mirror of
https://github.com/Druthulu/BFM-decomp
synced 2026-09-29 07:10:32 -04:00
docs(phase-30 S44 I.0): the static loader routing table + the full tool audit — knowledge captured
Plan-approved campaign (Fable5Max, ~/.claude/plans/optimized-squishing-engelbart.md). I.0 = capture
while hot (R30/R31), before any code:
- memory-map.md §"Phase 30 S44": the COMPLETE loader routing table, static-derived (G5) — the EXE's
loadDestPtrTable (0x80072C70: resident/overlay/slotA/slotB/type-7), the boot k-set {1,3,8,10,11},
the RESIDENT's index tables D_800D3764 (29x8, MAIN/13-41 -> 0x800CAE08) and D_800D384C (6x8,
MAIN/42-47 -> 0x800CCB1C), resident.c:641 (MAIN/12 -> 0x80128158), the SC07 pair's header-derived
0x801A00D8, gbase arithmetic (LIST.CD carries LBA+len ONLY), the slot-adjacency proof, the
module-id-word law (word0, dense 0x13..0x73, resident=0x36; MAIN/9-vs-39 duplicate flagged), and
"PAC type 1 = uncompressed overlay, type 4 = LZSS". SUPERSEDES P3-T5's "entries [1]+ are
runtime-indexed (no static xref)".
- disc-completeness.md: the "only knowable by runtime RE" doctrine REFUTED in place (H5, original
kept) — 46 of 78 addresses are static; the runtime-only remainder is 28 script modules + 4
stragglers, parked for L3 with evidence. Byte-sum correction (rows 3,406,325 B vs bucket
3,564,021 incl. PAC headers), MAIN/7 raw-path exception, MAIN/0≡1.
- tooling-audit.md §S44: EVERY tool classified with file:line — 8 must-change (family_remap VRAM
const, Makefile+modules.mk, sig-target generalization, audit_binaries de-ov_, family_hseq/
progress:647/audit_frontier globs, corpus.sig_is_independent), 7 one-line registrations, 5
retirements (disc_code_sweep superseded by disc_audit; reconcile_decls; 3 rollout one-shots;
ImportOverlay/VerifyOverlay.java), rest auto-OK/N-A. new_overlay.sh -> new_binary.sh design.
- decision-log (R31): the pivot entry — the emulator dependency dissolves; the "modules" mostly
dissolve into overlays (~75-77% h_exact-known; 802 novel fns); why the doctrine was missable for
30 phases (a confident negative doctrine is a claim like any other — date it, cite it, re-measure).
- cookbook §154 + index regen (454 sections): module-id word / dual base-voting (h_exact ~500:1 +
jal-alignment, must AGREE; thin votes => park, P9) / diff a mystery payload's head against classes
you already own before inventing a new one.
This commit is contained in:
+81
-19
@@ -2,7 +2,7 @@
|
||||
|
||||
> **Generated by `tools/cookbook_index.py` — do not hand-edit** (R33). Regenerate after adding a cookbook section.
|
||||
>
|
||||
> `docs/matching-cookbook.md` is ~716 KB / 424 sections. Grepping it blind is how three P30 wave-1 agents each "discovered" an idiom that was already written down. **Start here, then read the section.** A section appears under every symptom it addresses.
|
||||
> `docs/matching-cookbook.md` is ~716 KB / 454 sections. Grepping it blind is how three P30 wave-1 agents each "discovered" an idiom that was already written down. **Start here, then read the section.** A section appears under every symptom it addresses.
|
||||
|
||||
**How to use:** name what you SEE in the diff (a stolen delay slot, an extra `la`, a swapped register pair, a `conflicting types` error), find that symptom below, read those sections first. If nothing fits, THEN grind — and add a section when you win.
|
||||
|
||||
@@ -59,10 +59,10 @@
|
||||
- **§3-The** — attribution primitive (use this before calling anything a scheduling residual) <sub>L6050</sub>
|
||||
- **§3-The** — scheduling rules (refining §135-2 and §135-4) <sub>L8902</sub>
|
||||
- **Consequence** — for the family (a real scheduling decision) <sub>L10085</sub>
|
||||
- **§148** — The loop.c hoisting THRESHOLD is arithmetic you can compute, and the `?:` clamp that folds to MIN_EXPR (P30 S42, `func_8017C6F4`, 947 ins) <sub>L10098</sub>
|
||||
- **§3-A.** — `move_movables` hoists iff `threshold × savings × lifetime ≥ insn_count` — and you can read it <sub>L10104</sub>
|
||||
- **§148** — The loop.c hoisting THRESHOLD is arithmetic you can compute, and the `?:` clamp that folds to MIN_EXPR (P30 S42, `func_8017C6F4`, 947 ins) <sub>L10135</sub>
|
||||
- **§3-A.** — `move_movables` hoists iff `threshold × savings × lifetime ≥ insn_count` — and you can read it <sub>L10141</sub>
|
||||
|
||||
### register allocation & pins (36)
|
||||
### register allocation & pins (38)
|
||||
|
||||
- **§10** — Closing the regalloc/scheduling hard tail by hand (LZSS, Phase 7 session F — the full close) <sub>L835</sub>
|
||||
- **Residual** — A — commutative `|`/`&`/`+` result lands in the wrong source-operand register <sub>L856</sub>
|
||||
@@ -99,12 +99,15 @@
|
||||
- **§3-The** — same swallow, twice more, in the integration spine <sub>L9699</sub>
|
||||
- **§3-B.** — A `?:` on MEMORY operands costs ~16 bytes of invisible frame; on REGISTER operands, zero <sub>L10047</sub>
|
||||
- **§3-D.** — A lone `$t8`/`$t9` in the target is RELOAD SCRATCH — reproduce the spill, don't pin the register <sub>L10063</sub>
|
||||
- **§3-C.** — A zero-byte ALLOCNO-PRIORITY slider <sub>L10137</sub>
|
||||
- **§3-C.** — A zero-byte ALLOCNO-PRIORITY slider <sub>L10174</sub>
|
||||
- **§150** — A register ROTATION across symmetric blocks is VARIABLE-IDENTITY evidence, not an allocator tie (P30 S43, `func_8017C6F4`, 947 ins ×4) <sub>L10302</sub>
|
||||
