fix(phase-23): T7 — lora_grind broad-rotation banking (two gate bugs); ov_SC01_000 7/15

The 500-fn calibration banked 0/222 across the binary rotation. Root-caused (R14, by
reading the code + the run's own backlog — resolving a flat contradiction between two
scout agents) to TWO independent bugs in lora_grind's use of gate_stage.run_gate, NOT
model quality:
- Bug A: good_sha() passed the sha1sum line "<sha>  <name>" vs harvest_verify's bare
  sha1() -> 0 banks for EVERY binary incl. 077 (so the "0/12" was a bug artifact, not
  an exhausted tail)
- Bug B: the gate call left src/asm/out at the hardcoded ov_SC01_077 defaults -> non-077
  drafts dropped at the 077 stub-filter, silently (and the asm mis-resolution contaminated
  the backlog near-miss classification)

Fix (tools/gate_stage.py): run_gate resolves src/asm/out/good_sha from `binary` when unset
(binary-agnostic, no silent ov_SC01_077 default an overlay inherits; good_sha bare-hash
normalized) + a loud negative-control guard (0-overlap binary/src mismatch warns, so a 0
can never again masquerade as 'nothing matched'). tools/lora_grind.good_sha fixed at source.
Byte-neutral: make check-all 136/136.

Proof: ov_SC01_000 spot-run banked 7/15 (47%) byte-identical (@commit:0322); reach-2
func_8017CE24 propagated x2. ROI finding: 6/7 banks are reach-1 (overlay-unique) -> broad
rotation is high bank-RATE / low fleet-% ROI; the fleet lever is reach>=2 targeting (T9) +
corpus-v3 (T8). Backlog now correctly classified (4x close=1 = grinder fuel).

- docs/gen2-mips-matching-model.md: T7 RESULT section
- phase-ends/CURRENT_PHASE.md: T7 done; next = T8 corpus-v3 / T9 reach>=2 selection
This commit is contained in:
Drew T
2026-06-29 23:44:12 -06:00
parent 8016481036
commit bff03dbdb5
11 changed files with 305 additions and 237 deletions
+2
View File
@@ -110,3 +110,5 @@ datasets/
models/
*.gguf
*.safetensors
.venv-train/
unsloth_compiled_cache/
+7
View File
@@ -11552,3 +11552,10 @@ groups:
func: DEFINE_func_80128ED8
vram: 0x80128ED8
binaries: [ov_SC01_077, ov_SC01_005, ov_SC01_006, ov_SC03_001, ov_SC01_000, ov_SC01_001, ov_SC02_000, ov_SC02_003, ov_SC03_002, ov_SC03_006, ov_SC04_000, ov_SC04_018, ov_SC04_019, ov_SC05_000, ov_SC06_000, ov_SC07_000, ov_SC01_004, ov_SC01_008, ov_SC01_009, ov_SC01_074, ov_SC01_080, ov_SC01_084, ov_SC02_004, ov_SC02_005, ov_SC02_011, ov_SC02_015, ov_SC02_016, ov_SC02_017, ov_SC02_021, ov_SC02_026, ov_SC02_027, ov_SC02_028, ov_SC02_031, ov_SC02_035, ov_SC02_039, ov_SC02_041, ov_SC03_003, ov_SC03_007, ov_SC03_010, ov_SC03_011, ov_SC03_012, ov_SC03_013, ov_SC03_014, ov_SC03_015, ov_SC03_023, ov_SC03_024, ov_SC03_028, ov_SC03_029, ov_SC03_030, ov_SC03_031, ov_SC03_089, ov_SC03_090, ov_SC03_091, ov_SC03_092, ov_SC03_093, ov_SC03_094, ov_SC03_095, ov_SC03_096, ov_SC03_097, ov_SC03_098, ov_SC03_099, ov_SC03_100, ov_SC03_101, ov_SC03_102, ov_SC03_103, ov_SC03_104, ov_SC03_105, ov_SC03_108, ov_SC03_109, ov_SC03_110, ov_SC03_111, ov_SC03_112, ov_SC03_113, ov_SC03_114, ov_SC03_115, ov_SC03_116, ov_SC03_117, ov_SC03_118, ov_SC03_119, ov_SC03_121, ov_SC03_124, ov_SC03_125, ov_SC03_126, ov_SC04_002, ov_SC04_003, ov_SC04_004, ov_SC04_005, ov_SC04_006, ov_SC04_007, ov_SC04_008, ov_SC04_009, ov_SC04_010, ov_SC04_011, ov_SC04_012, ov_SC04_015, ov_SC04_016, ov_SC04_020, ov_SC04_021, ov_SC05_001, ov_SC05_002, ov_SC05_003, ov_SC05_004, ov_SC05_005, ov_SC05_006, ov_SC05_007, ov_SC05_008, ov_SC05_009, ov_SC05_010, ov_SC05_011, ov_SC05_017, ov_SC05_018, ov_SC05_019, ov_SC06_006, ov_SC06_008, ov_SC06_010, ov_SC06_011, ov_SC06_013, ov_SC06_014, ov_SC06_015, ov_SC06_016, ov_SC06_018, ov_SC06_020, ov_SC06_022, ov_SC06_024, ov_SC06_025, ov_SC06_027, ov_SC06_029, ov_SC06_030, ov_SC06_032, ov_SC06_033, ov_SC07_001, ov_SC07_002, ov_SC07_008, ov_SC07_009]
- id: E_func_8017CE24
tier: h_exact
hash: 511a8b68802b6800ebb271e89b28604ee53e3401
source: src/shared/engine_core.h
func: DEFINE_func_8017CE24
vram: 0x8017CE24
binaries: [ov_SC01_000, ov_SC01_001]
+169 -167
View File
@@ -2,7 +2,7 @@
> Generated by `tools/backlog.py render` from `.run/backlog.jsonl`. These are functions the Phase-21 automation got **close** on but did NOT byte-match. The whole-binary byte-gate is the sole arbiter (G3/P9): **byte-matches bank and are NOT listed here** — only genuine near-misses/blockers are. Ranked by hand-session priority: **reach** (×N propagation leverage) → **closeness** (match_one mismatch count, lower = closer) → **size**. Each row's `best_draft` is the closest C the machine reached — resume from there.
**Open near-misses:** 291 · by status {'near': 215, 'failed': 76} · by class {'WAVE': 19, 'plumbing': 42, 'other': 24, 'schedule': 61, 'loose-typing': 7, 'struct': 63, 'regalloc-order': 58, 'remat': 4, 'STUB': 2, 'iv-combine': 3, 'GIANT': 8}
**Open near-misses:** 293 · by status {'near': 218, 'failed': 75} · by class {'WAVE': 20, 'plumbing': 42, 'other': 23, 'STUB': 2, 'schedule': 61, 'loose-typing': 7, 'struct': 61, 'regalloc-order': 58, 'remat': 4, 'iv-combine': 3, 'GIANT': 8, 'STRUCT': 3, 'PINS': 1}
| # | addr | reach | class | nins | status | closeness | where it stuck | best draft |
|--:|------|------:|-------|-----:|--------|----------:|----------------|------------|
@@ -12,79 +12,79 @@
| 4 | func_8017331C | 134 | plumbing | 12 | near | 0 | none — MATCH (param_1 saved to $s0 across first call, passed to second) | `.run/backlog_drafts/func_8017331C.c` |
| 5 | func_80173374 | 134 | plumbing | 12 | near | 0 | none — MATCH expected (param_1 lives across first call → naturally lands in $s0) | `.run/backlog_drafts/func_80173374.c` |
| 6 | func_80174554 | 134 | plumbing | 12 | near | 0 | none — MATCH (clean stub; param_1 reused in $a0 across first call, saved to $s0 for second) | `.run/backlog_drafts/func_80174554.c` |
| 7 | func_8014C568 | 134 | plumbing | 13 | near | 0 | none — MATCH expected; straightforward ratan2 wrapper with two s16 deltas & 0xFFF | `.run/backlog_drafts/func_8014C568.c` |
| 8 | func_80161208 | 134 | plumbing | 14 | near | 0 | none — MATCH expected (param saved across call → natural $s0, no pin needed) | `.run/backlog_drafts/func_80161208.c` |
| 9 | func_801542A4 | 134 | plumbing | 14 | near | 0 | none — MATCH expected (simple stub: field stores + tail call) | `.run/backlog_drafts/func_801542A4.c` |
| 10 | func_8016F0AC | 134 | plumbing | 14 | near | 0 | none — MATCH (expected; address CSE'd into $s0 across both calls) | `.run/backlog_drafts/func_8016F0AC.c` |
| 11 | func_801653B8 | 134 | plumbing | 15 | near | 0 | none — MATCH expected (simple call-crossing wrapper, param saved in $s0) | `.run/backlog_drafts/func_801653B8.c` |
| 12 | func_80131CA8 | 134 | other | 19 | near | 0 | none — MATCH (call-through-fnptr dispatcher: explicit return 1/return 0) | `.run/backlog_drafts/func_80131CA8.c` |
| 13 | func_8016E778 | 134 | plumbing | 20 | near | 0 | none — MATCH (build-word spread + 3-halfword buffer, two stack addrs passed) | `.run/backlog_drafts/func_8016E778.c` |
| 14 | func_80172C50 | 134 | plumbing | 20 | near | 0 | none — MATCH (unaligned 8-byte memcpy + tail call) | `.run/backlog_drafts/func_80172C50.c` |
| 15 | func_8016BF50 | 134 | schedule | 22 | near | 0 | none — MATCH; short buf[3] keeps all 3 stores live + hoisting *(int*)(p+0x34) into a local | `.run/backlog_drafts/func_8016BF50.c` |
| 16 | func_80166244 | 134 | plumbing | 22 | near | 0 | none — MATCH expected (single tail-call STUB) | `.run/backlog_drafts/func_80166244.c` |
| 17 | func_80146C3C | 134 | loose-typing | 23 | near | 0 | none — MATCH | `.run/backlog_drafts/func_80146C3C.c` |
| 18 | func_80162CCC | 134 | plumbing | 23 | near | 0 | none — MATCH expected; direct translation, psVar1 as u16* gives lhu, $s0=param_1 survives both calls | `.run/backlog_drafts/func_80162CCC.c` |
| 19 | func_8012A598 | 134 | struct | 24 | near | 0 | none — MATCH (24 ins, relocation-masked) | `.run/backlog_drafts/func_8012A598.c` |
| 20 | func_801733FC | 134 | struct | 25 | near | 0 | none — modeled on sibling func_80173460 (packed 8-byte struct copy + two s16=1 stores) | `.run/backlog_drafts/func_801733FC.c` |
| 21 | func_80137614 | 134 | regalloc-order | 26 | near | 0 | none — MATCH (sibling func_8013767C pattern; all 3 params live across the call) | `.run/backlog_drafts/func_80137614.c` |
| 22 | func_80160F00 | 134 | plumbing | 28 | near | 0 | none — MATCH (straight-line STUB; $s0 holds param_1 across calls naturally) | `.run/backlog_drafts/func_80160F00.c` |
| 23 | func_8012F274 | 134 | remat | 29 | near | 0 | none — MATCH (29 ins, match_one byte-clean via relocation-masked pipeline) | `.run/backlog_drafts/func_8012F274.c` |
| 24 | func_8014A51C | 134 | schedule | 32 | near | 0 | none — MATCH (32 ins, relocation-masked) | `.run/backlog_drafts/func_8014A51C.c` |
| 25 | func_801495C4 | 134 | regalloc-order | 34 | near | 0 | none — MATCH expected (cloned byte-matched sibling func_8014964C recipe: $16 pin + asm barriers force param_2→$s0 and rematerialize &in/&mid/mtx) | `.run/backlog_drafts/func_801495C4.c` |
| 26 | func_8012A6D0 | 134 | plumbing | 34 | near | 0 | none — MATCH (sum order p[2]^2 + p[0]^2, then ratan2(p1[1]-p2[1], (s16)dist)) | `.run/backlog_drafts/func_8012A6D0.c` |
| 27 | func_80151664 | 134 | plumbing | 35 | near | 0 | none — MATCH (35 ins, relocation-masked); canonical externs kept, call-site casts only | `.run/backlog_drafts/func_80151664.c` |
| 28 | func_8012F40C | 134 | regalloc-order | 36 | near | 0 | none — MATCH (address rematerialized per call via caller-saved $a0 pin) | `.run/backlog_drafts/func_8012F40C.c` |
| 29 | func_80131D68 | 134 | regalloc-order | 38 | near | 0 | return value held in $v0 per-path (no $s1 frame); using explicit returns | `.run/backlog_drafts/func_80131D68.c` |
| 30 | func_801522CC | 134 | plumbing | 41 | near | 0 | TBD — first compile; func_80153C18 canonical is (void) but target sets $a0=$s0 in its delay slot (call-site cast) | `.run/backlog_drafts/func_801522CC.c` |
| 31 | func_80129C40 | 134 | struct | 46 | near | 0 | none — MATCH (array-of-struct %lo-fold for the two 3-element 0xA4-stride bases) | `.run/backlog_drafts/func_80129C40.c` |
| 32 | func_801497A8 | 134 | regalloc-order | 47 | near | 0 | none — MATCH. $s1 pinned to D_80078E78 base; result accumulator + masked | `.run/backlog_drafts/func_801497A8.c` |
| 33 | func_801483E8 | 134 | struct | 50 | near | 0 | none — MATCH | `.run/backlog_drafts/func_801483E8.c` |
| 34 | func_8015F380 | 134 | plumbing | 50 | near | 0 | none — expect MATCH (single call-crossing local pinned to $s0) | `.run/backlog_drafts/func_8015F380.c` |
| 35 | func_80136DFC | 134 | loose-typing | 50 | near | 0 | none — MATCH | `.run/backlog_drafts/func_80136DFC.c` |
| 36 | func_8016EFC8 | 134 | schedule | 51 | near | 0 | none — MATCH (51 ins). Temp `u32 v = *a0 / 0x4000000;` hoists the load to ins 0 and | `.run/backlog_drafts/func_8016EFC8.c` |
| 37 | func_801376E8 | 134 | schedule | 51 | near | 0 | none — MATCH (51 ins). 3 levers: (1) adjacent-field array u16 D_80126A14[] for A14/A16 | `.run/backlog_drafts/func_801376E8.c` |
| 38 | func_801758FC | 134 | schedule | 55 | near | 0 | none — MATCH (55 ins) | `.run/backlog_drafts/func_801758FC.c` |
| 39 | func_801759D8 | 134 | schedule | 56 | near | 0 | none — MATCH (56 ins) | `.run/backlog_drafts/func_801759D8.c` |
| 40 | func_8012A328 | 134 | schedule | 60 | near | 0 | none — MATCH (60 ins, relocation-masked) | `.run/backlog_drafts/func_8012A328.c` |
| 41 | func_80138DE0 | 134 | other | 60 | near | 0 | none — MATCH (60 ins) | `.run/backlog_drafts/func_80138DE0.c` |
| 42 | func_80133298 | 134 | struct | 65 | near | 0 | none — MATCH (65 ins, relocation-masked) | `.run/backlog_drafts/func_80133298.c` |
| 43 | func_80164418 | 134 | struct | 70 | near | 0 | none — MATCH (s16 stack array forces the spill; 2nd ratan2 reuses /dy/ in $a1) | `.run/backlog_drafts/func_80164418.c` |
| 44 | func_8012E014 | 134 | other | 73 | near | 0 | none — MATCH (expected; straightforward struct-field + global-copy body) | `.run/backlog_drafts/func_8012E014.c` |
| 45 | func_8012E138 | 134 | regalloc-order | 81 | near | 0 | none — MATCH (81/81 ins, match_one proxy); reloaded ptr pinned to $a0 | `.run/backlog_drafts/func_8012E138.c` |
| 46 | func_8012B4B8 | 134 | regalloc-order | 84 | near | 0 | none — MATCH | `.run/backlog_drafts/func_8012B4B8.c` |
| 47 | func_801379FC | 134 | regalloc-order | 97 | near | 0 | none — MATCH (match_one 97/97) | `.run/backlog_drafts/func_801379FC.c` |
| 48 | func_801463A0 | 134 | struct | 101 | near | 0 | none — MATCH (101 ins, match_one); real symbol names; misaligned 8B copy + s16 stores + masked B9C last | `.run/backlog_drafts/func_801463A0.c` |
| 49 | func_80167714 | 134 | regalloc-order | 104 | near | 0 | none — MATCH (104 ins) | `.run/backlog_drafts/func_80167714.c` |
| 50 | func_80169228 | 134 | regalloc-order | 105 | near | 0 | none — MATCH (105 ins, relocation-masked). Key levers: arg0/p pinned $s1/$s0, | `.run/backlog_drafts/func_80169228.c` |
| 51 | func_8012CC88 | 134 | struct | 105 | near | 0 | none — MATCH (105 ins, relocation-masked) | `.run/backlog_drafts/func_8012CC88.c` |
| 52 | func_80174CB0 | 134 | regalloc-order | 123 | near | 0 | none — MATCH (match_one 123/123). Levers: (1) §21 one combined stack struct {s32 a[5]; ...} | `.run/backlog_drafts/func_80174CB0.c` |
| 53 | func_80174CB0 | 134 | struct | 123 | near | 0 | close=0 match_one MATCH but its anon typedef is named 'Buf' which COLLIDES with the existing 'Buf' (s16 h[8], different layout) in the TU. To bank ×134: rename func_80174CB0's Buf -> a unique name AND lift it to engine_types.h (or keep local for ×1). Deferred (fiddly for 123 ins). Type-rename+lift candidate. | `.run/backlog_drafts/func_80174CB0.c` |
| 54 | func_80178004 | 134 | regalloc-order | 165 | near | 0 | none — MATCH (full register pins per sibling func_80177EA4; running-ptr $s2 to stop unroll-rebase; | `.run/backlog_drafts/func_80178004.c` |
| 55 | func_8014F74C | 134 | schedule | 174 | near | 0 | none — MATCH (174 ins). Last mile: §5a volatile barrier blocked gcc jump-threading | `.run/backlog_drafts/func_8014F74C.c` |
| 56 | func_8016F0E4 | 134 | plumbing | 26 | near | 1 | none — MATCH (26 ins); natural C form, param_1 auto-allocated to $s0 | `.run/backlog_drafts/func_8016F0E4.c` |
| 57 | func_8014F3E8 | 134 | WAVE | 32 | near | 1 | WAVE: 1 mismatch | `.run/backlog_drafts/func_8014F3E8.c` |
| 58 | func_80177AD4 | 134 | regalloc-order | 34 | near | 1 | 1 ins — loop-bound shift reads loop-carried $a3 (sll v0,a3,16) vs target's dying copy $v0 (sll v0,v0,16); gcc CSE canonicalizes the two equal-valued regs to the loop-carried one. IV-combine (§20) CRACKED via $a2/$a3 pins (was 31-mismatch "stub"). | `.run/backlog_drafts/func_80177AD4.c` |
