diff --git a/docs/cookbook-index.md b/docs/cookbook-index.md index 2b4eb32ed..3244c83e8 100644 --- a/docs/cookbook-index.md +++ b/docs/cookbook-index.md @@ -2,7 +2,7 @@ > **Generated by `tools/cookbook_index.py` — do not hand-edit** (R33). Regenerate after adding a cookbook section. > -> `docs/matching-cookbook.md` is ~716 KB / 919 sections. Grepping it blind is how three P30 wave-1 agents each "discovered" an idiom that was already written down. **Start here, then read the section.** A section appears under every symptom it addresses. +> `docs/matching-cookbook.md` is ~716 KB / 920 sections. Grepping it blind is how three P30 wave-1 agents each "discovered" an idiom that was already written down. **Start here, then read the section.** A section appears under every symptom it addresses. **How to use:** name what you SEE in the diff (a stolen delay slot, an extra `la`, a swapped register pair, a `conflicting types` error), find that symptom below, read those sections first. If nothing fits, THEN grind — and add a section when you win. @@ -38,56 +38,56 @@ - **§3-T4** — Branch polarity: invert the source condition to flip gcc's chosen branch L90 - **§5a** — Cross-jump tail-merge — gcc collapses two byte-identical blocks the original kept separate (FIX FOUND) L211 -- **§3-D.** — THE CROSS-JUMP RATCHET (the sharpest new trap — `func_80131340` L-C) L3508 -- **§3-C.** — Inner-block declaration does NOT delay slot allocation — BYTE-REFUTED L10068 -- **§162** — CROSS-JUMP DIRECTION: the surviving copy is always the LATER one, so a BACKWARD `j` into a sibling arm is a source `goto` (P30 S48) L11266 -- **§162** — The cross-jump "CALL veto" is a COUNT law, not a CALL law (BOUNDS §88a; P30 S48, `func_80189540`) L11302 -- **§177** — 🔴 THE EPILOGUE RETURN-DELAY SLOT IS DECIDED BY YOUR SAVED-REGISTER SET, NOT BY SCHEDULING L17182 -- **§176-A** — "SCHEDULE / DELAY-SLOT / LENGTH-DRIFT ±1" ⇒ check STATEMENT ORDER around the call first L17639 -- **§186** — CROSS-JUMPING RUNS **AFTER** SCHEDULING, SO NO C-LEVEL BARRIER CAN STEER IT L18092 -- **§194-H** — §164-29's WAR fence runs again at SCHED2 ON HARD REGISTERS: an in-place `v &= K` before a branch fences the store that reads v, and when TWO independent stores compete for the one delay slot the fence picks the winner at ZERO length drift (a WIDTH/sh!=sw swap, not a nop). Corrects §167-42's reconstruction (pseudo arm → hard-reg arm) and supplies its first re-runnable A/B. L19311 -- **§194-M** — A STORE in a CONDITIONAL branch's delay slot proves its C statement DOMINATES the branch — reorg can never pull a store out of either thread (gcc-2.7.2, -mips1) L19570 -- **§195-D** — §195 — `masked_diff.mask_for` returns 0 for EVERY `j`/`jal` word, so an internal `j` destination is invisible to match_one, the permuter scorer AND every similarity tier: a control-flow semantic error (which calls execute) surfaces as a 1-instruction residual mislabelled `DELAY-SLOT / profile=schedule`, or as an outright false MATCH L19884 -- **§195-E** — A 0/1 materialised at a JOIN immediately before the controlling `beqz`/`bnez` proves the source NAMED the condition — a truth expression in an `if`'s controlling position reaches `do_jump`, which has no value path L19952 -- **§195-F** — fold-const.c:4825 canonicalises a `?:` whose THEN arm is zero (or constant against a non-constant ELSE) by inverting the condition and swapping the arms — so a ternary's written arm order is byte-inert there, and `c ? 0 : X` is unspellable: it always compiles as `!c ? X : 0` L20010 -- **§195-G** — §NEW — TWO ARMS CALLING THE SAME CALLEE MERGE INTO ONE `jal` UNLESS EACH ARM'S OWN CODE CONSUMES THE RESULT: the C dial that keeps two call sites apart is WHERE the consumer test lives, and the branch SENSE you spell it with is byte-inert (jump.c:1737 canonicalises it) L20062 -- **§195-J** — GTE / PsyQ op CALL-vs-INLINE is a PER-SITE SOURCE FACT, not a TU style — both forms coexist in one TU (measured in 2 TUs), and the tell is the target's own opcodes (`lwc2`/`sqr`/`swc2` vs `jal`), not the sibling. Costs -8 ins on func_8018505C. Corollary: the game's inline `sqr` macro emits TWO hazard nops, the SDK's `Square0` body emits ONE — so the inline form is provably not `Square0` inlined (a second instance of §187's SDK-vs-game GTE nop divergence). L20222 -- **§195-N** — In a call-bearing chain of N≥2 `if (f(...)) return 1;` tests closed by `return 0;`, the LAST test must stay in STATEMENT form — the value form (`return f() != 0;` / `? 1 : 0` / `!!f()`) costs +1 `j` and empties the other N−1 delay slots. The cause is REORG block placement, not jump.c's `delete_jump`. L20419 -- **§197-B** — A REPEATED COMPARE OF ONE VALUE AGAINST ONE CONSTANT IS DELETED BY cse's `qty_comparison_code` CHANNEL (the non-EQ complement of §165-03) — and a front-end-opaque mask on EITHER compare is a pure-C dial that keeps the target's second branch L20619 -- **§199-F** — §164-36b — THE TARGET-HEAD FENCE IS A DELAY-SLOT THREAD SELECTOR, AND IT ONLY FIRES WHEN `mostly_true_jump > 0` (amendment to §164-36; its "−1 instruction" tell is falsified) L20979 -- **§199-G** — At TWO case nodes the switch-vs-if oracle is not blind — but the tell is ALL tests positive + a trailing `j default`, NOT the first test's polarity L21033 -- **§201-C** — §X — A CALL'S OWN DELAY SLOT AND THE UPSTREAM CONDITIONAL BRANCH'S SLOT COMPETE FOR ONE INSN (the call's argument copy), AND ONE STATEMENT'S POSITION RELATIVE TO THE CALL DECIDES BOTH — the residual is visible at the BRANCH, not at the call L21270 -- **§204-A** — A COMPARE THAT APPEARS BOTH IN A BRANCH'S DELAY SLOT AND AGAIN ON THE FALL-THROUGH IS A JOIN WITH TWO INCOMING EDGES: THE TWO GUARDS ARE SEQUENTIAL `if`s, NEVER `if/else if` L21566 -- **§211** — HOIST THE LOOP INIT ABOVE THE DOMINATING GUARD: it fills the guard's delay slot AND flips the counter/pointer register pair (P31 S58) L22374 -- **§221** — A CONSTANT SHARED BY TWO STORES DIES AT THE CALL WHOSE DELAY SLOT REFILLS ITS REGISTER **(single observation — not yet cross-confirmed)** (P31 S58) L22778 -- **§223** — READING A `jal` DELAY SLOT: the value in it was produced BEFORE the call, so it is NEVER that call's return (P31 S58) L22836 -- **§224** — CROSS-JUMP: WRITE THE DUPLICATE, AND READ A SHARED DELAY SLOT AS THE MERGE SIGNATURE (P31 S58) L22898 -- **§232** — WHEN THE `jr` DELAY SLOT'S STORE STORES THE RETURN VALUE, TIE THEM WITH ONE PSEUDO **(single observation — not yet cross-confirmed)** (P31 S58) L23180 -- **§243** — SPELL THE CSE BARRIER AS A REASSIGNED POINTER; AND THE `nop`-AFTER-EVERY-`lh` SIGNATURE (P31 S58b) L23680 -- **§247** — TWO BRANCHES TO **ONE** LABEL MEANS THE SOURCE CONDITION IS NEGATED (P31 S58b) L23832 -- **§224** — addendum (P31 S58b) — CROSS-JUMP MERGES *CALLS*, AND THE DELAY SLOT IS THE DISCRIMINATOR L24519 -- **§263** — A STOLEN DELAY SLOT WHOSE INSTRUCTION IS AN ARG-REGISTER COPY IS AN ARITY ERROR, NOT A SCHEDULE (P31 S59, byte-proven) L24886 -- **ADD-4** — → §225-3/-4 addendum — THE MIRROR ROW: VALUE-RETURN IN THE *TAKEN* ARM + TRAILING BARE `return 0` L25118 -- **ADD-5** — → §1/I1 addendum — THE INVERTED RANGE TEST: `(u32)(x-lo) >= N` WITH THE ZERO-ARM AS THE TRAILING `else` L25132 -- **ADD-5** — → §267-ADD-6 / §172b-1 addendum — THE SIGN-TEST FACE: `(s16)v < 0` IS `sll 16` + `bgez` ON THE SHIFTED COPY, RAW STAYS LIVE — AND THE HALFWORD-ABS SHAPE NEEDS NO RITUAL L25370 -- **ADDENDUM** — to §224 — CROSS-JUMP: THE DUPLICATE CAN BE A PLAIN STORE, NOT ONLY A CALL L25963 -- **ADDENDUM** — to §172a — RE-READING MEMORY (NOT NAMING A TEMP) IS WHAT KEEPS AN INCREMENT'S DELAY-SLOT FILL ALIVE L26263 -- **ADDENDUM** — to §225 / §256 — A GOTO TO A SHARED SET-POINT PREVENTS IF-CONVERSION FROM COLLAPSING A LATER BRANCH TEST L26294 -- **§277** — RETURN-TAIL C SPELLING PICKS THE DELAY-SLOT-FILL vs TRAILING-MOVE TOPOLOGY, AND A NARROWER SECOND VARIABLE KEEPS TWO PSEUDOS INSTEAD OF ONE (P31 S60; `func_801846F0` ov_SC03_104, `func_801A44C4` md_SC07_004, both byte-proven) L26520 -- **ADDENDUM** — to §22 (`volatile`-qualified-global reload lever, cookbook ~L1922) — for a NON-constant, same-address double RMW, a plain memory clobber beats `volatile`, and `volatile` actively breaks a delay-slot fill L27185 -- **ADDENDUM** — to §220 — REFERENCING THE RAW PARAMETER (NO NAMED COPY, NOT EVEN A PIN) LETS THE CALLEE-SAVED SPILL LAND IN THE FIRST CALL'S OWN DELAY SLOT L27439 -- **ADDENDUM** — to §252 — a `>=0`/`<0` split on an unconditionally-decremented value needs the POSTFIX operator INSIDE the branch condition, not a prior statement L27497 -- **ADDENDUM** — to §20's cross-jump EXPLOIT bullet (func_8017E360, ov_SC05_007 — wave dg) L27791 -- **ADDENDUM** — §NNN — sharpens §55a / §164-37 / §165-28 (switch-vs-tree cluster): A SHAPE THAT LOOKS LIKE A SWITCH DISPATCH CAN BE PLAIN NESTED `if`s WHOSE SHARED BODY WAS TRIPLICATED BY THE SOURCE AND THEN CROSS-JUMP-MERGED BACK DOWN L28182 -- **§285** — PRE-INITIALIZING A VARIABLE WITH A SHARED CONSTANT BEFORE A BRANCH MAKES BOTH ARMS OF THE FOLLOWING if/else DESTRUCTIVELY REUSE THE SAME DESTINATION REGISTER FOR THEIR BITWISE RESULT (byte-proven; `func_801811F0`, ov_SC03_102, independently rediscovered across waves di/dj) (P31 S60; waves #, byte-proven) L29037 -- **§286** — FOLD A STATEMENT'S SIDE EFFECT INTO A COMMA-EXPRESSION IN AN ARGUMENT POSITION TO PLACE ITS RTL RELATIVE TO A CALL'S OWN DELAY SLOT (P31 S60/dj; `func_80180A88`, ov_SC06_010, byte-proven 411/411) (P31 S60; waves #, byte-proven) L29041 -- **§291** — THE DELAY-SLOT FALSE-VALUE: A CONDITIONAL BRANCH'S ZERO ARM MUST BE A FALL-THROUGH-ADJACENT BLOCK ENDING IN AN EXPLICIT JUMP, OR REORG CANNOT MATERIALIZE IT INSIDE THE BRANCH'S OWN DELAY SLOT (P31 S60; waves #, byte-proven) L29061 -- **ADDENDUM** — to §253 — SECOND byte-proven card (upgrade from single-observation), and the placement face: postfix-in-condition parks the RMW store in the branch delay slot L29295 -- **§306** — A HAZARD `nop` IN FRONT OF A DIV-RESULT STORE IS A STATEMENT-ORDER DEFECT: THE INDEPENDENT TRAILING STATEMENT MUST BE WRITTEN *BEFORE* THE DIVISION-CONSUMING ONE (P31 S62 T4; byte-proven func_8017E7D0) L29833 -- **§308** — A NAIVE FINAL `goto` DELETES THE TARGET'S `j`+`nop`: SPELL THAT EDGE AS A TAUTOLOGICAL `if` SO cse FOLDS IT TO AN UNCONDITIONAL JUMP *AFTER* jump1's WINDOW HAS CLOSED (P31 S63 t5e-t5i; byte-proven func_80180808) L29942 -- **§308a** — A TWO-INSTRUCTION ARM STUB LAID *BEFORE* THE OTHER ARM AND REACHED ONLY BY A TRAILING `j` SURVIVES ONLY BEHIND A SHORT-CIRCUIT `&&` GUARD PLUS A SEPARATE RE-TEST; EVERY PLAIN if/else-if, GOTO-LADDER, NESTED-INVERTED-if AND 1-/2-NODE switch LETS jump1 INLINE IT (−2 ins) (P31 S63 t5e-t5i; byte-proven func_80180808) L29971 -- **§309** — A FRAME-ADDRESS EQUIVALENCE RIDES *THROUGH* A SKIPPABLE CONDITIONAL: POST-`if` STORES FOLD ONTO `$sp` UNLESS THE `if` SURVIVES jump1 AS A BARRIER-PRECEDED DIAMOND (P31 S63 t5e-t5i; byte-proven func_801812AC) L30005 -- **§311** — A JOIN-BLOCK STORE CAN SWALLOW AN ARM'S LOAD-DELAY `nop`: WHEN ONE ARM'S VALUE COMES FROM A LOAD, DUPLICATE THE STORE INTO BOTH ARMS (P31 S64 t5j-t5m; byte-proven func_8017D7E0) L30076 +- **§3-D.** — THE CROSS-JUMP RATCHET (the sharpest new trap — `func_80131340` L-C) L3523 +- **§3-C.** — Inner-block declaration does NOT delay slot allocation — BYTE-REFUTED L10083 +- **§162** — CROSS-JUMP DIRECTION: the surviving copy is always the LATER one, so a BACKWARD `j` into a sibling arm is a source `goto` (P30 S48) L11281 +- **§162** — The cross-jump "CALL veto" is a COUNT law, not a CALL law (BOUNDS §88a; P30 S48, `func_80189540`) L11317 +- **§177** — 🔴 THE EPILOGUE RETURN-DELAY SLOT IS DECIDED BY YOUR SAVED-REGISTER SET, NOT BY SCHEDULING L17197 +- **§176-A** — "SCHEDULE / DELAY-SLOT / LENGTH-DRIFT ±1" ⇒ check STATEMENT ORDER around the call first L17654 +- **§186** — CROSS-JUMPING RUNS **AFTER** SCHEDULING, SO NO C-LEVEL BARRIER CAN STEER IT L18107 +- **§194-H** — §164-29's WAR fence runs again at SCHED2 ON HARD REGISTERS: an in-place `v &= K` before a branch fences the store that reads v, and when TWO independent stores compete for the one delay slot the fence picks the winner at ZERO length drift (a WIDTH/sh!=sw swap, not a nop). Corrects §167-42's reconstruction (pseudo arm → hard-reg arm) and supplies its first re-runnable A/B. L19326 +- **§194-M** — A STORE in a CONDITIONAL branch's delay slot proves its C statement DOMINATES the branch — reorg can never pull a store out of either thread (gcc-2.7.2, -mips1) L19585 +- **§195-D** — §195 — `masked_diff.mask_for` returns 0 for EVERY `j`/`jal` word, so an internal `j` destination is invisible to match_one, the permuter scorer AND every similarity tier: a control-flow semantic error (which calls execute) surfaces as a 1-instruction residual mislabelled `DELAY-SLOT / profile=schedule`, or as an outright false MATCH L19899 +- **§195-E** — A 0/1 materialised at a JOIN immediately before the controlling `beqz`/`bnez` proves the source NAMED the condition — a truth expression in an `if`'s controlling position reaches `do_jump`, which has no value path L19967 +- **§195-F** — fold-const.c:4825 canonicalises a `?:` whose THEN arm is zero (or constant against a non-constant ELSE) by inverting the condition and swapping the arms — so a ternary's written arm order is byte-inert there, and `c ? 0 : X` is unspellable: it always compiles as `!c ? X : 0` L20025 +- **§195-G** — §NEW — TWO ARMS CALLING THE SAME CALLEE MERGE INTO ONE `jal` UNLESS EACH ARM'S OWN CODE CONSUMES THE RESULT: the C dial that keeps two call sites apart is WHERE the consumer test lives, and the branch SENSE you spell it with is byte-inert (jump.c:1737 canonicalises it) L20077 +- **§195-J** — GTE / PsyQ op CALL-vs-INLINE is a PER-SITE SOURCE FACT, not a TU style — both forms coexist in one TU (measured in 2 TUs), and the tell is the target's own opcodes (`lwc2`/`sqr`/`swc2` vs `jal`), not the sibling. Costs -8 ins on func_8018505C. Corollary: the game's inline `sqr` macro emits TWO hazard nops, the SDK's `Square0` body emits ONE — so the inline form is provably not `Square0` inlined (a second instance of §187's SDK-vs-game GTE nop divergence). L20237 +- **§195-N** — In a call-bearing chain of N≥2 `if (f(...)) return 1;` tests closed by `return 0;`, the LAST test must stay in STATEMENT form — the value form (`return f() != 0;` / `? 1 : 0` / `!!f()`) costs +1 `j` and empties the other N−1 delay slots. The cause is REORG block placement, not jump.c's `delete_jump`. L20434 +- **§197-B** — A REPEATED COMPARE OF ONE VALUE AGAINST ONE CONSTANT IS DELETED BY cse's `qty_comparison_code` CHANNEL (the non-EQ complement of §165-03) — and a front-end-opaque mask on EITHER compare is a pure-C dial that keeps the target's second branch L20634 +- **§199-F** — §164-36b — THE TARGET-HEAD FENCE IS A DELAY-SLOT THREAD SELECTOR, AND IT ONLY FIRES WHEN `mostly_true_jump > 0` (amendment to §164-36; its "−1 instruction" tell is falsified) L20994 +- **§199-G** — At TWO case nodes the switch-vs-if oracle is not blind — but the tell is ALL tests positive + a trailing `j default`, NOT the first test's polarity L21048 +- **§201-C** — §X — A CALL'S OWN DELAY SLOT AND THE UPSTREAM CONDITIONAL BRANCH'S SLOT COMPETE FOR ONE INSN (the call's argument copy), AND ONE STATEMENT'S POSITION RELATIVE TO THE CALL DECIDES BOTH — the residual is visible at the BRANCH, not at the call L21285 +- **§204-A** — A COMPARE THAT APPEARS BOTH IN A BRANCH'S DELAY SLOT AND AGAIN ON THE FALL-THROUGH IS A JOIN WITH TWO INCOMING EDGES: THE TWO GUARDS ARE SEQUENTIAL `if`s, NEVER `if/else if` L21581 +- **§211** — HOIST THE LOOP INIT ABOVE THE DOMINATING GUARD: it fills the guard's delay slot AND flips the counter/pointer register pair (P31 S58) L22389 +- **§221** — A CONSTANT SHARED BY TWO STORES DIES AT THE CALL WHOSE DELAY SLOT REFILLS ITS REGISTER **(single observation — not yet cross-confirmed)** (P31 S58) L22793 +- **§223** — READING A `jal` DELAY SLOT: the value in it was produced BEFORE the call, so it is NEVER that call's return (P31 S58) L22851 +- **§224** — CROSS-JUMP: WRITE THE DUPLICATE, AND READ A SHARED DELAY SLOT AS THE MERGE SIGNATURE (P31 S58) L22913 +- **§232** — WHEN THE `jr` DELAY SLOT'S STORE STORES THE RETURN VALUE, TIE THEM WITH ONE PSEUDO **(single observation — not yet cross-confirmed)** (P31 S58) L23195 +- **§243** — SPELL THE CSE BARRIER AS A REASSIGNED POINTER; AND THE `nop`-AFTER-EVERY-`lh` SIGNATURE (P31 S58b) L23695 +- **§247** — TWO BRANCHES TO **ONE** LABEL MEANS THE SOURCE CONDITION IS NEGATED (P31 S58b) L23847 +- **§224** — addendum (P31 S58b) — CROSS-JUMP MERGES *CALLS*, AND THE DELAY SLOT IS THE DISCRIMINATOR L24534 +- **§263** — A STOLEN DELAY SLOT WHOSE INSTRUCTION IS AN ARG-REGISTER COPY IS AN ARITY ERROR, NOT A SCHEDULE (P31 S59, byte-proven) L24901 +- **ADD-4** — → §225-3/-4 addendum — THE MIRROR ROW: VALUE-RETURN IN THE *TAKEN* ARM + TRAILING BARE `return 0` L25133 +- **ADD-5** — → §1/I1 addendum — THE INVERTED RANGE TEST: `(u32)(x-lo) >= N` WITH THE ZERO-ARM AS THE TRAILING `else` L25147 +- **ADD-5** — → §267-ADD-6 / §172b-1 addendum — THE SIGN-TEST FACE: `(s16)v < 0` IS `sll 16` + `bgez` ON THE SHIFTED COPY, RAW STAYS LIVE — AND THE HALFWORD-ABS SHAPE NEEDS NO RITUAL L25385 +- **ADDENDUM** — to §224 — CROSS-JUMP: THE DUPLICATE CAN BE A PLAIN STORE, NOT ONLY A CALL L25978 +- **ADDENDUM** — to §172a — RE-READING MEMORY (NOT NAMING A TEMP) IS WHAT KEEPS AN INCREMENT'S DELAY-SLOT FILL ALIVE L26278 +- **ADDENDUM** — to §225 / §256 — A GOTO TO A SHARED SET-POINT PREVENTS IF-CONVERSION FROM COLLAPSING A LATER BRANCH TEST L26309 +- **§277** — RETURN-TAIL C SPELLING PICKS THE DELAY-SLOT-FILL vs TRAILING-MOVE TOPOLOGY, AND A NARROWER SECOND VARIABLE KEEPS TWO PSEUDOS INSTEAD OF ONE (P31 S60; `func_801846F0` ov_SC03_104, `func_801A44C4` md_SC07_004, both byte-proven) L26535 +- **ADDENDUM** — to §22 (`volatile`-qualified-global reload lever, cookbook ~L1922) — for a NON-constant, same-address double RMW, a plain memory clobber beats `volatile`, and `volatile` actively breaks a delay-slot fill L27200 +- **ADDENDUM** — to §220 — REFERENCING THE RAW PARAMETER (NO NAMED COPY, NOT EVEN A PIN) LETS THE CALLEE-SAVED SPILL LAND IN THE FIRST CALL'S OWN DELAY SLOT L27454 +- **ADDENDUM** — to §252 — a `>=0`/`<0` split on an unconditionally-decremented value needs the POSTFIX operator INSIDE the branch condition, not a prior statement L27512 +- **ADDENDUM** — to §20's cross-jump EXPLOIT bullet (func_8017E360, ov_SC05_007 — wave dg) L27806 +- **ADDENDUM** — §NNN — sharpens §55a / §164-37 / §165-28 (switch-vs-tree cluster): A SHAPE THAT LOOKS LIKE A SWITCH DISPATCH CAN BE PLAIN NESTED `if`s WHOSE SHARED BODY WAS TRIPLICATED BY THE SOURCE AND THEN CROSS-JUMP-MERGED BACK DOWN L28197 +- **§285** — PRE-INITIALIZING A VARIABLE WITH A SHARED CONSTANT BEFORE A BRANCH MAKES BOTH ARMS OF THE FOLLOWING if/else DESTRUCTIVELY REUSE THE SAME DESTINATION REGISTER FOR THEIR BITWISE RESULT (byte-proven; `func_801811F0`, ov_SC03_102, independently rediscovered across waves di/dj) (P31 S60; waves #, byte-proven) L29052 +- **§286** — FOLD A STATEMENT'S SIDE EFFECT INTO A COMMA-EXPRESSION IN AN ARGUMENT POSITION TO PLACE ITS RTL RELATIVE TO A CALL'S OWN DELAY SLOT (P31 S60/dj; `func_80180A88`, ov_SC06_010, byte-proven 411/411) (P31 S60; waves #, byte-proven) L29056 +- **§291** — THE DELAY-SLOT FALSE-VALUE: A CONDITIONAL BRANCH'S ZERO ARM MUST BE A FALL-THROUGH-ADJACENT BLOCK ENDING IN AN EXPLICIT JUMP, OR REORG CANNOT MATERIALIZE IT INSIDE THE BRANCH'S OWN DELAY SLOT (P31 S60; waves #, byte-proven) L29076 +- **ADDENDUM** — to §253 — SECOND byte-proven card (upgrade from single-observation), and the placement face: postfix-in-condition parks the RMW store in the branch delay slot L29310 +- **§306** — A HAZARD `nop` IN FRONT OF A DIV-RESULT STORE IS A STATEMENT-ORDER DEFECT: THE INDEPENDENT TRAILING STATEMENT MUST BE WRITTEN *BEFORE* THE DIVISION-CONSUMING ONE (P31 S62 T4; byte-proven func_8017E7D0) L29848 +- **§308** — A NAIVE FINAL `goto` DELETES THE TARGET'S `j`+`nop`: SPELL THAT EDGE AS A TAUTOLOGICAL `if` SO cse FOLDS IT TO AN UNCONDITIONAL JUMP *AFTER* jump1's WINDOW HAS CLOSED (P31 S63 t5e-t5i; byte-proven func_80180808) L29957 +- **§308a** — A TWO-INSTRUCTION ARM STUB LAID *BEFORE* THE OTHER ARM AND REACHED ONLY BY A TRAILING `j` SURVIVES ONLY BEHIND A SHORT-CIRCUIT `&&` GUARD PLUS A SEPARATE RE-TEST; EVERY PLAIN if/else-if, GOTO-LADDER, NESTED-INVERTED-if AND 1-/2-NODE switch LETS jump1 INLINE IT (−2 ins) (P31 S63 t5e-t5i; byte-proven func_80180808) L29986 +- **§309** — A FRAME-ADDRESS EQUIVALENCE RIDES *THROUGH* A SKIPPABLE CONDITIONAL: POST-`if` STORES FOLD ONTO `$sp` UNLESS THE `if` SURVIVES jump1 AS A BARRIER-PRECEDED DIAMOND (P31 S63 t5e-t5i; byte-proven func_801812AC) L30020 +- **§311** — A JOIN-BLOCK STORE CAN SWALLOW AN ARM'S LOAD-DELAY `nop`: WHEN ONE ARM'S VALUE COMES FROM A LOAD, DUPLICATE THE STORE INTO BOTH ARMS (P31 S64 t5j-t5m; byte-proven func_8017D7E0) L30091 ### instruction scheduling (59) @@ -101,57 +101,57 @@ - **§32** — The region-a CAMERA-GIANT idiom set: struct-base hoisting + 4 sibling levers (Phase 24 T7, Fable5-cracked on `func_80129CF8` 191 ins, match_one MATCH; transferable to the 6 sibling giants) L2422 - **§34** — The `func_80138ED0` giant crack: gcc-2.7.2's **3-qty sort bug** + the **zero-byte asm allocation toolkit** + the **giv-init fence** (Phase 24 T5; Opus→close=21, Fable5→MATCH ×134) L2454 - **§35** — The region-a sibling-giant harvest: difficulty ≠ $s-reg count (it's global-array hoisting) + the banking recipe + new loop idioms (Phase 24 T7, 5 parallel Opus-Max agents) L2471 -- **§3-A4** — SINK THE CONSUMER CALL INTO THE ARMS (the inverse of A1; `func_8016AB6C`, byte-proven) L3444 -- **§49** — The LUID DIAL: a zero-byte SCHEDULING dial (the sched.c analogue of §47) — `func_8017A4AC` (536 ins ×134), Phase 26 session 8 L3527 -- **§66d-5** — `residual_class`'s "structural ⇒ permuter CPU is waste" is WRONG for schedule permutations (measured, Phase 29 SESSION-18) L5491 -- **§3-The** — attribution primitive (use this before calling anything a scheduling residual) L6057 -- **§3-The** — scheduling rules (refining §135-2 and §135-4) L8912 -- **Consequence** — for the family (a real scheduling decision) L10095 -- **§148** — The loop.c hoisting THRESHOLD is arithmetic you can compute, and the `?:` clamp that folds to MIN_EXPR (P30 S42, `func_8017C6F4`, 947 ins) L10145 -- **§3-A.** — `move_movables` hoists iff `threshold × savings × lifetime ≥ insn_count` — and you can read it L10151 -- **§16Z** — SHARPENS *(sharpens §37 "the /s-DEP LATTICE", §136-13, §136-14, §16Xy, §162q, `gcc-2.7.2-map/sched.md` §64)* L14353 -- **§175** — A CALLER-SAVED REGISTER PIN CAN BE A CORRECTNESS BUG, NOT JUST A SCHEDULING CHOICE (P31 wave H, 2026-08-15) L16735 -- **§177** — 🔴 THE EPILOGUE RETURN-DELAY SLOT IS DECIDED BY YOUR SAVED-REGISTER SET, NOT BY SCHEDULING L17182 -- **§3-B.** — A `return ` IS A PRIORITY-1 HARD-REG SET THE SCHEDULER PLACES FIRST (func_8001BE30, 92 ins) L17267 -- **§176-A** — "SCHEDULE / DELAY-SLOT / LENGTH-DRIFT ±1" ⇒ check STATEMENT ORDER around the call first L17639 -- **§176-C** — 🔴 WALL REFUTATION: a hard-register pin CANNOT schedule around a call, because of a genuine gcc-2.7.2 bug L17709 -- **§186** — CROSS-JUMPING RUNS **AFTER** SCHEDULING, SO NO C-LEVEL BARRIER CAN STEER IT L18092 -- **§193-C** — gcc-2.7.2 cross_jump merges the SCHEDULED common SUFFIX only — there is no prefix/head merge, so §8/§48-A1's "duplicate into both arms and cross_jump refunds it" is a TAIL-only lever L18547 -- **§193-D** — A COMPILER-GENERATED ARGUMENT COPY IS A `optimize_reg_copy_1` TRIGGER: when the pointer's LAST use in a block precedes a call that takes the pointer *as a register*, sched1 hoists the implicit `move $aN,$sN` to the block top and local-alloc re-bases the WHOLE block's memory operands onto `$aN`. The only C dial is a label (the §165-24 goto-join) between the block and the call. L18581 -- **§193-F** — §148-A2 — The `threshold -= 3` STAIRCASE: `move_movables` admits a COUNT of invariants, not a boolean — two identical merged constants split hoisted/not-hoisted by LIST ORDER, and `insn_count` picks the rank cutoff L18682 -- **§194-A** — A zero-byte scheduling fence goes AFTER the defining statement to make that computation emit FIRST in its block — and the barrier predicate is `volatile`-or-colon-less, not the `"memory"` clobber (COMPLEMENTS §165-40; does not refute it) L18950 -- **§194-D** — Declared width of a computed-value local is a sched1 dial (count-neutral) — a replication + attribution correction of §165-17, NOT a new argument-register law L19117 -- **§194-H** — §164-29's WAR fence runs again at SCHED2 ON HARD REGISTERS: an in-place `v &= K` before a branch fences the store that reads v, and when TWO independent stores compete for the one delay slot the fence picks the winner at ZERO length drift (a WIDTH/sh!=sw swap, not a nop). Corrects §167-42's reconstruction (pseudo arm → hard-reg arm) and supplies its first re-runnable A/B. L19311 -- **§194-K** — Blind sched1's alias oracle with a second SET of a pointer pseudo — the first zero-byte, non-volatile, dependence-CREATING lever (corrects §167-05's "volatile is the only door"; fourth consumer of reg_n_sets) L19444 -- **§194-N** — §193-D's C dial is misstated: the lever is a SURVIVING CODE_LABEL (a label with a real incoming edge), not "a label between the block and the call" — a bare label, or a `goto L; L:` pair whose target is the next active insn, is deleted by jump1 (jump.c:663-669 → delete_insn → jump.c:3458-3461, and jump.c:243 for the bare case) long before sched1/local-alloc, and costs exactly zero bytes L19628 -- **§195-D** — §195 — `masked_diff.mask_for` returns 0 for EVERY `j`/`jal` word, so an internal `j` destination is invisible to match_one, the permuter scorer AND every similarity tier: a control-flow semantic error (which calls execute) surfaces as a 1-instruction residual mislabelled `DELAY-SLOT / profile=schedule`, or as an outright false MATCH L19884 -- **§199-A** — §189-A's asm→source inference is byte-FALSE: an interloper between a split constant's `lui`/`ori` is a SCHEDULE fact, not a source fact — and the separator is the BIRTHING BOOST, not a "priority floor" (§189-A's split-timing half survives; its "no statement order / no pin" absolute and the candidate's own forward-scheduler narrative both fall) L20718 -- **§199-F** — §164-36b — THE TARGET-HEAD FENCE IS A DELAY-SLOT THREAD SELECTOR, AND IT ONLY FIRES WHEN `mostly_true_jump > 0` (amendment to §164-36; its "−1 instruction" tell is falsified) L20979 -- **§205** — THE CHAINED ASSIGNMENT IS ITS OWN SCHEDULING DIAL: `*b = *a = v;` moves an argument copy that no local, no pin and no statement reorder will move (P31 S56) L22057 -- **§211** — HOIST THE LOOP INIT ABOVE THE DOMINATING GUARD: it fills the guard's delay slot AND flips the counter/pointer register pair (P31 S58) L22374 -- **§219** — COMPOUND `+=`, FULL ASSIGNMENT, AND AN EXPLICIT TEMP ARE THREE DIFFERENT SCHEDULES OF ONE READ-MODIFY-WRITE (P31 S58) L22711 -- **§30** — addendum (P31 S58) — the `/s` grant closes a SCHEDULING residual and a REGISTER residual with one edit L23216 -- **§165-40** — addendum (P31 S58) — the barrier goes at the COPY SITE, not inside the region it protects L23248 -- **§239** — TWO-STATEMENT INTEGER-SPACE MATERIALISATION REORDERS `la` vs `sll`; AND THE PLUS-TREE OPERAND ORDER (P31 S58b) L23560 -- **§243** — SPELL THE CSE BARRIER AS A REASSIGNED POINTER; AND THE `nop`-AFTER-EVERY-`lh` SIGNATURE (P31 S58b) L23680 -- **§245** — THE CALL'S ARGUMENT LIST IS A SCHEDULING SLOT (P31 S58b) L23745 -- **§211** — addendum (P31 S58b) — INIT PLACEMENT: FIVE MORE DIALS BEYOND THE GUARD HOIST L24275 -- **§263** — A STOLEN DELAY SLOT WHOSE INSTRUCTION IS AN ARG-REGISTER COPY IS AN ARITY ERROR, NOT A SCHEDULE (P31 S59, byte-proven) L24886 -- **ADD-8** — → §245 addendum — THE RE-TIE BARRIER PINS CALL-ARG SETUP TO SOURCE ORDER (construct 6) L25162 -- **ADDENDUM** — to §244 — THE COMPILER BARRIER, NOT `volatile`, BLOCKS A STORE→LOAD HOIST THROUGH A POINTER-OFFSET FIELD L26028 -- **§281** — GROUP COPY-THEN-RMW BY OPERATION KIND, NOT FIELD BY FIELD: sched1 does the interleaving, the source must not (P31 S60; wave cf, func_80180FB4, ov_SC03_111, byte-proven) L26949 -- **§NNN** — A DEPENDENT COPY-THEN-RMW BLOCK MUST BE SOURCE-GROUPED BY OPERATION KIND, NOT BY FIELD, AND SCHED1 DOES THE INTERLEAVING (P31 S60; `func_80180FB4`, ov_SC03_111, byte-proven) L26950 -- **§282** — gcc's OWN LOOP REVERSAL PUTS THE COUNTER INIT AFTER THE HOISTED MOVABLES — a position no hand-written down-count can reach (P31 S60; wave cf, func_80180DD8, ov_SC04_005, byte-proven) L26995 -- **§NNN** — WRITE THE UP-COUNT LOOP: gcc's OWN REVERSAL PRODUCES A COUNTER-INIT INSTRUCTION THAT LANDS AFTER HOISTED MOVABLES, WHICH A HAND-WRITTEN DOWN-COUNT LOOP CANNOT REPRODUCE (P31 S60; `func_80180DD8`, ov_SC04_005, byte-proven) L26996 -- **ADDENDUM** — to §195-N — a GNU statement-expression slider must sit INSIDE the conditional arm's value position, not as a post-hoc barrier, to block the store-flag transform on a ternary chain L27266 -- **ADDENDUM** — §NNN — sharpens §167-13's boundary: CHAINING TWO IDENTICAL SIDE-BY-SIDE STORES INTO ONE C ASSIGNMENT STATEMENT IS A MID-BLOCK SCHEDULING-PRIORITY DIAL, NOT ONLY A STORE-ORDER SPELLING L28219 -- **§284** — COMBINE CAN REASSOCIATE TWO SEQUENTIAL BITWISE-AND MASKS INTO ONE AGAINST THE PRE-MASK VALUE; AN ASM IN/OUT FENCE RIGHT AFTER THE FIRST MASK BLOCKS IT (P31, wave dd, `func_8018087C`, ov_SC04_020, byte-proven) (P31 S60; waves #, byte-proven) L29033 -- **§298** — THE SHARED-TAIL POSITION DIAGNOSTIC: A FOLDED TAIL *BETWEEN* SWITCH ARMS MEANS PER-ARM DUPLICATED STATEMENTS, NOT A HOISTED POST-SWITCH STATEMENT (P31 S61; waves g0e/g0f, `func_80181B68`, ov_SC06_016, byte-proven 68/68) L29501 -- **§299** — TWO INDEPENDENT EXTRACTION CHAINS EMIT CONTIGUOUSLY INSIDE ONE EXPRESSION; ONLY A STATEMENT BOUNDARY MAKES THE SCHEDULER INTERLEAVE THEM (P31 S61; wave m0a, `func_8003A404`, main, byte-proven 8/8) L29526 -- **§307** — THE BRUTE-FORCE-THE-STATEMENT-ORDERS LEVER HAS A BOUND: A FAN-OUT COPY'S PRIORITY IS SCHEDULER-INTERNAL, AND NO SOURCE ORDER REACHES IT (P31 S63; byte-evidenced NEGATIVE result, main wave) L29898 -- **§309** — A FRAME-ADDRESS EQUIVALENCE RIDES *THROUGH* A SKIPPABLE CONDITIONAL: POST-`if` STORES FOLD ONTO `$sp` UNLESS THE `if` SURVIVES jump1 AS A BARRIER-PRECEDED DIAMOND (P31 S63 t5e-t5i; byte-proven func_801812AC) L30005 +- **§3-A4** — SINK THE CONSUMER CALL INTO THE ARMS (the inverse of A1; `func_8016AB6C`, byte-proven) L3459 +- **§49** — The LUID DIAL: a zero-byte SCHEDULING dial (the sched.c analogue of §47) — `func_8017A4AC` (536 ins ×134), Phase 26 session 8 L3542 +- **§66d-5** — `residual_class`'s "structural ⇒ permuter CPU is waste" is WRONG for schedule permutations (measured, Phase 29 SESSION-18) L5506 +- **§3-The** — attribution primitive (use this before calling anything a scheduling residual) L6072 +- **§3-The** — scheduling rules (refining §135-2 and §135-4) L8927 +- **Consequence** — for the family (a real scheduling decision) L10110 +- **§148** — The loop.c hoisting THRESHOLD is arithmetic you can compute, and the `?:` clamp that folds to MIN_EXPR (P30 S42, `func_8017C6F4`, 947 ins) L10160 +- **§3-A.** — `move_movables` hoists iff `threshold × savings × lifetime ≥ insn_count` — and you can read it L10166 +- **§16Z** — SHARPENS *(sharpens §37 "the /s-DEP LATTICE", §136-13, §136-14, §16Xy, §162q, `gcc-2.7.2-map/sched.md` §64)* L14368 +- **§175** — A CALLER-SAVED REGISTER PIN CAN BE A CORRECTNESS BUG, NOT JUST A SCHEDULING CHOICE (P31 wave H, 2026-08-15) L16750 +- **§177** — 🔴 THE EPILOGUE RETURN-DELAY SLOT IS DECIDED BY YOUR SAVED-REGISTER SET, NOT BY SCHEDULING L17197 +- **§3-B.** — A `return ` IS A PRIORITY-1 HARD-REG SET THE SCHEDULER PLACES FIRST (func_8001BE30, 92 ins) L17282 +- **§176-A** — "SCHEDULE / DELAY-SLOT / LENGTH-DRIFT ±1" ⇒ check STATEMENT ORDER around the call first L17654 +- **§176-C** — 🔴 WALL REFUTATION: a hard-register pin CANNOT schedule around a call, because of a genuine gcc-2.7.2 bug L17724 +- **§186** — CROSS-JUMPING RUNS **AFTER** SCHEDULING, SO NO C-LEVEL BARRIER CAN STEER IT L18107 +- **§193-C** — gcc-2.7.2 cross_jump merges the SCHEDULED common SUFFIX only — there is no prefix/head merge, so §8/§48-A1's "duplicate into both arms and cross_jump refunds it" is a TAIL-only lever L18562 +- **§193-D** — A COMPILER-GENERATED ARGUMENT COPY IS A `optimize_reg_copy_1` TRIGGER: when the pointer's LAST use in a block precedes a call that takes the pointer *as a register*, sched1 hoists the implicit `move $aN,$sN` to the block top and local-alloc re-bases the WHOLE block's memory operands onto `$aN`. The only C dial is a label (the §165-24 goto-join) between the block and the call. L18596 +- **§193-F** — §148-A2 — The `threshold -= 3` STAIRCASE: `move_movables` admits a COUNT of invariants, not a boolean — two identical merged constants split hoisted/not-hoisted by LIST ORDER, and `insn_count` picks the rank cutoff L18697 +- **§194-A** — A zero-byte scheduling fence goes AFTER the defining statement to make that computation emit FIRST in its block — and the barrier predicate is `volatile`-or-colon-less, not the `"memory"` clobber (COMPLEMENTS §165-40; does not refute it) L18965 +- **§194-D** — Declared width of a computed-value local is a sched1 dial (count-neutral) — a replication + attribution correction of §165-17, NOT a new argument-register law L19132 +- **§194-H** — §164-29's WAR fence runs again at SCHED2 ON HARD REGISTERS: an in-place `v &= K` before a branch fences the store that reads v, and when TWO independent stores compete for the one delay slot the fence picks the winner at ZERO length drift (a WIDTH/sh!=sw swap, not a nop). Corrects §167-42's reconstruction (pseudo arm → hard-reg arm) and supplies its first re-runnable A/B. L19326 +- **§194-K** — Blind sched1's alias oracle with a second SET of a pointer pseudo — the first zero-byte, non-volatile, dependence-CREATING lever (corrects §167-05's "volatile is the only door"; fourth consumer of reg_n_sets) L19459 +- **§194-N** — §193-D's C dial is misstated: the lever is a SURVIVING CODE_LABEL (a label with a real incoming edge), not "a label between the block and the call" — a bare label, or a `goto L; L:` pair whose target is the next active insn, is deleted by jump1 (jump.c:663-669 → delete_insn → jump.c:3458-3461, and jump.c:243 for the bare case) long before sched1/local-alloc, and costs exactly zero bytes L19643 +- **§195-D** — §195 — `masked_diff.mask_for` returns 0 for EVERY `j`/`jal` word, so an internal `j` destination is invisible to match_one, the permuter scorer AND every similarity tier: a control-flow semantic error (which calls execute) surfaces as a 1-instruction residual mislabelled `DELAY-SLOT / profile=schedule`, or as an outright false MATCH L19899 +- **§199-A** — §189-A's asm→source inference is byte-FALSE: an interloper between a split constant's `lui`/`ori` is a SCHEDULE fact, not a source fact — and the separator is the BIRTHING BOOST, not a "priority floor" (§189-A's split-timing half survives; its "no statement order / no pin" absolute and the candidate's own forward-scheduler narrative both fall) L20733 +- **§199-F** — §164-36b — THE TARGET-HEAD FENCE IS A DELAY-SLOT THREAD SELECTOR, AND IT ONLY FIRES WHEN `mostly_true_jump > 0` (amendment to §164-36; its "−1 instruction" tell is falsified) L20994 +- **§205** — THE CHAINED ASSIGNMENT IS ITS OWN SCHEDULING DIAL: `*b = *a = v;` moves an argument copy that no local, no pin and no statement reorder will move (P31 S56) L22072 +- **§211** — HOIST THE LOOP INIT ABOVE THE DOMINATING GUARD: it fills the guard's delay slot AND flips the counter/pointer register pair (P31 S58) L22389 +- **§219** — COMPOUND `+=`, FULL ASSIGNMENT, AND AN EXPLICIT TEMP ARE THREE DIFFERENT SCHEDULES OF ONE READ-MODIFY-WRITE (P31 S58) L22726 +- **§30** — addendum (P31 S58) — the `/s` grant closes a SCHEDULING residual and a REGISTER residual with one edit L23231 +- **§165-40** — addendum (P31 S58) — the barrier goes at the COPY SITE, not inside the region it protects L23263 +- **§239** — TWO-STATEMENT INTEGER-SPACE MATERIALISATION REORDERS `la` vs `sll`; AND THE PLUS-TREE OPERAND ORDER (P31 S58b) L23575 +- **§243** — SPELL THE CSE BARRIER AS A REASSIGNED POINTER; AND THE `nop`-AFTER-EVERY-`lh` SIGNATURE (P31 S58b) L23695 +- **§245** — THE CALL'S ARGUMENT LIST IS A SCHEDULING SLOT (P31 S58b) L23760 +- **§211** — addendum (P31 S58b) — INIT PLACEMENT: FIVE MORE DIALS BEYOND THE GUARD HOIST L24290 +- **§263** — A STOLEN DELAY SLOT WHOSE INSTRUCTION IS AN ARG-REGISTER COPY IS AN ARITY ERROR, NOT A SCHEDULE (P31 S59, byte-proven) L24901 +- **ADD-8** — → §245 addendum — THE RE-TIE BARRIER PINS CALL-ARG SETUP TO SOURCE ORDER (construct 6) L25177 +- **ADDENDUM** — to §244 — THE COMPILER BARRIER, NOT `volatile`, BLOCKS A STORE→LOAD HOIST THROUGH A POINTER-OFFSET FIELD L26043 +- **§281** — GROUP COPY-THEN-RMW BY OPERATION KIND, NOT FIELD BY FIELD: sched1 does the interleaving, the source must not (P31 S60; wave cf, func_80180FB4, ov_SC03_111, byte-proven) L26964 +- **§NNN** — A DEPENDENT COPY-THEN-RMW BLOCK MUST BE SOURCE-GROUPED BY OPERATION KIND, NOT BY FIELD, AND SCHED1 DOES THE INTERLEAVING (P31 S60; `func_80180FB4`, ov_SC03_111, byte-proven) L26965 +- **§282** — gcc's OWN LOOP REVERSAL PUTS THE COUNTER INIT AFTER THE HOISTED MOVABLES — a position no hand-written down-count can reach (P31 S60; wave cf, func_80180DD8, ov_SC04_005, byte-proven) L27010 +- **§NNN** — WRITE THE UP-COUNT LOOP: gcc's OWN REVERSAL PRODUCES A COUNTER-INIT INSTRUCTION THAT LANDS AFTER HOISTED MOVABLES, WHICH A HAND-WRITTEN DOWN-COUNT LOOP CANNOT REPRODUCE (P31 S60; `func_80180DD8`, ov_SC04_005, byte-proven) L27011 +- **ADDENDUM** — to §195-N — a GNU statement-expression slider must sit INSIDE the conditional arm's value position, not as a post-hoc barrier, to block the store-flag transform on a ternary chain L27281 +- **ADDENDUM** — §NNN — sharpens §167-13's boundary: CHAINING TWO IDENTICAL SIDE-BY-SIDE STORES INTO ONE C ASSIGNMENT STATEMENT IS A MID-BLOCK SCHEDULING-PRIORITY DIAL, NOT ONLY A STORE-ORDER SPELLING L28234 +- **§284** — COMBINE CAN REASSOCIATE TWO SEQUENTIAL BITWISE-AND MASKS INTO ONE AGAINST THE PRE-MASK VALUE; AN ASM IN/OUT FENCE RIGHT AFTER THE FIRST MASK BLOCKS IT (P31, wave dd, `func_8018087C`, ov_SC04_020, byte-proven) (P31 S60; waves #, byte-proven) L29048 +- **§298** — THE SHARED-TAIL POSITION DIAGNOSTIC: A FOLDED TAIL *BETWEEN* SWITCH ARMS MEANS PER-ARM DUPLICATED STATEMENTS, NOT A HOISTED POST-SWITCH STATEMENT (P31 S61; waves g0e/g0f, `func_80181B68`, ov_SC06_016, byte-proven 68/68) L29516 +- **§299** — TWO INDEPENDENT EXTRACTION CHAINS EMIT CONTIGUOUSLY INSIDE ONE EXPRESSION; ONLY A STATEMENT BOUNDARY MAKES THE SCHEDULER INTERLEAVE THEM (P31 S61; wave m0a, `func_8003A404`, main, byte-proven 8/8) L29541 +- **§307** — THE BRUTE-FORCE-THE-STATEMENT-ORDERS LEVER HAS A BOUND: A FAN-OUT COPY'S PRIORITY IS SCHEDULER-INTERNAL, AND NO SOURCE ORDER REACHES IT (P31 S63; byte-evidenced NEGATIVE result, main wave) L29913 +- **§309** — A FRAME-ADDRESS EQUIVALENCE RIDES *THROUGH* A SKIPPABLE CONDITIONAL: POST-`if` STORES FOLD ONTO `$sp` UNLESS THE `if` SURVIVES jump1 AS A BARRIER-PRECEDED DIAMOND (P31 S63 t5e-t5i; byte-proven func_801812AC) L30020 -### register allocation & pins (103) +### register allocation & pins (104) - **§10** — Closing the regalloc/scheduling hard tail by hand (LZSS, Phase 7 session F — the full close) L835 - **Residual** — A — commutative `|`/`&`/`+` result lands in the wrong source-operand register L856 @@ -161,168 +161,170 @@ - **§22** — DEF-side loose-typing recovery + grinder blacklist (Phase 21) L2005 - **§24** — The `ov_SC01_077_a.c` split-file vein: split-aware propagation, but loose-typing-gated (Phase 21) L2085 - **§25** — The "schedule" class is mostly COALESCING (pin-crackable), not scheduling; + the gate two-stage + h_exact over-counts ×134 (Phase 21, cont.6) L2132 -- **§42** — The F-band ≤28 regalloc crack wave: register-pin/DENSITY levers beat the permuter (Phase 25 T7 F-band, 2026-07-10; Ultracode 9-worker wave, 4/9 banked byte-identical, 266 swept ×134) L2900 -- **§43** — The K&R s16-param definition DISSOLVES the "narrow-param wall" for by-value register args (Phase 25 task A, Fable5 crack of the 369-ins giant `func_80166994` ×134, 2026-07-11) L3195 -- **§45** — The flagship `func_80133CD4` crack (399 ins ×134): the merged-variable permutation-breaker + the 1-death local-alloc gate (Phase 25 task A giant escalation, Fable5 gdb-on-cc1, 2026-07-11) L3298 -- **§47** — The live-length SLIDER: splitting a global.c allocno-priority TIE with one zero-byte asm (Phase 26 session 8, Fable5 Max, byte-proven on `func_8017BEBC` 952 ins ×113) L3365 -- **§48** — The 12-core jr crack wave: the ALLOCNO-PRICING dials and the EBB rule (Phase 26 session 8, Ultracode, 9/12 MATCH first pass) L3405 -- **§3-A.** — ALLOCNO-PRICING DIALS — move a value into the register you want, byte-neutrally L3413 -- **§52** — The WALKER-FAMILY skeleton: 6 regalloc-order levers + a deeply-characterized intrinsic wall (`func_80178004`, 165 ins ×134; Phase 26, Fable5, 2026-07-15) L3913 -- **§52a** — The regalloc sibling wave: new levers + two new wall classes (cheap-Opus applying §52, 2026-07-15) L3959 -- **§52b** — Sibling wave 2: more de-pin levers, a third wall class, and the match_one→whole-binary gap at scale (2026-07-15) L3997 -- **§66d-1** — What transfers between giants is the LOOP, not the PIN L5280 -- **§70** — The giv-init base register: walk the PARAMETER, not a copy of it (Phase 29 SESSION-18, `func_801777BC`) L5619 -- **§71** — Before mapping a giant, look for an already-matched SIBLING beside it (Phase 29 SESSION-18, `func_8017D960`, 3,338 ins) L5660 -- **§72** — A `register __asm__` pin is a PREFERENCE, not a reservation (Phase 29 SESSION-18, `func_8017F510`) L5726 -- **§74** — Auditing a pinned draft: the §72 hazard is CALLER-SAVED pins spanning a call, and only the disassembly can tell you (Phase 29 SESSION-19, `func_8017D960` b2, 5 pins) L5822 -- **§76** — The allocno CLASS (local vs global) is the dominant regalloc lever, and C reaches it ONLY through declaration scope and variable reuse (Phase 29 SESSION-19, behemoth #3 `func_8017F510` 1,511 ins, 97 → MATCH, pin-free) L6028 -- **§78** — A LENGTH drift can be a register grant in disguise; and `fold` never leaves a literal first in an `|` chain (Phase 29 SESSION-19, behemoth #2 `func_8017D960` 3,338 ins, 1806 → 0, pin-free) L6174 -- **§76** — confirmed at scale, and a pin nuance L6251 -- **§80** — A do-not-re-buy entry is scoped to its BASE, not to the function; and the pin's hidden cost is an unconditional `qty_phys_sugg` (Phase 29 SESSION-19, `func_8017BF14` 45 → 0) L6270 -- **§3-The** — pin's hidden cost, with the citation L6291 -- **§83** — The parameterised-repeat law, the spill-area trap, and why a per-case edit cannot move a per-case symptom (Phase 29 SESSION-20, `func_80183814` 5,122 ins, cold-ish start → 36 structural / 99.3%) L6412 -- **§83c** — TRAP: a "dead local" in a prior draft may be gcc's OWN spill area L6445 -- **§86** — Pinned-exemplar templatability is a PER-FAMILY property, not a per-member rate; and the §42e pin guard is now over-conservative (Phase 29 SESSION-20) L6589 -- **§3-Two** — further notes worth keeping L8248 -- **§137** — REGALLOC-PERM is a TWO-COMPILE ARITHMETIC PROBLEM, not a permuter job L9344 -- **§3-The** — same swallow, twice more, in the integration spine L9709 -- **§3-B.** — A `?:` on MEMORY operands costs ~16 bytes of invisible frame; on REGISTER operands, zero L10057 -- **§3-D.** — A lone `$t8`/`$t9` in the target is RELOAD SCRATCH — reproduce the spill, don't pin the register L10073 -- **§3-C.** — A zero-byte ALLOCNO-PRIORITY slider L10184 -- **§150** — A register ROTATION across symmetric blocks is VARIABLE-IDENTITY evidence, not an allocator tie (P30 S43, `func_8017C6F4`, 947 ins ×4) L10312 -- **§152** — BYTE SIZE is the family key that name- and h_seq-grouping both miss (P30 S43, the 0xECC family: 1 crack → 12 overlays → 11,364 ins) L10418 -- **§155** — hi/lo literal scanning MUST track base registers (S45) L10558 -- **§158** — The RANGE-EXTENDER: a fourth zero-emission asm lever completes the allocno toolkit (P30 S46 tier-3, `func_8017CE58`, 733 ins) L10712 -- **Bonus** — facts worth keeping L10757 -- **§156** — THE PREFERENCE-DONOR MERGE: cross-region variable reuse is what fills a0-a3, and a call-arg use in ONE region steers the fill in ALL of them (P30 S46 tier-3, `func_80186E24`, 611 ins: 236-off "S11 regalloc-order" → MATCH, zero new pins) L10772 -- **§175** — A CALLER-SAVED REGISTER PIN CAN BE A CORRECTNESS BUG, NOT JUST A SCHEDULING CHOICE (P31 wave H, 2026-08-15) L16735 -- **§176j** — STOPPING A WAVE MID-FLIGHT COSTS THE IN-FLIGHT TAIL (and how much is recoverable) L17119 -- **§177** — 🔴 THE EPILOGUE RETURN-DELAY SLOT IS DECIDED BY YOUR SAVED-REGISTER SET, NOT BY SCHEDULING L17182 -- **§179-A** — 🔴 A LOOP-WALKED POINTER **PARAMETER** HANDS ITS ARGUMENT REGISTER TO THE GIV (9 byte-proofs) L17336 -- **§179-F** — PINNING A LOOP-WALKED POINTER IS A TOTAL OFF-SWITCH FOR STRENGTH REDUCTION L17532 -- **§179-G** — 🟡 A PIN CAN **CREATE** A COMBINE `LOG_LINK` AND DELETE AN `andi` (sixth RC-5 channel, n=1) L17555 -- **§176** — SEVEN LEVERS FROM THE P31 OVERNIGHT WAVES (2026-08-15): statement order, false regalloc, and the pin that fights back L17633 -- **§176-B** — "REGALLOC-PERM, 1-4 instructions off" ⇒ it is usually NOT register allocation L17663 -- **§176-C** — 🔴 WALL REFUTATION: a hard-register pin CANNOT schedule around a call, because of a genuine gcc-2.7.2 bug L17709 -- **§3-18** — of 20 reconciled while keeping the match. The two that did not are mechanism, not effort. L17962 -- **§186** — CROSS-JUMPING RUNS **AFTER** SCHEDULING, SO NO C-LEVEL BARRIER CAN STEER IT L18092 -- **§186c** — WHERE A VALUE IS LOADED DECIDES WHICH ALLOCATOR OWNS IT, AND THEREFORE ITS REGISTER L18121 -- **§193-B** — A NARROW CAST OF A WIDE PARAMETER COSTS ONE EXTRA INSTRUCTION WHEN ITS STATEMENT SITS AFTER AN INTERVENING `jal` — AND THE DECIDER IS `combine.c:929`'s CROSS-CALL GUARD, NOT REGISTER ALLOCATION L18509 -- **§193-D** — A COMPILER-GENERATED ARGUMENT COPY IS A `optimize_reg_copy_1` TRIGGER: when the pointer's LAST use in a block precedes a call that takes the pointer *as a register*, sched1 hoists the implicit `move $aN,$sN` to the block top and local-alloc re-bases the WHOLE block's memory operands onto `$aN`. The only C dial is a label (the §165-24 goto-join) between the block and the call. L18581 -- **§194-B** — A `addu $rA,$rB,$zero` copy feeding ≥2 `sh` stores is a SECOND, 16-BIT-DECLARED local — the width, not the clamp or the join liveness, is what keeps the copy (and func_80183094's pin + `"memory"` clobber are both provably inert) L19016 -- **§194-C** — A CALLER-SAVED loop counter proves its live range crosses ZERO calls — so it cannot share a pseudo with any value LIVE ACROSS a call (but it may freely share one with values that merely sit between calls) L19054 -- **§194-D** — Declared width of a computed-value local is a sched1 dial (count-neutral) — a replication + attribution correction of §165-17, NOT a new argument-register law L19117 -- **§194-G** — Reading the integer half of a 16.16 stack aggregate: REGISTER-LIVENESS, not the C spelling, decides `sra` vs `lhu` — and the break is count-neutral L19268 -- **§194-H** — §164-29's WAR fence runs again at SCHED2 ON HARD REGISTERS: an in-place `v &= K` before a branch fences the store that reads v, and when TWO independent stores compete for the one delay slot the fence picks the winner at ZERO length drift (a WIDTH/sh!=sw swap, not a nop). Corrects §167-42's reconstruction (pseudo arm → hard-reg arm) and supplies its first re-runnable A/B. L19311 -- **§194-N** — §193-D's C dial is misstated: the lever is a SURVIVING CODE_LABEL (a label with a real incoming edge), not "a label between the block and the call" — a bare label, or a `goto L; L:` pair whose target is the next active insn, is deleted by jump1 (jump.c:663-669 → delete_insn → jump.c:3458-3461, and jump.c:243 for the bare case) long before sched1/local-alloc, and costs exactly zero bytes L19628 -- **§195-B** — A CALL_INSN does not start a basic block in gcc-2.7.2 — so a call-crossing temp can be a LOCAL-alloc quantity (the missing precondition under §48-A2 / §52 / regalloc.md K8) L19794 -- **§195-F** — fold-const.c:4825 canonicalises a `?:` whose THEN arm is zero (or constant against a non-constant ELSE) by inverting the condition and swapping the arms — so a ternary's written arm order is byte-inert there, and `c ? 0 : X` is unspellable: it always compiles as `!c ? X : 0` L20010 -- **§197-C** — Fix A1 (operand order) cannot move a commutative destination whose .greg conflict set already contains BOTH operand hard registers — split the accumulate so the destination IS the load's pseudo L20647 -- **§199-A** — §189-A's asm→source inference is byte-FALSE: an interloper between a split constant's `lui`/`ori` is a SCHEDULE fact, not a source fact — and the separator is the BIRTHING BOOST, not a "priority floor" (§189-A's split-timing half survives; its "no statement order / no pin" absolute and the candidate's own forward-scheduler narrative both fall) L20718 -- **§199-B** — A permutation sweep that holds ANY statement fixed is not a sweep: the statement an agent pins as "obviously load-bearing" is the one carrying the signal, and the partial sweep returns a FLAT residual that reads as proof of order-invariance L20767 -- **§199-E** — §189-A BOUNDED AND CORRECTED — the discriminator is INSN_PRIORITY, not "is the interloper a constant": an insn between a `lui`/`ori` pair proves NOTHING about the source spelling unless it TIES the `ori` on priority, and on the pinned `-mcpu=3000` triple a dependent load never does L20920 -- **§205** — THE CHAINED ASSIGNMENT IS ITS OWN SCHEDULING DIAL: `*b = *a = v;` moves an argument copy that no local, no pin and no statement reorder will move (P31 S56) L22057 -- **§208** — TWO NAMED LOCALS FOR ONE RELOADED EXPRESSION BUY TWO ALLOCNOS — the naming granularity owns the REGISTER SPLIT, not just the load count (P31 S58) L22202 -- **§211** — HOIST THE LOOP INIT ABOVE THE DOMINATING GUARD: it fills the guard's delay slot AND flips the counter/pointer register pair (P31 S58) L22374 -- **§215** — PIN ECONOMY: the twin's pins are NOT part of the shape, and §17's "pin every call-crossing value" is over-broad (P31 S58) L22560 -- **§220** — THE PARAMETER ITSELF IS A REGALLOC DIAL: use it directly, prefer `s32` to `void*`, and place the save-copy AFTER the first call (P31 S58) L22738 -- **§221** — A CONSTANT SHARED BY TWO STORES DIES AT THE CALL WHOSE DELAY SLOT REFILLS ITS REGISTER **(single observation — not yet cross-confirmed)** (P31 S58) L22778 -- **§30** — addendum (P31 S58) — the `/s` grant closes a SCHEDULING residual and a REGISTER residual with one edit L23216 -- **§244** — `volatile` IS A COUNTING INSTRUMENT, A STORE-ORDER PIN, AND MUST SOMETIMES BE ASYMMETRIC (P31 S58b) L23710 -- **§248** — SPLIT THE LOAD FROM THE ARITHMETIC: A FUSED `g + K` DENIES THE CALLEE-SAVED REGISTER ITS DIRECT HOME (P31 S58b) L23866 -- **§253** — POSTFIX `++` vs `+= 1` PICKS A DIFFERENT SCRATCH REGISTER **(single observation — not yet cross-confirmed)** (P31 S58b) L24012 -- **§254** — THE DEAD PARAMETER IS A REGISTER-PLACEMENT TOOL **(single observation — not yet cross-confirmed)** (P31 S58b) L24026 -- **§215** — addendum (P31 S58b) — PIN ECONOMY, PART 2: NINE REFINEMENTS L24383 -- **§223** — addendum (P31 S58b) — FIVE MORE CONFIRMATIONS, AND THE CONSTANT-IN-`$v0` CASE L24495 -- **§263** — A STOLEN DELAY SLOT WHOSE INSTRUCTION IS AN ARG-REGISTER COPY IS AN ARITY ERROR, NOT A SCHEDULE (P31 S59, byte-proven) L24886 -- **ADD-8** — → §245 addendum — THE RE-TIE BARRIER PINS CALL-ARG SETUP TO SOURCE ORDER (construct 6) L25162 -- **§268** — A `register __asm__` PIN ON A CALL-CLOBBERED REGISTER IS HONORED EXACTLY WHEN THE PINNED RANGE CROSSES NO CALL (P31 S59c; three A/B'd cards, unifying §257-2's two) L25244 -- **ADD-6** — → §220-addendum — THE FOURTH FACE: WHEN THE NAMED COPY ITSELF BUYS THE EXTRA CALLEE-SAVED, PIN THE COPY TO `$16` L25386 -- **ADD-7** — → §229 addendum — THE VALUE FACE: A LOOP-STORE CONSTANT SPELLED AS A LITERAL HAS NO SOURCE POSITION; NAME IT TO PIN THE PROLOGUE INIT ORDER L25402 -- **ADDENDUM** — to §82 — struct copies must stay MEMBER-WISE, not block-moved, to match a spill-slot save L25702 -- **ADDENDUM** — to §136d-1 (RC-12, the `$0`-add / opaque-copy family) — two symptoms beyond "compare reads the wrong register" L25740 -- **ADDENDUM** — to §164-64 — AN EMPTY CLOBBER ON AN ARGUMENT REGISTER CAN BE THE DELIBERATE FIX, NOT JUST THE ACCIDENTAL BUG L25997 -- **§275** — THE LEFTOVER-REGISTER READ L26371 -- **§NNN** — A DO-WHILE'S GUARD AND LATCH MUST REPEAT THE SAME BOUND EXPRESSION, NOT SHARE ONE LOCAL: THE REPETITION IS WHAT BUYS THE CSE'D COPY INTO A SECOND REGISTER (P31 S60; `func_8017F2A4`, ov_SC03_096, byte-proven 25/25) L26882 -- **ADDENDUM** — to §176-B2 — in a micro-function with no long/short lifetime asymmetry, BOTH contending pseudos need their own hard-register pin L27323 -- **ADDENDUM** — to §220 — REFERENCING THE RAW PARAMETER (NO NAMED COPY, NOT EVEN A PIN) LETS THE CALLEE-SAVED SPILL LAND IN THE FIRST CALL'S OWN DELAY SLOT L27439 -- **ADDENDUM** — to §215 — FIFTH SHAPE: reused mask constants across two call-free merge sites each get their own whole-function hard-register pin, and a shared sub-expression at the second site must be its own statement L27524 -- **ADDENDUM** — to §194-B (func_8017EB34, ov_SC03_117 — wave dk; distinct from the §74 co-pinning finding on the SAME function below) L27932 -- **ADDENDUM** — §NNN — sharpens §162a3/§60b: A `sll $v0,16 / sltiu $v0,1` ZERO-TEST OF A JUST-DECREMENTED HALFWORD IS A SIGNED-TEMP WIDTH TELL OUTSIDE ANY SWITCH/RANGE-TEST CONTEXT L28252 -- **§285** — PRE-INITIALIZING A VARIABLE WITH A SHARED CONSTANT BEFORE A BRANCH MAKES BOTH ARMS OF THE FOLLOWING if/else DESTRUCTIVELY REUSE THE SAME DESTINATION REGISTER FOR THEIR BITWISE RESULT (byte-proven; `func_801811F0`, ov_SC03_102, independently rediscovered across waves di/dj) (P31 S60; waves #, byte-proven) L29037 -- **§287** — A STACK-FRAME HOLE BELOW TWO ADDRESS-TAKEN AGGREGATE LOCALS IS A LEADING PAD MEMBER OF ONE COMBINED STRUCT, NOT SEPARATE LOCALS OR A REGISTER PIN (P31 S60/dj; `func_8017D104`, ov_SC06_027, byte-proven 47/47) (P31 S60; waves #, byte-proven) L29045 -- **§288** — A REGISTER PIN DECLARED UNINITIALIZED AND ASSIGNED ONLY AT ITS LATE, SOLE USE STILL FORCES THE FIXED REGISTER'S SAVE/RESTORE, AND THE ASSIGNMENT'S SOURCE POSITION CONTROLS WHERE THE VALUE MATERIALIZES (P31; `func_80186530`, ov_SC02_017, byte-proven, match_one MATCH re-verified) (P31 S60; waves #, byte-proven) L29049 -- **§290** — A SINGLE STRENGTH-REDUCED GIV CAN DRIVE STORES TO SEVERAL DISTINCT RELOCATABLE SYMBOLS, EACH KEEPING ITS OWN `%hi`/`%lo` ANCHOR (P31 S60; waves #, byte-proven) L29057 -- **ADDENDUM** — to §172b-1 (counter-type dial) — the sll's SOURCE REGISTER is the placement discriminator L29227 -- **ADDENDUM** — to §282 — the ADDRESS-GIV face: write the walked address INLINE so strength reduction births the induction register at loop.c's own insertion point L29272 -- **§310** — A TWO-OPERAND `subu`'s DESTINATION TIES ONLY TO THE OPERAND THAT IS BLOCK-LOCAL: SHARE *ONE* SIDE ACROSS BLOCKS TO CHOOSE WHICH OPERAND'S REGISTER IT LANDS IN (P31 S64 t5j-t5m; byte-proven func_8017F578) L30045 +- **§42** — The F-band ≤28 regalloc crack wave: register-pin/DENSITY levers beat the permuter (Phase 25 T7 F-band, 2026-07-10; Ultracode 9-worker wave, 4/9 banked byte-identical, 266 swept ×134) L2915 +- **§43** — The K&R s16-param definition DISSOLVES the "narrow-param wall" for by-value register args (Phase 25 task A, Fable5 crack of the 369-ins giant `func_80166994` ×134, 2026-07-11) L3210 +- **§45** — The flagship `func_80133CD4` crack (399 ins ×134): the merged-variable permutation-breaker + the 1-death local-alloc gate (Phase 25 task A giant escalation, Fable5 gdb-on-cc1, 2026-07-11) L3313 +- **§47** — The live-length SLIDER: splitting a global.c allocno-priority TIE with one zero-byte asm (Phase 26 session 8, Fable5 Max, byte-proven on `func_8017BEBC` 952 ins ×113) L3380 +- **§48** — The 12-core jr crack wave: the ALLOCNO-PRICING dials and the EBB rule (Phase 26 session 8, Ultracode, 9/12 MATCH first pass) L3420 +- **§3-A.** — ALLOCNO-PRICING DIALS — move a value into the register you want, byte-neutrally L3428 +- **§52** — The WALKER-FAMILY skeleton: 6 regalloc-order levers + a deeply-characterized intrinsic wall (`func_80178004`, 165 ins ×134; Phase 26, Fable5, 2026-07-15) L3928 +- **§52a** — The regalloc sibling wave: new levers + two new wall classes (cheap-Opus applying §52, 2026-07-15) L3974 +- **§52b** — Sibling wave 2: more de-pin levers, a third wall class, and the match_one→whole-binary gap at scale (2026-07-15) L4012 +- **§66d-1** — What transfers between giants is the LOOP, not the PIN L5295 +- **§70** — The giv-init base register: walk the PARAMETER, not a copy of it (Phase 29 SESSION-18, `func_801777BC`) L5634 +- **§71** — Before mapping a giant, look for an already-matched SIBLING beside it (Phase 29 SESSION-18, `func_8017D960`, 3,338 ins) L5675 +- **§72** — A `register __asm__` pin is a PREFERENCE, not a reservation (Phase 29 SESSION-18, `func_8017F510`) L5741 +- **§74** — Auditing a pinned draft: the §72 hazard is CALLER-SAVED pins spanning a call, and only the disassembly can tell you (Phase 29 SESSION-19, `func_8017D960` b2, 5 pins) L5837 +- **§76** — The allocno CLASS (local vs global) is the dominant regalloc lever, and C reaches it ONLY through declaration scope and variable reuse (Phase 29 SESSION-19, behemoth #3 `func_8017F510` 1,511 ins, 97 → MATCH, pin-free) L6043 +- **§78** — A LENGTH drift can be a register grant in disguise; and `fold` never leaves a literal first in an `|` chain (Phase 29 SESSION-19, behemoth #2 `func_8017D960` 3,338 ins, 1806 → 0, pin-free) L6189 +- **§76** — confirmed at scale, and a pin nuance L6266 +- **§80** — A do-not-re-buy entry is scoped to its BASE, not to the function; and the pin's hidden cost is an unconditional `qty_phys_sugg` (Phase 29 SESSION-19, `func_8017BF14` 45 → 0) L6285 +- **§3-The** — pin's hidden cost, with the citation L6306 +- **§83** — The parameterised-repeat law, the spill-area trap, and why a per-case edit cannot move a per-case symptom (Phase 29 SESSION-20, `func_80183814` 5,122 ins, cold-ish start → 36 structural / 99.3%) L6427 +- **§83c** — TRAP: a "dead local" in a prior draft may be gcc's OWN spill area L6460 +- **§86** — Pinned-exemplar templatability is a PER-FAMILY property, not a per-member rate; and the §42e pin guard is now over-conservative (Phase 29 SESSION-20) L6604 +- **§3-Two** — further notes worth keeping L8263 +- **§137** — REGALLOC-PERM is a TWO-COMPILE ARITHMETIC PROBLEM, not a permuter job L9359 +- **§3-The** — same swallow, twice more, in the integration spine L9724 +- **§3-B.** — A `?:` on MEMORY operands costs ~16 bytes of invisible frame; on REGISTER operands, zero L10072 +- **§3-D.** — A lone `$t8`/`$t9` in the target is RELOAD SCRATCH — reproduce the spill, don't pin the register L10088 +- **§3-C.** — A zero-byte ALLOCNO-PRIORITY slider L10199 +- **§150** — A register ROTATION across symmetric blocks is VARIABLE-IDENTITY evidence, not an allocator tie (P30 S43, `func_8017C6F4`, 947 ins ×4) L10327 +- **§152** — BYTE SIZE is the family key that name- and h_seq-grouping both miss (P30 S43, the 0xECC family: 1 crack → 12 overlays → 11,364 ins) L10433 +- **§155** — hi/lo literal scanning MUST track base registers (S45) L10573 +- **§158** — The RANGE-EXTENDER: a fourth zero-emission asm lever completes the allocno toolkit (P30 S46 tier-3, `func_8017CE58`, 733 ins) L10727 +- **Bonus** — facts worth keeping L10772 +- **§156** — THE PREFERENCE-DONOR MERGE: cross-region variable reuse is what fills a0-a3, and a call-arg use in ONE region steers the fill in ALL of them (P30 S46 tier-3, `func_80186E24`, 611 ins: 236-off "S11 regalloc-order" → MATCH, zero new pins) L10787 +- **§175** — A CALLER-SAVED REGISTER PIN CAN BE A CORRECTNESS BUG, NOT JUST A SCHEDULING CHOICE (P31 wave H, 2026-08-15) L16750 +- **§176j** — STOPPING A WAVE MID-FLIGHT COSTS THE IN-FLIGHT TAIL (and how much is recoverable) L17134 +- **§177** — 🔴 THE EPILOGUE RETURN-DELAY SLOT IS DECIDED BY YOUR SAVED-REGISTER SET, NOT BY SCHEDULING L17197 +- **§179-A** — 🔴 A LOOP-WALKED POINTER **PARAMETER** HANDS ITS ARGUMENT REGISTER TO THE GIV (9 byte-proofs) L17351 +- **§179-F** — PINNING A LOOP-WALKED POINTER IS A TOTAL OFF-SWITCH FOR STRENGTH REDUCTION L17547 +- **§179-G** — 🟡 A PIN CAN **CREATE** A COMBINE `LOG_LINK` AND DELETE AN `andi` (sixth RC-5 channel, n=1) L17570 +- **§176** — SEVEN LEVERS FROM THE P31 OVERNIGHT WAVES (2026-08-15): statement order, false regalloc, and the pin that fights back L17648 +- **§176-B** — "REGALLOC-PERM, 1-4 instructions off" ⇒ it is usually NOT register allocation L17678 +- **§176-C** — 🔴 WALL REFUTATION: a hard-register pin CANNOT schedule around a call, because of a genuine gcc-2.7.2 bug L17724 +- **§3-18** — of 20 reconciled while keeping the match. The two that did not are mechanism, not effort. L17977 +- **§186** — CROSS-JUMPING RUNS **AFTER** SCHEDULING, SO NO C-LEVEL BARRIER CAN STEER IT L18107 +- **§186c** — WHERE A VALUE IS LOADED DECIDES WHICH ALLOCATOR OWNS IT, AND THEREFORE ITS REGISTER L18136 +- **§193-B** — A NARROW CAST OF A WIDE PARAMETER COSTS ONE EXTRA INSTRUCTION WHEN ITS STATEMENT SITS AFTER AN INTERVENING `jal` — AND THE DECIDER IS `combine.c:929`'s CROSS-CALL GUARD, NOT REGISTER ALLOCATION L18524 +- **§193-D** — A COMPILER-GENERATED ARGUMENT COPY IS A `optimize_reg_copy_1` TRIGGER: when the pointer's LAST use in a block precedes a call that takes the pointer *as a register*, sched1 hoists the implicit `move $aN,$sN` to the block top and local-alloc re-bases the WHOLE block's memory operands onto `$aN`. The only C dial is a label (the §165-24 goto-join) between the block and the call. L18596 +- **§194-B** — A `addu $rA,$rB,$zero` copy feeding ≥2 `sh` stores is a SECOND, 16-BIT-DECLARED local — the width, not the clamp or the join liveness, is what keeps the copy (and func_80183094's pin + `"memory"` clobber are both provably inert) L19031 +- **§194-C** — A CALLER-SAVED loop counter proves its live range crosses ZERO calls — so it cannot share a pseudo with any value LIVE ACROSS a call (but it may freely share one with values that merely sit between calls) L19069 +- **§194-D** — Declared width of a computed-value local is a sched1 dial (count-neutral) — a replication + attribution correction of §165-17, NOT a new argument-register law L19132 +- **§194-G** — Reading the integer half of a 16.16 stack aggregate: REGISTER-LIVENESS, not the C spelling, decides `sra` vs `lhu` — and the break is count-neutral L19283 +- **§194-H** — §164-29's WAR fence runs again at SCHED2 ON HARD REGISTERS: an in-place `v &= K` before a branch fences the store that reads v, and when TWO independent stores compete for the one delay slot the fence picks the winner at ZERO length drift (a WIDTH/sh!=sw swap, not a nop). Corrects §167-42's reconstruction (pseudo arm → hard-reg arm) and supplies its first re-runnable A/B. L19326 +- **§194-N** — §193-D's C dial is misstated: the lever is a SURVIVING CODE_LABEL (a label with a real incoming edge), not "a label between the block and the call" — a bare label, or a `goto L; L:` pair whose target is the next active insn, is deleted by jump1 (jump.c:663-669 → delete_insn → jump.c:3458-3461, and jump.c:243 for the bare case) long before sched1/local-alloc, and costs exactly zero bytes L19643 +- **§195-B** — A CALL_INSN does not start a basic block in gcc-2.7.2 — so a call-crossing temp can be a LOCAL-alloc quantity (the missing precondition under §48-A2 / §52 / regalloc.md K8) L19809 +- **§195-F** — fold-const.c:4825 canonicalises a `?:` whose THEN arm is zero (or constant against a non-constant ELSE) by inverting the condition and swapping the arms — so a ternary's written arm order is byte-inert there, and `c ? 0 : X` is unspellable: it always compiles as `!c ? X : 0` L20025 +- **§197-C** — Fix A1 (operand order) cannot move a commutative destination whose .greg conflict set already contains BOTH operand hard registers — split the accumulate so the destination IS the load's pseudo L20662 +- **§199-A** — §189-A's asm→source inference is byte-FALSE: an interloper between a split constant's `lui`/`ori` is a SCHEDULE fact, not a source fact — and the separator is the BIRTHING BOOST, not a "priority floor" (§189-A's split-timing half survives; its "no statement order / no pin" absolute and the candidate's own forward-scheduler narrative both fall) L20733 +- **§199-B** — A permutation sweep that holds ANY statement fixed is not a sweep: the statement an agent pins as "obviously load-bearing" is the one carrying the signal, and the partial sweep returns a FLAT residual that reads as proof of order-invariance L20782 +- **§199-E** — §189-A BOUNDED AND CORRECTED — the discriminator is INSN_PRIORITY, not "is the interloper a constant": an insn between a `lui`/`ori` pair proves NOTHING about the source spelling unless it TIES the `ori` on priority, and on the pinned `-mcpu=3000` triple a dependent load never does L20935 +- **§205** — THE CHAINED ASSIGNMENT IS ITS OWN SCHEDULING DIAL: `*b = *a = v;` moves an argument copy that no local, no pin and no statement reorder will move (P31 S56) L22072 +- **§208** — TWO NAMED LOCALS FOR ONE RELOADED EXPRESSION BUY TWO ALLOCNOS — the naming granularity owns the REGISTER SPLIT, not just the load count (P31 S58) L22217 +- **§211** — HOIST THE LOOP INIT ABOVE THE DOMINATING GUARD: it fills the guard's delay slot AND flips the counter/pointer register pair (P31 S58) L22389 +- **§215** — PIN ECONOMY: the twin's pins are NOT part of the shape, and §17's "pin every call-crossing value" is over-broad (P31 S58) L22575 +- **§220** — THE PARAMETER ITSELF IS A REGALLOC DIAL: use it directly, prefer `s32` to `void*`, and place the save-copy AFTER the first call (P31 S58) L22753 +- **§221** — A CONSTANT SHARED BY TWO STORES DIES AT THE CALL WHOSE DELAY SLOT REFILLS ITS REGISTER **(single observation — not yet cross-confirmed)** (P31 S58) L22793 +- **§30** — addendum (P31 S58) — the `/s` grant closes a SCHEDULING residual and a REGISTER residual with one edit L23231 +- **§244** — `volatile` IS A COUNTING INSTRUMENT, A STORE-ORDER PIN, AND MUST SOMETIMES BE ASYMMETRIC (P31 S58b) L23725 +- **§248** — SPLIT THE LOAD FROM THE ARITHMETIC: A FUSED `g + K` DENIES THE CALLEE-SAVED REGISTER ITS DIRECT HOME (P31 S58b) L23881 +- **§253** — POSTFIX `++` vs `+= 1` PICKS A DIFFERENT SCRATCH REGISTER **(single observation — not yet cross-confirmed)** (P31 S58b) L24027 +- **§254** — THE DEAD PARAMETER IS A REGISTER-PLACEMENT TOOL **(single observation — not yet cross-confirmed)** (P31 S58b) L24041 +- **§215** — addendum (P31 S58b) — PIN ECONOMY, PART 2: NINE REFINEMENTS L24398 +- **§223** — addendum (P31 S58b) — FIVE MORE CONFIRMATIONS, AND THE CONSTANT-IN-`$v0` CASE L24510 +- **§263** — A STOLEN DELAY SLOT WHOSE INSTRUCTION IS AN ARG-REGISTER COPY IS AN ARITY ERROR, NOT A SCHEDULE (P31 S59, byte-proven) L24901 +- **ADD-8** — → §245 addendum — THE RE-TIE BARRIER PINS CALL-ARG SETUP TO SOURCE ORDER (construct 6) L25177 +- **§268** — A `register __asm__` PIN ON A CALL-CLOBBERED REGISTER IS HONORED EXACTLY WHEN THE PINNED RANGE CROSSES NO CALL (P31 S59c; three A/B'd cards, unifying §257-2's two) L25259 +- **ADD-6** — → §220-addendum — THE FOURTH FACE: WHEN THE NAMED COPY ITSELF BUYS THE EXTRA CALLEE-SAVED, PIN THE COPY TO `$16` L25401 +- **ADD-7** — → §229 addendum — THE VALUE FACE: A LOOP-STORE CONSTANT SPELLED AS A LITERAL HAS NO SOURCE POSITION; NAME IT TO PIN THE PROLOGUE INIT ORDER L25417 +- **ADDENDUM** — to §82 — struct copies must stay MEMBER-WISE, not block-moved, to match a spill-slot save L25717 +- **ADDENDUM** — to §136d-1 (RC-12, the `$0`-add / opaque-copy family) — two symptoms beyond "compare reads the wrong register" L25755 +- **ADDENDUM** — to §164-64 — AN EMPTY CLOBBER ON AN ARGUMENT REGISTER CAN BE THE DELIBERATE FIX, NOT JUST THE ACCIDENTAL BUG L26012 +- **§275** — THE LEFTOVER-REGISTER READ L26386 +- **§NNN** — A DO-WHILE'S GUARD AND LATCH MUST REPEAT THE SAME BOUND EXPRESSION, NOT SHARE ONE LOCAL: THE REPETITION IS WHAT BUYS THE CSE'D COPY INTO A SECOND REGISTER (P31 S60; `func_8017F2A4`, ov_SC03_096, byte-proven 25/25) L26897 +- **ADDENDUM** — to §176-B2 — in a micro-function with no long/short lifetime asymmetry, BOTH contending pseudos need their own hard-register pin L27338 +- **ADDENDUM** — to §220 — REFERENCING THE RAW PARAMETER (NO NAMED COPY, NOT EVEN A PIN) LETS THE CALLEE-SAVED SPILL LAND IN THE FIRST CALL'S OWN DELAY SLOT L27454 +- **ADDENDUM** — to §215 — FIFTH SHAPE: reused mask constants across two call-free merge sites each get their own whole-function hard-register pin, and a shared sub-expression at the second site must be its own statement L27539 +- **ADDENDUM** — to §194-B (func_8017EB34, ov_SC03_117 — wave dk; distinct from the §74 co-pinning finding on the SAME function below) L27947 +- **ADDENDUM** — §NNN — sharpens §162a3/§60b: A `sll $v0,16 / sltiu $v0,1` ZERO-TEST OF A JUST-DECREMENTED HALFWORD IS A SIGNED-TEMP WIDTH TELL OUTSIDE ANY SWITCH/RANGE-TEST CONTEXT L28267 +- **§285** — PRE-INITIALIZING A VARIABLE WITH A SHARED CONSTANT BEFORE A BRANCH MAKES BOTH ARMS OF THE FOLLOWING if/else DESTRUCTIVELY REUSE THE SAME DESTINATION REGISTER FOR THEIR BITWISE RESULT (byte-proven; `func_801811F0`, ov_SC03_102, independently rediscovered across waves di/dj) (P31 S60; waves #, byte-proven) L29052 +- **§287** — A STACK-FRAME HOLE BELOW TWO ADDRESS-TAKEN AGGREGATE LOCALS IS A LEADING PAD MEMBER OF ONE COMBINED STRUCT, NOT SEPARATE LOCALS OR A REGISTER PIN (P31 S60/dj; `func_8017D104`, ov_SC06_027, byte-proven 47/47) (P31 S60; waves #, byte-proven) L29060 +- **§288** — A REGISTER PIN DECLARED UNINITIALIZED AND ASSIGNED ONLY AT ITS LATE, SOLE USE STILL FORCES THE FIXED REGISTER'S SAVE/RESTORE, AND THE ASSIGNMENT'S SOURCE POSITION CONTROLS WHERE THE VALUE MATERIALIZES (P31; `func_80186530`, ov_SC02_017, byte-proven, match_one MATCH re-verified) (P31 S60; waves #, byte-proven) L29064 +- **§290** — A SINGLE STRENGTH-REDUCED GIV CAN DRIVE STORES TO SEVERAL DISTINCT RELOCATABLE SYMBOLS, EACH KEEPING ITS OWN `%hi`/`%lo` ANCHOR (P31 S60; waves #, byte-proven) L29072 +- **ADDENDUM** — to §172b-1 (counter-type dial) — the sll's SOURCE REGISTER is the placement discriminator L29242 +- **ADDENDUM** — to §282 — the ADDRESS-GIV face: write the walked address INLINE so strength reduction births the induction register at loop.c's own insertion point L29287 +- **§310** — A TWO-OPERAND `subu`'s DESTINATION TIES ONLY TO THE OPERAND THAT IS BLOCK-LOCAL: SHARE *ONE* SIDE ACROSS BLOCKS TO CHOOSE WHICH OPERAND'S REGISTER IT LANDS IN (P31 S64 t5j-t5m; byte-proven func_8017F578) L30060 +- **§312** — A BARE RELATIONAL IN AN `if` GIVES THE `slt` NO TARGET: ASSIGN THE COMPARISON INTO THE ALREADY-ALLOCATED VARIABLE TO CHOOSE ITS DESTINATION REGISTER, AT ZERO INSTRUCTION COST (P31 S64 t5o-t5r; byte-proven func_80180DCC) L30133 ### CSE / redundancy / rematerialization (28) -- **§46** — The `func_80178D40` crack (890 ins ×134, the heaviest core in the game): four LOOP-STRUCTURE levers cheap-Opus found by reading loop.c/jump.c/cse.c (Phase 26 session 8, 2026-07-13) L3313 -- **§83d** — CSE's quantity budget is WHOLE-FUNCTION, so a local rewrite cannot fix a local symptom L6452 -- **§153** — THE ADDRESS-REMATERIALISATION LAUNDER: a third zero-emission asm lever (P30 S43, `func_8018D98C`, 710 ins) L10466 -- **§176-D** — CSE-class levers used in reverse (two sharpenings of §153 and cse_expr §2) L17735 -- **§193-E** — A varying-address (pointer) load is re-emitted once per CSE-LIVE INTERVAL, and naming it in a C local is the only C-level lever over that count — no store SPELLING has any reach L18652 -- **§193-F** — §148-A2 — The `threshold -= 3` STAIRCASE: `move_movables` admits a COUNT of invariants, not a boolean — two identical merged constants split hoisted/not-hoisted by LIST ORDER, and `insn_count` picks the rank cutoff L18682 -- **§193-H** — A pointer-derived base load `*(s32*)(p+K)` is uncacheable across ANY memory write or call (cse's third kill disjunct) — so the target emits one `lw` per store-separated RUN of spellings, and a run of stores sharing one `lw` is a C local you must declare L18807 -- **§194-A** — A zero-byte scheduling fence goes AFTER the defining statement to make that computation emit FIRST in its block — and the barrier predicate is `volatile`-or-colon-less, not the `"memory"` clobber (COMPLEMENTS §165-40; does not refute it) L18950 -- **§194-J** — Back-to-back identical stores: flow.c's `last_mem_set` deletes the first, and only `volatile` saves it L19392 -- **§194-K** — Blind sched1's alias oracle with a second SET of a pointer pseudo — the first zero-byte, non-volatile, dependence-CREATING lever (corrects §167-05's "volatile is the only door"; fourth consumer of reg_n_sets) L19444 -- **§195-H** — §165-27g — ON A FIXED-SYMBOL GLOBAL, `extern T D[];` + `D[0]` IS THE CSE RELOAD DIAL, AT ZERO ADDRESSING COST, AND THE ELEMENT COUNT IS INERT (§165-27's `T v[2]` CAVEAT IS A LOCAL-FRAME FACT AND DOES NOT TRANSFER) L20110 -- **§195-I** — §145(b) AMENDED — the pointer-bump `addiu` is saved by cse, not combine: ANY second SET of a pseudo in the address's equivalence chain (in-place `p += K`, §145(b)'s `p = r;` copy, or an asm re-tie) kills the fold; the pass is cse and the gate is `invalidate`'s `reg_tick++` L20157 -- **§195-L** — The cse store-re-seed does not cross a JOIN LABEL: per-arm stores + a join read keep the reload that one join store deletes (bounds §193-E BOUND 1/BOUND 3 with §48-B's EBB boundary) L20318 -- **§197-A** — A NARROW SIGNED MEMORY READ FEEDING A CONSTANT `>>` LOSES ITS `lh`, AND THE CURE IS AN ASM RE-TIE (attribution CONTESTED: cse vs combine) L20581 -- **§197-B** — A REPEATED COMPARE OF ONE VALUE AGAINST ONE CONSTANT IS DELETED BY cse's `qty_comparison_code` CHANNEL (the non-EQ complement of §165-03) — and a front-end-opaque mask on EITHER compare is a pure-C dial that keeps the target's second branch L20619 -- **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` L20860 -- **§201-E** — §194-J-2 — The `last_mem_set` deletion window is measured in SOURCE/expand order, not in the printed stream; a foreign store moved between the pair in C source is a real lever, and `volatile` is not always the better one L21368 -- **§204-D** — A LOOP-INVARIANT LOAD IS ADMITTED AS A MOVABLE ONLY IF ITS ADDRESS CANNOT TRAP: `local.field` PASSES, THE SAME READ THROUGH A POINTER LOCAL IS REFUSED L21763 -- **§243** — SPELL THE CSE BARRIER AS A REASSIGNED POINTER; AND THE `nop`-AFTER-EVERY-`lh` SIGNATURE (P31 S58b) L23680 -- **§244** — `volatile` IS A COUNTING INSTRUMENT, A STORE-ORDER PIN, AND MUST SOMETIMES BE ASYMMETRIC (P31 S58b) L23710 -- **ADD-1** — → §257-8 addendum — THE INTERPOSED ASM'S `__volatile__` IS A PER-SHAPE DIAL, AND THE "NO-OUTPUT ASM IS IMPLICITLY VOLATILE" LORE IS BYTE-FALSE IN gcc-2.7.2 L25313 -- **ADDENDUM** — to §244 — THE COMPILER BARRIER, NOT `volatile`, BLOCKS A STORE→LOAD HOIST THROUGH A POINTER-OFFSET FIELD L26028 -- **ADDENDUM** — to §211 — AN IN-LOOP ACCUMULATOR WANTS A CLOSED-FORM EXPRESSION WHEN THE TARGET REMATERIALISES ITS CONSTANT AFTER EVERY CALL L26336 -- **§276** — MIXED ADDRESS-EXPRESSION SPELLING FOR ADJACENT RELOCATABLE SYMBOLS IS A CSE-UNIFICATION DIAL, NOT JUST A BYTE-ENCODING CHOICE (P31 S60; `func_80180FE8`, ov_SC06_006, byte-proven) L26411 -- **§NNN** — A DO-WHILE'S GUARD AND LATCH MUST REPEAT THE SAME BOUND EXPRESSION, NOT SHARE ONE LOCAL: THE REPETITION IS WHAT BUYS THE CSE'D COPY INTO A SECOND REGISTER (P31 S60; `func_8017F2A4`, ov_SC03_096, byte-proven 25/25) L26882 -- **ADDENDUM** — to §22 (`volatile`-qualified-global reload lever, cookbook ~L1922) — for a NON-constant, same-address double RMW, a plain memory clobber beats `volatile`, and `volatile` actively breaks a delay-slot fill L27185 -- **§302** — A RED BINARY IS A DRIFTED SPEC, NOT A MYSTERY: THE THREE CARVE-STATE INVARIANTS AND HOW TO DERIVE EACH FROM THE BYTES (P31 S62 T2; five reds healed in one session, 5/5, +39 held banks) L29678 -- **§308** — A NAIVE FINAL `goto` DELETES THE TARGET'S `j`+`nop`: SPELL THAT EDGE AS A TAUTOLOGICAL `if` SO cse FOLDS IT TO AN UNCONDITIONAL JUMP *AFTER* jump1's WINDOW HAS CLOSED (P31 S63 t5e-t5i; byte-proven func_80180808) L29942 +- **§46** — The `func_80178D40` crack (890 ins ×134, the heaviest core in the game): four LOOP-STRUCTURE levers cheap-Opus found by reading loop.c/jump.c/cse.c (Phase 26 session 8, 2026-07-13) L3328 +- **§83d** — CSE's quantity budget is WHOLE-FUNCTION, so a local rewrite cannot fix a local symptom L6467 +- **§153** — THE ADDRESS-REMATERIALISATION LAUNDER: a third zero-emission asm lever (P30 S43, `func_8018D98C`, 710 ins) L10481 +- **§176-D** — CSE-class levers used in reverse (two sharpenings of §153 and cse_expr §2) L17750 +- **§193-E** — A varying-address (pointer) load is re-emitted once per CSE-LIVE INTERVAL, and naming it in a C local is the only C-level lever over that count — no store SPELLING has any reach L18667 +- **§193-F** — §148-A2 — The `threshold -= 3` STAIRCASE: `move_movables` admits a COUNT of invariants, not a boolean — two identical merged constants split hoisted/not-hoisted by LIST ORDER, and `insn_count` picks the rank cutoff L18697 +- **§193-H** — A pointer-derived base load `*(s32*)(p+K)` is uncacheable across ANY memory write or call (cse's third kill disjunct) — so the target emits one `lw` per store-separated RUN of spellings, and a run of stores sharing one `lw` is a C local you must declare L18822 +- **§194-A** — A zero-byte scheduling fence goes AFTER the defining statement to make that computation emit FIRST in its block — and the barrier predicate is `volatile`-or-colon-less, not the `"memory"` clobber (COMPLEMENTS §165-40; does not refute it) L18965 +- **§194-J** — Back-to-back identical stores: flow.c's `last_mem_set` deletes the first, and only `volatile` saves it L19407 +- **§194-K** — Blind sched1's alias oracle with a second SET of a pointer pseudo — the first zero-byte, non-volatile, dependence-CREATING lever (corrects §167-05's "volatile is the only door"; fourth consumer of reg_n_sets) L19459 +- **§195-H** — §165-27g — ON A FIXED-SYMBOL GLOBAL, `extern T D[];` + `D[0]` IS THE CSE RELOAD DIAL, AT ZERO ADDRESSING COST, AND THE ELEMENT COUNT IS INERT (§165-27's `T v[2]` CAVEAT IS A LOCAL-FRAME FACT AND DOES NOT TRANSFER) L20125 +- **§195-I** — §145(b) AMENDED — the pointer-bump `addiu` is saved by cse, not combine: ANY second SET of a pseudo in the address's equivalence chain (in-place `p += K`, §145(b)'s `p = r;` copy, or an asm re-tie) kills the fold; the pass is cse and the gate is `invalidate`'s `reg_tick++` L20172 +- **§195-L** — The cse store-re-seed does not cross a JOIN LABEL: per-arm stores + a join read keep the reload that one join store deletes (bounds §193-E BOUND 1/BOUND 3 with §48-B's EBB boundary) L20333 +- **§197-A** — A NARROW SIGNED MEMORY READ FEEDING A CONSTANT `>>` LOSES ITS `lh`, AND THE CURE IS AN ASM RE-TIE (attribution CONTESTED: cse vs combine) L20596 +- **§197-B** — A REPEATED COMPARE OF ONE VALUE AGAINST ONE CONSTANT IS DELETED BY cse's `qty_comparison_code` CHANNEL (the non-EQ complement of §165-03) — and a front-end-opaque mask on EITHER compare is a pure-C dial that keeps the target's second branch L20634 +- **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` L20875 +- **§201-E** — §194-J-2 — The `last_mem_set` deletion window is measured in SOURCE/expand order, not in the printed stream; a foreign store moved between the pair in C source is a real lever, and `volatile` is not always the better one L21383 +- **§204-D** — A LOOP-INVARIANT LOAD IS ADMITTED AS A MOVABLE ONLY IF ITS ADDRESS CANNOT TRAP: `local.field` PASSES, THE SAME READ THROUGH A POINTER LOCAL IS REFUSED L21778 +- **§243** — SPELL THE CSE BARRIER AS A REASSIGNED POINTER; AND THE `nop`-AFTER-EVERY-`lh` SIGNATURE (P31 S58b) L23695 +- **§244** — `volatile` IS A COUNTING INSTRUMENT, A STORE-ORDER PIN, AND MUST SOMETIMES BE ASYMMETRIC (P31 S58b) L23725 +- **ADD-1** — → §257-8 addendum — THE INTERPOSED ASM'S `__volatile__` IS A PER-SHAPE DIAL, AND THE "NO-OUTPUT ASM IS IMPLICITLY VOLATILE" LORE IS BYTE-FALSE IN gcc-2.7.2 L25328 +- **ADDENDUM** — to §244 — THE COMPILER BARRIER, NOT `volatile`, BLOCKS A STORE→LOAD HOIST THROUGH A POINTER-OFFSET FIELD L26043 +- **ADDENDUM** — to §211 — AN IN-LOOP ACCUMULATOR WANTS A CLOSED-FORM EXPRESSION WHEN THE TARGET REMATERIALISES ITS CONSTANT AFTER EVERY CALL L26351 +- **§276** — MIXED ADDRESS-EXPRESSION SPELLING FOR ADJACENT RELOCATABLE SYMBOLS IS A CSE-UNIFICATION DIAL, NOT JUST A BYTE-ENCODING CHOICE (P31 S60; `func_80180FE8`, ov_SC06_006, byte-proven) L26426 +- **§NNN** — A DO-WHILE'S GUARD AND LATCH MUST REPEAT THE SAME BOUND EXPRESSION, NOT SHARE ONE LOCAL: THE REPETITION IS WHAT BUYS THE CSE'D COPY INTO A SECOND REGISTER (P31 S60; `func_8017F2A4`, ov_SC03_096, byte-proven 25/25) L26897 +- **ADDENDUM** — to §22 (`volatile`-qualified-global reload lever, cookbook ~L1922) — for a NON-constant, same-address double RMW, a plain memory clobber beats `volatile`, and `volatile` actively breaks a delay-slot fill L27200 +- **§302** — A RED BINARY IS A DRIFTED SPEC, NOT A MYSTERY: THE THREE CARVE-STATE INVARIANTS AND HOW TO DERIVE EACH FROM THE BYTES (P31 S62 T2; five reds healed in one session, 5/5, +39 held banks) L29693 +- **§308** — A NAIVE FINAL `goto` DELETES THE TARGET'S `j`+`nop`: SPELL THAT EDGE AS A TAUTOLOGICAL `if` SO cse FOLDS IT TO AN UNCONDITIONAL JUMP *AFTER* jump1's WINDOW HAS CLOSED (P31 S63 t5e-t5i; byte-proven func_80180808) L29957 -### loops & induction variables (31) +### loops & induction variables (32) - **§3-T1** — Loop pointer: top-of-body for `addu` induction, not constant-folded `addiu` L71 - **§34** — The `func_80138ED0` giant crack: gcc-2.7.2's **3-qty sort bug** + the **zero-byte asm allocation toolkit** + the **giv-init fence** (Phase 24 T5; Opus→close=21, Fable5→MATCH ×134) L2454 - **§35** — The region-a sibling-giant harvest: difficulty ≠ $s-reg count (it's global-array hoisting) + the banking recipe + new loop idioms (Phase 24 T7, 5 parallel Opus-Max agents) L2471 -- **§46** — The `func_80178D40` crack (890 ins ×134, the heaviest core in the game): four LOOP-STRUCTURE levers cheap-Opus found by reading loop.c/jump.c/cse.c (Phase 26 session 8, 2026-07-13) L3313 -- **§66d** — The permuter⇄reader loop: alternate a random search with a byte-verified idiom, and let `residual_class` decide whose turn it is (Phase 29 SESSION-17) L5245 -- **§66d-1** — What transfers between giants is the LOOP, not the PIN L5280 -- **§70** — The giv-init base register: walk the PARAMETER, not a copy of it (Phase 29 SESSION-18, `func_801777BC`) L5619 -- **§145** — Three loop/combine levers from the S40 wave-2 drafters (16/16 match_one) L9927 -- **§148** — The loop.c hoisting THRESHOLD is arithmetic you can compute, and the `?:` clamp that folds to MIN_EXPR (P30 S42, `func_8017C6F4`, 947 ins) L10145 -- **§171a** — THE MECHANICAL A-PROP DRAFT (P30 S50): 256 members banked with no agent in the loop L16433 -- **§179-A** — 🔴 A LOOP-WALKED POINTER **PARAMETER** HANDS ITS ARGUMENT REGISTER TO THE GIV (9 byte-proofs) L17336 -- **§179-E** — A `>2*MAX_MOVE_BYTES` BLOCK COPY IS A **STRUCT ASSIGNMENT**, NOT A HAND LOOP L17506 -- **§179-F** — PINNING A LOOP-WALKED POINTER IS A TOTAL OFF-SWITCH FOR STRENGTH REDUCTION L17532 -- **§194-C** — A CALLER-SAVED loop counter proves its live range crosses ZERO calls — so it cannot share a pseudo with any value LIVE ACROSS a call (but it may freely share one with values that merely sit between calls) L19054 -- **§204-B** — A LOOP COUNT THAT ARRIVES ON THE STACK IS DECREMENTED IN PLACE: a fresh counter local can cost a real `move` AND permute the whole callee-saved file L21641 -- **§204-D** — A LOOP-INVARIANT LOAD IS ADMITTED AS A MOVABLE ONLY IF ITS ADDRESS CANNOT TRAP: `local.field` PASSES, THE SAME READ THROUGH A POINTER LOCAL IS REFUSED L21763 -- **§211** — HOIST THE LOOP INIT ABOVE THE DOMINATING GUARD: it fills the guard's delay slot AND flips the counter/pointer register pair (P31 S58) L22374 -- **§246** — THREE-LIVE-VALUE SCAN LOOPS WANT ADDRESS-FROM-INDEX; AND TWO SYMBOLS CAN SHARE ONE giv (P31 S58b) L23792 -- **ADD-7** — → §229 addendum — THE VALUE FACE: A LOOP-STORE CONSTANT SPELLED AS A LITERAL HAS NO SOURCE POSITION; NAME IT TO PIN THE PROLOGUE INIT ORDER L25402 -- **ADD-8** — → §30a addendum — THE THIRD COLUMN: `*p++` IS ALSO SERIALIZED BUT BURNS `addiu`; ONLY CAST-PLUS GIVES SERIALIZATION *AND* DISPLACEMENT FOLDING L25415 -- **ADDENDUM** — to §172b-1 — TWO PLACEMENT DIALS THE PROMOTION LAW DOESN'T NAME: NARROW THE COUNTER'S DECLARED TYPE, AND MOVE THE CAST INTO THE LOOP BODY L26059 -- **ADDENDUM** — to §211 — AN IN-LOOP ACCUMULATOR WANTS A CLOSED-FORM EXPRESSION WHEN THE TARGET REMATERIALISES ITS CONSTANT AFTER EVERY CALL L26336 -- **§279** — A `do/while (p < end)` LOOP UNDER AN ENTRY GUARD: the guard decides the compare, not the loop (P31 S60; wave cf, func_8017F2A4, ov_SC03_096, byte-proven) L26881 -- **§NNN** — A DO-WHILE'S GUARD AND LATCH MUST REPEAT THE SAME BOUND EXPRESSION, NOT SHARE ONE LOCAL: THE REPETITION IS WHAT BUYS THE CSE'D COPY INTO A SECOND REGISTER (P31 S60; `func_8017F2A4`, ov_SC03_096, byte-proven 25/25) L26882 -- **§NNN** — A LOOP CURSOR'S C TYPE (POINTER vs PLAIN INTEGER) SELECTS `sltu` vs `slt` FOR ITS BOUND TEST, INDEPENDENT OF THE VALUES INVOLVED (P31 S60; `func_800CAE74`, md_MAIN_031, byte-proven; cross-confirmed same wave by `func_8017F2A4`, ov_SC03_096) L26916 -- **§282** — gcc's OWN LOOP REVERSAL PUTS THE COUNTER INIT AFTER THE HOISTED MOVABLES — a position no hand-written down-count can reach (P31 S60; wave cf, func_80180DD8, ov_SC04_005, byte-proven) L26995 -- **§NNN** — WRITE THE UP-COUNT LOOP: gcc's OWN REVERSAL PRODUCES A COUNTER-INIT INSTRUCTION THAT LANDS AFTER HOISTED MOVABLES, WHICH A HAND-WRITTEN DOWN-COUNT LOOP CANNOT REPRODUCE (P31 S60; `func_80180DD8`, ov_SC04_005, byte-proven) L26996 -- **§290** — A SINGLE STRENGTH-REDUCED GIV CAN DRIVE STORES TO SEVERAL DISTINCT RELOCATABLE SYMBOLS, EACH KEEPING ITS OWN `%hi`/`%lo` ANCHOR (P31 S60; waves #, byte-proven) L29057 -- **ADDENDUM** — to §282 — the ADDRESS-GIV face: write the walked address INLINE so strength reduction births the induction register at loop.c's own insertion point L29272 -- **ADDENDUM** — to the L1800 anchor-steer bullet — a DERIVED-POINTER local silently flips the merged giv's anchor END L29316 -- **§297** — ONE GIV SERVING MIXED-WIDTH LOADS *AND* A STORE NEEDS STRUCT-MEMBER SPELLING; CAST/INDEX SPELLINGS RE-SPLIT THE PSEUDO (P31 S61; wave m0a, `func_800347C8`, main, byte-proven 31/31) L29458 +- **§46** — The `func_80178D40` crack (890 ins ×134, the heaviest core in the game): four LOOP-STRUCTURE levers cheap-Opus found by reading loop.c/jump.c/cse.c (Phase 26 session 8, 2026-07-13) L3328 +- **§66d** — The permuter⇄reader loop: alternate a random search with a byte-verified idiom, and let `residual_class` decide whose turn it is (Phase 29 SESSION-17) L5260 +- **§66d-1** — What transfers between giants is the LOOP, not the PIN L5295 +- **§70** — The giv-init base register: walk the PARAMETER, not a copy of it (Phase 29 SESSION-18, `func_801777BC`) L5634 +- **§145** — Three loop/combine levers from the S40 wave-2 drafters (16/16 match_one) L9942 +- **§148** — The loop.c hoisting THRESHOLD is arithmetic you can compute, and the `?:` clamp that folds to MIN_EXPR (P30 S42, `func_8017C6F4`, 947 ins) L10160 +- **§171a** — THE MECHANICAL A-PROP DRAFT (P30 S50): 256 members banked with no agent in the loop L16448 +- **§179-A** — 🔴 A LOOP-WALKED POINTER **PARAMETER** HANDS ITS ARGUMENT REGISTER TO THE GIV (9 byte-proofs) L17351 +- **§179-E** — A `>2*MAX_MOVE_BYTES` BLOCK COPY IS A **STRUCT ASSIGNMENT**, NOT A HAND LOOP L17521 +- **§179-F** — PINNING A LOOP-WALKED POINTER IS A TOTAL OFF-SWITCH FOR STRENGTH REDUCTION L17547 +- **§194-C** — A CALLER-SAVED loop counter proves its live range crosses ZERO calls — so it cannot share a pseudo with any value LIVE ACROSS a call (but it may freely share one with values that merely sit between calls) L19069 +- **§204-B** — A LOOP COUNT THAT ARRIVES ON THE STACK IS DECREMENTED IN PLACE: a fresh counter local can cost a real `move` AND permute the whole callee-saved file L21656 +- **§204-D** — A LOOP-INVARIANT LOAD IS ADMITTED AS A MOVABLE ONLY IF ITS ADDRESS CANNOT TRAP: `local.field` PASSES, THE SAME READ THROUGH A POINTER LOCAL IS REFUSED L21778 +- **§211** — HOIST THE LOOP INIT ABOVE THE DOMINATING GUARD: it fills the guard's delay slot AND flips the counter/pointer register pair (P31 S58) L22389 +- **§246** — THREE-LIVE-VALUE SCAN LOOPS WANT ADDRESS-FROM-INDEX; AND TWO SYMBOLS CAN SHARE ONE giv (P31 S58b) L23807 +- **ADD-7** — → §229 addendum — THE VALUE FACE: A LOOP-STORE CONSTANT SPELLED AS A LITERAL HAS NO SOURCE POSITION; NAME IT TO PIN THE PROLOGUE INIT ORDER L25417 +- **ADD-8** — → §30a addendum — THE THIRD COLUMN: `*p++` IS ALSO SERIALIZED BUT BURNS `addiu`; ONLY CAST-PLUS GIVES SERIALIZATION *AND* DISPLACEMENT FOLDING L25430 +- **ADDENDUM** — to §172b-1 — TWO PLACEMENT DIALS THE PROMOTION LAW DOESN'T NAME: NARROW THE COUNTER'S DECLARED TYPE, AND MOVE THE CAST INTO THE LOOP BODY L26074 +- **ADDENDUM** — to §211 — AN IN-LOOP ACCUMULATOR WANTS A CLOSED-FORM EXPRESSION WHEN THE TARGET REMATERIALISES ITS CONSTANT AFTER EVERY CALL L26351 +- **§279** — A `do/while (p < end)` LOOP UNDER AN ENTRY GUARD: the guard decides the compare, not the loop (P31 S60; wave cf, func_8017F2A4, ov_SC03_096, byte-proven) L26896 +- **§NNN** — A DO-WHILE'S GUARD AND LATCH MUST REPEAT THE SAME BOUND EXPRESSION, NOT SHARE ONE LOCAL: THE REPETITION IS WHAT BUYS THE CSE'D COPY INTO A SECOND REGISTER (P31 S60; `func_8017F2A4`, ov_SC03_096, byte-proven 25/25) L26897 +- **§NNN** — A LOOP CURSOR'S C TYPE (POINTER vs PLAIN INTEGER) SELECTS `sltu` vs `slt` FOR ITS BOUND TEST, INDEPENDENT OF THE VALUES INVOLVED (P31 S60; `func_800CAE74`, md_MAIN_031, byte-proven; cross-confirmed same wave by `func_8017F2A4`, ov_SC03_096) L26931 +- **§282** — gcc's OWN LOOP REVERSAL PUTS THE COUNTER INIT AFTER THE HOISTED MOVABLES — a position no hand-written down-count can reach (P31 S60; wave cf, func_80180DD8, ov_SC04_005, byte-proven) L27010 +- **§NNN** — WRITE THE UP-COUNT LOOP: gcc's OWN REVERSAL PRODUCES A COUNTER-INIT INSTRUCTION THAT LANDS AFTER HOISTED MOVABLES, WHICH A HAND-WRITTEN DOWN-COUNT LOOP CANNOT REPRODUCE (P31 S60; `func_80180DD8`, ov_SC04_005, byte-proven) L27011 +- **§290** — A SINGLE STRENGTH-REDUCED GIV CAN DRIVE STORES TO SEVERAL DISTINCT RELOCATABLE SYMBOLS, EACH KEEPING ITS OWN `%hi`/`%lo` ANCHOR (P31 S60; waves #, byte-proven) L29072 +- **ADDENDUM** — to §282 — the ADDRESS-GIV face: write the walked address INLINE so strength reduction births the induction register at loop.c's own insertion point L29287 +- **ADDENDUM** — to the L1800 anchor-steer bullet — a DERIVED-POINTER local silently flips the merged giv's anchor END L29331 +- **§297** — ONE GIV SERVING MIXED-WIDTH LOADS *AND* A STORE NEEDS STRUCT-MEMBER SPELLING; CAST/INDEX SPELLINGS RE-SPLIT THE PSEUDO (P31 S61; wave m0a, `func_800347C8`, main, byte-proven 31/31) L29473 +- **§312** — A BARE RELATIONAL IN AN `if` GIVES THE `slt` NO TARGET: ASSIGN THE COMPARISON INTO THE ALREADY-ALLOCATED VARIABLE TO CHOOSE ITS DESTINATION REGISTER, AT ZERO INSTRUCTION COST (P31 S64 t5o-t5r; byte-proven func_80180DCC) L30133 -### structs, block moves & memcpy (70) +### structs, block moves & memcpy (71) - **§3-T2** — Source statement order drives instruction scheduling L78 - **§5** — Known hard-residual classes (instruction-identical, one byte-exact blocker) L199 @@ -337,63 +339,64 @@ - **§38** — The WHALE `func_80144B9C` (770 ins): the -O0 struct-assign memcpy idiom + the -O0 reach-134 ×134 rollout (Phase 24 T7 §G, cheap Opus — no Fable5, no calls.c) L2527 - **§40** — Structural families: the MECHANICAL symbol-remap (crack one exemplar → remap the rest, ~0 tokens) (Phase 25 T3/T7, 2026-07-08) L2553 - **§41** — The DEF-SIDE canonical-sig wall: mechanically banking a drafted giant past `conflicting types` (Phase 25 T5b batch-2, 2026-07-09; `tools/canon_sig_reconcile.py`, byte-proven on `func_8013B274`) L2710 -- **§42a** — addendum — wave 2 (residuals + 29-100 band): iso-MATCH ≠ real-TU bank, the memcpy→struct-assign fix, +5 levers (2026-07-10b) L2953 -- **§44** — The Phase-25 cheap-Opus giant batch: 5 structural levers + the §43 extension (2026-07-11, 6 crackers over the frontier giants) L3242 -- **§46** — The `func_80178D40` crack (890 ins ×134, the heaviest core in the game): four LOOP-STRUCTURE levers cheap-Opus found by reading loop.c/jump.c/cse.c (Phase 26 session 8, 2026-07-13) L3313 -- **§3-Why** — 0/8 was structural, and predictable from two words L4045 -- **§54** — `--fix-def-sig`: the member's CANONICAL DECLARATION is a build step too (tiny-IMM mega-pools, +4,801, Phase 29 T6, 2026-07-16) L4163 -- **§56b** — PROPAGATING an h_seq giant: the exemplar's externs MUST be fleet-canonical, not the draft's types L4232 -- **§65a** — The blast-radius taxonomy (makes §61's law structural instead of remembered) L5030 -- **§66d-5** — `residual_class`'s "structural ⇒ permuter CPU is waste" is WRONG for schedule permutations (measured, Phase 29 SESSION-18) L5491 -- **§83** — The parameterised-repeat law, the spill-area trap, and why a per-case edit cannot move a per-case symptom (Phase 29 SESSION-20, `func_80183814` 5,122 ins, cold-ish start → 36 structural / 99.3%) L6412 -- **§84** — The DERIVED-OFFSET remap bug: a hand-computed literal that encodes the DISTANCE between two per-overlay symbols, and why `match_one` is structurally blind to it (Phase 29 SESSION-20, `func_8013D53C`) L6472 -- **§3-The** — construct L6477 -- **§91** — A structure-TRANSFER is only valid where the structure corresponds: the `--like` role trap (Phase 29 SESSION-21, `func_8012AAAC` ×137) L6842 -- **§3-The** — three-hypothesis trail, because two of them were wrong and the wrongness is instructive L6871 -- **§129** — Post-carve, `rtu_match`/`match_one` COUNT THE JUMP TABLE AS INSTRUCTIONS; and a carve must never be committed without its owner (P30 S28, `func_8013BD74`) L8437 -- **§129a** — the target instruction count is INFLATED after a carve L8441 -- **§3-The** — DEFINITION-side alias is the only escape when the fleet canon disagrees on a promoting param L9473 -- **§3-Two** — errors of mine, both instructive L10009 -- **§160** — THE REACH-15 WAVE HARVEST: an align-1 block move, and the instrument that called it a wall (P30 S47) L10893 -- **§16Xy** — SHARPENS *(sharpens §136d-3, §37 /s-DEP LATTICE, §135-2, §136-13, §162q)* L12300 -- **§3-The** — `/s` drop clause is in ALL THREE dependence predicates, so the FIXED-ADDRESS STORE is what floats (P30 S48, `func_8017CA18`, ov_MAIN_012) L12302 -- **§16Z** — SHARPENS *(sharpens §37 "the /s-DEP LATTICE", §136-13, §136-14, §16Xy, §162q, `gcc-2.7.2-map/sched.md` §64)* L14353 -- **§3-The** — ADDRESS-CLASS TABLE: which load/store pairs even REACH the `/s` clause (P30 S48 wave 4, `func_80185B44`, ov_SC03_014) L14355 -- **§176g** — SIZE A WAVE BY INSTRUCTIONS, NOT BY CARDS (P31 S52 — the adopted doctrine) L16953 -- **§3-F.