From c5a60897bc16378d495c2096641806b6d6fbc64d Mon Sep 17 00:00:00 2001
From: Drew T <50529377+Druthulu@users.noreply.github.com>
Date: Sat, 29 Aug 2026 11:50:44 -0600
Subject: [PATCH] =?UTF-8?q?docs(cookbook):=20=C2=A7312=20(a=20bare=20if(a=
=?UTF-8?q?b)=20scatters=20the=20slt=20destination=20register=20=E2=80=94?=
=?UTF-8?q?=20materialize=20the=20compare=20to=20force=20it)=20+=20a=20?=
=?UTF-8?q?=C2=A741=20FINDABILITY=20addendum.=20The=20741-ins=20agent's=20?=
=?UTF-8?q?headline=20'new=20lever'=20was=20VERIFIED=20AS=20ALREADY-COVERE?=
=?UTF-8?q?D=20by=20=C2=A741=20step=203=20(cast=20a=20type-changed=20param?=
=?UTF-8?q?=20at=20its=20uses,=20never=20via=20an=20intermediate=20local);?=
=?UTF-8?q?=20the=20real=20gap=20was=20that=20=C2=A741's=20declaration-wal?=
=?UTF-8?q?l=20title=20hides=20its=20REGALLOC=20symptom,=20so=20the=20key?=
=?UTF-8?q?=20is=20filed=20there=20with=20the=20n7/n9/n10=20byte=20ladder?=
=?UTF-8?q?=20incl.=20the=20inert=20decl-order=20control=20(=C2=A767).=20I?=
=?UTF-8?q?ndex=20919=20->=20920=20(P31=20S64)?=
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
---
docs/cookbook-index.md | 5509 +++++++++++++++++++------------------
docs/matching-cookbook.md | 42 +
2 files changed, 2799 insertions(+), 2752 deletions(-)
diff --git a/docs/cookbook-index.md b/docs/cookbook-index.md
index 2b4eb32ed..3244c83e8 100644
--- a/docs/cookbook-index.md
+++ b/docs/cookbook-index.md
@@ -2,7 +2,7 @@
> **Generated by `tools/cookbook_index.py` — do not hand-edit** (R33). Regenerate after adding a cookbook section.
>
-> `docs/matching-cookbook.md` is ~716 KB / 919 sections. Grepping it blind is how three P30 wave-1 agents each "discovered" an idiom that was already written down. **Start here, then read the section.** A section appears under every symptom it addresses.
+> `docs/matching-cookbook.md` is ~716 KB / 920 sections. Grepping it blind is how three P30 wave-1 agents each "discovered" an idiom that was already written down. **Start here, then read the section.** A section appears under every symptom it addresses.
**How to use:** name what you SEE in the diff (a stolen delay slot, an extra `la`, a swapped register pair, a `conflicting types` error), find that symptom below, read those sections first. If nothing fits, THEN grind — and add a section when you win.
@@ -38,56 +38,56 @@
- **§3-T4** — Branch polarity: invert the source condition to flip gcc's chosen branch L90
- **§5a** — Cross-jump tail-merge — gcc collapses two byte-identical blocks the original kept separate (FIX FOUND) L211
-- **§3-D.** — THE CROSS-JUMP RATCHET (the sharpest new trap — `func_80131340` L-C) L3508
-- **§3-C.** — Inner-block declaration does NOT delay slot allocation — BYTE-REFUTED L10068
-- **§162** — CROSS-JUMP DIRECTION: the surviving copy is always the LATER one, so a BACKWARD `j` into a sibling arm is a source `goto` (P30 S48) L11266
-- **§162** — The cross-jump "CALL veto" is a COUNT law, not a CALL law (BOUNDS §88a; P30 S48, `func_80189540`) L11302
-- **§177** — 🔴 THE EPILOGUE RETURN-DELAY SLOT IS DECIDED BY YOUR SAVED-REGISTER SET, NOT BY SCHEDULING L17182
-- **§176-A** — "SCHEDULE / DELAY-SLOT / LENGTH-DRIFT ±1" ⇒ check STATEMENT ORDER around the call first L17639
-- **§186** — CROSS-JUMPING RUNS **AFTER** SCHEDULING, SO NO C-LEVEL BARRIER CAN STEER IT L18092
-- **§194-H** — §164-29's WAR fence runs again at SCHED2 ON HARD REGISTERS: an in-place `v &= K` before a branch fences the store that reads v, and when TWO independent stores compete for the one delay slot the fence picks the winner at ZERO length drift (a WIDTH/sh!=sw swap, not a nop). Corrects §167-42's reconstruction (pseudo arm → hard-reg arm) and supplies its first re-runnable A/B. L19311
-- **§194-M** — A STORE in a CONDITIONAL branch's delay slot proves its C statement DOMINATES the branch — reorg can never pull a store out of either thread (gcc-2.7.2, -mips1) L19570
-- **§195-D** — §195 — `masked_diff.mask_for` returns 0 for EVERY `j`/`jal` word, so an internal `j` destination is invisible to match_one, the permuter scorer AND every similarity tier: a control-flow semantic error (which calls execute) surfaces as a 1-instruction residual mislabelled `DELAY-SLOT / profile=schedule`, or as an outright false MATCH L19884
-- **§195-E** — A 0/1 materialised at a JOIN immediately before the controlling `beqz`/`bnez` proves the source NAMED the condition — a truth expression in an `if`'s controlling position reaches `do_jump`, which has no value path L19952
-- **§195-F** — fold-const.c:4825 canonicalises a `?:` whose THEN arm is zero (or constant against a non-constant ELSE) by inverting the condition and swapping the arms — so a ternary's written arm order is byte-inert there, and `c ? 0 : X` is unspellable: it always compiles as `!c ? X : 0` L20010
-- **§195-G** — §NEW — TWO ARMS CALLING THE SAME CALLEE MERGE INTO ONE `jal` UNLESS EACH ARM'S OWN CODE CONSUMES THE RESULT: the C dial that keeps two call sites apart is WHERE the consumer test lives, and the branch SENSE you spell it with is byte-inert (jump.c:1737 canonicalises it) L20062
-- **§195-J** — GTE / PsyQ op CALL-vs-INLINE is a PER-SITE SOURCE FACT, not a TU style — both forms coexist in one TU (measured in 2 TUs), and the tell is the target's own opcodes (`lwc2`/`sqr`/`swc2` vs `jal`), not the sibling. Costs -8 ins on func_8018505C. Corollary: the game's inline `sqr` macro emits TWO hazard nops, the SDK's `Square0` body emits ONE — so the inline form is provably not `Square0` inlined (a second instance of §187's SDK-vs-game GTE nop divergence). L20222
-- **§195-N** — In a call-bearing chain of N≥2 `if (f(...)) return 1;` tests closed by `return 0;`, the LAST test must stay in STATEMENT form — the value form (`return f() != 0;` / `? 1 : 0` / `!!f()`) costs +1 `j` and empties the other N−1 delay slots. The cause is REORG block placement, not jump.c's `delete_jump`. L20419
-- **§197-B** — A REPEATED COMPARE OF ONE VALUE AGAINST ONE CONSTANT IS DELETED BY cse's `qty_comparison_code` CHANNEL (the non-EQ complement of §165-03) — and a front-end-opaque mask on EITHER compare is a pure-C dial that keeps the target's second branch L20619
-- **§199-F** — §164-36b — THE TARGET-HEAD FENCE IS A DELAY-SLOT THREAD SELECTOR, AND IT ONLY FIRES WHEN `mostly_true_jump > 0` (amendment to §164-36; its "−1 instruction" tell is falsified) L20979
-- **§199-G** — At TWO case nodes the switch-vs-if oracle is not blind — but the tell is ALL tests positive + a trailing `j default`, NOT the first test's polarity L21033
-- **§201-C** — §X — A CALL'S OWN DELAY SLOT AND THE UPSTREAM CONDITIONAL BRANCH'S SLOT COMPETE FOR ONE INSN (the call's argument copy), AND ONE STATEMENT'S POSITION RELATIVE TO THE CALL DECIDES BOTH — the residual is visible at the BRANCH, not at the call L21270
-- **§204-A** — A COMPARE THAT APPEARS BOTH IN A BRANCH'S DELAY SLOT AND AGAIN ON THE FALL-THROUGH IS A JOIN WITH TWO INCOMING EDGES: THE TWO GUARDS ARE SEQUENTIAL `if`s, NEVER `if/else if` L21566
-- **§211** — HOIST THE LOOP INIT ABOVE THE DOMINATING GUARD: it fills the guard's delay slot AND flips the counter/pointer register pair (P31 S58) L22374
-- **§221** — A CONSTANT SHARED BY TWO STORES DIES AT THE CALL WHOSE DELAY SLOT REFILLS ITS REGISTER **(single observation — not yet cross-confirmed)** (P31 S58) L22778
-- **§223** — READING A `jal` DELAY SLOT: the value in it was produced BEFORE the call, so it is NEVER that call's return (P31 S58) L22836
-- **§224** — CROSS-JUMP: WRITE THE DUPLICATE, AND READ A SHARED DELAY SLOT AS THE MERGE SIGNATURE (P31 S58) L22898
-- **§232** — WHEN THE `jr` DELAY SLOT'S STORE STORES THE RETURN VALUE, TIE THEM WITH ONE PSEUDO **(single observation — not yet cross-confirmed)** (P31 S58) L23180
-- **§243** — SPELL THE CSE BARRIER AS A REASSIGNED POINTER; AND THE `nop`-AFTER-EVERY-`lh` SIGNATURE (P31 S58b) L23680
-- **§247** — TWO BRANCHES TO **ONE** LABEL MEANS THE SOURCE CONDITION IS NEGATED (P31 S58b) L23832
-- **§224** — addendum (P31 S58b) — CROSS-JUMP MERGES *CALLS*, AND THE DELAY SLOT IS THE DISCRIMINATOR L24519
-- **§263** — A STOLEN DELAY SLOT WHOSE INSTRUCTION IS AN ARG-REGISTER COPY IS AN ARITY ERROR, NOT A SCHEDULE (P31 S59, byte-proven) L24886
-- **ADD-4** — → §225-3/-4 addendum — THE MIRROR ROW: VALUE-RETURN IN THE *TAKEN* ARM + TRAILING BARE `return 0` L25118
-- **ADD-5** — → §1/I1 addendum — THE INVERTED RANGE TEST: `(u32)(x-lo) >= N` WITH THE ZERO-ARM AS THE TRAILING `else` L25132
-- **ADD-5** — → §267-ADD-6 / §172b-1 addendum — THE SIGN-TEST FACE: `(s16)v < 0` IS `sll 16` + `bgez` ON THE SHIFTED COPY, RAW STAYS LIVE — AND THE HALFWORD-ABS SHAPE NEEDS NO RITUAL L25370
-- **ADDENDUM** — to §224 — CROSS-JUMP: THE DUPLICATE CAN BE A PLAIN STORE, NOT ONLY A CALL L25963
-- **ADDENDUM** — to §172a — RE-READING MEMORY (NOT NAMING A TEMP) IS WHAT KEEPS AN INCREMENT'S DELAY-SLOT FILL ALIVE L26263
-- **ADDENDUM** — to §225 / §256 — A GOTO TO A SHARED SET-POINT PREVENTS IF-CONVERSION FROM COLLAPSING A LATER BRANCH TEST L26294
-- **§277** — RETURN-TAIL C SPELLING PICKS THE DELAY-SLOT-FILL vs TRAILING-MOVE TOPOLOGY, AND A NARROWER SECOND VARIABLE KEEPS TWO PSEUDOS INSTEAD OF ONE (P31 S60; `func_801846F0` ov_SC03_104, `func_801A44C4` md_SC07_004, both byte-proven) L26520
-- **ADDENDUM** — to §22 (`volatile`-qualified-global reload lever, cookbook ~L1922) — for a NON-constant, same-address double RMW, a plain memory clobber beats `volatile`, and `volatile` actively breaks a delay-slot fill L27185
-- **ADDENDUM** — to §220 — REFERENCING THE RAW PARAMETER (NO NAMED COPY, NOT EVEN A PIN) LETS THE CALLEE-SAVED SPILL LAND IN THE FIRST CALL'S OWN DELAY SLOT L27439
-- **ADDENDUM** — to §252 — a `>=0`/`<0` split on an unconditionally-decremented value needs the POSTFIX operator INSIDE the branch condition, not a prior statement L27497
-- **ADDENDUM** — to §20's cross-jump EXPLOIT bullet (func_8017E360, ov_SC05_007 — wave dg) L27791
-- **ADDENDUM** — §NNN — sharpens §55a / §164-37 / §165-28 (switch-vs-tree cluster): A SHAPE THAT LOOKS LIKE A SWITCH DISPATCH CAN BE PLAIN NESTED `if`s WHOSE SHARED BODY WAS TRIPLICATED BY THE SOURCE AND THEN CROSS-JUMP-MERGED BACK DOWN L28182
-- **§285** — PRE-INITIALIZING A VARIABLE WITH A SHARED CONSTANT BEFORE A BRANCH MAKES BOTH ARMS OF THE FOLLOWING if/else DESTRUCTIVELY REUSE THE SAME DESTINATION REGISTER FOR THEIR BITWISE RESULT (byte-proven; `func_801811F0`, ov_SC03_102, independently rediscovered across waves di/dj) (P31 S60; waves #, byte-proven) L29037
-- **§286** — FOLD A STATEMENT'S SIDE EFFECT INTO A COMMA-EXPRESSION IN AN ARGUMENT POSITION TO PLACE ITS RTL RELATIVE TO A CALL'S OWN DELAY SLOT (P31 S60/dj; `func_80180A88`, ov_SC06_010, byte-proven 411/411) (P31 S60; waves #, byte-proven) L29041
-- **§291** — THE DELAY-SLOT FALSE-VALUE: A CONDITIONAL BRANCH'S ZERO ARM MUST BE A FALL-THROUGH-ADJACENT BLOCK ENDING IN AN EXPLICIT JUMP, OR REORG CANNOT MATERIALIZE IT INSIDE THE BRANCH'S OWN DELAY SLOT (P31 S60; waves #, byte-proven) L29061
-- **ADDENDUM** — to §253 — SECOND byte-proven card (upgrade from single-observation), and the placement face: postfix-in-condition parks the RMW store in the branch delay slot L29295
-- **§306** — A HAZARD `nop` IN FRONT OF A DIV-RESULT STORE IS A STATEMENT-ORDER DEFECT: THE INDEPENDENT TRAILING STATEMENT MUST BE WRITTEN *BEFORE* THE DIVISION-CONSUMING ONE (P31 S62 T4; byte-proven func_8017E7D0) L29833
-- **§308** — A NAIVE FINAL `goto` DELETES THE TARGET'S `j`+`nop`: SPELL THAT EDGE AS A TAUTOLOGICAL `if` SO cse FOLDS IT TO AN UNCONDITIONAL JUMP *AFTER* jump1's WINDOW HAS CLOSED (P31 S63 t5e-t5i; byte-proven func_80180808) L29942
-- **§308a** — A TWO-INSTRUCTION ARM STUB LAID *BEFORE* THE OTHER ARM AND REACHED ONLY BY A TRAILING `j` SURVIVES ONLY BEHIND A SHORT-CIRCUIT `&&` GUARD PLUS A SEPARATE RE-TEST; EVERY PLAIN if/else-if, GOTO-LADDER, NESTED-INVERTED-if AND 1-/2-NODE switch LETS jump1 INLINE IT (−2 ins) (P31 S63 t5e-t5i; byte-proven func_80180808) L29971
-- **§309** — A FRAME-ADDRESS EQUIVALENCE RIDES *THROUGH* A SKIPPABLE CONDITIONAL: POST-`if` STORES FOLD ONTO `$sp` UNLESS THE `if` SURVIVES jump1 AS A BARRIER-PRECEDED DIAMOND (P31 S63 t5e-t5i; byte-proven func_801812AC) L30005
-- **§311** — A JOIN-BLOCK STORE CAN SWALLOW AN ARM'S LOAD-DELAY `nop`: WHEN ONE ARM'S VALUE COMES FROM A LOAD, DUPLICATE THE STORE INTO BOTH ARMS (P31 S64 t5j-t5m; byte-proven func_8017D7E0) L30076
+- **§3-D.** — THE CROSS-JUMP RATCHET (the sharpest new trap — `func_80131340` L-C) L3523
+- **§3-C.** — Inner-block declaration does NOT delay slot allocation — BYTE-REFUTED L10083
+- **§162** — CROSS-JUMP DIRECTION: the surviving copy is always the LATER one, so a BACKWARD `j` into a sibling arm is a source `goto` (P30 S48) L11281
+- **§162** — The cross-jump "CALL veto" is a COUNT law, not a CALL law (BOUNDS §88a; P30 S48, `func_80189540`) L11317
+- **§177** — 🔴 THE EPILOGUE RETURN-DELAY SLOT IS DECIDED BY YOUR SAVED-REGISTER SET, NOT BY SCHEDULING L17197
+- **§176-A** — "SCHEDULE / DELAY-SLOT / LENGTH-DRIFT ±1" ⇒ check STATEMENT ORDER around the call first L17654
+- **§186** — CROSS-JUMPING RUNS **AFTER** SCHEDULING, SO NO C-LEVEL BARRIER CAN STEER IT L18107
+- **§194-H** — §164-29's WAR fence runs again at SCHED2 ON HARD REGISTERS: an in-place `v &= K` before a branch fences the store that reads v, and when TWO independent stores compete for the one delay slot the fence picks the winner at ZERO length drift (a WIDTH/sh!=sw swap, not a nop). Corrects §167-42's reconstruction (pseudo arm → hard-reg arm) and supplies its first re-runnable A/B. L19326
+- **§194-M** — A STORE in a CONDITIONAL branch's delay slot proves its C statement DOMINATES the branch — reorg can never pull a store out of either thread (gcc-2.7.2, -mips1) L19585
+- **§195-D** — §195 — `masked_diff.mask_for` returns 0 for EVERY `j`/`jal` word, so an internal `j` destination is invisible to match_one, the permuter scorer AND every similarity tier: a control-flow semantic error (which calls execute) surfaces as a 1-instruction residual mislabelled `DELAY-SLOT / profile=schedule`, or as an outright false MATCH L19899
+- **§195-E** — A 0/1 materialised at a JOIN immediately before the controlling `beqz`/`bnez` proves the source NAMED the condition — a truth expression in an `if`'s controlling position reaches `do_jump`, which has no value path L19967
+- **§195-F** — fold-const.c:4825 canonicalises a `?:` whose THEN arm is zero (or constant against a non-constant ELSE) by inverting the condition and swapping the arms — so a ternary's written arm order is byte-inert there, and `c ? 0 : X` is unspellable: it always compiles as `!c ? X : 0` L20025
+- **§195-G** — §NEW — TWO ARMS CALLING THE SAME CALLEE MERGE INTO ONE `jal` UNLESS EACH ARM'S OWN CODE CONSUMES THE RESULT: the C dial that keeps two call sites apart is WHERE the consumer test lives, and the branch SENSE you spell it with is byte-inert (jump.c:1737 canonicalises it) L20077
+- **§195-J** — GTE / PsyQ op CALL-vs-INLINE is a PER-SITE SOURCE FACT, not a TU style — both forms coexist in one TU (measured in 2 TUs), and the tell is the target's own opcodes (`lwc2`/`sqr`/`swc2` vs `jal`), not the sibling. Costs -8 ins on func_8018505C. Corollary: the game's inline `sqr` macro emits TWO hazard nops, the SDK's `Square0` body emits ONE — so the inline form is provably not `Square0` inlined (a second instance of §187's SDK-vs-game GTE nop divergence). L20237
+- **§195-N** — In a call-bearing chain of N≥2 `if (f(...)) return 1;` tests closed by `return 0;`, the LAST test must stay in STATEMENT form — the value form (`return f() != 0;` / `? 1 : 0` / `!!f()`) costs +1 `j` and empties the other N−1 delay slots. The cause is REORG block placement, not jump.c's `delete_jump`. L20434
+- **§197-B** — A REPEATED COMPARE OF ONE VALUE AGAINST ONE CONSTANT IS DELETED BY cse's `qty_comparison_code` CHANNEL (the non-EQ complement of §165-03) — and a front-end-opaque mask on EITHER compare is a pure-C dial that keeps the target's second branch L20634
+- **§199-F** — §164-36b — THE TARGET-HEAD FENCE IS A DELAY-SLOT THREAD SELECTOR, AND IT ONLY FIRES WHEN `mostly_true_jump > 0` (amendment to §164-36; its "−1 instruction" tell is falsified) L20994
+- **§199-G** — At TWO case nodes the switch-vs-if oracle is not blind — but the tell is ALL tests positive + a trailing `j default`, NOT the first test's polarity L21048
+- **§201-C** — §X — A CALL'S OWN DELAY SLOT AND THE UPSTREAM CONDITIONAL BRANCH'S SLOT COMPETE FOR ONE INSN (the call's argument copy), AND ONE STATEMENT'S POSITION RELATIVE TO THE CALL DECIDES BOTH — the residual is visible at the BRANCH, not at the call L21285
+- **§204-A** — A COMPARE THAT APPEARS BOTH IN A BRANCH'S DELAY SLOT AND AGAIN ON THE FALL-THROUGH IS A JOIN WITH TWO INCOMING EDGES: THE TWO GUARDS ARE SEQUENTIAL `if`s, NEVER `if/else if` L21581
+- **§211** — HOIST THE LOOP INIT ABOVE THE DOMINATING GUARD: it fills the guard's delay slot AND flips the counter/pointer register pair (P31 S58) L22389
+- **§221** — A CONSTANT SHARED BY TWO STORES DIES AT THE CALL WHOSE DELAY SLOT REFILLS ITS REGISTER **(single observation — not yet cross-confirmed)** (P31 S58) L22793
+- **§223** — READING A `jal` DELAY SLOT: the value in it was produced BEFORE the call, so it is NEVER that call's return (P31 S58) L22851
+- **§224** — CROSS-JUMP: WRITE THE DUPLICATE, AND READ A SHARED DELAY SLOT AS THE MERGE SIGNATURE (P31 S58) L22913
+- **§232** — WHEN THE `jr` DELAY SLOT'S STORE STORES THE RETURN VALUE, TIE THEM WITH ONE PSEUDO **(single observation — not yet cross-confirmed)** (P31 S58) L23195
+- **§243** — SPELL THE CSE BARRIER AS A REASSIGNED POINTER; AND THE `nop`-AFTER-EVERY-`lh` SIGNATURE (P31 S58b) L23695
+- **§247** — TWO BRANCHES TO **ONE** LABEL MEANS THE SOURCE CONDITION IS NEGATED (P31 S58b) L23847
+- **§224** — addendum (P31 S58b) — CROSS-JUMP MERGES *CALLS*, AND THE DELAY SLOT IS THE DISCRIMINATOR L24534
+- **§263** — A STOLEN DELAY SLOT WHOSE INSTRUCTION IS AN ARG-REGISTER COPY IS AN ARITY ERROR, NOT A SCHEDULE (P31 S59, byte-proven) L24901
+- **ADD-4** — → §225-3/-4 addendum — THE MIRROR ROW: VALUE-RETURN IN THE *TAKEN* ARM + TRAILING BARE `return 0` L25133
+- **ADD-5** — → §1/I1 addendum — THE INVERTED RANGE TEST: `(u32)(x-lo) >= N` WITH THE ZERO-ARM AS THE TRAILING `else` L25147
+- **ADD-5** — → §267-ADD-6 / §172b-1 addendum — THE SIGN-TEST FACE: `(s16)v < 0` IS `sll 16` + `bgez` ON THE SHIFTED COPY, RAW STAYS LIVE — AND THE HALFWORD-ABS SHAPE NEEDS NO RITUAL L25385
+- **ADDENDUM** — to §224 — CROSS-JUMP: THE DUPLICATE CAN BE A PLAIN STORE, NOT ONLY A CALL L25978
+- **ADDENDUM** — to §172a — RE-READING MEMORY (NOT NAMING A TEMP) IS WHAT KEEPS AN INCREMENT'S DELAY-SLOT FILL ALIVE L26278
+- **ADDENDUM** — to §225 / §256 — A GOTO TO A SHARED SET-POINT PREVENTS IF-CONVERSION FROM COLLAPSING A LATER BRANCH TEST L26309
+- **§277** — RETURN-TAIL C SPELLING PICKS THE DELAY-SLOT-FILL vs TRAILING-MOVE TOPOLOGY, AND A NARROWER SECOND VARIABLE KEEPS TWO PSEUDOS INSTEAD OF ONE (P31 S60; `func_801846F0` ov_SC03_104, `func_801A44C4` md_SC07_004, both byte-proven) L26535
+- **ADDENDUM** — to §22 (`volatile`-qualified-global reload lever, cookbook ~L1922) — for a NON-constant, same-address double RMW, a plain memory clobber beats `volatile`, and `volatile` actively breaks a delay-slot fill L27200
+- **ADDENDUM** — to §220 — REFERENCING THE RAW PARAMETER (NO NAMED COPY, NOT EVEN A PIN) LETS THE CALLEE-SAVED SPILL LAND IN THE FIRST CALL'S OWN DELAY SLOT L27454
+- **ADDENDUM** — to §252 — a `>=0`/`<0` split on an unconditionally-decremented value needs the POSTFIX operator INSIDE the branch condition, not a prior statement L27512
+- **ADDENDUM** — to §20's cross-jump EXPLOIT bullet (func_8017E360, ov_SC05_007 — wave dg) L27806
+- **ADDENDUM** — §NNN — sharpens §55a / §164-37 / §165-28 (switch-vs-tree cluster): A SHAPE THAT LOOKS LIKE A SWITCH DISPATCH CAN BE PLAIN NESTED `if`s WHOSE SHARED BODY WAS TRIPLICATED BY THE SOURCE AND THEN CROSS-JUMP-MERGED BACK DOWN L28197
+- **§285** — PRE-INITIALIZING A VARIABLE WITH A SHARED CONSTANT BEFORE A BRANCH MAKES BOTH ARMS OF THE FOLLOWING if/else DESTRUCTIVELY REUSE THE SAME DESTINATION REGISTER FOR THEIR BITWISE RESULT (byte-proven; `func_801811F0`, ov_SC03_102, independently rediscovered across waves di/dj) (P31 S60; waves #, byte-proven) L29052
+- **§286** — FOLD A STATEMENT'S SIDE EFFECT INTO A COMMA-EXPRESSION IN AN ARGUMENT POSITION TO PLACE ITS RTL RELATIVE TO A CALL'S OWN DELAY SLOT (P31 S60/dj; `func_80180A88`, ov_SC06_010, byte-proven 411/411) (P31 S60; waves #, byte-proven) L29056
+- **§291** — THE DELAY-SLOT FALSE-VALUE: A CONDITIONAL BRANCH'S ZERO ARM MUST BE A FALL-THROUGH-ADJACENT BLOCK ENDING IN AN EXPLICIT JUMP, OR REORG CANNOT MATERIALIZE IT INSIDE THE BRANCH'S OWN DELAY SLOT (P31 S60; waves #, byte-proven) L29076
+- **ADDENDUM** — to §253 — SECOND byte-proven card (upgrade from single-observation), and the placement face: postfix-in-condition parks the RMW store in the branch delay slot L29310
+- **§306** — A HAZARD `nop` IN FRONT OF A DIV-RESULT STORE IS A STATEMENT-ORDER DEFECT: THE INDEPENDENT TRAILING STATEMENT MUST BE WRITTEN *BEFORE* THE DIVISION-CONSUMING ONE (P31 S62 T4; byte-proven func_8017E7D0) L29848
+- **§308** — A NAIVE FINAL `goto` DELETES THE TARGET'S `j`+`nop`: SPELL THAT EDGE AS A TAUTOLOGICAL `if` SO cse FOLDS IT TO AN UNCONDITIONAL JUMP *AFTER* jump1's WINDOW HAS CLOSED (P31 S63 t5e-t5i; byte-proven func_80180808) L29957
+- **§308a** — A TWO-INSTRUCTION ARM STUB LAID *BEFORE* THE OTHER ARM AND REACHED ONLY BY A TRAILING `j` SURVIVES ONLY BEHIND A SHORT-CIRCUIT `&&` GUARD PLUS A SEPARATE RE-TEST; EVERY PLAIN if/else-if, GOTO-LADDER, NESTED-INVERTED-if AND 1-/2-NODE switch LETS jump1 INLINE IT (−2 ins) (P31 S63 t5e-t5i; byte-proven func_80180808) L29986
+- **§309** — A FRAME-ADDRESS EQUIVALENCE RIDES *THROUGH* A SKIPPABLE CONDITIONAL: POST-`if` STORES FOLD ONTO `$sp` UNLESS THE `if` SURVIVES jump1 AS A BARRIER-PRECEDED DIAMOND (P31 S63 t5e-t5i; byte-proven func_801812AC) L30020
+- **§311** — A JOIN-BLOCK STORE CAN SWALLOW AN ARM'S LOAD-DELAY `nop`: WHEN ONE ARM'S VALUE COMES FROM A LOAD, DUPLICATE THE STORE INTO BOTH ARMS (P31 S64 t5j-t5m; byte-proven func_8017D7E0) L30091
### instruction scheduling (59)
@@ -101,57 +101,57 @@
- **§32** — The region-a CAMERA-GIANT idiom set: struct-base hoisting + 4 sibling levers (Phase 24 T7, Fable5-cracked on `func_80129CF8` 191 ins, match_one MATCH; transferable to the 6 sibling giants) L2422
- **§34** — The `func_80138ED0` giant crack: gcc-2.7.2's **3-qty sort bug** + the **zero-byte asm allocation toolkit** + the **giv-init fence** (Phase 24 T5; Opus→close=21, Fable5→MATCH ×134) L2454
- **§35** — The region-a sibling-giant harvest: difficulty ≠ $s-reg count (it's global-array hoisting) + the banking recipe + new loop idioms (Phase 24 T7, 5 parallel Opus-Max agents) L2471
-- **§3-A4** — SINK THE CONSUMER CALL INTO THE ARMS (the inverse of A1; `func_8016AB6C`, byte-proven) L3444
-- **§49** — The LUID DIAL: a zero-byte SCHEDULING dial (the sched.c analogue of §47) — `func_8017A4AC` (536 ins ×134), Phase 26 session 8 L3527
-- **§66d-5** — `residual_class`'s "structural ⇒ permuter CPU is waste" is WRONG for schedule permutations (measured, Phase 29 SESSION-18) L5491
-- **§3-The** — attribution primitive (use this before calling anything a scheduling residual) L6057
-- **§3-The** — scheduling rules (refining §135-2 and §135-4) L8912
-- **Consequence** — for the family (a real scheduling decision) L10095
-- **§148** — The loop.c hoisting THRESHOLD is arithmetic you can compute, and the `?:` clamp that folds to MIN_EXPR (P30 S42, `func_8017C6F4`, 947 ins) L10145
-- **§3-A.** — `move_movables` hoists iff `threshold × savings × lifetime ≥ insn_count` — and you can read it L10151
-- **§16Z** — SHARPENS *(sharpens §37 "the /s-DEP LATTICE", §136-13, §136-14, §16Xy, §162q, `gcc-2.7.2-map/sched.md` §64)* L14353
-- **§175** — A CALLER-SAVED REGISTER PIN CAN BE A CORRECTNESS BUG, NOT JUST A SCHEDULING CHOICE (P31 wave H, 2026-08-15) L16735
-- **§177** — 🔴 THE EPILOGUE RETURN-DELAY SLOT IS DECIDED BY YOUR SAVED-REGISTER SET, NOT BY SCHEDULING L17182
-- **§3-B.** — A `return ` IS A PRIORITY-1 HARD-REG SET THE SCHEDULER PLACES FIRST (func_8001BE30, 92 ins) L17267
-- **§176-A** — "SCHEDULE / DELAY-SLOT / LENGTH-DRIFT ±1" ⇒ check STATEMENT ORDER around the call first L17639
-- **§176-C** — 🔴 WALL REFUTATION: a hard-register pin CANNOT schedule around a call, because of a genuine gcc-2.7.2 bug L17709
-- **§186** — CROSS-JUMPING RUNS **AFTER** SCHEDULING, SO NO C-LEVEL BARRIER CAN STEER IT L18092
-- **§193-C** — gcc-2.7.2 cross_jump merges the SCHEDULED common SUFFIX only — there is no prefix/head merge, so §8/§48-A1's "duplicate into both arms and cross_jump refunds it" is a TAIL-only lever L18547
-- **§193-D** — A COMPILER-GENERATED ARGUMENT COPY IS A `optimize_reg_copy_1` TRIGGER: when the pointer's LAST use in a block precedes a call that takes the pointer *as a register*, sched1 hoists the implicit `move $aN,$sN` to the block top and local-alloc re-bases the WHOLE block's memory operands onto `$aN`. The only C dial is a label (the §165-24 goto-join) between the block and the call. L18581
-- **§193-F** — §148-A2 — The `threshold -= 3` STAIRCASE: `move_movables` admits a COUNT of invariants, not a boolean — two identical merged constants split hoisted/not-hoisted by LIST ORDER, and `insn_count` picks the rank cutoff L18682
-- **§194-A** — A zero-byte scheduling fence goes AFTER the defining statement to make that computation emit FIRST in its block — and the barrier predicate is `volatile`-or-colon-less, not the `"memory"` clobber (COMPLEMENTS §165-40; does not refute it) L18950
-- **§194-D** — Declared width of a computed-value local is a sched1 dial (count-neutral) — a replication + attribution correction of §165-17, NOT a new argument-register law L19117
-- **§194-H** — §164-29's WAR fence runs again at SCHED2 ON HARD REGISTERS: an in-place `v &= K` before a branch fences the store that reads v, and when TWO independent stores compete for the one delay slot the fence picks the winner at ZERO length drift (a WIDTH/sh!=sw swap, not a nop). Corrects §167-42's reconstruction (pseudo arm → hard-reg arm) and supplies its first re-runnable A/B. L19311
-- **§194-K** — Blind sched1's alias oracle with a second SET of a pointer pseudo — the first zero-byte, non-volatile, dependence-CREATING lever (corrects §167-05's "volatile is the only door"; fourth consumer of reg_n_sets) L19444
-- **§194-N** — §193-D's C dial is misstated: the lever is a SURVIVING CODE_LABEL (a label with a real incoming edge), not "a label between the block and the call" — a bare label, or a `goto L; L:` pair whose target is the next active insn, is deleted by jump1 (jump.c:663-669 → delete_insn → jump.c:3458-3461, and jump.c:243 for the bare case) long before sched1/local-alloc, and costs exactly zero bytes L19628
-- **§195-D** — §195 — `masked_diff.mask_for` returns 0 for EVERY `j`/`jal` word, so an internal `j` destination is invisible to match_one, the permuter scorer AND every similarity tier: a control-flow semantic error (which calls execute) surfaces as a 1-instruction residual mislabelled `DELAY-SLOT / profile=schedule`, or as an outright false MATCH L19884
-- **§199-A** — §189-A's asm→source inference is byte-FALSE: an interloper between a split constant's `lui`/`ori` is a SCHEDULE fact, not a source fact — and the separator is the BIRTHING BOOST, not a "priority floor" (§189-A's split-timing half survives; its "no statement order / no pin" absolute and the candidate's own forward-scheduler narrative both fall) L20718
-- **§199-F** — §164-36b — THE TARGET-HEAD FENCE IS A DELAY-SLOT THREAD SELECTOR, AND IT ONLY FIRES WHEN `mostly_true_jump > 0` (amendment to §164-36; its "−1 instruction" tell is falsified) L20979
-- **§205** — THE CHAINED ASSIGNMENT IS ITS OWN SCHEDULING DIAL: `*b = *a = v;` moves an argument copy that no local, no pin and no statement reorder will move (P31 S56) L22057
-- **§211** — HOIST THE LOOP INIT ABOVE THE DOMINATING GUARD: it fills the guard's delay slot AND flips the counter/pointer register pair (P31 S58) L22374
-- **§219** — COMPOUND `+=`, FULL ASSIGNMENT, AND AN EXPLICIT TEMP ARE THREE DIFFERENT SCHEDULES OF ONE READ-MODIFY-WRITE (P31 S58) L22711
-- **§30** — addendum (P31 S58) — the `/s` grant closes a SCHEDULING residual and a REGISTER residual with one edit L23216
-- **§165-40** — addendum (P31 S58) — the barrier goes at the COPY SITE, not inside the region it protects L23248
-- **§239** — TWO-STATEMENT INTEGER-SPACE MATERIALISATION REORDERS `la` vs `sll`; AND THE PLUS-TREE OPERAND ORDER (P31 S58b) L23560
-- **§243** — SPELL THE CSE BARRIER AS A REASSIGNED POINTER; AND THE `nop`-AFTER-EVERY-`lh` SIGNATURE (P31 S58b) L23680
-- **§245** — THE CALL'S ARGUMENT LIST IS A SCHEDULING SLOT (P31 S58b) L23745
-- **§211** — addendum (P31 S58b) — INIT PLACEMENT: FIVE MORE DIALS BEYOND THE GUARD HOIST L24275
-- **§263** — A STOLEN DELAY SLOT WHOSE INSTRUCTION IS AN ARG-REGISTER COPY IS AN ARITY ERROR, NOT A SCHEDULE (P31 S59, byte-proven) L24886
-- **ADD-8** — → §245 addendum — THE RE-TIE BARRIER PINS CALL-ARG SETUP TO SOURCE ORDER (construct 6) L25162
-- **ADDENDUM** — to §244 — THE COMPILER BARRIER, NOT `volatile`, BLOCKS A STORE→LOAD HOIST THROUGH A POINTER-OFFSET FIELD L26028
-- **§281** — GROUP COPY-THEN-RMW BY OPERATION KIND, NOT FIELD BY FIELD: sched1 does the interleaving, the source must not (P31 S60; wave cf, func_80180FB4, ov_SC03_111, byte-proven) L26949
-- **§NNN** — A DEPENDENT COPY-THEN-RMW BLOCK MUST BE SOURCE-GROUPED BY OPERATION KIND, NOT BY FIELD, AND SCHED1 DOES THE INTERLEAVING (P31 S60; `func_80180FB4`, ov_SC03_111, byte-proven) L26950
-- **§282** — gcc's OWN LOOP REVERSAL PUTS THE COUNTER INIT AFTER THE HOISTED MOVABLES — a position no hand-written down-count can reach (P31 S60; wave cf, func_80180DD8, ov_SC04_005, byte-proven) L26995
-- **§NNN** — WRITE THE UP-COUNT LOOP: gcc's OWN REVERSAL PRODUCES A COUNTER-INIT INSTRUCTION THAT LANDS AFTER HOISTED MOVABLES, WHICH A HAND-WRITTEN DOWN-COUNT LOOP CANNOT REPRODUCE (P31 S60; `func_80180DD8`, ov_SC04_005, byte-proven) L26996
-- **ADDENDUM** — to §195-N — a GNU statement-expression slider must sit INSIDE the conditional arm's value position, not as a post-hoc barrier, to block the store-flag transform on a ternary chain L27266
-- **ADDENDUM** — §NNN — sharpens §167-13's boundary: CHAINING TWO IDENTICAL SIDE-BY-SIDE STORES INTO ONE C ASSIGNMENT STATEMENT IS A MID-BLOCK SCHEDULING-PRIORITY DIAL, NOT ONLY A STORE-ORDER SPELLING L28219
-- **§284** — COMBINE CAN REASSOCIATE TWO SEQUENTIAL BITWISE-AND MASKS INTO ONE AGAINST THE PRE-MASK VALUE; AN ASM IN/OUT FENCE RIGHT AFTER THE FIRST MASK BLOCKS IT (P31, wave dd, `func_8018087C`, ov_SC04_020, byte-proven) (P31 S60; waves #, byte-proven) L29033
-- **§298** — THE SHARED-TAIL POSITION DIAGNOSTIC: A FOLDED TAIL *BETWEEN* SWITCH ARMS MEANS PER-ARM DUPLICATED STATEMENTS, NOT A HOISTED POST-SWITCH STATEMENT (P31 S61; waves g0e/g0f, `func_80181B68`, ov_SC06_016, byte-proven 68/68) L29501
-- **§299** — TWO INDEPENDENT EXTRACTION CHAINS EMIT CONTIGUOUSLY INSIDE ONE EXPRESSION; ONLY A STATEMENT BOUNDARY MAKES THE SCHEDULER INTERLEAVE THEM (P31 S61; wave m0a, `func_8003A404`, main, byte-proven 8/8) L29526
-- **§307** — THE BRUTE-FORCE-THE-STATEMENT-ORDERS LEVER HAS A BOUND: A FAN-OUT COPY'S PRIORITY IS SCHEDULER-INTERNAL, AND NO SOURCE ORDER REACHES IT (P31 S63; byte-evidenced NEGATIVE result, main wave) L29898
-- **§309** — A FRAME-ADDRESS EQUIVALENCE RIDES *THROUGH* A SKIPPABLE CONDITIONAL: POST-`if` STORES FOLD ONTO `$sp` UNLESS THE `if` SURVIVES jump1 AS A BARRIER-PRECEDED DIAMOND (P31 S63 t5e-t5i; byte-proven func_801812AC) L30005
+- **§3-A4** — SINK THE CONSUMER CALL INTO THE ARMS (the inverse of A1; `func_8016AB6C`, byte-proven) L3459
+- **§49** — The LUID DIAL: a zero-byte SCHEDULING dial (the sched.c analogue of §47) — `func_8017A4AC` (536 ins ×134), Phase 26 session 8 L3542
+- **§66d-5** — `residual_class`'s "structural ⇒ permuter CPU is waste" is WRONG for schedule permutations (measured, Phase 29 SESSION-18) L5506
+- **§3-The** — attribution primitive (use this before calling anything a scheduling residual) L6072
+- **§3-The** — scheduling rules (refining §135-2 and §135-4) L8927
+- **Consequence** — for the family (a real scheduling decision) L10110
+- **§148** — The loop.c hoisting THRESHOLD is arithmetic you can compute, and the `?:` clamp that folds to MIN_EXPR (P30 S42, `func_8017C6F4`, 947 ins) L10160
+- **§3-A.** — `move_movables` hoists iff `threshold × savings × lifetime ≥ insn_count` — and you can read it L10166
+- **§16Z** — SHARPENS *(sharpens §37 "the /s-DEP LATTICE", §136-13, §136-14, §16Xy, §162q, `gcc-2.7.2-map/sched.md` §64)* L14368
+- **§175** — A CALLER-SAVED REGISTER PIN CAN BE A CORRECTNESS BUG, NOT JUST A SCHEDULING CHOICE (P31 wave H, 2026-08-15) L16750
+- **§177** — 🔴 THE EPILOGUE RETURN-DELAY SLOT IS DECIDED BY YOUR SAVED-REGISTER SET, NOT BY SCHEDULING L17197
+- **§3-B.** — A `return ` IS A PRIORITY-1 HARD-REG SET THE SCHEDULER PLACES FIRST (func_8001BE30, 92 ins) L17282
+- **§176-A** — "SCHEDULE / DELAY-SLOT / LENGTH-DRIFT ±1" ⇒ check STATEMENT ORDER around the call first L17654
+- **§176-C** — 🔴 WALL REFUTATION: a hard-register pin CANNOT schedule around a call, because of a genuine gcc-2.7.2 bug L17724
+- **§186** — CROSS-JUMPING RUNS **AFTER** SCHEDULING, SO NO C-LEVEL BARRIER CAN STEER IT L18107
+- **§193-C** — gcc-2.7.2 cross_jump merges the SCHEDULED common SUFFIX only — there is no prefix/head merge, so §8/§48-A1's "duplicate into both arms and cross_jump refunds it" is a TAIL-only lever L18562
+- **§193-D** — A COMPILER-GENERATED ARGUMENT COPY IS A `optimize_reg_copy_1` TRIGGER: when the pointer's LAST use in a block precedes a call that takes the pointer *as a register*, sched1 hoists the implicit `move $aN,$sN` to the block top and local-alloc re-bases the WHOLE block's memory operands onto `$aN`. The only C dial is a label (the §165-24 goto-join) between the block and the call. L18596
+- **§193-F** — §148-A2 — The `threshold -= 3` STAIRCASE: `move_movables` admits a COUNT of invariants, not a boolean — two identical merged constants split hoisted/not-hoisted by LIST ORDER, and `insn_count` picks the rank cutoff L18697
+- **§194-A** — A zero-byte scheduling fence goes AFTER the defining statement to make that computation emit FIRST in its block — and the barrier predicate is `volatile`-or-colon-less, not the `"memory"` clobber (COMPLEMENTS §165-40; does not refute it) L18965
+- **§194-D** — Declared width of a computed-value local is a sched1 dial (count-neutral) — a replication + attribution correction of §165-17, NOT a new argument-register law L19132
+- **§194-H** — §164-29's WAR fence runs again at SCHED2 ON HARD REGISTERS: an in-place `v &= K` before a branch fences the store that reads v, and when TWO independent stores compete for the one delay slot the fence picks the winner at ZERO length drift (a WIDTH/sh!=sw swap, not a nop). Corrects §167-42's reconstruction (pseudo arm → hard-reg arm) and supplies its first re-runnable A/B. L19326
+- **§194-K** — Blind sched1's alias oracle with a second SET of a pointer pseudo — the first zero-byte, non-volatile, dependence-CREATING lever (corrects §167-05's "volatile is the only door"; fourth consumer of reg_n_sets) L19459
+- **§194-N** — §193-D's C dial is misstated: the lever is a SURVIVING CODE_LABEL (a label with a real incoming edge), not "a label between the block and the call" — a bare label, or a `goto L; L:` pair whose target is the next active insn, is deleted by jump1 (jump.c:663-669 → delete_insn → jump.c:3458-3461, and jump.c:243 for the bare case) long before sched1/local-alloc, and costs exactly zero bytes L19643
+- **§195-D** — §195 — `masked_diff.mask_for` returns 0 for EVERY `j`/`jal` word, so an internal `j` destination is invisible to match_one, the permuter scorer AND every similarity tier: a control-flow semantic error (which calls execute) surfaces as a 1-instruction residual mislabelled `DELAY-SLOT / profile=schedule`, or as an outright false MATCH L19899
+- **§199-A** — §189-A's asm→source inference is byte-FALSE: an interloper between a split constant's `lui`/`ori` is a SCHEDULE fact, not a source fact — and the separator is the BIRTHING BOOST, not a "priority floor" (§189-A's split-timing half survives; its "no statement order / no pin" absolute and the candidate's own forward-scheduler narrative both fall) L20733
+- **§199-F** — §164-36b — THE TARGET-HEAD FENCE IS A DELAY-SLOT THREAD SELECTOR, AND IT ONLY FIRES WHEN `mostly_true_jump > 0` (amendment to §164-36; its "−1 instruction" tell is falsified) L20994
+- **§205** — THE CHAINED ASSIGNMENT IS ITS OWN SCHEDULING DIAL: `*b = *a = v;` moves an argument copy that no local, no pin and no statement reorder will move (P31 S56) L22072
+- **§211** — HOIST THE LOOP INIT ABOVE THE DOMINATING GUARD: it fills the guard's delay slot AND flips the counter/pointer register pair (P31 S58) L22389
+- **§219** — COMPOUND `+=`, FULL ASSIGNMENT, AND AN EXPLICIT TEMP ARE THREE DIFFERENT SCHEDULES OF ONE READ-MODIFY-WRITE (P31 S58) L22726
+- **§30** — addendum (P31 S58) — the `/s` grant closes a SCHEDULING residual and a REGISTER residual with one edit L23231
+- **§165-40** — addendum (P31 S58) — the barrier goes at the COPY SITE, not inside the region it protects L23263
+- **§239** — TWO-STATEMENT INTEGER-SPACE MATERIALISATION REORDERS `la` vs `sll`; AND THE PLUS-TREE OPERAND ORDER (P31 S58b) L23575
+- **§243** — SPELL THE CSE BARRIER AS A REASSIGNED POINTER; AND THE `nop`-AFTER-EVERY-`lh` SIGNATURE (P31 S58b) L23695
+- **§245** — THE CALL'S ARGUMENT LIST IS A SCHEDULING SLOT (P31 S58b) L23760
+- **§211** — addendum (P31 S58b) — INIT PLACEMENT: FIVE MORE DIALS BEYOND THE GUARD HOIST L24290
+- **§263** — A STOLEN DELAY SLOT WHOSE INSTRUCTION IS AN ARG-REGISTER COPY IS AN ARITY ERROR, NOT A SCHEDULE (P31 S59, byte-proven) L24901
+- **ADD-8** — → §245 addendum — THE RE-TIE BARRIER PINS CALL-ARG SETUP TO SOURCE ORDER (construct 6) L25177
+- **ADDENDUM** — to §244 — THE COMPILER BARRIER, NOT `volatile`, BLOCKS A STORE→LOAD HOIST THROUGH A POINTER-OFFSET FIELD L26043
+- **§281** — GROUP COPY-THEN-RMW BY OPERATION KIND, NOT FIELD BY FIELD: sched1 does the interleaving, the source must not (P31 S60; wave cf, func_80180FB4, ov_SC03_111, byte-proven) L26964
+- **§NNN** — A DEPENDENT COPY-THEN-RMW BLOCK MUST BE SOURCE-GROUPED BY OPERATION KIND, NOT BY FIELD, AND SCHED1 DOES THE INTERLEAVING (P31 S60; `func_80180FB4`, ov_SC03_111, byte-proven) L26965
+- **§282** — gcc's OWN LOOP REVERSAL PUTS THE COUNTER INIT AFTER THE HOISTED MOVABLES — a position no hand-written down-count can reach (P31 S60; wave cf, func_80180DD8, ov_SC04_005, byte-proven) L27010
+- **§NNN** — WRITE THE UP-COUNT LOOP: gcc's OWN REVERSAL PRODUCES A COUNTER-INIT INSTRUCTION THAT LANDS AFTER HOISTED MOVABLES, WHICH A HAND-WRITTEN DOWN-COUNT LOOP CANNOT REPRODUCE (P31 S60; `func_80180DD8`, ov_SC04_005, byte-proven) L27011
+- **ADDENDUM** — to §195-N — a GNU statement-expression slider must sit INSIDE the conditional arm's value position, not as a post-hoc barrier, to block the store-flag transform on a ternary chain L27281
+- **ADDENDUM** — §NNN — sharpens §167-13's boundary: CHAINING TWO IDENTICAL SIDE-BY-SIDE STORES INTO ONE C ASSIGNMENT STATEMENT IS A MID-BLOCK SCHEDULING-PRIORITY DIAL, NOT ONLY A STORE-ORDER SPELLING L28234
+- **§284** — COMBINE CAN REASSOCIATE TWO SEQUENTIAL BITWISE-AND MASKS INTO ONE AGAINST THE PRE-MASK VALUE; AN ASM IN/OUT FENCE RIGHT AFTER THE FIRST MASK BLOCKS IT (P31, wave dd, `func_8018087C`, ov_SC04_020, byte-proven) (P31 S60; waves #, byte-proven) L29048
+- **§298** — THE SHARED-TAIL POSITION DIAGNOSTIC: A FOLDED TAIL *BETWEEN* SWITCH ARMS MEANS PER-ARM DUPLICATED STATEMENTS, NOT A HOISTED POST-SWITCH STATEMENT (P31 S61; waves g0e/g0f, `func_80181B68`, ov_SC06_016, byte-proven 68/68) L29516
+- **§299** — TWO INDEPENDENT EXTRACTION CHAINS EMIT CONTIGUOUSLY INSIDE ONE EXPRESSION; ONLY A STATEMENT BOUNDARY MAKES THE SCHEDULER INTERLEAVE THEM (P31 S61; wave m0a, `func_8003A404`, main, byte-proven 8/8) L29541
+- **§307** — THE BRUTE-FORCE-THE-STATEMENT-ORDERS LEVER HAS A BOUND: A FAN-OUT COPY'S PRIORITY IS SCHEDULER-INTERNAL, AND NO SOURCE ORDER REACHES IT (P31 S63; byte-evidenced NEGATIVE result, main wave) L29913
+- **§309** — A FRAME-ADDRESS EQUIVALENCE RIDES *THROUGH* A SKIPPABLE CONDITIONAL: POST-`if` STORES FOLD ONTO `$sp` UNLESS THE `if` SURVIVES jump1 AS A BARRIER-PRECEDED DIAMOND (P31 S63 t5e-t5i; byte-proven func_801812AC) L30020
-### register allocation & pins (103)
+### register allocation & pins (104)
- **§10** — Closing the regalloc/scheduling hard tail by hand (LZSS, Phase 7 session F — the full close) L835
- **Residual** — A — commutative `|`/`&`/`+` result lands in the wrong source-operand register L856
@@ -161,168 +161,170 @@
- **§22** — DEF-side loose-typing recovery + grinder blacklist (Phase 21) L2005
- **§24** — The `ov_SC01_077_a.c` split-file vein: split-aware propagation, but loose-typing-gated (Phase 21) L2085
- **§25** — The "schedule" class is mostly COALESCING (pin-crackable), not scheduling; + the gate two-stage + h_exact over-counts ×134 (Phase 21, cont.6) L2132
-- **§42** — The F-band ≤28 regalloc crack wave: register-pin/DENSITY levers beat the permuter (Phase 25 T7 F-band, 2026-07-10; Ultracode 9-worker wave, 4/9 banked byte-identical, 266 swept ×134) L2900
-- **§43** — The K&R s16-param definition DISSOLVES the "narrow-param wall" for by-value register args (Phase 25 task A, Fable5 crack of the 369-ins giant `func_80166994` ×134, 2026-07-11) L3195
-- **§45** — The flagship `func_80133CD4` crack (399 ins ×134): the merged-variable permutation-breaker + the 1-death local-alloc gate (Phase 25 task A giant escalation, Fable5 gdb-on-cc1, 2026-07-11) L3298
-- **§47** — The live-length SLIDER: splitting a global.c allocno-priority TIE with one zero-byte asm (Phase 26 session 8, Fable5 Max, byte-proven on `func_8017BEBC` 952 ins ×113) L3365
-- **§48** — The 12-core jr crack wave: the ALLOCNO-PRICING dials and the EBB rule (Phase 26 session 8, Ultracode, 9/12 MATCH first pass) L3405
-- **§3-A.** — ALLOCNO-PRICING DIALS — move a value into the register you want, byte-neutrally L3413
-- **§52** — The WALKER-FAMILY skeleton: 6 regalloc-order levers + a deeply-characterized intrinsic wall (`func_80178004`, 165 ins ×134; Phase 26, Fable5, 2026-07-15) L3913
-- **§52a** — The regalloc sibling wave: new levers + two new wall classes (cheap-Opus applying §52, 2026-07-15) L3959
-- **§52b** — Sibling wave 2: more de-pin levers, a third wall class, and the match_one→whole-binary gap at scale (2026-07-15) L3997
-- **§66d-1** — What transfers between giants is the LOOP, not the PIN L5280
-- **§70** — The giv-init base register: walk the PARAMETER, not a copy of it (Phase 29 SESSION-18, `func_801777BC`) L5619
-- **§71** — Before mapping a giant, look for an already-matched SIBLING beside it (Phase 29 SESSION-18, `func_8017D960`, 3,338 ins) L5660
-- **§72** — A `register __asm__` pin is a PREFERENCE, not a reservation (Phase 29 SESSION-18, `func_8017F510`) L5726
-- **§74** — Auditing a pinned draft: the §72 hazard is CALLER-SAVED pins spanning a call, and only the disassembly can tell you (Phase 29 SESSION-19, `func_8017D960` b2, 5 pins) L5822
-- **§76** — The allocno CLASS (local vs global) is the dominant regalloc lever, and C reaches it ONLY through declaration scope and variable reuse (Phase 29 SESSION-19, behemoth #3 `func_8017F510` 1,511 ins, 97 → MATCH, pin-free) L6028
-- **§78** — A LENGTH drift can be a register grant in disguise; and `fold` never leaves a literal first in an `|` chain (Phase 29 SESSION-19, behemoth #2 `func_8017D960` 3,338 ins, 1806 → 0, pin-free) L6174
-- **§76** — confirmed at scale, and a pin nuance L6251
-- **§80** — A do-not-re-buy entry is scoped to its BASE, not to the function; and the pin's hidden cost is an unconditional `qty_phys_sugg` (Phase 29 SESSION-19, `func_8017BF14` 45 → 0) L6270
-- **§3-The** — pin's hidden cost, with the citation L6291
-- **§83** — The parameterised-repeat law, the spill-area trap, and why a per-case edit cannot move a per-case symptom (Phase 29 SESSION-20, `func_80183814` 5,122 ins, cold-ish start → 36 structural / 99.3%) L6412
-- **§83c** — TRAP: a "dead local" in a prior draft may be gcc's OWN spill area L6445
-- **§86** — Pinned-exemplar templatability is a PER-FAMILY property, not a per-member rate; and the §42e pin guard is now over-conservative (Phase 29 SESSION-20) L6589
-- **§3-Two** — further notes worth keeping L8248
-- **§137** — REGALLOC-PERM is a TWO-COMPILE ARITHMETIC PROBLEM, not a permuter job L9344
-- **§3-The** — same swallow, twice more, in the integration spine L9709
-- **§3-B.** — A `?:` on MEMORY operands costs ~16 bytes of invisible frame; on REGISTER operands, zero L10057
-- **§3-D.** — A lone `$t8`/`$t9` in the target is RELOAD SCRATCH — reproduce the spill, don't pin the register L10073
-- **§3-C.** — A zero-byte ALLOCNO-PRIORITY slider L10184
-- **§150** — A register ROTATION across symmetric blocks is VARIABLE-IDENTITY evidence, not an allocator tie (P30 S43, `func_8017C6F4`, 947 ins ×4) L10312
-- **§152** — BYTE SIZE is the family key that name- and h_seq-grouping both miss (P30 S43, the 0xECC family: 1 crack → 12 overlays → 11,364 ins) L10418
-- **§155** — hi/lo literal scanning MUST track base registers (S45) L10558
-- **§158** — The RANGE-EXTENDER: a fourth zero-emission asm lever completes the allocno toolkit (P30 S46 tier-3, `func_8017CE58`, 733 ins) L10712
-- **Bonus** — facts worth keeping L10757
-- **§156** — THE PREFERENCE-DONOR MERGE: cross-region variable reuse is what fills a0-a3, and a call-arg use in ONE region steers the fill in ALL of them (P30 S46 tier-3, `func_80186E24`, 611 ins: 236-off "S11 regalloc-order" → MATCH, zero new pins) L10772
-- **§175** — A CALLER-SAVED REGISTER PIN CAN BE A CORRECTNESS BUG, NOT JUST A SCHEDULING CHOICE (P31 wave H, 2026-08-15) L16735
-- **§176j** — STOPPING A WAVE MID-FLIGHT COSTS THE IN-FLIGHT TAIL (and how much is recoverable) L17119
-- **§177** — 🔴 THE EPILOGUE RETURN-DELAY SLOT IS DECIDED BY YOUR SAVED-REGISTER SET, NOT BY SCHEDULING L17182
-- **§179-A** — 🔴 A LOOP-WALKED POINTER **PARAMETER** HANDS ITS ARGUMENT REGISTER TO THE GIV (9 byte-proofs) L17336
-- **§179-F** — PINNING A LOOP-WALKED POINTER IS A TOTAL OFF-SWITCH FOR STRENGTH REDUCTION L17532
-- **§179-G** — 🟡 A PIN CAN **CREATE** A COMBINE `LOG_LINK` AND DELETE AN `andi` (sixth RC-5 channel, n=1) L17555
-- **§176** — SEVEN LEVERS FROM THE P31 OVERNIGHT WAVES (2026-08-15): statement order, false regalloc, and the pin that fights back L17633
-- **§176-B** — "REGALLOC-PERM, 1-4 instructions off" ⇒ it is usually NOT register allocation L17663
-- **§176-C** — 🔴 WALL REFUTATION: a hard-register pin CANNOT schedule around a call, because of a genuine gcc-2.7.2 bug L17709
-- **§3-18** — of 20 reconciled while keeping the match. The two that did not are mechanism, not effort. L17962
-- **§186** — CROSS-JUMPING RUNS **AFTER** SCHEDULING, SO NO C-LEVEL BARRIER CAN STEER IT L18092
-- **§186c** — WHERE A VALUE IS LOADED DECIDES WHICH ALLOCATOR OWNS IT, AND THEREFORE ITS REGISTER L18121
-- **§193-B** — A NARROW CAST OF A WIDE PARAMETER COSTS ONE EXTRA INSTRUCTION WHEN ITS STATEMENT SITS AFTER AN INTERVENING `jal` — AND THE DECIDER IS `combine.c:929`'s CROSS-CALL GUARD, NOT REGISTER ALLOCATION L18509
-- **§193-D** — A COMPILER-GENERATED ARGUMENT COPY IS A `optimize_reg_copy_1` TRIGGER: when the pointer's LAST use in a block precedes a call that takes the pointer *as a register*, sched1 hoists the implicit `move $aN,$sN` to the block top and local-alloc re-bases the WHOLE block's memory operands onto `$aN`. The only C dial is a label (the §165-24 goto-join) between the block and the call. L18581
-- **§194-B** — A `addu $rA,$rB,$zero` copy feeding ≥2 `sh` stores is a SECOND, 16-BIT-DECLARED local — the width, not the clamp or the join liveness, is what keeps the copy (and func_80183094's pin + `"memory"` clobber are both provably inert) L19016
-- **§194-C** — A CALLER-SAVED loop counter proves its live range crosses ZERO calls — so it cannot share a pseudo with any value LIVE ACROSS a call (but it may freely share one with values that merely sit between calls) L19054
-- **§194-D** — Declared width of a computed-value local is a sched1 dial (count-neutral) — a replication + attribution correction of §165-17, NOT a new argument-register law L19117
-- **§194-G** — Reading the integer half of a 16.16 stack aggregate: REGISTER-LIVENESS, not the C spelling, decides `sra` vs `lhu` — and the break is count-neutral L19268
-- **§194-H** — §164-29's WAR fence runs again at SCHED2 ON HARD REGISTERS: an in-place `v &= K` before a branch fences the store that reads v, and when TWO independent stores compete for the one delay slot the fence picks the winner at ZERO length drift (a WIDTH/sh!=sw swap, not a nop). Corrects §167-42's reconstruction (pseudo arm → hard-reg arm) and supplies its first re-runnable A/B. L19311
-- **§194-N** — §193-D's C dial is misstated: the lever is a SURVIVING CODE_LABEL (a label with a real incoming edge), not "a label between the block and the call" — a bare label, or a `goto L; L:` pair whose target is the next active insn, is deleted by jump1 (jump.c:663-669 → delete_insn → jump.c:3458-3461, and jump.c:243 for the bare case) long before sched1/local-alloc, and costs exactly zero bytes L19628
-- **§195-B** — A CALL_INSN does not start a basic block in gcc-2.7.2 — so a call-crossing temp can be a LOCAL-alloc quantity (the missing precondition under §48-A2 / §52 / regalloc.md K8) L19794
-- **§195-F** — fold-const.c:4825 canonicalises a `?:` whose THEN arm is zero (or constant against a non-constant ELSE) by inverting the condition and swapping the arms — so a ternary's written arm order is byte-inert there, and `c ? 0 : X` is unspellable: it always compiles as `!c ? X : 0` L20010
-- **§197-C** — Fix A1 (operand order) cannot move a commutative destination whose .greg conflict set already contains BOTH operand hard registers — split the accumulate so the destination IS the load's pseudo L20647
-- **§199-A** — §189-A's asm→source inference is byte-FALSE: an interloper between a split constant's `lui`/`ori` is a SCHEDULE fact, not a source fact — and the separator is the BIRTHING BOOST, not a "priority floor" (§189-A's split-timing half survives; its "no statement order / no pin" absolute and the candidate's own forward-scheduler narrative both fall) L20718
-- **§199-B** — A permutation sweep that holds ANY statement fixed is not a sweep: the statement an agent pins as "obviously load-bearing" is the one carrying the signal, and the partial sweep returns a FLAT residual that reads as proof of order-invariance L20767
-- **§199-E** — §189-A BOUNDED AND CORRECTED — the discriminator is INSN_PRIORITY, not "is the interloper a constant": an insn between a `lui`/`ori` pair proves NOTHING about the source spelling unless it TIES the `ori` on priority, and on the pinned `-mcpu=3000` triple a dependent load never does L20920
-- **§205** — THE CHAINED ASSIGNMENT IS ITS OWN SCHEDULING DIAL: `*b = *a = v;` moves an argument copy that no local, no pin and no statement reorder will move (P31 S56) L22057
-- **§208** — TWO NAMED LOCALS FOR ONE RELOADED EXPRESSION BUY TWO ALLOCNOS — the naming granularity owns the REGISTER SPLIT, not just the load count (P31 S58) L22202
-- **§211** — HOIST THE LOOP INIT ABOVE THE DOMINATING GUARD: it fills the guard's delay slot AND flips the counter/pointer register pair (P31 S58) L22374
-- **§215** — PIN ECONOMY: the twin's pins are NOT part of the shape, and §17's "pin every call-crossing value" is over-broad (P31 S58) L22560
-- **§220** — THE PARAMETER ITSELF IS A REGALLOC DIAL: use it directly, prefer `s32` to `void*`, and place the save-copy AFTER the first call (P31 S58) L22738
-- **§221** — A CONSTANT SHARED BY TWO STORES DIES AT THE CALL WHOSE DELAY SLOT REFILLS ITS REGISTER **(single observation — not yet cross-confirmed)** (P31 S58) L22778
-- **§30** — addendum (P31 S58) — the `/s` grant closes a SCHEDULING residual and a REGISTER residual with one edit L23216
-- **§244** — `volatile` IS A COUNTING INSTRUMENT, A STORE-ORDER PIN, AND MUST SOMETIMES BE ASYMMETRIC (P31 S58b) L23710
-- **§248** — SPLIT THE LOAD FROM THE ARITHMETIC: A FUSED `g + K` DENIES THE CALLEE-SAVED REGISTER ITS DIRECT HOME (P31 S58b) L23866
-- **§253** — POSTFIX `++` vs `+= 1` PICKS A DIFFERENT SCRATCH REGISTER **(single observation — not yet cross-confirmed)** (P31 S58b) L24012
-- **§254** — THE DEAD PARAMETER IS A REGISTER-PLACEMENT TOOL **(single observation — not yet cross-confirmed)** (P31 S58b) L24026
-- **§215** — addendum (P31 S58b) — PIN ECONOMY, PART 2: NINE REFINEMENTS L24383
-- **§223** — addendum (P31 S58b) — FIVE MORE CONFIRMATIONS, AND THE CONSTANT-IN-`$v0` CASE L24495
-- **§263** — A STOLEN DELAY SLOT WHOSE INSTRUCTION IS AN ARG-REGISTER COPY IS AN ARITY ERROR, NOT A SCHEDULE (P31 S59, byte-proven) L24886
-- **ADD-8** — → §245 addendum — THE RE-TIE BARRIER PINS CALL-ARG SETUP TO SOURCE ORDER (construct 6) L25162
-- **§268** — A `register __asm__` PIN ON A CALL-CLOBBERED REGISTER IS HONORED EXACTLY WHEN THE PINNED RANGE CROSSES NO CALL (P31 S59c; three A/B'd cards, unifying §257-2's two) L25244
-- **ADD-6** — → §220-addendum — THE FOURTH FACE: WHEN THE NAMED COPY ITSELF BUYS THE EXTRA CALLEE-SAVED, PIN THE COPY TO `$16` L25386
-- **ADD-7** — → §229 addendum — THE VALUE FACE: A LOOP-STORE CONSTANT SPELLED AS A LITERAL HAS NO SOURCE POSITION; NAME IT TO PIN THE PROLOGUE INIT ORDER L25402
-- **ADDENDUM** — to §82 — struct copies must stay MEMBER-WISE, not block-moved, to match a spill-slot save L25702
-- **ADDENDUM** — to §136d-1 (RC-12, the `$0`-add / opaque-copy family) — two symptoms beyond "compare reads the wrong register" L25740
-- **ADDENDUM** — to §164-64 — AN EMPTY CLOBBER ON AN ARGUMENT REGISTER CAN BE THE DELIBERATE FIX, NOT JUST THE ACCIDENTAL BUG L25997
-- **§275** — THE LEFTOVER-REGISTER READ L26371
-- **§NNN** — A DO-WHILE'S GUARD AND LATCH MUST REPEAT THE SAME BOUND EXPRESSION, NOT SHARE ONE LOCAL: THE REPETITION IS WHAT BUYS THE CSE'D COPY INTO A SECOND REGISTER (P31 S60; `func_8017F2A4`, ov_SC03_096, byte-proven 25/25) L26882
-- **ADDENDUM** — to §176-B2 — in a micro-function with no long/short lifetime asymmetry, BOTH contending pseudos need their own hard-register pin L27323
-- **ADDENDUM** — to §220 — REFERENCING THE RAW PARAMETER (NO NAMED COPY, NOT EVEN A PIN) LETS THE CALLEE-SAVED SPILL LAND IN THE FIRST CALL'S OWN DELAY SLOT L27439
-- **ADDENDUM** — to §215 — FIFTH SHAPE: reused mask constants across two call-free merge sites each get their own whole-function hard-register pin, and a shared sub-expression at the second site must be its own statement L27524
-- **ADDENDUM** — to §194-B (func_8017EB34, ov_SC03_117 — wave dk; distinct from the §74 co-pinning finding on the SAME function below) L27932
-- **ADDENDUM** — §NNN — sharpens §162a3/§60b: A `sll $v0,16 / sltiu $v0,1` ZERO-TEST OF A JUST-DECREMENTED HALFWORD IS A SIGNED-TEMP WIDTH TELL OUTSIDE ANY SWITCH/RANGE-TEST CONTEXT L28252
-- **§285** — PRE-INITIALIZING A VARIABLE WITH A SHARED CONSTANT BEFORE A BRANCH MAKES BOTH ARMS OF THE FOLLOWING if/else DESTRUCTIVELY REUSE THE SAME DESTINATION REGISTER FOR THEIR BITWISE RESULT (byte-proven; `func_801811F0`, ov_SC03_102, independently rediscovered across waves di/dj) (P31 S60; waves #, byte-proven) L29037
-- **§287** — A STACK-FRAME HOLE BELOW TWO ADDRESS-TAKEN AGGREGATE LOCALS IS A LEADING PAD MEMBER OF ONE COMBINED STRUCT, NOT SEPARATE LOCALS OR A REGISTER PIN (P31 S60/dj; `func_8017D104`, ov_SC06_027, byte-proven 47/47) (P31 S60; waves #, byte-proven) L29045
-- **§288** — A REGISTER PIN DECLARED UNINITIALIZED AND ASSIGNED ONLY AT ITS LATE, SOLE USE STILL FORCES THE FIXED REGISTER'S SAVE/RESTORE, AND THE ASSIGNMENT'S SOURCE POSITION CONTROLS WHERE THE VALUE MATERIALIZES (P31; `func_80186530`, ov_SC02_017, byte-proven, match_one MATCH re-verified) (P31 S60; waves #, byte-proven) L29049
-- **§290** — A SINGLE STRENGTH-REDUCED GIV CAN DRIVE STORES TO SEVERAL DISTINCT RELOCATABLE SYMBOLS, EACH KEEPING ITS OWN `%hi`/`%lo` ANCHOR (P31 S60; waves #, byte-proven) L29057
-- **ADDENDUM** — to §172b-1 (counter-type dial) — the sll's SOURCE REGISTER is the placement discriminator L29227
-- **ADDENDUM** — to §282 — the ADDRESS-GIV face: write the walked address INLINE so strength reduction births the induction register at loop.c's own insertion point L29272
-- **§310** — A TWO-OPERAND `subu`'s DESTINATION TIES ONLY TO THE OPERAND THAT IS BLOCK-LOCAL: SHARE *ONE* SIDE ACROSS BLOCKS TO CHOOSE WHICH OPERAND'S REGISTER IT LANDS IN (P31 S64 t5j-t5m; byte-proven func_8017F578) L30045
+- **§42** — The F-band ≤28 regalloc crack wave: register-pin/DENSITY levers beat the permuter (Phase 25 T7 F-band, 2026-07-10; Ultracode 9-worker wave, 4/9 banked byte-identical, 266 swept ×134) L2915
+- **§43** — The K&R s16-param definition DISSOLVES the "narrow-param wall" for by-value register args (Phase 25 task A, Fable5 crack of the 369-ins giant `func_80166994` ×134, 2026-07-11) L3210
+- **§45** — The flagship `func_80133CD4` crack (399 ins ×134): the merged-variable permutation-breaker + the 1-death local-alloc gate (Phase 25 task A giant escalation, Fable5 gdb-on-cc1, 2026-07-11) L3313
+- **§47** — The live-length SLIDER: splitting a global.c allocno-priority TIE with one zero-byte asm (Phase 26 session 8, Fable5 Max, byte-proven on `func_8017BEBC` 952 ins ×113) L3380
+- **§48** — The 12-core jr crack wave: the ALLOCNO-PRICING dials and the EBB rule (Phase 26 session 8, Ultracode, 9/12 MATCH first pass) L3420
+- **§3-A.** — ALLOCNO-PRICING DIALS — move a value into the register you want, byte-neutrally L3428
+- **§52** — The WALKER-FAMILY skeleton: 6 regalloc-order levers + a deeply-characterized intrinsic wall (`func_80178004`, 165 ins ×134; Phase 26, Fable5, 2026-07-15) L3928
+- **§52a** — The regalloc sibling wave: new levers + two new wall classes (cheap-Opus applying §52, 2026-07-15) L3974
+- **§52b** — Sibling wave 2: more de-pin levers, a third wall class, and the match_one→whole-binary gap at scale (2026-07-15) L4012
+- **§66d-1** — What transfers between giants is the LOOP, not the PIN L5295
+- **§70** — The giv-init base register: walk the PARAMETER, not a copy of it (Phase 29 SESSION-18, `func_801777BC`) L5634
+- **§71** — Before mapping a giant, look for an already-matched SIBLING beside it (Phase 29 SESSION-18, `func_8017D960`, 3,338 ins) L5675
+- **§72** — A `register __asm__` pin is a PREFERENCE, not a reservation (Phase 29 SESSION-18, `func_8017F510`) L5741
+- **§74** — Auditing a pinned draft: the §72 hazard is CALLER-SAVED pins spanning a call, and only the disassembly can tell you (Phase 29 SESSION-19, `func_8017D960` b2, 5 pins) L5837
+- **§76** — The allocno CLASS (local vs global) is the dominant regalloc lever, and C reaches it ONLY through declaration scope and variable reuse (Phase 29 SESSION-19, behemoth #3 `func_8017F510` 1,511 ins, 97 → MATCH, pin-free) L6043
+- **§78** — A LENGTH drift can be a register grant in disguise; and `fold` never leaves a literal first in an `|` chain (Phase 29 SESSION-19, behemoth #2 `func_8017D960` 3,338 ins, 1806 → 0, pin-free) L6189
+- **§76** — confirmed at scale, and a pin nuance L6266
+- **§80** — A do-not-re-buy entry is scoped to its BASE, not to the function; and the pin's hidden cost is an unconditional `qty_phys_sugg` (Phase 29 SESSION-19, `func_8017BF14` 45 → 0) L6285
+- **§3-The** — pin's hidden cost, with the citation L6306
+- **§83** — The parameterised-repeat law, the spill-area trap, and why a per-case edit cannot move a per-case symptom (Phase 29 SESSION-20, `func_80183814` 5,122 ins, cold-ish start → 36 structural / 99.3%) L6427
+- **§83c** — TRAP: a "dead local" in a prior draft may be gcc's OWN spill area L6460
+- **§86** — Pinned-exemplar templatability is a PER-FAMILY property, not a per-member rate; and the §42e pin guard is now over-conservative (Phase 29 SESSION-20) L6604
+- **§3-Two** — further notes worth keeping L8263
+- **§137** — REGALLOC-PERM is a TWO-COMPILE ARITHMETIC PROBLEM, not a permuter job L9359
+- **§3-The** — same swallow, twice more, in the integration spine L9724
+- **§3-B.** — A `?:` on MEMORY operands costs ~16 bytes of invisible frame; on REGISTER operands, zero L10072
+- **§3-D.** — A lone `$t8`/`$t9` in the target is RELOAD SCRATCH — reproduce the spill, don't pin the register L10088
+- **§3-C.** — A zero-byte ALLOCNO-PRIORITY slider L10199
+- **§150** — A register ROTATION across symmetric blocks is VARIABLE-IDENTITY evidence, not an allocator tie (P30 S43, `func_8017C6F4`, 947 ins ×4) L10327
+- **§152** — BYTE SIZE is the family key that name- and h_seq-grouping both miss (P30 S43, the 0xECC family: 1 crack → 12 overlays → 11,364 ins) L10433
+- **§155** — hi/lo literal scanning MUST track base registers (S45) L10573
+- **§158** — The RANGE-EXTENDER: a fourth zero-emission asm lever completes the allocno toolkit (P30 S46 tier-3, `func_8017CE58`, 733 ins) L10727
+- **Bonus** — facts worth keeping L10772
+- **§156** — THE PREFERENCE-DONOR MERGE: cross-region variable reuse is what fills a0-a3, and a call-arg use in ONE region steers the fill in ALL of them (P30 S46 tier-3, `func_80186E24`, 611 ins: 236-off "S11 regalloc-order" → MATCH, zero new pins) L10787
+- **§175** — A CALLER-SAVED REGISTER PIN CAN BE A CORRECTNESS BUG, NOT JUST A SCHEDULING CHOICE (P31 wave H, 2026-08-15) L16750
+- **§176j** — STOPPING A WAVE MID-FLIGHT COSTS THE IN-FLIGHT TAIL (and how much is recoverable) L17134
+- **§177** — 🔴 THE EPILOGUE RETURN-DELAY SLOT IS DECIDED BY YOUR SAVED-REGISTER SET, NOT BY SCHEDULING L17197
+- **§179-A** — 🔴 A LOOP-WALKED POINTER **PARAMETER** HANDS ITS ARGUMENT REGISTER TO THE GIV (9 byte-proofs) L17351
+- **§179-F** — PINNING A LOOP-WALKED POINTER IS A TOTAL OFF-SWITCH FOR STRENGTH REDUCTION L17547
+- **§179-G** — 🟡 A PIN CAN **CREATE** A COMBINE `LOG_LINK` AND DELETE AN `andi` (sixth RC-5 channel, n=1) L17570
+- **§176** — SEVEN LEVERS FROM THE P31 OVERNIGHT WAVES (2026-08-15): statement order, false regalloc, and the pin that fights back L17648
+- **§176-B** — "REGALLOC-PERM, 1-4 instructions off" ⇒ it is usually NOT register allocation L17678
+- **§176-C** — 🔴 WALL REFUTATION: a hard-register pin CANNOT schedule around a call, because of a genuine gcc-2.7.2 bug L17724
+- **§3-18** — of 20 reconciled while keeping the match. The two that did not are mechanism, not effort. L17977
+- **§186** — CROSS-JUMPING RUNS **AFTER** SCHEDULING, SO NO C-LEVEL BARRIER CAN STEER IT L18107
+- **§186c** — WHERE A VALUE IS LOADED DECIDES WHICH ALLOCATOR OWNS IT, AND THEREFORE ITS REGISTER L18136
+- **§193-B** — A NARROW CAST OF A WIDE PARAMETER COSTS ONE EXTRA INSTRUCTION WHEN ITS STATEMENT SITS AFTER AN INTERVENING `jal` — AND THE DECIDER IS `combine.c:929`'s CROSS-CALL GUARD, NOT REGISTER ALLOCATION L18524
+- **§193-D** — A COMPILER-GENERATED ARGUMENT COPY IS A `optimize_reg_copy_1` TRIGGER: when the pointer's LAST use in a block precedes a call that takes the pointer *as a register*, sched1 hoists the implicit `move $aN,$sN` to the block top and local-alloc re-bases the WHOLE block's memory operands onto `$aN`. The only C dial is a label (the §165-24 goto-join) between the block and the call. L18596
+- **§194-B** — A `addu $rA,$rB,$zero` copy feeding ≥2 `sh` stores is a SECOND, 16-BIT-DECLARED local — the width, not the clamp or the join liveness, is what keeps the copy (and func_80183094's pin + `"memory"` clobber are both provably inert) L19031
+- **§194-C** — A CALLER-SAVED loop counter proves its live range crosses ZERO calls — so it cannot share a pseudo with any value LIVE ACROSS a call (but it may freely share one with values that merely sit between calls) L19069
+- **§194-D** — Declared width of a computed-value local is a sched1 dial (count-neutral) — a replication + attribution correction of §165-17, NOT a new argument-register law L19132
+- **§194-G** — Reading the integer half of a 16.16 stack aggregate: REGISTER-LIVENESS, not the C spelling, decides `sra` vs `lhu` — and the break is count-neutral L19283
+- **§194-H** — §164-29's WAR fence runs again at SCHED2 ON HARD REGISTERS: an in-place `v &= K` before a branch fences the store that reads v, and when TWO independent stores compete for the one delay slot the fence picks the winner at ZERO length drift (a WIDTH/sh!=sw swap, not a nop). Corrects §167-42's reconstruction (pseudo arm → hard-reg arm) and supplies its first re-runnable A/B. L19326
+- **§194-N** — §193-D's C dial is misstated: the lever is a SURVIVING CODE_LABEL (a label with a real incoming edge), not "a label between the block and the call" — a bare label, or a `goto L; L:` pair whose target is the next active insn, is deleted by jump1 (jump.c:663-669 → delete_insn → jump.c:3458-3461, and jump.c:243 for the bare case) long before sched1/local-alloc, and costs exactly zero bytes L19643
+- **§195-B** — A CALL_INSN does not start a basic block in gcc-2.7.2 — so a call-crossing temp can be a LOCAL-alloc quantity (the missing precondition under §48-A2 / §52 / regalloc.md K8) L19809
+- **§195-F** — fold-const.c:4825 canonicalises a `?:` whose THEN arm is zero (or constant against a non-constant ELSE) by inverting the condition and swapping the arms — so a ternary's written arm order is byte-inert there, and `c ? 0 : X` is unspellable: it always compiles as `!c ? X : 0` L20025
+- **§197-C** — Fix A1 (operand order) cannot move a commutative destination whose .greg conflict set already contains BOTH operand hard registers — split the accumulate so the destination IS the load's pseudo L20662
+- **§199-A** — §189-A's asm→source inference is byte-FALSE: an interloper between a split constant's `lui`/`ori` is a SCHEDULE fact, not a source fact — and the separator is the BIRTHING BOOST, not a "priority floor" (§189-A's split-timing half survives; its "no statement order / no pin" absolute and the candidate's own forward-scheduler narrative both fall) L20733
+- **§199-B** — A permutation sweep that holds ANY statement fixed is not a sweep: the statement an agent pins as "obviously load-bearing" is the one carrying the signal, and the partial sweep returns a FLAT residual that reads as proof of order-invariance L20782
+- **§199-E** — §189-A BOUNDED AND CORRECTED — the discriminator is INSN_PRIORITY, not "is the interloper a constant": an insn between a `lui`/`ori` pair proves NOTHING about the source spelling unless it TIES the `ori` on priority, and on the pinned `-mcpu=3000` triple a dependent load never does L20935
+- **§205** — THE CHAINED ASSIGNMENT IS ITS OWN SCHEDULING DIAL: `*b = *a = v;` moves an argument copy that no local, no pin and no statement reorder will move (P31 S56) L22072
+- **§208** — TWO NAMED LOCALS FOR ONE RELOADED EXPRESSION BUY TWO ALLOCNOS — the naming granularity owns the REGISTER SPLIT, not just the load count (P31 S58) L22217
+- **§211** — HOIST THE LOOP INIT ABOVE THE DOMINATING GUARD: it fills the guard's delay slot AND flips the counter/pointer register pair (P31 S58) L22389
+- **§215** — PIN ECONOMY: the twin's pins are NOT part of the shape, and §17's "pin every call-crossing value" is over-broad (P31 S58) L22575
+- **§220** — THE PARAMETER ITSELF IS A REGALLOC DIAL: use it directly, prefer `s32` to `void*`, and place the save-copy AFTER the first call (P31 S58) L22753
+- **§221** — A CONSTANT SHARED BY TWO STORES DIES AT THE CALL WHOSE DELAY SLOT REFILLS ITS REGISTER **(single observation — not yet cross-confirmed)** (P31 S58) L22793
+- **§30** — addendum (P31 S58) — the `/s` grant closes a SCHEDULING residual and a REGISTER residual with one edit L23231
+- **§244** — `volatile` IS A COUNTING INSTRUMENT, A STORE-ORDER PIN, AND MUST SOMETIMES BE ASYMMETRIC (P31 S58b) L23725
+- **§248** — SPLIT THE LOAD FROM THE ARITHMETIC: A FUSED `g + K` DENIES THE CALLEE-SAVED REGISTER ITS DIRECT HOME (P31 S58b) L23881
+- **§253** — POSTFIX `++` vs `+= 1` PICKS A DIFFERENT SCRATCH REGISTER **(single observation — not yet cross-confirmed)** (P31 S58b) L24027
+- **§254** — THE DEAD PARAMETER IS A REGISTER-PLACEMENT TOOL **(single observation — not yet cross-confirmed)** (P31 S58b) L24041
+- **§215** — addendum (P31 S58b) — PIN ECONOMY, PART 2: NINE REFINEMENTS L24398
+- **§223** — addendum (P31 S58b) — FIVE MORE CONFIRMATIONS, AND THE CONSTANT-IN-`$v0` CASE L24510
+- **§263** — A STOLEN DELAY SLOT WHOSE INSTRUCTION IS AN ARG-REGISTER COPY IS AN ARITY ERROR, NOT A SCHEDULE (P31 S59, byte-proven) L24901
+- **ADD-8** — → §245 addendum — THE RE-TIE BARRIER PINS CALL-ARG SETUP TO SOURCE ORDER (construct 6) L25177
+- **§268** — A `register __asm__` PIN ON A CALL-CLOBBERED REGISTER IS HONORED EXACTLY WHEN THE PINNED RANGE CROSSES NO CALL (P31 S59c; three A/B'd cards, unifying §257-2's two) L25259
+- **ADD-6** — → §220-addendum — THE FOURTH FACE: WHEN THE NAMED COPY ITSELF BUYS THE EXTRA CALLEE-SAVED, PIN THE COPY TO `$16` L25401
+- **ADD-7** — → §229 addendum — THE VALUE FACE: A LOOP-STORE CONSTANT SPELLED AS A LITERAL HAS NO SOURCE POSITION; NAME IT TO PIN THE PROLOGUE INIT ORDER L25417
+- **ADDENDUM** — to §82 — struct copies must stay MEMBER-WISE, not block-moved, to match a spill-slot save L25717
+- **ADDENDUM** — to §136d-1 (RC-12, the `$0`-add / opaque-copy family) — two symptoms beyond "compare reads the wrong register" L25755
+- **ADDENDUM** — to §164-64 — AN EMPTY CLOBBER ON AN ARGUMENT REGISTER CAN BE THE DELIBERATE FIX, NOT JUST THE ACCIDENTAL BUG L26012
+- **§275** — THE LEFTOVER-REGISTER READ L26386
+- **§NNN** — A DO-WHILE'S GUARD AND LATCH MUST REPEAT THE SAME BOUND EXPRESSION, NOT SHARE ONE LOCAL: THE REPETITION IS WHAT BUYS THE CSE'D COPY INTO A SECOND REGISTER (P31 S60; `func_8017F2A4`, ov_SC03_096, byte-proven 25/25) L26897
+- **ADDENDUM** — to §176-B2 — in a micro-function with no long/short lifetime asymmetry, BOTH contending pseudos need their own hard-register pin L27338
+- **ADDENDUM** — to §220 — REFERENCING THE RAW PARAMETER (NO NAMED COPY, NOT EVEN A PIN) LETS THE CALLEE-SAVED SPILL LAND IN THE FIRST CALL'S OWN DELAY SLOT L27454
+- **ADDENDUM** — to §215 — FIFTH SHAPE: reused mask constants across two call-free merge sites each get their own whole-function hard-register pin, and a shared sub-expression at the second site must be its own statement L27539
+- **ADDENDUM** — to §194-B (func_8017EB34, ov_SC03_117 — wave dk; distinct from the §74 co-pinning finding on the SAME function below) L27947
+- **ADDENDUM** — §NNN — sharpens §162a3/§60b: A `sll $v0,16 / sltiu $v0,1` ZERO-TEST OF A JUST-DECREMENTED HALFWORD IS A SIGNED-TEMP WIDTH TELL OUTSIDE ANY SWITCH/RANGE-TEST CONTEXT L28267
+- **§285** — PRE-INITIALIZING A VARIABLE WITH A SHARED CONSTANT BEFORE A BRANCH MAKES BOTH ARMS OF THE FOLLOWING if/else DESTRUCTIVELY REUSE THE SAME DESTINATION REGISTER FOR THEIR BITWISE RESULT (byte-proven; `func_801811F0`, ov_SC03_102, independently rediscovered across waves di/dj) (P31 S60; waves #, byte-proven) L29052
+- **§287** — A STACK-FRAME HOLE BELOW TWO ADDRESS-TAKEN AGGREGATE LOCALS IS A LEADING PAD MEMBER OF ONE COMBINED STRUCT, NOT SEPARATE LOCALS OR A REGISTER PIN (P31 S60/dj; `func_8017D104`, ov_SC06_027, byte-proven 47/47) (P31 S60; waves #, byte-proven) L29060
+- **§288** — A REGISTER PIN DECLARED UNINITIALIZED AND ASSIGNED ONLY AT ITS LATE, SOLE USE STILL FORCES THE FIXED REGISTER'S SAVE/RESTORE, AND THE ASSIGNMENT'S SOURCE POSITION CONTROLS WHERE THE VALUE MATERIALIZES (P31; `func_80186530`, ov_SC02_017, byte-proven, match_one MATCH re-verified) (P31 S60; waves #, byte-proven) L29064
+- **§290** — A SINGLE STRENGTH-REDUCED GIV CAN DRIVE STORES TO SEVERAL DISTINCT RELOCATABLE SYMBOLS, EACH KEEPING ITS OWN `%hi`/`%lo` ANCHOR (P31 S60; waves #, byte-proven) L29072
+- **ADDENDUM** — to §172b-1 (counter-type dial) — the sll's SOURCE REGISTER is the placement discriminator L29242
+- **ADDENDUM** — to §282 — the ADDRESS-GIV face: write the walked address INLINE so strength reduction births the induction register at loop.c's own insertion point L29287
+- **§310** — A TWO-OPERAND `subu`'s DESTINATION TIES ONLY TO THE OPERAND THAT IS BLOCK-LOCAL: SHARE *ONE* SIDE ACROSS BLOCKS TO CHOOSE WHICH OPERAND'S REGISTER IT LANDS IN (P31 S64 t5j-t5m; byte-proven func_8017F578) L30060
+- **§312** — A BARE RELATIONAL IN AN `if` GIVES THE `slt` NO TARGET: ASSIGN THE COMPARISON INTO THE ALREADY-ALLOCATED VARIABLE TO CHOOSE ITS DESTINATION REGISTER, AT ZERO INSTRUCTION COST (P31 S64 t5o-t5r; byte-proven func_80180DCC) L30133
### CSE / redundancy / rematerialization (28)
-- **§46** — The `func_80178D40` crack (890 ins ×134, the heaviest core in the game): four LOOP-STRUCTURE levers cheap-Opus found by reading loop.c/jump.c/cse.c (Phase 26 session 8, 2026-07-13) L3313
-- **§83d** — CSE's quantity budget is WHOLE-FUNCTION, so a local rewrite cannot fix a local symptom L6452
-- **§153** — THE ADDRESS-REMATERIALISATION LAUNDER: a third zero-emission asm lever (P30 S43, `func_8018D98C`, 710 ins) L10466
-- **§176-D** — CSE-class levers used in reverse (two sharpenings of §153 and cse_expr §2) L17735
-- **§193-E** — A varying-address (pointer) load is re-emitted once per CSE-LIVE INTERVAL, and naming it in a C local is the only C-level lever over that count — no store SPELLING has any reach L18652
-- **§193-F** — §148-A2 — The `threshold -= 3` STAIRCASE: `move_movables` admits a COUNT of invariants, not a boolean — two identical merged constants split hoisted/not-hoisted by LIST ORDER, and `insn_count` picks the rank cutoff L18682
-- **§193-H** — A pointer-derived base load `*(s32*)(p+K)` is uncacheable across ANY memory write or call (cse's third kill disjunct) — so the target emits one `lw` per store-separated RUN of spellings, and a run of stores sharing one `lw` is a C local you must declare L18807
-- **§194-A** — A zero-byte scheduling fence goes AFTER the defining statement to make that computation emit FIRST in its block — and the barrier predicate is `volatile`-or-colon-less, not the `"memory"` clobber (COMPLEMENTS §165-40; does not refute it) L18950
-- **§194-J** — Back-to-back identical stores: flow.c's `last_mem_set` deletes the first, and only `volatile` saves it L19392
-- **§194-K** — Blind sched1's alias oracle with a second SET of a pointer pseudo — the first zero-byte, non-volatile, dependence-CREATING lever (corrects §167-05's "volatile is the only door"; fourth consumer of reg_n_sets) L19444
-- **§195-H** — §165-27g — ON A FIXED-SYMBOL GLOBAL, `extern T D[];` + `D[0]` IS THE CSE RELOAD DIAL, AT ZERO ADDRESSING COST, AND THE ELEMENT COUNT IS INERT (§165-27's `T v[2]` CAVEAT IS A LOCAL-FRAME FACT AND DOES NOT TRANSFER) L20110
-- **§195-I** — §145(b) AMENDED — the pointer-bump `addiu` is saved by cse, not combine: ANY second SET of a pseudo in the address's equivalence chain (in-place `p += K`, §145(b)'s `p = r;` copy, or an asm re-tie) kills the fold; the pass is cse and the gate is `invalidate`'s `reg_tick++` L20157
-- **§195-L** — The cse store-re-seed does not cross a JOIN LABEL: per-arm stores + a join read keep the reload that one join store deletes (bounds §193-E BOUND 1/BOUND 3 with §48-B's EBB boundary) L20318
-- **§197-A** — A NARROW SIGNED MEMORY READ FEEDING A CONSTANT `>>` LOSES ITS `lh`, AND THE CURE IS AN ASM RE-TIE (attribution CONTESTED: cse vs combine) L20581
-- **§197-B** — A REPEATED COMPARE OF ONE VALUE AGAINST ONE CONSTANT IS DELETED BY cse's `qty_comparison_code` CHANNEL (the non-EQ complement of §165-03) — and a front-end-opaque mask on EITHER compare is a pure-C dial that keeps the target's second branch L20619
-- **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` L20860
-- **§201-E** — §194-J-2 — The `last_mem_set` deletion window is measured in SOURCE/expand order, not in the printed stream; a foreign store moved between the pair in C source is a real lever, and `volatile` is not always the better one L21368
-- **§204-D** — A LOOP-INVARIANT LOAD IS ADMITTED AS A MOVABLE ONLY IF ITS ADDRESS CANNOT TRAP: `local.field` PASSES, THE SAME READ THROUGH A POINTER LOCAL IS REFUSED L21763
-- **§243** — SPELL THE CSE BARRIER AS A REASSIGNED POINTER; AND THE `nop`-AFTER-EVERY-`lh` SIGNATURE (P31 S58b) L23680
-- **§244** — `volatile` IS A COUNTING INSTRUMENT, A STORE-ORDER PIN, AND MUST SOMETIMES BE ASYMMETRIC (P31 S58b) L23710
-- **ADD-1** — → §257-8 addendum — THE INTERPOSED ASM'S `__volatile__` IS A PER-SHAPE DIAL, AND THE "NO-OUTPUT ASM IS IMPLICITLY VOLATILE" LORE IS BYTE-FALSE IN gcc-2.7.2 L25313
-- **ADDENDUM** — to §244 — THE COMPILER BARRIER, NOT `volatile`, BLOCKS A STORE→LOAD HOIST THROUGH A POINTER-OFFSET FIELD L26028
-- **ADDENDUM** — to §211 — AN IN-LOOP ACCUMULATOR WANTS A CLOSED-FORM EXPRESSION WHEN THE TARGET REMATERIALISES ITS CONSTANT AFTER EVERY CALL L26336
-- **§276** — MIXED ADDRESS-EXPRESSION SPELLING FOR ADJACENT RELOCATABLE SYMBOLS IS A CSE-UNIFICATION DIAL, NOT JUST A BYTE-ENCODING CHOICE (P31 S60; `func_80180FE8`, ov_SC06_006, byte-proven) L26411
-- **§NNN** — A DO-WHILE'S GUARD AND LATCH MUST REPEAT THE SAME BOUND EXPRESSION, NOT SHARE ONE LOCAL: THE REPETITION IS WHAT BUYS THE CSE'D COPY INTO A SECOND REGISTER (P31 S60; `func_8017F2A4`, ov_SC03_096, byte-proven 25/25) L26882
-- **ADDENDUM** — to §22 (`volatile`-qualified-global reload lever, cookbook ~L1922) — for a NON-constant, same-address double RMW, a plain memory clobber beats `volatile`, and `volatile` actively breaks a delay-slot fill L27185
-- **§302** — A RED BINARY IS A DRIFTED SPEC, NOT A MYSTERY: THE THREE CARVE-STATE INVARIANTS AND HOW TO DERIVE EACH FROM THE BYTES (P31 S62 T2; five reds healed in one session, 5/5, +39 held banks) L29678
-- **§308** — A NAIVE FINAL `goto` DELETES THE TARGET'S `j`+`nop`: SPELL THAT EDGE AS A TAUTOLOGICAL `if` SO cse FOLDS IT TO AN UNCONDITIONAL JUMP *AFTER* jump1's WINDOW HAS CLOSED (P31 S63 t5e-t5i; byte-proven func_80180808) L29942
+- **§46** — The `func_80178D40` crack (890 ins ×134, the heaviest core in the game): four LOOP-STRUCTURE levers cheap-Opus found by reading loop.c/jump.c/cse.c (Phase 26 session 8, 2026-07-13) L3328
+- **§83d** — CSE's quantity budget is WHOLE-FUNCTION, so a local rewrite cannot fix a local symptom L6467
+- **§153** — THE ADDRESS-REMATERIALISATION LAUNDER: a third zero-emission asm lever (P30 S43, `func_8018D98C`, 710 ins) L10481
+- **§176-D** — CSE-class levers used in reverse (two sharpenings of §153 and cse_expr §2) L17750
+- **§193-E** — A varying-address (pointer) load is re-emitted once per CSE-LIVE INTERVAL, and naming it in a C local is the only C-level lever over that count — no store SPELLING has any reach L18667
+- **§193-F** — §148-A2 — The `threshold -= 3` STAIRCASE: `move_movables` admits a COUNT of invariants, not a boolean — two identical merged constants split hoisted/not-hoisted by LIST ORDER, and `insn_count` picks the rank cutoff L18697
+- **§193-H** — A pointer-derived base load `*(s32*)(p+K)` is uncacheable across ANY memory write or call (cse's third kill disjunct) — so the target emits one `lw` per store-separated RUN of spellings, and a run of stores sharing one `lw` is a C local you must declare L18822
+- **§194-A** — A zero-byte scheduling fence goes AFTER the defining statement to make that computation emit FIRST in its block — and the barrier predicate is `volatile`-or-colon-less, not the `"memory"` clobber (COMPLEMENTS §165-40; does not refute it) L18965
+- **§194-J** — Back-to-back identical stores: flow.c's `last_mem_set` deletes the first, and only `volatile` saves it L19407
+- **§194-K** — Blind sched1's alias oracle with a second SET of a pointer pseudo — the first zero-byte, non-volatile, dependence-CREATING lever (corrects §167-05's "volatile is the only door"; fourth consumer of reg_n_sets) L19459
+- **§195-H** — §165-27g — ON A FIXED-SYMBOL GLOBAL, `extern T D[];` + `D[0]` IS THE CSE RELOAD DIAL, AT ZERO ADDRESSING COST, AND THE ELEMENT COUNT IS INERT (§165-27's `T v[2]` CAVEAT IS A LOCAL-FRAME FACT AND DOES NOT TRANSFER) L20125
+- **§195-I** — §145(b) AMENDED — the pointer-bump `addiu` is saved by cse, not combine: ANY second SET of a pseudo in the address's equivalence chain (in-place `p += K`, §145(b)'s `p = r;` copy, or an asm re-tie) kills the fold; the pass is cse and the gate is `invalidate`'s `reg_tick++` L20172
+- **§195-L** — The cse store-re-seed does not cross a JOIN LABEL: per-arm stores + a join read keep the reload that one join store deletes (bounds §193-E BOUND 1/BOUND 3 with §48-B's EBB boundary) L20333
+- **§197-A** — A NARROW SIGNED MEMORY READ FEEDING A CONSTANT `>>` LOSES ITS `lh`, AND THE CURE IS AN ASM RE-TIE (attribution CONTESTED: cse vs combine) L20596
+- **§197-B** — A REPEATED COMPARE OF ONE VALUE AGAINST ONE CONSTANT IS DELETED BY cse's `qty_comparison_code` CHANNEL (the non-EQ complement of §165-03) — and a front-end-opaque mask on EITHER compare is a pure-C dial that keeps the target's second branch L20634
+- **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` L20875
+- **§201-E** — §194-J-2 — The `last_mem_set` deletion window is measured in SOURCE/expand order, not in the printed stream; a foreign store moved between the pair in C source is a real lever, and `volatile` is not always the better one L21383
+- **§204-D** — A LOOP-INVARIANT LOAD IS ADMITTED AS A MOVABLE ONLY IF ITS ADDRESS CANNOT TRAP: `local.field` PASSES, THE SAME READ THROUGH A POINTER LOCAL IS REFUSED L21778
+- **§243** — SPELL THE CSE BARRIER AS A REASSIGNED POINTER; AND THE `nop`-AFTER-EVERY-`lh` SIGNATURE (P31 S58b) L23695
+- **§244** — `volatile` IS A COUNTING INSTRUMENT, A STORE-ORDER PIN, AND MUST SOMETIMES BE ASYMMETRIC (P31 S58b) L23725
+- **ADD-1** — → §257-8 addendum — THE INTERPOSED ASM'S `__volatile__` IS A PER-SHAPE DIAL, AND THE "NO-OUTPUT ASM IS IMPLICITLY VOLATILE" LORE IS BYTE-FALSE IN gcc-2.7.2 L25328
+- **ADDENDUM** — to §244 — THE COMPILER BARRIER, NOT `volatile`, BLOCKS A STORE→LOAD HOIST THROUGH A POINTER-OFFSET FIELD L26043
+- **ADDENDUM** — to §211 — AN IN-LOOP ACCUMULATOR WANTS A CLOSED-FORM EXPRESSION WHEN THE TARGET REMATERIALISES ITS CONSTANT AFTER EVERY CALL L26351
+- **§276** — MIXED ADDRESS-EXPRESSION SPELLING FOR ADJACENT RELOCATABLE SYMBOLS IS A CSE-UNIFICATION DIAL, NOT JUST A BYTE-ENCODING CHOICE (P31 S60; `func_80180FE8`, ov_SC06_006, byte-proven) L26426
+- **§NNN** — A DO-WHILE'S GUARD AND LATCH MUST REPEAT THE SAME BOUND EXPRESSION, NOT SHARE ONE LOCAL: THE REPETITION IS WHAT BUYS THE CSE'D COPY INTO A SECOND REGISTER (P31 S60; `func_8017F2A4`, ov_SC03_096, byte-proven 25/25) L26897
+- **ADDENDUM** — to §22 (`volatile`-qualified-global reload lever, cookbook ~L1922) — for a NON-constant, same-address double RMW, a plain memory clobber beats `volatile`, and `volatile` actively breaks a delay-slot fill L27200
+- **§302** — A RED BINARY IS A DRIFTED SPEC, NOT A MYSTERY: THE THREE CARVE-STATE INVARIANTS AND HOW TO DERIVE EACH FROM THE BYTES (P31 S62 T2; five reds healed in one session, 5/5, +39 held banks) L29693
+- **§308** — A NAIVE FINAL `goto` DELETES THE TARGET'S `j`+`nop`: SPELL THAT EDGE AS A TAUTOLOGICAL `if` SO cse FOLDS IT TO AN UNCONDITIONAL JUMP *AFTER* jump1's WINDOW HAS CLOSED (P31 S63 t5e-t5i; byte-proven func_80180808) L29957
-### loops & induction variables (31)
+### loops & induction variables (32)
- **§3-T1** — Loop pointer: top-of-body for `addu` induction, not constant-folded `addiu` L71
- **§34** — The `func_80138ED0` giant crack: gcc-2.7.2's **3-qty sort bug** + the **zero-byte asm allocation toolkit** + the **giv-init fence** (Phase 24 T5; Opus→close=21, Fable5→MATCH ×134) L2454
- **§35** — The region-a sibling-giant harvest: difficulty ≠ $s-reg count (it's global-array hoisting) + the banking recipe + new loop idioms (Phase 24 T7, 5 parallel Opus-Max agents) L2471
-- **§46** — The `func_80178D40` crack (890 ins ×134, the heaviest core in the game): four LOOP-STRUCTURE levers cheap-Opus found by reading loop.c/jump.c/cse.c (Phase 26 session 8, 2026-07-13) L3313
-- **§66d** — The permuter⇄reader loop: alternate a random search with a byte-verified idiom, and let `residual_class` decide whose turn it is (Phase 29 SESSION-17) L5245
-- **§66d-1** — What transfers between giants is the LOOP, not the PIN L5280
-- **§70** — The giv-init base register: walk the PARAMETER, not a copy of it (Phase 29 SESSION-18, `func_801777BC`) L5619
-- **§145** — Three loop/combine levers from the S40 wave-2 drafters (16/16 match_one) L9927
-- **§148** — The loop.c hoisting THRESHOLD is arithmetic you can compute, and the `?:` clamp that folds to MIN_EXPR (P30 S42, `func_8017C6F4`, 947 ins) L10145
-- **§171a** — THE MECHANICAL A-PROP DRAFT (P30 S50): 256 members banked with no agent in the loop L16433
-- **§179-A** — 🔴 A LOOP-WALKED POINTER **PARAMETER** HANDS ITS ARGUMENT REGISTER TO THE GIV (9 byte-proofs) L17336
-- **§179-E** — A `>2*MAX_MOVE_BYTES` BLOCK COPY IS A **STRUCT ASSIGNMENT**, NOT A HAND LOOP L17506
-- **§179-F** — PINNING A LOOP-WALKED POINTER IS A TOTAL OFF-SWITCH FOR STRENGTH REDUCTION L17532
-- **§194-C** — A CALLER-SAVED loop counter proves its live range crosses ZERO calls — so it cannot share a pseudo with any value LIVE ACROSS a call (but it may freely share one with values that merely sit between calls) L19054
-- **§204-B** — A LOOP COUNT THAT ARRIVES ON THE STACK IS DECREMENTED IN PLACE: a fresh counter local can cost a real `move` AND permute the whole callee-saved file L21641
-- **§204-D** — A LOOP-INVARIANT LOAD IS ADMITTED AS A MOVABLE ONLY IF ITS ADDRESS CANNOT TRAP: `local.field` PASSES, THE SAME READ THROUGH A POINTER LOCAL IS REFUSED L21763
-- **§211** — HOIST THE LOOP INIT ABOVE THE DOMINATING GUARD: it fills the guard's delay slot AND flips the counter/pointer register pair (P31 S58) L22374