- **§152** — BYTE SIZE is the family key that name- and h_seq-grouping both miss (P30 S43, the 0xECC family: 1 crack → 12 overlays → 11,364 ins) <sub>L10408</sub>
|
||||
|
||||
### CSE / redundancy / rematerialization (2)
|
||||
### CSE / redundancy / rematerialization (3)
|
||||
|
||||
- **§46** — The `func_80178D40` crack (890 ins ×134, the heaviest core in the game): four LOOP-STRUCTURE levers cheap-Opus found by reading loop.c/jump.c/cse.c (Phase 26 session 8, 2026-07-13) <sub>L3306</sub>
|
||||
- **§83d** — CSE's quantity budget is WHOLE-FUNCTION, so a local rewrite cannot fix a local symptom <sub>L6445</sub>
|
||||
- **§153** — THE ADDRESS-REMATERIALISATION LAUNDER: a third zero-emission asm lever (P30 S43, `func_8018D98C`, 710 ins) <sub>L10456</sub>
|
||||
|
||||
### loops & induction variables (9)
|
||||
|
||||
@@ -116,7 +119,7 @@
|
||||
- **§66d-1** — What transfers between giants is the LOOP, not the PIN <sub>L5273</sub>
|
||||
- **§70** — The giv-init base register: walk the PARAMETER, not a copy of it (Phase 29 SESSION-18, `func_801777BC`) <sub>L5612</sub>
|
||||
- **§145** — Three loop/combine levers from the S40 wave-2 drafters (16/16 match_one) <sub>L9917</sub>
|
||||
- **§148** — The loop.c hoisting THRESHOLD is arithmetic you can compute, and the `?:` clamp that folds to MIN_EXPR (P30 S42, `func_8017C6F4`, 947 ins) <sub>L10098</sub>
|
||||
- **§148** — The loop.c hoisting THRESHOLD is arithmetic you can compute, and the `?:` clamp that folds to MIN_EXPR (P30 S42, `func_8017C6F4`, 947 ins) <sub>L10135</sub>
|
||||
|
||||
### structs, block moves & memcpy (30)
|
||||
|
||||
@@ -151,7 +154,7 @@
|
||||
- **§3-The** — DEFINITION-side alias is the only escape when the fleet canon disagrees on a promoting param <sub>L9463</sub>
|
||||
- **§3-Two** — errors of mine, both instructive <sub>L9999</sub>
|
||||
|
||||
### types, signedness & load/store width (31)
|
||||
### types, signedness & load/store width (33)
|
||||
|
||||
- **§3-I1** — Unsigned range check: `(x - lo) < (hi-lo)` → `addiu`+`sltiu` <sub>L41</sub>
|
||||
- **§3-I2** — Byte mask forces `andi` even after `lbu` <sub>L47</sub>
|
||||
@@ -184,6 +187,8 @@
|
||||
- **§3-The** — type-form rules <sub>L8872</sub>
|
||||
- **§143** — `cast_call_sites` read a RETURN STATEMENT as a prototype and deleted it. A 0/39 sweep became 18/39. (P30 S40) <sub>L9824</sub>
|
||||
- **Then** — propagation returned 0/137 TWICE — both times a missing TYPE <sub>L9990</sub>
|
||||
- **§154** — Reading a disc payload: the module-id word, static base derivation, and "type 1 = uncompressed overlay" (P30 S44) <sub>L10512</sub>
|
||||
- **§3-C.** — PAC type 1 = the same payload class as type 4, just NOT compressed <sub>L10538</sub>
|
||||
|
||||
### declarations, prototypes & K&R (55)
|
||||
|
||||
@@ -287,7 +292,7 @@
|
||||
- **§127a** — §71 (sibling-first) is the strongest `-O0` lever, and it beats the index <sub>L8370</sub>
|
||||
- **§132** — The `JR-PAIR-IN-ONE-O0-OBJECT` "wall" was TWO instrument defects: a merged-double span the carve could not see, and a truncated object no rule deleted (P30 S29, `func_8013B83C` + `func_8013BD74`) <sub>L8563</sub>
|
||||
|
||||
### family propagation & sweeps (74)
|
||||
### family propagation & sweeps (78)
|
||||
|
||||
- **§8d** — Templating a body INTO a TU must not CHANGE its declaration environment — demote the carried data externs (Phase 26 session 8, byte-proven on `func_8015AE2C` ×133) <sub>L483</sub>
|
||||
- **§11** — Cross-binary dedup & code-sharing (Phase 11 — "one match unlocks many") <sub>L908</sub>
|
||||
@@ -363,8 +368,12 @@
|
||||
- **§3-A.** — The frame has THREE strata, and stratum 3 is unreachable from C <sub>L10031</sub>
|
||||
- **§3-E.** — A `qty_compare` TIE is not spelling-reachable — recognise it and stop <sub>L10073</sub>
|
||||
- **Consequence** — for the family (a real scheduling decision) <sub>L10085</sub>
|
||||
- **§150** — A register ROTATION across symmetric blocks is VARIABLE-IDENTITY evidence, not an allocator tie (P30 S43, `func_8017C6F4`, 947 ins ×4) <sub>L10302</sub>
|
||||
- **§151** — THE GHOST WEDGE: when a load-before-store transposition is unreachable by ANY statement order (P30 S43, `func_8017EF68`, 969 ins) <sub>L10357</sub>
|
||||
- **When** — to reach for it <sub>L10397</sub>
|
||||
- **§152** — BYTE SIZE is the family key that name- and h_seq-grouping both miss (P30 S43, the 0xECC family: 1 crack → 12 overlays → 11,364 ins) <sub>L10408</sub>
|
||||
|
||||
### integration / TU plumbing (36)
|
||||
### integration / TU plumbing (37)
|
||||
|
||||
- **§8c** — Splitting a TU means rebuilding its DECLARATION ENVIRONMENT, not moving text (Phase 26 session 6) <sub>L437</sub>
|
||||
- **§8d** — Templating a body INTO a TU must not CHANGE its declaration environment — demote the carried data externs (Phase 26 session 8, byte-proven on `func_8015AE2C` ×133) <sub>L483</sub>
|
||||
@@ -402,6 +411,7 @@
|
||||
- **§3-The** — declaration surface (integration, not codegen) <sub>L8931</sub>
|
||||
- **Reconciling** — a gate-refused draft: which way you edit depends on WHERE the TU's decl is <sub>L9555</sub>
|
||||
- **§3-The** — same swallow, twice more, in the integration spine <sub>L9699</sub>
|
||||
- **§3-A.** — Payload word0 is a global MODULE ID; code starts after the header <sub>L10517</sub>
|
||||
|
||||
### build graph, splat & the harness (99)
|
||||
|
||||
@@ -505,7 +515,7 @@
|
||||