** — `MEM_IN_STRUCT_P` ASYMMETRY IN `true_dependence` (func_80037144, 124 ins) L17304 -- **§179-E** — A `>2*MAX_MOVE_BYTES` BLOCK COPY IS A **STRUCT ASSIGNMENT**, NOT A HAND LOOP L17506 -- **§176-B** — "REGALLOC-PERM, 1-4 instructions off" ⇒ it is usually NOT register allocation L17663 -- **§189** — FIVE COMPILER LAWS MINED FROM THE WAVE R/S JOURNALS (P31 S53), each source-cited and re-derived by a second agent L18226 -- **§193-A** — The wave card ships only OPEN-set pointers and discards the atlas's BANKED one — `exemplar`/`sibs` are stubs 100% by construction (tools/atlas.py:96/657), while `seed.ref` (matched pool, atlas.py:505-536) is dropped at build_wave_atlas.py:143 L18442 -- **§193-B** — A NARROW CAST OF A WIDE PARAMETER COSTS ONE EXTRA INSTRUCTION WHEN ITS STATEMENT SITS AFTER AN INTERVENING `jal` — AND THE DECIDER IS `combine.c:929`'s CROSS-CALL GUARD, NOT REGISTER ALLOCATION L18509 -- **§193-I** — A DECLARED AGGREGATE LOCAL HAS AN 8-BYTE FRAME STRIDE — CEIL(size,8), NOT size. N ARRAYS THEREFORE COST 8·k MORE THAN ONE HAND-LAID STRUCT (k = how many of them have size mod 8 ≠ 0), AND THE TELL IS IDENTICAL INSTRUCTION COUNT WITH EVERY $sp DISPLACEMENT SHIFTED BY THE SAME CONSTANT. L18847 -- **§194-E** — The wave card's `exemplar` is the TARGET ITSELF on 42/73 wave-U and 36/71 wave-T cards — a construction consequence of `atlas.py:657` (exemplar = max-nins OPEN member) meeting `build_wave_atlas.py:166` (one card per gid); and the shipped §193-A `seed_ref` is same-binary on 0/51, so no card field can ever name a destination-TU sibling L19158 -- **§194-H** — §164-29's WAR fence runs again at SCHED2 ON HARD REGISTERS: an in-place `v &= K` before a branch fences the store that reads v, and when TWO independent stores compete for the one delay slot the fence picks the winner at ZERO length drift (a WIDTH/sh!=sw swap, not a nop). Corrects §167-42's reconstruction (pseudo arm → hard-reg arm) and supplies its first re-runnable A/B. L19311 -- **§195-D** — §195 — `masked_diff.mask_for` returns 0 for EVERY `j`/`jal` word, so an internal `j` destination is invisible to match_one, the permuter scorer AND every similarity tier: a control-flow semantic error (which calls execute) surfaces as a 1-instruction residual mislabelled `DELAY-SLOT / profile=schedule`, or as an outright false MATCH L19884 -- **§195-F** — fold-const.c:4825 canonicalises a `?:` whose THEN arm is zero (or constant against a non-constant ELSE) by inverting the condition and swapping the arms — so a ternary's written arm order is byte-inert there, and `c ? 0 : X` is unspellable: it always compiles as `!c ? X : 0` L20010 -- **§195-G** — §NEW — TWO ARMS CALLING THE SAME CALLEE MERGE INTO ONE `jal` UNLESS EACH ARM'S OWN CODE CONSUMES THE RESULT: the C dial that keeps two call sites apart is WHERE the consumer test lives, and the branch SENSE you spell it with is byte-inert (jump.c:1737 canonicalises it) L20062 -- **§195-K** — At -O2 the §18 array-of-struct lever is a FRAME lever, not a length lever — but only when the N reads carry DISTINCT index expressions; with a SHARED index §18's +2-instruction residual is still alive at -O2 (the submitted "memory-loaded narrow index" precondition and unconditional length-neutrality are both falsified) L20266 -- **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` L20860 -- **§199-F** — §164-36b — THE TARGET-HEAD FENCE IS A DELAY-SLOT THREAD SELECTOR, AND IT ONLY FIRES WHEN `mostly_true_jump > 0` (amendment to §164-36; its "−1 instruction" tell is falsified) L20979 -- **§204-D** — A LOOP-INVARIANT LOAD IS ADMITTED AS A MOVABLE ONLY IF ITS ADDRESS CANNOT TRAP: `local.field` PASSES, THE SAME READ THROUGH A POINTER LOCAL IS REFUSED L21763 -- **§225** — THREE CONTROL-FLOW SHAPES NO STRUCTURED SPELLING REACHES (P31 S58) L22934 -- **§30** — addendum (P31 S58) — the `/s` grant closes a SCHEDULING residual and a REGISTER residual with one edit L23216 -- **§249** — THE SELF-ASSIGN, THE DEAD RE-ASSIGN, AND THE `+ zr` COPY: THREE WAYS TO MAKE A DELETED INSTRUCTION REAL (P31 S58b) L23890 -- **§30** — addendum (P31 S58b) — THE ANONYMOUS STRUCT MEMBER REF GRANTS `/s`, AND THAT IS A TWO-FOR-ONE L24158 -- **§263** — A STOLEN DELAY SLOT WHOSE INSTRUCTION IS AN ARG-REGISTER COPY IS AN ARITY ERROR, NOT A SCHEDULE (P31 S59, byte-proven) L24886 -- **ADD-8** — → §245 addendum — THE RE-TIE BARRIER PINS CALL-ARG SETUP TO SOURCE ORDER (construct 6) L25162 -- **ADD-11** — → Cross-confirmation card block (per §259's standing instruction: confirmation, not news) L25193 -- **ADD-4** — → §167-37 addendum — THE FIFTH PRECONDITION, NOW MEASURED: DOWNSTREAM FIELD RE-READS ⇒ NAME IT **AND** STORE **INSIDE** THE ARM L25353 -- **ADD-10** — → Cross-confirmation card block (per §259's standing instruction: confirmation, not news) L25444 -- **ADDENDUM** — to §82 — struct copies must stay MEMBER-WISE, not block-moved, to match a spill-slot save L25702 -- **ADDENDUM** — to §244 — THE COMPILER BARRIER, NOT `volatile`, BLOCKS A STORE→LOAD HOIST THROUGH A POINTER-OFFSET FIELD L26028 -- **§281** — GROUP COPY-THEN-RMW BY OPERATION KIND, NOT FIELD BY FIELD: sched1 does the interleaving, the source must not (P31 S60; wave cf, func_80180FB4, ov_SC03_111, byte-proven) L26949 -- **§NNN** — A DEPENDENT COPY-THEN-RMW BLOCK MUST BE SOURCE-GROUPED BY OPERATION KIND, NOT BY FIELD, AND SCHED1 DOES THE INTERLEAVING (P31 S60; `func_80180FB4`, ov_SC03_111, byte-proven) L26950 -- **§NNN** — WRITE THE UP-COUNT LOOP: gcc's OWN REVERSAL PRODUCES A COUNTER-INIT INSTRUCTION THAT LANDS AFTER HOISTED MOVABLES, WHICH A HAND-WRITTEN DOWN-COUNT LOOP CANNOT REPRODUCE (P31 S60; `func_80180DD8`, ov_SC04_005, byte-proven) L26996 -- **§285** — PRE-INITIALIZING A VARIABLE WITH A SHARED CONSTANT BEFORE A BRANCH MAKES BOTH ARMS OF THE FOLLOWING if/else DESTRUCTIVELY REUSE THE SAME DESTINATION REGISTER FOR THEIR BITWISE RESULT (byte-proven; `func_801811F0`, ov_SC03_102, independently rediscovered across waves di/dj) (P31 S60; waves #, byte-proven) L29037 -- **§287** — A STACK-FRAME HOLE BELOW TWO ADDRESS-TAKEN AGGREGATE LOCALS IS A LEADING PAD MEMBER OF ONE COMBINED STRUCT, NOT SEPARATE LOCALS OR A REGISTER PIN (P31 S60/dj; `func_8017D104`, ov_SC06_027, byte-proven 47/47) (P31 S60; waves #, byte-proven) L29045 -- **§297** — ONE GIV SERVING MIXED-WIDTH LOADS *AND* A STORE NEEDS STRUCT-MEMBER SPELLING; CAST/INDEX SPELLINGS RE-SPLIT THE PSEUDO (P31 S61; wave m0a, `func_800347C8`, main, byte-proven 31/31) L29458 -- **§308a** — A TWO-INSTRUCTION ARM STUB LAID *BEFORE* THE OTHER ARM AND REACHED ONLY BY A TRAILING `j` SURVIVES ONLY BEHIND A SHORT-CIRCUIT `&&` GUARD PLUS A SEPARATE RE-TEST; EVERY PLAIN if/else-if, GOTO-LADDER, NESTED-INVERTED-if AND 1-/2-NODE switch LETS jump1 INLINE IT (−2 ins) (P31 S63 t5e-t5i; byte-proven func_80180808) L29971 +- **§42a** — addendum — wave 2 (residuals + 29-100 band): iso-MATCH ≠ real-TU bank, the memcpy→struct-assign fix, +5 levers (2026-07-10b) L2968 +- **§44** — The Phase-25 cheap-Opus giant batch: 5 structural levers + the §43 extension (2026-07-11, 6 crackers over the frontier giants) L3257 +- **§46** — The `func_80178D40` crack (890 ins ×134, the heaviest core in the game): four LOOP-STRUCTURE levers cheap-Opus found by reading loop.c/jump.c/cse.c (Phase 26 session 8, 2026-07-13) L3328 +- **§3-Why** — 0/8 was structural, and predictable from two words L4060 +- **§54** — `--fix-def-sig`: the member's CANONICAL DECLARATION is a build step too (tiny-IMM mega-pools, +4,801, Phase 29 T6, 2026-07-16) L4178 +- **§56b** — PROPAGATING an h_seq giant: the exemplar's externs MUST be fleet-canonical, not the draft's types L4247 +- **§65a** — The blast-radius taxonomy (makes §61's law structural instead of remembered) L5045 +- **§66d-5** — `residual_class`'s "structural ⇒ permuter CPU is waste" is WRONG for schedule permutations (measured, Phase 29 SESSION-18) L5506 +- **§83** — The parameterised-repeat law, the spill-area trap, and why a per-case edit cannot move a per-case symptom (Phase 29 SESSION-20, `func_80183814` 5,122 ins, cold-ish start → 36 structural / 99.3%) L6427 +- **§84** — The DERIVED-OFFSET remap bug: a hand-computed literal that encodes the DISTANCE between two per-overlay symbols, and why `match_one` is structurally blind to it (Phase 29 SESSION-20, `func_8013D53C`) L6487 +- **§3-The** — construct L6492 +- **§91** — A structure-TRANSFER is only valid where the structure corresponds: the `--like` role trap (Phase 29 SESSION-21, `func_8012AAAC` ×137) L6857 +- **§3-The** — three-hypothesis trail, because two of them were wrong and the wrongness is instructive L6886 +- **§129** — Post-carve, `rtu_match`/`match_one` COUNT THE JUMP TABLE AS INSTRUCTIONS; and a carve must never be committed without its owner (P30 S28, `func_8013BD74`) L8452 +- **§129a** — the target instruction count is INFLATED after a carve L8456 +- **§3-The** — DEFINITION-side alias is the only escape when the fleet canon disagrees on a promoting param L9488 +- **§3-Two** — errors of mine, both instructive L10024 +- **§160** — THE REACH-15 WAVE HARVEST: an align-1 block move, and the instrument that called it a wall (P30 S47) L10908 +- **§16Xy** — SHARPENS *(sharpens §136d-3, §37 /s-DEP LATTICE, §135-2, §136-13, §162q)* L12315 +- **§3-The** — `/s` drop clause is in ALL THREE dependence predicates, so the FIXED-ADDRESS STORE is what floats (P30 S48, `func_8017CA18`, ov_MAIN_012) L12317 +- **§16Z** — SHARPENS *(sharpens §37 "the /s-DEP LATTICE", §136-13, §136-14, §16Xy, §162q, `gcc-2.7.2-map/sched.md` §64)* L14368 +- **§3-The** — ADDRESS-CLASS TABLE: which load/store pairs even REACH the `/s` clause (P30 S48 wave 4, `func_80185B44`, ov_SC03_014) L14370 +- **§176g** — SIZE A WAVE BY INSTRUCTIONS, NOT BY CARDS (P31 S52 — the adopted doctrine) L16968 +- **§3-F.** — `MEM_IN_STRUCT_P` ASYMMETRY IN `true_dependence` (func_80037144, 124 ins) L17319 +- **§179-E** — A `>2*MAX_MOVE_BYTES` BLOCK COPY IS A **STRUCT ASSIGNMENT**, NOT A HAND LOOP L17521 +- **§176-B** — "REGALLOC-PERM, 1-4 instructions off" ⇒ it is usually NOT register allocation L17678 +- **§189** — FIVE COMPILER LAWS MINED FROM THE WAVE R/S JOURNALS (P31 S53), each source-cited and re-derived by a second agent L18241 +- **§193-A** — The wave card ships only OPEN-set pointers and discards the atlas's BANKED one — `exemplar`/`sibs` are stubs 100% by construction (tools/atlas.py:96/657), while `seed.ref` (matched pool, atlas.py:505-536) is dropped at build_wave_atlas.py:143 L18457 +- **§193-B** — A NARROW CAST OF A WIDE PARAMETER COSTS ONE EXTRA INSTRUCTION WHEN ITS STATEMENT SITS AFTER AN INTERVENING `jal` — AND THE DECIDER IS `combine.c:929`'s CROSS-CALL GUARD, NOT REGISTER ALLOCATION L18524 +- **§193-I** — A DECLARED AGGREGATE LOCAL HAS AN 8-BYTE FRAME STRIDE — CEIL(size,8), NOT size. N ARRAYS THEREFORE COST 8·k MORE THAN ONE HAND-LAID STRUCT (k = how many of them have size mod 8 ≠ 0), AND THE TELL IS IDENTICAL INSTRUCTION COUNT WITH EVERY $sp DISPLACEMENT SHIFTED BY THE SAME CONSTANT. L18862 +- **§194-E** — The wave card's `exemplar` is the TARGET ITSELF on 42/73 wave-U and 36/71 wave-T cards — a construction consequence of `atlas.py:657` (exemplar = max-nins OPEN member) meeting `build_wave_atlas.py:166` (one card per gid); and the shipped §193-A `seed_ref` is same-binary on 0/51, so no card field can ever name a destination-TU sibling L19173 +- **§194-H** — §164-29's WAR fence runs again at SCHED2 ON HARD REGISTERS: an in-place `v &= K` before a branch fences the store that reads v, and when TWO independent stores compete for the one delay slot the fence picks the winner at ZERO length drift (a WIDTH/sh!=sw swap, not a nop). Corrects §167-42's reconstruction (pseudo arm → hard-reg arm) and supplies its first re-runnable A/B. L19326 +- **§195-D** — §195 — `masked_diff.mask_for` returns 0 for EVERY `j`/`jal` word, so an internal `j` destination is invisible to match_one, the permuter scorer AND every similarity tier: a control-flow semantic error (which calls execute) surfaces as a 1-instruction residual mislabelled `DELAY-SLOT / profile=schedule`, or as an outright false MATCH L19899 +- **§195-F** — fold-const.c:4825 canonicalises a `?:` whose THEN arm is zero (or constant against a non-constant ELSE) by inverting the condition and swapping the arms — so a ternary's written arm order is byte-inert there, and `c ? 0 : X` is unspellable: it always compiles as `!c ? X : 0` L20025 +- **§195-G** — §NEW — TWO ARMS CALLING THE SAME CALLEE MERGE INTO ONE `jal` UNLESS EACH ARM'S OWN CODE CONSUMES THE RESULT: the C dial that keeps two call sites apart is WHERE the consumer test lives, and the branch SENSE you spell it with is byte-inert (jump.c:1737 canonicalises it) L20077 +- **§195-K** — At -O2 the §18 array-of-struct lever is a FRAME lever, not a length lever — but only when the N reads carry DISTINCT index expressions; with a SHARED index §18's +2-instruction residual is still alive at -O2 (the submitted "memory-loaded narrow index" precondition and unconditional length-neutrality are both falsified) L20281 +- **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` L20875 +- **§199-F** — §164-36b — THE TARGET-HEAD FENCE IS A DELAY-SLOT THREAD SELECTOR, AND IT ONLY FIRES WHEN `mostly_true_jump > 0` (amendment to §164-36; its "−1 instruction" tell is falsified) L20994 +- **§204-D** — A LOOP-INVARIANT LOAD IS ADMITTED AS A MOVABLE ONLY IF ITS ADDRESS CANNOT TRAP: `local.field` PASSES, THE SAME READ THROUGH A POINTER LOCAL IS REFUSED L21778 +- **§225** — THREE CONTROL-FLOW SHAPES NO STRUCTURED SPELLING REACHES (P31 S58) L22949 +- **§30** — addendum (P31 S58) — the `/s` grant closes a SCHEDULING residual and a REGISTER residual with one edit L23231 +- **§249** — THE SELF-ASSIGN, THE DEAD RE-ASSIGN, AND THE `+ zr` COPY: THREE WAYS TO MAKE A DELETED INSTRUCTION REAL (P31 S58b) L23905 +- **§30** — addendum (P31 S58b) — THE ANONYMOUS STRUCT MEMBER REF GRANTS `/s`, AND THAT IS A TWO-FOR-ONE L24173 +- **§263** — A STOLEN DELAY SLOT WHOSE INSTRUCTION IS AN ARG-REGISTER COPY IS AN ARITY ERROR, NOT A SCHEDULE (P31 S59, byte-proven) L24901 +- **ADD-8** — → §245 addendum — THE RE-TIE BARRIER PINS CALL-ARG SETUP TO SOURCE ORDER (construct 6) L25177 +- **ADD-11** — → Cross-confirmation card block (per §259's standing instruction: confirmation, not news) L25208 +- **ADD-4** — → §167-37 addendum — THE FIFTH PRECONDITION, NOW MEASURED: DOWNSTREAM FIELD RE-READS ⇒ NAME IT **AND** STORE **INSIDE** THE ARM L25368 +- **ADD-10** — → Cross-confirmation card block (per §259's standing instruction: confirmation, not news) L25459 +- **ADDENDUM** — to §82 — struct copies must stay MEMBER-WISE, not block-moved, to match a spill-slot save L25717 +- **ADDENDUM** — to §244 — THE COMPILER BARRIER, NOT `volatile`, BLOCKS A STORE→LOAD HOIST THROUGH A POINTER-OFFSET FIELD L26043 +- **§281** — GROUP COPY-THEN-RMW BY OPERATION KIND, NOT FIELD BY FIELD: sched1 does the interleaving, the source must not (P31 S60; wave cf, func_80180FB4, ov_SC03_111, byte-proven) L26964 +- **§NNN** — A DEPENDENT COPY-THEN-RMW BLOCK MUST BE SOURCE-GROUPED BY OPERATION KIND, NOT BY FIELD, AND SCHED1 DOES THE INTERLEAVING (P31 S60; `func_80180FB4`, ov_SC03_111, byte-proven) L26965 +- **§NNN** — WRITE THE UP-COUNT LOOP: gcc's OWN REVERSAL PRODUCES A COUNTER-INIT INSTRUCTION THAT LANDS AFTER HOISTED MOVABLES, WHICH A HAND-WRITTEN DOWN-COUNT LOOP CANNOT REPRODUCE (P31 S60; `func_80180DD8`, ov_SC04_005, byte-proven) L27011 +- **§285** — PRE-INITIALIZING A VARIABLE WITH A SHARED CONSTANT BEFORE A BRANCH MAKES BOTH ARMS OF THE FOLLOWING if/else DESTRUCTIVELY REUSE THE SAME DESTINATION REGISTER FOR THEIR BITWISE RESULT (byte-proven; `func_801811F0`, ov_SC03_102, independently rediscovered across waves di/dj) (P31 S60; waves #, byte-proven) L29052 +- **§287** — A STACK-FRAME HOLE BELOW TWO ADDRESS-TAKEN AGGREGATE LOCALS IS A LEADING PAD MEMBER OF ONE COMBINED STRUCT, NOT SEPARATE LOCALS OR A REGISTER PIN (P31 S60/dj; `func_8017D104`, ov_SC06_027, byte-proven 47/47) (P31 S60; waves #, byte-proven) L29060 +- **§297** — ONE GIV SERVING MIXED-WIDTH LOADS *AND* A STORE NEEDS STRUCT-MEMBER SPELLING; CAST/INDEX SPELLINGS RE-SPLIT THE PSEUDO (P31 S61; wave m0a, `func_800347C8`, main, byte-proven 31/31) L29473 +- **§308a** — A TWO-INSTRUCTION ARM STUB LAID *BEFORE* THE OTHER ARM AND REACHED ONLY BY A TRAILING `j` SURVIVES ONLY BEHIND A SHORT-CIRCUIT `&&` GUARD PLUS A SEPARATE RE-TEST; EVERY PLAIN if/else-if, GOTO-LADDER, NESTED-INVERTED-if AND 1-/2-NODE switch LETS jump1 INLINE IT (−2 ins) (P31 S63 t5e-t5i; byte-proven func_80180808) L29986 +- **§312** — A BARE RELATIONAL IN AN `if` GIVES THE `slt` NO TARGET: ASSIGN THE COMPARISON INTO THE ALREADY-ALLOCATED VARIABLE TO CHOOSE ITS DESTINATION REGISTER, AT ZERO INSTRUCTION COST (P31 S64 t5o-t5r; byte-proven func_80180DCC) L30133 ### types, signedness & load/store width (77) @@ -408,72 +411,72 @@ - **§33** — Automating the giant decl-reconcile: `tools/reconcile_decls.py` (the DATA analog of §20's `cast_call_sites`) + a fleet-majority type oracle (Phase 24 T7b, byte-proven on `func_80129CF8`) L2434 - **§40a** — The DECL-RECONCILE pass (type-lift so remapped drafts compile in the sibling TU) (Phase 25 T7.2, 2026-07-08) L2601 - **§41** — The DEF-SIDE canonical-sig wall: mechanically banking a drafted giant past `conflicting types` (Phase 25 T5b batch-2, 2026-07-09; `tools/canon_sig_reconcile.py`, byte-proven on `func_8013B274`) L2710 -- **§41d** — `void`→`s32` is NOT always byte-neutral: gate the RAW draft FIRST (Phase 26 session 6, byte-proven) L2878 -- **§42b** — addendum — wave 3 (Max, 2026-07-10c): THE STALE-OBJECT GATE TRAP + the read-global `&`-cast drift + fix L2994 -- **§43** — The K&R s16-param definition DISSOLVES the "narrow-param wall" for by-value register args (Phase 25 task A, Fable5 crack of the 369-ins giant `func_80166994` ×134, 2026-07-11) L3195 -- **§3-C.** — TYPE- AND SHAPE-DRIVEN CODEGEN (the C type literally selects the addressing mode) L3484 -- **§56b** — PROPAGATING an h_seq giant: the exemplar's externs MUST be fleet-canonical, not the draft's types L4232 -- **§64** — The §20 type-lift's three laws: fold the tagged typedef, check VISIBILITY, and strip only what is TEXTUALLY IDENTICAL (`lift_types.py`, Phase 29 SESSION-14, 2026-07-23) L4908 -- **§64a** — VARIANT types: UNIQUIFY the camps, do not reconcile them (`uniquify_type.py`, Phase 29 SESSION-14) L4957 -- **§65g** — Where the cheap levers STOP: the local-type and in-TU-self-decl classes did not yield L5139 -- **§68** — A comment-only line halted the extern scan, and the skip label blamed the type cap (Phase 29 SESSION-18) L5524 -- **§73** — A def-side self-decl conflict has TWO axes: RETURN (fleet widen, T2) and PARAMS (casts at each use, T0). Diagnose which before paying for the expensive one (Phase 29 SESSION-19, `func_8014F3E8` + `func_8014D4C0`) L5783 -- **§75c** — Class-B's remedy is the FULL §17a-1 PAIR (decl **and** call-site cast); a decl-only fix moves the error and looks like a new wall (Phase 29 SESSION-19, `func_8012F14C`) L5997 -- **§3-The** — defect this exposed: a shared type that is present but invisible L6354 -- **§92** — Conforming a DECLARATION: pointer changes are caller-neutral, scalar-WIDTH changes are not (Phase 29 SESSION-21, `tools/conform_decls.py`) L6891 -- **§94** — A family sweep's `0/N` is a TYPE-CARRY failure until proven otherwise: lift the exemplar's local types, ALL of them, transitively (Phase 29 SESSION-21, `func_8016B6BC` 0/137 → 137/137) L6947 -- **§100** — Prefer the DRAFT-LOCAL fix: a type only one function uses belongs in its BODY, not in a shared header (Phase 29 SESSION-22, `func_80175DA8` 0/137 → 137/137) L7216 -- **§120** — Uniquify draft-defined TYPE names; and check which of N staging sites you actually patched (Phase 29 T93) L8026 -- **§3-Do** — NOT "strip the duplicate typedef" — it breaks the extern that uses it L8037 -- **§3-The** — type-form rules L8879 -- **§143** — `cast_call_sites` read a RETURN STATEMENT as a prototype and deleted it. A 0/39 sweep became 18/39. (P30 S40) L9834 -- **Then** — propagation returned 0/137 TWICE — both times a missing TYPE L10000 -- **§154** — Reading a disc payload: the module-id word, static base derivation, and "type 1 = uncompressed overlay" (P30 S44) L10522 -- **§3-C.** — PAC type 1 = the same payload class as type 4, just NOT compressed L10548 -- **§155b** — check the TYPE your oracle returns before comparing against it (S45 p5) L10587 -- **§3-B.** — Typedef handling — the only strategy that survives contact L17017 -- **§3-D.** — A NARROW TYPE BLOCKS COPY ELISION (func_8001D3FC — new idiom) L17288 -- **§185** — EDIT THE SIDE THAT IS CHEAP TO VERIFY, AND CHECK A TU RETYPE AT ITS USE SITES L18060 -- **§186b** — A NO-SAVE 16-BYTE FRAME IN A LEAF FUNCTION MEANS `s16` LOCALS, NOT A HIDDEN CALL L18113 -- **§193-B** — A NARROW CAST OF A WIDE PARAMETER COSTS ONE EXTRA INSTRUCTION WHEN ITS STATEMENT SITS AFTER AN INTERVENING `jal` — AND THE DECIDER IS `combine.c:929`'s CROSS-CALL GUARD, NOT REGISTER ALLOCATION L18509 -- **§193-G** — §164-54's "scope to ≥4 arms" bound is byte-wrong — the dispatch-topology oracle goes live at THREE case nodes (`balance_case_nodes` splits at `i > 2`), but only for a signed-after-promotion index L18746 -- **§193-H** — A pointer-derived base load `*(s32*)(p+K)` is uncacheable across ANY memory write or call (cse's third kill disjunct) — so the target emits one `lw` per store-separated RUN of spellings, and a run of stores sharing one `lw` is a C local you must declare L18807 -- **§194-B** — A `addu $rA,$rB,$zero` copy feeding ≥2 `sh` stores is a SECOND, 16-BIT-DECLARED local — the width, not the clamp or the join liveness, is what keeps the copy (and func_80183094's pin + `"memory"` clobber are both provably inert) L19016 -- **§194-D** — Declared width of a computed-value local is a sched1 dial (count-neutral) — a replication + attribution correction of §165-17, NOT a new argument-register law L19117 -- **§194-G** — Reading the integer half of a 16.16 stack aggregate: REGISTER-LIVENESS, not the C spelling, decides `sra` vs `lhu` — and the break is count-neutral L19268 -- **§194-H** — §164-29's WAR fence runs again at SCHED2 ON HARD REGISTERS: an in-place `v &= K` before a branch fences the store that reads v, and when TWO independent stores compete for the one delay slot the fence picks the winner at ZERO length drift (a WIDTH/sh!=sw swap, not a nop). Corrects §167-42's reconstruction (pseudo arm → hard-reg arm) and supplies its first re-runnable A/B. L19311 -- **§194-I** — §16N+2's magic-per-odd-part ladder has exactly one broken row — read the divisor arithmetically instead: d = round(2^(32 + post_shift) / magic_read_as_unsigned) L19349 -- **§197-A** — A NARROW SIGNED MEMORY READ FEEDING A CONSTANT `>>` LOSES ITS `lh`, AND THE CURE IS AN ASM RE-TIE (attribution CONTESTED: cse vs combine) L20581 -- **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` L20860 -- **§201-D** — THE SIGNEDNESS OF A div/mod MAGIC IS DECIDED BY THE STATIC TYPE OF THE DIVIDEND TREE AFTER `get_narrower` STRIPS WIDENING CONVERSIONS — NEVER BY A PROVABLE RANGE. AN `& 0xFF` IS NOT A CONVERSION, SO IT NEVER FLIPS THE MAGIC; A DECLARED-UNSIGNED LOCAL *OR* A NARROWING CAST WRITTEN AT THE DIVIDE BOTH DO. L21321 -- **§203** — A DEDUPED TYPEDEF MUST PRECEDE EVERY SPLICE POINT, NOT JUST ITS OWN (P31 S56) L21486 -- **§204-E** — `decl_prior`'s `%hi/%lo` ARM HAS NEVER FIRED: the card's promised GLOBAL-TYPE row is 0 of 1,210 L21838 -- **§218** — A NARROW TYPE AT THE ABI BOUNDARY COSTS AN IN-PLACE `sll/sra` PAIR — on the RETURN as well as on the PARAMETER (P31 S58) L22682 -- **§220** — THE PARAMETER ITSELF IS A REGALLOC DIAL: use it directly, prefer `s32` to `void*`, and place the save-copy AFTER the first call (P31 S58) L22738 -- **§227** — TYPE THE SOURCE BY THE **LOAD** WIDTH, NOT BY THE STORE WIDTH (P31 S58) L23018 -- **§234** — CONSTANT MATERIALISATION: THE STORE LVALUE'S SIGNEDNESS PICKS `addiu` vs `li`/`ori` (P31 S58b) L23316 -- **§237** — THE CAST-AT-CALL-SITE DECISION TABLE: WHAT §17a-1 FIXES, WHAT IT CANNOT, AND THE FOUR ESCAPES (P31 S58b) L23465 -- **§242** — `*k` vs `<>n`: EXPRESSION SPELLING OWNS THE LOAD WIDTH AND THE ROUNDING CHAIN (P31 S58b) L23652 -- **§243** — SPELL THE CSE BARRIER AS A REASSIGNED POINTER; AND THE `nop`-AFTER-EVERY-`lh` SIGNATURE (P31 S58b) L23680 -- **§251** — IMMEDIATE-SPELLING TRIGGERS: `+= 0xFF`, FULL-WIDTH `~K`, AND THE TWO-OR SPLIT (P31 S58b) L23969 -- **ADD-5** — → §1/I1 addendum — THE INVERTED RANGE TEST: `(u32)(x-lo) >= N` WITH THE ZERO-ARM AS THE TRAILING `else` L25132 -- **ADD-2** — → §236 addendum (item 1 corollary) — THE SILENT-SPLICE DECLARATION LADDER: WHERE THE TU HAS NO SPELLING, UNPROTOTYPED `()` BEATS THE FLEET VOTE L25326 -- **ADD-5** — → §267-ADD-6 / §172b-1 addendum — THE SIGN-TEST FACE: `(s16)v < 0` IS `sll 16` + `bgez` ON THE SHIFTED COPY, RAW STAYS LIVE — AND THE HALFWORD-ABS SHAPE NEEDS NO RITUAL L25370 -- **ADD-8** — → §30a addendum — THE THIRD COLUMN: `*p++` IS ALSO SERIALIZED BUT BURNS `addiu`; ONLY CAST-PLUS GIVES SERIALIZATION *AND* DISPLACEMENT FOLDING L25415 -- **ADDENDUM** — to §179-C — the `.type NAME, @function` requirement L25599 -- **ADDENDUM** — to §134 — a typedef defined BELOW the splice point is stripped anyway L25646 -- **ADDENDUM** — to §172b-1 — TWO PLACEMENT DIALS THE PROMOTION LAW DOESN'T NAME: NARROW THE COUNTER'S DECLARED TYPE, AND MOVE THE CAST INTO THE LOOP BODY L26059 -- **ADDENDUM** — to §172b-4 — THE PLAIN CAST-DIVISION ALREADY PRODUCES THE PATTERN; DON'T HAND-ROLL THE BIAS, AND KEEP THE OPERAND WIDE L26151 -- **§280** — THE CURSOR'S DECLARED TYPE PICKS `sltu` vs `slt`: a `T*` bound test is UNSIGNED by C rule, an integer cursor is signed (P31 S60; wave cf, func_800CAE74, md_MAIN_031, byte-proven) L26915 -- **§NNN** — A LOOP CURSOR'S C TYPE (POINTER vs PLAIN INTEGER) SELECTS `sltu` vs `slt` FOR ITS BOUND TEST, INDEPENDENT OF THE VALUES INVOLVED (P31 S60; `func_800CAE74`, md_MAIN_031, byte-proven; cross-confirmed same wave by `func_8017F2A4`, ov_SC03_096) L26916 -- **ADDENDUM** — to §21 — the `bltz`+`slti` (or N-separate-compares) signed-range-split bullet is now CONFIRMED on three independent functions, and generalizes beyond `lbu`/u8 L27116 -- **ADDENDUM** — to §202 — the DEF-SIDE ALIAS also resolves a function-vs-DATA-symbol identifier clash, not only a function-vs-function prototype clash L27162 -- **ADDENDUM** — §NNN — sharpens §162a3/§60b: A `sll $v0,16 / sltiu $v0,1` ZERO-TEST OF A JUST-DECREMENTED HALFWORD IS A SIGNED-TEMP WIDTH TELL OUTSIDE ANY SWITCH/RANGE-TEST CONTEXT L28252 -- **§288** — A REGISTER PIN DECLARED UNINITIALIZED AND ASSIGNED ONLY AT ITS LATE, SOLE USE STILL FORCES THE FIXED REGISTER'S SAVE/RESTORE, AND THE ASSIGNMENT'S SOURCE POSITION CONTROLS WHERE THE VALUE MATERIALIZES (P31; `func_80186530`, ov_SC02_017, byte-proven, match_one MATCH re-verified) (P31 S60; waves #, byte-proven) L29049 -- **§292** — DECLARING A SYMBOL UPSTREAM OF AN ALREADY-BANKED SIBLING THAT RELIES ON THAT SYMBOL'S IMPLICIT (K&R) DECLARATION CAN SILENTLY REPROTOTYPE THE SIBLING'S OWN CALL SITE (P31 S60; waves #, byte-proven) L29065 -- **ADDENDUM** — to §172b-1 (counter-type dial) — the sll's SOURCE REGISTER is the placement discriminator L29227 -- **ADDENDUM** — to §31's asm→layout inference — TWO WIDTH-PAIR DISCRIMINATORS (same offset, different widths) L29339 -- **§297** — ONE GIV SERVING MIXED-WIDTH LOADS *AND* A STORE NEEDS STRUCT-MEMBER SPELLING; CAST/INDEX SPELLINGS RE-SPLIT THE PSEUDO (P31 S61; wave m0a, `func_800347C8`, main, byte-proven 31/31) L29458 +- **§41d** — `void`→`s32` is NOT always byte-neutral: gate the RAW draft FIRST (Phase 26 session 6, byte-proven) L2893 +- **§42b** — addendum — wave 3 (Max, 2026-07-10c): THE STALE-OBJECT GATE TRAP + the read-global `&`-cast drift + fix L3009 +- **§43** — The K&R s16-param definition DISSOLVES the "narrow-param wall" for by-value register args (Phase 25 task A, Fable5 crack of the 369-ins giant `func_80166994` ×134, 2026-07-11) L3210 +- **§3-C.** — TYPE- AND SHAPE-DRIVEN CODEGEN (the C type literally selects the addressing mode) L3499 +- **§56b** — PROPAGATING an h_seq giant: the exemplar's externs MUST be fleet-canonical, not the draft's types L4247 +- **§64** — The §20 type-lift's three laws: fold the tagged typedef, check VISIBILITY, and strip only what is TEXTUALLY IDENTICAL (`lift_types.py`, Phase 29 SESSION-14, 2026-07-23) L4923 +- **§64a** — VARIANT types: UNIQUIFY the camps, do not reconcile them (`uniquify_type.py`, Phase 29 SESSION-14) L4972 +- **§65g** — Where the cheap levers STOP: the local-type and in-TU-self-decl classes did not yield L5154 +- **§68** — A comment-only line halted the extern scan, and the skip label blamed the type cap (Phase 29 SESSION-18) L5539 +- **§73** — A def-side self-decl conflict has TWO axes: RETURN (fleet widen, T2) and PARAMS (casts at each use, T0). Diagnose which before paying for the expensive one (Phase 29 SESSION-19, `func_8014F3E8` + `func_8014D4C0`) L5798 +- **§75c** — Class-B's remedy is the FULL §17a-1 PAIR (decl **and** call-site cast); a decl-only fix moves the error and looks like a new wall (Phase 29 SESSION-19, `func_8012F14C`) L6012 +- **§3-The** — defect this exposed: a shared type that is present but invisible L6369 +- **§92** — Conforming a DECLARATION: pointer changes are caller-neutral, scalar-WIDTH changes are not (Phase 29 SESSION-21, `tools/conform_decls.py`) L6906 +- **§94** — A family sweep's `0/N` is a TYPE-CARRY failure until proven otherwise: lift the exemplar's local types, ALL of them, transitively (Phase 29 SESSION-21, `func_8016B6BC` 0/137 → 137/137) L6962 +- **§100** — Prefer the DRAFT-LOCAL fix: a type only one function uses belongs in its BODY, not in a shared header (Phase 29 SESSION-22, `func_80175DA8` 0/137 → 137/137) L7231 +- **§120** — Uniquify draft-defined TYPE names; and check which of N staging sites you actually patched (Phase 29 T93) L8041 +- **§3-Do** — NOT "strip the duplicate typedef" — it breaks the extern that uses it L8052 +- **§3-The** — type-form rules L8894 +- **§143** — `cast_call_sites` read a RETURN STATEMENT as a prototype and deleted it. A 0/39 sweep became 18/39. (P30 S40) L9849 +- **Then** — propagation returned 0/137 TWICE — both times a missing TYPE L10015 +- **§154** — Reading a disc payload: the module-id word, static base derivation, and "type 1 = uncompressed overlay" (P30 S44) L10537 +- **§3-C.** — PAC type 1 = the same payload class as type 4, just NOT compressed L10563 +- **§155b** — check the TYPE your oracle returns before comparing against it (S45 p5) L10602 +- **§3-B.** — Typedef handling — the only strategy that survives contact L17032 +- **§3-D.** — A NARROW TYPE BLOCKS COPY ELISION (func_8001D3FC — new idiom) L17303 +- **§185** — EDIT THE SIDE THAT IS CHEAP TO VERIFY, AND CHECK A TU RETYPE AT ITS USE SITES L18075 +- **§186b** — A NO-SAVE 16-BYTE FRAME IN A LEAF FUNCTION MEANS `s16` LOCALS, NOT A HIDDEN CALL L18128 +- **§193-B** — A NARROW CAST OF A WIDE PARAMETER COSTS ONE EXTRA INSTRUCTION WHEN ITS STATEMENT SITS AFTER AN INTERVENING `jal` — AND THE DECIDER IS `combine.c:929`'s CROSS-CALL GUARD, NOT REGISTER ALLOCATION L18524 +- **§193-G** — §164-54's "scope to ≥4 arms" bound is byte-wrong — the dispatch-topology oracle goes live at THREE case nodes (`balance_case_nodes` splits at `i > 2`), but only for a signed-after-promotion index L18761 +- **§193-H** — A pointer-derived base load `*(s32*)(p+K)` is uncacheable across ANY memory write or call (cse's third kill disjunct) — so the target emits one `lw` per store-separated RUN of spellings, and a run of stores sharing one `lw` is a C local you must declare L18822 +- **§194-B** — A `addu $rA,$rB,$zero` copy feeding ≥2 `sh` stores is a SECOND, 16-BIT-DECLARED local — the width, not the clamp or the join liveness, is what keeps the copy (and func_80183094's pin + `"memory"` clobber are both provably inert) L19031 +- **§194-D** — Declared width of a computed-value local is a sched1 dial (count-neutral) — a replication + attribution correction of §165-17, NOT a new argument-register law L19132 +- **§194-G** — Reading the integer half of a 16.16 stack aggregate: REGISTER-LIVENESS, not the C spelling, decides `sra` vs `lhu` — and the break is count-neutral L19283 +- **§194-H** — §164-29's WAR fence runs again at SCHED2 ON HARD REGISTERS: an in-place `v &= K` before a branch fences the store that reads v, and when TWO independent stores compete for the one delay slot the fence picks the winner at ZERO length drift (a WIDTH/sh!=sw swap, not a nop). Corrects §167-42's reconstruction (pseudo arm → hard-reg arm) and supplies its first re-runnable A/B. L19326 +- **§194-I** — §16N+2's magic-per-odd-part ladder has exactly one broken row — read the divisor arithmetically instead: d = round(2^(32 + post_shift) / magic_read_as_unsigned) L19364 +- **§197-A** — A NARROW SIGNED MEMORY READ FEEDING A CONSTANT `>>` LOSES ITS `lh`, AND THE CURE IS AN ASM RE-TIE (attribution CONTESTED: cse vs combine) L20596 +- **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` L20875 +- **§201-D** — THE SIGNEDNESS OF A div/mod MAGIC IS DECIDED BY THE STATIC TYPE OF THE DIVIDEND TREE AFTER `get_narrower` STRIPS WIDENING CONVERSIONS — NEVER BY A PROVABLE RANGE. AN `& 0xFF` IS NOT A CONVERSION, SO IT NEVER FLIPS THE MAGIC; A DECLARED-UNSIGNED LOCAL *OR* A NARROWING CAST WRITTEN AT THE DIVIDE BOTH DO. L21336 +- **§203** — A DEDUPED TYPEDEF MUST PRECEDE EVERY SPLICE POINT, NOT JUST ITS OWN (P31 S56) L21501 +- **§204-E** — `decl_prior`'s `%hi/%lo` ARM HAS NEVER FIRED: the card's promised GLOBAL-TYPE row is 0 of 1,210 L21853 +- **§218** — A NARROW TYPE AT THE ABI BOUNDARY COSTS AN IN-PLACE `sll/sra` PAIR — on the RETURN as well as on the PARAMETER (P31 S58) L22697 +- **§220** — THE PARAMETER ITSELF IS A REGALLOC DIAL: use it directly, prefer `s32` to `void*`, and place the save-copy AFTER the first call (P31 S58) L22753 +- **§227** — TYPE THE SOURCE BY THE **LOAD** WIDTH, NOT BY THE STORE WIDTH (P31 S58) L23033 +- **§234** — CONSTANT MATERIALISATION: THE STORE LVALUE'S SIGNEDNESS PICKS `addiu` vs `li`/`ori` (P31 S58b) L23331 +- **§237** — THE CAST-AT-CALL-SITE DECISION TABLE: WHAT §17a-1 FIXES, WHAT IT CANNOT, AND THE FOUR ESCAPES (P31 S58b) L23480 +- **§242** — `*k` vs `<>n`: EXPRESSION SPELLING OWNS THE LOAD WIDTH AND THE ROUNDING CHAIN (P31 S58b) L23667 +- **§243** — SPELL THE CSE BARRIER AS A REASSIGNED POINTER; AND THE `nop`-AFTER-EVERY-`lh` SIGNATURE (P31 S58b) L23695 +- **§251** — IMMEDIATE-SPELLING TRIGGERS: `+= 0xFF`, FULL-WIDTH `~K`, AND THE TWO-OR SPLIT (P31 S58b) L23984 +- **ADD-5** — → §1/I1 addendum — THE INVERTED RANGE TEST: `(u32)(x-lo) >= N` WITH THE ZERO-ARM AS THE TRAILING `else` L25147 +- **ADD-2** — → §236 addendum (item 1 corollary) — THE SILENT-SPLICE DECLARATION LADDER: WHERE THE TU HAS NO SPELLING, UNPROTOTYPED `()` BEATS THE FLEET VOTE L25341 +- **ADD-5** — → §267-ADD-6 / §172b-1 addendum — THE SIGN-TEST FACE: `(s16)v < 0` IS `sll 16` + `bgez` ON THE SHIFTED COPY, RAW STAYS LIVE — AND THE HALFWORD-ABS SHAPE NEEDS NO RITUAL L25385 +- **ADD-8** — → §30a addendum — THE THIRD COLUMN: `*p++` IS ALSO SERIALIZED BUT BURNS `addiu`; ONLY CAST-PLUS GIVES SERIALIZATION *AND* DISPLACEMENT FOLDING L25430 +- **ADDENDUM** — to §179-C — the `.type NAME, @function` requirement L25614 +- **ADDENDUM** — to §134 — a typedef defined BELOW the splice point is stripped anyway L25661 +- **ADDENDUM** — to §172b-1 — TWO PLACEMENT DIALS THE PROMOTION LAW DOESN'T NAME: NARROW THE COUNTER'S DECLARED TYPE, AND MOVE THE CAST INTO THE LOOP BODY L26074 +- **ADDENDUM** — to §172b-4 — THE PLAIN CAST-DIVISION ALREADY PRODUCES THE PATTERN; DON'T HAND-ROLL THE BIAS, AND KEEP THE OPERAND WIDE L26166 +- **§280** — THE CURSOR'S DECLARED TYPE PICKS `sltu` vs `slt`: a `T*` bound test is UNSIGNED by C rule, an integer cursor is signed (P31 S60; wave cf, func_800CAE74, md_MAIN_031, byte-proven) L26930 +- **§NNN** — A LOOP CURSOR'S C TYPE (POINTER vs PLAIN INTEGER) SELECTS `sltu` vs `slt` FOR ITS BOUND TEST, INDEPENDENT OF THE VALUES INVOLVED (P31 S60; `func_800CAE74`, md_MAIN_031, byte-proven; cross-confirmed same wave by `func_8017F2A4`, ov_SC03_096) L26931 +- **ADDENDUM** — to §21 — the `bltz`+`slti` (or N-separate-compares) signed-range-split bullet is now CONFIRMED on three independent functions, and generalizes beyond `lbu`/u8 L27131 +- **ADDENDUM** — to §202 — the DEF-SIDE ALIAS also resolves a function-vs-DATA-symbol identifier clash, not only a function-vs-function prototype clash L27177 +- **ADDENDUM** — §NNN — sharpens §162a3/§60b: A `sll $v0,16 / sltiu $v0,1` ZERO-TEST OF A JUST-DECREMENTED HALFWORD IS A SIGNED-TEMP WIDTH TELL OUTSIDE ANY SWITCH/RANGE-TEST CONTEXT L28267 +- **§288** — A REGISTER PIN DECLARED UNINITIALIZED AND ASSIGNED ONLY AT ITS LATE, SOLE USE STILL FORCES THE FIXED REGISTER'S SAVE/RESTORE, AND THE ASSIGNMENT'S SOURCE POSITION CONTROLS WHERE THE VALUE MATERIALIZES (P31; `func_80186530`, ov_SC02_017, byte-proven, match_one MATCH re-verified) (P31 S60; waves #, byte-proven) L29064 +- **§292** — DECLARING A SYMBOL UPSTREAM OF AN ALREADY-BANKED SIBLING THAT RELIES ON THAT SYMBOL'S IMPLICIT (K&R) DECLARATION CAN SILENTLY REPROTOTYPE THE SIBLING'S OWN CALL SITE (P31 S60; waves #, byte-proven) L29080 +- **ADDENDUM** — to §172b-1 (counter-type dial) — the sll's SOURCE REGISTER is the placement discriminator L29242 +- **ADDENDUM** — to §31's asm→layout inference — TWO WIDTH-PAIR DISCRIMINATORS (same offset, different widths) L29354 +- **§297** — ONE GIV SERVING MIXED-WIDTH LOADS *AND* A STORE NEEDS STRUCT-MEMBER SPELLING; CAST/INDEX SPELLINGS RE-SPLIT THE PSEUDO (P31 S61; wave m0a, `func_800347C8`, main, byte-proven 31/31) L29473 ### declarations, prototypes & K&R (99) @@ -489,93 +492,93 @@ - **§33** — Automating the giant decl-reconcile: `tools/reconcile_decls.py` (the DATA analog of §20's `cast_call_sites`) + a fleet-majority type oracle (Phase 24 T7b, byte-proven on `func_80129CF8`) L2434 - **§40a** — The DECL-RECONCILE pass (type-lift so remapped drafts compile in the sibling TU) (Phase 25 T7.2, 2026-07-08) L2601 - **§41** — The DEF-SIDE canonical-sig wall: mechanically banking a drafted giant past `conflicting types` (Phase 25 T5b batch-2, 2026-07-09; `tools/canon_sig_reconcile.py`, byte-proven on `func_8013B274`) L2710 -- **§41b** — addendum — M4 "reconcile_decls" tier is ALSO a probe over-count: 0/8 mechanical (Phase 25 T7-M4, 2026-07-10) L2858 -- **§41d** — `void`→`s32` is NOT always byte-neutral: gate the RAW draft FIRST (Phase 26 session 6, byte-proven) L2878 -- **§43** — The K&R s16-param definition DISSOLVES the "narrow-param wall" for by-value register args (Phase 25 task A, Fable5 crack of the 369-ins giant `func_80166994` ×134, 2026-07-11) L3195 -- **§51g** — When the thing you are scanning has a GRAMMAR, parse the grammar (`tools/cdecl.py`) L3769 -- **§54** — `--fix-def-sig`: the member's CANONICAL DECLARATION is a build step too (tiny-IMM mega-pools, +4,801, Phase 29 T6, 2026-07-16) L4163 -- **§56** — Banking a hand-drafted GIANT into its exemplar TU: self-contained draft vs live-TU decls, 4 reconciliation tactics (`func_8013FAF8`, 312 ins ×138, Phase 29 T4, 2026-07-17) L4187 -- **§56b** — PROPAGATING an h_seq giant: the exemplar's externs MUST be fleet-canonical, not the draft's types L4232 -- **§57** — The SELF-decl normalize: the sibling's OWN caller declares the templated fn divergently (the third §17a-1 direction; `tools/normalize_self_decls.py`, func_801670E4 ×137, Phase 29, 2026-07-18) L4256 -- **§61** — Task 14: the gate ladder's missing stage is the ARITY pre-pass, and it is TU-side not draft-side (Phase 29, 2026-07-21) L4545 -- **§63** — The fresh-138 DEF-SIDE blocker: fix the HEADER decl, not the draft (`fix_header_decl.py`, Phase 29 SESSION-13, 2026-07-23) L4877 -- **§63** — UPDATE (Phase 29 SESSION-14) — `fix_header_decl`'s "SAFE" verdict is FLEET-BLIND; it MUST be R22-validated L5000 -- **§65c** — `rtu_match` MATCH → bank held 13/13 on self-decl, but broke on the FIRST callee-decl case L5081 -- **§65g** — Where the cheap levers STOP: the local-type and in-TU-self-decl classes did not yield L5139 -- **§66a** — The widest write in a pipeline is the one most likely to be UNDECLARED L5181 -- **§68** — A comment-only line halted the extern scan, and the skip label blamed the type cap (Phase 29 SESSION-18) L5524 -- **§73** — A def-side self-decl conflict has TWO axes: RETURN (fleet widen, T2) and PARAMS (casts at each use, T0). Diagnose which before paying for the expensive one (Phase 29 SESSION-19, `func_8014F3E8` + `func_8014D4C0`) L5783 -- **§75** — A propagation cap is usually a MINORITY-SPELLING SOURCE OVERLAY, not a wall: census the carried extern before believing the exclusion message (Phase 29 SESSION-19, `func_8014F3E8` ×4 → ×138) L5866 -- **§75b** — A body's preamble can carry `#define`s, not just `extern`s; extraction lifts only the externs (Phase 29 SESSION-19, `func_80165CA0` ×3 → fleet) L5948 -- **§75c** — Class-B's remedy is the FULL §17a-1 PAIR (decl **and** call-site cast); a decl-only fix moves the error and looks like a new wall (Phase 29 SESSION-19, `func_8012F14C`) L5997 -- **§76** — The allocno CLASS (local vs global) is the dominant regalloc lever, and C reaches it ONLY through declaration scope and variable reuse (Phase 29 SESSION-19, behemoth #3 `func_8017F510` 1,511 ins, 97 → MATCH, pin-free) L6028 -- **§79** — For a 0-callee giant, fingerprint by DATA symbols (§71 cannot fire); and the STACK-SLOT ORDER is a declaration-order oracle (Phase 29 SESSION-19, `func_8017BF14` 4,763 ins, cold start → 45/4763) L6220 -- **§3-NEW** — LEVER — the frame layout reads back the original declaration order L6240 -- **§3-1.** — The inlined-helper signature L6375 -- **§92** — Conforming a DECLARATION: pointer changes are caller-neutral, scalar-WIDTH changes are not (Phase 29 SESSION-21, `tools/conform_decls.py`) L6891 -- **§95** — `reconcile_tu` dropped the SIBLING declarators of a multi-symbol `extern` line (Phase 29 SESSION-21, `func_80176218`) L6983 -- **§96** — The same rewrite, one shape down: `reconcile_tu` matched statements to lines by TEXT, so every COMMENTED declaration was silently skipped (Phase 29 SESSION-22, `func_80176218` banked) L7018 -- **§98** — `conform_decls` had three defects, and only the third needed R22 to find (Phase 29 SESSION-22, `func_8014CF04`) L7113 -- **§99** — The narrow-param wall is a DEF-side problem with a ZERO-blast-radius fix: convert the definition to K&R (Phase 29 SESSION-22, `func_80175AB8` + `func_80175DA8`) L7167 -- **§102** — A PLUMBING verdict can MASK a DIFF; and K&R is not always a codegen change (Phase 29 SESSION-22, `func_8016EC0C`) L7272 -- **§103** — A FILE-scope `extern` in a shared overlay TU is a GLOBAL constraint on every LATER function; move the DECL, not the draft (Phase 29 T48/T51, `func_80135260` — the fleet-wide half) L7307 -- **§104** — Two silent-skip defects in one scan: match on MASKED text, emit from the ORIGINAL (Phase 29 T53, `gather_externs`) L7395 -- **§112** — A macro-scoped declaration only collides where the macro is INSTANTIATED (Phase 29 T67/T69, `audit_header_sigs.py`) L7730 -- **§113** — An ARITY blocker only exists if the macro CALLS the function; an address-taken use has no call site (Phase 29 T72) L7776 -- **§114** — The THIRD decl axis: a CALLEE the draft declares differently from the target TU (Phase 29 T76/T77) L7808 -- **§3-Do** — NOT "strip the duplicate typedef" — it breaks the extern that uses it L8037 -- **§121** — Synthesise externs for macro-DEFINED callees from the macro's own definition head (Phase 29 T95) L8061 -- **§3-The** — declaration surface (integration, not codegen) L8941 -- **§136f** — Two declaration sub-cases the reconcile lane surfaced (lane now 15/15 lifetime) L9186 -- **§138** — The propagation lanes: a gate refusal is a DECLARATION, and which lever you owe depends on blast radius L9415 -- **Reconciling** — a gate-refused draft: which way you edit depends on WHERE the TU's decl is L9565 -- **§141** — The §134 class is CLOSED: every line-shape decision now routes through `cdecl._mask` (P30 S39) L9740 -- **§143** — `cast_call_sites` read a RETURN STATEMENT as a prototype and deleted it. A 0/39 sweep became 18/39. (P30 S40) L9834 -- **§3-C.** — Inner-block declaration does NOT delay slot allocation — BYTE-REFUTED L10068 -- **§159** — THE DECLARATION AXIS: conform to byte-truth, and make every guard state its COVERAGE (P30 S47; ~10,930 sites across 8 axes, fleet byte-identical) L10828 -- **§168** — THE COUSIN TIER (P30 S49, 2026-08-12): h_seq's exact-hash brittleness, measured — and the similarity map above it L16224 -- **§176f** — THE DECLARATION FORM IS A MATCHING LEVER, SO RECONCILE TOWARD THE FORM THE MATCH NEEDS (P31 S52) L16922 -- **§183** — THE DECLARATION-RECONCILIATION PLAYBOOK (P31 S53, measured on 20 byte-verified drafts) L17961 -- **§193-H** — A pointer-derived base load `*(s32*)(p+K)` is uncacheable across ANY memory write or call (cse's third kill disjunct) — so the target emits one `lw` per store-separated RUN of spellings, and a run of stores sharing one `lw` is a C local you must declare L18807 -- **§193-I** — A DECLARED AGGREGATE LOCAL HAS AN 8-BYTE FRAME STRIDE — CEIL(size,8), NOT size. N ARRAYS THEREFORE COST 8·k MORE THAN ONE HAND-LAID STRUCT (k = how many of them have size mod 8 ≠ 0), AND THE TELL IS IDENTICAL INSTRUCTION COUNT WITH EVERY $sp DISPLACEMENT SHIFTED BY THE SAME CONSTANT. L18847 -- **§194-B** — A `addu $rA,$rB,$zero` copy feeding ≥2 `sh` stores is a SECOND, 16-BIT-DECLARED local — the width, not the clamp or the join liveness, is what keeps the copy (and func_80183094's pin + `"memory"` clobber are both provably inert) L19016 -- **§194-D** — Declared width of a computed-value local is a sched1 dial (count-neutral) — a replication + attribution correction of §165-17, NOT a new argument-register law L19117 -- **§195-A** — §167-08's "an $aN READ before the jal is scratch" has a byte-proven FALSE-NEGATIVE class: an argument that DIES at the call is allocated straight into $aN, so its only def is a plain load far above the jal and every intervening use reads $aN — there is no positive tell in either direction, only the two-arity A/B L19723 -- **§195-C** — A call-argument `%hi/%lo` pair sitting at the block head, far above its `jal`, is a load-delay-gap filler chosen by SOURCE STATEMENT ORDER — swap the two independent statements nearest the call; a single-use `void *p = &SYM;` call-arg temp is OUTPUT-inert against it (but NOT expand-stream-inert) L19836 -- **§195-D** — §195 — `masked_diff.mask_for` returns 0 for EVERY `j`/`jal` word, so an internal `j` destination is invisible to match_one, the permuter scorer AND every similarity tier: a control-flow semantic error (which calls execute) surfaces as a 1-instruction residual mislabelled `DELAY-SLOT / profile=schedule`, or as an outright false MATCH L19884 -- **§195-F** — fold-const.c:4825 canonicalises a `?:` whose THEN arm is zero (or constant against a non-constant ELSE) by inverting the condition and swapping the arms — so a ternary's written arm order is byte-inert there, and `c ? 0 : X` is unspellable: it always compiles as `!c ? X : 0` L20010 -- **§195-G** — §NEW — TWO ARMS CALLING THE SAME CALLEE MERGE INTO ONE `jal` UNLESS EACH ARM'S OWN CODE CONSUMES THE RESULT: the C dial that keeps two call sites apart is WHERE the consumer test lives, and the branch SENSE you spell it with is byte-inert (jump.c:1737 canonicalises it) L20062 -- **§195-H** — §165-27g — ON A FIXED-SYMBOL GLOBAL, `extern T D[];` + `D[0]` IS THE CSE RELOAD DIAL, AT ZERO ADDRESSING COST, AND THE ELEMENT COUNT IS INERT (§165-27's `T v[2]` CAVEAT IS A LOCAL-FRAME FACT AND DOES NOT TRANSFER) L20110 -- **§196** — PUT ON THE CARD WHAT THE TREE ALREADY KNOWS: the fleet's declaration consensus (P31 S54) L20512 -- **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` L20860 -- **§199-G** — At TWO case nodes the switch-vs-if oracle is not blind — but the tell is ALL tests positive + a trailing `j default`, NOT the first test's polarity L21033 -- **§200** — THE ALIAS IS THE UNIVERSAL DECLARATION ESCAPE: stop negotiating with the TU's spelling (P31 S55) L21099 -- **§201-A** — §150-B applies to `decl_prior`'s DEF row: for an overlay-window symbol the banked "definition" is usually another overlay's function, and the card ranks it ABOVE the destination TU L21158 -- **§201-D** — THE SIGNEDNESS OF A div/mod MAGIC IS DECIDED BY THE STATIC TYPE OF THE DIVIDEND TREE AFTER `get_narrower` STRIPS WIDENING CONVERSIONS — NEVER BY A PROVABLE RANGE. AN `& 0xFF` IS NOT A CONVERSION, SO IT NEVER FLIPS THE MAGIC; A DECLARED-UNSIGNED LOCAL *OR* A NARROWING CAST WRITTEN AT THE DIVIDE BOTH DO. L21321 -- **§202** — THE ALIAS CARRIES A DEFINITION, NOT JUST A DECLARATION: the DEF-SIDE-RETURN wall (P31 S56) L21449 -- **§204-C** — WHEN A LOCAL BUFFER'S ADDRESS IS PASSED TO A CALL, ITS SIZE IS A FACT ABOUT THE CALLEE'S BODY, NOT ABOUT THE CALL SITE: grep the callee's proven definition and count the stores through the pointer parameter before you declare the local L21705 -- **§204-E** — `decl_prior`'s `%hi/%lo` ARM HAS NEVER FIRED: the card's promised GLOBAL-TYPE row is 0 of 1,210 L21838 -- **§208** — TWO NAMED LOCALS FOR ONE RELOADED EXPRESSION BUY TWO ALLOCNOS — the naming granularity owns the REGISTER SPLIT, not just the load count (P31 S58) L22202 -- **§214** — THE BANKED TWIN MAY BE A MACRO, A DELETED `.s`, OR A SEMANTIC INVERSE — six ways a ≥0.9 similarity lies (P31 S58) L22514 -- **§216** — DISTINCT ADJACENT SCALARS vs ONE ARRAY: one `lui` per access is the tell, and the array decl is UNUSABLE (P31 S58) L22616 -- **§220** — THE PARAMETER ITSELF IS A REGALLOC DIAL: use it directly, prefer `s32` to `void*`, and place the save-copy AFTER the first call (P31 S58) L22738 -- **§224** — CROSS-JUMP: WRITE THE DUPLICATE, AND READ A SHARED DELAY SLOT AS THE MERGE SIGNATURE (P31 S58) L22898 -- **§236** — THE DECLARATION LAYER IS THE DOMINANT BANK-BLOCKER: NINE WAYS A BYTE-PERFECT BODY FAILS THE GATE (P31 S58b) L23386 -- **§243** — SPELL THE CSE BARRIER AS A REASSIGNED POINTER; AND THE `nop`-AFTER-EVERY-`lh` SIGNATURE (P31 S58b) L23680 -- **§250** — `%hi/%lo` vs `lw`: THE EXTERN'S ARRAY-vs-SCALAR SHAPE DECIDES ADDRESS MATERIALISATION (P31 S58b) L23932 -- **§214** — addendum (P31 S58b) — FOUR MORE WAYS A HIGH-SIMILARITY TWIN LIES L24347 -- **§226** — addendum (P31 S58b) — THE FRAME CATALOGUE: SEVEN MORE LEVERS, AND SLOT ORDER IS DECLARATION ORDER L24576 -- **§263** — A STOLEN DELAY SLOT WHOSE INSTRUCTION IS AN ARG-REGISTER COPY IS AN ARITY ERROR, NOT A SCHEDULE (P31 S59, byte-proven) L24886 -- **ADD-10** — → §237 addendum (arity-evidence paragraph) — AN `la` PAIR ABOVE THE PROLOGUE `sw $ra` IS AN OUTGOING-ARGUMENT MATERIALISATION L25184 -- **ADD-2** — → §236 addendum (item 1 corollary) — THE SILENT-SPLICE DECLARATION LADDER: WHERE THE TU HAS NO SPELLING, UNPROTOTYPED `()` BEATS THE FLEET VOTE L25326 -- **§272** — The `(void)`-decl + empty-call wall: K&R the DEFINITION, not just the decls (P31 S59) L25558 -- **ADDENDUM** — to §20 — a global declared as `T *` may itself BE the array base, not a pointer to dereference L25779 -- **ADDENDUM** — to §172b-1 — TWO PLACEMENT DIALS THE PROMOTION LAW DOESN'T NAME: NARROW THE COUNTER'S DECLARED TYPE, AND MOVE THE CAST INTO THE LOOP BODY L26059 -- **§280** — THE CURSOR'S DECLARED TYPE PICKS `sltu` vs `slt`: a `T*` bound test is UNSIGNED by C rule, an integer cursor is signed (P31 S60; wave cf, func_800CAE74, md_MAIN_031, byte-proven) L26915 -- **ADDENDUM** — to §202 — the DEF-SIDE ALIAS also resolves a function-vs-DATA-symbol identifier clash, not only a function-vs-function prototype clash L27162 -- **ADDENDUM** — §NNN — sharpens §37/§124 (unspecified-parameter-list family): DERIVE A CALLEE'S ARITY LOWER BOUND FROM ITS OWN `.s` STACK-ARGUMENT READS, NOT FROM ANY SINGLE CALL SITE L28285 -- **§288** — A REGISTER PIN DECLARED UNINITIALIZED AND ASSIGNED ONLY AT ITS LATE, SOLE USE STILL FORCES THE FIXED REGISTER'S SAVE/RESTORE, AND THE ASSIGNMENT'S SOURCE POSITION CONTROLS WHERE THE VALUE MATERIALIZES (P31; `func_80186530`, ov_SC02_017, byte-proven, match_one MATCH re-verified) (P31 S60; waves #, byte-proven) L29049 -- **§292** — DECLARING A SYMBOL UPSTREAM OF AN ALREADY-BANKED SIBLING THAT RELIES ON THAT SYMBOL'S IMPLICIT (K&R) DECLARATION CAN SILENTLY REPROTOTYPE THE SIBLING'S OWN CALL SITE (P31 S60; waves #, byte-proven) L29065 +- **§41b** — addendum — M4 "reconcile_decls" tier is ALSO a probe over-count: 0/8 mechanical (Phase 25 T7-M4, 2026-07-10) L2873 +- **§41d** — `void`→`s32` is NOT always byte-neutral: gate the RAW draft FIRST (Phase 26 session 6, byte-proven) L2893 +- **§43** — The K&R s16-param definition DISSOLVES the "narrow-param wall" for by-value register args (Phase 25 task A, Fable5 crack of the 369-ins giant `func_80166994` ×134, 2026-07-11) L3210 +- **§51g** — When the thing you are scanning has a GRAMMAR, parse the grammar (`tools/cdecl.py`) L3784 +- **§54** — `--fix-def-sig`: the member's CANONICAL DECLARATION is a build step too (tiny-IMM mega-pools, +4,801, Phase 29 T6, 2026-07-16) L4178 +- **§56** — Banking a hand-drafted GIANT into its exemplar TU: self-contained draft vs live-TU decls, 4 reconciliation tactics (`func_8013FAF8`, 312 ins ×138, Phase 29 T4, 2026-07-17) L4202 +- **§56b** — PROPAGATING an h_seq giant: the exemplar's externs MUST be fleet-canonical, not the draft's types L4247 +- **§57** — The SELF-decl normalize: the sibling's OWN caller declares the templated fn divergently (the third §17a-1 direction; `tools/normalize_self_decls.py`, func_801670E4 ×137, Phase 29, 2026-07-18) L4271 +- **§61** — Task 14: the gate ladder's missing stage is the ARITY pre-pass, and it is TU-side not draft-side (Phase 29, 2026-07-21) L4560 +- **§63** — The fresh-138 DEF-SIDE blocker: fix the HEADER decl, not the draft (`fix_header_decl.py`, Phase 29 SESSION-13, 2026-07-23) L4892 +- **§63** — UPDATE (Phase 29 SESSION-14) — `fix_header_decl`'s "SAFE" verdict is FLEET-BLIND; it MUST be R22-validated L5015 +- **§65c** — `rtu_match` MATCH → bank held 13/13 on self-decl, but broke on the FIRST callee-decl case L5096 +- **§65g** — Where the cheap levers STOP: the local-type and in-TU-self-decl classes did not yield L5154 +- **§66a** — The widest write in a pipeline is the one most likely to be UNDECLARED L5196 +- **§68** — A comment-only line halted the extern scan, and the skip label blamed the type cap (Phase 29 SESSION-18) L5539 +- **§73** — A def-side self-decl conflict has TWO axes: RETURN (fleet widen, T2) and PARAMS (casts at each use, T0). Diagnose which before paying for the expensive one (Phase 29 SESSION-19, `func_8014F3E8` + `func_8014D4C0`) L5798 +- **§75** — A propagation cap is usually a MINORITY-SPELLING SOURCE OVERLAY, not a wall: census the carried extern before believing the exclusion message (Phase 29 SESSION-19, `func_8014F3E8` ×4 → ×138) L5881 +- **§75b** — A body's preamble can carry `#define`s, not just `extern`s; extraction lifts only the externs (Phase 29 SESSION-19, `func_80165CA0` ×3 → fleet) L5963 +- **§75c** — Class-B's remedy is the FULL §17a-1 PAIR (decl **and** call-site cast); a decl-only fix moves the error and looks like a new wall (Phase 29 SESSION-19, `func_8012F14C`) L6012 +- **§76** — The allocno CLASS (local vs global) is the dominant regalloc lever, and C reaches it ONLY through declaration scope and variable reuse (Phase 29 SESSION-19, behemoth #3 `func_8017F510` 1,511 ins, 97 → MATCH, pin-free) L6043 +- **§79** — For a 0-callee giant, fingerprint by DATA symbols (§71 cannot fire); and the STACK-SLOT ORDER is a declaration-order oracle (Phase 29 SESSION-19, `func_8017BF14` 4,763 ins, cold start → 45/4763) L6235 +- **§3-NEW** — LEVER — the frame layout reads back the original declaration order L6255 +- **§3-1.** — The inlined-helper signature L6390 +- **§92** — Conforming a DECLARATION: pointer changes are caller-neutral, scalar-WIDTH changes are not (Phase 29 SESSION-21, `tools/conform_decls.py`) L6906 +- **§95** — `reconcile_tu` dropped the SIBLING declarators of a multi-symbol `extern` line (Phase 29 SESSION-21, `func_80176218`) L6998 +- **§96** — The same rewrite, one shape down: `reconcile_tu` matched statements to lines by TEXT, so every COMMENTED declaration was silently skipped (Phase 29 SESSION-22, `func_80176218` banked) L7033 +- **§98** — `conform_decls` had three defects, and only the third needed R22 to find (Phase 29 SESSION-22, `func_8014CF04`) L7128 +- **§99** — The narrow-param wall is a DEF-side problem with a ZERO-blast-radius fix: convert the definition to K&R (Phase 29 SESSION-22, `func_80175AB8` + `func_80175DA8`) L7182 +- **§102** — A PLUMBING verdict can MASK a DIFF; and K&R is not always a codegen change (Phase 29 SESSION-22, `func_8016EC0C`) L7287 +- **§103** — A FILE-scope `extern` in a shared overlay TU is a GLOBAL constraint on every LATER function; move the DECL, not the draft (Phase 29 T48/T51, `func_80135260` — the fleet-wide half) L7322 +- **§104** — Two silent-skip defects in one scan: match on MASKED text, emit from the ORIGINAL (Phase 29 T53, `gather_externs`) L7410 +- **§112** — A macro-scoped declaration only collides where the macro is INSTANTIATED (Phase 29 T67/T69, `audit_header_sigs.py`) L7745 +- **§113** — An ARITY blocker only exists if the macro CALLS the function; an address-taken use has no call site (Phase 29 T72) L7791 +- **§114** — The THIRD decl axis: a CALLEE the draft declares differently from the target TU (Phase 29 T76/T77) L7823 +- **§3-Do** — NOT "strip the duplicate typedef" — it breaks the extern that uses it L8052 +- **§121** — Synthesise externs for macro-DEFINED callees from the macro's own definition head (Phase 29 T95) L8076 +- **§3-The** — declaration surface (integration, not codegen) L8956 +- **§136f** — Two declaration sub-cases the reconcile lane surfaced (lane now 15/15 lifetime) L9201 +- **§138** — The propagation lanes: a gate refusal is a DECLARATION, and which lever you owe depends on blast radius L9430 +- **Reconciling** — a gate-refused draft: which way you edit depends on WHERE the TU's decl is L9580 +- **§141** — The §134 class is CLOSED: every line-shape decision now routes through `cdecl._mask` (P30 S39) L9755 +- **§143** — `cast_call_sites` read a RETURN STATEMENT as a prototype and deleted it. A 0/39 sweep became 18/39. (P30 S40) L9849 +- **§3-C.** — Inner-block declaration does NOT delay slot allocation — BYTE-REFUTED L10083 +- **§159** — THE DECLARATION AXIS: conform to byte-truth, and make every guard state its COVERAGE (P30 S47; ~10,930 sites across 8 axes, fleet byte-identical) L10843 +- **§168** — THE COUSIN TIER (P30 S49, 2026-08-12): h_seq's exact-hash brittleness, measured — and the similarity map above it L16239 +- **§176f** — THE DECLARATION FORM IS A MATCHING LEVER, SO RECONCILE TOWARD THE FORM THE MATCH NEEDS (P31 S52) L16937 +- **§183** — THE DECLARATION-RECONCILIATION PLAYBOOK (P31 S53, measured on 20 byte-verified drafts) L17976 +- **§193-H** — A pointer-derived base load `*(s32*)(p+K)` is uncacheable across ANY memory write or call (cse's third kill disjunct) — so the target emits one `lw` per store-separated RUN of spellings, and a run of stores sharing one `lw` is a C local you must declare L18822 +- **§193-I** — A DECLARED AGGREGATE LOCAL HAS AN 8-BYTE FRAME STRIDE — CEIL(size,8), NOT size. N ARRAYS THEREFORE COST 8·k MORE THAN ONE HAND-LAID STRUCT (k = how many of them have size mod 8 ≠ 0), AND THE TELL IS IDENTICAL INSTRUCTION COUNT WITH EVERY $sp DISPLACEMENT SHIFTED BY THE SAME CONSTANT. L18862 +- **§194-B** — A `addu $rA,$rB,$zero` copy feeding ≥2 `sh` stores is a SECOND, 16-BIT-DECLARED local — the width, not the clamp or the join liveness, is what keeps the copy (and func_80183094's pin + `"memory"` clobber are both provably inert) L19031 +- **§194-D** — Declared width of a computed-value local is a sched1 dial (count-neutral) — a replication + attribution correction of §165-17, NOT a new argument-register law L19132 +- **§195-A** — §167-08's "an $aN READ before the jal is scratch" has a byte-proven FALSE-NEGATIVE class: an argument that DIES at the call is allocated straight into $aN, so its only def is a plain load far above the jal and every intervening use reads $aN — there is no positive tell in either direction, only the two-arity A/B L19738 +- **§195-C** — A call-argument `%hi/%lo` pair sitting at the block head, far above its `jal`, is a load-delay-gap filler chosen by SOURCE STATEMENT ORDER — swap the two independent statements nearest the call; a single-use `void *p = &SYM;` call-arg temp is OUTPUT-inert against it (but NOT expand-stream-inert) L19851 +- **§195-D** — §195 — `masked_diff.mask_for` returns 0 for EVERY `j`/`jal` word, so an internal `j` destination is invisible to match_one, the permuter scorer AND every similarity tier: a control-flow semantic error (which calls execute) surfaces as a 1-instruction residual mislabelled `DELAY-SLOT / profile=schedule`, or as an outright false MATCH L19899 +- **§195-F** — fold-const.c:4825 canonicalises a `?:` whose THEN arm is zero (or constant against a non-constant ELSE) by inverting the condition and swapping the arms — so a ternary's written arm order is byte-inert there, and `c ? 0 : X` is unspellable: it always compiles as `!c ? X : 0` L20025 +- **§195-G** — §NEW — TWO ARMS CALLING THE SAME CALLEE MERGE INTO ONE `jal` UNLESS EACH ARM'S OWN CODE CONSUMES THE RESULT: the C dial that keeps two call sites apart is WHERE the consumer test lives, and the branch SENSE you spell it with is byte-inert (jump.c:1737 canonicalises it) L20077 +- **§195-H** — §165-27g — ON A FIXED-SYMBOL GLOBAL, `extern T D[];` + `D[0]` IS THE CSE RELOAD DIAL, AT ZERO ADDRESSING COST, AND THE ELEMENT COUNT IS INERT (§165-27's `T v[2]` CAVEAT IS A LOCAL-FRAME FACT AND DOES NOT TRANSFER) L20125 +- **§196** — PUT ON THE CARD WHAT THE TREE ALREADY KNOWS: the fleet's declaration consensus (P31 S54) L20527 +- **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` L20875 +- **§199-G** — At TWO case nodes the switch-vs-if oracle is not blind — but the tell is ALL tests positive + a trailing `j default`, NOT the first test's polarity L21048 +- **§200** — THE ALIAS IS THE UNIVERSAL DECLARATION ESCAPE: stop negotiating with the TU's spelling (P31 S55) L21114 +- **§201-A** — §150-B applies to `decl_prior`'s DEF row: for an overlay-window symbol the banked "definition" is usually another overlay's function, and the card ranks it ABOVE the destination TU L21173 +- **§201-D** — THE SIGNEDNESS OF A div/mod MAGIC IS DECIDED BY THE STATIC TYPE OF THE DIVIDEND TREE AFTER `get_narrower` STRIPS WIDENING CONVERSIONS — NEVER BY A PROVABLE RANGE. AN `& 0xFF` IS NOT A CONVERSION, SO IT NEVER FLIPS THE MAGIC; A DECLARED-UNSIGNED LOCAL *OR* A NARROWING CAST WRITTEN AT THE DIVIDE BOTH DO. L21336 +- **§202** — THE ALIAS CARRIES A DEFINITION, NOT JUST A DECLARATION: the DEF-SIDE-RETURN wall (P31 S56) L21464 +- **§204-C** — WHEN A LOCAL BUFFER'S ADDRESS IS PASSED TO A CALL, ITS SIZE IS A FACT ABOUT THE CALLEE'S BODY, NOT ABOUT THE CALL SITE: grep the callee's proven definition and count the stores through the pointer parameter before you declare the local L21720 +- **§204-E** — `decl_prior`'s `%hi/%lo` ARM HAS NEVER FIRED: the card's promised GLOBAL-TYPE row is 0 of 1,210 L21853 +- **§208** — TWO NAMED LOCALS FOR ONE RELOADED EXPRESSION BUY TWO ALLOCNOS — the naming granularity owns the REGISTER SPLIT, not just the load count (P31 S58) L22217 +- **§214** — THE BANKED TWIN MAY BE A MACRO, A DELETED `.s`, OR A SEMANTIC INVERSE — six ways a ≥0.9 similarity lies (P31 S58) L22529 +- **§216** — DISTINCT ADJACENT SCALARS vs ONE ARRAY: one `lui` per access is the tell, and the array decl is UNUSABLE (P31 S58) L22631 +- **§220** — THE PARAMETER ITSELF IS A REGALLOC DIAL: use it directly, prefer `s32` to `void*`, and place the save-copy AFTER the first call (P31 S58) L22753 +- **§224** — CROSS-JUMP: WRITE THE DUPLICATE, AND READ A SHARED DELAY SLOT AS THE MERGE SIGNATURE (P31 S58) L22913 +- **§236** — THE DECLARATION LAYER IS THE DOMINANT BANK-BLOCKER: NINE WAYS A BYTE-PERFECT BODY FAILS THE GATE (P31 S58b) L23401 +- **§243** — SPELL THE CSE BARRIER AS A REASSIGNED POINTER; AND THE `nop`-AFTER-EVERY-`lh` SIGNATURE (P31 S58b) L23695 +- **§250** — `%hi/%lo` vs `lw`: THE EXTERN'S ARRAY-vs-SCALAR SHAPE DECIDES ADDRESS MATERIALISATION (P31 S58b) L23947 +- **§214** — addendum (P31 S58b) — FOUR MORE WAYS A HIGH-SIMILARITY TWIN LIES L24362 +- **§226** — addendum (P31 S58b) — THE FRAME CATALOGUE: SEVEN MORE LEVERS, AND SLOT ORDER IS DECLARATION ORDER L24591 +- **§263** — A STOLEN DELAY SLOT WHOSE INSTRUCTION IS AN ARG-REGISTER COPY IS AN ARITY ERROR, NOT A SCHEDULE (P31 S59, byte-proven) L24901 +- **ADD-10** — → §237 addendum (arity-evidence paragraph) — AN `la` PAIR ABOVE THE PROLOGUE `sw $ra` IS AN OUTGOING-ARGUMENT MATERIALISATION L25199 +- **ADD-2** — → §236 addendum (item 1 corollary) — THE SILENT-SPLICE DECLARATION LADDER: WHERE THE TU HAS NO SPELLING, UNPROTOTYPED `()` BEATS THE FLEET VOTE L25341 +- **§272** — The `(void)`-decl + empty-call wall: K&R the DEFINITION, not just the decls (P31 S59) L25573 +- **ADDENDUM** — to §20 — a global declared as `T *` may itself BE the array base, not a pointer to dereference L25794 +- **ADDENDUM** — to §172b-1 — TWO PLACEMENT DIALS THE PROMOTION LAW DOESN'T NAME: NARROW THE COUNTER'S DECLARED TYPE, AND MOVE THE CAST INTO THE LOOP BODY L26074 +- **§280** — THE CURSOR'S DECLARED TYPE PICKS `sltu` vs `slt`: a `T*` bound test is UNSIGNED by C rule, an integer cursor is signed (P31 S60; wave cf, func_800CAE74, md_MAIN_031, byte-proven) L26930 +- **ADDENDUM** — to §202 — the DEF-SIDE ALIAS also resolves a function-vs-DATA-symbol identifier clash, not only a function-vs-function prototype clash L27177 +- **ADDENDUM** — §NNN — sharpens §37/§124 (unspecified-parameter-list family): DERIVE A CALLEE'S ARITY LOWER BOUND FROM ITS OWN `.s` STACK-ARGUMENT READS, NOT FROM ANY SINGLE CALL SITE L28300 +- **§288** — A REGISTER PIN DECLARED UNINITIALIZED AND ASSIGNED ONLY AT ITS LATE, SOLE USE STILL FORCES THE FIXED REGISTER'S SAVE/RESTORE, AND THE ASSIGNMENT'S SOURCE POSITION CONTROLS WHERE THE VALUE MATERIALIZES (P31; `func_80186530`, ov_SC02_017, byte-proven, match_one MATCH re-verified) (P31 S60; waves #, byte-proven) L29064 +- **§292** — DECLARING A SYMBOL UPSTREAM OF AN ALREADY-BANKED SIBLING THAT RELIES ON THAT SYMBOL'S IMPLICIT (K&R) DECLARATION CAN SILENTLY REPROTOTYPE THE SIBLING'S OWN CALL SITE (P31 S60; waves #, byte-proven) L29080 ### jump tables & switches (46) @@ -585,46 +588,46 @@ - **§8b** — MULTI-jtbl per overlay — the `ld_interleave --order` sandwich + the same-subseg cases (Phase 26 session 4) L404 - **§8e** — The jtbl ALIGNMENT LAW + the pad-spec filter — multi-table .rodata spans (Phase 29, byte-proven; `.run/probe_jtbl/verdict.md`) L530 - **§3-The** — clean object-level metric (use this, not the permuter score, for jtbl/rodata functions) L844 -- **§41b** — T7 execution: the object-only probe OVER-counts BANKABLE by two link/rodata classes (Phase 25 T7-M1, 2026-07-10) L2809 -- **§48** — The 12-core jr crack wave: the ALLOCNO-PRICING dials and the EBB rule (Phase 26 session 8, Ultracode, 9/12 MATCH first pass) L3405 -- **§53** — SWEEP A FAMILY WITH THE TOOL ITS EXEMPLAR NEEDED: the jr/switch carve, and how omitting it manufactured the "families don't template" doctrine (Phase 28 T1, 2026-07-15) L4028 -- **§61b** — The jtbl gate stage: built, and the ORDERING law it exposed (Phase 29 Task-14 stage 4, 2026-07-21) L4658 -- **§61c** — The jtbl bank is INCREMENTALLY valid and CLEAN-INVALID (Phase 29, 2026-07-21) — the blocking finding L4713 -- **§62** — The jtbl RECONCILE must also follow the carve: the post-carve draft reconcile (`harvest_verify._jtbl_reconcile`, Phase 29 SESSION-11, 2026-07-22) L4833 -- **§81** — Banking a jr (jump-table) function: the 3-step carve chain, and why `match_one` cannot see the problem (Phase 29 SESSION-19, `func_8017C954`) L6323 -- **§88d** — BANKING ORDER: run the §81 carve chain BEFORE banking, never after L6701 -- **§97** — The gate's own tree hygiene: a refused carve, an unchecked recovery, and a snapshot that captured a dirty tree (Phase 29 SESSION-22) L7066 -- **§105** — A gate's revert must survive an EXCEPTION, not just a failure (Phase 29 T53, `jtbl_family_bank`) L7431 -- **§125** — Split the CARVE from the BODY before calling a jr residue a wall — and measure it by SHA from a CLEAN tree (P30 SESSION-28; **this section's first draft was WRONG and the method caught it**) L8206 -- **§126** — The carve-within-a-carve: an ADDRESS RANGE is not an OPTIMIZATION REGION (P30 T2, byte-proven end-to-end) L8264 -- **§129** — Post-carve, `rtu_match`/`match_one` COUNT THE JUMP TABLE AS INSTRUCTIONS; and a carve must never be committed without its owner (P30 S28, `func_8013BD74`) L8437 -- **§129a** — the target instruction count is INFLATED after a carve L8441 -- **§129b** — never commit a carve whose owner is still a stub (it strands the carve) L8462 -- **§130** — An INCREMENTAL build can report BYTE-IDENTICAL for a change the CLEAN build cannot even LINK (P30 S28, the jr pair) L8486 -- **§131** — The jtbl OVER-SPAN: `sltiu N` is ground truth in BOTH directions, and the zero-word rule only guards one (P30 S28, `func_80191C50`) L8533 -- **§132** — The `JR-PAIR-IN-ONE-O0-OBJECT` "wall" was TWO instrument defects: a merged-double span the carve could not see, and a truncated object no rule deleted (P30 S29, `func_8013B83C` + `func_8013BD74`) L8570 -- **§132b** — When the span's already-matched owner is ITSELF multi-switch: `--span-rel` (P30 S1, `func_8014032C`) L8660 -- **§139** — A GATE THAT GREPS FOR VERDICTS MUST ASSERT 1:1 ACCOUNTING; and a `--src` filter must not survive a carve (P30 S38, wave 6: 10 of 16 drafts vanished) L9594 -- **§161** — THE RETRY-WAVE HARVEST: a jump table indexed from zero, and two allocator traps (P30 S47) L10969 -- **§179-F** — PINNING A LOOP-WALKED POINTER IS A TOTAL OFF-SWITCH FOR STRENGTH REDUCTION L17532 -- **§188** — 🔴 THE `jr $ra` + `addiu $sp` TAIL IS AN **ASSEMBLER** ARTIFACT, NOT A FRAME SHAPE L18176 -- **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` L20860 -- **§199-G** — At TWO case nodes the switch-vs-if oracle is not blind — but the tell is ALL tests positive + a trailing `j default`, NOT the first test's polarity L21033 -- **§206** — THE JTBL-CARVE DRAFTING IDIOM: the bounds check is the entry count, and an EMPTY case owns a slot (P31 S56) L22112 -- **§222** — SWITCH vs IF-CHAIN, PART 3: source arm order IS emission order, a leading EMPTY case buys the median split, and a 2-way dispatch with a shared post-block is a `switch` (P31 S58) L22794 -- **§232** — WHEN THE `jr` DELAY SLOT'S STORE STORES THE RETURN VALUE, TIE THEM WITH ONE PSEUDO **(single observation — not yet cross-confirmed)** (P31 S58) L23180 -- **§256** — GOTOS IN THE TARGET'S BLOCK ORDER REPRODUCE SWITCH PLACEMENT WITHOUT SWITCH'S SIDE EFFECTS (P31 S58b) L24073 -- **§222** — addendum (P31 S58b) — IF-CHAIN vs SWITCH: THREE MORE DISCRIMINATORS L24477 -- **§260-A** — STAGE 2 IS PROVEN, AND THE WHOLE jtbl PIPELINE IS AUTOMATED AT THE GATE (P31 S59, same day) L24772 -- **ADDENDUM** — to §8 — WHEN `INCLUDE_RODATA` NEEDS A STANDALONE `.s` YOU CAN'T CREATE, CARRY THE FRAGMENT AS A FILE-SCOPE `__asm__` BLOB L26181 -- **ADDENDUM** — §NNN — sharpens §55a / §164-37 / §165-28 (switch-vs-tree cluster): A SHAPE THAT LOOKS LIKE A SWITCH DISPATCH CAN BE PLAIN NESTED `if`s WHOSE SHARED BODY WAS TRIPLICATED BY THE SOURCE AND THEN CROSS-JUMP-MERGED BACK DOWN L28182 -- **ADDENDUM** — §NNN — sharpens §162a3/§60b: A `sll $v0,16 / sltiu $v0,1` ZERO-TEST OF A JUST-DECREMENTED HALFWORD IS A SIGNED-TEMP WIDTH TELL OUTSIDE ANY SWITCH/RANGE-TEST CONTEXT L28252 -- **§295** — THE KERNEL-TRAP STUB: §81's jr-DETECTOR WITHOUT A TABLE IS A PsyQ SYSCALL TRAMPOLINE — ROUTE TO §265, NEVER INTO THE CARVE CHAIN (P31 S61; wave m0a, 9 cards byte-proven; resolves §182's held cluster) L29360 -- **§298** — THE SHARED-TAIL POSITION DIAGNOSTIC: A FOLDED TAIL *BETWEEN* SWITCH ARMS MEANS PER-ARM DUPLICATED STATEMENTS, NOT A HOISTED POST-SWITCH STATEMENT (P31 S61; waves g0e/g0f, `func_80181B68`, ov_SC06_016, byte-proven 68/68) L29501 -- **§302** — A RED BINARY IS A DRIFTED SPEC, NOT A MYSTERY: THE THREE CARVE-STATE INVARIANTS AND HOW TO DERIVE EACH FROM THE BYTES (P31 S62 T2; five reds healed in one session, 5/5, +39 held banks) L29678 -- **§304** — SELF-DEFINING RODATA: WHEN A FUNCTION'S `.s` IS THE ONLY OWNER OF THE DATA IT REFERENCES, THE C BODY MUST DEFINE IT (P31 S62 T3; byte-proven md_MAIN_011/func_800D04F4) L29758 -- **§305** — "CARVE-REFUSED" AT GATE TIME IS THREE NAMED, DETERMINISTIC CLASSES — NONE OF THEM A CARVE (P31 S62 T3; 28 resolver drafts autopsied 28/28) L29781 -- **§308a** — A TWO-INSTRUCTION ARM STUB LAID *BEFORE* THE OTHER ARM AND REACHED ONLY BY A TRAILING `j` SURVIVES ONLY BEHIND A SHORT-CIRCUIT `&&` GUARD PLUS A SEPARATE RE-TEST; EVERY PLAIN if/else-if, GOTO-LADDER, NESTED-INVERTED-if AND 1-/2-NODE switch LETS jump1 INLINE IT (−2 ins) (P31 S63 t5e-t5i; byte-proven func_80180808) L29971 +- **§41b** — T7 execution: the object-only probe OVER-counts BANKABLE by two link/rodata classes (Phase 25 T7-M1, 2026-07-10) L2824 +- **§48** — The 12-core jr crack wave: the ALLOCNO-PRICING dials and the EBB rule (Phase 26 session 8, Ultracode, 9/12 MATCH first pass) L3420 +- **§53** — SWEEP A FAMILY WITH THE TOOL ITS EXEMPLAR NEEDED: the jr/switch carve, and how omitting it manufactured the "families don't template" doctrine (Phase 28 T1, 2026-07-15) L4043 +- **§61b** — The jtbl gate stage: built, and the ORDERING law it exposed (Phase 29 Task-14 stage 4, 2026-07-21) L4673 +- **§61c** — The jtbl bank is INCREMENTALLY valid and CLEAN-INVALID (Phase 29, 2026-07-21) — the blocking finding L4728 +- **§62** — The jtbl RECONCILE must also follow the carve: the post-carve draft reconcile (`harvest_verify._jtbl_reconcile`, Phase 29 SESSION-11, 2026-07-22) L4848 +- **§81** — Banking a jr (jump-table) function: the 3-step carve chain, and why `match_one` cannot see the problem (Phase 29 SESSION-19, `func_8017C954`) L6338 +- **§88d** — BANKING ORDER: run the §81 carve chain BEFORE banking, never after L6716 +- **§97** — The gate's own tree hygiene: a refused carve, an unchecked recovery, and a snapshot that captured a dirty tree (Phase 29 SESSION-22) L7081 +- **§105** — A gate's revert must survive an EXCEPTION, not just a failure (Phase 29 T53, `jtbl_family_bank`) L7446 +- **§125** — Split the CARVE from the BODY before calling a jr residue a wall — and measure it by SHA from a CLEAN tree (P30 SESSION-28; **this section's first draft was WRONG and the method caught it**) L8221 +- **§126** — The carve-within-a-carve: an ADDRESS RANGE is not an OPTIMIZATION REGION (P30 T2, byte-proven end-to-end) L8279 +- **§129** — Post-carve, `rtu_match`/`match_one` COUNT THE JUMP TABLE AS INSTRUCTIONS; and a carve must never be committed without its owner (P30 S28, `func_8013BD74`) L8452 +- **§129a** — the target instruction count is INFLATED after a carve L8456 +- **§129b** — never commit a carve whose owner is still a stub (it strands the carve) L8477 +- **§130** — An INCREMENTAL build can report BYTE-IDENTICAL for a change the CLEAN build cannot even LINK (P30 S28, the jr pair) L8501 +- **§131** — The jtbl OVER-SPAN: `sltiu N` is ground truth in BOTH directions, and the zero-word rule only guards one (P30 S28, `func_80191C50`) L8548 +- **§132** — The `JR-PAIR-IN-ONE-O0-OBJECT` "wall" was TWO instrument defects: a merged-double span the carve could not see, and a truncated object no rule deleted (P30 S29, `func_8013B83C` + `func_8013BD74`) L8585 +- **§132b** — When the span's already-matched owner is ITSELF multi-switch: `--span-rel` (P30 S1, `func_8014032C`) L8675 +- **§139** — A GATE THAT GREPS FOR VERDICTS MUST ASSERT 1:1 ACCOUNTING; and a `--src` filter must not survive a carve (P30 S38, wave 6: 10 of 16 drafts vanished) L9609 +- **§161** — THE RETRY-WAVE HARVEST: a jump table indexed from zero, and two allocator traps (P30 S47) L10984 +- **§179-F** — PINNING A LOOP-WALKED POINTER IS A TOTAL OFF-SWITCH FOR STRENGTH REDUCTION L17547 +- **§188** — 🔴 THE `jr $ra` + `addiu $sp` TAIL IS AN **ASSEMBLER** ARTIFACT, NOT A FRAME SHAPE L18191 +- **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` L20875 +- **§199-G** — At TWO case nodes the switch-vs-if oracle is not blind — but the tell is ALL tests positive + a trailing `j default`, NOT the first test's polarity L21048 +- **§206** — THE JTBL-CARVE DRAFTING IDIOM: the bounds check is the entry count, and an EMPTY case owns a slot (P31 S56) L22127 +- **§222** — SWITCH vs IF-CHAIN, PART 3: source arm order IS emission order, a leading EMPTY case buys the median split, and a 2-way dispatch with a shared post-block is a `switch` (P31 S58) L22809 +- **§232** — WHEN THE `jr` DELAY SLOT'S STORE STORES THE RETURN VALUE, TIE THEM WITH ONE PSEUDO **(single observation — not yet cross-confirmed)** (P31 S58) L23195 +- **§256** — GOTOS IN THE TARGET'S BLOCK ORDER REPRODUCE SWITCH PLACEMENT WITHOUT SWITCH'S SIDE EFFECTS (P31 S58b) L24088 +- **§222** — addendum (P31 S58b) — IF-CHAIN vs SWITCH: THREE MORE DISCRIMINATORS L24492 +- **§260-A** — STAGE 2 IS PROVEN, AND THE WHOLE jtbl PIPELINE IS AUTOMATED AT THE GATE (P31 S59, same day) L24787 +- **ADDENDUM** — to §8 — WHEN `INCLUDE_RODATA` NEEDS A STANDALONE `.s` YOU CAN'T CREATE, CARRY THE FRAGMENT AS A FILE-SCOPE `__asm__` BLOB L26196 +- **ADDENDUM** — §NNN — sharpens §55a / §164-37 / §165-28 (switch-vs-tree cluster): A SHAPE THAT LOOKS LIKE A SWITCH DISPATCH CAN BE PLAIN NESTED `if`s WHOSE SHARED BODY WAS TRIPLICATED BY THE SOURCE AND THEN CROSS-JUMP-MERGED BACK DOWN L28197 +- **ADDENDUM** — §NNN — sharpens §162a3/§60b: A `sll $v0,16 / sltiu $v0,1` ZERO-TEST OF A JUST-DECREMENTED HALFWORD IS A SIGNED-TEMP WIDTH TELL OUTSIDE ANY SWITCH/RANGE-TEST CONTEXT L28267 +- **§295** — THE KERNEL-TRAP STUB: §81's jr-DETECTOR WITHOUT A TABLE IS A PsyQ SYSCALL TRAMPOLINE — ROUTE TO §265, NEVER INTO THE CARVE CHAIN (P31 S61; wave m0a, 9 cards byte-proven; resolves §182's held cluster) L29375 +- **§298** — THE SHARED-TAIL POSITION DIAGNOSTIC: A FOLDED TAIL *BETWEEN* SWITCH ARMS MEANS PER-ARM DUPLICATED STATEMENTS, NOT A HOISTED POST-SWITCH STATEMENT (P31 S61; waves g0e/g0f, `func_80181B68`, ov_SC06_016, byte-proven 68/68) L29516 +- **§302** — A RED BINARY IS A DRIFTED SPEC, NOT A MYSTERY: THE THREE CARVE-STATE INVARIANTS AND HOW TO DERIVE EACH FROM THE BYTES (P31 S62 T2; five reds healed in one session, 5/5, +39 held banks) L29693 +- **§304** — SELF-DEFINING RODATA: WHEN A FUNCTION'S `.s` IS THE ONLY OWNER OF THE DATA IT REFERENCES, THE C BODY MUST DEFINE IT (P31 S62 T3; byte-proven md_MAIN_011/func_800D04F4) L29773 +- **§305** — "CARVE-REFUSED" AT GATE TIME IS THREE NAMED, DETERMINISTIC CLASSES — NONE OF THEM A CARVE (P31 S62 T3; 28 resolver drafts autopsied 28/28) L29796 +- **§308a** — A TWO-INSTRUCTION ARM STUB LAID *BEFORE* THE OTHER ARM AND REACHED ONLY BY A TRAILING `j` SURVIVES ONLY BEHIND A SHORT-CIRCUIT `&&` GUARD PLUS A SEPARATE RE-TEST; EVERY PLAIN if/else-if, GOTO-LADDER, NESTED-INVERTED-if AND 1-/2-NODE switch LETS jump1 INLINE IT (−2 ins) (P31 S63 t5e-t5i; byte-proven func_80180808) L29986 ### optimisation level (-O0/-O2) (18) @@ -634,18 +637,18 @@ - **§18** — Per-file `-O0` split inside an overlay/blob (Phase 19 T1) L1519 - **§38** — The WHALE `func_80144B9C` (770 ins): the -O0 struct-assign memcpy idiom + the -O0 reach-134 ×134 rollout (Phase 24 T7 §G, cheap Opus — no Fable5, no calls.c) L2527 - **§39** — The ×1→×134 giant-endgame: propagate a matched **-O2** giant via the NATIVE DEFINE-macro path (Phase 24 T7 §G close, 2026-07-08) L2537 -- **§116** — Optimization level is a property of the FILE, not the function: read a family 0/N against the member's stub HOME (Phase 29 T79) L7877 -- **§3-The** — finding: opt level is per FILE, so the file's contents must be opt-HOMOGENEOUS L8279 -- **§127** — The `-O0` regime: the CONSTANT-OFFSET FOLD, and why `-O0` needs its own idiom set (P30 T3 wave, 15 targets) L8349 -- **§3-The** — rest of the `-O0` regime (write PLAIN C, and mean it) L8367 -- **§127a** — §71 (sibling-first) is the strongest `-O0` lever, and it beats the index L8377 -- **§132** — The `JR-PAIR-IN-ONE-O0-OBJECT` "wall" was TWO instrument defects: a merged-double span the carve could not see, and a truncated object no rule deleted (P30 S29, `func_8013B83C` + `func_8013BD74`) L8570 -- **§195-K** — At -O2 the §18 array-of-struct lever is a FRAME lever, not a length lever — but only when the N reads carry DISTINCT index expressions; with a SHARED index §18's +2-instruction residual is still alive at -O2 (the submitted "memory-loaded narrow index" precondition and unconditional length-neutrality are both falsified) L20266 -- **§261** — THE -O0 ORACLE: DERIVE THE OPT LEVEL FROM THE TARGET, AND `$fp` IS NOT THE TELL (P31 S59) L24808 -- **§261a** — THE -O0 FRAME-RELOAD GRAMMAR: reload COUNT disambiguates the C spelling (P31 S59, byte-proven) L24834 -- **§265** — THE VERBATIM-ASM BANK LANE: A FUNCTION NO -O2 C CAN EVER MATCH BANKS AS A RAW `__asm__` BODY (P31 S59b; two banked cards, two in-tree precedents) L24977 -- **ADDENDUM** — to §127 — the -O0 constant-offset fold keys on the MEMBER-ACCESS tree shape, not on the index being constant L29129 -- **ADDENDUM** — to §261a — FOUR MORE -O0 DIALS BEYOND THE RELOAD COUNT (boot.c + md_MAIN_011/003, wave m0a/g0a/g0f, byte-proven) L29157 +- **§116** — Optimization level is a property of the FILE, not the function: read a family 0/N against the member's stub HOME (Phase 29 T79) L7892 +- **§3-The** — finding: opt level is per FILE, so the file's contents must be opt-HOMOGENEOUS L8294 +- **§127** — The `-O0` regime: the CONSTANT-OFFSET FOLD, and why `-O0` needs its own idiom set (P30 T3 wave, 15 targets) L8364 +- **§3-The** — rest of the `-O0` regime (write PLAIN C, and mean it) L8382 +- **§127a** — §71 (sibling-first) is the strongest `-O0` lever, and it beats the index L8392 +- **§132** — The `JR-PAIR-IN-ONE-O0-OBJECT` "wall" was TWO instrument defects: a merged-double span the carve could not see, and a truncated object no rule deleted (P30 S29, `func_8013B83C` + `func_8013BD74`) L8585 +- **§195-K** — At -O2 the §18 array-of-struct lever is a FRAME lever, not a length lever — but only when the N reads carry DISTINCT index expressions; with a SHARED index §18's +2-instruction residual is still alive at -O2 (the submitted "memory-loaded narrow index" precondition and unconditional length-neutrality are both falsified) L20281 +- **§261** — THE -O0 ORACLE: DERIVE THE OPT LEVEL FROM THE TARGET, AND `$fp` IS NOT THE TELL (P31 S59) L24823 +- **§261a** — THE -O0 FRAME-RELOAD GRAMMAR: reload COUNT disambiguates the C spelling (P31 S59, byte-proven) L24849 +- **§265** — THE VERBATIM-ASM BANK LANE: A FUNCTION NO -O2 C CAN EVER MATCH BANKS AS A RAW `__asm__` BODY (P31 S59b; two banked cards, two in-tree precedents) L24992 +- **ADDENDUM** — to §127 — the -O0 constant-offset fold keys on the MEMBER-ACCESS tree shape, not on the index being constant L29144 +- **ADDENDUM** — to §261a — FOUR MORE -O0 DIALS BEYOND THE RELOAD COUNT (boot.c + md_MAIN_011/003, wave m0a/g0a/g0f, byte-proven) L29172 ### family propagation & sweeps (109) @@ -672,92 +675,92 @@ - **§40a** — The DECL-RECONCILE pass (type-lift so remapped drafts compile in the sibling TU) (Phase 25 T7.2, 2026-07-08) L2601 - **§40b** — The reloc-tracker blind spot: the indexed-global idiom that hid the "reach-1 tail" (Phase 26 Task 1, 2026-07-11, byte-verified V0/V1) L2634 - **§40c** — The h_seq per-sibling reconcile: templating a reconcile-class crack ×134 (Phase 26 Task 8, 2026-07-12, byte-proven) L2676 -- **§41c** — T7-M2: the ×134 def-side-wall sweep via per-sibling RE-reconcile (Phase 25, 2026-07-10; 4,389 banks, ~0 agent tokens) L2839 -- **§42** — The F-band ≤28 regalloc crack wave: register-pin/DENSITY levers beat the permuter (Phase 25 T7 F-band, 2026-07-10; Ultracode 9-worker wave, 4/9 banked byte-identical, 266 swept ×134) L2900 -- **§42e** — propagating a CRACK ×134: the def-finder bug + the byte-drift residual (the "remap-fail" misdiagnosis) L3121 -- **§43** — The K&R s16-param definition DISSOLVES the "narrow-param wall" for by-value register args (Phase 25 task A, Fable5 crack of the 369-ins giant `func_80166994` ×134, 2026-07-11) L3195 -- **§45** — The flagship `func_80133CD4` crack (399 ins ×134): the merged-variable permutation-breaker + the 1-death local-alloc gate (Phase 25 task A giant escalation, Fable5 gdb-on-cc1, 2026-07-11) L3298 -- **§46** — The `func_80178D40` crack (890 ins ×134, the heaviest core in the game): four LOOP-STRUCTURE levers cheap-Opus found by reading loop.c/jump.c/cse.c (Phase 26 session 8, 2026-07-13) L3313 -- **§47** — The live-length SLIDER: splitting a global.c allocno-priority TIE with one zero-byte asm (Phase 26 session 8, Fable5 Max, byte-proven on `func_8017BEBC` 952 ins ×113) L3365 -- **§49** — The LUID DIAL: a zero-byte SCHEDULING dial (the sched.c analogue of §47) — `func_8017A4AC` (536 ins ×134), Phase 26 session 8 L3527 -- **§52** — The WALKER-FAMILY skeleton: 6 regalloc-order levers + a deeply-characterized intrinsic wall (`func_80178004`, 165 ins ×134; Phase 26, Fable5, 2026-07-15) L3913 -- **§3-The** — 6 levers (the "walker-family skeleton" — apply to the 12 siblings; levers 1-5 retire ~half the residual) L3924 -- **§53** — SWEEP A FAMILY WITH THE TOOL ITS EXEMPLAR NEEDED: the jr/switch carve, and how omitting it manufactured the "families don't template" doctrine (Phase 28 T1, 2026-07-15) L4028 -- **§55c** — Sizing the propagate: a TARGETED propagate is ~4 min/core, and "it's slow" was a BROKEN-TREE ARTIFACT L4141 -- **§54** — `--fix-def-sig`: the member's CANONICAL DECLARATION is a build step too (tiny-IMM mega-pools, +4,801, Phase 29 T6, 2026-07-16) L4163 -- **§56** — Banking a hand-drafted GIANT into its exemplar TU: self-contained draft vs live-TU decls, 4 reconciliation tactics (`func_8013FAF8`, 312 ins ×138, Phase 29 T4, 2026-07-17) L4187 -- **§56b** — PROPAGATING an h_seq giant: the exemplar's externs MUST be fleet-canonical, not the draft's types L4232 -- **§57** — The SELF-decl normalize: the sibling's OWN caller declares the templated fn divergently (the third §17a-1 direction; `tools/normalize_self_decls.py`, func_801670E4 ×137, Phase 29, 2026-07-18) L4256 -- **§57a** — Two NSD corrections + the SURGICAL-ONLY law + the honest broad-sweep yield (Phase 29, 2026-07-18) L4303 -- **§59** — Three h_seq sweep-residual classes match_one/the-exemplar-bank don't reveal (Phase 29 crack-wave close, 2026-07-18) L4377 -- **§3-Two** — corollaries worth remembering L4450 -- **§65a** — The blast-radius taxonomy (makes §61's law structural instead of remembered) L5030 -- **§3-Giv** — record order (the §70 family) L5760 -- **§75** — A propagation cap is usually a MINORITY-SPELLING SOURCE OVERLAY, not a wall: census the carried extern before believing the exclusion message (Phase 29 SESSION-19, `func_8014F3E8` ×4 → ×138) L5866 -- **§75a** — The exclusion classes, enumerated with named causes (Phase 29 SESSION-19, the 134-binary `dedup_extend` sweep) L5925 -- **§75b** — A body's preamble can carry `#define`s, not just `extern`s; extraction lifts only the externs (Phase 29 SESSION-19, `func_80165CA0` ×3 → fleet) L5948 -- **§76** — The allocno CLASS (local vs global) is the dominant regalloc lever, and C reaches it ONLY through declaration scope and variable reuse (Phase 29 SESSION-19, behemoth #3 `func_8017F510` 1,511 ins, 97 → MATCH, pin-free) L6028 -- **§77** — Every extraction tool carries a NARROW hard-coded preamble set; anything outside it silently caps the body's reach. Diff the preamble before you gate. (Phase 29 SESSION-19 — three variants in one session, two different tools) L6084 -- **§84** — The DERIVED-OFFSET remap bug: a hand-computed literal that encodes the DISTANCE between two per-overlay symbols, and why `match_one` is structurally blind to it (Phase 29 SESSION-20, `func_8013D53C`) L6472 -- **§86** — Pinned-exemplar templatability is a PER-FAMILY property, not a per-member rate; and the §42e pin guard is now over-conservative (Phase 29 SESSION-20) L6589 -- **§3-THE** — LAW: all-or-nothing PER FAMILY L6600 -- **§3-Why** — the two live families differ from the three dead ones — the open question L6627 -- **§3-The** — cheap discriminator, before spending a sweep L6666 -- **§89b** — the parallel gate farm existed; the family path could not reach it (`tools/sweep_parallel.py`) L6745 -- **§91** — A structure-TRANSFER is only valid where the structure corresponds: the `--like` role trap (Phase 29 SESSION-21, `func_8012AAAC` ×137) L6842 -- **§94** — A family sweep's `0/N` is a TYPE-CARRY failure until proven otherwise: lift the exemplar's local types, ALL of them, transitively (Phase 29 SESSION-21, `func_8016B6BC` 0/137 → 137/137) L6947 -- **§105** — A gate's revert must survive an EXCEPTION, not just a failure (Phase 29 T53, `jtbl_family_bank`) L7431 -- **§107** — A lever wired into ONE gate path is a lever most families cannot reach (Phase 29 T56, `func_80144090` 0/136 → 136/136) L7513 -- **§108** — Diagnosing a family `0/N`: the four causes, and the third opt-in lever (Phase 29 T59) L7551 -- **§111** — The distinct-code metric is not noisy: a family pays it only if its members are byte-VARIANT (Phase 29 T66) L7681 -- **§116** — Optimization level is a property of the FILE, not the function: read a family 0/N against the member's stub HOME (Phase 29 T79) L7877 -- **§123** — PROPAGATE A FAMILY WITH THE TOOL ITS TIER NEEDS: `dedup_propagate` is h_exact-only; its refusals are statements about the TOOL (P30 wave 1, 2026-07-30) L8116 -- **§124** — A "not matched" verdict can mean the definition is there under a DIFFERENT C NAME: the asm-label alias blind spot (P30 SESSION-28, `func_8016191C` ×137) L8153 -- **§124a** — a family sweep's `0 matched-exemplar families` may be a FILTER, not a wall L8198 -- **§134** — MULTI-LINE BLINDNESS: one root cause, four faces, in `family_remap`'s preamble scanner (P30 S6, 190 zero-crack families) L8711 -- **§136c** — SIBLING-FIRST is a DERIVATION shortcut, not just a conflict fix (the fastest route in a family wave) L9069 -- **§138** — The propagation lanes: a gate refusal is a DECLARATION, and which lever you owe depends on blast radius L9415 -- **§142** — An open stub whose `h_exact` class is MATCHED elsewhere is FREE. Propagate the body; do not gate a draft. (P30 S39, +7,710 ins in two commands) L9778 -- **§143** — `cast_call_sites` read a RETURN STATEMENT as a prototype and deleted it. A 0/39 sweep became 18/39. (P30 S40) L9834 -- **Then** — propagation returned 0/137 TWICE — both times a missing TYPE L10000 -- **§3-A.** — The frame has THREE strata, and stratum 3 is unreachable from C L10041 -- **§3-E.** — A `qty_compare` TIE is not spelling-reachable — recognise it and stop L10083 -- **Consequence** — for the family (a real scheduling decision) L10095 -- **§150** — A register ROTATION across symmetric blocks is VARIABLE-IDENTITY evidence, not an allocator tie (P30 S43, `func_8017C6F4`, 947 ins ×4) L10312 -- **§151** — THE GHOST WEDGE: when a load-before-store transposition is unreachable by ANY statement order (P30 S43, `func_8017EF68`, 969 ins) L10367 -- **When** — to reach for it L10407 -- **§152** — BYTE SIZE is the family key that name- and h_seq-grouping both miss (P30 S43, the 0xECC family: 1 crack → 12 overlays → 11,364 ins) L10418 -- **§156** — an ORPHANED reconcile poisons the fleet: `dedup_propagate`'s kept edit (S45 p6/p7) L10640 -- **§160** — THE REACH-15 WAVE HARVEST: an align-1 block move, and the instrument that called it a wall (P30 S47) L10893 -- **§162** — S48 WAVE-1 HARVEST (P30, 2026-08-11): the reach-ordered sibling campaign's first 12 targets L11014 -- **§163z** — THE UNVETTED REMAINDER (do not cite as law; each needs a dedupe pass) L11828 -- **§3-The** — ADDRESS-CLASS TABLE: which load/store pairs even REACH the `/s` clause (P30 S48 wave 4, `func_80185B44`, ov_SC03_014) L14355 -- **§168** — THE COUSIN TIER (P30 S49, 2026-08-12): h_seq's exact-hash brittleness, measured — and the similarity map above it L16224 -- **§171a** — THE MECHANICAL A-PROP DRAFT (P30 S50): 256 members banked with no agent in the loop L16433 -- **§171b** — THREE CARRIES THE MECHANICAL DRAFT NEEDS (P30 S50, banking the top-reach families) L16483 -- **§3-G.** — TWO MODELLING TRAPS THAT COST THESE AGENTS SWEEPS OF HUNDREDS OF COMPILES L17310 -- **§193-E** — A varying-address (pointer) load is re-emitted once per CSE-LIVE INTERVAL, and naming it in a C local is the only C-level lever over that count — no store SPELLING has any reach L18652 -- **§194-E** — The wave card's `exemplar` is the TARGET ITSELF on 42/73 wave-U and 36/71 wave-T cards — a construction consequence of `atlas.py:657` (exemplar = max-nins OPEN member) meeting `build_wave_atlas.py:166` (one card per gid); and the shipped §193-A `seed_ref` is same-binary on 0/51, so no card field can ever name a destination-TU sibling L19158 -- **§195-E** — A 0/1 materialised at a JOIN immediately before the controlling `beqz`/`bnez` proves the source NAMED the condition — a truth expression in an `if`'s controlling position reaches `do_jump`, which has no value path L19952 -- **§199-B** — A permutation sweep that holds ANY statement fixed is not a sweep: the statement an agent pins as "obviously load-bearing" is the one carrying the signal, and the partial sweep returns a FLAT residual that reads as proof of order-invariance L20767 -- **§203** — A DEDUPED TYPEDEF MUST PRECEDE EVERY SPLICE POINT, NOT JUST ITS OWN (P31 S56) L21486 -- **§225** — THREE CONTROL-FLOW SHAPES NO STRUCTURED SPELLING REACHES (P31 S58) L22934 -- **§30** — addendum (P31 S58b) — THE ANONYMOUS STRUCT MEMBER REF GRANTS `/s`, AND THAT IS A TWO-FOR-ONE L24158 -- **§3-1a.** — The §266 sweep — every solo-lever A/B run for this batch L25485 -- **ADDENDUM** — to §179-D (GTE macro reference family) — `gte_SetRotMatrix`/`gte_SetTransMatrix` bodies L25676 -- **ADDENDUM** — to §82 — struct copies must stay MEMBER-WISE, not block-moved, to match a spill-slot save L25702 -- **ADDENDUM** — to §136d-1 (RC-12, the `$0`-add / opaque-copy family) — two symptoms beyond "compare reads the wrong register" L25740 -- **§282** — gcc's OWN LOOP REVERSAL PUTS THE COUNTER INIT AFTER THE HOISTED MOVABLES — a position no hand-written down-count can reach (P31 S60; wave cf, func_80180DD8, ov_SC04_005, byte-proven) L26995 -- **ADDENDUM** — to the zero-byte-asm-slider family (§47 / §148-C / §153) (func_800CB874, md_MAIN_040 — wave dj; open tension with a more cautious dm-wave card — see closing) L27914 -- **ADDENDUM** — the zero-emission-asm family gains a REF-SLIDER PLACEMENT LAW and a paired RESTORER (func_800CB900, md_MAIN_026) L28124 -- **ADDENDUM** — §NNN — sharpens §37/§124 (unspecified-parameter-list family): DERIVE A CALLEE'S ARITY LOWER BOUND FROM ITS OWN `.s` STACK-ARGUMENT READS, NOT FROM ANY SINGLE CALL SITE L28285 -- **ADDENDUM** — to §199-F family (func_8017EFB0, ov_SC02_021, wave cu) L28437 -- **§287** — A STACK-FRAME HOLE BELOW TWO ADDRESS-TAKEN AGGREGATE LOCALS IS A LEADING PAD MEMBER OF ONE COMBINED STRUCT, NOT SEPARATE LOCALS OR A REGISTER PIN (P31 S60/dj; `func_8017D104`, ov_SC06_027, byte-proven 47/47) (P31 S60; waves #, byte-proven) L29045 -- **ADDENDUM** — to §127 — the -O0 constant-offset fold keys on the MEMBER-ACCESS tree shape, not on the index being constant L29129 -- **§296** — THE FRAME CHECK OUTRANKS THE ATLAS LEVER: READ PROLOGUE/EPILOGUE BEFORE DRAFTING ANY C — A REAL TELL CAN LIVE INSIDE AN UNREACHABLE FRAGMENT (P31 S61; wave m0a, 16 cards byte-proven; extends §179-C) L29415 -- **§297** — ONE GIV SERVING MIXED-WIDTH LOADS *AND* A STORE NEEDS STRUCT-MEMBER SPELLING; CAST/INDEX SPELLINGS RE-SPLIT THE PSEUDO (P31 S61; wave m0a, `func_800347C8`, main, byte-proven 31/31) L29458 -- **§307** — THE BRUTE-FORCE-THE-STATEMENT-ORDERS LEVER HAS A BOUND: A FAN-OUT COPY'S PRIORITY IS SCHEDULER-INTERNAL, AND NO SOURCE ORDER REACHES IT (P31 S63; byte-evidenced NEGATIVE result, main wave) L29898 -- **§308a** — A TWO-INSTRUCTION ARM STUB LAID *BEFORE* THE OTHER ARM AND REACHED ONLY BY A TRAILING `j` SURVIVES ONLY BEHIND A SHORT-CIRCUIT `&&` GUARD PLUS A SEPARATE RE-TEST; EVERY PLAIN if/else-if, GOTO-LADDER, NESTED-INVERTED-if AND 1-/2-NODE switch LETS jump1 INLINE IT (−2 ins) (P31 S63 t5e-t5i; byte-proven func_80180808) L29971 +- **§41c** — T7-M2: the ×134 def-side-wall sweep via per-sibling RE-reconcile (Phase 25, 2026-07-10; 4,389 banks, ~0 agent tokens) L2854 +- **§42** — The F-band ≤28 regalloc crack wave: register-pin/DENSITY levers beat the permuter (Phase 25 T7 F-band, 2026-07-10; Ultracode 9-worker wave, 4/9 banked byte-identical, 266 swept ×134) L2915 +- **§42e** — propagating a CRACK ×134: the def-finder bug + the byte-drift residual (the "remap-fail" misdiagnosis) L3136 +- **§43** — The K&R s16-param definition DISSOLVES the "narrow-param wall" for by-value register args (Phase 25 task A, Fable5 crack of the 369-ins giant `func_80166994` ×134, 2026-07-11) L3210 +- **§45** — The flagship `func_80133CD4` crack (399 ins ×134): the merged-variable permutation-breaker + the 1-death local-alloc gate (Phase 25 task A giant escalation, Fable5 gdb-on-cc1, 2026-07-11) L3313 +- **§46** — The `func_80178D40` crack (890 ins ×134, the heaviest core in the game): four LOOP-STRUCTURE levers cheap-Opus found by reading loop.c/jump.c/cse.c (Phase 26 session 8, 2026-07-13) L3328 +- **§47** — The live-length SLIDER: splitting a global.c allocno-priority TIE with one zero-byte asm (Phase 26 session 8, Fable5 Max, byte-proven on `func_8017BEBC` 952 ins ×113) L3380 +- **§49** — The LUID DIAL: a zero-byte SCHEDULING dial (the sched.c analogue of §47) — `func_8017A4AC` (536 ins ×134), Phase 26 session 8 L3542 +- **§52** — The WALKER-FAMILY skeleton: 6 regalloc-order levers + a deeply-characterized intrinsic wall (`func_80178004`, 165 ins ×134; Phase 26, Fable5, 2026-07-15) L3928 +- **§3-The** — 6 levers (the "walker-family skeleton" — apply to the 12 siblings; levers 1-5 retire ~half the residual) L3939 +- **§53** — SWEEP A FAMILY WITH THE TOOL ITS EXEMPLAR NEEDED: the jr/switch carve, and how omitting it manufactured the "families don't template" doctrine (Phase 28 T1, 2026-07-15) L4043 +- **§55c** — Sizing the propagate: a TARGETED propagate is ~4 min/core, and "it's slow" was a BROKEN-TREE ARTIFACT L4156 +- **§54** — `--fix-def-sig`: the member's CANONICAL DECLARATION is a build step too (tiny-IMM mega-pools, +4,801, Phase 29 T6, 2026-07-16) L4178 +- **§56** — Banking a hand-drafted GIANT into its exemplar TU: self-contained draft vs live-TU decls, 4 reconciliation tactics (`func_8013FAF8`, 312 ins ×138, Phase 29 T4, 2026-07-17) L4202 +- **§56b** — PROPAGATING an h_seq giant: the exemplar's externs MUST be fleet-canonical, not the draft's types L4247 +- **§57** — The SELF-decl normalize: the sibling's OWN caller declares the templated fn divergently (the third §17a-1 direction; `tools/normalize_self_decls.py`, func_801670E4 ×137, Phase 29, 2026-07-18) L4271 +- **§57a** — Two NSD corrections + the SURGICAL-ONLY law + the honest broad-sweep yield (Phase 29, 2026-07-18) L4318 +- **§59** — Three h_seq sweep-residual classes match_one/the-exemplar-bank don't reveal (Phase 29 crack-wave close, 2026-07-18) L4392 +- **§3-Two** — corollaries worth remembering L4465 +- **§65a** — The blast-radius taxonomy (makes §61's law structural instead of remembered) L5045 +- **§3-Giv** — record order (the §70 family) L5775 +- **§75** — A propagation cap is usually a MINORITY-SPELLING SOURCE OVERLAY, not a wall: census the carried extern before believing the exclusion message (Phase 29 SESSION-19, `func_8014F3E8` ×4 → ×138) L5881 +- **§75a** — The exclusion classes, enumerated with named causes (Phase 29 SESSION-19, the 134-binary `dedup_extend` sweep) L5940 +- **§75b** — A body's preamble can carry `#define`s, not just `extern`s; extraction lifts only the externs (Phase 29 SESSION-19, `func_80165CA0` ×3 → fleet) L5963 +- **§76** — The allocno CLASS (local vs global) is the dominant regalloc lever, and C reaches it ONLY through declaration scope and variable reuse (Phase 29 SESSION-19, behemoth #3 `func_8017F510` 1,511 ins, 97 → MATCH, pin-free) L6043 +- **§77** — Every extraction tool carries a NARROW hard-coded preamble set; anything outside it silently caps the body's reach. Diff the preamble before you gate. (Phase 29 SESSION-19 — three variants in one session, two different tools) L6099 +- **§84** — The DERIVED-OFFSET remap bug: a hand-computed literal that encodes the DISTANCE between two per-overlay symbols, and why `match_one` is structurally blind to it (Phase 29 SESSION-20, `func_8013D53C`) L6487 +- **§86** — Pinned-exemplar templatability is a PER-FAMILY property, not a per-member rate; and the §42e pin guard is now over-conservative (Phase 29 SESSION-20) L6604 +- **§3-THE** — LAW: all-or-nothing PER FAMILY L6615 +- **§3-Why** — the two live families differ from the three dead ones — the open question L6642 +- **§3-The** — cheap discriminator, before spending a sweep L6681 +- **§89b** — the parallel gate farm existed; the family path could not reach it (`tools/sweep_parallel.py`) L6760 +- **§91** — A structure-TRANSFER is only valid where the structure corresponds: the `--like` role trap (Phase 29 SESSION-21, `func_8012AAAC` ×137) L6857 +- **§94** — A family sweep's `0/N` is a TYPE-CARRY failure until proven otherwise: lift the exemplar's local types, ALL of them, transitively (Phase 29 SESSION-21, `func_8016B6BC` 0/137 → 137/137) L6962 +- **§105** — A gate's revert must survive an EXCEPTION, not just a failure (Phase 29 T53, `jtbl_family_bank`) L7446 +- **§107** — A lever wired into ONE gate path is a lever most families cannot reach (Phase 29 T56, `func_80144090` 0/136 → 136/136) L7528 +- **§108** — Diagnosing a family `0/N`: the four causes, and the third opt-in lever (Phase 29 T59) L7566 +- **§111** — The distinct-code metric is not noisy: a family pays it only if its members are byte-VARIANT (Phase 29 T66) L7696 +- **§116** — Optimization level is a property of the FILE, not the function: read a family 0/N against the member's stub HOME (Phase 29 T79) L7892 +- **§123** — PROPAGATE A FAMILY WITH THE TOOL ITS TIER NEEDS: `dedup_propagate` is h_exact-only; its refusals are statements about the TOOL (P30 wave 1, 2026-07-30) L8131 +- **§124** — A "not matched" verdict can mean the definition is there under a DIFFERENT C NAME: the asm-label alias blind spot (P30 SESSION-28, `func_8016191C` ×137) L8168 +- **§124a** — a family sweep's `0 matched-exemplar families` may be a FILTER, not a wall L8213 +- **§134** — MULTI-LINE BLINDNESS: one root cause, four faces, in `family_remap`'s preamble scanner (P30 S6, 190 zero-crack families) L8726 +- **§136c** — SIBLING-FIRST is a DERIVATION shortcut, not just a conflict fix (the fastest route in a family wave) L9084 +- **§138** — The propagation lanes: a gate refusal is a DECLARATION, and which lever you owe depends on blast radius L9430 +- **§142** — An open stub whose `h_exact` class is MATCHED elsewhere is FREE. Propagate the body; do not gate a draft. (P30 S39, +7,710 ins in two commands) L9793 +- **§143** — `cast_call_sites` read a RETURN STATEMENT as a prototype and deleted it. A 0/39 sweep became 18/39. (P30 S40) L9849 +- **Then** — propagation returned 0/137 TWICE — both times a missing TYPE L10015 +- **§3-A.** — The frame has THREE strata, and stratum 3 is unreachable from C L10056 +- **§3-E.** — A `qty_compare` TIE is not spelling-reachable — recognise it and stop L10098 +- **Consequence** — for the family (a real scheduling decision) L10110 +- **§150** — A register ROTATION across symmetric blocks is VARIABLE-IDENTITY evidence, not an allocator tie (P30 S43, `func_8017C6F4`, 947 ins ×4) L10327 +- **§151** — THE GHOST WEDGE: when a load-before-store transposition is unreachable by ANY statement order (P30 S43, `func_8017EF68`, 969 ins) L10382 +- **When** — to reach for it L10422 +- **§152** — BYTE SIZE is the family key that name- and h_seq-grouping both miss (P30 S43, the 0xECC family: 1 crack → 12 overlays → 11,364 ins) L10433 +- **§156** — an ORPHANED reconcile poisons the fleet: `dedup_propagate`'s kept edit (S45 p6/p7) L10655 +- **§160** — THE REACH-15 WAVE HARVEST: an align-1 block move, and the instrument that called it a wall (P30 S47) L10908 +- **§162** — S48 WAVE-1 HARVEST (P30, 2026-08-11): the reach-ordered sibling campaign's first 12 targets L11029 +- **§163z** — THE UNVETTED REMAINDER (do not cite as law; each needs a dedupe pass) L11843 +- **§3-The** — ADDRESS-CLASS TABLE: which load/store pairs even REACH the `/s` clause (P30 S48 wave 4, `func_80185B44`, ov_SC03_014) L14370 +- **§168** — THE COUSIN TIER (P30 S49, 2026-08-12): h_seq's exact-hash brittleness, measured — and the similarity map above it L16239 +- **§171a** — THE MECHANICAL A-PROP DRAFT (P30 S50): 256 members banked with no agent in the loop L16448 +- **§171b** — THREE CARRIES THE MECHANICAL DRAFT NEEDS (P30 S50, banking the top-reach families) L16498 +- **§3-G.** — TWO MODELLING TRAPS THAT COST THESE AGENTS SWEEPS OF HUNDREDS OF COMPILES L17325 +- **§193-E** — A varying-address (pointer) load is re-emitted once per CSE-LIVE INTERVAL, and naming it in a C local is the only C-level lever over that count — no store SPELLING has any reach L18667 +- **§194-E** — The wave card's `exemplar` is the TARGET ITSELF on 42/73 wave-U and 36/71 wave-T cards — a construction consequence of `atlas.py:657` (exemplar = max-nins OPEN member) meeting `build_wave_atlas.py:166` (one card per gid); and the shipped §193-A `seed_ref` is same-binary on 0/51, so no card field can ever name a destination-TU sibling L19173 +- **§195-E** — A 0/1 materialised at a JOIN immediately before the controlling `beqz`/`bnez` proves the source NAMED the condition — a truth expression in an `if`'s controlling position reaches `do_jump`, which has no value path L19967 +- **§199-B** — A permutation sweep that holds ANY statement fixed is not a sweep: the statement an agent pins as "obviously load-bearing" is the one carrying the signal, and the partial sweep returns a FLAT residual that reads as proof of order-invariance L20782 +- **§203** — A DEDUPED TYPEDEF MUST PRECEDE EVERY SPLICE POINT, NOT JUST ITS OWN (P31 S56) L21501 +- **§225** — THREE CONTROL-FLOW SHAPES NO STRUCTURED SPELLING REACHES (P31 S58) L22949 +- **§30** — addendum (P31 S58b) — THE ANONYMOUS STRUCT MEMBER REF GRANTS `/s`, AND THAT IS A TWO-FOR-ONE L24173 +- **§3-1a.** — The §266 sweep — every solo-lever A/B run for this batch L25500 +- **ADDENDUM** — to §179-D (GTE macro reference family) — `gte_SetRotMatrix`/`gte_SetTransMatrix` bodies L25691 +- **ADDENDUM** — to §82 — struct copies must stay MEMBER-WISE, not block-moved, to match a spill-slot save L25717 +- **ADDENDUM** — to §136d-1 (RC-12, the `$0`-add / opaque-copy family) — two symptoms beyond "compare reads the wrong register" L25755 +- **§282** — gcc's OWN LOOP REVERSAL PUTS THE COUNTER INIT AFTER THE HOISTED MOVABLES — a position no hand-written down-count can reach (P31 S60; wave cf, func_80180DD8, ov_SC04_005, byte-proven) L27010 +- **ADDENDUM** — to the zero-byte-asm-slider family (§47 / §148-C / §153) (func_800CB874, md_MAIN_040 — wave dj; open tension with a more cautious dm-wave card — see closing) L27929 +- **ADDENDUM** — the zero-emission-asm family gains a REF-SLIDER PLACEMENT LAW and a paired RESTORER (func_800CB900, md_MAIN_026) L28139 +- **ADDENDUM** — §NNN — sharpens §37/§124 (unspecified-parameter-list family): DERIVE A CALLEE'S ARITY LOWER BOUND FROM ITS OWN `.s` STACK-ARGUMENT READS, NOT FROM ANY SINGLE CALL SITE L28300 +- **ADDENDUM** — to §199-F family (func_8017EFB0, ov_SC02_021, wave cu) L28452 +- **§287** — A STACK-FRAME HOLE BELOW TWO ADDRESS-TAKEN AGGREGATE LOCALS IS A LEADING PAD MEMBER OF ONE COMBINED STRUCT, NOT SEPARATE LOCALS OR A REGISTER PIN (P31 S60/dj; `func_8017D104`, ov_SC06_027, byte-proven 47/47) (P31 S60; waves #, byte-proven) L29060 +- **ADDENDUM** — to §127 — the -O0 constant-offset fold keys on the MEMBER-ACCESS tree shape, not on the index being constant L29144 +- **§296** — THE FRAME CHECK OUTRANKS THE ATLAS LEVER: READ PROLOGUE/EPILOGUE BEFORE DRAFTING ANY C — A REAL TELL CAN LIVE INSIDE AN UNREACHABLE FRAGMENT (P31 S61; wave m0a, 16 cards byte-proven; extends §179-C) L29430 +- **§297** — ONE GIV SERVING MIXED-WIDTH LOADS *AND* A STORE NEEDS STRUCT-MEMBER SPELLING; CAST/INDEX SPELLINGS RE-SPLIT THE PSEUDO (P31 S61; wave m0a, `func_800347C8`, main, byte-proven 31/31) L29473 +- **§307** — THE BRUTE-FORCE-THE-STATEMENT-ORDERS LEVER HAS A BOUND: A FAN-OUT COPY'S PRIORITY IS SCHEDULER-INTERNAL, AND NO SOURCE ORDER REACHES IT (P31 S63; byte-evidenced NEGATIVE result, main wave) L29913 +- **§308a** — A TWO-INSTRUCTION ARM STUB LAID *BEFORE* THE OTHER ARM AND REACHED ONLY BY A TRAILING `j` SURVIVES ONLY BEHIND A SHORT-CIRCUIT `&&` GUARD PLUS A SEPARATE RE-TEST; EVERY PLAIN if/else-if, GOTO-LADDER, NESTED-INVERTED-if AND 1-/2-NODE switch LETS jump1 INLINE IT (−2 ins) (P31 S63 t5e-t5i; byte-proven func_80180808) L29986 ### integration / TU plumbing (60) @@ -772,55 +775,55 @@ - **§28d** — The "macro-extern-injection" lever: freeing reach-134 inline matches dedup_propagate skips as "not self-contained" (Phase 23, `tools/inject_capped_externs.py`) L2366 - **§30a** — §30 generalizes to the FULL near-miss backlog (via STANDARD Opus agents, not just Fable5) + 2 more steer levers + the mechanical-integration throughput unlock (Phase 23 (a)) L2394 - **§40a** — The DECL-RECONCILE pass (type-lift so remapped drafts compile in the sibling TU) (Phase 25 T7.2, 2026-07-08) L2601 -- **§42a** — addendum — wave 2 (residuals + 29-100 band): iso-MATCH ≠ real-TU bank, the memcpy→struct-assign fix, +5 levers (2026-07-10b) L2953 -- **§42c** — addendum — wave 3 (Max orchestrator + CORRECTED Ultracode fan-out, 2026-07-10c): the real-TU-faithful parallel harness (rtu_match) + 7/9 crack, ZERO iso-drift L3033 -- **§56** — Banking a hand-drafted GIANT into its exemplar TU: self-contained draft vs live-TU decls, 4 reconciliation tactics (`func_8013FAF8`, 312 ins ×138, Phase 29 T4, 2026-07-17) L4187 -- **§61** — Task 14: the gate ladder's missing stage is the ARITY pre-pass, and it is TU-side not draft-side (Phase 29, 2026-07-21) L4545 -- **§61a** — The Task-5 wave: 11/12 MATCH, 0 banked — three DISTINCT integration walls, each now named (Phase 29, 2026-07-21) L4606 -- **§63** — The fresh-138 DEF-SIDE blocker: fix the HEADER decl, not the draft (`fix_header_decl.py`, Phase 29 SESSION-13, 2026-07-23) L4877 -- **§63** — UPDATE (Phase 29 SESSION-14) — `fix_header_decl`'s "SAFE" verdict is FLEET-BLIND; it MUST be R22-validated L5000 -- **§65** — The stranded-draft recovery: BLAST-RADIUS TIERS, and the per-overlay de-macroize that refutes §20's DEF-conflict wall (`tools/demacroize.py` + `tools/blocker_probe.py`, Phase 29 SESSION-16, 2026-07-24) L5015 -- **§65b** — The escape: de-macroize the instantiation, don't touch the shared header L5045 -- **§65f** — The de-macroize lever's BOUNDARY, measured: byte-neutral 14 times of 15, and the 15th is why the gate exists L5118 -- **§65g** — Where the cheap levers STOP: the local-type and in-TU-self-decl classes did not yield L5139 -- **§85** — The RETURN-axis fleet widen is ALL-OR-NOTHING: widening the shared header alone guarantees a conflict in the source overlay (Phase 29 SESSION-20, `func_8012CC88` / `func_8014D12C`) L6539 -- **§95** — `reconcile_tu` dropped the SIBLING declarators of a multi-symbol `extern` line (Phase 29 SESSION-21, `func_80176218`) L6983 -- **§96** — The same rewrite, one shape down: `reconcile_tu` matched statements to lines by TEXT, so every COMMENTED declaration was silently skipped (Phase 29 SESSION-22, `func_80176218` banked) L7018 -- **§3-Two** — `reconcile_tu` bugs found underneath, one introduced while fixing the other L7190 -- **§100** — Prefer the DRAFT-LOCAL fix: a type only one function uses belongs in its BODY, not in a shared header (Phase 29 SESSION-22, `func_80175DA8` 0/137 → 137/137) L7216 -- **§102** — A PLUMBING verdict can MASK a DIFF; and K&R is not always a codegen change (Phase 29 SESSION-22, `func_8016EC0C`) L7272 -- **§103** — A FILE-scope `extern` in a shared overlay TU is a GLOBAL constraint on every LATER function; move the DECL, not the draft (Phase 29 T48/T51, `func_80135260` — the fleet-wide half) L7307 -- **§109** — Conforming a definition to a shared header: fix the NAMES, then check the RETURN precondition (Phase 29 T60) L7600 -- **§112** — A macro-scoped declaration only collides where the macro is INSTANTIATED (Phase 29 T67/T69, `audit_header_sigs.py`) L7730 -- **§114** — The THIRD decl axis: a CALLEE the draft declares differently from the target TU (Phase 29 T76/T77) L7808 -- **§3-The** — integration idioms (these decide whether a byte-correct draft BANKS) L8804 -- **§3-The** — declaration surface (integration, not codegen) L8941 -- **Reconciling** — a gate-refused draft: which way you edit depends on WHERE the TU's decl is L9565 -- **§3-The** — same swallow, twice more, in the integration spine L9709 -- **§3-A.** — Payload word0 is a global MODULE ID; code starts after the header L10527 -- **§162** — THE LICM PAIR: what makes an address a movable AT ALL, and why the preheader order is the body order (P30 S47, `ov_MAIN_012`) L11143 -- **§166** — THE DESTINATION-TU ORACLE (P30 S48): the seven-attempt bug that was never codegen L14915 -- **§173** — THE STORED-PLUMBING RECOVERY RECIPE (P31 T6): symfix-first, per-group isolation, and where the verdicts have no drafts L16629 -- **§176d** — THE CONFLICT TABLE MUST BE SEEDED FROM THE TU, AND KEYED PER FILE (P31 S52, 2026-08-15) L16826 -- **§180b** — WHAT THE PRE-GATE LADDER ACTUALLY FINDS IN A COLD PILE (the shape of integration debt) L17842 -- **§185** — EDIT THE SIDE THAT IS CHEAP TO VERIFY, AND CHECK A TU RETYPE AT ITS USE SITES L18060 -- **§194-E** — The wave card's `exemplar` is the TARGET ITSELF on 42/73 wave-U and 36/71 wave-T cards — a construction consequence of `atlas.py:657` (exemplar = max-nins OPEN member) meeting `build_wave_atlas.py:166` (one card per gid); and the shipped §193-A `seed_ref` is same-binary on 0/51, so no card field can ever name a destination-TU sibling L19158 -- **§195-J** — GTE / PsyQ op CALL-vs-INLINE is a PER-SITE SOURCE FACT, not a TU style — both forms coexist in one TU (measured in 2 TUs), and the tell is the target's own opcodes (`lwc2`/`sqr`/`swc2` vs `jal`), not the sibling. Costs -8 ins on func_8018505C. Corollary: the game's inline `sqr` macro emits TWO hazard nops, the SDK's `Square0` body emits ONE — so the inline form is provably not `Square0` inlined (a second instance of §187's SDK-vs-game GTE nop divergence). L20222 -- **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` L20860 -- **§200** — THE ALIAS IS THE UNIVERSAL DECLARATION ESCAPE: stop negotiating with the TU's spelling (P31 S55) L21099 -- **§201-A** — §150-B applies to `decl_prior`'s DEF row: for an overlay-window symbol the banked "definition" is usually another overlay's function, and the card ranks it ABOVE the destination TU L21158 -- **§203** — A DEDUPED TYPEDEF MUST PRECEDE EVERY SPLICE POINT, NOT JUST ITS OWN (P31 S56) L21486 -- **§210** — THE SINGLE-BIT MASK IN A BOOLEAN TAIL: `andi K ; sltu $zero,v` vs `srl n ; andi 1` is a STATEMENT-SHAPE dial, not an operator choice (P31 S58) L22328 -- **ADD-2** — → §42a addendum — A SHARED CONSTANT *NAMED IN A LOCAL* ACROSS A `jal` IS AN ISO→TU DRIFT HAZARD; WRITE BARE LITERALS L25096 -- **ADD-3** — → §236, item 10 — THE UN-DELETED `INCLUDE_ASM` STUB IS A DUPLICATE DEFINITION L25108 -- **ADD-2** — → §236 addendum (item 1 corollary) — THE SILENT-SPLICE DECLARATION LADDER: WHERE THE TU HAS NO SPELLING, UNPROTOTYPED `()` BEATS THE FLEET VOTE L25326 -- **§273** — A standalone compile is the WRONG oracle for a TU-destined draft (P31 S59) L25578 -- **ADDENDUM** — to §134 — a typedef defined BELOW the splice point is stripped anyway L25646 -- **ADDENDUM** — to §8 — WHEN `INCLUDE_RODATA` NEEDS A STANDALONE `.s` YOU CAN'T CREATE, CARRY THE FRAGMENT AS A FILE-SCOPE `__asm__` BLOB L26181 -- **§280** — THE CURSOR'S DECLARED TYPE PICKS `sltu` vs `slt`: a `T*` bound test is UNSIGNED by C rule, an integer cursor is signed (P31 S60; wave cf, func_800CAE74, md_MAIN_031, byte-proven) L26915 -- **§NNN** — A LOOP CURSOR'S C TYPE (POINTER vs PLAIN INTEGER) SELECTS `sltu` vs `slt` FOR ITS BOUND TEST, INDEPENDENT OF THE VALUES INVOLVED (P31 S60; `func_800CAE74`, md_MAIN_031, byte-proven; cross-confirmed same wave by `func_8017F2A4`, ov_SC03_096) L26916 -- **ADDENDUM** — to §199-G — A `default:` LABEL GROUPED ONTO THE LAST CASE REMOVES THE `j default` TAIL, EVEN THOUGH THE 2-NODE HEADER STAYS ALL-POSITIVE L27370 -- **§301** — AN INTERNAL `j` CARRIES `R_MIPS_26 .text`: rtu/match_one "MATCH" COULD NOT SEE WHICH LABEL A `j` TAKES — FIXED (`jrel`), AND THE TWO DRAFT SHAPES IT HID (P31 S62 T1; byte-proven 2/2, negative-controlled over 3,297 stubs) L29630 +- **§42a** — addendum — wave 2 (residuals + 29-100 band): iso-MATCH ≠ real-TU bank, the memcpy→struct-assign fix, +5 levers (2026-07-10b) L2968 +- **§42c** — addendum — wave 3 (Max orchestrator + CORRECTED Ultracode fan-out, 2026-07-10c): the real-TU-faithful parallel harness (rtu_match) + 7/9 crack, ZERO iso-drift L3048 +- **§56** — Banking a hand-drafted GIANT into its exemplar TU: self-contained draft vs live-TU decls, 4 reconciliation tactics (`func_8013FAF8`, 312 ins ×138, Phase 29 T4, 2026-07-17) L4202 +- **§61** — Task 14: the gate ladder's missing stage is the ARITY pre-pass, and it is TU-side not draft-side (Phase 29, 2026-07-21) L4560 +- **§61a** — The Task-5 wave: 11/12 MATCH, 0 banked — three DISTINCT integration walls, each now named (Phase 29, 2026-07-21) L4621 +- **§63** — The fresh-138 DEF-SIDE blocker: fix the HEADER decl, not the draft (`fix_header_decl.py`, Phase 29 SESSION-13, 2026-07-23) L4892 +- **§63** — UPDATE (Phase 29 SESSION-14) — `fix_header_decl`'s "SAFE" verdict is FLEET-BLIND; it MUST be R22-validated L5015 +- **§65** — The stranded-draft recovery: BLAST-RADIUS TIERS, and the per-overlay de-macroize that refutes §20's DEF-conflict wall (`tools/demacroize.py` + `tools/blocker_probe.py`, Phase 29 SESSION-16, 2026-07-24) L5030 +- **§65b** — The escape: de-macroize the instantiation, don't touch the shared header L5060 +- **§65f** — The de-macroize lever's BOUNDARY, measured: byte-neutral 14 times of 15, and the 15th is why the gate exists L5133 +- **§65g** — Where the cheap levers STOP: the local-type and in-TU-self-decl classes did not yield L5154 +- **§85** — The RETURN-axis fleet widen is ALL-OR-NOTHING: widening the shared header alone guarantees a conflict in the source overlay (Phase 29 SESSION-20, `func_8012CC88` / `func_8014D12C`) L6554 +- **§95** — `reconcile_tu` dropped the SIBLING declarators of a multi-symbol `extern` line (Phase 29 SESSION-21, `func_80176218`) L6998 +- **§96** — The same rewrite, one shape down: `reconcile_tu` matched statements to lines by TEXT, so every COMMENTED declaration was silently skipped (Phase 29 SESSION-22, `func_80176218` banked) L7033 +- **§3-Two** — `reconcile_tu` bugs found underneath, one introduced while fixing the other L7205 +- **§100** — Prefer the DRAFT-LOCAL fix: a type only one function uses belongs in its BODY, not in a shared header (Phase 29 SESSION-22, `func_80175DA8` 0/137 → 137/137) L7231 +- **§102** — A PLUMBING verdict can MASK a DIFF; and K&R is not always a codegen change (Phase 29 SESSION-22, `func_8016EC0C`) L7287 +- **§103** — A FILE-scope `extern` in a shared overlay TU is a GLOBAL constraint on every LATER function; move the DECL, not the draft (Phase 29 T48/T51, `func_80135260` — the fleet-wide half) L7322 +- **§109** — Conforming a definition to a shared header: fix the NAMES, then check the RETURN precondition (Phase 29 T60) L7615 +- **§112** — A macro-scoped declaration only collides where the macro is INSTANTIATED (Phase 29 T67/T69, `audit_header_sigs.py`) L7745 +- **§114** — The THIRD decl axis: a CALLEE the draft declares differently from the target TU (Phase 29 T76/T77) L7823 +- **§3-The** — integration idioms (these decide whether a byte-correct draft BANKS) L8819 +- **§3-The** — declaration surface (integration, not codegen) L8956 +- **Reconciling** — a gate-refused draft: which way you edit depends on WHERE the TU's decl is L9580 +- **§3-The** — same swallow, twice more, in the integration spine L9724 +- **§3-A.** — Payload word0 is a global MODULE ID; code starts after the header L10542 +- **§162** — THE LICM PAIR: what makes an address a movable AT ALL, and why the preheader order is the body order (P30 S47, `ov_MAIN_012`) L11158 +- **§166** — THE DESTINATION-TU ORACLE (P30 S48): the seven-attempt bug that was never codegen L14930 +- **§173** — THE STORED-PLUMBING RECOVERY RECIPE (P31 T6): symfix-first, per-group isolation, and where the verdicts have no drafts L16644 +- **§176d** — THE CONFLICT TABLE MUST BE SEEDED FROM THE TU, AND KEYED PER FILE (P31 S52, 2026-08-15) L16841 +- **§180b** — WHAT THE PRE-GATE LADDER ACTUALLY FINDS IN A COLD PILE (the shape of integration debt) L17857 +- **§185** — EDIT THE SIDE THAT IS CHEAP TO VERIFY, AND CHECK A TU RETYPE AT ITS USE SITES L18075 +- **§194-E** — The wave card's `exemplar` is the TARGET ITSELF on 42/73 wave-U and 36/71 wave-T cards — a construction consequence of `atlas.py:657` (exemplar = max-nins OPEN member) meeting `build_wave_atlas.py:166` (one card per gid); and the shipped §193-A `seed_ref` is same-binary on 0/51, so no card field can ever name a destination-TU sibling L19173 +- **§195-J** — GTE / PsyQ op CALL-vs-INLINE is a PER-SITE SOURCE FACT, not a TU style — both forms coexist in one TU (measured in 2 TUs), and the tell is the target's own opcodes (`lwc2`/`sqr`/`swc2` vs `jal`), not the sibling. Costs -8 ins on func_8018505C. Corollary: the game's inline `sqr` macro emits TWO hazard nops, the SDK's `Square0` body emits ONE — so the inline form is provably not `Square0` inlined (a second instance of §187's SDK-vs-game GTE nop divergence). L20237 +- **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` L20875 +- **§200** — THE ALIAS IS THE UNIVERSAL DECLARATION ESCAPE: stop negotiating with the TU's spelling (P31 S55) L21114 +- **§201-A** — §150-B applies to `decl_prior`'s DEF row: for an overlay-window symbol the banked "definition" is usually another overlay's function, and the card ranks it ABOVE the destination TU L21173 +- **§203** — A DEDUPED TYPEDEF MUST PRECEDE EVERY SPLICE POINT, NOT JUST ITS OWN (P31 S56) L21501 +- **§210** — THE SINGLE-BIT MASK IN A BOOLEAN TAIL: `andi K ; sltu $zero,v` vs `srl n ; andi 1` is a STATEMENT-SHAPE dial, not an operator choice (P31 S58) L22343 +- **ADD-2** — → §42a addendum — A SHARED CONSTANT *NAMED IN A LOCAL* ACROSS A `jal` IS AN ISO→TU DRIFT HAZARD; WRITE BARE LITERALS L25111 +- **ADD-3** — → §236, item 10 — THE UN-DELETED `INCLUDE_ASM` STUB IS A DUPLICATE DEFINITION L25123 +- **ADD-2** — → §236 addendum (item 1 corollary) — THE SILENT-SPLICE DECLARATION LADDER: WHERE THE TU HAS NO SPELLING, UNPROTOTYPED `()` BEATS THE FLEET VOTE L25341 +- **§273** — A standalone compile is the WRONG oracle for a TU-destined draft (P31 S59) L25593 +- **ADDENDUM** — to §134 — a typedef defined BELOW the splice point is stripped anyway L25661 +- **ADDENDUM** — to §8 — WHEN `INCLUDE_RODATA` NEEDS A STANDALONE `.s` YOU CAN'T CREATE, CARRY THE FRAGMENT AS A FILE-SCOPE `__asm__` BLOB L26196 +- **§280** — THE CURSOR'S DECLARED TYPE PICKS `sltu` vs `slt`: a `T*` bound test is UNSIGNED by C rule, an integer cursor is signed (P31 S60; wave cf, func_800CAE74, md_MAIN_031, byte-proven) L26930 +- **§NNN** — A LOOP CURSOR'S C TYPE (POINTER vs PLAIN INTEGER) SELECTS `sltu` vs `slt` FOR ITS BOUND TEST, INDEPENDENT OF THE VALUES INVOLVED (P31 S60; `func_800CAE74`, md_MAIN_031, byte-proven; cross-confirmed same wave by `func_8017F2A4`, ov_SC03_096) L26931 +- **ADDENDUM** — to §199-G — A `default:` LABEL GROUPED ONTO THE LAST CASE REMOVES THE `j default` TAIL, EVEN THOUGH THE 2-NODE HEADER STAYS ALL-POSITIVE L27385 +- **§301** — AN INTERNAL `j` CARRIES `R_MIPS_26 .text`: rtu/match_one "MATCH" COULD NOT SEE WHICH LABEL A `j` TAKES — FIXED (`jrel`), AND THE TWO DRAFT SHAPES IT HID (P31 S62 T1; byte-proven 2/2, negative-controlled over 3,297 stubs) L29645 ### build graph, splat & the harness (167) @@ -864,133 +867,133 @@ - **§37** — The T7 §G giant endgame: 6/8 cracked, meta-laws + transferable levers (Phase 24, 2026-07-07; FULL byte-verified detail + gcc-2.7.2 line cites in `docs/gcc-2.7.2-map/t7g-giant-harvest.md`) L2506 - **§39** — The ×1→×134 giant-endgame: propagate a matched **-O2** giant via the NATIVE DEFINE-macro path (Phase 24 T7 §G close, 2026-07-08) L2537 - **§41** — The DEF-SIDE canonical-sig wall: mechanically banking a drafted giant past `conflicting types` (Phase 25 T5b batch-2, 2026-07-09; `tools/canon_sig_reconcile.py`, byte-proven on `func_8013B274`) L2710 -- **§41a** — v3.1: the def-side wall was ~71% TOOL-shaped — the five measured defects + the laws that dissolve them (Phase 25 T6, Fable5, 2026-07-09) L2754 -- **§41b** — T7 execution: the object-only probe OVER-counts BANKABLE by two link/rodata classes (Phase 25 T7-M1, 2026-07-10) L2809 -- **§41d** — `void`→`s32` is NOT always byte-neutral: gate the RAW draft FIRST (Phase 26 session 6, byte-proven) L2878 -- **§42b** — addendum — wave 3 (Max, 2026-07-10c): THE STALE-OBJECT GATE TRAP + the read-global `&`-cast drift + fix L2994 -- **§45** — The flagship `func_80133CD4` crack (399 ins ×134): the merged-variable permutation-breaker + the 1-death local-alloc gate (Phase 25 task A giant escalation, Fable5 gdb-on-cc1, 2026-07-11) L3298 -- **§51** — TOOLING INTEGRITY: the silent skip, and how to hunt it L3630 -- **§51b** — Why the byte-gate cannot save you L3652 -- **§51f** — Checklist for any new corpus-scanning tool L3755 -- **§51g** — When the thing you are scanning has a GRAMMAR, parse the grammar (`tools/cdecl.py`) L3769 -- **§53** — SWEEP A FAMILY WITH THE TOOL ITS EXEMPLAR NEEDED: the jr/switch carve, and how omitting it manufactured the "families don't template" doctrine (Phase 28 T1, 2026-07-15) L4028 -- **§55** — Core-crack wave levers + the GATE-ORCHESTRATION law (Phase 29 T3, 13-agent ultracode wave, 2026-07-17) L4093 -- **§55b** — THE GATE-ORCHESTRATION LAW (3 traps, ~3.5h lost; all recovered, 0 data lost) L4122 -- **§55c** — Sizing the propagate: a TARGETED propagate is ~4 min/core, and "it's slow" was a BROKEN-TREE ARTIFACT L4141 -- **§54** — `--fix-def-sig`: the member's CANONICAL DECLARATION is a build step too (tiny-IMM mega-pools, +4,801, Phase 29 T6, 2026-07-16) L4163 -- **§57** — The SELF-decl normalize: the sibling's OWN caller declares the templated fn divergently (the third §17a-1 direction; `tools/normalize_self_decls.py`, func_801670E4 ×137, Phase 29, 2026-07-18) L4256 -- **§61** — Task 14: the gate ladder's missing stage is the ARITY pre-pass, and it is TU-side not draft-side (Phase 29, 2026-07-21) L4545 -- **§61b** — The jtbl gate stage: built, and the ORDERING law it exposed (Phase 29 Task-14 stage 4, 2026-07-21) L4658 -- **§61d** — The undo was eating the tree: two tools, one defect, invisible to the byte-gate (Phase 29, 2026-07-22) L4779 -- **§62** — The jtbl RECONCILE must also follow the carve: the post-carve draft reconcile (`harvest_verify._jtbl_reconcile`, Phase 29 SESSION-11, 2026-07-22) L4833 -- **§65** — The stranded-draft recovery: BLAST-RADIUS TIERS, and the per-overlay de-macroize that refutes §20's DEF-conflict wall (`tools/demacroize.py` + `tools/blocker_probe.py`, Phase 29 SESSION-16, 2026-07-24) L5015 -- **§65d** — Existing-ladder baseline, measured (do this before building a recovery stage) L5091 -- **§65e** — Two oracles, and the disagreement is the finding (R34 in practice) L5101 -- **§65f** — The de-macroize lever's BOUNDARY, measured: byte-neutral 14 times of 15, and the 15th is why the gate exists L5118 -- **§66b** — A metric parsed out of another tool's prose goes NULL silently when the label changes L5200 -- **§67a** — Run the symbol-set guard BEFORE you pay for a gate (`tools/symcheck.py`, Phase 29 SESSION-18) L5405 -- **§77** — Every extraction tool carries a NARROW hard-coded preamble set; anything outside it silently caps the body's reach. Diff the preamble before you gate. (Phase 29 SESSION-19 — three variants in one session, two different tools) L6084 -- **§3-The** — CANDIDATE gate and the REAL gate need DIFFERENT preambles — keep the difference out of the bank L6124 -- **§79** — For a 0-callee giant, fingerprint by DATA symbols (§71 cannot fire); and the STACK-SLOT ORDER is a declaration-order oracle (Phase 29 SESSION-19, `func_8017BF14` 4,763 ins, cold start → 45/4763) L6220 -- **§82** — Two source-shape oracles from behemoth #6: a duplicated `addiu $aN,$sp,K` across a `jal` means the block was INLINED, and scalar-vs-aggregate decides WHEN a stack slot is allocated (Phase 29 SESSION-19, `func_8017C730` 1,061 ins) L6370 -- **§3-2.** — Scalar vs aggregate decides *when* the slot is allocated L6389 -- **§3-Why** — it survived every candidate gate L6495 -- **§3-THE** — FIX IS MECHANICAL — the tool already holds the answer L6510 -- **§87** — `match_one` COMPILES but never LINKS, so an unresolvable data symbol reads as MATCH; and stored drafts go STALE against the tree (Phase 29 SESSION-20) L6633 -- **§88f** — the missing rung: a RELOCATION gate between `match_one` and the binary L6718 -- **§89a** — MEASURE the write set; do not assert its tier (`tools/blast_radius.py`) L6732 -- **§89b** — the parallel gate farm existed; the family path could not reach it (`tools/sweep_parallel.py`) L6745 -- **§90** — Five tool-integrity laws from one session, each of which changed an answer (Phase 29 SESSION-21, 2026-07-27) L6766 -- **§90a** — A comparison tool MUST share its reference oracle's index space, exactly L6772 -- **§92** — Conforming a DECLARATION: pointer changes are caller-neutral, scalar-WIDTH changes are not (Phase 29 SESSION-21, `tools/conform_decls.py`) L6891 -- **§97** — The gate's own tree hygiene: a refused carve, an unchecked recovery, and a snapshot that captured a dirty tree (Phase 29 SESSION-22) L7066 -- **§105** — A gate's revert must survive an EXCEPTION, not just a failure (Phase 29 T53, `jtbl_family_bank`) L7431 -- **§107** — A lever wired into ONE gate path is a lever most families cannot reach (Phase 29 T56, `func_80144090` 0/136 → 136/136) L7513 -- **§3-Why** — it survived so long: a MASKED oracle will MATCH a wrong symbol L7953 -- **§122** — GATE RAW BEFORE TRANSFORMING; the undo belongs to the WRITER, as a per-edit journal (P30 T0a, 2026-07-30) L8084 -- **§123** — PROPAGATE A FAMILY WITH THE TOOL ITS TIER NEEDS: `dedup_propagate` is h_exact-only; its refusals are statements about the TOOL (P30 wave 1, 2026-07-30) L8116 -- **§126a** — a bare `except: continue` around a coverage-asserting oracle re-creates the silent skip (P30 S28) L8317 -- **§130** — An INCREMENTAL build can report BYTE-IDENTICAL for a change the CLEAN build cannot even LINK (P30 S28, the jr pair) L8486 -- **§132** — The `JR-PAIR-IN-ONE-O0-OBJECT` "wall" was TWO instrument defects: a merged-double span the carve could not see, and a truncated object no rule deleted (P30 S29, `func_8013B83C` + `func_8013BD74`) L8570 -- **§133** — The DEFAULT-FILTER class: three times in one session, a tool silently answered a narrower question than the one asked (P30 S1–S3) L8685 -- **§134** — MULTI-LINE BLINDNESS: one root cause, four faces, in `family_remap`'s preamble scanner (P30 S6, 190 zero-crack families) L8711 -- **§3-The** — splitting/merging rules (each closed a residual, byte-gated) L8853 -- **§137a** — A gate verdict has a TIMESTAMP; re-check it against the draft's mtime L9386 -- **§138** — The propagation lanes: a gate refusal is a DECLARATION, and which lever you owe depends on blast radius L9415 -- **§134** — again, in a second tool — and the waiter rule corrected L9526 -- **Reconciling** — a gate-refused draft: which way you edit depends on WHERE the TU's decl is L9565 -- **§139** — A GATE THAT GREPS FOR VERDICTS MUST ASSERT 1:1 ACCOUNTING; and a `--src` filter must not survive a carve (P30 S38, wave 6: 10 of 16 drafts vanished) L9594 -- **§140** — A METRIC IS NOT A MEASUREMENT UNTIL IT IS REPRODUCIBLE FROM THE COMMITTED TREE (P30 S1e: a phantom regression that gated the session's best lever) L9660 -- **§142** — An open stub whose `h_exact` class is MATCHED elsewhere is FREE. Propagate the body; do not gate a draft. (P30 S39, +7,710 ins in two commands) L9778 -- **§3-The** — measurement (do this before any wave; it is ~20 lines and needs no builds) L9790 -- **§155b** — check the TYPE your oracle returns before comparing against it (S45 p5) L10587 -- **§156** — an ORPHANED reconcile poisons the fleet: `dedup_propagate`'s kept edit (S45 p6/p7) L10640 -- **§158** — The RANGE-EXTENDER: a fourth zero-emission asm lever completes the allocno toolkit (P30 S46 tier-3, `func_8017CE58`, 733 ins) L10712 -- **§160** — THE REACH-15 WAVE HARVEST: an align-1 block move, and the instrument that called it a wall (P30 S47) L10893 -- **§161** — THE RETRY-WAVE HARVEST: a jump table indexed from zero, and two allocator traps (P30 S47) L10969 -- **§162** — S48 WAVE-1 HARVEST (P30, 2026-08-11): the reach-ordered sibling campaign's first 12 targets L11014 -- **§163** — S48 WAVES 2-3 HARVEST (P30, 2026-08-11/12): the five that were byte-probed and are actionable L11760 -- **§165** — S48 WAVE-4 HARVEST (P30, 2026-08-12): banked the same day the wave landed L13702 -- **§166** — THE DESTINATION-TU ORACLE (P30 S48): the seven-attempt bug that was never codegen L14915 -- **§167** — S48 WAVE-5/6 HARVEST (P30, 2026-08-12): the saturation point L14971 -- **§176e** — SYMBOL IDENTITY IS COMPUTABLE OFFLINE (P31 S52): `tools/reloc_identity.py` L16865 -- **§3-A.** — The seven under-reporting holes (all in `gate_main`, all the same shape) L16999 -- **§3-C2.** — RECONCILE BEFORE THE FIRST GATE — a parked draft gets HARDER to bank, not easier L17046 -- **§3-D.** — The measured cost shape, and what to build next L17069 -- **§176i** — WHAT A STATIC PRE-GATE CHECK CAN AND CANNOT PROVE (P31 S52, wave Q) L17087 -- **§179** — IDIOMS MINED FROM THE WAVE P/Q JOURNALS (P31 S52, harvest pass) L17326 -- **§179-G** — 🟡 A PIN CAN **CREATE** A COMBINE `LOG_LINK` AND DELETE AN `andi` (sixth RC-5 channel, n=1) L17555 -- **§176c** — MAIN (SLUS_007.26) CANNOT BE GATED INCREMENTALLY L17622 -- **§180** — THE LEFTOVER-DRAFT HARVEST: RE-VERIFY WHAT YOU ALREADY HAVE BEFORE DRAFTING ANYTHING NEW L17813 -- **§180b** — WHAT THE PRE-GATE LADDER ACTUALLY FINDS IN A COLD PILE (the shape of integration debt) L17842 -- **§181** — WHAT A WAVE'S GATE ACTUALLY REJECTS (P31 S53, measured on wave R's 45-draft main pile) L17879 -- **§184** — COMMENT-BLINDNESS IS A DEFECT CLASS, NOT A BUG (P31 S53: three tools, one root cause, one session) L18032 -- **§187** — 🔴 "SAME SOURCE" IS NOT "SAME OBJECT": THE SDK BUILD AND THE GAME BUILD DISAGREE ON GTE NOPS L18138 -- **§190** — THREE PRESCRIPTIONS FROM THE SAME HARVEST (weaker evidence than §189, honestly labelled) L18301 -- **§191** — WHAT THIS HARVEST DID **NOT** BANK (4 rejected, 4 narrowed) — recorded so it is not re-derived L18338 -- **§192** — THE PRE-GATE LADDER WAS MAIN-ONLY, AND NOBODY COULD SEE IT (P31 S54) L18360 -- **§193** — THE WAVE-T HARVEST (P31 S54): 71 index_gap reports -> 9 laws, 5 rejected, 61 already-covered L18425 -- **§193-A** — The wave card ships only OPEN-set pointers and discards the atlas's BANKED one — `exemplar`/`sibs` are stubs 100% by construction (tools/atlas.py:96/657), while `seed.ref` (matched pool, atlas.py:505-536) is dropped at build_wave_atlas.py:143 L18442 -- **§193-G** — §164-54's "scope to ≥4 arms" bound is byte-wrong — the dispatch-topology oracle goes live at THREE case nodes (`balance_case_nodes` splits at `i > 2`), but only for a signed-after-promotion index L18746 -- **§193-I** — A DECLARED AGGREGATE LOCAL HAS AN 8-BYTE FRAME STRIDE — CEIL(size,8), NOT size. N ARRAYS THEREFORE COST 8·k MORE THAN ONE HAND-LAID STRUCT (k = how many of them have size mod 8 ≠ 0), AND THE TELL IS IDENTICAL INSTRUCTION COUNT WITH EVERY $sp DISPLACEMENT SHIFTED BY THE SAME CONSTANT. L18847 -- **§193-REJECTED** — what this harvest did NOT bank (recorded so it is not re-derived) L18906 -- **§194** — THE WAVE-U HARVEST (P31 S54): 64 index_gap reports -> 14 laws, 5 rejected, 44 already-covered L18933 -- **§194-E** — The wave card's `exemplar` is the TARGET ITSELF on 42/73 wave-U and 36/71 wave-T cards — a construction consequence of `atlas.py:657` (exemplar = max-nins OPEN member) meeting `build_wave_atlas.py:166` (one card per gid); and the shipped §193-A `seed_ref` is same-binary on 0/51, so no card field can ever name a destination-TU sibling L19158 -- **§194-G** — Reading the integer half of a 16.16 stack aggregate: REGISTER-LIVENESS, not the C spelling, decides `sra` vs `lhu` — and the break is count-neutral L19268 -- **§194-K** — Blind sched1's alias oracle with a second SET of a pointer pseudo — the first zero-byte, non-volatile, dependence-CREATING lever (corrects §167-05's "volatile is the only door"; fourth consumer of reg_n_sets) L19444 -- **§194-REJECTED** — what this harvest did NOT bank (recorded so it is not re-derived) L19688 -- **§195** — THE WAVE-V HARVEST (P31 S54): 67 index_gap reports -> 14 laws, 9 rejected, 76 already-covered L19709 -- **§195-I** — §145(b) AMENDED — the pointer-bump `addiu` is saved by cse, not combine: ANY second SET of a pseudo in the address's equivalence chain (in-place `p += K`, §145(b)'s `p = r;` copy, or an asm re-tie) kills the fold; the pass is cse and the gate is `invalidate`'s `reg_tick++` L20157 -- **§195-M** — Frame `vars` is a SEQUENTIAL bump-allocation, not a flat sum: §193-I's CEIL(aggregate,8) term and §165-03/§167-06's 8×orphan term are the SAME frame_offset walk at two different compiler stages, and each stage re-CEILs frame_offset to 8 before it allocates L20370 -- **§195-REJECTED** — what this harvest did NOT bank (recorded so it is not re-derived) L20466 -- **§197** — THE WAVE-W HARVEST (P31 S54): 68 index_gap reports -> 4 laws, 3 rejected, 41 already-covered L20567 -- **§199** — THE WAVE-X HARVEST (P31 S54/S55): 63 index_gap reports -> 7 laws, 2 rejected, 56 already-covered L20707 -- **§199-C** — A NEGATIVE CONSTANT MULTIPLY ALWAYS TAKES expmed's negate_variant — but whether you ever SEE the neg is decided by COMBINE, and for an EVEN |K| it never disappears L20812 -- **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` L20860 -- **§199-G** — At TWO case nodes the switch-vs-if oracle is not blind — but the tell is ALL tests positive + a trailing `j default`, NOT the first test's polarity L21033 -- **§201** — THE WAVE-Y HARVEST (P31 S55): 67 gap reports -> 5 laws, 8 rejected, 53 already-covered L21148 -- **§204** — THE WAVE-Z HARVEST (P31 S56): 82 gap reports -> 5 laws, 16 rejected, 30 already-covered L21547 -- **§207** — THE WAVE ab–ag HARVEST (P31 S58): 278 byte-banked notes → 25 laws, 103 self-reported no-gap L22181 -- **§233** — THE WAVE aa–bg HARVEST (P31 S58b): 1,101 byte-banked notes → 24 new laws, 21 addenda, ~700 already-covered L23272 -- **§236** — THE DECLARATION LAYER IS THE DOMINANT BANK-BLOCKER: NINE WAYS A BYTE-PERFECT BODY FAILS THE GATE (P31 S58b) L23386 -- **§247** — TWO BRANCHES TO **ONE** LABEL MEANS THE SOURCE CONDITION IS NEGATED (P31 S58b) L23832 -- **§254** — THE DEAD PARAMETER IS A REGISTER-PLACEMENT TOOL **(single observation — not yet cross-confirmed)** (P31 S58b) L24026 -- **§259** — THE DISCARD LEDGER FOR THE aa–bg HARVEST (P31 S58b): WHAT WAS MINED AND REJECTED, AND WHY L24683 -- **§260-A** — STAGE 2 IS PROVEN, AND THE WHOLE jtbl PIPELINE IS AUTOMATED AT THE GATE (P31 S59, same day) L24772 -- **§261** — THE -O0 ORACLE: DERIVE THE OPT LEVEL FROM THE TARGET, AND `$fp` IS NOT THE TELL (P31 S59) L24808 -- **§267** — ADDENDA HARVESTED FROM WAVES at/bh/bk/bl (P31 S59b) L25079 -- **ADD-9** — → §213-3 / §217 addendum — ADJACENT PRE-CALL FRAME STORES ARE ONE AGGREGATE; THE UNESCAPED SCALAR NEIGHBOR IS DEAD-STORED L25174 -- **§269** — ADDENDA HARVESTED FROM WAVES ax/bm (P31 S59c) L25298 -- **§271** — Ordinal IMM pairing: text order is NOT emission order; emit CANDIDATES, let the oracle pick (P31 S59) L25536 -- **§273** — A standalone compile is the WRONG oracle for a TU-destined draft (P31 S59) L25578 -- **§274** — ADDENDA HARVESTED FROM 18 WAVES (P31 S60): 315 candidates, 255 already covered, 21 sharpenings, 3 new laws L25593 -- **§278** — ADDENDA HARVESTED FROM WAVE cf (P31 S60): 34 candidates, 13 already covered, 8 sharpenings, 4 new laws L26584 -- **§283** — ADDENDA HARVESTED FROM THE 36-WAVE BATCH (P31 S60): 1,216 candidates, 859 already covered, 46 sharpenings, 9 new laws L27080 -- **§287** — A STACK-FRAME HOLE BELOW TWO ADDRESS-TAKEN AGGREGATE LOCALS IS A LEADING PAD MEMBER OF ONE COMBINED STRUCT, NOT SEPARATE LOCALS OR A REGISTER PIN (P31 S60/dj; `func_8017D104`, ov_SC06_027, byte-proven 47/47) (P31 S60; waves #, byte-proven) L29045 -- **§293** — THE "WHOLE-OBJECT GATE NEEDS EVERY SIBLING" LAW, WRITTEN PROPERLY: IT IS THREE LAWS, AND THE LOAD-BEARING ONE IS "THE BASELINE, NOT THE SIBLINGS" (P31 S61; byte-proven on 15 binaries in one night) L29068 -- **§294** — ADDENDA HARVESTED FROM THE S61 GEN0/MAXTOK/MAIN/DEEPSEEK BATCH (waves ab8/ab16/ab24/ab32 · g0a–g0f · m0a · ds1/ds2): 99 candidates, 52 covered, 15 notes → 10 addenda, 29 notes → 5 new laws (§295–§299), 3 refuted L29118 -- **§303** — MODULE ISLAND TABLES: DERIVE THE PADS AT BUILD TIME, PEEL NOTHING — THE §154-A/§260 "island-pads"/"island-blocked" WALLS DISSOLVE (P31 S62 T3a; byte-proven md_SC03_076 func_801F0A9C + func_801F0F28, sha 9a165e36…) L29722 -- **§305** — "CARVE-REFUSED" AT GATE TIME IS THREE NAMED, DETERMINISTIC CLASSES — NONE OF THEM A CARVE (P31 S62 T3; 28 resolver drafts autopsied 28/28) L29781 +- **§41a** — v3.1: the def-side wall was ~71% TOOL-shaped — the five measured defects + the laws that dissolve them (Phase 25 T6, Fable5, 2026-07-09) L2769 +- **§41b** — T7 execution: the object-only probe OVER-counts BANKABLE by two link/rodata classes (Phase 25 T7-M1, 2026-07-10) L2824 +- **§41d** — `void`→`s32` is NOT always byte-neutral: gate the RAW draft FIRST (Phase 26 session 6, byte-proven) L2893 +- **§42b** — addendum — wave 3 (Max, 2026-07-10c): THE STALE-OBJECT GATE TRAP + the read-global `&`-cast drift + fix L3009 +- **§45** — The flagship `func_80133CD4` crack (399 ins ×134): the merged-variable permutation-breaker + the 1-death local-alloc gate (Phase 25 task A giant escalation, Fable5 gdb-on-cc1, 2026-07-11) L3313 +- **§51** — TOOLING INTEGRITY: the silent skip, and how to hunt it L3645 +- **§51b** — Why the byte-gate cannot save you L3667 +- **§51f** — Checklist for any new corpus-scanning tool L3770 +- **§51g** — When the thing you are scanning has a GRAMMAR, parse the grammar (`tools/cdecl.py`) L3784 +- **§53** — SWEEP A FAMILY WITH THE TOOL ITS EXEMPLAR NEEDED: the jr/switch carve, and how omitting it manufactured the "families don't template" doctrine (Phase 28 T1, 2026-07-15) L4043 +- **§55** — Core-crack wave levers + the GATE-ORCHESTRATION law (Phase 29 T3, 13-agent ultracode wave, 2026-07-17) L4108 +- **§55b** — THE GATE-ORCHESTRATION LAW (3 traps, ~3.5h lost; all recovered, 0 data lost) L4137 +- **§55c** — Sizing the propagate: a TARGETED propagate is ~4 min/core, and "it's slow" was a BROKEN-TREE ARTIFACT L4156 +- **§54** — `--fix-def-sig`: the member's CANONICAL DECLARATION is a build step too (tiny-IMM mega-pools, +4,801, Phase 29 T6, 2026-07-16) L4178 +- **§57** — The SELF-decl normalize: the sibling's OWN caller declares the templated fn divergently (the third §17a-1 direction; `tools/normalize_self_decls.py`, func_801670E4 ×137, Phase 29, 2026-07-18) L4271 +- **§61** — Task 14: the gate ladder's missing stage is the ARITY pre-pass, and it is TU-side not draft-side (Phase 29, 2026-07-21) L4560 +- **§61b** — The jtbl gate stage: built, and the ORDERING law it exposed (Phase 29 Task-14 stage 4, 2026-07-21) L4673 +- **§61d** — The undo was eating the tree: two tools, one defect, invisible to the byte-gate (Phase 29, 2026-07-22) L4794 +- **§62** — The jtbl RECONCILE must also follow the carve: the post-carve draft reconcile (`harvest_verify._jtbl_reconcile`, Phase 29 SESSION-11, 2026-07-22) L4848 +- **§65** — The stranded-draft recovery: BLAST-RADIUS TIERS, and the per-overlay de-macroize that refutes §20's DEF-conflict wall (`tools/demacroize.py` + `tools/blocker_probe.py`, Phase 29 SESSION-16, 2026-07-24) L5030 +- **§65d** — Existing-ladder baseline, measured (do this before building a recovery stage) L5106 +- **§65e** — Two oracles, and the disagreement is the finding (R34 in practice) L5116 +- **§65f** — The de-macroize lever's BOUNDARY, measured: byte-neutral 14 times of 15, and the 15th is why the gate exists L5133 +- **§66b** — A metric parsed out of another tool's prose goes NULL silently when the label changes L5215 +- **§67a** — Run the symbol-set guard BEFORE you pay for a gate (`tools/symcheck.py`, Phase 29 SESSION-18) L5420 +- **§77** — Every extraction tool carries a NARROW hard-coded preamble set; anything outside it silently caps the body's reach. Diff the preamble before you gate. (Phase 29 SESSION-19 — three variants in one session, two different tools) L6099 +- **§3-The** — CANDIDATE gate and the REAL gate need DIFFERENT preambles — keep the difference out of the bank L6139 +- **§79** — For a 0-callee giant, fingerprint by DATA symbols (§71 cannot fire); and the STACK-SLOT ORDER is a declaration-order oracle (Phase 29 SESSION-19, `func_8017BF14` 4,763 ins, cold start → 45/4763) L6235 +- **§82** — Two source-shape oracles from behemoth #6: a duplicated `addiu $aN,$sp,K` across a `jal` means the block was INLINED, and scalar-vs-aggregate decides WHEN a stack slot is allocated (Phase 29 SESSION-19, `func_8017C730` 1,061 ins) L6385 +- **§3-2.** — Scalar vs aggregate decides *when* the slot is allocated L6404 +- **§3-Why** — it survived every candidate gate L6510 +- **§3-THE** — FIX IS MECHANICAL — the tool already holds the answer L6525 +- **§87** — `match_one` COMPILES but never LINKS, so an unresolvable data symbol reads as MATCH; and stored drafts go STALE against the tree (Phase 29 SESSION-20) L6648 +- **§88f** — the missing rung: a RELOCATION gate between `match_one` and the binary L6733 +- **§89a** — MEASURE the write set; do not assert its tier (`tools/blast_radius.py`) L6747 +- **§89b** — the parallel gate farm existed; the family path could not reach it (`tools/sweep_parallel.py`) L6760 +- **§90** — Five tool-integrity laws from one session, each of which changed an answer (Phase 29 SESSION-21, 2026-07-27) L6781 +- **§90a** — A comparison tool MUST share its reference oracle's index space, exactly L6787 +- **§92** — Conforming a DECLARATION: pointer changes are caller-neutral, scalar-WIDTH changes are not (Phase 29 SESSION-21, `tools/conform_decls.py`) L6906 +- **§97** — The gate's own tree hygiene: a refused carve, an unchecked recovery, and a snapshot that captured a dirty tree (Phase 29 SESSION-22) L7081 +- **§105** — A gate's revert must survive an EXCEPTION, not just a failure (Phase 29 T53, `jtbl_family_bank`) L7446 +- **§107** — A lever wired into ONE gate path is a lever most families cannot reach (Phase 29 T56, `func_80144090` 0/136 → 136/136) L7528 +- **§3-Why** — it survived so long: a MASKED oracle will MATCH a wrong symbol L7968 +- **§122** — GATE RAW BEFORE TRANSFORMING; the undo belongs to the WRITER, as a per-edit journal (P30 T0a, 2026-07-30) L8099 +- **§123** — PROPAGATE A FAMILY WITH THE TOOL ITS TIER NEEDS: `dedup_propagate` is h_exact-only; its refusals are statements about the TOOL (P30 wave 1, 2026-07-30) L8131 +- **§126a** — a bare `except: continue` around a coverage-asserting oracle re-creates the silent skip (P30 S28) L8332 +- **§130** — An INCREMENTAL build can report BYTE-IDENTICAL for a change the CLEAN build cannot even LINK (P30 S28, the jr pair) L8501 +- **§132** — The `JR-PAIR-IN-ONE-O0-OBJECT` "wall" was TWO instrument defects: a merged-double span the carve could not see, and a truncated object no rule deleted (P30 S29, `func_8013B83C` + `func_8013BD74`) L8585 +- **§133** — The DEFAULT-FILTER class: three times in one session, a tool silently answered a narrower question than the one asked (P30 S1–S3) L8700 +- **§134** — MULTI-LINE BLINDNESS: one root cause, four faces, in `family_remap`'s preamble scanner (P30 S6, 190 zero-crack families) L8726 +- **§3-The** — splitting/merging rules (each closed a residual, byte-gated) L8868 +- **§137a** — A gate verdict has a TIMESTAMP; re-check it against the draft's mtime L9401 +- **§138** — The propagation lanes: a gate refusal is a DECLARATION, and which lever you owe depends on blast radius L9430 +- **§134** — again, in a second tool — and the waiter rule corrected L9541 +- **Reconciling** — a gate-refused draft: which way you edit depends on WHERE the TU's decl is L9580 +- **§139** — A GATE THAT GREPS FOR VERDICTS MUST ASSERT 1:1 ACCOUNTING; and a `--src` filter must not survive a carve (P30 S38, wave 6: 10 of 16 drafts vanished) L9609 +- **§140** — A METRIC IS NOT A MEASUREMENT UNTIL IT IS REPRODUCIBLE FROM THE COMMITTED TREE (P30 S1e: a phantom regression that gated the session's best lever) L9675 +- **§142** — An open stub whose `h_exact` class is MATCHED elsewhere is FREE. Propagate the body; do not gate a draft. (P30 S39, +7,710 ins in two commands) L9793 +- **§3-The** — measurement (do this before any wave; it is ~20 lines and needs no builds) L9805 +- **§155b** — check the TYPE your oracle returns before comparing against it (S45 p5) L10602 +- **§156** — an ORPHANED reconcile poisons the fleet: `dedup_propagate`'s kept edit (S45 p6/p7) L10655 +- **§158** — The RANGE-EXTENDER: a fourth zero-emission asm lever completes the allocno toolkit (P30 S46 tier-3, `func_8017CE58`, 733 ins) L10727 +- **§160** — THE REACH-15 WAVE HARVEST: an align-1 block move, and the instrument that called it a wall (P30 S47) L10908 +- **§161** — THE RETRY-WAVE HARVEST: a jump table indexed from zero, and two allocator traps (P30 S47) L10984 +- **§162** — S48 WAVE-1 HARVEST (P30, 2026-08-11): the reach-ordered sibling campaign's first 12 targets L11029 +- **§163** — S48 WAVES 2-3 HARVEST (P30, 2026-08-11/12): the five that were byte-probed and are actionable L11775 +- **§165** — S48 WAVE-4 HARVEST (P30, 2026-08-12): banked the same day the wave landed L13717 +- **§166** — THE DESTINATION-TU ORACLE (P30 S48): the seven-attempt bug that was never codegen L14930 +- **§167** — S48 WAVE-5/6 HARVEST (P30, 2026-08-12): the saturation point L14986 +- **§176e** — SYMBOL IDENTITY IS COMPUTABLE OFFLINE (P31 S52): `tools/reloc_identity.py` L16880 +- **§3-A.** — The seven under-reporting holes (all in `gate_main`, all the same shape) L17014 +- **§3-C2.** — RECONCILE BEFORE THE FIRST GATE — a parked draft gets HARDER to bank, not easier L17061 +- **§3-D.** — The measured cost shape, and what to build next L17084 +- **§176i** — WHAT A STATIC PRE-GATE CHECK CAN AND CANNOT PROVE (P31 S52, wave Q) L17102 +- **§179** — IDIOMS MINED FROM THE WAVE P/Q JOURNALS (P31 S52, harvest pass) L17341 +- **§179-G** — 🟡 A PIN CAN **CREATE** A COMBINE `LOG_LINK` AND DELETE AN `andi` (sixth RC-5 channel, n=1) L17570 +- **§176c** — MAIN (SLUS_007.26) CANNOT BE GATED INCREMENTALLY L17637 +- **§180** — THE LEFTOVER-DRAFT HARVEST: RE-VERIFY WHAT YOU ALREADY HAVE BEFORE DRAFTING ANYTHING NEW L17828 +- **§180b** — WHAT THE PRE-GATE LADDER ACTUALLY FINDS IN A COLD PILE (the shape of integration debt) L17857 +- **§181** — WHAT A WAVE'S GATE ACTUALLY REJECTS (P31 S53, measured on wave R's 45-draft main pile) L17894 +- **§184** — COMMENT-BLINDNESS IS A DEFECT CLASS, NOT A BUG (P31 S53: three tools, one root cause, one session) L18047 +- **§187** — 🔴 "SAME SOURCE" IS NOT "SAME OBJECT": THE SDK BUILD AND THE GAME BUILD DISAGREE ON GTE NOPS L18153 +- **§190** — THREE PRESCRIPTIONS FROM THE SAME HARVEST (weaker evidence than §189, honestly labelled) L18316 +- **§191** — WHAT THIS HARVEST DID **NOT** BANK (4 rejected, 4 narrowed) — recorded so it is not re-derived L18353 +- **§192** — THE PRE-GATE LADDER WAS MAIN-ONLY, AND NOBODY COULD SEE IT (P31 S54) L18375 +- **§193** — THE WAVE-T HARVEST (P31 S54): 71 index_gap reports -> 9 laws, 5 rejected, 61 already-covered L18440 +- **§193-A** — The wave card ships only OPEN-set pointers and discards the atlas's BANKED one — `exemplar`/`sibs` are stubs 100% by construction (tools/atlas.py:96/657), while `seed.ref` (matched pool, atlas.py:505-536) is dropped at build_wave_atlas.py:143 L18457 +- **§193-G** — §164-54's "scope to ≥4 arms" bound is byte-wrong — the dispatch-topology oracle goes live at THREE case nodes (`balance_case_nodes` splits at `i > 2`), but only for a signed-after-promotion index L18761 +- **§193-I** — A DECLARED AGGREGATE LOCAL HAS AN 8-BYTE FRAME STRIDE — CEIL(size,8), NOT size. N ARRAYS THEREFORE COST 8·k MORE THAN ONE HAND-LAID STRUCT (k = how many of them have size mod 8 ≠ 0), AND THE TELL IS IDENTICAL INSTRUCTION COUNT WITH EVERY $sp DISPLACEMENT SHIFTED BY THE SAME CONSTANT. L18862 +- **§193-REJECTED** — what this harvest did NOT bank (recorded so it is not re-derived) L18921 +- **§194** — THE WAVE-U HARVEST (P31 S54): 64 index_gap reports -> 14 laws, 5 rejected, 44 already-covered L18948 +- **§194-E** — The wave card's `exemplar` is the TARGET ITSELF on 42/73 wave-U and 36/71 wave-T cards — a construction consequence of `atlas.py:657` (exemplar = max-nins OPEN member) meeting `build_wave_atlas.py:166` (one card per gid); and the shipped §193-A `seed_ref` is same-binary on 0/51, so no card field can ever name a destination-TU sibling L19173 +- **§194-G** — Reading the integer half of a 16.16 stack aggregate: REGISTER-LIVENESS, not the C spelling, decides `sra` vs `lhu` — and the break is count-neutral L19283 +- **§194-K** — Blind sched1's alias oracle with a second SET of a pointer pseudo — the first zero-byte, non-volatile, dependence-CREATING lever (corrects §167-05's "volatile is the only door"; fourth consumer of reg_n_sets) L19459 +- **§194-REJECTED** — what this harvest did NOT bank (recorded so it is not re-derived) L19703 +- **§195** — THE WAVE-V HARVEST (P31 S54): 67 index_gap reports -> 14 laws, 9 rejected, 76 already-covered L19724 +- **§195-I** — §145(b) AMENDED — the pointer-bump `addiu` is saved by cse, not combine: ANY second SET of a pseudo in the address's equivalence chain (in-place `p += K`, §145(b)'s `p = r;` copy, or an asm re-tie) kills the fold; the pass is cse and the gate is `invalidate`'s `reg_tick++` L20172 +- **§195-M** — Frame `vars` is a SEQUENTIAL bump-allocation, not a flat sum: §193-I's CEIL(aggregate,8) term and §165-03/§167-06's 8×orphan term are the SAME frame_offset walk at two different compiler stages, and each stage re-CEILs frame_offset to 8 before it allocates L20385 +- **§195-REJECTED** — what this harvest did NOT bank (recorded so it is not re-derived) L20481 +- **§197** — THE WAVE-W HARVEST (P31 S54): 68 index_gap reports -> 4 laws, 3 rejected, 41 already-covered L20582 +- **§199** — THE WAVE-X HARVEST (P31 S54/S55): 63 index_gap reports -> 7 laws, 2 rejected, 56 already-covered L20722 +- **§199-C** — A NEGATIVE CONSTANT MULTIPLY ALWAYS TAKES expmed's negate_variant — but whether you ever SEE the neg is decided by COMBINE, and for an EVEN |K| it never disappears L20827 +- **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` L20875 +- **§199-G** — At TWO case nodes the switch-vs-if oracle is not blind — but the tell is ALL tests positive + a trailing `j default`, NOT the first test's polarity L21048 +- **§201** — THE WAVE-Y HARVEST (P31 S55): 67 gap reports -> 5 laws, 8 rejected, 53 already-covered L21163 +- **§204** — THE WAVE-Z HARVEST (P31 S56): 82 gap reports -> 5 laws, 16 rejected, 30 already-covered L21562 +- **§207** — THE WAVE ab–ag HARVEST (P31 S58): 278 byte-banked notes → 25 laws, 103 self-reported no-gap L22196 +- **§233** — THE WAVE aa–bg HARVEST (P31 S58b): 1,101 byte-banked notes → 24 new laws, 21 addenda, ~700 already-covered L23287 +- **§236** — THE DECLARATION LAYER IS THE DOMINANT BANK-BLOCKER: NINE WAYS A BYTE-PERFECT BODY FAILS THE GATE (P31 S58b) L23401 +- **§247** — TWO BRANCHES TO **ONE** LABEL MEANS THE SOURCE CONDITION IS NEGATED (P31 S58b) L23847 +- **§254** — THE DEAD PARAMETER IS A REGISTER-PLACEMENT TOOL **(single observation — not yet cross-confirmed)** (P31 S58b) L24041 +- **§259** — THE DISCARD LEDGER FOR THE aa–bg HARVEST (P31 S58b): WHAT WAS MINED AND REJECTED, AND WHY L24698 +- **§260-A** — STAGE 2 IS PROVEN, AND THE WHOLE jtbl PIPELINE IS AUTOMATED AT THE GATE (P31 S59, same day) L24787 +- **§261** — THE -O0 ORACLE: DERIVE THE OPT LEVEL FROM THE TARGET, AND `$fp` IS NOT THE TELL (P31 S59) L24823 +- **§267** — ADDENDA HARVESTED FROM WAVES at/bh/bk/bl (P31 S59b) L25094 +- **ADD-9** — → §213-3 / §217 addendum — ADJACENT PRE-CALL FRAME STORES ARE ONE AGGREGATE; THE UNESCAPED SCALAR NEIGHBOR IS DEAD-STORED L25189 +- **§269** — ADDENDA HARVESTED FROM WAVES ax/bm (P31 S59c) L25313 +- **§271** — Ordinal IMM pairing: text order is NOT emission order; emit CANDIDATES, let the oracle pick (P31 S59) L25551 +- **§273** — A standalone compile is the WRONG oracle for a TU-destined draft (P31 S59) L25593 +- **§274** — ADDENDA HARVESTED FROM 18 WAVES (P31 S60): 315 candidates, 255 already covered, 21 sharpenings, 3 new laws L25608 +- **§278** — ADDENDA HARVESTED FROM WAVE cf (P31 S60): 34 candidates, 13 already covered, 8 sharpenings, 4 new laws L26599 +- **§283** — ADDENDA HARVESTED FROM THE 36-WAVE BATCH (P31 S60): 1,216 candidates, 859 already covered, 46 sharpenings, 9 new laws L27095 +- **§287** — A STACK-FRAME HOLE BELOW TWO ADDRESS-TAKEN AGGREGATE LOCALS IS A LEADING PAD MEMBER OF ONE COMBINED STRUCT, NOT SEPARATE LOCALS OR A REGISTER PIN (P31 S60/dj; `func_8017D104`, ov_SC06_027, byte-proven 47/47) (P31 S60; waves #, byte-proven) L29060 +- **§293** — THE "WHOLE-OBJECT GATE NEEDS EVERY SIBLING" LAW, WRITTEN PROPERLY: IT IS THREE LAWS, AND THE LOAD-BEARING ONE IS "THE BASELINE, NOT THE SIBLINGS" (P31 S61; byte-proven on 15 binaries in one night) L29083 +- **§294** — ADDENDA HARVESTED FROM THE S61 GEN0/MAXTOK/MAIN/DEEPSEEK BATCH (waves ab8/ab16/ab24/ab32 · g0a–g0f · m0a · ds1/ds2): 99 candidates, 52 covered, 15 notes → 10 addenda, 29 notes → 5 new laws (§295–§299), 3 refuted L29133 +- **§303** — MODULE ISLAND TABLES: DERIVE THE PADS AT BUILD TIME, PEEL NOTHING — THE §154-A/§260 "island-pads"/"island-blocked" WALLS DISSOLVE (P31 S62 T3a; byte-proven md_SC03_076 func_801F0A9C + func_801F0F28, sha 9a165e36…) L29737 +- **§305** — "CARVE-REFUSED" AT GATE TIME IS THREE NAMED, DETERMINISTIC CLASSES — NONE OF THEM A CARVE (P31 S62 T3; 28 resolver drafts autopsied 28/28) L29796 ### process, measurement & doctrine (107) @@ -1004,103 +1007,103 @@ - **§3-h** — _exact OVER-COUNTS ×134 — verify shareability before crediting a class's "reach-134" (R14) L2177 - **§28c** — The close=0 recovery is NOT fully exhausted (§26 corrected, R14); + the dedup_propagate registry-skip recovery (Phase 22 T2) L2352 - **§31-triage** — R17 applies to CODEGEN residuals, never to a compile ERROR (Phase 26 session 7, Drew asked) L2693 -- **§41a** — v3.1: the def-side wall was ~71% TOOL-shaped — the five measured defects + the laws that dissolve them (Phase 25 T6, Fable5, 2026-07-09) L2754 -- **§41b** — T7 execution: the object-only probe OVER-counts BANKABLE by two link/rodata classes (Phase 25 T7-M1, 2026-07-10) L2809 -- **§41b** — addendum — M4 "reconcile_decls" tier is ALSO a probe over-count: 0/8 mechanical (Phase 25 T7-M4, 2026-07-10) L2858 -- **§53** — SWEEP A FAMILY WITH THE TOOL ITS EXEMPLAR NEEDED: the jr/switch carve, and how omitting it manufactured the "families don't template" doctrine (Phase 28 T1, 2026-07-15) L4028 -- **§3-The** — meta-lesson (R35, and why this one is expensive) L4078 -- **§55** — Core-crack wave levers + the GATE-ORCHESTRATION law (Phase 29 T3, 13-agent ultracode wave, 2026-07-17) L4093 -- **§55b** — THE GATE-ORCHESTRATION LAW (3 traps, ~3.5h lost; all recovered, 0 data lost) L4122 -- **§57a** — Two NSD corrections + the SURGICAL-ONLY law + the honest broad-sweep yield (Phase 29, 2026-07-18) L4303 -- **§58** — match_one MATCH ≠ BANK: the four blind spots + the crack-wave reconcile-before-bank law (Phase 29 crack-wave, 2026-07-18) L4343 -- **§60** — Classify the residual, don't rank it: the deterministic residual→class classifier and what it measured about the backlog (Phase 29 Task-13A, 2026-07-21) L4407 -- **What** — it measured — the whole open backlog, byte-grounded L4431 -- **§3-The** — parallel-probe race this surfaced L4463 -- **§61b** — The jtbl gate stage: built, and the ORDERING law it exposed (Phase 29 Task-14 stage 4, 2026-07-21) L4658 -- **§62** — The jtbl RECONCILE must also follow the carve: the post-carve draft reconcile (`harvest_verify._jtbl_reconcile`, Phase 29 SESSION-11, 2026-07-22) L4833 -- **§63** — UPDATE (Phase 29 SESSION-14) — `fix_header_decl`'s "SAFE" verdict is FLEET-BLIND; it MUST be R22-validated L5000 -- **§65** — The stranded-draft recovery: BLAST-RADIUS TIERS, and the per-overlay de-macroize that refutes §20's DEF-conflict wall (`tools/demacroize.py` + `tools/blocker_probe.py`, Phase 29 SESSION-16, 2026-07-24) L5015 -- **§65a** — The blast-radius taxonomy (makes §61's law structural instead of remembered) L5030 -- **§65d** — Existing-ladder baseline, measured (do this before building a recovery stage) L5091 -- **§65e** — Two oracles, and the disagreement is the finding (R34 in practice) L5101 -- **§65f** — The de-macroize lever's BOUNDARY, measured: byte-neutral 14 times of 15, and the 15th is why the gate exists L5118 -- **§66c** — Before a wave, verify the FUEL exists; an "already attempted" set built from the wrong directory lies in BOTH directions L5217 -- **§66d-5** — `residual_class`'s "structural ⇒ permuter CPU is waste" is WRONG for schedule permutations (measured, Phase 29 SESSION-18) L5491 -- **§3-The** — honest fix was source-level and cheap L5750 -- **§3-The** — residual, and the honest read L6260 -- **§83** — The parameterised-repeat law, the spill-area trap, and why a per-case edit cannot move a per-case symptom (Phase 29 SESSION-20, `func_80183814` 5,122 ins, cold-ish start → 36 structural / 99.3%) L6412 -- **Scope** — , measured (do not over-generalise — §80) L6518 -- **§3-Two** — ladder lessons banked with it L6528 -- **§3-Do** — the WHOLE axis in one edit, then R22 once L6567 -- **§3-THE** — LAW: all-or-nothing PER FAMILY L6600 -- **§88b** — the `slti` literal-position law (extends §78 to comparisons) L6686 -- **§88e** — a wrong diagnosis, refuted properly (the model for how to treat an inherited lever) L6708 -- **§89a** — MEASURE the write set; do not assert its tier (`tools/blast_radius.py`) L6732 -- **§90d** — Do not measure a live wave's drafts (§87 in real time) L6810 -- **§98** — `conform_decls` had three defects, and only the third needed R22 to find (Phase 29 SESSION-22, `func_8014CF04`) L7113 -- **§106** — Persist the MEASUREMENT, derive the POLICY: a stored route let a stale file out-vote the live table (Phase 29 T54, `residual_class._ROUTE`) L7470 -- **§125** — Split the CARVE from the BODY before calling a jr residue a wall — and measure it by SHA from a CLEAN tree (P30 SESSION-28; **this section's first draft was WRONG and the method caught it**) L8206 -- **§3-The** — meta-lesson L8257 -- **Wave** — economics (measured, for the next batch's sizing) L8953 -- **§136b** — A prior wave's "genuine byte-DIFF" verdict is NOT reliable evidence (4 of 4 refuted) L9033 -- **§136g** — When the index points at the WRONG lever: two byte-refuted routings (func_801863B4) L9211 -- **§136h** — CORRECTION: the zero-crack pool does NOT "refill with cheap work" (my error, byte-measured) L9240 -- **§136j** — The failure MIX flips with function size (measured across four bands, one session) L9302 -- **Rank** — the lane by measured concentration, not by class count L9481 -- **§140** — A METRIC IS NOT A MEASUREMENT UNTIL IT IS REPRODUCIBLE FROM THE COMMITTED TREE (P30 S1e: a phantom regression that gated the session's best lever) L9660 -- **§3-The** — measurement (do this before any wave; it is ~20 lines and needs no builds) L9790 -- **§3-And** — the report-vs-bytes lesson attached to it L9822 -- **§146** — RE-MEASURE A WALL BEFORE YOU RESPECT IT. Both "permanent" giants fell to drafts already on disk. (P30 S6, +50,094 ins) L9977 -- **§147** — The three-stratum FRAME LAW, and four "stop searching" verdicts (P30 S42, `func_8017C294`, serial run) L10036 -- **§3-C.