-- **§246** — THREE-LIVE-VALUE SCAN LOOPS WANT ADDRESS-FROM-INDEX; AND TWO SYMBOLS CAN SHARE ONE giv (P31 S58b) L23792
-- **ADD-7** — → §229 addendum — THE VALUE FACE: A LOOP-STORE CONSTANT SPELLED AS A LITERAL HAS NO SOURCE POSITION; NAME IT TO PIN THE PROLOGUE INIT ORDER L25402
-- **ADD-8** — → §30a addendum — THE THIRD COLUMN: `*p++` IS ALSO SERIALIZED BUT BURNS `addiu`; ONLY CAST-PLUS GIVES SERIALIZATION *AND* DISPLACEMENT FOLDING L25415
-- **ADDENDUM** — to §172b-1 — TWO PLACEMENT DIALS THE PROMOTION LAW DOESN'T NAME: NARROW THE COUNTER'S DECLARED TYPE, AND MOVE THE CAST INTO THE LOOP BODY L26059
-- **ADDENDUM** — to §211 — AN IN-LOOP ACCUMULATOR WANTS A CLOSED-FORM EXPRESSION WHEN THE TARGET REMATERIALISES ITS CONSTANT AFTER EVERY CALL L26336
-- **§279** — A `do/while (p < end)` LOOP UNDER AN ENTRY GUARD: the guard decides the compare, not the loop (P31 S60; wave cf, func_8017F2A4, ov_SC03_096, byte-proven) L26881
-- **§NNN** — A DO-WHILE'S GUARD AND LATCH MUST REPEAT THE SAME BOUND EXPRESSION, NOT SHARE ONE LOCAL: THE REPETITION IS WHAT BUYS THE CSE'D COPY INTO A SECOND REGISTER (P31 S60; `func_8017F2A4`, ov_SC03_096, byte-proven 25/25) L26882
-- **§NNN** — A LOOP CURSOR'S C TYPE (POINTER vs PLAIN INTEGER) SELECTS `sltu` vs `slt` FOR ITS BOUND TEST, INDEPENDENT OF THE VALUES INVOLVED (P31 S60; `func_800CAE74`, md_MAIN_031, byte-proven; cross-confirmed same wave by `func_8017F2A4`, ov_SC03_096) L26916
-- **§282** — gcc's OWN LOOP REVERSAL PUTS THE COUNTER INIT AFTER THE HOISTED MOVABLES — a position no hand-written down-count can reach (P31 S60; wave cf, func_80180DD8, ov_SC04_005, byte-proven) L26995
-- **§NNN** — WRITE THE UP-COUNT LOOP: gcc's OWN REVERSAL PRODUCES A COUNTER-INIT INSTRUCTION THAT LANDS AFTER HOISTED MOVABLES, WHICH A HAND-WRITTEN DOWN-COUNT LOOP CANNOT REPRODUCE (P31 S60; `func_80180DD8`, ov_SC04_005, byte-proven) L26996
-- **§290** — A SINGLE STRENGTH-REDUCED GIV CAN DRIVE STORES TO SEVERAL DISTINCT RELOCATABLE SYMBOLS, EACH KEEPING ITS OWN `%hi`/`%lo` ANCHOR (P31 S60; waves #, byte-proven) L29057
-- **ADDENDUM** — to §282 — the ADDRESS-GIV face: write the walked address INLINE so strength reduction births the induction register at loop.c's own insertion point L29272
-- **ADDENDUM** — to the L1800 anchor-steer bullet — a DERIVED-POINTER local silently flips the merged giv's anchor END L29316
-- **§297** — ONE GIV SERVING MIXED-WIDTH LOADS *AND* A STORE NEEDS STRUCT-MEMBER SPELLING; CAST/INDEX SPELLINGS RE-SPLIT THE PSEUDO (P31 S61; wave m0a, `func_800347C8`, main, byte-proven 31/31) L29458
+- **§46** — The `func_80178D40` crack (890 ins ×134, the heaviest core in the game): four LOOP-STRUCTURE levers cheap-Opus found by reading loop.c/jump.c/cse.c (Phase 26 session 8, 2026-07-13) L3328
+- **§66d** — The permuter⇄reader loop: alternate a random search with a byte-verified idiom, and let `residual_class` decide whose turn it is (Phase 29 SESSION-17) L5260
+- **§66d-1** — What transfers between giants is the LOOP, not the PIN L5295
+- **§70** — The giv-init base register: walk the PARAMETER, not a copy of it (Phase 29 SESSION-18, `func_801777BC`) L5634
+- **§145** — Three loop/combine levers from the S40 wave-2 drafters (16/16 match_one) L9942
+- **§148** — The loop.c hoisting THRESHOLD is arithmetic you can compute, and the `?:` clamp that folds to MIN_EXPR (P30 S42, `func_8017C6F4`, 947 ins) L10160
+- **§171a** — THE MECHANICAL A-PROP DRAFT (P30 S50): 256 members banked with no agent in the loop L16448
+- **§179-A** — 🔴 A LOOP-WALKED POINTER **PARAMETER** HANDS ITS ARGUMENT REGISTER TO THE GIV (9 byte-proofs) L17351
+- **§179-E** — A `>2*MAX_MOVE_BYTES` BLOCK COPY IS A **STRUCT ASSIGNMENT**, NOT A HAND LOOP L17521
+- **§179-F** — PINNING A LOOP-WALKED POINTER IS A TOTAL OFF-SWITCH FOR STRENGTH REDUCTION L17547
+- **§194-C** — A CALLER-SAVED loop counter proves its live range crosses ZERO calls — so it cannot share a pseudo with any value LIVE ACROSS a call (but it may freely share one with values that merely sit between calls) L19069
+- **§204-B** — A LOOP COUNT THAT ARRIVES ON THE STACK IS DECREMENTED IN PLACE: a fresh counter local can cost a real `move` AND permute the whole callee-saved file L21656
+- **§204-D** — A LOOP-INVARIANT LOAD IS ADMITTED AS A MOVABLE ONLY IF ITS ADDRESS CANNOT TRAP: `local.field` PASSES, THE SAME READ THROUGH A POINTER LOCAL IS REFUSED L21778
+- **§211** — HOIST THE LOOP INIT ABOVE THE DOMINATING GUARD: it fills the guard's delay slot AND flips the counter/pointer register pair (P31 S58) L22389
+- **§246** — THREE-LIVE-VALUE SCAN LOOPS WANT ADDRESS-FROM-INDEX; AND TWO SYMBOLS CAN SHARE ONE giv (P31 S58b) L23807
+- **ADD-7** — → §229 addendum — THE VALUE FACE: A LOOP-STORE CONSTANT SPELLED AS A LITERAL HAS NO SOURCE POSITION; NAME IT TO PIN THE PROLOGUE INIT ORDER L25417
+- **ADD-8** — → §30a addendum — THE THIRD COLUMN: `*p++` IS ALSO SERIALIZED BUT BURNS `addiu`; ONLY CAST-PLUS GIVES SERIALIZATION *AND* DISPLACEMENT FOLDING L25430
+- **ADDENDUM** — to §172b-1 — TWO PLACEMENT DIALS THE PROMOTION LAW DOESN'T NAME: NARROW THE COUNTER'S DECLARED TYPE, AND MOVE THE CAST INTO THE LOOP BODY L26074
+- **ADDENDUM** — to §211 — AN IN-LOOP ACCUMULATOR WANTS A CLOSED-FORM EXPRESSION WHEN THE TARGET REMATERIALISES ITS CONSTANT AFTER EVERY CALL L26351
+- **§279** — A `do/while (p < end)` LOOP UNDER AN ENTRY GUARD: the guard decides the compare, not the loop (P31 S60; wave cf, func_8017F2A4, ov_SC03_096, byte-proven) L26896
+- **§NNN** — A DO-WHILE'S GUARD AND LATCH MUST REPEAT THE SAME BOUND EXPRESSION, NOT SHARE ONE LOCAL: THE REPETITION IS WHAT BUYS THE CSE'D COPY INTO A SECOND REGISTER (P31 S60; `func_8017F2A4`, ov_SC03_096, byte-proven 25/25) L26897
+- **§NNN** — A LOOP CURSOR'S C TYPE (POINTER vs PLAIN INTEGER) SELECTS `sltu` vs `slt` FOR ITS BOUND TEST, INDEPENDENT OF THE VALUES INVOLVED (P31 S60; `func_800CAE74`, md_MAIN_031, byte-proven; cross-confirmed same wave by `func_8017F2A4`, ov_SC03_096) L26931
+- **§282** — gcc's OWN LOOP REVERSAL PUTS THE COUNTER INIT AFTER THE HOISTED MOVABLES — a position no hand-written down-count can reach (P31 S60; wave cf, func_80180DD8, ov_SC04_005, byte-proven) L27010
+- **§NNN** — WRITE THE UP-COUNT LOOP: gcc's OWN REVERSAL PRODUCES A COUNTER-INIT INSTRUCTION THAT LANDS AFTER HOISTED MOVABLES, WHICH A HAND-WRITTEN DOWN-COUNT LOOP CANNOT REPRODUCE (P31 S60; `func_80180DD8`, ov_SC04_005, byte-proven) L27011
+- **§290** — A SINGLE STRENGTH-REDUCED GIV CAN DRIVE STORES TO SEVERAL DISTINCT RELOCATABLE SYMBOLS, EACH KEEPING ITS OWN `%hi`/`%lo` ANCHOR (P31 S60; waves #, byte-proven) L29072
+- **ADDENDUM** — to §282 — the ADDRESS-GIV face: write the walked address INLINE so strength reduction births the induction register at loop.c's own insertion point L29287
+- **ADDENDUM** — to the L1800 anchor-steer bullet — a DERIVED-POINTER local silently flips the merged giv's anchor END L29331
+- **§297** — ONE GIV SERVING MIXED-WIDTH LOADS *AND* A STORE NEEDS STRUCT-MEMBER SPELLING; CAST/INDEX SPELLINGS RE-SPLIT THE PSEUDO (P31 S61; wave m0a, `func_800347C8`, main, byte-proven 31/31) L29473
+- **§312** — A BARE RELATIONAL IN AN `if` GIVES THE `slt` NO TARGET: ASSIGN THE COMPARISON INTO THE ALREADY-ALLOCATED VARIABLE TO CHOOSE ITS DESTINATION REGISTER, AT ZERO INSTRUCTION COST (P31 S64 t5o-t5r; byte-proven func_80180DCC) L30133
-### structs, block moves & memcpy (70)
+### structs, block moves & memcpy (71)
- **§3-T2** — Source statement order drives instruction scheduling L78
- **§5** — Known hard-residual classes (instruction-identical, one byte-exact blocker) L199
@@ -337,63 +339,64 @@
- **§38** — The WHALE `func_80144B9C` (770 ins): the -O0 struct-assign memcpy idiom + the -O0 reach-134 ×134 rollout (Phase 24 T7 §G, cheap Opus — no Fable5, no calls.c) L2527
- **§40** — Structural families: the MECHANICAL symbol-remap (crack one exemplar → remap the rest, ~0 tokens) (Phase 25 T3/T7, 2026-07-08) L2553
- **§41** — The DEF-SIDE canonical-sig wall: mechanically banking a drafted giant past `conflicting types` (Phase 25 T5b batch-2, 2026-07-09; `tools/canon_sig_reconcile.py`, byte-proven on `func_8013B274`) L2710
-- **§42a** — addendum — wave 2 (residuals + 29-100 band): iso-MATCH ≠ real-TU bank, the memcpy→struct-assign fix, +5 levers (2026-07-10b) L2953
-- **§44** — The Phase-25 cheap-Opus giant batch: 5 structural levers + the §43 extension (2026-07-11, 6 crackers over the frontier giants) L3242
-- **§46** — The `func_80178D40` crack (890 ins ×134, the heaviest core in the game): four LOOP-STRUCTURE levers cheap-Opus found by reading loop.c/jump.c/cse.c (Phase 26 session 8, 2026-07-13) L3313
-- **§3-Why** — 0/8 was structural, and predictable from two words L4045
-- **§54** — `--fix-def-sig`: the member's CANONICAL DECLARATION is a build step too (tiny-IMM mega-pools, +4,801, Phase 29 T6, 2026-07-16) L4163
-- **§56b** — PROPAGATING an h_seq giant: the exemplar's externs MUST be fleet-canonical, not the draft's types L4232
-- **§65a** — The blast-radius taxonomy (makes §61's law structural instead of remembered) L5030
-- **§66d-5** — `residual_class`'s "structural ⇒ permuter CPU is waste" is WRONG for schedule permutations (measured, Phase 29 SESSION-18) L5491
-- **§83** — The parameterised-repeat law, the spill-area trap, and why a per-case edit cannot move a per-case symptom (Phase 29 SESSION-20, `func_80183814` 5,122 ins, cold-ish start → 36 structural / 99.3%) L6412
-- **§84** — The DERIVED-OFFSET remap bug: a hand-computed literal that encodes the DISTANCE between two per-overlay symbols, and why `match_one` is structurally blind to it (Phase 29 SESSION-20, `func_8013D53C`) L6472
-- **§3-The** — construct L6477
-- **§91** — A structure-TRANSFER is only valid where the structure corresponds: the `--like` role trap (Phase 29 SESSION-21, `func_8012AAAC` ×137) L6842
-- **§3-The** — three-hypothesis trail, because two of them were wrong and the wrongness is instructive L6871
-- **§129** — Post-carve, `rtu_match`/`match_one` COUNT THE JUMP TABLE AS INSTRUCTIONS; and a carve must never be committed without its owner (P30 S28, `func_8013BD74`) L8437
-- **§129a** — the target instruction count is INFLATED after a carve L8441
-- **§3-The** — DEFINITION-side alias is the only escape when the fleet canon disagrees on a promoting param L9473
-- **§3-Two** — errors of mine, both instructive L10009
-- **§160** — THE REACH-15 WAVE HARVEST: an align-1 block move, and the instrument that called it a wall (P30 S47) L10893
-- **§16Xy** — SHARPENS *(sharpens §136d-3, §37 /s-DEP LATTICE, §135-2, §136-13, §162q)* L12300
-- **§3-The** — `/s` drop clause is in ALL THREE dependence predicates, so the FIXED-ADDRESS STORE is what floats (P30 S48, `func_8017CA18`, ov_MAIN_012) L12302
-- **§16Z** — SHARPENS *(sharpens §37 "the /s-DEP LATTICE", §136-13, §136-14, §16Xy, §162q, `gcc-2.7.2-map/sched.md` §64)* L14353
-- **§3-The** — ADDRESS-CLASS TABLE: which load/store pairs even REACH the `/s` clause (P30 S48 wave 4, `func_80185B44`, ov_SC03_014) L14355
-- **§176g** — SIZE A WAVE BY INSTRUCTIONS, NOT BY CARDS (P31 S52 — the adopted doctrine) L16953
-- **§3-F.** — `MEM_IN_STRUCT_P` ASYMMETRY IN `true_dependence` (func_80037144, 124 ins) L17304
-- **§179-E** — A `>2*MAX_MOVE_BYTES` BLOCK COPY IS A **STRUCT ASSIGNMENT**, NOT A HAND LOOP L17506
-- **§176-B** — "REGALLOC-PERM, 1-4 instructions off" ⇒ it is usually NOT register allocation L17663
-- **§189** — FIVE COMPILER LAWS MINED FROM THE WAVE R/S JOURNALS (P31 S53), each source-cited and re-derived by a second agent L18226
-- **§193-A** — The wave card ships only OPEN-set pointers and discards the atlas's BANKED one — `exemplar`/`sibs` are stubs 100% by construction (tools/atlas.py:96/657), while `seed.ref` (matched pool, atlas.py:505-536) is dropped at build_wave_atlas.py:143 L18442
-- **§193-B** — A NARROW CAST OF A WIDE PARAMETER COSTS ONE EXTRA INSTRUCTION WHEN ITS STATEMENT SITS AFTER AN INTERVENING `jal` — AND THE DECIDER IS `combine.c:929`'s CROSS-CALL GUARD, NOT REGISTER ALLOCATION L18509
-- **§193-I** — A DECLARED AGGREGATE LOCAL HAS AN 8-BYTE FRAME STRIDE — CEIL(size,8), NOT size. N ARRAYS THEREFORE COST 8·k MORE THAN ONE HAND-LAID STRUCT (k = how many of them have size mod 8 ≠ 0), AND THE TELL IS IDENTICAL INSTRUCTION COUNT WITH EVERY $sp DISPLACEMENT SHIFTED BY THE SAME CONSTANT. L18847
-- **§194-E** — The wave card's `exemplar` is the TARGET ITSELF on 42/73 wave-U and 36/71 wave-T cards — a construction consequence of `atlas.py:657` (exemplar = max-nins OPEN member) meeting `build_wave_atlas.py:166` (one card per gid); and the shipped §193-A `seed_ref` is same-binary on 0/51, so no card field can ever name a destination-TU sibling L19158
-- **§194-H** — §164-29's WAR fence runs again at SCHED2 ON HARD REGISTERS: an in-place `v &= K` before a branch fences the store that reads v, and when TWO independent stores compete for the one delay slot the fence picks the winner at ZERO length drift (a WIDTH/sh!=sw swap, not a nop). Corrects §167-42's reconstruction (pseudo arm → hard-reg arm) and supplies its first re-runnable A/B. L19311
-- **§195-D** — §195 — `masked_diff.mask_for` returns 0 for EVERY `j`/`jal` word, so an internal `j` destination is invisible to match_one, the permuter scorer AND every similarity tier: a control-flow semantic error (which calls execute) surfaces as a 1-instruction residual mislabelled `DELAY-SLOT / profile=schedule`, or as an outright false MATCH L19884
-- **§195-F** — fold-const.c:4825 canonicalises a `?:` whose THEN arm is zero (or constant against a non-constant ELSE) by inverting the condition and swapping the arms — so a ternary's written arm order is byte-inert there, and `c ? 0 : X` is unspellable: it always compiles as `!c ? X : 0` L20010
-- **§195-G** — §NEW — TWO ARMS CALLING THE SAME CALLEE MERGE INTO ONE `jal` UNLESS EACH ARM'S OWN CODE CONSUMES THE RESULT: the C dial that keeps two call sites apart is WHERE the consumer test lives, and the branch SENSE you spell it with is byte-inert (jump.c:1737 canonicalises it) L20062
-- **§195-K** — At -O2 the §18 array-of-struct lever is a FRAME lever, not a length lever — but only when the N reads carry DISTINCT index expressions; with a SHARED index §18's +2-instruction residual is still alive at -O2 (the submitted "memory-loaded narrow index" precondition and unconditional length-neutrality are both falsified) L20266
-- **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` L20860
-- **§199-F** — §164-36b — THE TARGET-HEAD FENCE IS A DELAY-SLOT THREAD SELECTOR, AND IT ONLY FIRES WHEN `mostly_true_jump > 0` (amendment to §164-36; its "−1 instruction" tell is falsified) L20979
-- **§204-D** — A LOOP-INVARIANT LOAD IS ADMITTED AS A MOVABLE ONLY IF ITS ADDRESS CANNOT TRAP: `local.field` PASSES, THE SAME READ THROUGH A POINTER LOCAL IS REFUSED L21763
-- **§225** — THREE CONTROL-FLOW SHAPES NO STRUCTURED SPELLING REACHES (P31 S58) L22934
-- **§30** — addendum (P31 S58) — the `/s` grant closes a SCHEDULING residual and a REGISTER residual with one edit L23216
-- **§249** — THE SELF-ASSIGN, THE DEAD RE-ASSIGN, AND THE `+ zr` COPY: THREE WAYS TO MAKE A DELETED INSTRUCTION REAL (P31 S58b) L23890
-- **§30** — addendum (P31 S58b) — THE ANONYMOUS STRUCT MEMBER REF GRANTS `/s`, AND THAT IS A TWO-FOR-ONE L24158
-- **§263** — A STOLEN DELAY SLOT WHOSE INSTRUCTION IS AN ARG-REGISTER COPY IS AN ARITY ERROR, NOT A SCHEDULE (P31 S59, byte-proven) L24886
-- **ADD-8** — → §245 addendum — THE RE-TIE BARRIER PINS CALL-ARG SETUP TO SOURCE ORDER (construct 6) L25162
-- **ADD-11** — → Cross-confirmation card block (per §259's standing instruction: confirmation, not news) L25193
-- **ADD-4** — → §167-37 addendum — THE FIFTH PRECONDITION, NOW MEASURED: DOWNSTREAM FIELD RE-READS ⇒ NAME IT **AND** STORE **INSIDE** THE ARM L25353
-- **ADD-10** — → Cross-confirmation card block (per §259's standing instruction: confirmation, not news) L25444
-- **ADDENDUM** — to §82 — struct copies must stay MEMBER-WISE, not block-moved, to match a spill-slot save L25702
-- **ADDENDUM** — to §244 — THE COMPILER BARRIER, NOT `volatile`, BLOCKS A STORE→LOAD HOIST THROUGH A POINTER-OFFSET FIELD L26028
-- **§281** — GROUP COPY-THEN-RMW BY OPERATION KIND, NOT FIELD BY FIELD: sched1 does the interleaving, the source must not (P31 S60; wave cf, func_80180FB4, ov_SC03_111, byte-proven) L26949
-- **§NNN** — A DEPENDENT COPY-THEN-RMW BLOCK MUST BE SOURCE-GROUPED BY OPERATION KIND, NOT BY FIELD, AND SCHED1 DOES THE INTERLEAVING (P31 S60; `func_80180FB4`, ov_SC03_111, byte-proven) L26950
-- **§NNN** — WRITE THE UP-COUNT LOOP: gcc's OWN REVERSAL PRODUCES A COUNTER-INIT INSTRUCTION THAT LANDS AFTER HOISTED MOVABLES, WHICH A HAND-WRITTEN DOWN-COUNT LOOP CANNOT REPRODUCE (P31 S60; `func_80180DD8`, ov_SC04_005, byte-proven) L26996
-- **§285** — PRE-INITIALIZING A VARIABLE WITH A SHARED CONSTANT BEFORE A BRANCH MAKES BOTH ARMS OF THE FOLLOWING if/else DESTRUCTIVELY REUSE THE SAME DESTINATION REGISTER FOR THEIR BITWISE RESULT (byte-proven; `func_801811F0`, ov_SC03_102, independently rediscovered across waves di/dj) (P31 S60; waves #, byte-proven) L29037
-- **§287** — A STACK-FRAME HOLE BELOW TWO ADDRESS-TAKEN AGGREGATE LOCALS IS A LEADING PAD MEMBER OF ONE COMBINED STRUCT, NOT SEPARATE LOCALS OR A REGISTER PIN (P31 S60/dj; `func_8017D104`, ov_SC06_027, byte-proven 47/47) (P31 S60; waves #, byte-proven) L29045
-- **§297** — ONE GIV SERVING MIXED-WIDTH LOADS *AND* A STORE NEEDS STRUCT-MEMBER SPELLING; CAST/INDEX SPELLINGS RE-SPLIT THE PSEUDO (P31 S61; wave m0a, `func_800347C8`, main, byte-proven 31/31) L29458
-- **§308a** — A TWO-INSTRUCTION ARM STUB LAID *BEFORE* THE OTHER ARM AND REACHED ONLY BY A TRAILING `j` SURVIVES ONLY BEHIND A SHORT-CIRCUIT `&&` GUARD PLUS A SEPARATE RE-TEST; EVERY PLAIN if/else-if, GOTO-LADDER, NESTED-INVERTED-if AND 1-/2-NODE switch LETS jump1 INLINE IT (−2 ins) (P31 S63 t5e-t5i; byte-proven func_80180808) L29971
+- **§42a** — addendum — wave 2 (residuals + 29-100 band): iso-MATCH ≠ real-TU bank, the memcpy→struct-assign fix, +5 levers (2026-07-10b) L2968
+- **§44** — The Phase-25 cheap-Opus giant batch: 5 structural levers + the §43 extension (2026-07-11, 6 crackers over the frontier giants) L3257
+- **§46** — The `func_80178D40` crack (890 ins ×134, the heaviest core in the game): four LOOP-STRUCTURE levers cheap-Opus found by reading loop.c/jump.c/cse.c (Phase 26 session 8, 2026-07-13) L3328
+- **§3-Why** — 0/8 was structural, and predictable from two words L4060
+- **§54** — `--fix-def-sig`: the member's CANONICAL DECLARATION is a build step too (tiny-IMM mega-pools, +4,801, Phase 29 T6, 2026-07-16) L4178
+- **§56b** — PROPAGATING an h_seq giant: the exemplar's externs MUST be fleet-canonical, not the draft's types L4247
+- **§65a** — The blast-radius taxonomy (makes §61's law structural instead of remembered) L5045
+- **§66d-5** — `residual_class`'s "structural ⇒ permuter CPU is waste" is WRONG for schedule permutations (measured, Phase 29 SESSION-18) L5506
+- **§83** — The parameterised-repeat law, the spill-area trap, and why a per-case edit cannot move a per-case symptom (Phase 29 SESSION-20, `func_80183814` 5,122 ins, cold-ish start → 36 structural / 99.3%) L6427
+- **§84** — The DERIVED-OFFSET remap bug: a hand-computed literal that encodes the DISTANCE between two per-overlay symbols, and why `match_one` is structurally blind to it (Phase 29 SESSION-20, `func_8013D53C`) L6487
+- **§3-The** — construct L6492
+- **§91** — A structure-TRANSFER is only valid where the structure corresponds: the `--like` role trap (Phase 29 SESSION-21, `func_8012AAAC` ×137) L6857
+- **§3-The** — three-hypothesis trail, because two of them were wrong and the wrongness is instructive L6886
+- **§129** — Post-carve, `rtu_match`/`match_one` COUNT THE JUMP TABLE AS INSTRUCTIONS; and a carve must never be committed without its owner (P30 S28, `func_8013BD74`) L8452
+- **§129a** — the target instruction count is INFLATED after a carve L8456
+- **§3-The** — DEFINITION-side alias is the only escape when the fleet canon disagrees on a promoting param L9488
+- **§3-Two** — errors of mine, both instructive L10024
+- **§160** — THE REACH-15 WAVE HARVEST: an align-1 block move, and the instrument that called it a wall (P30 S47) L10908
+- **§16Xy** — SHARPENS *(sharpens §136d-3, §37 /s-DEP LATTICE, §135-2, §136-13, §162q)* L12315
+- **§3-The** — `/s` drop clause is in ALL THREE dependence predicates, so the FIXED-ADDRESS STORE is what floats (P30 S48, `func_8017CA18`, ov_MAIN_012) L12317
+- **§16Z** — SHARPENS *(sharpens §37 "the /s-DEP LATTICE", §136-13, §136-14, §16Xy, §162q, `gcc-2.7.2-map/sched.md` §64)* L14368
+- **§3-The** — ADDRESS-CLASS TABLE: which load/store pairs even REACH the `/s` clause (P30 S48 wave 4, `func_80185B44`, ov_SC03_014) L14370
+- **§176g** — SIZE A WAVE BY INSTRUCTIONS, NOT BY CARDS (P31 S52 — the adopted doctrine) L16968
+- **§3-F.** — `MEM_IN_STRUCT_P` ASYMMETRY IN `true_dependence` (func_80037144, 124 ins) L17319
+- **§179-E** — A `>2*MAX_MOVE_BYTES` BLOCK COPY IS A **STRUCT ASSIGNMENT**, NOT A HAND LOOP L17521
+- **§176-B** — "REGALLOC-PERM, 1-4 instructions off" ⇒ it is usually NOT register allocation L17678
+- **§189** — FIVE COMPILER LAWS MINED FROM THE WAVE R/S JOURNALS (P31 S53), each source-cited and re-derived by a second agent L18241
+- **§193-A** — The wave card ships only OPEN-set pointers and discards the atlas's BANKED one — `exemplar`/`sibs` are stubs 100% by construction (tools/atlas.py:96/657), while `seed.ref` (matched pool, atlas.py:505-536) is dropped at build_wave_atlas.py:143 L18457
+- **§193-B** — A NARROW CAST OF A WIDE PARAMETER COSTS ONE EXTRA INSTRUCTION WHEN ITS STATEMENT SITS AFTER AN INTERVENING `jal` — AND THE DECIDER IS `combine.c:929`'s CROSS-CALL GUARD, NOT REGISTER ALLOCATION L18524
+- **§193-I** — A DECLARED AGGREGATE LOCAL HAS AN 8-BYTE FRAME STRIDE — CEIL(size,8), NOT size. N ARRAYS THEREFORE COST 8·k MORE THAN ONE HAND-LAID STRUCT (k = how many of them have size mod 8 ≠ 0), AND THE TELL IS IDENTICAL INSTRUCTION COUNT WITH EVERY $sp DISPLACEMENT SHIFTED BY THE SAME CONSTANT. L18862
+- **§194-E** — The wave card's `exemplar` is the TARGET ITSELF on 42/73 wave-U and 36/71 wave-T cards — a construction consequence of `atlas.py:657` (exemplar = max-nins OPEN member) meeting `build_wave_atlas.py:166` (one card per gid); and the shipped §193-A `seed_ref` is same-binary on 0/51, so no card field can ever name a destination-TU sibling L19173
+- **§194-H** — §164-29's WAR fence runs again at SCHED2 ON HARD REGISTERS: an in-place `v &= K` before a branch fences the store that reads v, and when TWO independent stores compete for the one delay slot the fence picks the winner at ZERO length drift (a WIDTH/sh!=sw swap, not a nop). Corrects §167-42's reconstruction (pseudo arm → hard-reg arm) and supplies its first re-runnable A/B. L19326
+- **§195-D** — §195 — `masked_diff.mask_for` returns 0 for EVERY `j`/`jal` word, so an internal `j` destination is invisible to match_one, the permuter scorer AND every similarity tier: a control-flow semantic error (which calls execute) surfaces as a 1-instruction residual mislabelled `DELAY-SLOT / profile=schedule`, or as an outright false MATCH L19899
+- **§195-F** — fold-const.c:4825 canonicalises a `?:` whose THEN arm is zero (or constant against a non-constant ELSE) by inverting the condition and swapping the arms — so a ternary's written arm order is byte-inert there, and `c ? 0 : X` is unspellable: it always compiles as `!c ? X : 0` L20025
+- **§195-G** — §NEW — TWO ARMS CALLING THE SAME CALLEE MERGE INTO ONE `jal` UNLESS EACH ARM'S OWN CODE CONSUMES THE RESULT: the C dial that keeps two call sites apart is WHERE the consumer test lives, and the branch SENSE you spell it with is byte-inert (jump.c:1737 canonicalises it) L20077
+- **§195-K** — At -O2 the §18 array-of-struct lever is a FRAME lever, not a length lever — but only when the N reads carry DISTINCT index expressions; with a SHARED index §18's +2-instruction residual is still alive at -O2 (the submitted "memory-loaded narrow index" precondition and unconditional length-neutrality are both falsified) L20281
+- **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` L20875
+- **§199-F** — §164-36b — THE TARGET-HEAD FENCE IS A DELAY-SLOT THREAD SELECTOR, AND IT ONLY FIRES WHEN `mostly_true_jump > 0` (amendment to §164-36; its "−1 instruction" tell is falsified) L20994
+- **§204-D** — A LOOP-INVARIANT LOAD IS ADMITTED AS A MOVABLE ONLY IF ITS ADDRESS CANNOT TRAP: `local.field` PASSES, THE SAME READ THROUGH A POINTER LOCAL IS REFUSED L21778
+- **§225** — THREE CONTROL-FLOW SHAPES NO STRUCTURED SPELLING REACHES (P31 S58) L22949
+- **§30** — addendum (P31 S58) — the `/s` grant closes a SCHEDULING residual and a REGISTER residual with one edit L23231
+- **§249** — THE SELF-ASSIGN, THE DEAD RE-ASSIGN, AND THE `+ zr` COPY: THREE WAYS TO MAKE A DELETED INSTRUCTION REAL (P31 S58b) L23905
+- **§30** — addendum (P31 S58b) — THE ANONYMOUS STRUCT MEMBER REF GRANTS `/s`, AND THAT IS A TWO-FOR-ONE L24173
+- **§263** — A STOLEN DELAY SLOT WHOSE INSTRUCTION IS AN ARG-REGISTER COPY IS AN ARITY ERROR, NOT A SCHEDULE (P31 S59, byte-proven) L24901
+- **ADD-8** — → §245 addendum — THE RE-TIE BARRIER PINS CALL-ARG SETUP TO SOURCE ORDER (construct 6) L25177
+- **ADD-11** — → Cross-confirmation card block (per §259's standing instruction: confirmation, not news) L25208
+- **ADD-4** — → §167-37 addendum — THE FIFTH PRECONDITION, NOW MEASURED: DOWNSTREAM FIELD RE-READS ⇒ NAME IT **AND** STORE **INSIDE** THE ARM L25368
+- **ADD-10** — → Cross-confirmation card block (per §259's standing instruction: confirmation, not news) L25459
+- **ADDENDUM** — to §82 — struct copies must stay MEMBER-WISE, not block-moved, to match a spill-slot save L25717
+- **ADDENDUM** — to §244 — THE COMPILER BARRIER, NOT `volatile`, BLOCKS A STORE→LOAD HOIST THROUGH A POINTER-OFFSET FIELD L26043
+- **§281** — GROUP COPY-THEN-RMW BY OPERATION KIND, NOT FIELD BY FIELD: sched1 does the interleaving, the source must not (P31 S60; wave cf, func_80180FB4, ov_SC03_111, byte-proven) L26964
+- **§NNN** — A DEPENDENT COPY-THEN-RMW BLOCK MUST BE SOURCE-GROUPED BY OPERATION KIND, NOT BY FIELD, AND SCHED1 DOES THE INTERLEAVING (P31 S60; `func_80180FB4`, ov_SC03_111, byte-proven) L26965
+- **§NNN** — WRITE THE UP-COUNT LOOP: gcc's OWN REVERSAL PRODUCES A COUNTER-INIT INSTRUCTION THAT LANDS AFTER HOISTED MOVABLES, WHICH A HAND-WRITTEN DOWN-COUNT LOOP CANNOT REPRODUCE (P31 S60; `func_80180DD8`, ov_SC04_005, byte-proven) L27011
+- **§285** — PRE-INITIALIZING A VARIABLE WITH A SHARED CONSTANT BEFORE A BRANCH MAKES BOTH ARMS OF THE FOLLOWING if/else DESTRUCTIVELY REUSE THE SAME DESTINATION REGISTER FOR THEIR BITWISE RESULT (byte-proven; `func_801811F0`, ov_SC03_102, independently rediscovered across waves di/dj) (P31 S60; waves #, byte-proven) L29052
+- **§287** — A STACK-FRAME HOLE BELOW TWO ADDRESS-TAKEN AGGREGATE LOCALS IS A LEADING PAD MEMBER OF ONE COMBINED STRUCT, NOT SEPARATE LOCALS OR A REGISTER PIN (P31 S60/dj; `func_8017D104`, ov_SC06_027, byte-proven 47/47) (P31 S60; waves #, byte-proven) L29060
+- **§297** — ONE GIV SERVING MIXED-WIDTH LOADS *AND* A STORE NEEDS STRUCT-MEMBER SPELLING; CAST/INDEX SPELLINGS RE-SPLIT THE PSEUDO (P31 S61; wave m0a, `func_800347C8`, main, byte-proven 31/31) L29473
+- **§308a** — A TWO-INSTRUCTION ARM STUB LAID *BEFORE* THE OTHER ARM AND REACHED ONLY BY A TRAILING `j` SURVIVES ONLY BEHIND A SHORT-CIRCUIT `&&` GUARD PLUS A SEPARATE RE-TEST; EVERY PLAIN if/else-if, GOTO-LADDER, NESTED-INVERTED-if AND 1-/2-NODE switch LETS jump1 INLINE IT (−2 ins) (P31 S63 t5e-t5i; byte-proven func_80180808) L29986
+- **§312** — A BARE RELATIONAL IN AN `if` GIVES THE `slt` NO TARGET: ASSIGN THE COMPARISON INTO THE ALREADY-ALLOCATED VARIABLE TO CHOOSE ITS DESTINATION REGISTER, AT ZERO INSTRUCTION COST (P31 S64 t5o-t5r; byte-proven func_80180DCC) L30133
### types, signedness & load/store width (77)
@@ -408,72 +411,72 @@
- **§33** — Automating the giant decl-reconcile: `tools/reconcile_decls.py` (the DATA analog of §20's `cast_call_sites`) + a fleet-majority type oracle (Phase 24 T7b, byte-proven on `func_80129CF8`) L2434
- **§40a** — The DECL-RECONCILE pass (type-lift so remapped drafts compile in the sibling TU) (Phase 25 T7.2, 2026-07-08) L2601
- **§41** — The DEF-SIDE canonical-sig wall: mechanically banking a drafted giant past `conflicting types` (Phase 25 T5b batch-2, 2026-07-09; `tools/canon_sig_reconcile.py`, byte-proven on `func_8013B274`) L2710
-- **§41d** — `void`→`s32` is NOT always byte-neutral: gate the RAW draft FIRST (Phase 26 session 6, byte-proven) L2878
-- **§42b** — addendum — wave 3 (Max, 2026-07-10c): THE STALE-OBJECT GATE TRAP + the read-global `&`-cast drift + fix L2994
-- **§43** — The K&R s16-param definition DISSOLVES the "narrow-param wall" for by-value register args (Phase 25 task A, Fable5 crack of the 369-ins giant `func_80166994` ×134, 2026-07-11) L3195
-- **§3-C.** — TYPE- AND SHAPE-DRIVEN CODEGEN (the C type literally selects the addressing mode) L3484
-- **§56b** — PROPAGATING an h_seq giant: the exemplar's externs MUST be fleet-canonical, not the draft's types L4232
-- **§64** — The §20 type-lift's three laws: fold the tagged typedef, check VISIBILITY, and strip only what is TEXTUALLY IDENTICAL (`lift_types.py`, Phase 29 SESSION-14, 2026-07-23) L4908
-- **§64a** — VARIANT types: UNIQUIFY the camps, do not reconcile them (`uniquify_type.py`, Phase 29 SESSION-14) L4957
-- **§65g** — Where the cheap levers STOP: the local-type and in-TU-self-decl classes did not yield L5139
-- **§68** — A comment-only line halted the extern scan, and the skip label blamed the type cap (Phase 29 SESSION-18) L5524
-- **§73** — A def-side self-decl conflict has TWO axes: RETURN (fleet widen, T2) and PARAMS (casts at each use, T0). Diagnose which before paying for the expensive one (Phase 29 SESSION-19, `func_8014F3E8` + `func_8014D4C0`) L5783
-- **§75c** — Class-B's remedy is the FULL §17a-1 PAIR (decl **and** call-site cast); a decl-only fix moves the error and looks like a new wall (Phase 29 SESSION-19, `func_8012F14C`) L5997
-- **§3-The** — defect this exposed: a shared type that is present but invisible L6354
-- **§92** — Conforming a DECLARATION: pointer changes are caller-neutral, scalar-WIDTH changes are not (Phase 29 SESSION-21, `tools/conform_decls.py`) L6891
-- **§94** — A family sweep's `0/N` is a TYPE-CARRY failure until proven otherwise: lift the exemplar's local types, ALL of them, transitively (Phase 29 SESSION-21, `func_8016B6BC` 0/137 → 137/137) L6947
-- **§100** — Prefer the DRAFT-LOCAL fix: a type only one function uses belongs in its BODY, not in a shared header (Phase 29 SESSION-22, `func_80175DA8` 0/137 → 137/137) L7216
-- **§120** — Uniquify draft-defined TYPE names; and check which of N staging sites you actually patched (Phase 29 T93) L8026
-- **§3-Do** — NOT "strip the duplicate typedef" — it breaks the extern that uses it L8037
-- **§3-The** — type-form rules L8879
-- **§143** — `cast_call_sites` read a RETURN STATEMENT as a prototype and deleted it. A 0/39 sweep became 18/39. (P30 S40) L9834
-- **Then** — propagation returned 0/137 TWICE — both times a missing TYPE L10000
-- **§154** — Reading a disc payload: the module-id word, static base derivation, and "type 1 = uncompressed overlay" (P30 S44) L10522
-- **§3-C.** — PAC type 1 = the same payload class as type 4, just NOT compressed L10548
-- **§155b** — check the TYPE your oracle returns before comparing against it (S45 p5) L10587
-- **§3-B.** — Typedef handling — the only strategy that survives contact L17017
-- **§3-D.** — A NARROW TYPE BLOCKS COPY ELISION (func_8001D3FC — new idiom) L17288
-- **§185** — EDIT THE SIDE THAT IS CHEAP TO VERIFY, AND CHECK A TU RETYPE AT ITS USE SITES L18060
-- **§186b** — A NO-SAVE 16-BYTE FRAME IN A LEAF FUNCTION MEANS `s16` LOCALS, NOT A HIDDEN CALL L18113
-- **§193-B** — A NARROW CAST OF A WIDE PARAMETER COSTS ONE EXTRA INSTRUCTION WHEN ITS STATEMENT SITS AFTER AN INTERVENING `jal` — AND THE DECIDER IS `combine.c:929`'s CROSS-CALL GUARD, NOT REGISTER ALLOCATION L18509
-- **§193-G** — §164-54's "scope to ≥4 arms" bound is byte-wrong — the dispatch-topology oracle goes live at THREE case nodes (`balance_case_nodes` splits at `i > 2`), but only for a signed-after-promotion index L18746
-- **§193-H** — A pointer-derived base load `*(s32*)(p+K)` is uncacheable across ANY memory write or call (cse's third kill disjunct) — so the target emits one `lw` per store-separated RUN of spellings, and a run of stores sharing one `lw` is a C local you must declare L18807
-- **§194-B** — A `addu $rA,$rB,$zero` copy feeding ≥2 `sh` stores is a SECOND, 16-BIT-DECLARED local — the width, not the clamp or the join liveness, is what keeps the copy (and func_80183094's pin + `"memory"` clobber are both provably inert) L19016
-- **§194-D** — Declared width of a computed-value local is a sched1 dial (count-neutral) — a replication + attribution correction of §165-17, NOT a new argument-register law L19117
-- **§194-G** — Reading the integer half of a 16.16 stack aggregate: REGISTER-LIVENESS, not the C spelling, decides `sra` vs `lhu` — and the break is count-neutral L19268
-- **§194-H** — §164-29's WAR fence runs again at SCHED2 ON HARD REGISTERS: an in-place `v &= K` before a branch fences the store that reads v, and when TWO independent stores compete for the one delay slot the fence picks the winner at ZERO length drift (a WIDTH/sh!=sw swap, not a nop). Corrects §167-42's reconstruction (pseudo arm → hard-reg arm) and supplies its first re-runnable A/B. L19311
-- **§194-I** — §16N+2's magic-per-odd-part ladder has exactly one broken row — read the divisor arithmetically instead: d = round(2^(32 + post_shift) / magic_read_as_unsigned) L19349
-- **§197-A** — A NARROW SIGNED MEMORY READ FEEDING A CONSTANT `>>` LOSES ITS `lh`, AND THE CURE IS AN ASM RE-TIE (attribution CONTESTED: cse vs combine) L20581
-- **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` L20860
-- **§201-D** — THE SIGNEDNESS OF A div/mod MAGIC IS DECIDED BY THE STATIC TYPE OF THE DIVIDEND TREE AFTER `get_narrower` STRIPS WIDENING CONVERSIONS — NEVER BY A PROVABLE RANGE. AN `& 0xFF` IS NOT A CONVERSION, SO IT NEVER FLIPS THE MAGIC; A DECLARED-UNSIGNED LOCAL *OR* A NARROWING CAST WRITTEN AT THE DIVIDE BOTH DO. L21321
-- **§203** — A DEDUPED TYPEDEF MUST PRECEDE EVERY SPLICE POINT, NOT JUST ITS OWN (P31 S56) L21486
-- **§204-E** — `decl_prior`'s `%hi/%lo` ARM HAS NEVER FIRED: the card's promised GLOBAL-TYPE row is 0 of 1,210 L21838
-- **§218** — A NARROW TYPE AT THE ABI BOUNDARY COSTS AN IN-PLACE `sll/sra` PAIR — on the RETURN as well as on the PARAMETER (P31 S58) L22682
-- **§220** — THE PARAMETER ITSELF IS A REGALLOC DIAL: use it directly, prefer `s32` to `void*`, and place the save-copy AFTER the first call (P31 S58) L22738
-- **§227** — TYPE THE SOURCE BY THE **LOAD** WIDTH, NOT BY THE STORE WIDTH (P31 S58) L23018
-- **§234** — CONSTANT MATERIALISATION: THE STORE LVALUE'S SIGNEDNESS PICKS `addiu` vs `li`/`ori` (P31 S58b) L23316
-- **§237** — THE CAST-AT-CALL-SITE DECISION TABLE: WHAT §17a-1 FIXES, WHAT IT CANNOT, AND THE FOUR ESCAPES (P31 S58b) L23465
-- **§242** — `*k` vs `<>n`: EXPRESSION SPELLING OWNS THE LOAD WIDTH AND THE ROUNDING CHAIN (P31 S58b) L23652
-- **§243** — SPELL THE CSE BARRIER AS A REASSIGNED POINTER; AND THE `nop`-AFTER-EVERY-`lh` SIGNATURE (P31 S58b) L23680
-- **§251** — IMMEDIATE-SPELLING TRIGGERS: `+= 0xFF`, FULL-WIDTH `~K`, AND THE TWO-OR SPLIT (P31 S58b) L23969
-- **ADD-5** — → §1/I1 addendum — THE INVERTED RANGE TEST: `(u32)(x-lo) >= N` WITH THE ZERO-ARM AS THE TRAILING `else` L25132
-- **ADD-2** — → §236 addendum (item 1 corollary) — THE SILENT-SPLICE DECLARATION LADDER: WHERE THE TU HAS NO SPELLING, UNPROTOTYPED `()` BEATS THE FLEET VOTE L25326
-- **ADD-5** — → §267-ADD-6 / §172b-1 addendum — THE SIGN-TEST FACE: `(s16)v < 0` IS `sll 16` + `bgez` ON THE SHIFTED COPY, RAW STAYS LIVE — AND THE HALFWORD-ABS SHAPE NEEDS NO RITUAL L25370
-- **ADD-8** — → §30a addendum — THE THIRD COLUMN: `*p++` IS ALSO SERIALIZED BUT BURNS `addiu`; ONLY CAST-PLUS GIVES SERIALIZATION *AND* DISPLACEMENT FOLDING L25415
-- **ADDENDUM** — to §179-C — the `.type NAME, @function` requirement L25599
-- **ADDENDUM** — to §134 — a typedef defined BELOW the splice point is stripped anyway L25646
-- **ADDENDUM** — to §172b-1 — TWO PLACEMENT DIALS THE PROMOTION LAW DOESN'T NAME: NARROW THE COUNTER'S DECLARED TYPE, AND MOVE THE CAST INTO THE LOOP BODY L26059
-- **ADDENDUM** — to §172b-4 — THE PLAIN CAST-DIVISION ALREADY PRODUCES THE PATTERN; DON'T HAND-ROLL THE BIAS, AND KEEP THE OPERAND WIDE L26151
-- **§280** — THE CURSOR'S DECLARED TYPE PICKS `sltu` vs `slt`: a `T*` bound test is UNSIGNED by C rule, an integer cursor is signed (P31 S60; wave cf, func_800CAE74, md_MAIN_031, byte-proven) L26915
-- **§NNN** — A LOOP CURSOR'S C TYPE (POINTER vs PLAIN INTEGER) SELECTS `sltu` vs `slt` FOR ITS BOUND TEST, INDEPENDENT OF THE VALUES INVOLVED (P31 S60; `func_800CAE74`, md_MAIN_031, byte-proven; cross-confirmed same wave by `func_8017F2A4`, ov_SC03_096) L26916
-- **ADDENDUM** — to §21 — the `bltz`+`slti` (or N-separate-compares) signed-range-split bullet is now CONFIRMED on three independent functions, and generalizes beyond `lbu`/u8 L27116
-- **ADDENDUM** — to §202 — the DEF-SIDE ALIAS also resolves a function-vs-DATA-symbol identifier clash, not only a function-vs-function prototype clash L27162
-- **ADDENDUM** — §NNN — sharpens §162a3/§60b: A `sll $v0,16 / sltiu $v0,1` ZERO-TEST OF A JUST-DECREMENTED HALFWORD IS A SIGNED-TEMP WIDTH TELL OUTSIDE ANY SWITCH/RANGE-TEST CONTEXT L28252
-- **§288** — A REGISTER PIN DECLARED UNINITIALIZED AND ASSIGNED ONLY AT ITS LATE, SOLE USE STILL FORCES THE FIXED REGISTER'S SAVE/RESTORE, AND THE ASSIGNMENT'S SOURCE POSITION CONTROLS WHERE THE VALUE MATERIALIZES (P31; `func_80186530`, ov_SC02_017, byte-proven, match_one MATCH re-verified) (P31 S60; waves #, byte-proven) L29049
-- **§292** — DECLARING A SYMBOL UPSTREAM OF AN ALREADY-BANKED SIBLING THAT RELIES ON THAT SYMBOL'S IMPLICIT (K&R) DECLARATION CAN SILENTLY REPROTOTYPE THE SIBLING'S OWN CALL SITE (P31 S60; waves #, byte-proven) L29065
-- **ADDENDUM** — to §172b-1 (counter-type dial) — the sll's SOURCE REGISTER is the placement discriminator L29227
-- **ADDENDUM** — to §31's asm→layout inference — TWO WIDTH-PAIR DISCRIMINATORS (same offset, different widths) L29339
-- **§297** — ONE GIV SERVING MIXED-WIDTH LOADS *AND* A STORE NEEDS STRUCT-MEMBER SPELLING; CAST/INDEX SPELLINGS RE-SPLIT THE PSEUDO (P31 S61; wave m0a, `func_800347C8`, main, byte-proven 31/31) L29458
+- **§41d** — `void`→`s32` is NOT always byte-neutral: gate the RAW draft FIRST (Phase 26 session 6, byte-proven) L2893
+- **§42b** — addendum — wave 3 (Max, 2026-07-10c): THE STALE-OBJECT GATE TRAP + the read-global `&`-cast drift + fix L3009
+- **§43** — The K&R s16-param definition DISSOLVES the "narrow-param wall" for by-value register args (Phase 25 task A, Fable5 crack of the 369-ins giant `func_80166994` ×134, 2026-07-11) L3210
+- **§3-C.** — TYPE- AND SHAPE-DRIVEN CODEGEN (the C type literally selects the addressing mode) L3499
+- **§56b** — PROPAGATING an h_seq giant: the exemplar's externs MUST be fleet-canonical, not the draft's types L4247
+- **§64** — The §20 type-lift's three laws: fold the tagged typedef, check VISIBILITY, and strip only what is TEXTUALLY IDENTICAL (`lift_types.py`, Phase 29 SESSION-14, 2026-07-23) L4923
+- **§64a** — VARIANT types: UNIQUIFY the camps, do not reconcile them (`uniquify_type.py`, Phase 29 SESSION-14) L4972
+- **§65g** — Where the cheap levers STOP: the local-type and in-TU-self-decl classes did not yield L5154
+- **§68** — A comment-only line halted the extern scan, and the skip label blamed the type cap (Phase 29 SESSION-18) L5539
+- **§73** — A def-side self-decl conflict has TWO axes: RETURN (fleet widen, T2) and PARAMS (casts at each use, T0). Diagnose which before paying for the expensive one (Phase 29 SESSION-19, `func_8014F3E8` + `func_8014D4C0`) L5798
+- **§75c** — Class-B's remedy is the FULL §17a-1 PAIR (decl **and** call-site cast); a decl-only fix moves the error and looks like a new wall (Phase 29 SESSION-19, `func_8012F14C`) L6012
+- **§3-The** — defect this exposed: a shared type that is present but invisible L6369
+- **§92** — Conforming a DECLARATION: pointer changes are caller-neutral, scalar-WIDTH changes are not (Phase 29 SESSION-21, `tools/conform_decls.py`) L6906
+- **§94** — A family sweep's `0/N` is a TYPE-CARRY failure until proven otherwise: lift the exemplar's local types, ALL of them, transitively (Phase 29 SESSION-21, `func_8016B6BC` 0/137 → 137/137) L6962
+- **§100** — Prefer the DRAFT-LOCAL fix: a type only one function uses belongs in its BODY, not in a shared header (Phase 29 SESSION-22, `func_80175DA8` 0/137 → 137/137) L7231
+- **§120** — Uniquify draft-defined TYPE names; and check which of N staging sites you actually patched (Phase 29 T93) L8041
+- **§3-Do** — NOT "strip the duplicate typedef" — it breaks the extern that uses it L8052
+- **§3-The** — type-form rules L8894
+- **§143** — `cast_call_sites` read a RETURN STATEMENT as a prototype and deleted it. A 0/39 sweep became 18/39. (P30 S40) L9849
+- **Then** — propagation returned 0/137 TWICE — both times a missing TYPE L10015
+- **§154** — Reading a disc payload: the module-id word, static base derivation, and "type 1 = uncompressed overlay" (P30 S44) L10537
+- **§3-C.** — PAC type 1 = the same payload class as type 4, just NOT compressed L10563
+- **§155b** — check the TYPE your oracle returns before comparing against it (S45 p5) L10602
+- **§3-B.** — Typedef handling — the only strategy that survives contact L17032
+- **§3-D.** — A NARROW TYPE BLOCKS COPY ELISION (func_8001D3FC — new idiom) L17303
+- **§185** — EDIT THE SIDE THAT IS CHEAP TO VERIFY, AND CHECK A TU RETYPE AT ITS USE SITES L18075
+- **§186b** — A NO-SAVE 16-BYTE FRAME IN A LEAF FUNCTION MEANS `s16` LOCALS, NOT A HIDDEN CALL L18128
+- **§193-B** — A NARROW CAST OF A WIDE PARAMETER COSTS ONE EXTRA INSTRUCTION WHEN ITS STATEMENT SITS AFTER AN INTERVENING `jal` — AND THE DECIDER IS `combine.c:929`'s CROSS-CALL GUARD, NOT REGISTER ALLOCATION L18524
+- **§193-G** — §164-54's "scope to ≥4 arms" bound is byte-wrong — the dispatch-topology oracle goes live at THREE case nodes (`balance_case_nodes` splits at `i > 2`), but only for a signed-after-promotion index L18761
+- **§193-H** — A pointer-derived base load `*(s32*)(p+K)` is uncacheable across ANY memory write or call (cse's third kill disjunct) — so the target emits one `lw` per store-separated RUN of spellings, and a run of stores sharing one `lw` is a C local you must declare L18822
+- **§194-B** — A `addu $rA,$rB,$zero` copy feeding ≥2 `sh` stores is a SECOND, 16-BIT-DECLARED local — the width, not the clamp or the join liveness, is what keeps the copy (and func_80183094's pin + `"memory"` clobber are both provably inert) L19031
+- **§194-D** — Declared width of a computed-value local is a sched1 dial (count-neutral) — a replication + attribution correction of §165-17, NOT a new argument-register law L19132
+- **§194-G** — Reading the integer half of a 16.16 stack aggregate: REGISTER-LIVENESS, not the C spelling, decides `sra` vs `lhu` — and the break is count-neutral L19283
+- **§194-H** — §164-29's WAR fence runs again at SCHED2 ON HARD REGISTERS: an in-place `v &= K` before a branch fences the store that reads v, and when TWO independent stores compete for the one delay slot the fence picks the winner at ZERO length drift (a WIDTH/sh!=sw swap, not a nop). Corrects §167-42's reconstruction (pseudo arm → hard-reg arm) and supplies its first re-runnable A/B. L19326
+- **§194-I** — §16N+2's magic-per-odd-part ladder has exactly one broken row — read the divisor arithmetically instead: d = round(2^(32 + post_shift) / magic_read_as_unsigned) L19364
+- **§197-A** — A NARROW SIGNED MEMORY READ FEEDING A CONSTANT `>>` LOSES ITS `lh`, AND THE CURE IS AN ASM RE-TIE (attribution CONTESTED: cse vs combine) L20596
+- **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` L20875
+- **§201-D** — THE SIGNEDNESS OF A div/mod MAGIC IS DECIDED BY THE STATIC TYPE OF THE DIVIDEND TREE AFTER `get_narrower` STRIPS WIDENING CONVERSIONS — NEVER BY A PROVABLE RANGE. AN `& 0xFF` IS NOT A CONVERSION, SO IT NEVER FLIPS THE MAGIC; A DECLARED-UNSIGNED LOCAL *OR* A NARROWING CAST WRITTEN AT THE DIVIDE BOTH DO. L21336
+- **§203** — A DEDUPED TYPEDEF MUST PRECEDE EVERY SPLICE POINT, NOT JUST ITS OWN (P31 S56) L21501
+- **§204-E** — `decl_prior`'s `%hi/%lo` ARM HAS NEVER FIRED: the card's promised GLOBAL-TYPE row is 0 of 1,210 L21853
+- **§218** — A NARROW TYPE AT THE ABI BOUNDARY COSTS AN IN-PLACE `sll/sra` PAIR — on the RETURN as well as on the PARAMETER (P31 S58) L22697
+- **§220** — THE PARAMETER ITSELF IS A REGALLOC DIAL: use it directly, prefer `s32` to `void*`, and place the save-copy AFTER the first call (P31 S58) L22753
+- **§227** — TYPE THE SOURCE BY THE **LOAD** WIDTH, NOT BY THE STORE WIDTH (P31 S58) L23033
+- **§234** — CONSTANT MATERIALISATION: THE STORE LVALUE'S SIGNEDNESS PICKS `addiu` vs `li`/`ori` (P31 S58b) L23331
+- **§237** — THE CAST-AT-CALL-SITE DECISION TABLE: WHAT §17a-1 FIXES, WHAT IT CANNOT, AND THE FOUR ESCAPES (P31 S58b) L23480
+- **§242** — `*k` vs `<>n`: EXPRESSION SPELLING OWNS THE LOAD WIDTH AND THE ROUNDING CHAIN (P31 S58b) L23667
+- **§243** — SPELL THE CSE BARRIER AS A REASSIGNED POINTER; AND THE `nop`-AFTER-EVERY-`lh` SIGNATURE (P31 S58b) L23695
+- **§251** — IMMEDIATE-SPELLING TRIGGERS: `+= 0xFF`, FULL-WIDTH `~K`, AND THE TWO-OR SPLIT (P31 S58b) L23984
+- **ADD-5** — → §1/I1 addendum — THE INVERTED RANGE TEST: `(u32)(x-lo) >= N` WITH THE ZERO-ARM AS THE TRAILING `else` L25147
+- **ADD-2** — → §236 addendum (item 1 corollary) — THE SILENT-SPLICE DECLARATION LADDER: WHERE THE TU HAS NO SPELLING, UNPROTOTYPED `()` BEATS THE FLEET VOTE L25341
+- **ADD-5** — → §267-ADD-6 / §172b-1 addendum — THE SIGN-TEST FACE: `(s16)v < 0` IS `sll 16` + `bgez` ON THE SHIFTED COPY, RAW STAYS LIVE — AND THE HALFWORD-ABS SHAPE NEEDS NO RITUAL L25385
+- **ADD-8** — → §30a addendum — THE THIRD COLUMN: `*p++` IS ALSO SERIALIZED BUT BURNS `addiu`; ONLY CAST-PLUS GIVES SERIALIZATION *AND* DISPLACEMENT FOLDING L25430
+- **ADDENDUM** — to §179-C — the `.type NAME, @function` requirement L25614
+- **ADDENDUM** — to §134 — a typedef defined BELOW the splice point is stripped anyway L25661
+- **ADDENDUM** — to §172b-1 — TWO PLACEMENT DIALS THE PROMOTION LAW DOESN'T NAME: NARROW THE COUNTER'S DECLARED TYPE, AND MOVE THE CAST INTO THE LOOP BODY L26074
+- **ADDENDUM** — to §172b-4 — THE PLAIN CAST-DIVISION ALREADY PRODUCES THE PATTERN; DON'T HAND-ROLL THE BIAS, AND KEEP THE OPERAND WIDE L26166
+- **§280** — THE CURSOR'S DECLARED TYPE PICKS `sltu` vs `slt`: a `T*` bound test is UNSIGNED by C rule, an integer cursor is signed (P31 S60; wave cf, func_800CAE74, md_MAIN_031, byte-proven) L26930
+- **§NNN** — A LOOP CURSOR'S C TYPE (POINTER vs PLAIN INTEGER) SELECTS `sltu` vs `slt` FOR ITS BOUND TEST, INDEPENDENT OF THE VALUES INVOLVED (P31 S60; `func_800CAE74`, md_MAIN_031, byte-proven; cross-confirmed same wave by `func_8017F2A4`, ov_SC03_096) L26931
+- **ADDENDUM** — to §21 — the `bltz`+`slti` (or N-separate-compares) signed-range-split bullet is now CONFIRMED on three independent functions, and generalizes beyond `lbu`/u8 L27131
+- **ADDENDUM** — to §202 — the DEF-SIDE ALIAS also resolves a function-vs-DATA-symbol identifier clash, not only a function-vs-function prototype clash L27177
+- **ADDENDUM** — §NNN — sharpens §162a3/§60b: A `sll $v0,16 / sltiu $v0,1` ZERO-TEST OF A JUST-DECREMENTED HALFWORD IS A SIGNED-TEMP WIDTH TELL OUTSIDE ANY SWITCH/RANGE-TEST CONTEXT L28267
+- **§288** — A REGISTER PIN DECLARED UNINITIALIZED AND ASSIGNED ONLY AT ITS LATE, SOLE USE STILL FORCES THE FIXED REGISTER'S SAVE/RESTORE, AND THE ASSIGNMENT'S SOURCE POSITION CONTROLS WHERE THE VALUE MATERIALIZES (P31; `func_80186530`, ov_SC02_017, byte-proven, match_one MATCH re-verified) (P31 S60; waves #, byte-proven) L29064
+- **§292** — DECLARING A SYMBOL UPSTREAM OF AN ALREADY-BANKED SIBLING THAT RELIES ON THAT SYMBOL'S IMPLICIT (K&R) DECLARATION CAN SILENTLY REPROTOTYPE THE SIBLING'S OWN CALL SITE (P31 S60; waves #, byte-proven) L29080
+- **ADDENDUM** — to §172b-1 (counter-type dial) — the sll's SOURCE REGISTER is the placement discriminator L29242
+- **ADDENDUM** — to §31's asm→layout inference — TWO WIDTH-PAIR DISCRIMINATORS (same offset, different widths) L29354
+- **§297** — ONE GIV SERVING MIXED-WIDTH LOADS *AND* A STORE NEEDS STRUCT-MEMBER SPELLING; CAST/INDEX SPELLINGS RE-SPLIT THE PSEUDO (P31 S61; wave m0a, `func_800347C8`, main, byte-proven 31/31) L29473
### declarations, prototypes & K&R (99)
@@ -489,93 +492,93 @@
- **§33** — Automating the giant decl-reconcile: `tools/reconcile_decls.py` (the DATA analog of §20's `cast_call_sites`) + a fleet-majority type oracle (Phase 24 T7b, byte-proven on `func_80129CF8`) L2434
- **§40a** — The DECL-RECONCILE pass (type-lift so remapped drafts compile in the sibling TU) (Phase 25 T7.2, 2026-07-08) L2601
- **§41** — The DEF-SIDE canonical-sig wall: mechanically banking a drafted giant past `conflicting types` (Phase 25 T5b batch-2, 2026-07-09; `tools/canon_sig_reconcile.py`, byte-proven on `func_8013B274`) L2710
-- **§41b** — addendum — M4 "reconcile_decls" tier is ALSO a probe over-count: 0/8 mechanical (Phase 25 T7-M4, 2026-07-10) L2858
-- **§41d** — `void`→`s32` is NOT always byte-neutral: gate the RAW draft FIRST (Phase 26 session 6, byte-proven) L2878
-- **§43** — The K&R s16-param definition DISSOLVES the "narrow-param wall" for by-value register args (Phase 25 task A, Fable5 crack of the 369-ins giant `func_80166994` ×134, 2026-07-11) L3195
-- **§51g** — When the thing you are scanning has a GRAMMAR, parse the grammar (`tools/cdecl.py`) L3769
-- **§54** — `--fix-def-sig`: the member's CANONICAL DECLARATION is a build step too (tiny-IMM mega-pools, +4,801, Phase 29 T6, 2026-07-16) L4163
-- **§56** — Banking a hand-drafted GIANT into its exemplar TU: self-contained draft vs live-TU decls, 4 reconciliation tactics (`func_8013FAF8`, 312 ins ×138, Phase 29 T4, 2026-07-17) L4187
-- **§56b** — PROPAGATING an h_seq giant: the exemplar's externs MUST be fleet-canonical, not the draft's types L4232
-- **§57** — The SELF-decl normalize: the sibling's OWN caller declares the templated fn divergently (the third §17a-1 direction; `tools/normalize_self_decls.py`, func_801670E4 ×137, Phase 29, 2026-07-18) L4256
-- **§61** — Task 14: the gate ladder's missing stage is the ARITY pre-pass, and it is TU-side not draft-side (Phase 29, 2026-07-21) L4545
-- **§63** — The fresh-138 DEF-SIDE blocker: fix the HEADER decl, not the draft (`fix_header_decl.py`, Phase 29 SESSION-13, 2026-07-23) L4877
-- **§63** — UPDATE (Phase 29 SESSION-14) — `fix_header_decl`'s "SAFE" verdict is FLEET-BLIND; it MUST be R22-validated L5000
-- **§65c** — `rtu_match` MATCH → bank held 13/13 on self-decl, but broke on the FIRST callee-decl case L5081
-- **§65g** — Where the cheap levers STOP: the local-type and in-TU-self-decl classes did not yield L5139
-- **§66a** — The widest write in a pipeline is the one most likely to be UNDECLARED L5181
-- **§68** — A comment-only line halted the extern scan, and the skip label blamed the type cap (Phase 29 SESSION-18) L5524
-- **§73** — A def-side self-decl conflict has TWO axes: RETURN (fleet widen, T2) and PARAMS (casts at each use, T0). Diagnose which before paying for the expensive one (Phase 29 SESSION-19, `func_8014F3E8` + `func_8014D4C0`) L5783
-- **§75** — A propagation cap is usually a MINORITY-SPELLING SOURCE OVERLAY, not a wall: census the carried extern before believing the exclusion message (Phase 29 SESSION-19, `func_8014F3E8` ×4 → ×138) L5866
-- **§75b** — A body's preamble can carry `#define`s, not just `extern`s; extraction lifts only the externs (Phase 29 SESSION-19, `func_80165CA0` ×3 → fleet) L5948
-- **§75c** — Class-B's remedy is the FULL §17a-1 PAIR (decl **and** call-site cast); a decl-only fix moves the error and looks like a new wall (Phase 29 SESSION-19, `func_8012F14C`) L5997
-- **§76** — The allocno CLASS (local vs global) is the dominant regalloc lever, and C reaches it ONLY through declaration scope and variable reuse (Phase 29 SESSION-19, behemoth #3 `func_8017F510` 1,511 ins, 97 → MATCH, pin-free) L6028
-- **§79** — For a 0-callee giant, fingerprint by DATA symbols (§71 cannot fire); and the STACK-SLOT ORDER is a declaration-order oracle (Phase 29 SESSION-19, `func_8017BF14` 4,763 ins, cold start → 45/4763) L6220
-- **§3-NEW** — LEVER — the frame layout reads back the original declaration order L6240
-- **§3-1.** — The inlined-helper signature L6375
-- **§92** — Conforming a DECLARATION: pointer changes are caller-neutral, scalar-WIDTH changes are not (Phase 29 SESSION-21, `tools/conform_decls.py`) L6891
-- **§95** — `reconcile_tu` dropped the SIBLING declarators of a multi-symbol `extern` line (Phase 29 SESSION-21, `func_80176218`) L6983
-- **§96** — The same rewrite, one shape down: `reconcile_tu` matched statements to lines by TEXT, so every COMMENTED declaration was silently skipped (Phase 29 SESSION-22, `func_80176218` banked) L7018
-- **§98** — `conform_decls` had three defects, and only the third needed R22 to find (Phase 29 SESSION-22, `func_8014CF04`) L7113
-- **§99** — The narrow-param wall is a DEF-side problem with a ZERO-blast-radius fix: convert the definition to K&R (Phase 29 SESSION-22, `func_80175AB8` + `func_80175DA8`) L7167
-- **§102** — A PLUMBING verdict can MASK a DIFF; and K&R is not always a codegen change (Phase 29 SESSION-22, `func_8016EC0C`) L7272
-- **§103** — A FILE-scope `extern` in a shared overlay TU is a GLOBAL constraint on every LATER function; move the DECL, not the draft (Phase 29 T48/T51, `func_80135260` — the fleet-wide half) L7307
-- **§104** — Two silent-skip defects in one scan: match on MASKED text, emit from the ORIGINAL (Phase 29 T53, `gather_externs`) L7395
-- **§112** — A macro-scoped declaration only collides where the macro is INSTANTIATED (Phase 29 T67/T69, `audit_header_sigs.py`) L7730
-- **§113** — An ARITY blocker only exists if the macro CALLS the function; an address-taken use has no call site (Phase 29 T72) L7776
-- **§114** — The THIRD decl axis: a CALLEE the draft declares differently from the target TU (Phase 29 T76/T77) L7808
-- **§3-Do** — NOT "strip the duplicate typedef" — it breaks the extern that uses it L8037
-- **§121** — Synthesise externs for macro-DEFINED callees from the macro's own definition head (Phase 29 T95) L8061
-- **§3-The** — declaration surface (integration, not codegen) L8941
-- **§136f** — Two declaration sub-cases the reconcile lane surfaced (lane now 15/15 lifetime) L9186
-- **§138** — The propagation lanes: a gate refusal is a DECLARATION, and which lever you owe depends on blast radius L9415
-- **Reconciling** — a gate-refused draft: which way you edit depends on WHERE the TU's decl is L9565
-- **§141** — The §134 class is CLOSED: every line-shape decision now routes through `cdecl._mask` (P30 S39) L9740
-- **§143** — `cast_call_sites` read a RETURN STATEMENT as a prototype and deleted it. A 0/39 sweep became 18/39. (P30 S40) L9834
-- **§3-C.** — Inner-block declaration does NOT delay slot allocation — BYTE-REFUTED L10068
-- **§159** — THE DECLARATION AXIS: conform to byte-truth, and make every guard state its COVERAGE (P30 S47; ~10,930 sites across 8 axes, fleet byte-identical) L10828
-- **§168** — THE COUSIN TIER (P30 S49, 2026-08-12): h_seq's exact-hash brittleness, measured — and the similarity map above it L16224
-- **§176f** — THE DECLARATION FORM IS A MATCHING LEVER, SO RECONCILE TOWARD THE FORM THE MATCH NEEDS (P31 S52) L16922
-- **§183** — THE DECLARATION-RECONCILIATION PLAYBOOK (P31 S53, measured on 20 byte-verified drafts) L17961
-- **§193-H** — A pointer-derived base load `*(s32*)(p+K)` is uncacheable across ANY memory write or call (cse's third kill disjunct) — so the target emits one `lw` per store-separated RUN of spellings, and a run of stores sharing one `lw` is a C local you must declare L18807
-- **§193-I** — A DECLARED AGGREGATE LOCAL HAS AN 8-BYTE FRAME STRIDE — CEIL(size,8), NOT size. N ARRAYS THEREFORE COST 8·k MORE THAN ONE HAND-LAID STRUCT (k = how many of them have size mod 8 ≠ 0), AND THE TELL IS IDENTICAL INSTRUCTION COUNT WITH EVERY $sp DISPLACEMENT SHIFTED BY THE SAME CONSTANT. L18847
-- **§194-B** — A `addu $rA,$rB,$zero` copy feeding ≥2 `sh` stores is a SECOND, 16-BIT-DECLARED local — the width, not the clamp or the join liveness, is what keeps the copy (and func_80183094's pin + `"memory"` clobber are both provably inert) L19016
-- **§194-D** — Declared width of a computed-value local is a sched1 dial (count-neutral) — a replication + attribution correction of §165-17, NOT a new argument-register law L19117
-- **§195-A** — §167-08's "an $aN READ before the jal is scratch" has a byte-proven FALSE-NEGATIVE class: an argument that DIES at the call is allocated straight into $aN, so its only def is a plain load far above the jal and every intervening use reads $aN — there is no positive tell in either direction, only the two-arity A/B L19723
-- **§195-C** — A call-argument `%hi/%lo` pair sitting at the block head, far above its `jal`, is a load-delay-gap filler chosen by SOURCE STATEMENT ORDER — swap the two independent statements nearest the call; a single-use `void *p = &SYM;` call-arg temp is OUTPUT-inert against it (but NOT expand-stream-inert) L19836
-- **§195-D** — §195 — `masked_diff.mask_for` returns 0 for EVERY `j`/`jal` word, so an internal `j` destination is invisible to match_one, the permuter scorer AND every similarity tier: a control-flow semantic error (which calls execute) surfaces as a 1-instruction residual mislabelled `DELAY-SLOT / profile=schedule`, or as an outright false MATCH L19884
-- **§195-F** — fold-const.c:4825 canonicalises a `?:` whose THEN arm is zero (or constant against a non-constant ELSE) by inverting the condition and swapping the arms — so a ternary's written arm order is byte-inert there, and `c ? 0 : X` is unspellable: it always compiles as `!c ? X : 0` L20010
-- **§195-G** — §NEW — TWO ARMS CALLING THE SAME CALLEE MERGE INTO ONE `jal` UNLESS EACH ARM'S OWN CODE CONSUMES THE RESULT: the C dial that keeps two call sites apart is WHERE the consumer test lives, and the branch SENSE you spell it with is byte-inert (jump.c:1737 canonicalises it) L20062
-- **§195-H** — §165-27g — ON A FIXED-SYMBOL GLOBAL, `extern T D[];` + `D[0]` IS THE CSE RELOAD DIAL, AT ZERO ADDRESSING COST, AND THE ELEMENT COUNT IS INERT (§165-27's `T v[2]` CAVEAT IS A LOCAL-FRAME FACT AND DOES NOT TRANSFER) L20110
-- **§196** — PUT ON THE CARD WHAT THE TREE ALREADY KNOWS: the fleet's declaration consensus (P31 S54) L20512
-- **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` L20860
-- **§199-G** — At TWO case nodes the switch-vs-if oracle is not blind — but the tell is ALL tests positive + a trailing `j default`, NOT the first test's polarity L21033
-- **§200** — THE ALIAS IS THE UNIVERSAL DECLARATION ESCAPE: stop negotiating with the TU's spelling (P31 S55) L21099
-- **§201-A** — §150-B applies to `decl_prior`'s DEF row: for an overlay-window symbol the banked "definition" is usually another overlay's function, and the card ranks it ABOVE the destination TU L21158
-- **§201-D** — THE SIGNEDNESS OF A div/mod MAGIC IS DECIDED BY THE STATIC TYPE OF THE DIVIDEND TREE AFTER `get_narrower` STRIPS WIDENING CONVERSIONS — NEVER BY A PROVABLE RANGE. AN `& 0xFF` IS NOT A CONVERSION, SO IT NEVER FLIPS THE MAGIC; A DECLARED-UNSIGNED LOCAL *OR* A NARROWING CAST WRITTEN AT THE DIVIDE BOTH DO. L21321
-- **§202** — THE ALIAS CARRIES A DEFINITION, NOT JUST A DECLARATION: the DEF-SIDE-RETURN wall (P31 S56) L21449
-- **§204-C** — WHEN A LOCAL BUFFER'S ADDRESS IS PASSED TO A CALL, ITS SIZE IS A FACT ABOUT THE CALLEE'S BODY, NOT ABOUT THE CALL SITE: grep the callee's proven definition and count the stores through the pointer parameter before you declare the local L21705
-- **§204-E** — `decl_prior`'s `%hi/%lo` ARM HAS NEVER FIRED: the card's promised GLOBAL-TYPE row is 0 of 1,210 L21838
-- **§208** — TWO NAMED LOCALS FOR ONE RELOADED EXPRESSION BUY TWO ALLOCNOS — the naming granularity owns the REGISTER SPLIT, not just the load count (P31 S58) L22202
-- **§214** — THE BANKED TWIN MAY BE A MACRO, A DELETED `.s`, OR A SEMANTIC INVERSE — six ways a ≥0.9 similarity lies (P31 S58) L22514
-- **§216** — DISTINCT ADJACENT SCALARS vs ONE ARRAY: one `lui` per access is the tell, and the array decl is UNUSABLE (P31 S58) L22616
-- **§220** — THE PARAMETER ITSELF IS A REGALLOC DIAL: use it directly, prefer `s32` to `void*`, and place the save-copy AFTER the first call (P31 S58) L22738
-- **§224** — CROSS-JUMP: WRITE THE DUPLICATE, AND READ A SHARED DELAY SLOT AS THE MERGE SIGNATURE (P31 S58) L22898
-- **§236** — THE DECLARATION LAYER IS THE DOMINANT BANK-BLOCKER: NINE WAYS A BYTE-PERFECT BODY FAILS THE GATE (P31 S58b) L23386
-- **§243** — SPELL THE CSE BARRIER AS A REASSIGNED POINTER; AND THE `nop`-AFTER-EVERY-`lh` SIGNATURE (P31 S58b) L23680
-- **§250** — `%hi/%lo` vs `lw`: THE EXTERN'S ARRAY-vs-SCALAR SHAPE DECIDES ADDRESS MATERIALISATION (P31 S58b) L23932
-- **§214** — addendum (P31 S58b) — FOUR MORE WAYS A HIGH-SIMILARITY TWIN LIES L24347
-- **§226** — addendum (P31 S58b) — THE FRAME CATALOGUE: SEVEN MORE LEVERS, AND SLOT ORDER IS DECLARATION ORDER L24576
-- **§263** — A STOLEN DELAY SLOT WHOSE INSTRUCTION IS AN ARG-REGISTER COPY IS AN ARITY ERROR, NOT A SCHEDULE (P31 S59, byte-proven) L24886
-- **ADD-10** — → §237 addendum (arity-evidence paragraph) — AN `la` PAIR ABOVE THE PROLOGUE `sw $ra` IS AN OUTGOING-ARGUMENT MATERIALISATION L25184
-- **ADD-2** — → §236 addendum (item 1 corollary) — THE SILENT-SPLICE DECLARATION LADDER: WHERE THE TU HAS NO SPELLING, UNPROTOTYPED `()` BEATS THE FLEET VOTE L25326
-- **§272** — The `(void)`-decl + empty-call wall: K&R the DEFINITION, not just the decls (P31 S59) L25558
-- **ADDENDUM** — to §20 — a global declared as `T *` may itself BE the array base, not a pointer to dereference L25779
-- **ADDENDUM** — to §172b-1 — TWO PLACEMENT DIALS THE PROMOTION LAW DOESN'T NAME: NARROW THE COUNTER'S DECLARED TYPE, AND MOVE THE CAST INTO THE LOOP BODY L26059
-- **§280** — THE CURSOR'S DECLARED TYPE PICKS `sltu` vs `slt`: a `T*` bound test is UNSIGNED by C rule, an integer cursor is signed (P31 S60; wave cf, func_800CAE74, md_MAIN_031, byte-proven) L26915
-- **ADDENDUM** — to §202 — the DEF-SIDE ALIAS also resolves a function-vs-DATA-symbol identifier clash, not only a function-vs-function prototype clash L27162
-- **ADDENDUM** — §NNN — sharpens §37/§124 (unspecified-parameter-list family): DERIVE A CALLEE'S ARITY LOWER BOUND FROM ITS OWN `.s` STACK-ARGUMENT READS, NOT FROM ANY SINGLE CALL SITE L28285
-- **§288** — A REGISTER PIN DECLARED UNINITIALIZED AND ASSIGNED ONLY AT ITS LATE, SOLE USE STILL FORCES THE FIXED REGISTER'S SAVE/RESTORE, AND THE ASSIGNMENT'S SOURCE POSITION CONTROLS WHERE THE VALUE MATERIALIZES (P31; `func_80186530`, ov_SC02_017, byte-proven, match_one MATCH re-verified) (P31 S60; waves #, byte-proven) L29049
-- **§292** — DECLARING A SYMBOL UPSTREAM OF AN ALREADY-BANKED SIBLING THAT RELIES ON THAT SYMBOL'S IMPLICIT (K&R) DECLARATION CAN SILENTLY REPROTOTYPE THE SIBLING'S OWN CALL SITE (P31 S60; waves #, byte-proven) L29065
+- **§41b** — addendum — M4 "reconcile_decls" tier is ALSO a probe over-count: 0/8 mechanical (Phase 25 T7-M4, 2026-07-10) L2873
+- **§41d** — `void`→`s32` is NOT always byte-neutral: gate the RAW draft FIRST (Phase 26 session 6, byte-proven) L2893
+- **§43** — The K&R s16-param definition DISSOLVES the "narrow-param wall" for by-value register args (Phase 25 task A, Fable5 crack of the 369-ins giant `func_80166994` ×134, 2026-07-11) L3210
+- **§51g** — When the thing you are scanning has a GRAMMAR, parse the grammar (`tools/cdecl.py`) L3784
+- **§54** — `--fix-def-sig`: the member's CANONICAL DECLARATION is a build step too (tiny-IMM mega-pools, +4,801, Phase 29 T6, 2026-07-16) L4178
+- **§56** — Banking a hand-drafted GIANT into its exemplar TU: self-contained draft vs live-TU decls, 4 reconciliation tactics (`func_8013FAF8`, 312 ins ×138, Phase 29 T4, 2026-07-17) L4202
+- **§56b** — PROPAGATING an h_seq giant: the exemplar's externs MUST be fleet-canonical, not the draft's types L4247
+- **§57** — The SELF-decl normalize: the sibling's OWN caller declares the templated fn divergently (the third §17a-1 direction; `tools/normalize_self_decls.py`, func_801670E4 ×137, Phase 29, 2026-07-18) L4271
+- **§61** — Task 14: the gate ladder's missing stage is the ARITY pre-pass, and it is TU-side not draft-side (Phase 29, 2026-07-21) L4560
+- **§63** — The fresh-138 DEF-SIDE blocker: fix the HEADER decl, not the draft (`fix_header_decl.py`, Phase 29 SESSION-13, 2026-07-23) L4892
+- **§63** — UPDATE (Phase 29 SESSION-14) — `fix_header_decl`'s "SAFE" verdict is FLEET-BLIND; it MUST be R22-validated L5015
+- **§65c** — `rtu_match` MATCH → bank held 13/13 on self-decl, but broke on the FIRST callee-decl case L5096
+- **§65g** — Where the cheap levers STOP: the local-type and in-TU-self-decl classes did not yield L5154
+- **§66a** — The widest write in a pipeline is the one most likely to be UNDECLARED L5196
+- **§68** — A comment-only line halted the extern scan, and the skip label blamed the type cap (Phase 29 SESSION-18) L5539
+- **§73** — A def-side self-decl conflict has TWO axes: RETURN (fleet widen, T2) and PARAMS (casts at each use, T0). Diagnose which before paying for the expensive one (Phase 29 SESSION-19, `func_8014F3E8` + `func_8014D4C0`) L5798
+- **§75** — A propagation cap is usually a MINORITY-SPELLING SOURCE OVERLAY, not a wall: census the carried extern before believing the exclusion message (Phase 29 SESSION-19, `func_8014F3E8` ×4 → ×138) L5881
+- **§75b** — A body's preamble can carry `#define`s, not just `extern`s; extraction lifts only the externs (Phase 29 SESSION-19, `func_80165CA0` ×3 → fleet) L5963
+- **§75c** — Class-B's remedy is the FULL §17a-1 PAIR (decl **and** call-site cast); a decl-only fix moves the error and looks like a new wall (Phase 29 SESSION-19, `func_8012F14C`) L6012
+- **§76** — The allocno CLASS (local vs global) is the dominant regalloc lever, and C reaches it ONLY through declaration scope and variable reuse (Phase 29 SESSION-19, behemoth #3 `func_8017F510` 1,511 ins, 97 → MATCH, pin-free) L6043
+- **§79** — For a 0-callee giant, fingerprint by DATA symbols (§71 cannot fire); and the STACK-SLOT ORDER is a declaration-order oracle (Phase 29 SESSION-19, `func_8017BF14` 4,763 ins, cold start → 45/4763) L6235
+- **§3-NEW** — LEVER — the frame layout reads back the original declaration order L6255
+- **§3-1.** — The inlined-helper signature L6390
+- **§92** — Conforming a DECLARATION: pointer changes are caller-neutral, scalar-WIDTH changes are not (Phase 29 SESSION-21, `tools/conform_decls.py`) L6906
+- **§95** — `reconcile_tu` dropped the SIBLING declarators of a multi-symbol `extern` line (Phase 29 SESSION-21, `func_80176218`) L6998
+- **§96** — The same rewrite, one shape down: `reconcile_tu` matched statements to lines by TEXT, so every COMMENTED declaration was silently skipped (Phase 29 SESSION-22, `func_80176218` banked) L7033
+- **§98** — `conform_decls` had three defects, and only the third needed R22 to find (Phase 29 SESSION-22, `func_8014CF04`) L7128
+- **§99** — The narrow-param wall is a DEF-side problem with a ZERO-blast-radius fix: convert the definition to K&R (Phase 29 SESSION-22, `func_80175AB8` + `func_80175DA8`) L7182
+- **§102** — A PLUMBING verdict can MASK a DIFF; and K&R is not always a codegen change (Phase 29 SESSION-22, `func_8016EC0C`) L7287
+- **§103** — A FILE-scope `extern` in a shared overlay TU is a GLOBAL constraint on every LATER function; move the DECL, not the draft (Phase 29 T48/T51, `func_80135260` — the fleet-wide half) L7322
+- **§104** — Two silent-skip defects in one scan: match on MASKED text, emit from the ORIGINAL (Phase 29 T53, `gather_externs`) L7410
+- **§112** — A macro-scoped declaration only collides where the macro is INSTANTIATED (Phase 29 T67/T69, `audit_header_sigs.py`) L7745
+- **§113** — An ARITY blocker only exists if the macro CALLS the function; an address-taken use has no call site (Phase 29 T72) L7791
+- **§114** — The THIRD decl axis: a CALLEE the draft declares differently from the target TU (Phase 29 T76/T77) L7823
+- **§3-Do** — NOT "strip the duplicate typedef" — it breaks the extern that uses it L8052
+- **§121** — Synthesise externs for macro-DEFINED callees from the macro's own definition head (Phase 29 T95) L8076
+- **§3-The** — declaration surface (integration, not codegen) L8956
+- **§136f** — Two declaration sub-cases the reconcile lane surfaced (lane now 15/15 lifetime) L9201
+- **§138** — The propagation lanes: a gate refusal is a DECLARATION, and which lever you owe depends on blast radius L9430
+- **Reconciling** — a gate-refused draft: which way you edit depends on WHERE the TU's decl is L9580
+- **§141** — The §134 class is CLOSED: every line-shape decision now routes through `cdecl._mask` (P30 S39) L9755
+- **§143** — `cast_call_sites` read a RETURN STATEMENT as a prototype and deleted it. A 0/39 sweep became 18/39. (P30 S40) L9849
+- **§3-C.** — Inner-block declaration does NOT delay slot allocation — BYTE-REFUTED L10083
+- **§159** — THE DECLARATION AXIS: conform to byte-truth, and make every guard state its COVERAGE (P30 S47; ~10,930 sites across 8 axes, fleet byte-identical) L10843
+- **§168** — THE COUSIN TIER (P30 S49, 2026-08-12): h_seq's exact-hash brittleness, measured — and the similarity map above it L16239
+- **§176f** — THE DECLARATION FORM IS A MATCHING LEVER, SO RECONCILE TOWARD THE FORM THE MATCH NEEDS (P31 S52) L16937
+- **§183** — THE DECLARATION-RECONCILIATION PLAYBOOK (P31 S53, measured on 20 byte-verified drafts) L17976
+- **§193-H** — A pointer-derived base load `*(s32*)(p+K)` is uncacheable across ANY memory write or call (cse's third kill disjunct) — so the target emits one `lw` per store-separated RUN of spellings, and a run of stores sharing one `lw` is a C local you must declare L18822
+- **§193-I** — A DECLARED AGGREGATE LOCAL HAS AN 8-BYTE FRAME STRIDE — CEIL(size,8), NOT size. N ARRAYS THEREFORE COST 8·k MORE THAN ONE HAND-LAID STRUCT (k = how many of them have size mod 8 ≠ 0), AND THE TELL IS IDENTICAL INSTRUCTION COUNT WITH EVERY $sp DISPLACEMENT SHIFTED BY THE SAME CONSTANT. L18862
+- **§194-B** — A `addu $rA,$rB,$zero` copy feeding ≥2 `sh` stores is a SECOND, 16-BIT-DECLARED local — the width, not the clamp or the join liveness, is what keeps the copy (and func_80183094's pin + `"memory"` clobber are both provably inert) L19031
+- **§194-D** — Declared width of a computed-value local is a sched1 dial (count-neutral) — a replication + attribution correction of §165-17, NOT a new argument-register law L19132
+- **§195-A** — §167-08's "an $aN READ before the jal is scratch" has a byte-proven FALSE-NEGATIVE class: an argument that DIES at the call is allocated straight into $aN, so its only def is a plain load far above the jal and every intervening use reads $aN — there is no positive tell in either direction, only the two-arity A/B L19738
+- **§195-C** — A call-argument `%hi/%lo` pair sitting at the block head, far above its `jal`, is a load-delay-gap filler chosen by SOURCE STATEMENT ORDER — swap the two independent statements nearest the call; a single-use `void *p = &SYM;` call-arg temp is OUTPUT-inert against it (but NOT expand-stream-inert) L19851
+- **§195-D** — §195 — `masked_diff.mask_for` returns 0 for EVERY `j`/`jal` word, so an internal `j` destination is invisible to match_one, the permuter scorer AND every similarity tier: a control-flow semantic error (which calls execute) surfaces as a 1-instruction residual mislabelled `DELAY-SLOT / profile=schedule`, or as an outright false MATCH L19899
+- **§195-F** — fold-const.c:4825 canonicalises a `?:` whose THEN arm is zero (or constant against a non-constant ELSE) by inverting the condition and swapping the arms — so a ternary's written arm order is byte-inert there, and `c ? 0 : X` is unspellable: it always compiles as `!c ? X : 0` L20025
+- **§195-G** — §NEW — TWO ARMS CALLING THE SAME CALLEE MERGE INTO ONE `jal` UNLESS EACH ARM'S OWN CODE CONSUMES THE RESULT: the C dial that keeps two call sites apart is WHERE the consumer test lives, and the branch SENSE you spell it with is byte-inert (jump.c:1737 canonicalises it) L20077
+- **§195-H** — §165-27g — ON A FIXED-SYMBOL GLOBAL, `extern T D[];` + `D[0]` IS THE CSE RELOAD DIAL, AT ZERO ADDRESSING COST, AND THE ELEMENT COUNT IS INERT (§165-27's `T v[2]` CAVEAT IS A LOCAL-FRAME FACT AND DOES NOT TRANSFER) L20125
+- **§196** — PUT ON THE CARD WHAT THE TREE ALREADY KNOWS: the fleet's declaration consensus (P31 S54) L20527
+- **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` L20875
+- **§199-G** — At TWO case nodes the switch-vs-if oracle is not blind — but the tell is ALL tests positive + a trailing `j default`, NOT the first test's polarity L21048
+- **§200** — THE ALIAS IS THE UNIVERSAL DECLARATION ESCAPE: stop negotiating with the TU's spelling (P31 S55) L21114
+- **§201-A** — §150-B applies to `decl_prior`'s DEF row: for an overlay-window symbol the banked "definition" is usually another overlay's function, and the card ranks it ABOVE the destination TU L21173
+- **§201-D** — THE SIGNEDNESS OF A div/mod MAGIC IS DECIDED BY THE STATIC TYPE OF THE DIVIDEND TREE AFTER `get_narrower` STRIPS WIDENING CONVERSIONS — NEVER BY A PROVABLE RANGE. AN `& 0xFF` IS NOT A CONVERSION, SO IT NEVER FLIPS THE MAGIC; A DECLARED-UNSIGNED LOCAL *OR* A NARROWING CAST WRITTEN AT THE DIVIDE BOTH DO. L21336
+- **§202** — THE ALIAS CARRIES A DEFINITION, NOT JUST A DECLARATION: the DEF-SIDE-RETURN wall (P31 S56) L21464
+- **§204-C** — WHEN A LOCAL BUFFER'S ADDRESS IS PASSED TO A CALL, ITS SIZE IS A FACT ABOUT THE CALLEE'S BODY, NOT ABOUT THE CALL SITE: grep the callee's proven definition and count the stores through the pointer parameter before you declare the local L21720
+- **§204-E** — `decl_prior`'s `%hi/%lo` ARM HAS NEVER FIRED: the card's promised GLOBAL-TYPE row is 0 of 1,210 L21853
+- **§208** — TWO NAMED LOCALS FOR ONE RELOADED EXPRESSION BUY TWO ALLOCNOS — the naming granularity owns the REGISTER SPLIT, not just the load count (P31 S58) L22217
+- **§214** — THE BANKED TWIN MAY BE A MACRO, A DELETED `.s`, OR A SEMANTIC INVERSE — six ways a ≥0.9 similarity lies (P31 S58) L22529
+- **§216** — DISTINCT ADJACENT SCALARS vs ONE ARRAY: one `lui` per access is the tell, and the array decl is UNUSABLE (P31 S58) L22631
+- **§220** — THE PARAMETER ITSELF IS A REGALLOC DIAL: use it directly, prefer `s32` to `void*`, and place the save-copy AFTER the first call (P31 S58) L22753
+- **§224** — CROSS-JUMP: WRITE THE DUPLICATE, AND READ A SHARED DELAY SLOT AS THE MERGE SIGNATURE (P31 S58) L22913
+- **§236** — THE DECLARATION LAYER IS THE DOMINANT BANK-BLOCKER: NINE WAYS A BYTE-PERFECT BODY FAILS THE GATE (P31 S58b) L23401
+- **§243** — SPELL THE CSE BARRIER AS A REASSIGNED POINTER; AND THE `nop`-AFTER-EVERY-`lh` SIGNATURE (P31 S58b) L23695
+- **§250** — `%hi/%lo` vs `lw`: THE EXTERN'S ARRAY-vs-SCALAR SHAPE DECIDES ADDRESS MATERIALISATION (P31 S58b) L23947
+- **§214** — addendum (P31 S58b) — FOUR MORE WAYS A HIGH-SIMILARITY TWIN LIES L24362
+- **§226** — addendum (P31 S58b) — THE FRAME CATALOGUE: SEVEN MORE LEVERS, AND SLOT ORDER IS DECLARATION ORDER L24591
+- **§263** — A STOLEN DELAY SLOT WHOSE INSTRUCTION IS AN ARG-REGISTER COPY IS AN ARITY ERROR, NOT A SCHEDULE (P31 S59, byte-proven) L24901
+- **ADD-10** — → §237 addendum (arity-evidence paragraph) — AN `la` PAIR ABOVE THE PROLOGUE `sw $ra` IS AN OUTGOING-ARGUMENT MATERIALISATION L25199
+- **ADD-2** — → §236 addendum (item 1 corollary) — THE SILENT-SPLICE DECLARATION LADDER: WHERE THE TU HAS NO SPELLING, UNPROTOTYPED `()` BEATS THE FLEET VOTE L25341
+- **§272** — The `(void)`-decl + empty-call wall: K&R the DEFINITION, not just the decls (P31 S59) L25573
+- **ADDENDUM** — to §20 — a global declared as `T *` may itself BE the array base, not a pointer to dereference L25794
+- **ADDENDUM** — to §172b-1 — TWO PLACEMENT DIALS THE PROMOTION LAW DOESN'T NAME: NARROW THE COUNTER'S DECLARED TYPE, AND MOVE THE CAST INTO THE LOOP BODY L26074
+- **§280** — THE CURSOR'S DECLARED TYPE PICKS `sltu` vs `slt`: a `T*` bound test is UNSIGNED by C rule, an integer cursor is signed (P31 S60; wave cf, func_800CAE74, md_MAIN_031, byte-proven) L26930
+- **ADDENDUM** — to §202 — the DEF-SIDE ALIAS also resolves a function-vs-DATA-symbol identifier clash, not only a function-vs-function prototype clash L27177
+- **ADDENDUM** — §NNN — sharpens §37/§124 (unspecified-parameter-list family): DERIVE A CALLEE'S ARITY LOWER BOUND FROM ITS OWN `.s` STACK-ARGUMENT READS, NOT FROM ANY SINGLE CALL SITE L28300
+- **§288** — A REGISTER PIN DECLARED UNINITIALIZED AND ASSIGNED ONLY AT ITS LATE, SOLE USE STILL FORCES THE FIXED REGISTER'S SAVE/RESTORE, AND THE ASSIGNMENT'S SOURCE POSITION CONTROLS WHERE THE VALUE MATERIALIZES (P31; `func_80186530`, ov_SC02_017, byte-proven, match_one MATCH re-verified) (P31 S60; waves #, byte-proven) L29064
+- **§292** — DECLARING A SYMBOL UPSTREAM OF AN ALREADY-BANKED SIBLING THAT RELIES ON THAT SYMBOL'S IMPLICIT (K&R) DECLARATION CAN SILENTLY REPROTOTYPE THE SIBLING'S OWN CALL SITE (P31 S60; waves #, byte-proven) L29080
### jump tables & switches (46)
@@ -585,46 +588,46 @@
- **§8b** — MULTI-jtbl per overlay — the `ld_interleave --order` sandwich + the same-subseg cases (Phase 26 session 4) L404
- **§8e** — The jtbl ALIGNMENT LAW + the pad-spec filter — multi-table .rodata spans (Phase 29, byte-proven; `.run/probe_jtbl/verdict.md`) L530
- **§3-The** — clean object-level metric (use this, not the permuter score, for jtbl/rodata functions) L844
-- **§41b** — T7 execution: the object-only probe OVER-counts BANKABLE by two link/rodata classes (Phase 25 T7-M1, 2026-07-10) L2809
-- **§48** — The 12-core jr crack wave: the ALLOCNO-PRICING dials and the EBB rule (Phase 26 session 8, Ultracode, 9/12 MATCH first pass) L3405
-- **§53** — SWEEP A FAMILY WITH THE TOOL ITS EXEMPLAR NEEDED: the jr/switch carve, and how omitting it manufactured the "families don't template" doctrine (Phase 28 T1, 2026-07-15) L4028
-- **§61b** — The jtbl gate stage: built, and the ORDERING law it exposed (Phase 29 Task-14 stage 4, 2026-07-21) L4658
-- **§61c** — The jtbl bank is INCREMENTALLY valid and CLEAN-INVALID (Phase 29, 2026-07-21) — the blocking finding L4713
-- **§62** — The jtbl RECONCILE must also follow the carve: the post-carve draft reconcile (`harvest_verify._jtbl_reconcile`, Phase 29 SESSION-11, 2026-07-22) L4833
-- **§81** — Banking a jr (jump-table) function: the 3-step carve chain, and why `match_one` cannot see the problem (Phase 29 SESSION-19, `func_8017C954`) L6323
-- **§88d** — BANKING ORDER: run the §81 carve chain BEFORE banking, never after L6701
-- **§97** — The gate's own tree hygiene: a refused carve, an unchecked recovery, and a snapshot that captured a dirty tree (Phase 29 SESSION-22) L7066
-- **§105** — A gate's revert must survive an EXCEPTION, not just a failure (Phase 29 T53, `jtbl_family_bank`) L7431
-- **§125** — Split the CARVE from the BODY before calling a jr residue a wall — and measure it by SHA from a CLEAN tree (P30 SESSION-28; **this section's first draft was WRONG and the method caught it**) L8206
-- **§126** — The carve-within-a-carve: an ADDRESS RANGE is not an OPTIMIZATION REGION (P30 T2, byte-proven end-to-end) L8264
-- **§129** — Post-carve, `rtu_match`/`match_one` COUNT THE JUMP TABLE AS INSTRUCTIONS; and a carve must never be committed without its owner (P30 S28, `func_8013BD74`) L8437
-- **§129a** — the target instruction count is INFLATED after a carve L8441
-- **§129b** — never commit a carve whose owner is still a stub (it strands the carve) L8462
-- **§130** — An INCREMENTAL build can report BYTE-IDENTICAL for a change the CLEAN build cannot even LINK (P30 S28, the jr pair) L8486
-- **§131** — The jtbl OVER-SPAN: `sltiu N` is ground truth in BOTH directions, and the zero-word rule only guards one (P30 S28, `func_80191C50`) L8533
-- **§132** — The `JR-PAIR-IN-ONE-O0-OBJECT` "wall" was TWO instrument defects: a merged-double span the carve could not see, and a truncated object no rule deleted (P30 S29, `func_8013B83C` + `func_8013BD74`) L8570
-- **§132b** — When the span's already-matched owner is ITSELF multi-switch: `--span-rel` (P30 S1, `func_8014032C`) L8660
-- **§139** — A GATE THAT GREPS FOR VERDICTS MUST ASSERT 1:1 ACCOUNTING; and a `--src` filter must not survive a carve (P30 S38, wave 6: 10 of 16 drafts vanished) L9594
-- **§161** — THE RETRY-WAVE HARVEST: a jump table indexed from zero, and two allocator traps (P30 S47) L10969
-- **§179-F** — PINNING A LOOP-WALKED POINTER IS A TOTAL OFF-SWITCH FOR STRENGTH REDUCTION L17532
-- **§188** — 🔴 THE `jr $ra` + `addiu $sp` TAIL IS AN **ASSEMBLER** ARTIFACT, NOT A FRAME SHAPE L18176
-- **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` L20860
-- **§199-G** — At TWO case nodes the switch-vs-if oracle is not blind — but the tell is ALL tests positive + a trailing `j default`, NOT the first test's polarity L21033
-- **§206** — THE JTBL-CARVE DRAFTING IDIOM: the bounds check is the entry count, and an EMPTY case owns a slot (P31 S56) L22112
-- **§222** — SWITCH vs IF-CHAIN, PART 3: source arm order IS emission order, a leading EMPTY case buys the median split, and a 2-way dispatch with a shared post-block is a `switch` (P31 S58) L22794
-- **§232** — WHEN THE `jr` DELAY SLOT'S STORE STORES THE RETURN VALUE, TIE THEM WITH ONE PSEUDO **(single observation — not yet cross-confirmed)** (P31 S58) L23180
-- **§256** — GOTOS IN THE TARGET'S BLOCK ORDER REPRODUCE SWITCH PLACEMENT WITHOUT SWITCH'S SIDE EFFECTS (P31 S58b) L24073
-- **§222** — addendum (P31 S58b) — IF-CHAIN vs SWITCH: THREE MORE DISCRIMINATORS L24477
-- **§260-A** — STAGE 2 IS PROVEN, AND THE WHOLE jtbl PIPELINE IS AUTOMATED AT THE GATE (P31 S59, same day) L24772
-- **ADDENDUM** — to §8 — WHEN `INCLUDE_RODATA` NEEDS A STANDALONE `.s` YOU CAN'T CREATE, CARRY THE FRAGMENT AS A FILE-SCOPE `__asm__` BLOB L26181
-- **ADDENDUM** — §NNN — sharpens §55a / §164-37 / §165-28 (switch-vs-tree cluster): A SHAPE THAT LOOKS LIKE A SWITCH DISPATCH CAN BE PLAIN NESTED `if`s WHOSE SHARED BODY WAS TRIPLICATED BY THE SOURCE AND THEN CROSS-JUMP-MERGED BACK DOWN L28182
-- **ADDENDUM** — §NNN — sharpens §162a3/§60b: A `sll $v0,16 / sltiu $v0,1` ZERO-TEST OF A JUST-DECREMENTED HALFWORD IS A SIGNED-TEMP WIDTH TELL OUTSIDE ANY SWITCH/RANGE-TEST CONTEXT L28252
-- **§295** — THE KERNEL-TRAP STUB: §81's jr-DETECTOR WITHOUT A TABLE IS A PsyQ SYSCALL TRAMPOLINE — ROUTE TO §265, NEVER INTO THE CARVE CHAIN (P31 S61; wave m0a, 9 cards byte-proven; resolves §182's held cluster) L29360
-- **§298** — THE SHARED-TAIL POSITION DIAGNOSTIC: A FOLDED TAIL *BETWEEN* SWITCH ARMS MEANS PER-ARM DUPLICATED STATEMENTS, NOT A HOISTED POST-SWITCH STATEMENT (P31 S61; waves g0e/g0f, `func_80181B68`, ov_SC06_016, byte-proven 68/68) L29501
-- **§302** — A RED BINARY IS A DRIFTED SPEC, NOT A MYSTERY: THE THREE CARVE-STATE INVARIANTS AND HOW TO DERIVE EACH FROM THE BYTES (P31 S62 T2; five reds healed in one session, 5/5, +39 held banks) L29678
-- **§304** — SELF-DEFINING RODATA: WHEN A FUNCTION'S `.s` IS THE ONLY OWNER OF THE DATA IT REFERENCES, THE C BODY MUST DEFINE IT (P31 S62 T3; byte-proven md_MAIN_011/func_800D04F4) L29758
-- **§305** — "CARVE-REFUSED" AT GATE TIME IS THREE NAMED, DETERMINISTIC CLASSES — NONE OF THEM A CARVE (P31 S62 T3; 28 resolver drafts autopsied 28/28) L29781
-- **§308a** — A TWO-INSTRUCTION ARM STUB LAID *BEFORE* THE OTHER ARM AND REACHED ONLY BY A TRAILING `j` SURVIVES ONLY BEHIND A SHORT-CIRCUIT `&&` GUARD PLUS A SEPARATE RE-TEST; EVERY PLAIN if/else-if, GOTO-LADDER, NESTED-INVERTED-if AND 1-/2-NODE switch LETS jump1 INLINE IT (−2 ins) (P31 S63 t5e-t5i; byte-proven func_80180808) L29971
+- **§41b** — T7 execution: the object-only probe OVER-counts BANKABLE by two link/rodata classes (Phase 25 T7-M1, 2026-07-10) L2824
+- **§48** — The 12-core jr crack wave: the ALLOCNO-PRICING dials and the EBB rule (Phase 26 session 8, Ultracode, 9/12 MATCH first pass) L3420
+- **§53** — SWEEP A FAMILY WITH THE TOOL ITS EXEMPLAR NEEDED: the jr/switch carve, and how omitting it manufactured the "families don't template" doctrine (Phase 28 T1, 2026-07-15) L4043
+- **§61b** — The jtbl gate stage: built, and the ORDERING law it exposed (Phase 29 Task-14 stage 4, 2026-07-21) L4673
+- **§61c** — The jtbl bank is INCREMENTALLY valid and CLEAN-INVALID (Phase 29, 2026-07-21) — the blocking finding L4728
+- **§62** — The jtbl RECONCILE must also follow the carve: the post-carve draft reconcile (`harvest_verify._jtbl_reconcile`, Phase 29 SESSION-11, 2026-07-22) L4848
+- **§81** — Banking a jr (jump-table) function: the 3-step carve chain, and why `match_one` cannot see the problem (Phase 29 SESSION-19, `func_8017C954`) L6338
+- **§88d** — BANKING ORDER: run the §81 carve chain BEFORE banking, never after L6716
+- **§97** — The gate's own tree hygiene: a refused carve, an unchecked recovery, and a snapshot that captured a dirty tree (Phase 29 SESSION-22) L7081
+- **§105** — A gate's revert must survive an EXCEPTION, not just a failure (Phase 29 T53, `jtbl_family_bank`) L7446
+- **§125** — Split the CARVE from the BODY before calling a jr residue a wall — and measure it by SHA from a CLEAN tree (P30 SESSION-28; **this section's first draft was WRONG and the method caught it**) L8221
+- **§126** — The carve-within-a-carve: an ADDRESS RANGE is not an OPTIMIZATION REGION (P30 T2, byte-proven end-to-end) L8279
