docs(phase-30 S44 I.0): the static loader routing table + the full tool audit — knowledge captured

Plan-approved campaign (Fable5Max, ~/.claude/plans/optimized-squishing-engelbart.md). I.0 = capture
while hot (R30/R31), before any code:

- memory-map.md §"Phase 30 S44": the COMPLETE loader routing table, static-derived (G5) — the EXE's
  loadDestPtrTable (0x80072C70: resident/overlay/slotA/slotB/type-7), the boot k-set {1,3,8,10,11},
  the RESIDENT's index tables D_800D3764 (29x8, MAIN/13-41 -> 0x800CAE08) and D_800D384C (6x8,
  MAIN/42-47 -> 0x800CCB1C), resident.c:641 (MAIN/12 -> 0x80128158), the SC07 pair's header-derived
  0x801A00D8, gbase arithmetic (LIST.CD carries LBA+len ONLY), the slot-adjacency proof, the
  module-id-word law (word0, dense 0x13..0x73, resident=0x36; MAIN/9-vs-39 duplicate flagged), and
  "PAC type 1 = uncompressed overlay, type 4 = LZSS". SUPERSEDES P3-T5's "entries [1]+ are
  runtime-indexed (no static xref)".
- disc-completeness.md: the "only knowable by runtime RE" doctrine REFUTED in place (H5, original
  kept) — 46 of 78 addresses are static; the runtime-only remainder is 28 script modules + 4
  stragglers, parked for L3 with evidence. Byte-sum correction (rows 3,406,325 B vs bucket
  3,564,021 incl. PAC headers), MAIN/7 raw-path exception, MAIN/0≡1.
- tooling-audit.md §S44: EVERY tool classified with file:line — 8 must-change (family_remap VRAM
  const, Makefile+modules.mk, sig-target generalization, audit_binaries de-ov_, family_hseq/
  progress:647/audit_frontier globs, corpus.sig_is_independent), 7 one-line registrations, 5
  retirements (disc_code_sweep superseded by disc_audit; reconcile_decls; 3 rollout one-shots;
  ImportOverlay/VerifyOverlay.java), rest auto-OK/N-A. new_overlay.sh -> new_binary.sh design.
- decision-log (R31): the pivot entry — the emulator dependency dissolves; the "modules" mostly
  dissolve into overlays (~75-77% h_exact-known; 802 novel fns); why the doctrine was missable for
  30 phases (a confident negative doctrine is a claim like any other — date it, cite it, re-measure).
- cookbook §154 + index regen (454 sections): module-id word / dual base-voting (h_exact ~500:1 +
  jal-alignment, must AGREE; thin votes => park, P9) / diff a mystery payload's head against classes
  you already own before inventing a new one.
This commit is contained in:
Drew T
2026-08-06 10:52:07 -06:00
parent 7473640838
commit c697746462
7 changed files with 339 additions and 19 deletions
+81 -19
View File
@@ -2,7 +2,7 @@
> **Generated by `tools/cookbook_index.py` — do not hand-edit** (R33). Regenerate after adding a cookbook section.
>
> `docs/matching-cookbook.md` is ~716 KB / 424 sections. Grepping it blind is how three P30 wave-1 agents each "discovered" an idiom that was already written down. **Start here, then read the section.** A section appears under every symptom it addresses.
> `docs/matching-cookbook.md` is ~716 KB / 454 sections. Grepping it blind is how three P30 wave-1 agents each "discovered" an idiom that was already written down. **Start here, then read the section.** A section appears under every symptom it addresses.
**How to use:** name what you SEE in the diff (a stolen delay slot, an extra `la`, a swapped register pair, a `conflicting types` error), find that symptom below, read those sections first. If nothing fits, THEN grind — and add a section when you win.
@@ -59,10 +59,10 @@
- **§3-The** — attribution primitive (use this before calling anything a scheduling residual) <sub>L6050</sub>
- **§3-The** — scheduling rules (refining §135-2 and §135-4) <sub>L8902</sub>
- **Consequence** — for the family (a real scheduling decision) <sub>L10085</sub>
- **§148** — The loop.c hoisting THRESHOLD is arithmetic you can compute, and the `?:` clamp that folds to MIN_EXPR (P30 S42, `func_8017C6F4`, 947 ins) <sub>L10098</sub>
- **§3-A.** — `move_movables` hoists iff `threshold × savings × lifetime ≥ insn_count` — and you can read it <sub>L10104</sub>
- **§148** — The loop.c hoisting THRESHOLD is arithmetic you can compute, and the `?:` clamp that folds to MIN_EXPR (P30 S42, `func_8017C6F4`, 947 ins) <sub>L10135</sub>
- **§3-A.** — `move_movables` hoists iff `threshold × savings × lifetime ≥ insn_count` — and you can read it <sub>L10141</sub>
### register allocation & pins (36)
### register allocation & pins (38)
- **§10** — Closing the regalloc/scheduling hard tail by hand (LZSS, Phase 7 session F — the full close) <sub>L835</sub>
- **Residual** — A — commutative `|`/`&`/`+` result lands in the wrong source-operand register <sub>L856</sub>
@@ -99,12 +99,15 @@
- **§3-The** — same swallow, twice more, in the integration spine <sub>L9699</sub>
- **§3-B.** — A `?:` on MEMORY operands costs ~16 bytes of invisible frame; on REGISTER operands, zero <sub>L10047</sub>
- **§3-D.** — A lone `$t8`/`$t9` in the target is RELOAD SCRATCH — reproduce the spill, don't pin the register <sub>L10063</sub>
- **§3-C.** — A zero-byte ALLOCNO-PRIORITY slider <sub>L10137</sub>
- **§3-C.** — A zero-byte ALLOCNO-PRIORITY slider <sub>L10174</sub>