** — Inner-block declaration does NOT delay slot allocation — BYTE-REFUTED L10068 -- **§3-D.** — "Cheap fuel" that was never probed: 0 of 31 templatable L10293 -- **§3-Two** — corrections to the record L10345 -- **§3-The** — two fallouts, and how to close them (both measured, in order) L10395 -- **What** — does NOT work (14 byte-measured probes) L10486 -- **§157** — the cheap-tier size cliff, measured (S45 p6) L10687 -- **§162** — The cross-jump "CALL veto" is a COUNT law, not a CALL law (BOUNDS §88a; P30 S48, `func_80189540`) L11302 -- **§3-The** — law L11549 -- **DIAGNOSTIC** — TELL — two faces, one law L11591 -- **§163** — S48 WAVES 2-3 HARVEST (P30, 2026-08-11/12): the five that were byte-probed and are actionable L11760 -- **§163z** — THE UNVETTED REMAINDER (do not cite as law; each needs a dedupe pass) L11828 -- **§164z** — REFUTED CLAIMS: do NOT re-derive these L13636 -- **§165z** — REFUTED THIS WAVE: do NOT re-derive L14871 -- **§167z** — REFUTED IN WAVES 5/6: do NOT re-derive L16167 -- **§168** — THE COUSIN TIER (P30 S49, 2026-08-12): h_seq's exact-hash brittleness, measured — and the similarity map above it L16224 -- **§176g** — SIZE A WAVE BY INSTRUCTIONS, NOT BY CARDS (P31 S52 — the adopted doctrine) L16953 -- **§176h** — THE BATCH-SUBSTITUTION HAZARD MAP (P31 S52): seven holes, three wrong fixes, one law L16991 -- **§3-D.** — The measured cost shape, and what to build next L17069 -- **§176j-2** — THE REPAIR PASS, MEASURED (do this instead of resuming) L17145 -- **§176-C** — 🔴 WALL REFUTATION: a hard-register pin CANNOT schedule around a call, because of a genuine gcc-2.7.2 bug L17709 -- **§176-E** — Two cheap source spellings, both cc1-probed L17761 -- **§180** — THE LEFTOVER-DRAFT HARVEST: RE-VERIFY WHAT YOU ALREADY HAVE BEFORE DRAFTING ANYTHING NEW L17813 -- **§181** — WHAT A WAVE'S GATE ACTUALLY REJECTS (P31 S53, measured on wave R's 45-draft main pile) L17879 -- **§182** — §177's HONEST NEGATIVE: the epilogue lever cracked 4 of 16, and the `800c3` cluster held L17935 -- **§183** — THE DECLARATION-RECONCILIATION PLAYBOOK (P31 S53, measured on 20 byte-verified drafts) L17961 -- **§185** — EDIT THE SIDE THAT IS CHEAP TO VERIFY, AND CHECK A TU RETYPE AT ITS USE SITES L18060 -- **§190** — THREE PRESCRIPTIONS FROM THE SAME HARVEST (weaker evidence than §189, honestly labelled) L18301 -- **§194-A** — A zero-byte scheduling fence goes AFTER the defining statement to make that computation emit FIRST in its block — and the barrier predicate is `volatile`-or-colon-less, not the `"memory"` clobber (COMPLEMENTS §165-40; does not refute it) L18950 -- **§194-D** — Declared width of a computed-value local is a sched1 dial (count-neutral) — a replication + attribution correction of §165-17, NOT a new argument-register law L19117 -- **§195-J** — GTE / PsyQ op CALL-vs-INLINE is a PER-SITE SOURCE FACT, not a TU style — both forms coexist in one TU (measured in 2 TUs), and the tell is the target's own opcodes (`lwc2`/`sqr`/`swc2` vs `jal`), not the sibling. Costs -8 ins on func_8018505C. Corollary: the game's inline `sqr` macro emits TWO hazard nops, the SDK's `Square0` body emits ONE — so the inline form is provably not `Square0` inlined (a second instance of §187's SDK-vs-game GTE nop divergence). L20222 -- **§201-E** — §194-J-2 — The `last_mem_set` deletion window is measured in SOURCE/expand order, not in the printed stream; a foreign store moved between the pair in C source is a real lever, and `volatile` is not always the better one L21368 -- **§230** — THE ANCHOR PROBE: with `%hi`/`%lo` masked, the surviving `addiu` deltas tell you which assignment was written first **(single observation — not yet cross-confirmed)** (P31 S58) L23124 -- **§257** — THE DEAD-END LEDGER (P31 S58b): ELEVEN LEVERS THAT MEASURED NULL OR BACKFIRED L24110 -- **§194-B** — / §209 addendum (P31 S58b) — TWO MORE INSTANCES, AND THE BOUND IS NOW REFUTED FOUR WAYS L24179 -- **§266** — THE INERT-RIDER LAW: A LEVER IS ONLY CITABLE WHEN ITS SOLO REMOVAL BREAKS THE MATCH (P31 S59b; measured 4-of-8 on this batch) L25039 -- **ADD-4** — → §167-37 addendum — THE FIFTH PRECONDITION, NOW MEASURED: DOWNSTREAM FIELD RE-READS ⇒ NAME IT **AND** STORE **INSIDE** THE ARM L25353 -- **ADD-9** — → §255 "AND CASE-BODY PLACEMENT" bound / §222-addendum-3 — ON A LARGE SPARSE TREE, BODIES FOLLOW **SOURCE** ORDER (measured by a one-word probe) L25430 -- **ADDENDUM** — to §172b-1 — TWO PLACEMENT DIALS THE PROMOTION LAW DOESN'T NAME: NARROW THE COUNTER'S DECLARED TYPE, AND MOVE THE CAST INTO THE LOOP BODY L26059 -- **What** — I could not verify L27033 -- **ADDENDUM** — to §164-75 — the fold-reassociation law also fires at a variable's INITIALIZER, not only a later expression L27090 -- **What** — I could not verify L27607 -- **ADDENDUM** — to §153 / §236-5 (func_801A419C, md_SC07_003 — waves di and dl, corroborating; refutes a contradicted dj-wave card) L27824 -- **What** — I could not verify L28064 -- **ADDENDUM** — to §174 Law 4 (func_8017E9A8, ov_SC06_015) L28084 -- **ADDENDUM** — the zero-emission-asm family gains a REF-SLIDER PLACEMENT LAW and a paired RESTORER (func_800CB900, md_MAIN_026) L28124 -- **What** — I could not verify L28622 -- **What** — I could not verify L28928 -- **§293** — THE "WHOLE-OBJECT GATE NEEDS EVERY SIBLING" LAW, WRITTEN PROPERLY: IT IS THREE LAWS, AND THE LOAD-BEARING ONE IS "THE BASELINE, NOT THE SIBLINGS" (P31 S61; byte-proven on 15 binaries in one night) L29068 -- **§294** — ADDENDA HARVESTED FROM THE S61 GEN0/MAXTOK/MAIN/DEEPSEEK BATCH (waves ab8/ab16/ab24/ab32 · g0a–g0f · m0a · ds1/ds2): 99 candidates, 52 covered, 15 notes → 10 addenda, 29 notes → 5 new laws (§295–§299), 3 refuted L29118 +- **§41a** — v3.1: the def-side wall was ~71% TOOL-shaped — the five measured defects + the laws that dissolve them (Phase 25 T6, Fable5, 2026-07-09) L2769 +- **§41b** — T7 execution: the object-only probe OVER-counts BANKABLE by two link/rodata classes (Phase 25 T7-M1, 2026-07-10) L2824 +- **§41b** — addendum — M4 "reconcile_decls" tier is ALSO a probe over-count: 0/8 mechanical (Phase 25 T7-M4, 2026-07-10) L2873 +- **§53** — SWEEP A FAMILY WITH THE TOOL ITS EXEMPLAR NEEDED: the jr/switch carve, and how omitting it manufactured the "families don't template" doctrine (Phase 28 T1, 2026-07-15) L4043 +- **§3-The** — meta-lesson (R35, and why this one is expensive) L4093 +- **§55** — Core-crack wave levers + the GATE-ORCHESTRATION law (Phase 29 T3, 13-agent ultracode wave, 2026-07-17) L4108 +- **§55b** — THE GATE-ORCHESTRATION LAW (3 traps, ~3.5h lost; all recovered, 0 data lost) L4137 +- **§57a** — Two NSD corrections + the SURGICAL-ONLY law + the honest broad-sweep yield (Phase 29, 2026-07-18) L4318 +- **§58** — match_one MATCH ≠ BANK: the four blind spots + the crack-wave reconcile-before-bank law (Phase 29 crack-wave, 2026-07-18) L4358 +- **§60** — Classify the residual, don't rank it: the deterministic residual→class classifier and what it measured about the backlog (Phase 29 Task-13A, 2026-07-21) L4422 +- **What** — it measured — the whole open backlog, byte-grounded L4446 +- **§3-The** — parallel-probe race this surfaced L4478 +- **§61b** — The jtbl gate stage: built, and the ORDERING law it exposed (Phase 29 Task-14 stage 4, 2026-07-21) L4673 +- **§62** — The jtbl RECONCILE must also follow the carve: the post-carve draft reconcile (`harvest_verify._jtbl_reconcile`, Phase 29 SESSION-11, 2026-07-22) L4848 +- **§63** — UPDATE (Phase 29 SESSION-14) — `fix_header_decl`'s "SAFE" verdict is FLEET-BLIND; it MUST be R22-validated L5015 +- **§65** — The stranded-draft recovery: BLAST-RADIUS TIERS, and the per-overlay de-macroize that refutes §20's DEF-conflict wall (`tools/demacroize.py` + `tools/blocker_probe.py`, Phase 29 SESSION-16, 2026-07-24) L5030 +- **§65a** — The blast-radius taxonomy (makes §61's law structural instead of remembered) L5045 +- **§65d** — Existing-ladder baseline, measured (do this before building a recovery stage) L5106 +- **§65e** — Two oracles, and the disagreement is the finding (R34 in practice) L5116 +- **§65f** — The de-macroize lever's BOUNDARY, measured: byte-neutral 14 times of 15, and the 15th is why the gate exists L5133 +- **§66c** — Before a wave, verify the FUEL exists; an "already attempted" set built from the wrong directory lies in BOTH directions L5232 +- **§66d-5** — `residual_class`'s "structural ⇒ permuter CPU is waste" is WRONG for schedule permutations (measured, Phase 29 SESSION-18) L5506 +- **§3-The** — honest fix was source-level and cheap L5765 +- **§3-The** — residual, and the honest read L6275 +- **§83** — The parameterised-repeat law, the spill-area trap, and why a per-case edit cannot move a per-case symptom (Phase 29 SESSION-20, `func_80183814` 5,122 ins, cold-ish start → 36 structural / 99.3%) L6427 +- **Scope** — , measured (do not over-generalise — §80) L6533 +- **§3-Two** — ladder lessons banked with it L6543 +- **§3-Do** — the WHOLE axis in one edit, then R22 once L6582 +- **§3-THE** — LAW: all-or-nothing PER FAMILY L6615 +- **§88b** — the `slti` literal-position law (extends §78 to comparisons) L6701 +- **§88e** — a wrong diagnosis, refuted properly (the model for how to treat an inherited lever) L6723 +- **§89a** — MEASURE the write set; do not assert its tier (`tools/blast_radius.py`) L6747 +- **§90d** — Do not measure a live wave's drafts (§87 in real time) L6825 +- **§98** — `conform_decls` had three defects, and only the third needed R22 to find (Phase 29 SESSION-22, `func_8014CF04`) L7128 +- **§106** — Persist the MEASUREMENT, derive the POLICY: a stored route let a stale file out-vote the live table (Phase 29 T54, `residual_class._ROUTE`) L7485 +- **§125** — Split the CARVE from the BODY before calling a jr residue a wall — and measure it by SHA from a CLEAN tree (P30 SESSION-28; **this section's first draft was WRONG and the method caught it**) L8221 +- **§3-The** — meta-lesson L8272 +- **Wave** — economics (measured, for the next batch's sizing) L8968 +- **§136b** — A prior wave's "genuine byte-DIFF" verdict is NOT reliable evidence (4 of 4 refuted) L9048 +- **§136g** — When the index points at the WRONG lever: two byte-refuted routings (func_801863B4) L9226 +- **§136h** — CORRECTION: the zero-crack pool does NOT "refill with cheap work" (my error, byte-measured) L9255 +- **§136j** — The failure MIX flips with function size (measured across four bands, one session) L9317 +- **Rank** — the lane by measured concentration, not by class count L9496 +- **§140** — A METRIC IS NOT A MEASUREMENT UNTIL IT IS REPRODUCIBLE FROM THE COMMITTED TREE (P30 S1e: a phantom regression that gated the session's best lever) L9675 +- **§3-The** — measurement (do this before any wave; it is ~20 lines and needs no builds) L9805 +- **§3-And** — the report-vs-bytes lesson attached to it L9837 +- **§146** — RE-MEASURE A WALL BEFORE YOU RESPECT IT. Both "permanent" giants fell to drafts already on disk. (P30 S6, +50,094 ins) L9992 +- **§147** — The three-stratum FRAME LAW, and four "stop searching" verdicts (P30 S42, `func_8017C294`, serial run) L10051 +- **§3-C.** — Inner-block declaration does NOT delay slot allocation — BYTE-REFUTED L10083 +- **§3-D.** — "Cheap fuel" that was never probed: 0 of 31 templatable L10308 +- **§3-Two** — corrections to the record L10360 +- **§3-The** — two fallouts, and how to close them (both measured, in order) L10410 +- **What** — does NOT work (14 byte-measured probes) L10501 +- **§157** — the cheap-tier size cliff, measured (S45 p6) L10702 +- **§162** — The cross-jump "CALL veto" is a COUNT law, not a CALL law (BOUNDS §88a; P30 S48, `func_80189540`) L11317 +- **§3-The** — law L11564 +- **DIAGNOSTIC** — TELL — two faces, one law L11606 +- **§163** — S48 WAVES 2-3 HARVEST (P30, 2026-08-11/12): the five that were byte-probed and are actionable L11775 +- **§163z** — THE UNVETTED REMAINDER (do not cite as law; each needs a dedupe pass) L11843 +- **§164z** — REFUTED CLAIMS: do NOT re-derive these L13651 +- **§165z** — REFUTED THIS WAVE: do NOT re-derive L14886 +- **§167z** — REFUTED IN WAVES 5/6: do NOT re-derive L16182 +- **§168** — THE COUSIN TIER (P30 S49, 2026-08-12): h_seq's exact-hash brittleness, measured — and the similarity map above it L16239 +- **§176g** — SIZE A WAVE BY INSTRUCTIONS, NOT BY CARDS (P31 S52 — the adopted doctrine) L16968 +- **§176h** — THE BATCH-SUBSTITUTION HAZARD MAP (P31 S52): seven holes, three wrong fixes, one law L17006 +- **§3-D.** — The measured cost shape, and what to build next L17084 +- **§176j-2** — THE REPAIR PASS, MEASURED (do this instead of resuming) L17160 +- **§176-C** — 🔴 WALL REFUTATION: a hard-register pin CANNOT schedule around a call, because of a genuine gcc-2.7.2 bug L17724 +- **§176-E** — Two cheap source spellings, both cc1-probed L17776 +- **§180** — THE LEFTOVER-DRAFT HARVEST: RE-VERIFY WHAT YOU ALREADY HAVE BEFORE DRAFTING ANYTHING NEW L17828 +- **§181** — WHAT A WAVE'S GATE ACTUALLY REJECTS (P31 S53, measured on wave R's 45-draft main pile) L17894 +- **§182** — §177's HONEST NEGATIVE: the epilogue lever cracked 4 of 16, and the `800c3` cluster held L17950 +- **§183** — THE DECLARATION-RECONCILIATION PLAYBOOK (P31 S53, measured on 20 byte-verified drafts) L17976 +- **§185** — EDIT THE SIDE THAT IS CHEAP TO VERIFY, AND CHECK A TU RETYPE AT ITS USE SITES L18075 +- **§190** — THREE PRESCRIPTIONS FROM THE SAME HARVEST (weaker evidence than §189, honestly labelled) L18316 +- **§194-A** — A zero-byte scheduling fence goes AFTER the defining statement to make that computation emit FIRST in its block — and the barrier predicate is `volatile`-or-colon-less, not the `"memory"` clobber (COMPLEMENTS §165-40; does not refute it) L18965 +- **§194-D** — Declared width of a computed-value local is a sched1 dial (count-neutral) — a replication + attribution correction of §165-17, NOT a new argument-register law L19132 +- **§195-J** — GTE / PsyQ op CALL-vs-INLINE is a PER-SITE SOURCE FACT, not a TU style — both forms coexist in one TU (measured in 2 TUs), and the tell is the target's own opcodes (`lwc2`/`sqr`/`swc2` vs `jal`), not the sibling. Costs -8 ins on func_8018505C. Corollary: the game's inline `sqr` macro emits TWO hazard nops, the SDK's `Square0` body emits ONE — so the inline form is provably not `Square0` inlined (a second instance of §187's SDK-vs-game GTE nop divergence). L20237 +- **§201-E** — §194-J-2 — The `last_mem_set` deletion window is measured in SOURCE/expand order, not in the printed stream; a foreign store moved between the pair in C source is a real lever, and `volatile` is not always the better one L21383 +- **§230** — THE ANCHOR PROBE: with `%hi`/`%lo` masked, the surviving `addiu` deltas tell you which assignment was written first **(single observation — not yet cross-confirmed)** (P31 S58) L23139 +- **§257** — THE DEAD-END LEDGER (P31 S58b): ELEVEN LEVERS THAT MEASURED NULL OR BACKFIRED L24125 +- **§194-B** — / §209 addendum (P31 S58b) — TWO MORE INSTANCES, AND THE BOUND IS NOW REFUTED FOUR WAYS L24194 +- **§266** — THE INERT-RIDER LAW: A LEVER IS ONLY CITABLE WHEN ITS SOLO REMOVAL BREAKS THE MATCH (P31 S59b; measured 4-of-8 on this batch) L25054 +- **ADD-4** — → §167-37 addendum — THE FIFTH PRECONDITION, NOW MEASURED: DOWNSTREAM FIELD RE-READS ⇒ NAME IT **AND** STORE **INSIDE** THE ARM L25368 +- **ADD-9** — → §255 "AND CASE-BODY PLACEMENT" bound / §222-addendum-3 — ON A LARGE SPARSE TREE, BODIES FOLLOW **SOURCE** ORDER (measured by a one-word probe) L25445 +- **ADDENDUM** — to §172b-1 — TWO PLACEMENT DIALS THE PROMOTION LAW DOESN'T NAME: NARROW THE COUNTER'S DECLARED TYPE, AND MOVE THE CAST INTO THE LOOP BODY L26074 +- **What** — I could not verify L27048 +- **ADDENDUM** — to §164-75 — the fold-reassociation law also fires at a variable's INITIALIZER, not only a later expression L27105 +- **What** — I could not verify L27622 +- **ADDENDUM** — to §153 / §236-5 (func_801A419C, md_SC07_003 — waves di and dl, corroborating; refutes a contradicted dj-wave card) L27839 +- **What** — I could not verify L28079 +- **ADDENDUM** — to §174 Law 4 (func_8017E9A8, ov_SC06_015) L28099 +- **ADDENDUM** — the zero-emission-asm family gains a REF-SLIDER PLACEMENT LAW and a paired RESTORER (func_800CB900, md_MAIN_026) L28139 +- **What** — I could not verify L28637 +- **What** — I could not verify L28943 +- **§293** — THE "WHOLE-OBJECT GATE NEEDS EVERY SIBLING" LAW, WRITTEN PROPERLY: IT IS THREE LAWS, AND THE LOAD-BEARING ONE IS "THE BASELINE, NOT THE SIBLINGS" (P31 S61; byte-proven on 15 binaries in one night) L29083 +- **§294** — ADDENDA HARVESTED FROM THE S61 GEN0/MAXTOK/MAIN/DEEPSEEK BATCH (waves ab8/ab16/ab24/ab32 · g0a–g0f · m0a · ds1/ds2): 99 candidates, 52 covered, 15 notes → 10 addenda, 29 notes → 5 new laws (§295–§299), 3 refuted L29133 ### (unbucketed — title matched no symptom vocabulary) (288) @@ -1129,269 +1132,269 @@ - **§28a** — decomp.wiki GCC patterns worth trying on BFM giants (decomp.wiki/compilers/GCC, raw at decompals/decompedia; PS1-applicable subset) L2345 - **§31** — THE gcc-2.7.2 CODEGEN MAP: pass → residual → C-lever catalog (Phase 23; 4 Fable5 agents read the compiler source) L2402 - **§36** — Fable5 giant-crack levers (Phase 24 T7 Fable5 batch; accumulates as each lands — full RTL dumps in `.run/t7/fable/`) L2487 -- **§42d** — addendum — wave 4 (rtu_match fan-out over the mapped frontier, 2026-07-10c): 24/26 MATCH, +5 durable levers L3082 -- **§3-B.** — THE EBB RULE — the general form of §46-L2 L3468 -- **§3-E.** — Meta L3518 -- **§50** — Refinements that BOUND §47/§48 (from the `func_80135EB0` wall, 21→6; Phase 26 session 8) L3576 -- **§51a** — The bug class L3636 -- **§51c** — THE METHOD (do not audit by reading the regex) L3662 -- **§51d** — THE LAWS L3677 -- **§51e** — The false-wall pipeline (why this is not just hygiene) L3739 -- **§3-Why** — the wall is (probably) intrinsic L3945 -- **§3-The** — case L4033 -- **§3-The** — rule L4062 -- **§55a** — New byte-proven levers (each from a banked or near draft) L4098 -- **§60a** — What the first DIRECTED grinder run exposed (Phase 29 Task-13B, 2026-07-21) L4472 -- **§60b** — The plateau autopsy's verdict: a `partial` drift is a WRONG DRAFT, not a missing transform (Phase 29 Task-13B close, 2026-07-21) L4510 -- **§66** — Exercise a banking driver's SUCCESS path before pointing it at a wave: the free re-bank test (Phase 29 SESSION-17, 2026-07-24) L5159 -- **§66d-2** — Two operational sharp edges L5289 -- **§66d-3** — Read the ILS per-cycle SERIES, not its final best: a repeated score and a still-falling one look identical in a summary line and mean opposite things L5300 -- **§67** — The arg-copy PLACEMENT lever: launder a parameter into a fresh pseudo AT the statement where the target's copy lands (Phase 29 SESSION-18, `func_8014D820` 25 → 16) L5315 -- **§66d-4** — "ILS converged" means converged FOR THAT WEIGHT PROFILE, not a floor (amends §66d-3; Phase 29 SESSION-18) L5438 -- **§69** — How to attack a behemoth: map it, don't draft it (Phase 29 SESSION-18, `func_80183814`, 5,122 ins) L5569 -- **What** — is left, and what is byte-recorded as SPENT L5766 -- **§3-The** — mechanism, with citations L6037 -- **§3-Two** — diagnosis traps this function proved L6064 -- **Practice** — Practice L6074 -- **§3-The** — drift was an allocation decision, not missing code L6180 -- **§3-The** — economics L6211 -- **§71** — has a blind spot, and this is it L6226 -- **§3-The** — flagged "#1 move" LOST — and why the failure is informative L6302 -- **§78** — 's attribution primitive, run and reproduced L6312 -- **Cold-start** — economics, now complete L6318 -- **Also** — reproduced on this function L6401 -- **§3-And** — the banking footnote (§75a class A, one line) L6405 -- **§83a** — READ THE HEADLINE NUMBER CORRECTLY: a LENGTH drift makes `match_one`'s count meaningless L6419 -- **§83b** — THE LEVER: find the parameterised REPEAT before decoding case-by-case L6427 -- **§83e** — §80 vindicated again, on the same day it was written L6466 -- **§3-The** — conflict L6544 -- **§3-THE** — FAILURE MODE — widening only `engine_core.h` is worse than not starting L6552 -- **§3-The** — precondition, and how to check it in one grep L6559 -- **Reading** — , for the next person L6576 -- **§3-The** — guard refuses a class that largely works L6591 -- **§3-The** — blindness ladder, now complete — FOUR classes `match_one` cannot see L6649 -- **Consequence** — for the backlog ledger L6659 -- **§88** — `cross_jump` will not merge a common suffix containing a CALL; and §78 is scoped to ORDERED comparisons only (Phase 29 SESSION-20, the behemoth close-out) L6674 -- **§88a** — repeated CALL-shaped blocks are left UNMERGED; call-free tails are merged for you L6679 -- **§89** — Two throughput rules the project already had written down and was not following (Phase 29 SESSION-20) L6726 -- **§3-The** — standing sequence L6758 -- **§90b** — "Byte-neutral" is not "wanted": undo on the SUCCESS path too L6789 -- **§90c** — A library-callable function must FAIL CLOSED on an unconfigured module L6799 -- **§90e** — An agent's CONCLUSION and its EVIDENCE fail independently — re-derive the premise, not the fix L6818 -- **§93** — `set -o pipefail` attributes a pipeline failure to the LAST stage, not the failing one (Phase 29 SESSION-21, `func_8014D820`) L6922 -- **§101** — The STALE DEFAULT class: a guard whose cause was removed is a silent skip wearing a safety label (Phase 29 SESSION-22, three instances in one session) L7245 -- **§110** — A unit must define exactly ONE function, and "ends in `;`" does not tell you which line defines it (Phase 29 T65) L7640 -- **§115** — A `func_XXXXXXXX` predicate rots by design: the same name-form assumption in THREE places (Phase 29 T78) L7850 -- **§3-The** — fix moves the DEFINITION, not the stub — and here is why the obvious shortcut fails L7895 -- **§117** — Spell the sibling's symbol from the SIBLING's address, not the exemplar's kind (Phase 29 T82) L7926 -- **§118** — Ordinal (positional) immediate resolution: compare C tokens to the DIFFERING asm uses (Phase 29 T87) L7963 -- **§119** — Two levers on the SAME axis, opposite directions: test the off-diagonal (Phase 29 T89) L7997 -- **§3-The** — wiring trap that cost two attempts L8043 -- **§3-The** — method (keep this) L8213 -- **§3-The** — instrument rules that make its answer trustworthy (this is where I failed) L8223 -- **§3-The** — corrected results (each SHA-verified, from a clean tree, restore re-verified) L8238 -- **§3-The** — instrument trap that hid it (and it is §124's shape again) L8290 -- **§3-The** — mechanics L8299 -- **§3-The** — idiom they kept re-deriving: the constant-offset fold L8356 -- **§127b** — the knowledge was in a SOURCE COMMENT, not the cookbook L8386 -- **§128** — A raw NUL in C source makes grep SILENTLY SKIP the file (P30 S28, 137 files) L8393 -- **§128a** — a negative control must corrupt a SCRATCH COPY, never the tracked file L8425 -- **§3-The** — real blocker underneath, for the record L8477 -- **§3-The** — diagnostic ladder that finally located it (reusable) L8523 -- **Defect** — 1 — a pre-§8e MERGED DOUBLE is not a single-table predecessor L8579 -- **Defect** — 2 — `as` writes a corpse and nothing deletes it L8597 -- **§3-The** — fingerprint, and the 30-second ladder that found it L8607 -- **§3-The** — transferable rule L8628 -- **§132a** — `--like` is for a sibling with NO record; against one that HAS a record it over-derives (P30 S29, `ov_SC07_010`) L8635 -- **§135** — Six byte-verified gcc-2.7.2 idioms from the P30 S6f-h waves (and the two-lane wave shape that found them) L8765 -- **§3-The** — codegen idioms L8770 -- **§3-The** — wave shape that produced these L8819 -- **§136** — The LOCAL-VARIABLE lever: how many C locals, at what scope (P30 wave 4a, 25 byte-verified banks) L8837 -- **§136a** — Blocker capture: classify on the OUTPUT, never on the exit status L8976 -- **§136d** — Four gcc-2.7.2 levers the redraft lane found (each closed a residual no other lever moved) L9094 -- **§136e** — §136c's PRECONDITION, and two more symptom keys (wave 4b batch 3) L9138 -- **§136i** — The drafter model LADDER: Haiku → **Sonnet** → Opus → Fable5 (Drew, 2026-08-03) L9270 -- **§3-The** — triage, cheapest first L9421 -- **THREE** — carry variants hide in one "CARRY-FIXABLE" bucket — and they need different fixes L9490 -- **STEP** — 0 of sibling-first: grep `src/` for a distinctive LITERAL from the `.s` L9546 -- **§3-The** — generalisation — three corollaries worth more than the bug L9626 -- **§3-And** — the inverse-lookup trap, same session L9643 -- **§3-The** — three-line proof (do this before diagnosing any metric movement) L9680 -- **§3-The** — two instrument defects it exposed L9689 -- **§3-Two** — wrong mechanisms I chased first, and why they were wrong L9720 -- **§3-The** — trap that hid it — SAME FUNCTION, TWO ROUTES, ONLY ONE IS FREE L9805 -- **Route** — selection (why `--addr` sometimes says "nothing changed") L9814 -- **§144** — THE LITERAL'S SPELLING PICKS THE IMMEDIATE ENCODING (P30 S40 wave 1, `func_801822E0`) L9888 -- **§3-Why** — a correct draft can read as an intrinsic wall L9988 -- **§3-The** — rule L10023 -- **§3-B.** — `(v < 0x40) ? v : 0x3F` is folded to `MIN_EXPR` and expands to the WRONG SHAPE L10170 -- **§3-D.** — Reproduce the original's BUGS verbatim L10194 -- **§149** — Four instrument defects in one session, and the two questions they were hiding (P30 S43) L10243 -- **§3-A.** — A prep step that returns its input on failure is indistinguishable from a search that found nothing L10249 -- **§3-B.** — Same address + same name ≠ same body — and the ledger keys on address L10267 -- **§3-C.** — `make: *** [...] Error N` is a summary, never a diagnosis L10283 -- **§3-The** — fix L10319 -- **§3-The** — method that found it (this is the transferable part) L10329 -- **Diagnostic** — order (adopt this) L10356 -- **§3-The** — mechanism (read from cc1's own `-dR` trace, not inferred) L10372 -- **§3-The** — lever — a zero-emission insn that absorbs the blocked tick L10387 -- **§3-The** — finding L10423 -- **§3-The** — key L10432 -- **§3-Two** — cautions that must travel with this technique L10443 -- **§3-The** — companion defect (open) L10454 -- **Symptom** — Symptom L10474 -- **Mechanism** — (gcc source + RTL dumps, not inferred) L10479 -- **§3-The** — cure — a fresh launder per site, each in its own block L10492 -- **Companion** — levers from the same function L10502 -- **§3-B.** — Two static base-derivation methods that must AGREE (use both) L10536 -- **§155a** — the same failure class, one level up: SHAPE-blind table scanning (S45 p5) L10567 -- **§155c** — the ZERO-REFERENCE trap: gcc splits a global-array address across the `lui` and the LOAD (S46) L10610 -- **Symptom** — Symptom L10721 -- **§3-Why** — the fork is chained (gcc source, validated insn-by-insn against -dS/-dR dumps) L10727 -- **§3-The** — method (dump-arithmetic first, then place — no probing) L10740 -- **§162a** — SHARPENS *(sharpens §161a, §131, §8a-pad, §129a)* L11041 -- **§162b** — SHARPENS *(sharpens §48-A3, §156, §150, §76)* L11070 -- **§162d** — SHARPENS *(sharpens §31, §21, §30, §55a)* L11099 -- **§162e** — NEW L11141 -- **§162f** — SHARPENS *(sharpens §42d, §41d, §73, §10)* L11209 -- **§162g** — NEW L11264 -- **§162h** — SHARPENS *(sharpens §88, §88a, §50-B, §8)* L11300 -- **§162i** — SHARPENS *(sharpens §135, §21, §42, §32)* L11368 -- **§162j** — SHARPENS *(sharpens §25, §136d-1, §48-B, §46-L2)* L11393 -- **§162k** — SHARPENS *(sharpens §1-I2, §12, §160d, §21)* L11422 -- **§162l** — SHARPENS *(sharpens §48-B, §48-C1, §20, §21)* L11485 -- **§162m** — SHARPENS *(sharpens §36, §158, §148, §153)* L11540 -- **§158a** — THE FIFTH LEVER IS NOT AN ASM: `do { } while (0)` is a REGION ref-multiplier you MINT (P30 S48, `func_8017CBC8`, ov_MAIN_012 / jr_801789AC, 188 ins → MATCH) L11542 -- **Size** — it before you write it (§158 step 1-2, applied) L11560 -- **§3-The** — wrap BOUNDARY is the dial — and it is indiscriminate L11581 -- **§3-Not** — a pure dial L11587 -- **§162n** — NEW L11613 -- **§162o** — SHARPENS *(sharpens §158, §136-1, §136-6, §79)* L11646 -- **§162p** — SHARPENS *(sharpens §48-B, §46-L2, §156, §136d-1)* L11705 -- **§162q** — SHARPENS *(sharpens §30, §30a, §135-2, §136-13)* L11722 -- **§164** — S48 §163z SKEPTIC PASS (P30, 2026-08-12): 190 claims vetted, 82 banked L11848 -- **§169** — THE MICRO-ADAPT LANE (P30 S49): edit a proven body, don't crack a new one L16276 -- **§170** — THE A-PROP WORD-DIFF CARD (P30 S49): the lane that had no owner L16323 -- **§171** — THE STALE SEED SYMBOL (P30 S50, 2026-08-13): why §170's 91%→57% was never codegen L16367 -- **§172** — THE ORPHAN-SLOT MECHANISM v2 (P30 S50-Max): the complete frame-residue model for gcc-2.7.2 MIPS L16516 -- **§172a** — TWO DECOMPILATION TELLS FROM THE SAME DIG (P30 S50-Max) L16570 -- **§172b** — THREE MORE TELLS FROM THE GCC READ (P30 S50-Max, banked on Drew's ask) L16586 -- **§174** — THE ADAPT-CARD WAVE RECIPE (P31 waves A/B, 2026-08-14): prevention beats recovery L16665 -- **§176a** — THE VERIFICATION-LAYER LAWS (P31 overnight, 2026-08-15). What each check can and cannot prove. L16760 -- **§176b** — BATCH-GATING MECHANICS (P31): what changes when N drafts land in ONE .c L16800 -- **§3-C.** — The limit that remains (recorded, not solved) L17039 -- **§176k** — TWO SELECTOR BUGS THAT SILENTLY SHRINK A WAVE L17165 -- **§178** — SIX LEVERS MINED FROM THE WAVE-P JOURNALS (P31 S52), each byte-proven and source-cited L17239 -- **§3-A.** — THE `$0`-ADD OPAQUE COPY defeats `make_regs_eqv` (func_80033398, 93 ins) L17251 -- **§3-C.** — SINGLE-SET TEMPS GET THE BIRTHING BOOST (func_8001D3FC, 196 ins) L17280 -- **§3-E.** — THE ZERO-OFFSET ALIAS HOLE (func_80037028, 71 ins) L17295 -- **§179-B** — 🔴 THE HAND-WRITTEN-ASM TRANSCRIPTION CHECKLIST (maspsx + masked_diff; 10 byte-proofs) L17385 -- **§179-C** — 🔴 A FUNCTION WITH NO EPILOGUE (falls into a sibling's shared tail) MUST BE FILE-SCOPE `__asm__` L17435 -- **§179-D** — `gte_stflg` MUST CLOBBER `"$12"` OR THE WHOLE TEMP FILE ROTATES BY ONE L17486 -- **§179-H** — A MID-BODY `.global LABEL` PAIR SLICES A BYTE-COMPARABLE FRAGMENT OUT OF A LARGER ROUTINE L17582 -- **Considered** — and NOT banked L17605 -- **§176-F** — Misdiagnosis triage: four residual verdicts that were lying L17783 -- **What** — is NOT banked here L17800 -- **§180c** — WHEN A BINARY'S MASS BAND IS SPENT, THE FLEET-WIDE DRAW IS STRICTLY BETTER L17861 -- **Only** — ONE of 27 blocked drafts was wrong. The other 26 were correct and unbankable. L17880 -- **§180d** — THE `pgrep` BRACKET TRICK PROTECTS THE PATTERN, NOT THE COMMAND LINE L17949 -- **Three** — defects in one call path; the overlay slates that carry most of the wave work were being waved through L18361 -- **§194-F** — `if ((*p = v = f()) == 0)` is an expand-time pseudo SPLITTER (store_expr's `want_value && MEM` path), not a fold — it partitions one value between local_alloc and global_alloc. BOUNDS §21's L1872 bullet, whose stated direction is byte-wrong on 3 of 4 instances, and CLOSES the control §167-37 asked for. L19195 -- **§194-L** — §88b and §189-E are BOTH half-wrong, but not the way the candidate says: the compare-constant shape is a 2-D lookup (cmp_info ROW × constant-in-window), and naming matters on OPPOSITE sides of the window for the GE/LT rows vs the GT/LE rows L19522 -- **§197-REJECTED** — §197-REJECTED L20692 -- **§199-REJECTED** — §199-REJECTED L21088 -- **§201-B** — In a narrowed PLUS/MINUS/AND/IOR/XOR expression the destination pointee is INERT — the sign of the materialized constant is decided by an OR over the UNWIDENED operands (convert.c trunc1), which bounds §1841 to direct constant stores L21190 -- **§201-REJECTED** — eight, the session's highest L21424 -- **§204-CONFIRMED** — 30 reports that the index already answered L21890 -- **§204-REJECTED** — sixteen, twice the previous record L21984 -- **§209** — THE NARROW LOCAL IS A DIAL IN TWO OPPOSITE DIRECTIONS, AND §194-B's "≥2 `sh` STORES" BOUND IS BYTE-WRONG (P31 S58) L22251 -- **§212** — THE WALKING CURSOR IS COUNTABLE: `*wp++` emits one `addiu` PER STORE, `wp[0..2]` emits one (P31 S58) L22433 -- **§213** — INDEPENDENT SAME-BASE STORES: THE EMISSION ORDER IS A PERMUTATION OF SOURCE ORDER, AND THE PERMUTATION IS NOT ALWAYS THE IDENTITY (P31 S58) L22478 -- **§217** — DECODING A CALL'S STACK ARGUMENT SLOTS: `sw` at `0x10`/`0x14`/`0x18` are params 5/6/7 **(single observation — not yet cross-confirmed)** (P31 S58) L22656 -- **§226** — FRAME PADS: FOUR WAYS §162i1/§2429's DEAD-LOCAL LEVER MISFIRES (P31 S58) L22977 -- **§228** — READING THE DIVIDE, PART N: the off-by-one compare is `% K == 1`, and three more discriminators (P31 S58) L23038 -- **§229** — THE ADDRESS IS A VALUE: NAMING IT MOVES THE `lui`/`addiu` PAIR — AND §L14410 SAYS THE OPPOSITE FOR A REASON (P31 S58) L23075 -- **§231** — TRANSCRIPTION AND SEMANTIC-READ HYGIENE: six ways the listing misleads (P31 S58) L23139 -- **§194-B** — addendum (P31 S58) — BOUND 2 is byte-wrong; see §209 Direction A L23236 -- **§176-B** — addendum (P31 S58) — the misdiagnosis direction L23242 -- **§164-63** — addendum (P31 S58) — the interposed asm works when the SECOND value is an ordinary assignment L23257 -- **§193-A** — / §194-E addendum (P31 S58) — where the twin's body actually lives L23266 -- **§235** — THE PHANTOM SYMBOL: A MASKED `MATCH` CAN CARRY A RELOCATION THAT DOES NOT EXIST (P31 S58b) L23357 -- **§238** — SAME NAME, DIFFERENT FUNCTION: THE OVERLAY-HOMONYM TRAP (P31 S58b) L23520 -- **§240** — `A + K + B`: WRITE THE CONSTANT **BETWEEN** THE TWO RUNTIME TERMS (P31 S58b) L23594 -- **§241** — THE FOLDED SIGN-EXTEND-AND-SCALE: `sll 16 ; sra (16 − log2 scale)` (P31 S58b) L23623 -- **§252** — THE GUARDED PRE-DECREMENT: `(x != 0) && (--x == 0)` (P31 S58b) L23991 -- **§255** — THE EMPTY CASE, PART 2: FOUR TREE SHAPES IT BUYS (P31 S58b) L24038 -- **§258** — ADDENDA TO EXISTING SECTIONS (P31 S58b) L24153 -- **§202** — addendum (P31 S58b) — THE DEF-SIDE ALIAS ALSO CLEARS A RETURN+PARAM DOUBLE CONFLICT L24202 -- **§205** — addendum (P31 S58b) — CHAINED ASSIGNMENT: N≥3 IS INNERMOST-FIRST, AND THE TEXT MIRRORS EMISSION L24213 -- **§208** — addendum (P31 S58b) — IT SCALES TO SIX SITES, AND IT HAS AN EXACT INVERSE L24230 -- **§210** — addendum (P31 S58b) — THREE CONFIRMED SPELLINGS OF THE BOOLEAN TAIL L24259 -- **§213** — addendum (P31 S58b) — THREE MORE PERMUTATION LAWS FOR INDEPENDENT SAME-BASE STORES L24318 -- **§217** — CROSS-CONFIRMED (P31 S58b) — AND THE INCOMING HOME SLOT IS THE MIRROR L24435 -- **§220** — addendum (P31 S58b) — THE PARAMETER, NOT A COPY (SEVEN CARDS) L24452 -- **§225** — addendum (P31 S58b) — THE GUARD-CLAUSE FINGERPRINT, AND THREE MORE SHAPES L24549 -- **§229** — addendum (P31 S58b) — NAME IT **INSIDE** THE ARM L24621 -- **§230** — CROSS-CONFIRMED (P31 S58b) L24632 -- **§231** — addendum (P31 S58b) — FOUR MORE WAYS THE LISTING MISLEADS L24641 -- **§232** — CROSS-CONFIRMED (P31 S58b) L24672 -- **§260** — THE §154-A LEADING-ISLAND SPLIT: ONE CONFIG LINE, AND THE ISLAND PEELS FROM THE END (P31 S59, byte-proven) L24722 -- **§262** — A LANE'S YIELD IS ONLY A LANE FACT IF IT IS SIZE-MATCHED (P31 S59) L24856 -- **§264** — FOUR TELLS-LANE C RECIPES, EACH DRIVEN TO MATCH (P31 S59) L24927 -- **ADD-1** — → §231 addendum (also cross-ref from §195-D) — THE MASKED-`jal` "MISSING CALL" ILLUSION L25087 -- **ADD-6** — → §172b-1 / §264 addendum — SHIFT-AS-TEST: `(x << 16) != 0` TESTS THE LOW HALF WITHOUT TRUNCATING THE PSEUDO L25141 -- **ADD-7** — → §256 addendum — THE SINGLE-GUARD GOTO: THEN-BLOCK OUT OF LINE AT THE TAIL L25150 -- **ADD-3** — → §238 addendum — TWO BINARIES CAN EACH DEFINE THE SAME `func_` NAME WITH DIFFERENT BYTES, AND NO GENERATED REPORT SHOWS IT L25340 -- **§270** — The A-prop 0-bank anatomy: a byte-correct body still needs FOUR layers to agree (P31 S59) L25518 -- **ADDENDUM** — to §1-I5 L25808 -- **ADDENDUM** — to §164-51 L25873 -- **ADDENDUM** — to §176-F5 L25889 -- **ADDENDUM** — to §225 L25918 -- **ADDENDUM** — to §229 — A POINTER'S NUMBER OF USES DECIDES WHETHER ITS ADDRESS FOLDS OR SURVIVES A CALL L26106 -- **ADDENDUM** — to §226 — A DEAD LOCAL SCOPED TO A NESTED BLOCK BUYS A MID-FUNCTION `addiu sp` PAIR, NOT A FRAME-SIZE CHANGE L26224 -- **ADDENDUM** — to §74 (func_800D0E30, resident) L26592 -- **ADDENDUM** — to §172b-4 (func_80185054, ov_SC03_097) L26628 -- **ADDENDUM** — to §265 (func_8017DC80, ov_SC07_002) L26666 -- **ADDENDUM** — to §17 (func_800CB794, md_MAIN_036) L26705 -- **ADDENDUM** — to §162p (func_8017C120, ov_MAIN_012) L26753 -- **ADDENDUM** — to §20 (~L1947) (func_80186AD0, ov_SC06_032) L26787 -- **ADDENDUM** — to §164-56 (func_8017F644, ov_SC04_005) L26817 -- **ADDENDUM** — to §237 (func_8017F7FC, ov_SC03_092) L26852 -- **ADDENDUM** — to §195-E — a goto-ladder's STORES must sit AT the labels, after the gotos, not inline before them L27204 -- **Harness-defect** — flags L27678 -- **ADDENDUM** — to §167-40 (func_8017E2CC, ov_SC04_015 — wave dg) L27771 -- **ADDENDUM** — to §87 (func_801815F4 ov_SC06_032; corroborating func_801840DC ov_SC05_017, func_80189C68 ov_SC03_006 — wave dg) L27805 -- **ADDENDUM** — to §263 (func_801E83AC, md_SC04_029 — wave dj) L27844 -- **ADDENDUM** — to §265 (func_8017D878, ov_SC03_107 — wave dj; corroborated by a REJECTED, contradicted card in wave dm — see closing) L27858 -- **ADDENDUM** — to §6 (func_801811F0, ov_SC03_102 — waves dj and dl, corroborated by a self-reported "nothing new" dm-wave card) L27872 -- **ADDENDUM** — to §195-G (func_80183BB0, ov_SC05_001 — wave dj) L27886 -- **ADDENDUM** — to §74 (func_8017EB34, ov_SC03_117 — counter/clamp variant; wave dj, corroborated by dk/dl/dm cards on the same function) L27964 -- **ADDENDUM** — §37 — merged into the §153/§236-5 entry above (func_801A419C, wave dl) L27984 -- **ADDENDUM** — §6 — merged into the §6 entry above (func_801811F0, wave dl) L27992 -- **ADDENDUM** — to §238 (func_80182CB4, ov_SC02_000 — wave dl) L28000 -- **ADDENDUM** — to §137a (func_801684B4, ov_MAIN_012; corroborated independently by func_80189E68, func_8017FF9C, func_801822B4, func_8018DA8C — wave dl) L28018 -- **ADDENDUM** — to §8c / §88d (func_8016AB6C, ov_MAIN_012 — wave dm) L28034 -- **ADDENDUM** — to §73 / §30#2 (func_800D1984, resident — wave dm) L28048 -- **From** — ck + cl + cm L28176 -- **ADDENDUM** — to §5a (func_80181F74, ov_SC03_112, wave cn) L28318 -- **ADDENDUM** — to §265 (func_8017E26C, ov_SC04_016, wave cn) L28368 -- **ADDENDUM** — to §42b (func_8018247C, ov_SC07_002, waves cu + cw) L28406 -- **ADDENDUM** — to §195-E (func_800CFC1C, md_MAIN_003, wave cv) L28492 -- **ADDENDUM** — to §215 addendum (func_800CB2C8, md_MAIN_033, waves cv + cw) L28537 -- **ADDENDUM** — to §236 item 4 (func_8017D268, ov_SC04_006, wave cw) L28593 -- **Harness-defect** — flags (not idioms — flagged for the operator) L28654 -- **ADDENDUM** — to §250 (func_8017D7CC, ov_SC03_115 — cx/cy/cz/dr) L28695 -- **ADDENDUM** — to §225 (func_8017E190, ov_SC03_115 — cx/cy/cz) L28740 -- **ADDENDUM** — to §45-A (func_8017F6A4, ov_SC02_016 — cy/cz) L28793 -- **ADDENDUM** — to §249 (func_80182ED4, ov_SC04_004 — dp/dr/dt) L28837 -- **ADDENDUM** — to §199-A (func_801816FC, ov_SC02_005 — dp/dr/dt) L28882 -- **Harness-defect** — flags L28971 -- **§289** — an array local's address-taken base keeps every element's store alive, even though only one pointer escapes (`func_80189EFC`, ov_SC04_011) (P31 S60; waves #, byte-proven) L29053 -- **ADDENDUM** — to §264-3 — the explicit entry copy's BOUND: required exactly when the RAW value must outlive the call that consumes only the PROMOTED value L29207 -- **ADDENDUM** — to §276 — the SHARE direction: spell the second adjacent symbol RELATIVE to force ONE anchor L29239 -- **ADDENDUM** — to §31's density-dummy dial (L2460/L2497) — the dose is TWO refs, and the dummy must sit where the loser is live-through L29255 -- **§300** — S61 DISTILL BATCH NOTES (waves ab8/ab16/ab24/ab32 · g0a–g0f · m0a · ds1/ds2 · m0b) L29561 -- **§306a** — T4 DISTILL ADDENDA (P31 S62; four byte-proven refinements to existing laws, verified against the book by an independent verifier; each names its parent §) L29860 +- **§42d** — addendum — wave 4 (rtu_match fan-out over the mapped frontier, 2026-07-10c): 24/26 MATCH, +5 durable levers L3097 +- **§3-B.** — THE EBB RULE — the general form of §46-L2 L3483 +- **§3-E.** — Meta L3533 +- **§50** — Refinements that BOUND §47/§48 (from the `func_80135EB0` wall, 21→6; Phase 26 session 8) L3591 +- **§51a** — The bug class L3651 +- **§51c** — THE METHOD (do not audit by reading the regex) L3677 +- **§51d** — THE LAWS L3692 +- **§51e** — The false-wall pipeline (why this is not just hygiene) L3754 +- **§3-Why** — the wall is (probably) intrinsic L3960 +- **§3-The** — case L4048 +- **§3-The** — rule L4077 +- **§55a** — New byte-proven levers (each from a banked or near draft) L4113 +- **§60a** — What the first DIRECTED grinder run exposed (Phase 29 Task-13B, 2026-07-21) L4487 +- **§60b** — The plateau autopsy's verdict: a `partial` drift is a WRONG DRAFT, not a missing transform (Phase 29 Task-13B close, 2026-07-21) L4525 +- **§66** — Exercise a banking driver's SUCCESS path before pointing it at a wave: the free re-bank test (Phase 29 SESSION-17, 2026-07-24) L5174 +- **§66d-2** — Two operational sharp edges L5304 +- **§66d-3** — Read the ILS per-cycle SERIES, not its final best: a repeated score and a still-falling one look identical in a summary line and mean opposite things L5315 +- **§67** — The arg-copy PLACEMENT lever: launder a parameter into a fresh pseudo AT the statement where the target's copy lands (Phase 29 SESSION-18, `func_8014D820` 25 → 16) L5330 +- **§66d-4** — "ILS converged" means converged FOR THAT WEIGHT PROFILE, not a floor (amends §66d-3; Phase 29 SESSION-18) L5453 +- **§69** — How to attack a behemoth: map it, don't draft it (Phase 29 SESSION-18, `func_80183814`, 5,122 ins) L5584 +- **What** — is left, and what is byte-recorded as SPENT L5781 +- **§3-The** — mechanism, with citations L6052 +- **§3-Two** — diagnosis traps this function proved L6079 +- **Practice** — Practice L6089 +- **§3-The** — drift was an allocation decision, not missing code L6195 +- **§3-The** — economics L6226 +- **§71** — has a blind spot, and this is it L6241 +- **§3-The** — flagged "#1 move" LOST — and why the failure is informative L6317 +- **§78** — 's attribution primitive, run and reproduced L6327 +- **Cold-start** — economics, now complete L6333 +- **Also** — reproduced on this function L6416 +- **§3-And** — the banking footnote (§75a class A, one line) L6420 +- **§83a** — READ THE HEADLINE NUMBER CORRECTLY: a LENGTH drift makes `match_one`'s count meaningless L6434 +- **§83b** — THE LEVER: find the parameterised REPEAT before decoding case-by-case L6442 +- **§83e** — §80 vindicated again, on the same day it was written L6481 +- **§3-The** — conflict L6559 +- **§3-THE** — FAILURE MODE — widening only `engine_core.h` is worse than not starting L6567 +- **§3-The** — precondition, and how to check it in one grep L6574 +- **Reading** — , for the next person L6591 +- **§3-The** — guard refuses a class that largely works L6606 +- **§3-The** — blindness ladder, now complete — FOUR classes `match_one` cannot see L6664 +- **Consequence** — for the backlog ledger L6674 +- **§88** — `cross_jump` will not merge a common suffix containing a CALL; and §78 is scoped to ORDERED comparisons only (Phase 29 SESSION-20, the behemoth close-out) L6689 +- **§88a** — repeated CALL-shaped blocks are left UNMERGED; call-free tails are merged for you L6694 +- **§89** — Two throughput rules the project already had written down and was not following (Phase 29 SESSION-20) L6741 +- **§3-The** — standing sequence L6773 +- **§90b** — "Byte-neutral" is not "wanted": undo on the SUCCESS path too L6804 +- **§90c** — A library-callable function must FAIL CLOSED on an unconfigured module L6814 +- **§90e** — An agent's CONCLUSION and its EVIDENCE fail independently — re-derive the premise, not the fix L6833 +- **§93** — `set -o pipefail` attributes a pipeline failure to the LAST stage, not the failing one (Phase 29 SESSION-21, `func_8014D820`) L6937 +- **§101** — The STALE DEFAULT class: a guard whose cause was removed is a silent skip wearing a safety label (Phase 29 SESSION-22, three instances in one session) L7260 +- **§110** — A unit must define exactly ONE function, and "ends in `;`" does not tell you which line defines it (Phase 29 T65) L7655 +- **§115** — A `func_XXXXXXXX` predicate rots by design: the same name-form assumption in THREE places (Phase 29 T78) L7865 +- **§3-The** — fix moves the DEFINITION, not the stub — and here is why the obvious shortcut fails L7910 +- **§117** — Spell the sibling's symbol from the SIBLING's address, not the exemplar's kind (Phase 29 T82) L7941 +- **§118** — Ordinal (positional) immediate resolution: compare C tokens to the DIFFERING asm uses (Phase 29 T87) L7978 +- **§119** — Two levers on the SAME axis, opposite directions: test the off-diagonal (Phase 29 T89) L8012 +- **§3-The** — wiring trap that cost two attempts L8058 +- **§3-The** — method (keep this) L8228 +- **§3-The** — instrument rules that make its answer trustworthy (this is where I failed) L8238 +- **§3-The** — corrected results (each SHA-verified, from a clean tree, restore re-verified) L8253 +- **§3-The** — instrument trap that hid it (and it is §124's shape again) L8305 +- **§3-The** — mechanics L8314 +- **§3-The** — idiom they kept re-deriving: the constant-offset fold L8371 +- **§127b** — the knowledge was in a SOURCE COMMENT, not the cookbook L8401 +- **§128** — A raw NUL in C source makes grep SILENTLY SKIP the file (P30 S28, 137 files) L8408 +- **§128a** — a negative control must corrupt a SCRATCH COPY, never the tracked file L8440 +- **§3-The** — real blocker underneath, for the record L8492 +- **§3-The** — diagnostic ladder that finally located it (reusable) L8538 +- **Defect** — 1 — a pre-§8e MERGED DOUBLE is not a single-table predecessor L8594 +- **Defect** — 2 — `as` writes a corpse and nothing deletes it L8612 +- **§3-The** — fingerprint, and the 30-second ladder that found it L8622 +- **§3-The** — transferable rule L8643 +- **§132a** — `--like` is for a sibling with NO record; against one that HAS a record it over-derives (P30 S29, `ov_SC07_010`) L8650 +- **§135** — Six byte-verified gcc-2.7.2 idioms from the P30 S6f-h waves (and the two-lane wave shape that found them) L8780 +- **§3-The** — codegen idioms L8785 +- **§3-The** — wave shape that produced these L8834 +- **§136** — The LOCAL-VARIABLE lever: how many C locals, at what scope (P30 wave 4a, 25 byte-verified banks) L8852 +- **§136a** — Blocker capture: classify on the OUTPUT, never on the exit status L8991 +- **§136d** — Four gcc-2.7.2 levers the redraft lane found (each closed a residual no other lever moved) L9109 +- **§136e** — §136c's PRECONDITION, and two more symptom keys (wave 4b batch 3) L9153 +- **§136i** — The drafter model LADDER: Haiku → **Sonnet** → Opus → Fable5 (Drew, 2026-08-03) L9285 +- **§3-The** — triage, cheapest first L9436 +- **THREE** — carry variants hide in one "CARRY-FIXABLE" bucket — and they need different fixes L9505 +- **STEP** — 0 of sibling-first: grep `src/` for a distinctive LITERAL from the `.s` L9561 +- **§3-The** — generalisation — three corollaries worth more than the bug L9641 +- **§3-And** — the inverse-lookup trap, same session L9658 +- **§3-The** — three-line proof (do this before diagnosing any metric movement) L9695 +- **§3-The** — two instrument defects it exposed L9704 +- **§3-Two** — wrong mechanisms I chased first, and why they were wrong L9735 +- **§3-The** — trap that hid it — SAME FUNCTION, TWO ROUTES, ONLY ONE IS FREE L9820 +- **Route** — selection (why `--addr` sometimes says "nothing changed") L9829 +- **§144** — THE LITERAL'S SPELLING PICKS THE IMMEDIATE ENCODING (P30 S40 wave 1, `func_801822E0`) L9903 +- **§3-Why** — a correct draft can read as an intrinsic wall L10003 +- **§3-The** — rule L10038 +- **§3-B.** — `(v < 0x40) ? v : 0x3F` is folded to `MIN_EXPR` and expands to the WRONG SHAPE L10185 +- **§3-D.** — Reproduce the original's BUGS verbatim L10209 +- **§149** — Four instrument defects in one session, and the two questions they were hiding (P30 S43) L10258 +- **§3-A.** — A prep step that returns its input on failure is indistinguishable from a search that found nothing L10264 +- **§3-B.** — Same address + same name ≠ same body — and the ledger keys on address L10282 +- **§3-C.** — `make: *** [...] Error N` is a summary, never a diagnosis L10298 +- **§3-The** — fix L10334 +- **§3-The** — method that found it (this is the transferable part) L10344 +- **Diagnostic** — order (adopt this) L10371 +- **§3-The** — mechanism (read from cc1's own `-dR` trace, not inferred) L10387 +- **§3-The** — lever — a zero-emission insn that absorbs the blocked tick L10402 +- **§3-The** — finding L10438 +- **§3-The** — key L10447 +- **§3-Two** — cautions that must travel with this technique L10458 +- **§3-The** — companion defect (open) L10469 +- **Symptom** — Symptom L10489 +- **Mechanism** — (gcc source + RTL dumps, not inferred) L10494 +- **§3-The** — cure — a fresh launder per site, each in its own block L10507 +- **Companion** — levers from the same function L10517 +- **§3-B.** — Two static base-derivation methods that must AGREE (use both) L10551 +- **§155a** — the same failure class, one level up: SHAPE-blind table scanning (S45 p5) L10582 +- **§155c** — the ZERO-REFERENCE trap: gcc splits a global-array address across the `lui` and the LOAD (S46) L10625 +- **Symptom** — Symptom L10736 +- **§3-Why** — the fork is chained (gcc source, validated insn-by-insn against -dS/-dR dumps) L10742 +- **§3-The** — method (dump-arithmetic first, then place — no probing) L10755 +- **§162a** — SHARPENS *(sharpens §161a, §131, §8a-pad, §129a)* L11056 +- **§162b** — SHARPENS *(sharpens §48-A3, §156, §150, §76)* L11085 +- **§162d** — SHARPENS *(sharpens §31, §21, §30, §55a)* L11114 +- **§162e** — NEW L11156 +- **§162f** — SHARPENS *(sharpens §42d, §41d, §73, §10)* L11224 +- **§162g** — NEW L11279 +- **§162h** — SHARPENS *(sharpens §88, §88a, §50-B, §8)* L11315 +- **§162i** — SHARPENS *(sharpens §135, §21, §42, §32)* L11383 +- **§162j** — SHARPENS *(sharpens §25, §136d-1, §48-B, §46-L2)* L11408 +- **§162k** — SHARPENS *(sharpens §1-I2, §12, §160d, §21)* L11437 +- **§162l** — SHARPENS *(sharpens §48-B, §48-C1, §20, §21)* L11500 +- **§162m** — SHARPENS *(sharpens §36, §158, §148, §153)* L11555 +- **§158a** — THE FIFTH LEVER IS NOT AN ASM: `do { } while (0)` is a REGION ref-multiplier you MINT (P30 S48, `func_8017CBC8`, ov_MAIN_012 / jr_801789AC, 188 ins → MATCH) L11557 +- **Size** — it before you write it (§158 step 1-2, applied) L11575 +- **§3-The** — wrap BOUNDARY is the dial — and it is indiscriminate L11596 +- **§3-Not** — a pure dial L11602 +- **§162n** — NEW L11628 +- **§162o** — SHARPENS *(sharpens §158, §136-1, §136-6, §79)* L11661 +- **§162p** — SHARPENS *(sharpens §48-B, §46-L2, §156, §136d-1)* L11720 +- **§162q** — SHARPENS *(sharpens §30, §30a, §135-2, §136-13)* L11737 +- **§164** — S48 §163z SKEPTIC PASS (P30, 2026-08-12): 190 claims vetted, 82 banked L11863 +- **§169** — THE MICRO-ADAPT LANE (P30 S49): edit a proven body, don't crack a new one L16291 +- **§170** — THE A-PROP WORD-DIFF CARD (P30 S49): the lane that had no owner L16338 +- **§171** — THE STALE SEED SYMBOL (P30 S50, 2026-08-13): why §170's 91%→57% was never codegen L16382 +- **§172** — THE ORPHAN-SLOT MECHANISM v2 (P30 S50-Max): the complete frame-residue model for gcc-2.7.2 MIPS L16531 +- **§172a** — TWO DECOMPILATION TELLS FROM THE SAME DIG (P30 S50-Max) L16585 +- **§172b** — THREE MORE TELLS FROM THE GCC READ (P30 S50-Max, banked on Drew's ask) L16601 +- **§174** — THE ADAPT-CARD WAVE RECIPE (P31 waves A/B, 2026-08-14): prevention beats recovery L16680 +- **§176a** — THE VERIFICATION-LAYER LAWS (P31 overnight, 2026-08-15). What each check can and cannot prove. L16775 +- **§176b** — BATCH-GATING MECHANICS (P31): what changes when N drafts land in ONE .c L16815 +- **§3-C.** — The limit that remains (recorded, not solved) L17054 +- **§176k** — TWO SELECTOR BUGS THAT SILENTLY SHRINK A WAVE L17180 +- **§178** — SIX LEVERS MINED FROM THE WAVE-P JOURNALS (P31 S52), each byte-proven and source-cited L17254 +- **§3-A.** — THE `$0`-ADD OPAQUE COPY defeats `make_regs_eqv` (func_80033398, 93 ins) L17266 +- **§3-C.** — SINGLE-SET TEMPS GET THE BIRTHING BOOST (func_8001D3FC, 196 ins) L17295 +- **§3-E.** — THE ZERO-OFFSET ALIAS HOLE (func_80037028, 71 ins) L17310 +- **§179-B** — 🔴 THE HAND-WRITTEN-ASM TRANSCRIPTION CHECKLIST (maspsx + masked_diff; 10 byte-proofs) L17400 +- **§179-C** — 🔴 A FUNCTION WITH NO EPILOGUE (falls into a sibling's shared tail) MUST BE FILE-SCOPE `__asm__` L17450 +- **§179-D** — `gte_stflg` MUST CLOBBER `"$12"` OR THE WHOLE TEMP FILE ROTATES BY ONE L17501 +- **§179-H** — A MID-BODY `.global LABEL` PAIR SLICES A BYTE-COMPARABLE FRAGMENT OUT OF A LARGER ROUTINE L17597 +- **Considered** — and NOT banked L17620 +- **§176-F** — Misdiagnosis triage: four residual verdicts that were lying L17798 +- **What** — is NOT banked here L17815 +- **§180c** — WHEN A BINARY'S MASS BAND IS SPENT, THE FLEET-WIDE DRAW IS STRICTLY BETTER L17876 +- **Only** — ONE of 27 blocked drafts was wrong. The other 26 were correct and unbankable. L17895 +- **§180d** — THE `pgrep` BRACKET TRICK PROTECTS THE PATTERN, NOT THE COMMAND LINE L17964 +- **Three** — defects in one call path; the overlay slates that carry most of the wave work were being waved through L18376 +- **§194-F** — `if ((*p = v = f()) == 0)` is an expand-time pseudo SPLITTER (store_expr's `want_value && MEM` path), not a fold — it partitions one value between local_alloc and global_alloc. BOUNDS §21's L1872 bullet, whose stated direction is byte-wrong on 3 of 4 instances, and CLOSES the control §167-37 asked for. L19210 +- **§194-L** — §88b and §189-E are BOTH half-wrong, but not the way the candidate says: the compare-constant shape is a 2-D lookup (cmp_info ROW × constant-in-window), and naming matters on OPPOSITE sides of the window for the GE/LT rows vs the GT/LE rows L19537 +- **§197-REJECTED** — §197-REJECTED L20707 +- **§199-REJECTED** — §199-REJECTED L21103 +- **§201-B** — In a narrowed PLUS/MINUS/AND/IOR/XOR expression the destination pointee is INERT — the sign of the materialized constant is decided by an OR over the UNWIDENED operands (convert.c trunc1), which bounds §1841 to direct constant stores L21205 +- **§201-REJECTED** — eight, the session's highest L21439 +- **§204-CONFIRMED** — 30 reports that the index already answered L21905 +- **§204-REJECTED** — sixteen, twice the previous record L21999 +- **§209** — THE NARROW LOCAL IS A DIAL IN TWO OPPOSITE DIRECTIONS, AND §194-B's "≥2 `sh` STORES" BOUND IS BYTE-WRONG (P31 S58) L22266 +- **§212** — THE WALKING CURSOR IS COUNTABLE: `*wp++` emits one `addiu` PER STORE, `wp[0..2]` emits one (P31 S58) L22448 +- **§213** — INDEPENDENT SAME-BASE STORES: THE EMISSION ORDER IS A PERMUTATION OF SOURCE ORDER, AND THE PERMUTATION IS NOT ALWAYS THE IDENTITY (P31 S58) L22493 +- **§217** — DECODING A CALL'S STACK ARGUMENT SLOTS: `sw` at `0x10`/`0x14`/`0x18` are params 5/6/7 **(single observation — not yet cross-confirmed)** (P31 S58) L22671 +- **§226** — FRAME PADS: FOUR WAYS §162i1/§2429's DEAD-LOCAL LEVER MISFIRES (P31 S58) L22992 +- **§228** — READING THE DIVIDE, PART N: the off-by-one compare is `% K == 1`, and three more discriminators (P31 S58) L23053 +- **§229** — THE ADDRESS IS A VALUE: NAMING IT MOVES THE `lui`/`addiu` PAIR — AND §L14410 SAYS THE OPPOSITE FOR A REASON (P31 S58) L23090 +- **§231** — TRANSCRIPTION AND SEMANTIC-READ HYGIENE: six ways the listing misleads (P31 S58) L23154 +- **§194-B** — addendum (P31 S58) — BOUND 2 is byte-wrong; see §209 Direction A L23251 +- **§176-B** — addendum (P31 S58) — the misdiagnosis direction L23257 +- **§164-63** — addendum (P31 S58) — the interposed asm works when the SECOND value is an ordinary assignment L23272 +- **§193-A** — / §194-E addendum (P31 S58) — where the twin's body actually lives L23281 +- **§235** — THE PHANTOM SYMBOL: A MASKED `MATCH` CAN CARRY A RELOCATION THAT DOES NOT EXIST (P31 S58b) L23372 +- **§238** — SAME NAME, DIFFERENT FUNCTION: THE OVERLAY-HOMONYM TRAP (P31 S58b) L23535 +- **§240** — `A + K + B`: WRITE THE CONSTANT **BETWEEN** THE TWO RUNTIME TERMS (P31 S58b) L23609 +- **§241** — THE FOLDED SIGN-EXTEND-AND-SCALE: `sll 16 ; sra (16 − log2 scale)` (P31 S58b) L23638 +- **§252** — THE GUARDED PRE-DECREMENT: `(x != 0) && (--x == 0)` (P31 S58b) L24006 +- **§255** — THE EMPTY CASE, PART 2: FOUR TREE SHAPES IT BUYS (P31 S58b) L24053 +- **§258** — ADDENDA TO EXISTING SECTIONS (P31 S58b) L24168 +- **§202** — addendum (P31 S58b) — THE DEF-SIDE ALIAS ALSO CLEARS A RETURN+PARAM DOUBLE CONFLICT L24217 +- **§205** — addendum (P31 S58b) — CHAINED ASSIGNMENT: N≥3 IS INNERMOST-FIRST, AND THE TEXT MIRRORS EMISSION L24228 +- **§208** — addendum (P31 S58b) — IT SCALES TO SIX SITES, AND IT HAS AN EXACT INVERSE L24245 +- **§210** — addendum (P31 S58b) — THREE CONFIRMED SPELLINGS OF THE BOOLEAN TAIL L24274 +- **§213** — addendum (P31 S58b) — THREE MORE PERMUTATION LAWS FOR INDEPENDENT SAME-BASE STORES L24333 +- **§217** — CROSS-CONFIRMED (P31 S58b) — AND THE INCOMING HOME SLOT IS THE MIRROR L24450 +- **§220** — addendum (P31 S58b) — THE PARAMETER, NOT A COPY (SEVEN CARDS) L24467 +- **§225** — addendum (P31 S58b) — THE GUARD-CLAUSE FINGERPRINT, AND THREE MORE SHAPES L24564 +- **§229** — addendum (P31 S58b) — NAME IT **INSIDE** THE ARM L24636 +- **§230** — CROSS-CONFIRMED (P31 S58b) L24647 +- **§231** — addendum (P31 S58b) — FOUR MORE WAYS THE LISTING MISLEADS L24656 +- **§232** — CROSS-CONFIRMED (P31 S58b) L24687 +- **§260** — THE §154-A LEADING-ISLAND SPLIT: ONE CONFIG LINE, AND THE ISLAND PEELS FROM THE END (P31 S59, byte-proven) L24737 +- **§262** — A LANE'S YIELD IS ONLY A LANE FACT IF IT IS SIZE-MATCHED (P31 S59) L24871 +- **§264** — FOUR TELLS-LANE C RECIPES, EACH DRIVEN TO MATCH (P31 S59) L24942 +- **ADD-1** — → §231 addendum (also cross-ref from §195-D) — THE MASKED-`jal` "MISSING CALL" ILLUSION L25102 +- **ADD-6** — → §172b-1 / §264 addendum — SHIFT-AS-TEST: `(x << 16) != 0` TESTS THE LOW HALF WITHOUT TRUNCATING THE PSEUDO L25156 +- **ADD-7** — → §256 addendum — THE SINGLE-GUARD GOTO: THEN-BLOCK OUT OF LINE AT THE TAIL L25165 +- **ADD-3** — → §238 addendum — TWO BINARIES CAN EACH DEFINE THE SAME `func_` NAME WITH DIFFERENT BYTES, AND NO GENERATED REPORT SHOWS IT L25355 +- **§270** — The A-prop 0-bank anatomy: a byte-correct body still needs FOUR layers to agree (P31 S59) L25533 +- **ADDENDUM** — to §1-I5 L25823 +- **ADDENDUM** — to §164-51 L25888 +- **ADDENDUM** — to §176-F5 L25904 +- **ADDENDUM** — to §225 L25933 +- **ADDENDUM** — to §229 — A POINTER'S NUMBER OF USES DECIDES WHETHER ITS ADDRESS FOLDS OR SURVIVES A CALL L26121 +- **ADDENDUM** — to §226 — A DEAD LOCAL SCOPED TO A NESTED BLOCK BUYS A MID-FUNCTION `addiu sp` PAIR, NOT A FRAME-SIZE CHANGE L26239 +- **ADDENDUM** — to §74 (func_800D0E30, resident) L26607 +- **ADDENDUM** — to §172b-4 (func_80185054, ov_SC03_097) L26643 +- **ADDENDUM** — to §265 (func_8017DC80, ov_SC07_002) L26681 +- **ADDENDUM** — to §17 (func_800CB794, md_MAIN_036) L26720 +- **ADDENDUM** — to §162p (func_8017C120, ov_MAIN_012) L26768 +- **ADDENDUM** — to §20 (~L1947) (func_80186AD0, ov_SC06_032) L26802 +- **ADDENDUM** — to §164-56 (func_8017F644, ov_SC04_005) L26832 +- **ADDENDUM** — to §237 (func_8017F7FC, ov_SC03_092) L26867 +- **ADDENDUM** — to §195-E — a goto-ladder's STORES must sit AT the labels, after the gotos, not inline before them L27219 +- **Harness-defect** — flags L27693 +- **ADDENDUM** — to §167-40 (func_8017E2CC, ov_SC04_015 — wave dg) L27786 +- **ADDENDUM** — to §87 (func_801815F4 ov_SC06_032; corroborating func_801840DC ov_SC05_017, func_80189C68 ov_SC03_006 — wave dg) L27820 +- **ADDENDUM** — to §263 (func_801E83AC, md_SC04_029 — wave dj) L27859 +- **ADDENDUM** — to §265 (func_8017D878, ov_SC03_107 — wave dj; corroborated by a REJECTED, contradicted card in wave dm — see closing) L27873 +- **ADDENDUM** — to §6 (func_801811F0, ov_SC03_102 — waves dj and dl, corroborated by a self-reported "nothing new" dm-wave card) L27887 +- **ADDENDUM** — to §195-G (func_80183BB0, ov_SC05_001 — wave dj) L27901 +- **ADDENDUM** — to §74 (func_8017EB34, ov_SC03_117 — counter/clamp variant; wave dj, corroborated by dk/dl/dm cards on the same function) L27979 +- **ADDENDUM** — §37 — merged into the §153/§236-5 entry above (func_801A419C, wave dl) L27999 +- **ADDENDUM** — §6 — merged into the §6 entry above (func_801811F0, wave dl) L28007 +- **ADDENDUM** — to §238 (func_80182CB4, ov_SC02_000 — wave dl) L28015 +- **ADDENDUM** — to §137a (func_801684B4, ov_MAIN_012; corroborated independently by func_80189E68, func_8017FF9C, func_801822B4, func_8018DA8C — wave dl) L28033 +- **ADDENDUM** — to §8c / §88d (func_8016AB6C, ov_MAIN_012 — wave dm) L28049 +- **ADDENDUM** — to §73 / §30#2 (func_800D1984, resident — wave dm) L28063 +- **From** — ck + cl + cm L28191 +- **ADDENDUM** — to §5a (func_80181F74, ov_SC03_112, wave cn) L28333 +- **ADDENDUM** — to §265 (func_8017E26C, ov_SC04_016, wave cn) L28383 +- **ADDENDUM** — to §42b (func_8018247C, ov_SC07_002, waves cu + cw) L28421 +- **ADDENDUM** — to §195-E (func_800CFC1C, md_MAIN_003, wave cv) L28507 +- **ADDENDUM** — to §215 addendum (func_800CB2C8, md_MAIN_033, waves cv + cw) L28552 +- **ADDENDUM** — to §236 item 4 (func_8017D268, ov_SC04_006, wave cw) L28608 +- **Harness-defect** — flags (not idioms — flagged for the operator) L28669 +- **ADDENDUM** — to §250 (func_8017D7CC, ov_SC03_115 — cx/cy/cz/dr) L28710 +- **ADDENDUM** — to §225 (func_8017E190, ov_SC03_115 — cx/cy/cz) L28755 +- **ADDENDUM** — to §45-A (func_8017F6A4, ov_SC02_016 — cy/cz) L28808 +- **ADDENDUM** — to §249 (func_80182ED4, ov_SC04_004 — dp/dr/dt) L28852 +- **ADDENDUM** — to §199-A (func_801816FC, ov_SC02_005 — dp/dr/dt) L28897 +- **Harness-defect** — flags L28986 +- **§289** — an array local's address-taken base keeps every element's store alive, even though only one pointer escapes (`func_80189EFC`, ov_SC04_011) (P31 S60; waves #, byte-proven) L29068 +- **ADDENDUM** — to §264-3 — the explicit entry copy's BOUND: required exactly when the RAW value must outlive the call that consumes only the PROMOTED value L29222 +- **ADDENDUM** — to §276 — the SHARE direction: spell the second adjacent symbol RELATIVE to force ONE anchor L29254 +- **ADDENDUM** — to §31's density-dummy dial (L2460/L2497) — the dose is TWO refs, and the dummy must sit where the loser is live-through L29270 +- **§300** — S61 DISTILL BATCH NOTES (waves ab8/ab16/ab24/ab32 · g0a–g0f · m0a · ds1/ds2 · m0b) L29576 +- **§306a** — T4 DISTILL ADDENDA (P31 S62; four byte-proven refinements to existing laws, verified against the book by an independent verifier; each names its parent §) L29875 ## All sections, in order @@ -1508,813 +1511,814 @@ - **§40c** — The h_seq per-sibling reconcile: templating a reconcile-class crack ×134 (Phase 26 Task 8, 2026-07-12, byte-proven) L2676 - **§31-triage** — R17 applies to CODEGEN residuals, never to a compile ERROR (Phase 26 session 7, Drew asked) L2693 - **§41** — The DEF-SIDE canonical-sig wall: mechanically banking a drafted giant past `conflicting types` (Phase 25 T5b batch-2, 2026-07-09; `tools/canon_sig_reconcile.py`, byte-proven on `func_8013B274`) L2710 -- **§41a** — v3.1: the def-side wall was ~71% TOOL-shaped — the five measured defects + the laws that dissolve them (Phase 25 T6, Fable5, 2026-07-09) L2754 -- **§41b** — T7 execution: the object-only probe OVER-counts BANKABLE by two link/rodata classes (Phase 25 T7-M1, 2026-07-10) L2809 -- **§41c** — T7-M2: the ×134 def-side-wall sweep via per-sibling RE-reconcile (Phase 25, 2026-07-10; 4,389 banks, ~0 agent tokens) L2839 -- **§41b** — addendum — M4 "reconcile_decls" tier is ALSO a probe over-count: 0/8 mechanical (Phase 25 T7-M4, 2026-07-10) L2858 -- **§41d** — `void`→`s32` is NOT always byte-neutral: gate the RAW draft FIRST (Phase 26 session 6, byte-proven) L2878 -- **§42** — The F-band ≤28 regalloc crack wave: register-pin/DENSITY levers beat the permuter (Phase 25 T7 F-band, 2026-07-10; Ultracode 9-worker wave, 4/9 banked byte-identical, 266 swept ×134) L2900 -- **§42a** — addendum — wave 2 (residuals + 29-100 band): iso-MATCH ≠ real-TU bank, the memcpy→struct-assign fix, +5 levers (2026-07-10b) L2953 -- **§42b** — addendum — wave 3 (Max, 2026-07-10c): THE STALE-OBJECT GATE TRAP + the read-global `&`-cast drift + fix L2994 -- **§42c** — addendum — wave 3 (Max orchestrator + CORRECTED Ultracode fan-out, 2026-07-10c): the real-TU-faithful parallel harness (rtu_match) + 7/9 crack, ZERO iso-drift L3033 -- **§42d** — addendum — wave 4 (rtu_match fan-out over the mapped frontier, 2026-07-10c): 24/26 MATCH, +5 durable levers L3082 -- **§42e** — propagating a CRACK ×134: the def-finder bug + the byte-drift residual (the "remap-fail" misdiagnosis) L3121 -- **§43** — The K&R s16-param definition DISSOLVES the "narrow-param wall" for by-value register args (Phase 25 task A, Fable5 crack of the 369-ins giant `func_80166994` ×134, 2026-07-11) L3195 -- **§44** — The Phase-25 cheap-Opus giant batch: 5 structural levers + the §43 extension (2026-07-11, 6 crackers over the frontier giants) L3242 -- **§45** — The flagship `func_80133CD4` crack (399 ins ×134): the merged-variable permutation-breaker + the 1-death local-alloc gate (Phase 25 task A giant escalation, Fable5 gdb-on-cc1, 2026-07-11) L3298 -- **§46** — The `func_80178D40` crack (890 ins ×134, the heaviest core in the game): four LOOP-STRUCTURE levers cheap-Opus found by reading loop.c/jump.c/cse.c (Phase 26 session 8, 2026-07-13) L3313 -- **§47** — The live-length SLIDER: splitting a global.c allocno-priority TIE with one zero-byte asm (Phase 26 session 8, Fable5 Max, byte-proven on `func_8017BEBC` 952 ins ×113) L3365 -- **§48** — The 12-core jr crack wave: the ALLOCNO-PRICING dials and the EBB rule (Phase 26 session 8, Ultracode, 9/12 MATCH first pass) L3405 -- **§3-A.** — ALLOCNO-PRICING DIALS — move a value into the register you want, byte-neutrally L3413 -- **§3-A4** — SINK THE CONSUMER CALL INTO THE ARMS (the inverse of A1; `func_8016AB6C`, byte-proven) L3444 -- **§3-B.** — THE EBB RULE — the general form of §46-L2 L3468 -- **§3-C.** — TYPE- AND SHAPE-DRIVEN CODEGEN (the C type literally selects the addressing mode) L3484 -- **§3-D.** — THE CROSS-JUMP RATCHET (the sharpest new trap — `func_80131340` L-C) L3508 -- **§3-E.** — Meta L3518 -- **§49** — The LUID DIAL: a zero-byte SCHEDULING dial (the sched.c analogue of §47) — `func_8017A4AC` (536 ins ×134), Phase 26 session 8 L3527 -- **§50** — Refinements that BOUND §47/§48 (from the `func_80135EB0` wall, 21→6; Phase 26 session 8) L3576 -- **§51** — TOOLING INTEGRITY: the silent skip, and how to hunt it L3630 -- **§51a** — The bug class L3636 -- **§51b** — Why the byte-gate cannot save you L3652 -- **§51c** — THE METHOD (do not audit by reading the regex) L3662 -- **§51d** — THE LAWS L3677 -- **§51e** — The false-wall pipeline (why this is not just hygiene) L3739 -- **§51f** — Checklist for any new corpus-scanning tool L3755 -- **§51g** — When the thing you are scanning has a GRAMMAR, parse the grammar (`tools/cdecl.py`) L3769 -- **§52** — The WALKER-FAMILY skeleton: 6 regalloc-order levers + a deeply-characterized intrinsic wall (`func_80178004`, 165 ins ×134; Phase 26, Fable5, 2026-07-15) L3913 -- **§3-The** — 6 levers (the "walker-family skeleton" — apply to the 12 siblings; levers 1-5 retire ~half the residual) L3924 -- **§3-Why** — the wall is (probably) intrinsic L3945 -- **§52a** — The regalloc sibling wave: new levers + two new wall classes (cheap-Opus applying §52, 2026-07-15) L3959 -- **§52b** — Sibling wave 2: more de-pin levers, a third wall class, and the match_one→whole-binary gap at scale (2026-07-15) L3997 -- **§53** — SWEEP A FAMILY WITH THE TOOL ITS EXEMPLAR NEEDED: the jr/switch carve, and how omitting it manufactured the "families don't template" doctrine (Phase 28 T1, 2026-07-15) L4028 -- **§3-The** — case L4033 -- **§3-Why** — 0/8 was structural, and predictable from two words L4045 -- **§3-The** — rule L4062 -- **§3-The** — meta-lesson (R35, and why this one is expensive) L4078 -- **§55** — Core-crack wave levers + the GATE-ORCHESTRATION law (Phase 29 T3, 13-agent ultracode wave, 2026-07-17) L4093 -- **§55a** — New byte-proven levers (each from a banked or near draft) L4098 -- **§55b** — THE GATE-ORCHESTRATION LAW (3 traps, ~3.5h lost; all recovered, 0 data lost) L4122 -- **§55c** — Sizing the propagate: a TARGETED propagate is ~4 min/core, and "it's slow" was a BROKEN-TREE ARTIFACT L4141 -- **§54** — `--fix-def-sig`: the member's CANONICAL DECLARATION is a build step too (tiny-IMM mega-pools, +4,801, Phase 29 T6, 2026-07-16) L4163 -- **§56** — Banking a hand-drafted GIANT into its exemplar TU: self-contained draft vs live-TU decls, 4 reconciliation tactics (`func_8013FAF8`, 312 ins ×138, Phase 29 T4, 2026-07-17) L4187 -- **§56b** — PROPAGATING an h_seq giant: the exemplar's externs MUST be fleet-canonical, not the draft's types L4232 -- **§57** — The SELF-decl normalize: the sibling's OWN caller declares the templated fn divergently (the third §17a-1 direction; `tools/normalize_self_decls.py`, func_801670E4 ×137, Phase 29, 2026-07-18) L4256 -- **§57a** — Two NSD corrections + the SURGICAL-ONLY law + the honest broad-sweep yield (Phase 29, 2026-07-18) L4303 -- **§58** — match_one MATCH ≠ BANK: the four blind spots + the crack-wave reconcile-before-bank law (Phase 29 crack-wave, 2026-07-18) L4343 -- **§59** — Three h_seq sweep-residual classes match_one/the-exemplar-bank don't reveal (Phase 29 crack-wave close, 2026-07-18) L4377 -- **§60** — Classify the residual, don't rank it: the deterministic residual→class classifier and what it measured about the backlog (Phase 29 Task-13A, 2026-07-21) L4407 -- **What** — it measured — the whole open backlog, byte-grounded L4431 -- **§3-Two** — corollaries worth remembering L4450 -- **§3-The** — parallel-probe race this surfaced L4463 -- **§60a** — What the first DIRECTED grinder run exposed (Phase 29 Task-13B, 2026-07-21) L4472 -- **§60b** — The plateau autopsy's verdict: a `partial` drift is a WRONG DRAFT, not a missing transform (Phase 29 Task-13B close, 2026-07-21) L4510 -- **§61** — Task 14: the gate ladder's missing stage is the ARITY pre-pass, and it is TU-side not draft-side (Phase 29, 2026-07-21) L4545 -- **§61a** — The Task-5 wave: 11/12 MATCH, 0 banked — three DISTINCT integration walls, each now named (Phase 29, 2026-07-21) L4606 -- **§61b** — The jtbl gate stage: built, and the ORDERING law it exposed (Phase 29 Task-14 stage 4, 2026-07-21) L4658 -- **§61c** — The jtbl bank is INCREMENTALLY valid and CLEAN-INVALID (Phase 29, 2026-07-21) — the blocking finding L4713 -- **§61d** — The undo was eating the tree: two tools, one defect, invisible to the byte-gate (Phase 29, 2026-07-22) L4779 -- **§62** — The jtbl RECONCILE must also follow the carve: the post-carve draft reconcile (`harvest_verify._jtbl_reconcile`, Phase 29 SESSION-11, 2026-07-22) L4833 -- **§63** — The fresh-138 DEF-SIDE blocker: fix the HEADER decl, not the draft (`fix_header_decl.py`, Phase 29 SESSION-13, 2026-07-23) L4877 -- **§64** — The §20 type-lift's three laws: fold the tagged typedef, check VISIBILITY, and strip only what is TEXTUALLY IDENTICAL (`lift_types.py`, Phase 29 SESSION-14, 2026-07-23) L4908 -- **§64a** — VARIANT types: UNIQUIFY the camps, do not reconcile them (`uniquify_type.py`, Phase 29 SESSION-14) L4957 -- **§63** — UPDATE (Phase 29 SESSION-14) — `fix_header_decl`'s "SAFE" verdict is FLEET-BLIND; it MUST be R22-validated L5000 -- **§65** — The stranded-draft recovery: BLAST-RADIUS TIERS, and the per-overlay de-macroize that refutes §20's DEF-conflict wall (`tools/demacroize.py` + `tools/blocker_probe.py`, Phase 29 SESSION-16, 2026-07-24) L5015 -- **§65a** — The blast-radius taxonomy (makes §61's law structural instead of remembered) L5030 -- **§65b** — The escape: de-macroize the instantiation, don't touch the shared header L5045 -- **§65c** — `rtu_match` MATCH → bank held 13/13 on self-decl, but broke on the FIRST callee-decl case L5081 -- **§65d** — Existing-ladder baseline, measured (do this before building a recovery stage) L5091 -- **§65e** — Two oracles, and the disagreement is the finding (R34 in practice) L5101 -- **§65f** — The de-macroize lever's BOUNDARY, measured: byte-neutral 14 times of 15, and the 15th is why the gate exists L5118 -- **§65g** — Where the cheap levers STOP: the local-type and in-TU-self-decl classes did not yield L5139 -- **§66** — Exercise a banking driver's SUCCESS path before pointing it at a wave: the free re-bank test (Phase 29 SESSION-17, 2026-07-24) L5159 -- **§66a** — The widest write in a pipeline is the one most likely to be UNDECLARED L5181 -- **§66b** — A metric parsed out of another tool's prose goes NULL silently when the label changes L5200 -- **§66c** — Before a wave, verify the FUEL exists; an "already attempted" set built from the wrong directory lies in BOTH directions L5217 -- **§66d** — The permuter⇄reader loop: alternate a random search with a byte-verified idiom, and let `residual_class` decide whose turn it is (Phase 29 SESSION-17) L5245 -- **§66d-1** — What transfers between giants is the LOOP, not the PIN L5280 -- **§66d-2** — Two operational sharp edges L5289 -- **§66d-3** — Read the ILS per-cycle SERIES, not its final best: a repeated score and a still-falling one look identical in a summary line and mean opposite things L5300 -- **§67** — The arg-copy PLACEMENT lever: launder a parameter into a fresh pseudo AT the statement where the target's copy lands (Phase 29 SESSION-18, `func_8014D820` 25 → 16) L5315 -- **§67a** — Run the symbol-set guard BEFORE you pay for a gate (`tools/symcheck.py`, Phase 29 SESSION-18) L5405 -- **§66d-4** — "ILS converged" means converged FOR THAT WEIGHT PROFILE, not a floor (amends §66d-3; Phase 29 SESSION-18) L5438 -- **§66d-5** — `residual_class`'s "structural ⇒ permuter CPU is waste" is WRONG for schedule permutations (measured, Phase 29 SESSION-18) L5491 -- **§68** — A comment-only line halted the extern scan, and the skip label blamed the type cap (Phase 29 SESSION-18) L5524 -- **§69** — How to attack a behemoth: map it, don't draft it (Phase 29 SESSION-18, `func_80183814`, 5,122 ins) L5569 -- **§70** — The giv-init base register: walk the PARAMETER, not a copy of it (Phase 29 SESSION-18, `func_801777BC`) L5619 -- **§71** — Before mapping a giant, look for an already-matched SIBLING beside it (Phase 29 SESSION-18, `func_8017D960`, 3,338 ins) L5660 -- **§72** — A `register __asm__` pin is a PREFERENCE, not a reservation (Phase 29 SESSION-18, `func_8017F510`) L5726 -- **§3-The** — honest fix was source-level and cheap L5750 -- **§3-Giv** — record order (the §70 family) L5760 -- **What** — is left, and what is byte-recorded as SPENT L5766 -- **§73** — A def-side self-decl conflict has TWO axes: RETURN (fleet widen, T2) and PARAMS (casts at each use, T0). Diagnose which before paying for the expensive one (Phase 29 SESSION-19, `func_8014F3E8` + `func_8014D4C0`) L5783 -- **§74** — Auditing a pinned draft: the §72 hazard is CALLER-SAVED pins spanning a call, and only the disassembly can tell you (Phase 29 SESSION-19, `func_8017D960` b2, 5 pins) L5822 -- **§75** — A propagation cap is usually a MINORITY-SPELLING SOURCE OVERLAY, not a wall: census the carried extern before believing the exclusion message (Phase 29 SESSION-19, `func_8014F3E8` ×4 → ×138) L5866 -- **§75a** — The exclusion classes, enumerated with named causes (Phase 29 SESSION-19, the 134-binary `dedup_extend` sweep) L5925 -- **§75b** — A body's preamble can carry `#define`s, not just `extern`s; extraction lifts only the externs (Phase 29 SESSION-19, `func_80165CA0` ×3 → fleet) L5948 -- **§75c** — Class-B's remedy is the FULL §17a-1 PAIR (decl **and** call-site cast); a decl-only fix moves the error and looks like a new wall (Phase 29 SESSION-19, `func_8012F14C`) L5997 -- **§76** — The allocno CLASS (local vs global) is the dominant regalloc lever, and C reaches it ONLY through declaration scope and variable reuse (Phase 29 SESSION-19, behemoth #3 `func_8017F510` 1,511 ins, 97 → MATCH, pin-free) L6028 -- **§3-The** — mechanism, with citations L6037 -- **§3-The** — attribution primitive (use this before calling anything a scheduling residual) L6057 -- **§3-Two** — diagnosis traps this function proved L6064 -- **Practice** — Practice L6074 -- **§77** — Every extraction tool carries a NARROW hard-coded preamble set; anything outside it silently caps the body's reach. Diff the preamble before you gate. (Phase 29 SESSION-19 — three variants in one session, two different tools) L6084 -- **§3-The** — CANDIDATE gate and the REAL gate need DIFFERENT preambles — keep the difference out of the bank L6124 -- **§78** — A LENGTH drift can be a register grant in disguise; and `fold` never leaves a literal first in an `|` chain (Phase 29 SESSION-19, behemoth #2 `func_8017D960` 3,338 ins, 1806 → 0, pin-free) L6174 -- **§3-The** — drift was an allocation decision, not missing code L6180 -- **§3-The** — economics L6211 -- **§79** — For a 0-callee giant, fingerprint by DATA symbols (§71 cannot fire); and the STACK-SLOT ORDER is a declaration-order oracle (Phase 29 SESSION-19, `func_8017BF14` 4,763 ins, cold start → 45/4763) L6220 -- **§71** — has a blind spot, and this is it L6226 -- **§3-NEW** — LEVER — the frame layout reads back the original declaration order L6240 -- **§76** — confirmed at scale, and a pin nuance L6251 -- **§3-The** — residual, and the honest read L6260 -- **§80** — A do-not-re-buy entry is scoped to its BASE, not to the function; and the pin's hidden cost is an unconditional `qty_phys_sugg` (Phase 29 SESSION-19, `func_8017BF14` 45 → 0) L6270 -- **§3-The** — pin's hidden cost, with the citation L6291 -- **§3-The** — flagged "#1 move" LOST — and why the failure is informative L6302 -- **§78** — 's attribution primitive, run and reproduced L6312 -- **Cold-start** — economics, now complete L6318 -- **§81** — Banking a jr (jump-table) function: the 3-step carve chain, and why `match_one` cannot see the problem (Phase 29 SESSION-19, `func_8017C954`) L6323 -- **§3-The** — defect this exposed: a shared type that is present but invisible L6354 -- **§82** — Two source-shape oracles from behemoth #6: a duplicated `addiu $aN,$sp,K` across a `jal` means the block was INLINED, and scalar-vs-aggregate decides WHEN a stack slot is allocated (Phase 29 SESSION-19, `func_8017C730` 1,061 ins) L6370 -- **§3-1.** — The inlined-helper signature L6375 -- **§3-2.