- **§142** — An open stub whose `h_exact` class is MATCHED elsewhere is FREE. Propagate the body; do not gate a draft. (P30 S39, +7,710 ins in two commands) <sub>L9768</sub>
|
||||
- **§3-The** — measurement (do this before any wave; it is ~20 lines and needs no builds) <sub>L9780</sub>
|
||||
|
||||
### process, measurement & doctrine (59)
|
||||
### process, measurement & doctrine (63)
|
||||
|
||||
- **§8e** — The jtbl ALIGNMENT LAW + the pad-spec filter — multi-table .rodata spans (Phase 29, byte-proven; `.run/probe_jtbl/verdict.md`) <sub>L530</sub>
|
||||
- **§3-The** — mechanism: game-code dedup is SOURCE-LEVEL, not an object swap (R-D1, the key lesson) <sub>L926</sub>
|
||||
@@ -566,8 +576,12 @@
|
||||
- **§146** — RE-MEASURE A WALL BEFORE YOU RESPECT IT. Both "permanent" giants fell to drafts already on disk. (P30 S6, +50,094 ins) <sub>L9967</sub>
|
||||
- **§147** — The three-stratum FRAME LAW, and four "stop searching" verdicts (P30 S42, `func_8017C294`, serial run) <sub>L10026</sub>
|
||||
- **§3-C.** — Inner-block declaration does NOT delay slot allocation — BYTE-REFUTED <sub>L10058</sub>
|
||||
- **§3-D.** — "Cheap fuel" that was never probed: 0 of 31 templatable <sub>L10283</sub>
|
||||
- **§3-Two** — corrections to the record <sub>L10335</sub>
|
||||
- **§3-The** — two fallouts, and how to close them (both measured, in order) <sub>L10385</sub>
|
||||
- **What** — does NOT work (14 byte-measured probes) <sub>L10476</sub>
|
||||
|
||||
### (unbucketed — title matched no symptom vocabulary) (122)
|
||||
### (unbucketed — title matched no symptom vocabulary) (140)
|
||||
|
||||
- **§3-How** — to use this <sub>L30</sub>
|
||||
- **§1** — Idiom catalog (asm pattern → C that produces it) <sub>L39</sub>
|
||||
@@ -689,8 +703,26 @@
|
||||
- **§144** — THE LITERAL'S SPELLING PICKS THE IMMEDIATE ENCODING (P30 S40 wave 1, `func_801822E0`) <sub>L9878</sub>
|
||||
- **§3-Why** — a correct draft can read as an intrinsic wall <sub>L9978</sub>
|
||||
- **§3-The** — rule <sub>L10013</sub>
|
||||
- **§3-B.** — `(v < 0x40) ? v : 0x3F` is folded to `MIN_EXPR` and expands to the WRONG SHAPE <sub>L10123</sub>
|
||||
- **§3-D.** — Reproduce the original's BUGS verbatim <sub>L10147</sub>
|
||||
- **§3-B.** — `(v < 0x40) ? v : 0x3F` is folded to `MIN_EXPR` and expands to the WRONG SHAPE <sub>L10160</sub>
|
||||
- **§3-D.** — Reproduce the original's BUGS verbatim <sub>L10184</sub>
|
||||
- **§149** — Four instrument defects in one session, and the two questions they were hiding (P30 S43) <sub>L10233</sub>
|
||||
- **§3-A.** — A prep step that returns its input on failure is indistinguishable from a search that found nothing <sub>L10239</sub>
|
||||
- **§3-B.** — Same address + same name ≠ same body — and the ledger keys on address <sub>L10257</sub>
|
||||
- **§3-C.** — `make: *** [...] Error N` is a summary, never a diagnosis <sub>L10273</sub>
|
||||
- **§3-The** — fix <sub>L10309</sub>
|
||||
- **§3-The** — method that found it (this is the transferable part) <sub>L10319</sub>
|
||||
- **Diagnostic** — order (adopt this) <sub>L10346</sub>
|
||||
- **§3-The** — mechanism (read from cc1's own `-dR` trace, not inferred) <sub>L10362</sub>
|
||||
- **§3-The** — lever — a zero-emission insn that absorbs the blocked tick <sub>L10377</sub>
|
||||
- **§3-The** — finding <sub>L10413</sub>
|
||||
- **§3-The** — key <sub>L10422</sub>
|
||||
- **§3-Two** — cautions that must travel with this technique <sub>L10433</sub>
|
||||
- **§3-The** — companion defect (open) <sub>L10444</sub>
|
||||
- **Symptom** — Symptom <sub>L10464</sub>
|
||||
- **Mechanism** — (gcc source + RTL dumps, not inferred) <sub>L10469</sub>
|
||||
- **§3-The** — cure — a fresh launder per site, each in its own block <sub>L10482</sub>
|
||||
- **Companion** — levers from the same function <sub>L10492</sub>
|
||||
- **§3-B.** — Two static base-derivation methods that must AGREE (use both) <sub>L10526</sub>
|
||||
|
||||
|
||||
## All sections, in order
|
||||
@@ -1114,8 +1146,38 @@
|
||||
- **§3-D.** — A lone `$t8`/`$t9` in the target is RELOAD SCRATCH — reproduce the spill, don't pin the register <sub>L10063</sub>
|
||||
- **§3-E.** — A `qty_compare` TIE is not spelling-reachable — recognise it and stop <sub>L10073</sub>
|
||||
- **Consequence** — for the family (a real scheduling decision) <sub>L10085</sub>
|
||||
- **§148** — The loop.c hoisting THRESHOLD is arithmetic you can compute, and the `?:` clamp that folds to MIN_EXPR (P30 S42, `func_8017C6F4`, 947 ins) <sub>L10098</sub>
|
||||
- **§3-A.** — `move_movables` hoists iff `threshold × savings × lifetime ≥ insn_count` — and you can read it <sub>L10104</sub>
|
||||
- **§3-B.** — `(v < 0x40) ? v : 0x3F` is folded to `MIN_EXPR` and expands to the WRONG SHAPE <sub>L10123</sub>
|
||||
- **§3-C.** — A zero-byte ALLOCNO-PRIORITY slider <sub>L10137</sub>
|
||||
- **§3-D.** — Reproduce the original's BUGS verbatim <sub>L10147</sub>
|
||||
- **§148** — The loop.c hoisting THRESHOLD is arithmetic you can compute, and the `?:` clamp that folds to MIN_EXPR (P30 S42, `func_8017C6F4`, 947 ins) <sub>L10135</sub>
|
||||
- **§3-A.** — `move_movables` hoists iff `threshold × savings × lifetime ≥ insn_count` — and you can read it <sub>L10141</sub>
|
||||
- **§3-B.** — `(v < 0x40) ? v : 0x3F` is folded to `MIN_EXPR` and expands to the WRONG SHAPE <sub>L10160</sub>
|
||||
- **§3-C.** — A zero-byte ALLOCNO-PRIORITY slider <sub>L10174</sub>
|
||||