| 59 | func_801775E0 | 134 | regalloc-order | 67 | near | 1 | 1 ins — target `sb $v0,0x6($s0)` vs mine `sb $v0,26($s1)` (same store P1+0x1a; gcc address-CSE picks $s1 base not the recomputed $s0); all else byte-identical | `.run/backlog_drafts/func_801775E0.c` |
| 60 | func_8014FFDC | 134 | struct | 93 | near | 1 | none — MATCH | `.run/backlog_drafts/func_8014FFDC.c` |
| 61 | func_80158638 | 134 | plumbing | 87 | near | 2 | none — MATCH (proxy); callee externs are plain func_<addr>, gate's canon/cast passes own them | `.run/backlog_drafts/func_80158638.c` |
| 62 | func_80131A34 | 134 | regalloc-order | 37 | near | 3 | 3-off — (a) prologue saves $ra before $s0 (target: $s0 then $ra) and (b) return-0 path reuses $a1's proven-zero (move $v0,$a1) instead of $zero; both are gcc prologue/return scheduling tie-breaks. Body matches incl. the $v0->$a1 result copy (forced via the $a1-pinned asm anchor), the $v1=-5 mask hoist into the bne delay slot, and the shared-store merge. | `.run/backlog_drafts/func_80131A34.c` |
| 63 | func_80171FFC | 134 | regalloc-order | 40 | near | 3 | none — MATCH (40 ins). Key: func_8017248C takes (a0,a1); calling it with | `.run/backlog_drafts/func_80171FFC.c` |
| 64 | func_801466F0 | 134 | plumbing | 24 | near | 4 | none — MATCH (struct param-spill + branch-polarity) | `.run/backlog_drafts/func_801466F0.c` |
| 65 | func_80147364 | 134 | remat | 30 | near | 4 | none — MATCH (30 ins). Lever: hoist &D_80126B58 into a local ptr `u8 *p=&D_80126B58;` so gcc | `.run/backlog_drafts/func_80147364.c` |
| 66 | func_801325B8 | 134 | schedule | 113 | near | 4 | 4/113 — prologue save-order of the $s0(cur/p3) vs $s5(p1) pair; gcc emits | `.run/backlog_drafts/func_801325B8.c` |
| 67 | func_80146A6C | 134 | struct | 18 | near | 5 | none — MATCH | `.run/backlog_drafts/func_80146A6C.c` |
| 68 | func_80140D68 | 134 | schedule | 65 | near | 5 | 5-ins near-miss — gcc hoists `lui 0xff00` (the 0xFF000000 mask) one slot too early in the first AddPrim block, so the D_800B9A02 index value lands in $v1 instead of $a1 and *param_1 is read late (idx 35-43). Structure + regs otherwise byte-exact (frame eliminated via struct-array D_800AE7BC, &D_800B9A02 held in $a2 via the pB $6 pin, param_1+8 grouping fixes the rest). Pure sched1 list-order residual -> permuter candidate (try reg-hint + reorder around the lui 0xff00 / lw 0($a0) pair). | `.run/backlog_drafts/func_80140D68.c` |
| 69 | func_80130C08 | 134 | schedule | 65 | near | 5 | tail shares one jal func_80131CA8 between the a1=5 and a1=0x38 arms via `j .L80130CEC` with a DUPLICATED `move a0,s0` (one in the beqz delay slot, one at jump-in label .L80130CDC); goto-merge form collapses to 64 ins (one move dropped), if-else form keeps 65 ins but emits two separate jals (idx 54-56 differ + the recheck branch inverts bnez/beqz at idx 51). 5 mismatched, count correct. | `.run/backlog_drafts/func_80130C08.c` |
| 70 | func_80175820 | 134 | schedule | 55 | near | 6 | body byte-IDENTICAL; only residual is the phantom 0x10 leaf frame — target schedules `addiu $sp,-0x10` into the load-delay slot at insn 26 (after the D_8011F7C0 load) and `addiu $sp,0x10` before `jr ra`. With the frame forced (reserved local + anchor) gcc emits the prologue adjust at insn 0 instead of the delay slot (§5 frame-scheduling class); pins block the permuter, no C lever found to move it. Frameless form left here = body byte-exact, 2 frame insns short. | `.run/backlog_drafts/func_80175820.c` |
| 71 | func_8014EA4C | 134 | schedule | 183 | near | 6 | raw close=6: D_801150D8=0 store between a0/a1 loads + abs($v1 move vs in-place negu) pressure-locked by buf[16]+memcpy frame hack — permuter fuel | `.run/drafts-giants/func_8014EA4C.c` |
| 72 | func_8014EE14 | 134 | schedule | 248 | near | 6 | §20 store-vs-load tie-break (x2 loops); frame/regalloc/control-flow/constants byte-exact; no pins/asm -> permuter-ready | `.run/backlog_drafts/func_8014EE14.c` |
| 73 | func_8016130C | 134 | WAVE | 26 | near | 9 | WAVE: 9 mismatch | `.run/backlog_drafts/func_8016130C.c` |
| 74 | func_80161374 | 134 | schedule | 41 | near | 10 | none — MATCH (41/41 relocation-masked) | `.run/backlog_drafts/func_80161374.c` |
| 75 | func_80163764 | 134 | regalloc-order | 42 | near | 10 | none — MATCH (42 ins). pins $s2/$s1/$s0/$s3 + u32 counter (sltiu) + init order s2,s3,i,p | `.run/backlog_drafts/func_80163764.c` |
| 76 | func_80136F3C | 134 | schedule | 61 | near | 10 | 10/61 — regalloc EXACT (param-copy + corner register-pins). residual = gcc list-scheduler permutation of the prologue window (idx 7-16): target saves $s0 before computing xp, sets $s4=0xFF before the D_800B9A02 lhu, and defers xm($s1=$s1-3) to AFTER the lhu; no C-level reorder/barrier reaches it; permuter can't run (pycparser rejects register __asm__). | `.run/backlog_drafts/func_80136F3C.c` |
| 77 | func_80149374 | 134 | remat | 23 | near | 11 | gcc -O2 CSEs &sp18 into freed callee-saved $s0 (1 addu + 2 move); target rematerializes addiu $sp,0x18 twice. Single-buffer straight-line address reused across 2 calls -> CSE wins; no clean C (cast/type/union/ptr-var/$8-pin) flips it; two-distinct-locals remats but grows frame +8 (gcc-2.7.2 won't coalesce slots back to 0x18). Frame/regs/params all match; only this 1 insn differs. | `.run/backlog_drafts/func_80149374.c` |
| 78 | func_8012EFB8 | 134 | other | 32 | near | 11 | none — MATCH (32 ins, byte-verified via objdump -dz; match_one's default objdump elides the 2 consecutive rtps-delay nops as "..." and miscounts 30, but raw bytes are identical) | `.run/backlog_drafts/func_8012EFB8.c` |
| 79 | func_801745AC | 134 | STUB | 12 | near | 12 | STUB: 12 mismatch | `.run/backlog_drafts/func_801745AC.c` |
| 7 | func_801745AC | 134 | STUB | 12 | near | 0 | match_one MATCH but gate rejected (declaration/TU plumbing) | `.run/backlog_drafts/func_801745AC.c` |
| 8 | func_8014C568 | 134 | plumbing | 13 | near | 0 | none — MATCH expected; straightforward ratan2 wrapper with two s16 deltas & 0xFFF | `.run/backlog_drafts/func_8014C568.c` |
| 9 | func_80161208 | 134 | plumbing | 14 | near | 0 | none — MATCH expected (param saved across call → natural $s0, no pin needed) | `.run/backlog_drafts/func_80161208.c` |
| 10 | func_801542A4 | 134 | plumbing | 14 | near | 0 | none — MATCH expected (simple stub: field stores + tail call) | `.run/backlog_drafts/func_801542A4.c` |
| 11 | func_8016F0AC | 134 | plumbing | 14 | near | 0 | none — MATCH (expected; address CSE'd into $s0 across both calls) | `.run/backlog_drafts/func_8016F0AC.c` |
| 12 | func_801653B8 | 134 | plumbing | 15 | near | 0 | none — MATCH expected (simple call-crossing wrapper, param saved in $s0) | `.run/backlog_drafts/func_801653B8.c` |
| 13 | func_80131CA8 | 134 | other | 19 | near | 0 | none — MATCH (call-through-fnptr dispatcher: explicit return 1/return 0) | `.run/backlog_drafts/func_80131CA8.c` |
| 14 | func_8016E778 | 134 | plumbing | 20 | near | 0 | none — MATCH (build-word spread + 3-halfword buffer, two stack addrs passed) | `.run/backlog_drafts/func_8016E778.c` |
| 15 | func_80172C50 | 134 | plumbing | 20 | near | 0 | none — MATCH (unaligned 8-byte memcpy + tail call) | `.run/backlog_drafts/func_80172C50.c` |
| 16 | func_8016BF50 | 134 | schedule | 22 | near | 0 | none — MATCH; short buf[3] keeps all 3 stores live + hoisting *(int*)(p+0x34) into a local | `.run/backlog_drafts/func_8016BF50.c` |
| 17 | func_80166244 | 134 | plumbing | 22 | near | 0 | none — MATCH expected (single tail-call STUB) | `.run/backlog_drafts/func_80166244.c` |
| 18 | func_80146C3C | 134 | loose-typing | 23 | near | 0 | none — MATCH | `.run/backlog_drafts/func_80146C3C.c` |
| 19 | func_80162CCC | 134 | plumbing | 23 | near | 0 | none — MATCH expected; direct translation, psVar1 as u16* gives lhu, $s0=param_1 survives both calls | `.run/backlog_drafts/func_80162CCC.c` |
| 20 | func_8012A598 | 134 | struct | 24 | near | 0 | none — MATCH (24 ins, relocation-masked) | `.run/backlog_drafts/func_8012A598.c` |
| 21 | func_801733FC | 134 | struct | 25 | near | 0 | none — modeled on sibling func_80173460 (packed 8-byte struct copy + two s16=1 stores) | `.run/backlog_drafts/func_801733FC.c` |
| 22 | func_80137614 | 134 | regalloc-order | 26 | near | 0 | none — MATCH (sibling func_8013767C pattern; all 3 params live across the call) | `.run/backlog_drafts/func_80137614.c` |
| 23 | func_80160F00 | 134 | plumbing | 28 | near | 0 | none — MATCH (straight-line STUB; $s0 holds param_1 across calls naturally) | `.run/backlog_drafts/func_80160F00.c` |
| 24 | func_8012F274 | 134 | remat | 29 | near | 0 | none — MATCH (29 ins, match_one byte-clean via relocation-masked pipeline) | `.run/backlog_drafts/func_8012F274.c` |
| 25 | func_8014A51C | 134 | schedule | 32 | near | 0 | none — MATCH (32 ins, relocation-masked) | `.run/backlog_drafts/func_8014A51C.c` |
| 26 | func_801495C4 | 134 | regalloc-order | 34 | near | 0 | none — MATCH expected (cloned byte-matched sibling func_8014964C recipe: $16 pin + asm barriers force param_2→$s0 and rematerialize &in/&mid/mtx) | `.run/backlog_drafts/func_801495C4.c` |
| 27 | func_8012A6D0 | 134 | plumbing | 34 | near | 0 | none — MATCH (sum order p[2]^2 + p[0]^2, then ratan2(p1[1]-p2[1], (s16)dist)) | `.run/backlog_drafts/func_8012A6D0.c` |
| 28 | func_80151664 | 134 | plumbing | 35 | near | 0 | none — MATCH (35 ins, relocation-masked); canonical externs kept, call-site casts only | `.run/backlog_drafts/func_80151664.c` |
| 29 | func_8012F40C | 134 | regalloc-order | 36 | near | 0 | none — MATCH (address rematerialized per call via caller-saved $a0 pin) | `.run/backlog_drafts/func_8012F40C.c` |
| 30 | func_80131D68 | 134 | regalloc-order | 38 | near | 0 | return value held in $v0 per-path (no $s1 frame); using explicit returns | `.run/backlog_drafts/func_80131D68.c` |
| 31 | func_801522CC | 134 | plumbing | 41 | near | 0 | TBD — first compile; func_80153C18 canonical is (void) but target sets $a0=$s0 in its delay slot (call-site cast) | `.run/backlog_drafts/func_801522CC.c` |
| 32 | func_80129C40 | 134 | struct | 46 | near | 0 | none — MATCH (array-of-struct %lo-fold for the two 3-element 0xA4-stride bases) | `.run/backlog_drafts/func_80129C40.c` |
| 33 | func_801497A8 | 134 | regalloc-order | 47 | near | 0 | none — MATCH. $s1 pinned to D_80078E78 base; result accumulator + masked | `.run/backlog_drafts/func_801497A8.c` |
| 34 | func_801483E8 | 134 | struct | 50 | near | 0 | none — MATCH | `.run/backlog_drafts/func_801483E8.c` |
| 35 | func_8015F380 | 134 | plumbing | 50 | near | 0 | none — expect MATCH (single call-crossing local pinned to $s0) | `.run/backlog_drafts/func_8015F380.c` |
| 36 | func_80136DFC | 134 | loose-typing | 50 | near | 0 | none — MATCH | `.run/backlog_drafts/func_80136DFC.c` |
| 37 | func_8016EFC8 | 134 | schedule | 51 | near | 0 | none — MATCH (51 ins). Temp `u32 v = *a0 / 0x4000000;` hoists the load to ins 0 and | `.run/backlog_drafts/func_8016EFC8.c` |
| 38 | func_801376E8 | 134 | schedule | 51 | near | 0 | none — MATCH (51 ins). 3 levers: (1) adjacent-field array u16 D_80126A14[] for A14/A16 | `.run/backlog_drafts/func_801376E8.c` |
| 39 | func_801758FC | 134 | schedule | 55 | near | 0 | none — MATCH (55 ins) | `.run/backlog_drafts/func_801758FC.c` |
| 40 | func_801759D8 | 134 | schedule | 56 | near | 0 | none — MATCH (56 ins) | `.run/backlog_drafts/func_801759D8.c` |
| 41 | func_8012A328 | 134 | schedule | 60 | near | 0 | none — MATCH (60 ins, relocation-masked) | `.run/backlog_drafts/func_8012A328.c` |
| 42 | func_80138DE0 | 134 | other | 60 | near | 0 | none — MATCH (60 ins) | `.run/backlog_drafts/func_80138DE0.c` |
| 43 | func_80133298 | 134 | struct | 65 | near | 0 | none — MATCH (65 ins, relocation-masked) | `.run/backlog_drafts/func_80133298.c` |
| 44 | func_80164418 | 134 | struct | 70 | near | 0 | none — MATCH (s16 stack array forces the spill; 2nd ratan2 reuses /dy/ in $a1) | `.run/backlog_drafts/func_80164418.c` |
| 45 | func_8012E014 | 134 | other | 73 | near | 0 | none — MATCH (expected; straightforward struct-field + global-copy body) | `.run/backlog_drafts/func_8012E014.c` |
| 46 | func_8012E138 | 134 | regalloc-order | 81 | near | 0 | none — MATCH (81/81 ins, match_one proxy); reloaded ptr pinned to $a0 | `.run/backlog_drafts/func_8012E138.c` |
| 47 | func_8012B4B8 | 134 | regalloc-order | 84 | near | 0 | none — MATCH | `.run/backlog_drafts/func_8012B4B8.c` |
| 48 | func_801379FC | 134 | regalloc-order | 97 | near | 0 | none — MATCH (match_one 97/97) | `.run/backlog_drafts/func_801379FC.c` |
| 49 | func_801463A0 | 134 | struct | 101 | near | 0 | none — MATCH (101 ins, match_one); real symbol names; misaligned 8B copy + s16 stores + masked B9C last | `.run/backlog_drafts/func_801463A0.c` |
| 50 | func_80167714 | 134 | regalloc-order | 104 | near | 0 | none — MATCH (104 ins) | `.run/backlog_drafts/func_80167714.c` |
| 51 | func_80169228 | 134 | regalloc-order | 105 | near | 0 | none — MATCH (105 ins, relocation-masked). Key levers: arg0/p pinned $s1/$s0, | `.run/backlog_drafts/func_80169228.c` |
| 52 | func_8012CC88 | 134 | struct | 105 | near | 0 | none — MATCH (105 ins, relocation-masked) | `.run/backlog_drafts/func_8012CC88.c` |
| 53 | func_80174CB0 | 134 | regalloc-order | 123 | near | 0 | none — MATCH (match_one 123/123). Levers: (1) §21 one combined stack struct {s32 a[5]; ...} | `.run/backlog_drafts/func_80174CB0.c` |
| 54 | func_80174CB0 | 134 | struct | 123 | near | 0 | close=0 match_one MATCH but its anon typedef is named 'Buf' which COLLIDES with the existing 'Buf' (s16 h[8], different layout) in the TU. To bank ×134: rename func_80174CB0's Buf -> a unique name AND lift it to engine_types.h (or keep local for ×1). Deferred (fiddly for 123 ins). Type-rename+lift candidate. | `.run/backlog_drafts/func_80174CB0.c` |
| 55 | func_80178004 | 134 | regalloc-order | 165 | near | 0 | none — MATCH (full register pins per sibling func_80177EA4; running-ptr $s2 to stop unroll-rebase; | `.run/backlog_drafts/func_80178004.c` |
| 56 | func_8014F74C | 134 | schedule | 174 | near | 0 | none — MATCH (174 ins). Last mile: §5a volatile barrier blocked gcc jump-threading | `.run/backlog_drafts/func_8014F74C.c` |
| 57 | func_8016F0E4 | 134 | plumbing | 26 | near | 1 | none — MATCH (26 ins); natural C form, param_1 auto-allocated to $s0 | `.run/backlog_drafts/func_8016F0E4.c` |
| 58 | func_8014F3E8 | 134 | WAVE | 32 | near | 1 | WAVE: 1 mismatch | `.run/backlog_drafts/func_8014F3E8.c` |
| 59 | func_80177AD4 | 134 | regalloc-order | 34 | near | 1 | 1 ins — loop-bound shift reads loop-carried $a3 (sll v0,a3,16) vs target's dying copy $v0 (sll v0,v0,16); gcc CSE canonicalizes the two equal-valued regs to the loop-carried one. IV-combine (§20) CRACKED via $a2/$a3 pins (was 31-mismatch "stub"). | `.run/backlog_drafts/func_80177AD4.c` |