- **§150** — A register ROTATION across symmetric blocks is VARIABLE-IDENTITY evidence, not an allocator tie (P30 S43, `func_8017C6F4`, 947 ins ×4) <sub>L10302</sub>
- **§152** — BYTE SIZE is the family key that name- and h_seq-grouping both miss (P30 S43, the 0xECC family: 1 crack → 12 overlays → 11,364 ins) <sub>L10408</sub>
### CSE / redundancy / rematerialization (2)
### CSE / redundancy / rematerialization (3)
- **§46** — The `func_80178D40` crack (890 ins ×134, the heaviest core in the game): four LOOP-STRUCTURE levers cheap-Opus found by reading loop.c/jump.c/cse.c (Phase 26 session 8, 2026-07-13) <sub>L3306</sub>
- **§83d** — CSE's quantity budget is WHOLE-FUNCTION, so a local rewrite cannot fix a local symptom <sub>L6445</sub>
- **§153** — THE ADDRESS-REMATERIALISATION LAUNDER: a third zero-emission asm lever (P30 S43, `func_8018D98C`, 710 ins) <sub>L10456</sub>
### loops & induction variables (9)
@@ -116,7 +119,7 @@
- **§66d-1** — What transfers between giants is the LOOP, not the PIN <sub>L5273</sub>
- **§70** — The giv-init base register: walk the PARAMETER, not a copy of it (Phase 29 SESSION-18, `func_801777BC`) <sub>L5612</sub>
- **§145** — Three loop/combine levers from the S40 wave-2 drafters (16/16 match_one) <sub>L9917</sub>
- **§148** — The loop.c hoisting THRESHOLD is arithmetic you can compute, and the `?:` clamp that folds to MIN_EXPR (P30 S42, `func_8017C6F4`, 947 ins) <sub>L10098</sub>
- **§148** — The loop.c hoisting THRESHOLD is arithmetic you can compute, and the `?:` clamp that folds to MIN_EXPR (P30 S42, `func_8017C6F4`, 947 ins) <sub>L10135</sub>
### structs, block moves & memcpy (30)
@@ -151,7 +154,7 @@
- **§3-The** — DEFINITION-side alias is the only escape when the fleet canon disagrees on a promoting param <sub>L9463</sub>
- **§3-Two** — errors of mine, both instructive <sub>L9999</sub>
### types, signedness & load/store width (31)
### types, signedness & load/store width (33)
- **§3-I1** — Unsigned range check: `(x - lo) < (hi-lo)` → `addiu`+`sltiu` <sub>L41</sub>
- **§3-I2** — Byte mask forces `andi` even after `lbu` <sub>L47</sub>
@@ -184,6 +187,8 @@
- **§3-The** — type-form rules <sub>L8872</sub>
- **§143** — `cast_call_sites` read a RETURN STATEMENT as a prototype and deleted it. A 0/39 sweep became 18/39. (P30 S40) <sub>L9824</sub>
- **Then** — propagation returned 0/137 TWICE — both times a missing TYPE <sub>L9990</sub>
- **§154** — Reading a disc payload: the module-id word, static base derivation, and "type 1 = uncompressed overlay" (P30 S44) <sub>L10512</sub>
- **§3-C.** — PAC type 1 = the same payload class as type 4, just NOT compressed <sub>L10538</sub>
### declarations, prototypes & K&R (55)
@@ -287,7 +292,7 @@
- **§127a** — §71 (sibling-first) is the strongest `-O0` lever, and it beats the index <sub>L8370</sub>
- **§132** — The `JR-PAIR-IN-ONE-O0-OBJECT` "wall" was TWO instrument defects: a merged-double span the carve could not see, and a truncated object no rule deleted (P30 S29, `func_8013B83C` + `func_8013BD74`) <sub>L8563</sub>
### family propagation & sweeps (74)
### family propagation & sweeps (78)
- **§8d** — Templating a body INTO a TU must not CHANGE its declaration environment — demote the carried data externs (Phase 26 session 8, byte-proven on `func_8015AE2C` ×133) <sub>L483</sub>
- **§11** — Cross-binary dedup & code-sharing (Phase 11 — "one match unlocks many") <sub>L908</sub>
@@ -363,8 +368,12 @@
- **§3-A.** — The frame has THREE strata, and stratum 3 is unreachable from C <sub>L10031</sub>
- **§3-E.** — A `qty_compare` TIE is not spelling-reachable — recognise it and stop <sub>L10073</sub>
- **Consequence** — for the family (a real scheduling decision) <sub>L10085</sub>
- **§150** — A register ROTATION across symmetric blocks is VARIABLE-IDENTITY evidence, not an allocator tie (P30 S43, `func_8017C6F4`, 947 ins ×4) <sub>L10302</sub>
- **§151** — THE GHOST WEDGE: when a load-before-store transposition is unreachable by ANY statement order (P30 S43, `func_8017EF68`, 969 ins) <sub>L10357</sub>
- **When** — to reach for it <sub>L10397</sub>
- **§152** — BYTE SIZE is the family key that name- and h_seq-grouping both miss (P30 S43, the 0xECC family: 1 crack → 12 overlays → 11,364 ins) <sub>L10408</sub>
### integration / TU plumbing (36)
### integration / TU plumbing (37)
- **§8c** — Splitting a TU means rebuilding its DECLARATION ENVIRONMENT, not moving text (Phase 26 session 6) <sub>L437</sub>
- **§8d** — Templating a body INTO a TU must not CHANGE its declaration environment — demote the carried data externs (Phase 26 session 8, byte-proven on `func_8015AE2C` ×133) <sub>L483</sub>
@@ -402,6 +411,7 @@
- **§3-The** — declaration surface (integration, not codegen) <sub>L8931</sub>
- **Reconciling** — a gate-refused draft: which way you edit depends on WHERE the TU's decl is <sub>L9555</sub>
- **§3-The** — same swallow, twice more, in the integration spine <sub>L9699</sub>
- **§3-A.** — Payload word0 is a global MODULE ID; code starts after the header <sub>L10517</sub>