- **§3-D.** — Reproduce the original's BUGS verbatim <sub>L10184</sub>
|
||||
- **§149** — Four instrument defects in one session, and the two questions they were hiding (P30 S43) <sub>L10233</sub>
|
||||
- **§3-A.** — A prep step that returns its input on failure is indistinguishable from a search that found nothing <sub>L10239</sub>
|
||||
- **§3-B.** — Same address + same name ≠ same body — and the ledger keys on address <sub>L10257</sub>
|
||||
- **§3-C.** — `make: *** [...] Error N` is a summary, never a diagnosis <sub>L10273</sub>
|
||||
- **§3-D.** — "Cheap fuel" that was never probed: 0 of 31 templatable <sub>L10283</sub>
|
||||
- **§150** — A register ROTATION across symmetric blocks is VARIABLE-IDENTITY evidence, not an allocator tie (P30 S43, `func_8017C6F4`, 947 ins ×4) <sub>L10302</sub>
|
||||
- **§3-The** — fix <sub>L10309</sub>
|
||||
- **§3-The** — method that found it (this is the transferable part) <sub>L10319</sub>
|
||||
- **§3-Two** — corrections to the record <sub>L10335</sub>
|
||||
- **Diagnostic** — order (adopt this) <sub>L10346</sub>
|
||||
- **§151** — THE GHOST WEDGE: when a load-before-store transposition is unreachable by ANY statement order (P30 S43, `func_8017EF68`, 969 ins) <sub>L10357</sub>
|
||||
- **§3-The** — mechanism (read from cc1's own `-dR` trace, not inferred) <sub>L10362</sub>
|
||||
- **§3-The** — lever — a zero-emission insn that absorbs the blocked tick <sub>L10377</sub>
|
||||
- **§3-The** — two fallouts, and how to close them (both measured, in order) <sub>L10385</sub>
|
||||
- **When** — to reach for it <sub>L10397</sub>
|
||||
- **§152** — BYTE SIZE is the family key that name- and h_seq-grouping both miss (P30 S43, the 0xECC family: 1 crack → 12 overlays → 11,364 ins) <sub>L10408</sub>
|
||||
- **§3-The** — finding <sub>L10413</sub>
|
||||
- **§3-The** — key <sub>L10422</sub>
|
||||
- **§3-Two** — cautions that must travel with this technique <sub>L10433</sub>
|
||||
- **§3-The** — companion defect (open) <sub>L10444</sub>
|
||||
- **§153** — THE ADDRESS-REMATERIALISATION LAUNDER: a third zero-emission asm lever (P30 S43, `func_8018D98C`, 710 ins) <sub>L10456</sub>
|
||||
- **Symptom** — Symptom <sub>L10464</sub>
|
||||
- **Mechanism** — (gcc source + RTL dumps, not inferred) <sub>L10469</sub>
|
||||
- **What** — does NOT work (14 byte-measured probes) <sub>L10476</sub>
|
||||
- **§3-The** — cure — a fresh launder per site, each in its own block <sub>L10482</sub>
|
||||
- **Companion** — levers from the same function <sub>L10492</sub>
|
||||
- **§154** — Reading a disc payload: the module-id word, static base derivation, and "type 1 = uncompressed overlay" (P30 S44) <sub>L10512</sub>
|
||||
- **§3-A.** — Payload word0 is a global MODULE ID; code starts after the header <sub>L10517</sub>
|
||||
- **§3-B.** — Two static base-derivation methods that must AGREE (use both) <sub>L10526</sub>
|
||||
- **§3-C.** — PAC type 1 = the same payload class as type 4, just NOT compressed <sub>L10538</sub>
|
||||
|
||||
@@ -2204,3 +2204,38 @@ contract, and this makes it enforceable rather than remembered.
|
||||
|
||||
**Sequencing (Drew's call):** finish the serial crack queue → L1+L2 (cheap, deterministic, and they
|
||||
sharpen L3's target list) → L3 + type-1 onboarding. Fold into **P31**, which already owns bucket T.
|
||||
|
||||
## 2026-08-06 (P30 S44) — the 78-payload campaign: static addresses dissolve the emulator dependency; "modules" mostly dissolve into overlays
|
||||
|
||||
**Context + belief.** `make audit-disc` (S43) enumerated 78 unclaimed code payloads (~3.4 MB). Standing
|
||||
doctrine (`disc-completeness.md`, from P27): these are "type-1 modules" whose load addresses are "only
|
||||
knowable by runtime RE" — so onboarding was gated on an emulator session (L3), and the completion
|
||||
contract carried them as a 39-module backlog.
|
||||
|
||||
**What the measurement said (3 read-only agents, byte-verified).** (1) The load addresses are STATIC
|
||||
for 46 of 78: the EXE's `loadDestPtrTable` + boot literals + two index tables inside the resident +
|
||||
`resident.c:641` + the SC07 pair's own headers give every MAIN payload and the SC07 pair a derived
|
||||
address, corroborated by two independent corpus-side voting methods at ~500:1 margins
|
||||
(`memory-map.md` §S44). (2) The three biggest "modules" are ORDINARY OVERLAYS stored uncompressed
|
||||
(type 1 = raw overlay, type 4 = LZSS) for the standard 0x80128158 slot — ~75–77% of their functions
|
||||
h_exact-identical to the onboarded corpus, 802 genuinely novel across all three. (3) The remainder
|
||||
tiers honestly: 35 small actor modules at two statically-known ping-pong slots; SC07/3+4 at their own
|
||||
slot; 28 script modules (7 × 4 per-disc builds) + 4 stragglers genuinely runtime-determined.
|
||||
|
||||
**The pivot.** L3 shrinks from "the onboarding prerequisite" to a small runtime-confirm pass (28+4
|
||||
payloads + R34 verification of the static addresses). The campaign inverts: tooling updates → onboard
|
||||
the big 3 through the EXISTING overlay machinery → dedup-bank the h_exact majority → batch the small
|
||||
modules — all emulator-free. The "new binary class" tooling burden collapses to: `config/modules.mk`,
|
||||
a de-ov_'d R36 gate, a vram-derived `family_remap`, glob widenings, and a parameterized
|
||||
`new_binary.sh`. Full per-tool table: `tooling-audit.md` §S44.