** — Scalar vs aggregate decides *when* the slot is allocated L6389 -- **Also** — reproduced on this function L6401 -- **§3-And** — the banking footnote (§75a class A, one line) L6405 -- **§83** — The parameterised-repeat law, the spill-area trap, and why a per-case edit cannot move a per-case symptom (Phase 29 SESSION-20, `func_80183814` 5,122 ins, cold-ish start → 36 structural / 99.3%) L6412 -- **§83a** — READ THE HEADLINE NUMBER CORRECTLY: a LENGTH drift makes `match_one`'s count meaningless L6419 -- **§83b** — THE LEVER: find the parameterised REPEAT before decoding case-by-case L6427 -- **§83c** — TRAP: a "dead local" in a prior draft may be gcc's OWN spill area L6445 -- **§83d** — CSE's quantity budget is WHOLE-FUNCTION, so a local rewrite cannot fix a local symptom L6452 -- **§83e** — §80 vindicated again, on the same day it was written L6466 -- **§84** — The DERIVED-OFFSET remap bug: a hand-computed literal that encodes the DISTANCE between two per-overlay symbols, and why `match_one` is structurally blind to it (Phase 29 SESSION-20, `func_8013D53C`) L6472 -- **§3-The** — construct L6477 -- **§3-Why** — it survived every candidate gate L6495 -- **§3-THE** — FIX IS MECHANICAL — the tool already holds the answer L6510 -- **Scope** — , measured (do not over-generalise — §80) L6518 -- **§3-Two** — ladder lessons banked with it L6528 -- **§85** — The RETURN-axis fleet widen is ALL-OR-NOTHING: widening the shared header alone guarantees a conflict in the source overlay (Phase 29 SESSION-20, `func_8012CC88` / `func_8014D12C`) L6539 -- **§3-The** — conflict L6544 -- **§3-THE** — FAILURE MODE — widening only `engine_core.h` is worse than not starting L6552 -- **§3-The** — precondition, and how to check it in one grep L6559 -- **§3-Do** — the WHOLE axis in one edit, then R22 once L6567 -- **Reading** — , for the next person L6576 -- **§86** — Pinned-exemplar templatability is a PER-FAMILY property, not a per-member rate; and the §42e pin guard is now over-conservative (Phase 29 SESSION-20) L6589 -- **§3-The** — guard refuses a class that largely works L6591 -- **§3-THE** — LAW: all-or-nothing PER FAMILY L6600 -- **§3-Why** — the two live families differ from the three dead ones — the open question L6627 -- **§87** — `match_one` COMPILES but never LINKS, so an unresolvable data symbol reads as MATCH; and stored drafts go STALE against the tree (Phase 29 SESSION-20) L6633 -- **§3-The** — blindness ladder, now complete — FOUR classes `match_one` cannot see L6649 -- **Consequence** — for the backlog ledger L6659 -- **§3-The** — cheap discriminator, before spending a sweep L6666 -- **§88** — `cross_jump` will not merge a common suffix containing a CALL; and §78 is scoped to ORDERED comparisons only (Phase 29 SESSION-20, the behemoth close-out) L6674 -- **§88a** — repeated CALL-shaped blocks are left UNMERGED; call-free tails are merged for you L6679 -- **§88b** — the `slti` literal-position law (extends §78 to comparisons) L6686 -- **§88d** — BANKING ORDER: run the §81 carve chain BEFORE banking, never after L6701 -- **§88e** — a wrong diagnosis, refuted properly (the model for how to treat an inherited lever) L6708 -- **§88f** — the missing rung: a RELOCATION gate between `match_one` and the binary L6718 -- **§89** — Two throughput rules the project already had written down and was not following (Phase 29 SESSION-20) L6726 -- **§89a** — MEASURE the write set; do not assert its tier (`tools/blast_radius.py`) L6732 -- **§89b** — the parallel gate farm existed; the family path could not reach it (`tools/sweep_parallel.py`) L6745 -- **§3-The** — standing sequence L6758 -- **§90** — Five tool-integrity laws from one session, each of which changed an answer (Phase 29 SESSION-21, 2026-07-27) L6766 -- **§90a** — A comparison tool MUST share its reference oracle's index space, exactly L6772 -- **§90b** — "Byte-neutral" is not "wanted": undo on the SUCCESS path too L6789 -- **§90c** — A library-callable function must FAIL CLOSED on an unconfigured module L6799 -- **§90d** — Do not measure a live wave's drafts (§87 in real time) L6810 -- **§90e** — An agent's CONCLUSION and its EVIDENCE fail independently — re-derive the premise, not the fix L6818 -- **§91** — A structure-TRANSFER is only valid where the structure corresponds: the `--like` role trap (Phase 29 SESSION-21, `func_8012AAAC` ×137) L6842 -- **§3-The** — three-hypothesis trail, because two of them were wrong and the wrongness is instructive L6871 -- **§92** — Conforming a DECLARATION: pointer changes are caller-neutral, scalar-WIDTH changes are not (Phase 29 SESSION-21, `tools/conform_decls.py`) L6891 -- **§93** — `set -o pipefail` attributes a pipeline failure to the LAST stage, not the failing one (Phase 29 SESSION-21, `func_8014D820`) L6922 -- **§94** — A family sweep's `0/N` is a TYPE-CARRY failure until proven otherwise: lift the exemplar's local types, ALL of them, transitively (Phase 29 SESSION-21, `func_8016B6BC` 0/137 → 137/137) L6947 -- **§95** — `reconcile_tu` dropped the SIBLING declarators of a multi-symbol `extern` line (Phase 29 SESSION-21, `func_80176218`) L6983 -- **§96** — The same rewrite, one shape down: `reconcile_tu` matched statements to lines by TEXT, so every COMMENTED declaration was silently skipped (Phase 29 SESSION-22, `func_80176218` banked) L7018 -- **§97** — The gate's own tree hygiene: a refused carve, an unchecked recovery, and a snapshot that captured a dirty tree (Phase 29 SESSION-22) L7066 -- **§98** — `conform_decls` had three defects, and only the third needed R22 to find (Phase 29 SESSION-22, `func_8014CF04`) L7113 -- **§99** — The narrow-param wall is a DEF-side problem with a ZERO-blast-radius fix: convert the definition to K&R (Phase 29 SESSION-22, `func_80175AB8` + `func_80175DA8`) L7167 -- **§3-Two** — `reconcile_tu` bugs found underneath, one introduced while fixing the other L7190 -- **§100** — Prefer the DRAFT-LOCAL fix: a type only one function uses belongs in its BODY, not in a shared header (Phase 29 SESSION-22, `func_80175DA8` 0/137 → 137/137) L7216 -- **§101** — The STALE DEFAULT class: a guard whose cause was removed is a silent skip wearing a safety label (Phase 29 SESSION-22, three instances in one session) L7245 -- **§102** — A PLUMBING verdict can MASK a DIFF; and K&R is not always a codegen change (Phase 29 SESSION-22, `func_8016EC0C`) L7272 -- **§103** — A FILE-scope `extern` in a shared overlay TU is a GLOBAL constraint on every LATER function; move the DECL, not the draft (Phase 29 T48/T51, `func_80135260` — the fleet-wide half) L7307 -- **§104** — Two silent-skip defects in one scan: match on MASKED text, emit from the ORIGINAL (Phase 29 T53, `gather_externs`) L7395 -- **§105** — A gate's revert must survive an EXCEPTION, not just a failure (Phase 29 T53, `jtbl_family_bank`) L7431 -- **§106** — Persist the MEASUREMENT, derive the POLICY: a stored route let a stale file out-vote the live table (Phase 29 T54, `residual_class._ROUTE`) L7470 -- **§107** — A lever wired into ONE gate path is a lever most families cannot reach (Phase 29 T56, `func_80144090` 0/136 → 136/136) L7513 -- **§108** — Diagnosing a family `0/N`: the four causes, and the third opt-in lever (Phase 29 T59) L7551 -- **§109** — Conforming a definition to a shared header: fix the NAMES, then check the RETURN precondition (Phase 29 T60) L7600 -- **§110** — A unit must define exactly ONE function, and "ends in `;`" does not tell you which line defines it (Phase 29 T65) L7640 -- **§111** — The distinct-code metric is not noisy: a family pays it only if its members are byte-VARIANT (Phase 29 T66) L7681 -- **§112** — A macro-scoped declaration only collides where the macro is INSTANTIATED (Phase 29 T67/T69, `audit_header_sigs.py`) L7730 -- **§113** — An ARITY blocker only exists if the macro CALLS the function; an address-taken use has no call site (Phase 29 T72) L7776 -- **§114** — The THIRD decl axis: a CALLEE the draft declares differently from the target TU (Phase 29 T76/T77) L7808 -- **§115** — A `func_XXXXXXXX` predicate rots by design: the same name-form assumption in THREE places (Phase 29 T78) L7850 -- **§116** — Optimization level is a property of the FILE, not the function: read a family 0/N against the member's stub HOME (Phase 29 T79) L7877 -- **§3-The** — fix moves the DEFINITION, not the stub — and here is why the obvious shortcut fails L7895 -- **§117** — Spell the sibling's symbol from the SIBLING's address, not the exemplar's kind (Phase 29 T82) L7926 -- **§3-Why** — it survived so long: a MASKED oracle will MATCH a wrong symbol L7953 -- **§118** — Ordinal (positional) immediate resolution: compare C tokens to the DIFFERING asm uses (Phase 29 T87) L7963 -- **§119** — Two levers on the SAME axis, opposite directions: test the off-diagonal (Phase 29 T89) L7997 -- **§120** — Uniquify draft-defined TYPE names; and check which of N staging sites you actually patched (Phase 29 T93) L8026 -- **§3-Do** — NOT "strip the duplicate typedef" — it breaks the extern that uses it L8037 -- **§3-The** — wiring trap that cost two attempts L8043 -- **§121** — Synthesise externs for macro-DEFINED callees from the macro's own definition head (Phase 29 T95) L8061 -- **§122** — GATE RAW BEFORE TRANSFORMING; the undo belongs to the WRITER, as a per-edit journal (P30 T0a, 2026-07-30) L8084 -- **§123** — PROPAGATE A FAMILY WITH THE TOOL ITS TIER NEEDS: `dedup_propagate` is h_exact-only; its refusals are statements about the TOOL (P30 wave 1, 2026-07-30) L8116 -- **§124** — A "not matched" verdict can mean the definition is there under a DIFFERENT C NAME: the asm-label alias blind spot (P30 SESSION-28, `func_8016191C` ×137) L8153 -- **§124a** — a family sweep's `0 matched-exemplar families` may be a FILTER, not a wall L8198 -- **§125** — Split the CARVE from the BODY before calling a jr residue a wall — and measure it by SHA from a CLEAN tree (P30 SESSION-28; **this section's first draft was WRONG and the method caught it**) L8206 -- **§3-The** — method (keep this) L8213 -- **§3-The** — instrument rules that make its answer trustworthy (this is where I failed) L8223 -- **§3-The** — corrected results (each SHA-verified, from a clean tree, restore re-verified) L8238 -- **§3-Two** — further notes worth keeping L8248 -- **§3-The** — meta-lesson L8257 -- **§126** — The carve-within-a-carve: an ADDRESS RANGE is not an OPTIMIZATION REGION (P30 T2, byte-proven end-to-end) L8264 -- **§3-The** — finding: opt level is per FILE, so the file's contents must be opt-HOMOGENEOUS L8279 -- **§3-The** — instrument trap that hid it (and it is §124's shape again) L8290 -- **§3-The** — mechanics L8299 -- **§126a** — a bare `except: continue` around a coverage-asserting oracle re-creates the silent skip (P30 S28) L8317 -- **§127** — The `-O0` regime: the CONSTANT-OFFSET FOLD, and why `-O0` needs its own idiom set (P30 T3 wave, 15 targets) L8349 -- **§3-The** — idiom they kept re-deriving: the constant-offset fold L8356 -- **§3-The** — rest of the `-O0` regime (write PLAIN C, and mean it) L8367 -- **§127a** — §71 (sibling-first) is the strongest `-O0` lever, and it beats the index L8377 -- **§127b** — the knowledge was in a SOURCE COMMENT, not the cookbook L8386 -- **§128** — A raw NUL in C source makes grep SILENTLY SKIP the file (P30 S28, 137 files) L8393 -- **§128a** — a negative control must corrupt a SCRATCH COPY, never the tracked file L8425 -- **§129** — Post-carve, `rtu_match`/`match_one` COUNT THE JUMP TABLE AS INSTRUCTIONS; and a carve must never be committed without its owner (P30 S28, `func_8013BD74`) L8437 -- **§129a** — the target instruction count is INFLATED after a carve L8441 -- **§129b** — never commit a carve whose owner is still a stub (it strands the carve) L8462 -- **§3-The** — real blocker underneath, for the record L8477 -- **§130** — An INCREMENTAL build can report BYTE-IDENTICAL for a change the CLEAN build cannot even LINK (P30 S28, the jr pair) L8486 -- **§3-The** — diagnostic ladder that finally located it (reusable) L8523 -- **§131** — The jtbl OVER-SPAN: `sltiu N` is ground truth in BOTH directions, and the zero-word rule only guards one (P30 S28, `func_80191C50`) L8533 -- **§132** — The `JR-PAIR-IN-ONE-O0-OBJECT` "wall" was TWO instrument defects: a merged-double span the carve could not see, and a truncated object no rule deleted (P30 S29, `func_8013B83C` + `func_8013BD74`) L8570 -- **Defect** — 1 — a pre-§8e MERGED DOUBLE is not a single-table predecessor L8579 -- **Defect** — 2 — `as` writes a corpse and nothing deletes it L8597 -- **§3-The** — fingerprint, and the 30-second ladder that found it L8607 -- **§3-The** — transferable rule L8628 -- **§132a** — `--like` is for a sibling with NO record; against one that HAS a record it over-derives (P30 S29, `ov_SC07_010`) L8635 -- **§132b** — When the span's already-matched owner is ITSELF multi-switch: `--span-rel` (P30 S1, `func_8014032C`) L8660 -- **§133** — The DEFAULT-FILTER class: three times in one session, a tool silently answered a narrower question than the one asked (P30 S1–S3) L8685 -- **§134** — MULTI-LINE BLINDNESS: one root cause, four faces, in `family_remap`'s preamble scanner (P30 S6, 190 zero-crack families) L8711 -- **§135** — Six byte-verified gcc-2.7.2 idioms from the P30 S6f-h waves (and the two-lane wave shape that found them) L8765 -- **§3-The** — codegen idioms L8770 -- **§3-The** — integration idioms (these decide whether a byte-correct draft BANKS) L8804 -- **§3-The** — wave shape that produced these L8819 -- **§136** — The LOCAL-VARIABLE lever: how many C locals, at what scope (P30 wave 4a, 25 byte-verified banks) L8837 -- **§3-The** — splitting/merging rules (each closed a residual, byte-gated) L8853 -- **§3-The** — type-form rules L8879 -- **§3-The** — scheduling rules (refining §135-2 and §135-4) L8912 -- **§3-The** — declaration surface (integration, not codegen) L8941 -- **Wave** — economics (measured, for the next batch's sizing) L8953 -- **§136a** — Blocker capture: classify on the OUTPUT, never on the exit status L8976 -- **§136b** — A prior wave's "genuine byte-DIFF" verdict is NOT reliable evidence (4 of 4 refuted) L9033 -- **§136c** — SIBLING-FIRST is a DERIVATION shortcut, not just a conflict fix (the fastest route in a family wave) L9069 -- **§136d** — Four gcc-2.7.2 levers the redraft lane found (each closed a residual no other lever moved) L9094 -- **§136e** — §136c's PRECONDITION, and two more symptom keys (wave 4b batch 3) L9138 -- **§136f** — Two declaration sub-cases the reconcile lane surfaced (lane now 15/15 lifetime) L9186 -- **§136g** — When the index points at the WRONG lever: two byte-refuted routings (func_801863B4) L9211 -- **§136h** — CORRECTION: the zero-crack pool does NOT "refill with cheap work" (my error, byte-measured) L9240 -- **§136i** — The drafter model LADDER: Haiku → **Sonnet** → Opus → Fable5 (Drew, 2026-08-03) L9270 -- **§136j** — The failure MIX flips with function size (measured across four bands, one session) L9302 -- **§137** — REGALLOC-PERM is a TWO-COMPILE ARITHMETIC PROBLEM, not a permuter job L9344 -- **§137a** — A gate verdict has a TIMESTAMP; re-check it against the draft's mtime L9386 -- **§138** — The propagation lanes: a gate refusal is a DECLARATION, and which lever you owe depends on blast radius L9415 -- **§3-The** — triage, cheapest first L9421 -- **§3-The** — DEFINITION-side alias is the only escape when the fleet canon disagrees on a promoting param L9473 -- **Rank** — the lane by measured concentration, not by class count L9481 -- **THREE** — carry variants hide in one "CARRY-FIXABLE" bucket — and they need different fixes L9490 -- **§134** — again, in a second tool — and the waiter rule corrected L9526 -- **STEP** — 0 of sibling-first: grep `src/` for a distinctive LITERAL from the `.s` L9546 -- **Reconciling** — a gate-refused draft: which way you edit depends on WHERE the TU's decl is L9565 -- **§139** — A GATE THAT GREPS FOR VERDICTS MUST ASSERT 1:1 ACCOUNTING; and a `--src` filter must not survive a carve (P30 S38, wave 6: 10 of 16 drafts vanished) L9594 -- **§3-The** — generalisation — three corollaries worth more than the bug L9626 -- **§3-And** — the inverse-lookup trap, same session L9643 -- **§140** — A METRIC IS NOT A MEASUREMENT UNTIL IT IS REPRODUCIBLE FROM THE COMMITTED TREE (P30 S1e: a phantom regression that gated the session's best lever) L9660 -- **§3-The** — three-line proof (do this before diagnosing any metric movement) L9680 -- **§3-The** — two instrument defects it exposed L9689 -- **§3-The** — same swallow, twice more, in the integration spine L9709 -- **§3-Two** — wrong mechanisms I chased first, and why they were wrong L9720 -- **§141** — The §134 class is CLOSED: every line-shape decision now routes through `cdecl._mask` (P30 S39) L9740 -- **§142** — An open stub whose `h_exact` class is MATCHED elsewhere is FREE. Propagate the body; do not gate a draft. (P30 S39, +7,710 ins in two commands) L9778 -- **§3-The** — measurement (do this before any wave; it is ~20 lines and needs no builds) L9790 -- **§3-The** — trap that hid it — SAME FUNCTION, TWO ROUTES, ONLY ONE IS FREE L9805 -- **Route** — selection (why `--addr` sometimes says "nothing changed") L9814 -- **§3-And** — the report-vs-bytes lesson attached to it L9822 -- **§143** — `cast_call_sites` read a RETURN STATEMENT as a prototype and deleted it. A 0/39 sweep became 18/39. (P30 S40) L9834 -- **§144** — THE LITERAL'S SPELLING PICKS THE IMMEDIATE ENCODING (P30 S40 wave 1, `func_801822E0`) L9888 -- **§145** — Three loop/combine levers from the S40 wave-2 drafters (16/16 match_one) L9927 -- **§146** — RE-MEASURE A WALL BEFORE YOU RESPECT IT. Both "permanent" giants fell to drafts already on disk. (P30 S6, +50,094 ins) L9977 -- **§3-Why** — a correct draft can read as an intrinsic wall L9988 -- **Then** — propagation returned 0/137 TWICE — both times a missing TYPE L10000 -- **§3-Two** — errors of mine, both instructive L10009 -- **§3-The** — rule L10023 -- **§147** — The three-stratum FRAME LAW, and four "stop searching" verdicts (P30 S42, `func_8017C294`, serial run) L10036 -- **§3-A.** — The frame has THREE strata, and stratum 3 is unreachable from C L10041 -- **§3-B.** — A `?:` on MEMORY operands costs ~16 bytes of invisible frame; on REGISTER operands, zero L10057 -- **§3-C.** — Inner-block declaration does NOT delay slot allocation — BYTE-REFUTED L10068 -- **§3-D.** — A lone `$t8`/`$t9` in the target is RELOAD SCRATCH — reproduce the spill, don't pin the register L10073 -- **§3-E.** — A `qty_compare` TIE is not spelling-reachable — recognise it and stop L10083 -- **Consequence** — for the family (a real scheduling decision) L10095 -- **§148** — The loop.c hoisting THRESHOLD is arithmetic you can compute, and the `?:` clamp that folds to MIN_EXPR (P30 S42, `func_8017C6F4`, 947 ins) L10145 -- **§3-A.** — `move_movables` hoists iff `threshold × savings × lifetime ≥ insn_count` — and you can read it L10151 -- **§3-B.** — `(v < 0x40) ? v : 0x3F` is folded to `MIN_EXPR` and expands to the WRONG SHAPE L10170 -- **§3-C.** — A zero-byte ALLOCNO-PRIORITY slider L10184 -- **§3-D.** — Reproduce the original's BUGS verbatim L10194 -- **§149** — Four instrument defects in one session, and the two questions they were hiding (P30 S43) L10243 -- **§3-A.** — A prep step that returns its input on failure is indistinguishable from a search that found nothing L10249 -- **§3-B.** — Same address + same name ≠ same body — and the ledger keys on address L10267 -- **§3-C.** — `make: *** [...] Error N` is a summary, never a diagnosis L10283 -- **§3-D.** — "Cheap fuel" that was never probed: 0 of 31 templatable L10293 -- **§150** — A register ROTATION across symmetric blocks is VARIABLE-IDENTITY evidence, not an allocator tie (P30 S43, `func_8017C6F4`, 947 ins ×4) L10312 -- **§3-The** — fix L10319 -- **§3-The** — method that found it (this is the transferable part) L10329 -- **§3-Two** — corrections to the record L10345 -- **Diagnostic** — order (adopt this) L10356 -- **§151** — THE GHOST WEDGE: when a load-before-store transposition is unreachable by ANY statement order (P30 S43, `func_8017EF68`, 969 ins) L10367 -- **§3-The** — mechanism (read from cc1's own `-dR` trace, not inferred) L10372 -- **§3-The** — lever — a zero-emission insn that absorbs the blocked tick L10387 -- **§3-The** — two fallouts, and how to close them (both measured, in order) L10395 -- **When** — to reach for it L10407 -- **§152** — BYTE SIZE is the family key that name- and h_seq-grouping both miss (P30 S43, the 0xECC family: 1 crack → 12 overlays → 11,364 ins) L10418 -- **§3-The** — finding L10423 -- **§3-The** — key L10432 -- **§3-Two** — cautions that must travel with this technique L10443 -- **§3-The** — companion defect (open) L10454 -- **§153** — THE ADDRESS-REMATERIALISATION LAUNDER: a third zero-emission asm lever (P30 S43, `func_8018D98C`, 710 ins) L10466 -- **Symptom** — Symptom L10474 -- **Mechanism** — (gcc source + RTL dumps, not inferred) L10479 -- **What** — does NOT work (14 byte-measured probes) L10486 -- **§3-The** — cure — a fresh launder per site, each in its own block L10492 -- **Companion** — levers from the same function L10502 -- **§154** — Reading a disc payload: the module-id word, static base derivation, and "type 1 = uncompressed overlay" (P30 S44) L10522 -- **§3-A.** — Payload word0 is a global MODULE ID; code starts after the header L10527 -- **§3-B.** — Two static base-derivation methods that must AGREE (use both) L10536 -- **§3-C.** — PAC type 1 = the same payload class as type 4, just NOT compressed L10548 -- **§155** — hi/lo literal scanning MUST track base registers (S45) L10558 -- **§155a** — the same failure class, one level up: SHAPE-blind table scanning (S45 p5) L10567 -- **§155b** — check the TYPE your oracle returns before comparing against it (S45 p5) L10587 -- **§155c** — the ZERO-REFERENCE trap: gcc splits a global-array address across the `lui` and the LOAD (S46) L10610 -- **§156** — an ORPHANED reconcile poisons the fleet: `dedup_propagate`'s kept edit (S45 p6/p7) L10640 -- **§157** — the cheap-tier size cliff, measured (S45 p6) L10687 -- **§158** — The RANGE-EXTENDER: a fourth zero-emission asm lever completes the allocno toolkit (P30 S46 tier-3, `func_8017CE58`, 733 ins) L10712 -- **Symptom** — Symptom L10721 -- **§3-Why** — the fork is chained (gcc source, validated insn-by-insn against -dS/-dR dumps) L10727 -- **§3-The** — method (dump-arithmetic first, then place — no probing) L10740 -- **Bonus** — facts worth keeping L10757 -- **§156** — THE PREFERENCE-DONOR MERGE: cross-region variable reuse is what fills a0-a3, and a call-arg use in ONE region steers the fill in ALL of them (P30 S46 tier-3, `func_80186E24`, 611 ins: 236-off "S11 regalloc-order" → MATCH, zero new pins) L10772 -- **§159** — THE DECLARATION AXIS: conform to byte-truth, and make every guard state its COVERAGE (P30 S47; ~10,930 sites across 8 axes, fleet byte-identical) L10828 -- **§160** — THE REACH-15 WAVE HARVEST: an align-1 block move, and the instrument that called it a wall (P30 S47) L10893 -- **§161** — THE RETRY-WAVE HARVEST: a jump table indexed from zero, and two allocator traps (P30 S47) L10969 -- **§162** — S48 WAVE-1 HARVEST (P30, 2026-08-11): the reach-ordered sibling campaign's first 12 targets L11014 -- **§162a** — SHARPENS *(sharpens §161a, §131, §8a-pad, §129a)* L11041 -- **§162b** — SHARPENS *(sharpens §48-A3, §156, §150, §76)* L11070 -- **§162d** — SHARPENS *(sharpens §31, §21, §30, §55a)* L11099 -- **§162e** — NEW L11141 -- **§162** — THE LICM PAIR: what makes an address a movable AT ALL, and why the preheader order is the body order (P30 S47, `ov_MAIN_012`) L11143 -- **§162f** — SHARPENS *(sharpens §42d, §41d, §73, §10)* L11209 -- **§162g** — NEW L11264 -- **§162** — CROSS-JUMP DIRECTION: the surviving copy is always the LATER one, so a BACKWARD `j` into a sibling arm is a source `goto` (P30 S48) L11266 -- **§162h** — SHARPENS *(sharpens §88, §88a, §50-B, §8)* L11300 -- **§162** — The cross-jump "CALL veto" is a COUNT law, not a CALL law (BOUNDS §88a; P30 S48, `func_80189540`) L11302 -- **§162i** — SHARPENS *(sharpens §135, §21, §42, §32)* L11368 -- **§162j** — SHARPENS *(sharpens §25, §136d-1, §48-B, §46-L2)* L11393 -- **§162k** — SHARPENS *(sharpens §1-I2, §12, §160d, §21)* L11422 -- **§162l** — SHARPENS *(sharpens §48-B, §48-C1, §20, §21)* L11485 -- **§162m** — SHARPENS *(sharpens §36, §158, §148, §153)* L11540 -- **§158a** — THE FIFTH LEVER IS NOT AN ASM: `do { } while (0)` is a REGION ref-multiplier you MINT (P30 S48, `func_8017CBC8`, ov_MAIN_012 / jr_801789AC, 188 ins → MATCH) L11542 -- **§3-The** — law L11549 -- **Size** — it before you write it (§158 step 1-2, applied) L11560 -- **§3-The** — wrap BOUNDARY is the dial — and it is indiscriminate L11581 -- **§3-Not** — a pure dial L11587 -- **DIAGNOSTIC** — TELL — two faces, one law L11591 -- **§162n** — NEW L11613 -- **§162o** — SHARPENS *(sharpens §158, §136-1, §136-6, §79)* L11646 -- **§162p** — SHARPENS *(sharpens §48-B, §46-L2, §156, §136d-1)* L11705 -- **§162q** — SHARPENS *(sharpens §30, §30a, §135-2, §136-13)* L11722 -- **§163** — S48 WAVES 2-3 HARVEST (P30, 2026-08-11/12): the five that were byte-probed and are actionable L11760 -- **§163z** — THE UNVETTED REMAINDER (do not cite as law; each needs a dedupe pass) L11828 -- **§164** — S48 §163z SKEPTIC PASS (P30, 2026-08-12): 190 claims vetted, 82 banked L11848 -- **§16Xy** — SHARPENS *(sharpens §136d-3, §37 /s-DEP LATTICE, §135-2, §136-13, §162q)* L12300 -- **§3-The** — `/s` drop clause is in ALL THREE dependence predicates, so the FIXED-ADDRESS STORE is what floats (P30 S48, `func_8017CA18`, ov_MAIN_012) L12302 -- **§164z** — REFUTED CLAIMS: do NOT re-derive these L13636 -- **§165** — S48 WAVE-4 HARVEST (P30, 2026-08-12): banked the same day the wave landed L13702 -- **§16Z** — SHARPENS *(sharpens §37 "the /s-DEP LATTICE", §136-13, §136-14, §16Xy, §162q, `gcc-2.7.2-map/sched.md` §64)* L14353 -- **§3-The** — ADDRESS-CLASS TABLE: which load/store pairs even REACH the `/s` clause (P30 S48 wave 4, `func_80185B44`, ov_SC03_014) L14355 -- **§165z** — REFUTED THIS WAVE: do NOT re-derive L14871 -- **§166** — THE DESTINATION-TU ORACLE (P30 S48): the seven-attempt bug that was never codegen L14915 -- **§167** — S48 WAVE-5/6 HARVEST (P30, 2026-08-12): the saturation point L14971 -- **§167z** — REFUTED IN WAVES 5/6: do NOT re-derive L16167 -- **§168** — THE COUSIN TIER (P30 S49, 2026-08-12): h_seq's exact-hash brittleness, measured — and the similarity map above it L16224 -- **§169** — THE MICRO-ADAPT LANE (P30 S49): edit a proven body, don't crack a new one L16276 -- **§170** — THE A-PROP WORD-DIFF CARD (P30 S49): the lane that had no owner L16323 -- **§171** — THE STALE SEED SYMBOL (P30 S50, 2026-08-13): why §170's 91%→57% was never codegen L16367 -- **§171a** — THE MECHANICAL A-PROP DRAFT (P30 S50): 256 members banked with no agent in the loop L16433 -- **§171b** — THREE CARRIES THE MECHANICAL DRAFT NEEDS (P30 S50, banking the top-reach families) L16483 -- **§172** — THE ORPHAN-SLOT MECHANISM v2 (P30 S50-Max): the complete frame-residue model for gcc-2.7.2 MIPS L16516 -- **§172a** — TWO DECOMPILATION TELLS FROM THE SAME DIG (P30 S50-Max) L16570 -- **§172b** — THREE MORE TELLS FROM THE GCC READ (P30 S50-Max, banked on Drew's ask) L16586 -- **§173** — THE STORED-PLUMBING RECOVERY RECIPE (P31 T6): symfix-first, per-group isolation, and where the verdicts have no drafts L16629 -- **§174** — THE ADAPT-CARD WAVE RECIPE (P31 waves A/B, 2026-08-14): prevention beats recovery L16665 -- **§175** — A CALLER-SAVED REGISTER PIN CAN BE A CORRECTNESS BUG, NOT JUST A SCHEDULING CHOICE (P31 wave H, 2026-08-15) L16735 -- **§176a** — THE VERIFICATION-LAYER LAWS (P31 overnight, 2026-08-15). What each check can and cannot prove. L16760 -- **§176b** — BATCH-GATING MECHANICS (P31): what changes when N drafts land in ONE .c L16800 -- **§176d** — THE CONFLICT TABLE MUST BE SEEDED FROM THE TU, AND KEYED PER FILE (P31 S52, 2026-08-15) L16826 -- **§176e** — SYMBOL IDENTITY IS COMPUTABLE OFFLINE (P31 S52): `tools/reloc_identity.py` L16865 -- **§176f** — THE DECLARATION FORM IS A MATCHING LEVER, SO RECONCILE TOWARD THE FORM THE MATCH NEEDS (P31 S52) L16922 -- **§176g** — SIZE A WAVE BY INSTRUCTIONS, NOT BY CARDS (P31 S52 — the adopted doctrine) L16953 -- **§176h** — THE BATCH-SUBSTITUTION HAZARD MAP (P31 S52): seven holes, three wrong fixes, one law L16991 -- **§3-A.** — The seven under-reporting holes (all in `gate_main`, all the same shape) L16999 -- **§3-B.** — Typedef handling — the only strategy that survives contact L17017 -- **§3-C.** — The limit that remains (recorded, not solved) L17039 -- **§3-C2.** — RECONCILE BEFORE THE FIRST GATE — a parked draft gets HARDER to bank, not easier L17046 -- **§3-D.** — The measured cost shape, and what to build next L17069 -- **§176i** — WHAT A STATIC PRE-GATE CHECK CAN AND CANNOT PROVE (P31 S52, wave Q) L17087 -- **§176j** — STOPPING A WAVE MID-FLIGHT COSTS THE IN-FLIGHT TAIL (and how much is recoverable) L17119 -- **§176j-2** — THE REPAIR PASS, MEASURED (do this instead of resuming) L17145 -- **§176k** — TWO SELECTOR BUGS THAT SILENTLY SHRINK A WAVE L17165 -- **§177** — 🔴 THE EPILOGUE RETURN-DELAY SLOT IS DECIDED BY YOUR SAVED-REGISTER SET, NOT BY SCHEDULING L17182 -- **§178** — SIX LEVERS MINED FROM THE WAVE-P JOURNALS (P31 S52), each byte-proven and source-cited L17239 -- **§3-A.** — THE `$0`-ADD OPAQUE COPY defeats `make_regs_eqv` (func_80033398, 93 ins) L17251 -- **§3-B.** — A `return ` IS A PRIORITY-1 HARD-REG SET THE SCHEDULER PLACES FIRST (func_8001BE30, 92 ins) L17267 -- **§3-C.** — SINGLE-SET TEMPS GET THE BIRTHING BOOST (func_8001D3FC, 196 ins) L17280 -- **§3-D.** — A NARROW TYPE BLOCKS COPY ELISION (func_8001D3FC — new idiom) L17288 -- **§3-E.** — THE ZERO-OFFSET ALIAS HOLE (func_80037028, 71 ins) L17295 -- **§3-F.** — `MEM_IN_STRUCT_P` ASYMMETRY IN `true_dependence` (func_80037144, 124 ins) L17304 -- **§3-G.** — TWO MODELLING TRAPS THAT COST THESE AGENTS SWEEPS OF HUNDREDS OF COMPILES L17310 -- **§179** — IDIOMS MINED FROM THE WAVE P/Q JOURNALS (P31 S52, harvest pass) L17326 -- **§179-A** — 🔴 A LOOP-WALKED POINTER **PARAMETER** HANDS ITS ARGUMENT REGISTER TO THE GIV (9 byte-proofs) L17336 -- **§179-B** — 🔴 THE HAND-WRITTEN-ASM TRANSCRIPTION CHECKLIST (maspsx + masked_diff; 10 byte-proofs) L17385 -- **§179-C** — 🔴 A FUNCTION WITH NO EPILOGUE (falls into a sibling's shared tail) MUST BE FILE-SCOPE `__asm__` L17435 -- **§179-D** — `gte_stflg` MUST CLOBBER `"$12"` OR THE WHOLE TEMP FILE ROTATES BY ONE L17486 -- **§179-E** — A `>2*MAX_MOVE_BYTES` BLOCK COPY IS A **STRUCT ASSIGNMENT**, NOT A HAND LOOP L17506 -- **§179-F** — PINNING A LOOP-WALKED POINTER IS A TOTAL OFF-SWITCH FOR STRENGTH REDUCTION L17532 -- **§179-G** — 🟡 A PIN CAN **CREATE** A COMBINE `LOG_LINK` AND DELETE AN `andi` (sixth RC-5 channel, n=1) L17555 -- **§179-H** — A MID-BODY `.global LABEL` PAIR SLICES A BYTE-COMPARABLE FRAGMENT OUT OF A LARGER ROUTINE L17582 -- **Considered** — and NOT banked L17605 -- **§176c** — MAIN (SLUS_007.26) CANNOT BE GATED INCREMENTALLY L17622 -- **§176** — SEVEN LEVERS FROM THE P31 OVERNIGHT WAVES (2026-08-15): statement order, false regalloc, and the pin that fights back L17633 -- **§176-A** — "SCHEDULE / DELAY-SLOT / LENGTH-DRIFT ±1" ⇒ check STATEMENT ORDER around the call first L17639 -- **§176-B** — "REGALLOC-PERM, 1-4 instructions off" ⇒ it is usually NOT register allocation L17663 -- **§176-C** — 🔴 WALL REFUTATION: a hard-register pin CANNOT schedule around a call, because of a genuine gcc-2.7.2 bug L17709 -- **§176-D** — CSE-class levers used in reverse (two sharpenings of §153 and cse_expr §2) L17735 -- **§176-E** — Two cheap source spellings, both cc1-probed L17761 -- **§176-F** — Misdiagnosis triage: four residual verdicts that were lying L17783 -- **What** — is NOT banked here L17800 -- **§180** — THE LEFTOVER-DRAFT HARVEST: RE-VERIFY WHAT YOU ALREADY HAVE BEFORE DRAFTING ANYTHING NEW L17813 -- **§180b** — WHAT THE PRE-GATE LADDER ACTUALLY FINDS IN A COLD PILE (the shape of integration debt) L17842 -- **§180c** — WHEN A BINARY'S MASS BAND IS SPENT, THE FLEET-WIDE DRAW IS STRICTLY BETTER L17861 -- **§181** — WHAT A WAVE'S GATE ACTUALLY REJECTS (P31 S53, measured on wave R's 45-draft main pile) L17879 -- **Only** — ONE of 27 blocked drafts was wrong. The other 26 were correct and unbankable. L17880 -- **§182** — §177's HONEST NEGATIVE: the epilogue lever cracked 4 of 16, and the `800c3` cluster held L17935 -- **§180d** — THE `pgrep` BRACKET TRICK PROTECTS THE PATTERN, NOT THE COMMAND LINE L17949 -- **§183** — THE DECLARATION-RECONCILIATION PLAYBOOK (P31 S53, measured on 20 byte-verified drafts) L17961 -- **§3-18** — of 20 reconciled while keeping the match. The two that did not are mechanism, not effort. L17962 -- **§184** — COMMENT-BLINDNESS IS A DEFECT CLASS, NOT A BUG (P31 S53: three tools, one root cause, one session) L18032 -- **§185** — EDIT THE SIDE THAT IS CHEAP TO VERIFY, AND CHECK A TU RETYPE AT ITS USE SITES L18060 -- **§186** — CROSS-JUMPING RUNS **AFTER** SCHEDULING, SO NO C-LEVEL BARRIER CAN STEER IT L18092 -- **§186b** — A NO-SAVE 16-BYTE FRAME IN A LEAF FUNCTION MEANS `s16` LOCALS, NOT A HIDDEN CALL L18113 -- **§186c** — WHERE A VALUE IS LOADED DECIDES WHICH ALLOCATOR OWNS IT, AND THEREFORE ITS REGISTER L18121 -- **§187** — 🔴 "SAME SOURCE" IS NOT "SAME OBJECT": THE SDK BUILD AND THE GAME BUILD DISAGREE ON GTE NOPS L18138 -- **§188** — 🔴 THE `jr $ra` + `addiu $sp` TAIL IS AN **ASSEMBLER** ARTIFACT, NOT A FRAME SHAPE L18176 -- **§189** — FIVE COMPILER LAWS MINED FROM THE WAVE R/S JOURNALS (P31 S53), each source-cited and re-derived by a second agent L18226 -- **§190** — THREE PRESCRIPTIONS FROM THE SAME HARVEST (weaker evidence than §189, honestly labelled) L18301 -- **§191** — WHAT THIS HARVEST DID **NOT** BANK (4 rejected, 4 narrowed) — recorded so it is not re-derived L18338 -- **§192** — THE PRE-GATE LADDER WAS MAIN-ONLY, AND NOBODY COULD SEE IT (P31 S54) L18360 -- **Three** — defects in one call path; the overlay slates that carry most of the wave work were being waved through L18361 -- **§193** — THE WAVE-T HARVEST (P31 S54): 71 index_gap reports -> 9 laws, 5 rejected, 61 already-covered L18425 -- **§193-A** — The wave card ships only OPEN-set pointers and discards the atlas's BANKED one — `exemplar`/`sibs` are stubs 100% by construction (tools/atlas.py:96/657), while `seed.ref` (matched pool, atlas.py:505-536) is dropped at build_wave_atlas.py:143 L18442 -- **§193-B** — A NARROW CAST OF A WIDE PARAMETER COSTS ONE EXTRA INSTRUCTION WHEN ITS STATEMENT SITS AFTER AN INTERVENING `jal` — AND THE DECIDER IS `combine.c:929`'s CROSS-CALL GUARD, NOT REGISTER ALLOCATION L18509 -- **§193-C** — gcc-2.7.2 cross_jump merges the SCHEDULED common SUFFIX only — there is no prefix/head merge, so §8/§48-A1's "duplicate into both arms and cross_jump refunds it" is a TAIL-only lever L18547 -- **§193-D** — A COMPILER-GENERATED ARGUMENT COPY IS A `optimize_reg_copy_1` TRIGGER: when the pointer's LAST use in a block precedes a call that takes the pointer *as a register*, sched1 hoists the implicit `move $aN,$sN` to the block top and local-alloc re-bases the WHOLE block's memory operands onto `$aN`. The only C dial is a label (the §165-24 goto-join) between the block and the call. L18581 -- **§193-E** — A varying-address (pointer) load is re-emitted once per CSE-LIVE INTERVAL, and naming it in a C local is the only C-level lever over that count — no store SPELLING has any reach L18652 -- **§193-F** — §148-A2 — The `threshold -= 3` STAIRCASE: `move_movables` admits a COUNT of invariants, not a boolean — two identical merged constants split hoisted/not-hoisted by LIST ORDER, and `insn_count` picks the rank cutoff L18682 -- **§193-G** — §164-54's "scope to ≥4 arms" bound is byte-wrong — the dispatch-topology oracle goes live at THREE case nodes (`balance_case_nodes` splits at `i > 2`), but only for a signed-after-promotion index L18746 -- **§193-H** — A pointer-derived base load `*(s32*)(p+K)` is uncacheable across ANY memory write or call (cse's third kill disjunct) — so the target emits one `lw` per store-separated RUN of spellings, and a run of stores sharing one `lw` is a C local you must declare L18807 -- **§193-I** — A DECLARED AGGREGATE LOCAL HAS AN 8-BYTE FRAME STRIDE — CEIL(size,8), NOT size. N ARRAYS THEREFORE COST 8·k MORE THAN ONE HAND-LAID STRUCT (k = how many of them have size mod 8 ≠ 0), AND THE TELL IS IDENTICAL INSTRUCTION COUNT WITH EVERY $sp DISPLACEMENT SHIFTED BY THE SAME CONSTANT. L18847 -- **§193-REJECTED** — what this harvest did NOT bank (recorded so it is not re-derived) L18906 -- **§194** — THE WAVE-U HARVEST (P31 S54): 64 index_gap reports -> 14 laws, 5 rejected, 44 already-covered L18933 -- **§194-A** — A zero-byte scheduling fence goes AFTER the defining statement to make that computation emit FIRST in its block — and the barrier predicate is `volatile`-or-colon-less, not the `"memory"` clobber (COMPLEMENTS §165-40; does not refute it) L18950 -- **§194-B** — A `addu $rA,$rB,$zero` copy feeding ≥2 `sh` stores is a SECOND, 16-BIT-DECLARED local — the width, not the clamp or the join liveness, is what keeps the copy (and func_80183094's pin + `"memory"` clobber are both provably inert) L19016 -- **§194-C** — A CALLER-SAVED loop counter proves its live range crosses ZERO calls — so it cannot share a pseudo with any value LIVE ACROSS a call (but it may freely share one with values that merely sit between calls) L19054 -- **§194-D** — Declared width of a computed-value local is a sched1 dial (count-neutral) — a replication + attribution correction of §165-17, NOT a new argument-register law L19117 -- **§194-E** — The wave card's `exemplar` is the TARGET ITSELF on 42/73 wave-U and 36/71 wave-T cards — a construction consequence of `atlas.py:657` (exemplar = max-nins OPEN member) meeting `build_wave_atlas.py:166` (one card per gid); and the shipped §193-A `seed_ref` is same-binary on 0/51, so no card field can ever name a destination-TU sibling L19158 -- **§194-F** — `if ((*p = v = f()) == 0)` is an expand-time pseudo SPLITTER (store_expr's `want_value && MEM` path), not a fold — it partitions one value between local_alloc and global_alloc. BOUNDS §21's L1872 bullet, whose stated direction is byte-wrong on 3 of 4 instances, and CLOSES the control §167-37 asked for. L19195 -- **§194-G** — Reading the integer half of a 16.16 stack aggregate: REGISTER-LIVENESS, not the C spelling, decides `sra` vs `lhu` — and the break is count-neutral L19268 -- **§194-H** — §164-29's WAR fence runs again at SCHED2 ON HARD REGISTERS: an in-place `v &= K` before a branch fences the store that reads v, and when TWO independent stores compete for the one delay slot the fence picks the winner at ZERO length drift (a WIDTH/sh!=sw swap, not a nop). Corrects §167-42's reconstruction (pseudo arm → hard-reg arm) and supplies its first re-runnable A/B. L19311 -- **§194-I** — §16N+2's magic-per-odd-part ladder has exactly one broken row — read the divisor arithmetically instead: d = round(2^(32 + post_shift) / magic_read_as_unsigned) L19349 -- **§194-J** — Back-to-back identical stores: flow.c's `last_mem_set` deletes the first, and only `volatile` saves it L19392 -- **§194-K** — Blind sched1's alias oracle with a second SET of a pointer pseudo — the first zero-byte, non-volatile, dependence-CREATING lever (corrects §167-05's "volatile is the only door"; fourth consumer of reg_n_sets) L19444 -- **§194-L** — §88b and §189-E are BOTH half-wrong, but not the way the candidate says: the compare-constant shape is a 2-D lookup (cmp_info ROW × constant-in-window), and naming matters on OPPOSITE sides of the window for the GE/LT rows vs the GT/LE rows L19522 -- **§194-M** — A STORE in a CONDITIONAL branch's delay slot proves its C statement DOMINATES the branch — reorg can never pull a store out of either thread (gcc-2.7.2, -mips1) L19570 -- **§194-N** — §193-D's C dial is misstated: the lever is a SURVIVING CODE_LABEL (a label with a real incoming edge), not "a label between the block and the call" — a bare label, or a `goto L; L:` pair whose target is the next active insn, is deleted by jump1 (jump.c:663-669 → delete_insn → jump.c:3458-3461, and jump.c:243 for the bare case) long before sched1/local-alloc, and costs exactly zero bytes L19628 -- **§194-REJECTED** — what this harvest did NOT bank (recorded so it is not re-derived) L19688 -- **§195** — THE WAVE-V HARVEST (P31 S54): 67 index_gap reports -> 14 laws, 9 rejected, 76 already-covered L19709 -- **§195-A** — §167-08's "an $aN READ before the jal is scratch" has a byte-proven FALSE-NEGATIVE class: an argument that DIES at the call is allocated straight into $aN, so its only def is a plain load far above the jal and every intervening use reads $aN — there is no positive tell in either direction, only the two-arity A/B L19723 -- **§195-B** — A CALL_INSN does not start a basic block in gcc-2.7.2 — so a call-crossing temp can be a LOCAL-alloc quantity (the missing precondition under §48-A2 / §52 / regalloc.md K8) L19794 -- **§195-C** — A call-argument `%hi/%lo` pair sitting at the block head, far above its `jal`, is a load-delay-gap filler chosen by SOURCE STATEMENT ORDER — swap the two independent statements nearest the call; a single-use `void *p = &SYM;` call-arg temp is OUTPUT-inert against it (but NOT expand-stream-inert) L19836 -- **§195-D** — §195 — `masked_diff.mask_for` returns 0 for EVERY `j`/`jal` word, so an internal `j` destination is invisible to match_one, the permuter scorer AND every similarity tier: a control-flow semantic error (which calls execute) surfaces as a 1-instruction residual mislabelled `DELAY-SLOT / profile=schedule`, or as an outright false MATCH L19884 -- **§195-E** — A 0/1 materialised at a JOIN immediately before the controlling `beqz`/`bnez` proves the source NAMED the condition — a truth expression in an `if`'s controlling position reaches `do_jump`, which has no value path L19952 -- **§195-F** — fold-const.c:4825 canonicalises a `?:` whose THEN arm is zero (or constant against a non-constant ELSE) by inverting the condition and swapping the arms — so a ternary's written arm order is byte-inert there, and `c ? 0 : X` is unspellable: it always compiles as `!c ? X : 0` L20010 -- **§195-G** — §NEW — TWO ARMS CALLING THE SAME CALLEE MERGE INTO ONE `jal` UNLESS EACH ARM'S OWN CODE CONSUMES THE RESULT: the C dial that keeps two call sites apart is WHERE the consumer test lives, and the branch SENSE you spell it with is byte-inert (jump.c:1737 canonicalises it) L20062 -- **§195-H** — §165-27g — ON A FIXED-SYMBOL GLOBAL, `extern T D[];` + `D[0]` IS THE CSE RELOAD DIAL, AT ZERO ADDRESSING COST, AND THE ELEMENT COUNT IS INERT (§165-27's `T v[2]` CAVEAT IS A LOCAL-FRAME FACT AND DOES NOT TRANSFER) L20110 -- **§195-I** — §145(b) AMENDED — the pointer-bump `addiu` is saved by cse, not combine: ANY second SET of a pseudo in the address's equivalence chain (in-place `p += K`, §145(b)'s `p = r;` copy, or an asm re-tie) kills the fold; the pass is cse and the gate is `invalidate`'s `reg_tick++` L20157 -- **§195-J** — GTE / PsyQ op CALL-vs-INLINE is a PER-SITE SOURCE FACT, not a TU style — both forms coexist in one TU (measured in 2 TUs), and the tell is the target's own opcodes (`lwc2`/`sqr`/`swc2` vs `jal`), not the sibling. Costs -8 ins on func_8018505C. Corollary: the game's inline `sqr` macro emits TWO hazard nops, the SDK's `Square0` body emits ONE — so the inline form is provably not `Square0` inlined (a second instance of §187's SDK-vs-game GTE nop divergence). L20222 -- **§195-K** — At -O2 the §18 array-of-struct lever is a FRAME lever, not a length lever — but only when the N reads carry DISTINCT index expressions; with a SHARED index §18's +2-instruction residual is still alive at -O2 (the submitted "memory-loaded narrow index" precondition and unconditional length-neutrality are both falsified) L20266 -- **§195-L** — The cse store-re-seed does not cross a JOIN LABEL: per-arm stores + a join read keep the reload that one join store deletes (bounds §193-E BOUND 1/BOUND 3 with §48-B's EBB boundary) L20318 -- **§195-M** — Frame `vars` is a SEQUENTIAL bump-allocation, not a flat sum: §193-I's CEIL(aggregate,8) term and §165-03/§167-06's 8×orphan term are the SAME frame_offset walk at two different compiler stages, and each stage re-CEILs frame_offset to 8 before it allocates L20370 -- **§195-N** — In a call-bearing chain of N≥2 `if (f(...)) return 1;` tests closed by `return 0;`, the LAST test must stay in STATEMENT form — the value form (`return f() != 0;` / `? 1 : 0` / `!!f()`) costs +1 `j` and empties the other N−1 delay slots. The cause is REORG block placement, not jump.c's `delete_jump`. L20419 -- **§195-REJECTED** — what this harvest did NOT bank (recorded so it is not re-derived) L20466 -- **§196** — PUT ON THE CARD WHAT THE TREE ALREADY KNOWS: the fleet's declaration consensus (P31 S54) L20512 -- **§197** — THE WAVE-W HARVEST (P31 S54): 68 index_gap reports -> 4 laws, 3 rejected, 41 already-covered L20567 -- **§197-A** — A NARROW SIGNED MEMORY READ FEEDING A CONSTANT `>>` LOSES ITS `lh`, AND THE CURE IS AN ASM RE-TIE (attribution CONTESTED: cse vs combine) L20581 -- **§197-B** — A REPEATED COMPARE OF ONE VALUE AGAINST ONE CONSTANT IS DELETED BY cse's `qty_comparison_code` CHANNEL (the non-EQ complement of §165-03) — and a front-end-opaque mask on EITHER compare is a pure-C dial that keeps the target's second branch L20619 -- **§197-C** — Fix A1 (operand order) cannot move a commutative destination whose .greg conflict set already contains BOTH operand hard registers — split the accumulate so the destination IS the load's pseudo L20647 -- **§197-REJECTED** — §197-REJECTED L20692 -- **§199** — THE WAVE-X HARVEST (P31 S54/S55): 63 index_gap reports -> 7 laws, 2 rejected, 56 already-covered L20707 -- **§199-A** — §189-A's asm→source inference is byte-FALSE: an interloper between a split constant's `lui`/`ori` is a SCHEDULE fact, not a source fact — and the separator is the BIRTHING BOOST, not a "priority floor" (§189-A's split-timing half survives; its "no statement order / no pin" absolute and the candidate's own forward-scheduler narrative both fall) L20718 -- **§199-B** — A permutation sweep that holds ANY statement fixed is not a sweep: the statement an agent pins as "obviously load-bearing" is the one carrying the signal, and the partial sweep returns a FLAT residual that reads as proof of order-invariance L20767 -- **§199-C** — A NEGATIVE CONSTANT MULTIPLY ALWAYS TAKES expmed's negate_variant — but whether you ever SEE the neg is decided by COMBINE, and for an EVEN |K| it never disappears L20812 -- **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` L20860 -- **§199-E** — §189-A BOUNDED AND CORRECTED — the discriminator is INSN_PRIORITY, not "is the interloper a constant": an insn between a `lui`/`ori` pair proves NOTHING about the source spelling unless it TIES the `ori` on priority, and on the pinned `-mcpu=3000` triple a dependent load never does L20920 -- **§199-F** — §164-36b — THE TARGET-HEAD FENCE IS A DELAY-SLOT THREAD SELECTOR, AND IT ONLY FIRES WHEN `mostly_true_jump > 0` (amendment to §164-36; its "−1 instruction" tell is falsified) L20979 -- **§199-G** — At TWO case nodes the switch-vs-if oracle is not blind — but the tell is ALL tests positive + a trailing `j default`, NOT the first test's polarity L21033 -- **§199-REJECTED** — §199-REJECTED L21088 -- **§200** — THE ALIAS IS THE UNIVERSAL DECLARATION ESCAPE: stop negotiating with the TU's spelling (P31 S55) L21099 -- **§201** — THE WAVE-Y HARVEST (P31 S55): 67 gap reports -> 5 laws, 8 rejected, 53 already-covered L21148 -- **§201-A** — §150-B applies to `decl_prior`'s DEF row: for an overlay-window symbol the banked "definition" is usually another overlay's function, and the card ranks it ABOVE the destination TU L21158 -- **§201-B** — In a narrowed PLUS/MINUS/AND/IOR/XOR expression the destination pointee is INERT — the sign of the materialized constant is decided by an OR over the UNWIDENED operands (convert.c trunc1), which bounds §1841 to direct constant stores L21190 -- **§201-C** — §X — A CALL'S OWN DELAY SLOT AND THE UPSTREAM CONDITIONAL BRANCH'S SLOT COMPETE FOR ONE INSN (the call's argument copy), AND ONE STATEMENT'S POSITION RELATIVE TO THE CALL DECIDES BOTH — the residual is visible at the BRANCH, not at the call L21270 -- **§201-D** — THE SIGNEDNESS OF A div/mod MAGIC IS DECIDED BY THE STATIC TYPE OF THE DIVIDEND TREE AFTER `get_narrower` STRIPS WIDENING CONVERSIONS — NEVER BY A PROVABLE RANGE. AN `& 0xFF` IS NOT A CONVERSION, SO IT NEVER FLIPS THE MAGIC; A DECLARED-UNSIGNED LOCAL *OR* A NARROWING CAST WRITTEN AT THE DIVIDE BOTH DO. L21321 -- **§201-E** — §194-J-2 — The `last_mem_set` deletion window is measured in SOURCE/expand order, not in the printed stream; a foreign store moved between the pair in C source is a real lever, and `volatile` is not always the better one L21368 -- **§201-REJECTED** — eight, the session's highest L21424 -- **§202** — THE ALIAS CARRIES A DEFINITION, NOT JUST A DECLARATION: the DEF-SIDE-RETURN wall (P31 S56) L21449 -- **§203** — A DEDUPED TYPEDEF MUST PRECEDE EVERY SPLICE POINT, NOT JUST ITS OWN (P31 S56) L21486 -- **§204** — THE WAVE-Z HARVEST (P31 S56): 82 gap reports -> 5 laws, 16 rejected, 30 already-covered L21547 -- **§204-A** — A COMPARE THAT APPEARS BOTH IN A BRANCH'S DELAY SLOT AND AGAIN ON THE FALL-THROUGH IS A JOIN WITH TWO INCOMING EDGES: THE TWO GUARDS ARE SEQUENTIAL `if`s, NEVER `if/else if` L21566 -- **§204-B** — A LOOP COUNT THAT ARRIVES ON THE STACK IS DECREMENTED IN PLACE: a fresh counter local can cost a real `move` AND permute the whole callee-saved file L21641 -- **§204-C** — WHEN A LOCAL BUFFER'S ADDRESS IS PASSED TO A CALL, ITS SIZE IS A FACT ABOUT THE CALLEE'S BODY, NOT ABOUT THE CALL SITE: grep the callee's proven definition and count the stores through the pointer parameter before you declare the local L21705 -- **§204-D** — A LOOP-INVARIANT LOAD IS ADMITTED AS A MOVABLE ONLY IF ITS ADDRESS CANNOT TRAP: `local.field` PASSES, THE SAME READ THROUGH A POINTER LOCAL IS REFUSED L21763 -- **§204-E** — `decl_prior`'s `%hi/%lo` ARM HAS NEVER FIRED: the card's promised GLOBAL-TYPE row is 0 of 1,210 L21838 -- **§204-CONFIRMED** — 30 reports that the index already answered L21890 -- **§204-REJECTED** — sixteen, twice the previous record L21984 -- **§205** — THE CHAINED ASSIGNMENT IS ITS OWN SCHEDULING DIAL: `*b = *a = v;` moves an argument copy that no local, no pin and no statement reorder will move (P31 S56) L22057 -- **§206** — THE JTBL-CARVE DRAFTING IDIOM: the bounds check is the entry count, and an EMPTY case owns a slot (P31 S56) L22112 -- **§207** — THE WAVE ab–ag HARVEST (P31 S58): 278 byte-banked notes → 25 laws, 103 self-reported no-gap L22181 -- **§208** — TWO NAMED LOCALS FOR ONE RELOADED EXPRESSION BUY TWO ALLOCNOS — the naming granularity owns the REGISTER SPLIT, not just the load count (P31 S58) L22202 -- **§209** — THE NARROW LOCAL IS A DIAL IN TWO OPPOSITE DIRECTIONS, AND §194-B's "≥2 `sh` STORES" BOUND IS BYTE-WRONG (P31 S58) L22251 -- **§210** — THE SINGLE-BIT MASK IN A BOOLEAN TAIL: `andi K ; sltu $zero,v` vs `srl n ; andi 1` is a STATEMENT-SHAPE dial, not an operator choice (P31 S58) L22328 -- **§211** — HOIST THE LOOP INIT ABOVE THE DOMINATING GUARD: it fills the guard's delay slot AND flips the counter/pointer register pair (P31 S58) L22374 -- **§212** — THE WALKING CURSOR IS COUNTABLE: `*wp++` emits one `addiu` PER STORE, `wp[0..2]` emits one (P31 S58) L22433 -- **§213** — INDEPENDENT SAME-BASE STORES: THE EMISSION ORDER IS A PERMUTATION OF SOURCE ORDER, AND THE PERMUTATION IS NOT ALWAYS THE IDENTITY (P31 S58) L22478 -- **§214** — THE BANKED TWIN MAY BE A MACRO, A DELETED `.s`, OR A SEMANTIC INVERSE — six ways a ≥0.9 similarity lies (P31 S58) L22514 -- **§215** — PIN ECONOMY: the twin's pins are NOT part of the shape, and §17's "pin every call-crossing value" is over-broad (P31 S58) L22560 -- **§216** — DISTINCT ADJACENT SCALARS vs ONE ARRAY: one `lui` per access is the tell, and the array decl is UNUSABLE (P31 S58) L22616 -- **§217** — DECODING A CALL'S STACK ARGUMENT SLOTS: `sw` at `0x10`/`0x14`/`0x18` are params 5/6/7 **(single observation — not yet cross-confirmed)** (P31 S58) L22656 -- **§218** — A NARROW TYPE AT THE ABI BOUNDARY COSTS AN IN-PLACE `sll/sra` PAIR — on the RETURN as well as on the PARAMETER (P31 S58) L22682 -- **§219** — COMPOUND `+=`, FULL ASSIGNMENT, AND AN EXPLICIT TEMP ARE THREE DIFFERENT SCHEDULES OF ONE READ-MODIFY-WRITE (P31 S58) L22711 -- **§220** — THE PARAMETER ITSELF IS A REGALLOC DIAL: use it directly, prefer `s32` to `void*`, and place the save-copy AFTER the first call (P31 S58) L22738 -- **§221** — A CONSTANT SHARED BY TWO STORES DIES AT THE CALL WHOSE DELAY SLOT REFILLS ITS REGISTER **(single observation — not yet cross-confirmed)** (P31 S58) L22778 -- **§222** — SWITCH vs IF-CHAIN, PART 3: source arm order IS emission order, a leading EMPTY case buys the median split, and a 2-way dispatch with a shared post-block is a `switch` (P31 S58) L22794 -- **§223** — READING A `jal` DELAY SLOT: the value in it was produced BEFORE the call, so it is NEVER that call's return (P31 S58) L22836 -- **§224** — CROSS-JUMP: WRITE THE DUPLICATE, AND READ A SHARED DELAY SLOT AS THE MERGE SIGNATURE (P31 S58) L22898 -- **§225** — THREE CONTROL-FLOW SHAPES NO STRUCTURED SPELLING REACHES (P31 S58) L22934 -- **§226** — FRAME PADS: FOUR WAYS §162i1/§2429's DEAD-LOCAL LEVER MISFIRES (P31 S58) L22977 -- **§227** — TYPE THE SOURCE BY THE **LOAD** WIDTH, NOT BY THE STORE WIDTH (P31 S58) L23018 -- **§228** — READING THE DIVIDE, PART N: the off-by-one compare is `% K == 1`, and three more discriminators (P31 S58) L23038 -- **§229** — THE ADDRESS IS A VALUE: NAMING IT MOVES THE `lui`/`addiu` PAIR — AND §L14410 SAYS THE OPPOSITE FOR A REASON (P31 S58) L23075 -- **§230** — THE ANCHOR PROBE: with `%hi`/`%lo` masked, the surviving `addiu` deltas tell you which assignment was written first **(single observation — not yet cross-confirmed)** (P31 S58) L23124 -- **§231** — TRANSCRIPTION AND SEMANTIC-READ HYGIENE: six ways the listing misleads (P31 S58) L23139 -- **§232** — WHEN THE `jr` DELAY SLOT'S STORE STORES THE RETURN VALUE, TIE THEM WITH ONE PSEUDO **(single observation — not yet cross-confirmed)** (P31 S58) L23180 -- **§30** — addendum (P31 S58) — the `/s` grant closes a SCHEDULING residual and a REGISTER residual with one edit L23216 -- **§194-B** — addendum (P31 S58) — BOUND 2 is byte-wrong; see §209 Direction A L23236 -- **§176-B** — addendum (P31 S58) — the misdiagnosis direction L23242 -- **§165-40** — addendum (P31 S58) — the barrier goes at the COPY SITE, not inside the region it protects L23248 -- **§164-63** — addendum (P31 S58) — the interposed asm works when the SECOND value is an ordinary assignment L23257 -- **§193-A** — / §194-E addendum (P31 S58) — where the twin's body actually lives L23266 -- **§233** — THE WAVE aa–bg HARVEST (P31 S58b): 1,101 byte-banked notes → 24 new laws, 21 addenda, ~700 already-covered L23272 -- **§234** — CONSTANT MATERIALISATION: THE STORE LVALUE'S SIGNEDNESS PICKS `addiu` vs `li`/`ori` (P31 S58b) L23316 -- **§235** — THE PHANTOM SYMBOL: A MASKED `MATCH` CAN CARRY A RELOCATION THAT DOES NOT EXIST (P31 S58b) L23357 -- **§236** — THE DECLARATION LAYER IS THE DOMINANT BANK-BLOCKER: NINE WAYS A BYTE-PERFECT BODY FAILS THE GATE (P31 S58b) L23386 -- **§237** — THE CAST-AT-CALL-SITE DECISION TABLE: WHAT §17a-1 FIXES, WHAT IT CANNOT, AND THE FOUR ESCAPES (P31 S58b) L23465 -- **§238** — SAME NAME, DIFFERENT FUNCTION: THE OVERLAY-HOMONYM TRAP (P31 S58b) L23520 -- **§239** — TWO-STATEMENT INTEGER-SPACE MATERIALISATION REORDERS `la` vs `sll`; AND THE PLUS-TREE OPERAND ORDER (P31 S58b) L23560 -- **§240** — `A + K + B`: WRITE THE CONSTANT **BETWEEN** THE TWO RUNTIME TERMS (P31 S58b) L23594 -- **§241** — THE FOLDED SIGN-EXTEND-AND-SCALE: `sll 16 ; sra (16 − log2 scale)` (P31 S58b) L23623 -- **§242** — `*k` vs `<>n`: EXPRESSION SPELLING OWNS THE LOAD WIDTH AND THE ROUNDING CHAIN (P31 S58b) L23652 -- **§243** — SPELL THE CSE BARRIER AS A REASSIGNED POINTER; AND THE `nop`-AFTER-EVERY-`lh` SIGNATURE (P31 S58b) L23680 -- **§244** — `volatile` IS A COUNTING INSTRUMENT, A STORE-ORDER PIN, AND MUST SOMETIMES BE ASYMMETRIC (P31 S58b) L23710 -- **§245** — THE CALL'S ARGUMENT LIST IS A SCHEDULING SLOT (P31 S58b) L23745 -- **§246** — THREE-LIVE-VALUE SCAN LOOPS WANT ADDRESS-FROM-INDEX; AND TWO SYMBOLS CAN SHARE ONE giv (P31 S58b) L23792 -- **§247** — TWO BRANCHES TO **ONE** LABEL MEANS THE SOURCE CONDITION IS NEGATED (P31 S58b) L23832 -- **§248** — SPLIT THE LOAD FROM THE ARITHMETIC: A FUSED `g + K` DENIES THE CALLEE-SAVED REGISTER ITS DIRECT HOME (P31 S58b) L23866 -- **§249** — THE SELF-ASSIGN, THE DEAD RE-ASSIGN, AND THE `+ zr` COPY: THREE WAYS TO MAKE A DELETED INSTRUCTION REAL (P31 S58b) L23890 -- **§250** — `%hi/%lo` vs `lw`: THE EXTERN'S ARRAY-vs-SCALAR SHAPE DECIDES ADDRESS MATERIALISATION (P31 S58b) L23932 -- **§251** — IMMEDIATE-SPELLING TRIGGERS: `+= 0xFF`, FULL-WIDTH `~K`, AND THE TWO-OR SPLIT (P31 S58b) L23969 -- **§252** — THE GUARDED PRE-DECREMENT: `(x != 0) && (--x == 0)` (P31 S58b) L23991 -- **§253** — POSTFIX `++` vs `+= 1` PICKS A DIFFERENT SCRATCH REGISTER **(single observation — not yet cross-confirmed)** (P31 S58b) L24012 -- **§254** — THE DEAD PARAMETER IS A REGISTER-PLACEMENT TOOL **(single observation — not yet cross-confirmed)** (P31 S58b) L24026 -- **§255** — THE EMPTY CASE, PART 2: FOUR TREE SHAPES IT BUYS (P31 S58b) L24038 -- **§256** — GOTOS IN THE TARGET'S BLOCK ORDER REPRODUCE SWITCH PLACEMENT WITHOUT SWITCH'S SIDE EFFECTS (P31 S58b) L24073 -- **§257** — THE DEAD-END LEDGER (P31 S58b): ELEVEN LEVERS THAT MEASURED NULL OR BACKFIRED L24110 -- **§258** — ADDENDA TO EXISTING SECTIONS (P31 S58b) L24153 -- **§30** — addendum (P31 S58b) — THE ANONYMOUS STRUCT MEMBER REF GRANTS `/s`, AND THAT IS A TWO-FOR-ONE L24158 -- **§194-B** — / §209 addendum (P31 S58b) — TWO MORE INSTANCES, AND THE BOUND IS NOW REFUTED FOUR WAYS L24179 -- **§202** — addendum (P31 S58b) — THE DEF-SIDE ALIAS ALSO CLEARS A RETURN+PARAM DOUBLE CONFLICT L24202 -- **§205** — addendum (P31 S58b) — CHAINED ASSIGNMENT: N≥3 IS INNERMOST-FIRST, AND THE TEXT MIRRORS EMISSION L24213 -- **§208** — addendum (P31 S58b) — IT SCALES TO SIX SITES, AND IT HAS AN EXACT INVERSE L24230 -- **§210** — addendum (P31 S58b) — THREE CONFIRMED SPELLINGS OF THE BOOLEAN TAIL L24259 -- **§211** — addendum (P31 S58b) — INIT PLACEMENT: FIVE MORE DIALS BEYOND THE GUARD HOIST L24275 -- **§213** — addendum (P31 S58b) — THREE MORE PERMUTATION LAWS FOR INDEPENDENT SAME-BASE STORES L24318 -- **§214** — addendum (P31 S58b) — FOUR MORE WAYS A HIGH-SIMILARITY TWIN LIES L24347 -- **§215** — addendum (P31 S58b) — PIN ECONOMY, PART 2: NINE REFINEMENTS L24383 -- **§217** — CROSS-CONFIRMED (P31 S58b) — AND THE INCOMING HOME SLOT IS THE MIRROR L24435 -- **§220** — addendum (P31 S58b) — THE PARAMETER, NOT A COPY (SEVEN CARDS) L24452 -- **§222** — addendum (P31 S58b) — IF-CHAIN vs SWITCH: THREE MORE DISCRIMINATORS L24477 -- **§223** — addendum (P31 S58b) — FIVE MORE CONFIRMATIONS, AND THE CONSTANT-IN-`$v0` CASE L24495 -- **§224** — addendum (P31 S58b) — CROSS-JUMP MERGES *CALLS*, AND THE DELAY SLOT IS THE DISCRIMINATOR L24519 -- **§225** — addendum (P31 S58b) — THE GUARD-CLAUSE FINGERPRINT, AND THREE MORE SHAPES L24549 -- **§226** — addendum (P31 S58b) — THE FRAME CATALOGUE: SEVEN MORE LEVERS, AND SLOT ORDER IS DECLARATION ORDER L24576 -- **§229** — addendum (P31 S58b) — NAME IT **INSIDE** THE ARM L24621 -- **§230** — CROSS-CONFIRMED (P31 S58b) L24632 -- **§231** — addendum (P31 S58b) — FOUR MORE WAYS THE LISTING MISLEADS L24641 -- **§232** — CROSS-CONFIRMED (P31 S58b) L24672 -- **§259** — THE DISCARD LEDGER FOR THE aa–bg HARVEST (P31 S58b): WHAT WAS MINED AND REJECTED, AND WHY L24683 -- **§260** — THE §154-A LEADING-ISLAND SPLIT: ONE CONFIG LINE, AND THE ISLAND PEELS FROM THE END (P31 S59, byte-proven) L24722 -- **§260-A** — STAGE 2 IS PROVEN, AND THE WHOLE jtbl PIPELINE IS AUTOMATED AT THE GATE (P31 S59, same day) L24772 -- **§261** — THE -O0 ORACLE: DERIVE THE OPT LEVEL FROM THE TARGET, AND `$fp` IS NOT THE TELL (P31 S59) L24808 -- **§261a** — THE -O0 FRAME-RELOAD GRAMMAR: reload COUNT disambiguates the C spelling (P31 S59, byte-proven) L24834 -- **§262** — A LANE'S YIELD IS ONLY A LANE FACT IF IT IS SIZE-MATCHED (P31 S59) L24856 -- **§263** — A STOLEN DELAY SLOT WHOSE INSTRUCTION IS AN ARG-REGISTER COPY IS AN ARITY ERROR, NOT A SCHEDULE (P31 S59, byte-proven) L24886 -- **§264** — FOUR TELLS-LANE C RECIPES, EACH DRIVEN TO MATCH (P31 S59) L24927 -- **§265** — THE VERBATIM-ASM BANK LANE: A FUNCTION NO -O2 C CAN EVER MATCH BANKS AS A RAW `__asm__` BODY (P31 S59b; two banked cards, two in-tree precedents) L24977 -- **§266** — THE INERT-RIDER LAW: A LEVER IS ONLY CITABLE WHEN ITS SOLO REMOVAL BREAKS THE MATCH (P31 S59b; measured 4-of-8 on this batch) L25039 -- **§267** — ADDENDA HARVESTED FROM WAVES at/bh/bk/bl (P31 S59b) L25079 -- **ADD-1** — → §231 addendum (also cross-ref from §195-D) — THE MASKED-`jal` "MISSING CALL" ILLUSION L25087 -- **ADD-2** — → §42a addendum — A SHARED CONSTANT *NAMED IN A LOCAL* ACROSS A `jal` IS AN ISO→TU DRIFT HAZARD; WRITE BARE LITERALS L25096 -- **ADD-3** — → §236, item 10 — THE UN-DELETED `INCLUDE_ASM` STUB IS A DUPLICATE DEFINITION L25108 -- **ADD-4** — → §225-3/-4 addendum — THE MIRROR ROW: VALUE-RETURN IN THE *TAKEN* ARM + TRAILING BARE `return 0` L25118 -- **ADD-5** — → §1/I1 addendum — THE INVERTED RANGE TEST: `(u32)(x-lo) >= N` WITH THE ZERO-ARM AS THE TRAILING `else` L25132 -- **ADD-6** — → §172b-1 / §264 addendum — SHIFT-AS-TEST: `(x << 16) != 0` TESTS THE LOW HALF WITHOUT TRUNCATING THE PSEUDO L25141 -- **ADD-7** — → §256 addendum — THE SINGLE-GUARD GOTO: THEN-BLOCK OUT OF LINE AT THE TAIL L25150 -- **ADD-8** — → §245 addendum — THE RE-TIE BARRIER PINS CALL-ARG SETUP TO SOURCE ORDER (construct 6) L25162 -- **ADD-9** — → §213-3 / §217 addendum — ADJACENT PRE-CALL FRAME STORES ARE ONE AGGREGATE; THE UNESCAPED SCALAR NEIGHBOR IS DEAD-STORED L25174 -- **ADD-10** — → §237 addendum (arity-evidence paragraph) — AN `la` PAIR ABOVE THE PROLOGUE `sw $ra` IS AN OUTGOING-ARGUMENT MATERIALISATION L25184 -- **ADD-11** — → Cross-confirmation card block (per §259's standing instruction: confirmation, not news) L25193 -- **§268** — A `register __asm__` PIN ON A CALL-CLOBBERED REGISTER IS HONORED EXACTLY WHEN THE PINNED RANGE CROSSES NO CALL (P31 S59c; three A/B'd cards, unifying §257-2's two) L25244 -- **§269** — ADDENDA HARVESTED FROM WAVES ax/bm (P31 S59c) L25298 -- **ADD-1** — → §257-8 addendum — THE INTERPOSED ASM'S `__volatile__` IS A PER-SHAPE DIAL, AND THE "NO-OUTPUT ASM IS IMPLICITLY VOLATILE" LORE IS BYTE-FALSE IN gcc-2.7.2 L25313 -- **ADD-2** — → §236 addendum (item 1 corollary) — THE SILENT-SPLICE DECLARATION LADDER: WHERE THE TU HAS NO SPELLING, UNPROTOTYPED `()` BEATS THE FLEET VOTE L25326 -- **ADD-3** — → §238 addendum — TWO BINARIES CAN EACH DEFINE THE SAME `func_` NAME WITH DIFFERENT BYTES, AND NO GENERATED REPORT SHOWS IT L25340 -- **ADD-4** — → §167-37 addendum — THE FIFTH PRECONDITION, NOW MEASURED: DOWNSTREAM FIELD RE-READS ⇒ NAME IT **AND** STORE **INSIDE** THE ARM L25353 -- **ADD-5** — → §267-ADD-6 / §172b-1 addendum — THE SIGN-TEST FACE: `(s16)v < 0` IS `sll 16` + `bgez` ON THE SHIFTED COPY, RAW STAYS LIVE — AND THE HALFWORD-ABS SHAPE NEEDS NO RITUAL L25370 -- **ADD-6** — → §220-addendum — THE FOURTH FACE: WHEN THE NAMED COPY ITSELF BUYS THE EXTRA CALLEE-SAVED, PIN THE COPY TO `$16` L25386 -- **ADD-7** — → §229 addendum — THE VALUE FACE: A LOOP-STORE CONSTANT SPELLED AS A LITERAL HAS NO SOURCE POSITION; NAME IT TO PIN THE PROLOGUE INIT ORDER L25402 -- **ADD-8** — → §30a addendum — THE THIRD COLUMN: `*p++` IS ALSO SERIALIZED BUT BURNS `addiu`; ONLY CAST-PLUS GIVES SERIALIZATION *AND* DISPLACEMENT FOLDING L25415 -- **ADD-9** — → §255 "AND CASE-BODY PLACEMENT" bound / §222-addendum-3 — ON A LARGE SPARSE TREE, BODIES FOLLOW **SOURCE** ORDER (measured by a one-word probe) L25430 -- **ADD-10** — → Cross-confirmation card block (per §259's standing instruction: confirmation, not news) L25444 -- **§3-1a.** — The §266 sweep — every solo-lever A/B run for this batch L25485 -- **§270** — The A-prop 0-bank anatomy: a byte-correct body still needs FOUR layers to agree (P31 S59) L25518 -- **§271** — Ordinal IMM pairing: text order is NOT emission order; emit CANDIDATES, let the oracle pick (P31 S59) L25536 -- **§272** — The `(void)`-decl + empty-call wall: K&R the DEFINITION, not just the decls (P31 S59) L25558 -- **§273** — A standalone compile is the WRONG oracle for a TU-destined draft (P31 S59) L25578 -- **§274** — ADDENDA HARVESTED FROM 18 WAVES (P31 S60): 315 candidates, 255 already covered, 21 sharpenings, 3 new laws L25593 -- **ADDENDUM** — to §179-C — the `.type NAME, @function` requirement L25599 -- **ADDENDUM** — to §134 — a typedef defined BELOW the splice point is stripped anyway L25646 -- **ADDENDUM** — to §179-D (GTE macro reference family) — `gte_SetRotMatrix`/`gte_SetTransMatrix` bodies L25676 -- **ADDENDUM** — to §82 — struct copies must stay MEMBER-WISE, not block-moved, to match a spill-slot save L25702 -- **ADDENDUM** — to §136d-1 (RC-12, the `$0`-add / opaque-copy family) — two symptoms beyond "compare reads the wrong register" L25740 -- **ADDENDUM** — to §20 — a global declared as `T *` may itself BE the array base, not a pointer to dereference L25779 -- **ADDENDUM** — to §1-I5 L25808 -- **ADDENDUM** — to §164-51 L25873 -- **ADDENDUM** — to §176-F5 L25889 -- **ADDENDUM** — to §225 L25918 -- **ADDENDUM** — to §224 — CROSS-JUMP: THE DUPLICATE CAN BE A PLAIN STORE, NOT ONLY A CALL L25963 -- **ADDENDUM** — to §164-64 — AN EMPTY CLOBBER ON AN ARGUMENT REGISTER CAN BE THE DELIBERATE FIX, NOT JUST THE ACCIDENTAL BUG L25997 -- **ADDENDUM** — to §244 — THE COMPILER BARRIER, NOT `volatile`, BLOCKS A STORE→LOAD HOIST THROUGH A POINTER-OFFSET FIELD L26028 -- **ADDENDUM** — to §172b-1 — TWO PLACEMENT DIALS THE PROMOTION LAW DOESN'T NAME: NARROW THE COUNTER'S DECLARED TYPE, AND MOVE THE CAST INTO THE LOOP BODY L26059 -- **ADDENDUM** — to §229 — A POINTER'S NUMBER OF USES DECIDES WHETHER ITS ADDRESS FOLDS OR SURVIVES A CALL L26106 -- **ADDENDUM** — to §172b-4 — THE PLAIN CAST-DIVISION ALREADY PRODUCES THE PATTERN; DON'T HAND-ROLL THE BIAS, AND KEEP THE OPERAND WIDE L26151 -- **ADDENDUM** — to §8 — WHEN `INCLUDE_RODATA` NEEDS A STANDALONE `.s` YOU CAN'T CREATE, CARRY THE FRAGMENT AS A FILE-SCOPE `__asm__` BLOB L26181 -- **ADDENDUM** — to §226 — A DEAD LOCAL SCOPED TO A NESTED BLOCK BUYS A MID-FUNCTION `addiu sp` PAIR, NOT A FRAME-SIZE CHANGE L26224 -- **ADDENDUM** — to §172a — RE-READING MEMORY (NOT NAMING A TEMP) IS WHAT KEEPS AN INCREMENT'S DELAY-SLOT FILL ALIVE L26263 -- **ADDENDUM** — to §225 / §256 — A GOTO TO A SHARED SET-POINT PREVENTS IF-CONVERSION FROM COLLAPSING A LATER BRANCH TEST L26294 -- **ADDENDUM** — to §211 — AN IN-LOOP ACCUMULATOR WANTS A CLOSED-FORM EXPRESSION WHEN THE TARGET REMATERIALISES ITS CONSTANT AFTER EVERY CALL L26336 -- **§275** — THE LEFTOVER-REGISTER READ L26371 -- **§276** — MIXED ADDRESS-EXPRESSION SPELLING FOR ADJACENT RELOCATABLE SYMBOLS IS A CSE-UNIFICATION DIAL, NOT JUST A BYTE-ENCODING CHOICE (P31 S60; `func_80180FE8`, ov_SC06_006, byte-proven) L26411 -- **§277** — RETURN-TAIL C SPELLING PICKS THE DELAY-SLOT-FILL vs TRAILING-MOVE TOPOLOGY, AND A NARROWER SECOND VARIABLE KEEPS TWO PSEUDOS INSTEAD OF ONE (P31 S60; `func_801846F0` ov_SC03_104, `func_801A44C4` md_SC07_004, both byte-proven) L26520 -- **§278** — ADDENDA HARVESTED FROM WAVE cf (P31 S60): 34 candidates, 13 already covered, 8 sharpenings, 4 new laws L26584 -- **ADDENDUM** — to §74 (func_800D0E30, resident) L26592 -- **ADDENDUM** — to §172b-4 (func_80185054, ov_SC03_097) L26628 -- **ADDENDUM** — to §265 (func_8017DC80, ov_SC07_002) L26666 -- **ADDENDUM** — to §17 (func_800CB794, md_MAIN_036) L26705 -- **ADDENDUM** — to §162p (func_8017C120, ov_MAIN_012) L26753 -- **ADDENDUM** — to §20 (~L1947) (func_80186AD0, ov_SC06_032) L26787 -- **ADDENDUM** — to §164-56 (func_8017F644, ov_SC04_005) L26817 -- **ADDENDUM** — to §237 (func_8017F7FC, ov_SC03_092) L26852 -- **§279** — A `do/while (p < end)` LOOP UNDER AN ENTRY GUARD: the guard decides the compare, not the loop (P31 S60; wave cf, func_8017F2A4, ov_SC03_096, byte-proven) L26881 -- **§NNN** — A DO-WHILE'S GUARD AND LATCH MUST REPEAT THE SAME BOUND EXPRESSION, NOT SHARE ONE LOCAL: THE REPETITION IS WHAT BUYS THE CSE'D COPY INTO A SECOND REGISTER (P31 S60; `func_8017F2A4`, ov_SC03_096, byte-proven 25/25) L26882 -- **§280** — THE CURSOR'S DECLARED TYPE PICKS `sltu` vs `slt`: a `T*` bound test is UNSIGNED by C rule, an integer cursor is signed (P31 S60; wave cf, func_800CAE74, md_MAIN_031, byte-proven) L26915 -- **§NNN** — A LOOP CURSOR'S C TYPE (POINTER vs PLAIN INTEGER) SELECTS `sltu` vs `slt` FOR ITS BOUND TEST, INDEPENDENT OF THE VALUES INVOLVED (P31 S60; `func_800CAE74`, md_MAIN_031, byte-proven; cross-confirmed same wave by `func_8017F2A4`, ov_SC03_096) L26916 -- **§281** — GROUP COPY-THEN-RMW BY OPERATION KIND, NOT FIELD BY FIELD: sched1 does the interleaving, the source must not (P31 S60; wave cf, func_80180FB4, ov_SC03_111, byte-proven) L26949 -- **§NNN** — A DEPENDENT COPY-THEN-RMW BLOCK MUST BE SOURCE-GROUPED BY OPERATION KIND, NOT BY FIELD, AND SCHED1 DOES THE INTERLEAVING (P31 S60; `func_80180FB4`, ov_SC03_111, byte-proven) L26950 -- **§282** — gcc's OWN LOOP REVERSAL PUTS THE COUNTER INIT AFTER THE HOISTED MOVABLES — a position no hand-written down-count can reach (P31 S60; wave cf, func_80180DD8, ov_SC04_005, byte-proven) L26995 -- **§NNN** — WRITE THE UP-COUNT LOOP: gcc's OWN REVERSAL PRODUCES A COUNTER-INIT INSTRUCTION THAT LANDS AFTER HOISTED MOVABLES, WHICH A HAND-WRITTEN DOWN-COUNT LOOP CANNOT REPRODUCE (P31 S60; `func_80180DD8`, ov_SC04_005, byte-proven) L26996 -- **What** — I could not verify L27033 -- **§283** — ADDENDA HARVESTED FROM THE 36-WAVE BATCH (P31 S60): 1,216 candidates, 859 already covered, 46 sharpenings, 9 new laws L27080 -- **ADDENDUM** — to §164-75 — the fold-reassociation law also fires at a variable's INITIALIZER, not only a later expression L27090 -- **ADDENDUM** — to §21 — the `bltz`+`slti` (or N-separate-compares) signed-range-split bullet is now CONFIRMED on three independent functions, and generalizes beyond `lbu`/u8 L27116 -- **ADDENDUM** — to §202 — the DEF-SIDE ALIAS also resolves a function-vs-DATA-symbol identifier clash, not only a function-vs-function prototype clash L27162 -- **ADDENDUM** — to §22 (`volatile`-qualified-global reload lever, cookbook ~L1922) — for a NON-constant, same-address double RMW, a plain memory clobber beats `volatile`, and `volatile` actively breaks a delay-slot fill L27185 -- **ADDENDUM** — to §195-E — a goto-ladder's STORES must sit AT the labels, after the gotos, not inline before them L27204 -- **ADDENDUM** — to §195-N — a GNU statement-expression slider must sit INSIDE the conditional arm's value position, not as a post-hoc barrier, to block the store-flag transform on a ternary chain L27266 -- **ADDENDUM** — to §176-B2 — in a micro-function with no long/short lifetime asymmetry, BOTH contending pseudos need their own hard-register pin L27323 -- **ADDENDUM** — to §199-G — A `default:` LABEL GROUPED ONTO THE LAST CASE REMOVES THE `j default` TAIL, EVEN THOUGH THE 2-NODE HEADER STAYS ALL-POSITIVE L27370 -- **ADDENDUM** — to §220 — REFERENCING THE RAW PARAMETER (NO NAMED COPY, NOT EVEN A PIN) LETS THE CALLEE-SAVED SPILL LAND IN THE FIRST CALL'S OWN DELAY SLOT L27439 -- **ADDENDUM** — to §252 — a `>=0`/`<0` split on an unconditionally-decremented value needs the POSTFIX operator INSIDE the branch condition, not a prior statement L27497 -- **ADDENDUM** — to §215 — FIFTH SHAPE: reused mask constants across two call-free merge sites each get their own whole-function hard-register pin, and a shared sub-expression at the second site must be its own statement L27524 -- **What** — I could not verify L27607 -- **Harness-defect** — flags L27678 -- **ADDENDUM** — to §167-40 (func_8017E2CC, ov_SC04_015 — wave dg) L27771 -- **ADDENDUM** — to §20's cross-jump EXPLOIT bullet (func_8017E360, ov_SC05_007 — wave dg) L27791 -- **ADDENDUM** — to §87 (func_801815F4 ov_SC06_032; corroborating func_801840DC ov_SC05_017, func_80189C68 ov_SC03_006 — wave dg) L27805 -- **ADDENDUM** — to §153 / §236-5 (func_801A419C, md_SC07_003 — waves di and dl, corroborating; refutes a contradicted dj-wave card) L27824 -- **ADDENDUM** — to §263 (func_801E83AC, md_SC04_029 — wave dj) L27844 -- **ADDENDUM** — to §265 (func_8017D878, ov_SC03_107 — wave dj; corroborated by a REJECTED, contradicted card in wave dm — see closing) L27858 -- **ADDENDUM** — to §6 (func_801811F0, ov_SC03_102 — waves dj and dl, corroborated by a self-reported "nothing new" dm-wave card) L27872 -- **ADDENDUM** — to §195-G (func_80183BB0, ov_SC05_001 — wave dj) L27886 -- **ADDENDUM** — to the zero-byte-asm-slider family (§47 / §148-C / §153) (func_800CB874, md_MAIN_040 — wave dj; open tension with a more cautious dm-wave card — see closing) L27914 -- **ADDENDUM** — to §194-B (func_8017EB34, ov_SC03_117 — wave dk; distinct from the §74 co-pinning finding on the SAME function below) L27932 -- **ADDENDUM** — to §74 (func_8017EB34, ov_SC03_117 — counter/clamp variant; wave dj, corroborated by dk/dl/dm cards on the same function) L27964 -- **ADDENDUM** — §37 — merged into the §153/§236-5 entry above (func_801A419C, wave dl) L27984 -- **ADDENDUM** — §6 — merged into the §6 entry above (func_801811F0, wave dl) L27992 -- **ADDENDUM** — to §238 (func_80182CB4, ov_SC02_000 — wave dl) L28000 -- **ADDENDUM** — to §137a (func_801684B4, ov_MAIN_012; corroborated independently by func_80189E68, func_8017FF9C, func_801822B4, func_8018DA8C — wave dl) L28018 -- **ADDENDUM** — to §8c / §88d (func_8016AB6C, ov_MAIN_012 — wave dm) L28034 -- **ADDENDUM** — to §73 / §30#2 (func_800D1984, resident — wave dm) L28048 -- **What** — I could not verify L28064 -- **ADDENDUM** — to §174 Law 4 (func_8017E9A8, ov_SC06_015) L28084 -- **ADDENDUM** — the zero-emission-asm family gains a REF-SLIDER PLACEMENT LAW and a paired RESTORER (func_800CB900, md_MAIN_026) L28124 -- **From** — ck + cl + cm L28176 -- **ADDENDUM** — §NNN — sharpens §55a / §164-37 / §165-28 (switch-vs-tree cluster): A SHAPE THAT LOOKS LIKE A SWITCH DISPATCH CAN BE PLAIN NESTED `if`s WHOSE SHARED BODY WAS TRIPLICATED BY THE SOURCE AND THEN CROSS-JUMP-MERGED BACK DOWN L28182 -- **ADDENDUM** — §NNN — sharpens §167-13's boundary: CHAINING TWO IDENTICAL SIDE-BY-SIDE STORES INTO ONE C ASSIGNMENT STATEMENT IS A MID-BLOCK SCHEDULING-PRIORITY DIAL, NOT ONLY A STORE-ORDER SPELLING L28219 -- **ADDENDUM** — §NNN — sharpens §162a3/§60b: A `sll $v0,16 / sltiu $v0,1` ZERO-TEST OF A JUST-DECREMENTED HALFWORD IS A SIGNED-TEMP WIDTH TELL OUTSIDE ANY SWITCH/RANGE-TEST CONTEXT L28252 -- **ADDENDUM** — §NNN — sharpens §37/§124 (unspecified-parameter-list family): DERIVE A CALLEE'S ARITY LOWER BOUND FROM ITS OWN `.s` STACK-ARGUMENT READS, NOT FROM ANY SINGLE CALL SITE L28285 -- **ADDENDUM** — to §5a (func_80181F74, ov_SC03_112, wave cn) L28318 -- **ADDENDUM** — to §265 (func_8017E26C, ov_SC04_016, wave cn) L28368 -- **ADDENDUM** — to §42b (func_8018247C, ov_SC07_002, waves cu + cw) L28406 -- **ADDENDUM** — to §199-F family (func_8017EFB0, ov_SC02_021, wave cu) L28437 -- **ADDENDUM** — to §195-E (func_800CFC1C, md_MAIN_003, wave cv) L28492 -- **ADDENDUM** — to §215 addendum (func_800CB2C8, md_MAIN_033, waves cv + cw) L28537 -- **ADDENDUM** — to §236 item 4 (func_8017D268, ov_SC04_006, wave cw) L28593 -- **What** — I could not verify L28622 -- **Harness-defect** — flags (not idioms — flagged for the operator) L28654 -- **ADDENDUM** — to §250 (func_8017D7CC, ov_SC03_115 — cx/cy/cz/dr) L28695 -- **ADDENDUM** — to §225 (func_8017E190, ov_SC03_115 — cx/cy/cz) L28740 -- **ADDENDUM** — to §45-A (func_8017F6A4, ov_SC02_016 — cy/cz) L28793 -- **ADDENDUM** — to §249 (func_80182ED4, ov_SC04_004 — dp/dr/dt) L28837 -- **ADDENDUM** — to §199-A (func_801816FC, ov_SC02_005 — dp/dr/dt) L28882 -- **What** — I could not verify L28928 -- **Harness-defect** — flags L28971 -- **§284** — COMBINE CAN REASSOCIATE TWO SEQUENTIAL BITWISE-AND MASKS INTO ONE AGAINST THE PRE-MASK VALUE; AN ASM IN/OUT FENCE RIGHT AFTER THE FIRST MASK BLOCKS IT (P31, wave dd, `func_8018087C`, ov_SC04_020, byte-proven) (P31 S60; waves #, byte-proven) L29033 -- **§285** — PRE-INITIALIZING A VARIABLE WITH A SHARED CONSTANT BEFORE A BRANCH MAKES BOTH ARMS OF THE FOLLOWING if/else DESTRUCTIVELY REUSE THE SAME DESTINATION REGISTER FOR THEIR BITWISE RESULT (byte-proven; `func_801811F0`, ov_SC03_102, independently rediscovered across waves di/dj) (P31 S60; waves #, byte-proven) L29037 -- **§286** — FOLD A STATEMENT'S SIDE EFFECT INTO A COMMA-EXPRESSION IN AN ARGUMENT POSITION TO PLACE ITS RTL RELATIVE TO A CALL'S OWN DELAY SLOT (P31 S60/dj; `func_80180A88`, ov_SC06_010, byte-proven 411/411) (P31 S60; waves #, byte-proven) L29041 -- **§287** — A STACK-FRAME HOLE BELOW TWO ADDRESS-TAKEN AGGREGATE LOCALS IS A LEADING PAD MEMBER OF ONE COMBINED STRUCT, NOT SEPARATE LOCALS OR A REGISTER PIN (P31 S60/dj; `func_8017D104`, ov_SC06_027, byte-proven 47/47) (P31 S60; waves #, byte-proven) L29045 -- **§288** — A REGISTER PIN DECLARED UNINITIALIZED AND ASSIGNED ONLY AT ITS LATE, SOLE USE STILL FORCES THE FIXED REGISTER'S SAVE/RESTORE, AND THE ASSIGNMENT'S SOURCE POSITION CONTROLS WHERE THE VALUE MATERIALIZES (P31; `func_80186530`, ov_SC02_017, byte-proven, match_one MATCH re-verified) (P31 S60; waves #, byte-proven) L29049 -- **§289** — an array local's address-taken base keeps every element's store alive, even though only one pointer escapes (`func_80189EFC`, ov_SC04_011) (P31 S60; waves #, byte-proven) L29053 -- **§290** — A SINGLE STRENGTH-REDUCED GIV CAN DRIVE STORES TO SEVERAL DISTINCT RELOCATABLE SYMBOLS, EACH KEEPING ITS OWN `%hi`/`%lo` ANCHOR (P31 S60; waves #, byte-proven) L29057 -- **§291** — THE DELAY-SLOT FALSE-VALUE: A CONDITIONAL BRANCH'S ZERO ARM MUST BE A FALL-THROUGH-ADJACENT BLOCK ENDING IN AN EXPLICIT JUMP, OR REORG CANNOT MATERIALIZE IT INSIDE THE BRANCH'S OWN DELAY SLOT (P31 S60; waves #, byte-proven) L29061 -- **§292** — DECLARING A SYMBOL UPSTREAM OF AN ALREADY-BANKED SIBLING THAT RELIES ON THAT SYMBOL'S IMPLICIT (K&R) DECLARATION CAN SILENTLY REPROTOTYPE THE SIBLING'S OWN CALL SITE (P31 S60; waves #, byte-proven) L29065 -- **§293** — THE "WHOLE-OBJECT GATE NEEDS EVERY SIBLING" LAW, WRITTEN PROPERLY: IT IS THREE LAWS, AND THE LOAD-BEARING ONE IS "THE BASELINE, NOT THE SIBLINGS" (P31 S61; byte-proven on 15 binaries in one night) L29068 -- **§294** — ADDENDA HARVESTED FROM THE S61 GEN0/MAXTOK/MAIN/DEEPSEEK BATCH (waves ab8/ab16/ab24/ab32 · g0a–g0f · m0a · ds1/ds2): 99 candidates, 52 covered, 15 notes → 10 addenda, 29 notes → 5 new laws (§295–§299), 3 refuted L29118 -- **ADDENDUM** — to §127 — the -O0 constant-offset fold keys on the MEMBER-ACCESS tree shape, not on the index being constant L29129 -- **ADDENDUM** — to §261a — FOUR MORE -O0 DIALS BEYOND THE RELOAD COUNT (boot.c + md_MAIN_011/003, wave m0a/g0a/g0f, byte-proven) L29157 -- **ADDENDUM** — to §264-3 — the explicit entry copy's BOUND: required exactly when the RAW value must outlive the call that consumes only the PROMOTED value L29207 -- **ADDENDUM** — to §172b-1 (counter-type dial) — the sll's SOURCE REGISTER is the placement discriminator L29227 -- **ADDENDUM** — to §276 — the SHARE direction: spell the second adjacent symbol RELATIVE to force ONE anchor L29239 -- **ADDENDUM** — to §31's density-dummy dial (L2460/L2497) — the dose is TWO refs, and the dummy must sit where the loser is live-through L29255 -- **ADDENDUM** — to §282 — the ADDRESS-GIV face: write the walked address INLINE so strength reduction births the induction register at loop.c's own insertion point L29272 -- **ADDENDUM** — to §253 — SECOND byte-proven card (upgrade from single-observation), and the placement face: postfix-in-condition parks the RMW store in the branch delay slot L29295 -- **ADDENDUM** — to the L1800 anchor-steer bullet — a DERIVED-POINTER local silently flips the merged giv's anchor END L29316 -- **ADDENDUM** — to §31's asm→layout inference — TWO WIDTH-PAIR DISCRIMINATORS (same offset, different widths) L29339 -- **§295** — THE KERNEL-TRAP STUB: §81's jr-DETECTOR WITHOUT A TABLE IS A PsyQ SYSCALL TRAMPOLINE — ROUTE TO §265, NEVER INTO THE CARVE CHAIN (P31 S61; wave m0a, 9 cards byte-proven; resolves §182's held cluster) L29360 -- **§296** — THE FRAME CHECK OUTRANKS THE ATLAS LEVER: READ PROLOGUE/EPILOGUE BEFORE DRAFTING ANY C — A REAL TELL CAN LIVE INSIDE AN UNREACHABLE FRAGMENT (P31 S61; wave m0a, 16 cards byte-proven; extends §179-C) L29415 -- **§297** — ONE GIV SERVING MIXED-WIDTH LOADS *AND* A STORE NEEDS STRUCT-MEMBER SPELLING; CAST/INDEX SPELLINGS RE-SPLIT THE PSEUDO (P31 S61; wave m0a, `func_800347C8`, main, byte-proven 31/31) L29458 -- **§298** — THE SHARED-TAIL POSITION DIAGNOSTIC: A FOLDED TAIL *BETWEEN* SWITCH ARMS MEANS PER-ARM DUPLICATED STATEMENTS, NOT A HOISTED POST-SWITCH STATEMENT (P31 S61; waves g0e/g0f, `func_80181B68`, ov_SC06_016, byte-proven 68/68) L29501 -- **§299** — TWO INDEPENDENT EXTRACTION CHAINS EMIT CONTIGUOUSLY INSIDE ONE EXPRESSION; ONLY A STATEMENT BOUNDARY MAKES THE SCHEDULER INTERLEAVE THEM (P31 S61; wave m0a, `func_8003A404`, main, byte-proven 8/8) L29526 -- **§300** — S61 DISTILL BATCH NOTES (waves ab8/ab16/ab24/ab32 · g0a–g0f · m0a · ds1/ds2 · m0b) L29561 -- **§301** — AN INTERNAL `j` CARRIES `R_MIPS_26 .text`: rtu/match_one "MATCH" COULD NOT SEE WHICH LABEL A `j` TAKES — FIXED (`jrel`), AND THE TWO DRAFT SHAPES IT HID (P31 S62 T1; byte-proven 2/2, negative-controlled over 3,297 stubs) L29630 -- **§302** — A RED BINARY IS A DRIFTED SPEC, NOT A MYSTERY: THE THREE CARVE-STATE INVARIANTS AND HOW TO DERIVE EACH FROM THE BYTES (P31 S62 T2; five reds healed in one session, 5/5, +39 held banks) L29678 -- **§303** — MODULE ISLAND TABLES: DERIVE THE PADS AT BUILD TIME, PEEL NOTHING — THE §154-A/§260 "island-pads"/"island-blocked" WALLS DISSOLVE (P31 S62 T3a; byte-proven md_SC03_076 func_801F0A9C + func_801F0F28, sha 9a165e36…) L29722 -- **§304** — SELF-DEFINING RODATA: WHEN A FUNCTION'S `.s` IS THE ONLY OWNER OF THE DATA IT REFERENCES, THE C BODY MUST DEFINE IT (P31 S62 T3; byte-proven md_MAIN_011/func_800D04F4) L29758 -- **§305** — "CARVE-REFUSED" AT GATE TIME IS THREE NAMED, DETERMINISTIC CLASSES — NONE OF THEM A CARVE (P31 S62 T3; 28 resolver drafts autopsied 28/28) L29781 -- **§306** — A HAZARD `nop` IN FRONT OF A DIV-RESULT STORE IS A STATEMENT-ORDER DEFECT: THE INDEPENDENT TRAILING STATEMENT MUST BE WRITTEN *BEFORE* THE DIVISION-CONSUMING ONE (P31 S62 T4; byte-proven func_8017E7D0) L29833 -- **§306a** — T4 DISTILL ADDENDA (P31 S62; four byte-proven refinements to existing laws, verified against the book by an independent verifier; each names its parent §) L29860 -- **§307** — THE BRUTE-FORCE-THE-STATEMENT-ORDERS LEVER HAS A BOUND: A FAN-OUT COPY'S PRIORITY IS SCHEDULER-INTERNAL, AND NO SOURCE ORDER REACHES IT (P31 S63; byte-evidenced NEGATIVE result, main wave) L29898 -- **§308** — A NAIVE FINAL `goto` DELETES THE TARGET'S `j`+`nop`: SPELL THAT EDGE AS A TAUTOLOGICAL `if` SO cse FOLDS IT TO AN UNCONDITIONAL JUMP *AFTER* jump1's WINDOW HAS CLOSED (P31 S63 t5e-t5i; byte-proven func_80180808) L29942 -- **§308a** — A TWO-INSTRUCTION ARM STUB LAID *BEFORE* THE OTHER ARM AND REACHED ONLY BY A TRAILING `j` SURVIVES ONLY BEHIND A SHORT-CIRCUIT `&&` GUARD PLUS A SEPARATE RE-TEST; EVERY PLAIN if/else-if, GOTO-LADDER, NESTED-INVERTED-if AND 1-/2-NODE switch LETS jump1 INLINE IT (−2 ins) (P31 S63 t5e-t5i; byte-proven func_80180808) L29971 -- **§309** — A FRAME-ADDRESS EQUIVALENCE RIDES *THROUGH* A SKIPPABLE CONDITIONAL: POST-`if` STORES FOLD ONTO `$sp` UNLESS THE `if` SURVIVES jump1 AS A BARRIER-PRECEDED DIAMOND (P31 S63 t5e-t5i; byte-proven func_801812AC) L30005 -- **§310** — A TWO-OPERAND `subu`'s DESTINATION TIES ONLY TO THE OPERAND THAT IS BLOCK-LOCAL: SHARE *ONE* SIDE ACROSS BLOCKS TO CHOOSE WHICH OPERAND'S REGISTER IT LANDS IN (P31 S64 t5j-t5m; byte-proven func_8017F578) L30045 -- **§311** — A JOIN-BLOCK STORE CAN SWALLOW AN ARM'S LOAD-DELAY `nop`: WHEN ONE ARM'S VALUE COMES FROM A LOAD, DUPLICATE THE STORE INTO BOTH ARMS (P31 S64 t5j-t5m; byte-proven func_8017D7E0) L30076 +- **§41a** — v3.1: the def-side wall was ~71% TOOL-shaped — the five measured defects + the laws that dissolve them (Phase 25 T6, Fable5, 2026-07-09) L2769 +- **§41b** — T7 execution: the object-only probe OVER-counts BANKABLE by two link/rodata classes (Phase 25 T7-M1, 2026-07-10) L2824 +- **§41c** — T7-M2: the ×134 def-side-wall sweep via per-sibling RE-reconcile (Phase 25, 2026-07-10; 4,389 banks, ~0 agent tokens) L2854 +- **§41b** — addendum — M4 "reconcile_decls" tier is ALSO a probe over-count: 0/8 mechanical (Phase 25 T7-M4, 2026-07-10) L2873 +- **§41d** — `void`→`s32` is NOT always byte-neutral: gate the RAW draft FIRST (Phase 26 session 6, byte-proven) L2893 +- **§42** — The F-band ≤28 regalloc crack wave: register-pin/DENSITY levers beat the permuter (Phase 25 T7 F-band, 2026-07-10; Ultracode 9-worker wave, 4/9 banked byte-identical, 266 swept ×134) L2915 +- **§42a** — addendum — wave 2 (residuals + 29-100 band): iso-MATCH ≠ real-TU bank, the memcpy→struct-assign fix, +5 levers (2026-07-10b) L2968 +- **§42b** — addendum — wave 3 (Max, 2026-07-10c): THE STALE-OBJECT GATE TRAP + the read-global `&`-cast drift + fix L3009 +- **§42c** — addendum — wave 3 (Max orchestrator + CORRECTED Ultracode fan-out, 2026-07-10c): the real-TU-faithful parallel harness (rtu_match) + 7/9 crack, ZERO iso-drift L3048 +- **§42d** — addendum — wave 4 (rtu_match fan-out over the mapped frontier, 2026-07-10c): 24/26 MATCH, +5 durable levers L3097 +- **§42e** — propagating a CRACK ×134: the def-finder bug + the byte-drift residual (the "remap-fail" misdiagnosis) L3136 +- **§43** — The K&R s16-param definition DISSOLVES the "narrow-param wall" for by-value register args (Phase 25 task A, Fable5 crack of the 369-ins giant `func_80166994` ×134, 2026-07-11) L3210 +- **§44** — The Phase-25 cheap-Opus giant batch: 5 structural levers + the §43 extension (2026-07-11, 6 crackers over the frontier giants) L3257 +- **§45** — The flagship `func_80133CD4` crack (399 ins ×134): the merged-variable permutation-breaker + the 1-death local-alloc gate (Phase 25 task A giant escalation, Fable5 gdb-on-cc1, 2026-07-11) L3313 +- **§46** — The `func_80178D40` crack (890 ins ×134, the heaviest core in the game): four LOOP-STRUCTURE levers cheap-Opus found by reading loop.c/jump.c/cse.c (Phase 26 session 8, 2026-07-13) L3328 +- **§47** — The live-length SLIDER: splitting a global.c allocno-priority TIE with one zero-byte asm (Phase 26 session 8, Fable5 Max, byte-proven on `func_8017BEBC` 952 ins ×113) L3380 +- **§48** — The 12-core jr crack wave: the ALLOCNO-PRICING dials and the EBB rule (Phase 26 session 8, Ultracode, 9/12 MATCH first pass) L3420 +- **§3-A.** — ALLOCNO-PRICING DIALS — move a value into the register you want, byte-neutrally L3428 +- **§3-A4** — SINK THE CONSUMER CALL INTO THE ARMS (the inverse of A1; `func_8016AB6C`, byte-proven) L3459 +- **§3-B.** — THE EBB RULE — the general form of §46-L2 L3483 +- **§3-C.** — TYPE- AND SHAPE-DRIVEN CODEGEN (the C type literally selects the addressing mode) L3499 +- **§3-D.** — THE CROSS-JUMP RATCHET (the sharpest new trap — `func_80131340` L-C) L3523 +- **§3-E.