed char forces lbu+sll24/sra24 sign-extend; default char is unsigned in this toolchain) | `.run/backlog_drafts/func_8015E018.c` |
| 273 | func_80159A20 | 1 | struct | 58 | failed | | none — MATCH. Key lever: block tail-MERGE (gcc shared `bne ...,$L1` cross-jump) by making the two return-tests STRUCTURALLY DIFFERENT — positive `if(==){goto mask;} return;` per branch (not `if(!=) return;`), so neither tail can merge. Then fix block ORDER by inverting the outer test (`if(d!=1)` makes the ==4/return path the inline fall-through, the d==1/p[2] path the forward `beq`-target block — matching the target layout). | `.run/backlog_drafts/func_80159A20.c` |
| 274 | func_8013E958 | 1 | schedule | 63 | failed | | 2 ins swapped — cc1 emits `andi 0x7f; andi 0xff; beqz`(tests doubly-masked) but target wants `andi 0x7f; beqz; andi 0xff`(andi 0xff in the first beqz delay slot). Loop fully byte-matches; struct/ptr fold idioms nailed (D_80115110.q[0x16] hoists base+0x58 disp, Cell D_80115188[i].v folds %lo). func_800D0488 takes (m&0xFF) arg. s16 m -> 2 mism (right ins count); s32 m fixes order but merges andi+arg-move (62 ins, 1 short). | `.run/backlog_drafts/func_8013E958.c` |
| 275 | func_8013E83C | 1 | plumbing | 71 | failed | | none — MATCH (scalar global stores + 2 conditional calls; §3-T4 branch-polarity invert on the &0xFF test) | `.run/backlog_drafts/func_8013E83C.c` |
| 276 | func_8017B368 | 1 | schedule | 74 | failed | | dead table-path off by 1 ins — target keeps src*16 live in $s0 & computes 2nd arg src16+(base+8) in call1 delay slot; every C form either folds to e+8 (73 ins) or CSEs base into an extra saved reg $s2 (75 ins). All live code (prologue, sltiu dispatch, copy path, 4 struct-copy stores, tail) matches; only the unreachable func_8012F214 path scheduling diverges. | `.run/backlog_drafts/func_8017B368.c` |
| 277 | func_80180B64 | 1 | struct | 75 | failed | | none — MATCH (75 ins, relocation-masked) | `.run/backlog_drafts/func_80180B64.c` |
| 278 | func_80180F10 | 1 | schedule | 75 | failed | | none — MATCH (aggregate-initializer form schedules const setup after the prologue saves) | `.run/backlog_drafts/func_80180F10.c` |
| 279 | func_8016C188 | 1 | schedule | 79 | failed | | none — MATCH (79 ins, match_one). Levers: invert if to if(iVar1!=0){big}else{small} | `.run/backlog_drafts/func_8016C188.c` |
| 280 | func_80164930 | 1 | regalloc-order | 81 | failed | | none — MATCH (81 ins, relocation-masked) | `.run/backlog_drafts/func_80164930.c` |
| 281 | func_801418F8 | 1 | loose-typing | 90 | failed | | none — MATCH (90 ins). Keys: D_8011511A is `volatile u16` (store-2-then-read must NOT const-fold), read ONCE into a `u16` local t (an `unsigned int` local adds a stray andi 0xffff; reusing t feeds the single lhu to both sltiu and t-3), and the lone D_80115158 store after the if yields the delay-slot-fill-from-target dup of `addiu 0x106`. | `.run/backlog_drafts/func_801418F8.c` |
| 282 | func_801789AC | 1 | struct | 91 | failed | | none — MATCH (91 ins, relocation-masked) | `.run/backlog_drafts/func_801789AC.c` |
| 283 | func_80183DE0 | 1 | regalloc-order | 91 | failed | | testing if(!=1) layout + counter-before-pointer init order | `.run/backlog_drafts/func_80183DE0.c` |
| 284 | func_80185428 | 1 | struct | 94 | failed | | none — MATCH (94 ins, relocation-masked) | `.run/backlog_drafts/func_80185428.c` |
| 285 | func_801506A4 | 1 | loose-typing | 95 | failed | | none — MATCH (95 ins). switch var must be int not u16 (u16 adds andi 0xffff promotion mask) | `.run/backlog_drafts/func_801506A4.c` |