|
||||
|
||||
**Why this was missable for 30 phases.** Each prior tool was correct about its subset and silent about
|
||||
the rest (the audit's founding observation) — and the doctrine layer had the same shape: the P27
|
||||
"only knowable by runtime RE" sentence was true of the tools that existed then, and nobody re-derived
|
||||
it after the loader cluster was matched (the tables were sitting in matched C + the resident's own
|
||||
bytes). A confident negative doctrine is a claim like any other — date it, cite its evidence,
|
||||
re-measure before letting it gate a campaign (the §146/§147 lesson at doctrine scale).
|
||||
|
||||
**Hindsight better path.** When Phase 3 T5 wrote "entries [1]+ are runtime-indexed (no static xref)",
|
||||
the honest follow-up was a named open question ("WHERE do the indices live?") rather than a doctrine.
|
||||
The answer was one grep away once the resident was matched in Phase 12.
|
||||
|
||||
@@ -44,6 +44,20 @@ loads at its own address, the way the resident loads at `0x800CEDF8`. So — unl
|
||||
that address is only knowable by runtime RE (a PCSX-Redux RAM-dump proof, the Phase-3 method). Onboarding
|
||||
them is a Gen2 RE task, deferred with this evidence — NOT a false "complete" while code sits unbuilt.
|
||||
|
||||
> **⚠️ 2026-08-06 (S44): the "only knowable by runtime RE" sentence above is REFUTED.** The load
|
||||
> addresses are **static** for 46 of the 78 unclaimed payloads: the EXE's `loadDestPtrTable`
|
||||
> (0x80072C70) + the boot loaders' literal `&cdFileLocTable[k]` operands + two index tables INSIDE the
|
||||
> resident (`D_800D3764` → slot A 0x800CAE08 for MAIN/13…41; `D_800D384C` → slot B 0x800CCB1C for
|
||||
> MAIN/42…47) + `src/resident/resident.c:641` (MAIN/12 → the standard overlay slot 0x80128158) + the
|
||||
> SC07 pair's own headers (→ 0x801A00D8). Full routing table with provenance:
|
||||
> **`docs/memory-map.md` §"Phase 30 S44"**. Independently corroborated by h_exact base voting (~500:1)
|
||||
> and jal-alignment voting. The genuinely runtime-only remainder is the 28 SC0x script modules +
|
||||
> MAIN/7, MAIN/9, SC02/9 — parked for L3 with evidence. Additional corrections from the same pass:
|
||||
> the three biggest "modules" (MAIN/12, SC02/37, SC03/107) are **ordinary overlays stored uncompressed**
|
||||
> (PAC type 1 = raw overlay, type 4 = LZSS overlay); the 78 ledger rows sum **3,406,325 B** (the
|
||||
> bucket's 3,564,021 additionally counts PAC headers); `MAIN/7` is a raw file (`FILE_007`, not
|
||||
> PAC-wrapped); `MAIN/0 ≡ MAIN/1` byte-identical; payload word0 is a global module id (resident=0x36).
|
||||
|
||||
## Consequence for the completion contract (roadmap §1)
|
||||
|
||||
The contract's binary count is **no longer "136"**. Two corrections:
|
||||
|
||||
@@ -10506,3 +10506,41 @@ exist, gate the PLAIN one first.
|
||||
**Symptom lines for the index:** **"an extra `sw $sN` in the prologue"** · **"`la $sN,SYM` + moves
|
||||
where the target rematerialises"** · **"an address argument used twice in one block"** · **"a hoist no
|
||||
respelling reaches"**.
|
||||
|
||||
---
|
||||
|
||||
## §154 — Reading a disc payload: the module-id word, static base derivation, and "type 1 = uncompressed overlay" (P30 S44)
|
||||
|
||||
Not codegen — payload forensics. Three laws from the 78-unclaimed-payload analysis, each of which
|
||||
turns a former "needs the emulator" into a static read.
|
||||
|
||||
### A. Payload word0 is a global MODULE ID; code starts after the header
|
||||
75 of 78 unclaimed payloads begin with a small LE integer forming one dense id space across all discs
|
||||
(0x13…0x73; the resident is 0x36). Some follow it with a function-pointer table (SC07/3: table to
|
||||
0xF8; SC07/4: to 0x154) before code. **Consequences:** `sig_image --bootstrap` returns **0 functions**
|
||||
on any of them if run from offset 0 (its linear partition hits the header, finds no `jr $ra`, stops) —
|
||||
**always pass `--text-lo` past the header**; and a header's own pointer table dates the base for free
|
||||
(first table target − first prologue file offset = base). Only payloads that begin directly with code
|
||||
(a `27bdffe8`-class prologue at offset 0) may be signed bare.
|
||||
|
||||
### B. Two static base-derivation methods that must AGREE (use both)
|
||||
1. **h_exact voting:** sign the payload at ANY nominal base; for every function h_exact-identical to a
|
||||
corpus function, `delta = corpus_addr − signed_addr` votes for the true base. On real overlays the
|
||||
margin is decisive (~500:1 — 218,454 votes vs a 414 runner-up).
|
||||
2. **jal-alignment voting:** collect distinct internal `jal` targets; the base under which the most
|
||||
land on actual prologue file offsets wins. Corpus-independent; the control (the resident) reproduces
|
||||
its known 0x800CEDF8 and ends 4 bytes under the overlay slot.
|
||||
A payload where the two disagree, or where votes are thin (script modules: 3–14 aligned jals, calls
|
||||
almost all outward), is **loader-determined** — park it for runtime confirm rather than guessing (P9).
|
||||
And check the LOADER first: the EXE's `loadDestPtrTable` + the resident's index tables route most
|
||||
payloads statically (`memory-map.md` §S44) — the vote is then the R34 cross-check, not the source.
|
||||
|
||||
### C. PAC type 1 = the same payload class as type 4, just NOT compressed
|
||||
The three biggest "mystery modules" were ordinary location overlays for the standard 0x80128158 slot,
|
||||
stored raw. Their first 192 bytes are byte-identical to built ov_ images; ~75% of their functions are
|
||||
h_exact-identical to the corpus. **Before inventing a new class for a payload, diff its head against
|
||||
the classes you already own.** (Corollary of §152: same-bytes is the family key — here at payload
|
||||
scale.)
|
||||
|
||||
**Symptom lines for the index:** **"sig_image bootstrap finds 0 functions"** · **"a payload with a
|
||||
small integer first word"** · **"where does this blob load"** · **"a huge type-1 module"**.