** — Meta L3533 +- **§49** — The LUID DIAL: a zero-byte SCHEDULING dial (the sched.c analogue of §47) — `func_8017A4AC` (536 ins ×134), Phase 26 session 8 L3542 +- **§50** — Refinements that BOUND §47/§48 (from the `func_80135EB0` wall, 21→6; Phase 26 session 8) L3591 +- **§51** — TOOLING INTEGRITY: the silent skip, and how to hunt it L3645 +- **§51a** — The bug class L3651 +- **§51b** — Why the byte-gate cannot save you L3667 +- **§51c** — THE METHOD (do not audit by reading the regex) L3677 +- **§51d** — THE LAWS L3692 +- **§51e** — The false-wall pipeline (why this is not just hygiene) L3754 +- **§51f** — Checklist for any new corpus-scanning tool L3770 +- **§51g** — When the thing you are scanning has a GRAMMAR, parse the grammar (`tools/cdecl.py`) L3784 +- **§52** — The WALKER-FAMILY skeleton: 6 regalloc-order levers + a deeply-characterized intrinsic wall (`func_80178004`, 165 ins ×134; Phase 26, Fable5, 2026-07-15) L3928 +- **§3-The** — 6 levers (the "walker-family skeleton" — apply to the 12 siblings; levers 1-5 retire ~half the residual) L3939 +- **§3-Why** — the wall is (probably) intrinsic L3960 +- **§52a** — The regalloc sibling wave: new levers + two new wall classes (cheap-Opus applying §52, 2026-07-15) L3974 +- **§52b** — Sibling wave 2: more de-pin levers, a third wall class, and the match_one→whole-binary gap at scale (2026-07-15) L4012 +- **§53** — SWEEP A FAMILY WITH THE TOOL ITS EXEMPLAR NEEDED: the jr/switch carve, and how omitting it manufactured the "families don't template" doctrine (Phase 28 T1, 2026-07-15) L4043 +- **§3-The** — case L4048 +- **§3-Why** — 0/8 was structural, and predictable from two words L4060 +- **§3-The** — rule L4077 +- **§3-The** — meta-lesson (R35, and why this one is expensive) L4093 +- **§55** — Core-crack wave levers + the GATE-ORCHESTRATION law (Phase 29 T3, 13-agent ultracode wave, 2026-07-17) L4108 +- **§55a** — New byte-proven levers (each from a banked or near draft) L4113 +- **§55b** — THE GATE-ORCHESTRATION LAW (3 traps, ~3.5h lost; all recovered, 0 data lost) L4137 +- **§55c** — Sizing the propagate: a TARGETED propagate is ~4 min/core, and "it's slow" was a BROKEN-TREE ARTIFACT L4156 +- **§54** — `--fix-def-sig`: the member's CANONICAL DECLARATION is a build step too (tiny-IMM mega-pools, +4,801, Phase 29 T6, 2026-07-16) L4178 +- **§56** — Banking a hand-drafted GIANT into its exemplar TU: self-contained draft vs live-TU decls, 4 reconciliation tactics (`func_8013FAF8`, 312 ins ×138, Phase 29 T4, 2026-07-17) L4202 +- **§56b** — PROPAGATING an h_seq giant: the exemplar's externs MUST be fleet-canonical, not the draft's types L4247 +- **§57** — The SELF-decl normalize: the sibling's OWN caller declares the templated fn divergently (the third §17a-1 direction; `tools/normalize_self_decls.py`, func_801670E4 ×137, Phase 29, 2026-07-18) L4271 +- **§57a** — Two NSD corrections + the SURGICAL-ONLY law + the honest broad-sweep yield (Phase 29, 2026-07-18) L4318 +- **§58** — match_one MATCH ≠ BANK: the four blind spots + the crack-wave reconcile-before-bank law (Phase 29 crack-wave, 2026-07-18) L4358 +- **§59** — Three h_seq sweep-residual classes match_one/the-exemplar-bank don't reveal (Phase 29 crack-wave close, 2026-07-18) L4392 +- **§60** — Classify the residual, don't rank it: the deterministic residual→class classifier and what it measured about the backlog (Phase 29 Task-13A, 2026-07-21) L4422 +- **What** — it measured — the whole open backlog, byte-grounded L4446 +- **§3-Two** — corollaries worth remembering L4465 +- **§3-The** — parallel-probe race this surfaced L4478 +- **§60a** — What the first DIRECTED grinder run exposed (Phase 29 Task-13B, 2026-07-21) L4487 +- **§60b** — The plateau autopsy's verdict: a `partial` drift is a WRONG DRAFT, not a missing transform (Phase 29 Task-13B close, 2026-07-21) L4525 +- **§61** — Task 14: the gate ladder's missing stage is the ARITY pre-pass, and it is TU-side not draft-side (Phase 29, 2026-07-21) L4560 +- **§61a** — The Task-5 wave: 11/12 MATCH, 0 banked — three DISTINCT integration walls, each now named (Phase 29, 2026-07-21) L4621 +- **§61b** — The jtbl gate stage: built, and the ORDERING law it exposed (Phase 29 Task-14 stage 4, 2026-07-21) L4673 +- **§61c** — The jtbl bank is INCREMENTALLY valid and CLEAN-INVALID (Phase 29, 2026-07-21) — the blocking finding L4728 +- **§61d** — The undo was eating the tree: two tools, one defect, invisible to the byte-gate (Phase 29, 2026-07-22) L4794 +- **§62** — The jtbl RECONCILE must also follow the carve: the post-carve draft reconcile (`harvest_verify._jtbl_reconcile`, Phase 29 SESSION-11, 2026-07-22) L4848 +- **§63** — The fresh-138 DEF-SIDE blocker: fix the HEADER decl, not the draft (`fix_header_decl.py`, Phase 29 SESSION-13, 2026-07-23) L4892 +- **§64** — The §20 type-lift's three laws: fold the tagged typedef, check VISIBILITY, and strip only what is TEXTUALLY IDENTICAL (`lift_types.py`, Phase 29 SESSION-14, 2026-07-23) L4923 +- **§64a** — VARIANT types: UNIQUIFY the camps, do not reconcile them (`uniquify_type.py`, Phase 29 SESSION-14) L4972 +- **§63** — UPDATE (Phase 29 SESSION-14) — `fix_header_decl`'s "SAFE" verdict is FLEET-BLIND; it MUST be R22-validated L5015 +- **§65** — The stranded-draft recovery: BLAST-RADIUS TIERS, and the per-overlay de-macroize that refutes §20's DEF-conflict wall (`tools/demacroize.py` + `tools/blocker_probe.py`, Phase 29 SESSION-16, 2026-07-24) L5030 +- **§65a** — The blast-radius taxonomy (makes §61's law structural instead of remembered) L5045 +- **§65b** — The escape: de-macroize the instantiation, don't touch the shared header L5060 +- **§65c** — `rtu_match` MATCH → bank held 13/13 on self-decl, but broke on the FIRST callee-decl case L5096 +- **§65d** — Existing-ladder baseline, measured (do this before building a recovery stage) L5106 +- **§65e** — Two oracles, and the disagreement is the finding (R34 in practice) L5116 +- **§65f** — The de-macroize lever's BOUNDARY, measured: byte-neutral 14 times of 15, and the 15th is why the gate exists L5133 +- **§65g** — Where the cheap levers STOP: the local-type and in-TU-self-decl classes did not yield L5154 +- **§66** — Exercise a banking driver's SUCCESS path before pointing it at a wave: the free re-bank test (Phase 29 SESSION-17, 2026-07-24) L5174 +- **§66a** — The widest write in a pipeline is the one most likely to be UNDECLARED L5196 +- **§66b** — A metric parsed out of another tool's prose goes NULL silently when the label changes L5215 +- **§66c** — Before a wave, verify the FUEL exists; an "already attempted" set built from the wrong directory lies in BOTH directions L5232 +- **§66d** — The permuter⇄reader loop: alternate a random search with a byte-verified idiom, and let `residual_class` decide whose turn it is (Phase 29 SESSION-17) L5260 +- **§66d-1** — What transfers between giants is the LOOP, not the PIN L5295 +- **§66d-2** — Two operational sharp edges L5304 +- **§66d-3** — Read the ILS per-cycle SERIES, not its final best: a repeated score and a still-falling one look identical in a summary line and mean opposite things L5315 +- **§67** — The arg-copy PLACEMENT lever: launder a parameter into a fresh pseudo AT the statement where the target's copy lands (Phase 29 SESSION-18, `func_8014D820` 25 → 16) L5330 +- **§67a** — Run the symbol-set guard BEFORE you pay for a gate (`tools/symcheck.py`, Phase 29 SESSION-18) L5420 +- **§66d-4** — "ILS converged" means converged FOR THAT WEIGHT PROFILE, not a floor (amends §66d-3; Phase 29 SESSION-18) L5453 +- **§66d-5** — `residual_class`'s "structural ⇒ permuter CPU is waste" is WRONG for schedule permutations (measured, Phase 29 SESSION-18) L5506 +- **§68** — A comment-only line halted the extern scan, and the skip label blamed the type cap (Phase 29 SESSION-18) L5539 +- **§69** — How to attack a behemoth: map it, don't draft it (Phase 29 SESSION-18, `func_80183814`, 5,122 ins) L5584 +- **§70** — The giv-init base register: walk the PARAMETER, not a copy of it (Phase 29 SESSION-18, `func_801777BC`) L5634 +- **§71** — Before mapping a giant, look for an already-matched SIBLING beside it (Phase 29 SESSION-18, `func_8017D960`, 3,338 ins) L5675 +- **§72** — A `register __asm__` pin is a PREFERENCE, not a reservation (Phase 29 SESSION-18, `func_8017F510`) L5741 +- **§3-The** — honest fix was source-level and cheap L5765 +- **§3-Giv** — record order (the §70 family) L5775 +- **What** — is left, and what is byte-recorded as SPENT L5781 +- **§73** — A def-side self-decl conflict has TWO axes: RETURN (fleet widen, T2) and PARAMS (casts at each use, T0). Diagnose which before paying for the expensive one (Phase 29 SESSION-19, `func_8014F3E8` + `func_8014D4C0`) L5798 +- **§74** — Auditing a pinned draft: the §72 hazard is CALLER-SAVED pins spanning a call, and only the disassembly can tell you (Phase 29 SESSION-19, `func_8017D960` b2, 5 pins) L5837 +- **§75** — A propagation cap is usually a MINORITY-SPELLING SOURCE OVERLAY, not a wall: census the carried extern before believing the exclusion message (Phase 29 SESSION-19, `func_8014F3E8` ×4 → ×138) L5881 +- **§75a** — The exclusion classes, enumerated with named causes (Phase 29 SESSION-19, the 134-binary `dedup_extend` sweep) L5940 +- **§75b** — A body's preamble can carry `#define`s, not just `extern`s; extraction lifts only the externs (Phase 29 SESSION-19, `func_80165CA0` ×3 → fleet) L5963 +- **§75c** — Class-B's remedy is the FULL §17a-1 PAIR (decl **and** call-site cast); a decl-only fix moves the error and looks like a new wall (Phase 29 SESSION-19, `func_8012F14C`) L6012 +- **§76** — The allocno CLASS (local vs global) is the dominant regalloc lever, and C reaches it ONLY through declaration scope and variable reuse (Phase 29 SESSION-19, behemoth #3 `func_8017F510` 1,511 ins, 97 → MATCH, pin-free) L6043 +- **§3-The** — mechanism, with citations L6052 +- **§3-The** — attribution primitive (use this before calling anything a scheduling residual) L6072 +- **§3-Two** — diagnosis traps this function proved L6079 +- **Practice** — Practice L6089 +- **§77** — Every extraction tool carries a NARROW hard-coded preamble set; anything outside it silently caps the body's reach. Diff the preamble before you gate. (Phase 29 SESSION-19 — three variants in one session, two different tools) L6099 +- **§3-The** — CANDIDATE gate and the REAL gate need DIFFERENT preambles — keep the difference out of the bank L6139 +- **§78** — A LENGTH drift can be a register grant in disguise; and `fold` never leaves a literal first in an `|` chain (Phase 29 SESSION-19, behemoth #2 `func_8017D960` 3,338 ins, 1806 → 0, pin-free) L6189 +- **§3-The** — drift was an allocation decision, not missing code L6195 +- **§3-The** — economics L6226 +- **§79** — For a 0-callee giant, fingerprint by DATA symbols (§71 cannot fire); and the STACK-SLOT ORDER is a declaration-order oracle (Phase 29 SESSION-19, `func_8017BF14` 4,763 ins, cold start → 45/4763) L6235 +- **§71** — has a blind spot, and this is it L6241 +- **§3-NEW** — LEVER — the frame layout reads back the original declaration order L6255 +- **§76** — confirmed at scale, and a pin nuance L6266 +- **§3-The** — residual, and the honest read L6275 +- **§80** — A do-not-re-buy entry is scoped to its BASE, not to the function; and the pin's hidden cost is an unconditional `qty_phys_sugg` (Phase 29 SESSION-19, `func_8017BF14` 45 → 0) L6285 +- **§3-The** — pin's hidden cost, with the citation L6306 +- **§3-The** — flagged "#1 move" LOST — and why the failure is informative L6317 +- **§78** — 's attribution primitive, run and reproduced L6327 +- **Cold-start** — economics, now complete L6333 +- **§81** — Banking a jr (jump-table) function: the 3-step carve chain, and why `match_one` cannot see the problem (Phase 29 SESSION-19, `func_8017C954`) L6338 +- **§3-The** — defect this exposed: a shared type that is present but invisible L6369 +- **§82** — Two source-shape oracles from behemoth #6: a duplicated `addiu $aN,$sp,K` across a `jal` means the block was INLINED, and scalar-vs-aggregate decides WHEN a stack slot is allocated (Phase 29 SESSION-19, `func_8017C730` 1,061 ins) L6385 +- **§3-1.** — The inlined-helper signature L6390 +- **§3-2.** — Scalar vs aggregate decides *when* the slot is allocated L6404 +- **Also** — reproduced on this function L6416 +- **§3-And** — the banking footnote (§75a class A, one line) L6420 +- **§83** — The parameterised-repeat law, the spill-area trap, and why a per-case edit cannot move a per-case symptom (Phase 29 SESSION-20, `func_80183814` 5,122 ins, cold-ish start → 36 structural / 99.3%) L6427 +- **§83a** — READ THE HEADLINE NUMBER CORRECTLY: a LENGTH drift makes `match_one`'s count meaningless L6434 +- **§83b** — THE LEVER: find the parameterised REPEAT before decoding case-by-case L6442 +- **§83c** — TRAP: a "dead local" in a prior draft may be gcc's OWN spill area L6460 +- **§83d** — CSE's quantity budget is WHOLE-FUNCTION, so a local rewrite cannot fix a local symptom L6467 +- **§83e** — §80 vindicated again, on the same day it was written L6481 +- **§84** — The DERIVED-OFFSET remap bug: a hand-computed literal that encodes the DISTANCE between two per-overlay symbols, and why `match_one` is structurally blind to it (Phase 29 SESSION-20, `func_8013D53C`) L6487 +- **§3-The** — construct L6492 +- **§3-Why** — it survived every candidate gate L6510 +- **§3-THE** — FIX IS MECHANICAL — the tool already holds the answer L6525 +- **Scope** — , measured (do not over-generalise — §80) L6533 +- **§3-Two** — ladder lessons banked with it L6543 +- **§85** — The RETURN-axis fleet widen is ALL-OR-NOTHING: widening the shared header alone guarantees a conflict in the source overlay (Phase 29 SESSION-20, `func_8012CC88` / `func_8014D12C`) L6554 +- **§3-The** — conflict L6559 +- **§3-THE** — FAILURE MODE — widening only `engine_core.h` is worse than not starting L6567 +- **§3-The** — precondition, and how to check it in one grep L6574 +- **§3-Do** — the WHOLE axis in one edit, then R22 once L6582 +- **Reading** — , for the next person L6591 +- **§86** — Pinned-exemplar templatability is a PER-FAMILY property, not a per-member rate; and the §42e pin guard is now over-conservative (Phase 29 SESSION-20) L6604 +- **§3-The** — guard refuses a class that largely works L6606 +- **§3-THE** — LAW: all-or-nothing PER FAMILY L6615 +- **§3-Why** — the two live families differ from the three dead ones — the open question L6642 +- **§87** — `match_one` COMPILES but never LINKS, so an unresolvable data symbol reads as MATCH; and stored drafts go STALE against the tree (Phase 29 SESSION-20) L6648 +- **§3-The** — blindness ladder, now complete — FOUR classes `match_one` cannot see L6664 +- **Consequence** — for the backlog ledger L6674 +- **§3-The** — cheap discriminator, before spending a sweep L6681 +- **§88** — `cross_jump` will not merge a common suffix containing a CALL; and §78 is scoped to ORDERED comparisons only (Phase 29 SESSION-20, the behemoth close-out) L6689 +- **§88a** — repeated CALL-shaped blocks are left UNMERGED; call-free tails are merged for you L6694 +- **§88b** — the `slti` literal-position law (extends §78 to comparisons) L6701 +- **§88d** — BANKING ORDER: run the §81 carve chain BEFORE banking, never after L6716 +- **§88e** — a wrong diagnosis, refuted properly (the model for how to treat an inherited lever) L6723 +- **§88f** — the missing rung: a RELOCATION gate between `match_one` and the binary L6733 +- **§89** — Two throughput rules the project already had written down and was not following (Phase 29 SESSION-20) L6741 +- **§89a** — MEASURE the write set; do not assert its tier (`tools/blast_radius.py`) L6747 +- **§89b** — the parallel gate farm existed; the family path could not reach it (`tools/sweep_parallel.py`) L6760 +- **§3-The** — standing sequence L6773 +- **§90** — Five tool-integrity laws from one session, each of which changed an answer (Phase 29 SESSION-21, 2026-07-27) L6781 +- **§90a** — A comparison tool MUST share its reference oracle's index space, exactly L6787 +- **§90b** — "Byte-neutral" is not "wanted": undo on the SUCCESS path too L6804 +- **§90c** — A library-callable function must FAIL CLOSED on an unconfigured module L6814 +- **§90d** — Do not measure a live wave's drafts (§87 in real time) L6825 +- **§90e** — An agent's CONCLUSION and its EVIDENCE fail independently — re-derive the premise, not the fix L6833 +- **§91** — A structure-TRANSFER is only valid where the structure corresponds: the `--like` role trap (Phase 29 SESSION-21, `func_8012AAAC` ×137) L6857 +- **§3-The** — three-hypothesis trail, because two of them were wrong and the wrongness is instructive L6886 +- **§92** — Conforming a DECLARATION: pointer changes are caller-neutral, scalar-WIDTH changes are not (Phase 29 SESSION-21, `tools/conform_decls.py`) L6906 +- **§93** — `set -o pipefail` attributes a pipeline failure to the LAST stage, not the failing one (Phase 29 SESSION-21, `func_8014D820`) L6937 +- **§94** — A family sweep's `0/N` is a TYPE-CARRY failure until proven otherwise: lift the exemplar's local types, ALL of them, transitively (Phase 29 SESSION-21, `func_8016B6BC` 0/137 → 137/137) L6962 +- **§95** — `reconcile_tu` dropped the SIBLING declarators of a multi-symbol `extern` line (Phase 29 SESSION-21, `func_80176218`) L6998 +- **§96** — The same rewrite, one shape down: `reconcile_tu` matched statements to lines by TEXT, so every COMMENTED declaration was silently skipped (Phase 29 SESSION-22, `func_80176218` banked) L7033 +- **§97** — The gate's own tree hygiene: a refused carve, an unchecked recovery, and a snapshot that captured a dirty tree (Phase 29 SESSION-22) L7081 +- **§98** — `conform_decls` had three defects, and only the third needed R22 to find (Phase 29 SESSION-22, `func_8014CF04`) L7128 +- **§99** — The narrow-param wall is a DEF-side problem with a ZERO-blast-radius fix: convert the definition to K&R (Phase 29 SESSION-22, `func_80175AB8` + `func_80175DA8`) L7182 +- **§3-Two** — `reconcile_tu` bugs found underneath, one introduced while fixing the other L7205 +- **§100** — Prefer the DRAFT-LOCAL fix: a type only one function uses belongs in its BODY, not in a shared header (Phase 29 SESSION-22, `func_80175DA8` 0/137 → 137/137) L7231 +- **§101** — The STALE DEFAULT class: a guard whose cause was removed is a silent skip wearing a safety label (Phase 29 SESSION-22, three instances in one session) L7260 +- **§102** — A PLUMBING verdict can MASK a DIFF; and K&R is not always a codegen change (Phase 29 SESSION-22, `func_8016EC0C`) L7287 +- **§103** — A FILE-scope `extern` in a shared overlay TU is a GLOBAL constraint on every LATER function; move the DECL, not the draft (Phase 29 T48/T51, `func_80135260` — the fleet-wide half) L7322 +- **§104** — Two silent-skip defects in one scan: match on MASKED text, emit from the ORIGINAL (Phase 29 T53, `gather_externs`) L7410 +- **§105** — A gate's revert must survive an EXCEPTION, not just a failure (Phase 29 T53, `jtbl_family_bank`) L7446 +- **§106** — Persist the MEASUREMENT, derive the POLICY: a stored route let a stale file out-vote the live table (Phase 29 T54, `residual_class._ROUTE`) L7485 +- **§107** — A lever wired into ONE gate path is a lever most families cannot reach (Phase 29 T56, `func_80144090` 0/136 → 136/136) L7528 +- **§108** — Diagnosing a family `0/N`: the four causes, and the third opt-in lever (Phase 29 T59) L7566 +- **§109** — Conforming a definition to a shared header: fix the NAMES, then check the RETURN precondition (Phase 29 T60) L7615 +- **§110** — A unit must define exactly ONE function, and "ends in `;`" does not tell you which line defines it (Phase 29 T65) L7655 +- **§111** — The distinct-code metric is not noisy: a family pays it only if its members are byte-VARIANT (Phase 29 T66) L7696 +- **§112** — A macro-scoped declaration only collides where the macro is INSTANTIATED (Phase 29 T67/T69, `audit_header_sigs.py`) L7745 +- **§113** — An ARITY blocker only exists if the macro CALLS the function; an address-taken use has no call site (Phase 29 T72) L7791 +- **§114** — The THIRD decl axis: a CALLEE the draft declares differently from the target TU (Phase 29 T76/T77) L7823 +- **§115** — A `func_XXXXXXXX` predicate rots by design: the same name-form assumption in THREE places (Phase 29 T78) L7865 +- **§116** — Optimization level is a property of the FILE, not the function: read a family 0/N against the member's stub HOME (Phase 29 T79) L7892 +- **§3-The** — fix moves the DEFINITION, not the stub — and here is why the obvious shortcut fails L7910 +- **§117** — Spell the sibling's symbol from the SIBLING's address, not the exemplar's kind (Phase 29 T82) L7941 +- **§3-Why** — it survived so long: a MASKED oracle will MATCH a wrong symbol L7968 +- **§118** — Ordinal (positional) immediate resolution: compare C tokens to the DIFFERING asm uses (Phase 29 T87) L7978 +- **§119** — Two levers on the SAME axis, opposite directions: test the off-diagonal (Phase 29 T89) L8012 +- **§120** — Uniquify draft-defined TYPE names; and check which of N staging sites you actually patched (Phase 29 T93) L8041 +- **§3-Do** — NOT "strip the duplicate typedef" — it breaks the extern that uses it L8052 +- **§3-The** — wiring trap that cost two attempts L8058 +- **§121** — Synthesise externs for macro-DEFINED callees from the macro's own definition head (Phase 29 T95) L8076 +- **§122** — GATE RAW BEFORE TRANSFORMING; the undo belongs to the WRITER, as a per-edit journal (P30 T0a, 2026-07-30) L8099 +- **§123** — PROPAGATE A FAMILY WITH THE TOOL ITS TIER NEEDS: `dedup_propagate` is h_exact-only; its refusals are statements about the TOOL (P30 wave 1, 2026-07-30) L8131 +- **§124** — A "not matched" verdict can mean the definition is there under a DIFFERENT C NAME: the asm-label alias blind spot (P30 SESSION-28, `func_8016191C` ×137) L8168 +- **§124a** — a family sweep's `0 matched-exemplar families` may be a FILTER, not a wall L8213 +- **§125** — Split the CARVE from the BODY before calling a jr residue a wall — and measure it by SHA from a CLEAN tree (P30 SESSION-28; **this section's first draft was WRONG and the method caught it**) L8221 +- **§3-The** — method (keep this) L8228 +- **§3-The** — instrument rules that make its answer trustworthy (this is where I failed) L8238 +- **§3-The** — corrected results (each SHA-verified, from a clean tree, restore re-verified) L8253 +- **§3-Two** — further notes worth keeping L8263 +- **§3-The** — meta-lesson L8272 +- **§126** — The carve-within-a-carve: an ADDRESS RANGE is not an OPTIMIZATION REGION (P30 T2, byte-proven end-to-end) L8279 +- **§3-The** — finding: opt level is per FILE, so the file's contents must be opt-HOMOGENEOUS L8294 +- **§3-The** — instrument trap that hid it (and it is §124's shape again) L8305 +- **§3-The** — mechanics L8314 +- **§126a** — a bare `except: continue` around a coverage-asserting oracle re-creates the silent skip (P30 S28) L8332 +- **§127** — The `-O0` regime: the CONSTANT-OFFSET FOLD, and why `-O0` needs its own idiom set (P30 T3 wave, 15 targets) L8364 +- **§3-The** — idiom they kept re-deriving: the constant-offset fold L8371 +- **§3-The** — rest of the `-O0` regime (write PLAIN C, and mean it) L8382 +- **§127a** — §71 (sibling-first) is the strongest `-O0` lever, and it beats the index L8392 +- **§127b** — the knowledge was in a SOURCE COMMENT, not the cookbook L8401 +- **§128** — A raw NUL in C source makes grep SILENTLY SKIP the file (P30 S28, 137 files) L8408 +- **§128a** — a negative control must corrupt a SCRATCH COPY, never the tracked file L8440 +- **§129** — Post-carve, `rtu_match`/`match_one` COUNT THE JUMP TABLE AS INSTRUCTIONS; and a carve must never be committed without its owner (P30 S28, `func_8013BD74`) L8452 +- **§129a** — the target instruction count is INFLATED after a carve L8456 +- **§129b** — never commit a carve whose owner is still a stub (it strands the carve) L8477 +- **§3-The** — real blocker underneath, for the record L8492 +- **§130** — An INCREMENTAL build can report BYTE-IDENTICAL for a change the CLEAN build cannot even LINK (P30 S28, the jr pair) L8501 +- **§3-The** — diagnostic ladder that finally located it (reusable) L8538 +- **§131** — The jtbl OVER-SPAN: `sltiu N` is ground truth in BOTH directions, and the zero-word rule only guards one (P30 S28, `func_80191C50`) L8548 +- **§132** — The `JR-PAIR-IN-ONE-O0-OBJECT` "wall" was TWO instrument defects: a merged-double span the carve could not see, and a truncated object no rule deleted (P30 S29, `func_8013B83C` + `func_8013BD74`) L8585 +- **Defect** — 1 — a pre-§8e MERGED DOUBLE is not a single-table predecessor L8594 +- **Defect** — 2 — `as` writes a corpse and nothing deletes it L8612 +- **§3-The** — fingerprint, and the 30-second ladder that found it L8622 +- **§3-The** — transferable rule L8643 +- **§132a** — `--like` is for a sibling with NO record; against one that HAS a record it over-derives (P30 S29, `ov_SC07_010`) L8650 +- **§132b** — When the span's already-matched owner is ITSELF multi-switch: `--span-rel` (P30 S1, `func_8014032C`) L8675 +- **§133** — The DEFAULT-FILTER class: three times in one session, a tool silently answered a narrower question than the one asked (P30 S1–S3) L8700 +- **§134** — MULTI-LINE BLINDNESS: one root cause, four faces, in `family_remap`'s preamble scanner (P30 S6, 190 zero-crack families) L8726 +- **§135** — Six byte-verified gcc-2.7.2 idioms from the P30 S6f-h waves (and the two-lane wave shape that found them) L8780 +- **§3-The** — codegen idioms L8785 +- **§3-The** — integration idioms (these decide whether a byte-correct draft BANKS) L8819 +- **§3-The** — wave shape that produced these L8834 +- **§136** — The LOCAL-VARIABLE lever: how many C locals, at what scope (P30 wave 4a, 25 byte-verified banks) L8852 +- **§3-The** — splitting/merging rules (each closed a residual, byte-gated) L8868 +- **§3-The** — type-form rules L8894 +- **§3-The** — scheduling rules (refining §135-2 and §135-4) L8927 +- **§3-The** — declaration surface (integration, not codegen) L8956 +- **Wave** — economics (measured, for the next batch's sizing) L8968 +- **§136a** — Blocker capture: classify on the OUTPUT, never on the exit status L8991 +- **§136b** — A prior wave's "genuine byte-DIFF" verdict is NOT reliable evidence (4 of 4 refuted) L9048 +- **§136c** — SIBLING-FIRST is a DERIVATION shortcut, not just a conflict fix (the fastest route in a family wave) L9084 +- **§136d** — Four gcc-2.7.2 levers the redraft lane found (each closed a residual no other lever moved) L9109 +- **§136e** — §136c's PRECONDITION, and two more symptom keys (wave 4b batch 3) L9153 +- **§136f** — Two declaration sub-cases the reconcile lane surfaced (lane now 15/15 lifetime) L9201 +- **§136g** — When the index points at the WRONG lever: two byte-refuted routings (func_801863B4) L9226 +- **§136h** — CORRECTION: the zero-crack pool does NOT "refill with cheap work" (my error, byte-measured) L9255 +- **§136i** — The drafter model LADDER: Haiku → **Sonnet** → Opus → Fable5 (Drew, 2026-08-03) L9285 +- **§136j** — The failure MIX flips with function size (measured across four bands, one session) L9317 +- **§137** — REGALLOC-PERM is a TWO-COMPILE ARITHMETIC PROBLEM, not a permuter job L9359 +- **§137a** — A gate verdict has a TIMESTAMP; re-check it against the draft's mtime L9401 +- **§138** — The propagation lanes: a gate refusal is a DECLARATION, and which lever you owe depends on blast radius L9430 +- **§3-The** — triage, cheapest first L9436 +- **§3-The** — DEFINITION-side alias is the only escape when the fleet canon disagrees on a promoting param L9488 +- **Rank** — the lane by measured concentration, not by class count L9496 +- **THREE** — carry variants hide in one "CARRY-FIXABLE" bucket — and they need different fixes L9505 +- **§134** — again, in a second tool — and the waiter rule corrected L9541 +- **STEP** — 0 of sibling-first: grep `src/` for a distinctive LITERAL from the `.s` L9561 +- **Reconciling** — a gate-refused draft: which way you edit depends on WHERE the TU's decl is L9580 +- **§139** — A GATE THAT GREPS FOR VERDICTS MUST ASSERT 1:1 ACCOUNTING; and a `--src` filter must not survive a carve (P30 S38, wave 6: 10 of 16 drafts vanished) L9609 +- **§3-The** — generalisation — three corollaries worth more than the bug L9641 +- **§3-And** — the inverse-lookup trap, same session L9658 +- **§140** — A METRIC IS NOT A MEASUREMENT UNTIL IT IS REPRODUCIBLE FROM THE COMMITTED TREE (P30 S1e: a phantom regression that gated the session's best lever) L9675 +- **§3-The** — three-line proof (do this before diagnosing any metric movement) L9695 +- **§3-The** — two instrument defects it exposed L9704 +- **§3-The** — same swallow, twice more, in the integration spine L9724 +- **§3-Two** — wrong mechanisms I chased first, and why they were wrong L9735 +- **§141** — The §134 class is CLOSED: every line-shape decision now routes through `cdecl._mask` (P30 S39) L9755 +- **§142** — An open stub whose `h_exact` class is MATCHED elsewhere is FREE. Propagate the body; do not gate a draft. (P30 S39, +7,710 ins in two commands) L9793 +- **§3-The** — measurement (do this before any wave; it is ~20 lines and needs no builds) L9805 +- **§3-The** — trap that hid it — SAME FUNCTION, TWO ROUTES, ONLY ONE IS FREE L9820 +- **Route** — selection (why `--addr` sometimes says "nothing changed") L9829 +- **§3-And** — the report-vs-bytes lesson attached to it L9837 +- **§143** — `cast_call_sites` read a RETURN STATEMENT as a prototype and deleted it. A 0/39 sweep became 18/39. (P30 S40) L9849 +- **§144** — THE LITERAL'S SPELLING PICKS THE IMMEDIATE ENCODING (P30 S40 wave 1, `func_801822E0`) L9903 +- **§145** — Three loop/combine levers from the S40 wave-2 drafters (16/16 match_one) L9942 +- **§146** — RE-MEASURE A WALL BEFORE YOU RESPECT IT. Both "permanent" giants fell to drafts already on disk. (P30 S6, +50,094 ins) L9992 +- **§3-Why** — a correct draft can read as an intrinsic wall L10003 +- **Then** — propagation returned 0/137 TWICE — both times a missing TYPE L10015 +- **§3-Two** — errors of mine, both instructive L10024 +- **§3-The** — rule L10038 +- **§147** — The three-stratum FRAME LAW, and four "stop searching" verdicts (P30 S42, `func_8017C294`, serial run) L10051 +- **§3-A.** — The frame has THREE strata, and stratum 3 is unreachable from C L10056 +- **§3-B.** — A `?:` on MEMORY operands costs ~16 bytes of invisible frame; on REGISTER operands, zero L10072 +- **§3-C.** — Inner-block declaration does NOT delay slot allocation — BYTE-REFUTED L10083 +- **§3-D.** — A lone `$t8`/`$t9` in the target is RELOAD SCRATCH — reproduce the spill, don't pin the register L10088 +- **§3-E.** — A `qty_compare` TIE is not spelling-reachable — recognise it and stop L10098 +- **Consequence** — for the family (a real scheduling decision) L10110 +- **§148** — The loop.c hoisting THRESHOLD is arithmetic you can compute, and the `?:` clamp that folds to MIN_EXPR (P30 S42, `func_8017C6F4`, 947 ins) L10160 +- **§3-A.** — `move_movables` hoists iff `threshold × savings × lifetime ≥ insn_count` — and you can read it L10166 +- **§3-B.** — `(v < 0x40) ? v : 0x3F` is folded to `MIN_EXPR` and expands to the WRONG SHAPE L10185 +- **§3-C.** — A zero-byte ALLOCNO-PRIORITY slider L10199 +- **§3-D.** — Reproduce the original's BUGS verbatim L10209 +- **§149** — Four instrument defects in one session, and the two questions they were hiding (P30 S43) L10258 +- **§3-A.** — A prep step that returns its input on failure is indistinguishable from a search that found nothing L10264 +- **§3-B.** — Same address + same name ≠ same body — and the ledger keys on address L10282 +- **§3-C.** — `make: *** [...] Error N` is a summary, never a diagnosis L10298 +- **§3-D.** — "Cheap fuel" that was never probed: 0 of 31 templatable L10308 +- **§150** — A register ROTATION across symmetric blocks is VARIABLE-IDENTITY evidence, not an allocator tie (P30 S43, `func_8017C6F4`, 947 ins ×4) L10327 +- **§3-The** — fix L10334 +- **§3-The** — method that found it (this is the transferable part) L10344 +- **§3-Two** — corrections to the record L10360 +- **Diagnostic** — order (adopt this) L10371 +- **§151** — THE GHOST WEDGE: when a load-before-store transposition is unreachable by ANY statement order (P30 S43, `func_8017EF68`, 969 ins) L10382 +- **§3-The** — mechanism (read from cc1's own `-dR` trace, not inferred) L10387 +- **§3-The** — lever — a zero-emission insn that absorbs the blocked tick L10402 +- **§3-The** — two fallouts, and how to close them (both measured, in order) L10410 +- **When** — to reach for it L10422 +- **§152** — BYTE SIZE is the family key that name- and h_seq-grouping both miss (P30 S43, the 0xECC family: 1 crack → 12 overlays → 11,364 ins) L10433 +- **§3-The** — finding L10438 +- **§3-The** — key L10447 +- **§3-Two** — cautions that must travel with this technique L10458 +- **§3-The** — companion defect (open) L10469 +- **§153** — THE ADDRESS-REMATERIALISATION LAUNDER: a third zero-emission asm lever (P30 S43, `func_8018D98C`, 710 ins) L10481 +- **Symptom** — Symptom L10489 +- **Mechanism** — (gcc source + RTL dumps, not inferred) L10494 +- **What** — does NOT work (14 byte-measured probes) L10501 +- **§3-The** — cure — a fresh launder per site, each in its own block L10507 +- **Companion** — levers from the same function L10517 +- **§154** — Reading a disc payload: the module-id word, static base derivation, and "type 1 = uncompressed overlay" (P30 S44) L10537 +- **§3-A.** — Payload word0 is a global MODULE ID; code starts after the header L10542 +- **§3-B.** — Two static base-derivation methods that must AGREE (use both) L10551 +- **§3-C.** — PAC type 1 = the same payload class as type 4, just NOT compressed L10563 +- **§155** — hi/lo literal scanning MUST track base registers (S45) L10573 +- **§155a** — the same failure class, one level up: SHAPE-blind table scanning (S45 p5) L10582 +- **§155b** — check the TYPE your oracle returns before comparing against it (S45 p5) L10602 +- **§155c** — the ZERO-REFERENCE trap: gcc splits a global-array address across the `lui` and the LOAD (S46) L10625 +- **§156** — an ORPHANED reconcile poisons the fleet: `dedup_propagate`'s kept edit (S45 p6/p7) L10655 +- **§157** — the cheap-tier size cliff, measured (S45 p6) L10702 +- **§158** — The RANGE-EXTENDER: a fourth zero-emission asm lever completes the allocno toolkit (P30 S46 tier-3, `func_8017CE58`, 733 ins) L10727 +- **Symptom** — Symptom L10736 +- **§3-Why** — the fork is chained (gcc source, validated insn-by-insn against -dS/-dR dumps) L10742 +- **§3-The** — method (dump-arithmetic first, then place — no probing) L10755 +- **Bonus** — facts worth keeping L10772 +- **§156** — THE PREFERENCE-DONOR MERGE: cross-region variable reuse is what fills a0-a3, and a call-arg use in ONE region steers the fill in ALL of them (P30 S46 tier-3, `func_80186E24`, 611 ins: 236-off "S11 regalloc-order" → MATCH, zero new pins) L10787 +- **§159** — THE DECLARATION AXIS: conform to byte-truth, and make every guard state its COVERAGE (P30 S47; ~10,930 sites across 8 axes, fleet byte-identical) L10843 +- **§160** — THE REACH-15 WAVE HARVEST: an align-1 block move, and the instrument that called it a wall (P30 S47) L10908 +- **§161** — THE RETRY-WAVE HARVEST: a jump table indexed from zero, and two allocator traps (P30 S47) L10984 +- **§162** — S48 WAVE-1 HARVEST (P30, 2026-08-11): the reach-ordered sibling campaign's first 12 targets L11029 +- **§162a** — SHARPENS *(sharpens §161a, §131, §8a-pad, §129a)* L11056 +- **§162b** — SHARPENS *(sharpens §48-A3, §156, §150, §76)* L11085 +- **§162d** — SHARPENS *(sharpens §31, §21, §30, §55a)* L11114 +- **§162e** — NEW L11156 +- **§162** — THE LICM PAIR: what makes an address a movable AT ALL, and why the preheader order is the body order (P30 S47, `ov_MAIN_012`) L11158 +- **§162f** — SHARPENS *(sharpens §42d, §41d, §73, §10)* L11224 +- **§162g** — NEW L11279 +- **§162** — CROSS-JUMP DIRECTION: the surviving copy is always the LATER one, so a BACKWARD `j` into a sibling arm is a source `goto` (P30 S48) L11281 +- **§162h** — SHARPENS *(sharpens §88, §88a, §50-B, §8)* L11315 +- **§162** — The cross-jump "CALL veto" is a COUNT law, not a CALL law (BOUNDS §88a; P30 S48, `func_80189540`) L11317 +- **§162i** — SHARPENS *(sharpens §135, §21, §42, §32)* L11383 +- **§162j** — SHARPENS *(sharpens §25, §136d-1, §48-B, §46-L2)* L11408 +- **§162k** — SHARPENS *(sharpens §1-I2, §12, §160d, §21)* L11437 +- **§162l** — SHARPENS *(sharpens §48-B, §48-C1, §20, §21)* L11500 +- **§162m** — SHARPENS *(sharpens §36, §158, §148, §153)* L11555 +- **§158a** — THE FIFTH LEVER IS NOT AN ASM: `do { } while (0)` is a REGION ref-multiplier you MINT (P30 S48, `func_8017CBC8`, ov_MAIN_012 / jr_801789AC, 188 ins → MATCH) L11557 +- **§3-The** — law L11564 +- **Size** — it before you write it (§158 step 1-2, applied) L11575 +- **§3-The** — wrap BOUNDARY is the dial — and it is indiscriminate L11596 +- **§3-Not** — a pure dial L11602 +- **DIAGNOSTIC** — TELL — two faces, one law L11606 +- **§162n** — NEW L11628 +- **§162o** — SHARPENS *(sharpens §158, §136-1, §136-6, §79)* L11661 +- **§162p** — SHARPENS *(sharpens §48-B, §46-L2, §156, §136d-1)* L11720 +- **§162q** — SHARPENS *(sharpens §30, §30a, §135-2, §136-13)* L11737 +- **§163** — S48 WAVES 2-3 HARVEST (P30, 2026-08-11/12): the five that were byte-probed and are actionable L11775 +- **§163z** — THE UNVETTED REMAINDER (do not cite as law; each needs a dedupe pass) L11843 +- **§164** — S48 §163z SKEPTIC PASS (P30, 2026-08-12): 190 claims vetted, 82 banked L11863 +- **§16Xy** — SHARPENS *(sharpens §136d-3, §37 /s-DEP LATTICE, §135-2, §136-13, §162q)* L12315 +- **§3-The** — `/s` drop clause is in ALL THREE dependence predicates, so the FIXED-ADDRESS STORE is what floats (P30 S48, `func_8017CA18`, ov_MAIN_012) L12317 +- **§164z** — REFUTED CLAIMS: do NOT re-derive these L13651 +- **§165** — S48 WAVE-4 HARVEST (P30, 2026-08-12): banked the same day the wave landed L13717 +- **§16Z** — SHARPENS *(sharpens §37 "the /s-DEP LATTICE", §136-13, §136-14, §16Xy, §162q, `gcc-2.7.2-map/sched.md` §64)* L14368 +- **§3-The** — ADDRESS-CLASS TABLE: which load/store pairs even REACH the `/s` clause (P30 S48 wave 4, `func_80185B44`, ov_SC03_014) L14370 +- **§165z** — REFUTED THIS WAVE: do NOT re-derive L14886 +- **§166** — THE DESTINATION-TU ORACLE (P30 S48): the seven-attempt bug that was never codegen L14930 +- **§167** — S48 WAVE-5/6 HARVEST (P30, 2026-08-12): the saturation point L14986 +- **§167z** — REFUTED IN WAVES 5/6: do NOT re-derive L16182 +- **§168** — THE COUSIN TIER (P30 S49, 2026-08-12): h_seq's exact-hash brittleness, measured — and the similarity map above it L16239 +- **§169** — THE MICRO-ADAPT LANE (P30 S49): edit a proven body, don't crack a new one L16291 +- **§170** — THE A-PROP WORD-DIFF CARD (P30 S49): the lane that had no owner L16338 +- **§171** — THE STALE SEED SYMBOL (P30 S50, 2026-08-13): why §170's 91%→57% was never codegen L16382 +- **§171a** — THE MECHANICAL A-PROP DRAFT (P30 S50): 256 members banked with no agent in the loop L16448 +- **§171b** — THREE CARRIES THE MECHANICAL DRAFT NEEDS (P30 S50, banking the top-reach families) L16498 +- **§172** — THE ORPHAN-SLOT MECHANISM v2 (P30 S50-Max): the complete frame-residue model for gcc-2.7.2 MIPS L16531 +- **§172a** — TWO DECOMPILATION TELLS FROM THE SAME DIG (P30 S50-Max) L16585 +- **§172b** — THREE MORE TELLS FROM THE GCC READ (P30 S50-Max, banked on Drew's ask) L16601 +- **§173** — THE STORED-PLUMBING RECOVERY RECIPE (P31 T6): symfix-first, per-group isolation, and where the verdicts have no drafts L16644 +- **§174** — THE ADAPT-CARD WAVE RECIPE (P31 waves A/B, 2026-08-14): prevention beats recovery L16680 +- **§175** — A CALLER-SAVED REGISTER PIN CAN BE A CORRECTNESS BUG, NOT JUST A SCHEDULING CHOICE (P31 wave H, 2026-08-15) L16750 +- **§176a** — THE VERIFICATION-LAYER LAWS (P31 overnight, 2026-08-15). What each check can and cannot prove. L16775 +- **§176b** — BATCH-GATING MECHANICS (P31): what changes when N drafts land in ONE .c L16815 +- **§176d** — THE CONFLICT TABLE MUST BE SEEDED FROM THE TU, AND KEYED PER FILE (P31 S52, 2026-08-15) L16841 +- **§176e** — SYMBOL IDENTITY IS COMPUTABLE OFFLINE (P31 S52): `tools/reloc_identity.py` L16880 +- **§176f** — THE DECLARATION FORM IS A MATCHING LEVER, SO RECONCILE TOWARD THE FORM THE MATCH NEEDS (P31 S52) L16937 +- **§176g** — SIZE A WAVE BY INSTRUCTIONS, NOT BY CARDS (P31 S52 — the adopted doctrine) L16968 +- **§176h** — THE BATCH-SUBSTITUTION HAZARD MAP (P31 S52): seven holes, three wrong fixes, one law L17006 +- **§3-A.** — The seven under-reporting holes (all in `gate_main`, all the same shape) L17014 +- **§3-B.** — Typedef handling — the only strategy that survives contact L17032 +- **§3-C.** — The limit that remains (recorded, not solved) L17054 +- **§3-C2.** — RECONCILE BEFORE THE FIRST GATE — a parked draft gets HARDER to bank, not easier L17061 +- **§3-D.** — The measured cost shape, and what to build next L17084 +- **§176i** — WHAT A STATIC PRE-GATE CHECK CAN AND CANNOT PROVE (P31 S52, wave Q) L17102 +- **§176j** — STOPPING A WAVE MID-FLIGHT COSTS THE IN-FLIGHT TAIL (and how much is recoverable) L17134 +- **§176j-2** — THE REPAIR PASS, MEASURED (do this instead of resuming) L17160 +- **§176k** — TWO SELECTOR BUGS THAT SILENTLY SHRINK A WAVE L17180 +- **§177** — 🔴 THE EPILOGUE RETURN-DELAY SLOT IS DECIDED BY YOUR SAVED-REGISTER SET, NOT BY SCHEDULING L17197 +- **§178** — SIX LEVERS MINED FROM THE WAVE-P JOURNALS (P31 S52), each byte-proven and source-cited L17254 +- **§3-A.** — THE `$0`-ADD OPAQUE COPY defeats `make_regs_eqv` (func_80033398, 93 ins) L17266 +- **§3-B.** — A `return ` IS A PRIORITY-1 HARD-REG SET THE SCHEDULER PLACES FIRST (func_8001BE30, 92 ins) L17282 +- **§3-C.** — SINGLE-SET TEMPS GET THE BIRTHING BOOST (func_8001D3FC, 196 ins) L17295 +- **§3-D.** — A NARROW TYPE BLOCKS COPY ELISION (func_8001D3FC — new idiom) L17303 +- **§3-E.** — THE ZERO-OFFSET ALIAS HOLE (func_80037028, 71 ins) L17310 +- **§3-F.** — `MEM_IN_STRUCT_P` ASYMMETRY IN `true_dependence` (func_80037144, 124 ins) L17319 +- **§3-G.** — TWO MODELLING TRAPS THAT COST THESE AGENTS SWEEPS OF HUNDREDS OF COMPILES L17325 +- **§179** — IDIOMS MINED FROM THE WAVE P/Q JOURNALS (P31 S52, harvest pass) L17341 +- **§179-A** — 🔴 A LOOP-WALKED POINTER **PARAMETER** HANDS ITS ARGUMENT REGISTER TO THE GIV (9 byte-proofs) L17351 +- **§179-B** — 🔴 THE HAND-WRITTEN-ASM TRANSCRIPTION CHECKLIST (maspsx + masked_diff; 10 byte-proofs) L17400 +- **§179-C** — 🔴 A FUNCTION WITH NO EPILOGUE (falls into a sibling's shared tail) MUST BE FILE-SCOPE `__asm__` L17450 +- **§179-D** — `gte_stflg` MUST CLOBBER `"$12"` OR THE WHOLE TEMP FILE ROTATES BY ONE L17501 +- **§179-E** — A `>2*MAX_MOVE_BYTES` BLOCK COPY IS A **STRUCT ASSIGNMENT**, NOT A HAND LOOP L17521 +- **§179-F** — PINNING A LOOP-WALKED POINTER IS A TOTAL OFF-SWITCH FOR STRENGTH REDUCTION L17547 +- **§179-G** — 🟡 A PIN CAN **CREATE** A COMBINE `LOG_LINK` AND DELETE AN `andi` (sixth RC-5 channel, n=1) L17570 +- **§179-H** — A MID-BODY `.global LABEL` PAIR SLICES A BYTE-COMPARABLE FRAGMENT OUT OF A LARGER ROUTINE L17597 +- **Considered** — and NOT banked L17620 +- **§176c** — MAIN (SLUS_007.26) CANNOT BE GATED INCREMENTALLY L17637 +- **§176** — SEVEN LEVERS FROM THE P31 OVERNIGHT WAVES (2026-08-15): statement order, false regalloc, and the pin that fights back L17648 +- **§176-A** — "SCHEDULE / DELAY-SLOT / LENGTH-DRIFT ±1" ⇒ check STATEMENT ORDER around the call first L17654 +- **§176-B** — "REGALLOC-PERM, 1-4 instructions off" ⇒ it is usually NOT register allocation L17678 +- **§176-C** — 🔴 WALL REFUTATION: a hard-register pin CANNOT schedule around a call, because of a genuine gcc-2.7.2 bug L17724 +- **§176-D** — CSE-class levers used in reverse (two sharpenings of §153 and cse_expr §2) L17750 +- **§176-E** — Two cheap source spellings, both cc1-probed L17776 +- **§176-F** — Misdiagnosis triage: four residual verdicts that were lying L17798 +- **What** — is NOT banked here L17815 +- **§180** — THE LEFTOVER-DRAFT HARVEST: RE-VERIFY WHAT YOU ALREADY HAVE BEFORE DRAFTING ANYTHING NEW L17828 +- **§180b** — WHAT THE PRE-GATE LADDER ACTUALLY FINDS IN A COLD PILE (the shape of integration debt) L17857 +- **§180c** — WHEN A BINARY'S MASS BAND IS SPENT, THE FLEET-WIDE DRAW IS STRICTLY BETTER L17876 +- **§181** — WHAT A WAVE'S GATE ACTUALLY REJECTS (P31 S53, measured on wave R's 45-draft main pile) L17894 +- **Only** — ONE of 27 blocked drafts was wrong. The other 26 were correct and unbankable. L17895 +- **§182** — §177's HONEST NEGATIVE: the epilogue lever cracked 4 of 16, and the `800c3` cluster held L17950 +- **§180d** — THE `pgrep` BRACKET TRICK PROTECTS THE PATTERN, NOT THE COMMAND LINE L17964 +- **§183** — THE DECLARATION-RECONCILIATION PLAYBOOK (P31 S53, measured on 20 byte-verified drafts) L17976 +- **§3-18** — of 20 reconciled while keeping the match. The two that did not are mechanism, not effort. L17977 +- **§184** — COMMENT-BLINDNESS IS A DEFECT CLASS, NOT A BUG (P31 S53: three tools, one root cause, one session) L18047 +- **§185** — EDIT THE SIDE THAT IS CHEAP TO VERIFY, AND CHECK A TU RETYPE AT ITS USE SITES L18075 +- **§186** — CROSS-JUMPING RUNS **AFTER** SCHEDULING, SO NO C-LEVEL BARRIER CAN STEER IT L18107 +- **§186b** — A NO-SAVE 16-BYTE FRAME IN A LEAF FUNCTION MEANS `s16` LOCALS, NOT A HIDDEN CALL L18128 +- **§186c** — WHERE A VALUE IS LOADED DECIDES WHICH ALLOCATOR OWNS IT, AND THEREFORE ITS REGISTER L18136 +- **§187** — 🔴 "SAME SOURCE" IS NOT "SAME OBJECT": THE SDK BUILD AND THE GAME BUILD DISAGREE ON GTE NOPS L18153 +- **§188** — 🔴 THE `jr $ra` + `addiu $sp` TAIL IS AN **ASSEMBLER** ARTIFACT, NOT A FRAME SHAPE L18191 +- **§189** — FIVE COMPILER LAWS MINED FROM THE WAVE R/S JOURNALS (P31 S53), each source-cited and re-derived by a second agent L18241 +- **§190** — THREE PRESCRIPTIONS FROM THE SAME HARVEST (weaker evidence than §189, honestly labelled) L18316 +- **§191** — WHAT THIS HARVEST DID **NOT** BANK (4 rejected, 4 narrowed) — recorded so it is not re-derived L18353 +- **§192** — THE PRE-GATE LADDER WAS MAIN-ONLY, AND NOBODY COULD SEE IT (P31 S54) L18375 +- **Three** — defects in one call path; the overlay slates that carry most of the wave work were being waved through L18376 +- **§193** — THE WAVE-T HARVEST (P31 S54): 71 index_gap reports -> 9 laws, 5 rejected, 61 already-covered L18440 +- **§193-A** — The wave card ships only OPEN-set pointers and discards the atlas's BANKED one — `exemplar`/`sibs` are stubs 100% by construction (tools/atlas.py:96/657), while `seed.ref` (matched pool, atlas.py:505-536) is dropped at build_wave_atlas.py:143 L18457 +- **§193-B** — A NARROW CAST OF A WIDE PARAMETER COSTS ONE EXTRA INSTRUCTION WHEN ITS STATEMENT SITS AFTER AN INTERVENING `jal` — AND THE DECIDER IS `combine.c:929`'s CROSS-CALL GUARD, NOT REGISTER ALLOCATION L18524 +- **§193-C** — gcc-2.7.2 cross_jump merges the SCHEDULED common SUFFIX only — there is no prefix/head merge, so §8/§48-A1's "duplicate into both arms and cross_jump refunds it" is a TAIL-only lever L18562 +- **§193-D** — A COMPILER-GENERATED ARGUMENT COPY IS A `optimize_reg_copy_1` TRIGGER: when the pointer's LAST use in a block precedes a call that takes the pointer *as a register*, sched1 hoists the implicit `move $aN,$sN` to the block top and local-alloc re-bases the WHOLE block's memory operands onto `$aN`. The only C dial is a label (the §165-24 goto-join) between the block and the call. L18596 +- **§193-E** — A varying-address (pointer) load is re-emitted once per CSE-LIVE INTERVAL, and naming it in a C local is the only C-level lever over that count — no store SPELLING has any reach L18667 +- **§193-F** — §148-A2 — The `threshold -= 3` STAIRCASE: `move_movables` admits a COUNT of invariants, not a boolean — two identical merged constants split hoisted/not-hoisted by LIST ORDER, and `insn_count` picks the rank cutoff L18697 +- **§193-G** — §164-54's "scope to ≥4 arms" bound is byte-wrong — the dispatch-topology oracle goes live at THREE case nodes (`balance_case_nodes` splits at `i > 2`), but only for a signed-after-promotion index L18761 +- **§193-H** — A pointer-derived base load `*(s32*)(p+K)` is uncacheable across ANY memory write or call (cse's third kill disjunct) — so the target emits one `lw` per store-separated RUN of spellings, and a run of stores sharing one `lw` is a C local you must declare L18822 +- **§193-I** — A DECLARED AGGREGATE LOCAL HAS AN 8-BYTE FRAME STRIDE — CEIL(size,8), NOT size. N ARRAYS THEREFORE COST 8·k MORE THAN ONE HAND-LAID STRUCT (k = how many of them have size mod 8 ≠ 0), AND THE TELL IS IDENTICAL INSTRUCTION COUNT WITH EVERY $sp DISPLACEMENT SHIFTED BY THE SAME CONSTANT. L18862 +- **§193-REJECTED** — what this harvest did NOT bank (recorded so it is not re-derived) L18921 +- **§194** — THE WAVE-U HARVEST (P31 S54): 64 index_gap reports -> 14 laws, 5 rejected, 44 already-covered L18948 +- **§194-A** — A zero-byte scheduling fence goes AFTER the defining statement to make that computation emit FIRST in its block — and the barrier predicate is `volatile`-or-colon-less, not the `"memory"` clobber (COMPLEMENTS §165-40; does not refute it) L18965 +- **§194-B** — A `addu $rA,$rB,$zero` copy feeding ≥2 `sh` stores is a SECOND, 16-BIT-DECLARED local — the width, not the clamp or the join liveness, is what keeps the copy (and func_80183094's pin + `"memory"` clobber are both provably inert) L19031 +- **§194-C** — A CALLER-SAVED loop counter proves its live range crosses ZERO calls — so it cannot share a pseudo with any value LIVE ACROSS a call (but it may freely share one with values that merely sit between calls) L19069 +- **§194-D** — Declared width of a computed-value local is a sched1 dial (count-neutral) — a replication + attribution correction of §165-17, NOT a new argument-register law L19132 +- **§194-E** — The wave card's `exemplar` is the TARGET ITSELF on 42/73 wave-U and 36/71 wave-T cards — a construction consequence of `atlas.py:657` (exemplar = max-nins OPEN member) meeting `build_wave_atlas.py:166` (one card per gid); and the shipped §193-A `seed_ref` is same-binary on 0/51, so no card field can ever name a destination-TU sibling L19173 +- **§194-F** — `if ((*p = v = f()) == 0)` is an expand-time pseudo SPLITTER (store_expr's `want_value && MEM` path), not a fold — it partitions one value between local_alloc and global_alloc. BOUNDS §21's L1872 bullet, whose stated direction is byte-wrong on 3 of 4 instances, and CLOSES the control §167-37 asked for. L19210 +- **§194-G** — Reading the integer half of a 16.16 stack aggregate: REGISTER-LIVENESS, not the C spelling, decides `sra` vs `lhu` — and the break is count-neutral L19283 +- **§194-H** — §164-29's WAR fence runs again at SCHED2 ON HARD REGISTERS: an in-place `v &= K` before a branch fences the store that reads v, and when TWO independent stores compete for the one delay slot the fence picks the winner at ZERO length drift (a WIDTH/sh!=sw swap, not a nop). Corrects §167-42's reconstruction (pseudo arm → hard-reg arm) and supplies its first re-runnable A/B. L19326 +- **§194-I** — §16N+2's magic-per-odd-part ladder has exactly one broken row — read the divisor arithmetically instead: d = round(2^(32 + post_shift) / magic_read_as_unsigned) L19364 +- **§194-J** — Back-to-back identical stores: flow.c's `last_mem_set` deletes the first, and only `volatile` saves it L19407 +- **§194-K** — Blind sched1's alias oracle with a second SET of a pointer pseudo — the first zero-byte, non-volatile, dependence-CREATING lever (corrects §167-05's "volatile is the only door"; fourth consumer of reg_n_sets) L19459 +- **§194-L** — §88b and §189-E are BOTH half-wrong, but not the way the candidate says: the compare-constant shape is a 2-D lookup (cmp_info ROW × constant-in-window), and naming matters on OPPOSITE sides of the window for the GE/LT rows vs the GT/LE rows L19537 +- **§194-M** — A STORE in a CONDITIONAL branch's delay slot proves its C statement DOMINATES the branch — reorg can never pull a store out of either thread (gcc-2.7.2, -mips1) L19585 +- **§194-N** — §193-D's C dial is misstated: the lever is a SURVIVING CODE_LABEL (a label with a real incoming edge), not "a label between the block and the call" — a bare label, or a `goto L; L:` pair whose target is the next active insn, is deleted by jump1 (jump.c:663-669 → delete_insn → jump.c:3458-3461, and jump.c:243 for the bare case) long before sched1/local-alloc, and costs exactly zero bytes L19643 +- **§194-REJECTED** — what this harvest did NOT bank (recorded so it is not re-derived) L19703 +- **§195** — THE WAVE-V HARVEST (P31 S54): 67 index_gap reports -> 14 laws, 9 rejected, 76 already-covered L19724 +- **§195-A** — §167-08's "an $aN READ before the jal is scratch" has a byte-proven FALSE-NEGATIVE class: an argument that DIES at the call is allocated straight into $aN, so its only def is a plain load far above the jal and every intervening use reads $aN — there is no positive tell in either direction, only the two-arity A/B L19738 +- **§195-B** — A CALL_INSN does not start a basic block in gcc-2.7.2 — so a call-crossing temp can be a LOCAL-alloc quantity (the missing precondition under §48-A2 / §52 / regalloc.md K8) L19809 +- **§195-C** — A call-argument `%hi/%lo` pair sitting at the block head, far above its `jal`, is a load-delay-gap filler chosen by SOURCE STATEMENT ORDER — swap the two independent statements nearest the call; a single-use `void *p = &SYM;` call-arg temp is OUTPUT-inert against it (but NOT expand-stream-inert) L19851 +- **§195-D** — §195 — `masked_diff.mask_for` returns 0 for EVERY `j`/`jal` word, so an internal `j` destination is invisible to match_one, the permuter scorer AND every similarity tier: a control-flow semantic error (which calls execute) surfaces as a 1-instruction residual mislabelled `DELAY-SLOT / profile=schedule`, or as an outright false MATCH L19899 +- **§195-E** — A 0/1 materialised at a JOIN immediately before the controlling `beqz`/`bnez` proves the source NAMED the condition — a truth expression in an `if`'s controlling position reaches `do_jump`, which has no value path L19967 +- **§195-F** — fold-const.c:4825 canonicalises a `?:` whose THEN arm is zero (or constant against a non-constant ELSE) by inverting the condition and swapping the arms — so a ternary's written arm order is byte-inert there, and `c ? 0 : X` is unspellable: it always compiles as `!c ? X : 0` L20025 +- **§195-G** — §NEW — TWO ARMS CALLING THE SAME CALLEE MERGE INTO ONE `jal` UNLESS EACH ARM'S OWN CODE CONSUMES THE RESULT: the C dial that keeps two call sites apart is WHERE the consumer test lives, and the branch SENSE you spell it with is byte-inert (jump.c:1737 canonicalises it) L20077 +- **§195-H** — §165-27g — ON A FIXED-SYMBOL GLOBAL, `extern T D[];` + `D[0]` IS THE CSE RELOAD DIAL, AT ZERO ADDRESSING COST, AND THE ELEMENT COUNT IS INERT (§165-27's `T v[2]` CAVEAT IS A LOCAL-FRAME FACT AND DOES NOT TRANSFER) L20125 +- **§195-I** — §145(b) AMENDED — the pointer-bump `addiu` is saved by cse, not combine: ANY second SET of a pseudo in the address's equivalence chain (in-place `p += K`, §145(b)'s `p = r;` copy, or an asm re-tie) kills the fold; the pass is cse and the gate is `invalidate`'s `reg_tick++` L20172 +- **§195-J** — GTE / PsyQ op CALL-vs-INLINE is a PER-SITE SOURCE FACT, not a TU style — both forms coexist in one TU (measured in 2 TUs), and the tell is the target's own opcodes (`lwc2`/`sqr`/`swc2` vs `jal`), not the sibling. Costs -8 ins on func_8018505C. Corollary: the game's inline `sqr` macro emits TWO hazard nops, the SDK's `Square0` body emits ONE — so the inline form is provably not `Square0` inlined (a second instance of §187's SDK-vs-game GTE nop divergence). L20237 +- **§195-K** — At -O2 the §18 array-of-struct lever is a FRAME lever, not a length lever — but only when the N reads carry DISTINCT index expressions; with a SHARED index §18's +2-instruction residual is still alive at -O2 (the submitted "memory-loaded narrow index" precondition and unconditional length-neutrality are both falsified) L20281 +- **§195-L** — The cse store-re-seed does not cross a JOIN LABEL: per-arm stores + a join read keep the reload that one join store deletes (bounds §193-E BOUND 1/BOUND 3 with §48-B's EBB boundary) L20333 +- **§195-M** — Frame `vars` is a SEQUENTIAL bump-allocation, not a flat sum: §193-I's CEIL(aggregate,8) term and §165-03/§167-06's 8×orphan term are the SAME frame_offset walk at two different compiler stages, and each stage re-CEILs frame_offset to 8 before it allocates L20385 +- **§195-N** — In a call-bearing chain of N≥2 `if (f(...)) return 1;` tests closed by `return 0;`, the LAST test must stay in STATEMENT form — the value form (`return f() != 0;` / `? 1 : 0` / `!!f()`) costs +1 `j` and empties the other N−1 delay slots. The cause is REORG block placement, not jump.c's `delete_jump`. L20434 +- **§195-REJECTED** — what this harvest did NOT bank (recorded so it is not re-derived) L20481 +- **§196** — PUT ON THE CARD WHAT THE TREE ALREADY KNOWS: the fleet's declaration consensus (P31 S54) L20527 +- **§197** — THE WAVE-W HARVEST (P31 S54): 68 index_gap reports -> 4 laws, 3 rejected, 41 already-covered L20582 +- **§197-A** — A NARROW SIGNED MEMORY READ FEEDING A CONSTANT `>>` LOSES ITS `lh`, AND THE CURE IS AN ASM RE-TIE (attribution CONTESTED: cse vs combine) L20596 +- **§197-B** — A REPEATED COMPARE OF ONE VALUE AGAINST ONE CONSTANT IS DELETED BY cse's `qty_comparison_code` CHANNEL (the non-EQ complement of §165-03) — and a front-end-opaque mask on EITHER compare is a pure-C dial that keeps the target's second branch L20634 +- **§197-C** — Fix A1 (operand order) cannot move a commutative destination whose .greg conflict set already contains BOTH operand hard registers — split the accumulate so the destination IS the load's pseudo L20662 +- **§197-REJECTED** — §197-REJECTED L20707 +- **§199** — THE WAVE-X HARVEST (P31 S54/S55): 63 index_gap reports -> 7 laws, 2 rejected, 56 already-covered L20722 +- **§199-A** — §189-A's asm→source inference is byte-FALSE: an interloper between a split constant's `lui`/`ori` is a SCHEDULE fact, not a source fact — and the separator is the BIRTHING BOOST, not a "priority floor" (§189-A's split-timing half survives; its "no statement order / no pin" absolute and the candidate's own forward-scheduler narrative both fall) L20733 +- **§199-B** — A permutation sweep that holds ANY statement fixed is not a sweep: the statement an agent pins as "obviously load-bearing" is the one carrying the signal, and the partial sweep returns a FLAT residual that reads as proof of order-invariance L20782 +- **§199-C** — A NEGATIVE CONSTANT MULTIPLY ALWAYS TAKES expmed's negate_variant — but whether you ever SEE the neg is decided by COMBINE, and for an EVEN |K| it never disappears L20827 +- **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` L20875 +- **§199-E** — §189-A BOUNDED AND CORRECTED — the discriminator is INSN_PRIORITY, not "is the interloper a constant": an insn between a `lui`/`ori` pair proves NOTHING about the source spelling unless it TIES the `ori` on priority, and on the pinned `-mcpu=3000` triple a dependent load never does L20935 +- **§199-F** — §164-36b — THE TARGET-HEAD FENCE IS A DELAY-SLOT THREAD SELECTOR, AND IT ONLY FIRES WHEN `mostly_true_jump > 0` (amendment to §164-36; its "−1 instruction" tell is falsified) L20994 +- **§199-G** — At TWO case nodes the switch-vs-if oracle is not blind — but the tell is ALL tests positive + a trailing `j default`, NOT the first test's polarity L21048 +- **§199-REJECTED** — §199-REJECTED L21103 +- **§200** — THE ALIAS IS THE UNIVERSAL DECLARATION ESCAPE: stop negotiating with the TU's spelling (P31 S55) L21114 +- **§201** — THE WAVE-Y HARVEST (P31 S55): 67 gap reports -> 5 laws, 8 rejected, 53 already-covered L21163 +- **§201-A** — §150-B applies to `decl_prior`'s DEF row: for an overlay-window symbol the banked "definition" is usually another overlay's function, and the card ranks it ABOVE the destination TU L21173 +- **§201-B** — In a narrowed PLUS/MINUS/AND/IOR/XOR expression the destination pointee is INERT — the sign of the materialized constant is decided by an OR over the UNWIDENED operands (convert.c trunc1), which bounds §1841 to direct constant stores L21205 +- **§201-C** — §X — A CALL'S OWN DELAY SLOT AND THE UPSTREAM CONDITIONAL BRANCH'S SLOT COMPETE FOR ONE INSN (the call's argument copy), AND ONE STATEMENT'S POSITION RELATIVE TO THE CALL DECIDES BOTH — the residual is visible at the BRANCH, not at the call L21285 +- **§201-D** — THE SIGNEDNESS OF A div/mod MAGIC IS DECIDED BY THE STATIC TYPE OF THE DIVIDEND TREE AFTER `get_narrower` STRIPS WIDENING CONVERSIONS — NEVER BY A PROVABLE RANGE. AN `& 0xFF` IS NOT A CONVERSION, SO IT NEVER FLIPS THE MAGIC; A DECLARED-UNSIGNED LOCAL *OR* A NARROWING CAST WRITTEN AT THE DIVIDE BOTH DO. L21336 +- **§201-E** — §194-J-2 — The `last_mem_set` deletion window is measured in SOURCE/expand order, not in the printed stream; a foreign store moved between the pair in C source is a real lever, and `volatile` is not always the better one L21383 +- **§201-REJECTED** — eight, the session's highest L21439 +- **§202** — THE ALIAS CARRIES A DEFINITION, NOT JUST A DECLARATION: the DEF-SIDE-RETURN wall (P31 S56) L21464 +- **§203** — A DEDUPED TYPEDEF MUST PRECEDE EVERY SPLICE POINT, NOT JUST ITS OWN (P31 S56) L21501 +- **§204** — THE WAVE-Z HARVEST (P31 S56): 82 gap reports -> 5 laws, 16 rejected, 30 already-covered L21562 +- **§204-A** — A COMPARE THAT APPEARS BOTH IN A BRANCH'S DELAY SLOT AND AGAIN ON THE FALL-THROUGH IS A JOIN WITH TWO INCOMING EDGES: THE TWO GUARDS ARE SEQUENTIAL `if`s, NEVER `if/else if` L21581 +- **§204-B** — A LOOP COUNT THAT ARRIVES ON THE STACK IS DECREMENTED IN PLACE: a fresh counter local can cost a real `move` AND permute the whole callee-saved file L21656 +- **§204-C** — WHEN A LOCAL BUFFER'S ADDRESS IS PASSED TO A CALL, ITS SIZE IS A FACT ABOUT THE CALLEE'S BODY, NOT ABOUT THE CALL SITE: grep the callee's proven definition and count the stores through the pointer parameter before you declare the local L21720 +- **§204-D** — A LOOP-INVARIANT LOAD IS ADMITTED AS A MOVABLE ONLY IF ITS ADDRESS CANNOT TRAP: `local.field` PASSES, THE SAME READ THROUGH A POINTER LOCAL IS REFUSED L21778 +- **§204-E** — `decl_prior`'s `%hi/%lo` ARM HAS NEVER FIRED: the card's promised GLOBAL-TYPE row is 0 of 1,210 L21853 +- **§204-CONFIRMED** — 30 reports that the index already answered L21905 +- **§204-REJECTED** — sixteen, twice the previous record L21999 +- **§205** — THE CHAINED ASSIGNMENT IS ITS OWN SCHEDULING DIAL: `*b = *a = v;` moves an argument copy that no local, no pin and no statement reorder will move (P31 S56) L22072 +- **§206** — THE JTBL-CARVE DRAFTING IDIOM: the bounds check is the entry count, and an EMPTY case owns a slot (P31 S56) L22127 +- **§207** — THE WAVE ab–ag HARVEST (P31 S58): 278 byte-banked notes → 25 laws, 103 self-reported no-gap L22196 +- **§208** — TWO NAMED LOCALS FOR ONE RELOADED EXPRESSION BUY TWO ALLOCNOS — the naming granularity owns the REGISTER SPLIT, not just the load count (P31 S58) L22217 +- **§209** — THE NARROW LOCAL IS A DIAL IN TWO OPPOSITE DIRECTIONS, AND §194-B's "≥2 `sh` STORES" BOUND IS BYTE-WRONG (P31 S58) L22266 +- **§210** — THE SINGLE-BIT MASK IN A BOOLEAN TAIL: `andi K ; sltu $zero,v` vs `srl n ; andi 1` is a STATEMENT-SHAPE dial, not an operator choice (P31 S58) L22343 +- **§211** — HOIST THE LOOP INIT ABOVE THE DOMINATING GUARD: it fills the guard's delay slot AND flips the counter/pointer register pair (P31 S58) L22389 +- **§212** — THE WALKING CURSOR IS COUNTABLE: `*wp++` emits one `addiu` PER STORE, `wp[0..2]` emits one (P31 S58) L22448 +- **§213** — INDEPENDENT SAME-BASE STORES: THE EMISSION ORDER IS A PERMUTATION OF SOURCE ORDER, AND THE PERMUTATION IS NOT ALWAYS THE IDENTITY (P31 S58) L22493 +- **§214** — THE BANKED TWIN MAY BE A MACRO, A DELETED `.s`, OR A SEMANTIC INVERSE — six ways a ≥0.9 similarity lies (P31 S58) L22529 +- **§215** — PIN ECONOMY: the twin's pins are NOT part of the shape, and §17's "pin every call-crossing value" is over-broad (P31 S58) L22575 +- **§216** — DISTINCT ADJACENT SCALARS vs ONE ARRAY: one `lui` per access is the tell, and the array decl is UNUSABLE (P31 S58) L22631 +- **§217** — DECODING A CALL'S STACK ARGUMENT SLOTS: `sw` at `0x10`/`0x14`/`0x18` are params 5/6/7 **(single observation — not yet cross-confirmed)** (P31 S58) L22671 +- **§218** — A NARROW TYPE AT THE ABI BOUNDARY COSTS AN IN-PLACE `sll/sra` PAIR — on the RETURN as well as on the PARAMETER (P31 S58) L22697 +- **§219** — COMPOUND `+=`, FULL ASSIGNMENT, AND AN EXPLICIT TEMP ARE THREE DIFFERENT SCHEDULES OF ONE READ-MODIFY-WRITE (P31 S58) L22726 +- **§220** — THE PARAMETER ITSELF IS A REGALLOC DIAL: use it directly, prefer `s32` to `void*`, and place the save-copy AFTER the first call (P31 S58) L22753 +- **§221** — A CONSTANT SHARED BY TWO STORES DIES AT THE CALL WHOSE DELAY SLOT REFILLS ITS REGISTER **(single observation — not yet cross-confirmed)** (P31 S58) L22793 +- **§222** — SWITCH vs IF-CHAIN, PART 3: source arm order IS emission order, a leading EMPTY case buys the median split, and a 2-way dispatch with a shared post-block is a `switch` (P31 S58) L22809 +- **§223** — READING A `jal` DELAY SLOT: the value in it was produced BEFORE the call, so it is NEVER that call's return (P31 S58) L22851 +- **§224** — CROSS-JUMP: WRITE THE DUPLICATE, AND READ A SHARED DELAY SLOT AS THE MERGE SIGNATURE (P31 S58) L22913 +- **§225** — THREE CONTROL-FLOW SHAPES NO STRUCTURED SPELLING REACHES (P31 S58) L22949 +- **§226** — FRAME PADS: FOUR WAYS §162i1/§2429's DEAD-LOCAL LEVER MISFIRES (P31 S58) L22992 +- **§227** — TYPE THE SOURCE BY THE **LOAD** WIDTH, NOT BY THE STORE WIDTH (P31 S58) L23033 +- **§228** — READING THE DIVIDE, PART N: the off-by-one compare is `% K == 1`, and three more discriminators (P31 S58) L23053 +- **§229** — THE ADDRESS IS A VALUE: NAMING IT MOVES THE `lui`/`addiu` PAIR — AND §L14410 SAYS THE OPPOSITE FOR A REASON (P31 S58) L23090 +- **§230** — THE ANCHOR PROBE: with `%hi`/`%lo` masked, the surviving `addiu` deltas tell you which assignment was written first **(single observation — not yet cross-confirmed)** (P31 S58) L23139 +- **§231** — TRANSCRIPTION AND SEMANTIC-READ HYGIENE: six ways the listing misleads (P31 S58) L23154 +- **§232** — WHEN THE `jr` DELAY SLOT'S STORE STORES THE RETURN VALUE, TIE THEM WITH ONE PSEUDO **(single observation — not yet cross-confirmed)** (P31 S58) L23195 +- **§30** — addendum (P31 S58) — the `/s` grant closes a SCHEDULING residual and a REGISTER residual with one edit L23231 +- **§194-B** — addendum (P31 S58) — BOUND 2 is byte-wrong; see §209 Direction A L23251 +- **§176-B** — addendum (P31 S58) — the misdiagnosis direction L23257 +- **§165-40** — addendum (P31 S58) — the barrier goes at the COPY SITE, not inside the region it protects L23263 +- **§164-63** — addendum (P31 S58) — the interposed asm works when the SECOND value is an ordinary assignment L23272 +- **§193-A** — / §194-E addendum (P31 S58) — where the twin's body actually lives L23281 +- **§233** — THE WAVE aa–bg HARVEST (P31 S58b): 1,101 byte-banked notes → 24 new laws, 21 addenda, ~700 already-covered L23287 +- **§234** — CONSTANT MATERIALISATION: THE STORE LVALUE'S SIGNEDNESS PICKS `addiu` vs `li`/`ori` (P31 S58b) L23331 +- **§235** — THE PHANTOM SYMBOL: A MASKED `MATCH` CAN CARRY A RELOCATION THAT DOES NOT EXIST (P31 S58b) L23372 +- **§236** — THE DECLARATION LAYER IS THE DOMINANT BANK-BLOCKER: NINE WAYS A BYTE-PERFECT BODY FAILS THE GATE (P31 S58b) L23401 +- **§237** — THE CAST-AT-CALL-SITE DECISION TABLE: WHAT §17a-1 FIXES, WHAT IT CANNOT, AND THE FOUR ESCAPES (P31 S58b) L23480 +- **§238** — SAME NAME, DIFFERENT FUNCTION: THE OVERLAY-HOMONYM TRAP (P31 S58b) L23535 +- **§239** — TWO-STATEMENT INTEGER-SPACE MATERIALISATION REORDERS `la` vs `sll`; AND THE PLUS-TREE OPERAND ORDER (P31 S58b) L23575 +- **§240** — `A + K + B`: WRITE THE CONSTANT **BETWEEN** THE TWO RUNTIME TERMS (P31 S58b) L23609 +- **§241** — THE FOLDED SIGN-EXTEND-AND-SCALE: `sll 16 ; sra (16 − log2 scale)` (P31 S58b) L23638 +- **§242** — `*k` vs `<>n`: EXPRESSION SPELLING OWNS THE LOAD WIDTH AND THE ROUNDING CHAIN (P31 S58b) L23667 +- **§243** — SPELL THE CSE BARRIER AS A REASSIGNED POINTER; AND THE `nop`-AFTER-EVERY-`lh` SIGNATURE (P31 S58b) L23695 +- **§244** — `volatile` IS A COUNTING INSTRUMENT, A STORE-ORDER PIN, AND MUST SOMETIMES BE ASYMMETRIC (P31 S58b) L23725 +- **§245** — THE CALL'S ARGUMENT LIST IS A SCHEDULING SLOT (P31 S58b) L23760 +- **§246** — THREE-LIVE-VALUE SCAN LOOPS WANT ADDRESS-FROM-INDEX; AND TWO SYMBOLS CAN SHARE ONE giv (P31 S58b) L23807 +- **§247** — TWO BRANCHES TO **ONE** LABEL MEANS THE SOURCE CONDITION IS NEGATED (P31 S58b) L23847 +- **§248** — SPLIT THE LOAD FROM THE ARITHMETIC: A FUSED `g + K` DENIES THE CALLEE-SAVED REGISTER ITS DIRECT HOME (P31 S58b) L23881 +- **§249** — THE SELF-ASSIGN, THE DEAD RE-ASSIGN, AND THE `+ zr` COPY: THREE WAYS TO MAKE A DELETED INSTRUCTION REAL (P31 S58b) L23905 +- **§250** — `%hi/%lo` vs `lw`: THE EXTERN'S ARRAY-vs-SCALAR SHAPE DECIDES ADDRESS MATERIALISATION (P31 S58b) L23947 +- **§251** — IMMEDIATE-SPELLING TRIGGERS: `+= 0xFF`, FULL-WIDTH `~K`, AND THE TWO-OR SPLIT (P31 S58b) L23984 +- **§252** — THE GUARDED PRE-DECREMENT: `(x != 0) && (--x == 0)` (P31 S58b) L24006 +- **§253** — POSTFIX `++` vs `+= 1` PICKS A DIFFERENT SCRATCH REGISTER **(single observation — not yet cross-confirmed)** (P31 S58b) L24027 +- **§254** — THE DEAD PARAMETER IS A REGISTER-PLACEMENT TOOL **(single observation — not yet cross-confirmed)** (P31 S58b) L24041 +- **§255** — THE EMPTY CASE, PART 2: FOUR TREE SHAPES IT BUYS (P31 S58b) L24053 +- **§256** — GOTOS IN THE TARGET'S BLOCK ORDER REPRODUCE SWITCH PLACEMENT WITHOUT SWITCH'S SIDE EFFECTS (P31 S58b) L24088 +- **§257** — THE DEAD-END LEDGER (P31 S58b): ELEVEN LEVERS THAT MEASURED NULL OR BACKFIRED L24125 +- **§258** — ADDENDA TO EXISTING SECTIONS (P31 S58b) L24168 +- **§30** — addendum (P31 S58b) — THE ANONYMOUS STRUCT MEMBER REF GRANTS `/s`, AND THAT IS A TWO-FOR-ONE L24173 +- **§194-B** — / §209 addendum (P31 S58b) — TWO MORE INSTANCES, AND THE BOUND IS NOW REFUTED FOUR WAYS L24194 +- **§202** — addendum (P31 S58b) — THE DEF-SIDE ALIAS ALSO CLEARS A RETURN+PARAM DOUBLE CONFLICT L24217 +- **§205** — addendum (P31 S58b) — CHAINED ASSIGNMENT: N≥3 IS INNERMOST-FIRST, AND THE TEXT MIRRORS EMISSION L24228 +- **§208** — addendum (P31 S58b) — IT SCALES TO SIX SITES, AND IT HAS AN EXACT INVERSE L24245 +- **§210** — addendum (P31 S58b) — THREE CONFIRMED SPELLINGS OF THE BOOLEAN TAIL L24274 +- **§211** — addendum (P31 S58b) — INIT PLACEMENT: FIVE MORE DIALS BEYOND THE GUARD HOIST L24290 +- **§213** — addendum (P31 S58b) — THREE MORE PERMUTATION LAWS FOR INDEPENDENT SAME-BASE STORES L24333 +- **§214** — addendum (P31 S58b) — FOUR MORE WAYS A HIGH-SIMILARITY TWIN LIES L24362 +- **§215** — addendum (P31 S58b) — PIN ECONOMY, PART 2: NINE REFINEMENTS L24398 +- **§217** — CROSS-CONFIRMED (P31 S58b) — AND THE INCOMING HOME SLOT IS THE MIRROR L24450 +- **§220** — addendum (P31 S58b) — THE PARAMETER, NOT A COPY (SEVEN CARDS) L24467 +- **§222** — addendum (P31 S58b) — IF-CHAIN vs SWITCH: THREE MORE DISCRIMINATORS L24492 +- **§223** — addendum (P31 S58b) — FIVE MORE CONFIRMATIONS, AND THE CONSTANT-IN-`$v0` CASE L24510 +- **§224** — addendum (P31 S58b) — CROSS-JUMP MERGES *CALLS*, AND THE DELAY SLOT IS THE DISCRIMINATOR L24534 +- **§225** — addendum (P31 S58b) — THE GUARD-CLAUSE FINGERPRINT, AND THREE MORE SHAPES L24564 +- **§226** — addendum (P31 S58b) — THE FRAME CATALOGUE: SEVEN MORE LEVERS, AND SLOT ORDER IS DECLARATION ORDER L24591 +- **§229** — addendum (P31 S58b) — NAME IT **INSIDE** THE ARM L24636 +- **§230** — CROSS-CONFIRMED (P31 S58b) L24647 +- **§231** — addendum (P31 S58b) — FOUR MORE WAYS THE LISTING MISLEADS L24656 +- **§232** — CROSS-CONFIRMED (P31 S58b) L24687 +- **§259** — THE DISCARD LEDGER FOR THE aa–bg HARVEST (P31 S58b): WHAT WAS MINED AND REJECTED, AND WHY L24698 +- **§260** — THE §154-A LEADING-ISLAND SPLIT: ONE CONFIG LINE, AND THE ISLAND PEELS FROM THE END (P31 S59, byte-proven) L24737 +- **§260-A** — STAGE 2 IS PROVEN, AND THE WHOLE jtbl PIPELINE IS AUTOMATED AT THE GATE (P31 S59, same day) L24787 +- **§261** — THE -O0 ORACLE: DERIVE THE OPT LEVEL FROM THE TARGET, AND `$fp` IS NOT THE TELL (P31 S59) L24823 +- **§261a** — THE -O0 FRAME-RELOAD GRAMMAR: reload COUNT disambiguates the C spelling (P31 S59, byte-proven) L24849 +- **§262** — A LANE'S YIELD IS ONLY A LANE FACT IF IT IS SIZE-MATCHED (P31 S59) L24871 +- **§263** — A STOLEN DELAY SLOT WHOSE INSTRUCTION IS AN ARG-REGISTER COPY IS AN ARITY ERROR, NOT A SCHEDULE (P31 S59, byte-proven) L24901 +- **§264** — FOUR TELLS-LANE C RECIPES, EACH DRIVEN TO MATCH (P31 S59) L24942 +- **§265** — THE VERBATIM-ASM BANK LANE: A FUNCTION NO -O2 C CAN EVER MATCH BANKS AS A RAW `__asm__` BODY (P31 S59b; two banked cards, two in-tree precedents) L24992 +- **§266** — THE INERT-RIDER LAW: A LEVER IS ONLY CITABLE WHEN ITS SOLO REMOVAL BREAKS THE MATCH (P31 S59b; measured 4-of-8 on this batch) L25054 +- **§267** — ADDENDA HARVESTED FROM WAVES at/bh/bk/bl (P31 S59b) L25094 +- **ADD-1** — → §231 addendum (also cross-ref from §195-D) — THE MASKED-`jal` "MISSING CALL" ILLUSION L25102 +- **ADD-2** — → §42a addendum — A SHARED CONSTANT *NAMED IN A LOCAL* ACROSS A `jal` IS AN ISO→TU DRIFT HAZARD; WRITE BARE LITERALS L25111 +- **ADD-3** — → §236, item 10 — THE UN-DELETED `INCLUDE_ASM` STUB IS A DUPLICATE DEFINITION L25123 +- **ADD-4** — → §225-3/-4 addendum — THE MIRROR ROW: VALUE-RETURN IN THE *TAKEN* ARM + TRAILING BARE `return 0` L25133 +- **ADD-5** — → §1/I1 addendum — THE INVERTED RANGE TEST: `(u32)(x-lo) >= N` WITH THE ZERO-ARM AS THE TRAILING `else` L25147 +- **ADD-6** — → §172b-1 / §264 addendum — SHIFT-AS-TEST: `(x << 16) != 0` TESTS THE LOW HALF WITHOUT TRUNCATING THE PSEUDO L25156 +- **ADD-7** — → §256 addendum — THE SINGLE-GUARD GOTO: THEN-BLOCK OUT OF LINE AT THE TAIL L25165 +- **ADD-8** — → §245 addendum — THE RE-TIE BARRIER PINS CALL-ARG SETUP TO SOURCE ORDER (construct 6) L25177 +- **ADD-9** — → §213-3 / §217 addendum — ADJACENT PRE-CALL FRAME STORES ARE ONE AGGREGATE; THE UNESCAPED SCALAR NEIGHBOR IS DEAD-STORED L25189 +- **ADD-10** — → §237 addendum (arity-evidence paragraph) — AN `la` PAIR ABOVE THE PROLOGUE `sw $ra` IS AN OUTGOING-ARGUMENT MATERIALISATION L25199 +- **ADD-11** — → Cross-confirmation card block (per §259's standing instruction: confirmation, not news) L25208 +- **§268** — A `register __asm__` PIN ON A CALL-CLOBBERED REGISTER IS HONORED EXACTLY WHEN THE PINNED RANGE CROSSES NO CALL (P31 S59c; three A/B'd cards, unifying §257-2's two) L25259 +- **§269** — ADDENDA HARVESTED FROM WAVES ax/bm (P31 S59c) L25313 +- **ADD-1** — → §257-8 addendum — THE INTERPOSED ASM'S `__volatile__` IS A PER-SHAPE DIAL, AND THE "NO-OUTPUT ASM IS IMPLICITLY VOLATILE" LORE IS BYTE-FALSE IN gcc-2.7.2 L25328 +- **ADD-2** — → §236 addendum (item 1 corollary) — THE SILENT-SPLICE DECLARATION LADDER: WHERE THE TU HAS NO SPELLING, UNPROTOTYPED `()` BEATS THE FLEET VOTE L25341 +- **ADD-3** — → §238 addendum — TWO BINARIES CAN EACH DEFINE THE SAME `func_` NAME WITH DIFFERENT BYTES, AND NO GENERATED REPORT SHOWS IT L25355 +- **ADD-4** — → §167-37 addendum — THE FIFTH PRECONDITION, NOW MEASURED: DOWNSTREAM FIELD RE-READS ⇒ NAME IT **AND** STORE **INSIDE** THE ARM L25368 +- **ADD-5** — → §267-ADD-6 / §172b-1 addendum — THE SIGN-TEST FACE: `(s16)v < 0` IS `sll 16` + `bgez` ON THE SHIFTED COPY, RAW STAYS LIVE — AND THE HALFWORD-ABS SHAPE NEEDS NO RITUAL L25385 +- **ADD-6** — → §220-addendum — THE FOURTH FACE: WHEN THE NAMED COPY ITSELF BUYS THE EXTRA CALLEE-SAVED, PIN THE COPY TO `$16` L25401 +- **ADD-7** — → §229 addendum — THE VALUE FACE: A LOOP-STORE CONSTANT SPELLED AS A LITERAL HAS NO SOURCE POSITION; NAME IT TO PIN THE PROLOGUE INIT ORDER L25417 +- **ADD-8** — → §30a addendum — THE THIRD COLUMN: `*p++` IS ALSO SERIALIZED BUT BURNS `addiu`; ONLY CAST-PLUS GIVES SERIALIZATION *AND* DISPLACEMENT FOLDING L25430 +- **ADD-9** — → §255 "AND CASE-BODY PLACEMENT" bound / §222-addendum-3 — ON A LARGE SPARSE TREE, BODIES FOLLOW **SOURCE** ORDER (measured by a one-word probe) L25445 +- **ADD-10** — → Cross-confirmation card block (per §259's standing instruction: confirmation, not news) L25459 +- **§3-1a.