| 60 | func_801775E0 | 134 | regalloc-order | 67 | near | 1 | 1 ins — target `sb $v0,0x6($s0)` vs mine `sb $v0,26($s1)` (same store P1+0x1a; gcc address-CSE picks $s1 base not the recomputed $s0); all else byte-identical | `.run/backlog_drafts/func_801775E0.c` |
| 61 | func_8014FFDC | 134 | struct | 93 | near | 1 | none — MATCH | `.run/backlog_drafts/func_8014FFDC.c` |
| 62 | func_80158638 | 134 | plumbing | 87 | near | 2 | none — MATCH (proxy); callee externs are plain func_<addr>, gate's canon/cast passes own them | `.run/backlog_drafts/func_80158638.c` |
| 63 | func_80131A34 | 134 | regalloc-order | 37 | near | 3 | 3-off — (a) prologue saves $ra before $s0 (target: $s0 then $ra) and (b) return-0 path reuses $a1's proven-zero (move $v0,$a1) instead of $zero; both are gcc prologue/return scheduling tie-breaks. Body matches incl. the $v0->$a1 result copy (forced via the $a1-pinned asm anchor), the $v1=-5 mask hoist into the bne delay slot, and the shared-store merge. | `.run/backlog_drafts/func_80131A34.c` |
| 64 | func_80171FFC | 134 | regalloc-order | 40 | near | 3 | none — MATCH (40 ins). Key: func_8017248C takes (a0,a1); calling it with | `.run/backlog_drafts/func_80171FFC.c` |
| 65 | func_801466F0 | 134 | plumbing | 24 | near | 4 | none — MATCH (struct param-spill + branch-polarity) | `.run/backlog_drafts/func_801466F0.c` |
| 66 | func_80147364 | 134 | remat | 30 | near | 4 | none — MATCH (30 ins). Lever: hoist &D_80126B58 into a local ptr `u8 *p=&D_80126B58;` so gcc | `.run/backlog_drafts/func_80147364.c` |
| 67 | func_801325B8 | 134 | schedule | 113 | near | 4 | 4/113 — prologue save-order of the $s0(cur/p3) vs $s5(p1) pair; gcc emits | `.run/backlog_drafts/func_801325B8.c` |
| 68 | func_80146A6C | 134 | struct | 18 | near | 5 | none — MATCH | `.run/backlog_drafts/func_80146A6C.c` |
| 69 | func_80140D68 | 134 | schedule | 65 | near | 5 | 5-ins near-miss — gcc hoists `lui 0xff00` (the 0xFF000000 mask) one slot too early in the first AddPrim block, so the D_800B9A02 index value lands in $v1 instead of $a1 and *param_1 is read late (idx 35-43). Structure + regs otherwise byte-exact (frame eliminated via struct-array D_800AE7BC, &D_800B9A02 held in $a2 via the pB $6 pin, param_1+8 grouping fixes the rest). Pure sched1 list-order residual -> permuter candidate (try reg-hint + reorder around the lui 0xff00 / lw 0($a0) pair). | `.run/backlog_drafts/func_80140D68.c` |
| 70 | func_80130C08 | 134 | schedule | 65 | near | 5 | tail shares one jal func_80131CA8 between the a1=5 and a1=0x38 arms via `j .L80130CEC` with a DUPLICATED `move a0,s0` (one in the beqz delay slot, one at jump-in label .L80130CDC); goto-merge form collapses to 64 ins (one move dropped), if-else form keeps 65 ins but emits two separate jals (idx 54-56 differ + the recheck branch inverts bnez/beqz at idx 51). 5 mismatched, count correct. | `.run/backlog_drafts/func_80130C08.c` |
| 71 | func_80175820 | 134 | schedule | 55 | near | 6 | body byte-IDENTICAL; only residual is the phantom 0x10 leaf frame — target schedules `addiu $sp,-0x10` into the load-delay slot at insn 26 (after the D_8011F7C0 load) and `addiu $sp,0x10` before `jr ra`. With the frame forced (reserved local + anchor) gcc emits the prologue adjust at insn 0 instead of the delay slot (§5 frame-scheduling class); pins block the permuter, no C lever found to move it. Frameless form left here = body byte-exact, 2 frame insns short. | `.run/backlog_drafts/func_80175820.c` |
| 72 | func_8014EA4C | 134 | schedule | 183 | near | 6 | raw close=6: D_801150D8=0 store between a0/a1 loads + abs($v1 move vs in-place negu) pressure-locked by buf[16]+memcpy frame hack — permuter fuel | `.run/drafts-giants/func_8014EA4C.c` |
| 73 | func_8014EE14 | 134 | schedule | 248 | near | 6 | §20 store-vs-load tie-break (x2 loops); frame/regalloc/control-flow/constants byte-exact; no pins/asm -> permuter-ready | `.run/backlog_drafts/func_8014EE14.c` |
| 74 | func_8016130C | 134 | WAVE | 26 | near | 9 | WAVE: 9 mismatch | `.run/backlog_drafts/func_8016130C.c` |
| 75 | func_80161374 | 134 | schedule | 41 | near | 10 | none — MATCH (41/41 relocation-masked) | `.run/backlog_drafts/func_80161374.c` |
| 76 | func_80163764 | 134 | regalloc-order | 42 | near | 10 | none — MATCH (42 ins). pins $s2/$s1/$s0/$s3 + u32 counter (sltiu) + init order s2,s3,i,p | `.run/backlog_drafts/func_80163764.c` |
| 77 | func_80136F3C | 134 | schedule | 61 | near | 10 | 10/61 — regalloc EXACT (param-copy + corner register-pins). residual = gcc list-scheduler permutation of the prologue window (idx 7-16): target saves $s0 before computing xp, sets $s4=0xFF before the D_800B9A02 lhu, and defers xm($s1=$s1-3) to AFTER the lhu; no C-level reorder/barrier reaches it; permuter can't run (pycparser rejects register __asm__). | `.run/backlog_drafts/func_80136F3C.c` |
| 78 | func_80149374 | 134 | remat | 23 | near | 11 | gcc -O2 CSEs &sp18 into freed callee-saved $s0 (1 addu + 2 move); target rematerializes addiu $sp,0x18 twice. Single-buffer straight-line address reused across 2 calls -> CSE wins; no clean C (cast/type/union/ptr-var/$8-pin) flips it; two-distinct-locals remats but grows frame +8 (gcc-2.7.2 won't coalesce slots back to 0x18). Frame/regs/params all match; only this 1 insn differs. | `.run/backlog_drafts/func_80149374.c` |
| 79 | func_8012EFB8 | 134 | other | 32 | near | 11 | none — MATCH (32 ins, byte-verified via objdump -dz; match_one's default objdump elides the 2 consecutive rtps-delay nops as "..." and miscounts 30, but raw bytes are identical) | `.run/backlog_drafts/func_8012EFB8.c` |
| 80 | func_80150528 | 134 | schedule | 53 | near | 12 | none — MATCH (53 ins). Modeled on banked sibling DEFINE_func_80163950 (same D_801202A0 stride-0x10C loop + func_80135A4C call); single-pointer for-loop reproduces gcc's two-IV (p, p+0x20) schedule exactly. NB: §20 had flagged this "unsteerable" pre-sibling-exemplar. | `.run/backlog_drafts/func_80150528.c` |
| 81 | func_80146AFC | 134 | schedule | 40 | near | 13 | none — MATCH | `.run/backlog_drafts/func_80146AFC.c` |
| 82 | func_80131CF4 | 134 | schedule | 29 | near | 15 | 15 mismatches cascade from a 2-instruction gap — target reloads *param_1 (lw v0,0(a0)) into v0 before the loop + a loop-label nop; gcc CSEs the guard-read with the loop-entry read so the pre-loop reload never emits. Top 9 instructions (bnez a0 + j epilogue + shared return-block-at-top) MATCH with this for-form. | `.run/backlog_drafts/func_80131CF4.c` |
@@ -179,65 +179,65 @@
| 171 | func_801372B0 | 134 | GIANT | 207 | failed | | won't compile standalone (loose-typing / missing decl) | |
| 172 | func_80144B9C | 134 | other | 770 | failed | | -O0 cluster fn (prologue 21F0A003, fp-frame, all locals spilled+reloaded, load-delay nops). match_one compiles -O2 so it CANNOT match this; needs its own per-file -O0 split (Makefile CC1FLAGS:=-O0), like ov_SC01_077_o0.c. Body below is the faithful -O0 source; gate via whole-binary -O0 build only. | `.run/backlog_drafts/func_80144B9C.c` |
| 173 | func_80151944 | 4 | struct | 15 | near | 0 | none — MATCH (fn-pointer table dispatch; array-of-ptr indexing folds %lo) | `.run/backlog_drafts/func_80151944.c` |
| 174 | func_8016039C | 2 | struct | 15 | near | 1 | none — MATCH (function-pointer table dispatch indexed by unsigned-halfword field) | `.run/backlog_drafts/func_8016039C.c` |
| 174 | func_8016039C | 2 | STRUCT | 15 | near | 0 | match_one MATCH but gate rejected (declaration/TU plumbing) | `.run/backlog_drafts/func_8016039C.c` |
| 175 | func_8015DAF8 | 1 | struct | 15 | near | 0 | none — MATCH (proxy); identical idiom to matched func_8016901C in same overlay | `.run/backlog_drafts/func_8015DAF8.c` |
| 176 | func_801577C8 | 1 | plumbing | 16 | near | 0 | none — MATCH expected (scalar global store + two sequential calls, param preserved across first call) | `.run/backlog_drafts/func_801577C8.c` |
| 177 | func_80178B70 | 1 | struct | 18 | near | 0 | none — MATCH; local ptr p=&D_8018A458 used for store AND (int)p-0xC arg forces $s0-base reuse across call1, param_1 into $s1 | `.run/backlog_drafts/func_80178B70.c` |
| 178 | func_8013373C | 1 | regalloc-order | 18 | near | 0 | none — MATCH (indexed-global int-array %lo-fold + (short)param*4 fuses sll16/sra14; loaded value pinned to $a0/$4 to reuse the param reg instead of $v0) | `.run/backlog_drafts/func_8013373C.c` |
| 179 | func_8017F240 | 1 | regalloc-order | 20 | near | 0 | none — MATCH (base &D_801270D0 pinned to $s0 holds across call; one lui/addiu reused for load+store) | `.run/backlog_drafts/func_8017F240.c` |
| 180 | func_80157D20 | 1 | plumbing | 21 | near | 0 | none — MATCH expected (call, indexed u16-global load as 2nd arg, then call; param_1 saved across all three calls) | `.run/backlog_drafts/func_80157D20.c` |
| 181 | func_80163408 | 1 | struct | 21 | near | 0 | local 8-byte struct copied from D_801D8BB0, &copy passed as 5th arg (s32) | `.run/backlog_drafts/func_80163408.c` |
| 182 | func_80175184 | 1 | struct | 21 | near | 0 | none — MATCH (fnptr-array %lo-fold dispatch; idx = *(u16*)(a0+2) < 2 ? D_8018A1A4[idx]() : func_80175268()) | `.run/backlog_drafts/func_80175184.c` |
| 183 | func_8012F8C8 | 1 | plumbing | 21 | near | 0 | none — MATCH (pending verify) | `.run/backlog_drafts/func_8012F8C8.c` |
| 184 | func_8014FBC0 | 1 | schedule | 22 | near | 0 | none — MATCH (22 ins). Stack-switch primitive: register $sp var, manual save/switch/restore around the call. | `.run/backlog_drafts/func_8014FBC0.c` |
| 185 | func_80178B18 | 1 | other | 22 | near | 0 | none — MATCH | `.run/backlog_drafts/func_80178B18.c` |
| 186 | func_8017B8E8 | 1 | plumbing | 22 | near | 0 | none — MATCH (two inlined unaligned 8-byte memcpy blocks: src[0..7]->D_801DA794, src[8..15]->D_801DA78C) | `.run/backlog_drafts/func_8017B8E8.c` |
| 187 | func_80182988 | 1 | plumbing | 22 | near | 0 | none — MATCH (u16 store of 0xAA10 forces ori, not sign-extended addiu) | `.run/backlog_drafts/func_80182988.c` |
| 188 | func_801320D8 | 1 | schedule | 27 | near | 0 | none — MATCH (27 ins, relocation-masked) | `.run/backlog_drafts/func_801320D8.c` |
| 189 | func_80132144 | 1 | other | 27 | near | 0 | none — MATCH | `.run/backlog_drafts/func_80132144.c` |
| 190 | func_801321B0 | 1 | other | 27 | near | 0 | none — MATCH (match_one 27/27, relocation-masked) | `.run/backlog_drafts/func_801321B0.c` |
| 191 | func_8013221C | 1 | other | 27 | near | 0 | none — MATCH (expected); straight scheduling, one call-crossing local -> $s0 naturally | `.run/backlog_drafts/func_8013221C.c` |
| 192 | func_801609B8 | 1 | struct | 28 | near | 0 | none — MATCH (pending byte-gate); function-pointer table %lo-fold via extern array | `.run/backlog_drafts/func_801609B8.c` |
| 193 | func_801312D0 | 1 | struct | 28 | near | 0 | none — MATCH (unaligned 8-byte memcpy from global; if/else branch layout) | `.run/backlog_drafts/func_801312D0.c` |
| 194 | func_80136C90 | 1 | other | 28 | near | 0 | local char[10] string-literal init -> rodata-template block move (lwl/lwr + swl/swr + lb/sb), 9+1 split | `.run/backlog_drafts/func_80136C90.c` |
| 195 | func_8017E224 | 1 | struct | 29 | near | 0 | none — MATCH (unaligned 8-byte memcpy of global onto stack + cond byte incr) | `.run/backlog_drafts/func_8017E224.c` |
| 196 | func_80165140 | 1 | regalloc-order | 30 | near | 0 | none — MATCH (pin i=$v1/eight=$a0/p=$a2; DON'T pin param — let it self-copy to $a3 first; memcpy 8/4 unaligned) | `.run/backlog_drafts/func_80165140.c` |
| 197 | func_801549F8 | 1 | iv-combine | 31 | near | 0 | none — MATCH (31 ins). Re-tie barrier on the index defeats gcc's pointer-giv | `.run/backlog_drafts/func_801549F8.c` |
| 198 | func_8015E698 | 1 | struct | 31 | near | 0 | none — MATCH (clean -O2 reconstruction; table-of-fnptr indexed by param_1[0]) | `.run/backlog_drafts/func_8015E698.c` |
| 199 | func_8017D98C | 1 | plumbing | 31 | near | 0 | none — MATCH (expected): straight global stores + tail call; const 0x140 reused for two halves | `.run/backlog_drafts/func_8017D98C.c` |
| 200 | func_80182268 | 1 | struct | 31 | near | 0 | none — MATCH (jump-table switch over sign-extended high byte of *(u16*)(a0+0x70); case4 decrements D_801270CC then falls into case3/7's func_8012C218; no default) | `.run/backlog_drafts/func_80182268.c` |
| 201 | func_801602A4 | 1 | struct | 34 | near | 0 | none — MATCH (template = matched twin func_801601E4; lhu+0x8000 == compare, fnptr-table dispatch D_801891B8[*(u16*)a0]() no-arg, then 3-call setup in target order; func_80161208 in else) | `.run/backlog_drafts/func_801602A4.c` |
| 202 | func_801734BC | 1 | struct | 34 | near | 0 | none — MATCH (pending byte-gate); switch-jtbl with no default, 3 short stores + fnptr call | `.run/backlog_drafts/func_801734BC.c` |
| 203 | func_8017D900 | 1 | plumbing | 35 | near | 0 | none — expect MATCH (STUB: ordered global stores + single tail call, sibling of func_8017D840) | `.run/backlog_drafts/func_8017D900.c` |
| 204 | func_8016BEA0 | 1 | other | 37 | near | 0 | none — MATCH (expected) | `.run/backlog_drafts/func_8016BEA0.c` |
| 205 | func_801754A8 | 1 | regalloc-order | 37 | near | 0 | none — MATCH (37 ins, relocation-masked proxy) | `.run/backlog_drafts/func_801754A8.c` |
| 206 | func_80160920 | 1 | struct | 38 | near | 0 | none — MATCH (function-pointer table folds %lo via extern array indexed by halfword) | `.run/backlog_drafts/func_80160920.c` |
| 207 | func_80183BAC | 1 | struct | 41 | near | 0 | switch jump-table dispatch (jtbl_801D9420); verifying case grouping 0,1,2,5,6/3,7/4 emits the target table + tail | `.run/backlog_drafts/func_80183BAC.c` |
| 208 | func_80183C50 | 1 | struct | 41 | near | 0 | none — MATCH (cross-jump exploit §cookbook L1543: dup func_8012C218 into case3/7 + case4 → merged jal;nop) | `.run/backlog_drafts/func_80183C50.c` |
| 209 | func_8015DF34 | 1 | struct | 44 | near | 0 | none — MATCH (clean structural; fn-ptr table via array index folds %lo) | `.run/backlog_drafts/func_8015DF34.c` |
| 210 | func_8015FE70 | 1 | struct | 44 | near | 0 | none — MATCH expected (fn-ptr-table dispatch + ushort struct fields) | `.run/backlog_drafts/func_8015FE70.c` |
| 211 | func_8014358C | 1 | regalloc-order | 45 | near | 0 | none — MATCH (relocation-masked match_one) | `.run/backlog_drafts/func_8014358C.c` |
| 212 | func_80183AF0 | 1 | regalloc-order | 47 | near | 0 | none — MATCH (mask pinned $a1/$5 + p pinned $v0/$2; switch w/ distributed func_8012C218 tail via dup calls + cross-jump merge) | `.run/backlog_drafts/func_80183AF0.c` |