### build graph, splat & the harness (99)
@@ -505,7 +515,7 @@
- **§142** — An open stub whose `h_exact` class is MATCHED elsewhere is FREE. Propagate the body; do not gate a draft. (P30 S39, +7,710 ins in two commands) <sub>L9768</sub>
- **§3-The** — measurement (do this before any wave; it is ~20 lines and needs no builds) <sub>L9780</sub>
### process, measurement & doctrine (59)
### process, measurement & doctrine (63)
- **§8e** — The jtbl ALIGNMENT LAW + the pad-spec filter — multi-table .rodata spans (Phase 29, byte-proven; `.run/probe_jtbl/verdict.md`) <sub>L530</sub>
- **§3-The** — mechanism: game-code dedup is SOURCE-LEVEL, not an object swap (R-D1, the key lesson) <sub>L926</sub>
@@ -566,8 +576,12 @@
- **§146** — RE-MEASURE A WALL BEFORE YOU RESPECT IT. Both "permanent" giants fell to drafts already on disk. (P30 S6, +50,094 ins) <sub>L9967</sub>
- **§147** — The three-stratum FRAME LAW, and four "stop searching" verdicts (P30 S42, `func_8017C294`, serial run) <sub>L10026</sub>
- **§3-C.** — Inner-block declaration does NOT delay slot allocation — BYTE-REFUTED <sub>L10058</sub>
- **§3-D.** — "Cheap fuel" that was never probed: 0 of 31 templatable <sub>L10283</sub>
- **§3-Two** — corrections to the record <sub>L10335</sub>
- **§3-The** — two fallouts, and how to close them (both measured, in order) <sub>L10385</sub>
- **What** — does NOT work (14 byte-measured probes) <sub>L10476</sub>
### (unbucketed — title matched no symptom vocabulary) (122)
### (unbucketed — title matched no symptom vocabulary) (140)
- **§3-How** — to use this <sub>L30</sub>
- **§1** — Idiom catalog (asm pattern → C that produces it) <sub>L39</sub>
@@ -689,8 +703,26 @@
- **§144** — THE LITERAL'S SPELLING PICKS THE IMMEDIATE ENCODING (P30 S40 wave 1, `func_801822E0`) <sub>L9878</sub>
- **§3-Why** — a correct draft can read as an intrinsic wall <sub>L9978</sub>
- **§3-The** — rule <sub>L10013</sub>
- **§3-B.** — `(v < 0x40) ? v : 0x3F` is folded to `MIN_EXPR` and expands to the WRONG SHAPE <sub>L10123</sub>
- **§3-D.** — Reproduce the original's BUGS verbatim <sub>L10147</sub>
- **§3-B.** — `(v < 0x40) ? v : 0x3F` is folded to `MIN_EXPR` and expands to the WRONG SHAPE <sub>L10160</sub>
- **§3-D.** — Reproduce the original's BUGS verbatim <sub>L10184</sub>
- **§149** — Four instrument defects in one session, and the two questions they were hiding (P30 S43) <sub>L10233</sub>
- **§3-A.** — A prep step that returns its input on failure is indistinguishable from a search that found nothing <sub>L10239</sub>
- **§3-B.** — Same address + same name ≠ same body — and the ledger keys on address <sub>L10257</sub>
- **§3-C.** — `make: *** [...] Error N` is a summary, never a diagnosis <sub>L10273</sub>
- **§3-The** — fix <sub>L10309</sub>
- **§3-The** — method that found it (this is the transferable part) <sub>L10319</sub>
- **Diagnostic** — order (adopt this) <sub>L10346</sub>
- **§3-The** — mechanism (read from cc1's own `-dR` trace, not inferred) <sub>L10362</sub>
- **§3-The** — lever — a zero-emission insn that absorbs the blocked tick <sub>L10377</sub>
- **§3-The** — finding <sub>L10413</sub>
- **§3-The** — key <sub>L10422</sub>
- **§3-Two** — cautions that must travel with this technique <sub>L10433</sub>
- **§3-The** — companion defect (open) <sub>L10444</sub>
- **Symptom** — Symptom <sub>L10464</sub>
- **Mechanism** — (gcc source + RTL dumps, not inferred) <sub>L10469</sub>
- **§3-The** — cure — a fresh launder per site, each in its own block <sub>L10482</sub>
- **Companion** — levers from the same function <sub>L10492</sub>
- **§3-B.** — Two static base-derivation methods that must AGREE (use both) <sub>L10526</sub>
## All sections, in order
@@ -1114,8 +1146,38 @@
- **§3-D.** — A lone `$t8`/`$t9` in the target is RELOAD SCRATCH — reproduce the spill, don't pin the register <sub>L10063</sub>
- **§3-E.** — A `qty_compare` TIE is not spelling-reachable — recognise it and stop <sub>L10073</sub>
- **Consequence** — for the family (a real scheduling decision) <sub>L10085</sub>
- **§148** — The loop.c hoisting THRESHOLD is arithmetic you can compute, and the `?:` clamp that folds to MIN_EXPR (P30 S42, `func_8017C6F4`, 947 ins) <sub>L10098</sub>
- **§3-A.** — `move_movables` hoists iff `threshold × savings × lifetime ≥ insn_count` — and you can read it <sub>L10104</sub>
- **§3-B.** — `(v < 0x40) ? v : 0x3F` is folded to `MIN_EXPR` and expands to the WRONG SHAPE <sub>L10123</sub>
- **§3-C.** — A zero-byte ALLOCNO-PRIORITY slider <sub>L10137</sub>
- **§3-D.** — Reproduce the original's BUGS verbatim <sub>L10147</sub>
- **§148** — The loop.c hoisting THRESHOLD is arithmetic you can compute, and the `?:` clamp that folds to MIN_EXPR (P30 S42, `func_8017C6F4`, 947 ins) <sub>L10135</sub>
- **§3-A.** — `move_movables` hoists iff `threshold × savings × lifetime ≥ insn_count` — and you can read it <sub>L10141</sub>
- **§3-B.** — `(v < 0x40) ? v : 0x3F` is folded to `MIN_EXPR` and expands to the WRONG SHAPE <sub>L10160</sub>
- **§3-C.** — A zero-byte ALLOCNO-PRIORITY slider <sub>L10174</sub>