+- **§129** — Post-carve, `rtu_match`/`match_one` COUNT THE JUMP TABLE AS INSTRUCTIONS; and a carve must never be committed without its owner (P30 S28, `func_8013BD74`) L8452
+- **§129a** — the target instruction count is INFLATED after a carve L8456
+- **§129b** — never commit a carve whose owner is still a stub (it strands the carve) L8477
+- **§130** — An INCREMENTAL build can report BYTE-IDENTICAL for a change the CLEAN build cannot even LINK (P30 S28, the jr pair) L8501
+- **§131** — The jtbl OVER-SPAN: `sltiu N` is ground truth in BOTH directions, and the zero-word rule only guards one (P30 S28, `func_80191C50`) L8548
+- **§132** — The `JR-PAIR-IN-ONE-O0-OBJECT` "wall" was TWO instrument defects: a merged-double span the carve could not see, and a truncated object no rule deleted (P30 S29, `func_8013B83C` + `func_8013BD74`) L8585
+- **§132b** — When the span's already-matched owner is ITSELF multi-switch: `--span-rel` (P30 S1, `func_8014032C`) L8675
+- **§139** — A GATE THAT GREPS FOR VERDICTS MUST ASSERT 1:1 ACCOUNTING; and a `--src` filter must not survive a carve (P30 S38, wave 6: 10 of 16 drafts vanished) L9609
+- **§161** — THE RETRY-WAVE HARVEST: a jump table indexed from zero, and two allocator traps (P30 S47) L10984
+- **§179-F** — PINNING A LOOP-WALKED POINTER IS A TOTAL OFF-SWITCH FOR STRENGTH REDUCTION L17547
+- **§188** — 🔴 THE `jr $ra` + `addiu $sp` TAIL IS AN **ASSEMBLER** ARTIFACT, NOT A FRAME SHAPE L18191
+- **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` L20875
+- **§199-G** — At TWO case nodes the switch-vs-if oracle is not blind — but the tell is ALL tests positive + a trailing `j default`, NOT the first test's polarity L21048
+- **§206** — THE JTBL-CARVE DRAFTING IDIOM: the bounds check is the entry count, and an EMPTY case owns a slot (P31 S56) L22127
+- **§222** — SWITCH vs IF-CHAIN, PART 3: source arm order IS emission order, a leading EMPTY case buys the median split, and a 2-way dispatch with a shared post-block is a `switch` (P31 S58) L22809
+- **§232** — WHEN THE `jr` DELAY SLOT'S STORE STORES THE RETURN VALUE, TIE THEM WITH ONE PSEUDO **(single observation — not yet cross-confirmed)** (P31 S58) L23195
+- **§256** — GOTOS IN THE TARGET'S BLOCK ORDER REPRODUCE SWITCH PLACEMENT WITHOUT SWITCH'S SIDE EFFECTS (P31 S58b) L24088
+- **§222** — addendum (P31 S58b) — IF-CHAIN vs SWITCH: THREE MORE DISCRIMINATORS L24492
+- **§260-A** — STAGE 2 IS PROVEN, AND THE WHOLE jtbl PIPELINE IS AUTOMATED AT THE GATE (P31 S59, same day) L24787
+- **ADDENDUM** — to §8 — WHEN `INCLUDE_RODATA` NEEDS A STANDALONE `.s` YOU CAN'T CREATE, CARRY THE FRAGMENT AS A FILE-SCOPE `__asm__` BLOB L26196
+- **ADDENDUM** — §NNN — sharpens §55a / §164-37 / §165-28 (switch-vs-tree cluster): A SHAPE THAT LOOKS LIKE A SWITCH DISPATCH CAN BE PLAIN NESTED `if`s WHOSE SHARED BODY WAS TRIPLICATED BY THE SOURCE AND THEN CROSS-JUMP-MERGED BACK DOWN L28197
+- **ADDENDUM** — §NNN — sharpens §162a3/§60b: A `sll $v0,16 / sltiu $v0,1` ZERO-TEST OF A JUST-DECREMENTED HALFWORD IS A SIGNED-TEMP WIDTH TELL OUTSIDE ANY SWITCH/RANGE-TEST CONTEXT L28267
+- **§295** — THE KERNEL-TRAP STUB: §81's jr-DETECTOR WITHOUT A TABLE IS A PsyQ SYSCALL TRAMPOLINE — ROUTE TO §265, NEVER INTO THE CARVE CHAIN (P31 S61; wave m0a, 9 cards byte-proven; resolves §182's held cluster) L29375
+- **§298** — THE SHARED-TAIL POSITION DIAGNOSTIC: A FOLDED TAIL *BETWEEN* SWITCH ARMS MEANS PER-ARM DUPLICATED STATEMENTS, NOT A HOISTED POST-SWITCH STATEMENT (P31 S61; waves g0e/g0f, `func_80181B68`, ov_SC06_016, byte-proven 68/68) L29516
+- **§302** — A RED BINARY IS A DRIFTED SPEC, NOT A MYSTERY: THE THREE CARVE-STATE INVARIANTS AND HOW TO DERIVE EACH FROM THE BYTES (P31 S62 T2; five reds healed in one session, 5/5, +39 held banks) L29693
+- **§304** — SELF-DEFINING RODATA: WHEN A FUNCTION'S `.s` IS THE ONLY OWNER OF THE DATA IT REFERENCES, THE C BODY MUST DEFINE IT (P31 S62 T3; byte-proven md_MAIN_011/func_800D04F4) L29773
+- **§305** — "CARVE-REFUSED" AT GATE TIME IS THREE NAMED, DETERMINISTIC CLASSES — NONE OF THEM A CARVE (P31 S62 T3; 28 resolver drafts autopsied 28/28) L29796
+- **§308a** — A TWO-INSTRUCTION ARM STUB LAID *BEFORE* THE OTHER ARM AND REACHED ONLY BY A TRAILING `j` SURVIVES ONLY BEHIND A SHORT-CIRCUIT `&&` GUARD PLUS A SEPARATE RE-TEST; EVERY PLAIN if/else-if, GOTO-LADDER, NESTED-INVERTED-if AND 1-/2-NODE switch LETS jump1 INLINE IT (−2 ins) (P31 S63 t5e-t5i; byte-proven func_80180808) L29986
### optimisation level (-O0/-O2) (18)
@@ -634,18 +637,18 @@
- **§18** — Per-file `-O0` split inside an overlay/blob (Phase 19 T1) L1519
- **§38** — The WHALE `func_80144B9C` (770 ins): the -O0 struct-assign memcpy idiom + the -O0 reach-134 ×134 rollout (Phase 24 T7 §G, cheap Opus — no Fable5, no calls.c) L2527
- **§39** — The ×1→×134 giant-endgame: propagate a matched **-O2** giant via the NATIVE DEFINE-macro path (Phase 24 T7 §G close, 2026-07-08) L2537
-- **§116** — Optimization level is a property of the FILE, not the function: read a family 0/N against the member's stub HOME (Phase 29 T79) L7877
-- **§3-The** — finding: opt level is per FILE, so the file's contents must be opt-HOMOGENEOUS L8279
-- **§127** — The `-O0` regime: the CONSTANT-OFFSET FOLD, and why `-O0` needs its own idiom set (P30 T3 wave, 15 targets) L8349
-- **§3-The** — rest of the `-O0` regime (write PLAIN C, and mean it) L8367
-- **§127a** — §71 (sibling-first) is the strongest `-O0` lever, and it beats the index L8377
-- **§132** — The `JR-PAIR-IN-ONE-O0-OBJECT` "wall" was TWO instrument defects: a merged-double span the carve could not see, and a truncated object no rule deleted (P30 S29, `func_8013B83C` + `func_8013BD74`) L8570
-- **§195-K** — At -O2 the §18 array-of-struct lever is a FRAME lever, not a length lever — but only when the N reads carry DISTINCT index expressions; with a SHARED index §18's +2-instruction residual is still alive at -O2 (the submitted "memory-loaded narrow index" precondition and unconditional length-neutrality are both falsified) L20266
-- **§261** — THE -O0 ORACLE: DERIVE THE OPT LEVEL FROM THE TARGET, AND `$fp` IS NOT THE TELL (P31 S59) L24808
-- **§261a** — THE -O0 FRAME-RELOAD GRAMMAR: reload COUNT disambiguates the C spelling (P31 S59, byte-proven) L24834
-- **§265** — THE VERBATIM-ASM BANK LANE: A FUNCTION NO -O2 C CAN EVER MATCH BANKS AS A RAW `__asm__` BODY (P31 S59b; two banked cards, two in-tree precedents) L24977
-- **ADDENDUM** — to §127 — the -O0 constant-offset fold keys on the MEMBER-ACCESS tree shape, not on the index being constant L29129
-- **ADDENDUM** — to §261a — FOUR MORE -O0 DIALS BEYOND THE RELOAD COUNT (boot.c + md_MAIN_011/003, wave m0a/g0a/g0f, byte-proven) L29157
+- **§116** — Optimization level is a property of the FILE, not the function: read a family 0/N against the member's stub HOME (Phase 29 T79) L7892
+- **§3-The** — finding: opt level is per FILE, so the file's contents must be opt-HOMOGENEOUS L8294
+- **§127** — The `-O0` regime: the CONSTANT-OFFSET FOLD, and why `-O0` needs its own idiom set (P30 T3 wave, 15 targets) L8364
+- **§3-The** — rest of the `-O0` regime (write PLAIN C, and mean it) L8382
+- **§127a** — §71 (sibling-first) is the strongest `-O0` lever, and it beats the index L8392
+- **§132** — The `JR-PAIR-IN-ONE-O0-OBJECT` "wall" was TWO instrument defects: a merged-double span the carve could not see, and a truncated object no rule deleted (P30 S29, `func_8013B83C` + `func_8013BD74`) L8585
+- **§195-K** — At -O2 the §18 array-of-struct lever is a FRAME lever, not a length lever — but only when the N reads carry DISTINCT index expressions; with a SHARED index §18's +2-instruction residual is still alive at -O2 (the submitted "memory-loaded narrow index" precondition and unconditional length-neutrality are both falsified) L20281
+- **§261** — THE -O0 ORACLE: DERIVE THE OPT LEVEL FROM THE TARGET, AND `$fp` IS NOT THE TELL (P31 S59) L24823
+- **§261a** — THE -O0 FRAME-RELOAD GRAMMAR: reload COUNT disambiguates the C spelling (P31 S59, byte-proven) L24849
+- **§265** — THE VERBATIM-ASM BANK LANE: A FUNCTION NO -O2 C CAN EVER MATCH BANKS AS A RAW `__asm__` BODY (P31 S59b; two banked cards, two in-tree precedents) L24992
+- **ADDENDUM** — to §127 — the -O0 constant-offset fold keys on the MEMBER-ACCESS tree shape, not on the index being constant L29144
+- **ADDENDUM** — to §261a — FOUR MORE -O0 DIALS BEYOND THE RELOAD COUNT (boot.c + md_MAIN_011/003, wave m0a/g0a/g0f, byte-proven) L29172
### family propagation & sweeps (109)
@@ -672,92 +675,92 @@
- **§40a** — The DECL-RECONCILE pass (type-lift so remapped drafts compile in the sibling TU) (Phase 25 T7.2, 2026-07-08) L2601
- **§40b** — The reloc-tracker blind spot: the indexed-global idiom that hid the "reach-1 tail" (Phase 26 Task 1, 2026-07-11, byte-verified V0/V1) L2634
- **§40c** — The h_seq per-sibling reconcile: templating a reconcile-class crack ×134 (Phase 26 Task 8, 2026-07-12, byte-proven) L2676
-- **§41c** — T7-M2: the ×134 def-side-wall sweep via per-sibling RE-reconcile (Phase 25, 2026-07-10; 4,389 banks, ~0 agent tokens) L2839
-- **§42** — The F-band ≤28 regalloc crack wave: register-pin/DENSITY levers beat the permuter (Phase 25 T7 F-band, 2026-07-10; Ultracode 9-worker wave, 4/9 banked byte-identical, 266 swept ×134) L2900
-- **§42e** — propagating a CRACK ×134: the def-finder bug + the byte-drift residual (the "remap-fail" misdiagnosis) L3121
-- **§43** — The K&R s16-param definition DISSOLVES the "narrow-param wall" for by-value register args (Phase 25 task A, Fable5 crack of the 369-ins giant `func_80166994` ×134, 2026-07-11) L3195
-- **§45** — The flagship `func_80133CD4` crack (399 ins ×134): the merged-variable permutation-breaker + the 1-death local-alloc gate (Phase 25 task A giant escalation, Fable5 gdb-on-cc1, 2026-07-11) L3298
-- **§46** — The `func_80178D40` crack (890 ins ×134, the heaviest core in the game): four LOOP-STRUCTURE levers cheap-Opus found by reading loop.c/jump.c/cse.c (Phase 26 session 8, 2026-07-13) L3313
-- **§47** — The live-length SLIDER: splitting a global.c allocno-priority TIE with one zero-byte asm (Phase 26 session 8, Fable5 Max, byte-proven on `func_8017BEBC` 952 ins ×113) L3365
-- **§49** — The LUID DIAL: a zero-byte SCHEDULING dial (the sched.c analogue of §47) — `func_8017A4AC` (536 ins ×134), Phase 26 session 8 L3527
-- **§52** — The WALKER-FAMILY skeleton: 6 regalloc-order levers + a deeply-characterized intrinsic wall (`func_80178004`, 165 ins ×134; Phase 26, Fable5, 2026-07-15) L3913
-- **§3-The** — 6 levers (the "walker-family skeleton" — apply to the 12 siblings; levers 1-5 retire ~half the residual) L3924
-- **§53** — SWEEP A FAMILY WITH THE TOOL ITS EXEMPLAR NEEDED: the jr/switch carve, and how omitting it manufactured the "families don't template" doctrine (Phase 28 T1, 2026-07-15) L4028
-- **§55c** — Sizing the propagate: a TARGETED propagate is ~4 min/core, and "it's slow" was a BROKEN-TREE ARTIFACT L4141
-- **§54** — `--fix-def-sig`: the member's CANONICAL DECLARATION is a build step too (tiny-IMM mega-pools, +4,801, Phase 29 T6, 2026-07-16) L4163
-- **§56** — Banking a hand-drafted GIANT into its exemplar TU: self-contained draft vs live-TU decls, 4 reconciliation tactics (`func_8013FAF8`, 312 ins ×138, Phase 29 T4, 2026-07-17) L4187
-- **§56b** — PROPAGATING an h_seq giant: the exemplar's externs MUST be fleet-canonical, not the draft's types L4232
-- **§57** — The SELF-decl normalize: the sibling's OWN caller declares the templated fn divergently (the third §17a-1 direction; `tools/normalize_self_decls.py`, func_801670E4 ×137, Phase 29, 2026-07-18) L4256
-- **§57a** — Two NSD corrections + the SURGICAL-ONLY law + the honest broad-sweep yield (Phase 29, 2026-07-18) L4303
-- **§59** — Three h_seq sweep-residual classes match_one/the-exemplar-bank don't reveal (Phase 29 crack-wave close, 2026-07-18) L4377
-- **§3-Two** — corollaries worth remembering L4450
-- **§65a** — The blast-radius taxonomy (makes §61's law structural instead of remembered) L5030
-- **§3-Giv** — record order (the §70 family) L5760
-- **§75** — A propagation cap is usually a MINORITY-SPELLING SOURCE OVERLAY, not a wall: census the carried extern before believing the exclusion message (Phase 29 SESSION-19, `func_8014F3E8` ×4 → ×138) L5866
-- **§75a** — The exclusion classes, enumerated with named causes (Phase 29 SESSION-19, the 134-binary `dedup_extend` sweep) L5925
-- **§75b** — A body's preamble can carry `#define`s, not just `extern`s; extraction lifts only the externs (Phase 29 SESSION-19, `func_80165CA0` ×3 → fleet) L5948
-- **§76** — The allocno CLASS (local vs global) is the dominant regalloc lever, and C reaches it ONLY through declaration scope and variable reuse (Phase 29 SESSION-19, behemoth #3 `func_8017F510` 1,511 ins, 97 → MATCH, pin-free) L6028
-- **§77** — Every extraction tool carries a NARROW hard-coded preamble set; anything outside it silently caps the body's reach. Diff the preamble before you gate. (Phase 29 SESSION-19 — three variants in one session, two different tools) L6084
-- **§84** — The DERIVED-OFFSET remap bug: a hand-computed literal that encodes the DISTANCE between two per-overlay symbols, and why `match_one` is structurally blind to it (Phase 29 SESSION-20, `func_8013D53C`) L6472
-- **§86** — Pinned-exemplar templatability is a PER-FAMILY property, not a per-member rate; and the §42e pin guard is now over-conservative (Phase 29 SESSION-20) L6589
-- **§3-THE** — LAW: all-or-nothing PER FAMILY L6600
-- **§3-Why** — the two live families differ from the three dead ones — the open question L6627
-- **§3-The** — cheap discriminator, before spending a sweep L6666
-- **§89b** — the parallel gate farm existed; the family path could not reach it (`tools/sweep_parallel.py`) L6745
-- **§91** — A structure-TRANSFER is only valid where the structure corresponds: the `--like` role trap (Phase 29 SESSION-21, `func_8012AAAC` ×137) L6842
-- **§94** — A family sweep's `0/N` is a TYPE-CARRY failure until proven otherwise: lift the exemplar's local types, ALL of them, transitively (Phase 29 SESSION-21, `func_8016B6BC` 0/137 → 137/137) L6947
-- **§105** — A gate's revert must survive an EXCEPTION, not just a failure (Phase 29 T53, `jtbl_family_bank`) L7431
-- **§107** — A lever wired into ONE gate path is a lever most families cannot reach (Phase 29 T56, `func_80144090` 0/136 → 136/136) L7513
-- **§108** — Diagnosing a family `0/N`: the four causes, and the third opt-in lever (Phase 29 T59) L7551
-- **§111** — The distinct-code metric is not noisy: a family pays it only if its members are byte-VARIANT (Phase 29 T66) L7681
-- **§116** — Optimization level is a property of the FILE, not the function: read a family 0/N against the member's stub HOME (Phase 29 T79) L7877
-- **§123** — PROPAGATE A FAMILY WITH THE TOOL ITS TIER NEEDS: `dedup_propagate` is h_exact-only; its refusals are statements about the TOOL (P30 wave 1, 2026-07-30) L8116
-- **§124** — A "not matched" verdict can mean the definition is there under a DIFFERENT C NAME: the asm-label alias blind spot (P30 SESSION-28, `func_8016191C` ×137) L8153
-- **§124a** — a family sweep's `0 matched-exemplar families` may be a FILTER, not a wall L8198
-- **§134** — MULTI-LINE BLINDNESS: one root cause, four faces, in `family_remap`'s preamble scanner (P30 S6, 190 zero-crack families) L8711
-- **§136c** — SIBLING-FIRST is a DERIVATION shortcut, not just a conflict fix (the fastest route in a family wave) L9069
-- **§138** — The propagation lanes: a gate refusal is a DECLARATION, and which lever you owe depends on blast radius L9415
-- **§142** — An open stub whose `h_exact` class is MATCHED elsewhere is FREE. Propagate the body; do not gate a draft. (P30 S39, +7,710 ins in two commands) L9778
-- **§143** — `cast_call_sites` read a RETURN STATEMENT as a prototype and deleted it. A 0/39 sweep became 18/39. (P30 S40) L9834
-- **Then** — propagation returned 0/137 TWICE — both times a missing TYPE L10000
-- **§3-A.** — The frame has THREE strata, and stratum 3 is unreachable from C L10041
-- **§3-E.** — A `qty_compare` TIE is not spelling-reachable — recognise it and stop L10083
-- **Consequence** — for the family (a real scheduling decision) L10095
-- **§150** — A register ROTATION across symmetric blocks is VARIABLE-IDENTITY evidence, not an allocator tie (P30 S43, `func_8017C6F4`, 947 ins ×4) L10312
-- **§151** — THE GHOST WEDGE: when a load-before-store transposition is unreachable by ANY statement order (P30 S43, `func_8017EF68`, 969 ins) L10367
-- **When** — to reach for it L10407
-- **§152** — BYTE SIZE is the family key that name- and h_seq-grouping both miss (P30 S43, the 0xECC family: 1 crack → 12 overlays → 11,364 ins) L10418
-- **§156** — an ORPHANED reconcile poisons the fleet: `dedup_propagate`'s kept edit (S45 p6/p7) L10640
-- **§160** — THE REACH-15 WAVE HARVEST: an align-1 block move, and the instrument that called it a wall (P30 S47) L10893
-- **§162** — S48 WAVE-1 HARVEST (P30, 2026-08-11): the reach-ordered sibling campaign's first 12 targets L11014
-- **§163z** — THE UNVETTED REMAINDER (do not cite as law; each needs a dedupe pass) L11828
-- **§3-The** — ADDRESS-CLASS TABLE: which load/store pairs even REACH the `/s` clause (P30 S48 wave 4, `func_80185B44`, ov_SC03_014) L14355
-- **§168** — THE COUSIN TIER (P30 S49, 2026-08-12): h_seq's exact-hash brittleness, measured — and the similarity map above it L16224
-- **§171a** — THE MECHANICAL A-PROP DRAFT (P30 S50): 256 members banked with no agent in the loop L16433
-- **§171b** — THREE CARRIES THE MECHANICAL DRAFT NEEDS (P30 S50, banking the top-reach families) L16483
-- **§3-G.** — TWO MODELLING TRAPS THAT COST THESE AGENTS SWEEPS OF HUNDREDS OF COMPILES L17310
-- **§193-E** — A varying-address (pointer) load is re-emitted once per CSE-LIVE INTERVAL, and naming it in a C local is the only C-level lever over that count — no store SPELLING has any reach L18652
-- **§194-E** — The wave card's `exemplar` is the TARGET ITSELF on 42/73 wave-U and 36/71 wave-T cards — a construction consequence of `atlas.py:657` (exemplar = max-nins OPEN member) meeting `build_wave_atlas.py:166` (one card per gid); and the shipped §193-A `seed_ref` is same-binary on 0/51, so no card field can ever name a destination-TU sibling L19158
-- **§195-E** — A 0/1 materialised at a JOIN immediately before the controlling `beqz`/`bnez` proves the source NAMED the condition — a truth expression in an `if`'s controlling position reaches `do_jump`, which has no value path L19952
-- **§199-B** — A permutation sweep that holds ANY statement fixed is not a sweep: the statement an agent pins as "obviously load-bearing" is the one carrying the signal, and the partial sweep returns a FLAT residual that reads as proof of order-invariance L20767
-- **§203** — A DEDUPED TYPEDEF MUST PRECEDE EVERY SPLICE POINT, NOT JUST ITS OWN (P31 S56) L21486
-- **§225** — THREE CONTROL-FLOW SHAPES NO STRUCTURED SPELLING REACHES (P31 S58) L22934
-- **§30** — addendum (P31 S58b) — THE ANONYMOUS STRUCT MEMBER REF GRANTS `/s`, AND THAT IS A TWO-FOR-ONE L24158
-- **§3-1a.** — The §266 sweep — every solo-lever A/B run for this batch L25485
-- **ADDENDUM** — to §179-D (GTE macro reference family) — `gte_SetRotMatrix`/`gte_SetTransMatrix` bodies L25676
-- **ADDENDUM** — to §82 — struct copies must stay MEMBER-WISE, not block-moved, to match a spill-slot save L25702
-- **ADDENDUM** — to §136d-1 (RC-12, the `$0`-add / opaque-copy family) — two symptoms beyond "compare reads the wrong register" L25740
-- **§282** — gcc's OWN LOOP REVERSAL PUTS THE COUNTER INIT AFTER THE HOISTED MOVABLES — a position no hand-written down-count can reach (P31 S60; wave cf, func_80180DD8, ov_SC04_005, byte-proven) L26995
-- **ADDENDUM** — to the zero-byte-asm-slider family (§47 / §148-C / §153) (func_800CB874, md_MAIN_040 — wave dj; open tension with a more cautious dm-wave card — see closing) L27914
-- **ADDENDUM** — the zero-emission-asm family gains a REF-SLIDER PLACEMENT LAW and a paired RESTORER (func_800CB900, md_MAIN_026) L28124
-- **ADDENDUM** — §NNN — sharpens §37/§124 (unspecified-parameter-list family): DERIVE A CALLEE'S ARITY LOWER BOUND FROM ITS OWN `.s` STACK-ARGUMENT READS, NOT FROM ANY SINGLE CALL SITE L28285
-- **ADDENDUM** — to §199-F family (func_8017EFB0, ov_SC02_021, wave cu) L28437
-- **§287** — A STACK-FRAME HOLE BELOW TWO ADDRESS-TAKEN AGGREGATE LOCALS IS A LEADING PAD MEMBER OF ONE COMBINED STRUCT, NOT SEPARATE LOCALS OR A REGISTER PIN (P31 S60/dj; `func_8017D104`, ov_SC06_027, byte-proven 47/47) (P31 S60; waves #, byte-proven) L29045
-- **ADDENDUM** — to §127 — the -O0 constant-offset fold keys on the MEMBER-ACCESS tree shape, not on the index being constant L29129
-- **§296** — THE FRAME CHECK OUTRANKS THE ATLAS LEVER: READ PROLOGUE/EPILOGUE BEFORE DRAFTING ANY C — A REAL TELL CAN LIVE INSIDE AN UNREACHABLE FRAGMENT (P31 S61; wave m0a, 16 cards byte-proven; extends §179-C) L29415
-- **§297** — ONE GIV SERVING MIXED-WIDTH LOADS *AND* A STORE NEEDS STRUCT-MEMBER SPELLING; CAST/INDEX SPELLINGS RE-SPLIT THE PSEUDO (P31 S61; wave m0a, `func_800347C8`, main, byte-proven 31/31) L29458
-- **§307** — THE BRUTE-FORCE-THE-STATEMENT-ORDERS LEVER HAS A BOUND: A FAN-OUT COPY'S PRIORITY IS SCHEDULER-INTERNAL, AND NO SOURCE ORDER REACHES IT (P31 S63; byte-evidenced NEGATIVE result, main wave) L29898
-- **§308a** — A TWO-INSTRUCTION ARM STUB LAID *BEFORE* THE OTHER ARM AND REACHED ONLY BY A TRAILING `j` SURVIVES ONLY BEHIND A SHORT-CIRCUIT `&&` GUARD PLUS A SEPARATE RE-TEST; EVERY PLAIN if/else-if, GOTO-LADDER, NESTED-INVERTED-if AND 1-/2-NODE switch LETS jump1 INLINE IT (−2 ins) (P31 S63 t5e-t5i; byte-proven func_80180808) L29971
+- **§41c** — T7-M2: the ×134 def-side-wall sweep via per-sibling RE-reconcile (Phase 25, 2026-07-10; 4,389 banks, ~0 agent tokens) L2854
+- **§42** — The F-band ≤28 regalloc crack wave: register-pin/DENSITY levers beat the permuter (Phase 25 T7 F-band, 2026-07-10; Ultracode 9-worker wave, 4/9 banked byte-identical, 266 swept ×134) L2915
+- **§42e** — propagating a CRACK ×134: the def-finder bug + the byte-drift residual (the "remap-fail" misdiagnosis) L3136
+- **§43** — The K&R s16-param definition DISSOLVES the "narrow-param wall" for by-value register args (Phase 25 task A, Fable5 crack of the 369-ins giant `func_80166994` ×134, 2026-07-11) L3210
+- **§45** — The flagship `func_80133CD4` crack (399 ins ×134): the merged-variable permutation-breaker + the 1-death local-alloc gate (Phase 25 task A giant escalation, Fable5 gdb-on-cc1, 2026-07-11) L3313
+- **§46** — The `func_80178D40` crack (890 ins ×134, the heaviest core in the game): four LOOP-STRUCTURE levers cheap-Opus found by reading loop.c/jump.c/cse.c (Phase 26 session 8, 2026-07-13) L3328
+- **§47** — The live-length SLIDER: splitting a global.c allocno-priority TIE with one zero-byte asm (Phase 26 session 8, Fable5 Max, byte-proven on `func_8017BEBC` 952 ins ×113) L3380
+- **§49** — The LUID DIAL: a zero-byte SCHEDULING dial (the sched.c analogue of §47) — `func_8017A4AC` (536 ins ×134), Phase 26 session 8 L3542
+- **§52** — The WALKER-FAMILY skeleton: 6 regalloc-order levers + a deeply-characterized intrinsic wall (`func_80178004`, 165 ins ×134; Phase 26, Fable5, 2026-07-15) L3928
+- **§3-The** — 6 levers (the "walker-family skeleton" — apply to the 12 siblings; levers 1-5 retire ~half the residual) L3939
+- **§53** — SWEEP A FAMILY WITH THE TOOL ITS EXEMPLAR NEEDED: the jr/switch carve, and how omitting it manufactured the "families don't template" doctrine (Phase 28 T1, 2026-07-15) L4043
+- **§55c** — Sizing the propagate: a TARGETED propagate is ~4 min/core, and "it's slow" was a BROKEN-TREE ARTIFACT L4156
+- **§54** — `--fix-def-sig`: the member's CANONICAL DECLARATION is a build step too (tiny-IMM mega-pools, +4,801, Phase 29 T6, 2026-07-16) L4178
+- **§56** — Banking a hand-drafted GIANT into its exemplar TU: self-contained draft vs live-TU decls, 4 reconciliation tactics (`func_8013FAF8`, 312 ins ×138, Phase 29 T4, 2026-07-17) L4202
+- **§56b** — PROPAGATING an h_seq giant: the exemplar's externs MUST be fleet-canonical, not the draft's types L4247
+- **§57** — The SELF-decl normalize: the sibling's OWN caller declares the templated fn divergently (the third §17a-1 direction; `tools/normalize_self_decls.py`, func_801670E4 ×137, Phase 29, 2026-07-18) L4271
+- **§57a** — Two NSD corrections + the SURGICAL-ONLY law + the honest broad-sweep yield (Phase 29, 2026-07-18) L4318
+- **§59** — Three h_seq sweep-residual classes match_one/the-exemplar-bank don't reveal (Phase 29 crack-wave close, 2026-07-18) L4392
+- **§3-Two** — corollaries worth remembering L4465
+- **§65a** — The blast-radius taxonomy (makes §61's law structural instead of remembered) L5045
+- **§3-Giv** — record order (the §70 family) L5775
+- **§75** — A propagation cap is usually a MINORITY-SPELLING SOURCE OVERLAY, not a wall: census the carried extern before believing the exclusion message (Phase 29 SESSION-19, `func_8014F3E8` ×4 → ×138) L5881
+- **§75a** — The exclusion classes, enumerated with named causes (Phase 29 SESSION-19, the 134-binary `dedup_extend` sweep) L5940
+- **§75b** — A body's preamble can carry `#define`s, not just `extern`s; extraction lifts only the externs (Phase 29 SESSION-19, `func_80165CA0` ×3 → fleet) L5963
+- **§76** — The allocno CLASS (local vs global) is the dominant regalloc lever, and C reaches it ONLY through declaration scope and variable reuse (Phase 29 SESSION-19, behemoth #3 `func_8017F510` 1,511 ins, 97 → MATCH, pin-free) L6043
+- **§77** — Every extraction tool carries a NARROW hard-coded preamble set; anything outside it silently caps the body's reach. Diff the preamble before you gate. (Phase 29 SESSION-19 — three variants in one session, two different tools) L6099
+- **§84** — The DERIVED-OFFSET remap bug: a hand-computed literal that encodes the DISTANCE between two per-overlay symbols, and why `match_one` is structurally blind to it (Phase 29 SESSION-20, `func_8013D53C`) L6487
+- **§86** — Pinned-exemplar templatability is a PER-FAMILY property, not a per-member rate; and the §42e pin guard is now over-conservative (Phase 29 SESSION-20) L6604
+- **§3-THE** — LAW: all-or-nothing PER FAMILY L6615
+- **§3-Why** — the two live families differ from the three dead ones — the open question L6642
+- **§3-The** — cheap discriminator, before spending a sweep L6681
+- **§89b** — the parallel gate farm existed; the family path could not reach it (`tools/sweep_parallel.py`) L6760
+- **§91** — A structure-TRANSFER is only valid where the structure corresponds: the `--like` role trap (Phase 29 SESSION-21, `func_8012AAAC` ×137) L6857
+- **§94** — A family sweep's `0/N` is a TYPE-CARRY failure until proven otherwise: lift the exemplar's local types, ALL of them, transitively (Phase 29 SESSION-21, `func_8016B6BC` 0/137 → 137/137) L6962
+- **§105** — A gate's revert must survive an EXCEPTION, not just a failure (Phase 29 T53, `jtbl_family_bank`) L7446
+- **§107** — A lever wired into ONE gate path is a lever most families cannot reach (Phase 29 T56, `func_80144090` 0/136 → 136/136) L7528
+- **§108** — Diagnosing a family `0/N`: the four causes, and the third opt-in lever (Phase 29 T59) L7566
+- **§111** — The distinct-code metric is not noisy: a family pays it only if its members are byte-VARIANT (Phase 29 T66) L7696
+- **§116** — Optimization level is a property of the FILE, not the function: read a family 0/N against the member's stub HOME (Phase 29 T79) L7892
+- **§123** — PROPAGATE A FAMILY WITH THE TOOL ITS TIER NEEDS: `dedup_propagate` is h_exact-only; its refusals are statements about the TOOL (P30 wave 1, 2026-07-30) L8131
+- **§124** — A "not matched" verdict can mean the definition is there under a DIFFERENT C NAME: the asm-label alias blind spot (P30 SESSION-28, `func_8016191C` ×137) L8168
+- **§124a** — a family sweep's `0 matched-exemplar families` may be a FILTER, not a wall L8213
+- **§134** — MULTI-LINE BLINDNESS: one root cause, four faces, in `family_remap`'s preamble scanner (P30 S6, 190 zero-crack families) L8726
+- **§136c** — SIBLING-FIRST is a DERIVATION shortcut, not just a conflict fix (the fastest route in a family wave) L9084
+- **§138** — The propagation lanes: a gate refusal is a DECLARATION, and which lever you owe depends on blast radius L9430
+- **§142** — An open stub whose `h_exact` class is MATCHED elsewhere is FREE. Propagate the body; do not gate a draft. (P30 S39, +7,710 ins in two commands) L9793
+- **§143** — `cast_call_sites` read a RETURN STATEMENT as a prototype and deleted it. A 0/39 sweep became 18/39. (P30 S40) L9849
+- **Then** — propagation returned 0/137 TWICE — both times a missing TYPE L10015
+- **§3-A.** — The frame has THREE strata, and stratum 3 is unreachable from C L10056
+- **§3-E.** — A `qty_compare` TIE is not spelling-reachable — recognise it and stop L10098
+- **Consequence** — for the family (a real scheduling decision) L10110
+- **§150** — A register ROTATION across symmetric blocks is VARIABLE-IDENTITY evidence, not an allocator tie (P30 S43, `func_8017C6F4`, 947 ins ×4) L10327
+- **§151** — THE GHOST WEDGE: when a load-before-store transposition is unreachable by ANY statement order (P30 S43, `func_8017EF68`, 969 ins) L10382
+- **When** — to reach for it L10422
+- **§152** — BYTE SIZE is the family key that name- and h_seq-grouping both miss (P30 S43, the 0xECC family: 1 crack → 12 overlays → 11,364 ins) L10433
+- **§156** — an ORPHANED reconcile poisons the fleet: `dedup_propagate`'s kept edit (S45 p6/p7) L10655
+- **§160** — THE REACH-15 WAVE HARVEST: an align-1 block move, and the instrument that called it a wall (P30 S47) L10908
+- **§162** — S48 WAVE-1 HARVEST (P30, 2026-08-11): the reach-ordered sibling campaign's first 12 targets L11029
+- **§163z** — THE UNVETTED REMAINDER (do not cite as law; each needs a dedupe pass) L11843
+- **§3-The** — ADDRESS-CLASS TABLE: which load/store pairs even REACH the `/s` clause (P30 S48 wave 4, `func_80185B44`, ov_SC03_014) L14370
+- **§168** — THE COUSIN TIER (P30 S49, 2026-08-12): h_seq's exact-hash brittleness, measured — and the similarity map above it L16239
+- **§171a** — THE MECHANICAL A-PROP DRAFT (P30 S50): 256 members banked with no agent in the loop L16448
+- **§171b** — THREE CARRIES THE MECHANICAL DRAFT NEEDS (P30 S50, banking the top-reach families) L16498
+- **§3-G.** — TWO MODELLING TRAPS THAT COST THESE AGENTS SWEEPS OF HUNDREDS OF COMPILES L17325
+- **§193-E** — A varying-address (pointer) load is re-emitted once per CSE-LIVE INTERVAL, and naming it in a C local is the only C-level lever over that count — no store SPELLING has any reach L18667
+- **§194-E** — The wave card's `exemplar` is the TARGET ITSELF on 42/73 wave-U and 36/71 wave-T cards — a construction consequence of `atlas.py:657` (exemplar = max-nins OPEN member) meeting `build_wave_atlas.py:166` (one card per gid); and the shipped §193-A `seed_ref` is same-binary on 0/51, so no card field can ever name a destination-TU sibling L19173
+- **§195-E** — A 0/1 materialised at a JOIN immediately before the controlling `beqz`/`bnez` proves the source NAMED the condition — a truth expression in an `if`'s controlling position reaches `do_jump`, which has no value path L19967
+- **§199-B** — A permutation sweep that holds ANY statement fixed is not a sweep: the statement an agent pins as "obviously load-bearing" is the one carrying the signal, and the partial sweep returns a FLAT residual that reads as proof of order-invariance L20782
+- **§203** — A DEDUPED TYPEDEF MUST PRECEDE EVERY SPLICE POINT, NOT JUST ITS OWN (P31 S56) L21501
+- **§225** — THREE CONTROL-FLOW SHAPES NO STRUCTURED SPELLING REACHES (P31 S58) L22949
+- **§30** — addendum (P31 S58b) — THE ANONYMOUS STRUCT MEMBER REF GRANTS `/s`, AND THAT IS A TWO-FOR-ONE L24173
+- **§3-1a.** — The §266 sweep — every solo-lever A/B run for this batch L25500
+- **ADDENDUM** — to §179-D (GTE macro reference family) — `gte_SetRotMatrix`/`gte_SetTransMatrix` bodies L25691
+- **ADDENDUM** — to §82 — struct copies must stay MEMBER-WISE, not block-moved, to match a spill-slot save L25717
+- **ADDENDUM** — to §136d-1 (RC-12, the `$0`-add / opaque-copy family) — two symptoms beyond "compare reads the wrong register" L25755
+- **§282** — gcc's OWN LOOP REVERSAL PUTS THE COUNTER INIT AFTER THE HOISTED MOVABLES — a position no hand-written down-count can reach (P31 S60; wave cf, func_80180DD8, ov_SC04_005, byte-proven) L27010
+- **ADDENDUM** — to the zero-byte-asm-slider family (§47 / §148-C / §153) (func_800CB874, md_MAIN_040 — wave dj; open tension with a more cautious dm-wave card — see closing) L27929
+- **ADDENDUM** — the zero-emission-asm family gains a REF-SLIDER PLACEMENT LAW and a paired RESTORER (func_800CB900, md_MAIN_026) L28139
+- **ADDENDUM** — §NNN — sharpens §37/§124 (unspecified-parameter-list family): DERIVE A CALLEE'S ARITY LOWER BOUND FROM ITS OWN `.s` STACK-ARGUMENT READS, NOT FROM ANY SINGLE CALL SITE L28300
+- **ADDENDUM** — to §199-F family (func_8017EFB0, ov_SC02_021, wave cu) L28452
+- **§287** — A STACK-FRAME HOLE BELOW TWO ADDRESS-TAKEN AGGREGATE LOCALS IS A LEADING PAD MEMBER OF ONE COMBINED STRUCT, NOT SEPARATE LOCALS OR A REGISTER PIN (P31 S60/dj; `func_8017D104`, ov_SC06_027, byte-proven 47/47) (P31 S60; waves #, byte-proven) L29060
+- **ADDENDUM** — to §127 — the -O0 constant-offset fold keys on the MEMBER-ACCESS tree shape, not on the index being constant L29144
+- **§296** — THE FRAME CHECK OUTRANKS THE ATLAS LEVER: READ PROLOGUE/EPILOGUE BEFORE DRAFTING ANY C — A REAL TELL CAN LIVE INSIDE AN UNREACHABLE FRAGMENT (P31 S61; wave m0a, 16 cards byte-proven; extends §179-C) L29430
+- **§297** — ONE GIV SERVING MIXED-WIDTH LOADS *AND* A STORE NEEDS STRUCT-MEMBER SPELLING; CAST/INDEX SPELLINGS RE-SPLIT THE PSEUDO (P31 S61; wave m0a, `func_800347C8`, main, byte-proven 31/31) L29473
+- **§307** — THE BRUTE-FORCE-THE-STATEMENT-ORDERS LEVER HAS A BOUND: A FAN-OUT COPY'S PRIORITY IS SCHEDULER-INTERNAL, AND NO SOURCE ORDER REACHES IT (P31 S63; byte-evidenced NEGATIVE result, main wave) L29913
+- **§308a** — A TWO-INSTRUCTION ARM STUB LAID *BEFORE* THE OTHER ARM AND REACHED ONLY BY A TRAILING `j` SURVIVES ONLY BEHIND A SHORT-CIRCUIT `&&` GUARD PLUS A SEPARATE RE-TEST; EVERY PLAIN if/else-if, GOTO-LADDER, NESTED-INVERTED-if AND 1-/2-NODE switch LETS jump1 INLINE IT (−2 ins) (P31 S63 t5e-t5i; byte-proven func_80180808) L29986
### integration / TU plumbing (60)
@@ -772,55 +775,55 @@
- **§28d** — The "macro-extern-injection" lever: freeing reach-134 inline matches dedup_propagate skips as "not self-contained" (Phase 23, `tools/inject_capped_externs.py`) L2366
- **§30a** — §30 generalizes to the FULL near-miss backlog (via STANDARD Opus agents, not just Fable5) + 2 more steer levers + the mechanical-integration throughput unlock (Phase 23 (a)) L2394
- **§40a** — The DECL-RECONCILE pass (type-lift so remapped drafts compile in the sibling TU) (Phase 25 T7.2, 2026-07-08) L2601
-- **§42a** — addendum — wave 2 (residuals + 29-100 band): iso-MATCH ≠ real-TU bank, the memcpy→struct-assign fix, +5 levers (2026-07-10b) L2953
-- **§42c** — addendum — wave 3 (Max orchestrator + CORRECTED Ultracode fan-out, 2026-07-10c): the real-TU-faithful parallel harness (rtu_match) + 7/9 crack, ZERO iso-drift L3033
-- **§56** — Banking a hand-drafted GIANT into its exemplar TU: self-contained draft vs live-TU decls, 4 reconciliation tactics (`func_8013FAF8`, 312 ins ×138, Phase 29 T4, 2026-07-17) L4187
-- **§61** — Task 14: the gate ladder's missing stage is the ARITY pre-pass, and it is TU-side not draft-side (Phase 29, 2026-07-21) L4545
-- **§61a** — The Task-5 wave: 11/12 MATCH, 0 banked — three DISTINCT integration walls, each now named (Phase 29, 2026-07-21) L4606
-- **§63** — The fresh-138 DEF-SIDE blocker: fix the HEADER decl, not the draft (`fix_header_decl.py`, Phase 29 SESSION-13, 2026-07-23) L4877
-- **§63** — UPDATE (Phase 29 SESSION-14) — `fix_header_decl`'s "SAFE" verdict is FLEET-BLIND; it MUST be R22-validated L5000
-- **§65** — The stranded-draft recovery: BLAST-RADIUS TIERS, and the per-overlay de-macroize that refutes §20's DEF-conflict wall (`tools/demacroize.py` + `tools/blocker_probe.py`, Phase 29 SESSION-16, 2026-07-24) L5015
-- **§65b** — The escape: de-macroize the instantiation, don't touch the shared header L5045
-- **§65f** — The de-macroize lever's BOUNDARY, measured: byte-neutral 14 times of 15, and the 15th is why the gate exists L5118
-- **§65g** — Where the cheap levers STOP: the local-type and in-TU-self-decl classes did not yield L5139
-- **§85** — The RETURN-axis fleet widen is ALL-OR-NOTHING: widening the shared header alone guarantees a conflict in the source overlay (Phase 29 SESSION-20, `func_8012CC88` / `func_8014D12C`) L6539
-- **§95** — `reconcile_tu` dropped the SIBLING declarators of a multi-symbol `extern` line (Phase 29 SESSION-21, `func_80176218`) L6983
-- **§96** — The same rewrite, one shape down: `reconcile_tu` matched statements to lines by TEXT, so every COMMENTED declaration was silently skipped (Phase 29 SESSION-22, `func_80176218` banked) L7018
-- **§3-Two** — `reconcile_tu` bugs found underneath, one introduced while fixing the other L7190
-- **§100** — Prefer the DRAFT-LOCAL fix: a type only one function uses belongs in its BODY, not in a shared header (Phase 29 SESSION-22, `func_80175DA8` 0/137 → 137/137) L7216
-- **§102** — A PLUMBING verdict can MASK a DIFF; and K&R is not always a codegen change (Phase 29 SESSION-22, `func_8016EC0C`) L7272
-- **§103** — A FILE-scope `extern` in a shared overlay TU is a GLOBAL constraint on every LATER function; move the DECL, not the draft (Phase 29 T48/T51, `func_80135260` — the fleet-wide half) L7307
-- **§109** — Conforming a definition to a shared header: fix the NAMES, then check the RETURN precondition (Phase 29 T60) L7600
-- **§112** — A macro-scoped declaration only collides where the macro is INSTANTIATED (Phase 29 T67/T69, `audit_header_sigs.py`) L7730
-- **§114** — The THIRD decl axis: a CALLEE the draft declares differently from the target TU (Phase 29 T76/T77) L7808
-- **§3-The** — integration idioms (these decide whether a byte-correct draft BANKS) L8804
-- **§3-The** — declaration surface (integration, not codegen) L8941
-- **Reconciling** — a gate-refused draft: which way you edit depends on WHERE the TU's decl is L9565
-- **§3-The** — same swallow, twice more, in the integration spine L9709
-- **§3-A.** — Payload word0 is a global MODULE ID; code starts after the header L10527
-- **§162** — THE LICM PAIR: what makes an address a movable AT ALL, and why the preheader order is the body order (P30 S47, `ov_MAIN_012`) L11143
-- **§166** — THE DESTINATION-TU ORACLE (P30 S48): the seven-attempt bug that was never codegen L14915
-- **§173** — THE STORED-PLUMBING RECOVERY RECIPE (P31 T6): symfix-first, per-group isolation, and where the verdicts have no drafts L16629
-- **§176d** — THE CONFLICT TABLE MUST BE SEEDED FROM THE TU, AND KEYED PER FILE (P31 S52, 2026-08-15) L16826
-- **§180b** — WHAT THE PRE-GATE LADDER ACTUALLY FINDS IN A COLD PILE (the shape of integration debt) L17842
-- **§185** — EDIT THE SIDE THAT IS CHEAP TO VERIFY, AND CHECK A TU RETYPE AT ITS USE SITES L18060
-- **§194-E** — The wave card's `exemplar` is the TARGET ITSELF on 42/73 wave-U and 36/71 wave-T cards — a construction consequence of `atlas.py:657` (exemplar = max-nins OPEN member) meeting `build_wave_atlas.py:166` (one card per gid); and the shipped §193-A `seed_ref` is same-binary on 0/51, so no card field can ever name a destination-TU sibling L19158
-- **§195-J** — GTE / PsyQ op CALL-vs-INLINE is a PER-SITE SOURCE FACT, not a TU style — both forms coexist in one TU (measured in 2 TUs), and the tell is the target's own opcodes (`lwc2`/`sqr`/`swc2` vs `jal`), not the sibling. Costs -8 ins on func_8018505C. Corollary: the game's inline `sqr` macro emits TWO hazard nops, the SDK's `Square0` body emits ONE — so the inline form is provably not `Square0` inlined (a second instance of §187's SDK-vs-game GTE nop divergence). L20222
-- **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` L20860
-- **§200** — THE ALIAS IS THE UNIVERSAL DECLARATION ESCAPE: stop negotiating with the TU's spelling (P31 S55) L21099
-- **§201-A** — §150-B applies to `decl_prior`'s DEF row: for an overlay-window symbol the banked "definition" is usually another overlay's function, and the card ranks it ABOVE the destination TU L21158
-- **§203** — A DEDUPED TYPEDEF MUST PRECEDE EVERY SPLICE POINT, NOT JUST ITS OWN (P31 S56) L21486
-- **§210** — THE SINGLE-BIT MASK IN A BOOLEAN TAIL: `andi K ; sltu $zero,v` vs `srl n ; andi 1` is a STATEMENT-SHAPE dial, not an operator choice (P31 S58) L22328
-- **ADD-2** — → §42a addendum — A SHARED CONSTANT *NAMED IN A LOCAL* ACROSS A `jal` IS AN ISO→TU DRIFT HAZARD; WRITE BARE LITERALS L25096
-- **ADD-3** — → §236, item 10 — THE UN-DELETED `INCLUDE_ASM` STUB IS A DUPLICATE DEFINITION L25108
-- **ADD-2** — → §236 addendum (item 1 corollary) — THE SILENT-SPLICE DECLARATION LADDER: WHERE THE TU HAS NO SPELLING, UNPROTOTYPED `()` BEATS THE FLEET VOTE L25326
-- **§273** — A standalone compile is the WRONG oracle for a TU-destined draft (P31 S59) L25578
-- **ADDENDUM** — to §134 — a typedef defined BELOW the splice point is stripped anyway L25646
-- **ADDENDUM** — to §8 — WHEN `INCLUDE_RODATA` NEEDS A STANDALONE `.s` YOU CAN'T CREATE, CARRY THE FRAGMENT AS A FILE-SCOPE `__asm__` BLOB L26181
-- **§280** — THE CURSOR'S DECLARED TYPE PICKS `sltu` vs `slt`: a `T*` bound test is UNSIGNED by C rule, an integer cursor is signed (P31 S60; wave cf, func_800CAE74, md_MAIN_031, byte-proven) L26915
-- **§NNN** — A LOOP CURSOR'S C TYPE (POINTER vs PLAIN INTEGER) SELECTS `sltu` vs `slt` FOR ITS BOUND TEST, INDEPENDENT OF THE VALUES INVOLVED (P31 S60; `func_800CAE74`, md_MAIN_031, byte-proven; cross-confirmed same wave by `func_8017F2A4`, ov_SC03_096) L26916
-- **ADDENDUM** — to §199-G — A `default:` LABEL GROUPED ONTO THE LAST CASE REMOVES THE `j default` TAIL, EVEN THOUGH THE 2-NODE HEADER STAYS ALL-POSITIVE L27370
-- **§301** — AN INTERNAL `j` CARRIES `R_MIPS_26 .text`: rtu/match_one "MATCH" COULD NOT SEE WHICH LABEL A `j` TAKES — FIXED (`jrel`), AND THE TWO DRAFT SHAPES IT HID (P31 S62 T1; byte-proven 2/2, negative-controlled over 3,297 stubs) L29630
+- **§42a** — addendum — wave 2 (residuals + 29-100 band): iso-MATCH ≠ real-TU bank, the memcpy→struct-assign fix, +5 levers (2026-07-10b) L2968
+- **§42c** — addendum — wave 3 (Max orchestrator + CORRECTED Ultracode fan-out, 2026-07-10c): the real-TU-faithful parallel harness (rtu_match) + 7/9 crack, ZERO iso-drift L3048
+- **§56** — Banking a hand-drafted GIANT into its exemplar TU: self-contained draft vs live-TU decls, 4 reconciliation tactics (`func_8013FAF8`, 312 ins ×138, Phase 29 T4, 2026-07-17) L4202
+- **§61** — Task 14: the gate ladder's missing stage is the ARITY pre-pass, and it is TU-side not draft-side (Phase 29, 2026-07-21) L4560
+- **§61a** — The Task-5 wave: 11/12 MATCH, 0 banked — three DISTINCT integration walls, each now named (Phase 29, 2026-07-21) L4621
+- **§63** — The fresh-138 DEF-SIDE blocker: fix the HEADER decl, not the draft (`fix_header_decl.py`, Phase 29 SESSION-13, 2026-07-23) L4892
+- **§63** — UPDATE (Phase 29 SESSION-14) — `fix_header_decl`'s "SAFE" verdict is FLEET-BLIND; it MUST be R22-validated L5015
+- **§65** — The stranded-draft recovery: BLAST-RADIUS TIERS, and the per-overlay de-macroize that refutes §20's DEF-conflict wall (`tools/demacroize.py` + `tools/blocker_probe.py`, Phase 29 SESSION-16, 2026-07-24) L5030
+- **§65b** — The escape: de-macroize the instantiation, don't touch the shared header L5060
+- **§65f** — The de-macroize lever's BOUNDARY, measured: byte-neutral 14 times of 15, and the 15th is why the gate exists L5133
+- **§65g** — Where the cheap levers STOP: the local-type and in-TU-self-decl classes did not yield L5154
+- **§85** — The RETURN-axis fleet widen is ALL-OR-NOTHING: widening the shared header alone guarantees a conflict in the source overlay (Phase 29 SESSION-20, `func_8012CC88` / `func_8014D12C`) L6554
+- **§95** — `reconcile_tu` dropped the SIBLING declarators of a multi-symbol `extern` line (Phase 29 SESSION-21, `func_80176218`) L6998
+- **§96** — The same rewrite, one shape down: `reconcile_tu` matched statements to lines by TEXT, so every COMMENTED declaration was silently skipped (Phase 29 SESSION-22, `func_80176218` banked) L7033
+- **§3-Two** — `reconcile_tu` bugs found underneath, one introduced while fixing the other L7205
+- **§100** — Prefer the DRAFT-LOCAL fix: a type only one function uses belongs in its BODY, not in a shared header (Phase 29 SESSION-22, `func_80175DA8` 0/137 → 137/137) L7231
+- **§102** — A PLUMBING verdict can MASK a DIFF; and K&R is not always a codegen change (Phase 29 SESSION-22, `func_8016EC0C`) L7287
+- **§103** — A FILE-scope `extern` in a shared overlay TU is a GLOBAL constraint on every LATER function; move the DECL, not the draft (Phase 29 T48/T51, `func_80135260` — the fleet-wide half) L7322
+- **§109** — Conforming a definition to a shared header: fix the NAMES, then check the RETURN precondition (Phase 29 T60) L7615
+- **§112** — A macro-scoped declaration only collides where the macro is INSTANTIATED (Phase 29 T67/T69, `audit_header_sigs.py`) L7745
+- **§114** — The THIRD decl axis: a CALLEE the draft declares differently from the target TU (Phase 29 T76/T77) L7823
+- **§3-The** — integration idioms (these decide whether a byte-correct draft BANKS) L8819
+- **§3-The** — declaration surface (integration, not codegen) L8956
+- **Reconciling** — a gate-refused draft: which way you edit depends on WHERE the TU's decl is L9580
+- **§3-The** — same swallow, twice more, in the integration spine L9724
+- **§3-A.** — Payload word0 is a global MODULE ID; code starts after the header L10542
+- **§162** — THE LICM PAIR: what makes an address a movable AT ALL, and why the preheader order is the body order (P30 S47, `ov_MAIN_012`) L11158
+- **§166** — THE DESTINATION-TU ORACLE (P30 S48): the seven-attempt bug that was never codegen L14930
+- **§173** — THE STORED-PLUMBING RECOVERY RECIPE (P31 T6): symfix-first, per-group isolation, and where the verdicts have no drafts L16644
+- **§176d** — THE CONFLICT TABLE MUST BE SEEDED FROM THE TU, AND KEYED PER FILE (P31 S52, 2026-08-15) L16841
+- **§180b** — WHAT THE PRE-GATE LADDER ACTUALLY FINDS IN A COLD PILE (the shape of integration debt) L17857
+- **§185** — EDIT THE SIDE THAT IS CHEAP TO VERIFY, AND CHECK A TU RETYPE AT ITS USE SITES L18075
+- **§194-E** — The wave card's `exemplar` is the TARGET ITSELF on 42/73 wave-U and 36/71 wave-T cards — a construction consequence of `atlas.py:657` (exemplar = max-nins OPEN member) meeting `build_wave_atlas.py:166` (one card per gid); and the shipped §193-A `seed_ref` is same-binary on 0/51, so no card field can ever name a destination-TU sibling L19173
+- **§195-J** — GTE / PsyQ op CALL-vs-INLINE is a PER-SITE SOURCE FACT, not a TU style — both forms coexist in one TU (measured in 2 TUs), and the tell is the target's own opcodes (`lwc2`/`sqr`/`swc2` vs `jal`), not the sibling. Costs -8 ins on func_8018505C. Corollary: the game's inline `sqr` macro emits TWO hazard nops, the SDK's `Square0` body emits ONE — so the inline form is provably not `Square0` inlined (a second instance of §187's SDK-vs-game GTE nop divergence). L20237
+- **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` L20875
+- **§200** — THE ALIAS IS THE UNIVERSAL DECLARATION ESCAPE: stop negotiating with the TU's spelling (P31 S55) L21114
+- **§201-A** — §150-B applies to `decl_prior`'s DEF row: for an overlay-window symbol the banked "definition" is usually another overlay's function, and the card ranks it ABOVE the destination TU L21173
+- **§203** — A DEDUPED TYPEDEF MUST PRECEDE EVERY SPLICE POINT, NOT JUST ITS OWN (P31 S56) L21501
+- **§210** — THE SINGLE-BIT MASK IN A BOOLEAN TAIL: `andi K ; sltu $zero,v` vs `srl n ; andi 1` is a STATEMENT-SHAPE dial, not an operator choice (P31 S58) L22343
+- **ADD-2** — → §42a addendum — A SHARED CONSTANT *NAMED IN A LOCAL* ACROSS A `jal` IS AN ISO→TU DRIFT HAZARD; WRITE BARE LITERALS L25111
+- **ADD-3** — → §236, item 10 — THE UN-DELETED `INCLUDE_ASM` STUB IS A DUPLICATE DEFINITION L25123
+- **ADD-2** — → §236 addendum (item 1 corollary) — THE SILENT-SPLICE DECLARATION LADDER: WHERE THE TU HAS NO SPELLING, UNPROTOTYPED `()` BEATS THE FLEET VOTE L25341
+- **§273** — A standalone compile is the WRONG oracle for a TU-destined draft (P31 S59) L25593
+- **ADDENDUM** — to §134 — a typedef defined BELOW the splice point is stripped anyway L25661
+- **ADDENDUM** — to §8 — WHEN `INCLUDE_RODATA` NEEDS A STANDALONE `.s` YOU CAN'T CREATE, CARRY THE FRAGMENT AS A FILE-SCOPE `__asm__` BLOB L26196
+- **§280** — THE CURSOR'S DECLARED TYPE PICKS `sltu` vs `slt`: a `T*` bound test is UNSIGNED by C rule, an integer cursor is signed (P31 S60; wave cf, func_800CAE74, md_MAIN_031, byte-proven) L26930
+- **§NNN** — A LOOP CURSOR'S C TYPE (POINTER vs PLAIN INTEGER) SELECTS `sltu` vs `slt` FOR ITS BOUND TEST, INDEPENDENT OF THE VALUES INVOLVED (P31 S60; `func_800CAE74`, md_MAIN_031, byte-proven; cross-confirmed same wave by `func_8017F2A4`, ov_SC03_096) L26931
+- **ADDENDUM** — to §199-G — A `default:` LABEL GROUPED ONTO THE LAST CASE REMOVES THE `j default` TAIL, EVEN THOUGH THE 2-NODE HEADER STAYS ALL-POSITIVE L27385
+- **§301** — AN INTERNAL `j` CARRIES `R_MIPS_26 .text`: rtu/match_one "MATCH" COULD NOT SEE WHICH LABEL A `j` TAKES — FIXED (`jrel`), AND THE TWO DRAFT SHAPES IT HID (P31 S62 T1; byte-proven 2/2, negative-controlled over 3,297 stubs) L29645
### build graph, splat & the harness (167)
@@ -864,133 +867,133 @@
- **§37** — The T7 §G giant endgame: 6/8 cracked, meta-laws + transferable levers (Phase 24, 2026-07-07; FULL byte-verified detail + gcc-2.7.2 line cites in `docs/gcc-2.7.2-map/t7g-giant-harvest.md`) L2506
- **§39** — The ×1→×134 giant-endgame: propagate a matched **-O2** giant via the NATIVE DEFINE-macro path (Phase 24 T7 §G close, 2026-07-08) L2537
- **§41** — The DEF-SIDE canonical-sig wall: mechanically banking a drafted giant past `conflicting types` (Phase 25 T5b batch-2, 2026-07-09; `tools/canon_sig_reconcile.py`, byte-proven on `func_8013B274`) L2710
-- **§41a** — v3.1: the def-side wall was ~71% TOOL-shaped — the five measured defects + the laws that dissolve them (Phase 25 T6, Fable5, 2026-07-09) L2754
-- **§41b** — T7 execution: the object-only probe OVER-counts BANKABLE by two link/rodata classes (Phase 25 T7-M1, 2026-07-10) L2809
-- **§41d** — `void`→`s32` is NOT always byte-neutral: gate the RAW draft FIRST (Phase 26 session 6, byte-proven) L2878
-- **§42b** — addendum — wave 3 (Max, 2026-07-10c): THE STALE-OBJECT GATE TRAP + the read-global `&`-cast drift + fix L2994
-- **§45** — The flagship `func_80133CD4` crack (399 ins ×134): the merged-variable permutation-breaker + the 1-death local-alloc gate (Phase 25 task A giant escalation, Fable5 gdb-on-cc1, 2026-07-11) L3298
-- **§51** — TOOLING INTEGRITY: the silent skip, and how to hunt it L3630
-- **§51b** — Why the byte-gate cannot save you L3652
-- **§51f** — Checklist for any new corpus-scanning tool L3755
-- **§51g** — When the thing you are scanning has a GRAMMAR, parse the grammar (`tools/cdecl.py`) L3769
-- **§53** — SWEEP A FAMILY WITH THE TOOL ITS EXEMPLAR NEEDED: the jr/switch carve, and how omitting it manufactured the "families don't template" doctrine (Phase 28 T1, 2026-07-15) L4028
-- **§55** — Core-crack wave levers + the GATE-ORCHESTRATION law (Phase 29 T3, 13-agent ultracode wave, 2026-07-17) L4093
-- **§55b** — THE GATE-ORCHESTRATION LAW (3 traps, ~3.5h lost; all recovered, 0 data lost) L4122
-- **§55c** — Sizing the propagate: a TARGETED propagate is ~4 min/core, and "it's slow" was a BROKEN-TREE ARTIFACT L4141
-- **§54** — `--fix-def-sig`: the member's CANONICAL DECLARATION is a build step too (tiny-IMM mega-pools, +4,801, Phase 29 T6, 2026-07-16) L4163
-- **§57** — The SELF-decl normalize: the sibling's OWN caller declares the templated fn divergently (the third §17a-1 direction; `tools/normalize_self_decls.py`, func_801670E4 ×137, Phase 29, 2026-07-18) L4256
-- **§61** — Task 14: the gate ladder's missing stage is the ARITY pre-pass, and it is TU-side not draft-side (Phase 29, 2026-07-21) L4545
-- **§61b** — The jtbl gate stage: built, and the ORDERING law it exposed (Phase 29 Task-14 stage 4, 2026-07-21) L4658
-- **§61d** — The undo was eating the tree: two tools, one defect, invisible to the byte-gate (Phase 29, 2026-07-22) L4779
-- **§62** — The jtbl RECONCILE must also follow the carve: the post-carve draft reconcile (`harvest_verify._jtbl_reconcile`, Phase 29 SESSION-11, 2026-07-22) L4833
-- **§65** — The stranded-draft recovery: BLAST-RADIUS TIERS, and the per-overlay de-macroize that refutes §20's DEF-conflict wall (`tools/demacroize.py` + `tools/blocker_probe.py`, Phase 29 SESSION-16, 2026-07-24) L5015
-- **§65d** — Existing-ladder baseline, measured (do this before building a recovery stage) L5091
-- **§65e** — Two oracles, and the disagreement is the finding (R34 in practice) L5101
-- **§65f** — The de-macroize lever's BOUNDARY, measured: byte-neutral 14 times of 15, and the 15th is why the gate exists L5118
-- **§66b** — A metric parsed out of another tool's prose goes NULL silently when the label changes L5200
-- **§67a** — Run the symbol-set guard BEFORE you pay for a gate (`tools/symcheck.py`, Phase 29 SESSION-18) L5405
-- **§77** — Every extraction tool carries a NARROW hard-coded preamble set; anything outside it silently caps the body's reach. Diff the preamble before you gate. (Phase 29 SESSION-19 — three variants in one session, two different tools) L6084
-- **§3-The** — CANDIDATE gate and the REAL gate need DIFFERENT preambles — keep the difference out of the bank L6124
-- **§79** — For a 0-callee giant, fingerprint by DATA symbols (§71 cannot fire); and the STACK-SLOT ORDER is a declaration-order oracle (Phase 29 SESSION-19, `func_8017BF14` 4,763 ins, cold start → 45/4763) L6220
-- **§82** — Two source-shape oracles from behemoth #6: a duplicated `addiu $aN,$sp,K` across a `jal` means the block was INLINED, and scalar-vs-aggregate decides WHEN a stack slot is allocated (Phase 29 SESSION-19, `func_8017C730` 1,061 ins) L6370
-- **§3-2.** — Scalar vs aggregate decides *when* the slot is allocated L6389
-- **§3-Why** — it survived every candidate gate L6495
-- **§3-THE** — FIX IS MECHANICAL — the tool already holds the answer L6510
-- **§87** — `match_one` COMPILES but never LINKS, so an unresolvable data symbol reads as MATCH; and stored drafts go STALE against the tree (Phase 29 SESSION-20) L6633
-- **§88f** — the missing rung: a RELOCATION gate between `match_one` and the binary L6718
-- **§89a** — MEASURE the write set; do not assert its tier (`tools/blast_radius.py`) L6732
-- **§89b** — the parallel gate farm existed; the family path could not reach it (`tools/sweep_parallel.py`) L6745
-- **§90** — Five tool-integrity laws from one session, each of which changed an answer (Phase 29 SESSION-21, 2026-07-27) L6766
-- **§90a** — A comparison tool MUST share its reference oracle's index space, exactly L6772
-- **§92** — Conforming a DECLARATION: pointer changes are caller-neutral, scalar-WIDTH changes are not (Phase 29 SESSION-21, `tools/conform_decls.py`) L6891
-- **§97** — The gate's own tree hygiene: a refused carve, an unchecked recovery, and a snapshot that captured a dirty tree (Phase 29 SESSION-22) L7066
-- **§105** — A gate's revert must survive an EXCEPTION, not just a failure (Phase 29 T53, `jtbl_family_bank`) L7431
-- **§107** — A lever wired into ONE gate path is a lever most families cannot reach (Phase 29 T56, `func_80144090` 0/136 → 136/136) L7513
-- **§3-Why** — it survived so long: a MASKED oracle will MATCH a wrong symbol L7953
-- **§122** — GATE RAW BEFORE TRANSFORMING; the undo belongs to the WRITER, as a per-edit journal (P30 T0a, 2026-07-30) L8084
-- **§123** — PROPAGATE A FAMILY WITH THE TOOL ITS TIER NEEDS: `dedup_propagate` is h_exact-only; its refusals are statements about the TOOL (P30 wave 1, 2026-07-30) L8116
-- **§126a** — a bare `except: continue` around a coverage-asserting oracle re-creates the silent skip (P30 S28) L8317
-- **§130** — An INCREMENTAL build can report BYTE-IDENTICAL for a change the CLEAN build cannot even LINK (P30 S28, the jr pair) L8486
-- **§132** — The `JR-PAIR-IN-ONE-O0-OBJECT` "wall" was TWO instrument defects: a merged-double span the carve could not see, and a truncated object no rule deleted (P30 S29, `func_8013B83C` + `func_8013BD74`) L8570
-- **§133** — The DEFAULT-FILTER class: three times in one session, a tool silently answered a narrower question than the one asked (P30 S1–S3) L8685
-- **§134** — MULTI-LINE BLINDNESS: one root cause, four faces, in `family_remap`'s preamble scanner (P30 S6, 190 zero-crack families) L8711
-- **§3-The** — splitting/merging rules (each closed a residual, byte-gated) L8853
-- **§137a** — A gate verdict has a TIMESTAMP; re-check it against the draft's mtime L9386
-- **§138** — The propagation lanes: a gate refusal is a DECLARATION, and which lever you owe depends on blast radius L9415
-- **§134** — again, in a second tool — and the waiter rule corrected L9526
-- **Reconciling** — a gate-refused draft: which way you edit depends on WHERE the TU's decl is L9565
-- **§139** — A GATE THAT GREPS FOR VERDICTS MUST ASSERT 1:1 ACCOUNTING; and a `--src` filter must not survive a carve (P30 S38, wave 6: 10 of 16 drafts vanished) L9594
-- **§140** — A METRIC IS NOT A MEASUREMENT UNTIL IT IS REPRODUCIBLE FROM THE COMMITTED TREE (P30 S1e: a phantom regression that gated the session's best lever) L9660
-- **§142** — An open stub whose `h_exact` class is MATCHED elsewhere is FREE. Propagate the body; do not gate a draft. (P30 S39, +7,710 ins in two commands) L9778
-- **§3-The** — measurement (do this before any wave; it is ~20 lines and needs no builds) L9790
-- **§155b** — check the TYPE your oracle returns before comparing against it (S45 p5) L10587
-- **§156** — an ORPHANED reconcile poisons the fleet: `dedup_propagate`'s kept edit (S45 p6/p7) L10640
-- **§158** — The RANGE-EXTENDER: a fourth zero-emission asm lever completes the allocno toolkit (P30 S46 tier-3, `func_8017CE58`, 733 ins) L10712
-- **§160** — THE REACH-15 WAVE HARVEST: an align-1 block move, and the instrument that called it a wall (P30 S47) L10893
-- **§161** — THE RETRY-WAVE HARVEST: a jump table indexed from zero, and two allocator traps (P30 S47) L10969
-- **§162** — S48 WAVE-1 HARVEST (P30, 2026-08-11): the reach-ordered sibling campaign's first 12 targets L11014
-- **§163** — S48 WAVES 2-3 HARVEST (P30, 2026-08-11/12): the five that were byte-probed and are actionable L11760
-- **§165** — S48 WAVE-4 HARVEST (P30, 2026-08-12): banked the same day the wave landed L13702
-- **§166** — THE DESTINATION-TU ORACLE (P30 S48): the seven-attempt bug that was never codegen L14915
-- **§167** — S48 WAVE-5/6 HARVEST (P30, 2026-08-12): the saturation point L14971
-- **§176e** — SYMBOL IDENTITY IS COMPUTABLE OFFLINE (P31 S52): `tools/reloc_identity.py` L16865
-- **§3-A.** — The seven under-reporting holes (all in `gate_main`, all the same shape) L16999
-- **§3-C2.** — RECONCILE BEFORE THE FIRST GATE — a parked draft gets HARDER to bank, not easier L17046
-- **§3-D.** — The measured cost shape, and what to build next L17069
-- **§176i** — WHAT A STATIC PRE-GATE CHECK CAN AND CANNOT PROVE (P31 S52, wave Q) L17087
-- **§179** — IDIOMS MINED FROM THE WAVE P/Q JOURNALS (P31 S52, harvest pass) L17326
-- **§179-G** — 🟡 A PIN CAN **CREATE** A COMBINE `LOG_LINK` AND DELETE AN `andi` (sixth RC-5 channel, n=1) L17555
-- **§176c** — MAIN (SLUS_007.26) CANNOT BE GATED INCREMENTALLY L17622
-- **§180** — THE LEFTOVER-DRAFT HARVEST: RE-VERIFY WHAT YOU ALREADY HAVE BEFORE DRAFTING ANYTHING NEW L17813
-- **§180b** — WHAT THE PRE-GATE LADDER ACTUALLY FINDS IN A COLD PILE (the shape of integration debt) L17842
-- **§181** — WHAT A WAVE'S GATE ACTUALLY REJECTS (P31 S53, measured on wave R's 45-draft main pile) L17879
-- **§184** — COMMENT-BLINDNESS IS A DEFECT CLASS, NOT A BUG (P31 S53: three tools, one root cause, one session) L18032
-- **§187** — 🔴 "SAME SOURCE" IS NOT "SAME OBJECT": THE SDK BUILD AND THE GAME BUILD DISAGREE ON GTE NOPS L18138
-- **§190** — THREE PRESCRIPTIONS FROM THE SAME HARVEST (weaker evidence than §189, honestly labelled) L18301
-- **§191** — WHAT THIS HARVEST DID **NOT** BANK (4 rejected, 4 narrowed) — recorded so it is not re-derived L18338
-- **§192** — THE PRE-GATE LADDER WAS MAIN-ONLY, AND NOBODY COULD SEE IT (P31 S54) L18360
-- **§193** — THE WAVE-T HARVEST (P31 S54): 71 index_gap reports -> 9 laws, 5 rejected, 61 already-covered L18425
-- **§193-A** — The wave card ships only OPEN-set pointers and discards the atlas's BANKED one — `exemplar`/`sibs` are stubs 100% by construction (tools/atlas.py:96/657), while `seed.ref` (matched pool, atlas.py:505-536) is dropped at build_wave_atlas.py:143 L18442
-- **§193-G** — §164-54's "scope to ≥4 arms" bound is byte-wrong — the dispatch-topology oracle goes live at THREE case nodes (`balance_case_nodes` splits at `i > 2`), but only for a signed-after-promotion index L18746
-- **§193-I** — A DECLARED AGGREGATE LOCAL HAS AN 8-BYTE FRAME STRIDE — CEIL(size,8), NOT size. N ARRAYS THEREFORE COST 8·k MORE THAN ONE HAND-LAID STRUCT (k = how many of them have size mod 8 ≠ 0), AND THE TELL IS IDENTICAL INSTRUCTION COUNT WITH EVERY $sp DISPLACEMENT SHIFTED BY THE SAME CONSTANT. L18847
-- **§193-REJECTED** — what this harvest did NOT bank (recorded so it is not re-derived) L18906
-- **§194** — THE WAVE-U HARVEST (P31 S54): 64 index_gap reports -> 14 laws, 5 rejected, 44 already-covered L18933
-- **§194-E** — The wave card's `exemplar` is the TARGET ITSELF on 42/73 wave-U and 36/71 wave-T cards — a construction consequence of `atlas.py:657` (exemplar = max-nins OPEN member) meeting `build_wave_atlas.py:166` (one card per gid); and the shipped §193-A `seed_ref` is same-binary on 0/51, so no card field can ever name a destination-TU sibling L19158
-- **§194-G** — Reading the integer half of a 16.16 stack aggregate: REGISTER-LIVENESS, not the C spelling, decides `sra` vs `lhu` — and the break is count-neutral L19268
-- **§194-K** — Blind sched1's alias oracle with a second SET of a pointer pseudo — the first zero-byte, non-volatile, dependence-CREATING lever (corrects §167-05's "volatile is the only door"; fourth consumer of reg_n_sets) L19444
-- **§194-REJECTED** — what this harvest did NOT bank (recorded so it is not re-derived) L19688
-- **§195** — THE WAVE-V HARVEST (P31 S54): 67 index_gap reports -> 14 laws, 9 rejected, 76 already-covered L19709
-- **§195-I** — §145(b) AMENDED — the pointer-bump `addiu` is saved by cse, not combine: ANY second SET of a pseudo in the address's equivalence chain (in-place `p += K`, §145(b)'s `p = r;` copy, or an asm re-tie) kills the fold; the pass is cse and the gate is `invalidate`'s `reg_tick++` L20157
-- **§195-M** — Frame `vars` is a SEQUENTIAL bump-allocation, not a flat sum: §193-I's CEIL(aggregate,8) term and §165-03/§167-06's 8×orphan term are the SAME frame_offset walk at two different compiler stages, and each stage re-CEILs frame_offset to 8 before it allocates L20370
-- **§195-REJECTED** — what this harvest did NOT bank (recorded so it is not re-derived) L20466
-- **§197** — THE WAVE-W HARVEST (P31 S54): 68 index_gap reports -> 4 laws, 3 rejected, 41 already-covered L20567
-- **§199** — THE WAVE-X HARVEST (P31 S54/S55): 63 index_gap reports -> 7 laws, 2 rejected, 56 already-covered L20707
-- **§199-C** — A NEGATIVE CONSTANT MULTIPLY ALWAYS TAKES expmed's negate_variant — but whether you ever SEE the neg is decided by COMBINE, and for an EVEN |K| it never disappears L20812
-- **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` L20860
-- **§199-G** — At TWO case nodes the switch-vs-if oracle is not blind — but the tell is ALL tests positive + a trailing `j default`, NOT the first test's polarity L21033
-- **§201** — THE WAVE-Y HARVEST (P31 S55): 67 gap reports -> 5 laws, 8 rejected, 53 already-covered L21148
-- **§204** — THE WAVE-Z HARVEST (P31 S56): 82 gap reports -> 5 laws, 16 rejected, 30 already-covered L21547
-- **§207** — THE WAVE ab–ag HARVEST (P31 S58): 278 byte-banked notes → 25 laws, 103 self-reported no-gap L22181
-- **§233** — THE WAVE aa–bg HARVEST (P31 S58b): 1,101 byte-banked notes → 24 new laws, 21 addenda, ~700 already-covered L23272
-- **§236** — THE DECLARATION LAYER IS THE DOMINANT BANK-BLOCKER: NINE WAYS A BYTE-PERFECT BODY FAILS THE GATE (P31 S58b) L23386
-- **§247** — TWO BRANCHES TO **ONE** LABEL MEANS THE SOURCE CONDITION IS NEGATED (P31 S58b) L23832
-- **§254** — THE DEAD PARAMETER IS A REGISTER-PLACEMENT TOOL **(single observation — not yet cross-confirmed)** (P31 S58b) L24026
-- **§259** — THE DISCARD LEDGER FOR THE aa–bg HARVEST (P31 S58b): WHAT WAS MINED AND REJECTED, AND WHY L24683
-- **§260-A** — STAGE 2 IS PROVEN, AND THE WHOLE jtbl PIPELINE IS AUTOMATED AT THE GATE (P31 S59, same day) L24772
-- **§261** — THE -O0 ORACLE: DERIVE THE OPT LEVEL FROM THE TARGET, AND `$fp` IS NOT THE TELL (P31 S59) L24808
-- **§267** — ADDENDA HARVESTED FROM WAVES at/bh/bk/bl (P31 S59b) L25079
-- **ADD-9** — → §213-3 / §217 addendum — ADJACENT PRE-CALL FRAME STORES ARE ONE AGGREGATE; THE UNESCAPED SCALAR NEIGHBOR IS DEAD-STORED L25174
-- **§269** — ADDENDA HARVESTED FROM WAVES ax/bm (P31 S59c) L25298
-- **§271** — Ordinal IMM pairing: text order is NOT emission order; emit CANDIDATES, let the oracle pick (P31 S59) L25536
-- **§273** — A standalone compile is the WRONG oracle for a TU-destined draft (P31 S59) L25578
-- **§274** — ADDENDA HARVESTED FROM 18 WAVES (P31 S60): 315 candidates, 255 already covered, 21 sharpenings, 3 new laws L25593
-- **§278** — ADDENDA HARVESTED FROM WAVE cf (P31 S60): 34 candidates, 13 already covered, 8 sharpenings, 4 new laws L26584
-- **§283** — ADDENDA HARVESTED FROM THE 36-WAVE BATCH (P31 S60): 1,216 candidates, 859 already covered, 46 sharpenings, 9 new laws L27080
-- **§287** — A STACK-FRAME HOLE BELOW TWO ADDRESS-TAKEN AGGREGATE LOCALS IS A LEADING PAD MEMBER OF ONE COMBINED STRUCT, NOT SEPARATE LOCALS OR A REGISTER PIN (P31 S60/dj; `func_8017D104`, ov_SC06_027, byte-proven 47/47) (P31 S60; waves #, byte-proven) L29045
-- **§293** — THE "WHOLE-OBJECT GATE NEEDS EVERY SIBLING" LAW, WRITTEN PROPERLY: IT IS THREE LAWS, AND THE LOAD-BEARING ONE IS "THE BASELINE, NOT THE SIBLINGS" (P31 S61; byte-proven on 15 binaries in one night) L29068
-- **§294** — ADDENDA HARVESTED FROM THE S61 GEN0/MAXTOK/MAIN/DEEPSEEK BATCH (waves ab8/ab16/ab24/ab32 · g0a–g0f · m0a · ds1/ds2): 99 candidates, 52 covered, 15 notes → 10 addenda, 29 notes → 5 new laws (§295–§299), 3 refuted L29118
-- **§303** — MODULE ISLAND TABLES: DERIVE THE PADS AT BUILD TIME, PEEL NOTHING — THE §154-A/§260 "island-pads"/"island-blocked" WALLS DISSOLVE (P31 S62 T3a; byte-proven md_SC03_076 func_801F0A9C + func_801F0F28, sha 9a165e36…) L29722
-- **§305** — "CARVE-REFUSED" AT GATE TIME IS THREE NAMED, DETERMINISTIC CLASSES — NONE OF THEM A CARVE (P31 S62 T3; 28 resolver drafts autopsied 28/28) L29781
+- **§41a** — v3.1: the def-side wall was ~71% TOOL-shaped — the five measured defects + the laws that dissolve them (Phase 25 T6, Fable5, 2026-07-09) L2769
+- **§41b** — T7 execution: the object-only probe OVER-counts BANKABLE by two link/rodata classes (Phase 25 T7-M1, 2026-07-10) L2824
+- **§41d** — `void`→`s32` is NOT always byte-neutral: gate the RAW draft FIRST (Phase 26 session 6, byte-proven) L2893
+- **§42b** — addendum — wave 3 (Max, 2026-07-10c): THE STALE-OBJECT GATE TRAP + the read-global `&`-cast drift + fix L3009
+- **§45** — The flagship `func_80133CD4` crack (399 ins ×134): the merged-variable permutation-breaker + the 1-death local-alloc gate (Phase 25 task A giant escalation, Fable5 gdb-on-cc1, 2026-07-11) L3313
+- **§51** — TOOLING INTEGRITY: the silent skip, and how to hunt it L3645
+- **§51b** — Why the byte-gate cannot save you L3667
+- **§51f** — Checklist for any new corpus-scanning tool L3770
+- **§51g** — When the thing you are scanning has a GRAMMAR, parse the grammar (`tools/cdecl.py`) L3784
+- **§53** — SWEEP A FAMILY WITH THE TOOL ITS EXEMPLAR NEEDED: the jr/switch carve, and how omitting it manufactured the "families don't template" doctrine (Phase 28 T1, 2026-07-15) L4043
+- **§55** — Core-crack wave levers + the GATE-ORCHESTRATION law (Phase 29 T3, 13-agent ultracode wave, 2026-07-17) L4108
+- **§55b** — THE GATE-ORCHESTRATION LAW (3 traps, ~3.5h lost; all recovered, 0 data lost) L4137
+- **§55c** — Sizing the propagate: a TARGETED propagate is ~4 min/core, and "it's slow" was a BROKEN-TREE ARTIFACT L4156
+- **§54** — `--fix-def-sig`: the member's CANONICAL DECLARATION is a build step too (tiny-IMM mega-pools, +4,801, Phase 29 T6, 2026-07-16) L4178
+- **§57** — The SELF-decl normalize: the sibling's OWN caller declares the templated fn divergently (the third §17a-1 direction; `tools/normalize_self_decls.py`, func_801670E4 ×137, Phase 29, 2026-07-18) L4271
+- **§61** — Task 14: the gate ladder's missing stage is the ARITY pre-pass, and it is TU-side not draft-side (Phase 29, 2026-07-21) L4560
+- **§61b** — The jtbl gate stage: built, and the ORDERING law it exposed (Phase 29 Task-14 stage 4, 2026-07-21) L4673
+- **§61d** — The undo was eating the tree: two tools, one defect, invisible to the byte-gate (Phase 29, 2026-07-22) L4794
+- **§62** — The jtbl RECONCILE must also follow the carve: the post-carve draft reconcile (`harvest_verify._jtbl_reconcile`, Phase 29 SESSION-11, 2026-07-22) L4848
+- **§65** — The stranded-draft recovery: BLAST-RADIUS TIERS, and the per-overlay de-macroize that refutes §20's DEF-conflict wall (`tools/demacroize.py` + `tools/blocker_probe.py`, Phase 29 SESSION-16, 2026-07-24) L5030
+- **§65d** — Existing-ladder baseline, measured (do this before building a recovery stage) L5106
+- **§65e** — Two oracles, and the disagreement is the finding (R34 in practice) L5116
+- **§65f** — The de-macroize lever's BOUNDARY, measured: byte-neutral 14 times of 15, and the 15th is why the gate exists L5133
+- **§66b** — A metric parsed out of another tool's prose goes NULL silently when the label changes L5215
+- **§67a** — Run the symbol-set guard BEFORE you pay for a gate (`tools/symcheck.py`, Phase 29 SESSION-18) L5420
+- **§77** — Every extraction tool carries a NARROW hard-coded preamble set; anything outside it silently caps the body's reach. Diff the preamble before you gate. (Phase 29 SESSION-19 — three variants in one session, two different tools) L6099
+- **§3-The** — CANDIDATE gate and the REAL gate need DIFFERENT preambles — keep the difference out of the bank L6139
+- **§79** — For a 0-callee giant, fingerprint by DATA symbols (§71 cannot fire); and the STACK-SLOT ORDER is a declaration-order oracle (Phase 29 SESSION-19, `func_8017BF14` 4,763 ins, cold start → 45/4763) L6235
+- **§82** — Two source-shape oracles from behemoth #6: a duplicated `addiu $aN,$sp,K` across a `jal` means the block was INLINED, and scalar-vs-aggregate decides WHEN a stack slot is allocated (Phase 29 SESSION-19, `func_8017C730` 1,061 ins) L6385
+- **§3-2.** — Scalar vs aggregate decides *when* the slot is allocated L6404
+- **§3-Why** — it survived every candidate gate L6510
+- **§3-THE** — FIX IS MECHANICAL — the tool already holds the answer L6525
+- **§87** — `match_one` COMPILES but never LINKS, so an unresolvable data symbol reads as MATCH; and stored drafts go STALE against the tree (Phase 29 SESSION-20) L6648
+- **§88f** — the missing rung: a RELOCATION gate between `match_one` and the binary L6733
+- **§89a** — MEASURE the write set; do not assert its tier (`tools/blast_radius.py`) L6747
+- **§89b** — the parallel gate farm existed; the family path could not reach it (`tools/sweep_parallel.py`) L6760
+- **§90** — Five tool-integrity laws from one session, each of which changed an answer (Phase 29 SESSION-21, 2026-07-27) L6781
+- **§90a** — A comparison tool MUST share its reference oracle's index space, exactly L6787
+- **§92** — Conforming a DECLARATION: pointer changes are caller-neutral, scalar-WIDTH changes are not (Phase 29 SESSION-21, `tools/conform_decls.py`) L6906
+- **§97** — The gate's own tree hygiene: a refused carve, an unchecked recovery, and a snapshot that captured a dirty tree (Phase 29 SESSION-22) L7081
+- **§105** — A gate's revert must survive an EXCEPTION, not just a failure (Phase 29 T53, `jtbl_family_bank`) L7446
+- **§107** — A lever wired into ONE gate path is a lever most families cannot reach (Phase 29 T56, `func_80144090` 0/136 → 136/136) L7528
+- **§3-Why** — it survived so long: a MASKED oracle will MATCH a wrong symbol L7968
+- **§122** — GATE RAW BEFORE TRANSFORMING; the undo belongs to the WRITER, as a per-edit journal (P30 T0a, 2026-07-30) L8099
+- **§123** — PROPAGATE A FAMILY WITH THE TOOL ITS TIER NEEDS: `dedup_propagate` is h_exact-only; its refusals are statements about the TOOL (P30 wave 1, 2026-07-30) L8131
+- **§126a** — a bare `except: continue` around a coverage-asserting oracle re-creates the silent skip (P30 S28) L8332
+- **§130** — An INCREMENTAL build can report BYTE-IDENTICAL for a change the CLEAN build cannot even LINK (P30 S28, the jr pair) L8501
+- **§132** — The `JR-PAIR-IN-ONE-O0-OBJECT` "wall" was TWO instrument defects: a merged-double span the carve could not see, and a truncated object no rule deleted (P30 S29, `func_8013B83C` + `func_8013BD74`) L8585
+- **§133** — The DEFAULT-FILTER class: three times in one session, a tool silently answered a narrower question than the one asked (P30 S1–S3) L8700
+- **§134** — MULTI-LINE BLINDNESS: one root cause, four faces, in `family_remap`'s preamble scanner (P30 S6, 190 zero-crack families) L8726
+- **§3-The** — splitting/merging rules (each closed a residual, byte-gated) L8868
+- **§137a** — A gate verdict has a TIMESTAMP; re-check it against the draft's mtime L9401
+- **§138** — The propagation lanes: a gate refusal is a DECLARATION, and which lever you owe depends on blast radius L9430
+- **§134** — again, in a second tool — and the waiter rule corrected L9541
+- **Reconciling** — a gate-refused draft: which way you edit depends on WHERE the TU's decl is L9580
+- **§139** — A GATE THAT GREPS FOR VERDICTS MUST ASSERT 1:1 ACCOUNTING; and a `--src` filter must not survive a carve (P30 S38, wave 6: 10 of 16 drafts vanished) L9609
+- **§140** — A METRIC IS NOT A MEASUREMENT UNTIL IT IS REPRODUCIBLE FROM THE COMMITTED TREE (P30 S1e: a phantom regression that gated the session's best lever) L9675
+- **§142** — An open stub whose `h_exact` class is MATCHED elsewhere is FREE. Propagate the body; do not gate a draft. (P30 S39, +7,710 ins in two commands) L9793
+- **§3-The** — measurement (do this before any wave; it is ~20 lines and needs no builds) L9805
+- **§155b** — check the TYPE your oracle returns before comparing against it (S45 p5) L10602
+- **§156** — an ORPHANED reconcile poisons the fleet: `dedup_propagate`'s kept edit (S45 p6/p7) L10655
+- **§158** — The RANGE-EXTENDER: a fourth zero-emission asm lever completes the allocno toolkit (P30 S46 tier-3, `func_8017CE58`, 733 ins) L10727
+- **§160** — THE REACH-15 WAVE HARVEST: an align-1 block move, and the instrument that called it a wall (P30 S47) L10908
+- **§161** — THE RETRY-WAVE HARVEST: a jump table indexed from zero, and two allocator traps (P30 S47) L10984
+- **§162** — S48 WAVE-1 HARVEST (P30, 2026-08-11): the reach-ordered sibling campaign's first 12 targets L11029
+- **§163** — S48 WAVES 2-3 HARVEST (P30, 2026-08-11/12): the five that were byte-probed and are actionable L11775
+- **§165** — S48 WAVE-4 HARVEST (P30, 2026-08-12): banked the same day the wave landed L13717
+- **§166** — THE DESTINATION-TU ORACLE (P30 S48): the seven-attempt bug that was never codegen L14930
+- **§167** — S48 WAVE-5/6 HARVEST (P30, 2026-08-12): the saturation point L14986
+- **§176e** — SYMBOL IDENTITY IS COMPUTABLE OFFLINE (P31 S52): `tools/reloc_identity.py` L16880
+- **§3-A.** — The seven under-reporting holes (all in `gate_main`, all the same shape) L17014
+- **§3-C2.** — RECONCILE BEFORE THE FIRST GATE — a parked draft gets HARDER to bank, not easier L17061
+- **§3-D.** — The measured cost shape, and what to build next L17084
+- **§176i** — WHAT A STATIC PRE-GATE CHECK CAN AND CANNOT PROVE (P31 S52, wave Q) L17102
+- **§179** — IDIOMS MINED FROM THE WAVE P/Q JOURNALS (P31 S52, harvest pass) L17341
+- **§179-G** — 🟡 A PIN CAN **CREATE** A COMBINE `LOG_LINK` AND DELETE AN `andi` (sixth RC-5 channel, n=1) L17570
+- **§176c** — MAIN (SLUS_007.26) CANNOT BE GATED INCREMENTALLY L17637
+- **§180** — THE LEFTOVER-DRAFT HARVEST: RE-VERIFY WHAT YOU ALREADY HAVE BEFORE DRAFTING ANYTHING NEW L17828
+- **§180b** — WHAT THE PRE-GATE LADDER ACTUALLY FINDS IN A COLD PILE (the shape of integration debt) L17857
+- **§181** — WHAT A WAVE'S GATE ACTUALLY REJECTS (P31 S53, measured on wave R's 45-draft main pile) L17894
+- **§184** — COMMENT-BLINDNESS IS A DEFECT CLASS, NOT A BUG (P31 S53: three tools, one root cause, one session) L18047
+- **§187** — 🔴 "SAME SOURCE" IS NOT "SAME OBJECT": THE SDK BUILD AND THE GAME BUILD DISAGREE ON GTE NOPS L18153
+- **§190** — THREE PRESCRIPTIONS FROM THE SAME HARVEST (weaker evidence than §189, honestly labelled) L18316
+- **§191** — WHAT THIS HARVEST DID **NOT** BANK (4 rejected, 4 narrowed) — recorded so it is not re-derived L18353
+- **§192** — THE PRE-GATE LADDER WAS MAIN-ONLY, AND NOBODY COULD SEE IT (P31 S54) L18375
+- **§193** — THE WAVE-T HARVEST (P31 S54): 71 index_gap reports -> 9 laws, 5 rejected, 61 already-covered L18440
+- **§193-A** — The wave card ships only OPEN-set pointers and discards the atlas's BANKED one — `exemplar`/`sibs` are stubs 100% by construction (tools/atlas.py:96/657), while `seed.ref` (matched pool, atlas.py:505-536) is dropped at build_wave_atlas.py:143 L18457
+- **§193-G** — §164-54's "scope to ≥4 arms" bound is byte-wrong — the dispatch-topology oracle goes live at THREE case nodes (`balance_case_nodes` splits at `i > 2`), but only for a signed-after-promotion index L18761
+- **§193-I** — A DECLARED AGGREGATE LOCAL HAS AN 8-BYTE FRAME STRIDE — CEIL(size,8), NOT size. N ARRAYS THEREFORE COST 8·k MORE THAN ONE HAND-LAID STRUCT (k = how many of them have size mod 8 ≠ 0), AND THE TELL IS IDENTICAL INSTRUCTION COUNT WITH EVERY $sp DISPLACEMENT SHIFTED BY THE SAME CONSTANT. L18862
+- **§193-REJECTED** — what this harvest did NOT bank (recorded so it is not re-derived) L18921
+- **§194** — THE WAVE-U HARVEST (P31 S54): 64 index_gap reports -> 14 laws, 5 rejected, 44 already-covered L18948
+- **§194-E** — The wave card's `exemplar` is the TARGET ITSELF on 42/73 wave-U and 36/71 wave-T cards — a construction consequence of `atlas.py:657` (exemplar = max-nins OPEN member) meeting `build_wave_atlas.py:166` (one card per gid); and the shipped §193-A `seed_ref` is same-binary on 0/51, so no card field can ever name a destination-TU sibling L19173
+- **§194-G** — Reading the integer half of a 16.16 stack aggregate: REGISTER-LIVENESS, not the C spelling, decides `sra` vs `lhu` — and the break is count-neutral L19283
+- **§194-K** — Blind sched1's alias oracle with a second SET of a pointer pseudo — the first zero-byte, non-volatile, dependence-CREATING lever (corrects §167-05's "volatile is the only door"; fourth consumer of reg_n_sets) L19459
+- **§194-REJECTED** — what this harvest did NOT bank (recorded so it is not re-derived) L19703
+- **§195** — THE WAVE-V HARVEST (P31 S54): 67 index_gap reports -> 14 laws, 9 rejected, 76 already-covered L19724
+- **§195-I** — §145(b) AMENDED — the pointer-bump `addiu` is saved by cse, not combine: ANY second SET of a pseudo in the address's equivalence chain (in-place `p += K`, §145(b)'s `p = r;` copy, or an asm re-tie) kills the fold; the pass is cse and the gate is `invalidate`'s `reg_tick++` L20172
+- **§195-M** — Frame `vars` is a SEQUENTIAL bump-allocation, not a flat sum: §193-I's CEIL(aggregate,8) term and §165-03/§167-06's 8×orphan term are the SAME frame_offset walk at two different compiler stages, and each stage re-CEILs frame_offset to 8 before it allocates L20385
+- **§195-REJECTED** — what this harvest did NOT bank (recorded so it is not re-derived) L20481
+- **§197** — THE WAVE-W HARVEST (P31 S54): 68 index_gap reports -> 4 laws, 3 rejected, 41 already-covered L20582
+- **§199** — THE WAVE-X HARVEST (P31 S54/S55): 63 index_gap reports -> 7 laws, 2 rejected, 56 already-covered L20722
+- **§199-C** — A NEGATIVE CONSTANT MULTIPLY ALWAYS TAKES expmed's negate_variant — but whether you ever SEE the neg is decided by COMBINE, and for an EVEN |K| it never disappears L20827
+- **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` L20875
+- **§199-G** — At TWO case nodes the switch-vs-if oracle is not blind — but the tell is ALL tests positive + a trailing `j default`, NOT the first test's polarity L21048
+- **§201** — THE WAVE-Y HARVEST (P31 S55): 67 gap reports -> 5 laws, 8 rejected, 53 already-covered L21163
+- **§204** — THE WAVE-Z HARVEST (P31 S56): 82 gap reports -> 5 laws, 16 rejected, 30 already-covered L21562
+- **§207** — THE WAVE ab–ag HARVEST (P31 S58): 278 byte-banked notes → 25 laws, 103 self-reported no-gap L22196
+- **§233** — THE WAVE aa–bg HARVEST (P31 S58b): 1,101 byte-banked notes → 24 new laws, 21 addenda, ~700 already-covered L23287
+- **§236** — THE DECLARATION LAYER IS THE DOMINANT BANK-BLOCKER: NINE WAYS A BYTE-PERFECT BODY FAILS THE GATE (P31 S58b) L23401
+- **§247** — TWO BRANCHES TO **ONE** LABEL MEANS THE SOURCE CONDITION IS NEGATED (P31 S58b) L23847
+- **§254** — THE DEAD PARAMETER IS A REGISTER-PLACEMENT TOOL **(single observation — not yet cross-confirmed)** (P31 S58b) L24041
+- **§259** — THE DISCARD LEDGER FOR THE aa–bg HARVEST (P31 S58b): WHAT WAS MINED AND REJECTED, AND WHY L24698
+- **§260-A** — STAGE 2 IS PROVEN, AND THE WHOLE jtbl PIPELINE IS AUTOMATED AT THE GATE (P31 S59, same day) L24787
+- **§261** — THE -O0 ORACLE: DERIVE THE OPT LEVEL FROM THE TARGET, AND `$fp` IS NOT THE TELL (P31 S59) L24823
+- **§267** — ADDENDA HARVESTED FROM WAVES at/bh/bk/bl (P31 S59b) L25094
+- **ADD-9** — → §213-3 / §217 addendum — ADJACENT PRE-CALL FRAME STORES ARE ONE AGGREGATE; THE UNESCAPED SCALAR NEIGHBOR IS DEAD-STORED L25189
+- **§269** — ADDENDA HARVESTED FROM WAVES ax/bm (P31 S59c) L25313
+- **§271** — Ordinal IMM pairing: text order is NOT emission order; emit CANDIDATES, let the oracle pick (P31 S59) L25551
+- **§273** — A standalone compile is the WRONG oracle for a TU-destined draft (P31 S59) L25593
+- **§274** — ADDENDA HARVESTED FROM 18 WAVES (P31 S60): 315 candidates, 255 already covered, 21 sharpenings, 3 new laws L25608
+- **§278** — ADDENDA HARVESTED FROM WAVE cf (P31 S60): 34 candidates, 13 already covered, 8 sharpenings, 4 new laws L26599
+- **§283** — ADDENDA HARVESTED FROM THE 36-WAVE BATCH (P31 S60): 1,216 candidates, 859 already covered, 46 sharpenings, 9 new laws L27095
+- **§287** — A STACK-FRAME HOLE BELOW TWO ADDRESS-TAKEN AGGREGATE LOCALS IS A LEADING PAD MEMBER OF ONE COMBINED STRUCT, NOT SEPARATE LOCALS OR A REGISTER PIN (P31 S60/dj; `func_8017D104`, ov_SC06_027, byte-proven 47/47) (P31 S60; waves #, byte-proven) L29060
+- **§293** — THE "WHOLE-OBJECT GATE NEEDS EVERY SIBLING" LAW, WRITTEN PROPERLY: IT IS THREE LAWS, AND THE LOAD-BEARING ONE IS "THE BASELINE, NOT THE SIBLINGS" (P31 S61; byte-proven on 15 binaries in one night) L29083
+- **§294** — ADDENDA HARVESTED FROM THE S61 GEN0/MAXTOK/MAIN/DEEPSEEK BATCH (waves ab8/ab16/ab24/ab32 · g0a–g0f · m0a · ds1/ds2): 99 candidates, 52 covered, 15 notes → 10 addenda, 29 notes → 5 new laws (§295–§299), 3 refuted L29133
+- **§303** — MODULE ISLAND TABLES: DERIVE THE PADS AT BUILD TIME, PEEL NOTHING — THE §154-A/§260 "island-pads"/"island-blocked" WALLS DISSOLVE (P31 S62 T3a; byte-proven md_SC03_076 func_801F0A9C + func_801F0F28, sha 9a165e36…) L29737
+- **§305** — "CARVE-REFUSED" AT GATE TIME IS THREE NAMED, DETERMINISTIC CLASSES — NONE OF THEM A CARVE (P31 S62 T3; 28 resolver drafts autopsied 28/28) L29796
### process, measurement & doctrine (107)
@@ -1004,103 +1007,103 @@
- **§3-h** — _exact OVER-COUNTS ×134 — verify shareability before crediting a class's "reach-134" (R14) L2177
- **§28c** — The close=0 recovery is NOT fully exhausted (§26 corrected, R14); + the dedup_propagate registry-skip recovery (Phase 22 T2) L2352
- **§31-triage** — R17 applies to CODEGEN residuals, never to a compile ERROR (Phase 26 session 7, Drew asked) L2693
-- **§41a** — v3.1: the def-side wall was ~71% TOOL-shaped — the five measured defects + the laws that dissolve them (Phase 25 T6, Fable5, 2026-07-09) L2754
-- **§41b** — T7 execution: the object-only probe OVER-counts BANKABLE by two link/rodata classes (Phase 25 T7-M1, 2026-07-10) L2809
-- **§41b** — addendum — M4 "reconcile_decls" tier is ALSO a probe over-count: 0/8 mechanical (Phase 25 T7-M4, 2026-07-10) L2858
-- **§53** — SWEEP A FAMILY WITH THE TOOL ITS EXEMPLAR NEEDED: the jr/switch carve, and how omitting it manufactured the "families don't template" doctrine (Phase 28 T1, 2026-07-15) L4028
-- **§3-The** — meta-lesson (R35, and why this one is expensive) L4078
-- **§55** — Core-crack wave levers + the GATE-ORCHESTRATION law (Phase 29 T3, 13-agent ultracode wave, 2026-07-17) L4093
-- **§55b** — THE GATE-ORCHESTRATION LAW (3 traps, ~3.5h lost; all recovered, 0 data lost) L4122
-- **§57a** — Two NSD corrections + the SURGICAL-ONLY law + the honest broad-sweep yield (Phase 29, 2026-07-18) L4303
-- **§58** — match_one MATCH ≠ BANK: the four blind spots + the crack-wave reconcile-before-bank law (Phase 29 crack-wave, 2026-07-18) L4343
-- **§60** — Classify the residual, don't rank it: the deterministic residual→class classifier and what it measured about the backlog (Phase 29 Task-13A, 2026-07-21) L4407