|
||||
|
||||
@@ -568,3 +568,59 @@ in retail too (shipped data, not a debug build). The proto's scene-select shares
|
||||
| gamehacking.org #88529 (US) / #93476 (JP) via libretro-database GameShark `.cht` | Player stat block, flags, misc | gamehacking.org Cloudflare-blocks scripts; cht mirror: `raw.githubusercontent.com/libretro/libretro-database/master/cht/Sony%20-%20PlayStation/Brave%20Fencer%20Musashi%20(USA,%20Japan)%20(GameShark).cht` |
|
||||
| jywjyw `bravefencer-hack` `doc/note.md` | JP overlay/memory map, LIST.CD-in-RAM behavior, pointer table | **All addresses JP (SLPS-01490)** — re-derive for US |
|
||||
| Hidden Palace / archive.org | Prototype facts | pages fetchable via `hiddenpalace.org/w/index.php?title=PAGE&action=raw` |
|
||||
|
||||
## Phase 30 S44 — the COMPLETE loader routing table (static-derived; supersedes "runtime-indexed, no static xref")
|
||||
|
||||
> **Provenance (G5):** `static-derived` — read from the EXE bytes (`extracted/retail/SLUS_007.26`,
|
||||
> vram = fileoff + 0x8000F800), the resident payload bytes (`MAIN.CD.dir/FILE_010.dir/1.1`, fileoff =
|
||||
> vram − 0x800CEDF8), the matched loader C (`src/800.c`, `src/resident/resident.c`), and the per-overlay
|
||||
> wrapper asm — by 3 read-only exploration agents, 2026-08-06. Region: **US**. The Phase-3 T5 note
|
||||
> "entries [1]+ are runtime-indexed (no static xref)" is **superseded**: the indices ARE static, they
|
||||
> live in the resident and in each overlay, not in the EXE. Independently corroborated by two
|
||||
> corpus-side methods (h_exact base voting at ~500:1; distinct-jal→prologue alignment voting) — and the
|
||||
> resident control reproduces its known 0x800CEDF8 and ends at 0x80128154, four bytes under the overlay slot.
|
||||
|
||||
### loadDestPtrTable — 0x80072C70 (EXE fileoff 0x63470), 5 × u32
|
||||
|
||||
| slot | value | role (byte-proven) |
|
||||
|---|---|---|
|
||||
| [0] | **0x800CEDF8** | resident-module slot (boot loaders) |
|
||||
| [1] | **0x80128158** | location-overlay slot |
|
||||
| [2] | **0x800CAE08** | module slot A (small actor modules) |
|
||||
| [3] | **0x800CCB1C** | module slot B (small actor modules) |
|
||||
| [4] | **0x800C7F08** | PAC-type-7 fixed destination |
|
||||
|
||||
### Who loads what where (all statically enumerated)
|
||||
|
||||
| loader | index source | payloads | dest |
|
||||
|---|---|---|---|
|
||||
| 5 boot loaders (literal `&cdFileLocTable[k]` at 0x80010CA4 / 0x80010F1C / 0x800112F0 / 0x80011100 / 0x80011144) | k ∈ {1,3,8,10,11} | MAIN/1,3,8,**10 (=resident)**,11 | `loadDestPtrTable[0]` = 0x800CEDF8 |
|
||||
| resident `func_800D02D0` | **`D_800D3764`** = 29 × {u32 cdFileLocIdx; u32 param} | MAIN/13…41 (contiguous) | `[2]` = 0x800CAE08 |
|
||||
| resident `func_800D0488` | **`D_800D384C`** = 6 × {u32,u32} | MAIN/42…47 | `[3]` = 0x800CCB1C |
|
||||
| resident `func_800CF94C` (`src/resident/resident.c:641`) | `&cdFileLocTable[12]` | MAIN/12 (an UNCOMPRESSED overlay) | `[1]` = 0x80128158 |
|
||||
| per-overlay wrapper `func_80128CFC` (every overlay) | per-overlay `IDXTAB` (s16, −1-terminated, 37 entries, same list fleet-wide) + `*DESTPTR` (per-overlay initialized word) | resources incl. the SC0x sets | per-overlay dest (e.g. ov_SC01_000: IDXTAB 0x8017EEC8, *0x801A3234 = 0x801A58E8) |
|
||||
| SC07 endgame pair | header-derived (id word + fn-ptr table; first table target − first prologue fileoff) | SC07/3 (code@0xFC), SC07/4 (code@0x158) | **0x801A00D8** (own slot, overlaps the overlay tail — disc-7 layout) |
|
||||
|
||||
### The arithmetic
|
||||
|
||||
- **Global cdFileLocTable index** = `gbase[cd] + subfile`; gbase = MAIN:0 SC01:49 SC02:135 SC03:178
|
||||
SC04:318 SC05:349 SC06:379 SC07:418 (LIST.CD counts 49/86/43/140/31/30/39/29, byte-verified; LIST.CD
|
||||
carries **LBA + length only**, never load addresses).
|
||||
- **Slot adjacency proof:** 0x800CAE08 + 7,444 (max slot-A payload, MAIN/34) = 0x800CCB1C;
|
||||
0x800CCB1C + 8,920 (max slot-B, MAIN/44) = 0x800CEDF4 → resident at 0x800CEDF8. The three regions are
|
||||
back-to-back, each sized to its largest member. MAIN/46's self-calls (base+0x724/0x978/0xAB0) confirm slot B.
|
||||
- **Module-ID law:** payload **word0 is a global module id** (dense 0x13…0x73 across all discs; the
|
||||
resident is 0x36). 75/78 unclaimed payloads carry it; only the 3 raw uncompressed overlays
|
||||
(MAIN/12, SC02/37, SC03/107) start directly with code. MAIN/9 and MAIN/39 both carry id 0x2D
|
||||
(unresolved duplicate). MAIN/0 ≡ MAIN/1 byte-identical (one module stored twice).
|
||||
- **PAC-type law (extends formats.md):** type **1** = uncompressed code/module payload; type **4** =
|
||||
the same class LZSS-compressed. The PAC header's bytes 0x10–0x7FF are never read by the loader
|
||||
(`CdGetSector(lzss_sectorStagingBuf, 4)` reads 4 words) — no address lives in the payload.
|
||||
|
||||
### Statically UNRESOLVED (parked for L3 — runtime confirm, R34)
|
||||
|
||||
The 28 SC0x script modules (SC03/73-79, SC03/132-138, SC04/24-30, SC05/23-29 = 7 modules × 4 per-disc
|
||||
builds), SC02/9, MAIN/7 (raw file, not PAC), MAIN/9: dest comes through the resourceIdMap /
|
||||
`StreamLoadStateMachine` descriptor path (`D_80068B60[(loadParam−0x100)*0x10]`) or per-overlay DESTPTR
|
||||
values — per-disc, not EXE-static. Their jal-vote bases are LOW-CONFIDENCE (3–14 aligned jals, calls
|
||||
almost entirely outward) and are NOT recorded as addresses here.