| 286 | func_8016BFD0 | 1 | struct | 95 | failed | | none — MATCH (95 ins). memcpy(d,s,4) -> lwl/lwr/swl/swr; MATRIX work buf as s32[16] (0x40, fills 0x10-0x4f, t[] = buf[5..7]); two SVECTOR locals at 0x50/0x58; natural saved-reg order s0=param_5/s1=param_4/s2=iVar5 | `.run/backlog_drafts/func_8016BFD0.c` |
| 287 | func_801596F0 | 1 | struct | 97 | failed | | none — MATCH (97 ins). Loop 1 = struct-ptr for-loop (E38, flag@+4) -> -4 guard / +4 test via gcc biv-elim. Loop 2 needed an EXPLICIT if-guard + do-while with the FIELD pointer as the loop var (so the giv init emits FIRST in the preheader, before the &D invariant block), a non-volatile re-tie barrier on d=&D_800AFAE8 (keeps &D BARE so +4/+0x88 add off it = +1 ins vs the folded %lo, matching target), an explicit u32 mask hoisted first (fills the guard's delay slot), and a separate range check fp<d+4 // fp>=d+0x88. | `.run/backlog_drafts/func_801596F0.c` |
| 288 | func_8017B490 | 1 | schedule | 97 | failed | | none — MATCH (97 ins). Keys: (1) inverted if so the SV4 block-copy else is fallthrough and block A is bnez-far (cond = (u32)&D_801DA73C >= 0xB, a relocated-symbol compare gcc can't fold); (2) SV4{s16 a,b,c,d} align-2 8-byte copy -> lwl/lwr/swl/swr, locals at sp+0x10/0x18; (3) the DEAD block-A index = (s32)&D_801DA73C into D_8018A45C[] (WAVE16=two SV4) needs BOTH source addrs (&[idx].v0,&[idx].v1) in EXPLICIT TEMPS before call1 so base (&D_8018A45C) dies pre-call -> temp $v0 (not callee-saved), forcing the natural 2-reg alloc idx=$s0/param_1=$s1 + src2 into call1's delay slot; (4) tail: D_801DA794/D_801DA78C are SV4, re-read .a/.b/.c via lh sign-extended to s32 stores. | `.run/backlog_drafts/func_8017B490.c` |
| 289 | func_80182C9C | 1 | schedule | 101 | failed | | none — MATCH (101 ins). Inner-switch break-to-shared-tail must be written as | `.run/backlog_drafts/func_80182C9C.c` |
| 290 | func_80183FB8 | 1 | loose-typing | 101 | failed | | none — MATCH (relocation-masked match_one, 101/101 ins) | `.run/backlog_drafts/func_80183FB8.c` |
| 291 | func_8013EF88 | 1 | struct | 108 | failed | | none — MATCH (108 ins). Keys: (1) §18 array-of-struct E4{s32 v} for | `.run/backlog_drafts/func_8013EF88.c` |
+4 -4
View File
@@ -3,11 +3,11 @@
# source-derived (committed src/*.c + config/dedup.us.yaml). Live byte gate: `make check-all`;
# cross-binary collapsible-byte leverage: docs/duplicates.cross.md.
FLEET REAL substantive : 217960 (of which dedup-shared 217217 via 1633 groups / 217268 instances)
FLEET REAL substantive : 217964 (of which dedup-shared 217217 via 1633 groups / 217268 instances)
FLEET LINKED PsyQ objs : 959
FLEET byte-identical : 219607 / 344941 = 63.67% (REAL+LINKED+empties)
FLEET byte-identical : 219611 / 344941 = 63.67% (REAL+LINKED+empties)
FLEET NON_MATCHING : 7 (0 in any default build — G4)
FLEET INCLUDE_ASM stubs : 125327
FLEET INCLUDE_ASM stubs : 125323
FLEET matchable : 344941
| binary | REAL | shared | LINKED | byte-ident | matchable | byte-ident % |
@@ -22,7 +22,7 @@ FLEET matchable : 344941
| ov_SC01_008 | 1617 | 1617 | 0 | 1619 | 2435 | 66.5% |
| ov_SC01_009 | 1617 | 1617 | 0 | 1618 | 2517 | 64.3% |
| ov_SC01_074 | 1617 | 1617 | 0 | 1619 | 2434 | 66.5% |
| ov_SC01_077 | 2146 | 1578 | 0 | 2148 | 2586 | 83.1% |
| ov_SC01_077 | 2150 | 1578 | 0 | 2152 | 2586 | 83.2% |
| ov_SC01_080 | 1621 | 1621 | 0 | 1621 | 2522 | 64.3% |
| ov_SC01_084 | 1621 | 1621 | 0 | 1626 | 2588 | 62.8% |
| ov_SC02_000 | 1625 | 1625 | 0 | 1632 | 2691 | 60.6% |
+30 -4
View File