-- **What** — it measured — the whole open backlog, byte-grounded L4431
-- **§3-The** — parallel-probe race this surfaced L4463
-- **§61b** — The jtbl gate stage: built, and the ORDERING law it exposed (Phase 29 Task-14 stage 4, 2026-07-21) L4658
-- **§62** — The jtbl RECONCILE must also follow the carve: the post-carve draft reconcile (`harvest_verify._jtbl_reconcile`, Phase 29 SESSION-11, 2026-07-22) L4833
-- **§63** — UPDATE (Phase 29 SESSION-14) — `fix_header_decl`'s "SAFE" verdict is FLEET-BLIND; it MUST be R22-validated L5000
-- **§65** — The stranded-draft recovery: BLAST-RADIUS TIERS, and the per-overlay de-macroize that refutes §20's DEF-conflict wall (`tools/demacroize.py` + `tools/blocker_probe.py`, Phase 29 SESSION-16, 2026-07-24) L5015
-- **§65a** — The blast-radius taxonomy (makes §61's law structural instead of remembered) L5030
-- **§65d** — Existing-ladder baseline, measured (do this before building a recovery stage) L5091
-- **§65e** — Two oracles, and the disagreement is the finding (R34 in practice) L5101
-- **§65f** — The de-macroize lever's BOUNDARY, measured: byte-neutral 14 times of 15, and the 15th is why the gate exists L5118
-- **§66c** — Before a wave, verify the FUEL exists; an "already attempted" set built from the wrong directory lies in BOTH directions L5217
-- **§66d-5** — `residual_class`'s "structural ⇒ permuter CPU is waste" is WRONG for schedule permutations (measured, Phase 29 SESSION-18) L5491
-- **§3-The** — honest fix was source-level and cheap L5750
-- **§3-The** — residual, and the honest read L6260
-- **§83** — The parameterised-repeat law, the spill-area trap, and why a per-case edit cannot move a per-case symptom (Phase 29 SESSION-20, `func_80183814` 5,122 ins, cold-ish start → 36 structural / 99.3%) L6412
-- **Scope** — , measured (do not over-generalise — §80) L6518
-- **§3-Two** — ladder lessons banked with it L6528
-- **§3-Do** — the WHOLE axis in one edit, then R22 once L6567
-- **§3-THE** — LAW: all-or-nothing PER FAMILY L6600
-- **§88b** — the `slti` literal-position law (extends §78 to comparisons) L6686
-- **§88e** — a wrong diagnosis, refuted properly (the model for how to treat an inherited lever) L6708
-- **§89a** — MEASURE the write set; do not assert its tier (`tools/blast_radius.py`) L6732
-- **§90d** — Do not measure a live wave's drafts (§87 in real time) L6810
-- **§98** — `conform_decls` had three defects, and only the third needed R22 to find (Phase 29 SESSION-22, `func_8014CF04`) L7113
-- **§106** — Persist the MEASUREMENT, derive the POLICY: a stored route let a stale file out-vote the live table (Phase 29 T54, `residual_class._ROUTE`) L7470
-- **§125** — Split the CARVE from the BODY before calling a jr residue a wall — and measure it by SHA from a CLEAN tree (P30 SESSION-28; **this section's first draft was WRONG and the method caught it**) L8206
-- **§3-The** — meta-lesson L8257
-- **Wave** — economics (measured, for the next batch's sizing) L8953
-- **§136b** — A prior wave's "genuine byte-DIFF" verdict is NOT reliable evidence (4 of 4 refuted) L9033
-- **§136g** — When the index points at the WRONG lever: two byte-refuted routings (func_801863B4) L9211
-- **§136h** — CORRECTION: the zero-crack pool does NOT "refill with cheap work" (my error, byte-measured) L9240
-- **§136j** — The failure MIX flips with function size (measured across four bands, one session) L9302
-- **Rank** — the lane by measured concentration, not by class count L9481
-- **§140** — A METRIC IS NOT A MEASUREMENT UNTIL IT IS REPRODUCIBLE FROM THE COMMITTED TREE (P30 S1e: a phantom regression that gated the session's best lever) L9660
-- **§3-The** — measurement (do this before any wave; it is ~20 lines and needs no builds) L9790
-- **§3-And** — the report-vs-bytes lesson attached to it L9822
-- **§146** — RE-MEASURE A WALL BEFORE YOU RESPECT IT. Both "permanent" giants fell to drafts already on disk. (P30 S6, +50,094 ins) L9977
-- **§147** — The three-stratum FRAME LAW, and four "stop searching" verdicts (P30 S42, `func_8017C294`, serial run) L10036
-- **§3-C.** — Inner-block declaration does NOT delay slot allocation — BYTE-REFUTED L10068
-- **§3-D.** — "Cheap fuel" that was never probed: 0 of 31 templatable L10293
-- **§3-Two** — corrections to the record L10345
-- **§3-The** — two fallouts, and how to close them (both measured, in order) L10395
-- **What** — does NOT work (14 byte-measured probes) L10486
-- **§157** — the cheap-tier size cliff, measured (S45 p6) L10687
-- **§162** — The cross-jump "CALL veto" is a COUNT law, not a CALL law (BOUNDS §88a; P30 S48, `func_80189540`) L11302
-- **§3-The** — law L11549
-- **DIAGNOSTIC** — TELL — two faces, one law L11591
-- **§163** — S48 WAVES 2-3 HARVEST (P30, 2026-08-11/12): the five that were byte-probed and are actionable L11760
-- **§163z** — THE UNVETTED REMAINDER (do not cite as law; each needs a dedupe pass) L11828
-- **§164z** — REFUTED CLAIMS: do NOT re-derive these L13636
-- **§165z** — REFUTED THIS WAVE: do NOT re-derive L14871
-- **§167z** — REFUTED IN WAVES 5/6: do NOT re-derive L16167
-- **§168** — THE COUSIN TIER (P30 S49, 2026-08-12): h_seq's exact-hash brittleness, measured — and the similarity map above it L16224
-- **§176g** — SIZE A WAVE BY INSTRUCTIONS, NOT BY CARDS (P31 S52 — the adopted doctrine) L16953
-- **§176h** — THE BATCH-SUBSTITUTION HAZARD MAP (P31 S52): seven holes, three wrong fixes, one law L16991
-- **§3-D.** — The measured cost shape, and what to build next L17069
-- **§176j-2** — THE REPAIR PASS, MEASURED (do this instead of resuming) L17145
-- **§176-C** — 🔴 WALL REFUTATION: a hard-register pin CANNOT schedule around a call, because of a genuine gcc-2.7.2 bug L17709
-- **§176-E** — Two cheap source spellings, both cc1-probed L17761
-- **§180** — THE LEFTOVER-DRAFT HARVEST: RE-VERIFY WHAT YOU ALREADY HAVE BEFORE DRAFTING ANYTHING NEW L17813
-- **§181** — WHAT A WAVE'S GATE ACTUALLY REJECTS (P31 S53, measured on wave R's 45-draft main pile) L17879
-- **§182** — §177's HONEST NEGATIVE: the epilogue lever cracked 4 of 16, and the `800c3` cluster held L17935
-- **§183** — THE DECLARATION-RECONCILIATION PLAYBOOK (P31 S53, measured on 20 byte-verified drafts) L17961
-- **§185** — EDIT THE SIDE THAT IS CHEAP TO VERIFY, AND CHECK A TU RETYPE AT ITS USE SITES L18060
-- **§190** — THREE PRESCRIPTIONS FROM THE SAME HARVEST (weaker evidence than §189, honestly labelled) L18301
-- **§194-A** — A zero-byte scheduling fence goes AFTER the defining statement to make that computation emit FIRST in its block — and the barrier predicate is `volatile`-or-colon-less, not the `"memory"` clobber (COMPLEMENTS §165-40; does not refute it) L18950
-- **§194-D** — Declared width of a computed-value local is a sched1 dial (count-neutral) — a replication + attribution correction of §165-17, NOT a new argument-register law L19117
-- **§195-J** — GTE / PsyQ op CALL-vs-INLINE is a PER-SITE SOURCE FACT, not a TU style — both forms coexist in one TU (measured in 2 TUs), and the tell is the target's own opcodes (`lwc2`/`sqr`/`swc2` vs `jal`), not the sibling. Costs -8 ins on func_8018505C. Corollary: the game's inline `sqr` macro emits TWO hazard nops, the SDK's `Square0` body emits ONE — so the inline form is provably not `Square0` inlined (a second instance of §187's SDK-vs-game GTE nop divergence). L20222
-- **§201-E** — §194-J-2 — The `last_mem_set` deletion window is measured in SOURCE/expand order, not in the printed stream; a foreign store moved between the pair in C source is a real lever, and `volatile` is not always the better one L21368
-- **§230** — THE ANCHOR PROBE: with `%hi`/`%lo` masked, the surviving `addiu` deltas tell you which assignment was written first **(single observation — not yet cross-confirmed)** (P31 S58) L23124
-- **§257** — THE DEAD-END LEDGER (P31 S58b): ELEVEN LEVERS THAT MEASURED NULL OR BACKFIRED L24110
-- **§194-B** — / §209 addendum (P31 S58b) — TWO MORE INSTANCES, AND THE BOUND IS NOW REFUTED FOUR WAYS L24179
-- **§266** — THE INERT-RIDER LAW: A LEVER IS ONLY CITABLE WHEN ITS SOLO REMOVAL BREAKS THE MATCH (P31 S59b; measured 4-of-8 on this batch) L25039
-- **ADD-4** — → §167-37 addendum — THE FIFTH PRECONDITION, NOW MEASURED: DOWNSTREAM FIELD RE-READS ⇒ NAME IT **AND** STORE **INSIDE** THE ARM L25353
-- **ADD-9** — → §255 "AND CASE-BODY PLACEMENT" bound / §222-addendum-3 — ON A LARGE SPARSE TREE, BODIES FOLLOW **SOURCE** ORDER (measured by a one-word probe) L25430
-- **ADDENDUM** — to §172b-1 — TWO PLACEMENT DIALS THE PROMOTION LAW DOESN'T NAME: NARROW THE COUNTER'S DECLARED TYPE, AND MOVE THE CAST INTO THE LOOP BODY L26059
-- **What** — I could not verify L27033
-- **ADDENDUM** — to §164-75 — the fold-reassociation law also fires at a variable's INITIALIZER, not only a later expression L27090
-- **What** — I could not verify L27607
-- **ADDENDUM** — to §153 / §236-5 (func_801A419C, md_SC07_003 — waves di and dl, corroborating; refutes a contradicted dj-wave card) L27824
-- **What** — I could not verify L28064
-- **ADDENDUM** — to §174 Law 4 (func_8017E9A8, ov_SC06_015) L28084
-- **ADDENDUM** — the zero-emission-asm family gains a REF-SLIDER PLACEMENT LAW and a paired RESTORER (func_800CB900, md_MAIN_026) L28124
-- **What** — I could not verify L28622
-- **What** — I could not verify L28928
-- **§293** — THE "WHOLE-OBJECT GATE NEEDS EVERY SIBLING" LAW, WRITTEN PROPERLY: IT IS THREE LAWS, AND THE LOAD-BEARING ONE IS "THE BASELINE, NOT THE SIBLINGS" (P31 S61; byte-proven on 15 binaries in one night) L29068
-- **§294** — ADDENDA HARVESTED FROM THE S61 GEN0/MAXTOK/MAIN/DEEPSEEK BATCH (waves ab8/ab16/ab24/ab32 · g0a–g0f · m0a · ds1/ds2): 99 candidates, 52 covered, 15 notes → 10 addenda, 29 notes → 5 new laws (§295–§299), 3 refuted L29118
+- **§41a** — v3.1: the def-side wall was ~71% TOOL-shaped — the five measured defects + the laws that dissolve them (Phase 25 T6, Fable5, 2026-07-09) L2769
+- **§41b** — T7 execution: the object-only probe OVER-counts BANKABLE by two link/rodata classes (Phase 25 T7-M1, 2026-07-10) L2824
+- **§41b** — addendum — M4 "reconcile_decls" tier is ALSO a probe over-count: 0/8 mechanical (Phase 25 T7-M4, 2026-07-10) L2873
+- **§53** — SWEEP A FAMILY WITH THE TOOL ITS EXEMPLAR NEEDED: the jr/switch carve, and how omitting it manufactured the "families don't template" doctrine (Phase 28 T1, 2026-07-15) L4043
+- **§3-The** — meta-lesson (R35, and why this one is expensive) L4093
+- **§55** — Core-crack wave levers + the GATE-ORCHESTRATION law (Phase 29 T3, 13-agent ultracode wave, 2026-07-17) L4108
+- **§55b** — THE GATE-ORCHESTRATION LAW (3 traps, ~3.5h lost; all recovered, 0 data lost) L4137
+- **§57a** — Two NSD corrections + the SURGICAL-ONLY law + the honest broad-sweep yield (Phase 29, 2026-07-18) L4318
+- **§58** — match_one MATCH ≠ BANK: the four blind spots + the crack-wave reconcile-before-bank law (Phase 29 crack-wave, 2026-07-18) L4358
+- **§60** — Classify the residual, don't rank it: the deterministic residual→class classifier and what it measured about the backlog (Phase 29 Task-13A, 2026-07-21) L4422
+- **What** — it measured — the whole open backlog, byte-grounded L4446
+- **§3-The** — parallel-probe race this surfaced L4478
+- **§61b** — The jtbl gate stage: built, and the ORDERING law it exposed (Phase 29 Task-14 stage 4, 2026-07-21) L4673
+- **§62** — The jtbl RECONCILE must also follow the carve: the post-carve draft reconcile (`harvest_verify._jtbl_reconcile`, Phase 29 SESSION-11, 2026-07-22) L4848
+- **§63** — UPDATE (Phase 29 SESSION-14) — `fix_header_decl`'s "SAFE" verdict is FLEET-BLIND; it MUST be R22-validated L5015
+- **§65** — The stranded-draft recovery: BLAST-RADIUS TIERS, and the per-overlay de-macroize that refutes §20's DEF-conflict wall (`tools/demacroize.py` + `tools/blocker_probe.py`, Phase 29 SESSION-16, 2026-07-24) L5030
+- **§65a** — The blast-radius taxonomy (makes §61's law structural instead of remembered) L5045
+- **§65d** — Existing-ladder baseline, measured (do this before building a recovery stage) L5106
+- **§65e** — Two oracles, and the disagreement is the finding (R34 in practice) L5116
+- **§65f** — The de-macroize lever's BOUNDARY, measured: byte-neutral 14 times of 15, and the 15th is why the gate exists L5133
+- **§66c** — Before a wave, verify the FUEL exists; an "already attempted" set built from the wrong directory lies in BOTH directions L5232
+- **§66d-5** — `residual_class`'s "structural ⇒ permuter CPU is waste" is WRONG for schedule permutations (measured, Phase 29 SESSION-18) L5506
+- **§3-The** — honest fix was source-level and cheap L5765
+- **§3-The** — residual, and the honest read L6275
+- **§83** — The parameterised-repeat law, the spill-area trap, and why a per-case edit cannot move a per-case symptom (Phase 29 SESSION-20, `func_80183814` 5,122 ins, cold-ish start → 36 structural / 99.3%) L6427
+- **Scope** — , measured (do not over-generalise — §80) L6533
+- **§3-Two** — ladder lessons banked with it L6543
+- **§3-Do** — the WHOLE axis in one edit, then R22 once L6582
+- **§3-THE** — LAW: all-or-nothing PER FAMILY L6615
+- **§88b** — the `slti` literal-position law (extends §78 to comparisons) L6701
+- **§88e** — a wrong diagnosis, refuted properly (the model for how to treat an inherited lever) L6723
+- **§89a** — MEASURE the write set; do not assert its tier (`tools/blast_radius.py`) L6747
+- **§90d** — Do not measure a live wave's drafts (§87 in real time) L6825
+- **§98** — `conform_decls` had three defects, and only the third needed R22 to find (Phase 29 SESSION-22, `func_8014CF04`) L7128
+- **§106** — Persist the MEASUREMENT, derive the POLICY: a stored route let a stale file out-vote the live table (Phase 29 T54, `residual_class._ROUTE`) L7485
+- **§125** — Split the CARVE from the BODY before calling a jr residue a wall — and measure it by SHA from a CLEAN tree (P30 SESSION-28; **this section's first draft was WRONG and the method caught it**) L8221
+- **§3-The** — meta-lesson L8272
+- **Wave** — economics (measured, for the next batch's sizing) L8968
+- **§136b** — A prior wave's "genuine byte-DIFF" verdict is NOT reliable evidence (4 of 4 refuted) L9048
+- **§136g** — When the index points at the WRONG lever: two byte-refuted routings (func_801863B4) L9226
+- **§136h** — CORRECTION: the zero-crack pool does NOT "refill with cheap work" (my error, byte-measured) L9255
+- **§136j** — The failure MIX flips with function size (measured across four bands, one session) L9317
+- **Rank** — the lane by measured concentration, not by class count L9496
+- **§140** — A METRIC IS NOT A MEASUREMENT UNTIL IT IS REPRODUCIBLE FROM THE COMMITTED TREE (P30 S1e: a phantom regression that gated the session's best lever) L9675
+- **§3-The** — measurement (do this before any wave; it is ~20 lines and needs no builds) L9805
+- **§3-And** — the report-vs-bytes lesson attached to it L9837
+- **§146** — RE-MEASURE A WALL BEFORE YOU RESPECT IT. Both "permanent" giants fell to drafts already on disk. (P30 S6, +50,094 ins) L9992
+- **§147** — The three-stratum FRAME LAW, and four "stop searching" verdicts (P30 S42, `func_8017C294`, serial run) L10051
+- **§3-C.** — Inner-block declaration does NOT delay slot allocation — BYTE-REFUTED L10083
+- **§3-D.** — "Cheap fuel" that was never probed: 0 of 31 templatable L10308
+- **§3-Two** — corrections to the record L10360
+- **§3-The** — two fallouts, and how to close them (both measured, in order) L10410
+- **What** — does NOT work (14 byte-measured probes) L10501
+- **§157** — the cheap-tier size cliff, measured (S45 p6) L10702
+- **§162** — The cross-jump "CALL veto" is a COUNT law, not a CALL law (BOUNDS §88a; P30 S48, `func_80189540`) L11317
+- **§3-The** — law L11564
+- **DIAGNOSTIC** — TELL — two faces, one law L11606
+- **§163** — S48 WAVES 2-3 HARVEST (P30, 2026-08-11/12): the five that were byte-probed and are actionable L11775
+- **§163z** — THE UNVETTED REMAINDER (do not cite as law; each needs a dedupe pass) L11843
+- **§164z** — REFUTED CLAIMS: do NOT re-derive these L13651
+- **§165z** — REFUTED THIS WAVE: do NOT re-derive L14886
+- **§167z** — REFUTED IN WAVES 5/6: do NOT re-derive L16182
+- **§168** — THE COUSIN TIER (P30 S49, 2026-08-12): h_seq's exact-hash brittleness, measured — and the similarity map above it L16239
+- **§176g** — SIZE A WAVE BY INSTRUCTIONS, NOT BY CARDS (P31 S52 — the adopted doctrine) L16968
+- **§176h** — THE BATCH-SUBSTITUTION HAZARD MAP (P31 S52): seven holes, three wrong fixes, one law L17006
+- **§3-D.** — The measured cost shape, and what to build next L17084
+- **§176j-2** — THE REPAIR PASS, MEASURED (do this instead of resuming) L17160
+- **§176-C** — 🔴 WALL REFUTATION: a hard-register pin CANNOT schedule around a call, because of a genuine gcc-2.7.2 bug L17724
+- **§176-E** — Two cheap source spellings, both cc1-probed L17776
+- **§180** — THE LEFTOVER-DRAFT HARVEST: RE-VERIFY WHAT YOU ALREADY HAVE BEFORE DRAFTING ANYTHING NEW L17828
+- **§181** — WHAT A WAVE'S GATE ACTUALLY REJECTS (P31 S53, measured on wave R's 45-draft main pile) L17894
+- **§182** — §177's HONEST NEGATIVE: the epilogue lever cracked 4 of 16, and the `800c3` cluster held L17950
+- **§183** — THE DECLARATION-RECONCILIATION PLAYBOOK (P31 S53, measured on 20 byte-verified drafts) L17976
+- **§185** — EDIT THE SIDE THAT IS CHEAP TO VERIFY, AND CHECK A TU RETYPE AT ITS USE SITES L18075
+- **§190** — THREE PRESCRIPTIONS FROM THE SAME HARVEST (weaker evidence than §189, honestly labelled) L18316
+- **§194-A** — A zero-byte scheduling fence goes AFTER the defining statement to make that computation emit FIRST in its block — and the barrier predicate is `volatile`-or-colon-less, not the `"memory"` clobber (COMPLEMENTS §165-40; does not refute it) L18965
+- **§194-D** — Declared width of a computed-value local is a sched1 dial (count-neutral) — a replication + attribution correction of §165-17, NOT a new argument-register law L19132
+- **§195-J** — GTE / PsyQ op CALL-vs-INLINE is a PER-SITE SOURCE FACT, not a TU style — both forms coexist in one TU (measured in 2 TUs), and the tell is the target's own opcodes (`lwc2`/`sqr`/`swc2` vs `jal`), not the sibling. Costs -8 ins on func_8018505C. Corollary: the game's inline `sqr` macro emits TWO hazard nops, the SDK's `Square0` body emits ONE — so the inline form is provably not `Square0` inlined (a second instance of §187's SDK-vs-game GTE nop divergence). L20237
+- **§201-E** — §194-J-2 — The `last_mem_set` deletion window is measured in SOURCE/expand order, not in the printed stream; a foreign store moved between the pair in C source is a real lever, and `volatile` is not always the better one L21383
+- **§230** — THE ANCHOR PROBE: with `%hi`/`%lo` masked, the surviving `addiu` deltas tell you which assignment was written first **(single observation — not yet cross-confirmed)** (P31 S58) L23139
+- **§257** — THE DEAD-END LEDGER (P31 S58b): ELEVEN LEVERS THAT MEASURED NULL OR BACKFIRED L24125
+- **§194-B** — / §209 addendum (P31 S58b) — TWO MORE INSTANCES, AND THE BOUND IS NOW REFUTED FOUR WAYS L24194
+- **§266** — THE INERT-RIDER LAW: A LEVER IS ONLY CITABLE WHEN ITS SOLO REMOVAL BREAKS THE MATCH (P31 S59b; measured 4-of-8 on this batch) L25054
+- **ADD-4** — → §167-37 addendum — THE FIFTH PRECONDITION, NOW MEASURED: DOWNSTREAM FIELD RE-READS ⇒ NAME IT **AND** STORE **INSIDE** THE ARM L25368
+- **ADD-9** — → §255 "AND CASE-BODY PLACEMENT" bound / §222-addendum-3 — ON A LARGE SPARSE TREE, BODIES FOLLOW **SOURCE** ORDER (measured by a one-word probe) L25445
+- **ADDENDUM** — to §172b-1 — TWO PLACEMENT DIALS THE PROMOTION LAW DOESN'T NAME: NARROW THE COUNTER'S DECLARED TYPE, AND MOVE THE CAST INTO THE LOOP BODY L26074
+- **What** — I could not verify L27048
+- **ADDENDUM** — to §164-75 — the fold-reassociation law also fires at a variable's INITIALIZER, not only a later expression L27105
+- **What** — I could not verify L27622
+- **ADDENDUM** — to §153 / §236-5 (func_801A419C, md_SC07_003 — waves di and dl, corroborating; refutes a contradicted dj-wave card) L27839
+- **What** — I could not verify L28079
+- **ADDENDUM** — to §174 Law 4 (func_8017E9A8, ov_SC06_015) L28099
+- **ADDENDUM** — the zero-emission-asm family gains a REF-SLIDER PLACEMENT LAW and a paired RESTORER (func_800CB900, md_MAIN_026) L28139
+- **What** — I could not verify L28637
+- **What** — I could not verify L28943
+- **§293** — THE "WHOLE-OBJECT GATE NEEDS EVERY SIBLING" LAW, WRITTEN PROPERLY: IT IS THREE LAWS, AND THE LOAD-BEARING ONE IS "THE BASELINE, NOT THE SIBLINGS" (P31 S61; byte-proven on 15 binaries in one night) L29083
+- **§294** — ADDENDA HARVESTED FROM THE S61 GEN0/MAXTOK/MAIN/DEEPSEEK BATCH (waves ab8/ab16/ab24/ab32 · g0a–g0f · m0a · ds1/ds2): 99 candidates, 52 covered, 15 notes → 10 addenda, 29 notes → 5 new laws (§295–§299), 3 refuted L29133
### (unbucketed — title matched no symptom vocabulary) (288)
@@ -1129,269 +1132,269 @@
- **§28a** — decomp.wiki GCC patterns worth trying on BFM giants (decomp.wiki/compilers/GCC, raw at decompals/decompedia; PS1-applicable subset) L2345
- **§31** — THE gcc-2.7.2 CODEGEN MAP: pass → residual → C-lever catalog (Phase 23; 4 Fable5 agents read the compiler source) L2402
- **§36** — Fable5 giant-crack levers (Phase 24 T7 Fable5 batch; accumulates as each lands — full RTL dumps in `.run/t7/fable/`) L2487
-- **§42d** — addendum — wave 4 (rtu_match fan-out over the mapped frontier, 2026-07-10c): 24/26 MATCH, +5 durable levers L3082
-- **§3-B.** — THE EBB RULE — the general form of §46-L2 L3468
-- **§3-E.** — Meta L3518
-- **§50** — Refinements that BOUND §47/§48 (from the `func_80135EB0` wall, 21→6; Phase 26 session 8) L3576
-- **§51a** — The bug class L3636
-- **§51c** — THE METHOD (do not audit by reading the regex) L3662
-- **§51d** — THE LAWS L3677
-- **§51e** — The false-wall pipeline (why this is not just hygiene) L3739
-- **§3-Why** — the wall is (probably) intrinsic L3945
-- **§3-The** — case L4033
-- **§3-The** — rule L4062
-- **§55a** — New byte-proven levers (each from a banked or near draft) L4098
-- **§60a** — What the first DIRECTED grinder run exposed (Phase 29 Task-13B, 2026-07-21) L4472
-- **§60b** — The plateau autopsy's verdict: a `partial` drift is a WRONG DRAFT, not a missing transform (Phase 29 Task-13B close, 2026-07-21) L4510
-- **§66** — Exercise a banking driver's SUCCESS path before pointing it at a wave: the free re-bank test (Phase 29 SESSION-17, 2026-07-24) L5159
-- **§66d-2** — Two operational sharp edges L5289
-- **§66d-3** — Read the ILS per-cycle SERIES, not its final best: a repeated score and a still-falling one look identical in a summary line and mean opposite things L5300
-- **§67** — The arg-copy PLACEMENT lever: launder a parameter into a fresh pseudo AT the statement where the target's copy lands (Phase 29 SESSION-18, `func_8014D820` 25 → 16) L5315
-- **§66d-4** — "ILS converged" means converged FOR THAT WEIGHT PROFILE, not a floor (amends §66d-3; Phase 29 SESSION-18) L5438
-- **§69** — How to attack a behemoth: map it, don't draft it (Phase 29 SESSION-18, `func_80183814`, 5,122 ins) L5569
-- **What** — is left, and what is byte-recorded as SPENT L5766
-- **§3-The** — mechanism, with citations L6037
-- **§3-Two** — diagnosis traps this function proved L6064
-- **Practice** — Practice L6074
-- **§3-The** — drift was an allocation decision, not missing code L6180
-- **§3-The** — economics L6211
-- **§71** — has a blind spot, and this is it L6226
-- **§3-The** — flagged "#1 move" LOST — and why the failure is informative L6302
-- **§78** — 's attribution primitive, run and reproduced L6312
-- **Cold-start** — economics, now complete L6318
-- **Also** — reproduced on this function L6401
-- **§3-And** — the banking footnote (§75a class A, one line) L6405
-- **§83a** — READ THE HEADLINE NUMBER CORRECTLY: a LENGTH drift makes `match_one`'s count meaningless L6419
-- **§83b** — THE LEVER: find the parameterised REPEAT before decoding case-by-case L6427
-- **§83e** — §80 vindicated again, on the same day it was written L6466
-- **§3-The** — conflict L6544
-- **§3-THE** — FAILURE MODE — widening only `engine_core.h` is worse than not starting L6552
-- **§3-The** — precondition, and how to check it in one grep L6559
-- **Reading** — , for the next person L6576
-- **§3-The** — guard refuses a class that largely works L6591
-- **§3-The** — blindness ladder, now complete — FOUR classes `match_one` cannot see L6649
-- **Consequence** — for the backlog ledger L6659
-- **§88** — `cross_jump` will not merge a common suffix containing a CALL; and §78 is scoped to ORDERED comparisons only (Phase 29 SESSION-20, the behemoth close-out) L6674
-- **§88a** — repeated CALL-shaped blocks are left UNMERGED; call-free tails are merged for you L6679
-- **§89** — Two throughput rules the project already had written down and was not following (Phase 29 SESSION-20) L6726
-- **§3-The** — standing sequence L6758
-- **§90b** — "Byte-neutral" is not "wanted": undo on the SUCCESS path too L6789
-- **§90c** — A library-callable function must FAIL CLOSED on an unconfigured module L6799
-- **§90e** — An agent's CONCLUSION and its EVIDENCE fail independently — re-derive the premise, not the fix L6818
-- **§93** — `set -o pipefail` attributes a pipeline failure to the LAST stage, not the failing one (Phase 29 SESSION-21, `func_8014D820`) L6922
-- **§101** — The STALE DEFAULT class: a guard whose cause was removed is a silent skip wearing a safety label (Phase 29 SESSION-22, three instances in one session) L7245
-- **§110** — A unit must define exactly ONE function, and "ends in `;`" does not tell you which line defines it (Phase 29 T65) L7640
-- **§115** — A `func_XXXXXXXX` predicate rots by design: the same name-form assumption in THREE places (Phase 29 T78) L7850
-- **§3-The** — fix moves the DEFINITION, not the stub — and here is why the obvious shortcut fails L7895
-- **§117** — Spell the sibling's symbol from the SIBLING's address, not the exemplar's kind (Phase 29 T82) L7926
-- **§118** — Ordinal (positional) immediate resolution: compare C tokens to the DIFFERING asm uses (Phase 29 T87) L7963
-- **§119** — Two levers on the SAME axis, opposite directions: test the off-diagonal (Phase 29 T89) L7997
-- **§3-The** — wiring trap that cost two attempts L8043
-- **§3-The** — method (keep this) L8213
-- **§3-The** — instrument rules that make its answer trustworthy (this is where I failed) L8223
-- **§3-The** — corrected results (each SHA-verified, from a clean tree, restore re-verified) L8238
-- **§3-The** — instrument trap that hid it (and it is §124's shape again) L8290
-- **§3-The** — mechanics L8299
-- **§3-The** — idiom they kept re-deriving: the constant-offset fold L8356
-- **§127b** — the knowledge was in a SOURCE COMMENT, not the cookbook L8386
-- **§128** — A raw NUL in C source makes grep SILENTLY SKIP the file (P30 S28, 137 files) L8393
-- **§128a** — a negative control must corrupt a SCRATCH COPY, never the tracked file L8425
-- **§3-The** — real blocker underneath, for the record L8477
-- **§3-The** — diagnostic ladder that finally located it (reusable) L8523
-- **Defect** — 1 — a pre-§8e MERGED DOUBLE is not a single-table predecessor L8579
-- **Defect** — 2 — `as` writes a corpse and nothing deletes it L8597
-- **§3-The** — fingerprint, and the 30-second ladder that found it L8607
-- **§3-The** — transferable rule L8628
-- **§132a** — `--like` is for a sibling with NO record; against one that HAS a record it over-derives (P30 S29, `ov_SC07_010`) L8635
-- **§135** — Six byte-verified gcc-2.7.2 idioms from the P30 S6f-h waves (and the two-lane wave shape that found them) L8765
-- **§3-The** — codegen idioms L8770
-- **§3-The** — wave shape that produced these L8819
-- **§136** — The LOCAL-VARIABLE lever: how many C locals, at what scope (P30 wave 4a, 25 byte-verified banks) L8837
-- **§136a** — Blocker capture: classify on the OUTPUT, never on the exit status L8976
-- **§136d** — Four gcc-2.7.2 levers the redraft lane found (each closed a residual no other lever moved) L9094
-- **§136e** — §136c's PRECONDITION, and two more symptom keys (wave 4b batch 3) L9138
-- **§136i** — The drafter model LADDER: Haiku → **Sonnet** → Opus → Fable5 (Drew, 2026-08-03) L9270
-- **§3-The** — triage, cheapest first L9421
-- **THREE** — carry variants hide in one "CARRY-FIXABLE" bucket — and they need different fixes L9490
-- **STEP** — 0 of sibling-first: grep `src/` for a distinctive LITERAL from the `.s` L9546
-- **§3-The** — generalisation — three corollaries worth more than the bug L9626
-- **§3-And** — the inverse-lookup trap, same session L9643
-- **§3-The** — three-line proof (do this before diagnosing any metric movement) L9680
-- **§3-The** — two instrument defects it exposed L9689
-- **§3-Two** — wrong mechanisms I chased first, and why they were wrong L9720
-- **§3-The** — trap that hid it — SAME FUNCTION, TWO ROUTES, ONLY ONE IS FREE L9805
-- **Route** — selection (why `--addr` sometimes says "nothing changed") L9814
-- **§144** — THE LITERAL'S SPELLING PICKS THE IMMEDIATE ENCODING (P30 S40 wave 1, `func_801822E0`) L9888
-- **§3-Why** — a correct draft can read as an intrinsic wall L9988
-- **§3-The** — rule L10023
-- **§3-B.** — `(v < 0x40) ? v : 0x3F` is folded to `MIN_EXPR` and expands to the WRONG SHAPE L10170
-- **§3-D.** — Reproduce the original's BUGS verbatim L10194
-- **§149** — Four instrument defects in one session, and the two questions they were hiding (P30 S43) L10243
-- **§3-A.** — A prep step that returns its input on failure is indistinguishable from a search that found nothing L10249
-- **§3-B.** — Same address + same name ≠ same body — and the ledger keys on address L10267
-- **§3-C.** — `make: *** [...] Error N` is a summary, never a diagnosis L10283
-- **§3-The** — fix L10319
-- **§3-The** — method that found it (this is the transferable part) L10329
-- **Diagnostic** — order (adopt this) L10356
-- **§3-The** — mechanism (read from cc1's own `-dR` trace, not inferred) L10372
-- **§3-The** — lever — a zero-emission insn that absorbs the blocked tick L10387
-- **§3-The** — finding L10423
-- **§3-The** — key L10432
-- **§3-Two** — cautions that must travel with this technique L10443
-- **§3-The** — companion defect (open) L10454
-- **Symptom** — Symptom L10474
-- **Mechanism** — (gcc source + RTL dumps, not inferred) L10479
-- **§3-The** — cure — a fresh launder per site, each in its own block L10492
-- **Companion** — levers from the same function L10502
-- **§3-B.** — Two static base-derivation methods that must AGREE (use both) L10536
-- **§155a** — the same failure class, one level up: SHAPE-blind table scanning (S45 p5) L10567
-- **§155c** — the ZERO-REFERENCE trap: gcc splits a global-array address across the `lui` and the LOAD (S46) L10610
-- **Symptom** — Symptom L10721
-- **§3-Why** — the fork is chained (gcc source, validated insn-by-insn against -dS/-dR dumps) L10727
-- **§3-The** — method (dump-arithmetic first, then place — no probing) L10740
-- **§162a** — SHARPENS *(sharpens §161a, §131, §8a-pad, §129a)* L11041
-- **§162b** — SHARPENS *(sharpens §48-A3, §156, §150, §76)* L11070
-- **§162d** — SHARPENS *(sharpens §31, §21, §30, §55a)* L11099
-- **§162e** — NEW L11141
-- **§162f** — SHARPENS *(sharpens §42d, §41d, §73, §10)* L11209
-- **§162g** — NEW L11264
-- **§162h** — SHARPENS *(sharpens §88, §88a, §50-B, §8)* L11300
-- **§162i** — SHARPENS *(sharpens §135, §21, §42, §32)* L11368
-- **§162j** — SHARPENS *(sharpens §25, §136d-1, §48-B, §46-L2)* L11393
-- **§162k** — SHARPENS *(sharpens §1-I2, §12, §160d, §21)* L11422
-- **§162l** — SHARPENS *(sharpens §48-B, §48-C1, §20, §21)* L11485
-- **§162m** — SHARPENS *(sharpens §36, §158, §148, §153)* L11540
-- **§158a** — THE FIFTH LEVER IS NOT AN ASM: `do { } while (0)` is a REGION ref-multiplier you MINT (P30 S48, `func_8017CBC8`, ov_MAIN_012 / jr_801789AC, 188 ins → MATCH) L11542
-- **Size** — it before you write it (§158 step 1-2, applied) L11560
-- **§3-The** — wrap BOUNDARY is the dial — and it is indiscriminate L11581
-- **§3-Not** — a pure dial L11587
-- **§162n** — NEW L11613
-- **§162o** — SHARPENS *(sharpens §158, §136-1, §136-6, §79)* L11646
-- **§162p** — SHARPENS *(sharpens §48-B, §46-L2, §156, §136d-1)* L11705
-- **§162q** — SHARPENS *(sharpens §30, §30a, §135-2, §136-13)* L11722
-- **§164** — S48 §163z SKEPTIC PASS (P30, 2026-08-12): 190 claims vetted, 82 banked L11848
-- **§169** — THE MICRO-ADAPT LANE (P30 S49): edit a proven body, don't crack a new one L16276
-- **§170** — THE A-PROP WORD-DIFF CARD (P30 S49): the lane that had no owner L16323
-- **§171** — THE STALE SEED SYMBOL (P30 S50, 2026-08-13): why §170's 91%→57% was never codegen L16367
-- **§172** — THE ORPHAN-SLOT MECHANISM v2 (P30 S50-Max): the complete frame-residue model for gcc-2.7.2 MIPS L16516
-- **§172a** — TWO DECOMPILATION TELLS FROM THE SAME DIG (P30 S50-Max) L16570
-- **§172b** — THREE MORE TELLS FROM THE GCC READ (P30 S50-Max, banked on Drew's ask) L16586
-- **§174** — THE ADAPT-CARD WAVE RECIPE (P31 waves A/B, 2026-08-14): prevention beats recovery L16665
-- **§176a** — THE VERIFICATION-LAYER LAWS (P31 overnight, 2026-08-15). What each check can and cannot prove. L16760
-- **§176b** — BATCH-GATING MECHANICS (P31): what changes when N drafts land in ONE .c L16800
-- **§3-C.** — The limit that remains (recorded, not solved) L17039
-- **§176k** — TWO SELECTOR BUGS THAT SILENTLY SHRINK A WAVE L17165
-- **§178** — SIX LEVERS MINED FROM THE WAVE-P JOURNALS (P31 S52), each byte-proven and source-cited L17239
-- **§3-A.** — THE `$0`-ADD OPAQUE COPY defeats `make_regs_eqv` (func_80033398, 93 ins) L17251
-- **§3-C.** — SINGLE-SET TEMPS GET THE BIRTHING BOOST (func_8001D3FC, 196 ins) L17280
-- **§3-E.** — THE ZERO-OFFSET ALIAS HOLE (func_80037028, 71 ins) L17295
-- **§179-B** — 🔴 THE HAND-WRITTEN-ASM TRANSCRIPTION CHECKLIST (maspsx + masked_diff; 10 byte-proofs) L17385
-- **§179-C** — 🔴 A FUNCTION WITH NO EPILOGUE (falls into a sibling's shared tail) MUST BE FILE-SCOPE `__asm__` L17435
-- **§179-D** — `gte_stflg` MUST CLOBBER `"$12"` OR THE WHOLE TEMP FILE ROTATES BY ONE L17486
-- **§179-H** — A MID-BODY `.global LABEL` PAIR SLICES A BYTE-COMPARABLE FRAGMENT OUT OF A LARGER ROUTINE L17582
-- **Considered** — and NOT banked L17605
-- **§176-F** — Misdiagnosis triage: four residual verdicts that were lying L17783
-- **What** — is NOT banked here L17800
-- **§180c** — WHEN A BINARY'S MASS BAND IS SPENT, THE FLEET-WIDE DRAW IS STRICTLY BETTER L17861
-- **Only** — ONE of 27 blocked drafts was wrong. The other 26 were correct and unbankable. L17880
-- **§180d** — THE `pgrep` BRACKET TRICK PROTECTS THE PATTERN, NOT THE COMMAND LINE L17949
-- **Three** — defects in one call path; the overlay slates that carry most of the wave work were being waved through L18361
-- **§194-F** — `if ((*p = v = f()) == 0)` is an expand-time pseudo SPLITTER (store_expr's `want_value && MEM` path), not a fold — it partitions one value between local_alloc and global_alloc. BOUNDS §21's L1872 bullet, whose stated direction is byte-wrong on 3 of 4 instances, and CLOSES the control §167-37 asked for. L19195
-- **§194-L** — §88b and §189-E are BOTH half-wrong, but not the way the candidate says: the compare-constant shape is a 2-D lookup (cmp_info ROW × constant-in-window), and naming matters on OPPOSITE sides of the window for the GE/LT rows vs the GT/LE rows L19522
-- **§197-REJECTED** — §197-REJECTED L20692
-- **§199-REJECTED** — §199-REJECTED L21088
-- **§201-B** — In a narrowed PLUS/MINUS/AND/IOR/XOR expression the destination pointee is INERT — the sign of the materialized constant is decided by an OR over the UNWIDENED operands (convert.c trunc1), which bounds §1841 to direct constant stores L21190
-- **§201-REJECTED** — eight, the session's highest L21424
-- **§204-CONFIRMED** — 30 reports that the index already answered L21890
-- **§204-REJECTED** — sixteen, twice the previous record L21984
-- **§209** — THE NARROW LOCAL IS A DIAL IN TWO OPPOSITE DIRECTIONS, AND §194-B's "≥2 `sh` STORES" BOUND IS BYTE-WRONG (P31 S58) L22251
-- **§212** — THE WALKING CURSOR IS COUNTABLE: `*wp++` emits one `addiu` PER STORE, `wp[0..2]` emits one (P31 S58) L22433
-- **§213** — INDEPENDENT SAME-BASE STORES: THE EMISSION ORDER IS A PERMUTATION OF SOURCE ORDER, AND THE PERMUTATION IS NOT ALWAYS THE IDENTITY (P31 S58) L22478
-- **§217** — DECODING A CALL'S STACK ARGUMENT SLOTS: `sw` at `0x10`/`0x14`/`0x18` are params 5/6/7 **(single observation — not yet cross-confirmed)** (P31 S58) L22656
-- **§226** — FRAME PADS: FOUR WAYS §162i1/§2429's DEAD-LOCAL LEVER MISFIRES (P31 S58) L22977
-- **§228** — READING THE DIVIDE, PART N: the off-by-one compare is `% K == 1`, and three more discriminators (P31 S58) L23038
-- **§229** — THE ADDRESS IS A VALUE: NAMING IT MOVES THE `lui`/`addiu` PAIR — AND §L14410 SAYS THE OPPOSITE FOR A REASON (P31 S58) L23075
-- **§231** — TRANSCRIPTION AND SEMANTIC-READ HYGIENE: six ways the listing misleads (P31 S58) L23139
-- **§194-B** — addendum (P31 S58) — BOUND 2 is byte-wrong; see §209 Direction A L23236
-- **§176-B** — addendum (P31 S58) — the misdiagnosis direction L23242
-- **§164-63** — addendum (P31 S58) — the interposed asm works when the SECOND value is an ordinary assignment L23257
-- **§193-A** — / §194-E addendum (P31 S58) — where the twin's body actually lives L23266
-- **§235** — THE PHANTOM SYMBOL: A MASKED `MATCH` CAN CARRY A RELOCATION THAT DOES NOT EXIST (P31 S58b) L23357
-- **§238** — SAME NAME, DIFFERENT FUNCTION: THE OVERLAY-HOMONYM TRAP (P31 S58b) L23520
-- **§240** — `A + K + B`: WRITE THE CONSTANT **BETWEEN** THE TWO RUNTIME TERMS (P31 S58b) L23594
-- **§241** — THE FOLDED SIGN-EXTEND-AND-SCALE: `sll 16 ; sra (16 − log2 scale)` (P31 S58b) L23623
-- **§252** — THE GUARDED PRE-DECREMENT: `(x != 0) && (--x == 0)` (P31 S58b) L23991
-- **§255** — THE EMPTY CASE, PART 2: FOUR TREE SHAPES IT BUYS (P31 S58b) L24038
-- **§258** — ADDENDA TO EXISTING SECTIONS (P31 S58b) L24153
-- **§202** — addendum (P31 S58b) — THE DEF-SIDE ALIAS ALSO CLEARS A RETURN+PARAM DOUBLE CONFLICT L24202
-- **§205** — addendum (P31 S58b) — CHAINED ASSIGNMENT: N≥3 IS INNERMOST-FIRST, AND THE TEXT MIRRORS EMISSION L24213
-- **§208** — addendum (P31 S58b) — IT SCALES TO SIX SITES, AND IT HAS AN EXACT INVERSE L24230
-- **§210** — addendum (P31 S58b) — THREE CONFIRMED SPELLINGS OF THE BOOLEAN TAIL L24259
-- **§213** — addendum (P31 S58b) — THREE MORE PERMUTATION LAWS FOR INDEPENDENT SAME-BASE STORES L24318
-- **§217** — CROSS-CONFIRMED (P31 S58b) — AND THE INCOMING HOME SLOT IS THE MIRROR L24435
-- **§220** — addendum (P31 S58b) — THE PARAMETER, NOT A COPY (SEVEN CARDS) L24452
-- **§225** — addendum (P31 S58b) — THE GUARD-CLAUSE FINGERPRINT, AND THREE MORE SHAPES L24549
-- **§229** — addendum (P31 S58b) — NAME IT **INSIDE** THE ARM L24621
-- **§230** — CROSS-CONFIRMED (P31 S58b) L24632
-- **§231** — addendum (P31 S58b) — FOUR MORE WAYS THE LISTING MISLEADS L24641
-- **§232** — CROSS-CONFIRMED (P31 S58b) L24672
-- **§260** — THE §154-A LEADING-ISLAND SPLIT: ONE CONFIG LINE, AND THE ISLAND PEELS FROM THE END (P31 S59, byte-proven) L24722
-- **§262** — A LANE'S YIELD IS ONLY A LANE FACT IF IT IS SIZE-MATCHED (P31 S59) L24856
-- **§264** — FOUR TELLS-LANE C RECIPES, EACH DRIVEN TO MATCH (P31 S59) L24927
-- **ADD-1** — → §231 addendum (also cross-ref from §195-D) — THE MASKED-`jal` "MISSING CALL" ILLUSION L25087
-- **ADD-6** — → §172b-1 / §264 addendum — SHIFT-AS-TEST: `(x << 16) != 0` TESTS THE LOW HALF WITHOUT TRUNCATING THE PSEUDO L25141
-- **ADD-7** — → §256 addendum — THE SINGLE-GUARD GOTO: THEN-BLOCK OUT OF LINE AT THE TAIL L25150
-- **ADD-3** — → §238 addendum — TWO BINARIES CAN EACH DEFINE THE SAME `func_` NAME WITH DIFFERENT BYTES, AND NO GENERATED REPORT SHOWS IT L25340
-- **§270** — The A-prop 0-bank anatomy: a byte-correct body still needs FOUR layers to agree (P31 S59) L25518
-- **ADDENDUM** — to §1-I5 L25808
-- **ADDENDUM** — to §164-51 L25873
-- **ADDENDUM** — to §176-F5 L25889
-- **ADDENDUM** — to §225 L25918
-- **ADDENDUM** — to §229 — A POINTER'S NUMBER OF USES DECIDES WHETHER ITS ADDRESS FOLDS OR SURVIVES A CALL L26106
-- **ADDENDUM** — to §226 — A DEAD LOCAL SCOPED TO A NESTED BLOCK BUYS A MID-FUNCTION `addiu sp` PAIR, NOT A FRAME-SIZE CHANGE L26224
-- **ADDENDUM** — to §74 (func_800D0E30, resident) L26592
-- **ADDENDUM** — to §172b-4 (func_80185054, ov_SC03_097) L26628
-- **ADDENDUM** — to §265 (func_8017DC80, ov_SC07_002) L26666
-- **ADDENDUM** — to §17 (func_800CB794, md_MAIN_036) L26705
-- **ADDENDUM** — to §162p (func_8017C120, ov_MAIN_012) L26753
-- **ADDENDUM** — to §20 (~L1947) (func_80186AD0, ov_SC06_032) L26787
-- **ADDENDUM** — to §164-56 (func_8017F644, ov_SC04_005) L26817
-- **ADDENDUM** — to §237 (func_8017F7FC, ov_SC03_092) L26852
-- **ADDENDUM** — to §195-E — a goto-ladder's STORES must sit AT the labels, after the gotos, not inline before them L27204
-- **Harness-defect** — flags L27678
-- **ADDENDUM** — to §167-40 (func_8017E2CC, ov_SC04_015 — wave dg) L27771
-- **ADDENDUM** — to §87 (func_801815F4 ov_SC06_032; corroborating func_801840DC ov_SC05_017, func_80189C68 ov_SC03_006 — wave dg) L27805
-- **ADDENDUM** — to §263 (func_801E83AC, md_SC04_029 — wave dj) L27844
-- **ADDENDUM** — to §265 (func_8017D878, ov_SC03_107 — wave dj; corroborated by a REJECTED, contradicted card in wave dm — see closing) L27858
-- **ADDENDUM** — to §6 (func_801811F0, ov_SC03_102 — waves dj and dl, corroborated by a self-reported "nothing new" dm-wave card) L27872
-- **ADDENDUM** — to §195-G (func_80183BB0, ov_SC05_001 — wave dj) L27886
-- **ADDENDUM** — to §74 (func_8017EB34, ov_SC03_117 — counter/clamp variant; wave dj, corroborated by dk/dl/dm cards on the same function) L27964
-- **ADDENDUM** — §37 — merged into the §153/§236-5 entry above (func_801A419C, wave dl) L27984
-- **ADDENDUM** — §6 — merged into the §6 entry above (func_801811F0, wave dl) L27992
-- **ADDENDUM** — to §238 (func_80182CB4, ov_SC02_000 — wave dl) L28000
-- **ADDENDUM** — to §137a (func_801684B4, ov_MAIN_012; corroborated independently by func_80189E68, func_8017FF9C, func_801822B4, func_8018DA8C — wave dl) L28018
-- **ADDENDUM** — to §8c / §88d (func_8016AB6C, ov_MAIN_012 — wave dm) L28034
-- **ADDENDUM** — to §73 / §30#2 (func_800D1984, resident — wave dm) L28048
-- **From** — ck + cl + cm L28176
-- **ADDENDUM** — to §5a (func_80181F74, ov_SC03_112, wave cn) L28318
-- **ADDENDUM** — to §265 (func_8017E26C, ov_SC04_016, wave cn) L28368
-- **ADDENDUM** — to §42b (func_8018247C, ov_SC07_002, waves cu + cw) L28406
-- **ADDENDUM** — to §195-E (func_800CFC1C, md_MAIN_003, wave cv) L28492
-- **ADDENDUM** — to §215 addendum (func_800CB2C8, md_MAIN_033, waves cv + cw) L28537
-- **ADDENDUM** — to §236 item 4 (func_8017D268, ov_SC04_006, wave cw) L28593
-- **Harness-defect** — flags (not idioms — flagged for the operator) L28654
-- **ADDENDUM** — to §250 (func_8017D7CC, ov_SC03_115 — cx/cy/cz/dr) L28695
-- **ADDENDUM** — to §225 (func_8017E190, ov_SC03_115 — cx/cy/cz) L28740
-- **ADDENDUM** — to §45-A (func_8017F6A4, ov_SC02_016 — cy/cz) L28793
-- **ADDENDUM** — to §249 (func_80182ED4, ov_SC04_004 — dp/dr/dt) L28837
-- **ADDENDUM** — to §199-A (func_801816FC, ov_SC02_005 — dp/dr/dt) L28882
-- **Harness-defect** — flags L28971
-- **§289** — an array local's address-taken base keeps every element's store alive, even though only one pointer escapes (`func_80189EFC`, ov_SC04_011) (P31 S60; waves #, byte-proven) L29053
-- **ADDENDUM** — to §264-3 — the explicit entry copy's BOUND: required exactly when the RAW value must outlive the call that consumes only the PROMOTED value L29207
-- **ADDENDUM** — to §276 — the SHARE direction: spell the second adjacent symbol RELATIVE to force ONE anchor L29239
-- **ADDENDUM** — to §31's density-dummy dial (L2460/L2497) — the dose is TWO refs, and the dummy must sit where the loser is live-through L29255
-- **§300** — S61 DISTILL BATCH NOTES (waves ab8/ab16/ab24/ab32 · g0a–g0f · m0a · ds1/ds2 · m0b) L29561
-- **§306a** — T4 DISTILL ADDENDA (P31 S62; four byte-proven refinements to existing laws, verified against the book by an independent verifier; each names its parent §) L29860
+- **§42d** — addendum — wave 4 (rtu_match fan-out over the mapped frontier, 2026-07-10c): 24/26 MATCH, +5 durable levers L3097
+- **§3-B.** — THE EBB RULE — the general form of §46-L2 L3483
+- **§3-E.** — Meta L3533
+- **§50** — Refinements that BOUND §47/§48 (from the `func_80135EB0` wall, 21→6; Phase 26 session 8) L3591
+- **§51a** — The bug class L3651
+- **§51c** — THE METHOD (do not audit by reading the regex) L3677
+- **§51d** — THE LAWS L3692
+- **§51e** — The false-wall pipeline (why this is not just hygiene) L3754
+- **§3-Why** — the wall is (probably) intrinsic L3960
+- **§3-The** — case L4048
+- **§3-The** — rule L4077
+- **§55a** — New byte-proven levers (each from a banked or near draft) L4113
+- **§60a** — What the first DIRECTED grinder run exposed (Phase 29 Task-13B, 2026-07-21) L4487
+- **§60b** — The plateau autopsy's verdict: a `partial` drift is a WRONG DRAFT, not a missing transform (Phase 29 Task-13B close, 2026-07-21) L4525
+- **§66** — Exercise a banking driver's SUCCESS path before pointing it at a wave: the free re-bank test (Phase 29 SESSION-17, 2026-07-24) L5174
+- **§66d-2** — Two operational sharp edges L5304
+- **§66d-3** — Read the ILS per-cycle SERIES, not its final best: a repeated score and a still-falling one look identical in a summary line and mean opposite things L5315
+- **§67** — The arg-copy PLACEMENT lever: launder a parameter into a fresh pseudo AT the statement where the target's copy lands (Phase 29 SESSION-18, `func_8014D820` 25 → 16) L5330
+- **§66d-4** — "ILS converged" means converged FOR THAT WEIGHT PROFILE, not a floor (amends §66d-3; Phase 29 SESSION-18) L5453
+- **§69** — How to attack a behemoth: map it, don't draft it (Phase 29 SESSION-18, `func_80183814`, 5,122 ins) L5584
+- **What** — is left, and what is byte-recorded as SPENT L5781
+- **§3-The** — mechanism, with citations L6052
+- **§3-Two** — diagnosis traps this function proved L6079
+- **Practice** — Practice L6089
+- **§3-The** — drift was an allocation decision, not missing code L6195
+- **§3-The** — economics L6226
+- **§71** — has a blind spot, and this is it L6241
+- **§3-The** — flagged "#1 move" LOST — and why the failure is informative L6317
+- **§78** — 's attribution primitive, run and reproduced L6327
+- **Cold-start** — economics, now complete L6333
+- **Also** — reproduced on this function L6416
+- **§3-And** — the banking footnote (§75a class A, one line) L6420
+- **§83a** — READ THE HEADLINE NUMBER CORRECTLY: a LENGTH drift makes `match_one`'s count meaningless L6434
+- **§83b** — THE LEVER: find the parameterised REPEAT before decoding case-by-case L6442
+- **§83e** — §80 vindicated again, on the same day it was written L6481
+- **§3-The** — conflict L6559
+- **§3-THE** — FAILURE MODE — widening only `engine_core.h` is worse than not starting L6567
+- **§3-The** — precondition, and how to check it in one grep L6574
+- **Reading** — , for the next person L6591
+- **§3-The** — guard refuses a class that largely works L6606
+- **§3-The** — blindness ladder, now complete — FOUR classes `match_one` cannot see L6664
+- **Consequence** — for the backlog ledger L6674
+- **§88** — `cross_jump` will not merge a common suffix containing a CALL; and §78 is scoped to ORDERED comparisons only (Phase 29 SESSION-20, the behemoth close-out) L6689
+- **§88a** — repeated CALL-shaped blocks are left UNMERGED; call-free tails are merged for you L6694
+- **§89** — Two throughput rules the project already had written down and was not following (Phase 29 SESSION-20) L6741
+- **§3-The** — standing sequence L6773
+- **§90b** — "Byte-neutral" is not "wanted": undo on the SUCCESS path too L6804
+- **§90c** — A library-callable function must FAIL CLOSED on an unconfigured module L6814
+- **§90e** — An agent's CONCLUSION and its EVIDENCE fail independently — re-derive the premise, not the fix L6833
+- **§93** — `set -o pipefail` attributes a pipeline failure to the LAST stage, not the failing one (Phase 29 SESSION-21, `func_8014D820`) L6937
+- **§101** — The STALE DEFAULT class: a guard whose cause was removed is a silent skip wearing a safety label (Phase 29 SESSION-22, three instances in one session) L7260
+- **§110** — A unit must define exactly ONE function, and "ends in `;`" does not tell you which line defines it (Phase 29 T65) L7655
+- **§115** — A `func_XXXXXXXX` predicate rots by design: the same name-form assumption in THREE places (Phase 29 T78) L7865
+- **§3-The** — fix moves the DEFINITION, not the stub — and here is why the obvious shortcut fails L7910
+- **§117** — Spell the sibling's symbol from the SIBLING's address, not the exemplar's kind (Phase 29 T82) L7941
+- **§118** — Ordinal (positional) immediate resolution: compare C tokens to the DIFFERING asm uses (Phase 29 T87) L7978
+- **§119** — Two levers on the SAME axis, opposite directions: test the off-diagonal (Phase 29 T89) L8012
+- **§3-The** — wiring trap that cost two attempts L8058
+- **§3-The** — method (keep this) L8228
+- **§3-The** — instrument rules that make its answer trustworthy (this is where I failed) L8238
+- **§3-The** — corrected results (each SHA-verified, from a clean tree, restore re-verified) L8253
+- **§3-The** — instrument trap that hid it (and it is §124's shape again) L8305
+- **§3-The** — mechanics L8314
+- **§3-The** — idiom they kept re-deriving: the constant-offset fold L8371
+- **§127b** — the knowledge was in a SOURCE COMMENT, not the cookbook L8401
+- **§128** — A raw NUL in C source makes grep SILENTLY SKIP the file (P30 S28, 137 files) L8408
+- **§128a** — a negative control must corrupt a SCRATCH COPY, never the tracked file L8440
+- **§3-The** — real blocker underneath, for the record L8492
+- **§3-The** — diagnostic ladder that finally located it (reusable) L8538
+- **Defect** — 1 — a pre-§8e MERGED DOUBLE is not a single-table predecessor L8594
+- **Defect** — 2 — `as` writes a corpse and nothing deletes it L8612
+- **§3-The** — fingerprint, and the 30-second ladder that found it L8622
+- **§3-The** — transferable rule L8643
+- **§132a** — `--like` is for a sibling with NO record; against one that HAS a record it over-derives (P30 S29, `ov_SC07_010`) L8650
+- **§135** — Six byte-verified gcc-2.7.2 idioms from the P30 S6f-h waves (and the two-lane wave shape that found them) L8780
+- **§3-The** — codegen idioms L8785
+- **§3-The** — wave shape that produced these L8834
+- **§136** — The LOCAL-VARIABLE lever: how many C locals, at what scope (P30 wave 4a, 25 byte-verified banks) L8852
+- **§136a** — Blocker capture: classify on the OUTPUT, never on the exit status L8991
+- **§136d** — Four gcc-2.7.2 levers the redraft lane found (each closed a residual no other lever moved) L9109
+- **§136e** — §136c's PRECONDITION, and two more symptom keys (wave 4b batch 3) L9153
+- **§136i** — The drafter model LADDER: Haiku → **Sonnet** → Opus → Fable5 (Drew, 2026-08-03) L9285
+- **§3-The** — triage, cheapest first L9436
+- **THREE** — carry variants hide in one "CARRY-FIXABLE" bucket — and they need different fixes L9505
+- **STEP** — 0 of sibling-first: grep `src/` for a distinctive LITERAL from the `.s` L9561
+- **§3-The** — generalisation — three corollaries worth more than the bug L9641
+- **§3-And** — the inverse-lookup trap, same session L9658
+- **§3-The** — three-line proof (do this before diagnosing any metric movement) L9695
+- **§3-The** — two instrument defects it exposed L9704
+- **§3-Two** — wrong mechanisms I chased first, and why they were wrong L9735
+- **§3-The** — trap that hid it — SAME FUNCTION, TWO ROUTES, ONLY ONE IS FREE L9820
+- **Route** — selection (why `--addr` sometimes says "nothing changed") L9829
+- **§144** — THE LITERAL'S SPELLING PICKS THE IMMEDIATE ENCODING (P30 S40 wave 1, `func_801822E0`) L9903
+- **§3-Why** — a correct draft can read as an intrinsic wall L10003
+- **§3-The** — rule L10038
+- **§3-B.** — `(v < 0x40) ? v : 0x3F` is folded to `MIN_EXPR` and expands to the WRONG SHAPE L10185
+- **§3-D.** — Reproduce the original's BUGS verbatim L10209
+- **§149** — Four instrument defects in one session, and the two questions they were hiding (P30 S43) L10258
+- **§3-A.** — A prep step that returns its input on failure is indistinguishable from a search that found nothing L10264
+- **§3-B.** — Same address + same name ≠ same body — and the ledger keys on address L10282
+- **§3-C.** — `make: *** [...] Error N` is a summary, never a diagnosis L10298
+- **§3-The** — fix L10334
+- **§3-The** — method that found it (this is the transferable part) L10344
+- **Diagnostic** — order (adopt this) L10371
+- **§3-The** — mechanism (read from cc1's own `-dR` trace, not inferred) L10387
+- **§3-The** — lever — a zero-emission insn that absorbs the blocked tick L10402
+- **§3-The** — finding L10438
+- **§3-The** — key L10447
+- **§3-Two** — cautions that must travel with this technique L10458
+- **§3-The** — companion defect (open) L10469
+- **Symptom** — Symptom L10489
+- **Mechanism** — (gcc source + RTL dumps, not inferred) L10494
+- **§3-The** — cure — a fresh launder per site, each in its own block L10507
+- **Companion** — levers from the same function L10517
+- **§3-B.** — Two static base-derivation methods that must AGREE (use both) L10551
+- **§155a** — the same failure class, one level up: SHAPE-blind table scanning (S45 p5) L10582
+- **§155c** — the ZERO-REFERENCE trap: gcc splits a global-array address across the `lui` and the LOAD (S46) L10625
+- **Symptom** — Symptom L10736
+- **§3-Why** — the fork is chained (gcc source, validated insn-by-insn against -dS/-dR dumps) L10742
+- **§3-The** — method (dump-arithmetic first, then place — no probing) L10755
+- **§162a** — SHARPENS *(sharpens §161a, §131, §8a-pad, §129a)* L11056
+- **§162b** — SHARPENS *(sharpens §48-A3, §156, §150, §76)* L11085
+- **§162d** — SHARPENS *(sharpens §31, §21, §30, §55a)* L11114
+- **§162e** — NEW L11156
+- **§162f** — SHARPENS *(sharpens §42d, §41d, §73, §10)* L11224
+- **§162g** — NEW L11279
+- **§162h** — SHARPENS *(sharpens §88, §88a, §50-B, §8)* L11315
+- **§162i** — SHARPENS *(sharpens §135, §21, §42, §32)* L11383
+- **§162j** — SHARPENS *(sharpens §25, §136d-1, §48-B, §46-L2)* L11408
+- **§162k** — SHARPENS *(sharpens §1-I2, §12, §160d, §21)* L11437
+- **§162l** — SHARPENS *(sharpens §48-B, §48-C1, §20, §21)* L11500
+- **§162m** — SHARPENS *(sharpens §36, §158, §148, §153)* L11555
+- **§158a** — THE FIFTH LEVER IS NOT AN ASM: `do { } while (0)` is a REGION ref-multiplier you MINT (P30 S48, `func_8017CBC8`, ov_MAIN_012 / jr_801789AC, 188 ins → MATCH) L11557
+- **Size** — it before you write it (§158 step 1-2, applied) L11575
+- **§3-The** — wrap BOUNDARY is the dial — and it is indiscriminate L11596
+- **§3-Not** — a pure dial L11602
+- **§162n** — NEW L11628
+- **§162o** — SHARPENS *(sharpens §158, §136-1, §136-6, §79)* L11661
+- **§162p** — SHARPENS *(sharpens §48-B, §46-L2, §156, §136d-1)* L11720
+- **§162q** — SHARPENS *(sharpens §30, §30a, §135-2, §136-13)* L11737
+- **§164** — S48 §163z SKEPTIC PASS (P30, 2026-08-12): 190 claims vetted, 82 banked L11863
+- **§169** — THE MICRO-ADAPT LANE (P30 S49): edit a proven body, don't crack a new one L16291
+- **§170** — THE A-PROP WORD-DIFF CARD (P30 S49): the lane that had no owner L16338
+- **§171** — THE STALE SEED SYMBOL (P30 S50, 2026-08-13): why §170's 91%→57% was never codegen L16382
+- **§172** — THE ORPHAN-SLOT MECHANISM v2 (P30 S50-Max): the complete frame-residue model for gcc-2.7.2 MIPS L16531
+- **§172a** — TWO DECOMPILATION TELLS FROM THE SAME DIG (P30 S50-Max) L16585
+- **§172b** — THREE MORE TELLS FROM THE GCC READ (P30 S50-Max, banked on Drew's ask) L16601
+- **§174** — THE ADAPT-CARD WAVE RECIPE (P31 waves A/B, 2026-08-14): prevention beats recovery L16680
+- **§176a** — THE VERIFICATION-LAYER LAWS (P31 overnight, 2026-08-15). What each check can and cannot prove. L16775
+- **§176b** — BATCH-GATING MECHANICS (P31): what changes when N drafts land in ONE .c L16815
+- **§3-C.** — The limit that remains (recorded, not solved) L17054
+- **§176k** — TWO SELECTOR BUGS THAT SILENTLY SHRINK A WAVE L17180
+- **§178** — SIX LEVERS MINED FROM THE WAVE-P JOURNALS (P31 S52), each byte-proven and source-cited L17254
+- **§3-A.** — THE `$0`-ADD OPAQUE COPY defeats `make_regs_eqv` (func_80033398, 93 ins) L17266
+- **§3-C.** — SINGLE-SET TEMPS GET THE BIRTHING BOOST (func_8001D3FC, 196 ins) L17295
+- **§3-E.** — THE ZERO-OFFSET ALIAS HOLE (func_80037028, 71 ins) L17310
+- **§179-B** — 🔴 THE HAND-WRITTEN-ASM TRANSCRIPTION CHECKLIST (maspsx + masked_diff; 10 byte-proofs) L17400
+- **§179-C** — 🔴 A FUNCTION WITH NO EPILOGUE (falls into a sibling's shared tail) MUST BE FILE-SCOPE `__asm__` L17450
+- **§179-D** — `gte_stflg` MUST CLOBBER `"$12"` OR THE WHOLE TEMP FILE ROTATES BY ONE L17501
+- **§179-H** — A MID-BODY `.global LABEL` PAIR SLICES A BYTE-COMPARABLE FRAGMENT OUT OF A LARGER ROUTINE L17597
+- **Considered** — and NOT banked L17620
+- **§176-F** — Misdiagnosis triage: four residual verdicts that were lying L17798
+- **What** — is NOT banked here L17815
+- **§180c** — WHEN A BINARY'S MASS BAND IS SPENT, THE FLEET-WIDE DRAW IS STRICTLY BETTER L17876
+- **Only** — ONE of 27 blocked drafts was wrong. The other 26 were correct and unbankable. L17895
+- **§180d** — THE `pgrep` BRACKET TRICK PROTECTS THE PATTERN, NOT THE COMMAND LINE L17964
+- **Three** — defects in one call path; the overlay slates that carry most of the wave work were being waved through L18376
+- **§194-F** — `if ((*p = v = f()) == 0)` is an expand-time pseudo SPLITTER (store_expr's `want_value && MEM` path), not a fold — it partitions one value between local_alloc and global_alloc. BOUNDS §21's L1872 bullet, whose stated direction is byte-wrong on 3 of 4 instances, and CLOSES the control §167-37 asked for. L19210
+- **§194-L** — §88b and §189-E are BOTH half-wrong, but not the way the candidate says: the compare-constant shape is a 2-D lookup (cmp_info ROW × constant-in-window), and naming matters on OPPOSITE sides of the window for the GE/LT rows vs the GT/LE rows L19537
+- **§197-REJECTED** — §197-REJECTED L20707
+- **§199-REJECTED** — §199-REJECTED L21103
+- **§201-B** — In a narrowed PLUS/MINUS/AND/IOR/XOR expression the destination pointee is INERT — the sign of the materialized constant is decided by an OR over the UNWIDENED operands (convert.c trunc1), which bounds §1841 to direct constant stores L21205
+- **§201-REJECTED** — eight, the session's highest L21439
+- **§204-CONFIRMED** — 30 reports that the index already answered L21905
+- **§204-REJECTED** — sixteen, twice the previous record L21999
+- **§209** — THE NARROW LOCAL IS A DIAL IN TWO OPPOSITE DIRECTIONS, AND §194-B's "≥2 `sh` STORES" BOUND IS BYTE-WRONG (P31 S58) L22266
+- **§212** — THE WALKING CURSOR IS COUNTABLE: `*wp++` emits one `addiu` PER STORE, `wp[0..2]` emits one (P31 S58) L22448
+- **§213** — INDEPENDENT SAME-BASE STORES: THE EMISSION ORDER IS A PERMUTATION OF SOURCE ORDER, AND THE PERMUTATION IS NOT ALWAYS THE IDENTITY (P31 S58) L22493
+- **§217** — DECODING A CALL'S STACK ARGUMENT SLOTS: `sw` at `0x10`/`0x14`/`0x18` are params 5/6/7 **(single observation — not yet cross-confirmed)** (P31 S58) L22671
+- **§226** — FRAME PADS: FOUR WAYS §162i1/§2429's DEAD-LOCAL LEVER MISFIRES (P31 S58) L22992
+- **§228** — READING THE DIVIDE, PART N: the off-by-one compare is `% K == 1`, and three more discriminators (P31 S58) L23053
+- **§229** — THE ADDRESS IS A VALUE: NAMING IT MOVES THE `lui`/`addiu` PAIR — AND §L14410 SAYS THE OPPOSITE FOR A REASON (P31 S58) L23090
+- **§231** — TRANSCRIPTION AND SEMANTIC-READ HYGIENE: six ways the listing misleads (P31 S58) L23154
+- **§194-B** — addendum (P31 S58) — BOUND 2 is byte-wrong; see §209 Direction A L23251
+- **§176-B** — addendum (P31 S58) — the misdiagnosis direction L23257
+- **§164-63** — addendum (P31 S58) — the interposed asm works when the SECOND value is an ordinary assignment L23272
+- **§193-A** — / §194-E addendum (P31 S58) — where the twin's body actually lives L23281
+- **§235** — THE PHANTOM SYMBOL: A MASKED `MATCH` CAN CARRY A RELOCATION THAT DOES NOT EXIST (P31 S58b) L23372
+- **§238** — SAME NAME, DIFFERENT FUNCTION: THE OVERLAY-HOMONYM TRAP (P31 S58b) L23535
+- **§240** — `A + K + B`: WRITE THE CONSTANT **BETWEEN** THE TWO RUNTIME TERMS (P31 S58b) L23609
+- **§241** — THE FOLDED SIGN-EXTEND-AND-SCALE: `sll 16 ; sra (16 − log2 scale)` (P31 S58b) L23638
+- **§252** — THE GUARDED PRE-DECREMENT: `(x != 0) && (--x == 0)` (P31 S58b) L24006
+- **§255** — THE EMPTY CASE, PART 2: FOUR TREE SHAPES IT BUYS (P31 S58b) L24053
+- **§258** — ADDENDA TO EXISTING SECTIONS (P31 S58b) L24168
+- **§202** — addendum (P31 S58b) — THE DEF-SIDE ALIAS ALSO CLEARS A RETURN+PARAM DOUBLE CONFLICT L24217
+- **§205** — addendum (P31 S58b) — CHAINED ASSIGNMENT: N≥3 IS INNERMOST-FIRST, AND THE TEXT MIRRORS EMISSION L24228
+- **§208** — addendum (P31 S58b) — IT SCALES TO SIX SITES, AND IT HAS AN EXACT INVERSE L24245
+- **§210** — addendum (P31 S58b) — THREE CONFIRMED SPELLINGS OF THE BOOLEAN TAIL L24274
+- **§213** — addendum (P31 S58b) — THREE MORE PERMUTATION LAWS FOR INDEPENDENT SAME-BASE STORES L24333
+- **§217** — CROSS-CONFIRMED (P31 S58b) — AND THE INCOMING HOME SLOT IS THE MIRROR L24450
+- **§220** — addendum (P31 S58b) — THE PARAMETER, NOT A COPY (SEVEN CARDS) L24467
+- **§225** — addendum (P31 S58b) — THE GUARD-CLAUSE FINGERPRINT, AND THREE MORE SHAPES L24564
+- **§229** — addendum (P31 S58b) — NAME IT **INSIDE** THE ARM L24636
+- **§230** — CROSS-CONFIRMED (P31 S58b) L24647
+- **§231** — addendum (P31 S58b) — FOUR MORE WAYS THE LISTING MISLEADS L24656
+- **§232** — CROSS-CONFIRMED (P31 S58b) L24687
+- **§260** — THE §154-A LEADING-ISLAND SPLIT: ONE CONFIG LINE, AND THE ISLAND PEELS FROM THE END (P31 S59, byte-proven) L24737
+- **§262** — A LANE'S YIELD IS ONLY A LANE FACT IF IT IS SIZE-MATCHED (P31 S59) L24871
+- **§264** — FOUR TELLS-LANE C RECIPES, EACH DRIVEN TO MATCH (P31 S59) L24942
+- **ADD-1** — → §231 addendum (also cross-ref from §195-D) — THE MASKED-`jal` "MISSING CALL" ILLUSION L25102
+- **ADD-6** — → §172b-1 / §264 addendum — SHIFT-AS-TEST: `(x << 16) != 0` TESTS THE LOW HALF WITHOUT TRUNCATING THE PSEUDO L25156
+- **ADD-7** — → §256 addendum — THE SINGLE-GUARD GOTO: THEN-BLOCK OUT OF LINE AT THE TAIL L25165
+- **ADD-3** — → §238 addendum — TWO BINARIES CAN EACH DEFINE THE SAME `func_` NAME WITH DIFFERENT BYTES, AND NO GENERATED REPORT SHOWS IT L25355
+- **§270** — The A-prop 0-bank anatomy: a byte-correct body still needs FOUR layers to agree (P31 S59) L25533
+- **ADDENDUM** — to §1-I5 L25823
+- **ADDENDUM** — to §164-51 L25888
+- **ADDENDUM** — to §176-F5 L25904
+- **ADDENDUM** — to §225 L25933
+- **ADDENDUM** — to §229 — A POINTER'S NUMBER OF USES DECIDES WHETHER ITS ADDRESS FOLDS OR SURVIVES A CALL L26121
+- **ADDENDUM** — to §226 — A DEAD LOCAL SCOPED TO A NESTED BLOCK BUYS A MID-FUNCTION `addiu sp` PAIR, NOT A FRAME-SIZE CHANGE L26239
+- **ADDENDUM** — to §74 (func_800D0E30, resident) L26607
+- **ADDENDUM** — to §172b-4 (func_80185054, ov_SC03_097) L26643
+- **ADDENDUM** — to §265 (func_8017DC80, ov_SC07_002) L26681
+- **ADDENDUM** — to §17 (func_800CB794, md_MAIN_036) L26720
+- **ADDENDUM** — to §162p (func_8017C120, ov_MAIN_012) L26768
+- **ADDENDUM** — to §20 (~L1947) (func_80186AD0, ov_SC06_032) L26802
+- **ADDENDUM** — to §164-56 (func_8017F644, ov_SC04_005) L26832
+- **ADDENDUM** — to §237 (func_8017F7FC, ov_SC03_092) L26867
+- **ADDENDUM** — to §195-E — a goto-ladder's STORES must sit AT the labels, after the gotos, not inline before them L27219
+- **Harness-defect** — flags L27693
+- **ADDENDUM** — to §167-40 (func_8017E2CC, ov_SC04_015 — wave dg) L27786
+- **ADDENDUM** — to §87 (func_801815F4 ov_SC06_032; corroborating func_801840DC ov_SC05_017, func_80189C68 ov_SC03_006 — wave dg) L27820
+- **ADDENDUM** — to §263 (func_801E83AC, md_SC04_029 — wave dj) L27859
+- **ADDENDUM** — to §265 (func_8017D878, ov_SC03_107 — wave dj; corroborated by a REJECTED, contradicted card in wave dm — see closing) L27873
+- **ADDENDUM** — to §6 (func_801811F0, ov_SC03_102 — waves dj and dl, corroborated by a self-reported "nothing new" dm-wave card) L27887
+- **ADDENDUM** — to §195-G (func_80183BB0, ov_SC05_001 — wave dj) L27901
+- **ADDENDUM** — to §74 (func_8017EB34, ov_SC03_117 — counter/clamp variant; wave dj, corroborated by dk/dl/dm cards on the same function) L27979
+- **ADDENDUM** — §37 — merged into the §153/§236-5 entry above (func_801A419C, wave dl) L27999
+- **ADDENDUM** — §6 — merged into the §6 entry above (func_801811F0, wave dl) L28007
+- **ADDENDUM** — to §238 (func_80182CB4, ov_SC02_000 — wave dl) L28015
+- **ADDENDUM** — to §137a (func_801684B4, ov_MAIN_012; corroborated independently by func_80189E68, func_8017FF9C, func_801822B4, func_8018DA8C — wave dl) L28033
+- **ADDENDUM** — to §8c / §88d (func_8016AB6C, ov_MAIN_012 — wave dm) L28049
+- **ADDENDUM** — to §73 / §30#2 (func_800D1984, resident — wave dm) L28063
+- **From** — ck + cl + cm L28191
+- **ADDENDUM** — to §5a (func_80181F74, ov_SC03_112, wave cn) L28333
+- **ADDENDUM** — to §265 (func_8017E26C, ov_SC04_016, wave cn) L28383
+- **ADDENDUM** — to §42b (func_8018247C, ov_SC07_002, waves cu + cw) L28421
+- **ADDENDUM** — to §195-E (func_800CFC1C, md_MAIN_003, wave cv) L28507
+- **ADDENDUM** — to §215 addendum (func_800CB2C8, md_MAIN_033, waves cv + cw) L28552
+- **ADDENDUM** — to §236 item 4 (func_8017D268, ov_SC04_006, wave cw) L28608
+- **Harness-defect** — flags (not idioms — flagged for the operator) L28669
+- **ADDENDUM** — to §250 (func_8017D7CC, ov_SC03_115 — cx/cy/cz/dr) L28710
+- **ADDENDUM** — to §225 (func_8017E190, ov_SC03_115 — cx/cy/cz) L28755
+- **ADDENDUM** — to §45-A (func_8017F6A4, ov_SC02_016 — cy/cz) L28808
+- **ADDENDUM** — to §249 (func_80182ED4, ov_SC04_004 — dp/dr/dt) L28852
+- **ADDENDUM** — to §199-A (func_801816FC, ov_SC02_005 — dp/dr/dt) L28897
+- **Harness-defect** — flags L28986
+- **§289** — an array local's address-taken base keeps every element's store alive, even though only one pointer escapes (`func_80189EFC`, ov_SC04_011) (P31 S60; waves #, byte-proven) L29068
+- **ADDENDUM** — to §264-3 — the explicit entry copy's BOUND: required exactly when the RAW value must outlive the call that consumes only the PROMOTED value L29222
+- **ADDENDUM** — to §276 — the SHARE direction: spell the second adjacent symbol RELATIVE to force ONE anchor L29254
+- **ADDENDUM** — to §31's density-dummy dial (L2460/L2497) — the dose is TWO refs, and the dummy must sit where the loser is live-through L29270
+- **§300** — S61 DISTILL BATCH NOTES (waves ab8/ab16/ab24/ab32 · g0a–g0f · m0a · ds1/ds2 · m0b) L29576
+- **§306a** — T4 DISTILL ADDENDA (P31 S62; four byte-proven refinements to existing laws, verified against the book by an independent verifier; each names its parent §) L29875
## All sections, in order
@@ -1508,813 +1511,814 @@
- **§40c** — The h_seq per-sibling reconcile: templating a reconcile-class crack ×134 (Phase 26 Task 8, 2026-07-12, byte-proven) L2676
- **§31-triage** — R17 applies to CODEGEN residuals, never to a compile ERROR (Phase 26 session 7, Drew asked) L2693
- **§41** — The DEF-SIDE canonical-sig wall: mechanically banking a drafted giant past `conflicting types` (Phase 25 T5b batch-2, 2026-07-09; `tools/canon_sig_reconcile.py`, byte-proven on `func_8013B274`) L2710
-- **§41a** — v3.1: the def-side wall was ~71% TOOL-shaped — the five measured defects + the laws that dissolve them (Phase 25 T6, Fable5, 2026-07-09) L2754
-- **§41b** — T7 execution: the object-only probe OVER-counts BANKABLE by two link/rodata classes (Phase 25 T7-M1, 2026-07-10) L2809
-- **§41c** — T7-M2: the ×134 def-side-wall sweep via per-sibling RE-reconcile (Phase 25, 2026-07-10; 4,389 banks, ~0 agent tokens) L2839
-- **§41b** — addendum — M4 "reconcile_decls" tier is ALSO a probe over-count: 0/8 mechanical (Phase 25 T7-M4, 2026-07-10) L2858
-- **§41d** — `void`→`s32` is NOT always byte-neutral: gate the RAW draft FIRST (Phase 26 session 6, byte-proven) L2878
-- **§42** — The F-band ≤28 regalloc crack wave: register-pin/DENSITY levers beat the permuter (Phase 25 T7 F-band, 2026-07-10; Ultracode 9-worker wave, 4/9 banked byte-identical, 266 swept ×134) L2900
-- **§42a** — addendum — wave 2 (residuals + 29-100 band): iso-MATCH ≠ real-TU bank, the memcpy→struct-assign fix, +5 levers (2026-07-10b) L2953
-- **§42b** — addendum — wave 3 (Max, 2026-07-10c): THE STALE-OBJECT GATE TRAP + the read-global `&`-cast drift + fix L2994
-- **§42c** — addendum — wave 3 (Max orchestrator + CORRECTED Ultracode fan-out, 2026-07-10c): the real-TU-faithful parallel harness (rtu_match) + 7/9 crack, ZERO iso-drift L3033
-- **§42d** — addendum — wave 4 (rtu_match fan-out over the mapped frontier, 2026-07-10c): 24/26 MATCH, +5 durable levers L3082
-- **§42e** — propagating a CRACK ×134: the def-finder bug + the byte-drift residual (the "remap-fail" misdiagnosis) L3121
-- **§43** — The K&R s16-param definition DISSOLVES the "narrow-param wall" for by-value register args (Phase 25 task A, Fable5 crack of the 369-ins giant `func_80166994` ×134, 2026-07-11) L3195
-- **§44** — The Phase-25 cheap-Opus giant batch: 5 structural levers + the §43 extension (2026-07-11, 6 crackers over the frontier giants) L3242
-- **§45** — The flagship `func_80133CD4` crack (399 ins ×134): the merged-variable permutation-breaker + the 1-death local-alloc gate (Phase 25 task A giant escalation, Fable5 gdb-on-cc1, 2026-07-11) L3298
-- **§46** — The `func_80178D40` crack (890 ins ×134, the heaviest core in the game): four LOOP-STRUCTURE levers cheap-Opus found by reading loop.c/jump.c/cse.c (Phase 26 session 8, 2026-07-13) L3313
-- **§47** — The live-length SLIDER: splitting a global.c allocno-priority TIE with one zero-byte asm (Phase 26 session 8, Fable5 Max, byte-proven on `func_8017BEBC` 952 ins ×113) L3365
-- **§48** — The 12-core jr crack wave: the ALLOCNO-PRICING dials and the EBB rule (Phase 26 session 8, Ultracode, 9/12 MATCH first pass) L3405
-- **§3-A.** — ALLOCNO-PRICING DIALS — move a value into the register you want, byte-neutrally L3413
-- **§3-A4** — SINK THE CONSUMER CALL INTO THE ARMS (the inverse of A1; `func_8016AB6C`, byte-proven) L3444
-- **§3-B.** — THE EBB RULE — the general form of §46-L2 L3468
-- **§3-C.** — TYPE- AND SHAPE-DRIVEN CODEGEN (the C type literally selects the addressing mode) L3484
-- **§3-D.** — THE CROSS-JUMP RATCHET (the sharpest new trap — `func_80131340` L-C) L3508
-- **§3-E.** — Meta L3518
-- **§49** — The LUID DIAL: a zero-byte SCHEDULING dial (the sched.c analogue of §47) — `func_8017A4AC` (536 ins ×134), Phase 26 session 8 L3527
-- **§50** — Refinements that BOUND §47/§48 (from the `func_80135EB0` wall, 21→6; Phase 26 session 8) L3576
-- **§51** — TOOLING INTEGRITY: the silent skip, and how to hunt it L3630
-- **§51a** — The bug class L3636
-- **§51b** — Why the byte-gate cannot save you L3652
-- **§51c** — THE METHOD (do not audit by reading the regex) L3662
-- **§51d** — THE LAWS L3677
-- **§51e** — The false-wall pipeline (why this is not just hygiene) L3739
-- **§51f** — Checklist for any new corpus-scanning tool L3755
-- **§51g** — When the thing you are scanning has a GRAMMAR, parse the grammar (`tools/cdecl.py`) L3769
-- **§52** — The WALKER-FAMILY skeleton: 6 regalloc-order levers + a deeply-characterized intrinsic wall (`func_80178004`, 165 ins ×134; Phase 26, Fable5, 2026-07-15) L3913
-- **§3-The** — 6 levers (the "walker-family skeleton" — apply to the 12 siblings; levers 1-5 retire ~half the residual) L3924
-- **§3-Why** — the wall is (probably) intrinsic L3945
-- **§52a** — The regalloc sibling wave: new levers + two new wall classes (cheap-Opus applying §52, 2026-07-15) L3959
-- **§52b** — Sibling wave 2: more de-pin levers, a third wall class, and the match_one→whole-binary gap at scale (2026-07-15) L3997
-- **§53** — SWEEP A FAMILY WITH THE TOOL ITS EXEMPLAR NEEDED: the jr/switch carve, and how omitting it manufactured the "families don't template" doctrine (Phase 28 T1, 2026-07-15) L4028
-- **§3-The** — case L4033
-- **§3-Why** — 0/8 was structural, and predictable from two words L4045
-- **§3-The** — rule L4062
-- **§3-The** — meta-lesson (R35, and why this one is expensive) L4078
-- **§55** — Core-crack wave levers + the GATE-ORCHESTRATION law (Phase 29 T3, 13-agent ultracode wave, 2026-07-17) L4093
-- **§55a** — New byte-proven levers (each from a banked or near draft) L4098
-- **§55b** — THE GATE-ORCHESTRATION LAW (3 traps, ~3.5h lost; all recovered, 0 data lost) L4122
-- **§55c** — Sizing the propagate: a TARGETED propagate is ~4 min/core, and "it's slow" was a BROKEN-TREE ARTIFACT L4141
-- **§54** — `--fix-def-sig`: the member's CANONICAL DECLARATION is a build step too (tiny-IMM mega-pools, +4,801, Phase 29 T6, 2026-07-16) L4163
-- **§56** — Banking a hand-drafted GIANT into its exemplar TU: self-contained draft vs live-TU decls, 4 reconciliation tactics (`func_8013FAF8`, 312 ins ×138, Phase 29 T4, 2026-07-17) L4187
-- **§56b** — PROPAGATING an h_seq giant: the exemplar's externs MUST be fleet-canonical, not the draft's types L4232
-- **§57** — The SELF-decl normalize: the sibling's OWN caller declares the templated fn divergently (the third §17a-1 direction; `tools/normalize_self_decls.py`, func_801670E4 ×137, Phase 29, 2026-07-18) L4256
-- **§57a** — Two NSD corrections + the SURGICAL-ONLY law + the honest broad-sweep yield (Phase 29, 2026-07-18) L4303
-- **§58** — match_one MATCH ≠ BANK: the four blind spots + the crack-wave reconcile-before-bank law (Phase 29 crack-wave, 2026-07-18) L4343
-- **§59** — Three h_seq sweep-residual classes match_one/the-exemplar-bank don't reveal (Phase 29 crack-wave close, 2026-07-18) L4377
-- **§60** — Classify the residual, don't rank it: the deterministic residual→class classifier and what it measured about the backlog (Phase 29 Task-13A, 2026-07-21) L4407
-- **What** — it measured — the whole open backlog, byte-grounded L4431
-- **§3-Two** — corollaries worth remembering L4450
-- **§3-The** — parallel-probe race this surfaced L4463
-- **§60a** — What the first DIRECTED grinder run exposed (Phase 29 Task-13B, 2026-07-21) L4472
-- **§60b** — The plateau autopsy's verdict: a `partial` drift is a WRONG DRAFT, not a missing transform (Phase 29 Task-13B close, 2026-07-21) L4510
-- **§61** — Task 14: the gate ladder's missing stage is the ARITY pre-pass, and it is TU-side not draft-side (Phase 29, 2026-07-21) L4545
-- **§61a** — The Task-5 wave: 11/12 MATCH, 0 banked — three DISTINCT integration walls, each now named (Phase 29, 2026-07-21) L4606
-- **§61b** — The jtbl gate stage: built, and the ORDERING law it exposed (Phase 29 Task-14 stage 4, 2026-07-21) L4658
-- **§61c** — The jtbl bank is INCREMENTALLY valid and CLEAN-INVALID (Phase 29, 2026-07-21) — the blocking finding L4713
-- **§61d** — The undo was eating the tree: two tools, one defect, invisible to the byte-gate (Phase 29, 2026-07-22) L4779
-- **§62** — The jtbl RECONCILE must also follow the carve: the post-carve draft reconcile (`harvest_verify._jtbl_reconcile`, Phase 29 SESSION-11, 2026-07-22) L4833
-- **§63** — The fresh-138 DEF-SIDE blocker: fix the HEADER decl, not the draft (`fix_header_decl.py`, Phase 29 SESSION-13, 2026-07-23) L4877
-- **§64** — The §20 type-lift's three laws: fold the tagged typedef, check VISIBILITY, and strip only what is TEXTUALLY IDENTICAL (`lift_types.py`, Phase 29 SESSION-14, 2026-07-23) L4908
-- **§64a** — VARIANT types: UNIQUIFY the camps, do not reconcile them (`uniquify_type.py`, Phase 29 SESSION-14) L4957
-- **§63** — UPDATE (Phase 29 SESSION-14) — `fix_header_decl`'s "SAFE" verdict is FLEET-BLIND; it MUST be R22-validated L5000
-- **§65** — The stranded-draft recovery: BLAST-RADIUS TIERS, and the per-overlay de-macroize that refutes §20's DEF-conflict wall (`tools/demacroize.py` + `tools/blocker_probe.py`, Phase 29 SESSION-16, 2026-07-24) L5015
-- **§65a** — The blast-radius taxonomy (makes §61's law structural instead of remembered) L5030
-- **§65b** — The escape: de-macroize the instantiation, don't touch the shared header L5045
-- **§65c** — `rtu_match` MATCH → bank held 13/13 on self-decl, but broke on the FIRST callee-decl case L5081
-- **§65d** — Existing-ladder baseline, measured (do this before building a recovery stage) L5091
-- **§65e** — Two oracles, and the disagreement is the finding (R34 in practice) L5101
-- **§65f** — The de-macroize lever's BOUNDARY, measured: byte-neutral 14 times of 15, and the 15th is why the gate exists L5118
-- **§65g** — Where the cheap levers STOP: the local-type and in-TU-self-decl classes did not yield L5139
-- **§66** — Exercise a banking driver's SUCCESS path before pointing it at a wave: the free re-bank test (Phase 29 SESSION-17, 2026-07-24) L5159
-- **§66a** — The widest write in a pipeline is the one most likely to be UNDECLARED L5181
-- **§66b** — A metric parsed out of another tool's prose goes NULL silently when the label changes L5200
-- **§66c** — Before a wave, verify the FUEL exists; an "already attempted" set built from the wrong directory lies in BOTH directions L5217
-- **§66d** — The permuter⇄reader loop: alternate a random search with a byte-verified idiom, and let `residual_class` decide whose turn it is (Phase 29 SESSION-17) L5245
-- **§66d-1** — What transfers between giants is the LOOP, not the PIN L5280
-- **§66d-2** — Two operational sharp edges L5289
-- **§66d-3** — Read the ILS per-cycle SERIES, not its final best: a repeated score and a still-falling one look identical in a summary line and mean opposite things L5300
-- **§67** — The arg-copy PLACEMENT lever: launder a parameter into a fresh pseudo AT the statement where the target's copy lands (Phase 29 SESSION-18, `func_8014D820` 25 → 16) L5315
-- **§67a** — Run the symbol-set guard BEFORE you pay for a gate (`tools/symcheck.py`, Phase 29 SESSION-18) L5405
-- **§66d-4** — "ILS converged" means converged FOR THAT WEIGHT PROFILE, not a floor (amends §66d-3; Phase 29 SESSION-18) L5438
-- **§66d-5** — `residual_class`'s "structural ⇒ permuter CPU is waste" is WRONG for schedule permutations (measured, Phase 29 SESSION-18) L5491
-- **§68** — A comment-only line halted the extern scan, and the skip label blamed the type cap (Phase 29 SESSION-18) L5524
-- **§69** — How to attack a behemoth: map it, don't draft it (Phase 29 SESSION-18, `func_80183814`, 5,122 ins) L5569
-- **§70** — The giv-init base register: walk the PARAMETER, not a copy of it (Phase 29 SESSION-18, `func_801777BC`) L5619
-- **§71** — Before mapping a giant, look for an already-matched SIBLING beside it (Phase 29 SESSION-18, `func_8017D960`, 3,338 ins) L5660
-- **§72** — A `register __asm__` pin is a PREFERENCE, not a reservation (Phase 29 SESSION-18, `func_8017F510`) L5726
-- **§3-The** — honest fix was source-level and cheap L5750
-- **§3-Giv** — record order (the §70 family) L5760
-- **What** — is left, and what is byte-recorded as SPENT L5766
-- **§73** — A def-side self-decl conflict has TWO axes: RETURN (fleet widen, T2) and PARAMS (casts at each use, T0). Diagnose which before paying for the expensive one (Phase 29 SESSION-19, `func_8014F3E8` + `func_8014D4C0`) L5783
-- **§74** — Auditing a pinned draft: the §72 hazard is CALLER-SAVED pins spanning a call, and only the disassembly can tell you (Phase 29 SESSION-19, `func_8017D960` b2, 5 pins) L5822
-- **§75** — A propagation cap is usually a MINORITY-SPELLING SOURCE OVERLAY, not a wall: census the carried extern before believing the exclusion message (Phase 29 SESSION-19, `func_8014F3E8` ×4 → ×138) L5866
-- **§75a** — The exclusion classes, enumerated with named causes (Phase 29 SESSION-19, the 134-binary `dedup_extend` sweep) L5925
-- **§75b** — A body's preamble can carry `#define`s, not just `extern`s; extraction lifts only the externs (Phase 29 SESSION-19, `func_80165CA0` ×3 → fleet) L5948
-- **§75c** — Class-B's remedy is the FULL §17a-1 PAIR (decl **and** call-site cast); a decl-only fix moves the error and looks like a new wall (Phase 29 SESSION-19, `func_8012F14C`) L5997
-- **§76** — The allocno CLASS (local vs global) is the dominant regalloc lever, and C reaches it ONLY through declaration scope and variable reuse (Phase 29 SESSION-19, behemoth #3 `func_8017F510` 1,511 ins, 97 → MATCH, pin-free) L6028
-- **§3-The** — mechanism, with citations L6037
-- **§3-The** — attribution primitive (use this before calling anything a scheduling residual) L6057
-- **§3-Two** — diagnosis traps this function proved L6064
-- **Practice** — Practice L6074
-- **§77** — Every extraction tool carries a NARROW hard-coded preamble set; anything outside it silently caps the body's reach. Diff the preamble before you gate. (Phase 29 SESSION-19 — three variants in one session, two different tools) L6084
-- **§3-The** — CANDIDATE gate and the REAL gate need DIFFERENT preambles — keep the difference out of the bank L6124
-- **§78** — A LENGTH drift can be a register grant in disguise; and `fold` never leaves a literal first in an `|` chain (Phase 29 SESSION-19, behemoth #2 `func_8017D960` 3,338 ins, 1806 → 0, pin-free) L6174
-- **§3-The** — drift was an allocation decision, not missing code L6180
-- **§3-The** — economics L6211
-- **§79** — For a 0-callee giant, fingerprint by DATA symbols (§71 cannot fire); and the STACK-SLOT ORDER is a declaration-order oracle (Phase 29 SESSION-19, `func_8017BF14` 4,763 ins, cold start → 45/4763) L6220
-- **§71** — has a blind spot, and this is it L6226
-- **§3-NEW** — LEVER — the frame layout reads back the original declaration order L6240
-- **§76** — confirmed at scale, and a pin nuance L6251
-- **§3-The** — residual, and the honest read L6260
-- **§80** — A do-not-re-buy entry is scoped to its BASE, not to the function; and the pin's hidden cost is an unconditional `qty_phys_sugg` (Phase 29 SESSION-19, `func_8017BF14` 45 → 0) L6270
-- **§3-The** — pin's hidden cost, with the citation L6291
-- **§3-The** — flagged "#1 move" LOST — and why the failure is informative L6302
-- **§78** — 's attribution primitive, run and reproduced L6312
-- **Cold-start** — economics, now complete L6318
-- **§81** — Banking a jr (jump-table) function: the 3-step carve chain, and why `match_one` cannot see the problem (Phase 29 SESSION-19, `func_8017C954`) L6323
-- **§3-The** — defect this exposed: a shared type that is present but invisible L6354
-- **§82** — Two source-shape oracles from behemoth #6: a duplicated `addiu $aN,$sp,K` across a `jal` means the block was INLINED, and scalar-vs-aggregate decides WHEN a stack slot is allocated (Phase 29 SESSION-19, `func_8017C730` 1,061 ins) L6370
-- **§3-1.** — The inlined-helper signature L6375
-- **§3-2.** — Scalar vs aggregate decides *when* the slot is allocated L6389
-- **Also** — reproduced on this function L6401
-- **§3-And** — the banking footnote (§75a class A, one line) L6405
-- **§83** — The parameterised-repeat law, the spill-area trap, and why a per-case edit cannot move a per-case symptom (Phase 29 SESSION-20, `func_80183814` 5,122 ins, cold-ish start → 36 structural / 99.3%) L6412
-- **§83a** — READ THE HEADLINE NUMBER CORRECTLY: a LENGTH drift makes `match_one`'s count meaningless L6419
-- **§83b** — THE LEVER: find the parameterised REPEAT before decoding case-by-case L6427
-- **§83c** — TRAP: a "dead local" in a prior draft may be gcc's OWN spill area L6445
-- **§83d** — CSE's quantity budget is WHOLE-FUNCTION, so a local rewrite cannot fix a local symptom L6452
-- **§83e** — §80 vindicated again, on the same day it was written L6466
-- **§84** — The DERIVED-OFFSET remap bug: a hand-computed literal that encodes the DISTANCE between two per-overlay symbols, and why `match_one` is structurally blind to it (Phase 29 SESSION-20, `func_8013D53C`) L6472
-- **§3-The** — construct L6477
-- **§3-Why** — it survived every candidate gate L6495
-- **§3-THE** — FIX IS MECHANICAL — the tool already holds the answer L6510
-- **Scope** — , measured (do not over-generalise — §80) L6518
-- **§3-Two** — ladder lessons banked with it L6528
-- **§85** — The RETURN-axis fleet widen is ALL-OR-NOTHING: widening the shared header alone guarantees a conflict in the source overlay (Phase 29 SESSION-20, `func_8012CC88` / `func_8014D12C`) L6539
-- **§3-The** — conflict L6544
-- **§3-THE** — FAILURE MODE — widening only `engine_core.h` is worse than not starting L6552
-- **§3-The** — precondition, and how to check it in one grep L6559
-- **§3-Do** — the WHOLE axis in one edit, then R22 once L6567
-- **Reading** — , for the next person L6576
-- **§86** — Pinned-exemplar templatability is a PER-FAMILY property, not a per-member rate; and the §42e pin guard is now over-conservative (Phase 29 SESSION-20) L6589
-- **§3-The** — guard refuses a class that largely works L6591
-- **§3-THE** — LAW: all-or-nothing PER FAMILY L6600
-- **§3-Why** — the two live families differ from the three dead ones — the open question L6627
-- **§87** — `match_one` COMPILES but never LINKS, so an unresolvable data symbol reads as MATCH; and stored drafts go STALE against the tree (Phase 29 SESSION-20) L6633
-- **§3-The** — blindness ladder, now complete — FOUR classes `match_one` cannot see L6649
-- **Consequence** — for the backlog ledger L6659
-- **§3-The** — cheap discriminator, before spending a sweep L6666
-- **§88** — `cross_jump` will not merge a common suffix containing a CALL; and §78 is scoped to ORDERED comparisons only (Phase 29 SESSION-20, the behemoth close-out) L6674
-- **§88a** — repeated CALL-shaped blocks are left UNMERGED; call-free tails are merged for you L6679
-- **§88b** — the `slti` literal-position law (extends §78 to comparisons) L6686
-- **§88d** — BANKING ORDER: run the §81 carve chain BEFORE banking, never after L6701
-- **§88e** — a wrong diagnosis, refuted properly (the model for how to treat an inherited lever) L6708