- **§3-D.** — Reproduce the original's BUGS verbatim <sub>L10184</sub>
- **§149** — Four instrument defects in one session, and the two questions they were hiding (P30 S43) <sub>L10233</sub>
- **§3-A.** — A prep step that returns its input on failure is indistinguishable from a search that found nothing <sub>L10239</sub>
- **§3-B.** — Same address + same name ≠ same body — and the ledger keys on address <sub>L10257</sub>
- **§3-C.** — `make: *** [...] Error N` is a summary, never a diagnosis <sub>L10273</sub>
- **§3-D.** — "Cheap fuel" that was never probed: 0 of 31 templatable <sub>L10283</sub>
- **§150** — A register ROTATION across symmetric blocks is VARIABLE-IDENTITY evidence, not an allocator tie (P30 S43, `func_8017C6F4`, 947 ins ×4) <sub>L10302</sub>
- **§3-The** — fix <sub>L10309</sub>
- **§3-The** — method that found it (this is the transferable part) <sub>L10319</sub>
- **§3-Two** — corrections to the record <sub>L10335</sub>
- **Diagnostic** — order (adopt this) <sub>L10346</sub>
- **§151** — THE GHOST WEDGE: when a load-before-store transposition is unreachable by ANY statement order (P30 S43, `func_8017EF68`, 969 ins) <sub>L10357</sub>
- **§3-The** — mechanism (read from cc1's own `-dR` trace, not inferred) <sub>L10362</sub>
- **§3-The** — lever — a zero-emission insn that absorbs the blocked tick <sub>L10377</sub>
- **§3-The** — two fallouts, and how to close them (both measured, in order) <sub>L10385</sub>
- **When** — to reach for it <sub>L10397</sub>
- **§152** — BYTE SIZE is the family key that name- and h_seq-grouping both miss (P30 S43, the 0xECC family: 1 crack → 12 overlays → 11,364 ins) <sub>L10408</sub>
- **§3-The** — finding <sub>L10413</sub>
- **§3-The** — key <sub>L10422</sub>
- **§3-Two** — cautions that must travel with this technique <sub>L10433</sub>
- **§3-The** — companion defect (open) <sub>L10444</sub>
- **§153** — THE ADDRESS-REMATERIALISATION LAUNDER: a third zero-emission asm lever (P30 S43, `func_8018D98C`, 710 ins) <sub>L10456</sub>
- **Symptom** — Symptom <sub>L10464</sub>
- **Mechanism** — (gcc source + RTL dumps, not inferred) <sub>L10469</sub>
- **What** — does NOT work (14 byte-measured probes) <sub>L10476</sub>
- **§3-The** — cure — a fresh launder per site, each in its own block <sub>L10482</sub>
- **Companion** — levers from the same function <sub>L10492</sub>
- **§154** — Reading a disc payload: the module-id word, static base derivation, and "type 1 = uncompressed overlay" (P30 S44) <sub>L10512</sub>
- **§3-A.** — Payload word0 is a global MODULE ID; code starts after the header <sub>L10517</sub>
- **§3-B.** — Two static base-derivation methods that must AGREE (use both) <sub>L10526</sub>
- **§3-C.** — PAC type 1 = the same payload class as type 4, just NOT compressed <sub>L10538</sub>
+35
View File
@@ -2204,3 +2204,38 @@ contract, and this makes it enforceable rather than remembered.
**Sequencing (Drew's call):** finish the serial crack queue → L1+L2 (cheap, deterministic, and they
sharpen L3's target list) → L3 + type-1 onboarding. Fold into **P31**, which already owns bucket T.
## 2026-08-06 (P30 S44) — the 78-payload campaign: static addresses dissolve the emulator dependency; "modules" mostly dissolve into overlays
**Context + belief.** `make audit-disc` (S43) enumerated 78 unclaimed code payloads (~3.4 MB). Standing
doctrine (`disc-completeness.md`, from P27): these are "type-1 modules" whose load addresses are "only
knowable by runtime RE" — so onboarding was gated on an emulator session (L3), and the completion
contract carried them as a 39-module backlog.
**What the measurement said (3 read-only agents, byte-verified).** (1) The load addresses are STATIC
for 46 of 78: the EXE's `loadDestPtrTable` + boot literals + two index tables inside the resident +
`resident.c:641` + the SC07 pair's own headers give every MAIN payload and the SC07 pair a derived
address, corroborated by two independent corpus-side voting methods at ~500:1 margins
(`memory-map.md` §S44). (2) The three biggest "modules" are ORDINARY OVERLAYS stored uncompressed
(type 1 = raw overlay, type 4 = LZSS) for the standard 0x80128158 slot — ~75–77% of their functions
h_exact-identical to the onboarded corpus, 802 genuinely novel across all three. (3) The remainder
tiers honestly: 35 small actor modules at two statically-known ping-pong slots; SC07/3+4 at their own
slot; 28 script modules (7 × 4 per-disc builds) + 4 stragglers genuinely runtime-determined.
**The pivot.** L3 shrinks from "the onboarding prerequisite" to a small runtime-confirm pass (28+4
payloads + R34 verification of the static addresses). The campaign inverts: tooling updates → onboard
the big 3 through the EXISTING overlay machinery → dedup-bank the h_exact majority → batch the small
modules — all emulator-free. The "new binary class" tooling burden collapses to: `config/modules.mk`,
a de-ov_'d R36 gate, a vram-derived `family_remap`, glob widenings, and a parameterized
`new_binary.sh`. Full per-tool table: `tooling-audit.md` §S44.