|
||||
|
||||
@@ -1693,3 +1693,101 @@ by a build from stale objects. Cheap, total, and it removes the need to remember
|
||||
**Assertion (R32):** after `build`, assert every `.o` linked into the image is NEWER than every `.s` it
|
||||
includes; fail loud on the first inversion. A build that consumed a stale object must never be allowed
|
||||
to report BYTE-IDENTICAL.
|
||||
|
||||
---
|
||||
|
||||
# S44 NEWCODE AUDIT (2026-08-06) — every tool vs the 78 unclaimed payloads
|
||||
|
||||
> Drew's directive: *"analyze every single one of our tools and determine how/if it needs to be
|
||||
> updated to properly account for our new code findings."* Ground truth: 3 read-only exploration
|
||||
> agents over the full inventory (117 `tools/*.py`, 13 `tools/*.sh`, `tools/bfm_extract/` ×11,
|
||||
> `tools/ghidra_scripts/` ×11, `tools/workflows/` ×6, `tools/permuter/`, `diff_settings.py`,
|
||||
> `Makefile`, the config registries). Vendored submodules out of scope.
|
||||
>
|
||||
> **The class mostly DISSOLVES:** the 3 big payloads are ordinary overlays (standard slot, existing
|
||||
> machinery); only the small modules + the SC07 pair need a genuinely new binary class ("md_*",
|
||||
> `config/modules.mk`). Classification: **(a)** parameterized per-binary · **(b)** derives the binary
|
||||
> set from configs · **(c)** hardcodes overlay shape · **(d)** binary-agnostic/N-A.
|
||||
|
||||
## Registration surfaces (the choke points)
|
||||
|
||||
| surface | class | point | verdict |
|
||||
|---|---|---|---|
|
||||
| `Makefile` | b | `:55` BINARIES; prune `:511`; check-all `:753` | **CODE**: `-include config/modules.mk`, `+ $(MODULE_BINARIES)`; downstream of `$(BINARIES)` auto-OK |
|
||||
| `config/overlays.mk` | b | generated registry | **NEW SIBLING** `config/modules.mk`, same 18-var block, per-alias VRAM |
|
||||
| `tools/dup_report.py` BINARIES | b | `:26-180` (sentinel `:167`) | registration line/binary (non-ov_ aliases already take the individual-ingest path `:210`) |
|
||||
| `tools/progress.py` BINARIES | b | `:23-305` (sentinel `:304`) | registration line/binary |
|
||||
| `diff_settings.py` BINARIES | b | `:16-437` (sentinel `:437`) | registration line/binary |
|
||||
| `tools/audit_binaries.py` (R36) | **c** | `onboarded()` `:41-43` globs `splat.ov_*.yaml`; `startswith("ov_")` `:92,:111,:124,:131` | **CODE**: derive from `splat.*.yaml` minus main (R33); keep engine_core-include check ov_-conditional |
|
||||
| `tools/corpus.py` | b | `:373` from dup_report; `sig_is_independent` `:336` | **CODE** at `:336` (ov_/resident-only ⇒ module sigs untrusted); rest auto-OK |
|
||||
| `tools/difficulty.py` | b→derived | `cfg_for(alias)` `:22-34` | **auto-OK** (P27 T6 migration) |
|
||||
|
||||
## Must-change (code)
|
||||
|
||||
| tool | defect | fix |
|
||||
|---|---|---|
|
||||
| `family_remap.py` | `VRAM = 0x80128158` module const `:30`, used in ALL offset math `:98,:160` (img_path is already yaml-derived) | `vram_base_of(alias)` from `config/splat.<a>.yaml` — the pattern `jtbl_carve.overlay_vram_base()` `:65-71` already implements |
|
||||
| Makefile sig targets | `sig-overlays` hardcodes `OVERLAY_VRAM :=0x80128158` `:292`; `sig-resident` separate | one generalized target over `$(filter-out main,$(BINARIES))` with `$($(a)_VRAM_BASE)` (+ per-alias TEXT_LO); keep old names as aliases |
|
||||
| `family_hseq.py` | `src/ov_*` `:43` + `sig.ov_*` `:45` globs; self-declared overlays-only `:189,:219` | include resident+modules (glob `sig.*.jsonl` minus main, or read registries) |
|
||||
| `progress.py --weighted` | `sig.ov_*` glob `:647` + explicit resident `:648` | derive from BINARIES |
|
||||
| `audit_frontier.py` | `:57-59` same glob shape | same fix |
|
||||
| `backlog.py` | alias regex `:137` `(ov_…|resident|main)` | add `md_…` |
|
||||
| `prefetch_fleet.py` | `:67` `("main","resident")` | add modules |
|
||||
| `dedup_propagate.py` | reads only `overlays.mk` `:44` | also read `modules.mk` |
|
||||
|
||||
## Retire (R33)
|
||||
|
||||
`disc_code_sweep.py` — superseded by `disc_audit.py` (whole-disc partition, both layers, no window,
|
||||
claims); zero build refs (Makefile mentions it only in a comment); doc refs to update:
|
||||
`docs/SETUP.md:667`, `docs/disc-completeness.md` · `reconcile_decls.py` — self-declared RETIRED ·
|
||||
`rollout_801457a4_o0.py`, `rollout_whale_o0.py`, `rollout_o0_cluster.py` — one-shot, slot-locked
|
||||
historical rollouts · `ghidra_scripts/ImportOverlay.java` + `VerifyOverlay.java` — 1-overlay-era
|
||||
hardcoded tables (`ghidra_import_raw.sh` is the live path).
|
||||
|
||||
## `new_overlay.sh` → `tools/new_binary.sh`
|
||||
|
||||
Overlay-specific: alias pattern `:29`, payload path `${ENTRY}.dec` `:30`, `VRAM=` `:31`, slot literals
|
||||
re-hardcoded at `:39,:44`, the overlay splat template. **Generic and reusable verbatim:** check.sha +
|
||||
symbols creation, the 18-var mk block, the sentinel-anchored 3-dict registrar `:104-133` (ast-checked),
|
||||
extract+build byte-check. ⇒ parameterize {ALIAS, PAYLOAD, VRAM, TEXT_LO, TEMPLATE, REGISTRY};
|
||||
`new_overlay.sh` becomes a wrapper with the old defaults.
|
||||
|
||||
## `sig_image.py` — no code change; a USAGE law
|
||||
|
||||
`--bootstrap` linear-partitions from `lo = vram_base` (`:232`, `bootstrap_seeds` `:81-98`) ⇒ assumes
|
||||
code at file offset 0. 75/78 payloads start with the module-id word (+ sometimes a ptr table) ⇒ 0
|
||||
seeds. **Law: pass `--text-lo` past the header** (prologue offsets are in the disc-ledger roster).