| 213 | func_80178BF8 | 1 | plumbing | 49 | near | 0 | none — MATCH (pure scalar-store + two pointer-decrement do-while loops) | `.run/backlog_drafts/func_80178BF8.c` |
| 214 | func_8015E344 | 1 | struct | 50 | near | 0 | none — MATCH (pending whole-binary gate); fn-ptr table folds %lo via extern array, 0x234 single word store | `.run/backlog_drafts/func_8015E344.c` |
| 215 | func_8017EC7C | 1 | struct | 52 | near | 0 | none — MATCH (52 ins, relocation-masked) | `.run/backlog_drafts/func_8017EC7C.c` |
| 216 | func_80183CF4 | 1 | struct | 57 | near | 0 | none — MATCH (clean switch + jtbl; orchestrator owns jtbl/rodata migration) | `.run/backlog_drafts/func_80183CF4.c` |
| 217 | func_8015D01C | 1 | regalloc-order | 58 | near | 0 | none — MATCH | `.run/backlog_drafts/func_8015D01C.c` |
| 218 | func_8016D688 | 1 | struct | 60 | near | 0 | none — MATCH (byte array D_801D9C20[] folds the &D_801D9C21 base/-1 offsets; emit p+0xE store BEFORE the param+2 increment so the lhu fills the load-delay slot in $v1) | `.run/backlog_drafts/func_8016D688.c` |
| 219 | func_801842C8 | 1 | plumbing | 62 | near | 0 | none — MATCH | `.run/backlog_drafts/func_801842C8.c` |
| 220 | func_80165240 | 1 | regalloc-order | 63 | near | 0 | none — MATCH (63 ins). buf pinned to $s2 (register __asm__("$18")) so it stays in a callee-saved reg; param_3 then naturally lands in $s3. memcpy(buf+0x30,param_3,4) -> lwl/lwr+swl/swr unaligned 4B copy (cookbook §1 mem->mem). array-of-u8 buf with explicit *(T*)(buf+off) stores; mtx[0x20] declared 2nd so it lands at sp+0x50, buf_ at sp+0x10. | `.run/backlog_drafts/func_80165240.c` |
| 221 | func_8017BB34 | 1 | struct | 65 | near | 0 | none — MATCH (65 ins). Keys: (1) align-1 {s8 b[8]} struct so the two 8-byte copies emit lwl/lwr; (2) stack-local declaration order = target frame order (svin@0x10, buf@0x18, out@0x38, local8@0x40, rt_in@0x48, rt_out@0x50) — reordering the locals to ascending offset fixed all 23 offset-only diffs. | `.run/backlog_drafts/func_8017BB34.c` |
| 222 | func_8016BD78 | 1 | regalloc-order | 74 | near | 0 | none — MATCH (lazy pointer locals pa=&BC4, pb=&BC8 assigned at first use → $a1/$a2 held thru middle code as final call args; middle bytes BC5/BC6/BC9/BCA direct global) | `.run/backlog_drafts/func_8016BD78.c` |
| 223 | func_8016E7C8 | 1 | regalloc-order | 74 | near | 0 | none — MATCH (match_one 74/74; pins $18=&prim, $19=param_3 fixed s2/s3 alloc order; Work struct sized to 0x20) | `.run/backlog_drafts/func_8016E7C8.c` |
| 224 | func_8018281C | 1 | struct | 76 | near | 0 | none — MATCH (76 ins). jtbl forced via explicit case 4/6 (count>=5 over MIPS tablejump threshold); case-5 block placed between if-block and default via goto so the if-block emits j default w/ e2=0 in the delay slot | `.run/backlog_drafts/func_8018281C.c` |
| 225 | func_8016AE5C | 1 | regalloc-order | 85 | near | 0 | none — MATCH (85 ins, match_one). switch/jtbl STRUCT fn. The tail's | `.run/backlog_drafts/func_8016AE5C.c` |
| 226 | func_80182E7C | 1 | struct | 85 | near | 0 | none — MATCH (85 ins, relocation-masked). Two switch-codegen levers: | `.run/backlog_drafts/func_80182E7C.c` |
| 227 | func_8015C7E4 | 1 | struct | 88 | near | 0 | none — MATCH (match_one 88/88); fn-ptr-array dispatch, top-level if/else needed branch-polarity invert (small block falls through, big block at L854) | `.run/backlog_drafts/func_8015C7E4.c` |
| 228 | func_8015CA28 | 1 | schedule | 91 | near | 0 | none — MATCH (goto forces the func_80161240 block to the function tail; bnez-to-end layout vs early-return fall-through) | `.run/backlog_drafts/func_8015CA28.c` |
| 229 | func_801820DC | 1 | struct | 94 | near | 0 | none — MATCH (switch on entity state at 0x34, inner jtbl on (s8)(u70>>8)) | `.run/backlog_drafts/func_801820DC.c` |
| 230 | func_80184D50 | 1 | schedule | 98 | near | 0 | none — MATCH (98 ins, relocation-masked) | `.run/backlog_drafts/func_80184D50.c` |
| 231 | func_80161D20 | 1 | struct | 14 | near | 1 | none — MATCH (array-of-u16 %lo-fold, §18) | `.run/backlog_drafts/func_80161D20.c` |
| 232 | func_8015FAAC | 1 | struct | 15 | near | 1 | none — MATCH expected; fn-ptr table indexed by u16 field at +2, *4 scaled load then jalr | `.run/backlog_drafts/func_8015FAAC.c` |
| 176 | func_8015FAAC | 1 | STRUCT | 15 | near | 0 | match_one MATCH but gate rejected (declaration/TU plumbing) | `.run/backlog_drafts/func_8015FAAC.c` |
| 177 | func_801577C8 | 1 | plumbing | 16 | near | 0 | none — MATCH expected (scalar global store + two sequential calls, param preserved across first call) | `.run/backlog_drafts/func_801577C8.c` |
| 178 | func_80178B70 | 1 | struct | 18 | near | 0 | none — MATCH; local ptr p=&D_8018A458 used for store AND (int)p-0xC arg forces $s0-base reuse across call1, param_1 into $s1 | `.run/backlog_drafts/func_80178B70.c` |
| 179 | func_8013373C | 1 | regalloc-order | 18 | near | 0 | none — MATCH (indexed-global int-array %lo-fold + (short)param*4 fuses sll16/sra14; loaded value pinned to $a0/$4 to reuse the param reg instead of $v0) | `.run/backlog_drafts/func_8013373C.c` |
| 180 | func_8017F240 | 1 | regalloc-order | 20 | near | 0 | none — MATCH (base &D_801270D0 pinned to $s0 holds across call; one lui/addiu reused for load+store) | `.run/backlog_drafts/func_8017F240.c` |
| 181 | func_80157D20 | 1 | plumbing | 21 | near | 0 | none — MATCH expected (call, indexed u16-global load as 2nd arg, then call; param_1 saved across all three calls) | `.run/backlog_drafts/func_80157D20.c` |
| 182 | func_80163408 | 1 | struct | 21 | near | 0 | local 8-byte struct copied from D_801D8BB0, &copy passed as 5th arg (s32) | `.run/backlog_drafts/func_80163408.c` |
| 183 | func_80175184 | 1 | struct | 21 | near | 0 | none — MATCH (fnptr-array %lo-fold dispatch; idx = *(u16*)(a0+2) < 2 ? D_8018A1A4[idx]() : func_80175268()) | `.run/backlog_drafts/func_80175184.c` |
| 184 | func_8012F8C8 | 1 | plumbing | 21 | near | 0 | none — MATCH (pending verify) | `.run/backlog_drafts/func_8012F8C8.c` |
| 185 | func_8014FBC0 | 1 | schedule | 22 | near | 0 | none — MATCH (22 ins). Stack-switch primitive: register $sp var, manual save/switch/restore around the call. | `.run/backlog_drafts/func_8014FBC0.c` |
| 186 | func_80178B18 | 1 | other | 22 | near | 0 | none — MATCH | `.run/backlog_drafts/func_80178B18.c` |
| 187 | func_8017B8E8 | 1 | plumbing | 22 | near | 0 | none — MATCH (two inlined unaligned 8-byte memcpy blocks: src[0..7]->D_801DA794, src[8..15]->D_801DA78C) | `.run/backlog_drafts/func_8017B8E8.c` |
| 188 | func_80182988 | 1 | plumbing | 22 | near | 0 | none — MATCH (u16 store of 0xAA10 forces ori, not sign-extended addiu) | `.run/backlog_drafts/func_80182988.c` |
| 189 | func_801320D8 | 1 | schedule | 27 | near | 0 | none — MATCH (27 ins, relocation-masked) | `.run/backlog_drafts/func_801320D8.c` |
| 190 | func_80132144 | 1 | other | 27 | near | 0 | none — MATCH | `.run/backlog_drafts/func_80132144.c` |
| 191 | func_801321B0 | 1 | other | 27 | near | 0 | none — MATCH (match_one 27/27, relocation-masked) | `.run/backlog_drafts/func_801321B0.c` |
| 192 | func_8013221C | 1 | other | 27 | near | 0 | none — MATCH (expected); straight scheduling, one call-crossing local -> $s0 naturally | `.run/backlog_drafts/func_8013221C.c` |
| 193 | func_801609B8 | 1 | struct | 28 | near | 0 | none — MATCH (pending byte-gate); function-pointer table %lo-fold via extern array | `.run/backlog_drafts/func_801609B8.c` |
| 194 | func_801312D0 | 1 | struct | 28 | near | 0 | none — MATCH (unaligned 8-byte memcpy from global; if/else branch layout) | `.run/backlog_drafts/func_801312D0.c` |
| 195 | func_80136C90 | 1 | other | 28 | near | 0 | local char[10] string-literal init -> rodata-template block move (lwl/lwr + swl/swr + lb/sb), 9+1 split | `.run/backlog_drafts/func_80136C90.c` |
| 196 | func_8017E224 | 1 | struct | 29 | near | 0 | none — MATCH (unaligned 8-byte memcpy of global onto stack + cond byte incr) | `.run/backlog_drafts/func_8017E224.c` |
| 197 | func_80165140 | 1 | regalloc-order | 30 | near | 0 | none — MATCH (pin i=$v1/eight=$a0/p=$a2; DON'T pin param — let it self-copy to $a3 first; memcpy 8/4 unaligned) | `.run/backlog_drafts/func_80165140.c` |
| 198 | func_801549F8 | 1 | iv-combine | 31 | near | 0 | none — MATCH (31 ins). Re-tie barrier on the index defeats gcc's pointer-giv | `.run/backlog_drafts/func_801549F8.c` |
| 199 | func_8015E698 | 1 | struct | 31 | near | 0 | none — MATCH (clean -O2 reconstruction; table-of-fnptr indexed by param_1[0]) | `.run/backlog_drafts/func_8015E698.c` |
| 200 | func_8017D98C | 1 | plumbing | 31 | near | 0 | none — MATCH (expected): straight global stores + tail call; const 0x140 reused for two halves | `.run/backlog_drafts/func_8017D98C.c` |
| 201 | func_80182268 | 1 | struct | 31 | near | 0 | none — MATCH (jump-table switch over sign-extended high byte of *(u16*)(a0+0x70); case4 decrements D_801270CC then falls into case3/7's func_8012C218; no default) | `.run/backlog_drafts/func_80182268.c` |
| 202 | func_801602A4 | 1 | struct | 34 | near | 0 | none — MATCH (template = matched twin func_801601E4; lhu+0x8000 == compare, fnptr-table dispatch D_801891B8[*(u16*)a0]() no-arg, then 3-call setup in target order; func_80161208 in else) | `.run/backlog_drafts/func_801602A4.c` |
| 203 | func_801734BC | 1 | struct | 34 | near | 0 | none — MATCH (pending byte-gate); switch-jtbl with no default, 3 short stores + fnptr call | `.run/backlog_drafts/func_801734BC.c` |
| 204 | func_8017D900 | 1 | plumbing | 35 | near | 0 | none — expect MATCH (STUB: ordered global stores + single tail call, sibling of func_8017D840) | `.run/backlog_drafts/func_8017D900.c` |
| 205 | func_8016BEA0 | 1 | other | 37 | near | 0 | none — MATCH (expected) | `.run/backlog_drafts/func_8016BEA0.c` |
| 206 | func_801754A8 | 1 | regalloc-order | 37 | near | 0 | none — MATCH (37 ins, relocation-masked proxy) | `.run/backlog_drafts/func_801754A8.c` |
| 207 | func_80160920 | 1 | struct | 38 | near | 0 | none — MATCH (function-pointer table folds %lo via extern array indexed by halfword) | `.run/backlog_drafts/func_80160920.c` |
| 208 | func_80183BAC | 1 | struct | 41 | near | 0 | switch jump-table dispatch (jtbl_801D9420); verifying case grouping 0,1,2,5,6/3,7/4 emits the target table + tail | `.run/backlog_drafts/func_80183BAC.c` |
| 209 | func_80183C50 | 1 | struct | 41 | near | 0 | none — MATCH (cross-jump exploit §cookbook L1543: dup func_8012C218 into case3/7 + case4 → merged jal;nop) | `.run/backlog_drafts/func_80183C50.c` |
| 210 | func_8015DF34 | 1 | struct | 44 | near | 0 | none — MATCH (clean structural; fn-ptr table via array index folds %lo) | `.run/backlog_drafts/func_8015DF34.c` |
| 211 | func_8015FE70 | 1 | struct | 44 | near | 0 | none — MATCH expected (fn-ptr-table dispatch + ushort struct fields) | `.run/backlog_drafts/func_8015FE70.c` |
| 212 | func_8014358C | 1 | regalloc-order | 45 | near | 0 | none — MATCH (relocation-masked match_one) | `.run/backlog_drafts/func_8014358C.c` |
| 213 | func_80183AF0 | 1 | regalloc-order | 47 | near | 0 | none — MATCH (mask pinned $a1/$5 + p pinned $v0/$2; switch w/ distributed func_8012C218 tail via dup calls + cross-jump merge) | `.run/backlog_drafts/func_80183AF0.c` |
| 214 | func_80178BF8 | 1 | plumbing | 49 | near | 0 | none — MATCH (pure scalar-store + two pointer-decrement do-while loops) | `.run/backlog_drafts/func_80178BF8.c` |
| 215 | func_8015E344 | 1 | struct | 50 | near | 0 | none — MATCH (pending whole-binary gate); fn-ptr table folds %lo via extern array, 0x234 single word store | `.run/backlog_drafts/func_8015E344.c` |
| 216 | func_8017EC7C | 1 | struct | 52 | near | 0 | none — MATCH (52 ins, relocation-masked) | `.run/backlog_drafts/func_8017EC7C.c` |
| 217 | func_80183CF4 | 1 | struct | 57 | near | 0 | none — MATCH (clean switch + jtbl; orchestrator owns jtbl/rodata migration) | `.run/backlog_drafts/func_80183CF4.c` |
| 218 | func_8015D01C | 1 | regalloc-order | 58 | near | 0 | none — MATCH | `.run/backlog_drafts/func_8015D01C.c` |
| 219 | func_8016D688 | 1 | struct | 60 | near | 0 | none — MATCH (byte array D_801D9C20[] folds the &D_801D9C21 base/-1 offsets; emit p+0xE store BEFORE the param+2 increment so the lhu fills the load-delay slot in $v1) | `.run/backlog_drafts/func_8016D688.c` |
| 220 | func_801842C8 | 1 | plumbing | 62 | near | 0 | none — MATCH | `.run/backlog_drafts/func_801842C8.c` |
| 221 | func_80165240 | 1 | regalloc-order | 63 | near | 0 | none — MATCH (63 ins). buf pinned to $s2 (register __asm__("$18")) so it stays in a callee-saved reg; param_3 then naturally lands in $s3. memcpy(buf+0x30,param_3,4) -> lwl/lwr+swl/swr unaligned 4B copy (cookbook §1 mem->mem). array-of-u8 buf with explicit *(T*)(buf+off) stores; mtx[0x20] declared 2nd so it lands at sp+0x50, buf_ at sp+0x10. | `.run/backlog_drafts/func_80165240.c` |
| 222 | func_8017BB34 | 1 | struct | 65 | near | 0 | none — MATCH (65 ins). Keys: (1) align-1 {s8 b[8]} struct so the two 8-byte copies emit lwl/lwr; (2) stack-local declaration order = target frame order (svin@0x10, buf@0x18, out@0x38, local8@0x40, rt_in@0x48, rt_out@0x50) — reordering the locals to ascending offset fixed all 23 offset-only diffs. | `.run/backlog_drafts/func_8017BB34.c` |
| 223 | func_8016BD78 | 1 | regalloc-order | 74 | near | 0 | none — MATCH (lazy pointer locals pa=&BC4, pb=&BC8 assigned at first use → $a1/$a2 held thru middle code as final call args; middle bytes BC5/BC6/BC9/BCA direct global) | `.run/backlog_drafts/func_8016BD78.c` |
| 224 | func_8016E7C8 | 1 | regalloc-order | 74 | near | 0 | none — MATCH (match_one 74/74; pins $18=&prim, $19=param_3 fixed s2/s3 alloc order; Work struct sized to 0x20) | `.run/backlog_drafts/func_8016E7C8.c` |
| 225 | func_8018281C | 1 | struct | 76 | near | 0 | none — MATCH (76 ins). jtbl forced via explicit case 4/6 (count>=5 over MIPS tablejump threshold); case-5 block placed between if-block and default via goto so the if-block emits j default w/ e2=0 in the delay slot | `.run/backlog_drafts/func_8018281C.c` |
| 226 | func_8016AE5C | 1 | regalloc-order | 85 | near | 0 | none — MATCH (85 ins, match_one). switch/jtbl STRUCT fn. The tail's | `.run/backlog_drafts/func_8016AE5C.c` |
| 227 | func_80182E7C | 1 | struct | 85 | near | 0 | none — MATCH (85 ins, relocation-masked). Two switch-codegen levers: | `.run/backlog_drafts/func_80182E7C.c` |
| 228 | func_8015C7E4 | 1 | struct | 88 | near | 0 | none — MATCH (match_one 88/88); fn-ptr-array dispatch, top-level if/else needed branch-polarity invert (small block falls through, big block at L854) | `.run/backlog_drafts/func_8015C7E4.c` |
| 229 | func_8015CA28 | 1 | schedule | 91 | near | 0 | none — MATCH (goto forces the func_80161240 block to the function tail; bnez-to-end layout vs early-return fall-through) | `.run/backlog_drafts/func_8015CA28.c` |