**Why this was missable for 30 phases.** Each prior tool was correct about its subset and silent about
the rest (the audit's founding observation) — and the doctrine layer had the same shape: the P27
"only knowable by runtime RE" sentence was true of the tools that existed then, and nobody re-derived
it after the loader cluster was matched (the tables were sitting in matched C + the resident's own
bytes). A confident negative doctrine is a claim like any other — date it, cite its evidence,
re-measure before letting it gate a campaign (the §146/§147 lesson at doctrine scale).
**Hindsight better path.** When Phase 3 T5 wrote "entries [1]+ are runtime-indexed (no static xref)",
the honest follow-up was a named open question ("WHERE do the indices live?") rather than a doctrine.
The answer was one grep away once the resident was matched in Phase 12.
+14
View File
@@ -44,6 +44,20 @@ loads at its own address, the way the resident loads at `0x800CEDF8`. So — unl
that address is only knowable by runtime RE (a PCSX-Redux RAM-dump proof, the Phase-3 method). Onboarding
them is a Gen2 RE task, deferred with this evidence — NOT a false "complete" while code sits unbuilt.
> **⚠️ 2026-08-06 (S44): the "only knowable by runtime RE" sentence above is REFUTED.** The load
> addresses are **static** for 46 of the 78 unclaimed payloads: the EXE's `loadDestPtrTable`
> (0x80072C70) + the boot loaders' literal `&cdFileLocTable[k]` operands + two index tables INSIDE the
> resident (`D_800D3764` → slot A 0x800CAE08 for MAIN/13…41; `D_800D384C` → slot B 0x800CCB1C for
> MAIN/42…47) + `src/resident/resident.c:641` (MAIN/12 → the standard overlay slot 0x80128158) + the
> SC07 pair's own headers (→ 0x801A00D8). Full routing table with provenance:
> **`docs/memory-map.md` §"Phase 30 S44"**. Independently corroborated by h_exact base voting (~500:1)
> and jal-alignment voting. The genuinely runtime-only remainder is the 28 SC0x script modules +
> MAIN/7, MAIN/9, SC02/9 — parked for L3 with evidence. Additional corrections from the same pass:
> the three biggest "modules" (MAIN/12, SC02/37, SC03/107) are **ordinary overlays stored uncompressed**
> (PAC type 1 = raw overlay, type 4 = LZSS overlay); the 78 ledger rows sum **3,406,325 B** (the
> bucket's 3,564,021 additionally counts PAC headers); `MAIN/7` is a raw file (`FILE_007`, not
> PAC-wrapped); `MAIN/0 ≡ MAIN/1` byte-identical; payload word0 is a global module id (resident=0x36).
## Consequence for the completion contract (roadmap §1)
The contract's binary count is **no longer "136"**. Two corrections:
+38
View File
@@ -10506,3 +10506,41 @@ exist, gate the PLAIN one first.
**Symptom lines for the index:** **"an extra `sw $sN` in the prologue"** · **"`la $sN,SYM` + moves
where the target rematerialises"** · **"an address argument used twice in one block"** · **"a hoist no
respelling reaches"**.
---
## §154 — Reading a disc payload: the module-id word, static base derivation, and "type 1 = uncompressed overlay" (P30 S44)
Not codegen — payload forensics. Three laws from the 78-unclaimed-payload analysis, each of which
turns a former "needs the emulator" into a static read.
### A. Payload word0 is a global MODULE ID; code starts after the header
75 of 78 unclaimed payloads begin with a small LE integer forming one dense id space across all discs
(0x13…0x73; the resident is 0x36). Some follow it with a function-pointer table (SC07/3: table to
0xF8; SC07/4: to 0x154) before code. **Consequences:** `sig_image --bootstrap` returns **0 functions**
on any of them if run from offset 0 (its linear partition hits the header, finds no `jr $ra`, stops) —
**always pass `--text-lo` past the header**; and a header's own pointer table dates the base for free
(first table target − first prologue file offset = base). Only payloads that begin directly with code
(a `27bdffe8`-class prologue at offset 0) may be signed bare.
### B. Two static base-derivation methods that must AGREE (use both)
1. **h_exact voting:** sign the payload at ANY nominal base; for every function h_exact-identical to a
corpus function, `delta = corpus_addr − signed_addr` votes for the true base. On real overlays the
margin is decisive (~500:1 — 218,454 votes vs a 414 runner-up).
2. **jal-alignment voting:** collect distinct internal `jal` targets; the base under which the most
land on actual prologue file offsets wins. Corpus-independent; the control (the resident) reproduces
its known 0x800CEDF8 and ends 4 bytes under the overlay slot.
A payload where the two disagree, or where votes are thin (script modules: 3–14 aligned jals, calls
almost all outward), is **loader-determined** — park it for runtime confirm rather than guessing (P9).
And check the LOADER first: the EXE's `loadDestPtrTable` + the resident's index tables route most
payloads statically (`memory-map.md` §S44) — the vote is then the R34 cross-check, not the source.
### C. PAC type 1 = the same payload class as type 4, just NOT compressed
The three biggest "mystery modules" were ordinary location overlays for the standard 0x80128158 slot,
stored raw. Their first 192 bytes are byte-identical to built ov_ images; ~75% of their functions are
h_exact-identical to the corpus. **Before inventing a new class for a payload, diff its head against
the classes you already own.** (Corollary of §152: same-bytes is the family key — here at payload
scale.)
**Symptom lines for the index:** **"sig_image bootstrap finds 0 functions"** · **"a payload with a
small integer first word"** · **"where does this blob load"** · **"a huge type-1 module"**.