** — The §266 sweep — every solo-lever A/B run for this batch L25500 +- **§270** — The A-prop 0-bank anatomy: a byte-correct body still needs FOUR layers to agree (P31 S59) L25533 +- **§271** — Ordinal IMM pairing: text order is NOT emission order; emit CANDIDATES, let the oracle pick (P31 S59) L25551 +- **§272** — The `(void)`-decl + empty-call wall: K&R the DEFINITION, not just the decls (P31 S59) L25573 +- **§273** — A standalone compile is the WRONG oracle for a TU-destined draft (P31 S59) L25593 +- **§274** — ADDENDA HARVESTED FROM 18 WAVES (P31 S60): 315 candidates, 255 already covered, 21 sharpenings, 3 new laws L25608 +- **ADDENDUM** — to §179-C — the `.type NAME, @function` requirement L25614 +- **ADDENDUM** — to §134 — a typedef defined BELOW the splice point is stripped anyway L25661 +- **ADDENDUM** — to §179-D (GTE macro reference family) — `gte_SetRotMatrix`/`gte_SetTransMatrix` bodies L25691 +- **ADDENDUM** — to §82 — struct copies must stay MEMBER-WISE, not block-moved, to match a spill-slot save L25717 +- **ADDENDUM** — to §136d-1 (RC-12, the `$0`-add / opaque-copy family) — two symptoms beyond "compare reads the wrong register" L25755 +- **ADDENDUM** — to §20 — a global declared as `T *` may itself BE the array base, not a pointer to dereference L25794 +- **ADDENDUM** — to §1-I5 L25823 +- **ADDENDUM** — to §164-51 L25888 +- **ADDENDUM** — to §176-F5 L25904 +- **ADDENDUM** — to §225 L25933 +- **ADDENDUM** — to §224 — CROSS-JUMP: THE DUPLICATE CAN BE A PLAIN STORE, NOT ONLY A CALL L25978 +- **ADDENDUM** — to §164-64 — AN EMPTY CLOBBER ON AN ARGUMENT REGISTER CAN BE THE DELIBERATE FIX, NOT JUST THE ACCIDENTAL BUG L26012 +- **ADDENDUM** — to §244 — THE COMPILER BARRIER, NOT `volatile`, BLOCKS A STORE→LOAD HOIST THROUGH A POINTER-OFFSET FIELD L26043 +- **ADDENDUM** — to §172b-1 — TWO PLACEMENT DIALS THE PROMOTION LAW DOESN'T NAME: NARROW THE COUNTER'S DECLARED TYPE, AND MOVE THE CAST INTO THE LOOP BODY L26074 +- **ADDENDUM** — to §229 — A POINTER'S NUMBER OF USES DECIDES WHETHER ITS ADDRESS FOLDS OR SURVIVES A CALL L26121 +- **ADDENDUM** — to §172b-4 — THE PLAIN CAST-DIVISION ALREADY PRODUCES THE PATTERN; DON'T HAND-ROLL THE BIAS, AND KEEP THE OPERAND WIDE L26166 +- **ADDENDUM** — to §8 — WHEN `INCLUDE_RODATA` NEEDS A STANDALONE `.s` YOU CAN'T CREATE, CARRY THE FRAGMENT AS A FILE-SCOPE `__asm__` BLOB L26196 +- **ADDENDUM** — to §226 — A DEAD LOCAL SCOPED TO A NESTED BLOCK BUYS A MID-FUNCTION `addiu sp` PAIR, NOT A FRAME-SIZE CHANGE L26239 +- **ADDENDUM** — to §172a — RE-READING MEMORY (NOT NAMING A TEMP) IS WHAT KEEPS AN INCREMENT'S DELAY-SLOT FILL ALIVE L26278 +- **ADDENDUM** — to §225 / §256 — A GOTO TO A SHARED SET-POINT PREVENTS IF-CONVERSION FROM COLLAPSING A LATER BRANCH TEST L26309 +- **ADDENDUM** — to §211 — AN IN-LOOP ACCUMULATOR WANTS A CLOSED-FORM EXPRESSION WHEN THE TARGET REMATERIALISES ITS CONSTANT AFTER EVERY CALL L26351 +- **§275** — THE LEFTOVER-REGISTER READ L26386 +- **§276** — MIXED ADDRESS-EXPRESSION SPELLING FOR ADJACENT RELOCATABLE SYMBOLS IS A CSE-UNIFICATION DIAL, NOT JUST A BYTE-ENCODING CHOICE (P31 S60; `func_80180FE8`, ov_SC06_006, byte-proven) L26426 +- **§277** — RETURN-TAIL C SPELLING PICKS THE DELAY-SLOT-FILL vs TRAILING-MOVE TOPOLOGY, AND A NARROWER SECOND VARIABLE KEEPS TWO PSEUDOS INSTEAD OF ONE (P31 S60; `func_801846F0` ov_SC03_104, `func_801A44C4` md_SC07_004, both byte-proven) L26535 +- **§278** — ADDENDA HARVESTED FROM WAVE cf (P31 S60): 34 candidates, 13 already covered, 8 sharpenings, 4 new laws L26599 +- **ADDENDUM** — to §74 (func_800D0E30, resident) L26607 +- **ADDENDUM** — to §172b-4 (func_80185054, ov_SC03_097) L26643 +- **ADDENDUM** — to §265 (func_8017DC80, ov_SC07_002) L26681 +- **ADDENDUM** — to §17 (func_800CB794, md_MAIN_036) L26720 +- **ADDENDUM** — to §162p (func_8017C120, ov_MAIN_012) L26768 +- **ADDENDUM** — to §20 (~L1947) (func_80186AD0, ov_SC06_032) L26802 +- **ADDENDUM** — to §164-56 (func_8017F644, ov_SC04_005) L26832 +- **ADDENDUM** — to §237 (func_8017F7FC, ov_SC03_092) L26867 +- **§279** — A `do/while (p < end)` LOOP UNDER AN ENTRY GUARD: the guard decides the compare, not the loop (P31 S60; wave cf, func_8017F2A4, ov_SC03_096, byte-proven) L26896 +- **§NNN** — A DO-WHILE'S GUARD AND LATCH MUST REPEAT THE SAME BOUND EXPRESSION, NOT SHARE ONE LOCAL: THE REPETITION IS WHAT BUYS THE CSE'D COPY INTO A SECOND REGISTER (P31 S60; `func_8017F2A4`, ov_SC03_096, byte-proven 25/25) L26897 +- **§280** — THE CURSOR'S DECLARED TYPE PICKS `sltu` vs `slt`: a `T*` bound test is UNSIGNED by C rule, an integer cursor is signed (P31 S60; wave cf, func_800CAE74, md_MAIN_031, byte-proven) L26930 +- **§NNN** — A LOOP CURSOR'S C TYPE (POINTER vs PLAIN INTEGER) SELECTS `sltu` vs `slt` FOR ITS BOUND TEST, INDEPENDENT OF THE VALUES INVOLVED (P31 S60; `func_800CAE74`, md_MAIN_031, byte-proven; cross-confirmed same wave by `func_8017F2A4`, ov_SC03_096) L26931 +- **§281** — GROUP COPY-THEN-RMW BY OPERATION KIND, NOT FIELD BY FIELD: sched1 does the interleaving, the source must not (P31 S60; wave cf, func_80180FB4, ov_SC03_111, byte-proven) L26964 +- **§NNN** — A DEPENDENT COPY-THEN-RMW BLOCK MUST BE SOURCE-GROUPED BY OPERATION KIND, NOT BY FIELD, AND SCHED1 DOES THE INTERLEAVING (P31 S60; `func_80180FB4`, ov_SC03_111, byte-proven) L26965 +- **§282** — gcc's OWN LOOP REVERSAL PUTS THE COUNTER INIT AFTER THE HOISTED MOVABLES — a position no hand-written down-count can reach (P31 S60; wave cf, func_80180DD8, ov_SC04_005, byte-proven) L27010 +- **§NNN** — WRITE THE UP-COUNT LOOP: gcc's OWN REVERSAL PRODUCES A COUNTER-INIT INSTRUCTION THAT LANDS AFTER HOISTED MOVABLES, WHICH A HAND-WRITTEN DOWN-COUNT LOOP CANNOT REPRODUCE (P31 S60; `func_80180DD8`, ov_SC04_005, byte-proven) L27011 +- **What** — I could not verify L27048 +- **§283** — ADDENDA HARVESTED FROM THE 36-WAVE BATCH (P31 S60): 1,216 candidates, 859 already covered, 46 sharpenings, 9 new laws L27095 +- **ADDENDUM** — to §164-75 — the fold-reassociation law also fires at a variable's INITIALIZER, not only a later expression L27105 +- **ADDENDUM** — to §21 — the `bltz`+`slti` (or N-separate-compares) signed-range-split bullet is now CONFIRMED on three independent functions, and generalizes beyond `lbu`/u8 L27131 +- **ADDENDUM** — to §202 — the DEF-SIDE ALIAS also resolves a function-vs-DATA-symbol identifier clash, not only a function-vs-function prototype clash L27177 +- **ADDENDUM** — to §22 (`volatile`-qualified-global reload lever, cookbook ~L1922) — for a NON-constant, same-address double RMW, a plain memory clobber beats `volatile`, and `volatile` actively breaks a delay-slot fill L27200 +- **ADDENDUM** — to §195-E — a goto-ladder's STORES must sit AT the labels, after the gotos, not inline before them L27219 +- **ADDENDUM** — to §195-N — a GNU statement-expression slider must sit INSIDE the conditional arm's value position, not as a post-hoc barrier, to block the store-flag transform on a ternary chain L27281 +- **ADDENDUM** — to §176-B2 — in a micro-function with no long/short lifetime asymmetry, BOTH contending pseudos need their own hard-register pin L27338 +- **ADDENDUM** — to §199-G — A `default:` LABEL GROUPED ONTO THE LAST CASE REMOVES THE `j default` TAIL, EVEN THOUGH THE 2-NODE HEADER STAYS ALL-POSITIVE L27385 +- **ADDENDUM** — to §220 — REFERENCING THE RAW PARAMETER (NO NAMED COPY, NOT EVEN A PIN) LETS THE CALLEE-SAVED SPILL LAND IN THE FIRST CALL'S OWN DELAY SLOT L27454 +- **ADDENDUM** — to §252 — a `>=0`/`<0` split on an unconditionally-decremented value needs the POSTFIX operator INSIDE the branch condition, not a prior statement L27512 +- **ADDENDUM** — to §215 — FIFTH SHAPE: reused mask constants across two call-free merge sites each get their own whole-function hard-register pin, and a shared sub-expression at the second site must be its own statement L27539 +- **What** — I could not verify L27622 +- **Harness-defect** — flags L27693 +- **ADDENDUM** — to §167-40 (func_8017E2CC, ov_SC04_015 — wave dg) L27786 +- **ADDENDUM** — to §20's cross-jump EXPLOIT bullet (func_8017E360, ov_SC05_007 — wave dg) L27806 +- **ADDENDUM** — to §87 (func_801815F4 ov_SC06_032; corroborating func_801840DC ov_SC05_017, func_80189C68 ov_SC03_006 — wave dg) L27820 +- **ADDENDUM** — to §153 / §236-5 (func_801A419C, md_SC07_003 — waves di and dl, corroborating; refutes a contradicted dj-wave card) L27839 +- **ADDENDUM** — to §263 (func_801E83AC, md_SC04_029 — wave dj) L27859 +- **ADDENDUM** — to §265 (func_8017D878, ov_SC03_107 — wave dj; corroborated by a REJECTED, contradicted card in wave dm — see closing) L27873 +- **ADDENDUM** — to §6 (func_801811F0, ov_SC03_102 — waves dj and dl, corroborated by a self-reported "nothing new" dm-wave card) L27887 +- **ADDENDUM** — to §195-G (func_80183BB0, ov_SC05_001 — wave dj) L27901 +- **ADDENDUM** — to the zero-byte-asm-slider family (§47 / §148-C / §153) (func_800CB874, md_MAIN_040 — wave dj; open tension with a more cautious dm-wave card — see closing) L27929 +- **ADDENDUM** — to §194-B (func_8017EB34, ov_SC03_117 — wave dk; distinct from the §74 co-pinning finding on the SAME function below) L27947 +- **ADDENDUM** — to §74 (func_8017EB34, ov_SC03_117 — counter/clamp variant; wave dj, corroborated by dk/dl/dm cards on the same function) L27979 +- **ADDENDUM** — §37 — merged into the §153/§236-5 entry above (func_801A419C, wave dl) L27999 +- **ADDENDUM** — §6 — merged into the §6 entry above (func_801811F0, wave dl) L28007 +- **ADDENDUM** — to §238 (func_80182CB4, ov_SC02_000 — wave dl) L28015 +- **ADDENDUM** — to §137a (func_801684B4, ov_MAIN_012; corroborated independently by func_80189E68, func_8017FF9C, func_801822B4, func_8018DA8C — wave dl) L28033 +- **ADDENDUM** — to §8c / §88d (func_8016AB6C, ov_MAIN_012 — wave dm) L28049 +- **ADDENDUM** — to §73 / §30#2 (func_800D1984, resident — wave dm) L28063 +- **What** — I could not verify L28079 +- **ADDENDUM** — to §174 Law 4 (func_8017E9A8, ov_SC06_015) L28099 +- **ADDENDUM** — the zero-emission-asm family gains a REF-SLIDER PLACEMENT LAW and a paired RESTORER (func_800CB900, md_MAIN_026) L28139 +- **From** — ck + cl + cm L28191 +- **ADDENDUM** — §NNN — sharpens §55a / §164-37 / §165-28 (switch-vs-tree cluster): A SHAPE THAT LOOKS LIKE A SWITCH DISPATCH CAN BE PLAIN NESTED `if`s WHOSE SHARED BODY WAS TRIPLICATED BY THE SOURCE AND THEN CROSS-JUMP-MERGED BACK DOWN L28197 +- **ADDENDUM** — §NNN — sharpens §167-13's boundary: CHAINING TWO IDENTICAL SIDE-BY-SIDE STORES INTO ONE C ASSIGNMENT STATEMENT IS A MID-BLOCK SCHEDULING-PRIORITY DIAL, NOT ONLY A STORE-ORDER SPELLING L28234 +- **ADDENDUM** — §NNN — sharpens §162a3/§60b: A `sll $v0,16 / sltiu $v0,1` ZERO-TEST OF A JUST-DECREMENTED HALFWORD IS A SIGNED-TEMP WIDTH TELL OUTSIDE ANY SWITCH/RANGE-TEST CONTEXT L28267 +- **ADDENDUM** — §NNN — sharpens §37/§124 (unspecified-parameter-list family): DERIVE A CALLEE'S ARITY LOWER BOUND FROM ITS OWN `.s` STACK-ARGUMENT READS, NOT FROM ANY SINGLE CALL SITE L28300 +- **ADDENDUM** — to §5a (func_80181F74, ov_SC03_112, wave cn) L28333 +- **ADDENDUM** — to §265 (func_8017E26C, ov_SC04_016, wave cn) L28383 +- **ADDENDUM** — to §42b (func_8018247C, ov_SC07_002, waves cu + cw) L28421 +- **ADDENDUM** — to §199-F family (func_8017EFB0, ov_SC02_021, wave cu) L28452 +- **ADDENDUM** — to §195-E (func_800CFC1C, md_MAIN_003, wave cv) L28507 +- **ADDENDUM** — to §215 addendum (func_800CB2C8, md_MAIN_033, waves cv + cw) L28552 +- **ADDENDUM** — to §236 item 4 (func_8017D268, ov_SC04_006, wave cw) L28608 +- **What** — I could not verify L28637 +- **Harness-defect** — flags (not idioms — flagged for the operator) L28669 +- **ADDENDUM** — to §250 (func_8017D7CC, ov_SC03_115 — cx/cy/cz/dr) L28710 +- **ADDENDUM** — to §225 (func_8017E190, ov_SC03_115 — cx/cy/cz) L28755 +- **ADDENDUM** — to §45-A (func_8017F6A4, ov_SC02_016 — cy/cz) L28808 +- **ADDENDUM** — to §249 (func_80182ED4, ov_SC04_004 — dp/dr/dt) L28852 +- **ADDENDUM** — to §199-A (func_801816FC, ov_SC02_005 — dp/dr/dt) L28897 +- **What** — I could not verify L28943 +- **Harness-defect** — flags L28986 +- **§284** — COMBINE CAN REASSOCIATE TWO SEQUENTIAL BITWISE-AND MASKS INTO ONE AGAINST THE PRE-MASK VALUE; AN ASM IN/OUT FENCE RIGHT AFTER THE FIRST MASK BLOCKS IT (P31, wave dd, `func_8018087C`, ov_SC04_020, byte-proven) (P31 S60; waves #, byte-proven) L29048 +- **§285** — PRE-INITIALIZING A VARIABLE WITH A SHARED CONSTANT BEFORE A BRANCH MAKES BOTH ARMS OF THE FOLLOWING if/else DESTRUCTIVELY REUSE THE SAME DESTINATION REGISTER FOR THEIR BITWISE RESULT (byte-proven; `func_801811F0`, ov_SC03_102, independently rediscovered across waves di/dj) (P31 S60; waves #, byte-proven) L29052 +- **§286** — FOLD A STATEMENT'S SIDE EFFECT INTO A COMMA-EXPRESSION IN AN ARGUMENT POSITION TO PLACE ITS RTL RELATIVE TO A CALL'S OWN DELAY SLOT (P31 S60/dj; `func_80180A88`, ov_SC06_010, byte-proven 411/411) (P31 S60; waves #, byte-proven) L29056 +- **§287** — A STACK-FRAME HOLE BELOW TWO ADDRESS-TAKEN AGGREGATE LOCALS IS A LEADING PAD MEMBER OF ONE COMBINED STRUCT, NOT SEPARATE LOCALS OR A REGISTER PIN (P31 S60/dj; `func_8017D104`, ov_SC06_027, byte-proven 47/47) (P31 S60; waves #, byte-proven) L29060 +- **§288** — A REGISTER PIN DECLARED UNINITIALIZED AND ASSIGNED ONLY AT ITS LATE, SOLE USE STILL FORCES THE FIXED REGISTER'S SAVE/RESTORE, AND THE ASSIGNMENT'S SOURCE POSITION CONTROLS WHERE THE VALUE MATERIALIZES (P31; `func_80186530`, ov_SC02_017, byte-proven, match_one MATCH re-verified) (P31 S60; waves #, byte-proven) L29064 +- **§289** — an array local's address-taken base keeps every element's store alive, even though only one pointer escapes (`func_80189EFC`, ov_SC04_011) (P31 S60; waves #, byte-proven) L29068 +- **§290** — A SINGLE STRENGTH-REDUCED GIV CAN DRIVE STORES TO SEVERAL DISTINCT RELOCATABLE SYMBOLS, EACH KEEPING ITS OWN `%hi`/`%lo` ANCHOR (P31 S60; waves #, byte-proven) L29072 +- **§291** — THE DELAY-SLOT FALSE-VALUE: A CONDITIONAL BRANCH'S ZERO ARM MUST BE A FALL-THROUGH-ADJACENT BLOCK ENDING IN AN EXPLICIT JUMP, OR REORG CANNOT MATERIALIZE IT INSIDE THE BRANCH'S OWN DELAY SLOT (P31 S60; waves #, byte-proven) L29076 +- **§292** — DECLARING A SYMBOL UPSTREAM OF AN ALREADY-BANKED SIBLING THAT RELIES ON THAT SYMBOL'S IMPLICIT (K&R) DECLARATION CAN SILENTLY REPROTOTYPE THE SIBLING'S OWN CALL SITE (P31 S60; waves #, byte-proven) L29080 +- **§293** — THE "WHOLE-OBJECT GATE NEEDS EVERY SIBLING" LAW, WRITTEN PROPERLY: IT IS THREE LAWS, AND THE LOAD-BEARING ONE IS "THE BASELINE, NOT THE SIBLINGS" (P31 S61; byte-proven on 15 binaries in one night) L29083 +- **§294** — ADDENDA HARVESTED FROM THE S61 GEN0/MAXTOK/MAIN/DEEPSEEK BATCH (waves ab8/ab16/ab24/ab32 · g0a–g0f · m0a · ds1/ds2): 99 candidates, 52 covered, 15 notes → 10 addenda, 29 notes → 5 new laws (§295–§299), 3 refuted L29133 +- **ADDENDUM** — to §127 — the -O0 constant-offset fold keys on the MEMBER-ACCESS tree shape, not on the index being constant L29144 +- **ADDENDUM** — to §261a — FOUR MORE -O0 DIALS BEYOND THE RELOAD COUNT (boot.c + md_MAIN_011/003, wave m0a/g0a/g0f, byte-proven) L29172 +- **ADDENDUM** — to §264-3 — the explicit entry copy's BOUND: required exactly when the RAW value must outlive the call that consumes only the PROMOTED value L29222 +- **ADDENDUM** — to §172b-1 (counter-type dial) — the sll's SOURCE REGISTER is the placement discriminator L29242 +- **ADDENDUM** — to §276 — the SHARE direction: spell the second adjacent symbol RELATIVE to force ONE anchor L29254 +- **ADDENDUM** — to §31's density-dummy dial (L2460/L2497) — the dose is TWO refs, and the dummy must sit where the loser is live-through L29270 +- **ADDENDUM** — to §282 — the ADDRESS-GIV face: write the walked address INLINE so strength reduction births the induction register at loop.c's own insertion point L29287 +- **ADDENDUM** — to §253 — SECOND byte-proven card (upgrade from single-observation), and the placement face: postfix-in-condition parks the RMW store in the branch delay slot L29310 +- **ADDENDUM** — to the L1800 anchor-steer bullet — a DERIVED-POINTER local silently flips the merged giv's anchor END L29331 +- **ADDENDUM** — to §31's asm→layout inference — TWO WIDTH-PAIR DISCRIMINATORS (same offset, different widths) L29354 +- **§295** — THE KERNEL-TRAP STUB: §81's jr-DETECTOR WITHOUT A TABLE IS A PsyQ SYSCALL TRAMPOLINE — ROUTE TO §265, NEVER INTO THE CARVE CHAIN (P31 S61; wave m0a, 9 cards byte-proven; resolves §182's held cluster) L29375 +- **§296** — THE FRAME CHECK OUTRANKS THE ATLAS LEVER: READ PROLOGUE/EPILOGUE BEFORE DRAFTING ANY C — A REAL TELL CAN LIVE INSIDE AN UNREACHABLE FRAGMENT (P31 S61; wave m0a, 16 cards byte-proven; extends §179-C) L29430 +- **§297** — ONE GIV SERVING MIXED-WIDTH LOADS *AND* A STORE NEEDS STRUCT-MEMBER SPELLING; CAST/INDEX SPELLINGS RE-SPLIT THE PSEUDO (P31 S61; wave m0a, `func_800347C8`, main, byte-proven 31/31) L29473 +- **§298** — THE SHARED-TAIL POSITION DIAGNOSTIC: A FOLDED TAIL *BETWEEN* SWITCH ARMS MEANS PER-ARM DUPLICATED STATEMENTS, NOT A HOISTED POST-SWITCH STATEMENT (P31 S61; waves g0e/g0f, `func_80181B68`, ov_SC06_016, byte-proven 68/68) L29516 +- **§299** — TWO INDEPENDENT EXTRACTION CHAINS EMIT CONTIGUOUSLY INSIDE ONE EXPRESSION; ONLY A STATEMENT BOUNDARY MAKES THE SCHEDULER INTERLEAVE THEM (P31 S61; wave m0a, `func_8003A404`, main, byte-proven 8/8) L29541 +- **§300** — S61 DISTILL BATCH NOTES (waves ab8/ab16/ab24/ab32 · g0a–g0f · m0a · ds1/ds2 · m0b) L29576 +- **§301** — AN INTERNAL `j` CARRIES `R_MIPS_26 .text`: rtu/match_one "MATCH" COULD NOT SEE WHICH LABEL A `j` TAKES — FIXED (`jrel`), AND THE TWO DRAFT SHAPES IT HID (P31 S62 T1; byte-proven 2/2, negative-controlled over 3,297 stubs) L29645 +- **§302** — A RED BINARY IS A DRIFTED SPEC, NOT A MYSTERY: THE THREE CARVE-STATE INVARIANTS AND HOW TO DERIVE EACH FROM THE BYTES (P31 S62 T2; five reds healed in one session, 5/5, +39 held banks) L29693 +- **§303** — MODULE ISLAND TABLES: DERIVE THE PADS AT BUILD TIME, PEEL NOTHING — THE §154-A/§260 "island-pads"/"island-blocked" WALLS DISSOLVE (P31 S62 T3a; byte-proven md_SC03_076 func_801F0A9C + func_801F0F28, sha 9a165e36…) L29737 +- **§304** — SELF-DEFINING RODATA: WHEN A FUNCTION'S `.s` IS THE ONLY OWNER OF THE DATA IT REFERENCES, THE C BODY MUST DEFINE IT (P31 S62 T3; byte-proven md_MAIN_011/func_800D04F4) L29773 +- **§305** — "CARVE-REFUSED" AT GATE TIME IS THREE NAMED, DETERMINISTIC CLASSES — NONE OF THEM A CARVE (P31 S62 T3; 28 resolver drafts autopsied 28/28) L29796 +- **§306** — A HAZARD `nop` IN FRONT OF A DIV-RESULT STORE IS A STATEMENT-ORDER DEFECT: THE INDEPENDENT TRAILING STATEMENT MUST BE WRITTEN *BEFORE* THE DIVISION-CONSUMING ONE (P31 S62 T4; byte-proven func_8017E7D0) L29848 +- **§306a** — T4 DISTILL ADDENDA (P31 S62; four byte-proven refinements to existing laws, verified against the book by an independent verifier; each names its parent §) L29875 +- **§307** — THE BRUTE-FORCE-THE-STATEMENT-ORDERS LEVER HAS A BOUND: A FAN-OUT COPY'S PRIORITY IS SCHEDULER-INTERNAL, AND NO SOURCE ORDER REACHES IT (P31 S63; byte-evidenced NEGATIVE result, main wave) L29913 +- **§308** — A NAIVE FINAL `goto` DELETES THE TARGET'S `j`+`nop`: SPELL THAT EDGE AS A TAUTOLOGICAL `if` SO cse FOLDS IT TO AN UNCONDITIONAL JUMP *AFTER* jump1's WINDOW HAS CLOSED (P31 S63 t5e-t5i; byte-proven func_80180808) L29957 +- **§308a** — A TWO-INSTRUCTION ARM STUB LAID *BEFORE* THE OTHER ARM AND REACHED ONLY BY A TRAILING `j` SURVIVES ONLY BEHIND A SHORT-CIRCUIT `&&` GUARD PLUS A SEPARATE RE-TEST; EVERY PLAIN if/else-if, GOTO-LADDER, NESTED-INVERTED-if AND 1-/2-NODE switch LETS jump1 INLINE IT (−2 ins) (P31 S63 t5e-t5i; byte-proven func_80180808) L29986 +- **§309** — A FRAME-ADDRESS EQUIVALENCE RIDES *THROUGH* A SKIPPABLE CONDITIONAL: POST-`if` STORES FOLD ONTO `$sp` UNLESS THE `if` SURVIVES jump1 AS A BARRIER-PRECEDED DIAMOND (P31 S63 t5e-t5i; byte-proven func_801812AC) L30020 +- **§310** — A TWO-OPERAND `subu`'s DESTINATION TIES ONLY TO THE OPERAND THAT IS BLOCK-LOCAL: SHARE *ONE* SIDE ACROSS BLOCKS TO CHOOSE WHICH OPERAND'S REGISTER IT LANDS IN (P31 S64 t5j-t5m; byte-proven func_8017F578) L30060 +- **§311** — A JOIN-BLOCK STORE CAN SWALLOW AN ARM'S LOAD-DELAY `nop`: WHEN ONE ARM'S VALUE COMES FROM A LOAD, DUPLICATE THE STORE INTO BOTH ARMS (P31 S64 t5j-t5m; byte-proven func_8017D7E0) L30091 +- **§312** — A BARE RELATIONAL IN AN `if` GIVES THE `slt` NO TARGET: ASSIGN THE COMPARISON INTO THE ALREADY-ALLOCATED VARIABLE TO CHOOSE ITS DESTINATION REGISTER, AT ZERO INSTRUCTION COST (P31 S64 t5o-t5r; byte-proven func_80180DCC) L30133 --- @@ -2439,810 +2443,811 @@ Notes routinely quote that as a section id. This table resolves it. Grep bait: ` | L2676 | §40c | The h_seq per-sibling reconcile: templating a reconcile-class crack ×134 (Phase 26 Task 8, | | L2693 | §31-triage | R17 applies to CODEGEN residuals, never to a compile ERROR (Phase 26 session 7, Drew asked | | L2710 | §41 | The DEF-SIDE canonical-sig wall: mechanically banking a drafted giant past `conflicting ty | -| L2754 | §41a | v3.1: the def-side wall was ~71% TOOL-shaped — the five measured defects + the laws that d | -| L2809 | §41b | T7 execution: the object-only probe OVER-counts BANKABLE by two link/rodata classes (Phase | -| L2839 | §41c | T7-M2: the ×134 def-side-wall sweep via per-sibling RE-reconcile (Phase 25, 2026-07-10; 4, | -| L2858 | §41b | addendum — M4 "reconcile_decls" tier is ALSO a probe over-count: 0/8 mechanical (Phase 25 | -| L2878 | §41d | `void`→`s32` is NOT always byte-neutral: gate the RAW draft FIRST (Phase 26 session 6, byt | -| L2900 | §42 | The F-band ≤28 regalloc crack wave: register-pin/DENSITY levers beat the permuter (Phase 2 | -| L2953 | §42a | addendum — wave 2 (residuals + 29-100 band): iso-MATCH ≠ real-TU bank, the memcpy→struct-a | -| L2994 | §42b | addendum — wave 3 (Max, 2026-07-10c): THE STALE-OBJECT GATE TRAP + the read-global `&`-cas | -| L3033 | §42c | addendum — wave 3 (Max orchestrator + CORRECTED Ultracode fan-out, 2026-07-10c): the real- | -| L3082 | §42d | addendum — wave 4 (rtu_match fan-out over the mapped frontier, 2026-07-10c): 24/26 MATCH, | -| L3121 | §42e | propagating a CRACK ×134: the def-finder bug + the byte-drift residual (the "remap-fail" m | -| L3195 | §43 | The K&R s16-param definition DISSOLVES the "narrow-param wall" for by-value register args | -| L3242 | §44 | The Phase-25 cheap-Opus giant batch: 5 structural levers + the §43 extension (2026-07-11, | -| L3298 | §45 | The flagship `func_80133CD4` crack (399 ins ×134): the merged-variable permutation-breaker | -| L3313 | §46 | The `func_80178D40` crack (890 ins ×134, the heaviest core in the game): four LOOP-STRUCTU | -| L3365 | §47 | The live-length SLIDER: splitting a global.c allocno-priority TIE with one zero-byte asm ( | -| L3405 | §48 | The 12-core jr crack wave: the ALLOCNO-PRICING dials and the EBB rule (Phase 26 session 8, | -| L3413 | §3-A. | ALLOCNO-PRICING DIALS — move a value into the register you want, byte-neutrally | -| L3444 | §3-A4 | SINK THE CONSUMER CALL INTO THE ARMS (the inverse of A1; `func_8016AB6C`, byte-proven) | -| L3468 | §3-B. | THE EBB RULE — the general form of §46-L2 | -| L3484 | §3-C. | TYPE- AND SHAPE-DRIVEN CODEGEN (the C type literally selects the addressing mode) | -| L3508 | §3-D. | THE CROSS-JUMP RATCHET (the sharpest new trap — `func_80131340` L-C) | -| L3518 | §3-E. | Meta | -| L3527 | §49 | The LUID DIAL: a zero-byte SCHEDULING dial (the sched.c analogue of §47) — `func_8017A4AC` | -| L3576 | §50 | Refinements that BOUND §47/§48 (from the `func_80135EB0` wall, 21→6; Phase 26 session 8) | -| L3630 | §51 | TOOLING INTEGRITY: the silent skip, and how to hunt it | -| L3636 | §51a | The bug class | -| L3652 | §51b | Why the byte-gate cannot save you | -| L3662 | §51c | THE METHOD (do not audit by reading the regex) | -| L3677 | §51d | THE LAWS | -| L3739 | §51e | The false-wall pipeline (why this is not just hygiene) | -| L3755 | §51f | Checklist for any new corpus-scanning tool | -| L3769 | §51g | When the thing you are scanning has a GRAMMAR, parse the grammar (`tools/cdecl.py`) | -| L3913 | §52 | The WALKER-FAMILY skeleton: 6 regalloc-order levers + a deeply-characterized intrinsic wal | -| L3924 | §3-The | 6 levers (the "walker-family skeleton" — apply to the 12 siblings; levers 1-5 retire ~half | -| L3945 | §3-Why | the wall is (probably) intrinsic | -| L3959 | §52a | The regalloc sibling wave: new levers + two new wall classes (cheap-Opus applying §52, 202 | -| L3997 | §52b | Sibling wave 2: more de-pin levers, a third wall class, and the match_one→whole-binary gap | -| L4028 | §53 | SWEEP A FAMILY WITH THE TOOL ITS EXEMPLAR NEEDED: the jr/switch carve, and how omitting it | -| L4033 | §3-The | case | -| L4045 | §3-Why | 0/8 was structural, and predictable from two words | -| L4062 | §3-The | rule | -| L4078 | §3-The | meta-lesson (R35, and why this one is expensive) | -| L4093 | §55 | Core-crack wave levers + the GATE-ORCHESTRATION law (Phase 29 T3, 13-agent ultracode wave, | -| L4098 | §55a | New byte-proven levers (each from a banked or near draft) | -| L4122 | §55b | THE GATE-ORCHESTRATION LAW (3 traps, ~3.5h lost; all recovered, 0 data lost) | -| L4141 | §55c | Sizing the propagate: a TARGETED propagate is ~4 min/core, and "it's slow" was a BROKEN-TR | -| L4163 | §54 | `--fix-def-sig`: the member's CANONICAL DECLARATION is a build step too (tiny-IMM mega-poo | -| L4187 | §56 | Banking a hand-drafted GIANT into its exemplar TU: self-contained draft vs live-TU decls, | -| L4232 | §56b | PROPAGATING an h_seq giant: the exemplar's externs MUST be fleet-canonical, not the draft' | -| L4256 | §57 | The SELF-decl normalize: the sibling's OWN caller declares the templated fn divergently (t | -| L4303 | §57a | Two NSD corrections + the SURGICAL-ONLY law + the honest broad-sweep yield (Phase 29, 2026 | -| L4343 | §58 | match_one MATCH ≠ BANK: the four blind spots + the crack-wave reconcile-before-bank law (P | -| L4377 | §59 | Three h_seq sweep-residual classes match_one/the-exemplar-bank don't reveal (Phase 29 crac | -| L4407 | §60 | Classify the residual, don't rank it: the deterministic residual→class classifier and what | -| L4431 | What | it measured — the whole open backlog, byte-grounded | -| L4450 | §3-Two | corollaries worth remembering | -| L4463 | §3-The | parallel-probe race this surfaced | -| L4472 | §60a | What the first DIRECTED grinder run exposed (Phase 29 Task-13B, 2026-07-21) | -| L4510 | §60b | The plateau autopsy's verdict: a `partial` drift is a WRONG DRAFT, not a missing transform | -| L4545 | §61 | Task 14: the gate ladder's missing stage is the ARITY pre-pass, and it is TU-side not draf | -| L4606 | §61a | The Task-5 wave: 11/12 MATCH, 0 banked — three DISTINCT integration walls, each now named | -| L4658 | §61b | The jtbl gate stage: built, and the ORDERING law it exposed (Phase 29 Task-14 stage 4, 202 | -| L4713 | §61c | The jtbl bank is INCREMENTALLY valid and CLEAN-INVALID (Phase 29, 2026-07-21) — the blocki | -| L4779 | §61d | The undo was eating the tree: two tools, one defect, invisible to the byte-gate (Phase 29, | -| L4833 | §62 | The jtbl RECONCILE must also follow the carve: the post-carve draft reconcile (`harvest_ve | -| L4877 | §63 | The fresh-138 DEF-SIDE blocker: fix the HEADER decl, not the draft (`fix_header_decl.py`, | -| L4908 | §64 | The §20 type-lift's three laws: fold the tagged typedef, check VISIBILITY, and strip only | -| L4957 | §64a | VARIANT types: UNIQUIFY the camps, do not reconcile them (`uniquify_type.py`, Phase 29 SES | -| L5000 | §63 | UPDATE (Phase 29 SESSION-14) — `fix_header_decl`'s "SAFE" verdict is FLEET-BLIND; it MUST | -| L5015 | §65 | The stranded-draft recovery: BLAST-RADIUS TIERS, and the per-overlay de-macroize that refu | -| L5030 | §65a | The blast-radius taxonomy (makes §61's law structural instead of remembered) | -| L5045 | §65b | The escape: de-macroize the instantiation, don't touch the shared header | -| L5081 | §65c | `rtu_match` MATCH → bank held 13/13 on self-decl, but broke on the FIRST callee-decl case | -| L5091 | §65d | Existing-ladder baseline, measured (do this before building a recovery stage) | -| L5101 | §65e | Two oracles, and the disagreement is the finding (R34 in practice) | -| L5118 | §65f | The de-macroize lever's BOUNDARY, measured: byte-neutral 14 times of 15, and the 15th is w | -| L5139 | §65g | Where the cheap levers STOP: the local-type and in-TU-self-decl classes did not yield | -| L5159 | §66 | Exercise a banking driver's SUCCESS path before pointing it at a wave: the free re-bank te | -| L5181 | §66a | The widest write in a pipeline is the one most likely to be UNDECLARED | -| L5200 | §66b | A metric parsed out of another tool's prose goes NULL silently when the label changes | -| L5217 | §66c | Before a wave, verify the FUEL exists; an "already attempted" set built from the wrong dir | -| L5245 | §66d | The permuter⇄reader loop: alternate a random search with a byte-verified idiom, and let `r | -| L5280 | §66d-1 | What transfers between giants is the LOOP, not the PIN | -| L5289 | §66d-2 | Two operational sharp edges | -| L5300 | §66d-3 | Read the ILS per-cycle SERIES, not its final best: a repeated score and a still-falling on | -| L5315 | §67 | The arg-copy PLACEMENT lever: launder a parameter into a fresh pseudo AT the statement whe | -| L5405 | §67a | Run the symbol-set guard BEFORE you pay for a gate (`tools/symcheck.py`, Phase 29 SESSION- | -| L5438 | §66d-4 | "ILS converged" means converged FOR THAT WEIGHT PROFILE, not a floor (amends §66d-3; Phase | -| L5491 | §66d-5 | `residual_class`'s "structural ⇒ permuter CPU is waste" is WRONG for schedule permutations | -| L5524 | §68 | A comment-only line halted the extern scan, and the skip label blamed the type cap (Phase | -| L5569 | §69 | How to attack a behemoth: map it, don't draft it (Phase 29 SESSION-18, `func_80183814`, 5, | -| L5619 | §70 | The giv-init base register: walk the PARAMETER, not a copy of it (Phase 29 SESSION-18, `fu | -| L5660 | §71 | Before mapping a giant, look for an already-matched SIBLING beside it (Phase 29 SESSION-18 | -| L5726 | §72 | A `register __asm__` pin is a PREFERENCE, not a reservation (Phase 29 SESSION-18, `func_80 | -| L5750 | §3-The | honest fix was source-level and cheap | -| L5760 | §3-Giv | record order (the §70 family) | -| L5766 | What | is left, and what is byte-recorded as SPENT | -| L5783 | §73 | A def-side self-decl conflict has TWO axes: RETURN (fleet widen, T2) and PARAMS (casts at | -| L5822 | §74 | Auditing a pinned draft: the §72 hazard is CALLER-SAVED pins spanning a call, and only the | -| L5866 | §75 | A propagation cap is usually a MINORITY-SPELLING SOURCE OVERLAY, not a wall: census the ca | -| L5925 | §75a | The exclusion classes, enumerated with named causes (Phase 29 SESSION-19, the 134-binary ` | -| L5948 | §75b | A body's preamble can carry `#define`s, not just `extern`s; extraction lifts only the exte | -| L5997 | §75c | Class-B's remedy is the FULL §17a-1 PAIR (decl **and** call-site cast); a decl-only fix mo | -| L6028 | §76 | The allocno CLASS (local vs global) is the dominant regalloc lever, and C reaches it ONLY | -| L6037 | §3-The | mechanism, with citations | -| L6057 | §3-The | attribution primitive (use this before calling anything a scheduling residual) | -| L6064 | §3-Two | diagnosis traps this function proved | -| L6074 | Practice | Practice | -| L6084 | §77 | Every extraction tool carries a NARROW hard-coded preamble set; anything outside it silent | -| L6124 | §3-The | CANDIDATE gate and the REAL gate need DIFFERENT preambles — keep the difference out of the | -| L6174 | §78 | A LENGTH drift can be a register grant in disguise; and `fold` never leaves a literal firs | -| L6180 | §3-The | drift was an allocation decision, not missing code | -| L6211 | §3-The | economics | -| L6220 | §79 | For a 0-callee giant, fingerprint by DATA symbols (§71 cannot fire); and the STACK-SLOT OR | -| L6226 | §71 | has a blind spot, and this is it | -| L6240 | §3-NEW | LEVER — the frame layout reads back the original declaration order | -| L6251 | §76 | confirmed at scale, and a pin nuance | -| L6260 | §3-The | residual, and the honest read | -| L6270 | §80 | A do-not-re-buy entry is scoped to its BASE, not to the function; and the pin's hidden cos | -| L6291 | §3-The | pin's hidden cost, with the citation | -| L6302 | §3-The | flagged "#1 move" LOST — and why the failure is informative | -| L6312 | §78 | 's attribution primitive, run and reproduced | -| L6318 | Cold-start | economics, now complete | -| L6323 | §81 | Banking a jr (jump-table) function: the 3-step carve chain, and why `match_one` cannot see | -| L6354 | §3-The | defect this exposed: a shared type that is present but invisible | -| L6370 | §82 | Two source-shape oracles from behemoth #6: a duplicated `addiu $aN,$sp,K` across a `jal` m | -| L6375 | §3-1. | The inlined-helper signature | -| L6389 | §3-2. | Scalar vs aggregate decides *when* the slot is allocated | -| L6401 | Also | reproduced on this function | -| L6405 | §3-And | the banking footnote (§75a class A, one line) | -| L6412 | §83 | The parameterised-repeat law, the spill-area trap, and why a per-case edit cannot move a p | -| L6419 | §83a | READ THE HEADLINE NUMBER CORRECTLY: a LENGTH drift makes `match_one`'s count meaningless | -| L6427 | §83b | THE LEVER: find the parameterised REPEAT before decoding case-by-case | -| L6445 | §83c | TRAP: a "dead local" in a prior draft may be gcc's OWN spill area | -| L6452 | §83d | CSE's quantity budget is WHOLE-FUNCTION, so a local rewrite cannot fix a local symptom | -| L6466 | §83e | §80 vindicated again, on the same day it was written | -| L6472 | §84 | The DERIVED-OFFSET remap bug: a hand-computed literal that encodes the DISTANCE between tw | -| L6477 | §3-The | construct | -| L6495 | §3-Why | it survived every candidate gate | -| L6510 | §3-THE | FIX IS MECHANICAL — the tool already holds the answer | -| L6518 | Scope | , measured (do not over-generalise — §80) | -| L6528 | §3-Two | ladder lessons banked with it | -| L6539 | §85 | The RETURN-axis fleet widen is ALL-OR-NOTHING: widening the shared header alone guarantees | -| L6544 | §3-The | conflict | -| L6552 | §3-THE | FAILURE MODE — widening only `engine_core.h` is worse than not starting | -| L6559 | §3-The | precondition, and how to check it in one grep | -| L6567 | §3-Do | the WHOLE axis in one edit, then R22 once | -| L6576 | Reading | , for the next person | -| L6589 | §86 | Pinned-exemplar templatability is a PER-FAMILY property, not a per-member rate; and the §4 | -| L6591 | §3-The | guard refuses a class that largely works | -| L6600 | §3-THE | LAW: all-or-nothing PER FAMILY | -| L6627 | §3-Why | the two live families differ from the three dead ones — the open question | -| L6633 | §87 | `match_one` COMPILES but never LINKS, so an unresolvable data symbol reads as MATCH; and s | -| L6649 | §3-The | blindness ladder, now complete — FOUR classes `match_one` cannot see | -| L6659 | Consequence | for the backlog ledger | -| L6666 | §3-The | cheap discriminator, before spending a sweep | -| L6674 | §88 | `cross_jump` will not merge a common suffix containing a CALL; and §78 is scoped to ORDERE | -| L6679 | §88a | repeated CALL-shaped blocks are left UNMERGED; call-free tails are merged for you | -| L6686 | §88b | the `slti` literal-position law (extends §78 to comparisons) | -| L6701 | §88d | BANKING ORDER: run the §81 carve chain BEFORE banking, never after | -| L6708 | §88e | a wrong diagnosis, refuted properly (the model for how to treat an inherited lever) | -| L6718 | §88f | the missing rung: a RELOCATION gate between `match_one` and the binary | -| L6726 | §89 | Two throughput rules the project already had written down and was not following (Phase 29 | -| L6732 | §89a | MEASURE the write set; do not assert its tier (`tools/blast_radius.py`) | -| L6745 | §89b | the parallel gate farm existed; the family path could not reach it (`tools/sweep_parallel. | -| L6758 | §3-The | standing sequence | -| L6766 | §90 | Five tool-integrity laws from one session, each of which changed an answer (Phase 29 SESSI | -| L6772 | §90a | A comparison tool MUST share its reference oracle's index space, exactly | -| L6789 | §90b | "Byte-neutral" is not "wanted": undo on the SUCCESS path too | -| L6799 | §90c | A library-callable function must FAIL CLOSED on an unconfigured module | -| L6810 | §90d | Do not measure a live wave's drafts (§87 in real time) | -| L6818 | §90e | An agent's CONCLUSION and its EVIDENCE fail independently — re-derive the premise, not the | -| L6842 | §91 | A structure-TRANSFER is only valid where the structure corresponds: the `--like` role trap | -| L6871 | §3-The | three-hypothesis trail, because two of them were wrong and the wrongness is instructive | -| L6891 | §92 | Conforming a DECLARATION: pointer changes are caller-neutral, scalar-WIDTH changes are not | -| L6922 | §93 | `set -o pipefail` attributes a pipeline failure to the LAST stage, not the failing one (Ph | -| L6947 | §94 | A family sweep's `0/N` is a TYPE-CARRY failure until proven otherwise: lift the exemplar's | -| L6983 | §95 | `reconcile_tu` dropped the SIBLING declarators of a multi-symbol `extern` line (Phase 29 S | -| L7018 | §96 | The same rewrite, one shape down: `reconcile_tu` matched statements to lines by TEXT, so e | -| L7066 | §97 | The gate's own tree hygiene: a refused carve, an unchecked recovery, and a snapshot that c | -| L7113 | §98 | `conform_decls` had three defects, and only the third needed R22 to find (Phase 29 SESSION | -| L7167 | §99 | The narrow-param wall is a DEF-side problem with a ZERO-blast-radius fix: convert the defi | -| L7190 | §3-Two | `reconcile_tu` bugs found underneath, one introduced while fixing the other | -| L7216 | §100 | Prefer the DRAFT-LOCAL fix: a type only one function uses belongs in its BODY, not in a sh | -| L7245 | §101 | The STALE DEFAULT class: a guard whose cause was removed is a silent skip wearing a safety | -| L7272 | §102 | A PLUMBING verdict can MASK a DIFF; and K&R is not always a codegen change (Phase 29 SESSI | -| L7307 | §103 | A FILE-scope `extern` in a shared overlay TU is a GLOBAL constraint on every LATER functio | -| L7395 | §104 | Two silent-skip defects in one scan: match on MASKED text, emit from the ORIGINAL (Phase 2 | -| L7431 | §105 | A gate's revert must survive an EXCEPTION, not just a failure (Phase 29 T53, `jtbl_family_ | -| L7470 | §106 | Persist the MEASUREMENT, derive the POLICY: a stored route let a stale file out-vote the l | -| L7513 | §107 | A lever wired into ONE gate path is a lever most families cannot reach (Phase 29 T56, `fun | -| L7551 | §108 | Diagnosing a family `0/N`: the four causes, and the third opt-in lever (Phase 29 T59) | -| L7600 | §109 | Conforming a definition to a shared header: fix the NAMES, then check the RETURN precondit | -| L7640 | §110 | A unit must define exactly ONE function, and "ends in `;`" does not tell you which line de | -| L7681 | §111 | The distinct-code metric is not noisy: a family pays it only if its members are byte-VARIA | -| L7730 | §112 | A macro-scoped declaration only collides where the macro is INSTANTIATED (Phase 29 T67/T69 | -| L7776 | §113 | An ARITY blocker only exists if the macro CALLS the function; an address-taken use has no | -| L7808 | §114 | The THIRD decl axis: a CALLEE the draft declares differently from the target TU (Phase 29 | -| L7850 | §115 | A `func_XXXXXXXX` predicate rots by design: the same name-form assumption in THREE places | -| L7877 | §116 | Optimization level is a property of the FILE, not the function: read a family 0/N against | -| L7895 | §3-The | fix moves the DEFINITION, not the stub — and here is why the obvious shortcut fails | -| L7926 | §117 | Spell the sibling's symbol from the SIBLING's address, not the exemplar's kind (Phase 29 T | -| L7953 | §3-Why | it survived so long: a MASKED oracle will MATCH a wrong symbol | -| L7963 | §118 | Ordinal (positional) immediate resolution: compare C tokens to the DIFFERING asm uses (Pha | -| L7997 | §119 | Two levers on the SAME axis, opposite directions: test the off-diagonal (Phase 29 T89) | -| L8026 | §120 | Uniquify draft-defined TYPE names; and check which of N staging sites you actually patched | -| L8037 | §3-Do | NOT "strip the duplicate typedef" — it breaks the extern that uses it | -| L8043 | §3-The | wiring trap that cost two attempts | -| L8061 | §121 | Synthesise externs for macro-DEFINED callees from the macro's own definition head (Phase 2 | -| L8084 | §122 | GATE RAW BEFORE TRANSFORMING; the undo belongs to the WRITER, as a per-edit journal (P30 T | -| L8116 | §123 | PROPAGATE A FAMILY WITH THE TOOL ITS TIER NEEDS: `dedup_propagate` is h_exact-only; its re | -| L8153 | §124 | A "not matched" verdict can mean the definition is there under a DIFFERENT C NAME: the asm | -| L8198 | §124a | a family sweep's `0 matched-exemplar families` may be a FILTER, not a wall | -| L8206 | §125 | Split the CARVE from the BODY before calling a jr residue a wall — and measure it by SHA f | -| L8213 | §3-The | method (keep this) | -| L8223 | §3-The | instrument rules that make its answer trustworthy (this is where I failed) | -| L8238 | §3-The | corrected results (each SHA-verified, from a clean tree, restore re-verified) | -| L8248 | §3-Two | further notes worth keeping | -| L8257 | §3-The | meta-lesson | -| L8264 | §126 | The carve-within-a-carve: an ADDRESS RANGE is not an OPTIMIZATION REGION (P30 T2, byte-pro | -| L8279 | §3-The | finding: opt level is per FILE, so the file's contents must be opt-HOMOGENEOUS | -| L8290 | §3-The | instrument trap that hid it (and it is §124's shape again) | -| L8299 | §3-The | mechanics | -| L8317 | §126a | a bare `except: continue` around a coverage-asserting oracle re-creates the silent skip (P | -| L8349 | §127 | The `-O0` regime: the CONSTANT-OFFSET FOLD, and why `-O0` needs its own idiom set (P30 T3 | -| L8356 | §3-The | idiom they kept re-deriving: the constant-offset fold | -| L8367 | §3-The | rest of the `-O0` regime (write PLAIN C, and mean it) | -| L8377 | §127a | §71 (sibling-first) is the strongest `-O0` lever, and it beats the index | -| L8386 | §127b | the knowledge was in a SOURCE COMMENT, not the cookbook | -| L8393 | §128 | A raw NUL in C source makes grep SILENTLY SKIP the file (P30 S28, 137 files) | -| L8425 | §128a | a negative control must corrupt a SCRATCH COPY, never the tracked file | -| L8437 | §129 | Post-carve, `rtu_match`/`match_one` COUNT THE JUMP TABLE AS INSTRUCTIONS; and a carve must | -| L8441 | §129a | the target instruction count is INFLATED after a carve | -| L8462 | §129b | never commit a carve whose owner is still a stub (it strands the carve) | -| L8477 | §3-The | real blocker underneath, for the record | -| L8486 | §130 | An INCREMENTAL build can report BYTE-IDENTICAL for a change the CLEAN build cannot even LI | -| L8523 | §3-The | diagnostic ladder that finally located it (reusable) | -| L8533 | §131 | The jtbl OVER-SPAN: `sltiu N` is ground truth in BOTH directions, and the zero-word rule o | -| L8570 | §132 | The `JR-PAIR-IN-ONE-O0-OBJECT` "wall" was TWO instrument defects: a merged-double span the | -| L8579 | Defect | 1 — a pre-§8e MERGED DOUBLE is not a single-table predecessor | -| L8597 | Defect | 2 — `as` writes a corpse and nothing deletes it | -| L8607 | §3-The | fingerprint, and the 30-second ladder that found it | -| L8628 | §3-The | transferable rule | -| L8635 | §132a | `--like` is for a sibling with NO record; against one that HAS a record it over-derives (P | -| L8660 | §132b | When the span's already-matched owner is ITSELF multi-switch: `--span-rel` (P30 S1, `func_ | -| L8685 | §133 | The DEFAULT-FILTER class: three times in one session, a tool silently answered a narrower | -| L8711 | §134 | MULTI-LINE BLINDNESS: one root cause, four faces, in `family_remap`'s preamble scanner (P3 | -| L8765 | §135 | Six byte-verified gcc-2.7.2 idioms from the P30 S6f-h waves (and the two-lane wave shape t | -| L8770 | §3-The | codegen idioms | -| L8804 | §3-The | integration idioms (these decide whether a byte-correct draft BANKS) | -| L8819 | §3-The | wave shape that produced these | -| L8837 | §136 | The LOCAL-VARIABLE lever: how many C locals, at what scope (P30 wave 4a, 25 byte-verified | -| L8853 | §3-The | splitting/merging rules (each closed a residual, byte-gated) | -| L8879 | §3-The | type-form rules | -| L8912 | §3-The | scheduling rules (refining §135-2 and §135-4) | -| L8941 | §3-The | declaration surface (integration, not codegen) | -| L8953 | Wave | economics (measured, for the next batch's sizing) | -| L8976 | §136a | Blocker capture: classify on the OUTPUT, never on the exit status | -| L9033 | §136b | A prior wave's "genuine byte-DIFF" verdict is NOT reliable evidence (4 of 4 refuted) | -| L9069 | §136c | SIBLING-FIRST is a DERIVATION shortcut, not just a conflict fix (the fastest route in a fa | -| L9094 | §136d | Four gcc-2.7.2 levers the redraft lane found (each closed a residual no other lever moved) | -| L9138 | §136e | §136c's PRECONDITION, and two more symptom keys (wave 4b batch 3) | -| L9186 | §136f | Two declaration sub-cases the reconcile lane surfaced (lane now 15/15 lifetime) | -| L9211 | §136g | When the index points at the WRONG lever: two byte-refuted routings (func_801863B4) | -| L9240 | §136h | CORRECTION: the zero-crack pool does NOT "refill with cheap work" (my error, byte-measured | -| L9270 | §136i | The drafter model LADDER: Haiku → **Sonnet** → Opus → Fable5 (Drew, 2026-08-03) | -| L9302 | §136j | The failure MIX flips with function size (measured across four bands, one session) | -| L9344 | §137 | REGALLOC-PERM is a TWO-COMPILE ARITHMETIC PROBLEM, not a permuter job | -| L9386 | §137a | A gate verdict has a TIMESTAMP; re-check it against the draft's mtime | -| L9415 | §138 | The propagation lanes: a gate refusal is a DECLARATION, and which lever you owe depends on | -| L9421 | §3-The | triage, cheapest first | -| L9473 | §3-The | DEFINITION-side alias is the only escape when the fleet canon disagrees on a promoting par | -| L9481 | Rank | the lane by measured concentration, not by class count | -| L9490 | THREE | carry variants hide in one "CARRY-FIXABLE" bucket — and they need different fixes | -| L9526 | §134 | again, in a second tool — and the waiter rule corrected | -| L9546 | STEP | 0 of sibling-first: grep `src/` for a distinctive LITERAL from the `.s` | -| L9565 | Reconciling | a gate-refused draft: which way you edit depends on WHERE the TU's decl is | -| L9594 | §139 | A GATE THAT GREPS FOR VERDICTS MUST ASSERT 1:1 ACCOUNTING; and a `--src` filter must not s | -| L9626 | §3-The | generalisation — three corollaries worth more than the bug | -| L9643 | §3-And | the inverse-lookup trap, same session | -| L9660 | §140 | A METRIC IS NOT A MEASUREMENT UNTIL IT IS REPRODUCIBLE FROM THE COMMITTED TREE (P30 S1e: a | -| L9680 | §3-The | three-line proof (do this before diagnosing any metric movement) | -| L9689 | §3-The | two instrument defects it exposed | -| L9709 | §3-The | same swallow, twice more, in the integration spine | -| L9720 | §3-Two | wrong mechanisms I chased first, and why they were wrong | -| L9740 | §141 | The §134 class is CLOSED: every line-shape decision now routes through `cdecl._mask` (P30 | -| L9778 | §142 | An open stub whose `h_exact` class is MATCHED elsewhere is FREE. Propagate the body; do no | -| L9790 | §3-The | measurement (do this before any wave; it is ~20 lines and needs no builds) | -| L9805 | §3-The | trap that hid it — SAME FUNCTION, TWO ROUTES, ONLY ONE IS FREE | -| L9814 | Route | selection (why `--addr` sometimes says "nothing changed") | -| L9822 | §3-And | the report-vs-bytes lesson attached to it | -| L9834 | §143 | `cast_call_sites` read a RETURN STATEMENT as a prototype and deleted it. A 0/39 sweep beca | -| L9888 | §144 | THE LITERAL'S SPELLING PICKS THE IMMEDIATE ENCODING (P30 S40 wave 1, `func_801822E0`) | -| L9927 | §145 | Three loop/combine levers from the S40 wave-2 drafters (16/16 match_one) | -| L9977 | §146 | RE-MEASURE A WALL BEFORE YOU RESPECT IT. Both "permanent" giants fell to drafts already on | -| L9988 | §3-Why | a correct draft can read as an intrinsic wall | -| L10000 | Then | propagation returned 0/137 TWICE — both times a missing TYPE | -| L10009 | §3-Two | errors of mine, both instructive | -| L10023 | §3-The | rule | -| L10036 | §147 | The three-stratum FRAME LAW, and four "stop searching" verdicts (P30 S42, `func_8017C294`, | -| L10041 | §3-A. | The frame has THREE strata, and stratum 3 is unreachable from C | -| L10057 | §3-B. | A `?:` on MEMORY operands costs ~16 bytes of invisible frame; on REGISTER operands, zero | -| L10068 | §3-C. | Inner-block declaration does NOT delay slot allocation — BYTE-REFUTED | -| L10073 | §3-D. | A lone `$t8`/`$t9` in the target is RELOAD SCRATCH — reproduce the spill, don't pin the re | -| L10083 | §3-E. | A `qty_compare` TIE is not spelling-reachable — recognise it and stop | -| L10095 | Consequence | for the family (a real scheduling decision) | -| L10145 | §148 | The loop.c hoisting THRESHOLD is arithmetic you can compute, and the `?:` clamp that folds | -| L10151 | §3-A. | `move_movables` hoists iff `threshold × savings × lifetime ≥ insn_count` — and you can rea | -| L10170 | §3-B. | `(v < 0x40) ? v : 0x3F` is folded to `MIN_EXPR` and expands to the WRONG SHAPE | -| L10184 | §3-C. | A zero-byte ALLOCNO-PRIORITY slider | -| L10194 | §3-D. | Reproduce the original's BUGS verbatim | -| L10243 | §149 | Four instrument defects in one session, and the two questions they were hiding (P30 S43) | -| L10249 | §3-A. | A prep step that returns its input on failure is indistinguishable from a search that foun | -| L10267 | §3-B. | Same address + same name ≠ same body — and the ledger keys on address | -| L10283 | §3-C. | `make: *** [...] Error N` is a summary, never a diagnosis | -| L10293 | §3-D. | "Cheap fuel" that was never probed: 0 of 31 templatable | -| L10312 | §150 | A register ROTATION across symmetric blocks is VARIABLE-IDENTITY evidence, not an allocato | -| L10319 | §3-The | fix | -| L10329 | §3-The | method that found it (this is the transferable part) | -| L10345 | §3-Two | corrections to the record | -| L10356 | Diagnostic | order (adopt this) | -| L10367 | §151 | THE GHOST WEDGE: when a load-before-store transposition is unreachable by ANY statement or | -| L10372 | §3-The | mechanism (read from cc1's own `-dR` trace, not inferred) | -| L10387 | §3-The | lever — a zero-emission insn that absorbs the blocked tick | -| L10395 | §3-The | two fallouts, and how to close them (both measured, in order) | -| L10407 | When | to reach for it | -| L10418 | §152 | BYTE SIZE is the family key that name- and h_seq-grouping both miss (P30 S43, the 0xECC fa | -| L10423 | §3-The | finding | -| L10432 | §3-The | key | -| L10443 | §3-Two | cautions that must travel with this technique | -| L10454 | §3-The | companion defect (open) | -| L10466 | §153 | THE ADDRESS-REMATERIALISATION LAUNDER: a third zero-emission asm lever (P30 S43, `func_801 | -| L10474 | Symptom | Symptom | -| L10479 | Mechanism | (gcc source + RTL dumps, not inferred) | -| L10486 | What | does NOT work (14 byte-measured probes) | -| L10492 | §3-The | cure — a fresh launder per site, each in its own block | -| L10502 | Companion | levers from the same function | -| L10522 | §154 | Reading a disc payload: the module-id word, static base derivation, and "type 1 = uncompre | -| L10527 | §3-A. | Payload word0 is a global MODULE ID; code starts after the header | -| L10536 | §3-B. | Two static base-derivation methods that must AGREE (use both) | -| L10548 | §3-C. | PAC type 1 = the same payload class as type 4, just NOT compressed | -| L10558 | §155 | hi/lo literal scanning MUST track base registers (S45) | -| L10567 | §155a | the same failure class, one level up: SHAPE-blind table scanning (S45 p5) | -| L10587 | §155b | check the TYPE your oracle returns before comparing against it (S45 p5) | -| L10610 | §155c | the ZERO-REFERENCE trap: gcc splits a global-array address across the `lui` and the LOAD ( | -| L10640 | §156 | an ORPHANED reconcile poisons the fleet: `dedup_propagate`'s kept edit (S45 p6/p7) | -| L10687 | §157 | the cheap-tier size cliff, measured (S45 p6) | -| L10712 | §158 | The RANGE-EXTENDER: a fourth zero-emission asm lever completes the allocno toolkit (P30 S4 | -| L10721 | Symptom | Symptom | -| L10727 | §3-Why | the fork is chained (gcc source, validated insn-by-insn against -dS/-dR dumps) | -| L10740 | §3-The | method (dump-arithmetic first, then place — no probing) | -| L10757 | Bonus | facts worth keeping | -| L10772 | §156 | THE PREFERENCE-DONOR MERGE: cross-region variable reuse is what fills a0-a3, and a call-ar | -| L10828 | §159 | THE DECLARATION AXIS: conform to byte-truth, and make every guard state its COVERAGE (P30 | -| L10893 | §160 | THE REACH-15 WAVE HARVEST: an align-1 block move, and the instrument that called it a wall | -| L10969 | §161 | THE RETRY-WAVE HARVEST: a jump table indexed from zero, and two allocator traps (P30 S47) | -| L11014 | §162 | S48 WAVE-1 HARVEST (P30, 2026-08-11): the reach-ordered sibling campaign's first 12 target | -| L11041 | §162a | SHARPENS *(sharpens §161a, §131, §8a-pad, §129a)* | -| L11070 | §162b | SHARPENS *(sharpens §48-A3, §156, §150, §76)* | -| L11099 | §162d | SHARPENS *(sharpens §31, §21, §30, §55a)* | -| L11141 | §162e | NEW | -| L11143 | §162 | THE LICM PAIR: what makes an address a movable AT ALL, and why the preheader order is the | -| L11209 | §162f | SHARPENS *(sharpens §42d, §41d, §73, §10)* | -| L11264 | §162g | NEW | -| L11266 | §162 | CROSS-JUMP DIRECTION: the surviving copy is always the LATER one, so a BACKWARD `j` into a | -| L11300 | §162h | SHARPENS *(sharpens §88, §88a, §50-B, §8)* | -| L11302 | §162 | The cross-jump "CALL veto" is a COUNT law, not a CALL law (BOUNDS §88a; P30 S48, `func_801 | -| L11368 | §162i | SHARPENS *(sharpens §135, §21, §42, §32)* | -| L11393 | §162j | SHARPENS *(sharpens §25, §136d-1, §48-B, §46-L2)* | -| L11422 | §162k | SHARPENS *(sharpens §1-I2, §12, §160d, §21)* | -| L11485 | §162l | SHARPENS *(sharpens §48-B, §48-C1, §20, §21)* | -| L11540 | §162m | SHARPENS *(sharpens §36, §158, §148, §153)* | -| L11542 | §158a | THE FIFTH LEVER IS NOT AN ASM: `do { } while (0)` is a REGION ref-multiplier you MINT (P30 | -| L11549 | §3-The | law | -| L11560 | Size | it before you write it (§158 step 1-2, applied) | -| L11581 | §3-The | wrap BOUNDARY is the dial — and it is indiscriminate | -| L11587 | §3-Not | a pure dial | -| L11591 | DIAGNOSTIC | TELL — two faces, one law | -| L11613 | §162n | NEW | -| L11646 | §162o | SHARPENS *(sharpens §158, §136-1, §136-6, §79)* | -| L11705 | §162p | SHARPENS *(sharpens §48-B, §46-L2, §156, §136d-1)* | -| L11722 | §162q | SHARPENS *(sharpens §30, §30a, §135-2, §136-13)* | -| L11760 | §163 | S48 WAVES 2-3 HARVEST (P30, 2026-08-11/12): the five that were byte-probed and are actiona | -| L11828 | §163z | THE UNVETTED REMAINDER (do not cite as law; each needs a dedupe pass) | -| L11848 | §164 | S48 §163z SKEPTIC PASS (P30, 2026-08-12): 190 claims vetted, 82 banked | -| L12300 | §16Xy | SHARPENS *(sharpens §136d-3, §37 /s-DEP LATTICE, §135-2, §136-13, §162q)* | -| L12302 | §3-The | `/s` drop clause is in ALL THREE dependence predicates, so the FIXED-ADDRESS STORE is what | -| L13636 | §164z | REFUTED CLAIMS: do NOT re-derive these | -| L13702 | §165 | S48 WAVE-4 HARVEST (P30, 2026-08-12): banked the same day the wave landed | -| L14353 | §16Z | SHARPENS *(sharpens §37 "the /s-DEP LATTICE", §136-13, §136-14, §16Xy, §162q, `gcc-2.7.2- | -| L14355 | §3-The | ADDRESS-CLASS TABLE: which load/store pairs even REACH the `/s` clause (P30 S48 wave 4, `f | -| L14871 | §165z | REFUTED THIS WAVE: do NOT re-derive | -| L14915 | §166 | THE DESTINATION-TU ORACLE (P30 S48): the seven-attempt bug that was never codegen | -| L14971 | §167 | S48 WAVE-5/6 HARVEST (P30, 2026-08-12): the saturation point | -| L16167 | §167z | REFUTED IN WAVES 5/6: do NOT re-derive | -| L16224 | §168 | THE COUSIN TIER (P30 S49, 2026-08-12): h_seq's exact-hash brittleness, measured — and the | -| L16276 | §169 | THE MICRO-ADAPT LANE (P30 S49): edit a proven body, don't crack a new one | -| L16323 | §170 | THE A-PROP WORD-DIFF CARD (P30 S49): the lane that had no owner | -| L16367 | §171 | THE STALE SEED SYMBOL (P30 S50, 2026-08-13): why §170's 91%→57% was never codegen | -| L16433 | §171a | THE MECHANICAL A-PROP DRAFT (P30 S50): 256 members banked with no agent in the loop | -| L16483 | §171b | THREE CARRIES THE MECHANICAL DRAFT NEEDS (P30 S50, banking the top-reach families) | -| L16516 | §172 | THE ORPHAN-SLOT MECHANISM v2 (P30 S50-Max): the complete frame-residue model for gcc-2.7.2 | -| L16570 | §172a | TWO DECOMPILATION TELLS FROM THE SAME DIG (P30 S50-Max) | -| L16586 | §172b | THREE MORE TELLS FROM THE GCC READ (P30 S50-Max, banked on Drew's ask) | -| L16629 | §173 | THE STORED-PLUMBING RECOVERY RECIPE (P31 T6): symfix-first, per-group isolation, and where | -| L16665 | §174 | THE ADAPT-CARD WAVE RECIPE (P31 waves A/B, 2026-08-14): prevention beats recovery | -| L16735 | §175 | A CALLER-SAVED REGISTER PIN CAN BE A CORRECTNESS BUG, NOT JUST A SCHEDULING CHOICE (P31 wa | -| L16760 | §176a | THE VERIFICATION-LAYER LAWS (P31 overnight, 2026-08-15). What each check can and cannot pr | -| L16800 | §176b | BATCH-GATING MECHANICS (P31): what changes when N drafts land in ONE .c | -| L16826 | §176d | THE CONFLICT TABLE MUST BE SEEDED FROM THE TU, AND KEYED PER FILE (P31 S52, 2026-08-15) | -| L16865 | §176e | SYMBOL IDENTITY IS COMPUTABLE OFFLINE (P31 S52): `tools/reloc_identity.py` | -| L16922 | §176f | THE DECLARATION FORM IS A MATCHING LEVER, SO RECONCILE TOWARD THE FORM THE MATCH NEEDS (P3 | -| L16953 | §176g | SIZE A WAVE BY INSTRUCTIONS, NOT BY CARDS (P31 S52 — the adopted doctrine) | -| L16991 | §176h | THE BATCH-SUBSTITUTION HAZARD MAP (P31 S52): seven holes, three wrong fixes, one law | -| L16999 | §3-A. | The seven under-reporting holes (all in `gate_main`, all the same shape) | -| L17017 | §3-B. | Typedef handling — the only strategy that survives contact | -| L17039 | §3-C. | The limit that remains (recorded, not solved) | -| L17046 | §3-C2. | RECONCILE BEFORE THE FIRST GATE — a parked draft gets HARDER to bank, not easier | -| L17069 | §3-D. | The measured cost shape, and what to build next | -| L17087 | §176i | WHAT A STATIC PRE-GATE CHECK CAN AND CANNOT PROVE (P31 S52, wave Q) | -| L17119 | §176j | STOPPING A WAVE MID-FLIGHT COSTS THE IN-FLIGHT TAIL (and how much is recoverable) | -| L17145 | §176j-2 | THE REPAIR PASS, MEASURED (do this instead of resuming) | -| L17165 | §176k | TWO SELECTOR BUGS THAT SILENTLY SHRINK A WAVE | -| L17182 | §177 | 🔴 THE EPILOGUE RETURN-DELAY SLOT IS DECIDED BY YOUR SAVED-REGISTER SET, NOT BY SCHEDULING | -| L17239 | §178 | SIX LEVERS MINED FROM THE WAVE-P JOURNALS (P31 S52), each byte-proven and source-cited | -| L17251 | §3-A. | THE `$0`-ADD OPAQUE COPY defeats `make_regs_eqv` (func_80033398, 93 ins) | -| L17267 | §3-B. | A `return ` IS A PRIORITY-1 HARD-REG SET THE SCHEDULER PLACES FIRST (func_8001BE30, | -| L17280 | §3-C. | SINGLE-SET TEMPS GET THE BIRTHING BOOST (func_8001D3FC, 196 ins) | -| L17288 | §3-D. | A NARROW TYPE BLOCKS COPY ELISION (func_8001D3FC — new idiom) | -| L17295 | §3-E. | THE ZERO-OFFSET ALIAS HOLE (func_80037028, 71 ins) | -| L17304 | §3-F. | `MEM_IN_STRUCT_P` ASYMMETRY IN `true_dependence` (func_80037144, 124 ins) | -| L17310 | §3-G. | TWO MODELLING TRAPS THAT COST THESE AGENTS SWEEPS OF HUNDREDS OF COMPILES | -| L17326 | §179 | IDIOMS MINED FROM THE WAVE P/Q JOURNALS (P31 S52, harvest pass) | -| L17336 | §179-A | 🔴 A LOOP-WALKED POINTER **PARAMETER** HANDS ITS ARGUMENT REGISTER TO THE GIV (9 byte-proof | -| L17385 | §179-B | 🔴 THE HAND-WRITTEN-ASM TRANSCRIPTION CHECKLIST (maspsx + masked_diff; 10 byte-proofs) | -| L17435 | §179-C | 🔴 A FUNCTION WITH NO EPILOGUE (falls into a sibling's shared tail) MUST BE FILE-SCOPE `__a | -| L17486 | §179-D | `gte_stflg` MUST CLOBBER `"$12"` OR THE WHOLE TEMP FILE ROTATES BY ONE | -| L17506 | §179-E | A `>2*MAX_MOVE_BYTES` BLOCK COPY IS A **STRUCT ASSIGNMENT**, NOT A HAND LOOP | -| L17532 | §179-F | PINNING A LOOP-WALKED POINTER IS A TOTAL OFF-SWITCH FOR STRENGTH REDUCTION | -| L17555 | §179-G | 🟡 A PIN CAN **CREATE** A COMBINE `LOG_LINK` AND DELETE AN `andi` (sixth RC-5 channel, n=1) | -| L17582 | §179-H | A MID-BODY `.global LABEL` PAIR SLICES A BYTE-COMPARABLE FRAGMENT OUT OF A LARGER ROUTINE | -| L17605 | Considered | and NOT banked | -| L17622 | §176c | MAIN (SLUS_007.26) CANNOT BE GATED INCREMENTALLY | -| L17633 | §176 | SEVEN LEVERS FROM THE P31 OVERNIGHT WAVES (2026-08-15): statement order, false regalloc, a | -| L17639 | §176-A | "SCHEDULE / DELAY-SLOT / LENGTH-DRIFT ±1" ⇒ check STATEMENT ORDER around the call first | -| L17663 | §176-B | "REGALLOC-PERM, 1-4 instructions off" ⇒ it is usually NOT register allocation | -| L17709 | §176-C | 🔴 WALL REFUTATION: a hard-register pin CANNOT schedule around a call, because of a genuine | -| L17735 | §176-D | CSE-class levers used in reverse (two sharpenings of §153 and cse_expr §2) | -| L17761 | §176-E | Two cheap source spellings, both cc1-probed | -| L17783 | §176-F | Misdiagnosis triage: four residual verdicts that were lying | -| L17800 | What | is NOT banked here | -| L17813 | §180 | THE LEFTOVER-DRAFT HARVEST: RE-VERIFY WHAT YOU ALREADY HAVE BEFORE DRAFTING ANYTHING NEW | -| L17842 | §180b | WHAT THE PRE-GATE LADDER ACTUALLY FINDS IN A COLD PILE (the shape of integration debt) | -| L17861 | §180c | WHEN A BINARY'S MASS BAND IS SPENT, THE FLEET-WIDE DRAW IS STRICTLY BETTER | -| L17879 | §181 | WHAT A WAVE'S GATE ACTUALLY REJECTS (P31 S53, measured on wave R's 45-draft main pile) | -| L17880 | Only | ONE of 27 blocked drafts was wrong. The other 26 were correct and unbankable. | -| L17935 | §182 | §177's HONEST NEGATIVE: the epilogue lever cracked 4 of 16, and the `800c3` cluster held | -| L17949 | §180d | THE `pgrep` BRACKET TRICK PROTECTS THE PATTERN, NOT THE COMMAND LINE | -| L17961 | §183 | THE DECLARATION-RECONCILIATION PLAYBOOK (P31 S53, measured on 20 byte-verified drafts) | -| L17962 | §3-18 | of 20 reconciled while keeping the match. The two that did not are mechanism, not effort. | -| L18032 | §184 | COMMENT-BLINDNESS IS A DEFECT CLASS, NOT A BUG (P31 S53: three tools, one root cause, one | -| L18060 | §185 | EDIT THE SIDE THAT IS CHEAP TO VERIFY, AND CHECK A TU RETYPE AT ITS USE SITES | -| L18092 | §186 | CROSS-JUMPING RUNS **AFTER** SCHEDULING, SO NO C-LEVEL BARRIER CAN STEER IT | -| L18113 | §186b | A NO-SAVE 16-BYTE FRAME IN A LEAF FUNCTION MEANS `s16` LOCALS, NOT A HIDDEN CALL | -| L18121 | §186c | WHERE A VALUE IS LOADED DECIDES WHICH ALLOCATOR OWNS IT, AND THEREFORE ITS REGISTER | -| L18138 | §187 | 🔴 "SAME SOURCE" IS NOT "SAME OBJECT": THE SDK BUILD AND THE GAME BUILD DISAGREE ON GTE NOP | -| L18176 | §188 | 🔴 THE `jr $ra` + `addiu $sp` TAIL IS AN **ASSEMBLER** ARTIFACT, NOT A FRAME SHAPE | -| L18226 | §189 | FIVE COMPILER LAWS MINED FROM THE WAVE R/S JOURNALS (P31 S53), each source-cited and re-de | -| L18301 | §190 | THREE PRESCRIPTIONS FROM THE SAME HARVEST (weaker evidence than §189, honestly labelled) | -| L18338 | §191 | WHAT THIS HARVEST DID **NOT** BANK (4 rejected, 4 narrowed) — recorded so it is not re-der | -| L18360 | §192 | THE PRE-GATE LADDER WAS MAIN-ONLY, AND NOBODY COULD SEE IT (P31 S54) | -| L18361 | Three | defects in one call path; the overlay slates that carry most of the wave work were being w | -| L18425 | §193 | THE WAVE-T HARVEST (P31 S54): 71 index_gap reports -> 9 laws, 5 rejected, 61 already-cover | -| L18442 | §193-A | The wave card ships only OPEN-set pointers and discards the atlas's BANKED one — `exemplar | -| L18509 | §193-B | A NARROW CAST OF A WIDE PARAMETER COSTS ONE EXTRA INSTRUCTION WHEN ITS STATEMENT SITS AFTE | -| L18547 | §193-C | gcc-2.7.2 cross_jump merges the SCHEDULED common SUFFIX only — there is no prefix/head mer | -| L18581 | §193-D | A COMPILER-GENERATED ARGUMENT COPY IS A `optimize_reg_copy_1` TRIGGER: when the pointer's | -| L18652 | §193-E | A varying-address (pointer) load is re-emitted once per CSE-LIVE INTERVAL, and naming it i | -| L18682 | §193-F | §148-A2 — The `threshold -= 3` STAIRCASE: `move_movables` admits a COUNT of invariants, no | -| L18746 | §193-G | §164-54's "scope to ≥4 arms" bound is byte-wrong — the dispatch-topology oracle goes live | -| L18807 | §193-H | A pointer-derived base load `*(s32*)(p+K)` is uncacheable across ANY memory write or call | -| L18847 | §193-I | A DECLARED AGGREGATE LOCAL HAS AN 8-BYTE FRAME STRIDE — CEIL(size,8), NOT size. N ARRAYS T | -| L18906 | §193-REJECTED | what this harvest did NOT bank (recorded so it is not re-derived) | -| L18933 | §194 | THE WAVE-U HARVEST (P31 S54): 64 index_gap reports -> 14 laws, 5 rejected, 44 already-cove | -| L18950 | §194-A | A zero-byte scheduling fence goes AFTER the defining statement to make that computation em | -| L19016 | §194-B | A `addu $rA,$rB,$zero` copy feeding ≥2 `sh` stores is a SECOND, 16-BIT-DECLARED local — th | -| L19054 | §194-C | A CALLER-SAVED loop counter proves its live range crosses ZERO calls — so it cannot share | -| L19117 | §194-D | Declared width of a computed-value local is a sched1 dial (count-neutral) — a replication | -| L19158 | §194-E | The wave card's `exemplar` is the TARGET ITSELF on 42/73 wave-U and 36/71 wave-T cards — a | -| L19195 | §194-F | `if ((*p = v = f()) == 0)` is an expand-time pseudo SPLITTER (store_expr's `want_value && | -| L19268 | §194-G | Reading the integer half of a 16.16 stack aggregate: REGISTER-LIVENESS, not the C spelling | -| L19311 | §194-H | §164-29's WAR fence runs again at SCHED2 ON HARD REGISTERS: an in-place `v &= K` before a | -| L19349 | §194-I | §16N+2's magic-per-odd-part ladder has exactly one broken row — read the divisor arithmeti | -| L19392 | §194-J | Back-to-back identical stores: flow.c's `last_mem_set` deletes the first, and only `volati | -| L19444 | §194-K | Blind sched1's alias oracle with a second SET of a pointer pseudo — the first zero-byte, n | -| L19522 | §194-L | §88b and §189-E are BOTH half-wrong, but not the way the candidate says: the compare-const | -| L19570 | §194-M | A STORE in a CONDITIONAL branch's delay slot proves its C statement DOMINATES the branch — | -| L19628 | §194-N | §193-D's C dial is misstated: the lever is a SURVIVING CODE_LABEL (a label with a real inc | -| L19688 | §194-REJECTED | what this harvest did NOT bank (recorded so it is not re-derived) | -| L19709 | §195 | THE WAVE-V HARVEST (P31 S54): 67 index_gap reports -> 14 laws, 9 rejected, 76 already-cove | -| L19723 | §195-A | §167-08's "an $aN READ before the jal is scratch" has a byte-proven FALSE-NEGATIVE class: | -| L19794 | §195-B | A CALL_INSN does not start a basic block in gcc-2.7.2 — so a call-crossing temp can be a L | -| L19836 | §195-C | A call-argument `%hi/%lo` pair sitting at the block head, far above its `jal`, is a load-d | -| L19884 | §195-D | §195 — `masked_diff.mask_for` returns 0 for EVERY `j`/`jal` word, so an internal `j` desti | -| L19952 | §195-E | A 0/1 materialised at a JOIN immediately before the controlling `beqz`/`bnez` proves the s | -| L20010 | §195-F | fold-const.c:4825 canonicalises a `?:` whose THEN arm is zero (or constant against a non-c | -| L20062 | §195-G | §NEW — TWO ARMS CALLING THE SAME CALLEE MERGE INTO ONE `jal` UNLESS EACH ARM'S OWN CODE CO | -| L20110 | §195-H | §165-27g — ON A FIXED-SYMBOL GLOBAL, `extern T D[];` + `D[0]` IS THE CSE RELOAD DIAL, AT Z | -| L20157 | §195-I | §145(b) AMENDED — the pointer-bump `addiu` is saved by cse, not combine: ANY second SET of | -| L20222 | §195-J | GTE / PsyQ op CALL-vs-INLINE is a PER-SITE SOURCE FACT, not a TU style — both forms coexis | -| L20266 | §195-K | At -O2 the §18 array-of-struct lever is a FRAME lever, not a length lever — but only when | -| L20318 | §195-L | The cse store-re-seed does not cross a JOIN LABEL: per-arm stores + a join read keep the r | -| L20370 | §195-M | Frame `vars` is a SEQUENTIAL bump-allocation, not a flat sum: §193-I's CEIL(aggregate,8) t | -| L20419 | §195-N | In a call-bearing chain of N≥2 `if (f(...)) return 1;` tests closed by `return 0;`, the LA | -| L20466 | §195-REJECTED | what this harvest did NOT bank (recorded so it is not re-derived) | -| L20512 | §196 | PUT ON THE CARD WHAT THE TREE ALREADY KNOWS: the fleet's declaration consensus (P31 S54) | -| L20567 | §197 | THE WAVE-W HARVEST (P31 S54): 68 index_gap reports -> 4 laws, 3 rejected, 41 already-cover | -| L20581 | §197-A | A NARROW SIGNED MEMORY READ FEEDING A CONSTANT `>>` LOSES ITS `lh`, AND THE CURE IS AN ASM | -| L20619 | §197-B | A REPEATED COMPARE OF ONE VALUE AGAINST ONE CONSTANT IS DELETED BY cse's `qty_comparison_c | -| L20647 | §197-C | Fix A1 (operand order) cannot move a commutative destination whose .greg conflict set alre | -| L20692 | §197-REJECTED | §197-REJECTED | -| L20707 | §199 | THE WAVE-X HARVEST (P31 S54/S55): 63 index_gap reports -> 7 laws, 2 rejected, 56 already-c | -| L20718 | §199-A | §189-A's asm→source inference is byte-FALSE: an interloper between a split constant's `lui | -| L20767 | §199-B | A permutation sweep that holds ANY statement fixed is not a sweep: the statement an agent | -| L20812 | §199-C | A NEGATIVE CONSTANT MULTIPLY ALWAYS TAKES expmed's negate_variant — but whether you ever S | -| L20860 | §199-D | A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is | -| L20920 | §199-E | §189-A BOUNDED AND CORRECTED — the discriminator is INSN_PRIORITY, not "is the interloper | -| L20979 | §199-F | §164-36b — THE TARGET-HEAD FENCE IS A DELAY-SLOT THREAD SELECTOR, AND IT ONLY FIRES WHEN ` | -| L21033 | §199-G | At TWO case nodes the switch-vs-if oracle is not blind — but the tell is ALL tests positiv | -| L21088 | §199-REJECTED | §199-REJECTED | -| L21099 | §200 | THE ALIAS IS THE UNIVERSAL DECLARATION ESCAPE: stop negotiating with the TU's spelling (P3 | -| L21148 | §201 | THE WAVE-Y HARVEST (P31 S55): 67 gap reports -> 5 laws, 8 rejected, 53 already-covered | -| L21158 | §201-A | §150-B applies to `decl_prior`'s DEF row: for an overlay-window symbol the banked "definit | -| L21190 | §201-B | In a narrowed PLUS/MINUS/AND/IOR/XOR expression the destination pointee is INERT — the sig | -| L21270 | §201-C | §X — A CALL'S OWN DELAY SLOT AND THE UPSTREAM CONDITIONAL BRANCH'S SLOT COMPETE FOR ONE IN | -| L21321 | §201-D | THE SIGNEDNESS OF A div/mod MAGIC IS DECIDED BY THE STATIC TYPE OF THE DIVIDEND TREE AFTER | -| L21368 | §201-E | §194-J-2 — The `last_mem_set` deletion window is measured in SOURCE/expand order, not in t | -| L21424 | §201-REJECTED | eight, the session's highest | -| L21449 | §202 | THE ALIAS CARRIES A DEFINITION, NOT JUST A DECLARATION: the DEF-SIDE-RETURN wall (P31 S56) | -| L21486 | §203 | A DEDUPED TYPEDEF MUST PRECEDE EVERY SPLICE POINT, NOT JUST ITS OWN (P31 S56) | -| L21547 | §204 | THE WAVE-Z HARVEST (P31 S56): 82 gap reports -> 5 laws, 16 rejected, 30 already-covered | -| L21566 | §204-A | A COMPARE THAT APPEARS BOTH IN A BRANCH'S DELAY SLOT AND AGAIN ON THE FALL-THROUGH IS A JO | -| L21641 | §204-B | A LOOP COUNT THAT ARRIVES ON THE STACK IS DECREMENTED IN PLACE: a fresh counter local can | -| L21705 | §204-C | WHEN A LOCAL BUFFER'S ADDRESS IS PASSED TO A CALL, ITS SIZE IS A FACT ABOUT THE CALLEE'S B | -| L21763 | §204-D | A LOOP-INVARIANT LOAD IS ADMITTED AS A MOVABLE ONLY IF ITS ADDRESS CANNOT TRAP: `local.fie | -| L21838 | §204-E | `decl_prior`'s `%hi/%lo` ARM HAS NEVER FIRED: the card's promised GLOBAL-TYPE row is 0 of | -| L21890 | §204-CONFIRMED | 30 reports that the index already answered | -| L21984 | §204-REJECTED | sixteen, twice the previous record | -| L22057 | §205 | THE CHAINED ASSIGNMENT IS ITS OWN SCHEDULING DIAL: `*b = *a = v;` moves an argument copy t | -| L22112 | §206 | THE JTBL-CARVE DRAFTING IDIOM: the bounds check is the entry count, and an EMPTY case owns | -| L22181 | §207 | THE WAVE ab–ag HARVEST (P31 S58): 278 byte-banked notes → 25 laws, 103 self-reported no-ga | -| L22202 | §208 | TWO NAMED LOCALS FOR ONE RELOADED EXPRESSION BUY TWO ALLOCNOS — the naming granularity own | -| L22251 | §209 | THE NARROW LOCAL IS A DIAL IN TWO OPPOSITE DIRECTIONS, AND §194-B's "≥2 `sh` STORES" BOUND | -| L22328 | §210 | THE SINGLE-BIT MASK IN A BOOLEAN TAIL: `andi K ; sltu $zero,v` vs `srl n ; andi 1` is a ST | -| L22374 | §211 | HOIST THE LOOP INIT ABOVE THE DOMINATING GUARD: it fills the guard's delay slot AND flips | -| L22433 | §212 | THE WALKING CURSOR IS COUNTABLE: `*wp++` emits one `addiu` PER STORE, `wp[0..2]` emits one | -| L22478 | §213 | INDEPENDENT SAME-BASE STORES: THE EMISSION ORDER IS A PERMUTATION OF SOURCE ORDER, AND THE | -| L22514 | §214 | THE BANKED TWIN MAY BE A MACRO, A DELETED `.s`, OR A SEMANTIC INVERSE — six ways a ≥0.9 si | -| L22560 | §215 | PIN ECONOMY: the twin's pins are NOT part of the shape, and §17's "pin every call-crossing | -| L22616 | §216 | DISTINCT ADJACENT SCALARS vs ONE ARRAY: one `lui` per access is the tell, and the array de | -| L22656 | §217 | DECODING A CALL'S STACK ARGUMENT SLOTS: `sw` at `0x10`/`0x14`/`0x18` are params 5/6/7 **(s | -| L22682 | §218 | A NARROW TYPE AT THE ABI BOUNDARY COSTS AN IN-PLACE `sll/sra` PAIR — on the RETURN as well | -| L22711 | §219 | COMPOUND `+=`, FULL ASSIGNMENT, AND AN EXPLICIT TEMP ARE THREE DIFFERENT SCHEDULES OF ONE | -| L22738 | §220 | THE PARAMETER ITSELF IS A REGALLOC DIAL: use it directly, prefer `s32` to `void*`, and pla | -| L22778 | §221 | A CONSTANT SHARED BY TWO STORES DIES AT THE CALL WHOSE DELAY SLOT REFILLS ITS REGISTER **( | -| L22794 | §222 | SWITCH vs IF-CHAIN, PART 3: source arm order IS emission order, a leading EMPTY case buys | -| L22836 | §223 | READING A `jal` DELAY SLOT: the value in it was produced BEFORE the call, so it is NEVER t | -| L22898 | §224 | CROSS-JUMP: WRITE THE DUPLICATE, AND READ A SHARED DELAY SLOT AS THE MERGE SIGNATURE (P31 | -| L22934 | §225 | THREE CONTROL-FLOW SHAPES NO STRUCTURED SPELLING REACHES (P31 S58) | -| L22977 | §226 | FRAME PADS: FOUR WAYS §162i1/§2429's DEAD-LOCAL LEVER MISFIRES (P31 S58) | -| L23018 | §227 | TYPE THE SOURCE BY THE **LOAD** WIDTH, NOT BY THE STORE WIDTH (P31 S58) | -| L23038 | §228 | READING THE DIVIDE, PART N: the off-by-one compare is `% K == 1`, and three more discrimin | -| L23075 | §229 | THE ADDRESS IS A VALUE: NAMING IT MOVES THE `lui`/`addiu` PAIR — AND §L14410 SAYS THE OPPO | -| L23124 | §230 | THE ANCHOR PROBE: with `%hi`/`%lo` masked, the surviving `addiu` deltas tell you which ass | -| L23139 | §231 | TRANSCRIPTION AND SEMANTIC-READ HYGIENE: six ways the listing misleads (P31 S58) | -| L23180 | §232 | WHEN THE `jr` DELAY SLOT'S STORE STORES THE RETURN VALUE, TIE THEM WITH ONE PSEUDO **(sing | -| L23216 | §30 | addendum (P31 S58) — the `/s` grant closes a SCHEDULING residual and a REGISTER residual w | -| L23236 | §194-B | addendum (P31 S58) — BOUND 2 is byte-wrong; see §209 Direction A | -| L23242 | §176-B | addendum (P31 S58) — the misdiagnosis direction | -| L23248 | §165-40 | addendum (P31 S58) — the barrier goes at the COPY SITE, not inside the region it protects | -| L23257 | §164-63 | addendum (P31 S58) — the interposed asm works when the SECOND value is an ordinary assignm | -| L23266 | §193-A | / §194-E addendum (P31 S58) — where the twin's body actually lives | -| L23272 | §233 | THE WAVE aa–bg HARVEST (P31 S58b): 1,101 byte-banked notes → 24 new laws, 21 addenda, ~700 | -| L23316 | §234 | CONSTANT MATERIALISATION: THE STORE LVALUE'S SIGNEDNESS PICKS `addiu` vs `li`/`ori` (P31 S | -| L23357 | §235 | THE PHANTOM SYMBOL: A MASKED `MATCH` CAN CARRY A RELOCATION THAT DOES NOT EXIST (P31 S58b) | -| L23386 | §236 | THE DECLARATION LAYER IS THE DOMINANT BANK-BLOCKER: NINE WAYS A BYTE-PERFECT BODY FAILS TH | -| L23465 | §237 | THE CAST-AT-CALL-SITE DECISION TABLE: WHAT §17a-1 FIXES, WHAT IT CANNOT, AND THE FOUR ESCA | -| L23520 | §238 | SAME NAME, DIFFERENT FUNCTION: THE OVERLAY-HOMONYM TRAP (P31 S58b) | -| L23560 | §239 | TWO-STATEMENT INTEGER-SPACE MATERIALISATION REORDERS `la` vs `sll`; AND THE PLUS-TREE OPER | -| L23594 | §240 | `A + K + B`: WRITE THE CONSTANT **BETWEEN** THE TWO RUNTIME TERMS (P31 S58b) | -| L23623 | §241 | THE FOLDED SIGN-EXTEND-AND-SCALE: `sll 16 ; sra (16 − log2 scale)` (P31 S58b) | -| L23652 | §242 | `*k` vs `<>n`: EXPRESSION SPELLING OWNS THE LOAD WIDTH AND THE ROUNDI | -| L23680 | §243 | SPELL THE CSE BARRIER AS A REASSIGNED POINTER; AND THE `nop`-AFTER-EVERY-`lh` SIGNATURE (P | -| L23710 | §244 | `volatile` IS A COUNTING INSTRUMENT, A STORE-ORDER PIN, AND MUST SOMETIMES BE ASYMMETRIC ( | -| L23745 | §245 | THE CALL'S ARGUMENT LIST IS A SCHEDULING SLOT (P31 S58b) | -| L23792 | §246 | THREE-LIVE-VALUE SCAN LOOPS WANT ADDRESS-FROM-INDEX; AND TWO SYMBOLS CAN SHARE ONE giv (P3 | -| L23832 | §247 | TWO BRANCHES TO **ONE** LABEL MEANS THE SOURCE CONDITION IS NEGATED (P31 S58b) | -| L23866 | §248 | SPLIT THE LOAD FROM THE ARITHMETIC: A FUSED `g + K` DENIES THE CALLEE-SAVED REGISTER ITS D | -| L23890 | §249 | THE SELF-ASSIGN, THE DEAD RE-ASSIGN, AND THE `+ zr` COPY: THREE WAYS TO MAKE A DELETED INS | -| L23932 | §250 | `%hi/%lo` vs `lw`: THE EXTERN'S ARRAY-vs-SCALAR SHAPE DECIDES ADDRESS MATERIALISATION (P31 | -| L23969 | §251 | IMMEDIATE-SPELLING TRIGGERS: `+= 0xFF`, FULL-WIDTH `~K`, AND THE TWO-OR SPLIT (P31 S58b) | -| L23991 | §252 | THE GUARDED PRE-DECREMENT: `(x != 0) && (--x == 0)` (P31 S58b) | -| L24012 | §253 | POSTFIX `++` vs `+= 1` PICKS A DIFFERENT SCRATCH REGISTER **(single observation — not yet | -| L24026 | §254 | THE DEAD PARAMETER IS A REGISTER-PLACEMENT TOOL **(single observation — not yet cross-conf | -| L24038 | §255 | THE EMPTY CASE, PART 2: FOUR TREE SHAPES IT BUYS (P31 S58b) | -| L24073 | §256 | GOTOS IN THE TARGET'S BLOCK ORDER REPRODUCE SWITCH PLACEMENT WITHOUT SWITCH'S SIDE EFFECTS | -| L24110 | §257 | THE DEAD-END LEDGER (P31 S58b): ELEVEN LEVERS THAT MEASURED NULL OR BACKFIRED | -| L24153 | §258 | ADDENDA TO EXISTING SECTIONS (P31 S58b) | -| L24158 | §30 | addendum (P31 S58b) — THE ANONYMOUS STRUCT MEMBER REF GRANTS `/s`, AND THAT IS A TWO-FOR-O | -| L24179 | §194-B | / §209 addendum (P31 S58b) — TWO MORE INSTANCES, AND THE BOUND IS NOW REFUTED FOUR WAYS | -| L24202 | §202 | addendum (P31 S58b) — THE DEF-SIDE ALIAS ALSO CLEARS A RETURN+PARAM DOUBLE CONFLICT | -| L24213 | §205 | addendum (P31 S58b) — CHAINED ASSIGNMENT: N≥3 IS INNERMOST-FIRST, AND THE TEXT MIRRORS EMI | -| L24230 | §208 | addendum (P31 S58b) — IT SCALES TO SIX SITES, AND IT HAS AN EXACT INVERSE | -| L24259 | §210 | addendum (P31 S58b) — THREE CONFIRMED SPELLINGS OF THE BOOLEAN TAIL | -| L24275 | §211 | addendum (P31 S58b) — INIT PLACEMENT: FIVE MORE DIALS BEYOND THE GUARD HOIST | -| L24318 | §213 | addendum (P31 S58b) — THREE MORE PERMUTATION LAWS FOR INDEPENDENT SAME-BASE STORES | -| L24347 | §214 | addendum (P31 S58b) — FOUR MORE WAYS A HIGH-SIMILARITY TWIN LIES | -| L24383 | §215 | addendum (P31 S58b) — PIN ECONOMY, PART 2: NINE REFINEMENTS | -| L24435 | §217 | CROSS-CONFIRMED (P31 S58b) — AND THE INCOMING HOME SLOT IS THE MIRROR | -| L24452 | §220 | addendum (P31 S58b) — THE PARAMETER, NOT A COPY (SEVEN CARDS) | -| L24477 | §222 | addendum (P31 S58b) — IF-CHAIN vs SWITCH: THREE MORE DISCRIMINATORS | -| L24495 | §223 | addendum (P31 S58b) — FIVE MORE CONFIRMATIONS, AND THE CONSTANT-IN-`$v0` CASE | -| L24519 | §224 | addendum (P31 S58b) — CROSS-JUMP MERGES *CALLS*, AND THE DELAY SLOT IS THE DISCRIMINATOR | -| L24549 | §225 | addendum (P31 S58b) — THE GUARD-CLAUSE FINGERPRINT, AND THREE MORE SHAPES | -| L24576 | §226 | addendum (P31 S58b) — THE FRAME CATALOGUE: SEVEN MORE LEVERS, AND SLOT ORDER IS DECLARATIO | -| L24621 | §229 | addendum (P31 S58b) — NAME IT **INSIDE** THE ARM | -| L24632 | §230 | CROSS-CONFIRMED (P31 S58b) | -| L24641 | §231 | addendum (P31 S58b) — FOUR MORE WAYS THE LISTING MISLEADS | -| L24672 | §232 | CROSS-CONFIRMED (P31 S58b) | -| L24683 | §259 | THE DISCARD LEDGER FOR THE aa–bg HARVEST (P31 S58b): WHAT WAS MINED AND REJECTED, AND WHY | -| L24722 | §260 | THE §154-A LEADING-ISLAND SPLIT: ONE CONFIG LINE, AND THE ISLAND PEELS FROM THE END (P31 S | -| L24772 | §260-A | STAGE 2 IS PROVEN, AND THE WHOLE jtbl PIPELINE IS AUTOMATED AT THE GATE (P31 S59, same day | -| L24808 | §261 | THE -O0 ORACLE: DERIVE THE OPT LEVEL FROM THE TARGET, AND `$fp` IS NOT THE TELL (P31 S59) | -| L24834 | §261a | THE -O0 FRAME-RELOAD GRAMMAR: reload COUNT disambiguates the C spelling (P31 S59, byte-pro | -| L24856 | §262 | A LANE'S YIELD IS ONLY A LANE FACT IF IT IS SIZE-MATCHED (P31 S59) | -| L24886 | §263 | A STOLEN DELAY SLOT WHOSE INSTRUCTION IS AN ARG-REGISTER COPY IS AN ARITY ERROR, NOT A SCH | -| L24927 | §264 | FOUR TELLS-LANE C RECIPES, EACH DRIVEN TO MATCH (P31 S59) | -| L24977 | §265 | THE VERBATIM-ASM BANK LANE: A FUNCTION NO -O2 C CAN EVER MATCH BANKS AS A RAW `__asm__` BO | -| L25039 | §266 | THE INERT-RIDER LAW: A LEVER IS ONLY CITABLE WHEN ITS SOLO REMOVAL BREAKS THE MATCH (P31 S | -| L25079 | §267 | ADDENDA HARVESTED FROM WAVES at/bh/bk/bl (P31 S59b) | -| L25087 | ADD-1 | → §231 addendum (also cross-ref from §195-D) — THE MASKED-`jal` "MISSING CALL" ILLUSION | -| L25096 | ADD-2 | → §42a addendum — A SHARED CONSTANT *NAMED IN A LOCAL* ACROSS A `jal` IS AN ISO→TU DRIFT H | -| L25108 | ADD-3 | → §236, item 10 — THE UN-DELETED `INCLUDE_ASM` STUB IS A DUPLICATE DEFINITION | -| L25118 | ADD-4 | → §225-3/-4 addendum — THE MIRROR ROW: VALUE-RETURN IN THE *TAKEN* ARM + TRAILING BARE `re | -| L25132 | ADD-5 | → §1/I1 addendum — THE INVERTED RANGE TEST: `(u32)(x-lo) >= N` WITH THE ZERO-ARM AS THE TR | -| L25141 | ADD-6 | → §172b-1 / §264 addendum — SHIFT-AS-TEST: `(x << 16) != 0` TESTS THE LOW HALF WITHOUT TRU | -| L25150 | ADD-7 | → §256 addendum — THE SINGLE-GUARD GOTO: THEN-BLOCK OUT OF LINE AT THE TAIL | -| L25162 | ADD-8 | → §245 addendum — THE RE-TIE BARRIER PINS CALL-ARG SETUP TO SOURCE ORDER (construct 6) | -| L25174 | ADD-9 | → §213-3 / §217 addendum — ADJACENT PRE-CALL FRAME STORES ARE ONE AGGREGATE; THE UNESCAPED | -| L25184 | ADD-10 | → §237 addendum (arity-evidence paragraph) — AN `la` PAIR ABOVE THE PROLOGUE `sw $ra` IS A | -| L25193 | ADD-11 | → Cross-confirmation card block (per §259's standing instruction: confirmation, not news) | -| L25244 | §268 | A `register __asm__` PIN ON A CALL-CLOBBERED REGISTER IS HONORED EXACTLY WHEN THE PINNED R | -| L25298 | §269 | ADDENDA HARVESTED FROM WAVES ax/bm (P31 S59c) | -| L25313 | ADD-1 | → §257-8 addendum — THE INTERPOSED ASM'S `__volatile__` IS A PER-SHAPE DIAL, AND THE "NO-O | -| L25326 | ADD-2 | → §236 addendum (item 1 corollary) — THE SILENT-SPLICE DECLARATION LADDER: WHERE THE TU HA | -| L25340 | ADD-3 | → §238 addendum — TWO BINARIES CAN EACH DEFINE THE SAME `func_` NAME WITH DIFFERENT BYTES, | -| L25353 | ADD-4 | → §167-37 addendum — THE FIFTH PRECONDITION, NOW MEASURED: DOWNSTREAM FIELD RE-READS ⇒ NAM | -| L25370 | ADD-5 | → §267-ADD-6 / §172b-1 addendum — THE SIGN-TEST FACE: `(s16)v < 0` IS `sll 16` + `bgez` ON | -| L25386 | ADD-6 | → §220-addendum — THE FOURTH FACE: WHEN THE NAMED COPY ITSELF BUYS THE EXTRA CALLEE-SAVED, | -| L25402 | ADD-7 | → §229 addendum — THE VALUE FACE: A LOOP-STORE CONSTANT SPELLED AS A LITERAL HAS NO SOURCE | -| L25415 | ADD-8 | → §30a addendum — THE THIRD COLUMN: `*p++` IS ALSO SERIALIZED BUT BURNS `addiu`; ONLY CAST | -| L25430 | ADD-9 | → §255 "AND CASE-BODY PLACEMENT" bound / §222-addendum-3 — ON A LARGE SPARSE TREE, BODIES | -| L25444 | ADD-10 | → Cross-confirmation card block (per §259's standing instruction: confirmation, not news) | -| L25485 | §3-1a. | The §266 sweep — every solo-lever A/B run for this batch | -| L25518 | §270 | The A-prop 0-bank anatomy: a byte-correct body still needs FOUR layers to agree (P31 S59) | -| L25536 | §271 | Ordinal IMM pairing: text order is NOT emission order; emit CANDIDATES, let the oracle pic | -| L25558 | §272 | The `(void)`-decl + empty-call wall: K&R the DEFINITION, not just the decls (P31 S59) | -| L25578 | §273 | A standalone compile is the WRONG oracle for a TU-destined draft (P31 S59) | -| L25593 | §274 | ADDENDA HARVESTED FROM 18 WAVES (P31 S60): 315 candidates, 255 already covered, 21 sharpen | -| L25599 | ADDENDUM | to §179-C — the `.type NAME, @function` requirement | -| L25646 | ADDENDUM | to §134 — a typedef defined BELOW the splice point is stripped anyway | -| L25676 | ADDENDUM | to §179-D (GTE macro reference family) — `gte_SetRotMatrix`/`gte_SetTransMatrix` bodies | -| L25702 | ADDENDUM | to §82 — struct copies must stay MEMBER-WISE, not block-moved, to match a spill-slot save | -| L25740 | ADDENDUM | to §136d-1 (RC-12, the `$0`-add / opaque-copy family) — two symptoms beyond "compare reads | -| L25779 | ADDENDUM | to §20 — a global declared as `T *` may itself BE the array base, not a pointer to derefer | -| L25808 | ADDENDUM | to §1-I5 | -| L25873 | ADDENDUM | to §164-51 | -| L25889 | ADDENDUM | to §176-F5 | -| L25918 | ADDENDUM | to §225 | -| L25963 | ADDENDUM | to §224 — CROSS-JUMP: THE DUPLICATE CAN BE A PLAIN STORE, NOT ONLY A CALL | -| L25997 | ADDENDUM | to §164-64 — AN EMPTY CLOBBER ON AN ARGUMENT REGISTER CAN BE THE DELIBERATE FIX, NOT JUST | -| L26028 | ADDENDUM | to §244 — THE COMPILER BARRIER, NOT `volatile`, BLOCKS A STORE→LOAD HOIST THROUGH A POINTE | -| L26059 | ADDENDUM | to §172b-1 — TWO PLACEMENT DIALS THE PROMOTION LAW DOESN'T NAME: NARROW THE COUNTER'S DECL | -| L26106 | ADDENDUM | to §229 — A POINTER'S NUMBER OF USES DECIDES WHETHER ITS ADDRESS FOLDS OR SURVIVES A CALL | -| L26151 | ADDENDUM | to §172b-4 — THE PLAIN CAST-DIVISION ALREADY PRODUCES THE PATTERN; DON'T HAND-ROLL THE BIA | -| L26181 | ADDENDUM | to §8 — WHEN `INCLUDE_RODATA` NEEDS A STANDALONE `.s` YOU CAN'T CREATE, CARRY THE FRAGMENT | -| L26224 | ADDENDUM | to §226 — A DEAD LOCAL SCOPED TO A NESTED BLOCK BUYS A MID-FUNCTION `addiu sp` PAIR, NOT A | -| L26263 | ADDENDUM | to §172a — RE-READING MEMORY (NOT NAMING A TEMP) IS WHAT KEEPS AN INCREMENT'S DELAY-SLOT F | -| L26294 | ADDENDUM | to §225 / §256 — A GOTO TO A SHARED SET-POINT PREVENTS IF-CONVERSION FROM COLLAPSING A LAT | -| L26336 | ADDENDUM | to §211 — AN IN-LOOP ACCUMULATOR WANTS A CLOSED-FORM EXPRESSION WHEN THE TARGET REMATERIAL | -| L26371 | §275 | THE LEFTOVER-REGISTER READ | -| L26411 | §276 | MIXED ADDRESS-EXPRESSION SPELLING FOR ADJACENT RELOCATABLE SYMBOLS IS A CSE-UNIFICATION DI | -| L26520 | §277 | RETURN-TAIL C SPELLING PICKS THE DELAY-SLOT-FILL vs TRAILING-MOVE TOPOLOGY, AND A NARROWER | -| L26584 | §278 | ADDENDA HARVESTED FROM WAVE cf (P31 S60): 34 candidates, 13 already covered, 8 sharpenings | -| L26592 | ADDENDUM | to §74 (func_800D0E30, resident) | -| L26628 | ADDENDUM | to §172b-4 (func_80185054, ov_SC03_097) | -| L26666 | ADDENDUM | to §265 (func_8017DC80, ov_SC07_002) | -| L26705 | ADDENDUM | to §17 (func_800CB794, md_MAIN_036) | -| L26753 | ADDENDUM | to §162p (func_8017C120, ov_MAIN_012) | -| L26787 | ADDENDUM | to §20 (~L1947) (func_80186AD0, ov_SC06_032) | -| L26817 | ADDENDUM | to §164-56 (func_8017F644, ov_SC04_005) | -| L26852 | ADDENDUM | to §237 (func_8017F7FC, ov_SC03_092) | -| L26881 | §279 | A `do/while (p < end)` LOOP UNDER AN ENTRY GUARD: the guard decides the compare, not the l | -| L26882 | §NNN | A DO-WHILE'S GUARD AND LATCH MUST REPEAT THE SAME BOUND EXPRESSION, NOT SHARE ONE LOCAL: T | -| L26915 | §280 | THE CURSOR'S DECLARED TYPE PICKS `sltu` vs `slt`: a `T*` bound test is UNSIGNED by C rule, | -| L26916 | §NNN | A LOOP CURSOR'S C TYPE (POINTER vs PLAIN INTEGER) SELECTS `sltu` vs `slt` FOR ITS BOUND TE | -| L26949 | §281 | GROUP COPY-THEN-RMW BY OPERATION KIND, NOT FIELD BY FIELD: sched1 does the interleaving, t | -| L26950 | §NNN | A DEPENDENT COPY-THEN-RMW BLOCK MUST BE SOURCE-GROUPED BY OPERATION KIND, NOT BY FIELD, AN | -| L26995 | §282 | gcc's OWN LOOP REVERSAL PUTS THE COUNTER INIT AFTER THE HOISTED MOVABLES — a position no h | -| L26996 | §NNN | WRITE THE UP-COUNT LOOP: gcc's OWN REVERSAL PRODUCES A COUNTER-INIT INSTRUCTION THAT LANDS | -| L27033 | What | I could not verify | -| L27080 | §283 | ADDENDA HARVESTED FROM THE 36-WAVE BATCH (P31 S60): 1,216 candidates, 859 already covered, | -| L27090 | ADDENDUM | to §164-75 — the fold-reassociation law also fires at a variable's INITIALIZER, not only a | -| L27116 | ADDENDUM | to §21 — the `bltz`+`slti` (or N-separate-compares) signed-range-split bullet is now CONFI | -| L27162 | ADDENDUM | to §202 — the DEF-SIDE ALIAS also resolves a function-vs-DATA-symbol identifier clash, not | -| L27185 | ADDENDUM | to §22 (`volatile`-qualified-global reload lever, cookbook ~L1922) — for a NON-constant, s | -| L27204 | ADDENDUM | to §195-E — a goto-ladder's STORES must sit AT the labels, after the gotos, not inline bef | -| L27266 | ADDENDUM | to §195-N — a GNU statement-expression slider must sit INSIDE the conditional arm's value | -| L27323 | ADDENDUM | to §176-B2 — in a micro-function with no long/short lifetime asymmetry, BOTH contending ps | -| L27370 | ADDENDUM | to §199-G — A `default:` LABEL GROUPED ONTO THE LAST CASE REMOVES THE `j default` TAIL, EV | -| L27439 | ADDENDUM | to §220 — REFERENCING THE RAW PARAMETER (NO NAMED COPY, NOT EVEN A PIN) LETS THE CALLEE-SA | -| L27497 | ADDENDUM | to §252 — a `>=0`/`<0` split on an unconditionally-decremented value needs the POSTFIX ope | -| L27524 | ADDENDUM | to §215 — FIFTH SHAPE: reused mask constants across two call-free merge sites each get the | -| L27607 | What | I could not verify | -| L27678 | Harness-defect | flags | -| L27771 | ADDENDUM | to §167-40 (func_8017E2CC, ov_SC04_015 — wave dg) | -| L27791 | ADDENDUM | to §20's cross-jump EXPLOIT bullet (func_8017E360, ov_SC05_007 — wave dg) | -| L27805 | ADDENDUM | to §87 (func_801815F4 ov_SC06_032; corroborating func_801840DC ov_SC05_017, func_80189C68 | -| L27824 | ADDENDUM | to §153 / §236-5 (func_801A419C, md_SC07_003 — waves di and dl, corroborating; refutes a c | -| L27844 | ADDENDUM | to §263 (func_801E83AC, md_SC04_029 — wave dj) | -| L27858 | ADDENDUM | to §265 (func_8017D878, ov_SC03_107 — wave dj; corroborated by a REJECTED, contradicted ca | -| L27872 | ADDENDUM | to §6 (func_801811F0, ov_SC03_102 — waves dj and dl, corroborated by a self-reported "noth | -| L27886 | ADDENDUM | to §195-G (func_80183BB0, ov_SC05_001 — wave dj) | -| L27914 | ADDENDUM | to the zero-byte-asm-slider family (§47 / §148-C / §153) (func_800CB874, md_MAIN_040 — wav | -| L27932 | ADDENDUM | to §194-B (func_8017EB34, ov_SC03_117 — wave dk; distinct from the §74 co-pinning finding | -| L27964 | ADDENDUM | to §74 (func_8017EB34, ov_SC03_117 — counter/clamp variant; wave dj, corroborated by dk/dl | -| L27984 | ADDENDUM | §37 — merged into the §153/§236-5 entry above (func_801A419C, wave dl) | -| L27992 | ADDENDUM | §6 — merged into the §6 entry above (func_801811F0, wave dl) | -| L28000 | ADDENDUM | to §238 (func_80182CB4, ov_SC02_000 — wave dl) | -| L28018 | ADDENDUM | to §137a (func_801684B4, ov_MAIN_012; corroborated independently by func_80189E68, func_80 | -| L28034 | ADDENDUM | to §8c / §88d (func_8016AB6C, ov_MAIN_012 — wave dm) | -| L28048 | ADDENDUM | to §73 / §30#2 (func_800D1984, resident — wave dm) | -| L28064 | What | I could not verify | -| L28084 | ADDENDUM | to §174 Law 4 (func_8017E9A8, ov_SC06_015) | -| L28124 | ADDENDUM | the zero-emission-asm family gains a REF-SLIDER PLACEMENT LAW and a paired RESTORER (func_ | -| L28176 | From | ck + cl + cm | -| L28182 | ADDENDUM | §NNN — sharpens §55a / §164-37 / §165-28 (switch-vs-tree cluster): A SHAPE THAT LOOKS LIKE | -| L28219 | ADDENDUM | §NNN — sharpens §167-13's boundary: CHAINING TWO IDENTICAL SIDE-BY-SIDE STORES INTO ONE C | -| L28252 | ADDENDUM | §NNN — sharpens §162a3/§60b: A `sll $v0,16 / sltiu $v0,1` ZERO-TEST OF A JUST-DECREMENTED | -| L28285 | ADDENDUM | §NNN — sharpens §37/§124 (unspecified-parameter-list family): DERIVE A CALLEE'S ARITY LOWE | -| L28318 | ADDENDUM | to §5a (func_80181F74, ov_SC03_112, wave cn) | -| L28368 | ADDENDUM | to §265 (func_8017E26C, ov_SC04_016, wave cn) | -| L28406 | ADDENDUM | to §42b (func_8018247C, ov_SC07_002, waves cu + cw) | -| L28437 | ADDENDUM | to §199-F family (func_8017EFB0, ov_SC02_021, wave cu) | -| L28492 | ADDENDUM | to §195-E (func_800CFC1C, md_MAIN_003, wave cv) | -| L28537 | ADDENDUM | to §215 addendum (func_800CB2C8, md_MAIN_033, waves cv + cw) | -| L28593 | ADDENDUM | to §236 item 4 (func_8017D268, ov_SC04_006, wave cw) | -| L28622 | What | I could not verify | -| L28654 | Harness-defect | flags (not idioms — flagged for the operator) | -| L28695 | ADDENDUM | to §250 (func_8017D7CC, ov_SC03_115 — cx/cy/cz/dr) | -| L28740 | ADDENDUM | to §225 (func_8017E190, ov_SC03_115 — cx/cy/cz) | -| L28793 | ADDENDUM | to §45-A (func_8017F6A4, ov_SC02_016 — cy/cz) | -| L28837 | ADDENDUM | to §249 (func_80182ED4, ov_SC04_004 — dp/dr/dt) | -| L28882 | ADDENDUM | to §199-A (func_801816FC, ov_SC02_005 — dp/dr/dt) | -| L28928 | What | I could not verify | -| L28971 | Harness-defect | flags | -| L29033 | §284 | COMBINE CAN REASSOCIATE TWO SEQUENTIAL BITWISE-AND MASKS INTO ONE AGAINST THE PRE-MASK VAL | -| L29037 | §285 | PRE-INITIALIZING A VARIABLE WITH A SHARED CONSTANT BEFORE A BRANCH MAKES BOTH ARMS OF THE | -| L29041 | §286 | FOLD A STATEMENT'S SIDE EFFECT INTO A COMMA-EXPRESSION IN AN ARGUMENT POSITION TO PLACE IT | -| L29045 | §287 | A STACK-FRAME HOLE BELOW TWO ADDRESS-TAKEN AGGREGATE LOCALS IS A LEADING PAD MEMBER OF ONE | -| L29049 | §288 | A REGISTER PIN DECLARED UNINITIALIZED AND ASSIGNED ONLY AT ITS LATE, SOLE USE STILL FORCES | -| L29053 | §289 | an array local's address-taken base keeps every element's store alive, even though only on | -| L29057 | §290 | A SINGLE STRENGTH-REDUCED GIV CAN DRIVE STORES TO SEVERAL DISTINCT RELOCATABLE SYMBOLS, EA | -| L29061 | §291 | THE DELAY-SLOT FALSE-VALUE: A CONDITIONAL BRANCH'S ZERO ARM MUST BE A FALL-THROUGH-ADJACEN | -| L29065 | §292 | DECLARING A SYMBOL UPSTREAM OF AN ALREADY-BANKED SIBLING THAT RELIES ON THAT SYMBOL'S IMPL | -| L29068 | §293 | THE "WHOLE-OBJECT GATE NEEDS EVERY SIBLING" LAW, WRITTEN PROPERLY: IT IS THREE LAWS, AND T | -| L29118 | §294 | ADDENDA HARVESTED FROM THE S61 GEN0/MAXTOK/MAIN/DEEPSEEK BATCH (waves ab8/ab16/ab24/ab32 · | -| L29129 | ADDENDUM | to §127 — the -O0 constant-offset fold keys on the MEMBER-ACCESS tree shape, not on the in | -| L29157 | ADDENDUM | to §261a — FOUR MORE -O0 DIALS BEYOND THE RELOAD COUNT (boot.c + md_MAIN_011/003, wave m0a | -| L29207 | ADDENDUM | to §264-3 — the explicit entry copy's BOUND: required exactly when the RAW value must outl | -| L29227 | ADDENDUM | to §172b-1 (counter-type dial) — the sll's SOURCE REGISTER is the placement discriminator | -| L29239 | ADDENDUM | to §276 — the SHARE direction: spell the second adjacent symbol RELATIVE to force ONE anch | -| L29255 | ADDENDUM | to §31's density-dummy dial (L2460/L2497) — the dose is TWO refs, and the dummy must sit w | -| L29272 | ADDENDUM | to §282 — the ADDRESS-GIV face: write the walked address INLINE so strength reduction birt | -| L29295 | ADDENDUM | to §253 — SECOND byte-proven card (upgrade from single-observation), and the placement fac | -| L29316 | ADDENDUM | to the L1800 anchor-steer bullet — a DERIVED-POINTER local silently flips the merged giv's | -| L29339 | ADDENDUM | to §31's asm→layout inference — TWO WIDTH-PAIR DISCRIMINATORS (same offset, different widt | -| L29360 | §295 | THE KERNEL-TRAP STUB: §81's jr-DETECTOR WITHOUT A TABLE IS A PsyQ SYSCALL TRAMPOLINE — ROU | -| L29415 | §296 | THE FRAME CHECK OUTRANKS THE ATLAS LEVER: READ PROLOGUE/EPILOGUE BEFORE DRAFTING ANY C — A | -| L29458 | §297 | ONE GIV SERVING MIXED-WIDTH LOADS *AND* A STORE NEEDS STRUCT-MEMBER SPELLING; CAST/INDEX S | -| L29501 | §298 | THE SHARED-TAIL POSITION DIAGNOSTIC: A FOLDED TAIL *BETWEEN* SWITCH ARMS MEANS PER-ARM DUP | -| L29526 | §299 | TWO INDEPENDENT EXTRACTION CHAINS EMIT CONTIGUOUSLY INSIDE ONE EXPRESSION; ONLY A STATEMEN | -| L29561 | §300 | S61 DISTILL BATCH NOTES (waves ab8/ab16/ab24/ab32 · g0a–g0f · m0a · ds1/ds2 · m0b) | -| L29630 | §301 | AN INTERNAL `j` CARRIES `R_MIPS_26 .text`: rtu/match_one "MATCH" COULD NOT SEE WHICH LABEL | -| L29678 | §302 | A RED BINARY IS A DRIFTED SPEC, NOT A MYSTERY: THE THREE CARVE-STATE INVARIANTS AND HOW TO | -| L29722 | §303 | MODULE ISLAND TABLES: DERIVE THE PADS AT BUILD TIME, PEEL NOTHING — THE §154-A/§260 "islan | -| L29758 | §304 | SELF-DEFINING RODATA: WHEN A FUNCTION'S `.s` IS THE ONLY OWNER OF THE DATA IT REFERENCES, | -| L29781 | §305 | "CARVE-REFUSED" AT GATE TIME IS THREE NAMED, DETERMINISTIC CLASSES — NONE OF THEM A CARVE | -| L29833 | §306 | A HAZARD `nop` IN FRONT OF A DIV-RESULT STORE IS A STATEMENT-ORDER DEFECT: THE INDEPENDENT | -| L29860 | §306a | T4 DISTILL ADDENDA (P31 S62; four byte-proven refinements to existing laws, verified again | -| L29898 | §307 | THE BRUTE-FORCE-THE-STATEMENT-ORDERS LEVER HAS A BOUND: A FAN-OUT COPY'S PRIORITY IS SCHED | -| L29942 | §308 | A NAIVE FINAL `goto` DELETES