-- **§88f** — the missing rung: a RELOCATION gate between `match_one` and the binary L6718
-- **§89** — Two throughput rules the project already had written down and was not following (Phase 29 SESSION-20) L6726
-- **§89a** — MEASURE the write set; do not assert its tier (`tools/blast_radius.py`) L6732
-- **§89b** — the parallel gate farm existed; the family path could not reach it (`tools/sweep_parallel.py`) L6745
-- **§3-The** — standing sequence L6758
-- **§90** — Five tool-integrity laws from one session, each of which changed an answer (Phase 29 SESSION-21, 2026-07-27) L6766
-- **§90a** — A comparison tool MUST share its reference oracle's index space, exactly L6772
-- **§90b** — "Byte-neutral" is not "wanted": undo on the SUCCESS path too L6789
-- **§90c** — A library-callable function must FAIL CLOSED on an unconfigured module L6799
-- **§90d** — Do not measure a live wave's drafts (§87 in real time) L6810
-- **§90e** — An agent's CONCLUSION and its EVIDENCE fail independently — re-derive the premise, not the fix L6818
-- **§91** — A structure-TRANSFER is only valid where the structure corresponds: the `--like` role trap (Phase 29 SESSION-21, `func_8012AAAC` ×137) L6842
-- **§3-The** — three-hypothesis trail, because two of them were wrong and the wrongness is instructive L6871
-- **§92** — Conforming a DECLARATION: pointer changes are caller-neutral, scalar-WIDTH changes are not (Phase 29 SESSION-21, `tools/conform_decls.py`) L6891
-- **§93** — `set -o pipefail` attributes a pipeline failure to the LAST stage, not the failing one (Phase 29 SESSION-21, `func_8014D820`) L6922
-- **§94** — A family sweep's `0/N` is a TYPE-CARRY failure until proven otherwise: lift the exemplar's local types, ALL of them, transitively (Phase 29 SESSION-21, `func_8016B6BC` 0/137 → 137/137) L6947
-- **§95** — `reconcile_tu` dropped the SIBLING declarators of a multi-symbol `extern` line (Phase 29 SESSION-21, `func_80176218`) L6983
-- **§96** — The same rewrite, one shape down: `reconcile_tu` matched statements to lines by TEXT, so every COMMENTED declaration was silently skipped (Phase 29 SESSION-22, `func_80176218` banked) L7018
-- **§97** — The gate's own tree hygiene: a refused carve, an unchecked recovery, and a snapshot that captured a dirty tree (Phase 29 SESSION-22) L7066
-- **§98** — `conform_decls` had three defects, and only the third needed R22 to find (Phase 29 SESSION-22, `func_8014CF04`) L7113
-- **§99** — The narrow-param wall is a DEF-side problem with a ZERO-blast-radius fix: convert the definition to K&R (Phase 29 SESSION-22, `func_80175AB8` + `func_80175DA8`) L7167
-- **§3-Two** — `reconcile_tu` bugs found underneath, one introduced while fixing the other L7190
-- **§100** — Prefer the DRAFT-LOCAL fix: a type only one function uses belongs in its BODY, not in a shared header (Phase 29 SESSION-22, `func_80175DA8` 0/137 → 137/137) L7216
-- **§101** — The STALE DEFAULT class: a guard whose cause was removed is a silent skip wearing a safety label (Phase 29 SESSION-22, three instances in one session) L7245
-- **§102** — A PLUMBING verdict can MASK a DIFF; and K&R is not always a codegen change (Phase 29 SESSION-22, `func_8016EC0C`) L7272
-- **§103** — A FILE-scope `extern` in a shared overlay TU is a GLOBAL constraint on every LATER function; move the DECL, not the draft (Phase 29 T48/T51, `func_80135260` — the fleet-wide half) L7307
-- **§104** — Two silent-skip defects in one scan: match on MASKED text, emit from the ORIGINAL (Phase 29 T53, `gather_externs`) L7395
-- **§105** — A gate's revert must survive an EXCEPTION, not just a failure (Phase 29 T53, `jtbl_family_bank`) L7431
-- **§106** — Persist the MEASUREMENT, derive the POLICY: a stored route let a stale file out-vote the live table (Phase 29 T54, `residual_class._ROUTE`) L7470
-- **§107** — A lever wired into ONE gate path is a lever most families cannot reach (Phase 29 T56, `func_80144090` 0/136 → 136/136) L7513
-- **§108** — Diagnosing a family `0/N`: the four causes, and the third opt-in lever (Phase 29 T59) L7551
-- **§109** — Conforming a definition to a shared header: fix the NAMES, then check the RETURN precondition (Phase 29 T60) L7600
-- **§110** — A unit must define exactly ONE function, and "ends in `;`" does not tell you which line defines it (Phase 29 T65) L7640
-- **§111** — The distinct-code metric is not noisy: a family pays it only if its members are byte-VARIANT (Phase 29 T66) L7681
-- **§112** — A macro-scoped declaration only collides where the macro is INSTANTIATED (Phase 29 T67/T69, `audit_header_sigs.py`) L7730
-- **§113** — An ARITY blocker only exists if the macro CALLS the function; an address-taken use has no call site (Phase 29 T72) L7776
-- **§114** — The THIRD decl axis: a CALLEE the draft declares differently from the target TU (Phase 29 T76/T77) L7808
-- **§115** — A `func_XXXXXXXX` predicate rots by design: the same name-form assumption in THREE places (Phase 29 T78) L7850
-- **§116** — Optimization level is a property of the FILE, not the function: read a family 0/N against the member's stub HOME (Phase 29 T79) L7877
-- **§3-The** — fix moves the DEFINITION, not the stub — and here is why the obvious shortcut fails L7895
-- **§117** — Spell the sibling's symbol from the SIBLING's address, not the exemplar's kind (Phase 29 T82) L7926
-- **§3-Why** — it survived so long: a MASKED oracle will MATCH a wrong symbol L7953
-- **§118** — Ordinal (positional) immediate resolution: compare C tokens to the DIFFERING asm uses (Phase 29 T87) L7963
-- **§119** — Two levers on the SAME axis, opposite directions: test the off-diagonal (Phase 29 T89) L7997
-- **§120** — Uniquify draft-defined TYPE names; and check which of N staging sites you actually patched (Phase 29 T93) L8026
-- **§3-Do** — NOT "strip the duplicate typedef" — it breaks the extern that uses it L8037
-- **§3-The** — wiring trap that cost two attempts L8043
-- **§121** — Synthesise externs for macro-DEFINED callees from the macro's own definition head (Phase 29 T95) L8061
-- **§122** — GATE RAW BEFORE TRANSFORMING; the undo belongs to the WRITER, as a per-edit journal (P30 T0a, 2026-07-30) L8084
-- **§123** — PROPAGATE A FAMILY WITH THE TOOL ITS TIER NEEDS: `dedup_propagate` is h_exact-only; its refusals are statements about the TOOL (P30 wave 1, 2026-07-30) L8116
-- **§124** — A "not matched" verdict can mean the definition is there under a DIFFERENT C NAME: the asm-label alias blind spot (P30 SESSION-28, `func_8016191C` ×137) L8153
-- **§124a** — a family sweep's `0 matched-exemplar families` may be a FILTER, not a wall L8198
-- **§125** — Split the CARVE from the BODY before calling a jr residue a wall — and measure it by SHA from a CLEAN tree (P30 SESSION-28; **this section's first draft was WRONG and the method caught it**) L8206
-- **§3-The** — method (keep this) L8213
-- **§3-The** — instrument rules that make its answer trustworthy (this is where I failed) L8223
-- **§3-The** — corrected results (each SHA-verified, from a clean tree, restore re-verified) L8238
-- **§3-Two** — further notes worth keeping L8248
-- **§3-The** — meta-lesson L8257
-- **§126** — The carve-within-a-carve: an ADDRESS RANGE is not an OPTIMIZATION REGION (P30 T2, byte-proven end-to-end) L8264
-- **§3-The** — finding: opt level is per FILE, so the file's contents must be opt-HOMOGENEOUS L8279
-- **§3-The** — instrument trap that hid it (and it is §124's shape again) L8290
-- **§3-The** — mechanics L8299
-- **§126a** — a bare `except: continue` around a coverage-asserting oracle re-creates the silent skip (P30 S28) L8317
-- **§127** — The `-O0` regime: the CONSTANT-OFFSET FOLD, and why `-O0` needs its own idiom set (P30 T3 wave, 15 targets) L8349
-- **§3-The** — idiom they kept re-deriving: the constant-offset fold L8356
-- **§3-The** — rest of the `-O0` regime (write PLAIN C, and mean it) L8367
-- **§127a** — §71 (sibling-first) is the strongest `-O0` lever, and it beats the index L8377
-- **§127b** — the knowledge was in a SOURCE COMMENT, not the cookbook L8386
-- **§128** — A raw NUL in C source makes grep SILENTLY SKIP the file (P30 S28, 137 files) L8393
-- **§128a** — a negative control must corrupt a SCRATCH COPY, never the tracked file L8425
-- **§129** — Post-carve, `rtu_match`/`match_one` COUNT THE JUMP TABLE AS INSTRUCTIONS; and a carve must never be committed without its owner (P30 S28, `func_8013BD74`) L8437
-- **§129a** — the target instruction count is INFLATED after a carve L8441
-- **§129b** — never commit a carve whose owner is still a stub (it strands the carve) L8462
-- **§3-The** — real blocker underneath, for the record L8477
-- **§130** — An INCREMENTAL build can report BYTE-IDENTICAL for a change the CLEAN build cannot even LINK (P30 S28, the jr pair) L8486
-- **§3-The** — diagnostic ladder that finally located it (reusable) L8523
-- **§131** — The jtbl OVER-SPAN: `sltiu N` is ground truth in BOTH directions, and the zero-word rule only guards one (P30 S28, `func_80191C50`) L8533
-- **§132** — The `JR-PAIR-IN-ONE-O0-OBJECT` "wall" was TWO instrument defects: a merged-double span the carve could not see, and a truncated object no rule deleted (P30 S29, `func_8013B83C` + `func_8013BD74`) L8570
-- **Defect** — 1 — a pre-§8e MERGED DOUBLE is not a single-table predecessor L8579
-- **Defect** — 2 — `as` writes a corpse and nothing deletes it L8597
-- **§3-The** — fingerprint, and the 30-second ladder that found it L8607
-- **§3-The** — transferable rule L8628
-- **§132a** — `--like` is for a sibling with NO record; against one that HAS a record it over-derives (P30 S29, `ov_SC07_010`) L8635
-- **§132b** — When the span's already-matched owner is ITSELF multi-switch: `--span-rel` (P30 S1, `func_8014032C`) L8660
-- **§133** — The DEFAULT-FILTER class: three times in one session, a tool silently answered a narrower question than the one asked (P30 S1–S3) L8685
-- **§134** — MULTI-LINE BLINDNESS: one root cause, four faces, in `family_remap`'s preamble scanner (P30 S6, 190 zero-crack families) L8711
-- **§135** — Six byte-verified gcc-2.7.2 idioms from the P30 S6f-h waves (and the two-lane wave shape that found them) L8765
-- **§3-The** — codegen idioms L8770
-- **§3-The** — integration idioms (these decide whether a byte-correct draft BANKS) L8804
-- **§3-The** — wave shape that produced these L8819
-- **§136** — The LOCAL-VARIABLE lever: how many C locals, at what scope (P30 wave 4a, 25 byte-verified banks) L8837
-- **§3-The** — splitting/merging rules (each closed a residual, byte-gated) L8853
-- **§3-The** — type-form rules L8879
-- **§3-The** — scheduling rules (refining §135-2 and §135-4) L8912
-- **§3-The** — declaration surface (integration, not codegen) L8941
-- **Wave** — economics (measured, for the next batch's sizing) L8953
-- **§136a** — Blocker capture: classify on the OUTPUT, never on the exit status L8976
-- **§136b** — A prior wave's "genuine byte-DIFF" verdict is NOT reliable evidence (4 of 4 refuted) L9033
-- **§136c** — SIBLING-FIRST is a DERIVATION shortcut, not just a conflict fix (the fastest route in a family wave) L9069
-- **§136d** — Four gcc-2.7.2 levers the redraft lane found (each closed a residual no other lever moved) L9094
-- **§136e** — §136c's PRECONDITION, and two more symptom keys (wave 4b batch 3) L9138
-- **§136f** — Two declaration sub-cases the reconcile lane surfaced (lane now 15/15 lifetime) L9186
-- **§136g** — When the index points at the WRONG lever: two byte-refuted routings (func_801863B4) L9211
-- **§136h** — CORRECTION: the zero-crack pool does NOT "refill with cheap work" (my error, byte-measured) L9240
-- **§136i** — The drafter model LADDER: Haiku → **Sonnet** → Opus → Fable5 (Drew, 2026-08-03) L9270
-- **§136j** — The failure MIX flips with function size (measured across four bands, one session) L9302
-- **§137** — REGALLOC-PERM is a TWO-COMPILE ARITHMETIC PROBLEM, not a permuter job L9344
-- **§137a** — A gate verdict has a TIMESTAMP; re-check it against the draft's mtime L9386
-- **§138** — The propagation lanes: a gate refusal is a DECLARATION, and which lever you owe depends on blast radius L9415
-- **§3-The** — triage, cheapest first L9421
-- **§3-The** — DEFINITION-side alias is the only escape when the fleet canon disagrees on a promoting param L9473
-- **Rank** — the lane by measured concentration, not by class count L9481
-- **THREE** — carry variants hide in one "CARRY-FIXABLE" bucket — and they need different fixes L9490
-- **§134** — again, in a second tool — and the waiter rule corrected L9526
-- **STEP** — 0 of sibling-first: grep `src/` for a distinctive LITERAL from the `.s` L9546
-- **Reconciling** — a gate-refused draft: which way you edit depends on WHERE the TU's decl is L9565
-- **§139** — A GATE THAT GREPS FOR VERDICTS MUST ASSERT 1:1 ACCOUNTING; and a `--src` filter must not survive a carve (P30 S38, wave 6: 10 of 16 drafts vanished) L9594
-- **§3-The** — generalisation — three corollaries worth more than the bug L9626
-- **§3-And** — the inverse-lookup trap, same session L9643
-- **§140** — A METRIC IS NOT A MEASUREMENT UNTIL IT IS REPRODUCIBLE FROM THE COMMITTED TREE (P30 S1e: a phantom regression that gated the session's best lever) L9660
-- **§3-The** — three-line proof (do this before diagnosing any metric movement) L9680
-- **§3-The** — two instrument defects it exposed L9689
-- **§3-The** — same swallow, twice more, in the integration spine L9709
-- **§3-Two** — wrong mechanisms I chased first, and why they were wrong L9720
-- **§141** — The §134 class is CLOSED: every line-shape decision now routes through `cdecl._mask` (P30 S39) L9740
-- **§142** — An open stub whose `h_exact` class is MATCHED elsewhere is FREE. Propagate the body; do not gate a draft. (P30 S39, +7,710 ins in two commands) L9778
-- **§3-The** — measurement (do this before any wave; it is ~20 lines and needs no builds) L9790
-- **§3-The** — trap that hid it — SAME FUNCTION, TWO ROUTES, ONLY ONE IS FREE L9805
-- **Route** — selection (why `--addr` sometimes says "nothing changed") L9814
-- **§3-And** — the report-vs-bytes lesson attached to it L9822
-- **§143** — `cast_call_sites` read a RETURN STATEMENT as a prototype and deleted it. A 0/39 sweep became 18/39. (P30 S40) L9834
-- **§144** — THE LITERAL'S SPELLING PICKS THE IMMEDIATE ENCODING (P30 S40 wave 1, `func_801822E0`) L9888
-- **§145** — Three loop/combine levers from the S40 wave-2 drafters (16/16 match_one) L9927
-- **§146** — RE-MEASURE A WALL BEFORE YOU RESPECT IT. Both "permanent" giants fell to drafts already on disk. (P30 S6, +50,094 ins) L9977
-- **§3-Why** — a correct draft can read as an intrinsic wall L9988
-- **Then** — propagation returned 0/137 TWICE — both times a missing TYPE L10000
-- **§3-Two** — errors of mine, both instructive L10009
-- **§3-The** — rule L10023
-- **§147** — The three-stratum FRAME LAW, and four "stop searching" verdicts (P30 S42, `func_8017C294`, serial run) L10036
-- **§3-A.** — The frame has THREE strata, and stratum 3 is unreachable from C L10041
-- **§3-B.** — A `?:` on MEMORY operands costs ~16 bytes of invisible frame; on REGISTER operands, zero L10057
-- **§3-C.** — Inner-block declaration does NOT delay slot allocation — BYTE-REFUTED L10068
-- **§3-D.** — A lone `$t8`/`$t9` in the target is RELOAD SCRATCH — reproduce the spill, don't pin the register L10073
-- **§3-E.** — A `qty_compare` TIE is not spelling-reachable — recognise it and stop L10083
-- **Consequence** — for the family (a real scheduling decision) L10095
-- **§148** — The loop.c hoisting THRESHOLD is arithmetic you can compute, and the `?:` clamp that folds to MIN_EXPR (P30 S42, `func_8017C6F4`, 947 ins) L10145
-- **§3-A.** — `move_movables` hoists iff `threshold × savings × lifetime ≥ insn_count` — and you can read it L10151
-- **§3-B.** — `(v < 0x40) ? v : 0x3F` is folded to `MIN_EXPR` and expands to the WRONG SHAPE L10170
-- **§3-C.** — A zero-byte ALLOCNO-PRIORITY slider L10184
-- **§3-D.** — Reproduce the original's BUGS verbatim L10194
-- **§149** — Four instrument defects in one session, and the two questions they were hiding (P30 S43) L10243
-- **§3-A.** — A prep step that returns its input on failure is indistinguishable from a search that found nothing L10249
-- **§3-B.** — Same address + same name ≠ same body — and the ledger keys on address L10267
-- **§3-C.** — `make: *** [...] Error N` is a summary, never a diagnosis L10283
-- **§3-D.** — "Cheap fuel" that was never probed: 0 of 31 templatable L10293
-- **§150** — A register ROTATION across symmetric blocks is VARIABLE-IDENTITY evidence, not an allocator tie (P30 S43, `func_8017C6F4`, 947 ins ×4) L10312
-- **§3-The** — fix L10319
-- **§3-The** — method that found it (this is the transferable part) L10329
-- **§3-Two** — corrections to the record L10345
-- **Diagnostic** — order (adopt this) L10356
-- **§151** — THE GHOST WEDGE: when a load-before-store transposition is unreachable by ANY statement order (P30 S43, `func_8017EF68`, 969 ins) L10367
-- **§3-The** — mechanism (read from cc1's own `-dR` trace, not inferred) L10372
-- **§3-The** — lever — a zero-emission insn that absorbs the blocked tick L10387
-- **§3-The** — two fallouts, and how to close them (both measured, in order) L10395
-- **When** — to reach for it L10407
-- **§152** — BYTE SIZE is the family key that name- and h_seq-grouping both miss (P30 S43, the 0xECC family: 1 crack → 12 overlays → 11,364 ins) L10418
-- **§3-The** — finding L10423
-- **§3-The** — key L10432
-- **§3-Two** — cautions that must travel with this technique L10443
-- **§3-The** — companion defect (open) L10454
-- **§153** — THE ADDRESS-REMATERIALISATION LAUNDER: a third zero-emission asm lever (P30 S43, `func_8018D98C`, 710 ins) L10466
-- **Symptom** — Symptom L10474
-- **Mechanism** — (gcc source + RTL dumps, not inferred) L10479
-- **What** — does NOT work (14 byte-measured probes) L10486
-- **§3-The** — cure — a fresh launder per site, each in its own block L10492
-- **Companion** — levers from the same function L10502
-- **§154** — Reading a disc payload: the module-id word, static base derivation, and "type 1 = uncompressed overlay" (P30 S44) L10522
-- **§3-A.** — Payload word0 is a global MODULE ID; code starts after the header L10527
-- **§3-B.** — Two static base-derivation methods that must AGREE (use both) L10536
-- **§3-C.** — PAC type 1 = the same payload class as type 4, just NOT compressed L10548
-- **§155** — hi/lo literal scanning MUST track base registers (S45) L10558
-- **§155a** — the same failure class, one level up: SHAPE-blind table scanning (S45 p5) L10567
-- **§155b** — check the TYPE your oracle returns before comparing against it (S45 p5) L10587
-- **§155c** — the ZERO-REFERENCE trap: gcc splits a global-array address across the `lui` and the LOAD (S46) L10610
-- **§156** — an ORPHANED reconcile poisons the fleet: `dedup_propagate`'s kept edit (S45 p6/p7) L10640
-- **§157** — the cheap-tier size cliff, measured (S45 p6) L10687
-- **§158** — The RANGE-EXTENDER: a fourth zero-emission asm lever completes the allocno toolkit (P30 S46 tier-3, `func_8017CE58`, 733 ins) L10712
-- **Symptom** — Symptom L10721
-- **§3-Why** — the fork is chained (gcc source, validated insn-by-insn against -dS/-dR dumps) L10727
-- **§3-The** — method (dump-arithmetic first, then place — no probing) L10740
-- **Bonus** — facts worth keeping L10757
-- **§156** — THE PREFERENCE-DONOR MERGE: cross-region variable reuse is what fills a0-a3, and a call-arg use in ONE region steers the fill in ALL of them (P30 S46 tier-3, `func_80186E24`, 611 ins: 236-off "S11 regalloc-order" → MATCH, zero new pins) L10772
-- **§159** — THE DECLARATION AXIS: conform to byte-truth, and make every guard state its COVERAGE (P30 S47; ~10,930 sites across 8 axes, fleet byte-identical) L10828
-- **§160** — THE REACH-15 WAVE HARVEST: an align-1 block move, and the instrument that called it a wall (P30 S47) L10893
-- **§161** — THE RETRY-WAVE HARVEST: a jump table indexed from zero, and two allocator traps (P30 S47) L10969
-- **§162** — S48 WAVE-1 HARVEST (P30, 2026-08-11): the reach-ordered sibling campaign's first 12 targets L11014
-- **§162a** — SHARPENS *(sharpens §161a, §131, §8a-pad, §129a)* L11041
-- **§162b** — SHARPENS *(sharpens §48-A3, §156, §150, §76)* L11070
-- **§162d** — SHARPENS *(sharpens §31, §21, §30, §55a)* L11099
-- **§162e** — NEW L11141
-- **§162** — THE LICM PAIR: what makes an address a movable AT ALL, and why the preheader order is the body order (P30 S47, `ov_MAIN_012`) L11143
-- **§162f** — SHARPENS *(sharpens §42d, §41d, §73, §10)* L11209
-- **§162g** — NEW L11264
-- **§162** — CROSS-JUMP DIRECTION: the surviving copy is always the LATER one, so a BACKWARD `j` into a sibling arm is a source `goto` (P30 S48) L11266
-- **§162h** — SHARPENS *(sharpens §88, §88a, §50-B, §8)* L11300
-- **§162** — The cross-jump "CALL veto" is a COUNT law, not a CALL law (BOUNDS §88a; P30 S48, `func_80189540`) L11302
-- **§162i** — SHARPENS *(sharpens §135, §21, §42, §32)* L11368
-- **§162j** — SHARPENS *(sharpens §25, §136d-1, §48-B, §46-L2)* L11393
-- **§162k** — SHARPENS *(sharpens §1-I2, §12, §160d, §21)* L11422
-- **§162l** — SHARPENS *(sharpens §48-B, §48-C1, §20, §21)* L11485
-- **§162m** — SHARPENS *(sharpens §36, §158, §148, §153)* L11540
-- **§158a** — THE FIFTH LEVER IS NOT AN ASM: `do { } while (0)` is a REGION ref-multiplier you MINT (P30 S48, `func_8017CBC8`, ov_MAIN_012 / jr_801789AC, 188 ins → MATCH) L11542
-- **§3-The** — law L11549
-- **Size** — it before you write it (§158 step 1-2, applied) L11560
-- **§3-The** — wrap BOUNDARY is the dial — and it is indiscriminate L11581
-- **§3-Not** — a pure dial L11587
-- **DIAGNOSTIC** — TELL — two faces, one law L11591
-- **§162n** — NEW L11613
-- **§162o** — SHARPENS *(sharpens §158, §136-1, §136-6, §79)* L11646
-- **§162p** — SHARPENS *(sharpens §48-B, §46-L2, §156, §136d-1)* L11705
-- **§162q** — SHARPENS *(sharpens §30, §30a, §135-2, §136-13)* L11722
-- **§163** — S48 WAVES 2-3 HARVEST (P30, 2026-08-11/12): the five that were byte-probed and are actionable L11760
-- **§163z** — THE UNVETTED REMAINDER (do not cite as law; each needs a dedupe pass) L11828
-- **§164** — S48 §163z SKEPTIC PASS (P30, 2026-08-12): 190 claims vetted, 82 banked L11848
-- **§16Xy** — SHARPENS *(sharpens §136d-3, §37 /s-DEP LATTICE, §135-2, §136-13, §162q)* L12300
-- **§3-The** — `/s` drop clause is in ALL THREE dependence predicates, so the FIXED-ADDRESS STORE is what floats (P30 S48, `func_8017CA18`, ov_MAIN_012) L12302
-- **§164z** — REFUTED CLAIMS: do NOT re-derive these L13636
-- **§165** — S48 WAVE-4 HARVEST (P30, 2026-08-12): banked the same day the wave landed L13702
-- **§16Z** — SHARPENS *(sharpens §37 "the /s-DEP LATTICE", §136-13, §136-14, §16Xy, §162q, `gcc-2.7.2-map/sched.md` §64)* L14353
-- **§3-The** — ADDRESS-CLASS TABLE: which load/store pairs even REACH the `/s` clause (P30 S48 wave 4, `func_80185B44`, ov_SC03_014) L14355
-- **§165z** — REFUTED THIS WAVE: do NOT re-derive L14871
-- **§166** — THE DESTINATION-TU ORACLE (P30 S48): the seven-attempt bug that was never codegen L14915
-- **§167** — S48 WAVE-5/6 HARVEST (P30, 2026-08-12): the saturation point L14971
-- **§167z** — REFUTED IN WAVES 5/6: do NOT re-derive L16167
-- **§168** — THE COUSIN TIER (P30 S49, 2026-08-12): h_seq's exact-hash brittleness, measured — and the similarity map above it L16224
-- **§169** — THE MICRO-ADAPT LANE (P30 S49): edit a proven body, don't crack a new one L16276
-- **§170** — THE A-PROP WORD-DIFF CARD (P30 S49): the lane that had no owner L16323
-- **§171** — THE STALE SEED SYMBOL (P30 S50, 2026-08-13): why §170's 91%→57% was never codegen L16367
-- **§171a** — THE MECHANICAL A-PROP DRAFT (P30 S50): 256 members banked with no agent in the loop L16433
-- **§171b** — THREE CARRIES THE MECHANICAL DRAFT NEEDS (P30 S50, banking the top-reach families) L16483
-- **§172** — THE ORPHAN-SLOT MECHANISM v2 (P30 S50-Max): the complete frame-residue model for gcc-2.7.2 MIPS L16516
-- **§172a** — TWO DECOMPILATION TELLS FROM THE SAME DIG (P30 S50-Max) L16570
-- **§172b** — THREE MORE TELLS FROM THE GCC READ (P30 S50-Max, banked on Drew's ask) L16586
-- **§173** — THE STORED-PLUMBING RECOVERY RECIPE (P31 T6): symfix-first, per-group isolation, and where the verdicts have no drafts L16629
-- **§174** — THE ADAPT-CARD WAVE RECIPE (P31 waves A/B, 2026-08-14): prevention beats recovery L16665
-- **§175** — A CALLER-SAVED REGISTER PIN CAN BE A CORRECTNESS BUG, NOT JUST A SCHEDULING CHOICE (P31 wave H, 2026-08-15) L16735
-- **§176a** — THE VERIFICATION-LAYER LAWS (P31 overnight, 2026-08-15). What each check can and cannot prove. L16760
-- **§176b** — BATCH-GATING MECHANICS (P31): what changes when N drafts land in ONE .c L16800
-- **§176d** — THE CONFLICT TABLE MUST BE SEEDED FROM THE TU, AND KEYED PER FILE (P31 S52, 2026-08-15) L16826
-- **§176e** — SYMBOL IDENTITY IS COMPUTABLE OFFLINE (P31 S52): `tools/reloc_identity.py` L16865
-- **§176f** — THE DECLARATION FORM IS A MATCHING LEVER, SO RECONCILE TOWARD THE FORM THE MATCH NEEDS (P31 S52) L16922
-- **§176g** — SIZE A WAVE BY INSTRUCTIONS, NOT BY CARDS (P31 S52 — the adopted doctrine) L16953
-- **§176h** — THE BATCH-SUBSTITUTION HAZARD MAP (P31 S52): seven holes, three wrong fixes, one law L16991
-- **§3-A.** — The seven under-reporting holes (all in `gate_main`, all the same shape) L16999
-- **§3-B.** — Typedef handling — the only strategy that survives contact L17017
-- **§3-C.** — The limit that remains (recorded, not solved) L17039
-- **§3-C2.** — RECONCILE BEFORE THE FIRST GATE — a parked draft gets HARDER to bank, not easier L17046
-- **§3-D.** — The measured cost shape, and what to build next L17069
-- **§176i** — WHAT A STATIC PRE-GATE CHECK CAN AND CANNOT PROVE (P31 S52, wave Q) L17087
-- **§176j** — STOPPING A WAVE MID-FLIGHT COSTS THE IN-FLIGHT TAIL (and how much is recoverable) L17119
-- **§176j-2** — THE REPAIR PASS, MEASURED (do this instead of resuming) L17145
-- **§176k** — TWO SELECTOR BUGS THAT SILENTLY SHRINK A WAVE L17165
-- **§177** — 🔴 THE EPILOGUE RETURN-DELAY SLOT IS DECIDED BY YOUR SAVED-REGISTER SET, NOT BY SCHEDULING L17182
-- **§178** — SIX LEVERS MINED FROM THE WAVE-P JOURNALS (P31 S52), each byte-proven and source-cited L17239
-- **§3-A.** — THE `$0`-ADD OPAQUE COPY defeats `make_regs_eqv` (func_80033398, 93 ins) L17251
-- **§3-B.** — A `return ` IS A PRIORITY-1 HARD-REG SET THE SCHEDULER PLACES FIRST (func_8001BE30, 92 ins) L17267
-- **§3-C.** — SINGLE-SET TEMPS GET THE BIRTHING BOOST (func_8001D3FC, 196 ins) L17280
-- **§3-D.** — A NARROW TYPE BLOCKS COPY ELISION (func_8001D3FC — new idiom) L17288
-- **§3-E.** — THE ZERO-OFFSET ALIAS HOLE (func_80037028, 71 ins) L17295
-- **§3-F.** — `MEM_IN_STRUCT_P` ASYMMETRY IN `true_dependence` (func_80037144, 124 ins) L17304
-- **§3-G.** — TWO MODELLING TRAPS THAT COST THESE AGENTS SWEEPS OF HUNDREDS OF COMPILES L17310
-- **§179** — IDIOMS MINED FROM THE WAVE P/Q JOURNALS (P31 S52, harvest pass) L17326
-- **§179-A** — 🔴 A LOOP-WALKED POINTER **PARAMETER** HANDS ITS ARGUMENT REGISTER TO THE GIV (9 byte-proofs) L17336
-- **§179-B** — 🔴 THE HAND-WRITTEN-ASM TRANSCRIPTION CHECKLIST (maspsx + masked_diff; 10 byte-proofs) L17385
-- **§179-C** — 🔴 A FUNCTION WITH NO EPILOGUE (falls into a sibling's shared tail) MUST BE FILE-SCOPE `__asm__` L17435
-- **§179-D** — `gte_stflg` MUST CLOBBER `"$12"` OR THE WHOLE TEMP FILE ROTATES BY ONE L17486
-- **§179-E** — A `>2*MAX_MOVE_BYTES` BLOCK COPY IS A **STRUCT ASSIGNMENT**, NOT A HAND LOOP L17506
-- **§179-F** — PINNING A LOOP-WALKED POINTER IS A TOTAL OFF-SWITCH FOR STRENGTH REDUCTION L17532
-- **§179-G** — 🟡 A PIN CAN **CREATE** A COMBINE `LOG_LINK` AND DELETE AN `andi` (sixth RC-5 channel, n=1) L17555
-- **§179-H** — A MID-BODY `.global LABEL` PAIR SLICES A BYTE-COMPARABLE FRAGMENT OUT OF A LARGER ROUTINE L17582
-- **Considered** — and NOT banked L17605
-- **§176c** — MAIN (SLUS_007.26) CANNOT BE GATED INCREMENTALLY L17622
-- **§176** — SEVEN LEVERS FROM THE P31 OVERNIGHT WAVES (2026-08-15): statement order, false regalloc, and the pin that fights back L17633
-- **§176-A** — "SCHEDULE / DELAY-SLOT / LENGTH-DRIFT ±1" ⇒ check STATEMENT ORDER around the call first L17639
-- **§176-B** — "REGALLOC-PERM, 1-4 instructions off" ⇒ it is usually NOT register allocation L17663
-- **§176-C** — 🔴 WALL REFUTATION: a hard-register pin CANNOT schedule around a call, because of a genuine gcc-2.7.2 bug L17709
-- **§176-D** — CSE-class levers used in reverse (two sharpenings of §153 and cse_expr §2) L17735
-- **§176-E** — Two cheap source spellings, both cc1-probed L17761
-- **§176-F** — Misdiagnosis triage: four residual verdicts that were lying L17783
-- **What** — is NOT banked here L17800
-- **§180** — THE LEFTOVER-DRAFT HARVEST: RE-VERIFY WHAT YOU ALREADY HAVE BEFORE DRAFTING ANYTHING NEW L17813
-- **§180b** — WHAT THE PRE-GATE LADDER ACTUALLY FINDS IN A COLD PILE (the shape of integration debt) L17842
-- **§180c** — WHEN A BINARY'S MASS BAND IS SPENT, THE FLEET-WIDE DRAW IS STRICTLY BETTER L17861
-- **§181** — WHAT A WAVE'S GATE ACTUALLY REJECTS (P31 S53, measured on wave R's 45-draft main pile) L17879
-- **Only** — ONE of 27 blocked drafts was wrong. The other 26 were correct and unbankable. L17880
-- **§182** — §177's HONEST NEGATIVE: the epilogue lever cracked 4 of 16, and the `800c3` cluster held L17935
-- **§180d** — THE `pgrep` BRACKET TRICK PROTECTS THE PATTERN, NOT THE COMMAND LINE L17949
-- **§183** — THE DECLARATION-RECONCILIATION PLAYBOOK (P31 S53, measured on 20 byte-verified drafts) L17961
-- **§3-18** — of 20 reconciled while keeping the match. The two that did not are mechanism, not effort. L17962
-- **§184** — COMMENT-BLINDNESS IS A DEFECT CLASS, NOT A BUG (P31 S53: three tools, one root cause, one session) L18032
-- **§185** — EDIT THE SIDE THAT IS CHEAP TO VERIFY, AND CHECK A TU RETYPE AT ITS USE SITES L18060
-- **§186** — CROSS-JUMPING RUNS **AFTER** SCHEDULING, SO NO C-LEVEL BARRIER CAN STEER IT L18092
-- **§186b** — A NO-SAVE 16-BYTE FRAME IN A LEAF FUNCTION MEANS `s16` LOCALS, NOT A HIDDEN CALL L18113
-- **§186c** — WHERE A VALUE IS LOADED DECIDES WHICH ALLOCATOR OWNS IT, AND THEREFORE ITS REGISTER L18121
-- **§187** — 🔴 "SAME SOURCE" IS NOT "SAME OBJECT": THE SDK BUILD AND THE GAME BUILD DISAGREE ON GTE NOPS L18138
-- **§188** — 🔴 THE `jr $ra` + `addiu $sp` TAIL IS AN **ASSEMBLER** ARTIFACT, NOT A FRAME SHAPE L18176
-- **§189** — FIVE COMPILER LAWS MINED FROM THE WAVE R/S JOURNALS (P31 S53), each source-cited and re-derived by a second agent L18226
-- **§190** — THREE PRESCRIPTIONS FROM THE SAME HARVEST (weaker evidence than §189, honestly labelled) L18301
-- **§191** — WHAT THIS HARVEST DID **NOT** BANK (4 rejected, 4 narrowed) — recorded so it is not re-derived L18338
-- **§192** — THE PRE-GATE LADDER WAS MAIN-ONLY, AND NOBODY COULD SEE IT (P31 S54) L18360
-- **Three** — defects in one call path; the overlay slates that carry most of the wave work were being waved through L18361
-- **§193** — THE WAVE-T HARVEST (P31 S54): 71 index_gap reports -> 9 laws, 5 rejected, 61 already-covered L18425
-- **§193-A** — The wave card ships only OPEN-set pointers and discards the atlas's BANKED one — `exemplar`/`sibs` are stubs 100% by construction (tools/atlas.py:96/657), while `seed.ref` (matched pool, atlas.py:505-536) is dropped at build_wave_atlas.py:143 L18442
-- **§193-B** — A NARROW CAST OF A WIDE PARAMETER COSTS ONE EXTRA INSTRUCTION WHEN ITS STATEMENT SITS AFTER AN INTERVENING `jal` — AND THE DECIDER IS `combine.c:929`'s CROSS-CALL GUARD, NOT REGISTER ALLOCATION L18509
-- **§193-C** — gcc-2.7.2 cross_jump merges the SCHEDULED common SUFFIX only — there is no prefix/head merge, so §8/§48-A1's "duplicate into both arms and cross_jump refunds it" is a TAIL-only lever L18547
-- **§193-D** — A COMPILER-GENERATED ARGUMENT COPY IS A `optimize_reg_copy_1` TRIGGER: when the pointer's LAST use in a block precedes a call that takes the pointer *as a register*, sched1 hoists the implicit `move $aN,$sN` to the block top and local-alloc re-bases the WHOLE block's memory operands onto `$aN`. The only C dial is a label (the §165-24 goto-join) between the block and the call. L18581
-- **§193-E** — A varying-address (pointer) load is re-emitted once per CSE-LIVE INTERVAL, and naming it in a C local is the only C-level lever over that count — no store SPELLING has any reach L18652
-- **§193-F** — §148-A2 — The `threshold -= 3` STAIRCASE: `move_movables` admits a COUNT of invariants, not a boolean — two identical merged constants split hoisted/not-hoisted by LIST ORDER, and `insn_count` picks the rank cutoff L18682
-- **§193-G** — §164-54's "scope to ≥4 arms" bound is byte-wrong — the dispatch-topology oracle goes live at THREE case nodes (`balance_case_nodes` splits at `i > 2`), but only for a signed-after-promotion index L18746
-- **§193-H** — A pointer-derived base load `*(s32*)(p+K)` is uncacheable across ANY memory write or call (cse's third kill disjunct) — so the target emits one `lw` per store-separated RUN of spellings, and a run of stores sharing one `lw` is a C local you must declare L18807
-- **§193-I** — A DECLARED AGGREGATE LOCAL HAS AN 8-BYTE FRAME STRIDE — CEIL(size,8), NOT size. N ARRAYS THEREFORE COST 8·k MORE THAN ONE HAND-LAID STRUCT (k = how many of them have size mod 8 ≠ 0), AND THE TELL IS IDENTICAL INSTRUCTION COUNT WITH EVERY $sp DISPLACEMENT SHIFTED BY THE SAME CONSTANT. L18847
-- **§193-REJECTED** — what this harvest did NOT bank (recorded so it is not re-derived) L18906
-- **§194** — THE WAVE-U HARVEST (P31 S54): 64 index_gap reports -> 14 laws, 5 rejected, 44 already-covered L18933
-- **§194-A** — A zero-byte scheduling fence goes AFTER the defining statement to make that computation emit FIRST in its block — and the barrier predicate is `volatile`-or-colon-less, not the `"memory"` clobber (COMPLEMENTS §165-40; does not refute it) L18950
-- **§194-B** — A `addu $rA,$rB,$zero` copy feeding ≥2 `sh` stores is a SECOND, 16-BIT-DECLARED local — the width, not the clamp or the join liveness, is what keeps the copy (and func_80183094's pin + `"memory"` clobber are both provably inert) L19016
-- **§194-C** — A CALLER-SAVED loop counter proves its live range crosses ZERO calls — so it cannot share a pseudo with any value LIVE ACROSS a call (but it may freely share one with values that merely sit between calls) L19054
-- **§194-D** — Declared width of a computed-value local is a sched1 dial (count-neutral) — a replication + attribution correction of §165-17, NOT a new argument-register law L19117
-- **§194-E** — The wave card's `exemplar` is the TARGET ITSELF on 42/73 wave-U and 36/71 wave-T cards — a construction consequence of `atlas.py:657` (exemplar = max-nins OPEN member) meeting `build_wave_atlas.py:166` (one card per gid); and the shipped §193-A `seed_ref` is same-binary on 0/51, so no card field can ever name a destination-TU sibling L19158
-- **§194-F** — `if ((*p = v = f()) == 0)` is an expand-time pseudo SPLITTER (store_expr's `want_value && MEM` path), not a fold — it partitions one value between local_alloc and global_alloc. BOUNDS §21's L1872 bullet, whose stated direction is byte-wrong on 3 of 4 instances, and CLOSES the control §167-37 asked for. L19195
-- **§194-G** — Reading the integer half of a 16.16 stack aggregate: REGISTER-LIVENESS, not the C spelling, decides `sra` vs `lhu` — and the break is count-neutral L19268
-- **§194-H** — §164-29's WAR fence runs again at SCHED2 ON HARD REGISTERS: an in-place `v &= K` before a branch fences the store that reads v, and when TWO independent stores compete for the one delay slot the fence picks the winner at ZERO length drift (a WIDTH/sh!=sw swap, not a nop). Corrects §167-42's reconstruction (pseudo arm → hard-reg arm) and supplies its first re-runnable A/B. L19311
-- **§194-I** — §16N+2's magic-per-odd-part ladder has exactly one broken row — read the divisor arithmetically instead: d = round(2^(32 + post_shift) / magic_read_as_unsigned) L19349
-- **§194-J** — Back-to-back identical stores: flow.c's `last_mem_set` deletes the first, and only `volatile` saves it L19392
-- **§194-K** — Blind sched1's alias oracle with a second SET of a pointer pseudo — the first zero-byte, non-volatile, dependence-CREATING lever (corrects §167-05's "volatile is the only door"; fourth consumer of reg_n_sets) L19444
-- **§194-L** — §88b and §189-E are BOTH half-wrong, but not the way the candidate says: the compare-constant shape is a 2-D lookup (cmp_info ROW × constant-in-window), and naming matters on OPPOSITE sides of the window for the GE/LT rows vs the GT/LE rows L19522
-- **§194-M** — A STORE in a CONDITIONAL branch's delay slot proves its C statement DOMINATES the branch — reorg can never pull a store out of either thread (gcc-2.7.2, -mips1) L19570
-- **§194-N** — §193-D's C dial is misstated: the lever is a SURVIVING CODE_LABEL (a label with a real incoming edge), not "a label between the block and the call" — a bare label, or a `goto L; L:` pair whose target is the next active insn, is deleted by jump1 (jump.c:663-669 → delete_insn → jump.c:3458-3461, and jump.c:243 for the bare case) long before sched1/local-alloc, and costs exactly zero bytes L19628
-- **§194-REJECTED** — what this harvest did NOT bank (recorded so it is not re-derived) L19688
-- **§195** — THE WAVE-V HARVEST (P31 S54): 67 index_gap reports -> 14 laws, 9 rejected, 76 already-covered L19709
-- **§195-A** — §167-08's "an $aN READ before the jal is scratch" has a byte-proven FALSE-NEGATIVE class: an argument that DIES at the call is allocated straight into $aN, so its only def is a plain load far above the jal and every intervening use reads $aN — there is no positive tell in either direction, only the two-arity A/B L19723
-- **§195-B** — A CALL_INSN does not start a basic block in gcc-2.7.2 — so a call-crossing temp can be a LOCAL-alloc quantity (the missing precondition under §48-A2 / §52 / regalloc.md K8) L19794
-- **§195-C** — A call-argument `%hi/%lo` pair sitting at the block head, far above its `jal`, is a load-delay-gap filler chosen by SOURCE STATEMENT ORDER — swap the two independent statements nearest the call; a single-use `void *p = &SYM;` call-arg temp is OUTPUT-inert against it (but NOT expand-stream-inert) L19836
-- **§195-D** — §195 — `masked_diff.mask_for` returns 0 for EVERY `j`/`jal` word, so an internal `j` destination is invisible to match_one, the permuter scorer AND every similarity tier: a control-flow semantic error (which calls execute) surfaces as a 1-instruction residual mislabelled `DELAY-SLOT / profile=schedule`, or as an outright false MATCH L19884
-- **§195-E** — A 0/1 materialised at a JOIN immediately before the controlling `beqz`/`bnez` proves the source NAMED the condition — a truth expression in an `if`'s controlling position reaches `do_jump`, which has no value path L19952
-- **§195-F** — fold-const.c:4825 canonicalises a `?:` whose THEN arm is zero (or constant against a non-constant ELSE) by inverting the condition and swapping the arms — so a ternary's written arm order is byte-inert there, and `c ? 0 : X` is unspellable: it always compiles as `!c ? X : 0` L20010
-- **§195-G** — §NEW — TWO ARMS CALLING THE SAME CALLEE MERGE INTO ONE `jal` UNLESS EACH ARM'S OWN CODE CONSUMES THE RESULT: the C dial that keeps two call sites apart is WHERE the consumer test lives, and the branch SENSE you spell it with is byte-inert (jump.c:1737 canonicalises it) L20062
-- **§195-H** — §165-27g — ON A FIXED-SYMBOL GLOBAL, `extern T D[];` + `D[0]` IS THE CSE RELOAD DIAL, AT ZERO ADDRESSING COST, AND THE ELEMENT COUNT IS INERT (§165-27's `T v[2]` CAVEAT IS A LOCAL-FRAME FACT AND DOES NOT TRANSFER) L20110
-- **§195-I** — §145(b) AMENDED — the pointer-bump `addiu` is saved by cse, not combine: ANY second SET of a pseudo in the address's equivalence chain (in-place `p += K`, §145(b)'s `p = r;` copy, or an asm re-tie) kills the fold; the pass is cse and the gate is `invalidate`'s `reg_tick++` L20157
-- **§195-J** — GTE / PsyQ op CALL-vs-INLINE is a PER-SITE SOURCE FACT, not a TU style — both forms coexist in one TU (measured in 2 TUs), and the tell is the target's own opcodes (`lwc2`/`sqr`/`swc2` vs `jal`), not the sibling. Costs -8 ins on func_8018505C. Corollary: the game's inline `sqr` macro emits TWO hazard nops, the SDK's `Square0` body emits ONE — so the inline form is provably not `Square0` inlined (a second instance of §187's SDK-vs-game GTE nop divergence). L20222
-- **§195-K** — At -O2 the §18 array-of-struct lever is a FRAME lever, not a length lever — but only when the N reads carry DISTINCT index expressions; with a SHARED index §18's +2-instruction residual is still alive at -O2 (the submitted "memory-loaded narrow index" precondition and unconditional length-neutrality are both falsified) L20266
-- **§195-L** — The cse store-re-seed does not cross a JOIN LABEL: per-arm stores + a join read keep the reload that one join store deletes (bounds §193-E BOUND 1/BOUND 3 with §48-B's EBB boundary) L20318
-- **§195-M** — Frame `vars` is a SEQUENTIAL bump-allocation, not a flat sum: §193-I's CEIL(aggregate,8) term and §165-03/§167-06's 8×orphan term are the SAME frame_offset walk at two different compiler stages, and each stage re-CEILs frame_offset to 8 before it allocates L20370
-- **§195-N** — In a call-bearing chain of N≥2 `if (f(...)) return 1;` tests closed by `return 0;`, the LAST test must stay in STATEMENT form — the value form (`return f() != 0;` / `? 1 : 0` / `!!f()`) costs +1 `j` and empties the other N−1 delay slots. The cause is REORG block placement, not jump.c's `delete_jump`. L20419
-- **§195-REJECTED** — what this harvest did NOT bank (recorded so it is not re-derived) L20466
-- **§196** — PUT ON THE CARD WHAT THE TREE ALREADY KNOWS: the fleet's declaration consensus (P31 S54) L20512
-- **§197** — THE WAVE-W HARVEST (P31 S54): 68 index_gap reports -> 4 laws, 3 rejected, 41 already-covered L20567
-- **§197-A** — A NARROW SIGNED MEMORY READ FEEDING A CONSTANT `>>` LOSES ITS `lh`, AND THE CURE IS AN ASM RE-TIE (attribution CONTESTED: cse vs combine) L20581
-- **§197-B** — A REPEATED COMPARE OF ONE VALUE AGAINST ONE CONSTANT IS DELETED BY cse's `qty_comparison_code` CHANNEL (the non-EQ complement of §165-03) — and a front-end-opaque mask on EITHER compare is a pure-C dial that keeps the target's second branch L20619
-- **§197-C** — Fix A1 (operand order) cannot move a commutative destination whose .greg conflict set already contains BOTH operand hard registers — split the accumulate so the destination IS the load's pseudo L20647
-- **§197-REJECTED** — §197-REJECTED L20692
-- **§199** — THE WAVE-X HARVEST (P31 S54/S55): 63 index_gap reports -> 7 laws, 2 rejected, 56 already-covered L20707
-- **§199-A** — §189-A's asm→source inference is byte-FALSE: an interloper between a split constant's `lui`/`ori` is a SCHEDULE fact, not a source fact — and the separator is the BIRTHING BOOST, not a "priority floor" (§189-A's split-timing half survives; its "no statement order / no pin" absolute and the candidate's own forward-scheduler narrative both fall) L20718
-- **§199-B** — A permutation sweep that holds ANY statement fixed is not a sweep: the statement an agent pins as "obviously load-bearing" is the one carrying the signal, and the partial sweep returns a FLAT residual that reads as proof of order-invariance L20767
-- **§199-C** — A NEGATIVE CONSTANT MULTIPLY ALWAYS TAKES expmed's negate_variant — but whether you ever SEE the neg is decided by COMBINE, and for an EVEN |K| it never disappears L20812
-- **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` L20860
-- **§199-E** — §189-A BOUNDED AND CORRECTED — the discriminator is INSN_PRIORITY, not "is the interloper a constant": an insn between a `lui`/`ori` pair proves NOTHING about the source spelling unless it TIES the `ori` on priority, and on the pinned `-mcpu=3000` triple a dependent load never does L20920
-- **§199-F** — §164-36b — THE TARGET-HEAD FENCE IS A DELAY-SLOT THREAD SELECTOR, AND IT ONLY FIRES WHEN `mostly_true_jump > 0` (amendment to §164-36; its "−1 instruction" tell is falsified) L20979
-- **§199-G** — At TWO case nodes the switch-vs-if oracle is not blind — but the tell is ALL tests positive + a trailing `j default`, NOT the first test's polarity L21033
-- **§199-REJECTED** — §199-REJECTED L21088
-- **§200** — THE ALIAS IS THE UNIVERSAL DECLARATION ESCAPE: stop negotiating with the TU's spelling (P31 S55) L21099
-- **§201** — THE WAVE-Y HARVEST (P31 S55): 67 gap reports -> 5 laws, 8 rejected, 53 already-covered L21148
-- **§201-A** — §150-B applies to `decl_prior`'s DEF row: for an overlay-window symbol the banked "definition" is usually another overlay's function, and the card ranks it ABOVE the destination TU L21158
-- **§201-B** — In a narrowed PLUS/MINUS/AND/IOR/XOR expression the destination pointee is INERT — the sign of the materialized constant is decided by an OR over the UNWIDENED operands (convert.c trunc1), which bounds §1841 to direct constant stores L21190
-- **§201-C** — §X — A CALL'S OWN DELAY SLOT AND THE UPSTREAM CONDITIONAL BRANCH'S SLOT COMPETE FOR ONE INSN (the call's argument copy), AND ONE STATEMENT'S POSITION RELATIVE TO THE CALL DECIDES BOTH — the residual is visible at the BRANCH, not at the call L21270
-- **§201-D** — THE SIGNEDNESS OF A div/mod MAGIC IS DECIDED BY THE STATIC TYPE OF THE DIVIDEND TREE AFTER `get_narrower` STRIPS WIDENING CONVERSIONS — NEVER BY A PROVABLE RANGE. AN `& 0xFF` IS NOT A CONVERSION, SO IT NEVER FLIPS THE MAGIC; A DECLARED-UNSIGNED LOCAL *OR* A NARROWING CAST WRITTEN AT THE DIVIDE BOTH DO. L21321
-- **§201-E** — §194-J-2 — The `last_mem_set` deletion window is measured in SOURCE/expand order, not in the printed stream; a foreign store moved between the pair in C source is a real lever, and `volatile` is not always the better one L21368
-- **§201-REJECTED** — eight, the session's highest L21424
-- **§202** — THE ALIAS CARRIES A DEFINITION, NOT JUST A DECLARATION: the DEF-SIDE-RETURN wall (P31 S56) L21449
-- **§203** — A DEDUPED TYPEDEF MUST PRECEDE EVERY SPLICE POINT, NOT JUST ITS OWN (P31 S56) L21486
-- **§204** — THE WAVE-Z HARVEST (P31 S56): 82 gap reports -> 5 laws, 16 rejected, 30 already-covered L21547
-- **§204-A** — A COMPARE THAT APPEARS BOTH IN A BRANCH'S DELAY SLOT AND AGAIN ON THE FALL-THROUGH IS A JOIN WITH TWO INCOMING EDGES: THE TWO GUARDS ARE SEQUENTIAL `if`s, NEVER `if/else if` L21566
-- **§204-B** — A LOOP COUNT THAT ARRIVES ON THE STACK IS DECREMENTED IN PLACE: a fresh counter local can cost a real `move` AND permute the whole callee-saved file L21641
-- **§204-C** — WHEN A LOCAL BUFFER'S ADDRESS IS PASSED TO A CALL, ITS SIZE IS A FACT ABOUT THE CALLEE'S BODY, NOT ABOUT THE CALL SITE: grep the callee's proven definition and count the stores through the pointer parameter before you declare the local L21705
-- **§204-D** — A LOOP-INVARIANT LOAD IS ADMITTED AS A MOVABLE ONLY IF ITS ADDRESS CANNOT TRAP: `local.field` PASSES, THE SAME READ THROUGH A POINTER LOCAL IS REFUSED L21763
-- **§204-E** — `decl_prior`'s `%hi/%lo` ARM HAS NEVER FIRED: the card's promised GLOBAL-TYPE row is 0 of 1,210 L21838
-- **§204-CONFIRMED** — 30 reports that the index already answered L21890
-- **§204-REJECTED** — sixteen, twice the previous record L21984
-- **§205** — THE CHAINED ASSIGNMENT IS ITS OWN SCHEDULING DIAL: `*b = *a = v;` moves an argument copy that no local, no pin and no statement reorder will move (P31 S56) L22057
-- **§206** — THE JTBL-CARVE DRAFTING IDIOM: the bounds check is the entry count, and an EMPTY case owns a slot (P31 S56) L22112
-- **§207** — THE WAVE ab–ag HARVEST (P31 S58): 278 byte-banked notes → 25 laws, 103 self-reported no-gap L22181
-- **§208** — TWO NAMED LOCALS FOR ONE RELOADED EXPRESSION BUY TWO ALLOCNOS — the naming granularity owns the REGISTER SPLIT, not just the load count (P31 S58) L22202
-- **§209** — THE NARROW LOCAL IS A DIAL IN TWO OPPOSITE DIRECTIONS, AND §194-B's "≥2 `sh` STORES" BOUND IS BYTE-WRONG (P31 S58) L22251
-- **§210** — THE SINGLE-BIT MASK IN A BOOLEAN TAIL: `andi K ; sltu $zero,v` vs `srl n ; andi 1` is a STATEMENT-SHAPE dial, not an operator choice (P31 S58) L22328
-- **§211** — HOIST THE LOOP INIT ABOVE THE DOMINATING GUARD: it fills the guard's delay slot AND flips the counter/pointer register pair (P31 S58) L22374
-- **§212** — THE WALKING CURSOR IS COUNTABLE: `*wp++` emits one `addiu` PER STORE, `wp[0..2]` emits one (P31 S58) L22433
-- **§213** — INDEPENDENT SAME-BASE STORES: THE EMISSION ORDER IS A PERMUTATION OF SOURCE ORDER, AND THE PERMUTATION IS NOT ALWAYS THE IDENTITY (P31 S58) L22478
-- **§214** — THE BANKED TWIN MAY BE A MACRO, A DELETED `.s`, OR A SEMANTIC INVERSE — six ways a ≥0.9 similarity lies (P31 S58) L22514
-- **§215** — PIN ECONOMY: the twin's pins are NOT part of the shape, and §17's "pin every call-crossing value" is over-broad (P31 S58) L22560
-- **§216** — DISTINCT ADJACENT SCALARS vs ONE ARRAY: one `lui` per access is the tell, and the array decl is UNUSABLE (P31 S58) L22616
-- **§217** — DECODING A CALL'S STACK ARGUMENT SLOTS: `sw` at `0x10`/`0x14`/`0x18` are params 5/6/7 **(single observation — not yet cross-confirmed)** (P31 S58) L22656
-- **§218** — A NARROW TYPE AT THE ABI BOUNDARY COSTS AN IN-PLACE `sll/sra` PAIR — on the RETURN as well as on the PARAMETER (P31 S58) L22682
-- **§219** — COMPOUND `+=`, FULL ASSIGNMENT, AND AN EXPLICIT TEMP ARE THREE DIFFERENT SCHEDULES OF ONE READ-MODIFY-WRITE (P31 S58) L22711
-- **§220** — THE PARAMETER ITSELF IS A REGALLOC DIAL: use it directly, prefer `s32` to `void*`, and place the save-copy AFTER the first call (P31 S58) L22738
-- **§221** — A CONSTANT SHARED BY TWO STORES DIES AT THE CALL WHOSE DELAY SLOT REFILLS ITS REGISTER **(single observation — not yet cross-confirmed)** (P31 S58) L22778
-- **§222** — SWITCH vs IF-CHAIN, PART 3: source arm order IS emission order, a leading EMPTY case buys the median split, and a 2-way dispatch with a shared post-block is a `switch` (P31 S58) L22794
-- **§223** — READING A `jal` DELAY SLOT: the value in it was produced BEFORE the call, so it is NEVER that call's return (P31 S58) L22836
-- **§224** — CROSS-JUMP: WRITE THE DUPLICATE, AND READ A SHARED DELAY SLOT AS THE MERGE SIGNATURE (P31 S58) L22898
-- **§225** — THREE CONTROL-FLOW SHAPES NO STRUCTURED SPELLING REACHES (P31 S58) L22934
-- **§226** — FRAME PADS: FOUR WAYS §162i1/§2429's DEAD-LOCAL LEVER MISFIRES (P31 S58) L22977
-- **§227** — TYPE THE SOURCE BY THE **LOAD** WIDTH, NOT BY THE STORE WIDTH (P31 S58) L23018
-- **§228** — READING THE DIVIDE, PART N: the off-by-one compare is `% K == 1`, and three more discriminators (P31 S58) L23038
-- **§229** — THE ADDRESS IS A VALUE: NAMING IT MOVES THE `lui`/`addiu` PAIR — AND §L14410 SAYS THE OPPOSITE FOR A REASON (P31 S58) L23075
-- **§230** — THE ANCHOR PROBE: with `%hi`/`%lo` masked, the surviving `addiu` deltas tell you which assignment was written first **(single observation — not yet cross-confirmed)** (P31 S58) L23124
-- **§231** — TRANSCRIPTION AND SEMANTIC-READ HYGIENE: six ways the listing misleads (P31 S58) L23139
-- **§232** — WHEN THE `jr` DELAY SLOT'S STORE STORES THE RETURN VALUE, TIE THEM WITH ONE PSEUDO **(single observation — not yet cross-confirmed)** (P31 S58) L23180
-- **§30** — addendum (P31 S58) — the `/s` grant closes a SCHEDULING residual and a REGISTER residual with one edit L23216
-- **§194-B** — addendum (P31 S58) — BOUND 2 is byte-wrong; see §209 Direction A L23236
-- **§176-B** — addendum (P31 S58) — the misdiagnosis direction L23242
-- **§165-40** — addendum (P31 S58) — the barrier goes at the COPY SITE, not inside the region it protects L23248
-- **§164-63** — addendum (P31 S58) — the interposed asm works when the SECOND value is an ordinary assignment L23257
-- **§193-A** — / §194-E addendum (P31 S58) — where the twin's body actually lives L23266
-- **§233** — THE WAVE aa–bg HARVEST (P31 S58b): 1,101 byte-banked notes → 24 new laws, 21 addenda, ~700 already-covered L23272
-- **§234** — CONSTANT MATERIALISATION: THE STORE LVALUE'S SIGNEDNESS PICKS `addiu` vs `li`/`ori` (P31 S58b) L23316
-- **§235** — THE PHANTOM SYMBOL: A MASKED `MATCH` CAN CARRY A RELOCATION THAT DOES NOT EXIST (P31 S58b) L23357
-- **§236** — THE DECLARATION LAYER IS THE DOMINANT BANK-BLOCKER: NINE WAYS A BYTE-PERFECT BODY FAILS THE GATE (P31 S58b) L23386
-- **§237** — THE CAST-AT-CALL-SITE DECISION TABLE: WHAT §17a-1 FIXES, WHAT IT CANNOT, AND THE FOUR ESCAPES (P31 S58b) L23465
-- **§238** — SAME NAME, DIFFERENT FUNCTION: THE OVERLAY-HOMONYM TRAP (P31 S58b) L23520
-- **§239** — TWO-STATEMENT INTEGER-SPACE MATERIALISATION REORDERS `la` vs `sll`; AND THE PLUS-TREE OPERAND ORDER (P31 S58b) L23560
-- **§240** — `A + K + B`: WRITE THE CONSTANT **BETWEEN** THE TWO RUNTIME TERMS (P31 S58b) L23594
-- **§241** — THE FOLDED SIGN-EXTEND-AND-SCALE: `sll 16 ; sra (16 − log2 scale)` (P31 S58b) L23623
-- **§242** — `*k` vs `<>n`: EXPRESSION SPELLING OWNS THE LOAD WIDTH AND THE ROUNDING CHAIN (P31 S58b) L23652
-- **§243** — SPELL THE CSE BARRIER AS A REASSIGNED POINTER; AND THE `nop`-AFTER-EVERY-`lh` SIGNATURE (P31 S58b) L23680
-- **§244** — `volatile` IS A COUNTING INSTRUMENT, A STORE-ORDER PIN, AND MUST SOMETIMES BE ASYMMETRIC (P31 S58b) L23710
-- **§245** — THE CALL'S ARGUMENT LIST IS A SCHEDULING SLOT (P31 S58b) L23745
-- **§246** — THREE-LIVE-VALUE SCAN LOOPS WANT ADDRESS-FROM-INDEX; AND TWO SYMBOLS CAN SHARE ONE giv (P31 S58b) L23792
-- **§247** — TWO BRANCHES TO **ONE** LABEL MEANS THE SOURCE CONDITION IS NEGATED (P31 S58b) L23832
-- **§248** — SPLIT THE LOAD FROM THE ARITHMETIC: A FUSED `g + K` DENIES THE CALLEE-SAVED REGISTER ITS DIRECT HOME (P31 S58b) L23866
-- **§249** — THE SELF-ASSIGN, THE DEAD RE-ASSIGN, AND THE `+ zr` COPY: THREE WAYS TO MAKE A DELETED INSTRUCTION REAL (P31 S58b) L23890
-- **§250** — `%hi/%lo` vs `lw`: THE EXTERN'S ARRAY-vs-SCALAR SHAPE DECIDES ADDRESS MATERIALISATION (P31 S58b) L23932
-- **§251** — IMMEDIATE-SPELLING TRIGGERS: `+= 0xFF`, FULL-WIDTH `~K`, AND THE TWO-OR SPLIT (P31 S58b) L23969
-- **§252** — THE GUARDED PRE-DECREMENT: `(x != 0) && (--x == 0)` (P31 S58b) L23991
-- **§253** — POSTFIX `++` vs `+= 1` PICKS A DIFFERENT SCRATCH REGISTER **(single observation — not yet cross-confirmed)** (P31 S58b) L24012
-- **§254** — THE DEAD PARAMETER IS A REGISTER-PLACEMENT TOOL **(single observation — not yet cross-confirmed)** (P31 S58b) L24026
-- **§255** — THE EMPTY CASE, PART 2: FOUR TREE SHAPES IT BUYS (P31 S58b) L24038
-- **§256** — GOTOS IN THE TARGET'S BLOCK ORDER REPRODUCE SWITCH PLACEMENT WITHOUT SWITCH'S SIDE EFFECTS (P31 S58b) L24073
-- **§257** — THE DEAD-END LEDGER (P31 S58b): ELEVEN LEVERS THAT MEASURED NULL OR BACKFIRED L24110
-- **§258** — ADDENDA TO EXISTING SECTIONS (P31 S58b) L24153
-- **§30** — addendum (P31 S58b) — THE ANONYMOUS STRUCT MEMBER REF GRANTS `/s`, AND THAT IS A TWO-FOR-ONE L24158
-- **§194-B** — / §209 addendum (P31 S58b) — TWO MORE INSTANCES, AND THE BOUND IS NOW REFUTED FOUR WAYS L24179
-- **§202** — addendum (P31 S58b) — THE DEF-SIDE ALIAS ALSO CLEARS A RETURN+PARAM DOUBLE CONFLICT L24202
-- **§205** — addendum (P31 S58b) — CHAINED ASSIGNMENT: N≥3 IS INNERMOST-FIRST, AND THE TEXT MIRRORS EMISSION L24213
-- **§208** — addendum (P31 S58b) — IT SCALES TO SIX SITES, AND IT HAS AN EXACT INVERSE L24230
-- **§210** — addendum (P31 S58b) — THREE CONFIRMED SPELLINGS OF THE BOOLEAN TAIL L24259
-- **§211** — addendum (P31 S58b) — INIT PLACEMENT: FIVE MORE DIALS BEYOND THE GUARD HOIST L24275
-- **§213** — addendum (P31 S58b) — THREE MORE PERMUTATION LAWS FOR INDEPENDENT SAME-BASE STORES L24318
-- **§214** — addendum (P31 S58b) — FOUR MORE WAYS A HIGH-SIMILARITY TWIN LIES L24347
-- **§215** — addendum (P31 S58b) — PIN ECONOMY, PART 2: NINE REFINEMENTS L24383
-- **§217** — CROSS-CONFIRMED (P31 S58b) — AND THE INCOMING HOME SLOT IS THE MIRROR L24435
-- **§220** — addendum (P31 S58b) — THE PARAMETER, NOT A COPY (SEVEN CARDS) L24452
-- **§222** — addendum (P31 S58b) — IF-CHAIN vs SWITCH: THREE MORE DISCRIMINATORS L24477
-- **§223** — addendum (P31 S58b) — FIVE MORE CONFIRMATIONS, AND THE CONSTANT-IN-`$v0` CASE L24495
-- **§224** — addendum (P31 S58b) — CROSS-JUMP MERGES *CALLS*, AND THE DELAY SLOT IS THE DISCRIMINATOR L24519
-- **§225** — addendum (P31 S58b) — THE GUARD-CLAUSE FINGERPRINT, AND THREE MORE SHAPES L24549
-- **§226** — addendum (P31 S58b) — THE FRAME CATALOGUE: SEVEN MORE LEVERS, AND SLOT ORDER IS DECLARATION ORDER L24576
-- **§229** — addendum (P31 S58b) — NAME IT **INSIDE** THE ARM L24621
-- **§230** — CROSS-CONFIRMED (P31 S58b) L24632
-- **§231** — addendum (P31 S58b) — FOUR MORE WAYS THE LISTING MISLEADS L24641
-- **§232** — CROSS-CONFIRMED (P31 S58b) L24672
-- **§259** — THE DISCARD LEDGER FOR THE aa–bg HARVEST (P31 S58b): WHAT WAS MINED AND REJECTED, AND WHY L24683
-- **§260** — THE §154-A LEADING-ISLAND SPLIT: ONE CONFIG LINE, AND THE ISLAND PEELS FROM THE END (P31 S59, byte-proven) L24722
-- **§260-A** — STAGE 2 IS PROVEN, AND THE WHOLE jtbl PIPELINE IS AUTOMATED AT THE GATE (P31 S59, same day) L24772
-- **§261** — THE -O0 ORACLE: DERIVE THE OPT LEVEL FROM THE TARGET, AND `$fp` IS NOT THE TELL (P31 S59) L24808
-- **§261a** — THE -O0 FRAME-RELOAD GRAMMAR: reload COUNT disambiguates the C spelling (P31 S59, byte-proven) L24834
-- **§262** — A LANE'S YIELD IS ONLY A LANE FACT IF IT IS SIZE-MATCHED (P31 S59) L24856
-- **§263** — A STOLEN DELAY SLOT WHOSE INSTRUCTION IS AN ARG-REGISTER COPY IS AN ARITY ERROR, NOT A SCHEDULE (P31 S59, byte-proven) L24886
-- **§264** — FOUR TELLS-LANE C RECIPES, EACH DRIVEN TO MATCH (P31 S59) L24927
-- **§265** — THE VERBATIM-ASM BANK LANE: A FUNCTION NO -O2 C CAN EVER MATCH BANKS AS A RAW `__asm__` BODY (P31 S59b; two banked cards, two in-tree precedents) L24977
-- **§266** — THE INERT-RIDER LAW: A LEVER IS ONLY CITABLE WHEN ITS SOLO REMOVAL BREAKS THE MATCH (P31 S59b; measured 4-of-8 on this batch) L25039
-- **§267** — ADDENDA HARVESTED FROM WAVES at/bh/bk/bl (P31 S59b) L25079
-- **ADD-1** — → §231 addendum (also cross-ref from §195-D) — THE MASKED-`jal` "MISSING CALL" ILLUSION L25087
-- **ADD-2** — → §42a addendum — A SHARED CONSTANT *NAMED IN A LOCAL* ACROSS A `jal` IS AN ISO→TU DRIFT HAZARD; WRITE BARE LITERALS L25096
-- **ADD-3** — → §236, item 10 — THE UN-DELETED `INCLUDE_ASM` STUB IS A DUPLICATE DEFINITION L25108
-- **ADD-4** — → §225-3/-4 addendum — THE MIRROR ROW: VALUE-RETURN IN THE *TAKEN* ARM + TRAILING BARE `return 0` L25118
-- **ADD-5** — → §1/I1 addendum — THE INVERTED RANGE TEST: `(u32)(x-lo) >= N` WITH THE ZERO-ARM AS THE TRAILING `else` L25132
-- **ADD-6** — → §172b-1 / §264 addendum — SHIFT-AS-TEST: `(x << 16) != 0` TESTS THE LOW HALF WITHOUT TRUNCATING THE PSEUDO L25141
-- **ADD-7** — → §256 addendum — THE SINGLE-GUARD GOTO: THEN-BLOCK OUT OF LINE AT THE TAIL L25150
-- **ADD-8** — → §245 addendum — THE RE-TIE BARRIER PINS CALL-ARG SETUP TO SOURCE ORDER (construct 6) L25162
-- **ADD-9** — → §213-3 / §217 addendum — ADJACENT PRE-CALL FRAME STORES ARE ONE AGGREGATE; THE UNESCAPED SCALAR NEIGHBOR IS DEAD-STORED L25174
-- **ADD-10** — → §237 addendum (arity-evidence paragraph) — AN `la` PAIR ABOVE THE PROLOGUE `sw $ra` IS AN OUTGOING-ARGUMENT MATERIALISATION L25184
-- **ADD-11** — → Cross-confirmation card block (per §259's standing instruction: confirmation, not news) L25193
-- **§268** — A `register __asm__` PIN ON A CALL-CLOBBERED REGISTER IS HONORED EXACTLY WHEN THE PINNED RANGE CROSSES NO CALL (P31 S59c; three A/B'd cards, unifying §257-2's two) L25244
-- **§269** — ADDENDA HARVESTED FROM WAVES ax/bm (P31 S59c) L25298
-- **ADD-1** — → §257-8 addendum — THE INTERPOSED ASM'S `__volatile__` IS A PER-SHAPE DIAL, AND THE "NO-OUTPUT ASM IS IMPLICITLY VOLATILE" LORE IS BYTE-FALSE IN gcc-2.7.2 L25313
-- **ADD-2** — → §236 addendum (item 1 corollary) — THE SILENT-SPLICE DECLARATION LADDER: WHERE THE TU HAS NO SPELLING, UNPROTOTYPED `()` BEATS THE FLEET VOTE L25326
-- **ADD-3** — → §238 addendum — TWO BINARIES CAN EACH DEFINE THE SAME `func_` NAME WITH DIFFERENT BYTES, AND NO GENERATED REPORT SHOWS IT L25340
-- **ADD-4** — → §167-37 addendum — THE FIFTH PRECONDITION, NOW MEASURED: DOWNSTREAM FIELD RE-READS ⇒ NAME IT **AND** STORE **INSIDE** THE ARM L25353
-- **ADD-5** — → §267-ADD-6 / §172b-1 addendum — THE SIGN-TEST FACE: `(s16)v < 0` IS `sll 16` + `bgez` ON THE SHIFTED COPY, RAW STAYS LIVE — AND THE HALFWORD-ABS SHAPE NEEDS NO RITUAL L25370
-- **ADD-6** — → §220-addendum — THE FOURTH FACE: WHEN THE NAMED COPY ITSELF BUYS THE EXTRA CALLEE-SAVED, PIN THE COPY TO `$16` L25386
-- **ADD-7** — → §229 addendum — THE VALUE FACE: A LOOP-STORE CONSTANT SPELLED AS A LITERAL HAS NO SOURCE POSITION; NAME IT TO PIN THE PROLOGUE INIT ORDER L25402
-- **ADD-8** — → §30a addendum — THE THIRD COLUMN: `*p++` IS ALSO SERIALIZED BUT BURNS `addiu`; ONLY CAST-PLUS GIVES SERIALIZATION *AND* DISPLACEMENT FOLDING L25415
-- **ADD-9** — → §255 "AND CASE-BODY PLACEMENT" bound / §222-addendum-3 — ON A LARGE SPARSE TREE, BODIES FOLLOW **SOURCE** ORDER (measured by a one-word probe) L25430
-- **ADD-10** — → Cross-confirmation card block (per §259's standing instruction: confirmation, not news) L25444
-- **§3-1a.** — The §266 sweep — every solo-lever A/B run for this batch L25485
-- **§270** — The A-prop 0-bank anatomy: a byte-correct body still needs FOUR layers to agree (P31 S59) L25518
-- **§271** — Ordinal IMM pairing: text order is NOT emission order; emit CANDIDATES, let the oracle pick (P31 S59) L25536
-- **§272** — The `(void)`-decl + empty-call wall: K&R the DEFINITION, not just the decls (P31 S59) L25558
-- **§273** — A standalone compile is the WRONG oracle for a TU-destined draft (P31 S59) L25578
-- **§274** — ADDENDA HARVESTED FROM 18 WAVES (P31 S60): 315 candidates, 255 already covered, 21 sharpenings, 3 new laws L25593
-- **ADDENDUM** — to §179-C — the `.type NAME, @function` requirement L25599
-- **ADDENDUM** — to §134 — a typedef defined BELOW the splice point is stripped anyway L25646
-- **ADDENDUM** — to §179-D (GTE macro reference family) — `gte_SetRotMatrix`/`gte_SetTransMatrix` bodies L25676
-- **ADDENDUM** — to §82 — struct copies must stay MEMBER-WISE, not block-moved, to match a spill-slot save L25702
-- **ADDENDUM** — to §136d-1 (RC-12, the `$0`-add / opaque-copy family) — two symptoms beyond "compare reads the wrong register" L25740
-- **ADDENDUM** — to §20 — a global declared as `T *` may itself BE the array base, not a pointer to dereference L25779
-- **ADDENDUM** — to §1-I5 L25808
-- **ADDENDUM** — to §164-51 L25873
-- **ADDENDUM** — to §176-F5 L25889
-- **ADDENDUM** — to §225 L25918
-- **ADDENDUM** — to §224 — CROSS-JUMP: THE DUPLICATE CAN BE A PLAIN STORE, NOT ONLY A CALL L25963
-- **ADDENDUM** — to §164-64 — AN EMPTY CLOBBER ON AN ARGUMENT REGISTER CAN BE THE DELIBERATE FIX, NOT JUST THE ACCIDENTAL BUG L25997
-- **ADDENDUM** — to §244 — THE COMPILER BARRIER, NOT `volatile`, BLOCKS A STORE→LOAD HOIST THROUGH A POINTER-OFFSET FIELD L26028
-- **ADDENDUM** — to §172b-1 — TWO PLACEMENT DIALS THE PROMOTION LAW DOESN'T NAME: NARROW THE COUNTER'S DECLARED TYPE, AND MOVE THE CAST INTO THE LOOP BODY L26059
-- **ADDENDUM** — to §229 — A POINTER'S NUMBER OF USES DECIDES WHETHER ITS ADDRESS FOLDS OR SURVIVES A CALL L26106
-- **ADDENDUM** — to §172b-4 — THE PLAIN CAST-DIVISION ALREADY PRODUCES THE PATTERN; DON'T HAND-ROLL THE BIAS, AND KEEP THE OPERAND WIDE L26151
-- **ADDENDUM** — to §8 — WHEN `INCLUDE_RODATA` NEEDS A STANDALONE `.s` YOU CAN'T CREATE, CARRY THE FRAGMENT AS A FILE-SCOPE `__asm__` BLOB L26181
-- **ADDENDUM** — to §226 — A DEAD LOCAL SCOPED TO A NESTED BLOCK BUYS A MID-FUNCTION `addiu sp` PAIR, NOT A FRAME-SIZE CHANGE L26224
-- **ADDENDUM** — to §172a — RE-READING MEMORY (NOT NAMING A TEMP) IS WHAT KEEPS AN INCREMENT'S DELAY-SLOT FILL ALIVE L26263
-- **ADDENDUM** — to §225 / §256 — A GOTO TO A SHARED SET-POINT PREVENTS IF-CONVERSION FROM COLLAPSING A LATER BRANCH TEST L26294
-- **ADDENDUM** — to §211 — AN IN-LOOP ACCUMULATOR WANTS A CLOSED-FORM EXPRESSION WHEN THE TARGET REMATERIALISES ITS CONSTANT AFTER EVERY CALL L26336
-- **§275** — THE LEFTOVER-REGISTER READ L26371
-- **§276** — MIXED ADDRESS-EXPRESSION SPELLING FOR ADJACENT RELOCATABLE SYMBOLS IS A CSE-UNIFICATION DIAL, NOT JUST A BYTE-ENCODING CHOICE (P31 S60; `func_80180FE8`, ov_SC06_006, byte-proven) L26411
-- **§277** — RETURN-TAIL C SPELLING PICKS THE DELAY-SLOT-FILL vs TRAILING-MOVE TOPOLOGY, AND A NARROWER SECOND VARIABLE KEEPS TWO PSEUDOS INSTEAD OF ONE (P31 S60; `func_801846F0` ov_SC03_104, `func_801A44C4` md_SC07_004, both byte-proven) L26520
-- **§278** — ADDENDA HARVESTED FROM WAVE cf (P31 S60): 34 candidates, 13 already covered, 8 sharpenings, 4 new laws L26584
-- **ADDENDUM** — to §74 (func_800D0E30, resident) L26592
-- **ADDENDUM** — to §172b-4 (func_80185054, ov_SC03_097) L26628
-- **ADDENDUM** — to §265 (func_8017DC80, ov_SC07_002) L26666
-- **ADDENDUM** — to §17 (func_800CB794, md_MAIN_036) L26705
-- **ADDENDUM** — to §162p (func_8017C120, ov_MAIN_012) L26753
-- **ADDENDUM** — to §20 (~L1947) (func_80186AD0, ov_SC06_032) L26787
-- **ADDENDUM** — to §164-56 (func_8017F644, ov_SC04_005) L26817
-- **ADDENDUM** — to §237 (func_8017F7FC, ov_SC03_092) L26852
-- **§279** — A `do/while (p < end)` LOOP UNDER AN ENTRY GUARD: the guard decides the compare, not the loop (P31 S60; wave cf, func_8017F2A4, ov_SC03_096, byte-proven) L26881
-- **§NNN** — A DO-WHILE'S GUARD AND LATCH MUST REPEAT THE SAME BOUND EXPRESSION, NOT SHARE ONE LOCAL: THE REPETITION IS WHAT BUYS THE CSE'D COPY INTO A SECOND REGISTER (P31 S60; `func_8017F2A4`, ov_SC03_096, byte-proven 25/25) L26882
-- **§280** — THE CURSOR'S DECLARED TYPE PICKS `sltu` vs `slt`: a `T*` bound test is UNSIGNED by C rule, an integer cursor is signed (P31 S60; wave cf, func_800CAE74, md_MAIN_031, byte-proven) L26915
-- **§NNN** — A LOOP CURSOR'S C TYPE (POINTER vs PLAIN INTEGER) SELECTS `sltu` vs `slt` FOR ITS BOUND TEST, INDEPENDENT OF THE VALUES INVOLVED (P31 S60; `func_800CAE74`, md_MAIN_031, byte-proven; cross-confirmed same wave by `func_8017F2A4`, ov_SC03_096) L26916
-- **§281** — GROUP COPY-THEN-RMW BY OPERATION KIND, NOT FIELD BY FIELD: sched1 does the interleaving, the source must not (P31 S60; wave cf, func_80180FB4, ov_SC03_111, byte-proven) L26949
-- **§NNN** — A DEPENDENT COPY-THEN-RMW BLOCK MUST BE SOURCE-GROUPED BY OPERATION KIND, NOT BY FIELD, AND SCHED1 DOES THE INTERLEAVING (P31 S60; `func_80180FB4`, ov_SC03_111, byte-proven) L26950
-- **§282** — gcc's OWN LOOP REVERSAL PUTS THE COUNTER INIT AFTER THE HOISTED MOVABLES — a position no hand-written down-count can reach (P31 S60; wave cf, func_80180DD8, ov_SC04_005, byte-proven) L26995
-- **§NNN** — WRITE THE UP-COUNT LOOP: gcc's OWN REVERSAL PRODUCES A COUNTER-INIT INSTRUCTION THAT LANDS AFTER HOISTED MOVABLES, WHICH A HAND-WRITTEN DOWN-COUNT LOOP CANNOT REPRODUCE (P31 S60; `func_80180DD8`, ov_SC04_005, byte-proven) L26996
-- **What** — I could not verify L27033
-- **§283** — ADDENDA HARVESTED FROM THE 36-WAVE BATCH (P31 S60): 1,216 candidates, 859 already covered, 46 sharpenings, 9 new laws L27080
-- **ADDENDUM** — to §164-75 — the fold-reassociation law also fires at a variable's INITIALIZER, not only a later expression L27090
-- **ADDENDUM** — to §21 — the `bltz`+`slti` (or N-separate-compares) signed-range-split bullet is now CONFIRMED on three independent functions, and generalizes beyond `lbu`/u8 L27116
-- **ADDENDUM** — to §202 — the DEF-SIDE ALIAS also resolves a function-vs-DATA-symbol identifier clash, not only a function-vs-function prototype clash L27162
-- **ADDENDUM** — to §22 (`volatile`-qualified-global reload lever, cookbook ~L1922) — for a NON-constant, same-address double RMW, a plain memory clobber beats `volatile`, and `volatile` actively breaks a delay-slot fill L27185
-- **ADDENDUM** — to §195-E — a goto-ladder's STORES must sit AT the labels, after the gotos, not inline before them L27204
-- **ADDENDUM** — to §195-N — a GNU statement-expression slider must sit INSIDE the conditional arm's value position, not as a post-hoc barrier, to block the store-flag transform on a ternary chain L27266
-- **ADDENDUM** — to §176-B2 — in a micro-function with no long/short lifetime asymmetry, BOTH contending pseudos need their own hard-register pin L27323
-- **ADDENDUM** — to §199-G — A `default:` LABEL GROUPED ONTO THE LAST CASE REMOVES THE `j default` TAIL, EVEN THOUGH THE 2-NODE HEADER STAYS ALL-POSITIVE L27370
-- **ADDENDUM** — to §220 — REFERENCING THE RAW PARAMETER (NO NAMED COPY, NOT EVEN A PIN) LETS THE CALLEE-SAVED SPILL LAND IN THE FIRST CALL'S OWN DELAY SLOT L27439
-- **ADDENDUM** — to §252 — a `>=0`/`<0` split on an unconditionally-decremented value needs the POSTFIX operator INSIDE the branch condition, not a prior statement L27497
-- **ADDENDUM** — to §215 — FIFTH SHAPE: reused mask constants across two call-free merge sites each get their own whole-function hard-register pin, and a shared sub-expression at the second site must be its own statement L27524
-- **What** — I could not verify L27607
-- **Harness-defect** — flags L27678
-- **ADDENDUM** — to §167-40 (func_8017E2CC, ov_SC04_015 — wave dg) L27771
-- **ADDENDUM** — to §20's cross-jump EXPLOIT bullet (func_8017E360, ov_SC05_007 — wave dg) L27791
-- **ADDENDUM** — to §87 (func_801815F4 ov_SC06_032; corroborating func_801840DC ov_SC05_017, func_80189C68 ov_SC03_006 — wave dg) L27805
-- **ADDENDUM** — to §153 / §236-5 (func_801A419C, md_SC07_003 — waves di and dl, corroborating; refutes a contradicted dj-wave card) L27824
-- **ADDENDUM** — to §263 (func_801E83AC, md_SC04_029 — wave dj) L27844
-- **ADDENDUM** — to §265 (func_8017D878, ov_SC03_107 — wave dj; corroborated by a REJECTED, contradicted card in wave dm — see closing) L27858
-- **ADDENDUM** — to §6 (func_801811F0, ov_SC03_102 — waves dj and dl, corroborated by a self-reported "nothing new" dm-wave card) L27872
-- **ADDENDUM** — to §195-G (func_80183BB0, ov_SC05_001 — wave dj) L27886
-- **ADDENDUM** — to the zero-byte-asm-slider family (§47 / §148-C / §153) (func_800CB874, md_MAIN_040 — wave dj; open tension with a more cautious dm-wave card — see closing) L27914
-- **ADDENDUM** — to §194-B (func_8017EB34, ov_SC03_117 — wave dk; distinct from the §74 co-pinning finding on the SAME function below) L27932
-- **ADDENDUM** — to §74 (func_8017EB34, ov_SC03_117 — counter/clamp variant; wave dj, corroborated by dk/dl/dm cards on the same function) L27964
-- **ADDENDUM** — §37 — merged into the §153/§236-5 entry above (func_801A419C, wave dl) L27984
-- **ADDENDUM** — §6 — merged into the §6 entry above (func_801811F0, wave dl) L27992
-- **ADDENDUM** — to §238 (func_80182CB4, ov_SC02_000 — wave dl) L28000
-- **ADDENDUM** — to §137a (func_801684B4, ov_MAIN_012; corroborated independently by func_80189E68, func_8017FF9C, func_801822B4, func_8018DA8C — wave dl) L28018
-- **ADDENDUM** — to §8c / §88d (func_8016AB6C, ov_MAIN_012 — wave dm) L28034
-- **ADDENDUM** — to §73 / §30#2 (func_800D1984, resident — wave dm) L28048
-- **What** — I could not verify L28064
-- **ADDENDUM** — to §174 Law 4 (func_8017E9A8, ov_SC06_015) L28084
-- **ADDENDUM** — the zero-emission-asm family gains a REF-SLIDER PLACEMENT LAW and a paired RESTORER (func_800CB900, md_MAIN_026) L28124
-- **From** — ck + cl + cm L28176
-- **ADDENDUM** — §NNN — sharpens §55a / §164-37 / §165-28 (switch-vs-tree cluster): A SHAPE THAT LOOKS LIKE A SWITCH DISPATCH CAN BE PLAIN NESTED `if`s WHOSE SHARED BODY WAS TRIPLICATED BY THE SOURCE AND THEN CROSS-JUMP-MERGED BACK DOWN L28182
-- **ADDENDUM** — §NNN — sharpens §167-13's boundary: CHAINING TWO IDENTICAL SIDE-BY-SIDE STORES INTO ONE C ASSIGNMENT STATEMENT IS A MID-BLOCK SCHEDULING-PRIORITY DIAL, NOT ONLY A STORE-ORDER SPELLING L28219
-- **ADDENDUM** — §NNN — sharpens §162a3/§60b: A `sll $v0,16 / sltiu $v0,1` ZERO-TEST OF A JUST-DECREMENTED HALFWORD IS A SIGNED-TEMP WIDTH TELL OUTSIDE ANY SWITCH/RANGE-TEST CONTEXT L28252
-- **ADDENDUM** — §NNN — sharpens §37/§124 (unspecified-parameter-list family): DERIVE A CALLEE'S ARITY LOWER BOUND FROM ITS OWN `.s` STACK-ARGUMENT READS, NOT FROM ANY SINGLE CALL SITE L28285
-- **ADDENDUM** — to §5a (func_80181F74, ov_SC03_112, wave cn) L28318
-- **ADDENDUM** — to §265 (func_8017E26C, ov_SC04_016, wave cn) L28368
-- **ADDENDUM** — to §42b (func_8018247C, ov_SC07_002, waves cu + cw) L28406
-- **ADDENDUM** — to §199-F family (func_8017EFB0, ov_SC02_021, wave cu) L28437
-- **ADDENDUM** — to §195-E (func_800CFC1C, md_MAIN_003, wave cv) L28492
-- **ADDENDUM** — to §215 addendum (func_800CB2C8, md_MAIN_033, waves cv + cw) L28537
-- **ADDENDUM** — to §236 item 4 (func_8017D268, ov_SC04_006, wave cw) L28593
-- **What** — I could not verify L28622
-- **Harness-defect** — flags (not idioms — flagged for the operator) L28654
-- **ADDENDUM** — to §250 (func_8017D7CC, ov_SC03_115 — cx/cy/cz/dr) L28695
-- **ADDENDUM** — to §225 (func_8017E190, ov_SC03_115 — cx/cy/cz) L28740
-- **ADDENDUM** — to §45-A (func_8017F6A4, ov_SC02_016 — cy/cz) L28793
-- **ADDENDUM** — to §249 (func_80182ED4, ov_SC04_004 — dp/dr/dt) L28837
-- **ADDENDUM** — to §199-A (func_801816FC, ov_SC02_005 — dp/dr/dt) L28882
-- **What** — I could not verify L28928
-- **Harness-defect** — flags L28971
-- **§284** — COMBINE CAN REASSOCIATE TWO SEQUENTIAL BITWISE-AND MASKS INTO ONE AGAINST THE PRE-MASK VALUE; AN ASM IN/OUT FENCE RIGHT AFTER THE FIRST MASK BLOCKS IT (P31, wave dd, `func_8018087C`, ov_SC04_020, byte-proven) (P31 S60; waves #, byte-proven) L29033
-- **§285** — PRE-INITIALIZING A VARIABLE WITH A SHARED CONSTANT BEFORE A BRANCH MAKES BOTH ARMS OF THE FOLLOWING if/else DESTRUCTIVELY REUSE THE SAME DESTINATION REGISTER FOR THEIR BITWISE RESULT (byte-proven; `func_801811F0`, ov_SC03_102, independently rediscovered across waves di/dj) (P31 S60; waves #, byte-proven) L29037
-- **§286** — FOLD A STATEMENT'S SIDE EFFECT INTO A COMMA-EXPRESSION IN AN ARGUMENT POSITION TO PLACE ITS RTL RELATIVE TO A CALL'S OWN DELAY SLOT (P31 S60/dj; `func_80180A88`, ov_SC06_010, byte-proven 411/411) (P31 S60; waves #, byte-proven) L29041
-- **§287** — A STACK-FRAME HOLE BELOW TWO ADDRESS-TAKEN AGGREGATE LOCALS IS A LEADING PAD MEMBER OF ONE COMBINED STRUCT, NOT SEPARATE LOCALS OR A REGISTER PIN (P31 S60/dj; `func_8017D104`, ov_SC06_027, byte-proven 47/47) (P31 S60; waves #, byte-proven) L29045
-- **§288** — A REGISTER PIN DECLARED UNINITIALIZED AND ASSIGNED ONLY AT ITS LATE, SOLE USE STILL FORCES THE FIXED REGISTER'S SAVE/RESTORE, AND THE ASSIGNMENT'S SOURCE POSITION CONTROLS WHERE THE VALUE MATERIALIZES (P31; `func_80186530`, ov_SC02_017, byte-proven, match_one MATCH re-verified) (P31 S60; waves #, byte-proven) L29049
-- **§289** — an array local's address-taken base keeps every element's store alive, even though only one pointer escapes (`func_80189EFC`, ov_SC04_011) (P31 S60; waves #, byte-proven) L29053
-- **§290** — A SINGLE STRENGTH-REDUCED GIV CAN DRIVE STORES TO SEVERAL DISTINCT RELOCATABLE SYMBOLS, EACH KEEPING ITS OWN `%hi`/`%lo` ANCHOR (P31 S60; waves #, byte-proven) L29057
-- **§291** — THE DELAY-SLOT FALSE-VALUE: A CONDITIONAL BRANCH'S ZERO ARM MUST BE A FALL-THROUGH-ADJACENT BLOCK ENDING IN AN EXPLICIT JUMP, OR REORG CANNOT MATERIALIZE IT INSIDE THE BRANCH'S OWN DELAY SLOT (P31 S60; waves #, byte-proven) L29061
-- **§292** — DECLARING A SYMBOL UPSTREAM OF AN ALREADY-BANKED SIBLING THAT RELIES ON THAT SYMBOL'S IMPLICIT (K&R) DECLARATION CAN SILENTLY REPROTOTYPE THE SIBLING'S OWN CALL SITE (P31 S60; waves #, byte-proven) L29065
-- **§293** — THE "WHOLE-OBJECT GATE NEEDS EVERY SIBLING" LAW, WRITTEN PROPERLY: IT IS THREE LAWS, AND THE LOAD-BEARING ONE IS "THE BASELINE, NOT THE SIBLINGS" (P31 S61; byte-proven on 15 binaries in one night) L29068
-- **§294** — ADDENDA HARVESTED FROM THE S61 GEN0/MAXTOK/MAIN/DEEPSEEK BATCH (waves ab8/ab16/ab24/ab32 · g0a–g0f · m0a · ds1/ds2): 99 candidates, 52 covered, 15 notes → 10 addenda, 29 notes → 5 new laws (§295–§299), 3 refuted L29118
-- **ADDENDUM** — to §127 — the -O0 constant-offset fold keys on the MEMBER-ACCESS tree shape, not on the index being constant L29129
-- **ADDENDUM** — to §261a — FOUR MORE -O0 DIALS BEYOND THE RELOAD COUNT (boot.c + md_MAIN_011/003, wave m0a/g0a/g0f, byte-proven) L29157
-- **ADDENDUM** — to §264-3 — the explicit entry copy's BOUND: required exactly when the RAW value must outlive the call that consumes only the PROMOTED value L29207
-- **ADDENDUM** — to §172b-1 (counter-type dial) — the sll's SOURCE REGISTER is the placement discriminator L29227
-- **ADDENDUM** — to §276 — the SHARE direction: spell the second adjacent symbol RELATIVE to force ONE anchor L29239
-- **ADDENDUM** — to §31's density-dummy dial (L2460/L2497) — the dose is TWO refs, and the dummy must sit where the loser is live-through L29255
-- **ADDENDUM** — to §282 — the ADDRESS-GIV face: write the walked address INLINE so strength reduction births the induction register at loop.c's own insertion point L29272
-- **ADDENDUM** — to §253 — SECOND byte-proven card (upgrade from single-observation), and the placement face: postfix-in-condition parks the RMW store in the branch delay slot L29295
-- **ADDENDUM** — to the L1800 anchor-steer bullet — a DERIVED-POINTER local silently flips the merged giv's anchor END L29316
-- **ADDENDUM** — to §31's asm→layout inference — TWO WIDTH-PAIR DISCRIMINATORS (same offset, different widths) L29339
-- **§295** — THE KERNEL-TRAP STUB: §81's jr-DETECTOR WITHOUT A TABLE IS A PsyQ SYSCALL TRAMPOLINE — ROUTE TO §265, NEVER INTO THE CARVE CHAIN (P31 S61; wave m0a, 9 cards byte-proven; resolves §182's held cluster) L29360
-- **§296** — THE FRAME CHECK OUTRANKS THE ATLAS LEVER: READ PROLOGUE/EPILOGUE BEFORE DRAFTING ANY C — A REAL TELL CAN LIVE INSIDE AN UNREACHABLE FRAGMENT (P31 S61; wave m0a, 16 cards byte-proven; extends §179-C) L29415
-- **§297** — ONE GIV SERVING MIXED-WIDTH LOADS *AND* A STORE NEEDS STRUCT-MEMBER SPELLING; CAST/INDEX SPELLINGS RE-SPLIT THE PSEUDO (P31 S61; wave m0a, `func_800347C8`, main, byte-proven 31/31) L29458
-- **§298** — THE SHARED-TAIL POSITION DIAGNOSTIC: A FOLDED TAIL *BETWEEN* SWITCH ARMS MEANS PER-ARM DUPLICATED STATEMENTS, NOT A HOISTED POST-SWITCH STATEMENT (P31 S61; waves g0e/g0f, `func_80181B68`, ov_SC06_016, byte-proven 68/68) L29501
-- **§299** — TWO INDEPENDENT EXTRACTION CHAINS EMIT CONTIGUOUSLY INSIDE ONE EXPRESSION; ONLY A STATEMENT BOUNDARY MAKES THE SCHEDULER INTERLEAVE THEM (P31 S61; wave m0a, `func_8003A404`, main, byte-proven 8/8) L29526
-- **§300** — S61 DISTILL BATCH NOTES (waves ab8/ab16/ab24/ab32 · g0a–g0f · m0a · ds1/ds2 · m0b) L29561
-- **§301** — AN INTERNAL `j` CARRIES `R_MIPS_26 .text`: rtu/match_one "MATCH" COULD NOT SEE WHICH LABEL A `j` TAKES — FIXED (`jrel`), AND THE TWO DRAFT SHAPES IT HID (P31 S62 T1; byte-proven 2/2, negative-controlled over 3,297 stubs) L29630
-- **§302** — A RED BINARY IS A DRIFTED SPEC, NOT A MYSTERY: THE THREE CARVE-STATE INVARIANTS AND HOW TO DERIVE EACH FROM THE BYTES (P31 S62 T2; five reds healed in one session, 5/5, +39 held banks) L29678
-- **§303** — MODULE ISLAND TABLES: DERIVE THE PADS AT BUILD TIME, PEEL NOTHING — THE §154-A/§260 "island-pads"/"island-blocked" WALLS DISSOLVE (P31 S62 T3a; byte-proven md_SC03_076 func_801F0A9C + func_801F0F28, sha 9a165e36…) L29722
-- **§304** — SELF-DEFINING RODATA: WHEN A FUNCTION'S `.s` IS THE ONLY OWNER OF THE DATA IT REFERENCES, THE C BODY MUST DEFINE IT (P31 S62 T3; byte-proven md_MAIN_011/func_800D04F4) L29758
-- **§305** — "CARVE-REFUSED" AT GATE TIME IS THREE NAMED, DETERMINISTIC CLASSES — NONE OF THEM A CARVE (P31 S62 T3; 28 resolver drafts autopsied 28/28) L29781
-- **§306** — A HAZARD `nop` IN FRONT OF A DIV-RESULT STORE IS A STATEMENT-ORDER DEFECT: THE INDEPENDENT TRAILING STATEMENT MUST BE WRITTEN *BEFORE* THE DIVISION-CONSUMING ONE (P31 S62 T4; byte-proven func_8017E7D0) L29833
-- **§306a** — T4 DISTILL ADDENDA (P31 S62; four byte-proven refinements to existing laws, verified against the book by an independent verifier; each names its parent §) L29860
-- **§307** — THE BRUTE-FORCE-THE-STATEMENT-ORDERS LEVER HAS A BOUND: A FAN-OUT COPY'S PRIORITY IS SCHEDULER-INTERNAL, AND NO SOURCE ORDER REACHES IT (P31 S63; byte-evidenced NEGATIVE result, main wave) L29898
-- **§308** — A NAIVE FINAL `goto` DELETES THE TARGET'S `j`+`nop`: SPELL THAT EDGE AS A TAUTOLOGICAL `if` SO cse FOLDS IT TO AN UNCONDITIONAL JUMP *AFTER* jump1's WINDOW HAS CLOSED (P31 S63 t5e-t5i; byte-proven func_80180808) L29942
-- **§308a** — A TWO-INSTRUCTION ARM STUB LAID *BEFORE* THE OTHER ARM AND REACHED ONLY BY A TRAILING `j` SURVIVES ONLY BEHIND A SHORT-CIRCUIT `&&` GUARD PLUS A SEPARATE RE-TEST; EVERY PLAIN if/else-if, GOTO-LADDER, NESTED-INVERTED-if AND 1-/2-NODE switch LETS jump1 INLINE IT (−2 ins) (P31 S63 t5e-t5i; byte-proven func_80180808) L29971
-- **§309** — A FRAME-ADDRESS EQUIVALENCE RIDES *THROUGH* A SKIPPABLE CONDITIONAL: POST-`if` STORES FOLD ONTO `$sp` UNLESS THE `if` SURVIVES jump1 AS A BARRIER-PRECEDED DIAMOND (P31 S63 t5e-t5i; byte-proven func_801812AC) L30005
-- **§310** — A TWO-OPERAND `subu`'s DESTINATION TIES ONLY TO THE OPERAND THAT IS BLOCK-LOCAL: SHARE *ONE* SIDE ACROSS BLOCKS TO CHOOSE WHICH OPERAND'S REGISTER IT LANDS IN (P31 S64 t5j-t5m; byte-proven func_8017F578) L30045
-- **§311** — A JOIN-BLOCK STORE CAN SWALLOW AN ARM'S LOAD-DELAY `nop`: WHEN ONE ARM'S VALUE COMES FROM A LOAD, DUPLICATE THE STORE INTO BOTH ARMS (P31 S64 t5j-t5m; byte-proven func_8017D7E0) L30076
+- **§41a** — v3.1: the def-side wall was ~71% TOOL-shaped — the five measured defects + the laws that dissolve them (Phase 25 T6, Fable5, 2026-07-09) L2769
+- **§41b** — T7 execution: the object-only probe OVER-counts BANKABLE by two link/rodata classes (Phase 25 T7-M1, 2026-07-10) L2824
+- **§41c** — T7-M2: the ×134 def-side-wall sweep via per-sibling RE-reconcile (Phase 25, 2026-07-10; 4,389 banks, ~0 agent tokens) L2854
+- **§41b** — addendum — M4 "reconcile_decls" tier is ALSO a probe over-count: 0/8 mechanical (Phase 25 T7-M4, 2026-07-10) L2873
+- **§41d** — `void`→`s32` is NOT always byte-neutral: gate the RAW draft FIRST (Phase 26 session 6, byte-proven) L2893
+- **§42** — The F-band ≤28 regalloc crack wave: register-pin/DENSITY levers beat the permuter (Phase 25 T7 F-band, 2026-07-10; Ultracode 9-worker wave, 4/9 banked byte-identical, 266 swept ×134) L2915
+- **§42a** — addendum — wave 2 (residuals + 29-100 band): iso-MATCH ≠ real-TU bank, the memcpy→struct-assign fix, +5 levers (2026-07-10b) L2968
+- **§42b** — addendum — wave 3 (Max, 2026-07-10c): THE STALE-OBJECT GATE TRAP + the read-global `&`-cast drift + fix L3009
+- **§42c** — addendum — wave 3 (Max orchestrator + CORRECTED Ultracode fan-out, 2026-07-10c): the real-TU-faithful parallel harness (rtu_match) + 7/9 crack, ZERO iso-drift L3048
+- **§42d** — addendum — wave 4 (rtu_match fan-out over the mapped frontier, 2026-07-10c): 24/26 MATCH, +5 durable levers L3097
+- **§42e** — propagating a CRACK ×134: the def-finder bug + the byte-drift residual (the "remap-fail" misdiagnosis) L3136
+- **§43** — The K&R s16-param definition DISSOLVES the "narrow-param wall" for by-value register args (Phase 25 task A, Fable5 crack of the 369-ins giant `func_80166994` ×134, 2026-07-11) L3210
+- **§44** — The Phase-25 cheap-Opus giant batch: 5 structural levers + the §43 extension (2026-07-11, 6 crackers over the frontier giants) L3257
+- **§45** — The flagship `func_80133CD4` crack (399 ins ×134): the merged-variable permutation-breaker + the 1-death local-alloc gate (Phase 25 task A giant escalation, Fable5 gdb-on-cc1, 2026-07-11) L3313
+- **§46** — The `func_80178D40` crack (890 ins ×134, the heaviest core in the game): four LOOP-STRUCTURE levers cheap-Opus found by reading loop.c/jump.c/cse.c (Phase 26 session 8, 2026-07-13) L3328
+- **§47** — The live-length SLIDER: splitting a global.c allocno-priority TIE with one zero-byte asm (Phase 26 session 8, Fable5 Max, byte-proven on `func_8017BEBC` 952 ins ×113) L3380
+- **§48** — The 12-core jr crack wave: the ALLOCNO-PRICING dials and the EBB rule (Phase 26 session 8, Ultracode, 9/12 MATCH first pass) L3420
+- **§3-A.** — ALLOCNO-PRICING DIALS — move a value into the register you want, byte-neutrally L3428
+- **§3-A4** — SINK THE CONSUMER CALL INTO THE ARMS (the inverse of A1; `func_8016AB6C`, byte-proven) L3459
+- **§3-B.** — THE EBB RULE — the general form of §46-L2 L3483
+- **§3-C.** — TYPE- AND SHAPE-DRIVEN CODEGEN (the C type literally selects the addressing mode) L3499
+- **§3-D.** — THE CROSS-JUMP RATCHET (the sharpest new trap — `func_80131340` L-C) L3523
+- **§3-E.** — Meta L3533
+- **§49** — The LUID DIAL: a zero-byte SCHEDULING dial (the sched.c analogue of §47) — `func_8017A4AC` (536 ins ×134), Phase 26 session 8 L3542
+- **§50** — Refinements that BOUND §47/§48 (from the `func_80135EB0` wall, 21→6; Phase 26 session 8) L3591
+- **§51** — TOOLING INTEGRITY: the silent skip, and how to hunt it L3645
+- **§51a** — The bug class L3651
+- **§51b** — Why the byte-gate cannot save you L3667
+- **§51c** — THE METHOD (do not audit by reading the regex) L3677
+- **§51d** — THE LAWS L3692
+- **§51e** — The false-wall pipeline (why this is not just hygiene) L3754
+- **§51f** — Checklist for any new corpus-scanning tool L3770
+- **§51g** — When the thing you are scanning has a GRAMMAR, parse the grammar (`tools/cdecl.py`) L3784
+- **§52** — The WALKER-FAMILY skeleton: 6 regalloc-order levers + a deeply-characterized intrinsic wall (`func_80178004`, 165 ins ×134; Phase 26, Fable5, 2026-07-15) L3928
+- **§3-The** — 6 levers (the "walker-family skeleton" — apply to the 12 siblings; levers 1-5 retire ~half the residual) L3939
+- **§3-Why** — the wall is (probably) intrinsic L3960
+- **§52a** — The regalloc sibling wave: new levers + two new wall classes (cheap-Opus applying §52, 2026-07-15) L3974
+- **§52b** — Sibling wave 2: more de-pin levers, a third wall class, and the match_one→whole-binary gap at scale (2026-07-15) L4012
+- **§53** — SWEEP A FAMILY WITH THE TOOL ITS EXEMPLAR NEEDED: the jr/switch carve, and how omitting it manufactured the "families don't template" doctrine (Phase 28 T1, 2026-07-15) L4043