| 230 | func_801820DC | 1 | struct | 94 | near | 0 | none — MATCH (switch on entity state at 0x34, inner jtbl on (s8)(u70>>8)) | `.run/backlog_drafts/func_801820DC.c` |
| 231 | func_80184D50 | 1 | schedule | 98 | near | 0 | none — MATCH (98 ins, relocation-masked) | `.run/backlog_drafts/func_80184D50.c` |
| 232 | func_80161D20 | 1 | struct | 14 | near | 1 | none — MATCH (array-of-u16 %lo-fold, §18) | `.run/backlog_drafts/func_80161D20.c` |
| 233 | func_8017F714 | 1 | plumbing | 27 | near | 1 | none — MATCH (27/27 ins, match_one verified) | `.run/backlog_drafts/func_8017F714.c` |
| 234 | func_80142A10 | 1 | struct | 28 | near | 1 | none — MATCH (pending byte-gate) | `.run/backlog_drafts/func_80142A10.c` |
| 235 | func_80161C24 | 1 | struct | 29 | near | 1 | none — MATCH (array-of-struct %lo-fold; even/odd u16 fields at off 0/2, stride 4) | `.run/backlog_drafts/func_80161C24.c` |
@@ -262,38 +262,40 @@
| 254 | func_80156044 | 1 | struct | 74 | near | 12 | none — MATCH (74 ins, relocation-masked); $s2-pin for u16-return + def-mask + 3-arg cast on func_80156848 | `.run/backlog_drafts/func_80156044.c` |
| 255 | func_80161CD0 | 1 | regalloc-order | 20 | near | 14 | param_2 must survive the call in $s0; try plain C first then pin to $16 | `.run/backlog_drafts/func_80161CD0.c` |
| 256 | func_80158FA4 | 1 | schedule | 51 | near | 17 | target keeps a DEAD `sra $a1,$v0,16` before `beqz $a1` (sign-extend of func_80159464's | `.run/backlog_drafts/func_80158FA4.c` |
| 257 | func_8018301C | 1 | plumbing | 28 | near | 24 | none — MATCH (straight-line, statement-order; verify with match_one) | `.run/backlog_drafts/func_8018301C.c` |
| 258 | func_8016BBE0 | 1 | other | 56 | near | 24 | none — straightforward; expect MATCH (mirror Ghidra-C order, synth_mult ×0x555) | `.run/backlog_drafts/func_8016BBE0.c` |
| 259 | func_8016E95C | 1 | regalloc-order | 36 | near | 25 | none — MATCH (pending byte-gate) | `.run/backlog_drafts/func_8016E95C.c` |
| 260 | func_80139BE0 | 1 | loose-typing | 39 | near | 32 | target has redundant andi a1,v0,0xff (uchar zero-extend) gcc proves away; else identical | `.run/backlog_drafts/func_80139BE0.c` |
| 261 | func_80148E54 | 1 | regalloc-order | 67 | near | 40 | 67/67 ins, structure+branches+block-order+body-reload all match; residual is pure register-allocation order (permuter-eligible, no register-pins). (1) masked first-angle folds andi->$s1; target keeps it in $a0 then copies addu $s1,$a0 lazily into the beq delay-slot (the s1-copy schedules 1 slot later). (2) the 0x80 const is CSE-held in $a2 across both test+body; target re-materializes 0x80 in $v0 per block (it gets clobbered by `srl v0,v1,8`), which both renames the compare regs ($v0 not $a2) AND fills the body's reload load-delay slot (mine emits a nop there). (3) single-exit ret funnels $v1->$v0 (move v0,v1) where target writes $v0 directly. All three are gcc regalloc/value-prop tie-breaks no C reshape steered (tried: $v0 pin, temp-split, low-mask-reuse compare, memory-clobber-vs-volatile reload) — leave for the permuter. | `.run/backlog_drafts/func_80148E54.c` |
| 262 | func_8017B0E4 | 1 | other | 61 | near | 51 | none — MATCH (expected; clean six-call sign-extend-store pattern) | `.run/backlog_drafts/func_8017B0E4.c` |
| 263 | func_80166F58 | 1 | schedule | 69 | near | 55 | regs/loop/logic/%lo-fold all match (pinned $s0-$s6); residual is reorg.c delay-slot fill — target replicates `addiu $v0,$s2,1` into the 3 skip-branch delay slots + commits `addu $s2,$v0,0` at merge (my codegen emits in-place `addiu $s2,$s2,1` w/ nop slots, -1 ins); plus prologue short-arg promote-then-move not fusing (`sra $a1;addu $s4,$a1,0` vs my fused `sra $s4,$a1`). Not source-steerable (pins block permuter). | `.run/backlog_drafts/func_80166F58.c` |
| 264 | func_80177DA8 | 1 | remat | 63 | near | 58 | gcc narrows `&0xfffffeff` on a 16-bit (lhu) value to `andi 0xfeff` (inline), but target hoisted -0x101 into $t4 (and-reg) in the loop preheader — a gcc-2.7.2 LICM-before-combine pass-ordering quirk unsteerable from C; that 1-ins gap cascades the constant-reg numbering + tail reassoc. Secondary: single-IV loop ptr anchors at +0xA (short, 2 accesses) not +0xC (byte) like target. | `.run/backlog_drafts/func_80177DA8.c` |
| 265 | func_80141A60 | 1 | other | 76 | near | 63 | none — MATCH (76 ins, relocation-masked). Body byte-identical; target reserves an 8-byte | `.run/backlog_drafts/func_80141A60.c` |
| 266 | func_801457A4 | 1 | other | 79 | near | 74 | MATCH at -O0 (79 ins, reloc-masked, real -O0 flags). BANKING BLOCKER: this -O0 fn lives in the -O2 main ov_SC01_077.c; needs its own §18 -O0 split at 0x801457A4 (existing _o0.c covers 0x8013B568..0x8013C98C only). match_one is -O2 -> WRONG here. | `.run/backlog_drafts/func_801457A4.c` |
| 267 | func_8016B6BC | 1 | schedule | 94 | near | 80 | 12-off, all in the last 12 ins (tail). First 82 ins byte-match. Target materializes | `.run/backlog_drafts/func_8016B6BC.c` |
| 268 | func_80134A74 | 1 | regalloc-order | 107 | near | 84 | structure + all 8 callee-saved regs (s0..s7) + block layout MATCH; residual is caller-saved-temp | `.run/backlog_drafts/func_80134A74.c` |
| 269 | func_8013EE10 | 1 | struct | 94 | near | 86 | none — MATCH (94 ins). array-of-struct %lo-fold (E[]) for the 5-elt loops; | `.run/backlog_drafts/func_8013EE10.c` |
| 270 | func_80182338 | 1 | other | 26 | failed | | none — straight-line init; rely on gcc scheduler to hoist $a1/$v0=6 into prologue/delay-slot | `.run/backlog_drafts/func_80182338.c` |
| 271 | func_80184A68 | 1 | regalloc-order | 33 | failed | | none — MATCH | `.run/backlog_drafts/func_80184A68.c` |
| 272 | func_8015E018 | 1 | loose-typing | 47 | failed | | none — MATCH (signed char forces lbu+sll24/sra24 sign-extend; default char is unsigned in this toolchain) | `.run/backlog_drafts/func_8015E018.c` |
| 273 | func_80159A20 | 1 | struct | 58 | failed | | none — MATCH. Key lever: block tail-MERGE (gcc shared `bne ...,$L1` cross-jump) by making the two return-tests STRUCTURALLY DIFFERENT — positive `if(==){goto mask;} return;` per branch (not `if(!=) return;`), so neither tail can merge. Then fix block ORDER by inverting the outer test (`if(d!=1)` makes the ==4/return path the inline fall-through, the d==1/p[2] path the forward `beq`-target block — matching the target layout). | `.run/backlog_drafts/func_80159A20.c` |
| 274 | func_8013E958 | 1 | schedule | 63 | failed | | 2 ins swapped — cc1 emits `andi 0x7f; andi 0xff; beqz`(tests doubly-masked) but target wants `andi 0x7f; beqz; andi 0xff`(andi 0xff in the first beqz delay slot). Loop fully byte-matches; struct/ptr fold idioms nailed (D_80115110.q[0x16] hoists base+0x58 disp, Cell D_80115188[i].v folds %lo). func_800D0488 takes (m&0xFF) arg. s16 m -> 2 mism (right ins count); s32 m fixes order but merges andi+arg-move (62 ins, 1 short). | `.run/backlog_drafts/func_8013E958.c` |
| 275 | func_8013E83C | 1 | plumbing | 71 | failed | | none — MATCH (scalar global stores + 2 conditional calls; §3-T4 branch-polarity invert on the &0xFF test) | `.run/backlog_drafts/func_8013E83C.c` |
| 276 | func_8017B368 | 1 | schedule | 74 | failed | | dead table-path off by 1 ins — target keeps src*16 live in $s0 & computes 2nd arg src16+(base+8) in call1 delay slot; every C form either folds to e+8 (73 ins) or CSEs base into an extra saved reg $s2 (75 ins). All live code (prologue, sltiu dispatch, copy path, 4 struct-copy stores, tail) matches; only the unreachable func_8012F214 path scheduling diverges. | `.run/backlog_drafts/func_8017B368.c` |
| 277 | func_80180B64 | 1 | struct | 75 | failed | | none — MATCH (75 ins, relocation-masked) | `.run/backlog_drafts/func_80180B64.c` |
| 278 | func_80180F10 | 1 | schedule | 75 | failed | | none — MATCH (aggregate-initializer form schedules const setup after the prologue saves) | `.run/backlog_drafts/func_80180F10.c` |
| 279 | func_8016C188 | 1 | schedule | 79 | failed | | none — MATCH (79 ins, match_one). Levers: invert if to if(iVar1!=0){big}else{small} | `.run/backlog_drafts/func_8016C188.c` |
| 280 | func_80164930 | 1 | regalloc-order | 81 | failed | | none — MATCH (81 ins, relocation-masked) | `.run/backlog_drafts/func_80164930.c` |
| 281 | func_801418F8 | 1 | loose-typing | 90 | failed | | none — MATCH (90 ins). Keys: D_8011511A is `volatile u16` (store-2-then-read must NOT const-fold), read ONCE into a `u16` local t (an `unsigned int` local adds a stray andi 0xffff; reusing t feeds the single lhu to both sltiu and t-3), and the lone D_80115158 store after the if yields the delay-slot-fill-from-target dup of `addiu 0x106`. | `.run/backlog_drafts/func_801418F8.c` |
| 282 | func_801789AC | 1 | struct | 91 | failed | | none — MATCH (91 ins, relocation-masked) | `.run/backlog_drafts/func_801789AC.c` |
| 283 | func_80183DE0 | 1 | regalloc-order | 91 | failed | | testing if(!=1) layout + counter-before-pointer init order | `.run/backlog_drafts/func_80183DE0.c` |
| 284 | func_80185428 | 1 | struct | 94 | failed | | none — MATCH (94 ins, relocation-masked) | `.run/backlog_drafts/func_80185428.c` |
| 285 | func_801506A4 | 1 | loose-typing | 95 | failed | | none — MATCH (95 ins). switch var must be int not u16 (u16 adds andi 0xffff promotion mask) | `.run/backlog_drafts/func_801506A4.c` |
| 286 | func_8016BFD0 | 1 | struct | 95 | failed | | none — MATCH (95 ins). memcpy(d,s,4) -> lwl/lwr/swl/swr; MATRIX work buf as s32[16] (0x40, fills 0x10-0x4f, t[] = buf[5..7]); two SVECTOR locals at 0x50/0x58; natural saved-reg order s0=param_5/s1=param_4/s2=iVar5 | `.run/backlog_drafts/func_8016BFD0.c` |
| 287 | func_801596F0 | 1 | struct | 97 | failed | | none — MATCH (97 ins). Loop 1 = struct-ptr for-loop (E38, flag@+4) -> -4 guard / +4 test via gcc biv-elim. Loop 2 needed an EXPLICIT if-guard + do-while with the FIELD pointer as the loop var (so the giv init emits FIRST in the preheader, before the &D invariant block), a non-volatile re-tie barrier on d=&D_800AFAE8 (keeps &D BARE so +4/+0x88 add off it = +1 ins vs the folded %lo, matching target), an explicit u32 mask hoisted first (fills the guard's delay slot), and a separate range check fp<d+4 // fp>=d+0x88. | `.run/backlog_drafts/func_801596F0.c` |
| 288 | func_8017B490 | 1 | schedule | 97 | failed | | none — MATCH (97 ins). Keys: (1) inverted if so the SV4 block-copy else is fallthrough and block A is bnez-far (cond = (u32)&D_801DA73C >= 0xB, a relocated-symbol compare gcc can't fold); (2) SV4{s16 a,b,c,d} align-2 8-byte copy -> lwl/lwr/swl/swr, locals at sp+0x10/0x18; (3) the DEAD block-A index = (s32)&D_801DA73C into D_8018A45C[] (WAVE16=two SV4) needs BOTH source addrs (&[idx].v0,&[idx].v1) in EXPLICIT TEMPS before call1 so base (&D_8018A45C) dies pre-call -> temp $v0 (not callee-saved), forcing the natural 2-reg alloc idx=$s0/param_1=$s1 + src2 into call1's delay slot; (4) tail: D_801DA794/D_801DA78C are SV4, re-read .a/.b/.c via lh sign-extended to s32 stores. | `.run/backlog_drafts/func_8017B490.c` |
| 289 | func_80182C9C | 1 | schedule | 101 | failed | | none — MATCH (101 ins). Inner-switch break-to-shared-tail must be written as | `.run/backlog_drafts/func_80182C9C.c` |
| 290 | func_80183FB8 | 1 | loose-typing | 101 | failed | | none — MATCH (relocation-masked match_one, 101/101 ins) | `.run/backlog_drafts/func_80183FB8.c` |
| 291 | func_8013EF88 | 1 | struct | 108 | failed | | none — MATCH (108 ins). Keys: (1) §18 array-of-struct E4{s32 v} for | `.run/backlog_drafts/func_8013EF88.c` |
| 257 | func_80182338 | 1 | PINS | 26 | near | 24 | PINS: 24 mismatch | `.run/backlog_drafts/func_80182338.c` |
| 258 | func_8018301C | 1 | plumbing | 28 | near | 24 | none — MATCH (straight-line, statement-order; verify with match_one) | `.run/backlog_drafts/func_8018301C.c` |
| 259 | func_8016BBE0 | 1 | other | 56 | near | 24 | none — straightforward; expect MATCH (mirror Ghidra-C order, synth_mult ×0x555) | `.run/backlog_drafts/func_8016BBE0.c` |
| 260 | func_8016E95C | 1 | regalloc-order | 36 | near | 25 | none — MATCH (pending byte-gate) | `.run/backlog_drafts/func_8016E95C.c` |
| 261 | func_80139BE0 | 1 | loose-typing | 39 | near | 32 | target has redundant andi a1,v0,0xff (uchar zero-extend) gcc proves away; else identical | `.run/backlog_drafts/func_80139BE0.c` |
| 262 | func_80148E54 | 1 | regalloc-order | 67 | near | 40 | 67/67 ins, structure+branches+block-order+body-reload all match; residual is pure register-allocation order (permuter-eligible, no register-pins). (1) masked first-angle folds andi->$s1; target keeps it in $a0 then copies addu $s1,$a0 lazily into the beq delay-slot (the s1-copy schedules 1 slot later). (2) the 0x80 const is CSE-held in $a2 across both test+body; target re-materializes 0x80 in $v0 per block (it gets clobbered by `srl v0,v1,8`), which both renames the compare regs ($v0 not $a2) AND fills the body's reload load-delay slot (mine emits a nop there). (3) single-exit ret funnels $v1->$v0 (move v0,v1) where target writes $v0 directly. All three are gcc regalloc/value-prop tie-breaks no C reshape steered (tried: $v0 pin, temp-split, low-mask-reuse compare, memory-clobber-vs-volatile reload) — leave for the permuter. | `.run/backlog_drafts/func_80148E54.c` |
| 263 | func_8017B0E4 | 1 | other | 61 | near | 51 | none — MATCH (expected; clean six-call sign-extend-store pattern) | `.run/backlog_drafts/func_8017B0E4.c` |
| 264 | func_80166F58 | 1 | schedule | 69 | near | 55 | regs/loop/logic/%lo-fold all match (pinned $s0-$s6); residual is reorg.c delay-slot fill — target replicates `addiu $v0,$s2,1` into the 3 skip-branch delay slots + commits `addu $s2,$v0,0` at merge (my codegen emits in-place `addiu $s2,$s2,1` w/ nop slots, -1 ins); plus prologue short-arg promote-then-move not fusing (`sra $a1;addu $s4,$a1,0` vs my fused `sra $s4,$a1`). Not source-steerable (pins block permuter). | `.run/backlog_drafts/func_80166F58.c` |
| 265 | func_80177DA8 | 1 | remat | 63 | near | 58 | gcc narrows `&0xfffffeff` on a 16-bit (lhu) value to `andi 0xfeff` (inline), but target hoisted -0x101 into $t4 (and-reg) in the loop preheader — a gcc-2.7.2 LICM-before-combine pass-ordering quirk unsteerable from C; that 1-ins gap cascades the constant-reg numbering + tail reassoc. Secondary: single-IV loop ptr anchors at +0xA (short, 2 accesses) not +0xC (byte) like target. | `.run/backlog_drafts/func_80177DA8.c` |
| 266 | func_80141A60 | 1 | other | 76 | near | 63 | none — MATCH (76 ins, relocation-masked). Body byte-identical; target reserves an 8-byte | `.run/backlog_drafts/func_80141A60.c` |