|
||||
`--seeds` accepts a sig jsonl or 0xADDR lines (`:47-59`).
|
||||
|
||||
## Auto-OK once registered — (a) parameterized / (b) derived
|
||||
|
||||
`gate_stage` · `harvest_verify` · `match_one` · `rtu_match` · `masked_diff`/`masked_scorer` ·
|
||||
`family_sweep` (cross-address `--to-addr` EXISTS: `:332-343,:537`) · `family_manifest`(glob fix rides
|
||||
family_hseq) · `dedup_extend` · `dedup_integrate` · `jtbl_carve` (the model implementation) ·
|
||||
`jtbl_family_bank` · `jr_isolate`/`jr_isolate_all` · `o0_subsplit` · `overlay_src_split` ·
|
||||
`split_src_region` · `blast_radius` (derives from `splat.*.yaml` — best-in-class) · `worklist` ·
|
||||
`exemplar_miner` · `diff_regions` · `lift_types` · `build_engine_types` · `uniquify_type` ·
|
||||
`canon_sig_reconcile` · `recover_giant` · `recover_integration` · `fix_arity_callers` ·
|
||||
`fix_header_decl` · `cast_call_sites` · `sig_unify` · `reconcile_tu` · `canon_draft_decls` ·
|
||||
`canon_resident_calls` · `inject_capped_externs` · `scope_tu_externs` · `scope_data_externs` ·
|
||||
`normalize_self_decls` · `conform_decls` · `blocker_probe` · `demacroize` · `autopsy` ·
|
||||
`residual_class` · `bank_exemplar` · `t7_bank` · `sweep_parallel` · `bulk_harvest` (alias side via
|
||||
`lora_grind.binaries()` = check-sha glob) · `lora_grind` (`binaries()` auto-OK; reach-glob rides the
|
||||
hseq fix) · `gen_harvest_targets`(same) · `build_fuel_manifest`(same) · `wave_targets` ·
|
||||
`build_wave_args` · `idiom_loop` · `audit_digest` (via progress.BINARIES) · `lint_symbol_refs` ·
|
||||
`cookbook_index` · `symcheck` · `burndown` · `p16_permute`/`permuter_ils`/`permuter_weights`/
|
||||
`p16_improve`/`p16_known_answer` · `grinder` · `auto_driver` · workflows (`worker_wave.js` etc. —
|
||||
aliases are prompt args) · `glm_reconcile`.
|
||||
|
||||
## N-A (binary-agnostic)
|
||||
|
||||
Extract stack (`bfm_extract/*` — already extracted the payloads) · PsyQ linking (`psyq_*`,
|
||||
`gen_lib_subsegs`, `ld_interleave`, `make_*_used`, `make_libgs.sh`, `jtbl_rodata_pads`) · LLM tier
|
||||
(`serve_local`, `api_draft`, `train_lora`, `eval_lora`, `format_finetune`, `export_pairs`,
|
||||
`idiom_hunt`, `glm_parallel.sh`, `orchestrator`) · permuter internals (`run_masked`, `compile*.sh`) ·
|
||||
Ghidra plumbing (`ghidra_import.sh`, `ghidra_import_raw.sh` — the live module importer,
|
||||
`ghidra_mcp_*.sh`, the .java scripts except the two retired above) · automation shell
|
||||
(`auto_status/stop/supervisor.sh`, `treelock.sh`) · `decompile.py` · `match_protos.py` ·
|
||||
`ram_probe.py` · `audit_text_sources.py` · `sweep_citations.py` · `ab_match.js`/`ab_score.py` ·
|
||||
`disc_audit.py` (the new oracle itself; its `claimed-by` derives from `config/check.*.sha`, so newly
|
||||
onboarded binaries flip to claimed with ZERO wiring).
|
||||
|
||||
@@ -2527,6 +2527,23 @@ and is booked as data. **Not in `tools-health`** — it needs `disks/`, which a
|
||||
**Next (task #11 / L3):** the emulator tour resolves whether these 34 are the 39 type-1 modules, gives
|
||||
their load addresses, and proves completeness against execution.
|
||||
|
||||
### ▶ S44-I.0 — the new-code campaign opens: knowledge captured (2026-08-06, Fable5Max plan approved)
|
||||
Plan: `~/.claude/plans/optimized-squishing-engelbart.md` (Part I this session, Part II fresh). Three
|
||||
exploration agents broke the 78-payload class open; everything captured while hot (R30/R31):
|
||||
- **`docs/memory-map.md` §"Phase 30 S44"** — the COMPLETE static loader routing table
|
||||
(`loadDestPtrTable` slots · boot k-set {1,3,8,10,11} · resident tables `D_800D3764`/`D_800D384C` →
|
||||
slots A/B 0x800CAE08/0x800CCB1C · MAIN/12 → 0x80128158 · SC07 pair → 0x801A00D8 · gbase arithmetic ·
|
||||
slot-adjacency proof · module-id law · "type 1 = uncompressed overlay"). Supersedes P3-T5's
|
||||
"runtime-indexed, no static xref" and P27's "only knowable by runtime RE"
|
||||
(`disc-completeness.md` corrected in place, H5).
|
||||
- **`docs/tooling-audit.md` §S44** — EVERY tool classified (a/b/c/d) with file:line: 8 code-changes,
|
||||
7 registrations, 5 retirements, the rest auto-OK/N-A. The "every single tool" deliverable.
|
||||
- **`docs/decision-log.md`** — the R31 pivot entry (why L3 shrank; why the doctrine was missable:
|
||||
a confident negative doctrine is a claim like any other — the §146/§147 lesson at doctrine scale).
|
||||
- **Cookbook §154** (+ index regen, 454 sections): module-id word / dual base-voting methods /
|
||||
type-1-is-an-overlay. Key numbers: big-3 base 0x80128158 at ~500:1; ~75-77% h_exact-known;
|
||||
**802 novel fns**; 46/78 addresses static; 28+4 parked for L3.
|
||||
|
||||
### ▶ S11 — the propagation lag: EXTEND 0/36 -> 31/36, and every blocker was a DECLARATION (2026-08-03/04)
|
||||
Lane 2 of the S10 checkpoint ("26,006 ins, ~0 agent tokens, PARTLY BLOCKED"), taken first on the
|
||||
standing doctrine that the cheap deterministic lever is probed before the expensive agent one.
|
||||
|
||||
Reference in New Issue
Block a user