+- **§3-The** — case L4048
+- **§3-Why** — 0/8 was structural, and predictable from two words L4060
+- **§3-The** — rule L4077
+- **§3-The** — meta-lesson (R35, and why this one is expensive) L4093
+- **§55** — Core-crack wave levers + the GATE-ORCHESTRATION law (Phase 29 T3, 13-agent ultracode wave, 2026-07-17) L4108
+- **§55a** — New byte-proven levers (each from a banked or near draft) L4113
+- **§55b** — THE GATE-ORCHESTRATION LAW (3 traps, ~3.5h lost; all recovered, 0 data lost) L4137
+- **§55c** — Sizing the propagate: a TARGETED propagate is ~4 min/core, and "it's slow" was a BROKEN-TREE ARTIFACT L4156
+- **§54** — `--fix-def-sig`: the member's CANONICAL DECLARATION is a build step too (tiny-IMM mega-pools, +4,801, Phase 29 T6, 2026-07-16) L4178
+- **§56** — Banking a hand-drafted GIANT into its exemplar TU: self-contained draft vs live-TU decls, 4 reconciliation tactics (`func_8013FAF8`, 312 ins ×138, Phase 29 T4, 2026-07-17) L4202
+- **§56b** — PROPAGATING an h_seq giant: the exemplar's externs MUST be fleet-canonical, not the draft's types L4247
+- **§57** — The SELF-decl normalize: the sibling's OWN caller declares the templated fn divergently (the third §17a-1 direction; `tools/normalize_self_decls.py`, func_801670E4 ×137, Phase 29, 2026-07-18) L4271
+- **§57a** — Two NSD corrections + the SURGICAL-ONLY law + the honest broad-sweep yield (Phase 29, 2026-07-18) L4318
+- **§58** — match_one MATCH ≠ BANK: the four blind spots + the crack-wave reconcile-before-bank law (Phase 29 crack-wave, 2026-07-18) L4358
+- **§59** — Three h_seq sweep-residual classes match_one/the-exemplar-bank don't reveal (Phase 29 crack-wave close, 2026-07-18) L4392
+- **§60** — Classify the residual, don't rank it: the deterministic residual→class classifier and what it measured about the backlog (Phase 29 Task-13A, 2026-07-21) L4422
+- **What** — it measured — the whole open backlog, byte-grounded L4446
+- **§3-Two** — corollaries worth remembering L4465
+- **§3-The** — parallel-probe race this surfaced L4478
+- **§60a** — What the first DIRECTED grinder run exposed (Phase 29 Task-13B, 2026-07-21) L4487
+- **§60b** — The plateau autopsy's verdict: a `partial` drift is a WRONG DRAFT, not a missing transform (Phase 29 Task-13B close, 2026-07-21) L4525
+- **§61** — Task 14: the gate ladder's missing stage is the ARITY pre-pass, and it is TU-side not draft-side (Phase 29, 2026-07-21) L4560
+- **§61a** — The Task-5 wave: 11/12 MATCH, 0 banked — three DISTINCT integration walls, each now named (Phase 29, 2026-07-21) L4621
+- **§61b** — The jtbl gate stage: built, and the ORDERING law it exposed (Phase 29 Task-14 stage 4, 2026-07-21) L4673
+- **§61c** — The jtbl bank is INCREMENTALLY valid and CLEAN-INVALID (Phase 29, 2026-07-21) — the blocking finding L4728
+- **§61d** — The undo was eating the tree: two tools, one defect, invisible to the byte-gate (Phase 29, 2026-07-22) L4794
+- **§62** — The jtbl RECONCILE must also follow the carve: the post-carve draft reconcile (`harvest_verify._jtbl_reconcile`, Phase 29 SESSION-11, 2026-07-22) L4848
+- **§63** — The fresh-138 DEF-SIDE blocker: fix the HEADER decl, not the draft (`fix_header_decl.py`, Phase 29 SESSION-13, 2026-07-23) L4892
+- **§64** — The §20 type-lift's three laws: fold the tagged typedef, check VISIBILITY, and strip only what is TEXTUALLY IDENTICAL (`lift_types.py`, Phase 29 SESSION-14, 2026-07-23) L4923
+- **§64a** — VARIANT types: UNIQUIFY the camps, do not reconcile them (`uniquify_type.py`, Phase 29 SESSION-14) L4972
+- **§63** — UPDATE (Phase 29 SESSION-14) — `fix_header_decl`'s "SAFE" verdict is FLEET-BLIND; it MUST be R22-validated L5015
+- **§65** — The stranded-draft recovery: BLAST-RADIUS TIERS, and the per-overlay de-macroize that refutes §20's DEF-conflict wall (`tools/demacroize.py` + `tools/blocker_probe.py`, Phase 29 SESSION-16, 2026-07-24) L5030
+- **§65a** — The blast-radius taxonomy (makes §61's law structural instead of remembered) L5045
+- **§65b** — The escape: de-macroize the instantiation, don't touch the shared header L5060
+- **§65c** — `rtu_match` MATCH → bank held 13/13 on self-decl, but broke on the FIRST callee-decl case L5096
+- **§65d** — Existing-ladder baseline, measured (do this before building a recovery stage) L5106
+- **§65e** — Two oracles, and the disagreement is the finding (R34 in practice) L5116
+- **§65f** — The de-macroize lever's BOUNDARY, measured: byte-neutral 14 times of 15, and the 15th is why the gate exists L5133
+- **§65g** — Where the cheap levers STOP: the local-type and in-TU-self-decl classes did not yield L5154
+- **§66** — Exercise a banking driver's SUCCESS path before pointing it at a wave: the free re-bank test (Phase 29 SESSION-17, 2026-07-24) L5174
+- **§66a** — The widest write in a pipeline is the one most likely to be UNDECLARED L5196
+- **§66b** — A metric parsed out of another tool's prose goes NULL silently when the label changes L5215
+- **§66c** — Before a wave, verify the FUEL exists; an "already attempted" set built from the wrong directory lies in BOTH directions L5232
+- **§66d** — The permuter⇄reader loop: alternate a random search with a byte-verified idiom, and let `residual_class` decide whose turn it is (Phase 29 SESSION-17) L5260
+- **§66d-1** — What transfers between giants is the LOOP, not the PIN L5295
+- **§66d-2** — Two operational sharp edges L5304
+- **§66d-3** — Read the ILS per-cycle SERIES, not its final best: a repeated score and a still-falling one look identical in a summary line and mean opposite things L5315
+- **§67** — The arg-copy PLACEMENT lever: launder a parameter into a fresh pseudo AT the statement where the target's copy lands (Phase 29 SESSION-18, `func_8014D820` 25 → 16) L5330
+- **§67a** — Run the symbol-set guard BEFORE you pay for a gate (`tools/symcheck.py`, Phase 29 SESSION-18) L5420
+- **§66d-4** — "ILS converged" means converged FOR THAT WEIGHT PROFILE, not a floor (amends §66d-3; Phase 29 SESSION-18) L5453
+- **§66d-5** — `residual_class`'s "structural ⇒ permuter CPU is waste" is WRONG for schedule permutations (measured, Phase 29 SESSION-18) L5506
+- **§68** — A comment-only line halted the extern scan, and the skip label blamed the type cap (Phase 29 SESSION-18) L5539
+- **§69** — How to attack a behemoth: map it, don't draft it (Phase 29 SESSION-18, `func_80183814`, 5,122 ins) L5584
+- **§70** — The giv-init base register: walk the PARAMETER, not a copy of it (Phase 29 SESSION-18, `func_801777BC`) L5634
+- **§71** — Before mapping a giant, look for an already-matched SIBLING beside it (Phase 29 SESSION-18, `func_8017D960`, 3,338 ins) L5675
+- **§72** — A `register __asm__` pin is a PREFERENCE, not a reservation (Phase 29 SESSION-18, `func_8017F510`) L5741
+- **§3-The** — honest fix was source-level and cheap L5765
+- **§3-Giv** — record order (the §70 family) L5775
+- **What** — is left, and what is byte-recorded as SPENT L5781
+- **§73** — A def-side self-decl conflict has TWO axes: RETURN (fleet widen, T2) and PARAMS (casts at each use, T0). Diagnose which before paying for the expensive one (Phase 29 SESSION-19, `func_8014F3E8` + `func_8014D4C0`) L5798
+- **§74** — Auditing a pinned draft: the §72 hazard is CALLER-SAVED pins spanning a call, and only the disassembly can tell you (Phase 29 SESSION-19, `func_8017D960` b2, 5 pins) L5837
+- **§75** — A propagation cap is usually a MINORITY-SPELLING SOURCE OVERLAY, not a wall: census the carried extern before believing the exclusion message (Phase 29 SESSION-19, `func_8014F3E8` ×4 → ×138) L5881
+- **§75a** — The exclusion classes, enumerated with named causes (Phase 29 SESSION-19, the 134-binary `dedup_extend` sweep) L5940
+- **§75b** — A body's preamble can carry `#define`s, not just `extern`s; extraction lifts only the externs (Phase 29 SESSION-19, `func_80165CA0` ×3 → fleet) L5963
+- **§75c** — Class-B's remedy is the FULL §17a-1 PAIR (decl **and** call-site cast); a decl-only fix moves the error and looks like a new wall (Phase 29 SESSION-19, `func_8012F14C`) L6012
+- **§76** — The allocno CLASS (local vs global) is the dominant regalloc lever, and C reaches it ONLY through declaration scope and variable reuse (Phase 29 SESSION-19, behemoth #3 `func_8017F510` 1,511 ins, 97 → MATCH, pin-free) L6043
+- **§3-The** — mechanism, with citations L6052
+- **§3-The** — attribution primitive (use this before calling anything a scheduling residual) L6072
+- **§3-Two** — diagnosis traps this function proved L6079
+- **Practice** — Practice L6089
+- **§77** — Every extraction tool carries a NARROW hard-coded preamble set; anything outside it silently caps the body's reach. Diff the preamble before you gate. (Phase 29 SESSION-19 — three variants in one session, two different tools) L6099
+- **§3-The** — CANDIDATE gate and the REAL gate need DIFFERENT preambles — keep the difference out of the bank L6139
+- **§78** — A LENGTH drift can be a register grant in disguise; and `fold` never leaves a literal first in an `|` chain (Phase 29 SESSION-19, behemoth #2 `func_8017D960` 3,338 ins, 1806 → 0, pin-free) L6189
+- **§3-The** — drift was an allocation decision, not missing code L6195
+- **§3-The** — economics L6226
+- **§79** — For a 0-callee giant, fingerprint by DATA symbols (§71 cannot fire); and the STACK-SLOT ORDER is a declaration-order oracle (Phase 29 SESSION-19, `func_8017BF14` 4,763 ins, cold start → 45/4763) L6235
+- **§71** — has a blind spot, and this is it L6241
+- **§3-NEW** — LEVER — the frame layout reads back the original declaration order L6255
+- **§76** — confirmed at scale, and a pin nuance L6266
+- **§3-The** — residual, and the honest read L6275
+- **§80** — A do-not-re-buy entry is scoped to its BASE, not to the function; and the pin's hidden cost is an unconditional `qty_phys_sugg` (Phase 29 SESSION-19, `func_8017BF14` 45 → 0) L6285
+- **§3-The** — pin's hidden cost, with the citation L6306
+- **§3-The** — flagged "#1 move" LOST — and why the failure is informative L6317
+- **§78** — 's attribution primitive, run and reproduced L6327
+- **Cold-start** — economics, now complete L6333
+- **§81** — Banking a jr (jump-table) function: the 3-step carve chain, and why `match_one` cannot see the problem (Phase 29 SESSION-19, `func_8017C954`) L6338
+- **§3-The** — defect this exposed: a shared type that is present but invisible L6369
+- **§82** — Two source-shape oracles from behemoth #6: a duplicated `addiu $aN,$sp,K` across a `jal` means the block was INLINED, and scalar-vs-aggregate decides WHEN a stack slot is allocated (Phase 29 SESSION-19, `func_8017C730` 1,061 ins) L6385
+- **§3-1.** — The inlined-helper signature L6390
+- **§3-2.** — Scalar vs aggregate decides *when* the slot is allocated L6404
+- **Also** — reproduced on this function L6416
+- **§3-And** — the banking footnote (§75a class A, one line) L6420
+- **§83** — The parameterised-repeat law, the spill-area trap, and why a per-case edit cannot move a per-case symptom (Phase 29 SESSION-20, `func_80183814` 5,122 ins, cold-ish start → 36 structural / 99.3%) L6427
+- **§83a** — READ THE HEADLINE NUMBER CORRECTLY: a LENGTH drift makes `match_one`'s count meaningless L6434
+- **§83b** — THE LEVER: find the parameterised REPEAT before decoding case-by-case L6442
+- **§83c** — TRAP: a "dead local" in a prior draft may be gcc's OWN spill area L6460
+- **§83d** — CSE's quantity budget is WHOLE-FUNCTION, so a local rewrite cannot fix a local symptom L6467
+- **§83e** — §80 vindicated again, on the same day it was written L6481
+- **§84** — The DERIVED-OFFSET remap bug: a hand-computed literal that encodes the DISTANCE between two per-overlay symbols, and why `match_one` is structurally blind to it (Phase 29 SESSION-20, `func_8013D53C`) L6487
+- **§3-The** — construct L6492
+- **§3-Why** — it survived every candidate gate L6510
+- **§3-THE** — FIX IS MECHANICAL — the tool already holds the answer L6525
+- **Scope** — , measured (do not over-generalise — §80) L6533
+- **§3-Two** — ladder lessons banked with it L6543
+- **§85** — The RETURN-axis fleet widen is ALL-OR-NOTHING: widening the shared header alone guarantees a conflict in the source overlay (Phase 29 SESSION-20, `func_8012CC88` / `func_8014D12C`) L6554
+- **§3-The** — conflict L6559
+- **§3-THE** — FAILURE MODE — widening only `engine_core.h` is worse than not starting L6567
+- **§3-The** — precondition, and how to check it in one grep L6574
+- **§3-Do** — the WHOLE axis in one edit, then R22 once L6582
+- **Reading** — , for the next person L6591
+- **§86** — Pinned-exemplar templatability is a PER-FAMILY property, not a per-member rate; and the §42e pin guard is now over-conservative (Phase 29 SESSION-20) L6604
+- **§3-The** — guard refuses a class that largely works L6606
+- **§3-THE** — LAW: all-or-nothing PER FAMILY L6615
+- **§3-Why** — the two live families differ from the three dead ones — the open question L6642
+- **§87** — `match_one` COMPILES but never LINKS, so an unresolvable data symbol reads as MATCH; and stored drafts go STALE against the tree (Phase 29 SESSION-20) L6648
+- **§3-The** — blindness ladder, now complete — FOUR classes `match_one` cannot see L6664
+- **Consequence** — for the backlog ledger L6674
+- **§3-The** — cheap discriminator, before spending a sweep L6681
+- **§88** — `cross_jump` will not merge a common suffix containing a CALL; and §78 is scoped to ORDERED comparisons only (Phase 29 SESSION-20, the behemoth close-out) L6689
+- **§88a** — repeated CALL-shaped blocks are left UNMERGED; call-free tails are merged for you L6694
+- **§88b** — the `slti` literal-position law (extends §78 to comparisons) L6701
+- **§88d** — BANKING ORDER: run the §81 carve chain BEFORE banking, never after L6716
+- **§88e** — a wrong diagnosis, refuted properly (the model for how to treat an inherited lever) L6723
+- **§88f** — the missing rung: a RELOCATION gate between `match_one` and the binary L6733
+- **§89** — Two throughput rules the project already had written down and was not following (Phase 29 SESSION-20) L6741
+- **§89a** — MEASURE the write set; do not assert its tier (`tools/blast_radius.py`) L6747
+- **§89b** — the parallel gate farm existed; the family path could not reach it (`tools/sweep_parallel.py`) L6760
+- **§3-The** — standing sequence L6773
+- **§90** — Five tool-integrity laws from one session, each of which changed an answer (Phase 29 SESSION-21, 2026-07-27) L6781
+- **§90a** — A comparison tool MUST share its reference oracle's index space, exactly L6787
+- **§90b** — "Byte-neutral" is not "wanted": undo on the SUCCESS path too L6804
+- **§90c** — A library-callable function must FAIL CLOSED on an unconfigured module L6814
+- **§90d** — Do not measure a live wave's drafts (§87 in real time) L6825
+- **§90e** — An agent's CONCLUSION and its EVIDENCE fail independently — re-derive the premise, not the fix L6833
+- **§91** — A structure-TRANSFER is only valid where the structure corresponds: the `--like` role trap (Phase 29 SESSION-21, `func_8012AAAC` ×137) L6857
+- **§3-The** — three-hypothesis trail, because two of them were wrong and the wrongness is instructive L6886
+- **§92** — Conforming a DECLARATION: pointer changes are caller-neutral, scalar-WIDTH changes are not (Phase 29 SESSION-21, `tools/conform_decls.py`) L6906
+- **§93** — `set -o pipefail` attributes a pipeline failure to the LAST stage, not the failing one (Phase 29 SESSION-21, `func_8014D820`) L6937
+- **§94** — A family sweep's `0/N` is a TYPE-CARRY failure until proven otherwise: lift the exemplar's local types, ALL of them, transitively (Phase 29 SESSION-21, `func_8016B6BC` 0/137 → 137/137) L6962
+- **§95** — `reconcile_tu` dropped the SIBLING declarators of a multi-symbol `extern` line (Phase 29 SESSION-21, `func_80176218`) L6998
+- **§96** — The same rewrite, one shape down: `reconcile_tu` matched statements to lines by TEXT, so every COMMENTED declaration was silently skipped (Phase 29 SESSION-22, `func_80176218` banked) L7033
+- **§97** — The gate's own tree hygiene: a refused carve, an unchecked recovery, and a snapshot that captured a dirty tree (Phase 29 SESSION-22) L7081
+- **§98** — `conform_decls` had three defects, and only the third needed R22 to find (Phase 29 SESSION-22, `func_8014CF04`) L7128
+- **§99** — The narrow-param wall is a DEF-side problem with a ZERO-blast-radius fix: convert the definition to K&R (Phase 29 SESSION-22, `func_80175AB8` + `func_80175DA8`) L7182
+- **§3-Two** — `reconcile_tu` bugs found underneath, one introduced while fixing the other L7205
+- **§100** — Prefer the DRAFT-LOCAL fix: a type only one function uses belongs in its BODY, not in a shared header (Phase 29 SESSION-22, `func_80175DA8` 0/137 → 137/137) L7231
+- **§101** — The STALE DEFAULT class: a guard whose cause was removed is a silent skip wearing a safety label (Phase 29 SESSION-22, three instances in one session) L7260
+- **§102** — A PLUMBING verdict can MASK a DIFF; and K&R is not always a codegen change (Phase 29 SESSION-22, `func_8016EC0C`) L7287
+- **§103** — A FILE-scope `extern` in a shared overlay TU is a GLOBAL constraint on every LATER function; move the DECL, not the draft (Phase 29 T48/T51, `func_80135260` — the fleet-wide half) L7322
+- **§104** — Two silent-skip defects in one scan: match on MASKED text, emit from the ORIGINAL (Phase 29 T53, `gather_externs`) L7410
+- **§105** — A gate's revert must survive an EXCEPTION, not just a failure (Phase 29 T53, `jtbl_family_bank`) L7446
+- **§106** — Persist the MEASUREMENT, derive the POLICY: a stored route let a stale file out-vote the live table (Phase 29 T54, `residual_class._ROUTE`) L7485
+- **§107** — A lever wired into ONE gate path is a lever most families cannot reach (Phase 29 T56, `func_80144090` 0/136 → 136/136) L7528
+- **§108** — Diagnosing a family `0/N`: the four causes, and the third opt-in lever (Phase 29 T59) L7566
+- **§109** — Conforming a definition to a shared header: fix the NAMES, then check the RETURN precondition (Phase 29 T60) L7615
+- **§110** — A unit must define exactly ONE function, and "ends in `;`" does not tell you which line defines it (Phase 29 T65) L7655
+- **§111** — The distinct-code metric is not noisy: a family pays it only if its members are byte-VARIANT (Phase 29 T66) L7696
+- **§112** — A macro-scoped declaration only collides where the macro is INSTANTIATED (Phase 29 T67/T69, `audit_header_sigs.py`) L7745
+- **§113** — An ARITY blocker only exists if the macro CALLS the function; an address-taken use has no call site (Phase 29 T72) L7791
+- **§114** — The THIRD decl axis: a CALLEE the draft declares differently from the target TU (Phase 29 T76/T77) L7823
+- **§115** — A `func_XXXXXXXX` predicate rots by design: the same name-form assumption in THREE places (Phase 29 T78) L7865
+- **§116** — Optimization level is a property of the FILE, not the function: read a family 0/N against the member's stub HOME (Phase 29 T79) L7892
+- **§3-The** — fix moves the DEFINITION, not the stub — and here is why the obvious shortcut fails L7910
+- **§117** — Spell the sibling's symbol from the SIBLING's address, not the exemplar's kind (Phase 29 T82) L7941
+- **§3-Why** — it survived so long: a MASKED oracle will MATCH a wrong symbol L7968
+- **§118** — Ordinal (positional) immediate resolution: compare C tokens to the DIFFERING asm uses (Phase 29 T87) L7978
+- **§119** — Two levers on the SAME axis, opposite directions: test the off-diagonal (Phase 29 T89) L8012
+- **§120** — Uniquify draft-defined TYPE names; and check which of N staging sites you actually patched (Phase 29 T93) L8041
+- **§3-Do** — NOT "strip the duplicate typedef" — it breaks the extern that uses it L8052
+- **§3-The** — wiring trap that cost two attempts L8058
+- **§121** — Synthesise externs for macro-DEFINED callees from the macro's own definition head (Phase 29 T95) L8076
+- **§122** — GATE RAW BEFORE TRANSFORMING; the undo belongs to the WRITER, as a per-edit journal (P30 T0a, 2026-07-30) L8099
+- **§123** — PROPAGATE A FAMILY WITH THE TOOL ITS TIER NEEDS: `dedup_propagate` is h_exact-only; its refusals are statements about the TOOL (P30 wave 1, 2026-07-30) L8131
+- **§124** — A "not matched" verdict can mean the definition is there under a DIFFERENT C NAME: the asm-label alias blind spot (P30 SESSION-28, `func_8016191C` ×137) L8168
+- **§124a** — a family sweep's `0 matched-exemplar families` may be a FILTER, not a wall L8213
+- **§125** — Split the CARVE from the BODY before calling a jr residue a wall — and measure it by SHA from a CLEAN tree (P30 SESSION-28; **this section's first draft was WRONG and the method caught it**) L8221
+- **§3-The** — method (keep this) L8228
+- **§3-The** — instrument rules that make its answer trustworthy (this is where I failed) L8238
+- **§3-The** — corrected results (each SHA-verified, from a clean tree, restore re-verified) L8253
+- **§3-Two** — further notes worth keeping L8263
+- **§3-The** — meta-lesson L8272
+- **§126** — The carve-within-a-carve: an ADDRESS RANGE is not an OPTIMIZATION REGION (P30 T2, byte-proven end-to-end) L8279
+- **§3-The** — finding: opt level is per FILE, so the file's contents must be opt-HOMOGENEOUS L8294
+- **§3-The** — instrument trap that hid it (and it is §124's shape again) L8305
+- **§3-The** — mechanics L8314
+- **§126a** — a bare `except: continue` around a coverage-asserting oracle re-creates the silent skip (P30 S28) L8332
+- **§127** — The `-O0` regime: the CONSTANT-OFFSET FOLD, and why `-O0` needs its own idiom set (P30 T3 wave, 15 targets) L8364
+- **§3-The** — idiom they kept re-deriving: the constant-offset fold L8371
+- **§3-The** — rest of the `-O0` regime (write PLAIN C, and mean it) L8382
+- **§127a** — §71 (sibling-first) is the strongest `-O0` lever, and it beats the index L8392
+- **§127b** — the knowledge was in a SOURCE COMMENT, not the cookbook L8401
+- **§128** — A raw NUL in C source makes grep SILENTLY SKIP the file (P30 S28, 137 files) L8408
+- **§128a** — a negative control must corrupt a SCRATCH COPY, never the tracked file L8440
+- **§129** — Post-carve, `rtu_match`/`match_one` COUNT THE JUMP TABLE AS INSTRUCTIONS; and a carve must never be committed without its owner (P30 S28, `func_8013BD74`) L8452
+- **§129a** — the target instruction count is INFLATED after a carve L8456
+- **§129b** — never commit a carve whose owner is still a stub (it strands the carve) L8477
+- **§3-The** — real blocker underneath, for the record L8492
+- **§130** — An INCREMENTAL build can report BYTE-IDENTICAL for a change the CLEAN build cannot even LINK (P30 S28, the jr pair) L8501
+- **§3-The** — diagnostic ladder that finally located it (reusable) L8538
+- **§131** — The jtbl OVER-SPAN: `sltiu N` is ground truth in BOTH directions, and the zero-word rule only guards one (P30 S28, `func_80191C50`) L8548
+- **§132** — The `JR-PAIR-IN-ONE-O0-OBJECT` "wall" was TWO instrument defects: a merged-double span the carve could not see, and a truncated object no rule deleted (P30 S29, `func_8013B83C` + `func_8013BD74`) L8585
+- **Defect** — 1 — a pre-§8e MERGED DOUBLE is not a single-table predecessor L8594
+- **Defect** — 2 — `as` writes a corpse and nothing deletes it L8612
+- **§3-The** — fingerprint, and the 30-second ladder that found it L8622
+- **§3-The** — transferable rule L8643
+- **§132a** — `--like` is for a sibling with NO record; against one that HAS a record it over-derives (P30 S29, `ov_SC07_010`) L8650
+- **§132b** — When the span's already-matched owner is ITSELF multi-switch: `--span-rel` (P30 S1, `func_8014032C`) L8675
+- **§133** — The DEFAULT-FILTER class: three times in one session, a tool silently answered a narrower question than the one asked (P30 S1–S3) L8700
+- **§134** — MULTI-LINE BLINDNESS: one root cause, four faces, in `family_remap`'s preamble scanner (P30 S6, 190 zero-crack families) L8726
+- **§135** — Six byte-verified gcc-2.7.2 idioms from the P30 S6f-h waves (and the two-lane wave shape that found them) L8780
+- **§3-The** — codegen idioms L8785
+- **§3-The** — integration idioms (these decide whether a byte-correct draft BANKS) L8819
+- **§3-The** — wave shape that produced these L8834
+- **§136** — The LOCAL-VARIABLE lever: how many C locals, at what scope (P30 wave 4a, 25 byte-verified banks) L8852
+- **§3-The** — splitting/merging rules (each closed a residual, byte-gated) L8868
+- **§3-The** — type-form rules L8894
+- **§3-The** — scheduling rules (refining §135-2 and §135-4) L8927
+- **§3-The** — declaration surface (integration, not codegen) L8956
+- **Wave** — economics (measured, for the next batch's sizing) L8968
+- **§136a** — Blocker capture: classify on the OUTPUT, never on the exit status L8991
+- **§136b** — A prior wave's "genuine byte-DIFF" verdict is NOT reliable evidence (4 of 4 refuted) L9048
+- **§136c** — SIBLING-FIRST is a DERIVATION shortcut, not just a conflict fix (the fastest route in a family wave) L9084
+- **§136d** — Four gcc-2.7.2 levers the redraft lane found (each closed a residual no other lever moved) L9109
+- **§136e** — §136c's PRECONDITION, and two more symptom keys (wave 4b batch 3) L9153
+- **§136f** — Two declaration sub-cases the reconcile lane surfaced (lane now 15/15 lifetime) L9201
+- **§136g** — When the index points at the WRONG lever: two byte-refuted routings (func_801863B4) L9226
+- **§136h** — CORRECTION: the zero-crack pool does NOT "refill with cheap work" (my error, byte-measured) L9255
+- **§136i** — The drafter model LADDER: Haiku → **Sonnet** → Opus → Fable5 (Drew, 2026-08-03) L9285
+- **§136j** — The failure MIX flips with function size (measured across four bands, one session) L9317
+- **§137** — REGALLOC-PERM is a TWO-COMPILE ARITHMETIC PROBLEM, not a permuter job L9359
+- **§137a** — A gate verdict has a TIMESTAMP; re-check it against the draft's mtime L9401
+- **§138** — The propagation lanes: a gate refusal is a DECLARATION, and which lever you owe depends on blast radius L9430
+- **§3-The** — triage, cheapest first L9436
+- **§3-The** — DEFINITION-side alias is the only escape when the fleet canon disagrees on a promoting param L9488
+- **Rank** — the lane by measured concentration, not by class count L9496
+- **THREE** — carry variants hide in one "CARRY-FIXABLE" bucket — and they need different fixes L9505
+- **§134** — again, in a second tool — and the waiter rule corrected L9541
+- **STEP** — 0 of sibling-first: grep `src/` for a distinctive LITERAL from the `.s` L9561
+- **Reconciling** — a gate-refused draft: which way you edit depends on WHERE the TU's decl is L9580
+- **§139** — A GATE THAT GREPS FOR VERDICTS MUST ASSERT 1:1 ACCOUNTING; and a `--src` filter must not survive a carve (P30 S38, wave 6: 10 of 16 drafts vanished) L9609
+- **§3-The** — generalisation — three corollaries worth more than the bug L9641
+- **§3-And** — the inverse-lookup trap, same session L9658
+- **§140** — A METRIC IS NOT A MEASUREMENT UNTIL IT IS REPRODUCIBLE FROM THE COMMITTED TREE (P30 S1e: a phantom regression that gated the session's best lever) L9675
+- **§3-The** — three-line proof (do this before diagnosing any metric movement) L9695
+- **§3-The** — two instrument defects it exposed L9704
+- **§3-The** — same swallow, twice more, in the integration spine L9724
+- **§3-Two** — wrong mechanisms I chased first, and why they were wrong L9735
+- **§141** — The §134 class is CLOSED: every line-shape decision now routes through `cdecl._mask` (P30 S39) L9755
+- **§142** — An open stub whose `h_exact` class is MATCHED elsewhere is FREE. Propagate the body; do not gate a draft. (P30 S39, +7,710 ins in two commands) L9793
+- **§3-The** — measurement (do this before any wave; it is ~20 lines and needs no builds) L9805
+- **§3-The** — trap that hid it — SAME FUNCTION, TWO ROUTES, ONLY ONE IS FREE L9820
+- **Route** — selection (why `--addr` sometimes says "nothing changed") L9829
+- **§3-And** — the report-vs-bytes lesson attached to it L9837
+- **§143** — `cast_call_sites` read a RETURN STATEMENT as a prototype and deleted it. A 0/39 sweep became 18/39. (P30 S40) L9849
+- **§144** — THE LITERAL'S SPELLING PICKS THE IMMEDIATE ENCODING (P30 S40 wave 1, `func_801822E0`) L9903
+- **§145** — Three loop/combine levers from the S40 wave-2 drafters (16/16 match_one) L9942
+- **§146** — RE-MEASURE A WALL BEFORE YOU RESPECT IT. Both "permanent" giants fell to drafts already on disk. (P30 S6, +50,094 ins) L9992
+- **§3-Why** — a correct draft can read as an intrinsic wall L10003
+- **Then** — propagation returned 0/137 TWICE — both times a missing TYPE L10015
+- **§3-Two** — errors of mine, both instructive L10024
+- **§3-The** — rule L10038
+- **§147** — The three-stratum FRAME LAW, and four "stop searching" verdicts (P30 S42, `func_8017C294`, serial run) L10051
+- **§3-A.** — The frame has THREE strata, and stratum 3 is unreachable from C L10056
+- **§3-B.** — A `?:` on MEMORY operands costs ~16 bytes of invisible frame; on REGISTER operands, zero L10072
+- **§3-C.** — Inner-block declaration does NOT delay slot allocation — BYTE-REFUTED L10083
+- **§3-D.** — A lone `$t8`/`$t9` in the target is RELOAD SCRATCH — reproduce the spill, don't pin the register L10088
+- **§3-E.** — A `qty_compare` TIE is not spelling-reachable — recognise it and stop L10098
+- **Consequence** — for the family (a real scheduling decision) L10110
+- **§148** — The loop.c hoisting THRESHOLD is arithmetic you can compute, and the `?:` clamp that folds to MIN_EXPR (P30 S42, `func_8017C6F4`, 947 ins) L10160
+- **§3-A.** — `move_movables` hoists iff `threshold × savings × lifetime ≥ insn_count` — and you can read it L10166
+- **§3-B.** — `(v < 0x40) ? v : 0x3F` is folded to `MIN_EXPR` and expands to the WRONG SHAPE L10185
+- **§3-C.** — A zero-byte ALLOCNO-PRIORITY slider L10199
+- **§3-D.** — Reproduce the original's BUGS verbatim L10209
+- **§149** — Four instrument defects in one session, and the two questions they were hiding (P30 S43) L10258
+- **§3-A.** — A prep step that returns its input on failure is indistinguishable from a search that found nothing L10264
+- **§3-B.** — Same address + same name ≠ same body — and the ledger keys on address L10282
+- **§3-C.** — `make: *** [...] Error N` is a summary, never a diagnosis L10298
+- **§3-D.** — "Cheap fuel" that was never probed: 0 of 31 templatable L10308
+- **§150** — A register ROTATION across symmetric blocks is VARIABLE-IDENTITY evidence, not an allocator tie (P30 S43, `func_8017C6F4`, 947 ins ×4) L10327
+- **§3-The** — fix L10334
+- **§3-The** — method that found it (this is the transferable part) L10344
+- **§3-Two** — corrections to the record L10360
+- **Diagnostic** — order (adopt this) L10371
+- **§151** — THE GHOST WEDGE: when a load-before-store transposition is unreachable by ANY statement order (P30 S43, `func_8017EF68`, 969 ins) L10382
+- **§3-The** — mechanism (read from cc1's own `-dR` trace, not inferred) L10387
+- **§3-The** — lever — a zero-emission insn that absorbs the blocked tick L10402
+- **§3-The** — two fallouts, and how to close them (both measured, in order) L10410
+- **When** — to reach for it L10422
+- **§152** — BYTE SIZE is the family key that name- and h_seq-grouping both miss (P30 S43, the 0xECC family: 1 crack → 12 overlays → 11,364 ins) L10433
+- **§3-The** — finding L10438
+- **§3-The** — key L10447
+- **§3-Two** — cautions that must travel with this technique L10458
+- **§3-The** — companion defect (open) L10469
+- **§153** — THE ADDRESS-REMATERIALISATION LAUNDER: a third zero-emission asm lever (P30 S43, `func_8018D98C`, 710 ins) L10481
+- **Symptom** — Symptom L10489
+- **Mechanism** — (gcc source + RTL dumps, not inferred) L10494
+- **What** — does NOT work (14 byte-measured probes) L10501
+- **§3-The** — cure — a fresh launder per site, each in its own block L10507
+- **Companion** — levers from the same function L10517
+- **§154** — Reading a disc payload: the module-id word, static base derivation, and "type 1 = uncompressed overlay" (P30 S44) L10537
+- **§3-A.** — Payload word0 is a global MODULE ID; code starts after the header L10542
+- **§3-B.** — Two static base-derivation methods that must AGREE (use both) L10551
+- **§3-C.** — PAC type 1 = the same payload class as type 4, just NOT compressed L10563
+- **§155** — hi/lo literal scanning MUST track base registers (S45) L10573
+- **§155a** — the same failure class, one level up: SHAPE-blind table scanning (S45 p5) L10582
+- **§155b** — check the TYPE your oracle returns before comparing against it (S45 p5) L10602
+- **§155c** — the ZERO-REFERENCE trap: gcc splits a global-array address across the `lui` and the LOAD (S46) L10625
+- **§156** — an ORPHANED reconcile poisons the fleet: `dedup_propagate`'s kept edit (S45 p6/p7) L10655
+- **§157** — the cheap-tier size cliff, measured (S45 p6) L10702
+- **§158** — The RANGE-EXTENDER: a fourth zero-emission asm lever completes the allocno toolkit (P30 S46 tier-3, `func_8017CE58`, 733 ins) L10727
+- **Symptom** — Symptom L10736
+- **§3-Why** — the fork is chained (gcc source, validated insn-by-insn against -dS/-dR dumps) L10742
+- **§3-The** — method (dump-arithmetic first, then place — no probing) L10755
+- **Bonus** — facts worth keeping L10772
+- **§156** — THE PREFERENCE-DONOR MERGE: cross-region variable reuse is what fills a0-a3, and a call-arg use in ONE region steers the fill in ALL of them (P30 S46 tier-3, `func_80186E24`, 611 ins: 236-off "S11 regalloc-order" → MATCH, zero new pins) L10787
+- **§159** — THE DECLARATION AXIS: conform to byte-truth, and make every guard state its COVERAGE (P30 S47; ~10,930 sites across 8 axes, fleet byte-identical) L10843
+- **§160** — THE REACH-15 WAVE HARVEST: an align-1 block move, and the instrument that called it a wall (P30 S47) L10908
+- **§161** — THE RETRY-WAVE HARVEST: a jump table indexed from zero, and two allocator traps (P30 S47) L10984
+- **§162** — S48 WAVE-1 HARVEST (P30, 2026-08-11): the reach-ordered sibling campaign's first 12 targets L11029
+- **§162a** — SHARPENS *(sharpens §161a, §131, §8a-pad, §129a)* L11056
+- **§162b** — SHARPENS *(sharpens §48-A3, §156, §150, §76)* L11085
+- **§162d** — SHARPENS *(sharpens §31, §21, §30, §55a)* L11114
+- **§162e** — NEW L11156
+- **§162** — THE LICM PAIR: what makes an address a movable AT ALL, and why the preheader order is the body order (P30 S47, `ov_MAIN_012`) L11158
+- **§162f** — SHARPENS *(sharpens §42d, §41d, §73, §10)* L11224
+- **§162g** — NEW L11279
+- **§162** — CROSS-JUMP DIRECTION: the surviving copy is always the LATER one, so a BACKWARD `j` into a sibling arm is a source `goto` (P30 S48) L11281
+- **§162h** — SHARPENS *(sharpens §88, §88a, §50-B, §8)* L11315
+- **§162** — The cross-jump "CALL veto" is a COUNT law, not a CALL law (BOUNDS §88a; P30 S48, `func_80189540`) L11317
+- **§162i** — SHARPENS *(sharpens §135, §21, §42, §32)* L11383
+- **§162j** — SHARPENS *(sharpens §25, §136d-1, §48-B, §46-L2)* L11408
+- **§162k** — SHARPENS *(sharpens §1-I2, §12, §160d, §21)* L11437
+- **§162l** — SHARPENS *(sharpens §48-B, §48-C1, §20, §21)* L11500
+- **§162m** — SHARPENS *(sharpens §36, §158, §148, §153)* L11555
+- **§158a** — THE FIFTH LEVER IS NOT AN ASM: `do { } while (0)` is a REGION ref-multiplier you MINT (P30 S48, `func_8017CBC8`, ov_MAIN_012 / jr_801789AC, 188 ins → MATCH) L11557
+- **§3-The** — law L11564
+- **Size** — it before you write it (§158 step 1-2, applied) L11575
+- **§3-The** — wrap BOUNDARY is the dial — and it is indiscriminate L11596
+- **§3-Not** — a pure dial L11602
+- **DIAGNOSTIC** — TELL — two faces, one law L11606
+- **§162n** — NEW L11628
+- **§162o** — SHARPENS *(sharpens §158, §136-1, §136-6, §79)* L11661
+- **§162p** — SHARPENS *(sharpens §48-B, §46-L2, §156, §136d-1)* L11720
+- **§162q** — SHARPENS *(sharpens §30, §30a, §135-2, §136-13)* L11737
+- **§163** — S48 WAVES 2-3 HARVEST (P30, 2026-08-11/12): the five that were byte-probed and are actionable L11775
+- **§163z** — THE UNVETTED REMAINDER (do not cite as law; each needs a dedupe pass) L11843
+- **§164** — S48 §163z SKEPTIC PASS (P30, 2026-08-12): 190 claims vetted, 82 banked L11863
+- **§16Xy** — SHARPENS *(sharpens §136d-3, §37 /s-DEP LATTICE, §135-2, §136-13, §162q)* L12315
+- **§3-The** — `/s` drop clause is in ALL THREE dependence predicates, so the FIXED-ADDRESS STORE is what floats (P30 S48, `func_8017CA18`, ov_MAIN_012) L12317
+- **§164z** — REFUTED CLAIMS: do NOT re-derive these L13651
+- **§165** — S48 WAVE-4 HARVEST (P30, 2026-08-12): banked the same day the wave landed L13717
+- **§16Z** — SHARPENS *(sharpens §37 "the /s-DEP LATTICE", §136-13, §136-14, §16Xy, §162q, `gcc-2.7.2-map/sched.md` §64)* L14368
+- **§3-The** — ADDRESS-CLASS TABLE: which load/store pairs even REACH the `/s` clause (P30 S48 wave 4, `func_80185B44`, ov_SC03_014) L14370
+- **§165z** — REFUTED THIS WAVE: do NOT re-derive L14886
+- **§166** — THE DESTINATION-TU ORACLE (P30 S48): the seven-attempt bug that was never codegen L14930
+- **§167** — S48 WAVE-5/6 HARVEST (P30, 2026-08-12): the saturation point L14986
+- **§167z** — REFUTED IN WAVES 5/6: do NOT re-derive L16182
+- **§168** — THE COUSIN TIER (P30 S49, 2026-08-12): h_seq's exact-hash brittleness, measured — and the similarity map above it L16239
+- **§169** — THE MICRO-ADAPT LANE (P30 S49): edit a proven body, don't crack a new one L16291
+- **§170** — THE A-PROP WORD-DIFF CARD (P30 S49): the lane that had no owner L16338
+- **§171** — THE STALE SEED SYMBOL (P30 S50, 2026-08-13): why §170's 91%→57% was never codegen L16382
+- **§171a** — THE MECHANICAL A-PROP DRAFT (P30 S50): 256 members banked with no agent in the loop L16448
+- **§171b** — THREE CARRIES THE MECHANICAL DRAFT NEEDS (P30 S50, banking the top-reach families) L16498
+- **§172** — THE ORPHAN-SLOT MECHANISM v2 (P30 S50-Max): the complete frame-residue model for gcc-2.7.2 MIPS L16531
+- **§172a** — TWO DECOMPILATION TELLS FROM THE SAME DIG (P30 S50-Max) L16585
+- **§172b** — THREE MORE TELLS FROM THE GCC READ (P30 S50-Max, banked on Drew's ask) L16601
+- **§173** — THE STORED-PLUMBING RECOVERY RECIPE (P31 T6): symfix-first, per-group isolation, and where the verdicts have no drafts L16644
+- **§174** — THE ADAPT-CARD WAVE RECIPE (P31 waves A/B, 2026-08-14): prevention beats recovery L16680
+- **§175** — A CALLER-SAVED REGISTER PIN CAN BE A CORRECTNESS BUG, NOT JUST A SCHEDULING CHOICE (P31 wave H, 2026-08-15) L16750
+- **§176a** — THE VERIFICATION-LAYER LAWS (P31 overnight, 2026-08-15). What each check can and cannot prove. L16775
+- **§176b** — BATCH-GATING MECHANICS (P31): what changes when N drafts land in ONE .c L16815
+- **§176d** — THE CONFLICT TABLE MUST BE SEEDED FROM THE TU, AND KEYED PER FILE (P31 S52, 2026-08-15) L16841
+- **§176e** — SYMBOL IDENTITY IS COMPUTABLE OFFLINE (P31 S52): `tools/reloc_identity.py` L16880
+- **§176f** — THE DECLARATION FORM IS A MATCHING LEVER, SO RECONCILE TOWARD THE FORM THE MATCH NEEDS (P31 S52) L16937
+- **§176g** — SIZE A WAVE BY INSTRUCTIONS, NOT BY CARDS (P31 S52 — the adopted doctrine) L16968
+- **§176h** — THE BATCH-SUBSTITUTION HAZARD MAP (P31 S52): seven holes, three wrong fixes, one law L17006
+- **§3-A.** — The seven under-reporting holes (all in `gate_main`, all the same shape) L17014
+- **§3-B.** — Typedef handling — the only strategy that survives contact L17032
+- **§3-C.** — The limit that remains (recorded, not solved) L17054
+- **§3-C2.** — RECONCILE BEFORE THE FIRST GATE — a parked draft gets HARDER to bank, not easier L17061
+- **§3-D.** — The measured cost shape, and what to build next L17084
+- **§176i** — WHAT A STATIC PRE-GATE CHECK CAN AND CANNOT PROVE (P31 S52, wave Q) L17102
+- **§176j** — STOPPING A WAVE MID-FLIGHT COSTS THE IN-FLIGHT TAIL (and how much is recoverable) L17134
+- **§176j-2** — THE REPAIR PASS, MEASURED (do this instead of resuming) L17160
+- **§176k** — TWO SELECTOR BUGS THAT SILENTLY SHRINK A WAVE L17180
+- **§177** — 🔴 THE EPILOGUE RETURN-DELAY SLOT IS DECIDED BY YOUR SAVED-REGISTER SET, NOT BY SCHEDULING L17197
+- **§178** — SIX LEVERS MINED FROM THE WAVE-P JOURNALS (P31 S52), each byte-proven and source-cited L17254
+- **§3-A.** — THE `$0`-ADD OPAQUE COPY defeats `make_regs_eqv` (func_80033398, 93 ins) L17266
+- **§3-B.** — A `return ` IS A PRIORITY-1 HARD-REG SET THE SCHEDULER PLACES FIRST (func_8001BE30, 92 ins) L17282
+- **§3-C.** — SINGLE-SET TEMPS GET THE BIRTHING BOOST (func_8001D3FC, 196 ins) L17295
+- **§3-D.** — A NARROW TYPE BLOCKS COPY ELISION (func_8001D3FC — new idiom) L17303
+- **§3-E.** — THE ZERO-OFFSET ALIAS HOLE (func_80037028, 71 ins) L17310
+- **§3-F.** — `MEM_IN_STRUCT_P` ASYMMETRY IN `true_dependence` (func_80037144, 124 ins) L17319
+- **§3-G.** — TWO MODELLING TRAPS THAT COST THESE AGENTS SWEEPS OF HUNDREDS OF COMPILES L17325
+- **§179** — IDIOMS MINED FROM THE WAVE P/Q JOURNALS (P31 S52, harvest pass) L17341
+- **§179-A** — 🔴 A LOOP-WALKED POINTER **PARAMETER** HANDS ITS ARGUMENT REGISTER TO THE GIV (9 byte-proofs) L17351
+- **§179-B** — 🔴 THE HAND-WRITTEN-ASM TRANSCRIPTION CHECKLIST (maspsx + masked_diff; 10 byte-proofs) L17400
+- **§179-C** — 🔴 A FUNCTION WITH NO EPILOGUE (falls into a sibling's shared tail) MUST BE FILE-SCOPE `__asm__` L17450
+- **§179-D** — `gte_stflg` MUST CLOBBER `"$12"` OR THE WHOLE TEMP FILE ROTATES BY ONE L17501
+- **§179-E** — A `>2*MAX_MOVE_BYTES` BLOCK COPY IS A **STRUCT ASSIGNMENT**, NOT A HAND LOOP L17521
+- **§179-F** — PINNING A LOOP-WALKED POINTER IS A TOTAL OFF-SWITCH FOR STRENGTH REDUCTION L17547
+- **§179-G** — 🟡 A PIN CAN **CREATE** A COMBINE `LOG_LINK` AND DELETE AN `andi` (sixth RC-5 channel, n=1) L17570
+- **§179-H** — A MID-BODY `.global LABEL` PAIR SLICES A BYTE-COMPARABLE FRAGMENT OUT OF A LARGER ROUTINE L17597
+- **Considered** — and NOT banked L17620
+- **§176c** — MAIN (SLUS_007.26) CANNOT BE GATED INCREMENTALLY L17637
+- **§176** — SEVEN LEVERS FROM THE P31 OVERNIGHT WAVES (2026-08-15): statement order, false regalloc, and the pin that fights back L17648
+- **§176-A** — "SCHEDULE / DELAY-SLOT / LENGTH-DRIFT ±1" ⇒ check STATEMENT ORDER around the call first L17654
+- **§176-B** — "REGALLOC-PERM, 1-4 instructions off" ⇒ it is usually NOT register allocation L17678
+- **§176-C** — 🔴 WALL REFUTATION: a hard-register pin CANNOT schedule around a call, because of a genuine gcc-2.7.2 bug L17724
+- **§176-D** — CSE-class levers used in reverse (two sharpenings of §153 and cse_expr §2) L17750
+- **§176-E** — Two cheap source spellings, both cc1-probed L17776
+- **§176-F** — Misdiagnosis triage: four residual verdicts that were lying L17798
+- **What** — is NOT banked here L17815
+- **§180** — THE LEFTOVER-DRAFT HARVEST: RE-VERIFY WHAT YOU ALREADY HAVE BEFORE DRAFTING ANYTHING NEW L17828
+- **§180b** — WHAT THE PRE-GATE LADDER ACTUALLY FINDS IN A COLD PILE (the shape of integration debt) L17857
+- **§180c** — WHEN A BINARY'S MASS BAND IS SPENT, THE FLEET-WIDE DRAW IS STRICTLY BETTER L17876
+- **§181** — WHAT A WAVE'S GATE ACTUALLY REJECTS (P31 S53, measured on wave R's 45-draft main pile) L17894
+- **Only** — ONE of 27 blocked drafts was wrong. The other 26 were correct and unbankable. L17895
+- **§182** — §177's HONEST NEGATIVE: the epilogue lever cracked 4 of 16, and the `800c3` cluster held L17950
+- **§180d** — THE `pgrep` BRACKET TRICK PROTECTS THE PATTERN, NOT THE COMMAND LINE L17964
+- **§183** — THE DECLARATION-RECONCILIATION PLAYBOOK (P31 S53, measured on 20 byte-verified drafts) L17976
+- **§3-18** — of 20 reconciled while keeping the match. The two that did not are mechanism, not effort. L17977
+- **§184** — COMMENT-BLINDNESS IS A DEFECT CLASS, NOT A BUG (P31 S53: three tools, one root cause, one session) L18047
+- **§185** — EDIT THE SIDE THAT IS CHEAP TO VERIFY, AND CHECK A TU RETYPE AT ITS USE SITES L18075
+- **§186** — CROSS-JUMPING RUNS **AFTER** SCHEDULING, SO NO C-LEVEL BARRIER CAN STEER IT L18107
+- **§186b** — A NO-SAVE 16-BYTE FRAME IN A LEAF FUNCTION MEANS `s16` LOCALS, NOT A HIDDEN CALL L18128
+- **§186c** — WHERE A VALUE IS LOADED DECIDES WHICH ALLOCATOR OWNS IT, AND THEREFORE ITS REGISTER L18136
+- **§187** — 🔴 "SAME SOURCE" IS NOT "SAME OBJECT": THE SDK BUILD AND THE GAME BUILD DISAGREE ON GTE NOPS L18153
+- **§188** — 🔴 THE `jr $ra` + `addiu $sp` TAIL IS AN **ASSEMBLER** ARTIFACT, NOT A FRAME SHAPE L18191
+- **§189** — FIVE COMPILER LAWS MINED FROM THE WAVE R/S JOURNALS (P31 S53), each source-cited and re-derived by a second agent L18241
+- **§190** — THREE PRESCRIPTIONS FROM THE SAME HARVEST (weaker evidence than §189, honestly labelled) L18316
+- **§191** — WHAT THIS HARVEST DID **NOT** BANK (4 rejected, 4 narrowed) — recorded so it is not re-derived L18353
+- **§192** — THE PRE-GATE LADDER WAS MAIN-ONLY, AND NOBODY COULD SEE IT (P31 S54) L18375
+- **Three** — defects in one call path; the overlay slates that carry most of the wave work were being waved through L18376
+- **§193** — THE WAVE-T HARVEST (P31 S54): 71 index_gap reports -> 9 laws, 5 rejected, 61 already-covered L18440
+- **§193-A** — The wave card ships only OPEN-set pointers and discards the atlas's BANKED one — `exemplar`/`sibs` are stubs 100% by construction (tools/atlas.py:96/657), while `seed.ref` (matched pool, atlas.py:505-536) is dropped at build_wave_atlas.py:143 L18457
+- **§193-B** — A NARROW CAST OF A WIDE PARAMETER COSTS ONE EXTRA INSTRUCTION WHEN ITS STATEMENT SITS AFTER AN INTERVENING `jal` — AND THE DECIDER IS `combine.c:929`'s CROSS-CALL GUARD, NOT REGISTER ALLOCATION L18524
+- **§193-C** — gcc-2.7.2 cross_jump merges the SCHEDULED common SUFFIX only — there is no prefix/head merge, so §8/§48-A1's "duplicate into both arms and cross_jump refunds it" is a TAIL-only lever L18562
+- **§193-D** — A COMPILER-GENERATED ARGUMENT COPY IS A `optimize_reg_copy_1` TRIGGER: when the pointer's LAST use in a block precedes a call that takes the pointer *as a register*, sched1 hoists the implicit `move $aN,$sN` to the block top and local-alloc re-bases the WHOLE block's memory operands onto `$aN`. The only C dial is a label (the §165-24 goto-join) between the block and the call. L18596
+- **§193-E** — A varying-address (pointer) load is re-emitted once per CSE-LIVE INTERVAL, and naming it in a C local is the only C-level lever over that count — no store SPELLING has any reach L18667
+- **§193-F** — §148-A2 — The `threshold -= 3` STAIRCASE: `move_movables` admits a COUNT of invariants, not a boolean — two identical merged constants split hoisted/not-hoisted by LIST ORDER, and `insn_count` picks the rank cutoff L18697
+- **§193-G** — §164-54's "scope to ≥4 arms" bound is byte-wrong — the dispatch-topology oracle goes live at THREE case nodes (`balance_case_nodes` splits at `i > 2`), but only for a signed-after-promotion index L18761
+- **§193-H** — A pointer-derived base load `*(s32*)(p+K)` is uncacheable across ANY memory write or call (cse's third kill disjunct) — so the target emits one `lw` per store-separated RUN of spellings, and a run of stores sharing one `lw` is a C local you must declare L18822
+- **§193-I** — A DECLARED AGGREGATE LOCAL HAS AN 8-BYTE FRAME STRIDE — CEIL(size,8), NOT size. N ARRAYS THEREFORE COST 8·k MORE THAN ONE HAND-LAID STRUCT (k = how many of them have size mod 8 ≠ 0), AND THE TELL IS IDENTICAL INSTRUCTION COUNT WITH EVERY $sp DISPLACEMENT SHIFTED BY THE SAME CONSTANT. L18862
+- **§193-REJECTED** — what this harvest did NOT bank (recorded so it is not re-derived) L18921
+- **§194** — THE WAVE-U HARVEST (P31 S54): 64 index_gap reports -> 14 laws, 5 rejected, 44 already-covered L18948
+- **§194-A** — A zero-byte scheduling fence goes AFTER the defining statement to make that computation emit FIRST in its block — and the barrier predicate is `volatile`-or-colon-less, not the `"memory"` clobber (COMPLEMENTS §165-40; does not refute it) L18965
+- **§194-B** — A `addu $rA,$rB,$zero` copy feeding ≥2 `sh` stores is a SECOND, 16-BIT-DECLARED local — the width, not the clamp or the join liveness, is what keeps the copy (and func_80183094's pin + `"memory"` clobber are both provably inert) L19031
+- **§194-C** — A CALLER-SAVED loop counter proves its live range crosses ZERO calls — so it cannot share a pseudo with any value LIVE ACROSS a call (but it may freely share one with values that merely sit between calls) L19069
+- **§194-D** — Declared width of a computed-value local is a sched1 dial (count-neutral) — a replication + attribution correction of §165-17, NOT a new argument-register law L19132
+- **§194-E** — The wave card's `exemplar` is the TARGET ITSELF on 42/73 wave-U and 36/71 wave-T cards — a construction consequence of `atlas.py:657` (exemplar = max-nins OPEN member) meeting `build_wave_atlas.py:166` (one card per gid); and the shipped §193-A `seed_ref` is same-binary on 0/51, so no card field can ever name a destination-TU sibling L19173
+- **§194-F** — `if ((*p = v = f()) == 0)` is an expand-time pseudo SPLITTER (store_expr's `want_value && MEM` path), not a fold — it partitions one value between local_alloc and global_alloc. BOUNDS §21's L1872 bullet, whose stated direction is byte-wrong on 3 of 4 instances, and CLOSES the control §167-37 asked for. L19210
+- **§194-G** — Reading the integer half of a 16.16 stack aggregate: REGISTER-LIVENESS, not the C spelling, decides `sra` vs `lhu` — and the break is count-neutral L19283
+- **§194-H** — §164-29's WAR fence runs again at SCHED2 ON HARD REGISTERS: an in-place `v &= K` before a branch fences the store that reads v, and when TWO independent stores compete for the one delay slot the fence picks the winner at ZERO length drift (a WIDTH/sh!=sw swap, not a nop). Corrects §167-42's reconstruction (pseudo arm → hard-reg arm) and supplies its first re-runnable A/B. L19326
+- **§194-I** — §16N+2's magic-per-odd-part ladder has exactly one broken row — read the divisor arithmetically instead: d = round(2^(32 + post_shift) / magic_read_as_unsigned) L19364
+- **§194-J** — Back-to-back identical stores: flow.c's `last_mem_set` deletes the first, and only `volatile` saves it L19407
+- **§194-K** — Blind sched1's alias oracle with a second SET of a pointer pseudo — the first zero-byte, non-volatile, dependence-CREATING lever (corrects §167-05's "volatile is the only door"; fourth consumer of reg_n_sets) L19459
+- **§194-L** — §88b and §189-E are BOTH half-wrong, but not the way the candidate says: the compare-constant shape is a 2-D lookup (cmp_info ROW × constant-in-window), and naming matters on OPPOSITE sides of the window for the GE/LT rows vs the GT/LE rows L19537
+- **§194-M** — A STORE in a CONDITIONAL branch's delay slot proves its C statement DOMINATES the branch — reorg can never pull a store out of either thread (gcc-2.7.2, -mips1) L19585
+- **§194-N** — §193-D's C dial is misstated: the lever is a SURVIVING CODE_LABEL (a label with a real incoming edge), not "a label between the block and the call" — a bare label, or a `goto L; L:` pair whose target is the next active insn, is deleted by jump1 (jump.c:663-669 → delete_insn → jump.c:3458-3461, and jump.c:243 for the bare case) long before sched1/local-alloc, and costs exactly zero bytes L19643
+- **§194-REJECTED** — what this harvest did NOT bank (recorded so it is not re-derived) L19703
+- **§195** — THE WAVE-V HARVEST (P31 S54): 67 index_gap reports -> 14 laws, 9 rejected, 76 already-covered L19724
+- **§195-A** — §167-08's "an $aN READ before the jal is scratch" has a byte-proven FALSE-NEGATIVE class: an argument that DIES at the call is allocated straight into $aN, so its only def is a plain load far above the jal and every intervening use reads $aN — there is no positive tell in either direction, only the two-arity A/B L19738
+- **§195-B** — A CALL_INSN does not start a basic block in gcc-2.7.2 — so a call-crossing temp can be a LOCAL-alloc quantity (the missing precondition under §48-A2 / §52 / regalloc.md K8) L19809
+- **§195-C** — A call-argument `%hi/%lo` pair sitting at the block head, far above its `jal`, is a load-delay-gap filler chosen by SOURCE STATEMENT ORDER — swap the two independent statements nearest the call; a single-use `void *p = &SYM;` call-arg temp is OUTPUT-inert against it (but NOT expand-stream-inert) L19851
+- **§195-D** — §195 — `masked_diff.mask_for` returns 0 for EVERY `j`/`jal` word, so an internal `j` destination is invisible to match_one, the permuter scorer AND every similarity tier: a control-flow semantic error (which calls execute) surfaces as a 1-instruction residual mislabelled `DELAY-SLOT / profile=schedule`, or as an outright false MATCH L19899
+- **§195-E** — A 0/1 materialised at a JOIN immediately before the controlling `beqz`/`bnez` proves the source NAMED the condition — a truth expression in an `if`'s controlling position reaches `do_jump`, which has no value path L19967
+- **§195-F** — fold-const.c:4825 canonicalises a `?:` whose THEN arm is zero (or constant against a non-constant ELSE) by inverting the condition and swapping the arms — so a ternary's written arm order is byte-inert there, and `c ? 0 : X` is unspellable: it always compiles as `!c ? X : 0` L20025
+- **§195-G** — §NEW — TWO ARMS CALLING THE SAME CALLEE MERGE INTO ONE `jal` UNLESS EACH ARM'S OWN CODE CONSUMES THE RESULT: the C dial that keeps two call sites apart is WHERE the consumer test lives, and the branch SENSE you spell it with is byte-inert (jump.c:1737 canonicalises it) L20077
+- **§195-H** — §165-27g — ON A FIXED-SYMBOL GLOBAL, `extern T D[];` + `D[0]` IS THE CSE RELOAD DIAL, AT ZERO ADDRESSING COST, AND THE ELEMENT COUNT IS INERT (§165-27's `T v[2]` CAVEAT IS A LOCAL-FRAME FACT AND DOES NOT TRANSFER) L20125
+- **§195-I** — §145(b) AMENDED — the pointer-bump `addiu` is saved by cse, not combine: ANY second SET of a pseudo in the address's equivalence chain (in-place `p += K`, §145(b)'s `p = r;` copy, or an asm re-tie) kills the fold; the pass is cse and the gate is `invalidate`'s `reg_tick++` L20172
+- **§195-J** — GTE / PsyQ op CALL-vs-INLINE is a PER-SITE SOURCE FACT, not a TU style — both forms coexist in one TU (measured in 2 TUs), and the tell is the target's own opcodes (`lwc2`/`sqr`/`swc2` vs `jal`), not the sibling. Costs -8 ins on func_8018505C. Corollary: the game's inline `sqr` macro emits TWO hazard nops, the SDK's `Square0` body emits ONE — so the inline form is provably not `Square0` inlined (a second instance of §187's SDK-vs-game GTE nop divergence). L20237
+- **§195-K** — At -O2 the §18 array-of-struct lever is a FRAME lever, not a length lever — but only when the N reads carry DISTINCT index expressions; with a SHARED index §18's +2-instruction residual is still alive at -O2 (the submitted "memory-loaded narrow index" precondition and unconditional length-neutrality are both falsified) L20281
+- **§195-L** — The cse store-re-seed does not cross a JOIN LABEL: per-arm stores + a join read keep the reload that one join store deletes (bounds §193-E BOUND 1/BOUND 3 with §48-B's EBB boundary) L20333
+- **§195-M** — Frame `vars` is a SEQUENTIAL bump-allocation, not a flat sum: §193-I's CEIL(aggregate,8) term and §165-03/§167-06's 8×orphan term are the SAME frame_offset walk at two different compiler stages, and each stage re-CEILs frame_offset to 8 before it allocates L20385
+- **§195-N** — In a call-bearing chain of N≥2 `if (f(...)) return 1;` tests closed by `return 0;`, the LAST test must stay in STATEMENT form — the value form (`return f() != 0;` / `? 1 : 0` / `!!f()`) costs +1 `j` and empties the other N−1 delay slots. The cause is REORG block placement, not jump.c's `delete_jump`. L20434
+- **§195-REJECTED** — what this harvest did NOT bank (recorded so it is not re-derived) L20481
+- **§196** — PUT ON THE CARD WHAT THE TREE ALREADY KNOWS: the fleet's declaration consensus (P31 S54) L20527
+- **§197** — THE WAVE-W HARVEST (P31 S54): 68 index_gap reports -> 4 laws, 3 rejected, 41 already-covered L20582
+- **§197-A** — A NARROW SIGNED MEMORY READ FEEDING A CONSTANT `>>` LOSES ITS `lh`, AND THE CURE IS AN ASM RE-TIE (attribution CONTESTED: cse vs combine) L20596
+- **§197-B** — A REPEATED COMPARE OF ONE VALUE AGAINST ONE CONSTANT IS DELETED BY cse's `qty_comparison_code` CHANNEL (the non-EQ complement of §165-03) — and a front-end-opaque mask on EITHER compare is a pure-C dial that keeps the target's second branch L20634
+- **§197-C** — Fix A1 (operand order) cannot move a commutative destination whose .greg conflict set already contains BOTH operand hard registers — split the accumulate so the destination IS the load's pseudo L20662
+- **§197-REJECTED** — §197-REJECTED L20707
+- **§199** — THE WAVE-X HARVEST (P31 S54/S55): 63 index_gap reports -> 7 laws, 2 rejected, 56 already-covered L20722
+- **§199-A** — §189-A's asm→source inference is byte-FALSE: an interloper between a split constant's `lui`/`ori` is a SCHEDULE fact, not a source fact — and the separator is the BIRTHING BOOST, not a "priority floor" (§189-A's split-timing half survives; its "no statement order / no pin" absolute and the candidate's own forward-scheduler narrative both fall) L20733
+- **§199-B** — A permutation sweep that holds ANY statement fixed is not a sweep: the statement an agent pins as "obviously load-bearing" is the one carrying the signal, and the partial sweep returns a FLAT residual that reads as proof of order-invariance L20782
+- **§199-C** — A NEGATIVE CONSTANT MULTIPLY ALWAYS TAKES expmed's negate_variant — but whether you ever SEE the neg is decided by COMBINE, and for an EVEN |K| it never disappears L20827
+- **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` L20875
+- **§199-E** — §189-A BOUNDED AND CORRECTED — the discriminator is INSN_PRIORITY, not "is the interloper a constant": an insn between a `lui`/`ori` pair proves NOTHING about the source spelling unless it TIES the `ori` on priority, and on the pinned `-mcpu=3000` triple a dependent load never does L20935
+- **§199-F** — §164-36b — THE TARGET-HEAD FENCE IS A DELAY-SLOT THREAD SELECTOR, AND IT ONLY FIRES WHEN `mostly_true_jump > 0` (amendment to §164-36; its "−1 instruction" tell is falsified) L20994
+- **§199-G** — At TWO case nodes the switch-vs-if oracle is not blind — but the tell is ALL tests positive + a trailing `j default`, NOT the first test's polarity L21048
+- **§199-REJECTED** — §199-REJECTED L21103
+- **§200** — THE ALIAS IS THE UNIVERSAL DECLARATION ESCAPE: stop negotiating with the TU's spelling (P31 S55) L21114
+- **§201** — THE WAVE-Y HARVEST (P31 S55): 67 gap reports -> 5 laws, 8 rejected, 53 already-covered L21163
+- **§201-A** — §150-B applies to `decl_prior`'s DEF row: for an overlay-window symbol the banked "definition" is usually another overlay's function, and the card ranks it ABOVE the destination TU L21173
+- **§201-B** — In a narrowed PLUS/MINUS/AND/IOR/XOR expression the destination pointee is INERT — the sign of the materialized constant is decided by an OR over the UNWIDENED operands (convert.c trunc1), which bounds §1841 to direct constant stores L21205
+- **§201-C** — §X — A CALL'S OWN DELAY SLOT AND THE UPSTREAM CONDITIONAL BRANCH'S SLOT COMPETE FOR ONE INSN (the call's argument copy), AND ONE STATEMENT'S POSITION RELATIVE TO THE CALL DECIDES BOTH — the residual is visible at the BRANCH, not at the call L21285
+- **§201-D** — THE SIGNEDNESS OF A div/mod MAGIC IS DECIDED BY THE STATIC TYPE OF THE DIVIDEND TREE AFTER `get_narrower` STRIPS WIDENING CONVERSIONS — NEVER BY A PROVABLE RANGE. AN `& 0xFF` IS NOT A CONVERSION, SO IT NEVER FLIPS THE MAGIC; A DECLARED-UNSIGNED LOCAL *OR* A NARROWING CAST WRITTEN AT THE DIVIDE BOTH DO. L21336
+- **§201-E** — §194-J-2 — The `last_mem_set` deletion window is measured in SOURCE/expand order, not in the printed stream; a foreign store moved between the pair in C source is a real lever, and `volatile` is not always the better one L21383
+- **§201-REJECTED** — eight, the session's highest L21439
+- **§202** — THE ALIAS CARRIES A DEFINITION, NOT JUST A DECLARATION: the DEF-SIDE-RETURN wall (P31 S56) L21464
+- **§203** — A DEDUPED TYPEDEF MUST PRECEDE EVERY SPLICE POINT, NOT JUST ITS OWN (P31 S56) L21501
+- **§204** — THE WAVE-Z HARVEST (P31 S56): 82 gap reports -> 5 laws, 16 rejected, 30 already-covered L21562
+- **§204-A** — A COMPARE THAT APPEARS BOTH IN A BRANCH'S DELAY SLOT AND AGAIN ON THE FALL-THROUGH IS A JOIN WITH TWO INCOMING EDGES: THE TWO GUARDS ARE SEQUENTIAL `if`s, NEVER `if/else if` L21581
+- **§204-B** — A LOOP COUNT THAT ARRIVES ON THE STACK IS DECREMENTED IN PLACE: a fresh counter local can cost a real `move` AND permute the whole callee-saved file L21656
+- **§204-C** — WHEN A LOCAL BUFFER'S ADDRESS IS PASSED TO A CALL, ITS SIZE IS A FACT ABOUT THE CALLEE'S BODY, NOT ABOUT THE CALL SITE: grep the callee's proven definition and count the stores through the pointer parameter before you declare the local L21720
+- **§204-D** — A LOOP-INVARIANT LOAD IS ADMITTED AS A MOVABLE ONLY IF ITS ADDRESS CANNOT TRAP: `local.field` PASSES, THE SAME READ THROUGH A POINTER LOCAL IS REFUSED L21778
+- **§204-E** — `decl_prior`'s `%hi/%lo` ARM HAS NEVER FIRED: the card's promised GLOBAL-TYPE row is 0 of 1,210 L21853
+- **§204-CONFIRMED** — 30 reports that the index already answered L21905
+- **§204-REJECTED** — sixteen, twice the previous record L21999
+- **§205** — THE CHAINED ASSIGNMENT IS ITS OWN SCHEDULING DIAL: `*b = *a = v;` moves an argument copy that no local, no pin and no statement reorder will move (P31 S56) L22072
+- **§206** — THE JTBL-CARVE DRAFTING IDIOM: the bounds check is the entry count, and an EMPTY case owns a slot (P31 S56) L22127
+- **§207** — THE WAVE ab–ag HARVEST (P31 S58): 278 byte-banked notes → 25 laws, 103 self-reported no-gap L22196
+- **§208** — TWO NAMED LOCALS FOR ONE RELOADED EXPRESSION BUY TWO ALLOCNOS — the naming granularity owns the REGISTER SPLIT, not just the load count (P31 S58) L22217
+- **§209** — THE NARROW LOCAL IS A DIAL IN TWO OPPOSITE DIRECTIONS, AND §194-B's "≥2 `sh` STORES" BOUND IS BYTE-WRONG (P31 S58) L22266
+- **§210** — THE SINGLE-BIT MASK IN A BOOLEAN TAIL: `andi K ; sltu $zero,v` vs `srl n ; andi 1` is a STATEMENT-SHAPE dial, not an operator choice (P31 S58) L22343
+- **§211** — HOIST THE LOOP INIT ABOVE THE DOMINATING GUARD: it fills the guard's delay slot AND flips the counter/pointer register pair (P31 S58) L22389
+- **§212** — THE WALKING CURSOR IS COUNTABLE: `*wp++` emits one `addiu` PER STORE, `wp[0..2]` emits one (P31 S58) L22448
+- **§213** — INDEPENDENT SAME-BASE STORES: THE EMISSION ORDER IS A PERMUTATION OF SOURCE ORDER, AND THE PERMUTATION IS NOT ALWAYS THE IDENTITY (P31 S58) L22493
+- **§214** — THE BANKED TWIN MAY BE A MACRO, A DELETED `.s`, OR A SEMANTIC INVERSE — six ways a ≥0.9 similarity lies (P31 S58) L22529
+- **§215** — PIN ECONOMY: the twin's pins are NOT part of the shape, and §17's "pin every call-crossing value" is over-broad (P31 S58) L22575
+- **§216** — DISTINCT ADJACENT SCALARS vs ONE ARRAY: one `lui` per access is the tell, and the array decl is UNUSABLE (P31 S58) L22631
+- **§217** — DECODING A CALL'S STACK ARGUMENT SLOTS: `sw` at `0x10`/`0x14`/`0x18` are params 5/6/7 **(single observation — not yet cross-confirmed)** (P31 S58) L22671
+- **§218** — A NARROW TYPE AT THE ABI BOUNDARY COSTS AN IN-PLACE `sll/sra` PAIR — on the RETURN as well as on the PARAMETER (P31 S58) L22697
+- **§219** — COMPOUND `+=`, FULL ASSIGNMENT, AND AN EXPLICIT TEMP ARE THREE DIFFERENT SCHEDULES OF ONE READ-MODIFY-WRITE (P31 S58) L22726
+- **§220** — THE PARAMETER ITSELF IS A REGALLOC DIAL: use it directly, prefer `s32` to `void*`, and place the save-copy AFTER the first call (P31 S58) L22753
+- **§221** — A CONSTANT SHARED BY TWO STORES DIES AT THE CALL WHOSE DELAY SLOT REFILLS ITS REGISTER **(single observation — not yet cross-confirmed)** (P31 S58) L22793
+- **§222** — SWITCH vs IF-CHAIN, PART 3: source arm order IS emission order, a leading EMPTY case buys the median split, and a 2-way dispatch with a shared post-block is a `switch` (P31 S58) L22809
+- **§223** — READING A `jal` DELAY SLOT: the value in it was produced BEFORE the call, so it is NEVER that call's return (P31 S58) L22851
+- **§224** — CROSS-JUMP: WRITE THE DUPLICATE, AND READ A SHARED DELAY SLOT AS THE MERGE SIGNATURE (P31 S58) L22913
+- **§225** — THREE CONTROL-FLOW SHAPES NO STRUCTURED SPELLING REACHES (P31 S58) L22949
+- **§226** — FRAME PADS: FOUR WAYS §162i1/§2429's DEAD-LOCAL LEVER MISFIRES (P31 S58) L22992
+- **§227** — TYPE THE SOURCE BY THE **LOAD** WIDTH, NOT BY THE STORE WIDTH (P31 S58) L23033
+- **§228** — READING THE DIVIDE, PART N: the off-by-one compare is `% K == 1`, and three more discriminators (P31 S58) L23053
+- **§229** — THE ADDRESS IS A VALUE: NAMING IT MOVES THE `lui`/`addiu` PAIR — AND §L14410 SAYS THE OPPOSITE FOR A REASON (P31 S58) L23090
+- **§230** — THE ANCHOR PROBE: with `%hi`/`%lo` masked, the surviving `addiu` deltas tell you which assignment was written first **(single observation — not yet cross-confirmed)** (P31 S58) L23139
+- **§231** — TRANSCRIPTION AND SEMANTIC-READ HYGIENE: six ways the listing misleads (P31 S58) L23154
+- **§232** — WHEN THE `jr` DELAY SLOT'S STORE STORES THE RETURN VALUE, TIE THEM WITH ONE PSEUDO **(single observation — not yet cross-confirmed)** (P31 S58) L23195
+- **§30** — addendum (P31 S58) — the `/s` grant closes a SCHEDULING residual and a REGISTER residual with one edit L23231
+- **§194-B** — addendum (P31 S58) — BOUND 2 is byte-wrong; see §209 Direction A L23251
+- **§176-B** — addendum (P31 S58) — the misdiagnosis direction L23257
+- **§165-40** — addendum (P31 S58) — the barrier goes at the COPY SITE, not inside the region it protects L23263
+- **§164-63** — addendum (P31 S58) — the interposed asm works when the SECOND value is an ordinary assignment L23272
+- **§193-A** — / §194-E addendum (P31 S58) — where the twin's body actually lives L23281
+- **§233** — THE WAVE aa–bg HARVEST (P31 S58b): 1,101 byte-banked notes → 24 new laws, 21 addenda, ~700 already-covered L23287
+- **§234** — CONSTANT MATERIALISATION: THE STORE LVALUE'S SIGNEDNESS PICKS `addiu` vs `li`/`ori` (P31 S58b) L23331
+- **§235** — THE PHANTOM SYMBOL: A MASKED `MATCH` CAN CARRY A RELOCATION THAT DOES NOT EXIST (P31 S58b) L23372
+- **§236** — THE DECLARATION LAYER IS THE DOMINANT BANK-BLOCKER: NINE WAYS A BYTE-PERFECT BODY FAILS THE GATE (P31 S58b) L23401
+- **§237** — THE CAST-AT-CALL-SITE DECISION TABLE: WHAT §17a-1 FIXES, WHAT IT CANNOT, AND THE FOUR ESCAPES (P31 S58b) L23480
+- **§238** — SAME NAME, DIFFERENT FUNCTION: THE OVERLAY-HOMONYM TRAP (P31 S58b) L23535
+- **§239** — TWO-STATEMENT INTEGER-SPACE MATERIALISATION REORDERS `la` vs `sll`; AND THE PLUS-TREE OPERAND ORDER (P31 S58b) L23575
+- **§240** — `A + K + B`: WRITE THE CONSTANT **BETWEEN** THE TWO RUNTIME TERMS (P31 S58b) L23609
+- **§241** — THE FOLDED SIGN-EXTEND-AND-SCALE: `sll 16 ; sra (16 − log2 scale)` (P31 S58b) L23638
+- **§242** — `*k` vs `<>n`: EXPRESSION SPELLING OWNS THE LOAD WIDTH AND THE ROUNDING CHAIN (P31 S58b) L23667
+- **§243** — SPELL THE CSE BARRIER AS A REASSIGNED POINTER; AND THE `nop`-AFTER-EVERY-`lh` SIGNATURE (P31 S58b) L23695
+- **§244** — `volatile` IS A COUNTING INSTRUMENT, A STORE-ORDER PIN, AND MUST SOMETIMES BE ASYMMETRIC (P31 S58b) L23725
+- **§245** — THE CALL'S ARGUMENT LIST IS A SCHEDULING SLOT (P31 S58b) L23760
+- **§246** — THREE-LIVE-VALUE SCAN LOOPS WANT ADDRESS-FROM-INDEX; AND TWO SYMBOLS CAN SHARE ONE giv (P31 S58b) L23807
+- **§247** — TWO BRANCHES TO **ONE** LABEL MEANS THE SOURCE CONDITION IS NEGATED (P31 S58b) L23847
+- **§248** — SPLIT THE LOAD FROM THE ARITHMETIC: A FUSED `g + K` DENIES THE CALLEE-SAVED REGISTER ITS DIRECT HOME (P31 S58b) L23881
+- **§249** — THE SELF-ASSIGN, THE DEAD RE-ASSIGN, AND THE `+ zr` COPY: THREE WAYS TO MAKE A DELETED INSTRUCTION REAL (P31 S58b) L23905
+- **§250** — `%hi/%lo` vs `lw`: THE EXTERN'S ARRAY-vs-SCALAR SHAPE DECIDES ADDRESS MATERIALISATION (P31 S58b) L23947
+- **§251** — IMMEDIATE-SPELLING TRIGGERS: `+= 0xFF`, FULL-WIDTH `~K`, AND THE TWO-OR SPLIT (P31 S58b) L23984
+- **§252** — THE GUARDED PRE-DECREMENT: `(x != 0) && (--x == 0)` (P31 S58b) L24006
+- **§253** — POSTFIX `++` vs `+= 1` PICKS A DIFFERENT SCRATCH REGISTER **(single observation — not yet cross-confirmed)** (P31 S58b) L24027
+- **§254** — THE DEAD PARAMETER IS A REGISTER-PLACEMENT TOOL **(single observation — not yet cross-confirmed)** (P31 S58b) L24041
+- **§255** — THE EMPTY CASE, PART 2: FOUR TREE SHAPES IT BUYS (P31 S58b) L24053
+- **§256** — GOTOS IN THE TARGET'S BLOCK ORDER REPRODUCE SWITCH PLACEMENT WITHOUT SWITCH'S SIDE EFFECTS (P31 S58b) L24088
+- **§257** — THE DEAD-END LEDGER (P31 S58b): ELEVEN LEVERS THAT MEASURED NULL OR BACKFIRED L24125
+- **§258** — ADDENDA TO EXISTING SECTIONS (P31 S58b) L24168
+- **§30** — addendum (P31 S58b) — THE ANONYMOUS STRUCT MEMBER REF GRANTS `/s`, AND THAT IS A TWO-FOR-ONE L24173
+- **§194-B** — / §209 addendum (P31 S58b) — TWO MORE INSTANCES, AND THE BOUND IS NOW REFUTED FOUR WAYS L24194
+- **§202** — addendum (P31 S58b) — THE DEF-SIDE ALIAS ALSO CLEARS A RETURN+PARAM DOUBLE CONFLICT L24217
+- **§205** — addendum (P31 S58b) — CHAINED ASSIGNMENT: N≥3 IS INNERMOST-FIRST, AND THE TEXT MIRRORS EMISSION L24228
+- **§208** — addendum (P31 S58b) — IT SCALES TO SIX SITES, AND IT HAS AN EXACT INVERSE L24245
+- **§210** — addendum (P31 S58b) — THREE CONFIRMED SPELLINGS OF THE BOOLEAN TAIL L24274
+- **§211** — addendum (P31 S58b) — INIT PLACEMENT: FIVE MORE DIALS BEYOND THE GUARD HOIST L24290
+- **§213** — addendum (P31 S58b) — THREE MORE PERMUTATION LAWS FOR INDEPENDENT SAME-BASE STORES L24333
+- **§214** — addendum (P31 S58b) — FOUR MORE WAYS A HIGH-SIMILARITY TWIN LIES L24362
+- **§215** — addendum (P31 S58b) — PIN ECONOMY, PART 2: NINE REFINEMENTS L24398
+- **§217** — CROSS-CONFIRMED (P31 S58b) — AND THE INCOMING HOME SLOT IS THE MIRROR L24450
+- **§220** — addendum (P31 S58b) — THE PARAMETER, NOT A COPY (SEVEN CARDS) L24467
+- **§222** — addendum (P31 S58b) — IF-CHAIN vs SWITCH: THREE MORE DISCRIMINATORS L24492
+- **§223** — addendum (P31 S58b) — FIVE MORE CONFIRMATIONS, AND THE CONSTANT-IN-`$v0` CASE L24510
+- **§224** — addendum (P31 S58b) — CROSS-JUMP MERGES *CALLS*, AND THE DELAY SLOT IS THE DISCRIMINATOR L24534
+- **§225** — addendum (P31 S58b) — THE GUARD-CLAUSE FINGERPRINT, AND THREE MORE SHAPES L24564
+- **§226** — addendum (P31 S58b) — THE FRAME CATALOGUE: SEVEN MORE LEVERS, AND SLOT ORDER IS DECLARATION ORDER L24591
+- **§229** — addendum (P31 S58b) — NAME IT **INSIDE** THE ARM L24636
+- **§230** — CROSS-CONFIRMED (P31 S58b) L24647
+- **§231** — addendum (P31 S58b) — FOUR MORE WAYS THE LISTING MISLEADS L24656
+- **§232** — CROSS-CONFIRMED (P31 S58b) L24687
+- **§259** — THE DISCARD LEDGER FOR THE aa–bg HARVEST (P31 S58b): WHAT WAS MINED AND REJECTED, AND WHY L24698
+- **§260** — THE §154-A LEADING-ISLAND SPLIT: ONE CONFIG LINE, AND THE ISLAND PEELS FROM THE END (P31 S59, byte-proven) L24737
+- **§260-A** — STAGE 2 IS PROVEN, AND THE WHOLE jtbl PIPELINE IS AUTOMATED AT THE GATE (P31 S59, same day) L24787
+- **§261** — THE -O0 ORACLE: DERIVE THE OPT LEVEL FROM THE TARGET, AND `$fp` IS NOT THE TELL (P31 S59) L24823
+- **§261a** — THE -O0 FRAME-RELOAD GRAMMAR: reload COUNT disambiguates the C spelling (P31 S59, byte-proven) L24849
+- **§262** — A LANE'S YIELD IS ONLY A LANE FACT IF IT IS SIZE-MATCHED (P31 S59) L24871
+- **§263** — A STOLEN DELAY SLOT WHOSE INSTRUCTION IS AN ARG-REGISTER COPY IS AN ARITY ERROR, NOT A SCHEDULE (P31 S59, byte-proven) L24901
+- **§264** — FOUR TELLS-LANE C RECIPES, EACH DRIVEN TO MATCH (P31 S59) L24942
+- **§265** — THE VERBATIM-ASM BANK LANE: A FUNCTION NO -O2 C CAN EVER MATCH BANKS AS A RAW `__asm__` BODY (P31 S59b; two banked cards, two in-tree precedents) L24992
+- **§266** — THE INERT-RIDER LAW: A LEVER IS ONLY CITABLE WHEN ITS SOLO REMOVAL BREAKS THE MATCH (P31 S59b; measured 4-of-8 on this batch) L25054
+- **§267** — ADDENDA HARVESTED FROM WAVES at/bh/bk/bl (P31 S59b) L25094
+- **ADD-1** — → §231 addendum (also cross-ref from §195-D) — THE MASKED-`jal` "MISSING CALL" ILLUSION L25102
+- **ADD-2** — → §42a addendum — A SHARED CONSTANT *NAMED IN A LOCAL* ACROSS A `jal` IS AN ISO→TU DRIFT HAZARD; WRITE BARE LITERALS L25111
+- **ADD-3** — → §236, item 10 — THE UN-DELETED `INCLUDE_ASM` STUB IS A DUPLICATE DEFINITION L25123
+- **ADD-4** — → §225-3/-4 addendum — THE MIRROR ROW: VALUE-RETURN IN THE *TAKEN* ARM + TRAILING BARE `return 0` L25133
+- **ADD-5** — → §1/I1 addendum — THE INVERTED RANGE TEST: `(u32)(x-lo) >= N` WITH THE ZERO-ARM AS THE TRAILING `else` L25147
+- **ADD-6** — → §172b-1 / §264 addendum — SHIFT-AS-TEST: `(x << 16) != 0` TESTS THE LOW HALF WITHOUT TRUNCATING THE PSEUDO L25156
+- **ADD-7** — → §256 addendum — THE SINGLE-GUARD GOTO: THEN-BLOCK OUT OF LINE AT THE TAIL L25165
+- **ADD-8** — → §245 addendum — THE RE-TIE BARRIER PINS CALL-ARG SETUP TO SOURCE ORDER (construct 6) L25177
+- **ADD-9** — → §213-3 / §217 addendum — ADJACENT PRE-CALL FRAME STORES ARE ONE AGGREGATE; THE UNESCAPED SCALAR NEIGHBOR IS DEAD-STORED L25189
+- **ADD-10** — → §237 addendum (arity-evidence paragraph) — AN `la` PAIR ABOVE THE PROLOGUE `sw $ra` IS AN OUTGOING-ARGUMENT MATERIALISATION L25199
+- **ADD-11** — → Cross-confirmation card block (per §259's standing instruction: confirmation, not news) L25208
+- **§268** — A `register __asm__` PIN ON A CALL-CLOBBERED REGISTER IS HONORED EXACTLY WHEN THE PINNED RANGE CROSSES NO CALL (P31 S59c; three A/B'd cards, unifying §257-2's two) L25259
+- **§269** — ADDENDA HARVESTED FROM WAVES ax/bm (P31 S59c) L25313
+- **ADD-1** — → §257-8 addendum — THE INTERPOSED ASM'S `__volatile__` IS A PER-SHAPE DIAL, AND THE "NO-OUTPUT ASM IS IMPLICITLY VOLATILE" LORE IS BYTE-FALSE IN gcc-2.7.2 L25328
+- **ADD-2** — → §236 addendum (item 1 corollary) — THE SILENT-SPLICE DECLARATION LADDER: WHERE THE TU HAS NO SPELLING, UNPROTOTYPED `()` BEATS THE FLEET VOTE L25341
+- **ADD-3** — → §238 addendum — TWO BINARIES CAN EACH DEFINE THE SAME `func_` NAME WITH DIFFERENT BYTES, AND NO GENERATED REPORT SHOWS IT L25355
+- **ADD-4** — → §167-37 addendum — THE FIFTH PRECONDITION, NOW MEASURED: DOWNSTREAM FIELD RE-READS ⇒ NAME IT **AND** STORE **INSIDE** THE ARM L25368
+- **ADD-5** — → §267-ADD-6 / §172b-1 addendum — THE SIGN-TEST FACE: `(s16)v < 0` IS `sll 16` + `bgez` ON THE SHIFTED COPY, RAW STAYS LIVE — AND THE HALFWORD-ABS SHAPE NEEDS NO RITUAL L25385
+- **ADD-6** — → §220-addendum — THE FOURTH FACE: WHEN THE NAMED COPY ITSELF BUYS THE EXTRA CALLEE-SAVED, PIN THE COPY TO `$16` L25401
+- **ADD-7** — → §229 addendum — THE VALUE FACE: A LOOP-STORE CONSTANT SPELLED AS A LITERAL HAS NO SOURCE POSITION; NAME IT TO PIN THE PROLOGUE INIT ORDER L25417
+- **ADD-8** — → §30a addendum — THE THIRD COLUMN: `*p++` IS ALSO SERIALIZED BUT BURNS `addiu`; ONLY CAST-PLUS GIVES SERIALIZATION *AND* DISPLACEMENT FOLDING L25430
+- **ADD-9** — → §255 "AND CASE-BODY PLACEMENT" bound / §222-addendum-3 — ON A LARGE SPARSE TREE, BODIES FOLLOW **SOURCE** ORDER (measured by a one-word probe) L25445
+- **ADD-10** — → Cross-confirmation card block (per §259's standing instruction: confirmation, not news) L25459
+- **§3-1a.** — The §266 sweep — every solo-lever A/B run for this batch L25500
+- **§270** — The A-prop 0-bank anatomy: a byte-correct body still needs FOUR layers to agree (P31 S59) L25533
+- **§271** — Ordinal IMM pairing: text order is NOT emission order; emit CANDIDATES, let the oracle pick (P31 S59) L25551
+- **§272** — The `(void)`-decl + empty-call wall: K&R the DEFINITION, not just the decls (P31 S59) L25573
+- **§273** — A standalone compile is the WRONG oracle for a TU-destined draft (P31 S59) L25593
+- **§274** — ADDENDA HARVESTED FROM 18 WAVES (P31 S60): 315 candidates, 255 already covered, 21 sharpenings, 3 new laws L25608
+- **ADDENDUM** — to §179-C — the `.type NAME, @function` requirement L25614
+- **ADDENDUM** — to §134 — a typedef defined BELOW the splice point is stripped anyway L25661
+- **ADDENDUM** — to §179-D (GTE macro reference family) — `gte_SetRotMatrix`/`gte_SetTransMatrix` bodies L25691
+- **ADDENDUM** — to §82 — struct copies must stay MEMBER-WISE, not block-moved, to match a spill-slot save L25717
+- **ADDENDUM** — to §136d-1 (RC-12, the `$0`-add / opaque-copy family) — two symptoms beyond "compare reads the wrong register" L25755
+- **ADDENDUM** — to §20 — a global declared as `T *` may itself BE the array base, not a pointer to dereference L25794
+- **ADDENDUM** — to §1-I5 L25823
+- **ADDENDUM** — to §164-51 L25888
+- **ADDENDUM** — to §176-F5 L25904
+- **ADDENDUM** — to §225 L25933
+- **ADDENDUM** — to §224 — CROSS-JUMP: THE DUPLICATE CAN BE A PLAIN STORE, NOT ONLY A CALL L25978
+- **ADDENDUM** — to §164-64 — AN EMPTY CLOBBER ON AN ARGUMENT REGISTER CAN BE THE DELIBERATE FIX, NOT JUST THE ACCIDENTAL BUG L26012
+- **ADDENDUM** — to §244 — THE COMPILER BARRIER, NOT `volatile`, BLOCKS A STORE→LOAD HOIST THROUGH A POINTER-OFFSET FIELD L26043
+- **ADDENDUM** — to §172b-1 — TWO PLACEMENT DIALS THE PROMOTION LAW DOESN'T NAME: NARROW THE COUNTER'S DECLARED TYPE, AND MOVE THE CAST INTO THE LOOP BODY L26074
+- **ADDENDUM** — to §229 — A POINTER'S NUMBER OF USES DECIDES WHETHER ITS ADDRESS FOLDS OR SURVIVES A CALL L26121
+- **ADDENDUM** — to §172b-4 — THE PLAIN CAST-DIVISION ALREADY PRODUCES THE PATTERN; DON'T HAND-ROLL THE BIAS, AND KEEP THE OPERAND WIDE L26166
+- **ADDENDUM** — to §8 — WHEN `INCLUDE_RODATA` NEEDS A STANDALONE `.s` YOU CAN'T CREATE, CARRY THE FRAGMENT AS A FILE-SCOPE `__asm__` BLOB L26196
+- **ADDENDUM** — to §226 — A DEAD LOCAL SCOPED TO A NESTED BLOCK BUYS A MID-FUNCTION `addiu sp` PAIR, NOT A FRAME-SIZE CHANGE L26239
+- **ADDENDUM** — to §172a — RE-READING MEMORY (NOT NAMING A TEMP) IS WHAT KEEPS AN INCREMENT'S DELAY-SLOT FILL ALIVE L26278
+- **ADDENDUM** — to §225 / §256 — A GOTO TO A SHARED SET-POINT PREVENTS IF-CONVERSION FROM COLLAPSING A LATER BRANCH TEST L26309
+- **ADDENDUM** — to §211 — AN IN-LOOP ACCUMULATOR WANTS A CLOSED-FORM EXPRESSION WHEN THE TARGET REMATERIALISES ITS CONSTANT AFTER EVERY CALL L26351
+- **§275** — THE LEFTOVER-REGISTER READ L26386
+- **§276** — MIXED ADDRESS-EXPRESSION SPELLING FOR ADJACENT RELOCATABLE SYMBOLS IS A CSE-UNIFICATION DIAL, NOT JUST A BYTE-ENCODING CHOICE (P31 S60; `func_80180FE8`, ov_SC06_006, byte-proven) L26426
+- **§277** — RETURN-TAIL C SPELLING PICKS THE DELAY-SLOT-FILL vs TRAILING-MOVE TOPOLOGY, AND A NARROWER SECOND VARIABLE KEEPS TWO PSEUDOS INSTEAD OF ONE (P31 S60; `func_801846F0` ov_SC03_104, `func_801A44C4` md_SC07_004, both byte-proven) L26535
+- **§278** — ADDENDA HARVESTED FROM WAVE cf (P31 S60): 34 candidates, 13 already covered, 8 sharpenings, 4 new laws L26599
+- **ADDENDUM** — to §74 (func_800D0E30, resident) L26607
+- **ADDENDUM** — to §172b-4 (func_80185054, ov_SC03_097) L26643
+- **ADDENDUM** — to §265 (func_8017DC80, ov_SC07_002) L26681
+- **ADDENDUM** — to §17 (func_800CB794, md_MAIN_036) L26720
+- **ADDENDUM** — to §162p (func_8017C120, ov_MAIN_012) L26768
+- **ADDENDUM** — to §20 (~L1947) (func_80186AD0, ov_SC06_032) L26802
+- **ADDENDUM** — to §164-56 (func_8017F644, ov_SC04_005) L26832
+- **ADDENDUM** — to §237 (func_8017F7FC, ov_SC03_092) L26867
+- **§279** — A `do/while (p < end)` LOOP UNDER AN ENTRY GUARD: the guard decides the compare, not the loop (P31 S60; wave cf, func_8017F2A4, ov_SC03_096, byte-proven) L26896
+- **§NNN** — A DO-WHILE'S GUARD AND LATCH MUST REPEAT THE SAME BOUND EXPRESSION, NOT SHARE ONE LOCAL: THE REPETITION IS WHAT BUYS THE CSE'D COPY INTO A SECOND REGISTER (P31 S60; `func_8017F2A4`, ov_SC03_096, byte-proven 25/25) L26897
+- **§280** — THE CURSOR'S DECLARED TYPE PICKS `sltu` vs `slt`: a `T*` bound test is UNSIGNED by C rule, an integer cursor is signed (P31 S60; wave cf, func_800CAE74, md_MAIN_031, byte-proven) L26930
+- **§NNN** — A LOOP CURSOR'S C TYPE (POINTER vs PLAIN INTEGER) SELECTS `sltu` vs `slt` FOR ITS BOUND TEST, INDEPENDENT OF THE VALUES INVOLVED (P31 S60; `func_800CAE74`, md_MAIN_031, byte-proven; cross-confirmed same wave by `func_8017F2A4`, ov_SC03_096) L26931
+- **§281** — GROUP COPY-THEN-RMW BY OPERATION KIND, NOT FIELD BY FIELD: sched1 does the interleaving, the source must not (P31 S60; wave cf, func_80180FB4, ov_SC03_111, byte-proven) L26964
+- **§NNN** — A DEPENDENT COPY-THEN-RMW BLOCK MUST BE SOURCE-GROUPED BY OPERATION KIND, NOT BY FIELD, AND SCHED1 DOES THE INTERLEAVING (P31 S60; `func_80180FB4`, ov_SC03_111, byte-proven) L26965
+- **§282** — gcc's OWN LOOP REVERSAL PUTS THE COUNTER INIT AFTER THE HOISTED MOVABLES — a position no hand-written down-count can reach (P31 S60; wave cf, func_80180DD8, ov_SC04_005, byte-proven) L27010
+- **§NNN** — WRITE THE UP-COUNT LOOP: gcc's OWN REVERSAL PRODUCES A COUNTER-INIT INSTRUCTION THAT LANDS AFTER HOISTED MOVABLES, WHICH A HAND-WRITTEN DOWN-COUNT LOOP CANNOT REPRODUCE (P31 S60; `func_80180DD8`, ov_SC04_005, byte-proven) L27011
+- **What** — I could not verify L27048
+- **§283** — ADDENDA HARVESTED FROM THE 36-WAVE BATCH (P31 S60): 1,216 candidates, 859 already covered, 46 sharpenings, 9 new laws L27095
+- **ADDENDUM** — to §164-75 — the fold-reassociation law also fires at a variable's INITIALIZER, not only a later expression L27105
+- **ADDENDUM** — to §21 — the `bltz`+`slti` (or N-separate-compares) signed-range-split bullet is now CONFIRMED on three independent functions, and generalizes beyond `lbu`/u8 L27131
+- **ADDENDUM** — to §202 — the DEF-SIDE ALIAS also resolves a function-vs-DATA-symbol identifier clash, not only a function-vs-function prototype clash L27177
+- **ADDENDUM** — to §22 (`volatile`-qualified-global reload lever, cookbook ~L1922) — for a NON-constant, same-address double RMW, a plain memory clobber beats `volatile`, and `volatile` actively breaks a delay-slot fill L27200
+- **ADDENDUM** — to §195-E — a goto-ladder's STORES must sit AT the labels, after the gotos, not inline before them L27219
+- **ADDENDUM** — to §195-N — a GNU statement-expression slider must sit INSIDE the conditional arm's value position, not as a post-hoc barrier, to block the store-flag transform on a ternary chain L27281
+- **ADDENDUM** — to §176-B2 — in a micro-function with no long/short lifetime asymmetry, BOTH contending pseudos need their own hard-register pin L27338
+- **ADDENDUM** — to §199-G — A `default:` LABEL GROUPED ONTO THE LAST CASE REMOVES THE `j default` TAIL, EVEN THOUGH THE 2-NODE HEADER STAYS ALL-POSITIVE L27385
+- **ADDENDUM** — to §220 — REFERENCING THE RAW PARAMETER (NO NAMED COPY, NOT EVEN A PIN) LETS THE CALLEE-SAVED SPILL LAND IN THE FIRST CALL'S OWN DELAY SLOT L27454
+- **ADDENDUM** — to §252 — a `>=0`/`<0` split on an unconditionally-decremented value needs the POSTFIX operator INSIDE the branch condition, not a prior statement L27512
+- **ADDENDUM** — to §215 — FIFTH SHAPE: reused mask constants across two call-free merge sites each get their own whole-function hard-register pin, and a shared sub-expression at the second site must be its own statement L27539
+- **What** — I could not verify L27622
+- **Harness-defect** — flags L27693
+- **ADDENDUM** — to §167-40 (func_8017E2CC, ov_SC04_015 — wave dg) L27786
+- **ADDENDUM** — to §20's cross-jump EXPLOIT bullet (func_8017E360, ov_SC05_007 — wave dg) L27806
+- **ADDENDUM** — to §87 (func_801815F4 ov_SC06_032; corroborating func_801840DC ov_SC05_017, func_80189C68 ov_SC03_006 — wave dg) L27820
+- **ADDENDUM** — to §153 / §236-5 (func_801A419C, md_SC07_003 — waves di and dl, corroborating; refutes a contradicted dj-wave card) L27839
+- **ADDENDUM** — to §263 (func_801E83AC, md_SC04_029 — wave dj) L27859
+- **ADDENDUM** — to §265 (func_8017D878, ov_SC03_107 — wave dj; corroborated by a REJECTED, contradicted card in wave dm — see closing) L27873
+- **ADDENDUM** — to §6 (func_801811F0, ov_SC03_102 — waves dj and dl, corroborated by a self-reported "nothing new" dm-wave card) L27887
+- **ADDENDUM** — to §195-G (func_80183BB0, ov_SC05_001 — wave dj) L27901
+- **ADDENDUM** — to the zero-byte-asm-slider family (§47 / §148-C / §153) (func_800CB874, md_MAIN_040 — wave dj; open tension with a more cautious dm-wave card — see closing) L27929
+- **ADDENDUM** — to §194-B (func_8017EB34, ov_SC03_117 — wave dk; distinct from the §74 co-pinning finding on the SAME function below) L27947
+- **ADDENDUM** — to §74 (func_8017EB34, ov_SC03_117 — counter/clamp variant; wave dj, corroborated by dk/dl/dm cards on the same function) L27979
+- **ADDENDUM** — §37 — merged into the §153/§236-5 entry above (func_801A419C, wave dl) L27999
+- **ADDENDUM** — §6 — merged into the §6 entry above (func_801811F0, wave dl) L28007
+- **ADDENDUM** — to §238 (func_80182CB4, ov_SC02_000 — wave dl) L28015
+- **ADDENDUM** — to §137a (func_801684B4, ov_MAIN_012; corroborated independently by func_80189E68, func_8017FF9C, func_801822B4, func_8018DA8C — wave dl) L28033
+- **ADDENDUM** — to §8c / §88d (func_8016AB6C, ov_MAIN_012 — wave dm) L28049
+- **ADDENDUM** — to §73 / §30#2 (func_800D1984, resident — wave dm) L28063
+- **What** — I could not verify L28079
+- **ADDENDUM** — to §174 Law 4 (func_8017E9A8, ov_SC06_015) L28099
+- **ADDENDUM** — the zero-emission-asm family gains a REF-SLIDER PLACEMENT LAW and a paired RESTORER (func_800CB900, md_MAIN_026) L28139
+- **From** — ck + cl + cm L28191
+- **ADDENDUM** — §NNN — sharpens §55a / §164-37 / §165-28 (switch-vs-tree cluster): A SHAPE THAT LOOKS LIKE A SWITCH DISPATCH CAN BE PLAIN NESTED `if`s WHOSE SHARED BODY WAS TRIPLICATED BY THE SOURCE AND THEN CROSS-JUMP-MERGED BACK DOWN L28197
+- **ADDENDUM** — §NNN — sharpens §167-13's boundary: CHAINING TWO IDENTICAL SIDE-BY-SIDE STORES INTO ONE C ASSIGNMENT STATEMENT IS A MID-BLOCK SCHEDULING-PRIORITY DIAL, NOT ONLY A STORE-ORDER SPELLING L28234
+- **ADDENDUM** — §NNN — sharpens §162a3/§60b: A `sll $v0,16 / sltiu $v0,1` ZERO-TEST OF A JUST-DECREMENTED HALFWORD IS A SIGNED-TEMP WIDTH TELL OUTSIDE ANY SWITCH/RANGE-TEST CONTEXT L28267
+- **ADDENDUM** — §NNN — sharpens §37/§124 (unspecified-parameter-list family): DERIVE A CALLEE'S ARITY LOWER BOUND FROM ITS OWN `.s` STACK-ARGUMENT READS, NOT FROM ANY SINGLE CALL SITE L28300
+- **ADDENDUM** — to §5a (func_80181F74, ov_SC03_112, wave cn) L28333