+56
View File
@@ -568,3 +568,59 @@ in retail too (shipped data, not a debug build). The proto's scene-select shares
| gamehacking.org #88529 (US) / #93476 (JP) via libretro-database GameShark `.cht` | Player stat block, flags, misc | gamehacking.org Cloudflare-blocks scripts; cht mirror: `raw.githubusercontent.com/libretro/libretro-database/master/cht/Sony%20-%20PlayStation/Brave%20Fencer%20Musashi%20(USA,%20Japan)%20(GameShark).cht` |
| jywjyw `bravefencer-hack` `doc/note.md` | JP overlay/memory map, LIST.CD-in-RAM behavior, pointer table | **All addresses JP (SLPS-01490)** — re-derive for US |
| Hidden Palace / archive.org | Prototype facts | pages fetchable via `hiddenpalace.org/w/index.php?title=PAGE&action=raw` |
## Phase 30 S44 — the COMPLETE loader routing table (static-derived; supersedes "runtime-indexed, no static xref")
> **Provenance (G5):** `static-derived` — read from the EXE bytes (`extracted/retail/SLUS_007.26`,
> vram = fileoff + 0x8000F800), the resident payload bytes (`MAIN.CD.dir/FILE_010.dir/1.1`, fileoff =
> vram − 0x800CEDF8), the matched loader C (`src/800.c`, `src/resident/resident.c`), and the per-overlay
> wrapper asm — by 3 read-only exploration agents, 2026-08-06. Region: **US**. The Phase-3 T5 note
> "entries [1]+ are runtime-indexed (no static xref)" is **superseded**: the indices ARE static, they
> live in the resident and in each overlay, not in the EXE. Independently corroborated by two
> corpus-side methods (h_exact base voting at ~500:1; distinct-jal→prologue alignment voting) — and the
> resident control reproduces its known 0x800CEDF8 and ends at 0x80128154, four bytes under the overlay slot.
### loadDestPtrTable — 0x80072C70 (EXE fileoff 0x63470), 5 × u32
| slot | value | role (byte-proven) |
|---|---|---|
| [0] | **0x800CEDF8** | resident-module slot (boot loaders) |
| [1] | **0x80128158** | location-overlay slot |
| [2] | **0x800CAE08** | module slot A (small actor modules) |
| [3] | **0x800CCB1C** | module slot B (small actor modules) |
| [4] | **0x800C7F08** | PAC-type-7 fixed destination |
### Who loads what where (all statically enumerated)
| loader | index source | payloads | dest |
|---|---|---|---|
| 5 boot loaders (literal `&cdFileLocTable[k]` at 0x80010CA4 / 0x80010F1C / 0x800112F0 / 0x80011100 / 0x80011144) | k ∈ {1,3,8,10,11} | MAIN/1,3,8,**10 (=resident)**,11 | `loadDestPtrTable[0]` = 0x800CEDF8 |
| resident `func_800D02D0` | **`D_800D3764`** = 29 × {u32 cdFileLocIdx; u32 param} | MAIN/13…41 (contiguous) | `[2]` = 0x800CAE08 |
| resident `func_800D0488` | **`D_800D384C`** = 6 × {u32,u32} | MAIN/42…47 | `[3]` = 0x800CCB1C |
| resident `func_800CF94C` (`src/resident/resident.c:641`) | `&cdFileLocTable[12]` | MAIN/12 (an UNCOMPRESSED overlay) | `[1]` = 0x80128158 |
| per-overlay wrapper `func_80128CFC` (every overlay) | per-overlay `IDXTAB` (s16, −1-terminated, 37 entries, same list fleet-wide) + `*DESTPTR` (per-overlay initialized word) | resources incl. the SC0x sets | per-overlay dest (e.g. ov_SC01_000: IDXTAB 0x8017EEC8, *0x801A3234 = 0x801A58E8) |
| SC07 endgame pair | header-derived (id word + fn-ptr table; first table target − first prologue fileoff) | SC07/3 (code@0xFC), SC07/4 (code@0x158) | **0x801A00D8** (own slot, overlaps the overlay tail — disc-7 layout) |
### The arithmetic
- **Global cdFileLocTable index** = `gbase[cd] + subfile`; gbase = MAIN:0 SC01:49 SC02:135 SC03:178
SC04:318 SC05:349 SC06:379 SC07:418 (LIST.CD counts 49/86/43/140/31/30/39/29, byte-verified; LIST.CD
carries **LBA + length only**, never load addresses).
- **Slot adjacency proof:** 0x800CAE08 + 7,444 (max slot-A payload, MAIN/34) = 0x800CCB1C;
0x800CCB1C + 8,920 (max slot-B, MAIN/44) = 0x800CEDF4 → resident at 0x800CEDF8. The three regions are
back-to-back, each sized to its largest member. MAIN/46's self-calls (base+0x724/0x978/0xAB0) confirm slot B.
- **Module-ID law:** payload **word0 is a global module id** (dense 0x13…0x73 across all discs; the
resident is 0x36). 75/78 unclaimed payloads carry it; only the 3 raw uncompressed overlays
(MAIN/12, SC02/37, SC03/107) start directly with code. MAIN/9 and MAIN/39 both carry id 0x2D
(unresolved duplicate). MAIN/0 ≡ MAIN/1 byte-identical (one module stored twice).
- **PAC-type law (extends formats.md):** type **1** = uncompressed code/module payload; type **4** =
the same class LZSS-compressed. The PAC header's bytes 0x10–0x7FF are never read by the loader
(`CdGetSector(lzss_sectorStagingBuf, 4)` reads 4 words) — no address lives in the payload.
### Statically UNRESOLVED (parked for L3 — runtime confirm, R34)
The 28 SC0x script modules (SC03/73-79, SC03/132-138, SC04/24-30, SC05/23-29 = 7 modules × 4 per-disc
builds), SC02/9, MAIN/7 (raw file, not PAC), MAIN/9: dest comes through the resourceIdMap /
`StreamLoadStateMachine` descriptor path (`D_80068B60[(loadParam−0x100)*0x10]`) or per-overlay DESTPTR
values — per-disc, not EXE-static. Their jal-vote bases are LOW-CONFIDENCE (3–14 aligned jals, calls
almost entirely outward) and are NOT recorded as addresses here.