THE TARGET'S `j`+`nop`: SPELL THAT EDGE AS A TAUTOLOGICAL `if | -| L29971 | §308a | A TWO-INSTRUCTION ARM STUB LAID *BEFORE* THE OTHER ARM AND REACHED ONLY BY A TRAILING `j` | -| L30005 | §309 | A FRAME-ADDRESS EQUIVALENCE RIDES *THROUGH* A SKIPPABLE CONDITIONAL: POST-`if` STORES FOLD | -| L30045 | §310 | A TWO-OPERAND `subu`'s DESTINATION TIES ONLY TO THE OPERAND THAT IS BLOCK-LOCAL: SHARE *ON | -| L30076 | §311 | A JOIN-BLOCK STORE CAN SWALLOW AN ARM'S LOAD-DELAY `nop`: WHEN ONE ARM'S VALUE COMES FROM | +| L2769 | §41a | v3.1: the def-side wall was ~71% TOOL-shaped — the five measured defects + the laws that d | +| L2824 | §41b | T7 execution: the object-only probe OVER-counts BANKABLE by two link/rodata classes (Phase | +| L2854 | §41c | T7-M2: the ×134 def-side-wall sweep via per-sibling RE-reconcile (Phase 25, 2026-07-10; 4, | +| L2873 | §41b | addendum — M4 "reconcile_decls" tier is ALSO a probe over-count: 0/8 mechanical (Phase 25 | +| L2893 | §41d | `void`→`s32` is NOT always byte-neutral: gate the RAW draft FIRST (Phase 26 session 6, byt | +| L2915 | §42 | The F-band ≤28 regalloc crack wave: register-pin/DENSITY levers beat the permuter (Phase 2 | +| L2968 | §42a | addendum — wave 2 (residuals + 29-100 band): iso-MATCH ≠ real-TU bank, the memcpy→struct-a | +| L3009 | §42b | addendum — wave 3 (Max, 2026-07-10c): THE STALE-OBJECT GATE TRAP + the read-global `&`-cas | +| L3048 | §42c | addendum — wave 3 (Max orchestrator + CORRECTED Ultracode fan-out, 2026-07-10c): the real- | +| L3097 | §42d | addendum — wave 4 (rtu_match fan-out over the mapped frontier, 2026-07-10c): 24/26 MATCH, | +| L3136 | §42e | propagating a CRACK ×134: the def-finder bug + the byte-drift residual (the "remap-fail" m | +| L3210 | §43 | The K&R s16-param definition DISSOLVES the "narrow-param wall" for by-value register args | +| L3257 | §44 | The Phase-25 cheap-Opus giant batch: 5 structural levers + the §43 extension (2026-07-11, | +| L3313 | §45 | The flagship `func_80133CD4` crack (399 ins ×134): the merged-variable permutation-breaker | +| L3328 | §46 | The `func_80178D40` crack (890 ins ×134, the heaviest core in the game): four LOOP-STRUCTU | +| L3380 | §47 | The live-length SLIDER: splitting a global.c allocno-priority TIE with one zero-byte asm ( | +| L3420 | §48 | The 12-core jr crack wave: the ALLOCNO-PRICING dials and the EBB rule (Phase 26 session 8, | +| L3428 | §3-A. | ALLOCNO-PRICING DIALS — move a value into the register you want, byte-neutrally | +| L3459 | §3-A4 | SINK THE CONSUMER CALL INTO THE ARMS (the inverse of A1; `func_8016AB6C`, byte-proven) | +| L3483 | §3-B. | THE EBB RULE — the general form of §46-L2 | +| L3499 | §3-C. | TYPE- AND SHAPE-DRIVEN CODEGEN (the C type literally selects the addressing mode) | +| L3523 | §3-D. | THE CROSS-JUMP RATCHET (the sharpest new trap — `func_80131340` L-C) | +| L3533 | §3-E. | Meta | +| L3542 | §49 | The LUID DIAL: a zero-byte SCHEDULING dial (the sched.c analogue of §47) — `func_8017A4AC` | +| L3591 | §50 | Refinements that BOUND §47/§48 (from the `func_80135EB0` wall, 21→6; Phase 26 session 8) | +| L3645 | §51 | TOOLING INTEGRITY: the silent skip, and how to hunt it | +| L3651 | §51a | The bug class | +| L3667 | §51b | Why the byte-gate cannot save you | +| L3677 | §51c | THE METHOD (do not audit by reading the regex) | +| L3692 | §51d | THE LAWS | +| L3754 | §51e | The false-wall pipeline (why this is not just hygiene) | +| L3770 | §51f | Checklist for any new corpus-scanning tool | +| L3784 | §51g | When the thing you are scanning has a GRAMMAR, parse the grammar (`tools/cdecl.py`) | +| L3928 | §52 | The WALKER-FAMILY skeleton: 6 regalloc-order levers + a deeply-characterized intrinsic wal | +| L3939 | §3-The | 6 levers (the "walker-family skeleton" — apply to the 12 siblings; levers 1-5 retire ~half | +| L3960 | §3-Why | the wall is (probably) intrinsic | +| L3974 | §52a | The regalloc sibling wave: new levers + two new wall classes (cheap-Opus applying §52, 202 | +| L4012 | §52b | Sibling wave 2: more de-pin levers, a third wall class, and the match_one→whole-binary gap | +| L4043 | §53 | SWEEP A FAMILY WITH THE TOOL ITS EXEMPLAR NEEDED: the jr/switch carve, and how omitting it | +| L4048 | §3-The | case | +| L4060 | §3-Why | 0/8 was structural, and predictable from two words | +| L4077 | §3-The | rule | +| L4093 | §3-The | meta-lesson (R35, and why this one is expensive) | +| L4108 | §55 | Core-crack wave levers + the GATE-ORCHESTRATION law (Phase 29 T3, 13-agent ultracode wave, | +| L4113 | §55a | New byte-proven levers (each from a banked or near draft) | +| L4137 | §55b | THE GATE-ORCHESTRATION LAW (3 traps, ~3.5h lost; all recovered, 0 data lost) | +| L4156 | §55c | Sizing the propagate: a TARGETED propagate is ~4 min/core, and "it's slow" was a BROKEN-TR | +| L4178 | §54 | `--fix-def-sig`: the member's CANONICAL DECLARATION is a build step too (tiny-IMM mega-poo | +| L4202 | §56 | Banking a hand-drafted GIANT into its exemplar TU: self-contained draft vs live-TU decls, | +| L4247 | §56b | PROPAGATING an h_seq giant: the exemplar's externs MUST be fleet-canonical, not the draft' | +| L4271 | §57 | The SELF-decl normalize: the sibling's OWN caller declares the templated fn divergently (t | +| L4318 | §57a | Two NSD corrections + the SURGICAL-ONLY law + the honest broad-sweep yield (Phase 29, 2026 | +| L4358 | §58 | match_one MATCH ≠ BANK: the four blind spots + the crack-wave reconcile-before-bank law (P | +| L4392 | §59 | Three h_seq sweep-residual classes match_one/the-exemplar-bank don't reveal (Phase 29 crac | +| L4422 | §60 | Classify the residual, don't rank it: the deterministic residual→class classifier and what | +| L4446 | What | it measured — the whole open backlog, byte-grounded | +| L4465 | §3-Two | corollaries worth remembering | +| L4478 | §3-The | parallel-probe race this surfaced | +| L4487 | §60a | What the first DIRECTED grinder run exposed (Phase 29 Task-13B, 2026-07-21) | +| L4525 | §60b | The plateau autopsy's verdict: a `partial` drift is a WRONG DRAFT, not a missing transform | +| L4560 | §61 | Task 14: the gate ladder's missing stage is the ARITY pre-pass, and it is TU-side not draf | +| L4621 | §61a | The Task-5 wave: 11/12 MATCH, 0 banked — three DISTINCT integration walls, each now named | +| L4673 | §61b | The jtbl gate stage: built, and the ORDERING law it exposed (Phase 29 Task-14 stage 4, 202 | +| L4728 | §61c | The jtbl bank is INCREMENTALLY valid and CLEAN-INVALID (Phase 29, 2026-07-21) — the blocki | +| L4794 | §61d | The undo was eating the tree: two tools, one defect, invisible to the byte-gate (Phase 29, | +| L4848 | §62 | The jtbl RECONCILE must also follow the carve: the post-carve draft reconcile (`harvest_ve | +| L4892 | §63 | The fresh-138 DEF-SIDE blocker: fix the HEADER decl, not the draft (`fix_header_decl.py`, | +| L4923 | §64 | The §20 type-lift's three laws: fold the tagged typedef, check VISIBILITY, and strip only | +| L4972 | §64a | VARIANT types: UNIQUIFY the camps, do not reconcile them (`uniquify_type.py`, Phase 29 SES | +| L5015 | §63 | UPDATE (Phase 29 SESSION-14) — `fix_header_decl`'s "SAFE" verdict is FLEET-BLIND; it MUST | +| L5030 | §65 | The stranded-draft recovery: BLAST-RADIUS TIERS, and the per-overlay de-macroize that refu | +| L5045 | §65a | The blast-radius taxonomy (makes §61's law structural instead of remembered) | +| L5060 | §65b | The escape: de-macroize the instantiation, don't touch the shared header | +| L5096 | §65c | `rtu_match` MATCH → bank held 13/13 on self-decl, but broke on the FIRST callee-decl case | +| L5106 | §65d | Existing-ladder baseline, measured (do this before building a recovery stage) | +| L5116 | §65e | Two oracles, and the disagreement is the finding (R34 in practice) | +| L5133 | §65f | The de-macroize lever's BOUNDARY, measured: byte-neutral 14 times of 15, and the 15th is w | +| L5154 | §65g | Where the cheap levers STOP: the local-type and in-TU-self-decl classes did not yield | +| L5174 | §66 | Exercise a banking driver's SUCCESS path before pointing it at a wave: the free re-bank te | +| L5196 | §66a | The widest write in a pipeline is the one most likely to be UNDECLARED | +| L5215 | §66b | A metric parsed out of another tool's prose goes NULL silently when the label changes | +| L5232 | §66c | Before a wave, verify the FUEL exists; an "already attempted" set built from the wrong dir | +| L5260 | §66d | The permuter⇄reader loop: alternate a random search with a byte-verified idiom, and let `r | +| L5295 | §66d-1 | What transfers between giants is the LOOP, not the PIN | +| L5304 | §66d-2 | Two operational sharp edges | +| L5315 | §66d-3 | Read the ILS per-cycle SERIES, not its final best: a repeated score and a still-falling on | +| L5330 | §67 | The arg-copy PLACEMENT lever: launder a parameter into a fresh pseudo AT the statement whe | +| L5420 | §67a | Run the symbol-set guard BEFORE you pay for a gate (`tools/symcheck.py`, Phase 29 SESSION- | +| L5453 | §66d-4 | "ILS converged" means converged FOR THAT WEIGHT PROFILE, not a floor (amends §66d-3; Phase | +| L5506 | §66d-5 | `residual_class`'s "structural ⇒ permuter CPU is waste" is WRONG for schedule permutations | +| L5539 | §68 | A comment-only line halted the extern scan, and the skip label blamed the type cap (Phase | +| L5584 | §69 | How to attack a behemoth: map it, don't draft it (Phase 29 SESSION-18, `func_80183814`, 5, | +| L5634 | §70 | The giv-init base register: walk the PARAMETER, not a copy of it (Phase 29 SESSION-18, `fu | +| L5675 | §71 | Before mapping a giant, look for an already-matched SIBLING beside it (Phase 29 SESSION-18 | +| L5741 | §72 | A `register __asm__` pin is a PREFERENCE, not a reservation (Phase 29 SESSION-18, `func_80 | +| L5765 | §3-The | honest fix was source-level and cheap | +| L5775 | §3-Giv | record order (the §70 family) | +| L5781 | What | is left, and what is byte-recorded as SPENT | +| L5798 | §73 | A def-side self-decl conflict has TWO axes: RETURN (fleet widen, T2) and PARAMS (casts at | +| L5837 | §74 | Auditing a pinned draft: the §72 hazard is CALLER-SAVED pins spanning a call, and only the | +| L5881 | §75 | A propagation cap is usually a MINORITY-SPELLING SOURCE OVERLAY, not a wall: census the ca | +| L5940 | §75a | The exclusion classes, enumerated with named causes (Phase 29 SESSION-19, the 134-binary ` | +| L5963 | §75b | A body's preamble can carry `#define`s, not just `extern`s; extraction lifts only the exte | +| L6012 | §75c | Class-B's remedy is the FULL §17a-1 PAIR (decl **and** call-site cast); a decl-only fix mo | +| L6043 | §76 | The allocno CLASS (local vs global) is the dominant regalloc lever, and C reaches it ONLY | +| L6052 | §3-The | mechanism, with citations | +| L6072 | §3-The | attribution primitive (use this before calling anything a scheduling residual) | +| L6079 | §3-Two | diagnosis traps this function proved | +| L6089 | Practice | Practice | +| L6099 | §77 | Every extraction tool carries a NARROW hard-coded preamble set; anything outside it silent | +| L6139 | §3-The | CANDIDATE gate and the REAL gate need DIFFERENT preambles — keep the difference out of the | +| L6189 | §78 | A LENGTH drift can be a register grant in disguise; and `fold` never leaves a literal firs | +| L6195 | §3-The | drift was an allocation decision, not missing code | +| L6226 | §3-The | economics | +| L6235 | §79 | For a 0-callee giant, fingerprint by DATA symbols (§71 cannot fire); and the STACK-SLOT OR | +| L6241 | §71 | has a blind spot, and this is it | +| L6255 | §3-NEW | LEVER — the frame layout reads back the original declaration order | +| L6266 | §76 | confirmed at scale, and a pin nuance | +| L6275 | §3-The | residual, and the honest read | +| L6285 | §80 | A do-not-re-buy entry is scoped to its BASE, not to the function; and the pin's hidden cos | +| L6306 | §3-The | pin's hidden cost, with the citation | +| L6317 | §3-The | flagged "#1 move" LOST — and why the failure is informative | +| L6327 | §78 | 's attribution primitive, run and reproduced | +| L6333 | Cold-start | economics, now complete | +| L6338 | §81 | Banking a jr (jump-table) function: the 3-step carve chain, and why `match_one` cannot see | +| L6369 | §3-The | defect this exposed: a shared type that is present but invisible | +| L6385 | §82 | Two source-shape oracles from behemoth #6: a duplicated `addiu $aN,$sp,K` across a `jal` m | +| L6390 | §3-1. | The inlined-helper signature | +| L6404 | §3-2. | Scalar vs aggregate decides *when* the slot is allocated | +| L6416 | Also | reproduced on this function | +| L6420 | §3-And | the banking footnote (§75a class A, one line) | +| L6427 | §83 | The parameterised-repeat law, the spill-area trap, and why a per-case edit cannot move a p | +| L6434 | §83a | READ THE HEADLINE NUMBER CORRECTLY: a LENGTH drift makes `match_one`'s count meaningless | +| L6442 | §83b | THE LEVER: find the parameterised REPEAT before decoding case-by-case | +| L6460 | §83c | TRAP: a "dead local" in a prior draft may be gcc's OWN spill area | +| L6467 | §83d | CSE's quantity budget is WHOLE-FUNCTION, so a local rewrite cannot fix a local symptom | +| L6481 | §83e | §80 vindicated again, on the same day it was written | +| L6487 | §84 | The DERIVED-OFFSET remap bug: a hand-computed literal that encodes the DISTANCE between tw | +| L6492 | §3-The | construct | +| L6510 | §3-Why | it survived every candidate gate | +| L6525 | §3-THE | FIX IS MECHANICAL — the tool already holds the answer | +| L6533 | Scope | , measured (do not over-generalise — §80) | +| L6543 | §3-Two | ladder lessons banked with it | +| L6554 | §85 | The RETURN-axis fleet widen is ALL-OR-NOTHING: widening the shared header alone guarantees | +| L6559 | §3-The | conflict | +| L6567 | §3-THE | FAILURE MODE — widening only `engine_core.h` is worse than not starting | +| L6574 | §3-The | precondition, and how to check it in one grep | +| L6582 | §3-Do | the WHOLE axis in one edit, then R22 once | +| L6591 | Reading | , for the next person | +| L6604 | §86 | Pinned-exemplar templatability is a PER-FAMILY property, not a per-member rate; and the §4 | +| L6606 | §3-The | guard refuses a class that largely works | +| L6615 | §3-THE | LAW: all-or-nothing PER FAMILY | +| L6642 | §3-Why | the two live families differ from the three dead ones — the open question | +| L6648 | §87 | `match_one` COMPILES but never LINKS, so an unresolvable data symbol reads as MATCH; and s | +| L6664 | §3-The | blindness ladder, now complete — FOUR classes `match_one` cannot see | +| L6674 | Consequence | for the backlog ledger | +| L6681 | §3-The | cheap discriminator, before spending a sweep | +| L6689 | §88 | `cross_jump` will not merge a common suffix containing a CALL; and §78 is scoped to ORDERE | +| L6694 | §88a | repeated CALL-shaped blocks are left UNMERGED; call-free tails are merged for you | +| L6701 | §88b | the `slti` literal-position law (extends §78 to comparisons) | +| L6716 | §88d | BANKING ORDER: run the §81 carve chain BEFORE banking, never after | +| L6723 | §88e | a wrong diagnosis, refuted properly (the model for how to treat an inherited lever) | +| L6733 | §88f | the missing rung: a RELOCATION gate between `match_one` and the binary | +| L6741 | §89 | Two throughput rules the project already had written down and was not following (Phase 29 | +| L6747 | §89a | MEASURE the write set; do not assert its tier (`tools/blast_radius.py`) | +| L6760 | §89b | the parallel gate farm existed; the family path could not reach it (`tools/sweep_parallel. | +| L6773 | §3-The | standing sequence | +| L6781 | §90 | Five tool-integrity laws from one session, each of which changed an answer (Phase 29 SESSI | +| L6787 | §90a | A comparison tool MUST share its reference oracle's index space, exactly | +| L6804 | §90b | "Byte-neutral" is not "wanted": undo on the SUCCESS path too | +| L6814 | §90c | A library-callable function must FAIL CLOSED on an unconfigured module | +| L6825 | §90d | Do not measure a live wave's drafts (§87 in real time) | +| L6833 | §90e | An agent's CONCLUSION and its EVIDENCE fail independently — re-derive the premise, not the | +| L6857 | §91 | A structure-TRANSFER is only valid where the structure corresponds: the `--like` role trap | +| L6886 | §3-The | three-hypothesis trail, because two of them were wrong and the wrongness is instructive | +| L6906 | §92 | Conforming a DECLARATION: pointer changes are caller-neutral, scalar-WIDTH changes are not | +| L6937 | §93 | `set -o pipefail` attributes a pipeline failure to the LAST stage, not the failing one (Ph | +| L6962 | §94 | A family sweep's `0/N` is a TYPE-CARRY failure until proven otherwise: lift the exemplar's | +| L6998 | §95 | `reconcile_tu` dropped the SIBLING declarators of a multi-symbol `extern` line (Phase 29 S | +| L7033 | §96 | The same rewrite, one shape down: `reconcile_tu` matched statements to lines by TEXT, so e | +| L7081 | §97 | The gate's own tree hygiene: a refused carve, an unchecked recovery, and a snapshot that c | +| L7128 | §98 | `conform_decls` had three defects, and only the third needed R22 to find (Phase 29 SESSION | +| L7182 | §99 | The narrow-param wall is a DEF-side problem with a ZERO-blast-radius fix: convert the defi | +| L7205 | §3-Two | `reconcile_tu` bugs found underneath, one introduced while fixing the other | +| L7231 | §100 | Prefer the DRAFT-LOCAL fix: a type only one function uses belongs in its BODY, not in a sh | +| L7260 | §101 | The STALE DEFAULT class: a guard whose cause was removed is a silent skip wearing a safety | +| L7287 | §102 | A PLUMBING verdict can MASK a DIFF; and K&R is not always a codegen change (Phase 29 SESSI | +| L7322 | §103 | A FILE-scope `extern` in a shared overlay TU is a GLOBAL constraint on every LATER functio | +| L7410 | §104 | Two silent-skip defects in one scan: match on MASKED text, emit from the ORIGINAL (Phase 2 | +| L7446 | §105 | A gate's revert must survive an EXCEPTION, not just a failure (Phase 29 T53, `jtbl_family_ | +| L7485 | §106 | Persist the MEASUREMENT, derive the POLICY: a stored route let a stale file out-vote the l | +| L7528 | §107 | A lever wired into ONE gate path is a lever most families cannot reach (Phase 29 T56, `fun | +| L7566 | §108 | Diagnosing a family `0/N`: the four causes, and the third opt-in lever (Phase 29 T59) | +| L7615 | §109 | Conforming a definition to a shared header: fix the NAMES, then check the RETURN precondit | +| L7655 | §110 | A unit must define exactly ONE function, and "ends in `;`" does not tell you which line de | +| L7696 | §111 | The distinct-code metric is not noisy: a family pays it only if its members are byte-VARIA | +| L7745 | §112 | A macro-scoped declaration only collides where the macro is INSTANTIATED (Phase 29 T67/T69 | +| L7791 | §113 | An ARITY blocker only exists if the macro CALLS the function; an address-taken use has no | +| L7823 | §114 | The THIRD decl axis: a CALLEE the draft declares differently from the target TU (Phase 29 | +| L7865 | §115 | A `func_XXXXXXXX` predicate rots by design: the same name-form assumption in THREE places | +| L7892 | §116 | Optimization level is a property of the FILE, not the function: read a family 0/N against | +| L7910 | §3-The | fix moves the DEFINITION, not the stub — and here is why the obvious shortcut fails | +| L7941 | §117 | Spell the sibling's symbol from the SIBLING's address, not the exemplar's kind (Phase 29 T | +| L7968 | §3-Why | it survived so long: a MASKED oracle will MATCH a wrong symbol | +| L7978 | §118 | Ordinal (positional) immediate resolution: compare C tokens to the DIFFERING asm uses (Pha | +| L8012 | §119 | Two levers on the SAME axis, opposite directions: test the off-diagonal (Phase 29 T89) | +| L8041 | §120 | Uniquify draft-defined TYPE names; and check which of N staging sites you actually patched | +| L8052 | §3-Do | NOT "strip the duplicate typedef" — it breaks the extern that uses it | +| L8058 | §3-The | wiring trap that cost two attempts | +| L8076 | §121 | Synthesise externs for macro-DEFINED callees from the macro's own definition head (Phase 2 | +| L8099 | §122 | GATE RAW BEFORE TRANSFORMING; the undo belongs to the WRITER, as a per-edit journal (P30 T | +| L8131 | §123 | PROPAGATE A FAMILY WITH THE TOOL ITS TIER NEEDS: `dedup_propagate` is h_exact-only; its re | +| L8168 | §124 | A "not matched" verdict can mean the definition is there under a DIFFERENT C NAME: the asm | +| L8213 | §124a | a family sweep's `0 matched-exemplar families` may be a FILTER, not a wall | +| L8221 | §125 | Split the CARVE from the BODY before calling a jr residue a wall — and measure it by SHA f | +| L8228 | §3-The | method (keep this) | +| L8238 | §3-The | instrument rules that make its answer trustworthy (this is where I failed) | +| L8253 | §3-The | corrected results (each SHA-verified, from a clean tree, restore re-verified) | +| L8263 | §3-Two | further notes worth keeping | +| L8272 | §3-The | meta-lesson | +| L8279 | §126 | The carve-within-a-carve: an ADDRESS RANGE is not an OPTIMIZATION REGION (P30 T2, byte-pro | +| L8294 | §3-The | finding: opt level is per FILE, so the file's contents must be opt-HOMOGENEOUS | +| L8305 | §3-The | instrument trap that hid it (and it is §124's shape again) | +| L8314 | §3-The | mechanics | +| L8332 | §126a | a bare `except: continue` around a coverage-asserting oracle re-creates the silent skip (P | +| L8364 | §127 | The `-O0` regime: the CONSTANT-OFFSET FOLD, and why `-O0` needs its own idiom set (P30 T3 | +| L8371 | §3-The | idiom they kept re-deriving: the constant-offset fold | +| L8382 | §3-The | rest of the `-O0` regime (write PLAIN C, and mean it) | +| L8392 | §127a | §71 (sibling-first) is the strongest `-O0` lever, and it beats the index | +| L8401 | §127b | the knowledge was in a SOURCE COMMENT, not the cookbook | +| L8408 | §128 | A raw NUL in C source makes grep SILENTLY SKIP the file (P30 S28, 137 files) | +| L8440 | §128a | a negative control must corrupt a SCRATCH COPY, never the tracked file | +| L8452 | §129 | Post-carve, `rtu_match`/`match_one` COUNT THE JUMP TABLE AS INSTRUCTIONS; and a carve must | +| L8456 | §129a | the target instruction count is INFLATED after a carve | +| L8477 | §129b | never commit a carve whose owner is still a stub (it strands the carve) | +| L8492 | §3-The | real blocker underneath, for the record | +| L8501 | §130 | An INCREMENTAL build can report BYTE-IDENTICAL for a change the CLEAN build cannot even LI | +| L8538 | §3-The | diagnostic ladder that finally located it (reusable) | +| L8548 | §131 | The jtbl OVER-SPAN: `sltiu N` is ground truth in BOTH directions, and the zero-word rule o | +| L8585 | §132 | The `JR-PAIR-IN-ONE-O0-OBJECT` "wall" was TWO instrument defects: a merged-double span the | +| L8594 | Defect | 1 — a pre-§8e MERGED DOUBLE is not a single-table predecessor | +| L8612 | Defect | 2 — `as` writes a corpse and nothing deletes it | +| L8622 | §3-The | fingerprint, and the 30-second ladder that found it | +| L8643 | §3-The | transferable rule | +| L8650 | §132a | `--like` is for a sibling with NO record; against one that HAS a record it over-derives (P | +| L8675 | §132b | When the span's already-matched owner is ITSELF multi-switch: `--span-rel` (P30 S1, `func_ | +| L8700 | §133 | The DEFAULT-FILTER class: three times in one session, a tool silently answered a narrower | +| L8726 | §134 | MULTI-LINE BLINDNESS: one root cause, four faces, in `family_remap`'s preamble scanner (P3 | +| L8780 | §135 | Six byte-verified gcc-2.7.2 idioms from the P30 S6f-h waves (and the two-lane wave shape t | +| L8785 | §3-The | codegen idioms | +| L8819 | §3-The | integration idioms (these decide whether a byte-correct draft BANKS) | +| L8834 | §3-The | wave shape that produced these | +| L8852 | §136 | The LOCAL-VARIABLE lever: how many C locals, at what scope (P30 wave 4a, 25 byte-verified | +| L8868 | §3-The | splitting/merging rules (each closed a residual, byte-gated) | +| L8894 | §3-The | type-form rules | +| L8927 | §3-The | scheduling rules (refining §135-2 and §135-4) | +| L8956 | §3-The | declaration surface (integration, not codegen) | +| L8968 | Wave | economics (measured, for the next batch's sizing) | +| L8991 | §136a | Blocker capture: classify on the OUTPUT, never on the exit status | +| L9048 | §136b | A prior wave's "genuine byte-DIFF" verdict is NOT reliable evidence (4 of 4 refuted) | +| L9084 | §136c | SIBLING-FIRST is a DERIVATION shortcut, not just a conflict fix (the fastest route in a fa | +| L9109 | §136d | Four gcc-2.7.2 levers the redraft lane found (each closed a residual no other lever moved) | +| L9153 | §136e | §136c's PRECONDITION, and two more symptom keys (wave 4b batch 3) | +| L9201 | §136f | Two declaration sub-cases the reconcile lane surfaced (lane now 15/15 lifetime) | +| L9226 | §136g | When the index points at the WRONG lever: two byte-refuted routings (func_801863B4) | +| L9255 | §136h | CORRECTION: the zero-crack pool does NOT "refill with cheap work" (my error, byte-measured | +| L9285 | §136i | The drafter model LADDER: Haiku → **Sonnet** → Opus → Fable5 (Drew, 2026-08-03) | +| L9317 | §136j | The failure MIX flips with function size (measured across four bands, one session) | +| L9359 | §137 | REGALLOC-PERM is a TWO-COMPILE ARITHMETIC PROBLEM, not a permuter job | +| L9401 | §137a | A gate verdict has a TIMESTAMP; re-check it against the draft's mtime | +| L9430 | §138 | The propagation lanes: a gate refusal is a DECLARATION, and which lever you owe depends on | +| L9436 | §3-The | triage, cheapest first | +| L9488 | §3-The | DEFINITION-side alias is the only escape when the fleet canon disagrees on a promoting par | +| L9496 | Rank | the lane by measured concentration, not by class count | +| L9505 | THREE | carry variants hide in one "CARRY-FIXABLE" bucket — and they need different fixes | +| L9541 | §134 | again, in a second tool — and the waiter rule corrected | +| L9561 | STEP | 0 of sibling-first: grep `src/` for a distinctive LITERAL from the `.s` | +| L9580 | Reconciling | a gate-refused draft: which way you edit depends on WHERE the TU's decl is | +| L9609 | §139 | A GATE THAT GREPS FOR VERDICTS MUST ASSERT 1:1 ACCOUNTING; and a `--src` filter must not s | +| L9641 | §3-The | generalisation — three corollaries worth more than the bug | +| L9658 | §3-And | the inverse-lookup trap, same session | +| L9675 | §140 | A METRIC IS NOT A MEASUREMENT UNTIL IT IS REPRODUCIBLE FROM THE COMMITTED TREE (P30 S1e: a | +| L9695 | §3-The | three-line proof (do this before diagnosing any metric movement) | +| L9704 | §3-The | two instrument defects it exposed | +| L9724 | §3-The | same swallow, twice more, in the integration spine | +| L9735 | §3-Two | wrong mechanisms I chased first, and why they were wrong | +| L9755 | §141 | The §134 class is CLOSED: every line-shape decision now routes through `cdecl._mask` (P30 | +| L9793 | §142 | An open stub whose `h_exact` class is MATCHED elsewhere is FREE. Propagate the body; do no | +| L9805 | §3-The | measurement (do this before any wave; it is ~20 lines and needs no builds) | +| L9820 | §3-The | trap that hid it — SAME FUNCTION, TWO ROUTES, ONLY ONE IS FREE | +| L9829 | Route | selection (why `--addr` sometimes says "nothing changed") | +| L9837 | §3-And | the report-vs-bytes lesson attached to it | +| L9849 | §143 | `cast_call_sites` read a RETURN STATEMENT as a prototype and deleted it. A 0/39 sweep beca | +| L9903 | §144 | THE LITERAL'S SPELLING PICKS THE IMMEDIATE ENCODING (P30 S40 wave 1, `func_801822E0`) | +| L9942 | §145 | Three loop/combine levers from the S40 wave-2 drafters (16/16 match_one) | +| L9992 | §146 | RE-MEASURE A WALL BEFORE YOU RESPECT IT. Both "permanent" giants fell to drafts already on | +| L10003 | §3-Why | a correct draft can read as an intrinsic wall | +| L10015 | Then | propagation returned 0/137 TWICE — both times a missing TYPE | +| L10024 | §3-Two | errors of mine, both instructive | +| L10038 | §3-The | rule | +| L10051 | §147 | The three-stratum FRAME LAW, and four "stop searching" verdicts (P30 S42, `func_8017C294`, | +| L10056 | §3-A. | The frame has THREE strata, and stratum 3 is unreachable from C | +| L10072 | §3-B. | A `?:` on MEMORY operands costs ~16 bytes of invisible frame; on REGISTER operands, zero | +| L10083 | §3-C. | Inner-block declaration does NOT delay slot allocation — BYTE-REFUTED | +| L10088 | §3-D. | A lone `$t8`/`$t9` in the target is RELOAD SCRATCH — reproduce the spill, don't pin the re | +| L10098 | §3-E. | A `qty_compare` TIE is not spelling-reachable — recognise it and stop | +| L10110 | Consequence | for the family (a real scheduling decision) | +| L10160 | §148 | The loop.c hoisting THRESHOLD is arithmetic you can compute, and the `?:` clamp that folds | +| L10166 | §3-A. | `move_movables` hoists iff `threshold × savings × lifetime ≥ insn_count` — and you can rea | +| L10185 | §3-B. | `(v < 0x40) ? v : 0x3F` is folded to `MIN_EXPR` and expands to the WRONG SHAPE | +| L10199 | §3-C. | A zero-byte ALLOCNO-PRIORITY slider | +| L10209 | §3-D. | Reproduce the original's BUGS verbatim | +| L10258 | §149 | Four instrument defects in one session, and the two questions they were hiding (P30 S43) | +| L10264 | §3-A. | A prep step that returns its input on failure is indistinguishable from a search that foun | +| L10282 | §3-B. | Same address + same name ≠ same body — and the ledger keys on address | +| L10298 | §3-C. | `make: *** [...] Error N` is a summary, never a diagnosis | +| L10308 | §3-D. | "Cheap fuel" that was never probed: 0 of 31 templatable | +| L10327 | §150 | A register ROTATION across symmetric blocks is VARIABLE-IDENTITY evidence, not an allocato | +| L10334 | §3-The | fix | +| L10344 | §3-The | method that found it (this is the transferable part) | +| L10360 | §3-Two | corrections to the record | +| L10371 | Diagnostic | order (adopt this) | +| L10382 | §151 | THE GHOST WEDGE: when a load-before-store transposition is unreachable by ANY statement or | +| L10387 | §3-The | mechanism (read from cc1's own `-dR` trace, not inferred) | +| L10402 | §3-The | lever — a zero-emission insn that absorbs the blocked tick | +| L10410 | §3-The | two fallouts, and how to close them (both measured, in order) | +| L10422 | When | to reach for it | +| L10433 | §152 | BYTE SIZE is the family key that name- and h_seq-grouping both miss (P30 S43, the 0xECC fa | +| L10438 | §3-The | finding | +| L10447 | §3-The | key | +| L10458 | §3-Two | cautions that must travel with this technique | +| L10469 | §3-The | companion defect (open) | +| L10481 | §153 | THE ADDRESS-REMATERIALISATION LAUNDER: a third zero-emission asm lever (P30 S43, `func_801 | +| L10489 | Symptom | Symptom | +| L10494 | Mechanism | (gcc source + RTL dumps, not inferred) | +| L10501 | What | does NOT work (14 byte-measured probes) | +| L10507 | §3-The | cure — a fresh launder per site, each in its own block | +| L10517 | Companion | levers from the same function | +| L10537 | §154 | Reading a disc payload: the module-id word, static base derivation, and "type 1 = uncompre | +| L10542 | §3-A. | Payload word0 is a global MODULE ID; code starts after the header | +| L10551 | §3-B. | Two static base-derivation methods that must AGREE (use both) | +| L10563 | §3-C. | PAC type 1 = the same payload class as type 4, just NOT compressed | +| L10573 | §155 | hi/lo literal scanning MUST track base registers (S45) | +| L10582 | §155a | the same failure class, one level up: SHAPE-blind table scanning (S45 p5) | +| L10602 | §155b | check the TYPE your oracle returns before comparing against it (S45 p5) | +| L10625 | §155c | the ZERO-REFERENCE trap: gcc splits a global-array address across the `lui` and the LOAD ( | +| L10655 | §156 | an ORPHANED reconcile poisons the fleet: `dedup_propagate`'s kept edit (S45 p6/p7) | +| L10702 | §157 | the cheap-tier size cliff, measured (S45 p6) | +| L10727 | §158 | The RANGE-EXTENDER: a fourth zero-emission asm lever completes the allocno toolkit (P30 S4 | +| L10736 | Symptom | Symptom | +| L10742 | §3-Why | the fork is chained (gcc source, validated insn-by-insn against -dS/-dR dumps) | +| L10755 | §3-The | method (dump-arithmetic first, then place — no probing) | +| L10772 | Bonus | facts worth keeping | +| L10787 | §156 | THE PREFERENCE-DONOR MERGE: cross-region variable reuse is what fills a0-a3, and a call-ar | +| L10843 | §159 | THE DECLARATION AXIS: conform to byte-truth, and make every guard state its COVERAGE (P30 | +| L10908 | §160 | THE REACH-15 WAVE HARVEST: an align-1 block move, and the instrument that called it a wall | +| L10984 | §161 | THE RETRY-WAVE HARVEST: a jump table indexed from zero, and two allocator traps (P30 S47) | +| L11029 | §162 | S48 WAVE-1 HARVEST (P30, 2026-08-11): the reach-ordered sibling campaign's first 12 target | +| L11056 | §162a | SHARPENS *(sharpens §161a, §131, §8a-pad, §129a)* | +| L11085 | §162b | SHARPENS *(sharpens §48-A3, §156, §150, §76)* | +| L11114 | §162d | SHARPENS *(sharpens §31, §21, §30, §55a)* | +| L11156 | §162e | NEW | +| L11158 | §162 | THE LICM PAIR: what makes an address a movable AT ALL, and why the preheader order is the | +| L11224 | §162f | SHARPENS *(sharpens §42d, §41d, §73, §10)* | +| L11279 | §162g | NEW | +| L11281 | §162 | CROSS-JUMP DIRECTION: the surviving copy is always the LATER one, so a BACKWARD `j` into a | +| L11315 | §162h | SHARPENS *(sharpens §88, §88a, §50-B, §8)* | +| L11317 | §162 | The cross-jump "CALL veto" is a COUNT law, not a CALL law (BOUNDS §88a; P30 S48, `func_801 | +| L11383 | §162i | SHARPENS *(sharpens §135, §21, §42, §32)* | +| L11408 | §162j | SHARPENS *(sharpens §25, §136d-1, §48-B, §46-L2)* | +| L11437 | §162k | SHARPENS *(sharpens §1-I2, §12, §160d, §21)* | +| L11500 | §162l | SHARPENS *(sharpens §48-B, §48-C1, §20, §21)* | +| L11555 | §162m | SHARPENS *(sharpens §36, §158, §148, §153)* | +| L11557 | §158a | THE FIFTH LEVER IS NOT AN ASM: `do { } while (0)` is a REGION ref-multiplier you MINT (P30 | +| L11564 | §3-The | law | +| L11575 | Size | it before you write it (§158 step 1-2, applied) | +| L11596 | §3-The | wrap BOUNDARY is the dial — and it is indiscriminate | +| L11602 | §3-Not | a pure dial | +| L11606 | DIAGNOSTIC | TELL — two faces, one law | +| L11628 | §162n | NEW | +| L11661 | §162o | SHARPENS *(sharpens §158, §136-1, §136-6, §79)* | +| L11720 | §162p | SHARPENS *(sharpens §48-B, §46-L2, §156, §136d-1)* | +| L11737 | §162q | SHARPENS *(sharpens §30, §30a, §135-2, §136-13)* | +| L11775 | §163 | S48 WAVES 2-3 HARVEST (P30, 2026-08-11/12): the five that were byte-probed and are actiona | +| L11843 | §163z | THE UNVETTED REMAINDER (do not cite as law; each needs a dedupe pass) | +| L11863 | §164 | S48 §163z SKEPTIC PASS (P30, 2026-08-12): 190 claims vetted, 82 banked | +| L12315 | §16Xy | SHARPENS *(sharpens §136d-3, §37 /s-DEP LATTICE, §135-2, §136-13, §162q)* | +| L12317 | §3-The | `/s` drop clause is in ALL THREE dependence predicates, so the FIXED-ADDRESS STORE is what | +| L13651 | §164z | REFUTED CLAIMS: do NOT re-derive these | +| L13717 | §165 | S48 WAVE-4 HARVEST (P30, 2026-08-12): banked the same day the wave landed | +| L14368 | §16Z | SHARPENS *(sharpens §37 "the /s-DEP LATTICE", §136-13, §136-14, §16Xy, §162q, `gcc-2.7.2- | +| L14370 | §3-The | ADDRESS-CLASS TABLE: which load/store pairs even REACH the `/s` clause (P30 S48 wave 4, `f | +| L14886 | §165z | REFUTED THIS WAVE: do NOT re-derive | +| L14930 | §166 | THE DESTINATION-TU ORACLE (P30 S48): the seven-attempt bug that was never codegen | +| L14986 | §167 | S48 WAVE-5/6 HARVEST (P30, 2026-08-12): the saturation point | +| L16182 | §167z | REFUTED IN WAVES 5/6: do NOT re-derive | +| L16239 | §168 | THE COUSIN TIER (P30 S49, 2026-08-12): h_seq's exact-hash brittleness, measured — and the | +| L16291 | §169 | THE MICRO-ADAPT LANE (P30 S49): edit a proven body, don't crack a new one | +| L16338 | §170 | THE A-PROP WORD-DIFF CARD (P30 S49): the lane that had no owner | +| L16382 | §171 | THE STALE SEED SYMBOL (P30 S50, 2026-08-13): why §170's 91%→57% was never codegen | +| L16448 | §171a | THE MECHANICAL A-PROP DRAFT (P30 S50): 256 members banked with no agent in the loop | +| L16498 | §171b | THREE CARRIES THE MECHANICAL DRAFT NEEDS (P30 S50, banking the top-reach families) | +| L16531 | §172 | THE ORPHAN-SLOT MECHANISM v2 (P30 S50-Max): the complete frame-residue model for gcc-2.7.2 | +| L16585 | §172a | TWO DECOMPILATION TELLS FROM THE SAME DIG (P30 S50-Max) | +| L16601 | §172b | THREE MORE TELLS FROM THE GCC READ (P30 S50-Max, banked on Drew's ask) | +| L16644 | §173 | THE STORED-PLUMBING RECOVERY RECIPE (P31 T6): symfix-first, per-group isolation, and where | +| L16680 | §174 | THE ADAPT-CARD WAVE RECIPE (P31 waves A/B, 2026-08-14): prevention beats recovery | +| L16750 | §175 | A CALLER-SAVED REGISTER PIN CAN BE A CORRECTNESS BUG, NOT JUST A SCHEDULING CHOICE (P31 wa | +| L16775 | §176a | THE VERIFICATION-LAYER LAWS (P31 overnight, 2026-08-15). What each check can and cannot pr | +| L16815 | §176b | BATCH-GATING MECHANICS (P31): what changes when N drafts land in ONE .c | +| L16841 | §176d | THE CONFLICT TABLE MUST BE SEEDED FROM THE TU, AND KEYED PER FILE (P31 S52, 2026-08-15) | +| L16880 | §176e | SYMBOL IDENTITY IS COMPUTABLE OFFLINE (P31 S52): `tools/reloc_identity.py` | +| L16937 | §176f | THE DECLARATION FORM IS A MATCHING LEVER, SO RECONCILE TOWARD THE FORM THE MATCH NEEDS (P3 | +| L16968 | §176g | SIZE A WAVE BY INSTRUCTIONS, NOT BY CARDS (P31 S52 — the adopted doctrine) | +| L17006 | §176h | THE BATCH-SUBSTITUTION HAZARD MAP (P31 S52): seven holes, three wrong fixes, one law | +| L17014 | §3-A. | The seven under-reporting holes (all in `gate_main`, all the same shape) | +| L17032 | §3-B. | Typedef handling — the only strategy that survives contact | +| L17054 | §3-C. | The limit that remains (recorded, not solved) | +| L17061 | §3-C2. | RECONCILE BEFORE THE FIRST GATE — a parked draft gets HARDER to bank, not easier | +| L17084 | §3-D. | The measured cost shape, and what to build next | +| L17102 | §176i | WHAT A STATIC PRE-GATE CHECK CAN AND CANNOT PROVE (P31 S52, wave Q) | +| L17134 | §176j | STOPPING A WAVE MID-FLIGHT COSTS THE IN-FLIGHT TAIL (and how much is recoverable) | +| L17160 | §176j-2 | THE REPAIR PASS, MEASURED (do this instead of resuming) | +| L17180 | §176k | TWO SELECTOR BUGS THAT SILENTLY SHRINK A WAVE | +| L17197 | §177 | 🔴 THE EPILOGUE RETURN-DELAY SLOT IS DECIDED BY YOUR SAVED-REGISTER SET, NOT BY SCHEDULING | +| L17254 | §178 | SIX LEVERS MINED FROM THE WAVE-P JOURNALS (P31 S52), each byte-proven and source-cited | +| L17266 | §3-A. | THE `$0`-ADD OPAQUE COPY defeats `make_regs_eqv` (func_80033398, 93 ins) | +| L17282 | §3-B. | A `return ` IS A PRIORITY-1 HARD-REG SET THE SCHEDULER PLACES FIRST (func_8001BE30, | +| L17295 | §3-C. | SINGLE-SET TEMPS GET THE BIRTHING BOOST (func_8001D3FC, 196 ins) | +| L17303 | §3-D. | A NARROW TYPE BLOCKS COPY ELISION (func_8001D3FC — new idiom) | +| L17310 | §3-E. | THE ZERO-OFFSET ALIAS HOLE (func_80037028, 71 ins) | +| L17319 | §3-F. | `MEM_IN_STRUCT_P` ASYMMETRY IN `true_dependence` (func_80037144, 124 ins) | +| L17325 | §3-G. | TWO MODELLING TRAPS THAT COST THESE AGENTS SWEEPS OF HUNDREDS OF COMPILES | +| L17341 | §179 | IDIOMS MINED FROM THE WAVE P/Q JOURNALS (P31 S52, harvest pass) | +| L17351 | §179-A | 🔴 A LOOP-WALKED POINTER **PARAMETER** HANDS ITS ARGUMENT REGISTER TO THE GIV (9 byte-proof | +| L17400 | §179-B | 🔴 THE HAND-WRITTEN-ASM TRANSCRIPTION CHECKLIST (maspsx + masked_diff; 10 byte-proofs) | +| L17450 | §179-C | 🔴 A FUNCTION WITH NO EPILOGUE (falls into a sibling's shared tail) MUST BE FILE-SCOPE `__a | +| L17501 | §179-D | `gte_stflg` MUST CLOBBER `"$12"` OR THE WHOLE TEMP FILE ROTATES BY ONE | +| L17521 | §179-E | A `>2*MAX_MOVE_BYTES` BLOCK COPY IS A **STRUCT ASSIGNMENT**, NOT A HAND LOOP | +| L17547 | §179-F | PINNING A LOOP-WALKED POINTER IS A TOTAL OFF-SWITCH FOR STRENGTH REDUCTION | +| L17570 | §179-G | 🟡 A PIN CAN **CREATE** A COMBINE `LOG_LINK` AND DELETE AN `andi` (sixth RC-5 channel, n=1) | +| L17597 | §179-H | A MID-BODY `.global LABEL` PAIR SLICES A BYTE-COMPARABLE FRAGMENT OUT OF A LARGER ROUTINE | +| L17620 | Considered | and NOT banked | +| L17637 | §176c | MAIN (SLUS_007.26) CANNOT BE GATED INCREMENTALLY | +| L17648 | §176 | SEVEN LEVERS FROM THE P31 OVERNIGHT WAVES (2026-08-15): statement order, false regalloc, a | +| L17654 | §176-A | "SCHEDULE / DELAY-SLOT / LENGTH-DRIFT ±1" ⇒ check STATEMENT ORDER around the call first | +| L17678 | §176-B | "REGALLOC-PERM, 1-4 instructions off" ⇒ it is usually NOT register allocation | +| L17724 | §176-C | 🔴 WALL REFUTATION: a hard-register pin CANNOT schedule around a call, because of a genuine | +| L17750 | §176-D | CSE-class levers used in reverse (two sharpenings of §153 and cse_expr §2) | +| L17776 | §176-E | Two cheap source spellings, both cc1-probed | +| L17798 | §176-F | Misdiagnosis triage: four residual verdicts that were lying | +| L17815 | What | is NOT banked here | +| L17828 | §180 | THE LEFTOVER-DRAFT HARVEST: RE-VERIFY WHAT YOU ALREADY HAVE BEFORE DRAFTING ANYTHING NEW | +| L17857 | §180b | WHAT THE PRE-GATE LADDER ACTUALLY FINDS IN A COLD PILE (the shape of integration debt) | +| L17876 | §180c | WHEN A BINARY'S MASS BAND IS SPENT, THE FLEET-WIDE DRAW IS STRICTLY BETTER | +| L17894 | §181 | WHAT A WAVE'S GATE ACTUALLY REJECTS (P31 S53, measured on wave R's 45-draft main pile) | +| L17895 | Only | ONE of 27 blocked drafts was wrong. The other 26 were correct and unbankable. | +| L17950 | §182 | §177's HONEST NEGATIVE: the epilogue lever cracked 4 of 16, and the `800c3` cluster held | +| L17964 | §180d | THE `pgrep` BRACKET TRICK PROTECTS THE PATTERN, NOT THE COMMAND LINE | +| L17976 | §183 | THE DECLARATION-RECONCILIATION PLAYBOOK (P31 S53, measured on 20 byte-verified drafts) | +| L17977 | §3-18 | of 20 reconciled while keeping the match. The two that did not are mechanism, not effort. | +| L18047 | §184 | COMMENT-BLINDNESS IS A DEFECT CLASS, NOT A BUG (P31 S53: three tools, one root cause, one | +| L18075 | §185 | EDIT THE SIDE THAT IS CHEAP TO VERIFY, AND CHECK A TU RETYPE AT ITS USE SITES | +| L18107 | §186 | CROSS-JUMPING RUNS **AFTER** SCHEDULING, SO NO C-LEVEL BARRIER CAN STEER IT | +| L18128 | §186b | A NO-SAVE 16-BYTE FRAME IN A LEAF FUNCTION MEANS `s16` LOCALS, NOT A HIDDEN CALL | +| L18136 | §186c | WHERE A VALUE IS LOADED DECIDES WHICH ALLOCATOR OWNS IT, AND THEREFORE ITS REGISTER | +| L18153 | §187 | 🔴 "SAME SOURCE" IS NOT "SAME OBJECT": THE SDK BUILD AND THE GAME BUILD DISAGREE ON GTE NOP | +| L18191 | §188 | 🔴 THE `jr $ra` + `addiu $sp` TAIL IS AN **ASSEMBLER** ARTIFACT, NOT A FRAME SHAPE | +| L18241 | §189 | FIVE COMPILER LAWS MINED FROM THE WAVE R/S JOURNALS (P31 S53), each source-cited and re-de | +| L18316 | §190 | THREE PRESCRIPTIONS FROM THE SAME HARVEST (weaker evidence than §189, honestly labelled) | +| L18353 | §191 | WHAT THIS HARVEST DID **NOT** BANK (4 rejected, 4 narrowed) — recorded so it is not re-der | +| L18375 | §192 | THE PRE-GATE LADDER WAS MAIN-ONLY, AND NOBODY COULD SEE IT (P31 S54) | +| L18376 | Three | defects in one call path; the overlay slates that carry most of the wave work were being w | +| L18440 | §193 | THE WAVE-T HARVEST (P31 S54): 71 index_gap reports -> 9 laws, 5 rejected, 61 already-cover | +| L18457 | §193-A | The wave card ships only OPEN-set pointers and discards the atlas's BANKED one — `exemplar | +| L18524 | §193-B | A NARROW CAST OF A WIDE PARAMETER COSTS ONE EXTRA INSTRUCTION WHEN ITS STATEMENT SITS AFTE | +| L18562 | §193-C | gcc-2.7.2 cross_jump merges the SCHEDULED common SUFFIX only — there is no prefix/head mer | +| L18596 | §193-D | A COMPILER-GENERATED ARGUMENT COPY IS A `optimize_reg_copy_1` TRIGGER: when the pointer's | +| L18667 | §193-E | A varying-address (pointer) load is re-emitted once per CSE-LIVE INTERVAL, and naming it i | +| L18697 | §193-F | §148-A2 — The `threshold -= 3` STAIRCASE: `move_movables` admits a COUNT of invariants, no | +| L18761 | §193-G | §164-54's "scope to ≥4 arms" bound is byte-wrong — the dispatch-topology oracle goes live | +| L18822 | §193-H | A pointer-derived base load `*(s32*)(p+K)` is uncacheable across ANY memory write or call | +| L18862 | §193-I | A DECLARED AGGREGATE LOCAL HAS AN 8-BYTE FRAME STRIDE — CEIL(size,8), NOT size. N ARRAYS T | +| L18921 | §193-REJECTED | what this harvest did NOT bank (recorded so it is not re-derived) | +| L18948 | §194 | THE WAVE-U HARVEST (P31 S54): 64 index_gap reports -> 14 laws, 5 rejected, 44 already-cove | +| L18965 | §194-A | A zero-byte scheduling fence goes AFTER the defining statement to make that computation em | +| L19031 | §194-B | A `addu $rA,$rB,$zero` copy feeding ≥2 `sh` stores is a SECOND, 16-BIT-DECLARED local — th | +| L19069 | §194-C | A CALLER-SAVED loop counter proves its live range crosses ZERO calls — so it cannot share | +| L19132 | §194-D | Declared width of a computed-value local is a sched1 dial (count-neutral) — a replication | +| L19173 | §194-E | The wave card's `exemplar` is the TARGET ITSELF on 42/73 wave-U and 36/71 wave-T cards — a | +| L19210 | §194-F | `if ((*p = v = f()) == 0)` is an expand-time pseudo SPLITTER (store_expr's `want_value && | +| L19283 | §194-G | Reading the integer half of a 16.16 stack aggregate: REGISTER-LIVENESS, not the C spelling | +| L19326 | §194-H | §164-29's WAR fence runs again at SCHED2 ON HARD REGISTERS: an in-place `v &= K` before a | +| L19364 | §194-I | §16N+2's magic-per-odd-part ladder has exactly one broken row — read the divisor arithmeti | +| L19407 | §194-J | Back-to-back identical stores: flow.c's `last_mem_set` deletes the first, and only `volati | +| L19459 | §194-K | Blind sched1's alias oracle with a second SET of a pointer pseudo — the first zero-byte, n | +| L19537 | §194-L | §88b and §189-E are BOTH half-wrong, but not the way the candidate says: the compare-const | +| L19585 | §194-M | A STORE in a CONDITIONAL branch's delay slot proves its C statement DOMINATES the branch — | +| L19643 | §194-N | §193-D's C dial is misstated: the lever is a SURVIVING CODE_LABEL (a label with a real inc | +| L19703 | §194-REJECTED | what this harvest did NOT bank (recorded so it is not re-derived) | +| L19724 | §195 | THE WAVE-V HARVEST (P31 S54): 67 index_gap reports -> 14 laws, 9 rejected, 76 already-cove | +| L19738 | §195-A | §167-08's "an $aN READ before the jal is scratch" has a byte-proven FALSE-NEGATIVE class: | +| L19809 | §195-B | A CALL_INSN does not start a basic block in gcc-2.7.2 — so a call-crossing temp can be a L | +| L19851 | §195-C | A call-argument `%hi/%lo` pair sitting at the block head, far above its `jal`, is a load-d | +| L19899 | §195-D | §195 — `masked_diff.mask_for` returns 0 for EVERY `j`/`jal` word, so an internal `j` desti | +| L19967 | §195-E | A 0/1 materialised at a JOIN immediately before the controlling `beqz`/`bnez` proves the s | +| L20025 | §195-F | fold-const.c:4825 canonicalises a `?:` whose THEN arm is zero (or constant against a non-c | +| L20077 | §195-G | §NEW — TWO ARMS CALLING THE SAME CALLEE MERGE INTO ONE `jal` UNLESS EACH ARM'S OWN CODE CO | +| L20125 | §195-H | §165-27g — ON A FIXED-SYMBOL GLOBAL, `extern T D[];` + `D[0]` IS THE CSE RELOAD DIAL, AT Z | +| L20172 | §195-I | §145(b) AMENDED — the pointer-bump `addiu` is saved by cse, not combine: ANY second SET of | +| L20237 | §195-J | GTE / PsyQ op CALL-vs-INLINE is a PER-SITE SOURCE FACT, not a TU style — both forms coexis | +| L20281 | §195-K | At -O2 the §18 array-of-struct lever is a FRAME lever, not a length lever — but only when | +| L20333 | §195-L | The cse store-re-seed does not cross a JOIN LABEL: per-arm stores + a join read keep the r | +| L20385 | §195-M | Frame `vars` is a SEQUENTIAL bump-allocation, not a flat sum: §193-I's CEIL(aggregate,8) t | +| L20434 | §195-N | In a call-bearing chain of N≥2 `if (f(...)) return 1;` tests closed by `return 0;`, the LA | +| L20481 | §195-REJECTED | what this harvest did NOT bank (recorded so it is not re-derived) | +| L20527 | §196 | PUT ON THE CARD WHAT THE TREE ALREADY KNOWS: the fleet's declaration consensus (P31 S54) | +| L20582 | §197 | THE WAVE-W HARVEST (P31 S54): 68 index_gap reports -> 4 laws, 3 rejected, 41 already-cover | +| L20596 | §197-A | A NARROW SIGNED MEMORY READ FEEDING A CONSTANT `>>` LOSES ITS `lh`, AND THE CURE IS AN ASM | +| L20634 | §197-B | A REPEATED COMPARE OF ONE VALUE AGAINST ONE CONSTANT IS DELETED BY cse's `qty_comparison_c | +| L20662 | §197-C | Fix A1 (operand order) cannot move a commutative destination whose .greg conflict set alre | +| L20707 | §197-REJECTED | §197-REJECTED | +| L20722 | §199 | THE WAVE-X HARVEST (P31 S54/S55): 63 index_gap reports -> 7 laws, 2 rejected, 56 already-c | +| L20733 | §199-A | §189-A's asm→source inference is byte-FALSE: an interloper between a split constant's `lui | +| L20782 | §199-B | A permutation sweep that holds ANY statement fixed is not a sweep: the statement an agent | +| L20827 | §199-C | A NEGATIVE CONSTANT MULTIPLY ALWAYS TAKES expmed's negate_variant — but whether you ever S | +| L20875 | §199-D | A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is | +| L20935 | §199-E | §189-A BOUNDED AND CORRECTED — the discriminator is INSN_PRIORITY, not "is the interloper | +| L20994 | §199-F | §164-36b — THE TARGET-HEAD FENCE IS A DELAY-SLOT THREAD SELECTOR, AND IT ONLY FIRES WHEN ` | +| L21048 | §199-G | At TWO case nodes the switch-vs-if oracle is not blind — but the tell is ALL tests positiv | +| L21103 | §199-REJECTED | §199-REJECTED | +| L21114 | §200 | THE ALIAS IS THE UNIVERSAL DECLARATION ESCAPE: stop negotiating with the TU's spelling (P3 | +| L21163 | §201 | THE WAVE-Y HARVEST (P31 S55): 67 gap reports -> 5 laws, 8 rejected, 53 already-covered | +| L21173 | §201-A | §150-B applies to `decl_prior`'s DEF row: for an overlay-window symbol the banked "definit | +| L21205 | §201-B | In a narrowed PLUS/MINUS/AND/IOR/XOR expression the destination pointee is INERT — the sig | +| L21285 | §201-C | §X — A CALL'S OWN DELAY SLOT AND THE UPSTREAM CONDITIONAL BRANCH'S SLOT COMPETE FOR ONE IN | +| L21336 | §201-D | THE SIGNEDNESS OF A div/mod MAGIC IS DECIDED BY THE STATIC TYPE OF THE DIVIDEND TREE AFTER | +| L21383 | §201-E | §194-J-2 — The `last_mem_set` deletion window is measured in SOURCE/expand order, not in t | +| L21439 | §201-REJECTED | eight, the session's highest | +| L21464 | §202 | THE ALIAS CARRIES A DEFINITION, NOT JUST A DECLARATION: the DEF-SIDE-RETURN wall (P31 S56) | +| L21501 | §203 | A DEDUPED TYPEDEF MUST PRECEDE EVERY SPLICE POINT, NOT JUST ITS OWN (P31 S56) | +| L21562 | §204 | THE WAVE-Z HARVEST (P31 S56): 82 gap reports -> 5 laws, 16 rejected, 30 already-covered | +| L21581 | §204-A | A COMPARE THAT APPEARS BOTH IN A BRANCH'S DELAY SLOT AND AGAIN ON THE FALL-THROUGH IS A JO | +| L21656 | §204-B | A LOOP COUNT THAT ARRIVES ON THE STACK IS DECREMENTED IN PLACE: a fresh counter local can | +| L21720 | §204-C | WHEN A LOCAL BUFFER'S ADDRESS IS PASSED TO A CALL, ITS SIZE IS A FACT ABOUT THE CALLEE'S B | +| L21778 | §204-D | A LOOP-INVARIANT LOAD IS ADMITTED AS A MOVABLE ONLY IF ITS ADDRESS CANNOT TRAP: `local.fie | +| L21853 | §204-E | `decl_prior`'s `%hi/%lo` ARM HAS NEVER FIRED: the card's promised GLOBAL-TYPE row is 0 of | +| L21905 | §204-CONFIRMED | 30 reports that the index already answered | +| L21999 | §204-REJECTED | sixteen, twice the previous record | +| L22072 | §205 | THE CHAINED ASSIGNMENT IS ITS OWN SCHEDULING DIAL: `*b = *a = v;` moves an argument copy t | +| L22127 | §206 | THE JTBL-CARVE DRAFTING IDIOM: the bounds check is the entry count, and an EMPTY case owns | +| L22196 | §207 | THE WAVE ab–ag HARVEST (P31 S58): 278 byte-banked notes → 25 laws, 103 self-reported no-ga | +| L22217 | §208 | TWO NAMED LOCALS FOR ONE RELOADED EXPRESSION BUY TWO ALLOCNOS — the naming granularity own | +| L22266 | §209 | THE NARROW LOCAL IS A DIAL IN TWO OPPOSITE DIRECTIONS, AND §194-B's "≥2 `sh` STORES" BOUND | +| L22343 | §210 | THE SINGLE-BIT MASK IN A BOOLEAN TAIL: `andi K ; sltu $zero,v` vs `srl n ; andi 1` is a ST | +| L22389 | §211 | HOIST THE LOOP INIT ABOVE THE DOMINATING GUARD: it fills the guard's delay slot AND flips | +| L22448 | §212 | THE WALKING CURSOR IS COUNTABLE: `*wp++` emits one `addiu` PER STORE, `wp[0..2]` emits one | +| L22493 | §213 | INDEPENDENT SAME-BASE STORES: THE EMISSION ORDER IS A PERMUTATION OF SOURCE ORDER, AND THE | +| L22529 | §214 | THE BANKED TWIN MAY BE A MACRO, A DELETED `.s`, OR A SEMANTIC INVERSE — six ways a ≥0.9 si | +| L22575 | §215 | PIN ECONOMY: the twin's pins are NOT part of the shape, and §17's "pin every call-crossing | +| L22631 | §216 | DISTINCT ADJACENT SCALARS vs ONE ARRAY: one `lui` per access is the tell, and the array de | +| L22671 | §217 | DECODING A CALL'S STACK ARGUMENT SLOTS: `sw` at `0x10`/`0x14`/`0x18` are params 5/6/7 **(s | +| L22697 | §218 | A NARROW TYPE AT THE ABI BOUNDARY COSTS AN IN-PLACE `sll/sra` PAIR — on the RETURN as well | +| L22726 | §219 | COMPOUND `+=`, FULL ASSIGNMENT, AND AN EXPLICIT TEMP ARE THREE DIFFERENT SCHEDULES OF ONE | +| L22753 | §220 | THE PARAMETER ITSELF IS A REGALLOC DIAL: use it directly, prefer `s32` to `void*`, and pla | +| L22793 | §221 | A CONSTANT SHARED BY TWO STORES DIES AT THE CALL WHOSE DELAY SLOT REFILLS ITS REGISTER **( | +| L22809 | §222 | SWITCH vs IF-CHAIN, PART 3: source arm order IS emission order, a leading EMPTY case buys | +| L22851 | §223 | READING A `jal` DELAY SLOT: the value in it was produced BEFORE the call, so it is NEVER t | +| L22913 | §224 | CROSS-JUMP: WRITE THE DUPLICATE, AND READ A SHARED DELAY SLOT AS THE MERGE SIGNATURE (P31 | +| L22949 | §225 | THREE CONTROL-FLOW SHAPES NO STRUCTURED SPELLING REACHES (P31 S58) | +| L22992 | §226 | FRAME PADS: FOUR WAYS §162i1/§2429's DEAD-LOCAL LEVER MISFIRES (P31 S58) | +| L23033 | §227 | TYPE THE SOURCE BY THE **LOAD** WIDTH, NOT BY THE STORE WIDTH (P31 S58) | +| L23053 | §228 | READING THE DIVIDE, PART N: the off-by-one compare is `% K == 1`, and three more discrimin | +| L23090 | §229 | THE ADDRESS IS A VALUE: NAMING IT MOVES THE `lui`/`addiu` PAIR — AND §L14410 SAYS THE OPPO | +| L23139 | §230 | THE ANCHOR PROBE: with `%hi`/`%lo` masked, the surviving `addiu` deltas tell you which ass | +| L23154 | §231 | TRANSCRIPTION AND SEMANTIC-READ HYGIENE: six ways the listing misleads (P31 S58) | +| L23195 | §232 | WHEN THE `jr` DELAY SLOT'S STORE STORES THE RETURN VALUE, TIE THEM WITH ONE PSEUDO **(sing | +| L23231 | §30 | addendum (P31 S58) — the `/s` grant closes a SCHEDULING residual and a REGISTER residual w | +| L23251 | §194-B | addendum (P31 S58) — BOUND 2 is byte-wrong; see §209 Direction A | +| L23257 | §176-B | addendum (P31 S58) — the misdiagnosis direction | +| L23263 | §165-40 | addendum (P31 S58) — the barrier goes at the COPY SITE, not inside the region it protects | +| L23272 | §164-63 | addendum (P31 S58) — the interposed asm works when the SECOND value is an ordinary assignm | +| L23281 | §193-A | / §194-E addendum (P31 S58) — where the twin's body actually lives | +| L23287 | §233 | THE WAVE aa–bg HARVEST (P31 S58b): 1,101 byte-banked notes → 24 new laws, 21 addenda, ~700 | +| L23331 | §234 | CONSTANT MATERIALISATION: THE STORE LVALUE'S SIGNEDNESS PICKS `addiu` vs `li`/`ori` (P31 S | +| L23372 | §235 | THE PHANTOM SYMBOL: A MASKED `MATCH` CAN CARRY A RELOCATION THAT DOES NOT EXIST (P31 S58b) | +| L23401 | §236 | THE DECLARATION LAYER IS THE DOMINANT BANK-BLOCKER: NINE WAYS A BYTE-PERFECT BODY FAILS TH | +| L23480 | §237 | THE CAST-AT-CALL-SITE DECISION TABLE: WHAT §17a-1 FIXES, WHAT IT CANNOT, AND THE FOUR ESCA | +| L23535 | §238 | SAME NAME, DIFFERENT FUNCTION: THE OVERLAY-HOMONYM TRAP (P31 S58b) | +| L23575 | §239 | TWO-STATEMENT INTEGER-SPACE MATERIALISATION REORDERS `la` vs `sll`; AND THE PLUS-TREE OPER | +| L23609 | §240 | `A + K + B`: WRITE THE CONSTANT **BETWEEN** THE TWO RUNTIME TERMS (P31 S58b) | +| L23638 | §241 | THE FOLDED SIGN-EXTEND-AND-SCALE: `sll 16 ; sra (16 − log2 scale)` (P31 S58b) | +| L23667 | §242 | `*k` vs `<>n`: EXPRESSION SPELLING OWNS THE LOAD WIDTH AND THE ROUNDI | +| L23695 | §243 | SPELL THE CSE BARRIER AS A REASSIGNED POINTER; AND THE `nop`-AFTER-EVERY-`lh` SIGNATURE (P | +| L23725 | §244 | `volatile` IS A COUNTING INSTRUMENT, A STORE-ORDER PIN, AND MUST SOMETIMES BE ASYMMETRIC ( | +| L23760 | §245 | THE CALL'S ARGUMENT LIST IS A SCHEDULING SLOT (P31 S58b) | +| L23807 | §246 | THREE-LIVE-VALUE SCAN LOOPS WANT ADDRESS-FROM-INDEX; AND TWO SYMBOLS CAN SHARE ONE giv (P3 | +| L23847 | §247 | TWO BRANCHES TO **ONE** LABEL MEANS THE SOURCE CONDITION IS NEGATED (P31 S58b) | +| L23881 | §248 | SPLIT THE LOAD FROM THE ARITHMETIC: A FUSED `g + K` DENIES THE CALLEE-SAVED REGISTER ITS D | +| L23905 | §249 | THE SELF-ASSIGN, THE DEAD RE-ASSIGN, AND THE `+ zr` COPY: THREE WAYS TO MAKE A DELETED INS | +| L23947 | §250 | `%hi/%lo` vs `lw`: THE EXTERN'S ARRAY-vs-SCALAR SHAPE DECIDES ADDRESS MATERIALISATION (P31 | +| L23984 | §251 | IMMEDIATE-SPELLING TRIGGERS: `+= 0xFF`, FULL-WIDTH `~K`, AND THE TWO-OR SPLIT (P31 S58b) | +| L24006 | §252 | THE GUARDED PRE-DECREMENT: `(x != 0) && (--x == 0)` (P31 S58b) | +| L24027 | §253 | POSTFIX `++` vs `+= 1` PICKS A DIFFERENT SCRATCH REGISTER **(single observation — not yet | +| L24041 | §254 | THE DEAD PARAMETER IS A REGISTER-PLACEMENT TOOL **(single observation — not yet cross-conf | +| L24053 | §255 | THE EMPTY CASE, PART 2: FOUR TREE SHAPES IT BUYS (P31 S58b) | +| L24088 | §256 | GOTOS IN THE TARGET'S BLOCK ORDER REPRODUCE SWITCH PLACEMENT WITHOUT SWITCH'S SIDE EFFECTS | +| L24125 | §257 | THE DEAD-END LEDGER (P31 S58b): ELEVEN LEVERS THAT MEASURED NULL OR BACKFIRED | +| L24168 | §258 | ADDENDA TO EXISTING SECTIONS (P31 S58b) | +| L24173 | §30 | addendum (P31 S58b) — THE ANONYMOUS STRUCT MEMBER REF GRANTS `/s`, AND THAT IS A TWO-FOR-O | +| L24194 | §194-B | / §209 addendum (P31 S58b) — TWO MORE INSTANCES, AND THE BOUND IS NOW REFUTED FOUR WAYS | +| L24217 | §202 | addendum (P31 S58b) — THE DEF-SIDE ALIAS ALSO CLEARS A RETURN+PARAM DOUBLE CONFLICT | +| L24228 | §205 | addendum (P31 S58b) — CHAINED ASSIGNMENT: N≥3 IS INNERMOST-FIRST, AND THE TEXT MIRRORS EMI | +| L24245 | §208 | addendum (P31 S58b) — IT SCALES TO SIX SITES, AND IT HAS AN EXACT INVERSE | +| L24274 | §210 | addendum (P31 S58b) — THREE CONFIRMED SPELLINGS OF THE BOOLEAN TAIL | +| L24290 | §211 | addendum (P31 S58b) — INIT PLACEMENT: FIVE MORE DIALS BEYOND THE GUARD HOIST | +| L24333 | §213 | addendum (P31 S58b) — THREE MORE PERMUTATION LAWS FOR INDEPENDENT SAME-BASE STORES | +| L24362 | §214 | addendum (P31 S58b) — FOUR MORE WAYS A HIGH-SIMILARITY TWIN LIES | +| L24398 | §215 | addendum (P31 S58b) — PIN ECONOMY, PART 2: NINE REFINEMENTS | +| L24450 | §217 | CROSS-CONFIRMED (P31 S58b) — AND THE INCOMING HOME SLOT IS THE MIRROR | +| L24467 | §220 | addendum (P31 S58b) — THE PARAMETER, NOT A COPY (SEVEN CARDS) | +| L24492 | §222 | addendum (P31 S58b) — IF-CHAIN vs SWITCH: THREE MORE DISCRIMINATORS | +| L24510 | §223 | addendum (P31 S58b) — FIVE MORE CONFIRMATIONS, AND THE CONSTANT-IN-`$v0` CASE | +| L24534 | §224 | addendum (P31 S58b) — CROSS-JUMP MERGES *CALLS*, AND THE DELAY SLOT IS THE DISCRIMINATOR | +| L24564 | §225 | addendum (P31 S58b) — THE GUARD-CLAUSE FINGERPRINT, AND THREE MORE SHAPES | +| L24591 | §226 | addendum (P31 S58b) — THE FRAME CATALOGUE: SEVEN MORE LEVERS, AND SLOT ORDER IS DECLARATIO | +| L24636 | §229 | addendum (P31 S58b) — NAME IT **INSIDE** THE ARM | +| L24647 | §230 | CROSS-CONFIRMED (P31 S58b) | +| L24656 | §231 | addendum (P31 S58b) — FOUR MORE WAYS THE LISTING MISLEADS | +| L24687 | §232 | CROSS-CONFIRMED (P31 S58b) | +| L24698 | §259 | THE DISCARD LEDGER FOR THE aa–bg HARVEST (P31 S58b): WHAT WAS MINED AND REJECTED, AND WHY | +| L24737 | §260 | THE §154-A LEADING-ISLAND SPLIT: ONE CONFIG LINE, AND THE ISLAND PEELS FROM THE END (P31 S | +| L24787 | §260-A | STAGE 2 IS PROVEN, AND THE WHOLE jtbl PIPELINE IS AUTOMATED AT THE GATE (P31 S59, same day | +| L24823 | §261 | THE -O0 ORACLE: DERIVE THE OPT LEVEL FROM THE TARGET, AND `$fp` IS NOT THE TELL (P31 S59) | +| L24849 | §261a | THE -O0 FRAME-RELOAD GRAMMAR: reload COUNT disambiguates the C spelling (P31 S59, byte-pro | +| L24871 | §262 | A LANE'S YIELD IS ONLY A LANE FACT IF IT IS SIZE-MATCHED (P31 S59) | +| L24901 | §263 | A STOLEN DELAY SLOT WHOSE INSTRUCTION IS AN ARG-REGISTER COPY IS AN ARITY ERROR, NOT A SCH | +| L24942 | §264 | FOUR TELLS-LANE C RECIPES, EACH DRIVEN TO MATCH (P31 S59) | +| L24992 | §265 | THE VERBATIM-ASM BANK LANE: A FUNCTION NO -O2 C CAN EVER MATCH BANKS AS A RAW `__asm__` BO | +| L25054 | §266 | THE INERT-RIDER LAW: A LEVER IS ONLY CITABLE WHEN ITS SOLO REMOVAL BREAKS THE MATCH (P31 S | +| L25094 | §267 | ADDENDA HARVESTED FROM WAVES at/bh/bk/bl (P31 S59b) | +| L25102 | ADD-1 | → §231 addendum (also cross-ref from §195-D) — THE MASKED-`jal` "MISSING CALL" ILLUSION | +| L25111 | ADD-2 | → §42a addendum — A SHARED CONSTANT *NAMED IN A LOCAL* ACROSS A `jal` IS AN ISO→TU DRIFT H | +| L25123 | ADD-3 | → §236, item 10 — THE UN-DELETED `INCLUDE_ASM` STUB IS A DUPLICATE DEFINITION | +| L25133 | ADD-4 | → §225-3/-4 addendum — THE MIRROR ROW: VALUE-RETURN IN THE *TAKEN* ARM + TRAILING BARE `re | +| L25147 | ADD-5 | → §1/I1 addendum — THE INVERTED RANGE TEST: `(u32)(x-lo) >= N` WITH THE ZERO-ARM AS THE TR | +| L25156 | ADD-6 | → §172b-1 / §264 addendum — SHIFT-AS-TEST: `(x << 16) != 0` TESTS THE LOW HALF WITHOUT TRU | +| L25165 | ADD-7 | → §256 addendum — THE SINGLE-GUARD GOTO: THEN-BLOCK OUT OF LINE AT THE TAIL | +| L25177 | ADD-8 | → §245 addendum — THE RE-TIE BARRIER PINS CALL-ARG SETUP TO SOURCE ORDER (construct 6) | +| L25189 | ADD-9 | → §213-3 / §217 addendum — ADJACENT PRE-CALL FRAME STORES ARE ONE AGGREGATE; THE UNESCAPED | +| L25199 | ADD-10 | → §237 addendum (arity-evidence paragraph) — AN `la` PAIR ABOVE THE PROLOGUE `sw $ra` IS A | +| L25208 | ADD-11 | → Cross-confirmation card block (per §259's standing instruction: confirmation, not news) | +| L25259 | §268 | A `register __asm__` PIN ON A CALL-CLOBBERED REGISTER IS HONORED EXACTLY WHEN THE PINNED R | +| L25313 | §269 | ADDENDA HARVESTED FROM WAVES ax/bm (P31 S59c) | +| L25328 | ADD-1 | → §257-8 addendum — THE INTERPOSED ASM'S `__volatile__` IS A PER-SHAPE DIAL, AND THE "NO-O | +| L25341 | ADD-2 | → §236 addendum (item 1 corollary) — THE SILENT-SPLICE DECLARATION LADDER: WHERE THE TU HA | +| L25355 | ADD-3 | → §238 addendum — TWO BINARIES CAN EACH DEFINE THE SAME `func_` NAME WITH DIFFERENT BYTES, | +| L25368 | ADD-4 | → §167-37 addendum — THE FIFTH PRECONDITION, NOW MEASURED: DOWNSTREAM FIELD RE-READS ⇒ NAM | +| L25385 | ADD-5 | → §267-ADD-6 / §172b-1 addendum — THE SIGN-TEST FACE: `(s16)v < 0` IS `sll 16` + `bgez` ON | +| L25401 | ADD-6 | → §220-addendum — THE FOURTH FACE: WHEN THE NAMED COPY ITSELF BUYS THE EXTRA CALLEE-SAVED, | +| L25417 | ADD-7 | → §229 addendum — THE VALUE FACE: A LOOP-STORE CONSTANT SPELLED AS A LITERAL HAS NO SOURCE | +| L25430 | ADD-8 | → §30a addendum — THE THIRD COLUMN: `*p++` IS ALSO SERIALIZED BUT BURNS `addiu`; ONLY CAST | +| L25445 | ADD-9 | → §255 "AND CASE-BODY PLACEMENT" bound / §222-addendum-3 — ON A LARGE SPARSE TREE, BODIES | +| L25459 | ADD-10 | → Cross-confirmation card block (per §259's standing instruction: confirmation, not news) | +| L25500 | §3-1a. | The §266 sweep — every solo-lever A/B run for this batch | +| L25533 | §270 | The A-prop 0-bank anatomy: a byte-correct body still needs FOUR layers to agree (P31 S59) | +| L25551 | §271 | Ordinal IMM pairing: text order is NOT emission order; emit CANDIDATES, let the oracle pic | +| L25573 | §272 | The `(void)`-decl + empty-call wall: K&R the DEFINITION, not just the decls (P31 S59) | +| L25593 | §273 | A standalone compile is the WRONG oracle for a TU-destined draft (P31 S59) | +| L25608 | §274 | ADDENDA HARVESTED FROM 18 WAVES (P31 S60): 315 candidates, 255 already covered, 21 sharpen | +| L25614 | ADDENDUM | to §179-C — the `.type NAME, @function` requirement | +| L25661 | ADDENDUM | to §134 — a typedef defined BELOW the splice point is stripped anyway | +| L25691 | ADDENDUM | to §179-D (GTE macro reference family) — `gte_SetRotMatrix`/`gte_SetTransMatrix` bodies | +| L25717 | ADDENDUM | to §82 — struct copies must stay MEMBER-WISE, not block-moved, to match a spill-slot save | +| L25755 | ADDENDUM | to §136d-1 (RC-12, the `$0`-add / opaque-copy family) — two symptoms beyond "compare reads | +| L25794 | ADDENDUM | to §20 — a global declared as `T *` may itself BE the array base, not a pointer to derefer | +| L25823 | ADDENDUM | to §1-I5 | +| L25888 | ADDENDUM | to §164-51 | +| L25904 | ADDENDUM | to §176-F5 | +| L25933 | ADDENDUM | to §225 | +| L25978 | ADDENDUM | to §224 — CROSS-JUMP: THE DUPLICATE CAN BE A PLAIN STORE, NOT ONLY A CALL | +| L26012 | ADDENDUM | to §164-64 — AN EMPTY CLOBBER ON AN ARGUMENT REGISTER CAN BE THE DELIBERATE FIX, NOT JUST | +| L26043 | ADDENDUM | to §244 — THE COMPILER BARRIER, NOT `volatile`, BLOCKS A STORE→LOAD HOIST THROUGH A POINTE | +| L26074 | ADDENDUM | to §172b-1 — TWO PLACEMENT DIALS THE PROMOTION LAW DOESN'T NAME: NARROW THE COUNTER'S DECL | +| L26121 | ADDENDUM | to §229 — A POINTER'S NUMBER OF USES DECIDES WHETHER ITS ADDRESS FOLDS OR SURVIVES A CALL | +| L26166 | ADDENDUM | to §172b-4 — THE PLAIN CAST-DIVISION ALREADY PRODUCES THE PATTERN; DON'T HAND-ROLL THE BIA | +| L26196 | ADDENDUM | to §8 — WHEN `INCLUDE_RODATA` NEEDS A STANDALONE `.s` YOU CAN'T CREATE, CARRY THE FRAGMENT | +| L26239 | ADDENDUM | to §226 — A DEAD LOCAL SCOPED TO A NESTED BLOCK BUYS A MID-FUNCTION `addiu sp` PAIR, NOT A | +| L26278 | ADDENDUM | to §172a — RE-READING MEMORY (NOT NAMING A TEMP) IS WHAT KEEPS AN INCREMENT'S DELAY-SLOT F | +| L26309 | ADDENDUM | to §225 / §256 — A GOTO TO A SHARED SET-POINT PREVENTS IF-CONVERSION FROM COLLAPSING A LAT | +| L26351 | ADDENDUM | to §211 — AN IN-LOOP ACCUMULATOR WANTS A CLOSED-FORM EXPRESSION WHEN THE TARGET REMATERIAL | +| L26386 | §275 | THE LEFTOVER-REGISTER READ | +| L26426 | §276 | MIXED ADDRESS-EXPRESSION SPELLING FOR ADJACENT RELOCATABLE SYMBOLS IS A CSE-UNIFICATION DI | +| L26535 | §277 | RETURN-TAIL C SPELLING PICKS THE DELAY-SLOT-FILL vs TRAILING-MOVE TOPOLOGY, AND A NARROWER | +| L26599 | §278 | ADDENDA HARVESTED FROM WAVE cf (P31 S60): 34 candidates, 13 already covered, 8 sharpenings | +| L26607 | ADDENDUM | to §74 (func_800D0E30, resident) | +| L26643 | ADDENDUM | to §172b-4 (func_80185054, ov_SC03_097) | +| L26681 | ADDENDUM | to §265 (func_8017DC80, ov_SC07_002) | +| L26720 | ADDENDUM | to §17 (func_800CB794, md_MAIN_036) | +| L26768 | ADDENDUM | to §162p (func_8017C120, ov_MAIN_012) | +| L26802 | ADDENDUM | to §20 (~L1947) (func_80186AD0, ov_SC06_032) | +| L26832 | ADDENDUM | to §164-56 (func_8017F644, ov_SC04_005) | +| L26867 | ADDENDUM | to §237 (func_8017F7FC, ov_SC03_092) | +| L26896 | §279 | A `do/while (p < end)` LOOP UNDER AN ENTRY GUARD: the guard decides the compare, not the l | +| L26897 | §NNN | A DO-WHILE'S GUARD AND LATCH MUST REPEAT THE SAME BOUND EXPRESSION, NOT SHARE ONE LOCAL: T | +| L26930 | §280 | THE CURSOR'S DECLARED TYPE PICKS `sltu` vs `slt`: a `T*` bound test is UNSIGNED by C rule, | +| L26931 | §NNN | A LOOP CURSOR'S C TYPE (POINTER vs PLAIN INTEGER) SELECTS `sltu` vs `slt` FOR ITS BOUND TE | +| L26964 | §281 | GROUP COPY-THEN-RMW BY OPERATION KIND, NOT FIELD BY FIELD: sched1 does the interleaving, t | +| L26965 | §NNN | A DEPENDENT COPY-THEN-RMW BLOCK MUST BE SOURCE-GROUPED BY OPERATION KIND, NOT BY FIELD, AN | +| L27010 | §282 | gcc's OWN LOOP REVERSAL PUTS THE COUNTER INIT AFTER THE HOISTED MOVABLES — a position no h | +| L27011 | §NNN | WRITE THE UP-COUNT LOOP: gcc's OWN REVERSAL PRODUCES A COUNTER-INIT INSTRUCTION THAT LANDS | +| L27048 | What | I could not verify | +| L27095 | §283 | ADDENDA HARVESTED FROM THE 36-WAVE BATCH (P31 S60): 1,216 candidates, 859 already covered, | +| L27105 | ADDENDUM | to §164-75 — the fold-reassociation law also fires at a variable's INITIALIZER, not only a | +| L27131 | ADDENDUM | to §21 — the `bltz`+`slti` (or N-separate-compares) signed-range-split bullet is now CONFI | +| L27177 | ADDENDUM | to §202 — the DEF-SIDE ALIAS also resolves a function-vs-DATA-symbol identifier clash, not | +| L27200 | ADDENDUM | to §22 (`volatile`-qualified-global reload lever, cookbook ~L1922) — for a NON-constant, s | +| L27219 | ADDENDUM | to §195-E — a goto-ladder's STORES must sit AT the labels, after the gotos, not inline bef | +| L27281 | ADDENDUM | to §195-N — a GNU statement-expression slider must sit INSIDE the conditional arm's value | +| L27338 | ADDENDUM | to §176-B2 — in a micro-function with no long/short lifetime asymmetry, BOTH contending ps | +| L27385 | ADDENDUM | to §199-G — A `default:` LABEL GROUPED ONTO THE LAST CASE REMOVES THE `j default` TAIL, EV | +| L27454 | ADDENDUM | to §220 — REFERENCING THE RAW PARAMETER (NO NAMED COPY, NOT EVEN A PIN) LETS THE CALLEE-SA | +| L27512 | ADDENDUM | to §252 — a `>=0`/`<0` split on an unconditionally-decremented value needs the POSTFIX ope | +| L27539 | ADDENDUM | to §215 — FIFTH SHAPE: reused mask constants across two call-free merge sites each get the | +| L27622 | What | I could not verify | +| L27693 | Harness-defect | flags | +| L27786 | ADDENDUM | to §167-40 (func_8017E2CC, ov_SC04_015 — wave dg) | +| L27806 | ADDENDUM | to §20's cross-jump EXPLOIT bullet (func_8017E360, ov_SC05_007 — wave dg) | +| L27820 | ADDENDUM | to §87 (func_801815F4 ov_SC06_032; corroborating func_801840DC ov_SC05_017, func_80189C68 | +| L27839 | ADDENDUM | to §153 / §236-5 (func_801A419C, md_SC07_003 — waves di and dl, corroborating; refutes a c | +| L27859 | ADDENDUM | to §263 (func_801E83AC, md_SC04_029 — wave dj) | +| L27873 | ADDENDUM | to §265 (func_8017D878, ov_SC03_107 — wave dj; corroborated by a REJECTED, contradicted ca | +| L27887 | ADDENDUM | to §6 (func_801811F0, ov_SC03_102 — waves dj and dl, corroborated by a self-reported "noth | +| L27901 | ADDENDUM | to §195-G (func_80183BB0, ov_SC05_001 — wave dj) | +| L27929 | ADDENDUM | to the zero-byte-asm-slider family (§47 / §148-C / §153) (func_800CB874, md_MAIN_040 — wav | +| L27947 | ADDENDUM | to §194-B (func_8017EB34, ov_SC03_117 — wave dk; distinct from the §74 co-pinning finding | +| L27979 | ADDENDUM | to §74 (func_8017EB34, ov_SC03_117 — counter/clamp variant; wave dj, corroborated by dk/dl | +| L27999 | ADDENDUM | §37 — merged into the §153/§236-5 entry above (func_801A419C, wave dl) | +| L28007 | ADDENDUM | §6 — merged into the §6 entry above (func_801811F0, wave dl) | +| L28015 | ADDENDUM | to §238 (func_80182CB4, ov_SC02_000 — wave dl) | +| L28033 | ADDENDUM | to §137a (func_801684B4, ov_MAIN_012; corroborated independently by func_80189E68, func_80 | +| L28049 | ADDENDUM | to §8c / §88d (func_8016AB6C, ov_MAIN_012 — wave dm) | +| L28063 | ADDENDUM | to §73 / §30#2 (func_800D1984, resident — wave dm) | +| L28079 | What | I could not verify | +| L28099 | ADDENDUM | to §174 Law 4 (func_8017E9A8, ov_SC06_015) | +| L28139 | ADDENDUM | the zero-emission-asm family gains a REF-SLIDER PLACEMENT LAW and a paired RESTORER (func_ | +| L28191 | From | ck + cl + cm | +| L28197 | ADDENDUM | §NNN — sharpens §55a / §164-37 / §165-28 (switch-vs-tree cluster): A SHAPE THAT LOOKS LIKE | +| L28234 | ADDENDUM | §NNN — sharpens §167-13's boundary: CHAINING TWO IDENTICAL SIDE-BY-SIDE STORES INTO ONE C | +| L28267 | ADDENDUM | §NNN — sharpens §162a3/§60b: A `sll $v0,16 / sltiu $v0,1` ZERO-TEST OF A JUST-DECREMENTED | +| L28300 | ADDENDUM | §NNN — sharpens §37/§124 (unspecified-parameter-list family): DERIVE A CALLEE'S ARITY LOWE | +| L28333 | ADDENDUM | to §5a (func_80181F74, ov_SC03_112, wave cn) | +| L28383 | ADDENDUM | to §265 (func_8017E26C, ov_SC04_016, wave cn) | +| L28421 | ADDENDUM | to §42b (func_8018247C, ov_SC07_002, waves cu + cw) | +| L28452 | ADDENDUM | to §199-F family (func_8017EFB0, ov_SC02_021, wave cu) | +| L28507 | ADDENDUM | to §195-E (func_800CFC1C, md_MAIN_003, wave cv) | +| L28552 | ADDENDUM | to §215 addendum (func_800CB2C8, md_MAIN_033, waves cv + cw) | +| L28608 | ADDENDUM | to §236 item 4 (func_8017D268, ov_SC04_006, wave cw) | +| L28637 | What | I could not verify | +| L28669 | Harness-defect | flags (not idioms — flagged for the operator) | +| L28710 | ADDENDUM | to §250 (func_8017D7CC, ov_SC03_115 — cx/cy/cz/dr) | +| L28755 | ADDENDUM | to §225 (func_8017E190, ov_SC03_115 — cx/cy/cz) | +| L28808 | ADDENDUM | to §45-A (func_8017F6A4, ov_SC02_016 — cy/cz) | +| L28852 | ADDENDUM | to §249 (func_80182ED4, ov_SC04_004 — dp/dr/dt) | +| L28897 | ADDENDUM | to §199-A (func_801816FC, ov_SC02_005 — dp/dr/dt) | +| L28943 | What | I could not verify | +| L28986 | Harness-defect | flags | +| L29048 | §284 | COMBINE CAN REASSOCIATE TWO SEQUENTIAL BITWISE-AND MASKS INTO ONE AGAINST THE PRE-MASK VAL | +| L29052 | §285 | PRE-INITIALIZING A VARIABLE WITH A SHARED CONSTANT BEFORE A BRANCH MAKES BOTH ARMS OF THE | +| L29056 | §286 | FOLD A STATEMENT'S SIDE EFFECT INTO A COMMA-EXPRESSION IN AN ARGUMENT POSITION TO PLACE IT | +| L29060 | §287 | A STACK-FRAME HOLE BELOW TWO ADDRESS-TAKEN AGGREGATE LOCALS IS A LEADING PAD MEMBER OF ONE | +| L29064 | §288 | A REGISTER PIN DECLARED UNINITIALIZED AND ASSIGNED ONLY AT ITS LATE, SOLE USE STILL FORCES | +| L29068 | §289 | an array local's address-taken base keeps every element's store alive, even though only on | +| L29072 | §290 | A SINGLE STRENGTH-REDUCED GIV CAN DRIVE STORES TO SEVERAL DISTINCT RELOCATABLE SYMBOLS, EA | +| L29076 | §291 | THE DELAY-SLOT FALSE-VALUE: A CONDITIONAL BRANCH'S ZERO ARM MUST BE A FALL-THROUGH-ADJACEN | +| L29080 | §292 | DECLARING A SYMBOL UPSTREAM OF AN ALREADY-BANKED SIBLING THAT RELIES ON THAT SYMBOL'S IMPL | +| L29083 | §293 | THE "WHOLE-OBJECT GATE NEEDS EVERY SIBLING" LAW, WRITTEN PROPERLY: IT IS THREE LAWS, AND T | +| L29133 | §294 | ADDENDA HARVESTED FROM THE S61 GEN0/MAXTOK/MAIN/DEEPSEEK BATCH (waves ab8/ab16/ab24/ab32 · | +| L29144 | ADDENDUM | to §127 — the -O0 constant-offset fold keys on the MEMBER-ACCESS tree shape, not on the in | +| L29172 | ADDENDUM | to §261a — FOUR MORE -O0 DIALS BEYOND THE RELOAD COUNT (boot.c + md_MAIN_011/003, wave m0a | +| L29222 | ADDENDUM | to §264-3 — the explicit entry copy's BOUND: required exactly when the RAW value must outl | +| L29242 | ADDENDUM | to §172b-1 (counter-type dial) — the sll's SOURCE REGISTER is the placement discriminator | +| L29254 | ADDENDUM | to §276 — the SHARE direction: spell the second adjacent symbol RELATIVE to force ONE anch | +| L29270 | ADDENDUM | to §31's density-dummy dial (L2460/L2497) — the dose is TWO refs, and the dummy must sit w | +| L29287 | ADDENDUM | to §282 — the ADDRESS-GIV face: write the walked address INLINE so strength reduction birt | +| L29310 | ADDENDUM | to §253 — SECOND byte-proven card (upgrade from single-observation), and the placement fac | +| L29331 | ADDENDUM | to the L1800 anchor-steer bullet — a DERIVED-POINTER local silently flips the merged giv's | +| L29354 | ADDENDUM | to §31's asm→layout inference — TWO WIDTH-PAIR DISCRIMINATORS (same offset, different widt | +| L29375 | §295 | THE KERNEL-TRAP STUB: §81's jr-DETECTOR WITHOUT A TABLE IS A PsyQ SYSCALL TRAMPOLINE — ROU | +| L29430 | §296 | THE FRAME CHECK OUTRANKS THE ATLAS LEVER: READ PROLOGUE/EPILOGUE BEFORE DRAFTING ANY C — A | +| L29473 | §297 | ONE GIV SERVING MIXED-WIDTH LOADS *AND* A STORE NEEDS STRUCT-MEMBER SPELLING; CAST/INDEX S | +| L29516 | §298 | THE SHARED-TAIL POSITION DIAGNOSTIC: A FOLDED TAIL *BETWEEN* SWITCH ARMS MEANS PER-ARM DUP | +| L29541 | §299 | TWO INDEPENDENT EXTRACTION CHAINS EMIT CONTIGUOUSLY INSIDE ONE EXPRESSION; ONLY A STATEMEN | +| L29576 | §300 | S61 DISTILL BATCH NOTES (waves ab8/ab16/ab24/ab32 · g0a–g0f · m0a · ds1/ds2 · m0b) | +| L29645 | §301 | AN INTERNAL `j` CARRIES `R_MIPS_26 .text`: rtu/match_one "MATCH" COULD NOT SEE WHICH LABEL | +| L29693 | §302 | A RED BINARY IS A DRIFTED SPEC, NOT A MYSTERY: THE THREE CARVE-STATE INVARIANTS AND HOW TO | +| L29737 | §303 | MODULE ISLAND TABLES: DERIVE THE PADS AT BUILD TIME, PEEL NOTHING — THE §154-A/§260 "islan | +| L29773 | §304 | SELF-DEFINING RODATA: WHEN A FUNCTION'S `.s` IS THE ONLY OWNER OF THE DATA IT REFERENCES, | +| L29796 | §305 | "CARVE-REFUSED" AT GATE TIME IS THREE NAMED, DETERMINISTIC CLASSES — NONE OF THEM A CARVE | +| L29848 | §306 | A HAZARD `nop` IN FRONT OF A DIV-RESULT STORE IS A STATEMENT-ORDER DEFECT: THE INDEPENDENT | +| L29875 | §306a | T4 DISTILL ADDENDA (P31 S62; four byte-proven refinements to existing laws, verified again | +| L29913 | §307 | THE BRUTE-FORCE-THE-STATEMENT-ORDERS LEVER HAS A BOUND: A FAN-OUT COPY'S PRIORITY IS SCHED | +| L29957 | §308 | A NAIVE FINAL `goto` DELETES THE TARGET'S `j`+`nop`: SPELL THAT EDGE AS A TAUTOLOGICAL `if | +| L29986 | §308a | A TWO-INSTRUCTION ARM STUB LAID *BEFORE* THE OTHER ARM AND REACHED ONLY BY A TRAILING `j` | +| L30020 | §309 | A FRAME-ADDRESS EQUIVALENCE RIDES *THROUGH* A SKIPPABLE CONDITIONAL: POST-`if` STORES FOLD | +| L30060 | §310 | A TWO-OPERAND `subu`'s DESTINATION TIES ONLY TO THE OPERAND THAT IS BLOCK-LOCAL: SHARE *ON | +| L30091 | §311 | A JOIN-BLOCK STORE CAN SWALLOW AN ARM'S LOAD-DELAY `nop`: WHEN ONE ARM'S VALUE COMES FROM | +| L30133 | §312 | A BARE RELATIONAL IN AN `if` GIVES THE `slt` NO TARGET: ASSIGN THE COMPARISON INTO THE ALR | diff --git a/docs/matching-cookbook.md b/docs/matching-cookbook.md index 72f86116e..70709f5c3 100644 --- a/docs/matching-cookbook.md +++ b/docs/matching-cookbook.md @@ -2709,6 +2709,21 @@ tie in `global.c`): compiles fine, wrong bytes → exactly an R17/§45-B target. ## §41 — The DEF-SIDE canonical-sig wall: mechanically banking a drafted giant past `conflicting types` (Phase 25 T5b batch-2, 2026-07-09; `tools/canon_sig_reconcile.py`, byte-proven on `func_8013B274`) +**Addendum (P31 S64 t5o-t5r, func_8017BEBC @ ov_SC03_007, 246 ins) — A FINDABILITY KEY, not a new law.** §41 step 3 +("Cast each type-changed param AT ITS USES — NEVER via an intermediate local") also owns a purely **REGALLOC** +symptom, and this section's declaration-wall title hides it: a drafter hunting a register residual greps past §41 +entirely. **The tell:** a closeness plateau that will NOT move under clamp / loop-shape / integer-width levers, +with the instruction COUNT already exact, on a function whose C declares `T *out = (T *)paramN;` and stores through +`out[i]`. The named alias is a fresh pseudo — gcc gives it its own register, which frees the incoming arg register +for a competing tail temp and shifts the whole prologue schedule. Casting in place at each store +(`((T *)paramN)[i] = …`) adds no pseudo and is byte-free. **Byte evidence:** n7 (`s16 *out = (s16 *)a1; out[i] = …`) += near, closeness 17, nins 246; n9 (same body, alias deleted, `((s16 *)a1)[i] = …`) = **MATCH, closeness 0, nins 246**; +n11 re-confirms. **⚠ The decl-order control is INERT (§67):** n10 swapped the two pointer locals' declaration order, +kept the alias, and stayed at 17 — so an unchanged closeness under reordering does NOT exonerate the alias. This is +the FOURTH confirmation of §41 step 3 / §67's two-pseudo law, and the transcript printed only aggregate +`status closeness nins` lines, so it sharpens findability, not the mechanism. + + **The wall (dominant for GIANTS — ~universal, vs ~35% clean-bank for small fns):** a drafter writes an **isolation-MATCH** giant body (`match_one` c=0) with Ghidra-derived **TYPED** params — `void func(u32 *a0, s16 *a2)`. Placed in the real overlay TU it fails the whole-binary gate on `conflicting types for func_X` (a *declaration* @@ -30113,3 +30128,30 @@ else { *(s32 *)(p + 0x14) = TBL[*(u8 *)(p + 5)]; } **BYTE EVIDENCE.** `func_8017D7E0` (ov_SC06_033, 166 ins, banked at `src/ov_SC06_033/ov_SC06_033_jr_8017C24C.c:3568-3572`). v3 (pointer-CSE, `val` temp present): `closeness 22 / nins 165 / LENGTH-DRIFT/-1?` at 127, `explains: partial`. v4a/b/c reordered the tail statements around the temp — **inert, still 22**, which is what rules out §176-A2's statement-move lever. v5 (temp deleted, store duplicated into both arms): **closeness 2, nins 165 → 166, the LENGTH-DRIFT class gone entirely**, leaving only an unrelated 2-insn operand-order residual at `[127,128]`. The final 2 → 0 came one step later from an ordinary source-order edit (`D_801274EA` before `D_801274EC`, inlining a `(u16)` cast condition) — §176-A / §165-14 territory, **not part of this law**. *Re-read at vet time out of the banked object:* `objdump` of the banked build shows `nop` at 0x240 and exactly **one** `sw $v0,0x14($s1)` at 0x244 — the merge is visible in the bytes, and 0x240/4 = 144 is the residual's own index. **⚠ MECHANISM BOUND (R14).** No `-dS`/`-dR` dump was taken. The step "an independent join-block insn covers the cross-block hazard" is read off the final stream plus the pass order, not off the scheduler; `-dS` on the two spellings is the cheap confirmation and has not been run. What is **measured** is: the temp spelling is −1 with the `nop` absent, the duplicated spelling restores it at the correct byte, and the object still emits only one store. + + +## §312 — A BARE RELATIONAL IN AN `if` GIVES THE `slt` NO TARGET: ASSIGN THE COMPARISON INTO THE ALREADY-ALLOCATED VARIABLE TO CHOOSE ITS DESTINATION REGISTER, AT ZERO INSTRUCTION COST (P31 S64 t5o-t5r; byte-proven func_80180DCC) + +*(NEW axis, not a restatement. §164-38/§164-39 and §164-39's t5j-t5m addendum own the compare's **INPUT** colouring — which operand got which register — and their levers are the in-out fence on operand 0 and the relational transposition; both are the wrong door when the inputs are already correct. §197-C/§164-64 own "write it IN PLACE so the destination **is** an existing pseudo" for `*`/`+`/`|`/`&`; this extends that lever to the relational operator, where §197-C's companion note — "a pinned pseudo can never be the load's destination" — had left the impression that a pin cannot own a computed dest at all. §164-65 also names a value you were going to consume inline, but its payload is allocno REF COUNT, not `SET_DEST`. §195-E is the other naming law and is about whether a 0/1 **materialises** at a join; here naming is length-neutral, which is exactly what makes this lever free.)* + +**THE TELL.** The target's `slt` writes back into one of its **own two source registers** — an in-place compare, `slt $v0,$v0,$v1` — and is immediately consumed by a `bnez`/`beqz` on that same register. Your draft emits the identical pair with **every operand register already correct and only the destination one register over**: `match_one` reports `REGALLOC-PERM` with a single-register cycle (`{"$v1":"$v0"}`, `kinds:{"reg":2}`), residual exactly 2 instructions — the `slt` and its branch — and zero length drift. That is not structure and it is not input colouring; nothing but the compare's `SET_DEST` is wrong. + +**THE MECHANISM — INFERRED, NOT TRACED (cite as a place to look, never as proven pass behaviour; §164z / §137's bar).** A truth value used only inside an `if` reaches `do_jump`/`expand_expr` with no fixed target, so the `slt`'s destination is synthesised from whatever pseudo is cheapest at that point, tied to **neither** compared operand — which is why it can land one register away even when both operands are correctly pinned. Writing the comparison as an assignment hands `expand_expr` an explicit target pseudo and `store_expr` honours it, forcing the `slt`'s `SET_DEST` to that variable's hard register. No `-dS`/`-dg`/`-dl`/`-dg` dump was taken; `local-alloc.c combine_regs`' tie-to-a-dying-source-operand (§10 Residual A) is the other place worth dumping first if this recurs. + +**THE C SHAPE.** + + /* wrong — dest register unpredictable */ + if (v0 < v1) { goto TRUE1; } + + /* right — forces the slt's dest into v0's pinned hard reg */ + v0 = (v0 < v1); + if (v0 != 0) { goto TRUE1; } + + /* v0 is `register s32 v0 __asm__("$2")`; v1 a sibling pinned s16-cast temp, + `register s32 v1 __asm__("$3")` */ + +The two spellings cost the **same instruction count** — a bare relational has no join and no constant arms, so §195-E's "naming materialises a 0/1" does not fire and the naming is byte-free apart from the register it buys. + +**BYTE EVIDENCE.** `func_80180DCC`, 66 ins, all quotes from `match_one --json` on the pinned triple. v0 (backlog draft, `register s16 s1` pin + call-site `(s16)` casts) → closeness 9, `STRENGTH/sll!=sra`. Unpinning `s1` → closeness 6, same sig (block 2 clean, block 1's `sll/sra/slt/bnez` still wrong). v6 (pin `register s32 v1 __asm__("$3")`, hoist `v1 = (s16)s1; v0 = (s16)v0;` as statements ahead of a still-bare `if (v0 < v1)`) → **6 → 2**: `{"status":"near","closeness":2,"residual":[[34,"0043182a slt v1,v0,v1","0043102a slt $v0, $v0, $v1"],[35,"14600013 bnez v1,…","14400013 bnez $v0, .L80180EA8"]],"verdict":{"klass":"REGALLOC-PERM","sig":"REGALLOC-PERM/$v1>$v0","detail":{"map":{"$v1":"$v0"}}}}`. v7, the **only** change being `if (v0 < v1) {…}` → `v0 = (v0 < v1); if (v0 != 0) {…}` → **2 → 0**: `{"status":"match","closeness":0,"residual":[],"verdict":{"klass":"MATCH"}}`. + +**BOUND.** (1) n = 1. (2) Only the **v6 → v7** delta is solo-proven (§266): the pins and the cast hoist arrived in compound edits and are co-requisites of the shape, not separately ablated — the pin is what makes "the variable's hard register" a nameable thing here, and an unpinned local would only move the dest to whatever that local got. (3) Routing: on a REGALLOC-PERM whose single wrong register is the compare's **DEST**, try this first — one statement, zero bytes; go to §164-39's fence or its addendum's transposition only when the wrong register is one of the compare's **INPUTS**. (4) Says nothing about compare-against-constant shape (`slti`/`sltiu` immediate-vs-register is §194-L's 2-D lookup) or about signedness (§280).