+- **ADDENDUM** — to §265 (func_8017E26C, ov_SC04_016, wave cn) L28383
+- **ADDENDUM** — to §42b (func_8018247C, ov_SC07_002, waves cu + cw) L28421
+- **ADDENDUM** — to §199-F family (func_8017EFB0, ov_SC02_021, wave cu) L28452
+- **ADDENDUM** — to §195-E (func_800CFC1C, md_MAIN_003, wave cv) L28507
+- **ADDENDUM** — to §215 addendum (func_800CB2C8, md_MAIN_033, waves cv + cw) L28552
+- **ADDENDUM** — to §236 item 4 (func_8017D268, ov_SC04_006, wave cw) L28608
+- **What** — I could not verify L28637
+- **Harness-defect** — flags (not idioms — flagged for the operator) L28669
+- **ADDENDUM** — to §250 (func_8017D7CC, ov_SC03_115 — cx/cy/cz/dr) L28710
+- **ADDENDUM** — to §225 (func_8017E190, ov_SC03_115 — cx/cy/cz) L28755
+- **ADDENDUM** — to §45-A (func_8017F6A4, ov_SC02_016 — cy/cz) L28808
+- **ADDENDUM** — to §249 (func_80182ED4, ov_SC04_004 — dp/dr/dt) L28852
+- **ADDENDUM** — to §199-A (func_801816FC, ov_SC02_005 — dp/dr/dt) L28897
+- **What** — I could not verify L28943
+- **Harness-defect** — flags L28986
+- **§284** — COMBINE CAN REASSOCIATE TWO SEQUENTIAL BITWISE-AND MASKS INTO ONE AGAINST THE PRE-MASK VALUE; AN ASM IN/OUT FENCE RIGHT AFTER THE FIRST MASK BLOCKS IT (P31, wave dd, `func_8018087C`, ov_SC04_020, byte-proven) (P31 S60; waves #, byte-proven) L29048
+- **§285** — PRE-INITIALIZING A VARIABLE WITH A SHARED CONSTANT BEFORE A BRANCH MAKES BOTH ARMS OF THE FOLLOWING if/else DESTRUCTIVELY REUSE THE SAME DESTINATION REGISTER FOR THEIR BITWISE RESULT (byte-proven; `func_801811F0`, ov_SC03_102, independently rediscovered across waves di/dj) (P31 S60; waves #, byte-proven) L29052
+- **§286** — FOLD A STATEMENT'S SIDE EFFECT INTO A COMMA-EXPRESSION IN AN ARGUMENT POSITION TO PLACE ITS RTL RELATIVE TO A CALL'S OWN DELAY SLOT (P31 S60/dj; `func_80180A88`, ov_SC06_010, byte-proven 411/411) (P31 S60; waves #, byte-proven) L29056
+- **§287** — A STACK-FRAME HOLE BELOW TWO ADDRESS-TAKEN AGGREGATE LOCALS IS A LEADING PAD MEMBER OF ONE COMBINED STRUCT, NOT SEPARATE LOCALS OR A REGISTER PIN (P31 S60/dj; `func_8017D104`, ov_SC06_027, byte-proven 47/47) (P31 S60; waves #, byte-proven) L29060
+- **§288** — A REGISTER PIN DECLARED UNINITIALIZED AND ASSIGNED ONLY AT ITS LATE, SOLE USE STILL FORCES THE FIXED REGISTER'S SAVE/RESTORE, AND THE ASSIGNMENT'S SOURCE POSITION CONTROLS WHERE THE VALUE MATERIALIZES (P31; `func_80186530`, ov_SC02_017, byte-proven, match_one MATCH re-verified) (P31 S60; waves #, byte-proven) L29064
+- **§289** — an array local's address-taken base keeps every element's store alive, even though only one pointer escapes (`func_80189EFC`, ov_SC04_011) (P31 S60; waves #, byte-proven) L29068
+- **§290** — A SINGLE STRENGTH-REDUCED GIV CAN DRIVE STORES TO SEVERAL DISTINCT RELOCATABLE SYMBOLS, EACH KEEPING ITS OWN `%hi`/`%lo` ANCHOR (P31 S60; waves #, byte-proven) L29072
+- **§291** — THE DELAY-SLOT FALSE-VALUE: A CONDITIONAL BRANCH'S ZERO ARM MUST BE A FALL-THROUGH-ADJACENT BLOCK ENDING IN AN EXPLICIT JUMP, OR REORG CANNOT MATERIALIZE IT INSIDE THE BRANCH'S OWN DELAY SLOT (P31 S60; waves #, byte-proven) L29076
+- **§292** — DECLARING A SYMBOL UPSTREAM OF AN ALREADY-BANKED SIBLING THAT RELIES ON THAT SYMBOL'S IMPLICIT (K&R) DECLARATION CAN SILENTLY REPROTOTYPE THE SIBLING'S OWN CALL SITE (P31 S60; waves #, byte-proven) L29080
+- **§293** — THE "WHOLE-OBJECT GATE NEEDS EVERY SIBLING" LAW, WRITTEN PROPERLY: IT IS THREE LAWS, AND THE LOAD-BEARING ONE IS "THE BASELINE, NOT THE SIBLINGS" (P31 S61; byte-proven on 15 binaries in one night) L29083
+- **§294** — ADDENDA HARVESTED FROM THE S61 GEN0/MAXTOK/MAIN/DEEPSEEK BATCH (waves ab8/ab16/ab24/ab32 · g0a–g0f · m0a · ds1/ds2): 99 candidates, 52 covered, 15 notes → 10 addenda, 29 notes → 5 new laws (§295–§299), 3 refuted L29133
+- **ADDENDUM** — to §127 — the -O0 constant-offset fold keys on the MEMBER-ACCESS tree shape, not on the index being constant L29144
+- **ADDENDUM** — to §261a — FOUR MORE -O0 DIALS BEYOND THE RELOAD COUNT (boot.c + md_MAIN_011/003, wave m0a/g0a/g0f, byte-proven) L29172
+- **ADDENDUM** — to §264-3 — the explicit entry copy's BOUND: required exactly when the RAW value must outlive the call that consumes only the PROMOTED value L29222
+- **ADDENDUM** — to §172b-1 (counter-type dial) — the sll's SOURCE REGISTER is the placement discriminator L29242
+- **ADDENDUM** — to §276 — the SHARE direction: spell the second adjacent symbol RELATIVE to force ONE anchor L29254
+- **ADDENDUM** — to §31's density-dummy dial (L2460/L2497) — the dose is TWO refs, and the dummy must sit where the loser is live-through L29270
+- **ADDENDUM** — to §282 — the ADDRESS-GIV face: write the walked address INLINE so strength reduction births the induction register at loop.c's own insertion point L29287
+- **ADDENDUM** — to §253 — SECOND byte-proven card (upgrade from single-observation), and the placement face: postfix-in-condition parks the RMW store in the branch delay slot L29310
+- **ADDENDUM** — to the L1800 anchor-steer bullet — a DERIVED-POINTER local silently flips the merged giv's anchor END L29331
+- **ADDENDUM** — to §31's asm→layout inference — TWO WIDTH-PAIR DISCRIMINATORS (same offset, different widths) L29354
+- **§295** — THE KERNEL-TRAP STUB: §81's jr-DETECTOR WITHOUT A TABLE IS A PsyQ SYSCALL TRAMPOLINE — ROUTE TO §265, NEVER INTO THE CARVE CHAIN (P31 S61; wave m0a, 9 cards byte-proven; resolves §182's held cluster) L29375
+- **§296** — THE FRAME CHECK OUTRANKS THE ATLAS LEVER: READ PROLOGUE/EPILOGUE BEFORE DRAFTING ANY C — A REAL TELL CAN LIVE INSIDE AN UNREACHABLE FRAGMENT (P31 S61; wave m0a, 16 cards byte-proven; extends §179-C) L29430
+- **§297** — ONE GIV SERVING MIXED-WIDTH LOADS *AND* A STORE NEEDS STRUCT-MEMBER SPELLING; CAST/INDEX SPELLINGS RE-SPLIT THE PSEUDO (P31 S61; wave m0a, `func_800347C8`, main, byte-proven 31/31) L29473
+- **§298** — THE SHARED-TAIL POSITION DIAGNOSTIC: A FOLDED TAIL *BETWEEN* SWITCH ARMS MEANS PER-ARM DUPLICATED STATEMENTS, NOT A HOISTED POST-SWITCH STATEMENT (P31 S61; waves g0e/g0f, `func_80181B68`, ov_SC06_016, byte-proven 68/68) L29516
+- **§299** — TWO INDEPENDENT EXTRACTION CHAINS EMIT CONTIGUOUSLY INSIDE ONE EXPRESSION; ONLY A STATEMENT BOUNDARY MAKES THE SCHEDULER INTERLEAVE THEM (P31 S61; wave m0a, `func_8003A404`, main, byte-proven 8/8) L29541
+- **§300** — S61 DISTILL BATCH NOTES (waves ab8/ab16/ab24/ab32 · g0a–g0f · m0a · ds1/ds2 · m0b) L29576
+- **§301** — AN INTERNAL `j` CARRIES `R_MIPS_26 .text`: rtu/match_one "MATCH" COULD NOT SEE WHICH LABEL A `j` TAKES — FIXED (`jrel`), AND THE TWO DRAFT SHAPES IT HID (P31 S62 T1; byte-proven 2/2, negative-controlled over 3,297 stubs) L29645
+- **§302** — A RED BINARY IS A DRIFTED SPEC, NOT A MYSTERY: THE THREE CARVE-STATE INVARIANTS AND HOW TO DERIVE EACH FROM THE BYTES (P31 S62 T2; five reds healed in one session, 5/5, +39 held banks) L29693
+- **§303** — MODULE ISLAND TABLES: DERIVE THE PADS AT BUILD TIME, PEEL NOTHING — THE §154-A/§260 "island-pads"/"island-blocked" WALLS DISSOLVE (P31 S62 T3a; byte-proven md_SC03_076 func_801F0A9C + func_801F0F28, sha 9a165e36…) L29737
+- **§304** — SELF-DEFINING RODATA: WHEN A FUNCTION'S `.s` IS THE ONLY OWNER OF THE DATA IT REFERENCES, THE C BODY MUST DEFINE IT (P31 S62 T3; byte-proven md_MAIN_011/func_800D04F4) L29773
+- **§305** — "CARVE-REFUSED" AT GATE TIME IS THREE NAMED, DETERMINISTIC CLASSES — NONE OF THEM A CARVE (P31 S62 T3; 28 resolver drafts autopsied 28/28) L29796
+- **§306** — A HAZARD `nop` IN FRONT OF A DIV-RESULT STORE IS A STATEMENT-ORDER DEFECT: THE INDEPENDENT TRAILING STATEMENT MUST BE WRITTEN *BEFORE* THE DIVISION-CONSUMING ONE (P31 S62 T4; byte-proven func_8017E7D0) L29848
+- **§306a** — T4 DISTILL ADDENDA (P31 S62; four byte-proven refinements to existing laws, verified against the book by an independent verifier; each names its parent §) L29875
+- **§307** — THE BRUTE-FORCE-THE-STATEMENT-ORDERS LEVER HAS A BOUND: A FAN-OUT COPY'S PRIORITY IS SCHEDULER-INTERNAL, AND NO SOURCE ORDER REACHES IT (P31 S63; byte-evidenced NEGATIVE result, main wave) L29913
+- **§308** — A NAIVE FINAL `goto` DELETES THE TARGET'S `j`+`nop`: SPELL THAT EDGE AS A TAUTOLOGICAL `if` SO cse FOLDS IT TO AN UNCONDITIONAL JUMP *AFTER* jump1's WINDOW HAS CLOSED (P31 S63 t5e-t5i; byte-proven func_80180808) L29957
+- **§308a** — A TWO-INSTRUCTION ARM STUB LAID *BEFORE* THE OTHER ARM AND REACHED ONLY BY A TRAILING `j` SURVIVES ONLY BEHIND A SHORT-CIRCUIT `&&` GUARD PLUS A SEPARATE RE-TEST; EVERY PLAIN if/else-if, GOTO-LADDER, NESTED-INVERTED-if AND 1-/2-NODE switch LETS jump1 INLINE IT (−2 ins) (P31 S63 t5e-t5i; byte-proven func_80180808) L29986
+- **§309** — A FRAME-ADDRESS EQUIVALENCE RIDES *THROUGH* A SKIPPABLE CONDITIONAL: POST-`if` STORES FOLD ONTO `$sp` UNLESS THE `if` SURVIVES jump1 AS A BARRIER-PRECEDED DIAMOND (P31 S63 t5e-t5i; byte-proven func_801812AC) L30020
+- **§310** — A TWO-OPERAND `subu`'s DESTINATION TIES ONLY TO THE OPERAND THAT IS BLOCK-LOCAL: SHARE *ONE* SIDE ACROSS BLOCKS TO CHOOSE WHICH OPERAND'S REGISTER IT LANDS IN (P31 S64 t5j-t5m; byte-proven func_8017F578) L30060
+- **§311** — A JOIN-BLOCK STORE CAN SWALLOW AN ARM'S LOAD-DELAY `nop`: WHEN ONE ARM'S VALUE COMES FROM A LOAD, DUPLICATE THE STORE INTO BOTH ARMS (P31 S64 t5j-t5m; byte-proven func_8017D7E0) L30091
+- **§312** — A BARE RELATIONAL IN AN `if` GIVES THE `slt` NO TARGET: ASSIGN THE COMPARISON INTO THE ALREADY-ALLOCATED VARIABLE TO CHOOSE ITS DESTINATION REGISTER, AT ZERO INSTRUCTION COST (P31 S64 t5o-t5r; byte-proven func_80180DCC) L30133
---
@@ -2439,810 +2443,811 @@ Notes routinely quote that as a section id. This table resolves it. Grep bait: `
| L2676 | §40c | The h_seq per-sibling reconcile: templating a reconcile-class crack ×134 (Phase 26 Task 8, |
| L2693 | §31-triage | R17 applies to CODEGEN residuals, never to a compile ERROR (Phase 26 session 7, Drew asked |
| L2710 | §41 | The DEF-SIDE canonical-sig wall: mechanically banking a drafted giant past `conflicting ty |
-| L2754 | §41a | v3.1: the def-side wall was ~71% TOOL-shaped — the five measured defects + the laws that d |
-| L2809 | §41b | T7 execution: the object-only probe OVER-counts BANKABLE by two link/rodata classes (Phase |
-| L2839 | §41c | T7-M2: the ×134 def-side-wall sweep via per-sibling RE-reconcile (Phase 25, 2026-07-10; 4, |
-| L2858 | §41b | addendum — M4 "reconcile_decls" tier is ALSO a probe over-count: 0/8 mechanical (Phase 25 |
-| L2878 | §41d | `void`→`s32` is NOT always byte-neutral: gate the RAW draft FIRST (Phase 26 session 6, byt |
-| L2900 | §42 | The F-band ≤28 regalloc crack wave: register-pin/DENSITY levers beat the permuter (Phase 2 |
-| L2953 | §42a | addendum — wave 2 (residuals + 29-100 band): iso-MATCH ≠ real-TU bank, the memcpy→struct-a |
-| L2994 | §42b | addendum — wave 3 (Max, 2026-07-10c): THE STALE-OBJECT GATE TRAP + the read-global `&`-cas |
-| L3033 | §42c | addendum — wave 3 (Max orchestrator + CORRECTED Ultracode fan-out, 2026-07-10c): the real- |
-| L3082 | §42d | addendum — wave 4 (rtu_match fan-out over the mapped frontier, 2026-07-10c): 24/26 MATCH, |
-| L3121 | §42e | propagating a CRACK ×134: the def-finder bug + the byte-drift residual (the "remap-fail" m |
-| L3195 | §43 | The K&R s16-param definition DISSOLVES the "narrow-param wall" for by-value register args |
-| L3242 | §44 | The Phase-25 cheap-Opus giant batch: 5 structural levers + the §43 extension (2026-07-11, |
-| L3298 | §45 | The flagship `func_80133CD4` crack (399 ins ×134): the merged-variable permutation-breaker |
-| L3313 | §46 | The `func_80178D40` crack (890 ins ×134, the heaviest core in the game): four LOOP-STRUCTU |
-| L3365 | §47 | The live-length SLIDER: splitting a global.c allocno-priority TIE with one zero-byte asm ( |
-| L3405 | §48 | The 12-core jr crack wave: the ALLOCNO-PRICING dials and the EBB rule (Phase 26 session 8, |
-| L3413 | §3-A. | ALLOCNO-PRICING DIALS — move a value into the register you want, byte-neutrally |
-| L3444 | §3-A4 | SINK THE CONSUMER CALL INTO THE ARMS (the inverse of A1; `func_8016AB6C`, byte-proven) |
-| L3468 | §3-B. | THE EBB RULE — the general form of §46-L2 |
-| L3484 | §3-C. | TYPE- AND SHAPE-DRIVEN CODEGEN (the C type literally selects the addressing mode) |
-| L3508 | §3-D. | THE CROSS-JUMP RATCHET (the sharpest new trap — `func_80131340` L-C) |
-| L3518 | §3-E. | Meta |
-| L3527 | §49 | The LUID DIAL: a zero-byte SCHEDULING dial (the sched.c analogue of §47) — `func_8017A4AC` |
-| L3576 | §50 | Refinements that BOUND §47/§48 (from the `func_80135EB0` wall, 21→6; Phase 26 session 8) |
-| L3630 | §51 | TOOLING INTEGRITY: the silent skip, and how to hunt it |
-| L3636 | §51a | The bug class |
-| L3652 | §51b | Why the byte-gate cannot save you |
-| L3662 | §51c | THE METHOD (do not audit by reading the regex) |
-| L3677 | §51d | THE LAWS |
-| L3739 | §51e | The false-wall pipeline (why this is not just hygiene) |
-| L3755 | §51f | Checklist for any new corpus-scanning tool |
-| L3769 | §51g | When the thing you are scanning has a GRAMMAR, parse the grammar (`tools/cdecl.py`) |
-| L3913 | §52 | The WALKER-FAMILY skeleton: 6 regalloc-order levers + a deeply-characterized intrinsic wal |
-| L3924 | §3-The | 6 levers (the "walker-family skeleton" — apply to the 12 siblings; levers 1-5 retire ~half |
-| L3945 | §3-Why | the wall is (probably) intrinsic |
-| L3959 | §52a | The regalloc sibling wave: new levers + two new wall classes (cheap-Opus applying §52, 202 |
-| L3997 | §52b | Sibling wave 2: more de-pin levers, a third wall class, and the match_one→whole-binary gap |
-| L4028 | §53 | SWEEP A FAMILY WITH THE TOOL ITS EXEMPLAR NEEDED: the jr/switch carve, and how omitting it |
-| L4033 | §3-The | case |
-| L4045 | §3-Why | 0/8 was structural, and predictable from two words |
-| L4062 | §3-The | rule |
-| L4078 | §3-The | meta-lesson (R35, and why this one is expensive) |
-| L4093 | §55 | Core-crack wave levers + the GATE-ORCHESTRATION law (Phase 29 T3, 13-agent ultracode wave, |
-| L4098 | §55a | New byte-proven levers (each from a banked or near draft) |
-| L4122 | §55b | THE GATE-ORCHESTRATION LAW (3 traps, ~3.5h lost; all recovered, 0 data lost) |
-| L4141 | §55c | Sizing the propagate: a TARGETED propagate is ~4 min/core, and "it's slow" was a BROKEN-TR |
-| L4163 | §54 | `--fix-def-sig`: the member's CANONICAL DECLARATION is a build step too (tiny-IMM mega-poo |
-| L4187 | §56 | Banking a hand-drafted GIANT into its exemplar TU: self-contained draft vs live-TU decls, |
-| L4232 | §56b | PROPAGATING an h_seq giant: the exemplar's externs MUST be fleet-canonical, not the draft' |
-| L4256 | §57 | The SELF-decl normalize: the sibling's OWN caller declares the templated fn divergently (t |
-| L4303 | §57a | Two NSD corrections + the SURGICAL-ONLY law + the honest broad-sweep yield (Phase 29, 2026 |
-| L4343 | §58 | match_one MATCH ≠ BANK: the four blind spots + the crack-wave reconcile-before-bank law (P |
-| L4377 | §59 | Three h_seq sweep-residual classes match_one/the-exemplar-bank don't reveal (Phase 29 crac |
-| L4407 | §60 | Classify the residual, don't rank it: the deterministic residual→class classifier and what |
-| L4431 | What | it measured — the whole open backlog, byte-grounded |
-| L4450 | §3-Two | corollaries worth remembering |
-| L4463 | §3-The | parallel-probe race this surfaced |
-| L4472 | §60a | What the first DIRECTED grinder run exposed (Phase 29 Task-13B, 2026-07-21) |
-| L4510 | §60b | The plateau autopsy's verdict: a `partial` drift is a WRONG DRAFT, not a missing transform |
-| L4545 | §61 | Task 14: the gate ladder's missing stage is the ARITY pre-pass, and it is TU-side not draf |
-| L4606 | §61a | The Task-5 wave: 11/12 MATCH, 0 banked — three DISTINCT integration walls, each now named |
-| L4658 | §61b | The jtbl gate stage: built, and the ORDERING law it exposed (Phase 29 Task-14 stage 4, 202 |
-| L4713 | §61c | The jtbl bank is INCREMENTALLY valid and CLEAN-INVALID (Phase 29, 2026-07-21) — the blocki |
-| L4779 | §61d | The undo was eating the tree: two tools, one defect, invisible to the byte-gate (Phase 29, |
-| L4833 | §62 | The jtbl RECONCILE must also follow the carve: the post-carve draft reconcile (`harvest_ve |
-| L4877 | §63 | The fresh-138 DEF-SIDE blocker: fix the HEADER decl, not the draft (`fix_header_decl.py`, |
-| L4908 | §64 | The §20 type-lift's three laws: fold the tagged typedef, check VISIBILITY, and strip only |
-| L4957 | §64a | VARIANT types: UNIQUIFY the camps, do not reconcile them (`uniquify_type.py`, Phase 29 SES |
-| L5000 | §63 | UPDATE (Phase 29 SESSION-14) — `fix_header_decl`'s "SAFE" verdict is FLEET-BLIND; it MUST |
-| L5015 | §65 | The stranded-draft recovery: BLAST-RADIUS TIERS, and the per-overlay de-macroize that refu |
-| L5030 | §65a | The blast-radius taxonomy (makes §61's law structural instead of remembered) |
-| L5045 | §65b | The escape: de-macroize the instantiation, don't touch the shared header |
-| L5081 | §65c | `rtu_match` MATCH → bank held 13/13 on self-decl, but broke on the FIRST callee-decl case |
-| L5091 | §65d | Existing-ladder baseline, measured (do this before building a recovery stage) |
-| L5101 | §65e | Two oracles, and the disagreement is the finding (R34 in practice) |
-| L5118 | §65f | The de-macroize lever's BOUNDARY, measured: byte-neutral 14 times of 15, and the 15th is w |
-| L5139 | §65g | Where the cheap levers STOP: the local-type and in-TU-self-decl classes did not yield |
-| L5159 | §66 | Exercise a banking driver's SUCCESS path before pointing it at a wave: the free re-bank te |
-| L5181 | §66a | The widest write in a pipeline is the one most likely to be UNDECLARED |
-| L5200 | §66b | A metric parsed out of another tool's prose goes NULL silently when the label changes |
-| L5217 | §66c | Before a wave, verify the FUEL exists; an "already attempted" set built from the wrong dir |
-| L5245 | §66d | The permuter⇄reader loop: alternate a random search with a byte-verified idiom, and let `r |
-| L5280 | §66d-1 | What transfers between giants is the LOOP, not the PIN |
-| L5289 | §66d-2 | Two operational sharp edges |
-| L5300 | §66d-3 | Read the ILS per-cycle SERIES, not its final best: a repeated score and a still-falling on |
-| L5315 | §67 | The arg-copy PLACEMENT lever: launder a parameter into a fresh pseudo AT the statement whe |
-| L5405 | §67a | Run the symbol-set guard BEFORE you pay for a gate (`tools/symcheck.py`, Phase 29 SESSION- |
-| L5438 | §66d-4 | "ILS converged" means converged FOR THAT WEIGHT PROFILE, not a floor (amends §66d-3; Phase |
-| L5491 | §66d-5 | `residual_class`'s "structural ⇒ permuter CPU is waste" is WRONG for schedule permutations |
-| L5524 | §68 | A comment-only line halted the extern scan, and the skip label blamed the type cap (Phase |
-| L5569 | §69 | How to attack a behemoth: map it, don't draft it (Phase 29 SESSION-18, `func_80183814`, 5, |
-| L5619 | §70 | The giv-init base register: walk the PARAMETER, not a copy of it (Phase 29 SESSION-18, `fu |
-| L5660 | §71 | Before mapping a giant, look for an already-matched SIBLING beside it (Phase 29 SESSION-18 |
-| L5726 | §72 | A `register __asm__` pin is a PREFERENCE, not a reservation (Phase 29 SESSION-18, `func_80 |
-| L5750 | §3-The | honest fix was source-level and cheap |
-| L5760 | §3-Giv | record order (the §70 family) |
-| L5766 | What | is left, and what is byte-recorded as SPENT |
-| L5783 | §73 | A def-side self-decl conflict has TWO axes: RETURN (fleet widen, T2) and PARAMS (casts at |
-| L5822 | §74 | Auditing a pinned draft: the §72 hazard is CALLER-SAVED pins spanning a call, and only the |
-| L5866 | §75 | A propagation cap is usually a MINORITY-SPELLING SOURCE OVERLAY, not a wall: census the ca |
-| L5925 | §75a | The exclusion classes, enumerated with named causes (Phase 29 SESSION-19, the 134-binary ` |
-| L5948 | §75b | A body's preamble can carry `#define`s, not just `extern`s; extraction lifts only the exte |
-| L5997 | §75c | Class-B's remedy is the FULL §17a-1 PAIR (decl **and** call-site cast); a decl-only fix mo |
-| L6028 | §76 | The allocno CLASS (local vs global) is the dominant regalloc lever, and C reaches it ONLY |
-| L6037 | §3-The | mechanism, with citations |
-| L6057 | §3-The | attribution primitive (use this before calling anything a scheduling residual) |
-| L6064 | §3-Two | diagnosis traps this function proved |
-| L6074 | Practice | Practice |
-| L6084 | §77 | Every extraction tool carries a NARROW hard-coded preamble set; anything outside it silent |
-| L6124 | §3-The | CANDIDATE gate and the REAL gate need DIFFERENT preambles — keep the difference out of the |
-| L6174 | §78 | A LENGTH drift can be a register grant in disguise; and `fold` never leaves a literal firs |
-| L6180 | §3-The | drift was an allocation decision, not missing code |
-| L6211 | §3-The | economics |
-| L6220 | §79 | For a 0-callee giant, fingerprint by DATA symbols (§71 cannot fire); and the STACK-SLOT OR |
-| L6226 | §71 | has a blind spot, and this is it |
-| L6240 | §3-NEW | LEVER — the frame layout reads back the original declaration order |
-| L6251 | §76 | confirmed at scale, and a pin nuance |
-| L6260 | §3-The | residual, and the honest read |
-| L6270 | §80 | A do-not-re-buy entry is scoped to its BASE, not to the function; and the pin's hidden cos |
-| L6291 | §3-The | pin's hidden cost, with the citation |
-| L6302 | §3-The | flagged "#1 move" LOST — and why the failure is informative |
-| L6312 | §78 | 's attribution primitive, run and reproduced |
-| L6318 | Cold-start | economics, now complete |
-| L6323 | §81 | Banking a jr (jump-table) function: the 3-step carve chain, and why `match_one` cannot see |
-| L6354 | §3-The | defect this exposed: a shared type that is present but invisible |
-| L6370 | §82 | Two source-shape oracles from behemoth #6: a duplicated `addiu $aN,$sp,K` across a `jal` m |
-| L6375 | §3-1. | The inlined-helper signature |
-| L6389 | §3-2. | Scalar vs aggregate decides *when* the slot is allocated |
-| L6401 | Also | reproduced on this function |
-| L6405 | §3-And | the banking footnote (§75a class A, one line) |
-| L6412 | §83 | The parameterised-repeat law, the spill-area trap, and why a per-case edit cannot move a p |
-| L6419 | §83a | READ THE HEADLINE NUMBER CORRECTLY: a LENGTH drift makes `match_one`'s count meaningless |
-| L6427 | §83b | THE LEVER: find the parameterised REPEAT before decoding case-by-case |
-| L6445 | §83c | TRAP: a "dead local" in a prior draft may be gcc's OWN spill area |
-| L6452 | §83d | CSE's quantity budget is WHOLE-FUNCTION, so a local rewrite cannot fix a local symptom |
-| L6466 | §83e | §80 vindicated again, on the same day it was written |
-| L6472 | §84 | The DERIVED-OFFSET remap bug: a hand-computed literal that encodes the DISTANCE between tw |
-| L6477 | §3-The | construct |
-| L6495 | §3-Why | it survived every candidate gate |
-| L6510 | §3-THE | FIX IS MECHANICAL — the tool already holds the answer |
-| L6518 | Scope | , measured (do not over-generalise — §80) |
-| L6528 | §3-Two | ladder lessons banked with it |
-| L6539 | §85 | The RETURN-axis fleet widen is ALL-OR-NOTHING: widening the shared header alone guarantees |
-| L6544 | §3-The | conflict |
-| L6552 | §3-THE | FAILURE MODE — widening only `engine_core.h` is worse than not starting |
-| L6559 | §3-The | precondition, and how to check it in one grep |
-| L6567 | §3-Do | the WHOLE axis in one edit, then R22 once |
-| L6576 | Reading | , for the next person |
-| L6589 | §86 | Pinned-exemplar templatability is a PER-FAMILY property, not a per-member rate; and the §4 |
-| L6591 | §3-The | guard refuses a class that largely works |
-| L6600 | §3-THE | LAW: all-or-nothing PER FAMILY |
-| L6627 | §3-Why | the two live families differ from the three dead ones — the open question |
-| L6633 | §87 | `match_one` COMPILES but never LINKS, so an unresolvable data symbol reads as MATCH; and s |
-| L6649 | §3-The | blindness ladder, now complete — FOUR classes `match_one` cannot see |
-| L6659 | Consequence | for the backlog ledger |
-| L6666 | §3-The | cheap discriminator, before spending a sweep |
-| L6674 | §88 | `cross_jump` will not merge a common suffix containing a CALL; and §78 is scoped to ORDERE |
-| L6679 | §88a | repeated CALL-shaped blocks are left UNMERGED; call-free tails are merged for you |
-| L6686 | §88b | the `slti` literal-position law (extends §78 to comparisons) |
-| L6701 | §88d | BANKING ORDER: run the §81 carve chain BEFORE banking, never after |
-| L6708 | §88e | a wrong diagnosis, refuted properly (the model for how to treat an inherited lever) |
-| L6718 | §88f | the missing rung: a RELOCATION gate between `match_one` and the binary |
-| L6726 | §89 | Two throughput rules the project already had written down and was not following (Phase 29 |
-| L6732 | §89a | MEASURE the write set; do not assert its tier (`tools/blast_radius.py`) |
-| L6745 | §89b | the parallel gate farm existed; the family path could not reach it (`tools/sweep_parallel. |
-| L6758 | §3-The | standing sequence |
-| L6766 | §90 | Five tool-integrity laws from one session, each of which changed an answer (Phase 29 SESSI |
-| L6772 | §90a | A comparison tool MUST share its reference oracle's index space, exactly |
-| L6789 | §90b | "Byte-neutral" is not "wanted": undo on the SUCCESS path too |
-| L6799 | §90c | A library-callable function must FAIL CLOSED on an unconfigured module |
-| L6810 | §90d | Do not measure a live wave's drafts (§87 in real time) |
-| L6818 | §90e | An agent's CONCLUSION and its EVIDENCE fail independently — re-derive the premise, not the |
-| L6842 | §91 | A structure-TRANSFER is only valid where the structure corresponds: the `--like` role trap |
-| L6871 | §3-The | three-hypothesis trail, because two of them were wrong and the wrongness is instructive |
-| L6891 | §92 | Conforming a DECLARATION: pointer changes are caller-neutral, scalar-WIDTH changes are not |
-| L6922 | §93 | `set -o pipefail` attributes a pipeline failure to the LAST stage, not the failing one (Ph |
-| L6947 | §94 | A family sweep's `0/N` is a TYPE-CARRY failure until proven otherwise: lift the exemplar's |
-| L6983 | §95 | `reconcile_tu` dropped the SIBLING declarators of a multi-symbol `extern` line (Phase 29 S |
-| L7018 | §96 | The same rewrite, one shape down: `reconcile_tu` matched statements to lines by TEXT, so e |
-| L7066 | §97 | The gate's own tree hygiene: a refused carve, an unchecked recovery, and a snapshot that c |
-| L7113 | §98 | `conform_decls` had three defects, and only the third needed R22 to find (Phase 29 SESSION |
-| L7167 | §99 | The narrow-param wall is a DEF-side problem with a ZERO-blast-radius fix: convert the defi |
-| L7190 | §3-Two | `reconcile_tu` bugs found underneath, one introduced while fixing the other |
-| L7216 | §100 | Prefer the DRAFT-LOCAL fix: a type only one function uses belongs in its BODY, not in a sh |
-| L7245 | §101 | The STALE DEFAULT class: a guard whose cause was removed is a silent skip wearing a safety |
-| L7272 | §102 | A PLUMBING verdict can MASK a DIFF; and K&R is not always a codegen change (Phase 29 SESSI |
-| L7307 | §103 | A FILE-scope `extern` in a shared overlay TU is a GLOBAL constraint on every LATER functio |
-| L7395 | §104 | Two silent-skip defects in one scan: match on MASKED text, emit from the ORIGINAL (Phase 2 |
-| L7431 | §105 | A gate's revert must survive an EXCEPTION, not just a failure (Phase 29 T53, `jtbl_family_ |
-| L7470 | §106 | Persist the MEASUREMENT, derive the POLICY: a stored route let a stale file out-vote the l |
-| L7513 | §107 | A lever wired into ONE gate path is a lever most families cannot reach (Phase 29 T56, `fun |
-| L7551 | §108 | Diagnosing a family `0/N`: the four causes, and the third opt-in lever (Phase 29 T59) |
-| L7600 | §109 | Conforming a definition to a shared header: fix the NAMES, then check the RETURN precondit |
-| L7640 | §110 | A unit must define exactly ONE function, and "ends in `;`" does not tell you which line de |
-| L7681 | §111 | The distinct-code metric is not noisy: a family pays it only if its members are byte-VARIA |
-| L7730 | §112 | A macro-scoped declaration only collides where the macro is INSTANTIATED (Phase 29 T67/T69 |
-| L7776 | §113 | An ARITY blocker only exists if the macro CALLS the function; an address-taken use has no |
-| L7808 | §114 | The THIRD decl axis: a CALLEE the draft declares differently from the target TU (Phase 29 |
-| L7850 | §115 | A `func_XXXXXXXX` predicate rots by design: the same name-form assumption in THREE places |
-| L7877 | §116 | Optimization level is a property of the FILE, not the function: read a family 0/N against |
-| L7895 | §3-The | fix moves the DEFINITION, not the stub — and here is why the obvious shortcut fails |
-| L7926 | §117 | Spell the sibling's symbol from the SIBLING's address, not the exemplar's kind (Phase 29 T |
-| L7953 | §3-Why | it survived so long: a MASKED oracle will MATCH a wrong symbol |
-| L7963 | §118 | Ordinal (positional) immediate resolution: compare C tokens to the DIFFERING asm uses (Pha |
-| L7997 | §119 | Two levers on the SAME axis, opposite directions: test the off-diagonal (Phase 29 T89) |
-| L8026 | §120 | Uniquify draft-defined TYPE names; and check which of N staging sites you actually patched |
-| L8037 | §3-Do | NOT "strip the duplicate typedef" — it breaks the extern that uses it |
-| L8043 | §3-The | wiring trap that cost two attempts |
-| L8061 | §121 | Synthesise externs for macro-DEFINED callees from the macro's own definition head (Phase 2 |
-| L8084 | §122 | GATE RAW BEFORE TRANSFORMING; the undo belongs to the WRITER, as a per-edit journal (P30 T |
-| L8116 | §123 | PROPAGATE A FAMILY WITH THE TOOL ITS TIER NEEDS: `dedup_propagate` is h_exact-only; its re |
-| L8153 | §124 | A "not matched" verdict can mean the definition is there under a DIFFERENT C NAME: the asm |
-| L8198 | §124a | a family sweep's `0 matched-exemplar families` may be a FILTER, not a wall |
-| L8206 | §125 | Split the CARVE from the BODY before calling a jr residue a wall — and measure it by SHA f |
-| L8213 | §3-The | method (keep this) |
-| L8223 | §3-The | instrument rules that make its answer trustworthy (this is where I failed) |
-| L8238 | §3-The | corrected results (each SHA-verified, from a clean tree, restore re-verified) |
-| L8248 | §3-Two | further notes worth keeping |
-| L8257 | §3-The | meta-lesson |
-| L8264 | §126 | The carve-within-a-carve: an ADDRESS RANGE is not an OPTIMIZATION REGION (P30 T2, byte-pro |
-| L8279 | §3-The | finding: opt level is per FILE, so the file's contents must be opt-HOMOGENEOUS |
-| L8290 | §3-The | instrument trap that hid it (and it is §124's shape again) |
-| L8299 | §3-The | mechanics |
-| L8317 | §126a | a bare `except: continue` around a coverage-asserting oracle re-creates the silent skip (P |
-| L8349 | §127 | The `-O0` regime: the CONSTANT-OFFSET FOLD, and why `-O0` needs its own idiom set (P30 T3 |
-| L8356 | §3-The | idiom they kept re-deriving: the constant-offset fold |
-| L8367 | §3-The | rest of the `-O0` regime (write PLAIN C, and mean it) |
-| L8377 | §127a | §71 (sibling-first) is the strongest `-O0` lever, and it beats the index |
-| L8386 | §127b | the knowledge was in a SOURCE COMMENT, not the cookbook |
-| L8393 | §128 | A raw NUL in C source makes grep SILENTLY SKIP the file (P30 S28, 137 files) |
-| L8425 | §128a | a negative control must corrupt a SCRATCH COPY, never the tracked file |
-| L8437 | §129 | Post-carve, `rtu_match`/`match_one` COUNT THE JUMP TABLE AS INSTRUCTIONS; and a carve must |
-| L8441 | §129a | the target instruction count is INFLATED after a carve |
-| L8462 | §129b | never commit a carve whose owner is still a stub (it strands the carve) |
-| L8477 | §3-The | real blocker underneath, for the record |
-| L8486 | §130 | An INCREMENTAL build can report BYTE-IDENTICAL for a change the CLEAN build cannot even LI |
-| L8523 | §3-The | diagnostic ladder that finally located it (reusable) |
-| L8533 | §131 | The jtbl OVER-SPAN: `sltiu N` is ground truth in BOTH directions, and the zero-word rule o |
-| L8570 | §132 | The `JR-PAIR-IN-ONE-O0-OBJECT` "wall" was TWO instrument defects: a merged-double span the |
-| L8579 | Defect | 1 — a pre-§8e MERGED DOUBLE is not a single-table predecessor |
-| L8597 | Defect | 2 — `as` writes a corpse and nothing deletes it |
-| L8607 | §3-The | fingerprint, and the 30-second ladder that found it |
-| L8628 | §3-The | transferable rule |
-| L8635 | §132a | `--like` is for a sibling with NO record; against one that HAS a record it over-derives (P |
-| L8660 | §132b | When the span's already-matched owner is ITSELF multi-switch: `--span-rel` (P30 S1, `func_ |
-| L8685 | §133 | The DEFAULT-FILTER class: three times in one session, a tool silently answered a narrower |
-| L8711 | §134 | MULTI-LINE BLINDNESS: one root cause, four faces, in `family_remap`'s preamble scanner (P3 |
-| L8765 | §135 | Six byte-verified gcc-2.7.2 idioms from the P30 S6f-h waves (and the two-lane wave shape t |
-| L8770 | §3-The | codegen idioms |
-| L8804 | §3-The | integration idioms (these decide whether a byte-correct draft BANKS) |
-| L8819 | §3-The | wave shape that produced these |
-| L8837 | §136 | The LOCAL-VARIABLE lever: how many C locals, at what scope (P30 wave 4a, 25 byte-verified |
-| L8853 | §3-The | splitting/merging rules (each closed a residual, byte-gated) |
-| L8879 | §3-The | type-form rules |
-| L8912 | §3-The | scheduling rules (refining §135-2 and §135-4) |
-| L8941 | §3-The | declaration surface (integration, not codegen) |
-| L8953 | Wave | economics (measured, for the next batch's sizing) |
-| L8976 | §136a | Blocker capture: classify on the OUTPUT, never on the exit status |
-| L9033 | §136b | A prior wave's "genuine byte-DIFF" verdict is NOT reliable evidence (4 of 4 refuted) |
-| L9069 | §136c | SIBLING-FIRST is a DERIVATION shortcut, not just a conflict fix (the fastest route in a fa |
-| L9094 | §136d | Four gcc-2.7.2 levers the redraft lane found (each closed a residual no other lever moved) |
-| L9138 | §136e | §136c's PRECONDITION, and two more symptom keys (wave 4b batch 3) |
-| L9186 | §136f | Two declaration sub-cases the reconcile lane surfaced (lane now 15/15 lifetime) |
-| L9211 | §136g | When the index points at the WRONG lever: two byte-refuted routings (func_801863B4) |
-| L9240 | §136h | CORRECTION: the zero-crack pool does NOT "refill with cheap work" (my error, byte-measured |
-| L9270 | §136i | The drafter model LADDER: Haiku → **Sonnet** → Opus → Fable5 (Drew, 2026-08-03) |
-| L9302 | §136j | The failure MIX flips with function size (measured across four bands, one session) |
-| L9344 | §137 | REGALLOC-PERM is a TWO-COMPILE ARITHMETIC PROBLEM, not a permuter job |
-| L9386 | §137a | A gate verdict has a TIMESTAMP; re-check it against the draft's mtime |
-| L9415 | §138 | The propagation lanes: a gate refusal is a DECLARATION, and which lever you owe depends on |
-| L9421 | §3-The | triage, cheapest first |
-| L9473 | §3-The | DEFINITION-side alias is the only escape when the fleet canon disagrees on a promoting par |
-| L9481 | Rank | the lane by measured concentration, not by class count |
-| L9490 | THREE | carry variants hide in one "CARRY-FIXABLE" bucket — and they need different fixes |
-| L9526 | §134 | again, in a second tool — and the waiter rule corrected |
-| L9546 | STEP | 0 of sibling-first: grep `src/` for a distinctive LITERAL from the `.s` |
-| L9565 | Reconciling | a gate-refused draft: which way you edit depends on WHERE the TU's decl is |
-| L9594 | §139 | A GATE THAT GREPS FOR VERDICTS MUST ASSERT 1:1 ACCOUNTING; and a `--src` filter must not s |
-| L9626 | §3-The | generalisation — three corollaries worth more than the bug |
-| L9643 | §3-And | the inverse-lookup trap, same session |
-| L9660 | §140 | A METRIC IS NOT A MEASUREMENT UNTIL IT IS REPRODUCIBLE FROM THE COMMITTED TREE (P30 S1e: a |
-| L9680 | §3-The | three-line proof (do this before diagnosing any metric movement) |
-| L9689 | §3-The | two instrument defects it exposed |
-| L9709 | §3-The | same swallow, twice more, in the integration spine |
-| L9720 | §3-Two | wrong mechanisms I chased first, and why they were wrong |
-| L9740 | §141 | The §134 class is CLOSED: every line-shape decision now routes through `cdecl._mask` (P30 |
-| L9778 | §142 | An open stub whose `h_exact` class is MATCHED elsewhere is FREE. Propagate the body; do no |
-| L9790 | §3-The | measurement (do this before any wave; it is ~20 lines and needs no builds) |
-| L9805 | §3-The | trap that hid it — SAME FUNCTION, TWO ROUTES, ONLY ONE IS FREE |
-| L9814 | Route | selection (why `--addr` sometimes says "nothing changed") |
-| L9822 | §3-And | the report-vs-bytes lesson attached to it |
-| L9834 | §143 | `cast_call_sites` read a RETURN STATEMENT as a prototype and deleted it. A 0/39 sweep beca |
-| L9888 | §144 | THE LITERAL'S SPELLING PICKS THE IMMEDIATE ENCODING (P30 S40 wave 1, `func_801822E0`) |
-| L9927 | §145 | Three loop/combine levers from the S40 wave-2 drafters (16/16 match_one) |
-| L9977 | §146 | RE-MEASURE A WALL BEFORE YOU RESPECT IT. Both "permanent" giants fell to drafts already on |
-| L9988 | §3-Why | a correct draft can read as an intrinsic wall |
-| L10000 | Then | propagation returned 0/137 TWICE — both times a missing TYPE |
-| L10009 | §3-Two | errors of mine, both instructive |
-| L10023 | §3-The | rule |
-| L10036 | §147 | The three-stratum FRAME LAW, and four "stop searching" verdicts (P30 S42, `func_8017C294`, |
-| L10041 | §3-A. | The frame has THREE strata, and stratum 3 is unreachable from C |
-| L10057 | §3-B. | A `?:` on MEMORY operands costs ~16 bytes of invisible frame; on REGISTER operands, zero |
-| L10068 | §3-C. | Inner-block declaration does NOT delay slot allocation — BYTE-REFUTED |
-| L10073 | §3-D. | A lone `$t8`/`$t9` in the target is RELOAD SCRATCH — reproduce the spill, don't pin the re |
-| L10083 | §3-E. | A `qty_compare` TIE is not spelling-reachable — recognise it and stop |
-| L10095 | Consequence | for the family (a real scheduling decision) |
-| L10145 | §148 | The loop.c hoisting THRESHOLD is arithmetic you can compute, and the `?:` clamp that folds |
-| L10151 | §3-A. | `move_movables` hoists iff `threshold × savings × lifetime ≥ insn_count` — and you can rea |
-| L10170 | §3-B. | `(v < 0x40) ? v : 0x3F` is folded to `MIN_EXPR` and expands to the WRONG SHAPE |
-| L10184 | §3-C. | A zero-byte ALLOCNO-PRIORITY slider |
-| L10194 | §3-D. | Reproduce the original's BUGS verbatim |
-| L10243 | §149 | Four instrument defects in one session, and the two questions they were hiding (P30 S43) |
-| L10249 | §3-A. | A prep step that returns its input on failure is indistinguishable from a search that foun |
-| L10267 | §3-B. | Same address + same name ≠ same body — and the ledger keys on address |
-| L10283 | §3-C. | `make: *** [...] Error N` is a summary, never a diagnosis |
-| L10293 | §3-D. | "Cheap fuel" that was never probed: 0 of 31 templatable |
-| L10312 | §150 | A register ROTATION across symmetric blocks is VARIABLE-IDENTITY evidence, not an allocato |
-| L10319 | §3-The | fix |
-| L10329 | §3-The | method that found it (this is the transferable part) |
-| L10345 | §3-Two | corrections to the record |
-| L10356 | Diagnostic | order (adopt this) |
-| L10367 | §151 | THE GHOST WEDGE: when a load-before-store transposition is unreachable by ANY statement or |
-| L10372 | §3-The | mechanism (read from cc1's own `-dR` trace, not inferred) |
-| L10387 | §3-The | lever — a zero-emission insn that absorbs the blocked tick |
-| L10395 | §3-The | two fallouts, and how to close them (both measured, in order) |
-| L10407 | When | to reach for it |
-| L10418 | §152 | BYTE SIZE is the family key that name- and h_seq-grouping both miss (P30 S43, the 0xECC fa |
-| L10423 | §3-The | finding |
-| L10432 | §3-The | key |
-| L10443 | §3-Two | cautions that must travel with this technique |
-| L10454 | §3-The | companion defect (open) |
-| L10466 | §153 | THE ADDRESS-REMATERIALISATION LAUNDER: a third zero-emission asm lever (P30 S43, `func_801 |
-| L10474 | Symptom | Symptom |
-| L10479 | Mechanism | (gcc source + RTL dumps, not inferred) |
-| L10486 | What | does NOT work (14 byte-measured probes) |
-| L10492 | §3-The | cure — a fresh launder per site, each in its own block |
-| L10502 | Companion | levers from the same function |
-| L10522 | §154 | Reading a disc payload: the module-id word, static base derivation, and "type 1 = uncompre |
-| L10527 | §3-A. | Payload word0 is a global MODULE ID; code starts after the header |
-| L10536 | §3-B. | Two static base-derivation methods that must AGREE (use both) |
-| L10548 | §3-C. | PAC type 1 = the same payload class as type 4, just NOT compressed |
-| L10558 | §155 | hi/lo literal scanning MUST track base registers (S45) |
-| L10567 | §155a | the same failure class, one level up: SHAPE-blind table scanning (S45 p5) |
-| L10587 | §155b | check the TYPE your oracle returns before comparing against it (S45 p5) |
-| L10610 | §155c | the ZERO-REFERENCE trap: gcc splits a global-array address across the `lui` and the LOAD ( |
-| L10640 | §156 | an ORPHANED reconcile poisons the fleet: `dedup_propagate`'s kept edit (S45 p6/p7) |
-| L10687 | §157 | the cheap-tier size cliff, measured (S45 p6) |
-| L10712 | §158 | The RANGE-EXTENDER: a fourth zero-emission asm lever completes the allocno toolkit (P30 S4 |
-| L10721 | Symptom | Symptom |
-| L10727 | §3-Why | the fork is chained (gcc source, validated insn-by-insn against -dS/-dR dumps) |
-| L10740 | §3-The | method (dump-arithmetic first, then place — no probing) |
-| L10757 | Bonus | facts worth keeping |
-| L10772 | §156 | THE PREFERENCE-DONOR MERGE: cross-region variable reuse is what fills a0-a3, and a call-ar |
-| L10828 | §159 | THE DECLARATION AXIS: conform to byte-truth, and make every guard state its COVERAGE (P30 |
-| L10893 | §160 | THE REACH-15 WAVE HARVEST: an align-1 block move, and the instrument that called it a wall |
-| L10969 | §161 | THE RETRY-WAVE HARVEST: a jump table indexed from zero, and two allocator traps (P30 S47) |
-| L11014 | §162 | S48 WAVE-1 HARVEST (P30, 2026-08-11): the reach-ordered sibling campaign's first 12 target |
-| L11041 | §162a | SHARPENS *(sharpens §161a, §131, §8a-pad, §129a)* |
-| L11070 | §162b | SHARPENS *(sharpens §48-A3, §156, §150, §76)* |
-| L11099 | §162d | SHARPENS *(sharpens §31, §21, §30, §55a)* |
-| L11141 | §162e | NEW |
-| L11143 | §162 | THE LICM PAIR: what makes an address a movable AT ALL, and why the preheader order is the |
-| L11209 | §162f | SHARPENS *(sharpens §42d, §41d, §73, §10)* |
-| L11264 | §162g | NEW |
-| L11266 | §162 | CROSS-JUMP DIRECTION: the surviving copy is always the LATER one, so a BACKWARD `j` into a |
-| L11300 | §162h | SHARPENS *(sharpens §88, §88a, §50-B, §8)* |
-| L11302 | §162 | The cross-jump "CALL veto" is a COUNT law, not a CALL law (BOUNDS §88a; P30 S48, `func_801 |
-| L11368 | §162i | SHARPENS *(sharpens §135, §21, §42, §32)* |
-| L11393 | §162j | SHARPENS *(sharpens §25, §136d-1, §48-B, §46-L2)* |
-| L11422 | §162k | SHARPENS *(sharpens §1-I2, §12, §160d, §21)* |
-| L11485 | §162l | SHARPENS *(sharpens §48-B, §48-C1, §20, §21)* |
-| L11540 | §162m | SHARPENS *(sharpens §36, §158, §148, §153)* |
-| L11542 | §158a | THE FIFTH LEVER IS NOT AN ASM: `do { } while (0)` is a REGION ref-multiplier you MINT (P30 |
-| L11549 | §3-The | law |
-| L11560 | Size | it before you write it (§158 step 1-2, applied) |
-| L11581 | §3-The | wrap BOUNDARY is the dial — and it is indiscriminate |
-| L11587 | §3-Not | a pure dial |
-| L11591 | DIAGNOSTIC | TELL — two faces, one law |
-| L11613 | §162n | NEW |
-| L11646 | §162o | SHARPENS *(sharpens §158, §136-1, §136-6, §79)* |
-| L11705 | §162p | SHARPENS *(sharpens §48-B, §46-L2, §156, §136d-1)* |
-| L11722 | §162q | SHARPENS *(sharpens §30, §30a, §135-2, §136-13)* |
-| L11760 | §163 | S48 WAVES 2-3 HARVEST (P30, 2026-08-11/12): the five that were byte-probed and are actiona |
-| L11828 | §163z | THE UNVETTED REMAINDER (do not cite as law; each needs a dedupe pass) |
-| L11848 | §164 | S48 §163z SKEPTIC PASS (P30, 2026-08-12): 190 claims vetted, 82 banked |
-| L12300 | §16Xy | SHARPENS *(sharpens §136d-3, §37 /s-DEP LATTICE, §135-2, §136-13, §162q)* |
-| L12302 | §3-The | `/s` drop clause is in ALL THREE dependence predicates, so the FIXED-ADDRESS STORE is what |
-| L13636 | §164z | REFUTED CLAIMS: do NOT re-derive these |
-| L13702 | §165 | S48 WAVE-4 HARVEST (P30, 2026-08-12): banked the same day the wave landed |
-| L14353 | §16Z | SHARPENS *(sharpens §37 "the /s-DEP LATTICE", §136-13, §136-14, §16Xy, §162q, `gcc-2.7.2- |
-| L14355 | §3-The | ADDRESS-CLASS TABLE: which load/store pairs even REACH the `/s` clause (P30 S48 wave 4, `f |
-| L14871 | §165z | REFUTED THIS WAVE: do NOT re-derive |
-| L14915 | §166 | THE DESTINATION-TU ORACLE (P30 S48): the seven-attempt bug that was never codegen |
-| L14971 | §167 | S48 WAVE-5/6 HARVEST (P30, 2026-08-12): the saturation point |
-| L16167 | §167z | REFUTED IN WAVES 5/6: do NOT re-derive |
-| L16224 | §168 | THE COUSIN TIER (P30 S49, 2026-08-12): h_seq's exact-hash brittleness, measured — and the |
-| L16276 | §169 | THE MICRO-ADAPT LANE (P30 S49): edit a proven body, don't crack a new one |
-| L16323 | §170 | THE A-PROP WORD-DIFF CARD (P30 S49): the lane that had no owner |
-| L16367 | §171 | THE STALE SEED SYMBOL (P30 S50, 2026-08-13): why §170's 91%→57% was never codegen |
-| L16433 | §171a | THE MECHANICAL A-PROP DRAFT (P30 S50): 256 members banked with no agent in the loop |
-| L16483 | §171b | THREE CARRIES THE MECHANICAL DRAFT NEEDS (P30 S50, banking the top-reach families) |
-| L16516 | §172 | THE ORPHAN-SLOT MECHANISM v2 (P30 S50-Max): the complete frame-residue model for gcc-2.7.2 |
-| L16570 | §172a | TWO DECOMPILATION TELLS FROM THE SAME DIG (P30 S50-Max) |
-| L16586 | §172b | THREE MORE TELLS FROM THE GCC READ (P30 S50-Max, banked on Drew's ask) |
-| L16629 | §173 | THE STORED-PLUMBING RECOVERY RECIPE (P31 T6): symfix-first, per-group isolation, and where |
-| L16665 | §174 | THE ADAPT-CARD WAVE RECIPE (P31 waves A/B, 2026-08-14): prevention beats recovery |
-| L16735 | §175 | A CALLER-SAVED REGISTER PIN CAN BE A CORRECTNESS BUG, NOT JUST A SCHEDULING CHOICE (P31 wa |
-| L16760 | §176a | THE VERIFICATION-LAYER LAWS (P31 overnight, 2026-08-15). What each check can and cannot pr |
-| L16800 | §176b | BATCH-GATING MECHANICS (P31): what changes when N drafts land in ONE .c |
-| L16826 | §176d | THE CONFLICT TABLE MUST BE SEEDED FROM THE TU, AND KEYED PER FILE (P31 S52, 2026-08-15) |
-| L16865 | §176e | SYMBOL IDENTITY IS COMPUTABLE OFFLINE (P31 S52): `tools/reloc_identity.py` |
-| L16922 | §176f | THE DECLARATION FORM IS A MATCHING LEVER, SO RECONCILE TOWARD THE FORM THE MATCH NEEDS (P3 |
-| L16953 | §176g | SIZE A WAVE BY INSTRUCTIONS, NOT BY CARDS (P31 S52 — the adopted doctrine) |
-| L16991 | §176h | THE BATCH-SUBSTITUTION HAZARD MAP (P31 S52): seven holes, three wrong fixes, one law |
-| L16999 | §3-A. | The seven under-reporting holes (all in `gate_main`, all the same shape) |
-| L17017 | §3-B. | Typedef handling — the only strategy that survives contact |
-| L17039 | §3-C. | The limit that remains (recorded, not solved) |
-| L17046 | §3-C2. | RECONCILE BEFORE THE FIRST GATE — a parked draft gets HARDER to bank, not easier |
-| L17069 | §3-D. | The measured cost shape, and what to build next |
-| L17087 | §176i | WHAT A STATIC PRE-GATE CHECK CAN AND CANNOT PROVE (P31 S52, wave Q) |
-| L17119 | §176j | STOPPING A WAVE MID-FLIGHT COSTS THE IN-FLIGHT TAIL (and how much is recoverable) |
-| L17145 | §176j-2 | THE REPAIR PASS, MEASURED (do this instead of resuming) |
-| L17165 | §176k | TWO SELECTOR BUGS THAT SILENTLY SHRINK A WAVE |
-| L17182 | §177 | 🔴 THE EPILOGUE RETURN-DELAY SLOT IS DECIDED BY YOUR SAVED-REGISTER SET, NOT BY SCHEDULING |
-| L17239 | §178 | SIX LEVERS MINED FROM THE WAVE-P JOURNALS (P31 S52), each byte-proven and source-cited |
-| L17251 | §3-A. | THE `$0`-ADD OPAQUE COPY defeats `make_regs_eqv` (func_80033398, 93 ins) |
-| L17267 | §3-B. | A `return ` IS A PRIORITY-1 HARD-REG SET THE SCHEDULER PLACES FIRST (func_8001BE30, |
-| L17280 | §3-C. | SINGLE-SET TEMPS GET THE BIRTHING BOOST (func_8001D3FC, 196 ins) |
-| L17288 | §3-D. | A NARROW TYPE BLOCKS COPY ELISION (func_8001D3FC — new idiom) |
-| L17295 | §3-E. | THE ZERO-OFFSET ALIAS HOLE (func_80037028, 71 ins) |
-| L17304 | §3-F. | `MEM_IN_STRUCT_P` ASYMMETRY IN `true_dependence` (func_80037144, 124 ins) |
-| L17310 | §3-G. | TWO MODELLING TRAPS THAT COST THESE AGENTS SWEEPS OF HUNDREDS OF COMPILES |
-| L17326 | §179 | IDIOMS MINED FROM THE WAVE P/Q JOURNALS (P31 S52, harvest pass) |
-| L17336 | §179-A | 🔴 A LOOP-WALKED POINTER **PARAMETER** HANDS ITS ARGUMENT REGISTER TO THE GIV (9 byte-proof |
-| L17385 | §179-B | 🔴 THE HAND-WRITTEN-ASM TRANSCRIPTION CHECKLIST (maspsx + masked_diff; 10 byte-proofs) |
-| L17435 | §179-C | 🔴 A FUNCTION WITH NO EPILOGUE (falls into a sibling's shared tail) MUST BE FILE-SCOPE `__a |
-| L17486 | §179-D | `gte_stflg` MUST CLOBBER `"$12"` OR THE WHOLE TEMP FILE ROTATES BY ONE |
-| L17506 | §179-E | A `>2*MAX_MOVE_BYTES` BLOCK COPY IS A **STRUCT ASSIGNMENT**, NOT A HAND LOOP |
-| L17532 | §179-F | PINNING A LOOP-WALKED POINTER IS A TOTAL OFF-SWITCH FOR STRENGTH REDUCTION |
-| L17555 | §179-G | 🟡 A PIN CAN **CREATE** A COMBINE `LOG_LINK` AND DELETE AN `andi` (sixth RC-5 channel, n=1) |
-| L17582 | §179-H | A MID-BODY `.global LABEL` PAIR SLICES A BYTE-COMPARABLE FRAGMENT OUT OF A LARGER ROUTINE |
-| L17605 | Considered | and NOT banked |
-| L17622 | §176c | MAIN (SLUS_007.26) CANNOT BE GATED INCREMENTALLY |
-| L17633 | §176 | SEVEN LEVERS FROM THE P31 OVERNIGHT WAVES (2026-08-15): statement order, false regalloc, a |
-| L17639 | §176-A | "SCHEDULE / DELAY-SLOT / LENGTH-DRIFT ±1" ⇒ check STATEMENT ORDER around the call first |
-| L17663 | §176-B | "REGALLOC-PERM, 1-4 instructions off" ⇒ it is usually NOT register allocation |
-| L17709 | §176-C | 🔴 WALL REFUTATION: a hard-register pin CANNOT schedule around a call, because of a genuine |
-| L17735 | §176-D | CSE-class levers used in reverse (two sharpenings of §153 and cse_expr §2) |
-| L17761 | §176-E | Two cheap source spellings, both cc1-probed |
-| L17783 | §176-F | Misdiagnosis triage: four residual verdicts that were lying |
-| L17800 | What | is NOT banked here |
-| L17813 | §180 | THE LEFTOVER-DRAFT HARVEST: RE-VERIFY WHAT YOU ALREADY HAVE BEFORE DRAFTING ANYTHING NEW |
-| L17842 | §180b | WHAT THE PRE-GATE LADDER ACTUALLY FINDS IN A COLD PILE (the shape of integration debt) |
-| L17861 | §180c | WHEN A BINARY'S MASS BAND IS SPENT, THE FLEET-WIDE DRAW IS STRICTLY BETTER |
-| L17879 | §181 | WHAT A WAVE'S GATE ACTUALLY REJECTS (P31 S53, measured on wave R's 45-draft main pile) |
-| L17880 | Only | ONE of 27 blocked drafts was wrong. The other 26 were correct and unbankable. |
-| L17935 | §182 | §177's HONEST NEGATIVE: the epilogue lever cracked 4 of 16, and the `800c3` cluster held |
-| L17949 | §180d | THE `pgrep` BRACKET TRICK PROTECTS THE PATTERN, NOT THE COMMAND LINE |
-| L17961 | §183 | THE DECLARATION-RECONCILIATION PLAYBOOK (P31 S53, measured on 20 byte-verified drafts) |
-| L17962 | §3-18 | of 20 reconciled while keeping the match. The two that did not are mechanism, not effort. |
-| L18032 | §184 | COMMENT-BLINDNESS IS A DEFECT CLASS, NOT A BUG (P31 S53: three tools, one root cause, one |
-| L18060 | §185 | EDIT THE SIDE THAT IS CHEAP TO VERIFY, AND CHECK A TU RETYPE AT ITS USE SITES |
-| L18092 | §186 | CROSS-JUMPING RUNS **AFTER** SCHEDULING, SO NO C-LEVEL BARRIER CAN STEER IT |
-| L18113 | §186b | A NO-SAVE 16-BYTE FRAME IN A LEAF FUNCTION MEANS `s16` LOCALS, NOT A HIDDEN CALL |
-| L18121 | §186c | WHERE A VALUE IS LOADED DECIDES WHICH ALLOCATOR OWNS IT, AND THEREFORE ITS REGISTER |
-| L18138 | §187 | 🔴 "SAME SOURCE" IS NOT "SAME OBJECT": THE SDK BUILD AND THE GAME BUILD DISAGREE ON GTE NOP |
-| L18176 | §188 | 🔴 THE `jr $ra` + `addiu $sp` TAIL IS AN **ASSEMBLER** ARTIFACT, NOT A FRAME SHAPE |
-| L18226 | §189 | FIVE COMPILER LAWS MINED FROM THE WAVE R/S JOURNALS (P31 S53), each source-cited and re-de |
-| L18301 | §190 | THREE PRESCRIPTIONS FROM THE SAME HARVEST (weaker evidence than §189, honestly labelled) |
-| L18338 | §191 | WHAT THIS HARVEST DID **NOT** BANK (4 rejected, 4 narrowed) — recorded so it is not re-der |
-| L18360 | §192 | THE PRE-GATE LADDER WAS MAIN-ONLY, AND NOBODY COULD SEE IT (P31 S54) |
-| L18361 | Three | defects in one call path; the overlay slates that carry most of the wave work were being w |
-| L18425 | §193 | THE WAVE-T HARVEST (P31 S54): 71 index_gap reports -> 9 laws, 5 rejected, 61 already-cover |
-| L18442 | §193-A | The wave card ships only OPEN-set pointers and discards the atlas's BANKED one — `exemplar |
-| L18509 | §193-B | A NARROW CAST OF A WIDE PARAMETER COSTS ONE EXTRA INSTRUCTION WHEN ITS STATEMENT SITS AFTE |
-| L18547 | §193-C | gcc-2.7.2 cross_jump merges the SCHEDULED common SUFFIX only — there is no prefix/head mer |
-| L18581 | §193-D | A COMPILER-GENERATED ARGUMENT COPY IS A `optimize_reg_copy_1` TRIGGER: when the pointer's |
-| L18652 | §193-E | A varying-address (pointer) load is re-emitted once per CSE-LIVE INTERVAL, and naming it i |
-| L18682 | §193-F | §148-A2 — The `threshold -= 3` STAIRCASE: `move_movables` admits a COUNT of invariants, no |
-| L18746 | §193-G | §164-54's "scope to ≥4 arms" bound is byte-wrong — the dispatch-topology oracle goes live |
-| L18807 | §193-H | A pointer-derived base load `*(s32*)(p+K)` is uncacheable across ANY memory write or call |
-| L18847 | §193-I | A DECLARED AGGREGATE LOCAL HAS AN 8-BYTE FRAME STRIDE — CEIL(size,8), NOT size. N ARRAYS T |
-| L18906 | §193-REJECTED | what this harvest did NOT bank (recorded so it is not re-derived) |
-| L18933 | §194 | THE WAVE-U HARVEST (P31 S54): 64 index_gap reports -> 14 laws, 5 rejected, 44 already-cove |
-| L18950 | §194-A | A zero-byte scheduling fence goes AFTER the defining statement to make that computation em |
-| L19016 | §194-B | A `addu $rA,$rB,$zero` copy feeding ≥2 `sh` stores is a SECOND, 16-BIT-DECLARED local — th |
-| L19054 | §194-C | A CALLER-SAVED loop counter proves its live range crosses ZERO calls — so it cannot share |
-| L19117 | §194-D | Declared width of a computed-value local is a sched1 dial (count-neutral) — a replication |
-| L19158 | §194-E | The wave card's `exemplar` is the TARGET ITSELF on 42/73 wave-U and 36/71 wave-T cards — a |
-| L19195 | §194-F | `if ((*p = v = f()) == 0)` is an expand-time pseudo SPLITTER (store_expr's `want_value && |
-| L19268 | §194-G | Reading the integer half of a 16.16 stack aggregate: REGISTER-LIVENESS, not the C spelling |
-| L19311 | §194-H | §164-29's WAR fence runs again at SCHED2 ON HARD REGISTERS: an in-place `v &= K` before a |
-| L19349 | §194-I | §16N+2's magic-per-odd-part ladder has exactly one broken row — read the divisor arithmeti |
-| L19392 | §194-J | Back-to-back identical stores: flow.c's `last_mem_set` deletes the first, and only `volati |
-| L19444 | §194-K | Blind sched1's alias oracle with a second SET of a pointer pseudo — the first zero-byte, n |
-| L19522 | §194-L | §88b and §189-E are BOTH half-wrong, but not the way the candidate says: the compare-const |
-| L19570 | §194-M | A STORE in a CONDITIONAL branch's delay slot proves its C statement DOMINATES the branch — |
-| L19628 | §194-N | §193-D's C dial is misstated: the lever is a SURVIVING CODE_LABEL (a label with a real inc |
-| L19688 | §194-REJECTED | what this harvest did NOT bank (recorded so it is not re-derived) |
-| L19709 | §195 | THE WAVE-V HARVEST (P31 S54): 67 index_gap reports -> 14 laws, 9 rejected, 76 already-cove |
-| L19723 | §195-A | §167-08's "an $aN READ before the jal is scratch" has a byte-proven FALSE-NEGATIVE class: |
-| L19794 | §195-B | A CALL_INSN does not start a basic block in gcc-2.7.2 — so a call-crossing temp can be a L |
-| L19836 | §195-C | A call-argument `%hi/%lo` pair sitting at the block head, far above its `jal`, is a load-d |
-| L19884 | §195-D | §195 — `masked_diff.mask_for` returns 0 for EVERY `j`/`jal` word, so an internal `j` desti |
-| L19952 | §195-E | A 0/1 materialised at a JOIN immediately before the controlling `beqz`/`bnez` proves the s |
-| L20010 | §195-F | fold-const.c:4825 canonicalises a `?:` whose THEN arm is zero (or constant against a non-c |
-| L20062 | §195-G | §NEW — TWO ARMS CALLING THE SAME CALLEE MERGE INTO ONE `jal` UNLESS EACH ARM'S OWN CODE CO |
-| L20110 | §195-H | §165-27g — ON A FIXED-SYMBOL GLOBAL, `extern T D[];` + `D[0]` IS THE CSE RELOAD DIAL, AT Z |
-| L20157 | §195-I | §145(b) AMENDED — the pointer-bump `addiu` is saved by cse, not combine: ANY second SET of |
-| L20222 | §195-J | GTE / PsyQ op CALL-vs-INLINE is a PER-SITE SOURCE FACT, not a TU style — both forms coexis |
-| L20266 | §195-K | At -O2 the §18 array-of-struct lever is a FRAME lever, not a length lever — but only when |
-| L20318 | §195-L | The cse store-re-seed does not cross a JOIN LABEL: per-arm stores + a join read keep the r |
-| L20370 | §195-M | Frame `vars` is a SEQUENTIAL bump-allocation, not a flat sum: §193-I's CEIL(aggregate,8) t |
-| L20419 | §195-N | In a call-bearing chain of N≥2 `if (f(...)) return 1;` tests closed by `return 0;`, the LA |
-| L20466 | §195-REJECTED | what this harvest did NOT bank (recorded so it is not re-derived) |
-| L20512 | §196 | PUT ON THE CARD WHAT THE TREE ALREADY KNOWS: the fleet's declaration consensus (P31 S54) |
-| L20567 | §197 | THE WAVE-W HARVEST (P31 S54): 68 index_gap reports -> 4 laws, 3 rejected, 41 already-cover |
-| L20581 | §197-A | A NARROW SIGNED MEMORY READ FEEDING A CONSTANT `>>` LOSES ITS `lh`, AND THE CURE IS AN ASM |
-| L20619 | §197-B | A REPEATED COMPARE OF ONE VALUE AGAINST ONE CONSTANT IS DELETED BY cse's `qty_comparison_c |
-| L20647 | §197-C | Fix A1 (operand order) cannot move a commutative destination whose .greg conflict set alre |
-| L20692 | §197-REJECTED | §197-REJECTED |
-| L20707 | §199 | THE WAVE-X HARVEST (P31 S54/S55): 63 index_gap reports -> 7 laws, 2 rejected, 56 already-c |
-| L20718 | §199-A | §189-A's asm→source inference is byte-FALSE: an interloper between a split constant's `lui |
-| L20767 | §199-B | A permutation sweep that holds ANY statement fixed is not a sweep: the statement an agent |
-| L20812 | §199-C | A NEGATIVE CONSTANT MULTIPLY ALWAYS TAKES expmed's negate_variant — but whether you ever S |
-| L20860 | §199-D | A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is |
-| L20920 | §199-E | §189-A BOUNDED AND CORRECTED — the discriminator is INSN_PRIORITY, not "is the interloper |
-| L20979 | §199-F | §164-36b — THE TARGET-HEAD FENCE IS A DELAY-SLOT THREAD SELECTOR, AND IT ONLY FIRES WHEN ` |
-| L21033 | §199-G | At TWO case nodes the switch-vs-if oracle is not blind — but the tell is ALL tests positiv |
-| L21088 | §199-REJECTED | §199-REJECTED |
-| L21099 | §200 | THE ALIAS IS THE UNIVERSAL DECLARATION ESCAPE: stop negotiating with the TU's spelling (P3 |
-| L21148 | §201 | THE WAVE-Y HARVEST (P31 S55): 67 gap reports -> 5 laws, 8 rejected, 53 already-covered |
-| L21158 | §201-A | §150-B applies to `decl_prior`'s DEF row: for an overlay-window symbol the banked "definit |
-| L21190 | §201-B | In a narrowed PLUS/MINUS/AND/IOR/XOR expression the destination pointee is INERT — the sig |
-| L21270 | §201-C | §X — A CALL'S OWN DELAY SLOT AND THE UPSTREAM CONDITIONAL BRANCH'S SLOT COMPETE FOR ONE IN |
-| L21321 | §201-D | THE SIGNEDNESS OF A div/mod MAGIC IS DECIDED BY THE STATIC TYPE OF THE DIVIDEND TREE AFTER |
-| L21368 | §201-E | §194-J-2 — The `last_mem_set` deletion window is measured in SOURCE/expand order, not in t |
-| L21424 | §201-REJECTED | eight, the session's highest |
-| L21449 | §202 | THE ALIAS CARRIES A DEFINITION, NOT JUST A DECLARATION: the DEF-SIDE-RETURN wall (P31 S56) |
-| L21486 | §203 | A DEDUPED TYPEDEF MUST PRECEDE EVERY SPLICE POINT, NOT JUST ITS OWN (P31 S56) |
-| L21547 | §204 | THE WAVE-Z HARVEST (P31 S56): 82 gap reports -> 5 laws, 16 rejected, 30 already-covered |
-| L21566 | §204-A | A COMPARE THAT APPEARS BOTH IN A BRANCH'S DELAY SLOT AND AGAIN ON THE FALL-THROUGH IS A JO |
-| L21641 | §204-B | A LOOP COUNT THAT ARRIVES ON THE STACK IS DECREMENTED IN PLACE: a fresh counter local can |
-| L21705 | §204-C | WHEN A LOCAL BUFFER'S ADDRESS IS PASSED TO A CALL, ITS SIZE IS A FACT ABOUT THE CALLEE'S B |
-| L21763 | §204-D | A LOOP-INVARIANT LOAD IS ADMITTED AS A MOVABLE ONLY IF ITS ADDRESS CANNOT TRAP: `local.fie |
-| L21838 | §204-E | `decl_prior`'s `%hi/%lo` ARM HAS NEVER FIRED: the card's promised GLOBAL-TYPE row is 0 of |
-| L21890 | §204-CONFIRMED | 30 reports that the index already answered |
-| L21984 | §204-REJECTED | sixteen, twice the previous record |
-| L22057 | §205 | THE CHAINED ASSIGNMENT IS ITS OWN SCHEDULING DIAL: `*b = *a = v;` moves an argument copy t |
-| L22112 | §206 | THE JTBL-CARVE DRAFTING IDIOM: the bounds check is the entry count, and an EMPTY case owns |
-| L22181 | §207 | THE WAVE ab–ag HARVEST (P31 S58): 278 byte-banked notes → 25 laws, 103 self-reported no-ga |
-| L22202 | §208 | TWO NAMED LOCALS FOR ONE RELOADED EXPRESSION BUY TWO ALLOCNOS — the naming granularity own |
-| L22251 | §209 | THE NARROW LOCAL IS A DIAL IN TWO OPPOSITE DIRECTIONS, AND §194-B's "≥2 `sh` STORES" BOUND |
-| L22328 | §210 | THE SINGLE-BIT MASK IN A BOOLEAN TAIL: `andi K ; sltu $zero,v` vs `srl n ; andi 1` is a ST |
-| L22374 | §211 | HOIST THE LOOP INIT ABOVE THE DOMINATING GUARD: it fills the guard's delay slot AND flips |
-| L22433 | §212 | THE WALKING CURSOR IS COUNTABLE: `*wp++` emits one `addiu` PER STORE, `wp[0..2]` emits one |
-| L22478 | §213 | INDEPENDENT SAME-BASE STORES: THE EMISSION ORDER IS A PERMUTATION OF SOURCE ORDER, AND THE |
-| L22514 | §214 | THE BANKED TWIN MAY BE A MACRO, A DELETED `.s`, OR A SEMANTIC INVERSE — six ways a ≥0.9 si |
-| L22560 | §215 | PIN ECONOMY: the twin's pins are NOT part of the shape, and §17's "pin every call-crossing |
-| L22616 | §216 | DISTINCT ADJACENT SCALARS vs ONE ARRAY: one `lui` per access is the tell, and the array de |
-| L22656 | §217 | DECODING A CALL'S STACK ARGUMENT SLOTS: `sw` at `0x10`/`0x14`/`0x18` are params 5/6/7 **(s |
-| L22682 | §218 | A NARROW TYPE AT THE ABI BOUNDARY COSTS AN IN-PLACE `sll/sra` PAIR — on the RETURN as well |
-| L22711 | §219 | COMPOUND `+=`, FULL ASSIGNMENT, AND AN EXPLICIT TEMP ARE THREE DIFFERENT SCHEDULES OF ONE |
-| L22738 | §220 | THE PARAMETER ITSELF IS A REGALLOC DIAL: use it directly, prefer `s32` to `void*`, and pla |
-| L22778 | §221 | A CONSTANT SHARED BY TWO STORES DIES AT THE CALL WHOSE DELAY SLOT REFILLS ITS REGISTER **( |
-| L22794 | §222 | SWITCH vs IF-CHAIN, PART 3: source arm order IS emission order, a leading EMPTY case buys |
-| L22836 | §223 | READING A `jal` DELAY SLOT: the value in it was produced BEFORE the call, so it is NEVER t |
-| L22898 | §224 | CROSS-JUMP: WRITE THE DUPLICATE, AND READ A SHARED DELAY SLOT AS THE MERGE SIGNATURE (P31 |
-| L22934 | §225 | THREE CONTROL-FLOW SHAPES NO STRUCTURED SPELLING REACHES (P31 S58) |
-| L22977 | §226 | FRAME PADS: FOUR WAYS §162i1/§2429's DEAD-LOCAL LEVER MISFIRES (P31 S58) |
-| L23018 | §227 | TYPE THE SOURCE BY THE **LOAD** WIDTH, NOT BY THE STORE WIDTH (P31 S58) |
-| L23038 | §228 | READING THE DIVIDE, PART N: the off-by-one compare is `% K == 1`, and three more discrimin |
-| L23075 | §229 | THE ADDRESS IS A VALUE: NAMING IT MOVES THE `lui`/`addiu` PAIR — AND §L14410 SAYS THE OPPO |
-| L23124 | §230 | THE ANCHOR PROBE: with `%hi`/`%lo` masked, the surviving `addiu` deltas tell you which ass |
-| L23139 | §231 | TRANSCRIPTION AND SEMANTIC-READ HYGIENE: six ways the listing misleads (P31 S58) |
-| L23180 | §232 | WHEN THE `jr` DELAY SLOT'S STORE STORES THE RETURN VALUE, TIE THEM WITH ONE PSEUDO **(sing |
-| L23216 | §30 | addendum (P31 S58) — the `/s` grant closes a SCHEDULING residual and a REGISTER residual w |
-| L23236 | §194-B | addendum (P31 S58) — BOUND 2 is byte-wrong; see §209 Direction A |
-| L23242 | §176-B | addendum (P31 S58) — the misdiagnosis direction |
-| L23248 | §165-40 | addendum (P31 S58) — the barrier goes at the COPY SITE, not inside the region it protects |
-| L23257 | §164-63 | addendum (P31 S58) — the interposed asm works when the SECOND value is an ordinary assignm |
-| L23266 | §193-A | / §194-E addendum (P31 S58) — where the twin's body actually lives |
-| L23272 | §233 | THE WAVE aa–bg HARVEST (P31 S58b): 1,101 byte-banked notes → 24 new laws, 21 addenda, ~700 |
-| L23316 | §234 | CONSTANT MATERIALISATION: THE STORE LVALUE'S SIGNEDNESS PICKS `addiu` vs `li`/`ori` (P31 S |
-| L23357 | §235 | THE PHANTOM SYMBOL: A MASKED `MATCH` CAN CARRY A RELOCATION THAT DOES NOT EXIST (P31 S58b) |
-| L23386 | §236 | THE DECLARATION LAYER IS THE DOMINANT BANK-BLOCKER: NINE WAYS A BYTE-PERFECT BODY FAILS TH |
-| L23465 | §237 | THE CAST-AT-CALL-SITE DECISION TABLE: WHAT §17a-1 FIXES, WHAT IT CANNOT, AND THE FOUR ESCA |
-| L23520 | §238 | SAME NAME, DIFFERENT FUNCTION: THE OVERLAY-HOMONYM TRAP (P31 S58b) |
-| L23560 | §239 | TWO-STATEMENT INTEGER-SPACE MATERIALISATION REORDERS `la` vs `sll`; AND THE PLUS-TREE OPER |
-| L23594 | §240 | `A + K + B`: WRITE THE CONSTANT **BETWEEN** THE TWO RUNTIME TERMS (P31 S58b) |
-| L23623 | §241 | THE FOLDED SIGN-EXTEND-AND-SCALE: `sll 16 ; sra (16 − log2 scale)` (P31 S58b) |
-| L23652 | §242 | `*k` vs `<>n`: EXPRESSION SPELLING OWNS THE LOAD WIDTH AND THE ROUNDI |
-| L23680 | §243 | SPELL THE CSE BARRIER AS A REASSIGNED POINTER; AND THE `nop`-AFTER-EVERY-`lh` SIGNATURE (P |
-| L23710 | §244 | `volatile` IS A COUNTING INSTRUMENT, A STORE-ORDER PIN, AND MUST SOMETIMES BE ASYMMETRIC ( |
-| L23745 | §245 | THE CALL'S ARGUMENT LIST IS A SCHEDULING SLOT (P31 S58b) |
-| L23792 | §246 | THREE-LIVE-VALUE SCAN LOOPS WANT ADDRESS-FROM-INDEX; AND TWO SYMBOLS CAN SHARE ONE giv (P3 |
-| L23832 | §247 | TWO BRANCHES TO **ONE** LABEL MEANS THE SOURCE CONDITION IS NEGATED (P31 S58b) |
-| L23866 | §248 | SPLIT THE LOAD FROM THE ARITHMETIC: A FUSED `g + K` DENIES THE CALLEE-SAVED REGISTER ITS D |
-| L23890 | §249 | THE SELF-ASSIGN, THE DEAD RE-ASSIGN, AND THE `+ zr` COPY: THREE WAYS TO MAKE A DELETED INS |
-| L23932 | §250 | `%hi/%lo` vs `lw`: THE EXTERN'S ARRAY-vs-SCALAR SHAPE DECIDES ADDRESS MATERIALISATION (P31 |
-| L23969 | §251 | IMMEDIATE-SPELLING TRIGGERS: `+= 0xFF`, FULL-WIDTH `~K`, AND THE TWO-OR SPLIT (P31 S58b) |
-| L23991 | §252 | THE GUARDED PRE-DECREMENT: `(x != 0) && (--x == 0)` (P31 S58b) |
-| L24012 | §253 | POSTFIX `++` vs `+= 1` PICKS A DIFFERENT SCRATCH REGISTER **(single observation — not yet |
-| L24026 | §254 | THE DEAD PARAMETER IS A REGISTER-PLACEMENT TOOL **(single observation — not yet cross-conf |
-| L24038 | §255 | THE EMPTY CASE, PART 2: FOUR TREE SHAPES IT BUYS (P31 S58b) |
-| L24073 | §256 | GOTOS IN THE TARGET'S BLOCK ORDER REPRODUCE SWITCH PLACEMENT WITHOUT SWITCH'S SIDE EFFECTS |
-| L24110 | §257 | THE DEAD-END LEDGER (P31 S58b): ELEVEN LEVERS THAT MEASURED NULL OR BACKFIRED |
-| L24153 | §258 | ADDENDA TO EXISTING SECTIONS (P31 S58b) |
-| L24158 | §30 | addendum (P31 S58b) — THE ANONYMOUS STRUCT MEMBER REF GRANTS `/s`, AND THAT IS A TWO-FOR-O |
-| L24179 | §194-B | / §209 addendum (P31 S58b) — TWO MORE INSTANCES, AND THE BOUND IS NOW REFUTED FOUR WAYS |
-| L24202 | §202 | addendum (P31 S58b) — THE DEF-SIDE ALIAS ALSO CLEARS A RETURN+PARAM DOUBLE CONFLICT |
-| L24213 | §205 | addendum (P31 S58b) — CHAINED ASSIGNMENT: N≥3 IS INNERMOST-FIRST, AND THE TEXT MIRRORS EMI |
-| L24230 | §208 | addendum (P31 S58b) — IT SCALES TO SIX SITES, AND IT HAS AN EXACT INVERSE |
-| L24259 | §210 | addendum (P31 S58b) — THREE CONFIRMED SPELLINGS OF THE BOOLEAN TAIL |
-| L24275 | §211 | addendum (P31 S58b) — INIT PLACEMENT: FIVE MORE DIALS BEYOND THE GUARD HOIST |
-| L24318 | §213 | addendum (P31 S58b) — THREE MORE PERMUTATION LAWS FOR INDEPENDENT SAME-BASE STORES |
-| L24347 | §214 | addendum (P31 S58b) — FOUR MORE WAYS A HIGH-SIMILARITY TWIN LIES |
-| L24383 | §215 | addendum (P31 S58b) — PIN ECONOMY, PART 2: NINE REFINEMENTS |
-| L24435 | §217 | CROSS-CONFIRMED (P31 S58b) — AND THE INCOMING HOME SLOT IS THE MIRROR |
-| L24452 | §220 | addendum (P31 S58b) — THE PARAMETER, NOT A COPY (SEVEN CARDS) |
-| L24477 | §222 | addendum (P31 S58b) — IF-CHAIN vs SWITCH: THREE MORE DISCRIMINATORS |
-| L24495 | §223 | addendum (P31 S58b) — FIVE MORE CONFIRMATIONS, AND THE CONSTANT-IN-`$v0` CASE |
-| L24519 | §224 | addendum (P31 S58b) — CROSS-JUMP MERGES *CALLS*, AND THE DELAY SLOT IS THE DISCRIMINATOR |
-| L24549 | §225 | addendum (P31 S58b) — THE GUARD-CLAUSE FINGERPRINT, AND THREE MORE SHAPES |
-| L24576 | §226 | addendum (P31 S58b) — THE FRAME CATALOGUE: SEVEN MORE LEVERS, AND SLOT ORDER IS DECLARATIO |
-| L24621 | §229 | addendum (P31 S58b) — NAME IT **INSIDE** THE ARM |
-| L24632 | §230 | CROSS-CONFIRMED (P31 S58b) |
-| L24641 | §231 | addendum (P31 S58b) — FOUR MORE WAYS THE LISTING MISLEADS |
-| L24672 | §232 | CROSS-CONFIRMED (P31 S58b) |
-| L24683 | §259 | THE DISCARD LEDGER FOR THE aa–bg HARVEST (P31 S58b): WHAT WAS MINED AND REJECTED, AND WHY |
-| L24722 | §260 | THE §154-A LEADING-ISLAND SPLIT: ONE CONFIG LINE, AND THE ISLAND PEELS FROM THE END (P31 S |
-| L24772 | §260-A | STAGE 2 IS PROVEN, AND THE WHOLE jtbl PIPELINE IS AUTOMATED AT THE GATE (P31 S59, same day |
-| L24808 | §261 | THE -O0 ORACLE: DERIVE THE OPT LEVEL FROM THE TARGET, AND `$fp` IS NOT THE TELL (P31 S59) |
-| L24834 | §261a | THE -O0 FRAME-RELOAD GRAMMAR: reload COUNT disambiguates the C spelling (P31 S59, byte-pro |
-| L24856 | §262 | A LANE'S YIELD IS ONLY A LANE FACT IF IT IS SIZE-MATCHED (P31 S59) |
-| L24886 | §263 | A STOLEN DELAY SLOT WHOSE INSTRUCTION IS AN ARG-REGISTER COPY IS AN ARITY ERROR, NOT A SCH |
-| L24927 | §264 | FOUR TELLS-LANE C RECIPES, EACH DRIVEN TO MATCH (P31 S59) |
-| L24977 | §265 | THE VERBATIM-ASM BANK LANE: A FUNCTION NO -O2 C CAN EVER MATCH BANKS AS A RAW `__asm__` BO |
-| L25039 | §266 | THE INERT-RIDER LAW: A LEVER IS ONLY CITABLE WHEN ITS SOLO REMOVAL BREAKS THE MATCH (P31 S |
-| L25079 | §267 | ADDENDA HARVESTED FROM WAVES at/bh/bk/bl (P31 S59b) |
-| L25087 | ADD-1 | → §231 addendum (also cross-ref from §195-D) — THE MASKED-`jal` "MISSING CALL" ILLUSION |
-| L25096 | ADD-2 | → §42a addendum — A SHARED CONSTANT *NAMED IN A LOCAL* ACROSS A `jal` IS AN ISO→TU DRIFT H |
-| L25108 | ADD-3 | → §236, item 10 — THE UN-DELETED `INCLUDE_ASM` STUB IS A DUPLICATE DEFINITION |
-| L25118 | ADD-4 | → §225-3/-4 addendum — THE MIRROR ROW: VALUE-RETURN IN THE *TAKEN* ARM + TRAILING BARE `re |
-| L25132 | ADD-5 | → §1/I1 addendum — THE INVERTED RANGE TEST: `(u32)(x-lo) >= N` WITH THE ZERO-ARM AS THE TR |
-| L25141 | ADD-6 | → §172b-1 / §264 addendum — SHIFT-AS-TEST: `(x << 16) != 0` TESTS THE LOW HALF WITHOUT TRU |
-| L25150 | ADD-7 | → §256 addendum — THE SINGLE-GUARD GOTO: THEN-BLOCK OUT OF LINE AT THE TAIL |
-| L25162 | ADD-8 | → §245 addendum — THE RE-TIE BARRIER PINS CALL-ARG SETUP TO SOURCE ORDER (construct 6) |
-| L25174 | ADD-9 | → §213-3 / §217 addendum — ADJACENT PRE-CALL FRAME STORES ARE ONE AGGREGATE; THE UNESCAPED |
-| L25184 | ADD-10 | → §237 addendum (arity-evidence paragraph) — AN `la` PAIR ABOVE THE PROLOGUE `sw $ra` IS A |
-| L25193 | ADD-11 | → Cross-confirmation card block (per §259's standing instruction: confirmation, not news) |
-| L25244 | §268 | A `register __asm__` PIN ON A CALL-CLOBBERED REGISTER IS HONORED EXACTLY WHEN THE PINNED R |
-| L25298 | §269 | ADDENDA HARVESTED FROM WAVES ax/bm (P31 S59c) |
-| L25313 | ADD-1 | → §257-8 addendum — THE INTERPOSED ASM'S `__volatile__` IS A PER-SHAPE DIAL, AND THE "NO-O |
-| L25326 | ADD-2 | → §236 addendum (item 1 corollary) — THE SILENT-SPLICE DECLARATION LADDER: WHERE THE TU HA |
-| L25340 | ADD-3 | → §238 addendum — TWO BINARIES CAN EACH DEFINE THE SAME `func_` NAME WITH DIFFERENT BYTES, |
-| L25353 | ADD-4 | → §167-37 addendum — THE FIFTH PRECONDITION, NOW MEASURED: DOWNSTREAM FIELD RE-READS ⇒ NAM |
-| L25370 | ADD-5 | → §267-ADD-6 / §172b-1 addendum — THE SIGN-TEST FACE: `(s16)v < 0` IS `sll 16` + `bgez` ON |
-| L25386 | ADD-6 | → §220-addendum — THE FOURTH FACE: WHEN THE NAMED COPY ITSELF BUYS THE EXTRA CALLEE-SAVED, |
-| L25402 | ADD-7 | → §229 addendum — THE VALUE FACE: A LOOP-STORE CONSTANT SPELLED AS A LITERAL HAS NO SOURCE |
-| L25415 | ADD-8 | → §30a addendum — THE THIRD COLUMN: `*p++` IS ALSO SERIALIZED BUT BURNS `addiu`; ONLY CAST |
-| L25430 | ADD-9 | → §255 "AND CASE-BODY PLACEMENT" bound / §222-addendum-3 — ON A LARGE SPARSE TREE, BODIES |
-| L25444 | ADD-10 | → Cross-confirmation card block (per §259's standing instruction: confirmation, not news) |
-| L25485 | §3-1a. | The §266 sweep — every solo-lever A/B run for this batch |
-| L25518 | §270 | The A-prop 0-bank anatomy: a byte-correct body still needs FOUR layers to agree (P31 S59) |
-| L25536 | §271 | Ordinal IMM pairing: text order is NOT emission order; emit CANDIDATES, let the oracle pic |
-| L25558 | §272 | The `(void)`-decl + empty-call wall: K&R the DEFINITION, not just the decls (P31 S59) |
-| L25578 | §273 | A standalone compile is the WRONG oracle for a TU-destined draft (P31 S59) |
-| L25593 | §274 | ADDENDA HARVESTED FROM 18 WAVES (P31 S60): 315 candidates, 255 already covered, 21 sharpen |
-| L25599 | ADDENDUM | to §179-C — the `.type NAME, @function` requirement |
-| L25646 | ADDENDUM | to §134 — a typedef defined BELOW the splice point is stripped anyway |
-| L25676 | ADDENDUM | to §179-D (GTE macro reference family) — `gte_SetRotMatrix`/`gte_SetTransMatrix` bodies |
-| L25702 | ADDENDUM | to §82 — struct copies must stay MEMBER-WISE, not block-moved, to match a spill-slot save |
-| L25740 | ADDENDUM | to §136d-1 (RC-12, the `$0`-add / opaque-copy family) — two symptoms beyond "compare reads |
-| L25779 | ADDENDUM | to §20 — a global declared as `T *` may itself BE the array base, not a pointer to derefer |
-| L25808 | ADDENDUM | to §1-I5 |
-| L25873 | ADDENDUM | to §164-51 |
-| L25889 | ADDENDUM | to §176-F5 |
-| L25918 | ADDENDUM | to §225 |
-| L25963 | ADDENDUM | to §224 — CROSS-JUMP: THE DUPLICATE CAN BE A PLAIN STORE, NOT ONLY A CALL |
-| L25997 | ADDENDUM | to §164-64 — AN EMPTY CLOBBER ON AN ARGUMENT REGISTER CAN BE THE DELIBERATE FIX, NOT JUST |
-| L26028 | ADDENDUM | to §244 — THE COMPILER BARRIER, NOT `volatile`, BLOCKS A STORE→LOAD HOIST THROUGH A POINTE |
-| L26059 | ADDENDUM | to §172b-1 — TWO PLACEMENT DIALS THE PROMOTION LAW DOESN'T NAME: NARROW THE COUNTER'S DECL |
-| L26106 | ADDENDUM | to §229 — A POINTER'S NUMBER OF USES DECIDES WHETHER ITS ADDRESS FOLDS OR SURVIVES A CALL |
-| L26151 | ADDENDUM | to §172b-4 — THE PLAIN CAST-DIVISION ALREADY PRODUCES THE PATTERN; DON'T HAND-ROLL THE BIA |
-| L26181 | ADDENDUM | to §8 — WHEN `INCLUDE_RODATA` NEEDS A STANDALONE `.s` YOU CAN'T CREATE, CARRY THE FRAGMENT |
-| L26224 | ADDENDUM | to §226 — A DEAD LOCAL SCOPED TO A NESTED BLOCK BUYS A MID-FUNCTION `addiu sp` PAIR, NOT A |
-| L26263 | ADDENDUM | to §172a — RE-READING MEMORY (NOT NAMING A TEMP) IS WHAT KEEPS AN INCREMENT'S DELAY-SLOT F |
-| L26294 | ADDENDUM | to §225 / §256 — A GOTO TO A SHARED SET-POINT PREVENTS IF-CONVERSION FROM COLLAPSING A LAT |
-| L26336 | ADDENDUM | to §211 — AN IN-LOOP ACCUMULATOR WANTS A CLOSED-FORM EXPRESSION WHEN THE TARGET REMATERIAL |
-| L26371 | §275 | THE LEFTOVER-REGISTER READ |
-| L26411 | §276 | MIXED ADDRESS-EXPRESSION SPELLING FOR ADJACENT RELOCATABLE SYMBOLS IS A CSE-UNIFICATION DI |
-| L26520 | §277 | RETURN-TAIL C SPELLING PICKS THE DELAY-SLOT-FILL vs TRAILING-MOVE TOPOLOGY, AND A NARROWER |
-| L26584 | §278 | ADDENDA HARVESTED FROM WAVE cf (P31 S60): 34 candidates, 13 already covered, 8 sharpenings |
-| L26592 | ADDENDUM | to §74 (func_800D0E30, resident) |
-| L26628 | ADDENDUM | to §172b-4 (func_80185054, ov_SC03_097) |
-| L26666 | ADDENDUM | to §265 (func_8017DC80, ov_SC07_002) |
-| L26705 | ADDENDUM | to §17 (func_800CB794, md_MAIN_036) |
-| L26753 | ADDENDUM | to §162p (func_8017C120, ov_MAIN_012) |
-| L26787 | ADDENDUM | to §20 (~L1947) (func_80186AD0, ov_SC06_032) |
-| L26817 | ADDENDUM | to §164-56 (func_8017F644, ov_SC04_005) |
-| L26852 | ADDENDUM | to §237 (func_8017F7FC, ov_SC03_092) |
-| L26881 | §279 | A `do/while (p < end)` LOOP UNDER AN ENTRY GUARD: the guard decides the compare, not the l |
-| L26882 | §NNN | A DO-WHILE'S GUARD AND LATCH MUST REPEAT THE SAME BOUND EXPRESSION, NOT SHARE ONE LOCAL: T |
-| L26915 | §280 | THE CURSOR'S DECLARED TYPE PICKS `sltu` vs `slt`: a `T*` bound test is UNSIGNED by C rule, |
-| L26916 | §NNN | A LOOP CURSOR'S C TYPE (POINTER vs PLAIN INTEGER) SELECTS `sltu` vs `slt` FOR ITS BOUND TE |
-| L26949 | §281 | GROUP COPY-THEN-RMW BY OPERATION KIND, NOT FIELD BY FIELD: sched1 does the interleaving, t |
-| L26950 | §NNN | A DEPENDENT COPY-THEN-RMW BLOCK MUST BE SOURCE-GROUPED BY OPERATION KIND, NOT BY FIELD, AN |
-| L26995 | §282 | gcc's OWN LOOP REVERSAL PUTS THE COUNTER INIT AFTER THE HOISTED MOVABLES — a position no h |
-| L26996 | §NNN | WRITE THE UP-COUNT LOOP: gcc's OWN REVERSAL PRODUCES A COUNTER-INIT INSTRUCTION THAT LANDS |
-| L27033 | What | I could not verify |
-| L27080 | §283 | ADDENDA HARVESTED FROM THE 36-WAVE BATCH (P31 S60): 1,216 candidates, 859 already covered, |
-| L27090 | ADDENDUM | to §164-75 — the fold-reassociation law also fires at a variable's INITIALIZER, not only a |
-| L27116 | ADDENDUM | to §21 — the `bltz`+`slti` (or N-separate-compares) signed-range-split bullet is now CONFI |
-| L27162 | ADDENDUM | to §202 — the DEF-SIDE ALIAS also resolves a function-vs-DATA-symbol identifier clash, not |
-| L27185 | ADDENDUM | to §22 (`volatile`-qualified-global reload lever, cookbook ~L1922) — for a NON-constant, s |
-| L27204 | ADDENDUM | to §195-E — a goto-ladder's STORES must sit AT the labels, after the gotos, not inline bef |
-| L27266 | ADDENDUM | to §195-N — a GNU statement-expression slider must sit INSIDE the conditional arm's value |
-| L27323 | ADDENDUM | to §176-B2 — in a micro-function with no long/short lifetime asymmetry, BOTH contending ps |
-| L27370 | ADDENDUM | to §199-G — A `default:` LABEL GROUPED ONTO THE LAST CASE REMOVES THE `j default` TAIL, EV |
-| L27439 | ADDENDUM | to §220 — REFERENCING THE RAW PARAMETER (NO NAMED COPY, NOT EVEN A PIN) LETS THE CALLEE-SA |
-| L27497 | ADDENDUM | to §252 — a `>=0`/`<0` split on an unconditionally-decremented value needs the POSTFIX ope |
-| L27524 | ADDENDUM | to §215 — FIFTH SHAPE: reused mask constants across two call-free merge sites each get the |
-| L27607 | What | I could not verify |
-| L27678 | Harness-defect | flags |
-| L27771 | ADDENDUM | to §167-40 (func_8017E2CC, ov_SC04_015 — wave dg) |
-| L27791 | ADDENDUM | to §20's cross-jump EXPLOIT bullet (func_8017E360, ov_SC05_007 — wave dg) |
-| L27805 | ADDENDUM | to §87 (func_801815F4 ov_SC06_032; corroborating func_801840DC ov_SC05_017, func_80189C68 |
-| L27824 | ADDENDUM | to §153 / §236-5 (func_801A419C, md_SC07_003 — waves di and dl, corroborating; refutes a c |
-| L27844 | ADDENDUM | to §263 (func_801E83AC, md_SC04_029 — wave dj) |
-| L27858 | ADDENDUM | to §265 (func_8017D878, ov_SC03_107 — wave dj; corroborated by a REJECTED, contradicted ca |
-| L27872 | ADDENDUM | to §6 (func_801811F0, ov_SC03_102 — waves dj and dl, corroborated by a self-reported "noth |
-| L27886 | ADDENDUM | to §195-G (func_80183BB0, ov_SC05_001 — wave dj) |
-| L27914 | ADDENDUM | to the zero-byte-asm-slider family (§47 / §148-C / §153) (func_800CB874, md_MAIN_040 — wav |
-| L27932 | ADDENDUM | to §194-B (func_8017EB34, ov_SC03_117 — wave dk; distinct from the §74 co-pinning finding |
-| L27964 | ADDENDUM | to §74 (func_8017EB34, ov_SC03_117 — counter/clamp variant; wave dj, corroborated by dk/dl |
-| L27984 | ADDENDUM | §37 — merged into the §153/§236-5 entry above (func_801A419C, wave dl) |
-| L27992 | ADDENDUM | §6 — merged into the §6 entry above (func_801811F0, wave dl) |
-| L28000 | ADDENDUM | to §238 (func_80182CB4, ov_SC02_000 — wave dl) |
-| L28018 | ADDENDUM | to §137a (func_801684B4, ov_MAIN_012; corroborated independently by func_80189E68, func_80 |
-| L28034 | ADDENDUM | to §8c / §88d (func_8016AB6C, ov_MAIN_012 — wave dm) |
-| L28048 | ADDENDUM | to §73 / §30#2 (func_800D1984, resident — wave dm) |
-| L28064 | What | I could not verify |
-| L28084 | ADDENDUM | to §174 Law 4 (func_8017E9A8, ov_SC06_015) |
-| L28124 | ADDENDUM | the zero-emission-asm family gains a REF-SLIDER PLACEMENT LAW and a paired RESTORER (func_ |
-| L28176 | From | ck + cl + cm |
-| L28182 | ADDENDUM | §NNN — sharpens §55a / §164-37 / §165-28 (switch-vs-tree cluster): A SHAPE THAT LOOKS LIKE |
-| L28219 | ADDENDUM | §NNN — sharpens §167-13's boundary: CHAINING TWO IDENTICAL SIDE-BY-SIDE STORES INTO ONE C |
-| L28252 | ADDENDUM | §NNN — sharpens §162a3/§60b: A `sll $v0,16 / sltiu $v0,1` ZERO-TEST OF A JUST-DECREMENTED |
-| L28285 | ADDENDUM | §NNN — sharpens §37/§124 (unspecified-parameter-list family): DERIVE A CALLEE'S ARITY LOWE |
-| L28318 | ADDENDUM | to §5a (func_80181F74, ov_SC03_112, wave cn) |
-| L28368 | ADDENDUM | to §265 (func_8017E26C, ov_SC04_016, wave cn) |
-| L28406 | ADDENDUM | to §42b (func_8018247C, ov_SC07_002, waves cu + cw) |
-| L28437 | ADDENDUM | to §199-F family (func_8017EFB0, ov_SC02_021, wave cu) |
-| L28492 | ADDENDUM | to §195-E (func_800CFC1C, md_MAIN_003, wave cv) |
-| L28537 | ADDENDUM | to §215 addendum (func_800CB2C8, md_MAIN_033, waves cv + cw) |
-| L28593 | ADDENDUM | to §236 item 4 (func_8017D268, ov_SC04_006, wave cw) |
-| L28622 | What | I could not verify |
-| L28654 | Harness-defect | flags (not idioms — flagged for the operator) |
-| L28695 | ADDENDUM | to §250 (func_8017D7CC, ov_SC03_115 — cx/cy/cz/dr) |
-| L28740 | ADDENDUM | to §225 (func_8017E190, ov_SC03_115 — cx/cy/cz) |
-| L28793 | ADDENDUM | to §45-A (func_8017F6A4, ov_SC02_016 — cy/cz) |
-| L28837 | ADDENDUM | to §249 (func_80182ED4, ov_SC04_004 — dp/dr/dt) |
-| L28882 | ADDENDUM | to §199-A (func_801816FC, ov_SC02_005 — dp/dr/dt) |
-| L28928 | What | I could not verify |
-| L28971 | Harness-defect | flags |
-| L29033 | §284 | COMBINE CAN REASSOCIATE TWO SEQUENTIAL BITWISE-AND MASKS INTO ONE AGAINST THE PRE-MASK VAL |
-| L29037 | §285 | PRE-INITIALIZING A VARIABLE WITH A SHARED CONSTANT BEFORE A BRANCH MAKES BOTH ARMS OF THE |
-| L29041 | §286 | FOLD A STATEMENT'S SIDE EFFECT INTO A COMMA-EXPRESSION IN AN ARGUMENT POSITION TO PLACE IT |
-| L29045 | §287 | A STACK-FRAME HOLE BELOW TWO ADDRESS-TAKEN AGGREGATE LOCALS IS A LEADING PAD MEMBER OF ONE |
-| L29049 | §288 | A REGISTER PIN DECLARED UNINITIALIZED AND ASSIGNED ONLY AT ITS LATE, SOLE USE STILL FORCES |
-| L29053 | §289 | an array local's address-taken base keeps every element's store alive, even though only on |
-| L29057 | §290 | A SINGLE STRENGTH-REDUCED GIV CAN DRIVE STORES TO SEVERAL DISTINCT RELOCATABLE SYMBOLS, EA |
-| L29061 | §291 | THE DELAY-SLOT FALSE-VALUE: A CONDITIONAL BRANCH'S ZERO ARM MUST BE A FALL-THROUGH-ADJACEN |
-| L29065 | §292 | DECLARING A SYMBOL UPSTREAM OF AN ALREADY-BANKED SIBLING THAT RELIES ON THAT SYMBOL'S IMPL |
-| L29068 | §293 | THE "WHOLE-OBJECT GATE NEEDS EVERY SIBLING" LAW, WRITTEN PROPERLY: IT IS THREE LAWS, AND T |
-| L29118 | §294 | ADDENDA HARVESTED FROM THE S61 GEN0/MAXTOK/MAIN/DEEPSEEK BATCH (waves ab8/ab16/ab24/ab32 · |
-| L29129 | ADDENDUM | to §127 — the -O0 constant-offset fold keys on the MEMBER-ACCESS tree shape, not on the in |
-| L29157 | ADDENDUM | to §261a — FOUR MORE -O0 DIALS BEYOND THE RELOAD COUNT (boot.c + md_MAIN_011/003, wave m0a |
-| L29207 | ADDENDUM | to §264-3 — the explicit entry copy's BOUND: required exactly when the RAW value must outl |
-| L29227 | ADDENDUM | to §172b-1 (counter-type dial) — the sll's SOURCE REGISTER is the placement discriminator |
-| L29239 | ADDENDUM | to §276 — the SHARE direction: spell the second adjacent symbol RELATIVE to force ONE anch |
-| L29255 | ADDENDUM | to §31's density-dummy dial (L2460/L2497) — the dose is TWO refs, and the dummy must sit w |
-| L29272 | ADDENDUM | to §282 — the ADDRESS-GIV face: write the walked address INLINE so strength reduction birt |
-| L29295 | ADDENDUM | to §253 — SECOND byte-proven card (upgrade from single-observation), and the placement fac |
-| L29316 | ADDENDUM | to the L1800 anchor-steer bullet — a DERIVED-POINTER local silently flips the merged giv's |
-| L29339 | ADDENDUM | to §31's asm→layout inference — TWO WIDTH-PAIR DISCRIMINATORS (same offset, different widt |
-| L29360 | §295 | THE KERNEL-TRAP STUB: §81's jr-DETECTOR WITHOUT A TABLE IS A PsyQ SYSCALL TRAMPOLINE — ROU |
-| L29415 | §296 | THE FRAME CHECK OUTRANKS THE ATLAS LEVER: READ PROLOGUE/EPILOGUE BEFORE DRAFTING ANY C — A |
-| L29458 | §297 | ONE GIV SERVING MIXED-WIDTH LOADS *AND* A STORE NEEDS STRUCT-MEMBER SPELLING; CAST/INDEX S |
-| L29501 | §298 | THE SHARED-TAIL POSITION DIAGNOSTIC: A FOLDED TAIL *BETWEEN* SWITCH ARMS MEANS PER-ARM DUP |
-| L29526 | §299 | TWO INDEPENDENT EXTRACTION CHAINS EMIT CONTIGUOUSLY INSIDE ONE EXPRESSION; ONLY A STATEMEN |
-| L29561 | §300 | S61 DISTILL BATCH NOTES (waves ab8/ab16/ab24/ab32 · g0a–g0f · m0a · ds1/ds2 · m0b) |
-| L29630 | §301 | AN INTERNAL `j` CARRIES `R_MIPS_26 .text`: rtu/match_one "MATCH" COULD NOT SEE WHICH LABEL |
-| L29678 | §302 | A RED BINARY IS A DRIFTED SPEC, NOT A MYSTERY: THE THREE CARVE-STATE INVARIANTS AND HOW TO |
-| L29722 | §303 | MODULE ISLAND TABLES: DERIVE THE PADS AT BUILD TIME, PEEL NOTHING — THE §154-A/§260 "islan |
-| L29758 | §304 | SELF-DEFINING RODATA: WHEN A FUNCTION'S `.s` IS THE ONLY OWNER OF THE DATA IT REFERENCES, |
-| L29781 | §305 | "CARVE-REFUSED" AT GATE TIME IS THREE NAMED, DETERMINISTIC CLASSES — NONE OF THEM A CARVE |
-| L29833 | §306 | A HAZARD `nop` IN FRONT OF A DIV-RESULT STORE IS A STATEMENT-ORDER DEFECT: THE INDEPENDENT |
-| L29860 | §306a | T4 DISTILL ADDENDA (P31 S62; four byte-proven refinements to existing laws, verified again |