+98
View File
@@ -1693,3 +1693,101 @@ by a build from stale objects. Cheap, total, and it removes the need to remember
**Assertion (R32):** after `build`, assert every `.o` linked into the image is NEWER than every `.s` it
includes; fail loud on the first inversion. A build that consumed a stale object must never be allowed
to report BYTE-IDENTICAL.
---
# S44 NEWCODE AUDIT (2026-08-06) — every tool vs the 78 unclaimed payloads
> Drew's directive: *"analyze every single one of our tools and determine how/if it needs to be
> updated to properly account for our new code findings."* Ground truth: 3 read-only exploration
> agents over the full inventory (117 `tools/*.py`, 13 `tools/*.sh`, `tools/bfm_extract/` ×11,
> `tools/ghidra_scripts/` ×11, `tools/workflows/` ×6, `tools/permuter/`, `diff_settings.py`,
> `Makefile`, the config registries). Vendored submodules out of scope.
>
> **The class mostly DISSOLVES:** the 3 big payloads are ordinary overlays (standard slot, existing
> machinery); only the small modules + the SC07 pair need a genuinely new binary class ("md_*",
> `config/modules.mk`). Classification: **(a)** parameterized per-binary · **(b)** derives the binary
> set from configs · **(c)** hardcodes overlay shape · **(d)** binary-agnostic/N-A.
## Registration surfaces (the choke points)
| surface | class | point | verdict |
|---|---|---|---|
| `Makefile` | b | `:55` BINARIES; prune `:511`; check-all `:753` | **CODE**: `-include config/modules.mk`, `+ $(MODULE_BINARIES)`; downstream of `$(BINARIES)` auto-OK |
| `config/overlays.mk` | b | generated registry | **NEW SIBLING** `config/modules.mk`, same 18-var block, per-alias VRAM |
| `tools/dup_report.py` BINARIES | b | `:26-180` (sentinel `:167`) | registration line/binary (non-ov_ aliases already take the individual-ingest path `:210`) |
| `tools/progress.py` BINARIES | b | `:23-305` (sentinel `:304`) | registration line/binary |
| `diff_settings.py` BINARIES | b | `:16-437` (sentinel `:437`) | registration line/binary |
| `tools/audit_binaries.py` (R36) | **c** | `onboarded()` `:41-43` globs `splat.ov_*.yaml`; `startswith("ov_")` `:92,:111,:124,:131` | **CODE**: derive from `splat.*.yaml` minus main (R33); keep engine_core-include check ov_-conditional |
| `tools/corpus.py` | b | `:373` from dup_report; `sig_is_independent` `:336` | **CODE** at `:336` (ov_/resident-only ⇒ module sigs untrusted); rest auto-OK |
| `tools/difficulty.py` | b→derived | `cfg_for(alias)` `:22-34` | **auto-OK** (P27 T6 migration) |
## Must-change (code)
| tool | defect | fix |
|---|---|---|
| `family_remap.py` | `VRAM = 0x80128158` module const `:30`, used in ALL offset math `:98,:160` (img_path is already yaml-derived) | `vram_base_of(alias)` from `config/splat.<a>.yaml` — the pattern `jtbl_carve.overlay_vram_base()` `:65-71` already implements |
| Makefile sig targets | `sig-overlays` hardcodes `OVERLAY_VRAM :=0x80128158` `:292`; `sig-resident` separate | one generalized target over `$(filter-out main,$(BINARIES))` with `$($(a)_VRAM_BASE)` (+ per-alias TEXT_LO); keep old names as aliases |
| `family_hseq.py` | `src/ov_*` `:43` + `sig.ov_*` `:45` globs; self-declared overlays-only `:189,:219` | include resident+modules (glob `sig.*.jsonl` minus main, or read registries) |
| `progress.py --weighted` | `sig.ov_*` glob `:647` + explicit resident `:648` | derive from BINARIES |
| `audit_frontier.py` | `:57-59` same glob shape | same fix |
| `backlog.py` | alias regex `:137` `(ov_…|resident|main)` | add `md_…` |
| `prefetch_fleet.py` | `:67` `("main","resident")` | add modules |
| `dedup_propagate.py` | reads only `overlays.mk` `:44` | also read `modules.mk` |
## Retire (R33)
`disc_code_sweep.py` — superseded by `disc_audit.py` (whole-disc partition, both layers, no window,
claims); zero build refs (Makefile mentions it only in a comment); doc refs to update:
`docs/SETUP.md:667`, `docs/disc-completeness.md` · `reconcile_decls.py` — self-declared RETIRED ·
`rollout_801457a4_o0.py`, `rollout_whale_o0.py`, `rollout_o0_cluster.py` — one-shot, slot-locked
historical rollouts · `ghidra_scripts/ImportOverlay.java` + `VerifyOverlay.java` — 1-overlay-era
hardcoded tables (`ghidra_import_raw.sh` is the live path).
## `new_overlay.sh` → `tools/new_binary.sh`
Overlay-specific: alias pattern `:29`, payload path `${ENTRY}.dec` `:30`, `VRAM=` `:31`, slot literals
re-hardcoded at `:39,:44`, the overlay splat template. **Generic and reusable verbatim:** check.sha +
symbols creation, the 18-var mk block, the sentinel-anchored 3-dict registrar `:104-133` (ast-checked),
extract+build byte-check. ⇒ parameterize {ALIAS, PAYLOAD, VRAM, TEXT_LO, TEMPLATE, REGISTRY};
`new_overlay.sh` becomes a wrapper with the old defaults.