| 267 | func_801457A4 | 1 | other | 79 | near | 74 | MATCH at -O0 (79 ins, reloc-masked, real -O0 flags). BANKING BLOCKER: this -O0 fn lives in the -O2 main ov_SC01_077.c; needs its own §18 -O0 split at 0x801457A4 (existing _o0.c covers 0x8013B568..0x8013C98C only). match_one is -O2 -> WRONG here. | `.run/backlog_drafts/func_801457A4.c` |
| 268 | func_8016B6BC | 1 | schedule | 94 | near | 80 | 12-off, all in the last 12 ins (tail). First 82 ins byte-match. Target materializes | `.run/backlog_drafts/func_8016B6BC.c` |
| 269 | func_80134A74 | 1 | regalloc-order | 107 | near | 84 | structure + all 8 callee-saved regs (s0..s7) + block layout MATCH; residual is caller-saved-temp | `.run/backlog_drafts/func_80134A74.c` |
| 270 | func_8013EE10 | 1 | struct | 94 | near | 86 | none — MATCH (94 ins). array-of-struct %lo-fold (E[]) for the 5-elt loops; | `.run/backlog_drafts/func_8013EE10.c` |
| 271 | func_80185E68 | 1 | STRUCT | 132 | near | 131 | STRUCT: 131 mismatch | `.run/backlog_drafts/func_80185E68.c` |
| 272 | func_801824D0 | 1 | WAVE | 181 | near | 180 | WAVE: 180 mismatch | `.run/backlog_drafts/func_801824D0.c` |
| 273 | func_80184A68 | 1 | regalloc-order | 33 | failed | | none — MATCH | `.run/backlog_drafts/func_80184A68.c` |
| 274 | func_8015E018 | 1 | loose-typing | 47 | failed | | none — MATCH (signed char forces lbu+sll24/sra24 sign-extend; default char is unsigned in this toolchain) | `.run/backlog_drafts/func_8015E018.c` |
| 275 | func_80159A20 | 1 | struct | 58 | failed | | none — MATCH. Key lever: block tail-MERGE (gcc shared `bne ...,$L1` cross-jump) by making the two return-tests STRUCTURALLY DIFFERENT — positive `if(==){goto mask;} return;` per branch (not `if(!=) return;`), so neither tail can merge. Then fix block ORDER by inverting the outer test (`if(d!=1)` makes the ==4/return path the inline fall-through, the d==1/p[2] path the forward `beq`-target block — matching the target layout). | `.run/backlog_drafts/func_80159A20.c` |
| 276 | func_8013E958 | 1 | schedule | 63 | failed | | 2 ins swapped — cc1 emits `andi 0x7f; andi 0xff; beqz`(tests doubly-masked) but target wants `andi 0x7f; beqz; andi 0xff`(andi 0xff in the first beqz delay slot). Loop fully byte-matches; struct/ptr fold idioms nailed (D_80115110.q[0x16] hoists base+0x58 disp, Cell D_80115188[i].v folds %lo). func_800D0488 takes (m&0xFF) arg. s16 m -> 2 mism (right ins count); s32 m fixes order but merges andi+arg-move (62 ins, 1 short). | `.run/backlog_drafts/func_8013E958.c` |
| 277 | func_8013E83C | 1 | plumbing | 71 | failed | | none — MATCH (scalar global stores + 2 conditional calls; §3-T4 branch-polarity invert on the &0xFF test) | `.run/backlog_drafts/func_8013E83C.c` |
| 278 | func_8017B368 | 1 | schedule | 74 | failed | | dead table-path off by 1 ins — target keeps src*16 live in $s0 & computes 2nd arg src16+(base+8) in call1 delay slot; every C form either folds to e+8 (73 ins) or CSEs base into an extra saved reg $s2 (75 ins). All live code (prologue, sltiu dispatch, copy path, 4 struct-copy stores, tail) matches; only the unreachable func_8012F214 path scheduling diverges. | `.run/backlog_drafts/func_8017B368.c` |
| 279 | func_80180B64 | 1 | struct | 75 | failed | | none — MATCH (75 ins, relocation-masked) | `.run/backlog_drafts/func_80180B64.c` |
| 280 | func_80180F10 | 1 | schedule | 75 | failed | | none — MATCH (aggregate-initializer form schedules const setup after the prologue saves) | `.run/backlog_drafts/func_80180F10.c` |
| 281 | func_8016C188 | 1 | schedule | 79 | failed | | none — MATCH (79 ins, match_one). Levers: invert if to if(iVar1!=0){big}else{small} | `.run/backlog_drafts/func_8016C188.c` |
| 282 | func_80164930 | 1 | regalloc-order | 81 | failed | | none — MATCH (81 ins, relocation-masked) | `.run/backlog_drafts/func_80164930.c` |
| 283 | func_801418F8 | 1 | loose-typing | 90 | failed | | none — MATCH (90 ins). Keys: D_8011511A is `volatile u16` (store-2-then-read must NOT const-fold), read ONCE into a `u16` local t (an `unsigned int` local adds a stray andi 0xffff; reusing t feeds the single lhu to both sltiu and t-3), and the lone D_80115158 store after the if yields the delay-slot-fill-from-target dup of `addiu 0x106`. | `.run/backlog_drafts/func_801418F8.c` |
| 284 | func_801789AC | 1 | struct | 91 | failed | | none — MATCH (91 ins, relocation-masked) | `.run/backlog_drafts/func_801789AC.c` |
| 285 | func_80183DE0 | 1 | regalloc-order | 91 | failed | | testing if(!=1) layout + counter-before-pointer init order | `.run/backlog_drafts/func_80183DE0.c` |
| 286 | func_80185428 | 1 | struct | 94 | failed | | none — MATCH (94 ins, relocation-masked) | `.run/backlog_drafts/func_80185428.c` |
| 287 | func_801506A4 | 1 | loose-typing | 95 | failed | | none — MATCH (95 ins). switch var must be int not u16 (u16 adds andi 0xffff promotion mask) | `.run/backlog_drafts/func_801506A4.c` |
| 288 | func_8016BFD0 | 1 | struct | 95 | failed | | none — MATCH (95 ins). memcpy(d,s,4) -> lwl/lwr/swl/swr; MATRIX work buf as s32[16] (0x40, fills 0x10-0x4f, t[] = buf[5..7]); two SVECTOR locals at 0x50/0x58; natural saved-reg order s0=param_5/s1=param_4/s2=iVar5 | `.run/backlog_drafts/func_8016BFD0.c` |
| 289 | func_801596F0 | 1 | struct | 97 | failed | | none — MATCH (97 ins). Loop 1 = struct-ptr for-loop (E38, flag@+4) -> -4 guard / +4 test via gcc biv-elim. Loop 2 needed an EXPLICIT if-guard + do-while with the FIELD pointer as the loop var (so the giv init emits FIRST in the preheader, before the &D invariant block), a non-volatile re-tie barrier on d=&D_800AFAE8 (keeps &D BARE so +4/+0x88 add off it = +1 ins vs the folded %lo, matching target), an explicit u32 mask hoisted first (fills the guard's delay slot), and a separate range check fp<d+4 // fp>=d+0x88. | `.run/backlog_drafts/func_801596F0.c` |
| 290 | func_8017B490 | 1 | schedule | 97 | failed | | none — MATCH (97 ins). Keys: (1) inverted if so the SV4 block-copy else is fallthrough and block A is bnez-far (cond = (u32)&D_801DA73C >= 0xB, a relocated-symbol compare gcc can't fold); (2) SV4{s16 a,b,c,d} align-2 8-byte copy -> lwl/lwr/swl/swr, locals at sp+0x10/0x18; (3) the DEAD block-A index = (s32)&D_801DA73C into D_8018A45C[] (WAVE16=two SV4) needs BOTH source addrs (&[idx].v0,&[idx].v1) in EXPLICIT TEMPS before call1 so base (&D_8018A45C) dies pre-call -> temp $v0 (not callee-saved), forcing the natural 2-reg alloc idx=$s0/param_1=$s1 + src2 into call1's delay slot; (4) tail: D_801DA794/D_801DA78C are SV4, re-read .a/.b/.c via lh sign-extended to s32 stores. | `.run/backlog_drafts/func_8017B490.c` |
| 291 | func_80182C9C | 1 | schedule | 101 | failed | | none — MATCH (101 ins). Inner-switch break-to-shared-tail must be written as | `.run/backlog_drafts/func_80182C9C.c` |
| 292 | func_80183FB8 | 1 | loose-typing | 101 | failed | | none — MATCH (relocation-masked match_one, 101/101 ins) | `.run/backlog_drafts/func_80183FB8.c` |
| 293 | func_8013EF88 | 1 | struct | 108 | failed | | none — MATCH (108 ins). Keys: (1) §18 array-of-struct E4{s32 v} for | `.run/backlog_drafts/func_8013EF88.c` |
+36
View File
@@ -113,6 +113,42 @@ Two forward levers besides fine-tuning:
- **Cloud cheap tier (Haiku/GLM-5.2)** stays the working low-cost drafter today (the local-free tier
needs the fine-tune or the seed role to be useful).
### T7 RESULT — the broad-rotation gate debugged 2026-06-30 (0/222 was TWO harness bugs, not the model)
The 500-fn calibration run (`lora_grind`) banked **0/222** across ov_SC01_000→ov_SC02_005 while the
model banked ~18% on ov_SC01_077. Root-caused (R14 — by reading the code + the run's own backlog,
which resolved a direct contradiction between two scout agents) to **two independent bugs in
`lora_grind`'s use of `gate_stage.run_gate`**, NOT model quality:
- **Bug A — good_sha format:** `lora_grind.good_sha()` returned the whole sha1sum line `"<sha> <name>"`;
`harvest_verify` compares it against a bare `sha1()` → never equal → **0 banks for EVERY binary
including 077**. So the "077 0/12" in that run was a *bug artifact*, not an exhausted tail (a claim I
nearly enshrined before reading the `.sha` format — the R14 payoff).
- **Bug B — path mis-resolution:** the gate call passed only `binary`+`good_sha`, leaving
`src`/`asm`/`out` at the hardcoded ov_SC01_077 defaults → non-077 drafts dropped at the 077 stub-filter
→ 0 banks, **silently**, and the backlog near-miss classes were contaminated by the mis-resolved asm
(so that run's "199 compile-fail" breakdown was untrustworthy for non-077 fns).
Fix (`tools/gate_stage.py`): `run_gate` now resolves `src`/`asm`/`out`/`good_sha` from `binary` when
unset (binary-agnostic — the Phase-9 "no silent default an overlay inherits" discipline; good_sha
normalized to the bare hash) + a **loud negative-control guard** (warns when 0 drafts are stubs in the
binary's own sources — the silent-0 can never recur). `lora_grind.good_sha` also fixed at source.
Byte-neutral (check-all 136/136); zero `lora_grind` logic change beyond the one-line good_sha fix.
**The first trustworthy on-OPEN-stubs signal (ov_SC01_000 spot-run, 15 smallest ≤15-ins stubs):**
- **Gate-banked 7/15 (47%) byte-identical** (check-all 136/136, auto-committed). Proxy `match_one`:
6 leaf-exact + 1 recovered via the TU-plumbing pipeline. Backlog (now correctly classified): 6
near-misses — **four at closeness=1** (prime grinder/permuter fuel) — + 2 standalone-compile-fails
(struct types → corpus-v3). The 0/222 was 100% the bugs; the model is a strong Tier-0 on the small
open-stub tail **fleet-wide**, the production number the corpus-v2 caveat (above) flagged as unmeasured.
**ROI finding (the sizing input):** of the 7 banks, **6 are reach-1 (overlay-UNIQUE, ×1)** and 1 is
reach-2. The broad rotation's small non-077 stubs are predominantly overlay-unique → **high bank-RATE,
low fleet-% ROI** (each ×1; the fleet % barely moved, +8 fns). The fleet-% levers are therefore
**reach≥2 targeting** (the ×134 multiplier — a `lora_grind`/`wave_targets` `--min-reach` filter, T9) and
the canonical-site (077) harvest, plus **corpus-v3** for the struct compile-fails (T8) — NOT a blind
broad rotation. A broad ≤15-ins run remains worthwhile for per-overlay completeness, corpus growth
(retrain fuel), and seeding the permuter grinder with the close=1 near-misses.
## Open questions / notes
- **Corpus quality > size.** ~1,700 verified pairs is plenty for LoRA; dedup near-identical reach
+5 -5
View File
@@ -3,19 +3,19 @@
# source-derived (committed src/*.c + config/dedup.us.yaml). Live byte gate: `make check-all`;
# cross-binary collapsible-byte leverage: docs/duplicates.cross.md.
FLEET REAL substantive : 217964 (of which dedup-shared 217217 via 1633 groups / 217268 instances)
FLEET REAL substantive : 217972 (of which dedup-shared 217219 via 1634 groups / 217270 instances)
FLEET LINKED PsyQ objs : 959
FLEET byte-identical : 219611 / 344941 = 63.67% (REAL+LINKED+empties)
FLEET byte-identical : 219619 / 344941 = 63.67% (REAL+LINKED+empties)
FLEET NON_MATCHING : 7 (0 in any default build — G4)
FLEET INCLUDE_ASM stubs : 125323
FLEET INCLUDE_ASM stubs : 125315
FLEET matchable : 344941
| binary | REAL | shared | LINKED | byte-ident | matchable | byte-ident % |
|---|---:|---:|---:|---:|---:|---:|
| main | 54 | 2 | 959 | 1055 | 2096 | 50.3% |
| resident | 123 | 0 | 0 | 125 | 146 | 85.6% |
| ov_SC01_000 | 1625 | 1625 | 0 | 1625 | 2410 | 67.4% |
| ov_SC01_001 | 1625 | 1625 | 0 | 1627 | 2474 | 65.8% |
| ov_SC01_000 | 1632 | 1626 | 0 | 1632 | 2410 | 67.7% |
| ov_SC01_001 | 1626 | 1626 | 0 | 1628 | 2474 | 65.8% |
| ov_SC01_004 | 1617 | 1617 | 0 | 1618 | 2423 | 66.8% |
| ov_SC01_005 | 1624 | 1624 | 0 | 1631 | 2511 | 65.0% |
| ov_SC01_006 | 1624 | 1624 | 0 | 1631 | 2511 | 65.0% |
+45 -52
View File
@@ -1,74 +1,67 @@
# CURRENT PHASE — Phase 22: Hand-grind the giants (×134) + idiom-distill-then-fan-out flywheel
# CURRENT PHASE — Phase 23: The offline LLM matching tier (free local-model grinder + the data flywheel)
**Generation:** Gen2 (14th phase of the arc; Phase 14 deferred to Gen3+) · **Started:** 2026-06-26 · **Effort:** Max (giants/synthesis) ↔ Ultracode (idiom waves, prompt per R27) · **Plan approved:** gate 1 ✅ (Drew)
**Generation:** Gen2 (15th phase of the arc) · **Started:** 2026-06-29 · **Effort:** Max (synthesis/decisions/debug) ↔ xHigh (mechanical) · **Plan:** set up at PhaseEnd_Phase22 close (Drew); substance was already built across the 2026-06-29 session.
> Per-task crash-recovery log (P3). The full approved plan is at `~/.claude/plans/plan-mode-enabled-max-shimmering-thimble.md`. This file is the committable state a fresh session resumes from.
> Per-task crash-recovery log (P3). This file is the committable state a fresh session resumes from. Phase 22 (giants) closed → `PhaseEnd_Phase22.md` + `phase-ends/logs/Phase22.md`. The deep design + measured results of this phase live in `docs/gen2-mips-matching-model.md` (+ `docs/history/cheap-tier-ab-experiment.md`); the working-knowledge in the `cheap-tier-ab-validated` memory.
## Goal
Stand up a **free, local, fine-tuned matching model** that grinds the small/medium-function bulk and banks byte-verified matches for **$0** — with (a) a **data flywheel** (banks grow the corpus → retrain → the model improves *during* the run), (b) **escalation** (the permuter `grinder.py` closes the regalloc/schedule near-misses the model leaves; bigger models / your Opus take the tail), and (c) the **whole-binary byte-gate as the incorruptible sole arbiter** (a weak model is a *throughput* risk only, never correctness). **On-demand, NOT 24/7** (run only when Drew says go).
Drive the **byte-weighted** progress number (~30% decomp.dev-comparable; the function-count metric is at 63.18%) by **hand-grinding the giants** (reach-134, >150 ins — each banks ×134), distilling each crack into a reusable idiom, then fanning that idiom out across its class via the existing wave harness. Open-ended; monotonic; zero regressions; close at a clean checkpoint when giant ROI drops.
## Decisions (Drew)
- **On-demand runs**, bounded — never a standing 24/7 daemon. Queue a large batch, run a single shot, measure, scale the next.
- **Serve the model on the GPU via LM Studio** (Unsloth's bundled llama.cpp is CPU-only); the WSL agent hits it over the LAN (`http://192.168.1.113:1234/v1`, "serve on local network" + Windows host IP).
- **Measure before investing** (the discipline that killed the v1 dead-end): every corpus/model change is **retested free on the 7B first**, and only scaled to a cloud dense model if the cheap retest pays.
- **Corpus-v3 = struct types** (next), then a dense **Qwen2.5-Coder-14B** (the "12B") on cloud for the struct *giants* — only if v3-on-7B lifts the struct band.