-| L29898 | §307 | THE BRUTE-FORCE-THE-STATEMENT-ORDERS LEVER HAS A BOUND: A FAN-OUT COPY'S PRIORITY IS SCHED |
-| L29942 | §308 | A NAIVE FINAL `goto` DELETES THE TARGET'S `j`+`nop`: SPELL THAT EDGE AS A TAUTOLOGICAL `if |
-| L29971 | §308a | A TWO-INSTRUCTION ARM STUB LAID *BEFORE* THE OTHER ARM AND REACHED ONLY BY A TRAILING `j` |
-| L30005 | §309 | A FRAME-ADDRESS EQUIVALENCE RIDES *THROUGH* A SKIPPABLE CONDITIONAL: POST-`if` STORES FOLD |
-| L30045 | §310 | A TWO-OPERAND `subu`'s DESTINATION TIES ONLY TO THE OPERAND THAT IS BLOCK-LOCAL: SHARE *ON |
-| L30076 | §311 | A JOIN-BLOCK STORE CAN SWALLOW AN ARM'S LOAD-DELAY `nop`: WHEN ONE ARM'S VALUE COMES FROM |
+| L2769 | §41a | v3.1: the def-side wall was ~71% TOOL-shaped — the five measured defects + the laws that d |
+| L2824 | §41b | T7 execution: the object-only probe OVER-counts BANKABLE by two link/rodata classes (Phase |
+| L2854 | §41c | T7-M2: the ×134 def-side-wall sweep via per-sibling RE-reconcile (Phase 25, 2026-07-10; 4, |
+| L2873 | §41b | addendum — M4 "reconcile_decls" tier is ALSO a probe over-count: 0/8 mechanical (Phase 25 |
+| L2893 | §41d | `void`→`s32` is NOT always byte-neutral: gate the RAW draft FIRST (Phase 26 session 6, byt |
+| L2915 | §42 | The F-band ≤28 regalloc crack wave: register-pin/DENSITY levers beat the permuter (Phase 2 |
+| L2968 | §42a | addendum — wave 2 (residuals + 29-100 band): iso-MATCH ≠ real-TU bank, the memcpy→struct-a |
+| L3009 | §42b | addendum — wave 3 (Max, 2026-07-10c): THE STALE-OBJECT GATE TRAP + the read-global `&`-cas |
+| L3048 | §42c | addendum — wave 3 (Max orchestrator + CORRECTED Ultracode fan-out, 2026-07-10c): the real- |
+| L3097 | §42d | addendum — wave 4 (rtu_match fan-out over the mapped frontier, 2026-07-10c): 24/26 MATCH, |
+| L3136 | §42e | propagating a CRACK ×134: the def-finder bug + the byte-drift residual (the "remap-fail" m |
+| L3210 | §43 | The K&R s16-param definition DISSOLVES the "narrow-param wall" for by-value register args |
+| L3257 | §44 | The Phase-25 cheap-Opus giant batch: 5 structural levers + the §43 extension (2026-07-11, |
+| L3313 | §45 | The flagship `func_80133CD4` crack (399 ins ×134): the merged-variable permutation-breaker |
+| L3328 | §46 | The `func_80178D40` crack (890 ins ×134, the heaviest core in the game): four LOOP-STRUCTU |
+| L3380 | §47 | The live-length SLIDER: splitting a global.c allocno-priority TIE with one zero-byte asm ( |
+| L3420 | §48 | The 12-core jr crack wave: the ALLOCNO-PRICING dials and the EBB rule (Phase 26 session 8, |
+| L3428 | §3-A. | ALLOCNO-PRICING DIALS — move a value into the register you want, byte-neutrally |
+| L3459 | §3-A4 | SINK THE CONSUMER CALL INTO THE ARMS (the inverse of A1; `func_8016AB6C`, byte-proven) |
+| L3483 | §3-B. | THE EBB RULE — the general form of §46-L2 |
+| L3499 | §3-C. | TYPE- AND SHAPE-DRIVEN CODEGEN (the C type literally selects the addressing mode) |
+| L3523 | §3-D. | THE CROSS-JUMP RATCHET (the sharpest new trap — `func_80131340` L-C) |
+| L3533 | §3-E. | Meta |
+| L3542 | §49 | The LUID DIAL: a zero-byte SCHEDULING dial (the sched.c analogue of §47) — `func_8017A4AC` |
+| L3591 | §50 | Refinements that BOUND §47/§48 (from the `func_80135EB0` wall, 21→6; Phase 26 session 8) |
+| L3645 | §51 | TOOLING INTEGRITY: the silent skip, and how to hunt it |
+| L3651 | §51a | The bug class |
+| L3667 | §51b | Why the byte-gate cannot save you |
+| L3677 | §51c | THE METHOD (do not audit by reading the regex) |
+| L3692 | §51d | THE LAWS |
+| L3754 | §51e | The false-wall pipeline (why this is not just hygiene) |
+| L3770 | §51f | Checklist for any new corpus-scanning tool |
+| L3784 | §51g | When the thing you are scanning has a GRAMMAR, parse the grammar (`tools/cdecl.py`) |
+| L3928 | §52 | The WALKER-FAMILY skeleton: 6 regalloc-order levers + a deeply-characterized intrinsic wal |
+| L3939 | §3-The | 6 levers (the "walker-family skeleton" — apply to the 12 siblings; levers 1-5 retire ~half |
+| L3960 | §3-Why | the wall is (probably) intrinsic |
+| L3974 | §52a | The regalloc sibling wave: new levers + two new wall classes (cheap-Opus applying §52, 202 |
+| L4012 | §52b | Sibling wave 2: more de-pin levers, a third wall class, and the match_one→whole-binary gap |
+| L4043 | §53 | SWEEP A FAMILY WITH THE TOOL ITS EXEMPLAR NEEDED: the jr/switch carve, and how omitting it |
+| L4048 | §3-The | case |
+| L4060 | §3-Why | 0/8 was structural, and predictable from two words |
+| L4077 | §3-The | rule |
+| L4093 | §3-The | meta-lesson (R35, and why this one is expensive) |
+| L4108 | §55 | Core-crack wave levers + the GATE-ORCHESTRATION law (Phase 29 T3, 13-agent ultracode wave, |
+| L4113 | §55a | New byte-proven levers (each from a banked or near draft) |
+| L4137 | §55b | THE GATE-ORCHESTRATION LAW (3 traps, ~3.5h lost; all recovered, 0 data lost) |
+| L4156 | §55c | Sizing the propagate: a TARGETED propagate is ~4 min/core, and "it's slow" was a BROKEN-TR |
+| L4178 | §54 | `--fix-def-sig`: the member's CANONICAL DECLARATION is a build step too (tiny-IMM mega-poo |
+| L4202 | §56 | Banking a hand-drafted GIANT into its exemplar TU: self-contained draft vs live-TU decls, |
+| L4247 | §56b | PROPAGATING an h_seq giant: the exemplar's externs MUST be fleet-canonical, not the draft' |
+| L4271 | §57 | The SELF-decl normalize: the sibling's OWN caller declares the templated fn divergently (t |
+| L4318 | §57a | Two NSD corrections + the SURGICAL-ONLY law + the honest broad-sweep yield (Phase 29, 2026 |
+| L4358 | §58 | match_one MATCH ≠ BANK: the four blind spots + the crack-wave reconcile-before-bank law (P |
+| L4392 | §59 | Three h_seq sweep-residual classes match_one/the-exemplar-bank don't reveal (Phase 29 crac |
+| L4422 | §60 | Classify the residual, don't rank it: the deterministic residual→class classifier and what |
+| L4446 | What | it measured — the whole open backlog, byte-grounded |
+| L4465 | §3-Two | corollaries worth remembering |
+| L4478 | §3-The | parallel-probe race this surfaced |
+| L4487 | §60a | What the first DIRECTED grinder run exposed (Phase 29 Task-13B, 2026-07-21) |
+| L4525 | §60b | The plateau autopsy's verdict: a `partial` drift is a WRONG DRAFT, not a missing transform |
+| L4560 | §61 | Task 14: the gate ladder's missing stage is the ARITY pre-pass, and it is TU-side not draf |
+| L4621 | §61a | The Task-5 wave: 11/12 MATCH, 0 banked — three DISTINCT integration walls, each now named |
+| L4673 | §61b | The jtbl gate stage: built, and the ORDERING law it exposed (Phase 29 Task-14 stage 4, 202 |
+| L4728 | §61c | The jtbl bank is INCREMENTALLY valid and CLEAN-INVALID (Phase 29, 2026-07-21) — the blocki |
+| L4794 | §61d | The undo was eating the tree: two tools, one defect, invisible to the byte-gate (Phase 29, |
+| L4848 | §62 | The jtbl RECONCILE must also follow the carve: the post-carve draft reconcile (`harvest_ve |
+| L4892 | §63 | The fresh-138 DEF-SIDE blocker: fix the HEADER decl, not the draft (`fix_header_decl.py`, |
+| L4923 | §64 | The §20 type-lift's three laws: fold the tagged typedef, check VISIBILITY, and strip only |
+| L4972 | §64a | VARIANT types: UNIQUIFY the camps, do not reconcile them (`uniquify_type.py`, Phase 29 SES |
+| L5015 | §63 | UPDATE (Phase 29 SESSION-14) — `fix_header_decl`'s "SAFE" verdict is FLEET-BLIND; it MUST |
+| L5030 | §65 | The stranded-draft recovery: BLAST-RADIUS TIERS, and the per-overlay de-macroize that refu |
+| L5045 | §65a | The blast-radius taxonomy (makes §61's law structural instead of remembered) |
+| L5060 | §65b | The escape: de-macroize the instantiation, don't touch the shared header |
+| L5096 | §65c | `rtu_match` MATCH → bank held 13/13 on self-decl, but broke on the FIRST callee-decl case |
+| L5106 | §65d | Existing-ladder baseline, measured (do this before building a recovery stage) |
+| L5116 | §65e | Two oracles, and the disagreement is the finding (R34 in practice) |
+| L5133 | §65f | The de-macroize lever's BOUNDARY, measured: byte-neutral 14 times of 15, and the 15th is w |
+| L5154 | §65g | Where the cheap levers STOP: the local-type and in-TU-self-decl classes did not yield |
+| L5174 | §66 | Exercise a banking driver's SUCCESS path before pointing it at a wave: the free re-bank te |
+| L5196 | §66a | The widest write in a pipeline is the one most likely to be UNDECLARED |
+| L5215 | §66b | A metric parsed out of another tool's prose goes NULL silently when the label changes |
+| L5232 | §66c | Before a wave, verify the FUEL exists; an "already attempted" set built from the wrong dir |
+| L5260 | §66d | The permuter⇄reader loop: alternate a random search with a byte-verified idiom, and let `r |
+| L5295 | §66d-1 | What transfers between giants is the LOOP, not the PIN |
+| L5304 | §66d-2 | Two operational sharp edges |
+| L5315 | §66d-3 | Read the ILS per-cycle SERIES, not its final best: a repeated score and a still-falling on |
+| L5330 | §67 | The arg-copy PLACEMENT lever: launder a parameter into a fresh pseudo AT the statement whe |
+| L5420 | §67a | Run the symbol-set guard BEFORE you pay for a gate (`tools/symcheck.py`, Phase 29 SESSION- |
+| L5453 | §66d-4 | "ILS converged" means converged FOR THAT WEIGHT PROFILE, not a floor (amends §66d-3; Phase |
+| L5506 | §66d-5 | `residual_class`'s "structural ⇒ permuter CPU is waste" is WRONG for schedule permutations |
+| L5539 | §68 | A comment-only line halted the extern scan, and the skip label blamed the type cap (Phase |
+| L5584 | §69 | How to attack a behemoth: map it, don't draft it (Phase 29 SESSION-18, `func_80183814`, 5, |
+| L5634 | §70 | The giv-init base register: walk the PARAMETER, not a copy of it (Phase 29 SESSION-18, `fu |
+| L5675 | §71 | Before mapping a giant, look for an already-matched SIBLING beside it (Phase 29 SESSION-18 |
+| L5741 | §72 | A `register __asm__` pin is a PREFERENCE, not a reservation (Phase 29 SESSION-18, `func_80 |
+| L5765 | §3-The | honest fix was source-level and cheap |
+| L5775 | §3-Giv | record order (the §70 family) |
+| L5781 | What | is left, and what is byte-recorded as SPENT |
+| L5798 | §73 | A def-side self-decl conflict has TWO axes: RETURN (fleet widen, T2) and PARAMS (casts at |
+| L5837 | §74 | Auditing a pinned draft: the §72 hazard is CALLER-SAVED pins spanning a call, and only the |
+| L5881 | §75 | A propagation cap is usually a MINORITY-SPELLING SOURCE OVERLAY, not a wall: census the ca |
+| L5940 | §75a | The exclusion classes, enumerated with named causes (Phase 29 SESSION-19, the 134-binary ` |
+| L5963 | §75b | A body's preamble can carry `#define`s, not just `extern`s; extraction lifts only the exte |
+| L6012 | §75c | Class-B's remedy is the FULL §17a-1 PAIR (decl **and** call-site cast); a decl-only fix mo |
+| L6043 | §76 | The allocno CLASS (local vs global) is the dominant regalloc lever, and C reaches it ONLY |
+| L6052 | §3-The | mechanism, with citations |
+| L6072 | §3-The | attribution primitive (use this before calling anything a scheduling residual) |
+| L6079 | §3-Two | diagnosis traps this function proved |
+| L6089 | Practice | Practice |
+| L6099 | §77 | Every extraction tool carries a NARROW hard-coded preamble set; anything outside it silent |
+| L6139 | §3-The | CANDIDATE gate and the REAL gate need DIFFERENT preambles — keep the difference out of the |
+| L6189 | §78 | A LENGTH drift can be a register grant in disguise; and `fold` never leaves a literal firs |
+| L6195 | §3-The | drift was an allocation decision, not missing code |
+| L6226 | §3-The | economics |
+| L6235 | §79 | For a 0-callee giant, fingerprint by DATA symbols (§71 cannot fire); and the STACK-SLOT OR |
+| L6241 | §71 | has a blind spot, and this is it |
+| L6255 | §3-NEW | LEVER — the frame layout reads back the original declaration order |
+| L6266 | §76 | confirmed at scale, and a pin nuance |
+| L6275 | §3-The | residual, and the honest read |
+| L6285 | §80 | A do-not-re-buy entry is scoped to its BASE, not to the function; and the pin's hidden cos |
+| L6306 | §3-The | pin's hidden cost, with the citation |
+| L6317 | §3-The | flagged "#1 move" LOST — and why the failure is informative |
+| L6327 | §78 | 's attribution primitive, run and reproduced |
+| L6333 | Cold-start | economics, now complete |
+| L6338 | §81 | Banking a jr (jump-table) function: the 3-step carve chain, and why `match_one` cannot see |
+| L6369 | §3-The | defect this exposed: a shared type that is present but invisible |
+| L6385 | §82 | Two source-shape oracles from behemoth #6: a duplicated `addiu $aN,$sp,K` across a `jal` m |
+| L6390 | §3-1. | The inlined-helper signature |
+| L6404 | §3-2. | Scalar vs aggregate decides *when* the slot is allocated |
+| L6416 | Also | reproduced on this function |
+| L6420 | §3-And | the banking footnote (§75a class A, one line) |
+| L6427 | §83 | The parameterised-repeat law, the spill-area trap, and why a per-case edit cannot move a p |
+| L6434 | §83a | READ THE HEADLINE NUMBER CORRECTLY: a LENGTH drift makes `match_one`'s count meaningless |
+| L6442 | §83b | THE LEVER: find the parameterised REPEAT before decoding case-by-case |
+| L6460 | §83c | TRAP: a "dead local" in a prior draft may be gcc's OWN spill area |
+| L6467 | §83d | CSE's quantity budget is WHOLE-FUNCTION, so a local rewrite cannot fix a local symptom |
+| L6481 | §83e | §80 vindicated again, on the same day it was written |
+| L6487 | §84 | The DERIVED-OFFSET remap bug: a hand-computed literal that encodes the DISTANCE between tw |
+| L6492 | §3-The | construct |
+| L6510 | §3-Why | it survived every candidate gate |
+| L6525 | §3-THE | FIX IS MECHANICAL — the tool already holds the answer |
+| L6533 | Scope | , measured (do not over-generalise — §80) |
+| L6543 | §3-Two | ladder lessons banked with it |
+| L6554 | §85 | The RETURN-axis fleet widen is ALL-OR-NOTHING: widening the shared header alone guarantees |
+| L6559 | §3-The | conflict |
+| L6567 | §3-THE | FAILURE MODE — widening only `engine_core.h` is worse than not starting |
+| L6574 | §3-The | precondition, and how to check it in one grep |
+| L6582 | §3-Do | the WHOLE axis in one edit, then R22 once |
+| L6591 | Reading | , for the next person |
+| L6604 | §86 | Pinned-exemplar templatability is a PER-FAMILY property, not a per-member rate; and the §4 |
+| L6606 | §3-The | guard refuses a class that largely works |
+| L6615 | §3-THE | LAW: all-or-nothing PER FAMILY |
+| L6642 | §3-Why | the two live families differ from the three dead ones — the open question |
+| L6648 | §87 | `match_one` COMPILES but never LINKS, so an unresolvable data symbol reads as MATCH; and s |
+| L6664 | §3-The | blindness ladder, now complete — FOUR classes `match_one` cannot see |
+| L6674 | Consequence | for the backlog ledger |
+| L6681 | §3-The | cheap discriminator, before spending a sweep |
+| L6689 | §88 | `cross_jump` will not merge a common suffix containing a CALL; and §78 is scoped to ORDERE |
+| L6694 | §88a | repeated CALL-shaped blocks are left UNMERGED; call-free tails are merged for you |
+| L6701 | §88b | the `slti` literal-position law (extends §78 to comparisons) |
+| L6716 | §88d | BANKING ORDER: run the §81 carve chain BEFORE banking, never after |
+| L6723 | §88e | a wrong diagnosis, refuted properly (the model for how to treat an inherited lever) |
+| L6733 | §88f | the missing rung: a RELOCATION gate between `match_one` and the binary |
+| L6741 | §89 | Two throughput rules the project already had written down and was not following (Phase 29 |
+| L6747 | §89a | MEASURE the write set; do not assert its tier (`tools/blast_radius.py`) |
+| L6760 | §89b | the parallel gate farm existed; the family path could not reach it (`tools/sweep_parallel. |
+| L6773 | §3-The | standing sequence |
+| L6781 | §90 | Five tool-integrity laws from one session, each of which changed an answer (Phase 29 SESSI |
+| L6787 | §90a | A comparison tool MUST share its reference oracle's index space, exactly |
+| L6804 | §90b | "Byte-neutral" is not "wanted": undo on the SUCCESS path too |
+| L6814 | §90c | A library-callable function must FAIL CLOSED on an unconfigured module |
+| L6825 | §90d | Do not measure a live wave's drafts (§87 in real time) |
+| L6833 | §90e | An agent's CONCLUSION and its EVIDENCE fail independently — re-derive the premise, not the |
+| L6857 | §91 | A structure-TRANSFER is only valid where the structure corresponds: the `--like` role trap |
+| L6886 | §3-The | three-hypothesis trail, because two of them were wrong and the wrongness is instructive |
+| L6906 | §92 | Conforming a DECLARATION: pointer changes are caller-neutral, scalar-WIDTH changes are not |
+| L6937 | §93 | `set -o pipefail` attributes a pipeline failure to the LAST stage, not the failing one (Ph |
+| L6962 | §94 | A family sweep's `0/N` is a TYPE-CARRY failure until proven otherwise: lift the exemplar's |
+| L6998 | §95 | `reconcile_tu` dropped the SIBLING declarators of a multi-symbol `extern` line (Phase 29 S |
+| L7033 | §96 | The same rewrite, one shape down: `reconcile_tu` matched statements to lines by TEXT, so e |
+| L7081 | §97 | The gate's own tree hygiene: a refused carve, an unchecked recovery, and a snapshot that c |
+| L7128 | §98 | `conform_decls` had three defects, and only the third needed R22 to find (Phase 29 SESSION |
+| L7182 | §99 | The narrow-param wall is a DEF-side problem with a ZERO-blast-radius fix: convert the defi |
+| L7205 | §3-Two | `reconcile_tu` bugs found underneath, one introduced while fixing the other |
+| L7231 | §100 | Prefer the DRAFT-LOCAL fix: a type only one function uses belongs in its BODY, not in a sh |
+| L7260 | §101 | The STALE DEFAULT class: a guard whose cause was removed is a silent skip wearing a safety |
+| L7287 | §102 | A PLUMBING verdict can MASK a DIFF; and K&R is not always a codegen change (Phase 29 SESSI |
+| L7322 | §103 | A FILE-scope `extern` in a shared overlay TU is a GLOBAL constraint on every LATER functio |
+| L7410 | §104 | Two silent-skip defects in one scan: match on MASKED text, emit from the ORIGINAL (Phase 2 |
+| L7446 | §105 | A gate's revert must survive an EXCEPTION, not just a failure (Phase 29 T53, `jtbl_family_ |
+| L7485 | §106 | Persist the MEASUREMENT, derive the POLICY: a stored route let a stale file out-vote the l |
+| L7528 | §107 | A lever wired into ONE gate path is a lever most families cannot reach (Phase 29 T56, `fun |
+| L7566 | §108 | Diagnosing a family `0/N`: the four causes, and the third opt-in lever (Phase 29 T59) |
+| L7615 | §109 | Conforming a definition to a shared header: fix the NAMES, then check the RETURN precondit |
+| L7655 | §110 | A unit must define exactly ONE function, and "ends in `;`" does not tell you which line de |
+| L7696 | §111 | The distinct-code metric is not noisy: a family pays it only if its members are byte-VARIA |
+| L7745 | §112 | A macro-scoped declaration only collides where the macro is INSTANTIATED (Phase 29 T67/T69 |
+| L7791 | §113 | An ARITY blocker only exists if the macro CALLS the function; an address-taken use has no |
+| L7823 | §114 | The THIRD decl axis: a CALLEE the draft declares differently from the target TU (Phase 29 |
+| L7865 | §115 | A `func_XXXXXXXX` predicate rots by design: the same name-form assumption in THREE places |
+| L7892 | §116 | Optimization level is a property of the FILE, not the function: read a family 0/N against |
+| L7910 | §3-The | fix moves the DEFINITION, not the stub — and here is why the obvious shortcut fails |
+| L7941 | §117 | Spell the sibling's symbol from the SIBLING's address, not the exemplar's kind (Phase 29 T |
+| L7968 | §3-Why | it survived so long: a MASKED oracle will MATCH a wrong symbol |
+| L7978 | §118 | Ordinal (positional) immediate resolution: compare C tokens to the DIFFERING asm uses (Pha |
+| L8012 | §119 | Two levers on the SAME axis, opposite directions: test the off-diagonal (Phase 29 T89) |
+| L8041 | §120 | Uniquify draft-defined TYPE names; and check which of N staging sites you actually patched |
+| L8052 | §3-Do | NOT "strip the duplicate typedef" — it breaks the extern that uses it |
+| L8058 | §3-The | wiring trap that cost two attempts |
+| L8076 | §121 | Synthesise externs for macro-DEFINED callees from the macro's own definition head (Phase 2 |
+| L8099 | §122 | GATE RAW BEFORE TRANSFORMING; the undo belongs to the WRITER, as a per-edit journal (P30 T |
+| L8131 | §123 | PROPAGATE A FAMILY WITH THE TOOL ITS TIER NEEDS: `dedup_propagate` is h_exact-only; its re |
+| L8168 | §124 | A "not matched" verdict can mean the definition is there under a DIFFERENT C NAME: the asm |
+| L8213 | §124a | a family sweep's `0 matched-exemplar families` may be a FILTER, not a wall |
+| L8221 | §125 | Split the CARVE from the BODY before calling a jr residue a wall — and measure it by SHA f |
+| L8228 | §3-The | method (keep this) |
+| L8238 | §3-The | instrument rules that make its answer trustworthy (this is where I failed) |
+| L8253 | §3-The | corrected results (each SHA-verified, from a clean tree, restore re-verified) |
+| L8263 | §3-Two | further notes worth keeping |
+| L8272 | §3-The | meta-lesson |
+| L8279 | §126 | The carve-within-a-carve: an ADDRESS RANGE is not an OPTIMIZATION REGION (P30 T2, byte-pro |
+| L8294 | §3-The | finding: opt level is per FILE, so the file's contents must be opt-HOMOGENEOUS |
+| L8305 | §3-The | instrument trap that hid it (and it is §124's shape again) |
+| L8314 | §3-The | mechanics |
+| L8332 | §126a | a bare `except: continue` around a coverage-asserting oracle re-creates the silent skip (P |
+| L8364 | §127 | The `-O0` regime: the CONSTANT-OFFSET FOLD, and why `-O0` needs its own idiom set (P30 T3 |
+| L8371 | §3-The | idiom they kept re-deriving: the constant-offset fold |
+| L8382 | §3-The | rest of the `-O0` regime (write PLAIN C, and mean it) |
+| L8392 | §127a | §71 (sibling-first) is the strongest `-O0` lever, and it beats the index |
+| L8401 | §127b | the knowledge was in a SOURCE COMMENT, not the cookbook |
+| L8408 | §128 | A raw NUL in C source makes grep SILENTLY SKIP the file (P30 S28, 137 files) |
+| L8440 | §128a | a negative control must corrupt a SCRATCH COPY, never the tracked file |
+| L8452 | §129 | Post-carve, `rtu_match`/`match_one` COUNT THE JUMP TABLE AS INSTRUCTIONS; and a carve must |
+| L8456 | §129a | the target instruction count is INFLATED after a carve |
+| L8477 | §129b | never commit a carve whose owner is still a stub (it strands the carve) |
+| L8492 | §3-The | real blocker underneath, for the record |
+| L8501 | §130 | An INCREMENTAL build can report BYTE-IDENTICAL for a change the CLEAN build cannot even LI |
+| L8538 | §3-The | diagnostic ladder that finally located it (reusable) |
+| L8548 | §131 | The jtbl OVER-SPAN: `sltiu N` is ground truth in BOTH directions, and the zero-word rule o |
+| L8585 | §132 | The `JR-PAIR-IN-ONE-O0-OBJECT` "wall" was TWO instrument defects: a merged-double span the |
+| L8594 | Defect | 1 — a pre-§8e MERGED DOUBLE is not a single-table predecessor |
+| L8612 | Defect | 2 — `as` writes a corpse and nothing deletes it |
+| L8622 | §3-The | fingerprint, and the 30-second ladder that found it |
+| L8643 | §3-The | transferable rule |
+| L8650 | §132a | `--like` is for a sibling with NO record; against one that HAS a record it over-derives (P |
+| L8675 | §132b | When the span's already-matched owner is ITSELF multi-switch: `--span-rel` (P30 S1, `func_ |
+| L8700 | §133 | The DEFAULT-FILTER class: three times in one session, a tool silently answered a narrower |
+| L8726 | §134 | MULTI-LINE BLINDNESS: one root cause, four faces, in `family_remap`'s preamble scanner (P3 |
+| L8780 | §135 | Six byte-verified gcc-2.7.2 idioms from the P30 S6f-h waves (and the two-lane wave shape t |
+| L8785 | §3-The | codegen idioms |
+| L8819 | §3-The | integration idioms (these decide whether a byte-correct draft BANKS) |
+| L8834 | §3-The | wave shape that produced these |
+| L8852 | §136 | The LOCAL-VARIABLE lever: how many C locals, at what scope (P30 wave 4a, 25 byte-verified |
+| L8868 | §3-The | splitting/merging rules (each closed a residual, byte-gated) |
+| L8894 | §3-The | type-form rules |
+| L8927 | §3-The | scheduling rules (refining §135-2 and §135-4) |
+| L8956 | §3-The | declaration surface (integration, not codegen) |
+| L8968 | Wave | economics (measured, for the next batch's sizing) |
+| L8991 | §136a | Blocker capture: classify on the OUTPUT, never on the exit status |
+| L9048 | §136b | A prior wave's "genuine byte-DIFF" verdict is NOT reliable evidence (4 of 4 refuted) |
+| L9084 | §136c | SIBLING-FIRST is a DERIVATION shortcut, not just a conflict fix (the fastest route in a fa |
+| L9109 | §136d | Four gcc-2.7.2 levers the redraft lane found (each closed a residual no other lever moved) |
+| L9153 | §136e | §136c's PRECONDITION, and two more symptom keys (wave 4b batch 3) |
+| L9201 | §136f | Two declaration sub-cases the reconcile lane surfaced (lane now 15/15 lifetime) |
+| L9226 | §136g | When the index points at the WRONG lever: two byte-refuted routings (func_801863B4) |
+| L9255 | §136h | CORRECTION: the zero-crack pool does NOT "refill with cheap work" (my error, byte-measured |
+| L9285 | §136i | The drafter model LADDER: Haiku → **Sonnet** → Opus → Fable5 (Drew, 2026-08-03) |
+| L9317 | §136j | The failure MIX flips with function size (measured across four bands, one session) |
+| L9359 | §137 | REGALLOC-PERM is a TWO-COMPILE ARITHMETIC PROBLEM, not a permuter job |
+| L9401 | §137a | A gate verdict has a TIMESTAMP; re-check it against the draft's mtime |
+| L9430 | §138 | The propagation lanes: a gate refusal is a DECLARATION, and which lever you owe depends on |
+| L9436 | §3-The | triage, cheapest first |
+| L9488 | §3-The | DEFINITION-side alias is the only escape when the fleet canon disagrees on a promoting par |
+| L9496 | Rank | the lane by measured concentration, not by class count |
+| L9505 | THREE | carry variants hide in one "CARRY-FIXABLE" bucket — and they need different fixes |
+| L9541 | §134 | again, in a second tool — and the waiter rule corrected |
+| L9561 | STEP | 0 of sibling-first: grep `src/` for a distinctive LITERAL from the `.s` |
+| L9580 | Reconciling | a gate-refused draft: which way you edit depends on WHERE the TU's decl is |
+| L9609 | §139 | A GATE THAT GREPS FOR VERDICTS MUST ASSERT 1:1 ACCOUNTING; and a `--src` filter must not s |
+| L9641 | §3-The | generalisation — three corollaries worth more than the bug |
+| L9658 | §3-And | the inverse-lookup trap, same session |
+| L9675 | §140 | A METRIC IS NOT A MEASUREMENT UNTIL IT IS REPRODUCIBLE FROM THE COMMITTED TREE (P30 S1e: a |
+| L9695 | §3-The | three-line proof (do this before diagnosing any metric movement) |
+| L9704 | §3-The | two instrument defects it exposed |
+| L9724 | §3-The | same swallow, twice more, in the integration spine |
+| L9735 | §3-Two | wrong mechanisms I chased first, and why they were wrong |
+| L9755 | §141 | The §134 class is CLOSED: every line-shape decision now routes through `cdecl._mask` (P30 |
+| L9793 | §142 | An open stub whose `h_exact` class is MATCHED elsewhere is FREE. Propagate the body; do no |
+| L9805 | §3-The | measurement (do this before any wave; it is ~20 lines and needs no builds) |
+| L9820 | §3-The | trap that hid it — SAME FUNCTION, TWO ROUTES, ONLY ONE IS FREE |
+| L9829 | Route | selection (why `--addr` sometimes says "nothing changed") |
+| L9837 | §3-And | the report-vs-bytes lesson attached to it |
+| L9849 | §143 | `cast_call_sites` read a RETURN STATEMENT as a prototype and deleted it. A 0/39 sweep beca |
+| L9903 | §144 | THE LITERAL'S SPELLING PICKS THE IMMEDIATE ENCODING (P30 S40 wave 1, `func_801822E0`) |
+| L9942 | §145 | Three loop/combine levers from the S40 wave-2 drafters (16/16 match_one) |
+| L9992 | §146 | RE-MEASURE A WALL BEFORE YOU RESPECT IT. Both "permanent" giants fell to drafts already on |
+| L10003 | §3-Why | a correct draft can read as an intrinsic wall |
+| L10015 | Then | propagation returned 0/137 TWICE — both times a missing TYPE |
+| L10024 | §3-Two | errors of mine, both instructive |
+| L10038 | §3-The | rule |
+| L10051 | §147 | The three-stratum FRAME LAW, and four "stop searching" verdicts (P30 S42, `func_8017C294`, |
+| L10056 | §3-A. | The frame has THREE strata, and stratum 3 is unreachable from C |
+| L10072 | §3-B. | A `?:` on MEMORY operands costs ~16 bytes of invisible frame; on REGISTER operands, zero |
+| L10083 | §3-C. | Inner-block declaration does NOT delay slot allocation — BYTE-REFUTED |
+| L10088 | §3-D. | A lone `$t8`/`$t9` in the target is RELOAD SCRATCH — reproduce the spill, don't pin the re |
+| L10098 | §3-E. | A `qty_compare` TIE is not spelling-reachable — recognise it and stop |
+| L10110 | Consequence | for the family (a real scheduling decision) |
+| L10160 | §148 | The loop.c hoisting THRESHOLD is arithmetic you can compute, and the `?:` clamp that folds |
+| L10166 | §3-A. | `move_movables` hoists iff `threshold × savings × lifetime ≥ insn_count` — and you can rea |
+| L10185 | §3-B. | `(v < 0x40) ? v : 0x3F` is folded to `MIN_EXPR` and expands to the WRONG SHAPE |
+| L10199 | §3-C. | A zero-byte ALLOCNO-PRIORITY slider |
+| L10209 | §3-D. | Reproduce the original's BUGS verbatim |
+| L10258 | §149 | Four instrument defects in one session, and the two questions they were hiding (P30 S43) |
+| L10264 | §3-A. | A prep step that returns its input on failure is indistinguishable from a search that foun |
+| L10282 | §3-B. | Same address + same name ≠ same body — and the ledger keys on address |
+| L10298 | §3-C. | `make: *** [...] Error N` is a summary, never a diagnosis |
+| L10308 | §3-D. | "Cheap fuel" that was never probed: 0 of 31 templatable |
+| L10327 | §150 | A register ROTATION across symmetric blocks is VARIABLE-IDENTITY evidence, not an allocato |
+| L10334 | §3-The | fix |
+| L10344 | §3-The | method that found it (this is the transferable part) |
+| L10360 | §3-Two | corrections to the record |
+| L10371 | Diagnostic | order (adopt this) |
+| L10382 | §151 | THE GHOST WEDGE: when a load-before-store transposition is unreachable by ANY statement or |
+| L10387 | §3-The | mechanism (read from cc1's own `-dR` trace, not inferred) |
+| L10402 | §3-The | lever — a zero-emission insn that absorbs the blocked tick |
+| L10410 | §3-The | two fallouts, and how to close them (both measured, in order) |
+| L10422 | When | to reach for it |
+| L10433 | §152 | BYTE SIZE is the family key that name- and h_seq-grouping both miss (P30 S43, the 0xECC fa |
+| L10438 | §3-The | finding |
+| L10447 | §3-The | key |
+| L10458 | §3-Two | cautions that must travel with this technique |
+| L10469 | §3-The | companion defect (open) |
+| L10481 | §153 | THE ADDRESS-REMATERIALISATION LAUNDER: a third zero-emission asm lever (P30 S43, `func_801 |
+| L10489 | Symptom | Symptom |
+| L10494 | Mechanism | (gcc source + RTL dumps, not inferred) |
+| L10501 | What | does NOT work (14 byte-measured probes) |
+| L10507 | §3-The | cure — a fresh launder per site, each in its own block |
+| L10517 | Companion | levers from the same function |
+| L10537 | §154 | Reading a disc payload: the module-id word, static base derivation, and "type 1 = uncompre |
+| L10542 | §3-A. | Payload word0 is a global MODULE ID; code starts after the header |
+| L10551 | §3-B. | Two static base-derivation methods that must AGREE (use both) |
+| L10563 | §3-C. | PAC type 1 = the same payload class as type 4, just NOT compressed |
+| L10573 | §155 | hi/lo literal scanning MUST track base registers (S45) |
+| L10582 | §155a | the same failure class, one level up: SHAPE-blind table scanning (S45 p5) |
+| L10602 | §155b | check the TYPE your oracle returns before comparing against it (S45 p5) |
+| L10625 | §155c | the ZERO-REFERENCE trap: gcc splits a global-array address across the `lui` and the LOAD ( |
+| L10655 | §156 | an ORPHANED reconcile poisons the fleet: `dedup_propagate`'s kept edit (S45 p6/p7) |
+| L10702 | §157 | the cheap-tier size cliff, measured (S45 p6) |
+| L10727 | §158 | The RANGE-EXTENDER: a fourth zero-emission asm lever completes the allocno toolkit (P30 S4 |
+| L10736 | Symptom | Symptom |
+| L10742 | §3-Why | the fork is chained (gcc source, validated insn-by-insn against -dS/-dR dumps) |
+| L10755 | §3-The | method (dump-arithmetic first, then place — no probing) |
+| L10772 | Bonus | facts worth keeping |
+| L10787 | §156 | THE PREFERENCE-DONOR MERGE: cross-region variable reuse is what fills a0-a3, and a call-ar |
+| L10843 | §159 | THE DECLARATION AXIS: conform to byte-truth, and make every guard state its COVERAGE (P30 |
+| L10908 | §160 | THE REACH-15 WAVE HARVEST: an align-1 block move, and the instrument that called it a wall |
+| L10984 | §161 | THE RETRY-WAVE HARVEST: a jump table indexed from zero, and two allocator traps (P30 S47) |
+| L11029 | §162 | S48 WAVE-1 HARVEST (P30, 2026-08-11): the reach-ordered sibling campaign's first 12 target |
+| L11056 | §162a | SHARPENS *(sharpens §161a, §131, §8a-pad, §129a)* |
+| L11085 | §162b | SHARPENS *(sharpens §48-A3, §156, §150, §76)* |
+| L11114 | §162d | SHARPENS *(sharpens §31, §21, §30, §55a)* |
+| L11156 | §162e | NEW |
+| L11158 | §162 | THE LICM PAIR: what makes an address a movable AT ALL, and why the preheader order is the |
+| L11224 | §162f | SHARPENS *(sharpens §42d, §41d, §73, §10)* |
+| L11279 | §162g | NEW |
+| L11281 | §162 | CROSS-JUMP DIRECTION: the surviving copy is always the LATER one, so a BACKWARD `j` into a |
+| L11315 | §162h | SHARPENS *(sharpens §88, §88a, §50-B, §8)* |
+| L11317 | §162 | The cross-jump "CALL veto" is a COUNT law, not a CALL law (BOUNDS §88a; P30 S48, `func_801 |
+| L11383 | §162i | SHARPENS *(sharpens §135, §21, §42, §32)* |
+| L11408 | §162j | SHARPENS *(sharpens §25, §136d-1, §48-B, §46-L2)* |
+| L11437 | §162k | SHARPENS *(sharpens §1-I2, §12, §160d, §21)* |
+| L11500 | §162l | SHARPENS *(sharpens §48-B, §48-C1, §20, §21)* |
+| L11555 | §162m | SHARPENS *(sharpens §36, §158, §148, §153)* |
+| L11557 | §158a | THE FIFTH LEVER IS NOT AN ASM: `do { } while (0)` is a REGION ref-multiplier you MINT (P30 |
+| L11564 | §3-The | law |
+| L11575 | Size | it before you write it (§158 step 1-2, applied) |
+| L11596 | §3-The | wrap BOUNDARY is the dial — and it is indiscriminate |
+| L11602 | §3-Not | a pure dial |
+| L11606 | DIAGNOSTIC | TELL — two faces, one law |
+| L11628 | §162n | NEW |
+| L11661 | §162o | SHARPENS *(sharpens §158, §136-1, §136-6, §79)* |
+| L11720 | §162p | SHARPENS *(sharpens §48-B, §46-L2, §156, §136d-1)* |
+| L11737 | §162q | SHARPENS *(sharpens §30, §30a, §135-2, §136-13)* |
+| L11775 | §163 | S48 WAVES 2-3 HARVEST (P30, 2026-08-11/12): the five that were byte-probed and are actiona |
+| L11843 | §163z | THE UNVETTED REMAINDER (do not cite as law; each needs a dedupe pass) |
+| L11863 | §164 | S48 §163z SKEPTIC PASS (P30, 2026-08-12): 190 claims vetted, 82 banked |
+| L12315 | §16Xy | SHARPENS *(sharpens §136d-3, §37 /s-DEP LATTICE, §135-2, §136-13, §162q)* |
+| L12317 | §3-The | `/s` drop clause is in ALL THREE dependence predicates, so the FIXED-ADDRESS STORE is what |
+| L13651 | §164z | REFUTED CLAIMS: do NOT re-derive these |
+| L13717 | §165 | S48 WAVE-4 HARVEST (P30, 2026-08-12): banked the same day the wave landed |
+| L14368 | §16Z | SHARPENS *(sharpens §37 "the /s-DEP LATTICE", §136-13, §136-14, §16Xy, §162q, `gcc-2.7.2- |
+| L14370 | §3-The | ADDRESS-CLASS TABLE: which load/store pairs even REACH the `/s` clause (P30 S48 wave 4, `f |
+| L14886 | §165z | REFUTED THIS WAVE: do NOT re-derive |
+| L14930 | §166 | THE DESTINATION-TU ORACLE (P30 S48): the seven-attempt bug that was never codegen |
+| L14986 | §167 | S48 WAVE-5/6 HARVEST (P30, 2026-08-12): the saturation point |
+| L16182 | §167z | REFUTED IN WAVES 5/6: do NOT re-derive |
+| L16239 | §168 | THE COUSIN TIER (P30 S49, 2026-08-12): h_seq's exact-hash brittleness, measured — and the |
+| L16291 | §169 | THE MICRO-ADAPT LANE (P30 S49): edit a proven body, don't crack a new one |
+| L16338 | §170 | THE A-PROP WORD-DIFF CARD (P30 S49): the lane that had no owner |
+| L16382 | §171 | THE STALE SEED SYMBOL (P30 S50, 2026-08-13): why §170's 91%→57% was never codegen |
+| L16448 | §171a | THE MECHANICAL A-PROP DRAFT (P30 S50): 256 members banked with no agent in the loop |
+| L16498 | §171b | THREE CARRIES THE MECHANICAL DRAFT NEEDS (P30 S50, banking the top-reach families) |
+| L16531 | §172 | THE ORPHAN-SLOT MECHANISM v2 (P30 S50-Max): the complete frame-residue model for gcc-2.7.2 |
+| L16585 | §172a | TWO DECOMPILATION TELLS FROM THE SAME DIG (P30 S50-Max) |
+| L16601 | §172b | THREE MORE TELLS FROM THE GCC READ (P30 S50-Max, banked on Drew's ask) |
+| L16644 | §173 | THE STORED-PLUMBING RECOVERY RECIPE (P31 T6): symfix-first, per-group isolation, and where |
+| L16680 | §174 | THE ADAPT-CARD WAVE RECIPE (P31 waves A/B, 2026-08-14): prevention beats recovery |
+| L16750 | §175 | A CALLER-SAVED REGISTER PIN CAN BE A CORRECTNESS BUG, NOT JUST A SCHEDULING CHOICE (P31 wa |
+| L16775 | §176a | THE VERIFICATION-LAYER LAWS (P31 overnight, 2026-08-15). What each check can and cannot pr |
+| L16815 | §176b | BATCH-GATING MECHANICS (P31): what changes when N drafts land in ONE .c |
+| L16841 | §176d | THE CONFLICT TABLE MUST BE SEEDED FROM THE TU, AND KEYED PER FILE (P31 S52, 2026-08-15) |
+| L16880 | §176e | SYMBOL IDENTITY IS COMPUTABLE OFFLINE (P31 S52): `tools/reloc_identity.py` |
+| L16937 | §176f | THE DECLARATION FORM IS A MATCHING LEVER, SO RECONCILE TOWARD THE FORM THE MATCH NEEDS (P3 |
+| L16968 | §176g | SIZE A WAVE BY INSTRUCTIONS, NOT BY CARDS (P31 S52 — the adopted doctrine) |
+| L17006 | §176h | THE BATCH-SUBSTITUTION HAZARD MAP (P31 S52): seven holes, three wrong fixes, one law |
+| L17014 | §3-A. | The seven under-reporting holes (all in `gate_main`, all the same shape) |
+| L17032 | §3-B. | Typedef handling — the only strategy that survives contact |
+| L17054 | §3-C. | The limit that remains (recorded, not solved) |
+| L17061 | §3-C2. | RECONCILE BEFORE THE FIRST GATE — a parked draft gets HARDER to bank, not easier |
+| L17084 | §3-D. | The measured cost shape, and what to build next |
+| L17102 | §176i | WHAT A STATIC PRE-GATE CHECK CAN AND CANNOT PROVE (P31 S52, wave Q) |
+| L17134 | §176j | STOPPING A WAVE MID-FLIGHT COSTS THE IN-FLIGHT TAIL (and how much is recoverable) |
+| L17160 | §176j-2 | THE REPAIR PASS, MEASURED (do this instead of resuming) |
+| L17180 | §176k | TWO SELECTOR BUGS THAT SILENTLY SHRINK A WAVE |
+| L17197 | §177 | 🔴 THE EPILOGUE RETURN-DELAY SLOT IS DECIDED BY YOUR SAVED-REGISTER SET, NOT BY SCHEDULING |
+| L17254 | §178 | SIX LEVERS MINED FROM THE WAVE-P JOURNALS (P31 S52), each byte-proven and source-cited |
+| L17266 | §3-A. | THE `$0`-ADD OPAQUE COPY defeats `make_regs_eqv` (func_80033398, 93 ins) |
+| L17282 | §3-B. | A `return ` IS A PRIORITY-1 HARD-REG SET THE SCHEDULER PLACES FIRST (func_8001BE30, |
+| L17295 | §3-C. | SINGLE-SET TEMPS GET THE BIRTHING BOOST (func_8001D3FC, 196 ins) |
+| L17303 | §3-D. | A NARROW TYPE BLOCKS COPY ELISION (func_8001D3FC — new idiom) |
+| L17310 | §3-E. | THE ZERO-OFFSET ALIAS HOLE (func_80037028, 71 ins) |
+| L17319 | §3-F. | `MEM_IN_STRUCT_P` ASYMMETRY IN `true_dependence` (func_80037144, 124 ins) |
+| L17325 | §3-G. | TWO MODELLING TRAPS THAT COST THESE AGENTS SWEEPS OF HUNDREDS OF COMPILES |
+| L17341 | §179 | IDIOMS MINED FROM THE WAVE P/Q JOURNALS (P31 S52, harvest pass) |
+| L17351 | §179-A | 🔴 A LOOP-WALKED POINTER **PARAMETER** HANDS ITS ARGUMENT REGISTER TO THE GIV (9 byte-proof |
+| L17400 | §179-B | 🔴 THE HAND-WRITTEN-ASM TRANSCRIPTION CHECKLIST (maspsx + masked_diff; 10 byte-proofs) |
+| L17450 | §179-C | 🔴 A FUNCTION WITH NO EPILOGUE (falls into a sibling's shared tail) MUST BE FILE-SCOPE `__a |
+| L17501 | §179-D | `gte_stflg` MUST CLOBBER `"$12"` OR THE WHOLE TEMP FILE ROTATES BY ONE |
+| L17521 | §179-E | A `>2*MAX_MOVE_BYTES` BLOCK COPY IS A **STRUCT ASSIGNMENT**, NOT A HAND LOOP |
+| L17547 | §179-F | PINNING A LOOP-WALKED POINTER IS A TOTAL OFF-SWITCH FOR STRENGTH REDUCTION |
+| L17570 | §179-G | 🟡 A PIN CAN **CREATE** A COMBINE `LOG_LINK` AND DELETE AN `andi` (sixth RC-5 channel, n=1) |
+| L17597 | §179-H | A MID-BODY `.global LABEL` PAIR SLICES A BYTE-COMPARABLE FRAGMENT OUT OF A LARGER ROUTINE |
+| L17620 | Considered | and NOT banked |
+| L17637 | §176c | MAIN (SLUS_007.26) CANNOT BE GATED INCREMENTALLY |
+| L17648 | §176 | SEVEN LEVERS FROM THE P31 OVERNIGHT WAVES (2026-08-15): statement order, false regalloc, a |
+| L17654 | §176-A | "SCHEDULE / DELAY-SLOT / LENGTH-DRIFT ±1" ⇒ check STATEMENT ORDER around the call first |
+| L17678 | §176-B | "REGALLOC-PERM, 1-4 instructions off" ⇒ it is usually NOT register allocation |
+| L17724 | §176-C | 🔴 WALL REFUTATION: a hard-register pin CANNOT schedule around a call, because of a genuine |
+| L17750 | §176-D | CSE-class levers used in reverse (two sharpenings of §153 and cse_expr §2) |
+| L17776 | §176-E | Two cheap source spellings, both cc1-probed |
+| L17798 | §176-F | Misdiagnosis triage: four residual verdicts that were lying |
+| L17815 | What | is NOT banked here |
+| L17828 | §180 | THE LEFTOVER-DRAFT HARVEST: RE-VERIFY WHAT YOU ALREADY HAVE BEFORE DRAFTING ANYTHING NEW |
+| L17857 | §180b | WHAT THE PRE-GATE LADDER ACTUALLY FINDS IN A COLD PILE (the shape of integration debt) |
+| L17876 | §180c | WHEN A BINARY'S MASS BAND IS SPENT, THE FLEET-WIDE DRAW IS STRICTLY BETTER |
+| L17894 | §181 | WHAT A WAVE'S GATE ACTUALLY REJECTS (P31 S53, measured on wave R's 45-draft main pile) |
+| L17895 | Only | ONE of 27 blocked drafts was wrong. The other 26 were correct and unbankable. |
+| L17950 | §182 | §177's HONEST NEGATIVE: the epilogue lever cracked 4 of 16, and the `800c3` cluster held |
+| L17964 | §180d | THE `pgrep` BRACKET TRICK PROTECTS THE PATTERN, NOT THE COMMAND LINE |
+| L17976 | §183 | THE DECLARATION-RECONCILIATION PLAYBOOK (P31 S53, measured on 20 byte-verified drafts) |
+| L17977 | §3-18 | of 20 reconciled while keeping the match. The two that did not are mechanism, not effort. |
+| L18047 | §184 | COMMENT-BLINDNESS IS A DEFECT CLASS, NOT A BUG (P31 S53: three tools, one root cause, one |
+| L18075 | §185 | EDIT THE SIDE THAT IS CHEAP TO VERIFY, AND CHECK A TU RETYPE AT ITS USE SITES |
+| L18107 | §186 | CROSS-JUMPING RUNS **AFTER** SCHEDULING, SO NO C-LEVEL BARRIER CAN STEER IT |
+| L18128 | §186b | A NO-SAVE 16-BYTE FRAME IN A LEAF FUNCTION MEANS `s16` LOCALS, NOT A HIDDEN CALL |
+| L18136 | §186c | WHERE A VALUE IS LOADED DECIDES WHICH ALLOCATOR OWNS IT, AND THEREFORE ITS REGISTER |
+| L18153 | §187 | 🔴 "SAME SOURCE" IS NOT "SAME OBJECT": THE SDK BUILD AND THE GAME BUILD DISAGREE ON GTE NOP |
+| L18191 | §188 | 🔴 THE `jr $ra` + `addiu $sp` TAIL IS AN **ASSEMBLER** ARTIFACT, NOT A FRAME SHAPE |
+| L18241 | §189 | FIVE COMPILER LAWS MINED FROM THE WAVE R/S JOURNALS (P31 S53), each source-cited and re-de |
+| L18316 | §190 | THREE PRESCRIPTIONS FROM THE SAME HARVEST (weaker evidence than §189, honestly labelled) |
+| L18353 | §191 | WHAT THIS HARVEST DID **NOT** BANK (4 rejected, 4 narrowed) — recorded so it is not re-der |
+| L18375 | §192 | THE PRE-GATE LADDER WAS MAIN-ONLY, AND NOBODY COULD SEE IT (P31 S54) |
+| L18376 | Three | defects in one call path; the overlay slates that carry most of the wave work were being w |
+| L18440 | §193 | THE WAVE-T HARVEST (P31 S54): 71 index_gap reports -> 9 laws, 5 rejected, 61 already-cover |
+| L18457 | §193-A | The wave card ships only OPEN-set pointers and discards the atlas's BANKED one — `exemplar |
+| L18524 | §193-B | A NARROW CAST OF A WIDE PARAMETER COSTS ONE EXTRA INSTRUCTION WHEN ITS STATEMENT SITS AFTE |
+| L18562 | §193-C | gcc-2.7.2 cross_jump merges the SCHEDULED common SUFFIX only — there is no prefix/head mer |
+| L18596 | §193-D | A COMPILER-GENERATED ARGUMENT COPY IS A `optimize_reg_copy_1` TRIGGER: when the pointer's |
+| L18667 | §193-E | A varying-address (pointer) load is re-emitted once per CSE-LIVE INTERVAL, and naming it i |
+| L18697 | §193-F | §148-A2 — The `threshold -= 3` STAIRCASE: `move_movables` admits a COUNT of invariants, no |
+| L18761 | §193-G | §164-54's "scope to ≥4 arms" bound is byte-wrong — the dispatch-topology oracle goes live |
+| L18822 | §193-H | A pointer-derived base load `*(s32*)(p+K)` is uncacheable across ANY memory write or call |
+| L18862 | §193-I | A DECLARED AGGREGATE LOCAL HAS AN 8-BYTE FRAME STRIDE — CEIL(size,8), NOT size. N ARRAYS T |
+| L18921 | §193-REJECTED | what this harvest did NOT bank (recorded so it is not re-derived) |
+| L18948 | §194 | THE WAVE-U HARVEST (P31 S54): 64 index_gap reports -> 14 laws, 5 rejected, 44 already-cove |
+| L18965 | §194-A | A zero-byte scheduling fence goes AFTER the defining statement to make that computation em |
+| L19031 | §194-B | A `addu $rA,$rB,$zero` copy feeding ≥2 `sh` stores is a SECOND, 16-BIT-DECLARED local — th |
+| L19069 | §194-C | A CALLER-SAVED loop counter proves its live range crosses ZERO calls — so it cannot share |
+| L19132 | §194-D | Declared width of a computed-value local is a sched1 dial (count-neutral) — a replication |
+| L19173 | §194-E | The wave card's `exemplar` is the TARGET ITSELF on 42/73 wave-U and 36/71 wave-T cards — a |
+| L19210 | §194-F | `if ((*p = v = f()) == 0)` is an expand-time pseudo SPLITTER (store_expr's `want_value && |
+| L19283 | §194-G | Reading the integer half of a 16.16 stack aggregate: REGISTER-LIVENESS, not the C spelling |
+| L19326 | §194-H | §164-29's WAR fence runs again at SCHED2 ON HARD REGISTERS: an in-place `v &= K` before a |
+| L19364 | §194-I | §16N+2's magic-per-odd-part ladder has exactly one broken row — read the divisor arithmeti |
+| L19407 | §194-J | Back-to-back identical stores: flow.c's `last_mem_set` deletes the first, and only `volati |
+| L19459 | §194-K | Blind sched1's alias oracle with a second SET of a pointer pseudo — the first zero-byte, n |
+| L19537 | §194-L | §88b and §189-E are BOTH half-wrong, but not the way the candidate says: the compare-const |
+| L19585 | §194-M | A STORE in a CONDITIONAL branch's delay slot proves its C statement DOMINATES the branch — |
+| L19643 | §194-N | §193-D's C dial is misstated: the lever is a SURVIVING CODE_LABEL (a label with a real inc |
+| L19703 | §194-REJECTED | what this harvest did NOT bank (recorded so it is not re-derived) |
+| L19724 | §195 | THE WAVE-V HARVEST (P31 S54): 67 index_gap reports -> 14 laws, 9 rejected, 76 already-cove |
+| L19738 | §195-A | §167-08's "an $aN READ before the jal is scratch" has a byte-proven FALSE-NEGATIVE class: |
+| L19809 | §195-B | A CALL_INSN does not start a basic block in gcc-2.7.2 — so a call-crossing temp can be a L |
+| L19851 | §195-C | A call-argument `%hi/%lo` pair sitting at the block head, far above its `jal`, is a load-d |
+| L19899 | §195-D | §195 — `masked_diff.mask_for` returns 0 for EVERY `j`/`jal` word, so an internal `j` desti |
+| L19967 | §195-E | A 0/1 materialised at a JOIN immediately before the controlling `beqz`/`bnez` proves the s |
+| L20025 | §195-F | fold-const.c:4825 canonicalises a `?:` whose THEN arm is zero (or constant against a non-c |
+| L20077 | §195-G | §NEW — TWO ARMS CALLING THE SAME CALLEE MERGE INTO ONE `jal` UNLESS EACH ARM'S OWN CODE CO |
+| L20125 | §195-H | §165-27g — ON A FIXED-SYMBOL GLOBAL, `extern T D[];` + `D[0]` IS THE CSE RELOAD DIAL, AT Z |
+| L20172 | §195-I | §145(b) AMENDED — the pointer-bump `addiu` is saved by cse, not combine: ANY second SET of |
+| L20237 | §195-J | GTE / PsyQ op CALL-vs-INLINE is a PER-SITE SOURCE FACT, not a TU style — both forms coexis |
+| L20281 | §195-K | At -O2 the §18 array-of-struct lever is a FRAME lever, not a length lever — but only when |
+| L20333 | §195-L | The cse store-re-seed does not cross a JOIN LABEL: per-arm stores + a join read keep the r |
+| L20385 | §195-M | Frame `vars` is a SEQUENTIAL bump-allocation, not a flat sum: §193-I's CEIL(aggregate,8) t |
+| L20434 | §195-N | In a call-bearing chain of N≥2 `if (f(...)) return 1;` tests closed by `return 0;`, the LA |
+| L20481 | §195-REJECTED | what this harvest did NOT bank (recorded so it is not re-derived) |
+| L20527 | §196 | PUT ON THE CARD WHAT THE TREE ALREADY KNOWS: the fleet's declaration consensus (P31 S54) |
+| L20582 | §197 | THE WAVE-W HARVEST (P31 S54): 68 index_gap reports -> 4 laws, 3 rejected, 41 already-cover |
+| L20596 | §197-A | A NARROW SIGNED MEMORY READ FEEDING A CONSTANT `>>` LOSES ITS `lh`, AND THE CURE IS AN ASM |
+| L20634 | §197-B | A REPEATED COMPARE OF ONE VALUE AGAINST ONE CONSTANT IS DELETED BY cse's `qty_comparison_c |
+| L20662 | §197-C | Fix A1 (operand order) cannot move a commutative destination whose .greg conflict set alre |
+| L20707 | §197-REJECTED | §197-REJECTED |
+| L20722 | §199 | THE WAVE-X HARVEST (P31 S54/S55): 63 index_gap reports -> 7 laws, 2 rejected, 56 already-c |
+| L20733 | §199-A | §189-A's asm→source inference is byte-FALSE: an interloper between a split constant's `lui |
+| L20782 | §199-B | A permutation sweep that holds ANY statement fixed is not a sweep: the statement an agent |
+| L20827 | §199-C | A NEGATIVE CONSTANT MULTIPLY ALWAYS TAKES expmed's negate_variant — but whether you ever S |
+| L20875 | §199-D | A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is |
+| L20935 | §199-E | §189-A BOUNDED AND CORRECTED — the discriminator is INSN_PRIORITY, not "is the interloper |
+| L20994 | §199-F | §164-36b — THE TARGET-HEAD FENCE IS A DELAY-SLOT THREAD SELECTOR, AND IT ONLY FIRES WHEN ` |
+| L21048 | §199-G | At TWO case nodes the switch-vs-if oracle is not blind — but the tell is ALL tests positiv |
+| L21103 | §199-REJECTED | §199-REJECTED |
+| L21114 | §200 | THE ALIAS IS THE UNIVERSAL DECLARATION ESCAPE: stop negotiating with the TU's spelling (P3 |
+| L21163 | §201 | THE WAVE-Y HARVEST (P31 S55): 67 gap reports -> 5 laws, 8 rejected, 53 already-covered |
+| L21173 | §201-A | §150-B applies to `decl_prior`'s DEF row: for an overlay-window symbol the banked "definit |
+| L21205 | §201-B | In a narrowed PLUS/MINUS/AND/IOR/XOR expression the destination pointee is INERT — the sig |
+| L21285 | §201-C | §X — A CALL'S OWN DELAY SLOT AND THE UPSTREAM CONDITIONAL BRANCH'S SLOT COMPETE FOR ONE IN |
+| L21336 | §201-D | THE SIGNEDNESS OF A div/mod MAGIC IS DECIDED BY THE STATIC TYPE OF THE DIVIDEND TREE AFTER |
+| L21383 | §201-E | §194-J-2 — The `last_mem_set` deletion window is measured in SOURCE/expand order, not in t |
+| L21439 | §201-REJECTED | eight, the session's highest |
+| L21464 | §202 | THE ALIAS CARRIES A DEFINITION, NOT JUST A DECLARATION: the DEF-SIDE-RETURN wall (P31 S56) |
+| L21501 | §203 | A DEDUPED TYPEDEF MUST PRECEDE EVERY SPLICE POINT, NOT JUST ITS OWN (P31 S56) |
+| L21562 | §204 | THE WAVE-Z HARVEST (P31 S56): 82 gap reports -> 5 laws, 16 rejected, 30 already-covered |
+| L21581 | §204-A | A COMPARE THAT APPEARS BOTH IN A BRANCH'S DELAY SLOT AND AGAIN ON THE FALL-THROUGH IS A JO |
+| L21656 | §204-B | A LOOP COUNT THAT ARRIVES ON THE STACK IS DECREMENTED IN PLACE: a fresh counter local can |
+| L21720 | §204-C | WHEN A LOCAL BUFFER'S ADDRESS IS PASSED TO A CALL, ITS SIZE IS A FACT ABOUT THE CALLEE'S B |
+| L21778 | §204-D | A LOOP-INVARIANT LOAD IS ADMITTED AS A MOVABLE ONLY IF ITS ADDRESS CANNOT TRAP: `local.fie |
+| L21853 | §204-E | `decl_prior`'s `%hi/%lo` ARM HAS NEVER FIRED: the card's promised GLOBAL-TYPE row is 0 of |
+| L21905 | §204-CONFIRMED | 30 reports that the index already answered |
+| L21999 | §204-REJECTED | sixteen, twice the previous record |
+| L22072 | §205 | THE CHAINED ASSIGNMENT IS ITS OWN SCHEDULING DIAL: `*b = *a = v;` moves an argument copy t |
+| L22127 | §206 | THE JTBL-CARVE DRAFTING IDIOM: the bounds check is the entry count, and an EMPTY case owns |
+| L22196 | §207 | THE WAVE ab–ag HARVEST (P31 S58): 278 byte-banked notes → 25 laws, 103 self-reported no-ga |
+| L22217 | §208 | TWO NAMED LOCALS FOR ONE RELOADED EXPRESSION BUY TWO ALLOCNOS — the naming granularity own |
+| L22266 | §209 | THE NARROW LOCAL IS A DIAL IN TWO OPPOSITE DIRECTIONS, AND §194-B's "≥2 `sh` STORES" BOUND |
+| L22343 | §210 | THE SINGLE-BIT MASK IN A BOOLEAN TAIL: `andi K ; sltu $zero,v` vs `srl n ; andi 1` is a ST |
+| L22389 | §211 | HOIST THE LOOP INIT ABOVE THE DOMINATING GUARD: it fills the guard's delay slot AND flips |
+| L22448 | §212 | THE WALKING CURSOR IS COUNTABLE: `*wp++` emits one `addiu` PER STORE, `wp[0..2]` emits one |
+| L22493 | §213 | INDEPENDENT SAME-BASE STORES: THE EMISSION ORDER IS A PERMUTATION OF SOURCE ORDER, AND THE |
+| L22529 | §214 | THE BANKED TWIN MAY BE A MACRO, A DELETED `.s`, OR A SEMANTIC INVERSE — six ways a ≥0.9 si |
+| L22575 | §215 | PIN ECONOMY: the twin's pins are NOT part of the shape, and §17's "pin every call-crossing |
+| L22631 | §216 | DISTINCT ADJACENT SCALARS vs ONE ARRAY: one `lui` per access is the tell, and the array de |
+| L22671 | §217 | DECODING A CALL'S STACK ARGUMENT SLOTS: `sw` at `0x10`/`0x14`/`0x18` are params 5/6/7 **(s |
+| L22697 | §218 | A NARROW TYPE AT THE ABI BOUNDARY COSTS AN IN-PLACE `sll/sra` PAIR — on the RETURN as well |
+| L22726 | §219 | COMPOUND `+=`, FULL ASSIGNMENT, AND AN EXPLICIT TEMP ARE THREE DIFFERENT SCHEDULES OF ONE |
+| L22753 | §220 | THE PARAMETER ITSELF IS A REGALLOC DIAL: use it directly, prefer `s32` to `void*`, and pla |
+| L22793 | §221 | A CONSTANT SHARED BY TWO STORES DIES AT THE CALL WHOSE DELAY SLOT REFILLS ITS REGISTER **( |
+| L22809 | §222 | SWITCH vs IF-CHAIN, PART 3: source arm order IS emission order, a leading EMPTY case buys |
+| L22851 | §223 | READING A `jal` DELAY SLOT: the value in it was produced BEFORE the call, so it is NEVER t |
+| L22913 | §224 | CROSS-JUMP: WRITE THE DUPLICATE, AND READ A SHARED DELAY SLOT AS THE MERGE SIGNATURE (P31 |
+| L22949 | §225 | THREE CONTROL-FLOW SHAPES NO STRUCTURED SPELLING REACHES (P31 S58) |
+| L22992 | §226 | FRAME PADS: FOUR WAYS §162i1/§2429's DEAD-LOCAL LEVER MISFIRES (P31 S58) |
+| L23033 | §227 | TYPE THE SOURCE BY THE **LOAD** WIDTH, NOT BY THE STORE WIDTH (P31 S58) |
+| L23053 | §228 | READING THE DIVIDE, PART N: the off-by-one compare is `% K == 1`, and three more discrimin |
+| L23090 | §229 | THE ADDRESS IS A VALUE: NAMING IT MOVES THE `lui`/`addiu` PAIR — AND §L14410 SAYS THE OPPO |
+| L23139 | §230 | THE ANCHOR PROBE: with `%hi`/`%lo` masked, the surviving `addiu` deltas tell you which ass |
+| L23154 | §231 | TRANSCRIPTION AND SEMANTIC-READ HYGIENE: six ways the listing misleads (P31 S58) |
+| L23195 | §232 | WHEN THE `jr` DELAY SLOT'S STORE STORES THE RETURN VALUE, TIE THEM WITH ONE PSEUDO **(sing |
+| L23231 | §30 | addendum (P31 S58) — the `/s` grant closes a SCHEDULING residual and a REGISTER residual w |
+| L23251 | §194-B | addendum (P31 S58) — BOUND 2 is byte-wrong; see §209 Direction A |
+| L23257 | §176-B | addendum (P31 S58) — the misdiagnosis direction |
+| L23263 | §165-40 | addendum (P31 S58) — the barrier goes at the COPY SITE, not inside the region it protects |
+| L23272 | §164-63 | addendum (P31 S58) — the interposed asm works when the SECOND value is an ordinary assignm |
+| L23281 | §193-A | / §194-E addendum (P31 S58) — where the twin's body actually lives |
+| L23287 | §233 | THE WAVE aa–bg HARVEST (P31 S58b): 1,101 byte-banked notes → 24 new laws, 21 addenda, ~700 |
+| L23331 | §234 | CONSTANT MATERIALISATION: THE STORE LVALUE'S SIGNEDNESS PICKS `addiu` vs `li`/`ori` (P31 S |
+| L23372 | §235 | THE PHANTOM SYMBOL: A MASKED `MATCH` CAN CARRY A RELOCATION THAT DOES NOT EXIST (P31 S58b) |
+| L23401 | §236 | THE DECLARATION LAYER IS THE DOMINANT BANK-BLOCKER: NINE WAYS A BYTE-PERFECT BODY FAILS TH |
+| L23480 | §237 | THE CAST-AT-CALL-SITE DECISION TABLE: WHAT §17a-1 FIXES, WHAT IT CANNOT, AND THE FOUR ESCA |
+| L23535 | §238 | SAME NAME, DIFFERENT FUNCTION: THE OVERLAY-HOMONYM TRAP (P31 S58b) |
+| L23575 | §239 | TWO-STATEMENT INTEGER-SPACE MATERIALISATION REORDERS `la` vs `sll`; AND THE PLUS-TREE OPER |
+| L23609 | §240 | `A + K + B`: WRITE THE CONSTANT **BETWEEN** THE TWO RUNTIME TERMS (P31 S58b) |
+| L23638 | §241 | THE FOLDED SIGN-EXTEND-AND-SCALE: `sll 16 ; sra (16 − log2 scale)` (P31 S58b) |
+| L23667 | §242 | `*k` vs `<>n`: EXPRESSION SPELLING OWNS THE LOAD WIDTH AND THE ROUNDI |
+| L23695 | §243 | SPELL THE CSE BARRIER AS A REASSIGNED POINTER; AND THE `nop`-AFTER-EVERY-`lh` SIGNATURE (P |
+| L23725 | §244 | `volatile` IS A COUNTING INSTRUMENT, A STORE-ORDER PIN, AND MUST SOMETIMES BE ASYMMETRIC ( |
+| L23760 | §245 | THE CALL'S ARGUMENT LIST IS A SCHEDULING SLOT (P31 S58b) |
+| L23807 | §246 | THREE-LIVE-VALUE SCAN LOOPS WANT ADDRESS-FROM-INDEX; AND TWO SYMBOLS CAN SHARE ONE giv (P3 |
+| L23847 | §247 | TWO BRANCHES TO **ONE** LABEL MEANS THE SOURCE CONDITION IS NEGATED (P31 S58b) |
+| L23881 | §248 | SPLIT THE LOAD FROM THE ARITHMETIC: A FUSED `g + K` DENIES THE CALLEE-SAVED REGISTER ITS D |
+| L23905 | §249 | THE SELF-ASSIGN, THE DEAD RE-ASSIGN, AND THE `+ zr` COPY: THREE WAYS TO MAKE A DELETED INS |
+| L23947 | §250 | `%hi/%lo` vs `lw`: THE EXTERN'S ARRAY-vs-SCALAR SHAPE DECIDES ADDRESS MATERIALISATION (P31 |
+| L23984 | §251 | IMMEDIATE-SPELLING TRIGGERS: `+= 0xFF`, FULL-WIDTH `~K`, AND THE TWO-OR SPLIT (P31 S58b) |
+| L24006 | §252 | THE GUARDED PRE-DECREMENT: `(x != 0) && (--x == 0)` (P31 S58b) |
+| L24027 | §253 | POSTFIX `++` vs `+= 1` PICKS A DIFFERENT SCRATCH REGISTER **(single observation — not yet |
+| L24041 | §254 | THE DEAD PARAMETER IS A REGISTER-PLACEMENT TOOL **(single observation — not yet cross-conf |
+| L24053 | §255 | THE EMPTY CASE, PART 2: FOUR TREE SHAPES IT BUYS (P31 S58b) |
+| L24088 | §256 | GOTOS IN THE TARGET'S BLOCK ORDER REPRODUCE SWITCH PLACEMENT WITHOUT SWITCH'S SIDE EFFECTS |
+| L24125 | §257 | THE DEAD-END LEDGER (P31 S58b): ELEVEN LEVERS THAT MEASURED NULL OR BACKFIRED |
+| L24168 | §258 | ADDENDA TO EXISTING SECTIONS (P31 S58b) |
+| L24173 | §30 | addendum (P31 S58b) — THE ANONYMOUS STRUCT MEMBER REF GRANTS `/s`, AND THAT IS A TWO-FOR-O |
+| L24194 | §194-B | / §209 addendum (P31 S58b) — TWO MORE INSTANCES, AND THE BOUND IS NOW REFUTED FOUR WAYS |
+| L24217 | §202 | addendum (P31 S58b) — THE DEF-SIDE ALIAS ALSO CLEARS A RETURN+PARAM DOUBLE CONFLICT |
+| L24228 | §205 | addendum (P31 S58b) — CHAINED ASSIGNMENT: N≥3 IS INNERMOST-FIRST, AND THE TEXT MIRRORS EMI |
+| L24245 | §208 | addendum (P31 S58b) — IT SCALES TO SIX SITES, AND IT HAS AN EXACT INVERSE |
+| L24274 | §210 | addendum (P31 S58b) — THREE CONFIRMED SPELLINGS OF THE BOOLEAN TAIL |
+| L24290 | §211 | addendum (P31 S58b) — INIT PLACEMENT: FIVE MORE DIALS BEYOND THE GUARD HOIST |
+| L24333 | §213 | addendum (P31 S58b) — THREE MORE PERMUTATION LAWS FOR INDEPENDENT SAME-BASE STORES |
+| L24362 | §214 | addendum (P31 S58b) — FOUR MORE WAYS A HIGH-SIMILARITY TWIN LIES |
+| L24398 | §215 | addendum (P31 S58b) — PIN ECONOMY, PART 2: NINE REFINEMENTS |
+| L24450 | §217 | CROSS-CONFIRMED (P31 S58b) — AND THE INCOMING HOME SLOT IS THE MIRROR |
+| L24467 | §220 | addendum (P31 S58b) — THE PARAMETER, NOT A COPY (SEVEN CARDS) |
+| L24492 | §222 | addendum (P31 S58b) — IF-CHAIN vs SWITCH: THREE MORE DISCRIMINATORS |
+| L24510 | §223 | addendum (P31 S58b) — FIVE MORE CONFIRMATIONS, AND THE CONSTANT-IN-`$v0` CASE |
+| L24534 | §224 | addendum (P31 S58b) — CROSS-JUMP MERGES *CALLS*, AND THE DELAY SLOT IS THE DISCRIMINATOR |
+| L24564 | §225 | addendum (P31 S58b) — THE GUARD-CLAUSE FINGERPRINT, AND THREE MORE SHAPES |
+| L24591 | §226 | addendum (P31 S58b) — THE FRAME CATALOGUE: SEVEN MORE LEVERS, AND SLOT ORDER IS DECLARATIO |
+| L24636 | §229 | addendum (P31 S58b) — NAME IT **INSIDE** THE ARM |
+| L24647 | §230 | CROSS-CONFIRMED (P31 S58b) |
+| L24656 | §231 | addendum (P31 S58b) — FOUR MORE WAYS THE LISTING MISLEADS |
+| L24687 | §232 | CROSS-CONFIRMED (P31 S58b) |
+| L24698 | §259 | THE DISCARD LEDGER FOR THE aa–bg HARVEST (P31 S58b): WHAT WAS MINED AND REJECTED, AND WHY |
+| L24737 | §260 | THE §154-A LEADING-ISLAND SPLIT: ONE CONFIG LINE, AND THE ISLAND PEELS FROM THE END (P31 S |
+| L24787 | §260-A | STAGE 2 IS PROVEN, AND THE WHOLE jtbl PIPELINE IS AUTOMATED AT THE GATE (P31 S59, same day |
+| L24823 | §261 | THE -O0 ORACLE: DERIVE THE OPT LEVEL FROM THE TARGET, AND `$fp` IS NOT THE TELL (P31 S59) |
+| L24849 | §261a | THE -O0 FRAME-RELOAD GRAMMAR: reload COUNT disambiguates the C spelling (P31 S59, byte-pro |
+| L24871 | §262 | A LANE'S YIELD IS ONLY A LANE FACT IF IT IS SIZE-MATCHED (P31 S59) |
+| L24901 | §263 | A STOLEN DELAY SLOT WHOSE INSTRUCTION IS AN ARG-REGISTER COPY IS AN ARITY ERROR, NOT A SCH |
+| L24942 | §264 | FOUR TELLS-LANE C RECIPES, EACH DRIVEN TO MATCH (P31 S59) |
+| L24992 | §265 | THE VERBATIM-ASM BANK LANE: A FUNCTION NO -O2 C CAN EVER MATCH BANKS AS A RAW `__asm__` BO |
+| L25054 | §266 | THE INERT-RIDER LAW: A LEVER IS ONLY CITABLE WHEN ITS SOLO REMOVAL BREAKS THE MATCH (P31 S |
+| L25094 | §267 | ADDENDA HARVESTED FROM WAVES at/bh/bk/bl (P31 S59b) |
+| L25102 | ADD-1 | → §231 addendum (also cross-ref from §195-D) — THE MASKED-`jal` "MISSING CALL" ILLUSION |
+| L25111 | ADD-2 | → §42a addendum — A SHARED CONSTANT *NAMED IN A LOCAL* ACROSS A `jal` IS AN ISO→TU DRIFT H |
+| L25123 | ADD-3 | → §236, item 10 — THE UN-DELETED `INCLUDE_ASM` STUB IS A DUPLICATE DEFINITION |
+| L25133 | ADD-4 | → §225-3/-4 addendum — THE MIRROR ROW: VALUE-RETURN IN THE *TAKEN* ARM + TRAILING BARE `re |
+| L25147 | ADD-5 | → §1/I1 addendum — THE INVERTED RANGE TEST: `(u32)(x-lo) >= N` WITH THE ZERO-ARM AS THE TR |
+| L25156 | ADD-6 | → §172b-1 / §264 addendum — SHIFT-AS-TEST: `(x << 16) != 0` TESTS THE LOW HALF WITHOUT TRU |
+| L25165 | ADD-7 | → §256 addendum — THE SINGLE-GUARD GOTO: THEN-BLOCK OUT OF LINE AT THE TAIL |
+| L25177 | ADD-8 | → §245 addendum — THE RE-TIE BARRIER PINS CALL-ARG SETUP TO SOURCE ORDER (construct 6) |
+| L25189 | ADD-9 | → §213-3 / §217 addendum — ADJACENT PRE-CALL FRAME STORES ARE ONE AGGREGATE; THE UNESCAPED |
+| L25199 | ADD-10 | → §237 addendum (arity-evidence paragraph) — AN `la` PAIR ABOVE THE PROLOGUE `sw $ra` IS A |
+| L25208 | ADD-11 | → Cross-confirmation card block (per §259's standing instruction: confirmation, not news) |
+| L25259 | §268 | A `register __asm__` PIN ON A CALL-CLOBBERED REGISTER IS HONORED EXACTLY WHEN THE PINNED R |
+| L25313 | §269 | ADDENDA HARVESTED FROM WAVES ax/bm (P31 S59c) |
+| L25328 | ADD-1 | → §257-8 addendum — THE INTERPOSED ASM'S `__volatile__` IS A PER-SHAPE DIAL, AND THE "NO-O |
+| L25341 | ADD-2 | → §236 addendum (item 1 corollary) — THE SILENT-SPLICE DECLARATION LADDER: WHERE THE TU HA |
+| L25355 | ADD-3 | → §238 addendum — TWO BINARIES CAN EACH DEFINE THE SAME `func_` NAME WITH DIFFERENT BYTES, |
+| L25368 | ADD-4 | → §167-37 addendum — THE FIFTH PRECONDITION, NOW MEASURED: DOWNSTREAM FIELD RE-READS ⇒ NAM |
+| L25385 | ADD-5 | → §267-ADD-6 / §172b-1 addendum — THE SIGN-TEST FACE: `(s16)v < 0` IS `sll 16` + `bgez` ON |
+| L25401 | ADD-6 | → §220-addendum — THE FOURTH FACE: WHEN THE NAMED COPY ITSELF BUYS THE EXTRA CALLEE-SAVED, |
+| L25417 | ADD-7 | → §229 addendum — THE VALUE FACE: A LOOP-STORE CONSTANT SPELLED AS A LITERAL HAS NO SOURCE |
+| L25430 | ADD-8 | → §30a addendum — THE THIRD COLUMN: `*p++` IS ALSO SERIALIZED BUT BURNS `addiu`; ONLY CAST |
+| L25445 | ADD-9 | → §255 "AND CASE-BODY PLACEMENT" bound / §222-addendum-3 — ON A LARGE SPARSE TREE, BODIES |
+| L25459 | ADD-10 | → Cross-confirmation card block (per §259's standing instruction: confirmation, not news) |
+| L25500 | §3-1a. | The §266 sweep — every solo-lever A/B run for this batch |
+| L25533 | §270 | The A-prop 0-bank anatomy: a byte-correct body still needs FOUR layers to agree (P31 S59) |
+| L25551 | §271 | Ordinal IMM pairing: text order is NOT emission order; emit CANDIDATES, let the oracle pic |
+| L25573 | §272 | The `(void)`-decl + empty-call wall: K&R the DEFINITION, not just the decls (P31 S59) |
+| L25593 | §273 | A standalone compile is the WRONG oracle for a TU-destined draft (P31 S59) |
+| L25608 | §274 | ADDENDA HARVESTED FROM 18 WAVES (P31 S60): 315 candidates, 255 already covered, 21 sharpen |
+| L25614 | ADDENDUM | to §179-C — the `.type NAME, @function` requirement |
+| L25661 | ADDENDUM | to §134 — a typedef defined BELOW the splice point is stripped anyway |
+| L25691 | ADDENDUM | to §179-D (GTE macro reference family) — `gte_SetRotMatrix`/`gte_SetTransMatrix` bodies |
+| L25717 | ADDENDUM | to §82 — struct copies must stay MEMBER-WISE, not block-moved, to match a spill-slot save |
+| L25755 | ADDENDUM | to §136d-1 (RC-12, the `$0`-add / opaque-copy family) — two symptoms beyond "compare reads |
+| L25794 | ADDENDUM | to §20 — a global declared as `T *` may itself BE the array base, not a pointer to derefer |
+| L25823 | ADDENDUM | to §1-I5 |
+| L25888 | ADDENDUM | to §164-51 |
+| L25904 | ADDENDUM | to §176-F5 |
+| L25933 | ADDENDUM | to §225 |
+| L25978 | ADDENDUM | to §224 — CROSS-JUMP: THE DUPLICATE CAN BE A PLAIN STORE, NOT ONLY A CALL |
+| L26012 | ADDENDUM | to §164-64 — AN EMPTY CLOBBER ON AN ARGUMENT REGISTER CAN BE THE DELIBERATE FIX, NOT JUST |
+| L26043 | ADDENDUM | to §244 — THE COMPILER BARRIER, NOT `volatile`, BLOCKS A STORE→LOAD HOIST THROUGH A POINTE |
+| L26074 | ADDENDUM | to §172b-1 — TWO PLACEMENT DIALS THE PROMOTION LAW DOESN'T NAME: NARROW THE COUNTER'S DECL |
+| L26121 | ADDENDUM | to §229 — A POINTER'S NUMBER OF USES DECIDES WHETHER ITS ADDRESS FOLDS OR SURVIVES A CALL |
+| L26166 | ADDENDUM | to §172b-4 — THE PLAIN CAST-DIVISION ALREADY PRODUCES THE PATTERN; DON'T HAND-ROLL THE BIA |
+| L26196 | ADDENDUM | to §8 — WHEN `INCLUDE_RODATA` NEEDS A STANDALONE `.s` YOU CAN'T CREATE, CARRY THE FRAGMENT |
+| L26239 | ADDENDUM | to §226 — A DEAD LOCAL SCOPED TO A NESTED BLOCK BUYS A MID-FUNCTION `addiu sp` PAIR, NOT A |
+| L26278 | ADDENDUM | to §172a — RE-READING MEMORY (NOT NAMING A TEMP) IS WHAT KEEPS AN INCREMENT'S DELAY-SLOT F |
+| L26309 | ADDENDUM | to §225 / §256 — A GOTO TO A SHARED SET-POINT PREVENTS IF-CONVERSION FROM COLLAPSING A LAT |
+| L26351 | ADDENDUM | to §211 — AN IN-LOOP ACCUMULATOR WANTS A CLOSED-FORM EXPRESSION WHEN THE TARGET REMATERIAL |
+| L26386 | §275 | THE LEFTOVER-REGISTER READ |
+| L26426 | §276 | MIXED ADDRESS-EXPRESSION SPELLING FOR ADJACENT RELOCATABLE SYMBOLS IS A CSE-UNIFICATION DI |
+| L26535 | §277 | RETURN-TAIL C SPELLING PICKS THE DELAY-SLOT-FILL vs TRAILING-MOVE TOPOLOGY, AND A NARROWER |
+| L26599 | §278 | ADDENDA HARVESTED FROM WAVE cf (P31 S60): 34 candidates, 13 already covered, 8 sharpenings |
+| L26607 | ADDENDUM | to §74 (func_800D0E30, resident) |
+| L26643 | ADDENDUM | to §172b-4 (func_80185054, ov_SC03_097) |
+| L26681 | ADDENDUM | to §265 (func_8017DC80, ov_SC07_002) |
+| L26720 | ADDENDUM | to §17 (func_800CB794, md_MAIN_036) |
+| L26768 | ADDENDUM | to §162p (func_8017C120, ov_MAIN_012) |
+| L26802 | ADDENDUM | to §20 (~L1947) (func_80186AD0, ov_SC06_032) |
+| L26832 | ADDENDUM | to §164-56 (func_8017F644, ov_SC04_005) |
+| L26867 | ADDENDUM | to §237 (func_8017F7FC, ov_SC03_092) |
+| L26896 | §279 | A `do/while (p < end)` LOOP UNDER AN ENTRY GUARD: the guard decides the compare, not the l |
+| L26897 | §NNN | A DO-WHILE'S GUARD AND LATCH MUST REPEAT THE SAME BOUND EXPRESSION, NOT SHARE ONE LOCAL: T |
+| L26930 | §280 | THE CURSOR'S DECLARED TYPE PICKS `sltu` vs `slt`: a `T*` bound test is UNSIGNED by C rule, |
+| L26931 | §NNN | A LOOP CURSOR'S C TYPE (POINTER vs PLAIN INTEGER) SELECTS `sltu` vs `slt` FOR ITS BOUND TE |
+| L26964 | §281 | GROUP COPY-THEN-RMW BY OPERATION KIND, NOT FIELD BY FIELD: sched1 does the interleaving, t |
+| L26965 | §NNN | A DEPENDENT COPY-THEN-RMW BLOCK MUST BE SOURCE-GROUPED BY OPERATION KIND, NOT BY FIELD, AN |
+| L27010 | §282 | gcc's OWN LOOP REVERSAL PUTS THE COUNTER INIT AFTER THE HOISTED MOVABLES — a position no h |
+| L27011 | §NNN | WRITE THE UP-COUNT LOOP: gcc's OWN REVERSAL PRODUCES A COUNTER-INIT INSTRUCTION THAT LANDS |
+| L27048 | What | I could not verify |
+| L27095 | §283 | ADDENDA HARVESTED FROM THE 36-WAVE BATCH (P31 S60): 1,216 candidates, 859 already covered, |
+| L27105 | ADDENDUM | to §164-75 — the fold-reassociation law also fires at a variable's INITIALIZER, not only a |
+| L27131 | ADDENDUM | to §21 — the `bltz`+`slti` (or N-separate-compares) signed-range-split bullet is now CONFI |
+| L27177 | ADDENDUM | to §202 — the DEF-SIDE ALIAS also resolves a function-vs-DATA-symbol identifier clash, not |
+| L27200 | ADDENDUM | to §22 (`volatile`-qualified-global reload lever, cookbook ~L1922) — for a NON-constant, s |
+| L27219 | ADDENDUM | to §195-E — a goto-ladder's STORES must sit AT the labels, after the gotos, not inline bef |
+| L27281 | ADDENDUM | to §195-N — a GNU statement-expression slider must sit INSIDE the conditional arm's value |
+| L27338 | ADDENDUM | to §176-B2 — in a micro-function with no long/short lifetime asymmetry, BOTH contending ps |
+| L27385 | ADDENDUM | to §199-G — A `default:` LABEL GROUPED ONTO THE LAST CASE REMOVES THE `j default` TAIL, EV |
+| L27454 | ADDENDUM | to §220 — REFERENCING THE RAW PARAMETER (NO NAMED COPY, NOT EVEN A PIN) LETS THE CALLEE-SA |
+| L27512 | ADDENDUM | to §252 — a `>=0`/`<0` split on an unconditionally-decremented value needs the POSTFIX ope |
+| L27539 | ADDENDUM | to §215 — FIFTH SHAPE: reused mask constants across two call-free merge sites each get the |
+| L27622 | What | I could not verify |
+| L27693 | Harness-defect | flags |
+| L27786 | ADDENDUM | to §167-40 (func_8017E2CC, ov_SC04_015 — wave dg) |
+| L27806 | ADDENDUM | to §20's cross-jump EXPLOIT bullet (func_8017E360, ov_SC05_007 — wave dg) |
+| L27820 | ADDENDUM | to §87 (func_801815F4 ov_SC06_032; corroborating func_801840DC ov_SC05_017, func_80189C68 |
+| L27839 | ADDENDUM | to §153 / §236-5 (func_801A419C, md_SC07_003 — waves di and dl, corroborating; refutes a c |
+| L27859 | ADDENDUM | to §263 (func_801E83AC, md_SC04_029 — wave dj) |
+| L27873 | ADDENDUM | to §265 (func_8017D878, ov_SC03_107 — wave dj; corroborated by a REJECTED, contradicted ca |
+| L27887 | ADDENDUM | to §6 (func_801811F0, ov_SC03_102 — waves dj and dl, corroborated by a self-reported "noth |
+| L27901 | ADDENDUM | to §195-G (func_80183BB0, ov_SC05_001 — wave dj) |
+| L27929 | ADDENDUM | to the zero-byte-asm-slider family (§47 / §148-C / §153) (func_800CB874, md_MAIN_040 — wav |
+| L27947 | ADDENDUM | to §194-B (func_8017EB34, ov_SC03_117 — wave dk; distinct from the §74 co-pinning finding |
+| L27979 | ADDENDUM | to §74 (func_8017EB34, ov_SC03_117 — counter/clamp variant; wave dj, corroborated by dk/dl |
+| L27999 | ADDENDUM | §37 — merged into the §153/§236-5 entry above (func_801A419C, wave dl) |
+| L28007 | ADDENDUM | §6 — merged into the §6 entry above (func_801811F0, wave dl) |
+| L28015 | ADDENDUM | to §238 (func_80182CB4, ov_SC02_000 — wave dl) |
+| L28033 | ADDENDUM | to §137a (func_801684B4, ov_MAIN_012; corroborated independently by func_80189E68, func_80 |
+| L28049 | ADDENDUM | to §8c / §88d (func_8016AB6C, ov_MAIN_012 — wave dm) |
+| L28063 | ADDENDUM | to §73 / §30#2 (func_800D1984, resident — wave dm) |
+| L28079 | What | I could not verify |
+| L28099 | ADDENDUM | to §174 Law 4 (func_8017E9A8, ov_SC06_015) |
+| L28139 | ADDENDUM | the zero-emission-asm family gains a REF-SLIDER PLACEMENT LAW and a paired RESTORER (func_ |
+| L28191 | From | ck + cl + cm |
+| L28197 | ADDENDUM | §NNN — sharpens §55a / §164-37 / §165-28 (switch-vs-tree cluster): A SHAPE THAT LOOKS LIKE |
+| L28234 | ADDENDUM | §NNN — sharpens §167-13's boundary: CHAINING TWO IDENTICAL SIDE-BY-SIDE STORES INTO ONE C |
+| L28267 | ADDENDUM | §NNN — sharpens §162a3/§60b: A `sll $v0,16 / sltiu $v0,1` ZERO-TEST OF A JUST-DECREMENTED |
+| L28300 | ADDENDUM | §NNN — sharpens §37/§124 (unspecified-parameter-list family): DERIVE A CALLEE'S ARITY LOWE |
+| L28333 | ADDENDUM | to §5a (func_80181F74, ov_SC03_112, wave cn) |
+| L28383 | ADDENDUM | to §265 (func_8017E26C, ov_SC04_016, wave cn) |
+| L28421 | ADDENDUM | to §42b (func_8018247C, ov_SC07_002, waves cu + cw) |
+| L28452 | ADDENDUM | to §199-F family (func_8017EFB0, ov_SC02_021, wave cu) |
+| L28507 | ADDENDUM | to §195-E (func_800CFC1C, md_MAIN_003, wave cv) |
+| L28552 | ADDENDUM | to §215 addendum (func_800CB2C8, md_MAIN_033, waves cv + cw) |
+| L28608 | ADDENDUM | to §236 item 4 (func_8017D268, ov_SC04_006, wave cw) |
+| L28637 | What | I could not verify |
+| L28669 | Harness-defect | flags (not idioms — flagged for the operator) |
+| L28710 | ADDENDUM | to §250 (func_8017D7CC, ov_SC03_115 — cx/cy/cz/dr) |
+| L28755 | ADDENDUM | to §225 (func_8017E190, ov_SC03_115 — cx/cy/cz) |
+| L28808 | ADDENDUM | to §45-A (func_8017F6A4, ov_SC02_016 — cy/cz) |
+| L28852 | ADDENDUM | to §249 (func_80182ED4, ov_SC04_004 — dp/dr/dt) |
+| L28897 | ADDENDUM | to §199-A (func_801816FC, ov_SC02_005 — dp/dr/dt) |
+| L28943 | What | I could not verify |
+| L28986 | Harness-defect | flags |
+| L29048 | §284 | COMBINE CAN REASSOCIATE TWO SEQUENTIAL BITWISE-AND MASKS INTO ONE AGAINST THE PRE-MASK VAL |
+| L29052 | §285 | PRE-INITIALIZING A VARIABLE WITH A SHARED CONSTANT BEFORE A BRANCH MAKES BOTH ARMS OF THE |
+| L29056 | §286 | FOLD A STATEMENT'S SIDE EFFECT INTO A COMMA-EXPRESSION IN AN ARGUMENT POSITION TO PLACE IT |
+| L29060 | §287 | A STACK-FRAME HOLE BELOW TWO ADDRESS-TAKEN AGGREGATE LOCALS IS A LEADING PAD MEMBER OF ONE |
+| L29064 | §288 | A REGISTER PIN DECLARED UNINITIALIZED AND ASSIGNED ONLY AT ITS LATE, SOLE USE STILL FORCES |
+| L29068 | §289 | an array local's address-taken base keeps every element's store alive, even though only on |
+| L29072 | §290 | A SINGLE STRENGTH-REDUCED GIV CAN DRIVE STORES TO SEVERAL DISTINCT RELOCATABLE SYMBOLS, EA |
+| L29076 | §291 | THE DELAY-SLOT FALSE-VALUE: A CONDITIONAL BRANCH'S ZERO ARM MUST BE A FALL-THROUGH-ADJACEN |
+| L29080 | §292 | DECLARING A SYMBOL UPSTREAM OF AN ALREADY-BANKED SIBLING THAT RELIES ON THAT SYMBOL'S IMPL |
+| L29083 | §293 | THE "WHOLE-OBJECT GATE NEEDS EVERY SIBLING" LAW, WRITTEN PROPERLY: IT IS THREE LAWS, AND T |
+| L29133 | §294 | ADDENDA HARVESTED FROM THE S61 GEN0/MAXTOK/MAIN/DEEPSEEK BATCH (waves ab8/ab16/ab24/ab32 · |
+| L29144 | ADDENDUM | to §127 — the -O0 constant-offset fold keys on the MEMBER-ACCESS tree shape, not on the in |
+| L29172 | ADDENDUM | to §261a — FOUR MORE -O0 DIALS BEYOND THE RELOAD COUNT (boot.c + md_MAIN_011/003, wave m0a |
+| L29222 | ADDENDUM | to §264-3 — the explicit entry copy's BOUND: required exactly when the RAW value must outl |
+| L29242 | ADDENDUM | to §172b-1 (counter-type dial) — the sll's SOURCE REGISTER is the placement discriminator |
+| L29254 | ADDENDUM | to §276 — the SHARE direction: spell the second adjacent symbol RELATIVE to force ONE anch |
+| L29270 | ADDENDUM | to §31's density-dummy dial (L2460/L2497) — the dose is TWO refs, and the dummy must sit w |
+| L29287 | ADDENDUM | to §282 — the ADDRESS-GIV face: write the walked address INLINE so strength reduction birt |
+| L29310 | ADDENDUM | to §253 — SECOND byte-proven card (upgrade from single-observation), and the placement fac |
+| L29331 | ADDENDUM | to the L1800 anchor-steer bullet — a DERIVED-POINTER local silently flips the merged giv's |
+| L29354 | ADDENDUM | to §31's asm→layout inference — TWO WIDTH-PAIR DISCRIMINATORS (same offset, different widt |
+| L29375 | §295 | THE KERNEL-TRAP STUB: §81's jr-DETECTOR WITHOUT A TABLE IS A PsyQ SYSCALL TRAMPOLINE — ROU |
+| L29430 | §296 | THE FRAME CHECK OUTRANKS THE ATLAS LEVER: READ PROLOGUE/EPILOGUE BEFORE DRAFTING ANY C — A |
+| L29473 | §297 | ONE GIV SERVING MIXED-WIDTH LOADS *AND* A STORE NEEDS STRUCT-MEMBER SPELLING; CAST/INDEX S |
+| L29516 | §298 | THE SHARED-TAIL POSITION DIAGNOSTIC: A FOLDED TAIL *BETWEEN* SWITCH ARMS MEANS PER-ARM DUP |
+| L29541 | §299 | TWO INDEPENDENT EXTRACTION CHAINS EMIT CONTIGUOUSLY INSIDE ONE EXPRESSION; ONLY A STATEMEN |
+| L29576 | §300 | S61 DISTILL BATCH NOTES (waves ab8/ab16/ab24/ab32 · g0a–g0f · m0a · ds1/ds2 · m0b) |
+| L29645 | §301 | AN INTERNAL `j` CARRIES `R_MIPS_26 .text`: rtu/match_one "MATCH" COULD NOT SEE WHICH LABEL |
+| L29693 | §302 | A RED BINARY IS A DRIFTED SPEC, NOT A MYSTERY: THE THREE CARVE-STATE INVARIANTS AND HOW TO |
+| L29737 | §303 | MODULE ISLAND TABLES: DERIVE THE PADS AT BUILD TIME, PEEL NOTHING — THE §154-A/§260 "islan |
+| L29773 | §304 | SELF-DEFINING RODATA: WHEN A FUNCTION'S `.s` IS THE ONLY OWNER OF THE DATA IT REFERENCES, |
+| L29796 | §305 | "CARVE-REFUSED" AT GATE TIME IS THREE NAMED, DETERMINISTIC CLASSES — NONE OF THEM A CARVE |
+| L29848 | §306 | A HAZARD `nop` IN FRONT OF A DIV-RESULT STORE IS A STATEMENT-ORDER DEFECT: THE INDEPENDENT |
+| L29875 | §306a | T4 DISTILL ADDENDA (P31 S62; four byte-proven refinements to existing laws, verified again |
+| L29913 | §307 | THE BRUTE-FORCE-THE-STATEMENT-ORDERS LEVER HAS A BOUND: A FAN-OUT COPY'S PRIORITY IS SCHED |
+| L29957 | §308 | A NAIVE FINAL `goto` DELETES THE TARGET'S `j`+`nop`: SPELL THAT EDGE AS A TAUTOLOGICAL `if |
+| L29986 | §308a | A TWO-INSTRUCTION ARM STUB LAID *BEFORE* THE OTHER ARM AND REACHED ONLY BY A TRAILING `j` |
+| L30020 | §309 | A FRAME-ADDRESS EQUIVALENCE RIDES *THROUGH* A SKIPPABLE CONDITIONAL: POST-`if` STORES FOLD |
+| L30060 | §310 | A TWO-OPERAND `subu`'s DESTINATION TIES ONLY TO THE OPERAND THAT IS BLOCK-LOCAL: SHARE *ON |
+| L30091 | §311 | A JOIN-BLOCK STORE CAN SWALLOW AN ARM'S LOAD-DELAY `nop`: WHEN ONE ARM'S VALUE COMES FROM |
+| L30133 | §312 | A BARE RELATIONAL IN AN `if` GIVES THE `slt` NO TARGET: ASSIGN THE COMPARISON INTO THE ALR |
diff --git a/docs/matching-cookbook.md b/docs/matching-cookbook.md
index 72f86116e..70709f5c3 100644
--- a/docs/matching-cookbook.md
+++ b/docs/matching-cookbook.md
@@ -2709,6 +2709,21 @@ tie in `global.c`): compiles fine, wrong bytes → exactly an R17/§45-B target.
## §41 — The DEF-SIDE canonical-sig wall: mechanically banking a drafted giant past `conflicting types` (Phase 25 T5b batch-2, 2026-07-09; `tools/canon_sig_reconcile.py`, byte-proven on `func_8013B274`)
+**Addendum (P31 S64 t5o-t5r, func_8017BEBC @ ov_SC03_007, 246 ins) — A FINDABILITY KEY, not a new law.** §41 step 3
+("Cast each type-changed param AT ITS USES — NEVER via an intermediate local") also owns a purely **REGALLOC**
+symptom, and this section's declaration-wall title hides it: a drafter hunting a register residual greps past §41
+entirely. **The tell:** a closeness plateau that will NOT move under clamp / loop-shape / integer-width levers,
+with the instruction COUNT already exact, on a function whose C declares `T *out = (T *)paramN;` and stores through
+`out[i]`. The named alias is a fresh pseudo — gcc gives it its own register, which frees the incoming arg register
+for a competing tail temp and shifts the whole prologue schedule. Casting in place at each store
+(`((T *)paramN)[i] = …`) adds no pseudo and is byte-free. **Byte evidence:** n7 (`s16 *out = (s16 *)a1; out[i] = …`)
+= near, closeness 17, nins 246; n9 (same body, alias deleted, `((s16 *)a1)[i] = …`) = **MATCH, closeness 0, nins 246**;
+n11 re-confirms. **⚠ The decl-order control is INERT (§67):** n10 swapped the two pointer locals' declaration order,
+kept the alias, and stayed at 17 — so an unchanged closeness under reordering does NOT exonerate the alias. This is
+the FOURTH confirmation of §41 step 3 / §67's two-pseudo law, and the transcript printed only aggregate
+`status closeness nins` lines, so it sharpens findability, not the mechanism.
+
+
**The wall (dominant for GIANTS — ~universal, vs ~35% clean-bank for small fns):** a drafter writes an
**isolation-MATCH** giant body (`match_one` c=0) with Ghidra-derived **TYPED** params — `void func(u32 *a0, s16 *a2)`.
Placed in the real overlay TU it fails the whole-binary gate on `conflicting types for func_X` (a *declaration*
@@ -30113,3 +30128,30 @@ else { *(s32 *)(p + 0x14) = TBL[*(u8 *)(p + 5)]; }
**BYTE EVIDENCE.** `func_8017D7E0` (ov_SC06_033, 166 ins, banked at `src/ov_SC06_033/ov_SC06_033_jr_8017C24C.c:3568-3572`). v3 (pointer-CSE, `val` temp present): `closeness 22 / nins 165 / LENGTH-DRIFT/-1?` at 127, `explains: partial`. v4a/b/c reordered the tail statements around the temp — **inert, still 22**, which is what rules out §176-A2's statement-move lever. v5 (temp deleted, store duplicated into both arms): **closeness 2, nins 165 → 166, the LENGTH-DRIFT class gone entirely**, leaving only an unrelated 2-insn operand-order residual at `[127,128]`. The final 2 → 0 came one step later from an ordinary source-order edit (`D_801274EA` before `D_801274EC`, inlining a `(u16)` cast condition) — §176-A / §165-14 territory, **not part of this law**. *Re-read at vet time out of the banked object:* `objdump` of the banked build shows `nop` at 0x240 and exactly **one** `sw $v0,0x14($s1)` at 0x244 — the merge is visible in the bytes, and 0x240/4 = 144 is the residual's own index.
**⚠ MECHANISM BOUND (R14).** No `-dS`/`-dR` dump was taken. The step "an independent join-block insn covers the cross-block hazard" is read off the final stream plus the pass order, not off the scheduler; `-dS` on the two spellings is the cheap confirmation and has not been run. What is **measured** is: the temp spelling is −1 with the `nop` absent, the duplicated spelling restores it at the correct byte, and the object still emits only one store.
+
+
+## §312 — A BARE RELATIONAL IN AN `if` GIVES THE `slt` NO TARGET: ASSIGN THE COMPARISON INTO THE ALREADY-ALLOCATED VARIABLE TO CHOOSE ITS DESTINATION REGISTER, AT ZERO INSTRUCTION COST (P31 S64 t5o-t5r; byte-proven func_80180DCC)
+
+*(NEW axis, not a restatement. §164-38/§164-39 and §164-39's t5j-t5m addendum own the compare's **INPUT** colouring — which operand got which register — and their levers are the in-out fence on operand 0 and the relational transposition; both are the wrong door when the inputs are already correct. §197-C/§164-64 own "write it IN PLACE so the destination **is** an existing pseudo" for `*`/`+`/`|`/`&`; this extends that lever to the relational operator, where §197-C's companion note — "a pinned pseudo can never be the load's destination" — had left the impression that a pin cannot own a computed dest at all. §164-65 also names a value you were going to consume inline, but its payload is allocno REF COUNT, not `SET_DEST`. §195-E is the other naming law and is about whether a 0/1 **materialises** at a join; here naming is length-neutral, which is exactly what makes this lever free.)*
+
+**THE TELL.** The target's `slt` writes back into one of its **own two source registers** — an in-place compare, `slt $v0,$v0,$v1` — and is immediately consumed by a `bnez`/`beqz` on that same register. Your draft emits the identical pair with **every operand register already correct and only the destination one register over**: `match_one` reports `REGALLOC-PERM` with a single-register cycle (`{"$v1":"$v0"}`, `kinds:{"reg":2}`), residual exactly 2 instructions — the `slt` and its branch — and zero length drift. That is not structure and it is not input colouring; nothing but the compare's `SET_DEST` is wrong.
+
+**THE MECHANISM — INFERRED, NOT TRACED (cite as a place to look, never as proven pass behaviour; §164z / §137's bar).** A truth value used only inside an `if` reaches `do_jump`/`expand_expr` with no fixed target, so the `slt`'s destination is synthesised from whatever pseudo is cheapest at that point, tied to **neither** compared operand — which is why it can land one register away even when both operands are correctly pinned. Writing the comparison as an assignment hands `expand_expr` an explicit target pseudo and `store_expr` honours it, forcing the `slt`'s `SET_DEST` to that variable's hard register. No `-dS`/`-dg`/`-dl`/`-dg` dump was taken; `local-alloc.c combine_regs`' tie-to-a-dying-source-operand (§10 Residual A) is the other place worth dumping first if this recurs.
+
+**THE C SHAPE.**
+
+ /* wrong — dest register unpredictable */
+ if (v0 < v1) { goto TRUE1; }
+
+ /* right — forces the slt's dest into v0's pinned hard reg */
+ v0 = (v0 < v1);
+ if (v0 != 0) { goto TRUE1; }
+
+ /* v0 is `register s32 v0 __asm__("$2")`; v1 a sibling pinned s16-cast temp,
+ `register s32 v1 __asm__("$3")` */
+
+The two spellings cost the **same instruction count** — a bare relational has no join and no constant arms, so §195-E's "naming materialises a 0/1" does not fire and the naming is byte-free apart from the register it buys.
+
+**BYTE EVIDENCE.** `func_80180DCC`, 66 ins, all quotes from `match_one --json` on the pinned triple. v0 (backlog draft, `register s16 s1` pin + call-site `(s16)` casts) → closeness 9, `STRENGTH/sll!=sra`. Unpinning `s1` → closeness 6, same sig (block 2 clean, block 1's `sll/sra/slt/bnez` still wrong). v6 (pin `register s32 v1 __asm__("$3")`, hoist `v1 = (s16)s1; v0 = (s16)v0;` as statements ahead of a still-bare `if (v0 < v1)`) → **6 → 2**: `{"status":"near","closeness":2,"residual":[[34,"0043182a slt v1,v0,v1","0043102a slt $v0, $v0, $v1"],[35,"14600013 bnez v1,…","14400013 bnez $v0, .L80180EA8"]],"verdict":{"klass":"REGALLOC-PERM","sig":"REGALLOC-PERM/$v1>$v0","detail":{"map":{"$v1":"$v0"}}}}`. v7, the **only** change being `if (v0 < v1) {…}` → `v0 = (v0 < v1); if (v0 != 0) {…}` → **2 → 0**: `{"status":"match","closeness":0,"residual":[],"verdict":{"klass":"MATCH"}}`.
+
+**BOUND.** (1) n = 1. (2) Only the **v6 → v7** delta is solo-proven (§266): the pins and the cast hoist arrived in compound edits and are co-requisites of the shape, not separately ablated — the pin is what makes "the variable's hard register" a nameable thing here, and an unpinned local would only move the dest to whatever that local got. (3) Routing: on a REGALLOC-PERM whose single wrong register is the compare's **DEST**, try this first — one statement, zero bytes; go to §164-39's fence or its addendum's transposition only when the wrong register is one of the compare's **INPUTS**. (4) Says nothing about compare-against-constant shape (`slti`/`sltiu` immediate-vs-register is §194-L's 2-D lookup) or about signedness (§280).