## `sig_image.py` — no code change; a USAGE law
`--bootstrap` linear-partitions from `lo = vram_base` (`:232`, `bootstrap_seeds` `:81-98`) ⇒ assumes
code at file offset 0. 75/78 payloads start with the module-id word (+ sometimes a ptr table) ⇒ 0
seeds. **Law: pass `--text-lo` past the header** (prologue offsets are in the disc-ledger roster).
`--seeds` accepts a sig jsonl or 0xADDR lines (`:47-59`).
## Auto-OK once registered — (a) parameterized / (b) derived
`gate_stage` · `harvest_verify` · `match_one` · `rtu_match` · `masked_diff`/`masked_scorer` ·
`family_sweep` (cross-address `--to-addr` EXISTS: `:332-343,:537`) · `family_manifest`(glob fix rides
family_hseq) · `dedup_extend` · `dedup_integrate` · `jtbl_carve` (the model implementation) ·
`jtbl_family_bank` · `jr_isolate`/`jr_isolate_all` · `o0_subsplit` · `overlay_src_split` ·
`split_src_region` · `blast_radius` (derives from `splat.*.yaml` — best-in-class) · `worklist` ·
`exemplar_miner` · `diff_regions` · `lift_types` · `build_engine_types` · `uniquify_type` ·
`canon_sig_reconcile` · `recover_giant` · `recover_integration` · `fix_arity_callers` ·
`fix_header_decl` · `cast_call_sites` · `sig_unify` · `reconcile_tu` · `canon_draft_decls` ·
`canon_resident_calls` · `inject_capped_externs` · `scope_tu_externs` · `scope_data_externs` ·
`normalize_self_decls` · `conform_decls` · `blocker_probe` · `demacroize` · `autopsy` ·
`residual_class` · `bank_exemplar` · `t7_bank` · `sweep_parallel` · `bulk_harvest` (alias side via
`lora_grind.binaries()` = check-sha glob) · `lora_grind` (`binaries()` auto-OK; reach-glob rides the
hseq fix) · `gen_harvest_targets`(same) · `build_fuel_manifest`(same) · `wave_targets` ·
`build_wave_args` · `idiom_loop` · `audit_digest` (via progress.BINARIES) · `lint_symbol_refs` ·
`cookbook_index` · `symcheck` · `burndown` · `p16_permute`/`permuter_ils`/`permuter_weights`/
`p16_improve`/`p16_known_answer` · `grinder` · `auto_driver` · workflows (`worker_wave.js` etc. —
aliases are prompt args) · `glm_reconcile`.
## N-A (binary-agnostic)
Extract stack (`bfm_extract/*` — already extracted the payloads) · PsyQ linking (`psyq_*`,
`gen_lib_subsegs`, `ld_interleave`, `make_*_used`, `make_libgs.sh`, `jtbl_rodata_pads`) · LLM tier
(`serve_local`, `api_draft`, `train_lora`, `eval_lora`, `format_finetune`, `export_pairs`,
`idiom_hunt`, `glm_parallel.sh`, `orchestrator`) · permuter internals (`run_masked`, `compile*.sh`) ·
Ghidra plumbing (`ghidra_import.sh`, `ghidra_import_raw.sh` — the live module importer,
`ghidra_mcp_*.sh`, the .java scripts except the two retired above) · automation shell
(`auto_status/stop/supervisor.sh`, `treelock.sh`) · `decompile.py` · `match_protos.py` ·
`ram_probe.py` · `audit_text_sources.py` · `sweep_citations.py` · `ab_match.js`/`ab_score.py` ·
`disc_audit.py` (the new oracle itself; its `claimed-by` derives from `config/check.*.sha`, so newly
onboarded binaries flip to claimed with ZERO wiring).
+17
View File
@@ -2527,6 +2527,23 @@ and is booked as data. **Not in `tools-health`** — it needs `disks/`, which a
**Next (task #11 / L3):** the emulator tour resolves whether these 34 are the 39 type-1 modules, gives
their load addresses, and proves completeness against execution.
### ▶ S44-I.0 — the new-code campaign opens: knowledge captured (2026-08-06, Fable5Max plan approved)
Plan: `~/.claude/plans/optimized-squishing-engelbart.md` (Part I this session, Part II fresh). Three
exploration agents broke the 78-payload class open; everything captured while hot (R30/R31):
- **`docs/memory-map.md` §"Phase 30 S44"** — the COMPLETE static loader routing table
(`loadDestPtrTable` slots · boot k-set {1,3,8,10,11} · resident tables `D_800D3764`/`D_800D384C` →
slots A/B 0x800CAE08/0x800CCB1C · MAIN/12 → 0x80128158 · SC07 pair → 0x801A00D8 · gbase arithmetic ·
slot-adjacency proof · module-id law · "type 1 = uncompressed overlay"). Supersedes P3-T5's
"runtime-indexed, no static xref" and P27's "only knowable by runtime RE"
(`disc-completeness.md` corrected in place, H5).
- **`docs/tooling-audit.md` §S44** — EVERY tool classified (a/b/c/d) with file:line: 8 code-changes,
7 registrations, 5 retirements, the rest auto-OK/N-A. The "every single tool" deliverable.
- **`docs/decision-log.md`** — the R31 pivot entry (why L3 shrank; why the doctrine was missable:
a confident negative doctrine is a claim like any other — the §146/§147 lesson at doctrine scale).
- **Cookbook §154** (+ index regen, 454 sections): module-id word / dual base-voting methods /
type-1-is-an-overlay. Key numbers: big-3 base 0x80128158 at ~500:1; ~75-77% h_exact-known;
**802 novel fns**; 46/78 addresses static; 28+4 parked for L3.
### ▶ S11 — the propagation lag: EXTEND 0/36 -> 31/36, and every blocker was a DECLARATION (2026-08-03/04)
Lane 2 of the S10 checkpoint ("26,006 ins, ~0 agent tokens, PARTLY BLOCKED"), taken first on the
standing doctrine that the cheap deterministic lever is probed before the expensive agent one.