## Decisions (Drew, gate 1)
- **Calibrate on a mid-giant first:** `func_8015126C` (254 ins / 135K, already a **close=2** backlog near-miss) → `func_8014EE14` (248 / 131K, close=6) → escalate toward `func_80144B9C` (770 / 410K).
- **Background grinder ON:** token-free permuter daemon on the regalloc/coalescing residual, alongside the hand-loop.
## The operating loop
A. Hand-decomp next giant (Max) → §27 recipe → match_one → harvest_verify byte-gate → dedup_propagate ×134 → commit. ROI-gate: irreducible class → bank closest draft to backlog (P9), move on.
B. Distill the last-mile idiom → cookbook (R16/R30).
C. If general → fan out a few waves (Ultracode, prompt R26/R27) applying it → gate_stage → distill.js → backlog.
D. Rinse and repeat (next giant, highest byte-weight first).
## The operating loop (when running)
A. `lora_grind.py` (GPU) drafts open ≤N-ins stubs with the served fine-tuned model → banks via `gate_stage` → near-misses to the backlog.
B. `grinder.py` (CPU permuter) closes the backlog's regalloc/schedule near-misses → banks. **Run A+B concurrently** (GPU vs CPU; the histogram already shows 94 schedule/regalloc nears waiting).
C. Periodic propagate sweep (`dedup_propagate`) multiplies each bank fleet-wide.
D. Periodically: `export_pairs → format_finetune → train_lora → redeploy` (the model learns its own new wins); read the near-by-class histogram → pick the corpus-v3 / recovery-tooling target; raise `--max-nins` as the band lifts.
## Tasks
- [x] **T0 — Unified byte-weighted ranked worklist** *(done — `commit:0296`)* — `tools/worklist.py` → `docs/worklist.md` + `.run/worklist.json`.
- [x] **T1 — Calibrate on func_8015126C** *(done — banked ×134, fleet 63.18→63.22%, check-all 136/136)* — pin idiom + canonical-extern/block-scope recovery cracked it; all 23 giants confirmed Ghidra-C-cached (no prefetch needed).
- [ ] **T2 — Hand-decomp giants by byte-weight (loop)** — func_8014EE14 → … → func_80144B9C; one at a time, byte-gated, propagated ×134, committed. Report each (P3).
- [x] **T3 — Distill idioms → cookbook** *(done for func_8015126C — cookbook §28/§28a + `tools/recover_giant.py`, `commit:0298`)* — recurring per future crack.
- [ ] **T4 — Idiom fan-out waves (Ultracode)** — a few waves per learned idiom over its class (prompt R27). *(close=0 canonical-extern "wave" was probed → R14 refuted near-free; only func_8015126C banked.)*
- [x] **T5 — Background grinder** *(started + STOPPED for handoff; STOP sentinel set; banked 0 on the hard giants it sampled)* — RESUME: `rm .run/auto/STOP` then `DRIVER=tools/grinder.py setsid nohup bash tools/auto_supervisor.sh --permute-secs 120 -j 14 >/dev/null 2>&1 & disown`; monitor `bash tools/auto_status.sh`.
- [ ] **T6 — Progress honesty + PhaseEnd** — keep worklist/backlog/progress.fleet.md fresh; track both %s; PhaseEnd_Phase22.md at close (Tier-1 Max).
- [x] **T1 — Cheap-tier A/B** (Opus orchestrator + cheap agents) — Haiku 4.8× more matches/$ than Opus on the bulk; tools `tools/workflows/ab_match.js` + `tools/ab_score.py`. (`docs/history/cheap-tier-ab-experiment.md`.)
- [x] **T2 — Stock-local floor** — Qwen3.6-35B-A3B (LM Studio): structurally smart but **0 reliable byte-matches** (can't refine to byte-exact); format-robust; full-cookbook context made it *worse* (dilution). The floor to beat.
- [x] **T3 — The LoRA specialist pipeline** — `export_pairs.py` (mine banked asm↔C from build objects) → `format_finetune.py` (Qwen chat-template, compile-filtered) → `train_lora.py` (Unsloth QLoRA, Qwen2.5-Coder-7B, GPU on the 3080 Ti) → `eval_lora.py` (held-out gate-true). Corpus `datasets/match_pairs/` (gitignored).
- [x] **T4 — Corpus-v2 = the extern-block fix (THE unlock)** — capture the `extern <type> D_xxx;` block the src declares above each def (correct byte-verified types) → self-contained completions, compile 52%→92%, train 638→1111 (non-trivial 257→813). Same 7B retrained: held-out **6–15 ins 0%→85%**, non-trivial 0→26, meaningful(>15) 0→3. **Data was the bottleneck, confirmed.**
- [x] **T5 — First REAL banks on open stubs** — the v2 model drafted real open ov_SC01_077 stubs (LEAN, raw `.s` — model is format-robust, no bridge needed); whole-binary gate **banked 4** (func_80160B34, func_8015CC74, func_8016084C, func_801705C0; @commit:0320). Sample rate: 9/22 match_one proxy → **4/22 (18%) whole-binary** (the proxy→gate TU-plumbing gap).
- [x] **T6 — The mass-run driver** — `tools/lora_grind.py`: rotates every binary (config/check.*.sha), drafts the served model, banks via gate_stage (commit), defers/periodic-propagates, writes the **classified near-miss histogram** (the flywheel "missing idioms" signal). STOP/heartbeat/stats like grinder.py.
- [x] **T7 — Calibration run + the 0/222 puzzle — DEBUGGED + FIXED (2026-06-30).** Root cause = TWO independent harness bugs in `lora_grind`'s use of `gate_stage.run_gate` (R14, by reading the code + the run's backlog — which resolved a direct contradiction between two scout agents): **Bug A** — `good_sha()` passed the whole sha1sum line `"<sha> <name>"` vs harvest_verify's bare `sha1()` → **0 banks for EVERY binary incl. 077** (the "0/12" was a bug artifact, NOT an exhausted tail — the prior "`.sha` files carry the filename" note was the unfollowed thread); **Bug B** — the gate call left `src/asm/out` at the hardcoded ov_SC01_077 defaults → non-077 drafts dropped at the 077 stub-filter, **silently** (and the asm mis-resolution contaminated the backlog near-miss classes). Fix (`tools/gate_stage.py`): `run_gate` is binary-agnostic (resolve src/asm/out/good_sha from `binary`; good_sha bare-hash normalized) + a **loud negative-control guard**; `lora_grind.good_sha` fixed at source; byte-neutral (check-all 136/136). **Proof:** ov_SC01_000 spot-run banked **7/15 (47%) byte-identical** (was 0; @commit:0322). **ROI finding:** 6/7 banks are reach-1 (overlay-unique ×1) → broad rotation = high bank-RATE, low fleet-% ROI; the fleet lever is reach≥2 targeting (T9) + corpus-v3 (T8). Full write-up: `docs/gen2-mips-matching-model.md` → "T7 RESULT".
- [ ] **T8 — Corpus-v3 (struct types)** — emit the `struct {...}` definitions each fn needs (v2 did globals only; giants compile-fail on undefined structs). Build → **retest on the 7B free** (does the struct band lift on small/medium?) → only then a dense **14B cloud** train for the struct giants.
- [ ] **T9 — Wire the operating loop** — concurrent `lora_grind` + `grinder.py` for on-demand runs; the periodic retrain cycle; raise `--max-nins` as retrains lift the band.
- [ ] **T10 — Progress honesty + PhaseEnd** — track fleet % + bank-rate; PhaseEnd_Phase23 at a clean checkpoint (Tier-1 Max).
## ▶ RESUME HERE (fresh session)
**State:** Phase 22 in progress (NOT a phase end — no PhaseEnd file). 3 commits this session on top of Phase-21 close `commit:0295`: `commit:0296` (T0 worklist) · `commit:0297` (T1 func_8015126C ×134) · `commit:0298` (T3 cookbook §28 + recover_giant.py) + a reports-regen checkpoint commit. All 136 binaries byte-identical (`make check-all` 136/136); fleet **63.22%** function-count; dedup-check 1617/0. Working tree clean except the R23 `db.*.gbf` churn (do NOT stage). **Drew commits AND pushes the session work (R6/R8).** Grinder STOPPED (STOP sentinel set).
**State:** Phase 23 in progress (NOT a phase end). Phase 22 closed (`PhaseEnd_Phase22.md`, uncommitted — Drew's gate-2 commit+push). The fine-tuned model **`bfm-match-7b-v2`** (Qwen2.5-Coder-7B QLoRA on corpus-v2) is built; **served by LM Studio** at `http://192.168.1.113:1234/v1` (model id `bfm-match-7b-v2`; GGUF at `models/bfm-match-7b_gguf/`). Corpus `datasets/match_pairs/` + training stack `.venv-train` (gitignored). **T7 FIXED** — the gate banks fleet-wide now (ov_SC01_000 7/15 byte-identical, +1 reach-2 propagated; @commit:0322 + the T7 checkpoint commit). The 0/222 was two harness bugs (good_sha format + src/asm/out 077-default), not the model.
**NEXT TASK — T2: hand-decomp the next giants by byte-weight** (effort **Max**; the loop is A hand-crack → B distill → C fan-out). Use `docs/worklist.md` (the GIANT queue, refreshed) as the decision spine. Concrete queue:
1. **func_80132784** (400 ins, #2 byte-weight giant; backlog close=240: prologue+GTE pipelines match, residual = else-branch `$s0` pointer regalloc + GTE-section stack-ptr allocation → §17 pins). The biggest reachable hand target.
2. **The struct-walled close=0 trio** `func_80156B74` (214), `func_8014F74C` (174), `func_80163C2C` (167): match_one MATCH but blocked by a local `struct S8`/`B8` colliding with the TU (§28 case 3). Lever: lift `S8`/`B8` to `src/shared/engine_types.h` (or reuse the existing def / rename), then `tools/recover_giant.py` + gate. Could bank ~3 giants if the type-lift resolves it.
3. **func_80178004** (165): saved draft regressed (DIFF 91) — re-derive from cached Ghidra-C (it had register-pins-per-sibling-func_80177EA4 keys).
4. **decomp.wiki levers to try** (§28a): `func_801412A8` (198, offset-fold-vs-advance residual) → the **negative-struct-offset-in-loop** idiom (`for(...; p++)`); the **branch-duplication** lever for call-crossing regalloc swaps.
5. After each bank: `dedup_propagate` ×134 (BACKGROUND), `make check-all`, commit, distill any new idiom (T3), then optionally a fan-out wave (T4, prompt for Ultracode R27).
**NEXT TASK — T8: corpus-v3 (struct types).** T7 is closed; a bounded mass-run is now safe to size. The remaining draft losses split into: (a) standalone-compile-fails on **struct types** (→ corpus-v3, THIS task — emit the `struct {...}` defs each fn needs; v2 did globals only) and (b) **reach-1 ROI** (→ T9). Build corpus-v3 → **retest free on the 7B** (does the struct band lift on small/medium?) → only then a dense 14B cloud train if it pays. Then T9 (reach≥2 target selection — the fleet-% lever — a `lora_grind`/`wave_targets` `--min-reach 2` filter) + wire the concurrent permuter grinder on the close=1 near-misses T7 surfaced.
**Reusable this session:** `tools/recover_giant.py` (canonical-extern recovery for pure-extern close=0 giants); `tools/worklist.py --refresh` (the ranked decision table); calib drafts in `.run/drafts-t1-calib6/`. **Op gotchas (cookbook §28):** run `dedup_propagate` in BACKGROUND; `git checkout src/` does NOT revert `config/dedup.us.yaml` (reset both on a redo). **Pending tooling polish:** `gate_stage.py` commit message hardcodes "phase-21" → make phase-agnostic before the T4 worker waves.
**Run a bounded mass-run (when Drew says go):**
```
# LM Studio serving bfm-match-7b-v2 on the network first:
API_BASE=http://192.168.1.113:1234/v1 MODEL=bfm-local/bfm-match-7b-v2 GATE_PHASE=phase-23 \
.venv/bin/python -u tools/lora_grind.py --max-nins 15 --batch 15 --max-batches N
# concurrent permuter (closes the near-misses): rm .run/auto/STOP; bash tools/auto_supervisor.sh ... (grinder.py)
# stop anytime: touch .run/auto/STOP
```
## Verification invariant (every bank)
`make check-all` → 136/136 byte-identical from a CLEAN tree (R22); `dedup-check` validated, 0 failed; 0 NON_MATCHING (G4); byte-gate (harvest_verify) is the sole arbiter (G3/P9); each bank = checkpoint commit; the `db.*.gbf` churn is R23 restart-noise (do NOT stage).
The **whole-binary byte-gate** (`gate_stage`/`harvest_verify`, G3/P9) is the sole arbiter — a wrong/weak draft can NEVER bank (it reverts to the stub). `make check-all` 136/136 byte-identical from a clean tree (R22); `dedup-check` 0 failed; the `db.*.gbf` churn is R23 restart-noise (do NOT stage). The fine-tuned model only affects *throughput*, never correctness.
## Reuse (no rewrites)
orchestrator / wave_targets / worker_wave.js / distill.js / gate_stage / idiom_loop / grinder + supervisor / harvest_verify / match_one / dedup_propagate / build_fuel_manifest / backlog; cookbook §17–§27 + hand-matching-process.md + automation-runbook.md.
*New (this phase):* `api_draft.py` (provider-agnostic LEAN/full drafter + the unused `.s`→objdump NORMALIZE bridge) · `ab_match.js`/`ab_score.py` (the cost A/B) · `export_pairs.py` / `format_finetune.py` / `train_lora.py` / `eval_lora.py` (the LoRA pipeline) · `lora_grind.py` (the mass-run).
*Existing:* `gate_stage` (now `GATE_PHASE`-tagged) / `grinder.py` + `auto_supervisor.sh` / `dedup_propagate` / `backlog` / `harvest_verify` / `match_one`; cookbook §17–§28.
## Guardrails
- Don't grind confirmed-irreducible classes (store-vs-load sched, hoist-vs-remat, IV-combine, hoisted-invariant order, narrow-param loose-typing, cross-jump merge) — ROI-gate, bank closest, move on.
- Actor struct is byte-NEUTRAL for matching (comprehension only).
- R27 effort transitions: prompt Drew to toggle Max↔Ultracode at every A/B↔C boundary; never launch a Workflow on a verbal yes.
- **On-demand only** — never leave a 24/7 daemon running; bounded `--max-batches`, STOP-sentinel safe-exit.
- **Measure before investing** — retest every corpus/model change free on the 7B before any cloud spend.
- **Disk** — GGUF conversion writes ~30 GB intermediates onto the WSL vhdx (C:); `train_lora` now auto-cleans them; keep only the q4 GGUF. (A disk-full crash cost a session on 2026-06-29.)
- **Serve on GPU** (LM Studio) — Unsloth's llama.cpp is CPU-only; don't eval through it.
- Model size matches data size — no "massive" models on ~1–2k examples (overfit); dense > MoE for a limited-data LoRA.
## Blockers
(none)
- **(cleared) T7 — the 0/222 broad-rotation banking.** Root-caused to two harness bugs (good_sha sha1sum-format + the src/asm/out ov_SC01_077-default) and fixed + proven (ov_SC01_000 7/15 byte-identical, check-all 136/136). No blockers; a bounded mass-run is safe to size. Open levers (not blockers): corpus-v3 struct types (T8) + reach≥2 targeting (T9).
## Progress log
- 2026-06-26: Phase plan approved (gate 1). Task list built (R28). CURRENT_PHASE.md written. Starting T0.
- 2026-06-26: **T0 done** (commit `commit:0296`) — `tools/worklist.py` + `docs/worklist.md` + `.run/worklist.json`. 451 live stubs / 1.85M ins remaining gain; GIANT queue = 23 fns = 37.2% of remaining gain; top = func_80144B9C (770 ins, 5.58%).
- 2026-06-26: **T1 calibration on func_8015126C (254 ins, top-5 giant) — CRACKED, byte-identical in ov_SC01_077; ×134 propagation running (bg bl73feigi).** Key findings (→ T3 distill):
- **(idiom) §17 pin for the coalescing residual:** the `(s16)p[0x79]!=1000` compare wanted `$a0` (coalesced) not `$v1`. Lever: `register s32 cmp79 __asm__("$4")` + assign **inside** the `&&` (lazy, not hoisted) → MATCH. Reusable for the regalloc-coalescing giant group.
- **(THE close=0 wall, byte-proven) why match_one MATCH ≠ whole-binary bank:** the saved draft's *self-contained file-scope externs* conflict with engine_core.h's canonical sigs (e.g. my `extern void func_8015173C(void*)` vs canonical `void func_8015173C(s32*)`). `cast_call_sites`/`sig_unify` do NOT canonicalize these → the close=0 giants sit unbanked. **Fix (deterministic):** rewrite each engine_core.h-callee extern to its canonical def-sig AND move ALL externs **block-scope** (inside the body) so `find_site`/`compiles_standalone`/`dedup_propagate` accept them (file-scope externs are excluded from the lifted body → "not self-contained"). This is a missing gate-stage recovery step.
- **(gotcha) saved best_drafts get clobbered** by later worse attempts (func_8015126C's close=0 winner was overwritten by a close=2/case-broken copy). Trust the gate, re-derive from match_one.
- **(gotcha) propagation is slow** (134 overlay builds) — run dedup_propagate in the background, not a 2-min foreground (a SIGTERM leaves a partial non-atomic state: macro + instantiations applied, registry unwritten).
- **(T4 hypothesis)** the other close=0 giants (func_80156B74 214, func_8014F74C 174, func_80163C2C 167, func_80178004 165) likely unblock with the SAME canonical-extern + block-scope recovery → a deterministic near-free wave.