@@ -5557,7 +5557,13 @@ DEFINE_func_8015CC0C() /* dedup: shared engine-core @0x8015CC0C (src/shared) */
DEFINE_func_8015CC40() /* dedup: shared engine-core @0x8015CC40 (src/shared) */
INCLUDE_ASM("asm/ov_SC01_077/nonmatchings/ov_SC01_077", func_8015CC74);
extern void (*D_80189354[])(void);
void func_8015CC74(s32 * a0)
{
D_80189354[*(u16 *)((s32)a0 + 0x2)]();
}
DEFINE_func_8015CCB0() /* dedup: shared engine-core @0x8015CCB0 (src/shared) */
@@ -6464,7 +6470,13 @@ void func_80160818(s32 *a0) {
func_8016084C(a0);
}
INCLUDE_ASM("asm/ov_SC01_077/nonmatchings/ov_SC01_077", func_8016084C);
extern void (*D_801895A8[])(void *);
void func_8016084C(s32 * a0)
{
D_801895A8[*(u16 *)((s32)a0 + 0x2)](a0);
}
DEFINE_func_80160888() /* dedup: shared engine-core @0x80160888 (src/shared) */
@@ -6488,7 +6500,13 @@ void func_80160ACC(s32 *a0) {
DEFINE_func_80160B00() /* dedup: shared engine-core @0x80160B00 (src/shared) */
INCLUDE_ASM("asm/ov_SC01_077/nonmatchings/ov_SC01_077", func_80160B34);
extern void (*D_801895B4[])(void);
s32 func_80160B34(s32 a0)
{
D_801895B4[*(u16 *)((s32)a0 + 0x2)]();
}
DEFINE_func_80160B70() /* dedup: shared engine-core @0x80160B70 (src/shared) */
@@ -8952,7 +8970,15 @@ void func_80170548(u8 *a0)
DEFINE_func_80170584() /* dedup: shared engine-core @0x80170584 (src/shared) */
INCLUDE_ASM("asm/ov_SC01_077/nonmatchings/ov_SC01_077", func_801705C0);
extern void *D_8011F738;
extern void func_80171928(void *a0);
void func_801705C0(u8 * a0)
{
((void (*)(void))D_8011F738)();
func_80171928(a0);
}
extern void (*D_8018A014[])(void);
+23 -2
View File
@@ -118,9 +118,30 @@ LEAN_SYS = ("You are an expert at MATCHING decompilation for MIPS (PSX, gcc-2.7.
"predefined (common.h). Output ONLY the C (the function definition + any externs it needs).")
# Bridge: real OPEN stubs are splat .s (headers, 3-field comment, spaced operands, resolved jal); the
# fine-tuned model trained on objdump/corpus style. NORMALIZE_ASM=1 converts .s -> that style so a
# fine-tuned model sees its training format on real stubs (no retrain needed).
NORMALIZE = os.environ.get('NORMALIZE_ASM', '0') != '0'
def normalize_asm(asm):
out = []
for line in asm.splitlines():
m = re.match(r'\s*/\*\s*[0-9A-Fa-f]+\s+([0-9A-Fa-f]+)\s+([0-9A-Fa-f]{8})\s*\*/\s*(\S.*)', line)
if not m:
continue # drop glabel/endlabel/nonmatching/blank headers
vaddr, leword, rest = m.group(1).upper(), m.group(2).upper(), m.group(3).strip()
parts = rest.split(None, 1)
mnem = parts[0]
ops = re.sub(r',\s+', ',', parts[1]) if len(parts) > 1 else '' # "$sp, $sp" -> "$sp,$sp"
out.append(('/* %s %s */ %-9s %s' % (vaddr, leword, mnem, ops)).rstrip())
return '\n'.join(out)
def build_user_lean(t, asm_text, ghidra_text):
asm = normalize_asm(asm_text) if NORMALIZE else asm_text.strip()
return ("Target assembly (each `/* vaddr WORD */ mnemonic` line is one encoded instruction):\n"
+ asm_text.strip() + "\n\nWrite the byte-matching C function.")
+ asm + "\n\nWrite the byte-matching C function.")
def call_api(messages, max_tokens=4096, temperature=TEMP, timeout=600):
@@ -168,7 +189,7 @@ def draft_one(t, outdir, iters):
asm_subdir = os.path.dirname(t['asm'])
gc_path = os.path.join(REPO, t.get('ghidra_c', ''))
asm_text = open(asm_path).read() if os.path.exists(asm_path) else '(asm missing)'
ghidra_text = open(gc_path).read() if os.path.exists(gc_path) else '(no ghidra-c)'
ghidra_text = open(gc_path).read() if (t.get('ghidra_c') and os.path.isfile(gc_path)) else '(no ghidra-c)'
cfile = os.path.join(outdir, fn + '.c')
sys_msg = LEAN_SYS if LEAN else SYS