- 2026-06-26: **T1 CLOSED — func_8015126C banked ×134, fleet 63.18%→63.22%, `make check-all` 136/136 byte-identical, dedup-check 1617 validated/0 failed.** The full loop is proven end-to-end (hand-crack → bank → ×134 propagate → fleet-verify). Calib draft saved at `.run/drafts-t1-calib6/`. Reusable canonical-extern recovery: extract each engine_core.h callee's def-sig, rewrite the draft's extern to it, move ALL externs block-scope; then harvest_verify + dedup_propagate (run propagate in BACKGROUND — foreground gets killed; and `git checkout src/` does NOT revert `config/dedup.us.yaml`, so reset BOTH on a redo).
- 2026-06-26: Drew Q — decomp.wiki/compilers/GCC patterns: ~6 useful for us (PS1 gcc-2.7.2-psx). Top for giants: **negative-struct-offset-in-loops** (`for(...;ptr++)` → directly addresses func_801412A8's offset-fold residual), **branch-invariant code duplication** (alt to §17 pins for call-crossing regalloc swaps), **load-coalescing** (`if(t->a||t->b)`→`lw`). Also: div magic-constant table, s16/s8 div-by-2, gcc-2.7.2.x `slti …,0`. N/A to PS1: `bnel`-likely (MIPS II+), `.lit4` NOPs (PS2), C++ bool (C only). → fold the 3 top into cookbook in T3.
- 2026-06-26: **close=0-giant fan-out probed — R14 REFUTES "near-free" (only func_8015126C was pure-extern).** Of the 5 close=0 giants: func_8015126C #1 pure-extern (BANKED); func_80156B74/func_8014F74C/func_80163C2C #3 STRUCT-walled (local `struct S8`/`B8` collide w/ TU — need type-lift); func_8014F74C also #2 masked-residual (§27, permuter); func_80178004 #4 regressed draft (DIFF 91, re-derive). The canonical-extern lever is real but the group is NOT uniformly near-free. **T3 captured:** cookbook §28 (the 4-way close=0 triage + the canonical-extern recovery + the coalescing pin) + §28a (decomp.wiki PS1 patterns) + `tools/recover_giant.py` (promoted). Net giant strategy unchanged: genuine per-giant hand-work (T2), grinder for the masked/coalescing tail (T5).
- 2026-06-26: **Session paused at a clean checkpoint (Drew).** T0/T1/T3 committed; T5 grinder started then STOPPED for handoff (banked 0). Reports regenerated. Tree clean (only R23 db churn). Resume from the ▶ RESUME HERE block → T2 giants. Grinder is OFF (STOP sentinel) until a fresh session restarts it.
- 2026-06-26 (new session, effort **xHigh** — Drew testing xHigh vs Max on giants): tasklist rebuilt (R28); T2/T3/T4 reframed as a recurring cycle (Drew). **T2 giant #1 BANKED: func_80156B74 (214 ins) ×134** — the struct-walled close=0 trio's lever proven. Method (→ cookbook §28b): lifted the `S8`/`B8` typedefs from ov_SC01_077.c's prelude block to `src/shared/engine_types.h` (shared fleet-wide; byte-neutral verified on resident + 2 overlays), removed the dup typedefs, `recover_giant.py` (block-scope externs) → whole-binary `harvest_verify` MATCH → `dedup_propagate` ×134. **Fleet 63.22% → 63.25%** (function-count; +28,676 ins byte-weighted), `make check-all` **136/136**, dedup-check **1618**/0 failed, 0 NON_MATCHING. Gotcha hit + fixed: a concurrent `make` job (check-all racing dedup_propagate) corrupted an `.o` AND dropped the propagation's registry write — re-ran dedup_propagate (idempotent) to register; **lesson: serialize all make jobs** (cookbook §28b-6). NEXT: func_80163C2C (167, Blk16/Buf32 — same type-lift lever; recovered draft staged in `.run/drafts-t2/`).
- 2026-06-26 (xHigh): **T2 giant #2 BANKED: func_80163C2C (167 ins) ×134** — same type-lift lever. Lifted `Blk16`(u32×4) + `Buf32`(2×Blk16) to engine_types.h, removed the Blk16 dupes from ov_SC01_077.c AND ov_SC01_077_a.c (the -O0 split), byte-neutral verified → recover_giant → harvest_verify MATCH → dedup_propagate ×134. **Fleet 63.25% → 63.29%** (+22,378 ins byte-weighted), `make check-all` **136/136**, dedup-check **1619**/0 failed. Struct-walled close=0 trio DONE (func_80156B74 ✓, func_80163C2C ✓; func_8014F74C is masked-residual → grinder fuel, not type-liftable). **Tool quirk (recurring, benign):** dedup_propagate's first full run applies source + registers but its per-overlay byte-gate output didn't appear in-log; the authoritative gate is the post-bank `make check-all` (136/136). NEXT: restart grinder (T5) on permuter-class giants; hand-decomp func_80132784 (400, close=240, §17 pins GTE-section regalloc — the big one).
- 2026-06-26 (xHigh): **func_80132784 HARD-DEFER** (R14, byte-evidenced) — residual = hoist-vs-remat (irreducible §10) + register-LIFETIME-reuse (target reuses $s0/$s2 for GTE pointers after s0p/s2v die; function-scoped `register __asm__` pins can't express this). Too big (400) + far for the grinder. Logged to backlog. Grinder restarted (T5, permuting) then PAUSED for the batch below.
- 2026-06-26 (xHigh): **T2 close=0 RECOVERY BATCH — 14 functions ×134 (R14 corrects §26 "exhausted").** Surveyed the 43 still-live close=0 reach-134 fns; `recover_giant` + whole-binary gate banked **7** (func_80156ECC, func_80147E44, func_8015ADB0, func_801661CC, func_80166054, func_8012CFA8, func_8012A62C); `dedup_propagate --auto-from` propagated those + **7 pre-existing inline-matched bonus** (func_8012C098/F14C/F038/C0EC/E5CC/C750, func_80128ED8) ×134. The other ~33 are the genuine DEF-side/masked wall. **Fleet 63.29% → 63.66%**, `make check-all` **136/136 byte-identical**, dedup-check **1633**/0 failed. Hit the recurring dedup_propagate registry-skip (source propagated, registry partial) → recovered by direct `append_groups` registration (cookbook §28c; bytes were already correct per check-all). Distilled §28c (close=0 not exhausted + the registry-skip recovery).
- 2026-06-26 (xHigh): **from-scratch giant test — func_801372B0 (207) STRUCTURALLY CRACKED but scheduler-walled (Drew chose 'keep hand-decomp at xHigh').** Decompiled from raw Ghidra-C: a 3D-gizmo/compass HUD drawer (SVEC in/out + GsLINE prim, 4 axis projections via ApplyMatrixSV → GsSortLine + func_80137030/178). First draft was structurally PERFECT (206/207 ins, logic 100%); 4 pin iterations placed the regs but the residual is the **giant scheduler/regalloc last-mile** (10 held callee-saved regs; gcc's list-scheduler orders prologue-saves+materializations differently → pervasive positional diff, ~173). NOT C-steerable to byte-exact; too far for the grinder (173>30). Banked the structural draft to backlog (high-value head-start). **xHigh finding (Drew's test):** xHigh reached structural match FAST on giants — the wall is gcc determinism (§27/§17), not reasoning depth, so xHigh appears sufficient for this work (the bottleneck isn't depth). Grinder running on the permuter tail. SESSION DELIVERED: **16 functions banked ×134** (2 giants + 14 close=0), fleet 63.22%→63.66%, §28b/§28c, 2 hard giants diagnosed+logged.
- 2026-06-27: **Grinder STOPPED (clean, rc=0) + ROI audited (Drew asked for the total).** All-time grinder banks across 11 runs = **7 functions** — ALL during Phase 21 (~06-22, fleet 61-62% when tractable close≤30 fuel existed); **0 banks since** (late Phase 21 + all of Phase 22). Efficiency: 62 "permuter WON" events but only 7 banks (~11%) — the rest were gate-rejected (masked-residual §25) or pure CHURN (func_8014F3E8 won ~22×, func_8014FE60 ~18× across runs, never banked AND never blacklisted). **Two grinder BUGS found (fix before next use):** (1) split-file-blind — it looks for `.s` only in `asm/ov_SC01_077/nonmatchings/ov_SC01_077/`, NOT the `_a`/`_o0` split subdirs → this session it errored on 100% of targets (all `_a`-region); (2) churn-without-blacklist on permuter-won-but-gate-rejected-for-non-plumbing fns. Net: the grinder is a real-but-modest token-free contributor (7 all-time), now exhausted on the hard tail — keep for future fresh tractable fuel only after the 2 fixes. T5 is OFF (STOP sentinel set).
- 2026-06-29: **Phase opened at PhaseEnd_Phase22 close (Drew).** Built across this session: cheap-tier A/B (T1, Haiku 4.8×/$), stock-local floor (T2, 0), the LoRA pipeline (T3) + corpus-v2 extern-fix (T4, 6–15 ins 0%→85%), first 4 real open-stub banks (T5, @commit:0320), the `lora_grind` mass-run driver (T6). Calibration run (T7) launched (500 fns) — **18% on ov_SC01_077 but 0/222 broad rotation → #1 debug.** gate_stage commit tag made phase-agnostic. The whole arc + measured numbers: `docs/gen2-mips-matching-model.md`; memory `cheap-tier-ab-validated`. NEXT: T7 debug, then bounded mass-runs + corpus-v3.
- 2026-06-30: **T7 DEBUGGED + FIXED.** 3 Explore scouts (tooling / run-evidence / corpus) + a direct code read (R14 — which resolved a flat contradiction between two scouts) found **two independent bugs** in `lora_grind`'s gate path: **(A)** `good_sha()` passed `"<sha> <name>"` vs harvest_verify's bare `sha1()` → 0 banks for ALL binaries incl. 077 (so 077's "0/12" was a bug artifact); **(B)** `src/asm/out` defaulted to ov_SC01_077 → non-077 drafts dropped at the 077 stub-filter, silently. Fixed `gate_stage.run_gate` (binary-agnostic resolution + bare-hash normalize + a loud negative-control guard) + `lora_grind.good_sha`; byte-neutral (check-all 136/136). ov_SC01_000 spot-run **banked 7/15 (47%) byte-identical** (@commit:0322) → reach-2 `func_8017CE24` propagated ×2. **ROI:** 6/7 reach-1 → broad rotation is high bank-rate / low fleet-% ROI; the fleet lever is **reach≥2 targeting** + corpus-v3. Backlog now correctly classified (4× close=1 = grinder fuel). NEXT: **T8 corpus-v3** (struct types) + **T9 reach≥2 selection** + concurrent grinder.
+1 -5
View File
@@ -4781,11 +4781,7 @@ INCLUDE_ASM("asm/ov_SC01_000/nonmatchings/ov_SC01_000", func_8017CD9C);
INCLUDE_ASM("asm/ov_SC01_000/nonmatchings/ov_SC01_000", func_8017CDD8);
extern s32 func_800167F0(s32 arg0);
s32 func_8017CE24(void) {
return (func_800167F0(0) & 0xFFFF) != 0;
}
DEFINE_func_8017CE24() /* dedup: shared engine-core @0x8017CE24 (src/shared) */
INCLUDE_ASM("asm/ov_SC01_000/nonmatchings/ov_SC01_000", func_8017CE48);
+1 -1
View File
@@ -4755,7 +4755,7 @@ INCLUDE_ASM("asm/ov_SC01_001/nonmatchings/ov_SC01_001", func_8017CD9C);
INCLUDE_ASM("asm/ov_SC01_001/nonmatchings/ov_SC01_001", func_8017CDD8);
INCLUDE_ASM("asm/ov_SC01_001/nonmatchings/ov_SC01_001", func_8017CE24);
DEFINE_func_8017CE24() /* dedup: shared engine-core @0x8017CE24 (src/shared) */
INCLUDE_ASM("asm/ov_SC01_001/nonmatchings/ov_SC01_001", func_8017CE48);
+6
View File
@@ -23910,4 +23910,10 @@
} \
}
#define DEFINE_func_8017CE24() \
extern s32 func_800167F0(s32 arg0); \
s32 func_8017CE24(void) { \
return (func_800167F0(0) & 0xFFFF) != 0; \
}
#endif
+32 -6
View File
@@ -46,6 +46,12 @@ def _isdir(p):
return os.path.isdir(os.path.join(REPO, p))
def _check_sha(binary):
"""The bare locked SHA1 for a binary (config/check.<bin>.sha is sha1sum format '<sha> <name>')."""
p = os.path.join(REPO, f"config/check.{binary}.sha")
return open(p).read().split()[0] if os.path.exists(p) else None
def _xform(tool, ov, indir, suffix, extra=None):
"""Run a draft-dir transform; return its out dir, or the in dir if the tool no-ops/fails."""
out = indir + suffix
@@ -94,7 +100,7 @@ def match_one_closeness(fn, cpath, asm):
return ("near", int(m.group(1))) if m else ("fail", None)
def run_gate(drafts, binary=OV, src=DEF_SRC, asm=DEF_ASM, out=DEF_OUT, good_sha=DEF_SHA,
def run_gate(drafts, binary=OV, src=None, asm=None, out=None, good_sha=None,
propagate=True, source_tag="worker", commit=False, src_file=None):
# Serialize: the grinder and the orchestrator both call this, and it mutates the shared
# build tree + git. One gate at a time (blocking flock) — never two builds/commits racing.
@@ -111,10 +117,30 @@ def run_gate(drafts, binary=OV, src=DEF_SRC, asm=DEF_ASM, out=DEF_OUT, good_sha=
def _run_gate_locked(drafts, binary, src, asm, out, good_sha, propagate, source_tag, commit, src_file=None):
# Resolve per-binary paths when unset — binary-agnostic, no silent ov_SC01_077 default an
# overlay could inherit (the Phase-9 "required-no-default" discipline; the lora_grind mass-run's
# 0/222 Bug-B). good_sha is normalized to the BARE hash: config/check.<bin>.sha is sha1sum format
# "<sha> <name>", but harvest_verify compares it against a bare sha1() — passing the whole line
# never matches, so banking is 0 for EVERY binary incl. ov_SC01_077 (the 0/12 Bug-A).
src = src or f"src/{binary}/{binary}.c"
asm = asm or f"asm/{binary}/nonmatchings/{binary}"
out = out or f"build/{binary}/{binary}"
good_sha = (good_sha or _check_sha(binary) or DEF_SHA).split()[0]
draft_fns = sorted(os.path.basename(p)[:-2] for p in
glob.glob(os.path.join(REPO, drafts, "*.c")))
if not draft_fns:
return {"drafts": 0, "banked": 0, "propagated": 0, "near": 0, "failed": 0, "verified": []}
# Negative control (P9 / Phase-9): the drafts MUST be INCLUDE_ASM stubs SOMEWHERE in this
# binary's sources (main + any _a/_o0 split — a split-only batch is legitimately gated by the
# per-split run_gate call, so check the UNION, mirroring lora_grind.open_stubs' glob). If a
# non-empty draft set overlaps ZERO of them, it's a binary/src mismatch (the silent-077-default
# Bug-B) — warn loudly so a 0 can never again masquerade as "nothing matched".
bin_stubs = set()
for cf in glob.glob(os.path.join(REPO, f"src/{binary}/{binary}*.c")):
bin_stubs |= set(re.findall(r'INCLUDE_ASM\([^,]+,\s*(func_[0-9A-Fa-f]+|DsMix)\)', open(cf).read()))
if bin_stubs and not (set(draft_fns) & bin_stubs):
print(f"[gate] WARNING: 0/{len(draft_fns)} drafts are INCLUDE_ASM stubs in {binary} — "
f"binary/src mismatch (drafts for a different binary?); banking will be 0", file=sys.stderr)
# Recovery is CANON-FIRST, sig_unify FALLBACK (§19/§25): sig_unify can REGRESS an already-byte-
# correct draft (e.g. a hand-pinned crack — it rewrites the def-sig to a banked caller's wrong
@@ -150,14 +176,14 @@ def _run_gate_locked(drafts, binary, src, asm, out, good_sha, propagate, source_
# Surface a REAL failure: dedup_propagate exits non-zero on a byte-gate revert (a false-reach
# straggler poisoned the all-or-nothing batch) — distinct from the benign "nothing to propagate"
# empty-plan no-op. A swallowed revert previously hid a real ×134 gain (cont.4); never again.
out = (pr.stdout or "") + (pr.stderr or "")
if pr.returncode != 0 and "nothing to propagate" not in out:
pout = (pr.stdout or "") + (pr.stderr or "")
if pr.returncode != 0 and "nothing to propagate" not in pout:
errlog = os.path.join(REPO, ".run/auto/last_propagate_error.log")
try:
open(errlog, "w").write(out)
open(errlog, "w").write(pout)
except OSError:
pass
prop_error = [l for l in out.strip().splitlines() if l.strip()][-3:] or [f"exit {pr.returncode}"]
prop_error = [l for l in pout.strip().splitlines() if l.strip()][-3:] or [f"exit {pr.returncode}"]
print(f"[gate] WARNING: dedup_propagate exited {pr.returncode} ({propagated} groups added); "
f"see {errlog}", file=sys.stderr)
@@ -203,7 +229,7 @@ def _run_gate_locked(drafts, binary, src, asm, out, good_sha, propagate, source_
sh(["git", "add", src, "src/shared/engine_core.h", DEDUP_YAML] +
glob.glob(os.path.join(REPO, "src/ov_*/*.c")))
sh(["git", "commit", "-q", "-m",
f"feat(phase-21): {source_tag} gate — +{len(verified)} fns x{propagated} propagated (fleet {fp}%)"])
f"feat({os.environ.get('GATE_PHASE', 'decomp')}): {source_tag} gate — +{len(verified)} fns x{propagated} propagated (fleet {fp}%)"])
commit_sha = sh(["git", "rev-parse", "--short", "HEAD"]).stdout.strip()
return {"drafts": len(draft_fns), "banked": len(verified), "propagated": propagated,
+1 -1
View File
@@ -41,7 +41,7 @@ def binaries():
def good_sha(b):
p = os.path.join(REPO, "config/check.%s.sha" % b)
return open(p).read().strip() if os.path.exists(p) else None
return open(p).read().split()[0] if os.path.exists(p) else None # bare hash (sha1sum format)
def nins(s_path):